samba-client-libs-4.19.8+git.435.78ced6cf30d-150600.3.21.1<>, ܉hp9|Z| 1†EV0 &t,;+G+\]N~`~6SnfjGjdbZoWӄh[*!`@D ^xX0S ݨH#`"'ϴm$MѦ},{␐A>?rtLaY…;3^gk à@! \ߒ;Mˡٓ$'Ej]O*20J|bo=-io !/kRnM#Q >C?d/ = T 9PV`v8v $v v v v !v#v&v(l(v*|`Td(8(9(:V(>N@NBNFOGPvHQvISvXT8YXDZ[l[[\^v]_v^j3bjgckdkekfklkukvvmdwvxdvy< zָּ֨Csamba-client-libs4.19.8+git.435.78ced6cf30d150600.3.21.1Samba client librariesThe samba-libs package contains the libraries needed by samba client programs.hh03-ch2a4ZSUSE Linux Enterprise 15SUSE LLC GPL-3.0-or-laterhttps://www.suse.com/Development/Libraries/C and C++https://www.samba.org/linuxx86_64X`(`(XXX7XXPhXXxX9@ ]`H8(XXɨhhXx8p`hXX(P(8((8+X8@HxpX'XX PHHX`)'H(8`PH(8XX0!M((((X(X88Ahhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhh924670ef8da835c0c9c815c3bf3544c6b98c78ee31e245bb29358051ce4b044e12c9ad249d3fd982ed11b648ab17f0147316703facf6124e51e89fe4aade1e5226d2abbe0a4538472456e9b824e3228cdd7534ec99b974542087d4097a32f07337eeaf2858e25f5a255dc4c8d7f58bf2df02e682617187f4fb1d7fea4d23eda1c9fc81ab547d2e6e59e8002317a606271d04bdc5bf444f7cd6ea7994d13e6810650e19f7b42579e64a5aeba9a59bd3148dba22f762c517957e07775c5e2f31bc379826ffec213e0a943e89b35816632799da3cb7e24b64bae5588a989e01118582c646f6d420a3c7d11d63d4af4ac524edf2f18e087a7ea2286abb329e35d32b0e74508ba0b8986badd8221566361cdd172b289b827329a49546a900ba4287ce4d5b837722b26ddbc29bf03a7b4280e239430a78210e0b9ad80c1a7196882957a633a1076d6717f526e13cc789a47f1ac496a9dd35403e2b8656592f5a1c35da7d3c9eb0c878df5be7557f59a9fb8ad4ace3224d9205f632ece45093fb776902b2d99637aa29354964a1659fa699854635a99ec2e62959902080363d809c310789fa063c8bdb1cffac79b8c2eb80b2ef9cad1983320a8402298db64e32df5c2e6231d89134f5442378f87c4bce387aec2e926b92eea6ea1423f8a6fef0c9008debc2611f1ce6db727b051bfc8fc2aa541874b799adc7f43efa8e954f77bb0f5cf19ced2f75874125ddcdb3e6f9e44b1c80dd8076e651bd0cc78a6cbf2cb66df0dd7243ff75310759506fb6686f68ca38da956f5084dd459c4f8c6d55cd1752560ee6e974c4d710ce8c687410a2dc6e6638b3b13a524741ba13c52647e0e9052fcaa6f504da1b48bb66e9d60c0ae1df044a0fceb4f9e5805ae626420862ec96415cf00d07693eb33ec596bebc45e8a70bd835324b752077d4796714a73314c9baf1d4bd592594dde0fc4b96806a82fe198cba11c28acc7eb169899d00f06d1559e2f2c9272ba109181baa81da5be5a85b19a56cdb52843300cf59a8cf95de3ecf9f45bc1911a253228479167643b072d1b9295e99231246ac1c71f8cdae13c692d83b6ed8609e58a53767b1c777073276f664cfc61bc821e124e04a3e962dc9dbb4df13a5f596a9b8d3358061adf4212cceee091c31640c947d72207900bd8a404648ad31ba37ef09b9347a95f6fea16d7ff04ada792201f826c45a1feb970c46c36feb9d91e5288715b18636dda45cff33ac86e0f2d64a3a872d495ea327b7c72e806700e61453ba106ae2e50461659b8ccca55d91175e1e731578cc460e0026a8db5e9cad2b410a33eb4c3128b3384218fafa07cbcb157299273290534ec6cfae3e66fbf760ee2609b2c12b1dec8b49a4e8b764bb67e6e3ae039c675a45c8ff37fc82ca7af280d600f2e14bf53f6f3e3fc99d6e968867e569c19cd7d6bc15b50b61a1d56bed22f25f1944e194e37fd3dcd9bb0ab4dd48b55f1b982c86ede136b408847e08b552412e57bd9f809babc12232eb5694221a82a352d1ba6cef0d42ced6683d78234ce1e60bd82204306e44609cbef3629ba0acab996881dec37752a8ced3bb603b4c16c0bfca2435a6b0845d49e003641998b73cb378531908658fc3a332fac638fa128bc5b400147d33a464d880bda24e1aa2fe1a5bdd38b4c25b6b2d3635b9ad3d823440317e6e791209f2040200e1941196c37bc06396a4895e01faadc17d377d7b3819f49bbe3cc20f7c45eee5421aa036972cdc22e7980f62915c4c02b6758ab4e6c730f8c4777408f22ff7a2794d3011ad193808fa25956d7b9aa358dbaf8290311d64823cd46a545418c46d8a2cf941322bceb048cfb1960d531bd2858aaa57d2c21736d4a355bac5eab57a4b93bf6b1685bee8579c16a4cf2cee706916651e432b5cd26b625135a5009019f7486eadf74700b34cf6911ec39f1eb4529c939cab9e1693e6fa7e340724bc5ace8b12f68304ab9619a5e679f93ba34089c20b4936475226eb5c0cb55bdd215aa5a8e5a637cf9d13aa97d36fb3787eb4130f98d0e09a66a2ba8b315fe08a1bd5a183e6f6cd8039920555d83d6f2554f394a6b99b870065ccce9bf19558d9a19ffc12a4ff77db825c6ab1d287a384f12cd5bac4d60228ff3b53f096baf8d92ed7395c1d509a826b97fa9afc9542c36b44751878df87a110b466e9408ba8c3fc18ef263b5cc851903be5978720ad1f21d93eb4fbf17ba7de4a6a9a267f87f82ffac188c68ee2774d319db680245801eaae1143ebe3b2bd22818e4de0006735b37654038c5ca28e9b1b1801e69146d7155662559d417f150a58da9bd1757b1f65a51e15ee40d762ff7fc23fa382d5debbb4fedc7c9ea0d2c7b01685137e76e96e279835d81eb9865c269caf0520de6e6232d1dd432fa33f91d2cd0b8e932b58ac54c56ab9eb9fe191aecb57bf0e55557109de23e656e38faa91cc41b0bf880ea72787edcf46f2a30e62f63b83f6dcc69edf732ff6e6c40475f191fbe150aa2dd3318eba8b0522c24d8e9c1c3a9edf49464f9204c51de05bbf55d9353dfd07b7607a48a417d2022a999586b387ac5cd2a4e651d0150a1d057892707232424a63c821242ce5aa3848d86cf3071cfba5abf0f08865e6f3701fd3d216ee7b109dd8845e2e89ccd57c309f18f8a36d051eebed4f6f762ea07893ed48aaa8a7a66d9a0f5847812ae037682ce09b2430d43285b3bee6715746160c41c66cfe3affb594e5770307e08ab6510a94cac2eea3a8669497aaa933a4ebb00c4430e6642a98b88201ca37b9a430e772093bed97b75f8d15977790e82aec07f31ee61fef61686007eb1c7f075fb92364430bc2a362b96b9836eb5cd89ff26a1df392edc3fc876830cbfb15dd034d975d4df0bf2c4de4cad6e780464ce605b7f150a7498ada2f695f1e696af402ab0db8a2be81a8b056aa269e5703db30dc0987ae72d0be50e7891e8cefe8e396433e9201c442335415bcd18c357aba72493309cb958249e215448c62a74f94827394a8dc716180e1816954650d99285e05ef5c217a8f04cef035e9b3f4b8ca5d231618dbd295c4527734f584208e18d2642bdb13832da5b5a6ac268a8b36f9094fb8cee8324713842a5ada1a2d6050306656fd32629cf4e94488f39677538ec86a39a40fafd683128ed31da5716374bcb8de50b8ead9bf91a7289c1d105e2cdb06d2fae7f692733a454941e3bbed43b63fae1b0d96edb7ffe9217a2c6ee6f38cb284e04a5ca35c6487de0b8887a5df5faf8c63fca1a36e9be3ec773985c63c11b74b1cd5a15db441c6bee7a37a45638d7a0ef54e0edddbc06cc2f79570146e5293477f0329be810c700d6ffc1e426b458f78e2171e06862c6933fcbf8f7bba04318716a62d1b3db69a97eb629827cbc1f7d4ef8dc7c4d6b31777bf4e1e2aa15ed294d14121bdb2af6b35600872c8b55f46b8dd4590fee4359c0972089028b8645fc4064b0fb51984a0945a9e1cc0c77d42db04ed6f41b3a64488918cdfa5fe1d0a3a026f0706a5371b062363a9de940e98ef49ee49f384090659754bd7f98103c3296c7cca35e9a35bd271b218fb0da4a5b43aa060f7b756672e2a49a29fe6f4f5ec9646e40daae7b9338b936fbe20d5c886e4dafb2a183fbf935e6359554c69ba2c9f23b7ee942d919143b32e1fc0c08f84acd4600990837e0f2217571a54878f0755bffe4777e97e18d827852cd6a31c560816e0bd2725afe4ac3e9e26cf37c1e978e59016445fd37d846eb5ab70fd87196ffa9fe0d715e12799866a0cca7394c44475be437de69b15225edb6fe4d7551c0da9bd53dbc8f9630f802bf207510210006892d4dd8b74b72285ec7e6bfd2c67d0067cc7ad862410cd3991f7639996335902e937a5402642116d273029d7337c7eca3e55d62a9883a949444256483b68cda3ddfe78dc39e63f72302ecbdbb915a04b0633e144b28e594b1a0fef0295e86b0b0802e95eef0fd654b355b2a2dcd7afa346ebfbae9eb75a2736fac42047ae4546d35a64590ff40dd3ddab105066ccd5adb08fd16bde1c94822aad72b3537494a7c22e5e18d84ab7da8291c8f015577643b0fa1e84b80097ee71647814861cd63092b281a7012d7a5ea3e4839e3525d417e68e28074a059a2770c5d65ce03c5963aa9e22ee53d0e499ee4d91398f5abb7c89e23c59c24380511a05e5ade99f27c894738f305e1e401695470d67acfa70ebe3eb58d67d2c57ed31874648c07bd36ce93ad58b6cef7970c4f9f121fcac22e78489589b8abae00ea3d23ae133986e24f2db8fe3bffebf24f0ca6717781136c593f1288edf9a1752ae7c0a2741b2f93b88cd490d6dcff1d4dcd0179e67a83704a5d99938049ea59cf4be0a6a5cc2cd0308fdfe69099397bbf5aa70bd407151e63df10c5437f1dceca9ab550e1e0f135af949d3aalibdcerpc-binding.so.0.0.1libdcerpc-server-core.so.0.0.1libdcerpc.so.0.0.1libndr-krb5pac.so.0.0.1libndr-nbt.so.0.0.1libndr-standard.so.0.0.1libndr.so.3.0.1libnetapi.so.1.0.0libsamba-credentials.so.1.0.0libsamba-errors.so.1.0.0libsamba-hostconfig.so.0.0.1libsamba-passdb.so.0.28.0libsamba-util.so.0.0.1libsamdb.so.0.0.1libsmbclient.so.0.7.0libsmbconf.so.0.0.1libsmbldap.so.2.1.0libtevent-util.so.0.0.1libwbclient.so.0.16rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsamba-4.19.8+git.435.78ced6cf30d-150600.3.21.1.src.rpmlibCHARSET3-samba4.so()(64bit)libCHARSET3-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libMESSAGING-SEND-samba4.so()(64bit)libMESSAGING-SEND-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libMESSAGING-samba4.so()(64bit)libMESSAGING-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libaddns-samba4.so()(64bit)libaddns-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libads-samba4.so()(64bit)libads-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libasn1util-samba4.so()(64bit)libasn1util-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libauth-samba4.so()(64bit)libauth-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libauthkrb5-samba4.so()(64bit)libauthkrb5-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libcli-cldap-samba4.so()(64bit)libcli-cldap-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libcli-ldap-common-samba4.so()(64bit)libcli-ldap-common-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libcli-ldap-samba4.so()(64bit)libcli-ldap-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libcli-nbt-samba4.so()(64bit)libcli-nbt-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libcli-smb-common-samba4.so()(64bit)libcli-smb-common-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libcli-spoolss-samba4.so()(64bit)libcli-spoolss-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libcliauth-samba4.so()(64bit)libcliauth-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libclidns-samba4.so()(64bit)libclidns-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libcluster-samba4.so()(64bit)libcluster-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libcmdline-contexts-samba4.so()(64bit)libcmdline-contexts-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libcmdline-samba4.so()(64bit)libcmdline-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libcommon-auth-samba4.so()(64bit)libcommon-auth-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libdbwrap-samba4.so()(64bit)libdbwrap-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libdcerpc-binding.so.0()(64bit)libdcerpc-binding.so.0(DCERPC_BINDING_0.0.1)(64bit)libdcerpc-binding0libdcerpc-pkt-auth-samba4.so()(64bit)libdcerpc-pkt-auth-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libdcerpc-samba-samba4.so()(64bit)libdcerpc-samba-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libdcerpc-samba4.so()(64bit)libdcerpc-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libdcerpc-server-core.so.0()(64bit)libdcerpc-server-core.so.0(DCERPC_SERVER_CORE_0.0.1)(64bit)libdcerpc.so.0()(64bit)libdcerpc.so.0(DCERPC_0.0.1)(64bit)libdcerpc0libevents-samba4.so()(64bit)libevents-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libflag-mapping-samba4.so()(64bit)libflag-mapping-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libgenrand-samba4.so()(64bit)libgenrand-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libgensec-samba4.so()(64bit)libgensec-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libgpo-samba4.so()(64bit)libgpo-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libgse-samba4.so()(64bit)libgse-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libhttp-samba4.so()(64bit)libhttp-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libinterfaces-samba4.so()(64bit)libinterfaces-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libiov-buf-samba4.so()(64bit)libiov-buf-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libkrb5samba-samba4.so()(64bit)libkrb5samba-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libldbsamba-samba4.so()(64bit)libldbsamba-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)liblibcli-lsa3-samba4.so()(64bit)liblibcli-lsa3-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)liblibcli-netlogon3-samba4.so()(64bit)liblibcli-netlogon3-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)liblibsmb-samba4.so()(64bit)liblibsmb-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libmessages-dgm-samba4.so()(64bit)libmessages-dgm-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libmessages-util-samba4.so()(64bit)libmessages-util-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libmscat-samba4.so()(64bit)libmscat-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libmsghdr-samba4.so()(64bit)libmsghdr-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libmsrpc3-samba4.so()(64bit)libmsrpc3-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-krb5pac0libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-nbt0libndr-samba-samba4.so()(64bit)libndr-samba-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libndr-samba4.so()(64bit)libndr-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libndr-standard.so.0()(64bit)libndr-standard.so.0(NDR_STANDARD_0.0.1)(64bit)libndr-standard0libndr.so.3()(64bit)libndr.so.3(NDR_0.0.1)(64bit)libndr.so.3(NDR_0.0.2)(64bit)libndr.so.3(NDR_0.0.3)(64bit)libndr.so.3(NDR_0.0.4)(64bit)libndr.so.3(NDR_0.0.5)(64bit)libndr.so.3(NDR_0.0.6)(64bit)libndr.so.3(NDR_0.0.7)(64bit)libndr.so.3(NDR_0.0.8)(64bit)libndr.so.3(NDR_0.0.9)(64bit)libndr.so.3(NDR_0.1.0)(64bit)libndr.so.3(NDR_0.1.1)(64bit)libndr.so.3(NDR_0.1.2)(64bit)libndr.so.3(NDR_0.2.0)(64bit)libndr.so.3(NDR_0.2.1)(64bit)libndr.so.3(NDR_1.0.0)(64bit)libndr.so.3(NDR_1.0.1)(64bit)libndr.so.3(NDR_1.0.2)(64bit)libndr.so.3(NDR_2.0.0)(64bit)libndr.so.3(NDR_3.0.0)(64bit)libndr.so.3(NDR_3.0.1)(64bit)libndr2libnet-keytab-samba4.so()(64bit)libnet-keytab-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libnetapi.so.1()(64bit)libnetapi.so.1(NETAPI_1.0.0)(64bit)libnetapi0libnetif-samba4.so()(64bit)libnetif-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libnpa-tstream-samba4.so()(64bit)libnpa-tstream-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libprinting-migrate-samba4.so()(64bit)libprinting-migrate-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libregistry-samba4.so()(64bit)libregistry-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libreplace-samba4.so()(64bit)libreplace-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsamba-cluster-support-samba4.so()(64bit)libsamba-cluster-support-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsamba-credentials.so.1()(64bit)libsamba-credentials.so.1(SAMBA_CREDENTIALS_1.0.0)(64bit)libsamba-credentials1libsamba-debug-samba4.so()(64bit)libsamba-debug-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsamba-errors.so.1()(64bit)libsamba-errors.so.1(SAMBA_ERRORS_1.0.0)(64bit)libsamba-errors0libsamba-hostconfig.so.0()(64bit)libsamba-hostconfig.so.0(SAMBA_HOSTCONFIG_0.0.1)(64bit)libsamba-hostconfig0libsamba-modules-samba4.so()(64bit)libsamba-modules-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsamba-passdb.so.0()(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.2.0)(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.24.1)(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.24.2)(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.25.0)(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.26.0)(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.27.0)(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.27.1)(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.27.2)(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.28.0)(64bit)libsamba-passdb0libsamba-security-samba4.so()(64bit)libsamba-security-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsamba-sockets-samba4.so()(64bit)libsamba-sockets-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsamba-util.so.0()(64bit)libsamba-util.so.0(SAMBA_UTIL_0.0.1)(64bit)libsamba-util0libsamba3-util-samba4.so()(64bit)libsamba3-util-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsamdb-common-samba4.so()(64bit)libsamdb-common-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsamdb.so.0()(64bit)libsamdb.so.0(SAMDB_0.0.1)(64bit)libsamdb0libsecrets3-samba4.so()(64bit)libsecrets3-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libserver-id-db-samba4.so()(64bit)libserver-id-db-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libserver-role-samba4.so()(64bit)libserver-role-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsmb-transport-samba4.so()(64bit)libsmb-transport-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsmbclient-raw-samba4.so()(64bit)libsmbclient-raw-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsmbclient.so.0()(64bit)libsmbclient.so.0(SMBCLIENT_0.1.0)(64bit)libsmbclient.so.0(SMBCLIENT_0.2.0)(64bit)libsmbclient.so.0(SMBCLIENT_0.2.1)(64bit)libsmbclient.so.0(SMBCLIENT_0.2.2)(64bit)libsmbclient.so.0(SMBCLIENT_0.2.3)(64bit)libsmbclient.so.0(SMBCLIENT_0.3.0)(64bit)libsmbclient.so.0(SMBCLIENT_0.3.1)(64bit)libsmbclient.so.0(SMBCLIENT_0.3.2)(64bit)libsmbclient.so.0(SMBCLIENT_0.3.3)(64bit)libsmbclient.so.0(SMBCLIENT_0.4.0)(64bit)libsmbclient.so.0(SMBCLIENT_0.5.0)(64bit)libsmbclient.so.0(SMBCLIENT_0.6.0)(64bit)libsmbclient.so.0(SMBCLIENT_0.7.0)(64bit)libsmbclient0libsmbconf.so.0()(64bit)libsmbconf.so.0(SMBCONF_0.0.1)(64bit)libsmbconf0libsmbd-base-samba4.so()(64bit)libsmbd-base-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsmbd-shim-samba4.so()(64bit)libsmbd-shim-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsmbldap.so.2()(64bit)libsmbldap.so.2(SMBLDAP_0)(64bit)libsmbldap.so.2(SMBLDAP_1)(64bit)libsmbldap.so.2(SMBLDAP_2)(64bit)libsmbldap.so.2(SMBLDAP_2.1.0)(64bit)libsmbldap2libsmbldaphelper-samba4.so()(64bit)libsmbldaphelper-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsocket-blocking-samba4.so()(64bit)libsocket-blocking-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libstable-sort-samba4.so()(64bit)libstable-sort-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsys-rw-samba4.so()(64bit)libsys-rw-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libtalloc-report-printf-samba4.so()(64bit)libtalloc-report-printf-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libtdb-wrap-samba4.so()(64bit)libtdb-wrap-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libtevent-util.so.0()(64bit)libtevent-util.so.0(TEVENT_UTIL_0.0.1)(64bit)libtevent-util0libtime-basic-samba4.so()(64bit)libtime-basic-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libtrusts-util-samba4.so()(64bit)libtrusts-util-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libutil-reg-samba4.so()(64bit)libutil-reg-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libutil-setid-samba4.so()(64bit)libutil-setid-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libutil-tdb-samba4.so()(64bit)libutil-tdb-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libwbclient.so.0()(64bit)libwbclient.so.0(WBCLIENT_0.10)(64bit)libwbclient.so.0(WBCLIENT_0.11)(64bit)libwbclient.so.0(WBCLIENT_0.12)(64bit)libwbclient.so.0(WBCLIENT_0.13)(64bit)libwbclient.so.0(WBCLIENT_0.14)(64bit)libwbclient.so.0(WBCLIENT_0.15)(64bit)libwbclient.so.0(WBCLIENT_0.16)(64bit)libwbclient.so.0(WBCLIENT_0.9)(64bit)libwbclient0samba-client-libssamba-client-libs(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    /sbin/ldconfig/sbin/ldconfigld-linux-x86-64.so.2()(64bit)ld-linux-x86-64.so.2(GLIBC_2.3)(64bit)libCHARSET3-samba4.so()(64bit)libCHARSET3-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libMESSAGING-SEND-samba4.so()(64bit)libMESSAGING-SEND-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libMESSAGING-samba4.so()(64bit)libMESSAGING-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libacl.so.1()(64bit)libacl.so.1(ACL_1.0)(64bit)libaddns-samba4.so()(64bit)libaddns-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libads-samba4.so()(64bit)libads-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libasn1util-samba4.so()(64bit)libasn1util-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libauth-samba4.so()(64bit)libauth-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libauthkrb5-samba4.so()(64bit)libauthkrb5-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libavahi-client.so.3()(64bit)libavahi-common.so.3()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.10)(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.15)(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.27)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.2)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.32)(64bit)libc.so.6(GLIBC_2.33)(64bit)libc.so.6(GLIBC_2.34)(64bit)libc.so.6(GLIBC_2.38)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.5)(64bit)libc.so.6(GLIBC_2.6)(64bit)libc.so.6(GLIBC_2.8)(64bit)libcli-cldap-samba4.so()(64bit)libcli-cldap-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libcli-ldap-common-samba4.so()(64bit)libcli-ldap-common-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libcli-ldap-samba4.so()(64bit)libcli-ldap-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libcli-nbt-samba4.so()(64bit)libcli-nbt-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libcli-smb-common-samba4.so()(64bit)libcli-smb-common-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libcli-spoolss-samba4.so()(64bit)libcli-spoolss-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libcliauth-samba4.so()(64bit)libcliauth-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libclidns-samba4.so()(64bit)libclidns-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libcluster-samba4.so()(64bit)libcluster-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libcom_err.so.2()(64bit)libcommon-auth-samba4.so()(64bit)libcommon-auth-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libdbwrap-samba4.so()(64bit)libdbwrap-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libdcerpc-binding.so.0()(64bit)libdcerpc-binding.so.0(DCERPC_BINDING_0.0.1)(64bit)libdcerpc-pkt-auth-samba4.so()(64bit)libdcerpc-pkt-auth-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libdcerpc-samba-samba4.so()(64bit)libdcerpc-samba-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libdcerpc.so.0()(64bit)libdcerpc.so.0(DCERPC_0.0.1)(64bit)libflag-mapping-samba4.so()(64bit)libflag-mapping-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libgenrand-samba4.so()(64bit)libgenrand-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libgensec-samba4.so()(64bit)libgensec-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libgnutls.so.30()(64bit)libgnutls.so.30(GNUTLS_3_4)(64bit)libgnutls.so.30(GNUTLS_3_6_10)(64bit)libgnutls.so.30(GNUTLS_3_6_13)(64bit)libgnutls.so.30(GNUTLS_3_6_3)(64bit)libgse-samba4.so()(64bit)libgse-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libgssapi_krb5.so.2()(64bit)libgssapi_krb5.so.2(gssapi_krb5_2_MIT)(64bit)libhttp-samba4.so()(64bit)libhttp-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libinterfaces-samba4.so()(64bit)libinterfaces-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libiov-buf-samba4.so()(64bit)libiov-buf-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libk5crypto.so.3()(64bit)libk5crypto.so.3(k5crypto_3_MIT)(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libkrb5samba-samba4.so()(64bit)libkrb5samba-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)liblber-2.4.so.2()(64bit)libldap_r-2.4.so.2()(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libldb.so.2(LDB_0.9.15)(64bit)libldb.so.2(LDB_0.9.16)(64bit)libldb.so.2(LDB_0.9.23)(64bit)libldb.so.2(LDB_1.1.1)(64bit)libldb.so.2(LDB_1.1.19)(64bit)libldb.so.2(LDB_1.1.30)(64bit)libldb.so.2(LDB_1.3.0)(64bit)libldb.so.2(LDB_2.6.1)(64bit)libldb.so.2(LDB_2.8.0)(64bit)libldbsamba-samba4.so()(64bit)libldbsamba-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)liblibcli-lsa3-samba4.so()(64bit)liblibcli-lsa3-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)liblibcli-netlogon3-samba4.so()(64bit)liblibcli-netlogon3-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)liblibsmb-samba4.so()(64bit)liblibsmb-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libmessages-dgm-samba4.so()(64bit)libmessages-dgm-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libmessages-util-samba4.so()(64bit)libmessages-util-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libmsghdr-samba4.so()(64bit)libmsghdr-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libmsrpc3-samba4.so()(64bit)libmsrpc3-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-samba-samba4.so()(64bit)libndr-samba-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libndr-samba4.so()(64bit)libndr-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libndr-standard.so.0()(64bit)libndr-standard.so.0(NDR_STANDARD_0.0.1)(64bit)libndr.so.3()(64bit)libndr.so.3(NDR_0.0.1)(64bit)libndr.so.3(NDR_0.0.3)(64bit)libndr.so.3(NDR_0.0.4)(64bit)libndr.so.3(NDR_0.0.5)(64bit)libndr.so.3(NDR_0.0.6)(64bit)libndr.so.3(NDR_0.0.7)(64bit)libndr.so.3(NDR_0.0.8)(64bit)libndr.so.3(NDR_0.0.9)(64bit)libndr.so.3(NDR_0.1.1)(64bit)libndr.so.3(NDR_0.1.2)(64bit)libndr.so.3(NDR_0.2.0)(64bit)libndr.so.3(NDR_0.2.1)(64bit)libndr.so.3(NDR_1.0.0)(64bit)libndr.so.3(NDR_1.0.1)(64bit)libndr.so.3(NDR_1.0.2)(64bit)libndr.so.3(NDR_2.0.0)(64bit)libndr.so.3(NDR_3.0.1)(64bit)libnetif-samba4.so()(64bit)libnetif-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libnpa-tstream-samba4.so()(64bit)libnpa-tstream-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libnscd.so.1()(64bit)libnscd.so.1(LIBNSCD_1.0)(64bit)libpam.so.0()(64bit)libpam.so.0(LIBPAM_1.0)(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libreplace-samba4.so()(64bit)libreplace-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsamba-cluster-support-samba4.so()(64bit)libsamba-cluster-support-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsamba-credentials.so.1()(64bit)libsamba-credentials.so.1(SAMBA_CREDENTIALS_1.0.0)(64bit)libsamba-debug-samba4.so()(64bit)libsamba-debug-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsamba-errors.so.1()(64bit)libsamba-errors.so.1(SAMBA_ERRORS_1.0.0)(64bit)libsamba-hostconfig.so.0()(64bit)libsamba-hostconfig.so.0(SAMBA_HOSTCONFIG_0.0.1)(64bit)libsamba-modules-samba4.so()(64bit)libsamba-modules-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsamba-passdb.so.0()(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.2.0)(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.27.1)(64bit)libsamba-security-samba4.so()(64bit)libsamba-security-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsamba-sockets-samba4.so()(64bit)libsamba-sockets-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsamba-util.so.0()(64bit)libsamba-util.so.0(SAMBA_UTIL_0.0.1)(64bit)libsamba3-util-samba4.so()(64bit)libsamba3-util-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsamdb-common-samba4.so()(64bit)libsamdb-common-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsamdb.so.0()(64bit)libsamdb.so.0(SAMDB_0.0.1)(64bit)libsecrets3-samba4.so()(64bit)libsecrets3-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libserver-id-db-samba4.so()(64bit)libserver-id-db-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libserver-role-samba4.so()(64bit)libserver-role-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsmb-transport-samba4.so()(64bit)libsmb-transport-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsmbclient-raw-samba4.so()(64bit)libsmbclient-raw-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsmbconf.so.0()(64bit)libsmbconf.so.0(SMBCONF_0.0.1)(64bit)libsmbd-shim-samba4.so()(64bit)libsmbd-shim-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsmbldap.so.2()(64bit)libsmbldap.so.2(SMBLDAP_0)(64bit)libsmbldap.so.2(SMBLDAP_1)(64bit)libsmbldaphelper-samba4.so()(64bit)libsmbldaphelper-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsocket-blocking-samba4.so()(64bit)libsocket-blocking-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libstable-sort-samba4.so()(64bit)libstable-sort-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsys-rw-samba4.so()(64bit)libsys-rw-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsystemd.so.0()(64bit)libsystemd.so.0(LIBSYSTEMD_209)(64bit)libtalloc-report-printf-samba4.so()(64bit)libtalloc-report-printf-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtalloc.so.2(TALLOC_2.1.0)(64bit)libtalloc.so.2(TALLOC_2.3.5)(64bit)libtasn1.so.6()(64bit)libtasn1.so.6(LIBTASN1_0_3)(64bit)libtdb-wrap-samba4.so()(64bit)libtdb-wrap-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtdb.so.1(TDB_1.2.2)(64bit)libtdb.so.1(TDB_1.2.5)(64bit)libtdb.so.1(TDB_1.3.0)(64bit)libtdb.so.1(TDB_1.3.11)(64bit)libtdb.so.1(TDB_1.3.17)(64bit)libtevent-util.so.0()(64bit)libtevent-util.so.0(TEVENT_UTIL_0.0.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.11.0)(64bit)libtevent.so.0(TEVENT_0.12.0)(64bit)libtevent.so.0(TEVENT_0.13.0)(64bit)libtevent.so.0(TEVENT_0.15.0)(64bit)libtevent.so.0(TEVENT_0.9.12)(64bit)libtevent.so.0(TEVENT_0.9.13)(64bit)libtevent.so.0(TEVENT_0.9.16)(64bit)libtevent.so.0(TEVENT_0.9.20)(64bit)libtevent.so.0(TEVENT_0.9.30)(64bit)libtevent.so.0(TEVENT_0.9.31)(64bit)libtevent.so.0(TEVENT_0.9.37)(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libtime-basic-samba4.so()(64bit)libtime-basic-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libtrusts-util-samba4.so()(64bit)libtrusts-util-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libutil-reg-samba4.so()(64bit)libutil-reg-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libutil-setid-samba4.so()(64bit)libutil-setid-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libutil-tdb-samba4.so()(64bit)libutil-tdb-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libwbclient.so.0()(64bit)libwbclient.so.0(WBCLIENT_0.13)(64bit)libwbclient.so.0(WBCLIENT_0.9)(64bit)libz.so.1()(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-14.14.3hҋhm@g`@gRgR@gMgp@fٝ@fxfteԔ@ee5@ede6`@e-%e'e%anopower@suse.comscabrero@suse.denopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comddiss@suse.comscabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comdmulder@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comscabrero@suse.dedmulder@suse.comscabrero@suse.denopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedimstar@opensuse.orgscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.denopower@suse.comscabrero@suse.deddiss@suse.comddiss@suse.comddiss@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comscabrero@suse.descabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comdmulder@suse.comscabrero@suse.denopower@suse.comddiss@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comddiss@suse.comddiss@suse.comnopower@suse.comnopower@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comddiss@suse.comscabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comjengelh@inai.dedmulder@suse.comscabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comdmulder@suse.comdmulder@suse.comjmcdonough@suse.comdmulder@suse.comscabrero@suse.dedmulder@suse.comscabrero@suse.dedmulder@suse.comdmulder@suse.comvcizek@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.dejmcdonough@suse.comscabrero@suse.deaaptel@suse.comjengelh@inai.dedimstar@opensuse.orgdmulder@suse.comjmcdonough@suse.comdavid.mulder@suse.comjmcdonough@suse.comaaptel@suse.comdmulder@suse.comscabrero@suse.comscabrero@suse.comkukuk@suse.dedavid.mulder@suse.comscabrero@suse.comrbrown@suse.comdmulder@suse.comscabrero@suse.comdimstar@opensuse.orgscabrero@suse.comaaptel@suse.comnopower@suse.comnopower@suse.comaaptel@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comddiss@suse.comnopower@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comdmulder@suse.comnopower@suse.comjmcdonough@suse.comaaptel@suse.comkukuk@suse.comkukuk@suse.denopower@suse.comaaptel@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comddiss@suse.comjmcdonough@suse.comddiss@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comtchvatal@suse.comlmuelle@suse.comnopower@suse.comcrrodriguez@opensuse.orglmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnoel.power@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.commpluskal@suse.comlmuelle@suse.comnopower@suse.deddiss@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.denopower@suse.delmuelle@suse.comnopower@suse.deddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.com- CVE-2025-9640: fix vfs_streams_xattr uninitialized memory write; (bsc#1251279);(bso#15885). - CVE-2025-10230: fix command Injection in WINS Server Hook Script; (bsc#1251280);(bso#15903).- Windows security hardening locks out schannel'ed netlogon dc calls like netr_DsRGetDCName; (bsc#1246431); (bso#15876).- Fix Samba printers reporting invalid sid during print jobs; (bsc#1234210); (bso#15792).- Fix crossing automounter mount points; (bsc#1215212); (bsc#1236803);- Update shipped /etc/samba/smb.conf to point to smb.conf man page;(bsc#1233880).- Update to 4.19.9 * libldb: performance issue with indexes (ldb 2.8.2 is already released); (bso#15590). * DH reconnect error handling can lead to stale sharemode entries; (bso#15624). * Incorrect FSCTL_QUERY_ALLOCATED_RANGES response when truncated; (bso#15699). * irpc_destructor may crash during shutdown; (bso#15280). * Compound SMB2 requests don't return NT_STATUS_NETWORK_SESSION_EXPIRED for all requests, confuses MacOSX clients; (bso#15696). * Crash when readlinkat fails; (bso#15700).- Adjust spec to split out rpcd_* binaries into a separate sub package; (bsc#1231414).- Incorrect FSCTL_QUERY_ALLOCATED_RANGES response when truncated; (bso#15699); (bsc#1229684). - Update to 4.19.8 * Invalid client warning about command line passwords; (bso#15671); * Version string is truncated in manpages; (bso#15672); * --version-* options are still not ergonomic, and they reject tilde characters; (bso#15673); * cmdline_burn does not always burn secrets; (bso#15674); * Samba doesn't parse SDDL found in defaultSecurityDescriptor in AD_DS_Classes_Windows_Server_v1903.ldf; (bso#15685); * We have added new options --vendor-name and --vendor-patch- revision arguments to ./configure to allow distributions and packagers to put their name in the Samba version string so that when debugging Samba the source of the binary is obvious; (bso#15654); * When claims enabled with heimdal kerberos, unable to log on to a Windows computer when user account need to change their own password; (bso#15655); * Fix clock skew error message and memory cache clock skew recovery; (bso#15676); * CTDB RADOS mutex helper misses namespace support; (bso#15665); * The images don't build after the git security release and CentOS 8 Stream is EOL; (bso#15660); * Fix unnecessary delays in CTDB while processing requests under high load; (bso#15678); * Dynamic DNS updates with the internal DNS are not working; (bso#13019); * s4:nbt_server: does not provide unexpected handling, so winbindd can't use nmb requests instead cldap; (bso#15620); * Panic in vfs_offload_token_db_fetch_fsp(); (bso#15664); * "client use kerberos" and --use-kerberos is ignored for the machine account; (bso#15666); * Regression DFS not working with widelinks = true; (bso#15435); * ntlm_auth make logs more consistent with length check; (bso#15677);- Fix a crash when joining offline and 'kerberos method' includes keytab; (bsc#1228732); - Fix reading the password from STDIN or environment vars if it was already given in the command line; (bsc#1228732);- Update to 4.19.7 * ldb qsort might r/w out of bounds with an intransitive compare function (ldb 2.8.1 is already released); (bso#15569). * Many qsort() comparison functions are non-transitive, which can lead to out-of-bounds access in some circumstances (ldb 2.8.1 is already released); (bso#15625). * Need to change gitlab-ci.yml tags in all branches to avoid CI bill; (bso#15638). * netr_LogonSamLogonEx returns NR_STATUS_ACCESS_DENIED with SysvolReady=0; (bso#14981). * Anonymous smb3 signing/encryption should be allowed (similar to Windows Server 2022); (bso#15412). * Panic in dreplsrv_op_pull_source_apply_changes_trigger; (bso#15573). * winbindd, net ads join and other things don't work on an ipv6 only host; (bso#15642). * Smbcacls incorrectly propagates inheritance with Inherit-Only flag; (bso#15636). * http library doesn't support 'chunked transfer encoding'; (bso#15611). - Update to 4.19.6 * fd_handle_destructor() panics within an smbd_smb2_close() if vfs_stat_fsp() fails in fd_close(); (bso#15527). * samba-gpupdate: Correctly implement site support; (bso#15588). * libgpo: Segfault in python bindings; (bso#15599). * Packet marshalling push support missing for CTDB_CONTROL_TCP_CLIENT_DISCONNECTED and CTDB_CONTROL_TCP_CLIENT_PASSED; (bso#15580).- Update to 4.19.5 * Windows 2016 fails to restore previous version of a file from a shadow_copy2 snapshot; (bso#13688). * Symlinks on AIX are broken in 4.19 (and a few version before that); (bso#15549). * Fake directory create times has no effect; (bso#12421). * ctime mixed up with mtime by smbd; (bso#15550). * samba-gpupdate --rsop fails if machine is not in a site; (bso#15548). * gpupdate: The root cert import when NDES is not available is broken; (bso#15557). * samba-gpupdate should print a useful message if cepces-submit can't be found; (bso#15552). * samba-gpupdate logging doesn't work; (bso#15558). * smbpasswd reset permissions only if not 0600; (bso#15555).- Remove -x from bash shebang update-apparmor-samba-profile; (bsc#1218431).- Update to 4.19.4 * net changesecretpw cannot set the machine account password if secrets.tdb is empty; (bso#13577). * For generating doc, take, if defined, env XML_CATALOG_FILES; (bso#15540). * Trivial C typo in nsswitch/winbind_nss_netbsd.c; (bso#15541). * vfs_linux_xfs is incorrectly named; (bso#15542). * systemd stumbled over copyright-message at smbd startup; (bso#15377). * Following intermediate abolute share-local symlinks is broken; (bso#15505). * ctdb RELEASE_IP causes a crash in release_ip if a connection to a non-public address disconnects first; (bso#15523). * shadow_copy2 broken when current fileset's directories are removed; (bso#15544). * smbd does not detect ctdb public ipv6 addresses for multichannel exclusion; (bso#15534). * 'force user = localunixuser' doesn't work if 'allow trusted domains = no' is set; (bso#15469). * smbget debug logging doesn't work; (bso#15525). * smget: username in the smburl and interactive password entry doesn't work; (bso#15532). * smbget auth function doesn't set values for password prompt correctly; (bso#15538). * Unable to copy and write files from clients to Ceph cluster via SMB Linux gateway with Ceph VFS module; (bso#15440). * Multichannel refresh network information; (bso#15547).- Update to 4.19.3 * sid_strings test broken by unix epoch > 1700000000; (bso#15520). * smbd crashes if asked to return full information on close of a stream handle with delete on close disposition set; (bso#15487). * smbd: fix close order of base_fsp and stream_fsp in smb_fname_fsp_destructor(); (bso#15521). * Improve logging for failover scenarios; (bso#15499). * Files without "read attributes" NFS4 ACL permission are not listed in directories; (bso#15093). * CVE-2018-14628 [SECURITY] Deleted Object tombstones visible in AD LDAP to normal users; (bso#13595). * Kerberos TGS-REQ with User2User does not work for normal accounts; (bso#15492). * vfs_gpfs stat calls fail due to file system permissions; (bso#15507). * Samba doesn't build with Python 3.12; (bso#15513).- packaging: samba-tool domain provision requires python3-Markdown; (bsc#1216519).- Update to 4.19.2 * Use-after-free in aio_del_req_from_fsp during smbd shutdown after failed IPC FSCTL_PIPE_TRANSCEIVE; (bso#15423). * clidfs.c do_connect() missing a "return" after a cli_shutdown() call; (bso#15426). * macOS mdfind returns only 50 results; (bso#15463). * GETREALFILENAME_CACHE can modify incoming new filename with previous cache entry value; (bso#15481). * libnss_winbind causes memory corruption since samba-4.18, impacts sendmail, zabbix, potentially more; (bso#15464). * ctdbd: setproctitle not initialized messages flooding logs; (bso#15479). * CVE-2023-5568 Heap buffer overflow with freshness tokens in the Heimdal KDC in Samba 4.19; (bso#15491). * The heimdal KDC doesn't detect s4u2self correctly when fast is in use; (bso#15477).