samba-client-libs-4.17.12+git.455.b299ac1e60-150500.3.20.1<>,$e p9|F/;1"u>ֺE8* Xٙ6tZ["GZQu^l LuD} h$O3." !Z7FSDO!oSEZώ^QCP V`iyXkkcfЏ1mo27MO_9ПXr-A(w(wu; *B* >R {?w;tk״)z9zu >vJm=H1+&D>C?d/ = T 9PV`u4u u u u u !u#u%u((Lu* _xcZ(w89:>@B"F[GtuHHuIuXYZ[ \"`u]$4u^.^b.c/;d/e/f/l/u/uv1cwi uxjuyl z<LPVCsamba-client-libs4.17.12+git.455.b299ac1e60150500.3.20.1Samba client librariesThe samba-libs package contains the libraries needed by samba client programs.e h02-armsrv3y@SUSE Linux Enterprise 15SUSE LLC GPL-3.0-or-laterhttps://www.suse.com/Development/Libraries/C and C++https://www.samba.org/linuxaarch64 :y 0  8(  px &h8 !x` @ `Aeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeec0621b02e4b1e67cc67ce21df1c9113ac3c05131eb2535c0e8562058904a4235dc8159b722728fc04ff41b6c9474edccf5ee7a834eded36e6dfdfdfa2c0738a1f78053c4974bdad2afa3b6dac675ef18426b36cd05dd7355cb275801f79d3ac0641ce757c8af8d3e9ad8222ea7daf46cb20be3ecd18c2d59386675127885e9e715bf2e2058bc415d770f9bf69fc886cda06b2c8c61c53fb5c7c972e265c677d80b72bd3d90c9d62d3d5ab1a57908c6367f464686747cf943465d983efa6d2f4712065defecb12376fd91d14708951aa12f4d16e879c61cc74d92fc6800280cf871c85fd8b3e7ac4968a66864e3cda9608cea6e5e0dc2b90d526aea23fba846444ba2a7a9c967ee1971dd5de6a92d20007f5c7fc6c24f8ccd192a0d7df186904de068cf8a924bc5425ec3159706aeeffea2eefe6e3128776df0f267d89dcd4af0577c9fa70daab50a43155d617b25fb8cde02b1d0758e853d9c3285586e7eef976f4f50ee042b6f09427912bdc92e86267b9b7f3d15f4a443b4393c97036eb6934bc03f00f3ee8d8102f8ad6920262bc101adc0ab60f8252c2d4b755b32b22cfe174fe2f16b83659299e3bf8d0a2ade0695dff004fcc73f0a7f955d0f950aa3061d408205d3f366875a64f87c8bdd03abcee761d06d925a2425d66c1ae8a1ac4c4485d3d40387c86c2e79f0d28304a45358d2a878d19f19a47071e8163d78c253888ae352ecb40f428a6b442b35c34e5df12ae7e9ae649c30e67a1f87a3ee7520e9e677df88320c35ecf3e47f56eeb8767f61d0eb267efaffeca6912446ad8591438b7fb91cd8af4b26e1530fc0439f7a54c0bbec5d32d0a0eefc8eeb18f858bb81b33822f5c5ef70e0f297bf20ac7fee9fa21134fb90a8c45ee8069945a88c7c2b8c61a7f34933440638dff3ee12343512fcad09be3391f7959ad7c249800861ba7bf75791983103a0d0a87b96f535296b67c07602d743dc1742d9e1442066325727301f52b3c88704ab69449aabede4fae9ec3e729516a10df30d7eb70ba5e3f986a6e5affda11c7cc5081169a648449759a847c1325f162b247f4c49238a83ee86dda2d5824d823866dee280fbe403f27fedd1e93626d44cc64c9b7c02cde7d6b2a20cc17e95f9b874b07d69ab1f46cead1d094086b21e82c6cc1cd9d63b7223c0489353bce7b3c7b1c700a282ef7eab56f966c252ddc3cb4fe5a1ed677d32e206ad9d455866d0615ac84d810ece4d61e1dde0950f4717356846d5d85754d7ed87ec76c8a407277e149b931e264754927f123e2266e1a89825f5a766d99480b9d51a1afc83ae976e6a310130b5f6c9da9ddf35f94dbd6b6bbbb3f3daf2ac1df777938eea086bab5fcebd7c37de0ecc2da6bd98f7d25b64d014fa75c855913c40a78ad9da0746d04b7a3f90edc76edccdc10ed69bcdc9727d8316aeaa73319504c2ffc0b5bff02dd165c27b904de7ac18ec3394426dbb5b2cc053c0f8b0d162e32686e3f48161af3f7c885717e55743bd033c2b369a8689e56b187cc8151320b816751a6630954408b3658c8d3c9fad7f22c06694ce729338cdaffea5bdb97a06812fd7291c3f96602dae2c2c0d446a11a69717ea2f63e216fc22f511c9f210bd81aa1012f418df1b8f4d3bc697d680e93044e4dacc5f4042e721323419e51adbd74101fa55251912a9f8d9edac642e891abf7b24fcb736841268452544086b24dd1d5cdb5b9a583dd09818a90bda4c384fa85421e8ec7a74da70763ae940615b82c3cfb13d1445520a2165e7b875eadb0e25b2be380d476aaa825787e28d4e8af85e1859fbc8554a6b1f65fbfb699650ab8180dae52191acc4b776f6afd053badd818bd6b5194bf61a40123e8c30a31fd90148ac6913a67e62aadce529a853d9130725d29e6764d63302a89bee2f1f821de57e2981755b7d0d8b21345878a0bdcb8ee59bfc8ad7d36c919cafec13f65dc2327800c0f0e5a408a1b99eece21bcfd193689ccb769fb71e24b149c512c307e5289216585ec3ac0e898f1c92a7aae033c97406596daebf8cf9ecb15a58a4c28e06fd3935a77657649a4207c0181bf3d90bd563cd85796b9fabda298a2002ac9e02290da5df32ba0c894115ea258f85dfd8439927e698b307fb8bd1d51105825f09aeb2fdc40cb5f8d919355cf55764025f9cbce6cd91352d64091b2db3ec74dd33c48bccc65a4ccc39341aff62c4295bdcea5d4cc1aad86073429e6b5379aaf2592904825b8b3240aaf1cf67e7491992448507c47dfd60d4aff60d7fdbaae1e8dd808dbde84cf1c1eb76795a8ae60200e2741ca6e0e9095e4b88760b646211f8e380bd5083276375f988c4de1fb9abb2a29d035e0dbabafc52f6c9d548602a5ee1c5111c97be279d0fafbd5ab6375948445b96544bb833252346ce05fc20659102fb6b08bb863a2d2391c5304872dec352073dd0934aefc5fec5cfa02d01a0332c3a3db533c1b13da8bee282e9b0f9ee30371ea97736edc974479247837893be8a6e449a37646587bee38cc856e932207b6f00cf8fdbdf314785baee5a59d02e10c303227ba2d253e1cfdef8153c897aea4eed8a0baffc2d71b50062edc9626d7cb5fa4522150b8659f9c67d1411e730a925e2fa96c5ed0bd8a804605874d4fd8d095abc85e0237d3584bb2f16dc7e614ae87ae322cf5abf17eb921199f3bfb9b36ccd6aac7905b97fc05e2cca31752f7c1dc4f61958ac8fa06687e99347d4f00d4098ff6705b6c85dbcfeb43f35808468c5d18f42c312b55c57a883dbd8e13e7de4eb5897e39f26770a7c72d4480816af0f6a9505a22307aca0b9670db74b3278e248bc7040df12b4807a5979eb52c516af2412952aa4b70c2f8adbb8a7560457859b70ee328b5e8e6563d513b5edb6c8a7f31b6411bf51f079f4628640d38141ace6b1d5144d9d377b04df5399ab3fe2a76b5e54eb0256725cebef9c8b2b1ad053ca8200400a13c57a692eae820c69f4b2d335cbce19b2e738181a3677768a376c9bafd4ee4bac7e1522fef282fe1ea5cedf559c0909afa2be3149d3ad38ee86ba71bf2786eb6e3c778572613e20cc5f178a930ffab285439f7cd5697ee49c04db7b287572684856d36ab73ef9f3afd8de616b324c42d5aa745461310872eac3818b0f12578734770abb8c206ff8f7cb94210e32296bc0f828ec38d7ad38ef4650ccfcc67cf9cf1cc5a30a6d182086a43e680f40b7034d98e3b1d49ff30f5f6788588947712283b27d4d32272e8623aa50746e589e328a8e2c0880a71012f0ab1916cc5ee32bc6de540804f27c7977e527593737ebf82910de09188c42a0e5f214ff9201d16d5356286fa21d1386056ffe775a4da442bb36a5b18ff96ae0a52ee648435565d9026644ee6971f13715f8b8e14dde783c5a8b5116fdfe1391e8e9029685bb5bf4ec37ae328a0879316f29a6db0cd5fc872f9107609f1e0fc2792b9b21f5226b6694963aa92b86138a19aa08e04c96546f9609d963d1ee44a7a15f85e09b4bc840eaa8bce7ebf59d29bde5f75fd2a182c57dbcfe7562bfa74e78598e0d8272f73084223709d8ff2e946f439f7764aa982247d5594998d80bfc2032487ac91da9277e7da3055ff585d62a67f357864559426e2a0aaf3eb2f03fdfe33d03e65ac3340f3b847f5bd763fd51e894e021281ae71fa70b847fc0cc49508a9a90a1f6803970413b60ee8f591624e7cf45e34f6f8a3315d22f5fc6e1f3345ca6cab0058760f8c292b5d8f4fd45084b9808a253922b46a2441a6ca70daf21cde1c191551c4926d9ba7ba687c96a575cb6412dffd1ae7fbcc026882ca65d3f36740bf2bfe6dcda5b69c484df1279575a8b89aea281a2c58a0717d3640588859b3d802b3d24525f05e19430e200e80979352bb35c6208c07423a58d5326711defb6da1eb5c61654836cc0ec90814ded5789a08c82a96f95d00968ccd13128d2d0fdfce0f5657bfbe00537fa72b910548dd7f5775f5c8041906779708da7d328314e73f1958b0f12e3a11e25da368cdd1efd260cf4356b1334280eb82f87a46ddda06d3982a667a1b4dc8362bf68a5c5d22ced1a29939055b21139cefef3b2268be61e5d2c96e58d7d72d77537b7d6eb43f9fdebfd99bc19a4ae83ad597c924ef33c1feefea20fd352c89915107188524899f8cf5cbc4b9773b49580103e10c76356721ebae28d36695961ac7e88827fce9ee34e1ef9eabb6b5bfc214329fc609fde84d68a29a181a8693d774f8e26de5363d08b1e84553adb291075f754b5688635b99ee324c1f247d7488d00206c774545a5a0c9c308615b81e70d5827e3d6df9bf0cc0af6f8bfa4077082f655c6883092710b164c09a7d3ab6cd4b12d135b39d3b6fc106f61b6b8c8d31a8a1blibdcerpc-binding.so.0.0.1libdcerpc-server-core.so.0.0.1libdcerpc.so.0.0.1libndr-krb5pac.so.0.0.1libndr-nbt.so.0.0.1libndr-standard.so.0.0.1libndr.so.3.0.0libnetapi.so.1.0.0libsamba-credentials.so.1.0.0libsamba-errors.so.1.0.0libsamba-hostconfig.so.0.0.1libsamba-passdb.so.0.28.0libsamba-util.so.0.0.1libsamdb.so.0.0.1libsmbclient.so.0.7.0libsmbconf.so.0.0.1libsmbldap.so.2.1.0libtevent-util.so.0.0.1libwbclient.so.0.15rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsamba-4.17.12+git.455.b299ac1e60-150500.3.20.1.src.rpmlibCHARSET3-samba4.so()(64bit)libCHARSET3-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libMESSAGING-SEND-samba4.so()(64bit)libMESSAGING-SEND-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libMESSAGING-samba4.so()(64bit)libMESSAGING-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libaddns-samba4.so()(64bit)libaddns-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libads-samba4.so()(64bit)libads-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libasn1util-samba4.so()(64bit)libasn1util-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libauth-samba4.so()(64bit)libauth-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libauthkrb5-samba4.so()(64bit)libauthkrb5-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libcli-cldap-samba4.so()(64bit)libcli-cldap-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libcli-ldap-common-samba4.so()(64bit)libcli-ldap-common-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libcli-ldap-samba4.so()(64bit)libcli-ldap-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libcli-nbt-samba4.so()(64bit)libcli-nbt-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libcli-smb-common-samba4.so()(64bit)libcli-smb-common-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libcli-spoolss-samba4.so()(64bit)libcli-spoolss-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libcliauth-samba4.so()(64bit)libcliauth-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libclidns-samba4.so()(64bit)libclidns-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libcluster-samba4.so()(64bit)libcluster-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libcmdline-contexts-samba4.so()(64bit)libcmdline-contexts-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libcmdline-samba4.so()(64bit)libcmdline-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libcommon-auth-samba4.so()(64bit)libcommon-auth-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libdbwrap-samba4.so()(64bit)libdbwrap-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libdcerpc-binding.so.0()(64bit)libdcerpc-binding.so.0(DCERPC_BINDING_0.0.1)(64bit)libdcerpc-binding0libdcerpc-pkt-auth-samba4.so()(64bit)libdcerpc-pkt-auth-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libdcerpc-samba-samba4.so()(64bit)libdcerpc-samba-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libdcerpc-samba4.so()(64bit)libdcerpc-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libdcerpc-server-core.so.0()(64bit)libdcerpc-server-core.so.0(DCERPC_SERVER_CORE_0.0.1)(64bit)libdcerpc.so.0()(64bit)libdcerpc.so.0(DCERPC_0.0.1)(64bit)libdcerpc0libevents-samba4.so()(64bit)libevents-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libflag-mapping-samba4.so()(64bit)libflag-mapping-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libgenrand-samba4.so()(64bit)libgenrand-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libgensec-samba4.so()(64bit)libgensec-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libgpo-samba4.so()(64bit)libgpo-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libgse-samba4.so()(64bit)libgse-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libhttp-samba4.so()(64bit)libhttp-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libinterfaces-samba4.so()(64bit)libinterfaces-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libiov-buf-samba4.so()(64bit)libiov-buf-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libkrb5samba-samba4.so()(64bit)libkrb5samba-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libldbsamba-samba4.so()(64bit)libldbsamba-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)liblibcli-lsa3-samba4.so()(64bit)liblibcli-lsa3-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)liblibcli-netlogon3-samba4.so()(64bit)liblibcli-netlogon3-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)liblibsmb-samba4.so()(64bit)liblibsmb-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libmessages-dgm-samba4.so()(64bit)libmessages-dgm-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libmessages-util-samba4.so()(64bit)libmessages-util-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libmscat-samba4.so()(64bit)libmscat-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libmsghdr-samba4.so()(64bit)libmsghdr-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libmsrpc3-samba4.so()(64bit)libmsrpc3-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-krb5pac0libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-nbt0libndr-samba-samba4.so()(64bit)libndr-samba-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libndr-samba4.so()(64bit)libndr-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libndr-standard.so.0()(64bit)libndr-standard.so.0(NDR_STANDARD_0.0.1)(64bit)libndr-standard0libndr.so.3()(64bit)libndr.so.3(NDR_0.0.1)(64bit)libndr.so.3(NDR_0.0.2)(64bit)libndr.so.3(NDR_0.0.3)(64bit)libndr.so.3(NDR_0.0.4)(64bit)libndr.so.3(NDR_0.0.5)(64bit)libndr.so.3(NDR_0.0.6)(64bit)libndr.so.3(NDR_0.0.7)(64bit)libndr.so.3(NDR_0.0.8)(64bit)libndr.so.3(NDR_0.0.9)(64bit)libndr.so.3(NDR_0.1.0)(64bit)libndr.so.3(NDR_0.1.1)(64bit)libndr.so.3(NDR_0.1.2)(64bit)libndr.so.3(NDR_0.2.0)(64bit)libndr.so.3(NDR_0.2.1)(64bit)libndr.so.3(NDR_1.0.0)(64bit)libndr.so.3(NDR_1.0.1)(64bit)libndr.so.3(NDR_1.0.2)(64bit)libndr.so.3(NDR_2.0.0)(64bit)libndr.so.3(NDR_3.0.0)(64bit)libndr2libnet-keytab-samba4.so()(64bit)libnet-keytab-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libnetapi.so.1()(64bit)libnetapi.so.1(NETAPI_1.0.0)(64bit)libnetapi0libnetif-samba4.so()(64bit)libnetif-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libnpa-tstream-samba4.so()(64bit)libnpa-tstream-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libprinting-migrate-samba4.so()(64bit)libprinting-migrate-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libregistry-samba4.so()(64bit)libregistry-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libreplace-samba4.so()(64bit)libreplace-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsamba-cluster-support-samba4.so()(64bit)libsamba-cluster-support-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsamba-credentials.so.1()(64bit)libsamba-credentials.so.1(SAMBA_CREDENTIALS_1.0.0)(64bit)libsamba-credentials1libsamba-debug-samba4.so()(64bit)libsamba-debug-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsamba-errors.so.1()(64bit)libsamba-errors.so.1(SAMBA_ERRORS_1.0.0)(64bit)libsamba-errors0libsamba-hostconfig.so.0()(64bit)libsamba-hostconfig.so.0(SAMBA_HOSTCONFIG_0.0.1)(64bit)libsamba-hostconfig0libsamba-modules-samba4.so()(64bit)libsamba-modules-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsamba-passdb.so.0()(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.2.0)(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.24.1)(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.24.2)(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.25.0)(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.26.0)(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.27.0)(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.27.1)(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.27.2)(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.28.0)(64bit)libsamba-passdb0libsamba-security-samba4.so()(64bit)libsamba-security-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsamba-sockets-samba4.so()(64bit)libsamba-sockets-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsamba-util.so.0()(64bit)libsamba-util.so.0(SAMBA_UTIL_0.0.1)(64bit)libsamba-util0libsamba3-util-samba4.so()(64bit)libsamba3-util-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsamdb-common-samba4.so()(64bit)libsamdb-common-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsamdb.so.0()(64bit)libsamdb.so.0(SAMDB_0.0.1)(64bit)libsamdb0libsecrets3-samba4.so()(64bit)libsecrets3-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libserver-id-db-samba4.so()(64bit)libserver-id-db-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libserver-role-samba4.so()(64bit)libserver-role-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsmb-transport-samba4.so()(64bit)libsmb-transport-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsmbclient-raw-samba4.so()(64bit)libsmbclient-raw-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsmbclient.so.0()(64bit)libsmbclient.so.0(SMBCLIENT_0.1.0)(64bit)libsmbclient.so.0(SMBCLIENT_0.2.0)(64bit)libsmbclient.so.0(SMBCLIENT_0.2.1)(64bit)libsmbclient.so.0(SMBCLIENT_0.2.2)(64bit)libsmbclient.so.0(SMBCLIENT_0.2.3)(64bit)libsmbclient.so.0(SMBCLIENT_0.3.0)(64bit)libsmbclient.so.0(SMBCLIENT_0.3.1)(64bit)libsmbclient.so.0(SMBCLIENT_0.3.2)(64bit)libsmbclient.so.0(SMBCLIENT_0.3.3)(64bit)libsmbclient.so.0(SMBCLIENT_0.4.0)(64bit)libsmbclient.so.0(SMBCLIENT_0.5.0)(64bit)libsmbclient.so.0(SMBCLIENT_0.6.0)(64bit)libsmbclient.so.0(SMBCLIENT_0.7.0)(64bit)libsmbclient0libsmbconf.so.0()(64bit)libsmbconf.so.0(SMBCONF_0.0.1)(64bit)libsmbconf0libsmbd-base-samba4.so()(64bit)libsmbd-base-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsmbd-shim-samba4.so()(64bit)libsmbd-shim-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsmbldap.so.2()(64bit)libsmbldap.so.2(SMBLDAP_0)(64bit)libsmbldap.so.2(SMBLDAP_1)(64bit)libsmbldap.so.2(SMBLDAP_2)(64bit)libsmbldap.so.2(SMBLDAP_2.1.0)(64bit)libsmbldap2libsmbldaphelper-samba4.so()(64bit)libsmbldaphelper-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsocket-blocking-samba4.so()(64bit)libsocket-blocking-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsys-rw-samba4.so()(64bit)libsys-rw-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libtalloc-report-printf-samba4.so()(64bit)libtalloc-report-printf-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libtdb-wrap-samba4.so()(64bit)libtdb-wrap-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libtevent-util.so.0()(64bit)libtevent-util.so.0(TEVENT_UTIL_0.0.1)(64bit)libtevent-util0libtime-basic-samba4.so()(64bit)libtime-basic-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libtrusts-util-samba4.so()(64bit)libtrusts-util-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libutil-reg-samba4.so()(64bit)libutil-reg-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libutil-setid-samba4.so()(64bit)libutil-setid-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libutil-tdb-samba4.so()(64bit)libutil-tdb-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libwbclient.so.0()(64bit)libwbclient.so.0(WBCLIENT_0.10)(64bit)libwbclient.so.0(WBCLIENT_0.11)(64bit)libwbclient.so.0(WBCLIENT_0.12)(64bit)libwbclient.so.0(WBCLIENT_0.13)(64bit)libwbclient.so.0(WBCLIENT_0.14)(64bit)libwbclient.so.0(WBCLIENT_0.15)(64bit)libwbclient.so.0(WBCLIENT_0.9)(64bit)libwbclient0samba-client-libssamba-client-libs(aarch-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    /sbin/ldconfig/sbin/ldconfigld-linux-aarch64.so.1()(64bit)ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)libCHARSET3-samba4.so()(64bit)libCHARSET3-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libMESSAGING-SEND-samba4.so()(64bit)libMESSAGING-SEND-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libMESSAGING-samba4.so()(64bit)libMESSAGING-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libacl.so.1()(64bit)libacl.so.1(ACL_1.0)(64bit)libaddns-samba4.so()(64bit)libaddns-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libads-samba4.so()(64bit)libads-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libasn1util-samba4.so()(64bit)libasn1util-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libauth-samba4.so()(64bit)libauth-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libauthkrb5-samba4.so()(64bit)libauthkrb5-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libavahi-client.so.3()(64bit)libavahi-common.so.3()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.27)(64bit)libcli-cldap-samba4.so()(64bit)libcli-cldap-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libcli-ldap-common-samba4.so()(64bit)libcli-ldap-common-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libcli-ldap-samba4.so()(64bit)libcli-ldap-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libcli-nbt-samba4.so()(64bit)libcli-nbt-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libcli-smb-common-samba4.so()(64bit)libcli-smb-common-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libcli-spoolss-samba4.so()(64bit)libcli-spoolss-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libcliauth-samba4.so()(64bit)libcliauth-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libclidns-samba4.so()(64bit)libclidns-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libcluster-samba4.so()(64bit)libcluster-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libcom_err.so.2()(64bit)libcommon-auth-samba4.so()(64bit)libcommon-auth-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libdbwrap-samba4.so()(64bit)libdbwrap-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libdcerpc-binding.so.0()(64bit)libdcerpc-binding.so.0(DCERPC_BINDING_0.0.1)(64bit)libdcerpc-pkt-auth-samba4.so()(64bit)libdcerpc-pkt-auth-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libdcerpc-samba-samba4.so()(64bit)libdcerpc-samba-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libdcerpc.so.0()(64bit)libdcerpc.so.0(DCERPC_0.0.1)(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.17)(64bit)libflag-mapping-samba4.so()(64bit)libflag-mapping-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libgenrand-samba4.so()(64bit)libgenrand-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libgensec-samba4.so()(64bit)libgensec-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libgnutls.so.30()(64bit)libgnutls.so.30(GNUTLS_3_4)(64bit)libgnutls.so.30(GNUTLS_3_6_10)(64bit)libgnutls.so.30(GNUTLS_3_6_13)(64bit)libgnutls.so.30(GNUTLS_3_6_3)(64bit)libgse-samba4.so()(64bit)libgse-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libgssapi_krb5.so.2()(64bit)libgssapi_krb5.so.2(gssapi_krb5_2_MIT)(64bit)libhttp-samba4.so()(64bit)libhttp-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libinterfaces-samba4.so()(64bit)libinterfaces-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libiov-buf-samba4.so()(64bit)libiov-buf-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libk5crypto.so.3()(64bit)libk5crypto.so.3(k5crypto_3_MIT)(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libkrb5samba-samba4.so()(64bit)libkrb5samba-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)liblber-2.4.so.2()(64bit)libldap_r-2.4.so.2()(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libldb.so.2(LDB_0.9.15)(64bit)libldb.so.2(LDB_0.9.16)(64bit)libldb.so.2(LDB_0.9.23)(64bit)libldb.so.2(LDB_1.1.1)(64bit)libldb.so.2(LDB_1.1.19)(64bit)libldb.so.2(LDB_1.1.30)(64bit)libldb.so.2(LDB_1.3.0)(64bit)libldb.so.2(LDB_2.6.1)(64bit)libldb.so.2(LDB_2.6.2)(64bit)libldbsamba-samba4.so()(64bit)libldbsamba-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)liblibcli-lsa3-samba4.so()(64bit)liblibcli-lsa3-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)liblibcli-netlogon3-samba4.so()(64bit)liblibcli-netlogon3-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)liblibsmb-samba4.so()(64bit)liblibsmb-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libmessages-dgm-samba4.so()(64bit)libmessages-dgm-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libmessages-util-samba4.so()(64bit)libmessages-util-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libmsghdr-samba4.so()(64bit)libmsghdr-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libmsrpc3-samba4.so()(64bit)libmsrpc3-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-samba-samba4.so()(64bit)libndr-samba-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libndr-samba4.so()(64bit)libndr-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libndr-standard.so.0()(64bit)libndr-standard.so.0(NDR_STANDARD_0.0.1)(64bit)libndr.so.3()(64bit)libndr.so.3(NDR_0.0.1)(64bit)libndr.so.3(NDR_0.0.3)(64bit)libndr.so.3(NDR_0.0.4)(64bit)libndr.so.3(NDR_0.0.5)(64bit)libndr.so.3(NDR_0.0.6)(64bit)libndr.so.3(NDR_0.0.7)(64bit)libndr.so.3(NDR_0.0.8)(64bit)libndr.so.3(NDR_0.0.9)(64bit)libndr.so.3(NDR_0.1.1)(64bit)libndr.so.3(NDR_0.1.2)(64bit)libndr.so.3(NDR_0.2.0)(64bit)libndr.so.3(NDR_0.2.1)(64bit)libndr.so.3(NDR_1.0.0)(64bit)libndr.so.3(NDR_1.0.1)(64bit)libndr.so.3(NDR_1.0.2)(64bit)libndr.so.3(NDR_2.0.0)(64bit)libnetif-samba4.so()(64bit)libnetif-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libnpa-tstream-samba4.so()(64bit)libnpa-tstream-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libnscd.so.1()(64bit)libnscd.so.1(LIBNSCD_1.0)(64bit)libpam.so.0()(64bit)libpam.so.0(LIBPAM_1.0)(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.17)(64bit)libreplace-samba4.so()(64bit)libreplace-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libresolv.so.2()(64bit)libresolv.so.2(GLIBC_2.17)(64bit)libsamba-cluster-support-samba4.so()(64bit)libsamba-cluster-support-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsamba-credentials.so.1()(64bit)libsamba-credentials.so.1(SAMBA_CREDENTIALS_1.0.0)(64bit)libsamba-debug-samba4.so()(64bit)libsamba-debug-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsamba-errors.so.1()(64bit)libsamba-errors.so.1(SAMBA_ERRORS_1.0.0)(64bit)libsamba-hostconfig.so.0()(64bit)libsamba-hostconfig.so.0(SAMBA_HOSTCONFIG_0.0.1)(64bit)libsamba-modules-samba4.so()(64bit)libsamba-modules-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsamba-passdb.so.0()(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.2.0)(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.27.1)(64bit)libsamba-security-samba4.so()(64bit)libsamba-security-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsamba-sockets-samba4.so()(64bit)libsamba-sockets-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsamba-util.so.0()(64bit)libsamba-util.so.0(SAMBA_UTIL_0.0.1)(64bit)libsamba3-util-samba4.so()(64bit)libsamba3-util-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsamdb-common-samba4.so()(64bit)libsamdb-common-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsamdb.so.0()(64bit)libsamdb.so.0(SAMDB_0.0.1)(64bit)libsecrets3-samba4.so()(64bit)libsecrets3-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libserver-id-db-samba4.so()(64bit)libserver-id-db-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libserver-role-samba4.so()(64bit)libserver-role-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsmb-transport-samba4.so()(64bit)libsmb-transport-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsmbclient-raw-samba4.so()(64bit)libsmbclient-raw-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsmbconf.so.0()(64bit)libsmbconf.so.0(SMBCONF_0.0.1)(64bit)libsmbd-shim-samba4.so()(64bit)libsmbd-shim-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsmbldap.so.2()(64bit)libsmbldap.so.2(SMBLDAP_0)(64bit)libsmbldap.so.2(SMBLDAP_1)(64bit)libsmbldaphelper-samba4.so()(64bit)libsmbldaphelper-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsocket-blocking-samba4.so()(64bit)libsocket-blocking-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsys-rw-samba4.so()(64bit)libsys-rw-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsystemd.so.0()(64bit)libsystemd.so.0(LIBSYSTEMD_209)(64bit)libtalloc-report-printf-samba4.so()(64bit)libtalloc-report-printf-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtalloc.so.2(TALLOC_2.1.0)(64bit)libtasn1.so.6()(64bit)libtasn1.so.6(LIBTASN1_0_3)(64bit)libtdb-wrap-samba4.so()(64bit)libtdb-wrap-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtdb.so.1(TDB_1.2.2)(64bit)libtdb.so.1(TDB_1.2.5)(64bit)libtdb.so.1(TDB_1.3.0)(64bit)libtdb.so.1(TDB_1.3.11)(64bit)libtdb.so.1(TDB_1.3.17)(64bit)libtevent-util.so.0()(64bit)libtevent-util.so.0(TEVENT_UTIL_0.0.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.11.0)(64bit)libtevent.so.0(TEVENT_0.12.0)(64bit)libtevent.so.0(TEVENT_0.13.0)(64bit)libtevent.so.0(TEVENT_0.9.12)(64bit)libtevent.so.0(TEVENT_0.9.13)(64bit)libtevent.so.0(TEVENT_0.9.14)(64bit)libtevent.so.0(TEVENT_0.9.16)(64bit)libtevent.so.0(TEVENT_0.9.20)(64bit)libtevent.so.0(TEVENT_0.9.21)(64bit)libtevent.so.0(TEVENT_0.9.30)(64bit)libtevent.so.0(TEVENT_0.9.31)(64bit)libtevent.so.0(TEVENT_0.9.37)(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libtime-basic-samba4.so()(64bit)libtime-basic-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libtrusts-util-samba4.so()(64bit)libtrusts-util-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libutil-reg-samba4.so()(64bit)libutil-reg-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libutil-setid-samba4.so()(64bit)libutil-setid-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libutil-tdb-samba4.so()(64bit)libutil-tdb-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libwbclient.so.0()(64bit)libwbclient.so.0(WBCLIENT_0.13)(64bit)libwbclient.so.0(WBCLIENT_0.9)(64bit)libz.so.1()(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-14.14.3ez@e[J@e6`@eSd@d.@dd-@d@dd@d6@d@d @cvcvc@c@c @c@cctc5cM@b@b@b@ba@bascabrero@suse.descabrero@suse.descabrero@suse.denopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comscabrero@suse.dedmulder@suse.comscabrero@suse.denopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedimstar@opensuse.orgscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.denopower@suse.comscabrero@suse.deddiss@suse.comddiss@suse.comddiss@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comscabrero@suse.descabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comdmulder@suse.comscabrero@suse.denopower@suse.comddiss@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comddiss@suse.comddiss@suse.comnopower@suse.comnopower@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comddiss@suse.comscabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comjengelh@inai.dedmulder@suse.comscabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comdmulder@suse.comdmulder@suse.comjmcdonough@suse.comdmulder@suse.comscabrero@suse.dedmulder@suse.comscabrero@suse.dedmulder@suse.comdmulder@suse.comvcizek@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.dejmcdonough@suse.comscabrero@suse.deaaptel@suse.comjengelh@inai.dedimstar@opensuse.orgdmulder@suse.comjmcdonough@suse.comdavid.mulder@suse.comjmcdonough@suse.comaaptel@suse.comdmulder@suse.comscabrero@suse.comscabrero@suse.comkukuk@suse.dedavid.mulder@suse.comscabrero@suse.comrbrown@suse.comdmulder@suse.comscabrero@suse.comdimstar@opensuse.orgscabrero@suse.comaaptel@suse.comnopower@suse.comnopower@suse.comaaptel@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comddiss@suse.comnopower@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comdmulder@suse.comnopower@suse.comjmcdonough@suse.comaaptel@suse.comkukuk@suse.comkukuk@suse.denopower@suse.comaaptel@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comddiss@suse.comjmcdonough@suse.comddiss@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comtchvatal@suse.comlmuelle@suse.comnopower@suse.comcrrodriguez@opensuse.orglmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnoel.power@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.commpluskal@suse.comlmuelle@suse.comnopower@suse.deddiss@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.denopower@suse.delmuelle@suse.comnopower@suse.deddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.com- Add new idmap_nss option 'use_upn' for those NSS modules able to handle UPNs or DOMAIN/user name format; (bsc#1215369); - Avoid unnecessary locking in idmap parent setup; (bsc#1215369);- Add "net offlinejoin composeodj" command; (bsc#1214076);- Update to samba 4.17.12 * Weird filename can cause assert to fail in openat_pathref_fsp_nosymlink(); (bso#15419); * reply_sesssetup_and_X() can dereference uninitialized tmp pointer; (bso#15420); * Missing return in reply_exit_done(); (bso#15430); * TREE_CONNECT without SETUP causes smbd to use uninitialized pointer; (bso#15432); * Improve GetNChanges to address some (but not all "Azure AD Connect") syncronisation tool looping during the initial user sync phase; (bso#15401); * Samba replication logs show (null) DN; (bso#15407); * Spotlight sometimes returns no results on latest macOS; (bso#15342); * Renaming results in NT_STATUS_SHARING_VIOLATION if previously attempted to remove the destination; (bso#15417); * Spotlight results return wrong date in result list; (bso#15427); * macOS mdfind returns only 50 results; (bso#15463); * 2-3min delays at reconnect with smb2_validate_sequence_number: bad message_id 2; (bso#15346); * samba-tool ntacl get segfault if aio_pthread appended; (bso#15441); * DCERPC_PKT_CO_CANCEL and DCERPC_PKT_ORPHANED can't be parsed; (bso#15446); * File doesn't show when user doesn't have permission if aio_pthread is loaded; (bso#15453); * net ads lookup (with unspecified realm) fails; (bso#15384); (bsc#1213826); * Regression DFS not working with widelinks = true; (bso#15435); (bsc#1213607); * ctdb_killtcp fails to work with --enable-pcap and libpcap 1.9.1; (bso#15451); * mdssvc: Do an early talloc_free() in _mdssvc_open(); (bso#15449); * Windows client join fails if a second container CN=System exists somewhere; (bso#9959); - Fix crossing automounter mount points; (bsc#1215212);- CVE-2023-4091: samba: Client can truncate file with read-only permissions; (bsc#1215904); (bso#15439). - CVE-2023-42669: samba: rpcecho, enabled and running in AD DC, allows blocking sleep on request; (bso#1215905); (bso#15474). - CVE-2023-42670: samba: The procedure number is out of range when starting Active Directory Users and Computers; (bsc#1215906); (bso#15473). - CVE-2023-3961: samba: Unsanitized client pipe name passed to local_np_connect(); (bsc#1215907); (bso#15422). - CVE-2023-4154: samba: dirsync allows SYSTEM access with only "GUID_DRS_GET_CHANGES" right, not "GUID_DRS_GET_ALL_CHANGES; (bsc#1215908); (bso#15424).- Fix DFS not working with widelinks enabled; (bsc#1213607); (bso#15435);- Move libcluster-samba4.so from samba-libs to samba-client-libs; (bsc#1213940);- net ads lookup with unspecified realm fails; (bso#15384); (bsc#1213826);- secure channel faulty since Windows 10/11 update 07/2023; (bso#15418); (bsc#1213384).- CVE-2022-2127: lm_resp_len not checked properly in winbindd_pam_auth_crap_send; (bso#15072); (bsc#1213174). - CVE-2023-34966: Samba Spotlight mdssvc RPC Request Infinite Loop Denial-of-Service Vulnerability; (bso#15340); (bsc#1213173). - CVE-2023-34967: Samba Spotlight mdssvc RPC Request Type Confusion Denial-of-Service Vulnerability; (bso#15341); (bsc#1213172). - CVE-2023-34968: Spotlight server-side Share Path Disclosure; (bso#15388); (bsc#1213171). - CVE-2023-3347: Samba doesn't require SMB2+ signing if `server signing = mandatory` is set; (bso#15397); (bsc#1213170).- Update to 4.17.9 * Backport --pidl-developer fixes; (bso#15404). * smbd_scavenger crashes when service smbd is stopped; (bso#15275). * vfs_fruit might cause a failing open for delete; (bso#15378). * named crashes on DLZ zone update; (bso#14030). * winbind recurses into itself via rpcd_lsad; (bso#15361). * cli_list loops 100% CPU against pre-lanman2 servers; (bso#15382). * smbclient leaks fds with showacls; (bso#15391). * aes256 smb3 encryption algorithms are not allowed in smb3_sid_parse(); (bso#15374). * winbindd gets stuck on NT_STATUS_RPC_SEC_PKG_ERROR; (bso#15413). * smbget memory leak if failed to download files recursively; (bso#15403).- Update to 4.17.8 * log flood: smbd_calculate_access_mask_fsp: Access denied: message level should be lower; (bso#15302). * Floating point exception (FPE) via cli_pull_send at source3/libsmb/clireadwrite.c; (bso#15306). * test_tstream_more_tcp_user_timeout_spin fails intermittently on Rackspace GitLab runners; (bso#15328). * Reduce flapping of ridalloc test; (bso#15329). * large_ldap test is unreliable; (bso#15351). * New filename parser doesn't check veto files smb.conf parameter; (bso#15143). * mdssvc may crash when initializing; (bso#15354). * Large directory optimization broken for non-lcomp path elements; (bso#15313). * streams_depot fails to create streams; (bso#15357). * shadow_copy2 and streams_depot don't play well together; (bso#15358). * wbinfo -u fails on ad dc with >1000 users; (bso#15366). * winbindd idmap child contacts the domain controller without a need; (bso#15317). * idmap_autorid may fail to map sids of trusted domains for the first time; (bso#15318). * idmap_hash doesn't use ID_TYPE_BOTH for reverse mappings; (bso#15319). * net ads search -P doesn't work against servers in other domains; (bso#15323). * DS ACEs might be inherited to unrelated object classes; (bso#15338). * Temporary smbXsrv_tcon_global.tdb can't be parsed; (bso#15353). * Setting veto files = /.*/ break listing directories; (bso#15360); (bsc#1212375). * CVE-2020-25720 [SECURITY] Create Child permission should not allow full write to all attributes (additional changes); (bso#14810). * dsgetdcname: assumes local system uses IPv4; (bso#15325).