samba-python3-4.17.12+git.455.b299ac1e60-150500.3.20.1<>,}ep9|7\ޭe;  K /S/PAT:J  Tv*\I =FE߰2'gɩ'cWed22st;]2fUWd_ゃ(c @@K3Z=S_a6v@J'qiLXcWB/ iZ0jy{G-*=w&ə8F"=F4$ɽ:'d  {k[Kρ՟?&N@ZC䗦X>>D?4d+ 9 Q6G ]z|   X 4  L(K8T9θ:mFEGEHLISXU\YUd\U]\^|bcd8e=f@lBuTv0MwxypYz0Csamba-python34.17.12+git.455.b299ac1e60150500.3.20.1Samba Python3 librariesThe samba-python3 package contains the Python libraries needed by programs that use SMB, RPC and other Samba provided protocols in Python3 programs.eh03-ch2aI SUSE Linux Enterprise 15SUSE LLC GPL-3.0-or-laterhttps://www.suse.com/Development/Libraries/Pythonhttps://www.samba.org/linuxx86_642ZK h [:9h {0bP.0%x  VM@̸ +p~`ph@;Xex ݀>1(Xq`M@-kp +8;OOIhSFpOlA V[Rt2%P" 2#[0 g l m 2'^o , :í,n0-W6M[$%D9k`J:&@dykg%4Q[ N@9/?$Il]P_((  ə_hH/K0fL(-y' >(f!0 H`d`a3li/lL)  _ u Muw  mM ;I| Xe 1 j~@ C oyn (qQ_/9/T} y3Imk(< ;.#} # J0iB|5 l6& >L*c!T3:k*},L h /g#OufK2 F :Y * P W6" = 9dS1Y/b@ h,a LR?T]u t4w*m! 1 q,1tb2~}ZFUg*4>^m > #o4Ke%- "# Nu4gf<hP((A큤큤큤A큤큤A큤큤A큤A큤A큤큤A큤큤A큤A큤큤A큤큤큤큤큤A큤A큤A큤A큤A큤A큤A큤A큤A큤큤ee|;eeee|;e|;e|;eee|;ee|;eeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee|;e|;e|;e|;e|;eeee|;e|;e|;e|;ee|;ee|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;ee|;e|;e|;e|;e|;e|;e|;e|;e|;ee|;e|;e|;e|;e|;e|;ee|;e|;e|;e|;ee|;e|;e|;e|;e|;e|;e|;e|;ee|;e|;e|;e|;e|;eeeee|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;eeeeee|;e|;e|;e|;ee|;ee|;ee|;ee|;eeeeee|;e|;e|;ee|;ee|;ee|;e|;e|;ee|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;ee|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;ee|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;ee|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;ee|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;ee|;e|;e|;e|;e|;ee|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;ee|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;e|;ee|;ee1faab3af1f03904ab8e5f7852bffc718d5ae41f68782b683031f38cce0c32bf153915aee79357a35b758533ac619c3ba03202342fd1479e0beb2e5f716a2bd4eec4e8ec87a6f3bd0fe74ecab148939e9d1ca8f5a44a35d22abc44083b28a7a1cb9ba5af355bd58efc1fed978132328394259a13183d1bbae15130538b6e2553419e9d92759626841cecfd01337290e88042bf069806240af00101bc87c6d341e6bc217b7c780069d67e788f6de57ddff5077d323b8982ec6d40d325cc92587b2309332cb72e2cc1d2b994d9facd9b2dd66fc4f8def7b703b6ca5381f7dd0538fb4cdd2c37be542e48b7c44e1d25f6f6e88cddd6a95043e0230db5d516573afa33efec96d78caf4ea9143580730509738faf6569891706214c05fd33ee0490c39cc6b586e9f760f7ad00cd52967488542494e6b228b7d588bb0798707181b9821f844f9bf230f2c7a1406b80da7a8582911d16ba8954a50190c1a3faa47bd4b094433665cd6558716a3a955dd069bd7cfb7b18841779742699494356cd8c46eb1425dc96ed6728026875fda328a4e01101291d60e5ab9b0bdb62fd3ad89b251f63e8c5d161f6cc57fcd2e671bcc8d759d00fd1ebf8aa8d3799ecf5281f6f82bacd48b991ce21604b55e3ffdbf6f5c81a3392191db1162f6d3fcb404dabdb1da3bf11a9403464b9dd0fb8ee70143d8e13318ad5522586c6833ad83e26dea750f70edd2fcc287cf627f353b1e6f718f9afbb39ddd20a447664b262cb9c59d9ba1fec0c222c3fdaf93ac68a81fd30b7129ee21c02fc138311bc3466f6cbf5f82998d6dd99483f80d71ef8142cf6322117b78de6589f8b6910220a182dce72d4fcea3e82d632e97f9815301e42b4385ed694de88803241de0417dca8825fd1488bd153dd6685a48c94c0235ddf1aea9be323391b4a7c78831f6c946bbf9bfc914783b1104d787330e68865a53da5a391965b7199874906679a514e7c9cc0b85e3257e34be72f4c1607ec475c463733e1880f72b01454914ac7fc73391e4b92cf8e1b5cc8f58af36924f214c648f75211c1327df362301166ba89063a54ec6a586749f66c74cf8d4df4aee12b933b8ee1357a1ba2a0271d907672233d7af03ac58a06fbb0dc243179b445684d69ec3cbbf50148ccc38fa8daa123e6ece6fdab434dcd436ebac12d96287dcc8178ab81fe7915dab8d28a2ca6251c1794f052b2e0abfd54c616815b86cd0ee4d8c930dd8b83651edb4406e6066dc4ef4edc43f21e6dd448fe58c77dd0048686473d55e36362f1848418874b2c82bdf95931bd1f71fc6c580c512b955e56ab9278313a063d681a1641c08eb3ed2c3ae7fea949e986474c710887971fe566af5cf703cd184355fd65d19a8dde54e071c98ef9cd320b43ca0df4b81423dbcc2b8d4ac216a3043f8da8d8ad77500ad00681aff36324f66763e21cdeb9c37719ee848f39a8f783dbae33576572bc9d3970b40051d5ecd5d5fc92a98012c5464074cb3aeac8166aa6ac5cd2fc58eb251670b1e453a213f257ee7eafbdd1bd0b4fcd552a52b0f5dd2fa8b662eb06a20d06e1e85ce0e3a19ad236fd66e96c119a5d9e76482a6ff2cc9d092e4979c379c13db838d421dc7123a7c5399c1db5aafc2e8f7c4cec285d7eb7ea429df37086db6f749a322d56d8e70a0a4b587d79ff9cfcf0e09072b374c50c3b770ad81a512ebec297c7cdaa93ea05760b55e6b92f9703f9896c44893d83746e3648f40921612ac9ddf1f80b46cd3a739cb44d60396b9ee309fb70b0484c247835251bdfd7efacec5d058127e25e7fe79892389d5847a933d4884075d4253ecb6733b89406a1307ee3786ea6e4e73b7ad036eee5837fe7ad28ec702e5edbd830ce66804fe079cd9c1e79330875a91fbaff7ca26e6ffb2f5b12adc3c0101b43737bc5bd25f13a4f1e432a7b9b18961d1924cb948f9be815b70ca83dfdce3a0d82755ae90a7431ef18a1b39213b1204a49f61d1e37a9c6d6a65cb87ee5e911154fbe8a0488c459f81d1d98fc9bcf585a610bc607f231ace164fbe78f99a41f4c5c071cc389a0690744769d22c0668aedda98f62fe1a0593032fd19f2b8e468bbf89a8818b3f2f8056258aa63ba0d417d384ee6b79ed6efe00eef2115423940235c83ab3e81f37fe268212d22896e635deac5dfd62cacc63713c07c716f218c0606fd6c798f54ffc34adad9f6facf7b812d5c21f02dcab12b5a720335c48a7d2efda9ce678c6224db73d1bf9002a1168c34e00f1b542302e7c5d7ae77fce27a03d0a4b84f26e336dd22e3e9b78ddc57af12239e657d7da6b88b35bee755de12906204caa2f359bf9ab72739018d767eaad476eb8c34a762e6fbcc36ecc82cfcc915f2d8277c8eb6884180b88ed69e991a86f554684c5b0533e4062d60f12cbcee378a39da2439bf7b67d71c0b9c71cc3f066bf4f6988ddb5e7fe14f83046fc815ee33bc58e27c2341dd2aeaa5b9dff71ae86bd728e5db087be54d01a8b58de5e036ca1f4502937f4043cef3f14ea2dda03b220d5ff09aeab5252bf0a9b5a08fb9bef44a74a35b60ec623fc3f9556c3dae1fe56707e488b410c00a029f8023bb60cffdab1b24dfae8f291b3a78aef719c825a634c38e03cbcb97d794333c1792307958aa0ae38787d2b1fc972a539f767a87d135bbe5d34fc0cf8535955f6f8369fa7ac6876e3c0118aa45c90af4c4235c0cd5876cea496ec5761faa1921d5ac3acef08e36b7d3159848a225d3d5510cf795d71c7c317756200be72cb0aa5f448a51b2bb37c826b9708cda876eaec733112ff31c935fb2bf6fdb1b1c761348801336927c931013de98e713293a003413e9b82757cf8df6093e121ab13c74af494478016e162f2b73d63e398d2635a52cec947910a48ad49484185f9d05382ec4516f3ac709c0999774cc53991af7e9cc3658dfe77cbf324ddda5eef8123c10368b08266d353916e7e6bab880dddb2ea1f89086df72ce690a11b5c801d4fe9285d581506acfde9b5892f5ca4871c703bd8b68f1abacbdf9d63be9cc7f51bd51092c8829f9b59d0371ffad52d486679c877ded7956385ebf506edecbd08da745248c8835f635b52333089f3de2cd2bc2f39a0856a8cd2b0c127f8c80f6c866a0779da0fd88f1bd33138eb0c81b7caaa7e14d794b9c0dbe3a19b4ce6b8fec6b9408d71751d3dc5a016c35009eb2495bce704087d2fc4e4efb010cd3624189126e05810105d643be07aec720816168727eb5a355c0ab42f066fdda2a59f88960a1c3c4a35ba459c3af041e3d390557f9c5201992d146f6ffc33da0f7c970ba21418fc44bd0d8ff13d2aefc19fb9264d6fc52cd6599960f2b6ce2b708862225a11bea439e250acbcd4cdf416768d4ffcdade553357d39ce0f902a714afcddf1cc36d38f25be3567c8e873ab687b952c257a90cf255a1f62efb57fa7927ec3b5e6ccd2cde90a2527ce01af56ab684dc589f12debc5800b5444a4cc8b85c9b31f14072c4e9619eb9372fe5ccdcf4fd18a89206e100bc0ef63df369d1387bf2b5ce01d38c0c59c9711aa08f71e54394dc025a613d04bdd431e674c8c94c726c32fbf1b536c6486d413f45da38b9a4f1678f48ea16c0ee56a0e7fe78e7744a5ff931dc9960f76788a57ae8e7c6950cc2e3a8c18ed57f1724a590045a23ef40e91c1624b4c17985182924b47a4e70f93ae5d4c8944b4ae4d0a3ec46f2b425e14fa94d4677890f61abea880a284fd51f2f408471788ef88ad5844cc22275204c1185ae27c4e047fa70e9681f957844e91318ae4b5784ad860646f23af619fd1d8e576730ee4bb31acc03758e4b52c7ed65e42f849c21c5d35cd623414b4fabd12336096c73286b67577e544a6e7f31fa34187bb4f5d7fdd9c06c7e6a38e6806c1477cd5815980539f454a145cc934157da785eafde78d1db4f46df342f00b77f9d36ed2032fc132cd37c5aba723083758059ad3f3468b273732bc698200bfba9983c1c54cef2d5019951b81e18d3df56cd4b131ef442d8b3c7302b1969f071318245b0ab9c5e115218ce0d958834ce402a7c83cb1241cee4e1dd4d8b4b9ca49f4d3376c75d0020f030d84b8d70cb682df82eddda8d6e758ea80758151f484a9ff7ad363452695282f4e94181c70443de3baa29ae995ee1217aae859aa11f2621eefb15945345c768c16534538796db750278ab069338d27ba3c57bab8d6bcb612750b6f79a9336e709ad10ad09c4f1eeb9594a897f9d218e686163d7a152e3eb5a10d3bb546e96c3873cf47b22ebde3083b6824ea55dad126d1abc647a936176c653650830b369479abbc3ecf8ca319b072cae196a09e3d37af9d88a5a53d3cf5512a8f7494e1ed074f35de5e8b58d5a07d881d1be0114dff3271b4b865a88503a42d65eb9ab63f257f37671211858456eb5911c22b4be402edd00df8c448c3830dc2aa758ffc4227def1cbaf2006a9686a7168e13c553eaee0027ef85757d60490c48d02898c2d843f1f169cccaaea3343a2096eeda0ca28919532990f2017738b36a1db9a199716fce28091d9b64abbe1f325fabbff84d087dd8ec05f81415c40056716ae0a29625fdd31e8e4d896f7bab19422bf6fa7984cd9d7c03d87711eb06898d104d3f16681f0c68b3b037bad5f3822cf52bf41f5a20740877bc4667723b59c42ef2a36a34b8140090bd26e853add8461d23e4acfe4e05a9ed4f65f6f00427cbb6cdc29a0dd6b86726308de84a4fd030d747ea2e40e32ab25d0e081f9b42d651522dc0cb5bd63f979be2c2089823aa0ac90b11e29fdbff24ddf41e025a8bf04bccc68cafef20538073c59a4f20a7760924fca0f3454e5a1d39d74c7ca88267743ffbfb96826aab7514d63dfffe811d6ffa30bf3dcf2bc4679bf2cd82123985bfc3e364052bb31bb16250ce3d0729292f6ebbb291b6fc09ebf9e02518c97b322a61059ed000432986ba8763528d21aeb45cd71d0c269fe82a92dca4c12e6ee6feee7ed09a71ef3a223746f3c4bfc3d4debc1601bb9fee9b5342324fa0a70dbb56d6d3e5051393b8ff70a5f51c4b13b337eff69acbac85f2c950dcd1eeec0a3ad039e801a5fddb65d09853e38d4e8c03852ad6e16e67f965c4a8121e80b3b65a77fdd91690ed5b84dca6ca357d5cf8fec67508f931f9901269c143b009a61c968bb25f333f9a96a61b8bb3891e1652697c73c97555b5b0e34dc660b868272c664af4e9c9d292a304d640450496f7f31c2a2c63fd936952e7b94353316aa2d1c8ec5a84b6e4b2b3f866b1960b75109b966375a8ecdb885727b85cf684587314ac75e2df7cc3162bed143494df566d7ecb2a735587ccf8c5204adc2c6c0d8ebfb0db9dd35d60ef4df42d516faaf8bd0a2e2f081bff556dc964120ca70e116213406e6728e4155f81a6b2f4eb48c3b95766bd188f8acfce20998cff66d17bbb7ebc6c708b18720175ae49b916adf0f9dd698f903e4ded151a69968cf69643c547e89d4cbe61ac8082e66dc090ef6b5e219497d42369fd0cc80c321f381b4f7231f811e98b14eecd2a07ac791527d137465780ffcdfc7f574a0f4476c84fb07ad0debe06bc075a15d078b4d221d92f91df337d626ccffee03ef046e3b57dc3a0735b01ab8975f1b7fcd0098f1716296c6e3eaabd51ce20ada718596050139dca5b2593eb73abdb51758dd71f433459bacf9dec1d515aee5a3fb57df714791311d65870ba601fa3136edc1eb82cfe36cf431a8deb3b1d1e62209380ab52886a28b0cd066f7d5f7fadef0e2f00354eb41e0d3a106b3e0dc55a737f05c159928dc530be299cbb35c7f6f4ec48a673b8ed55c4c9524f7ade107ee73678afc9804507d7681e0d3ee81536c4b4bb97b0245a428fb9fd7aeac1786652d3eca7933735489e09c9abcaefee3199a2a11d62211d7f8dc784c0e3b009fcf99cb1b910d5bd4f16d98efe4f2f3773d5c4feded77bdb8277eaf67af1f06db08af0205f76c98a0682f44a3fb50b7779072a343b16b7a17ef2e55cce5c0da9bff204c49ad683405908d471a5bf62c2101a839cb700fc3e7dd458aebcb17ea342b592f78d9ad20554fa2ba49378ff4938fa7842a1d333c3a9c9efd423eb808e796d20ce8f056fb77f25186d64097cc77833a52eb43b1e4fc8655d136fe50b7e74194c52fa507d40d3c6a2c0477680128a0e3739c96ea5439135fdc0647c04081239faedec255bd3451988744413d8b901cd9f51a265fdaa4bee83c92c3255c5f4edcd8abaf83573a1c7de2bca6a37c4b912c0548d8a0ef82ecd00dec698fc6b43bd7a7427d1d93c1df41c8c1eca2bc108728c3e451b7a49fcdcbbbafa06f895d9927b1d3c795ecb51546ad14f8cd7d35b73360d753759e6c245b22a88b95356efaf5ccd3ab0359312541fb7793f98dff9c59bdaeba2a62aff62919db7904e86e6f4c01630e5ce2bc716de1a1d8e507b23bdfb6ed95224aa8948f427a91cb0c9153359cd8b7538ff0345c0a7038a5490d84f1bde346efea586287af16a4e50e5ae2c4f3f9d8be184b70dd1d615b81c88e45a2c63c5576f980a589aeba939b8b9a491757fcdb73f4894e1063b93c9c6765ad1285b2067b60da2e983bb6ccbe282f3bbea301a381857b1d730f2d96f5bfd5bcf69900721bd073c2b4744a9c7bf82c263475a31f721a37248c5f6ff4a2a9c5c72b32dc1ef13a21829e06694ac29961f10106218c7eedcdea214d33b1c608f706453a04b5bc791a51a8be2b4c0851c438740f9075fcb3fc1e0c40dfd474ed6ed0327e8cdf2a146eb371f35b2553c24e9f059f78959f9050916f1d634adbf72ad125a367e5921c0ca95cb0be3dfabc38dc606bad253e7853c5ed374b9e869eeddd9ce5888ca4ec7138a8e38d3ecf0772db7c1d15cef97e12bf0cad6690403e17636d642dddf18b787c40823257605c9c7ce698b02c6a51e8e64e1a41cfa83b0b8053712f983af64507007486de78cd6c64dfdeb1fa2acffb6cb027970e45bee3cf18f14b1f94110247ebb4aa15f434668716fd141c9fc1fc3afa0defedd42099f81c58e79cf9d4f9b7ab39ffd09615af018810b85d591615970abdc92d7e6542ca868ca00b15251b6ff5cf7e3b134d2c01991cd2777964194090ccb10b0ba7ccd34e22f247336c28e6e11665cb87b7a82a98a745585d1a497421806062bc9483270b9cf64d5019a0f040d22c2045d772c4dd0c6f6ee14ded7cb9e51da3806b82440cf44ff5704c7d6796b1d2b6acde656fe2b762e06350a4b36b8d2a0caa92d9bc6464ccc18e04628b21fb140a654d141f142e61fa1c8f19414bbfc84703041ad7411af919e5c3b632e4499b1d39374fa3e8d87c2c725e5d2c620cff12cc8413d4f6d9511c3c33342663fce893e05a446bc1d2cedaedc2eae081aeac3c4fe50b15dd0079d5bcd953c655c526de11051e7d73da3db74fe5e32638c0b08ef0d20817f67b9b24e7702987aa2aea5f71fc02711273ef07c6807d6db28473f1770e19408e6617ef4de4717f9559e4889dac921c55bc9e0bbbee60fef1021d1e413c6303be6160ba752f227cebb85fd11be1e3d1ad1c526dbd4e6c0678353cd11f9a8d74206e7f82bd4d155b4e9176c7a5c18d2544a616cfb116770051fea5a835e2aed6d4e64b95978bc277407f6c8d9c7a013459a4304f52726f72a4137b24bcab4cafcfaa12f3ea601e33823019995271a2769b9124650b4756141f65269c88d75f1c406dfb5b2d51180af3ccaf53d02c1ca3e0a058d4c8d1eef975ceae2b5e84a9bedc7ebd34ba48d21bcd5feb931c9246d7d8b1f82eaa42a7233606f92f803e46a98cdec926d3d460904e2a079656b16f339a1ac0b4464397f7c9b80a36479307cbd3a6efacfa638f496d809ece5c188084891ca840faabf14fe36a6eb93514b194120f914481507bd305de3fca6e4b44e036c0c7291834da1c51a5ba486f081d5f5698c12f0ed0700e1f5c6faa5287a8f618756dcf95f24eda1f90cf22c3cd5e0de93951a73e46a0b76cf39f54ceecaf4154eb4f73023b7442d5dfabf0aa84e105fb8260083eaf13b01edd881aff0916260c70721df6d79a7d2e937cb9f2b247747d11839639169d1b2a4ae3f0977719c24f58c22901209346442eb6bdd4736cc051f7c3388ef948692949ad826012ab01d13d94b42154be3f3553e924bc1f8152d582602b397e8b578b5dc3c877a1cff552537ca1854c5f917c9315c59648821a82284c74a916e39a54ebdf72bee024245aca192ace2debe243991e3d6e557fe748e66009cba79370b0ad15de50674b371292d540be97c22d7d97984b23b737c3ae23ba82610b6f03f1917b0a9122003f7676723466c64627cfa47894178291c2410d67555e8a9738afa81c265bf6c4c068160084a63623b9ce7fb5cf5f89ee6ce59756eddd28547c5f2f7c4a2a2cf7b5cccf95f4406cb4244caf8de83c6cbd44a21c1e3e3c1c16b967b165f1da12d7b7626b4f67c4cf8fcac36c935bdda8ebf274fd8822c0090d8821c62ba957b4d0ac0deac619f9fad734630c5441e4c456dcd9957cada9a77aee9b4ecf0d441469afcb733b7ed5197927aeeac9af2e36d92c32f6511b3ae916b6f50459ffc707eea667bc49be94869fa451f9eeb808aeb321bf93a9f5e900d9556026dc0715606446bccfe1e154d3056b35ed0fdb8ac865e83fe70f2a7c829c53fef0691cdf95691de97420836c8664745ef7257a6d76e9967a493301a868b0b6f6a299dee8087310fe575a326fcae8564c74006532c7e041b0517e176b20a57c4dad2ff5208e8a06dc1e9d3cbb1724fb78283a0cf73c1a9318f59feb257c1610f363c3f3bdd0410aff9e9bb212884ee4b3e6f2cd352e103a0a2836d2d4c354ccd3cdb4cef59d6f294d7b59c1f1b64104795daecbd7ebed4c57c7992e7b21a388d3e067621000dda2e5a11e9a1f6675f54f930e26bc2bb5d265a5841201c6c9aab15681f540537c388131994244da3b29029f2f0e08008fce9ea56357e39d174a41669ded277a6374d9176d06f65d69e9b469ec813096ef6ef2873f206a8a4a5463dc35c1385d1562a644080a1392387d652e5e104375211a5197f4fb7cd0a592549c7c2ebc72647bff137081c9d21ef0feaf1e114120f67942037eb7aa78a97500b5548272804b6ce2c54d7f29abb4d492b515ca3cb8d15d16d478f67a331a29547c9b76674f07c2c6e6c361774f60191c69622972e727bc4280c1b8877fcfdaa1bb682179b4b7fed6a93aa6fca8410a4ac5cadbfc158698b1d8b02719e5f33fa58e35c414e3925385105104ef22ac7b1f8242f143c4909e494f74581112b4c48232ef4750d1d4468a482fb35902090d771152a4fe163bdf6e8eb735ff54ec5c265b0efb7fa9249eda84b5da534437424dd503156cb28d84731d3eba97bcc49f95d3b16dd884abb38fcae0f2e9cc4d6c2e060133950827fe50f48d2d17aa8d873e13d9344c929d309b4d89a9970ba8b95f80092e77216f86d1d2ef101e04d26d53b4f28976e0f5c11d97dd7a053ca024553aa321842e3dac34c9c0be1149fae9207233dfe5fadb65e3cdffd149b2d97b0fdd7da1a614c5169f51ae2ba8030d0f96b45e1720586dbc7f0ac3781099e12511018f411b7bcc8527f3a64179c971d212f9c6ed6568e99b6d736de3752b20ce75b4f0dac7438f1619cbbb117a6d0ba80996833d8d516c845789de8543390e6b72b2d86f93485c398fa8cf4f771bb8b05c3afb853f171f6c0b71ab43adf18437a549a719b4902e7d41da0fc30af8c30a5e60cf0027e5202c1afdbf93073e4e4fcf2a1efdffa214ee06c2fdcf60c021eb2245e2a89ded1e9a4f3ce7d3f252b5193694306ba7e57e0e2dd43287e10a57f632de2cef9530fb74313f68e82c99fa762874c69dec87ad7acc6fee2f6bb969942bc7926f3815c14914d06a4df2c9b90f4aa813b0a3e8dee5d86be400f62a1d5080371fa6d3f5a60e644ed799dcfa06c2b99f9bbea9b18c40140aaf2a71b1db2e2c02842645c62238d54212babd66081519a4b2862e580d4718902c2d873442ea204c1905bddc1181c441573bbb5d6f528d778d33c1bc91f885e44eae10357ea700f0a976d9a79735bd9bd5c16bd2441119e6389f676d3444b8c298349785ee82720c348b9e05529e0b989cc7e7dd3e3061a4ce5a49a5a55abfd097bd9c49e37681cef60b00719713b24b588eea1d663b9a9742982287588f2ce4ee2e113359a6902ecf932a880fabc4eb84533ed614f88caf909a9747b02917a825abb506605100090046cc523b8168ead782a1d9ce607ec5f2e3aa6b62325d052fc2cfba0f94858802ae3caf3c1810723ef14d815ef5bbf9caa4275e1bffddc3b9765e61347972afa69b38e2566dc7b1fdd54eacf0d62ba586957149befe2405d2d0548a8439f2c2b033b1a7e649aba3487ba8a2b51448c0b568ea9a80eaa3593c01b08af952a9ce1988341fc1ef79b24a726cc15b1b081e272459b2b989932de0734185fba613a990cea2636c260323253026cf60f57ee46e9f81e6b40d8ea13a81f4152b3ee3e0b01185cd6b3603299ea707958f549da2c4d11b6097f9461c06399d24ca613f459de66c910edda3523214cdece399b7532b10b48700f45aa7575a2e40b9c68107dfda8fd2c73765f2ed967478394b74bacb362414242f6c3b0223c95e49997ddff97de27be0e99aba38cd7d14dbcd16bca6c7686d08edb099c8167c3d0044eabab7273b9f2124a2e4b9458ef0ba2a33acecf110f12b21c537ca72435750fa67d8309e2899fb40e6ba0d5d6f66a499e0c3fe8d76ed763f71d6e40502381d104964d79d8b3fa2af3cd23d48f45f7460ff2d3b6f742bc88053f6f6435cbe734b73cd056fda565924ecaaffe486c7d71fe32d63a0efaae77015d49556406df6048c4f52ccc02c61a9e60a04846e0cc7f29a1bea1c184fb358657256fecf39bc23b8d049fdcaac62e44a6d8e1483d2a092b289000778f581f133d38a0079f6fe425f1172288b842caca62f1e8ca346a446cb2fd09534096672c2fb3f56d823e1e3c26eb49b9c7f407bc032c2ab1d0d63c02ed68e2d85f1bae9f5c5a306b5fc888a713a3d65a6369a13a68cb35e36cb825820d04a4bfe1684b30b75c3614cc33d3d2b04c5c7d0ad74810d1caf59eb258a1571b759f81227cdaf1890457cc4a20221d9521c533aa8fef5848a7e17f7e58266a56072c93c35a654e5666863a0cded0fc7aedb78bde4d68d40427fc229d1b0b5fde0d5f69719567716f281750793ac117d94b7ef5c2c961c82eb5c83c7ad37f2b627cffeb8e341bd16edb69de9a99a5dbd6ea9118eefcd41afb71242ff15b8336417d4eb889eb55a40e0da8f636b1ce4ea84a8e186721288296b8a4520ad1872469b6b6e0ef87c33cdbc9116aa6feadc6a63873ee73fbc193886962a2e3b14dc3bc63b27d319a9defe9191c1f831a15ff9193fa85df1212153227cbd817b4fe3cd14b4e556339edd8ef40bf8eb8cccfc52192cc87f39f608fad2cbc98df26e4ee2d746c05fccbd98c7dac6b4702a07ecef61a7907573f2abccc06b00eb294a162ec6c60eb0cc2b002d6a27889343edc0ba228b80ebe2f3f8d3257bac0591499261964c8ec4b44fef1fa63f6e4a31fad94b0e4622b33c295b15050c2b949572e1dbe70bbea5351499d89fc0a5ac6707c423e79177587a3e3d5e6a3a553b4629c7dde29011751174ea5643584b749ee1d87bb271774a96113d1233c01f82074e8fa9cb73d60b0206dab3167543c207996535db28b979bcaa8f8c722a84473ffe0dfa95f1d513b7a3389ea763028d0fb667e08a494496170d4c92f96abb56a331b2d7ad1607653f026c062b2cfa81746ddc40cd6873b8645dade8106c58dc30a7ddb5e8f68185b891af7e8d989544f0c808c034d92b7e3aa363a9473eef07ad3430ca2039675971da4cf4224167a35f748ba65d10dfcdb3fea031e561f12c10f3de00399205ee3ec57b5ac6dc15a052e5a9663af372d150f808e96834244469ff765ce6c21c80f4aabed96db36d4ced65d2d386af81f6b081fe5af5d522a45bd8e51e747a223de3e1a7b936d70297d4d502ceb81c66b17e57af500bb0922dfa5044cd5a9659279221ca897a52b25cfa953dd67381dc39e550a93166132edb1a5568d6c093dad28545b25bc0c5dcad80f0ef6b741a16de9474119a4c21bfdce770ed4dcc23b2a808fe9a1e2bc16bb08ac85bf4eea8f2d3de21db9ab5264f3875a239578fe3e6981ef14a24fac9e2e4240168abebd9679d0737db347fcc849465ebb0f34d62434f8ac17dd7909610385f709b87c2cc538010e774c604a5e8130a043ba5f715fce1f85eebcda3e23fe8713d6caae1b5e4641653ad58d929bb037be67e18b175dd07f4e3bc168e5dcc4ebb0ee02a270e1a593070e1501f196af8852ab6f31fe9e2d494b96bf787d9efc726888fdd3712831c2a7d86cd5a05b34097b2f83aa8bf83f22bd8f19baca99812f2043f1e189b33786f280a27165e42f55eb6f5ff944615deffee13c6746b324d953d78c0a62deeb8208bd5959f1bb0b141549e50cb652c05b744b212e75aea1ae793f48a2a6cb73b0c0966792879ec1dca1cfcf55410e1bb5e3fc321ca13d361dcf467cb1e9b4e312a35b53e6c108242d5f64a812e2aaab457647f22f7ae9c38220effdbe40df32a33abe3d2512a236ee6aae0c0db8fbe74cc8c33d520126c5efe2f15da5c617b8b4e459ddbbb26dccfe5d741360f0435d0c3f81144097ef14a4e386319334cc8571beb1e8d08310bfd08ac27b0ab2a97c62fba86df24449bad7f11f954c8953abfae0a5aa219fc085ea4f69e9064881f5f01567f0c2e804441a4b3ed8f48bcf5c95e6a9ddbe0f61b2aeeba621f1bb35ff16ab73c79b48af849c867b38852b05de2c301825bae1b654165f02b5356404bf76abf07c5669da33c1850a2a852c8a28960951c5cd39eb0902e429646f5d91a4790dd136af3fe9d3b6133dc13fe4102ac8dfab93d51e8b35a26cc34b62138729b1dcd6d64eb8baeda67b2305f794da6b70722c2025547c326d1034d6f59ecd56be56479be63dd0e95336261c5001a3c2178e9ed78795add1c20e9204689692a7744255c66cf0b32eb6db3fab89989cf1c7edb8d004116fd17cc149a4af16df9bd770b76d1cc67d06dc4dc367a22e781aac355a00bb347847f4af829c024523ed1896cbb976d4331b82811937afc712eb21cbf8ee97e7b4e9bb13e35123e83c45e8263ccd9e60095608b73a52d4434eb4a5a722521b75519bbb74bac55fdc0b7ed0a6cb99aeddb94d0c94fed7516585e4bc950cef1e3745fe74a5ea18bd2a0bdf7c16949f934c3725a27458192e2de779eb8069244950a1fefcd383ce65d5ad94756f2f5f74eb60513e6cc47a08d8bb14ed18605fac6bafec5887e8aa3e1dfb6e19e9a3a5e88be91b463ce078e514a9e968eec6f757813b6c930513e6092f83e81c476c79855f9fc08beb3cbfd79c9077ca94a96928ccb2f728fc1b91f54bb91b5bc25dbb890eadd534a5ff1129bd75e00b46881ebba5ad098bfbeeed108f5ff9a4d855b063c0b2af991745a4973469cd1696c4fdfeaf9aad4ffc9c1129b3df1724936006759412642dc4e59515b81b0648d80d1447aaab47581f43ca66dfeea43b5a537c1502b3a618a85d70dfe60cd8f26a436fb9a9692ff5038ad816ef24d91079fe57dce570915bf5f4a27d7ced5fedd5034cade22501ebe5675b9f520f5e927dcd686a7c8a940a298b310031338f8865763f80185dd796edd2e54b95068178239798fea2700bd1a5c891657c85e5f88cd738f37f6b7ea69ff05faf5ec7779fa9de0bf18596b361ea671aad8591352e2d81aa896f98afb9a801883404533e90388d07721974f600e1c0b41532ec62784097ffdeb719cb4c2e796942996c7e8d76d670a94f3082be1dd9ac7909e044d875006abb97c8abc01727298a8e77ed7005c50cfa1c6ce0489943571768afa27c23ee96907c6e8def439ea6807122aaea97ab1967a761581dc57aae59d548882db90ac9c13a49f80e1f75d2bfd12e495c66aff7d87992b228a359dbce1af211653d21d64640d57907ce7e34fbc636ba4bbbb692845c2da398297ac710a91c45c5b49068e530bb85bb67f47bab951a32cef005459e8bac3e22b5010bc96c8b9cc021a5c01bc42ede02d4de8ca1f49ebe86b9820059ab0ba581a2921b6bfc7c6e125fb5892f93552049775f15c7e05ed8b0724160c34a2f86cc7f0a7049ab0a7009d3b1f498ee22fccbc5cd45a5d39b13e120d69cc19cd47695766188ffd8a573085ce3bd6e95cd7b3d32dd362b3e649661829755c9ed529b72515df18539c9f8072fa7b045ca96bad662ab6c9ea28e908df87744356cbfe3caf0755c307b78e49282daa5012b2d2ad7e7ab2a37d456e3dc67269ef8b2131b32294ef2c617f88042068999cd5d99857adb7f514457028777e2fe325830dee9283287121b626d25766bc73e65feb03b1a9e88f1e6c2ebde3213f564c65dfd8fa7d8b41b4ed4699cd24719d2e7389d91d8589a2f98c25b7d1676448c4db8daee29f8387fda6764650c36187e1be4e950ba4278a51ecdad8f96823ceb884f42f071b977ad91fe8bc9662b906654e518ecc961e99895c14489cae70e8ed596fa682f405d180c843e255c2355ef59c4a7f7e9967c27dce8c9e0df439a7d05165f2e886d8ba83a8c19d07b57539b8363f98200c96c8d92daaecd927909edf120cb8493719f473081840a81b370e37e12c1d0788e9908fc2cecc19095b42e1d0226142523baa34b48f08347338152c1724205675704337ef2e1b4c4499a2706b64052c90dcdc672e722e3d845773f2389205e062d9192721584973d1008601898cec680b56ccefbce6ae91f05471e9eb6d749769f6834807a48980dcaaf5bfacd2203591ed2376189c909cd7db599633483e3e6238112062fed89b331bb14f59a97577c6d79270d268949a4b9b9d34da76d1aac9067cbd0f2080f3746e88ce982d8dda50872dd1a01fb66f96686cc4752f3939d2f8ee16b66801538afac62afc50fe5042e39bcae80341da7bac68734c59c7e5b20031671e2153a7832a08345973a48e44ee7f01d30c61c7e4a3d3a1e6cc14390ac381aae979a2dd2eac5efd02008f959c41cc104053a0a8967b8916214efc23154c7707cb9c40f626316efc4fac46cf65e83badf008490e908bf31376ddac136924ba8628c6f1b64ee211e19b6084710a5bde9edd760f31dd7f391848232b5ff4d8ab3c2c545113b0d71b7563b3e446f880251b6e23f3eeef40f79d9aa611bbaaa340bd855e159aec2fa4f0714edf76087242a0d6bfb26900bc677b163da39b43c2fd1a1e66ccf0856420139d1e3ef7c66024d58fe26288080d4e7ef8eef95670bd5e8c19ea476f36ae47d9e27f31038541c88bdb1ae52ce90deb8fe188e14dfd21b3cb28eebff223a0b71c0fbd3deeea90340f0cb3807a30eaf3950da888791e03ddf7e28f953756dfdd1eeed3079415baf22dca11c05451fb3dcd8f17ea9ca0fe54be98add4d216ffce80e814b19ec55ea5105d7e53665e1f4c16ece09dcc86fc6a0f7cb76b0ae1a7a16ff5c52d04f0b46177b7ec859fced6e8f2e1dccbcb62927c50db6ae717095f75c05e4b9425b116c528d42354af933d58d499ea85095ab08c9b4ad56dbf8f0aeb6bc2f46d958472bb6e8a470c53602925c20730602c5908c730f5f3bbb4edf325b5577fa07262b56f769a88a8f80f08f6446e5476672a46e5f8fe53c232e405ed8a117e0500d99807fb2fd6673b33747f481239b9ee6e0969b3b7db8edd589eddd602da90132e73d75b06cca8ee031a0bd69f02e9c9820de0d16ba8c22d06ca38e79a0ee5f339989a10a14c14dca52b179977a6037641031775a01144c3c20fc6c9afa30355c5ec7b4ffe7ba49d1c1d2561f30eeea21a4503055c0f47f3db4c752926e8c66d5e6f8b47ca352931f1c507f2a017250574d1dec61abbd8f4ebde70a4c9ecbe33d4e32e57976d30431d8b9108b8fb02a8b538e4139fac2f5893dc5d341e1785b397cf21330b8ef6f07beaf6998418ab430c8f22782633ae7030286c9bc8d8a4782e97f61891b0640697d3f4c1130f3e4bdfee2ba4fed7836478b752e6be6a346322016161a0b5d6ffb79fed353a074d1d9188d5aafbef16fd274858d1cdc58813b677117b0fb75bbed79374b7aa96a8eac22c3f6badf8481ea68b3c7a9805dcff3ef58651019b41a3bbc5c5f0446053ee72d00105c02f72bfc08bfc2c3765449d255850fdb921c1673b7f075ed327ef7995fb97d7ee1d92866ed0ac321a61b29442f203689ac02938a1a45ba49445e206993d2b9b19f2b960e52491f6d3fc956211b5838d1a5975a642d7db4223da81c9f3e61e03c8d48db6453cc7fcf1ca4524e5efeaf637370a7154468993e3f5d6a7659228eac82e78e3b37b4570b628db6f90e1f9077835f31a2e8c7ba7a9332e2cef0f22b3a0e25332b40ab6dd667ba88a92c1a5fa69961950aa81a3621a5e7ed077d5a2097101af09f5b77d1c6e472859349b4efd926f127087998c32e62eef092b70ba70c048c966c52183fee60894876edf6160e5842dc902798cc5e8905a938ba9326e6d8187f28769914795cffd782b360d674ef81d78958911cc6f84de5e8d73d50a943f6e58eca80d270a4aeaf8061251545dce049134e93571abf6be832f1e2ce92d33e0c1eaf855df4fdc96d8776edd80575ecd6e628a2305841c3b063109f80a8669c37b68862f8644cd02b6c502cd94d78a2d0deaf89f3109509834651edba1601d4196c1659df6fb4412111d6f9f6fe483f315c1aedde66c8b0e84a9c07b05f2fd517ee0f8d03a4c2543c16580abbbfb18efc854323f401c3edd273a9548bd7dc55c19d003d028801891248906f695a48e6c6d8ab375e05dfaaa8bbfe5fdca57e13c3694dabed9a89a684dcf3514867162ac0c870a4f3827b1a1f33884e6603c0773ba29476ceca90e37a1259fc7783ea79144cb7627793a5843523da390a587efaa05ae61ce4f8206862b20e233f0278dd8d0cdee3b01fd2de9ac70b380ec068f3b0642b1fe2327d7942ec2f5f800d83396534e4d720f72a2b94070ac175b29af3cde1ad28967925027b0b650b3e680aca0e27560a5303034d42154b7ebcbcd93e917e2576307b83b7443ac2c712042adbb5eb570140502c8f9a570bd393a0647893f84bbfabbe5c10392c41a31ca19bd02394d9d4d37bfd90d50a5b233b1aca2a37da1b9f7d36e89b8a06c2085830a7b53e7a45208c889a9906942d6ca870ec312e295f6922220cf13d6305a7834d6a5e2130b11b1f13390cc5b78344211e22069080feabda127c002e658153797d28f0008f339f8373f4481999eae398f89b609ddfb4ba1f11bfc341035bc0ef1694928f3996731c57bf62eb305b8e1e51a9d8430a359ed8166ee654793bede62afec421a45a7d5c7d8c9ae1e7ed08000d5c9aee13151a5ac6ccce52b34e3e88b463aeb1c22a971d0e0094e94c758b2e53d3c7d93bf48a3b9d6c1c84b9be3f905e08f4691727c7146644da6afb0f656240e1d1bd7fc898128172793694c8c4e4202af6a9fbbf84f4c308d84861e4a98a6552992b5744154f4eb911c98d02da314826ff057b0dd9d9a021bfc9836d087abe872cd33c5bfa0e399a735cc43663037c3ffc5786fcee0a1e50b6770295665657652c1a5026542f61e6c221977f5cdefb2a378c67aec260ecd34f62c1e2a9544e8a704a8caa5fd4c272a43b9531438bb2e740804aba2794ce8cadb6a31c04e44588b16eb6de016f75760a7d498e5a5e663f31ae00522aab96a34fd3a30e81d209ef283302c02a1f63de0c70817ffdab42bf3ebb02a2b7c9858de31b8171cac9e1e1fe6e8620ac93a0756c1269cefe5bd4fc8db85c21c4b69389a72f2ca28eb07455ca60a78c6711ab128ba527f1680aae0543679f82451e72449941ae263b762c524718c78bb6c0bd8889c7b87181e07a412679186c472b7cd37eaf462acd0fd531af02b89b1600f32c6f976a8d841f9b02104735f3e25594bd4abefa2e51ad2ce77b16aadd3c3053c8e395b570d9f66ed1f46e4a7a1615072c03c95bc9b7f6cb284767f9c0e0afa35f84ca7699c78e75309a0d22897a97c9784b7dcc2591c5f4b2cda4d92f441d758c1ea1834b1a18ca94474baaf41a18ba1491115c261002bb30e546d11b204900fb124b855ed77dd6dab5d989c9812e8abfc8362983f5ac6a5a17ac08decefa140022530b4fd8e069aaf7ae3f7630eca40ac9d0d3f2c9f21316ba3f703e8dcb60a0df8b88c89e5bec221ab0492b7c0687297a58b6a33dc5056a7a7928d703cc53e292859788f398ca4e4d417b979c0c0f8681759cf07eb8907ab1f71f7a78d7ebc463cb5c9d68e372f1abbb9fb025aae11dabf83ab16fb7c88b973b37b99a04911a35d321c669aa42d76bf85ccab7da3801165cf46c332bfb43745244b22427eb4eb1ccc23cb272c7301ff4c56ea95da42472206e3c91ccaae5eb14bf25d779b7dae170f48adf2b111e13e2bc4ed2506c31406f83572e636983a89afc9c9bdd8698ef58749d6807dadc7728b61b2d4f8fabeb02c5b9f09a5f99577a8aa1512ee37edea358893b993b1d0248b6206d843ad5478351c30b5166e47ec76ef8ea137947ad8643a9bad5dea989085b5f194791b7e1675eda274c9d37d34fca1fd700804536fd2b24aabe4fae12690d0e1eb9bb81684e22a584eb9ac7c5c301217cd2d5f19eef86007e38b75a7232eff819b8bf39bac51317a6c4a0392a478a84f7c7472a85db0a3b5a929805634a1192328cc2e3caff1a264e422d083b65566c13fceb9eac78256a2f8342b642eeac76432b3caeccc9074cfee58116c58164441e0865f9b98f70b1c203e3c30366b37b54cf1915eaf1341b2a2b425194c03513ec501dfd3fd0017e6fe165a90126a8d044626de56faf35a3f523d5798cd66390d42cca61df511ff8700848788d245da8rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsamba-4.17.12+git.455.b299ac1e60-150500.3.20.1.src.rpmsamba-python3samba-python3(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    libMESSAGING-SEND-samba4.so()(64bit)libMESSAGING-SEND-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libMESSAGING-samba4.so()(64bit)libMESSAGING-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libaddns-samba4.so()(64bit)libaddns-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libads-samba4.so()(64bit)libads-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libauth-unix-token-samba4.so()(64bit)libauth-unix-token-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libauth4-samba4.so()(64bit)libauth4-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.8)(64bit)libcli-ldap-samba4.so()(64bit)libcli-ldap-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libcli-nbt-samba4.so()(64bit)libcli-nbt-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libcli-smb-common-samba4.so()(64bit)libcli-smb-common-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libcliauth-samba4.so()(64bit)libcliauth-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libcluster-samba4.so()(64bit)libcluster-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libcmdline-contexts-samba4.so()(64bit)libcmdline-contexts-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libcom_err.so.2()(64bit)libcommon-auth-samba4.so()(64bit)libcommon-auth-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libdbwrap-samba4.so()(64bit)libdbwrap-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libdcerpc-binding.so.0()(64bit)libdcerpc-binding.so.0(DCERPC_BINDING_0.0.1)(64bit)libdcerpc-samba-samba4.so()(64bit)libdcerpc-samba-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libdcerpc-samba4.so()(64bit)libdcerpc-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libdcerpc.so.0()(64bit)libdcerpc.so.0(DCERPC_0.0.1)(64bit)libdnsserver-common-samba4.so()(64bit)libdnsserver-common-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libevents-samba4.so()(64bit)libevents-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libflag-mapping-samba4.so()(64bit)libflag-mapping-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libgenrand-samba4.so()(64bit)libgenrand-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libgensec-samba4.so()(64bit)libgensec-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libgnutls.so.30()(64bit)libgnutls.so.30(GNUTLS_3_4)(64bit)libgnutls.so.30(GNUTLS_3_6_13)(64bit)libgnutls.so.30(GNUTLS_3_6_3)(64bit)libgpo-samba4.so()(64bit)libgpo-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libgse-samba4.so()(64bit)libgse-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libgssapi_krb5.so.2()(64bit)libgssapi_krb5.so.2(gssapi_krb5_2_MIT)(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libldbsamba-samba4.so()(64bit)libldbsamba-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)liblibcli-lsa3-samba4.so()(64bit)liblibcli-lsa3-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)liblibcli-netlogon3-samba4.so()(64bit)liblibcli-netlogon3-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)liblibsmb-samba4.so()(64bit)liblibsmb-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libmsrpc3-samba4.so()(64bit)libmsrpc3-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-samba-samba4.so()(64bit)libndr-samba-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libndr-samba4.so()(64bit)libndr-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libndr-standard.so.0()(64bit)libndr-standard.so.0(NDR_STANDARD_0.0.1)(64bit)libndr.so.3()(64bit)libndr.so.3(NDR_0.0.1)(64bit)libndr.so.3(NDR_0.0.4)(64bit)libndr.so.3(NDR_0.2.0)(64bit)libndr.so.3(NDR_1.0.0)(64bit)libndr.so.3(NDR_2.0.0)(64bit)libnetif-samba4.so()(64bit)libnetif-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libposix-eadb-samba4.so()(64bit)libposix-eadb-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libpthread.so.0(GLIBC_2.3.2)(64bit)libpyldb-util.cpython-36m-x86_64-linux-gnu.so.2()(64bit)libpyldb-util.cpython-36m-x86_64-linux-gnu.so.2(PYLDB_UTIL_1.1.2)(64bit)libpyldb-util.cpython-36m-x86_64-linux-gnu.so.2(PYLDB_UTIL_2.1.0)(64bit)libpytalloc-util.cpython-36m-x86_64-linux-gnu.so.2()(64bit)libpytalloc-util.cpython-36m-x86_64-linux-gnu.so.2(PYTALLOC_UTIL_2.0.6)(64bit)libpytalloc-util.cpython-36m-x86_64-linux-gnu.so.2(PYTALLOC_UTIL_2.1.6)(64bit)libpytalloc-util.cpython-36m-x86_64-linux-gnu.so.2(PYTALLOC_UTIL_2.1.9)(64bit)libpytalloc-util.cpython-36m-x86_64-linux-gnu.so.2(PYTALLOC_UTIL_2.3.0)(64bit)libpython3.6m.so.1.0()(64bit)libregistry-samba4.so()(64bit)libregistry-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libreplace-samba4.so()(64bit)libreplace-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsamba-credentials.so.1()(64bit)libsamba-credentials.so.1(SAMBA_CREDENTIALS_1.0.0)(64bit)libsamba-debug-samba4.so()(64bit)libsamba-debug-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsamba-errors.so.1()(64bit)libsamba-errors.so.1(SAMBA_ERRORS_1.0.0)(64bit)libsamba-hostconfig.so.0()(64bit)libsamba-hostconfig.so.0(SAMBA_HOSTCONFIG_0.0.1)(64bit)libsamba-net.cpython-36m-x86-64-linux-gnu-samba4.so()(64bit)libsamba-net.cpython-36m-x86-64-linux-gnu-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsamba-passdb.so.0()(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.2.0)(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.27.1)(64bit)libsamba-policy.cpython-36m-x86-64-linux-gnu.so.0()(64bit)libsamba-policy.cpython-36m-x86-64-linux-gnu.so.0(SAMBA_POLICY.CPYTHON_36M_X86_64_LINUX_GNU_0.0.1)(64bit)libsamba-policy0-python3libsamba-python.cpython-36m-x86-64-linux-gnu-samba4.so()(64bit)libsamba-python.cpython-36m-x86-64-linux-gnu-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsamba-security-samba4.so()(64bit)libsamba-security-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsamba-util.so.0()(64bit)libsamba-util.so.0(SAMBA_UTIL_0.0.1)(64bit)libsamba3-util-samba4.so()(64bit)libsamba3-util-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsamdb-common-samba4.so()(64bit)libsamdb-common-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsamdb.so.0()(64bit)libsamdb.so.0(SAMDB_0.0.1)(64bit)libsecrets3-samba4.so()(64bit)libsecrets3-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libserver-role-samba4.so()(64bit)libserver-role-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsmbconf.so.0()(64bit)libsmbconf.so.0(SMBCONF_0.0.1)(64bit)libsmbd-base-samba4.so()(64bit)libsmbd-base-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb-wrap-samba4.so()(64bit)libtdb-wrap-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libtevent-util.so.0()(64bit)libtevent-util.so.0(TEVENT_UTIL_0.0.