- use systemd-logind rather than utmp for y2038 safety; (bsc#1216159).- CVE-2023-4091: samba: Client can truncate file with read-only permissions; (bsc#1215904); (bso#15439). - CVE-2023-42669: samba: rpcecho, enabled and running in AD DC, allows blocking sleep on request; (bso#1215905); (bso#15474). - CVE-2023-42670: samba: The procedure number is out of range when starting Active Directory Users and Computers; (bsc#1215906); (bso#15473). - CVE-2023-3961: samba: Unsanitized client pipe name passed to local_np_connect(); (bsc#1215907); (bso#15422). - CVE-2023-4154: samba: dirsync allows SYSTEM access with only "GUID_DRS_GET_CHANGES" right, not "GUID_DRS_GET_ALL_CHANGES; (bsc#1215908); (bso#15424).- Update to 4.19.0 * File doesn't show when user doesn't have permission if aio_pthread is loaded; (bso#15453). * ctdb_killtcp fails to work with --enable-pcap and libpcap ≥ 1.9.1; (bso#15451). * Logging to stdout/stderr with DEBUG_SYSLOG_FORMAT_ALWAYS can log to syslog; (bso#15460). * ‘samba-tool domain level raise’ fails unless given a URL; (bso#15458). * reply_sesssetup_and_X() can dereference uninitialized tmp pointer; (bso#15420). * missing return in reply_exit_done(); (bso#15430). * TREE_CONNECT without SETUP causes smbd to use uninitialized pointer; (bso#15432). * Avoid infinite loop in initial user sync with Azure AD Connect when synchronising a large Samba AD domain; (bso#15401). * Samba replication logs show (null) DN; (bso#15407). * 2-3min delays at reconnect with smb2_validate_sequence_number: bad message_id 2; (bso#15346). * DCERPC_PKT_CO_CANCEL and DCERPC_PKT_ORPHANED can't be parsed; (bso#15446). * CID 1539212 causes real issue when output contains only newlines; (bso#15438). * KDC encodes INT64 claims incorrectly; (bso#15452). * mdssvc: Do an early talloc_free() in _mdssvc_open(); (bso#15449). * Windows client join fails if a second container CN=System exists somewhere; (bso#9959). * regression DFS not working with widelinks = true; (bso#15435). * Heimdal fails to build on 32-bit FreeBSD; (bso#15443). * samba-tool ntacl get segfault if aio_pthread appended; (bso#15441). - Update to 4.18.6 * reply_sesssetup_and_X() can dereference uninitialized tmp pointer; (bso#15420); * Missing return in reply_exit_done(); (bso#15430); * post-exec password redaction for samba-tool is more reliable for fully random passwords as it no longer uses regular expressions containing the password value itself; (bso#15289); * Windows client join fails if a second container CN=System exists somewhere; (bso#9959); * Spotlight sometimes returns no results on latest macOS; (bso#15342); * Renaming results in NT_STATUS_SHARING_VIOLATION if previously attempted to remove the destination; (bso#15417); * Spotlight results return wrong date in result list; (bso#15427); * "net offlinejoin provision" does not work as non-root user; (bso#15414); * rpcserver no longer accepts double backslash in dfs pathname; (bso#15400); * cm_prepare_connection() calls close(fd) for the second time; (bso#15433); * 2-3min delays at reconnect with smb2_validate_sequence_number: bad message_id 2; (bso#15346); * samba-tool ntacl get segfault if aio_pthread appended; (bso#15441); * DCERPC_PKT_CO_CANCEL and DCERPC_PKT_ORPHANED can't be parsed; (bso#15446); * Python tarfile extraction needs change to avoid a warning (CVE-2007-4559 mitigation); (bso#15390); * Regression DFS not working with widelinks = true; (bso#15435); * mdssvc: Do an early talloc_free() in _mdssvc_open(); (bso#15449); - Update to 4.18.5 * CVE-2022-2127: lm_resp_len not checked properly in winbindd_pam_auth_crap_send; (bso#15072); (bsc#1213174). * CVE-2023-34966: Samba Spotlight mdssvc RPC Request Infinite Loop Denial-of-Service Vulnerability; (bso#15340); (bsc#1213173). * CVE-2023-34967: Samba Spotlight mdssvc RPC Request Type Confusion Denial-of-Service Vulnerability; (bso#15341); (bsc#1213172). * CVE-2023-34968: Spotlight server-side Share Path Disclosure; (bso#15388); (bsc#1213171). * CVE-2023-3347: Samba doesn't require SMB2+ signing if `server signing = mandatory` is set; (bso#15397); (bsc#1213170). * secure channel faulty since Windows 10/11 update 07/2023; (bso#15418); (bsc#1213384). - Update to 4.18.4 * Backport --pidl-developer fixes; (bso#15404). * Named crashes on DLZ zone update; (bso#14030). * smbcacls and smbcquotas do not check // before the server; (bso#2312). * cli_list loops 100% CPU against pre-lanman2 servers; (bso#15382). * smbclient leaks fds with showacls; (bso#15391). * smbd returns NOT_FOUND when creating files on a r/o filesystem; (bso#15402). * NSS_WRAPPER_HOSTNAME doesn't match NSS_WRAPPER_HOSTS entry and causes test timeouts; (bso#15355). * net ads lookup (with unspecified realm) fails; (bso#15384). * Register Samba processes with GPFS; (bso#15381). * Python tarfile extraction needs change to avoid a warning (CVE-2007-4559 mitigation); (bso#15390). * The winbind child segfaults when listing users with `winbind scan trusted domains = yes`; (bso#15398). * Remove comments about deprecated 'write cache size'; (bso#15383). * smbget memory leak if failed to download files recursively; (bso#15403). - Update to 4.18.3 * Symlinks to files can have random DOS mode information in a directory listing; (bso#15375). * vfs_fruit might cause a failing open for delete; (bso#15378). * winbind recurses into itself via rpcd_lsad; (bso#15361). * wbinfo -u fails on ad dc with >1000 users; (bso#15366). * DS ACEs might be inherited to unrelated object classes; (bso#15338). * a lot of messages: get_static_share_mode_data: get_static_share_mode_data_fn failed: NT_STATUS_NOT_FOUND; (bso#15362). * aes256 smb3 encryption algorithms are not allowed in smb3_sid_parse(); (bso#15374). * Setting veto files = /.*/ break listing directories; (bso#15360). * "samba-tool domain provision" does not run interactive mode if no arguments are given; (bso#15363). * dsgetdcname: assumes local system uses IPv4; (bso#15325). - Update to 4.18.2 * Log flood: smbd_calculate_access_mask_fsp: Access denied: message level should be lower; (bso#15302). * Floating point exception (FPE) via cli_pull_send at source3/libsmb/clireadwrite.c; (bso#15306). * test_tstream_more_tcp_user_timeout_spin fails intermittently on Rackspace GitLab runners; (bso#15328). * Reduce flapping of ridalloc test; (bso#15329). * large_ldap test is unreliable; (bso#15351). * New filename parser doesn't check veto files smb.conf parameter; (bso#15143). * mdssvc may crash when initializing; (bso#15354). * large directory optimization broken for non-lcomp path elements; (bso#15313). * streams_depot fails to create streams; (bso#15357). * shadow_copy2 and streams_depot don't play well together; (bso#15358). * Flapping tests in samba_tool_drs_show_repl.py; (bso#15316). * winbindd idmap child contacts the domain controller without a need; (bso#15317). * idmap_autorid may fail to map sids of trusted domains for the first time; (bso#15318). * idmap_hash doesn't use ID_TYPE_BOTH for reverse mappings; (bso#15319). * net ads search -P doesn't work against servers in other domains; (bso#15323). * Temporary smbXsrv_tcon_global.tdb can't be parsed; (bso#15353). * Tests use depricated and removed methods like assertRegexpMatches; (bso#15343). - Update to 4.18.1 * CVE-2023-0225: AD DC "dnsHostname" attribute can be deleted by unprivileged authenticated users. (bso#15276);(bsc#1209483). * CVE-2023-0614: Access controlled AD LDAP attributes can be discovered (bso#15270); (bsc#1209485). * CVE-2023-0922: Samba AD DC admin tool samba-tool sends passwords in cleartext(bso#15315);(bsc#1209481). * ldb wildcard matching makes excessive allocations; (bso#15331). * large_ldap test is inefficient; (bso#15332). - Update to 4.18.0 * SMB server performance improvements * More succinct samba-tool error messages * Color output with samba-tool --color The NO_COLOR environment variable will disable colour output * New samba-tool dsacl subcommand for deleting ACEs * New wbinfo option --change-secret-at * Net option to change the NT ACL default location * Azure AD / Office365 synchronization improvements- Fix DFS not working with widelinks enabled; (bsc#1213607); (bso#15435);- Move libcluster-samba4.so from samba-libs to samba-client-libs; (bsc#1213940);- net ads lookup with unspecified realm fails; (bso#15384); (bsc#1213826);- secure channel faulty since Windows 10/11 update 07/2023; (bso#15418); (bsc#1213384).- CVE-2022-2127: lm_resp_len not checked properly in winbindd_pam_auth_crap_send; (bso#15072); (bsc#1213174). - CVE-2023-34966: Samba Spotlight mdssvc RPC Request Infinite Loop Denial-of-Service Vulnerability; (bso#15340); (bsc#1213173). - CVE-2023-34967: Samba Spotlight mdssvc RPC Request Type Confusion Denial-of-Service Vulnerability; (bso#15341); (bsc#1213172). - CVE-2023-34968: Spotlight server-side Share Path Disclosure; (bso#15388); (bsc#1213171). - CVE-2023-3347: Samba doesn't require SMB2+ signing if `server signing = mandatory` is set; (bso#15397); (bsc#1213170).- Update to 4.17.9 * Backport --pidl-developer fixes; (bso#15404). * smbd_scavenger crashes when service smbd is stopped; (bso#15275). * vfs_fruit might cause a failing open for delete; (bso#15378). * named crashes on DLZ zone update; (bso#14030). * winbind recurses into itself via rpcd_lsad; (bso#15361). * cli_list loops 100% CPU against pre-lanman2 servers; (bso#15382). * smbclient leaks fds with showacls; (bso#15391). * aes256 smb3 encryption algorithms are not allowed in smb3_sid_parse(); (bso#15374). * winbindd gets stuck on NT_STATUS_RPC_SEC_PKG_ERROR; (bso#15413). * smbget memory leak if failed to download files recursively; (bso#15403).- Update to 4.17.8 * log flood: smbd_calculate_access_mask_fsp: Access denied: message level should be lower; (bso#15302). * Floating point exception (FPE) via cli_pull_send at source3/libsmb/clireadwrite.c; (bso#15306). * test_tstream_more_tcp_user_timeout_spin fails intermittently on Rackspace GitLab runners; (bso#15328). * Reduce flapping of ridalloc test; (bso#15329). * large_ldap test is unreliable; (bso#15351). * New filename parser doesn't check veto files smb.conf parameter; (bso#15143). * mdssvc may crash when initializing; (bso#15354). * Large directory optimization broken for non-lcomp path elements; (bso#15313). * streams_depot fails to create streams; (bso#15357). * shadow_copy2 and streams_depot don't play well together; (bso#15358). * wbinfo -u fails on ad dc with >1000 users; (bso#15366). * winbindd idmap child contacts the domain controller without a need; (bso#15317). * idmap_autorid may fail to map sids of trusted domains for the first time; (bso#15318). * idmap_hash doesn't use ID_TYPE_BOTH for reverse mappings; (bso#15319). * net ads search -P doesn't work against servers in other domains; (bso#15323). * DS ACEs might be inherited to unrelated object classes; (bso#15338). * Temporary smbXsrv_tcon_global.tdb can't be parsed; (bso#15353). * Setting veto files = /.*/ break listing directories; (bso#15360); (bsc#1212375). * CVE-2020-25720 [SECURITY] Create Child permission should not allow full write to all attributes (additional changes); (bso#14810). * dsgetdcname: assumes local system uses IPv4; (bso#15325).- Update to 4.17.7 * CVE-2023-0922: Samba AD DC admin tool samba-tool sends passwords in cleartext; (bso#15315); (bsc#1209481). * CVE-2023-0225: Samba AD DC "dnsHostname" attribute can be deleted by unprivileged authenticated users; (bso#15276); (bsc#1209483). * CVE-2023-0614: samba: Access controlled AD LDAP attributes can be discovered; (bso#15270); (bsc#1209485). * large_ldap test is inefficient; (bso#15332). * CVE-2020-25720 [SECURITY] Create Child permission should not allow full write to all attributes (additional changes); (bso#14810). - Update to 4.17.6 * streams_xattr is creating unexpected locks on folders; (bso#15314). * Use of the Azure AD Connect cloud sync tool is now supported for password hash synchronisation, allowing Samba AD Domains to synchronise passwords with this popular cloud environment; (bso#10635). * Spotlight doesn't work with latest macOS Ventura; (bso#15299). * New samba-dcerpc architecture does not scale gracefully; (bso#15310). * vfs_ceph incorrectly uses fsp_get_io_fd() instead of fsp_get_pathref_fd() in close and fstat; (bso#15307). * With clustering enabled samba-bgqd can core dump due to use after free; (bso#15293). * fd_load() function implicitly closes the fd where it should not; (bso#15311). - Update to 4.17.5 * smbc_getxattr() return value is incorrect; (bso#14808). * Compound SMB2 FLUSH+CLOSE requests from MacOSX are not handled correctly; (bso#15172). * synthetic_pathref AFP_AfpInfo failed errors; (bso#15210). * samba-tool gpo listall fails IPv6 only - finddcs() fails to find DC when there is only an AAAA record for the DC in DNS; (bso#15226). * smbd crashes if an FSCTL request is done on a stream handle; (bso#15236). * DFS links don't work anymore on Mac clients since 4.17; (bso#15277). * vfs_virusfilter segfault on access, directory edgecase (accessing NULL value); (bso#15283). * CVE-2022-38023 [SECURITY] Samba should refuse RC4 (aka md5) based SChannel on NETLOGON (additional changes); (bso#15240). * %U for include directive doesn't work for share listing (netshareenum); (bso#15243). * Shares missing from netshareenum response in samba 4.17.4; (bso#15266). * ctdb: use-after-free in run_proc; (bso#15269). * irpc_destructor may crash during shutdown; (bso#15280). * auth3_generate_session_info_pac leaks wbcAuthUserInfo; (bso#15286). * smbclient segfaults with use after free on an optimized build; (bso#15268). * smbstatus leaking files in msg.sock and msg.lock; (bso#15282). * Leak in wbcCtxPingDc2; (bso#15164). * Access based share enum does not work in Samba 4.16+; (bso#15265). * Crash during share enumeration; (bso#15267). * rep_listxattr on FreeBSD does not properly check for reads off end of returned buffer; (bso#15271). * Avoid relying on C89 features in a few places; (bso#15281).- Make (32bit) samba-libs conflict with old samba-ad-dc-libs package to satisfy installcheck.- Make samba-libs conflict with old samba-ad-dc-libs package to satisfy installcheck.- Remove non functioning ifup/ifdown samba-winbindd scripts; (bsc#1207414).- libdsdb-module-samba4 should be packaged as part of samba-libs and not samba-ad-dc-libs. Additionally no need for it to be removed conditionally.- Clean up logic for PAM migration settings in spec file.- Change with_dc default to 0 (for non TW builds), ADDC feature is deprecated and will no longer be included in >= SLE15-SP5; (jsc#PED-1122).- Update to 4.17.4 * CVE-2022-44640 Upstream Heimdal free of user-controlled pointer in FAST; (bsc#14929); * CVE-2021-20251 Bad password count not incremented atomically; (bsc#14611); * CVE-2022-42898 krb5_pac_parse() buffer parsing vulnerability; (bsc#15203); * CVE-2022-37966 rc4-hmac Kerberos session keys issued to modern servers; (bso#15237); * CVE-2022-37967 Kerberos constrained delegation ticket forgery possible against Samba AD DC; (bso#15231); * CVE-2022-38023 RC4/HMAC-MD5 NetLogon Secure Channel is weak and should be avoided; (bso#15240); * pam_winbind uses time_t and pointers assuming they are of the same size; (bso#15224); * Heimdal session key selection in AS-REQ examines wrong entry; (bso#15219); * filter-subunit is inefficient with large numbers of knownfails; (bso#15258); * smbd allows setting FILE_ATTRIBUTE_TEMPORARY on directories; (bso#15252); * The KDC logic arround msDs-supportedEncryptionTypes differs from Windows; (bso#13135); * libnet: change_password() doesn't work with dcerpc_samr_ChangePasswordUser4(); (bso#15206); * Heimdal session key selection in AS-REQ examines wrong entry; (bso#15219); * Memory leak in snprintf replacement functions; (bso#15230); * RODC doesn't reset badPwdCount reliable via an RWDC (CVE-2021-20251 regression); (bso#15253); * Prevent EBADF errors with vfs_glusterfs; (bso#15198); * %U for include directive doesn't work for share listing (netshareenum); (bso#15243); * Stack smashing in net offlinejoin requestodj; (bso#15257); * Windows 11 22H2 and Samba-AD 4.15 Kerberos login issue; (bso#15197); * Heimdal session key selection in AS-REQ examines wrong entry; (bso#15219); - Remove deprecated if-{down,up} scripts; (bsc#1206444); - Adjust the systemd drop-in file for named service; (bsc#1201689); * Paths are additive so do not repeat paths from named.service * Prefix the samba DLZ directory with "-" to ignore this path if it does not exists- Introduce without-smb1-server spec flag; (bsc#1205104); - Update to 4.17.3 * CVE-2022-42898: Samba buffer overflow vulnerabilities on 32-bit systems; (bsc#1205126); (bso#15203); - Replace obsolete python-gpgme with python-gpg * Upstream replaced it in v4.9.5 -- bso#13728 - Update to 4.17.2 * CVE-2022-3592 [SECURITY] samba: Wide links protection broken; (bso#15207); (bsc#1204499). * CVE-2022-3437 [SECURITY] samba: Buffer overflow in Heimdal unwrap_des3();(bso#15134); (bsc#1204254). - Update to 4.17.1 * CVE-2021-20251 [SECURITY] Bad password count not incremented atomically; (bso#14611). * smbXsrv_connection_shutdown_send result leaked; (bso#15174). * Flush on a named stream never completes; (bso#15182). * Permission denied calling SMBC_getatr when file not exists; (bso#15195). * Samba 4.5 sometimes cannot be upgraded to Samba 4.6 or later over DRS: WERROR_DS_DRA_MISSING_PARENT due to faulty GET_ANC; (bso#15189). * pytest: add file removal helpers for TestCaseInTempDir; (bso#15191). * CVE-2021-20251 [SECURITY] Bad password count not incremented atomically; (bso#14611). * Samba 4.5 sometimes cannot be upgraded to Samba 4.6 or later over DRS: WERROR_DS_DRA_MISSING_PARENT due to faulty GET_ANC; (bso#15189). * Flush on a named stream never completes; (bso#15182). * vfs_gpfs silently garbles timestamps > year 2106; (bso#15151). * CVE-2021-20251 [SECURITY] Bad password count not incremented atomically; (bso#14611). * multi-channel socket passing may hit a race if one of the involved processes already existed; (bso#15200). * memory leak on temporary of struct imessaging_post_state and struct tevent_immediate on struct imessaging_context (in rpcd_spoolss and maybe others); (bso#15201). * Since popt1.19 various use after free errors using result of poptGetArg are now exposed; (bso#15205); (boo#1204279). * Remove special case for O_CREAT in SMB_VFS_OPENAT from vfs_glusterfs; (bso#15192). * GETPWSID in memory cache grows indefinetly with each NTLM auth; (bso#15169). * CVE-2021-20251 [SECURITY] Bad password count not incremented atomically; (bso#14611). - Install a systemd drop-in file for named service to allow read/write access to the DLZ directory; (bsc#1201689); - Fix use after free errors resulting from using return of poptGetArg exposed since popt-1.19; (boo#1204279); (bso#15205). - s3: smbd: Fix memory leak in smbd_server_connection_terminate_done(); (bso#15174). - Disable SMB1 for tumbleweed builds. - Update to 4.17.0 * acl_xattr VFS module may unintentionally use filesystem permissions instead of ACL from xattr; (bso#15126). * Missing SMB2-GETINFO access checks from MS-SMB2 3.3.5.20.1; (bso#15153). * assert failed: !is_named_stream(smb_fname)") at ../../lib/util/fault.c:197; (bso#15161). * acl_xattr VFS module may unintentionally use filesystem permissions instead of ACL from xattr; (bso#15126). * assert failed: !is_named_stream(smb_fname)") at ../../lib/util/fault.c:197; (bso#15161). * Cross-node multi-channel reconnects result in SMB2 Negotiate returning NT_STATUS_NOT_SUPPORTED; (bso#15159). * winbind at info level debug can coredump when processing wb_lookupusergroups; (bso#15160). * Make use of glfs_*at() API calls in vfs_glusterfs; (bso#15157). * Possible use after free of connection_struct when iterating smbd_server_connection->connections; (bso#15128). * `net usershare add` fails with flag works with --long but fails with -l; (bso#15145). * acl_xattr VFS module may unintentionally use filesystem permissions instead of ACL from xattr; (bso#15126). * Performance regression on contended path based operations; (bso#15125). * Missing READ_LEASE break could cause data corruption; (bso#15148). * libsamba-errors uses a wrong version number; (bso#15141). * SMB1 negotiation can fail to handle connection errors; (bso#15152). * New filename parser doesn't check veto files smb.conf parameter; (bso#15143). * 4.17.rc1 still uses symlink-race prone unix_convert(); (bso#15144). * Backport fileserver related changed to 4.17.0rc2; (bso#15146). * Manpage for smbstatus json is missing; (bso#15147). * Backport fileserver related changed to 4.17.0rc2; (bso#15146). * Performance regression on contended path based operations; (bso#15125). * Backport fileserver related changed to 4.17.0rc2; (bso#15146). * Fix issues found by coverity in smbstatus json code; (bso#15140). * Backport fileserver related changed to 4.17.0rc2; (bso#15146). - Migration to /usr/etc: Saving user changed configuration files in /etc and restoring them while an RPM update. - Update to 4.16.4 * CVE-2022-2031: Samba AD users can bypass certain restrictions associated with changing passwords; (bsc#1201495); (bso#15047); * CVE-2022-32744: Samba AD users can forge password change requests for any user; (bsc#1201493); (bso#15074); * CVE-2022-32745: Samba AD users can crash the server process with an LDAP add or modify request; (bsc#1201492); (bso#15008); * CVE-2022-32746: Samba AD users can induce a use-after-free in the server process with an LDAP add or modify request; (bsc#1201490); (bso#15009); * CVE-2022-32742: Server memory information leak via SMB1; (bsc#1201496); (bso#15085); - Update to 4.16.3 * Using vfs_streams_xattr and deleting a file causes a panic; (bso#15099); * Add support for bind 9.18; (bso#14986); * logging dsdb audit to specific files does not work; (bso#15076); * Problem when winbind renews Kerberos; (bso#14979); (bsc#1196224); * Samba with new lorikeet-heimdal fails to build on gcc 12.1 in developer mode; (bso#15095); * Crash in streams_xattr because fsp->base_fsp->fsp_name is NULL; (bso#15105); * Crash in rpcd_classic - NULL pointer deference in mangle_is_mangled(); (bso#15118); * smbclient commands del & deltree fail with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556); * Fix check for chown when processing NFSv4 ACL; (bso#15120); * The pcap background queue process should not be stopped; (bso#15082); * testparm: Fix typo in idmap rangesize check; (bso#15097); * net ads info returns LDAP server and LDAP server name as null; (bso#15106); * ldconfig: /lib64/libsmbconf.so.0 is not a symbolic link; (bso#15108); * CTDB child process logging does not work as expected; (bso#15090); - Update spec file to fix the optional Heimdal DC build - Fix external trusts with MIT Kerberos 1.20 - Add missing samba-client requirement to samba-winbind package; (bsc#1198255); - Move pdb backends from package samba-libs to package samba-client-libs and remove samba-libs requirement from samba-winbind; (bsc#1200964); (bsc#1198255); - Add sysuser-shadow requirement for packages using systemd-sysusers - Use the canonical realm name to refresh the Kerberos tickets; (bsc#1196224); (bso#14979); - Moved logrotate files from user specific directory /etc/logrotate.d to vendor specific directory /usr/etc/logrotate.d. - Update to 4.16.2 * Use pathref fd instead of io fd in vfs_default_durable_cookie; (bso#15042); * vfs_gpfs with vfs_shadowcopy2 fail to restore file if original file had been deleted; (bso#15069); * Reintroduce netgroups support; (bso#15087); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); * Update from 4.15 to 4.16 breaks discovery of [homes] on standalone server from Win and IOS; (bso#15062); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * smbclient -E doesn't work as advertised; (bso#15075); * The samba background daemon doesn't refresh the printcap cache on startup; (bso#15081); * Out-by-4 error in smbd read reply max_send clamp; (bso#14443); - Fix samba4.blackbox.net_ads_dns_async test with bind9 >= 9.17.7 - Support building with MIT Kerberos 1.20 - Bronze bit and S4U support with MIT Kerberos 1.20 for Samba AD DC; (CVE-2020-17049); - Resource Based Constrained Delegation (RBCD) for Samba AD DC - Support building with gcc 12.1 - Use requires_eq macro to require the libldb2 version available at samba-dsdb-modules build time; (bsc#1199362); - Update to 4.16.1 * Share and server swapped in smbget password prompt; (bso#14831); * Durable handles won't reconnect if the leased file is written to; (bso#15022); * rmdir silently fails if directory contains unreadable files and hide unreadable is yes; (bso#15023); * SMB2_CLOSE_FLAGS_FULL_INFORMATION fails to return information on renamed file handle; (bso#15038); * Need to describe --builtin-libraries= better (compare with - -bundled-libraries); (bso#8731); * vfs_shadow_copy2 breaks "smbd async dosmode" sync fallback; (bso#14957); * shadow_copy2 fails listing snapshotted dirs with shadow:fixinodes; (bso#15035); * PAM Kerberos authentication incorrectly fails with a clock skew error; (bso#15046); * Username map - samba erroneously applies unix group memberships to user account entries; (bso#15041); * KVNO off by 100000; (bso#14951); * Uninitialized litemask in variable in vfs_gpfs module; (bso#15027); * vfs_gpfs recalls=no option prevents listing files; (bso#15055); * smbd doesn't handle UPNs for looking up names; (bso#15054); - Update update-apparmor-samba-profile script, replace non-printable delimiter with more human readable separator as sed can accept separators that can appear in the input data. - Fix update-apparmor-samba-profile script, sed doesn't like multibyte separators; (bsc#1198309). - Update to 4.16.0 * New samba-dcerpcd binary to provide DCERPC in the member server setup * Certificate Auto Enrollment * Ability to add ports to dns forwarder addresses in internal DNS backend * No longer using Linux mandatory locks for sharemodes * SMB1 protocol has been deprecated, particularly older dialects * SMB1 protocol SMBCopy command removed * SMB1 server-side wildcard expansion removed - Add python3-dnspython to samba-ad-dc recommens; (bsc#1187101); - Use systemd-sysusers to create system users; (bsc#1182847);- Install a systemd drop-in file for named service to allow read/write access to the DLZ directory; (bsc#1201689);- Update to 4.15.12 * CVE-2022-42898: samba: heimdal: Samba buffer overflow vulnerabilities on 32-bit systems; (bso#15203); (bsc#1205126). - Update to 4.15.11 * Allow rebuild of Centos 8 images after move to vault for Samba 4.15; (bso#15193). * CVE-2022-3437: samba: Buffer overflow in Heimdal unwrap_des3(); (bso#15134); (bsc#1204254)- Update to 4.15.10 * Possible use after free of connection_struct when iterating smbd_server_connection->connections; (bso#15128); (bsc#1200102). * smbXsrv_connection_shutdown_send result leaked; (bso#15174). * Spotlight RPC service returns wrong response when Spotlight is disabled on a share; (bso#15086). * acl_xattr VFS module may unintentionally use filesystem permissions instead of ACL from xattr; (bso#15126). * Missing SMB2-GETINFO access checks from MS-SMB2 3.3.5.20.1; (bso#15153). * assert failed: !is_named_stream(smb_fname)") at ../../lib/util/fault.c:197; (bso#15161). * Missing READ_LEASE break could cause data corruption; (bso#15148). * rpcclient can crash using setuserinfo(2); (bso#15124). * Samba fails to build with glibc 2.36 caused by including in libreplace; (bso#15132). * SMB1 negotiation can fail to handle connection errors; (bso#15152). * samba-tool domain join segfault when joining a samba ad domain; (bso#15078). - Update to 4.15.9 * CVE-2022-32742:SMB1 code does not correct verify SMB1write, SMB1write_and_close, SMB1write_and_unlock lengths; (bso#15085); (bsc#1201496). * CVE-2022-32746: samba: Use-after-free occurring in database audit logging; (bso#15009); (bso#15096); (bsc#1201490). * CVE-2022-2031: samba, ldb: AD users can bypass certain restrictions associated with changing passwords; (bso#15047); (bsc#1201495); * CVE-2022-32745: samba: ldb: AD users can crash the server process with an LDAP add or modify request; (bso#15008); (bso#15096); (bsc#1201492). * CVE-2022-2031: samba, ldb: AD users can bypass certain restrictions associated with changing passwords; (bso#15047); (bsc#1201495); * CVE-2022-32744: samba, ldb: AD users can forge password change requests for any user; (bso#15074); (bso#15047); (bsc#1201493).- CVE-2022-1615: Do not ignore errors in random number generation; (bso#15103); (bsc#1202976); - CVE-2022-32743: Implement validated dnsHostName write rights; (bso#14833); (bsc#1202803);- Fix Use after free when iterating smbd_server_connection->connections after tree disconnect failure; (bso#15128); (bsc#1200102).- CVE-2022-32746: samba: Use-after-free occurring in database audit logging; (bso#15009); (bso#15096); (bsc#1201490). - CVE-2022-32745: samba: ldb: AD users can crash the server process with an LDAP add or modify request; (bso#15008); (bso#15096); (bsc#1201492). - CVE-2022-2031: samba, ldb: AD users can bypass certain restrictions associated with changing passwords; (bso#15047); (bsc#1201495); - CVE-2022-32742:SMB1 code does not correct verify SMB1write, SMB1write_and_close, SMB1write_and_unlock lengths; (bso#15085); (bsc#1201496). - CVE-2022-32744: samba, ldb: AD users can forge password change requests for any user; (bso#15074); (bso#15047); (bsc#1201493).- Update to 4.15.8 * Use pathref fd instead of io fd in vfs_default_durable_cookie; (bso#15042); * Setting fruit:resource = stream in vfs_fruit causes a panic; (bso#15099); * Add support for bind 9.18; (bso#14986); * logging dsdb audit to specific files does not work; (bso#15076); * vfs_gpfs with vfs_shadowcopy2 fail to restore file if original file had been deleted; (bso#15069); * netgroups support removed; (bso#15087); (bsc#1199247); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); (bsc#1199734); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * smbclient commands del & deltree fail with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556); * vfs_gpfs recalls=no option prevents listing files; (bso#15055); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * Compile error in source3/utils/regedit_hexedit.c; (bso#15091); * ldconfig: /lib64/libsmbconf.so.0 is not a symbolic link; (bso#15108); * smbd doesn't handle UPNs for looking up names; (bso#15054); * Out-by-4 error in smbd read reply max_send clamp; (bso#14443); - Move pdb backends from package samba-libs to package samba-client-libs and remove samba-libs requirement from samba-winbind; (bsc#1200964); (bsc#1198255); - Use the canonical realm name to refresh the Kerberos tickets; (bsc#1196224); (bso#14979);- Fix smbclient commands del & deltree failing with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556).- Revert NIS support removal; (bsc#1199247);- Use requires_eq macro to require the libldb2 version available at samba-dsdb-modules build time; (bsc#1199362);- Add missing samba-client requirement to samba-winbind package; (bsc#1198255);- Update to 4.15.7 * Share and server swapped in smbget password prompt; (bso#14831); * Durable handles won't reconnect if the leased file is written to; (bso#15022); * rmdir silently fails if directory contains unreadable files and hide unreadable is yes; (bso#15023); * SMB2_CLOSE_FLAGS_FULL_INFORMATION fails to return information on renamed file handle; (bso#15038); * vfs_shadow_copy2 breaks "smbd async dosmode" sync fallback; (bso#14957); * shadow_copy2 fails listing snapshotted dirs with shadow:fixinodes; (bso#15035); * PAM Kerberos authentication incorrectly fails with a clock skew error; (bso#15046); * username map - samba erroneously applies unix group memberships to user account entries; (bso#15041); * NT_STATUS_ACCESS_DENIED translates into EPERM instead of EACCES in SMBC_server_internal; (bso#14983); * Simple bind doesn't work against an RODC (with non-preloaded users); (bso#13879); * Crash of winbind on RODC; (bso#14641); * uncached logon on RODC always fails once; (bso#14865); * KVNO off by 100000; (bso#14951); * LDAP simple binds should honour "old password allowed period"; (bso#15001); * wbinfo -a doesn't work reliable with upn names; (bso#15003); * Simple bind doesn't work against an RODC (with non-preloaded users); (bso#13879); * Uninitialized litemask in variable in vfs_gpfs module; (bso#15027); * Regression: create krb5 conf = yes doesn't work with a single KDC; (bso#15016);- Add provides to samba-client-libs package to fix upgrades from previous versions; (bsc#1197995);- Add missing samba-libs requirement to samba-winbind package; (bsc#1198255);- Update to 4.15.6 * Renaming file on DFS root fails with NT_STATUS_OBJECT_PATH_NOT_FOUND; (bso#14169); * Samba does not response STATUS_INVALID_PARAMETER when opening 2 objects with same lease key; (bso#14737); * NT error code is not set when overwriting a file during rename in libsmbclient; (bso#14938); * Fix ldap simple bind with TLS auditing; (bso#14996); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); * Problem when winbind renews Kerberos; (bso#14979); (bsc#1196224); * pam_winbind will not allow gdm login if password about to expire; (bso#8691); * virusfilter_vfs_openat: Not scanned: Directory or special file; (bso#14971); * DFS fix for AIX broken; (bso#13631); * Solaris and AIX acl modules: wrong function arguments; (bso#14974); * Function aixacl_sys_acl_get_file not declared / coredump; (bso#7239); * Regression: Samba 4.15.2 on macOS segfaults intermittently during strcpy in tdbsam_getsampwnam; (bso#14900); * Fix a use-after-free in SMB1 server; (bso#14989); * smb2_signing_decrypt_pdu() may not decrypt with gnutls_aead_cipher_decrypt() from gnutls before 3.5.2; (bso#14968); * Changing the machine password against an RODC likely destroys the domain join; (bso#14984); * authsam_make_user_info_dc() steals memory from its struct ldb_message *msg argument; (bso#14993); * Use Heimdal 8.0 (pre) rather than an earlier snapshot; (bso#14995); * Samba autorid fails to map AD users if id rangesize fits in the id range only once; (bso#14967);- Fix mismatched version of libldb2; (bsc#1196788). - Drop obsolete SuSEfirewall2 service files.- Drop obsolete Samba fsrvp v0->v1 state upgrade functionality; (bsc#1080338).- Fix ntlm authentications with "winbind use default domain = yes"; (bso#13126); (bsc#1173429); (bsc#1196308).- Fix samba-ad-dc status warning notification message by disabling systemd notifications in bgqd; (bsc#1195896); (bso#14947).- libldb version mismatch in Samba dsdb component; (bsc#1118508);- Update to 4.15.5 * CVE-2021-44141: UNIX extensions in SMB1 disclose whether the outside target of a symlink exists; (bso#14911); (bsc#1193690). * CVE-2021-44142: Out-of-Bound Read/Write on Samba vfs_fruit module; (bso#14914); (bsc#1194859). * CVE-2022-0336: Re-adding an SPN skips subsequent SPN conflict checks; bso#14950); (bsc#1195048).- CVE-2021-44141: Information leak via symlinks of existance of files or directories outside of the exported share; (bso#14911); (bsc#1193690); - CVE-2021-44142: Out-of-bounds heap read/write vulnerability in VFS module vfs_fruit allows code execution; (bso#14914); (bsc#1194859); - CVE-2022-0336: Samba AD users with permission to write to an account can impersonate arbitrary services; (bso#14950); (bsc#1195048);- Update to 4.15.4 * Duplicate SMB file_ids leading to Windows client cache poisoning; (bso#14928); * Failed to parse NTLMv2_RESPONSE length 95 - Buffer Size Error - NT_STATUS_BUFFER_TOO_SMALL; (bso#14932); * kill_tcp_connections does not work; (bso#14934); * Can't connect to Windows shares not requiring authentication using KDE/Gnome; (bso#14935); * smbclient -L doesn't set "client max protocol" to NT1 before calling the "Reconnecting with SMB1 for workgroup listing" path; (bso#14939); * Cross device copy of the crossrename module always fails; (bso#14940); * symlinkat function from VFS cap module always fails with an error; (bso#14941); * Fix possible fsp pointer deference; (bso#14942); * Missing pop_sec_ctx() in error path inside close_directory(); (bso#14944); * "smbd --build-options" no longer works without an smb.conf file; (bso#14945);- Use pkgconfig(krb5) as dependency for the -devel package: allow OBS to pick the right flavor of krb5-devel (full vs mini). - Do not require the 'krb5' symbol by samba-client-libs: this package has an automatic dependency due to linkage on libgssapi_krb5.so.2. Automatic deps are always better. - Do not require the 'krb5' symbol from samba-libs: samba-libs requires samba-client-libs, which in turn requires krb5 libraries. Samba-libs itself has no need for krb5 (but get it indirectly anyway).- Reorganize libs packages. Split samba-libs into samba-client-libs, samba-libs, samba-winbind-libs and samba-ad-dc-libs, merging samba public libraries depending on internal samba libraries into these packages as there were dependency problems everytime one of these public libraries changed its version (bsc#1192684). The devel packages are merged into samba-devel. - Rename package samba-core-devel to samba-devel - Add python-rpm-macros to build requirements - Update the symlink create by samba-dsdb-modules to private samba ldb modules following libldb2 changes from /usr/lib64/ldb/samba to /usr/lib64/ldb2/modules/ldb/samba- Update to 4.15.3 * Recursive directory delete with veto files is broken in 4.15.0; (bso#14878); * A directory containing dangling symlinks cannot be deleted by SMB2 alone when they are the only entry in the directory; (bso#14879); * SIGSEGV in rmdir_internals/synthetic_pathref - dirfsp is used uninitialized in rmdir_internals(); (bso#14892); * MaxQueryDuration not honoured in Samba AD DC LDAP; (bso#14694); * The CVE-2020-25717 username map [script] advice has undesired side effects for the local nt token; (bso#14901); (bsc#1192849); * User with multiple spaces (eg FredNurk) become un-deletable; (bso#14902); * Avoid storing NTTIME_THAW (-2) as value on disk; (bso#14127); * smbXsrv_client_global record validation leads to crash if existing record points at non-existing process; (bso#14882); * Crash in vfs_fruit asking for fsp_get_io_fd() for an XATTR call; (bso#14890); * Samba process doesn't log to logfile; (bso#14897); * set_ea_dos_attribute() fallback calling get_file_handle_for_metadata() triggers locking.tdb assert; (bso#14907); * Kerberos authentication on standalone server in MIT realm broken; (bso#14922); * Segmentation fault when joining the domain; (bso#14923); * Support for ROLE_IPA_DC is incomplete; (bso#14903); * rpcclient cannot connect to ncacn_ip_tcp services anymore; (bso#14767); * winexe crashes since 4.15.0 after popt parsing; (bso#14893); * net ads status -P broken in a clustered environment; (bso#14908); * Memory leak if ioctl(FSCTL_VALIDATE_NEGOTIATE_INFO) fails before smbd_smb2_ioctl_send; (bso#14788); * winbindd doesn't start when "allow trusted domains" is off; (bso#14899); * smbclient login without password using '-N' fails with NT_STATUS_INVALID_PARAMETER on Samba AD DC; (bso#14883); * A schannel client incorrectly detects a downgrade connecting to an AES only server; (bso#14912); * Possible null pointer dereference in winbind; (bso#14921); * Fix -k legacy option for client tools like smbclient, rpcclient, net, etc.; (bso#14846); * Add Debian 11 CI bootstrap support; (bso#14872); * Crash in recycle_unlink_internal(); (bso#14888);- Fix dependency problem upgrading from libndr0 to libndr2 and from libsamba-credentials0 to libsamba-credentials1; (bsc#1192684);- Fix regression introduced by CVE-2020-25717 patches, winbindd does not start when 'allow trusted domains' is off; (bso#14899); - Update to 4.15.2 * CVE-2016-2124: SMB1 client connections can be downgraded to plaintext authentication; (bso#12444); (bsc#1014440); * CVE-2020-25717: A user on the domain can become root on domain members; (bso#14556); (bsc#1192284); * CVE-2020-25718: Samba AD DC did not correctly sandbox Kerberos tickets issued by an RODC; (bso#14558); (bsc#1192246); * CVE-2020-25719: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets; (bso#14561); (bsc#1192247); * CVE-2020-25721: Kerberos acceptors need easy access to stable AD identifiers (eg objectSid); (bso#14557); (bsc#1192505); * CVE-2020-25722: Samba AD DC did not do suffienct access and conformance checking of data stored; (bso#14564); (bsc#1192283); * CVE-2021-3738: Use after free in Samba AD DC RPC server; (bso#14468); (bsc#1192215); * CVE-2021-23192: Subsequent DCE/RPC fragment injection vulnerability; (bso#14875); (bsc#1192214); - Update to 4.15.1 * vfs_shadow_copy2: core dump in make_relative_path; (bso#14682); * Log clutter from filename_convert_internal; (bso#14685); * MacOSX compilation fixes; (bso#14862); * rodc_rwdc test flaps; (bso#14868); * Provide a fix for MS CVE-2020-17049 in Samba [SECURITY] 'Bronze bit' S4U2Proxy Constrained Delegation bypass in Samba with embedded Heimdal; (bso#14642); * Python ldb.msg_diff() memory handling failure; (bso#14836); * "in" operator on ldb.Message is case sensitive; (bso#14845); * Release LDB 2.4.1 for Samba 4.15.1; (bso#14848); * samldb_krbtgtnumber_available() looks for incorrect string; (bso#14854); * Fix Samba support for UF_NO_AUTH_DATA_REQUIRED; (bso#14871); * Allow special chars like "@" in samAccountName when generating the salt; (bso#14874); * Correctly ignore comments in CTDB public addresses file; (bso#14826); * Fix transit path validation; (bso#12998); * Fix that child winbindd logs to log.winbindd instead of log.wb-; (bso#14852); * SMB3 cancel requests should only include the MID together with AsyncID when AES-128-GMAC is used; (bso#14855); * Prepare to operate with MIT krb5 >= 1.20; (bso#14870); * Heimdal prefers RC4 over AES for machine accounts; (bso#14864);- Enable samba-tool without ad dc.