- Update to 4.17.7 * CVE-2023-0922: Samba AD DC admin tool samba-tool sends passwords in cleartext; (bso#15315); (bsc#1209481). * CVE-2023-0225: Samba AD DC "dnsHostname" attribute can be deleted by unprivileged authenticated users; (bso#15276); (bsc#1209483). * CVE-2023-0614: samba: Access controlled AD LDAP attributes can be discovered; (bso#15270); (bsc#1209485). * large_ldap test is inefficient; (bso#15332). * CVE-2020-25720 [SECURITY] Create Child permission should not allow full write to all attributes (additional changes); (bso#14810). - Update to 4.17.6 * streams_xattr is creating unexpected locks on folders; (bso#15314). * Use of the Azure AD Connect cloud sync tool is now supported for password hash synchronisation, allowing Samba AD Domains to synchronise passwords with this popular cloud environment; (bso#10635). * Spotlight doesn't work with latest macOS Ventura; (bso#15299). * New samba-dcerpc architecture does not scale gracefully; (bso#15310). * vfs_ceph incorrectly uses fsp_get_io_fd() instead of fsp_get_pathref_fd() in close and fstat; (bso#15307). * With clustering enabled samba-bgqd can core dump due to use after free; (bso#15293). * fd_load() function implicitly closes the fd where it should not; (bso#15311). - Update to 4.17.5 * smbc_getxattr() return value is incorrect; (bso#14808). * Compound SMB2 FLUSH+CLOSE requests from MacOSX are not handled correctly; (bso#15172). * synthetic_pathref AFP_AfpInfo failed errors; (bso#15210). * samba-tool gpo listall fails IPv6 only - finddcs() fails to find DC when there is only an AAAA record for the DC in DNS; (bso#15226). * smbd crashes if an FSCTL request is done on a stream handle; (bso#15236). * DFS links don't work anymore on Mac clients since 4.17; (bso#15277). * vfs_virusfilter segfault on access, directory edgecase (accessing NULL value); (bso#15283). * CVE-2022-38023 [SECURITY] Samba should refuse RC4 (aka md5) based SChannel on NETLOGON (additional changes); (bso#15240). * %U for include directive doesn't work for share listing (netshareenum); (bso#15243). * Shares missing from netshareenum response in samba 4.17.4; (bso#15266). * ctdb: use-after-free in run_proc; (bso#15269). * irpc_destructor may crash during shutdown; (bso#15280). * auth3_generate_session_info_pac leaks wbcAuthUserInfo; (bso#15286). * smbclient segfaults with use after free on an optimized build; (bso#15268). * smbstatus leaking files in msg.sock and msg.lock; (bso#15282). * Leak in wbcCtxPingDc2; (bso#15164). * Access based share enum does not work in Samba 4.16+; (bso#15265). * Crash during share enumeration; (bso#15267). * rep_listxattr on FreeBSD does not properly check for reads off end of returned buffer; (bso#15271). * Avoid relying on C89 features in a few places; (bso#15281).- Make (32bit) samba-libs conflict with old samba-ad-dc-libs package to satisfy installcheck.- Make samba-libs conflict with old samba-ad-dc-libs package to satisfy installcheck.- Remove non functioning ifup/ifdown samba-winbindd scripts; (bsc#1207414).- libdsdb-module-samba4 should be packaged as part of samba-libs and not samba-ad-dc-libs. Additionally no need for it to be removed conditionally.- Clean up logic for PAM migration settings in spec file.- Change with_dc default to 0 (for non TW builds), ADDC feature is deprecated and will no longer be included in >= SLE15-SP5; (jsc#PED-1122).- Update to 4.17.4 * CVE-2022-44640 Upstream Heimdal free of user-controlled pointer in FAST; (bsc#14929); * CVE-2021-20251 Bad password count not incremented atomically; (bsc#14611); * CVE-2022-42898 krb5_pac_parse() buffer parsing vulnerability; (bsc#15203); * CVE-2022-37966 rc4-hmac Kerberos session keys issued to modern servers; (bso#15237); * CVE-2022-37967 Kerberos constrained delegation ticket forgery possible against Samba AD DC; (bso#15231); * CVE-2022-38023 RC4/HMAC-MD5 NetLogon Secure Channel is weak and should be avoided; (bso#15240); * pam_winbind uses time_t and pointers assuming they are of the same size; (bso#15224); * Heimdal session key selection in AS-REQ examines wrong entry; (bso#15219); * filter-subunit is inefficient with large numbers of knownfails; (bso#15258); * smbd allows setting FILE_ATTRIBUTE_TEMPORARY on directories; (bso#15252); * The KDC logic arround msDs-supportedEncryptionTypes differs from Windows; (bso#13135); * libnet: change_password() doesn't work with dcerpc_samr_ChangePasswordUser4(); (bso#15206); * Heimdal session key selection in AS-REQ examines wrong entry; (bso#15219); * Memory leak in snprintf replacement functions; (bso#15230); * RODC doesn't reset badPwdCount reliable via an RWDC (CVE-2021-20251 regression); (bso#15253); * Prevent EBADF errors with vfs_glusterfs; (bso#15198); * %U for include directive doesn't work for share listing (netshareenum); (bso#15243); * Stack smashing in net offlinejoin requestodj; (bso#15257); * Windows 11 22H2 and Samba-AD 4.15 Kerberos login issue; (bso#15197); * Heimdal session key selection in AS-REQ examines wrong entry; (bso#15219); - Remove deprecated if-{down,up} scripts; (bsc#1206444); - Adjust the systemd drop-in file for named service; (bsc#1201689); * Paths are additive so do not repeat paths from named.service * Prefix the samba DLZ directory with "-" to ignore this path if it does not exists- Introduce without-smb1-server spec flag; (bsc#1205104); - Update to 4.17.3 * CVE-2022-42898: Samba buffer overflow vulnerabilities on 32-bit systems; (bsc#1205126); (bso#15203); - Replace obsolete python-gpgme with python-gpg * Upstream replaced it in v4.9.5 -- bso#13728 - Update to 4.17.2 * CVE-2022-3592 [SECURITY] samba: Wide links protection broken; (bso#15207); (bsc#1204499). * CVE-2022-3437 [SECURITY] samba: Buffer overflow in Heimdal unwrap_des3();(bso#15134); (bsc#1204254). - Update to 4.17.1 * CVE-2021-20251 [SECURITY] Bad password count not incremented atomically; (bso#14611). * smbXsrv_connection_shutdown_send result leaked; (bso#15174). * Flush on a named stream never completes; (bso#15182). * Permission denied calling SMBC_getatr when file not exists; (bso#15195). * Samba 4.5 sometimes cannot be upgraded to Samba 4.6 or later over DRS: WERROR_DS_DRA_MISSING_PARENT due to faulty GET_ANC; (bso#15189). * pytest: add file removal helpers for TestCaseInTempDir; (bso#15191). * CVE-2021-20251 [SECURITY] Bad password count not incremented atomically; (bso#14611). * Samba 4.5 sometimes cannot be upgraded to Samba 4.6 or later over DRS: WERROR_DS_DRA_MISSING_PARENT due to faulty GET_ANC; (bso#15189). * Flush on a named stream never completes; (bso#15182). * vfs_gpfs silently garbles timestamps > year 2106; (bso#15151). * CVE-2021-20251 [SECURITY] Bad password count not incremented atomically; (bso#14611). * multi-channel socket passing may hit a race if one of the involved processes already existed; (bso#15200). * memory leak on temporary of struct imessaging_post_state and struct tevent_immediate on struct imessaging_context (in rpcd_spoolss and maybe others); (bso#15201). * Since popt1.19 various use after free errors using result of poptGetArg are now exposed; (bso#15205); (boo#1204279). * Remove special case for O_CREAT in SMB_VFS_OPENAT from vfs_glusterfs; (bso#15192). * GETPWSID in memory cache grows indefinetly with each NTLM auth; (bso#15169). * CVE-2021-20251 [SECURITY] Bad password count not incremented atomically; (bso#14611). - Install a systemd drop-in file for named service to allow read/write access to the DLZ directory; (bsc#1201689); - Fix use after free errors resulting from using return of poptGetArg exposed since popt-1.19; (boo#1204279); (bso#15205). - s3: smbd: Fix memory leak in smbd_server_connection_terminate_done(); (bso#15174). - Disable SMB1 for tumbleweed builds. - Update to 4.17.0 * acl_xattr VFS module may unintentionally use filesystem permissions instead of ACL from xattr; (bso#15126). * Missing SMB2-GETINFO access checks from MS-SMB2 3.3.5.20.1; (bso#15153). * assert failed: !is_named_stream(smb_fname)") at ../../lib/util/fault.c:197; (bso#15161). * acl_xattr VFS module may unintentionally use filesystem permissions instead of ACL from xattr; (bso#15126). * assert failed: !is_named_stream(smb_fname)") at ../../lib/util/fault.c:197; (bso#15161). * Cross-node multi-channel reconnects result in SMB2 Negotiate returning NT_STATUS_NOT_SUPPORTED; (bso#15159). * winbind at info level debug can coredump when processing wb_lookupusergroups; (bso#15160). * Make use of glfs_*at() API calls in vfs_glusterfs; (bso#15157). * Possible use after free of connection_struct when iterating smbd_server_connection->connections; (bso#15128). * `net usershare add` fails with flag works with --long but fails with -l; (bso#15145). * acl_xattr VFS module may unintentionally use filesystem permissions instead of ACL from xattr; (bso#15126). * Performance regression on contended path based operations; (bso#15125). * Missing READ_LEASE break could cause data corruption; (bso#15148). * libsamba-errors uses a wrong version number; (bso#15141). * SMB1 negotiation can fail to handle connection errors; (bso#15152). * New filename parser doesn't check veto files smb.conf parameter; (bso#15143). * 4.17.rc1 still uses symlink-race prone unix_convert(); (bso#15144). * Backport fileserver related changed to 4.17.0rc2; (bso#15146). * Manpage for smbstatus json is missing; (bso#15147). * Backport fileserver related changed to 4.17.0rc2; (bso#15146). * Performance regression on contended path based operations; (bso#15125). * Backport fileserver related changed to 4.17.0rc2; (bso#15146). * Fix issues found by coverity in smbstatus json code; (bso#15140). * Backport fileserver related changed to 4.17.0rc2; (bso#15146). - Migration to /usr/etc: Saving user changed configuration files in /etc and restoring them while an RPM update. - Update to 4.16.4 * CVE-2022-2031: Samba AD users can bypass certain restrictions associated with changing passwords; (bsc#1201495); (bso#15047); * CVE-2022-32744: Samba AD users can forge password change requests for any user; (bsc#1201493); (bso#15074); * CVE-2022-32745: Samba AD users can crash the server process with an LDAP add or modify request; (bsc#1201492); (bso#15008); * CVE-2022-32746: Samba AD users can induce a use-after-free in the server process with an LDAP add or modify request; (bsc#1201490); (bso#15009); * CVE-2022-32742: Server memory information leak via SMB1; (bsc#1201496); (bso#15085); - Update to 4.16.3 * Using vfs_streams_xattr and deleting a file causes a panic; (bso#15099); * Add support for bind 9.18; (bso#14986); * logging dsdb audit to specific files does not work; (bso#15076); * Problem when winbind renews Kerberos; (bso#14979); (bsc#1196224); * Samba with new lorikeet-heimdal fails to build on gcc 12.1 in developer mode; (bso#15095); * Crash in streams_xattr because fsp->base_fsp->fsp_name is NULL; (bso#15105); * Crash in rpcd_classic - NULL pointer deference in mangle_is_mangled(); (bso#15118); * smbclient commands del & deltree fail with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556); * Fix check for chown when processing NFSv4 ACL; (bso#15120); * The pcap background queue process should not be stopped; (bso#15082); * testparm: Fix typo in idmap rangesize check; (bso#15097); * net ads info returns LDAP server and LDAP server name as null; (bso#15106); * ldconfig: /lib64/libsmbconf.so.0 is not a symbolic link; (bso#15108); * CTDB child process logging does not work as expected; (bso#15090); - Update spec file to fix the optional Heimdal DC build - Fix external trusts with MIT Kerberos 1.20 - Add missing samba-client requirement to samba-winbind package; (bsc#1198255); - Move pdb backends from package samba-libs to package samba-client-libs and remove samba-libs requirement from samba-winbind; (bsc#1200964); (bsc#1198255); - Add sysuser-shadow requirement for packages using systemd-sysusers - Use the canonical realm name to refresh the Kerberos tickets; (bsc#1196224); (bso#14979); - Moved logrotate files from user specific directory /etc/logrotate.d to vendor specific directory /usr/etc/logrotate.d. - Update to 4.16.2 * Use pathref fd instead of io fd in vfs_default_durable_cookie; (bso#15042); * vfs_gpfs with vfs_shadowcopy2 fail to restore file if original file had been deleted; (bso#15069); * Reintroduce netgroups support; (bso#15087); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); * Update from 4.15 to 4.16 breaks discovery of [homes] on standalone server from Win and IOS; (bso#15062); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * smbclient -E doesn't work as advertised; (bso#15075); * The samba background daemon doesn't refresh the printcap cache on startup; (bso#15081); * Out-by-4 error in smbd read reply max_send clamp; (bso#14443); - Fix samba4.blackbox.net_ads_dns_async test with bind9 >= 9.17.7 - Support building with MIT Kerberos 1.20 - Bronze bit and S4U support with MIT Kerberos 1.20 for Samba AD DC; (CVE-2020-17049); - Resource Based Constrained Delegation (RBCD) for Samba AD DC - Support building with gcc 12.1 - Use requires_eq macro to require the libldb2 version available at samba-dsdb-modules build time; (bsc#1199362); - Update to 4.16.1 * Share and server swapped in smbget password prompt; (bso#14831); * Durable handles won't reconnect if the leased file is written to; (bso#15022); * rmdir silently fails if directory contains unreadable files and hide unreadable is yes; (bso#15023); * SMB2_CLOSE_FLAGS_FULL_INFORMATION fails to return information on renamed file handle; (bso#15038); * Need to describe --builtin-libraries= better (compare with - -bundled-libraries); (bso#8731); * vfs_shadow_copy2 breaks "smbd async dosmode" sync fallback; (bso#14957); * shadow_copy2 fails listing snapshotted dirs with shadow:fixinodes; (bso#15035); * PAM Kerberos authentication incorrectly fails with a clock skew error; (bso#15046); * Username map - samba erroneously applies unix group memberships to user account entries; (bso#15041); * KVNO off by 100000; (bso#14951); * Uninitialized litemask in variable in vfs_gpfs module; (bso#15027); * vfs_gpfs recalls=no option prevents listing files; (bso#15055); * smbd doesn't handle UPNs for looking up names; (bso#15054); - Update update-apparmor-samba-profile script, replace non-printable delimiter with more human readable separator as sed can accept separators that can appear in the input data. - Fix update-apparmor-samba-profile script, sed doesn't like multibyte separators; (bsc#1198309). - Update to 4.16.0 * New samba-dcerpcd binary to provide DCERPC in the member server setup * Certificate Auto Enrollment * Ability to add ports to dns forwarder addresses in internal DNS backend * No longer using Linux mandatory locks for sharemodes * SMB1 protocol has been deprecated, particularly older dialects * SMB1 protocol SMBCopy command removed * SMB1 server-side wildcard expansion removed - Add python3-dnspython to samba-ad-dc recommens; (bsc#1187101); - Use systemd-sysusers to create system users; (bsc#1182847);- Install a systemd drop-in file for named service to allow read/write access to the DLZ directory; (bsc#1201689);- Update to 4.15.12 * CVE-2022-42898: samba: heimdal: Samba buffer overflow vulnerabilities on 32-bit systems; (bso#15203); (bsc#1205126). - Update to 4.15.11 * Allow rebuild of Centos 8 images after move to vault for Samba 4.15; (bso#15193). * CVE-2022-3437: samba: Buffer overflow in Heimdal unwrap_des3(); (bso#15134); (bsc#1204254)- Update to 4.15.10 * Possible use after free of connection_struct when iterating smbd_server_connection->connections; (bso#15128); (bsc#1200102). * smbXsrv_connection_shutdown_send result leaked; (bso#15174). * Spotlight RPC service returns wrong response when Spotlight is disabled on a share; (bso#15086). * acl_xattr VFS module may unintentionally use filesystem permissions instead of ACL from xattr; (bso#15126). * Missing SMB2-GETINFO access checks from MS-SMB2 3.3.5.20.1; (bso#15153). * assert failed: !is_named_stream(smb_fname)") at ../../lib/util/fault.c:197; (bso#15161). * Missing READ_LEASE break could cause data corruption; (bso#15148). * rpcclient can crash using setuserinfo(2); (bso#15124). * Samba fails to build with glibc 2.36 caused by including in libreplace; (bso#15132). * SMB1 negotiation can fail to handle connection errors; (bso#15152). * samba-tool domain join segfault when joining a samba ad domain; (bso#15078). - Update to 4.15.9 * CVE-2022-32742:SMB1 code does not correct verify SMB1write, SMB1write_and_close, SMB1write_and_unlock lengths; (bso#15085); (bsc#1201496). * CVE-2022-32746: samba: Use-after-free occurring in database audit logging; (bso#15009); (bso#15096); (bsc#1201490). * CVE-2022-2031: samba, ldb: AD users can bypass certain restrictions associated with changing passwords; (bso#15047); (bsc#1201495); * CVE-2022-32745: samba: ldb: AD users can crash the server process with an LDAP add or modify request; (bso#15008); (bso#15096); (bsc#1201492). * CVE-2022-2031: samba, ldb: AD users can bypass certain restrictions associated with changing passwords; (bso#15047); (bsc#1201495); * CVE-2022-32744: samba, ldb: AD users can forge password change requests for any user; (bso#15074); (bso#15047); (bsc#1201493).- CVE-2022-1615: Do not ignore errors in random number generation; (bso#15103); (bsc#1202976); - CVE-2022-32743: Implement validated dnsHostName write rights; (bso#14833); (bsc#1202803);- Fix Use after free when iterating smbd_server_connection->connections after tree disconnect failure; (bso#15128); (bsc#1200102).- CVE-2022-32746: samba: Use-after-free occurring in database audit logging; (bso#15009); (bso#15096); (bsc#1201490). - CVE-2022-32745: samba: ldb: AD users can crash the server process with an LDAP add or modify request; (bso#15008); (bso#15096); (bsc#1201492). - CVE-2022-2031: samba, ldb: AD users can bypass certain restrictions associated with changing passwords; (bso#15047); (bsc#1201495); - CVE-2022-32742:SMB1 code does not correct verify SMB1write, SMB1write_and_close, SMB1write_and_unlock lengths; (bso#15085); (bsc#1201496). - CVE-2022-32744: samba, ldb: AD users can forge password change requests for any user; (bso#15074); (bso#15047); (bsc#1201493).- Update to 4.15.8 * Use pathref fd instead of io fd in vfs_default_durable_cookie; (bso#15042); * Setting fruit:resource = stream in vfs_fruit causes a panic; (bso#15099); * Add support for bind 9.18; (bso#14986); * logging dsdb audit to specific files does not work; (bso#15076); * vfs_gpfs with vfs_shadowcopy2 fail to restore file if original file had been deleted; (bso#15069); * netgroups support removed; (bso#15087); (bsc#1199247); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); (bsc#1199734); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * smbclient commands del & deltree fail with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556); * vfs_gpfs recalls=no option prevents listing files; (bso#15055); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * Compile error in source3/utils/regedit_hexedit.c; (bso#15091); * ldconfig: /lib64/libsmbconf.so.0 is not a symbolic link; (bso#15108); * smbd doesn't handle UPNs for looking up names; (bso#15054); * Out-by-4 error in smbd read reply max_send clamp; (bso#14443); - Move pdb backends from package samba-libs to package samba-client-libs and remove samba-libs requirement from samba-winbind; (bsc#1200964); (bsc#1198255); - Use the canonical realm name to refresh the Kerberos tickets; (bsc#1196224); (bso#14979);- Fix smbclient commands del & deltree failing with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556).- Revert NIS support removal; (bsc#1199247);- Use requires_eq macro to require the libldb2 version available at samba-dsdb-modules build time; (bsc#1199362);- Add missing samba-client requirement to samba-winbind package; (bsc#1198255);- Update to 4.15.7 * Share and server swapped in smbget password prompt; (bso#14831); * Durable handles won't reconnect if the leased file is written to; (bso#15022); * rmdir silently fails if directory contains unreadable files and hide unreadable is yes; (bso#15023); * SMB2_CLOSE_FLAGS_FULL_INFORMATION fails to return information on renamed file handle; (bso#15038); * vfs_shadow_copy2 breaks "smbd async dosmode" sync fallback; (bso#14957); * shadow_copy2 fails listing snapshotted dirs with shadow:fixinodes; (bso#15035); * PAM Kerberos authentication incorrectly fails with a clock skew error; (bso#15046); * username map - samba erroneously applies unix group memberships to user account entries; (bso#15041); * NT_STATUS_ACCESS_DENIED translates into EPERM instead of EACCES in SMBC_server_internal; (bso#14983); * Simple bind doesn't work against an RODC (with non-preloaded users); (bso#13879); * Crash of winbind on RODC; (bso#14641); * uncached logon on RODC always fails once; (bso#14865); * KVNO off by 100000; (bso#14951); * LDAP simple binds should honour "old password allowed period"; (bso#15001); * wbinfo -a doesn't work reliable with upn names; (bso#15003); * Simple bind doesn't work against an RODC (with non-preloaded users); (bso#13879); * Uninitialized litemask in variable in vfs_gpfs module; (bso#15027); * Regression: create krb5 conf = yes doesn't work with a single KDC; (bso#15016);- Add provides to samba-client-libs package to fix upgrades from previous versions; (bsc#1197995);- Add missing samba-libs requirement to samba-winbind package; (bsc#1198255);- Update to 4.15.6 * Renaming file on DFS root fails with NT_STATUS_OBJECT_PATH_NOT_FOUND; (bso#14169); * Samba does not response STATUS_INVALID_PARAMETER when opening 2 objects with same lease key; (bso#14737); * NT error code is not set when overwriting a file during rename in libsmbclient; (bso#14938); * Fix ldap simple bind with TLS auditing; (bso#14996); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); * Problem when winbind renews Kerberos; (bso#14979); (bsc#1196224); * pam_winbind will not allow gdm login if password about to expire; (bso#8691); * virusfilter_vfs_openat: Not scanned: Directory or special file; (bso#14971); * DFS fix for AIX broken; (bso#13631); * Solaris and AIX acl modules: wrong function arguments; (bso#14974); * Function aixacl_sys_acl_get_file not declared / coredump; (bso#7239); * Regression: Samba 4.15.2 on macOS segfaults intermittently during strcpy in tdbsam_getsampwnam; (bso#14900); * Fix a use-after-free in SMB1 server; (bso#14989); * smb2_signing_decrypt_pdu() may not decrypt with gnutls_aead_cipher_decrypt() from gnutls before 3.5.2; (bso#14968); * Changing the machine password against an RODC likely destroys the domain join; (bso#14984); * authsam_make_user_info_dc() steals memory from its struct ldb_message *msg argument; (bso#14993); * Use Heimdal 8.0 (pre) rather than an earlier snapshot; (bso#14995); * Samba autorid fails to map AD users if id rangesize fits in the id range only once; (bso#14967);- Fix mismatched version of libldb2; (bsc#1196788). - Drop obsolete SuSEfirewall2 service files.- Drop obsolete Samba fsrvp v0->v1 state upgrade functionality; (bsc#1080338).- Fix ntlm authentications with "winbind use default domain = yes"; (bso#13126); (bsc#1173429); (bsc#1196308).- Fix samba-ad-dc status warning notification message by disabling systemd notifications in bgqd; (bsc#1195896); (bso#14947).- libldb version mismatch in Samba dsdb component; (bsc#1118508);- Update to 4.15.5 * CVE-2021-44141: UNIX extensions in SMB1 disclose whether the outside target of a symlink exists; (bso#14911); (bsc#1193690). * CVE-2021-44142: Out-of-Bound Read/Write on Samba vfs_fruit module; (bso#14914); (bsc#1194859). * CVE-2022-0336: Re-adding an SPN skips subsequent SPN conflict checks; bso#14950); (bsc#1195048).- CVE-2021-44141: Information leak via symlinks of existance of files or directories outside of the exported share; (bso#14911); (bsc#1193690); - CVE-2021-44142: Out-of-bounds heap read/write vulnerability in VFS module vfs_fruit allows code execution; (bso#14914); (bsc#1194859); - CVE-2022-0336: Samba AD users with permission to write to an account can impersonate arbitrary services; (bso#14950); (bsc#1195048);- Update to 4.15.4 * Duplicate SMB file_ids leading to Windows client cache poisoning; (bso#14928); * Failed to parse NTLMv2_RESPONSE length 95 - Buffer Size Error - NT_STATUS_BUFFER_TOO_SMALL; (bso#14932); * kill_tcp_connections does not work; (bso#14934); * Can't connect to Windows shares not requiring authentication using KDE/Gnome; (bso#14935); * smbclient -L doesn't set "client max protocol" to NT1 before calling the "Reconnecting with SMB1 for workgroup listing" path; (bso#14939); * Cross device copy of the crossrename module always fails; (bso#14940); * symlinkat function from VFS cap module always fails with an error; (bso#14941); * Fix possible fsp pointer deference; (bso#14942); * Missing pop_sec_ctx() in error path inside close_directory(); (bso#14944); * "smbd --build-options" no longer works without an smb.conf file; (bso#14945);- Use pkgconfig(krb5) as dependency for the -devel package: allow OBS to pick the right flavor of krb5-devel (full vs mini). - Do not require the 'krb5' symbol by samba-client-libs: this package has an automatic dependency due to linkage on libgssapi_krb5.so.2. Automatic deps are always better. - Do not require the 'krb5' symbol from samba-libs: samba-libs requires samba-client-libs, which in turn requires krb5 libraries. Samba-libs itself has no need for krb5 (but get it indirectly anyway).- Reorganize libs packages. Split samba-libs into samba-client-libs, samba-libs, samba-winbind-libs and samba-ad-dc-libs, merging samba public libraries depending on internal samba libraries into these packages as there were dependency problems everytime one of these public libraries changed its version (bsc#1192684). The devel packages are merged into samba-devel. - Rename package samba-core-devel to samba-devel - Add python-rpm-macros to build requirements - Update the symlink create by samba-dsdb-modules to private samba ldb modules following libldb2 changes from /usr/lib64/ldb/samba to /usr/lib64/ldb2/modules/ldb/samba- Update to 4.15.3 * Recursive directory delete with veto files is broken in 4.15.0; (bso#14878); * A directory containing dangling symlinks cannot be deleted by SMB2 alone when they are the only entry in the directory; (bso#14879); * SIGSEGV in rmdir_internals/synthetic_pathref - dirfsp is used uninitialized in rmdir_internals(); (bso#14892); * MaxQueryDuration not honoured in Samba AD DC LDAP; (bso#14694); * The CVE-2020-25717 username map [script] advice has undesired side effects for the local nt token; (bso#14901); (bsc#1192849); * User with multiple spaces (eg FredNurk) become un-deletable; (bso#14902); * Avoid storing NTTIME_THAW (-2) as value on disk; (bso#14127); * smbXsrv_client_global record validation leads to crash if existing record points at non-existing process; (bso#14882); * Crash in vfs_fruit asking for fsp_get_io_fd() for an XATTR call; (bso#14890); * Samba process doesn't log to logfile; (bso#14897); * set_ea_dos_attribute() fallback calling get_file_handle_for_metadata() triggers locking.tdb assert; (bso#14907); * Kerberos authentication on standalone server in MIT realm broken; (bso#14922); * Segmentation fault when joining the domain; (bso#14923); * Support for ROLE_IPA_DC is incomplete; (bso#14903); * rpcclient cannot connect to ncacn_ip_tcp services anymore; (bso#14767); * winexe crashes since 4.15.0 after popt parsing; (bso#14893); * net ads status -P broken in a clustered environment; (bso#14908); * Memory leak if ioctl(FSCTL_VALIDATE_NEGOTIATE_INFO) fails before smbd_smb2_ioctl_send; (bso#14788); * winbindd doesn't start when "allow trusted domains" is off; (bso#14899); * smbclient login without password using '-N' fails with NT_STATUS_INVALID_PARAMETER on Samba AD DC; (bso#14883); * A schannel client incorrectly detects a downgrade connecting to an AES only server; (bso#14912); * Possible null pointer dereference in winbind; (bso#14921); * Fix -k legacy option for client tools like smbclient, rpcclient, net, etc.; (bso#14846); * Add Debian 11 CI bootstrap support; (bso#14872); * Crash in recycle_unlink_internal(); (bso#14888);- Fix dependency problem upgrading from libndr0 to libndr2 and from libsamba-credentials0 to libsamba-credentials1; (bsc#1192684);- Fix regression introduced by CVE-2020-25717 patches, winbindd does not start when 'allow trusted domains' is off; (bso#14899); - Update to 4.15.2 * CVE-2016-2124: SMB1 client connections can be downgraded to plaintext authentication; (bso#12444); (bsc#1014440); * CVE-2020-25717: A user on the domain can become root on domain members; (bso#14556); (bsc#1192284); * CVE-2020-25718: Samba AD DC did not correctly sandbox Kerberos tickets issued by an RODC; (bso#14558); (bsc#1192246); * CVE-2020-25719: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets; (bso#14561); (bsc#1192247); * CVE-2020-25721: Kerberos acceptors need easy access to stable AD identifiers (eg objectSid); (bso#14557); (bsc#1192505); * CVE-2020-25722: Samba AD DC did not do suffienct access and conformance checking of data stored; (bso#14564); (bsc#1192283); * CVE-2021-3738: Use after free in Samba AD DC RPC server; (bso#14468); (bsc#1192215); * CVE-2021-23192: Subsequent DCE/RPC fragment injection vulnerability; (bso#14875); (bsc#1192214); - Update to 4.15.1 * vfs_shadow_copy2: core dump in make_relative_path; (bso#14682); * Log clutter from filename_convert_internal; (bso#14685); * MacOSX compilation fixes; (bso#14862); * rodc_rwdc test flaps; (bso#14868); * Provide a fix for MS CVE-2020-17049 in Samba [SECURITY] 'Bronze bit' S4U2Proxy Constrained Delegation bypass in Samba with embedded Heimdal; (bso#14642); * Python ldb.msg_diff() memory handling failure; (bso#14836); * "in" operator on ldb.Message is case sensitive; (bso#14845); * Release LDB 2.4.1 for Samba 4.15.1; (bso#14848); * samldb_krbtgtnumber_available() looks for incorrect string; (bso#14854); * Fix Samba support for UF_NO_AUTH_DATA_REQUIRED; (bso#14871); * Allow special chars like "@" in samAccountName when generating the salt; (bso#14874); * Correctly ignore comments in CTDB public addresses file; (bso#14826); * Fix transit path validation; (bso#12998); * Fix that child winbindd logs to log.winbindd instead of log.wb-; (bso#14852); * SMB3 cancel requests should only include the MID together with AsyncID when AES-128-GMAC is used; (bso#14855); * Prepare to operate with MIT krb5 >= 1.20; (bso#14870); * Heimdal prefers RC4 over AES for machine accounts; (bso#14864);- Enable samba-tool without ad dc.- Adjust spec to use pam macros; (bsc#1191046).- Adjust spec for size * allow some Recommends instead Requires to be configured for cifs-utils, samba-libs-python3 & samba-gpupdate; (bsc#1182847). * remove fam, undocumented and unneeded.- Add missing build dependency on bison when building with the embedded Heimdal Kerberos- Update to 4.15.0 * Removed SMB development dialects SMB2_22, SMB2_24 and SMB3_10 * VFS layer modernized. * Add the ability to set allow/deny lists for zone transfer clients in Bind DLZ plugin * Server multi-channel support no longer experimental * Improved command line user experience, unifying the options in different commands * Winbindd no longer scans trusted domains on startup and will use enterprise principals by default. * The net utility is now able to support the offline domain join feature * New options for 'samba-tool dns zoneoptions' for aging control and to mark old records as static or dynamic * DNS tombstones are now deleted as appropriate and use a consistent timestamp format * The 'samba-tool dns update' command validates and rejects now malformed IPv4 and IPv6 addresses * The 'samba-tool domain backup' command correctly takes out locks against concurrent modification during backup when using the LMDB backend * TruACL support has been removed * NIS support has been removed- Fix 'net rpc' authentication when using the machine account; (bsc#1189017); (bso#14796);- Fix dependency problem upgrading from libndr0 to libndr1; (bsc#1189875); - Fix dependency problem upgrading from libsmbldap0 to libsmbldap2; (bsc#1189875); - Fix wrong kvno exported to keytab after net ads changetrustpw due to replication delay; (bsc#1188727); - Add Certificate Auto Enrollment Policy; (jsc#SLE-18456). - Update to 4.13.10 * s3: smbd: Ensure POSIX default ACL is mapped into returned Windows ACL for directory handles; (bso#14708); * Take a copy to make sure we don't reference free'd memory; (bso#14721); * s3: lib: Fix talloc heirarcy error in parent_smb_fname(); (bso#14722); * s3: smbd: Remove erroneous TALLOC_FREE(smb_fname_parent) in change_file_owner_to_parent() error path; (bso#14736); * samba-tool: Give better error information when the 'domain backup restore' fails with a duplicate SID; (bso#14575); * smbd: Correctly initialize close timestamp fields; (bso#14714); * Spotlight RPC service doesn't work with vfs_glusterfs; (bso#14740); * ctdb: Fix a crash in run_proc_signal_handler(); (bso#14475); * gensec_krb5: Restore ipv6 support for kpasswd; (bso#14750); * smbXsrv_{open,session,tcon}: Protect smbXsrv_{open,session,tcon}_global_traverse_fn against invalid records; (bso#14752); * samba-tool domain backup offline doesn't work against bind DLZ backend; (bso#14027); * netcmd: Use next_free_rid() function to calculate a SID for restoring a backup; (bso#14669); - Update to 4.13.9 * s3: smbd: SMB1 SMBsplwr doesn't send a reply packet on success; (bso#14696); * Add documentation for dsdb_group_audit and dsdb_group_json_audit to "log level", synchronise "log level" in smb.conf with the code; (bso#14689); * Fix smbd panic when two clients open same file; (bso#14672); * Fix memory leak in the RPC server; (bso#14675); * s3: smbd: Fix deferred renames; (bso#14679); * s3-iremotewinspool: Set the per-request memory context; (bso#14675); * rpc_server3: Fix a memleak for internal pipes; (bso#14675); * third_party: Update socket_wrapper to version 1.3.2; (bso#11899); * third_party: Update socket_wrapper to version 1.3.3; (bso#14639); * idmap_rfc2307 and idmap_nss return wrong mapping for uid/gid conflict; (bso#14663); * Fix the build on OmniOS; (bso#14288); - Update to 4.13.8 * CVE-2021-20254: Fix buffer overrun in sids_to_unixids(); (bso#14571 - Update to 4.13.7 * Release with dependency on ldb version 2.2.1.- CVE-2021-20254 Buffer overrun in sids_to_unixids(); (bnc#14571); (bsc#1184677).- Fix offline domain backup not possible using lmdb version >= 0.9.26; (bso#14676); - Require libldb >= 2.2.1; (bsc#1183572); (bsc#1183574); - Update to 4.13.6 * CVE-2020-27840: samba: Unauthenticated remote heap corruption via bad DNs; (bso#14595); (bsc#1183572). * CVE-2021-20277: samba: out of bounds read in ldb_handler_fold; (bso#14655); (bsc#1183574). - Update to 4.13.5 * s3:modules:vfs_virusfilter: Recent talloc changes cause infinite start-up failure; (bso#14634); * s3: libsmb: Add missing cli_tdis() in error path if encryption setup failed on temp proxy connection; (bso#13992); * smbd: In conn_force_tdis_done() when forcing a connection closed force a full reload of services; (bso#14604); * dbcheck: Check Deleted Objects and reduce noise in reports about expired tombstones (bso#14593); * s3: Fix fcntl waf configure check; (bso#14503); * s3/auth: Implement "winbind:ignore domains"; (bso#14602); * smbd: Use fsp->conn->session_info for the initial delete-on-close token; (bso#14617); * s3: VFS: nfs4_acls. Add missing TALLOC_FREE(frame) in error path; (bso#14648); * classicupgrade: Treat old never expires value right; (bso#14624); * g_lock: Fix uninitalized variable reads; (bso#14636); * s3:pysmbd: Fix fd leak in py_smbd_create_file(); (bso#13898); * lib:util: Avoid free'ing our own pointer; (bso#14625); * HEIMDAL: krb5_storage_free(NULL) should work; (bso#12505);- Spec file fixes around systemd and requires; (bsc#1182830); - Align systemd service unit files with upstream provided ones.- Update to 4.13.4 * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * lib: Avoid declaring zero-length VLAs in various messaging functions; (bso#14605); * Do not create an empty DB when accessing a sam.ldb; (bso#14579); * vfs_fruit may close wrong backend fd; (bso#14596); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * vfs_virusfilter: Allocate separate memory for config char*; (bso#14606); * vfs_fruit may close wrong backend fd; (bso#14596); * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * The cache directory for the user gencache should be created recursively; (bso#14601); * Be more flexible with repository names in CentOS 8 test environments; (bso#14594);- Uninstalling samba-client: Failed to disable unit, cifs.service does not exists; (bsc#1180388);- Update to 4.13.3 + libcli: smb2: Never print length if smb2_signing_key_valid() fails for crypto blob; (bso#14210); + s3: modules: gluster. Fix the error I made in preventing talloc leaks from a function; (bso#14486); + s3: smbd: Don't overwrite contents of fsp->aio_requests[0] with NULL via TALLOC_FREE(); (bso#14515); + s3: spoolss: Make parameters in call to user_ok_token() match all other uses; (bso#14568); + s3: smbd: Quiet log messages from usershares for an unknown share; (bso#14590); + samba process does not honor max log size; (bso#14248); + vfs_zfsacl: Add missing inherited flag on hidden "magic" everyone@ ACE; (bso#14587); + s3-libads: Pass timeout to open_socket_out in ms; (bso#13124); + s3-vfs_glusterfs: Always disable write-behind translator; (bso#14486); + smbclient: Fix recursive mget; (bso#14517); + clitar: Use do_list()'s recursion in clitar.c; (bso#14581); + manpages/vfs_glusterfs: Mention silent skipping of write-behind translator; (bso#14486); + vfs_shadow_copy2: Preserve all open flags assuming ROFS; (bso#14573); + interface: Fix if_index is not parsed correctly; (bso#14514);- Update to 4.13.2 + s3: modules: vfs_glusterfs: Fix leak of char **lines onto mem_ctx on return; (bso#14486); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471); + smb.conf.5: Add clarification how configuration changes reflected by Samba; (bso#14538); + daemons: Report status to systemd even when running in foreground; (bso#14552); + DNS Resolver: Support both dnspython before and after 2.0.0; (bso#14553); + s3-vfs_glusterfs: Refuse connection when write-behind xlator is present; (bso#14486); + provision: Add support for BIND 9.16.x; (bso#14487); + ctdb-common: Avoid aliasing errors during code optimization; (bso#14537); + libndr: Avoid assigning duplicate versions to symbols; (bso#14541); + docs: Fix default value of spoolss:architecture; (bso#14522); + winbind: Fix a memleak; (bso#14388); + s4:dsdb:acl_read: Implement "List Object" mode feature; (bso#14531); + docs-xml/manpages: Add warning about write-behind translator for vfs_glusterfs; (bso#14486); + nsswitch/nsstest.c: Avoid nss function conflicts with glibc nss.h. + vfs_shadow_copy2: Avoid closing snapsdir twice; (bso#14530); + third_party: Update resolv_wrapper to version 1.1.7; (bso#14547); + examples:auth: Do not install example plugin; (bso#14550); + ctdb-recoverd: Drop unnecessary and broken code; (bso#14513); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471);- Adjust smbcacls '--propagate-inheritance' feature to align with upstream; (bsc#1178469).