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.16)(64bit)libtevent.so.0(TEVENT_0.9.20)(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libtrusts-util-samba4.so()(64bit)libtrusts-util-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libutil-reg-samba4.so()(64bit)libutil-reg-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libxattr-tdb-samba4.so()(64bit)libxattr-tdb-samba4.so(SAMBA_4.17.12_GIT.455.B299AC1E60150500.3.20.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)python(abi)python3-ldbpython3-tallocpython3-tdbpython3-teventrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)samba4.17.12+git.455.b299ac1e603.63.0.4-14.6.0-14.0-15.2-14.17.12+git.455.b299ac1e604.14.3ez@e[J@e6`@eSd@d.@dd-@d@dd@d6@d@d @cvcvc@c@c @c@cctc5cM@b@b@b@ba@bascabrero@suse.descabrero@suse.descabrero@suse.denopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comscabrero@suse.dedmulder@suse.comscabrero@suse.denopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedimstar@opensuse.orgscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.denopower@suse.comscabrero@suse.deddiss@suse.comddiss@suse.comddiss@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comscabrero@suse.descabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comdmulder@suse.comscabrero@suse.denopower@suse.comddiss@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comddiss@suse.comddiss@suse.comnopower@suse.comnopower@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comddiss@suse.comscabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comjengelh@inai.dedmulder@suse.comscabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comdmulder@suse.comdmulder@suse.comjmcdonough@suse.comdmulder@suse.comscabrero@suse.dedmulder@suse.comscabrero@suse.dedmulder@suse.comdmulder@suse.comvcizek@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.dejmcdonough@suse.comscabrero@suse.deaaptel@suse.comjengelh@inai.dedimstar@opensuse.orgdmulder@suse.comjmcdonough@suse.comdavid.mulder@suse.comjmcdonough@suse.comaaptel@suse.comdmulder@suse.comscabrero@suse.comscabrero@suse.comkukuk@suse.dedavid.mulder@suse.comscabrero@suse.comrbrown@suse.comdmulder@suse.comscabrero@suse.comdimstar@opensuse.orgscabrero@suse.comaaptel@suse.comnopower@suse.comnopower@suse.comaaptel@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comddiss@suse.comnopower@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comdmulder@suse.comnopower@suse.comjmcdonough@suse.comaaptel@suse.comkukuk@suse.comkukuk@suse.denopower@suse.comaaptel@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comddiss@suse.comjmcdonough@suse.comddiss@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comtchvatal@suse.comlmuelle@suse.comnopower@suse.comcrrodriguez@opensuse.orglmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnoel.power@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.commpluskal@suse.comlmuelle@suse.comnopower@suse.deddiss@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.denopower@suse.delmuelle@suse.comnopower@suse.deddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.com- Add new idmap_nss option 'use_upn' for those NSS modules able to handle UPNs or DOMAIN/user name format; (bsc#1215369); - Avoid unnecessary locking in idmap parent setup; (bsc#1215369);- Add "net offlinejoin composeodj" command; (bsc#1214076);- Update to samba 4.17.12 * Weird filename can cause assert to fail in openat_pathref_fsp_nosymlink(); (bso#15419); * reply_sesssetup_and_X() can dereference uninitialized tmp pointer; (bso#15420); * Missing return in reply_exit_done(); (bso#15430); * TREE_CONNECT without SETUP causes smbd to use uninitialized pointer; (bso#15432); * Improve GetNChanges to address some (but not all "Azure AD Connect") syncronisation tool looping during the initial user sync phase; (bso#15401); * Samba replication logs show (null) DN; (bso#15407); * Spotlight sometimes returns no results on latest macOS; (bso#15342); * Renaming results in NT_STATUS_SHARING_VIOLATION if previously attempted to remove the destination; (bso#15417); * Spotlight results return wrong date in result list; (bso#15427); * macOS mdfind returns only 50 results; (bso#15463); * 2-3min delays at reconnect with smb2_validate_sequence_number: bad message_id 2; (bso#15346); * samba-tool ntacl get segfault if aio_pthread appended; (bso#15441); * DCERPC_PKT_CO_CANCEL and DCERPC_PKT_ORPHANED can't be parsed; (bso#15446); * File doesn't show when user doesn't have permission if aio_pthread is loaded; (bso#15453); * net ads lookup (with unspecified realm) fails; (bso#15384); (bsc#1213826); * Regression DFS not working with widelinks = true; (bso#15435); (bsc#1213607); * ctdb_killtcp fails to work with --enable-pcap and libpcap 1.9.1; (bso#15451); * mdssvc: Do an early talloc_free() in _mdssvc_open(); (bso#15449); * Windows client join fails if a second container CN=System exists somewhere; (bso#9959); - Fix crossing automounter mount points; (bsc#1215212);- CVE-2023-4091: samba: Client can truncate file with read-only permissions; (bsc#1215904); (bso#15439). - CVE-2023-42669: samba: rpcecho, enabled and running in AD DC, allows blocking sleep on request; (bso#1215905); (bso#15474). - CVE-2023-42670: samba: The procedure number is out of range when starting Active Directory Users and Computers; (bsc#1215906); (bso#15473). - CVE-2023-3961: samba: Unsanitized client pipe name passed to local_np_connect(); (bsc#1215907); (bso#15422). - CVE-2023-4154: samba: dirsync allows SYSTEM access with only "GUID_DRS_GET_CHANGES" right, not "GUID_DRS_GET_ALL_CHANGES; (bsc#1215908); (bso#15424).- Fix DFS not working with widelinks enabled; (bsc#1213607); (bso#15435);- Move libcluster-samba4.so from samba-libs to samba-client-libs; (bsc#1213940);- net ads lookup with unspecified realm fails; (bso#15384); (bsc#1213826);- secure channel faulty since Windows 10/11 update 07/2023; (bso#15418); (bsc#1213384).- CVE-2022-2127: lm_resp_len not checked properly in winbindd_pam_auth_crap_send; (bso#15072); (bsc#1213174). - CVE-2023-34966: Samba Spotlight mdssvc RPC Request Infinite Loop Denial-of-Service Vulnerability; (bso#15340); (bsc#1213173). - CVE-2023-34967: Samba Spotlight mdssvc RPC Request Type Confusion Denial-of-Service Vulnerability; (bso#15341); (bsc#1213172). - CVE-2023-34968: Spotlight server-side Share Path Disclosure; (bso#15388); (bsc#1213171). - CVE-2023-3347: Samba doesn't require SMB2+ signing if `server signing = mandatory` is set; (bso#15397); (bsc#1213170).- Update to 4.17.9 * Backport --pidl-developer fixes; (bso#15404). * smbd_scavenger crashes when service smbd is stopped; (bso#15275). * vfs_fruit might cause a failing open for delete; (bso#15378). * named crashes on DLZ zone update; (bso#14030). * winbind recurses into itself via rpcd_lsad; (bso#15361). * cli_list loops 100% CPU against pre-lanman2 servers; (bso#15382). * smbclient leaks fds with showacls; (bso#15391). * aes256 smb3 encryption algorithms are not allowed in smb3_sid_parse(); (bso#15374). * winbindd gets stuck on NT_STATUS_RPC_SEC_PKG_ERROR; (bso#15413). * smbget memory leak if failed to download files recursively; (bso#15403).- Update to 4.17.8 * log flood: smbd_calculate_access_mask_fsp: Access denied: message level should be lower; (bso#15302). * Floating point exception (FPE) via cli_pull_send at source3/libsmb/clireadwrite.c; (bso#15306). * test_tstream_more_tcp_user_timeout_spin fails intermittently on Rackspace GitLab runners; (bso#15328). * Reduce flapping of ridalloc test; (bso#15329). * large_ldap test is unreliable; (bso#15351). * New filename parser doesn't check veto files smb.conf parameter; (bso#15143). * mdssvc may crash when initializing; (bso#15354). * Large directory optimization broken for non-lcomp path elements; (bso#15313). * streams_depot fails to create streams; (bso#15357). * shadow_copy2 and streams_depot don't play well together; (bso#15358). * wbinfo -u fails on ad dc with >1000 users; (bso#15366). * winbindd idmap child contacts the domain controller without a need; (bso#15317). * idmap_autorid may fail to map sids of trusted domains for the first time; (bso#15318). * idmap_hash doesn't use ID_TYPE_BOTH for reverse mappings; (bso#15319). * net ads search -P doesn't work against servers in other domains; (bso#15323). * DS ACEs might be inherited to unrelated object classes; (bso#15338). * Temporary smbXsrv_tcon_global.tdb can't be parsed; (bso#15353). * Setting veto files = /.*/ break listing directories; (bso#15360); (bsc#1212375). * CVE-2020-25720 [SECURITY] Create Child permission should not allow full write to all attributes (additional changes); (bso#14810). * dsgetdcname: assumes local system uses IPv4; (bso#15325).- Update to 4.17.7 * CVE-2023-0922: Samba AD DC admin tool samba-tool sends passwords in cleartext; (bso#15315); (bsc#1209481). * CVE-2023-0225: Samba AD DC "dnsHostname" attribute can be deleted by unprivileged authenticated users; (bso#15276); (bsc#1209483). * CVE-2023-0614: samba: Access controlled AD LDAP attributes can be discovered; (bso#15270); (bsc#1209485). * large_ldap test is inefficient; (bso#15332). * CVE-2020-25720 [SECURITY] Create Child permission should not allow full write to all attributes (additional changes); (bso#14810). - Update to 4.17.6 * streams_xattr is creating unexpected locks on folders; (bso#15314). * Use of the Azure AD Connect cloud sync tool is now supported for password hash synchronisation, allowing Samba AD Domains to synchronise passwords with this popular cloud environment; (bso#10635). * Spotlight doesn't work with latest macOS Ventura; (bso#15299). * New samba-dcerpc architecture does not scale gracefully; (bso#15310). * vfs_ceph incorrectly uses fsp_get_io_fd() instead of fsp_get_pathref_fd() in close and fstat; (bso#15307). * With clustering enabled samba-bgqd can core dump due to use after free; (bso#15293). * fd_load() function implicitly closes the fd where it should not; (bso#15311). - Update to 4.17.5 * smbc_getxattr() return value is incorrect; (bso#14808). * Compound SMB2 FLUSH+CLOSE requests from MacOSX are not handled correctly; (bso#15172). * synthetic_pathref AFP_AfpInfo failed errors; (bso#15210). * samba-tool gpo listall fails IPv6 only - finddcs() fails to find DC when there is only an AAAA record for the DC in DNS; (bso#15226). * smbd crashes if an FSCTL request is done on a stream handle; (bso#15236). * DFS links don't work anymore on Mac clients since 4.17; (bso#15277). * vfs_virusfilter segfault on access, directory edgecase (accessing NULL value); (bso#15283). * CVE-2022-38023 [SECURITY] Samba should refuse RC4 (aka md5) based SChannel on NETLOGON (additional changes); (bso#15240). * %U for include directive doesn't work for share listing (netshareenum); (bso#15243). * Shares missing from netshareenum response in samba 4.17.4; (bso#15266). * ctdb: use-after-free in run_proc; (bso#15269). * irpc_destructor may crash during shutdown; (bso#15280). * auth3_generate_session_info_pac leaks wbcAuthUserInfo; (bso#15286). * smbclient segfaults with use after free on an optimized build; (bso#15268). * smbstatus leaking files in msg.sock and msg.lock; (bso#15282). * Leak in wbcCtxPingDc2; (bso#15164). * Access based share enum does not work in Samba 4.16+; (bso#15265). * Crash during share enumeration; (bso#15267). * rep_listxattr on FreeBSD does not properly check for reads off end of returned buffer; (bso#15271). * Avoid relying on C89 features in a few places; (bso#15281).- Make (32bit) samba-libs conflict with old samba-ad-dc-libs package to satisfy installcheck.- Make samba-libs conflict with old samba-ad-dc-libs package to satisfy installcheck.- Remove non functioning ifup/ifdown samba-winbindd scripts; (bsc#1207414).- libdsdb-module-samba4 should be packaged as part of samba-libs and not samba-ad-dc-libs. Additionally no need for it to be removed conditionally.- Clean up logic for PAM migration settings in spec file.- Change with_dc default to 0 (for non TW builds), ADDC feature is deprecated and will no longer be included in >= SLE15-SP5; (jsc#PED-1122).- Update to 4.17.4 * CVE-2022-44640 Upstream Heimdal free of user-controlled pointer in FAST; (bsc#14929); * CVE-2021-20251 Bad password count not incremented atomically; (bsc#14611); * CVE-2022-42898 krb5_pac_parse() buffer parsing vulnerability; (bsc#15203); * CVE-2022-37966 rc4-hmac Kerberos session keys issued to modern servers; (bso#15237); * CVE-2022-37967 Kerberos constrained delegation ticket forgery possible against Samba AD DC; (bso#15231); * CVE-2022-38023 RC4/HMAC-MD5 NetLogon Secure Channel is weak and should be avoided; (bso#15240); * pam_winbind uses time_t and pointers assuming they are of the same size; (bso#15224); * Heimdal session key selection in AS-REQ examines wrong entry; (bso#15219); * filter-subunit is inefficient with large numbers of knownfails; (bso#15258); * smbd allows setting FILE_ATTRIBUTE_TEMPORARY on directories; (bso#15252); * The KDC logic arround msDs-supportedEncryptionTypes differs from Windows; (bso#13135); * libnet: change_password() doesn't work with dcerpc_samr_ChangePasswordUser4(); (bso#15206); * Heimdal session key selection in AS-REQ examines wrong entry; (bso#15219); * Memory leak in snprintf replacement functions; (bso#15230); * RODC doesn't reset badPwdCount reliable via an RWDC (CVE-2021-20251 regression); (bso#15253); * Prevent EBADF errors with vfs_glusterfs; (bso#15198); * %U for include directive doesn't work for share listing (netshareenum); (bso#15243); * Stack smashing in net offlinejoin requestodj; (bso#15257); * Windows 11 22H2 and Samba-AD 4.15 Kerberos login issue; (bso#15197); * Heimdal session key selection in AS-REQ examines wrong entry; (bso#15219); - Remove deprecated if-{down,up} scripts; (bsc#1206444); - Adjust the systemd drop-in file for named service; (bsc#1201689); * Paths are additive so do not repeat paths from named.service * Prefix the samba DLZ directory with "-" to ignore this path if it does not exists- Introduce without-smb1-server spec flag; (bsc#1205104); - Update to 4.17.3 * CVE-2022-42898: Samba buffer overflow vulnerabilities on 32-bit systems; (bsc#1205126); (bso#15203); - Replace obsolete python-gpgme with python-gpg * Upstream replaced it in v4.9.5 -- bso#13728 - Update to 4.17.2 * CVE-2022-3592 [SECURITY] samba: Wide links protection broken; (bso#15207); (bsc#1204499). * CVE-2022-3437 [SECURITY] samba: Buffer overflow in Heimdal unwrap_des3();(bso#15134); (bsc#1204254). - Update to 4.17.1 * CVE-2021-20251 [SECURITY] Bad password count not incremented atomically; (bso#14611). * smbXsrv_connection_shutdown_send result leaked; (bso#15174). * Flush on a named stream never completes; (bso#15182). * Permission denied calling SMBC_getatr when file not exists; (bso#15195). * Samba 4.5 sometimes cannot be upgraded to Samba 4.6 or later over DRS: WERROR_DS_DRA_MISSING_PARENT due to faulty GET_ANC; (bso#15189). * pytest: add file removal helpers for TestCaseInTempDir; (bso#15191). * CVE-2021-20251 [SECURITY] Bad password count not incremented atomically; (bso#14611). * Samba 4.5 sometimes cannot be upgraded to Samba 4.6 or later over DRS: WERROR_DS_DRA_MISSING_PARENT due to faulty GET_ANC; (bso#15189). * Flush on a named stream never completes; (bso#15182). * vfs_gpfs silently garbles timestamps > year 2106; (bso#15151). * CVE-2021-20251 [SECURITY] Bad password count not incremented atomically; (bso#14611). * multi-channel socket passing may hit a race if one of the involved processes already existed; (bso#15200). * memory leak on temporary of struct imessaging_post_state and struct tevent_immediate on struct imessaging_context (in rpcd_spoolss and maybe others); (bso#15201). * Since popt1.19 various use after free errors using result of poptGetArg are now exposed; (bso#15205); (boo#1204279). * Remove special case for O_CREAT in SMB_VFS_OPENAT from vfs_glusterfs; (bso#15192). * GETPWSID in memory cache grows indefinetly with each NTLM auth; (bso#15169). * CVE-2021-20251 [SECURITY] Bad password count not incremented atomically; (bso#14611). - Install a systemd drop-in file for named service to allow read/write access to the DLZ directory; (bsc#1201689); - Fix use after free errors resulting from using return of poptGetArg exposed since popt-1.19; (boo#1204279); (bso#15205). - s3: smbd: Fix memory leak in smbd_server_connection_terminate_done(); (bso#15174). - Disable SMB1 for tumbleweed builds. - Update to 4.17.0 * acl_xattr VFS module may unintentionally use filesystem permissions instead of ACL from xattr; (bso#15126). * Missing SMB2-GETINFO access checks from MS-SMB2 3.3.5.20.1; (bso#15153). * assert failed: !is_named_stream(smb_fname)") at ../../lib/util/fault.c:197; (bso#15161). * acl_xattr VFS module may unintentionally use filesystem permissions instead of ACL from xattr; (bso#15126). * assert failed: !is_named_stream(smb_fname)") at ../../lib/util/fault.c:197; (bso#15161). * Cross-node multi-channel reconnects result in SMB2 Negotiate returning NT_STATUS_NOT_SUPPORTED; (bso#15159). * winbind at info level debug can coredump when processing wb_lookupusergroups; (bso#15160). * Make use of glfs_*at() API calls in vfs_glusterfs; (bso#15157). * Possible use after free of connection_struct when iterating smbd_server_connection->connections; (bso#15128). * `net usershare add` fails with flag works with --long but fails with -l; (bso#15145). * acl_xattr VFS module may unintentionally use filesystem permissions instead of ACL from xattr; (bso#15126). * Performance regression on contended path based operations; (bso#15125). * Missing READ_LEASE break could cause data corruption; (bso#15148). * libsamba-errors uses a wrong version number; (bso#15141). * SMB1 negotiation can fail to handle connection errors; (bso#15152). * New filename parser doesn't check veto files smb.conf parameter; (bso#15143). * 4.17.rc1 still uses symlink-race prone unix_convert(); (bso#15144). * Backport fileserver related changed to 4.17.0rc2; (bso#15146). * Manpage for smbstatus json is missing; (bso#15147). * Backport fileserver related changed to 4.17.0rc2; (bso#15146). * Performance regression on contended path based operations; (bso#15125). * Backport fileserver related changed to 4.17.0rc2; (bso#15146). * Fix issues found by coverity in smbstatus json code; (bso#15140). * Backport fileserver related changed to 4.17.0rc2; (bso#15146). - Migration to /usr/etc: Saving user changed configuration files in /etc and restoring them while an RPM update. - Update to 4.16.4 * CVE-2022-2031: Samba AD users can bypass certain restrictions associated with changing passwords; (bsc#1201495); (bso#15047); * CVE-2022-32744: Samba AD users can forge password change requests for any user; (bsc#1201493); (bso#15074); * CVE-2022-32745: Samba AD users can crash the server process with an LDAP add or modify request; (bsc#1201492); (bso#15008); * CVE-2022-32746: Samba AD users can induce a use-after-free in the server process with an LDAP add or modify request; (bsc#1201490); (bso#15009); * CVE-2022-32742: Server memory information leak via SMB1; (bsc#1201496); (bso#15085); - Update to 4.16.3 * Using vfs_streams_xattr and deleting a file causes a panic; (bso#15099); * Add support for bind 9.18; (bso#14986); * logging dsdb audit to specific files does not work; (bso#15076); * Problem when winbind renews Kerberos; (bso#14979); (bsc#1196224); * Samba with new lorikeet-heimdal fails to build on gcc 12.1 in developer mode; (bso#15095); * Crash in streams_xattr because fsp->base_fsp->fsp_name is NULL; (bso#15105); * Crash in rpcd_classic - NULL pointer deference in mangle_is_mangled(); (bso#15118); * smbclient commands del & deltree fail with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556); * Fix check for chown when processing NFSv4 ACL; (bso#15120); * The pcap background queue process should not be stopped; (bso#15082); * testparm: Fix typo in idmap rangesize check; (bso#15097); * net ads info returns LDAP server and LDAP server name as null; (bso#15106); * ldconfig: /lib64/libsmbconf.so.0 is not a symbolic link; (bso#15108); * CTDB child process logging does not work as expected; (bso#15090); - Update spec file to fix the optional Heimdal DC build - Fix external trusts with MIT Kerberos 1.20 - Add missing samba-client requirement to samba-winbind package; (bsc#1198255); - Move pdb backends from package samba-libs to package samba-client-libs and remove samba-libs requirement from samba-winbind; (bsc#1200964); (bsc#1198255); - Add sysuser-shadow requirement for packages using systemd-sysusers - Use the canonical realm name to refresh the Kerberos tickets; (bsc#1196224); (bso#14979); - Moved logrotate files from user specific directory /etc/logrotate.d to vendor specific directory /usr/etc/logrotate.d. - Update to 4.16.2 * Use pathref fd instead of io fd in vfs_default_durable_cookie; (bso#15042); * vfs_gpfs with vfs_shadowcopy2 fail to restore file if original file had been deleted; (bso#15069); * Reintroduce netgroups support; (bso#15087); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); * Update from 4.15 to 4.16 breaks discovery of [homes] on standalone server from Win and IOS; (bso#15062); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * smbclient -E doesn't work as advertised; (bso#15075); * The samba background daemon doesn't refresh the printcap cache on startup; (bso#15081); * Out-by-4 error in smbd read reply max_send clamp; (bso#14443); - Fix samba4.blackbox.net_ads_dns_async test with bind9 >= 9.17.7 - Support building with MIT Kerberos 1.20 - Bronze bit and S4U support with MIT Kerberos 1.20 for Samba AD DC; (CVE-2020-17049); - Resource Based Constrained Delegation (RBCD) for Samba AD DC - Support building with gcc 12.1 - Use requires_eq macro to require the libldb2 version available at samba-dsdb-modules build time; (bsc#1199362); - Update to 4.16.1 * Share and server swapped in smbget password prompt; (bso#14831); * Durable handles won't reconnect if the leased file is written to; (bso#15022); * rmdir silently fails if directory contains unreadable files and hide unreadable is yes; (bso#15023); * SMB2_CLOSE_FLAGS_FULL_INFORMATION fails to return information on renamed file handle; (bso#15038); * Need to describe --builtin-libraries= better (compare with - -bundled-libraries); (bso#8731); * vfs_shadow_copy2 breaks "smbd async dosmode" sync fallback; (bso#14957); * shadow_copy2 fails listing snapshotted dirs with shadow:fixinodes; (bso#15035); * PAM Kerberos authentication incorrectly fails with a clock skew error; (bso#15046); * Username map - samba erroneously applies unix group memberships to user account entries; (bso#15041); * KVNO off by 100000; (bso#14951); * Uninitialized litemask in variable in vfs_gpfs module; (bso#15027); * vfs_gpfs recalls=no option prevents listing files; (bso#15055); * smbd doesn't handle UPNs for looking up names; (bso#15054); - Update update-apparmor-samba-profile script, replace non-printable delimiter with more human readable separator as sed can accept separators that can appear in the input data. - Fix update-apparmor-samba-profile script, sed doesn't like multibyte separators; (bsc#1198309). - Update to 4.16.0 * New samba-dcerpcd binary to provide DCERPC in the member server setup * Certificate Auto Enrollment * Ability to add ports to dns forwarder addresses in internal DNS backend * No longer using Linux mandatory locks for sharemodes * SMB1 protocol has been deprecated, particularly older dialects * SMB1 protocol SMBCopy command removed * SMB1 server-side wildcard expansion removed - Add python3-dnspython to samba-ad-dc recommens; (bsc#1187101); - Use systemd-sysusers to create system users; (bsc#1182847);- Install a systemd drop-in file for named service to allow read/write access to the DLZ directory; (bsc#1201689);- Update to 4.15.12 * CVE-2022-42898: samba: heimdal: Samba buffer overflow vulnerabilities on 32-bit systems; (bso#15203); (bsc#1205126). - Update to 4.15.11 * Allow rebuild of Centos 8 images after move to vault for Samba 4.15; (bso#15193). * CVE-2022-3437: samba: Buffer overflow in Heimdal unwrap_des3(); (bso#15134); (bsc#1204254)- Update to 4.15.10 * Possible use after free of connection_struct when iterating smbd_server_connection->connections; (bso#15128); (bsc#1200102). * smbXsrv_connection_shutdown_send result leaked; (bso#15174). * Spotlight RPC service returns wrong response when Spotlight is disabled on a share; (bso#15086). * acl_xattr VFS module may unintentionally use filesystem permissions instead of ACL from xattr; (bso#15126). * Missing SMB2-GETINFO access checks from MS-SMB2 3.3.5.20.1; (bso#15153). * assert failed: !is_named_stream(smb_fname)") at ../../lib/util/fault.c:197; (bso#15161). * Missing READ_LEASE break could cause data corruption; (bso#15148). * rpcclient can crash using setuserinfo(2); (bso#15124). * Samba fails to build with glibc 2.36 caused by including in libreplace; (bso#15132). * SMB1 negotiation can fail to handle connection errors; (bso#15152). * samba-tool domain join segfault when joining a samba ad domain; (bso#15078). - Update to 4.15.9 * CVE-2022-32742:SMB1 code does not correct verify SMB1write, SMB1write_and_close, SMB1write_and_unlock lengths; (bso#15085); (bsc#1201496). * CVE-2022-32746: samba: Use-after-free occurring in database audit logging; (bso#15009); (bso#15096); (bsc#1201490). * CVE-2022-2031: samba, ldb: AD users can bypass certain restrictions associated with changing passwords; (bso#15047); (bsc#1201495); * CVE-2022-32745: samba: ldb: AD users can crash the server process with an LDAP add or modify request; (bso#15008); (bso#15096); (bsc#1201492). * CVE-2022-2031: samba, ldb: AD users can bypass certain restrictions associated with changing passwords; (bso#15047); (bsc#1201495); * CVE-2022-32744: samba, ldb: AD users can forge password change requests for any user; (bso#15074); (bso#15047); (bsc#1201493).- CVE-2022-1615: Do not ignore errors in random number generation; (bso#15103); (bsc#1202976); - CVE-2022-32743: Implement validated dnsHostName write rights; (bso#14833); (bsc#1202803);- Fix Use after free when iterating smbd_server_connection->connections after tree disconnect failure; (bso#15128); (bsc#1200102).- CVE-2022-32746: samba: Use-after-free occurring in database audit logging; (bso#15009); (bso#15096); (bsc#1201490). - CVE-2022-32745: samba: ldb: AD users can crash the server process with an LDAP add or modify request; (bso#15008); (bso#15096); (bsc#1201492). - CVE-2022-2031: samba, ldb: AD users can bypass certain restrictions associated with changing passwords; (bso#15047); (bsc#1201495); - CVE-2022-32742:SMB1 code does not correct verify SMB1write, SMB1write_and_close, SMB1write_and_unlock lengths; (bso#15085); (bsc#1201496). - CVE-2022-32744: samba, ldb: AD users can forge password change requests for any user; (bso#15074); (bso#15047); (bsc#1201493).- Update to 4.15.8 * Use pathref fd instead of io fd in vfs_default_durable_cookie; (bso#15042); * Setting fruit:resource = stream in vfs_fruit causes a panic; (bso#15099); * Add support for bind 9.18; (bso#14986); * logging dsdb audit to specific files does not work; (bso#15076); * vfs_gpfs with vfs_shadowcopy2 fail to restore file if original file had been deleted; (bso#15069); * netgroups support removed; (bso#15087); (bsc#1199247); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); (bsc#1199734); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * smbclient commands del & deltree fail with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556); * vfs_gpfs recalls=no option prevents listing files; (bso#15055); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * Compile error in source3/utils/regedit_hexedit.c; (bso#15091); * ldconfig: /lib64/libsmbconf.so.0 is not a symbolic link; (bso#15108); * smbd doesn't handle UPNs for looking up names; (bso#15054); * Out-by-4 error in smbd read reply max_send clamp; (bso#14443); - Move pdb backends from package samba-libs to package samba-client-libs and remove samba-libs requirement from samba-winbind; (bsc#1200964); (bsc#1198255); - Use the canonical realm name to refresh the Kerberos tickets; (bsc#1196224); (bso#14979);- Fix smbclient commands del & deltree failing with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556).- Revert NIS support removal; (bsc#1199247);- Use requires_eq macro to require the libldb2 version available at samba-dsdb-modules build time; (bsc#1199362);- Add missing samba-client requirement to samba-winbind package; (bsc#1198255);- Update to 4.15.7 * Share and server swapped in smbget password prompt; (bso#14831); * Durable handles won't reconnect if the leased file is written to; (bso#15022); * rmdir silently fails if directory contains unreadable files and hide unreadable is yes; (bso#15023); * SMB2_CLOSE_FLAGS_FULL_INFORMATION fails to return information on renamed file handle; (bso#15038); * vfs_shadow_copy2 breaks "smbd async dosmode" sync fallback; (bso#14957); * shadow_copy2 fails listing snapshotted dirs with shadow:fixinodes; (bso#15035); * PAM Kerberos authentication incorrectly fails with a clock skew error; (bso#15046); * username map - samba erroneously applies unix group memberships to user account entries; (bso#15041); * NT_STATUS_ACCESS_DENIED translates into EPERM instead of EACCES in SMBC_server_internal; (bso#14983); * Simple bind doesn't work against an RODC (with non-preloaded users); (bso#13879); * Crash of winbind on RODC; (bso#14641); * uncached logon on RODC always fails once; (bso#14865); * KVNO off by 100000; (bso#14951); * LDAP simple binds should honour "old password allowed period"; (bso#15001); * wbinfo -a doesn't work reliable with upn names; (bso#15003); * Simple bind doesn't work against an RODC (with non-preloaded users); (bso#13879); * Uninitialized litemask in variable in vfs_gpfs module; (bso#15027); * Regression: create krb5 conf = yes doesn't work with a single KDC; (bso#15016);- Add provides to samba-client-libs package to fix upgrades from previous versions; (bsc#1197995);- Add missing samba-libs requirement to samba-winbind package; (bsc#1198255);- Update to 4.15.6 * Renaming file on DFS root fails with NT_STATUS_OBJECT_PATH_NOT_FOUND; (bso#14169); * Samba does not response STATUS_INVALID_PARAMETER when opening 2 objects with same lease key; (bso#14737); * NT error code is not set when overwriting a file during rename in libsmbclient; (bso#14938); * Fix ldap simple bind with TLS auditing; (bso#14996); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); * Problem when winbind renews Kerberos; (bso#14979); (bsc#1196224); * pam_winbind will not allow gdm login if password about to expire; (bso#8691); * virusfilter_vfs_openat: Not scanned: Directory or special file; (bso#14971); * DFS fix for AIX broken; (bso#13631); * Solaris and AIX acl modules: wrong function arguments; (bso#14974); * Function aixacl_sys_acl_get_file not declared / coredump; (bso#7239); * Regression: Samba 4.15.2 on macOS segfaults intermittently during strcpy in tdbsam_getsampwnam; (bso#14900); * Fix a use-after-free in SMB1 server; (bso#14989); * smb2_signing_decrypt_pdu() may not decrypt with gnutls_aead_cipher_decrypt() from gnutls before 3.5.2; (bso#14968); * Changing the machine password against an RODC likely destroys the domain join; (bso#14984); * authsam_make_user_info_dc() steals memory from its struct ldb_message *msg argument; (bso#14993); * Use Heimdal 8.0 (pre) rather than an earlier snapshot; (bso#14995); * Samba autorid fails to map AD users if id rangesize fits in the id range only once; (bso#14967);- Fix mismatched version of libldb2; (bsc#1196788). - Drop obsolete SuSEfirewall2 service files.