- Adjust spec to use pam macros; (bsc#1191046).- Adjust spec for size * allow some Recommends instead Requires to be configured for cifs-utils, samba-libs-python3 & samba-gpupdate; (bsc#1182847). * remove fam, undocumented and unneeded.- Add missing build dependency on bison when building with the embedded Heimdal Kerberos- Update to 4.15.0 * Removed SMB development dialects SMB2_22, SMB2_24 and SMB3_10 * VFS layer modernized. * Add the ability to set allow/deny lists for zone transfer clients in Bind DLZ plugin * Server multi-channel support no longer experimental * Improved command line user experience, unifying the options in different commands * Winbindd no longer scans trusted domains on startup and will use enterprise principals by default. * The net utility is now able to support the offline domain join feature * New options for 'samba-tool dns zoneoptions' for aging control and to mark old records as static or dynamic * DNS tombstones are now deleted as appropriate and use a consistent timestamp format * The 'samba-tool dns update' command validates and rejects now malformed IPv4 and IPv6 addresses * The 'samba-tool domain backup' command correctly takes out locks against concurrent modification during backup when using the LMDB backend * TruACL support has been removed * NIS support has been removed- Fix 'net rpc' authentication when using the machine account; (bsc#1189017); (bso#14796);- Fix dependency problem upgrading from libndr0 to libndr1; (bsc#1189875); - Fix dependency problem upgrading from libsmbldap0 to libsmbldap2; (bsc#1189875); - Fix wrong kvno exported to keytab after net ads changetrustpw due to replication delay; (bsc#1188727); - Add Certificate Auto Enrollment Policy; (jsc#SLE-18456). - Update to 4.13.10 * s3: smbd: Ensure POSIX default ACL is mapped into returned Windows ACL for directory handles; (bso#14708); * Take a copy to make sure we don't reference free'd memory; (bso#14721); * s3: lib: Fix talloc heirarcy error in parent_smb_fname(); (bso#14722); * s3: smbd: Remove erroneous TALLOC_FREE(smb_fname_parent) in change_file_owner_to_parent() error path; (bso#14736); * samba-tool: Give better error information when the 'domain backup restore' fails with a duplicate SID; (bso#14575); * smbd: Correctly initialize close timestamp fields; (bso#14714); * Spotlight RPC service doesn't work with vfs_glusterfs; (bso#14740); * ctdb: Fix a crash in run_proc_signal_handler(); (bso#14475); * gensec_krb5: Restore ipv6 support for kpasswd; (bso#14750); * smbXsrv_{open,session,tcon}: Protect smbXsrv_{open,session,tcon}_global_traverse_fn against invalid records; (bso#14752); * samba-tool domain backup offline doesn't work against bind DLZ backend; (bso#14027); * netcmd: Use next_free_rid() function to calculate a SID for restoring a backup; (bso#14669); - Update to 4.13.9 * s3: smbd: SMB1 SMBsplwr doesn't send a reply packet on success; (bso#14696); * Add documentation for dsdb_group_audit and dsdb_group_json_audit to "log level", synchronise "log level" in smb.conf with the code; (bso#14689); * Fix smbd panic when two clients open same file; (bso#14672); * Fix memory leak in the RPC server; (bso#14675); * s3: smbd: Fix deferred renames; (bso#14679); * s3-iremotewinspool: Set the per-request memory context; (bso#14675); * rpc_server3: Fix a memleak for internal pipes; (bso#14675); * third_party: Update socket_wrapper to version 1.3.2; (bso#11899); * third_party: Update socket_wrapper to version 1.3.3; (bso#14639); * idmap_rfc2307 and idmap_nss return wrong mapping for uid/gid conflict; (bso#14663); * Fix the build on OmniOS; (bso#14288); - Update to 4.13.8 * CVE-2021-20254: Fix buffer overrun in sids_to_unixids(); (bso#14571 - Update to 4.13.7 * Release with dependency on ldb version 2.2.1.- CVE-2021-20254 Buffer overrun in sids_to_unixids(); (bnc#14571); (bsc#1184677).- Fix offline domain backup not possible using lmdb version >= 0.9.26; (bso#14676); - Require libldb >= 2.2.1; (bsc#1183572); (bsc#1183574); - Update to 4.13.6 * CVE-2020-27840: samba: Unauthenticated remote heap corruption via bad DNs; (bso#14595); (bsc#1183572). * CVE-2021-20277: samba: out of bounds read in ldb_handler_fold; (bso#14655); (bsc#1183574). - Update to 4.13.5 * s3:modules:vfs_virusfilter: Recent talloc changes cause infinite start-up failure; (bso#14634); * s3: libsmb: Add missing cli_tdis() in error path if encryption setup failed on temp proxy connection; (bso#13992); * smbd: In conn_force_tdis_done() when forcing a connection closed force a full reload of services; (bso#14604); * dbcheck: Check Deleted Objects and reduce noise in reports about expired tombstones (bso#14593); * s3: Fix fcntl waf configure check; (bso#14503); * s3/auth: Implement "winbind:ignore domains"; (bso#14602); * smbd: Use fsp->conn->session_info for the initial delete-on-close token; (bso#14617); * s3: VFS: nfs4_acls. Add missing TALLOC_FREE(frame) in error path; (bso#14648); * classicupgrade: Treat old never expires value right; (bso#14624); * g_lock: Fix uninitalized variable reads; (bso#14636); * s3:pysmbd: Fix fd leak in py_smbd_create_file(); (bso#13898); * lib:util: Avoid free'ing our own pointer; (bso#14625); * HEIMDAL: krb5_storage_free(NULL) should work; (bso#12505);- Spec file fixes around systemd and requires; (bsc#1182830); - Align systemd service unit files with upstream provided ones.- Update to 4.13.4 * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * lib: Avoid declaring zero-length VLAs in various messaging functions; (bso#14605); * Do not create an empty DB when accessing a sam.ldb; (bso#14579); * vfs_fruit may close wrong backend fd; (bso#14596); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * vfs_virusfilter: Allocate separate memory for config char*; (bso#14606); * vfs_fruit may close wrong backend fd; (bso#14596); * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * The cache directory for the user gencache should be created recursively; (bso#14601); * Be more flexible with repository names in CentOS 8 test environments; (bso#14594);- Uninstalling samba-client: Failed to disable unit, cifs.service does not exists; (bsc#1180388);- Update to 4.13.3 + libcli: smb2: Never print length if smb2_signing_key_valid() fails for crypto blob; (bso#14210); + s3: modules: gluster. Fix the error I made in preventing talloc leaks from a function; (bso#14486); + s3: smbd: Don't overwrite contents of fsp->aio_requests[0] with NULL via TALLOC_FREE(); (bso#14515); + s3: spoolss: Make parameters in call to user_ok_token() match all other uses; (bso#14568); + s3: smbd: Quiet log messages from usershares for an unknown share; (bso#14590); + samba process does not honor max log size; (bso#14248); + vfs_zfsacl: Add missing inherited flag on hidden "magic" everyone@ ACE; (bso#14587); + s3-libads: Pass timeout to open_socket_out in ms; (bso#13124); + s3-vfs_glusterfs: Always disable write-behind translator; (bso#14486); + smbclient: Fix recursive mget; (bso#14517); + clitar: Use do_list()'s recursion in clitar.c; (bso#14581); + manpages/vfs_glusterfs: Mention silent skipping of write-behind translator; (bso#14486); + vfs_shadow_copy2: Preserve all open flags assuming ROFS; (bso#14573); + interface: Fix if_index is not parsed correctly; (bso#14514);- Update to 4.13.2 + s3: modules: vfs_glusterfs: Fix leak of char **lines onto mem_ctx on return; (bso#14486); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471); + smb.conf.5: Add clarification how configuration changes reflected by Samba; (bso#14538); + daemons: Report status to systemd even when running in foreground; (bso#14552); + DNS Resolver: Support both dnspython before and after 2.0.0; (bso#14553); + s3-vfs_glusterfs: Refuse connection when write-behind xlator is present; (bso#14486); + provision: Add support for BIND 9.16.x; (bso#14487); + ctdb-common: Avoid aliasing errors during code optimization; (bso#14537); + libndr: Avoid assigning duplicate versions to symbols; (bso#14541); + docs: Fix default value of spoolss:architecture; (bso#14522); + winbind: Fix a memleak; (bso#14388); + s4:dsdb:acl_read: Implement "List Object" mode feature; (bso#14531); + docs-xml/manpages: Add warning about write-behind translator for vfs_glusterfs; (bso#14486); + nsswitch/nsstest.c: Avoid nss function conflicts with glibc nss.h. + vfs_shadow_copy2: Avoid closing snapsdir twice; (bso#14530); + third_party: Update resolv_wrapper to version 1.1.7; (bso#14547); + examples:auth: Do not install example plugin; (bso#14550); + ctdb-recoverd: Drop unnecessary and broken code; (bso#14513); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471);- Adjust smbcacls '--propagate-inheritance' feature to align with upstream; (bsc#1178469).- Update to samba 4.13.1 + CVE-2020-14383: An authenticated user can crash the DCE/RPC DNS with easily crafted records; (bsc#1177613); (bso#14472); + CVE-2020-14323: Unprivileged user can crash winbind; (bsc#1173994); (bso#14436); + CVE-2020-14318: Missing handle permissions check in SMB1/2/3 ChangeNotify; (bsc#1173902); (bso#14434); - Adjust systemd tmpfiles.d configuration, use /run/samba instead of /var/run/samba; (bsc#1177355);- Fix vfs_ceph query_directory regression; (bso#14519) - Drop liburing-devel for SLE15-SP2; (bsc#1177245)- Register CTDB recovery lock holder with ceph-mgr - Add liburing-devel dependency- Update to samba 4.13.0 + Require Python 3.6 + Move wide links functionality into VFS module + Deprecate NT4-like 'classic' Samba domain controllers + Deprecate SMBv1 only protocol options + Remove deprecated "ldap ssl ads" option + Unify asynchronous DCE-RPC server; (jsc#SES-645) + Replay multichannel lease break requests; (bso#11897); (jsc#SES-655) + Drop internal byteorder.h header from util-devel package + Remove final code for the AD DC LDAP backend + Add AD DC Group Policy Scripts + Only use gnutls_aead_cipher_encryptv2() for GnuTLS > 3.6.14; (bso#14399) + Fix %U substitutions if it contains a domain name; (bso#14467) + Fix krb5.conf creation for 'net ads join'; (bso#14479) + Fix build problem if libbsd-dev is not installed; (bso#14482) + Toggle vfs_snapper using "--with-shared-modules"; (bso#14437) + Fix idmap_ad RFC4511 response handling; (bso#14465) + Fix panic in get_lease_type(); (bso#14428)- Update to samba 4.11.13 + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Protect netr_ServerPasswordSet2 against unencrypted passwords; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Support "server require schannel:WORKSTATION$ = no" about unsecure configurations; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s4 torture rpc: repeated bytes in client challenge; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): libcli/auth: Reject weak client challenges in netlogon_creds_server_init() "server require schannel:WORKSTATION$ = no"; (bsc#1176579); (bso#14497); - Update to samba 4.11.12 + s3: libsmb: Fix SMB2 client rename bug to a Windows server; (bso#14403); + dsdb: Allow "password hash userPassword schemes = CryptSHA256" to work on RHEL7; (bso#14424); + dbcheck: Allow a dangling forward link outside our known NCs; (bso#14450); + lib/debug: Set the correct default backend loglevel to MAX_DEBUG_LEVEL; (bso#14426); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + lib/util: do not install "test_util_paths"; (bso#14370); + lib:util: Fix smbclient -l basename dir; (bso#14345); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + util: Allow symlinks in directory_create_or_exist; (bso#14166); + docs: Fix documentation for require_membership_of of pam_winbind; (bso#14358); + s3:winbind:idmap_ad: Make failure to get attrnames for schema mode fatal; (bso#14425);- Add obsoletes to libsmbldap2 package to fix upgrades from previous versions; (bsc#1172810);- Fix net command unable to negotiate SMB2; (bsc#1174120);- Update to samba 4.11.11 + CVE-2020-10730: NULL de-reference in AD DC LDAP server when ASQ and VLV combined; (bso#14364); (bsc#1173159] + CVE-2020-10745: invalid DNS or NBT queries containing dots use several seconds of CPU each; (bso#14378); (bsc#1173160). + CVE-2020-10760: Use-after-free in AD DC Global Catalog LDAP server with paged_result or VLV; (bso#14402); (bsc#1173161) + CVE-2020-14303: Endless loop from empty UDP packet sent to AD DC nbt_server; (bso#14417); (bsc#1173359). - Update to samba 4.11.10 + Fix segfault when using SMBC_opendir_ctx() routine for share folder that contains incorrect symbols in any file name; (bso#14374). + vfs_shadow_copy2 doesn't fail case looking in snapdirseverywhere mode; (bso#14350) + ldb_ldap: Fix off-by-one increment in lldb_add_msg_attr; (bso#14413). + Malicous SMB1 server can crash libsmbclient; (bso#14366) + winbindd: Fix a use-after-free when winbind clients exit; (bso#14382) + ldb: Bump version to 2.0.11, LMDB databases can grow without bounds. (bso#14330) - Update to samba 4.11.9 + nmblib: Avoid undefined behaviour in handle_name_ptrs(); (bso#14242). + 'samba-tool group' commands do not handle group names with special chars correctly; (bso#14296). + smbd: avoid calling vfs_file_id_from_sbuf() if statinfo is not valid; (bso#14237). + Missing check for DMAPI offline status in async DOS attributes; (bso#14293). + smbd: Ignore set NTACL requests which contain S-1-5-88 NFS ACEs; (bso#14307). + vfs_recycle: Prevent flooding the log if we're called on non-existant paths; (bso#14316) + smbd mistakenly updates a file's write-time on close; (bso#14320). + RPC handles cannot be differentiated in source3 RPC server; (bso#14359). + librpc: Fix IDL for svcctl_ChangeServiceConfigW; (bso#14313). + nsswitch: Fix use-after-free causing segfault in _pam_delete_cred; (bso#14327). + Fix fruit:time machine max size on arm; (bso#13622) + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294). + ctdb: Fix a memleak; (bso#14348). + libsmb: Don't try to find posix stat info in SMBC_getatr(). + ctdb-tcp: Move free of inbound queue to TCP restart; (bso#14295); (bsc#1162680). + s3/librpc/crypto: Fix double free with unresolved credential cache; (bso#14344); (bsc#1169095) + s3:libads: Fix ads_get_upn(); (bso#14336). + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294) + Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680). + ctdb-recoverd: Avoid dereferencing NULL rec->nodemap; (bso#14324) - Update to samba 4.11.8 + CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850); + CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - Update to samba 4.11.7 + s3: lib: nmblib. Clean up and harden nmb packet processing; (bso#14239). + s3: VFS: full_audit. Use system session_info if called from a temporary share definition; (bso#14283) + dsdb: Correctly handle memory in objectclass_attrs; (bso#14258). + ldb: version 2.0.9, Samba 4.11 and later give incorrect results for SCOPE_ONE searches; (bso#14270) + auth: Fix CIDs 1458418 and 1458420 Null pointer dereferences; (bso#14247). + smbd: Handle EINTR from open(2) properly; (bso#14285) + winbind member (source3) fails local SAM auth with empty domain name; (bso#14247) + winbindd: Handling missing idmap in getgrgid(); (bso#14265). + lib:util: Log mkdir error on correct debug levels; (bso#14253). + wafsamba: Do not use 'rU' as the 'U' is deprecated in Python 3.9; (bso#14266). + ctdb-tcp: Make error handling for outbound connection consistent; (bso#14274). - Update to samba 4.11.6 + pygpo: Use correct method flags; (bso#14209). + vfs_ceph_snapshots: Fix root relative path handling; (bso#14216); (bsc#1141320). + Avoiding bad call flags with python 3.8, using METH_NOARGS instead of zero; (bso#14209). + source4/utils/oLschema2ldif: Include stdint.h before cmocka.h; (bso#14218). + docs-xml/winbindnssinfo: Clarify interaction with idmap_ad etc; (bso#14122). + smbd: Fix the build with clang; (bso#14251). + upgradedns: Ensure lmdb lock files linked; (bso#14199). + s3: VFS: glusterfs: Reset nlinks for symlink entries during readdir; (bso#14182). + smbc_stat() doesn't return the correct st_mode and also the uid/gid is not filled (SMBv1) file; (bso#14101). + librpc: Fix string length checking in ndr_pull_charset_to_null(); (bso#14219). + ctdb-scripts: Strip square brackets when gathering connection info; (bso#14227).- Add libnetapi-devel to baselibs conf, for wine usage; (bsc#1172307);- Installing: samba - samba-ad-dc.service does not exist and unit not found; (bsc#1171437);- Fix samba_winbind package is installing python3-base without python3 package; (bsc#1169521);- Require libldb2 >= 2.0.10 after security release.- CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850);- Fix smbclient crash with double free (with unresolved krb5 credential cache); (bso#14344); (bsc#1169095).- Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680).- CTDB doesn't retry outgoing connections on bind (and some other) failures; (bso#14274); (bsc#1162680).- Revert: Allow idmap_rid to have primary group other than "Domain Users"; (bsc#1087931).- Fix nmbstatus not reporting detailed information about workgroups; (bsc#1159464); - Fix querying all names registered within broadcast area; (bso#8927);- Update to samab 4.11.5 + CVE-2019-14902: Replication of ACLs down subtree on AD Directory is not automatic; (bso#12497); (bsc#1160850). + CVE-2019-19344: Fix server crash with dns zone scavenging = yes; (bso#14050); (bsc#1160852). + CVE-2019-14907: server-side crash after charset conversion failure (eg during NTLMSSP processing); (bso#14208); (bsc#1160888). - Update to samba 4.11.4 + Ensure SMB1 cli_qpathinfo2() doesn't return an inode number; (bso#14161). + Ensure we don't call cli_RNetShareEnum() on an SMB1 connection; (bso#14174). + NT_STATUS_ACCESS_DENIED becomes EINVAL when using SMB2 in SMBC_opendir_ctx; (bso#14176). + SMB2 - Ensure we use the correct session_id if encrypting an interim response; (bso#14189). + Prevent smbd crash after invalid SMB1 negprot; (bso#14205). + printing: Fix %J substition; (bso#13745). + Remove now unneeded call to cmdline_messaging_context(); (bso#13925). + Fix incomplete conversion of former parametric options; (bso#14069). + Fix sync dosmode fallback in async dosmode codepath; (bso#14070). + vfs_fruit returns capped resource fork length; (bso#14171). + libnet_join: Add SPNs for additional-dns-hostnames entries; (bso#14116). + smbd: Increase a debug level; (bso#14211). + Prevent azure ad connect from reporting discovery errors reference-value-not-ldap-conformant; (bso#14153). + krb5_plugin: Fix developer build with newer heimdal system library; (bso#14179). + replace: Only link libnsl and libsocket if required; (bso#14168); + ctdb: Incoming queue can be orphaned causing communication; breakdown; (bso#14175). + ldb: Release ldb 2.0.8. Cross-compile will not take cross-answers or cross-execute; (bso#13846). + heimdal-build: Avoid hard-coded /usr/include/heimdal in asn1_compile-generated code; (bso#13856).- Fix Ceph snapshot root relative path handling; (bso#14216); (bsc#1141320).- Update to samba 4.11.3 + CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). + CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). - CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- Update to samba 4.11.2 + CVE-2019-10218: Client code can return filenames containing path separators; (bsc#1144902); (bso#14071). + CVE-2019-14833: Samba AD DC check password script does not receive the full password; (bso#12438). + CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040). - Fixes from 4.11.1 + Overlinking libreplace against librt and pthread against every binary or library causes issues; (bso#14140); + kpasswd fails when built with MIT Kerberos; (bso#14155); + Fix spnego fallback from kerberos to ntlmssp in smbd server; (bso#14106); + Stale file handle error when using mkstemp on a share; (bso#14137); + non-AES schannel broken; (bso#14134); + Joining Active Directory should not use SAMR to set the password; (bso#13884); + smbclient can blunder into the SMB1 specific cli_RNetShareEnum() call on an SMB2 connection; (bso#14152); + Deleted records can be resurrected during recovery; (bso#14147); + getpwnam and getpwuid need to return data for ID_TYPE_BOTH group; (bso#14141); + winbind does not list forest trusts with additional trust attributes; (bso#14130); + fault report points to outdated documentation; (bso#14139); + pam_winbind with krb5_auth or wbinfo -K doesn't work for users of trusted domains/forests; (bso#14124); + classicupgrade results in uncaught exception - a bytes-like object is required, not 'str'; (bso#14136); + pod2man is not longer required, stop checking at build time; (bso#14131); + Exit code of ctdb nodestatus should not be influenced by deleted nodes; (bso#14129); + username/password authentication doesn't work with CUPS and smbspool; (bso#14128); + smbc_readdirplus() is incompatible with smbc_telldir() and smbc_lseekdir(); (bso#14094);- CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040); (bsc#1154598); - CVE-2019-10218: Client code can return filenames containing path separators; (bso#14071); (bsc#1144902);- CVE-2019-14833: samba: Accent with "check script password" Samba AD DC check password script does not receive the full password; (bso#12438); (bsc#1154289).- Update to samba 4.11.0 + For details on all items see WHATSNEW.txt in samba-doc package + Python2 runtime support removed; python 3.4 or later required + Security improvements: - SMB1 disabled by default - lanman and plaintext authentication deprecated - winbind: PAM_AUTH and NTLM_AUTH events logged - GnuTLS 3.2 required; system FIPS mode setting honored + CephFS Snapshot integration, exposed as previous file versions + ctdb changes: - onnode -o option removed - ctdbd logs when using more than 90% of a CPU thread - CTDB_MONITOR_SWAP_USAGE variable removed + AD Domain controller improvements: - Upgrade AD databse format - BIND9_FLATFILE deprecated - default process model chagned to prefork - bind9 dns operation duration logging - Default schema updated to 2012_R2; function level is unchanged - many performance improvements + Configuration webserver support removed- Fix broken username/password authentication with CUPS and smbspool; (bsc#1152143); (bso#14128).- Fix auth problems when printing via smbspool backend with kerberos; (bnc#1148539); (bso#13832).- Update to samba 4.10.8 + CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267);- Fix build on newer systems by modifying samba.spec to use consistent non-relative paths for pammodules in configure line and specification of pam_winbind.so library to package.- Update to samba 4.10.7 + Unable to create or rename file/directory inside shares configured with vfs_glusterfs_fuse module; (bso#14010). + build: Allow build when '--disable-gnutls' is set; (bso#13844) + samba-tool: Add 'import samba.drs_utils' to fsmo.py; (bso#13973). + Fix 'Error 32 determining PSOs in system' message on old DB with FL upgrade; (bso#14008). + s4/libnet: Fix joining a Windows pre-2008R2 DC; (bso#14021) + join: Use a specific attribute order for the DsAddEntry nTDSDSA object; (bso#14046). + vfs_catia: Pass stat info to synthetic_smb_fname(); (bso#14015). + lookup_name: Allow own domain lookup when flags == 0; (bso#14091). + s4 librpc rpc pyrpc: Ensure tevent_context deleted last; (bso#13932). + DEBUGC and DEBUGADDC doesn't print into a class specific log file; (bso#13915). + Request to keep deprecated option "server schannel", VMWare Quickprep requires "auto"; (bso#13949). + dbcheck: Fallback to the default tombstoneLifetime of 180 days; (bso#13967). + dnsProperty fails to decode values from older Windows versions; (bso#13969). + samba-tool: Use only one LDAP modify for dns partition fsmo role transfer; (bso#13973). + third_party: Update waf to version 2.0.17; (bso#13960). + netcmd: Allow 'drs replicate --local' to create partitions; (bso#14051). + ctdb-config: Depend on /etc/ctdb/nodes file; (bso#14017).- CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267).- Prepare for use future use of kernel keyrings, modify /etc/pam.d/samba to include pam_keyinit.so; (bsc#1144059).- Update samba-winbind script to work with systemd; (bsc#1132739); - Drop samba dhcpcd hook scripts - Update to samba 4.10.6 + s3: winbind: Fix crash when invoking winbind idmap scripts; (bso#13956). + smbd does not correctly parse arguments passed to dfree and quota scripts; (bso#13964). + samba-tool dns: use bytes for inet_ntop; (bso#13965). + samba-tool domain provision: Fix --interactive module in python3; (bso#13828). + ldb_kv: Skip @ records early in a search full scan; (bso#13893). + docs: Improve documentation of "lanman auth" and "ntlm auth" connection; (bso#13981). + python/ntacls: Use correct "state directory" smb.conf option instead of "state dir"; (bso#14002). + registry: Add a missing include; (bso#13840). + Fix SMB guest authentication; (bso#13944). + AppleDouble conversion breaks Resourceforks; (bso#13958). + vfs_fruit makes direct use of syscalls like mmap() and pread(); (bso#13968). + s3:mdssvc: Fix flex compilation error; (bso#13987). + s3/vfs_glusterfs[_fuse]: Avoid using NAME_MAX directly; (bso#13872). + dsdb:samdb: schemainfo update with relax control; (bso#13799). + s3:util: Move static file_pload() function to lib/util; (bso#13964). + smbd: Fix a panic; (bso#13957). + ldap server: Generate correct referral schemes; (bso#12478). + s4 dsdb/repl_meta_data: fix use after free in dsdb_audit_add_ldb_value; (bso#13941). + s4 dsdb: Fix use after free in samldb_rename_search_base_callback; (bso#13942). + dsdb/repl: we need to replicate the whole schema before we can apply it; (bso#12204). + ldb: Release ldb 1.5.5; (bso#12478). + Schema replication fails if link crosses chunk boundary backwards; (bso#13713). + 'samba-tool domain schemaupgrade' uses relax control and skips the schemaInfo update provision; (bso#13799). + dsdb_audit: avoid printing "... remote host [Unknown] SID [(NULL SID)] ..."; (bso#13916). + python/ntacls: We only need security.SEC_STD_READ_CONTROL in order to get the ACL; (bso#13917). + s3:loadparm: Ensure to truncate FS Volume Label at multibyte boundary; (bso#13947). + Using Kerberos credentials to print using spoolss doesn't work; (bso#13939). + wafsamba: Use native waf timer; (bso#13998). + ctdb-scripts: Fix tcp_tw_recycle existence check; (bso#13984).- Update to samba-4.10.5 (including updates for 4.10.4, 4.10.3) + CVE-2019-12435 rpc/dns: Avoid NULL deference if zone not found in DnssrvOperation2; (bso#13922); (bsc#1137815). + CVE-2019-12436 dsdb/paged_results: Ignore successful results without messages; (bso#13951); (bsc#1137816). - Update to samba-4.10.4 + s3: SMB1: Don't allow recvfile on stream fsp's; (bso#13938). + py/provision: Fix for Python 2.6; (bso#13882). + netcmd: Fix 'passwordsettings --max-pwd-age' command; (bso#13873). + s3-libnet_join: 'net ads join' to child domain fails when using "-U admin@forestroot"; (bso#13861). + vfs_ceph: Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245). + vfs_ceph: Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). + ctdb-common: Avoid race between fd and signal events; (bso#13895). + ctdb-common: Fix memory leak in run_proc; (bso#13943). + lib: Initialize getline() arguments; (bso#13892). + winbind: Fix overlapping id ranges; (bco#13903). + lib util debug: Increase format buffer to 4KiB; (bso#13902). + nsswitch pam_winbind: Fix Asan use after free; (bso#13927). + s4 lib socket: Ensure address string owned by parent struct; (bso#13929). + s3 rpc_client: Fix Asan stack use after scope; (bso#13936). + s3:smbd: Handle IO_REPARSE_TAG_DFS in SMB_FIND_FILE_FULL_DIRECTORY_INFO; (bso#10097). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#10344). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#12845). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#13698). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#13796). + dbcheck: Fix the err_empty_attribute() check; (bso#13843). + vfs_snapper: Drop unneeded fstat handler; (bso#13858). + vfs_default: Fix vfswrap_offload_write_send() NT_STATUS_INVALID_VIEW_SIZE check; (bso#13862). + smb2_server: Grant all 8192 credits to clients; (bso#13863). + smbd: Implement SMB_FILE_NORMALIZED_NAME_INFORMATION handling; (bso#13919). + s3/vfs_glusterfs: Dynamically determine NAME_MAX; (bso#13872). + s3: modules: ceph: Use current working directory instead of share path; (bso#13918); (bsc#1134452). + winbind: Use domain name from lsa query for sid_to_name cache entry; (bso#13831). + memcache: Increase size of default memcache to 512k; (bso#13865). + docs: Update smbclient manpage for "--max-protocol"; (bso#13857). + s3:utils: If share is NULL in smbcacls, don't print it; (bso#13937). + s3:smbspool: Fix regression printing with Kerberos credentials; (bso#13939). + ctdb-scripts: CTDB restarts failed NFS RPC services by hand, which is incompatible with systemd; (bso#13860). + ctdb-daemon: Revert "We can not assume that just because we could complete a TCP handshake"; (bso#13888). + ctdb-daemon: Never use 0 as a client ID; (bso#13930). + ctdb-common: Fix memory leak; (bso#13943). + s3:debug: Enable logging for early startup failures; (bso#13904) - Update to samba-4.10.3 + CVE-2018-16860: Heimdal KDC: Reject PA-S4U2Self with unkeyed checksum; (bso#13685); (bsc#1134024).- CVE-2019-12435: zone operations can crash rpc server; (bso#13922); (bsc#1137815).- Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). - Add ceph_snapshots VFS module; (jsc#SES-183).- Fix vfs_ceph realpath; (bso#13918); (bsc#1134452).- Update to samba-4.10.2: + CVE-2019-3870 (World writable files in Samba AD DC private/ dir); (bso#13834). + CVE-2019-3880 (Save registry file outside share as unprivileged user); (bso#13851). + py/kcc_utils: py2.6 compatibility; (bso#13837). + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869). + regfio: Improve handling of malformed registry hive files; (bso#13840). + ctdb-version: Simplify version string usage; (bso#13789). + lib: Make fd_load work for non-regular files; (bso#13859). + dbcheck: in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816). + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818). + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854). + acl_read: Fix regression for empty lists; (bso#13836). + s4:dlz make b9_has_soa check dc=@ node; (bso#13841). + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832). + s4:librpc: Fix installation of Samba; (bso#13847). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853). * ctdb-build: Drop creation of .distversion in tarball; (bso#13789). * ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838). - Update to samba-4.10.1: + py/kcc_utils: py2.6 compatibility; (bso#13837); + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869); + regfio: Improve handling of malformed registry hive files; (bso#13840); + ctdb-version: Simplify version string usage; (bso#13789); + lib: Make fd_load work for non-regular files; (bso#13859); + dbcheck in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816); + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818); + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854); + acl_read: Fix regression for empty lists; (bso#13836); + s4:dlz make b9_has_soa check dc=@ node; (bso#13841); + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832); + s4:librpc: Fix installation of Samba; (bso#13847); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853); + ctdb-build: Drop creation of .distversion in tarball; (bso#13789); + ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838); - Update to samba-4.10.0: + s4-server: Open and close a transaction on sam.ldb at startup; (bso#13760); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s4/scripting/bin: Open unicode files with utf8 encoding and write + unicode string. + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + Fix idmap cache pollution with S-1-22- IDs on winbind hickup; (bso#13813); + passdb: Update ABI to 0.27.2. + lib/winbind_util: Add winbind_xid_to_sid for --without-winbind; (bso#13813); + lib:util: Move debug message for mkdir failing to log level 1; (bso#13823);- MacOS credit accounting breaks with async SESSION SETUP; (bsc#1125601); (bso#13796). - Mac OS X SMB2 implmenetation sees Input/output error or Resource temporarily unavailable and drops connection; (bso#13698)- Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245).- CVE-2019-3880: Save registry file outside share as unprivileged user; (bso#13851); (bsc#1131060 ).- CVE-2019-3870 pysmbd: missing restoration of original umask after umask(0); (bso#13834); (bsc#1130703);- Update to samba-4.9.5 + audit_logging: Remove debug log header and JSON Authentication: prefix; (bso#13714); + Fix upgrade from 4.7 (or earlier) to 4.9; (bso#13760); + s3: lib: nmbname: Ensure we limit the NetBIOS name correctly; (bso# CID: 1433607; (bso#11495); + smbd: uid: Don't crash if 'force group' is added to an existing share connection; (bso#13690); + s3: VFS: vfs_fruit. Fix the NetAtalk deny mode compatibility code; (bso#13770); + s3: SMB1 POSIX mkdir does case insensitive name lookup; (bso#13803); + s3:utils/smbget fix recursive download with empty source directories; (bso#13199); + samba-tool drs showrepl: Do not crash if no dnsHostName found; (bso#13716); + s3:libsmb: cli_smb2_list() can sometimes fail initially on a connection; (bso#13736); + join: Throw CommandError instead of Exception for simple errors; (bso#13747); + ldb: Avoid inefficient one-level searches; (bso#13762); + s3: libsmb: use smb2cli_conn_max_trans_size() in cli_smb2_list(); (bso#13736); + tldap: Avoid use after free errors; (bso#13776); + Fix idmap xid2sid cache churn; (bso#13802); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s3-smbd: Avoid assuming fsp is always intact after close_file call; (bso#13720); + s3-vfs-fruit: Add close call; (bso#13725); + s3-smbd: Use fruit:model string for mDNS registration; (bso#13746); + s3-vfs: add glusterfs_fuse vfs module; (bso#13774); + printing: Check lp_load_printers() prior to pcap cache update; (bso#13766); + vfs_ceph: vfs_ceph strict_allocate_ftruncate calls (local FS) ftruncate and fallocate; (bso#13807); + lib/audit_logging: Actually create talloc; (bso#13737); + netcmd/user: python[3]-gpgme unsupported and replaced by python[3]-gpg; (bso#13728); + dns: Changing onelevel search for wildcard to subtree; (bso#13738); + samba-tool: Don't print backtrace on simple DNS errors; (bso#13721); + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + ctdb: Print locks latency in machinereadable stats; (bso#13742); + messages_dgm: Messaging gets stuck when pids are recycled; (bso#13786); + audit_logging: auth_json_audit required auth_json; (bso#13715); + man pages: Document prefork process model; (bso#13765); + CVE-2019-3824 ldb: Release ldb 1.4.6; (bso#13773); + s3:auth: ignore create_builtin_guests() failing without a valid idmap configuration; (bso#13697); + s3:auth_winbind: Ignore a missing winbindd as NT4 PDC/BDC without trusts; (bso#13722); + s3:auth_winbind: return NT_STATUS_NO_LOGON_SERVERS if winbindd is not available; (bso#13723); + s4:server: Add support for 'smbcontrol samba shutdown' and 'smbcontrol debug/debuglevel'; (bso#13752); + Python: Ensure ldb.Dn can doesn't rencoded str with py2; (bso#13616); + vfs_glusterfs: Adapt to changes in libgfapi signatures; (bso#13330); + s3-vfs: Use ENOATTR in errno comparison for getxattr; (bso#13774); + notifyd: Fix SIGBUS on sparc; (bso#13704); + waf: Check for libnscd; (bso#13787); + s3:vfs: Correctly check if OFD locks should be enabled or not; (bso#13770); + lib/util: Count a trailing line that doesn't end in a newline; (bso#13717); + Recovery lock bug fixes; (bso#13800); + s3: net: Do not set NET_FLAGS_ANONYMOUS with -k; (bso#13726); + s3:libsmb: Honor disable_netbios option in smbsock_connect_send; (bso#13727); + vfs_fileid: Fix get_connectpath_ino; (bso#13741); + vfs_fileid: Fix fsname_norootdir algorithm; (bso#13744);- Fix vfs_ceph ftruncate and fallocate handling; (bso#13807); (bsc#1127153).- Fix update-apparmor-samba-profile script after apparmor switched to using named profiles. The change is backwards compatible; (bsc#1126377);- LoadParm().load_default() fails with "Unable to load default file"; (bsc#1089758);- Abide by load_printers smb.conf parameter; (bso#13766); (bsc#1124223);- Update to samba-4.9.4 + libcli/smb: Don't overwrite status code; (bso#9175). + wbinfo --group-info 'NT AUTHORITY\System' does not work; (bso#12164). + Session setup reauth fails to sign response; (bso#13661). + vfs_fruit: Validation of writes on AFP_AfpInfo stream; (bso#13677). + vfs_shadow_copy2: Nicely deal with attempts to open previous version for writing; (bso#13688). + Restoring previous version of stream with vfs_shadow_copy2 fails with NT_STATUS_OBJECT_NAME_INVALID fsp->base_fsp->fsp_name; (bso#13455). + CVE-2018-16853: Fix S4U2Self crash with MIT KDC build; (bso#13571). + s3-vfs: Prevent NULL pointer dereference in vfs_glusterfs; (bso#13708) + PEP8: fix E231: missing whitespace after ','. + winbindd: Fix crash when taking profiles;(bso#13629) + CVE-2018-14629 dns: Fix CNAME loop prevention using counter regression; (bso#13600) + 'samba-tool user syscpasswords' fails on a domain with many DCs; (bso#13686). + CVE-2018-16853: Do not segfault if client is not set; (bso#13571). + lib:util: Fix DEBUGCLASS pointer initializiation; (bso#13679) + ctdb-daemon: Exit with error if a database directory does not exist; (bso#13696). + s3:libads: Add net ads leave keep-account option; (bso#13498).