- Update to samba 4.13.1 + CVE-2020-14383: An authenticated user can crash the DCE/RPC DNS with easily crafted records; (bsc#1177613); (bso#14472); + CVE-2020-14323: Unprivileged user can crash winbind; (bsc#1173994); (bso#14436); + CVE-2020-14318: Missing handle permissions check in SMB1/2/3 ChangeNotify; (bsc#1173902); (bso#14434); - Adjust systemd tmpfiles.d configuration, use /run/samba instead of /var/run/samba; (bsc#1177355);- Fix vfs_ceph query_directory regression; (bso#14519) - Drop liburing-devel for SLE15-SP2; (bsc#1177245)- Register CTDB recovery lock holder with ceph-mgr - Add liburing-devel dependency- Update to samba 4.13.0 + Require Python 3.6 + Move wide links functionality into VFS module + Deprecate NT4-like 'classic' Samba domain controllers + Deprecate SMBv1 only protocol options + Remove deprecated "ldap ssl ads" option + Unify asynchronous DCE-RPC server; (jsc#SES-645) + Replay multichannel lease break requests; (bso#11897); (jsc#SES-655) + Drop internal byteorder.h header from util-devel package + Remove final code for the AD DC LDAP backend + Add AD DC Group Policy Scripts + Only use gnutls_aead_cipher_encryptv2() for GnuTLS > 3.6.14; (bso#14399) + Fix %U substitutions if it contains a domain name; (bso#14467) + Fix krb5.conf creation for 'net ads join'; (bso#14479) + Fix build problem if libbsd-dev is not installed; (bso#14482) + Toggle vfs_snapper using "--with-shared-modules"; (bso#14437) + Fix idmap_ad RFC4511 response handling; (bso#14465) + Fix panic in get_lease_type(); (bso#14428)- Update to samba 4.11.13 + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Protect netr_ServerPasswordSet2 against unencrypted passwords; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Support "server require schannel:WORKSTATION$ = no" about unsecure configurations; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s4 torture rpc: repeated bytes in client challenge; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): libcli/auth: Reject weak client challenges in netlogon_creds_server_init() "server require schannel:WORKSTATION$ = no"; (bsc#1176579); (bso#14497); - Update to samba 4.11.12 + s3: libsmb: Fix SMB2 client rename bug to a Windows server; (bso#14403); + dsdb: Allow "password hash userPassword schemes = CryptSHA256" to work on RHEL7; (bso#14424); + dbcheck: Allow a dangling forward link outside our known NCs; (bso#14450); + lib/debug: Set the correct default backend loglevel to MAX_DEBUG_LEVEL; (bso#14426); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + lib/util: do not install "test_util_paths"; (bso#14370); + lib:util: Fix smbclient -l basename dir; (bso#14345); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + util: Allow symlinks in directory_create_or_exist; (bso#14166); + docs: Fix documentation for require_membership_of of pam_winbind; (bso#14358); + s3:winbind:idmap_ad: Make failure to get attrnames for schema mode fatal; (bso#14425);- Add obsoletes to libsmbldap2 package to fix upgrades from previous versions; (bsc#1172810);- Fix net command unable to negotiate SMB2; (bsc#1174120);- Update to samba 4.11.11 + CVE-2020-10730: NULL de-reference in AD DC LDAP server when ASQ and VLV combined; (bso#14364); (bsc#1173159] + CVE-2020-10745: invalid DNS or NBT queries containing dots use several seconds of CPU each; (bso#14378); (bsc#1173160). + CVE-2020-10760: Use-after-free in AD DC Global Catalog LDAP server with paged_result or VLV; (bso#14402); (bsc#1173161) + CVE-2020-14303: Endless loop from empty UDP packet sent to AD DC nbt_server; (bso#14417); (bsc#1173359). - Update to samba 4.11.10 + Fix segfault when using SMBC_opendir_ctx() routine for share folder that contains incorrect symbols in any file name; (bso#14374). + vfs_shadow_copy2 doesn't fail case looking in snapdirseverywhere mode; (bso#14350) + ldb_ldap: Fix off-by-one increment in lldb_add_msg_attr; (bso#14413). + Malicous SMB1 server can crash libsmbclient; (bso#14366) + winbindd: Fix a use-after-free when winbind clients exit; (bso#14382) + ldb: Bump version to 2.0.11, LMDB databases can grow without bounds. (bso#14330) - Update to samba 4.11.9 + nmblib: Avoid undefined behaviour in handle_name_ptrs(); (bso#14242). + 'samba-tool group' commands do not handle group names with special chars correctly; (bso#14296). + smbd: avoid calling vfs_file_id_from_sbuf() if statinfo is not valid; (bso#14237). + Missing check for DMAPI offline status in async DOS attributes; (bso#14293). + smbd: Ignore set NTACL requests which contain S-1-5-88 NFS ACEs; (bso#14307). + vfs_recycle: Prevent flooding the log if we're called on non-existant paths; (bso#14316) + smbd mistakenly updates a file's write-time on close; (bso#14320). + RPC handles cannot be differentiated in source3 RPC server; (bso#14359). + librpc: Fix IDL for svcctl_ChangeServiceConfigW; (bso#14313). + nsswitch: Fix use-after-free causing segfault in _pam_delete_cred; (bso#14327). + Fix fruit:time machine max size on arm; (bso#13622) + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294). + ctdb: Fix a memleak; (bso#14348). + libsmb: Don't try to find posix stat info in SMBC_getatr(). + ctdb-tcp: Move free of inbound queue to TCP restart; (bso#14295); (bsc#1162680). + s3/librpc/crypto: Fix double free with unresolved credential cache; (bso#14344); (bsc#1169095) + s3:libads: Fix ads_get_upn(); (bso#14336). + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294) + Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680). + ctdb-recoverd: Avoid dereferencing NULL rec->nodemap; (bso#14324) - Update to samba 4.11.8 + CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850); + CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - Update to samba 4.11.7 + s3: lib: nmblib. Clean up and harden nmb packet processing; (bso#14239). + s3: VFS: full_audit. Use system session_info if called from a temporary share definition; (bso#14283) + dsdb: Correctly handle memory in objectclass_attrs; (bso#14258). + ldb: version 2.0.9, Samba 4.11 and later give incorrect results for SCOPE_ONE searches; (bso#14270) + auth: Fix CIDs 1458418 and 1458420 Null pointer dereferences; (bso#14247). + smbd: Handle EINTR from open(2) properly; (bso#14285) + winbind member (source3) fails local SAM auth with empty domain name; (bso#14247) + winbindd: Handling missing idmap in getgrgid(); (bso#14265). + lib:util: Log mkdir error on correct debug levels; (bso#14253). + wafsamba: Do not use 'rU' as the 'U' is deprecated in Python 3.9; (bso#14266). + ctdb-tcp: Make error handling for outbound connection consistent; (bso#14274). - Update to samba 4.11.6 + pygpo: Use correct method flags; (bso#14209). + vfs_ceph_snapshots: Fix root relative path handling; (bso#14216); (bsc#1141320). + Avoiding bad call flags with python 3.8, using METH_NOARGS instead of zero; (bso#14209). + source4/utils/oLschema2ldif: Include stdint.h before cmocka.h; (bso#14218). + docs-xml/winbindnssinfo: Clarify interaction with idmap_ad etc; (bso#14122). + smbd: Fix the build with clang; (bso#14251). + upgradedns: Ensure lmdb lock files linked; (bso#14199). + s3: VFS: glusterfs: Reset nlinks for symlink entries during readdir; (bso#14182). + smbc_stat() doesn't return the correct st_mode and also the uid/gid is not filled (SMBv1) file; (bso#14101). + librpc: Fix string length checking in ndr_pull_charset_to_null(); (bso#14219). + ctdb-scripts: Strip square brackets when gathering connection info; (bso#14227).- Add libnetapi-devel to baselibs conf, for wine usage; (bsc#1172307);- Installing: samba - samba-ad-dc.service does not exist and unit not found; (bsc#1171437);- Fix samba_winbind package is installing python3-base without python3 package; (bsc#1169521);- Require libldb2 >= 2.0.10 after security release.- CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850);- Fix smbclient crash with double free (with unresolved krb5 credential cache); (bso#14344); (bsc#1169095).- Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680).- CTDB doesn't retry outgoing connections on bind (and some other) failures; (bso#14274); (bsc#1162680).- Revert: Allow idmap_rid to have primary group other than "Domain Users"; (bsc#1087931).- Fix nmbstatus not reporting detailed information about workgroups; (bsc#1159464); - Fix querying all names registered within broadcast area; (bso#8927);- Update to samab 4.11.5 + CVE-2019-14902: Replication of ACLs down subtree on AD Directory is not automatic; (bso#12497); (bsc#1160850). + CVE-2019-19344: Fix server crash with dns zone scavenging = yes; (bso#14050); (bsc#1160852). + CVE-2019-14907: server-side crash after charset conversion failure (eg during NTLMSSP processing); (bso#14208); (bsc#1160888). - Update to samba 4.11.4 + Ensure SMB1 cli_qpathinfo2() doesn't return an inode number; (bso#14161). + Ensure we don't call cli_RNetShareEnum() on an SMB1 connection; (bso#14174). + NT_STATUS_ACCESS_DENIED becomes EINVAL when using SMB2 in SMBC_opendir_ctx; (bso#14176). + SMB2 - Ensure we use the correct session_id if encrypting an interim response; (bso#14189). + Prevent smbd crash after invalid SMB1 negprot; (bso#14205). + printing: Fix %J substition; (bso#13745). + Remove now unneeded call to cmdline_messaging_context(); (bso#13925). + Fix incomplete conversion of former parametric options; (bso#14069). + Fix sync dosmode fallback in async dosmode codepath; (bso#14070). + vfs_fruit returns capped resource fork length; (bso#14171). + libnet_join: Add SPNs for additional-dns-hostnames entries; (bso#14116). + smbd: Increase a debug level; (bso#14211). + Prevent azure ad connect from reporting discovery errors reference-value-not-ldap-conformant; (bso#14153). + krb5_plugin: Fix developer build with newer heimdal system library; (bso#14179). + replace: Only link libnsl and libsocket if required; (bso#14168); + ctdb: Incoming queue can be orphaned causing communication; breakdown; (bso#14175). + ldb: Release ldb 2.0.8. Cross-compile will not take cross-answers or cross-execute; (bso#13846). + heimdal-build: Avoid hard-coded /usr/include/heimdal in asn1_compile-generated code; (bso#13856).- Fix Ceph snapshot root relative path handling; (bso#14216); (bsc#1141320).- Update to samba 4.11.3 + CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). + CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). - CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- Update to samba 4.11.2 + CVE-2019-10218: Client code can return filenames containing path separators; (bsc#1144902); (bso#14071). + CVE-2019-14833: Samba AD DC check password script does not receive the full password; (bso#12438). + CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040). - Fixes from 4.11.1 + Overlinking libreplace against librt and pthread against every binary or library causes issues; (bso#14140); + kpasswd fails when built with MIT Kerberos; (bso#14155); + Fix spnego fallback from kerberos to ntlmssp in smbd server; (bso#14106); + Stale file handle error when using mkstemp on a share; (bso#14137); + non-AES schannel broken; (bso#14134); + Joining Active Directory should not use SAMR to set the password; (bso#13884); + smbclient can blunder into the SMB1 specific cli_RNetShareEnum() call on an SMB2 connection; (bso#14152); + Deleted records can be resurrected during recovery; (bso#14147); + getpwnam and getpwuid need to return data for ID_TYPE_BOTH group; (bso#14141); + winbind does not list forest trusts with additional trust attributes; (bso#14130); + fault report points to outdated documentation; (bso#14139); + pam_winbind with krb5_auth or wbinfo -K doesn't work for users of trusted domains/forests; (bso#14124); + classicupgrade results in uncaught exception - a bytes-like object is required, not 'str'; (bso#14136); + pod2man is not longer required, stop checking at build time; (bso#14131); + Exit code of ctdb nodestatus should not be influenced by deleted nodes; (bso#14129); + username/password authentication doesn't work with CUPS and smbspool; (bso#14128); + smbc_readdirplus() is incompatible with smbc_telldir() and smbc_lseekdir(); (bso#14094);- CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040); (bsc#1154598); - CVE-2019-10218: Client code can return filenames containing path separators; (bso#14071); (bsc#1144902);- CVE-2019-14833: samba: Accent with "check script password" Samba AD DC check password script does not receive the full password; (bso#12438); (bsc#1154289).- Update to samba 4.11.0 + For details on all items see WHATSNEW.txt in samba-doc package + Python2 runtime support removed; python 3.4 or later required + Security improvements: - SMB1 disabled by default - lanman and plaintext authentication deprecated - winbind: PAM_AUTH and NTLM_AUTH events logged - GnuTLS 3.2 required; system FIPS mode setting honored + CephFS Snapshot integration, exposed as previous file versions + ctdb changes: - onnode -o option removed - ctdbd logs when using more than 90% of a CPU thread - CTDB_MONITOR_SWAP_USAGE variable removed + AD Domain controller improvements: - Upgrade AD databse format - BIND9_FLATFILE deprecated - default process model chagned to prefork - bind9 dns operation duration logging - Default schema updated to 2012_R2; function level is unchanged - many performance improvements + Configuration webserver support removed- Fix broken username/password authentication with CUPS and smbspool; (bsc#1152143); (bso#14128).- Fix auth problems when printing via smbspool backend with kerberos; (bnc#1148539); (bso#13832).- Update to samba 4.10.8 + CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267);- Fix build on newer systems by modifying samba.spec to use consistent non-relative paths for pammodules in configure line and specification of pam_winbind.so library to package.- Update to samba 4.10.7 + Unable to create or rename file/directory inside shares configured with vfs_glusterfs_fuse module; (bso#14010). + build: Allow build when '--disable-gnutls' is set; (bso#13844) + samba-tool: Add 'import samba.drs_utils' to fsmo.py; (bso#13973). + Fix 'Error 32 determining PSOs in system' message on old DB with FL upgrade; (bso#14008). + s4/libnet: Fix joining a Windows pre-2008R2 DC; (bso#14021) + join: Use a specific attribute order for the DsAddEntry nTDSDSA object; (bso#14046). + vfs_catia: Pass stat info to synthetic_smb_fname(); (bso#14015). + lookup_name: Allow own domain lookup when flags == 0; (bso#14091). + s4 librpc rpc pyrpc: Ensure tevent_context deleted last; (bso#13932). + DEBUGC and DEBUGADDC doesn't print into a class specific log file; (bso#13915). + Request to keep deprecated option "server schannel", VMWare Quickprep requires "auto"; (bso#13949). + dbcheck: Fallback to the default tombstoneLifetime of 180 days; (bso#13967). + dnsProperty fails to decode values from older Windows versions; (bso#13969). + samba-tool: Use only one LDAP modify for dns partition fsmo role transfer; (bso#13973). + third_party: Update waf to version 2.0.17; (bso#13960). + netcmd: Allow 'drs replicate --local' to create partitions; (bso#14051). + ctdb-config: Depend on /etc/ctdb/nodes file; (bso#14017).- CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267).- Prepare for use future use of kernel keyrings, modify /etc/pam.d/samba to include pam_keyinit.so; (bsc#1144059).- Update samba-winbind script to work with systemd; (bsc#1132739); - Drop samba dhcpcd hook scripts - Update to samba 4.10.6 + s3: winbind: Fix crash when invoking winbind idmap scripts; (bso#13956). + smbd does not correctly parse arguments passed to dfree and quota scripts; (bso#13964). + samba-tool dns: use bytes for inet_ntop; (bso#13965). + samba-tool domain provision: Fix --interactive module in python3; (bso#13828). + ldb_kv: Skip @ records early in a search full scan; (bso#13893). + docs: Improve documentation of "lanman auth" and "ntlm auth" connection; (bso#13981). + python/ntacls: Use correct "state directory" smb.conf option instead of "state dir"; (bso#14002). + registry: Add a missing include; (bso#13840). + Fix SMB guest authentication; (bso#13944). + AppleDouble conversion breaks Resourceforks; (bso#13958). + vfs_fruit makes direct use of syscalls like mmap() and pread(); (bso#13968). + s3:mdssvc: Fix flex compilation error; (bso#13987). + s3/vfs_glusterfs[_fuse]: Avoid using NAME_MAX directly; (bso#13872). + dsdb:samdb: schemainfo update with relax control; (bso#13799). + s3:util: Move static file_pload() function to lib/util; (bso#13964). + smbd: Fix a panic; (bso#13957). + ldap server: Generate correct referral schemes; (bso#12478). + s4 dsdb/repl_meta_data: fix use after free in dsdb_audit_add_ldb_value; (bso#13941). + s4 dsdb: Fix use after free in samldb_rename_search_base_callback; (bso#13942). + dsdb/repl: we need to replicate the whole schema before we can apply it; (bso#12204). + ldb: Release ldb 1.5.5; (bso#12478). + Schema replication fails if link crosses chunk boundary backwards; (bso#13713). + 'samba-tool domain schemaupgrade' uses relax control and skips the schemaInfo update provision; (bso#13799). + dsdb_audit: avoid printing "... remote host [Unknown] SID [(NULL SID)] ..."; (bso#13916). + python/ntacls: We only need security.SEC_STD_READ_CONTROL in order to get the ACL; (bso#13917). + s3:loadparm: Ensure to truncate FS Volume Label at multibyte boundary; (bso#13947). + Using Kerberos credentials to print using spoolss doesn't work; (bso#13939). + wafsamba: Use native waf timer; (bso#13998). + ctdb-scripts: Fix tcp_tw_recycle existence check; (bso#13984).- Update to samba-4.10.5 (including updates for 4.10.4, 4.10.3) + CVE-2019-12435 rpc/dns: Avoid NULL deference if zone not found in DnssrvOperation2; (bso#13922); (bsc#1137815). + CVE-2019-12436 dsdb/paged_results: Ignore successful results without messages; (bso#13951); (bsc#1137816). - Update to samba-4.10.4 + s3: SMB1: Don't allow recvfile on stream fsp's; (bso#13938). + py/provision: Fix for Python 2.6; (bso#13882). + netcmd: Fix 'passwordsettings --max-pwd-age' command; (bso#13873). + s3-libnet_join: 'net ads join' to child domain fails when using "-U admin@forestroot"; (bso#13861). + vfs_ceph: Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245). + vfs_ceph: Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). + ctdb-common: Avoid race between fd and signal events; (bso#13895). + ctdb-common: Fix memory leak in run_proc; (bso#13943). + lib: Initialize getline() arguments; (bso#13892). + winbind: Fix overlapping id ranges; (bco#13903). + lib util debug: Increase format buffer to 4KiB; (bso#13902). + nsswitch pam_winbind: Fix Asan use after free; (bso#13927). + s4 lib socket: Ensure address string owned by parent struct; (bso#13929). + s3 rpc_client: Fix Asan stack use after scope; (bso#13936). + s3:smbd: Handle IO_REPARSE_TAG_DFS in SMB_FIND_FILE_FULL_DIRECTORY_INFO; (bso#10097). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#10344). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#12845). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#13698). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#13796). + dbcheck: Fix the err_empty_attribute() check; (bso#13843). + vfs_snapper: Drop unneeded fstat handler; (bso#13858). + vfs_default: Fix vfswrap_offload_write_send() NT_STATUS_INVALID_VIEW_SIZE check; (bso#13862). + smb2_server: Grant all 8192 credits to clients; (bso#13863). + smbd: Implement SMB_FILE_NORMALIZED_NAME_INFORMATION handling; (bso#13919). + s3/vfs_glusterfs: Dynamically determine NAME_MAX; (bso#13872). + s3: modules: ceph: Use current working directory instead of share path; (bso#13918); (bsc#1134452). + winbind: Use domain name from lsa query for sid_to_name cache entry; (bso#13831). + memcache: Increase size of default memcache to 512k; (bso#13865). + docs: Update smbclient manpage for "--max-protocol"; (bso#13857). + s3:utils: If share is NULL in smbcacls, don't print it; (bso#13937). + s3:smbspool: Fix regression printing with Kerberos credentials; (bso#13939). + ctdb-scripts: CTDB restarts failed NFS RPC services by hand, which is incompatible with systemd; (bso#13860). + ctdb-daemon: Revert "We can not assume that just because we could complete a TCP handshake"; (bso#13888). + ctdb-daemon: Never use 0 as a client ID; (bso#13930). + ctdb-common: Fix memory leak; (bso#13943). + s3:debug: Enable logging for early startup failures; (bso#13904) - Update to samba-4.10.3 + CVE-2018-16860: Heimdal KDC: Reject PA-S4U2Self with unkeyed checksum; (bso#13685); (bsc#1134024).- CVE-2019-12435: zone operations can crash rpc server; (bso#13922); (bsc#1137815).- Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). - Add ceph_snapshots VFS module; (jsc#SES-183).- Fix vfs_ceph realpath; (bso#13918); (bsc#1134452).- Update to samba-4.10.2: + CVE-2019-3870 (World writable files in Samba AD DC private/ dir); (bso#13834). + CVE-2019-3880 (Save registry file outside share as unprivileged user); (bso#13851). + py/kcc_utils: py2.6 compatibility; (bso#13837). + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869). + regfio: Improve handling of malformed registry hive files; (bso#13840). + ctdb-version: Simplify version string usage; (bso#13789). + lib: Make fd_load work for non-regular files; (bso#13859). + dbcheck: in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816). + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818). + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854). + acl_read: Fix regression for empty lists; (bso#13836). + s4:dlz make b9_has_soa check dc=@ node; (bso#13841). + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832). + s4:librpc: Fix installation of Samba; (bso#13847). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853). * ctdb-build: Drop creation of .distversion in tarball; (bso#13789). * ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838). - Update to samba-4.10.1: + py/kcc_utils: py2.6 compatibility; (bso#13837); + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869); + regfio: Improve handling of malformed registry hive files; (bso#13840); + ctdb-version: Simplify version string usage; (bso#13789); + lib: Make fd_load work for non-regular files; (bso#13859); + dbcheck in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816); + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818); + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854); + acl_read: Fix regression for empty lists; (bso#13836); + s4:dlz make b9_has_soa check dc=@ node; (bso#13841); + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832); + s4:librpc: Fix installation of Samba; (bso#13847); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853); + ctdb-build: Drop creation of .distversion in tarball; (bso#13789); + ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838); - Update to samba-4.10.0: + s4-server: Open and close a transaction on sam.ldb at startup; (bso#13760); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s4/scripting/bin: Open unicode files with utf8 encoding and write + unicode string. + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + Fix idmap cache pollution with S-1-22- IDs on winbind hickup; (bso#13813); + passdb: Update ABI to 0.27.2. + lib/winbind_util: Add winbind_xid_to_sid for --without-winbind; (bso#13813); + lib:util: Move debug message for mkdir failing to log level 1; (bso#13823);- MacOS credit accounting breaks with async SESSION SETUP; (bsc#1125601); (bso#13796). - Mac OS X SMB2 implmenetation sees Input/output error or Resource temporarily unavailable and drops connection; (bso#13698)- Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245).- CVE-2019-3880: Save registry file outside share as unprivileged user; (bso#13851); (bsc#1131060 ).- CVE-2019-3870 pysmbd: missing restoration of original umask after umask(0); (bso#13834); (bsc#1130703);- Update to samba-4.9.5 + audit_logging: Remove debug log header and JSON Authentication: prefix; (bso#13714); + Fix upgrade from 4.7 (or earlier) to 4.9; (bso#13760); + s3: lib: nmbname: Ensure we limit the NetBIOS name correctly; (bso# CID: 1433607; (bso#11495); + smbd: uid: Don't crash if 'force group' is added to an existing share connection; (bso#13690); + s3: VFS: vfs_fruit. Fix the NetAtalk deny mode compatibility code; (bso#13770); + s3: SMB1 POSIX mkdir does case insensitive name lookup; (bso#13803); + s3:utils/smbget fix recursive download with empty source directories; (bso#13199); + samba-tool drs showrepl: Do not crash if no dnsHostName found; (bso#13716); + s3:libsmb: cli_smb2_list() can sometimes fail initially on a connection; (bso#13736); + join: Throw CommandError instead of Exception for simple errors; (bso#13747); + ldb: Avoid inefficient one-level searches; (bso#13762); + s3: libsmb: use smb2cli_conn_max_trans_size() in cli_smb2_list(); (bso#13736); + tldap: Avoid use after free errors; (bso#13776); + Fix idmap xid2sid cache churn; (bso#13802); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s3-smbd: Avoid assuming fsp is always intact after close_file call; (bso#13720); + s3-vfs-fruit: Add close call; (bso#13725); + s3-smbd: Use fruit:model string for mDNS registration; (bso#13746); + s3-vfs: add glusterfs_fuse vfs module; (bso#13774); + printing: Check lp_load_printers() prior to pcap cache update; (bso#13766); + vfs_ceph: vfs_ceph strict_allocate_ftruncate calls (local FS) ftruncate and fallocate; (bso#13807); + lib/audit_logging: Actually create talloc; (bso#13737); + netcmd/user: python[3]-gpgme unsupported and replaced by python[3]-gpg; (bso#13728); + dns: Changing onelevel search for wildcard to subtree; (bso#13738); + samba-tool: Don't print backtrace on simple DNS errors; (bso#13721); + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + ctdb: Print locks latency in machinereadable stats; (bso#13742); + messages_dgm: Messaging gets stuck when pids are recycled; (bso#13786); + audit_logging: auth_json_audit required auth_json; (bso#13715); + man pages: Document prefork process model; (bso#13765); + CVE-2019-3824 ldb: Release ldb 1.4.6; (bso#13773); + s3:auth: ignore create_builtin_guests() failing without a valid idmap configuration; (bso#13697); + s3:auth_winbind: Ignore a missing winbindd as NT4 PDC/BDC without trusts; (bso#13722); + s3:auth_winbind: return NT_STATUS_NO_LOGON_SERVERS if winbindd is not available; (bso#13723); + s4:server: Add support for 'smbcontrol samba shutdown' and 'smbcontrol debug/debuglevel'; (bso#13752); + Python: Ensure ldb.Dn can doesn't rencoded str with py2; (bso#13616); + vfs_glusterfs: Adapt to changes in libgfapi signatures; (bso#13330); + s3-vfs: Use ENOATTR in errno comparison for getxattr; (bso#13774); + notifyd: Fix SIGBUS on sparc; (bso#13704); + waf: Check for libnscd; (bso#13787); + s3:vfs: Correctly check if OFD locks should be enabled or not; (bso#13770); + lib/util: Count a trailing line that doesn't end in a newline; (bso#13717); + Recovery lock bug fixes; (bso#13800); + s3: net: Do not set NET_FLAGS_ANONYMOUS with -k; (bso#13726); + s3:libsmb: Honor disable_netbios option in smbsock_connect_send; (bso#13727); + vfs_fileid: Fix get_connectpath_ino; (bso#13741); + vfs_fileid: Fix fsname_norootdir algorithm; (bso#13744);- Fix vfs_ceph ftruncate and fallocate handling; (bso#13807); (bsc#1127153).- Fix update-apparmor-samba-profile script after apparmor switched to using named profiles. The change is backwards compatible; (bsc#1126377);- LoadParm().load_default() fails with "Unable to load default file"; (bsc#1089758);- Abide by load_printers smb.conf parameter; (bso#13766); (bsc#1124223);- Update to samba-4.9.4 + libcli/smb: Don't overwrite status code; (bso#9175). + wbinfo --group-info 'NT AUTHORITY\System' does not work; (bso#12164). + Session setup reauth fails to sign response; (bso#13661). + vfs_fruit: Validation of writes on AFP_AfpInfo stream; (bso#13677). + vfs_shadow_copy2: Nicely deal with attempts to open previous version for writing; (bso#13688). + Restoring previous version of stream with vfs_shadow_copy2 fails with NT_STATUS_OBJECT_NAME_INVALID fsp->base_fsp->fsp_name; (bso#13455). + CVE-2018-16853: Fix S4U2Self crash with MIT KDC build; (bso#13571). + s3-vfs: Prevent NULL pointer dereference in vfs_glusterfs; (bso#13708) + PEP8: fix E231: missing whitespace after ','. + winbindd: Fix crash when taking profiles;(bso#13629) + CVE-2018-14629 dns: Fix CNAME loop prevention using counter regression; (bso#13600) + 'samba-tool user syscpasswords' fails on a domain with many DCs; (bso#13686). + CVE-2018-16853: Do not segfault if client is not set; (bso#13571). + lib:util: Fix DEBUGCLASS pointer initializiation; (bso#13679) + ctdb-daemon: Exit with error if a database directory does not exist; (bso#13696). + s3:libads: Add net ads leave keep-account option; (bso#13498).- Drop more %if..%endif guards which are idempotent. - Drop requires on ldconfig which are already auto-discovered. - Do not ignore errors from useradd/groupadd.- Remove python2 build dependency from samba-libs; (bsc#1116900);- Update update-apparmor-samba-profile script to ignore the shares's paths containing substitution variables in any place, not only at the beginning of the path.- Update to samba-4.9.3 + CVE-2018-14629: Unprivileged adding of CNAME record causing loop in AD Internal DNS server; (bso#13600); (bsc#1116319); + CVE-2018-16841: Double-free in Samba AD DC KDC with PKINIT; (bso#13628); (bsc#1116320); + CVE-2018-16851: NULL pointer de-reference in Samba AD DC LDAP server; (bso#13674); (bsc#1116322); + CVE-2018-16852: NULL pointer de-reference in Samba AD DC DNS servers; (bso#13669); (bsc#1116321); + CVE-2018-16853: Samba AD DC S4U2Self crash in experimental MIT Kerberos configuration (unsupported); (bso#13678); (bsc#1116324); + CVE-2018-16857: Bad password count in AD DC not always effective; window; (bso#13683); (bsc#1116323);- Update to samba-4.9.2 + dsdb: Add comments explaining the limitations of our current backlink behaviour; (bso#13418); + Fix problems running domain backups (handling SMBv2, sites); (bso#13621); + testparm: Fix crashes with PANIC: Messaging not initialized on SLES 12 SP3; (bso#13465); + Make vfs_fruit able to cleanup AppleDouble files; (bso#13642); + File saving issues with vfs_fruit on samba >= 4.8.5; (bso#13646); + Enabling vfs_fruit looses FinderInfo; (bso#13649); + Cancelling of SMB2 aio reads and writes returns wrong error NT_STATUS_INTERNAL_ERROR; (bso#13667); + Fix CTDB recovery record resurrection from inactive nodes and simplify vacuuming; (bso#13641); + examples: Fix the smb2mount build; (bso#13465); + libtevent: Fix build due to missing open_memstream on Illiumos; (bso#13629); + winbindd_cache: Fix timeout calculation for sid<->name cache; (bso#13662); + dsdb encrypted_secrets: Allow "ldb:// and "mdb://" in file path; (bso#13653); + Extended DN SID component missing for member after switching group membership; (bso#13418); + Return STATUS_SESSION_EXPIRED error encrypted, if the request was encrypted; (bso#13624); + python: Allow forced signing via smb.SMB(); (bso#13621); + lib:socket: If returning early, set ifaces; (bso#13665); + ldb: Bump ldb version to 1.4.3, Python: Ensure ldb.Dn can accept utf8 encoded unicode; (bso#13616); + smbd: Fix DELETE_ON_CLOSE behaviour on files with READ_ONLY attribute; (bso#13673); + waf: Add -fstack-clash-protection; (bso#13601); + winbind: Fix segfault if an invalid passdb backend is configured; (bso#13668); + Fix bugs in CTDB event handling; (bso#13659); + Misbehaving nodes are sometimes not banned; (bso#13670);- lib:socket: If returning early, set ifaces; (bso#13665); (bsc#1111373);- winbind requires latest version of libtevent-util0 to start- Backport latest gpo code from master + Read policy from local gpt cache + Offline policy application + Make group policy extensible via register/unregister gpext + gpext's run via a process_group_policy method- Enable profiling data collection- Change samba-kdc package name to samba-ad-dc - Move samba-ad-dc.service to the samba-ad-dc package- Update to samba-4.9.1 + s3: nmbd: Stop nmbd network announce storm; (bso#13620); + s3-rpcclient: Use spoolss_init_spoolss_UserLevel1 in winspool cmds; (bso#13597); + CTDB recovery lock has some race conditions; (bso#13617); + s3-rpc_client: Advertise Windows 7 client info; (bso#13597); + ctdb-doc: Remove PIDFILE option from ctdbd_wrapper man page; (bso#13610);- Tumbleweed doesn't define the sle_version macro, so we must include a check for suse_version also. Otherwise python3 is disabled on Tumbleweed.- Update to samba-4.9.0 + samba_dnsupdate: Honor 'dns zone scavenging' option, only update if needed; (bso#13605); + wafsamba: Fix 'make -j'; (bso#13606);- Update to samba-4.9.0rc5 + s3: VFS: vfs_full_audit: Ensure smb_fname_str_do_log() only returns absolute pathnames; (bso#13565); + s3: util: Do not take over stderr when there is no log file; (bso#13578); + Durable Reconnect fails because cookie.allow_reconnect is not set; (bso#13549); + krb5-samba: Interdomain trust uses different salt principal; (bso#13539); + vfs_fruit: Don't unlink the main file; (bso#13441); + smbd: Fix a memleak in async search ask sharemode; (bso#13602); + Fix Samba GPO issue when Trust is enabled; (bso#11517); + samba-tool: Add "virtualKerberosSalt" attribute to 'user getpassword/syncpasswords'; (bso#13539); + Fix CTDB configuration issues; (bso#13589); + ctdbd logs an error until it can successfully connect to eventd; (bso#13592);- Update to samba-4.9.0rc4 + s3: smbd: Ensure get_real_filename() copes with empty pathnames; (bso#13585); + samba domain backup online/rename commands force user to specify password on CLI; (bso#13566); + wafsamba/samba_abi: Always hide ABI symbols which must be local; (bso#13579); + Fix a panic if fruit_access_check detects a locking conflict; (bso#13584); + Fix memory and resource leaks; (bso#13567); + python: Fix print in dns_invalid.py; (bso#13580); + Aliasing issue causes incorrect IPv6 checksum; (bso#13588); + Fix CTDB configuration issues; (bso#13589); + s3: vfs: time_audit: fix handling of token_blob in smb_time_audit_offload_read_recv(); (bso#13568);- Add missing zlib-devel dependency which was previously pulled in by libopenssl-devel- Update to samba-4.9.0rc3+git.22.3fff23ae36e + CVE-2018-10858: libsmb: Harden smbc_readdir_internal() against returns from malicious servers; (bso#13453); + CVE-2018-1140: ldbsearch '(distinguishedName=abc)' and DNS query with escapes crashes, ldb: Release LDB 1.3.5 for CVE-2018-1140; (bso#13374); + CVE-2018-10918: cracknames: Fix DoS (NULL pointer de-ref) when not servicePrincipalName is set on a user; (bso#13552); + CVE-2018-10919: acl_read: Fix unauthorized attribute access via searches; (bso#13434); + ctdb_mutex_ceph_rados_helper: Set SIGINT signal handler; (bso#13540); + CVE-2018-1139 libcli/auth: Do not allow ntlmv1 over SMB1 when it is disabled via "ntlm auth"; (bso#13360); + s3-tldap: do not install test_tldap; (bso#13529); + ctdb_mutex_ceph_rados_helper: Fix deadlock via lock renewals; (bso#13540); + CVE-2018-1140 Add NULL check for ldb_dn_get_casefold() in ltdb_index_dn_attr(); (bso#13374); + ctdb-eventd: Fix CID 1438155; (bso#13554); + Fix CIDs 1438243, (Unchecked return value) 1438244 (Unsigned compared against 0), 1438245 (Dereference before null check) and 1438246 (Unchecked return value); (bso#13553); + ctdb: Fix a cut&paste error; (bso#13554); + systemd: Only start smb when network interfaces are up; (bso#13559); + Fix quotas don't work with SMB2; (bso#13553); + s3/smbd: Ensure quota code is only called when quota support detected; (bso#13563); + s3/libsmb: Explicitly set delete_on_close token for rmdir; (bso#13204); + s3:waf: Install eventlogadm to /usr/sbin; (bso#13561); + Shorten description in vfs_linux_xfs_sgid manual; (bso#13562);- Update to samba-4.9.0rc2+git.21.a1069afb007 + s3: smbd: Using "sendfile = yes" with SMB2 can cause CPU spin; (bso#13537); + s3: smbd: Fix path check in smbd_smb2_create_durable_lease_check(); (bso#13535); + samba-tool trust: Support discovery via netr_GetDcName; (bso#13538); + s4-dsdb: Only build dsdb Python modules for AD DC; (bso#13542); + Fix portability issues on freebsd; (bso#13520); + DNS wildcard search does not handle multiple labels correctly; (bso#13536); + samba-tool domain trust: Fix trust compatibility to Windows Server 1709 and FreeIPA; (bso#13308); + Fix portability issues on freebsd; (bso#13520); + ctdb-protocol: Fix CTDB compilation issues; (bso#13545); + ctdb-docs: Replace obsolete reference to CTDB_DEBUG_HUNG_SCRIPT option; (bso#13546); + ctdb-doc: Provide an example script for migrating old configuration; (bso#13550); + ctdb-event: Implement event tool "script list" command; (bso#13551);- Update to samba-4.8.4+git.37.a7a861d7982; + CVE-2018-1139: Weak authentication protocol allowed; (bsc#1095048); (bsc#13360); + CVE-2018-1140: Denial of Service Attack on DNS and LDAP server; (bsc#1095056); (bso#13466); (bso#13374); + CVE-2018-10858: Insufficient input validation on client directory listing in libsmbclient; (bsc#1103411); (bso#13453); + CVE-2018-10918: Denial of Service Attack on AD DC DRSUAPI server; (bsc#1103414); (bso#13552); + CVE-2018-10919: Confidential attribute disclosure from the AD LDAP server; (bsc#1095057); (bso#13434); + s3:winbind: winbind normalize names' doesn't work for users; (bso#12851); + winbind: Fix UPN handling in canonicalize_username(); (bso#13369); + s3: smbd: Fix SMB2-FLUSH against directories; (bso#13428); + samdb: Fix building Samba with gcc 8.1; (bso#13437); + s3:utils: Do not segfault on error in DoDNSUpdate(); (bso#13440); + smbd: Flush dfree memcache on service reload; (bso#13446); + ldb: Save a copy of the index result before calling the + lib/util: No Backtrace given by Samba's AD DC by default; (bso#13454). + s3: smbd: printing: Re-implement delete-on-close semantics for print files missing since 3.5.x; (bso#13457). + python: Fix talloc frame use in make_simple_acl(); (bso#13474). + krb5_wrap: Fix keep_old_entries logic for older Kerberos libraries;(bso#13478). + krb5_plugin: Add winbind localauth plugin for MIT Kerberos; (bso#13480).