- Drop obsolete Samba fsrvp v0->v1 state upgrade functionality; (bsc#1080338).- Fix ntlm authentications with "winbind use default domain = yes"; (bso#13126); (bsc#1173429); (bsc#1196308).- Fix samba-ad-dc status warning notification message by disabling systemd notifications in bgqd; (bsc#1195896); (bso#14947).- libldb version mismatch in Samba dsdb component; (bsc#1118508);- Update to 4.15.5 * CVE-2021-44141: UNIX extensions in SMB1 disclose whether the outside target of a symlink exists; (bso#14911); (bsc#1193690). * CVE-2021-44142: Out-of-Bound Read/Write on Samba vfs_fruit module; (bso#14914); (bsc#1194859). * CVE-2022-0336: Re-adding an SPN skips subsequent SPN conflict checks; bso#14950); (bsc#1195048).- CVE-2021-44141: Information leak via symlinks of existance of files or directories outside of the exported share; (bso#14911); (bsc#1193690); - CVE-2021-44142: Out-of-bounds heap read/write vulnerability in VFS module vfs_fruit allows code execution; (bso#14914); (bsc#1194859); - CVE-2022-0336: Samba AD users with permission to write to an account can impersonate arbitrary services; (bso#14950); (bsc#1195048);- Update to 4.15.4 * Duplicate SMB file_ids leading to Windows client cache poisoning; (bso#14928); * Failed to parse NTLMv2_RESPONSE length 95 - Buffer Size Error - NT_STATUS_BUFFER_TOO_SMALL; (bso#14932); * kill_tcp_connections does not work; (bso#14934); * Can't connect to Windows shares not requiring authentication using KDE/Gnome; (bso#14935); * smbclient -L doesn't set "client max protocol" to NT1 before calling the "Reconnecting with SMB1 for workgroup listing" path; (bso#14939); * Cross device copy of the crossrename module always fails; (bso#14940); * symlinkat function from VFS cap module always fails with an error; (bso#14941); * Fix possible fsp pointer deference; (bso#14942); * Missing pop_sec_ctx() in error path inside close_directory(); (bso#14944); * "smbd --build-options" no longer works without an smb.conf file; (bso#14945);- Use pkgconfig(krb5) as dependency for the -devel package: allow OBS to pick the right flavor of krb5-devel (full vs mini). - Do not require the 'krb5' symbol by samba-client-libs: this package has an automatic dependency due to linkage on libgssapi_krb5.so.2. Automatic deps are always better. - Do not require the 'krb5' symbol from samba-libs: samba-libs requires samba-client-libs, which in turn requires krb5 libraries. Samba-libs itself has no need for krb5 (but get it indirectly anyway).- Reorganize libs packages. Split samba-libs into samba-client-libs, samba-libs, samba-winbind-libs and samba-ad-dc-libs, merging samba public libraries depending on internal samba libraries into these packages as there were dependency problems everytime one of these public libraries changed its version (bsc#1192684). The devel packages are merged into samba-devel. - Rename package samba-core-devel to samba-devel - Add python-rpm-macros to build requirements - Update the symlink create by samba-dsdb-modules to private samba ldb modules following libldb2 changes from /usr/lib64/ldb/samba to /usr/lib64/ldb2/modules/ldb/samba- Update to 4.15.3 * Recursive directory delete with veto files is broken in 4.15.0; (bso#14878); * A directory containing dangling symlinks cannot be deleted by SMB2 alone when they are the only entry in the directory; (bso#14879); * SIGSEGV in rmdir_internals/synthetic_pathref - dirfsp is used uninitialized in rmdir_internals(); (bso#14892); * MaxQueryDuration not honoured in Samba AD DC LDAP; (bso#14694); * The CVE-2020-25717 username map [script] advice has undesired side effects for the local nt token; (bso#14901); (bsc#1192849); * User with multiple spaces (eg FredNurk) become un-deletable; (bso#14902); * Avoid storing NTTIME_THAW (-2) as value on disk; (bso#14127); * smbXsrv_client_global record validation leads to crash if existing record points at non-existing process; (bso#14882); * Crash in vfs_fruit asking for fsp_get_io_fd() for an XATTR call; (bso#14890); * Samba process doesn't log to logfile; (bso#14897); * set_ea_dos_attribute() fallback calling get_file_handle_for_metadata() triggers locking.tdb assert; (bso#14907); * Kerberos authentication on standalone server in MIT realm broken; (bso#14922); * Segmentation fault when joining the domain; (bso#14923); * Support for ROLE_IPA_DC is incomplete; (bso#14903); * rpcclient cannot connect to ncacn_ip_tcp services anymore; (bso#14767); * winexe crashes since 4.15.0 after popt parsing; (bso#14893); * net ads status -P broken in a clustered environment; (bso#14908); * Memory leak if ioctl(FSCTL_VALIDATE_NEGOTIATE_INFO) fails before smbd_smb2_ioctl_send; (bso#14788); * winbindd doesn't start when "allow trusted domains" is off; (bso#14899); * smbclient login without password using '-N' fails with NT_STATUS_INVALID_PARAMETER on Samba AD DC; (bso#14883); * A schannel client incorrectly detects a downgrade connecting to an AES only server; (bso#14912); * Possible null pointer dereference in winbind; (bso#14921); * Fix -k legacy option for client tools like smbclient, rpcclient, net, etc.; (bso#14846); * Add Debian 11 CI bootstrap support; (bso#14872); * Crash in recycle_unlink_internal(); (bso#14888);- Fix dependency problem upgrading from libndr0 to libndr2 and from libsamba-credentials0 to libsamba-credentials1; (bsc#1192684);- Fix regression introduced by CVE-2020-25717 patches, winbindd does not start when 'allow trusted domains' is off; (bso#14899); - Update to 4.15.2 * CVE-2016-2124: SMB1 client connections can be downgraded to plaintext authentication; (bso#12444); (bsc#1014440); * CVE-2020-25717: A user on the domain can become root on domain members; (bso#14556); (bsc#1192284); * CVE-2020-25718: Samba AD DC did not correctly sandbox Kerberos tickets issued by an RODC; (bso#14558); (bsc#1192246); * CVE-2020-25719: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets; (bso#14561); (bsc#1192247); * CVE-2020-25721: Kerberos acceptors need easy access to stable AD identifiers (eg objectSid); (bso#14557); (bsc#1192505); * CVE-2020-25722: Samba AD DC did not do suffienct access and conformance checking of data stored; (bso#14564); (bsc#1192283); * CVE-2021-3738: Use after free in Samba AD DC RPC server; (bso#14468); (bsc#1192215); * CVE-2021-23192: Subsequent DCE/RPC fragment injection vulnerability; (bso#14875); (bsc#1192214); - Update to 4.15.1 * vfs_shadow_copy2: core dump in make_relative_path; (bso#14682); * Log clutter from filename_convert_internal; (bso#14685); * MacOSX compilation fixes; (bso#14862); * rodc_rwdc test flaps; (bso#14868); * Provide a fix for MS CVE-2020-17049 in Samba [SECURITY] 'Bronze bit' S4U2Proxy Constrained Delegation bypass in Samba with embedded Heimdal; (bso#14642); * Python ldb.msg_diff() memory handling failure; (bso#14836); * "in" operator on ldb.Message is case sensitive; (bso#14845); * Release LDB 2.4.1 for Samba 4.15.1; (bso#14848); * samldb_krbtgtnumber_available() looks for incorrect string; (bso#14854); * Fix Samba support for UF_NO_AUTH_DATA_REQUIRED; (bso#14871); * Allow special chars like "@" in samAccountName when generating the salt; (bso#14874); * Correctly ignore comments in CTDB public addresses file; (bso#14826); * Fix transit path validation; (bso#12998); * Fix that child winbindd logs to log.winbindd instead of log.wb-; (bso#14852); * SMB3 cancel requests should only include the MID together with AsyncID when AES-128-GMAC is used; (bso#14855); * Prepare to operate with MIT krb5 >= 1.20; (bso#14870); * Heimdal prefers RC4 over AES for machine accounts; (bso#14864);- Enable samba-tool without ad dc.- Adjust spec to use pam macros; (bsc#1191046).- Adjust spec for size * allow some Recommends instead Requires to be configured for cifs-utils, samba-libs-python3 & samba-gpupdate; (bsc#1182847). * remove fam, undocumented and unneeded.- Add missing build dependency on bison when building with the embedded Heimdal Kerberos- Update to 4.15.0 * Removed SMB development dialects SMB2_22, SMB2_24 and SMB3_10 * VFS layer modernized. * Add the ability to set allow/deny lists for zone transfer clients in Bind DLZ plugin * Server multi-channel support no longer experimental * Improved command line user experience, unifying the options in different commands * Winbindd no longer scans trusted domains on startup and will use enterprise principals by default. * The net utility is now able to support the offline domain join feature * New options for 'samba-tool dns zoneoptions' for aging control and to mark old records as static or dynamic * DNS tombstones are now deleted as appropriate and use a consistent timestamp format * The 'samba-tool dns update' command validates and rejects now malformed IPv4 and IPv6 addresses * The 'samba-tool domain backup' command correctly takes out locks against concurrent modification during backup when using the LMDB backend * TruACL support has been removed * NIS support has been removed- Fix 'net rpc' authentication when using the machine account; (bsc#1189017); (bso#14796);- Fix dependency problem upgrading from libndr0 to libndr1; (bsc#1189875); - Fix dependency problem upgrading from libsmbldap0 to libsmbldap2; (bsc#1189875); - Fix wrong kvno exported to keytab after net ads changetrustpw due to replication delay; (bsc#1188727); - Add Certificate Auto Enrollment Policy; (jsc#SLE-18456). - Update to 4.13.10 * s3: smbd: Ensure POSIX default ACL is mapped into returned Windows ACL for directory handles; (bso#14708); * Take a copy to make sure we don't reference free'd memory; (bso#14721); * s3: lib: Fix talloc heirarcy error in parent_smb_fname(); (bso#14722); * s3: smbd: Remove erroneous TALLOC_FREE(smb_fname_parent) in change_file_owner_to_parent() error path; (bso#14736); * samba-tool: Give better error information when the 'domain backup restore' fails with a duplicate SID; (bso#14575); * smbd: Correctly initialize close timestamp fields; (bso#14714); * Spotlight RPC service doesn't work with vfs_glusterfs; (bso#14740); * ctdb: Fix a crash in run_proc_signal_handler(); (bso#14475); * gensec_krb5: Restore ipv6 support for kpasswd; (bso#14750); * smbXsrv_{open,session,tcon}: Protect smbXsrv_{open,session,tcon}_global_traverse_fn against invalid records; (bso#14752); * samba-tool domain backup offline doesn't work against bind DLZ backend; (bso#14027); * netcmd: Use next_free_rid() function to calculate a SID for restoring a backup; (bso#14669); - Update to 4.13.9 * s3: smbd: SMB1 SMBsplwr doesn't send a reply packet on success; (bso#14696); * Add documentation for dsdb_group_audit and dsdb_group_json_audit to "log level", synchronise "log level" in smb.conf with the code; (bso#14689); * Fix smbd panic when two clients open same file; (bso#14672); * Fix memory leak in the RPC server; (bso#14675); * s3: smbd: Fix deferred renames; (bso#14679); * s3-iremotewinspool: Set the per-request memory context; (bso#14675); * rpc_server3: Fix a memleak for internal pipes; (bso#14675); * third_party: Update socket_wrapper to version 1.3.2; (bso#11899); * third_party: Update socket_wrapper to version 1.3.3; (bso#14639); * idmap_rfc2307 and idmap_nss return wrong mapping for uid/gid conflict; (bso#14663); * Fix the build on OmniOS; (bso#14288); - Update to 4.13.8 * CVE-2021-20254: Fix buffer overrun in sids_to_unixids(); (bso#14571 - Update to 4.13.7 * Release with dependency on ldb version 2.2.1.- CVE-2021-20254 Buffer overrun in sids_to_unixids(); (bnc#14571); (bsc#1184677).- Fix offline domain backup not possible using lmdb version >= 0.9.26; (bso#14676); - Require libldb >= 2.2.1; (bsc#1183572); (bsc#1183574); - Update to 4.13.6 * CVE-2020-27840: samba: Unauthenticated remote heap corruption via bad DNs; (bso#14595); (bsc#1183572). * CVE-2021-20277: samba: out of bounds read in ldb_handler_fold; (bso#14655); (bsc#1183574). - Update to 4.13.5 * s3:modules:vfs_virusfilter: Recent talloc changes cause infinite start-up failure; (bso#14634); * s3: libsmb: Add missing cli_tdis() in error path if encryption setup failed on temp proxy connection; (bso#13992); * smbd: In conn_force_tdis_done() when forcing a connection closed force a full reload of services; (bso#14604); * dbcheck: Check Deleted Objects and reduce noise in reports about expired tombstones (bso#14593); * s3: Fix fcntl waf configure check; (bso#14503); * s3/auth: Implement "winbind:ignore domains"; (bso#14602); * smbd: Use fsp->conn->session_info for the initial delete-on-close token; (bso#14617); * s3: VFS: nfs4_acls. Add missing TALLOC_FREE(frame) in error path; (bso#14648); * classicupgrade: Treat old never expires value right; (bso#14624); * g_lock: Fix uninitalized variable reads; (bso#14636); * s3:pysmbd: Fix fd leak in py_smbd_create_file(); (bso#13898); * lib:util: Avoid free'ing our own pointer; (bso#14625); * HEIMDAL: krb5_storage_free(NULL) should work; (bso#12505);- Spec file fixes around systemd and requires; (bsc#1182830); - Align systemd service unit files with upstream provided ones.- Update to 4.13.4 * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * lib: Avoid declaring zero-length VLAs in various messaging functions; (bso#14605); * Do not create an empty DB when accessing a sam.ldb; (bso#14579); * vfs_fruit may close wrong backend fd; (bso#14596); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * vfs_virusfilter: Allocate separate memory for config char*; (bso#14606); * vfs_fruit may close wrong backend fd; (bso#14596); * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * The cache directory for the user gencache should be created recursively; (bso#14601); * Be more flexible with repository names in CentOS 8 test environments; (bso#14594);- Uninstalling samba-client: Failed to disable unit, cifs.service does not exists; (bsc#1180388);- Update to 4.13.3 + libcli: smb2: Never print length if smb2_signing_key_valid() fails for crypto blob; (bso#14210); + s3: modules: gluster. Fix the error I made in preventing talloc leaks from a function; (bso#14486); + s3: smbd: Don't overwrite contents of fsp->aio_requests[0] with NULL via TALLOC_FREE(); (bso#14515); + s3: spoolss: Make parameters in call to user_ok_token() match all other uses; (bso#14568); + s3: smbd: Quiet log messages from usershares for an unknown share; (bso#14590); + samba process does not honor max log size; (bso#14248); + vfs_zfsacl: Add missing inherited flag on hidden "magic" everyone@ ACE; (bso#14587); + s3-libads: Pass timeout to open_socket_out in ms; (bso#13124); + s3-vfs_glusterfs: Always disable write-behind translator; (bso#14486); + smbclient: Fix recursive mget; (bso#14517); + clitar: Use do_list()'s recursion in clitar.c; (bso#14581); + manpages/vfs_glusterfs: Mention silent skipping of write-behind translator; (bso#14486); + vfs_shadow_copy2: Preserve all open flags assuming ROFS; (bso#14573); + interface: Fix if_index is not parsed correctly; (bso#14514);- Update to 4.13.2 + s3: modules: vfs_glusterfs: Fix leak of char **lines onto mem_ctx on return; (bso#14486); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471); + smb.conf.5: Add clarification how configuration changes reflected by Samba; (bso#14538); + daemons: Report status to systemd even when running in foreground; (bso#14552); + DNS Resolver: Support both dnspython before and after 2.0.0; (bso#14553); + s3-vfs_glusterfs: Refuse connection when write-behind xlator is present; (bso#14486); + provision: Add support for BIND 9.16.x; (bso#14487); + ctdb-common: Avoid aliasing errors during code optimization; (bso#14537); + libndr: Avoid assigning duplicate versions to symbols; (bso#14541); + docs: Fix default value of spoolss:architecture; (bso#14522); + winbind: Fix a memleak; (bso#14388); + s4:dsdb:acl_read: Implement "List Object" mode feature; (bso#14531); + docs-xml/manpages: Add warning about write-behind translator for vfs_glusterfs; (bso#14486); + nsswitch/nsstest.c: Avoid nss function conflicts with glibc nss.h. + vfs_shadow_copy2: Avoid closing snapsdir twice; (bso#14530); + third_party: Update resolv_wrapper to version 1.1.7; (bso#14547); + examples:auth: Do not install example plugin; (bso#14550); + ctdb-recoverd: Drop unnecessary and broken code; (bso#14513); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471);- Adjust smbcacls '--propagate-inheritance' feature to align with upstream; (bsc#1178469).- Update to samba 4.13.1 + CVE-2020-14383: An authenticated user can crash the DCE/RPC DNS with easily crafted records; (bsc#1177613); (bso#14472); + CVE-2020-14323: Unprivileged user can crash winbind; (bsc#1173994); (bso#14436); + CVE-2020-14318: Missing handle permissions check in SMB1/2/3 ChangeNotify; (bsc#1173902); (bso#14434); - Adjust systemd tmpfiles.d configuration, use /run/samba instead of /var/run/samba; (bsc#1177355);- Fix vfs_ceph query_directory regression; (bso#14519) - Drop liburing-devel for SLE15-SP2; (bsc#1177245)- Register CTDB recovery lock holder with ceph-mgr - Add liburing-devel dependency- Update to samba 4.13.0 + Require Python 3.6 + Move wide links functionality into VFS module + Deprecate NT4-like 'classic' Samba domain controllers + Deprecate SMBv1 only protocol options + Remove deprecated "ldap ssl ads" option + Unify asynchronous DCE-RPC server; (jsc#SES-645) + Replay multichannel lease break requests; (bso#11897); (jsc#SES-655) + Drop internal byteorder.h header from util-devel package + Remove final code for the AD DC LDAP backend + Add AD DC Group Policy Scripts + Only use gnutls_aead_cipher_encryptv2() for GnuTLS > 3.6.14; (bso#14399) + Fix %U substitutions if it contains a domain name; (bso#14467) + Fix krb5.conf creation for 'net ads join'; (bso#14479) + Fix build problem if libbsd-dev is not installed; (bso#14482) + Toggle vfs_snapper using "--with-shared-modules"; (bso#14437) + Fix idmap_ad RFC4511 response handling; (bso#14465) + Fix panic in get_lease_type(); (bso#14428)- Update to samba 4.11.13 + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Protect netr_ServerPasswordSet2 against unencrypted passwords; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Support "server require schannel:WORKSTATION$ = no" about unsecure configurations; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s4 torture rpc: repeated bytes in client challenge; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): libcli/auth: Reject weak client challenges in netlogon_creds_server_init() "server require schannel:WORKSTATION$ = no"; (bsc#1176579); (bso#14497); - Update to samba 4.11.12 + s3: libsmb: Fix SMB2 client rename bug to a Windows server; (bso#14403); + dsdb: Allow "password hash userPassword schemes = CryptSHA256" to work on RHEL7; (bso#14424); + dbcheck: Allow a dangling forward link outside our known NCs; (bso#14450); + lib/debug: Set the correct default backend loglevel to MAX_DEBUG_LEVEL; (bso#14426); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + lib/util: do not install "test_util_paths"; (bso#14370); + lib:util: Fix smbclient -l basename dir; (bso#14345); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + util: Allow symlinks in directory_create_or_exist; (bso#14166); + docs: Fix documentation for require_membership_of of pam_winbind; (bso#14358); + s3:winbind:idmap_ad: Make failure to get attrnames for schema mode fatal; (bso#14425);- Add obsoletes to libsmbldap2 package to fix upgrades from previous versions; (bsc#1172810);- Fix net command unable to negotiate SMB2; (bsc#1174120);- Update to samba 4.11.11 + CVE-2020-10730: NULL de-reference in AD DC LDAP server when ASQ and VLV combined; (bso#14364); (bsc#1173159] + CVE-2020-10745: invalid DNS or NBT queries containing dots use several seconds of CPU each; (bso#14378); (bsc#1173160). + CVE-2020-10760: Use-after-free in AD DC Global Catalog LDAP server with paged_result or VLV; (bso#14402); (bsc#1173161) + CVE-2020-14303: Endless loop from empty UDP packet sent to AD DC nbt_server; (bso#14417); (bsc#1173359). - Update to samba 4.11.10 + Fix segfault when using SMBC_opendir_ctx() routine for share folder that contains incorrect symbols in any file name; (bso#14374). + vfs_shadow_copy2 doesn't fail case looking in snapdirseverywhere mode; (bso#14350) + ldb_ldap: Fix off-by-one increment in lldb_add_msg_attr; (bso#14413). + Malicous SMB1 server can crash libsmbclient; (bso#14366) + winbindd: Fix a use-after-free when winbind clients exit; (bso#14382) + ldb: Bump version to 2.0.11, LMDB databases can grow without bounds. (bso#14330) - Update to samba 4.11.9 + nmblib: Avoid undefined behaviour in handle_name_ptrs(); (bso#14242). + 'samba-tool group' commands do not handle group names with special chars correctly; (bso#14296). + smbd: avoid calling vfs_file_id_from_sbuf() if statinfo is not valid; (bso#14237). + Missing check for DMAPI offline status in async DOS attributes; (bso#14293). + smbd: Ignore set NTACL requests which contain S-1-5-88 NFS ACEs; (bso#14307). + vfs_recycle: Prevent flooding the log if we're called on non-existant paths; (bso#14316) + smbd mistakenly updates a file's write-time on close; (bso#14320). + RPC handles cannot be differentiated in source3 RPC server; (bso#14359). + librpc: Fix IDL for svcctl_ChangeServiceConfigW; (bso#14313). + nsswitch: Fix use-after-free causing segfault in _pam_delete_cred; (bso#14327). + Fix fruit:time machine max size on arm; (bso#13622) + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294). + ctdb: Fix a memleak; (bso#14348). + libsmb: Don't try to find posix stat info in SMBC_getatr(). + ctdb-tcp: Move free of inbound queue to TCP restart; (bso#14295); (bsc#1162680). + s3/librpc/crypto: Fix double free with unresolved credential cache; (bso#14344); (bsc#1169095) + s3:libads: Fix ads_get_upn(); (bso#14336). + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294) + Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680). + ctdb-recoverd: Avoid dereferencing NULL rec->nodemap; (bso#14324) - Update to samba 4.11.8 + CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850); + CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - Update to samba 4.11.7 + s3: lib: nmblib. Clean up and harden nmb packet processing; (bso#14239). + s3: VFS: full_audit. Use system session_info if called from a temporary share definition; (bso#14283) + dsdb: Correctly handle memory in objectclass_attrs; (bso#14258). + ldb: version 2.0.9, Samba 4.11 and later give incorrect results for SCOPE_ONE searches; (bso#14270) + auth: Fix CIDs 1458418 and 1458420 Null pointer dereferences; (bso#14247). + smbd: Handle EINTR from open(2) properly; (bso#14285) + winbind member (source3) fails local SAM auth with empty domain name; (bso#14247) + winbindd: Handling missing idmap in getgrgid(); (bso#14265). + lib:util: Log mkdir error on correct debug levels; (bso#14253). + wafsamba: Do not use 'rU' as the 'U' is deprecated in Python 3.9; (bso#14266). + ctdb-tcp: Make error handling for outbound connection consistent; (bso#14274). - Update to samba 4.11.6 + pygpo: Use correct method flags; (bso#14209). + vfs_ceph_snapshots: Fix root relative path handling; (bso#14216); (bsc#1141320). + Avoiding bad call flags with python 3.8, using METH_NOARGS instead of zero; (bso#14209). + source4/utils/oLschema2ldif: Include stdint.h before cmocka.h; (bso#14218). + docs-xml/winbindnssinfo: Clarify interaction with idmap_ad etc; (bso#14122). + smbd: Fix the build with clang; (bso#14251). + upgradedns: Ensure lmdb lock files linked; (bso#14199). + s3: VFS: glusterfs: Reset nlinks for symlink entries during readdir; (bso#14182). + smbc_stat() doesn't return the correct st_mode and also the uid/gid is not filled (SMBv1) file; (bso#14101). + librpc: Fix string length checking in ndr_pull_charset_to_null(); (bso#14219). + ctdb-scripts: Strip square brackets when gathering connection info; (bso#14227).- Add libnetapi-devel to baselibs conf, for wine usage; (bsc#1172307);- Installing: samba - samba-ad-dc.service does not exist and unit not found; (bsc#1171437);- Fix samba_winbind package is installing python3-base without python3 package; (bsc#1169521);- Require libldb2 >= 2.0.10 after security release.- CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850);- Fix smbclient crash with double free (with unresolved krb5 credential cache); (bso#14344); (bsc#1169095).- Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680).- CTDB doesn't retry outgoing connections on bind (and some other) failures; (bso#14274); (bsc#1162680).- Revert: Allow idmap_rid to have primary group other than "Domain Users"; (bsc#1087931).- Fix nmbstatus not reporting detailed information about workgroups; (bsc#1159464); - Fix querying all names registered within broadcast area; (bso#8927);- Update to samab 4.11.5 + CVE-2019-14902: Replication of ACLs down subtree on AD Directory is not automatic; (bso#12497); (bsc#1160850). + CVE-2019-19344: Fix server crash with dns zone scavenging = yes; (bso#14050); (bsc#1160852). + CVE-2019-14907: server-side crash after charset conversion failure (eg during NTLMSSP processing); (bso#14208); (bsc#1160888). - Update to samba 4.11.4 + Ensure SMB1 cli_qpathinfo2() doesn't return an inode number; (bso#14161). + Ensure we don't call cli_RNetShareEnum() on an SMB1 connection; (bso#14174). + NT_STATUS_ACCESS_DENIED becomes EINVAL when using SMB2 in SMBC_opendir_ctx; (bso#14176). + SMB2 - Ensure we use the correct session_id if encrypting an interim response; (bso#14189). + Prevent smbd crash after invalid SMB1 negprot; (bso#14205). + printing: Fix %J substition; (bso#13745). + Remove now unneeded call to cmdline_messaging_context(); (bso#13925). + Fix incomplete conversion of former parametric options; (bso#14069). + Fix sync dosmode fallback in async dosmode codepath; (bso#14070). + vfs_fruit returns capped resource fork length; (bso#14171). + libnet_join: Add SPNs for additional-dns-hostnames entries; (bso#14116). + smbd: Increase a debug level; (bso#14211). + Prevent azure ad connect from reporting discovery errors reference-value-not-ldap-conformant; (bso#14153). + krb5_plugin: Fix developer build with newer heimdal system library; (bso#14179). + replace: Only link libnsl and libsocket if required; (bso#14168); + ctdb: Incoming queue can be orphaned causing communication; breakdown; (bso#14175). + ldb: Release ldb 2.0.8. Cross-compile will not take cross-answers or cross-execute; (bso#13846). + heimdal-build: Avoid hard-coded /usr/include/heimdal in asn1_compile-generated code; (bso#13856).- Fix Ceph snapshot root relative path handling; (bso#14216); (bsc#1141320).- Update to samba 4.11.3 + CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). + CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). - CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- Update to samba 4.11.2 + CVE-2019-10218: Client code can return filenames containing path separators; (bsc#1144902); (bso#14071). + CVE-2019-14833: Samba AD DC check password script does not receive the full password; (bso#12438). + CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040). - Fixes from 4.11.1 + Overlinking libreplace against librt and pthread against every binary or library causes issues; (bso#14140); + kpasswd fails when built with MIT Kerberos; (bso#14155); + Fix spnego fallback from kerberos to ntlmssp in smbd server; (bso#14106); + Stale file handle error when using mkstemp on a share; (bso#14137); + non-AES schannel broken; (bso#14134); + Joining Active Directory should not use SAMR to set the password; (bso#13884); + smbclient can blunder into the SMB1 specific cli_RNetShareEnum() call on an SMB2 connection; (bso#14152); + Deleted records can be resurrected during recovery; (bso#14147); + getpwnam and getpwuid need to return data for ID_TYPE_BOTH group; (bso#14141); + winbind does not list forest trusts with additional trust attributes; (bso#14130); + fault report points to outdated documentation; (bso#14139); + pam_winbind with krb5_auth or wbinfo -K doesn't work for users of trusted domains/forests; (bso#14124); + classicupgrade results in uncaught exception - a bytes-like object is required, not 'str'; (bso#14136); + pod2man is not longer required, stop checking at build time; (bso#14131); + Exit code of ctdb nodestatus should not be influenced by deleted nodes; (bso#14129); + username/password authentication doesn't work with CUPS and smbspool; (bso#14128); + smbc_readdirplus() is incompatible with smbc_telldir() and smbc_lseekdir(); (bso#14094);- CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040); (bsc#1154598); - CVE-2019-10218: Client code can return filenames containing path separators; (bso#14071); (bsc#1144902);- CVE-2019-14833: samba: Accent with "check script password" Samba AD DC check password script does not receive the full password; (bso#12438); (bsc#1154289).- Update to samba 4.11.0 + For details on all items see WHATSNEW.txt in samba-doc package + Python2 runtime support removed; python 3.4 or later required + Security improvements: - SMB1 disabled by default - lanman and plaintext authentication deprecated - winbind: PAM_AUTH and NTLM_AUTH events logged - GnuTLS 3.2 required; system FIPS mode setting honored + CephFS Snapshot integration, exposed as previous file versions + ctdb changes: - onnode -o option removed - ctdbd logs when using more than 90% of a CPU thread - CTDB_MONITOR_SWAP_USAGE variable removed + AD Domain controller improvements: - Upgrade AD databse format - BIND9_FLATFILE deprecated - default process model chagned to prefork - bind9 dns operation duration logging - Default schema updated to 2012_R2; function level is unchanged - many performance improvements + Configuration webserver support removed- Fix broken username/password authentication with CUPS and smbspool; (bsc#1152143); (bso#14128).- Fix auth problems when printing via smbspool backend with kerberos; (bnc#1148539); (bso#13832).- Update to samba 4.10.8 + CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267);- Fix build on newer systems by modifying samba.spec to use consistent non-relative paths for pammodules in configure line and specification of pam_winbind.so library to package.- Update to samba 4.10.7 + Unable to create or rename file/directory inside shares configured with vfs_glusterfs_fuse module; (bso#14010). + build: Allow build when '--disable-gnutls' is set; (bso#13844) + samba-tool: Add 'import samba.drs_utils' to fsmo.py; (bso#13973). + Fix 'Error 32 determining PSOs in system' message on old DB with FL upgrade; (bso#14008). + s4/libnet: Fix joining a Windows pre-2008R2 DC; (bso#14021) + join: Use a specific attribute order for the DsAddEntry nTDSDSA object; (bso#14046). + vfs_catia: Pass stat info to synthetic_smb_fname(); (bso#14015). + lookup_name: Allow own domain lookup when flags == 0; (bso#14091). + s4 librpc rpc pyrpc: Ensure tevent_context deleted last; (bso#13932). + DEBUGC and DEBUGADDC doesn't print into a class specific log file; (bso#13915). + Request to keep deprecated option "server schannel", VMWare Quickprep requires "auto"; (bso#13949). + dbcheck: Fallback to the default tombstoneLifetime of 180 days; (bso#13967). + dnsProperty fails to decode values from older Windows versions; (bso#13969). + samba-tool: Use only one LDAP modify for dns partition fsmo role transfer; (bso#13973). + third_party: Update waf to version 2.0.17; (bso#13960). + netcmd: Allow 'drs replicate --local' to create partitions; (bso#14051). + ctdb-config: Depend on /etc/ctdb/nodes file; (bso#14017).- CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267).- Prepare for use future use of kernel keyrings, modify /etc/pam.d/samba to include pam_keyinit.so; (bsc#1144059).