- Drop more %if..%endif guards which are idempotent. - Drop requires on ldconfig which are already auto-discovered. - Do not ignore errors from useradd/groupadd.- Remove python2 build dependency from samba-libs; (bsc#1116900);- Update update-apparmor-samba-profile script to ignore the shares's paths containing substitution variables in any place, not only at the beginning of the path.- Update to samba-4.9.3 + CVE-2018-14629: Unprivileged adding of CNAME record causing loop in AD Internal DNS server; (bso#13600); (bsc#1116319); + CVE-2018-16841: Double-free in Samba AD DC KDC with PKINIT; (bso#13628); (bsc#1116320); + CVE-2018-16851: NULL pointer de-reference in Samba AD DC LDAP server; (bso#13674); (bsc#1116322); + CVE-2018-16852: NULL pointer de-reference in Samba AD DC DNS servers; (bso#13669); (bsc#1116321); + CVE-2018-16853: Samba AD DC S4U2Self crash in experimental MIT Kerberos configuration (unsupported); (bso#13678); (bsc#1116324); + CVE-2018-16857: Bad password count in AD DC not always effective; window; (bso#13683); (bsc#1116323);- Update to samba-4.9.2 + dsdb: Add comments explaining the limitations of our current backlink behaviour; (bso#13418); + Fix problems running domain backups (handling SMBv2, sites); (bso#13621); + testparm: Fix crashes with PANIC: Messaging not initialized on SLES 12 SP3; (bso#13465); + Make vfs_fruit able to cleanup AppleDouble files; (bso#13642); + File saving issues with vfs_fruit on samba >= 4.8.5; (bso#13646); + Enabling vfs_fruit looses FinderInfo; (bso#13649); + Cancelling of SMB2 aio reads and writes returns wrong error NT_STATUS_INTERNAL_ERROR; (bso#13667); + Fix CTDB recovery record resurrection from inactive nodes and simplify vacuuming; (bso#13641); + examples: Fix the smb2mount build; (bso#13465); + libtevent: Fix build due to missing open_memstream on Illiumos; (bso#13629); + winbindd_cache: Fix timeout calculation for sid<->name cache; (bso#13662); + dsdb encrypted_secrets: Allow "ldb:// and "mdb://" in file path; (bso#13653); + Extended DN SID component missing for member after switching group membership; (bso#13418); + Return STATUS_SESSION_EXPIRED error encrypted, if the request was encrypted; (bso#13624); + python: Allow forced signing via smb.SMB(); (bso#13621); + lib:socket: If returning early, set ifaces; (bso#13665); + ldb: Bump ldb version to 1.4.3, Python: Ensure ldb.Dn can accept utf8 encoded unicode; (bso#13616); + smbd: Fix DELETE_ON_CLOSE behaviour on files with READ_ONLY attribute; (bso#13673); + waf: Add -fstack-clash-protection; (bso#13601); + winbind: Fix segfault if an invalid passdb backend is configured; (bso#13668); + Fix bugs in CTDB event handling; (bso#13659); + Misbehaving nodes are sometimes not banned; (bso#13670);- lib:socket: If returning early, set ifaces; (bso#13665); (bsc#1111373);- winbind requires latest version of libtevent-util0 to start- Backport latest gpo code from master + Read policy from local gpt cache + Offline policy application + Make group policy extensible via register/unregister gpext + gpext's run via a process_group_policy method- Enable profiling data collection- Change samba-kdc package name to samba-ad-dc - Move samba-ad-dc.service to the samba-ad-dc package- Update to samba-4.9.1 + s3: nmbd: Stop nmbd network announce storm; (bso#13620); + s3-rpcclient: Use spoolss_init_spoolss_UserLevel1 in winspool cmds; (bso#13597); + CTDB recovery lock has some race conditions; (bso#13617); + s3-rpc_client: Advertise Windows 7 client info; (bso#13597); + ctdb-doc: Remove PIDFILE option from ctdbd_wrapper man page; (bso#13610);- Tumbleweed doesn't define the sle_version macro, so we must include a check for suse_version also. Otherwise python3 is disabled on Tumbleweed.- Update to samba-4.9.0 + samba_dnsupdate: Honor 'dns zone scavenging' option, only update if needed; (bso#13605); + wafsamba: Fix 'make -j'; (bso#13606);- Update to samba-4.9.0rc5 + s3: VFS: vfs_full_audit: Ensure smb_fname_str_do_log() only returns absolute pathnames; (bso#13565); + s3: util: Do not take over stderr when there is no log file; (bso#13578); + Durable Reconnect fails because cookie.allow_reconnect is not set; (bso#13549); + krb5-samba: Interdomain trust uses different salt principal; (bso#13539); + vfs_fruit: Don't unlink the main file; (bso#13441); + smbd: Fix a memleak in async search ask sharemode; (bso#13602); + Fix Samba GPO issue when Trust is enabled; (bso#11517); + samba-tool: Add "virtualKerberosSalt" attribute to 'user getpassword/syncpasswords'; (bso#13539); + Fix CTDB configuration issues; (bso#13589); + ctdbd logs an error until it can successfully connect to eventd; (bso#13592);- Update to samba-4.9.0rc4 + s3: smbd: Ensure get_real_filename() copes with empty pathnames; (bso#13585); + samba domain backup online/rename commands force user to specify password on CLI; (bso#13566); + wafsamba/samba_abi: Always hide ABI symbols which must be local; (bso#13579); + Fix a panic if fruit_access_check detects a locking conflict; (bso#13584); + Fix memory and resource leaks; (bso#13567); + python: Fix print in dns_invalid.py; (bso#13580); + Aliasing issue causes incorrect IPv6 checksum; (bso#13588); + Fix CTDB configuration issues; (bso#13589); + s3: vfs: time_audit: fix handling of token_blob in smb_time_audit_offload_read_recv(); (bso#13568);- Add missing zlib-devel dependency which was previously pulled in by libopenssl-devel- Update to samba-4.9.0rc3+git.22.3fff23ae36e + CVE-2018-10858: libsmb: Harden smbc_readdir_internal() against returns from malicious servers; (bso#13453); + CVE-2018-1140: ldbsearch '(distinguishedName=abc)' and DNS query with escapes crashes, ldb: Release LDB 1.3.5 for CVE-2018-1140; (bso#13374); + CVE-2018-10918: cracknames: Fix DoS (NULL pointer de-ref) when not servicePrincipalName is set on a user; (bso#13552); + CVE-2018-10919: acl_read: Fix unauthorized attribute access via searches; (bso#13434); + ctdb_mutex_ceph_rados_helper: Set SIGINT signal handler; (bso#13540); + CVE-2018-1139 libcli/auth: Do not allow ntlmv1 over SMB1 when it is disabled via "ntlm auth"; (bso#13360); + s3-tldap: do not install test_tldap; (bso#13529); + ctdb_mutex_ceph_rados_helper: Fix deadlock via lock renewals; (bso#13540); + CVE-2018-1140 Add NULL check for ldb_dn_get_casefold() in ltdb_index_dn_attr(); (bso#13374); + ctdb-eventd: Fix CID 1438155; (bso#13554); + Fix CIDs 1438243, (Unchecked return value) 1438244 (Unsigned compared against 0), 1438245 (Dereference before null check) and 1438246 (Unchecked return value); (bso#13553); + ctdb: Fix a cut&paste error; (bso#13554); + systemd: Only start smb when network interfaces are up; (bso#13559); + Fix quotas don't work with SMB2; (bso#13553); + s3/smbd: Ensure quota code is only called when quota support detected; (bso#13563); + s3/libsmb: Explicitly set delete_on_close token for rmdir; (bso#13204); + s3:waf: Install eventlogadm to /usr/sbin; (bso#13561); + Shorten description in vfs_linux_xfs_sgid manual; (bso#13562);- Update to samba-4.9.0rc2+git.21.a1069afb007 + s3: smbd: Using "sendfile = yes" with SMB2 can cause CPU spin; (bso#13537); + s3: smbd: Fix path check in smbd_smb2_create_durable_lease_check(); (bso#13535); + samba-tool trust: Support discovery via netr_GetDcName; (bso#13538); + s4-dsdb: Only build dsdb Python modules for AD DC; (bso#13542); + Fix portability issues on freebsd; (bso#13520); + DNS wildcard search does not handle multiple labels correctly; (bso#13536); + samba-tool domain trust: Fix trust compatibility to Windows Server 1709 and FreeIPA; (bso#13308); + Fix portability issues on freebsd; (bso#13520); + ctdb-protocol: Fix CTDB compilation issues; (bso#13545); + ctdb-docs: Replace obsolete reference to CTDB_DEBUG_HUNG_SCRIPT option; (bso#13546); + ctdb-doc: Provide an example script for migrating old configuration; (bso#13550); + ctdb-event: Implement event tool "script list" command; (bso#13551);- Update to samba-4.8.4+git.37.a7a861d7982; + CVE-2018-1139: Weak authentication protocol allowed; (bsc#1095048); (bsc#13360); + CVE-2018-1140: Denial of Service Attack on DNS and LDAP server; (bsc#1095056); (bso#13466); (bso#13374); + CVE-2018-10858: Insufficient input validation on client directory listing in libsmbclient; (bsc#1103411); (bso#13453); + CVE-2018-10918: Denial of Service Attack on AD DC DRSUAPI server; (bsc#1103414); (bso#13552); + CVE-2018-10919: Confidential attribute disclosure from the AD LDAP server; (bsc#1095057); (bso#13434); + s3:winbind: winbind normalize names' doesn't work for users; (bso#12851); + winbind: Fix UPN handling in canonicalize_username(); (bso#13369); + s3: smbd: Fix SMB2-FLUSH against directories; (bso#13428); + samdb: Fix building Samba with gcc 8.1; (bso#13437); + s3:utils: Do not segfault on error in DoDNSUpdate(); (bso#13440); + smbd: Flush dfree memcache on service reload; (bso#13446); + ldb: Save a copy of the index result before calling the + lib/util: No Backtrace given by Samba's AD DC by default; (bso#13454). + s3: smbd: printing: Re-implement delete-on-close semantics for print files missing since 3.5.x; (bso#13457). + python: Fix talloc frame use in make_simple_acl(); (bso#13474). + krb5_wrap: Fix keep_old_entries logic for older Kerberos libraries;(bso#13478). + krb5_plugin: Add winbind localauth plugin for MIT Kerberos; (bso#13480).- Add missing package descriptions; (bsc#1093864); - Fix dependency issue between samba-python and samba-kdc; (bsc#1062876); - Call update-apparmor-samba-profile when running samba-ad-dc; (bsc#1092099);- Update to 4.8.2 + After update to 4.8.0 DC failed with "Failed to find our own NTDS Settings objectGUID" (bso#13335). + fix incorrect reporting of stream dos attributes on a directory (bso#13380). + vfs_ceph: add asynchronous fsync; fake synchronous call (bso#13412). + vfs_ceph: add fake async pwrite/pread send/recv hooks; (bso#13425) + vfs_ceph: Fix memory leak; (bso#13424). + libsmbclient: Fix hard-coded connection error return of ETIMEDOUT; (bso#13419). + s4-lsa: Fix use-after-free in LSA server; (bso#13420). + winbindd: Do re-connect if the RPC call fails in the passdb case; (bso#13430). + cleanupd: Sends MSG_SMB_UNLOCK twice to interested peers; (bso#13416). + cleanupd: Use MSG_SMB_BRL_VALIDATE to signal cleanupd unclean process shutdown; (bso#13414). + ctdb-client: Remove ununsed functions from old client code; (bso#13411). + printing: Return the same error code as windows does on upload failures; (bso#13395). + nsswitch: Fix memory leak in winbind_open_pipe_sock() when the privileged pipe is not accessable; (bso#13400). + s4:lsa_lookup: remove TALLOC_FREE(state) after all dcesrv_lsa_Lookup{Names,Sids}_base_map() calls; (bso#13420). + rpc_server: Fix NetSessEnum with stale sessions; (bso#13407). + s3:smbspool: Fix cmdline argument handling; (bso#13417).- Move libdfs-server-ad-samba4.so library from kdc to libs package, as it is required by some client libs; (bsc#1074135); - Update to 4.8.1; (bsc#1091179); + s3: ldap: Ensure the ADS_STRUCT pointer doesn't get freed on error, we don't own it here; (bso#13244); + s3: smbd: Fix possible directory fd leak if the underlying OS doesn't support fdopendir(); (bso#13270); + Round-tripping ACL get/set through vfs_fruit will increase the number of ACE entries without limit; (bso#13319); + s3: smbd: SMB2: Add DBGC_SMB2_CREDITS class to specifically debug credit issues; (bso#13347); + s3: smbd: Files or directories can't be opened DELETE_ON_CLOSE without delete access; (bso#13358); + s3: smbd: Fix memory leak in vfswrap_getwd(); (bso#13372); + s3: smbd: Unix extensions attempts to change wrong field in fchown call; (bso#13375); + ms_schema/samba-tool visualize: Fix python2.6 incompatibility; (bso#13337); + Fix invocation of gnutls_aead_cipher_encrypt(); (bso#13352); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + winbindd: Recover loss of netlogon secure channel in case the peer DC is rebooted; (bso#13332); + s3:smbd: Don't use the directory cache for SMB2/3; (bso#13363); + ctdb-client: Fix bugs in client code; (bso#13356); + ctdb-scripts: Drop "net serverid wipe" from 50.samba event script; (bso#13359); + s3: lib: messages: Don't use the result of sec_init() before calling sec_init(); (bso#13368); + libads: Fix the build '--without-ads'; (bso#13273); + winbind: Keep "force_reauth" in invalidate_cm_connection, add 'smbcontrol disconnect-dc'; (bso#13332); + vfs_virusfilter: Fix CIDs 1428738-1428740; (bso#13343); + dsdb: Fix CID 1034966 Uninitialized scalar variable; (bso#13367); + rpc_server: Fix core dump in dfsgetinfo; (bso#13370); + smbclient: Fix notify; (bso#13382); + Fix smbd panic if the client-supplied channel sequence number wraps; (bso#13215); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + lib/util: Remove unused '#include ' from tests/tfork.c; (bso#13342); + Fix build errors with cc from developerstudio 12.5 on Solaris; (bso#13343); + Fix the picky-developer build on FreeBSD 11; (bso#13344); + s3:modules: Fix the build of vfs_aixacl2.c; (bso#13345); + s3:smbd: map nterror on smb2_flush errorpath; (bso#13338); + lib:replace: Fix linking when libtirpc-devel overwrites system headers; (bso#13341); + winbindd: 'wbinfo --name-to-sid' returns misleading result on invalid query; (bso#13312); + s3:passdb: Do not return OK if we don't have pinfo set up; (bso#13376); + Allow AESNI to be used on all processor supporting AESNI; (bso#13302);- Use new foreground execution flags for systemd samba daemons; (bsc#1088574); (bsc#1071090); (bsc#1065551); + Add %post scriptlet to clear old sysconfig flags - Update vendor-files to commit 880b3e7. + Set samba sysconfig template variables to "" + Add required daemon flags directly to systemd unit- Specfile cleanup + Remove %if..%endif guards which don't affect the build + Remove redundant %clean section + Replace old $RPM_* shell vars with macros- BuildRequire pkgconfig(systemd) and pkgconfig(libsystemd) in place of systemd and systemd-devel: Allow OBS to optimize the workload by allowing the usage of the 'build-optimized' systemd packages.- Enable building samba with python3, and create a samba-python3 package.- Update to 4.8 + New GUID Index mode in sam.ldb for the AD DC + GPO support for samba KDC + Time machine support with vfs_fruit + Encrypted secrets + AD Replication visualization + Improved trust support - ability to not scan global trust list - AD external trusts have limited support - verbose trusted domain listing + VirusFilter VFS module + NT4-style replication removed + vfs_aio_linux removed- Disable samba-pidl package, due to the removal of dependency perl-Parse-Yapp; (bsc#1085150);- Update to 4.7.6; + CVE-2018-1050: DOS vulnerability when SPOOLSS is run externally; (bso#11343); (bsc#1081741); + CVE-2018-1057: Authenticated users can change other users' password; (bso#13272); (bsc#1081024).- Disable python until full python3 port is done; (bsc#1082139); + Remove contents of package samba-python + Remove contents of package libsamba-policy0 + Remove contents of package libsamba-policy-devel + Remove library libsamba-python-samba4.so from samba-libs package + Remove library libsamba-net-samba4.so from samba-libs package + Remove smbtorture binary and manpage from samba-test- samba fails to build with glibc2.27; (bsc#1081042);- Update to 4.7.5; (bsc#1080545); + smbd tries to release not leased oplock during oplock II downgrade; (bso#13193); + Fix copying file with empty FinderInfo from Windows client to Samba share with fruit; (bso#13181); + build: Deal with recent glibc sunrpc header removal; (bso#10976); + Make Samba work with tirpc and libnsl2; (bso#13238); + vfs_ceph: Add fs_capabilities hook to avoid local statvfs; (bso#13208); (bsc#1075206); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + ctdb-recovery-helper: Deregister message handler in error paths; (bso#13188); + samba: Only use async signal-safe functions in signal handler; (bso#13240); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + repl_meta_data: Fix linked attribute corruption on databases with unsorted links on expunge. dbcheck: Add functionality to fix the corrupt database; (bso#13228); + Fix smbd panic when chdir returns error during exit; (bso#13189); + Make Samba work with tirpc and libnsl2; (bso#13238); + Fix POSIX ACL support on HPUX and possibly other big-endian OSs; (bso#13176);- Update to 4.7.4; (bsc#1080545); + s3: smbclient: Implement 'volume' command over SMB2; (bso#13140); + s3: libsmb: Fix valgrind read-after-free error in cli_smb2_close_fnum_recv(); (bso#13171); + s3: libsmb: Fix reversing of oldname/newname paths when creating a reparse point symlink on Windows from smbclient; (bso#13172); + Build man page for vfs_zfsacl.8 with Samba; (bso#12934); + repl_meta_data: Allow delete of an object with dangling backlinks; (bso#13095); + s4:samba: Fix default to be running samba as a deamon; (bso#13129); + Performance regression in DNS server with introduction of DNS wildcard, ldb: Release 1.2.3; (bso#13191); + vfs_zfsacl: Fix compilation error; (bso#6133); + "smb encrypt" setting changes are not fully applied until full smbd restart; (bso#13051); + winbindd: Fix idmap_rid dependency on trusted domain list; (bso#13052); + vfs_fruit: Proper VFS-stackable conversion of FinderInfo; (bso#13155); + winbindd: Dependency on trusted-domain list in winbindd in critical auth codepath; (bso#13173); + repl_meta_data: Fix removing of backlink on deleted objects; (bso#13120); + ctdb: sock_daemon leaks memory; (bso#13153); + TCP tickles not getting synchronised on CTDB restart; (bso#13154); + winbindd: winbind parent and child share a ctdb connection; (bso#13150); + pthreadpool: Fix deadlock; (bso#13170); + pthreadpool: Fix starvation after fork; (bso#13179); + messaging: Always register the unique id; (bso#13180); + s4/smbd: set the process group; (bso#13129); + Fix broken linked attribute handling; (bso#13095); + The KDC on an RWDC doesn't send error replies in some situations; (bso#13132); + libnet_join: Fix 'net rpc oldjoin'; (bso#13149); + g_lock conflict detection broken when processing stale entries; (bso#13195); + s3:smb2_server: allow logoff, close, unlock, cancel and echo on expired sessions; (bso#13197); + s3:libads: net ads keytab list fails with "Key table name malformed"; (bso#13166); (bsc#1067700); + Fix crash in pthreadpool thread after failure from pthread_create; (bso#13170); + s4:samba: Allow samba daemon to run in foreground; (bso#13129); (bsc#1065551); + third_party: Link the aesni-intel library with "-z noexecstack"; (bso#13174); + vfs_glusterfs: include glusterfs/api/glfs.h without relying on "-I" options; (bso#13125);- Re-enable usage of libnsl (did got lost with glibc change) - Use TI-RPC (sunrpc is deprecated and will be removed soon from glibc)- smbc_opendir should not return EEXIST with invalid login credentials; (bnc#1065868).- Update to 4.7.3; (bsc#1069666); + Non-smbd processes using kernel oplocks can hang smbd; (bso#13121); + python: use communicate to fix Popen deadlock; (bso#13127); + smbd on disk file corruption bug under heavy threaded load; (bso#13130); + tevent: version 0.9.34; (bso#13130); + s3: smbd: Fix delete-on-close after smb2_find; (bso#13118); + CVE-2017-14746: s3: smbd: Fix SMB1 use-after-free crash bug; (bsc#1060427);(bso#13041); + CVE-2017-15275: s3: smbd: Chain code can return uninitialized memory when talloc buffer is grown; (bsc#1063008); (bso#13077); - Build with AD DC support only in openSUSE.- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- samba-tool requires samba-python; (bnc#1067771).- Run all daemons in the foreground and let systemd handle it; (bsc#1065551). - Update to 4.7.1; + Fix exporting subdirs with shadow_copy2; (bso#13091); + Currently if getwd() fails after a chdir(), we panic; (bso#13027); + Ensure default SMB_VFS_GETWD() call can't return a partially completed struct smb_filename; (bso#13068); + sys_getwd() can leak memory or possibly return the wrong errno on older systems; (bso#13069); + smbclient doesn't correctly canonicalize all local names before use; (bso#13093); + Fix broken linked attribute handling; (bso#13095); + Missing LDAP query escapes in DNS rpc server; (bso#12994); + Link to -lbsd when building replace.c by hand; (bso#13087); + Cannot delete non-ACL files on Solaris/ZFS/NFSv4 ACL filesystem; (bso#6133); + Map SYNCHRONIZE acl permission statically in zfs_acl vfs module; (bso#7909); + Samba fails to honor SEC_STD_WRITE_OWNER bit with the acl_xattr module; (bso#7933); + Missing assignment in sl_pack_float; (bso#12991); + Wrong Samba access checks when changing DOS attributes; (bso#12995); + samba_runcmd_send() leaves zombie processes on timeout; (bso#13062); + groupmap cleanup should not delete BUILTIN mappings; (bso#13065); + Enabling vfs_fruit results in loss of Finder tags and other xattrs; (bso#13076); + man pages: Properly ident lists; (bso#9613); + smb.conf.5: Sort parameters alphabetically; (bso#13081); + Fix GUID string format on GetPrinter info; (bso#12993); + Remote serverid check doesn't check for the unique id; (bso#13042); + CTDB starts consuming memory if there are dead nodes in the cluster; (bso#13056); + ctdb-common: Ignore event scripts with multiple '.'s; (bso#13070); + libgpo doesn't sort the GPOs in the correct order; (bso#13046); + Remote serverid check doesn't check for the unique id; (bso#13042); + vfs_catia: Fix a potential memleak; (bso#13090); + Fix file change notification for renames; (bso#12903); + Samba DNS server does not honour wildcards; (bso#12952); + Can't change password in samba from a Windows client if Samba runs on IPv6 only interface; (bso#13079); + vfs_fruit: Replace closedir() by SMB_VFS_CLOSEDIR; (bso#13086); + Apple client can't cope with SMB2 async replies when creating symlinks; (bso#13047); + s4:rpc_server:backupkey: Move variable into scope; (bso#12959); + Fix ntstatus_gen.h generation on 32bit; (bso#13099); + Fix a double free in vfs_gluster_getwd(); (bso#13100); + Fix resouce leaks and pointer issues; (bso#13101); + vfs_solarisacl: Fix build for samba 4.7 and up; (bso#13049);- Add samba-kdc to baselibs.conf. - Do not wrap samba-kdc's package definition into if/endif: the package won't be generated simply based on the fact that there is no files section for the package. Allows the source validator to ensure samba-kdc is a built package.- Update to 4.7.0; + Whole DB read locks: Improved LDAP and replication consistency; (bso#12858). + Samba AD with MIT Kerberos + Dynamic RPC port range: Default range changed from "1024-1300" to "49152-65535". + Authentication and Authorization audit support: New auth_audit debug class. + Multi-process LDAP Server: The LDAP server in the AD DC now honours the process model used for the rest of the 'samba' process. + Improved Read-Only Domain Controller (RODC) Support; (bso#12977). + Additional password hashes stored in supplementalCredentials. + Improvements to DNS during Active Directory domain join. + Significant AD performance and replication improvements. + Query record for open file or directory. + Removal of lpcfg_register_defaults_hook(). + Change of loadable module interface. + SHA256 LDAPS Certificates: The self-signed certificate generated for use on LDAPS will now be generated with a SHA256 self-signature, not a SHA1 self-signature. + CTDB no longer allows mixed minor versions in a cluster. + CTDB now ignores hints from Samba about TDB flags when attaching to databases. + New configuration variable CTDB_NFS_CHECKS_DIR. + The CTDB_SERVICE_AUTOSTARTSTOP configuration has been removed. + The CTDB_SCRIPT_DEBUGLEVEL configuration variable has been removed. + The example NFS Ganesha call-out has been improved. + A new "replicated" database type is available.- CVE-2017-12163: Prevent client short SMB1 write from writing server memory to file; (bso#13020); (bsc#1058624).- CVE-2017-12150: Some code path don't enforce smb signing, when they should; (bso#12997); (bsc#1058622).- CVE-2017-12151: Keep required encryption across SMB3 dfs redirects; (bso#12996); (bsc#1058565).- Clean specfile assuming SUSE-only system and product >=SLE11 + %{ul_version}, %{rhel_version}, %{mandriva_version}, %{centos_version} are always undefined + %{_vendor} is "suse" and %{suse_version} is at least 1100- Update to 4.6.7; (bsc#1054017) + Joining a Huawai storage fails: empty CLDAP ping answer; (bso#11392). + smbcacls can fail against a directory on Windows using SMB2.; (bso#12937). + vfs_ceph provides inconsistent directory listings; (bso#12911). + Misused talloc context can cause a user to crash their smbd by chaining SMB1 commands.; (bso#12836). + Use-after free can crash libsmbclient code.; (bso#12927). + Server exit with active AIO can crash.; (bso#12925). + Ensure notifyd doesn't return from smbd_notifyd_init; (bso#12910). + fd leak to ctdb sub-processes leads to SELinux AVC denial in audit logs; (bso#12898). + vfs_fruit shouldn't send MS NFS ACEs to Windows clients; (bso#12897). + smbspool_krb5_wrapper does not tell CUPS that it requires negotiate for authentication; (bso#12886). + finder sidebar showing question mark instead of icon when using ip to connect with vfs_fruit; (bso#12840). + Winbind stops obtaining the 'unixHomeDirectory' & 'loginShell' attributes from AD.; (bso#12720). + KCC run at selftest startup can fail spuriously due to a race; (bso#12869). + winbindd changes the local password and gets NT_STATUS_WRONG_PASSWORD for the remote change; (bso#12782). + rpc_pipe_client memory leaks due to long term memory context passed to rpc_pipe_open_interface(); (bso#12890). + CVE-2017-2619 breaks accessing previous versions of directories with snapshots in subdirectories of the share; (bso#12885). + dns_name_equal doing OOB read; (bso#12813). + replica_sync tests flap; (bso#12753). + Selftest should not call 'net cache flush' and wipe important winbind entries; (bso#12868). + Old Samba versions don't support using recent ldb versions (>=1.1.30); (bso#12859). + pam_winbind fails with kerberos method = secrets and keytab; (bso#10490). + race starting winbindd against posixacl test; (bso#12843). + Crash in the reentrant smbd_smb2_create_send() if the something fails in the subsequent try; (bso#12832). + spnego.c passes the wrong argument order to gensec_update_ev() for the FALLBACK case; (bso#12788). + Clients with SMB3 support can't connect with "server max protocol = SMB2_02"; (bso#12772). + A log message of samb-tool user syncpasswords reverses string arguments in a debug message "Call Popen[...".; (bso#12768). + The smb tarmode tests kills the share dir contents; (bso#12867). + Fix for a bug in MacOS X Sierra NTLMv2 processing; (bso#12862). + CVE-2017-2619 regression with non-wide symlinks to directories; (bso#12860). + manpage/index.html lists links not in alphabetical order; (bso#12854). + smbcacls got error NT_STATUS_NETWORK_NAME_DELETED; (bso#12831). + If a record is locked in a database, then recovery does not complete; (bso#12857). + debug_locks.sh script does not log any information; (bso#12856). + SIGSEGV in cm_connect_lsa_tcp dereferencing conn->lsa_tcp_pipe->transport after error; (bso#12852). + smbclient can't parse DOMAIN+username if a different winbind separator is used; (bso#12849). + Related requests with SessionSetup fail with INTERNAL_ERROR; (bso#12845). + Related requests with TreeConnect fail with NETWORK_NAME_DELETED; (bso#12844). + cli->server_os not filled correctly; (bso#12779). + REGRESSION: smbclient doesn't print the session setup anymore; (bso#12824). + smblcient doesn't handle STATUS_NOT_SUPPORTED gracefully for FSCTL_VALIDATE_NEGOTIATE_INFO; (bso#12808). + CTDB NFS call-out failures do not cause event failures; (bso#12837). + net command fails due to incorrectly return code; (bso#12828). + Fix building Samba with GCC 7.1; (bso#12827).- Fix duplicate CTDB_LOGGING params when downgraded and upgraded again; (bsc#1048339).- fix cephwrap_chdir(); (bsc#1048790). - Update to 4.6.6 + CVE-2017-11103: Orpheus' Lyre KDC-REP service name validation; (bsc#1048278).- Fix ctdb logs to /var/log/log.ctdb instead of /var/log/ctdb; (bsc#1048339).- Fix inconsistent ctdb socket path; (bsc#1048352). - Fix non-admin cephx authentication; (bsc#1048387).- Update to 4.6.5; (bsc#1040157) + Specifying CTDB_LOGGING=syslog:nonblocking causes ctdbd to crash at startup; (bso#12814). + vfs_expand_msdfs tries to open the remote address as a file path; (bso#12687). + PANIC (pid 1096): assert failed: lease_type_is_exclusive(e_lease_type); (bso#12798). + With clustering get update_num_read_oplocks failed and PANIC: num_share_modes == 1 assertion failure; (bso#11844). + contend_level2_oplocks_begin_default oplock optimisation doesn't carry over to leases; (bso#12766). + `ctdb nodestatus` incorrectly displays status for all nodes with wrong exit code; (bso#12802). + CTDB can spin hard on revoking readonly delegations if a node becomes disconnected; (bso#12697). + Printing a share mode entry with leases can crash in the ndr code; (bso#12793). + Fix flakey unit tests for eventd; (bso#12792). + CTDB daemon crashes if built with clang; (bso#12770). + smbcacls fails if no password is specified; (bso#12765). + idmap_rfc2307: Lookup of more than two SIDs fails; (bso#12757). + samba-tool user syncpasswords doesn't trigger the script when a user gets removed; (bso#12767). + systemd: fix detection of libsystemd; (bso#12764). + Notify subsystem only maps first inotify mask to Windows notify filter; (bso#12760). + Allow passing trusted domain password as plain-text to PASSDB layer; (bso#12751). + Can't case-rename files with vfs_fruit; (bso#12749). + wrong sid->uid mapping for SIDs residing in sIDHistory; (bso#12702). + vfs_acl_common should force "create mask = 0777", not 0666; (bso#12562). + Ordering of notify responses broken; (bso#12756).- s3: libsmb: Fix error where short name length was read as 2 bytes, should be 1; (bso#11822); (bsc#1042419).- Revert explicit winbind %{version}-%{release} dependency. + The ABI has stabilized since (bsc#936909), so remove to fix cross-media dependencies; (bsc#1037899).- Fix CVE-2017-7494 remote code execution from a writable share; (bso#12780); (bsc#1038231).- Update to 4.6.3; (bsc#1036011) + s3:vfs:shadow_copy2: vfs_shadow_copy2 fails to list snapshots from shares with GlusterFS backend; (bso#12743). + Fix for Solaris C compiler; (bso#12559). + s3: locking: Update oplock optimization for the leases era; (bso#12628). + Make the Solaris C compiler happy; (bso#12693). + s3: libgpo: Allow skipping GPO objects that don't have the expected LDAP attributes; (bso#12695). + Fix buffer overflow caused by wrong use of getgroups; (bso#12747). + lib: debug: Avoid negative array access; (bso#12746). + cleanupdb: Fix a memory read error; (bso#12748). + streams_xattr and kernel oplocks results in NT_STATUS_NETWORK_BUSY; (bso#7537). + winbindd: idmap_autorid allocates ids for unknown SIDs from other backends; (bso#11961). + vfs_fruit: Resource fork open request with flags=O_CREAT|O_RDONLY; (bso#12565). + manpages/vfs_fruit: Document global options; (bso#12615). + lib/pthreadpool: Fix a memory leak; (bso#12624). + Lookup-domain for well-known SIDs on a DC; (bso#12727). + winbindd: Fix error handling in rpc_lookup_sids(); (bso#12728). + winbindd: Trigger possible passdb_dsdb initialisation; (bso#12729). + credentials_krb5: use gss_acquire_cred for client-side GSSAPI use case; (bso#12611). + lib/crypto: Implement samba.crypto Python module for RC4; (bso#12690). + ctdb-readonly: Avoid a tight loop waiting for revoke to complete; (bso#12697). + ctdb_event monitor command crashes if event is not specified; (bso#12723). + ctdb-docs: Fix documentation of "-n" option to 'ctdb tool'; (bso#12733). + smbd: Fix smb1 findfirst with DFS; (bso#12558). + smbd: Do an early exit on negprot failure; (bso#12610). + winbindd: Fix substitution for 'template homedir'; (bso#12699). + s4:kdc: Disable principal based autodetected referral detection; (bso#12554). + idmap_autorid: Allocate new domain range if the callers knows the sid is valid; (bso#12613). + LINKFLAGS_PYEMBED should not contain -L/some/path; (bso#12724). + PAM auth with WBFLAG_PAM_GET_PWD_POLICY returns wrong policy for trusted domain; (bso#12725). + rpcclient: Allow -U'OTHERDOMAIN\user' again; (bso#12731). + winbindd: Fix password policy for pam authentication; (bso#12725). + s3:gse: Correctly handle external trusts with MIT; (bso#12554). + auth/credentials: Always set the realm if we set the principal from the ccache; (bso#12611). + replace: Include sysmacros.h; (bso#12686). + s3:vfs_expand_msdfs: Do not open the remote address as a file; (bso#12687). + s3:libsmb: Only print error message if kerberos use is forced; (bso#12704). + winbindd: Child process crashes when kerberos-authenticating a user with wrong password; (bso#12708). + vfs_fruit: Office document opens as read-only on macOS due to CNID semantics; (bso#12715). + vfs_acl_xattr: Fix failure to get ACL on Linux if memory is fragmented; (bso#12737).- Generate and update vendor-files tarball from Git + SuSEfirewall2 service samba-client only setup IPv4 rule; (bsc#1034416).- Generate source tarball directly from Git using OBS tar_scm + use version string derived from parent Git tag and commit hash - remove obsolete vendor-files/tools/package-data version ID + explicitly generate ctdb manpages, needed without "make dist"- Update to 4.6.2 + remove bso#12721 patches now upstream- Enable samba-ceph build for openSUSE and SLE12SP3+; (fate#321622). + x86-64 and aarch64- Enable librados CTDB lock helper for samba-ceph package; (fate#321622).- Build and install the html man pages (bsc#1021907).- Fix CVE-2017-2619 regression with "follow symlinks = no"; (bso#12721).- Update to 4.6.1 + symlink race permits opening files outside share directory; CVE-2017-2619; (bso#12496); (bsc#1027147) + testparm checks for valid idmap parameters + add new krb client encryption types + support for printer driver upload from windows 10 + inherit owner = 'unix only' for improved quota support + improved CTDB event support + new primary group support for idmap_ad + idmap_hash deprecated + mvxattr added to recursively rename extended attributes- Remove chkconfig requirements for systemd systems- Don't call insserv if systemd is used- Fix check if we need to require insserv- async_req: make async_connect_send() "reentrant"; (bso#12105); (bsc#1024416).- Force usage of ncurses6-config thru NCURSES_CONFIG env var; (bsc#1023847).- add missing patch for libnss_wins segfault; (bsc#995730).- Fix vfs_ceph builds against recent Ceph versions; (bsc#1021933).- Document "winbind: ignore domains" parameter; (bsc#1019416).- Add base Samba dependency to samba-ceph package.- Update to 4.5.3 + Heap-based Buffer Overflow Remote Code Execution Vulnerability; CVE-2016-2123; (bso#12409); (bsc#1014437). + Don't send delegated credentials to all servers; CVE-2016-2125; (bso#12445); (bsc#1014441). + denial of service due to a client triggered crash in the winbindd parent process; CVE-2016-2126; (bso#12446); (bsc#1014442). - 4.5.1 and 4.5.2 updates + various streams vfs fixes + various printing fixes + ntlm_auth: do not map explicitly empty domain + various stability fixes in smbd + match file compression ReFS behavior- Add missing ldb module directory; (bnc#1012092).- s3/client: obey 'disable netbios' smb.conf param, don't connect via NBT port; (bsc#1009085); (bso#12418).- Include vfstest in samba-test; (bsc#1001203).- s3/winbindd: using default domain with user@domain.com format fails; (bsc#997833).- Fix segfault in libnss_wins; (bso#12277); (bso#12269); (bsc#995730).- Update to 4.5.0 + NTLM1 Authentication disabled by default + SMB2.1 leases enabled by default + Support for OFD locks + ctdb tool rewritten + Added shadow copy snapshot prefix parameter- Fix illegal memory access after memory has been deleted; (bso#11836); (bsc#975299).- Prevent core, make sure response->extra_data.data is always cleared out; (bsc#993692).- Don't package man pages for VFS modules that aren't built; (boo#993707).- Fix population of ctdb sysconfig after source merge; (bsc#981566).- Enable vfs_ceph builds for Factory (x86-64) + Package as samba-ceph to avoid Ceph dependency in base package.- Update to 4.4.5 + Prevent client-side SMB2 signing downgrade; CVE-2016-2119; (bso#11860); (bsc#986869).- Remove obsolete syslog.target; (bsc#983938).- Honor smb.conf socket options in winbind; (bsc#975131).- Don't use htons() with IP_PROTO_RAW; (bso#11705); (bsc#969522).- Update to 4.4.4 + SMB3 multichannel: Add implementation of missing channel sequence number verification; (bso#11809). + smbd:close: Only remove kernel share modes if they had been taken at open; (bso#11919). + notifyd: Prevent NULL deref segfault in notifyd_peer_destructor; (bso#11930). + s3:rpcclient: Make '--pw-nt-hash' option work; (bso#10796). + Fix case sensitivity issues over SMB2 or above; (bso#11438). + s3:smbd: Fix anonymous authentication if signing is mandatory. (bso#11910) + Fix NTLM Authentication issue with squid; (bso#11914). + pdb: Fix segfault in pdb_ldap for missing gecos; (bso#11530). + Fix memory leak in share mode locking; (bso#11934).- Update to 4.4.3 + Various post-badlock regressions; (bso#11841); (bso#11850); (bso#11858); (bso#11870); (bso#11872). + Only allow idmap_hash for default idmap config (bso#11786). + smbd: Avoid large reads beyond EOF; (bso#11878). + vfs_acl_common: Avoid setting POSIX ACLs if "ignore system acls" is set; (bso#11806). + libads: Record session expiry for spnego sasl binds; (bso#11852).- Fix NTLMSSP regressions caused by previous CVE fixes; (bso#11849); (bsc#975962); (bsc#979268), (bsc#977669).- Revert shared library packaging to comply with SLPP- Update to 4.4.2 + A man-in-the-middle can downgrade NTLMSSP authentication; CVE-2016-2110; (bso#11688); (bsc#973031). + Domain controller netlogon member computer can be spoofed; CVE-2016-2111; (bso#11749); (bsc#973032). + LDAP conenctions vulnerable to downgrade and MITM attack; CVE-2016-2112; (bso#11644); (bsc#973033). + TLS certificate validation missing; CVE-2016-2113; (bso#11752); (bsc#973034). + Named pipe IPC vulnerable to MITM attacks; CVE-2016-2115; (bso#11756); (bsc#973036). + "Badlock" DCERPC impersonation of authenticated account possible; CVE-2016-2118; (bso#11804); (bsc#971965). + DCERPC server and client vulnerable to DOS and MITM attacks; CVE-2015-5370; (bso#11344); (bsc#936862).- Fix samba.tests.messaging test and prevent potential tdb corruption by removing obsolete now invalid tdb_close call; (bsc#974629).- Obsolete libsmbclient from libsmbclient0 while not providing it; (bsc#972197).