- Add missing package descriptions; (bsc#1093864); - Fix dependency issue between samba-python and samba-kdc; (bsc#1062876); - Call update-apparmor-samba-profile when running samba-ad-dc; (bsc#1092099);- Update to 4.8.2 + After update to 4.8.0 DC failed with "Failed to find our own NTDS Settings objectGUID" (bso#13335). + fix incorrect reporting of stream dos attributes on a directory (bso#13380). + vfs_ceph: add asynchronous fsync; fake synchronous call (bso#13412). + vfs_ceph: add fake async pwrite/pread send/recv hooks; (bso#13425) + vfs_ceph: Fix memory leak; (bso#13424). + libsmbclient: Fix hard-coded connection error return of ETIMEDOUT; (bso#13419). + s4-lsa: Fix use-after-free in LSA server; (bso#13420). + winbindd: Do re-connect if the RPC call fails in the passdb case; (bso#13430). + cleanupd: Sends MSG_SMB_UNLOCK twice to interested peers; (bso#13416). + cleanupd: Use MSG_SMB_BRL_VALIDATE to signal cleanupd unclean process shutdown; (bso#13414). + ctdb-client: Remove ununsed functions from old client code; (bso#13411). + printing: Return the same error code as windows does on upload failures; (bso#13395). + nsswitch: Fix memory leak in winbind_open_pipe_sock() when the privileged pipe is not accessable; (bso#13400). + s4:lsa_lookup: remove TALLOC_FREE(state) after all dcesrv_lsa_Lookup{Names,Sids}_base_map() calls; (bso#13420). + rpc_server: Fix NetSessEnum with stale sessions; (bso#13407). + s3:smbspool: Fix cmdline argument handling; (bso#13417).- Move libdfs-server-ad-samba4.so library from kdc to libs package, as it is required by some client libs; (bsc#1074135); - Update to 4.8.1; (bsc#1091179); + s3: ldap: Ensure the ADS_STRUCT pointer doesn't get freed on error, we don't own it here; (bso#13244); + s3: smbd: Fix possible directory fd leak if the underlying OS doesn't support fdopendir(); (bso#13270); + Round-tripping ACL get/set through vfs_fruit will increase the number of ACE entries without limit; (bso#13319); + s3: smbd: SMB2: Add DBGC_SMB2_CREDITS class to specifically debug credit issues; (bso#13347); + s3: smbd: Files or directories can't be opened DELETE_ON_CLOSE without delete access; (bso#13358); + s3: smbd: Fix memory leak in vfswrap_getwd(); (bso#13372); + s3: smbd: Unix extensions attempts to change wrong field in fchown call; (bso#13375); + ms_schema/samba-tool visualize: Fix python2.6 incompatibility; (bso#13337); + Fix invocation of gnutls_aead_cipher_encrypt(); (bso#13352); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + winbindd: Recover loss of netlogon secure channel in case the peer DC is rebooted; (bso#13332); + s3:smbd: Don't use the directory cache for SMB2/3; (bso#13363); + ctdb-client: Fix bugs in client code; (bso#13356); + ctdb-scripts: Drop "net serverid wipe" from 50.samba event script; (bso#13359); + s3: lib: messages: Don't use the result of sec_init() before calling sec_init(); (bso#13368); + libads: Fix the build '--without-ads'; (bso#13273); + winbind: Keep "force_reauth" in invalidate_cm_connection, add 'smbcontrol disconnect-dc'; (bso#13332); + vfs_virusfilter: Fix CIDs 1428738-1428740; (bso#13343); + dsdb: Fix CID 1034966 Uninitialized scalar variable; (bso#13367); + rpc_server: Fix core dump in dfsgetinfo; (bso#13370); + smbclient: Fix notify; (bso#13382); + Fix smbd panic if the client-supplied channel sequence number wraps; (bso#13215); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + lib/util: Remove unused '#include ' from tests/tfork.c; (bso#13342); + Fix build errors with cc from developerstudio 12.5 on Solaris; (bso#13343); + Fix the picky-developer build on FreeBSD 11; (bso#13344); + s3:modules: Fix the build of vfs_aixacl2.c; (bso#13345); + s3:smbd: map nterror on smb2_flush errorpath; (bso#13338); + lib:replace: Fix linking when libtirpc-devel overwrites system headers; (bso#13341); + winbindd: 'wbinfo --name-to-sid' returns misleading result on invalid query; (bso#13312); + s3:passdb: Do not return OK if we don't have pinfo set up; (bso#13376); + Allow AESNI to be used on all processor supporting AESNI; (bso#13302);- Use new foreground execution flags for systemd samba daemons; (bsc#1088574); (bsc#1071090); (bsc#1065551); + Add %post scriptlet to clear old sysconfig flags - Update vendor-files to commit 880b3e7. + Set samba sysconfig template variables to "" + Add required daemon flags directly to systemd unit- Specfile cleanup + Remove %if..%endif guards which don't affect the build + Remove redundant %clean section + Replace old $RPM_* shell vars with macros- BuildRequire pkgconfig(systemd) and pkgconfig(libsystemd) in place of systemd and systemd-devel: Allow OBS to optimize the workload by allowing the usage of the 'build-optimized' systemd packages.- Enable building samba with python3, and create a samba-python3 package.- Update to 4.8 + New GUID Index mode in sam.ldb for the AD DC + GPO support for samba KDC + Time machine support with vfs_fruit + Encrypted secrets + AD Replication visualization + Improved trust support - ability to not scan global trust list - AD external trusts have limited support - verbose trusted domain listing + VirusFilter VFS module + NT4-style replication removed + vfs_aio_linux removed- Disable samba-pidl package, due to the removal of dependency perl-Parse-Yapp; (bsc#1085150);- Update to 4.7.6; + CVE-2018-1050: DOS vulnerability when SPOOLSS is run externally; (bso#11343); (bsc#1081741); + CVE-2018-1057: Authenticated users can change other users' password; (bso#13272); (bsc#1081024).- Disable python until full python3 port is done; (bsc#1082139); + Remove contents of package samba-python + Remove contents of package libsamba-policy0 + Remove contents of package libsamba-policy-devel + Remove library libsamba-python-samba4.so from samba-libs package + Remove library libsamba-net-samba4.so from samba-libs package + Remove smbtorture binary and manpage from samba-test- samba fails to build with glibc2.27; (bsc#1081042);- Update to 4.7.5; (bsc#1080545); + smbd tries to release not leased oplock during oplock II downgrade; (bso#13193); + Fix copying file with empty FinderInfo from Windows client to Samba share with fruit; (bso#13181); + build: Deal with recent glibc sunrpc header removal; (bso#10976); + Make Samba work with tirpc and libnsl2; (bso#13238); + vfs_ceph: Add fs_capabilities hook to avoid local statvfs; (bso#13208); (bsc#1075206); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + ctdb-recovery-helper: Deregister message handler in error paths; (bso#13188); + samba: Only use async signal-safe functions in signal handler; (bso#13240); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + repl_meta_data: Fix linked attribute corruption on databases with unsorted links on expunge. dbcheck: Add functionality to fix the corrupt database; (bso#13228); + Fix smbd panic when chdir returns error during exit; (bso#13189); + Make Samba work with tirpc and libnsl2; (bso#13238); + Fix POSIX ACL support on HPUX and possibly other big-endian OSs; (bso#13176);- Update to 4.7.4; (bsc#1080545); + s3: smbclient: Implement 'volume' command over SMB2; (bso#13140); + s3: libsmb: Fix valgrind read-after-free error in cli_smb2_close_fnum_recv(); (bso#13171); + s3: libsmb: Fix reversing of oldname/newname paths when creating a reparse point symlink on Windows from smbclient; (bso#13172); + Build man page for vfs_zfsacl.8 with Samba; (bso#12934); + repl_meta_data: Allow delete of an object with dangling backlinks; (bso#13095); + s4:samba: Fix default to be running samba as a deamon; (bso#13129); + Performance regression in DNS server with introduction of DNS wildcard, ldb: Release 1.2.3; (bso#13191); + vfs_zfsacl: Fix compilation error; (bso#6133); + "smb encrypt" setting changes are not fully applied until full smbd restart; (bso#13051); + winbindd: Fix idmap_rid dependency on trusted domain list; (bso#13052); + vfs_fruit: Proper VFS-stackable conversion of FinderInfo; (bso#13155); + winbindd: Dependency on trusted-domain list in winbindd in critical auth codepath; (bso#13173); + repl_meta_data: Fix removing of backlink on deleted objects; (bso#13120); + ctdb: sock_daemon leaks memory; (bso#13153); + TCP tickles not getting synchronised on CTDB restart; (bso#13154); + winbindd: winbind parent and child share a ctdb connection; (bso#13150); + pthreadpool: Fix deadlock; (bso#13170); + pthreadpool: Fix starvation after fork; (bso#13179); + messaging: Always register the unique id; (bso#13180); + s4/smbd: set the process group; (bso#13129); + Fix broken linked attribute handling; (bso#13095); + The KDC on an RWDC doesn't send error replies in some situations; (bso#13132); + libnet_join: Fix 'net rpc oldjoin'; (bso#13149); + g_lock conflict detection broken when processing stale entries; (bso#13195); + s3:smb2_server: allow logoff, close, unlock, cancel and echo on expired sessions; (bso#13197); + s3:libads: net ads keytab list fails with "Key table name malformed"; (bso#13166); (bsc#1067700); + Fix crash in pthreadpool thread after failure from pthread_create; (bso#13170); + s4:samba: Allow samba daemon to run in foreground; (bso#13129); (bsc#1065551); + third_party: Link the aesni-intel library with "-z noexecstack"; (bso#13174); + vfs_glusterfs: include glusterfs/api/glfs.h without relying on "-I" options; (bso#13125);- Re-enable usage of libnsl (did got lost with glibc change) - Use TI-RPC (sunrpc is deprecated and will be removed soon from glibc)- smbc_opendir should not return EEXIST with invalid login credentials; (bnc#1065868).- Update to 4.7.3; (bsc#1069666); + Non-smbd processes using kernel oplocks can hang smbd; (bso#13121); + python: use communicate to fix Popen deadlock; (bso#13127); + smbd on disk file corruption bug under heavy threaded load; (bso#13130); + tevent: version 0.9.34; (bso#13130); + s3: smbd: Fix delete-on-close after smb2_find; (bso#13118); + CVE-2017-14746: s3: smbd: Fix SMB1 use-after-free crash bug; (bsc#1060427);(bso#13041); + CVE-2017-15275: s3: smbd: Chain code can return uninitialized memory when talloc buffer is grown; (bsc#1063008); (bso#13077); - Build with AD DC support only in openSUSE.- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- samba-tool requires samba-python; (bnc#1067771).- Run all daemons in the foreground and let systemd handle it; (bsc#1065551). - Update to 4.7.1; + Fix exporting subdirs with shadow_copy2; (bso#13091); + Currently if getwd() fails after a chdir(), we panic; (bso#13027); + Ensure default SMB_VFS_GETWD() call can't return a partially completed struct smb_filename; (bso#13068); + sys_getwd() can leak memory or possibly return the wrong errno on older systems; (bso#13069); + smbclient doesn't correctly canonicalize all local names before use; (bso#13093); + Fix broken linked attribute handling; (bso#13095); + Missing LDAP query escapes in DNS rpc server; (bso#12994); + Link to -lbsd when building replace.c by hand; (bso#13087); + Cannot delete non-ACL files on Solaris/ZFS/NFSv4 ACL filesystem; (bso#6133); + Map SYNCHRONIZE acl permission statically in zfs_acl vfs module; (bso#7909); + Samba fails to honor SEC_STD_WRITE_OWNER bit with the acl_xattr module; (bso#7933); + Missing assignment in sl_pack_float; (bso#12991); + Wrong Samba access checks when changing DOS attributes; (bso#12995); + samba_runcmd_send() leaves zombie processes on timeout; (bso#13062); + groupmap cleanup should not delete BUILTIN mappings; (bso#13065); + Enabling vfs_fruit results in loss of Finder tags and other xattrs; (bso#13076); + man pages: Properly ident lists; (bso#9613); + smb.conf.5: Sort parameters alphabetically; (bso#13081); + Fix GUID string format on GetPrinter info; (bso#12993); + Remote serverid check doesn't check for the unique id; (bso#13042); + CTDB starts consuming memory if there are dead nodes in the cluster; (bso#13056); + ctdb-common: Ignore event scripts with multiple '.'s; (bso#13070); + libgpo doesn't sort the GPOs in the correct order; (bso#13046); + Remote serverid check doesn't check for the unique id; (bso#13042); + vfs_catia: Fix a potential memleak; (bso#13090); + Fix file change notification for renames; (bso#12903); + Samba DNS server does not honour wildcards; (bso#12952); + Can't change password in samba from a Windows client if Samba runs on IPv6 only interface; (bso#13079); + vfs_fruit: Replace closedir() by SMB_VFS_CLOSEDIR; (bso#13086); + Apple client can't cope with SMB2 async replies when creating symlinks; (bso#13047); + s4:rpc_server:backupkey: Move variable into scope; (bso#12959); + Fix ntstatus_gen.h generation on 32bit; (bso#13099); + Fix a double free in vfs_gluster_getwd(); (bso#13100); + Fix resouce leaks and pointer issues; (bso#13101); + vfs_solarisacl: Fix build for samba 4.7 and up; (bso#13049);- Add samba-kdc to baselibs.conf. - Do not wrap samba-kdc's package definition into if/endif: the package won't be generated simply based on the fact that there is no files section for the package. Allows the source validator to ensure samba-kdc is a built package.- Update to 4.7.0; + Whole DB read locks: Improved LDAP and replication consistency; (bso#12858). + Samba AD with MIT Kerberos + Dynamic RPC port range: Default range changed from "1024-1300" to "49152-65535". + Authentication and Authorization audit support: New auth_audit debug class. + Multi-process LDAP Server: The LDAP server in the AD DC now honours the process model used for the rest of the 'samba' process. + Improved Read-Only Domain Controller (RODC) Support; (bso#12977). + Additional password hashes stored in supplementalCredentials. + Improvements to DNS during Active Directory domain join. + Significant AD performance and replication improvements. + Query record for open file or directory. + Removal of lpcfg_register_defaults_hook(). + Change of loadable module interface. + SHA256 LDAPS Certificates: The self-signed certificate generated for use on LDAPS will now be generated with a SHA256 self-signature, not a SHA1 self-signature. + CTDB no longer allows mixed minor versions in a cluster. + CTDB now ignores hints from Samba about TDB flags when attaching to databases. + New configuration variable CTDB_NFS_CHECKS_DIR. + The CTDB_SERVICE_AUTOSTARTSTOP configuration has been removed. + The CTDB_SCRIPT_DEBUGLEVEL configuration variable has been removed. + The example NFS Ganesha call-out has been improved. + A new "replicated" database type is available.- CVE-2017-12163: Prevent client short SMB1 write from writing server memory to file; (bso#13020); (bsc#1058624).- CVE-2017-12150: Some code path don't enforce smb signing, when they should; (bso#12997); (bsc#1058622).- CVE-2017-12151: Keep required encryption across SMB3 dfs redirects; (bso#12996); (bsc#1058565).- Clean specfile assuming SUSE-only system and product >=SLE11 + %{ul_version}, %{rhel_version}, %{mandriva_version}, %{centos_version} are always undefined + %{_vendor} is "suse" and %{suse_version} is at least 1100- Update to 4.6.7; (bsc#1054017) + Joining a Huawai storage fails: empty CLDAP ping answer; (bso#11392). + smbcacls can fail against a directory on Windows using SMB2.; (bso#12937). + vfs_ceph provides inconsistent directory listings; (bso#12911). + Misused talloc context can cause a user to crash their smbd by chaining SMB1 commands.; (bso#12836). + Use-after free can crash libsmbclient code.; (bso#12927). + Server exit with active AIO can crash.; (bso#12925). + Ensure notifyd doesn't return from smbd_notifyd_init; (bso#12910). + fd leak to ctdb sub-processes leads to SELinux AVC denial in audit logs; (bso#12898). + vfs_fruit shouldn't send MS NFS ACEs to Windows clients; (bso#12897). + smbspool_krb5_wrapper does not tell CUPS that it requires negotiate for authentication; (bso#12886). + finder sidebar showing question mark instead of icon when using ip to connect with vfs_fruit; (bso#12840). + Winbind stops obtaining the 'unixHomeDirectory' & 'loginShell' attributes from AD.; (bso#12720). + KCC run at selftest startup can fail spuriously due to a race; (bso#12869). + winbindd changes the local password and gets NT_STATUS_WRONG_PASSWORD for the remote change; (bso#12782). + rpc_pipe_client memory leaks due to long term memory context passed to rpc_pipe_open_interface(); (bso#12890). + CVE-2017-2619 breaks accessing previous versions of directories with snapshots in subdirectories of the share; (bso#12885). + dns_name_equal doing OOB read; (bso#12813). + replica_sync tests flap; (bso#12753). + Selftest should not call 'net cache flush' and wipe important winbind entries; (bso#12868). + Old Samba versions don't support using recent ldb versions (>=1.1.30); (bso#12859). + pam_winbind fails with kerberos method = secrets and keytab; (bso#10490). + race starting winbindd against posixacl test; (bso#12843). + Crash in the reentrant smbd_smb2_create_send() if the something fails in the subsequent try; (bso#12832). + spnego.c passes the wrong argument order to gensec_update_ev() for the FALLBACK case; (bso#12788). + Clients with SMB3 support can't connect with "server max protocol = SMB2_02"; (bso#12772). + A log message of samb-tool user syncpasswords reverses string arguments in a debug message "Call Popen[...".; (bso#12768). + The smb tarmode tests kills the share dir contents; (bso#12867). + Fix for a bug in MacOS X Sierra NTLMv2 processing; (bso#12862). + CVE-2017-2619 regression with non-wide symlinks to directories; (bso#12860). + manpage/index.html lists links not in alphabetical order; (bso#12854). + smbcacls got error NT_STATUS_NETWORK_NAME_DELETED; (bso#12831). + If a record is locked in a database, then recovery does not complete; (bso#12857). + debug_locks.sh script does not log any information; (bso#12856). + SIGSEGV in cm_connect_lsa_tcp dereferencing conn->lsa_tcp_pipe->transport after error; (bso#12852). + smbclient can't parse DOMAIN+username if a different winbind separator is used; (bso#12849). + Related requests with SessionSetup fail with INTERNAL_ERROR; (bso#12845). + Related requests with TreeConnect fail with NETWORK_NAME_DELETED; (bso#12844). + cli->server_os not filled correctly; (bso#12779). + REGRESSION: smbclient doesn't print the session setup anymore; (bso#12824). + smblcient doesn't handle STATUS_NOT_SUPPORTED gracefully for FSCTL_VALIDATE_NEGOTIATE_INFO; (bso#12808). + CTDB NFS call-out failures do not cause event failures; (bso#12837). + net command fails due to incorrectly return code; (bso#12828). + Fix building Samba with GCC 7.1; (bso#12827).- Fix duplicate CTDB_LOGGING params when downgraded and upgraded again; (bsc#1048339).- fix cephwrap_chdir(); (bsc#1048790). - Update to 4.6.6 + CVE-2017-11103: Orpheus' Lyre KDC-REP service name validation; (bsc#1048278).- Fix ctdb logs to /var/log/log.ctdb instead of /var/log/ctdb; (bsc#1048339).- Fix inconsistent ctdb socket path; (bsc#1048352). - Fix non-admin cephx authentication; (bsc#1048387).- Update to 4.6.5; (bsc#1040157) + Specifying CTDB_LOGGING=syslog:nonblocking causes ctdbd to crash at startup; (bso#12814). + vfs_expand_msdfs tries to open the remote address as a file path; (bso#12687). + PANIC (pid 1096): assert failed: lease_type_is_exclusive(e_lease_type); (bso#12798). + With clustering get update_num_read_oplocks failed and PANIC: num_share_modes == 1 assertion failure; (bso#11844). + contend_level2_oplocks_begin_default oplock optimisation doesn't carry over to leases; (bso#12766). + `ctdb nodestatus` incorrectly displays status for all nodes with wrong exit code; (bso#12802). + CTDB can spin hard on revoking readonly delegations if a node becomes disconnected; (bso#12697). + Printing a share mode entry with leases can crash in the ndr code; (bso#12793). + Fix flakey unit tests for eventd; (bso#12792). + CTDB daemon crashes if built with clang; (bso#12770). + smbcacls fails if no password is specified; (bso#12765). + idmap_rfc2307: Lookup of more than two SIDs fails; (bso#12757). + samba-tool user syncpasswords doesn't trigger the script when a user gets removed; (bso#12767). + systemd: fix detection of libsystemd; (bso#12764). + Notify subsystem only maps first inotify mask to Windows notify filter; (bso#12760). + Allow passing trusted domain password as plain-text to PASSDB layer; (bso#12751). + Can't case-rename files with vfs_fruit; (bso#12749). + wrong sid->uid mapping for SIDs residing in sIDHistory; (bso#12702). + vfs_acl_common should force "create mask = 0777", not 0666; (bso#12562). + Ordering of notify responses broken; (bso#12756).- s3: libsmb: Fix error where short name length was read as 2 bytes, should be 1; (bso#11822); (bsc#1042419).- Revert explicit winbind %{version}-%{release} dependency. + The ABI has stabilized since (bsc#936909), so remove to fix cross-media dependencies; (bsc#1037899).- Fix CVE-2017-7494 remote code execution from a writable share; (bso#12780); (bsc#1038231).- Update to 4.6.3; (bsc#1036011) + s3:vfs:shadow_copy2: vfs_shadow_copy2 fails to list snapshots from shares with GlusterFS backend; (bso#12743). + Fix for Solaris C compiler; (bso#12559). + s3: locking: Update oplock optimization for the leases era; (bso#12628). + Make the Solaris C compiler happy; (bso#12693). + s3: libgpo: Allow skipping GPO objects that don't have the expected LDAP attributes; (bso#12695). + Fix buffer overflow caused by wrong use of getgroups; (bso#12747). + lib: debug: Avoid negative array access; (bso#12746). + cleanupdb: Fix a memory read error; (bso#12748). + streams_xattr and kernel oplocks results in NT_STATUS_NETWORK_BUSY; (bso#7537). + winbindd: idmap_autorid allocates ids for unknown SIDs from other backends; (bso#11961). + vfs_fruit: Resource fork open request with flags=O_CREAT|O_RDONLY; (bso#12565). + manpages/vfs_fruit: Document global options; (bso#12615). + lib/pthreadpool: Fix a memory leak; (bso#12624). + Lookup-domain for well-known SIDs on a DC; (bso#12727). + winbindd: Fix error handling in rpc_lookup_sids(); (bso#12728). + winbindd: Trigger possible passdb_dsdb initialisation; (bso#12729). + credentials_krb5: use gss_acquire_cred for client-side GSSAPI use case; (bso#12611). + lib/crypto: Implement samba.crypto Python module for RC4; (bso#12690). + ctdb-readonly: Avoid a tight loop waiting for revoke to complete; (bso#12697). + ctdb_event monitor command crashes if event is not specified; (bso#12723). + ctdb-docs: Fix documentation of "-n" option to 'ctdb tool'; (bso#12733). + smbd: Fix smb1 findfirst with DFS; (bso#12558). + smbd: Do an early exit on negprot failure; (bso#12610). + winbindd: Fix substitution for 'template homedir'; (bso#12699). + s4:kdc: Disable principal based autodetected referral detection; (bso#12554). + idmap_autorid: Allocate new domain range if the callers knows the sid is valid; (bso#12613). + LINKFLAGS_PYEMBED should not contain -L/some/path; (bso#12724). + PAM auth with WBFLAG_PAM_GET_PWD_POLICY returns wrong policy for trusted domain; (bso#12725). + rpcclient: Allow -U'OTHERDOMAIN\user' again; (bso#12731). + winbindd: Fix password policy for pam authentication; (bso#12725). + s3:gse: Correctly handle external trusts with MIT; (bso#12554). + auth/credentials: Always set the realm if we set the principal from the ccache; (bso#12611). + replace: Include sysmacros.h; (bso#12686). + s3:vfs_expand_msdfs: Do not open the remote address as a file; (bso#12687). + s3:libsmb: Only print error message if kerberos use is forced; (bso#12704). + winbindd: Child process crashes when kerberos-authenticating a user with wrong password; (bso#12708). + vfs_fruit: Office document opens as read-only on macOS due to CNID semantics; (bso#12715). + vfs_acl_xattr: Fix failure to get ACL on Linux if memory is fragmented; (bso#12737).- Generate and update vendor-files tarball from Git + SuSEfirewall2 service samba-client only setup IPv4 rule; (bsc#1034416).- Generate source tarball directly from Git using OBS tar_scm + use version string derived from parent Git tag and commit hash - remove obsolete vendor-files/tools/package-data version ID + explicitly generate ctdb manpages, needed without "make dist"- Update to 4.6.2 + remove bso#12721 patches now upstream- Enable samba-ceph build for openSUSE and SLE12SP3+; (fate#321622). + x86-64 and aarch64- Enable librados CTDB lock helper for samba-ceph package; (fate#321622).- Build and install the html man pages (bsc#1021907).- Fix CVE-2017-2619 regression with "follow symlinks = no"; (bso#12721).- Update to 4.6.1 + symlink race permits opening files outside share directory; CVE-2017-2619; (bso#12496); (bsc#1027147) + testparm checks for valid idmap parameters + add new krb client encryption types + support for printer driver upload from windows 10 + inherit owner = 'unix only' for improved quota support + improved CTDB event support + new primary group support for idmap_ad + idmap_hash deprecated + mvxattr added to recursively rename extended attributes- Remove chkconfig requirements for systemd systems- Don't call insserv if systemd is used- Fix check if we need to require insserv- async_req: make async_connect_send() "reentrant"; (bso#12105); (bsc#1024416).- Force usage of ncurses6-config thru NCURSES_CONFIG env var; (bsc#1023847).- add missing patch for libnss_wins segfault; (bsc#995730).- Fix vfs_ceph builds against recent Ceph versions; (bsc#1021933).- Document "winbind: ignore domains" parameter; (bsc#1019416).- Add base Samba dependency to samba-ceph package.- Update to 4.5.3 + Heap-based Buffer Overflow Remote Code Execution Vulnerability; CVE-2016-2123; (bso#12409); (bsc#1014437). + Don't send delegated credentials to all servers; CVE-2016-2125; (bso#12445); (bsc#1014441). + denial of service due to a client triggered crash in the winbindd parent process; CVE-2016-2126; (bso#12446); (bsc#1014442). - 4.5.1 and 4.5.2 updates + various streams vfs fixes + various printing fixes + ntlm_auth: do not map explicitly empty domain + various stability fixes in smbd + match file compression ReFS behavior- Add missing ldb module directory; (bnc#1012092).- s3/client: obey 'disable netbios' smb.conf param, don't connect via NBT port; (bsc#1009085); (bso#12418).- Include vfstest in samba-test; (bsc#1001203).- s3/winbindd: using default domain with user@domain.com format fails; (bsc#997833).- Fix segfault in libnss_wins; (bso#12277); (bso#12269); (bsc#995730).- Update to 4.5.0 + NTLM1 Authentication disabled by default + SMB2.1 leases enabled by default + Support for OFD locks + ctdb tool rewritten + Added shadow copy snapshot prefix parameter- Fix illegal memory access after memory has been deleted; (bso#11836); (bsc#975299).- Prevent core, make sure response->extra_data.data is always cleared out; (bsc#993692).- Don't package man pages for VFS modules that aren't built; (boo#993707).- Fix population of ctdb sysconfig after source merge; (bsc#981566).- Enable vfs_ceph builds for Factory (x86-64) + Package as samba-ceph to avoid Ceph dependency in base package.- Update to 4.4.5 + Prevent client-side SMB2 signing downgrade; CVE-2016-2119; (bso#11860); (bsc#986869).- Remove obsolete syslog.target; (bsc#983938).- Honor smb.conf socket options in winbind; (bsc#975131).- Don't use htons() with IP_PROTO_RAW; (bso#11705); (bsc#969522).- Update to 4.4.4 + SMB3 multichannel: Add implementation of missing channel sequence number verification; (bso#11809). + smbd:close: Only remove kernel share modes if they had been taken at open; (bso#11919). + notifyd: Prevent NULL deref segfault in notifyd_peer_destructor; (bso#11930). + s3:rpcclient: Make '--pw-nt-hash' option work; (bso#10796). + Fix case sensitivity issues over SMB2 or above; (bso#11438). + s3:smbd: Fix anonymous authentication if signing is mandatory. (bso#11910) + Fix NTLM Authentication issue with squid; (bso#11914). + pdb: Fix segfault in pdb_ldap for missing gecos; (bso#11530). + Fix memory leak in share mode locking; (bso#11934).- Update to 4.4.3 + Various post-badlock regressions; (bso#11841); (bso#11850); (bso#11858); (bso#11870); (bso#11872). + Only allow idmap_hash for default idmap config (bso#11786). + smbd: Avoid large reads beyond EOF; (bso#11878). + vfs_acl_common: Avoid setting POSIX ACLs if "ignore system acls" is set; (bso#11806). + libads: Record session expiry for spnego sasl binds; (bso#11852).- Fix NTLMSSP regressions caused by previous CVE fixes; (bso#11849); (bsc#975962); (bsc#979268), (bsc#977669).- Revert shared library packaging to comply with SLPP- Update to 4.4.2 + A man-in-the-middle can downgrade NTLMSSP authentication; CVE-2016-2110; (bso#11688); (bsc#973031). + Domain controller netlogon member computer can be spoofed; CVE-2016-2111; (bso#11749); (bsc#973032). + LDAP conenctions vulnerable to downgrade and MITM attack; CVE-2016-2112; (bso#11644); (bsc#973033). + TLS certificate validation missing; CVE-2016-2113; (bso#11752); (bsc#973034). + Named pipe IPC vulnerable to MITM attacks; CVE-2016-2115; (bso#11756); (bsc#973036). + "Badlock" DCERPC impersonation of authenticated account possible; CVE-2016-2118; (bso#11804); (bsc#971965). + DCERPC server and client vulnerable to DOS and MITM attacks; CVE-2015-5370; (bso#11344); (bsc#936862).- Fix samba.tests.messaging test and prevent potential tdb corruption by removing obsolete now invalid tdb_close call; (bsc#974629).- Obsolete libsmbclient from libsmbclient0 while not providing it; (bsc#972197).- Update to 4.4.0. + Read of uninitialized memory DNS TXT handling; (bso#11128); (bso#11686); CVE-2016-0771. + Getting and setting Windows ACLs on symlinks can change permissions on link target; (bso#11648); CVE-2015-7560. + Sockets with htons(IPPROTO_RAW); (bso#11705); CVE-2015-8543. + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystem with no ACL support; (bso#10489). + docs: Add example for domain logins to smbspool man page; (bso#11643). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + docs: Add smbspool_krb5_wrapper manpage; (bso#11690). + winbindd: Return trust parameters when listing trusts; (bso#11691). + ctdb: Do not provide a useless pkgconfig file for ctdb; (bso#11696). + Crypto.Cipher.ARC4 is not available on some platforms, fallback to M2Crypto.RC4.RC4 then; (bso#11699). + s3:utils/smbget: Set default blocksize; (bso#11700). + Streamline 'smbget' options with the rest of the Samba utils; (bso#11700). + s3:clispnego: Fix confusing warning in spnego_gen_krb5_wrap(); (bso#11702). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + s3:vfs:glusterfs: Fix build after quota changes; (bso#11715). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + lib:socket: Fix CID 1350010: Integer OVERFLOW_BEFORE_WIDEN; (bso#11723). + smbd: Fix CID 1351215 Improper use of negative value; (bso#11724). + smbd: Fix CID 1351216 Dereference null return value; (bso#11725). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + docs: Add manpage for cifsdd; (bso#11730). + param: Fix str_list_v3 to accept ; again; (bso#11732). + lib/socket: Fix improper use of default interface speed; (bso#11734). + lib:socket: Fix CID 1350009: Fix illegal memory accesses (BUFFER_SIZE_WARNING); (bso#11735). + libcli: Fix debug message, print sid string for new_ace trustee; (bso#11738). + Fix installation path of Samba helper binaries; (bso#11739). + Fix memory leak in loadparm; (bso#11740). + tevent: version 0.9.28: Fix memory leak when old signal action restored; (bso#11742). + smbd: Ignore SVHDX create context; (bso#11753). + Fix net join; (bso#11755). + s3:libads: setup the msDS-SupportedEncryptionTypes attribute on ldap_add; (bso#11755). + passdb: Add linefeed to debug message; (bso#11763). + s3:utils/smbget: Fix option parsing; (bso#11767). + libnet: Make Kerberos domain join site-aware; (bso#11769). + Reset TCP Connections during IP failover; (bso#11770). + ldb: Version 1.1.26; (bso#11772). + s3:smbd: Add negprot remote arch detection for OSX; (bso#11773). + vfs_glusterfs: Fix use after free in AIO callback; (bso#11774). + mkdir can return ACCESS_DENIED incorrectly on create race; (bso#11780). + "trustdom_list_done: Got invalid trustdom response" message should be avoided; (bso#11782). + Mismatch between local and remote attribute ids lets replication fail with custom schema; (bso#11783). + Quota is not supported on Solaris 10; (bso#11788). + Talloc: Version 2.1.6; (bso#11789). + smbd: Enable multi-channel if 'server multi channel support = yes' in the config; (bso#11796). + build: Fix build when '--without-quota' specified; (bso#11798). + lib/socket/interfaces: Fix some uninitialied bytes; (bso#11802). + Access based share enum: handle permission set in configuration files; (bso#8093). + See also WHATSNEW.txt from the samba-doc package.- Update to 4.3.6. + Getting and setting Windows ACLs on symlinks can change permissions on link target; CVE-2015-7560; (bso#11648); (bsc#968222). + Fix Out-of-bounds read in internal DNS server; CVE-2016-0771; (bso#11128); (bso#11686); (bsc#968223).- Upgrade on-disk FSRVP server state to new version; (bsc#924519).- Only obsolete but do not provide gplv2/3 package names; (bsc#968973).- Relocate existing lock files to /var/lib/samba/lock; (bsc#968963).- Obsolete no longer existing samba-32bit package; (bsc#967625).- Update to 4.3.5. + s3:utils/smbget: Fix recursive download; (bso#6482). + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystemi with no ACL support; (bso#10489). + s3:smbd/oplock: Obey kernel oplock setting when releasing oplocks; (bso#11400). + vfs_shadow_copy2: Fix case where snapshots are outside the share; (bso#11580). + smbclient: Query disk usage relative to current directory; (bso#11662). + winbindd: Handle expired sessions correctly; (bso#11670). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + smbcacls: Fix uninitialized variable; (bso#11682). + s3:smbd: Ignore initial allocation size for directory creation; (bso#11684). + s3-client: Add a KRB5 wrapper for smbspool; (bso#11690). + s3-parm: Clean up defaults when removing global parameters; (bso#11693). + Use M2Crypto.RC4.RC4 on platforms without Crypto.Cipher.ARC4; (bso#11699). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + ctdb: Remove error messages after kernel security update; CVE-2015-8543; (bso#11705). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + param: Fix str_list_v3 to accept ";" again; (bso#11732).