- Update samba-winbind script to work with systemd; (bsc#1132739); - Drop samba dhcpcd hook scripts - Update to samba 4.10.6 + s3: winbind: Fix crash when invoking winbind idmap scripts; (bso#13956). + smbd does not correctly parse arguments passed to dfree and quota scripts; (bso#13964). + samba-tool dns: use bytes for inet_ntop; (bso#13965). + samba-tool domain provision: Fix --interactive module in python3; (bso#13828). + ldb_kv: Skip @ records early in a search full scan; (bso#13893). + docs: Improve documentation of "lanman auth" and "ntlm auth" connection; (bso#13981). + python/ntacls: Use correct "state directory" smb.conf option instead of "state dir"; (bso#14002). + registry: Add a missing include; (bso#13840). + Fix SMB guest authentication; (bso#13944). + AppleDouble conversion breaks Resourceforks; (bso#13958). + vfs_fruit makes direct use of syscalls like mmap() and pread(); (bso#13968). + s3:mdssvc: Fix flex compilation error; (bso#13987). + s3/vfs_glusterfs[_fuse]: Avoid using NAME_MAX directly; (bso#13872). + dsdb:samdb: schemainfo update with relax control; (bso#13799). + s3:util: Move static file_pload() function to lib/util; (bso#13964). + smbd: Fix a panic; (bso#13957). + ldap server: Generate correct referral schemes; (bso#12478). + s4 dsdb/repl_meta_data: fix use after free in dsdb_audit_add_ldb_value; (bso#13941). + s4 dsdb: Fix use after free in samldb_rename_search_base_callback; (bso#13942). + dsdb/repl: we need to replicate the whole schema before we can apply it; (bso#12204). + ldb: Release ldb 1.5.5; (bso#12478). + Schema replication fails if link crosses chunk boundary backwards; (bso#13713). + 'samba-tool domain schemaupgrade' uses relax control and skips the schemaInfo update provision; (bso#13799). + dsdb_audit: avoid printing "... remote host [Unknown] SID [(NULL SID)] ..."; (bso#13916). + python/ntacls: We only need security.SEC_STD_READ_CONTROL in order to get the ACL; (bso#13917). + s3:loadparm: Ensure to truncate FS Volume Label at multibyte boundary; (bso#13947). + Using Kerberos credentials to print using spoolss doesn't work; (bso#13939). + wafsamba: Use native waf timer; (bso#13998). + ctdb-scripts: Fix tcp_tw_recycle existence check; (bso#13984).- Update to samba-4.10.5 (including updates for 4.10.4, 4.10.3) + CVE-2019-12435 rpc/dns: Avoid NULL deference if zone not found in DnssrvOperation2; (bso#13922); (bsc#1137815). + CVE-2019-12436 dsdb/paged_results: Ignore successful results without messages; (bso#13951); (bsc#1137816). - Update to samba-4.10.4 + s3: SMB1: Don't allow recvfile on stream fsp's; (bso#13938). + py/provision: Fix for Python 2.6; (bso#13882). + netcmd: Fix 'passwordsettings --max-pwd-age' command; (bso#13873). + s3-libnet_join: 'net ads join' to child domain fails when using "-U admin@forestroot"; (bso#13861). + vfs_ceph: Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245). + vfs_ceph: Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). + ctdb-common: Avoid race between fd and signal events; (bso#13895). + ctdb-common: Fix memory leak in run_proc; (bso#13943). + lib: Initialize getline() arguments; (bso#13892). + winbind: Fix overlapping id ranges; (bco#13903). + lib util debug: Increase format buffer to 4KiB; (bso#13902). + nsswitch pam_winbind: Fix Asan use after free; (bso#13927). + s4 lib socket: Ensure address string owned by parent struct; (bso#13929). + s3 rpc_client: Fix Asan stack use after scope; (bso#13936). + s3:smbd: Handle IO_REPARSE_TAG_DFS in SMB_FIND_FILE_FULL_DIRECTORY_INFO; (bso#10097). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#10344). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#12845). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#13698). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#13796). + dbcheck: Fix the err_empty_attribute() check; (bso#13843). + vfs_snapper: Drop unneeded fstat handler; (bso#13858). + vfs_default: Fix vfswrap_offload_write_send() NT_STATUS_INVALID_VIEW_SIZE check; (bso#13862). + smb2_server: Grant all 8192 credits to clients; (bso#13863). + smbd: Implement SMB_FILE_NORMALIZED_NAME_INFORMATION handling; (bso#13919). + s3/vfs_glusterfs: Dynamically determine NAME_MAX; (bso#13872). + s3: modules: ceph: Use current working directory instead of share path; (bso#13918); (bsc#1134452). + winbind: Use domain name from lsa query for sid_to_name cache entry; (bso#13831). + memcache: Increase size of default memcache to 512k; (bso#13865). + docs: Update smbclient manpage for "--max-protocol"; (bso#13857). + s3:utils: If share is NULL in smbcacls, don't print it; (bso#13937). + s3:smbspool: Fix regression printing with Kerberos credentials; (bso#13939). + ctdb-scripts: CTDB restarts failed NFS RPC services by hand, which is incompatible with systemd; (bso#13860). + ctdb-daemon: Revert "We can not assume that just because we could complete a TCP handshake"; (bso#13888). + ctdb-daemon: Never use 0 as a client ID; (bso#13930). + ctdb-common: Fix memory leak; (bso#13943). + s3:debug: Enable logging for early startup failures; (bso#13904) - Update to samba-4.10.3 + CVE-2018-16860: Heimdal KDC: Reject PA-S4U2Self with unkeyed checksum; (bso#13685); (bsc#1134024).- CVE-2019-12435: zone operations can crash rpc server; (bso#13922); (bsc#1137815).- Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). - Add ceph_snapshots VFS module; (jsc#SES-183).- Fix vfs_ceph realpath; (bso#13918); (bsc#1134452).- Update to samba-4.10.2: + CVE-2019-3870 (World writable files in Samba AD DC private/ dir); (bso#13834). + CVE-2019-3880 (Save registry file outside share as unprivileged user); (bso#13851). + py/kcc_utils: py2.6 compatibility; (bso#13837). + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869). + regfio: Improve handling of malformed registry hive files; (bso#13840). + ctdb-version: Simplify version string usage; (bso#13789). + lib: Make fd_load work for non-regular files; (bso#13859). + dbcheck: in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816). + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818). + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854). + acl_read: Fix regression for empty lists; (bso#13836). + s4:dlz make b9_has_soa check dc=@ node; (bso#13841). + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832). + s4:librpc: Fix installation of Samba; (bso#13847). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853). * ctdb-build: Drop creation of .distversion in tarball; (bso#13789). * ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838). - Update to samba-4.10.1: + py/kcc_utils: py2.6 compatibility; (bso#13837); + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869); + regfio: Improve handling of malformed registry hive files; (bso#13840); + ctdb-version: Simplify version string usage; (bso#13789); + lib: Make fd_load work for non-regular files; (bso#13859); + dbcheck in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816); + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818); + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854); + acl_read: Fix regression for empty lists; (bso#13836); + s4:dlz make b9_has_soa check dc=@ node; (bso#13841); + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832); + s4:librpc: Fix installation of Samba; (bso#13847); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853); + ctdb-build: Drop creation of .distversion in tarball; (bso#13789); + ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838); - Update to samba-4.10.0: + s4-server: Open and close a transaction on sam.ldb at startup; (bso#13760); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s4/scripting/bin: Open unicode files with utf8 encoding and write + unicode string. + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + Fix idmap cache pollution with S-1-22- IDs on winbind hickup; (bso#13813); + passdb: Update ABI to 0.27.2. + lib/winbind_util: Add winbind_xid_to_sid for --without-winbind; (bso#13813); + lib:util: Move debug message for mkdir failing to log level 1; (bso#13823);- MacOS credit accounting breaks with async SESSION SETUP; (bsc#1125601); (bso#13796). - Mac OS X SMB2 implmenetation sees Input/output error or Resource temporarily unavailable and drops connection; (bso#13698)- Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245).- CVE-2019-3880: Save registry file outside share as unprivileged user; (bso#13851); (bsc#1131060 ).- CVE-2019-3870 pysmbd: missing restoration of original umask after umask(0); (bso#13834); (bsc#1130703);- Update to samba-4.9.5 + audit_logging: Remove debug log header and JSON Authentication: prefix; (bso#13714); + Fix upgrade from 4.7 (or earlier) to 4.9; (bso#13760); + s3: lib: nmbname: Ensure we limit the NetBIOS name correctly; (bso# CID: 1433607; (bso#11495); + smbd: uid: Don't crash if 'force group' is added to an existing share connection; (bso#13690); + s3: VFS: vfs_fruit. Fix the NetAtalk deny mode compatibility code; (bso#13770); + s3: SMB1 POSIX mkdir does case insensitive name lookup; (bso#13803); + s3:utils/smbget fix recursive download with empty source directories; (bso#13199); + samba-tool drs showrepl: Do not crash if no dnsHostName found; (bso#13716); + s3:libsmb: cli_smb2_list() can sometimes fail initially on a connection; (bso#13736); + join: Throw CommandError instead of Exception for simple errors; (bso#13747); + ldb: Avoid inefficient one-level searches; (bso#13762); + s3: libsmb: use smb2cli_conn_max_trans_size() in cli_smb2_list(); (bso#13736); + tldap: Avoid use after free errors; (bso#13776); + Fix idmap xid2sid cache churn; (bso#13802); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s3-smbd: Avoid assuming fsp is always intact after close_file call; (bso#13720); + s3-vfs-fruit: Add close call; (bso#13725); + s3-smbd: Use fruit:model string for mDNS registration; (bso#13746); + s3-vfs: add glusterfs_fuse vfs module; (bso#13774); + printing: Check lp_load_printers() prior to pcap cache update; (bso#13766); + vfs_ceph: vfs_ceph strict_allocate_ftruncate calls (local FS) ftruncate and fallocate; (bso#13807); + lib/audit_logging: Actually create talloc; (bso#13737); + netcmd/user: python[3]-gpgme unsupported and replaced by python[3]-gpg; (bso#13728); + dns: Changing onelevel search for wildcard to subtree; (bso#13738); + samba-tool: Don't print backtrace on simple DNS errors; (bso#13721); + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + ctdb: Print locks latency in machinereadable stats; (bso#13742); + messages_dgm: Messaging gets stuck when pids are recycled; (bso#13786); + audit_logging: auth_json_audit required auth_json; (bso#13715); + man pages: Document prefork process model; (bso#13765); + CVE-2019-3824 ldb: Release ldb 1.4.6; (bso#13773); + s3:auth: ignore create_builtin_guests() failing without a valid idmap configuration; (bso#13697); + s3:auth_winbind: Ignore a missing winbindd as NT4 PDC/BDC without trusts; (bso#13722); + s3:auth_winbind: return NT_STATUS_NO_LOGON_SERVERS if winbindd is not available; (bso#13723); + s4:server: Add support for 'smbcontrol samba shutdown' and 'smbcontrol debug/debuglevel'; (bso#13752); + Python: Ensure ldb.Dn can doesn't rencoded str with py2; (bso#13616); + vfs_glusterfs: Adapt to changes in libgfapi signatures; (bso#13330); + s3-vfs: Use ENOATTR in errno comparison for getxattr; (bso#13774); + notifyd: Fix SIGBUS on sparc; (bso#13704); + waf: Check for libnscd; (bso#13787); + s3:vfs: Correctly check if OFD locks should be enabled or not; (bso#13770); + lib/util: Count a trailing line that doesn't end in a newline; (bso#13717); + Recovery lock bug fixes; (bso#13800); + s3: net: Do not set NET_FLAGS_ANONYMOUS with -k; (bso#13726); + s3:libsmb: Honor disable_netbios option in smbsock_connect_send; (bso#13727); + vfs_fileid: Fix get_connectpath_ino; (bso#13741); + vfs_fileid: Fix fsname_norootdir algorithm; (bso#13744);- Fix vfs_ceph ftruncate and fallocate handling; (bso#13807); (bsc#1127153).- Fix update-apparmor-samba-profile script after apparmor switched to using named profiles. The change is backwards compatible; (bsc#1126377);- LoadParm().load_default() fails with "Unable to load default file"; (bsc#1089758);- Abide by load_printers smb.conf parameter; (bso#13766); (bsc#1124223);- Update to samba-4.9.4 + libcli/smb: Don't overwrite status code; (bso#9175). + wbinfo --group-info 'NT AUTHORITY\System' does not work; (bso#12164). + Session setup reauth fails to sign response; (bso#13661). + vfs_fruit: Validation of writes on AFP_AfpInfo stream; (bso#13677). + vfs_shadow_copy2: Nicely deal with attempts to open previous version for writing; (bso#13688). + Restoring previous version of stream with vfs_shadow_copy2 fails with NT_STATUS_OBJECT_NAME_INVALID fsp->base_fsp->fsp_name; (bso#13455). + CVE-2018-16853: Fix S4U2Self crash with MIT KDC build; (bso#13571). + s3-vfs: Prevent NULL pointer dereference in vfs_glusterfs; (bso#13708) + PEP8: fix E231: missing whitespace after ','. + winbindd: Fix crash when taking profiles;(bso#13629) + CVE-2018-14629 dns: Fix CNAME loop prevention using counter regression; (bso#13600) + 'samba-tool user syscpasswords' fails on a domain with many DCs; (bso#13686). + CVE-2018-16853: Do not segfault if client is not set; (bso#13571). + lib:util: Fix DEBUGCLASS pointer initializiation; (bso#13679) + ctdb-daemon: Exit with error if a database directory does not exist; (bso#13696). + s3:libads: Add net ads leave keep-account option; (bso#13498).- Drop more %if..%endif guards which are idempotent. - Drop requires on ldconfig which are already auto-discovered. - Do not ignore errors from useradd/groupadd.- Remove python2 build dependency from samba-libs; (bsc#1116900);- Update update-apparmor-samba-profile script to ignore the shares's paths containing substitution variables in any place, not only at the beginning of the path.- Update to samba-4.9.3 + CVE-2018-14629: Unprivileged adding of CNAME record causing loop in AD Internal DNS server; (bso#13600); (bsc#1116319); + CVE-2018-16841: Double-free in Samba AD DC KDC with PKINIT; (bso#13628); (bsc#1116320); + CVE-2018-16851: NULL pointer de-reference in Samba AD DC LDAP server; (bso#13674); (bsc#1116322); + CVE-2018-16852: NULL pointer de-reference in Samba AD DC DNS servers; (bso#13669); (bsc#1116321); + CVE-2018-16853: Samba AD DC S4U2Self crash in experimental MIT Kerberos configuration (unsupported); (bso#13678); (bsc#1116324); + CVE-2018-16857: Bad password count in AD DC not always effective; window; (bso#13683); (bsc#1116323);- Update to samba-4.9.2 + dsdb: Add comments explaining the limitations of our current backlink behaviour; (bso#13418); + Fix problems running domain backups (handling SMBv2, sites); (bso#13621); + testparm: Fix crashes with PANIC: Messaging not initialized on SLES 12 SP3; (bso#13465); + Make vfs_fruit able to cleanup AppleDouble files; (bso#13642); + File saving issues with vfs_fruit on samba >= 4.8.5; (bso#13646); + Enabling vfs_fruit looses FinderInfo; (bso#13649); + Cancelling of SMB2 aio reads and writes returns wrong error NT_STATUS_INTERNAL_ERROR; (bso#13667); + Fix CTDB recovery record resurrection from inactive nodes and simplify vacuuming; (bso#13641); + examples: Fix the smb2mount build; (bso#13465); + libtevent: Fix build due to missing open_memstream on Illiumos; (bso#13629); + winbindd_cache: Fix timeout calculation for sid<->name cache; (bso#13662); + dsdb encrypted_secrets: Allow "ldb:// and "mdb://" in file path; (bso#13653); + Extended DN SID component missing for member after switching group membership; (bso#13418); + Return STATUS_SESSION_EXPIRED error encrypted, if the request was encrypted; (bso#13624); + python: Allow forced signing via smb.SMB(); (bso#13621); + lib:socket: If returning early, set ifaces; (bso#13665); + ldb: Bump ldb version to 1.4.3, Python: Ensure ldb.Dn can accept utf8 encoded unicode; (bso#13616); + smbd: Fix DELETE_ON_CLOSE behaviour on files with READ_ONLY attribute; (bso#13673); + waf: Add -fstack-clash-protection; (bso#13601); + winbind: Fix segfault if an invalid passdb backend is configured; (bso#13668); + Fix bugs in CTDB event handling; (bso#13659); + Misbehaving nodes are sometimes not banned; (bso#13670);- lib:socket: If returning early, set ifaces; (bso#13665); (bsc#1111373);- winbind requires latest version of libtevent-util0 to start- Backport latest gpo code from master + Read policy from local gpt cache + Offline policy application + Make group policy extensible via register/unregister gpext + gpext's run via a process_group_policy method- Enable profiling data collection- Change samba-kdc package name to samba-ad-dc - Move samba-ad-dc.service to the samba-ad-dc package- Update to samba-4.9.1 + s3: nmbd: Stop nmbd network announce storm; (bso#13620); + s3-rpcclient: Use spoolss_init_spoolss_UserLevel1 in winspool cmds; (bso#13597); + CTDB recovery lock has some race conditions; (bso#13617); + s3-rpc_client: Advertise Windows 7 client info; (bso#13597); + ctdb-doc: Remove PIDFILE option from ctdbd_wrapper man page; (bso#13610);- Tumbleweed doesn't define the sle_version macro, so we must include a check for suse_version also. Otherwise python3 is disabled on Tumbleweed.- Update to samba-4.9.0 + samba_dnsupdate: Honor 'dns zone scavenging' option, only update if needed; (bso#13605); + wafsamba: Fix 'make -j'; (bso#13606);- Update to samba-4.9.0rc5 + s3: VFS: vfs_full_audit: Ensure smb_fname_str_do_log() only returns absolute pathnames; (bso#13565); + s3: util: Do not take over stderr when there is no log file; (bso#13578); + Durable Reconnect fails because cookie.allow_reconnect is not set; (bso#13549); + krb5-samba: Interdomain trust uses different salt principal; (bso#13539); + vfs_fruit: Don't unlink the main file; (bso#13441); + smbd: Fix a memleak in async search ask sharemode; (bso#13602); + Fix Samba GPO issue when Trust is enabled; (bso#11517); + samba-tool: Add "virtualKerberosSalt" attribute to 'user getpassword/syncpasswords'; (bso#13539); + Fix CTDB configuration issues; (bso#13589); + ctdbd logs an error until it can successfully connect to eventd; (bso#13592);- Update to samba-4.9.0rc4 + s3: smbd: Ensure get_real_filename() copes with empty pathnames; (bso#13585); + samba domain backup online/rename commands force user to specify password on CLI; (bso#13566); + wafsamba/samba_abi: Always hide ABI symbols which must be local; (bso#13579); + Fix a panic if fruit_access_check detects a locking conflict; (bso#13584); + Fix memory and resource leaks; (bso#13567); + python: Fix print in dns_invalid.py; (bso#13580); + Aliasing issue causes incorrect IPv6 checksum; (bso#13588); + Fix CTDB configuration issues; (bso#13589); + s3: vfs: time_audit: fix handling of token_blob in smb_time_audit_offload_read_recv(); (bso#13568);- Add missing zlib-devel dependency which was previously pulled in by libopenssl-devel- Update to samba-4.9.0rc3+git.22.3fff23ae36e + CVE-2018-10858: libsmb: Harden smbc_readdir_internal() against returns from malicious servers; (bso#13453); + CVE-2018-1140: ldbsearch '(distinguishedName=abc)' and DNS query with escapes crashes, ldb: Release LDB 1.3.5 for CVE-2018-1140; (bso#13374); + CVE-2018-10918: cracknames: Fix DoS (NULL pointer de-ref) when not servicePrincipalName is set on a user; (bso#13552); + CVE-2018-10919: acl_read: Fix unauthorized attribute access via searches; (bso#13434); + ctdb_mutex_ceph_rados_helper: Set SIGINT signal handler; (bso#13540); + CVE-2018-1139 libcli/auth: Do not allow ntlmv1 over SMB1 when it is disabled via "ntlm auth"; (bso#13360); + s3-tldap: do not install test_tldap; (bso#13529); + ctdb_mutex_ceph_rados_helper: Fix deadlock via lock renewals; (bso#13540); + CVE-2018-1140 Add NULL check for ldb_dn_get_casefold() in ltdb_index_dn_attr(); (bso#13374); + ctdb-eventd: Fix CID 1438155; (bso#13554); + Fix CIDs 1438243, (Unchecked return value) 1438244 (Unsigned compared against 0), 1438245 (Dereference before null check) and 1438246 (Unchecked return value); (bso#13553); + ctdb: Fix a cut&paste error; (bso#13554); + systemd: Only start smb when network interfaces are up; (bso#13559); + Fix quotas don't work with SMB2; (bso#13553); + s3/smbd: Ensure quota code is only called when quota support detected; (bso#13563); + s3/libsmb: Explicitly set delete_on_close token for rmdir; (bso#13204); + s3:waf: Install eventlogadm to /usr/sbin; (bso#13561); + Shorten description in vfs_linux_xfs_sgid manual; (bso#13562);- Update to samba-4.9.0rc2+git.21.a1069afb007 + s3: smbd: Using "sendfile = yes" with SMB2 can cause CPU spin; (bso#13537); + s3: smbd: Fix path check in smbd_smb2_create_durable_lease_check(); (bso#13535); + samba-tool trust: Support discovery via netr_GetDcName; (bso#13538); + s4-dsdb: Only build dsdb Python modules for AD DC; (bso#13542); + Fix portability issues on freebsd; (bso#13520); + DNS wildcard search does not handle multiple labels correctly; (bso#13536); + samba-tool domain trust: Fix trust compatibility to Windows Server 1709 and FreeIPA; (bso#13308); + Fix portability issues on freebsd; (bso#13520); + ctdb-protocol: Fix CTDB compilation issues; (bso#13545); + ctdb-docs: Replace obsolete reference to CTDB_DEBUG_HUNG_SCRIPT option; (bso#13546); + ctdb-doc: Provide an example script for migrating old configuration; (bso#13550); + ctdb-event: Implement event tool "script list" command; (bso#13551);- Update to samba-4.8.4+git.37.a7a861d7982; + CVE-2018-1139: Weak authentication protocol allowed; (bsc#1095048); (bsc#13360); + CVE-2018-1140: Denial of Service Attack on DNS and LDAP server; (bsc#1095056); (bso#13466); (bso#13374); + CVE-2018-10858: Insufficient input validation on client directory listing in libsmbclient; (bsc#1103411); (bso#13453); + CVE-2018-10918: Denial of Service Attack on AD DC DRSUAPI server; (bsc#1103414); (bso#13552); + CVE-2018-10919: Confidential attribute disclosure from the AD LDAP server; (bsc#1095057); (bso#13434); + s3:winbind: winbind normalize names' doesn't work for users; (bso#12851); + winbind: Fix UPN handling in canonicalize_username(); (bso#13369); + s3: smbd: Fix SMB2-FLUSH against directories; (bso#13428); + samdb: Fix building Samba with gcc 8.1; (bso#13437); + s3:utils: Do not segfault on error in DoDNSUpdate(); (bso#13440); + smbd: Flush dfree memcache on service reload; (bso#13446); + ldb: Save a copy of the index result before calling the + lib/util: No Backtrace given by Samba's AD DC by default; (bso#13454). + s3: smbd: printing: Re-implement delete-on-close semantics for print files missing since 3.5.x; (bso#13457). + python: Fix talloc frame use in make_simple_acl(); (bso#13474). + krb5_wrap: Fix keep_old_entries logic for older Kerberos libraries;(bso#13478). + krb5_plugin: Add winbind localauth plugin for MIT Kerberos; (bso#13480).- Add missing package descriptions; (bsc#1093864); - Fix dependency issue between samba-python and samba-kdc; (bsc#1062876); - Call update-apparmor-samba-profile when running samba-ad-dc; (bsc#1092099);- Update to 4.8.2 + After update to 4.8.0 DC failed with "Failed to find our own NTDS Settings objectGUID" (bso#13335). + fix incorrect reporting of stream dos attributes on a directory (bso#13380). + vfs_ceph: add asynchronous fsync; fake synchronous call (bso#13412). + vfs_ceph: add fake async pwrite/pread send/recv hooks; (bso#13425) + vfs_ceph: Fix memory leak; (bso#13424). + libsmbclient: Fix hard-coded connection error return of ETIMEDOUT; (bso#13419). + s4-lsa: Fix use-after-free in LSA server; (bso#13420). + winbindd: Do re-connect if the RPC call fails in the passdb case; (bso#13430). + cleanupd: Sends MSG_SMB_UNLOCK twice to interested peers; (bso#13416). + cleanupd: Use MSG_SMB_BRL_VALIDATE to signal cleanupd unclean process shutdown; (bso#13414). + ctdb-client: Remove ununsed functions from old client code; (bso#13411). + printing: Return the same error code as windows does on upload failures; (bso#13395). + nsswitch: Fix memory leak in winbind_open_pipe_sock() when the privileged pipe is not accessable; (bso#13400). + s4:lsa_lookup: remove TALLOC_FREE(state) after all dcesrv_lsa_Lookup{Names,Sids}_base_map() calls; (bso#13420). + rpc_server: Fix NetSessEnum with stale sessions; (bso#13407). + s3:smbspool: Fix cmdline argument handling; (bso#13417).- Move libdfs-server-ad-samba4.so library from kdc to libs package, as it is required by some client libs; (bsc#1074135); - Update to 4.8.1; (bsc#1091179); + s3: ldap: Ensure the ADS_STRUCT pointer doesn't get freed on error, we don't own it here; (bso#13244); + s3: smbd: Fix possible directory fd leak if the underlying OS doesn't support fdopendir(); (bso#13270); + Round-tripping ACL get/set through vfs_fruit will increase the number of ACE entries without limit; (bso#13319); + s3: smbd: SMB2: Add DBGC_SMB2_CREDITS class to specifically debug credit issues; (bso#13347); + s3: smbd: Files or directories can't be opened DELETE_ON_CLOSE without delete access; (bso#13358); + s3: smbd: Fix memory leak in vfswrap_getwd(); (bso#13372); + s3: smbd: Unix extensions attempts to change wrong field in fchown call; (bso#13375); + ms_schema/samba-tool visualize: Fix python2.6 incompatibility; (bso#13337); + Fix invocation of gnutls_aead_cipher_encrypt(); (bso#13352); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + winbindd: Recover loss of netlogon secure channel in case the peer DC is rebooted; (bso#13332); + s3:smbd: Don't use the directory cache for SMB2/3; (bso#13363); + ctdb-client: Fix bugs in client code; (bso#13356); + ctdb-scripts: Drop "net serverid wipe" from 50.samba event script; (bso#13359); + s3: lib: messages: Don't use the result of sec_init() before calling sec_init(); (bso#13368); + libads: Fix the build '--without-ads'; (bso#13273); + winbind: Keep "force_reauth" in invalidate_cm_connection, add 'smbcontrol disconnect-dc'; (bso#13332); + vfs_virusfilter: Fix CIDs 1428738-1428740; (bso#13343); + dsdb: Fix CID 1034966 Uninitialized scalar variable; (bso#13367); + rpc_server: Fix core dump in dfsgetinfo; (bso#13370); + smbclient: Fix notify; (bso#13382); + Fix smbd panic if the client-supplied channel sequence number wraps; (bso#13215); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + lib/util: Remove unused '#include ' from tests/tfork.c; (bso#13342); + Fix build errors with cc from developerstudio 12.5 on Solaris; (bso#13343); + Fix the picky-developer build on FreeBSD 11; (bso#13344); + s3:modules: Fix the build of vfs_aixacl2.c; (bso#13345); + s3:smbd: map nterror on smb2_flush errorpath; (bso#13338); + lib:replace: Fix linking when libtirpc-devel overwrites system headers; (bso#13341); + winbindd: 'wbinfo --name-to-sid' returns misleading result on invalid query; (bso#13312); + s3:passdb: Do not return OK if we don't have pinfo set up; (bso#13376); + Allow AESNI to be used on all processor supporting AESNI; (bso#13302);- Use new foreground execution flags for systemd samba daemons; (bsc#1088574); (bsc#1071090); (bsc#1065551); + Add %post scriptlet to clear old sysconfig flags - Update vendor-files to commit 880b3e7. + Set samba sysconfig template variables to "" + Add required daemon flags directly to systemd unit- Specfile cleanup + Remove %if..%endif guards which don't affect the build + Remove redundant %clean section + Replace old $RPM_* shell vars with macros- BuildRequire pkgconfig(systemd) and pkgconfig(libsystemd) in place of systemd and systemd-devel: Allow OBS to optimize the workload by allowing the usage of the 'build-optimized' systemd packages.- Enable building samba with python3, and create a samba-python3 package.- Update to 4.8 + New GUID Index mode in sam.ldb for the AD DC + GPO support for samba KDC + Time machine support with vfs_fruit + Encrypted secrets + AD Replication visualization + Improved trust support - ability to not scan global trust list - AD external trusts have limited support - verbose trusted domain listing + VirusFilter VFS module + NT4-style replication removed + vfs_aio_linux removed- Disable samba-pidl package, due to the removal of dependency perl-Parse-Yapp; (bsc#1085150);- Update to 4.7.6; + CVE-2018-1050: DOS vulnerability when SPOOLSS is run externally; (bso#11343); (bsc#1081741); + CVE-2018-1057: Authenticated users can change other users' password; (bso#13272); (bsc#1081024).- Disable python until full python3 port is done; (bsc#1082139); + Remove contents of package samba-python + Remove contents of package libsamba-policy0 + Remove contents of package libsamba-policy-devel + Remove library libsamba-python-samba4.so from samba-libs package + Remove library libsamba-net-samba4.so from samba-libs package + Remove smbtorture binary and manpage from samba-test- samba fails to build with glibc2.27; (bsc#1081042);- Update to 4.7.5; (bsc#1080545); + smbd tries to release not leased oplock during oplock II downgrade; (bso#13193); + Fix copying file with empty FinderInfo from Windows client to Samba share with fruit; (bso#13181); + build: Deal with recent glibc sunrpc header removal; (bso#10976); + Make Samba work with tirpc and libnsl2; (bso#13238); + vfs_ceph: Add fs_capabilities hook to avoid local statvfs; (bso#13208); (bsc#1075206); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + ctdb-recovery-helper: Deregister message handler in error paths; (bso#13188); + samba: Only use async signal-safe functions in signal handler; (bso#13240); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + repl_meta_data: Fix linked attribute corruption on databases with unsorted links on expunge. dbcheck: Add functionality to fix the corrupt database; (bso#13228); + Fix smbd panic when chdir returns error during exit; (bso#13189); + Make Samba work with tirpc and libnsl2; (bso#13238); + Fix POSIX ACL support on HPUX and possibly other big-endian OSs; (bso#13176);- Update to 4.7.4; (bsc#1080545); + s3: smbclient: Implement 'volume' command over SMB2; (bso#13140); + s3: libsmb: Fix valgrind read-after-free error in cli_smb2_close_fnum_recv(); (bso#13171); + s3: libsmb: Fix reversing of oldname/newname paths when creating a reparse point symlink on Windows from smbclient; (bso#13172); + Build man page for vfs_zfsacl.8 with Samba; (bso#12934); + repl_meta_data: Allow delete of an object with dangling backlinks; (bso#13095); + s4:samba: Fix default to be running samba as a deamon; (bso#13129); + Performance regression in DNS server with introduction of DNS wildcard, ldb: Release 1.2.3; (bso#13191); + vfs_zfsacl: Fix compilation error; (bso#6133); + "smb encrypt" setting changes are not fully applied until full smbd restart; (bso#13051); + winbindd: Fix idmap_rid dependency on trusted domain list; (bso#13052); + vfs_fruit: Proper VFS-stackable conversion of FinderInfo; (bso#13155); + winbindd: Dependency on trusted-domain list in winbindd in critical auth codepath; (bso#13173); + repl_meta_data: Fix removing of backlink on deleted objects; (bso#13120); + ctdb: sock_daemon leaks memory; (bso#13153); + TCP tickles not getting synchronised on CTDB restart; (bso#13154); + winbindd: winbind parent and child share a ctdb connection; (bso#13150); + pthreadpool: Fix deadlock; (bso#13170); + pthreadpool: Fix starvation after fork; (bso#13179); + messaging: Always register the unique id; (bso#13180); + s4/smbd: set the process group; (bso#13129); + Fix broken linked attribute handling; (bso#13095); + The KDC on an RWDC doesn't send error replies in some situations; (bso#13132); + libnet_join: Fix 'net rpc oldjoin'; (bso#13149); + g_lock conflict detection broken when processing stale entries; (bso#13195); + s3:smb2_server: allow logoff, close, unlock, cancel and echo on expired sessions; (bso#13197); + s3:libads: net ads keytab list fails with "Key table name malformed"; (bso#13166); (bsc#1067700); + Fix crash in pthreadpool thread after failure from pthread_create; (bso#13170); + s4:samba: Allow samba daemon to run in foreground; (bso#13129); (bsc#1065551); + third_party: Link the aesni-intel library with "-z noexecstack"; (bso#13174); + vfs_glusterfs: include glusterfs/api/glfs.h without relying on "-I" options; (bso#13125);- Re-enable usage of libnsl (did got lost with glibc change) - Use TI-RPC (sunrpc is deprecated and will be removed soon from glibc)- smbc_opendir should not return EEXIST with invalid login credentials; (bnc#1065868).- Update to 4.7.3; (bsc#1069666); + Non-smbd processes using kernel oplocks can hang smbd; (bso#13121); + python: use communicate to fix Popen deadlock; (bso#13127); + smbd on disk file corruption bug under heavy threaded load; (bso#13130); + tevent: version 0.9.34; (bso#13130); + s3: smbd: Fix delete-on-close after smb2_find; (bso#13118); + CVE-2017-14746: s3: smbd: Fix SMB1 use-after-free crash bug; (bsc#1060427);(bso#13041); + CVE-2017-15275: s3: smbd: Chain code can return uninitialized memory when talloc buffer is grown; (bsc#1063008); (bso#13077); - Build with AD DC support only in openSUSE.- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- samba-tool requires samba-python; (bnc#1067771).