- Update to 4.4.0. + Read of uninitialized memory DNS TXT handling; (bso#11128); (bso#11686); CVE-2016-0771. + Getting and setting Windows ACLs on symlinks can change permissions on link target; (bso#11648); CVE-2015-7560. + Sockets with htons(IPPROTO_RAW); (bso#11705); CVE-2015-8543. + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystem with no ACL support; (bso#10489). + docs: Add example for domain logins to smbspool man page; (bso#11643). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + docs: Add smbspool_krb5_wrapper manpage; (bso#11690). + winbindd: Return trust parameters when listing trusts; (bso#11691). + ctdb: Do not provide a useless pkgconfig file for ctdb; (bso#11696). + Crypto.Cipher.ARC4 is not available on some platforms, fallback to M2Crypto.RC4.RC4 then; (bso#11699). + s3:utils/smbget: Set default blocksize; (bso#11700). + Streamline 'smbget' options with the rest of the Samba utils; (bso#11700). + s3:clispnego: Fix confusing warning in spnego_gen_krb5_wrap(); (bso#11702). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + s3:vfs:glusterfs: Fix build after quota changes; (bso#11715). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + lib:socket: Fix CID 1350010: Integer OVERFLOW_BEFORE_WIDEN; (bso#11723). + smbd: Fix CID 1351215 Improper use of negative value; (bso#11724). + smbd: Fix CID 1351216 Dereference null return value; (bso#11725). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + docs: Add manpage for cifsdd; (bso#11730). + param: Fix str_list_v3 to accept ; again; (bso#11732). + lib/socket: Fix improper use of default interface speed; (bso#11734). + lib:socket: Fix CID 1350009: Fix illegal memory accesses (BUFFER_SIZE_WARNING); (bso#11735). + libcli: Fix debug message, print sid string for new_ace trustee; (bso#11738). + Fix installation path of Samba helper binaries; (bso#11739). + Fix memory leak in loadparm; (bso#11740). + tevent: version 0.9.28: Fix memory leak when old signal action restored; (bso#11742). + smbd: Ignore SVHDX create context; (bso#11753). + Fix net join; (bso#11755). + s3:libads: setup the msDS-SupportedEncryptionTypes attribute on ldap_add; (bso#11755). + passdb: Add linefeed to debug message; (bso#11763). + s3:utils/smbget: Fix option parsing; (bso#11767). + libnet: Make Kerberos domain join site-aware; (bso#11769). + Reset TCP Connections during IP failover; (bso#11770). + ldb: Version 1.1.26; (bso#11772). + s3:smbd: Add negprot remote arch detection for OSX; (bso#11773). + vfs_glusterfs: Fix use after free in AIO callback; (bso#11774). + mkdir can return ACCESS_DENIED incorrectly on create race; (bso#11780). + "trustdom_list_done: Got invalid trustdom response" message should be avoided; (bso#11782). + Mismatch between local and remote attribute ids lets replication fail with custom schema; (bso#11783). + Quota is not supported on Solaris 10; (bso#11788). + Talloc: Version 2.1.6; (bso#11789). + smbd: Enable multi-channel if 'server multi channel support = yes' in the config; (bso#11796). + build: Fix build when '--without-quota' specified; (bso#11798). + lib/socket/interfaces: Fix some uninitialied bytes; (bso#11802). + Access based share enum: handle permission set in configuration files; (bso#8093). + See also WHATSNEW.txt from the samba-doc package.- Update to 4.3.6. + Getting and setting Windows ACLs on symlinks can change permissions on link target; CVE-2015-7560; (bso#11648); (bsc#968222). + Fix Out-of-bounds read in internal DNS server; CVE-2016-0771; (bso#11128); (bso#11686); (bsc#968223).- Upgrade on-disk FSRVP server state to new version; (bsc#924519).- Only obsolete but do not provide gplv2/3 package names; (bsc#968973).- Relocate existing lock files to /var/lib/samba/lock; (bsc#968963).- Obsolete no longer existing samba-32bit package; (bsc#967625).- Update to 4.3.5. + s3:utils/smbget: Fix recursive download; (bso#6482). + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystemi with no ACL support; (bso#10489). + s3:smbd/oplock: Obey kernel oplock setting when releasing oplocks; (bso#11400). + vfs_shadow_copy2: Fix case where snapshots are outside the share; (bso#11580). + smbclient: Query disk usage relative to current directory; (bso#11662). + winbindd: Handle expired sessions correctly; (bso#11670). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + smbcacls: Fix uninitialized variable; (bso#11682). + s3:smbd: Ignore initial allocation size for directory creation; (bso#11684). + s3-client: Add a KRB5 wrapper for smbspool; (bso#11690). + s3-parm: Clean up defaults when removing global parameters; (bso#11693). + Use M2Crypto.RC4.RC4 on platforms without Crypto.Cipher.ARC4; (bso#11699). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + ctdb: Remove error messages after kernel security update; CVE-2015-8543; (bso#11705). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + param: Fix str_list_v3 to accept ";" again; (bso#11732).- Shift samba-client sysconfig data into samba and samba-winbind; (bsc#947361).- Simplify shared library packaging; (bsc#966956).- Enable clustering (CTDB) support; (bsc#966271).- s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703); (bsc#964023).- Add quotes around path of update-apparmor-samba-profile; (bnc#962177).- Remove autoconf build-time requirement.- Update to 4.3.4. + vfs_fruit: Enable POSIX directory rename semantics; (bso#11065). + Crash: Bad talloc magic value - access after free; (bso#11394). + Copying files with vfs_fruit fails when using vfs_streams_xattr without stream prefix and type suffix; (bso#11466). + samba-tool: Fix uncaught exception if no fSMORoleOwner attribute is given; (bso#11613). + Fix a typo in the smb.conf manpage, explanation of idmap config; (bso#11619). + Correctly initialize the list head when keeping a list of primary followed by DFS connections; (bso#11624). + Reduce the memory footprint of empty string options; (bso#11625). + lib/async_req: Do not install async_connect_send_test; (bso#11639). + Fix typos in man vfs_gpfs; (bso#11641). + Make "hide dot files" option work with "store dos attributes = yes"; (bso#11645). + Fix a corner case of the symlink verification; (bso#11647); (bnc#960249). + Do not disable "store dos attributes" on-the-fly; (bso#11649). + Update lastLogon and lastLogonTimestamp; (bso#11659).- Prevent access denied if the share path is "/"; (bso#11647); (bnc#960249).- Update to 4.3.3. + Malicious request can cause Samba LDAP server to hang, spinning using CPU; CVE-2015-3223; (bso#11325); (bnc#958581). + Remote read memory exploit in LDB; CVE-2015-5330; (bso#11599); (bnc#958586). + Insufficient symlink verification (file access outside the share); CVE-2015-5252; (bso#11395); (bnc#958582). + No man in the middle protection when forcing smb encryption on the client side; CVE-2015-5296; (bso#11536); (bnc#958584). + Currently the snapshot browsing is not secure thru windows previous version (shadow_copy2); CVE-2015-5299; (bso#11529); (bnc#958583). + Fix Microsoft MS15-096 to prevent machine accounts from being changed into user accounts; CVE-2015-8467; (bso#11552); (bnc#958585).- Update to 4.3.2. + vfs_gpfs: Re-enable share modes; (bso#11243). + dcerpc.idl: Accept invalid dcerpc_bind_nak pdus; (bso#11327). + s3-smbd: Fix old DOS client doing wildcard delete - gives an attribute type of zero; (bso#11452). + Add libreplace dependency to texpect, fixes a linking error on Solaris; (bso#11511). + s4: Fix linking of 'smbtorture' on Solaris; (bso#11512). + s4:lib/messaging: Use correct path for names.tdb; (bso#11562). + Fix segfault of 'net ads (join|leave) -S INVALID' with nss_wins; (bso#11563). + async_req: Fix non-blocking connect(); (bso#11564). + auth: gensec: Fix a memory leak; (bso#11565). + lib: util: Make non-critical message a warning; (bso#11566). + Fix winbindd crashes with samlogon for trusted domain user; (bso#11569); (bnc#949022). + smbd: Send SMB2 oplock breaks unencrypted; (bso#11570). + ctdb: Open the RO tracking db with perms 0600 instead of 0000; (bso#11577). + s3:smb2_server: Make the logic of SMB2_CANCEL DLIST_REMOVE() clearer; (bso#11581). + s3-smbd: Fix use after issue in smbd_smb2_request_dispatch(); (bso#11581). + manpage: Correct small typo error; (bso#11584). + s3: smbd: If EAs are turned off on a share don't allow an SMB2 create containing them; (bso#11589). + Backport some valgrind fixes from upstream master; (bso#11597). + auth: Consistent handling of well-known alias as primary gid; (bso#11608). + winbind: Fix crash on invalid idmap configs; (bso#11612). + s3: smbd: have_file_open_below() fails to enumerate open files below an open directory handle; (bso#11615). + Changing log level of two entries to DBG_NOTICE; (bso#9912).- Ensure samlogon fallback requests are rerouted after kerberos failure; (bnc#953382); (bnc#953972).- Ensure to link with --as-needed flag by removing SUSE_ASNEEDED=0. - Always use the default optimization even on pre-9.2 systems.- Remove redundant configure options while adding with-relro.- Relocate the lockdir to the /var/lib/samba/lock directory.- Cleanup and enhance the pidl sub package.- Require renamed python-ldb-devel and python-talloc-devel at build-time. - Requires python-ldb and python-talloc from the python subpackage.- Update to 4.3.1. + s3: smbd: Fix our access-based enumeration on "hide unreadable" to match Windows; (bso#10252). + nss_winbind: Fix hang on Solaris on big groups; (bso#10365). + smbd: Fix file name buflen and padding in notify repsonse; (bso#10634). + kerberos: Make sure we only use prompter type when available; winbind: Fix 100% loop; (bso#11038). + source3/lib/msghdr.c: Fix compiling error on Solaris; (bso#11053). + s3:ctdbd_conn: make sure we destroy tevent_fd before closing the socket; (bso#11316). + s3: smbd: Fix mkdir race condition; (bso#11486). + pam_winbind: Fix a segfault if initialization fails; (bso#11502). + s3: dfs: Fix a crash when the dfs targets are disabled; (bso#11509). + s4:lib/messaging: Use 'msg.lock' and 'msg.sock' for messaging related subdirs; (bso#11515). + s3: smbd: Fix opening/creating :stream files on the root share directory; (bso#11522). + lib/param: Fix hiding of FLAG_SYNONYM values; (bso#11526). + net: Fix a crash with 'net ads keytab create'; (bso#11528). + s3: smbd: Fix a crash in unix_convert(); (bso#11535). + s3: smbd: Fix NULL pointer bug introduced by previous 'raw' stream fix (bso#11522); (bso#11535). + vfs_fruit: Return value of ad_pack in vfs_fruit.c; (bso#11543). + vfs_commit: set the fd on open before calling SMB_VFS_FSTAT; (bso#11547). + s3:locking: Initialize lease pointer in share_mode_traverse_fn(); (bso#11549). + s3:smbstatus: Add stream name to share_entry_forall(); (bso#11550). + s3:lib: Validate domain name in lookup_wellknown_name(); (bso#11555). + s3: lsa: lookup_name() logic for unqualified (no DOMAIN component) names is incorrect; (bso#11555).- Fix 100% CPU in winbindd when logging in with "user must change password on next logon"; (bso#11038).- Relocate the tmpfiles.d directory to the client package; (bnc#947552).- Do not provide libpdb0 from libsamba-passdb0 but add it to baselibs.conf instead; (bnc#942716).- Package /var/lib/samba/private/sock with 0700 permissions; (bnc#946051).- Package /var/lib/samba/msg with 0755 permissions; (bso#11515); (bnc#945502).- Require to install libfam0-gamin from samba-libs on post-12.1 and pre-13.15 systems; (bnc#945013).- Update to 4.3.0. + Samba "map to guest = Bad uid" doesn't work; (bso#9862). + revert LDAP extended rule 1.2.840.113556.1.4.1941 LDAP_MATCHING_RULE_IN_CHAIN changes; (bso#10493). + No objectClass found in replPropertyMetaData on ordinary objects (non-deleted); (bso#10973). + Stream names with colon don't work with fruit:encoding = native; (bso#11278). + NetApp joined to a Samba/ADDC cannot resolve SIDs; (bso#11291). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + "force group" with local group not working; (bso#11320). + strsep is not available on Solaris; (bso#11359). + smbtorture does not build when configured --with-system-mitkrb5; (bso#11411). + Build with GPFS support is broken; (bso#11421). + Build broken with --disable-python; (bso#11424). + net share allowedusers crashes; (bso#11426). + nmbd incorrectly matches netbios names as own name; (bso#11427). + Python bindings don't check integer types; (bso#11429). + Python bindings don't check array sizes; (bso#11430). + CTDB's eventscript error handling is broken; (bso#11431). + Fix crash in nested ctdb banning; (bso#11432). + Cannot build ctdbpmda; (bso#11434). + samba-tool uncaught exception error; (bso#11436). + Crash in notify_remove caused by change notify = no; (bso#11444). + Poor SMB3 encryption performance with AES-GCM; (bso#11451). + Poor SMB3 encryption performance with AES-GCM (part1); (bso#11451). + fix recursion problem in rep_strtoll in lib/replace/replace.c; (bso#11455). + --bundled-libraries=!ldb,!pyldb,!pyldb-util doesn't disable ldb build and install; (bso#11458). + xid2sid gives inconsistent results; (bso#11464). + ctdb: Fix the build on FreeBSD 10.1; (bso#11465). + Handling of 0 byte resource fork stream; (bso#11467). + AD samr GetGroupsForUser fails for users with "()" in their name; (bso#11488).- Configure with --bundled-libraries=NONE; (bso#11458).- Adapt net-kdc-lookup patch for post-3.3 Samba versions; (bnc#295284).- Remove libiniparser-devel build-time requirement.- Update to 4.2.3. + s4:lib/tls: Fix build with gnutls 3.4; (bso#8780). + s4.2/fsmo.py: Fixed fsmo transfer exception; (bso#10924). + winbindd: Sync secrets.ldb into secrets.tdb on startup; (bso#10991). + Logon via MS Remote Desktop hangs; (bso#11061). + s3: lib: util: Ensure we read a hex number as %x, not %u; (bso#11068). + tevent: Add a note to tevent_add_fd(); (bso#11141). + s3:param/loadparm: Fix 'testparm --show-all-parameters'; (bso#11170). + s3-unix_msg: Remove socket file after closing socket fd; (bso#11217). + smbd: Fix a use-after-free; (bso#11218); (bnc#919309). + s3-rpc_server: Fix rpc_create_tcpip_sockets() processing of interfaces; (bso#11245). + s3:smb2: Add padding to last command in compound requests; (bso#11277). + Add IPv6 support to ADS client side LDAP connects; (bso#11281). + Add IPv6 support for determining FQDN during ADS join; (bso#11282). + s3: IPv6 enabled DNS connections for ADS client; (bso#11283). + Fix invalid write in ctdb_lock_context_destructor; (bso#11293). + Excessive cli_resolve_path() usage can slow down transmission; (bso#11295). + vfs_fruit: Add option "veto_appledouble"; (bso#11305). + tstream: Make socketpair nonblocking; (bso#11312). + idmap_rfc2307: Fix wbinfo '--gid-to-sid' query; (bso#11313). + Group creation: Add msSFU30Name only when --nis-domain was given; (bso#11315). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + Build fails on Solaris 11 with "‘PTHREAD_MUTEX_ROBUST’ undeclared"; (bso#11319). + smbd/trans2: Add a useful diagnostic for files with bad encoding; (bso#11323). + Change sharesec output back to previous format; (bso#11324). + Robust mutex support broken in 1.3.5; (bso#11326). + Kerberos auth info3 should contain resource group ids available from pac_logon; winbindd: winbindd_raw_kerberos_login - ensure logon_info exists in PAC; (bso#11328); (bnc#912457). + s3:smb2_setinfo: Fix memory leak in the defer_rename case; (bso#11329). + tevent: Fix CID 1035381 Unchecked return value; (bso#11330). + tdb: Fix CID 1034842 and 1034841 Resource leaks; (bso#11331). + s3: smbd: Use separate flag to track become_root()/unbecome_root() state; (bso#11339). + s3: smbd: Codenomicon crash in do_smb_load_module(); (bso#11342). + pidl: Make the compilation of PIDL producing the same results if the content hasn't change; (bso#11356). + winbindd: Disconnect child process if request is cancelled at main process; (bso#11358). + vfs_fruit: Check offset and length for AFP_AfpInfo read requests; (bso#11363). + docs: Overhaul the description of "smb encrypt" to include SMB3 encryption; (bso#11366). + s3:auth_domain: Fix talloc problem in connect_to_domain_password_server(); (bso#11367). + ncacn_http: Fix GNUism; (bso#11371).- Disable rpath usage; (bnc#902421).- Make the winbind package depend on the matching libwbclient version and vice versa; (bnc#936909).- Backport changes to use resource group sids obtained from pac logon_info; (bso#11328); (bnc#912457).- Order winbind.service Before and Want nss-user-lookup target.- Remove fam-devel build-time dependency for post-6 RHEL systems.- Update to 4.2.2. + s3:smbXsrv: refactor duplicate code into smbXsrv_session_clear_and_logoff(); (bso#11182). + gencache: don't fail gencache_stabilize if there were records to delete; (bso#11260). + s3: libsmbclient: After getting attribute server, ensure main srv pointer is still valid; (bso#11186). + s4: rpc: Refactor dcesrv_alter() function into setup and send steps; (bso#11236). + s3: smbd: Incorrect file size returned in the response of "FILE_SUPERSEDE Create"; (bso#11240). + Mangled names do not work with acl_xattr; (bso#11249). + nmbd rewrites browse.dat when not required; (bso#11254). + vfs_fruit: add option "nfs_aces" that controls the NFS ACEs stuff; (bso#11213). + s3:smbd: Add missing tevent_req_nterror; (bso#11224). + vfs: kernel_flock and named streams; (bso#11243). + vfs_gpfs: Error code path doesn't call END_PROFILE; (bso#11244). + s4: libcli/finddcs_cldap: continue processing CLDAP until all addresses are used; (bso#11284). + ctdb: check for talloc_asprintf() failure; (bso#11201). + spoolss: purge the printer name cache on name change; (bso#11210); (bnc#901813). + CTDB statd-callout does not scale; (bso#11204). + vfs_fruit: also map characters below 0x20; (bso#11221). + ctdb: Coverity fix for CID 1291643; (bso#11201). + Multiplexed RPC connections are not handled by DCERPC server; (bso#11225). + Fix terminate connection behavior for asynchronous endpoint with PUSH notification flavors; (bso#11226). + ctdb-scripts: Fix bashism in ctdbd_wrapper script; (bso#11007). + ctdb: Fix CIDs 1125615, 1125634, 1125613, 1288201 and 1125553; (bso#11201). + SMB2 should cancel pending NOTIFY calls with DELETE_PENDING if the directory is deleted; (bso#11257). + s3:winbindd: make sure we remove pending io requests before closing client sockets; (bso#11141); (bnc#931854). + Fix panic triggered by smbd_smb2_request_notify_done() -> smbXsrv_session_find_channel() in smbd; (bso#11182). + 'sharesec' output no longer matches input format; (bso#11237). + waf: Fix systemd detection; (bso#11200). + CTDB: Fix portability issues; (bso#11202). + CTDB: Fix some IPv6-related issues; (bso#11203). + CTDB statd-callout does not scale; (bso#11204). + 'net ads dns gethostbyname' crashes with an error in TALLOC_FREE if you enter invalid values; (bso#11234). + libads: record service ticket endtime for sealed ldap connections; (bso#11267). + lib/util: Include DEBUG macro in internal header files before samba_util.h; (bso#11033).- Avoid a crash inside the tevent epoll backend; (bso#11141); (bnc#931854).- Remove the independently built libraries ldb, talloc, tdn, and tevent and the post-10.3 renamed libsmbclient from baselibs.conf.- Drop redundant doc attribute from man pages.- Update to 4.2.1. + s3:winbind:grent: Don't stop group enumeration when a group has no gid; (bso#8905). + Initialize dwFlags field of DNS_RPC_NODE structure; (bso#9791). + s3: lib: ntlmssp: If NTLMSSP_NEGOTIATE_TARGET_INFO isn't set, cope with servers that don't send the 2 unused fields; (bso#10016). + build:wafadmin: Fix use of spaces instead of tabs; (bso#10476). + waf: Fix the build on openbsd; (bso#10476). + s3: client: "client use spnego principal = yes" code checks wrong name; (bso#10888). + spoolss: Retrieve published printer GUID if not in registry; (bso#11018). + s3: lib: libsmbclient: If reusing a server struct, check every cli->timout miliseconds if it's still valid before use; (bso#11079). + vfs_fruit: Enhance handling of malformed AppleDouble files; (bso#11125). + backupkey: Explicitly link to gnutls and gcrypt; (bso#11135). + replace: Remove superfluous check for gcrypt header; (bso#11135). + Backport subunit changes; (bso#11137). + libcli/auth: Match Declaration of netlogon_creds_cli_context_tmp with implementation; (bso#11140). + s3-winbind: Fix cached user group lookup of trusted domains; (bso#11143). + talloc: Version 2.1.2; (bso#11144). + Update libwbclient version to 0.12; (bso#11149). + brlock: Use 0 instead of empty initializer list; (bso#11153). + s4:auth/gensec_gssapi: Let gensec_gssapi_update() return NT_STATUS_LOGON_FAILURE for unknown errors; (bso#11164). + docs/idmap_rid: Remove deprecated base_rid from example; (bso#11169); (bnc#913304). + s3: libcli: smb1: Ensure we correctly finish a tevent req if the writev fails in the SMB1 case; (bso#11173). + backupkey: Use ndr_pull_struct_blob_all(); (bso#11174). + Fix lots of winbindd zombie processes on Solaris platform; (bso#11175). + s3: libsmbclient: Add missing talloc stackframe; (bso#11177). + s4-process_model: Do not close random fds while forking; (bso#11180). + s3-passdb: Fix 'force user' with winbind default domain; (bso#11185).- Prevent samba package updates from disabling samba kerberos printing.- Add sparse file support for samba; (fate#318424).- Purge printer name cache on spoolss SetPrinter change; (bso#11210); (bnc#901813).- Correctly retain errno from Btrfs snapshot ioctls; (bnc#923374).- Simplify libxslt build requirement and README.SUSE install. - Remove no longer required cleanup steps while populating the build root.- Remove deprecated base_rid example from idmap_rid manpage; (bso#11169); (bnc#913304).- Update to 4.2.0. + smbd: Stop using vfs_Chdir after SMB_VFS_DISCONNECT; (bso#1115). + pam_winbind: fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Make 'profiles' work again; (bso#9629). + s3:smb2_server: protect against integer wrap with "smb2 max credits = 65535"; (bso#9702). + Make validate_ldb of String(Generalized-Time) accept millisecond format ".000Z"; (bso#9810). + Use -R linker flag on Solaris, not -rpath; (bso#10112). + vfs: Add glusterfs manpage; (bso#10240). + Make 'smbclient' use cached creds; (bso#10279). + pdb: Fix build issues with shared modules; (bso#10355). + s4-dns: Add support for BIND 9.10; (bso#10620). + idmap: Return the correct id type to *id_to_sid methods; (bso#10720). + printing/cups: Pack requested-attributes with IPP_TAG_KEYWORD; (bso#10808). + Don't build vfs_snapper on FreeBSD; (bso#10834). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3: smb2cli: query info return length check was reversed; (bso#10848). + s3: lib, s3: modules: Fix compilation on Solaris; (bso#10849). + lib: uid_wrapper: Fix setgroups and syscall detection on a system without native uid_wrapper library; (bso#10851). + winbind3: Fix pwent variable substitution; (bso#10852). + Improve samba-regedit; (bso#10859). + registry: Don't leave dangling transactions; (bso#10860). + Fix build of socket_wrapper on systems without SO_PROTOCOL; (bso#10861). + build: Do not install 'texpect' binary anymore; (bso#10862). + Fix testparm to show hidden share defaults; (bso#10864). + libcli/smb: Fix smb2cli_validate_negotiate_info with min=PROTOCOL_NT1 max=PROTOCOL_SMB2_02; (bso#10866). + Integrate CTDB into top-level Samba build; (bso#10892). + samba-tool group add: Add option '--nis-domain' and '--gid'; (bso#10895). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + Fix smbclient loops doing a directory listing against Mac OS X 10 server with a non-wildcard path; (bso#10904). + Fix print job enumeration; (bso#10905); (bnc#898031). + samba-tool: Create NIS enabled users and unixHomeDirectory attribute; (bso#10909). + Add support for SMB2 leases; (bso#10911). + btrfs: Don't leak opened directory handle; (bso#10918). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: fix keytab array NULL termination; (bso#10933). + s3:passdb: fix logic in pdb_set_pw_history(); (bso#10940). + Cleanup add_string_to_array and usage; (bso#10942). + dbwrap_ctdb: Pass on mutex flags to tdb_open; (bso#10942). + Fix RootDSE search with extended dn control; (bso#10949). + Fix 'samba-tool dns serverinfo ' for IPv6; (bso#10952). + libcli/smb: only force signing of smb2 session setups when binding a new session; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + socket_wrapper: Add missing prototype check for eventfd; (bso#10965). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + vfs_streams_xattr: Check stream type; (bso#10971). + s3: smbd: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + vfs_fruit: Add support for AAPL; (bso#10983). + Fix spoolss IDL response marshalling when returning error without clearing info; (bso#10984). + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279). + Fix IPv6 support in CTDB; (bso#10996). + ctdb-daemon: Use correct tdb flags when enabling robust mutex support; (bso#11000). + vfs_streams_xattr: Add missing call to SMB_VFS_NEXT_CONNECT; (bso#11005). + s3-util: Fix authentication with long hostnames; (bso#11008). + ctdb-build: Fix build without xsltproc; (bso#11014). + packaging: Include CTDB man pages in the tarball; (bso#11014). + pdb_get_trusteddom_pw() fails with non valid UTF16 random passwords; (bso#11016). + Make Sharepoint search show user documents; (bso#11022). + nss_wrapper: check for nss.h; (bso#11026). + Enable mutexes in gencache_notrans.tdb; (bso#11032). + tdb_wrap: Make mutexes easier to use; (bso#11032). + lib/util: Avoid collision which alread defined consumer DEBUG macro; (bso#11033). + winbind: Retry after SESSION_EXPIRED error in ping-dc; (bso#11034). + s3-libads: Fix a possible segfault in kerberos_fetch_pac(); (bso#11037). + vfs_fruit: Fix base_fsp name conversion; (bso#11039). + vfs_fruit: mmap under FreeBSD needs PROT_READ; (bso#11040). + Fix authentication using Kerberos (not AD); (bso#11044). + net: Fix sam addgroupmem; (bso#11051). + vfs_snapper: Correctly handles multi-byte DBus strings; (bso#11055); (bnc#913238). + cli_connect_nb_send: Don't segfault on host == NULL; (bso#11058). + utils: Fix 'net time' segfault; (bso#11058). + libsmb: Provide authinfo domain for encrypted session referrals; (bso#11059). + s3-pam_smbpass: Fix memory leak in pam_sm_authenticate(); (bso#11066). + vfs_glusterfs: Add comments to the pipe(2) code; (bso#11069). + vfs/glusterfs: Change xattr key to match gluster key; (bso#11069). + vfs_glusterfs: Implement AIO support; (bso#11069). + s3-vfs: Fix developer build of vfs_ceph module; (bso#11070). + s3: netlogon: Ensure we don't call talloc_free on an uninitialized pointer; (bso#11077); CVE-2015-0240; (bnc#917376). + vfs: Add a brief vfs_ceph manpage; (bso#11088). + s3: smbclient: Allinfo leaves the file handle open; (bso#11094). + Fix Win8.1 Credentials Manager issue after KB2992611 on Samba domain; (bso#11097). + debug: Set close-on-exec for the main log file FD; (bso#11100). + s3: smbd: leases - losen paranoia check. Stat opens can grant leases; (bso#11102). + s3: smbd: SMB2 close. If a file has delete on close, store the return info before deleting; (bso#11104). + doc:man:vfs_glusterfs: improve the configuration section; (bso#11117). + snprintf: Try to support %j; (bso#11119). + ctdb-io: Do not use sys_write to write to client sockets; (bso#11124). + doc-xml: Add 'sharesec' reference to 'access based share enum'; (bso#11127).- Update to 4.2.0rc5. + Ensure we don't call talloc_free on an uninitialized pointer; CVE-2015-0240; (bso#11077); (bnc#917376).- Fix usage of freed memory on server exit; (bso#11218); (bnc#919309).- Fix tdb_store_flag_to_ntdb() gcc5 build failure.- Fix vfs_snapper DBus string handling; (bso#11055); (bnc#913238).- Update to 4.1.16. + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279).- Adjust baselibs.conf due to libpdb0 package rename to libsamba-passdb0.- Fix libsmbclient DFS referral handling. + Reuse connections derived from DFS referrals; (bso#10123); (fate#316512). + Set domain/workgroup based on authentication callback value; (bso#11059).- Update to 4.2.0rc4. - Add libsamba-debug, libsocket-blocking, libsamba-cluster-support, and libhttp to the libs package; (boo#913547). - Rename libpdb packages to libsamba-passdb. - Drop libsmbsharemodes packages.- Enable avahi support on post-12.2 systems.- Update to 4.1.15. + pam_winbind: Fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Fix profiles tool; (bso#9629). + s3-lib: Do not require a password with --use-ccache; (bso#10279). + s4:dsdb/rootdse: Expand extended dn values with the AS_SYSTEM control; (bso#10949). + s4-rpc: dnsserver: Fix enumeration of IPv4 and IPv6 addresses; (bso#10952). + s3:smb2_server: Allow reauthentication without signing; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + s3: smbd/modules: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + Fix 'domain join' by adding 'drsuapi.DsBindInfoFallBack' attribute 'supported_extensions'; (bso#11006). + idl:drsuapi: Manage all possible lengths of drsuapi_DsBindInfo; (bso#11006). + winbind: Retry LogonControl RPC in ping-dc after session expiration; (bso#11034).- yast2-samba-client should be able to specify osName and osVer on AD domain join; (bnc#873922).- Lookup FSRVP share snums at runtime rather than storing them persistently; (bnc#908627).- Specify soft dependency for network-online.target in Winbind systemd service file; (bnc#889175).- Fix spoolss error response marshalling; (bso#10984).- Update to 4.1.14. + pidl/wscript: Remove --with-perl-* options; revert buildtools/wafadmin/ Tools/perl.py back to upstream state; (bso#10472). + s4-dns: Add support for BIND 9.10; (bso#10620). + nmbd fails to accept "--piddir" option; (bso#10711). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + S3: source3/smbd/process.c::srv_send_smb() returns true on the error path; (bso#10880). + vfs_glusterfs: Remove "integer fd" code and store the glfs pointers; (bso#10889). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + s3: libsmbclient-smb2. MacOSX 10 SMB2 server doesn't set STATUS_NO_MORE_FILES when handed a non-wildcard path; (bso#10904). + spoolss: Fix jobid in level 3 EnumJobs response; (bso#10905). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: Fix keytab array NULL termination; (bso#10933). + Cleanup add_string_to_array and usage; (bso#10942).- Remove and cleanup shares and registry state associated with externally deleted snaphots exposed as shadow copies; (bnc#876312).- Use the upstream tar ball, as signature verification is now able to handle compressed archives.- Fix leak when closing file descriptor returned from dirfd; (bso#10918).- Fix spoolss EnumJobs and GetJob responses; (bso#10905); (bnc#898031). + Fix handling of bad EnumJobs levels; (bso#10898).- Remove dependency on gpg-offline as signature checking is implemented in the source validator.- Update to 4.1.13. + s3-libnet: Add libnet_join_get_machine_spns(); (bso#9984). + s3-libnet: Make sure we do not overwrite precreated SPNs; (bso#9984). + s3-libads: Add all machine account principals to the keytab; (bso#9985). + s3: winbindd: Old NT Domain code sets struct winbind_domain->alt_name to be NULL. Ensure this is safe with modern AD-DCs; (bso#10717). + Fix unstrcpy; (bso#10735). + pthreadpool: Slightly serialize jobs; (bso#10779). + s3: smbd: streams - Ensure share mode validation ignores internal opens (op_mid == 0); (bso#10797). + s3: smbd:open_file: Open logic fix; Use a more natural check; (bso#10809). + vfs_media_harmony: Fix a crash bug; (bso#10813). + docs: Mention incompatibility between kernel oplocks and streams_xattr; (bso#10814). + nmbd: Send waiting status to systemd; (bso#10816). + libcli: Fix a segfault calling smbXcli_req_set_pending() on NULL; (bso#10817). + nsswitch: Skip groups we were not able to map; (bso#10824). + s3-winbindd: Use correct realm for trusted domains in idmap child; (bso#10826). + s3: nmbd: Ensure the main nmbd process doesn't create zombies; (bso#10830). + s3: lib: Signal handling - ensure smbrun and change password code save and restore existing SIGCHLD handlers; (bso#10831). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3-winbindd: Do not use domain SID from LookupSids for Sids2UnixIDs call; (bso#10838). + s3: smb2cli: Query info return length check was reversed; (bso#10848). + registry: Don't leave dangling transactions; (bso#10860).- Update to 4.2.0rc2./sbin/ldconfig/sbin/ldconfiglibdcerpc-binding0libdcerpc0libndr-krb5pac0libndr-nbt0libndr-standard0libndr0libndr1libndr2libnetapi0libsamba-credentials0libsamba-credentials1libsamba-errors0libsamba-hostconfig0libsamba-passdb0libsamba-util0libsamdb0libsmbclient0libsmbconf0libsmbldap0libsmbldap2libtevent-util0libwbclient0h03-ch2a 1760090087  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuv4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d-150600.3.21.14.19.8+git.435.78ced6cf30d-150600.3.21.14.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30dlibdcerpc-binding.so.0libdcerpc-binding.so.0.0.1libdcerpc-server-core.so.0libdcerpc-server-core.so.0.0.1libdcerpc.so.0libdcerpc.so.0.0.1libndr-krb5pac.so.0libndr-krb5pac.so.0.0.1libndr-nbt.so.0libndr-nbt.so.0.0.1libndr-standard.so.0libndr-standard.so.0.0.1libndr.so.3libndr.so.3.0.1libnetapi.so.1libnetapi.so.1.0.0libsamba-credentials.so.1libsamba-credentials.so.1.0.0libsamba-errors.so.1libsamba-errors.so.1.0.0libsamba-hostconfig.so.0libsamba-hostconfig.so.0.0.1libsamba-passdb.so.0libsamba-passdb.so.0.28.0libsamba-util.so.0libsamba-util.so.0.0.1libsamdb.so.0libsamdb.so.0.0.1libsmbclient.so.0libsmbclient.so.0.7.0libsmbconf.so.0libsmbconf.so.0.0.1libsmbldap.so.2libsmbldap.so.2.1.0libtevent-util.so.0libtevent-util.so.0.0.1libwbclient.so.0libwbclient.so.0.16libCHARSET3-samba4.solibMESSAGING-SEND-samba4.solibMESSAGING-samba4.solibaddns-samba4.solibads-samba4.solibasn1util-samba4.solibauth-samba4.solibauthkrb5-samba4.solibcli-cldap-samba4.solibcli-ldap-common-samba4.solibcli-ldap-samba4.solibcli-nbt-samba4.solibcli-smb-common-samba4.solibcli-spoolss-samba4.solibcliauth-samba4.solibclidns-samba4.solibcluster-samba4.solibcmdline-contexts-samba4.solibcmdline-samba4.solibcommon-auth-samba4.solibdbwrap-samba4.solibdcerpc-pkt-auth-samba4.solibdcerpc-samba-samba4.solibdcerpc-samba4.solibevents-samba4.solibflag-mapping-samba4.solibgenrand-samba4.solibgensec-samba4.solibgpo-samba4.solibgse-samba4.solibhttp-samba4.solibinterfaces-samba4.solibiov-buf-samba4.solibkrb5samba-samba4.solibldbsamba-samba4.soliblibcli-lsa3-samba4.soliblibcli-netlogon3-samba4.soliblibsmb-samba4.solibmessages-dgm-samba4.solibmessages-util-samba4.solibmscat-samba4.solibmsghdr-samba4.solibmsrpc3-samba4.solibndr-samba-samba4.solibndr-samba4.solibnet-keytab-samba4.solibnetif-samba4.solibnpa-tstream-samba4.solibprinting-migrate-samba4.solibregistry-samba4.solibreplace-samba4.solibsamba-cluster-support-samba4.solibsamba-debug-samba4.solibsamba-modules-samba4.solibsamba-security-samba4.solibsamba-sockets-samba4.solibsamba3-util-samba4.solibsamdb-common-samba4.solibsecrets3-samba4.solibserver-id-db-samba4.solibserver-role-samba4.solibsmb-transport-samba4.solibsmbclient-raw-samba4.solibsmbd-base-samba4.solibsmbd-shim-samba4.solibsmbldaphelper-samba4.solibsocket-blocking-samba4.solibstable-sort-samba4.solibsys-rw-samba4.solibtalloc-report-printf-samba4.solibtdb-wrap-samba4.solibtime-basic-samba4.solibtrusts-util-samba4.solibutil-reg-samba4.solibutil-setid-samba4.solibutil-tdb-samba4.sopdbldapsam.sosmbpasswd.sotdbsam.so/usr/lib64//usr/lib64/samba//usr/lib64/samba/pdb/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:41070/SUSE_SLE-15-SP6_Update/5add5f7dce01a5b57b4b9abf50b932e5-samba.SUSE_SLE-15-SP6_Updatedrpmxz5x86_64-suse-linux  