- Shift samba-client sysconfig data into samba and samba-winbind; (bsc#947361).- Simplify shared library packaging; (bsc#966956).- Enable clustering (CTDB) support; (bsc#966271).- s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703); (bsc#964023).- Add quotes around path of update-apparmor-samba-profile; (bnc#962177).- Remove autoconf build-time requirement.- Update to 4.3.4. + vfs_fruit: Enable POSIX directory rename semantics; (bso#11065). + Crash: Bad talloc magic value - access after free; (bso#11394). + Copying files with vfs_fruit fails when using vfs_streams_xattr without stream prefix and type suffix; (bso#11466). + samba-tool: Fix uncaught exception if no fSMORoleOwner attribute is given; (bso#11613). + Fix a typo in the smb.conf manpage, explanation of idmap config; (bso#11619). + Correctly initialize the list head when keeping a list of primary followed by DFS connections; (bso#11624). + Reduce the memory footprint of empty string options; (bso#11625). + lib/async_req: Do not install async_connect_send_test; (bso#11639). + Fix typos in man vfs_gpfs; (bso#11641). + Make "hide dot files" option work with "store dos attributes = yes"; (bso#11645). + Fix a corner case of the symlink verification; (bso#11647); (bnc#960249). + Do not disable "store dos attributes" on-the-fly; (bso#11649). + Update lastLogon and lastLogonTimestamp; (bso#11659).- Prevent access denied if the share path is "/"; (bso#11647); (bnc#960249).- Update to 4.3.3. + Malicious request can cause Samba LDAP server to hang, spinning using CPU; CVE-2015-3223; (bso#11325); (bnc#958581). + Remote read memory exploit in LDB; CVE-2015-5330; (bso#11599); (bnc#958586). + Insufficient symlink verification (file access outside the share); CVE-2015-5252; (bso#11395); (bnc#958582). + No man in the middle protection when forcing smb encryption on the client side; CVE-2015-5296; (bso#11536); (bnc#958584). + Currently the snapshot browsing is not secure thru windows previous version (shadow_copy2); CVE-2015-5299; (bso#11529); (bnc#958583). + Fix Microsoft MS15-096 to prevent machine accounts from being changed into user accounts; CVE-2015-8467; (bso#11552); (bnc#958585).- Update to 4.3.2. + vfs_gpfs: Re-enable share modes; (bso#11243). + dcerpc.idl: Accept invalid dcerpc_bind_nak pdus; (bso#11327). + s3-smbd: Fix old DOS client doing wildcard delete - gives an attribute type of zero; (bso#11452). + Add libreplace dependency to texpect, fixes a linking error on Solaris; (bso#11511). + s4: Fix linking of 'smbtorture' on Solaris; (bso#11512). + s4:lib/messaging: Use correct path for names.tdb; (bso#11562). + Fix segfault of 'net ads (join|leave) -S INVALID' with nss_wins; (bso#11563). + async_req: Fix non-blocking connect(); (bso#11564). + auth: gensec: Fix a memory leak; (bso#11565). + lib: util: Make non-critical message a warning; (bso#11566). + Fix winbindd crashes with samlogon for trusted domain user; (bso#11569); (bnc#949022). + smbd: Send SMB2 oplock breaks unencrypted; (bso#11570). + ctdb: Open the RO tracking db with perms 0600 instead of 0000; (bso#11577). + s3:smb2_server: Make the logic of SMB2_CANCEL DLIST_REMOVE() clearer; (bso#11581). + s3-smbd: Fix use after issue in smbd_smb2_request_dispatch(); (bso#11581). + manpage: Correct small typo error; (bso#11584). + s3: smbd: If EAs are turned off on a share don't allow an SMB2 create containing them; (bso#11589). + Backport some valgrind fixes from upstream master; (bso#11597). + auth: Consistent handling of well-known alias as primary gid; (bso#11608). + winbind: Fix crash on invalid idmap configs; (bso#11612). + s3: smbd: have_file_open_below() fails to enumerate open files below an open directory handle; (bso#11615). + Changing log level of two entries to DBG_NOTICE; (bso#9912).- Ensure samlogon fallback requests are rerouted after kerberos failure; (bnc#953382); (bnc#953972).- Ensure to link with --as-needed flag by removing SUSE_ASNEEDED=0. - Always use the default optimization even on pre-9.2 systems.- Remove redundant configure options while adding with-relro.- Relocate the lockdir to the /var/lib/samba/lock directory.- Cleanup and enhance the pidl sub package.- Require renamed python-ldb-devel and python-talloc-devel at build-time. - Requires python-ldb and python-talloc from the python subpackage.- Update to 4.3.1. + s3: smbd: Fix our access-based enumeration on "hide unreadable" to match Windows; (bso#10252). + nss_winbind: Fix hang on Solaris on big groups; (bso#10365). + smbd: Fix file name buflen and padding in notify repsonse; (bso#10634). + kerberos: Make sure we only use prompter type when available; winbind: Fix 100% loop; (bso#11038). + source3/lib/msghdr.c: Fix compiling error on Solaris; (bso#11053). + s3:ctdbd_conn: make sure we destroy tevent_fd before closing the socket; (bso#11316). + s3: smbd: Fix mkdir race condition; (bso#11486). + pam_winbind: Fix a segfault if initialization fails; (bso#11502). + s3: dfs: Fix a crash when the dfs targets are disabled; (bso#11509). + s4:lib/messaging: Use 'msg.lock' and 'msg.sock' for messaging related subdirs; (bso#11515). + s3: smbd: Fix opening/creating :stream files on the root share directory; (bso#11522). + lib/param: Fix hiding of FLAG_SYNONYM values; (bso#11526). + net: Fix a crash with 'net ads keytab create'; (bso#11528). + s3: smbd: Fix a crash in unix_convert(); (bso#11535). + s3: smbd: Fix NULL pointer bug introduced by previous 'raw' stream fix (bso#11522); (bso#11535). + vfs_fruit: Return value of ad_pack in vfs_fruit.c; (bso#11543). + vfs_commit: set the fd on open before calling SMB_VFS_FSTAT; (bso#11547). + s3:locking: Initialize lease pointer in share_mode_traverse_fn(); (bso#11549). + s3:smbstatus: Add stream name to share_entry_forall(); (bso#11550). + s3:lib: Validate domain name in lookup_wellknown_name(); (bso#11555). + s3: lsa: lookup_name() logic for unqualified (no DOMAIN component) names is incorrect; (bso#11555).- Fix 100% CPU in winbindd when logging in with "user must change password on next logon"; (bso#11038).- Relocate the tmpfiles.d directory to the client package; (bnc#947552).- Do not provide libpdb0 from libsamba-passdb0 but add it to baselibs.conf instead; (bnc#942716).- Package /var/lib/samba/private/sock with 0700 permissions; (bnc#946051).- Package /var/lib/samba/msg with 0755 permissions; (bso#11515); (bnc#945502).- Require to install libfam0-gamin from samba-libs on post-12.1 and pre-13.15 systems; (bnc#945013).- Update to 4.3.0. + Samba "map to guest = Bad uid" doesn't work; (bso#9862). + revert LDAP extended rule 1.2.840.113556.1.4.1941 LDAP_MATCHING_RULE_IN_CHAIN changes; (bso#10493). + No objectClass found in replPropertyMetaData on ordinary objects (non-deleted); (bso#10973). + Stream names with colon don't work with fruit:encoding = native; (bso#11278). + NetApp joined to a Samba/ADDC cannot resolve SIDs; (bso#11291). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + "force group" with local group not working; (bso#11320). + strsep is not available on Solaris; (bso#11359). + smbtorture does not build when configured --with-system-mitkrb5; (bso#11411). + Build with GPFS support is broken; (bso#11421). + Build broken with --disable-python; (bso#11424). + net share allowedusers crashes; (bso#11426). + nmbd incorrectly matches netbios names as own name; (bso#11427). + Python bindings don't check integer types; (bso#11429). + Python bindings don't check array sizes; (bso#11430). + CTDB's eventscript error handling is broken; (bso#11431). + Fix crash in nested ctdb banning; (bso#11432). + Cannot build ctdbpmda; (bso#11434). + samba-tool uncaught exception error; (bso#11436). + Crash in notify_remove caused by change notify = no; (bso#11444). + Poor SMB3 encryption performance with AES-GCM; (bso#11451). + Poor SMB3 encryption performance with AES-GCM (part1); (bso#11451). + fix recursion problem in rep_strtoll in lib/replace/replace.c; (bso#11455). + --bundled-libraries=!ldb,!pyldb,!pyldb-util doesn't disable ldb build and install; (bso#11458). + xid2sid gives inconsistent results; (bso#11464). + ctdb: Fix the build on FreeBSD 10.1; (bso#11465). + Handling of 0 byte resource fork stream; (bso#11467). + AD samr GetGroupsForUser fails for users with "()" in their name; (bso#11488).- Configure with --bundled-libraries=NONE; (bso#11458).- Adapt net-kdc-lookup patch for post-3.3 Samba versions; (bnc#295284).- Remove libiniparser-devel build-time requirement.- Update to 4.2.3. + s4:lib/tls: Fix build with gnutls 3.4; (bso#8780). + s4.2/fsmo.py: Fixed fsmo transfer exception; (bso#10924). + winbindd: Sync secrets.ldb into secrets.tdb on startup; (bso#10991). + Logon via MS Remote Desktop hangs; (bso#11061). + s3: lib: util: Ensure we read a hex number as %x, not %u; (bso#11068). + tevent: Add a note to tevent_add_fd(); (bso#11141). + s3:param/loadparm: Fix 'testparm --show-all-parameters'; (bso#11170). + s3-unix_msg: Remove socket file after closing socket fd; (bso#11217). + smbd: Fix a use-after-free; (bso#11218); (bnc#919309). + s3-rpc_server: Fix rpc_create_tcpip_sockets() processing of interfaces; (bso#11245). + s3:smb2: Add padding to last command in compound requests; (bso#11277). + Add IPv6 support to ADS client side LDAP connects; (bso#11281). + Add IPv6 support for determining FQDN during ADS join; (bso#11282). + s3: IPv6 enabled DNS connections for ADS client; (bso#11283). + Fix invalid write in ctdb_lock_context_destructor; (bso#11293). + Excessive cli_resolve_path() usage can slow down transmission; (bso#11295). + vfs_fruit: Add option "veto_appledouble"; (bso#11305). + tstream: Make socketpair nonblocking; (bso#11312). + idmap_rfc2307: Fix wbinfo '--gid-to-sid' query; (bso#11313). + Group creation: Add msSFU30Name only when --nis-domain was given; (bso#11315). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + Build fails on Solaris 11 with "‘PTHREAD_MUTEX_ROBUST’ undeclared"; (bso#11319). + smbd/trans2: Add a useful diagnostic for files with bad encoding; (bso#11323). + Change sharesec output back to previous format; (bso#11324). + Robust mutex support broken in 1.3.5; (bso#11326). + Kerberos auth info3 should contain resource group ids available from pac_logon; winbindd: winbindd_raw_kerberos_login - ensure logon_info exists in PAC; (bso#11328); (bnc#912457). + s3:smb2_setinfo: Fix memory leak in the defer_rename case; (bso#11329). + tevent: Fix CID 1035381 Unchecked return value; (bso#11330). + tdb: Fix CID 1034842 and 1034841 Resource leaks; (bso#11331). + s3: smbd: Use separate flag to track become_root()/unbecome_root() state; (bso#11339). + s3: smbd: Codenomicon crash in do_smb_load_module(); (bso#11342). + pidl: Make the compilation of PIDL producing the same results if the content hasn't change; (bso#11356). + winbindd: Disconnect child process if request is cancelled at main process; (bso#11358). + vfs_fruit: Check offset and length for AFP_AfpInfo read requests; (bso#11363). + docs: Overhaul the description of "smb encrypt" to include SMB3 encryption; (bso#11366). + s3:auth_domain: Fix talloc problem in connect_to_domain_password_server(); (bso#11367). + ncacn_http: Fix GNUism; (bso#11371).- Disable rpath usage; (bnc#902421).- Make the winbind package depend on the matching libwbclient version and vice versa; (bnc#936909).- Backport changes to use resource group sids obtained from pac logon_info; (bso#11328); (bnc#912457).- Order winbind.service Before and Want nss-user-lookup target.- Remove fam-devel build-time dependency for post-6 RHEL systems.- Update to 4.2.2. + s3:smbXsrv: refactor duplicate code into smbXsrv_session_clear_and_logoff(); (bso#11182). + gencache: don't fail gencache_stabilize if there were records to delete; (bso#11260). + s3: libsmbclient: After getting attribute server, ensure main srv pointer is still valid; (bso#11186). + s4: rpc: Refactor dcesrv_alter() function into setup and send steps; (bso#11236). + s3: smbd: Incorrect file size returned in the response of "FILE_SUPERSEDE Create"; (bso#11240). + Mangled names do not work with acl_xattr; (bso#11249). + nmbd rewrites browse.dat when not required; (bso#11254). + vfs_fruit: add option "nfs_aces" that controls the NFS ACEs stuff; (bso#11213). + s3:smbd: Add missing tevent_req_nterror; (bso#11224). + vfs: kernel_flock and named streams; (bso#11243). + vfs_gpfs: Error code path doesn't call END_PROFILE; (bso#11244). + s4: libcli/finddcs_cldap: continue processing CLDAP until all addresses are used; (bso#11284). + ctdb: check for talloc_asprintf() failure; (bso#11201). + spoolss: purge the printer name cache on name change; (bso#11210); (bnc#901813). + CTDB statd-callout does not scale; (bso#11204). + vfs_fruit: also map characters below 0x20; (bso#11221). + ctdb: Coverity fix for CID 1291643; (bso#11201). + Multiplexed RPC connections are not handled by DCERPC server; (bso#11225). + Fix terminate connection behavior for asynchronous endpoint with PUSH notification flavors; (bso#11226). + ctdb-scripts: Fix bashism in ctdbd_wrapper script; (bso#11007). + ctdb: Fix CIDs 1125615, 1125634, 1125613, 1288201 and 1125553; (bso#11201). + SMB2 should cancel pending NOTIFY calls with DELETE_PENDING if the directory is deleted; (bso#11257). + s3:winbindd: make sure we remove pending io requests before closing client sockets; (bso#11141); (bnc#931854). + Fix panic triggered by smbd_smb2_request_notify_done() -> smbXsrv_session_find_channel() in smbd; (bso#11182). + 'sharesec' output no longer matches input format; (bso#11237). + waf: Fix systemd detection; (bso#11200). + CTDB: Fix portability issues; (bso#11202). + CTDB: Fix some IPv6-related issues; (bso#11203). + CTDB statd-callout does not scale; (bso#11204). + 'net ads dns gethostbyname' crashes with an error in TALLOC_FREE if you enter invalid values; (bso#11234). + libads: record service ticket endtime for sealed ldap connections; (bso#11267). + lib/util: Include DEBUG macro in internal header files before samba_util.h; (bso#11033).- Avoid a crash inside the tevent epoll backend; (bso#11141); (bnc#931854).- Remove the independently built libraries ldb, talloc, tdn, and tevent and the post-10.3 renamed libsmbclient from baselibs.conf.- Drop redundant doc attribute from man pages.- Update to 4.2.1. + s3:winbind:grent: Don't stop group enumeration when a group has no gid; (bso#8905). + Initialize dwFlags field of DNS_RPC_NODE structure; (bso#9791). + s3: lib: ntlmssp: If NTLMSSP_NEGOTIATE_TARGET_INFO isn't set, cope with servers that don't send the 2 unused fields; (bso#10016). + build:wafadmin: Fix use of spaces instead of tabs; (bso#10476). + waf: Fix the build on openbsd; (bso#10476). + s3: client: "client use spnego principal = yes" code checks wrong name; (bso#10888). + spoolss: Retrieve published printer GUID if not in registry; (bso#11018). + s3: lib: libsmbclient: If reusing a server struct, check every cli->timout miliseconds if it's still valid before use; (bso#11079). + vfs_fruit: Enhance handling of malformed AppleDouble files; (bso#11125). + backupkey: Explicitly link to gnutls and gcrypt; (bso#11135). + replace: Remove superfluous check for gcrypt header; (bso#11135). + Backport subunit changes; (bso#11137). + libcli/auth: Match Declaration of netlogon_creds_cli_context_tmp with implementation; (bso#11140). + s3-winbind: Fix cached user group lookup of trusted domains; (bso#11143). + talloc: Version 2.1.2; (bso#11144). + Update libwbclient version to 0.12; (bso#11149). + brlock: Use 0 instead of empty initializer list; (bso#11153). + s4:auth/gensec_gssapi: Let gensec_gssapi_update() return NT_STATUS_LOGON_FAILURE for unknown errors; (bso#11164). + docs/idmap_rid: Remove deprecated base_rid from example; (bso#11169); (bnc#913304). + s3: libcli: smb1: Ensure we correctly finish a tevent req if the writev fails in the SMB1 case; (bso#11173). + backupkey: Use ndr_pull_struct_blob_all(); (bso#11174). + Fix lots of winbindd zombie processes on Solaris platform; (bso#11175). + s3: libsmbclient: Add missing talloc stackframe; (bso#11177). + s4-process_model: Do not close random fds while forking; (bso#11180). + s3-passdb: Fix 'force user' with winbind default domain; (bso#11185).- Prevent samba package updates from disabling samba kerberos printing.- Add sparse file support for samba; (fate#318424).- Purge printer name cache on spoolss SetPrinter change; (bso#11210); (bnc#901813).- Correctly retain errno from Btrfs snapshot ioctls; (bnc#923374).- Simplify libxslt build requirement and README.SUSE install. - Remove no longer required cleanup steps while populating the build root.- Remove deprecated base_rid example from idmap_rid manpage; (bso#11169); (bnc#913304).- Update to 4.2.0. + smbd: Stop using vfs_Chdir after SMB_VFS_DISCONNECT; (bso#1115). + pam_winbind: fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Make 'profiles' work again; (bso#9629). + s3:smb2_server: protect against integer wrap with "smb2 max credits = 65535"; (bso#9702). + Make validate_ldb of String(Generalized-Time) accept millisecond format ".000Z"; (bso#9810). + Use -R linker flag on Solaris, not -rpath; (bso#10112). + vfs: Add glusterfs manpage; (bso#10240). + Make 'smbclient' use cached creds; (bso#10279). + pdb: Fix build issues with shared modules; (bso#10355). + s4-dns: Add support for BIND 9.10; (bso#10620). + idmap: Return the correct id type to *id_to_sid methods; (bso#10720). + printing/cups: Pack requested-attributes with IPP_TAG_KEYWORD; (bso#10808). + Don't build vfs_snapper on FreeBSD; (bso#10834). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3: smb2cli: query info return length check was reversed; (bso#10848). + s3: lib, s3: modules: Fix compilation on Solaris; (bso#10849). + lib: uid_wrapper: Fix setgroups and syscall detection on a system without native uid_wrapper library; (bso#10851). + winbind3: Fix pwent variable substitution; (bso#10852). + Improve samba-regedit; (bso#10859). + registry: Don't leave dangling transactions; (bso#10860). + Fix build of socket_wrapper on systems without SO_PROTOCOL; (bso#10861). + build: Do not install 'texpect' binary anymore; (bso#10862). + Fix testparm to show hidden share defaults; (bso#10864). + libcli/smb: Fix smb2cli_validate_negotiate_info with min=PROTOCOL_NT1 max=PROTOCOL_SMB2_02; (bso#10866). + Integrate CTDB into top-level Samba build; (bso#10892). + samba-tool group add: Add option '--nis-domain' and '--gid'; (bso#10895). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + Fix smbclient loops doing a directory listing against Mac OS X 10 server with a non-wildcard path; (bso#10904). + Fix print job enumeration; (bso#10905); (bnc#898031). + samba-tool: Create NIS enabled users and unixHomeDirectory attribute; (bso#10909). + Add support for SMB2 leases; (bso#10911). + btrfs: Don't leak opened directory handle; (bso#10918). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: fix keytab array NULL termination; (bso#10933). + s3:passdb: fix logic in pdb_set_pw_history(); (bso#10940). + Cleanup add_string_to_array and usage; (bso#10942). + dbwrap_ctdb: Pass on mutex flags to tdb_open; (bso#10942). + Fix RootDSE search with extended dn control; (bso#10949). + Fix 'samba-tool dns serverinfo ' for IPv6; (bso#10952). + libcli/smb: only force signing of smb2 session setups when binding a new session; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + socket_wrapper: Add missing prototype check for eventfd; (bso#10965). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + vfs_streams_xattr: Check stream type; (bso#10971). + s3: smbd: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + vfs_fruit: Add support for AAPL; (bso#10983). + Fix spoolss IDL response marshalling when returning error without clearing info; (bso#10984). + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279). + Fix IPv6 support in CTDB; (bso#10996). + ctdb-daemon: Use correct tdb flags when enabling robust mutex support; (bso#11000). + vfs_streams_xattr: Add missing call to SMB_VFS_NEXT_CONNECT; (bso#11005). + s3-util: Fix authentication with long hostnames; (bso#11008). + ctdb-build: Fix build without xsltproc; (bso#11014). + packaging: Include CTDB man pages in the tarball; (bso#11014). + pdb_get_trusteddom_pw() fails with non valid UTF16 random passwords; (bso#11016). + Make Sharepoint search show user documents; (bso#11022). + nss_wrapper: check for nss.h; (bso#11026). + Enable mutexes in gencache_notrans.tdb; (bso#11032). + tdb_wrap: Make mutexes easier to use; (bso#11032). + lib/util: Avoid collision which alread defined consumer DEBUG macro; (bso#11033). + winbind: Retry after SESSION_EXPIRED error in ping-dc; (bso#11034). + s3-libads: Fix a possible segfault in kerberos_fetch_pac(); (bso#11037). + vfs_fruit: Fix base_fsp name conversion; (bso#11039). + vfs_fruit: mmap under FreeBSD needs PROT_READ; (bso#11040). + Fix authentication using Kerberos (not AD); (bso#11044). + net: Fix sam addgroupmem; (bso#11051). + vfs_snapper: Correctly handles multi-byte DBus strings; (bso#11055); (bnc#913238). + cli_connect_nb_send: Don't segfault on host == NULL; (bso#11058). + utils: Fix 'net time' segfault; (bso#11058). + libsmb: Provide authinfo domain for encrypted session referrals; (bso#11059). + s3-pam_smbpass: Fix memory leak in pam_sm_authenticate(); (bso#11066). + vfs_glusterfs: Add comments to the pipe(2) code; (bso#11069). + vfs/glusterfs: Change xattr key to match gluster key; (bso#11069). + vfs_glusterfs: Implement AIO support; (bso#11069). + s3-vfs: Fix developer build of vfs_ceph module; (bso#11070). + s3: netlogon: Ensure we don't call talloc_free on an uninitialized pointer; (bso#11077); CVE-2015-0240; (bnc#917376). + vfs: Add a brief vfs_ceph manpage; (bso#11088). + s3: smbclient: Allinfo leaves the file handle open; (bso#11094). + Fix Win8.1 Credentials Manager issue after KB2992611 on Samba domain; (bso#11097). + debug: Set close-on-exec for the main log file FD; (bso#11100). + s3: smbd: leases - losen paranoia check. Stat opens can grant leases; (bso#11102). + s3: smbd: SMB2 close. If a file has delete on close, store the return info before deleting; (bso#11104). + doc:man:vfs_glusterfs: improve the configuration section; (bso#11117). + snprintf: Try to support %j; (bso#11119). + ctdb-io: Do not use sys_write to write to client sockets; (bso#11124). + doc-xml: Add 'sharesec' reference to 'access based share enum'; (bso#11127).- Update to 4.2.0rc5. + Ensure we don't call talloc_free on an uninitialized pointer; CVE-2015-0240; (bso#11077); (bnc#917376).- Fix usage of freed memory on server exit; (bso#11218); (bnc#919309).- Fix tdb_store_flag_to_ntdb() gcc5 build failure.- Fix vfs_snapper DBus string handling; (bso#11055); (bnc#913238).- Update to 4.1.16. + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279).- Adjust baselibs.conf due to libpdb0 package rename to libsamba-passdb0.- Fix libsmbclient DFS referral handling. + Reuse connections derived from DFS referrals; (bso#10123); (fate#316512). + Set domain/workgroup based on authentication callback value; (bso#11059).- Update to 4.2.0rc4. - Add libsamba-debug, libsocket-blocking, libsamba-cluster-support, and libhttp to the libs package; (boo#913547). - Rename libpdb packages to libsamba-passdb. - Drop libsmbsharemodes packages.- Enable avahi support on post-12.2 systems.- Update to 4.1.15. + pam_winbind: Fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Fix profiles tool; (bso#9629). + s3-lib: Do not require a password with --use-ccache; (bso#10279). + s4:dsdb/rootdse: Expand extended dn values with the AS_SYSTEM control; (bso#10949). + s4-rpc: dnsserver: Fix enumeration of IPv4 and IPv6 addresses; (bso#10952). + s3:smb2_server: Allow reauthentication without signing; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + s3: smbd/modules: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + Fix 'domain join' by adding 'drsuapi.DsBindInfoFallBack' attribute 'supported_extensions'; (bso#11006). + idl:drsuapi: Manage all possible lengths of drsuapi_DsBindInfo; (bso#11006). + winbind: Retry LogonControl RPC in ping-dc after session expiration; (bso#11034).- yast2-samba-client should be able to specify osName and osVer on AD domain join; (bnc#873922).- Lookup FSRVP share snums at runtime rather than storing them persistently; (bnc#908627).- Specify soft dependency for network-online.target in Winbind systemd service file; (bnc#889175).- Fix spoolss error response marshalling; (bso#10984).- Update to 4.1.14. + pidl/wscript: Remove --with-perl-* options; revert buildtools/wafadmin/ Tools/perl.py back to upstream state; (bso#10472). + s4-dns: Add support for BIND 9.10; (bso#10620). + nmbd fails to accept "--piddir" option; (bso#10711). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + S3: source3/smbd/process.c::srv_send_smb() returns true on the error path; (bso#10880). + vfs_glusterfs: Remove "integer fd" code and store the glfs pointers; (bso#10889). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + s3: libsmbclient-smb2. MacOSX 10 SMB2 server doesn't set STATUS_NO_MORE_FILES when handed a non-wildcard path; (bso#10904). + spoolss: Fix jobid in level 3 EnumJobs response; (bso#10905). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: Fix keytab array NULL termination; (bso#10933). + Cleanup add_string_to_array and usage; (bso#10942).- Remove and cleanup shares and registry state associated with externally deleted snaphots exposed as shadow copies; (bnc#876312).- Use the upstream tar ball, as signature verification is now able to handle compressed archives.- Fix leak when closing file descriptor returned from dirfd; (bso#10918).- Fix spoolss EnumJobs and GetJob responses; (bso#10905); (bnc#898031). + Fix handling of bad EnumJobs levels; (bso#10898).- Remove dependency on gpg-offline as signature checking is implemented in the source validator.- Update to 4.1.13. + s3-libnet: Add libnet_join_get_machine_spns(); (bso#9984). + s3-libnet: Make sure we do not overwrite precreated SPNs; (bso#9984). + s3-libads: Add all machine account principals to the keytab; (bso#9985). + s3: winbindd: Old NT Domain code sets struct winbind_domain->alt_name to be NULL. Ensure this is safe with modern AD-DCs; (bso#10717). + Fix unstrcpy; (bso#10735). + pthreadpool: Slightly serialize jobs; (bso#10779). + s3: smbd: streams - Ensure share mode validation ignores internal opens (op_mid == 0); (bso#10797). + s3: smbd:open_file: Open logic fix; Use a more natural check; (bso#10809). + vfs_media_harmony: Fix a crash bug; (bso#10813). + docs: Mention incompatibility between kernel oplocks and streams_xattr; (bso#10814). + nmbd: Send waiting status to systemd; (bso#10816). + libcli: Fix a segfault calling smbXcli_req_set_pending() on NULL; (bso#10817). + nsswitch: Skip groups we were not able to map; (bso#10824). + s3-winbindd: Use correct realm for trusted domains in idmap child; (bso#10826). + s3: nmbd: Ensure the main nmbd process doesn't create zombies; (bso#10830). + s3: lib: Signal handling - ensure smbrun and change password code save and restore existing SIGCHLD handlers; (bso#10831). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3-winbindd: Do not use domain SID from LookupSids for Sids2UnixIDs call; (bso#10838). + s3: smb2cli: Query info return length check was reversed; (bso#10848). + registry: Don't leave dangling transactions; (bso#10860).- Update to 4.2.0rc2./sbin/ldconfig/sbin/ldconfiglibdcerpc-binding0libdcerpc0libndr-krb5pac0libndr-nbt0libndr-standard0libndr0libndr1libndr2libnetapi0libsamba-credentials0libsamba-credentials1libsamba-errors0libsamba-hostconfig0libsamba-passdb0libsamba-util0libsamdb0libsmbclient0libsmbconf0libsmbldap0libsmbldap2libtevent-util0libwbclient0h02-armsrv3 1704181770  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstu4.17.12+git.455.b299ac1e604.17.12+git.455.b299ac1e604.17.12+git.455.b299ac1e604.17.12+git.455.b299ac1e604.17.12+git.455.b299ac1e604.17.12+git.455.b299ac1e604.17.12+git.455.b299ac1e604.17.12+git.455.b299ac1e604.17.12+git.455.b299ac1e604.17.12+git.455.b299ac1e604.17.12+git.455.b299ac1e604.17.12+git.455.b299ac1e604.17.12+git.455.b299ac1e604.17.12+git.455.b299ac1e604.17.12+git.455.b299ac1e604.17.12+git.455.b299ac1e604.17.12+git.455.b299ac1e604.17.12+git.455.b299ac1e604.17.12+git.455.b299ac1e60-150500.3.20.14.17.12+git.455.b299ac1e60-150500.3.20.14.17.12+git.455.b299ac1e604.17.12+git.455.b299ac1e604.17.12+git.455.b299ac1e604.17.12+git.455.b299ac1e604.17.12+git.455.b299ac1e604.17.12+git.455.b299ac1e604.17.12+git.455.b299ac1e604.17.12+git.455.b299ac1e604.17.12+git.455.b299ac1e604.17.12+git.455.b299ac1e604.17.12+git.455.b299ac1e604.17.12+git.455.b299ac1e604.17.12+git.455.b299ac1e604.17.12+git.455.b299ac1e604.17.12+git.455.b299ac1e604.17.12+git.455.b299ac1e604.17.12+git.455.b299ac1e604.17.12+git.455.b299ac1e604.17.12+git.455.b299ac1e604.17.12+git.455.b299ac1e604.17.12+git.455.b299ac1e604.17.12+git.455.b299ac1e60libdcerpc-binding.so.0libdcerpc-binding.so.0.0.1libdcerpc-server-core.so.0libdcerpc-server-core.so.0.0.1libdcerpc.so.0libdcerpc.so.0.0.1libndr-krb5pac.so.0libndr-krb5pac.so.0.0.1libndr-nbt.so.0libndr-nbt.so.0.0.1libndr-standard.so.0libndr-standard.so.0.0.1libndr.so.3libndr.so.3.0.0libnetapi.so.1libnetapi.so.1.0.0libsamba-credentials.so.1libsamba-credentials.so.1.0.0libsamba-errors.so.1libsamba-errors.so.1.0.0libsamba-hostconfig.so.0libsamba-hostconfig.so.0.0.1libsamba-passdb.so.0libsamba-passdb.so.0.28.0libsamba-util.so.0libsamba-util.so.0.0.1libsamdb.so.0libsamdb.so.0.0.1libsmbclient.so.0libsmbclient.so.0.7.0libsmbconf.so.0libsmbconf.so.0.0.1libsmbldap.so.2libsmbldap.so.2.1.0libtevent-util.so.0libtevent-util.so.0.0.1libwbclient.so.0libwbclient.so.0.15libCHARSET3-samba4.solibMESSAGING-SEND-samba4.solibMESSAGING-samba4.solibaddns-samba4.solibads-samba4.solibasn1util-samba4.solibauth-samba4.solibauthkrb5-samba4.solibcli-cldap-samba4.solibcli-ldap-common-samba4.solibcli-ldap-samba4.solibcli-nbt-samba4.solibcli-smb-common-samba4.solibcli-spoolss-samba4.solibcliauth-samba4.solibclidns-samba4.solibcluster-samba4.solibcmdline-contexts-samba4.solibcmdline-samba4.solibcommon-auth-samba4.solibdbwrap-samba4.solibdcerpc-pkt-auth-samba4.solibdcerpc-samba-samba4.solibdcerpc-samba4.solibevents-samba4.solibflag-mapping-samba4.solibgenrand-samba4.solibgensec-samba4.solibgpo-samba4.solibgse-samba4.solibhttp-samba4.solibinterfaces-samba4.solibiov-buf-samba4.solibkrb5samba-samba4.solibldbsamba-samba4.soliblibcli-lsa3-samba4.soliblibcli-netlogon3-samba4.soliblibsmb-samba4.solibmessages-dgm-samba4.solibmessages-util-samba4.solibmscat-samba4.solibmsghdr-samba4.solibmsrpc3-samba4.solibndr-samba-samba4.solibndr-samba4.solibnet-keytab-samba4.solibnetif-samba4.solibnpa-tstream-samba4.solibprinting-migrate-samba4.solibregistry-samba4.solibreplace-samba4.solibsamba-cluster-support-samba4.solibsamba-debug-samba4.solibsamba-modules-samba4.solibsamba-security-samba4.solibsamba-sockets-samba4.solibsamba3-util-samba4.solibsamdb-common-samba4.solibsecrets3-samba4.solibserver-id-db-samba4.solibserver-role-samba4.solibsmb-transport-samba4.solibsmbclient-raw-samba4.solibsmbd-base-samba4.solibsmbd-shim-samba4.solibsmbldaphelper-samba4.solibsocket-blocking-samba4.solibsys-rw-samba4.solibtalloc-report-printf-samba4.solibtdb-wrap-samba4.solibtime-basic-samba4.solibtrusts-util-samba4.solibutil-reg-samba4.solibutil-setid-samba4.solibutil-tdb-samba4.sopdbldapsam.sosmbpasswd.sotdbsam.so/usr/lib64//usr/lib64/samba//usr/lib64/samba/pdb/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:31987/SUSE_SLE-15-SP5_Update/5d6206584aa08ed2ed19252942a3645f-samba.SUSE_SLE-15-SP5_Updatedrpmxz5aarch64-suse-linux  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=5661a5254c0d573e6619ed17eb41766dcec93ec0, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=94b14181f933410c828e331641e2674c8e600904, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=33fce42eee9089d26b1b02bea84bb3f161a1f8cd, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=d8bddcbace98b1525e1b3318b7190aeaa653e0ac, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=b27aa7efdac956115ad1325bd2ecb8af7950ab5d, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=8072f1f3aa842cc50ea92467a489dae669f7fb15, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=6001ddd401999d48e94a4f5fbcc619d8396b5178, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=6c80fdc229125a11e58b0fcf9637b35288bca13b, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=5ada926809c4e3387489616f765a4cd22be581d3, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=12a1007b7658422999d316234675e14d32ce5ef7, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=26cef50a7a8156bf63a584799da59eeb0c592c1f, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=a23c99709a715958f6d5c61f0f76f75d00231c36, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=fd48cf3b39a5842fec250dcbd832f22e15935f11, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=03ba343e1e172506ee52f820f497a2ec2510a0e3, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=1580dbb98fe81ccf087599321a9230e3c4c81594, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=7108bb1a84e4976fd9aa326ccb070d4c5d590fc8, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=6873d6c417fa094fa7a90b5614cbd8cb0e1984e0, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=fa361b54999f10f53bf0246105a5be001c879b49, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=9a7e150be05ff0184d62e94e8d3a2885e93b3e0c, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=3c89023d5fb1ecfdd9542df1151230b2d4117f7b, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=4db8d0442331fe9cfc80039a47f4a4962762c18e, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=a5863a1b4aa4dda7eb21e64618ace2ccb1e87d5c, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=2cc23332265825eb70679d552198ca18b92745c7, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=ea6744c1f5339ae65e59dd9cc8f848104b8c5114, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=5019153dfe287fa80aed96de54b832512bd5e93d, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=080793caa910dd5f9bfc8effcf6374dd7accdf6d, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=dcd2e88a371c1bc4dd3a143305cb2e97b7eca0c0, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=88a2220aed79c26f4db36bc749d9e93656dd49a7, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=27ea93ce96eb657deb149c18724ae887dc1fb255, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=21089089d92285f86038aa2c95230ec5f7ab84c6, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=e209c2e78c138d525ac62f20feef2343767a1a52, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=56876679e62f1f7659ec76d893fb54e512c89ecf, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=fb5de777ade74b8d673a922640edcada87cf4ae2, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=126e21bf3dbed8f731692bb1ec2d2cb8f55a6550, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=c4bbd3a880b2eab2e58627f6b83a408829a9a23f, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=de08b21e53810b06477d8ac6edb0fbd9c44b2b1b, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=4859ac1152f709e0bd33a5af3dd0b416156591e7, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=c52076be085058ed72615501611692d5d1308af8, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=ec4593caf22152bf7d9298c00b2b6be79ea2aac7, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=31a0cb07bf72b4593e8267c6f8375bb696ed3a28, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=4684ec76a08765178e17091898d055f56b24f905, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=04d43567b8b9293983b471b8c19d1685d527f2be, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=bd2853642d723222cd6b661a721a5461c4bb5583, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=2e151243ebffc3780a9b80331995e6151174fc85, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=1612199a1002aca9ef956d9285f645758a5b4969, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=f204463f0fa09ac1853f141722096314f173c29c, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=e602b037f1da43ba50ae5123b2e3f3ba5ffc5aa0, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=ecfed8c3917183b9a9c09eda4dc74c82da630d2d, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=43c70c41380b2323daf2c8fc9a559ee359a40006, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=9e93883e81d1c5348134457efc7fc46a6bf7f992, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=b4cf2f4b23e2bf459aeadcab9b127517eb88241f, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=4405e1bf4eb01ee65a565de0c7c0f7b56e0ee5f1, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=bd5b228938c15f2ad39161a3cf5ae94df7c146fb, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=dfec0ff2cbc1614bd89290790ffa7e7734906931, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=328c90691813879bc24da65ed02a2275aad326e4, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=d291e6080d9916b8c118dd0ccf5cd092af074935, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=5dd4880cfd84ebb38c54716484609a00b42e2e20, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=252fc329530ba0f55c90d9c29e78ae6e7c730845, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=22429faa3ed72ff43a3b05889837c0a783f084d9, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=b635aa193f3a536ccd6374cfe5dca19aaa82d741, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=03b101d3cc69f8f3e08a37dab5ae23b45072cc89, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=ea1febe5fe764aa64cd15c58d270674bf2e2c3ca, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=e43eafd026a5f7f529b76a3e30c4d51c5fe7aad1, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=3ed344a176452d4f24c1bd0f34825ae827950dc5, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=5655a2d8fbb863e0445528f4312dae400741efa9, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=b1bc53b8f1ad2101410838fea5f69176a89a93ba, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=8ba30337241df02ed0c0ba34513d6493845919c9, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=1397a9efdf6f3b4964783eaf30ae14fda918367e, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=b4295c2118df04900a1d399a367a4a2ebd9ca443, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=d9c7daec83d891b3ed82fa52d779ef77a9559580, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=ad6fb6a1791094375532d966c5ae34e4e8a01956, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=765fe85b3ec9fb8eeb1289f52fae386fe0a02ea1, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=c1735f1dab7e77a95dae37bcf203ec7387ba1c58, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=f62f62a5a62f0e9e37de2bf4f457dee9a91e7eb2, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=8719403934e88e7c6d68150598ae117bc5724814, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=7b67e3aaf2fad1a7f6f4070ae7b0bc58df4db845, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=19aa4cda46c16e88568659879a808f4e305cc695, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=35649eb7c57efd04fe7124a603520823ce05c05d, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=e00edb623c6888c3b0e73961a8597891d9046081, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=7fab06c573f2bab850f922235c2ff344890d6f15, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=a9a99439f2c854ed2c3d96bb74549a47f95d2848, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=cdb9a70064e77683103411f73ab8ce20aa3aba56, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=b64cae99ec1500fc38ab3365c7b32285277be32c, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=42f67a02efe77ed6c0b2e3f8e7d072104e210e77, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=5535f0058ec78ad909a48db9a540fadb6eabcf89, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=c70f0ec0563d4e0393d2bbebb26fc32d6e95524e, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=01aebaad0cac02a42603c0097fd37ab40a55275d, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=33621e4458e7de64eb6fbf940053ea339a103791, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=683ea25a114c61473aac254d150c7d17020811dd, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=ff9f5c4b2b1306b3067c0497ade30fc9e5ccd466, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=ab0267023f7c97ac64c6cd03bdb5d1226d4405e4, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=9bcbcf659f3ce8ceee29574bcd00d9f894f9b04e, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=4677046ef1ad2537b422f103fbeccb3fe09f8198, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=4177871c7e015140bd4b18ca5d82edee737ee631, strippeddirectoryELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=cfe1658cfe041471d07fcd96cd57adc1d2d7e89f, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=ee6c6b4d775378db98918a3fd69c67dc749d6c3b, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=ae88649c91575e85986a715582ebb02d25e268c6, stripped!JArz,x%9dCiC]ksW3Gi+Ik   - = S r   E  ) 3 7 A f !)B5E1F2L^+ ;I+&4- &  =(<."