- Run all daemons in the foreground and let systemd handle it; (bsc#1065551). - Update to 4.7.1; + Fix exporting subdirs with shadow_copy2; (bso#13091); + Currently if getwd() fails after a chdir(), we panic; (bso#13027); + Ensure default SMB_VFS_GETWD() call can't return a partially completed struct smb_filename; (bso#13068); + sys_getwd() can leak memory or possibly return the wrong errno on older systems; (bso#13069); + smbclient doesn't correctly canonicalize all local names before use; (bso#13093); + Fix broken linked attribute handling; (bso#13095); + Missing LDAP query escapes in DNS rpc server; (bso#12994); + Link to -lbsd when building replace.c by hand; (bso#13087); + Cannot delete non-ACL files on Solaris/ZFS/NFSv4 ACL filesystem; (bso#6133); + Map SYNCHRONIZE acl permission statically in zfs_acl vfs module; (bso#7909); + Samba fails to honor SEC_STD_WRITE_OWNER bit with the acl_xattr module; (bso#7933); + Missing assignment in sl_pack_float; (bso#12991); + Wrong Samba access checks when changing DOS attributes; (bso#12995); + samba_runcmd_send() leaves zombie processes on timeout; (bso#13062); + groupmap cleanup should not delete BUILTIN mappings; (bso#13065); + Enabling vfs_fruit results in loss of Finder tags and other xattrs; (bso#13076); + man pages: Properly ident lists; (bso#9613); + smb.conf.5: Sort parameters alphabetically; (bso#13081); + Fix GUID string format on GetPrinter info; (bso#12993); + Remote serverid check doesn't check for the unique id; (bso#13042); + CTDB starts consuming memory if there are dead nodes in the cluster; (bso#13056); + ctdb-common: Ignore event scripts with multiple '.'s; (bso#13070); + libgpo doesn't sort the GPOs in the correct order; (bso#13046); + Remote serverid check doesn't check for the unique id; (bso#13042); + vfs_catia: Fix a potential memleak; (bso#13090); + Fix file change notification for renames; (bso#12903); + Samba DNS server does not honour wildcards; (bso#12952); + Can't change password in samba from a Windows client if Samba runs on IPv6 only interface; (bso#13079); + vfs_fruit: Replace closedir() by SMB_VFS_CLOSEDIR; (bso#13086); + Apple client can't cope with SMB2 async replies when creating symlinks; (bso#13047); + s4:rpc_server:backupkey: Move variable into scope; (bso#12959); + Fix ntstatus_gen.h generation on 32bit; (bso#13099); + Fix a double free in vfs_gluster_getwd(); (bso#13100); + Fix resouce leaks and pointer issues; (bso#13101); + vfs_solarisacl: Fix build for samba 4.7 and up; (bso#13049);- Add samba-kdc to baselibs.conf. - Do not wrap samba-kdc's package definition into if/endif: the package won't be generated simply based on the fact that there is no files section for the package. Allows the source validator to ensure samba-kdc is a built package.- Update to 4.7.0; + Whole DB read locks: Improved LDAP and replication consistency; (bso#12858). + Samba AD with MIT Kerberos + Dynamic RPC port range: Default range changed from "1024-1300" to "49152-65535". + Authentication and Authorization audit support: New auth_audit debug class. + Multi-process LDAP Server: The LDAP server in the AD DC now honours the process model used for the rest of the 'samba' process. + Improved Read-Only Domain Controller (RODC) Support; (bso#12977). + Additional password hashes stored in supplementalCredentials. + Improvements to DNS during Active Directory domain join. + Significant AD performance and replication improvements. + Query record for open file or directory. + Removal of lpcfg_register_defaults_hook(). + Change of loadable module interface. + SHA256 LDAPS Certificates: The self-signed certificate generated for use on LDAPS will now be generated with a SHA256 self-signature, not a SHA1 self-signature. + CTDB no longer allows mixed minor versions in a cluster. + CTDB now ignores hints from Samba about TDB flags when attaching to databases. + New configuration variable CTDB_NFS_CHECKS_DIR. + The CTDB_SERVICE_AUTOSTARTSTOP configuration has been removed. + The CTDB_SCRIPT_DEBUGLEVEL configuration variable has been removed. + The example NFS Ganesha call-out has been improved. + A new "replicated" database type is available.- CVE-2017-12163: Prevent client short SMB1 write from writing server memory to file; (bso#13020); (bsc#1058624).- CVE-2017-12150: Some code path don't enforce smb signing, when they should; (bso#12997); (bsc#1058622).- CVE-2017-12151: Keep required encryption across SMB3 dfs redirects; (bso#12996); (bsc#1058565).- Clean specfile assuming SUSE-only system and product >=SLE11 + %{ul_version}, %{rhel_version}, %{mandriva_version}, %{centos_version} are always undefined + %{_vendor} is "suse" and %{suse_version} is at least 1100- Update to 4.6.7; (bsc#1054017) + Joining a Huawai storage fails: empty CLDAP ping answer; (bso#11392). + smbcacls can fail against a directory on Windows using SMB2.; (bso#12937). + vfs_ceph provides inconsistent directory listings; (bso#12911). + Misused talloc context can cause a user to crash their smbd by chaining SMB1 commands.; (bso#12836). + Use-after free can crash libsmbclient code.; (bso#12927). + Server exit with active AIO can crash.; (bso#12925). + Ensure notifyd doesn't return from smbd_notifyd_init; (bso#12910). + fd leak to ctdb sub-processes leads to SELinux AVC denial in audit logs; (bso#12898). + vfs_fruit shouldn't send MS NFS ACEs to Windows clients; (bso#12897). + smbspool_krb5_wrapper does not tell CUPS that it requires negotiate for authentication; (bso#12886). + finder sidebar showing question mark instead of icon when using ip to connect with vfs_fruit; (bso#12840). + Winbind stops obtaining the 'unixHomeDirectory' & 'loginShell' attributes from AD.; (bso#12720). + KCC run at selftest startup can fail spuriously due to a race; (bso#12869). + winbindd changes the local password and gets NT_STATUS_WRONG_PASSWORD for the remote change; (bso#12782). + rpc_pipe_client memory leaks due to long term memory context passed to rpc_pipe_open_interface(); (bso#12890). + CVE-2017-2619 breaks accessing previous versions of directories with snapshots in subdirectories of the share; (bso#12885). + dns_name_equal doing OOB read; (bso#12813). + replica_sync tests flap; (bso#12753). + Selftest should not call 'net cache flush' and wipe important winbind entries; (bso#12868). + Old Samba versions don't support using recent ldb versions (>=1.1.30); (bso#12859). + pam_winbind fails with kerberos method = secrets and keytab; (bso#10490). + race starting winbindd against posixacl test; (bso#12843). + Crash in the reentrant smbd_smb2_create_send() if the something fails in the subsequent try; (bso#12832). + spnego.c passes the wrong argument order to gensec_update_ev() for the FALLBACK case; (bso#12788). + Clients with SMB3 support can't connect with "server max protocol = SMB2_02"; (bso#12772). + A log message of samb-tool user syncpasswords reverses string arguments in a debug message "Call Popen[...".; (bso#12768). + The smb tarmode tests kills the share dir contents; (bso#12867). + Fix for a bug in MacOS X Sierra NTLMv2 processing; (bso#12862). + CVE-2017-2619 regression with non-wide symlinks to directories; (bso#12860). + manpage/index.html lists links not in alphabetical order; (bso#12854). + smbcacls got error NT_STATUS_NETWORK_NAME_DELETED; (bso#12831). + If a record is locked in a database, then recovery does not complete; (bso#12857). + debug_locks.sh script does not log any information; (bso#12856). + SIGSEGV in cm_connect_lsa_tcp dereferencing conn->lsa_tcp_pipe->transport after error; (bso#12852). + smbclient can't parse DOMAIN+username if a different winbind separator is used; (bso#12849). + Related requests with SessionSetup fail with INTERNAL_ERROR; (bso#12845). + Related requests with TreeConnect fail with NETWORK_NAME_DELETED; (bso#12844). + cli->server_os not filled correctly; (bso#12779). + REGRESSION: smbclient doesn't print the session setup anymore; (bso#12824). + smblcient doesn't handle STATUS_NOT_SUPPORTED gracefully for FSCTL_VALIDATE_NEGOTIATE_INFO; (bso#12808). + CTDB NFS call-out failures do not cause event failures; (bso#12837). + net command fails due to incorrectly return code; (bso#12828). + Fix building Samba with GCC 7.1; (bso#12827).- Fix duplicate CTDB_LOGGING params when downgraded and upgraded again; (bsc#1048339).- fix cephwrap_chdir(); (bsc#1048790). - Update to 4.6.6 + CVE-2017-11103: Orpheus' Lyre KDC-REP service name validation; (bsc#1048278).- Fix ctdb logs to /var/log/log.ctdb instead of /var/log/ctdb; (bsc#1048339).- Fix inconsistent ctdb socket path; (bsc#1048352). - Fix non-admin cephx authentication; (bsc#1048387).- Update to 4.6.5; (bsc#1040157) + Specifying CTDB_LOGGING=syslog:nonblocking causes ctdbd to crash at startup; (bso#12814). + vfs_expand_msdfs tries to open the remote address as a file path; (bso#12687). + PANIC (pid 1096): assert failed: lease_type_is_exclusive(e_lease_type); (bso#12798). + With clustering get update_num_read_oplocks failed and PANIC: num_share_modes == 1 assertion failure; (bso#11844). + contend_level2_oplocks_begin_default oplock optimisation doesn't carry over to leases; (bso#12766). + `ctdb nodestatus` incorrectly displays status for all nodes with wrong exit code; (bso#12802). + CTDB can spin hard on revoking readonly delegations if a node becomes disconnected; (bso#12697). + Printing a share mode entry with leases can crash in the ndr code; (bso#12793). + Fix flakey unit tests for eventd; (bso#12792). + CTDB daemon crashes if built with clang; (bso#12770). + smbcacls fails if no password is specified; (bso#12765). + idmap_rfc2307: Lookup of more than two SIDs fails; (bso#12757). + samba-tool user syncpasswords doesn't trigger the script when a user gets removed; (bso#12767). + systemd: fix detection of libsystemd; (bso#12764). + Notify subsystem only maps first inotify mask to Windows notify filter; (bso#12760). + Allow passing trusted domain password as plain-text to PASSDB layer; (bso#12751). + Can't case-rename files with vfs_fruit; (bso#12749). + wrong sid->uid mapping for SIDs residing in sIDHistory; (bso#12702). + vfs_acl_common should force "create mask = 0777", not 0666; (bso#12562). + Ordering of notify responses broken; (bso#12756).- s3: libsmb: Fix error where short name length was read as 2 bytes, should be 1; (bso#11822); (bsc#1042419).- Revert explicit winbind %{version}-%{release} dependency. + The ABI has stabilized since (bsc#936909), so remove to fix cross-media dependencies; (bsc#1037899).- Fix CVE-2017-7494 remote code execution from a writable share; (bso#12780); (bsc#1038231).- Update to 4.6.3; (bsc#1036011) + s3:vfs:shadow_copy2: vfs_shadow_copy2 fails to list snapshots from shares with GlusterFS backend; (bso#12743). + Fix for Solaris C compiler; (bso#12559). + s3: locking: Update oplock optimization for the leases era; (bso#12628). + Make the Solaris C compiler happy; (bso#12693). + s3: libgpo: Allow skipping GPO objects that don't have the expected LDAP attributes; (bso#12695). + Fix buffer overflow caused by wrong use of getgroups; (bso#12747). + lib: debug: Avoid negative array access; (bso#12746). + cleanupdb: Fix a memory read error; (bso#12748). + streams_xattr and kernel oplocks results in NT_STATUS_NETWORK_BUSY; (bso#7537). + winbindd: idmap_autorid allocates ids for unknown SIDs from other backends; (bso#11961). + vfs_fruit: Resource fork open request with flags=O_CREAT|O_RDONLY; (bso#12565). + manpages/vfs_fruit: Document global options; (bso#12615). + lib/pthreadpool: Fix a memory leak; (bso#12624). + Lookup-domain for well-known SIDs on a DC; (bso#12727). + winbindd: Fix error handling in rpc_lookup_sids(); (bso#12728). + winbindd: Trigger possible passdb_dsdb initialisation; (bso#12729). + credentials_krb5: use gss_acquire_cred for client-side GSSAPI use case; (bso#12611). + lib/crypto: Implement samba.crypto Python module for RC4; (bso#12690). + ctdb-readonly: Avoid a tight loop waiting for revoke to complete; (bso#12697). + ctdb_event monitor command crashes if event is not specified; (bso#12723). + ctdb-docs: Fix documentation of "-n" option to 'ctdb tool'; (bso#12733). + smbd: Fix smb1 findfirst with DFS; (bso#12558). + smbd: Do an early exit on negprot failure; (bso#12610). + winbindd: Fix substitution for 'template homedir'; (bso#12699). + s4:kdc: Disable principal based autodetected referral detection; (bso#12554). + idmap_autorid: Allocate new domain range if the callers knows the sid is valid; (bso#12613). + LINKFLAGS_PYEMBED should not contain -L/some/path; (bso#12724). + PAM auth with WBFLAG_PAM_GET_PWD_POLICY returns wrong policy for trusted domain; (bso#12725). + rpcclient: Allow -U'OTHERDOMAIN\user' again; (bso#12731). + winbindd: Fix password policy for pam authentication; (bso#12725). + s3:gse: Correctly handle external trusts with MIT; (bso#12554). + auth/credentials: Always set the realm if we set the principal from the ccache; (bso#12611). + replace: Include sysmacros.h; (bso#12686). + s3:vfs_expand_msdfs: Do not open the remote address as a file; (bso#12687). + s3:libsmb: Only print error message if kerberos use is forced; (bso#12704). + winbindd: Child process crashes when kerberos-authenticating a user with wrong password; (bso#12708). + vfs_fruit: Office document opens as read-only on macOS due to CNID semantics; (bso#12715). + vfs_acl_xattr: Fix failure to get ACL on Linux if memory is fragmented; (bso#12737).- Generate and update vendor-files tarball from Git + SuSEfirewall2 service samba-client only setup IPv4 rule; (bsc#1034416).- Generate source tarball directly from Git using OBS tar_scm + use version string derived from parent Git tag and commit hash - remove obsolete vendor-files/tools/package-data version ID + explicitly generate ctdb manpages, needed without "make dist"- Update to 4.6.2 + remove bso#12721 patches now upstream- Enable samba-ceph build for openSUSE and SLE12SP3+; (fate#321622). + x86-64 and aarch64- Enable librados CTDB lock helper for samba-ceph package; (fate#321622).- Build and install the html man pages (bsc#1021907).- Fix CVE-2017-2619 regression with "follow symlinks = no"; (bso#12721).- Update to 4.6.1 + symlink race permits opening files outside share directory; CVE-2017-2619; (bso#12496); (bsc#1027147) + testparm checks for valid idmap parameters + add new krb client encryption types + support for printer driver upload from windows 10 + inherit owner = 'unix only' for improved quota support + improved CTDB event support + new primary group support for idmap_ad + idmap_hash deprecated + mvxattr added to recursively rename extended attributes- Remove chkconfig requirements for systemd systems- Don't call insserv if systemd is used- Fix check if we need to require insserv- async_req: make async_connect_send() "reentrant"; (bso#12105); (bsc#1024416).- Force usage of ncurses6-config thru NCURSES_CONFIG env var; (bsc#1023847).- add missing patch for libnss_wins segfault; (bsc#995730).- Fix vfs_ceph builds against recent Ceph versions; (bsc#1021933).- Document "winbind: ignore domains" parameter; (bsc#1019416).- Add base Samba dependency to samba-ceph package.- Update to 4.5.3 + Heap-based Buffer Overflow Remote Code Execution Vulnerability; CVE-2016-2123; (bso#12409); (bsc#1014437). + Don't send delegated credentials to all servers; CVE-2016-2125; (bso#12445); (bsc#1014441). + denial of service due to a client triggered crash in the winbindd parent process; CVE-2016-2126; (bso#12446); (bsc#1014442). - 4.5.1 and 4.5.2 updates + various streams vfs fixes + various printing fixes + ntlm_auth: do not map explicitly empty domain + various stability fixes in smbd + match file compression ReFS behavior- Add missing ldb module directory; (bnc#1012092).- s3/client: obey 'disable netbios' smb.conf param, don't connect via NBT port; (bsc#1009085); (bso#12418).- Include vfstest in samba-test; (bsc#1001203).- s3/winbindd: using default domain with user@domain.com format fails; (bsc#997833).- Fix segfault in libnss_wins; (bso#12277); (bso#12269); (bsc#995730).- Update to 4.5.0 + NTLM1 Authentication disabled by default + SMB2.1 leases enabled by default + Support for OFD locks + ctdb tool rewritten + Added shadow copy snapshot prefix parameter- Fix illegal memory access after memory has been deleted; (bso#11836); (bsc#975299).- Prevent core, make sure response->extra_data.data is always cleared out; (bsc#993692).- Don't package man pages for VFS modules that aren't built; (boo#993707).- Fix population of ctdb sysconfig after source merge; (bsc#981566).- Enable vfs_ceph builds for Factory (x86-64) + Package as samba-ceph to avoid Ceph dependency in base package.- Update to 4.4.5 + Prevent client-side SMB2 signing downgrade; CVE-2016-2119; (bso#11860); (bsc#986869).- Remove obsolete syslog.target; (bsc#983938).- Honor smb.conf socket options in winbind; (bsc#975131).- Don't use htons() with IP_PROTO_RAW; (bso#11705); (bsc#969522).- Update to 4.4.4 + SMB3 multichannel: Add implementation of missing channel sequence number verification; (bso#11809). + smbd:close: Only remove kernel share modes if they had been taken at open; (bso#11919). + notifyd: Prevent NULL deref segfault in notifyd_peer_destructor; (bso#11930). + s3:rpcclient: Make '--pw-nt-hash' option work; (bso#10796). + Fix case sensitivity issues over SMB2 or above; (bso#11438). + s3:smbd: Fix anonymous authentication if signing is mandatory. (bso#11910) + Fix NTLM Authentication issue with squid; (bso#11914). + pdb: Fix segfault in pdb_ldap for missing gecos; (bso#11530). + Fix memory leak in share mode locking; (bso#11934).- Update to 4.4.3 + Various post-badlock regressions; (bso#11841); (bso#11850); (bso#11858); (bso#11870); (bso#11872). + Only allow idmap_hash for default idmap config (bso#11786). + smbd: Avoid large reads beyond EOF; (bso#11878). + vfs_acl_common: Avoid setting POSIX ACLs if "ignore system acls" is set; (bso#11806). + libads: Record session expiry for spnego sasl binds; (bso#11852).- Fix NTLMSSP regressions caused by previous CVE fixes; (bso#11849); (bsc#975962); (bsc#979268), (bsc#977669).- Revert shared library packaging to comply with SLPP- Update to 4.4.2 + A man-in-the-middle can downgrade NTLMSSP authentication; CVE-2016-2110; (bso#11688); (bsc#973031). + Domain controller netlogon member computer can be spoofed; CVE-2016-2111; (bso#11749); (bsc#973032). + LDAP conenctions vulnerable to downgrade and MITM attack; CVE-2016-2112; (bso#11644); (bsc#973033). + TLS certificate validation missing; CVE-2016-2113; (bso#11752); (bsc#973034). + Named pipe IPC vulnerable to MITM attacks; CVE-2016-2115; (bso#11756); (bsc#973036). + "Badlock" DCERPC impersonation of authenticated account possible; CVE-2016-2118; (bso#11804); (bsc#971965). + DCERPC server and client vulnerable to DOS and MITM attacks; CVE-2015-5370; (bso#11344); (bsc#936862).- Fix samba.tests.messaging test and prevent potential tdb corruption by removing obsolete now invalid tdb_close call; (bsc#974629).- Obsolete libsmbclient from libsmbclient0 while not providing it; (bsc#972197).- Update to 4.4.0. + Read of uninitialized memory DNS TXT handling; (bso#11128); (bso#11686); CVE-2016-0771. + Getting and setting Windows ACLs on symlinks can change permissions on link target; (bso#11648); CVE-2015-7560. + Sockets with htons(IPPROTO_RAW); (bso#11705); CVE-2015-8543. + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystem with no ACL support; (bso#10489). + docs: Add example for domain logins to smbspool man page; (bso#11643). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + docs: Add smbspool_krb5_wrapper manpage; (bso#11690). + winbindd: Return trust parameters when listing trusts; (bso#11691). + ctdb: Do not provide a useless pkgconfig file for ctdb; (bso#11696). + Crypto.Cipher.ARC4 is not available on some platforms, fallback to M2Crypto.RC4.RC4 then; (bso#11699). + s3:utils/smbget: Set default blocksize; (bso#11700). + Streamline 'smbget' options with the rest of the Samba utils; (bso#11700). + s3:clispnego: Fix confusing warning in spnego_gen_krb5_wrap(); (bso#11702). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + s3:vfs:glusterfs: Fix build after quota changes; (bso#11715). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + lib:socket: Fix CID 1350010: Integer OVERFLOW_BEFORE_WIDEN; (bso#11723). + smbd: Fix CID 1351215 Improper use of negative value; (bso#11724). + smbd: Fix CID 1351216 Dereference null return value; (bso#11725). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + docs: Add manpage for cifsdd; (bso#11730). + param: Fix str_list_v3 to accept ; again; (bso#11732). + lib/socket: Fix improper use of default interface speed; (bso#11734). + lib:socket: Fix CID 1350009: Fix illegal memory accesses (BUFFER_SIZE_WARNING); (bso#11735). + libcli: Fix debug message, print sid string for new_ace trustee; (bso#11738). + Fix installation path of Samba helper binaries; (bso#11739). + Fix memory leak in loadparm; (bso#11740). + tevent: version 0.9.28: Fix memory leak when old signal action restored; (bso#11742). + smbd: Ignore SVHDX create context; (bso#11753). + Fix net join; (bso#11755). + s3:libads: setup the msDS-SupportedEncryptionTypes attribute on ldap_add; (bso#11755). + passdb: Add linefeed to debug message; (bso#11763). + s3:utils/smbget: Fix option parsing; (bso#11767). + libnet: Make Kerberos domain join site-aware; (bso#11769). + Reset TCP Connections during IP failover; (bso#11770). + ldb: Version 1.1.26; (bso#11772). + s3:smbd: Add negprot remote arch detection for OSX; (bso#11773). + vfs_glusterfs: Fix use after free in AIO callback; (bso#11774). + mkdir can return ACCESS_DENIED incorrectly on create race; (bso#11780). + "trustdom_list_done: Got invalid trustdom response" message should be avoided; (bso#11782). + Mismatch between local and remote attribute ids lets replication fail with custom schema; (bso#11783). + Quota is not supported on Solaris 10; (bso#11788). + Talloc: Version 2.1.6; (bso#11789). + smbd: Enable multi-channel if 'server multi channel support = yes' in the config; (bso#11796). + build: Fix build when '--without-quota' specified; (bso#11798). + lib/socket/interfaces: Fix some uninitialied bytes; (bso#11802). + Access based share enum: handle permission set in configuration files; (bso#8093). + See also WHATSNEW.txt from the samba-doc package.- Update to 4.3.6. + Getting and setting Windows ACLs on symlinks can change permissions on link target; CVE-2015-7560; (bso#11648); (bsc#968222). + Fix Out-of-bounds read in internal DNS server; CVE-2016-0771; (bso#11128); (bso#11686); (bsc#968223).- Upgrade on-disk FSRVP server state to new version; (bsc#924519).- Only obsolete but do not provide gplv2/3 package names; (bsc#968973).- Relocate existing lock files to /var/lib/samba/lock; (bsc#968963).- Obsolete no longer existing samba-32bit package; (bsc#967625).- Update to 4.3.5. + s3:utils/smbget: Fix recursive download; (bso#6482). + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystemi with no ACL support; (bso#10489). + s3:smbd/oplock: Obey kernel oplock setting when releasing oplocks; (bso#11400). + vfs_shadow_copy2: Fix case where snapshots are outside the share; (bso#11580). + smbclient: Query disk usage relative to current directory; (bso#11662). + winbindd: Handle expired sessions correctly; (bso#11670). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + smbcacls: Fix uninitialized variable; (bso#11682). + s3:smbd: Ignore initial allocation size for directory creation; (bso#11684). + s3-client: Add a KRB5 wrapper for smbspool; (bso#11690). + s3-parm: Clean up defaults when removing global parameters; (bso#11693). + Use M2Crypto.RC4.RC4 on platforms without Crypto.Cipher.ARC4; (bso#11699). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + ctdb: Remove error messages after kernel security update; CVE-2015-8543; (bso#11705). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + param: Fix str_list_v3 to accept ";" again; (bso#11732).- Shift samba-client sysconfig data into samba and samba-winbind; (bsc#947361).- Simplify shared library packaging; (bsc#966956).- Enable clustering (CTDB) support; (bsc#966271).- s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703); (bsc#964023).- Add quotes around path of update-apparmor-samba-profile; (bnc#962177).- Remove autoconf build-time requirement.- Update to 4.3.4. + vfs_fruit: Enable POSIX directory rename semantics; (bso#11065). + Crash: Bad talloc magic value - access after free; (bso#11394). + Copying files with vfs_fruit fails when using vfs_streams_xattr without stream prefix and type suffix; (bso#11466). + samba-tool: Fix uncaught exception if no fSMORoleOwner attribute is given; (bso#11613). + Fix a typo in the smb.conf manpage, explanation of idmap config; (bso#11619). + Correctly initialize the list head when keeping a list of primary followed by DFS connections; (bso#11624). + Reduce the memory footprint of empty string options; (bso#11625). + lib/async_req: Do not install async_connect_send_test; (bso#11639). + Fix typos in man vfs_gpfs; (bso#11641). + Make "hide dot files" option work with "store dos attributes = yes"; (bso#11645). + Fix a corner case of the symlink verification; (bso#11647); (bnc#960249). + Do not disable "store dos attributes" on-the-fly; (bso#11649). + Update lastLogon and lastLogonTimestamp; (bso#11659).- Prevent access denied if the share path is "/"; (bso#11647); (bnc#960249).- Update to 4.3.3. + Malicious request can cause Samba LDAP server to hang, spinning using CPU; CVE-2015-3223; (bso#11325); (bnc#958581). + Remote read memory exploit in LDB; CVE-2015-5330; (bso#11599); (bnc#958586). + Insufficient symlink verification (file access outside the share); CVE-2015-5252; (bso#11395); (bnc#958582). + No man in the middle protection when forcing smb encryption on the client side; CVE-2015-5296; (bso#11536); (bnc#958584). + Currently the snapshot browsing is not secure thru windows previous version (shadow_copy2); CVE-2015-5299; (bso#11529); (bnc#958583). + Fix Microsoft MS15-096 to prevent machine accounts from being changed into user accounts; CVE-2015-8467; (bso#11552); (bnc#958585).- Update to 4.3.2. + vfs_gpfs: Re-enable share modes; (bso#11243). + dcerpc.idl: Accept invalid dcerpc_bind_nak pdus; (bso#11327). + s3-smbd: Fix old DOS client doing wildcard delete - gives an attribute type of zero; (bso#11452). + Add libreplace dependency to texpect, fixes a linking error on Solaris; (bso#11511). + s4: Fix linking of 'smbtorture' on Solaris; (bso#11512). + s4:lib/messaging: Use correct path for names.tdb; (bso#11562). + Fix segfault of 'net ads (join|leave) -S INVALID' with nss_wins; (bso#11563). + async_req: Fix non-blocking connect(); (bso#11564). + auth: gensec: Fix a memory leak; (bso#11565). + lib: util: Make non-critical message a warning; (bso#11566). + Fix winbindd crashes with samlogon for trusted domain user; (bso#11569); (bnc#949022). + smbd: Send SMB2 oplock breaks unencrypted; (bso#11570). + ctdb: Open the RO tracking db with perms 0600 instead of 0000; (bso#11577). + s3:smb2_server: Make the logic of SMB2_CANCEL DLIST_REMOVE() clearer; (bso#11581). + s3-smbd: Fix use after issue in smbd_smb2_request_dispatch(); (bso#11581). + manpage: Correct small typo error; (bso#11584). + s3: smbd: If EAs are turned off on a share don't allow an SMB2 create containing them; (bso#11589). + Backport some valgrind fixes from upstream master; (bso#11597). + auth: Consistent handling of well-known alias as primary gid; (bso#11608). + winbind: Fix crash on invalid idmap configs; (bso#11612). + s3: smbd: have_file_open_below() fails to enumerate open files below an open directory handle; (bso#11615). + Changing log level of two entries to DBG_NOTICE; (bso#9912).- Ensure samlogon fallback requests are rerouted after kerberos failure; (bnc#953382); (bnc#953972).- Ensure to link with --as-needed flag by removing SUSE_ASNEEDED=0. - Always use the default optimization even on pre-9.2 systems.- Remove redundant configure options while adding with-relro.- Relocate the lockdir to the /var/lib/samba/lock directory.- Cleanup and enhance the pidl sub package.- Require renamed python-ldb-devel and python-talloc-devel at build-time. - Requires python-ldb and python-talloc from the python subpackage.- Update to 4.3.1. + s3: smbd: Fix our access-based enumeration on "hide unreadable" to match Windows; (bso#10252). + nss_winbind: Fix hang on Solaris on big groups; (bso#10365). + smbd: Fix file name buflen and padding in notify repsonse; (bso#10634). + kerberos: Make sure we only use prompter type when available; winbind: Fix 100% loop; (bso#11038). + source3/lib/msghdr.c: Fix compiling error on Solaris; (bso#11053). + s3:ctdbd_conn: make sure we destroy tevent_fd before closing the socket; (bso#11316). + s3: smbd: Fix mkdir race condition; (bso#11486). + pam_winbind: Fix a segfault if initialization fails; (bso#11502). + s3: dfs: Fix a crash when the dfs targets are disabled; (bso#11509). + s4:lib/messaging: Use 'msg.lock' and 'msg.sock' for messaging related subdirs; (bso#11515). + s3: smbd: Fix opening/creating :stream files on the root share directory; (bso#11522). + lib/param: Fix hiding of FLAG_SYNONYM values; (bso#11526). + net: Fix a crash with 'net ads keytab create'; (bso#11528). + s3: smbd: Fix a crash in unix_convert(); (bso#11535). + s3: smbd: Fix NULL pointer bug introduced by previous 'raw' stream fix (bso#11522); (bso#11535). + vfs_fruit: Return value of ad_pack in vfs_fruit.c; (bso#11543). + vfs_commit: set the fd on open before calling SMB_VFS_FSTAT; (bso#11547). + s3:locking: Initialize lease pointer in share_mode_traverse_fn(); (bso#11549). + s3:smbstatus: Add stream name to share_entry_forall(); (bso#11550). + s3:lib: Validate domain name in lookup_wellknown_name(); (bso#11555). + s3: lsa: lookup_name() logic for unqualified (no DOMAIN component) names is incorrect; (bso#11555).- Fix 100% CPU in winbindd when logging in with "user must change password on next logon"; (bso#11038).- Relocate the tmpfiles.d directory to the client package; (bnc#947552).- Do not provide libpdb0 from libsamba-passdb0 but add it to baselibs.conf instead; (bnc#942716).- Package /var/lib/samba/private/sock with 0700 permissions; (bnc#946051).- Package /var/lib/samba/msg with 0755 permissions; (bso#11515); (bnc#945502).- Require to install libfam0-gamin from samba-libs on post-12.1 and pre-13.15 systems; (bnc#945013).- Update to 4.3.0. + Samba "map to guest = Bad uid" doesn't work; (bso#9862). + revert LDAP extended rule 1.2.840.113556.1.4.1941 LDAP_MATCHING_RULE_IN_CHAIN changes; (bso#10493). + No objectClass found in replPropertyMetaData on ordinary objects (non-deleted); (bso#10973). + Stream names with colon don't work with fruit:encoding = native; (bso#11278). + NetApp joined to a Samba/ADDC cannot resolve SIDs; (bso#11291). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + "force group" with local group not working; (bso#11320). + strsep is not available on Solaris; (bso#11359). + smbtorture does not build when configured --with-system-mitkrb5; (bso#11411). + Build with GPFS support is broken; (bso#11421). + Build broken with --disable-python; (bso#11424). + net share allowedusers crashes; (bso#11426). + nmbd incorrectly matches netbios names as own name; (bso#11427). + Python bindings don't check integer types; (bso#11429). + Python bindings don't check array sizes; (bso#11430). + CTDB's eventscript error handling is broken; (bso#11431). + Fix crash in nested ctdb banning; (bso#11432). + Cannot build ctdbpmda; (bso#11434). + samba-tool uncaught exception error; (bso#11436). + Crash in notify_remove caused by change notify = no; (bso#11444). + Poor SMB3 encryption performance with AES-GCM; (bso#11451). + Poor SMB3 encryption performance with AES-GCM (part1); (bso#11451). + fix recursion problem in rep_strtoll in lib/replace/replace.c; (bso#11455). + --bundled-libraries=!ldb,!pyldb,!pyldb-util doesn't disable ldb build and install; (bso#11458). + xid2sid gives inconsistent results; (bso#11464). + ctdb: Fix the build on FreeBSD 10.1; (bso#11465). + Handling of 0 byte resource fork stream; (bso#11467). + AD samr GetGroupsForUser fails for users with "()" in their name; (bso#11488).- Configure with --bundled-libraries=NONE; (bso#11458).- Adapt net-kdc-lookup patch for post-3.3 Samba versions; (bnc#295284).- Remove libiniparser-devel build-time requirement.- Update to 4.2.3. + s4:lib/tls: Fix build with gnutls 3.4; (bso#8780). + s4.2/fsmo.py: Fixed fsmo transfer exception; (bso#10924). + winbindd: Sync secrets.ldb into secrets.tdb on startup; (bso#10991). + Logon via MS Remote Desktop hangs; (bso#11061). + s3: lib: util: Ensure we read a hex number as %x, not %u; (bso#11068). + tevent: Add a note to tevent_add_fd(); (bso#11141). + s3:param/loadparm: Fix 'testparm --show-all-parameters'; (bso#11170). + s3-unix_msg: Remove socket file after closing socket fd; (bso#11217). + smbd: Fix a use-after-free; (bso#11218); (bnc#919309). + s3-rpc_server: Fix rpc_create_tcpip_sockets() processing of interfaces; (bso#11245). + s3:smb2: Add padding to last command in compound requests; (bso#11277). + Add IPv6 support to ADS client side LDAP connects; (bso#11281). + Add IPv6 support for determining FQDN during ADS join; (bso#11282). + s3: IPv6 enabled DNS connections for ADS client; (bso#11283). + Fix invalid write in ctdb_lock_context_destructor; (bso#11293). + Excessive cli_resolve_path() usage can slow down transmission; (bso#11295). + vfs_fruit: Add option "veto_appledouble"; (bso#11305). + tstream: Make socketpair nonblocking; (bso#11312). + idmap_rfc2307: Fix wbinfo '--gid-to-sid' query; (bso#11313). + Group creation: Add msSFU30Name only when --nis-domain was given; (bso#11315). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + Build fails on Solaris 11 with "‘PTHREAD_MUTEX_ROBUST’ undeclared"; (bso#11319). + smbd/trans2: Add a useful diagnostic for files with bad encoding; (bso#11323). + Change sharesec output back to previous format; (bso#11324). + Robust mutex support broken in 1.3.5; (bso#11326). + Kerberos auth info3 should contain resource group ids available from pac_logon; winbindd: winbindd_raw_kerberos_login - ensure logon_info exists in PAC; (bso#11328); (bnc#912457). + s3:smb2_setinfo: Fix memory leak in the defer_rename case; (bso#11329). + tevent: Fix CID 1035381 Unchecked return value; (bso#11330). + tdb: Fix CID 1034842 and 1034841 Resource leaks; (bso#11331). + s3: smbd: Use separate flag to track become_root()/unbecome_root() state; (bso#11339). + s3: smbd: Codenomicon crash in do_smb_load_module(); (bso#11342). + pidl: Make the compilation of PIDL producing the same results if the content hasn't change; (bso#11356). + winbindd: Disconnect child process if request is cancelled at main process; (bso#11358). + vfs_fruit: Check offset and length for AFP_AfpInfo read requests; (bso#11363). + docs: Overhaul the description of "smb encrypt" to include SMB3 encryption; (bso#11366). + s3:auth_domain: Fix talloc problem in connect_to_domain_password_server(); (bso#11367). + ncacn_http: Fix GNUism; (bso#11371).- Disable rpath usage; (bnc#902421).- Make the winbind package depend on the matching libwbclient version and vice versa; (bnc#936909).- Backport changes to use resource group sids obtained from pac logon_info; (bso#11328); (bnc#912457).- Order winbind.service Before and Want nss-user-lookup target.- Remove fam-devel build-time dependency for post-6 RHEL systems.- Update to 4.2.2. + s3:smbXsrv: refactor duplicate code into smbXsrv_session_clear_and_logoff(); (bso#11182). + gencache: don't fail gencache_stabilize if there were records to delete; (bso#11260). + s3: libsmbclient: After getting attribute server, ensure main srv pointer is still valid; (bso#11186). + s4: rpc: Refactor dcesrv_alter() function into setup and send steps; (bso#11236). + s3: smbd: Incorrect file size returned in the response of "FILE_SUPERSEDE Create"; (bso#11240). + Mangled names do not work with acl_xattr; (bso#11249). + nmbd rewrites browse.dat when not required; (bso#11254). + vfs_fruit: add option "nfs_aces" that controls the NFS ACEs stuff; (bso#11213). + s3:smbd: Add missing tevent_req_nterror; (bso#11224). + vfs: kernel_flock and named streams; (bso#11243). + vfs_gpfs: Error code path doesn't call END_PROFILE; (bso#11244). + s4: libcli/finddcs_cldap: continue processing CLDAP until all addresses are used; (bso#11284). + ctdb: check for talloc_asprintf() failure; (bso#11201). + spoolss: purge the printer name cache on name change; (bso#11210); (bnc#901813). + CTDB statd-callout does not scale; (bso#11204). + vfs_fruit: also map characters below 0x20; (bso#11221). + ctdb: Coverity fix for CID 1291643; (bso#11201). + Multiplexed RPC connections are not handled by DCERPC server; (bso#11225). + Fix terminate connection behavior for asynchronous endpoint with PUSH notification flavors; (bso#11226). + ctdb-scripts: Fix bashism in ctdbd_wrapper script; (bso#11007). + ctdb: Fix CIDs 1125615, 1125634, 1125613, 1288201 and 1125553; (bso#11201). + SMB2 should cancel pending NOTIFY calls with DELETE_PENDING if the directory is deleted; (bso#11257). + s3:winbindd: make sure we remove pending io requests before closing client sockets; (bso#11141); (bnc#931854). + Fix panic triggered by smbd_smb2_request_notify_done() -> smbXsrv_session_find_channel() in smbd; (bso#11182). + 'sharesec' output no longer matches input format; (bso#11237). + waf: Fix systemd detection; (bso#11200). + CTDB: Fix portability issues; (bso#11202). + CTDB: Fix some IPv6-related issues; (bso#11203). + CTDB statd-callout does not scale; (bso#11204). + 'net ads dns gethostbyname' crashes with an error in TALLOC_FREE if you enter invalid values; (bso#11234). + libads: record service ticket endtime for sealed ldap connections; (bso#11267). + lib/util: Include DEBUG macro in internal header files before samba_util.h; (bso#11033).- Avoid a crash inside the tevent epoll backend; (bso#11141); (bnc#931854).- Remove the independently built libraries ldb, talloc, tdn, and tevent and the post-10.3 renamed libsmbclient from baselibs.conf.- Drop redundant doc attribute from man pages.- Update to 4.2.1. + s3:winbind:grent: Don't stop group enumeration when a group has no gid; (bso#8905). + Initialize dwFlags field of DNS_RPC_NODE structure; (bso#9791). + s3: lib: ntlmssp: If NTLMSSP_NEGOTIATE_TARGET_INFO isn't set, cope with servers that don't send the 2 unused fields; (bso#10016). + build:wafadmin: Fix use of spaces instead of tabs; (bso#10476). + waf: Fix the build on openbsd; (bso#10476). + s3: client: "client use spnego principal = yes" code checks wrong name; (bso#10888). + spoolss: Retrieve published printer GUID if not in registry; (bso#11018). + s3: lib: libsmbclient: If reusing a server struct, check every cli->timout miliseconds if it's still valid before use; (bso#11079). + vfs_fruit: Enhance handling of malformed AppleDouble files; (bso#11125). + backupkey: Explicitly link to gnutls and gcrypt; (bso#11135). + replace: Remove superfluous check for gcrypt header; (bso#11135). + Backport subunit changes; (bso#11137). + libcli/auth: Match Declaration of netlogon_creds_cli_context_tmp with implementation; (bso#11140). + s3-winbind: Fix cached user group lookup of trusted domains; (bso#11143). + talloc: Version 2.1.2; (bso#11144). + Update libwbclient version to 0.12; (bso#11149). + brlock: Use 0 instead of empty initializer list; (bso#11153). + s4:auth/gensec_gssapi: Let gensec_gssapi_update() return NT_STATUS_LOGON_FAILURE for unknown errors; (bso#11164). + docs/idmap_rid: Remove deprecated base_rid from example; (bso#11169); (bnc#913304). + s3: libcli: smb1: Ensure we correctly finish a tevent req if the writev fails in the SMB1 case; (bso#11173). + backupkey: Use ndr_pull_struct_blob_all(); (bso#11174). + Fix lots of winbindd zombie processes on Solaris platform; (bso#11175). + s3: libsmbclient: Add missing talloc stackframe; (bso#11177). + s4-process_model: Do not close random fds while forking; (bso#11180). + s3-passdb: Fix 'force user' with winbind default domain; (bso#11185).- Prevent samba package updates from disabling samba kerberos printing.- Add sparse file support for samba; (fate#318424).- Purge printer name cache on spoolss SetPrinter change; (bso#11210); (bnc#901813).- Correctly retain errno from Btrfs snapshot ioctls; (bnc#923374).- Simplify libxslt build requirement and README.SUSE install. - Remove no longer required cleanup steps while populating the build root.- Remove deprecated base_rid example from idmap_rid manpage; (bso#11169); (bnc#913304).- Update to 4.2.0. + smbd: Stop using vfs_Chdir after SMB_VFS_DISCONNECT; (bso#1115). + pam_winbind: fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Make 'profiles' work again; (bso#9629). + s3:smb2_server: protect against integer wrap with "smb2 max credits = 65535"; (bso#9702). + Make validate_ldb of String(Generalized-Time) accept millisecond format ".000Z"; (bso#9810). + Use -R linker flag on Solaris, not -rpath; (bso#10112). + vfs: Add glusterfs manpage; (bso#10240). + Make 'smbclient' use cached creds; (bso#10279). + pdb: Fix build issues with shared modules; (bso#10355). + s4-dns: Add support for BIND 9.10; (bso#10620). + idmap: Return the correct id type to *id_to_sid methods; (bso#10720). + printing/cups: Pack requested-attributes with IPP_TAG_KEYWORD; (bso#10808). + Don't build vfs_snapper on FreeBSD; (bso#10834). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3: smb2cli: query info return length check was reversed; (bso#10848). + s3: lib, s3: modules: Fix compilation on Solaris; (bso#10849). + lib: uid_wrapper: Fix setgroups and syscall detection on a system without native uid_wrapper library; (bso#10851). + winbind3: Fix pwent variable substitution; (bso#10852). + Improve samba-regedit; (bso#10859). + registry: Don't leave dangling transactions; (bso#10860). + Fix build of socket_wrapper on systems without SO_PROTOCOL; (bso#10861). + build: Do not install 'texpect' binary anymore; (bso#10862). + Fix testparm to show hidden share defaults; (bso#10864). + libcli/smb: Fix smb2cli_validate_negotiate_info with min=PROTOCOL_NT1 max=PROTOCOL_SMB2_02; (bso#10866). + Integrate CTDB into top-level Samba build; (bso#10892). + samba-tool group add: Add option '--nis-domain' and '--gid'; (bso#10895). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + Fix smbclient loops doing a directory listing against Mac OS X 10 server with a non-wildcard path; (bso#10904). + Fix print job enumeration; (bso#10905); (bnc#898031). + samba-tool: Create NIS enabled users and unixHomeDirectory attribute; (bso#10909). + Add support for SMB2 leases; (bso#10911). + btrfs: Don't leak opened directory handle; (bso#10918). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: fix keytab array NULL termination; (bso#10933). + s3:passdb: fix logic in pdb_set_pw_history(); (bso#10940). + Cleanup add_string_to_array and usage; (bso#10942). + dbwrap_ctdb: Pass on mutex flags to tdb_open; (bso#10942). + Fix RootDSE search with extended dn control; (bso#10949). + Fix 'samba-tool dns serverinfo ' for IPv6; (bso#10952). + libcli/smb: only force signing of smb2 session setups when binding a new session; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + socket_wrapper: Add missing prototype check for eventfd; (bso#10965). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + vfs_streams_xattr: Check stream type; (bso#10971). + s3: smbd: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + vfs_fruit: Add support for AAPL; (bso#10983). + Fix spoolss IDL response marshalling when returning error without clearing info; (bso#10984). + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279). + Fix IPv6 support in CTDB; (bso#10996). + ctdb-daemon: Use correct tdb flags when enabling robust mutex support; (bso#11000). + vfs_streams_xattr: Add missing call to SMB_VFS_NEXT_CONNECT; (bso#11005). + s3-util: Fix authentication with long hostnames; (bso#11008). + ctdb-build: Fix build without xsltproc; (bso#11014). + packaging: Include CTDB man pages in the tarball; (bso#11014). + pdb_get_trusteddom_pw() fails with non valid UTF16 random passwords; (bso#11016). + Make Sharepoint search show user documents; (bso#11022). + nss_wrapper: check for nss.h; (bso#11026). + Enable mutexes in gencache_notrans.tdb; (bso#11032). + tdb_wrap: Make mutexes easier to use; (bso#11032). + lib/util: Avoid collision which alread defined consumer DEBUG macro; (bso#11033). + winbind: Retry after SESSION_EXPIRED error in ping-dc; (bso#11034). + s3-libads: Fix a possible segfault in kerberos_fetch_pac(); (bso#11037). + vfs_fruit: Fix base_fsp name conversion; (bso#11039). + vfs_fruit: mmap under FreeBSD needs PROT_READ; (bso#11040). + Fix authentication using Kerberos (not AD); (bso#11044). + net: Fix sam addgroupmem; (bso#11051). + vfs_snapper: Correctly handles multi-byte DBus strings; (bso#11055); (bnc#913238). + cli_connect_nb_send: Don't segfault on host == NULL; (bso#11058). + utils: Fix 'net time' segfault; (bso#11058). + libsmb: Provide authinfo domain for encrypted session referrals; (bso#11059). + s3-pam_smbpass: Fix memory leak in pam_sm_authenticate(); (bso#11066). + vfs_glusterfs: Add comments to the pipe(2) code; (bso#11069). + vfs/glusterfs: Change xattr key to match gluster key; (bso#11069). + vfs_glusterfs: Implement AIO support; (bso#11069). + s3-vfs: Fix developer build of vfs_ceph module; (bso#11070). + s3: netlogon: Ensure we don't call talloc_free on an uninitialized pointer; (bso#11077); CVE-2015-0240; (bnc#917376). + vfs: Add a brief vfs_ceph manpage; (bso#11088). + s3: smbclient: Allinfo leaves the file handle open; (bso#11094). + Fix Win8.1 Credentials Manager issue after KB2992611 on Samba domain; (bso#11097). + debug: Set close-on-exec for the main log file FD; (bso#11100). + s3: smbd: leases - losen paranoia check. Stat opens can grant leases; (bso#11102). + s3: smbd: SMB2 close. If a file has delete on close, store the return info before deleting; (bso#11104). + doc:man:vfs_glusterfs: improve the configuration section; (bso#11117). + snprintf: Try to support %j; (bso#11119). + ctdb-io: Do not use sys_write to write to client sockets; (bso#11124). + doc-xml: Add 'sharesec' reference to 'access based share enum'; (bso#11127).- Update to 4.2.0rc5. + Ensure we don't call talloc_free on an uninitialized pointer; CVE-2015-0240; (bso#11077); (bnc#917376).- Fix usage of freed memory on server exit; (bso#11218); (bnc#919309).- Fix tdb_store_flag_to_ntdb() gcc5 build failure.- Fix vfs_snapper DBus string handling; (bso#11055); (bnc#913238).- Update to 4.1.16. + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279).- Adjust baselibs.conf due to libpdb0 package rename to libsamba-passdb0.- Fix libsmbclient DFS referral handling. + Reuse connections derived from DFS referrals; (bso#10123); (fate#316512). + Set domain/workgroup based on authentication callback value; (bso#11059).- Update to 4.2.0rc4. - Add libsamba-debug, libsocket-blocking, libsamba-cluster-support, and libhttp to the libs package; (boo#913547). - Rename libpdb packages to libsamba-passdb. - Drop libsmbsharemodes packages.- Enable avahi support on post-12.2 systems.- Update to 4.1.15. + pam_winbind: Fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Fix profiles tool; (bso#9629). + s3-lib: Do not require a password with --use-ccache; (bso#10279). + s4:dsdb/rootdse: Expand extended dn values with the AS_SYSTEM control; (bso#10949). + s4-rpc: dnsserver: Fix enumeration of IPv4 and IPv6 addresses; (bso#10952). + s3:smb2_server: Allow reauthentication without signing; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + s3: smbd/modules: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + Fix 'domain join' by adding 'drsuapi.DsBindInfoFallBack' attribute 'supported_extensions'; (bso#11006). + idl:drsuapi: Manage all possible lengths of drsuapi_DsBindInfo; (bso#11006). + winbind: Retry LogonControl RPC in ping-dc after session expiration; (bso#11034).- yast2-samba-client should be able to specify osName and osVer on AD domain join; (bnc#873922).- Lookup FSRVP share snums at runtime rather than storing them persistently; (bnc#908627).- Specify soft dependency for network-online.target in Winbind systemd service file; (bnc#889175).- Fix spoolss error response marshalling; (bso#10984).- Update to 4.1.14. + pidl/wscript: Remove --with-perl-* options; revert buildtools/wafadmin/ Tools/perl.py back to upstream state; (bso#10472). + s4-dns: Add support for BIND 9.10; (bso#10620). + nmbd fails to accept "--piddir" option; (bso#10711). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + S3: source3/smbd/process.c::srv_send_smb() returns true on the error path; (bso#10880). + vfs_glusterfs: Remove "integer fd" code and store the glfs pointers; (bso#10889). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + s3: libsmbclient-smb2. MacOSX 10 SMB2 server doesn't set STATUS_NO_MORE_FILES when handed a non-wildcard path; (bso#10904). + spoolss: Fix jobid in level 3 EnumJobs response; (bso#10905). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: Fix keytab array NULL termination; (bso#10933). + Cleanup add_string_to_array and usage; (bso#10942).- Remove and cleanup shares and registry state associated with externally deleted snaphots exposed as shadow copies; (bnc#876312).- Use the upstream tar ball, as signature verification is now able to handle compressed archives.- Fix leak when closing file descriptor returned from dirfd; (bso#10918).- Fix spoolss EnumJobs and GetJob responses; (bso#10905); (bnc#898031). + Fix handling of bad EnumJobs levels; (bso#10898).- Remove dependency on gpg-offline as signature checking is implemented in the source validator.- Update to 4.1.13. + s3-libnet: Add libnet_join_get_machine_spns(); (bso#9984). + s3-libnet: Make sure we do not overwrite precreated SPNs; (bso#9984). + s3-libads: Add all machine account principals to the keytab; (bso#9985). + s3: winbindd: Old NT Domain code sets struct winbind_domain->alt_name to be NULL. Ensure this is safe with modern AD-DCs; (bso#10717). + Fix unstrcpy; (bso#10735). + pthreadpool: Slightly serialize jobs; (bso#10779). + s3: smbd: streams - Ensure share mode validation ignores internal opens (op_mid == 0); (bso#10797). + s3: smbd:open_file: Open logic fix; Use a more natural check; (bso#10809). + vfs_media_harmony: Fix a crash bug; (bso#10813). + docs: Mention incompatibility between kernel oplocks and streams_xattr; (bso#10814). + nmbd: Send waiting status to systemd; (bso#10816). + libcli: Fix a segfault calling smbXcli_req_set_pending() on NULL; (bso#10817). + nsswitch: Skip groups we were not able to map; (bso#10824). + s3-winbindd: Use correct realm for trusted domains in idmap child; (bso#10826). + s3: nmbd: Ensure the main nmbd process doesn't create zombies; (bso#10830). + s3: lib: Signal handling - ensure smbrun and change password code save and restore existing SIGCHLD handlers; (bso#10831). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3-winbindd: Do not use domain SID from LookupSids for Sids2UnixIDs call; (bso#10838). + s3: smb2cli: Query info return length check was reversed; (bso#10848). + registry: Don't leave dangling transactions; (bso#10860).- Update to 4.2.0rc2.h03-ch2a 1704181754  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~4.17.12+git.455.b299ac1e60-150500.3.20.14.17.12+git.455.b299ac1e60-150500.3.20.1          samba__init__.py_glue.cpython-36m-x86_64-linux-gnu.so_ldb.cpython-36m-x86_64-linux-gnu.soauth.cpython-36m-x86_64-linux-gnu.soauth_util.pycolour.pycommon.pycredentials.cpython-36m-x86_64-linux-gnu.socrypto.cpython-36m-x86_64-linux-gnu.sodbchecker.pydcerpc__init__.pyatsvc.cpython-36m-x86_64-linux-gnu.soauth.cpython-36m-x86_64-linux-gnu.sobase.cpython-36m-x86_64-linux-gnu.sodcerpc.cpython-36m-x86_64-linux-gnu.sodfs.cpython-36m-x86_64-linux-gnu.sodns.cpython-36m-x86_64-linux-gnu.sodnsp.cpython-36m-x86_64-linux-gnu.sodnsserver.cpython-36m-x86_64-linux-gnu.sodrsblobs.cpython-36m-x86_64-linux-gnu.sodrsuapi.cpython-36m-x86_64-linux-gnu.soecho.cpython-36m-x86_64-linux-gnu.soepmapper.cpython-36m-x86_64-linux-gnu.soidmap.cpython-36m-x86_64-linux-gnu.soinitshutdown.cpython-36m-x86_64-linux-gnu.soirpc.cpython-36m-x86_64-linux-gnu.sokrb5ccache.cpython-36m-x86_64-linux-gnu.sokrb5pac.cpython-36m-x86_64-linux-gnu.solsa.cpython-36m-x86_64-linux-gnu.somdssvc.cpython-36m-x86_64-linux-gnu.somessaging.cpython-36m-x86_64-linux-gnu.somgmt.cpython-36m-x86_64-linux-gnu.somisc.cpython-36m-x86_64-linux-gnu.sonbt.cpython-36m-x86_64-linux-gnu.sonetlogon.cpython-36m-x86_64-linux-gnu.sontlmssp.cpython-36m-x86_64-linux-gnu.sopreg.cpython-36m-x86_64-linux-gnu.sosamr.cpython-36m-x86_64-linux-gnu.sosecurity.cpython-36m-x86_64-linux-gnu.soserver_id.cpython-36m-x86_64-linux-gnu.sosmb_acl.cpython-36m-x86_64-linux-gnu.sospoolss.cpython-36m-x86_64-linux-gnu.sosrvsvc.cpython-36m-x86_64-linux-gnu.sosvcctl.cpython-36m-x86_64-linux-gnu.sounixinfo.cpython-36m-x86_64-linux-gnu.sowinbind.cpython-36m-x86_64-linux-gnu.sowindows_event_ids.cpython-36m-x86_64-linux-gnu.sowinreg.cpython-36m-x86_64-linux-gnu.sowinspool.cpython-36m-x86_64-linux-gnu.sowitness.cpython-36m-x86_64-linux-gnu.sowkssvc.cpython-36m-x86_64-linux-gnu.soxattr.cpython-36m-x86_64-linux-gnu.sodescriptor.pydnsresolver.pydnsserver.pydomain_update.pydrs_utils.pydsdb.cpython-36m-x86_64-linux-gnu.sodsdb_dns.cpython-36m-x86_64-linux-gnu.soemulate__init__.pytraffic.pytraffic_packets.pyforest_update.pygensec.cpython-36m-x86_64-linux-gnu.sogetopt.pygpgp_centrify_crontab_ext.pygp_centrify_sudoers_ext.pygp_cert_auto_enroll_ext.pygp_chromium_ext.pygp_ext_loader.pygp_firefox_ext.pygp_firewalld_ext.pygp_gnome_settings_ext.pygp_msgs_ext.pygp_scripts_ext.pygp_sec_ext.pygp_smb_conf_ext.pygp_sudoers_ext.pygpclass.pyutillogging.pyvgp_access_ext.pyvgp_files_ext.pyvgp_issue_ext.pyvgp_motd_ext.pyvgp_openssh_ext.pyvgp_startup_scripts_ext.pyvgp_sudoers_ext.pyvgp_symlink_ext.pygp_parse__init__.pygp_aas.pygp_csv.pygp_inf.pygp_ini.pygp_pol.pygpo.cpython-36m-x86_64-linux-gnu.sograph.pyhostconfig.pyidmap.pyjoin.pykcc__init__.pydebug.pygraph.pygraph_utils.pykcc_utils.pyldif_import_export.pylogger.pymdb_util.pymessaging.cpython-36m-x86_64-linux-gnu.soms_display_specifiers.pyms_forest_updates_markdown.pyms_schema.pyms_schema_markdown.pyndr.pynet.cpython-36m-x86_64-linux-gnu.sonet_s3.cpython-36m-x86_64-linux-gnu.sonetbios.cpython-36m-x86_64-linux-gnu.sonetcmd__init__.pycommon.pycomputer.pycontact.pydbcheck.pydelegation.pydns.pydomain.pydomain_backup.pydrs.pydsacl.pyforest.pyfsmo.pygpo.pygroup.pyldapcmp.pymain.pynettime.pyntacl.pyou.pyprocesses.pypso.pyrodc.pyschema.pysites.pyspn.pytestparm.pyuser.pyvisualize.pyntacls.pyntstatus.cpython-36m-x86_64-linux-gnu.soparam.cpython-36m-x86_64-linux-gnu.sopolicy.cpython-36m-x86_64-linux-gnu.soposix_eadb.cpython-36m-x86_64-linux-gnu.soprovision__init__.pybackend.pycommon.pykerberos.pykerberos_implementation.pysambadns.pyregistry.cpython-36m-x86_64-linux-gnu.soremove_dc.pysamba3__init__.pylibsmb_samba_cwrapper.cpython-36m-x86_64-linux-gnu.solibsmb_samba_internal.pymdscli.cpython-36m-x86_64-linux-gnu.soparam.cpython-36m-x86_64-linux-gnu.sopassdb.cpython-36m-x86_64-linux-gnu.sosmbconf.cpython-36m-x86_64-linux-gnu.sosmbd.cpython-36m-x86_64-linux-gnu.sosamdb.pyschema.pysd_utils.pysecurity.cpython-36m-x86_64-linux-gnu.sosites.pysmbconf.cpython-36m-x86_64-linux-gnu.sosubnets.pysubunit__init__.pyrun.pytdb_util.pytests__init__.pyaudit_log_base.pyaudit_log_dsdb.pyaudit_log_pass_change.pyauth.pyauth_log.pyauth_log_base.pyauth_log_ncalrpc.pyauth_log_netlogon.pyauth_log_netlogon_bad_creds.pyauth_log_pass_change.pyauth_log_samlogon.pyauth_log_winbind.pyblackbox__init__.pybug13653.pycheck_output.pydowngradedatabase.pymdsearch.pyndrdump.pynetads_dns.pynetads_json.pysamba_dnsupdate.pysmbcacls.pysmbcacls_basic.pysmbcacls_dfs_propagate_inherit.pysmbcacls_propagate_inhertance.pysmbcontrol.pysmbcontrol_process.pytraffic_learner.pytraffic_replay.pytraffic_summary.pycommon.pycomplex_expressions.pycore.pycred_opt.pycredentials.pydcerpc__init__.pyarray.pybare.pybinding.pycreatetrustrelax.pydnsserver.pyinteger.pylsa.pymdssvc.pymisc.pyraw_protocol.pyraw_testcase.pyregistry.pyrpc_talloc.pyrpcecho.pysam.pysamr_change_password.pysrvsvc.pystring_tests.pytestrpc.pyunix.pydckeytab.pydns.pydns_aging.pydns_base.pydns_forwarder.pydns_forwarder_helpersserver.pydns_invalid.pydns_packet.pydns_tkey.pydns_wildcard.pydocs.pydomain_backup.pydomain_backup_offline.pydsdb.pydsdb_api.pydsdb_dns.pydsdb_lock.pydsdb_schema_attributes.pyemulate__init__.pytraffic.pytraffic_packet.pyencrypted_secrets.pygensec.pyget_opt.pygetdcname.pyglue.pygpo.pygpo_member.pygraph.pygroup_audit.pyhostconfig.pyimports.pyjoin.pykcc__init__.pygraph.pygraph_utils.pykcc_utils.pyldif_import_export.pykrb5alias_tests.pyas_canonicalization_tests.pyas_req_tests.pycompatability_tests.pyetype_tests.pyfast_tests.pykcrypto.pykdc_base_test.pykdc_tests.pykdc_tgs_tests.pykpasswd_tests.pylockout_tests.pyms_kile_client_principal_lookup_tests.pynt_hash_tests.pypac_align_tests.pyprotected_users_tests.pyraw_testcase.pyrfc4120_constants.pyrfc4120_pyasn1.pyrodc_tests.pys4u_tests.pysalt_tests.pysimple_tests.pyspn_tests.pytest_ccache.pytest_idmap_nss.pytest_ldap.pytest_min_domain_uid.pytest_rpc.pytest_smb.pyxrealm_tests.pykrb5_credentials.pyldap_raw.pyldap_referrals.pyldap_spn.pyldap_upn_sam_account.pylibsmb.pyloadparm.pylogfiles.pylsa_string.pymessaging.pyndr.pynet_join.pynet_join_no_spnego.pynetbios.pynetcmd.pynetlogonsvc.pyntacls.pyntacls_backup.pyntlm_auth.pyntlm_auth_base.pyntlm_auth_default_domain.pyntlm_auth_krb5.pyntlmdisabled.pypam_winbind.pypam_winbind_chauthtok.pypam_winbind_setcred.pypam_winbind_warn_pwd_expire.pyparam.pypassword_hash.pypassword_hash_fl2003.pypassword_hash_fl2008.pypassword_hash_gpgme.pypassword_hash_ldap.pypassword_quality.pypassword_test.pypolicy.pyposixacl.pyprefork_restart.pyprocess_limits.pyprovision.pypso.pypy_credentials.pyregistry.pys3_net_join.pys3idmapdb.pys3param.pys3passdb.pys3registry.pys3windb.pysamba3sam.pysamba_tool__init__.pybase.pycomputer.pycontact.pydemote.pydnscmd.pydrs_clone_dc_data_lmdb_size.pydsacl.pyforest.pyfsmo.pygpo.pygpo_exts.pygroup.pyhelp.pyjoin.pyjoin_lmdb_size.pyjoin_member.pyntacl.pyou.pypasswordsettings.pyprocesses.pypromote_dc_lmdb_size.pyprovision_lmdb_size.pyprovision_password_check.pyprovision_userPassword_crypt.pyrodc.pyschema.pysites.pytimecmd.pyuser.pyuser_check_password_script.pyuser_virtualCryptSHA.pyuser_virtualCryptSHA_base.pyuser_virtualCryptSHA_gpg.pyuser_virtualCryptSHA_userPassword.pyuser_wdigest.pyvisualize.pyvisualize_drs.pysamba_upgradedns_lmdb.pysamdb.pysamdb_api.pysddl.pysecurity.pysegfault.pysid_strings.pysmb-notify.pysmb.pysmbconf.pysmbd_base.pysmbd_fuzztest.pysource.pysource_chars.pystrings.pysubunitrun.pytdb_util.pyupgrade.pyupgradeprovision.pyupgradeprovisionneeddc.pyusage.pyxattr.pytrust_utils.pyupgrade.pyupgradehelpers.pyuptodateness.pywerror.cpython-36m-x86_64-linux-gnu.soxattr.pyxattr_native.cpython-36m-x86_64-linux-gnu.soxattr_tdb.cpython-36m-x86_64-linux-gnu.so/usr/lib64/python3.6/site-packages//usr/lib64/python3.6/site-packages/samba//usr/lib64/python3.6/site-packages/samba/dcerpc//usr/lib64/python3.6/site-packages/samba/emulate//usr/lib64/python3.6/site-packages/samba/gp//usr/lib64/python3.6/site-packages/samba/gp/util//usr/lib64/python3.6/site-packages/samba/gp_parse//usr/lib64/python3.6/site-packages/samba/kcc//usr/lib64/python3.6/site-packages/samba/netcmd//usr/lib64/python3.6/site-packages/samba/provision//usr/lib64/python3.6/site-packages/samba/samba3//usr/lib64/python3.6/site-packages/samba/subunit//usr/lib64/python3.6/site-packages/samba/tests//usr/lib64/python3.6/site-packages/samba/tests/blackbox//usr/lib64/python3.6/site-packages/samba/tests/dcerpc//usr/lib64/python3.6/site-packages/samba/tests/dns_forwarder_helpers//usr/lib64/python3.6/site-packages/samba/tests/emulate//usr/lib64/python3.6/site-packages/samba/tests/kcc//usr/lib64/python3.6/site-packages/samba/tests/krb5//usr/lib64/python3.6/site-packages/samba/tests/samba_tool/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:31987/SUSE_SLE-15-SP5_Update/5d6206584aa08ed2ed19252942a3645f-samba.SUSE_SLE-15-SP5_Updatedrpmxz5x86_64-suse-linux  !"#$%&'()*+,-./012345363789::;<=>2?@ABCDEFG2:3H3333332:I233333:2:33333JKLdirectoryPython script, ASCII text executableELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=6eb29580f6f14ee6d8fb9c04a79506f2c8d93786, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=22765d602722f17d9cea568c003b6a6c850711bf, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=f2d96a1a9f4dd7d47929f6f63e61046ac3b89fef, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=b890e01357df19c124e99ab67def5eb32f540110, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=70e7d8847978f4f71da835be9d1afdbd2e25f7c6, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=8bc97ef71d8b0bddfc2b5743646716025efb270f, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=d464bf48146194b571de00797a285655f946140c, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=8f5a2906ffa7a25cd40e3784f750c56fcb87b05d, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=ef64e0b2b495e28e681f781c4f24ec2c800829e2, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=bee4c41391ef71aeb784d7dbd7364e99a03f1284, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=8eea85bf28cf8987d90f9566523c967d864d4bb2, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=d51f3bc39a1cf87435915bb701b09e62fc963738, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=d3eb2120f7df6e7a44c2402babcce9321b944237, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=09f7efc0323215556704f3a664b9d6f87d022ce6, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=a79a95333786074335a1d216ea025fdd1706b259, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=98908a857dbe189afd291b17995601c04f6a1ab3, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=38e91a3cb743af6afbc95e35149737835ad1e96f, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=0ff22b8e70d5e75634b53cf18a1bca25498c0d85, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=41b8a7628a8ab2885a5dda53a7eb4c885bac7f97, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=c0d0344b9d922830f23d19a1c04c45c37b986d25, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=a2794b0a98f9468cd6cb93165a0e3e340be372ed, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=b48513b261acd9ae151611ab952352abfd9b597f, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=c61658efa386a0e35c8453841a607927f95093b9, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=38769eb0fe6da9ddbc51256df03723e1bc44c5b5, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=4d95c9df56a5b12234de757e8f0b29b22be13831, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=d03b1ee2d4ef0adb8b15dcec439d572c966d92d9, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=aae909e989cb8efd3a386d520813b4b4ca6f8249, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=e877a999ba9c232f14675d8dd20dc107c1e74fef, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=b163e5122e8dc837e2a50e4ed149f88a846b6814, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=114f0773c39b63f85c6baee5c4ec1777ac59550e, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=fa2bd031dcb18cc1255171423a14c8795b2303c6, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=84672363f9538f6f0356d04335349fd2f0dec952, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=4cc799a7355e302891911e983f8cf3aa2db362bd, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=135df7c89ed1c1f85d999a8464c4618d6d655459, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=b55e3679aeba197443edfdded882ac6b2dca136e, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=b8566f2be51cf062de39de11bb0c653ead2a05ae, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=fbe556fd30cf892c62302d075e2a54c0b183c400, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=57ff337afc54434d10493dc8091e9b324e783c60, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=70d01c652bb74f7e0660c0cad11dff7f1ef8c62d, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=981bc0f5a527eceff9c6e5f0f01ab54ec020f805, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=ad005814b1539ff36d82e1f17a4e02c03831420b, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=4a99d05e56a581f71789bedaf7f9b55ddd0d0cac, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=e61593859b24591cb7033b990f65435c0bff6514, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=37af29af3cc773c518db5d10ae131f878542e141, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=ca28cecc78f69bc098836a8b10efdcd0cdcec794, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=a0c01e4eb1799b0f376d5b1d9c35645b81b121b1, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=d054a8e5308e3a9e2836c1869300b06336a24153, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=c07574f57616f86a0dbeb1c47f55a307ba272032, strippedASCII textPython script, UTF-8 Unicode text executableELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=fdf632ab356cc156921f05b929843591f3cf532f, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=531834bd50fd5ba74230f8aebdd3160afd800fcc, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=a7c38973f743de884f063c0b0f21da059a192ddf, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=a79754393a93c830230c8e4798536b1474523e37, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=73d984325f6e799d84bb8c1cdac1823aa44ca505, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=f8a5dc0bab10ac5a75cee96ece7d2edb84d9a5bc, strippedPython script, ASCII text executable, with very long linesELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=2edb07652ac8158d31cfe3453135b851d5373524, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=2b3ac87d1a508b8d35d707bb6a7d7aa325da48f1, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=b3879dbbb064e80b027bcbe79286169293c72bf6, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=5be2860bc0390c844714c6b4fc86a0f431b5db39, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=3908aa0a4213dddef7f11af9aea6ccfacc25745e, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=06c1bcd540eae2b11446eed803b5dfc90d5193c6, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=cfe1b9ede6a64e84a6355ce2e4fa44c790ab07bd, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=bf8db27938167ac9cab21df8322ef8ba64d3e5a9, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=bfe9c37042644f06e58381f85addde4a074805ad, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=86e12296610f2216365b32a60d5f4ee9121c71a5, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=c3510847d0bff8af2c46a9d91a881da6d6def10d, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=37cbdd1e133c9fbe6d711497ce676af0b748142a, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=ce53d662fc8e9518c712a81ebf4245e68d87f5cf, strippedUTF-8 Unicode textPython script, UTF-8 Unicode text executable, with escape sequencesELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=090d6494f4cebac33aef5bf802e4c5ad7837ac74, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=fb70a86e6e546dc2e0a411b7ac92b991bf1234b8, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=16da8ad4861df50b7570763fec5b926478883fd6, stripped@hijk.DYv7G\p2Gb~-./01FGHIJKLMNOPQRSTUVWXYZ[\]^_`abcd!./0123456789:;<=>?