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=f69b15b19a5cafdb74eef4b7df1ec0257f1c08a5, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=4d7356910c19cd140401dc1b0e92de7ea861f438, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=4d1774b814bf9c45de1cad0f029625ab1a2971f6, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=bef090ce8380dc424bb2372d34fbf1352399bae7, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=cfb73248bf6650c2f737c11f45db35b4f16b2586, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=eb40281792b0f26aa68d77ceff53036674b4ef6e, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=b93c95896a8d3865875fca8892d360dfa83843a6, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=b8e3a55f29f4e823d1ecd32172696feae1155cb2, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=f24e98dd848e9ca4fe87c19ee2cb2e8fb734ac6f, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=cccb02b2d71db290bc15cdc6f860f9e8101a18b9, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=f64908781671e0741f677a1424c517c36ffd1201, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=9ca288cf4960ce83faac0b44453f7acb0c57bde9, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=fc8ed6281057d65672a272cc923e47dbfc3aa9f5, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=277282add9c57ef5edcee7d4e675dd420124525d, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=e0ad9e9d06262d520eb4a16b45036a0c019b69f6, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=a1c65b1472b432266e7c7c0717c81d37fc8e3e96, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=642b5054c819b35f1337ac9bbf3f9ab64ffe88fe, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=3e046aeb1825e9aaf69358781e5f73ca2ae94421, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=a04608997b694cad17301add8b401de70fabfa21, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=ffc5c88397f4d8942a4246fe40a1177d0ea2dd39, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=95dc08310166dd2ef6c9519313d9aaf2839a156a, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=81dfb1dbf9bde14e8322f3b3859ebe097fa09dcc, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=7bed9bd6ef17a319cfee1710f275d5bbaad1ae3e, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=2f82ecbf4777ab818f20c75116fe9b30c7901b7d, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=d52fce5deb74410cba22165e29c0fad7aa355ba8, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=0206ae510096441ae80ecbea40635fe9bead16dc, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=07eaa88dd1fab5ed1cf0110f0d5cdcef58e40c89, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=108d9c2acf3b5fb0a39e308b00e64d0d64a645e7, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=4a007ad89bc1a72fc0d4fe7c759971cfb1f73d85, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=2ebd746960424111bf26723827e4c0d9effa3782, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=e6142d5dfc5a6084a43470cb52b6b082920ce470, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=7a642e981a2f7ad8815deaf050960f46946082e6, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=30be2c21599fc0870bf3d5060c6782add021a60f, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=e1d3333f6e35aa226c5aa098823aa55ac70676b2, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=0fc6d2eb18c22ef1dfef0fe61fc89eb1d5cd8897, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=0767e305298ba19c57c88ac52397e8106faf33a9, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=238e2cec332485d9eb2193a9a490ac9e69f046fd, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=0173ee005cbafdaea5e207ea6c08794e0f5b5f10, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=c5dc16126c8652f24a757462a8e7565d4bbc97d2, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=fb8c0aad23c64465fd70af04bdbba3704a06ce9e, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=3696f5a215a8fbfe56ad88d289733e8bd46255e2, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=0aba6718b55248cdd76d05583380e672e5aa0733, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=75708249d2c6d84a2611acdd8c403121e98c3f37, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=99535760700e2af80cf5a638c1b2ceb7ad44dcc1, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=a570394c40822b024534922ebac85986d80c1ede, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=f3d4687811200331b7a85faaa01b722b8fd8bdef, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=069692af2492f0b0fe97ff77f99dec6ab547f3ea, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=9e85325fb8b30ae0adf3dc42101916b0ec7028b2, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=9fa979d8c39ca5d50df1b61f55914917c83b23c8, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=b2cc3f5d2c9faf788aa8481594f0dc7588919f0c, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=d3073225dd552aeea9aa85b3ae16d0a3a37a254b, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=b906aff9e0ce8b4dc8753e8336a63a2126583d88, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=5d54f615d06a520d2ebf56bc53154725f2376909, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=87dc0c94f585dd29c116f992dbdf2d8f3834d1e5, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=3f86cfa5939577acfc8abdf50f4cc2369849deb5, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=97a4cd49ef7fc59ddd80222b6fe517d077374f7c, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=54192148bd30e4026501b4b4a65e682f1af540d7, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=a94a2c04c24616622f41942b49c4dfcb748fd5ae, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=e9a9d4a00820e87db66575caa4122ddea4833c9c, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=740a3401c38facf476e905d88dbcbb58c493672a, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=2e70cdd8a87c60047e58b855d86d86aead4a7c2b, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=24652ef2d4bd1ee54f0fbf80c8024a459cdd7f85, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=ef48dc2e4d96b7542d3db4edc925af53ba82045d, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=9d6ceb231a0a196c3305762c9fb011688c597f61, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=cee99d574fd9a0d29bce1a64a4e1886c3b76acd5, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=a5cb9078de432989b55ce104e90206f2cdad3a6d, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=7ea74d6da626588f33707b3e157b7502ff588189, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=ef2abc7297749c2b23e28d2156aee45e6f28b7f3, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=474dce3a7fd56ee9920251969c76135dd7b15f74, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=5aaf9851a51da49318ad9875af1007fd4de7c093, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=0c0ebb17c90274faf46ff79b5945320d8a8885eb, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=ab94992b20c250a43e3a1a4d0a895bc9fe17ab72, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=c59357ed9afa8c2b2ad01d964a00774c6fe7724c, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=e68bfb0e8e1a47120b48b52e4a885bb8189e6427, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=374af324a9ba59c07537c1810bc770052a41d653, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=15878b699e199accf1645acc261a16340184f162, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=e72424224a3eb072a6620a9a27ea4fa833404540, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=3cf97623e659442b32313ac40eef7b48e1654b7e, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=cd091777189160e6048e8dd22ea6220f160da9fb, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=3b4e29960986bc23dbc13eb6a578983e4711649d, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=e6d834f859fbec7e06458afa9435ac50d1ec3b0f, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=30b6f24b0493ed8f78f7a879d826f9c164a6f17a, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=8711f3c3b4d1b3f5bc27061d834907ed1a4e045e, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=8af682d6a676c77bea90005837454bea0cd46829, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=0b8b5b293bb0c3301a66a4b4f5f434740136efab, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=f865ed2c3eec30645027884140fae5a76f92f9a9, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=27642c4e61aae164efc0e0540d5bc83bf4022b40, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=42a588ae25c2316bfd1288acfabbb3ad37ae6c6d, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=2bf046d804d50878bee4daa26c920880f818366a, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=f7b992faf2a8fe7a1e01dfcf42531a47dee05a90, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=aeab60904ec6d5b6a9a4bc718b8636e6c9f27afb, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=f4f02abe4c51f4ee712c49e2ddc8e1a5727b6525, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=b022e3a02751ea5083fde271c9bdcae8f8d80bea, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=a40ff553585fe978269fa06e3080f237a6c005b5, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=20c78dd8f09c23f562a2e7ef10dd6bb8940d805e, strippeddirectoryELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=58e762c7f77dcaa5a40493c4482cbbdbb943a7ff, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=ffbeae89b9b138157219fec6605d035a02633381, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=72a8618e8f8d377d3ea12e3ed0ea32e9ef290908, stripped#MTL+EReKu+Kq*28E2cv [w  , 2 H ] k  - 3 D t   " * 3 A G d m q { #*C9E0 I&4Nb *!AI*&2, &   <(> 1!;"I""* 5+0   &P+P*RLRRRRRRRRRRR)R&R%RR!RRRRRRRRRRRRRRKRRRP4P3RRRRDRRRRRLRR$R!R&RRRRBRRRNRRRRRRCRARRRRMRRRKRRRRRRP6P5RRRRR+RDRR/RFRRRRRR3RRYRRRRRRRRLRRNR7RR%R)R&RRRRBRRRCRARRRRR2RRRR6RRRRXRMRERR*RRRRKR.RRRP_P^RRRRRRRRR&R!RRRRRRRRRRRRRRR RPbPaRRRRR&RR!RRRRRRRRRRPiPhRRRR&RRRRRRRRRRRRRRRRRPlPmPmPnPnPoPoPpPpPqPqPrPrPsPsPtPtPuPuPvPvPwPwPxPxPyPyPzPzP{P{P|P|P}P}P~P~PPkRLRRRRR)R&RR!RRRRRRRKRRPPRJRR3RRxRPRRRRRvRtRRRRRRRRRRRLRRURRRR%R!R&RRRRRRFR7RRuRRRRRRRRERRRR6RsRRIRRwRRRTRRRKRR2RRORPPRRLRRRPRRRRRcRRrRWRgR@RR%R&R!RRRRaR7RRRqR?RRRRbRRRRR6RRKR`RRRRRRRRuRR=R6RsRRRRRRRRRRRMRRR RRRTRRRKRRRRRRRPPRR>R_RRRRRLRRRRcRR&RRRRWRRaRPRR=RRbRRRRRRRKR`R^RR>RRRR RRRRWRRRRcRRRRRRRRPRRLR7RR!R&RRRRRRRRRRRRRR RRRR6RR=RbRRRKRRRRARwR?RRRTRRRRR6RRRRRMRERRRR2RRRKRRR=RRRPePdRR&R%R)RRRRRRRRRRRRRRRRRRRRRRPgPfRRRRRRR!R&RRRRRRRRRRRRRRRRRRRRRRRRPPRRURRRR&RRLRRcRaRbRRRTRRKRRR`RRRRR5RURRRtR|RRRRRFRNRSRPRRR@RzRRRRRRRRRRRRRLRRRRRRRRRRRRxR R3RRRRR)R!RR(RR&RR$R%RRcRRRRRRRRRR{R4RwRR?RRRRbRRyRRRRRRRRR\RRRRRRMRERRTR2R6RRRRKRRRRRRRR=RsRR RYzkN5V3LfsZ,+#EKgr`}.Ҙ)1â t^ʼn;0$!^ɉ\ΐh[$NLN̐PM]GÌ4:pd7r.,/WCx[T/ɟIzu#TYS%%?UpSepCkJ(ކOx(|"z8:n.CU NVܗ n(6lJe# .8 g0l\ORI㈔"5CnD"0Ou2֓af(fCڄQ%khK@;` V5ߖWp=7W8J(S>¢0zx PTMx>MCAyD+u:>3Lo׬)w,encX\Qy[1z"(@TP,vz%qCqo@gsBܶnmU{R)$kqz)|9 !۞M[z $%7Ͳ,ѹl:R{&Pq 4f8xMGd?Ӏ݆W2qyG/'#ޅuP)\ق;Ff)((N^%hK1 p!AJa!dm4qꦧ?j''+z6@1z`@(۫kutZߢWxGuoni~]Si|I]~G+$Ь>">y3Laxzw(cTIK8a $w)C0ᯇU` ҥ)w@26;֒Dp6;-⧲Hl1g ;Ҷ\)s=rvgcDw 1I_k#<%RlP):T2RbRA= {eH5& TS25[xcӜP|(\2X⧓Bt^DIў*}}ß$̮[/M D9RaT |KÉvJEn2C<"R7Up):IKrp ) ,Tp?m$ 56x*}BD&|E;=804 /KNàvhZ:[Gnћ|WhQprE9"*9\.Lpk^+ "z`+>)4qI kvư.EO|k6:HAbΏϚ}ވ[9bH?06xjb\pzaݔ i @ [mom[CyvjU)#lN- |k|0],ٸ LD !+&&9ѧ!szsEz,8}fᭆ8@'DnW+auҫ[5:֓Lh(]6 y˫wj&qCC"fUJWnԤ<6׳m43=@2xoTNs|-sumdǫA ^++;?`ab~S""xYՒWX;ui0S[HC̼j_W O'KƆ,r785e-lvx$mjl)YXj1qdz+1'ުPwɕ `s@0 w\VKQ'LlhXu,Q~_J ՄB{U&NvoCD:hPtM-O'1q'diBW?kHrM>ԿsŬҍ|4|hKBQשj^4^P:QbѤ¢A+KmmikE% wx[{^l)O&Lenr~GORѝ,RAϗjErA)EaQ PNtW\l<=繻k*(Sj ֥ʣu w%-HYݎNeu~2"Ξ53Z)[hлpzг6\ثO*. P aU%&R13^!t$ hsW:eX07+5~p _c$M]V8^ 4  DT{t ""{ !`t ?آ#͢?~GPPnQdZFm"UP5gG,?$o^q (CrLr|yOIK^Idta@qutD 6}w@KMnt$ g`PMF՚OFDѡbPlt.sG ss-ۦrD Kh#r8i߁v;%=tsb*Ggن/^\ ^ya>%t.f0d)Q1=1@yFIE!1,Sn B ^4 2+N^z/wL"tN? A8ѹkP$U]7- !&'1(O8NJC1Y:MSm+6O̙+JSrȖl8|In=!(l6bzS. ackُ>@DTΓҿ?au׭e.*t⤷KKVlqH(On)(${)((sBGlfvC }*ȮtnJt˧`^#wK@gRK+zˉ4P^>}v6v 7)4\͠)m c?Yv?pqY BIT흁xNkX[?n.=QtNASr{f-1Nj֢?@tOoYk%CXRqB'{ 63ܾ4uuE.9nxXb9u{2!v8dxnnLy/2 |P%B ">S1Fue|`6j]_[`PCޕv^ 0̬cnȊ~jWط.s8hҽS#R`~m\a}`‘>jU~EE!ڵCQ{i.l'`KM]D؂9:ރ(-})W̗`pɼܯ.u})΋8g}PUDQ&)+i΂E.v%`gَ.Wm]ˮe5|;VoSc9NZ77Թ?E͑`FeN`h<1aN SCzd2Q=:.@ˑrki43O^NeN/P -jAljv3,B)p ! Nk&]6u!?^Ϯ+kXC.gkjk>n,7,۝4J5A` grݧ2K<٠N,lBZ\=ʄ>Rf)'9 v>-D5;P:th!ӡ֨;6YGO!ˇ9sNaKF ⠒F$Aqf7qּ&l/AG`R(]Gzԯ4_(Eq9SRع_vQjIt'ԽE3&]mvǦksǬ(=yL\ cRAXmkf'p>ov@J, pZn$l豬ZFYjCl }J2GD<Dc05pMik`rS|>Л?w89Ԝm>9Fi]'%pw&`(a7&ZI *K_CfGN18#n*-؍BrhdCUgFxFH}Kl? S qQIoN#Ge\M3{7R3o{˜f!2DHnsu(%{0;ByMzQĒo\omCw \?]p1Zf 0ae#xpf2-"8 /SlݒmW1gGk8& .y4}rcMi:irkmn(+Z=m'I ˌHF -cwh|pBZh}WC=Elgơͺа+3CBh+IWR#h7Ŭ8yE?| Fqـdحb1uz.$2%˿iA5897 Lq#Ǿ$(w23^} ]>%bfg-Hymf҂9c;E0ool'$aelZI:$}7֦{rt8`J^k)Ղ=V1Ǿ:@,^WPEFh;iRKKATDK;m{&y/(1)EP킓: ZTNřC 6˸N6͆#J1j6in20DXjhz)\@[j!s't]0v}Dm)wd\):M1n>mټ]fA?=K7 u̷U,6v1f=f$l:FE_,9_5 kM\s«,U$rb8/<߻TxZ<D"~Rˆ橐&7WR[̝2U ȑ~NǮ&Pȇ\,im׀-WRfe㊺&T?O>^n`<(rԭvK0諑QABʾ۬b@@ٶa#sP䁐SK<|xԋrDa\=a%V?C/( K|2LMFtR!4mjwyW#Πo+K+_Z<bBD|9tTj!RUGaA'γQEEmD [ڔ>1S \J)ǶЏf·C]0OFq (Hsnt=b ༲ioG5:K%xD*_N mR;tJq[/ϘA3ywf %2 NPj{rbV2Ry{04D-[P?;C?4t|XErT=y]ZRVUs z$L53Tv4bjE$)m$=:@;ܡ┾fX+Me4><"b4JJfii'_MWhGxőZԽ6 wYKoپVï:!ݖLzh,ҭ2RsxA{#mBK,Xt }j@J%1&ta`<֕}Xɠn Q u-'K1sل3,ޯb\,+9w}n/{R>+Dd'~pîD~Ȅ@{GhO#TҘjM A9\ (eTn}(,C!8]%j|[?.N-UjD'-*١T_:rݬ4E`.0365;穢Sa֩1M΀bj̭.]Tt?p'R=[2MT$b @5T$TGՋ.ʀ~/))V ̴~EH;,:qFkc'e=Zlf(v!.C]ggo}޾ۛʥAOBmX Wј8HO+'}ˮկ,d h1r|v2NJSHZA lvt?jG "";nJ~+om5msqzErgBZ,Eɒ2Rsg{R]|ʒeRcb`NG6.nyEE w)#;B,P宯Sg}:w/铬JV*`^Ϩ\΢0谥A0̆ĢT&Ϻ Қ坎r DjFw|7iō|(c_OzcPz:Pm  XX#zb.Uí|ԧMgDw(ře+";$:0=XBPg-IˢootRWԀ[Č~t*["7]:Ez\ƨz+a4x&GK A,[Z= jO6<[6wf 1:śdi0.D 9LaQu|ahIaտv+͔.C"C4{;,SѳbRȳl t5)dmq ٙ[X `Ub SIL;x^fpmK&q:$6yIwIBwpvyb}cxbr$ wruᅊ4 vq9OvP2M?ߋI eؚO.$WV6(g/3ǬC>({@,LЙg^[>aHl}=\3SD a#WBE-QHsI%f4 V4VOg$zY"\|PFӒPZDʼnɳU\,C.\^c/A=(̔\cd @AR B|5 wxva5`9OG6oÑ ; K*bwAEH}HiDC:v$4MWI^06Y4z"O-9֓j]_d~].[=2Ȗv'39^ʥX)~]uZ`8Q|]lov(9qO*yhAϊ{X,KV*Qb쯡< {BMPqP3۟#VM!W=lUՁ"{v(.ԇ MXM2Q I?XO m{ oZ/ΈX!t@)ۦ HQC5 2$}v| $$iÏ&fCXB51\aB>k5e VYJoI>/CPr[8HY*SK{H gq?r}%}H> {XRz~=TTWF~ g~ 4ɤ/Pc zz ډC0nnU*8L^$FxTҡ'9uShA#"FhtTt N弫X-S rDd`'eg&|dH X MyX5.QsRA\ s܁Yw.$wENBCUT_vdӿV;ބy:G:l6F.9f>3X݉\z£:%Pzf}wj7 Sq|)y WFwTDN. gf~WWkV85%XPYlkn5)?ެa\i]C_yE2{8W*. ]jՌ\Ln#X1חs˲ֻ;ΧX1HAN!ړ?#]@:ܠEiEe me@|U#Y 8 ¶vrEƖ iJаɸ65 YY=tw'3[g_:槭Kش챋Ub0-ND+BukȕgzCj-GBi Q$_{?F[[ōʶ{ʳ!b^JWFP3~m""X*xW3h~y;K Ru% B:t9ƏHڌ &Rrݧ[s4sw,*5FݪsRx})xT@a@Rvf̲۽[Jp?' Rp q+I{J}q ׀!NJ҇ @ԥ(zKvT+4$WybH>g- .3솿jSm_F=syp&.dMB\l?jY+M#ДV/~λ2nS篳Ap!y;Z ilӜk#qQ ?*V;t~5@zO)˥[Z@G[ { y_"$=UKw<(..{/O䃱®#T&䵏c+lRx)nI814>3|?YSǕR;<? r#%T2 o|4ⶴ'*qFo}3ΤߝSQ3nuc+jd5AtuS[ \ILoT+ߍY#68X;ʵDy|FJѸxg Շ2:IB{:gך93o|Fn[蕗<\G "A*QyEQ~bޯ1q@8!hA+b2EB} qi{:Q/ӷ"t]arh\n<@LL}FODsX9Vk]2$H+VWA~UZ89i۞NZJXiG'sKH!"{/a_PS@.8nZ4YN[NsJ.f~I53\ |F_h[}b~U2o}g3*Xmz'Kjoη_ c _``," /hSmɎlhkF [@wv|.{Cdt-X5sE3^wc(Q\Ɣ CYUPjG--(fhuZOW_x]Cx-9yWLI?h陘,@7c&[P*4S )>7pMn.1PYH~C NyɤN}]>{s?KQKn(qOD|;ԆWqRgLv/u=UrD3=^c2()^t-ެib鵕cWM(kjM}4$XZ ٛl])SɻJ}znK䋏ߵ7c7Z| M_0ƿ(%[Z< .Q A@[.``n ջηN :RnnrV(P~O\C׸0t<gM`LE? sQ^X.l}(wkAۈáL֔5֒&@qRf=}qzLY\xؐV_3ʙI}q\ݯ隝*Y"mi=ZEw0ֱh%Y| O8$}G_uNŌ[ nydo$o݃~s"XUoJAƒC\TjnVU=Yas?'`V -ͦc\H)G2fR=vHj=Lij:C0@_T刅 5j 3D37w 0=S+0hAd3jWw&uYw:AQp3Occ/V2lW BM=V9*76jK<|5wJ SZ4} O<*+p.2sPV_* J !wJx˲"iMy>Y g A1An.Ƹ yGB2Uf5䗖D.H} T狦EQ0_.D%|ׄ|1ݽshZ {Re*p8Ж=~ϔq}} 7eXRg`'19)X_[ 4bECe6^x\Y|*TcȢvsTȽTY|,U=׻\1wi'=ƓM(=}.\a86ii%>8Ӟ$-AJ/Иw>TqT競n 3 o)ǿ0;GyVj .8LӯzˣA=ύ@q8)܁'X6>KzFc|zgJCiA N6Q>:A x>gb7[}FTZP].=0QXfM:[8Z̶f?3)箊K36HD쉑m܃8F.VW&^ AT~Dָx\>.ԇǟ4 Y82gf } 0s禞-ˢWIyFsEi5yYpmChh}WO}T,W9,N:*P,$,=BC MkWƦ,fM,cChz+Jz9}B6`n׆ ,J;۟ҬAȣyT_l[ԾIk/?=gPbN"q5x7-'zd,%Yepv{%z{$Չ˘UoX Jr/?$.-ԧ_8H= 9FʲtW>ݑEk2x"+$Xpy#@n Ѭz5G))ڡV[ kqB] `ꋎ2]>’Fѐ(8s]NБq+>$ TDJ^Q/8lޭ8Rw?VUҕ6aZ!HA7j.{O\X5fig?1R3^( N7;Z>ŬX66 Mz黤I3lnem,Z*6FF"&yer4rǴݰA|-Fg?ˑA8- oe*dlSct2 t{~7=Y* r4w.@\!-1 LG섂6ïMtJV-9Ѐ vl21χD(4*ĝ!YPri3p8^.]:j~Qn j?b +49jsK`&xpxm}45؇YF`+jͽd1198}d9ջ3%N:%âTa$ޡ7,Q}/'N~vpT8TRw+)Bd slۯ9:]M+a2!'*^fҜ)t[,S xGNF8>[gg7|~#Se{-ad9T@vXmd ~S'L,]ǬKxVbM1TOnWov @rB/ilVnJz^~X4'8j,Xd/#fk|LRbAQ4_}M<KB " Rjym)l=@[n2Y>-Qһ[);x^5=" QLwP٤$zt4 Y?{xh{<_IMWZݥE w>z>J",(uFsIMFo@EZbP+1 Aͅ ]^qGeh8M{)P/*W^YFL]Ub};$vXz4 Z\1;Edմ y]M)GÃ(Lk)&a.¸ik>Pja"[gӺ #!ΰR4 AhJوpߟ9 W}WYd< Y{]aRmjP,Z(O%a;{ztIxCfe*(Vmuϧs dkhD,$M"?.m EgjRtM364(qF*! 4G_ #W$]{@܈Uc&wEZ ø;v+o78oԇ`i< &&Իl0XvR<3µ*~k~C| 9Ǘ0W9mTp/*4%9S} |6?5?PܯΏlAECqqB>A;+,ho^%6oEO.Vw[(4Jdx#1q2| KN~`}-Avnˈɐp!ߨ@SBBDڶ橿Чjޘml2"@6[q";lwigìR:,8 F)};!i}m;!F|g.lwI Y@D;G7j{ =s&:ނ_c2 `pN~4~xCzH ?ߢ\řZ<\KSUE؏r~n圌#9s]RSUWg3N#,אPmjDi5גԹTgiۗi)|9GAe[3)P)Fx3/NNFpE;Oh'kA~-,wgL&Ǎn5Jwc1vQ_`8"I(T;K><-"Q&f}L޳rX_ \kqʠcCJ>p8GTCԐbi#GYy#5cLDVljaiűLaXO$ pieձ:\^i_k3e:(VtUUߚip} 籰u/I F4GQ+M _EF˜z">cDr??ѝpt8gF" e /Twyװ-&4ȫɹ3[#)n QW;zm]vJ1Kwf5~¤m='sWbnb8l[C=̨ IkPU܄vE8oSiLd -,˴܎P&0_R[ad gkuθV9Hdؘ ` Ae:GxE(؋oӏ@aȈܞc~0Z@uxZ2)PG00_A*>_YGd~D:ѸU} -9cпVlDFO= ^ŽoQjF( ݦ@5$J 9(3FDY6iEʆXdY'݃H"iAEa.;yOD$GBSo ya:1uz0E-2I8+/)Z3QrB]+DA y1K2^|2 CGrG:u^ s 6S%/c7/'Uyv9kIhoedVR(m%֢"za1BGI.͊3T!׵)8rAp\I`ìGCA uG gt^\sCKk^Q%ڮyl__>`HYD e7k&9:<&v̓~w8o CY-FVӻhD]S \GJ0`6n)/!0g+ ՉTfBџ=9̳b^I`4r%%C]Rk9@Q9Vk*Mb Nll,J) ]ъ3Bb ްT2e8.0嘷8\sz6Y̝I!["!D\Ҫ_tHXn8w3n"r5:cQM,M;i]݅6vH~i CSA\7DZ}ڑ#Wb93(]g F} TQ;I Ll.YXNܧ 5< paK+*/ߢ1k2Isc !lr)}HS#O%WF~1a*:#pLyR̋skFT)̀R)+ 0soGA;Ϳؖ0hNf}YC69@$ļ9m*"D+NS>xМ[;)^$f`;XkC^%Q䮈olGeef S0/+ ?M-}\yVK$~}x!d[yre Ћp<^Y! d'3.iSvG+!Qn~sOxՖJ D ~h;nk?R{0;vFF;aYnߢ\{aA&$m2j=uL8m$;*sAfɸU/uu@LѨ+A%OosBMӎ2XgwV· Nm pe' gɟy Eka63&V$i },O[|/xcyoL {Ǫ n3χ誊p@?tN5a}R,D&ţpL薞|Nr:֜4H%fD$Uy"t. B"C 34ft$츄2-ۢKG-nXf4c(@Ԡ8׾S#,D9Sv}Ŧ r00tжb|SX@GE؊(0,) ibTë|A1/s0*/NHm}I{Mv"Y9qpOz{9<'T{K$76}L! jD a5<9.4&o4`q>kfN]{tǔBJ!ugA5[.쫝$ri<chjbs̋ء7킑Mo.L >:]N-d(̌#.%R@4 "(M k`v't< lKI݊iiO{4sKOgVF"@QFKhL9Jm/rHpb5Z~%{+\~]Thο-[rV`RSҖ9#uz@!PBzpF9]ϐ8\iU#C(+kFk8dm&~ѯVh..JLbxw-G |r)Y-sNHxKӎt%fzòFiTqq?u- :g+b]Q̼ S.`a{EZkq5Ԙ1߸]?} yVxBŏv@'gmJ8䄄x,^f!0uE.NJ 8<ʶ&^kn˗y5W2C/n{! ,pb NjT_nJ\"9/'_^Z%{;. N$R{IF1CKU,RNa{V%+桨1B%sQK/\H^e=0j>k8|Ҁ8J|uGo>`2n@3^-ܕ:~Ͱ3Y^+]u&vU--3@cQ{So@P2fgE$IP1U~$N:w$K7%i ,B}IĠ%i&ccCP?< j~4z`,4qLc7BȆrW]G6b ] >Jّ+#>9oW-!k \ݐ`/Tj'<WBnޛ]2}Ήv}%0;%&&I4H 2C4'ټsvv^PyO٥V!y- QЀoIәs>?=}iNh$R5C,#slqA|̟ w@a2G,OU*8򽕹2$wNNG Q s#w#WZk@=wv/w.%m$ٵ 9eVXގ?8]F MˆjA |hov*7-h4Y ?C<BN3C2\PP;~xBP( |ǵErUoXAXY۵V07Ksf~= h=(\e#,б+ v٥W[7Uq/hA7oNLݫ1sq RGĻhpS_{h)Fě WDDO[A`t{G"n8yʋ#P[+&c#01\P^W_ %Fan %cѯ=@; K7%Vr~DkTô40~άt)q@R1Vw'{q'fk[o--:д.bCoa$(И?Wy*hv~O[l? ̿y))bx]ⴜZ%S8yF cp{[x%ONГ/3gte8ÓQppDO]nޣct]\9Ϣ 3QA˂EP?ju3RZOi dK[>'6ߊ<~%0S{gj隬<}5QndXo,R[ {A`s9^+}x2= lA^2ysn40Uw~䔣>&d0lMt ?kRw8,fpeP+Jݟ S_Y답i,4G.hqryh[Ǽ:T/8= r@ 9Uw^2gd1KܥIVc<@C81^֢0Hq͌82|;.jRyyR(oNzn͒{M+-Tɂ?<7O;J/zϘ0`+?%Xv1Q\1*q QӔIkX[ 3K:6*0<;#-\ϲM~j5ǗԶDE1o"p#yuGfSݸqd&qp77'q[#yU^ DǤA|]= G"Nc\RDq7aO$ARU8քRpҦ&e!cvC^6v2Dt @7Ξ(Dwl5F9x4=lҾ'stON1/9h$@hą=vlu> я`B# IX?|.TPMpЯaHVu E\y=iW~j4@ u 4wm!qQ][,bl3 '8E! ntĄNFG[.՗Dվ/4W(7pFeX-7$9_!Qz6IDo'A]Fk<V?vKpaQĻfE Eȼ'YKS/>R?dL X g d}Y_ZK$6KHPTXC3#rƑ20BqiI\3f7xpk昄UDylҘ9ێѷAJBQGay&[ޖ̑V/XZ k>#^ϥ><'ղ$|g佡/2C4NڑnaU1x^Y7D72w{?&7[8HM h cxXLz<2ENt} Pb8ӥ/]ǿ%ݼʕp~BjOyiB&ޕXkTc<^6Ny oZϿTJ 8 :gOVs9>Sc h7 6Fi˩Ss$wȤ1Zd4 ;t `bnѻl  nlPЌ";I4]7%zZՆq,aSa (-4~3gԤ~ʋ(A뜄"ҫ58r?1QrC.~٤ht, YeS9jy<)*pc0<HT[iV;h$ I;a!H\JS^P4miÃRP>^5CY"М5%=N̵Nx13@g##ݻ )yz61[^ (9e`P`Z_`Vnl|Ze^UŻ`[5n:I9&|Ɯ5 Φ0R""Oklf 6b#Hmg Q;%oF֛Ç%&&7b(s o8y_j]i ݁PK8ƴ`Oy Hh2 wOld(W.-oFvn b(Tа/3Պ͂-yaIih!b^wfZ3DjnRWyV9w1A\:y@;ƺvC^xFAρiԀ_Vs;Zjۙ"# s^fZ}" yea|*[,{L 0X`˼$BV}j]D]̗cEm[ [;Sg †XJ}ٙ۝Bz2P|'DQ@.՟gtӥ HEKS,t\tUw ]]#gS:l]D tv4"QWGJ"溬PyWCthS .>s9>[oL{L8ՇN IL̼u*bq)kRxƞB<6%'UմxtA]b۵jmOFkUc"yFmPv\6kqk+ 8*Z._ {&{I]Ѽth;ԂHͦFVFnלbų&p~4u~3 ́q}r}F-رճ@>O P(K.>6)t[+ oAajَ]x蒌"Z#DM 1-S'KP@ߞJ9c|jWL]Gn%S<3a$[C+T%"&<H*5;uf"B v&l{$A΃(=ݩT,H1JkPOTRDQCaQ<>$rʡHބP츨'u则{/ j;r::GA$Wzm,n,Xa "5LPu#2 Z5m[NJq.89i>OͷձQ?>!Z !tWJ*F C \Sq]pGx1=@>pa_q(ֶgGKaΟvpoDOVBA|<%*Uy`L}4rz?sydEalzgc]5Og^`3]h,1 _䥠 4i |Q Ÿe='i(Ob*%~L,Xؑv#1(ݚ2ؕȣ6emJbm({B+Gꃨǜ-魺ӑ֫c{u ?FG ı~P9EǓ5HZb!%56Xu:,g{= ҫpqbv=ʐ|nI@\hʖ*uYܫ*['RȗlT5X[ OjGB~ k74-ESLʥt\@qf"szQMWVMD?[lujҮ N{mJqN1Gkscs3*༌%@+iZyipeԪLwVr#7; A?J!Z,ݐ>C\Z?gon9M` O/̱,{-ɟ{ v4ר|=Ć҈CͿ iNSr~5#NM, FK#ôXPYVv_S3}4qTI^z³w_{2 F3fo\ܸ9e 3eq1ؑ_iC휾#D=q!>Q7!ҵի]LsS)^=5DqSX.s!ujn[jIe2 fT 5UWxd^8~ dהT .u$"dMo;栣f=W%]K[Jx^;AYY6|rc 4݈݃˙jL7ycm | |deGɞO5Fє:D Vߗ-!laT Wx\lrL,:SNIo.|ɴ"z4Yx kBy1ַbM.Pg;%1yK98+zpVnfr2 OΫ~ԐJGp8"-&0@9:寢 uZ/{oJg^F)e@cJ>Ej8kiРYC9 ے۠o@qMВ==䧪9LhSCї5uL6E_ʓ pq}:L~޽4g/h>Ace-)1c T}K}0>_r/d5P1`6Ca0dQh4.)?rBeQ%E_ XPJڠX)8d:y*]\58np~6i6M:rcCZMh2WD_}X vvS[Q|ȦA* }p 8@c; zi6[gV;{P҅H1@auB~k ,VNGc )<^51)ܥ"n4jp̬gt4I4i"[=q3y !+]X?J(#h-dKu'edBWX`En}>z\܉\ӒARs @Y4T^t{*7߸ ;F?SNdqdtŞlbOc)_Mj]٤Mо,(PZHu n)O՝&=ĉvDthDM|Fu5L8#G# A/ t RcB{Kʗt_vxLW d$;Zul֞(Ryxl-^P9ҥ?0',FH>-0rZ\BSs }(brq>f& 2T> )m85Cd9 da7`z0^N S?AbƛZqL,+o) սaA8o>PeUf$k\N#S./_7;TJt>}@T%X#kCu2Ռh 4Ț ްyv$)xW KL:x,/C\ļkAm0.s O̜ւuݗQۆaɰv4(,s?MJOD~큥RLB?vw۞ZOm Y0VgPʀ& Q 4$ǮJ~^J jIDUn0=>0(eiA #$P"XdX)Uϡhy= ġ}C ?)8´!}\5f8:0svbdjp{mٓjk봽^sI:ȩᚴY;9".9%gIyE @{T&7uU8QR (xĹȱSīxt5h/ sW8l{1lOygUfcŨ^Ā&67heGRR!Ȣt9#Z}t>vE2$;UV6lhC'T6r$?Q^_nج\=^A}X%3aBvG~#= {bmUو-a Γ6P$kBjZ-Nol8|U2$كsx7L~ QDvZ>.xhf\ܚB3 urv*ZڊrD(\9uA pĈC<''21}$!!42΢NY8! {e52C-g˶tV}7ׄ4ԧE2F E6%c`3dBYBR>+e.2IYVa>+e2qDxFz%҃-U1py3OB\WԮ7Σc+E^+k"óI;"{.h-cꤗ"~9 -q`R/y5PË<-Fm>ǎkפZh(}z2)t#o(EoL{Q@^}"|j?\"쟑k^6aoʊ!{"Լi F1vg䴍ZzE%8|GK6xKvI8yAea|67Ie:Xp >7Gq<  /Ö'2HO) ]n Aw:75%@ ?YIZ:f!K1B}.lqЈ/{Lr JYYm-s 2Jf?#>s_VĀl6>hK8Nc]IW.&\`ؕwL0`GOLS .?A?*BQy6e{\iѹ>|혨ul5C7^I8rگmMUA!7^l'e S^);|TaDOs?M\+hAs3 G[+ݓ|Vy?^؍S#o'ݦ͘6gG>bH4b3t,DIO%c:<*OI.(;+e0Mz6>9( C-v>UXgV"biӺv#yN\t׶*dRI9SO?&M.H)s6Vs.,F wZajp7.6?yw49Zwc]MJp6 t¿ I|1Alg8^Ns9ne d ׂ/bg?rK:[lg>sz !7 : .?da Tȁ:~2֫3nlhfu@+"a˫OɤL(g¶E =(hԼI+kh  T(_ˌ`:%ǵT4:TXɶ2#p?H´e[W &Fu\ +J,Ɓ6# tU1*~!IJh$5ZGyzJ14m@oð}FCK`4~Ŷρk"Z~2B>'zKx<i/D8S~ЧĉzE^OgwM U\Ŗ1ZkaseKYK]\4G;S#4s+FDw" 3Ir{ swې*6ejX3`( +\k0P+`Nnfܢ2m"&WSx}wOM=- Qg:OϡS>5հcU;{>X\Qndb$,j->杒.JšZWcS7A s[tX>A~ vAa+jϵq{#M:Q#7~'ki@jZ80t*OTi_cjbeKSjyKK-lhu0r l\}us@֒*Z7f*tI5#wa<@Fz>JH?psY`] +?px r~]18N:GO=V>0X%:DZ^VKGg|4N1Cy{xE[?E3̇9C.=׈0@B#LY~mHAw:bM&G$vFz0S<9AdM-#9k7vHG (}1zz K4aJs+x<#/SjeEDYd *C[o~nkTOV}R+搔1%_w`tP9׽* nƬ?exFT0BqM DMMW; gl04Yu$)h'WEntbhp8vPeKNO^HN/>8(b1uK>!DR ÙkO~ +td\D@oAi@4KSe7% WUnb+'N>>1 \=(¨n)OF7&5끱9P"za>rVEE#pÍBzQ^ظH2,"Fx%~MP%&D†,)y.YNSdψ鵃 9b}qҟC1S7xTM|[WlM+0qAAX2Mg #==A]|] ;! '"GYkWxKҟ7ȖݖXXyĹ|"~( +2qt)8]lgp F^=).}HaAy l=gMAƑ-qS!!/:3OpOh}F(X'|lOŭ g~&W h8BWxkv/J<iR2]Vj)Fp |}٩zU~y-Q`zn_EOpwDDz`#LM/e0uC"w@DXFnRuƫEsO3}%GeMb}%fsIt,m $6Կ*RNp/ o.T*/3㍃Ӣ(nƀknէN;|D8^,d$M)>CVP֙uj+sC89L  FG7)χKW@^\6"C M8<`3b-,@D]΃jR 4kF&JNύҎFɿx |2>E. :(OqbEhC^%?a"١;Asb"Q7U8l (5.d_'.4".AHt`}5]oIQ[d $Yfv)Ā*sb,R* 6w` b1ԦQ(z#fOl2Y{/;N8n@߆O,I6Z[O#)NYKv{wd\tVfU!~ɱ0Uk4!J4,@^>s-ZqB;?:_J]e&0v'h?zV"V,&5R(QGDQDgNiPTֻfTAd#Sm\ '``q!KHsayR[n@/1-YEm~^6Ӿ:=BKg-2ݥ+>fߚ9-\7ietn߶{sy,/ʮ>!,s{٪mnmNy,% b*^zNRXލnw)h5?e${nބQĺ_ObZ5$PE4R_44CND*D 8hc~?dȲtw0D9o+5g5&䆤Lߙd/+_ZD6U< @e\BvufȾ+@ІpF:H-H4/X|×}u$y7t@ N!dFL5$z[8L-EJC$L:˧]#7ԘnN/Zl 2f I4m󆱺+>́pi<фnu mѵ`xd _G' 9+O!8>T9d,*>&y:?zN'*lBآ>+TIe93<_j;-;y,8>S#IOpDsCUۯnѝỪ-%Bs+{v16t=un~i~O4dpA"s~kP#/Ԟ=Y,*eMYƻػ4Ӓ JvFccUQx?괶G=˟v8#hgC+{tͯN3fu=$ቂP3.B+&(oa3Hu"5'zbI#܇7k~\x .Βi=@҃c823yRU!bԟ;'} émA~3%9TG6ץKɓ3]\u1!] _p0 42uo =E>Zʒ[6;=g6^F,k1y z,'ň/mIS\{ p<|fVi#!ɟa\5';Py;oa jwic(CǹMPH vlG$(^qwSJ_׫\"wD{ .v΄ڷs;>$o^udP[Ax ^8p"DwN K跏)>r?VE7@B[f72M'=/.*]%@L/z"7X塽^ϳy}}i[xڰA(ӣmGiяA${f Bl *7q^?$D"e . O0>Tx:쥲R!yLm) w̙7p>u9ܥ>*Ab`9~4+mwHQT4蚂WX|Ct¸Mow@q]|QWWm5keh@fF{Q%LP8Q*kE@e3hSnIM/C, eHe>e-653'P hM(kd/?WBV5? :5ygc&VƟEUAx W.|9ZX\ qz!!$#)Ũ@?|.f5tyaMH@SZk8W m RƀEQ_~o u,cpljIx ${^>NѶ#., _6`Ө:Uܻu/(ưXBajRP'QF5 7%cQqO }~KOǘB<\ l`^G aő96g`An7))gR0*7kCc'l帞q? cX(+v0.6];vj|mz& ;IŢ};ہTX!H&>qa ^~~ЧpزaI=)i93^0T7>0P/ je( i)!]6ncȍ'&G&|1 )(Qk 2wIJ1t;ݹSz +C@"8\ ´j@N?,kV+m`w#r*5.? ֑(× {&Wɶm ~w<&ꆱh=#Sg,8UK2W"~pl@=9ݭz:C$N>5{Jϡ^IZxYyv*q&^FaS=EKHd ꢜfE%7,V {L Ot}(3GvgxT?q%(NLGx=kaX|VKT/A*C>Ɩɱ= 2gT weJT?qFЮ#ۈ{L 0Զf*He?sm+g'`xu<-Ö<Ϝ'i &47];DžS'ᱽr/ 0뭤:I#2\T&RYAiD7|S*#17X*Ԯ=ʆ2$^=J;,: F36$8SM0OF @8t\ )D3VxB { 0 6![Dd_\Yh;(W.5fBLZv[5w친Y kJ^zgA%f 0ft={9i;yyucVv", i9&2z[^"MJbnb!6wC-N 7ŪQFL$=!2 QɽMiUsA)2jJ0^VhGf,(GՊ 9K:#?7WG7}FoONӦijIc/IH+~02?50l yiLV9ix㿢02zp_E09\Z$-#Ef^5>1ĦSpɾ+ 00 ,Q8q>F TO~儢T05Kqcv<:V^ޫ_iA2:'m[@>咢e"BZ2:n cLAa &hGp΀XS϶3X>5\z LT\f[ kw*ѯFZK j *3$c 昤xCqL(Z={L.'YeP++#Y4}Ae;YT(M[V;o@n =aNQ۵7$7^ѢbOQo\I1RbxlkOfW54~*eJ>>IIf7#u)y< P%BcI>jӁM$F?y^Q; ͂>[X`zAX_2־$k* ZtKb% J;^.N0]-@8O}70(*Sb^y"tcb7%X3D+Ω/.<dJ tCƼgP4`QQ͜"5<K3#.ø({A:`@(9Y@ QEڙzm)a n2rw*gIL>bT5MJHP[UP'?R$x4{JkŃ e0}j_ݶ!TC+b'k'qZ5Ģ.k[>j*~ "wIRl}떴S>L)ׄ:Ijd`P>QG^@mO:dě2[(RNj2 y >&x߼&_P9L1cU`[A!PjW0e)kI:"p$K=Vڬ~D M4g449a^Zu֑4wy:..HDIPNЩ'f9I Y64ɒ梸o:} hS4W|FBRyͷ݆%6/ dEo鸱s%}XC0Wnn#g"k?w"(r򥭏ht7 cREiS_: rͤ@s𗋀i=L eJasTe<ݐ%vpۨmeZ t"B%)غN:npqW?}Ew.'g4ab$㋲BO%*"Lt*̖UNCnJ)`{,7Pmܷ/Qp;=EeSS9 Y*-@g~4{bNt@Eu^%H`6R!\7xS{/Ϋė'@{I&r7TE'$/0cqxA_mq$OX8L*YJ撂 ȴJTZ|ڥ~c{!k Z{1<)Fٷunz٪(UP F!﫦.bKКמ ;(L9&d s/c/:cn{ncZ~WL[Ac*3$H/^ݖ򐙥z U䭭y& 2ip?6F8B3M]ͤE2QG\PgMVFa Wt*AF* B"p 1$wtع`TC怭"⌋=5Vs6yuaEWr)}X_B a~D3B#6{w\kƼoϕ. 2"|N"ԏ_H!I4Ъ7r~:H/lfwwHGFAwvb a&EA+ ܵ>;E[kvc\ݭ&SO\ w?=pP5*r4踞)*;=B-K t]ݏn*o0>91lǖ8fh \xN2u"f88 Ԯ޴?xKcAr69jEq 0c+ = }K 46OUD^ځ͘!*)iE>|Tj0A)ʶ/ժa2Nܦunaw#^1!i[C@0ߡ>:Zlh{ːhC$:ib?ϮA޵O]\B \_'p:! vQV LX#ЩuE>KY'H!ZԌ%,\HM%Dq$ ? "Cnu7]pᅟ;ŞpY[Z_uo̿VSw'(q&iL)`?%ޣԊ G(+4*} Kdi ^\ԃKʔ>5̌~;qUuXl~!@Ӭ᎐~ZlgD1QUYPUPz5b5Iޥ_<.,)Nz0m`Pqm ""88q[wC*tߖO{x z|(0?b_<^Os^@@.1aIJ'p#YA1C{N9Ӊ ?0#3:4%< oH.߾ЪN ʶ4vB. L0GS1.քb+,nKPzi}Mdfa$G$iQy1$U=C>,…SM.^*6 q˭Nx1;$#KT6'Q4{tshbϡ}$XL9ݝ^^4KÖRύH$K8= Y(nfާmvܹb䛎{xLtbS&noc?)0E:)Gp  %&[,N=C۔ٓ]e#8sx>Xm0_7?JהV/5p*粃WnUDM[pvT>TԷF~IɩK E=p9f"9@WL ܴm>a8E`RP`8$ݐ#/qØǡ _<;®QL=`|.gnWeP ʘ"m5f2xpr:5٬Tb#i`\ƢK5Mד޹7JB̈́D |ͳ6/~)hP 'j:x  gD*B=񙁐qs2Wɿf/A\-?=Sn vG8;l&I&:(\ʒу^ҞQ)Hb="nppV5_BI~cND%8Zm*$o~R1 ~࿐i9$!B"Iljʍj:0 ;.HDnԩ5΢F ꠃ={F>V"b,TˀH9n9kNGh&̈,zbTP[W(L]JSG bcC{a:?8˥d AB D/z)=ʏ1sW BpauYPsqtVE: U)՟VY8Qg1;]leI>y=0cq"֓sHRPsg  wfVA!ECRp] Y:˷IQ!iRԤ'}:.]mxl)- bolve+td ?( @ A>}/ӽ%B:rAp.fV \dc8h5}" k#LI R{ 8(ԓh߇fiA*UQAׅimtX,&~t_+/Ŕ=A|B!K)QE,-`{g:-`mB5DgG! \%YVe4c L>)'ב|!\bx|]UPtKLc &w2vh{IkoG,tU)ti3v 2"ӟ{hG:;w"Y\㖽cD u0BI}N򪪀^mˠ|6AExFRrbxc$`<@l E35J"-fEKU c9w,a.X@Ze0x@.2 p}&_)Zjaabr``4mlHRҨ:@'&[W(@k,el>TDL~Xǜd gb/ESVVtŠe{̷暌/7ZMvyS]bjtT#윛(͛g283z$7~<] ੯%UI/F'M40-rN23y!,GdB)qUs/xqԎ^¬r-uE#"L#ų>kz 2cݽF$ore 9p?ɑbl56E|R:f?)O 1clY2tQId@a}'0pba g)76+ JY-6,A]5+$"GۑIkаTzdcl@KlyTA>?.WBzB8R6*7P²7NHֶcD.?sfHo{yL$fxvyκJҧavBc8SY(-1<ېT/v.J~2I'ʢ:ScFM^p "Er'3,9:qT=C)! Gʭo3 2#+`!݀3ѷAtW;3^x7Z 3.Qٍ܉w˱)5R,$&ZT;& SP*@|" NDb{8E͒#TS9Xȓ 7eCJt `ˊ\ 8\{pF[W޴`ϭeՍ(v)Y/zPLU!L OTױs;h 9!`իų=ub@Ec抿CUjW=B{J`,prĂb+#,7Q)9~=z sz-Q+[J|a'*<+`8%z _~O lXwWM: ߱Oޭ!FWFV& "8,Bqe̥opW(2~;m9:H C_5#LWǂ]5dfIPqlaRl(ݫ"%) !cѾ~ :y$FX&a.w:Uח=V]bQ0XaZ@[i~+IMCx ,r!B zCP>CmșFea!~;_[j6EWH] R>H3G O:vP҇N4`hsI"F`prΖg?76 6я(޲y|Y= s%_oitz2^E“eނ40[D+S5F4],t{Gq9b_+$AkO di<ꎊmXzSc>sk>Q?[a1~{37!6+퐨e3 L=W*NVu00`qd.x8n WB0@ruwڋ۾_<T 0nTLٮUG2 \ڢ|V#^IR&Bǽ,zP*i, dҲF ;xE-^?f:O2|YQR,p%=?K<9H܃l=A< w0{\p={xC B`ETwGXJy9ofEm8O7 F#;ib.7W]>O; t-5n,a!zM*I g$_Jѯ+O?kfbӔxӵۦ>gCjKKO^?,zor`NfӚ+$3&RNǣT >L. dr=A Ie\u+dbUy7XSҽb\df<C:B{Ib+ZR:PߊvR" [CXnnmduY i?KX= [ ^2ޙpLM╢MbO̚uvBiU Av-QyߥCVrtDA.œ\iq2Wrxaw;N6UC>#!w{tN{s &Hɤ v=[v7;aƀp(Ծ@'J+Wn7r2&ЕA(zL&="<ϓB~@QV4O`龪+0btK.[RrqԸN̛bNs4U̚TF`Yrv7 bkwBoN2lW7l Eփho8i&tQ zh'mϊ%]U(Q=E|>5o>CuF{(DHДF;?GYD`J(FT]u+F[i4/2,F7f:[48wiq"A\ȳÎ]ms_ ɩdjnRס5重@;D#d4g! JՌ,OQ|viuڬwvW<2snl/ۓ30>QK !vFrr~,g:e K[ڭjT53:Վ_7䟰ʠi[Ġw[kz_<V{oX ̚ )GM,"vDV˽ڬS3=OYҸTI u2U TО6Jt&zpB?QOvM2}_SO滪[jކV?S_߭3A^ęU *}C^e!)OJ<' s*,5 9~fkP^0!<ćvL!HB[@ϻ|KQ.f)vftzh@gx=%=$҃a-bRhFQ4~RVYM׺:)|t%:SyW0hgvyBD牰]9 m=XXR_ZO[:P椄u`L!&gMGbuZyI硤 m8y sαF+ҧ{+F +B:MHAۏ֖Zu_]Ju,3k r=rCIe>̧a4&gȥL3%(Zx{#J`䬓15mKs[Y Y #Ȣk& jW^XzKY1,#HoMB`>NpЈ#Sc\i7/ALZԒ~4 n}==Q̂%6TpJG@c@lx#D>~>9Cԙ? %6נĔ7ĭ dQ#^hi~}L4/GҎ >sěhFeBό|a%kɬ w Vžta9 <6,hy@x2?E"KPĀhO&̘rkG޿ܲw)tz\٫=.IPjl\T<3,c.ow+xR1xB;İFOx?b{kQ.^B{FZ} Ho Riߙ vAxSx(ހUysl32=1 ϶k}Z!埂PčhQMt.mx[;&f<UFRE}MBNz+ىẁl]Bvy,ĝuYfE%{Z_YG "iz=L J!kÜɏsDQTp_|_aU:͙C`}2 |@@vi?¸Bx.a_\/VS0Ji#oc$ ]yV8A"+J9Obx/!y?DJ?/ddu_Hz}w1}<\P?D;blcPKk%6'K 4J",lW"r teA@d½Ny%JZ _C6up{yqI~PUIv wCEBReZ_-dAh,)&o $4qer+/1YfEUg/Ž#PtD9πwWР -tR+PoL䄠qKDY% t&M|6ȸ;m_gg?ƭp ;x:v|zg.‘35) š4A_UIefgY|˛`Ѯv7#N+?5 a NAU `H&8OL8@vc>g:J[H{^o;!4HK10턧Q7Fjm%:7Mi`qͣMDo'$mz\\8Fr.p6>Zݧ9jD.h8wq56bҗ߁.w.eTs|p1owREӐ$G\>{!{?) 6xz1F9ij@!mǍKmbEg8ȱTs>6+\ %5݌yC>:(Z+w|UGІ8Y  =EXb2졾a\z0Z/=\fHO Ralj@=(_݃^7'9eeqT `i!?wB7* Bw5Xqʚ>/ d~ Rj%Cp%y?rpGK}NXKnSM@Jwc^[dZ;chA P9ˡ9UoP8|c$+z)Dd+vp%z{\@Jynrbx{yJn"eùpspJ ŐP[[ 7GmwozҸێk;I[{-WWITIex,&u|no~'vUA ƂH|?8 .oWZ' M=⣊3xj>1 3  ǒl1{qb}gR ԜQ.VLïpnC dpbh=ߤ٫5:v4;6[f ?%*Z\\}gn%[#GKK03>b Ir[xXr Ʋ ;h#f^NoU)z,$P#T Yp/cU1PX&v!5xi<ǖim|Y}WSQ7yn쓪vlɱ;Xi[zOGm&ٛi0,a* ;G{f-W{z6N6ĺԬ9 TZ#.o.cZUAw4 Ɠk &yoDL4Ѽbmnne"f˖Ԃ `-bmօWN`$wNXK` $YR{;Wl%]wv,L/>a`B=Z`D񨾂]JY؃%jT/j+oӨFk+Ga?E6kw\˲tu fJ$H1; al-j vb^YDIZd"%tpWy\-AJQNL6R;1x R"  iJ#x!?vw=Qm~>6]${ el_cU.7-cps `Q nbubBʤfj4լ u:} pN7#"ҞHrMiZJɏcEqr?PPXϵlot%{"|0 Kj]mޭ_4A3}%Rd4 рmOeV6B.~~9HF|`_;|HG)rנ WisV3:%#^H5S=CxsM[umdKNK' 8[~%[.G] v̴ؖC-`-;dZPF%0< r\b^=[sTi̡BIR~l鹆`jhtơHv3X簀(s1-*9RlW1#Eyc,Du?Ș)z >? m:h`Zger a8@ă, m_m^[‹S됫hk`{/5G2їxDfcG/}I="xZ{-yIf bT&%* rGGB m:+p\c3sÚW(+x7ںH,ޥ:mFVŞWU|9`";q$*XŗH$ݧF#(,l rmoqu* /ʱekˣz*oc N)$DGE3m *f䞦gchXShGd7D~Bu^GZt۲^ c%~p(^ܜNe{!]+a>-'R ȋ|F@aǀ0K$C?K¾^bl=Ah%,PY? .19*Wa P:cEm _@X3֪@٭ ) 9^BTATvݽ BRaoeF 7:$>֌]d'6UZQ$, 6R%\͍dASs/heXVZX ߁z)Pb%~lqX҇sz '?>i71]᧵Gχ=ꊏ~PP >b]BoE%']% .PG e]eN}Nډtp@Au[Xʬ#ӁQma9:FRռu'K< q*bW(d;ZG5oD].[KH("5Pg}0{W 3ʡpgmc :8Gh~87g qdM2^`)H!C[i^8V /ߋ7k}rHfO%"\3,/^0=˯ cAi [c^ӑp:pL%܁)^ fXC0Q{8Vt9Luvk>!|nƀjbP hFH~p\C}U__s֍Y$!]+tDem8l6oWeSf:#wLdHGXuI‚\j|Y0H2NMw+ĦmFnl( iGd̈YJP!5 wod<"N 4P+UE;ޯuZS&a2G~ߐl}VUorQy&5QbWiEl>Ϡ$ub^Zp'!Dj?67_CA'YddC^_&5`F_)Qa}6yPj< 0&Tyo\02%^AK$iü pVz?$D6}vTz u oOSP1A%SFj`4h_h+3agDL8)1ɝ%JDA@ K֕@8$MNxq_n?n@Vw|:)2߈aٴθDre+v, '}0&g@~&||BoqIϣt(JGxǔb2ǘ"]ߨ7SUIo@U*IzGշ38uG gywEҢ $hI=#-Os;RPgmk? ~艼YOF־V_xAlkxZS s#uy`aoS?uּ:wbP d{2{ZphDRO 2 >L Qeev(ϛ!"n3[K +%P#Lҁw1/ k%Y2U+gpDq;[uI 5ܙ Nm3MzcM$d%0]zɵ&qFp tǦXY~,Rx'c'&tx$m"o(H86f:CW8vUоN6_m;x6g1Zjr3t&CNqCɛ@բ~C]\۬~.H׊b|?d7앂^8^"U!=悎(ē ؗ4Yyu(S6nd4M^i)i |}lb9^sCu Cb-d~u . %4A[1n YP^NS#ZKӔsIVn^WvLJh}pL)S>fxEؑU# B)i՗_O#_>V=nջ>Z-bG! %+N/"!~hN_4X<27dCCc1m,|)=I븝+P2AI7'.}„5YmS&0$>85/9 $.*, z<$}&!Ws<_!=(z'1ja;zN'M).iW$ bn@a=,$eA(ʫJ҉nYndK&cWkA\~2s[2: EDŽxç;O@ DFǯΞy>$ؿU$^6˾Q\m~{w烞 Wk3 QONKD\H ƒmi2T=W:T}&zk Bah>2EgË%S6\?̟m95HQũV(ʣ#X!K6L$Jawr'Sb `_1Hh\:iYXvv;{S}&~&IY$nAb9>]IӵHvϮֳ`wIN&hXnnzԾm 43#!T/YHFd%6ndCIjXh=妼0eF~t#LwWJCT=f0 T Nk3F#^?K./2wQab/_Kdtۿf^h b~@M.2 z*:#'<D OjQujِOpZrв_@Z}i*kߘU9X*fX,>iѶdUpԣd@D%_L尼_^ۢ Q/[rwTjygt ;§La}Y6mXOz÷:JѺӏm@V~ 02'ׂ~u߿¦< owQyz~)sήLO.y4Nϴڬ^fD}'v ԥFL /JBjA's틏.ݱ7Ԍ0,0 ̊q:*քj a;/@CeߚV .>DΧ|{2ӿp/+k| ]!,%AIT- B\JjסJ^npeKNy8d&]. 踖_㈗F(LӦai]! `P_)J@⾞bצ",:%S֩:RM6ߟ>=SƧ"mj_`$ұ!0n8wAÕU=ȸBT^ w2ELB!CWO pne$ rOsyJwHvJ9r{x H!!\MtZ%Sso7t═ xej}8%R9jF'J}\ ݎU :jҁ <ݨSy5pc7~:L*ZaϗoKrZu,|Y\{P*Q5'ۖN(U5&<}aklHPJFAOG |(I=;Qh m1g_VjWjnj܁GbwsFth^~TCR=\whˌ*# ؐE>[̡ *<4V[Y'XR 5r0)*+t:I2=oxKJ[| ws)yMӕˠ7_m>lx~k<Y6VbWdc E*EViF0UkڊFT M%wWQO_h8(X4m4*.!h%2{% & y>; G+U'4]ۯw)Jwr'>$\ ~No{NvQtoTTQVpfːs|dp'nL\0?]%9TΟ %K=)o`׭I;*YGVM5{ -vc1t $ȳ}.yzxOG;zgvBhgs*Sh4dN=+yg}L429H> X|P2 >$a, | vqywd? B6 |WqcyaP@k|wSҖ$o~XC y 6AzujDƍVtpk#?Oj~{lo__]>õ5ߞK}6G?I.F-A >aa-+՝ƕE0A\Yy>'Aϭ/+DŨHTE-E B, [ IFF=G²7 HiڰyfۋgGcubL3)\<1@}<|w+ռ[E$]]' \m7Ѿ ,l,Ȣ(# Q"  wzOV}vc7VP"":DQ! D Eȁ.i X݅`s*T 99`䎤`_AŰ2-Ҥt4CF"_C"a XVs*T-h c:WҤJ%teUAd$$V|vhEٶ<7AeaaB"jD "&ChJ⋧]` :"EK ^QE64#-a6PѧJH_IY$SD1B@5j[ ȭ=7@L kE4 kC xE @=Pax*"ZA A$[)B:A]B.K>E&Ir=_;˻+ |1$lpOZz2288h mjDPLPQ/Hcg77Ͻŋ[iz|+kd7u:6фqht?j>OARq{NJF@ߝTC/ }5kkd68uN8@PA6&NR"!Zn;2R &r\e p QhDD*tSR *jAQ q8Vkߩyuڙ.P\nÛӻ$D$"_!T--;Y9&:-4]HԈ]FMV5:0v[@h oEW{T8 GCA[^1ρX5$ lEKMyt, q ^*;""5OZ\ (yKj)& CD T\j!)hU49R78osk2/C6v ڴh\QMuرPMr] 2 /«DtDo$o_ h[KF*H@ 02Y Td-Utӆh u8LPpr/_a1X$LTLq2@21DԈ(.hšT@ϋEA:$0*f|CG! (z.$gM+| @lvP4CNiش@-T(A79BT MK`UD |vՆcԫ_Djj- ¨a˛ KTob#Vl@3E qo@vVgd˫[[JӚ5s֗A3pu4RVƴh^Fo=;*;1 ˾9(19l:LM+(tCrw7M: Hԋ0cN7@1@҈ FtB0fDT 4@>[ȖNH QAmoRxriPP[[᭎BJGV02 >H,\L D`MfZcB(\Ϳ4t~M"s:\((p,p.B P."YրǹIF5cLEoM:PhR2`LH #2h).pٯ6B78ڨ퐪28H0sp L_*P:jSȉdQ%SLmVf05Rԛޠ)2EY'*91d dÎhNOo_YR{O`AeE'ΚĜJsܭ.ٖR%]enQ+tJqW)"]v+0$mewʖᩨ\FnbکIN.+a#+TVLa5Y  9d !E+L!ÒtqxlW  7հ& * DA DkHi1RI@QZhjK 7d"gְPǶ UH TF"TB![nŞ7Yu8S@iJ!U|.^eA  @m".?F?X^ Ԛ>IhcY+n/!5#QJPOx;1vO9V<|)*p{kwvb(7PniE!s.s˒Y%۽jՁވ,>ƉTgȏ{~BSX~i9yeV&H( hn`p[DLD4@@hT x_(%WMsbs\iA.pȀ } ":Lb*^C-v+2n\ܖZQ_Svlǻ,yoν~]NвfnM.kmx҂v!x6іCښt2"|; *ߵ ._W= 2=PUUqskjCz:OxXs6#.\OF9p5ګ +!L}^ݢo]IѧS=JtbF݂eD5ΗQ. l_uRxTA3L4PC ,j0D{ "q]3춚$K $,`tXc<=vH$EcRnӭ H̺|I$bIޒBiH &rU!fթ62'N:r\G6q~H17A{oݒC6_ԗrGƌwk@JpKzNzӹ"Yf~jILMkæ2\ϫ8nگL܂ X0Ys(k`TRtn,sIUuU-"p ]c{ѓvr: ʃiZ>+ѝ.Lې`\-b9̴mb9 t6wR o(- JD 5ȝ z~9#$ \ [ `Ǫj\ق t#xJDpp1jkl},Ycݻ=ǭ_EE1.G>ބx0§&C:R,kp%zۻl=yVFDH}wd'* %Tm+2랓rT" !(]Lž_:X<tջzqp#/3$|9]}3 fe2zTn6V[g1r!%9J2'.j\RUS<\˵&FF\*5+@"#I">mn~*ϫmy4BRvH%.!gQpϬ2|OX+&~vSX~6O!eGFziH4(Yb1!j|\eVW>lQUfA^fXS+ttUݦ3w~?tf;].{?%EUׂV+|[BI b5-.PKZ讖ȓhuߚfZp;sV`L濃tF"o"Ӝ{ #6{E]\Pkm|+J5Ki{3:\T;Ͷ2SD(NjkDB㛂_,soPcf|׻i5z-pTZ 9;jv`&gY]1\nP N_p(D1b!5FI/VLP1:ר\6g4Tdĝ-]'cr46" Uέ+iPF9}+ɠrїqrX\V[*E"*E" dAs[x\5?7m5{[:dqT88\C@K3kp9ƞVeR_F͹ɤETAE6pz tnrO?@psp\ wl7GfYϣ趬MA@dg.7scK W~.z( %י1 *GN#q;}D2vQ@1֖ bA: 8kn(%A2y ]K•sQiU"梈s8 |*x8 9誠m QusruqTe|CDP8SynFyiyyAPSV ";F )CE᠊8mN2 yHdӔOE@> d7E9 qQ hTD7QKES"j:HP !p]bq[@8\ y(j@Q^ 8,1 PD7qAo " /Nr!DAW<D]ՙ`kERN1PX8DAotPPLE:(fؤPp@A&s5` | b{H*D $AQb1"AQqJW@vU7@u  6`*xD+j٤ETq0.*(DT*#ERQ:@MQAAWyDW`Ȝ4Q3EQNj$h 1 f.Dz/zCM%h ZT9Qw WYdj CDBm+ '$e JE%Dbr$4 BO; .TBB Rl/fmdO;ʋD>[W]\YhҘ <ɂH4" B`ΩOIw'"~ʓT&t-wnu5BȤ*{Fnخ:V* Jzʡ%$+1v;%.U00$̕k7 JQLUbKi+RsfR٧ -]vE)1<`"y`'7T,JObEi 'yDU%c1!Xh|lNiɥj(#>P;jиKW&,βo[x)M=/ ͼ'bx;xNx0O>xK'7)`tCrCfWzvCѥ˕jWVk Ľ ++~ȫt=qpMy>[؇ ; eev͹ZXh>?Q~XOyVepe|1z(D/-!ZZ.@EB栥-R*1D!FB42Cr1ʅT[#껈zB"QikJKXDJVBګ824-EHE ZF$GPDJj" 8͗jiV@F჉D-8cM Q"4Ѝ(?BH^׸?&G^+N{T0G"ezx1_ j J93G"gw#6?^nGMc4ʚ5Jx# Om FΡ Zs9U[S"EƑ_’9\-VnUyMpu??M=54(0ی$&nfo_Ra,-kYR]Yc@c9289Tu)ͦ(xr#"d&ߌבhVS=oa6 Hd\PE/s@)P)95U>^;229='] L\*}fĒT̻Ѹrb`C s 04~IS)|s+տd MRu;`j<'ҭZقFjD37Lc'D=I7._kPsXI2 @׈_4mT~E\Og[ L[n)J"p" 2W|O󧒁$b>{-jdͱw>Z42I(]R4ċij6ivYuHw.bHP Iު~Wkܸ9> k$@"zZ-{KƔ23]{A +vqx'{:s7&.~8^xiz}RaX3Fs_$оM*%ۢX5bouE<⑌QRP;wP@[Fhm"2yՀ2&#P#"F!Ӕgr,MAYh2g@\MW8?(+8(}E:i4}*#:0@cIbNs\8vs%L/5#Nl T|$Y#hHqt=)Jt{$u?!,J~˯Z"@͹U3(%!^ʑ.g:*ÇX{P~Qͣo v(ۿx?ԵHVۅy4ywlq8gtyvXCSNx3ԟ>١4 rD𯲅[7gBGj7c]Xjk-#{+?WNՖ Q0'PTo:!)N^d'5g{![_%@#Tޛ\Mmj.|`e5M 8b@$. bVqXz6]A"iܮ-NKRח;Y tH0-sB'vn{wFS Uc#s tUphUK˷>@.D7B `c"u%YVj @8:gfUcY WZR٘ū5Jkp0D!ArFNijBq\/78`}g,$Af:d]pE+c(FmGvI6.ɛ*>=lfJT sŠ]:D<:֫곭]Ʒ(5j 0J%XJU4VTh)( n4(~ݮ6τzS u9ŞpgsFp8DYyu@,j$vdZ5BwE@Đӕ `^pbnY@¾EX,ִRy0 &}R|=wE8N}w$\? [cv7V~4M7TzT%U_|[%%!jjޚ$>.]_A J@z3Jh~3w|ۇaa;}۰e멟)0?_?lF,oOt|w㨬f Ni&ϋ27͗/̚1}9y}"/Qֶv qyG)ηHޖ&_yvV_2t̵5R‰ xYD3*>v-}쾾(' '3l_zuvӟWonbbe}[OFugZl^zoدl+`ikO5@ R҆'&yQTw9K?o'kk^D埴n`VKM|T:4)B * "@As~j~?|oE(YփIafulp{q`!9` .Og0/Rllxc)ZmxSt'н!x;>)œ@ ZRS}}ƫB\zOwKwj_\7yg p?h襷,~8QDg_U#;Z =/ڠg>+龤vc <['̓巼x9i8.GՃOݶQUgk|N] Yѓ:ƣ?:[n #wbxKmYuɻw~) 1aäR;T{xfSj/GTݧ5|?L@nan$v!RJ7Wr 'p1_;h/,ej ył._z~s{7H]|N``w"I# y 6"H/ϥTL EhZQh#TTAZLIUT5B+JRRSIK@R5"R--Q@P$RI ԑFD- E jڈ-Qh(DZAhTiQ еKE( šhPQSA2 *ePZ-j*@h7(U`JҨ(([AE*QZH$-DREIđZ iA[+Gn(]ƕ2s@! d Lj@o7|0,VxDZGʄ718Kw(i|w~k4Ҩ=+7Z $ںBAvdbMou:7> $K~8lI āH3-wML/4**"#B)U#S9E^m;ΈI5fiu5[ƹ@R{rvAwf]\H45痾B^~m^Ozh-Hęρ4GXgsv뻼x|7ÏBV,D G=,+PpbK\w;]p<( AL:fd! %_HpQְ45,wc0kH(- Uq#ɜݿ'dss{7 *МW\n.4G1ZC-'Q&k`s RȈ{[1tE^P2};B})Ju˷( d\Xn@d`D[pxG3?JDv݅e=\j|(!v0 #RelO7Eu]J}7/%uٰ\L##{7:aKEC&잂up[,ҩX*M8{@ 8 & P*ԽkV Atƃ30g[Lv;p5^0 T>Y4(zwD<w!UBg- ?hB{ y!]چ1iR|ofM#ɖt76 Mt-Z99KIڄ@Z4m:hY~5't  ˜.ѠznzA@Z\b%߻dHBvOE.z0-4ʞV挤x6۷ӎ :ֹFjf4x,fE.ļ\ i/DFX̥c{*7oOR]kFIs$=1^@"#FY֪jbuɫuE.KJ~1E׈𛥚Yn}#Rra"$0nhVYae _=G_g$1S[̲v,5aX@)U=3Rs˫GoX4U*=3hkH76mT~3Ζ~I䗍r JA2>[Lˆue[}?LM7΋8 u=Wf0.f6d?&+՚|m小Vn8-\[Wª\6уYd$t5_>< +Pi?KnƐBhuuN!8 X8%@Y]L|8=98tzLX :$#3e8nX:(rDe*>𴻱IKxMZ=L ],VF qD@F< h䌧5o: 5"@.|>:&ХiU^/xGTRmIP{_3z9{5A'[Lq EK9$ IF(VF^(56!!YDH~Pzz P/ +Qc<_#Rd597ߪ5}iX'# 23?ͪJ'$~r+l {om;=ϕcT?̠Oho'rePhўK\ڪj*|?{s9Z'G0u3h }Zi归0Ojy]VNJST>Sd@/Tds P?,<˒e)9]h:$ &s-˔D#V )ZF"{;nPՊդAhRI +Jʊ ƔF*+ (QRKj "4*I)W2 C.<Fq PFAAJUZ@Vը*FOH'-ގ,EiiEu9;%"k *%)Q@VmFTFAFF "Qj QJPhAbIK(#CHD %JVAAhf/ *-"e4Q!Y/0EZD2$*@U((;D0*텸#աj]R$JI*4 F9hPҶZRUZPSfZ²DmL"P(IDAhPVPĀ8a-9R+J(aTiUbZ2(i"a" Jmjдi.AUjIJTf̢ E$Dj5ThZP)d#VB--6E EFVP4T4Y@JZ b_p&< +q@?G#δ"A}~m,[PHNJKݮMC!|$]}W:&'"C%εuN`Ȓv|]ɾ,J3<=L;92y'{;Cmzy#'Cy/cӗ9ܛn9mC鮵9ǎ#weQ5Xq5Qyd${ǎ&џF夜VSGZ`d:F}Fmz')_ͼ n3к^=}\|zW\m%Ba/~;[4K{jOs?'C5ٺfoXo2Ų_tz'/ѵzw*l[ɇ7ߝF:6Zw6a%~Nel ׹? 3QV7蛽hl:Qx)>Vt 6Bӛrq n?Ng]4^G wܱ.[g9U|4ȻyF s=p oԯv]^opvl"l 6SwKi#޼ƴDj} Ԓ$< ξH+ 69J>b lj煯%AmoWЅ?>L?i7Oן}gٮޘby\? '-1/c^bVB3d[U?ڴF8+hQrnNKCI^NP`L"qѺpfT %Ep(wzTa @2d)@Ě-Kwx<)/Ն:s3L?WNwYr B*ц R}Y,)ͩ~Gq{!wN|{ }~mBIlitoZ2aٱyusQv= )x"v^s71GR"tͯr@Y|~nRlGeҠy%QZ8_ao].7J;D ɞEQ?ՖboD?^>t29 4!;[^EsT4JT1&ğVLj\wyhީjU=2/o[*=VQL#dByynt5%;n~{[bu.i[\ե4Lw'9aS+xntwf}VvFcդwWl2ry>̷ʹῸkwU?>ʞ>%ɲS]Hjlޖp9~Q7?h]FrJS~0m+k*q}:.[aߟi/>{|,` '{w\oٟ y^; ̷¹| /^=ßt4oׁ|zȹ5-.$ ͮi=|׸xs۷<)O?j]Lᷣiry)Yw4?'~Xӹ˶+Wi|ߓsO!U=_L/ 4RF4 **P4"*"*"R 4ijR5~8%}׌FRdĨ G*4JQ>kM,J#_#J>TCoݾ 2>׊gҦlH%Qw$aYЛr9_ L\!Ln݅ wQ >Dq!% +]! W5AZ;Nm]j :w ng_`V(cF2ue!mTCO3wMA.i'lp{#̉P5y |Dž ۱DLx(7GH+woFkD|4`})߿~yj.a}_&:L˶V,@Mqq8 ^!jxO+nutWX'?sQ~˱iBtǕBMH.{ < k?DgY'O6tB&sh"B2i &V$MÝozp:~}o)y6M]KʷgW^|?ׇY5kq_ ~_q帴1yؕv5K;nF:ya,-*6d/g;Ou_=W3_mr`oYX)f{N[_Y:}-׷7|=ny/կDw?X~O'1LSf2\6(ەWQ9hcL7"{+]l<_SGە(Ck^~f;D~TD:9`c>#jW?r f;Ge|tk5pA{?7CV8O@Oכ~N=66=)QHjZO#$qdOR% TE0tEl$~|@ 2nC6~gvL+3<1!""4QPvC*U CD5=3?.L&))w?z~cn-iA/)A}B[))w_:6 MEE*7XTv`7g<[\fS;:7YcsnQ=ׯ/׹&\t'|8O׾ ;pM(/'!KtWPgv1+?V땷:!}w഍p9{;w[Ҏ؄lf|N;Kۅ~lY{X~z\ ;5~hID[",7ٰ81]'m?&7ߎE|mns\ej# HB2J(-* ), 4ТҴQESHw8r~mvmD t0ѠAZ;l̀"W `p Ң4>^I6`%kA)TV qH?ʮwoއ;&G ~ ZɜMm%sB>+Kh>1[5o q }w'{w>/W1oί|3kli<,p|wc݁c)`>} >USuL@|E-T<ҸO?MI<( Q~W.{;ra#֦iUB$# T`E@_[ȫޢ} ش}!p*H,#L'C C(7J :?vӇ3}E ѕIaN(74@!)9OӇ%r8\w#rTy$"'W~G>_j_3a vhzX@ln:_%? }y?^F9ӧ}Q< \+_G>nnwuMeC4jM֟;UGSloܿ!v=RtP?ʚ6 3~`z߸r/{M_u%j;!u/oOs'#Ǹx9FkjOfq!~ ,?T"RҴ*(/(a>AQ.;(0DEN&$IS ( !+Y Fk9oWF`f/NcQ"__ -aw;Q0IpS 1=xHY. '2{d`E1$&de'HCToɋYs \}`EbHot-zK:ƥܵ=G/O|AoJovϕ hjn_\wYľzWRleȽLGr7ŦԵrW?Jl+5B}%ҏiںY J݋F_|5@鎿y?CH}kg:Vں&W ހCwkvϘoigWk._1"am}~#M#08qf&B ݀`^aJp/$%wM_}.Kָ&'LUuM@V%32Džia*GWQ7BUdD՛& 7 }h}k؏#D1.\iqLCw' )昸ʽT*,Hga %tO']?#}Ղy%?0OpSDCD"GaC/߲z:Wns;J\Lwȫz.q{9}Gu|wc쩏o.'e]E-b@! p9 /Ez%Ø%DIBC6DDD$dBGEQ(&D0B@:"-$Qz/w-Qe>ٕ(Kǒ:A@Y zPB8$IvJs[7a_h?Y>pEĐFwP?j=ߎp~qt/@8XZZCB_FsY9֨s?"?ح4CR(-#/QP_sa~QS)@H ͉AHRK:o<_ϵ&4Q9*fK̺w\?.^+C|&i 7 BH B@>A ̕ĺ $"XH@h (+DU$I<>#Tꠈ>JvOLp*Qրb*#h> QYD"R!b# KPA IgҮ]?7K; H""% {4Ҳ {GλRir*X7*p< Mdž&llo Mfܽ5*m0[NXBGӵ"0?#Jt_=ߦ1_C3?U?q֪V~,E{^ ]W7b+{thE*5 W_gO Zi LJa?']~Yc=6u}+J dۿKvz|JTiϾa]lR:۠7AAAǣ~fgb 8 plV|91"@5aeQCpizޢ @Y(/HPQbC \S=!k k ay \Vh[1i-mnM.7R:;IKܵIPkxj?(9ۣU))?ZRwmߢsq^Q.d$O GdV%* 1lKv3i.>j9ܲ "J%:'m*Q4@˽r*y?Lڂbc8nݳLu瞿@ VUf4H @$P ?u!T;n](d*qE[H aybBI2:tƁA (9>{_[~k{y 0'^"vyXoYh)sĬv>-rlo̷fS_ׂ w&(\P+q! <\nFS8` ~{˔7g'ǰC¨nҷD5=LWzj ȂXT@^~]y`BO#:J? XqR'?h//\M?Fp{F&@j_b`g4/ *>xO<4!f5O}>-U#!0ԞnZݺ ],*-*FfM^[eog:Fu55nUЄ/T\OJgELJ %+^h6K$*$yryI{8$VUz$tg壿WK%@s h4FMUR5m?QXF'Q7x㋯srb"xKJ *")@1 E ?n*DDTwP,_Zڱj:k1־ @_hJ9VFbIPL_0PǧwI _8u`]~ݏv@lA/{]4orUtXMJo}mྣ=$rJN? |ձ3fߨ}v( ;4yL(BC~n#{ĘB#ޜClp^ק蕈kޱ>E[u1xJ{gL p á%p}@.,Vr\ȠsO܈]OgE*vqPyQ1A$!>T ="X,UP%ӎ䁬n81žj#(Ap|6]+ƕ4՗2MYy=O6ۥI…Yy+y79g%<]~?Ha'$"|iy">t;hWwSD!wto㲈0T1TJqFR@SC v 3-( A{۪ 68okB1TֵhcoB6bJ< {Q:(MVB8,e3%>ЬdTP/%V{'oYM^z^"20k 3 F0@CVP_׺@?ޥmW׻}'Xj[6|{:nI&aj H2:ҿ }ŁT? '%Qh(iPTdj#įپPK]4D$j?7wF!|1:Ȇ/M5/߳c|>C^;H} fa?Kξu;}1\P`bx.uziRvۮ:#gDA 6GG.H `!Q҂H""S~@ RA6j)D4i{Q">R}Y#cmhD#k8ޤ cCp85G+'Ք*:ha{5<ƈYxg4yٹ9);;r̈TPSK5S/>,aaYЮ:ڊ q8꼺۽7/fG ];@%&;vƵu$ Oq tkl" =Z[ Xk_}pN4ve-X-4\@@HK~{P>z#iCq ˡ=sEVҩ|Kcd6gN[{^ݙ(C~Ŋ2*U6IfVRn{pP)Н0  A ?" wԠPM5쬬Ԁ&>IsadmYJp լaF`_etU w>JA;(Tn'  ?mĎK#6֔2]2Z:~w ʕ/d?q3{VթQu #}_7:HcPN'QC$ku5(:^Mo >If{w.m&ɇaj-4,QT( q4CX(= tε"U$$oGpm@H#+QՇ$^m,n='{r?b}&K6_?*'{<@nB3*ɒvd^ĶowmI n/--@T~X1ކUMep%q(pD1u L4LTXXyiHJZ,neHLo(xJk@yJC޶`cJP蜜?8/ >)DR'*OX &Jd[?AA$aN S @C90TB0fhl3Ԕ_ B0bQC3Mgk$-Je -e?Oid7$(@F?*w=;/ Tt9 nTuCmrE [s4xZq1( 辽*7)bPs`3Q2vC HJQ0oxJ'Zfpm$bWylfF#PqFh05d h ~` uqO3nTv͢/e0 h0geQliI)r/úfLJe bӦl\tH/8+Ō=7|mǹ=/nǨI.}i`#f\E B!{s+Xc?a#3'PpzS8sҵj uT]z-&É,Ra@xDi࡬ K&&'@LlgIL6ɥ'"ڲ wS=rägPC)=> `vi rKo9 -7+egE^t!=Js6 I`h`H ?b͇=P=)5_.4i Pyr \ I9vҳ;C*N+vn̪A~vV(ab_] d obmS|]MBsz쌻▝r2lÜ>J;NE43kBgAAH^L3z@S#<=AZPmJOQ+ 3"0$nvdu|h)$]Tqq57gj8yA4~Ѥ<G)l/xޣoB2x1B{9 >LSa&RnVhͼU?;Jż 4]+k\phӪ#?A01ڏL?+QO_ snWnx 2fi0y U@vݿi8/9b[X1tQO9;cܑDH&P Z?m+|y|Qu)xK)u-vZnݚ֑ KVH&fYH3sj^e˔7$Fa;a~`ooS@>&nW-)F\}APwFK9cH~6.\gC 46q5)c/ᧁK2972e,?Npb:~yb#~ '3xpd]>H'[z4ЕK(17yjo"!$:XDžWڦ^\dt5S*vbH"1)lj[S.f8atھFE3'Y)M<$GI(BI["|3.?}P ZhK+ci;dׁ%),23@aϑyԄf眘c ' |j_2xkX\sf\#wkpN@_|? VOahn3ƶ/['edÅ<^>XTlmRWVlrmKBſZ2)&ʼ`3iOx9W$[7%Na[Ѧ~TI<mU׿= ͵z6 Y2i֕8>s:%kyhEh(qrط1. IJ -?Ad+sk'ݸ3(]D&ΐ'O P$yY_5|0UapaL5P5U'R҆\YW%o[j^(%㱽ki.ϸe3 Ր1AִHB9رɣjɡޏ1Pd#6(z)`z2[&5^y]RՊeX1+Cg_%ty>m8-]l]&7kdػ#:,E 5/+/0RJPk {L#kNiCrר$Sr&l@ݶv6k ATHGb!~ncS<]S}X,/ͻ\1߿rћV&nHw[XBӧ^ !\=\ӝ.woog wl {4l%ȣ\VuZJā;8W 1Jԉ2ê RFIIB~)[t9YePI^f͝ĭ/V&/&$U)O!= DHy Uci<tJHkz][drfV&bkمMs+c ة`)o ۴j:CvZ2qon`K C̔㮏OՍΨ;J5JԎcc`ѫSþǒ & qL }lfdt%-qPxt̪~Xg'K},ނ!>?=O aI t@p(@ {qs<$~ƭzE`]m"33mZ(- [|lvy!?3=RpxD <3A!u~u6-%"T %s#f `άև 7:AB/WGU?>y>G'_s|o}/;"զ%mCqKdܪ5ݰgr}<{&l^-JzK0/r&dy^{/ZnQQd ̔$~RL-%5Q|tPVs!53ͱ&o}PJ VjyQ]{'LZ} BEfPqsad$_OB'_ѬMxp )J=Ӂ[YӑID<{5zmut.RJLpI\kg}Rt[hݛ?8}D ri |tL`@VDbV}bs-h.{r}|UU8J89٠1(]{)a~x~X UY^䱡}HT%׭P P @ |i25zrDCPf)t[>71 9ˉhn~Ripl<[\(C.BM:8ۧ|U:Ƒٺ4zD-s݂\.' n!ǽ};nvѺ T6tqvKSQ45 3:lg=? 5^ؓ%ņuD  zlų4n YJ-XR{)78n7m-ep ᛅ'_m-;L? 2TY:0)(.K"/m{W'M/?*jHcu^a;5}DLJ5)%#p &pɻЫ Zh"l:Sxg(n)tԡ_ i"pG=Ȭ7CR>ɼ.UjJyp:lн nf46OpkZgҏט|Z[OWH*!ٰ{9yVyx>7uGm~=t,c??;}sHLz9x7xtcFz"R1V5X3zRAx0#* ,+mw(Z=?w+XGEn7*1|7 N hw)GXڌ6%ZeCr({>j($ATD@+qLC}27ǥ ?[ 2ɝ1>ucә"=ϖ;&f<#]\ :iyMD꬚A>Gzx`F+{ < va uٺpF3,6xWxuV2)@}U2/e')bTf#'z]G(1g!:& B2[Xa!;zNF'WRU>>:Zힻ0FPP~< PQ?A8 e"l;_YJQQ7^Ku3~Re\8771.E/,خ>*wP}{t4YPϮz\4}ii7g '((SZwZy^24%aO0.w !.#輑@I 1@\{GaHV8bi3s b(AJxl(0xqihsw?Xe@T+0Rе[\lG\LylIV\7s n~]S}nd& X:Bx }M&VcU]/_c ǾO?FwA ?].~\} ؂A=N`I;䮨7}=$WmXخj+_iE>dUx>>WP*.]7;E1oJӆ%){0*qSkO"{i()OO[uQn~ǁ^hVz](wU٧s- +]I!0 ~:Uu|qD6a ~o5 ) HTA=5"-D Dx |@*쐐@[ tqn ?Bb *}*A_kSZ-A B/@ "@>|4QOyDE+ "HD_$SQ: <Ĉ .o@}ڙc~7k|7>eӾMjC#aNAQ@a d S v=&jH✩vxؑC:*ۏtaCER޺hm+~~R!=T6^īkCѱCݎ䳛9}iUcb!X7nԼ*JދĐ?3ntW}]3\מ%W^.W!:hUnZ̊ BHf3Q%lJqں{.;?~6ʗ ֲd, )she778 JKޥh^GXRle@E ꀢQA OiQ UVE{%! F]9;uyn8@Nw[/=t?KoM&>P!҉KAQQD_,WZ@m*tD@UeQÒ/+mH1LW?yб bw a>k.! ,'SîL Kn#U3:ԟZL)=GȤM=/+(0e\fK)iF\1qj^ ZQ @pA FrId]UQATsZ T>TXb"FFtECnYb$CaB Z(dPQ}AԂ&'ҁID h_۹K}K,mh'Ap(JpGT^!9ȵ_-BȲH4@Q yȢ S!PO݊(I2ʒ"&Tg#C_6 ?G;~i-?]ܼ=@~A`uZ!PP iE@KjD}"m?. u P-I!,T<8;/=]O>w:~k%8kt ?9צ~| Ytpm*$ ?j((Q@|_> $#Ź zh)GNQD5H@ԮCVT>s~8g+aPnN7!20@DX0}/w>0@It^k~W?jX$:8D1u]8ANQΚ$Z|wbL":(x@h 6 •|h*OP|[DZmb1Y>owq5q3(R(Ei>2LTpn Ҿ޻%,|: ~78/^ATU10qs @<~[`j&/HQrJ`9@,Zn ,>oÌ&EϨ-TZC'q"N-0۾zF-\`S8 (օʻ R]k!7[ Y@(G/aRk6uQb r\[]]0ZʄTf0Ώz]O 㜱7]R-GTG0kb Z(w(S zb .=C cjǰ`LbFisy=\}.ly[jhx.pXN9nAU:0eΝLjbs 5*q 9\GbV44  !Ύon`bTzϿs' ״^*#8VIoC<9P lC•qK -RˑM'ת|'՗PU3{7x7-йi"xgeѽ'B夥%72wk>o5,hKw}{vm Ԫ@"A!(XMCE'j"+_}AP.NSTJ 릝('s Յ*<@)sEQo?( }wWw[SXJVoI&,>ϱo9Ffqp;W9HZ M*M ҡ5*ʦsrBZn=Ôt1FWߧ3ϼU <|4[5-dF!8jXǸƀ8]`ro12++,?9!ֺܩ!<\ix %?iP7jKZ^S QxZz^wwdkq[r R劶():O44Z2 oiaaXyyߛ0N~\`HH}N۲COq1v߹{ wSJ? zZ|v _mF$B ),b֚$X+h% tf@ {!r }jjj#Lb梮z=sBm ;kҘDSz$zVL;UI"dtdc,v?|R=%aݙ•B_1Nٳ*s(LL$SPIW:R j\ף,ӥP[E)]h*Co?L_Oa;՘p/_lx9.Ip@MVVW^Աo'׉,`TDiZ9Aw%+&1Q 3SKP0OĔӝh cȊ9U)Cy[?[ځ=ɼ, Pi"-4jS9͔Mq$Q! ( 9ݯZIa4EB8 mr ~A u[C(mhJD@Jnud(\Q؞GFWnw0BRZ;IP'oҍ6Eϻ=7Hh':Zs/콻A@hG,eV5q>.to?#5-s@q : ow\Zى駉Nc\Ad@B؃o평,Ӟ$/GSv߽cX}<S/ fU0+V̽8o;xB %-0tmq0ɔɸ$td pKq XbUDСޏm÷ZCNF8Pz@5kE"tpHE5<&v_{u0$ RA$ ߥx;=*&AmFQ&da3:?}\qSsHlPEu"8r& 0e$?UlZÄL `/Eǽ0*FB<} 5 ู&cJgNcQ|ٶvp.c֨|bgyM4KNyV,"HHȬ";弞QJp jU-QT1k]4?We5PP@%K,7)/G]W4u_[ɣ:M3q\ d$AdI@ $dEۉu-&~SF)Ȅ$xQNlOn5F"|3S0ȐDDp@hE!D?|h9]փyf[HPÝ^^K1]ơ.'£]e2 t#/@"\0 s׽ٺI9&b[#QNb1 6 k?qfΙf._1+( {᱾U;GްW(9[050WYYEBQsOO _@g0(-H{2|8)M'("eœh,g#qWm1wʷ}Z=g*Pq A*$J{b JV-U-)EDJhDVP>7 7iTt_Bh<:R?+4kZra>bpA!p6yjl#Al[>rxMS66חCy1·)NM_86EF_$))1Ă+ V'ً#QЊ XBgU{W|)>& ~ec5v=&tW(>6D ;z0v&%}R .]O x{;J#vNeYͲ/n G!&#ʲ?J- ;賈>^j)f+T*ޔ>خgJţ<_n>HmNgA.~1wX&V;gC6WCGH,MD}1*E>+];vry#0ɢn6% <(5u& e (;F^ȻjۼIMͶO$RgKICOx%@ܐRt1RB SAm0,)r;O\!rotq~ֵ Uapi&+P qE_^H=\ޱ] ]8aD#ѵΎ^R[Fr]gغ,KmەtrcިBIK")5y! Y8I!H( ֓}-CAqKd0TL1L=c;Lӡ<)q p&ŵ "R` G;T`G^+»]QZ~H &01T z}oiG=k1p1ؠ >b:a-- FP>GW񖯜pJxH8UPE rK\:|lk|%y&{GX i[; Iw(C4 ҔP rkOU@ ^4IJysWHD ;n&,Kz9c]Gr A ^DHG .OB st$#פ6zb81$%=P=Cz|otj88Syy&-Rº?gݍSu L,LLkEZ{!,t`y[Q舏t4k^S%qܮx+kz(r$ny5+ۧHt+aAR@OѹxX1KTb,R% ?jH9rWX3kJ}kqݲ, xs(@[ϖEes\IJ)"IСr꯹gJ-˦xו7C/&uh}٬;K nd :kg/3?W䗽Alcy*1'jyG]Ոy,˂q ]OX] F@Fha_3/z_H$>J0/mU 6@cfeWD7\V7%PRT`SP'%Bڤg`_#&cOƵaX Ax)GoUXH?iV MK 7t*tZr9<l萐2K98;^^Jx,[0b@ "Z݈Sckq9q,3e7xexsQi{jUtn'M w6A%L~{tQ' hJ(i]M0m⨎y@|w~%}q̦J?{:~U'S#/ٻuP2:y9$t K191r yt/drj[[,#~Τ_Ÿ|q]7TMV{ eYb;nn> ǔ3ь f׊j4>3+n&Ut4|jx(+p\9-u KJf"RpWȼӄz6t=ȁ$`VaFNgQFՄ^;*(eM`VY~P.\]/"$ 8ͭ-f?dq<A?\yl&"_4^N;-QOX)px;:.-Ju'DJ=&rק̜rjup$TIϡ`=#hr %PIͦHb ¡?%$k}*'&ze0ڛĒa=O%£~-]ِ4K)&ls/jḽsE1*3䷖6Q*F!ve$[ga^˰TzEaacvs[U`w!mwg@gʹBKD# n½풚\o mzvr]ZlLvF1 |`]bzep-M#6hcn 5U-_yz4Wŭl-HCv F刈z'X2P 4, u!'j`p',rZbT٫HMHne08>jP@e.HDҁ.