< H"$(400~  %"P+P*RR?RRRRRRRRRRRRRRRRR~RRRRRRR>RRRRRP4P3R?R;RRRyRRRRRRR5RRRAR3RRRRRR~R4R2RRRR@RRR>RRxRRR:RRRP6P5R(RRRRyR?R}R R5RRRRRR7RRRRRRARR$RRRRRwRRRRLR3RR~R4R2RRRxRR#RRRR'RRvRRKR@R6RRRR|RR>RRRRRRP_P^RRR}RRRRRRRR~RR|RRRRPbPaRRRRRRRRRR~RRRRRRPiPhRRRRRRRRRRRRRR~RRRRRRPlPmPmPnPnPoPoPpPpPqPqPrPrPsPsPtPtPuPuPvPvPwPwPxPxPyPyPzPzP{P{P|P|P}P}P~PkR?RRRRRRRRRRRR>RRRPPRRRR?RR=RCRERRRRRRHRR}RsRRRgRiR(R{RRRR$RkRRRRR7RRR~RhRRRRRRrRR6RRRR'RfRRRR#RRRBRRPPRRRRRCRR?RRRReRRRRR(RJRZRRRVR1RTR~RRdR0RRRRURRRRR'RR>RRSR-RRIRBRYRRPPRRRRRRPPRRRRRRR?RRRRRCRRRRRRR>RRRRBRRPPPPPPPPPPPPPPPPPRR?RRRRRRRRRRRRRRR(RRRRRR1RRRRyRRRRRR'RRR~R0RRRRRRxR>RRRRRRRRRPPRR;RRRRRRRRRRRCRR?R>RRRRRRRRR:RBRRRPPRRJRR(R,RR?RRRVRRRRRR1RRZRRRReRTRR~RRdRRRURRRRRRR'R0RR>R+RSRRIRYRRRPPPPPPPPPPPPPPPPPPPPPPPPPRRsRRR}R7R?RHRRRRRRRR$RRRgRRRRkRRRR~RjRfRRrRRRRRGR#R6RRRR|RRR>RRRRRRPPRRRR;RRRRRPRRRRR?RRRRRRRRRRRRRRRRmRRRRRRRRRRRRR1RoRRNRRRRRRRR~RRnRRR0RRRRRRRORRlRMRRRRRRRRRRR>RRRXRRRRRWR:RRRPPPPPPPRRRR?RRRRRRRRRR>RRRRRXRWRRRRPPRRRRRRRRRRRRRPPPPPPPPPPPPPRR;RR:RRPPR?RRRRRRRR>RRRPPRmR?RRRRRRoRRlRnRR>RRRRRPPRRmRR?RRRRRRR3RRRRRR{RRRoRR~RnRRzRRRRR2RRR>RRRlRRRRRPPRRRR?RRRRRR*RRRRRJRR~RR)RRR>RRRRRRIRRP PR?RRRRRRR}RRRRHRTRwRRARRRkRRRRRRVR RR~RRjRvRRRRRUR RRRRRGR@RR|RRR>RRXRRSR-RRWRRP P R?RRRRRRRRR>RRRRP P RRRRHRiR R?RRgRRR(RRRR/RRARRRRRRRRRuRRRRRRRRRR~RhRR.R'RfRRRRRRRRRRR@RRRRRRGRR>RRRtRRRRRRRPPRR?RRRVRRRRR/RRuRRRRRRJRRTRCR~R.RRURRRRtRRR>RRSRQR-RRRIRBRRPPRRRZRRRRRRRRRRRRwRRRRRRvRRRRR~RRRRRRRYRRRPPRRZRRRRRRRRRRR~RRRRRRRRYRRPPRRZRwRR RRRRRRRRRRRRRR"RARRRRRRRR RR!RR@RRRRRRRvRRRRRRRRYRRRPPRRRRRRRRRRwRRR~RRvRRRRRRRRRPPRRRARRRRRPRRRRRDRCRRRRRRRRRR?R~RRRR@RRORRRR>RRRRRRBRRPPRRRR}RARRRRRRRRRR7RR@R6RR~RRRRRRR|RRRPPRRR?RRRRRR1RRRCRRRRRRyR~RRR0RRxRRRRRR>RRRRBRRPPRRR?RRRRRRRRwRRRRvRR~RR>RRRRRP!P RRRRR1RRRR0RRRP#P"RRRRRRP%P$RRRRRRRR?RRRRRRRRRRR>RRRRRP'P&RRRRRRRRRRyRRRRRRRRxRRR~RRRRRP)P(RRR?RRRRRRRRRRRRRRRRRRRR>RRRRRRRP.P-RRRRR3RARR@R2RR~RRRP0P/RRRRRR}RyR3RRR~R2R|RxRRRRRP2P1R{RRRRRRR3RzR~R2RRRRRP9P8RRRRRRP;P:RRRRP=PRRRVRRRR?RRRR(R/RRRRCRRRRRRJRRRRRyRRRRRRRRRRxRRRRRRR'R~R.RURRR>RR-RRRIRBRRRPAP@RRRRRRHRRRRRRkRRRRRRRRRRRRR~RRRRjRRRGRRRRRRPCPBRRwRRR?RR"R RRRRRRRRRJRRRRARRRRRVRRTR~RvRRRUR RRRR@RRRRRRRRRR>R!RXRRSR-RRRIRRPEPDRARRRRRRRRRRRRR*RR@R)RRRRRRRRRRRRPGPFRRRRRRRRRRRRPIPHRRRRPKPJRRRRRRRRJRRTRRRRRRSRQR-RRIRRPMPLRR?RRwRRRRRRRRRR_RcR^RaR[R`RZRRRRRRyR~RRRRxRRRR>RRRvRRRRYRRPOPNRRRRRRRRR7RR6RRRRRRRPQPPRRR?RRR}R$RRRRsRRRR(RRRRrRR'RRRRR|RR>R#RRRPSPRRR?RCRRVRRRRRRRRRR(RRHRARRRRRRRR$RRRRRR~RRRGRUR#RRR@RR'RRRRRRR>RRRR-RRRBRRPUPTRRR?RRRRPRRqRRRRRRRRR>RpRRRRRORRRRRRPWPVRRRRPYPXRRRRRRRCRRRRRRRBRRP[PZRPRRORP]P\RRRRR/R?R}RRHR(R1RRRRRRRRRRRRRRRRRkRAR7R$R3RRRyRRR~R2RjR0RRRGRxRRRR'RRRR|R@R6RRR#RRR>RRR.RRRRRRPePdRRRRRR}RRRRwRRRRRRR~RR|RvRRRRRRRRPgPfRRRuRRRRRRyR}RwRRRRRRRRRR~R|RvRtRRxRRRRRRPPRHR?RRRRRRRRTRVRURRRGRR>RRRSR-RRPPRRRRRRRNRRMRRRRRRRPPRR?RRRRRRyRRRRRRRRxRRRRR~RR>RRRRRPPRRRRRRRR7RRRR}RyRRR&RR%RR6RxRR~RRRRRRR|RRRRPPR9ReRRRRR?RRRRR}RR7RRRZRRRRdRR8R6RR~RRRR>RRR|RRRYRRPPRRRRPPRRRRRRRRRRRRRRRRRRRPPRRRRRR;RRRRRR:RRRRPPRRRRR;RRRRRR:RRRPPR?RRRRRRRRRRRR~RRRR>RRRPPR?RRRRRwRRRRRRRPRNRRRRMRvRRRORR>RRRRRPPRR?RRR;RRRRRRRRR>RRRR:RRPPRRR?RRRRRRRRRRRRR=R\R]RbR[RZRRRRRRRyRRRRRRRYRRRPPRRRR?RRRR(RRRRRTRRRRR}RVR1RRRRR~R0RRRURRRR'RRRRR>RR|RRRSR-RRPPRRRRRRRRRRRRRRPPRRRRPPRRRRRRRRRPRRRRORRRRPPRRR(R?RRRRRRCRRRRRRRRRwRARRRR$R~RRvRRRRR#RRR@RRR'RR>RRRBRRRPPRRRRPR/RRgRoRRmRVR(RRRRRRRHR&RRFRCRRRR?RRRRR}RARRRRRRRRRRRRR R7RRR{RkRRRRRyRRRRRRRR$RRR1RsR~RnR%RjRR0RRRxRURRlRRRRRRRRRORrRRRRR@R6RRGR#R'RRR|R>RRRRRzRRR.RfRR-RRRR RRBRRRPPRRPPRRRRRRRRRRRRRRRRRRRRRRXRRPPRRPPRRPRRORRPPRRRRRRPPRRRRRRRRRRRRPPRRRRPPR?RRRRRRRRRRRsRR3RRRrRRRRR2RRRR>RRRRPPRRRRR~RRRPPRRPPRRRRRRRRRR?RRRRRRRRRRRRRR(RRRRRR'RRRRRRR>RRRRRXRWRRRRRRRR?RRRRRRRRRRRR>RRRRRRRRRR?RRRRRRRRRRRRRRR1RR0RRRRRRRR>RRRRRRRmCTCUJfx utf-8484fda330b3e1bde1e57f9b1d86dd36f0a3a884eaa187409e5042483d7165ff5?7zXZ !t/]"k%~2_e#ȄjkEltwxc㱣H SݢytdZ,`{.,U'Lo欯1xӇ6( IӁD0N@: kt1+C~5ݽklfAJv +]2`K,fN* 1_]kt>t^]( [eĔzr2 JH$u TCCy A[ H{# \m 5`LMHtF;|XASp [WLCI|NoˑH/pVT\Ԭ[k؆WI u|7oEs3`;<ۨr66BV>ETͲh /}UTה4s:4AfÅzB_Ru`Km9CQ4'M֒=Qewݞq9N3'R.=濁dL}a_:3*oa'xC[ XObIa_$hpwI͂k)P)34dmh(A\nF.]boEy+F Ԋe nqN==g'S]Copj>1{5PGh ܭ! zl#hٰcZ3(veBwQVMlNOe7~)tfT»T{&qU"d#D͘Rt,kGtas_no1{ z.#[cE'ٜ GCU=߂ǴiI|`S&| ׮+n.s JaZh05&B?!<=B-e7oXrw(6j,ʀpp#hژw_'#!RwKx&?*OyBi d4tve!rc rcS%iHI\k]zy#bW~GHA؉޲ '0}\b3WvmkŶpG`O1fm\#D'\ 0 Jh?0@6w;E2Da]ja7B2> Oy׬̦4Iz'o|49 ϲ# kc٦?;hKHKP8Tc 2`QB|;ؕDo|5K.= 4tSob57k=Xi U;!H/jmЌhpi~GogWq{qI\3_`X0u9]kr5_eÓuPҌ^n^42>|~LTkz}snX΀N|%cA~LʤqŭS Va-ALh6 s/apL+ D6 a͐ ~Uh˭'0e(@p+pvst]䛉6: !1WWE6>TޒBUށ &ڞm?t_Ӄpm*.X/B'x%SUq6?[ޣwL6dz?\1Q~OSE -!TBlJ[)n$MaHZ\@E;iܪm0л6DriG/X:!KetESnOMA'3oRYO*fPVڴI-k 9n{'ex?@&p/787:t@IF%Y% Lo-(yj>n4 !Ȓ|LTg h @)pwCD'C]dڕh5)lsO.>[p-K`&Tojgu: IklűWA< :|j{u H*x1r6/ pc3Mu<Ԛou 5t߄9)ĐQ;t1i o?nV[fIfp\%.ㇾ(t ރyQ",;ƈ #}2MwZŲ'귱π hK֪GMprX; 'Mbl]lKhn{9` %fa#s~/8óSTFb(v^h -Z XKl.&/\} _ϏZZV (疚UŁ4ep2bkPvI_um%hSd4d{rߟf5\T̑ ܖ"Nx+f$/Excx^@L-륫w)R0fk!Ʊ2Q ALV n7 _ kEs"}/:r!lR ?`[Z ]t}32I+ &w=1ҐH&D1Ա?'¥_ir*Y׬r B!AXO!8D /R.C}4|Mv>J'`dz86 P穮&W7f55;E;^HC}u'CL%ya SV}{g( I|' ? ;}G0iV7ɯ\-+I5FDJbq 1sjk򞁰s.m3Xcl`.8 H>%pOkzTo$' &=gp7[7$&FBq 3qtZK]r荅O7bs!ڜ'qCHޙ%;M9돀Y)42uUz&215X| #O9ihRމS(޺vOU7m E"a4j.3\ ]+{$*dz.fNc.Btqu :\&Iz2abtT8F}re w5c$_ $)cw/yAw&m)s3D3C#]ܸEkk\gZt;ѯY?ELB(/jw!g &L#*ovz&FE, W b:dLHFإNPh@ 8StġŗBuCk"֩r45sF9v|ŸSsA pX @qBP ~⾡b`s'Uf購aZ؆8#O1}uIf5J:MXFXʬU5ZPgQ, ̴xiSE^O%J]3 1y˹,EBd<*ö8SpqKYQq߶$:y4;`iρ.:k9@ ްmBS5xd= S$ G&*&JVPY~Ԥ.h(݊GU^*1)6x\y3mypiwK\XB?{19V)$3?r88Y 68v )jt_FV'5|xlyiPם0DgM*3p;)'=NZS,dQ4A7A,͵XX$) !난ί > ͆4H{c|OI`sm-ۋj ;jFRPAEpEp.c6.vj`ma\ C^ENX ǧԴfEp@\52 a\[4d# DiƃiyoHX5U4MW6 Y _@a7@8w)YdR&ѡ͐C]s2Ep-ǥo }a8"{|,yF_josf.h7|y@;'cX?R51~^wVrȡ(J3F1k ?Dy*e5mhVV ѽ*ܡva)WmYpS_W CGz*rwjXÑy[{F Dφ]EMqUi$T7Eif.ݾgoo*go.t++9|o)uɼ6}g{Ab0G52RHI>4 Ðs,8G4wniQbAVϚ tT fLU3ˀ8Nw8znC*(A7+M|ءLn}AL <9$k ntYU!E18*HCQg^hd  $JRx*kOwqWߖ#mYw/S,6 "DA~.: <+Z5<͓篝P9 _]E6lJtONY lFxU,BXe*j%5+rQRaX?Lrǥ;WٔbS}]EWK^LPTz0W: #$+sg&=dH*@I!'/pVxFVV QJyCBw7 Oȩ-$9' @!Ks^Bmm=+<dG1Ts(@`M ()ut%) e2Z/M/?8]lq3,τ B^0"z2ãb(y:-vMlcӉf .yɹꭽsϢ7C8eJVY)Af?tɺYP-aksqQGE{Vׄ08?5Űٺ!qq7aBI."__y%g#ʃ-R_Za+7gZ/Ɓh#ө$` 8& 1}Ԑ;q *cil}Z, 6ySoPf$|#0?\c4)[v -P8mo5`N ɳ2F&!P^hF5uR`-pti5([q6{; ֐{5X DJyDepag -p0jUd6+DlX9̉jd~\kKze LMZdlJfK!1=֪neW>izR ȸkS%/wpUl&@;AM.TI5W\ IwBׂ'e|fac0+G!Y Y6E̛qWHmTȏ0Aiw, $q1}- b؛Ly֊)c0:Q(&!Ydv GϬw›t!f5*Ĝl~ vq5auv'/RugI@2TOx0<=̖̾FlZ⒳m`!=0IEj-OA.U0Ϭ@8Sd+Xޙ۟—#U_teg!I!f#_.GrV*<mm#uW*+݋TO8/H݄]]d=AO 䐇Ǽb^鎇[a򊇯>fS9b#vTXu(T1F&!";pTf}h:vcc0EJ`>C^t su?&C7KF=@cP*봜-81EŪ8P_p~~">l.Rl?-bzWs,*S=tOra|ó $ 1{k:z.Yo#Z6Q^7zF ~=fu`?0wǘ$atȦ+6n{G{ݴނ6;]V#{hR,0Q>)Y>,C1+4![!mEk#, jP$u8x%\! =?:Z HOq-po#+" NAeW',} EPSL=&P!7.+B+5ޓ" }%O6*J!MK24yv4g7(D[l~2! HsM .T`plM9 2ȨO.=pI̝4:^ f-ݧ\t.L(R W>>R@mk,CWd|{&'+Vr' t8w:; [Q 켜(P^r}SlP؂~ :N=.E/qC5pn7 ha◹%!'G#ZFP/Qů10Wo~v9SRWiYQύzYiN= R+ҩ~ nTؑ}4Z3b m5 귟:s=v෈Vi@&PE镢ϺBwn\)$G|LFP5#92e^ԖUar󜚟R\F j79\LTj.{YxZ:΀Eԙ [+ AT!Bm[yڈ $j%wϐtJ$q+K 'Y0!'\ƥxt[qM[PZQq_TlmB⩜.wZ'2|IުJ7Fߩ<2n@=-($TjlO&xvܭ(FT' ܦ=pjo#Yffs~0{d1zů⫣8T-lĄ,_Cxl#dnE{+]ؔxigêw%D}mu͗HBlF\\zZcR,h@J.fD}J` "և(l+_u!?M r2̘(,٘=&^&_ۋxk<1K'X}3GV?:h%A=O :cy Y8x - 2kS&\*@VɞLJ1[U];B8~J)02gw@NҙI*,ۡז͢0ZIq,R*Z+zw)<1,1~sDkE goǸ V {u;Zg[{?$vCWmSp4C!Uy3+35{({nJ$pYƒw4WD8%P4=\yMDv,89|{:˅i߲/ks?h$v4AXВr1Ћ_=qs0 ̯!1cPuNP"嫚?iȔf]*y~HrR/"RKVLBJHZ$]b][]B#||@4z|wuT$ fjT gJ7Ph Ƿ~v4QxyĹO"o = Tm!EWIuxɘHuH%!10Ш屓\ZZl~ 8#C'CU4fP#bA@tWTnI? #YpX<_.PoOXayC `tZ`?}=\&Ae euMgT ]yMg0FFzUci_D7kecJֿ,$1>`%fbh%=Xi7Ă32);SUء= }o|bnVp'%Y|nf(L_,V"!9N9jLNj Amj96hbAmD:WOc$j6c5)Q DGj@8- :m_\~SS0>I(2͢c᪯a@ɹ q%,3%^ˡP'Z_v C&z;iu:ðz 6M( 5:. i}RZb/I?W}wY+ N14XQAKUl:*)Wo>薏Jk`2mp&soPk=yVd틓`wIHuVY)-g-Aa t9N0=V/.`n5 W[IUU㼳'sӨi1t=khtp,v0 ^ @ !Vk.(T uWR7'PʍF^Z !@®֜H'}t0֫lXgɝo`ξ#i!3FtoQHbj)c>72 [}KyZm 3skG"ÂEBO2,g( bG{R%2r^YWFa{Jݥ^K:#B9]a#}5BQvrteC(p^: }0ʃZvs8Lj\2oj`f Y7cU> Nߐ.Ҙg NWWsv?bn;]*ިVԔ͖{(+ b"T8CF)6&InsMhG[*qhPFp9p#{4Rao-3yj%$ i-Ɣ =~aeʫ;EH&Oy{2M8WYj5XCN7l 3`%IXS"D#UXlt}5s ;%1U@iH1!ըC4tQncZ5hfzGj 0˱VTcW@Tٜ67 0mgwh<JR r&^Pͺ[,W0 y*Lځ+f !dk~k)،KD踖Ж0TXG+"k?ߌ`*dKq25jؐ*Bb$E3(YfOkU7q<7; 򂾒8?|eP0[,e7&ymOy %Xs'To(Jb6?^ }gd#؅}{taIwOJ/^0]\l@e7t_ ]jA`, Ӝd6IqD>0yb.d--Y}/u' resc@ 6`Ie<$jK mJa9sC6|:pD!\ySj)|̴:o O;%t4aMٵc w;DM9H|,qէzlM0*7| #E>kͯ `hM0KV2{ KQ*hEQt3ϴi*N _7S9s=j5ֵKA i.~H'˪o%ʌiY`bpN|>ܘzwF+M HIJ~y-Q*UԶ~3S38lMm _"SBuh+nZd 3?AH@Yu0|mkw&3(Gv ǐ0]FWHfº'sa8NQZwad?4 [ؒe;Xi-g]U_AuNQm7}Lr NժŔzw N 6 <̀a`tGGڟ%6(O҉7BQ9 Q2^G~, mrwfw5rfC Ԣ$v}WV-چa31P?Op`G,F-XW"_QkiC~!𠆋`7N1P@U'G~'c V< : ;sklw$d`3&Q U wFQ&;niaYQ+m&~&ig>C5U(pvWEaվͪPT1fw N8BfUn_آzM(NLpIR'/?g3 FWBoq:J|ξu[5:&יN +`>to6cj>(3ty ɨ!/!霄Dj^Ic1FU"W年o @-tOZ;>PUS-`)Qw9#JvwaCꌂ&^Bh! Փ :5Y X86.I>fnϞpIM",)6=񀜞 f{^:-Fh-9Vx/yRNӳ!;@Q~8Q) }0kVAM>esH#6^d[t̒z) P>_#$$\؋s]+?=W^)W鋑r "e]Z'}_7 i;*#7 q z`/=ȾOWBއH$Yf _ ,xo ]IxgT]gn&r a[3Td2U,$FW7-4愲Tc_v]+UB `q;.*'%DUGŘi"q@>?y PdXFgr8@?ofHdĸW7d4lUjJb,e74i㉇۲!6\b`4 hd &=nam}6rYo+@2'Toj+:=H **.ڱx1]M-H-25S齤 3k!1D+u=蕪6[vp84NL8[eէUp|;WDCwE)Ns;[uˮO69L .oh7#mOˆ;V/v='@L_ xfAFb4!nn^(w±8?dO(\a7nތm&Y4\xDa7ZuobB%A]e;j |')sAeyhk'jEm>*-t͡FGS|b?qB$ \"M(؛N{($/x(p'ͮsR_r"P.\㶔 &vܯNO=:w^oY4^ 7RҤJJpZXوMdwcz7ݙT FQgcdlj$F%_3@ J,£AP؅~aKWCqL)H 죄9l-@1y97 g}8ӾJV_bD 8ILaJD^T3n)s3VT>W8\d--Q9FAsĔjZԜAI٢ [N3#.\XM$@ܮAtiRG${;/*b!'BL wα܄Ze(^`mU$}Zm^Ï&}I*\Sn6uԧhJz 50eш*>hwL1%^^Dh:d`AJIGi` .ގ.r!( xp`F33q5W iS2j 󃘗rI"fgG>҅q0"K뽉0ID>¦'lC~aG[:z/gw1eCeZ1,A'wJK_Z('D:9|mf) `m j k e7:Ԃ5u"d)O|H,~CzMk,68USꐎ Oh>pnqNoK ˢKWS }լ?kC_lB)Y]p|id!ji)ZDIf4ZiQ˫?^/BN=(k`53WVȎ8˞DK*(S׳QÂA5qG;ys^2)pid/whhNuř*u͊|K{Tcn7w̦'6txA<苵/g =W浱)&9+;>$mbRs}F=c tf J }@QMd; J]8V6\Z3j+n-Isdzc02<*UuHүiԡyOs>Sf"-fs&R9fZUruįf,}0K-'|J}AߒJIF)cDQl0ܼD>eW7 I5ybнʘziwcŀe,uh4L P7Nt=C\@? O; ۬12j$5%:Jmd/ @lf`3rrN˻cw0]ZYeO Ti UlMdyxT'DF sn4E! I9yHC~%2u}6!NWU *:ߺC*dI ́[ 2 &i܇)eOC-rZ'ZL!Y7eSYZbK/L.2 jEʺAsۇh9ac2RA'֢}Y>y.X՜V8ݖ`7&'?m5?zLDMV 8rf Iɹ}@̹tΟxn%2Td6@WP ,}a?71fh?563̏Y{F pS5#UH)jo}g,5G{ܳGnF׋GM8syRE.KgTyaV:,^o*5h?cYI?݋eJe6j}$hj_{<UT4Jv@7_ 3 b^MLǡ(bà%u %ҀSϊ(}Y:4;;:}?eK4lD~M!ؒНiY+Lmry3o̓^WCr֫M_E,0QDCxN:󏦋K$0fe6_Aw4_ԫu$d֦2OEJlEr譪’|%mj@rU9U@c AҢu= t6kJGvEcC]1;oA'M>-ge)Gc.ՔO[RZJ9Fg6okp C. x޾]!/.h\g *QUJaZ.Ft_R2#A|k҅Oy0v*UCGlaw Iv+To߬!W]~ U8&@4 ̥W}ԛ|8DrH֏NФy r_(1*k%.5Y\Ƿ\Т =/u(8ΰ~*/ yN1Xb0`39֧# *%G۵ k\+co^:}MX xoqj!IzdI_i[X64A,O׬ %!S|QKoǠFU99B31.?)tvV㻇@EkewrUY/)zcƸ=-Wp@J8>λs7g޹T:#﷐ ZEYAl!ɮP=Pb~ƍ8@THc>X@9`$nJȷkӛ'@$`d^ t?i"L앀.Eߨ6.(tQв\*MQTM֓sWTp1Hiwyz⬑Xޅ'D-M(u3"5V!UoeW y 5:[2#Xch~UL$?ڮɷzmM}N<ٮ^_x[xcxR:ϔiՋ*!T[~[6HA:@P]~ ~To4fإr(L^j$ZY 3H ";[T`oC4cVqhikӓ1 B QiIڢbצ0VapUܷc6)d4K2ԶӖKugdYloM@ȳV^!S,ׁ|a``BlKѠ h8tm@qUd;Bm^;K4Ra_0$Yp%+sH{ڹ%m v41E8jJ#sEv@^Cpd67dH$}"Z?8@F)e;R)+~;-g'EHBU)C"mk^ܨQ`zgV"#J0 L^>T΄lr /-:g#vgFaHv"dyX:3r==yw?䗲m*|ngᄉԵ);< D8H- @v򀱥_?HDtO'"B.M,K#vMn`N_X|rÈX%?7- _5#`"xGf5y4櫌_CSd:?Ir{?D{7S݂jՌm[ey$ȟuv, *$#',TQ1=emTMeH*!A'{\M>oGAJqu՝[̊9)Krݷeʡ*[U-?٭? ^סF }o~^uvȤ}8.ĺ]KMQ T&[žך7bl 2LҠ.~@0vE~q1,9?=G/@|h{lNJHEe#yzwv:hl&A ~o"LF` nN ̈́AUrE`_z8^MqmVlemi{q!I՟l.1yQ6zN+vt: lkft yP|i6oo"B0_yjǤ"((L :ieI3dYk(i_* \1)B9"zaKt{m>vxSl>~ԇ0@ aȒL6)X`ȮM3c1a(,5b;;D1+ 4x㶄Z=rOV.).啲4W!~6- ?ǛI{ϣlZji;UW%]r~UDu]^6X/=XJ5"cM%)wd=C뵢wس6cG"*e[&#a!(omN_Npz߯.5۝(>Fp12;I;y3No ~>l΀0h @9Y?9tKͳ |eZ1?qYJ04m[b+@׺Yݿ qD)' W6vCpU,B^-ѐ\erPpc2~ 0[fO%CT:0@&wU-'r&XW:ӻdMznyW~e+d쓻~Lӓň B¤'xC!ی{ZId:ԯ.Nx\OH` uk%[8r6 M)mGx2b@FehcuE~< X~2K*2EώFWbr)2l@ݸ60RtyӹQb+W萞=V"$fܣ;`]xO6ϐP%lslDǘH'$\Wmze[z3 m?:zvA:lj8PGu=d^Cjnpގ|fZ]TڣGStҹ0eNgFX"zs@)h\ŮQG \3%ݐ$H~I&W ;` uXKFKtzo_c؄LÖCNO]M浨aí7ϲw،%bWk);OS3co?vv ߉0mۺ{Nde1RԦjS~E=&!J x-YofoQ_`߲揋K5b+XJzT$j Hץݏf/2v8wp͋~չr];~}d|"rB}=hh^v?1Cχ:"ea'Hr%d0#Ck(NnkӠs*.P&L Kb`( @f3z@é f^)_HQ>?xĈ;sֿBG kd 6[ty'k;c|r8e}I(jyzXo:;$ +=r82))ə!1 .RSUۀ·DrDp?_[천색<\+zm|۽`ݘ3 sˏX=)\ԽD**CHilFWZl1ȣO<|=%3q;Ų~"v!6MTASr;E6ۡKšAE/jH5ɨ9 /2ol /[ $,+8咑.EBm5#VNk>ro-^ 6רU|/c& 7mABQNߨ%_2vq '!f9f ACujCI&:h4Xr,ͻjbS,-7q!1JĚlzT/~c] DUE?h'Z$R3r}*wGhqvKg #C+gAZK ŽYz0h[~:Jj4k5<f*0P49Z?՟@;b>XB9~"BMDcF ]AE"i nT+cb3+8*Bb߮9, qs|W.f{(1aIFR@+Y@$G?s`ܖTe)U |qZ)i2Gp K#k'i=qlXb%:Q%QX:l8\,_m" ի3EW?S Q-~ Ż} 氠f4,#G3u_:.֟S-@%tX#4kE^g;+co .9>:ߎ9/ʜح-кFū">ŒL5W d$f)n<qdVr򅆢}+Ě[m(S7&a>+Tb ;>ݚ:yG}w Q6q[p@#NdW4fi f 9|*Һg ս?S\[^ +_[c&+7ϰts-7O'5S hO בK=nn\3.P&RKL9?p+/juIzmLV룗~{UFTQU0 y"j;1>t"v[26eT qK/B ?h37uMz*e=yL(O* DSD}.KUx!+D#FD} ĜZ?tq2Y6O"D26}JZWp3鵀*:>hIzM vnSo2dwCf/ߋBVN ,-K@yѷYpZŀrO=.5MeQ2U#9@NJV+<LOm J׮k~E SsKGj}(ϱ+V4tFw `^p Tx3\L'JA(ömÎpIbg9T`F~U-Pcn[e}߱3Z?d/Z/L ƃ2:+T*JVKdsDɦu=]Ρ<=VڜY>Q#8`V~OeҖl׃c1g==TLm2/VŹkМLf67g:#ר[Y&rw`J[Iwn/M;ʇPPCP`f{ ׸Q1"ck8%NǏYDkƬ:]-CTt_P#)%RAUHTP Geܠ$0~u,UzvfgTa{3^eHY\3 '?qDfdIЛc {~*~b{Jnm8(Vh%MYWem{&bMolwȔ,h5E^ < pP{toB{s,g^M|k ԝ+ >QP{ j8?⬀nF8˱ їq9aOpKOI-Jcdvn.FR)谸sD U6‘L?7CUE 5AAuz]kB-b GA>BYleA f):;A sEk&."Lڳk" rӑW鷕42}?V3Nj/IsLxAL!U%os'`DER*s|မ1laK[?e46S:[rUgU'X&t@Jе1甫.U8-̆:"H-x^rYKC\|~`5OTӄH8Q[0B @hꐣQ Fp%c0MH#HJ8}л.גw:jڦ9]OD3;>bj` ׻b\&ҦjfճD5`te-̝r9_1vN-+E` /E7 ;͋n-yhGInqf-83DVYg({$&uԈSu7R jkoK noZ5Sl/P{\gz?PwiE;hNJsӜ5ijw" O`R.#0%g#=cÈo *N)f0ώi8jSWY?rm,[r*1?J-xKk+ 1-;JW@\sdhG(2UhWL=k!O 8%gN+S=_C LS^tqX`k|l(Ȑ9;_q_H-/k \]sMuO 5[q{EV*wr^ݲQ&W^;+x[W0_&Gmܾ}ݻp$E4ױ}9~P+BH@f2~}R"f\XgQW&FRzbF V[ˌ鰼z5VF]2ݰ]$ĉS*YRuEppt@0'A_$#=Z}&  a "vfl~ AfV 7tZG@Em o9vRrCT_{6}:X QcKJr7ʑ\T>,|^N#i<.p}u:ݍ7@B?TGnّmYՑ$Y_WտXRX#OJ6>zal?Y/Rduh?`dUD+jULJrp?|ISb:S,NaO0*2pb`Xq~,C#I˙)*A9rfh$wZ9hO%{5a{{-Iq"* k6Ld9Xvrp7g0t$vj;ѳdU(h/"Y`\/vA{,f6hDЍ rZdIQs;`X&c*|W$/XN$ƺ[ulTtgM9vym߸O5 y":aY/b墵L,⍳5R~%_KGUvqܣ&zÆДVgS}BSqA;\ɬ;o* Do^O?:WiE4CydUq~ϘE=DꋉIaUOY?/iMevѮ7jҏ5-ӋjWW )glxJ*4AhAL>% |!oi}-^?lUC}|$l(Q״u K_G!OwbEatW;tTH^/J:UҞ>T F7'hD:U 3([mR8 2`c2{{IjL2]K,nsCzt O)ޑ+D! =Fii;OMI@!,Qk(ПO3)HMu3e46aU#(q+)3#vp/〔lEa;ι5zK!3feK]"8c&[tEJߵ3W PT4Z!< 6NVAoqwhgG #efIN+j@lk^/:53Dj|+yQ~ޙp6?j9$Ȗ=د/m0tH%ZbQ5EUzW gXPN7`hX1ՀR隕-<w4n{`vW%1JVtE4 y@MCGVV&| TZDd%)\ӯ'ZG1i{W3*\L:4,`M驷KPHس~x8 jY[Mik]TKZYS u||7=,j`* w83VT0p8N ڞr.w|(*n+%y#<(ѴZwޮ]+z3󷶢-2-߇iu:@LJ.t##zr!þ~,q{ȲF=vF-:tcZLsbauy[m7>@ EVt}Q8꣆E.x.cTsu?gIVKͅRJl nnlgT~~+.Lx;E@!wF܉(q`ow(}6E+pr)pp>BӴeM;F]e8Jg5}9AowbԡGspvi({D+jlmp{$v U~ܻh9k97J|)O-<~p顣F7M+0,kLaժs16(A,yJ۝m@Kfa#Jߍm6(0,%rqCTbN>yИ$R7Fi;vZI¦AZ&H 9 C :n?UlF Mk2 }CVBsY|#fI%$!g:^|\[DDn$33N; =s *WJ A$(^^E4.ac,p\va@0 >IK:=咞lh˱%g3e`"2ّ$- {S~j2WTj:[qIx2/(Cag$e*W吼+wn{"U4 V6nlR}J14g}& Jqڎq&ILˆf8+6gKCH" 0<0]8A>=%]a%g+vhYYEʽ̂,.已$U+UP>%Տ4*$huJn9 y"Z |8QSq=֦Q37À<|~&3xxijT^} R NqpN6 xvDm s//]uMd@%*x9O/a@3d; n.t.}H4;,CL=CTQ܇HRX |gU]V\tGrzl%6/@磇8,ig %gٞn*]uġJ1/Z7A#:k% NvDc87My Iii/b(8JҮ}:} 8 E_{p 8lT@IDuI ])dZ]}}VRO\{<*};B~yRŭrة8gGMIq*u0)#[:?Um+ؒ_7ԮϠ"G:<Xi(,ktFplTȹf)q P AdB߆6X .aAC:uX=JUG.Qp4֫~fyCXcH%I=Q… b|`B@ط,/r>HY ۩4*|ru\FJ @Mg(3Ps?&ʓ`/χ~t5\-KS+0\(O,VLîD o_&'gXA-oX/75;u\4 lTĉB[i4Ln*/w<$ĢQ\sb ~H.r'o%pp4_E؏ fP륫Luf~MG' ~w&堋}S K~|Eݩmߓۡ˾?κOGw鯁]!d\Lgd'ʭ!Չ\S{#]mkә[S#&wI6'a,В/Q/r<ȉf oW򏹂 ZC-?05`18\3V5p ?_HdjlE/}j{ZgwZe$"z o Y D3Eĺ".ZL%O9vg%L }ʨ_XsٳGpl-‹ [?gD6Բ{|k n</f3E~L,+G*j"hn5I`lښbk =RG=Kj4<,Z\tmZN  Fn ;PJV&˴p/ۦ#/)=#W}iKon#E@XzNyTd0Nդﭛ})kJCqxb451 T$Pr-J \4XV=L V4}8,7C!?N_&mlx߷'s\K]1ɀg僜1DO:XÒyL-&.4~9\#OРSh/qr^PDiƪNuP0 7,2nHrSnB6n"e@daLiCߍ˒tfvVkl6+% $?#۠ŗKkm" +a1.}+ >z$MI6kmOܖ8d!@ͭ.Ǩ{=vhVZ8H ChSƉt37p `"s/Vʌtn&/BnơV!">JnBUfw3-͒Fj8pNjBi̠N.đ;Q C.Eʷ6,5 f>%+/ET}ttnc}u[{dXv 9+ۻmܝ4ЮOA<7::ܻ2Gj[ȇ-E&8%)Ey/wyVA؃|,ժ#52&ov[mittñ]p~b:^w O_Еy.Y}rڱ ^yۭG'^e:#@/5bُlp Y=/XY/FiN"@=M ,\~E9zje!%X>z[X(AjGj?I,R |dfރ2,f#wsW QWA0,OVbASu&9f6(C5w:ܓ0V^:IpAv}1!4,=:> ̳A\|󔷃8_QVyƈn2*Ͷ/+X'y-–vM|>:ɕ )ʊKKtK E**c$ c^}Z4|iӖ|rx>"ޮ65lJ[e)T\:Wa886~AC2QeS&9=+*nڛWW̳Sy\s+NBrxmח)e%~QӛFQ8%:0Y|"q7XF{5( gctb;*ﶕs"v}TuMB.p Xa+}ٲ]E*"fث嗀 8 g=nCq.)wnVڐ< / eXf'p,}JP#?Ŀ礧JhA#ޞRi 1#2x< Yxӡ'8#0 x+:p{- 2DXѝOm:!Ī>l'Pރf}]H\EPBlA# ma!T\ʺЋ/`z%Vy[qG4-%1) ey!@Z NCq# `bP9"{ed =йRgْXE~sA=*Sc0B(s &Gd>۵,X9dB:M+ôP>r y{Gfԑ>m*&_~~迀 K_ 3yWT[]SNYL}M:d{-`((x.\Ѕ,zbGwϋ?gef=˳!yG8kl,];HT+-yH"sA$ZF[)#(i:GBmuخɄ?il4$h^ OIORCˏd!`*p#- ݨM:Zϩj K00˓g<+~|hQmT.KZy,,. L +G:$˜'pD0])jVMD)$j+sug'/;dU'`!pz\^Dj-qȮ Rj$12T,R(eΒO 7㒎6&R֢Jל|j9zԢ;Y 3ĽI'#Am17P`ktZID%!t3Q=.4@ s9?Q7^p":cS.)އ<\*VkUi$q.ܛ| w͝v)6dʙ~Gp|LMR~ E]dnj7^ v .^^@eKZ&㌄Ϋ۽E)}IoxIFI~=:++F}^1*p#/˩BWwH%<]3nQC݂ 9LDzAT;ngT+K6#*ٌ/K24, I2"w6ϾԡQ |i}G 'k*LUi!1߇IF$F(vGu ;FFE.esQRo^D98G4"6]?Ry|Im4 ZR >c`0ٍ‘׆$;H}’Z0tG@P L|;{}(XGEW\>R^Sɪ)cQQWUtB*? s|{J:bS,VaOO1r:lu~Hk'{-2iԑ.:0Vڤ)K%f# $zXLH+Sbaю;a 'Sfb5Eu~o5\iɡ4a?5"[l84%4PM$5+-뇈zG* rۛkx~ˏvaY}C{Kl?"σ>/VW4 2&d#g/ME8s?k)'^rO74I( xb@f94V3=GKA<}\2vulve0Iz*]0j_v{T9Nc'dY=f ,=R-* /6$$}܅4$fbH[3r/KfQS=kCM5?bZGvS P:Z֌񦇬,seҍA4'ԡᕃ!,6ȳj5[Hi90.pnAcgE )DQz{8H7b)8r䜄Pn"%X1:;)֜Drq8.BJq9bhQ6 dY]~Pi(ڳ"_&"ag}I1aH@C .ƙ1Oc0_:,z2Lob9.cOQDԛ [P%9s<k7BeX3嫼{2Ė:l>yφ l&fؽǺwWO^.mͶ eo LIЍeɩTv_T"h> g $LhًGl8r̷c~z!lXcзnRjP%$eˋ:ʪhE?tV=I(ZPȬSQUgWCJ~{V|oe)R kv|ŜڂDGɄSv*B~d+KhFf}EڡL\jx{1 S7FٜY6p t^  "QAfJQP,o62$>><5.]~Zx>ǽOf2MQ |LuT%4@PP]+) :Â܆!k!d/VHu~Y:-4J3c pJ3G)+ob Ƒ#z%{% sNvY]pVbgHfkIc/^>({V%|Щ5,t1:!{L9عXk}qWDfGO`OTFM~̱:08C1P+ -_DXs(3~F=Jjk{1EnڼcmvxEQ`A/f[`@fc,I ֮l7e>$4fm_mki c߁h $Kqśɯ2s\8eY:ꝁX\V0d#ȆY'2i zZT f٨{@3.? O`3\ث[6wֶZ+{m/Qlzxǃ'ScOIԌXvʻ`J~Ask+@ݏ銺u xn(\ " 2qP;\uHI HIʴohF7zgAq#NEPyYxU[Lw3 F ڹV ҎBn:X[O2mjnk%t^D4q"f,xli,q5lz;ץl*Qbbl1.y,P#g 0޿z}f!'hZӂ"M`":E<a.16$J@;=N"'-t$~֛p8)(O{, p?/d܏o-!/af"Pqb)DE U@}O]q:kMN͏X3-%f]vc?ai5s9_ޚ=iVci  /F(*vel{kƀJY]IsKT@W087PM$P,lc`ZzebÎ?ONV) !T\ d!c)m?5UL̽a uF{뺏5>1S+ ,TL{SPiS22zԋ6ʘnBA70 k8,4 rPE2J~6dXy4rAoqnu [%,މβK~x5ZPMIp{@Re0s4192'0֞f4< vj20)\#yUi ;v~i }QWP)>tŒ9nlYg37nV|v|N}U8Yqhm4`Yw`g <=հܪ!2RX[>~u1Lry(} +FRrJ?i[UY2ɛȪUy(7CF+Kwm>/!bM161z tOڳSu>֓h0~IOrE07˵ﴣÂI̒r _6եu(C֠8!ivC휌Q&]!<;k˳IǥZwP%0Mʮ Qz8z)Ng`iF8f8wNb.Á<0G}pI5zLIh?]i)At@ȧD$TJYLⲑnGx.r93VR#fq<)~?To¬HMC z@hmf m .V?4., ɍ3x ,O% Jfi B ݢXCK1 LN{ 0euEf`c6iL,O\E̓@IQu%/=IBG7b:H,ׂʥvL(Eu{RG茇5:e ^ׄt>}0k>z[&]O{"6yXt$BKlGOuD6-w\)Ve\32t㹅\x|.UK͜`.`~FP!BsR>5oB_Bqurc%=XcP19s^Tcj#S=Urt>?wn:@,Q\qr$uU:Ґ oWޚ#Sy)[l ]8c`jf&-ކӄ`,Q̊!C o5&}!qÐQG1:+߈qFy3[kS =Z/ V|fOqyˇ)i=Y`C~Oi-Ks~Eo+<N7&d޶Zh){s3%r2bd46R+2⯀ jeY!lb u2J@囷x}`Ѥ 0Dڵsw$1ܕ0d*/K2`nMQSͭOhV $n#r[O/0X(a"R1:*f4xR437LDt+֠9Ӯ#]Ts?Y7X\f_z~`갡[@q/Meao(c2vTf"@ٚ+ Ð#˔Ҟh::s8% '3;Oߛ{aMd(pлH0ꃁs=Mb mi>)9&$3NaGzݏPS']׳Vⶑ{YC h `*ۇ-/({f ==x 9˗&K!b,gEb礏PWc%(S$|-2FюleCyʡt#&\Ym''INRBKOḛ$i q^6aN.&ɾ2T > N6gۉ 4^7aEzyV8bBBP+&_̩n,|ht՛_BRY&ﮪ{J?񇚔Bж&\2Z֬vu+z~ɱʽ\v0Ћy/mil`/ cjF->t^%Ǧ&T.GxߢOr5np Xy45:zHȇB9-U7Nɍ)5 MtIo"XAfw{_K( z^Bchҹ]@-F0%5Qcw~m%cF-$,ȇ H9nQT$%\VCwfZ/=^r!5].j! ۟tIJuC`wI:'M>&Il-O|@f0OpCʏN_* Og܅_6Jxc,oȢT\\MX"t"u6HL4NZo\i1fCؒHiWT#=^aΛk/̆ΤԕoD]yH5I*k TxHm NJEL vhKm F%՞gLIW4,3^̆yq˜^+ǖ9,i 8xWk[`DU>D~Լm!{fHݽ"gtPm.g_ -E6XְAy_% 0IW<ִ7C4xPB+&=^.1 U'$LNia1y\_hhqU Ǡ{n+dWg_}1&R]*K'>ߐ)K Lk 2paSws7)MeOmUfϼFts΀j]Fv-%6-1&פcNU pX@&B/*BhExgc;*QtnSF?b%iAM_a16TrWVYhOm7km ?2ŽC~l;[ aNnec8Hĩp/%>¨i: XA9T҅lIrQj3#C(ңmuzlH%#塲a.+Wx~ qFњr'BF :|(׿0̘ YB2A".(C!$S 7-bidMƙU{x^;Y@f1xri]F`}I.:asc #_,BcLMe:Cz9Ie wJ+ ;Ͽi?򥗉 '*ih|cɑUe02_$^N5*YY-n6\8U=`#l-h!ʽȨU -`IvQoy> =$d_{q:T S"+/?Yz^D do|wnq%*2k@aI:̈́cL.Wg \JǪۀ{%ˬ`4 ~nBiOK{֊lGcdJ|'RqwnA-EMHZ'#Q=ó]wutc=ӹwa"y{- ڝl9F$Ϛcc =_ ~,invʚo2b8 +^gU)_=dF8>l^ʩCSDWs{D{$G|Ѭ<0[hzjOT(=ouLqUyv@Emք (eDͶbְ n2ZQ46v/\s\aC-mcb01皷"kHh[rEI>+aqwFQLrjS[y$|Sywч;kO6>(vA6(25#n Pxavݿ^55C(JLkĻpO~H4g=LQ M\%:ng 7EY#0疦51sNשHҍ{Jqp=kk~C u ̜̱(2{ a$gP\ {0w w-t+|ÆiI䏕r1̲6f.g O [qT)$b]`2C[~Ks ڀamן3Ƶ "~ڀj ztԚ1~5k3{(UN'ʛ|x0uo nSH﭅;͟o j~:΍ JZyM?bqghj+Rp/MLAiK⋈N lb a"XsׂI.qm!dԥ*|!4W{zQ8*ﭗp,$rۚι3t,au9w-r@Qvcs{m|#Q9U6 dn0 نKNV˯׋DuCG_Zv)*ħ\Ԓ0[Spf±9uGÌ-_q1 - o`n@-kEuۮ CEe閭t\{ $'u{Vo!MtֻL1v*)  FHt.1eM&nGKk䶮@K(mtŴaRȹVYH}ydw d Y9e6E a<޾V &;Q3ZƊϴȭ<J*=YBU젮1rm6/v15LL`mܾC%;Z~4;<^#A!*v y# ߮BG6yQ V^;3$Xi3& i-?b9%+;֡{Y$03Vcm>?w.="Py4zmz#N؊ٿƛL|RযcX4ޒfU8O園3k_oIONZs5/8F)jcI] .]^R1;dYݖV(1c53/.%=Ӗu-x? 7-|Wsl@+ow W؃Rk>=ZV:XpmK@QN`mۍahD\HYd}"U<"j,`;$cW@In>;nR Bxmdj|fN3L!Ar%V]F`@xC(}P8x`''lӂOz䒗Jgb~* fQUYr>jBII ,57zײS,$[z`v5cbzY»aJ;e]16V%iE:D. ڒE#gNLP[O9mF ,C}->D~Sߞ@.Έ( bT)V/U vzO4&)+AIHZ,Uosl=+O8`\6:l&ZW`+kѸ"JEiRB.A3G:M-:֖i_˶@]$ 4*@=d7X~ :-;yC 7|e5y4<Ӏ}ǜ KCfJ/ījĊq)r&J0WM96gUw7=(RQ!Bsڛ Z+HHX{#v>I{,xkYM>3ZcnP`|zVBR7Z܋ ~pɡN\ <~L6ks,bez˯&ҡ"e>._KOR+7.|l B- fO])}ch>fg|ó! %̪Uy4ځ ܒd>p˷F͡.L uՌxz$*h^3WW"u7op9“~!}@(<wan0w7k&T`fyR ƀk3oe]I=3$P_$٬M?)7rD(i(FpQAG=ǺB[i 0/'vDo%`Xm)pV;G 'w$Ku Lshܬ^j %ފ*N);]s;*t(h\YKD4Z}Bw2.:4  a}~)9|1'1]e jWSѭf&]͢Z^˫>s1Yǝ[Kc _ӤJ)?*lyD/2~%m[et>X a*i9`(B&SRe6h{.HR(u9_`69Zi aJ p"KK@lyQm0L%lHzҰhFcpIZ'@iE))k}AVBϧ07lݔ5+vN=Qﷁ>#m6=*PZcm 4s]5>Eſ;WF{͜)e5[^=mw"8I0b2MF {dbTǯ|,m7j@q\{d&ӎXg+/&"YxRD35E*p 8mwȕPQD*O" oOp Sfw["֬qQ[4)dğ tуOo#M)r R {<~ 9*CyIߒs;pʪ$?>@}O>*mOAm,l ?Ligp$hl_;yc`$G228_<6G;*z>BU@ڞ-h *.yQFgGXח\!HazM :,ir0qgع5=-v6T2*(@1O%e.12凗?e/р'Dc aE R0T)aժp kNy"X UzF]}}8[+&G8nM@3 {`$z0bwSAe;*yP(Kߨ`_3E,ftVj|~ǼRqSUkh:ce+F\Vy_KOr6m,a$%0QLɂR4}:;oe>ǀɩ䤘¸Pc;jÕciw]ϊ4KB-W\0ٰ߆ Ia;YR)GpͶr|Į94,n8߽F|C|tgp*,ue`qÌZDzBqcjc";mu_`TIMȾ}1+%l,n5BsL,}|&/yJcx|Lfژ\.2=Z낽CNR_0Bö*+jz{LQT ;#QFO(gkmٺu*&8\7;촗8fF29:hz˅,:(B @iS?3ke8.="E/e,xfiR}<}78Qȩ9.:!;!\+'+$|r*|`Sx)yy1&:-mU(!S&m6 ?T}.|솏Wn4Arek{WB')E#Y6uAzEX'l~~̒iX̘X_3IeaEe7Gfpi ': W`j ߪqvVmn۷Dd~Zt ic$s _= U=7GaNP!qz-no"릣 : ҚN]. [:@ #iἅ^aaSUu >Mj ˜٩Prtɪ8h{B䯞VBB $f[Ae bV<0ML BٗgLZ6:Wb` /)]n9W*s㷍[VC ]׾p$G@eڀoŚьYI!8BSmbe(!xBBbZ֛h܃%8l;aZN%پVն8]4]9\0{qr0ʓIm;s?VSbH6PX#DKC3Xd;t{fgy\zdɝセ[siTu %$&e27ot8?`ٯ>p 8:AC@ԅ/F't5 C֮6XCh D#`'/t5.og!ղ>Ă9Wtë nxL܈ww]΃$OpڔP֝o >Ũki=;Ps 6۽ABԚ+iy:6:tW|l1YV~ކ5]]A򊘽/Nv12T+{eq9QPkئn\$KCKkioۿ6$o{=4L! xZsi2PUgO,h]~ȩtfdJm[=EGAdxźtIS)a&iեǏ?Gޡ{iiipb|\aHmf<[1-n\sZ (^hv7trf: 4i}]PT^> R[#i(( t^2fa#i*دvo׉iݒ(]>:0)R_r{#U赚7 IPO],Mdv|2s4q|& MUmV.i>CƊ!v'hS.r.4"YT30{Q H.3nd@2AXX?c}Մy39%\+<49rU/ o<t4vױ*R_Vn,_iO1c#bLIf0QqŞ/Lz \hc_>3 l  w=4[_Ǡ`cRи2b 6Oza8ۙu@Lq/Vr$v.7|D+L0E&#~帣d8(7)߁ rr߿X NGbm ELP Uқs_6Heo_vkR4McRt|~sh0$%E$\Fy?[BCI rAUn;?I)9Z{QJYUCH,9Ї01_=MplAYB f;}#6pU7=~do.@fcr9g'h5>yYap% @ 1 5kcmo4 |*?_x̐jt#fиzi,L{JN(?\Xy{Ync-7nHXdt;<åw !յ;΄&ak2{[,)K~̖\1C`-ԼS櫉LY̚ux{ω\lr߷ՂylObB@K zſylTg鐒ZgT5+řpqd@Z%%2M#BN.d0Ʋ`تc+\ÞYPIS>êJ- ޕ%c߾6ñG"-H"orD8,{֘0va:T'h@XZXr0?g2I!"hb!*}#- I$gĻ:b\,p18Q'p6w.1u7_oCyVsUݻ I@҄\5oȻPxBiy[duy')ѿQE`F"!8|6~dEOmd.fOIXcBtOn,uDЈ{T7컥D(E[ ->yTR/DU_ͨ^&UT;8/T;5q5B488 ٶr: *1blײ P ..ͲkxbРi(t,!gaؗ/F'h*hִlX"v^nfu@ty2yx(g 9ulC>si re# ~kXZ;Dmbrh*MW"q/&U{MJջc7NĄ6Q7 :v;HҮjN) ӟ`"/1tT}aAR$Pz,aY8o=w8i+mKϮFS',=e>N+q/ mP_6dx^KYwlD|1yʪh36 p7L)uS*w[Y}^C5!CݨATh05g ʉ5Sqb3[bNՆ_4 gd3k~%c5N"st9"тt/8/0չ>-\HT[ft[@tAq@@!- 'AKr)cȊvAs9ѱZ `PPd2;B J=vɒ7!ܫE8]]ƕ#?jZI8> Jd0Eja۠c.yT`6E8ٿ.՞t M`{`/mEU9(`U? ﶈ[= `a|D3[5 5] J7\cM%ό dZi={ ց`p01=+0]q?[YVs"Jʜ9V(9y#˥d J zm}pv"[zI:1COЇRTι-*0`Ct|qK-~1xu 쏡eɶ%Xl9vNU} s."7T4 9`=idz0Jh~"x@tĚ\DsG*mw<h t^X@r̕jϱ]%cӊ#Vd =cplJNZ$Hݑ #pC]NOS Bz4DvFA{%K*̆P&GC@ 9U[8)Z޺H&}A]= -φk:( "ۄ`lu@-ܞA Y-&j{rҁuT9Ii _hK B\U,Y.Xc@0Uf W^$@T38XPk6i* C۾ש .4vpK1,U(6r\v _>Uk)٤,1uJFG$/;v-՟fbbxzTV$>05 2n`wp/QDv^ JdA_^OLb;r/FN,[Qk]NkEnshd=D+."AdB╋^%__ݔqq4I7)"e~^-'P!}'DU}ޙ”灇9;4CRnPЎvg]z^*'v06ӠBbCOi.3{xIIn(5ӯ6 mjkioX3wjG59+˖, wD+KB^maMKssđ\gcR4"ɯz3hGѐ\= "hNr2sNt}X ~r=bT=:xra[A ?G ^!cGNTlOq]P0RH#͏{ip]} Lp%o|74[Фm/غDA"*4P#H%Pz{ubD~S[nٶڀ~սJU@?m7' :?zD7ysZ)RGGr`Vw1k[osEj `f- tn++"0kIx@3<\0t EwK( SsMK ;#L!j5ʯedP |%;ܿ"6L\,_Mz=[hm֯2RVuxɭ+\ho%&S 1b^j-ĭQkFt;бa1$~K?ɼ %Χ*>cY? NֈA7吠w=K |!QvcӠIf_/l\YAH@7#+KY!xs,W# j?s}.U۱BJLM7ŮHC)*ΡRES v<۰.* "[oa|_2*'|VcQӹ$&G4~B xdy'dtfy ՜ݓ- >7Z+ M =9dULAP76{9loX,6 c~U1CYxQeHVV?<&4vޝ4$ :-@kl_#@m|L?_d?JKGd 9͟2e>PR~xq\sGɘk`"g3GA ?ERlX`M^Dp Z$웧a*~,l̼|V  J675H'¾`X.bT37~}DiR|*jYLFfYNz(h[d;G "ez u4KjLIgO Yw+JgO*'၄1i-lrAׂ2LMT0l0;٬<'g>RWJP-d&{N(rW&VMOD+F|iSJs=kcJ)ztjfrfK&s=E,$IxS &C\#myoj Z lX @NKۮtS{tiiQAAnhD/E)Yp)m<ƥ'yfhw:UwK3 IXITաC+#NQ̓cJp(L֬7(]+eYp S#1y6:O?"KliEbi*(M%.$-ʋ'g%ewD얽hmWq7CkqmRF`CEl$re `%YSF(Ꚇ=qRx,=%\l5ӠcUj`4 }"*H+;RwOikuAL3._F : 'TQ)ؓL#yʧ?AGOy;8Y_)ܸ#c?)F.Pt@:CZIm=3Ó",_x%GMD< +מ.4ъf"N-`x&H5dV I .) ϓ+ʫA3 'S[onk"5EkBM- ՒI:4mt_GR&MGF1:ګEwAK jR.f+\M~dcG>Wnh3,e.!6Tj̣JH+Cb3d+n̢#-ԓ={KzD|펿U\)%9NMO8nCA4b1Pw93W]?ѺJ_K\2}[ٺ ᄔP܍ln Z?4DŽtДgp5z PRQT 5MbEd=b/*5$;gN!WQ 5eC$q<(Qeռ>?I'ԆܨնXe߾h@ 4̗AC Oɖ]$+ee_c֢0D+<}'$A _$Z2ZXtLDI:S/fOii\l& 5FAb~WI礐*k#z/ {'>q ]z |2qGµ̾g=/rRC B$a[iR5vLDɎ= uh@ i- .J' DU}S[/~)j MB.QCt}ZWkB;N$2z d7Ҫ閞Ruѵvy3H@s!tLGxq՛Y;@5r248y0|sTiH 8l^H,9E2J=%3 #$q_woF&A`w8aʽzե}n"i6` Tbӳ@ G<&QLjԏTEJ @dTWvi4{`0=gSjh[Л-!]ZU%IYrEaUXL >[؊\tσBxp֧s-3o1K.ۆd^ሁGd F-CUfzYSɛse/m2[WZ"wj\fG'G%J٠I-C%Œ7JnftSwFøw8&N6ڪia7V(/6 ){YICFeZ,4Nb Q+;s&y7&Ĝk$Id ,>J37k?Rc0ޭncXxgb:^8FzOɧl\g kyP)aeF3Ljc4*%8s j=1"5*߁V{V1N) f3׬ʢr;vIv5eeŶnqm%ߏvt?&^;]f ۑ %ӽ,i۩|\'/Nzm{5.bwzmgÉLvw8fK;v/XE#amn+?y_,8wN=IxEe"놣 |Z^nnQ[l244h (H ܦ Q3a\dg17˫x ]'`x0hø-b`Ǩh'W$'0=#뚉w=³<C7?@idg"ّ쯧!LsG~"TΜ!Yr@  }Bb @ B4v,/ͽ+ F=ǹ{.J6&`<{"qFN*h5  u.0i~'` "U'3Xf@0#vyHeoH@HH"@aZCf#;Dz,$j8B@@ Ю\<6y@ylduF:C_9(ϕeH7)K"xb0ZԮ=Xb6_JuCjgo7:ߓ`CuVEs 6nagG][C6?W|i!$@Y 'B& e72W^%"wMwb4:ŖƟX܂Ş m{ c<)*}N& jUN^⣑oZ-;xس=c* y=:6!2/u7[gclq1pw[4_jRH:]^JuyHP`p[%FצtZ^Ͽ4ZHJֻI얪{| g?>jdAb8`, T[8*Gfn0Y/ Afc)pv'=)S$W!PEl X}*:Z7 WoE0@Y*]0] =d$uj)x\<ӽuoX$sKjy|cA|7O{u`Ԫ/Ymw}=}k}\O6b5j\5H~=zpi?zu :З{l!G,;e[{g ~(̄+5h45%, Metn;2 Ku׸:6?=M-aom|u|ӧج~[C_=RԬŏp񧚰W唯GvTnCUnX{Dͯ˔:gv+o]*vo'&!h7.ul,^뿬%E]コoƩ ^~l\C1)T~;o#bԿ58Y\dlcưxtyߴ.jg, wɸ`w{MinR3݉{Tv9]wY7_{φߖ`b a/_.WdpjqO ȟa&;p&LdiuУ+f֏ѩkJbDR!K3p{>-O/T~NSU «0.Ga^*C,WlROq3ѹr7mx>]Y{t܏ |Ϲ+o{n߼+r9-jUIim[>w{7?$ml LTQZ(QTU?Me?]f(WU"Ec4Wq?A>>xOT^Y_aGU5uJŐU\TʑAR;_^7y3ٯ>ݐ}aKFaa9EMhl0Av'  W0K;G`0dp/LC.[eXb4gYP_ơw"0FI!q7i+o!p dDd|IVr[yC#Bfgss ?M,bS8Q:Yc"ʡ$=>;h ܼ0d$!FjXy;L(27gW2gh]nk&IWvSM<ߞԴV§0)_~ [#!$2H[_oxlGXc.Y" gV]~{s eaw>GBh GHRK◔ +NB~;\BCFgPd@#tT?O ]d馛T?M:fYtFޘ7,jV |3Clb z`Wݭv rqG# wK3َ4/'WV-t$zW|%P`㨺}17[n&CɷQ5z:q 璚RhKK5yhNxɿO0 rxE-v|x*Z/rN KgWsV} z=އ13*/35r6,C?ez}*Vӟk9<=Jf_3v~u] _խw}.3~]N7c}]Bpszj2o.NlԖv?m^kO^g;ԿZw:{KdO&.zv?k3q~:_; 'g?f#1m?Q=/*"|HxEBUSְX|Y0a;TZB $ &  l H.h$ .fղu^5E׋6=Uvk5SXSㅑs?߿ 6GOP9۱z/#~Gw䛹ڱDUIBO 9߽_f~gR~R^.ܳEE0 J?BzZBEvh`??-:0Ab߫Vmsϰm]~|hAnYDMSTs[/ ED?'8 T4+HfBI1u}[ja'͞)u8W[9,%c JndJQda̎ եVM#0RB& ~C݁ ts?p}/׏Qȝ~@qHC(̧ }L篜tC~ܣx$rEC]y~ϲgzt mZ E2T5ID 0}q{?ZL|~2:bOʫq߹]SKNtHp]*[?Cn_O᮵@  \b#lX-_U/~Auqwt.<$]sȀjZ率ZKNlTOn0|.#S yL ]|j0益2-)--/Guz^3[7F=%q+Zhi1T۞A?-vsc6 :l3Դq#s- ۳fo^L7md׻Ne69Υpu:?I-l*4.>] 8~T̈j0-lֶܚIVї_;S Or'i.sr.RUQW}qoRiCay,.m{#>䯍r+.[g7{0ٴ}0#iۦU͢}{E|/ٶ\!ŚD /Q:]6e9*mdTvcsx~ g@d}PYڻ 懟s,Ͷѣ~6n`YeY>ノ?sߚqI~s?+f|g94.wwcq-{v]wh,(E  'uGA/8G~d> viyEyss aU.ri/"SEm;ao71]gt\?Gfo-l[ 7Zڸ}7HۆZt}-&[i&t?<'꿖QPU"ͅ*"(}?l} NœO}QIsw?pv~)X8 z%޽TdĽ|8+ݱ*"3VPaR oT ' ! @ F R=_ޟ׽9@N<;~-Z)En_ōَUI;T7ٶϰ4Ca~굇+U5|lՎMC\L4V+Z1^%0Xu ~irƧz_U嫫Ot̓6BFDhf]' qXMףѯt4Ӑ^rn@]y_{fZqI8Og"CF!BO@Wu>a 5]C,N$ @BB儅d$P"HH,~+$'Y!@+$'AГKE.Կf6vKЎGan1]EA*ը~ILCm|T #'"I$l!oVaPvi5&d<lg՜SbHhf 3HZ a L9$!-fR)IGHooeWA8[5 >޷J`~'Qn#2މڐǿk_PjDUGZCT!i]FlW'` 0#"21CAȅzκl|~{;CL(:u:RJh!O%yVWwwbaKaMBZRsӪkto7Q%dJ v:P-TI܅i^0{}Ru^h]"Aϕ\stA_ x$!8A$vP&a[DFFz`n/9(Sys֤1] b˵Tvky>jrب mV^ImnнGO0ykR18xvnNރ#yO˭4}|gT:YkRMNb@ҬQ9 9xXejS5z3 ,ts+-r㼂'k/QΪٳ9!o)ՃRS48arwUR 9\WMzR_+ '/n^h` wIz$Rެ{cVV>|m5d3Vez,ha6Z2& ː6>q!,H<3`6}/e#&&)D:Ѥ(bogcPYׄ@ޞ\^6ރWku9ii\k(7Q¶硪sz9'erR :G5uOy#F}"=̟'/{@B@  (bĄ[B_ x/EKJD`#1 qʂ9P;r?UAث<]1uT0V[K-2/=IyWYR$YP0R,SֲT I k2(SXF _#౴76qE>hL8/T3_[nunh5yfCN ;5T]]q)q1c_Pb?(V S~@tVWkKim̤3֠#!>],? `M9hX К9<}瓞M.j:@x[IbǼSd$ סZWng[;^7|SO%cJUtwA3Q*VӍh_|On r[w6aΔ;_e zlGH@;Q4__ӵy7}f8CGvJB#@( P!aw <# # ڽxAW]) \X3i_3j+]aTQ qh7qf8HG?-˫_ë2CW2P!-"CXlqTy|)!m韂EYXX;l lb?Z WvzX:̔I↮7x@;7ݳʯJfw^"ժ )MƌҪm=߃1Fǥy!T߸1)ri=PE$ o%x8D:Bw&@˯=$'XHBgd Svj⸞|e >3d->k̕X,xu"Fߑo:Zo=H&sB\nbXqڵV(xR{Zy8:/}nƋru/Mt%%7x'ſ.wno?oPt[Mt:I)nAB IYL$"YL x-T㏊wwêӬK_KfU~>x)M}:x׿_O)m/NJ=@kr ]w8f m C#vHozi' A}f;3wK<]M 6#M?iۊso'7i/Jyy,зfڋ{|CE#g.vx/Pa@ $<}*FLlH A a 72roSY>%'u@*;l YE>F;q6@>" ׵$kQo'?V*㵫h!u?p= Msk;GtϰPvʹzX`ε,hA^#R c(i?LSUPKM$[QBRmh̎tۛ;%a'˦AӇH<{gJ9>\roovP?]h$@0uG;TUk. }ve<Y-^/G ~*,gٹ)utP|KHOYܧ'NՉqle}آkE{D0m=؃=kn+Wz%:[)"ҫzC-Г~ ϼ׺]7ѰY-ݿw]gz<ϥ,i$p cB)'ݒe|-^(\U2V۶顗Ec!Y1NjkQ=[T6>x~,!rmH(qڒ:ڽ_W,{ͱ#ïvk;߰ʤ^Ö*d}b\j{GG`ϳ|;lti5Вu[~)PiZ2I>R8>|:={:5ؒOxX'ݽ^e=5<]{{3~EJ;Vֱn||Hb׻z)Yq 2i"TX .xK8FOko CgOuM~cXz0D Cx'FA 8g-DZxN9&Ϣocj2u^uHv[>Wnsyqsx{{c^KZQ4Y=:n1to|WW<7(íeN/XJ`@"͙ M&bIl nz?[=rH;'ȒQC}+Ղ(|?,K[$S~ix†k4М|HODaFYj`:Flu =Y7趓ӓ;g5S=w'+[4rv聑Z~%_hK|=?th7y)tv4`^sYݛŞJ_PP9$hNavDD^Tx+C BO~:{".(ZC?wv:ރw}wv{Y؉}d%䒂F?=10ϼߍ'I} X˚,ԛ"KXjĐL&&=?Xsg[{F0!|OY(ė8$1&ZȌwOm]$;._szly=@;ۮqzj*Φ=F^`-pW%uIo~tV8ڔ^\r=_}^%~t5bZLIڧ,l[ܽ޲@Ƣ[/>*d"LG[Bg*+C^u5FYARFݔ3>ީ]}UO-+<2ZřѮf[+`ݍp:O9֯`!kqv>WW;ztOkr][9v{xoiȓ1cTh ڍ/˞1S2 -gcm|]ޯ][GpE;ti r^;=3}Gr{7:l{10XVk|nӣOD߮ex%:Jf`_U+ImSGݺYpߗ>'z6nAN&j(2]a*(.S_zm I~!$'fH@BE BI , I$ LR@ Y=oUwQ,g̱]I&ջoad|{AJ}}gK'}X#P&THLSm#?2D2}]QG*~aPHg7)Cj8U!+P↓ZafEGFAREY<ǎq"5z]`1/(ܑh35 bmO avOq߁L7@mv>o<%4g;KZalfT6anx+.c$ ="*ptku9PvtY!daDd^V+rm!ʨE\J+Ō AL;U_PI1;$]V/+[Wfd0^d-ݤ9 =^^嗩I5_ #ܛέ41T™WY%Rާ+gL/~4e88zQnI7`C0 +`˺ɺ9l0)/{ww|</ Q]~2gŴw@X)P A{ID`(VR([H Bc rY +$XU*E`Ea Y11Q!Ļym[ڤcg<$?ey"FzF &K"N/c~@ 7RxMwu1If:W˓Pgd20O3^(@d8ŜiN !cF*ݬRm{sG^kd] UZ/*!.QMb |\P8g~^z^%AW/ ~?7>NkLW& -#~}<7Hx1$P`@U},( BJp֗:I HjԦ.ow4mm-L'h_?FHrMK~fW=1@qD*".bIM qA"#\=fڔKE՗D/gJĀHX2}qϠ?#H)TStύ POٜv_wQv% q $*x_c旡Jߊߵ +}<4~rbp3폳-[ cjIsȧeK['.CIcc #h _v* g?f$/ E-z3^Z>/|x4is|[ns҄hfNf"dU?@drchqHp'8>0Z Dz-[5EKr) }5? nߖԒg;2*7Kg;aPĆXuco wAZ>ՅuS|@' .c`1^.~=8鿡E8Tz-E@T,b$$v=cxjuxj^UGRoVbՌ? +oӊxQw;/_N'B`0@ Fc؟'Z?hݢd5 <ݰHH3~D=}RTC /Hh ;f?h]>Ӹ=It@wR*f6ao|v@J?\KYBfN~%~?3P# 1L_!3?@`q(b!6> OLgzc`i¸[d{ Ax Gb!~9 MOO5KC%\\#/n=ou Hsp#(z")fܭ7+!5^+J0T,^'>#A̾,OUc9?M-=V{MMn;Tw|{MEz'}r+$̔8IyxT? #?a4&H#B *),@Z.WUpM;5u:wiOp|Jݾ%ٗ:M{wply_CŻ:H!d$$ZPݤ /ЀIX+I zHK!@Suőa "?$=HpCBH##33@A+I\ iҬ}L); !2 n3y: @\{RBaS@T#Qn=}ޙݸ|^azngeat(JHHSt:qWȽtfFMF) d-" Zf Tƾͺ'O42S`M,ĪBHv9("B $˜o&Vq2}e^jJ˳r~@>L&v*LBpPBε{l; $fȘ?EWbd|@c#DB$39&-N XE<ԤQyuL~oDve.=!EHSׇ8kǓv{@J@),M oz=P͚>BנKh[eD \/ZKl?O5'h!]*a#lՓMC'4-gyw6'mD;vDjJmHziaP@4#7.`+˾a0>@,e4k61[lu혲DBbfHv EU$b dmNt鄯3HQ,͸PHBKDiYi:,j*"@LgAAWLV1?~dv[])7JG)Pn뤞uL]uX{x=ў-̞" n=:c[3SIub &w3J jJl^"=,|S\%YGw>XO-`laDj 1a-&р67u."Zj@he8@LgN!40ᚤo~ C:/gL'3ʣi1 Y>yIE5z25+ecDZУ[%Ign\g٧) e=p9M@z;ݝ1y2A/8Pl}ePd< _aE"7 <瘥<v"_p_<ʖƹk>ϭVہ>ZɞomGmje6u3/D՝@=Mt/Kj{E1[*JUby!Dt%]EFrn q(fXcgy[|q7mt&B _e VJbemG Rw_[ix{̨ d\ t7 kc5&FU}n^Ygg+>y3|duq世4ӎRXye0f$!˓c0lEh}3!|7'^Q[[ˏhB Dl)mC3nᎀo䘓w[\OlaBIt?fߊdDCfvxJW {]X1OH3gddL.r"S& Vݺ L-V,M$$rrQ70_-ObP;2Te8g@P0]LRpq1)YWR;e' 9u_ B\Wn`6j+Y@VOm=uzuzI,ykKKwAR߸x6UN~]Drw IXѧXc^ٯWХ3 [cR"yMJuSw>1(1f1`Ӽmp%(x1dzȠ-T,uٰQYkث"="%oMxDxݝ 6 n 6TsGjԎ2a X&@Ypt'EV\# . +Bp]pm˩K6r@7Pq0玖cMϱVȾ^' k%])IbI ŭ@R%ͩhT>CqAѓ߽t+iyitN^ mgs `z[Oh2F=rcA"%J_%3E]9 8&N^OǞ&B $RYNNNDμB:mH@ZG {K]*g"wA/'L 9`E(`S`3F#QLd54{ܾ_.zee9`}TUA2RWF+rR%W}yHA|~=i9Oq<$ 2Jli}"Y^Kpa< 6 *Ϲ9c8VȘ/wsqjA ~#G ݌Vgo!e![BAB&FVu^J讼)M˨DjڂA0D!+ȝĐA6B~lbP;e*\`=wGH !aXN'0?qOU݃ǰd!!0R 4Dl<$^ܴHy`[$ :7#!+#j'R 0%&P( $!CA.9>Nzs[ڑ0?*rW()j`!ƑՓ) Kwz;&q|Wk$8ݜЌetKTFGSX҂@O46 'HBJM)X"CYH251C8zTzHa3)qP̾_'5Nc;D]b1Ps{MK LJ!r ѧZHqq/\Un]cJ)Ш D+cHDi",!P V}dӴR!:g ߐi 𦳐#(``BnCBpi4Rԯw]s [om'0<"E-zԱL=$2W]Ȩ\lZaY6dخlEΝe O=lDEVbjnsvNC6irꨴfH\]I) $47v#JiXz>Rf{uS/P= d|Y2 ̣, .63nNH~&dkw4=ۧ>:Lw+$a¼a+L 7nWP8L E_z=WzȰ I@Yl Z (K1w&+sb.J}ՂP'&%|8:$?L|C²IU\ %(HIW}".#!H8j}O`VDz\[I.q kئ9q7wUiʳ15\2 b@#%մ3ãLRAֻ^ ia0P̀'rOT!I @>o\:HlhmceuԾ>}/Nmi@ӱ6x7PS[f`ytC#$i =O߲2AO ]lһ_&)c]ys`]]j6w3ӏ4rS)7 hXJo6ɭj={Eo0=Y5P=4W{΄:DZkP'5'x)]sy&iB/ea )f]4UEZ._5̽[sWs&͎95_{6ŷ79-;lΡ'''ǎ33h'%+!=HO: @?5 %22eϷOae{ry\f(DjVRAxɠ 9E˹ѳw(Loݴfs6vw7&/=s,6ӆOʽDQϥM5iթ s >CH(h3T&X +9;lSO5wjAT=? {\hiP>+H޹€b=ߏc<>O;;dpyo$v}я= {N c@D]'S *A$fN$L/Uoȉ\Zqa x cfq&N5/,CAss~^U$LqR iKWԇ4f8GyuzRKiGʉ$#HMJLN݊WKbTXjq!(ROYS>z?VmڄΤ΋&XO|o~wK+wH-SM!bn9\2Y>ׅOm[-տK#xzuGfDoD^>?kROYuk:ɇd 6jr(W'vCH<jrBGML̈\Re7K)/f %H$"(g[GKOUxU?| \a#QR $B ߘQOcM5)KƯ.S(x K퓐eA<ݹ˝JJ)5sJr12Uo6mxM}=;iQYP'jnx =ρmvŵAa$D9U?J늻DÕ4$N_H􌽱ay/J԰w ;z +#jeׇA?տPEY5p1 C@0AҰXV;'qԬC4(9[3u&Ml-,9lf7)#헓ӦI 8 zZGhk6&|o`V j**jYDAJܺ3t2n!E J(6 :3KK8ygnIj7cz)m/'|I.6#\R Y9l>~!lk  sF Mި"H" fp8%1v+j\bm?j^vy2q9;=p9'"ĶVe#@gTkэ]ג^O}߁jsqpBRDV@$C1juD2 Bee5 ma1꼍-BcdR Lrdm@V@[鷇ɌZ\>([MlÉaIV2QwL2lQ>F{ '2?kCPH0xA[qxB3)l^CAE/PA'8e[JO2îCنDI^yB=Y|$ohʄQX0g"$ "3ym{F  aG6 DMXI& > ǵH:W2 !; ޜ R;H KTeS P DSC19w{,&U ``+iIO4|-B3OR9j'XJ|$tGH9/O8yj7˲V5H- j{$+yxJVֈyF 6 H\$!<+T',Y f>Z`#='=񍥘,y _=Do]σnD  Az'p=9hXJB|"y $2I5҃:<^"km+Ǘ%B%k*m s-dYi@Ny]zr 5&%+z NI((F=Wc.Ȁ.J3b#T*a!%a' Ai3̰%P-=NZ 邉Sl"csb8}c#`Y YYZjo5儿2}Ip!GRBbL@C  ^XsOky<-dZljl!|bC3AC5x?ytEPzy|IꢄsњBg;tzi! `}B6¤5[KdD@=NפPUM~.!5!LB214[XRj>VӁ\C~«Œ;Ry<<[)c@ge ZhmR>3͎AHWlo$8}LdUr[KLMFMsܧh֓"BL]~Wµ:-/m;6!Z 7 B3o~y^Os851e8 9hN9AP2|A@aj (܅$*ARH0IbA /Kfdt||^7˸qRnY0]zf6Y`P%@!&! $+ h}Dl@EdA"ZaM3W @wϲ1Hb@>õ<'ff5ʫQӹPXB@R$~z@z#" $$c3-d,bI,a `$ w*LE{^7V>?Cz{TUz:}Bc#M*^{d/q@DKؕ޻y\!|soe%Eyn<:!O^]W7Gj} )a^T#8dBwC:3_Of?|IsFߴ FYp$4oƧ\% hxȏ!!VZe Ui].K̙^/ھ=?eQvt )ng0.l k\vUJ7lqZOjCь6`eɽ )b- z 杺orCXo+ʹ׻xv'Ȭ” 4jcg_B!c1W:{iugJMq 0JLGomn Ok ՌD>=K@kMZ!HMA1 "Z)(KUrɅbzӚr8Jg'%|Ҧ_Aluz#z 0,l`/0ђ~v>^SAvcCgZLO}iV=5 @8$4T!"2@d SL$PEXNj^kHc׮?\ սǞfdf@M Ir§!$1@$'BBH,$00d$$?E!'B ! I$HH@R(,GT Z>Bz.~C=GgW6}ʺ^h0t_|7 }nv үVqeÆ{XޡWWky;<@rKg5Z s-:߰\X6c} [-&aj{,sL\a˜< eNpxUQ?_7ȼ52X/ZS>+ ,װ6gǛk:@~Uؿ [\*[;wϩrFrvfd55ѶI X0951%Gj!n^h]ԀJ?+*H+l7`qP=gntXne}ۃ#CB$̬F>F.ä`vL%$aH {%LrKu>X=UGv{N磴jT8<}rh3Xe!hc, $'9!PZOCOI (BHw $d`NI$|SkTv)z-i}5|EBs*Gʠ `dS'U$|'ВsX!*L?BIEBAd (I!$Y Fu%$<&BSAB8g/Ϙ_  DXUɐ'߮ fwPuBq 颤zŹi<7_f%ҿl*d#}β:'fd@ABXC4wC했0o[Il H%+iI>?Wop[^1BNdN"Ìʋ]M#2UXUm+%Go.O[=@MFCgXm SP&}ʤfxs^ 1bof=L^pFܻ`l'w_1Nڏ%:(B!= ^YY d@?J`HN4;$_ZHC2~T AYDF;Ǽ |ϙ[z7V-4 f!f[ h##,(@ 6Q @ds@ 'a {! t~^ HCI BI 2$ "O)AB`n FK^&f5<l8t]FZY7Zc]fÉ0hqz|ge5nJ-'8l`7Zgٓg5?;.#lZX)FtUCA9)DMq{/ 8]}pQ&β1A=j/#ؽ}ׄ [Ƈ2!r4Cv?Om4q6j#zlo7F6~{l3K 6%n^< /6.i"nwLǜfw&4̖4~Ϲ X_Ҙy㔤fY4miwm]Rn"(rVÚ?V 4&f:n)$ 6LSé|z@IS m|S0}Y~S$dOH@?y̒LYH $@jޒT6[5,ġEaς *XY$$PHC됐H8DۿdHgd $)I$$}7%`D݁&y+&R:*{ 6@&O-XW7pLj6v}a~Ĕ}2_)BҚ_P] r@,m?'Zryei7}4ϪOԁEY&HG,HƠ^Y巬eƪ Çe!y2@_~7_XF|J/Cw9#+2BpQ&-m&HL T=g95EDňL]sfAMThC2*Gm`V&HX"{P#k1%LaֲE0@&GBK'ye@ASKGJK}>.vdI3 [m# !ca4:Yb4M=Rχ-_QcToc!ܟDo2CH:27oD?!vƓ SȔn 7 {pw)WR~#?@E&j( Lx CRΐ,Dtյ09jD{Ő o0 !HBI5 ~y t"0 !?K A@$DRB;jT:jӅ.>5{>xqYc`8&OZ:-ZnSeLZ?jeW oIH,ԫ؏M_ANsQ(|@YPYIF__]Raqkb'pܵi'ʇ jh9sNRR qYB vљ%)޻\3C:\tew0?͠(XN-i&'?W?VlD5Cr>(v}tRz[6w<^Ƞ:J#<9ON4Aj]]pLggS4 :%{~X`14WWt5\QK <̻|i@)0E{.{_Θ~*l?L qnnr<=(■l9)7 \!Iq>xщgUnq|p,$) lYd𷦁P;>Gg, C"6ZŇ|b@Y 2b>Y&$ ` $*ٞϒrl/q϶qRI &R, a$HT?| dDERJ"A:Wqw:8gC&*XSAጇp75=rFP9\!"?GZl\3F3GvϾEnkwc_-uX  v]G~5sFT٩c^ƌ4wrt~Ȟ/% bsop}sÓ84:lw1+0TqRŔilj6j{v2STOZsVP%! LKQ&B u ՒB` 9Kg_ >[60>Gp.BRH Gz?d'l$P dP@"A@:bbE*;>sd3qSܚ.C'O.SL,_T/tX=W/e4'vo8x.QU7 &E| +AcKN:)zgZu=f#ak֓,YtjUJ JWNp}h`vniZ+ON_J1$(y {fQう}Ֆ(U~UGT CiBqP}" ;Ӏ<i&UPL21 $_$!Ղ/iK1Y]&~KHd . iU%|MAsi̬5,nT:X9P1\*UzOY (f[tqsu袉rVȒbHRi6hҍKQ*³hZ_5kġd}GK]8c"/gT%xh,P&RJ)Vc 1UiVLB͝gQGT(;-q˄s=|a\9${g,s}bd9z]9@3':עwZ^Ddm)݅A$ecD<5^e( K,'Ti:ъMX,KR`ʓJ`R=, SvLJ 9O]d| H'6~t!4}Rʮm9?&njxDL/c+t4$}c@;\.J);u#VˤjI>'&IH,XxI nJ4Sf'ⱋxPe H`Y ~ R HEH@2KO=1R?|iQ46zRer߬LV au)K JI#^XLP~R_}-Q=o]B$ Dl!2 8=lǼLU )5ՒJxp?-BFHdv`a=do~PyFDgvHH!H\]~{f~vi^ pc(Ct+!S "2(I=B%|ߴþ{(Te,*Oچ!@"H)H@+4%@ "/])!A Gf(z SǏ -ނbGk6>SN+32!̀u?I_wϱDdwFʔyT-q((+@m3l5ASk9¬kێ2$t@4?$?=@> }B@A &v-sNL+6& *Aa5=Ai[q!