@ABCDEFGHIJKLPbm~ ,-./;<EFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789=>H,(  (I  '    RRRR_RR3R]RRRuRRXRRR^R2RtRmRR RRARwR!RgRfRRRqRR RR/RR RRlRjRiRRRERCRsRDRRrRRvR RRRpR R.RRRmR@ReRBRRhR RRARwR!RgRfRRRqRR RR/RR RRlRjRiRRRsRRrRRvR RRRpR R.RRRmR@ReRRhR RRRRRARwRRRqRRRjRiRRRsRRrRvRRpRRmR@RRhR RRwRRRqRRyRRR9R8R7RpRRxRvRRR6RmR RRRRRwR'RRRRjRiRWR\RYR&RRXRVRvRmRRhR RRRYRRRRjRiRRSRXRRRRRmRRhR RRR5RjRiRR3RwRRR+RqR%RRuRYRXRRpRvR4RR*RtR$R2RmRRhR RRRYRRRRjRkRiRRURXRRRTRmRRhR RRWRwRRR'RRjRkRiRR\RYR&RRXRVRvRmRRhR RRRjRkRiRRRRRYRQRXRRRPRmRRhR RRRjRkRiRRRRRYRQRXRRRPRmRRhR RRwRRRRjRkRiRRSR'R\RYR&RRXRRRvRmRRhR RRwRRYRRRRjRkRiRRSRXRRRRvRRmRRhR RRRwRRRRRRjRkRiRR%R[R\RYRSR$RRRRXRRvRRmRRhRR RRWRwRRRRjRkRiR'RR\RYR&RRXRVRvRmRRhR RR'RRRRRjRkRiRRSR\RYRRXRRRR&RmRRhR RRRRYRRjRiRSRRRXRmRRhR RRWRRwRRRRjRiR'R\RYR&RRXRVRvRmRRhR RRRwRRRRRRjRkRiRRUR%R[R\RYRTRRXRvR$RRRmRRhRR RRRYRRRRjRkRiRRSRRRRXRRmRRhR RRRjRkRiRRRRRYRORNRRXRRmRRhR RRwRRRRjRkRiRR\RYRWR'R&RRXRVRvRmRRhR RRRRR RRRRjRiRSR%R[R\RYR$RRRRXRRmRRhRR RRRURYRRRRjRiRXRTRRmRRhR RRRSRwRRRRjRiR+R\RYR*RRXRRRvRmRRhR RRRjRkRiRRRRwRRZRYRRXRvRRmRRhR RRRjRkRiRRRRRYRQRPRRXRRmRRhR RRRRwRRRkRiRjR\RYR'RRWR&RRXRVRvRRmRRhR RRRYRRRRjRkRiRRSRRRRXRRmRRhR RRYRRRRjRiRRURXRRTRmRRhR RRwRRRRjRkRiRR'R\RYRWRR&RVRXRvRmRRhR RRRRjRkRiRRRRwRYRRXRRRvRRmRRhR RRRRiRjRYRWRRXRVRmRRhR RRRRjRkRiRRRRmRRhR RRRwRRRRkRiRjR\RYR'RRWR&RRXRVRvRRmRRhR RRwRWRRRRjRkRiRR'R\RYR&RRXRVRvRmRRhR RRRwRRRRjRiR'RWR\RYR&RRXRVRvRmRRhR RRRRwRRSR RRRRjRiR%R[R\RYR$RRRRXRRvRmRRhRR RRRRwRRRkRiRjR\RYR'RRURWR)R&R(RRXRVRTRvRRmRRhR RRRmR RRRwRWRRRRjRiR'R\RYR&RRXRVRvRmRRhR RRRURRwR RRRRjRkRiRR%R[R\RYRXR$RRvRRTRmRRhRR RRRwRRRRRRjRkRiRR%R[R\RYRSR$RRRRXRRvRRmRRhRR RRwRWRRRRjRkRiRR\RYR'R&RRXRVRvRmRRhR RRRYRRRRRRjRkRiRRSRRRRXRRmRRhR RRRRRRR1RwRfRRRRRCRYRERRRRXRRvRDRR0RmReRBRR RRRRjR-RRRRwRfRgRR,RvRRmReRRhR RRRRRRwRlRiRjRRRyRRRR5R4RxRRvRRmRRhR RRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRwR=RRRRsRuR;RRjRiRRRRRRRR:RRrRtRRvRR6R RRRR/RRRwRRvR.RRmR RRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRmR RRRiRjRuRRRRRyRxRRRtRRhRmR RRRRRwRRRvRmRR RRyRRRRRRwRaRxR`RRvRRmRR RRRRRRRR3RRRRsRjRiRwR/RRRRuRoRnRRRRvR2RtRrR.RmRhRR RRRRARRwRqRRRR RRRRRlRjRiRRRRcRdRsRKRRrRRvRRpRRJRRmRbR@RRRhR RRRSRwRiRjRRRuRRR RRRR%R[RYR$RRRRXRRvRRtRmRRhRR RRjRiRRRRyRRxRmRRhR RRwRRRRiRjRRRuRRR}R|RRRtRvRRRmRRhR RRRRRRmR RRjRlRcRRRRRRuRRRwRRRtRRRvRmRbRRhR RRRRRRjRlRRRwRRvRhRmR RRRRRRRRRmR RRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRmR RRRRRRRcRmRbRR RRyRRRRRRqR#RpRRxRR"RmRR L"y1Rmutf-8ea132d68cb0229278faa93d0716d860633a38c5554a6cf973dd973c2a4ac2f98? 7zXZ !t/]"k%2_f4pDJ(z*%"cxCUm4 yH0Ѽ9`F2> d.=Ex&bm6Y@PZTLP^V1G8G"#ߣ!)O~QG_$(]o1ɓpڒBRU`ݘV0ў}9}RWۂ{g,LE慴n0 mؙ6Rwg5b?kCmi'ը%PȪ N%WP[VQ߰H b&&x :EllN|̋8{8]bs#0Ϣ$u(~-HY.J08&Gbf;fh]gv`a :!]if.~2}%0e1$`p$&ּ_P!ɕ @ၧbl>LJ;( l`bL9Nu~||='9 DfL֕ym ,f?9qv}oz.V ڤ'pą`d|We'L.>+b܁WJaU^A*YDFr4t^}_ԾAON }_UH`=nCc Xy 8"6JJ9 j ^ 2 1/gf5DE/ p6JM|C}ߎ,Kn7pm\Zwr-5Ǡ| 5EOFk"`i@_S4DV$ ~eQ-.M2lJ_6^yGD#ȺX4^|6[Ͻ|Ii&dq@3{yd66q6;i6cR;j¥>>t:yS)$lپh=F 4R(ks^_1ڿ9K*#GI{lVFE&Qt=9nUT[D!ZgQt͒XZ!I U?`SMn']мt})0!N]>uLEreZ1kq)Ek/@T'0^zsSPlKcRM6$Ja^| L .Wd4w`լ,bJTGB(I?t#8L"[4^3 Cgn< P/iv:k.y߯E,%8)Wb/Qd>-t[]d8+ݱ@JAzQbQ VMtSM9t! M )eiRO3,9Lfq>ϵ=+R}$oo+v3lڔcN3*;t+T^i {ؙ̞N j Ju9C 8Oӧ@'޲eÏN-O@϶y H@]_# 8fSrbJEuq.ﻸh*lL R &td`Nqp|Kf^oyZi]$`y n&T";h)DrW- njbJg~BĖ($&h<˻j$^l.]0 R,Z&U_>^Pa;5;wHDkN 'x5R#l^{on*|JNr0~P/73V]995ˤagm H2J֖U"/7rtycfGKŋZHbWH'WlUy%hx\B$7pK{<+%w݌WlzVl[̈́ ۭpcfQ9l6-Xmf = {ߘϳ7(Q(Csl'GvM`m/Ľ$JR=]PZwSuϲ0vT!V|%islDWg]tX/ w OoU <)YR A56Xb{lߓg :}Lf#jk)h|S) \Ƒ~K{ɳGե Mԅ'dܳ/?+mT|@6+6F 3 q+,=L# i3lK]7M.Gf$,di5h &<0%!n0o䮇?G3l$y75YY -WoStUve Ndn\073Gd]Iۯ/jrv=isNWm s.ܱX\HtfrqhsEs06-W@2G4n9տWD`"7U0,cM?Տn6 @D 5e ~uA 4<>Q;xBSem0Sm#e O 6Ѓ\QZ卻/ 5YH4N6n*"DgCaEF:KVWXVp%D oA[vtUb5NexRGE>ӦN! *r" G>^Ƈ^' zʫۅ77z_?tW. hW @oBgB?wgI.LƳjMEy8|j0ʐ ykܝkE39?dha0#Y:BBܢ͍75Zy>.;u:n6Dv2ȊƱz[VfޠI _ ?L[ 4{DG-p];*jL" -|P岙t3ibb3k5{q6P#[dl/,E\z`&`{ Fv&EgsMr2ŎyE gm?Oe̒Riz~q 6ߐCܧku|bwB$ލ7 b3H7,NOQu|+9q0 9Á(w؊K,"xfӜ Z!4Ly=03ͱjO1sWDtY9bO*b o|hs=H#`=:+?8P  o;dxRUYFUa'dz̍"y)w#Si0IE9Go觚2N0 U-ڂռ~'I9i͘<0T%% +0܎$!( 7C|B<{D ~=>6_؁>?0'ԉٕ7Jϕbr+pPcֱ^͒? h3U8BE;>N(\F씄_>"V]ALP>+h9:>輑U1B@(2ȑ{`B?c˛l ̹J1̌iH(U&:eJ$ UCjK32,q31V0.<O'=pUZ/R{y9s:5PV/6.YkB+ j;9vi kk:l՝A8XrB5m2 IH|6#XQeAMB|`0}-ĘٰAbCT6^AYx%{RB/(1Syc԰7yd2Qo^SM8/<5Kߖ;Vtu'l"y1V>#S. LIKTZ]}vF c?VOA?~ΏnᄎT-W,%6m.N0o5 '0bve|X7E2 K,qQ=+ Xq+2'u|M )%p~^ ˻뻘f<3rzfTV^Cd,=jY b=a Q)NzV_H\6♈Š G"Qf@%]Q_xEWB÷GσԽEa[4 o.T,Pxe1"N169n4KF ;~a@G.h?0klr5Grmފ%f 9oG~hY; &iG"IF4}K<6WP,"_ʝtH~GcP6$Uk=ԗ (ǀ(h1E`ySh9&|2 P`N-X!lB1 0PJQAŬOMs"2HNX@ ܹ%dNSw{kDoV}V5lە4p,*b,[՟yJMOxB:vcGV(k˼u4 ^+nbX+^Rgߡ[3r2L5FD$5K;TDN3SR*@'{nX{¥rQr`awsn y=#?*mGm_;LPBv$)58yU~ZJ6Y[B8פ&ic2\ʶEq42A[N m @V P]fUZIݭם"pi#>ivoy9}`!5&#+Q8WҦv$u8)[?K앒=̪$JD:i6,}Jim( z&AAj~dE-_g'i1Ϸr<(e/&pr.}M%`H f`6™GaO ?>Tt.UC,!=U%ҕR"rMu۠82@YI @^p_vx ζ*$iTGޖ&umfs`̩% 4|i-ƨI?>5\?zo L^/~ֶ3ipco/ě.QC0|.^={Ĺx!k k-Qv0*6dm6{f]R)W(Y * {Xd`lWC_1T*+O&2@DhKՂE$/Z*αaywъ !D;Iv5>.6sJȲXփ_R(xH@prBlTQ @z%n,}t"?s?(CޓrB½o9聉Zwrl6s&j9t\c!i>6쇚) JV}r,KAw3Rf{f)vEKkF̻Ӽ,wQe,zfhLmT.cd-9j_KhXuJb@ĒGzlqd]' 9Q]n5.Nϵf$oHvj!N띲6UD.n7$#AAy*뭲c1:}oMBa=@ϩJyxH6O(DX4+]q<`!i b*"f0A]-9l e]5uE./_eW|05;yTGgF~)I Em(uOu7UѤPMNuE"]4Qtx=]aW^m%>|M\7;CyuE4bPzCc'Q-yaZ8y+,K4|-1zq' *iaV#t';ۨ,29E7Љ'J d4K r$ee-j~}fo[&>ӟLegDjy5E%s=<&:t^p>뀙7*($K~/PdCt`iGI^ qbgR$mgzНUZ:hBszV [)UL2it,a ր-\x2،)k+':%"?dpJunqظy^M,.@qW*%'kOXEt`?I$[\7W\:ϽMUqS$T&Խ$CV-.ĥtW CjVȟD\L=LB L kWu󸁎Ng`GsI# ue=zUKtANYj(.6xWISm> enP2^37-܇/$'2D#XcÏI5^a0ġd k_vu:A[Z(T9z\Jlj ;x%g!5ɥeNbpՑ)fΙZ"HliSE3&ŵC$ 3U=SjzO23,z9>kojW[)򆉪8dRt* 4JHg3rILU/vJѪ!aB.m?9?LC;}DS vA \ bcW!+㥖)4&!itgR33xZIYk83 W5~0up7 1v(œR6O HxkI"]zo)C Jq _BM6Z8}&4 x eZvƿ"42ӥr/*A`":& TbGTz)1o^Vn _v͗u;d4Bi+ 3‘? Z=V@CVCܔGb ΩAZ4ϰn!}I$w5Jg+CUJ[3> Uj,f)QMkkCC~!=p*2|IPOu 3 A颢ރ"@KkW1F q<~r@٧ $Sϐ6Zf>B9Ӻ<1py2!`KF9RUU T(""8/IbbP-AJC׹6 \PN0[ gsLL hbԀ U(?@/7/dv|ޠ M%cK6#p R}U=Ew`$@ՎqMni~9ۉcX(Ly`H8׋]yb{_!gU0"جixWDim / 6" E^G(cC<*XJ/o@Ȋg8-rfZ蒷mg |=zR`\ Pu.槳_K;#O? kxULl(d,Ϭ)B/wLrAqi YDPit`Py>n!.8 T g#a,+gSAPͨ)rlPF#3nq.ܙ Uq}x۫F$ف|ھX}JGPd^~z/Käٳch8e2흕:sNjaa%7u\FacY@︶U`TKNܻ{hx݅~~}H9dNGlB>vJg{B7xrw#l[r@tE^=QkM.5CK@N!R9ܼ̕*YmowJBO`-5FdmN;/DlD&Z6M2Vv L+|"j LYcg-!ӑ.3uBT xO}?l +Rv*.b+kZѐiy#N`,G`-d<{0(iOcx _9i௘DK~4p=P@@WQ Kj}أď!W_w3vkrNQQUZ)Ɲ'HAC+Qi#^iF\z"}1Mxګ_BL֠ӼLH#O%%> or?J{4''Ts,n'Ł;N R ӿO+\d@cdL~RqM{Y#g1p]jC"liR6LwA^H<zV94ď=2M JO ҂4Eꘅ$ݴ7ɚfOp2rp=Ƴ+5瞜XUux냳 Te|Ne!l˦{u*ڊF`*gcxP%l4ɹԲj *䐽0Ai^>]CߌRjL% F ? G9֠ӹ`FqNfN0$H%h\;;ʗqUg^e"MQtޭiK%,trbmt<+6{ WO^N[MY +Kh@9,FjlLF(EK܏h8;O3SX /&o-JrPo^5MBRSaT+PG6l![Nŕ s%-ƿbVXHƏ3qXMe>+׍E9:M ɇv_lxW.m >N[9W4 )BٍGwud\0Bn$i^/:LE\Խ fG: ;g;Q7 S40xPɠPE>5H1̣*lv^ƓބtsLuruAhoppC`ȹkUw_B55xqlʄ qGaRc+tM-ڈ2Bt|C_Fy, ba%cP9kٳIGFN,r3&z."Rw~WMޟ‹$mHk HْSӤ_qFK7V릇O zt6}A d'$m<'ԉ9Խ6zHHP&D}MGPhNaYlkWF&\ZbZ6n;gdѻU$z&c].7#,B职uN4aweK2~|,QvõvOXv(vm4;iGqMZ)rG^zgJuirFFs.GVazZC< Y#H$6"b|jMPv{zl9dS,t%:0T,2l޼ 1*5-lwu6/ Wz$]pzD$e=kUzfЋK{ nF8dZ0%C%H@I;\DrxGEe +irG~qN:J:>\5Y8aW1/6EZC>uKq3xhZַ0Xe^S3n+*xU27$2;g ۥH1*/28!ޚη(PǴ:`Ch\YzsB}vLUt*I42HK6`{xwz4߯oU8 Kqq;+@OߦS@(>~`% _3g܄ۯ;jɦ7Y!3αҨa[:o ƣ )=`;3e ΟZ@yF7[ik#~/  `Ǒ]lGG}})HX0YtԯC, nYj1fk!wPX$pu7z’r6TK<1w0]8oWed i}iFU /1sF)&')ܟxgZ@AdbG,Y(7@7= ҫa*׿j܊+}=KEɁN[F(?2Eׁ\=(}@@H)ͣ|8 &N.&%[]7&1A0,ɒNM'Z[4Lw lQ>Do0ڇE ixSI +wS밧m4tN'u8LLD ~}t$+F!qdipXR@Uhzm OVks'Wf@?ͪ5{j,"s,Ͷ]!y%đRAuGryo>/-\\>U8{sb&wz|py؟RLi>=w{vY4KS>M]g??WICWtD874j4B~FUte~WX.p=}Qu3 pSs>ifCB~Ξڥ("E? >&E_nEΤp-ݒI YU4y ظ%ܞXR.C4|e[=H=^uH/GL4}> ab[2 2Dc+״ xMM[Ӭ"N@&@0'ƅLseuk|< H7l-" I}&Dx~ɝd́9U> MԻ\r][Y5'+FT _dHPn!Y1~u(|?SQ$"a04~ƤMA jW6s'lJn 9\BIVzނ9.6kp?GϘpYX[Ipg_Ϣtj fvmqW,_\m_+X[۳/r6'RYd˕^Z%7=Eʩ2"! WTl޲EDBpil:,y ^3XMAU@2!GC&";'Ȓc,RF!6s5#ZɊ0RkN[u,'5%|4]VzP)N\cb'(ͳgI$8pϜ+`.rv{v<&SĬ7(Q`Ӻ Ÿ(Sa4])=5O3<CR@h0i͎%CԺ 3,WxZO`z74hXbd}WU!4d09CxK]awC>K ӵ EӔV(./| d]s<@7TAGlxT@w\"¬J%S%ZXB/~OOCk01-=kaHv'3oBhsޡ)ʼkMPʓ̻3lY:%BBܜ#[ʞOKx=!5PsB7)Ihj2~ 5͊EQq:A1wMتT`5rd6@NE. :lH77F(.Rј{ (w* Y9k}/ )P!/8ۼdەS.E:TFN ԉWJzhnc L[؇@q 0K)8zm.eD#c[NC'pL*9Zam7z)Jzq.OٰPd  k0x}1[UDdKHnQvt}۶/_焯,ѽ5CJs'-eǝ`@la&~O%>;ZcfpNOPx2ލv..{g&%3YOx]aR3ӬԋjM/Y5Zi  c]B,swX8kUVf+\t!߄e- jS AV j %(uSF40-/d[ A^|R'5혏Q16PyAhN{UG@4z2Q5?̕9gP?L{SWMX|O̦= q(S\QQ΋hKuA,4jq;S \rڢMW$z2sȘTPpJ̫0Nԋ9q@yc'ђ<-Ο84ojG݉T/ɄHGUN 4<,zeI(8*KoܵBlp;< L*Ar˄!y3(=\FBzQlV,չXk1Dg`辉06%Ӕj ^]Ka50B~1ئ ؟Uj*s87=uBG䵡w!%J|muӋA݀ӏf^qbi× Rir/I)L`Z+]ق張fꬒ<lkM.;KSq:B: ܃ڑ|0S,+ 2gCΉWWNVFU96ِ?s RUPw}uT̋_vvWY?V0Ie1)у4>8a*GNO;y^@{wB? ]C<25K7 9= !{(6LEϵ\ϒ9.wܩn&.bgiǃ'Uǃ˸I,\;">z.3xyaJc7U^aV,dmJ/Ob'jFqm̫trϨ0>fTW>Q[qgd;ho!Xn-\M'C"&*(N6hkPMdg_~X쵀63'(l{wf@ߒq=9x]iww(y!|eXz`+ʧ S@"Ad<ᐉlPhDr >U*6’QՠAM<5 yN`&P;/tz$5NX;/,^2njdq;$ ٳ"\`"%k;.nMw]ۉᗢM~E>m]\tAM6mzft(cu'`EIP}vwg 5~H=E+2)hb5VL wWhHDBBJcIehBO; DqSt ay@aFƗ&@qR)'goxoⷹUDV0j>'ֵ"ܤO7sݏ4㛣;ޘE3r%hd5 gfs*)0׹dI`+'opŔ;պknΤ9Ħ!?PV^ 9atb :9x* Y@i`Y'D B >Wtj4peb ՚%|*y] ٗ})[ß{s^omߟКAU1݂#\߀;6Єw~[-bڇ`QX(\ Q$@/G҆$(dU@;E_ZP1hk`I5 `9 SjGxboAۦzS)u <xܞ~%1tǫji4cΞt7XTt[Ysf6HG"=~F7Oꨐ,̙@0A7\@չe+JHJ`m+hlXΏ&mlx+Ŋh4Q/9%0" T !wyiM>q2bQoҠS^gKJlYS 6Y@)a;҃Bk2~I$fR3=h$:P/ B3?xP-ZkWVTe1 J5M]=%3:C^.o(Fx݉8vAK9\l7 ZmMABE#t;> m=`eWTd#qۓf\VZ=e7$v5óJ v{70F5-|"|]z{\Fi8KS W*2DqGf1j$F*ŏf\D5`RTtkL(v"~(@gcٶcQ:; NFVǷ(8n͍xnO֚?Vk7u[ٵdME B ~ᔲAe鴌˃KHBMH zWOXUՑsEigCzKё<Ĵp jj]£fGzk4(DL(h;_]ay%D9ڮܺz+"x`@adIfJ _n <^ a+<1VnбNSևl̎ qJORbX<\@UJf-[H ݌ge7pܦ+c1.tMȆQm.d7ѝN} 5'K&\#j"kFS ?Lh* xt ] 2 ǛVa !!9^ `5̕z}պGF)H nmgbΏe'0`kLcZO\rlnmW]٥ 4?GcY.j5z6s-G_xV+~2PSJ/:KBА'zߖD6YHwieF}=vZTKI2 ?>o"2  vQ>bYԝ4 FXqD+l~&Mhmϯg>tRTb@F#Af4LI[fS>˼nUp{w{}J1;-e:3LtƻO @fƅT"B3<`-Jt'Kߋl{1bhPSpǟV(W e?6+j*=gpeWBJlZ<{hORmս$AlH{TRDGʹOXhYsHy>A_q[F@F |"|m -Peu>vL@ S" /\ uL6 &^4Vh}b7>P&WQ\;+67Ƥ-T h9vHhIGZW펂Ul*[pN〴`96|nmm$~SN%8H523-:!Ż؄BhQCĶ뒆>0Rk`Ba^ZnXQRp@g̪YW\:E6!hY\Ǝi4gI}ّC3o͠ ׈.z 6m ռB.xףzn2 c-1d=O{BQS%^;6H9H }p4X Ϝ# 4NcJ-kx$҂ +Jnൠy/1KVI/ξ/Y\p0?c ";"= Kkb)1W .K}K`JM{I[va~"Xs?/Ɉ@`+1:̫Ed+,*&|)/–sƿ24j>;EG=bK :'_~k^5:S1ÒWJdGuS1 C,` -l"f6SmEgp7'ԨLƸV 9de=*2"wa:zdl0a_Edvc'բhR5DҴ$z֘0S3'o}2~B0@齎mR)obi.2nAIds/r5Na5+MITvnU838 ѕwXl7qҼO "j,-PzsG@| 77"?))Fl/i GK XmJzl.23jw 8SL=X@!žwXl!5`BOjvSֳwb5Kn]h =`#xЀ*~0T7MRH\p^/-Ī "YM߲~Ǹ:]{Gp \s*;y5\&yk\?F~yS2紽4@~NN$J5Lr6Ϩ> ] /)LH`}Iъ}c mWFuG=_WFvs(+%Ց|EDZ]iM8m%>tk=bbJ^O^&ѡgZ*wyC;E .;x?]XWJ&A'["IeiSC&a?:-u7!.[w \A{PMx%Dj j=}ZlJGت!T"\lZ!c\:5#TIXJFXrX7wC4[(!,b&k` _Na*tꬥΐ=2/+`vu鸪!U*WyYPFB{35e x#{8XDbRT"sa3lh& w r7嬷**H2_ zHG ԿWQd,W(C<,Ry6_5kcYCb=ޘ*-x4GKۦRn mӠKc~w^,W7cuO,ƹ?YфxA# ȅc3J)bЊ2$:g}p-3G;HVgcH ̯HhؼW ArA>7o[}j b7XIԣ0 桶QHm@N` iZ6'PB;4`$Sg_WL:}h1{7H CJ;Ӭp(+p B ˉ8m(qmw!%N KRU-S |NA1z:$`d%+N|llm cG6<G szI6ku0\) @:Y1a͍D8t%ÉR.Mtٸ#.ُh-Ȕ,;twP X7c(H ÚcJUqcuwA鍽e[][Mx? 21r,{49T& ҀF?R 8p9h}?/xOY4&VcO/?Tgt#T-M@Kd,#;;f=6{9=Bx9"̃JTz'*oJN*2[sW97-| vt|T\?abxp!Y's>2$BPBytY.|RMޥC uUrANށHDyRC裙wcC%JAQ \cJ. ;OЇx9ߧ>v\O|bPlu^ $!5hfbV sĶ=3D N`삜 &~ %>zRY>нg꙼;^lY'+Q[N7#wn0'J0%p9$6O]s=:|GB #> aZ8r/q@oOwZӚ vQ< LnMt_г[(">2<^`1l|Il/hŨN&ź~N xmC:$ 6?y4 w gܤ/".O_>EZЫCɪtKlO;o#Jxg vޛjȵ4u^oR4|mDʲٌ`x8vd:Jߥ{pp^ O@W*{J7U/}ʯ>=,!\8@Ck"@)Si.15o"EX3^KF)\[f6Avcw{2J`rZ} maXnө;#CL4xi֚K70zM 耣ǀ|\mAk ^Tx7GvM%,$:T{_䠘Or2K1E¿y(?U=Ûh>F;x^&E1b6Y3V5)E('rW𻸍6,.{D0Eω6Ba|!ƚV `~uUA4gAbmMǧBEIW-;ּ4V(ՠȮ=V/ʭVAg(F͋2fk!FN/O,Ol-u‹%{9}\)έO* xZ8`u- LϘQ;Mke嘓160ȵo}!9.r ma~}" 61LWiA#)c҈ ы!,uݱOZI1 mA +N5Bn+jkY<ꠐ8Om:VjSп$Ҫ'uBMQ/܆}D{W4&/@r1BnT- ao9o(Ay r?M7CƃD uaP a5hkPY0Rx2Ft|k5 W-,vZR= h!yeRHq-l3Ӹ=&e|Hrb8 멺NZv (HU>kL'S8@isrWXN~`D-)OFh M{fC}p_GR0"[Ash~_8U~?BVu&]% _j,u596i4 ;|t+-9P|=9mX'\"[H]R͈/T0j"#  ZRП 1D5`ܓ@fs $X'樕 1E,*}Nt{t%c.ӅeGtѮ!PyM/`P m?yX$t uW秾iJR5H2 A`|^pd@ h^RmdCM ^^)1y1O1NEp7EОc0Jqon̄:}V$vk'` o{:iy Zf)oG?YהLwI`݊D loucN¨mvGD|{;S$ 4ۇ #IitgIj9~4D:Y,;7|,ob#Wdɬ/Pibr|X_Q,QNr]ZnJwN#fp٪(QsjEO>5$9$y&?z3HcUtHiC F[AQlR0V@YՋ&Էk$Z)uF9\ɅobK][}HC;n4dqs#7쮪7 omb YPө8\$f26OC q0 ::Ir΃f"\Ϧv{FgG"`CIc@8;IFL'kћ|t25hUF5p[el܍+*Ry;cH՚qf{;C? LGbK[k:\n"1TNIK#opA#=A{u'4yɵONgF]Xog֤c?nxKF~R5*´畡=!>8;LQ"w Wc0}!1!i~B0;ЗOʹpTNk4}8דOMwZxװ3&em]D5"E^&2vA>U.H\|7-kM#9%axKJY~;V^.> QI_qJ1x9 DkH!@[1fy@(KVm ˋ&u^ tv##$r5q;7}1`X8'O Hmϓ{>Y`Ox f|,ŲC72=_9 k(q2#kjPĖ_\M|TEז \ؘRv&*[|?=TjxFmtKq*sB4 @8ЊSЋMuZHMմWKlWmkW u @K77#K$b.m+oeaF1面F̈́] h'5Gkp|w2p'>SЂꌴx,jg r:,jtC)eL ʝJV0L/ipo)Oz%MMtr=G BS&# l@SoAN!cj}@:H"#C<+{Em[qF=<"Mq|>C W]yR!k_£-kZΝWeYz19wQECoy1ۈ~o6-ǃw6<Т0tr'⫝̸_Dp`5BWTg-x0kaށFZci> @%WI0p*^t4XɮQ: C.-"` LMUvA7u8rR[ǎ |Waط@kG#Ƨ  T,s r%5x{C ]ҔЂ}X;Ï%Q,n(]L(#eI @8{xZ-^ʢM" %T*2}c GDAc OmpGUN7v."$9/SkJWrj码e\'vbƯT ⃌0ptSV(rN15WszSimq  "h]gc(1GKQ5E#pkW+aZP57zP6' ̮ 6s\&;Qzq0Տ[Z͔|Tcgw\ƻȀO}鞈4bVw;Wa[F%1ϔ:PחVz pl\k⌷ݒ0:!@{VP\hz7fQINEMx 2@{GqP & !'goY}F>yENJK/U𡶳0Ί~K (8\EЍ9-`8〘ё$/g|3XpIRsء Ƙ 쩽PI H)|QQRĵIgADtٖ{)Ϡ]<#=:C38~0,ADOcch;T ]z2y eaOuXfZNUL.z$n><yUm)05ţuRh$rwǢيbaDEUyvGpog0ˣeL`-C/p)@!L}bkFf>.i.a,}?d6E]5>F&G ҆dYj:iO`-36"{6;V ~$M#Wc6Qg3fN>ZkUm!U} iy~5d -Qh=J/Px_8o;,)뻂 QVA3\,u.gǭ6HU?rT*r"BucEe^%0[U,4BiO#Kt|~'B vmBsꖥ_8 z:^5P lFq0P%Jַ/wE:`<1Z) O}aG5<wv9I$m^ -`'n6[O6,ǵ YE,, %?'ec߱~);q+LgmcMo.1k 5Sq*:G;~2\(s8Z!?riPdLΊr()qy0ՅVnʦ\Ԧf] r!l#aYĪ`A 0~b4e"\-$8gxeðy[ n LxZ9 aEvX+̒Y߳ߠ[n)9pfnf=yZHznԩ}Hml;TM,76뎞o\St%I z}bL]k]bjbϰ6"\[A1MsJk5U(hfm` 4z/Q!Wy3 ۲):f5FP~NmE1wJmE"N= N`4BB${wGTWlޭl*L96Nho!"<YΛ&D:jyc-Dҭ]8=1J̫JSetܘݧ u؛;  ZYR8F,}"'sQ4NW1T(hG5$oG?_َʲۼô+h8Olxv=`M%O8>2-$&Ln4T9#Z-/^Pۍ\Aߚ0ODKlbmt y9ZrWbjdRM>Nȳe"#:j157}}Q`C]Z(?鴵Q"KǻMXIU' - B)߰x-mhc*AIҩg4&97sbЬdg$ )WmC48g Ðgu$Or|['_1hCp;Qk.'D%3F瞪Tzsg6 K(p>f9؏1 SfL Wz]tv^kCJqh5rU 'y`ЉY jB>/Ft01&>;'fD.;hڅ-1ә(~ة M@>O:㭦ɘwozkuꆊLg::˱"Δ讽px+;Gw}n |Bj%{yz'CPAHz PHnMAGnYB%pl7P}?F O~Y \l#G \9;eSMoz`{Ћ!KEQ^nH°\D3[u JY3e.k~W!LChKdq~OW'׽D<i8<5ǀB,c0{ J& ҋE~P*L[4lƚw@3L>(8I*@)Sȸ U,1#䟴i7R+xD2}k.q4pϤ4Qͨ1I7a ;gXV C4htHsX*wckpT^ az k|avyJ|$eUEDŽA/GF;[ȉ[BD$s"E׮b6~z<= T=^e gؼHJ%Qn@1=:OPWX1-k'4*"H3h6$N1K_!ZZ.18ٯoy| *$O!\ XE 7vVO;8&3{C@R``gc¢^ 5̜ZA] {O߮ Mߢ폲gI9w7kvA߅QUD.]9 kr"uq Y|hUa*i؎bVD7+6ntX~/cӱ4B/n΄b#4.gpt/~bh>:Ŷp{tO]j> ,c̰vw8<bJg>H{qb"+prK뀘P꛻o#wy 8,wA m! LD`젗 ~[u9C#Ӑ<)/g?", ! ,K'h \UWѡ< lgKPǾI7|"5䵐'M Hq,{<>Pz _7;ʲ㪻K_Jq]!OZ&dŭKv;adЀ8tYYxsQ2ݪa`-$&)'?@$j'Oi=GˏrE%@{ZJA(n .} 3 x,E_yʧ{A~iqڪMR}GyTYpPg?{ /ܧнZŌ/oxE =WMuY]y2<0m4'Su1 B}¹9fK#H}lUkW;(􁺋BBbyQa:r%҄ ODBaiET4΀ +(Qz=&eS[\8pjSrJ  |> ʠSf[<#UYjWeDP`NnՄe1md3%Q`<>D:Y.KZޕ#jTJPxHct&o=O4+ y3L/ߧ߈SJuNɜc0˹ONpE@Di/T`&cWch7#S?|]nT3Z22^`d27%A aIl=rsޗ++[2jg Y3}*9~}v$[(a40Y"&I(>brA(.kǚz$|T(}Mz槝YLJx%ZV"O#`DZ[WXXJ<#ڭ^QKIA~Km,@4J? Syʌ]^7RZOV!)"l 0OT;=\q'GbiԿy8p좧˱_ƒ#C% C%;W)}O; Ҕ-(5v_&EĴ)9vړrZȖu2 *r5Q Jw$X9q\-'D}9DCI_,1' qvňVnO4ȳ͹W;hYDSRc)•l%!,֖F3Ӷn- 7BԢ)Tp PSD9R?Pn=?򒡡OZe{{#%wcLD:IW|WM4|aˋf*~s-Hc7UǛ9I]ᐋԬaHTM]6r$/hqQ^Vq:.j\p3FV5ԍC ʰCIoMޚ()KSJX={Խo"&-ʔ5α'Vr Y6|{@e(6_FRSr>c=FINxE&«|uU1ѤgYqjf Mrz2(V?cAǘ?q)~/9q1=).^bى_(p4PѨˊ}; |EHIQ1J5o`EӍ0e6lt]2I:1k+n4iZ%m_ X!uLvRM4dM6XoZZ+u[;4G*_ˑU+N-*➴Iߋ[xl#ȱ=6ıLdR4Mlc]t$\V4 yϱ OJ'ϋLXN,2i+8WeI8PH[Hq0@2á0k{{E^!pH~+ >Q t$V0x R6Ndv*>tIH2b~%/ :8LV}eʽ\;lq'=wE;En~T MCk}9t'.?a.q Шzๅu/8 M*vDU0Vܻ%5^T3m)AIN_'XRr%;O#Jdθ;X"D9lJy+̙tHmVtV?tv4iv W]^JF7'w{sTU< 7g\h&'`P4+_b_> N8MJrF{8O5y5w\vi 9 G&f^R,=C1!݉ {P eoZzȜڟJjW:HոX(OXx5X/jCR 굛RcGC'Xw> eU0&iiw*$(ݘYbHZ3 Oa[j=ߓQ:'bct0oZzx27b81'1T|2͝7G -wYwXmkʋ2Hc9EU%Я%.vZ|RDQc0 'RH,XrWDgP}d9rp~4 d/qVAt'aN5nk tYwXz à9Si5nհJ{qq1CCF}%c94 bx<Z|3): )M:r+K⪜3rOQZp1 ;/7J0}yz]c[pѹG-0t|NO䁫(ދ5 KGylf8\(qF}^`apQ#ıOwtp3v4ge_#|@eX^V#Gjg&?|ߌ6jָ1v/y7zĎQ55KS.*ZK0 >2%!NL.V(3W Wgx+)nʺ˙^0W9g`x[zar %Y7P'4,±:D /]Hh@Hsm ¬5xTlT+ҭ&ώߘɲwz [PaNQ=#4A"^oUWVmUҝZ\{GgЖ[p%{W Df;,R]3 ?/`O:CܘtB*\q"gy߰hn%{ 1󴼧dWܛKT\&J9{'?N10|)l4W뻢KXDN V0"9ù/49 z9\ָC(3w։õPY++=@gRKX؈H,E>sveHya#@>_oY:3؊+iyi wQ(--~>45Hٖͦh-q17xxڷQjw-UoDI a RH,@SQ2 L{cbK1;HwyiX5e~HGo=}CrMA5 Q2VyKvUr\.@ʝYcC-.B D5l}HQp$U):Ρsn|k&̇ ZH&d꽱5^ &?!k1R*PKoKZxsM2'5c}i2I5zahE`ВV'JD7Ýz1Oi BL)!]d1` f5SUTc|IeL]y Zd~P@YZjL J`Q !Gg;,h\i@J֤P[lzW8i`Sd+ 1h& mPJ%KhTI8Oiޑad^1=@IG°Ou DٰpIB3 fݰ;*Sn`t7yIv~c&ܔ/[^QO+,/H>?{aSRy+\8x "m ^,Z!XEʫF830 ܛK ={=8t gA%+{m3f)U2jʀ.B xPYkmͳ]s$1@gVʒr.66$~@-_UV-k8 ]F&x2g^QlT |J|mkֳ`!Y쨚y ڊ{2\M6|kKop,r¯UMO_AW@D`Δ!n@}sQrDan%h׎UrǯSEY6(.=iho·݅ \XըUl[]ܱ0a5>+ >D$.%} S/P\^8Neܔ~/. -@KOؘLp^:Xe$:!j eƧS`2Y˅萜ԓ acrB>nk*@( /h!ߠ߬.Hb$2vv 7mAK3~qU֦Z3pk.X-wy5s+%ٷ+J8I

nXy Ɇ۰f7+yȵݥx0b&*`\ 3Kmj'WW+RN mV.O%}ks'H O:neF #"7-mgG7=>!XM! e8oʯH|)w<HŭHe?ѴGc0KK>%mzF(ˤڴ&MRпzT3<Ƴ 0:_㙽Q\c@ګol ۝}Pq7B ,z!5g29 E§<&pFҶU㿀Ϋ؁B5 Dv' mk*xAe3Kq]NĞ{#)NYboNՄ0RN CA0?F%tĖH )ͪKOXĭ  |+㻛9)x i Yf=- E IQNɇs+kt&"W8fʹ&kg=鶗[ދlVQ˭잛> WfC(>qycBHb*tUaB7//(o<$ZZ{0|\:Opwn[#3w&&VqZlޑTm&&iUIreN3tD_#A(1gج U9 2θxx.mm;NRR/ ms)fwr)ʶ-e!wK{%p0LzgڭI'4:XNŷ^Bx1&/?q-4dGi^Fח(iG,tGh@˱Lc2 w"Ƽ H1o@]=z}]љ٫c&~]FQN]Oz4OBLʰ0E%5ow8)Q+`U  kG8M㜪݋& Ƿ'W[&OJC / 69ճmP>$^zu8cGf `ߠ}Zs-r|o5&d{kI3kA5iaKD9 i!\Xs n$񕣵.62CvM9w!\!FAgJCQ-!lv=5t;GF#$gRn=l-4<0tP]7uu^ST(y:Ql ce]{C^"o -N+2Q?7?Id3.uy,;X>jmazeW0T17W'[.vG37}Px'Z ESc%5Raנu𧒔eoΛهuR7X@Ms o[G=6yt5u>ƃ1x%};˺@MX=VX?>L;ֹ* ^'0I"luq@̥<=tx`V+9 wAb_%W| ~?28 xN&Epо=8j-B.,Yk P yOoaIӠ)O|۞x~}9}<^Zv{0V҈k^&8;1kVK.`y:KWUi.pP;ps 4?([s ~1}tm"xI 1$Q|YH.O=N\7c+4HkTʾC3:U`6TfFj @2o[/55%ǕLE&y5; vd ٵȎsed+Lh pnit^8=dO$N*$S\?Jآr"%]s>xQ~#\+7);m`; ;F /G O~p%pf=mϾm~Sď'p| "&lL&=7,gr4vj > >!䉤Ë۵Yg{m50aCb]51*lvuc~^jzg8Z0;[At+ B'~Vh4~pM\94\T1#BԴiNEg RP+.O陽GOM| *BI캁?%<~Y"!AbSb&Z&J +*RHp|1pӽAja 1Bzrah:HsCG<6[ErYܪL`\yXH[s9{* ۱v{ SWRyT"" NJ dQF0kEm,bGLzʁMB?MrQn1_*nF)bƇ%?2j:RIj7\@`w3f/ƢzGKk)KXSɖրo\Ʈ=Nns0X!z:(oGSc=P0:gTYq-whFeP&-iCP0 ݙ(;Ouhm|*ءs/"Y;wuhӫ\憤?b ml7ch Jw޾Oj+ cg9GGBu {7-VQC[Ji]BxK-Ex\m Bi4ӑ@f.snH{]HTBs(g*BژwK8GY dcꀜc*B@ HЪY=!铢߼("#ve^gT.}X;yֻ%)dLHRlLzoxX2GCi缘ld)4# _Q78Jy'.- ΈI^B{~ Xƥ;D4!%Ԋ ؘ#i'5"w'?jǏɮ#̵Rh~!va n%owJ؀ o]WhiRByvf\a<4B ^𥧂SchCO]w`i:tEYa6eUO5j߳  0{)0pD]}y6}_W|Q_x|Y,k5=&̻,8҆%/wbPw:pkvIESՑXw6i$['s ,?\d3cyWQ3iޕ7ZWBC5*q_y"p>L@uV@OVӔ'{T\#~ft'q_%Fju*Gh@1MTQi/C( U݈H,ձlg] 2$gVy%imxGD{  &ĎZk TԷ}OVz,^ Z`H6Y?o`(#3 TE[-&ҜTO@=L&@=)se?!>9i64KfF{-A>:ŋr`Ger)W/=ϩIahw4HX]W&R*K7BZT%R.KXyL+);$!%rs!Wч}7m2w>X)*ofF@(xiz#ؿJ!{:O1&~kìY+5k 9w5*Sq,謽?VP+n-ǼqTX91BW:|8Oè@&e_{9D_mI=,3*S=T]uۿ$2([bUO ][(j㦅`ld5͇d&8i M[hs-*k~1nsCɟV'$(3ZEȌ_|?#LWy"^9)=Ucx\,(:KȮU\̩hTw-i5qnn$-aڠnY3$Ԃ\X oZWH N7 #jҮڸWS:fP*B?AZzdo쨘o⟬ 47Ĺ>:"n 1<~(36Qoq>ݡ:sk.,kec7vɴ%;gҭtib {u z3C;D73G @%#8]6G;<Ů'@=u5z?zxnP av@tr#fCoRS|'o3\cϛ jPZ}^cVO3\Qo_1i3saz89ٽ!W`̭ˁlq ?͇kvb^ĭ(վN,֛&=*ۀye0o0} zA)4UJ>0V,tQנrubhtNxTH>J1g"|*X}g*;Gi v$'.+G7NZCfdboth+b9/T2K1mPQ!f^x͆d~wc5cbǐL52kݮ4Y-}q2{ ¸q]M8.=a,i. @򹜻(8Ӊ@F?}a,f?םJ~`ۂR{bX~N>QQ|E8KO:6C4Ψ&*an{ ̦<, G&Ut濓9IWxc{c6xkp;oeu[BY^p g?zd~<hI,2.5 ډjۘ 4\E/Ss4}zGWBnd`O ?#L9xH!{}~x`ȂeSVъvjf|s7!I\_GeR贆?b5ZM&K1kړ' ?/9#Tk4^>ʵUh{*vWF*}JAd8}WD|7j2,z9X}-!DiܙL~%e$3C3wcP]p5Rnke[ƛv[{Oq 3ړ&HL@pNXrH~mraLG #huTɬf-%6%'Tzt0zp3VXRTkYI'7hbT8qh/n U 2-`IHמ5n*6Y)ׅF:y=֚b8ϰ]\hH2 O#k)f.D̉lɶPNvf %m z;tO;~S"2+)J{P~MIp_N1'jj~ vkOMy_|Gvr%8L٬a5^~T0. I8ʏqj2k}æ#hOˈe  ~mᨍ'z "LK+~Ay9̓6_C5̆e-ҷjVR܊9i*rIEV!c-YZ 痵:Abit2]:?Njzn#1A0)s8EC|f -oER,1KGRɄ+!SZ})K[ک/gӮڑ(Źu7'3'ư=>[$P¥R7+t:)c|\Nf]fΐͱvy(iL%avh_\*Y ^2D _TC. 2YK,{~Qz]90=`;_2C$ejs *-w=)$`vp--87܍SZT k_O༖^s%_4E:IdPRH lZ֯@ű3+;$Q!śѦ=|zˁV|&07j*'ЅnUm9 .t6 Kj&G'lIWdaf+ƍ |!'AVfr{w*Wd7mQH07*@"9)䯦LmQ 9sG`gQSf>FDZL upFC_jC\MH|TUl!`0?QlNC`9۩x>\+P#ȶfMmN-$(* I%Nr 9S Ι+XJE/̞ 81x*f^K`ޖedV)<@f޺1[\{ |8-)u:tMH]<RY_g\gT8 m5+  Dl⧠4ȫrO!:~3-B/&#cA`0^X ؎r3LF {+)m M=Ȋ.X` Jk&t7Ǭ2 aS1x͐iܔFbN7qH"„Wx62]՗%D{ L^-o~iX#`vn4؊3ZU5/WXG@R>x:L:WqF4';mC2Y |!VzX Nx.۸[d0ZL7v$ Μlå> 5RerkdvfP7-43%q;Vk|;МÒáS7i$s+?_Т|R# qj!sC.Gkos{_xڸU{rNp"&Y~\˃`o75( iXtn9$rx֑4_T{opv $h]p 8(ʍW;OvI-wz~Йl d۝2ՅsQ ?80f)4~$7AIvYyY-8|#'\tNm'O5<",-A%w]iBopII<}4W>@>;C ?IO`+UB4O ghi27#tvhPԦgkSύK4 >ZI:Znh(=M<Îj %/^Ywʹ$J%H(:1/m]+H1(KP5w~A6|~xVZC x4UuL b7S5:aUn@Is) 0Q =J((p3:/n0b? 6`F Wa>{7+7| ՞/k,W:W=InJ/~oT_>K@ eJɾ}#}^>r7uޠPY2BXPX_n@ бtޖ~8zQqk\UQnO;}_{yKE|Xư?UO2ت/woSȈIbkL))SRnB"P|p ɬ1]?tB!kv S鷣Wj UG  5 Fug/ܨQQJLlR]ާ#ҡ֫l旐rCV~~Պ^8TN-R9^ݬa+B3ukKGzۓ$IK:d *oITm 5hNΨF9n[ERDW.0Y">Ȋ\EeXgD_S cj%I|/K-:V#19!.7*J/5GR=@̀-xǏsԸ'`( EpƓEV[8kjQ*:۲<7aPy[o)PH]U g'~6Jʨ๺:^J(LoBnG@OU[) Hs2vPSߚKnsRRQFY;D cq:f\w_KD^j}Ͷ 1Ţ/hAL![ה5;CL9_ R?Ag{Q~3 P,.<~tw"e(?&Uœw=mm a@m&E{bJ0>Wab!zq^F2Y{n5VBWնoC~W766J86uЀo<]D]Ng\Ay?(z>&* oY9QVQ"@Z\}}H3 }+Bo_`]E jd@4}1QI8[T.:瀉+_wE}`e BiǪ:+U6xk{gϮ~DG;Sd3!.l y7-0oؠIѕCY +0y=ph"yZ萏>6[mw*Q҇u^cSF% ]@cP|)A _W-JflA#~˚yvsMAtPkn=\V N֫KW&`7{ xDF'0t]ӖiTkGkG.o vGx;c@yv< Idxȃ sirTt2Yuj 綻%3G_S #;CۂˠCMKı),GYrJ&1M(6gd*kz OGZ;]%v-@J^$5 0S2`^]tHaj#&-)7C{ ]#8˩" RrdMR!Jbc7" Ť}h% +|_=!_exbz[׭meu .5voM'wpE RO.*.ݦtM&O߾1lr*Tt&':ЪI&к}؜ _E0+~::gˬ5w̛uZ8jLmVSj.bn u V &?Xc" .L<%g;L˯ApSV >G2>tv_1g9 _O6#ze&j_xOAH4D vO @wP:hU)gVXY/to']d-+@Zp?2k>ndf!C^85.8`J\T P2tVLʛgt:_6+fsmܚ.~u H1Aa}ڡ/qY]Z15+i*O~U_0yZWa]j˞"~%qmyQ' *:1A$ՋW&`A`>/`u6 "nXIVF{hoLK" {>:% c5}>&jW_SsMܙ%DuA %}2#⯄|qQf^McTXźp\Zw$lr.߅&kKM*]D8RbC"G/]3QpԻ-g pqDnTz34Ⱥ$ apQ;G?<* qXwש֟!Z+fW҃k4'ctȸPʤjyi'j\3آzW1 ͂"qll)T\T݂YaRD!29jJ&έpiYU{\V:DZnl^adK<,WZ)g1 H! c_˴> l/ ~jGݹZp%qEWfiByn7j2N=v ΍P낀A6<<&=QM<o޳7Zo_FkpYRfVOp\5aҠNnyᆋHN㣫76.kڦ+a92YruHA!rąse +tȵ/:d nlNPSuP'MRoNAsl#ckUVhVVv[yN:~!zQJn Ad !Ѱb&MC#f1 t/]\v <0;$#Y+'Is{ǡ8 :} skt(é(HQb]w-Z_!XDXQcwяbzq [Uyz?B|Ww=\8C2%\S85%wd2=oo2'd(06=b"iGb+PmUr]IIFD.FNĨ8M4CW`Jra6isܜ p܄Φ Ss(˜)'yG$Iku"K(J`}Z4W=d*%9pTݣpn4@Jur o L.ب/CXG)Y^7 cS\4O|VG/g zL,} $Wrm@0P=FO1x6[!H5ɥ*+6X§]ksڬNKuludKSY~D=@rG9M {A($((3F. LW[101\{~4ps*qe)ʝIXúrT֧Ea~e{"[pC@f)eW2OS.X'loƵ7*iW`77 ^+Ubͪ6,[rOb!V mmT.f_59Es `Qp|0po c.p}SZ}``@:9X-$2.{5b~kG|aB?=XClY .e.)ay{a)o.}*EoQfl[.})=QTe7Z] 8L9ѤB`lkGmNwi<@hI>KHWGs^Ԑ$JV1LD+ċvM¨>ݑo@uWXkx@C48G61wC+n{#`- D:8|޻9xFxڂ#Ǎ·/h @m3$=t\FՊ͔4IjQ:E_>j~:LL: sKQ?'SjQlst-f=4~C^Bw #H6 E7ռ yI,Bby?Qs{h*6yf~ޓ Hmf0+bjJ)|(yKN _Xd]əLu/;Uo?譇 K>92lj ^O [k?^Grl'–ϓPu/;dɨ=1Y?фiZ=Z:<4 +Ym2qdE,΀R8 Ԅ):Ջ”bګ-Jdy{ICƅ$>R7+X[( .M.E܊^UO" l鄀mಃ0vʍ2UvgXȱGn|ЎQ-_Ronndiyekw+:C >7#c 9Z/ħқ(5Kkg#Zh3mzhyxԣX"Hg][ R10FT@+׭7ݱBFӦyAٟOr%%xek S^̪ݮ9oO ;HsrV`(:Qu?N&kVGvno%*N"LAk&GҮ,0ďaOP V9W !vDoV*ȝm6S,ェ{ŵ:+@ 7$ LL qeNkF^rٱ ,%v}B26/` `^Es+A! R\7py& ㅶ:Au2lʌAܶ5~`{I@k@ٵ.mɨi ?2 N+(gcGG:LDA B;;Hn׭_7̱h.|ZtTQڠU&2 y#8Z(p,ez.B3 Ѡ z:Q}.q ۊX~Sud;7k"|,OhNL}Hƙ( ӄ8[4PKQ2IEvZr+R=;$[p{zP`]BQ$k>E/Vq#}?K:s-1~+wLW WyAzxMf6|9Xw.Dv̳\$3Ǽv ܹJ–l1@.T)샆(=KQo<IFiJ鿗  K"NJ;bԫ%˶ v r"~ʠLꔱ~~ZOp$z x(*ɟv]/*2w˜čmoԐpkHE1b'y!3@4 HdSl|bl˱č˥sfz&[)Zf!?\jb6j- }tL3,flؽubE?A\+oyP ٓj kYo1 J̯?d藪)=w+߳Iks60"+mU8٦x[ѡtAS;/YF,Oيe_QRH>/=b #e+Óq\XG+QQ<(z.MQHj i/baB V L GbPsw}Y {{ew4?%RAD ˑ)BcE|S늡|rדdUϽzUskk{HAB-ti@$s?>A)jXtV TX;m-SPUVjcDG&jCRH߼S ;uDsF+4կ;s^2ao. Qvᙉu Pԟ.K}Z9I[N|AsWV95aJuX%,q~D5}wĵgr^y =}7ؖdƭk w<株*;bG&DRFz[:_0cXxn'pgYΦV؞(r"9O٧i-7f; w.Fboݤijj+(uN60*0£j|ULae xj{s:H}qoMDB xS$mEh0 h:1t4 `tjq9=Y|F=U YIȴkҮr kt5(ܯsUX=zJT Z !ĮB(Ba^;(ۿau_^$ͷ6c35Zcz]ngS9\QW!Yy&5fŪNj0a` u9M;HR''qyXymOaTbJ,'}o=⣿WS[fRߗB%a\Jn}q~~ߍ92e2jQќJ c1oH\9{X/.n6kL+ZSDžx5]S4O_(bIjsg)ڜ|IŸ _{As(N~ѯC@Wj'l2xoBs<\24^`K[dr #ed'T M>  2cw=*@_ʤ\p"XMwbeH$t^. &ώ CryRħMqJRl1Afyf&P'tSz 3wnѠu~7X^ v* dfjYZ$NzyhvGE F]H㉄^Y%7pZ4?f8>0 .NGoMfHfF٫>},AJHsf q!\]RrIGB.5*2<:o_}uռ ۧ;hhZ^&xp)J[}E^{$>Mm1jԈ +(p@|I"Dog~/w*u<S}(Z<&[hlgz"HPk1ew{ZߖL" Z~LKg)XG6DMƵ/(bT='ES"ưx=ˋT2BK眷f-wD;_=Dk! \`M9 >$ c8XbI9w y)t7}Zx+ruowk[Ik Uk%&˄rB'ߪ]~N4);鬴_S* v|hu ޫBPxmƜrL%tfL[: 0y Tx)|@J߱LI\R2LV!5kģ )nH{fs7_lqp@ioR@:W;mW=|uR_#c ZZ؇c5ֲ3f}ۋߓqm_C4h˙$vPA_P{='_#ItRl:#WcMF%̝~nȉ2fv7QZ> ۅO#s=O P~/NéKg1hH36%ֆ V\{Mb=. -+Zj~z! 34'%L3 d`F'}a n 9g@hmIRе6;9r嗋OJϰ f '(e$;7aKy~p39R}[f}B/~n&7j zkN0Y*u_->? #eLLbӴKկXN@#J@UEsfZR$gE(%Ai-e[tS'I Χ{<BT6Q~ַy*=E#BǩY}t?7%:KE;,h2ᙘ0 X۫pe[Yc > P0$p(!Qozs_TbzqVnX'_p$C?;Kv_p̋ݎrBt>VW X >4:-blS.Na/(л"۵#5Ϣ4{LݥVPn- K2kpTT.;D2Ջ.2fYx ۢD5mv{NȃQ f.7wxヌ,VӶc\-[gW؇P6{O0z{CDwL8 bn x1)RvwZ'EHlڜ0Eޅ`@֭?_D{Le]qõc7JyIApwQz$LYX Kmx?x{@;Zۉo4u/_ ʮ-Zq=y*P3`QrTȄtx &R 0DDLݤ-m:䵶"ZnI>oφ8 `Ң :,/)2 s&Y_E&AZE;P A/~ abؗu.zэsGr.Sch7ʯ(F`&^0(%G]r۫yit\9no x5ccLϭ7}jR`ʪzkM]ȘQ'p@vhul<&RG~I-<0Q-=ϕrU)H!w~H k",wR CŜ6΃xɓP%;[3ۙ /`U[D 5NI,[- ~ ;Ꞅ,ShezL˦xZD@.Rk% p&*iB$;eFI`fV$Op^2DzLOo33r9qk]'+5ן`? dq+Gќ8g˝SEʬd; >o.ݎ)thf1w"C&E`ʓ%4210(ФMX&~M󗹾wWirItezlE("lfX% Ë^u86fzQGF4og|FF.Ӫ^#Fz ̷ q&icVX81fZCir8yCb>ZkE(}p]HTueذjs= x@amUw4*: x[wX @-5U|OuxRaDY-#q=hxpjOU5bn~qipP=Z. n ;܅8Aۆ>c} 6N[?N6JQPb*Q;k_G aMuH?NT},@HS\b" C~>盒-%`bܚpXw`щCPN/eamnb8Fc2sW XzLCt'`]=R7q3E}W6*"/0FWrGcARwf!'7 Gq3*D,'wۻ,˷^{x䆖u62tlY p#Σrif{cCĢJ@&\لD)nKV5gqS'H;=VNcIP c}?1>RYluia[/[/@L::R\zs%gpb4T|=k֟4AO:QEzl3ß"’3pFɮ%ufV@#Y7A$LPJJֈuBhpzbС쑡Imb|n@44BFȘ$orC+(0a?Bꌱµ{6c8n׻{_NNٗ\ÄK\qth."V  L#;&jLק"Xfɘ5KVы =p2©uQ4CTk/Ef( .lM*jSZY*dw'=RPDsс{ąKZPn*daVV BI #DvQˍ6GY3L.If{vpV[ }X&ޙ[luPv >q'W.@ W#jx nKɄh@L=LWf4,~Q<MedDjD'AtNKz#-Stw>ˉnW>Ѩv[aQPe$hN(AuQ ]s|~:T|AZɻ3Q3/ .H }KVߘP@=a,7굲ѦMNd|Y!_4:֪PUS8wⴟ1>#Y4yv\sK+=28|Ubkrz&_)uMfBu<@UERۀNDN_N31XP)I[u5_PɜÎ QoSl_I,j&~3QCa:"/#|@FTgK^Q8g#!HIdL 0tLU5$7kFiM1^cܠ>p@CԿr56}2ZQs%^A'nN9J>"f%N{x[W9?t]8$ު8j&KBK=H6-Vz=^od}A=~[X[g%#\Q63P0\3NH`г#أ,Pb/ ؠ Ȁc`C=;sY -s_8qZ)}a7&w9!`VlOtU$EoS1MK\OuDvch#O;CaDT J592_GӤpz{d0/YS jAjC(3deS ,G=Kqk{Q߷.3u}XNj{}b ւ` mh5Vbk*DIE?/e\~"nKtEi XH3AD屉Zk^d ;>J۹:g;ItH0VT!iJPou̔iA[ a j:&n\#@;21gu ?z9h_naJ5ƖZHmIv>V_X@*1߽ 8 0ۋy6s-΢Nfd^]!9\Ԯhh<5^?PO*tl6 STX:CU儠nS#8VaJݫI~'2xO? `䯣qQe䘾ڱ;cg懵H \u`풨Գ8sy&>qm>uCG9H*qI1{~.F(i}gרkM*E8cYVs0撊RRPwh\pX#O ߷:lʶ#; pƲ|"c3C/O89{0ewn^+6Q+/>@Pq_t_p/g+BWފr@ili@ծ\I.R™՝@{@a[F M9+'aٵa.K2\BUA?U[tgne&q`7I%Y_Dj,(L ֡\<[,v0s( wɉ?s,No_/3%;4oU[_Ll;`krZDmF;mo)EeV'#5%V"n樁FOGM+k]:H Z+\4b $5|a z6+~rydx7RHө=CBEQnYRK,B~A+c6_+y!nWQ0`[V9d| }!!ґے}eNYc n,}T/g{y̻.oNg/B}97Q̮CB]ڤ,T3Ř*+ x`ʂFjZ4cI>:?iM[ɺ0HpV;߰S̨u!9KDHO@cVo$M%B=47_Wգ\)U Rz,уtvV ˸q/C|#e>FOvDgȱ# Y(vC*8CXJ̔A&3LрogB8Tq%ߖ{]a^/ 7\ҥR ]K1&j.7p(җҽrw2w,C{Omg*[& Zq%ANoּXuEA [tI}X^Z>2jzP*so%DTl |s|{F'f?5E+u #bpҽ͡G*3]ϩ.3$]PŊXvD=Я;.aZi| NG;!odK]xpazp8EgԸ)0>QVՕLńaNgfgUv>vh yJ` ?s9x NzPSCF/A̒ipa>ŸgBՄ8m^VzNp >}K3٬460=2,27)eŰvz{V\WK4WHybZWwNу6UNwgOse IȉoBKxĠR.@B '1hhPI輼J<1|."!i`l LZoɌe, SqUsfikVbn2Jb Dx Ơ֟[ZkuXzXu24Ubǹ67+^]X$YY=v,0#5H"axG*TfKjKqINT'}bJ !7jtoA6k=L ͨ8LM ޓzipͩ_]ib_Éq,7-edt]! $a N/nE#CSޅ,F-N]nQ調hBPW,^-6":~Cy!tS#Mӌm$d H.jd5rڏw0̃T$xAXgPMk*I8OppHgH"}_r4Ĥ-n(;1F[>:Vhk:Ue 9N: z7-Lq;?:pz|i9P Mk̂?d@l4f* i=ƿE\n"_&js2:ypQsmA=0N1TQ@FՓ19ٙs!_G0Ta>8kFʑ(hao7-i/쵊]Tl[XeA_4Qm\6)94#@\]LA*r`; ]Ak&~/,{Z@oA)G|&ҁjhjҜIń䥟r#,Pg= يkbWPd!u.dZ/%Q-@ y3n)2L:&[מkXoGE@X_M/rWf5Sdb ^ 9G (&LD{oA?avmmR:htڏ÷;7vhb51z5_0a8Fw]}ۻVO7*lMC[F[b!}lDeخR<'7fov"#ڦ"j$PR1Vj4Ȃ F cd\lXNo7Mߤzq/ /zb[Uo~x*MHۤ Jq˖5{ۣd4\W ܮU%\p!Qđ W%R ܮ˃XMF:܃N53F+:W^zoBҭM+ɋT6?I%m)9+tyS۩i)Am4zCÛ{KA'yAh$m}%zCYϴm/,2Z@x12 hw_N9 (q@h] FnۅLDu@<9nN;p߮!|tuu@kO =7*oߗ5JݨQM|i[Yj܉;C풨MQ5 k,ZͿu ;΃]sPr9lG|a|gs~ن:=Ԏ` om.;&lFSw!^~Xd{\U~;Mks͎HϲXD s[i" TRsL0KX*ГΣB< 'ӡ%’vٙ!dj/՟htF ¯QUZM+G(qI$J@]!\`'>Ct҃/[Ko.fI ]  ubM}~9qO7`xkU+R^ɔK g G=gג1w{{s RtͶ ƐU{Bxsk :X#t1u&. NmHIyg(n Cmީ,Eo:*Ӵo) J*@2%67J3 t{uB{Ʌ8mx > Vvz[m[ nHpB~oFyuxgmrMyW;;Ri@Z k8=T-g+ Qoraf<\tT5<#n@ G=(! i@i3)3@;s--%e3l~b\O/t:̺2 1!mQ.K[Bw"ez.F&bAd\Û_?%!xa]i(ty!\]LN[ɸ컿1PY_ Ĭڐl8(wZ@?F)uw&Dbd!×هLN'-em:2!iDKR]pT#k]sv@FZ U@x#_hpIuGzv8+%DG)_O59$hWDQkOTә jpU ᅥ3PyWqo@x2z틕*Ng* i7{ CrJ+Wϣ@3:KٗA/)?O4FMx>y>fLI#[:`JLVRuv1iS-ɎW,v9&K 1|X>"Un ʮCbYi^M6x2{2jLjtTogN5[?n&nVB1P)Rpz=#f!V܎,=1 "{^y:Rs7Gd[p;1d/Zh12'"#B#M'*}@p:C<+W q\b rTC\f-KYXwo;;0 `N\ >\Of"E[-v[*[-NwU(̵b)Pwy>4W/>< 8XdGUG*lAV: %3fAHV%KԪbMG 62'Uݜ^F""]a_-8x^yWC# ^zc_{ٙqsӳaJ⼫ݲV}IϗyhbˍWVʼn{^tܜj;?ɬA@ uȆrR-4O/) 㵱Vy|=7W")/ք %'k/a}6D{/5j3Xj?Gd^p-uNPe“wk%(&Fv{hbl3PRicD[K./20;5_N|'JzeYWDS%x|l؈j:z3AZ 6f|SoJcPA(X 3Qӽ/2grQ)?,"Q:g6CJm=Oy\Cǹ=SlE$ԃWvn޿A鬭91!s)R qkQޣ+7uC90M/$"I'yQrהXԛ˜1MOZA( D*k[T;3G| Og;7{*lry{SkYÐKwBuݚuПo=,g]Y0Ǡ$ \Z`U'_>XE\/o7NݟJwR'c(sgL K9t0rH3B dM)Vt-? MDqb/M/J12@3:B!l\- )ҋWcG"P\c 8/- A/}e9۰e U8^4}(Ei!lYa&-5_4vP6*u$bhw `rG;b&l~Lt^zhG>!d}+|s℠cO=65ҳ?^oYg0MyƋt 0z3H5y\/${čS8hI]|KGh).S[tg;ҲJ6`e+DF&$ghߍ=@Qh r4Xw$R('߶N<ټ`|*? }̀T:rYgm»H?yzc)2KI: 3?:k91T+.U& DBy!g-yv,3r'EV)ؼ[W%^4rtw0q/Lb&ƨd)#/ŚͅV lP~|yY,Äug#Q!"p8PTP'|lgq ]A$kpF~Jdl `_McJn L+[ggq5?9y"iuAҒ0!?|!o Z8 vsi0\cL> Zutظ:=|h9~tQ#^;14ѨjDar)fOۆ r [PU0Yp7BUk_X;Y)Dr.@.Sn3 ?$/ّԣ q@BH=8k6\d)T*XNZKG y?R;@FX@CWoq_ӿ%k!_+SexEb4sR4e(\=no4Y.npBj}VwCɦO-qSzyk>>'߈!z=?MhYsz AiA~;!@Ie·?asyqa\.GTQ[+N5R`$j7&…:]| _pDϠa:3Z#=y>lkoJl&^ *1<8KqƙU&s2 FzȲu-yG0ykj [PW --uT[ѫ uEIk-ZG>CvIF =fxCۂf%i(rBLQd+5z5坐@0$"!|>bq{e}b!O`(*%-Nqx; TJ1~4=hAS+8ʟ.>z[5$s{8D{䪶J6"t.+*xU Alg})л-|F^W 1g#<|Jḋ 5Kӎ}Ng w0)<0rkG+q65 lOi%7¤խlOę|زAD+ZΡ!, uر;Ty\w£ʄU0WNms.ᇱ`жxo%vV0)m-54TCI^æE?])=iP[ SL)r/|Gr;|Ou/9l~S>՘EUn|+2[ۺ 3SW㨗b!_yOcwv44?N0a/iƄ S@@[6zuƫ͠:d Em=4LU H}.>sm]H! YD\T:86\jr^r~z\ijeL3Ax=wnhX?^t_'aͩ7g *Aa09ciR"uA1a+N@OzI s: ,Lyk->rfIwyWY%.f}Q$iWv84u]I9H?0M_jsfփQE>%9`~7Qx^ *{=<s8ܜrGU ]7v>$3Mśv"k  xm> 1wdžwz@9lp)+W+vO |mۧ[:^ns`'Cv[r`kqpX BXi|Ws5C˼C9:+Xk @2HQuHdPNb`{ W}x kSh-XǦ_Uw]JPn ɼmintN"i:^5F{i* nsd3rՊ'ζ4 XCYW[6  Qu;,QSm=:TU^ 0cëqz]'Κ k9٨#vrgz ;A2E3i6SFۭ0z9&k;~T ^|>;Sܐ㞕`ǎ(dC,6 hdأ'<ԗ`X67Ȳ?{[f]a` ?/'WX .:p׬)KAiJlF;THZظٙomU vw΍!TBH8rQ@n0 tV0N Iu<ܰ[v<a`J޵pe֒D6 QwX~ .,Ry9^* 5hk ݴ_0@ak; &l}4ݾcZP'6Y+W2CAa&.32Z4jYK|&v>77qЄyMqSt*J6O˨_}z:: %h ą8=Xdn r\i'kԣwy7kްmv1;ݞ>m$+5p4g#7pj3qV3)@L*kI2(kyqC&`J<҇uxY} 9{p&ߖ?nwaK=P)=G`IwQM" 1SoCqӔsK,Fk%ƶs :[ n{G YqSDY<ʁ{ұMR'3 fܕf ^nF]L{#2r̺!=>32\c_i5rOeUg٫IORܕ+Jiu[Bx]ZvsFk”&:ur6Ȅ(N0UX#hVf6?XX(MaIx3􈻱N)VAfW(c˾_?) ۳4cb0yPrK~$"VϏ਩T$ (=o ^|+ɨDP'sHTtɤ|<[?՘d;~:SB+ JV@w*^!r 3:\Gu&ꬢBdG4/)L"Ven y;3Sw~Id 柚6`9G`_wyEBDM2]'g{kb!LTVDIRAmqQ3~kbK=2 (]2 #ݸ>Z$ /!!.MƇu"~=B5 dp uڨ\21HJ?Hvc:4SA %o eP"yLiIq׬Z0AQ:;D\> [T˚Zk0WIS08兽^Lu W|v3r6BjCۦ]6io5(0򢂘rkeK)&Dz@Kx!^;hJX?ۧmU)!-";Bv=k?+ ςKd$Ѻ$E%bJHxrq'KO1"\ۧʰ{~AR[jk1nf9(82=o.86_Ѿ1D@,7ܟ*[s\;QtsQ%U `-z4F$1 |6ܿH&d >Q(YrgSx3϶ ,{Mv]Sߕ7ziS<{~G7\Vڰ,ABuKE5}oV"b>^}P{8W="Tf6^gkl `6=c@S7  @@$i܇M5u9x8;oELw9Z"QI*ک-sӸ ˽)>+* Zt_|+{ w.5nԼ{ ,5T'!wna"7FΣ3%: ~Mv/(m p7Wf8 FI0{oYS5ܴ @ႍB AU~ m'p.ъ1  Aqcv:de4dqŲQQ*o)w{\ ,7qP6nP8Lh&xjC om-d0K{㾢Z *(%=Yѹ'muATJ5ordQ_tgk(^.-A89֦M|g߯vr"oXݏtYܙi\Q{ˡe~Y ~BߥȐ Nl%gm]߀̫JcX^%yQLCT mf#ߩ&@YK$ՓG@;291HjDՏ)4R.i$aGDSUfg%"~x-]pL|ّVI(qބ5zG[=)"~ J_^lobtV$[+s}.Mk$5#@ IPݙDB4D ܂f˂u Fp~uT~ qM=N,jpq0a8j.'wʕyNI ]?,ВDI%ݵV(*ðGy)"(OhʞX*2ӈC_m4MIgD';rU8-Z)S u`W|w伈%:.*f/N`]FVQxן 1B]K*7AKeМ=5#H5mVxzyȂbZ;,N{Gi$uNxFGUL߲Ca[#ńurFJ(OR5Gy sj1& 1Z+]2ժne:ҡPh|si@f7RXM(H=,-2O<); HEy$/S}RU8b\TpݧjجAzlIц`R QHHPTχ2$_Tv.ZqHj=_E353tLߚX 5,4FLIJLeE~,upض8Xu漬"WC(4B¾xЁIANR<.xPIh8Zm%Xi5a'lP:3Cwjwx]ua"A!4"e =bX;`?bw1EҘ#V$(sY[[Z=F%"!^w K'^ U+!3oDȍgӨa6ŵ;$z^ 7>y=/pRz.!$ȿS۴BsEԬ wzHOs췱aV$8+`W?i(;.adb$- g)GMKB]KWRUHD?1_d$ٽ]0|}t|,I pv1o r*Sgrbgrx5^l_Y+0q+yI {OYr##.&X@Eg`DBCL`~1QGu L^k!LV Cs#Z;h(:j6'm2ajdkwa{Si+6$_)D|m|Dݢ 2P9%=+:[^7ǯ@>+(W"3p4OoS?s"W΂ۺi8gؐ4S[S+Gfe"Y,fW 3ߘ}@ cF M Mˊ9 pYf |mHj?5,(&$0,R5t&mzȔQ@]>-&DRf2Q@midn[<{KL?UCJ!zQ"dw:v?RL42>NH]nAjo9!1L؇f0h bA26 1W1J@TxBZoym5{]W.+7AvfMW 'EIbYȠSq{aZ̈DcziDU~jPEz})Kr_6b2T|+RT=S37_T+{1$uey{̮D|{$7{vsaz'7^0 mp'@IĄ1tL^:~b/^gl8b4Xb KTxg;CS3 &fۥwzQ{[ al ) ]OrX@C\Q6V@WD8ʄ!ˣ}]@9'k&z$x ͒.HLOiJgi\nW5Mz { Rg-e++diQD|kxǫ]S^݌~*Ds9N<ɎneW$ A0CegaP{HpO^Isng`s7oaN cs fFRRliZ[HBchq+/ [i?DJ~!ۃOJ._z.N vቾ(;b'vS}g^aZːeU9yL򐾘|+ܡj !\G8-$$? ]/Vcu-aYRz= wPfݫp>S4 ;?.zƓ "툛tll~'A&r@fG/*#|Ho28OLn^&`GxV>YcL_?%CW.'KJRQEU P.#ѠӬ+AbyQOtl޼di]7\p|HVrM+"_qY=eK,-Kf=1Qtd=vLc2$C }uMLC,n0jqLxu욛sa+)U)n9%Ii?[~ ?uOu~o%ׂp(2\ڞƓWonSBc=hP Hf|V'Jw(L!TXkۨ@T"袍:v,c]BZ/8X 1 g" q5{kkHtEvz"V,cʑJ+G,7cJgcޡ+ H nfNٞ[+E׬_~q_ =H8+n[yV c-i7/9G_I\*ӡ3kuMM}%rf&eŰG`՛* 5u*NC4]\5h$['J}KM6 5}" PQ@Gaً ]ڮ@uN+k_k7FH}1HIZC'?MگvߒEB>ՁqnoJȷNz/͖IafJw)H>%%xtjGࠛtz1B223‚usw 6Wk$'YBNC&a';7=<}PapY3l{$);=4J^ Ht)G깁k 1bPyl47ʳJ X&tqXnbflN$HX=9F[fBJk,e.!:A#xC;=)]j֝ 6ev =/^|FӤx+/w g3Hm\jplᖤ͵";"w@3z("o _sAS=\H3$o?(CyFD8(e. H)uOWnr̉Eq\Ib4@FoЀ2Gk=F%4% C5`opőz5_fĚDLK K9Y8N0 `-ޤAG;i4Kك,RoayC3mJT7Ya_!d8ʻhJ[uO8k[%#Nqb!{7|?tÏ<{ W.x]ހNhB8ry.>V!' nhIs>钩P3$'.x "gvc78ޓwz?Q 06|ʚ Xy^CDqX3`a&>drEj|HL^/^5XQnחedblNdo^bb K\<(xjy/{QʶuS4-y뾌2w@xC>/` O %Wk7x6>7l9QٍUwr(aPMiK\ xS<Ԗ[ ڦڰW̮Ա+'K~[oqU?1v!VoEݠbF! j*JbiW_)I!O_z''|mӟSKm/S)c %q7@rJu/,IUD'zeJgA"nkBW2U]XpZfX8}':嬙WK .K0ej<5-&]"}|S|?P4TT1s:FfC},PtQջT\fb{CAfQA06ۄnB| hq} e_t?DS镠voeGΜh9 U?5&Np݂~jgMѶYem9ol@ @πVAl޹gc:jMx^UCI6֭wm6?90![Ƣf 2F5Ls uIpviPUk>}7.UD?9MW{ꏅI) u+Cy:&P->0]ᦂ`FXq#1[jФL"^ѡ+f}ߴ16j _E7LH6jF=VV ՍRCK%gr^6Ư4F,YPB?DI:xӬЖXQhtR٬L{)RB*&Me&I:с_,Vh#͉LF@.Mus6.[X^rov.uI'#|*@ ,ّRTu-y_@^΍Yo7Hㅭ_2kw;@%\%VB1 `eYXrht| {9x#|x鲺Jw$ WW $ 0gosnJyP',JpS,b;)K]6Y(R SXycex`I}>ф=IoU nbS@u&Z.Snʕ+>m`y7ɵ-cMNliNw06#w-R/qb "Ҍ ё{A(T Q[{g¯aVObʴ/B@P2ASؙD4)B tU{:^(.߹G q~SkE&}¡ŠO13M9.T[Ϡ\sG[Q_y9Y}':&D^^H̲#{;8$5ŕ߅@Kt^|1Y|y` -#lV%~VUSFKX%g1df}*PQrjwM=I1,SHPАn4(d|~Hj㺦:ر) rz;P"OP>$nL >(d]h cv9 +JoM,jN5ssoC"R!CDTs-9)獯@y"iO&ެhB Lc4ρODN/X`05,%bbQ$ RFĈd DXacL6w2L{샶Yy߸G7ufNM&}>+ `ǔDM:2dsZ^Z|U&m$˘kHV-9J.CAޛ.fdV!dvngU=Gъ*\īu Cr:2Q}?HAIB\%h*pfYVu=SsvFWėL?q<q^,c"LY%{掋O{{yߦ'\֚kLh yHj%T;{ejުͳ a Xrpic1xoaнI>}PS+:gHhגrヰiͫALp$Qpxw `X g!3|q mM pe/H>= ʳ>kf>OjGt\py,rʐL%0mhͺ/Ȑ%]u69BrD/a%Ts|p 鴯h2dJ3 Vr7نoւ?m(đ{ @s齨$Na(#+NdCS;{kEN䊈ǞQ ή&eq1!p3Vh[ZC̓9yx3jb lKXѧWdHAD@֨$T&@oWר; Ԅ!xdrj7/| FB>ͿV!+h@m.ٮuj[u'ID>1E0/2Dy!xNJS\{Ӭ67lw-iZkpBND%hyc 4CG8?pk']߇^h'qB`F,w @ۋ:7ꥃ%2s 'E,}sK3|1Z_Xf%w' VzN~k4a P?g1u@Mљ)Qtn3+GZJݑ `Կri/$]spSRuunLSA=ֳ 3.]笮vH$LR&W"Q>gn1жWykaiq"ޛ 3b>,J櫅A5,k9XnsγÃ\*fʡX\$03£LRGLH $F=gJV\l"Ia%5,b$>r(U]hB5$RErZeP\'pq+VOğ,9H;o k+A4AWMizc}xaAymw,+tqp2"x5}*|ꝓz*wPʏ[տ9a3#y܋tۻmNJnWg,Ա4VcQBd~(۞m!]"vBbs,sޘ}]t%iJ"ۻ#03Cil,kPqT)d@i, ")̋ jj[qk -ubCf' =ӡVI+p)Uo[owJ0f8myhR'-h5@<'NRka@$^Ϙ`t1qR( ,~VP2sP MPPI,9U&}(ݓ.Ϻ'ilk& G;$@į"931]+Ks2X3w^8V{6 6Ql#W [-i٘qO` E*۲p\-U8E-xjT;,LB2,Xحi.켟Q)f^A2m`>N1!HM/eY ݈;þA*P"-P=Miths|>~$Ʀa.g|0J>i'F+u&ʆ'ӗBt}{w'U9)}d$u2_2lPkx9sZr(v*׷< 9~:Td0Y_s7w+svqHnTOR8̩S>S#X*q͖w.S mt@W_,SW+":k#u_OM5{Di/=$+!|XXk;瀇U]5Otp/]-fϰjC=C"]9!flL R񲊜FBa.D{&pDZC|P, hлYPV ܅On̴ : ̀`+Hrf=P5Z?6XTػԌn*Rd,wГ1eU,l>ޱt~hj,d#$oLD|ԽēeڛGt ML;YHHg>kAl6ntpvF*,GleڒF.sC<۷hzi- rag DFp ,|fJ#_fGbDc^1B5O7!ʶ|#'~&wd )D jc(SkTNJx l H9LӇ#_1^B9Y$H[{DP¾ԓQu?W~y7yPg= $l n fea2gA!#S2j wutP-VP~!@Mxθm&7Y݌OE_5d ro`)h- ҏaY?yV ''?,֏zHEl~T!flF-[lOœ3f:RӲK_GU 2;cp ǩ~[|ܫ>\'Prs4fqkp %K@d9\"~9d_+S P | YlRu$v}<O\\&][iLXwoY]CQ6wL>r5'lĕyHgjC`Rm󓰷9+B` _ç] xmHD2s6Ȗmf N`Y{t&DRpgycjMK,> i|(86%J(Sw̾D.PuTx^C:0qfMiiLrFKco ?X~'gZx2~5&;Z`]fs[мRvQ.i4R=Ǔqt|@b5ܺІfz ޫc2E ( >DV)7*~%6`@MqC>jŒ]{)еHfJ}2.ӺHJ⌬_=4 GlN%2Ƈ(dS:Qxpn1vw1{h%&xQ`k\cUQgV,C9R`Hx/d ^˘Aus!+Mglմ TZHd]kĻvahG6"szٗ(h:װCԗ`˧V,R,o;K SαBw{=9 Rl4\ P~2cL^t?LN`5Q-Cg/3C0wC+YdoPOQ9I&K!d%#Ӹzx223vd=73 ')yA WRn{u̬,(Lj@ۿ]JLs+vYKPc!