$R W鄹3u݌9b%3 P/%*)ٝVGg( xmOIٌwV*rf6SOѓdm_a] 4'kտ v)Gx{k MeXg*NyV|iy/'煟:ɓ8ߎlR?]" "#R͆Yŧ|;Tǔsy"L,ȇ"u'<8>$@ɷZepEucN+6j/U$rrMH\#VM94&}ntnFV`4QĨHD, ,FJpͭ/@1TJ ˑ "Җ&ؗytMt('T$`ר2 B3/owQU @')=ߚt@P" G+ VG9{oĖI@ZHxpܯK9Ur}n\$0>L_|!(DRH!?_o'(7A}/+^K$/v{7[qjmV ~3KWNzޢs:LA'y)-%tZn\C@b0y1Ѓf_wp竲ay3R]p}Ԡgyj`n9H*9z eG_A,j>"g,~@uD"g%?IX~jܽ('z{68vL) co#'ȗߦ1q /Ky_—xi}Ut,:ꂛe!zrۓȓv60|j3&,ڳ[WE*=noѣkTr&O93JzQlUN =1\N8Hf˕tD$S&zV[x0h]'$ҝG򥩗]h b6}[L@ XKo OU"6kft@3*ɰ(ɸK%=]<λ͵D;^F(dQ|}p^:):fM0Bޛk7KV`?'E\7seeMRvRbh"GnUDP? |)Dn:@͗p./Cr`=ؤ}nX$Ha*I~šy~GqE3<GLCv׳&Pk4j685|+R^+}agʟ5qU{TUFz%Iy.A>&g BVnFSC!S>9Ieܭϐ8\_g 5gaktfhVi}Bå8_s{1`)V/\Mŋ}/EgIVېJ@Ё5qi2S3'6xV7{~q^w&9 KKĥHxxVKa^ +Ns r!:BOt_.l ZٟleIU_v^.hu+OZN-k.S,LlYkeNMHw#w)OZaX]K:F]Mr-K?*ʪO8*D@ C@⼜U;߷eE>TC'T JK6/CCcyONJ*01=r  ˍ0R ]j|YUBo`?oR"Ο\fbNS/(D@C #߳ax5`8,z"vO1@rдHIja^2'-DU@W($Ph9`Z/qEFF@޷zW[Ry mD㡳&#, G$(Ն\dQBD*S{7E Ca L*bXuaE>{&@)ս .ў'M $ 9(kMXf=]@$I!JH5yڳ2Y4V^~O?Άxyf (b RCbԱ| _X@$dDdU@&9mi֪~MQZ<Ǥrc˯}g99SإjB*DԤQEh!GdENC%㈇LR@ &[y 4j{\SG)p Ə;x|' ܻ'Y^'sr pTR߿BN{HI MFu'g,-9:"H*}BT@ "C)twΣ 1>?K\yA5IAbyʢFAREA{b@PwTϮsqՁfSCmbٔ" (_vRW{y.P:yGwQmϽ7u0~ۛo-(wbT>aMG]<W\4ۺW]9T! >8T Nu\#k6&-Ϛ?~4z V44?ሰ_6aLB  T*&*zoln hA2 :'  5PF_` &fQ" 3BȖ,Ϲ%/~]/KЫk{2q$I0[)A;&m'c7D7hD.kwiJHn?RU( ݣM qKnK@c !P%8YH<姆\Qr^t^o??b/?+0œyfn#_o-АD*3!77JU4pDOlyqF*.IyBq;$ʹ eJ͐aT`5`@6T #m(l\&P vKvI_`Diy=q$+A|+)JM ,)W{9{ר "%9.D@{&٤Z?-nM3[HĤ@N{Ú{v''%̕Iv)V;s>9UXa0C%/%#ʒLQYT$$r=Q!|R%^¯UMR=Ұ#ZD.DW;~N@ܕ,x&=2|[<..~!A!D g/Bz8bCԃJB$7pP4 8X .˃6O Ѷy;4I~af%D7؛ B*#`a&9e D- ,j6emdӮa_ EA=ޗO`ֻl/ͯ]IIw )M^\F>$,v H:~[+P(pQ$@u`jwu?o=O* -)JA!JQ3vLpZ|v +?fs'@wBY \ J PWMx `2X0NT+4HO]!o!ja#kıg?6.q%Fmb,DdU*sU4nfsB@BדL~`9B1@"2fMD=%lij>[.攕.\7SɍYt8+ذ2"#|qֶU2CZ:Y_B3Ư?3;rai Zk^N&fI`TeC]4wa/k0'oˣ\)+D.-Lӑͪ2!}LeZs JBh ]\Ꟊaxh}@wp[)3VoGF_`2i~~zLuLav'Gʇg[\dċ $CjTqO0miHEBl+M GhLoy+k;(sҀ._=o/鶴(Ը|?Yzq}2{SB+(~Xġ),h+Ē|ȁ""@J0kz#095L9׫beRUQQe`(Gw,ϣ""jjs$mU (H s+ݮ~Ms@jeSSkE?rR+ @ 4@O5v`@{ PY`(P]]Gb^OgJsnaCS"!ykG4HA!&$E!G^@{H *Z*%Thٖuu28v MbܐU>/m( n2]tӫM.+8~׹s<<\q?Oș`?)*UIwF1:94OCu|m>z0-%}U۩_U9H=ϼ~;C6 =R\aR4c|TvSb'Y`RH" I҉OhN( A :Ň34S~utD@5% ~ED=D*"=G 1\q(k40ƥBI1.6V#⏖7 4ޖ[ω4ZAmru~h=8R3o մ@@lxH5"`(Q-y{^K;NJJ7]LG$ "Aq E@1Lr^\Q Ғl٣Z6 ϦȁlAr?'DCMh *u|#4v OX(ٷ]t[jxDt~lRe҂t+~O6JI+j43wjGK_k.G##;wMaWRl$kj8ThKr~M岈! ] d y94s\cz:2 J$LE{uִ ҘnׇJ%) fY۹: Qx*_ZOfniUn @K*u<\5MZZp%Qv]6m0h^f=*w< Џ$ypZƣiT+ F():Q`6}iܤԧzu^KͭJqNZװvvY(r淈{.qf:dʧq-Zh}uʔ<6l;ߗ\QEA-J#3ZͫT6VLJO7HurGj×ދZ몍Rɭ@#]AS_= ;H%H)Q݌ f.s'KrTY:뽺HCm4yb_K(hU]K&!ĆI ib6@&[À8R/[Tmf?cgXڣ :5KΜcȘ.h/M8_D" c/.T_ Mwr#6ylep&z15NLCC]a}6GUw'I5j*6\h YJӷ%#׊6ŹƩ8\S _+'ڄ}Mn*\'9w3;4䱶>c˶ C3<,`_su 4ˀJϯ9{\ēUs4 75˯*gkhE\0}'"F\ŎSxȡOx@ҩ3q31I["EYRQ L(uZ R<$c8~j8qd*@@O$7 f,e>k=t5d|m(0z%OzPˆpe51I  [T Jk:@ 0 䎉R~"),47)7MRe);j}=pMaY;DRTMKٔPI+gJJ eS ngOt)Ɨ@1knڕ*?R_Z  a|A_Uv_N^H>,GwoI1P;c㧙ǦVL7-:h8l#HCy߹"HlɡB8@ ;8­YQ6eC?v Qw(pwN<[y.3bT?^L΂1mϘCx=ߪ4(t0BmS+l??Myط͠f2'jhp(8 ER Trej)_)D>=)^Kp7*p8SaG!@T*RArX<+P!&H85*}jülЀ( p^j Lve*ZQ B~[ʼnͭf:rCo/T)P(5LQI*T:[POڊIm)@(]iCPGFO7.S&i%/ҰC~8~P\XPeUM(1k~` TUy>^)Txmݮ%}K;ML>m/EA9'WK/J/Us$|]*ZχC/t<>A7N0\Wu~~o:873ͨD#BP&(|P੊*k*IrN$C)Yҟ}jm+JOܤZ} x_H8^ʰ e#y2@==;i}MVJ kAE}FI*IX3k~ɉ l:=-@ EA^PmϡHD*U~ǹC[mBoYlE %RD$V#P=,;#Ss]7_ɱ|4ڨDW!?f "Q(1nO$ӿ6:nKJ%P] V-h}MU g"@$6-NkUBQ B`zwLxC}H\c8WkۋsB"w1"hrJ} Fyף7E[I-*Lz?H?sV$;Xv޴Pn +RG+V=͠X3Q6—}ʹVrVXi܎D/UX/±Y^XPccK? Eb/pN.Ҹ8RJcцXn}q|[% ) ]7u+ kB-孝ES:1@#'n|+Iܵ1/:ZePgUq>ԛ⼻L~7A-.&ř7 WjWRuq^c(dsuv0i?z0j5$ ,ѭJZQb1,oڌ'baXZD~'jOb&M/OJ XUg$4&*ܒQEeWq""2ʔD)q} &$y `$"4f`@ [= 6U4Vc ݌+Ѿ M|V ~TϹh'iڹ ;#7t4FzTF)dpu%9d.N70̤=p r,5ij)׸Iz 0 P_L>%dbvf/[Ңc2oW{WS(fǻ$qtUw"+f:rS} epWo_ >lNKH!3"LJ̽f:7gǔ G*$@\ܚ&:2*W*Z{[ajO/R5Esj'9Y-Y}5/ÑFI"omb{'%resԸ[c%ż)J~mE 5rrkѻuo`?/3I`3sBWrpU0ݎU2\{;ދQ`a9k r9{U0Dg|baW*(H 6?TEjcѨ˳]<93UIpх g,4Jaw!=kƣy2͙ J[6{Z餜+5uVd0+h>~N_ԙfĄbWŲ[%Rf's`je.`4Ďvlg8䁒8~d \x<; 2L)`5ޚ('hyc"mz41 4:jд?@6gA,6r@Hřʟ߱6־.lg8h^^N:t4}M/phV[ϻK0rԐX:ɉ`V?-IQT.$B쮵9!{/0G ߫=/@? eK4&V9]G:bҪ"@s\b ]VxVwx_huv&QVBl&)tPgm23'vI_}dX@&|XK̥[T%kclA5?6&=O#yMo9G%i*9m{n(]ݣ(8&F(XHPlBi%NeOC4·\Pz #ܠѾL$(Eө4̜_aj RD47W- # K  $Y q ƌ8!Mr9)҉aRΉT yhe%b}K&y(f1z'չR4%7ÎAEoZ~;x9Xaܜ4stQkHH|!AH`L+%I ~F%Q@/.]~bh7R?U{'RAv~&?F+=YjŪhkWҍCuEa\USW漻.%EZhP)b1Q ,07s}_7 }Q$9/Io@SIȠ>w\#&`ӸҾ=2MgUQi* I.;/~x݊B'Ú uϽ68qX*( B@_3DF y/" nbJ:R$>f׳~$LH 0h餩= Q@0G?Ap #"(PmF5fgI'Z5g& C߇ܥfB :Aa!q?O ޚ QRYԞ>`mm[@z~3k*~`='aשg5M1W;Z=!H.CzlT "S.ucߎoUk@)LT9ĬT/fR^+j7{a;!E^# N YOJlQVU:4wh1c`.iYf4x)Y},kVo{_ XRf6۹k2 '#g-0: +-³aOO_a1QŇr2գN|=Zu|!ka6Ql>.+$hpJfw[sRMA7ٷiF,,Y pw-ksrӒ= ;##g*Cd\ٷzԻ^9HFѡ]j3Nƣ}'8J᳌;+`@=[@½ MAj.S@Y{p@819yZ fm|Oᕧ+Ƞ-/In}Y 7c3;6B-r 孷/9{s L?—=;2z<\`鞃iK"fps9*j7w2$C>WkT%&_xX7g^[r$(գGow&Gg2CoƀUmbko5;&ImלC~5-f_tOW9kޖy;i6&>W bMg^1VMyV23fu SȞU4%I0)dQ<&cIǴ\):RfGaՂg'0}iux0KZߚg3VjCzYpXK2I꺀U }%>!ܛq0,PҠp64Pm%AFrYY*BkUaGʑ=CJI 1g5Go \  \ͳ$t0IzVqv`j߇C'{m.SJNi kАQv +q_D[Ҁ YGD `9jj`a(R1RZ>xh>kB CW}Tv~9y):BRs!Ir5TQJ>ºa^:rwz\;x7gC9Gi!略j n]:t0w4Av;A܎uz|^::yWާݵ *2[=l'*9OqZ=.AT#}:@V܅AN!8q Te<.uhpS>V؅BH6<CQU‚I!mjϑɜsżvїsYB_O2Fdi۫Hk> v5zM,ZU߷*REr@&bW%部PS?/Ɂ8M cǢ&iځAmO/ISRQiXEz(93wUBiPmBJT?U Gf qY[Lk paC ˆxYQ<> =irc HȌ(PpfU*@ BTgL Yf$qPCXv*1T1G`Dh )-V(TCt ֥L.ʩ9,,jIi}S^̼/"^1 ͻZ)g{]8[ܸ8RC*UEQF//:QPiå:V5WC-~C{*SfޏRV.Y ̾Pʕ8>ҋ'J=([5|_nDSE"ϱes]Nn!ہbx xM=2Z|4˱?"`l ,m"H@ɘﰱs^3HfM&)yؓX,36-8Œ.nb$n+\:z.gp5p5UJ*p,}e.BkNkѯ q$'{:Bﱦp=Sdn6) n/jhI0!0.Ye>]k]N>Wtq,< 95/&ENO'X& s tꥭVbmc9k6QŜO͘:&9^8=y%tar -g߱[~-ٕٹHe:DscZAN&@˽rLP@ gVXs$0]{t뽰.aPuRVctx밴ϲ%nPy|NH'9r8ƮB Jwx=P{UBD`MRo>oݝc+|jS{EeԚR|RV!n(4RNzH¾:*GwMwzҞxu|^ZMOg67܀^ƠrgJXꪪ[(d_Za؆C!?7sɃ9 *u]hfKw-UpyDH%C%Ţ?ܝ+S'.䨗Rr\ȱ-&QBg24`ͼyԋ RDJqVIuʔCJȘ}$@MVMԷgJ *|۲n6e6?yUq-}P ?ana9zv[:eē^m 9HvE| Ģ)A(ȎCCƖiRjBUuecYJ ì N~, 2;A5aK#Q)ٯm|m`̡_EnsԆsnmZjц젌 )Vp]ʖ댦RW#{t5O@42V=GGZx=ש Й3Nfb1nhJ̚aߩճP0.a%qg^HYn*f#ȋ%+RηG܏J:[ފh䭋4|1,e"wZP6WczRƑfJ3['*$BÌ雓MO i+RuzE֟n:_u32i_maF)*uX+ ^&&@$e*;˴pԒHe 8⑄?gGoN~u.n ?̙)Qsw!g6\U\wY$eQu:wfP̦P:YߍcW.x %×3vqў,5bTFzy_mLjumY-2\hwi9$\ b`.$쉰`\X0v* .ޅfR97po-az\?,yȝ$ 1cvq$궱29!P:i"j]CPqqYzZX4Sg5-atT>.bN6"jY}3Uiy(Hd p6&ӜW8 u1г'M6(@`6{dg6t"DKQB`/OU94TcǨ{ݻte91{.3XR.cq X2e/ΛbVLDcQ@Bn|iʎa)AQqM' /0AVxϫ2뼼]զχ3*:Zr |$ڔ! 9&kR}*azX_ؼ)I'zKQ׷B YPUj1 ?恃(ZwAwKFP.i K±_#K,L0OiAd%gt9]r c  >KJPf ZcBre \05ł^B:K%`#|d]lYl;X:wَvI6bF+d0J7~!)̀SW4hxlTB|JJE $P$Ra]/Mմ졗4bqb=;sO|p.@QPMwKSӵܫVk =$"$j&C0;&&o%~̢@UjLC>ɚ%;9.&:zaw֚ՒAeB$)Rڊ X] /U4_!C@nv-G`@r$)>9"*^)(@>M[<f$t{_Ψ a<#a_ha!-ڮe,XYrC*%IcT .G\<)]YUq$1=Wқ&w@%q|z[vHGyC5*9UsVU D+Y+F aHe(V%jAC~-::+8rW*ʼ NC{JglS8 ֛Cɽ[* ^;{Nnْ&RvKtCfjKu՗;7A/ڇ(;%aU,!>u|ុIWBkPVQߩ]TyFHxTo"0źd@L64mHMgXPLBp_SҫU.7N|.*tƲչeJwTdp`B =JHUV|4 pA*BjVx{ⷹm^X]}cq#%SbJvGդ5Z`F>ȏ}NKaP^߅?wX2= >U ^VH5;@$2i{V)2c䠻k[J8IA !!o!r=Iq/]{c~}EE|x1O}%F>GXA-R4G+r~ ^>AuZUaF2DN {L CK~O]hs^rm#QU~|;+5!ݱ&okF %/xm i{ K"B.H_p4.`|ާ5𥳐2^2E*9e[ESwx>F{ ltA;' R>4d_.-Yp=۷B/h"\w&۹IKaqg wMq[bɝQ;h9wq~6/Nhqb+r54JSM0j3KCB>|%ؕ*M*:cY5'͈sZʯI?зV_7JqQvm/&L7R!H1+R5C]Ғ0|lY4QUWcM+93\rGrCGj o[0Q)8<{+:4/2zW>u%bJΡڵ[SBN2nx"f; mC.β5+pbSNxV57߬(ýlI8_>zaӷe* =;_UogP2KӚpd8%~|'\r`z]!B@ߋWdǕ2Ճs 5X),dnߔ\ʿ7yX6`8rDH2"[%Sۼ qq3O7d{$97px~*/7 ^b+J)Ç,io5 n7`Fͥg;?WdV2 ML;7ᾤdJ ²E ؐbPj;PSpAC_Re k0 y% EJ}&ART>n)G㽨}ꦺ\M+7صޥ+2Iɛn!Uԥ?9dwV{? al 5 Ӷ~ls# %IE2ͩ> bP$O2Jŗa e&:O!-k%zK9}fCNiw>;CqOeZJ;*ģG-?~ 4wŰl\fZ"KAf' ~3n2WJP7<zH\JT^vt#'ʁ磇E҇zhh$ȽuI_ ۣ( W?Eaߠ.h1՗z꫞;߯i8 #)\`)?uZVpe,jj6(襟0w0.]< B5ꦽt~eQ>teVH8xku3#o4]Mn,6j3ްU)D> s1(`vW_8bѣxK;m tueVy?O:oʿ%VJ䂜|QgM~1]湲=cs!V9-XL/8~]/J6j)B7  t0S@ԣI*1 Vh~>+@:8a$ L,淞wpw_e;F?eeMi E=S*|ɁRIu,ZRD0d~vdVS-JI{hIGb(jteyҙ7 \BT!*eˊm}kv#&z^Ăhrӷ3qBHA~K(RUU8)hUp {ɋ]sD)-,;t%(P?ge=·Ѿ+K@6^ 'pzw0 ϯO 4GzFX>^v\9eݵ=P#Zmҹ[ FN1ZP4w9t;L2>}ĝ7q 7iˉeXJi=&m B+rUVyIU԰SwŞ[zPZ9>y H@|0,Bk%Ҽz3EW+֬WUEF22,> rQ5לOBKԾ hRPl0b%N}lO%c&/)U~6: 3+@f?僀jH Î%PU/7|axj>h>+qӜy( v53q\={\Q g]j #:F1kG&N_Dxh;}>TI9R{]_afR`=es8V&$rz,3J.d4A6e \=$nC2vI|u7FSTkK=R%Iz)VWR: =б<+R\66$Qy^MV+8 @&'n?dܯ=.@ 6gN=nyGT T=6Q_| !]T q0y@H-ĴT#v> 9 C劰 $6p={AQBh0l6IF9?t,OXIKG;2#ҼisoZ~1@ȟcJ] Sb|Z.2&p- _jheɪ^h8GƉ\ Z`Sq1 U:J@Pԝ{txss_bH9*ѓ [:f$)x*SI_}J2U ڷSO3)r7Ty].N6ԧ'+R:nU!fC;87ڵ5Tס^roMy;ޒ^(` oQE2d5|+i1DKf2IKUNeRk\pSCS3a yswXnqfT:ZXfii%l.}ƖrnȎ7Y%jAJEE~os'bCWsB}KIȜ` ҥm=2F !@FRJ+}s6T(N[Հ[oA右ұVN Rv}u> nvYQX{1O#c@!uoSxL8Q$LJE~b{tظq$plpmrfSu.[{/w絤fK~vNTvEŭPËi՟YG` z4:Ǭx`bg7Si6۩'8jk0Aubp@~d>K{WfҾR룄c9l#R 'l3bh9_Ub̐T,ϟu3WVD_ou  *TbJ}xs1qiW{Nn1{g&aj,ɞF,G#nwk= #48ZU~ ]5a9=Yi"D΅U"cR^IԹs_}5Yį6~GC ;.uy.p`zyF,cb77vw7'6&LF(hY0#3'Пb3IT#Owru9iҝvKvŚ4I"- kb#Lٙ `e\IR뜴П谋KxK*\ER~v89{D5o*~ǩis*RѬ~Zjֹf?atJd|YZH)|7W]9}Ter>(8""BO[Z#|g{Pe5L0!6ȃ (Aj?S2B ɥp[gx[kz_'Gg!fqt>oJ'pc)Myi&qʜ6'Ƣ*HN?(}?aDL}n¾FjT)^nTڡ׌M@zXjrzK0D.:*{dk$TVWskRwֽ!54  IWcHf?Ev x+!Qx_wΙ85Gߕnz-+LLθ̙h$GJ~F  VŸ?Ju솠t+*E|yNK:#|;ؐAwkaL4%W签6F2%o'Ïzb)r$$Ĥ2[8ܸ H^Sf,4-̷9eVɒҜ2+'brt=V5nr2b|]񸴕ѴzMao?LVǟ60^brVĭCQnq4f ׋qT$ii-CblM)# G{6IGQ!IhҳCYok{Mk5F{4fjZV a?j>i;on2og/qT- _%؄@bk1:B4;9<(m",.S],$E]c"4P6hXa {ϔF8C 9:[wL'*anfѰcLiЮ/-< u#CHýH]D6D;ӭ:rs'DpnDȈds6}]l| bU3;DțKcЪ_P`N3_%V, Qˢ4׬zzZq=R[gzݵ>KTTMVMn;Th!L*%CߖV?/ꍌG`]ڰZqJ'":z݋nن7i,*v.K7ETW߲[|N|L*; ۥr8s2I5Xg.|/a@5#Оμpң%JĻY8=Nw˷Y ɒBrݥ"z\K>PAG$=}DwOyBM tJ_zH EE^$GS>Ī~]ח̖Eѽ~2f!4ã$ &X'ԇydP}m; gs N;qfjM>:Ra뿍xBuQHdڃQ'B7q?SŖ*(ͪ*$$n}< r #_IO+~E3TDC" roLO.rܐ'X0KE{1]RI*dG:-2iޝ$sRwyO:׬OBxJMiFBt=f+x G?#~OB^>s\8SvR?Z[uHr{]}U]z:hof% !=u1^Я>D~J:X% ))&|EҵO4L\խߩCf* ?~Ǣ>5p-|MYv(m_1-X%7G;N2/VA)x4A$hN18f_SM񖝧2/Gĭ_w.ԝu cH :NYx ܑw:4~nj1K= 2%P[ ##5vz[6QSODO4wkεE䴾P3V vde=w|ڔ $: 򶏳u *V8p,/J8I$ D J( aeun%+ uE:5\Prh^`[|́[5z][-nɺn?}s} 36bkb̝B{'L'\pJ\cEO+$XaAoܗ"@HJL9*[tw]n^~ 4.h gG G,X7>ul0{Oz]t|푸8oO/?:!8euCuث5I'|TҐEטRbB֡Bcq^zwѡ 2"OA iA;Y($j_32( @UZ1BBðP,Kؽx$:j̽ 7%/H7֍f=Q́9W#_IcEji 1y}<$ + yr=f%[PunpԿMz']P7* 꽦PJIs Q஘2gB $&12cL];S!Bi!OULho#mmYopCq!nt $_/ yBeZvqt,KE|g5:*֙P3aD}uh>Me?祴 '  젞B\h`i >d~iEK3|oN/mǽ<Ο_x]w7.DMsR,I SKe=0pp)[H* 灊oG4( fewҸVY3XDED?=[?P@@B<ʅt+$wz޿+_re+ǵR{G~ixr Z)GAGSYt.2"H;~_v0.Uvg&  #_H<(PM"#H̱oo (?]@{I=ȳc0̥L_@Jݝ)_Md/k-O~dPi-S}:}Ogd])Zk7/M=>g|W;sD?)RSRHHC'oИ1!gBI1oA[fMݲ# l`"SEZ^©Jo1}.z_\p Ғ5zI_5ITV?>M(QZ_.bR%T]~!4ρdB]\rX^_f&3*0IB94 \3bwZ ^AKJmҨKGF1ښPoh&91.8JPd +Zw+DR[啛*ؓ5cY8ܵ~, h RQKkƍ-nhALHnN'dL2@p)$柍j=}i@uA<}`?M@v),xPnj0%t0zN@$]CiLQ&+$uiZ #HI0%$V?V62A1#ӎc.m8NDZ9qїpm FWzc@rޛ5r FY^#@??]K#Q1+hBBH` 3.5 -*QUj#~qyA*3 WJ#H/(bB+Hu_w{"pDgsq)`peEV+Arv{8QcH$AyNA4fd\d8v]A/3 ia#I~ 2#*\qmdT?=C񳴶Gg:@)ڃsOM8!1)2B kD Ӊ Isci&n;|a:|]Y=)dDV !7JoX0, Җk|}۝uRmJGk>Ct raWA6SR#jXDK Er/zhJxN~kv@ XgKܾۗ\A;t*tCN<:VhdIS]7릑E8UK@a BI@) &.S]r;|k. HhɠqwTsJžL*#2ae0LAru0ObF.rU/ժWRɽ?;gÔlYOdĊ}W !WdWB@DH@6|eN| F&BGl6ChHݝ,ߩXxR\?yi) Gn"ÔT2{HG3vt*mdŒ:obd텽>#n!$iˋj o4Qv;Uput`JAk4T s Ks؍ݕvMAXCgWS)q<0"$O깽_O_ՂVV4 8<[(_J;zS$D82zŧ5c˚ASUmW?>K^E8HsS9baUGZրtm*uWk3J "@ܯ/ֳ ;F"a$+<$TG-Z-am98h1L.B(5RWy7ۥABc͔Ȗ$PՈ65FiVݪդ-*dq!㝼-~dBZ`Q 6!M'w[FcJ=[m@ 3,i4 ͂-Wbt)8yʖֈ&!) lwxWin5;]7 *4P0B` o0mH:4kY@4u*'iRLu_/O,p1J[S^c]TY Ƽ9MV-Û*d)7t`] $ȓyHLi?BNˆs-.Ւ9Kkbnlss" *ʖ;\7d(D2̯Ө.)$6*KоmAsl 0ٱrpeňmH˹F;e|UZi~ k,BvW$@ܶl8|@|B`fצfHҐ?]RXݭDق`4zU:m] )[Y,*V.)m%0NO#h<}Gl_ss~`J0 0Wq$T|*So~9{iE fTD]jw)h`1zhޤ3M9@V*%. pL3oد\cTW1>ݜ|H=?Hw|9'Sʁ2bEB@®s1$`үb:b"kPC\s5$2iM^̆H#F@ ʘ xORSB[h4WQ` JKd'pfL}$x6LI6Эrzҳ{=`I|*R"y#MR ^.ZgnN1$D;?!J]+N;Rʐdo* Rh!# BH{dE_X12͖nY$>߂^b@xk\Z֦ /9|3Hd]Z!{)e3T D!W4!~2CS6O!x59!km[bŬv+x 4'D3}\s<FhV5>]pؕl%Ux:Y_4N2rxAN7g%pU$??FHT$#_߯Eb- !t7dDU * ?1@Ġ ?1 `GGTiEOU2Hݙl~߹A>G=?bqh6`>W΋*~{߃}_?WJH0a߮ޯ룅"IG8sZK];Օ)_Z,vkεjk@0Y׼j/<"$R5#t=tCKaeXJG~-J8!D4D@?wJ<\J?V}|^>,CeӺj,._3 5g4 @@E̡z<.(_tK>qcca~wK B{e#[] {7Ox$p` sJ p ooybtum HߑZ  Ԉ`ZEE>ɀo? }Ďda8\(P]Wts];Vc 0qBP=G!u_ψxE@"Cbi4SL@ Uj]'_ 4a@\: w1 T֮cMi'@, Nm"^?$t8DUjH7` .@ q!DDS%p#w,P@J237n9 ben)J K$8w{}h=[3-\P8dA$O RkxYV%roo}DqŤe TB@u!<h(4C9qeX@bl7 BOL|x,u\ .kA.#n!ɠ S@tadurT7yq\Dej1aZ"/5XRPAh3(\6Qmv1E* WlI$WwVV:A*AQc1;\7\E[qaYwp6l'lJ$I[H'cSI>@ !Fњ}։%uIUOGLGeQͮ:Y-p\+-0   &)P``ZG;> (B2A@Co7zfaUp_ kC~ƞC8UT\@V%ժ Ki?G~b|D 棾V*&^U{v6J*g= zݷroiPA9rõ!D㥓b( ^FJO*u)RRtX<uq D/m}T5sFTeX\^|35i`a %sr$N$T\ =l{~vX;@!8N pbLBm|2 ^3af哐E]]?2l]N K<]IuX1]L;:xp ?8BnxQ˃4gjyT,jϏ{ݳ_J;Wl֋Rf |-8ːbhx[h1^@K E;&7Ž8&CX̞K^ [EmOh%B!`F\ 4HP H$oȋm??/_|Q:3NZ_֦ QT-U7ATk9͛8R-0$E #q1DzDQQIĐ>kMl">LQ:tj%G̞Nߢc:m\(Fb& Ef0(-jS-q0ɋck9r8O>;,&{A2?@)<#Z-(؃@߬C_OD~o?)^AAx7$yfӗ#{{Z#̾B r-]1O!arx0r11.Ѹ2C|zJ~KY)nYʭ_L)^ }[{U86 kT klz+jIdagNyp=60-qB<!H1c3<5X\'hϙ"j齀]#!tZS^rAYjLt#AhTW7!_^ճF8 ܶz"D$ x=Wi<DmdAX(zΗlu9ኧåX.f N:Z" >aS0n D'RK~ LhVa~NbZЃ^#2R%lsceͮ'{4LΟ&n@Լº[Z )"rV>F1P׽?K,9@WP>z@žڱuF /e}9.φWu,U'5ƅ;Y(Q.m{$)zRg-0Yiij N*5 72!3 C~Jw\kypJ<Hcy-q:OnU.甽fIy}q0x=XSL}IbĄtKKonݟ{/wު)bӇWq@lejiTJ>p ĎE0 0ó֤V̗@֛3?Dը;ڱkӐAPxe,I,0 Pjf Q64HBHHf/ )ș ZminʳWt1wp?ٕ(?w3|f@/;WA@ <+5y t cX(~uަ°oe[jWk % C/ȴ<{g"P$ ^ M&{}EoThjrϳB&U~b`u(>coOoy/HoCK>Ibg4UhQa_%˾ڗ}>PRV7)+͔ ~Do6b++q'#fiy#@*WwϷ7-=:T=(TvGeFbQ) ᦃ[ $;BGjg/`~19؃51`tB,Hnz mkȦ}eLb%)`lo\ !%wP-ȐĪ " !lҿ;l>{JCjL}2ѥ3%3B*ғ0e4qH 4" ,_-CHB 4) phSL8<1Ј߇G/r,@cFzᐰ)Nࡡf1m3v}TDM T6ɽ_luoq[Rf}537e ŷ[&Ndշ§Ss@zS"pr e"v Zuܢ@#ʛ1ZB.R[JA`|qwkЉF/-HghIٳVtJU&=eb ۹X(:iZq9Q cſW ?4+9hCM@R/~d9Ȅ!ZJQ0c J{\$%I Dňi2ʸyR~g!pg]8nQϛ6Rw(szB"dA A&(LI}N͉u!oAlF#/pi Jʎ[,8Fr{P(!#5o-B ? }g+fξbq/'"*Fے]\]PPI" 7VÃ4'PR3T޳4-l?Ưl{DT 2{(^fF`U-x+@p,Sy˹FaXAkE5݌c&CrHNBtԫ";/5@0tɁ܍h<:i%w%&A-E"*;}2}X`6~IG3j.ڙt~n 4+"MJ0֒ʹW)ujpL6&ߊ!1r68 yPF6VViE\ &sǶ<(~^Ub= +'Dy8Vq4ZcPB#ؖ 9<-i5MURؖlڍ}7٭2P; '=sz  jƅ36t G>Gq=f&޷n@~߻sm{)6X ҅\-/}^giq I|N7L_">T?{<) b櫫,?J[EZ 5X&4@ RR5KdH6 t RSOK=uŵqV Q_89"!jK\Ϥ$!a#X2'4yJ:/P At19?bHw9^cN[OА K`P4 ^~ϟ4& 2+Vnq4 Hγ{8h?}6ׅ.*[ib:9Uakfm.d'V<=8FbfRb2U)3hob&$a_V3 B5WwL4j/ʓΪt'ͫxn75SZpsh X4@ˈ9x83qtTH&|yv&*K؊|׶#"Auf @ѱ͋&.4 xÜ @{)zpʻ:CrpxLf8n-};dx`!eϧE(10Cօ%r'--!_^Q/{ȷPEC;i1Em,j_Dňq-D^I;ۼ`VIcKhmdZ- 9Esbs(Ly9B&jMW` R8:PWKFqs(mbY;)"-s.{W/aiHgxqyBL v+@BO.Oڬ4R7>KiCg/Uq7\tSGwkU~pha[ykZ3Y$(nJoK'T''+i)@ϓܢFEL/{YҡND95{KL~,ө~>r}}`>O͘zC~ 1dn-z+/%Q8I!Hd]-OveI5V G3i\/ޗ6‹N{Mi@͇[HKf5[|y˅U+tY3,{/c/>}&`;ą[.y[uwB~|ݢrLwH"/ϫ͑MNiX`_eVi."N)vFXtYYMV _PO(bOmZGp>9ASC $AE/OڕNPEx εx b0b $l VK<|h ԝ}yiR 2"vmp^M|m%Ґ3/t+#Mn9+9jE3J;pZ4J9v]`L@ xTXʖ27h iz /U#ΔU65A rEL 䌩J^qyGh,a1vXoq5COAUUk>1H09육)`ax8^lrdCsR[yNMP?* ZܸNNNL2!9^}椆QFTSeӻ7*>Q;0r]YYOsyfiWa̺:o\uw0YWL_a|ܶ/}$,NhNóvG\l`(1QrjU J[ȸU4\7z; (ґPd*L@/Hά,Iqxt e [HlE`TNަ*SaԨlIdH&ڥ6w!T\;ANkg 9#"<es蒬hrV9˄qQ85{98ZV(,\ t94SO*bdo9(ZQ6Ƀd*IˤD55&N 1Odn,z?:8$~JJMP1a@~LFAW55_dC`A笁Inڦ>:6Y-tc{*XY0EMڦ_-8HeIhkimTbߛiV[-X*fv,4׉GU\G(;Wn]Sz:8<Z?d&L\r.)xax~I}8ڦdpށA3dk\c8r)Mbe jGDyȈ:'xCwr=l@4Q],UL'ko`̓F̃b0#Kq6o ԛ4Kg^n~鮁I5aA!Jb<.pP$8@-g EhxY||\ޢ"VE ˭鏊LOPҥ {00 wvɂv+_9$ت8͞M-S 'y5x_o6Ԁ wh*)V)& ԏ9p,},2 y3܍Ţ+/:˓!͝F$j!UP#1)5bg0‰@[Y״' zEc`cw:=674i=;Yv z aj7͓.`Q+_ew@-)!2:NܱN׮:{\vX^u_a+57 mНy;O޶mt&BNxߴ&뿝vy[riN!ү2tȄZ߸#H\$UL\+gk ~({ag[)}.\uN]McwU|vkHbgrmJcM\{b9XE) S`'9S^X24T퀳 |H p\a%V3UwX$qzh>Knoo[c@fU1A[L4b[|#yʱTN>KY#5 \ͮ_ʃLccNO 6rpb )Hae6ߟMwݡUs>.A\BFZ~3!f/9 Y20:/,TA"W(qnע6D`1K#H s\ ~SX+KA~}ۚE]!;~_soﶥCs,,;]\/b W k84.n?M/@Jղi}aE&1fjyBAys3TX͉@ggE)kxpb쮉,IMozۻ7FC%aD+d?NoX'-X݉F v[]%Kr6`,$W{_YJY|_ǖHYӗMq>-Ț XC ^+?r+R y,oN1|̖TgZL^5_) M<5IL搐\R4VN~Z3œ^4Rãe@ B0nöA,"$G%\/g+8|B "nat=3yk$$I$i;K#e@Z$H r_|4j\pH58K4 %qj鍖R3HP7%)!m=D4,\e];^R8ȼYQ !Pͳ o: #F?k;ɂ&TDsB]1=]ϸJi|V%^Φf{gtJ '>2^_VCMz\e/҄[/Ss@)}K(~מ';"oB>iA3oWZLs.NAD!, &,:Zz]Ȱ UP6Ò_4sN}\%Paהǜ*-4Rqk -KRŹ_S{h7Q f^HISATFZ < VdiU2`fZ}0/;ǪJR{z/ɇ#'ON@H j1&hLfO)_;,bH3 A Q!&1N'k󘁈drO;I8ҬCnT׆m7H՝vX&a_ ~N3a$/2/Zg>M{'6ㅑM"T 77ioo1 PIiy|cs51 zvj=EH|8 ƨ6;a?'#;'9p/ K 8ecoB(]7lvpW(fi,S+qʈG)HI Se!Nohhޟ[f?=b% RF;;RsXKsѾn+" t|2eRp4OZ~ih$#`Drܧ+xeù 5b7@tPF@p\5$ ]Fȁ,{+)@7T.8DDq@?3͖(ret/o@$bAW~'Ǒ| 31Rt<`Ă!CP)A<&7_TZ!3<PaX`\>% qdt5k̼m_m;DŽˢヶ쨮 K3>vlf>0塷adTcsmn\ݍt#,E6@1~vi|ηF@dnXӄE.4۫1T8Wc慦 {K^E_]y2ҼcRUO%rDb&x|[d4 Mp۵"n% WqagӧA%x(o)RHg̳Wm|MCyn:rp5Is$Y1xI DjX\e4/S v_P3ED1h ^v _]"W ԾZO}oq=?S`SFuewh}Mڻ=&]rח>; \* iXzb4;{{y Tz.5 y5JoU~m3q5vASۑi2Z,G&u8ռ2Sk/'\pycgd|@BID\9ji=S7`^&xie4 =⵮~9rA9?MMzFMlA WD6NlԜHI"DNV[e3jlI52Z8|F#F߶˒[5h^^0L##@d | =>ݩdӁ9B7msur;J8d5q- "[]T%YVܹy;WEaX*h0K{k)z^ّ}f/tٕӛF% *\ {b%(} 8a^;J,ܕY`I2ƒN`ڱw?ˌ_ğd?99WiS"TԌms\iA46tw욛F}?R;Hm`m}H^)d;^U 0HaK04ouۜL,PX"*[@@$K* lPZ"=8\ńOQs$zl~os&^u!@_"xb ŀ"їhs3Lݘips-^Wa}+'ңW$'Ϭ=Vn^]އ${ok١AGwdu:؊S[Hf`QmdDnyx%#G+k@y)<+Oc1~e_`1:@x}Nřcg7Y8Bs=?PlܾΆSčcEe2ll#! z$!ŒƔiWw')3Y]L)ٗk.:m#\Lj2vdoصɛHAj" l4 V &"H= Wsuʪ|G4"x2J05ibM&Gu&a[WID0՝g‘ Q@ǎBP XtGCcv=e0ᵠ®op<{SF3j9742&k$řwPkOM*YHKҿVmi^q¶~$?()i VṡA^4kx85@P `  [CU5\]mj_#?\l(b_`RmXrĘvcQDH};;KInlئZ<), (@ :_վnj*nͤnxy` ې:0 d8=q&>c9ž|o^x;.mjDR#{sAT2IE#G݁I񟅵lv J@wJB% ;;`}߯)~{9HC~iE%ա1-qP%k6`qG+|y8wiid|WsY>o=!Lj-3?v!.>齧r&C='C#ZꓸV4F!UFB?5a.<}_IKH1PjjB>K@VH+'Ob4W`@Q%\rIY$c' IGD-.<1y@zD>HH)?gH?Dr# $pDd #Hh^7&̛?Zl\2FN谤w Bq+ Mg+RH}S!;1>f/;7)xX~י|f ~<%w߸L1`J `ۼ>ɼv{|+5Y1~:&vSEVtL4'"bK>p!fLs?=k)K?K= WFuA0!HTėd6#1~_'_ 'J.x߿ҿڝSD.A=o::rRί|o  o?_[;y|RNqVb͛~SSNj 1oࡨSDon4:(q$dtbQ}:-E:Wڸm\Ʉa׳x yB  m*{+P 9ag]W2|ʅp$UvNLӮMPŮJ{?bv|?a&;J+ȵ}@o,taLNP 80>;LqZp8<[w5pHg!܈AXƒ~HqR%2K T[H3.7K8db%(T EiQ q/898QuFm :uv޽*<\;'܏_͋qˣd5 Ha$~2m[UGD%`YVDG&3)~Ǚ_}jMhЁCM0HaM\(,8u( ZqOdհBQαfڜ 0c\f"UL |ѷƴFYZ|hi$*҅ >35b;[r?+GO_*7>hPxH-U8R1[ 0 S>fj,pw?pe6^ a)DK\ĺb> Ad \z8 Z,F^wDr@_sxqz EXẸV8ᝊ kg75j ((_ J15B@4@R _L ]jH~ÙtHo0|^Ceq,2  o*v-! sH(Jn g Օ  `rJP_{ޣ\o5>DLUCoa Q , !tag '`SĘa|Bu0 ‘A\@XtH` yKFB 5a+9hC;S6\%JI(+K0͢ސvtT%dGQk($:qOsYN@Ë)7?lX`NԩR`#\(G'mq(NSZk}>cql)^CpF?VBddM% J)[ =d<?6mO6k4}eZO]C{i.#0&*ĞChՍ^Ǐnl*9s D㕝<+62K>c0DGlPd hKT 㟷s򺜴qƓdV!ƥ |iAjW2,'k- !;`$!$+_r3!(&"*n@Q"ҕLD7,aM./'WIc%pйB1%$P\A;*n=+`"{cm}'%{?-C-($!$|NZH]0BҼ JҘbلÃ)*ڬ{'|*z6}i"uqЁbzSZĿc &!RGsq Qɋ "?G rpZ1c*U٘n+ B&[Q*jk-~nmZ܎FOd+[E;=J$DA" E$BD$Ir;5jםybd@өr3A=eqwwJKv [k,C5n¬Q;ivUǙ&J<ƀk)TD+0!ۡ'*H[^FDQ]GW)roA_恵Ub)>X{?D-+th k=ikة8(5C9C?ѫGN<-x~~|,;1wۊ!uWsa .o'0K(E Č04RO>J4\>* ]c; cdoOƐ1@'ψ!)<.k߆v\wJM@A\rvGm8dzB((FTCF`0JB^)U /fz85%Oo>W\:[҆POWW)-;=7Br/b4ߘ/-/\QqLy b2P%(N 9 [&<)3 S.cw۞(Bۙ59Qf< ̢KOB+A h.!QE ! QX$h 2*U)B ]j %AtLD0U F洕@!$ZP@6jPkث|5nJCjׁ (s5QWgwLz^P$DgXs3: Cu{?<-{@+U;DMz-&%Xx'@\aP `:n3Gh! 9ArnnLr'Bb8+K:ҙ-gE7RIAK J0Ս!u 1y˽*NU7 8IPeGD3€2Sk,odʙBJ[`Yh)+BFvAZ3tiX}/W`sCK6\dL}@ҕJ8= ;e!XVcHu*oɝ8D @jJJť;%݇|c+ E 1WB4 Т|lE?D1~b E({t^Dr9r]̤Vj",TհΞf1)J#4LKef#N#+AMԔ5pE)Kir5*2s;uqӏ & ɮwD5*tX2Cl6HB)Ҳub5ݕݜ^/L\7`:X%0, d[JܱO \booi{8T%nS“KDKRk̀`Dv$k'K!4:nGѫ% P̘ $tMD* bċ v[`B<$2.4migKe[n2 rMv4gn'6,gz{'&ͥ:Ի0*H/2H H HMD $mq.>?L:@"$5d9qȅql`. G=1JƼX^ܺ:r%-jֺʗȡ,h2A!f6c 3䲀/2G&&VHb̲EuGS^{3!'df}&/ݦtv{MU:OYg{`%1*{iDut!}O;Y!{yS U`}R MaHJA0e^^\ަjc:$]>$lE @|0u1~rW2P~\tغ9NF–qP䌬(%hzL ?=^:/כ3!]<pdMӞ NHf_+$!<'46.^4'bMnN,u Qc;Y]cPhxUy h`V.YI5U9{oc \jN@N /43R qu4@+k27ZyWgp.]=՚r2,^Praq; aX,q[^ܽ&ה4R2̢,)1dt(.ા.>!hhEN Eu_mΑe?Д\]zL Gvv X( pPCeN:wHAR7Oaax/ RΞ9@»ep#,#^?|WwOcqE6- {SdVQ-rdRV =}lO .; +s~qpD^d[X"릖Ptj`Cx0嫝+~Y d!4za,s5{)nGwyh6otAF7 KHݽHo4VvťC]j*uNծ'C ccwyXS̏VnvHI*Vh2 d _z=#T˳{9o/[/ W ZS6S]\;Ni˪L&m{I_44|| UYw}h3۬$W`q8yJ-NQU#(U+B(unįǞ*k{Qb$sB-9Ȫ0!}i#ޕ?[efvYdt;֘MiN&2-C٪gDɥWvvmI"oNbq2 xV $`T[kU[oK4 @Gxe봿&Cm\@KsCOoL֘Եe\p)tl*)C 7.?L[TEKP80/{dh/N8TUi+^ńrSafB "iQE&eա39Z wc"5@&ٞB70G6uUA8?O '׬8jh{(Fd%WOcuHɭBJq$j:9 ӝ0Gk?MBb]oDUqY l/Y)Z-FE9׵ Fߡ} 5DŽnUI'#TA*x -/)o:_-RJ0$yr ǐy'fI<2ytkv(|;{U`K UiKiIRv7f VJSfTy6՝hqkOe)M0A0N_EbV3WΣeslj ChGk̒~3>x e 9=<4q)hS.[MA[L>QEzHBi_[:Ƴ~P9CW* ?.#ZT]ڝY76T^gNhLnc9zv]NN3/\tJ f6':Y_4?@% ڢN wfMC0VM.9Q+;4@TAiwG1:79t/bߒU't9 G~Opoݓyn9DU g&;YXuB mCT@% C@HhId SO6 +4pkb[M$  iYpcPOgj;r(dv5&IVN%( R*(*7islrc~G9*8P̛ČX$#fjP3Y LDacl#\|C! Qxe"9JkZLٚ[LW%p%(H3 @suCu/՗Fb˘h?c+-8)TNpU$ePc$|okAPv4,N>9VG_sK2[+G5G8 c 7,@/KbEv4eh1;+.)D5J9Î1ķJaQQΟu=ף3aRH\ l!G-'/}ͦـqQ)M{Dߡ rf;)p@$,0Jwhe .2\"K_K[!R$ !qKH%IMK Z!ϸAH}MKg>%05c+;A dQo?VpX ɏ;NCù:ĞO569#vM)2##+9@IpUO2m'i.t h (pЗE5en9uwm2'No)7& k0@,k~nI?qQ$q?&Z|]L [a) 0 |`?8/@DI$y?s RxJ5`;~HQƽ&t; R ÂR7J|LnA8ae'K ʓյw˂HJCR]U2o>yď_' 7 \dtjwy?t3s=̜T!rwO)_"B|e~{`)y= Esۅ_ 0.z %ICk:6Y$y.jO^ ߿"-ҕ7eh͋euu>}'?o Ki ^NH&;%@<\ #I{B\>+ǝ[^aO^^sWc؛OڥŲ*c6o:h 'A'Zu!D@/t4/?l'SEe'G @ 7eT򏞳= y96w=M}HԀr~7:.k3o,GWU@?oD;O~F'$?g|lkG2=o҃>((AN B&YYU餖yL3NQJT5MG?X5~,^O7gZ H#K& f.8:9J]-07o.3\zn-sG~} Om=n?_?]&?SŞaQl0/9).gG_Nj ڇ@ aŽmOkw4<_Ik|Vs/֪~\,)"=/z@MPD-",GMz/;.^#{?v49L~W!(Jnu' #ͣ%[OHjVu5>iL}a>ID$>сAGaS±cKBkg~_Tx9BoWҕ$1pYί3y1 czPT擐@CLo,Ԅ%Am=̾]Ec' NkcT.5L?=\Ϝ,vĐ|vwKb&wrh/ȪQ=:B3 6p%7$b[2S"> A&®w3H CqC1iسMN˳YPrw:==szbr_dvw/=s>Yl?l3_:ni4 Qi|8}=kl_koW3}:/+oEv4ئ`Svf|l2gmPyZmm.'> J@]տ|/UҘCk8Mm&5RGyZ6<I G:M뙎gMۨftYsͮGCHI1lkv$Pv*) ǡɉubr P {p|| OmG?ir~^t;|󝸕^I>%W02)6ǫrrwgoCk>5{̦e㿀Y ^j ;3 ~-?OLg.}J`|)*}ܷ!9y@Ӫ{A@o Xh1\01:k5{,ˏ]Lz4%BO :M!JW~1Weұ:U8NtlJN'S]M;_k: Mm_+b7^:}R۩iTj;X|wJ2lPYMDzv \HJ[0 q8hakC *2 N<@,4BHCB6%EW3۔L@o@$0$HD AxQK`h[b}_81b\>Z _#ݾ>|; 8>ޮʣeЧ8Bnv>YDh}{>&#龯.w0Nۯnm$sKSY^[,FrK Ҙy/O{.;{ nv;NͲPe`Ԧ$3t>[9۴eO""g>/Kqpi6>2_)6c!q){c^,]Z^}zO,~8tpOj:-[ Vx:Z~*>ʖpVM LӆZ}Y+M+絗LY<̗ao?bt^ VCet4P6;< ld6ڭl$`7@ a50Nu&fE)ScvgO^\6z;o罏;{GHwvT.+R" K˒v|{}G῾+91?~3_ ':]ž޺"Q_u J~ciE"}ڋGY;^҆C$ D]q5\!z6Rm! a@4w"U&}E_Q߂]~a1ve1UD}`9 T gSw?Y~j, ^ϝ7eOwCi}n9K"+}3윛_ 5ռ^_ ]%.eW}=F!=h)戼W{`II'ݣc(@ 2P_> Kg/8AKcх{9‚Dg>Ш2;0e5$ {Dy!P5vĠvS6jD!f]Kh$OMɄLҋDLY p2G sMrX5b8PfmQ[+bQ/R!Q4-A/ rF@CV(Ԇ8ⅴ@zQ-QЛ4@ޢ j 2 !E`'ъ({mCkQ~n}׾:qܡJmjJS޸{q;T0==>\Σ.ٟkU!UXVCb00Z*k,ݖm+ávilMFg+_y~_އ}'ރߏs`vG&8A~Ծ)q+3Kfb"xOWgIҏS}q~:PnϚ7:H,A!v=yFguǹItǴXV)/asS..+ `mP $4  ֟(n[8ӧ*z04,gek(ʎ-y P +DLn3bP( CJ !TR( 9&z*ӣ}a_z%un'y3k, %?){dFc[)qٖg'lnrvu(K * ו ܅Xݕt7CK(ls*vչLn**}]ˬ梷d*6\vݯ'խ:?Lb"O/ϲkޏ[GQg~4;'?dzv~gYgc r }'rz+ZR'e;ɸlgVeƲ-{~;=_x&6h18$!B0'* @U?+hk/hׯ . slYo3W 3!?[K[ro0^`aj4-.D,g@dZG:*hƽXXP9(/IVõUb-E HYR!o6//~/3.9Th`ٜ[뢅300Ј}ώ~"B>aX0j4wJg>2U>1 |![na)D*z v HG0RR%4{?{msÑ)AI_<C_M-wP^]-SPuz= lԳ;KКX[GY|uKcEA܃fcM՜p`^CZ@{= ~˯Soֿ~oLr0]SZ0Bu :&d TA&\.y[ߊd&1{_C1R oN>doNNEp >ާjY_m_YVn~>]#n-|Wĺ?v%+t]&-z)ZčT.oƷ:y=q wG{pVoEtӟ9<Lu՟c^HpJHE/Y0^%!,(.[^T>DUd!ZQ ?{SK(-+FE$@|lԞ[6Z[f ɘ )bS<7a!['K-]m5]48-'KdTpXdvүߨv󛷘6:Ē]6cxUD|,[ct%e6k|:_Buwn7ڞ`/Y CҪ[twӞ} iOKԨ_>cZm lZ &CjޏTzٰ"R r̖Co=>jش_+0kC$۫M}䡨`ژ_R"!gG;Mhh4A)jf!Te2wGyyq41ϗe9DzV˿o amu]Vi+s{mzrŌ68loAv=RVV4{C׼ =c%lSJC 4 iV6af>mvUHkJw^/Kqmf .tȨ|HtwP&K>LZmꟵ>/עv3svR!"7Hpnnp73>SJyd? }=;?e  Liw#d i/zhF@`! 8T\1 _CDFu+=HE%na ZT[Wu6/Ao|m7߿?`bȐ aESvHBkd Lj6>IMon/23/y` 1M fD퐓7mvJcioDߤq>-W Fst`U!D yt]KOIΚ|JpDa0'Uһ0._sa 5_.@4";/YՖ ţ/-Qw e~C"khšs ,GX_NXkHqYg@ iXٜ^磌KTA$ (A) BRmؗFSD$p{_/czu3OY??f{=9tGsU[F٢BJ/Ҭ0d6-W}3ˎW˻i13=OCe?ڗw_O9bv;41[1mD%6:c$膂;;B=Y靴n?'=&Y;m}z (e+us5mNVzj]~*q!:\ު%=irjCl; wm5`߻>H?tf׬u2'̞7[,/F*(H5znKW^ #)u֧d;Ǽ#~.f痯Zo~#MsͶBYI*XimeRwaxgv]Q7µӤ7Az8Gq Y*jG; KrޯG;zZ -5rh`V\h۽fk c\rHCȢnԭ=so=<{;at8=6YWF@"L"`ָ߽cݽ43Y5Ǯ! C_ tY[:\tż^碓~6X |"gN&bpCyy.Bhh4+"r4=$ٖAiۯiHO̅Νe[Ϲw &_Ůp_9;/t+^Cqmsl#'~n#3 t*/mY˜/)EWco?/>'7yL?GLϙQ$؞Vv'[Ke^RfE_sb;Ŭ/OUv|$w9rb'(o3WFѻHӋ;hàp*K GT*j5/(WB2e!DQ!{y$ k|UA+ "+]waDw\7#]Ehuov?eovu̳*R5va^cCמDYˣJ?ْY p^:+ p9 y&p6z!b Rύ߮j~;M~4a>Gyǔ.ph[$5]UR,twGT6_դLH-V~q F)EhFEz[JKH@|挠h-TCKWhÉݳt* 5a0oN6̣gt bLτZk֧<>,'; ø{oNدcX&g: ar9$SzϥmQC~ phS}eb!/PI?3=uМu>|,Ӡ78X 58J4P܄p_܃[hJ#9[? 483k~ C-Yc1lr:i+ (%f\ H\GiWD+!=f+ wdI _4mYJӇ',Dk oփhJG' psRK@pm>J 7uC9ˌ|M׳,aZbx5|)sUeI\mO: vd.\چҤ-4d?cpC450.VX;vTЂx2e}-k'vN,̣\K Ͻ#5u%J$dwɦ1x0p]b^UҐb&p g?O#F@;{&$ncccTtgUT1uF9L4 q]\;+ ZdO4rM\oC 1#{wja9Nb-hh@# NWR=oHah&w\˜~ s:8?L:x+4(J& 0t3%' @9(D1ho}Rؔ <<bXO1ϝ1Ph ɡ >Glw͎w7;͌T-08O5 A^n ( 8\GƐhQM{R >[;NmP2H { 6pבGMJ N}9[;'yYY>q\u6E:Guϩ:8d80f<gfp@ %V(ߓ~7ݗ vFPCdClCͯuqƇ! zx=]A# G2HMiL8ca-S1}>ftdwDV" e.B1\_zp~Op1=1,%! vPj>— fUW\DJ'k@}`\j1x`ϱ9ߏgHWWtOBcaQB|?1)`0!FrW/PԾ_gsҐ7?MеYai|}Tux~_ I*P v٘v ǘߊ j+JZ6oi8*WX4z/!|#c(IkG ?{Aj~[kRȽ&eˊzצ" YLj:ȇ~O i""'$ W O2aͥ:HLZ5a٦taR"uZ>(j- 1H8V :KlմKm31+dܐY#)AI6I[TVП V-pj)pRHaO0!_t?Q^O~{px?:Jwg->):\uzT[J~Ss}Y=l`9 Zmfݱ}x7+4_z͏XSy_c~|[I=s\.~Ǖ.˭>ͼ_f/k9MGoKw->k;`/lN'-\RrngC>]9~~ i˷6/#G2{I;eި[/ n4:;^_6jw/ ~Mλv*v]]7ibf|륧?W[(Q?6ݮӭ.-wj8]/#Ս1o4?y`[%15>/SdCuu{o.zYˇ1k[|/7nVYI|"ڍ;i}avu]g4˫=tvN9[z{\$_ 3[w6NUosx؇405&i|ݓj:z h=@!!$r>u"1OsT(elT;%ӊ5 ~?”ቄ/ۄ.#ca1;;@w.}L}w&zo3˧&%@GnwP UEs֓CmQz0UR}׾mUΛYKE4HݳR=VG=zw}{t4%*f*hC݃1dm%$6$}rz:(N&T/P@ o/}}:4`&JBH] (ヤA@* wTUUO[5J;u׻R){_nܔEY(mzB S֊" *=8}P5TDW(U**gtq誕H%^PhP}E/lEQRSmm(E !T噋JRJޯ;R)Ӡ 䋰1U‡Jt$'5dy {oe۶oP8jhOv{mi" ;`'pg1o;S@AUJրPZ)u][w!J/d xg#S @F&CF IB&ѦiF FMLɣCi0L5= h@ LBmOA@hM2iCiMhGaOJz=2(JiOTzɥzcTb! LJ~4ilM4y#16'O)O"x7ilzM4zjm@=#dM!CS 􍩦M(&т2#i6Lh#&MOL45Mfy2OM= 1jlbiMSL4hS4y&FFi"D24h&&#A 4Ц?,#=*2,";U֕+A0Yn0Gk z\!Fxs?l-+Fu?.g8fmN/%ލ8r^W@q|(z J7|ˏ!*PYm@(A#LfFbDl& ӕ*PD,sKAxg+Q:/GqfU\RU0>%02\e<]UE3Yf+GPcEeF֢ LxCǤ1b_d:5C.],6"#L$Ya UdSNhjhByP·dxrNng0 AB@"ƾyH ۧGjs~Uyi;3\9PqjVcC/>' n6F$a]ӝtp b0!,IDGZK\T?$c׽9:vg?>ݎRy#u#+})3Z6N.",& :!)iFltpLj?𷲶<m$tnd}0{tjS{6oGa=[x=D1AMdLc;+'sZM׬Tu7'a"-.qKK\Rr /9nM8ֿ[ry:}f!Bh(# z $)x탟? nNTWLXiV?S+Vazמvk7e?ɨiF#!IJP("JxUêe]VcyR;,8 0<3_u5cdXvӓBEUS bD 4)T̺Rh\*vNk-fƙPsv2A˳-\ɲJ-]>D )ce9?MV‚"piKrkqT?6|9EbݎUJKw$V1|TB%~9{|e}q59k/:L7e ˅]!*/i~*QׅT.9G'Ge#%E7W|g$V<7]]3cS6R'>R!̕ ]=.$D&VNKkJLA<\>Z]@N:ȉF`D)T2,(.2xR:) -Anjn& HєAp6 L7Roُ n|NIt)-+9 q 7\#DBs}kDBe߸ $['(KY ‹W=_}Gu$DY|:X4h D*ma-}euZ1B V'Z~lY7hrܒԐ0ל@(Q AH$(ORZ8:͛q;i^ Z[W*Y1+1Ц,6g"-3Id[?c \TUKLhX [o]GBb1η)?d$^M++}}|I9-[af d F`30==&{OL"Ã7oU=* 9p;doKQԯtU2g:cPls%;.~F8Gy !S5Ǎ.x;9>'Q[a&`o_&I~Ɖ1ltϚ~ p3[aK@c-D37 h#}Eƚd?3:?H49K0h `* : *==%q1°>yE EӧeSuN3m-MFQ(ܓd;B"vw)NòL)N7]4rvAc)́D"9=L ^2a& 8,ӻędkMPlVhq 1w jkcdUx_1¾za9Hy>^˚}חЇI/7W;<ܹ+i7BT]A=6L@ !?882nUJQ[CEqWay A]𸴳Fb5' D5U9NHHn!B+}.xzȆ9DX `mC>#ڔ=#w+YkĈƐþwv'%Sg+ދhJ&J#i7';WB݅mkA*@;(KIA؅˼U܇2M;r&[>!N6mr'aq:Y3PFf92.bzMɗ(bhg4m_ "hA}3R)&;WG֘s|KC=8=&.f!7e?~DSnР&Z=( %)Pa eTWտFuhi7xFu[^.}>PrwʓE!wHph1XޝN cD`}~ faw)v3d.er\Y,ml +(ePho_v"w:WL]i5C EbD%XXR 1h6#qҘTXg+8Um%y‘)gN1M[¾ srQ7 [lbtVUI#I}Y0LJɈO/9-s!(?A]6s2RgԳq`<޿Oo&]' F:m ޓb.p-xLcЫ 8;":P+$)ϰa ? (/W7 C̃[Ȅz̉>RpDI=!RDHq1=unLJ7f& q%(G}xS#&P~r;c~{q`͠WeQ!I֝8_.D" =i}cWzz;ʗ0B|:BA2DPm{ @zӍ%$QI ] {3n 74އS"PF6Ǚ 6 I =`ve;p4AB):J{֠ qp#23vX fO\UҸaB>ݬ&nt|ުJa4Gw]D>Z}>_a??PTtyOPrpJ 3 Ձ8t5ki,FG56}sȟ M]hT|*`ɴ*?}N2#Έ$(S $^ϕՉR/\THcG 0_SL}GVek٘+ #mLeP_Y_j:yhM0 $q2 Rx FXJJ,FJ`,#9d'auȾ2'01W}+?LMd,wkLn=8>gfq'0E0{>a9%(Y4/fk0Qx?ͩI2?۟}mrF%.P =bA߿>j3hncV,e.華JG۶ID|BO-D`:C|/̎Z޻?5]?e_3 38(&R! fO XhldGENŞa &90@)TǿNХC2JfVgc?̂~Zz&7I_FhoP@ԈL&AN?Ac&ZT34]*3B..| "ڽNy| yV-F0h2NC"HAi{pQ_ؖ'4f\e, v_c_ekabpkjl£~iIHܞ%aQU2^oԞnj6Tޚ76;[xxQ ZKw`j5?O GG4m [a~ɚP l85_YMQ&. S.g0KB5f 1Ju`,/( Lk n@BXMf"ۖT?ͯߧyv}7l6't@t"aB0(~dt$c2ZC :gbz53LRX5?shoBW&* w bQ-P4na+9xp#y$/Pʤ HWZ]~ h7l7uLfr^N:Z4Mπ^S!>kz{LwTվCG+ק.F] l.?n&rH!)z-dפܐPs^mu4B@ H0+b zqB3ߛy;K"PA2=TNj~<ƤI="xSCd$pgcE9ʵE^8&2_KaC'PQZAE9. qkۚ@;CL)F.:/mD/jwQwRzPTW`%/a(|1%)X偋DL7%I%̄wŊ6=j7s!Hoik36w ֋vFoV׿x1>cc{E;:!z@h (2fM`18"<`W7/\` `>86'lz<|tڃe!'#{ʒQzb<#EAۇ~S`\k1<4L a&YQGb 041K-[,㱂 Paшg+ua4Ψ'۸w%2e:.5G I1Xd1 |gL1jCu=+oWK'c):eKL?rQ@qwUI9``XcR((]}q[f7/+/nD[Q'AvWZܖ"T4r1pUj$O_X :w|Bq7~!/be.FfL"9"LKNtW]U*M6"E"Ϻۢttt6C+ʦ>ݠnkY)7y*}"&.A[c#R:ͿVs >Pz ɡ+]XLGR1A5]K{"] c-]>cԵ:NkE|>({FC~9P]zAD@ĮEhI5'͵78!QQT^֙u+qC'!b0)wAM\r${.(q\6AJ }]Wdpud v8rq%>ihǫ&5g¨{E 0@D.YUA2f*UJrݲ\м2ͅu,H:i6L'Ltmˉ91㋐EJS#stGF9Ɩ;qa90 8rm )!  wpzS"(ڨF#R&:90mwi]9dw"F!m?q$<>GBNyy:Uwub@`L'a]+; 01?*?-!]: %pcSk";m=ڜKBg@Y4),VGO5\˃:iA<NĜ^ҙ%DŽTE!R]X|"гg^0~% Є$)\ +U Z&bzL>y:y^ϛmOpӎu&S_|n76qA`B%>wBJᴁb J '8V6o^_s }%%yqnPf>.UWQ$(N1*FoLG~gK61PpmFfӺU qeƛSM4~ti2 m&t+ 8͡9q<ѱqE 6Zqu-Y0:OtőC B IXg6J"*HEɞ>NWol.YeXAc G+F^M|KFW\\ez R2DaòJ DCG F-' VW{U;7Rr!׹ <>?ys8u'5.:~_jp=?ttQ0wwtnMR>T%G6BèiajPF7ImbF1DI`H T* Wcg/^%HKf̥q]y ;~ֶSz/.6XxQNcphO2JR[E+(ARMe뼕=WN18"IѼ~<)c%I'?A8p#㽽nwɪAfS,+66)rę &VHCZcDL+}>luϸ5kLKSl o LMء^]yZ2(%~:d !K !`} iI4D,ӣM-m#BMM ,$_fke@9%iepOIu8^> zbg"Ґ{fqf|i]$E?k %}έJ%$yP7L5~UOA uu9CρAYrF-L+Sja[vT]q%D/5-Q(MQ&M^"魌qf*5QJsw%Ne⢽l&c".`e?+=bcFbH"̹dfä«bwFG(@agXDhDM(Uf#CWzw@΅ 0O㚦]4?_J!7 %͔?. f&!JF=lhv58365(mbtn PӶyPF,>G6_aEj7 ؓB~;YEU~d~@4ػa`od؆ S rp6bZpF5%n: sw<:-?J!êDbȀ.#9Qe N&԰ bk6V;y2 򈥴Z~)/B,?4$ D:$(Us Q& J5*~.a|ֶ́7S2 NZ.N4@6nbn%BUT %7kXզKajmR D3FAa@͢I DцoR,壵TS9" Y eL8]:0 >)0`8CBw! 1\~FSYb`{e =2nm0s!ݶcPp@)˟= $Ji\y3i;j:ʪQVDq0q%.xtE:vR1󼜜=p"Nr{/6ܜ)QL?q⟺[ Z$F:7{Q_fM"4k< &_jG 8~)SCڻ]{x51'V1~J CoNM#a!T撒1Fq=fx 7ZJKvyĠnP'>c,iv^./gyD= ~ WY@OmkaJzLb@G-+J=uyF=mqh|T- L"F.ˑy;lH[17d#sA\(S){+?pE]`UJkTY= X.?!twbF#GO.A(cY#:kN@v\$~} 2|dM59Q>&e6FI?/^qVΗ$kt0m}y;o @#V uPɕ ^y N17f,xLH^ԄLtXᘴ$9>cCFgk8їCLwK:P-n3'{$4) >u.PrA@E%c68*(f&E8qF`sQW1Kp&e=jjkld5",`PADKF{r%^aW*F߃vcfwH. |!2a'RNtyrFKy`S&m-cm& # [tHG32J.Bx HDF,˳ɷ^]d4wkNPSW v35'Ŝ\'Ew܀rdv;GSbDΊW!cu6Id4Swx]o!_k:mb"41Bxuh dp`AoQqDcU2t5CNDE VADu\_}B .(߫JYcCFU`}tvpg;M6]Q.Mp-܆`Wm9 tn(nkGv(Ś) %sA@b0s`0t]ԫ@BȚ1!H=40ss{*BfFW-br42$Z\{; r34q|r` IJ[B$G 0 + -KYl^'Va"Fc6Ș\]Єh^7+ZC"eEc "/ɹ[fB~(Y~%ռ-y~RОbǯ)xG/|eR뵹.h▽;1 EPQAb,ߋώЬe>u—@He@5)WYC(V۳.dҕ#&$ya{VI.d c6K1ZfՕ2@ D{LD%$1X ANl[=yK#}f6x83X8"_MvK/bjhTɒ~ as|Ӯ4ed^$5KF&`ˣS)#%斎D~ Ǘ4q  uZLPڑEa s@j\L,Ur![U숔x-kI0\ؑ@ds7$[kcyF #h;ʼn]4%NoaI{8%2*D )Ӌ].S>7jv (>Y_j(;M!7V!8(=gLe[OAqTKI&51w`ӜBMȎγȎ O@Q9tXDǃ) +@`ǠwzywZ|6SɞQ$A$j0a/bi-p~ ~/?3)>U`\ʁ:fuy$fcJ,?U+vNBeO _,wYKz9.Y(1q &Ry"ɃDx4,iwnl!pg&a ۂ)!_t(rAB`a@%\_ I.謕 Fl 0i hjrwU`[/U$n.໽6b)PbrZBI17 wbq:rV>?S y1eX`_No ! ,L=K|0Qb[uwZ?$XtcF"cm0Rv ^^!9OߤfXE,҉fމQekR?>(.+Sɔ5Ud(}$)DS%ay)_~kہ!pP?&w+=m Ago0,E6({t7LiŠ`=4ڒ:9aJ(bHJ(tXԌQ'8.f#$N;xŌzCMs{?Qpg46bgeE^+ݿi= te~IʗX2-QFȅhܻTd8$pU9%ҙbnUrq0ۇ4iĢHxOvV/lels-0 ⡵쐞SJ(R(;:~}[W֐妲6$lbo F⾆~|ƛ]x"},xe~5cS"cseP;zL[˪pvqH az"av<Y"fmHW> UN.OfO=!ǃ}ߍf&2;|B7!yŌN 臝`wPb)gӅt:A<| @ @Ӈ-}a?w.ѰΓeO3W￉ETsRJx`288c$T,(azU< LP&uw ssK?6:m35}'BΚ`ICR8&|}ڸ k-g]ot0@ m+ihq~.& i 6eVE%@B;^j9wQǁ+*^+<8,m;#f^TSH,#3fYfF,AKbC!4y}L^$}aA@C ƍiEUCO`=$&`Py Ln4 a0lp匷@M2Zf D757pa^q 138"*@R7.*; +=3K6U$nY$ Vq#l@1x E5rÆQ@\&ŢI,!L s?c9DЄ`&yvPy(11bޱqi ŒB_1T  #ԟNF{d fEI%=aQP~b',d7D/nVlΌǾUcɊQԣyva2]-|?P胩ݚoE,'w8k#dFXåfsv~㫹}8Tb- "lZLh#Hcv Ȅ0Θ@%?yZsVT[fI)HMf"-{ʐz2<.VoI9QA"hy'NQBh0r  BdG@&Ws}6QM9o7WOJ@ "8;-IRwp9 EC23G`!J1"47ԉ"HF@0@( 9,'RZpf|pMo7djpD* Ab۬6aW-VXW9f 2ԽLvȰHu,eNg<+}LAd ɪL"dD_&4C÷+3|Zh5 (Wh@E@MGk&&j /lmAw긁QPqV>F]BLmi"0rL +w(Q!<]NXmJV*t onI`$9"1h{c ׫ZT4LX!%ܲp@$ rpٌgz l>_P.oldjdz;1d( z D&8OsJDs0'z'yaɈce (~ѧ~i0E,DD}ѩE>'Oy' %@-`1;uق"r`%6,tYJ);VaIC lCK0(hBPuq${}bY2Lq tڇS udp!#QnRvsw8Tvu03^bܸTEbTݮ$`ŭ8w MOjH/qH)48Ĥ{:M@g!Oj"2q@@/  żR!Yc)WYBn녋kfznF{YeCZ_+b0 \['q^54.iK㒍0y‘3u('O`'G#$8>J礩YmSvML%+ɫgtImw؝h!&Ϣ&Y9",OEDy)7 06!+d|CTf97_;(]]xD|Kp%JԀ4L J)]w+' TXl߮q),LCvyZma4#œ7[& >KЕ:7@q;B OAYinhgm#ԁa k=#k,(nDJ*є8.eڙ=0\8Z2fڿs|fiC Hc@kYxӔ߷Yl̆d@jtP-_-bĨ1Y< ~%fCxD$K$9-Z윌8&&n` NwS S,{p.nF{bk{Pm*RH;2X}r+AH $C=$nюwɰ'&Q3ċf7:z<`ɬb E (sr2erwF@jO)DNzdnm7T{^A6!&V ~ .m!f:Zf5Ry=cuY}4oZDV2bA "9!ZHDzL7 3c;r+S#&^0ZFmQcD~'<_K;']vۿf֌λ(dl+tj.xSL:ιR aGRNw#_9Fص߶7EB^)9 *x(=8rP/`.k$stzwKDUPho9tYץ#7>+YZ-4-aeU$XTc,ELcJɐKc?Ȣ-s@B GZhz&*F'f $Η\ӔcdfȒ/tM[}Vh` xS ?2C 5b$D{ Zd!D)Π(ΘH劗sg aX,(МwŘdQh(kwi??PYEkMe2#v6Ijr/*o#q iphatOOc인{4yR (uy84g؄0db %N9;8DqXDN`f~"<'|0{b:Cq"iw~Ⱥ^O~fQDql;^f2n. ZAJ-J8{lǏ]qqwy~5{X[!K (J,E#e̼~$z_y" PBB-%a00÷";H2AA&vSv$*{ n`nӆ˩6d,QE&%Y 1#c0qލ+-یSaT D~=qr=߸?h$,ABЍ<"PM12мf/ْn~I㘂s[>4t- @#%Bu91DZ̯!~dP2B ) ez3y.{լ?Up1}Y&}j >7{vN c'%";dA}f\\汯R%%SL""!)X(D"X1*izf$rH`юӍӑ#tyҶq+%:~%f"N f ]-뉽^qh%3X̔?6|rcvF2ZR-.7"~%X-)8%Z辿7~uB)IH(NO[Sނ1K+f}|OʌwEcW!2fy :ƙW#^H$Eu@"ɔ@V:m;Z3_务?ƾy֓CRd@X7i׈Nn+*MnUHÅx9tck.鬾jsCrPǗ098偶h,H3kTO2o>w?𿹡Qh&:*KA?wijJn| no+=#D&~AɶJ+גXИ7.p/^+!?F&N S@"Igo4JB RcTsg!ͬp ;R'CѨI_?_hO9$2scu=?\Uk ҐSβ:޻P M~_oBp>O\c/RC|kiS8 d󎚞~S{,KӘvvoS[9$@Guj|ya‰{d%81-)7P > Ujrnښ9W╻c n6ڈט '\Nb%a+Tp|4|ev\w?,\ayٯa G>]=8@Acգi'ƻL5KljNft l RZPDN9Z4d#*4Lefz/ re 6FfxHC1~njzTU(Ps~ŒawFqS`,bw~_Yx1qm- sJ@v~^X&cQcZa͐@ް~~t~~RN0g?G*J>7mPxd>c u37?:ړ"Koɞ>*?iڵFCJ# ?K@bjo>c'x__9EAeA WRTRу"#m lZՍk#1r3/Ec6Wv:H^'gy_n |#oEP0=3WOYuD6PnM7̦jp] e<d'9ξr<)|G9ƕ y+&t@[bGA/V Q}χ`A$BgK$h' p#tScɿR$"wǂUaE>3=}{%/Z Q)ۑ(G+a5zv㶸IͻrmE|>qƔwgh : Q&h(/WE-\!8Nd3}79}i)ySC}wTIAp|)>J2ۘ_)yiY+#^ъRVK"ٛ6dfN \< Ugz]x]qlp0 W"5az*D~m)Dh".|KkXA0sF"FNh]}okmxf2A&("|-0Rp8O %vd q+ny%u Sd1/"F4 0Fg @Rf5шGrh9ZLVnCI~\02@`" ؽ $PBlJͲ~>?ʂAkOHnS6j ަ&~f/kl:s|78̣ʀʉB; +ĥqdbJ7pNHtjL8Lc%ymCX1+Ev0hS'ŒIrvM|Q~\>b"Œ%رPQpߺ]$ L2qX3b!RL`QyT"|Ztg{*ONJƐD"r2]\b$U0ħƆS"KA:>?rhojwFqÌX_k5HʼnA FtJT<ʓS*3[#Q5?>4,HY8 u GxѩL1dP ȠԾ@9"=fT}:u>d߯<:uxy*wVͫ"lݽԅKž^c#F̎&h 9=}?!]?Z l~~8cWxuPqP^P*I! {OT}xL#2 g!(P}I=s̅^Μxe넶S0^/JoNgrk<ώo&^ޙ?[K^X€dDU*)\LeFƷ)D]x$rD0g[;p($JX뙭gUǨsdUP-ۋyN)[3CSGJ>F&* 5-[sS&bmZ F;=3#'%LI:xǗt06>!Ͻ)k!`~ߣ:"Z1+G@sRX =mdusr*V4=_ŋ?Ny^`H%Y)rqN;˩ ~=CGwww_w/EʮaA, v `O?S'FBW~;(0|2G2FԴ0HP% "#HoSS! ̔ߎ:ZQejOl#aV9!?8~ F: 9,DI )!cܣg> .H$VɅ ۴%dޖ謩3WӅ]z{Xq0D$0C$"ٖj-p?H08 %9EA>i"5pZ eD# ѨR/-TLirf*F*x|E:.+[ :! -SD54Z, B Cp[h-QEɡ+1@$ B'Kp 5B靤$C{E-b1CYeyγwso7]UGsyXljZph{JBLdy+AG GBHJiAH2»I%FwNv,h !!w[2|H#Hl " oV1t 'IVh ] -#brw6G+MʯZ~ sC3\ц-k5X LG#o.5P58!e)Q'*0vfm3gѣ}eP! ~OqAΏ<~%~5#V几'G{VeKܜت܎'榷e$7uoQAomN.MBmpHr+Zų!dYFÑgus_5yɘKWc~jw鯾R*WH=Q溿cbwmgjIhí{Ix_^nB` D8 #3*7R| ;I ԁ,$Y FbK#'TŒq+f}茡5&y>NxxkbɥU G{r$њeBu1tϺ,FW#1c";13n% x6 H ,(V-`(qZ=4KWͣtH2dYdĤ, lhʏuboX%$ĽQՒ##@rsw0,*~SX"hblք6!6d$#qGåЅϋdnydVf%9*T"bQ"X?/'w.h&pïswU R' *c-3$ϲ.Tݧ253Gp zeԖS[Q}4,jF\}/,\v%wgt/-%oGE_p Oɤy:V> $Ab1Acq cnr*Iz4@H6zDcgiPgvj!G7$%"j^Df(΍s7.1w1"/s$z͙d%W*~j}V(| Ѳ<$LC4;?z&Ÿ-P^DG@%Q_D(>5Xp7$׈"ԌLUmI4}B~t4Paj(GSA6eUEYQOj`EͿ3SmpH B Xxo\oxF!)T(W' $(+o iZWc$$N)NyriQl  <n-~PZ~JmlT#&sFtڻ-n{YrgٰJE`g.aڍB{/w1GTaD L0HL%Pl~!c`S7Gb3 M>eN* uj L("x*(!m1T=i`T-"ӕ0ڡE6MΔΚZlOSX1\h6ڞO\=> mlĆEB>yr"0Z:0L"`z>G\eY}]t088*H"Zc`/-hQ )NC3Q`1XḦdŤ)0 (IĉH 颛hV~HC4l %O qL:rNpc[g4U_*bMBaʵa"`֫v9Σayu<##dܞ剳ũgF|BSflfr;=>ţo#5U0{-NH˻bT8"٩Ͷa$|x4j<9R@Pg,(r.-{O D|T!9}5`qTFR>GgdW3BfE;Auۮ)_6)G%ZtuSh Jg7H}Ϸ\Z3s&?C|Vp赣X#v}vI\`}? U;li|[ (?6F%6A? cicz<N (%Yt3~ 8nҺ0қYM:ϑ:,&kG<ȶcFO` 'ՕT"QO_~t䲎% Fh6 *+}V=[m=vYP"'l회j BYԯ~HC.5za$hPY $ο tʀӑ+'2m}asOh.gl9='ulɄD&-JSUroVMqrC-2!TIQD@TxIPKuL3RᘤR#'3*.*5eZ~dDB(F7AϡEI;*,[`@Fl R)1PQ =NgZ5a_o͔r{{ZxaDM9(,0l=T O3?Hy112ܪ~5ljD&pfXI!E{>m؜ߣ"1IJDiY$' G_)NLIWU,y5aL] [ 8 i `-Po\~_ARDp,qg6#tJ@,tMr" ÈFƎ QG$)E>>fr(E~ qA!fc.>W؊D{Id(ͶV7g/ \P!pqI$ĉvȔO)!c$gKSƦ6K\fy_5,X܋[*i$ K:l]y-r5rA@"_0qz'â{I3v*nlCF9*P^'SK]7l|u>%+?zvv^t8^f?~ڢ /j͘!^gǿqXq1wzi4xl<큊^7NtM4HY +$*2IC)$B a$@),"#Ԥ/%ШB?/BX/n_3K,Ӵм&,, kA6=D)ΗX`pa2m.>;Yh^Oik\17H!%@~~;M wTe FqHl=tWGPc5%H7E31BǂX `>(7_\VeUf)Y bIM 1"_bIlvL ,-ٌ6=_¬m ߺ!v 6֖Jm3hйi#3<|OiK8"^gZt\"[qW&5gd.Co6IHZ}'5alyWcCwc< n \UFm1aV:Yv:פ(8:4ppԉN(AN˚P@{{+aXB/nXS4N9"H$ ?]SɃbFoz i)L5BR03C͖7!&@@~:TL[0Bw_Aihrh[v+ hˤzucMURoB[]Kq9`IMӤ- U80A", xBYL\.&LfnQI@TAF;sDZ&#Ab$|bl[ں #;JL,́6t2!u( Ёe$\\8\ ߈]3\(Tz0= YyƁ(0Җ3s["qF/":k[MƘ'+:Y ,:Qf#(A骣U;`LuNT PZgH"d˹`sqᮚ;Y%Q")|/6Mջ{M 0 'SAlxi\Y 3|i^|c A1^: Oڌ čC*A$D,ocbXtk0S1eX6eǁ$mh)UƲy˵Jl7݊(kCH"vӹ̯u( tЭ< S/<#`Oë!RcoCv{qcM!>pH&5D i+{6N=>N >ϝ#雠F&1n"\oɴ/;}ŬXֵFB/˧R!DP a _‚+G2#fJV6٦&[}#܄m6jB>4x1x&bOl*wGhl>ۺ;%8u_4ǯho}=?l @<_4QdxxtZVjq ێ#-Ɇe!`Ʃ$@4^z8k~i=%z#$uA/π`όI$&h Dr%b ra5`Q-3}.Yy lQ Zp'N^ [V?xʑ&`@csoOs[d#T+`=<6bRF pJ6:E*rݜA0)l jZ_8̭ +˲7um{Qa'{z+x۵ %dE̫gU]ogǝپ!4@s9d =#F|p4Ai 46`~چ=C;Sd&ehB H@7:u@đcJمTD !p\F eXL%i=ӣK _B ,Ĕ#ҙcI ʏ;EIgI, %C"NA稈SAꑙ7%c"/7HK"D H_ؽQ7# ZpAtdY %]Pin)NnNE10j5޷QĽgy z\}MXRh%Y}o~x;pJ8e8J e0́ 0 okW C8JzfdWHC_"lm5vâ~'Um:d 3t !6"Xc8)% 'S"&Er&?^Qg>NMym6|كnuM[QT;=̑Y“b Xnþ`B4(\t<*1krm̲"[c"_:&!loJf.YC #|FeG/^,_n|'7$uYRv$:lTiۭа 6wl. T3 h (.e; 1Ͱ]pX;-J"̾w‹8s% S4,DvSbSd-UbFF51i#5 "Ӻ9>6BHYܫ\DD^dȨDaĒyJ!ƉB `T.Ĭ:99ӎ*D*"pчS{cO78u!P)e-6V-X @@ C[5вhwLc{fV4ćciq@`lHB5mxDrOI OMѥBzs;.$X_5^Rj(-cdӽJ<]q@cuJ[&G=F/2wAQ#A \Eã^v}RTEe$ju9 aB)ATpD{RB+~Iq >TDd",*1F,5B(1 (őb" eAQH# *1V,hQUEU+ YHl*,b*R,-A6S6їF|(+4j-ZR!aQ#lS s6&جHj 5 Re`LmT!PN+K'd"RCI<]ro @oh/ńɊNJD|ԍk$o0\w@n] þzaQ9OE1_"&d ,Tb(#OScCK̋H-nhT #C}]x1̈́z+Tzw$BH  ^Csۼ2dx⋮׼IKjG>fGV7#k-ު$Z9š̼}aB![zʭ {Heݥx_4#{T)I! )64$txz^+e4[Co[ClyʛKCꊉ0 )%RB'cl#'fĦE+Ω@A*,72:Hh'3h'-ԯR{FhC{*sݐ(DJ~_~;ɧ;?ݻ?VXu I$dCDJG3|2rҠNuaH<㴨`]PVWv Iud1vB'",x!xLOg& }x  ĔD%d1 Lc d 2?S$Z0y#T u0ؿh1*N+Օ/F1G( gZar0ِCX9Pl(Lf LFW\KÜG.l `4*F1U=`xzfﳙAbJ[2̋ M I eW)#x^RAM]g~FÖvŧS{T"[SJƪ -}0.p% 0ffeiN:9"}Z y ܕ2RWuDݢؔKHP91:x#gA$mdy<LCjt-IHuth@]7Lю|/'v _.JJtE**E .z8=g.sL}bC\4]ݾ\JU `<Ŭ$8Q u;+Ձj"$>9-d⽝w K6 Њ9ܠSS]9f~ȍL2O rj٧i<*lŁ7`콈_,5DfC$L'^] vNױKrwXxf'LQ]@ZL;>:&y[ZI"φ50ۂQ2jA>WH78fL`v?71HI& +hAzrQz^MSC4gYi޴dbvUv 'Mkyd(JLb8c;>> Uˠu>ԣvH3\S% >H>Idkpu19FZU*,A͐bgǪkU^ ٗ,L[";DžF7rg!;čH2}ҡ+l"]DV)E|s89gp9 L; 1j7`L`L\r 32/+d, ul#K0S)x$1r3 Z2@0HQH {lȗ%V"IG#DM.LRΐF"ZAaB$rꣾIK=>c=S1vG }=c](6 Đ }V=-8b؅.EwPφYv>&P3ˉ`!awS,<7i)ww0q$<pI)PޕtKħ-]0x%8K"> T2kĹ4|ךdC :Dez@b bH]H*Bw"L.- bO=av&qle31p.o7licc9v˄QA[kos k }wf0!/6AX6Td;]vH6sN! ˿P@$];nL5PX~9cZXMr-A{~PvXByc^x(%yyQ`%~r| X$ofkI3 +fYBDi9 ky:vF02 HE4{Pl/w'R?Y?@F9hz%/\B?ݤߝ0XzJw?N*V>/qDa' &LD<q1Wn$_I;W(ы X(ҳdhvi9hMG@+G;ԕ0!i 40>KjIP#F )zB7k#b@\UWp#^u6!Jd-)Q430l4uM\=¬Ym4!fl=T1, -}U,7|O)xZy"D3a3T"0@"zUɩmި,L_+_R(x/#Osqǧ^`qF(ɀ$,o. 5zź_SCT EA nS}m[|1Dz9Emuk`n%X5*H:W( knnCo4SѬxdۻ84"`2Y6T$;/%xůc q@2`H<璪!P48/Jk&N1R +|)J4A2R*d@J4EFKutklUpTTҘN![ ;KD񎂯I}(J0AOήnk=`}z|SkuׄW`׶.B!L ^8px0&>RwXjpdt_V͢ⲃU+HD7GڱS-uw^%g@q3) zxl\ǒpED^!=_X?{#_@F!?| q4Icg 1¼<>b =^_ xMY(xXN{Y\D@ B;rJ lGY E9QuʃODB%0c7f M"0Q]&Q# H{9PG,F8a!!/JuHT@:'gCe+mKPʬqEY.ݐ"S  uE,-#tX1ٹwꔶM̂SWAMnŤ81[|8st cVhCdn+y'Gґ>MwI`8]ė`_|(ۈ(eo$yq vLB~#ȝ1ul 0X?T BnaC.2Nd)ZBggP!H T_҄P6 ah&L)B $ˆYIeD AxfP34s+ + řfVXKfʥK,qbdZ!RJir@*.LXj2!en6=;>*a.:;hp]"V!_"`K!: ɸ1Dt &:gL]wN='cM?'k{i 谣Cf>GpsGTE5QFFf:3O^W;fY]!mj@׬E- vDCZsߣR&-YϵLLm%%.'~AgeM}mR/5~Ѷ+$X-[ NX2rXwOaIj(hpDՋ+d5TDf9nBˀHPo2wn5o1\۸ IMe$|~5!mQо% 0ΖR",Fa@+Eɭ3ef4޷;nXeǦfW}t\X+|6܁޺BBQo-H Eb]$Yrر69}Qt&d2 DM50փbO̙xS7l›[t58e8Y#?b)BAUֱ"9ƐZ Ƞ$;P9 HE{d/(a_/z_TgebӢ:_7!n4 UWgǛQ.mzƛdKDqNZc=.d#֘{"%$#D Ԇ(zVr&Et{JJ-eBvs K$ы{qE#l!$1=emc[1^(o~ Xg^~V^(t)(v,(M2 ï5ϊ蝇tl;:+ H\ q;x*Eq.r8xnU{W:6=W :nSj8'^05Є4{Ru1ֈGAHT<[EaDd9a7o:PF8 /=R$+X3ؑ$R#?8 :>ݰ}]):j.|cm&|+ڹbL0 2BDHH$ p͇rh:۪^5۱<}}<'k{^ŚqJRxu=IwkkwXO2L`7wSӵ"Nn[vHvGP{w1ܯX ǏZtQ~Fxqepe#ˆϊnN荘K&:lNR `b Et–`("2=G[IVč 8=C(/PpVq1e ;*&*L7iKzXjw'瓴f t)./7 hg[5=@j~ a&N7 "Pݜ`7y$#7ٚBYPpCtsa/;ў-`ne :I0 L0eD! aoG떌OjcPhm^n9q3PqЯVӀ3>"v׳o5+>8Rz#tECۘјWA)Kå[]k֓u ϊL˄\=XSD?_':AYGy+ò^uOA|L^$H_R/GE 6$&+kw6 m17HvEU2Ɖz܎6UQEH܆0H%b:O3#EdI UYAej$8©z-e9(_!`mQ fxnsy, ʑ/-\ݻ- s\m(\l>G=Dܢ$Os*px)S> 2G9I/)VGY"j78s6luvQ,StMja$zbgn)[-JY] Z=jk!~ڥ2Ò")Bcp  '7G0#Y^3sJOS~P Sa[v.z90'#.4PBhY B]({"omi6ṯoi|K٪O|ЄKCҋ[UGfшB0#zQ#lT\ͧtyrC W*?_*1؜ H"M1B.=Y!X!V.Sbqm%xV3cQM=Vqߧy޴-Pj7ԧ^Zg]0a9z^ٺ;e <; v>,G/ pjd0񙈈(/KM)3 0~lхc\ hMR׊:`ͪPDS|OUz> v혟zg)Zsg4; "ҊDuQsN!Bc%;It~{!i)VNfwsɁtt,:O@G.&}yzEY,8h`^JeJ'YE0F(|r {ZϢI-lѓ!ܞREe9%~(g6m #zܱ@[ Ri!Ç@~`aK%]TH1t=qaʲeoN)B[|A629I4˂ kH!-B/Ӻ]Ls{2wӷުEN-6,S˯M:Q86}~gͲ*iNR?)lD20X+8r^k/2-:./Ƈ~u"'2mlz#l}) =kLaan1m7Bv ]B2#G^ڽ"8f.,B:9]-j4-̸JQC]w\l4H)+ LЌCz뤨]T!AC0tv9n QEj-Ll>~i6n۬J cnU (PrzK/G(G(rɆ9-R B͏3PXf>BVKHcqwIVT*isGgRNli\% /5#=&"5% d/^ا2۝dU8jS:;(Y L2AP rK.n$2f§|a>M:`g\6ޙGEZ Y Y8b <7XɋfL'y\藺Z]" >մDld¦GQr\o+н۝t#aC6\o ,D#7 ""8@d#v)UL*< ̮ST ?ye[o|z2ꈿ+y=#xX$}kݷ]<_v\gr{1̏W97'4p)!s7C! eXM-u}o;z)S)4SFhUs%3Xn(x fOUaU,T>E}9/öab]m_/ߑ}Nz廇iOyT;L # 7e=m4ei03ܪ 6Z[ $$ ٯ)#-76c!tlwLvT0,ϸ$$Y! S%kHȄa߿`R`Š 3?mYg@! !rB2 d呻e_Ƽ#&~z2JL=D_~Y^)"㩒9%r$U@v]jʷ)\>Z:,1b7c~ ]@bTauדh&AYKi}2\Que9"(gh #q!D0~";c'}X@yo>)ߢQpWd<+Z6Fņã{|XZͪu͔DOG|prh_pCᣆ"%!^1x?G)FG9[#uIMO$@o|9ф`~ĞIzyuLD|;SNP<:oHf\(K0ֽ&0Y|ʉѺΥJSU1~3'fI#Y`LDu0( }y+g_V ׌Xi$Z $ߋB.MX˦R7qP}Dk& FeL 6 &Bji.vUw{mN7  $@$de m0(Z[$EG 7א}dEDdT/]Uz{10ꪺsPwND@&H2H{0 n{KwZ1<]x䐹e@e^D>LIGkZ: ##jqT[4)7yB Aif/Lג흠XE8`(/g rDK~!B xDĚAXḭ.< bdyyiZeOILSx2.}P.)v;'KqU2:H%ivK bk' se4pgr'۽'_䢎v=ǯWW%uDBz0"UD ڍX <9) ;_[luFQT,b`ɈU6lD `Gn8[֒~ART\^e/Ys I+E!>u lzI]v_fǝ8]s;8L3[+ۚp}dlabN#D2uEݖ\bv[„@ý;Nq L ~OM0j\g4Mk͔Ph3tNPh]n95q,`" >92n:4L0 RӕFE8z*l)Ř .Xs"ۏLdE _i\E`AL"K]>rW8Qʼ OE 7BNDsSb"IҔDFWL= Ay&YDc%x$) q;)dkKkq^)C M4 2s;JHo;:_φ_/,4م[ @Ý١V(o eйWwcg^|c HL6Z۲~<{ \89{~Ϗ}p-f-<N2;n7l'ي?XI0UuCʬΒgH2mmRǻӦby) !~x0@볡o<*#=47OLt@[)A|wdrH cknXμvoe=׺x7hjq.Ћs:ZS`3Wix;u%D$Du)&H#<-.>k/.:3>pz ԟ5PZ8M \z;s _pMaOظ)N+&InXD!<|]xJ`E7W{s4M`Nk(d`L6K.`&zYa+㴚s`cLD`Ҧgj(@!B 46o]tp:@& 0n 1!-[1%78eK0cHJa5=3t@ÛiFV¥dXq߻r]wH(oN r J͕h(Vqʾu]qLt|]{7{2f7Ƴ( tV,"-~7vt[kOsTVC{Ez"Hne^o38F]o}Nf w㶻 ՛1ݑKwZa)"dn]s\]-BG9bҰ/$jR,G_b c4^C4YZQ,QKz(q**~?L;?`riEAaqX17)nl`> B*B Ao^u`aI+tdS!hb^ʡ"EY.T& n#@ku6'7V,boqo/PشDgFDʺD|>tzsixT k =A1ܪvK|Gte rG6шIGXrUaV6)({ϓiI~{J͉eJgVNH޴d->dD1H\ؑ۩P0|-iظ륧bd h3$q]ٮ.i4Hvژa+ ,*@6`6$ L) f$A-"xGjAb*Ƭhu+%*j ze -2ͣݢg<Bm2iomO޷Ӂ{H=\'][U䬤a:&HJ('%/wQgN;=ѢcJ,B@)pDqH YW @iEH=hn*K ,$kd9`o0hT&!>5 TryώXh>YGᗤ^"{/ #kzy#79:gB6֏QaJКFE:sX~W1/5h L".Q8t!5֮ ZN Do Yj}TCVRs ܣ˃-f9_4hMU3jiziz~\ cYX> B_5.cK~Ozm.O+MBc9Jʟ-(=ѵ*NČRRg@hrv(f([H׿I` H4d]aV}sCS. UyH!& P5r$ƌG4үg,~InDnT[eGWѡۿ2s(;r;|APzB],@Ea\b2d>t=mW+ ۥ8eTn~}p])ך e/.sҠRiڶڝNEm=n4t%kA'ObRWgv͊e}F<kSCM%E(s<7n:e0( {sj&=!^iJLO|¢®"΢aE }] v,m(X7w!xCͦysJ@KEXaRV *! e`h{}cD˜CcpzxgtZ>vwXK |F!"$?T:e9aD+Ȏu0e0iJ0 #&>!NL0CV_o5tf1j :Ԍ%^UP'B*;9LaKd$QTIJꏾ `Nm#Y;AȦ yL3MyN}IAdž2\N6[=$EGUU>Q{g}+} Cg;px(kTQk9֎?.3nҵr^z$s]*׎veۚ Ғe/PZ}LA:խ9V_Zt"¬E&܌e^~1B{{].!(%e6ō M=gm[\LM)evl)qK2 yȉD8J0`fDT ,G f@N3q$V?//H$pV~~YƋӐg*by^y"a4ul޼Dv!Ӄv[@\:4''j]Vѭփ7FMB@4HFB9aC4 Y/jޏVWZ\ENe䉆C:2l fr:7eIm;dWE`F&ErNKAT䐈e DfvE,1ڌ &#/Y_ÔpSs1c+[N0ccTzߒجQRX80xBanX{n C&@[f2 LTq2&nY) ]Ю&lb"H:ˁꚶNSp8J&?D0~_QTYsM7d,L[](n-狧e4]>f1ig^)'SI*AȋK³o{ |l",a J@ČY uש> `3%`XI~Oפǔ!95'6@F4-w^dQ*a㪓t]bc ]L@cYӏ6aV%RG~<M$¯iFxƓA4BI}o ĺ HMQ Pf:UAeЛDϢymh%,8deF'R#sFLᏛ6KTo[|Q{^c*-71<<$Ѻ7;.ͳV1%K1 q*ccͺ+ (j-j+XDBQ=z2n+Nzp\99暴ΐI vۺ;8Ks%f$? _T3_uz 2 W:1A([ŏ$nḌ$W@@EB@W[]4Q!m3H>U՜iϏⲢ] JA PMQB4[-K8E/2H8 &c>8nY`/r A k>DA"_ C:-S[0]?^81M>Ԏ8%biҍӲ&??*>eDLQػ2aS_[#Y$mi|:Jr@ qE[j"eCRP se,X+)jUN!6" Wv"v9x75P؀B($!"Z\Uk /L\F`YDm zAo[6Ěj{ 5|}1v[vl=%,Ȉ ~O}a| +o}uq"lqo{fXmwKl !56Z9K6|'( IEW܂;;,ɲ#tQ?5q*qGXHJtO+9|-2D3%SK4KOwt.{Ӧ,G>ZHΈA  *-fy,_tn86 xNY଩(P;tB1Ć7_t2o!BTf!Wg6RqN? -F 87}Y۾O^*T2'ݮIL^2e@-)|f`{xvjl훗!$zxpHaȊyVa]ݲ:Qƪ I2mK|/[a4l_ca8E(Ƌz֏@ DfQ"ȑRAȫ`fg v,Ӵ !6CGJIH&NeP n_NXշS&N6 X+:(ǚc4G\Z9uu{C\#0p e="HD !^g3T5;0R˶0ΐ`Qlc1i$A,̛UiClZ1n E aHE֥c2 g%l25ZyH1Q0>Nk~8*F8#wtD'1RdB2Fqrȸ{ʁ8P!>x"}x&@Zl}b#aH]R`dC` `8: b 3yl@0H_ě9~ ՄگkZ [cMI"Ƿ9Kibb`QEyGIەdklSs9b%V]^]LJg4*A2e_uN˵5].5֓2jLs5Q?Zv":o'Nt->a*ҭPYGa@ v]NNQ Q&f3]n5Et  gy@v񇒶\05QW`<֖&g5WVHNH wjyx#yh) *El")P((/ imj/Ɇ1f&&"T4!pKź]8 'C0P$̞L nUV (r }g(hl^SoӰ:s:oQ$I%(<^.|5_[{7 7P9SdHaMSaܐ҂ix>]X@iLuW48q3 [#m~k ߪe0:u}ͣ)&PJlAE+?YhP71LY7#r=I\ bkmu:Q%\3{wJ C-9 nX*gZ'|&q7M@QHP*P!:o'q3RMcP/{\?tPqy?|ں7=R!KcV}i8#+XbFPAȉ9+QB/bsfQpI˭XGߺwŸ7pƼ+ͷSGro~w 0X7j1(/}xqhRY!*VVjo1%h1dֱ-T.-T`W$P~q?}@zuz[2@Ί*e$䚎ڴj]zэamdf36(wote xwILwXmt08f2FVAohWF%aO:oA~1^O^(gLMᯂ,۷m6e} ;5z,qy*1<eya#,ȉ SEc*x?C>cmK7AN|?=yUah?y-]C<  đLG"z4{J *Q$5TI""gyQ0يZx"#ЀaRsC|kfe~^^-餧L"!\\ v w4dXj ^ɢ)DԆ6ϚT;%`2_NXlJ?=*ʅBn[N/;L!UZˮ 'Amy~5[%i>eT 1X\=v`oV2ɾݱ# LAb%.B&vhKoڗ̔֓͐pq^Ak{oC+I6! st!9lO$lj$?ӦcOՓ+iW&vVGU3ԐV(2n- ePFQ.jg7NiGf졣:D&0G_xїIKW+42ڴh^` "~θnW~ŔE>eղkY˪]ih7,inY>ԎҔY3T/S/;XOY@DQ  F ֦d&לܫ8&N[l&@L :.͋w JZ,`q^Ji,| ݳZv"ϊGM8J}.Yh qQ(Ɍ^|,몳ӥ3r% .n^r+M1i̭J"%d 4Ubܨ|ÑfU^cCdף,7Eoj$7[\ 'HU7 JV̛rU?5K5kѱmt"K  nk%TfaC`t4uaiejB@K!gD ?Sm (FRvXJs^(qá=#drB ыfQ{*,<~te8D} :@C@z؂q 9DQ~g]}c7Gb念Bէy!-ARSx WG0ZTv|oOIlߎ'ÝsZZ@ϻ|vc/4W=)4R4`X5HpƐOZvdđsz"IBYL:4÷Z%dR*E1?g6NiP Vr@zTCdVP3Ò.Wz>aiTr6ňdZ5O,/kL.9E8o$/-ˋh^1sFuB4DFr=li:NMӉ?Fp9Te*}+z8n|TYAQ ,)j>iXFfL@&}aXݺ@Ao_X3 9JƂ, b%5NC Mˑhخ0Ud3׍8)qjRU]b#ɊJobm"kyd^k usk־e9F-*xqUՊXg #I3$X$EdYh&E[V'%-o|Dl%zKB/o=;9ڬdpD&ypFf&WZn6 miMU[ ǠT±/=^-f8甹"ChV@;@qLa@E}Ma{ݕ0E>TԤzFg(ld$iYb^iU3rI,"(IIaΊJz=F+,dhJ Zˇ Xlձk& Uޜ"@X-|]b DY>z<(e9C'Zk*B4Crr) Ɉ@]C&2k)Պ+FDfтAt.p$@7>;Xr4E{^m >쫴FF=!O+>ԞsRL +0U Jd1YLIX"ra&Bİ!' =ϯ)w'\ecД $FFZƢ + UG-'TfMhɾ; SNG׌URۍ֏zE10UtX}13"O[\'dKn6uGr)b yG\dKZE| Zxf ]dɰSk[nB5JHm,ܒ;}qqQYU$x/PzLPPG6"&U`!:#b;-v/.•9en!5k)$Q6}5P*7lmOMzW臗JmE_?6E!JAʓo7JƝUъp_s?+3ѳ8ؚtr (\IgvEf# bxG$8療3rƭ|,}e (*,|Rڬ'2OۂZh5rĢp %Zxf|~b?Y !fYq,x4qȉyIqZҜ+ASdZ_~p{߶2^y'q† VRNL#t8^j'@qUY?_LmIE0I 8ag`*raBp5R\@`ɹ)*^,4>~ThRқ0֊6\1s 2]HSBl?ĸb?5{~T"m t}49JEOG#ZujwVtuN^Rs@Tp@fA"^x 1#ruD`jy z4W\0:etE$D;YPp*i/#Y$AZb̿TeQW=Eہ%5؁')PЊ2CosSBKD{%QP݈&?Rnyp@$D!OE'(@t?1Ĺc9*@BЃǤQhz]vu6#Q\Ƚ#ɸDBFe{{٪:k_"1-kH4ؖ@$&2VEfB4I`I@'Ϥ4AB !>!&Cߘtd,<HC{P$B*Cj,tCI7$RjeaI߰<I$6CԲIs$ [H;i/19Y?ao@:hnaT)$+0D 0 ,L! F@$&I+!'MפL C@=,OR@ C 2@z$AKB(hQ^7htrȷ],t=zDҴmt:{vnPh2_}f mInMRa&?;u81MRb}1.1 sWH.l@o,G82P mMT~ш$] *ÇiO߇lџKXnfW%¢Q-O3r#IDa![DS S9JsCss5*ht??[b ;m& %܉A,!"@tQuԜ7VY} A>F:e]Q^G(V\7Z Oy?_"`n{n$^pMJ4E*+{սFζꆍՀ J"R*~K[YOpBVY Hg#иQ?˃x>^Lpg{MBl,S7lZזgb$i G8 $V,x8YK8xr'??yk(P\nml:{y&G-9LLq.tؗn%Ă\\uirfHcX4>;+KF]lze$0+%"IJqܿ5\ ڔtZvUep `0[_*?!"c9cgs{~ (1ޗULǿ7%i=8HBα#0`ى%Du2իV|߳c0ܽ&@vDAd8~μ:~afa (\v!Ih@tjJ̨و[MOU(_c|$D[PL@'ݞuZ|nG -j2]{Z.@tñj\74?#|h20nbk]N%Fގ|l'rx?qDhhcbVkl 7+xLBÿ3Dh,w'⪠Bش$.]-T:c-m$}e$ 7IKc.d0vE<ٿ͆Bm+BIx $!! ,"W I$_FAle|/C峵xAiv 0Z^fDžwD5K4I ?Nt~>4jp"hBA1kg7vHj K]` $/No/v}+^c߽73V8RHB%q?XhZ_BAu8M.OSձ 6g;7mĄ|)x s5Hh.5>4I߰%?m?RiF_T`sX{[9z %Ȱi_Ks'|hIiGhCs;eYLHw*I_C~䲶y, BHDGp?X {llq񧱧x:XY#@~ t ]/.y\;VՈI$~,|fU@-H?!{Ǜ:cHc@;ŗ`ÂQAE=W%zjDRyci Lr7>Z]H$/o)wKȽ\ h@6 ,'MO@$- :te;< ?Q٨$<+@ ^biB4 {7ؚ@/%M$zbw4 F /(B]NT4"=$6!1x׉lwh!L69ٖ&>rVX8`X,%v3Izc{P1$MOArt`{?3@۵'&" \/8tDAZ,բB VlڿQ; %hFQwU% ;ɼc${zj4nH O&# > 3+/kE~8~$Xi #e_4iڠB v xl3_Wcj @0 W=zҁ//[j@1Mevo#)4 ?OAÄ"(Sky/k_+~+G#okH /dq}`ů[@O)?@_Yj 7ƻ3imsAb\6zKʫB~w$ p,!שsVyNWAmk!{)c/軞g)XcK`/LKq^M]v$Kz>Sq]J׹MR"Gl!2t\ɭ%{ty_B=ӳh }lj8t~I/.ױA>'/BV43=) /wfZ14!-v~&M,#a?XH7Gʽ!j7\lc.jd H"OiUOF+ 9@~ uT0tk(ÀٙWoҹ +gʜX9O53 ڰJwM 55~~, 7~Ÿ&եu!:A*9{gXMiD@[w4՜" PGkZZ6t mW]w{υ 7 f7Nɾ& ߹}!/KKV_V i؜y;셞joG?)o^QӤo)1VhTb} ?4v@E)r'Hdl xvϛ:$>ﵞ8a2J73 k=LͬxF23G'_8~m_o||FYjiZ O Vev Eϓ#٣Blٳ}no7rsD\;8r=^_Z;_d %=Øf?y:L!}E:{㭙[\tX*ߏyXm>A1z)9.>{mUURZ @Q5pl٩t1 "Ljkh`ph i)* =8#%IWUjjYydݳ{H*0^QO䒝1f3b/| !w&L2 Y:9V- ũJ-H;aU7n߬Olp8,:T)[H:l 쿉SBv@X %mg3z+4ϬfwLV_!/'X‘oay1aWg3Zgb~Ȍ`߀Y(Pīȁ -BXI쪨EVY^2o3BаX4&V&#X&:sbԴH܁ $FH 9\r8ٽ(f6qI鹘k\ D1^$I2fR윩Ii m bVb'{.S^6ڣ|kr9kÉe4{JMy_2&>~cE$ s( [4T=VqL-,V/Qc's(J"TY}[?aI'(=s?E&}FrkVZº: ͔^êk'[6KTF3 fw/ AqYd?xӻwHM>ߟȻ" l AwPD=LPd:lLd*mM]$67?uI l62M܄JCD28@>XI! Od$CLY6 N7΄fv\ Nz f Ya?o>՜v=i!$9XB$P*HT5I H8cΔڂx:OՄgୂ m Sb= JP $a2C@.E XP *.Iy'_G=q^$HlYF.14(A[ >85V-xO;":32Mȉ0 ʈgp1lݘ TʊGPB(d@Ƙ2Yd#B̈_{@cE2waň{ 0#ju,hc\m FY@p[`Jd"MV'?QF2-#m1ID="0M ?^UE:9,pbJrM 1 }SB~Tsyd$-JhgVqxGq#s79 DB. W?o?.1K:I-v;D*$`IhT(4-i*l(X$ ("٬ՀgmoIuR@;(4 }B4iGq̚pRQF 7B-S~xzsx=h r*٨^iōY[{ߦ55y2f$&kq~k KZ@ۺIzV! $4q[զ"K31 r#TBdV[]dV7ƭm­% ov$Y#`YuY5DNϟ~' %unv1M}~x;F8O}.zuH`pA>i@ ZXϗ4lp_fPe Qf-Ձ M%-D}NkHSyO+Ia4|x\87m=;mw Vp9LӼZgM3X`,w˰K U (a0s'7/`4<װ^XKkA0,TIbXs)rNJsϤwvW9ظZӘZVN "0}beY L äĒB۴!,R mAFngm b|a1MS,/</~Tv\IyKk?-jenixH@!{Dru7(/ gBԁkFMH(LL%VBN+|T !@B`EH=o$0k=?vRb hLtTl4ĩ$VH W.@\iO/ ^fYq->F`k]+DsiK9H@ B@&5EBvji~/ ⦒T,G% ]]:͸$b?~ *lWyLzt7.\rXxĄ&!p j>P$a A&[FISIFNZŽĎ "W$3E[[ v9eoY o$@`U8F+q5N剘7[. YhI k-M3LDd4cBUE;V=5:;&  \ҰŰF d«QN/Z-!H5w 뱼nܿ I$4- @eo5Muq?I8 A*J)6JiM ^)`B v Zh14Uoz)o:\Kԁ $L2quC=9X*&܇뱎rI %߬eZ&H˱$IZf9HBh!t[Γ/HKf; yiۖnz ;\O}$ʹXZ]|`$ w$mI!$ !!f RčHLі#ANzH,1lI J% ~v4`]@ ask{l+ baB$e}ށ2Heq46jI$olYM $$] fHhB @SI $ $ Sв @2FB f|@`H/ !F-R LD1LE-%Ń`2 sF'?ƥ0H)`6$F;B@2r/ @'K(`X|5'd% Hq!$C-[I ؁ $ A0)z\ԇIC@!0O{`H2)BuB$B@HGjp-4,HKa0[90I ! a4}Bh v!x$mK: \*iH ݠBs$2pI$$wHJ!=z BzB7&_)#i؄ # p`Bv7W& @I09 ;,zB}xl HOR, $ ;i r$;'3$dLTNF@8 Y "Lo #!95G "~YLs `rѠ%T 6Ph\ߪgw[fD;vi]!6&8BQLc^)U)eD BSqf~e+f\Fm1Cv /dN&bVVe$,HIR$BHvY^uqd]֚i;Ң=c`śnwd47e?i-'D}Q]̵C3iTr<ĩ=$34Y1jT;%C ⦕ Rc5*Gám'a&p4kZ۹Z=T+Yg9YR6KI5븤îlr9B.;5.7Ke]!Wۮ10 "^M0&C~uLw-"Gͦ(gEz+pT!F*AD\B r+;6bŎ/ šq],S+ޖD5-n.jlfs$E@6I\IXSW:Rsэ]'i HtRT![S<-ؒyjhη'`*D# 姴P^iM=Ǯ[Oiytw\1%[gvtزS+ARN :byZ@)x62/6s޾`[8huo{/D,IrRzbrycEʮx@NntNT&Mr͢z[f= 1boC<=sxS^EV.ۋ(X ĒHSi-"@61EEBmBy&UEbrB<UHN~.,I5BqxWT0@$ӿahؒ0X eN^3),b4?dN..)S}ĘӚUGamDA[ fQ&v* iB!f%s]]iwIbV=cvn :*Q>@?4FN m6|)Z,G(g#rʲ$,DVU|U%Wiwg K^E/7HFZ89Rd?Ksv9G5@4.x E;,kZ4!W_#78H湫(ڋմ{jq3X7 ?A/Dd2rGlHX /a_!&_PYl}CGjDlnƯW'E>UVZ*>Q@s/O'lyB`@g```` 6@7nuggMjHŰW7$Ͻ