|0H )}vW}$*nsJ9jΓ[W2&'d50DܠсtOfdx;/K a>6+싏9.!K$l, ݈ 1zr[q[meky-Nc¼(ɦ# |)-U[U `h'J'ۅH?1vBF*5!'uZN(t8EH#_4kX&#^OUܹn-"O9XDzd ڥ! 9B*Vk?Ok5<4d0LJ zi^+ן}4G1 K n^T_ta{Yߨ¥$@PY$XOdݵOXJH >BTXkXLo33,Q 8!K% %$crA\*lHaLKdW\h !S74,@p DmW&QѢI>҇lүqP3zOq{G" 3}<$%VP9h oa,XI℅IQd>gّ3z桅!-kI! 2~!<~#OJdhVB~U2 XjfU WglrқĢ0de$ٸ'%]yҥzVBd(.PLҜTENkDn&Q_i;UceO@A@a' [!]? 3"BE+2jA͉p9f—Z{_$>w3Ho[v\ٿW6]ΑDV*,`e Bݾ?ś2Nn {->c?`` tv*(6`m"`]˞O;58J? fH` ԅYLͮ>ѐ@RN2Y$N c:ۖE컚vY48g,^1%NS0*5"pT'4ھtQvbJQ_rJ _=֞a7oBci^|oV?. @$=rv/a24 L/Tz( ƃdٗH´G=&]!Z\X@0fϓu^},X,2f3I3@(g'ynm`Y"gj d';Ex>kEğfWk!i!`<HEkT>v@*rXywWTݞJlD$ fQcSŌxH#*Yc3Cej(M(ߟxg]T3IL4 ,%o_)(5T=4Z{pOޡzs~_N6 aUSx~m Γlö$4sV05KvA DLրru 0d@- IYd7$&2iM?/sj~ Cld`r2V|7\OO -B8Mؙ'cHGsJy=?f6KI H]\ޥ>ufa0Sܒ=iDDcf]כ!FuoS>4:8SzI[լu&tK*N]!$VtI ^OAB,$,৷%mϡ=-gQ9υ]JG"R u]K]i|G'V@)S*qo!ݜ6"31ăG7}cOC߹g+xzWCO`$D@rǨY uT,iNҞqY| gc#m 5(N*lC?wߛAca-AH'"c^0F1<-Ŀآ)42ߑDBPnvO1 % 74bld)YjE!d ! a $Ȍ3o{k[O\ʕ EP%rnH~rm"Wfi~Ƣi\qoTV-'XNZ{E<Q6D iЦgGCLթaG! ݍ+îU[y{Mq0By yѭCrz\qh4z?BQ$wu35=, `8(Vg}"؃IF-2TWahyE[,xC+U-3:ʔ . ^QHr:i |ȻL Y BƔ2$ bΓvXت@$hxJrRȳ:=h "JFɋ52%Oٓ<;q7SK- ;fVp7"75HLA4R঍rzg̸,*b7;DŽ{)Xfo:uć-CZjVg\l/Qåw,xzM*I@E!Tu(T+`\-5WKʵs~<[MR̬',~7AW!ӆ i 1[mjFDI[8wOM\۶V`- 0.B X~,Aˮ'Ş8uQ5JkNc-J|:݉T }Qz+xmjX.>F})w۞,54 VF9( $9C*jr_\Oͨج\-Al4jaѬ.4{ezO wQ*ڿn%Fx#q2|vmҳ'_T[JWQ"~ɝx}{;^f wy9BʻJFBN`&ƕv/AҀY1c[~~o6(mo0kmhYG].CYB d*@dIU'v~u:'łȉ=@&* ɳl \J>@N[gpҿm|14t92I7P zݺ{|[Rpg'<_fY/Iy^\϶cݽu:Ա 2(}lB3~ZB/#ކ5nb_Zqq0ͅT~jSpgm|~άgZ׼(ƥ O R.àZr{ڢI= JP!챬H&~>/!cԂ)zߏ\ue:v(4-0Fʫ 3q]^4OJ*[Ԧͭ ÆIz$ V-;z~]ܹW7\aZFЧ(5 A))r9yX &\ougFv5ZŮDChdϘg㛂PlK'uDrۼ9=&c /~ y JJ$CYRS000`f&aQ)B_zwDٲާ`a.ֱJ{4Sf ߍ}%8'ylwBNNGex௪CY/KfT x @v$#-Yq T~Z y+?w~&!z~U'?.;8<ծ14SBRLRY" Ԩaƍe-2ԥɜ/kݾ?OՔ=WGPQQ2Hc J Gdy0F-uFu<S{ .l ?ok%϶Do lfO {w_e?#l·9&*yUi?ކI1)?[eX#Onyv}to6JHOCT,JCδD}qFcWZUr6|\(\hYL_V7I㦐Ѷ@DY$مeq7 m 6.ck<5! IQ /7}xSkkX6w~z^l ۸93$%:FZCL CAD<3H{y;mHq5&0 &%YTJeE,y>W)6m_<=57=4Qs2TE *pd2O~'`E΀@%B@ _(2q0ndɇ`~ٹ}>Q7fb1pzCS?q:^ʋID͆+̕$|/,} j_L@Qd}O413PBb hP^ AlC"IW> ?huL9_' G$*0%T93.^zhqeyƾi hhm,W=|>V5׍2 -w7'\$a'][2}m̈iU^Ur|sQ[1s qð¿biSl Y۹`?]oZ].œzY>a_'q;LjU bċ|~W ;ϋy5V_%yZ_7hχ G.LJfAݍk\3ZHAu8~8~BBEzK?f:@Xg=њRdEҺhLDHIoxy ],$ףA̟8/v,iBʿ`|H~_yƞx~-`w|~3)Ne$Y fA=N쑘I{3"6l&c0GBY1OtaðVicT v/Ix-0L̦OR]b2P?օ$O!QRԯ;zf~f~}4EdGY."Im /ːq~WF2a%[v6 gdbp$=9˂ea_ Rc>cx%jaB\dDyTDrd5Py ddBfAEI@N XP&1qԻ{q9X+c^cY}X a 9Ba>+8_t-H[F؏'a̾_Q*9O2XF&WƌW24MjN]I+A YHgt Ѽ8NI8{Og3ø9gs4Zw?;{oøzep=gc?ೃ*(jni: OOwe#T;H6j"H*h^`E<ԩ$"9X޶2̄26O{qy/ /xx;#c%! lwh^qmB0JG+*id^Ii>pU0n!W!K5wi̚(A%B;O%~/߫wwG+eI}U;J΅)s{r."1?J-omǒ׳xdO9B@ҕ%Oh-*S)Ƒ!k")y4(D)Sj*+C%\}}l!= Pߩ9UYPsRSl;ukjƊ 59)A*$̾Kɷ(J(Mi,%$%:eTKP&,ns**ln? H"dwJ\q}%v{RI]E$4~q;2 f*Ua~g8ȥ̻]sM'S ٶX |zB C ׊ B !&~Vrv&JU$-sս)$,kfK 1VǦ#tv[U\#nUɓ$f)FOHR0`$!)3%vxT]_ (Qh6P4^M(Jŗ~?S}2/@ry?*=zCUL om(K ,6rR@~x$jH{پ'TM|[:z@]^/k79hvT2@y\DETTc~Oqed "8HKm6^>0r}Z NcJ`"_%.ͤ-Z$CPvtޒ7D ރ?Իz$י|ob)`J d*W_#$oLO}ѧ>`ղOcɂDVA@ #3?$O#yVgY"8D>1t- -u@ID>£R}(.1*h*5֙z-l Y;OW(CɆRܴ!?aeRHHʠ;D6L,Ox!Jx?쳫9Q y!̄mʛF""Pa)iCtx +{٘ i;payŘ'<)mVϩO{?޺!jaԞKz_+deq1 k28 k.ǷTSy<1~XDQ+I~P!Da_W0ed祔_v}K}g[kF;=}ZfNpª+e`\l~_-_[A 0SwsL.v\??=xF~e EsQ%"oq?6}ǵaE8Kgp6pEI4"? |]~O?AI;3,_x[a#KV_O?בliJq;]iq `d>ofd. .Ų㦯;Ec d VO\Ht%3  0k8!}X.$-, 6_ϳ}?Iِg08a &S/]TE"]'H;g+'V7wƶ ^s@E=.+|ȺUmב8 ߅'.< ϑ܀=p" "(D >N vCaMfMm8ʎ ɠ2~LC""u AFEz}T;jXd9M|@V3{2NܒO;6#J{OsqYSl[Y^wJ+نk =2 ?_˲4dnr/4-H”fhʔ#)!#пp~xZTS%=/q}t'i΃3B[wO=uf*[LtOؽY>IM+V>PS˰ Q룗^sѓf˞S*q(hly"{Zgi.CVk݆xBofn *vS^ " U_!ic喊EPP?` oCr8OpU-ʦ4@e!Ѡ꒕fŀ~]׶-O S4T,!:E۱B6 /$NjUKhRmjMVk8F`98Y> !5{! f!r޹DujIt2&nusDa|\l~&eo䑏$Yj,mBkm?$;?k|S,Coaԧس\Ʃ;$hlbC7^ wVH䫬a[,ֳ^H"[#VRl\#cj4yYF)lNZ͏ֻTٍ˥sE nfl#a_ }/;TjI]K^ /~eWO*ōVc:"Xפ>)ȣu͟g9yYP[D wbvܱ߻C,1[bsd}mEP0= ["<|Ӊ#0r/OEwWV9nlrcؗ6O..~s}>kn8k1bR*s_.\SA`. aCr vj(|E&x'ct|-i*BȊXhLAE3l(yf\?;A_H2) H\iC8~)E=|bh~Agc)7`<.M%#D`m6 DgC>k>F4W-vl_l$rnbG8K ?AlhC9Y@m\!\-?2Dt!h<+&=w{;?^U[&hv^̤G BdH;m|{"Єs^13Tz^9Z{1\2A"2~!&̎:U- Y?kZ*9HY$Q=ʇr曟2~ԥ@7L 6K~_3UQl- BNJ`k]>ϖe??>&`` D KIy$HS*4cT+tډT6*=-sd8SW"kW/TcMȯc0m0o|zYHFs;ʹ݈kOI:1d<ǑH lS >F׬]ʣ d0_ױ.ϠՋh~9jGٶD-}64Z{2=8*~q?6MzԮh|aDHma=6bTq~Z] sDN8+|=%w[Uo}ڼ[6KC'H""! ٗ86}ai0.a-R|C2{`dy$h\bǯ@ib$pByt{GrS>JqO/#_JGTu{Ү^=6-pfܗt/̽z<^&M'D.R!,K_ C5{K59@yem d*1W՟ϔWieW><]=$It/h; ]5 s~_^.!` GT).DWjdJ[_Ptp `{ "` Nֽ(+fk+dD1{ DB:WWԛ Ma=v5vOS_/O?(t"*yry/zBޣv}.ZUQO+#+U eM{}o= bUשMJIǏĺ%֭$%\~hM 奍ϱnA Q!Ģ8;MfI 6Ó+F kbL \q?fTkrxLb$~$0 5?(7ǍNpr/vx~fTnORrdm-L ԔzZ}5mI[|d03it/6Y]jb#*IzU:Bt]]PZ8;lH0 F_aF!3Ms `ZV`ڟt/#J6l>[FaAnDtHiOMVF 2Ȑ)afR}Kn$ꐼ20k=cwv RAY3E7 &(4>Ƴ'ʋtڜdC.ʯO7|,t`"ִBHi ymqXw6AY\ǿ=@t9HtIHpr2/E[/(i_N3` 1B$}S]5}Wizt4MOoec۞/O NMdޒHO8huЊާl-öcC@@IϟO!^gxlT#_q:; \~hLZnȁ2~d  ,+ގ:.*Q`nR3&E$-U=ғ0̨& Gq&6Ҩ} `9WA! mNHx'gqYު%U@5󔾁]] AV"@ٮ[BݼG8:씄 PZf332ASl߽ƌE}`bB̒LEU4ā1T$XwvX%B:nM+hqɉpoP2LG)HPXCJym~ "]䋄9.m|:m Z%nĶ$XT$ 2y%f+‹0B cV"0JriUo=e }ZNqƾCur5yob|hWyjۿᐂa1| MQRc%iF(Lpe1 P,I.~f7.v"n1@6ӷy9舕q z2q uC8new߄J9vㄭU"l`ٴ̐=E*Ke L!LU]Kp3A6ԏ9Q'F8"D$Hؐ0Ț%J0U"%5 1 F1sSIQK{۽M?ckC!2fo(dH-f% vs~ȷ< R2#X *̛]1f{zDvr}Oi>M'-%L殔ÉbpQ$)FG7}/Do\ 4S w|6& @Q0iI!8u m ("JE }isF~rNL4n6߄~ b@񓎼X`MQi 5x>8fYsUs@ӝɦiFK>bFս ̓:ޫ9Ot8Cjȷ#WyDstRdT$6\/^qW{ed;?z^ϛè oȾ"Ho/V|6a)o?! 9!:u&u_RK`?'>,>8kg =:{1AZN 4( mkbM yGA(~=x ~Hz}?xPk27x$饾Tƒ&( ָrxo/a2Hɖ52`@I"Pze}|MfNHŞ*w: //\޷OrtD(К̤xV⶜Ї5չ]$S&6ގF \CaSL:IruOi?F*%ÂT脕oԛI? G>HJ\&&Q \hJ>ܿ}y?xW ?ݾB$(\dqpvcas(d(0@ "V ? (1S۵{ۗk6Wmwْ}7?ݳZA޽Wf/ v@TRBSV4T1o817ID4+]1G-y+;N03((y:&N)iOW!=lُ*d b>q=[TV? u~꾃tjQ$ywo 1ugxsכ+[z7eE !Q\C .KH!W+g[.I{8^~u8ByNwW34Ӣy)>mL1/Nq CX)PÌҽl"=k^2 ۖbsɿ~9 6 *r.9 xl섋TQ50^_խe ֛b?k\ᴘs޽OC[o>j6RYKzxW[$^yO|{ @`RYRjKNIKcxIa'ïx⯧YtB DD]fݭ:ȡ/&˚^ļ *e4!ץйۦ1E8 !Hw>TuPhԙ,*nbŒ5KY(b1ĸsEPn;;# tܢU-qHc,Ʊ5؂RuK v-OL&ڱc66`wJ/R2XzB@@0}z.<0 sH T,qW9X~V<.& Ȓ.6 ҰBvk2 L:M&@aЎdjoI8(do{zUF xq4` ΢?&(Q>ݠvv\?U)֋"A6qqN/\2B DGo4M{/.|V#b$麍 b سoVa,PEj >zz'+cR YO?ԏY}6>QTJrxCfxKM`@p_]3Gu)z81jΑz|~ۯ7_~kGB2~Uݗr{C*% [}Ѳb Q!$!!Q{@Uwf4)#mr3!sK| 2`[Q/o=i+O7Ƒ/k+A_L^He^hk/_K{>9#qVCs$kNٴ~˕* 4ږyKO珤ImÈEpT%ѝ)Zۋ;G1GnF,(^e}6w~>ǢtMH9 =fMej`v\"~PΣ|!$?3FcL!=*yf9,/۳K=T>/DC3lcs0 XΠI*o]2PQKtL mHL$2[)-:~o']rhS%Aq4Љ Z$RSjf`|/ )&޽V=_M[37 sz\> !HzOJ&|+_k͢]l$);ş5^ZNȅ/\~Ts*}4hW9`t]aE@cl8,ifJ0 O>g6z jy㣴bU5[3lmyUL IG&d@u"& 'MLn+Bwm}'L=Zh|_bn螕V$WR_qA=50z^\:éer) Ћ׭k1 ZHJꠕ6){Aѓa|]6cO=A~?EjN'>DaNs?ץ߽P{fecf:WoMנs^y-ջ࿭Kg͒^z o"Dmׇe2)Mṷwto19ۊn]#DbCvbEK5%To!T-MxƐ=5+M@{66VBܭjƄ>JzSsV805*Tta?< ܄yK,6S\,ibogWlx|set-Pq<]eyX^ͦeG%_;SJl<ՇIJ#z^˼F·+~[/CM\^V98sprFvs]~blHʐYEwcӹ5>p/c69do@`)@aBuر17,Ftӫ:(c װWEI$/}~;޻3jÆȍ[4znEd~Dr%7^ۂ_jԇۆn9]Oy/7۶z 8= rN%,ڍVJ=|j}s"@3z$̈ 7le"1m` I$$h< avWӡ+@bGef4a#|g׿c]E{w~%rlػ'QF`fz΃uXE㠀(&@1~xWU}wLV^l. EnPjOklǎwkP.Gg~^!xzMee:J[ծ~gdrV陰}z1735@ +R~eKd#GҪ | "x~0|;v~C}N'oAyD +uK/n/]Ȝ%j_%PSKvQؓܟKc`e&B6O)9/⛲dռu,[_ٜ)kxۯ,=Mͽm{ft >6a^fw80ND>>|cÃ1I~gxnIהONKuCiffKpC嗿{~c4i,{+3懵-PxjHNI[f͟N~4J>ж.se"N0ϣ`ϋ&N\UQg0m5U)Qk4TXaxn)'Yh s/]fUC< r8x/ٶ)űJBma[yYW3yg2{U+w-J<| oQ-U*?mXģe8-k[_vE9Z{_Si X5#ɉu:r{gYXzɸ_OKbz]ۢCzL[2QmIԂ?kZzNKi}UHgЅ7ѫt4}dM׼5D7{E7m/ ̟&i"8vhfqV6~ -`L_oZ>nعsMJ\~Q.y㣭wmqйsZsVܛ=h1/k%86/dn2GĿ~^0lݭiW2Zӛ-' :r Fѡc>ڝ{4=뎮S eP9{ 0w-';,[o`MGNU(,5ogZj\7,WsF@7dv>mgֳm#K)9uS6;NΉ(`|Z~vNj ,aaXU  ʄ&HR$$JÓjp@xk]ko79uF(rX M;1yuqx>_q6XVL˜].,Y*UaVn멨~JCXȸ/JfFg$3=sp$BQoQ^D,HagaM1a?woB0AARc䏫6#E%$ܯ -޸OL0ïkOsC^I2Qz4sb3Kp _'erpDž$Ooi໼~/:>e-g`fG72<{jӆ#tTi։ʳcyV~> fngNG@A"\Yp>ݚ`xO2gyc?z$%OTHAK)TiQ9p.'Hbf ˱Xײ>Ҳir7 WnÖH^]I~&e jmf??ηR'REޡ% ׮b2Id ;[ E`R0JTVQҐpG )c04&gqi]Ԓj( b b `JD6LqTwOx;eG 2Xhҷk9(LP(4upi kA>8v['jP8v}EPƆV ,'Q( dޫ |ksf7E  :\)6tot*KVFٟNҒ/`*ϣi:QH%DSVw<5#o*>}zyc6uK1͟F*-K׺uuXX !|K/lir%%&{RnBRQQdV"d1 >'yWwУ#vE:Cּɩ1+:>!]&Rv"d3#2_ҠP{1ح幁vGA,ĦH]TnBB&YlI!5]B{ʕy/fBo@O=?5}6Mx! Fݎ}@r'WQ |T$)]% `&t֙Z|ń@5qњsQ'3\\]; xz<{VBUTB<hiATտ߳K@z>go sa1p\zuݍ5cH\z߻εS[Gp>pՐW2ZUSlq4w]>G Mcgc78%rjHȅĖ;t11^GbtUۋXn1R7wE %V>%B6O:]0>@Hٔ!BwwA> ;nz3鵲|Łuc-Xrs.Vp sBڴ$c5s9ͭ'0+br;jK weTنlwscŀd\alqVl:$v}C!aqhV _%SsU1M˽IQ>,&33:?%`2@g,^d̻ ? RD"QqP9WCÈR,DPܞb;(sa1T@:.s-4’̂sl ! d+լgyYuQ /ұ}lDQf d+ H6fםJ oE%dOL5Aen|~S^tLťNop8jL.|Y "4[Bb"|PMu%$+~Pc4f[ruQjg 2YBK*%vLPXQUTɬd:+@o:"zz 6L5h:,5mU%,œ݅EP72,/VOC4>*3\S&Bg*wӼ2{]b=8`Ŗ\UJ|?b?3P xGg97[jF'~} f+që $ ]{Ŋڀ=k3_p&+dF%sI/^FIP 0rf񍨤9Gմ<$& aCRkĈJjv<NY]8Qޠ|V[ '$ ead#2 SԍRӮt Fj py-=ٔ=DY V;U=p߳grmaD+N@CӚd_6y AMyӤ8)X6eRqK9wنa]1r];$,n2Hܤ%w/^dc<@2&MZM.8u `Vn4,/q,vH6V+n 9Sn)K:y s h2O:fx%"~,M6j2*y"?7<^ک| @J6 I\>EZmIf6ܲÉF/s꾄\)A@CBaŘ z~#f\*ܠ58bXQݟ+PtaSZ@P$ b9g2 ֕c)|BTA*]mHժ~gZK rq\c:8o>ܳ:sOYwEZGi]B D%uZ-M$hpD0$Lܺw~ ͞M(Mځ""AG$S~fEsdaPI^!{<8) :Gysx '@0,I.IKyQ)I0;('0GSA,4{ 1u-Wn W[t_@K" ܯEodE{kw-@ ^LjT'2[Y8pv  漑`"wRJ")z&8Db H"0JOI,y]͉ ė1lEDv]ur$׎-d122ʀ G!S[) R@#VIB:5)Sw~Cu wC;1l髆jHԭ[7&nN:c^w|뽞f[[EVuIc};"I;qnS }HNsxCsf6ƍn,j㺰BH"&6˵"jѾ%wpv z+v]/MņeS N_=LT9aDS<>qM'@ bup 47B0#4/7-Ƙŭֺ&2h٬}m3c |uʴ&UTؔW{M˭4 fB!OTQ%|9myYy햻-r_ģ'ebx-ˑ(KYs.PhYe*&).7[Φ(!0p₃WhStRn`H!]=EX $WoO!6RR5dÁ;|Yq $9%Ӽ5"2P@ﭘ,&Ȩ?SIG(;%W Nτoܱ.]OX|Da!.~boHskU>,nc|@&ÚU Rݕ-6Qi.$ sp(at~vPPhfA9jSw;}/;) ůȼ_owF,vح^HTl\0>Sv`I;RQ$NPy~F*)¨aq&v<3+YUL* 1ㄷ{Y&CSą 4}*$f=ߺŹa۴% J?R^tSCiXf645Vw Ky;({ܷ4Z!jƷ zٔ(>Q>'0U;WUL6*ڼpLj*>% \ÓDA٧juEji/HoYvn0-Pʮ:wuC?De3XM:[27 ,wCXo`2>u{fMHt?F౲ <+kI"^I(ϔk^_04O%>'ij{Zu;\K=bDɋoe5\d0M/e6/o̿5 X +n/ff(7TCag7kBHi=$3*`+h56^kݩP^Ϫvzض''xz×Wwe2zo|WuNĩ{=vnelPWU˫-/Gg:Z?2EDs3(YɝqSK̤@#Qf C$@V&sRxƦƖ}Ksm_y|V&jZ` P32~@Aې!RdΡΤ+wP6CXց4Q*a;to|$%YK$M tÊ,\h/iW8uY,T$*OAܬ]/Krw\7,gip ks[MߧYl in93&}4md]RHR2 TOJ2_^ݩUF5 ! nL4Y':۫2հZc>^ۻj w@í"H+:o,yhĬK=IfCd 3.DZ3ށژ3ryV]exchW;&4cvP*3A m_,l,aY{jt XQ?h~9eu& M5ۛ%tB.!YU2;*(y2L)lx ikQv>ȓ XbfR꧚.(q*-ES꽐!!:4disM!d ]Y(LQ,}*~#/uFk<- A`t]x?_.ٓTXE&&B\?rK[֐ O =~d>ӻUf,57>|)<~Yĸ6lyn3a;Jr1 7 @3M$WM Ԭ%]R B@ 0b1\nIHqӽ[-qKJ<~k*^33~ϲu6Bx.]k;8ߧ$ÀzOX|22.?NǏާCCI'E mR =G?-,)~q`MfNkc)asgCQہJ5#RɄy3H&5UK:EPv*UާCa5{>lJ>Lf@W䣝|>I(>ۼ\ _xnI*g/2V<]c'ʥ*/Tk 9|_2ͧ9hA-t`[[o";׻Dg)^*$Ƈ_.½sDm7i:-80kGy򁽻/$}?vttO^EZDL]闃拯H B{L nj!p(+=S fFSϹ4͑s2RCw N-xabaXb:ᶙt:-EnFSyQ_CQBտOizw0xܠNcFnaJɋ!!BsDCF~KNcFNDǫ6@u {,"! e.}S~w p'*IO,7@ی9}m"!HęN.2? 6+ӯyf=3kӨs14Z?rSSj#}Nm=ŧL[TWq^4ݑtpg9'm%Ҕ@i,t64Aֿ{c!Ђ_0C"J@@ h0F~,_ިŰjz:j'ǧz2EkCjcqFat w77wv6^53c'$.r~=rO aˡԩ.wsDM@{Ka[:{ @iEGbHƾopnG>DؐI,5Q+$YzBlk:H|mCp^l22M$IzƻJKbĉK̭ գtߺrN9THX [Qs ZbL(j)C^u{;}&򿿛}`,ܮ=`P=ٚKc-x}5ݍe\,%;OjF=r#쵚{O7#UV S_yuܰʽD%"&՚b`+؇:/;O BPxb$/'h1"SoJ)nV4)/hETaAJo( fxuPgq`o;f{ƙ= 0ވ|Q/զx+!&!KcYEjzcm{ hlt-d 2;U~3x0vZzWҦx^\W D%d2?`6-RCA굋q"h&*.' Zrڅ>::kÙ;?R}R]窚҃RbᲡ1@YPXXϫ{9b{Q- -I3s} .1]3o[eXE l<J-D/O'ޟe|X($p٩ũrvxF=ˏ&E$ @H8RM41C|B%A JU+ ӳUl wpy]J=JħT{ 03)C(dE>4<¨e@Ilₚff\eL{`!LDSP<.g׫tr@HWMҠ/]W|!g?rfn5ff[X"}M"Pq!B6x2=C?#hݛ0=;J"uȴ4? 5vLtTw%s=lmh^'Xad񹥘.'o[탖,r$5$=fWj,{gl?NcvYRbY<އkLH~#BAQx?@7=O# v'G5>}q ʦ&wZaS%=Gm<.LngFaֈ.יm .o=s Sx>}>8۩,zp#rn$ I74@BtܠB/zC5so-qE~x<^//CW~p/<8` Ye3C](߻}O!pnaSVuW: R`,TRbT2"yT / nq=<҉˾YׁYgviA\ec0QPi1!Y-K-BI3!SNJbQ PEm̖ e&x yf&yb ET88qYRxܱT-1Ÿ/Mr*-:K=r?7L@PA9r!݄e!?_hԐW+`_ Hf JGھnƤT+$  uab%1oVDޙ\` `pY$QjB/W7H ̿- )" =8!)uȔ qTsRA/ClVł9%{tZ$ ߨ}R۷JSu"df+[%^dc8F SϰdV' N<8a4k!N_Ck$IDE/ m Ɓ@c/|66R'Dcڄ*LYFjvb8#Ʌ̀z_efCɈja4" I $de@&NJy U;9 k0]zi׻>[-OBH@@0<$*U$(vci0j pu1rL ;z 2`i5^ʊ {TLz~oW~Qk>`9RrtYr&Wi5\z:6pOV5ayY UDr>Р=5@DP9ٯ (1\O>TTRBBtN7V]S&  :t^+ AN@]p͡}IEcIk7y2i.תR`uq - zN|M~y;<d#) @R aXB)di i1(' 3 jQ9V& )6{ӳ]qn> yV;}߉N'Wk$)8DNjD!7cҋᘮ}qzll8% brӰ761x|spjc-ahyxAKIiމ  @ENB+@"k8]Ԛ6y! `XG,P+z؂L.2e+)ej3 ]NFϻmY7D|]y% 2a\hcHF]#z@5,=ha=CkMBgPzW6pHn+)6>借5߁xbߥf0HLJ=;{h ObcUdhI>I <$ Ĕe.AW!,a 8+Vy*zH!3Ă$UcmhH =JX ;6^M5p YeAe:;V^:[mv任ÿDMtD);o]^7 C,E*p҈΍P\oHJz t`hNl-m9yyl.3H:Af$;n ƔPNe8P y @M $wb5Ql/LOB =Mrʈ_WLV(U=PK$K_wy$eRI=E>iapCW#QHyv<6;V",朘wpྔEȡBI"*$QU"(QTF1TT1(U?B UWVK>XYQPQ a (P X/:ެ*]54E!mmoQ"&1NE,?wMLE FD/HeJR2f#3󦻳exײbc\'M,u^OyUѷVo'&A@꽫[JAV-< E3h0RIť(s?u*,*ex,Vj2 ,M@̩ϖDOV6߾ zx\ۆ^jכɣ7q}tU(*0T@Z"`~E|P̩󵯸[`×(B >1L#[]t]3Y TR ! ? Ǔm/$j'JrBrk\9"['"!%H'w|mx1O);[$)bFsD,L%}fdLVuK-ܫuP`]|]卝]b1_nH faQ4Y,Ij,nVZ@Tc  u*CZfd ufBUQBeDU4]x ! Hp(9 M=~G]y+}Z[( tX1F5I!eH6aK`""1mrGS3[U8+L1aL啠יh7e,lc5!WHrTl(qe5B+~JCtLō֒Ё{"4E^ַ‰7cp8RCʂy]O#,Fha7["" m'tnr:nr58j-l( owR ey2$&uUP/E \8NZ6%,-'urs-sQ@.>(RӄBfXp8>-9R\-VWf6GhL:Щe D2:AQhI&0_jsu:cAXsGTU!(LHH]*(uwm֖܏y=qbsp%u[[e+W8|Z0 HP3A19dP\xhjd3+j~@ɐ[soހ=Wu֍X`kD&^pѿqI8MĠ 0(^!/Zk+S2`6|\T:Jj4*NCS̰ЖYl'y_ -A]u§=ӈ̃Ư{$kwðt˞z.)PfV5fj48 _zO~U9IcTqx5EnI?=i&㎩sT+x"ȷ^|RL].<4qĊ^Y"#9YKYܾ&ю,;YOxE}xMa3۸!<=R;BB$E31.`f9PCߜDMA6Tijz_7Yr tTwTap|!L`/&-Ϝ+40b#1jaV9`xaCO@2"%$KK^K7rjsA1ڛiplw.?+pv Fy z * ".@k ` '6uw!2ĘydAq6v 2BJPGĤ "c_tRډ$!pF$ɿrjv\2ղ^^_PnXdD  fDkmA~%wrf,2I\Q6P,{wzӞ6A穤툓{w?U& hœLfaJI!0NyjxnÉfI` 耙f( % I +KOv IXFhCQɇ=ܻ}[ շ46geQE ʨYU Tf b8uƨn29.*+Â2A+ G_0*B"UYk뼧٬ k!6q! DJbɼh 8{ B9dYֈU2}Wb;<7|n~^?W&;Hd'oпe'GQK%e9mjPAj$1$ֆ IdO e &٥q-ߢ6jM>D b Gۨ $C^RrhN<'(j4nJf+4b&k,Y=HJ׌(r:M-z6;ͤ_veVЧ'_FRj\nC4zõ$״C[)A@ ShccOX+|nw^䡫$lqɸ6cu5%RSu0N}{N 𵯮,_5ԞSU V]rGhz[lM?$ú\XhCnTV^[K7$RB! !щ~./A+ bmJSJ OuZ\䷒R-և^Y\KJ> r ;|3av~5e)º?X]ADp7Ѩ(!}dQaZ w4Ho.f; :<+l,nѥH# ".-IVLnzeD FH@ŏQwp=?U!%Ёp q H[5 9+.'<-_( 8 JY*+);>žrRVҞtbpzހ]rSOrz\vysj>Բ/ۛ}ñnleڧkv˂yVCW9laд"mBWՄCTAufW O#fʈ4`y@5-9<o_F7c1%.>ꈒ! TXԦ. 1vʄ7%q1Zf6GqRseV#n`{=ȧ|+n3 `ƚ+LWHѾ[И./{2#k("U/~mmXft@F`*k--ln \7<hëLAHƷ|}eqV"GjwH4|AB's?7$ÜW ˕:xC$A p@r1ri.qlNDK1BBCn&n'fφã2&Aw4Gt3o)XAn^zlr@mD,rch! \4(BZhuӗQT G/"q ҝ7KaeEkr%)*t0,ph+Xr+u֘q3y:JzrO7՞Zʎl!eh 3E"2@ѱBuxn^\iv gQ%xӭ䩨TNČē^B-.~ъg^cW)0 қU걏m5DV#Y(eUvrVՊR*ݹ,\i6<5zL. di1ȩۃғ%.t8FMv|1ϋ`{xŤzc׍ bYq7lQ#H.Tw_* b[6ZqJs!2w&RZ) gdkQbSIVj0\o|}Ypl]a}iPO;20*Ghx: DB^ؗS*n"؋DZ3 &6/­E"ӷ2б4!6Hr,c;|z,{$ыS!tes4\9ŒZ!Y oϥsrقԧl/0޵]pt3+'ځn5ÖEF6nH'8 ]zּ[[/u[zr(a>dYz[_ƚqYeV? w̍d%h0tqDbp i$)sS'sKmz~}ҕ&a糘k 3ą{*HdbdH_C(~o?}GY;=> Cgsq7Gs6S=N"S)!p乊hئ2;r@A[)] ]yrܚ]멪9PonO*U`7`!l|ْǒU_)iohw%IU S:kl+N XI  ul/I:\iE*x\v/jHo3- qfQ4ĪC/I*v<{l9@])- Mp-{;ܣscənyTcͬȳ[MiGEqBkJ<8T,+=W޹\ V Emj6z@$)eidܓ9n6-^q7@-92-iS;-@Wuտ d^'ˑ٬?yUM/upx5V:[<f'WbyUrWGqsL7+-x*Lu >"`!R5̂j*tlJ{cJj,10f 08ɠI:DOw1(,OhqQo\Xs6/'k-Ud $:^pQT x?2BfiMgnp^b7-?Ъe!&a_ݐ;sxzedJH_?򗉻 DEG:<%}^ܽeeϬG>ZتmrlNw:=jwCԸ]N%Lf'{*hYfyܰS?(k`*x;-@ NzgF3Gy6KnqoU X0fF 0dF`:7a t m'R 6)b5Rd$$Vy<1-{122 Q=aBg!oWeܕֿ<.ӱFSg벞Fo K##Jy6JguۨOAz̐"X``2S" QC k$f5queN3^I@2A-}[fTjqd Lp}'lid=S);OwkE}{WI>DB(ޤD\FX3 l,%*jD܂Ld埬I34$7Z68~V 2V_|RMȃ1fbD{Vlpk,lG#f\m0w)lq>,e!KFmrŏ ki6or,kLtaZ91[ 3/M;2~X~nZ}JgjbFk#eIO\uP%i{۩GtX7 ߦk*~ZDZDuzߒ}P`̤UDEOe1vUm˙q-혜C,x3(@ON/a:?elBCG m3M$ ; q, RVkgоC*NX9G>u_[сX~=iF|}RHaMΣ۲0Ji tOпa8j$BeYdkp;Ƅ/, WC9d$83 P%ρ$XYBm$@!+$HEla d,! Ԓ@$2@RcwcSzqxjnKM?ͥb{JmVk8}nGo8{nC.?{~) 7vC[rڼ_G sngX 8@fBH0%B}~,~6u7 1O[AT«Ud ac>'h'kۯN} 06M슰~* AwHz"JDPBNfQSxu!n_9?QÁ?;o7? 녈@22 H](g`+ARa $ J̷.uB?/*aY-1 ~X-8FxI԰vkw. t׻T] /L:SoAĻ@fAx|'U_|ORA͚k=U\nLޢ]-܇&b~j/;=eg1= |+M`\dVM((Pd-њR 7<]b %Υ]OWub$TLW@$Ah-(޿&w~?,cz*/w<[k/w 7,x!5__f5衬 "`"_=qeiD ć '[̉ k֣,E>rM\u4<7 8tv h\A$zފ_@KNY8u~F#xӖM\=uz-9EO/TtAFe<;nU斧DID`_Z[kΝ`BGd'o8|~ JdyݕUPb8;nX&\B?'9H-LcC}2B٠=JmoQfoSN>ro/FkRaF&=b!sYe5G ?Nsj D hϔ^饪#>'JG3WzB" Rl x -[,cVTrckm`]wؙ]"dL\a O~Ej{?yʒk9UҪy7??mt)ոQ7(aЙ[ӴSQ+` f5kLع,V-S.MrG mJ%4#[ue~kkr=Nwd%9ev!x%$4 CO% ٭7tu=[^ i8 5f0`$bC-{ z?S)VϱiU_v%W WT\t0bSP-ӵv2)qY0Iv(FQ(% ֝Zywq\0\f4gm֔B9nmMLM(** "%CvQ(Ø) ʪz$gҠ:ѣ'FӕA@ot5RaBE,ĬI^#pVnƭR)ETl['c}'Rth&WY''͋,鮻μHFu%|T!U& R4my !I 棇t AB>*׵r b@]4D|f٤H) <@@"7.zS{6KDFmٷQk5!L!2`{Sna$p j $[7+ kȶ9ۜB冯]F,CJNNڍ(uh.H>+K&xm,v0rp2!< @I<{Y˷z\|xKwe]k$=πo\H2=b Ar !C ئ&+]38G=x4V)i@ʾjall &}jg9O~{_];>PG& D3/ @.S7$QFD)>FJP6ی'Wc*}\#/u&^s~ѹ'v&W IV rK0 ^l-T hs7TpټHTI@@a$";əzid<^cuw:,uZ4;fT fpm5a%eifLE[d9V=Nc6""R㻒B;aG@6|/ܸ-Bn()b$.GUԕL, SWsO"0N]bV2w #) T,*. a! ~"0Q,\Zi(ς^MҾN!+tXW0d pD\0I aoQ, =],uMZz@RV\6IcT>E * XVsBÖٰ(֧[3#hτN6ݖm“5x.ʡ5ڱp Ud'i!0P/$arځeӶ&f͇k^04f"ld XK $$ vݾK1}_ROy[t4y{M>D\Zq>֭&j ԝ-[^_{M5=ڕjamV$i]0y8q]DGHPZbfm٦{5ʹVastrH^$zg-3q?=dF͇!6%;Ϝ~<R%>I5珎ݥ .(2rϔ1JݖdEv.9Li>Gi I\,>=uB-,kq% (7Uɸߛ sܜ(]J H~" b}컨 q@)p7|c B҄zQql[4 *>܃dnDJIWY+uRǷS߫r]_Vݷ,-S꾟{n) CbJ{ũ[=ng bӈ I^TiM|à~2liFڃ`TKV}͞i,eUaX@ʹ?jWfD\{iv*AON \ᐅ]h G.%:s*c˛>GhT1HJ,I'xY UE",!YJH5d)R,X(@X(ATt )"i9xjrt#/UPTmQϐAY\*:rSujLw2srk_WZBUcŏ絉hL#VemP,+= LQ\^x_~@鷼}3>^". F 5Aڵ50Sf 0 z"tv>VO%q'vTQKlfe(0I& rg2bm3b*c_[(cl֠Qg 1نuxIѢfIP]Sǎ[%-nGe]Tuy+.{;{sS( U`#Jb,Iλ{@WW}dez8qI@|:ve\[Nno΂b5^l7On7iQ6;v6Ʉ4n`(7Z}W7÷-xz4f)H0Dɒ rgaxworxg{ [v.=$xhԫXy`oYo6Mn#R<}4e +ǙS]t8|st}Im]t]k?_.CYdS3 Au̽~tˊJKZs}yzMTf',^SYp$-=egbomO+9X?]RykF!1X"Ӕ" URɷ@/X*" E-+E% n.+72nשv&б P饌n't70Oھ&G"Lgr~VH˹W6*LPS' IZ~-^2'UqI-vX,f:;O?p8\οސr|?s+lpzlr>\ϭ;xo_@3~?6 UQUҺ)BH(*n/Uh݂vC% y/pHgLYB3Nmh*ش_,k jyfVWXRtWP|=},cY_ d|ʊV7޴0/?scQ3۶z؞ Ǝf m")V?.E h˟yVIR 2q{`Bs:~1y987XkH>"RX9FDDHAzlA!20fb5*~q`Ǫ{x!7Uǹaytu!iKLMjĘHPH@&+ɂ g,9A?AwX%c?8}F?+n%8)޹R>Ѥt$3 ڄA*]j̀ x}:VڂS[ݏ|T8Ӡo*bmmY{e7si[;&-Ez3)Ufw@JӇh65J-CIkYn6{'m~_q>\_on'ZoVj߸{5X7ru)VתJhWvf?zJe W{o wgQ,|7ij6,tPunWo?7b!vxzx'w[rKX5CՅ`8I.nrY0%e7(gBpHHV1`W`5?$LQTG^ E'!R/tU1G?$tk \G,uNZ%/,_%@!h T2x_JAsi b^͟A;naRK,M"LCe_9oݙm2vIt9 WX5S|_bɎK|Oh @C©5Jr"7zݶߛ.z3,KI,2|(r>,GN?S8]pҋ^'gMU十@7HjWgϥtwJ7ƈm ޿^/ir_5r}{޷w޾QB'23QDE ,OoZ+Ƶ`-Q"C E R)?h )M$UłRc$BVXqOg<ƒdDkj_P|¨*qGI-k43N_~\D#jbug\/w" LB!L~7ۊ\R s٩Jr#0ڋby׻GW$7EJTA?&GXp«BDC v"ƴ7mq .CaoaNWyȽni@}/cϻr }X>$׊ڀN$&!6- K85b1a&   Ցmn[~gۥ@(&KC5vLZ.75,A{!rHjZuʋ‡9Z<>޸/e;Q*ŭ9WBnxy$Ttw4zHopa7 (=_ }巫is|6]U?Eq]-A)N-ڻ鮑_JJr83N١nڂ`f B#IF &% 5h$̆bm؇NG:*$oMf+G-nnvsmٱwbc7ڥTsK?[+oUZ/8ͮ&wE|0]Unrwӧ[{}'/^H|Y$??ha"^@0vD.^ L*L/i|;̸q ,&(75YƂD3edȗ۝g \ǁտGt u%W \G竽[OoUnw5cg_NqaOyx2ul{Mv3g.A'y!,5\dZ3X l@}ԭ+%[ތ7t[ :@}QC3 r-vQ,- vq%wd& 9?d0qhv~JT˖Ǝ fxsLj'Q7TR%e*[g3,X`X†peps0 חuQHdFL$W.b%s׍nwKZĨWn&%5L,z銌NUDE)+kmaG)+ U Tk6a`hU'ah=EY6/u_[.kLvz.cPvp!&6S?+tm% nY:lѫb}4uxVJj`'"pu74| !x)VJrn^DOBgk2!@rN}"ަO!>1Di=bhW3,ٿt "d}!! `:Ea{~jB] y8!u3%Eݺ0!&%YkΉنFTV6G.С R^n gİxvCF $t]9*[&8\9\_RȶrTY VC̡]h-3z45o!d$M3GY.{$0YpNƤB4OeZka7.bYF)U.3LUݣw`n7Y1ݬ{3M?y_wɮtN2ajIF8n%A,є!1 eO"UqtBDNh$.g2q52.5/Ѭ(ԍgv&#}=EKH\Z d Ǟ*[/GT8|s3! &;Ri>r3Uy1^\[I|jv_4zY.X1>i^;^EWn]wS V+\[}?|kj_iH}r1Z Xečkuo[؛Jb\\>֝m~Jvx"]H"t˨2:.M/7DVwL1ZFeTs].Cq˪*(6֋&5l3vqAZ\h+<-]rOKitV~iPiCJqtWeZ:~UUK7YŤpνlJZ\|= ߒı,{\YV{S?arKvFq]-Uݏ |8_ϧCc=o=k6գ/Y+Ws|&L U,{N?ǧjەU,噶L?ހ[xXǍ˟{]:g<||I=7>v'oAW,&;h֫nsZ;W :YjB-g}v[zc}{| ]r\ QfnZo5rg bXn3urz{UTx;cYWewwwE׿eyۮu r)rN ܼ7Lg{jD:I"c,V4 7?RK8s\9Al1ҋXB8phSM41\Jrf5I Hf'UWCv׹7+7qxu(LVQqX~0p v.]Na4:(L*NWhw8H0[co>kPM11r̖ҥh*Aag5\}A,d?a4ԭ$j K':*)z-_r7>^)-WN~!UtѴZScͿз%V1ɸ]Cr?w̽xxTb+U:W"S},ses1}kvkPmƊfb=? ^OQRaV0j DU_UOX(~"R|&b0R)* " 7DSC\>uY9b:-E"3yD",CK("i JOڡ7M.VG}~5M$,G"< ,w"gIIM/k5گWnx{6[d:Iap$u?zyVml?vAzCݳ2m/QHԫS8ː c%>R&OjVI͂eOkӻI=*.QJȐ4<1-sӭ5"Le`'HSDf8zK%Rϖf_-D n5ҖW h`K+Є%/:ru;ب*t"0_i~_i = ZxjvH \ B"%(6hٴŭ8v .aQoIm u_>L\_nSB/񫐰uRvGonzB2Ah<1A(֭umx\$Ay@"TV3x;fDe9P몋qe|u`X6oc0b>W ;~ LPV* F)m#|lu&K.υĸcOy:$i8#d= -sۯD\Jl+IkSYlFDmD|gu6dD ί2>*+W8 $k@H ѼTVd#nHjMCP ͫ<'s߱[iTOkU yY?ۣ'޷߁)ȷg[?ۯ(dT}ۏN󃴾V.59;s;t:GC$z*`q w5V/*}DW"`SRJ0uuf )QN%tZʂ(H?kk;R$9U5,40:wL2FZRڎVc/U. Ik`"Zf{=;Ӹ5PP$bBG݌wܦ7D8xnz\y^_*zY%#DUTګۧo?scx]e$ ckOd,yyk=cZHJ"y+1+Cٴ`( \=;Wfا0ztg, b[erlpz<&QIz=ȅ0D $$>+l2!V9e֫hEUD> @O8<;IHSB*Yb@B0ǔ2Z40H2)gby#,T@%!$ezfݍu^ˠQW>]LҔRz>g]^ְmiA$TB3*cHC/<:R.L9] Wr(/w"a1ݮ;ΞrB ͈Jy*na{kXeR9no9Z:ثv<1#H0@ {ĉ+Y2f#5"FD %ߋyr޽5)3".q-Eyy}Y}*=/#_1.30 Fi awܽ5=a@K4/֌j>(z*6?ұHOftPM[LkwlᨫΕ;a۹Wލ|ULξ֥enK.әaSQgw<:xjv :ŢyYn {ݯK3OyM'wX}pzu+\L%PUkV_BG˭kEX~MNl]ŹNS[-Atwk˳G&[ ZO) dD LDEU2 9,R,KDc9S6ʏ! ̭|hY4=hFPѿ^SֵlFe5&B*(}i[ݜ˽}{{/+Ց{fŌO\7.eۧ{'{ޞnU;&)wwSgsXkݦP;`65hkֺ^ΝT"/w!=.ԨCD+==޼l>=YBTkR)QHX=5=ҍmٵݮMm iŶu] ;owGؽy͏|ev|l0Jwtoi=8Qsn{)k[$^w8'L\,5Aܯ}ng]|Gg.e:C@)"fhYV@hϳhQO@(}{/2v-`wWѹJP*P_>فl >} P[=<4{yGݾ)݀k= PeCwB/t6@{̥oy-8&f|q]EIG du]:]{7){rQU/}*JjWW=KܦWr㛝Wj4w;[Wsvnî=jsu^RP $z}86& ʜ;ϥ_{{n}j2H-wfO>}wULz/-OT|Z={yuuۯCOn\{Vyx|vqou;]a"ӷt޶;g#UOHXOU>:i@Y::t#DTJm=(4 vݽyo{v4tU(@|V@ ;t={;ҫt0'W^}{f:D4hɓ0L&O1A@#AM42i& 54 LS4i=M=4hѩ5= A&iM zd l(Hzޚ䌞ڀij2yGoPi =M6#Fjz@iF)S$4i4&Q$%='&j~PzMO iMڇi䞚l=LSHI!Кdɦ!bz F&4OCFiyLOM4Bi7<&OD6Sd@&@ 4 0 ` & #SM5<4l#&5<F `4'_pF! kء<{߯ Nzx  7nGBJђOhk,|5@٪']o@ppv2BS>tHU ƬldxNj-ߡI ?9N]MhQbp0H0L2H5u].\P(*B?n@ b5Jm=J i +Xryd6 ׂ^ԛͲ[Q)L_9Ɍ4ݘKw+XTYb'kֈMȕu.TA{kӾMV<  "JFl^s?%?J 4 K"T"'xNzp#FF=;:,vl`}S ڢvfF#3~e=}N'::Y1sQBtArD,;: ,okTl2 ?uֳQ:;LrJ*_ 8|v$%N:S\"dA):j q:\ր.^,# G/W2?Ŧ@=JQȢ40dpUGI~,jp )\Pl$@,tVY[)h!>SDM882TO[7KMRbf*{̈́,fY@vҡ%ӋURw<(SX25 qJ/g>}jʠn$g42k׷h~Ѐ7r~#HC>w@{J:ΉCZ/bNS(|XѾl4չ2ſN.ZM+>By!ߙ%b?րQw,cR˘ %_jKN纉ʨ҈6IS[j$iv3dD hi fO?cۧRD>ڛzAsI bЃ+?+'D%շ_YE[a+! DD$fR3Tfp3d_g]K>F(GIƙzKH_/#J~7Ŝÿ/R,dQDaڳf:x\2}vdJYp 8}8 B0X) (V"ZHZxL[1WSB=ey,V[aTgzDНEZۛÄ+[ψ+HIRpל6gfssV0-iyۢ:SE-^!8 y͂WpsW~~de9]jV nZSYl_}u:2댔| sL`tPK5gpZvNn:+};jؤ7RRn+53cK. ?7cBOOiO]|zinw aVu믮˟f.xz@|Ϳ*ԣX$ 0`lOZCgT2!¥Yd;OlՔ5'JqP.Lt0fww& 0;\xIX H֙/__əG ue}˵a觬a}q09[._W{#%_kǢȡ`4-G3'(r"EI'E:HܐЏr? _^~wsM9R]` ϼD&DfmoVOF}knk:-ZL%$6qlbb)C1~@.kZ3\l:|8'+&#Әؼ*k6!vr@A–ꔤVNc"&RǵP\Af CŮ/DWݼ°ZIɓcˡR eJ)fT_7d?YIStՙ5@*thJZv$ARAvuz3@qQܝkCK$ُ$Ǟxv70;3^M| 1 ʑI?ؘO6u6^f%!P_0^N8w6-e,Wih>巁LUv wؚ:4\˙X(WYwo:K+ t7SrLH:`1]-:J%~лJ}cyFjP ; Pչ@wnOL#z?ϰ$x7E\r ¦R[Iipt3t3{Tb(DO$u/Cfj;rw~nme3LBB?.帣pIڨD B$#+*8ad>.vW HT<\/b[BDž@y!iJP eU%DE8VN;o9tF"# BԠIepRCr ̰̩E!s_=J#j(֩[nޥ;V "jMPGP Y<ʄ*7gr81d*]=Ljay}+K7[3r "Fx@pVNI$)B :t=#Mt k$3+mh鬒Ek9*5 @PomU;Vj"X$|d 3h$I~E(@zi&Ge\^3טVCSܢ wJƅ+c/>\- Əz|j;^׳+~*6s!jrc'>F"b{KGYMz.̀AsތSʜ AR& !ȫm߷ q*J6z(jn?U'^x_X8|=2(Y!ں@AfWܮ@"I0Qkmrvq6Moe+ }Vtǖ:2*ҜXCKmbTa}LY1@XE*y0q g$4iJԓ}sHGQTBlfۣSZ(H,P@ΥIWkA#I9FT)"_{d49QW5\NgQGlTFh-arڿ_;`+] &$\`@Oq>~׊f-&6&d7`&Q4fT `討şiz&n%uENNu4woLT,`J+ n L8@(!#7M Bg%xj5ˉLs?lH\#7֛)`a_ks-!z 1Y!(+!XӤVo"5Ψ 靦D\03i!IѬEP 3Ԭrud2ĚM" G6%mׯc=sO~:ge4IԾaݪ6hfO0XLbzQ[I)@ WVwQW6jSʦOCזW5c1|*T~9}tZv<f::%jO:}aP6=WK+HAhq&aH&Vugsj,ŏz`ozu݂B8uN=zPI(CBE`w9?cWyhF/]qO]4a#,z=eh5#d3VLxqb0NHsL%ht{V̋\G$SrSu<5c1+%ESf[(ӳ ә\d0d`EmU7;G(Npw6Ueq$"J!k1Њ0u2۹V,i0(@`޿T!g:o /ScO+thQQe(<D7~(45U=GW;z+*# ̀Mgx0'z8Ufcyp0V"q>`-pzcЮc|`|Hh8#JkF%7|ϲꐋ^{E>^j5D^g(wrB䅬bl>+m#Aga`KAvK-~9ZOiS_{Gj fh˩b!`oH;o()LԠdd!H܌K3i& Q,^ȅE 8Iw)[q#VK2m ؑ\,^.lǦ})U mLlv: (*#{ MuL}ut_t㎁@?sv s"O`wfFZw`T%"j)8B/.I%37Oy/O;܇ozq(:;I =q<#-ڹonS&B&jY9 l-F}m{Õ}_5L,~;m]YdO_g)%#ue>az"KڔE ƛwBҐq bV""p^ *fbds|1hX30ſDN(AFԓBӌ_.)s "R.Ŗ?*QD}NAvh` 7GI)DY A&):+DR$5ҩ0ˈF5x DSZ,S+zx3s=aX-fAF >%Oc!YT]r$Zا땘Bx;+lv/y{83t{j`D! 7j,Mrڱ>Z5̪Gȩ&ahUWa5%Ƙ?N7%!kIŒr(`wh3mEE8(lLQT+bq,"X(i bjfq陥Q-~Yn\\NdM>Jّ9_j8=X&,wﱤ+ ,Sz^wz7VLl: \oc3 DbګKQ/gmfT*^f_&;+j6'&jf~O>^x)p#hDuh_Zo.$wY};Βb$}ɡU^~ml%Q EUQIX&XtyZ2[$̘ Aӻ@ $w à)s$F@w 7plmc iwfl89lMYr` <:ð#Xbl摧EHGuIDZj 'nmlK`U;νo_RXH)XL^@>%hEo"'R>jt]P#J57DFspIF4IZ^LURɺ9OŞ{'&yOѳӎ2+/P?ǚ]VZ&9x"F," "*2 "#D"$EAlPcȤX |IDsɁA_`M d$t<MnC9haPpY56a3$S55-6㷱RYr=i 6c`[%^1&?U"P6JPTԴ*椐àM>16"k1=F#=c ސamL޼~%h9mm"O`*\ YOޟ5^LY/1GRdJfVz,d ^~^Uͅ+ 3<) 4 !!BI*t_XymޏN9!͖fgWf dPQ\ |לqiׁLU&G/D˞N ѱo^v | h A]4a_V+bPCHjTjfQSY2i$̄PAS9]ɿ'g`,?ߺwlxp͑ aNM$AB 'Re;cȳ0BPzdVŽkUQ Z "5X]jHV$ t-A ;E-Q0>{ [<-_x?{~O:% Q^Ӑ 4 l^no^jBxZלt0$ǬÀAY~ /bԱz3R :ApRFHghۛt ѫ0%dбh78,'jryaA;M ]ٞ4昑:=_y㳊kճ^6Ic(*e HQ[rэA$n2}/U (OV]fO8i g'Kߣ;!QS5q˥e?P# ^IꮫΎ4\fkTuGcm,B3ų˝oO cMʅys2:* ȴoePd4e n$LaNLNZ )4H"GEZ:Yөsq:,($G _V ձaƏ 0L@ f@Bm4liAGE H=W,X"G?KzU"$PUyJ;A+bUt3rX@ A0t3Z"W[]_7,%)!PQe1bH hSf-sZ0&pQUT|.הk uq4sĺZѲ,@'erf]P+9NN_^mJ>]&vybz[8<+q\^%UW*>Nr-7kӳ]P-sEG>-𵁣 7z=?Έ=C^L_T+Dob`^GK{,0:Df3*jvۅ ) <dk0b@Qⰶ7<O98iK_ t<Ʉ[((Z8=+^! _KJ͕;_-ݪqoljqt~~:Ktz ɒ<]Op '{0C%0sǿPPHVR~L]W7կRUɝĚ{Ie9XIO 7@1<5U33<*adQHږD@+崯ȳO6)xnf3ydk>L6 QhŌ[EZS+Ti"EB 3?jӳto'>97mDgQj۝ a޴S |u$)@Fz0e2kef'5Ky lkUGL* neW0z-NeA9fE0OsΝ 2 JK!H#+pMDB(o7S$׫5"fP1=[:=1LLTgPz?-zS;Bݖ%qssX]yڱcȇho֧gd`bI22eEW5YPB-FFͤq3J$fJQ{h5Qkv@d !i=.E[ NENkKTCZEerHX9L7b T5&ܴ "Ѝ4!])gT.Hhَd@@dEdH')[y2D # M ՙB|g.VU:dt]0!l@2l 7(D*#C_?Ah 1uZ֢%kvRIͱ)Hz vK[P=fᮬ!=0 wqۨ_̩F*xQMEh4K.Jə9ACM)حK=0NK, OZDH ';JEKIawsU5hW&;S hŌ!B!J%H*v ZqQ1ѝ>YL> +,*@Pd`1@Yc=L3 P '*X5\P"lI_wS,FȌ 9bBD]@0mL:d&N9&]slwkoC74QMFX[U1jJz2p&@T6 a]EJ R$E )BD7>X.{F11e ?.s8v fϴbf(d]ݻѱ=}E9!> =C 3˘ CCC!%!HݛBQh/ȋa/-”&?g:ϫ˓w-=i芛4*%d*56=CH9p i@|yoX̬XUmY8挔JS v{ ,]F®hv\N][j-#ozGH~TS'={>uR4t*bGAKuVȬ" g1zLL*C,Az UN7cؼH|B-L|=ݞ\u ;Dzy 'G/vaVe.UpQH f@,C ~/n0Lg=HGȯ#Ž RCq03gcձ-mZV+B$(l{bd[bĞ,u }wߟ!|鍊,!БR?{ΠAҾoz:z'>^\c4̜eK"#ruya ΃ 4BqB 13,7z~"/4C8lԨV2cD =xh4Byk0_DgA yRtBe#0 D$Q<_ _6zeK}@ZvsmVbB5(r̿LyVzŇo_nxZm6iZKcPa"ƆYfVAk47N&c&CYlD(A&1Iy6Ѷ03L1ڋX[A]tf&_O@j:4Œ<3χuڝuDx,]P2 0*kkx9 D$)8^fҴ/x^{II10, DiIfF62`J32&ZdPD xnFzPlKDDugS\f)vAāb+ @P#@.#l0s%sޢFc!# CAÛC Ἷ1 $EH;Kpkq6d$IP:Zrq7cr-0!#"}g95A3𨒘L{d%Ѻ\l#1mꊺ9 %@pg0e)Y:pڑS{.;! R|mwl$W2h׶5[Cak)&G-x9i@J&ˆ4[۲D 93It.q"E v H+=rk7N&35SJ!^,@ ɒ%(`hVk+U GKDo45`I[-KAIYl7B"(jgA872TΛDGR]-PvЈP96)Cfo@Cc+ iqQ!o#"I7Vld(+X2b,|z-Su+Æ6ܮ 4K贘̓<xޝ_F:#]\b^eqL8<=?wsN1ƸX kC0nXe ֬3` $spCVTbHZJjMj,V2 ]x[ι N(( 8FwKLi:Zv5ߺz3eP2`k+n_2@V}#Ӧwwz+]pūFT+(AT+"8Ar^ s([W¾wƢNdde"D$r,&ꒃQ/4E(kz|2 EvN{苀^ƒE-)eV.D`DyS[A3|dDNd]#=uMlKt+DAn.ٕTDƫ|j3:FC})\h-Mdoy*n-86pRLl7Ne (1o_d{8ܿz7reW Z[F9u$6eA˔[EDpÓiO 촐?&'7]qeI|UM>9cJCuٖz3sPe?U|rԨKO*3 ,"oLB.LcI{/30ffnt%IO{qp_uеyUvvg^bJfK$O xᇂ ew)t^|,'[zP`_Y^= nO.MXHW@0Ͼ>|X @t~`4P]euo$^Ǧ<ަZ7n^|5dϋH=GsNuPR0aܷo24 9 `2ѩӏ/6~>9r<:WP-oO&>BeQA֒|z`*|il"c"" \rJu45uaJon5JP!d@G5Uf%襍lLjGc:w[t1W&9! 2J>A ^pn04 %<5B bzk_^gw.47@̱50fk)lQX暘nuxz Ab3`Dơ"(Z5UL [ꌢM$:t&L(%|5YAFZ#bbZFeS7fKFRNvt;[YL_ ن&[J' ɋRh"!Z̍\  +M_UCrdPG0]~o>G=yTe"vId՘4ERq>Qē˦P q xr M-䷅=K0eKތ2t'#eX^ߣCSGJ n+jցީMFTZLj mO1h 75]Xn$,,,khJᙖ'9L^'Di)c$Nm?ՔX`F 0(ݷo{1^*@Y6ךʐD0 9f}p/T(mlK HDK|oj׫WE]MjꡦLd^|!tBMIUbvMވX<w%o$Iz&FcS4Ro;et\IJBhliNnGL!/&Nݜv9y;s/O̔ {/]܌oAnMhǑ" 朸Q3=SiGʐšy޴8Ҳs Z`u4^F# hJ4=OIo9̊""_6+ J #B }\@3UH !rWͽ jHKABZ>VXK5<&hRI܁jfw%by=mh9e(zK: pƨū7C1M2%bkMm`y1 V:[9b6bi m FxMA싖f x׷9KB^qg/P$<ɖ 0]DnM@B$&2rYQ*S3()N xd,y&TLJB}D4dk-@5Vof RnMfM&SoE7s Iem!*rN[YK Dq 7.W, hPX t&M[J\!R%je( A @!")IP @(BĬu!"A3\n 'JadH?t8EF8N"(/i4QDЙhaLZ0R.XY2]TZ=4&2@ #W ^Έab%&&kg8%!2ɔgc r&T#̸tCh#&0b.$?d> U~D@KR0ĀȈ1#XD w^Y6hF; 24% txAf2`QFЅm"Ot կ _i0hảZҧ+0A!5kq~"-eI>\YbZטrB!Ut`2* UA?n&N? xcWuD.@.4F f cį' 7;aJ^7*!$;/'2a Ў)\TFHsĠCRjqMޛ#N^ MCe 9) ikZ۹2:kݘ6iOoƈM!L6HV4Gfs}s-^Y:*Mw4 Z54 fbCK0S.?C??oZWMrU1@'9CtWbZFKtXK}T\P5I%vHցUuxJJ%ই%߸>-l!jBOҼ "Z7 9}u&/E%t rḐ6BҐ;N+tiEmS2Q^er^ЫLZ-}TM5 +CڶOGcT06;6hGN=76!x<5L~bM07OOwqyD[S=ֺhZa!PFJ'?~ϱw/t` o0[7n'LJ 03LP|3E DvhߝՋBu+""**"ez<UD}H|?}}߁]y1KbЀ5%`AjMÓl^Z?;&%:(9uo:%' US|+6:^%aA?\3,Q|EbV7+Ų³,1)̔+2ٯ웧;i@@KX=O PF[IID[+!|ê~_!&쀤5* Y%22{8ܟ__!7 j0qț}wn=\9MD{?\HK?RAZʰHLlZvռs}UeB`$룠iA(/d>ƄH1u2įnWmLJ"݃ߌ|JBM9+c,8[2e*ZaRA.R 󕛸_S6*ғؚW?>/?'Xi_=20=LQfWӁKSpzţ3g1Se{-_ ._8:h\z:,seI4*׊+.~Dơ/lo½wX.Z[]f!:w?ShuG ܂ X9SgYЖI_XŋТP s3D-]mj1E)d% 68ѓj7sgyEU֭DpzSWI$z %D/kl6Pl\1LzeetnZ{ˡoCGkeС^X.؂.+71(ۭ\}\SEyvYl ى^걋"PhryH[|R~"K:;p;2uwONk e개űg Ԓz *+?!(TEJͺP_ TǎspaLmnk wTU'a0BmS*aeZv^AiSzCRd1G'\9cbXk',qwAnȈ2v{?*3?>MSj_u{?O˒$Tj,@MR)kZ 6J$'gUT{^\|z"cwB0\y^Q l$>9Jlj5ڟoo_^ewt*B\iRVw2žuCqMJ35 ,8I,v,*|Z :-Zƺ )+7lz_ݿ>*7*NE59!H:8>j.&W(@I '/'O\>l2ҷRXa5U;d*TVbnDm]64<ު1 j`x(C՚7D4;IOXT_r9Sq-~ED^?:7eam~lp"uh*I ?Њ/:fE]W?xcaͻ>o4PXz9hE> >\VJq" t/++oYH^ŠٕL| N|:;VMZs3NUԇF߫{W!_vwP+EtD*O'K痧&K[VCES(kE1g*"&H"b+tއ]KeT٣|f} [EpjhC @"5~g+<BNB_Gl4fʥ kt"<K^ZRp*#2|L6MJJ %3ݹGKi-* JZY vث >d~V'JspT)WpZTPNO?йwgs*r 8!X188` yQl{zLRcZP h*.{3N=/Z.H֞$^|3{Tq+T/(]g8 /e7?eLG߹?~|?/i!yΉ9AJ&~!5Y&4 "̼q&{n˻V{V: -T;R`nnRhIrs%p ́e xpT#(A"&@`p<1Nyxeٱ|M0%*VOX<'tC~ӵT(`/1bĊ2}SFIQMz[gb$j{Ϩ|hYE%^.F> =cu0[ baHD:& >6nj+3h3hj~װ#ZIzk[m~o.'FQ'mFM'ds}S6RzD\ [,3JB7UaD,,Wcff)nr^?cm|yI23nVa SubXfj%iYLo0&e$ɥm/LzTYK`?~O%%(=}Ղ4.""" $LT[*7qOod ]W/b͓F Q#4x'AU @DbOR@󃢜0:?;E\DvLajىoFy ġҩ g#ڡaq( VU F: c?%ۛ&i!V="{^}CSJzepA܊8e5zqk[9h*5oX -NRΆ~aVC.?بXثm4NТAGjCB3C iHM{֙B،_Pvi[`qQvZtd^H 9MD0jA$BHd۾HwT̚g=S6|Z c`lJI M!x}40Ao(ʝX>}uVcS+DRfFKPhH2Vi'zѵ M&̶œ#ExWMn5_Kƻ6A H}lV8k~1=nw 1zm<)L!:<hh20RѵZլ)ip5JF06i-F_H0LD'1Do.Ԉ60[iȿ~#$%0#1,0̽Tk8Q!%"óԶ!:,h ­_.tSF:" t|F\_QJ5'z*&++{JAl2PE@A%cFs|@HÈ'4 P:M|SO~ |p>7{Qj/LD/OaK{WF/CZtpSq29Gт>e`B"pu_Nw(NCo3 Ԙ1a9L}'<7"L]kf@BsU6r0J~R]N`#2-ץ@$-#Ԑ ;S7JМZÂ,bR1r֯%vr(~#.c6ё] 5hTaW>?&4 zL cS V;3JILNW'6ZyN۬T"d*C2b U9E'j^wͬ6};04}=R2721Rz9ywy#-A-=Gځ_Mm4"hBO n!+>~oL8j_&$Wzs G$#@e/@ K "΋Ir^άkvQ=;g ?}H@T.n:Ϊb==?S)DAS4{^@MՕ%P^0yr"#Bh NKYNQHE;)X,.AQƺZRNn˺'lMwI})QJ%- Rh>P=u~?~%LCeD4ͦG# P_C[EJI+!ɸоTܵ͗ŗkkf2t j^ޭQ b3Iغ_gVw1QxLhn$ϻ;W{Zpǂi/ P,HH:ͩ1MKv2-$qF tlb3m2@)tT˩&,꺤C!BTܔrQe)9FoH2{߻N;Z:OM۔؄PP0~Q2sA+w 0:nZQd[eW@3#/D<]c0{(z{Et.>^rwLO3l!Yv<ե#v!7 -/l&jo/sL˶O ( #*N}x+Q1&a;Ϫ9U*0_kВXޕLsJSz BFgxWQ[ob;GJzl0pb8l7wou׉-$UyTsEl'vltz{5bG_x=ϝM%5=qa 9úKe. WZ`$[WQRWOAIYOZPߤ:LP]q}eԃCU=hnfZNh_|y;wW˅M존9~}Px#V.G>uY{2'7TWWozvf؍{i^mRO60Lea⨝U&M>ղ!ajO-ۗѝl= HM۝eStT>|{VGr=A[[.Qkj|CS"ʙ|IG܍AںYFmlnE+q7,7a*Z/)aU8>BZ42YpI{A`6h% 1(=VHO [N&uw9gf>ު+3g ڃz'Ua*Z:6ISt}yVՄ6gy+2?_*cϱB~DfB34aZmxK9} K>d1T,l;+#aM^3`I}o4zx'Kްt{06V%p$@OT˺:pO.cfн.8_Ⱥ wƩ DZ>sl.)~{;b)>*uEPWb#ΰWYm,*G'šjÍ!ySUONPD޻nE~Dȼd(v4 -,Iz3L.}XH;(26E,b!L>)CbIsGZϪK7 X78KkQ^^+S77ɯҕ<6dxTf֟;'[|='*'ܪ̳QmW}N]A@Z4g=T) s`9iъ4@:Y mα2g8}祖?K0/m6>r3Nnn+f/NfO7K&e 郳>:-*'1ٴGw#'YooW &*B q'khE T/Hq12jU)9:!Ej)&gQ;i|ț̩3imX{Jq[NLLC:bZXJȠygvwv39Ya U~>6_^\i%1&}?*l`I@3R"@+}b ;5ɀ*L4 nD#q0z_hê=aO gzՐ046d{<cDAKũ$#Ƌ RlS 0o2T1q m̼P:15Rt)>SLFWft*"1/\ ch}Ds,@=lF*)0Qb ś 3dՈD!tnzYAb>bݏ;kb I NiCSC`lpa gv(3WeW;1ט%^ʄ} bPs錋+eHDtPNӏy['QN A3sL*GnݠwNӯUU|]Jڔڥɿf4[K*+k^qE+麶߯Y KLqHp3hS1r([ɲNmV0 DMʁ=hAw}Pr~ RDmpu] '$>G$C&YD92CI aӉiYxؠ`$]|wocp@BP 6. !Ң"BMn9F*,²qz=飦KN9EwlTC"UtɊ]c V:SF`ҒڤD:?fF M6` wF y[ Fv`1q@Q H 2GRabV\I͐"6?5W$lEWFo"i?Ծ'tqie5=m|DMDj̍gP` urP"4!d.7o0=N͂cM!8bs-H~ Rbٝ4 `sq-3[uT4*CwNOgs ;{̖B  w=a`)"09Uo$s$zS<{a㢭0FߏQ?/n0a*1RCҵ =hPg,Hǿzk _efx:Bۻ^"/VɒTiTMo_v}-|1wPa `,exńV+ٽXk4 {eGȚ ߪ@.۷|#~v녾UҌTo,eVәDU<(nJY$1p2G;(6_ cz?h1aG\}H?|ljY>%H1U2D7Ѿ?"o}|c-o'q6 Ubݒi <2Mj\ >qIv@œH Yz­L$%.!xG Z$L:ݹ@r@]AV tS:?LXlW<>erS"J^U=!(vn.2Ib#M؀NkJ/>_C*J $_^Ɨճѹ?CO?LV[XJ@Ȑ!c -f-eq6ZQ8 H),O4*^x# HTVR̶abBDG2y[߂y(*q~eYDv+pl-'CF{3‰/,+ρa`#B RsjŊ g[p KsVOChe# M%epDU-5iBa5ɏFw_9qv`V$7b؁#+@W4c#=8sr^&(p *"+y ;Z1 pL|EH K Jk3sǦ= A8H RkC&H34yC M%@Y bH­*M 8H btB_nzGVT:Qc3Y`S5.- !J힊ܶVF,@Yr+6QtζEx8z] E ̐Ċ,^B,%!HIe`<{κFᔜGHT؆\FPZmQ axa|Њ0)p3H@XD,qHr#k,S7u4-EZoe@|؅F׭cm+v #l"E4o [`A8JCJOHjU;x A*F5$"3t4%&0B sr. 1yLEr3g%!ht+3g5Iqu X9֦L4XExHmTHͪPum$%fYe|8$~-d}ڌrj/f`ۯZ&+JXl4AgP*@˲MtwpiF51Wsk~fZ^L\@57:{UT#Si싮ŪvE9G^(iێMUJv5ݰVq bӶ(Q \f>h}CdfEpuT=.24N1s}UЋQS>>Blx?C$:Ysrod*Ĝ7|xhccДTREۦ) *N(Hb"uY݊*/&``` AVXLUVْ%FpLo$Xj轍\Ǹ ZLE@c6UbHȳ#K$j(wFk݌ f^2PZWOz@)NY{jfDuU暎00ŦKqo/%{>¹a{: l趘QJM@NHFU"=1b) 7l'ֹ&EEum'ucmԾwʲ'ܹ+USBC1e+! C By5"%+hädH#&Nx:>'Sr"Cѻ'FʩZE:Q7Yi7ⴑ6g,/Sv*>nդdqbaBhCaH*" E$XC>HF -Hz;ݜY0MPluC7&fɢ mRͼf.P8 .VPnI,G0 žz>S:=޺`C06K%}2ͨ-9H.'sUP5 栤,1QR/q{ƠeadrQx ʷp 36^x3s"訰' R, N{}/ g-hA" 6J1z*4z{Ž%d&zfJ+Ub 0m S~}sYEUҾE*_{W,&+I^eJ̰$EΖ(5푌mv0l묷)ũjRIܼVbUHGaF By=TjJY=4õ^)¦ctr\dɪmoMv~)W? S*>ww`q#$vV,QZH_]ۅ .N~_ww[e.#nPvY0o@@6 . =s(ˁRSLHi Õa^ ?*dXsGubSS=  :Od92qQ], BQW#  *@,#i#4 @7bfxiKEfceqSMI*E]]mcqlbA&$Bk!:RfD2–2cw] <;*$1Đ̀5z۪nwoePͿcl47%~gkJOUӋ>9N'CH!QdZV*)^<`CYM!^YA@cŔEZ+͊093]q6 {FHKۍ]Kzː6a ,cT!FE:s”OmW'mMS[Lաۥ}n&dI GI7qm!BAfe0e'9P8f+9 Qa23t`g@ԙګך Q0%k:?)pe ~7OsD3aгFB;Ʋ./iVocZq:$ & ͱ_MVoe0=ꛁK-H!Bs}ͱ4_;jey7 n W[v|yГr)ِ"N\ES~O:k,lixHWrhT|Ձt`D[n_iiBq[qsYoz*+}إEšof$tOdz3Ϭw5{t1!T'̍`7LK7Ueu nMJc G@ aѕ E B@w*!aYDV#2QfYa TfS) %QL=|2dqv {9aݺ24IIRCT6*f=̡QTBf#$@rWy\zv~9lG(;<W^"-]LQ#N)[P,f{:TҐB 1 FJxDЪb5զ.C1. EBHɵ4*MJVQ ӝYJ/ϣ M:?:66/ ٦F+\W{oCٵ\xg;k8$EѤP)_Ɠ j^ iz}0Y):ssO\M8W#f#cz!Vxxh\0 y~S[րƆʢRT[554H.h @cJ',=u&V 0A1 *l IEt­bb]$`6U0&b  ` 7U%e-R5-a%6q݆NDM&:ߧLr"Òj0`2V( I㥐]_j 8aRVeJ Ӎ4CCa2(8@@1J-2xfa "v:q=ӱhYn$C*.gqu=P*| TI-1m-bG5HCBcCZӦɞc2q@@!̝IܭHufkrdX7)B%I$~4Ԫғ! ɀ`wwxrdUƿxR'F`$ϔNkh749`O\P&Tu쮀<7Y14lf>tOaՌhZ5%r` u؊ qr`$-^çV-Th֍➇K( am%e7 P7 @`RWx rB Ϲki vTAyŮx@e(b3 $`̑soYAˏP4`rRȈ+,JHSO&QHb"Mx55=/N)m:>O/f0k/zsy=R,S;S<*#=ǮX̖p0? <'i_dYÝb%DkԽ*/pO#, $~A9 {$-kWJN;8I:.N#dͪ }7*GiI$I0c'{(RFx?CO\z= QLk:P) y51m}cFDl6mZ:@ˡn-a7}fǫ $$ɸ &?{d`Y *<) .ca GT5F6yvD f7$uHJ:1pV!Qff~ZhT Iu^CG.= $]质fQo]uyͲ3)ej;*2\ofɲ  qWQlj2LTPPQ$EUb1b*B5p8}n(EBwCDy(` B[NVQ쵩 <6b|F4pe[(;-9Use[^5AK9I flg|Z']>r]+̠nƊ'ZC.JJJrVǞɉsQB/aa &,B9n?;$m܁q57by-+m ? >sI(v!A!I2$_n6ix8W!u-& զ'`H뀕{"r\ԼݫQ@H|[5R$aYFr3$ D ϋyb7qrlO@D ̌M ָYD :=_ ; 磈b7Iu1!(R04I xDg-jZj4Nt FDJԝňjA9ԁp#05~3]ۧ{H@Ր"#Yv+8_ht9CҸ}{  očD HG쮴-Ϣp&fG?59HX8(eQRڑ+(Gxt`ĥC[V9sz6E??{+J{ZR"{o]E@Jw'BA]હWGʖ!E"-Fc>˄9$Zӕ:ǎNq?L>+=4/Ch V.m-KD; =x+/4 ɍxchɍJQs" @&Z}jZuo#δG@ܬ!A?(܀P'Po֡yF`Aw|Lbd% Ҫ?:D_rP[ikՖd{1*` 1IP۾7vO%@PYq6%[`2/)R{L 8 $$O]I!X 8)E&-,WzR/>mD Z'æm$`U-5Dxy9rpôw#Νgݬږ #" 5@ 7γs[{l:em4:L2ߍ\gEŭ4L$*͍ B N.^^ P7wM6ڼ}}EQ'-9Y_\Sʦ B: d#̑39iBe/j|{:1[F~ۉum74!Ty xipLdek+nOUC?dұu_DP rRҐC#-ݒ&g}}oP5m={M+5]v ] 0 BX 1&fe4ݟ41A^=\#DHԲ Jl/ *RĖtR| ×7#_sUFԀN3s)H26UNiNhvc[, 0KkZQO 1ݪgkc;S4"VD4jSq&`+z/L"@`-.KHKY@{@ ^!IZ4%Hl14s 60#EFtRH&9!+ڢWV쟧\Zc)e%Aō) 8tk-4`#,YNCr {|?^A4셙~(EIgC iS#0q4P5hd26]!@LLjUN݅86crBm]d}ljynEtKܴ2/$um/'}BCnXya@>4z}E;|]OnfL^Laz̅=rC0'TBEG4N!&lT,U|?N>Pltĸ NG%Ʋ0`BST̨$s2I)[]R!;T' !Ԑ^cWy#r> _< bJmRmq5@KZDM@ƑJorY1Hի~vq]'e!RG#-Lߥa!@!2\ht^j7N4|9W=Z449 V@N7<M9QI9R+S$ÆEP04ŐRCFRBR[EH¤6}Y"=ZJk zt&F;{S+^}cVnBvlى R<Ns* 96`hZ7nޒHZz`dcJALa"an˻ IR$+ lGHTA (pPRr@ɦQ4u!Pł+' ᆕa9trߐ1$m^h-YQB)m?iBHF(\bv/筣b׵Xp&DU t`s2nM;Tp=O`P\n]T>5DR7OQ)w5JK9wKDL0Cp<o+NfVCJ0scd@!_hAyN+IǏ+~`#i܇4^2Rf1X҇Ŀ!mPctYUs d3jJ0 a ْ!ڀn*D @Sy6T m]CCS"Ii%$y$L1ڶjI֑(5lL76QG'f>r[*͟&DIAxLR ~<4G6ʪνud3plRoE{fgd4&%4Z/gaf% Vu,W-CThV Fp)FS l`1{C!Nyנ9nZ(ޠ:L],\#GEucy&AiA9\4cZ"®. 7'ֹ&̬En6 b o fqK4ޙmvːlɂfD"5A ;Z~gZqXlĥum-f*qZ3=-`;x)_TmCH T7#c!Z-l~_R'D+HFB]Qz]y$ BIHBD[G1>b8^1Y1=t}xs ܍X1n Kǭ<|,)DQqe-#Q®鲫<ZHH69L_sT ٙ9-tH3[L Yk@]#mdYϯ~|F@dNۇrgPA +ݙM݂NYge4YFY)*Ohi^ݣnKLjxnF[` \̭+<@X)u׿XU*G mVqDXAr{"Zt@bmK&~NeBa F87Z7QYfװ ;R`oR!ˈVi""$ۅz3h`bNvTRI%ENs1^nޝ}nbl5*kmQf^+B151y:_;. RR%!jA1"b/6y8#3v,VéGH\ !1QVܮ(aݲi`]P5zu^h3wJr tMa)q3=.TYLS6h{>P7~euYw[.4 گi3P |;JKYB!4Y1F2'Cyrյ<׹;d; voۮ9)V}s2z]X-QdcD|}$}Fd37{N)mEv[Ve|PK;C82Fi]H} g4D1**&\2 3(́`@rIKor0age/LW \a=bnԏ3D=b)d4QY ͽ1e`S;YZ6.G'vr$lDKtBи& n&,'H|=Q`L=P;RI#W fF"d줗R+oLDwfa52]^T)ؘwkхM. gG97n/hJ{)ymIq >F {UcNFǞJ&*)yJ`X\2L$.L#7wp|5YrE)*p.1ki/|kx(>?HK1-WXT^}΅ ^MDz BY0ENf~:'!&6}yڊ4BRA*nרyݪd>(` 8 $ȒI3MkZRW aiqŒA%mA2 &=~( Ġ$j-]v[gث  @۷-dGwxH@Ka1c)[LJ E x&&'ǭӌ ӾjP):o% !E1{SOp"$OV\;Ka+kړ+53,I$urZˉS:!+YZKH_'\]+h'i~ ;qCJa# BE%ŨB!$Y ZN>d\%lIa+7U,&$+|{B·-R=%15Nf%"sX&2q4W''li#ziHu`bUBsA S~E%垙$V%,{o69< x֓I8~/.%̈́wt0 16* (BcJgB\e+8GjqWliZ\pk9Sy MI05Q(zMgjKQf0h hшAn Cߍ\ !8`` Ӵ҉sKl޽r\HB72BEs4k Vc홂ʚI9\lPHV3DW-Bu$U*z) g?vnu>%>^@o^npARvRL3b4jG~HXsÚT@?~c=]4u$hdbdlw:HҐ O˚bLyK;t" Xa7qk]:mvŽF$s˄,otdxYv㻦پ1(D4Qe'ytdlIT) Z炅ąOkl׹3IBa2&B!aֶRapl0$*l`S\ AʈD`YT-43zZi&kw~~@fd# H饎z^Sf 262f*] (~[]4|` Vl[g|"Oa~\8N Tn`2,(wF(qo( 91'E@X ev QBB'pةk & VڪK3[ z(}ypo _R8_0.+<~.71$g)`e)50lS၉ZSr!YX 3u#jC+ryVLFBؙFcxbJ\ZvXX+]oJbcVva\RCg%zn}Ĕ#Lm.GM6}uM U VJNOtT:rSEpWddgkU5Ms^N iARE YhPD X]IbE *0GΘQlp 0$,~xtCaY0,/϶dqÁܐ×ȖBwU#4-ũi>gD3 4C_v5;#<)S)"@jDl=y9GsnEU'LQלsI0SuAj@#RcX D U^G =`-rKXY} EfFgjє߼Vq^:Mr]ž;iy*dܸnegҗvux&E 4FUEP*b tA({v5$^X$Ok̉N-U0"[2]DpT  \"ig٨!A6ybms im6bͮ&ҲtdX2,]ުpn6x0"@PB$qa21XX!^h&N*#Eṷ&d3PD×jrdl_W4U -rFeK zn!7Q7  /Kz~q˜t #[fU ^am9'GH H?ZP., t0Qsd)/[>0 ;ۙ1ǞnnV߱ ha"QLmRQd.-1{b=Jbku\W0zE>@!P:M[B^wñv0uńBU3 # {={¤TQ%s .{4Cw̖JfAr J&'s)XsUKmq#V2$\0 O(W?í:Nl12M!nbD4}RWUBrX` $!iSPaq2L˩X:Y^ZOnقK!AdI&(gc፯FQ4EZ#ĚZ;}f$-2Q&]CI $J@hvf'ɬb|VmJH.2{ ҡ1 ŗ#%Y(@{yLk]<+{NyF_k"f -}k5-jn둪>nŋ{V_1L" s)r(4ԞA|¸Ds efi# {{T)G_`s0{1)}W ȚmjuN!j D0CTۛNmA4jB^@ T4I *"Bg;I*]$WMľzIp.$`P!zp'@|@# 6!)ӄb3Cca)(I)QO6hse^ԣՅj|O {emO&〰۔`PQ?v!QP]sV{KjnBA5;>ߔ8h av_ 6HD D0dٝە*pY{͚ KMED3ú#Kc[KˬcIhPT25yR I\fI`Kq1.3s$ BXKxvH ŎD6dOCaɋY [wpF0AXP"LɌ+Zżn(U΀U -VzFqyRcdz&uuFvV$MP{<G 7C ms[:<mg(XwF#qXˉod8@' Nt43 -'YgY\:3j!iJSlJZϦy7;]o9|宥H OXrfa'b/o*T:G:,dY#i1fRhBB%S y`&,4k`kmCS7} NlxcJH$Jb{w7',>%3xآN(coUk,(~j,Je=k!RnW }=-ݯX1e,u,ͰSfbT{YH4bHF@(GHS+Μ9"r ص]!qajc2@qc&שׁ-50J%n@І7㰈1ΠYC!nXȇo}5sK} #0n1"V|oV43gP Dgw}ddPLDYUw-TZ1aЧސ{?!B5_*_lG$`yFTâ C=lD G=u/SHz{GϢV`p0VKHfC-4V"ؕ(lCm)?:'[K%"@S(gjs7yWK(o> R^uaƄV*rT$sKP>O>b}%6ӻBHJ@hq&XHP7S-M9zϐ~jh9/B tHa1+c-e鎎ϛyԻo >+2f7(P̂VCPسFg 䅣3&(DɈnaD,]e.&{thpZr傁A_9t8B&6(n6 p-Ǭ7k[twulxoBt6 RϚj;%Zj>2.G'?&5'n}rb>^>ePH)]JB:g:vE k$"D`) CIg>=[ۯ8-k|} nkM2ʘ~XYb %ebyр.)1YcwnYqһVھJyB(h2@0NF&Aj.0 DU^zpjn@Ug&&{M2b5) "Lp c8#W!n| 陾]FO/-fFCI f%J)i]Oqy $$(.r' : QO/W{mR!E$T%^{)4Ł0&A6&ZV|cD)K1eP6(B.A{BQHt],Ci΢*$+GRo*WuQ8['#]EBl BV)kШ%i!&t˧SXM^z :.5R@yGmb1>%95D⃚CujIA۬ϳ{*"_6 )NB@էJkCQ=&웝R@D?"]?Y`KֳrZ%ʐ60޶O}6PHI"yo^r 1B(dJ_ȧcō.D)$i!nMfiR!#{vbq:cza68ʈfDR hSl/3b1u3`a(C_I3 ox A rYe;.`!/p.[4~*Z=aOKᝈa;=N"(2O^4v3N/n BFGs3BZ:3f\IZ4%yy%I:;=uϣقL 6 $,21#K[k| ÚѪ̍ { 0iNcB;@Z}YYc$8Hx2JЇ;Hڡ@!($ '^?fHiu"B mqo\lc, E"RUĄ!,BO!'ѲOH1 (H] 4BGFđ1`I#Ǵ.C{ 1$pxF`T?!?@Y>ـO '&HM`*H݁$>EB}$ $ 4'$ ?}B}$I C4X 2HBI$ R2I =@Ԁ@[ Z`$ -` @"B{Hd@P PN $$4 RBN䄬p!/bH>{.i$!d`0hI s @c$yFI$l1toL^[2Sd5\gWާ.tt@5q3[+W۟2iX?հ=;VkwFIGv3CG4/^ev%gDv,$d+y":76iBka2=gQuxI2[G !x޳ 7ͣE &GSb2N8eQ<ߡK#9JHTF^C _*1> ]Jѳr׷C#fBIyօ\Q9xR[<"c,j{ 4y1ڮA|ZX$U9T8FPY δԻ9"˦/{U[lI:{7=8wYg# 萄/ Xr\6(."ف%ZqjzU\J,*whυiN|:p`Є BHbKAkB6~5rmϱu?[7@__T DDDJc =m ZV{S1 ~n]b^38A&Cz&e p eOnNP)'cXEyҷVHBIzWE ]|l\)E=AH{  Ԧ3 @S+Lm; g [?K~n>ML۳i$I!$/  B Ե9h2)%xD , gPDCXֿɤ)b'3vSegאɧF_?I/>Mn#a7jb$ ; ,g@$I<V>:6[%³9c$&>zLztb e=?1nrX @@{R.3JoTЮH@ 4Ee6~7JjGw0$>HGڴKsmI??@(<ž"WΝCOV}kB@'d@}^N H8ނ *zv:+- 1$$Y$Xs ! %yJ !'Jme"nr@v~>$$wI b]+ȑ@ ~^Ae橍FYE DKM<7ynG\C X}R @!NۖOT*, Ӏ){$.M68>kwU v/ IFͤ˹Nl8Fl cb@!jtw~ބn4B>6| A $snu?N_sY?y,  'n]yBsm tPZ@_pthmw=|_&so;Nb,|eR@$t?vICR@f)ܒ! M?߀wLH^;I;~Oo>jP (JX g4 '}dxȉa=eo! QSC;?>ʑ۴ͤ?/_{CQ`yMjrI;SkBҁDBxH݂k</8.leq36 y9Ű'.%X|uͬy; g:\x,:vM$'z}ªưb$ ۢ-! '"@ oHB6{<@2XDб2`8wr LB͕BIέ9O}@(Y1,I0@S>mZ?%@!-?p a.` YH*5"B2)|?_ԪwL$_b#:ِ< kVTQX' wJ$%#1Sk筻>K>:oj&Iv-$oq !o{Wh$ a՚ƁPJׂRpHoe*GZ?<0a Tkߞ{/BL5p $x#ٛU(xp# lG m1 vsJ(pEˆxv==@ 'y-/vY"hsYhH蘒+^E;]iZݍ<JH.mѩLx%z H!)=r Ǖ@=x|&b;IX1wǙ1HB@!Qu/*Px'e q4#J D"WE^"@k,"ZP!]!"C]jq1Ճ3q!kNf`=m6nY@g_uX^Jx B!ʞa nDAO2+; g Hq! Y?ne3W4yzӢ{#m!+Q=$F}&E!8 $5t Ą֢us#qvFw,HK|uyYDl;.gZ'ԨQ uKM^HU'i3ZrA4xM5o~)#(i_Q 2euYCB2@&utpm(>]^,#:QIC El7 ÎL+ˎ p8Z{#0Cջ(2 sd<^l;*Wftc' O E"BL Cg:uM2exמa +Oc\֞y ѱEA@ 3!B 9gs73 ٠30!ؓd ,{t x9DnI%=Btw1{(㑄Y 3Ӑ&m=u$B($-aoFF=H՛ڂ8kBr[(NÓlWENZb1.yfNVK׮Wl_JB3Rgm4kTpIb! :9lLE wBwWVLVdRIv.`mkTf)blq-fT8*=QX+I+3R|7w`b ^.JQޖQ v𶥒oLblGZ '/AzZEFMC.j0ҏҕ8V66~mz)p$A{9c#l  ˈ{mEB͊N` )JF-FK_+JаDB扌՗q)[}7VD;/a9rc 9F H@YP,YBgΐ|rIq " Nrؖ+>؛?u:Nӊb/DL^d-H Bzt1QpRI#6/`҂/ <.a4V~Rw{V7n/@ܡ.1ztY㔬=.Z"l BH+0CBI$qѫŸRL⴪";n fNb-2)6bW8!={$cd%4ƍ$ޯ)Bx\P}.?voTIAUX_YSBoxxj ~WX`.}j 1)@ ,f"Oڗ9Z%s\MI+5W`!_Մ[ɩhǽs]{S"\6О+^J:g^e[07 ;~XrH}jPieuch7(XiԂ1jR!d=Uuze(}OҺ7_Z6ܙD8haMvtUO0(`0roNܡ0,Q,|"h%fպ澉"}7 uD4R~Eb^I<3Ӵ1$r@Y1^]j7] wKWy&68OI!@'˰Cv&K/`M)aFZ@RYCa:qHQd!nH2,N ;*P҆+YFeWd!!> i@0:aC_E*# \g#ŝlM/րS4<{ˡ)t $vs;;5b*!ItabLO}H{(f*UfF,!!! iB1dSc; *`պdm,XVei$"$958q 2YIg$Nn/6 +(J$P!#d9=H 07PX${w/Sߟ=J!8m5ogs*e{ı60NXd2NP!H4C}dI6 iܴ@!`i%cKkGǓntAnk)1s2BD@TԟQ>sm-ضq:*ѶvU"3D)K h-8" $$H|[6BBI 4u@ҹi#5ȒA0U,hy@YXIc7t,IBCfi6M$r @ ,߻"r6ikC ̖l$Y T9!w  j $H@r_rX7]@;R!Yٔ $^l   ! &ʮۗD`$dkh`#C нBCc ʰ$$ @-!$"b06$`XF;VjatBřDْBHlw<o z9wt° sNXal9 BvB$ IU 2B|;؋hȔ| Z!!"^mх!l oםdpHx CĄߵ(M+!N}-\ QKZH1wS,B ؔއkUk! ĒH;ih 4"@ݭE &3d!NNla $Ó 2'}$HnI Hn}kG}I億flt!7d2c;Gsa$!!7`B@:' mKM%NW5WtmY'nԄ tCf& HtBntKl4悬QsYf8aT$!XZB $JȺDFhVK;w1 ݽI $|uldž )bB3h,X,^.؀u׷M)fHC{Hv7b] }$k~fwxAxw}A&&kdąf HBC)њ`"ͶW;YR g&7gS MP1ĺ!֛oC8`v'$U^$9儁L$< ȁ7cbY8 )]IeaEfX" P+-yY"PmclHᗼ@ӳS=w'4Q6 giˬ40{$ BVTX\)%Q|z@:ҩ|}4@:e)IrbAN8I &tB@KY +B-fՐ,bfKkK24$"V<V ] 4N2NIMrbqZ`̸A,:BYB/SŲTJv+મqYHm)mШ30A-"Ȅm*7Q*V1gnj WcL态'mEr`,-p4@:tiΝLaznZwN7(w[r8I9'w;+ڛ mLӹ6AMįAV`QQ& L06#jQ`:]*pYyuM+Wv"2!ÎHtBv&膓,+;w^xT8AC2QFR怒1REsY(ŚkbШmxQދ5o=6E FDF `~w{d"w[ui31[YgWIng:!Ѐ8f/sύQIʛ L h;Nj]o8]@bieF" ER7:^7{il .jߍU eΏwf[tjCb(+ RB\$Ԁ&*M)ZVK"&|W/5lϋ2ϝ ⤰HD>8H$aa@H$xp $ $iԆ?fg&QɊ߾)7yM/ޭ/9vkѹpDc'_NFMv2֭@ 4{n\"_JnS˷N3]}KaX) :$ᓇ@Md;NHrBl2ݑa/$21 i% %NT$9$ֲ{VVFj٩%#:?kZ(}[5\1iG%uePIN":ƨ+Z=bg`d$i eY:"3QT%dBvCe7d (X[۬,ybYJ[mm<'h\gq.