ӳ;뒏gLaDEni! ^'0mَbiD!mptՎ.5J5'+%{v F&1[tN2pͶx@b" r2*W5Hf=vϺ_3C?-sȐR[&_`W #˦@ "n'.sm* _eN6 &Myh1m3)4w6. ]};CBO;塹Rw t7rddgCh(nFxhQf4mך~I;J@P̈́F*a=sKT6X*lRA0!L Qp4h*N|ۄp\G"$ V C K*ZJ*,+:jM8nQӥ7QΆgW XX 狦(*L$6~9 6$[snFJ¯jNj(ulgMHxC!ˠפ>6,2)=gl/ utFq0Ӭ`0dsыIX"!@[[M$QӚ4j$NXd6 (,iE k%6(`]5:ĸdxd-^&/qQE֋b҆4H$଱i&4B&PYlSU;!0gn9y0A! baf fO,:m2Qv6RLWnmCi8T1A^ 7  06J[y fnʶ1zq/zGB%PzW4gۛ_=6fE) |C"L>3߀.cI.!ZJJ\cU4h1!uhGCe3:лN=pѸn@ T2Ge,FbG&=N`)/a*o &AT*ٷMY&b,F-"VQ 7dTۄL!cFun#~Ya4#IȦvQyf¥p+"%:Y4{'t?vָDVCtS ,but~ 4ɇ&U jAޝ>gI#sT~;2="n/\tÆ1KS(1)&l1 B4MXs(r&*'ZwM{oqЕ߷#T>'/)gs.QH)s?yp3pr: 6.|.ƅ-DBXo(7y/A>Pn]VL* !=UHs$?W4Etz82Yps;v]#sc&)1tnc 8u CM 21 2M+ie$@~ݽ9gLTS/N֫RKo?C,GJ!Ib'm2(aeRE S0c9}1b@ܝf+} &X9erI"]lV>#8[рQIǏ\(m@0wVKU7s&GūgCi$^(\h(dΈacz:".)ʨsUm8{ޭlGI*|qf&p2$ ww ߸] +ļ80ZaG"aі߿p}pz If-dHE(ۉPڬ?;pTLdFʑ; UNiÊb- 6xƕ^Lq<;\.d?A '"**ه`IB6pH=ٗIbG\ψ*$A*E7*Gd-C%5Ua^FIql' is<8 jݹE.R-(J= 'q'i!+>~ҳyW,uzfT!y[EĂF]Q*x[6{]p0!B'W yElv02JMtyYL[Be0a - b K#t=kT rF/6zQͫ;(()V% )D)fime iwIc)YxȌQ/hZO!ZI d37(M0AZ)"Ɔd82c4H3h_uT.bcYY0z-@s(WִjزX-Uθkuti+ ji<6ۣ 8ެ Qxn ۓ3L)UKx"xƐzVv&/R(i3%*h@bU)hfS{W%kɍhw~V6R`\`߾#DR43`RbEf#b4 rf\ӃFqI%j$VVs-u(o=826\z,ZdGjRtD" ,)zHb c;s+:DK%}2¸(Yb'cAކ,)'-$&-s6q(# f7R uHʺ-磙vjKxNg)aRvsMV\DɧK7ѣiJda`qZvTMG80HLǼyMA|%Z'"l菥bkr 'dб X`ҊO &^< nw}hddEfqAt#g.oVoWK8 q5O~D4Ͳ)VtU<~pGS3d[lS!=}c&˵uNtj&\Dc?>ԝaXjؖKQ%i>jkij;8X<z^"*%dj㇆Q)kGtUtXJ*M1I*$Z?ZSd&qiEf'>_:*xvRP?S|<5kQbdgZ+ DB1F&U(Y~imX* Pqdu,ѕ%+ )c e88biDt;Oi4N큣~J'3(P`=%J:Haśwx:r]%Of§Χ]1ũWjJH՘sbUb"<K \l*—\UVU}Vf5\_guYJ}|^ׇCu7:骷hrn/WɔPN#_)V ,~9? Éot/%.հv|л6LQ0ߪJIbb̍G=ooڳCƪ*wrJ_}?FN}~I㳭;0*](hWbK^!bKKUr "}J,'ǗW"QGȻS}!RB .Gi='*TjIR֟g*&NF[미kg&US(g7\@G 9E$D C8OL`A'ac TX aQdXM&Y@yP6OigéE"H 1Txq8M}+.>N<=}hAFlC3_vLuU<v" .7lmntwv+7Yn?oygWvyw;P OLREe2IC˒V*(ˆN&{_>Lݨ#1ǟeF"p F*" ]d;m*?#g`Y~(!vA5.f}i2@FjABuL٫ EE 30N CN{O03bO>>oWkxO/B0΃ NwaHoN۝_N?NO~Ro>lo:Av&(~r/0W2`,˫}_l%~B ^y\cd/ÝױKtٓH"H?{]Weɭܷq[1i},^ZѦ]5j<5i}]}4GI^oui3>r&4߽`{ybVq(YNir/JOfsV~+Ħ#xeA\C^=I>4:40Oz_XC#L"dTWr)6ͥiΦLlEm_{xT&wæO ۉ;;vw\y3}PÖ9Tc~~3 ݣ)Ut.T0^ fesX]ܤxځFC*9S;$!& Paᮩ)g3I֧V85ekE0M@*HJRG0$}d `4R$ṘyX|&{x1kv=@4)C'!*bh[' UpŅL 7[it:Fw@sWi# K/aR_k:?B!L©w۠mwZ:H,H]^23nf}w~/ijy{~x;y&]g4>,yy_˥CQed֏^Qb3ߣWD] bl[vnM89zV4$y  VJg4/Nu dR "a?Mf&w$*N4$ $!?$ g,0P75S\\C}94Ey{ՏSto6OO_BRC+C*b"8lɜFECf=$٥o:|ΰ˥-S 0l*D2Al]wdUE*/W1ࡌwvؾSZM(CP#!R,Ks_?iZ {L/:Ŷ29#<K)پoo50ƺVl7媭e|3T_ޞ{_:_?,u:_Q[v^pW}ՇKisk/'iϹUA,ڝ^k(^C 7AG}ڄgy'h53s m꽿[LSkک#T0yq.w)R2mf[;j~^-T݃}!\=[^R?w|xsE![gg3=aM}nЅi|&J!m61`" (AAI>W "Z*UVIJDbb+;bUkEvI:oduWRiJ`-ȼ@\SlQ & Hv??1h0)!⢿ӕ{6s" aYR$L-DbS_qߋ71/prDdܒ?Et(ng-9,1G\7jPL*;ioì ԑQΚ`z§D0߳8 k6;N%^m'59,p C$@ˍn<;سi|M8mut;/ԃМ._SUf3<{<¾X6;~G'1Sy}tZw'Z)gs,1GGCoˋh(Em0 1xv:_"v>#;WEȱh^O5SX\8swA6jwy pPN^nkޛX s,=SIxHB4xL$<0V\44Hϲ$z@cB@XH!la4 i [@t>T![FĀ*b-][ @gč_@;āInpI ;ys%q[\ w=]HgoyWKC|s|b8)#[5ҳ?'}7r/yk<Ȧt]+U̽ux|^<oZLf#] #&ۅASAHm|Ρ6?oeU#2b}*0Y(~Šot(ɾB^!bC~1Uv&T# k<[53; 3sMX&1^kk0vm/ 4u~|+k[NΞ(;yn7mCFMp:e!"kڿ&W-5$3;WvY#ʢsj-;ZظKY-!   c`UQYδF/te'+S]s۳ysdG:~/^a_nqV P =*8!I\PSjU4B Ddь$4(Y_]Vyn/c cHjxtNEnO⩭/wz4ڦ܋|BL`wgGݵXv=vu~sSm9:Uo{G֫ڣߘ߃o9&iRcw3/oQ2̯ʫrp @A!Df%?.4U ~w/?ӥc ;߼l4 TpyL '}-?*{{x^NkKg{ 6 >It@F7)|Y~L&=]gb4M-?A[@*cI Oa!= L fbLpϔ!::Ek5(R\҅fA Xk@QFnė`V0;Zޡ] ϧ0ݔm69M)7'"/]b~>f?~{4D7ǹ4mYy-;g[ju口(Ws=޻?;dB;~oMqsYq3a;kΓd绘)Cߙdwtstr[V7pt7},>ϗ okt'm(Rտ8pcz0 o7Qpe{TH$9о vhL&Š -\S'CdHE!ueHOrL>f+Z<&!$=OL?OLa}%'FdQ;|o:Krfw?iL6.ߵ3:ZV@ʣsU=nnV,I#jE^sF HP,l*"bWl۽;+ !KӍ)~e1s/<ޯ{ދ^z6|~Q&+d*64I'}dBB {J\\r;)lll{5'gSDǣ|;r¼^İJsA2e~ oB TI:݊P'bCN'_4ԉWF?'YEUfUs9A`hU.%&Jsn=Y9N_K<{%9]SYIս}iC/ZNWʂh^.ҼvyjtzK>k}Or|H_i@uf3$6t3 3  ''òO0>*FIݡ'$>-'9dXEn$1$=(B $$*M$Z5@ >J}P DRpB]g9;ck:{.v/Sϧ͝9_Wݝ=G$v-]AnjD8cG{7߀6;]ҍ>nT# Ϸ\ Wa׎P1ppgbC, D/?<7بv鶠{Z'>U=Oy/=XoHF~AlQ@ᑭ$L;d-H B!q[rnG:qbhh24{>,>^:/ƿ]xjG[Dwؖn%Ʈ5nPmOPS C TBB٤~{!$d }OGG@VϘ@<$01龘rIvr\>?SYz/+0epRVqE1B8 `q%©~ 5[tH"EOOft'|m?#lS$>"q HÐH*#"HOݤGe0&On4](O'5"B Ӄ$2]+ Bl!bf&伦e] .ђu:bdJ%i0jPړ,>_8O;n-\F{:O>Gw_'4F.mBX A o>}CTP' z;U/Ц<iZT*xlK~aG|.H{-CwTC\+cvLb6$'ew) 'ҁCЄ?H@А G$ $?},$ HBAT^va aܹACHHq$uOʄh%ΨJF%Ȟ̚<523_ >_rh&(1Hl>oY33?[ā O$@0)KT4t$!"TаI]0I;E; xp{>UN׋OZ!02Gۜ}5%'0)c,74\ .;1O!NH_`uB{ " N"&rKD,숁J VsL. R;;Og\}brs9&Fc` sW`{<4XJ8SSLޚA b ICXBBCP!=}Ux@&3@&I= i?WφŎ'F0 P F=Mlv]Ta>ËWMr8B/>wȊ[o3oo3vy{`D27'>^eS 3Qksdl+$ߘssXd]K <!~H0MYY @Y uV mL qq mey[k>gGʺ}$ N?HXaZ+hMKs9 YǿK;eY1y%;C ;^/# YV!5T^Ju;M)YſWUѷL Rzwu}/$ài6q͸K`-~CN=,ƹ>a,%<4X4B\?_+䬍(yMpP uJj/vG$Hl|"};Yr3ٯſu|Vlty>?[>S5c2L K B:>7PZ(~~.ۖ} h;[eáUQr7K~}CsTQt>LI w2xnjD6(v,1jGso5R}-nET2iBxQE} auapm>+:c ~;9IDH2i,%^8EߓrxSD5cic5~3KCcc.nl(=@i/=6=̐^YU<7n՝SW<̻ǙɏGTL#yne|oȻe]]N]"\A#J71,5C'BQ$%֬G; L5r9pX M d>'48We=/ϔ$89VfU8Б&*"mN6dIbpw'^5]m98'@+&/-;{ytbPUbS͆SeJ#\X6TYVeP :+]U+Sd,08$ IV!b9*bkT06շ-;ԭ ggZLK4%ëാz&(WJHoZD,JK0Fi/Rh9ު9 y"= :ԝ'|:gP^eE<˞âmu&8t֖n3 υzx?Bxq 9]cYwi6͝΍tmC'<S S{!_"!ߟ$J&DsFza3?ғiz=YTrex l&CND }n20=ތ3Omfh4nKE/+Lb߮@[;GK) ѵ{}[=ܥvpI6JAA PG>RX'Y)SfHU_̐vSD?Khk e$cr ` lLR7gP[:5?An*U %]|uIz5\q1f4`ԭj?LN@%fd^NM)GQr;]tot]c~O1 NHPN( *Nb h-c[۽}؎+Мw ]*B˳{Y {\_oٔ۝&KZ : #tyzW%oTM2aZU禡I7ʌ. }{'Z(NfgXnE$tE$JqE[cP#Y='2bE M|XĠ)b_?x(,xx+-K҇6 +O uBڡfq{rsuYk6|H\5sq^x\ Yًޥ6#siJKomȺ+u1U;^^؉[;T*D'o7?S f`rđM\,˝(ՁOhr m~/m6R9&gv`` 9)]G64vVjrSeۖ5Ί [P(/&?tt)xM|~yi(HG GrտG*\r[ ƹ*%uXŌF1W3x`AFj-5&[u.75(b9ǚC=z " R¨O.Y)!p3F>Ǥ+:!Ly5X/O) AT`x:S7T338u~b#"6\$߈JUaP ?#˞+ b2sl֟VfIQ1Jqtpԇ٥ɝ X@18oN?r ɆIeKoȐT!Su(o&ߗ^6@C.R96sT[GK(˗N'J|X"p%>rX(PGC>^nŀ5 Y^#6~p*7LhȇT J ^3;sQS㬻ِbhٚ͗|7u&2 Gt ]5\6dGFf5;)L ʆRg I_AJ8!H* yc"T ! "QKc RHw=rJqJ4k5M՝/ɩgf'V&7-vYn=MҖBV:#ֆ{bH2n/5-5M赣"dJ À$Ӗ$WJ3WJz *"9uN20f6@2OXYnɅNrAPUDX2d1!H[P CBj#KxTGAY.G$k\YDD O\&x bnҭ Đ;y jdJO :cФ5A+6G=\y %f"'s'%6?o̮0S쥮t74N;ϗܛ@ڭl:|Ŏ,SV1\a,iKW u.@#WܑZs Ƭ{5MAĥ{< %8x4Y$HCRm9^ߐq^#Is5׎ й f>_ƽ8oJ?5JA4 ^̧ѝkA8dHe ^kwHD?I.5v}{`s|YW?7!#2zX"_e}UII]ΌUaY46àLrMxIsD<]z*T3<ߨʡkXb@҆v~ 6=Ih,M0upٽUz˥SRϐH 4`De`T7xt&Y5H|C"e(V/ gyIS(0:,?rj@V$! =ES6Q OFʀ~ӊlP_!i2j1!* 0{E0Т3܂"A Xݜl%vחEp)7I%7A83|J5vC6=q.rj@əkeLDt,/+[.D:cHߘ بEMAfVq ڤRrcEgNL !9Tmj 5DK VĨ|Ǯ.9[H`2^A}zfJ[&_#hQ ]#l-FTQ,]m웚d(t"C⍿M\ TEnlTEG9XVk`81L%(ommx5ȳFH2h >$ Nc [mb:&DP0{ {rw4A 4@nΌ%XɹAZQXM{ig)TfH+PgB_ {}aQ {58Ev\0Njp65$j9zAKңz*y+ sIb>74O5 rQ;[R!=5yypMf/)D DJq69ɀeV,y780VRv`՘uhl+nɚ`5he~1jc.BNK@lF"R@-_9;㣥FJ3"&EcF( zPK0eTEA75eTX4c<^é.Tsoeel_˒=ء^zUfeb",{eL1nw\l}3bS:ߧ`zR͉N[biH[!QSbg)01bf3da]c5Cp[uqY'IPu SLN>nP=( :D8 ΗG$cld͌JTG0 Ag`K۵ab p64fʓ逖7Wg`#v%u_ 11kVr4 v9vz~6\caI((EEB"PQ'<$>"jP}9{=Sl% Aq $LPX",m"A >Ǐ?w#=*hij%/*zuWY{G"v&t@*H q@EB,`xlOjOnrhԽыwd^ ӶG\6!i6 k-5u2/“õ%rDOlr0$ QWFZw߶cCPef4oѩ=yW=q(F^ UQt] Ug_G$5ch6+K[M${,Ф0-[ң8񹖂(u>7EN:TPٙ $1 ^@]ʱa, !!|C3@Gq&pƥ%SFnNz<*?i|ht#Ig1 Vt,XWsoSM[c%r l43ʇ= ZV|wvy^>GCht^p-g_ܲwݎωЕ7uNbTL, aP BvNv>?ۍF{2 W@R)ffנl(Oɗ~$]Qa:*d(۹ \:heWrْŠ]m԰B}KbqC;nCtG=gy+ކ!l\W2vNT XN30H(H:h;apQHQɎeE?Uݤ`G+bySBr׶ND뇙vbqU76 _ H0t,0@Lc|=w]jZ@@,$4UTP˕q֊aRCl@Bq  Py>v蜺TE.4ҋIT ~ǿ} &x{XiY4F.!0jj$ ۀ_"Fu:LJs"fJdD²l,8y,F*k2̫ae#Wh;2$Cj+x,6vp"vhMAzj~w8U.#$D@ȋ(_:87O m _̶pa?'i3K# TdR.Jt!ND 4J҇@b*VMY^uoNxY sՌ3O4~1#49'!w 6# !J%)@q}]ڂ7sl=P{‹~{PmyEAUMdNx-+kJRչ1Z &$,z["j*1vA&`YY,եZ7plI* 6z=N%F]wb[+0[BUcC, r{);k&XR_@% > v4>˛ AAgQLns!1:%iţ {S\;J7Ug4aa)DfkZݻ2!$P!R&a!¯ ע*+PqBf2z[MiB~$@͈)AzsZӃqt@^90 rUyx 4HהrdH؟(Tsaa p سA_W~dƨ#A`ZBntI_ $CjC=kJJjy!])Ey8s؄@_;[L:ChP(Q)h 46Zmr(2F䢙Ȗ'3_1 wB u>% %+S y}Ӱs-j L3Z8z7'}Ç:ƶ8h86fwTd\b|3}|veV;\I3. L A}&z-QП|!0(SVH\s>?,ҲvIpA+83wnM}JLTNgY֨ "S]G)9.ay,zDDR3t,?[^5;p16#Zׯ#q%o ͘`1 .G6U E&8FR)-:ǿ+NdkZW0" 4*bv7RIeKvJfh%(_+7 vLC8bj, @@D #L aHI ]V$Oe09aCVt/H0s x`8)ءlb>Vٓ4̙GY6X4WbKĹ.)#|gNך²f 6"jfRQ WPK&P; ECΨk#g5iy//6ACY3G}oH#J0I|*\M+p#~-QRp 5 ! cEW7ɗ_'S7Us|~}ZIBpZrorMAP)OySgWG wV6|Sܥ <A~rx76HWP m m\L0u& XGq~d<$mֺNoIh˔ޑÉY"E'0b \vrY<98Вy|t_ /Pؗ+_K}|uU,CO"M}z/oI#okȳڻEF2 7!mFRY<=I}7aB#m's Y6P @KMrQŁJXΰ=HY5I̬+&u<^ռҟg/"u$,ނωi5,HgU—k+=$就eӓ˹}|-rL "" ;Rn̘u#EeX NNu ċ6zM]R Y;(PQXMEk)!`!_:TJ m8'X+H}{u[2Y;熍{TV李I7<%Q±O7{f7ى}Sbb0WϒS5zKJ{fLb` 6:ϟ8 %&F_c/_W]P h l끹2VY\SZp9n( n>a"lIɤb"Ҧ):7馱y2و4(DC7jZMd)ǻhz2Ön=gV#msv@[5 Z, ȴi~DU&d N, J7åQWȝxwxcL{:T]w?y>{LJWmqبNkmۼVj BY^KQ7At&ZFr]T wx|yr93$DmJ򒗌Ũ1 2ԋَu+Vq!?,!u¤OݭҜLOlԛ @wwВˍ$!Ę3'R*,:Gc߮ c=Lc/e"!:h&$an|S y8i0.T M?f5-cWPZqԠv@txU|p=F2mgfUXdV\Dm0{EҶ'5M\ uX_t ^*Ƴ N0g=zwTTw^c][wgr>ҦimL =\=lo܆øQ 8U]n^.cQy:uS`r5kTj~srXUh]Oem>;M? NU94g[ Wa` ~X XU A \..g3#3S\нF_FB:#!G1ȭ:"{H)l9h>I5v%d*A|9!m1NW)F ˝zhaDL$!6BW3aBUȕӎ*HB7Wn&(&<,ι`l0X8F<ˬxg? QH77Ćfi b0ǟR&Jhhl/W!(e-箟.l?ۥҕ=-j(sw4c![ׅZ;LZ] }Jǰcаu#&c`3zvk<2(rDZ.>᝭ 봗 H x*bڜ_zZ4EOubK7EkP!Qb PZU@0Txn XEW.)AA nvR4UK-\c+,1;qg! 2"|syˏIC90O;`{~)ѧV?{qӖc4@RszNPP% R%CrF $3Ǫ:,FapTLYܩ,hKs$&p Oz`91 [~oиoL,XhRNe03'wF\vݶa J (ߨϮ>Lʺ^#Y|_,FL}a k0;?+HU|'QZPEp"La( %ڶy-r*$"YhL!b.C233ݯ>J(H[ •] bV>C4}߅rJۣƜ9K%Y $H0P;VRlF7tS)Z&%Zr< }iu]};D-Ze%#\!bBǸQhbPA;)t>k WH-5wp%m6V_&e;OAjrF$4`Ջ2Ǵ)?ep^a2!rb9A ĸHH^?ƤdL ՚P[! y:9kKn *(nu*iF<-L~K'S2Gr]JGlA$&س&IJ¨,zsGK_PBC<%Tz$4ˎo5:g2r>!ф bwh:K{+`"wR;srbV5P(j?P5r6>K> cg`}*Fvz6w RKD<ֹS+{׸KI7 X:-m{z^PG/{RemQ݉19IJ@v%l}ƻFG~G/EՁL|:)'|y'I"FS@?Oo)ۥ_峘6a_6*%~=Mb}>fK<׷@I8 aiK¢T֧ۣTOa:ť^- ž8j,@2QձNjty냳SINJ+AN,.E}Nڢ)N쵩vN% G$w>`B(>d?v5Xf,/6wu[sre_N߳[fFŐH(lIZ;~O@uS(r Ԧdc|!v0w{&X ͽO)l3)  !Q |$00@RIZBAB @XHmI VB@ @$Y!$$(M&愒o(E/I2NBE|{%;a\TX;XCRCA`Bm!Y $"R ((@$Bja !b@> F"$ZAIfQD|{-a+n~}g䱼\Grnq3%Q̖3I L> 3um0W0@;b!d$x^,TժB@9ćkɓ+:Wh{mu1ZC#[oft<gqZ'{7|jiZEׅZC93 ~$BC$2@9MZ"rq8''ii>c3L C dD, UˆbZzx;36㫃Llį^ !>-!$ A *I!B`-I !$.YJVNP~|q~{TPw9=\8Ev$ !q5d6qs]DžB<`E v\2G<xR@B (pI$!X$$%V :8(@P#RLhAA%"@vvKGW񿸝.oPӥՐ C.ryS3Laeϡ2m2BB *L@0I)$'qHN&w ^ǏlvⲹK}= #’ vVH#BB B $$4@'c@oƿi2!{'{$*x0Y!# $,2EI? X1s$b =B|fp8n:QI )3#*cV,ZBSQ~ 7OMZP!@'0%a=SJh@ Ԍ8"NA^/{{octڿ{g llۈO%a]uR ܙru<2XdϤ . {Ha`?=vI%EI:ŜibWp'3 AB!l y 䬲}ݕݖU "T~\۸x3.Yi gkG@y5<]1 9"̂>>0|Ƕq<~|kp Ӟ0'f3ƥtv 7џ2l߃[q=9j7$ fP@"Gg"du%>[tZ'bɩ+LoDr 4 YB-wZ1{#Udfey2;&F_ YQ4$P!D=e F&]0梄۸³ΟŦe<,77I `֊17>K=EFٰ1kO!:振}K-AKy6> jR&][sbDN!12f)%QǹIU&+ 1S@^Г!}RO =r@*렠}$;ͷ`DIOWzx;aMϔԄ""%/Ч??OwO.$~Szh晔.wY 3PjUe Xn0MJ,jXΌ աxBhI-œ)/"WaVpE`-Mw rcU/DiHHO@ [Z)H/8$;av-C`*6VDtMr IxSrb,| i&l oÜ/׏g7Mt<2z*e "{oOF3WgR{QCev}zHD4HJ &-ǁCP&: Dk9=flbfj~[MyoK׌?62є\;_R˛ / _̔z.UZ ,O({?[]W [  1 |>i Vb UM٦Pwr Qսf1xr2yl|j&6pߣ$%)=1/J䥓58kc9qZY0OF\JN6 6' !dwT˱oë;hПIV}֔'@elۿ` H`QH "+9:92hCQ`fNC)4I@ e/w*Bd0Mb(?37a.jU4F{wDV#z%^(c"E ua|WH `8i*D;Cm3x4: {O,n/;`:Ne nd&I7y1S ?j 5H.8N1`Z~ł{u%/6tJZfO&{\+ m1JۻXYEli2]-y5NM{gƴC1Yœ2Xe7&bbHzU:cpOzX훞k0i @5@Ƭ>,>U.]䇤ս*P +Bf^)Ԯa`S5=|q^%.asvYRe>z(;!ɩĄxா.<+x!Xܫ1ZbPy1KI0-nf6\khzl;wٴ3 WCmÄZ%گE)ɒ밟jD3< 1p({`ԫzP Q$(ȐECISѕėuXDMwfZr%ٝ-A9X)?L"ɒ8qE&(r|t嶩#|KA8NCwhU1I чJpݏis'ݤ,V(-k'd >i ͆#u6S TrAVֳJsaQzZÊep Dy"wzEy I1S冐 LVLd "áou4/Ik12kà@C3v}d?Ax@%7wξ}>Ga):Ju$&2G>C8cbDJ.Ky箖nYTR`i7ϡ$&`V!Y0R^Ř0Uƛ?I+Qr%S'  VOZM(;vׯ;.|P)eD ci^I,Oz uTє +Ŀ?ڒN|S$iw2Tdl`Dk 'TAtcJ24*]KRÊp. O"nq:Zf ckiلR,Ɠ\/-$Dk%L<ͫ&:z_ 'YG@'+bP0f h8`NA!k#CӓB ǿ}uy .Ӵd0*b[V":3f? Dx)T~J9(M_fug#;ԗt /ܹLb;qL:R@F,/R6?y;v9+s^ >AA(/f0 !#T8P9@@< =ym8",|=>ٕ|Vv]`V$(1#ٔ`ȍKJ#zýV ?^s[/V*H("FU3i֣h>(i}Y'G7THMG(aQJFd1(N:[&VM@BUl#?YۆP!hQ|>4 N]U b\s4U'ۈWaLd&ꐛJT LC#20Cl4"*|6`O}~WWrDX> DN)_]o @Dslo,ZdXSߩkf["}r*t9Z";J@LpmjK8(T6Jw 8gNU#p٩KjManX̧0h#N,eD]^I̮Py+udf6p.)WE.1@Q]4wKRVadn{}8Yzs88=LuX"VB@qL&+gJǗ(@дe'|Ï%՛9Tw(3<򲨕PLQ=Mw R-Umrȸ/$̪ZxҸ5MW}޵]oBFtSR B )L-݃Lo-6CyCkU;Qe|p 4 H TTQE7/31{!31vҼ`F7}Y'"K<Hbe/x3/w]p,gti^r5%l蹌 )zm>-$@Q ;5-v7p%!|m'_@ ň2w {a ~*$p@ "@<7s)JwXCW8 %U)m].oqr0 1=qc|#j_s]Bjk,2݆A QYGe̴\^fkWU\{7K)m`v&DN shySi a}]3ݠ.a`p:a1X Qaυa*mwVQQr`+M hf& {^D 4نt 5&ARDL_i`ko43ӏ`_6>I:Acv5-U| ^]5 e$x =0'qAE(f#fCFa{HڑXEPluD[9h6ۥ-oL+Gx<^jV0vXy.VI/*8wd0 7pyVQb>wJuZ"SWҩhoċ?[Y6t`珊94($q2eSƿ_)x10$ #)_S,pqp /Y.=76FZA@ʚG4~1֌b.qrbc2o!UŇ$ʿ@Pkj/FZG 2OO$LzydKb@h+D+mW2i_^o7T%K:"FH>W߆hEVA4`wmeq|p,(GxȢKevsYBN)kpD5FޅVJ-]~F}J:V5ǹv]VЙߟ˦oy/@{iw}>TU러h] =lɫQ PDHNK6b7zY* \s -Oaz"W;uzvA»6r{K|:y Wkٯע@bg{o\wI\Ձ jr_m ꕿk‹R"(C ¬`w}DJR\.b/3$S?3J121VD %@ɠCƹ"@К 1kRw/fh D<hQbOlC\=*e+ P+4i6̌@"+O)&5ȼ.9ԪU6"b>lN޹DkT E:Q|9I BBeJ [ e^S/kE"t\n9sdGç=FTHW@nGVL[HD/aJ )E.Fe ,pE Ҕ@=nN4 9z].A0"T&FQ]5? zL8Df*}|Q,JoN]乂C]9 66/TYwdC1{Pݷ14p&\bRXy|IN86AJ? m 3 k 1zRRC҆X:qIsOiXZ5@g( L#FUP:gZҰ:Ze~>G{"j'dNJw *Pj0vR2v XledDB=5ufx?Sb6+va\ ,:qȦK*41#,Ig 1/\Zsuktp!dKot2M DOl$1 Fsm~!Ž/e7tӎŐzh\ ´͚eY}8@繗^*t!ҽinu AYnD g^^\ wlHX xvxJHB"EY5qt>kG}X;x2AsQFENjI域4FYT{&eu@U,3-UPx>Άf2#,72U8kX4ɉT]D7>AR? $ %`I 1VBIC " IA/)sz3Au'Iw'j8hZzRr8nc9bhl`~ctB$# =*i>Ͽ9<ϣmˌyBמּ#yPTbNxqXˏD =d H@l@;А%0KѴ:$=d)D[p6ZI6x]GU+0^$f~m'G]vdx VwEFH!Kl!p BCcMvdlb]k+8wd7Gμ u:&{ڿXa!a d HHw_r4l?@$H<1 O(x풛߿kwU6u '=4t[..P3\&P =$HA$ }R;wyc5vHn6`Up1{~oӿelڶT3 |:"P]6Xf@#nĒ7$f#f90d'8!1HJ2#7ј!p Z'RݯzҴY Q&5Y5z!ClTJC|JPor? !0@oyP_HC`BH) m$!bH (M37 25]Fߦeg[;J[ HJ@W!ba}tH4V0KU&ҽ/|Nu{NY /eg0uc& > nd*R|r$ ,!CcocU,! pqAt֭7zT& ر$c5N4Q^dHDH4!s$5O{I3,*%1NB@%N,f~Zۭcxf'e+$!, XI@N0 "@cyL9\nbz!m^l{N^59SS*א'fy !6Ak4-1H~V@3h@q@PMې_m@c12v?3>ZFQx<>_9%l >́ $@Y>!I,db/08/x_us[:{V]RF[-qMZ7$M- ` O8/Xq4 <;oYcEG祘 ,&L/UDKnUx^k˿PՓa؝PQLzc tDtV{T?lZb#&9:_ 6}kڔGĠyԃ<+պX9 ӰǁTٳAL5 }Vp3(ӳ|sٱ5!һn\(8pDqpQԴ3|\l1jYpFg|ldnAFɣʚݿgǤu3$2*avWi,YEv|پ|]y '?O=6!`G"KUUjw<w1N+puv 򟶀_Uҡ,% Ä!L@ #sI:R^SR]/Jб$_/9t}ߺmBJ2EY'&):Q${&Mz)l@BÏ{2%z1Ս^ܢF$&6p| lA"J(~.uz޽l}]w\N2{Q%o6)te%(&_.gO#T&zʯ"..{ $&X WRx7aD]-)ٚr ~p޵O- 3R UqqLC-Z9 eHږEi68c x4^u8rt/.6ig`X)RSIQi0CtĻuȡ$ۣ $Ū8L(v`-խs:<`oɸv'Y9x%]Qm+-)ؚ[G6mD;*)Gke@8@/LMqʔe RMgTE$0|6LJ0YRUm(=\SĴgxXx7z;&c/LoEjAI;O7z|O7ԚE9?wh@@qu<B alb1*Mz,)bސmvܒeuסV{iU*DJ)0Ĕcd0'.G3*`EVtsB<Ȉe4Uv@;ʯ0$ $ C0Ix7_|M6f1w˓IIDђ(s5p!F< DN;nR|h<9B| oM cHmK;81C#i_G&x bHy#)1}IVEWrW!w{_7fL;xBA %9jN'!K{k[𐬚Kp}hl,!se^myv&ئn+5l{Σv9O͞@ :SpĦ)-+52ɵp*&[;ʓ/>Ul^ G͈J5u׃5JƲt#vMZ gnxPJ: B/Zd0Ew.HIvyWJoN_mkCǓ/d3e@) gk#kJFI6lEsY(qbv0?yyւa D:ߋ;& .QЍ:}~qr;wpg6Tʒcdqr!+Rf,PaKbE@KJgkx7g36ZfR!^lTSʴIe\kʑﱋL&^3m . 4qmkj7G^~JǑı-k;*q> eat9f$m~;ݙȧ|En*L9!E,}DwI^zB=VyWňn;%{eFQg1WΎ)b`RZnzrR~o[d4vy|/^{3ty_˂A"4³&$cg@8=wEՇ|kx2 pc6sAߵ4_[;an2Ix >'G"b É֕)+z'bc~ 3i^CqGc{;i; ] YZ?S WQ>6gp2 {%P{[Q]V P"c$Tl,r~wi8ix4z#$ҠSt]ctsqù=е-b-:Ev_r/ZPHeצׂ9b:Tx#lI#FgMХF {3sodl*#3~:L?[tNd`EN$m''dݞ-Y*/"fNyBnjy4X>.5&%%H1ϱyҹ]촅J̼T.|#%纣ȥ}?'dzUoN6ԯS"á+'4ЂiX=;L:v#9 ] *qbN\1lI$XpRI~a}h5900 @ 1< 2zIޑC _j Ȫ@&ى؄u~+H32Q% ?[7q)qcA9iRCneח_mbx;c{3es*;˓gr $d720;67ԣ%qͦ(৕w}-j;yR $Sq\p!mt2iͨqYN[jfZ Qͳj9Y}NX>HG24߯:6u F)pEj/&R{ہhE:lIyҫSH "Po٘ V>n^,8p/aY&⁢RgqSIK dLOYMž( 1g/x; W.SS+X-PMQ*]Y@} gc>uC (HIv1RvG~_«2<\"jhvo1u:U=CtͩVNEOo>MIMpqudWїэ۳6ݺ3U {]gqBizVp7M^h!˧k vSq}6>53gv{ύ¨+>AQ<v\phT,n.PLX<Ht#Z{]ɍ:`3No~4rh O{:Uܕ9lޏƮfͪ˅?:posL7e\"Iϫbٯ֛ǚN.XQ[/!͂9]h^Д}][~{O)e2p;0S{ ;:Vď6A$DX)="(X XX$hw1Ie4}ȏ>L<`a;~ -jxZ@<~gv$B BĿFe5ƤFn! =IqG=$| r=Uc_'ҕme=to7I#A9g>( åOu/]l?>_3#ߌDNSct@$) ElY5M{IO 0A>L=9aEbPV_6P((OW_gM+kI!'p+wq6C@oDrVϳDjoze<VĎ;^vѿ}7a8`饻nxv+k}Q$J  |ߗ]~^mwPdHr=h4?Y S(e%bcEwrz2;~rxa,G;nwK]HcI Hˤ ` Oa*FI P7dqoyvlז:|{|SSM;4CHz3}%CCbYbىR{zG69 r/\v-oEy6,I%X#i$)"eJ?\:Y'Hvl6<:ڐ߅ ![k4~HOd$9E  -I!wiWc{JFBTO0@찁 g@$ w^43lHU&В B$nٔh.|&~*p$ PI&Lޡ0=7FRi! " $U?{;6pC$ 项"HzI<$$ 0CjCSC)'"*f# ؄d۬#oqD85Hxbc2&7@ HՂw3W:/< 1\R`-F]ؒUD`OxbB};/8`,I.+$ >M(MˌcO}9XdaG2ÎH l\đ#d͜ڏov,B"4h\aVӝ9(r1D`$?7o.nmX< y)%J~ӂBeDe'AZhp`3F:Ojpq<[b$a0%PQ(5".?꼯 @GƐRH4<$rJ_fV_$ ^c4B &#QaRŪ $MD a'hL_.CU2):-hOHt]5,&37&$0C؅!BaYAf)]CŊlÛĂjC<ݓ|h,sC4VJLc?twcalS$v%%`uGDG[ u İ \ pjƁ2Jx+ A&& Ҕj+:}4a&2*daKgQRٛql/Z֛vq-§OM ݳDܕ9̾`RnH$b7\ע4@N"#[i:ɩTZR9GbXK*H_zB}6RIMvNV[]\ 7H[iM'Md+CBa! TH:g!Mb L>֩I2ozQ?U5atɴ6>c?eZvK=(>D5bK2jxC!n6UiyH d\kbXFP<ˇᱻ[-ʬ|lelm AC 3 vpEY&U|BY$,%`b8!jRL LB(~@`I/ʞvSk~9 %?$61Dqud]5} Q΋QӉ:4!>FPI}(fǃHSeh'L + zL% E @+$d .#:HjOUpzBZ,QwVZ7p$4sYƕTZ ; rV{~=)Yb'A\H9[Xy9W(ʫ ߽p159q0jPպzq粦 /3A&!p8t1%<ӒX@pfL9hf:@byFq^xc:ӑrKsK˂FxxiFҩ.'k^)FmM08"ֆٗoXP44( %}֪L*HG3ou@ "_EJ/&FHIIE陴  #)fTj)Eܓvtz1eRJF91߳>K}\q%J(o>wwW͉5df.璀 FxzXؾ[>;,iZU?OWm+K0=Ɏ3٫ S8m5ۂlC5z]xWf2eQ⁆MO*9/Y Xiq]`kMt쮧~-JxfϼeM~|_{ \X&;Q3RXoJ޼$#2# }9縋i1hF̆> T,DBاΉ!]/Sz5AWbdҼVyZVZ `D!j0rZi䥅nv|eu-@xI7Yjc3n/JՈ>K%`z~pQ7۸-4\'Ug# ~0Εt6|2hgkUԓ!b]hֳuAť![wcg=>̻8Br~v($YCe@A.]7(<>K:c'EFcB0 OԨ_*1- jB[NR3@p] <@|J$мҾl7Pqhߊ&l]])n3iGֶE7榬;c18OCBy`PY=(}nc̦(Sx"!1S9Dw' +K#pƭʭY[|^ħ:X|Փ뇝z^cc4ͭӲh4˿8朡! vڽTw(^ ["M?' r [E?C-:* 9t**o3*qnbHvA 612vE2KqRP}☇G#ՐJ(kW媓 1pb DK-CO;FxdHLE#a[=\N!bD#B.A,J:5(/@U^ד8s]b`PɷK"NninqflS|.Y#<%(/ 4f.ڹX̳f8B+J( e rfnc0~Xwy;}*GCPӿ@-L%q =7Z[U>L^JT)[Z283,=71W(ّ̔c#-cA$VR7*XcY0ɂGd)I=orV@lH QbK)f[1tXxu%>M]NT^/"^+E(Q;s%bԺo Zܡry%-ņ :*K-K !&jgKL4ie/sG7"]u,ʍHZڲnc_VuY e! Ӭ#>X-ܽI 5G(9Qk(N&0Tً`G.#g\BOĜY9 v.A9SLB]H-k!cXz< ǥ4y~Cq嶬aI _w^E|?X!f ';!&>$RVd?׊Oh '{z$̩XFw:dE}oAG.M DCBTX0`RvkfeC/WVk\m'j E q$#   䇞HB{WXCk EFw'6Lّw߄]жcM&"lnw8cduCk$tF?X~: E8ib~e zq}/{Oivz/}t}3.ʬȗA)s?g5I$dBK4ridvCiH9I6k;^@>MZ;jX{幃YQ6hNvTI4 3a So## a 3Y! !\ָWչfèu; [a "ڡ?`` /"v0Zri<}/{_A[Vt磷̍5uF*I!HP'}H,82>VE [%t-]UWpc;VH$伉F , $vRxH ,)ҥf)+~/"nnWv 6<:$L@#+)9Vu<_ -#4 nJ|]z?'txkjX̦RǧtՄ$`#(Y`p{)OQGvYvˈ@ 2IaIM/x} I2;(p{eWc1.ɌBĄII<\Y `}~B (GzGp 6H8-uVqq tq[S܈%}& iDTNB"V(( ;}~n B0Z2ksb^,Hh x[ eRXm*5>qm|8[Q `JNx34W@lbCc!q5DAEWo;~_=Kȵ&i)2_,wQ$h Cfp2pV$B8d$v+Zʵ00GM:K)|Gg,E9\#c<ce&TGx,Ґ 1?]VP"~N)Z /}v"^fJ%aLXs;+fV1tJ3AU+lo@)_z`V\.NMBdvotu j5*z&-Y) 4-HR=Wa=[S`V` W`cҙHfA'Q$@$1@"d٨_xͥq^|֊r,7- )dR  (r]zj;+Y%p?:,PhY1EYf6D<Y:+ sp]sQ_8jkl ; HW5w_褗s 6I' BSHU#y2zX g:u1< Z沬7Ҿ4C\R~(US)2&.dNSps'_轱Dz՛G/CȰC?>y5*z[\w$.4 rJѐg+7z0ہ+kť?],cW8T.:qDqAdjb+MUv& 42<)&%٠tnO1:K*r4nd2kiQ'53p7E80EbQn叴#̐0kdT'NCT1_${N,H eTE z<{l}H?xL.P~S{ꌕ[2PB":lD B}JCq@rc?n7se?g9@B u}F !7m2ѣWg?nOkwզ&ok?Ë+e`PqjZԒ< #ȓ#v!pp8\QAdžw3,ٷ[KGnNeX=}gAU8<}lw|1 NvܙəS5PhI!Ro= GO!Yo&k1re59(`_e<C?#3̦PFY6*c1tRQk}MGOKmA+tT=BS,T-BlSx;.j]dnob^fXg_P_aaZM^'\z5i5~\q0Ԏ[ǛDX]8m,5՚-[;t\˦ߥ&AW2;7ݤoVXfr"8x-g?vg?%ZTާ32e0s>.7 [}k\ega7s|&bC%7]Ei#'2²%锪γ1p3/mfTpP`WՌkXS`\㿺[ ;P K[xb JA`z'sŠu0%V䩸$o}h)WflaM1%ƶAdPX72`rRؓGp[d^P c'vBA{j weu{ + D+Uii5pi'5^q^!e*׿v%>=[6#%pNm&n Γ{*Yc48|E+@rLnP;m[(dP#JeT( }IV{8Oʫ|{NhQ K~.yWƺed$3o+Ša)Ϗ<įZ"jD&a:'m Mf%_&rl)xLJlZfd-DR DQ|[,-Rc.1HסiaeOB@ I$G+"'j@Tpn[.9ڠ bw6@BHORXD z$EN3  Ȁjaϙ2ĖZ# 5Gމd᳝Dux"Uٳ]8FgHpՎu,\\" V6Z\-J9, cYvVC&myRˊ #每'sd+O-]MIwU7mkZ'.S[j5^) $J2bC=t;9F16W:9 cc{D#L@(Ӗ*\htW7.< "wo`K`i)ys59rٝ0ap AgUxg093TsCGJG@Rr :\(Qv c젱Эm9Dntv9Ms,'#fhv*vHأo[ v.V8B9Фur/JϞ7qkfS+wZW{x^dWxfb2g,9 Y8pdXDV]'й۾9Ƈ/N}dh@ WBgEC6q҇&; .OkmB\ShINj [*FϽ"DH`*i10^dv,@%c‚@]8mN3`&>}qrK8Ct+3K5cM#&[oZgJ9[]; li]լe殫XAGgyppvzT]za7f;sIygB m>hbܸ?@u@'>Mrzv @ϣf>ǿmeeBPVg?B/U d*JqUi.<^Y9<=V1qp8R1R1UtHʻy-+KvdP4r A\CJb$.32|O#W; 45G96WE~s]4mt/^20cu.Z?d`0G(%}0>rKHмىIU OP ?BBlu6}[QAd'_с}E 'AqU繎NJ!AC-ȱc߸['Ncto&2(@ >aVO~~(b6%eren:4|}nWoQ-*R@ ?Z!d&ҨLyK?C]{.9zИp^.>{O7 6Q).lHvWY0$6~>W|_v! 00\D@IS!R+tHal3*gbl:I|-e34p6(b•$lƐP>EH2dȱa7^,-\Q{ _e}$v%:~;:*2`I GsM= 7t?}&7}c4 Lsyl2@RIZ_a)7v(,p;-rw鬫A8>T02 H+F(C X{I̬ ^6L M=["V 5Lu";~g_cvyZipJgQHG[ $Y~ΐDQb}92.2^-v i/Dmce6I _yY*Y% |y^8?aw.éPz(ōSI!P }$'~m&4&0WZ-};5\ߵ-W#C S| dRJEI% !_Hu:1\~֭a8'x{&Wj*W'36Ad})/y” C!*蠠x 4 dɍ^+X8YD)OGpUEpIca_0UȡSAuNdNyQDwdۉHyէՁoF<#qaPd,+WVq-NEglgC(c)+Z;3 t*N A~-9LBͼ21s@n=_YMN5??R/|$@|z9wF;R4@IhK o:r*7p,sT_h#L-w`b箼"&xbZ2үť,)N 5wgԍq{g6zh(^8jdVT? SW'nc]e\bh/"+ R/qǫ1J&2Jv{oֆҢ/SԛJ/ۍپة-5`Zܼ\b5}.*UnKKS hg:u3292!fk:1O=cDK oX oL߻nG!6nsN3"XPڞ0 f]A9` im:@z?|NMkWWGIz]g#)+VU@|Fغ~8A2aVL5{ {D@D ޜO^WuԌxM6A2{;h`ea^Wvՠ|Us[5T~$X!!U[#%?wAQ;>3Jkk6T{:g 7ӆ?W gNky*^M1RșjPiʛqc4{%c|gLrOZ,z$_t٘D:B3uzvV=[}7vzj"K G($eXU Ӛ>xKEp_/R̴au8K~jFP5k++j_{oqcvxi?keI8!⯥mEI3 NTIHaMTDRqCSsVE@!7U⃌ʳ1$LvgZI39DX!-wZSI#f&ZvW`XiC$-AHH)P=e 1>o3Qsn] V.  D嗿`1^bQԋi>B1d Q.*<OojCr'pGbO)k' ˳19ǰ^~6 ' H) D/1h1c~e3a'V@ d5iMG=)`qm"eI)66m/ >~kphs6 Nq [0}=3$=a;L! `xDj <"Ao9H_QɈKM&,:~`h@@yF#m9uޫ}ww,Y|rYA! j()y:8ҝM7~kvx=jň+FYywOCDG<Jb '!/қ2JR#HAhc ?8$L!MYqO8 _ԛǓ$dAF3Im I( K10;ݤHO 6՘;}s,K66lbQs;.]fwiW.PCg6 ܏'+#9=Nfp!Y/RJӦ?d?Kbv}< QKHQ$.Y7U>tIL{U-4Q`8Jz$|/[VJŀ{ vhJW=?EULOт174Ą3yBGD[:6~V7?PzP<|ɿH3*YCA>8?#?6Cara mŴ@ƕLgJLoAЀIt .ro=Ein 0V Z%'6?8J6Y2D Jz>Gr*-7-BAa:Xh#KֲxlOC^uYE-)%I+vu& Sϝ?%z:n!;BV:wxy,>޻͝ߔ^ #i+#/{?JW\?PBm1XzA5ƮKOG^8 K5#0> U-z*BLI@K\ҥ0W*9I_u`1%a~.?Qo+=W64zt~LQ_VObM׈ 1@J7Ab+ bт8T3(̎'ͷA *9[냵'qLo|nlv '=Av Xѻ:)q'!H-.*qY?dWio}S]mhmȫ3o)\{N%|c{M&!`23{H` b4BeCQR \sFa5}ORAÔ (D$% TB`[nʅ97#0L{KQG%J,.J`h45ճg|`# Y͏l|%}[qrpXzzk=巅sq}^hS*P/F:^U~3PeP}}z! -!MSR@U 5ab,hJ)@jO_x,c)O*WM'H&"A {{2R%7OԎ,$6ᯔC5$}wV8k%n؊wҾ!"s7>]n,t"b2Bjr=pO_æpasaw%rzALD Ѭ֭VQ|qugI HisO3 _Pfi=pn,/mP/:s)ĔIDXHA:6o-N&ۻ]9—6,FuoPV:b7P{pB nTC1SRVg O.o: 6?b 9yk"=*Z){0TjSFӢKD73gDđhW1~9pr1EIż{_k"@*/s] YXS/ 6O>`I+}͎s,BqoZ9H&lbz @  1=ĎwOުvf jŋǢcQJi|_} ^g>?Z*콧6loKPm=x%*"t{>UaR>>A21x>.9֫)\3:R>g#򡼴O Fa.S@C *BIMTB;^ p^ q`taS 0@ĄD S a=$L0e3Sd‚a.[{u 9xԄ&9RB%={i/Hh) %g$,q\(4՞w<"s| qt<`HK]xY6vg$?P[P>)4*V ]=5,LtGs&B'@ק)ґY%`@Hg7W?_l_CnݠͰ1:2s)`&T_gƦ̀,ƛ{naQY-к%8"3- }oǾy pKE)!mtK no+u؄ \b*T!޺aqOgI]Ԁe%,Akwuq?k[ފWBm]qҵ(i 6gr!6i#%N_UP]Vb&=a*xI~hzF\q|>cJ–A $P%].R$s>z;;`ތxUmMٴMދ&p!/b¿#T}-d.gt)0/ĝt?؟ƆEX&|q,HIzIvJ+6MSϸM0jpeA1/#ig\:斍=7˞uGn0b 61HG0嵮_v袛!;q~8;9ÁD"ڛP+a=Wл?̻B.h֦UgN)ﴓv|O[ iF 1SM-˜͢cRnTQad}tYIv݉I{31"5Pvp x.nǁ>>.;  <:JGՔȐzA25b Az c M^U¸KE5ջL eCŦ x 8{}D~B݂ȐJKlq^7r̽O*Nb.66qT'>e yCšB:R|bZwzݯS m$zPߑ1Y5-˯xC6+NɒK+`)S5&ʧ3hSj"g>UfKԖ{IO 5mb.ti%JpS6.5ğZk&53-(3i/ 1kZ;Jx6C]P ]"ˑo>x0G މc G6+WPUanJ6BB^҉JgS.;ő_ ׭Ҭw+ _׳MI*ǖ.Nkwe4Tӣ_L٬dVt/lr0ܣDOeOyY,xzax䉰aYX_bf($ė-Z ŪYۼ5YƥI #Ȫ| j$U5N-A(@#UamKUPCYJ\Rl:[7#q (#* 2b*BEZlK\''Z_ftaJ߭W!-/._>-FRM՘XE@FE".lUN%$C~z14&U[~Q?>j)ȃvD1q!N2(io|(ZM#yE&p6aE3~ƛ7mó aܐFG<..Em: ] _lNi@ ha.!㩭UrRA (>GƖ/0̌>ɯO<#ODƣc[+ڞ˩?a ^{6{\ql= mcuެnk>te7ݼ.)JƾHf?xҜQafN[%*[YPUҘqo"ZemH_!VH<]/&^4Oq8cGR50{w_ase: 3y^*&CůLb q}?1O-L6ڢ$Uʲ t!:">A^8,Igt|t̖!& "]A G`gYIQF%U^ G+>yobe( ʤW0|m匁UW*v*!$r^M?{}{6vL+%Yg2:b굦~!GL7[x29l7o) Kҝ#N aOSrT¨`NvnѢٔ72el+xoq?'*VpO'1h01, }m&3P=GN!CS!HMi>yEo~™jk_=+]/,#ϠR1/s24 P]Glno*rJñ%6mJ3l>NꇃfG`tIɔvS`",%@K8.s-D,%Z&Qui&TcinډXLOPRlW.y?SJP4( _u6\Hڠ㒙`[@Vc[Gaş'O~|1 ޷v,ntӖ.Cs2VOYclsQ0BĒHdr S>*^X˧e( ڱTR;ZQ+>oM1Nzt @RED8Oog`*ʘ]^P]q^S1ū/&ޭsEob\m)KII4K^4fdZVs5ѻ[.R'dWcfWc Ԩq_XDXUg5uŚhIUm6I3R0'Y{DlIOSG<7?/3"#Oe͗ZMTG]<_F> ԏ؏R07|T%iUxYQ6QnnhLK`jQ)|K CV= fĩH<:Q3q F#QV 1DIմ ?j 1NQ5rǴ-fLQ(c*sOóq$=wSs0]8|2)KFj<7 4@JL>ZB?{7N xj[E-_Ϫ{PYr lA8ݸ6 ɔ> =CKd m՘VOmQ^O}dcd0.W=fuBH t,\=2Ch(7m Ckc ,~1a#k}viDthbw7ֿܼ7X}F1Hi:d 43Vi09rZ^Upz^Y}5g߮|4Oah=ad!Qb$=SmMk\!>*ܜ!N/ߚ/{OwSHijF%ǘNBOL M en -%yS5fFjt\c K6Yb]6:MGMڴf,$Oe S)v2}BۊaA"yw5֛ɋ~<6enUArPm1 Wݡ%!wn^:DD9ԃIpY? meƲj'U-N PPI>>?~'qɈ}[ ;tҸ?Onqciۥ@+l*~ ?}E3$_m|1fhZDe)/7PC T/_ɧUѶsH2˅KNtwƷNbڋe6€pExe# eav;hM 8ZbP~qpcT#^.:=a_7dL7v83P;D@JMfIPa=(k;}@0癉yI89(%Ζ# :5"!pF` ugwңg'&i!.v02k>V[UE󝚓 ȑ{SVwcLfN7;* o IpȘ2}>婞۩;ilvRR/WO\P&2T59XC R$q^+rI5B%8q=<ǒݩo% YBor04EK0r?fA$aSKE*0KII, oydɭ2q $pueC/+4-޾_mV}^-wFcS/#HCֳy +盘jFh_k:UZ:_zK¤?dBTB,^ڵKR7r <k1fvӁa#  IxB#jȓU;ki?h}rf;|.b PPP1Ȯ8Y@IUV`:& ~|N@5A˘|*g9;W?-W^Ii@`es[~n8Ca5Ǩu~g= S.a4MۘwؓaNf:+A!qXХ*k]y Ebr=`Y, 1;j-Md:);vD*zK?зi9QX^9d_ E 0U`E(6q:zs9^RswZ=A?_˭4uRmXCw^w=O,&D[ {̢HGfRc#Ze1 q>:Wpx1QCA[ZXiGMq?W7aaѻCShCQ/$E1).Ra%=W`id)y͌8ؐݷI3|fp/:)DDPliz>IazyֳsTI czL,+-ZcĞe?S"r=Sd`S&<_îrY!YIcΉwBQO ~ѯ7{˓&s Q/r84ׯ~2o蠰#ev {}2&xьn%* }Jr%&z 'a <k?h,-0F\{Xs6{;zRJ^,A7pG~0jb>XVP):k:^wOFvfFC/Lc@u(?8_ F~k,ahVV̀+J E@z[Ei鮣J yY,ٌď-(VXRL`/( jf{W~bV;XTg]4MV,oh>м&.7`ۨ?G׎ m9Mׂ/θ(rRmlZ9Qx&~&^]\]dqk4iXK  e3WjE ;fKzurlmQr=׾.n!pI'צ;!gzX &d#t_7E^2M , m1 7fsb9 Pcnڲ;| c?'=NV(m̎rIvj0'K ?nAy2h,ҶS**F69 :,Y.mE3f\14iq @zPM ƮYZj%+!P^"[;JC6(ꈪ! Z٭Ձ^ Ot6Pt2j3+akEKwzHud},#[r(*P T&U%q^(О[= tTbl'A=Jn$\X4[a.3$PL@efbPc]i-v0d"6!k 藒ɬu:pAuT6Rj{x> r|]Ž2#B|څ_ ) Ѻ?="U.I5HڄBIRuEw$ѸR b,5X4QS8W@d/`4@ѢGi#Tsѿ COQ\믖,*HzUո:bk;($e$,(y۾>g,j~Z!ɁPuဝĠGe:Ρ.cZ&UBDԪd/쉊i"xRlkb4 P˵PTQ {yan [;pMdE=,™m1[jLܼQ{ݷ }ڔ+@+tLҰyO1 yϿ!` !a)cH!_ac6lFJ\BzLrYbӾC갣"!ה]UlrNeaS*ffEADBOy,PR#>ٻYj[~+_,[7])93Q%.jr@Ɔ|1oL(^-R;ݬ{ݿa3O Mub 1oNXÚH42 p7x<m~WcL_ݽNLc,_TcEBD˪}YS{~z^ПJ 7<C2v1.zgk'[x<e(ePOvײַZ;*g4j=-]FCvEɰIIca_Efh,q@y?MZ\vb:F@XLf H,<+; ZMʾ 1R@ yf㯀щyOqzQ?a&; B}6w]sz~Y벩֥g9nt $>/t"zEYGg}=/-ȶgXJa/ Ox>]ˏw ' =,L%/!vPA@ÞV o\Y#5\)uzŒ'ܲZp# 6jt ՟F3bRby'ݳao\-3QO)?K%{D𢆗wZc}$Xݴ1mkHthv;s,y10?d= M.N,!VwΪO"(Iȑ"skEHcu~52ƹw[B΃1.p7$kc0';fgpiWu5:^Qw/@ Nf>Lv(I0fi?:R&fVk{r2ϨVB@@b^Z 1 2^^1l;,Kb ? bJffr Gqo `$ D0"pb^KsiHa\|MONwv>Yr\<:o?ٔ|W|? zz_Ղ`E>_30U"J%.K# h^e3џa1Za!I\G>o*XӀҪP~883I (\Bw~ӯU9RJ B#U@QYQS}0\h@}iS G %l*)E4zupZUm_2EY I`l"В4xL/fk(K=,XK1d{hVD$y/g/}iMa2e 0`lfiڽ!Ѹ.>+8 RvYB$J/IBM֫pRY6g=J}'܉cb[tD?&`Mq+(PL)lUTBU 1%_c֝1xޔ'<*gXV1U<fneEȐ@D)=be=Ss.aȅaJ@Y)*s 34iu|jw !y@><tkjY62GO' ) ՞u8 QqſY)?p:;fXb?C $8 x7-ui=(:ne~yţ<K0A^m~/k,y鿒 D\(Tg jm_f2K5AzC D^V3NV-N YL9.[)SHJBBJܝp&!Yڞe ;~<7?Dٔq:E4 ZlTy ve@`y70r'6c3*\Xq8K9s'`snUfݾW.YEGWz;L>tλ,˂:J*28÷gt/K \ 7ǿ8&'AVnmlĩ.[gAQzuF_-urh#Ic&I`Zn 9GG;)bfyŝ(<&n[S%C"zumVZܛR1 $ADdkeD1o~QsyxÐ%bYT ߝΨwQɂ w=;vp'eD^RA!AdAd>>W+;|Ԍ~۾4@ | 0Aɨ%Z'F5ʰjka mDqQ ZJҒ5Q X/J>ja$pMsa4l/ (r k*Q@=`/tVBĆ+>֬eV ϭP( 1)o|\)J)1ҖwwyP̝ug~:s3lNu [ޝ}S{2cNhn9`b *jNe$%$^~ "Mׁ%jEÝ%zsGf na,qf/'Kb+őNӹj(#xY `kZk~%z4b!z΅qh]=NmtX,3ϛXʀQ ^`nЦE7΃ d8u %ύLQBqU7X}>TFӛlC"T D\B")7^!wdA@L.=Tx,VG['lp)RH,fX#0/9QTqҳb@>qǀLϝoCՇ-}M$ANOK{#tsRtF;&փu%eĜR.b p͂GWf=E@8c5PI'x Ȯ\ZȢ nw s. /0hQ;3(0SJ'XF-R8޺9JYzxTO@{}RV/ZZ,%%Źf O?wU5+1OSil3@?'J;[UKP|^,}wUnK,zNPdJ 7)?$?%`%uƚy1 -q;p`]brzkzG}gaM'&Z3u"{ $~Z$k~mx?n9o#A&C3$\~US,Xq`r^-]Otٮ/ΛoSek]:o"yh 1і@HѬ]cu/+fǔfrI.NP$./MXhC;qȵ)=!3{h_qޟ%e'B5{pVWGǻ{6;>lH Hd]Mɳ`.pob=ȎԻ$0 ? 1XP06#4$#4/_E:!B  Xc}GuS{OHD$]6wƢI Ǖ+3$_B1 a5]5﷟{6SrBlDDDb;4J|. 9FJ:%"ICf N/`˺8i3ȧUl- m/O(hKRd!JDM8xh Y*9mpTAҬOND8jˁb8{nr%Y9* ?.Wέ`%ztn*}'R`\7e N#!Әy3hJqLϢ]dl?EsFԔUSF ok%%ѻi 0'sn%l`#b]loNrE^;}M筌[剁D%aahs0 TxKMcۏ,}B@2?u0=6_+CqJK; ЎMٻr͘LWAb`7*eezk".i$Fto;򐁽.9FLkQao *NB1Z|S~[Q-XU'H,Q3FK N(rL=I3zd/ֽ3q9@GQɈKtUzWxI0Bp?#PĺӬ2=Z +|0|4`GKC8z\w۶y2eX-#x$7 =m)M(oeh'ʏS2?H=5_\򄭅 ?L5kjŧ=6:R.&ub)Zh/.@Mrc+d 3so;k x)OfBh([H 蝅k*;xy,,r>j%lvV\ɋ){Jƣ6R2(ynwKov)_xM=OXhO+zlϧvvM_kV`:0ߧ])kQG6|nd7Z=&^ ]+7- INSr= rrR<8n 9:Q=Ү{E#؍ƣ{X?jՑc/lΑ%qLWVO¢4k=o+]rvWF\0+rQ^ tYw6ΔݯMwt{4p6о{Ŧލgu8 X! H {@087Jg1-ͼ͸?C$#r1JFtLuj'nF2ss89/gi45tBҜHHaV. w;aSkšcTCNLe2-iM>mJtn@SG:D2c莢ju&U.B*~njIѷj<䩦>&fQa.Gd'Fz ƫKRå ȷ'ǖڈy, 3@N~9"Yg=K :F]PD'ƆgRГ(eHޙ=ȶ4j*mIc7k+T $jky6)Ж & $$0YY myw{Cʣ!_|}(|d*Кb(b0D( u=$ӚbwΈQ\s6|j~]Y_cx)r߿_I!n?A8;erU+eu݅K%hbfk^jN2N54Fe~n= ꦛǕ.ȉswu}kg \tMz5xc!02lɣZ@*(((@jĺZ0K{mcI[úZzOe.\G2{"]B7{ ֘̚Y"E?">+P3h$܋8"E-$7ԟx2);%ITa%dx P6tU{D7F_U,|rs1z4*ewEBQ+k`1BqM6~X:@jC7LE E)3@k1iM%YyGrZa6w2 kn*uIE7H3֚y">DX߾(X.aNyp oiQ[r$h|?4 0 fr8xb%yNdqڒyg^OHP sD5(%N\T7cHdZe騸`;TR%L[ C_,ŵ1fRŁrg"MQJA}E0)yNl}67akjŭ,$,VTzȵ/ n =;6=Q GyW4,;S0;OlȔVl)jlj3mYfJL/9s{߿3ó" ףrKtP9n]}>zK1%z%ɳrjQh9l&s5Kfw~Ws$ ɇ<ϯU^5!I$-\=H͔#x@] T0Pi7*RdReGA, '4Â|!i/c+$$3|V+N/h+'<~J RwC9-{LIu&>a .3<@⢈T"!P $B^'G=:{r$/8Nan$ӧ95jpts+ Y!try0)A$ N{lE0-Ci;]N|^?.Ob4 ~G0`xofg%ypN-NG'ODҳ[M}55v\{{;Xo힭r1}Y{+ 2 Ch.RŚf^`xnx%E9>և#uPg }4c_ҊNz /NFBU@6Eke8LLU{h=*Q\N"J881!Km4߸~w_6zçcdOn`󜀹50|Vy4xOzSw'$8_"CR@@ ]D0ٮ^ӔCYݓ%uZߝj#ؼ?N"ƪocG7@2!l$B4g&QʠF  1fi}9SдJ)?#EMJ|ѽ8c*J"L^s8Stj]L cyY8` a= "fClK4'9@Hb]I*%K()C=Љֲ#n`(9X&Ў GmUt7U˙/7w㩻*\J1U7& tozyݏGO9pِ}0 kekE`)%I v~:1Կxl|ZsxVѡbJ(twy TMM4r?@9-dKX48X -%הrL1 t!^kz`xr'RU%D"(JH azJI:F,xC4>{wpnUl7#_@Doe[72r'fT cƪiH3˧W\t;RLmل!7mj9Eh=Zx԰ ?"?dړ1d6+t2oYxN!"a-T.￷ޮpBҥ2@>ύGxP˹țeĹlfc 2 i .k̛t1Jn2"H8`C ܖT\珜! G)N7Z|u%++R'e%l!\Ӳ[y @2{|YB6?P%;D_SM;*S1W\1d<. (H7j)4(*Sf=a5}_K1؎H2솠8Xh?M=M.(z|0W*b2k뜱Qj]Gj9AӒ7Jlt%2W2wDQa#\tCwU8N \ n.ڶu q(C]!E^E]Jڿn[L#E}o^o݃? u@!T#W>#DMsGDF,~ '̈́r+_s z1B&0/oAх Rb$DV0B鸁tՊ2:ʥ] (h]\`oSZ%*&2}%RSŬ)a wIxMVg}) 8pa_*5">iv*Ja[яy{uOac WTPSC۱`wV4$ͯ0Ϭh1PGl1!zatl96 f~>r! 7LB@]N>i?':>ݯt34)UըFXnU6^aZeIwEq{x)SLHlmlsfg7rݪj4ٺV$ #Hhҝx8U^j'` V/@)婋drKS :s^H(fl*M6*(ʼnt_HmʚdQ A$vm\ k1:DF'&-yS#`lJ`,(㥥yaPjX)1f$Fz|FP)I/WcjSbzƝS!ylvf5O&&4 jz|8*lyYl/f'wa]IGBv.ZRĉ) 2@сbV̇V/%zZut~'Gyoʹ;wu.!Z5xz͸=y٪5ȂA O^x&h PddD$ !@EDՔF -L/"DE¦q敏\F Բs%Åˉ _"JӑlxqvheBQ8|}*/R61荸_=t-WDJecܿ&4-NŌa-Ұ7 2N=n5Y$>6T] ? w]wR&G 5r!?wf_QBb{+|C=}=F7;%~/|o~Oa=FfNV1O7`,qD`r3vj˻/>nפ>𹾇 l_ {>FPn>zy]f5hRAo3UCvscj+0;迟UZp*yȎo3q380'Ҹ>\F~V kϼWo~w[p-n ՅLmT _3z(lrūϿ@x~P:""IqYpv=]toa^8e2 @$d W)>IFrromZ~ks} ET6K!b2-1DzܢsJ Yc;O߾t Z!P1+#M<_;o0bc v!Tk RJhv3JϨ<՝ 6ZC]_"Q[=' }F<a7<ā}eZQ~ kTԚƜ68J*}t&gz ݠuaQJi9^c2$)'Ïag4fLCw*V0TE6,]%hrAp.R9K:4 _ag\O,@q5R\G07Ɨ`שfL?|^}JGosM=4o (D OIuj\YMjb`G3p+B N'A+,5gX P($vkYȬci4,gmWu@Ma/drLceXC)d U)MȌyYSsyPu^ⲵ<# g_ P-Jܹ20ƽeRSkD%f mA2qL/S"Bm6!=x=cP0z2r@ c /4*\ePYC #2`Jܒ0 JK^gΐ)QpMWL8~Ob҉=*!hʼ1jXMƴ,|6y,(Ww&^8 $@#[YS=]Ou?? C&VŊ4iA e*~:63> 1itJ(18[<+]MN~HN1RHaG\' ȯz"cFs;EZ~欖 K G|eĺ@ſ ehI!*Yd?9y`;N2 N"$RZe*P4ߛӢ'd=iݼKΐDkϒ8&DcuceM]DHWPa @iPI)e '4?:q@ YP4(B;jE BP_p; 9E}PZb:*Mh*Da"NQ, \Q^K ,gΪeSeaP7FND7VO.;Z]8ؐwyoFJwV6U=Lm&SO+9%jxI+SX||dYIId0wA J3Bzh^xKth6Uh5N 6QxЍcģAu@]j%}GOutWG(Ӧ:3Y$bԏL_: ^7L|Ug0Fˑ~4c[6p [E&oxp2)E&Dvd3yd}%K]z\KcV!;y {;ר 1:]wsoPLH-wp,lޒχ˓e޼@dH $X/T ~L[ { -NxvEFJyOǡ ͫ QQ87J< 눀7]VZ,sIWڢ%g&˾A)J*Rc%p[m'栢β$y5<cKQ#l5:3 22pY7'DAr1ncx :N* -v o"]"tWӚ) ~ψP>Շ (Ya3b؂"Gzn?1#G(ŧ*˔$yWPHlO-3)m[P],V!cqB B2eS[XAFȇ2uSb_Apy@z;gO826K"!䗘g5݉d543cxn7ȓs?}(.A9VCa.7&@ڰlFOIMf$&a<1^󌅄sWjGΜ˲24s[OéVzA};u{yӡry2&w '#"?&~> y&׍  ڂ#T |hMʃXO34 \R' *=#0rH D!&"o97́~DOd`݉Ѭrgf7(VO!]PS]MUH&ܦSrNy)^sp=؝M;ǎ^JPYV# ,ȝ\)4֔*Z۽Ou*5_ .%ݹ9==n|)ڬt3xN&ǎP;ff5c8'|ekus{#.ޙG#~{Ѥq) Psl ZHE#\ 1 C"mB.KIF6>“Ñ=VqWU|xytbSbS 瓨4-YF8tDPNK cz} FI*d*pvrjo?u/85>YiO^gPf/ڸPNA1MFACo3ϊ:BT{H2Aގ57xJ(cT+|&Vꠊ`P?ZdA5AAs񁃫];]Ioc7q_-4#"]DE zkb~y܊Te"Ij\$RW$6ȭς}I= WR}*?N-ܥTul E,g>JTwQ84 4tlu*V tSM+ (Ʋ5i绵nMF䭐=Ʀ@(D@@1. % lq-Iu X$W4LtY?jV>\5P[swgM畵K>}eh'H<a%#W[,+UXm/tAx$b  md uuo<>Īp^K9 sCk($4_\rkꞣ7 vA9>IبcܒU`v2>|6?E#Jn[`UtF`g;X_z0;$7Wv8+!SÝbwhMetOVYE.wKRRd)n_3dz魔]gN<%Upy×Rr\ ^ֹ_6MYι55J,e?lcd)M#' eA XHSEi_{z$d9~ jF hݹq|(twɃ[cTĈ.TjTH,-+қCz3UÕal\6F8Kٛk-jͨOȻI,|5!a)S5KUύ>e_%: ,D 7<V 3ASCE\_(< :Qs`Si=d׽! ޡ}|簋%:"RDw3v)X4Q,JAZ8@TMмihNaĒ!OB%=O-9\ qua+l?ܭ4{sscc 9u!nR[H^vo1oA~#1S_XJQ :8`I?yICkOQ{[껃*m [\ΎIl չL.WJ[?kFϕN}~="b'K! 0CAO#n#];)pIiTLX7f”0-]c1PqQA*!o"H$}2)3Q6c9q}LjAଖ!]Hm,. N[ n^I^$Hku*;VfUWw|OoHbQ7%dk3pH40,.^0~#Sᚈ HhI זA @=k^8i*T}v#Vji;<1K?(Z@E=+@7#d> 3AfG};N νF̽1͆WqAh3Ffbs9G` ΖN(.. 1b 8lk.;4(m+2ÒZO])sYG/ЀAif;ջ:`朌Rix̝TðH<$w.rq IǘQ$#'S&J  wQZsVX͋4EO=hvTz󙩦 YaE .hdTqU ߕ<_{L\T\_2K갡\Vfp9$,EC|? JNbѶu<\[xmNxĞLsDBOD>cr ؗnDij\^k,]T݊K迥{'zMjI: k0 ?p O\I$s hТ0bƂc }v~]EvBm "RF#MEt:W_%t㭂G,>U•7f.e#3xZbKM H{@?03 $z1]J/19 SO&YN#Svq)?b}{ }te;4WI0UnSK%>pb)W!vrAXSB}M \;{E,ϾnD/ԫ~|?|!gܛڽ|':Xw.uGM,+v?]Ř]]C #w@y+O.!gK+Ǟ6_ߣkWS}0y7NRqy9- t^f*ҍdl͒nH\QVJd%/"]$Qv4-Qaa6v`D2tݲ8AudexiK)r]Xy4nmd @huo{ݮ@%XC|nt~ ;-IH|(D@-4NAED=*MUaf,Il*$ &!: "GjM r8]肉큆,Uua#WmuU_t onv&/`A ci! .Fg22gpĊ:2X M V!SOA !gɊ0|FA 씞ȾYbB 9Hn.PrdʘYLlϴ ەjLV!*tpg]=Oۓ^ho(@K'$miMWXQys>hwn+;:Ɲ&lj9%d.'#Og|%t$3 )kgǧ3]EǚR1Q!xRAOzp Uk{7KVwdO.qYzwĶ GI7_`uqG- E Cی@h?OGso z򽆒ud͉B-MtjL@2fdo+Gy3ءQT-}U21YVH{'nռӗumnk?= %PkY rdzp|obPe1K adtH c~kj%{m+I)\m$]%ŮAF-T|%yS^ b &z\H+-EA,Vp(XѧB(@ɷHAnP L{"B G\[V&^L &HoSJ ۖ@AX2Y$I V cJ=$˕f/e=gt aY )"*. 6߿#Ds::s^ƌp_Z]kӗglC9N&E9&STz0L)$2G8O'\@vbTYVD@mܘ*qD؆ KCb]IB"MT۱ W4 ՘tv֥{8dJ'ϨIBƱڜZ[uaײ5;%; ޟ.wr.X?z]#]bR@p$?!`Utڑb"~It<C0d 7yQ{  )Xɾřp%lΡf|fjf⯾֍+*x[um4~%He7 :6Ӯd I)"ˋ#kS?wõ*۝(ӽԃi?*ŠRXx$&@H ָc%{:jjX;_Ŷa`SՁUXDQ#N[*`#k18bsAEI8<0T:B.4kgOBIάOm1BVgUg%GSr4Z1il cHʹ^kh&amx4B(,hLF>IH;Uy.\lrǣ9=+)f06]*RRߍ7rk4OKbtBIJGOg/YB5>Jllݛj I9M`>U]8 @Ϝ@&Oǣu-BM]d5kVO%";!RczF~ +|,]O+",!LXGQ=mn>ک[䥗o,ӋIE6]"B(00S( R'\  b$$%1 P9[&;lO~ӓrH7hY6$Gh=.)`*oGX8K7;Iځ="mx@@wn~X u EUcL0ΝS:],Svh-n1ץtiHQPm3*ZUWȨ᭢y+P*SaqpstR.sa_H}_9L}ynRni+YVEgd~L :bIQe@!o^^lflD \ݾCŒb)aS?a 86q=X!鳸;}x($z&C+=O2ޛWRa$ǎBKRMTuWk1F^}gz<5L}hV ſ)+_>jű*]U!ȯ5 r3?Fד(+i-*k1& d+{29 !w,(УzrKdT%t+1+!{H =. \-E)kPvlkt2a51ဴ@Q߷~($loV,:mHSX|{6 <e|ڸؐ+`(Rϳ`SU"%:;iRB"*S \ul7r~dehIQj(Ntm-\=-mҦB8Ɣq̧.n0Sk zSuiqՔtS%EHޕө>4~tSwGj5mF bk[6}ќKMrwɜo[w=)0Uw~0QZ9S)vzt/$e1q#0g/>b: OaiDYqշ$hRr)U0=Bи4ƒϛwge)߹zJf>mFOoxk;813,PPȀl )D^pqg9E[cOgHfXGˉGV^Nڽw=NϪLI_4pcPO;`RŎJ&r<б?jnT"R}$a u0\ NЃ Ђqo#SDXҶ2IQ"AKK+֝U5dCZe jGrؖ~ Xt8=:\>Qq٦r~%?6}#ү}hU)v$v;$p0yMb RqD"6@ $5q19o[daM'&o\)8$3ʴ<9Kt1+~zRv8x;^* s3䗔,Wl){Ʌ ^ $q}3, }}y޺[goń@ s[[kG_f2f6r>MSxgX#4l+ 3m#b*rRx, %c:ٞDMb93ޔ/i(*\ZH] %;EDBM0aO7 g'gWHLдo 79`Y8W; O설TZ:K߹Ҍ]5E`.i W5E}>w>EW#ķNQbL5Rz -4)X|_Bz=^Z\_$Ǭ9V_?y諘 BPDEJf[YE½1S?o p&ୌmUOys/be3ԩ.߸߇ˏ* r8Ab j^ oo716SvDugU}rQ,eZk;<ϲe=kܕ"YSN͹r&Rt9NжM4ysMx7cl)߽Ȩ6sYU Kvf?woSTio2w骷W(m[Ĺ<1VQ_Y TƢK w *S[~\&'z>=VY 7\r&vڎU8rfj5CG^6lc%\AOcG;\s~~P%(^ҫG[N :;q~" PǑKܻҖ]Y!++;0}v9Spyq%QȘÀ:$@}ݫ &@gyS-{< D#.(dIj U^{Q٘ѺPd\&'aa2Ǯh)&d0vx xQrwXu`N"j)5W7UZ?x1,bԸp#9#CORKU:ufYR=sZQybc^BgO7hiZr.;SDZ`(\!zGiL׫.qIrHC#VcD$YsqX)ٽ\ 8!a}hOSbU"KX{ DK<9(a$0^ `@ҖQvuӄJloH6Ovv̦ LnMqtUWNoT=.6)Srw N袊GRAlFc 辒_O(.2eZ#s78QNz?yuNFgRu@ؐ_Iz#Evh;e#A&g%6bյ/0?<eH̶vٔU^&}tښq(|X":m. Db?:GpӲ CIC0rӢ4@%k\GTxY Njz[o_iQaMf~$HҪ߉G֧ ^[2#$--XXi6gc@ݼ هd<, ~at6/Ҿn0Fp-=l]zkW?x&=(GσJ, '/Ds) :YRf/M:΍ h;dvMƢӲ96iUcJ8"k!`6 :=/ȑ'&~` 7itBSBO:h`- &E%I80X֎ f$b\y/ { l#aN}Oێ^&Zkh+&^MGmͬկV[{;>>s=&kw؁~"U0%0lI0"hFWW5߻; W;ͷ8Cڱ"MI aH_%9g"!оk}Oݒ8֛3 &URV}?Y~3n>j-q)\;q%_,(z+ŠepĠ }s{CZ{*ֳs犄o#~Z{߷X-Pj4|}xv {& f%/AIbg%ʓvS'c<υgؗճd8%(k@yClQc ߩ4_͙; fceܦ9į{?}_6_b|/ˊ$uAgcK4 D]B=~1OcY.Ӛ7</)Puuw#VMg?SNJbȄxIL ctp,_{!_a]R,))'No6{q`Hʻ!#/E6Kn[^ufM|BAe C(TZAٳ)Ul(iZ Cd0ϋeΐ[JYh$5E[ƥUw lX1+e(kcG|@@DpЯݜY7=/M_>D @ὔ>rղZZvSM#ti[t9JHMモm. BxeK9n3l֜F %P~fe:M |-L(Ym3jN~(v}^>Oiu.n75K^>V#M5AGkEi߁da;wK#o>Վ!Kb>.\t+= F Ob{ K-TD>Juܖ,)W=5Е 1=?Fw+M:LtoOc+?4`l3,gz_,n2n4r@BG @jH]~t=\Qmt";60B`܀cdUDh1𭢱oU^lm; =x9Ka7p/D~qN? +#-6'> `i:Q'+ 0te#+Y]miui~~[}_mA?H u>ibV+#Mv\Jlᴔ=o 6Y\r%0<!s?bS07%l{[<~8[mX[0K „@HX(y^zaaa{-S9& b$.*׈s.XH 46^_ T2^2_>gBSwU8O%]7=WxO]:<[zo~ 6>޳#%EC0V|{]/ lw {]i޲T X؅i N#/\4]]B?wG = 59f{9 u.a3.0sDֳ76X7&ya} ^7z}8]v*[XM,{awA}+~֯]G{ L$ěȼNSjԉy5t: c>'ɛϽ/S.V#}JH:R̤4HJ$ -=Oװda//1jQeW7Ap2?sNWrӊUh#6~SH.S0f^)7ro4OVp\{7#㷰4Psm\"~|$|ֿ3ƻu]6M7/٧NRs~uC þcabszzvmh[pB(DcW ,hV~S?I8`zmɩg￸ © ̌1v m2%uK ifu,&,ğ2bMl5a>2с 2!HBWDܲCs28 lBBzOD'ذq3k& Ba$G ^jU$7:߹7wޏ?T4胯#õt:V5=ǜ;ۡ_DgUa(_yyxur6&`9~'>/_GІđܴ oK3%bZ+㧃x `-b EZܝAL'2 Bv#E=gR(x'LI]D 8`'Lvk^)U{յeF?31}sYȻL4SeKl-UnYkf7U49Y.< 0M_닳YmWϷ#MKzY*'ygOM4ەstSls>ĕy5WKorb2w[9m37WwnUd?zӹuw'mhοܲH=RB4yεe=vS8A[=Czs `^vZp^ۤuͽ$q/?ϗy]ڸokx`=p:@$6~*B`}Un] һgX|[dZ`*ø?jrck%Ҁ7oIB<&L0(TA"OBK0D듳kN'  !dgo[*Q Kmj"1|ʹ{;ž3=UaڸWWo=ϭļ*'kOYcr}|>[)w{'w/Z^ydwLlF?f;cx\cw ޺[i uGN/|KM%. ѝ&+8QCK3G2\$ۺqs)#JϩWdzڻzv!~ Yc>1Yv?s!Nta0,by lOosXOw˕>ATL FCC&QʕQ?Տp?@ CG`Sج?č#87HC+ *c' Z/ߙC lK㞔BN@=xȈb0#r2 2e{/苷+W`47X~wqqXv%QOhҏqs̅Fug9.v y?fڼ 1겙#辭1g;KnLW}gQ{_7~ap~O{L3z5;>&z_wu~LB<*%kQ(ho rgoտm(|ָ,OL۰Mz߳xMN7q2j*lO%x Xh ˆAf<$0 IY'^qN ~n+#ӵ mTPh2gYe>ZA{}$wo7[#uT{*[~bqd 9iݼ|J p r"DF*bC bE o bJ˺|A.0Nd8*pѿm|t:\c!t_2IrdZ 抩6>/C>ڼC7³~_ܥ{:Akʍ3D `T#)@D9]/e\;|eۀV ½Y7¶%4cJ@Fr+ɟq?qxyu$v~2Go?$/q f׉.oy=I|SiLԿ;z3sYޑ_1޾oP᧷R?vKXX 'T1)^:,D$}ޫ= ۯ]އ_ ?@?M6gq%i8b# Y3<KAs0zٟqm?>62w-7m+?3]s;]'q2z_=P3CsVI'k;Onploj\ǩsKzX #z 7źT/ڳ8:?vG}6i>=o=⏝aprDPSlUЧ_ 벨EQE~墀>NPMK_5O0zU{X"JJvDQZ1AR(UQ?QD4Zu"T i:9EskǼSV < n +L<" QB\ȋP_ayI6DYKJ/3NT;*eL%RϺ i'3/h;/~^2H{23B_Z :6wY @v?e"x&/G 4J ߵ[t}xW: 8mFc]C'mC?d>7_ z^B㹸%_ZǨe޳xqO~I;n&~/,)_+DfVb:' º?YQp0OߣEzbHZ<q >iUQ@}0cg)K:MOEAQ/iccnw^i?Ly MmoI)?6K>vnˁ:^'mmi$ I>}'H{JRbёO񔗏(<.1Yض0vb% -R4jSt#u XyT ~;NSS*ĕ9]/0)w'~)GVe7x`x# 6sY9l,| i}S]jRg7kk童P]mS].~ߞ<КYN-+`}Llt?{v op?q\ÓCPϸrfԏ̽'!X?/KZ)QRabXZ|URYEc&Ģ}t~;P1ۍ[D:8p9\xdJ쎩(64~g9?e=umvtނ]j}T%CQŪ!cgyb3ct\%ya113^arc=+4AZh -cj&OcdR- on'Ftm3t) a"784v_xu{rv:]QD%u @BXN@wcqf b/?`fm`Xa۸ fw^ κڠ.om*BbǤc,/, ܼ؍/,Qɢ@k,ޟMgkVB?F :Ʈ9mڶ*(TJ.9l܅sZ`l$w#Q3f~`wH!H'{{͟caj>OTLU{`T, fh4qpI׹1`XCǘP A6`nU@- G+;ZXJλV!ĉ#aU  qན%ܰ*Tߨz `o~ # @>8l>@ |ǝh+}Pc[j L3 hPAi*,:#Dx8~UwwA. c¿fP崕 A "D4@Xc~^}}׻ЪL)_;k}rKŭ/>EɤG?Q=W[VuuuotwmW>q/R(y=,jM|oR.ō3'kGOwXELUB79|Cmߘi!T&{?{$E:7f0^«='f2 vT>#وE|s׳~yx3>ɹ,wAsɳٲG-[m$ŗc))tkH>my9 -gKsK]?o 2B@ {8Lko&ǁ> cߐdM|@k~ e Hy!S\z S@\Sf~G7XЋ };A!0=Pn%&Ț +_AP7!2I5T?z '`zM%m A 7i굧*U+?pϖ{ö=MqjvɆo@Z* *Ա$ 'J8d`TPMP"ua dECD3PVXEC,m"ȡȢ0*bF,嵒)0ʈb"PmHr|EDѪo ~mdũ2MBa RE #e0TBaR IRa5s&zf)&6ha ɵ0na4 igѓDe?gT܄ؒnQ, q^$PZ }SNl$T†W+0`3-M{>] ޯLigSm,_OKT:&])1 P<5m퇃 :U7l,Y%6x'˦ivnja,PXEUF HdDR UEH"g_n>R  @H<];^+&S}-?{}uŋ!D77qe[Ew9@F F=4DM^/|΃jܴF8ӏ4Rgџ$tT3S8#~sv^8ĥE)ylÿH2ae6o- $IR[&jDeǣ.vftfkeꭈ0M&r7Oc: ЯŹ6~<.&; +!VPY}ozp@`C/0|,׾0HQBZTxLk^1NBHt4jCu3D =1" #kHRbv/LGS~N~,i1øNj'B#<[lje 8|G1L!v*C,Vyd 4s>S:?e _Cj  - LG[! Ňj-s/ nӧwý dRG7iqYc$Yx0>yUA5֧2/4H9;/? \J DrUBY+YoڔyD/I0{!TxHQVR@ M}7kocyb>_g8}Y6ѵs nbV~;Gهroo_] $Y[} B4X!(?#IIAZ@"DN6~׏;\i <c[ M*тͪgU!R2p 11XaJJTwNzR2o}o$j(s A~T9(M}<_yMjj"`FX<(yߥHW8AA :(aETN{ǓܽUXōfo[EvmZH'cwg X˕_F-a~^BLјvXLx|QzexF4)}IY8AZ~ѷH iy /JGt[H˝ݢX1*Ϗr«#rwo~u dCkB1~$y|%{RxgL`;Sd}RAYh e5 ">4C ýn-cDƗ(8R M,S g4(S,1kh,n cاм, V Ȱ62G.1"FqMu˭n*fኳقcD^$Ŀe+ev*%&朹)L$EئWt+WLʥN8xRN*$iɉ$ӓեP%k+q0MrAL`2bт)dFa (%\RXСA\ȖjX f"bō[m-JR1bh-,@B24JdZZ"(nEHv:5aE""B6ŬG(VdhbUfTb* TֹGL24m iBspTj.l.*;PlMhZ(Pr8ЮnTz:1fc""*sUhR)f0gG0e!a&,J"!(UUHVfdUFU=2顄iGXcY4. eG6md0(d F*KP\`͸JfXE !DBfS -Vb-0Զ"[B%sa E-( aVBX* W SGZ** QpJV(X̡YJ+Vl*ָIQd)UAS TA& 2Ҥ VdFq`L j[@X H2-ҢZ"ݘa*E+UBF8BJIYU 8Pabh+s~~\J.+eV-i>D9%]O^T#x L_Q3xrP&IZn3}K~~YB <|t: \;c "v:Ј>-Lΰ?ؐRx!?d{hara*{+@?aD?!jt5Ԟm!!56d@XBMD|5