߼R|~^n #P'瑹?PK$חJI7Z׷}z >FS'}Hy AIFUV6 0Bi4?OVaL8NƿouC|k">]!$HBF$$JIao@u_|Y/r˱s31:B;R3M5 oӒ˺m[u&?R5+?/tHEβn!3}A쬋:+$ٺ([μ%"JUUICO~"i`J\/TlĞD<2K"`LˋZ%ZߚcQOTr膢ZۡA/v-Yبɸ#5o_~M}WG As8 "$@sڌsil%cл#|Ҕ+^|6+R<3bd){q9tEc&Oϊjb.7S.9#Z#bşMV_t}Fo^ Jɢ{/_aR-`9ݚeKq@ؒ0Uc'aSVL-9jd nѦ !%d$kV05Z ^]1ݹB,-Mt/Sƪ2rH՝/q ĸO4yM<\m0TsfTd5g$lyiӱ! 6I4Va[`)v͝\ JM[s\KUG1هikD9Zqk/ޙ.0EGbfxCAkU`sX`c61_[L8lnt-Lc25^ 1OR~}ّ۟K3]\bF)9=dlT_fL ')AQ[&U4\̳2B BgVV~/Ϧ& ҙRӭk})h⣧S..7OJ[IYS*),y)LZoKk#p!:]ˡI4 Fҙ7}Pדz2"Bu! &4uyl@Oi%!;wg0y/Kl\ہ`:cdٛL==")R]W1E $(c;a31tye0 w1ܒiUwsPS+ZqJk4ϭJf^cʤt$'nMiw/EhWw&) B@@$!gbD&)\>rd1G7rP90^ٕP[rG:a͉/9vB,@Yh~Ep].絼CYu(,İy.ml?MH,!XaQ'm=>.$c]RQ -S R@Or!z OO~93}t 4@Uh jYaɣM%&>lqPLkHpYW[.k+\gP*ʺ d5B!PQ]Sf,kgz (@a я_יz>V.鶸=9\@$E e^>>5`ӣeIojcu O>469jLxJسH@@HE <d F:};}E4]O/H1.4tP` sj2ss}Җ>-,[) i H?iU` 5HI }"!=bC%i#ұi bBK3$^5i`]B d!;  $K4$ĐX#ڴ]H$qFЀE "!*BO#$ Z!'a HsKyBJƁCHCH]HG%`7`,gЅxװV#hKi<@H]%c`_hìHKbԿvo\0^=7B73AJ[\fFہQ6r$!$"ۓvi[F. Q!Ez0axdquPsA #I!H !4yؘ]bcvt{2*:8*ͷi1-#CSN;A"iV.qAkn͛%i'Z EyTݦKO@K*r €A_~:%ed^ZH@Ӟ\Vl\LTY]͝Z]"YA"{R@@ňCv)L9#$>]3`LD4S 0-niffFj]R_]%'js(4k%E!!=FREmTV#8Ov^EbNusdp25R(x0M9i`ͨ9Yl lk(2 jlbV)+@P Dag܊b@d( -*X,ƃкgQa No=-VkAv- {(kVzӽdPZF9/ckgΨ#oyd_"b/PY9XkuZe~ZU:, )$0d$Ϧ*`(旻!9(&̭렁vqwϕw̘l}brm]2͍鎓Q&*ki4_߶Da\]N0H?vͅR-3bVVc~GIb`ރ* 0V!;\H־@˵Rdw㘏_hNP 8*D]7k6r3s濼xϞ4w2A GLW;r1f,S[48eML'XxT ϖQZf!ڞw+~[ŋŚ,ݽ&[I]~:nMgdójx7;xM[,:-ϯTs\v9칳KB 7lć2͓z]XIݞE$x, 5bBTkkQ;srfg(kU JN[RJ!vU>RE.@<9%|1uAzx93X' o8տ.)n B-Ļt_XkfaD6.5NȻh"|PO#299]r:+%S> &nT[&Df%W7-{TW=[ Ui+hT2"Beb@ M)GMs6b Zacu~p8,;֠Gm )tPM%3r({Z^e2fg5#kp'!!`%]/x Ю= lI߫*HCXoH#KoAOo4W_aOYäx9&a7v묨g iݨ%`AkD"NSsnIGM:ߋ%*PE#B%\&^QO t׻;7;ӺG)זFjM&Jj "E 6,D444=8s{.ۓ'ڣwԋe{m&o6+ߢ6I% CIfae&Uv2X6'5m>Xax'zǣy'.Q1A(>la>B:#k2/c2 !0㚺cgKΓ4_iOcZv l:DvݔTPRQؿ[v_$QC=TC]d+\>:}QOCSQwG!R?F> ouӽo-vW`Ѡ_˓ek@aZ<>%l'J0ra{ӮEMm,4ܑGzf d{FP Un@mԄ*&@QӰeT_Չw4?~n8!Y3 j+=g' "{w ߏ4lJqO1FIZ1L6z}Oz{aI'aR2!ZW R4I>SU2e2瞧O4.b-6ȟ'q\_Y=}v[?Ht@G7P׮$sԴbz'EAUaL Я6Q~J,n7uH cs֥=-jlA 7F>s?t=II[QF#ٰؖE& `?z=U8sB/$}_$zwʤ(f9׵i Vn籬-ס N3ǯ_m5l6cr}s5\r87{ݐSeBwμRh݆o-dm]?4}Lߗ[u:ճW6y[mӾβ K_ꞅ߷\3k$|GĹFuU:_nZPa쯻.v}~א@F}v}kkTvmy|._K@r;j]WU`wwł /@ӍI-F[y"sQwAQ59m<]-ƫܳgZ~YŬܷ(ɩ(aWnt;=,۲1wd}rBL[Ia36? )^^@mmk VsZw{eu޾+_;824*߭Q1\?'C~R@`{D?4:v&\QAϊޭL! drx놸tOi:Gh)$W= 9V\ʼnIO:M%u'TѲtv]=_tPt.}.7}EzzIõL-[j=cX/l?50z(sGt xm"d_Y;;5]^v{tf,9'$:+ N<{&w$AOr7J>ђU~[R X'jI!gmޭ)dY\޴y=e2`h"+UNH*يl=sJZ,iB_?'1|m7ҁOeꓴHLX @|׬>1(\V2~/OZ׽{%xgzaTا*oY0KV 8ϗT;R==7g5$N=B@2B) FJ jd04B jH[4|+#kO)43~q^mC@6h4NhV;U1paolOnȂVӛ6[|ӈ $U"Q@i+lwYxGf9z NBW?D<2+ʭCKmۨ҈ݜ(f/d^Q,D0TH~kw ɳ& y}@|8`J'L<䁘dg=:b%o1Gӄ!*Ѿ GCa6"K$))a(k ^=Y=/G]!Uۢ S H * ݒ $QQ:I>) *_գt;=y((<җ eАJU3_H8 b5?X) &;&RSRIG_]49PL~%)HHe>1ZheZnf*tVMFRvD0.ު$(._ΰBM1*f)Ebj ҈82bG:~6?+Oh}R?9 vxz)zgjNq1!K2 )[P6) iGNZA8Z]J[bt/)~d@or $0vz;IA z\Pȿi,Jk_Alӳe2y?K+vmIbf5PiHϳ KK?&&H8/@@ͺ#mOs﫯}IPX$+h"nP aAk*_;BhB>I L pd ٗA"6<,-URm/ gBg(l6=<y$eV}F۰eWai5޹Ed^°:6{vrn Ǿ~_~Wtsy`s wΩ5Yz5:_{9^+*v nEbFV9';+\C=Xvp:-On~ϝ1]`n%yd~7DvbglիF^52jLG}c<޺u{yGjfblR3ig;~4\vZU;4Z>cG4k?1ƱQg9Ëpbm)6 t:XL2~wR~3/:(9 GC٪*Լ/`{>.ĂX/昤b?~5@ӫxi a^ 0@J͒QX@Wq=j? kDDCx5ޫi[jmF{NY)f ǝGIL~W2ϷԱkl1Mᯯ꟧W7n"K]l%/IԀ]_0v*CIe3I^G~D^- YVHhG l>=MY#?;X WY SWi-:ƻ_=oŕ/@J֙FGO0T0#]B4oA%bYsr }(iWڦ=*.;`LyW#ЁL?ٻ%٧U4fDٷN @)]% ϻt[T@ o4u;*@ HKb~snqLf)1u ZwgqA'iyZ/ܶ1<֠e@П8}yWW=㡽 Y@Oi:kmG_V0 8._џGV&Awf3up7Savc/c)+WU ލ&!h+j"eϞ~_uONw -p1XUIuk%yNm&=꟎{Tp^IO~SI\=u)=~3kxPf7_}u'] 9_KYm;ى7\-frhn+)=ayN+xױU &{g+FƵ[o}UlSz>;31zަZ;.+go&}g~RC=t,˒tv lg-lǭ#ưHQ 1KkDcְM"(*_Y'㸣AEE EUDD gzY>O@5֥E=oK_hw+k#z's\C1i7vHFBlԄjpKR(˛sLr@j@H ׭ PggB3ͷH B+I^NC_E)-oyzO)3p$@KBkA#5}m13vNu9 ji/N~A'[?9ϝOwԢF북O6k :!_ A?4v(T,I%b5Rk)9iU,fsf|&c)~9lM]'yK;ׁks~vu{|kװWCA[uzwEs;OsMMKu_^Y;p-].[[C=z35ggjw~LTKk>yhOef?az9'd[u??c|B>:V]bX)71{e tQ({|hA燶Ĉi#ō-ﶒNl '$hBf~yVBd+fB>(Oֳf!=,`COnO`~e sB`{fk5)YHԀ}:~|s~kmaWGYp ws5 3UKq)f${QoAQ㄰1SZ'.֮ vqJbM]Oۄ UPfΠ:";P.,EjoWB́KKB  $xT $ {+Afop 8->Cs~?b`7D+>~=], Sx;`dMvyt#Ǟ x0WU\T-WĄ_}MIA_qAwg,+=Yu{fݵ\@ ݬcgv5[+َt垥W;ÜT_|_Qr 9<^R_ū:&vqO i7 z>шuL]}o~'AvVT"UDQb̵UE*ԅ~XS`?@2@xʢ +;S=Vp+`9H; *b 7M']emqyU-G B[m?ݭn9n4w$9 K١AKձ{f([*Xr"Tc[a,ui*V,KL/E\X@о\oX-sWy~jςQpT)Wmy~imuXnuw S7SMĻ\w9NfGIaZ4{^/m<; bn*lyՌ۽|I L̇P $O k!.p@u\] m!0Pd 2`_B$,4(W%- &`H;IFH3k!>Y46ڒw r 9yLaR&"AZz9k/[h|vwPdAP8t:@S&+j! BGc|-:li0:A +׍;cg4wuYU ^}_&?gdQ'ڗ `6Wr@Z{ -x0Jk/i?fg'*GeTο4ռu3 |gne\Y fw /;S}g{OJm Ȉoڈ*ڟ$('*8~2a[Fh {Xޢhpnۖ]5'+:~ ov `IcK3*6PJs$ӻmCA2e 3 S5O52ğ5 ˻WS>QS2)ùN0 e͒㠲6|]׳u2Or[y{<]5pG.K-:lgְ, 2#u]S+$:3JnʹP̽[H)[_$sDM |ZÉ*D/WA6!"O:6%dc ZQ(y::ٶ),W%H PJlP{iE/p-J1d ǛN)rf@sjQ~Ml~TӕgyD$']zɻ~}گJ*!\OK19II$ M+Y (txu%( X4If&dQdAVo~qVګ7eF"H\lW-YB/6.ɐv-jO<@7TQ  5J SԮGV8>֤ή M$TKpגd.f.IX7Z/ LQ=c}rnn|#{ aMBY0a@Juwu H# q! ~5y}ݜW[vhYugBu#-ke~$o.9urq3:;Ԡ8aS ~Ot_|L'&"9+lSt|ܻg\p@"m~kNnW0%̩]I iq x UןPoU"0;yݟSЂp?X62Y %i~kە8˦8N6ov9U&j]hujK[EM1)(leWuSI$$!]V wRSU* sxbQ,L9f"8*I4j &1'x#f:W>tOqˌn MGԌ"|&7^d4?}}R |7mc̾BQ|!ND@C nPS WgˎK>3߇:JY,˭u;)HՄ2. ` L<ڝw6J Nk c i^>V\ 7y>߆4XCdKfPع\RPe5;We[v[7f,0CX11H@K#m 33%vRfn1J{(ٻjq;eY=Gi 6c6gݯc "j$` q,d}TIS7cW'%`b㨮n5l;O^ x:_ wqVsn-L?%V0PK]/3ƍG)|qk-\T6wxmf&CgSޯ뷒18%}o.&37:ܶ^!U[KNڳ[W)קF9筀n])sM <CIkA,r &CZ_͏'ncScb0,GaL2x\oO#z;}_fOO''q3)|f^62هԝ6jD3x,}T N62 .uR KTߞI.N~+I\C" h,V }Tg 5_xenRD_e&*mox˷7 Ǒ;rwZC!^OއB&s1dž%oq"+7>PT2jqFcN,0]gKYUyeHt|T9x؂IP hyf=B׳ k5Ņ"vLUؐNÏ,C/_h|^4ϔu=??z_;9d^oҜrx9#ܫ[Lr3t,"{Y|+f]Z:{ŧ^EuD8R2ڐ%t݇ fnW\$1-; t?=ǐGGЯ=oc rZPa8Ti)= թ6R nuyfLu =p`B(*b |}{!t7pCyt*̤N d"iŸ^dpu6b+<ɕqyw:j{#3 j05-܏ wyƿjmVUTwB$iɒ+Zqk$z$k3;wT,fS)Ao|l7l0wijgGnǹy8VA[uwKYj,豹X(OqM$Nńߊ?T)6HugMp[<:邵\߫]vB<+ H#aw Nrӭ DjuYD!!E  ,汙:%ŃGXc^F7P>̮XB՗傺ù&);hBW `ؕlbOwH,~ }~ u<"qfE~nCBrd1?Za@G۫"+zvӦ|S]s73K'(I\[`ۂ:+[:w]sljURt!}Uah ]1j/ .=b,[ץZR+ 6 ⿇k{+{(!9(W5YKA7O꯰"V{`(p *}n<~w9wc7B8Oejz%kTN݌1bXppw5S8uLe?Cp?(M1 ́vYE(_\e(>`adc-p{8c=ãԹgC/.<ӊC a0m~/ˆ6Alhr[ʊkLկ6k3˻\8Kcsz柃Y `[hr fIt(UX8+ҏ#Wκ7+ONKК}Cnf׫ 1 X@pM2\waE:9d q别1=yE|(n oq lXPOe\$;R7  wbVPVC\0sFNSZU cǍ9GcE W>! sb7/ ?Au͇gc5!YzXmtaMZ+fG+ dҔ4]O=yuር,-X]gLAj! Qf, _4 [^QT;rs $R߯3^r1$dj(;P謿;ٳ27#*Nqh[|,HOa,`q[n?!-}A:pLcP&7ӫ7m$}I[(o"t$Dv Q~LE4_78R@i Vǻ~1ڙp߀M.U<=~71 e>n* )Uv 4օW oiF=GT-iE?ǂIQA\b \GQJunch4 $!͒&(|l% 5"Z #7F7ڥ*w%g@mbJSRīZ'78i&#RbԙƤMW+w #qz_. s-btU !e 7occ~[UG;x9uv8Mt`ɟk>Gz)ВH ic!/WO#3蟙*#;SM V30d$Zm.O;YW=zZDDWdx" a0 s8m>Mp8ZslM٠EzȊN*"c5F2YL?ePfzm[ r0Їg~gk^yZ.]*QH (n{M-*E>/t7t@+xl`.:2eܻruwe dH3`Rz\ތ~v] }</ܩǣb{7)#ﯛ]F{z4;yf{3H o G^˽wb;\sdp xKO'>z.>N*O:t38 ~NVHAAyNl{G>C_'6/:Om7f:O\F$jM>b$AO:5A#o+9>>ch5YW~mp?-Q5%X@3EmTgR}3Zx6ị4q6cKM?m3q}=?T"J5g/x/}$NG% b݂FOcLie32%k,-tBP% p* $"N?IzW>]|%+׬I~ B/H s.۾~uEnt?7_5QG)>} }cqOs8܇P`SMv[ŒnaǢɝg<!btw9CH!qX6:UF ShV7!kw/=v|+^G?_OoXKu0KIdbŢICOO ߲}< E6؁OM>n@a1b d8@@!+06(~wz?̋Wgpш7(7k캶=:(p >ӊ\8לVy3ZQ./: 2[ ,,sU]>p깚 h>amL\(2OӺvkU_;Vz,?O!o6J]_۾6ۋƿr*Cv0i^\>i/p26.'>anỞx%mϯ>kO QjEEQJz@ P5Ӕ>]=$D e`{Tw6]Yױlsnqߒjos F?E !bL!*? .3j5]5]ױN;'3Vy%3 cڦ8@T$l$ZmHF|6&IbJTE M)$$X @!$=MM! !?ԀC YuX(I$6}.翖r*Ϛpk'7/ij'BuwEfR7p{Ug-2dJ E4SP\?խCb391>_Cex=y<Ϗa[`I-;Щ޾Z8Ӥ{Eݯ/2{} +'q1wgQVeQDdVV#W}sDO 7:+lՈSK&, %~BbX@ \)@1| z ެď"zud?u;j-2ݚxn>1v#툨.u^ !HP&HIX@442̤.@PC2@@II""@`I)H@P VH@%a>"o0!V6/#4>gg a]^'=#=+~%*zeS;*<3a(0(@2%1)0_Ky’ Mn@FUw(+K-""NjߗWHy͒lR0@rƨ4jXA T K!f _~?3zM~LN5ܸc1,v't~ױ7Շ-?n{tnz}5o~x0QM'lA}iA6==Gt U=EO(%wdM/$!è+ujsOl%K!$A l J|WJpa+{>f^5f8w[?O.t챭E)VXDB X OM ހ?rZ`d(|"m EjiV t7Nʛ6IڔTXтLqac"2B@Y":du ,dt"d/wm^OxwH24D:"/r7@OV`K/ӳàڐܻsn眅7…_?$KK[lxh|)mُ]BHv#<3C ƺ:(k = sWA{RBVSon%9N8QaJBqvn`v%nN\>2ik-.Lu 0_k@"PWy)8L1Q˺yxY}@dE!W)i}⹲3KpQ*#N^&yh[8gq6ӫ*R+VifL㹖ޅPsp!CSGPA3hS%֧\ f@ w]1`a]o=6{MC3)X;ySCױٞΆ?|GNrH8,CeB}|(nWU%}\XΖE.]IuAHhIYKQ>OY7sS#0LC}ٝ+/I,vf Zq{2ޗ ܹ1 [} LY O { IeNcYTJHII?ZIUrNLP,_0L;JRvfq[C@[DbTA!b4L4O;7 qM;҃:|ş1[,I)lp2"bK|BO9*^^pnЇ58a;5+|" 4!q;$Ṣ]?==v9όps[%jx]XnmVgKG"Ӵh[F*U#lķ o%˷Vlv}X_DEq4>l:D=cMI 9僘,m6ec" .PTjx/pֆM)P%%ײtMÏS|)oh/< OW.T>B [!N4B/"GQ4 e*$:~dcQ~Y1ua_ʴnY *( .{DuD_ӾCc/9תǀX(@H}zy'>~ZGn_,>Imn2ݏA?(umX`mwam,mN:v~L3:P#7dIb(\d!^̯η:Q`Y"b O&CH2ow*xl΢:hҾn;>uDG,el67 < Ko}\\C='vc#h őq_QQ]^|" cy{ ϟ;+pFf6 1e@&LQd6adIwF6>&PˍPƷ/9Џ^g~ ʀ@&'.X r6[6 fi\o7s 0ynI>!cX cB* ,9-gH4拨x46k[ H:m`XWޭ8kBּz:$$E| w;KxD,<䒲1&/"| K7: ]$/t16<ը3) !gLǚn֕;aZ"YFIb"\GKr4cDh0峞GˣsUieauOqrO@ 0)!i7!j2lY7WU4e@M6iIwnRӧ1 6v ${C3r}^K/bE~/5*so2 y*b<P$ۙ^^t8i Y;ڔYHj ]MG#7'\Kݯ ԗٖ)»#ow<_MQϷcV+X(eBr*̧x90!l;? 1ˊQ8~X@R 2ll ch;.܉δB&2>HVz ?X+Eao$nipb1lP:!bEfERe!6WCAp̠7ŝM$D+OkH)'qł8UڷcdRm\T$ ȠO45)0O,*ZΚ#UɘdL>+Ճ\q/Ƽˤڤdżζ>k fj &k6Ѱ5wc+{''0luMw5{qpk ml'_^=E~GsU$!Zy l z΃%<0,}|t$Lqp`o4VeW4qy;oֲ>a إIdI6M-] >]9eN{s)3x۹!ߗ׏Ra:,@ ɶ \ s@O<LmH~Ϗ.s-oczro!S|^IH*Q$go[';XέVd@v]P ϭU//n qrv&nj\!,\bC@}zL=d"$X D^!6CBݤYtEIlxq§(nJd MRB[)K!K nwd.D{:PfыWl$L`TQj$c "EBH4D- |OiO&zm1Z+Рyr|vmԑZ\3!eU]w~^ͺ][s_e)|L 5hY]{\_hEuv(v#xe'wNDhC41fH? [Nla^v6;LNH#ҜjƝ;AF\3]s OƯdĴ^m#A#־O"*$RTA I"4*R(@F$eDw>)Ǜh\^::=🁝.NJ>k=_7-ZViMV4𽴂^>nNd\W|z&W~I|?n %%ZWjz~Q^#x^ND{P%Iof+ҬҐR8pǠ@H!PPhtZif겿!ԋ߯v1a|P1m)HB& "$ CƚDEeS21TSQ Q\h8vr'4Hq hY2=GHޮ#[!"(!EWc lgL]R*wzso=$_typhX!PcgJN_tS%N 6YaJ;T~o.*A&dWU|k蠧!1# "3I5 JPgg2-NuoA ]lk :_;[J_'k, G ;2 Om%c YҾ˃Y(Sbj. ZaO 6gMe=ehv/7aٮ"ɉ7l{<.7=mK < Q~qED,|o=ĢqON-#L(ԻA"I/ȿCz&zaC%?k~SݥT{!~V2q"RLyi:@~J>KQzq:IVo}:bi"÷ݛ,:\ 02۪m*ueOkNvVU\Je]{?"\=O쨶ш/ݡPil|V}[*C߫&N/IKunØI:ݸِλ>CoV =nў*:$ Bf_C;$ p1֡enBX@ $ $ $"' tuW\ڎ3(x2АMw^P\ UWP1C'~_ ES+rmlMUPI2)NLn>rq<,<L%DDApo!DF$AlIx7+GoNNGmUq*;bAF"n${^KQ($҄'!4&$rd }I$!$ ! T! %HI$c'd4'X~"&0 $yhA @ i@c! }c #8D2*kЈVM,\V6qE6c+H2 lk&9eGM3wF.j7iljAO}1S2+<s3G^&x?}=$ 1~m?RVb;ƸUnܜ{1в7\ S.d 祥1-#J[WVR@x\/]L[> VO.(|{4(J 0ax" ʈM2' %T'GiT`(V1JW c/9"M`&]e£!(?4V"$rqt'Bö|TΘcX꺘q|SB>-A(gHH [j){tkRJ|TX{$/XE}:*=WzP+ ++1>l\Q=%% Ab?j8PC\ UԮ댁M<=uCJS\t_x>Ɣ.DD tYDj=f6Ef`V\!d[1 66z>xܝޏIqzfʧF녍4P71z PmfΤ֥;ThMd2LzJx_@zH!.gMX/L5*~;N͝[CÃŦ\kN$ԟvmfDMWY)l!& i9Yx聆uWbeeѧ,ھa`"H4"RJ(PHi!^ڟ/gi T %Zm:kȤx%k|, ?X )]:n}OM;K_6fJl\PME<>c[lt>OMrQ!v$E x7jX̥g/3'D^PL A\i¼9V /~7+!Qã]d Hc V  H_K&͆س˸ bkU_@DZyCi#8~hS bs %"m#$w\#(vNFvaYĢXU+=yZ7Ol >qKy&9CO%Y\JWXh-aw2;$#@s=`4! ~kYb,QlNM]>Dwc}SŽžvR0lTLCG ͎`)FD%e$o@+{qd6F𭔲pBIRa(.T`T{FI `gpnsq'iLC;b(绦/r0ƛH m=kMt.wڌiYtePР (EbxTbpz4*Zx:Xd/ם.FYKܾViY+. wCF5yh3|H9q.^x;b TL}cp~3H7SCĊE^-ݶIvMPXŎl<(,^Fًșd\Dw{7WI8o;9EqLLLݥd-#MDt6@hZ/NX˭ƭ3c ieZZI`ﮗ ~~,P.غyjGC-zq Pet!O rJYI#.}LJk7x`F p[Wd~?:{yX48j׉~5sA1*1-=D:|4#;)$CbmMmηKĥ.ڄktUT#$]I HmN~M<6PqpYFZ07MxrSrcҚ&Z%DZ_40m\4u0e7ln!T9x$kPLe*u;qd^шPpHIOK`>>y/w%OnBgdؐTll{zqʲA[uϩSAKeFBq7bPX HkBZԧV]W\Di@Eb"SXWjR? b~0 ot:텪tW1'`?o; sba+G:}qpihiTD/lذ5l5.l*2)գ! (I @~8VZeHj@!s(`Pftc{‹@3qٻp9+ 'ǝS4ݏO2]tk\ߔwB(aDd6AK @`J99[g"݊Ź> ¹6Oй>5q-vyÝبM|Uk|7.<;: ?E'K4+jz s`|^ߪ)kG>OdwdSaݾp^)E<-K_[''e=;NIs%$5+a/ N5hz:G|o 駨]5ÛZ8x:nĩfC#naI^UjxBPŇ6dvnUdQin:: VbKN`` d!'I~nܳ~bPoiR"Z-TP-(綮fML֭ޡ*d)̅0VKMKKna:Kh#L%`PtS5.yb>,㺋8)[7ਝA ҔA2x2{! `>L;Ѭ ϰ-Q ~:nȲ >ҕO/AiD3%1#dq$8@"Lͳ_'VS-9o..c뢏|?Ȟ~ ]DqH $`g.%5_' PqB`06!RI !$uVI XIY$?4ف @ )$Ad $, l@ dY]imQS 5y|b]v7{z>co#}Q(}Tr(|rڽ{ٶ~?DŽ iz K BTyY1d$+ @ RI "$R@'D`HpvHp ,$$ I'0 !|@@C9 `I4)d$&>%P)(|"V)p3MMsϒm 47 Èr"iǢ杭uь !lbJ9}ĘuDYv-+ڷy_Ob d+&t uҜ_Q0P.F%ߕ\*e3)] (UҁgP[>H,Ϭd@Hv@QK~M[Gyޥkr%.'_ֈ^9gkmPC}:iw;SLJ`8 !s[7p5 zCPaɼXXG*Nkj[/d即G st@{/VH,uYxbi! ̩G*R<}֠$DO$w~g_K D-!޸< hL3ܚe E@M {iTm٪[#4-eA@Ơw,6g$L''ybPTZ`FȮinobs$! NPLUUs[q;Qϗ; {H/^XH\sHz* Aq`U3i{ŒvpvYv&k_ 6i:"]s*v!s  |F!;|w Z-f>-uk r/2hUfzkZ]i]C<drqGPC a8nu];?n'pɚof5jyX$PA U\bfk3 7"Ce-"\Y%ڑWv!? {{O'yCRARQ+%B,,Xz#=fܼ6r`R&IGM߽^<@R;uR"@ϧ{;}IM4}S;YXJT"@ c)nX"زסǺ-C!Re=^yDWه+b l:`=!DmTE>wjE8r%lB/;d1$[d)+Ҳodu,PgDji1ZtD{g7Z}Ǭ8V|֠FYiTQ\a#"VYCF+z>nƣ ǒ*uٛj5A!i(PZٹg|p/L3'7 :u#\T([qޚ?htoYNp׉f6D%P9FQ ɮa Rf)`(7c_'^vpmgQ )n bâE[(˩P,z\ԺA LPM{ MPq(dЊo

n"Ó9-7!ָ;ԚVI q!Xڐ(AdH(RM`,6N_KtxtTdh>5"b:=1jd-obkjݍxo[GfI^6#t"PHPH^D\ĥ3;%s,Bsї;((, <~W%#SA:pppwNDED ZV8V yA?&"%CW\ٜR="bCi\CM0Z=˦K2 Sy0m0hSHvllD6!@sfD4~k}B*1NT;2<5CZ6Z_l-dG*6l9$GC KX+^R'{ՓcYy͏}#ws*J2&L@jքgԔ Vov,L^JVoS8g4t&,cE0*Շ E$ZhBE SPJ_EtOZև쩡zse״T)άG-yISݨV dFKr{ܻ޶~n6ͅX 75CXp3ߴ~L$]^yWۃ+L97ȝ߉v?_+guR)$fޯ]A|^Z W&e2>}巣QZ skwLL`l5X(2dN?Sbg{e<yI{c'!ڳg1i#cݞ/\ay8'pR^q\wa !׬mmN^~V 桻)&Kc7KRV3Glk_ERˮE2)U>'80c@'ZAb "ig !}6wGj蹴/^:˹>4Xf-7d1~j/{kֱ+lhO%qBS]]K>c5ؙ*ӁQVt[O}+W('mX2!/h]xwHi>y|,y-u}-so7_߫}c+ć٬828/$ dir(Lxf()ˏKSf8 oQe=FK1ĂY Zᨡ &KBZg s69jN 0fpELwhxT{ǿCҽ=cfb_ BYO8@͏x(OYx*ۦ?[̝ƼK= c^K#L Ljxq~amImoƸ}gJ>e!\O>juF`y)2Y|tNkINE~F[OmΞ~~=&*,Q@ @>i>NP"H# !$V@ (@HE~S V )@B E!$=' PP!?Y޲Stf>}~A~^MOɛ_ҿg;}0$CN.҉byF26E`A.>8ލ !BIJAHB$!+$Ct$?@r h+$AdE4@1!%B@>$#! ~}ׄ@# 6;j!A{p׎$gɀ%$ ^$ ;>_=.Y7ug&l%l0b:N6mYVA&&  дdvLzp'^goL^zQ2O="VsL57(@D]doM{w+W,i/O$dJZ-IfD?H_([tXc&E%̫ Z߽R j+.f'dyp8jIgdL<Ԉ(j"ߡPp% 𻛷$q!慗u*^mf kf'}HkBbe.úِݿcY+*ޮ#a{ci(UEK7{2w L $.3Y%ͽ&Yv/EFtG9tO ̪ʡBDɆm&Ut|@||V<2&YA@qi?p/ 7EBlHDB Qc B.JJ8O:,I~>k:/tJx d"cU 7"tXϐ˘_K-1oXی> @3F:Dp0g $# Y)IQ !Fo_zG;kwR&"&JRnUXwP.+gԧ_͟6jҐi @w=LH>nt@y9\V=,9oC\q"9VxnN#[ ZHHۏ1!WͪȲ/'('U|[fAt2`V Q q؉R{z/T鸖ķfys7v9 Xzشܼ$@& Dg0!a4Mɠ<}iR zD?ύ"Χo$Ww͐XSi1@u<#Ll"#"8Iw7`xKcg~E]~d`(\BHr.= L= I=F0{ٟL x!7RA@(UA. PS =$$;-2]īeP~FDOjC\k((CRJ m tJK#䆕5!R/`an׾d@kL+$lzK51$YŒ_kl#r3jW!9N|hi<!ߗg 5<ɀqP{\/ 9y?ූNw 14|v> Y h#-Y> TqqKfD3Opjz|V~h%8& Hh]LfBр*b9-uHgY]GـH0B[zq龮t^mXH`M$`Q7ۄI7`jiqw_ U,G١E6mż\Nn %鏭TBC J=So߅ *4f}a's7trx2+F8=9z[Y].X8pbV8Ip:LW?/< ;{S!ll̦  C8c6KbV1:|?uĂ 9:r#=Wq87BA%Ȕ[ɺ"EմvoΡ:s!!q$6d$ cXH'Y$ P}kT"~2HRI s@%d^&CL02BP)AAxQ<gaiL}v{45J $,?BzPITX!D I !۲PH! Y! `BdLHHAg]Y*aBdmߪ$'G/Z#;:'a?@$Ih|}È4귢7ٗ7ދ߃FLcqRP9Yt酁wѷ+l;dN;0[>#q|zKJ_z`GL)>Ԙ~SU5a "_HXլJ`B($ 2v >~wu!ybM:Xup[T7ڛϠvo`?+~h0չwύ7BS^WzG?мYRD”T(b=tb1 ,7g"rej'Z yV]pB/rڬ}~Q|K*p$@$KOll<[>ag֯s>TE[<ߟh 'K҅*޸wew?8tV|JdYΔ=_Tk\Lؾd{IEXb =ʿA< ;0fWW! BTCljOC@P("P^欢E  ʋyG1{-~]c_}<_>Zw2%14td!y$&$sd$?_dH$ْB$ $,IR$,M !,^D|wBhe: ʌ@jFkAvK(TLfCkcor9!$CDNm)_QUY2Afc{> |tuNW dʽb,veA8OR᪇J#cܴC8Z%uJ#,$0}>Cp(!o^[#`&|رjtQ ADUb6ɂ2dvj~醴Ĥ,#YlHap3U&0e+]-X `SCY' JZP⊘}c4W v? c6Lnx1H$~.LY.Rf@j8(P4Ų/6MOTyHs ԝ'd&ҹ۹w,~oYy|] >\hld4e~8)g!*Wͷ|fL0,R ?K)uk:+d=z!jtE;l,t.i7 >1HD9MeR Z ;@-a|fQm#U-Mgf/?O[&{ddkrSE)ޮ>c[mh4X]02]wϹ+YvS}5= L϶M|L|>Avyjɗ v2E.?χ;ϫ2A}v |pۼ`pù/k_sܶbD+j!rX$ CbA8Ql bF-$ebp`gzz̺Հ#W`"Q8%O1&ROB/THJB $!ns%a!XI2 c$d@PI@Ȁ=]y&{=94w~Պ}E[W5x=7-+uMιd-g!aMLS}oN@ȱ[ WAZw"|I)amT0af7X]5jy(:d^2c_Y.l6ȟVۻj[v  5{7+Ps%IwBS1%8wƋv%}LZщXi,lv/PFN#I``Pd[2tK%Rqb^V(3щPaoSߊ֒B#6Ηa Ndڢ\.zKE XpO{zwE^05|б09Teě7_7w,ҸAީN !$K`3"1y KJqt K )4ȶw l?b<J4]L"#MJ\#\:W1I?]W=V|Lq5O -l^ :^e#lNMl:ԢnQo(PHVC4h,q:K!U1(f푱Ȕ4?Hc g%B"㧙7/oãN˥z 2㼳"S.^ mǝgpg#I 6{ Va 2&IOo׎v:ck Vq\naC ?p !'.]o6o+е7qc̶Yث=/#wâ.{~O;Neκ:!C_;y 'KF Ӆ;y\$l>,K%|T%LE~H$ޡ>ĺ:tYyu;UܷId]'x7`(Hǹ\۽5㹹!&|R^\}&Tl#Ͷ4(`U&*ޔ_|R|Kܪ:±@V=xˎ/h6G "m{QD$ 6gq؅ƯSIV)E!Xv6CK<>6+;q?q&DCs>6̟0,`$a$fMB@Qw/HJ`L!wܬ?3u_"">a.$ 0ׅpA!$ ?dDq@~ \BzcBbD "B @!TQ*KŊ8Vޙ:Ū| 'iJaVHBHf][ @=O$,  )$ mhI?Nha݁H IHB,@>AF B'ݞ'nÑvcz]?}7٦N%-W5h| ;cZt5D(Q'WF*d氛M2SkĽ>ݭ=W5-˷@Uq݂֒o4Bl[32 E_@]_Ƃ^y7Z@+@BiS肝_y{ gdTť _ׯ.oj]ZIXCk@)"ڲBTHП$$,F0Dr*9{,(b6ƴ ,TiBO@$ $'Ҥ%I$ddqHI pB;֝yq%sk'xH'1TO IyibZ"#[oֿ ը<+6Po]h=-ZR3 a14 vn\[8|fS頇ɇ֔Ӫ5*TP=\_| 2"&sݫ.xГ=u8pve<"gC Ӕ gtrM.y0׫԰[!O]l9푪:#R%h6I$%5B,]c`CGFY>v:Q~>o4^4G%0@\"%^bP@`/<F~wM7Xο׋QL-vaPRfܡf񽿊c輦S4}zOBD#@@*@A@ Y$ (Hl2F 9><{-M/Phց՘H$I$,$@YH}@i$ۙ@\Fy?u|'R4.F\pW {EYy4UZKbʹ}zծ{N '#,NIA/zd{^`Iڪ>~.U6Hu{2p9 8R?ljOq(KH|FLBsH!9a2XS~a St!J ?_Ϗ{X΋I Dq: *Pc)X>HkH]Lm[ׅݏkXL2Vwm#'YHٰA6#J .1J akt?I}TUjdZGuo‰)n9!F L^F: ^B}m0d"`|.Gd **DMo9uk0o7(h:\sh 8@+  HE$>/@=%I$; $(p%HD9?oPP~җHJ(d)B#2IY P =`HX FHF i$,Y2sHgPYynkG% <%JA[vq33u_.տ哦xR3ǧАO魖GSx~{@ +.XhPw*-z-w_V|eMpݎ=~=XwneBO%(l#u?޲Ox2,q{?K,l*A{8Y>吣$5@H {TY,VAbHL0գ/O}znn=N|e Gcl2 HE! "rdD6`() ||I $B#!"($+s YLJ3oGt}i*_o+iPԱW`C:Tyu >!^B`fhb,ƌRAcj )<CfF yd@7 h@ W>߸=f[p54n !kNL 2œ̕E$!dV$ȱYMvo;.w]GgmaLMI`CQ # OIQJ@NVzd=͇Ggs̳r(>E:z}d9eg#C2Ky-; mpZ'I\*T0_{yΠ_*``unO?}Gi$P|X=)}/7W-C_l1El&1ZVl^ eQNr=> O Q t$'6Z4PS7Ef<@Ո"H lH0ca8?l)H^QQ'(Bq'%Ԫ4'm/'oͮbp^ :Yc؊̵ >f$ /XbR)D+ڢٮYӲ* @Ɨ.fUtpwU1{ϪDBc FBI1dƉ(}>F/$2ii//!nrLcҪWV@jIdY?^ 1tO@ B@N )@HY] I`--XpP)}[o>= QI'c3|"Q\E@VGгQ;O],[-7DžF[5{9+PURF ؆@Zy=2 L !1J=UK)/D AnL|0qه-XH|;1"nIX `Y$gd!fO +ﺏֳc}q L:lݐ dFIY Aa$Y` ,Y i@)*~ D ,idBFV?Gj(<0T Q8J;q~# (U!~u*"L~` gҼ (tSYקe٠Bvq7PPxM5rXpUI*!;&8c=uo.8Vm_~K@h0UF~r`_G4Nbs|odzG_;*x4T2ՂY!X dY̓\`C@lCV3wsrqFk^Uw(`&`: K$ !QI lBAlH?k-BmH" ?sN # ­@FGoڶxuH PR`;BϲVpg7 f#vF\ԭP$x .?KK , ?`^V CPrcUdi#a7>HGy_uK2єͼiՁc &\ FH@PRH,OC&F@ HE $GjrD& $i7h5/ 1W=c ([k__XbSǞ|D$cəJ3'빾رGύx? qBu[Z\}''@_o}k 0=?-kP)" #0ˡ$8Dr@KJ~c Oް' z`Na c:J{ )Loziͷ H&Jf D$E )  >+' I41) $$!8*PI_K×RvVxZDQƔ~˓f tC!9,|7y}kd(ǭ=Ṟ⃔p遉d4!iWJ%?"}~YY~\Q ZϱboXNEi7 Ȑq dC՗*+Q ^IQ0Fy_xca2QBP?1vV"T!Ka!eǧ׆7eco}>E3ަVm椄lLB E$*ALJ!JrQ¥0h LY@@p#(:C139'2rKw :v`R>㳬u?SB7$*5be")4<;P:{?A{VPEaJaX,Y6oUc04q ׳;}߳$Da Pλ}5x=wq:6~[CnLZꃻ&MD1JZwɌDjB"d~5t0DPd l7Xb2 Do, q5J'B65y{J܅ήYpv'T{kGþ_OҲ?Mkހlt n2ۍ8/P},^Óvņ*n^vd/_ 2fgRQӼ:]r5g&ba,J$b0;fo-]Nlr=/~KiV0jBL$+m'|}݇bT~i$ 2cU0NN=o|cѹj9ṫevh*c'MDQO|Ƴ/wdnn?mxZئ89ndG}[j)(pަuxr@#/#ˀZ?|/C[uwli.ثgǺTCm f,{1Ok[=Wϝfχw@|tdQ|iaj隣z}K[17B$y@P'6VIC&>$Km?Mi2t[!k?pS1)"PKݦ| VGZaQ"RGA4\y3`%a+"ݾq0 w0p564zl߱ʨݯ]\n%NՖO>>7 CX$>X,Wyه2IެT{X|[dzgoէ scf AJ`F0DG >C$8ֿdQZ{ tII8peS3yC6 T5UGh]^G£2y⨖~,o8ux߀y= ::K\mETI{pgа(+Bs?ەnBwLbCB$Adc?7W|1P+͐D 5*;M~oBa0k )2\a$J&X3>"e k?ח?[\ d[\EWLl,Zmc@An0c&(2fWC!lƈtQ 5룑x4~ï3_㐦zK1*xӂ`*(pΘXc/ 6Y~[*a͂f?6WW[Kk߃Hl0lY{!!|Ϭhس|bE < !AHPPP@>HY9/7\GSHWXZǵq؟fO;sϢ)_QB>ڳOy9H0>Dceb\טx"(z7 ħΙJ~E񄽹J3~.mVEFd%g'NM^1F(hde\CRJ1Gwo_8J+ yGla%&~O|x匩8 ?8"BA$N~&̓I$DBeFc SC6iq ߭ {;)h?5wr;QU4- 1 : @ $身L)!r>ȼj=~b`DV.SV 7 & h/Nz,1IGL[={肇 SĞ=|."G=W~/0kyʺM}~$( m0mA3{ϓ4@} ,.eDUA7zVcF\4c|S%"XyÐIFdby")JT "\+c LGE <љ&Z+r? L9IYp|F<+J^xto"Bӊ?ȂqU=,HiYLY=p;l?>{?pDgF{ƈ(djK,oOWVm m >3?> D<^e"\ * ϵIAKI u[Teu0QMFq Ԁ_1F30g^ɾ B1)+Fb/a O3ۀN,`,r5M`^$W;pKغ蒀x"d`R&(Hsv\'6W9gĨ&  Oc6\}þޥ\n_v>(dD%HSd_A{+Ogq/OF':f}6-ZAR"<גh,d~5LHas&ahxulR#"DYU,GpZz X #߱:tB%ԉ}oKm'ԍ?[2|?'Ī|6{?]HQJi_Q5('/]]sm?'hae0s(JuB)'sHAFM+򜈽OfYf&"Y{ƭl !L=D $u {&B8S9) :>^ܵx89><w(bX&)fOy#^7H6 9Y(?H 1r?.w`AV AaG/+4=;>v~@2ԔH 'D )D\ke01\qY֚>"VFgg4fc̖YТXo{-y<[LŒH@4BA#((b5u;px4t:ff xZWS)6y_'3o0?7GHA0biBBn!#|0? N컵2P~ (ȿJ1>>=~J5_6xܢ PJw3_ T ΉɈ W!L " :DU4R fEIRW)"ֻ mC0tޔE)&>͚\3O>y-3HBtc<:wE\bna2 ej1aR򨨢eBj5Z6w_tkgR(F i"VX?E`po,7 KF">fҥYG8b^N;ҡ)L@P6Hjrp1?an41˅&gK_zg9 btNU{oNӍYoeq<c~*rw_c<mkw.ʼn6J\ ^OMvN?ѱ(q Pj(PeO[gwv= @3Mp=Iqܞ@LjQ.QI>"H-A֓!M0 *rG#^pmz5ο&su'=9&gH&Lϋj-&#ZJgQzoǜϋGY VZo\^c ] ~ +?K1@Ay7t;zCFeH^PK gQff({]L}n9֕&1XƘ"(xH$ /eߊ t7M#xnT;%@o0 BPr`~ߑ&:gwGhQfCo?nWvjbCNlg?pwL,%d -ir*8ڞ ("YU_^нY y&Pk(Ԟ)=A?J,Ω/D U<}uaOS/Ju]"%`5q^ϻyQJr"SDq-˾=/=I:r%< @ٳv`_<]gT2 F%61GƒrL 5#[W 9tqʨDlcbT6MnO?, }+$4ЪЛ_k/f)rHS4~1ꀠ"r$%Q8F.H[RȠ{)@m=>IB&B49\r%Q{M#պA5E +TFiȮє,ejvd:AUP`0RD RlO"p+Lf5ҳX$m3$+]ߙΰ}_lDZZ4VGXǮV0R~Ͽ$w%I"&He+?^ww;VhX@}`}է_LiZXA `g}Elz )X jG gk~n (=uxV%`P^>u a-PRU %!Hg<#dpQC]XPKqfaQSAE_W8[O]IQ"{n5qZ<"I0oURXREIH R@J#攟-{nOʏUa 8#cdlemA*IŜiƸ"DF 0 _L~UF"{-C`a"ObTT;<=}@k˾7O݀@0a9mnPy<6&g+;?wC}-VPySI{F H~O&+Q_HÔv1 LRWdkWVZOq6K{vg3ҝ\L6"H4/qȭ:/#v rO͈R!!m'WB dDQH> V49`倠)ȡ׫Ke(DHso2k33 sDZӡF('X݄j ?3CM:&GZޑ UxNw1z ؄݉7L%8w5CBFM ڵ2.CEXXQOwEOEuț)o94^M2cY*fs3Ń7h3$F_VPVb .~<60:"؏إl '~w{|wﺬU3i2S8`ySWeeU&۲_nUTF|k4ZN6,rZ  O~{G[nވ7y[*%@vmRᆮHK^ ia3T(rȮw Aφе0{X=;23o-g\* fj19 +JIq'Nv٫'4paGl)Dq*G,6.Y! KWuȻ$TO)SKe?IHg%BΪ}LN6qPvL /͛c-CyyrUǚ*r˳,8̜E/jolU󶙭]j4)qm=5df%6=ͩ0{H=b"?wHcQpllm†gћF|y"؃gKNWz"߂<1#1@05QE堳 PvJn,HʊY!`Xu3*Q*h+1lNr_?iz,4Kܙ&D!  Sۉ?/NBx0ZՄdJv|8$ɲAssb<1@ʗ)nحn[7*⇵Ã-gjghZh9U(vSpGp*[gZXe.iX4-˄+OYn,˒gLʅ|5C5Xb&JYUI.԰J*t{sמCt)1fI3_xkUT-`gcJC %֘-;h'gB_t[ApXn[2%e<1*CR 0UkO|YWu9 ΂ U'Y> ^ɦ*0틜a}{ NnYU6P}-k^ qܬsU˜r˯g^GT"UNW P)xQm^2",,j-;sW&-EЦRƸ}#вp'V MׯFp{b %?D̷+ph4±-MppIew|bU}KMWA',lNc.e;t2=&n|*NqmpjQPaȦemd8C6ªTs9'1lt֦sPyVC{fsQ![v q˴NrM LQA(ҝ+ZFZ#QSH/ukDHnܠ7T{nڽG^·r&~-_k|*J+A>&6L:?Vr$kt5<(зWONcK]S$7CsnU\Av>w=6 o;ۚ,_ᾥ˽[DϿWG~gvXAjW&! Y8QkQtjNh.h."ӂ$g-ȿgB?a9xt(~*19w+.OrF5j|9ƘsqK|ǯ.vƔ$φޕ^qv>g 0 KC(GHdlãOz%X/ (u`JE{?\k|wrTnv>2`{l'vw0^$aFz(N+C. A_bfJU#>"EqXq35Ԭ)cJ[#o,YlD[u0ѿ"^ Gp ul^ i1 Gi/+X# bDX%N ɵ:ohD[^̿~^+Jc5HNm[8F s0Ī*<М^nC ԰,Pdz{t7~>n(D@4JA$u˩秳FEhy^h4Yko$,C/*S"ǃ["v/Sv#kT*ؔ y L68o UrbfLDH J;{DfΧzjU`eff Wa$7KJX@| a? U)"@!ɩ ^KC"[k_mK)lVxSߖ_Q6$dY7d0G-j_ZpbȌ)pR (/m^h}JukL~3_(_@uO*3לLʄ X2x4@o * Իo"~ ;c{;y:{zUh['9 (>C3'C !VMmի>d%sJR+IwT˱-fY-wQH[Z'jT8[:)Xv´ïɄtl..ջ Y]y_oɑ#;w>!a`ӿP{=2OBmap ;9G< PR^BGF2 bFSRA`eICx;Dk6~M`"/rw;@39ܴ[ݗ_rC܎إ8] ZKJz#Q&>nRv]R \%{NGsVPYcr{ !WLK&IWa»ݼKvV+^][T&'_8#DE(Pcrn.+Ȉ9)<"(:CJ B?OUZuŠGl˖" [x_u=Kd1}3_ϝnBwB m"GyK}(E6M4dE?My;??|H(yIIH-<]pk.~`{Hb)xbR\}[F>MCfZ3ZbX3hie"_\ <n\  #֐-+H$m+G_iw>ynL\ϾߕLsw^!f2fua& &8)oJqc$9) T "}Y5IFuZoYVm='s`n&JXȥ D pJD@@DH<;@ %+o` q>_q))b ?w8#[DxZSi3 "!ϣg,/VBov=~Z`j~$"SL Z`q郩Hm"=دQ*t%K>zץ_U;D!C74pr2FN ڎ[P*ׯYpkjtix%8pkXL P;9)]8N_ GR?2>tM ەo䘙<"v0џ G$+)1޿FC|˙IoM""7g KZ1~^ߕo;X/6Vs67(إs;Sp38aݗ2o:Bڬ\A`XDIxD%ӚbWSs~1pQ/?ӧbٵ:;mKv?hpi[9^OF,lE4L>2Myg'%5.R$(i0l60CB`KPdj[*Bn|9\+I,@Pb~BQl}(D-Y ,NuR(Ջ-xs#o%tx&64>!@Bxe=(rJMsӯAVvr3L[ 7ZiO0I$հzV7V J`&>S[4NU՘iQ-7ű0\⭟Fz-޴L)Ɖ`d{&5u5]#D;6>)9Oț6=q܍utIpH+RCd\%o{rOP[ >">=6e]MkY\][$ oK+#9<ӒT^֜9^5XxUG )SzS0Y1dˇ&%!<޳˅4֊ۡ5YSHpW//^< Yt<;omBd03su }+Jg0>Vz[;`ע|2ӕU:wU4?m-ј0Bz_|7qZeÑFE<2t͗sf5OGx"g<|;іTqSR2YlOUך(v>(o1n@lv~x[Ov|m_1SgM/b&;b`ϒmn⇔7+_@X6OI^d@ #Kl`AH($'Ao2sw*^&lE]'B"Z8rM0v`Ly{_dyω_q}S1TD,Ah+=G[ 1W}D Vۡ(硹n;'JLϡ7BI]CįBm~Jx?*VoqE;#.8D5 HBs0MHOhҐJe .$/ 3@e !2i 8~";)q>UQ@I+G1cTU=R|=ӝƵkmsM%bLS6 )̂PwR'Hɒ~FѱyMw_Sf >˂/~Щ Ƶ=d:./QBf#l?ѩ>,1fG"n"2p#6Qeb?Rٝ oO/eدh4 vQ0 B^m[l1ъ>W43<3zhEDD 7Op1E4@Ovďo6eX>'}8C5ߦpe1b\\᳓<։s~ 7+ܳ+.FP39zunz.'IOVnqCbbԕa]gdH%൐n][B OX(, N k[ZFx ھu@@6 :Ó)I!fdAVpK^!Zp*@k} D#k)V( H(N)yZVk{cE6u62<loU8\. @&i-蟵 oms#'>˗W…K9ֱtD[](2u{ݾô!z`-D}GA+ӛ-#p#_ OiU}ϔVǻ=?b]G$:҃y,RozaIښ0Y (.ڽuI1I!=ʑӱ.][a"Q^,k:v׮u,H%@˥vLjDpJA,̃x{ʰ,T?k%ДUP|E9ؓRQ2x%1dv:xas 8Uo*+'a0IWEɥKҾX髑K4la]ʒW|rEut$ Kܞa]/oAVmth$Xa0YY3'4 i& 尜FVݟ^DH]E2~qlj`ճя]tx5`8Bo-H!]<1C = L )GjCPf %Z8l @O#~U՜K YorཛfQIX׻x/=Ѻp gεR<2cI)zL;@kǙF!Æ9ϛ1 a b>na?7wC/*(ê(̟X|WtnkqW ɇ[ik !rVNZfnD7FM^0M}6ZL6mM3iNVr_𧼱 :NUpzr(*>Ἤ1^)4A6wWvWVڻwWsŋъT\<Erf(?9{$ J MM`s0ؤJI` Q{0 {tRZk JkWV$t>H R_a z-ց.1nxaHknbMђc&k"*y|SV -CX/Fk&/vgf4ߪQ6=W1rv>=qjȹ!z/H4Xp" d , M.h -dV)B3 X(DJ2[H x'*A5ѐYNs{4ڄ(O_7&Jf͊JUUz˕rB& ]֎?{ MjOw5?BY 7 jr} _o}p$BՅTf#~,DET)ZP=%zXﰫݕv UmbN'h-4ًiaunKYњ{< gic$!ajM7Yr!ٵ16MO!ؙ Ԃ5ǰ)^Vz7jDNKSc]s>]ǟ!]d3xzsJ+ ^(sG43/SyF2Ax}~Υ\|>3>)"@r@f1Ԣ!gZ(YL墱M=ͅ%h~x6Kd8wpQ%%iras%zTf|kM4un*6c\^cK Db#6~ds{D&Μ)"pc2j8ϣ0\|*Ap<4j|=ժw 4e{5xE0{X@8Ć̉A6_>˨Y}EQM:CRnP2ьNEmvx,H1u8[{8}Kfjf"IhHU;B*ŦUj^MlXp!2D$a ]VֵiK,$ĤR[j0 V1LOSGDC֞C#W2K.]oѳ7؀ WBiJ0vt9z?=[ش Et! ܔ\IG# ![GËx]Phƥ R_Nsz<^$Dg*}(x1 ;y]R`t|m;2C\gڱ`3ä wIc#n> 2D{޳xL8=*g3}yu%\ ym z~W_U~o’!oMS| W>^+<hm=^`qE{fE^ؾ~AH1x3rd?Qз ЄFHpGN*pIrE,209""Cd/?_[CrL&YحeiHqµ_sSVyم=^$oȺ%F#=*7m0 Fl8_&=vi:= 㪝]mԵV/R/kkRkPE|،P㍴%8hfu!o|i%ҜN9g 2 'Ƚ ݃d@8`TU;zUAR޵!͟Y;ՃZK(-*#*z*a!mO EA\*nft1Ĝ7eݝ[/o"/ʼn{ԟ@ƍ33L6֪|>뗀NL4$@(D"C|QwMHd81J;"t/gD55>1bfW)}N>j7t +]ћ:)s1{?',+1\| 'Ny%Gl^ԁa'_ҫC'2z3-O8O/aTl.ʹn>,KM63uF*F$Li@T)Ld,-^8UE\Ih695/W*6(Nؤ(WCuYηսGUZOӻ1h{ߑ RA-([[WX{t"8La,`PȮ jESfފÀ}o_e`{ 2/^"@BQ(@e[iMlc'3wG+r'b5w-*nO b5}DdJPD4 NK9(u I:fjnK\¨x0q2)?y(8jE.eI $UJE=vNQޚ'a -jJbWnn-$,xP P'!^ Q^v1WRzdѲQuS2k92aQH@@[p/d6gP'D8p.fm+Tb-%d84*ի |)p՘ V"2# U׾dˁM"ޫ4)ci1, J FvS"5ןœ6ŸEAx:IDYLhA[ 9O`Gўẗ̶]H׸! @dB˲r5BNHU=ynS^砹H̥=$:LAh@z-oL }T/K7"X 3"wP.kTEL ڌ,JC!22 giEjLI1D`^G&4ʆ6^Ϙ`G;bf@>Wj)akD1C\%0$H$A«c%h՘o6z|8@ Rdf*"*5,\kص`i5 &03ˁScẰ55zJeAp2wt9ۘ^A L q\_*}vէ{h@"*) lhs>:fN\@rP+@1*hѝT'v+87AUʯvn)Ť XfPĴ&a,%,i;0~jhzFYdhRn)zL 1TSK7Ffi1Q$q푕SyL%HkSյ=vwL<\iXfRGp41طɔD vJlW_2D"a~qt>nh༵l7$/7->{MC3{*iVd-b)0lu1yF8I Tqy@T8 ]9!!jʿjd1L?pNQɩWe{;N֤Xxa-)i` 6fVgbteE,Cs|&G$+okX)\C( Mx4Ŋ91Rʡ7W^GUҍ!w<֯(9. @*\RGڨrF10U)e{W7Gw=<cd<)*"JzKoOs6`Ђ,`Ĥj}w]bϮkKx LC1})WdX`}Ζ󦂧y,v/|jxM~ajcc[ 2lS⇶ qF(dx~>NoyǾ2d2y嶼K[E2,+[lmך;_\|eݷwR.EhĄ3 ,[1 A^3Ԇ°ğh5EڹX.nk)1Mz7zšhLkSHs*Xq=?VDj,YlI@1Lgx^r d ]^f_w+e= {_g,v6~sI~aw:b9DoIPP1=$Z;Ub괃Q vYc!Cx@yMYğ^rnbBωD$T#m2<L.%AEpffF{yBo#NOp|1 ya*]e;m;.t%ڠ MQse|z5 %԰^EWޝ(nA!!G!zTDƞ?fRlms`M1ڿ}?%hQOCU%fJD/y|d75\ߢm_%$Z)b-džf Cpj9]HDDN}ƪ.8sNNjr$cߒaP k7nNidI:9tӒIٰdsUue熻Й436 dWJbf 3@H]5}y\׊@k$:D9>Ⱥ;䁇0Njҥ([Ă[s t0e>Jb%ȧa t51l$p1kcB2[f fNU!<z"4ԑ0q\v|ܛ̓N7^z-==4Gb*NEB):kf%1/#f8V-M!lV8%Us\EY-3aCgO޿lGѬx=Dtn͖-wPεi}aWO6c$Ha%$Jr3-n3#7kEZ.\&pZDkw,LtlF0W<אC0M-K ] sl}$w/zR)"!nǗ !A%(i11i`UkH1#hO+W[<-%?j"sGt^PGIz%Am Bdċ8<^g+:mvӞ^^Hzk dVyf봺0i2G> + USrR2Zg|m`p NLKI&C}']B>Ae$O(jFԦnKtz6+Ն.͢IT܏hɠڧ:eQyb+f=۩|pIN֝7:k*-V kI;nDI\RBC~ ̅Rsq,hF[wYS @Ql0oB$?u(aՊ)KB@j,HQ 0pJmw˃G.N܁P#sE"YQ>8|;}Z$4N7^㗏6o5l:6=c&?  Na^ۘ>ͱ_ Ȏl"ƈǟoV%HzOo6#kl@uI~Tx6(%*0)bD92Yr gJ!'v=bYe^Iap[>ViNdwgyZ@>m=0c{?~8IiZ ml#j &J);Q.N16\)،.;%H6]8=pOZ ]7T,/<'&Kk,Ew: ~cO.&s}Pq5~f6IUBUv>=猷Ā҄Β-W=n{Hl.VJ&ǎ@P.?U+8V@xzyy DTWҳd7:FpGM]EuK /VTȪ_A#'7MA$o})ùDkdWFIqV:CgM4B$6ꎳ&cah+Wm*a,Qݤ\(7&^fıh*U$yR ہPo1.2k8A yzwݧ)lY0{ jV)Åb64_&F)v{ӻ#*\t9ubb$ -lG!^Gw L#nb; G<++`1)JB 0@39˼ζâ֐dhOUAf95{Pџ#p'hedHVuaA}/x~p|7&iV|2\Fߺ|!\>zNpf.pOZ?&Gޡ='~<`(uJiOት?|_{|0`צl?yƧ |HKJ}eA{zYdXBs0:؜N#P#/y-]3{{8(=43z۾ c<º!_è+Q:NsF! V ?JZܟǴPfonzo7FZgCRm\9(B˶]fduZ`Fe֊)Tv`XnT Vz&c /9'3KPC 3̠$*'(=N2t`RP*F'vk]{=oWsђw=1C?ab-W3*RTlPBi6$ZZ) Cu)`:`0=v0C*R E7%c`:_q Q^پ,z<2۔HfH¶*KO|,ΥrK)퟾&6 ^ךHBvIFiNglpV' y8d0Ihy vVԙXyrm甘m*tct%!H ,ʯNO/-جKl)zi// ~ПuIpiQ*A@c@ٕ0&#A |A"x+PfPU;`^ R!h/!kIDU2'r 5x+;X3Cޅntι4迟<HT5GBC4^K8!-RI3D?8It'VC׻ܽ;6ژc n:NC~ HL #(daתg_%iqH2:&`¬brMїB 9wF)%⎲AݝJ L(Ac$(\[0?$t ڕ];1B)lHX$HVKnUFO+CJo1s-)'@T|̍9A2GI֩ϵͅZ#\㺻/}{Q#  ck4݇ P9ld )ʵmӝ5:Uz a%\x޺vjiԐ1[V'[^tv7bGra1hk w2pbQԹ+k/^zՔOw3746IҼkyAvw9 _Hq>Cial1L'K0b󻝥ˆ m>wqQx@\("qXP#<۬T%!bYa$Ex3ճ<`uwצS!3xXCqSB&=5+TUOMxm}2=n6}11ʿ>Jeב}xYu:0"`m P0x$xBX|.TG|_E?~~ _8|uc̿z)L2yzVdU0 IbbCk6m"YZG^rHCµ'<~ֳd-~-'@ڤ9e kK]iɝ9/ ״gݗ>a׼Zn^Ci$@@t%p;Wt{nX5ֳ`JǰO=M7<#OB\u1GI$u@!#RMZvҘ0;NRw+kƬTa{kyX)kD DI "^^K?0@HcP rpC;:?~=:g !uq3g Ϲcu6)ӫ`g/BG>^Kп'̡M6i>C>{âJ׌_ew(7+A*5;p[%sS ?IT64Eà|WZb z?K9isPMز]7AWVΒ?wbf_EֈRVҕV5EG/,׼T7/yu_Ctn׾IabӝP'~v ibJĨH8ZÇCU+TO .kz ɄUHǛmYCɗg\BQްpk ##n>-1r;fPKj~ DR4#dfw_r.{v!m] EZ[ X4jb&86ڹii`Tc=LaP'fȺm^f Q]Z^p8}m6ͺ߿jg:> uPiQ˜%bӼk2ps. ߠj~5ڬ;~oZutP;uw>H}0?G=/g[Sd4Q(t^vꏰ-'6%hYo5e^b1ޒsqV=4LL*% A]"fZDjZ!h+<=/=W\gْtrv=kVb$}%1 3ćGh=7IsDKy|KBfJ9٣ζmu"cB`o AV>5I 5i /L`"2z: #^O %V;EJz^d$pi ``$2{HZ7d6XkѴ--!X+,fOxkiB;o!"AA)u$D ކӎ2d̟lqS'QeL\p, {Sis(H̎ h9H:1LmZt<&8}IRS%S3kǂd HɇWHjrXGQ+r5'>Kt$1ěOCѸr`w3@̤3GQ$_\Ъ&[Ś=ɵG1R"P pf ɥ{v9e87X[ b1 $ lP6K Ks޾-GZ3M7tk2 jeEoNCT %:i87[-A"̱ljӫTR4A)"|E$ 3p3Hc`tFVN[׿,([L##qON 1x,lQDl_2L8HrȠ! ʍdU$#xgH 6,/$Ph. g3 '_9n"> ϓlMVRV6 M=D3P@tZi"3!gF,C+:g@;IBV C $lj)E:h8AT.FL5؊$=phgT2#m,K0@?W*k8ؑrub|'Z 1I$>&oP꿋ĨOL,;n/?S꧇V']RN \Y|RG6ܫU\"$OM^]ȇ qm\6;.e ΜdǔKQzNtZͳ8tw6"a(ɤTHϫ ,#Ocw'|u23G"j<)`T 0X#"\k NV~^BR,z5G%*]M'!H$*d8ͮ~Tw64W.{6܆savcMk~Xj&j%oA'S0m><ρTP뚸JDZ J5qaAAˉ0 x?$o[a]N)q{zе҂Zb$+Ҁo!Gb$\iپg<@w.'S3z#ڋǧlIJBq5طs$o+pw^jW-+; QB%b{ J;ɳV vB[IyzFвajOFտк@]j]yL&I1?PעIk>.ags72"RAqK{) ؑvJ#R@ %n?`h|+ku?Rd "HCRe kgJR(Zwz?yoTpoDŽ Ži = f˿^y!W.9L@LTWwOOKzA{SeaA6QZ Y*4啶r*3#yp3CvV`DrpǀX}0zD -Q#/t0N2,ʝ{9vexf!@Qm6[^_ܾ, BUik>[î?mMkT7."`EKZz X(b=;p<}6Iɀ~vRID\S#\"&*9S[nP yZBsMHT. 셁n85]~jMS EJK̢lՍk96}Gv|D![aT1VĩgWײHf P|\9iǓ= CMj^ |$b #`#T/ HXޜS!58Ir^L06jm c4>+: +E%u*Li7 qfCHuт!!b=Kh<; A=YF|NSbsnZP ́b;@+pkD{("$C~cd@"IdM8 AMp=lO!䈷i-eM^!fJY3 RGYn+ݮ,98SgUS]^d*R@03M$,= ׽Q|I z)$I9dDAol;Tm=VN~!}El "8O "(,_N-a_wT.*&%=QT[ֆBl -lpMEhz-#9 '31r f Ė8'O z$^يKL0.L#atc<͍p9Bӳhb4@0^8AFx;zw4MϿh:I*3yOۜLcNx B11gDX%;|6HSUcl j4 5yUw{a>LXO@0qHw=wࡩr;`x]¦(3")WZP>Ib$djBI@3xlIJv6q!<@'Ƴ`c%!HU7%Bu+32-$FWB"o* ~o&(y`Q-1ma| fc|ٵxj(n8.lkJAJ^[̍6uoh㿲Hb-I '?)uT j ɻpƫquS='DTpD!#0kGO6d" ,ږ q=)(wWMS`dW9No 4N9ZWzߟ{NdJ*i_*Iu뙘!08&D1\]: Wdl|6I5񚲽ĥNl^A+ԮPP˗_ֳ L_~۴(8d@ }&Wmnɰ4ăH)ÃqkBim/}p^Vz J3fo֒T5Y͊,;a׆oM*)2IN33& 0d Q*L_#unh8:`Q6(bDD%]VZ& FYfx5YH!0Dq,$Pf$ji0S|GKC}ېd67w)1N,*uJbTp1Q<$`NLU3bb"# s%Qay}2( <;<<,ed !A;2ʓ9?wkfbY&,,$@{n3:p<<ߵ5K`"MV- lP@Kk=z#B`K ٓՕ$'4G>v(ۘta;:5T$=+QÄ^tiouIi$rؑGr36fLgmb]sYr.h{2>v!Tpd<=ф>p6Ai%X)V{RW29R̈-T7ȱ_N[_8>qm!`Ϛ)/ڔ׻`Iqy a(Qh\4^vtmz,e빦 S,F"q|D @-/0z5;{ͬ61Ql^4CX$e\!oT1Ul%nd9fKuk]9.[H`B&9g&LAVAOtLS&{̉{dqicɞSy%'Q>*j֛Gee929 \N18R=ZdTsaZ\Y!*5H=nc6 yH{&(WG):7 6l 9 ɌolMX5 ;x”S b&!LɓvMXCFq('+og2P40MVO]; ><`6eꩤ9m$#J)Ts͟*8`X9O*f. <G6xԕ{gdT;߶Ӝe&S4ralv{ˍ5,.4H$z:uv(H'SRA ¥ L}"h(E^}z6͔ݽA89L9HT+߆@3*o>>9*QWHC찬<{Plٛ\,Ld~z£B@ȋ"t"}vj*Dž2DbۊeV ﭸ! Tj.N <)hK- S4X3„ĘvH ij1fatjZt)N0og<\zL?q$JG{/tt_AmoǒF'3 m+8?i[pJC'A F)v:麟![˦ȋV)Az!v9\}!h-2EC5 ,P7T8ҀfIOuQLDpf.z6tJ/4lFC;9vG@ ߯~ (_;g^:fZ8)D@ H#bg#Sؒ;&X|+Vx'~?yM;̈ -LH!jiԸ_Z9Gh˔j/h }⸥{,Ço2=E!U*c(HAj=dύ& r154Hד(g Lx,sN MѝF' /E8bxTI'Eg+Tfh=Aq+ҶUiG(j`aK*L@ɔ>LŞ4/ORYŰ7O68|+xvݣ oFۊu:*w6ɥu6 m&vSM޺o N*)61D LGpRԀ7`=#LCv??wgUM ~ "77H(F-1mE">\;{Tbazk~#$47+yi]bܡP`vz_Tz|A-3Tft!"z΃E6^KH՚~õ{{>\d m? %&t*O" ~)NPpJU+)Jq $_Rffjƀs c<f͝zdO@I茇P$6wew`$aT1n#A-E~#aAz^26) A"c?QnE$2Skg9c .Іr~6Z3 sX[iq!bp֨,{\{ &n[sw"wB:*q6K96 C @͓aD:cZcAcI 2[1ޟqB=͸ս)6uVCbk CaL9ݐ1Y:JTjvMLh*j~AGKFw E%iJH`4-0p64d-#%pPd# Q>B&Sg~uF`4iO&6E9O .c0v>/3mg*;a3Ha1/\*ˠS΍fusZos}ZBB9>8cmFς%@((X2 Q)lA53ݑߌ6ч|]P%Ki3ҁR: PST/W2*TvU1we%Y ;NC<]"FcD~Կ{E)tkct;;s-)jGÞšAd3H H"zjKxG@s@3 ;QX8-+جxYc44nIYf +~ƟT鱽f`?=#}əNVxAoؙfJͦ}ׄ# ngt1dⴶe(b5o8{ ^U]?ķjW*oΚ|G-t,n>yM|)4H`Ty? ؐ"8 21Z-;d@i '_:^cd3.QR{V @s`_Ѣ.] m;@]l/p_F_p\^a65"~!@~@VSLKs1kٟe3;c\s_${ x#;P($mLRfzf3β]_X^ᾊ[WMёwޯ647 q0l8vo?Ls̀ gR9js b}yRH$dlPw?JP{,짼:VهNF8幃4wv_oS"n9@#=9pU&A v]©L7qrZS,f.t뀲_bwaꐤ@j:`FhUv'9IjlS$emlwL+ޕt C/٦O~;KI=/;r38n%dRJ`L1ȅ(؁J:01g;<3^IR)8N5 l$о LV,Rz Qx6!T>M^/ :՛UL: tKk<|f@۹|BlX&u}>2_?hV@Wnu%p^I67QF{ۤ[ǣuJpza!19aqs}L>"zgJ;|#cZϫA"a$JyjJ53jZ`mMUw^^Ey.fҲӈ}{k_G(/UkQa,ܡgGs۠Ӯ+/^ۥ褳{T -D[C'g [}zv(!HdV7ƭ͗s$_^vn{#`톇(xKEaB 0}$Py7Bl>NhE]fs^{v2>o[|9{|xHɌb. /ʥ 7Gi{ `[HhƼ"8%QEu*Ddyy_ b8w$x2T"9mE=-}j2;Ep phdۓHΎq?ճ{F4^MQTD$sih*JΤ#YnĽݘ\@Uv;-rx lu1Ώ ޳p~6ƍVD dtyGVϋetGPVwxă Lm~CiF ) ܽM3E(qm'קn\}X&ON|ѠVB.5GH;;qvn05D;_ӈ]lFrA4V첅il>C{'o R}V#o-}mqSr+[Sٗ]w'vYIcCtKB@h"""/EhУmq~iFRaU=}S :_D_/XjAE Jrs H *,ld;Ӷ֡{L ?Goyl*8&/t nC 8D\ ^V鮸Bq@lǙyWFn8+jf*\ߎ{퇫 ׯ|Jg7xHa_jPAp0ȔQ\-:uSU.) .>V<->pt[1Rvñ{CPχ_mSa!yg+V&;+ޢ}ueSqNoxK}cwV':_61n1@3 "!qv{(^L!# ڦ($@D  "Qd$(۱AURǰ6tz^^q{zW\%wHP]Q?4ی,$$@v-$ݲWMF܄_f£k?N%C:'iQ4҈tӈ[}vQU9=.pj06~5ڣ*g\mL3 <0J) {8kGsfh'g]`\4/T( B8Z_a{-<#\TC|n vĄ8@N`1@+.;Cfኳch-N7 ^[w߽0sM[6:ۘ|@sZ*אָ_y߫׋}B#Nja F|9d2\}_o>f\s2'ݮC=B-,eq0DԤ"("R]4Ѓ=Ox,<69,~o ut/opRx9"%! p'QRqI @ ~KEo~8˗mڿf[o«/N%IcAF{ϣRϪ\yִdouE)g+^xv I΋k꬟~Kvd?۽q'3[ 6r'B ˰=ڒen'!4U;)M Ir%ԧwM?ؾkuΌGg]gĭ|ŷYٯYe( "1}K~FCd_OOKv{prCB=pR~H$(&>߭elhԁV<@`BpQ爛?i AdB Bڄ Pd}$$B}K!!!Ok_I}TP_\ݨT'wqbt b3yXie457N{ƼL1Hu?nwҝN0Xsr7o\NIv2Ij3_cwL@rzǠ;ϛ?z/hM.Əa'1%fGf']~ ~C9<.]o_kM ٍ8 }W;̭.q&IQ1Cg?:Mb$MN*z?c[Jc.%GSeL %.'A<%%8`(kO"^ߝ~b ~0s9‡]ږC߲r?`=2ZnLoyE0|j;tzNLf@[n03Tw R(^K5CQ̎&ω"Cl "7UTňbOݖ&XPo3O2ӳu-ܹ0 ,>rӨeGaI% bBcxsp,?bGE{E70g^TT"G԰&.X&0UCwag\ tr*b1BQqz0 v҄Qx]x$֐av@M$em# IZx3V?L)A$NƒsṎ<wq1kk}]i/jD:=G%{GU]O͒v;KZt4ߌy]&l;zM=Z7AKC-M#n&Ƕu)\K߷z;oźWTXbp}u/qsN0ӗ^;`n&06~N;tUqnW^9Q`|U3f*Wko`joXr~ 1Ãlalʼ p8MGv 3mWMnhz o79d^J]Peû! /SֱIH]Y]gu X9l;##!TDO?OWhZ~x5f=cV q̕<pw~ˠuW b .ܲpC1VˬS+u9cj{Ǭ&nM<c@"pTƈMw[$clz1:0k0@ʚԞzJLIG&OȗYi$| -s0J=ԝ$-$1#g*ʕuzܹ9됖5 8t9}I_1a3CvkDtbkj%( gpb)z|oB)k;WrްN62&%򚽷+++M-40a-|kDپ)')s dϰ ^[SB$T3(6uxjG]·S)9H].߾}v^)Nkإʾ%5ami3'52{fWLFBC # Ks#([ܠؘKǁKs'xϣ]UƍHHDTƕG[OXYhf?fxLMe!+ wZB)w;"nQR6#ƃ6^glCz#C|n]j56 O8=̊^E4v냙̙tp.#p=;!]5[t5bWkIH:&5ʔ_s~p>dvq\ XEQKlNz"F"I/.DA: dΠA& \;[#HL]Km`=M!w*}~sf"-7gӒHaT;H ސMigUPdkduef7sc,~pO&Xݤ@.X Ei'Ye^|癸 `,#FDA*paB@B~!|~b0JO+%9HsHP I6׎_ r^uC%tn%> R " α:6iDpV9K_(#Z[_li}tJifRiK3y{,oζ6$Vs!_C$lh6٪0"!x3=֜Sc{-'^ HƜШm C$(|އI=nC&v@KY$U TXTI1m$]TcRa%be"Y,d'6\$v  ;=JyK'hHåR'hWA'n68aBaQհR&T['u7u722W1seN{ĜHI^n0 5E[Ӏ5V>b{ cNr y~$Ns::o ~y'`cm>H 0 ZU؈3Gg$k4OiPR:YH)peޘnݘ3/8٧Zr~?/R68m8]}H:153%:1#SX&^Y~W>>WDrRD2܀l7ҏĉ0kzg?_ؚ'Ql땵;kD Eюh/l|BVO~6߭"'Pd0k:sYFZ^ku2P\EvJF;c$)NX !}aW RB)^-66l Sjw? ;SEJ)'?Wؐ]T.J7N/ߖ:KK%'&L Jږ՛+ŋe:p)(wȽ fc$ŋ o,"18$Sa+"e-ԯ`:7r|yoyX*|?qojz[nm{sPv#ۃ]PZ1@ ^M쌈#@}8x&½\]#'kVm7P]{IF͖ӗjPcZ=lxra3?n 6`eʻ-/! J=ʫ#6!=D.&9|㽜of"",^{ǁLiP<[/w b®UڝRDLHn`mC9^fӳ{V ved#ɧqdY2)yQM? @_ï)LG]r8(js],%[Ô*)qtL$C}پ00>"mhuڊM16+19-3sFRo`-s_: 6'J@yT!!-9w'kdtm2mH@`5Uuk CoKF$J<#Wpy:jTeJiZ LGHCq#\s([L ,Guf8SIOdv}/Z(^S3aY;H+ z'\1ӏTx|2bJAWRco<vN ^U~n:0y#Ԟ:(^ pˋ_W[rXelXZ ,CMbw7Ǯ}Qk# tP&FR:pS_b^#xѲR-0>f9D g`\tIg-)k =mێK,yY~$٨W3Ƣ"AF;5o_ `@@k#wpy ݴT'^<~,Z}2,A^^H ~AM Ô3"ciȂ~q! Ca /ZBV0KKswgzU% WdHр%x qӪCpEKP ]n =?+{) X;F1A7;KmbW>;Kta;~nM˳_"_2f˙B eprAg}O/D|g3;MUeFBmF) 5C=}>O4d*E=,ȴqWQ٭[sx6| rύűU7Ac"ۜ dm_;͏Q [}M.lܪ½ȬLTBjsBchYŕO-Te.c"*)n HWQwa6R-M{oṉˌ֝1N%1:` /X5%Zk ^:ǝ7/ }4h>I[}Il] t͟pJ\է kb{ط}?4ɾ&Y/f8ʟ̷ϡw+D\ @?WDx[sGa?OOKmw6";2o,ߝ2|;-Shb^稒CY,@8L1#__~'];`֧PՌ*ߞ^RD3A;In{ґi+«P>M/hT{c0XĿOBJf웶jqh\#Kt ,%r8d&gd+xЬ7/ Ӿ׻D@D҂rF O?0dhHrb r B@)QD QJSb_]x[}ZOVmd zqU^s;m޽]lMɚ?g]Sk\om篫|ygt zqmHȕ?M{jWwI/ZA PA7=]LZ~Rq)j ;&ZC p,dK % k|72(t&yBָiwKf*JU*rRi۪wG //p%jjPPyRXvZS~LcW1o1"J/=E>gC?)J_؁jwW\aΰZ9[ OVr :8 ?wl{H*ty[cTڅ: F94|9"~)t,>}UYUl-q9܇*+&/{W?w"%>ȳN+r7^g_NYߞ:??fay賫[m+{+?y+oZ[Oa4prƑ׸* 3PMcP]֖BG sXm(5P z<sY6%Q{< !.Ru  BX([~aU``f8X`l ' e0,ɗ_N vyAI? B+A05̕SvC/m6N.lth;G6u;SOչ廡#˔n 0ӳ]I,7mȣxsݗ3v^!-h;xVvۺM7&KUM(:@  "+Wf~HDDDlVWQ=v'uis7~@r!_ﰒ{ áreEcD˔))zӊd/~" Zw_XU^֎81l`H9ҭo|@'.}.#NdgjԤ$,QqU#l.hcA; \/<\џs< %2 ) "A8^+\[}96Th8eB騷(Zrw$ p<8Aj ( rD? Ő'2)ix|~C2QaW^x*g\屟V#p.cQH0J/L˾S< f̺Ae@Z;*5'=hz<;=ůwuZzHu0s_@К o .l畾.=ةxl\dHsI)U\\T!\s8Mb'|-wbNCـO \!~/8Jngj?fSX;V˄\ը)7k3i*.w/RkvʟV%%\xkt3ZF;i^U:gksuu*%4sA]_r& `r I|f۽*~<^#a2_ nz}^|}XZ /O (]>-QWRm/}س #mXͶ?[b1`"1""2s2 U`őVE ?})~ ]G]JkŀGɆwt*8oxC4-Z,XjLqF&UX h^:.Ѽl0+/A4iX CYo]j~?J4= OƯU z4/:kǎ0 ]ETdҔHX$@KZ>0s\ƭ/gĸT^x!DLF MJU̦|cORe;99rq*c @EoM?_uv_z<$~qF@,!?\mB)GS ;j jbh#γG(%RouO-}_ U}ƟRJZ#g41H B}Urܪ@X̙gwRm^ "..=+ؔ$ I XxH!%fv*vi1gVIY(Y+}QZ-Je&D'0RN,X|(4B""I6pKAVu˅6Lg"pu Ѭٯo.Bߌ3DJ8KBX QDj5?rĸIbr\5+1%$l,Y4:0Q @q3?vm-^,+?n"_PXtG7p\uþ^He5"+"QgE~}5 IX8?(yFbD5EL<[x73D}fOk ;4Un=Wܿ3% t;Ɠ-ԠtV}J /!/WOt枬!^ZçƷmCJLlGyg4 Eqvw>&bR+7۫ٓU%є98, X,X(lN(&1HIAʱ_P{'8?( xХ5MU?_GT=_{og`ʩRmf/#ՇaE1- Sf>!\+i=[Xtb'C3vH ץL[A'\ YPzـ"^5`^N[$СH JZH 4_*SCߒ 1 vȅƀ%/CE#G;%,©):D):aU#lĥ;8Hmgw2߽a\Nn[WƵn`K4ιu)2H ~>mq{*l,K!.v ГYg3ad4i[dY_r=Ց,̈^aL=eJ#.4@ *O}ؒW# ?J ojRЁ#>M>Gwcj5/[C!-0m;< ş;6^r!܎`Cxr;HMp@ бz+ѵaf^ﴋi;zI. ĉ82ky8cl5G;J5F5jTh#ew~R2 au_7YO I4D G3(yFPSA/hI"0h ZA.&kK33PrXnm_(ϣ8m".vM0t@4 Ju>wh㱧wʀ:OUEUc%rf6eGsWd|OMϹI8g:69nS{|?_ ۝H^nԘ5`i} QUJ(Q&0[<'`s}~?M7o[vxxGB/b$`}Tkx C8x4g^oT ']?ϫ skzߝ Aa]oN:JKp#ҽ4mƬKvd#~kWy[3>=4g93+=v{a땻֮R|Jm/^H;:|^r^}7ǽ8A~2gӰK5ߥ=>defx10#wV<]g5zOVZZ;~3a?fT^/(MWerVf~nkwE iP@`*/w];+R"O'àNfII/6SrN@*k/)6Usߓ]QOCow K h:R'@ OKCa5O DU*.dA[cE^gQg.ϐ {5zr $| HeŰ{= Zi~]ܣm $R5漗~[\^V۠UyMd9ucﴀZ)A$Vj:ޘ(.Ȱ1FEL@DQt'fb* F {ǚ|K?i~nQ;4zH"0ɥwT-DDY/CXb,ɏ&vo u۳8(3-IX\ C]8@j Ooz\5ź=P=BQAY0 Qt9ˠcYJ ԁ+RD$yXJ?ΞOW' "}Da LUdT$q#{YI G(J?R NXq$xT8PCi r)tN;Q3R1A(&t&Vݯ<6=*9x F)YyH9l@Ti%}gр8NYMXng} ʛqm} [N\N_@pCѲpt8LphB 7poߢ`@L l!!/jV)V9C kPŴk>#>сM C篦lVc(=;K!cޔM(Infxܝ8#hXY"G: qvlGy|܈ʗleB\0 u't8$rnA}j3oc[ג>_{MTI 7S^/k%;t޹"f B ֩Q+'̬`1b6jF@{Li27/@&Eab_\@s L@x bwZ.(=(Ґ$*CqwߜA$9E`x6[2zn۶ BJwTJ>g9*$1;Eo/4F`"D6;^ Zzo8yHm94vo@͛h᪥go4' 7u3G5^eٌf.+¢!.3ۡAN29Crld"3r  3z7O~CW-;!>/0gKqv 3kY'^Seb,AI fy g$O;qWn)m {>e kc?qx^7C?QuRkU }/7]O~#ˎr\Y1|!v'X?'%91xxrLu/Zښwrf7=.&>mh=\!g5oQ&}e4R}c^=׺'LТ@GߢvT5|7S%rg5sy5ֽluiN7\z^L"󯿏33[h疟E~^USVWݥ/bpUv<;5'WIj.iS[`kmNGõy7usZM1T=~mW|K+6ԟM_ ~u]wRKYw{_Mn~;Nzf@!!2H0!'4(lrJ- :w/:v! ϕ>^vBX,cVvtwe5 ݟG{ouV#5wCA=N-i'flҕ*[J[{{ޝٵM7{|cί2[ҝ^ݼq{}}f 8]`kQ|`uXUzgS\4!1h4a)S1?hzuh4mkt6=]shu79]I6m2}k*=D31)?[֫"̢GD!IZA)Mxϕyd{ w,ӾkD7(8~Zڥ{j&B5hdA¦?4< wr{b^1U5Ԩ,Thܠk0a7oeoG+$>&{u- /LTU?(@dlHUWFP(sVF!BܙW";3Sa/%c4PsFߙKD#(7Uz̮]4d 8645)poa/?h\hIǒ4z0,@ "( !Aa'tXC Y JFHIkR%';BbM\;EGLMK;v6Ob n6͸& !'gZ1M|,!;q"g|n j.^ r@gx٦^..z'}4p`R-ձB2yz#Znj.׵Ab.%!C98eqxҴsa" &D @$ $Z!Jҕ(#H--(ЌdKH(7QԱD_9eVuۏrx:Mm?' P|G 8 44`{F^sFq>II 8JGh p"='7vfx1#"y] EMm[P##WvOx08MlU䦞՛ԄA ݷ_Y|1O%glFx Nh!bX.]i̠֒av4AVd fqRk2Yp'#j:%sL{;W.HJ B# ,& Q{P,z騡g"[giTx`cB-Q4 } ԦjiY,YYs_O{mof+'|ټkC3 !=9x(e d2ܕ[ૺϩ~{#֤XEE$B m*jغQs:蜃Mt:≏;n3:]%ΖbuFFˢ']][[j-Dr'1_,ihVaE%+]kc26A‘ma\*M`:<@D$ddd(A@mB-kv1 2PXE2.ט\uFKRݍfk/uYKZ j"%RGu _}QDas` N> ߾ϒGYU2̜ŔZy=u w7Xɉ7d-yewuqt:sSNʒ}k.Z c!Ff o4PQ6Kr&J2q~Mh͸SSy]ϗ D9,v$3k^ $3>[>S#U@<N ysx"`RɎ +F)#1s.#p6uȊpqP)%͙O=A$IVE28/>aSVS=Tx,qܻht:DkڥCD|VNYD3T̷C#ӲĹyuگ_<,: _.YBk8 ħ` ;tWGf##UUɀc;5+0:c}ylWECX*wes_\ X1 RRNhTh@Q: HB$M&aHhΡ'm&%IB@iD%RYcMo$k9 r RM9 U\vu]RCe<Qpʜbs@bZ8lxPFlB$[E5kD~PDLC$O[,f ^HCBYFiLD1դbi1;5 s0&f-0D5fE '\gdPvFځjr͍D6 WLQ I$ NZo tٴ!IsD^ 6sD b׮.I\]\BQr<;V$$ A9S\ÄHY%Vx$$b 4]?H#=3n˲ClͬBS@D0SpWhڲ]a8ǚFi$`S` Ǔ(VBi Bݠ9i@Ӥ #tdƙ2 N3bdrdyQ>ȵd[7qI,&)j@)aԐCp,a4H''N#T@ P]X𙍶wZ ޻ A'w;-pttq3-PD1 pdzr5'ih2&(I.M.,jܒ\ 0Yd+UBd =EL Ix#Kc,4(n:]f,H-]kN Q,HV)rde=gL $g8kb<@8mhPUASڦbkZrYn &.$Lbц1E7(݄z;׈. U8_"m t غl%o3M'8S<3\) lM{ӵF17o[r jGz8D:h:He0 Y2> VkEr )xZV<n{SY"H0A[Ap@F@kDy@лao/t^2"ol\OL쮯!oj׽(] .rEN{eD9"2?{ex@/ED_Į; 8-`W; ݭhb!T({lUPDZx'ANfM=MnZt)訅CW(`P}d@8QQSyz(i,wj꠿n(>ˆCR %vt@8UՀ_׉! (!2gwEu=l7= ~C@?@9 *o>U Uy-;l6i17kfH-_fs.zdǔ(BDoK9ɰS {VL7;p|K@筍n^3} >6(4tquζM$z)S>(4E*ws-%o*D9 I$ԛ^JaF1jy|\v [up^+B ID !i7P@G;nu,)$A,( wo%A]V袦(J o@fQ/R"@ئ:TqXu2ÆbX dXU33"{:a;w5fм42ޭ\:Qu9 ͎ul65WZ,srb҇ 000;}ٲ״Y`u~k812򮚺W1`>?VԳ4T҄eXBV\ggP0cS X9Yu2jv~ zpVC:pÏ[F< ] *^G&TF"`H*2-bz訽U\@ҊJ C$@ (mUǩ@Lq%((B Iuk GH^nvq8[?F;FF^vI4 ]",@KcX01Ȱh $Ojaf΃55 VU,Id=X`a j_4+ߝ/Ln?qN|%a+ոH0rLR$6F݋;y-?~lvl*˚Az YrіaƪC0=G.01g3܃6~|Zc fvCţGYQú_\cE"^ 7bmxr{,ktu)ƭ;39w[p: \;gt@n@1wBzLWSEvO] ,*|v$}u:ldZ&+zAD55њÐ?-77% $"{ͿJ 1;TCUE<,o3 т+3d  'ӡ7q=_ՕO'z/EEN7SC9qN V g|FV RJ!!hCL^ A,唓I.{cMq0t; Y}ٽ<[t2STVѐG\`^v4N}sgS̜ǯcdTlXJ!1=B6 E9|Xk~=X_a*&nQ~ė8GRXr#'g(\ f]$\!x!t=7?YZ|7f06)-|F]>_3I&2nJRT]<[E@[@] &["'sȥ8*m%IJ\&:tٗ6+8) aX'aܜPۼh$Cيmru]U=!{WJ`#̟7 of4r=.6(S?ܾڵu_'`=&dr)'7um ^X7ok"!/a}.S,.䈼?Olov㢜uϦu n @n"ObX};Qrof`6 t #7;6>Zÿ_AHĜ/%Wk{gl}_yKgyA&O.2+߇x6LL rJuMO & I:EO4_LQ8˲m~q致W>-.Ӈeؾw7dG5P}eNlWbg ̓bljQmIeLrX7КFZˡQaeD  ~s*p!{U~ҋdCa!k^LN0Wm"˩ދ 8Q9"(3K;&ξ "|)+$JGx`E\y$LIF@ԪQ>++1ͳ!4OWhExpE>4 `dX m./̎YB]i\N\8Ie^u}.OC!E65+H6" 4QՀoL0E0ŷeX[BOm\9 Ú{d]g 5& FiYxyD6 ~JdPšC2![ZeCWgl47}+\kֆoLp=/ڇ82KOB zgX;5go]&Jm@T2U'L[u*j3PH,5];mޮpqfy7l(9a__ nvHg7H{G:hDlku1a?|ųMb{,uKOA=|Ae3B ]̣ IL2$I(HWIR+ z'\c#mol6ͪ<uSnۜosA#m{m#~V"^YY; V||)tъj1Cm4<{2ק W`t6SbfO=YfJ-,J8}mD>TP>@<~JltS2'td>'.wz`3q5+xmv>fDŽC<"E6< f:T򖆜|A -r߈sp c;Wrgt'\ n))IlCqd7FVL 3pۻJje.OJ|ƄJ +zr[fOK'b U!}&oa:⃺*=|]E JQ>,mIB 6i~Vkl"@DeϷ7$mk\ԋY%`{/?5fKa+3}6"h<'ޒiP1թS>ߓ6\?bxt6?k6COo_T:kpif{o yؘ.)e+9R"5(`A"CſwHb,a(+ɸנ&itLLgP+zvkWr 7;7DFJ5iՌ[3[@~&zijϏ^#cIϽ]薌'+f~$ i C7;WdA_9RhD Ǝi ό/0joy>qy6LUcI5ҫCL ߞyՔ8ԑ7l]QM0l̅MtzN5PS @rgS\G,-ލg d#@ٹxױ5hlR߶+Omw̨],Js,l."1 ԙLd kg$)M9HJ,;_^9y}'kfn~4ci@+DTk[Ek&:2#̸FrLXJW8;\"SILoǹ(g}Iv{xx(-]t ɍokScZ`Р>vQӨFdO ^L\<`Û#kۻg"Iu=*;*nVj;7|5\g{zZxݗ̩i7sm+ȼSpN`my3-"H@-y_Ʀ|G5tWlYqm {,|Ajhd1];` !ťssrpKMVCXߏÏH!ۜ9EأzRkG]0qo*2҈"޵QVu)>sy=*08e1uzHui9םm6cĞX+5H-zUhqjv{62֗c,)?mw>KYWN ^ 0b\cҎXCPun{Xe]8pԻK@W^":Wu9UkaFN0;O[@9bHt3h9^ח04`ZE@\UP#i8Fߨ {%%FΠRl9=`v}Kj9q \\Ixv2.p!ru4!6 Gyj3RUZ]5tDCzu~Dn>{ujZvUù˗5VL<3xg8;kl؊ [Q.p\vN̎ "@N!e~B 3hkHk*LN3xiOk9 u Fg3Q^hC*"A=E|.kU9:+]#UdźpWxi^ZCH'G}\4J{RՄ]Qo:L_ ̕O?+oL\zb)>.nO7y dz“^spLʼnBPke"z99Qg<'>ǰy[b_~^b9F sCʘםSɮ] eMI k-Y!-_NPǿHѷufus}D^Ŵ mIp0M&47 ~3.4dX(9SPۚX`БI4GATu' 9Ӑ~SfjXT1{m'hi%JI迌p}5?3l"o;m~W{WWL*MӋLAQx[_eI|KYIT0ȥP0: >kҦ ^y8'* m,:S4a.i![s{Φ~%S!WWܣAW B`]gۖml}zy0+XP)YWoSQ,3NA;{Dm낺D|,W r)-Y$oUo64}hJh =3'ilن@Θy>`ˆY%3ƳLbr` $UGоrvaKtx]]zNVn "u#Q.dۈx9Y\voR3@ R3plӭvs9 S< <Vz b V4{{*ZJĠA^gռ$^-IM!>1@9\VtRSk|_x94@?DL;>`(\ktiY$s)„Z+(LZ Z Z Z Z Z Z Z Z Z Z Z Z Z Z Z Z Z Z !aB Rڏ&^S;Ķ YZ