{GEߥ4GM渕pDH[ & W$86D)d렯ۋ;nAZƎKl />/:,BrQQ^&2q*Ƃ[DO FǠ$r"1Ab1UWsN%Ťq b>1Dx7t7ޭnqhwMmܴZ|uΒZ4IOo>ygκcC\Md>KtGw0_vix=P6~f.ĨT'jyl+쏮M ə. )!4>t'"ob +r4Tq6 Hh lK{9]֭QJ0Q|#o02|]CJ'&GakCN 9>!IV[hėm#d1卯u7I]T΅H K8iUٚ±C\lزݛC|~!g_t&ֶa%GN s;HÐR߻!$/6Qr'98DQwhcA-0 iZ?('hKKkh'/rp-d`:U =P6vL`]GVӏ_w"3,ܡ *FvٝFOۢz^|ܶ\2 ~kV2S1yB G^`@>n?mC:M@"!o4G$/^~?!txo-S9$aQ'Ňk}Xߴ {EƪxAn7|EhzMݺSÌ8r d+µufq>4. ׄo& /MkSZsj P]뢷U!#-HIج m|>\P뎷꾺/SrCN's\s03XsK>**A Tb)' >dH[tٝD9S"C*1:oS4\2d/akt1c4*~zbu[#E^noHݒtԸ`0iIOÕU%U97N-OD.UC}Ӽk5o"/ Ay` R$Y>V╿z$xc;ef`$ EA 1i"!2ϱnR.J 5a{cEi 4欓>UOyU> ?k~;[%_WD}*^0nCNGdzXLDPCN5]*;L=CQ<]O+ZI"fF"TyR8E+isb%̦]b5b-BؔsG/m(Qžm<4Y&˜4 sGp/7#( Q@;]Gvxa[p[(!v҅^6QC"!7c{Ko1unyB*ɷa~ C[m xiuKkK֜k+F+6{ׄ}&9h6{-g_דA,Wo*IJtrvfy尴PMwb6?|w^cMIɠON;Ov';e&K3͍ܮ,V#ʹ$}^;cM}(XMK.rN"896F g>Lx}lD@d[ݙpSOyD+=nykY_JObZtmr)A&f[L+TRV )% cPRk.S=[\ >Ɋu E>[n^_~ddk,CI<(`5vdb\&6W-ha(NMiq/n}#ϑ r-FE̷+XHT(i8=ůC|.nƜq޷VV []̖MʧsL0A&H'θsts.aA"@7  _&Yr'WNB9ZJSh=ϛS $1X7N[2GQ(/0PA$bw74P-^'UmiMj:˃aG㩬zt}&]9u~(;%XMvg0,-hEH_{U1mSʜ1 A\Eex/#E\'#ܪ M!flը|_uE bˀ5<^Ȫ倄 mIEs6kfCE לB#esXȷz\+*l)F`'S=qƷHga{_JfyJ[J3luvafsU,a4k$@st>2]>BMC̞ &lMMAa߱ ~&))〾LI_͔ꝇsޠ4ш6jNJA衦˜|C3_^j#g: Oxq/-Fq LրlTA8bpzkr;Ȯ ڟ^}D,e'" n;Uːܬ 4OڢB.N yh5 䒻:ヌ3i`S;A| M wy'emFLmD puA);/hhsqsH++!F?{ ^%=GN &N`aR1g40AN8}owxg3 > LRxξoG9M˂; -Dw#+υZֳtrnٞȤ[@o)_FM{H7/D'dmw޳O9a= @} ^~l> JfgqBN}ٗKi`R)ͲX5D49n,IVh\IfE6 nFsw;x!Y W!.]JK[H[üi:~+3#HmT kvvqѤ]Ys #;AƯ8&M7Ӝ'=cawtu}BkYO!w.f y] "ATV[ea9 l8EDA5H8iP APֱcLc\h 6 s7y n^alZ~|ȅ$&LZz bh+I%h#o'\쐋c>@{sh!:`AKA g; }7_SYﴜD_ALrm~ϲlN"zyt`~J^-GqnC ҆#Tzv3{[|OWsg QkˎZ+C.ke YNTЕc uORm,~\u]/U//)ߛA'0ߨ򎨌k :i}&x0&h*m7ZF=OM%n5"dBNXQVC3}ZpCI~aIR _hJh%,^EzdKQ|5YdVkBkyF]Ngu NE "DLU8Esc<+CquLN,^gUpߕ ӛ|z %>jx fBXq>ҷ#\՞%`;>Q]*hAeVK|˭=Ldu~GJFpJzHED$<.ZKAҮF lON͛i*g%؁8}JRisrֽc|&HsF2V?B2o;g"P$ ?n..m!*__aWl"nomBɀoQeF_蹇u3Kuh~65I0z (\Uuec++1+emz5E&ʐIZEf1.}Af+vp2KReI0_L҇>^¨g4 RƀEY Hw-$V|Ohj 'A=jja&!0TtqKVmUɁPJJ}•UM~4nl7JdVO0 dWQpSLeJGʕp2ygumWj< 8cZGdX]!+  :ckUGo>qZ*-bepI4MWKcCF ̓ 2m7TjK'W/–n8"ev e():P$ AlY@õ!Bov ~qXn;C3EدE. '+_c}Y1kϽTcwo3oD)*Eb_baפ/^uobzr9k<^xGW-핚j X7M8L"Y -([OX6X?hD#f@: +j2в`(d/"H&IQ͡r]0мSrê-7Ӆo9 N, f{, 짬 k"*H{J8ϯꀲR,YTELGz{÷Y4b]:-Gt7܀u  $?@U*m˩d|F4[gZjY͡dA>_ѯf*{uD9 ;i2B5[f>ۚ']YE*úilEkS,~AOvkfi\iMY#+"1A*~ 'Y 3^dZ Sk?O߹W%HYm+ٸ;Ǧ~^6QR|4vG9ښ[ryy!׿rΗۻ6W 6 |*2ڄc,7'{TQ=xUu~[5RZ+5,ƗˎEs .Iۥc0tRUARPY;Puvf{{A >\İL~s$fPc eɄ =/BU{7A!|H!5 =59I%㱓8}t Ǥ0q"#F!Vսp= *rUfwI3PZŬrV$cI y&/)u-w=H$ό.w0DQ nlt Ƶ$.*q#1Ėʥx׭18fK PG `~bvHpі<2w\ _7{/V 9>IM|c3 Hh7!go`ceY$3J&QT:U?-Lxp#!I͵K? $O&)tFnQIt 3:h i6o/4B|*TA{(6’mͣfj g dOE"to}ҒLe震jm‹l g<(>N M@Xl=ކ#b^1*GC'+Sv{u<+ <3ſST"cL:F/ 9V^ˍNm [ A%@mz'ZM`NQn_8y>>4"pWZ28"1<84'm]v*[Ū=or$5(GבH$BO||'C\!.e[dn1@gf(T*ݝMf?{}5t>ybMx+L<{L.µyEUsv#\|m=#Zdtbg u*Iv2\M1P@6=r";3% SBԗ%;s6a&8;vr@(Ή8'l^l 04i_?uG |" d<^/|mǒZxUufl-G%a8x<,^Z[sa$g=_PƯtp<3 W\){@><iԍҢsees4B8dՄB81WO ؙj&ӯ.?.ԯ2Wtb)*&R•-@LJP ʬ/=cFl88)h&A^ZRUx5HITwTӘ{V&"XD)&ECvha^&NkD:wf@?>;Ocnx^J}34Nf\-Hænr]g/ь VTx^yGze ®hؙtR;A\ɄjKbDD K\?Fª*%g_k=Q2 _ p$XWub'.KRiqb Z9k*^ N]`͗ZREy}j,|BwTxLb x#E )t8VyQBI73~٭)GТ+D>k7o6tkiǭԮ>Q.i3t=T$}qײj&^#1~>ʲNzP&/39FJIWh\0W|p'_/e{(KzΠC !H^.žUmZXBr,tjֆez_/Xԏ'RxʙL> $AQ~<)-fK<%J3~.MMލA_2(R6=F󤔶e,ҥB4C9FݑyOZkcm]ᴕè89M%9 H)m Wg`tjP<MƨJimlao0V]qܭ:=( U\0V@+k@x~k&p>1CEeǖѓO:Li_FqnmrɃ4ɝ\K3jPC3v^Y0y> tBvM8Dmos9&z/[3ёo+͕Z=}890)EtQt;nM@5 X=#x.b&5}{"awnNtwDgӋ!8>G=9SuGm\U%iUa&Y]B!wQw{OwW>Sy ! =|A)=N(#/u KeXOyy5[ ?$~gcNi$7v Lrg׎)`|4:"gZCl>2{G_~subkňP:i3c}Rgw`[EΡcX:7[%2/t7! <ۘp^ )b-?eS4}v50^KhAp̟Fw2, +5Z{svĸpZ4ݭ (`k}B`)TB;[,Pu.ḁi{ij C(RJwq*иwAMٙ6jx|rlu[Х#l爞L9VX|bo,dy dgx^raǵ NTi Ȍt!#/,mQȀʌΑNˀX)~l?e{6/Fjˏ5{+wA <&%okEs<ԋh )`]-'GhD}+6àRhjvig7 2Js{&.%B5XgL$罹+_Dv,nEpS U-}hY$9m3d&׎A\͊vs J4R|H :[3,fj[#TrZ`(,D+M}4q ryB On.mL5b錗h)XZmZB%_ K\p V pt4,f  ;EjiKꓦTCcr_KM{'OPcD)Y 9 פG1?]`5ҾA.^ FqHbe[Q&giY!Td=2` nNw"ޫsA5=Vcܨ LOO5TA}jv.h`J^XQF6c.=2^M]ueLvm %Tu\#ޮi.#zȁ2d乃(Zr:%Fyw聥ELfhPVHn DAW<|RC89y|խ\Ъ OA%fG'kfc6 U`CURA<: b0xLp/DBwocq;cXC3H{4ƵeeO(X]_)5XPj]mLU~dVbhXɛĨE^%sMtKax!8 ^6:BF;!JEhuI ^<ӥQjֻ䢽G5STfɢlrF9].:V]&kJ<]"wx m€R5!{Of.X#-ivXBwqd1dd4{&]GJ;CpL_D 0WL;'Mh0IxuAO|PVcT!U"7+^+o.Q n1πDUk)%NVO~},ޒ'/aL!iQ{ؽaByWQݽjVf#.@V瓫c*jv8< 􌷻MmsS e|JArv+F#Dr } qU@/ +9~fH=dcqՠB_/}2E&<qҁGPt+A{DCL;`6+|irMaޅ%~:ր:h_ D1E`ݹ< tc{λv#oVLK:P\2ǝ,͂;8Mt+W %0X7mJ2;m8bn9C&ۥP0/5w KC#nG?if0d1)\ ZygO/<;J} w/3`9/ٱ;uz bUY;#Vxf'kq4 F>En5WQM4A 6{907\x5H5):Wa @ GC`tٜk ;/ײ;ilEg#b-q7<3Ṉ7fPMgApMNatlA ].KṬIJ[@bms ے[pe[BX(9hYPuG'S͖;LYrBMIu 4Y2(7ΚY:m wO16T 4Ur;f UV^/+i%n'L>_Qт AIqc(nD7R kVBp$p%L7b*XЕvO_ZO*/"3pu"_λAlL\GnƲEcou|߳%1&A%a+eMŵSHu* 'E_qK?YN\JAk u5ֹߤ ɅY|^CDQABڙxD7%Иt.1F+g0~U1ق Vf &q-XW$[X/b" Ƙjsj߭}SݎsEQr 3J&)',W9!YZ7wnbPxHUpY :<_:=ֲtê O"3NFKzp_mN>&E.{Njiba-{*^E`',jDfǃ>u^;퐠p"DڋFzŭP\g(Q콏d9d^1P7!grYi7ȃ0!N6˫XnIY-j{jmr'.cy~Vdb O۴^f K9wY䗲>2z8[}qdޭv|| 63i^^iJkQB"m /ׇ}"oT/9ANV5gKKlٙen}vh]yyL0 ics[$7SIz[*ŵb>#D4}Ati,0&yu+AX'OUFAU$'AUA#Nw37[ZWאlWQ:DW8 Bl/v/C"= |ɨts@m&YZiSA&Mv:`ގ1ewߘ|]w~m55ۦ;j)zYg%V&ѝw׬ZĝROp_Iq̪-^?5u\ ~фmD%d! QsʸyXifR^deWO2؜Qr3?Lphpsw*R6ggK>153=HQi<f9|kI{Y8xBQaŵ%!(۠-Og۹]7"7KـTmMe\J%'%ɢ?ccJGcY'Ra}[d. +'LsGO%$p8S, B`=cR|NTAw=u#vw۩IY);9Z NUT^9H¤+;*I{:+=_M4r`.v5nү(Y<LI f5J2DVt#x\vX|0_j{).DMYO+L?ф<h[>o0zdpzZCl<5(yw |5{Ü v AN%UJ%dzQ(=ץC;1-ng>2 Jp?~.u< ̸TCZL|jaUA{)"c<5fYj'ZhO9- 64./ Ho aOVn!i N 1?6a"xEJwZR(pJ%s -QZzⶐ$LZ߯rZ97clfgLJ"t}q{x-?'rKB4&p+Hr{zO!tL,BH%5-ىy|HVr|=Kڪ׿tF3p&6 oXFtݒv \`oYww8LlSE\RV_i6Ds#5B$c>H6`b@ڠ#lXQډ,ɾ@̨# 0 &2H(xb%z =BՅ`nf4h{;D^ֱ+8#ЖUU~1V&6>ч ӾTvP53M3,Wo._OUö_Q_E&H*8 >7.Z}8gpۓ8`r6]:/M8?x_$mP0U$;_~B+RۄU2(yo7Gп~jҿDV՟\s&\Sءˈ`g`!ZJ*Y~ ukA9Zhv v`$-Ɍ0L|:`N33|̔x6G ӟU))IuWiӂSu5JHy>F% >9s1Y֙LmqP徒 Q0ϕ,Zl")^egq5,T{ DN`X`ݐ&gbBmm!*nmufq&lmXH{ou򛡰qː'!)Cc 8C!$X d#H 0-i˒,d1\hXI'$!].5vSnj'L4y79JhRB--V"GA`H BYJE O[$?vn2-W_ϓ;aJ1B$Pբ#ID \A-e}]²s:4q di?T]yi~c/f%/QBR2 R02*Εdcg?-SpUY~OS_PSlźHڴ,P :25 s,W u]3i{Q1@ňa8{~6 |Tխߜa.cn'wD13sͰSHh,&GԙJ07յ>$BE"BȠa{9< "aI|3ۍ`b@C{pR+V@-򙁳dY ^~$mqVU %xPh.BK8@pS&D6q';*xt@ˋ,`V e# eayF2T̆Da-1cDJT:ad)@+A]8oI8U9G{}|"Fq&"#7$dB '~ˁ:ӑ(p WrP.PD:Y Ļ C3qckJp6=fp{1J_}Пt-tnjȏY.t3,R>i+|@ rOs>K/nrEz1ZJʗ:[c x7y<x:@~bWc05,)/3Z'+=>ޠp<āJp{T{i~cް짶W )N2#":m:*ALzY?M\bYSW|HB#9V~^͋i-|_6YFtn!v2 X`^83f.dV)ˋPk=AE ۚbFƪUG,@BHq WD9SR.ߜr\F$:  b!-4 e?<_9M1?:ԅ' 0%<;+̍A*C,!B.s /zK>q;2ן Rm W^Y˝zp8gk7_w&w\O+z :2) 1 $HFF34QGUξt~7c|= H.\c+-AH#{a1AY&SYt@?w_w]> hT> ۽x.{wo{>>obvN9օm .wle!ZdMfweNz!{ݭٵ^ssLV;w'+]ݙ uf<*>Wx}q fkli4wKh wnunnXWv:۩)j*:mlnFum[r\ۯYf>J ]fMt=XrCjÀܢ<{wk;N3n|x|3-}׳m.0b2(el}vn g;ǯַmUnZmw}ڱ_v`5cMoz0o={׋S}֢׵{U__J9>>}]ov][ݕgיv=a:}oX{z_Ointz^<}xw{]O]ꭾn}P _0_}^o7ݷh׻}l^#zYyS}gxu}W/oMۢvd7aoN7=6X6V}lcV>nmI"m;F7p`;xJ3wv֧wuv㳝!JΪ ssvnܨ8W_8Q؋ *H$9I$@50Oa-nAjIp8{5\4B,=!. QA9A4x^$o9 % 5kk¯^^&NhupnxqH?g OD|`N a. La2MK+][{N4}cg /SAŶ20"d|r0Jcw*eLڧ䍖X]IXuNyjH7;]iҶFجʮҪc6>; (DOtla6-4lm[oM<Fb5 ^%7CFK#"l3K-S Gǐ;!*8|rgY)-隮Jd.rnQA14Ǔ.&x]lx߶YL{+#Kt$P-- @/4b>=LcNo,* "EU^ieUET2#]06]Y>X4Lϑ: ܽt%a8su\XU)v.c j+#D6 ۡΝ_=N3zr//dNidv"DbݙW]~ܼѵJݽv</W1bNG60؛kK ѣ{"7Zl۩; [5|bu|Μ G|=[[(|a#zsʡtrf-n9u5yc* }6;鍳,묧Yn=ٹ3¸lsU6 kf5tV4w2$-‚mӝ=+쭃m,^ 7Cvfӆ;V2`vo 9\Z66h:Iܪ)әn"{c&tz19| 065&p&x9m!$66cM4#;aƋfmW:ׄ x> cҌe l6HD LaLamA#r.P.54#$;c##‘":@V`mcw^FQ vy={8śE`m[ɀRedPxMqђڛ.E\nmqn\neպ[.SUښ#nֲ.%r$FTU!\[%c9!naeYEպc\:;N_8Å m6zطJnгhS ;oInRé M\3:fkk%^3juD*H#y۳Jo0#ܮo "bhBGCcFJ w}')1&|r{Yv fY\*6H171`W|"m\x41$cAɦjhEOkPqC ).9T Qma[mzV)@A ,`urخl3ռ-*:qޑ9#%1r\DӧR.\8ˎI$ s#: D6G713'ua x4lWmE7PyvX1<ՕZ55 +t' 8xs1aNjszwA:MpK6wpƭj$Pnh8Q䊩Ah;-"(T2 \{\#޳"v2MQ\6&pw>]F *qs::3qrE/Mf^eNʕdTg ӈhxN<]QB5(J@-*,s6F ɯW0! 3DIXzW^ϵgF,;o;w SNgDΚ.[m>)~xe%oמVM7Ӯz^4$@hm nֆӸcc牕{[5?O±|sUovn|AOb Lhl:XPk_6E0^E9;|{Ǒgvqh|` $5n&ʩ\q"4 z%#cs7W"I4=ph8u?0"ߡumCuHHI$MUeDphFRHE TUW0WVXb MyCt$P &`$F@Do2e_Q#̭EΝTgT1V٬njY& nb4h2{׈Wcbi_&XVl33 d !d!?;ޮhGv'i;^,c9YHIOc?8M=bҩCgVSfzf3КC0%`Pb S8Λ.G[+!BN^߁hU̳G0~禫V!`F d'첷]NQo7 22Ԟ^GJbmzdbjR{i/ A4XJJr<Ɵ}~|D**Fl , F !4("@J P `K!iZYJ˯/w5Tm7֪=V#157 ."'}`!uwT @1%ӌEZ_滩h]eLG31C!!p O~BqQu}Cln?:=-hBλj&N0 0ff`,?*ߥf&aK1@ @ 7H&Áw-F")q~I$0@<چTrYia0`@ `ꚵP"F "?_RgCo:8bz-,l@rb0V {X)knȈ;nkw$l$e$h3#,n ri  g)Dxܝݦ2. @ձ 8C6 ^S W.֌A\\nmt/t\FL@GB@lӐ,pB?Ͽ^+RwȄD_! FdppW 3Cd9hzʆlk ޷K@Q~bycDz S -{Ę:SnAݒsw_"}Z Fhs@!]YBu^nåcc%XD \Cb$T; !`D!" b 1ޗmq5Kf^DD@Ĉ 0Jzr<zx18t.[/+ZafcغoN\Z7Uk?9+& }FOMq_X6 g``cXw_{1 -EzguY1__&[S'9+(KO[?J4 hB"0_ 4%3 цkC@iXP(L$ Hb5v?M5G?`(xPzZo|_^Wl"0UqEekvݦʁ$iYBsRCVJ I '=L T@9c$?Ȉ#:_Õ!A!PJD{uU{nNʚgƯ B08]b* Q) >[ ܌pК&4#@;_Y++]&ZKhA7f{RS֧Fݦq2 O6 F,eRěvՌʌRe5CZ-%HeT)?jyo;1nB@d 6(m6]UzDx FDii!Vk4?{6|uA p$34`KlgеE@n|AƗg+|o*It^:vj#Y -b\hE3Z}l5D j$Z]EC!m׷ƞGrb 𩷗9UZĭV (ލm{>^bgsd }ə?Ev3'c: ofˢؘޗc`,dHA4@#P#є6U̺bѦJsXEֺ:mxZvK,4nbY!FBbX0! xW!C A7 V гaq0cFg7[cz88.&K5l-;3ل,ʈ" -(XFD @M Qm<4ܨ2+j$|16Y\JUՕB(rC`s\ $ʋ3AjҚ& E(C%9nM $hVmwJoDw~s$0i4#v\fvꮹ;sk˦1*PlLn$1N\-d(1 4!bPʴ mpR Jk"W/͢l ] ^e`;7LWHHLedS?*?4>>6 1M0 rMfN\nhKmxR Q]~oœ)O@I2CM^-1@*!~kuS V i+;WeU'%7n+EVF`) )j4p!HIKV9Xu#+K!R!V# 0XI5)YAQXbb, ! bHE֯$"-mbԻrٴ\Ch$DZ"w twJlJ6pGlnQ,:(Ftd!],4n5 ],C1QmHo2B76mzJJSVUN\"JGFB) +@,(+uBB`l_EK*Xb Y@w+t@,9 U@I6"$bULnB"C 0LP P!(!B*)!: Qmd,mtR$E}ȃ"*KX[&+%` Q eD,؆}HT U3 fnmO=O:6+{_qD>887@UW!xb&(Eo@BM0Ê Kf'^&@ T "]w_WKswAV$L>WX18yBmE Db0D tn- AAFǔ[0)H1p2}APͶ(),)B*E ,7 6J)z-~7iaĊ4 724[YO*b4HR@i0>C* ?FM:"6#Uz P@٥U[A*\T`Uh ,BE F(x&.%+JHDT(ł0b$@B4c!: I Q!01`T! 0AIo7#[-CD/I#J`BQa[SA)v{Yd>H&4yϘttGO,i5b s]8C]r"4{X#"LjHK٫믭XC_)&dU׍p)(N:Qt"]%m(ii(ŔvEN !M9E.b 6) MVʕ*B%GQATRm ĜF찴@@`Ra(YHvR ņ cw<061r @$D5`  Mh5AZQġ0/Qd#\x۶n*\N >/_~ۗ-ûhcTHyD7@ev,^;h[aϵie (gByrsfjݶiXeVMŧ]$Lt'_pz0g H2]\wl .b9ۂ 7p5<$RbHeҖB6R pְD@H*[.ѭ`,he,Rd.2DrcJJi:T6ɦ `75BSl6F@D LBZ4%,oS|V4kHm1nF1qۍFi ~);[oW4P 90ɸC[fBHc6ڃ9饞˦>f.~buHVe-Z6@%\:H|ΟAV>F9c%?҈€L8W} 2O1sl"A,%_3'{r[pAsCKrqiN];H[ӚTϵ+2fggvU ( M=-V<]BH_xzSѻ<@QZUş}?Sp"9vv qD*0'f>@_ȬvhvȚZL#p>d \ƒPys܆4sxRK~D {]:HQ!F_rg:(PA--Ԗ2%vL.Bx2 [^m` pZˬ))g, v[ Oli!a]ZŬh-Bzxu*K5Umupm#EF(,dY.Z{EdcnwU CE@"=)G?~}POwaLIO(M|dI0nQ{I4 ǦD{=Rͭe5BȍpTn)70&qNZjwnxDL("V'!aOoԛ^?+1!g)ױRV[nܹiWyo\h AFk@+x XIXAFA@`qv׭DB2RJ, E,!HBمƄ`Y1HHAHM T/aK$-]{5wvޚo:a` D[Vѩ"83MGo_uT؊h #HLfd6lѨXeZ0֫kvE$S;a `[DohM"T2 6ن9j7 xi^ b6Zq-$dK7~&燆ѳzqPbQMU"@@j!r@,IDDRDL[""B1P@ ")1 iVTĂ)DD±F $Hb@:@@bk'aյEotDl`ݦ T[>}TS| @ ru\XH4x) h1aIxHiI ؜DR1AIJȖ PB%AŕXАE %S$ 6LhRCD49Sׯ]mߛuqqAdYٷ6Yms DT"PJd(H ͛v63%NiS3ZXEB yV݈(H&<]}GZeͽ[kz3:C b<$+iL}6^KMo7c+5 nI;=y73}~U](|wIb𰪄opњVi]hxlݞY$97tߘ j@8@G )I9~΂pڦ ڄBBمl9xE "@C>V6QcDX 1&/@aT1..V^hji+EQjܺ\jzuLp*^BH$ HcLJ8×l*ekE yƒ hl.$3Z4mElQVKIs[iEjZH1dZ51 A"E0( x7"#Z,Y@DKJ٭SsͻNK|csf-ugow `h4LgDwymj(&XJ:qv_nMB!8%^6/WM\\FG /e.C{vhW~nssōEnW:iiS(4ҬA NRM$,E3`6+CvziAj hi b@ (Ċ TmT0Rȴ6(hYWTe}+41KVEֽ(ݰڹ5np݆V5m f@XxSVJ[\H֧.ȀE 8EUb@,0B9.rۿ\m I)9Td٠2M%To!!k歏#_>_]krJ%˞JvNi2c b- RT㵦Pwxz%U|ْԔ 2  I"H+&eF0$pVe(`KƔIanm92sXӁߏG<4mIc-;o~.Z[ջ_t0.R.xȉQTJBmrVȴ͚)j#Z6h&IHJ@#zZn=mgQ!`:3qjn>]/{g},x$"WZSWr*"ܛOWkZQlհIZƺhrjܺ[ujiMu.ߴ$ݝƺ\t岷~v,66!Rhƴ-ijKTxk]u5w[b*lF$IdLvZ--.VVms[հJ'榱ڷnkK6ة Iz)v<9>7[c_alC yr N$_.֮QwUGځ rۥ`+eZbAɭTX64UEyۺ}\{$% !dh0SPdǕX`QcPmMR|ϙ[4Y D@PmREFĐI$"rj ,ݿv7Skk]L3tؕ5Z?.[tqlݎҭs7' agP 3K+4jIۙ\Єqs4Doޯzɦ=T|t".$:c7'5O-fIN8rE8Q.ѷ{ZE8e@j˷t="N9 ۊX^TFti)m%`%pbAxwQeh,5$q?Үw4hqH3ÁO^/,:2:0e)JH盉h(,!/V}%&=Um.v˭w$eo-iMLim\Ãs9$$ Yot /WBHj bc\MTeTk>^VYWSYm(E, P0'cwn{ƠgG|{rۂj9S& 3<]mjCTho *WA?}x>Η*8ʚ/Rn] eWe(շ=&wM:k1Ӝ1:zŝ%G2f\"XݔF3/e0 \t%RBjt/MS2NUӞKԓV<2[gA^Ku?U |FIc떠tyVi΋=WDq+U-#^n!FL?Z|5Q~B" #єE1V1l6N tN5?WzF0]X(PS$@le ") _< b*nM*%C+negߡg u Ϛ*5%>7yzϠ#R`>V n]bWumԽ}3|n}|E +dkk{!ܢ[Rx>j8,pҞ*9lN-g?ҰE-5T cw65/ l#neQBa0i&`m_FyunW}XkHs}YoGE3ې|kֿ_,$cE\5x)%ڈ[lµ0*ZQ #兔OCJupΓ-Z)uZu3F 6٩ePBb>7k֍$6j0L1#! Z,Pn%Hi#fvamxQ/ &QDª(dú,Q$)nD 6P Pp. q=$~8as0`;RƲ[v}-PDA=14H "AR)93#Aؾc6.֜YJ€c Bfzݪ";Pc*4.elѬ LMGӕoIiBtbdH Zi& 絤!!+PT *Cn.NG_ٜb %Z oE*-m(XSgE j"e"0ܪlRPXj(Q6;m)XAu(&@ҡP4"QHTUFEPs\ "!$lm[FF%nLML`ZPU$ U\xJKIFQMmmn ڌlLa.:AMMLUbIAApeʢ6 У@TJ\б F2٬3,CaS4H^[6+; 6 Y/Nʅ2D1+B8Z8T+ LP;aBRE"q5-`mcl,-"B]m˪-Ak2[u%% R%T=&B%& [i ПH؋Vd#X[]X/1/ oA^$[+DLSZUvijc"DA M!4_ǟoϹfZ LaV= ߏ> Vx$$ a yx&TFbi,UFH$b!iH `AS`ݬrgPA@ckBx@Nm6X@jN!9 b버f!.& 4#RI\`R^6X`Ig ahX$cKAnDuIЌ$OfK |H&ms,}k"hbRJ"$b QLԥDFh7ssfK ^.`R((1"!= ؞|/ٝ (PaFAT7,:h(To)Qҩ$ %8u hl0JI+ Jm3@Y&e 5Pb*H)VdTpjZ-cItۍI*)"`D=s)S;9r"xX\n e\`I*5&> d2!fU$ DqI@- -y*0't<`hSY"67F&1F@e/J$L 5@S4#GfHnu?7'|:ZxRrІ4d닫a,VGn)qrF(7UP"fP"ع[+L/md@$DIhD֧=0`i60@P(NT &A a@e >/WGAD&4 1H+IƊ,*QVB+i&Р8sc5҅&$E`0 ЪPcڊH% ,%EQ2%LrP0 ~O:8(٥XZBڊ;hfCN8&%[J*D QKeākmieVJn] vRbHCT*SfU``P)P7ձe-=3ۆmtAXbH8ԨI8̤X7R B9\qs+uu=TDY`у eMa@ @75iӲ:Xml]ӧ\U]*I!@u1na# HFJ\E+5FJH6ب˗YBI*Xj$.Xbv-P.ӷ]"7ծ # 8$D *+T"Dj$S[QjZY[flңMVK\U5XZEEhM$6|S6 `-$A;. CH(7$21X*J$"DS +%A]Y/Up%u ңj#Z)4[JZ6+!m6ŊQF6o] @ȬbJe߮95`5mui,7`^8sA168#mLBvKF9t5Յ@[Ulh0xD qS_,_Vpkw8\pp჏/i6o"Bfi!LEo! p0ЩUpuK@ D 4#kXa*0V1*^=DA,A)/)M0@;E42 sL,d!Ha8!b!j%YRL)(hs`7kűcB]VƶҫB`m9Ҧ$ " Y @#!DZ\/J426i{0"1ˤ,^q 6CL*\. 2Ԉpidb} I9\ ͐ќxo\ $$)4Z$э/6MkJqIRXE£#\ys*˛}]kH$[ܚCؚwaAbw @51}qױdB*pA؁ARb͂6.P&@*$)w S$I^<\T4Q/A>hI b'H ;txllٕ" 2H;mr:ܫsF+F }h̍`#%gb i*>7I`+z(~hi ҇$)]t G#,[Bȩl6[ǜb{r ŊlTmPV5``Gp *0 BŨ@'J/%hqFmѫ-bDC 8$" CXy:k;]UvXĂOؿKPڼZpe:ک@W2/@/~1|HZ҃@ѱ2DB\$|pj@BD`HiĎCϲp_zA{ ۺHiV A_T@~s[<.Ib!%"`\DD@6rh,7R`+TH@d"+ 6PT*(7qU oy_ǽI ." ՜Ky2ȠURF*hMv`f8@:V @b (@PT(PV42 T(R%09D :>GAT ,($F@CD !Q4L arͺFS;EBɥG Mq [+6:P)Q \YbB,. T itY!HYV#Qhֺ멈Xt˂hqT2q!$eoiiBaT!¬ѓ*1-:h6-@uH4:Hnφᠭꄒp*J>.5OIC`24"Cqn 缠cA84kf˷H&CmA40X3Y Rьm3MjYΚDTTrqzp1~30&6|61:3圓^M[fEC5Mfo%e6#Ge1(49bi@+P_yc]i$X~R]FD,BU5ZDٛ+fv&+.6aqma=e!n h8<i*(LQ:k 6#>=猻#檄G~#dfP=Z)aHRR!H-JQ-4@/E$cH8ƹLCo'kT"h%-${6bqOAdƣhcV[(U|DSLqq6F7$ћ H@M4u_Q<ob HeYaCDLka@)]bKm';%]hw1YribJSEbx/J'H&$bhBCLơ@q1a2;X킃DX,c"A[/J!Mm],(^<< 3"AƳb`w c˺ ]Pџ4$4]qg*(e{\0i, H@;܁[^"i M4P?ZG4dlR4F2!(DX7^{EirYZ ڊe2SCS+8T2Mv)a@Hϛ^́65+^ ғE LRqǔBx$OX/o&1kTWs3̷o$C4HH,LƵzg^j^FȦh`X0;1#X HHՉ(l5.GǾ'"H!7X͢a9cxwrsfPoս+ t@XUtz5h;Y??5~~_>]yԀAMh18*L;ex$ң,n 5"0[EsDL0qi-2(9@QQ[@VRAPC( >D9pC"SAQKAUAZHEAb;ll?9[7('w ]Lц \@)/ B>oQUډ" H0?{{?k'2 /ZEdQTKSEFCIaW b _=TB* |aTT@ <_z~_Go@ "޿( WXiEDOmʊ?" ^QD|/ *(r1UkclUZoOAe(*(kD#cBxסES}2:&@^GwLPAsDBDP6@ в""{-z*'wY*!^i@EDx}'CΡTlT>>j$>stKAUz'^$NW`ï#Dw_8rTn~u wmXT oРZ"H{mUz*~q,6L?Wo@"p~?[AsO&COԠ}DRT_{D|Oٰ y/.yLWzDo^/u-dT}!"$!Js_b*/G%S."yO{۪ (W?-tS '_d?ﬠO( '9%>0|>d<*nԂwE ޖ\O(倂v5e_d T8Ϯ^ĊT=NT 'dE@l`yj8SLm}vm̚+@N c-Ea1Y,"$ǙKx'=|K",2+![!)O{E鿍Fh1 c4ZgI2jKUe@ F rC}77;}O@W.8nO=orwoC"\搳FpWA@F[FsG+$̵7FSo)Z+v.Z"dH1EEEmLȈ23"2"0ShZ:&.[ۿf rwHyyEKlKԐlio3A ̶:=S #Kqӱzw,oW8@@.0 21 EϮ[k.uJIǝչM0IT]hT`SaH%_ +Uhw ;uJmyV[|`*IV EA“D@ O|Z3[sՒK;U=]gQUrbjº\TYT1ŊHV5'>z.F '0{'>q2v,S& g`>9w S*ރMfVν^jK{,KW4;/ZiAZ`0j3kś.kqe\R+W3ݶZ]bDMitGMGZifyjŦmM;UL oZɘKeԞd\6ff ȂHQUAP 1ZZ" @Swӵsrzʩq˛'n왅QA3V[( Ŝ./í@D݌Pw0P)TUL mWqmP@B H((ky+5ګm&lBD[|0 DCI"iADJɄ P&ZRTA$@j85\cInNd $M3U0aSŠ B13-H fZ`&P5)G աj}ʶU~Z, LȒ0hKES*A4]4B@XB/,T@ G~$ĆEj(Z191hBBG$͙ >(F@4.kRɢdfj]ňԚbň Z+q&CU[[j+j wna5ud!~iIYcmi+z4EE xSsP*@LaZiS>́hQP@ X@1xȀ x͗bOjiɩLCCż-VXli+7EFl&WR@F5ǎg mΝ%qpw}whHFqdXeŕPr-NGGM3zbvk.4:IΦ8^rMnv\YjŻAv1"b^{ٹɉ%wk|q|97 k+N𕄒HS> ]\rxSZy̽! i$w5P~q ~_Gڤ:wws^G,i;$)9r5$pTPq%t\[)€Z w 䀪|E_G,$x@*QR> () D܂ TE@P :m eH o5"T"' */B(>"Ղb( PwP.EA-e ")E F "H 1V*Q xV*Z@""PIJF=D4A#ȀmLH 炢^** qp@8L@ؤR\Z.k(8ŴD h<0Dۂb-@ـ0x L Ll)n <F*#qxLUn¥z/co%m~bgd/:LF։5:mZ Nq& @`ʰ0MLX̺Һv,\l|[Kh%"!MεpUYt54?~b}!K!Իg9vo)M̧)HR|)7#T{~Y~:O_^d4m>j"%$u%}Խ$/b ůQ5{Os?Ohڿ8v~�r؏Lm?<|OuqTշzsfg&]bK1e3,=ԓLW&bAU2s^C2?cm$Cf1mŚ`? (4%>_ߛ 0m*yEW.)WFA[y"^W9~X: Wa12ڼܺ$rٙ2Q|` /0~nVhxi'ՁxjnY$j^XWS_k~O5 b$_瀕AEG_DG_Ӏ!\1VAUƂz:9 *0ǷSi_[U / Eu~mw #/-M D-W>5&i?֡aB2~10[m>M dM6bi1ՠqDe~ND1=!N>*&΀Z%I5">lݖ8FBR>osB DA'kť&(5,+23NwQ4!n`׿YiQ4|.8yn`rQ[X+}ZkI]ߌ ݜZm(3 K4M_%6SB2S&$7KgYi}`AIcfd < ^?Z*Ia&lWjTd 0ɑjܝdZU J$R[rJn&>VDPbZ7EyԳg&aan 5'"ozm9W,GogxwUmmoYfn-A[Ztp"c &)x k!`3ZϸlBHjA2<~sHg$p2sO'm {ܸ;߿owY=$P@k?_/nZJN\m"%_wSed"|N g_&:i }ZFߙtںE}*~<ꊯ%X"d (W$q3?Om²hY*HU<-W]P޲)Q%dk7_hlgY*-oqf͛ \LΓ!hJZf{Uq>L)} z4\[*VZd.wUf@/V|l f5 XEH4 E:&P8A0+(4rn?)·["$f'c[Y+ /A"qǧ>O'YzGLj@nrR*ZGMD@7+~ |*/~@_㆘}&XJ $Tϵb˥6^=C˳^{-Uj?q8EW,}>{rڞi|o7ߛnuoEo(КIEIlOٵrV{Km>,VS,%t͋`6^.IHdldz[>U6Q3\Er>u/.YGd߮HE|?zQ ]ЙM:uθB}"ʏնqX ÊIzJ-goDWӯȚ_B>1OxM&tp/ն$'Lq~Q @h`}׽m@_r,MoJ nlb~;׃$kSUtg{Q~ɯW_y%`"zEE)_SE3a _ GC :~]O\؀ fazՙaIF?jB}wWW G›.=6dbm8_]s?^:+tQxwc'*xяħ|DjYNbw_bTe!2Q`2 cJM4C7}K.B;ŇYp{V^>As;OK3qm-jsR]`;띳yn͜¼Q;zg='jhT[Gu<]H4H7wg}z?rڅngĮz(2x E-k.YiQ$A@ffdfs]nM ry]g|竍2 TsSJ[º|"j@m+6Go+YxAGA??4d6|+/4n#þt>?4GڢObſ!&|B#.*2!yd9^{EQN}Ezɜ(10J,PRĩ)_˜b[Σ0ayOmں˶>Ѧm7^ۀSfۚzuy%:}ñ\vhuPA]u_-pԍds FA)|q> kcy 7*F-; Yk(%% >{&fAƸCșcNRU܅ɸWuݜOz{F*ñ{͜ov]?W>vCCq{%βڪgkd3~.ή2ڗJ,{Zw7Ŭ7bWEgq`@I?U[)-vSP^I=F lK8!;'fwkRLT$"Xo A}L@1j;gf𻷺ei" 1dL{tr8K|˕$\/T_츥Tĸ?U/+luwױ: " /ޥ@?Z "D=8 DJ:$ ,ץ?wn/ x5EF]iR6J KeUqVK->'ќ~إ\>}7NH9z,`ᑷ5Yf}(|~F~&󔊐7\)u W-gbZ/)2\P?ƟY3beC^f> ttecLBJ:d5WW۽H)HGPjN5ؓw[椞R,Y%mP9wvlZK ,UH)D蹔pj6,'e`͊ūX1 9J֯MSS5fi%~^R•mFK7=>nPDDK>@k8 Uc1 f>ձ$PWj֍f^2s}^[6XZ+ouVbC aǣU>M_k̗ݯzv-er_8M;M\A װZB"`C(㣭^px|BI_"Jw0RX|* f#gtZkWV6XՊ0[^M"sD@U7 ],"Kc$ehjICT [l =-}yj9^G7e2DEVE TtѨ+a_Xn&hB݃}knb 6{l_ܝ-qG|ÿseQIH&n}}f o4H{R4DBb/mzj"hSU $H3ӷ PoɁ &'4maH ^1Krf/Uk+Bowqj]?Twri0SؕnԻ*5K(h[F!8! QL>{[}nˡXF.c 9-{mIc1,(MT `+;͔WUiH)N-qPeJqXx:T%CC'&> ~I"O@"ԾOq|KAj!ՊO"P=Z>g}哀؁͟qMzX+S{qaw_, Zq2R]~dDww);kuK٫S(Pݾ> FfD Z?%b\M`^y]ԲW&AF! Pz!R$٤)u- 2 +l+ /aWm"y<6^< E5caӧ0d )ḃֺy2\ S A@.B'H[y-AƻNaۗ$'k\{?(gK|wOPuS\.$$@H!hOkB?oFe3ִe2w>~߫y_ ;'}6(;ò3ulwq¦\x܎M˻V0D^dP H+z92DBۂmί &ך9o󑊿vz]l+/f_v8ޜ7\ϝ?W&Kd{<ű~n_yd;vv뾗roa7=_^܌-2tfv`",.iE)G#h.R`ֽ(j&i 3)^qQ&u !}쇳hx@E@DP" +yr7"aaq 1@^S@3q!E%clVsAIkzu~AS?rwXQ5b gnO8-\9e)zU h6!LO3޵>ūmCVV[}򶲅G!t۸#;9%yjO9ʲ[Cӽ!+98'B;#hXvv%NyAGu]nbI4w~&  $WSPОJgE<h"xPOul'hAMtgҶ>؀Hs3~O^Rg9zS~?i1Hi Hu576[E"S)ﳧSi(M\Tb Hl|.JoW,gvr*Rhz/@aF=w8ZܣJRV7_i.˴VEn\ 㽺rӃ%I^m}_Tl/_ܸ5wVC=8@/# F 7oS? ~g@0;(ؽ!SurdF@d J wP 7!F=\JmR5Ѫ5Љ*lT`dqOg4듕plX%K$F;ry,GIr9Fw^.]snFↅ XUt iR! HnJ\E9m~@VH%?.\xl{vbc|6jݰN f60fTJEZ`2 @!Pb ?>n;jI~?:&܂T P<@ @x"3.3ue40 ǺQw,d<Wق +тeBe[QbmURֶtʛ2+*xK7/vUCs2tFY9ZQՔ!}Hz]O,|񧞵``_m0)^P:~wO+|ky?E/ڔ \BDi*9 "b T$mZ4]//(Wn (MUuU֓UZ+Jޅ+@kخUsV6ܩΈ%ՋbDlV<c"pL :?}/>͵[˺Q-YU];D̑f @@@0 >Gb}q>_GvӲ?otiYP"*ۘ DDDxj}.?xӎ=-HiG) Mz#*e֊}żQ"eȩDP1wחO<-UҒˏ(6 d](0? dSTQ8 cD%PWgqUGbbjeQN_|;G& ddP<8(Dp>toF  \bU0l/ Bzxا >AI^CI&=}q!M HPmS9BAIiW^DR-`_kp(T@ ~2>%d~OU6UښξK}oQnVVrP@3A"&D'Al.7z|/~?Yxmn{>qE7=T뢪?eyHh6]$Pȁ~2sL*nR-+ qAT"(ڗtL'۠ۊ<|0^\l3>|hшq-Wcc2bvWuD"g_atF$gŲ]!,!P?sZ~#Shl?֖ 6ymm ++ A!ǔ@$I>tQ>.(Zn色]wzUe%慙x[F @"#*C'>4~)!QE;ܿ~dNܞ/oǻ"'^3ƻל ]R',t ʂ9wXW88A|A&X *B"MTǎHH#"v_*C$aGqM@H>|ǃ[={8t ut4<Rr;CH.b*F/Db|QoZ*QVaFp"J6N!?ZKoq b"J%m Hf )wMhs8^oڈec6j TɄh6o VƴFlU|d4mbY"|}G`tSP)W亣`U 1 B!˜| lA0C "{v%UJFr )u#OQؓY6#j-Zv:ռz) V9'41> Kuu˻v-]t6؊dYƻG4g7M0`I$րE Dժnj*QUơ+ZVo-Ez:ݘfy8DF4W\7IpG96JF9˖9sqZqn/G\ԛcȸۍÍ$Q%ι`\ba3\W$w06ޭAۊ%Kg,6-HsHiZ2! </AO@4hQֵ>oy"q&{z'cG Di@D9aAHm>j7@D;:a4@: R +?4-^E$Ɲ5>[ t=BE[Xϡ@k $H8KY團ݍЀDH ~Šלc>Hu` Wz H܆m(x(D"+@wrq Ȧ;NFSh@$ZJF(*ke7GV{CHiohbHXcW> gF;q@mYcQbhQj/5fUjJحFJ؛?)s\mEQohd&IWgľwz_gtۥ{~'xQPE!=)8I.41E5Ɓ #9׻;>B#M?+dϢg/VphbCmhF,L(: :@R8;W9x^nm΂D|~YN;$ޑ.;k)ޫôvHٗ {5 05,%HxЋc<[CEskz6WMv59y\q^7()*T!@1bzOc|+1ŀ\U&coN>)9TzJutp $NdF0R"ĄP<*Mu3f/~ 9\ͨs'[gȮ`6B2:Mh(CE4JK1&5"Ц-R->EKAkՕԮXP-^"Hqκ6qEbv"oEwxn<}"DbƆA/ʹ0*B)kQ "krL%$[ѥRewxWd+yzwCIv[(4S\[PZ[.nq9>˖ 6"$C)&Y"#Tܜ\|FM|9~۷b\Gn6϶&PD8W5g~`/\G, [c%!+f8s:4f34Gi h4jկ2v뽥ss3e+֤R-D-mEeDh6 эI|w^7ϛ߷*T`-!ȈSŋΡdŽAuVemE쫉"E6 |uMKU# հ@k ů50m6cw Wn7IW_7CЀ:s6Lɴ Q A+gVi qk?&ࢰW^7܉/E"aD . TEDD("U <Qܡ<μo)["3b$Zz6l3$Q{PMi̍Q|wi&#qlRYe27p`;`RCRm\ᵫY9v Ň|:xa߻/|ՠdy|u{K5&ҙ~ù 4쳬7}")Es @A #22" @,&%S(Dic,I^1 H(}dE??_|LwjP쪦P"H| DMɞ'āڐb4\qwc: Ÿ'ݤC֡T+ lR)u-=<9nnSFYGn*z*Ht\"pVŧ努SpUU]j@|^p:/E~̟#QMhŜؘ+T5"S14IEĘ7?C= ߽tV,"ˈ(DM)hy+ljy]c!DBݩ N5iPQXͪ(CkG2Y `_N6Ml]{{M >Q`dMzm{RQ2?6wjc ]@ej "lIɞ3t}ƈd`$`eUQ 6`zqHJaUc`GX@ ˫_o w-m `R{hpX4Ǵ?⺩iC)-|-r I$?3s򬅊,.V޿矙DwrkvGoŮ*H0obͣh\^iRuH N(]v왜\MNqO^E׼4yPOk?#ň{V(䒷S !z?T dhMĊDU˻ޯ7xsyWֵ GR!G/"d ?Rڣs.2?e_//'-PAW] aB$^^ەƌ[?:$ry>W܇DNTE5Pui)-uKKW _* "32T"@lN&P*Oi2i?{^ߟ77H1"DĤ 0F#uU~}u=UĬUt"z{kp P*H1 []ß{aBXwjv┍>MIz(x(O2PZӝ; o`cc RЃ|?^Պ|ݬ"VP/C`Nƣ~\= ]5NHe1DW` `^Ŵ{&IIr~pŠNPIHPƪ1IW ERU8dh&ImWKmWF$n6㥮-s6Rc\j)\u&cj#v+$qʕHl*(i$ e9ۮ][_-1F6:XƈIߝNˮ:0bdcj )"A Q$"4 Fi @ 0AU6\@k"ȱ!9&)=uC%JntC˛WOݗHbE)^k]$W(W({5}NַfuUBQY/kI hB&WNvVJ:_+FR5"!GM_!Zm>h Tf'9Y>aPU3dZky^"elv R~XDAڝ*%?Bdlʿ> >d̙fdAęP SI @ &nBS ft࢕]5ӯAd>+^3"A"0dDLx^z82cC]ܪ. sC#%H@Ìjʑ JRLc6 |*ٳ\ԩ.! s=_,HǪ$!e}C UfRGe+XkҘ@ @Pd(;u2yS?v[O;R~߶iA͟%N֛2$+ME>*Ofi% ?a~)Wf>O@_旼j~vԦ{.0`}Z3 <ߑyT74 a: (D@$!H~=`ל79K<w}/ J}~)C@N]aH""ui`l-. C# ̈Y,5*T! p`*)ʞ*)ne?S[Gwf4A+O6: k{JבTEҀZ>>j¾}QKZ?=7ndzODN|D6.S]z_V$Y;n~LX03ߟ "{QUKZ, $a3ZbyҋwM*x%f[#@ᵹe4lŐvOE@zm#]`6ك#6I$E!dC%YSz^eC2ӔZ9y\ PEx%Sl?ÿBh}}N{ecV'5֎PB4 NwWCHkvmA B=s8V#|1@L#a|4# \@@÷MO]-oiC"$EFl-&\=!0HN=II7W8"sR_oj>=E?oRGo{-<Ȃ*T$) սds1Ldb&}tɈ9}& 'UOeT=tddC!@K[?sx~Z PlE5ڗJ?gj?g >$NLmi`׽Ur'9rb*%6әn%"$풊;v)k%`gA_ HXT@>$C| 3^ճm[ũ:l1ݟkKKY[ @XK稟ZrunEx5%D9 ωFqgLJ2:E^H V[PEj ׸g7]4׈%Ǫwwdux Md[4 n,AÖS0k6`3Tw:"1Ëv=~SRJ'c](+ ;%iXcE$ mI$eK}Ʒ7Zھ_|1;5Hʣ#[&kCwoI?> ?[4!ot[wlj,}Sh` t_O2 _صOEEFh%Y~`^g2({|VYZЉt&M0B]Yt&qC^!ˁi!jYj˩Aݗ11.K'duAچ R]ptHBg %F2 ^x Xz||Ϲ,ܼ[8&}nJ@$D i(VB| c$F2&4fsD;Wuok-%6O?c/6֋ƀJ~Ǜot[^KFUݯ/H ]o:0+\wm߸u. ]Ȋn @ ƭĨm^le^U!d]QKA۪Ar(6pT70`t/>Ż0 dN|Z<.r}9(=~z^f>8P H3"$(".B_qQ%4!dص]}LWk4ΪE%%$/?ʁ* ]R_wbZ=޳M*lћ3h"0`!tnjs[${V-ۆ-f @ k.s/ӣw ܇E m\k(Kfi -~Qb=ϛ6rMB[@# @̬Edg4s񑳋߬qC%➀5f'>7QrAڵޫ-=CC0_B6URDe5I"`Ѓk͟,‘E[|P@9_ZƔ2vWtʟsΠ6-=[.yS3^=gPP~ :U -TI,H">tva_Np[vOh`R%y^O+kp}lraҋ4@q Z-kz809O&kߡ5߶:"y u|گWnmY]n1 Z5M5g#nQZKXȇo[]#WvT/\Ȫ&}hJ[G{@<*L"iZ5qdR(*0& H7` I>}XH04HMa lk7-th l#p ja <=ld@-7}Rͬ..:}~zbN}|\]&n?NY հRd9D؞o^mj-D$a f/LB)!#Xy2mKRX=ÁRU򑆚+9#AsSMVF-$rTz8ԑǹ?8𺯣.A,m{O/_F/&Ql,0Adzi!zC@q}ʰT)1:?h}A % HV\+|?ĊF@ΗM-{ E+`-S :⴯{76׋tjA@dWXܣ놺] QL!dIn@_û~@,Gƕ-}C}BVtgo$dF Xe[EYDEzЌFjb)V buைLE@Pq[sn P h<(f w|!sM:H3. "^âY7jSG21\X*M0}TL%3(#E^(XŜJ2{yU7V텰c’I1d  `i|j><`\\oݠ z Z9UtmCglⅫ!l߷WF+,ZDPN?o!PlkE%b󽫵U{]VZU|^ XRW) %Ke R EH3E!PKcT {HȰC&k W檹x^[>"l=4(w_ $q?OQ! ~բOw!uST l`` J-}.v ETB7eBψxxf,Z!ȋ*}A60Jg`.F@"AZ$F\,R^ iI`qɯ~)UT!Q aRT l{gC־oQ0jv XhnP]0۔:n@CR?s&鑲/7{tLH#2 ǿg{SxUrK/O saz<݋iw_^΃GiCT@W E=]Ѓ2Zkq!\eZ"4J!/p+[(d` NAmoX1~kI2%U?wA X.VH> ym,J+.Wvn9l+A;>_iVyhLƋZF#U/uYzk3mroJ&8rň~&D1lsrO۫L`$FAҩEOkjE&[䂵yoqxr~nAm)"0TF~728`6BIAWDREF{X>uum8DAyU >] 6U! 0՘~U?b-ǥ<=B,2N<h47+T>=norT9Ut LD 0` UDӑJX?_7NS3e(}m;z_Lȓ/BZ/RP-UFI6 u/fVj<,vkV ! I )eJtoK3$:$4qzI)תݟкȗT ~hr>!+ ;Ces H5ᙀfitG~':|/[2 vmvgF8D묂s, \9IH4 pđ#7|hy-[iңkQyh(ZT(LMgUJS~B>ߋpF]\`b-> &BX$ym)qJ޷MO9Wf{"_d>ٷIY su"ks}l?_Ϧ%L.z0CغQ@v{xB v5zmlԽ;+d <ȈPQ>2X 6JDk}uA\O9C_Sb4&DPX % mgczOɷkz:^{goQD_o miA*f(>226jn Og W@zHW$G5ivXg^ZWv1G)B :Z%CS Fjα2\L!zz^U+[Kq P24vst6Xg2CY_`ziAhD #nQ0IDk[Kdaj^ԭ+b_}0Gu1(/QFqin4qUBju2>69M^|^[^T/BSu$/A7bpBB %;[8JXK0 Ͱ.Lɂ~<ܥQ&;3M秣H̡ljYJE "25m':\oEǬ`#$)+޳ @$;D-=;`S% btԄip}ժoH4#b2صs1k$(5lV[%"P:`?;6bM_vDh^ZZLLgƦPC4_( a𪑂ȃ^{ 00mQ;>-\ߗ3BT"Lx{ e.$KC:S#vK]sϲZL/v BA8՜&.dRh&6 093t*1&5F5IRQcbt bu:PI $BǚsNcbApvfd$>ª/6\٭:۩?#!e"իZw@Q}.W p&Ƒk;v sYPK'R];tֳV(rlhB@ J ׎Hݪ$Jk@<!0LL!@q Q1dpKKBHK6Fpіb*B?50YzVoO_"w_v/tx]{Wn1"#ٞl@ZOKAѵ]Xx:>F,W)BM-!7ܹţκW6f2r9\&Ըnr崥3Fɉs+20)ipZ,qw ?! rٵ2q&~Rr7/֪?1@S@'"FNk7):wEL[n_E+i*6{f7&hܦ#φ_wdEPρ&mH#OQ3cqBjR] i/iEg@w=w1pkI<>!prn2ܞ'V]>mBNƷ-ߠ{n#?ME6V7LSԧWmc^z+h>HAUvMgzF/~7̇#59@':_}c_B=u5 !ik؍0DŌ*]ߥ-Z.ZZlw0i;;>iB 4Cj,T)ع1+|R1@P 4H}?yK__l53G?KZ2JCKb@5ZE OJ_|ŻELH dkۋOMfH<08{zLЛ5(7" lL\T`L F-8ŅM r9E:p__u}v.oi߲ڄa SpZh7;ρ߮>7ٝ5wSJI!/ ^5el`3 @NQ4qe[F*[*bص'Tͷxoج~˷!z~xinVR:сE,?̙QlӢprQm3I DXNgѱ1-8_[3=5ܯwwmj+8@6z\eu+oVxj PK;038x\$|v)3Jtׁ5kA^0ُ@ uT1Iud-&,cW=I9aN cwcȾH]Mֿ0`t21JNR0!sܭ +u-ȘAPM}M_o/W_̣֗j^ d.5*$ԑkd%l/>Tv^(*y 2%_7*s}¦Øx3頁 9km궯 wؓV?Ϟjn9Xr_oAB!#*rGG]=;+0 k" ʍE"E4ATkԔz@KJm1NX/$(AI FFvF=~P UwFeY  %) 8@}fC&aZ@մ`cӸf.@\ͅЫ*6@休'QfB>[~3[0 GҴ;ĩ'y%,Ia טt"7!@T. */ ׇmjy̦!J'^H"+j( 4{M#7 6LU#yM._8pyrBjcaM$-3k5,bwZ-J(P=\E%XL9hq8ؙ۞1Y.hg%O'Km $Hd%ECF+5Oc$,/C#ܾDe!h DLܘR`5gF\#ylcw1.Q(2& @+2h+HgR6Z'5QZ>uhc殧YwֿY=xYf=$ @h|z ұ9]ϢDi]+ A[(razѽIM/ 4z6߹V:NtZ*%X|0^ztJZvg+5X ҅钀#vn<~*8*t-EH1ʧ|^\f$-ChA"2?Ҟ :Ș #3֐u{a#@9$vrWɛHYOˇ8 Uy aj8 #n sQ c")p>E & MM.`1 &zgCҺ1"#ܽBX>Qo7=Q~F O&B T1!17ErK2lܦ681߀}k7*Nab$p)*pV"%i,!őaE+60q-7o0A\T*?l"sD<B8 VI"cXoIm)1y e 8MхuoQJ)6N4<+OjZ|vdGFdnLrd@H^-oܺ3T8ԢbYXҟ-څ ./7Cg4So=oC( SO>wlZjnē) (Xz|6'fJ9sBRR)Ou[.7x?p48Р(K4F%6uꤐooCGD8~_uiH|ظJBwic>.B7*0#>`م؀;jvі e-H SEPo -M%'*;68y%mpFGކ/.=E4ܿzM\ !$I ;\1ie XBZ=>9BuLĿA Z} hLVhd Y~gzʂ(D 4*'?4q" &u{M\W6#ӿ|C>Z8Hx])fxU2$I DfBQ9Tk(rφyo5M|{_'NM]'"=|P1 rC1b]9vp4э~A_/T)|]U㾒D̝ |jqZdIk(>Ka=Je[T ىD'3:VӹPMB[iL(J$U3 _}uCJ3Du`1<~c:Z36Ckv5m>hy)'SI$K a`jJBѰrtH!<[%/?p9 F TT$$Fl;ZAk[BGkJ$a`Yڔx<_ppVg:@*~=Љd{; TYl~uՠk,'X*9 H/N/goא3n 57='OS]R󃅱7ulf$I}\o渎]=PDۑr|@ O7K Y܏@e2 n<|Z =…~2d 4!u5> A2PHHo$$`[n |%޾?k(P )'&ƥW|_q=Ýny9y{M{fiIwYok<2<[I6W#@6ߘy覧8 =M>Jl>8@㋺=H@9sy6\+[61rpqIb׈e|*͚5[$ <fS%hcKQH ri( i dW,,qsV Q^= {PO \l̄7A?(:vU';z+S,~]kDsޗE. BhN0,[Y: FH \rBCNQ =7;}+|nnh6I̜r6 q5w z82;9؁㺥 NaM4Rdhܳ@vLs&IOz5ո= e3vd1#C8^!@A [Y71b w\mDKÅ葲!}e5j6: qQ?ȦpIvSi$_x0CEXn9~g]3wƽJҋI2(0V*iUSZ] I㞻r6eV4l(1dSaB{TM,cM5UiAh3_bƝ؏NY*Cj~s޷3JjgdʚzIQt F-A21@+"ǺWўt^ K4 J$+$rGW j:Rl'o겚FoSr{k#"\!B-V#}jfqvxGe/WכtXGbC7$?G-)^)(,\ΦrƍړB {y>s뾟*Ň`**!:e/d?(kpdxs8u)8@EB'-?GGːE <߁O珲y2_GwXCUwZ-7`z5Gh\#4`5 ${@rÃpmB"0F4VGʍrԈ!2԰ŐjP r3PA eݚE yExS`[f(R+De"@Dhh}!aΘ[I;vŊZirl_fa3[@P\`&q nxv$/-t= 2[]&xxlQ:b;HW_dpݟ@↢:ǖdѡHs֝.[gX -O 7'"K#Y~LS&!dI D|B! @ b4b/@Em66|fFFNou-\V؍B\\REH =-ZW{k *!s:"RRz`IJ Zi[]Ƞ7AH~+{ކإMCy4 ,ܞS0$;m$m\et5Vli *LL#PUvI:'c`P6:n)Mt0<6ӥO p H c]?Wt? uj " DY7+10K'-戄:d) JXS@д.=`r%k8-M$L$h?U}m@"@:EB=B iG=hRKyXu_!rZk&Č5(so}ߗ~_[=s$Tˌ+ikʝ{~TԴ t$kvQjM%\-0KIXˣ֣sH_=XtN6y4OЎdVq[<-S8%@ Ѭ2y jy M(/]R $Hgg$r&!͉dS}a laӪ ZlW d문 Hk{?/q~Dž # UY%}TԞW{IS5cBC֥r1l9S% w MFzkJ!wgobphxݨ;%+/?~ HZus|ۻzz+*"ˈLBF$PVXDCD6{7heW3EerIWIKy3SrLMPXɑ@&ļ`Atz>K|tpݤOjG\)Y"=h\WI|A<уv9(I#71 @$oJ *@1? y {#I ly9 eعtb8 /I=B! Ff.O FAg]{}B~眠; WUNַJx"+,p'ʀHg2yW  |Ԟ_uMOJ0z m(el^%v͚sp :kN~C/N! HDdA<U'KZrޱo;x>I9C඄HCE~=sh[QUm+j*oD"}CQK.S }W;@ 1+"amЍ7 C&Aʊr)X+h87l!;*j:+T4akB r yᖤ3E! 1PE:p(A**ŋx5YL@h7dFD7:D: &-.t)"bKF@d+ZTzh NN&#}î Y1S2>j%m%0!4xilo5VWbkg-nopUZk)ժBJtA2p yB$T;B2Zֺu\=2]Jaycm7kVYE'c=?=.X#/qt '݋œ!ubOZT87QRАbhM{h!sT8ot!#A*2! ;=Ѕa6g'ӛ6tLH]>_nMq|N:xüyq##t,FAON $B0χ2;OB&yw;_\΀qEw8+/clA2q*3hYP-."N㬹›h|Y 2 צCu8^Q՞k$a@b%L0m$5{`H9" *,0IcN䡶7Xs <(64gZg.0?sO }6va'dzE^ml7C'JwEA|[T!azI\i+ ۞$k(^2{CE^rc㦠H0P=zEJ3%x 7oLd4{Sy $g# 5tB8Dqr? U3@*}VC׾a@>֞<ҝ͊zO(x\|;ac:| ]7ނACi8A_t5EU>/ǣ6^McqĮp. #w~wBLVF([k5bWnŗ<ߜԼU4 <.D=hqCq\/kRv7'4L[ 020h\Pq;MwNa릫k]e<ƈۋLL1KH&.\o.\ut؏f21qDʖj>yxh, `V)/p@ڷqx\NmldDZB&G8 ǟ u]`c( E{< xiG® _`6GQyƴ>ދ܏,JGy5yƪ;tgikrÿČv\X$3 }ie#dd`}/XuGٛ;Ct* Qdr@Q>"?73i|i$d_)ۮ?5K꙲3#O1(vc(ut+/h֪t^JŔHЌm11jhq&Sk?2 M4Fڡ)m}.j}ΣNK# [)%p8.!Xmk@UdυG{ ibj.8Iw Y0y/K)id GП@ ރL!<џ]9H3Ni!H%@HN y aXz4q=iqpWvxa15Mt*p,eSP\U%:,$ry<0Ñrm{o _t+zY_R\I)^<\&RSġ,1km 3t,j=S,][sDX@%(kl?>OpATeX]#BcvIqz* `ێ>5JRMp))G@4c[;a861FXl՘I9 /7U£i.SۦD # VDcJ-sBXJhRs$d5?q>'75n@䏻4n7w[QַjݞJA (q/b]fxzy,=`F5~ NjS"T 1 oSt;/?xAu@.i3`P0t26bj4@q󽻓UP tf& ܖɟ}qͷM266«BI"V mٺ esf$Ά׾mRbj K }CtA8XU K&nl 6${9"DKC2g;6PE SSWРE0 #  "qx)DrS@ŚKE _x,4rxU<{L !0)#D !5IÖ7#{cϹKnd:7 kc'MEd!<9]p6G-z]eˊ&Hs M:;ݚMrYs!،#ܨ{!_nBJHaʀsoD!ubs^r$5Z,v s5 !%bEJP( X;$a|} OwXʜ/}ٲXBRJJsBBE)`4A -v_WG^SsaH'(ou3z6ٗ]c٬6!&IP`~$drR/h@6?FYï t]s1Hq_]8- .-=×9# $j C\ ݆::e <y44xZwrp&-~_˳ڢ"n{ݛ@#=Z`#$d7/jz~vx(@-c :Aor 0Ϛ؞T&BsR\p@jQ1lD0sC9Ɇtc*'6ƟnMwyL,10^ RCY:Ν[6Óan{ (&a)O'᮹ܡQ9.~&! \cWJns<=rG/=tצXBk:ЪjEעH owXwz[wn $쿽ș00H7*b4HuUSr(WK9 $x4ՠ*<4X#"Z %(Q-AdF*@D,A@Av[rlm/?C9U^2aQЅ 0$v%fZ h4N 4+8d#*Y&/Y?ּ4AwƮ&=X)[5HI32r +Щmg~jgV#I?xJ[5cکHIUzjFZu!<L[q`Bs*+L,U(.>2_ga~3M3=%kV ?ͨI{O%2 ɕ$G"'b-˯̈́Ixg:+_6'~șju# "&kpCD+hb8pfMm{wP$oEmE/NBu^ǧa? 0M'ǩɠ^0dwtҖιw'Lm 49VRbRԦp.X|>5P;z^+,b"2ŰAŃ#-yQ& ӪXTOaw2_!}]iW8*tB VuG"4<ߏϞu˴f;:cyBEObބސ7`b2J̬~:=a no! Q΃E3^iysA"xCyMT68Q+Y"9Ozs> gH[R3VŇM5$i4x-k89!v4KbWR%8{0NT8a#" I?U|PO/ LdC#DHk$U9͑qu|rgORHQ*jBxIg]}xbPg)[;ck&.-d8҅J<[vL ioL FKH2F$MQ~)(oa9oH-X:cT2A3 dYHol{[7fכ~M5$Y εSmȆ7Iڋh*U4S^][\<\1T}cۤ X#鎛ឌ+[;2H.HfGʬ,J>v:&"mmm[&o}hğj"I4>:872 EPUO:3y5܋qnj589"h^\c ")2huPa ϭŤ۱q4 b7!OII@ch;Wі3+17X7nǞ\` ;s2.snA+jrh 7W?:nrm9ƥQskں_]([2HؠěF:b1UIf qFFJUJ3dDĝ%%'U^Ƿ"g8D@VxDbۂUٱvTE$FE[\o^k͊X~;=! Ak@WB!9v;NꞭ<u]X@ryCIa [G{I {]aղ6nDªz<̼gZwzZ8b9<9wy-vng J l-M&MAd0$mhBb98ՊI Ᾱ27 U%s^oWFF+RZ؝m^(0^|)0C$~{auԪC[dkYW 5QfgLli'dƹ[ qT:wH+15C?PzY%}ʹ+ai#ɯtHȩрgw{\THA ,/~_3%]LQ vPd`XQF@Fd0 5OU[uw1I*EAZmx*ț,'bWf.-Oj-^aFC}8PCc\1 ӂ| ׵bQe轅X&5IEo} Io뿷={5ʪ,mR0%!1H=M"#z1eσwöCN_0#B4F,Zb+ ؛6NE/~4\{aެ9.̘lhaWex?/t((65x@ [-jG%{>0kz6coW6㼈r@6?p*ZY5(M9fƺd2@tD2*\mW FȆ朤eRHJ`mns"^W/&۹6Һ}'&LxaҒ=82ZۍF5\,Z r9WX*::V3 Uo # *q̑b`uArtq3becM SU&& _*U0A=8b16$lkYMpLD 5[{8Fj(ׁ"$;;էftP7᯸ ;hlyߌF'v*6S}5=g)=H$Nwvj|-Lۂ T6BR2 2Xf #+ӝ2rzw{淅]E C]fne8'2N)hE O>V[PFmWϾ޽wD Ket\{Lҡ/ pl~ 79KX 7P/L) y5$ewQN gg=o_O<$t2+Q< q!$N0qXLH, T.!"!@0_CyQb@Gx9'^'"?PB0vJ6F1 #Dr7F=BHρX,Ob2Z{$Cv0{"FONe#(FGx^ҽh=ne f1B:3XX 7 @R0z=<9y':]sIĄ>jDbQO@Ծ21QLƃlZ6O5"fji<+{V73MLmiI"8 wS`Qp{~yjS`.p0\ꚺ{s?Y`dFD} ڠd1aEH_NF G+ߓ6Yw!H!{n>A2dهP߅a@-x AfE:sdF| AՃ /A$ 9y^۟Yu^OxCQmL4R@# ! 7} H<[euBuBg}z9σSX`*TIHhFURئG֋} xJp\֔tp08LtB4BA 7+P1@Z5M\UB@] nUpKN9A^_:%:yrv!:w^ I~MB0!$jb4O'8y濩i8dr r3lҿZm66!ߊ9t3'A7#"<-O6peb4}fFhCIMpA=A H=і"vkF4cCݵ4Fd3B<]ϋ+}떦xѰ ʹGMp@qъ+^IC{WW6+WNj Bуu%QD"1m"L4L*'[Hw84҉F.8HĎZ:<-A"a".`!.J(@b`{ 9 ^CrN?oqo8gv!9%9:=2^u 46u)S/H[8"{{k '3<g+_ЫrmB@pTDLl5} lD>{}Twa8H6e$! X3$OCyxyp+<*$"v4YݻÈNlS,^"Kr"bËnH A*T$OW|\2{AFVPTWџ<0:lv$P mԎ{o@iqxx@ @8Y3WHeHD2xqۆF(KA9ʣ6-0cLdh/cxt@@z@3{;dDzd>Er_X%NpAB$:'Ӭs[$!pYlz*GPB#ȠP`+sSZ-Ab̹/f6j Qh̭۪)Q"`J* b!"H(Ī(bi`yNI晓 +>1Tnek$ڭj{i<3Bik0l<i+dN@Tۆ8]CxE~]T@8ww PwEC4eMD!j@;ޯL(v t./B%\܍ mKvVPG+c4deF̷.xz 4@<xpC`Ӯ 9PB``v+~ CCA!3Ïl 9U"BN"z2w\"}3iޯόk0⵭Dw9yhu~zD 'c7V{Fُ1,@FD<|0S[g~)m& Ʈ8ҏ2M}pr?@69IcH$Dȟ ÏtZ I#Y%wLVNӎM@~So䋤Kj &. Db.+\ u-9=H9y4?zޤ@!7DF- $/zIAh$#9YdrqϺEj$Pϒ=u:`F2>zvkIͮ#9˜,A/l¨jY5e66*3MڳlEZ)enB! &c-Td;fʍ~LNI;\?wlk.;*h.\gIw7K d:BAdGt8y;}pEɬqyWK9b;Bvph@p*9c %4!lt]Y:awt0{e2vNZ)06:o{rԒsW:01&qT*n5[Yxdwy{HEv~npR$[cCvpOq T?; Q9ҽ^4ƒI.CȪl 9 bzl ;?'d<|=-=Ίx6G0< zgYι79\8 [R` q'5ָ_[qmry&"AS]2 Aa ^p00M/M19[ e֖ V*W gbKQ$"w䖀zѫn7GvSVd1 Duav@\иB@e"4S9 bh"= ']I\FX k|HHvtx] 0Oc{>7Szqj R SyJ sx:AYh$`Cyܵl0p=m]m6w jՠJr*+fb, t;vaՇ۾6zh#8aΜAK,l*WpäQr9Rda]4[D[5TRMor$Mܫ7B;zN}QX3^͈ 5PY|f/᫕殩/5kjpxnvqst4ҐҰ\*@Vs6ɂ`AńCYWEn)x *IRU' D/kHjb> dkE@D}pkNXamaSp,"O6Zɭtx ˋ(ؗzy3?6ncj" dW7<]DS_Py1OLR[;\3_ V>0?d{_ {I|(H0ܿxBl@}gӧonGb50Z4B,o|~#K>|Dzχ/M0A ~ݟSp׆|+t{P~T6>sJ?Iakv*$ MZ4Khb<Ք,}>v;ܖ:]J(a أ.$.v)*H^X9 !GI) PL*6J h/PwbL [ڪiUbƋ`Yܶڸ֍b &dihJESBRno{q:>ѿj#/Sn{PRn163X o55YN2HB) {z>?)i4,Rϥ֒&7*?xTo ȑ8JN؍D"ϛf`m? x#vqf"r:ˇ I- |YNS~ǀ6,;`b67D|(NY,fOC!91O$idM:원:p8B 4ib%%CɧA axE!JiÜڒ!E1^'w| %7 դݚQdRMt!9,eTzg=Evi@EL ܈X)lUzho EnPc>׻ǢW*n']o'HA| op9:*[_q{^9tg7 e! BLp!6k2H5D'(&LJ٫[TZ+D h))CYxuNQ 9:Dxf7#i_Z.HpdR`<0fսKo()'?Gݰ_m3?ouͿ=_Át?'8S1 gW9_f?Cwsrw{vNgzsw4~篆{?|?crtcp}IkFټrTmdx/'/<j]˻MQ`q} %yc-dš8#啂Πo_C̏XJ[U.=p}]44떀XZP%3ȯ%joդP/ih[]>={^d#|-zʑՎj2Vԡ Q&*u*.`ݿЍQ=KJkw `וvq ò6e6܀ۑItv>КJ zà I+zaԘĊ'ZMĠfR觩6+~vI^s[5&wonVEKl8˻_׋\Wo?qZK3S|]eYy[.rƷ3\Ռ+`00HB}^tg%oO=>ֽ9\|zߚ٧b,VIX˫3 ՔiمNн.9h3+h>V^O tdgbifbɖgoi`qR<V4 6VO:msݞY4O6+jyW$fٽk,8IO#.CHK˘L.M`v ֛g"JD5~:pR2(R 5gZmVipd0s507h܌*w=,6,՛;:64HސC :[錖L-wGgfanyUUݮÍN&K4kODX:|(nv eo`/тW\YrTd S(W&)\+hrVy^Ϗ? )gw|//7CWߵi2Qjk120 -vuy{l5|z {* ͵1׳Mnz:S (~~ #X``̄+.:Vk0CwSѼxwsMn5ﹷ򾍗?elzORoFIR\ێs`FM ?_^Ka䰜L&#+j)z2ZZ`5Ja5]cy9c\Rpǥ\.^'b{op HvqwOS#s J)ܽb I %::͓0#e(u/#s`^HB)mq!m{c:%XCdYh(ܐtH^MokmR ! B =.%;( <U:I %C5B?v3 gn1;:>]zricDّle /gT{"})&?|)^W8C$o 9_٘M9ۡ@fNzB`\j~mlsi^g鞗=@ GŘC% iAt]ʯY_sXw3]Ns-`9r,g-t5Տo]by+(4rx[۷~w[pvm`x:w-FfB c_I;X/YdB@FD!HemQVg JskVC2<ݶ]JԖ|CIP_y\S_7ܕG5 qד65Bq훥lyo7c?.b~8bOs*0u_~O^7uʧ0. 1mREج?g[{)^Tݼz"J?d?oH/M2 k-M7=IOa-@@%1TG"X UCf3*ȟ< p`M ׏d ?jR fMq8 LXoJ Ğ>10@K29-klIWfK}imi66),<7 YR|nzTO߂]ж8q6Y[acˇ\E\#&}H{A{ih]n2^MB@~ʫ˭ۧ;o/?˲ՊUfn'V.;e|o@?f6DBq 0> . fH`cǣ\t?ct-j4Ӑ[F1iz@$2DAC]_ȭžzt6Qh (zQ>@M?mzUA=WD HHFB1VХ# OaUuп?{Ő͓ǤB8CВ7_H F%mM"Ϳ )H'\F1e&ٲ6Ĕpmi*Ee-ʌC)6rUɽ~oQ?W~ 4ǔǟ w^:/r ~>]5)պn՛)2w?W˹|e^͟_'^oܸt+շtr,‹b7fL;D>=_I_d}Uos~؞^6! U@[Ax([._^m_ý_pu/_/^#e>|>}yKpn?w`nn#]%>?\F`ߎ10__>%}?zxӋdrw-NE/ǰ fo~o{m:Fy=ݒ H+`6"$*d14.Y@UuaƸĿ'Ni9Iq بf$^~ ]+y-qTv!]6e[v_s0J0R$!hF~?ZBƷ,{LD$ c!j`Y+~ʾ?GqU2YLU Y0̊i3Sj-0c|-9QfEt?i/KPb[id<HEBd:ORf*tKC ٘R,Z @TZH 2,Hu^w'{kn]% b ,4&ĔXs>pC%`~6#?= O>yD" _W0M S>VUs[o:;}8c!: ^ťdB2|VJ\psv,0oozdw$7w稗{;Tu.od?wݺgzoomVK_}㒜'fLd0ZEnȏai{f@"Bkƅ-_@lґk_ןyUݱ[>pN>w{| C]Mbj: ~ϗ>YBdV AA)F2[,g>xy?*2hqνzD~ O{j.݇y|hKvn_UYc3's FL/?ׅnmw!R'N!H_AizTqxk~WLI?sHQ^߭Xڀ>w6o]cd'̠jD<(F>ɲc sƑ<3DFkDlk|Eƀ fH48TTb8^/yhofCf^A@#$4@HŶ?gX[?G8=OUXv#⼱_1111?m<֑Dh=oU73 p@{ (W9Z9XP…1(X"C7{6ݪ^ C(D4XSyO+v.ӷ.[&aIҮo rIbD庚-"m@ɈL'=);d XQZ}+;_͖‚kN; &HYHie ܵ,KfGLTA[j@ ԃJRf7ר,lGu;dc.rm^U{w?=$-Nm/{Iƥ ˺T s ^PzptgŢdyh-Zm$6SN#&x  4︃x1"[L f歍1B[!H0:lhKY&L{_K ^aRHI#9llcG,"͡*}dKH3L׃arZAuL#˦Ra.13VsFi[qĜ3ߘoT>K1㹚9k+~q2b#@DO,Fi{}G,WJĬwU/5ĀPXA"{}V &pP75q:Ars2 p&TXw>< !eRbVTTqjQIE Rj#5DHE+IBJP2U,a}Z'E ۵'߬Yո>|9Ω~iE^RD 3{9?tjAJ [/9>T~/2Ajæ)ݾ`;b1(VQ D;<[PD]ZBŋ!?'U;w:=m.e mz h$o~~'y8>@ q;b:H7 Q GjB>i_/w'3ɝ:z(B r3ШbUfEbHD}&R Ѐ҈SQĖkeB %"1⛈R AI  *E!qJoaaU.zf"$H@ciSJf' T#4 [M+sfxiXJKZe-Y]VnSU jALb5R@N"F*B((7 H@b6|.i= uH, Pm ,-0rܛKhinQ* {kЁ 4m5-iMƻmVĐa ꢣH %-DJ3Yuv[Iz0LjwC*-̚sgo5*^M&e=:mR&I1[oX 'eR@)^@HX,Qod@-hER* Ahp%RC35Tښkcsep!.K!Jo1h"Di "1cc zօ+ IM1$ZlJ6h ,%IjEHB" U j GFtYЦg:R"Hj$Q)I&A5hV aff4-o?+=wADP+iADDA,)W]ݔe-W4եKe3jNe"F ʅ ڳ*>]k\8%mڧͮs=]~'PTŒEhL EoO?-7 $EuN OeMXIF a5HdpTV,~j{*b/Fw%\'<Ӏ!4Y&if ˍUt\K'xuì_ێ6H (@Lg{I g dFS۸~Dٵ\ uG0vHv\-z$Q1 .F)YRT}l_ 4 m vB & ȁE5%/tT,6U+B TTJ$ `0$Ō,ZI(@kŶ*g\ܴݹ$LHP+Wѡ.UI&#VT)``P"F!*Q b5U 7Cdѩ-HfĒ0@$m,9簪m. 8bOI}5ݞJ́*#áۍFQG[(IĤʋ蠐zt5 {Gj7ϸ˿+2 sHBH?][K$rW/r>2 ] ?Nw/m Oõ9-'U1hY6)!xm?yyc~i@3vu;~Ae}J.҅u֑+..ԼINו!z0B QAKM?^yd?&bL~!V~qV}ul}{^}y޽ٗw.ր{{z˟%n=o gCo>nQlsݾۡy=t׷xMw^k7]w4,Ɣ06L{OԹݝ^NZ7K6k"\m[ydgwoOoGzӑ;V;9]DO`Sjo^sDAEhe|OB(h=}U*6+]!%I"0:ѽ}=}yW;7mO#d}nj0Ӄѯ<;_8.s>=}ŷoGw^yDwhܼ{2z|׶ sh \Jm+nomNƻOw_{﷽mgX6}M}=wu;R؜N*eJ6|v{}+W罎l>OUUO\viww}׼qYwp۫^i臨|Gw|Oxs{3. :/G[u_Pͭwu۷4@@&` dLLM44hCF0Sj`@4M2h`ʛL`LSi6BymFM5SmH&Jbi4 M #"a1F!ѦDjM4~ 4S){Ji~JoTyMCDBh)Bx#;poy$U<'"U4-H)H 1m_K4 dVsi]8^5 xCrHȱۯi~rRCĴ%i !>9B#x ر 5vB<Sr¶ 'E+RȐbS dgzܲ2bG#5zp!h V,eX f^}hb4j\2-&-E3fX-5mrjk$~>Uw˜<&!Y0KEm\%@b-hz^k@x{V'6\-XMa$jQl[x]ӛjZ-XݵfQTV+MKOƯq7pd ",Ѩ ,Z-hѬ1D͊1BXimF5F"aST[XEAKX5 $m&A4DՂ6U 6+E[lj-lmFbdRmdZPFBTb6ljѫ4ZZ0jQцk1h-dV5dѪ-hZ6ZZѩ+"ڥlH֒ŭ$QEM,IlT*1lmAaD$P1]~MWn.U}sy6}<҃/VQcQF6-|nj6ſkoܮkl-IW~Wtm3[U7ko\AQx+w_w{ץ;5>τ|mRq4eSgW *D ! ` X!tM]MBHUILvB@ PkO^5 'pPrWdטJj,^ϟ-??@fYy3ٳE##PTE,!!!jHZ[p{sE*}{uuZn4Ŭi2IHm01$,T igWU]ۻ]ƹՒ*J 0 0BVF~18MFE"ydAм]nn-ْ!!L6SL.v{=n|s92O!)Zǃ5ya)G;Ct1(ARz+[WPV(-62Oa8H KcQVA 0HH[- aa,`B h^aWAqT%DW'R!ѱҗ K!`/B*d, X#h2s"gv'yTJ/YF7pOKdw\f٩3(!_S.,0P e_f+f>_*یg30<ӓ lG`pG&LS˭Ҿ>i A]`}ڂ y-ElCi?:I>f* %Zb$)IRky w" @pΒ[ ;E\ 7{=r!1Au]jf6)CQ0‚s3?V3]xsv'Hh%,Z(1@Btbt}_nj? @?`ίlpC]DuDuٸ2ՇLpgټ^HJv9L}cCxny V(i߱gBFOuej_ɾv-1/QI8g J Llϱ/Q) F B%W%GvA^[{=s0A !D@H &qw vjһ1L@Z&m6 ,/.vIr]ښ(qY8wŊ [ j0$$?eH*GϾq29ZQRKPӢW_0(Y컮&Mg_F(D@Rfo+Qy[8mx[TE 0RBEH|QuskʙM$ Nj'!g+o_GK ䷭Wcyƽk+yN"Zմb2[[Lxj\gwM/|ߧCnPS??^2M_ATʐN}qJ򐎿ߎnG < @IVEC8jK]6Ū}7'!P}Rm5#F2<ea4l{wCEA!wx{ ` U,[{yʹ"M&P&6/?3w] ]Uv6ד?͒v ML >ˆ^MY nHHQfa4K$*6YQ NɯD'))+n°SÚkض쫊6uȬQ*;AH"h`M;ҺvĄ'x툝]Nҵjc%4ͪkw+ f*3.C9tɠlcC@%tY4dmPKA*=dBĢ&T]u2IԕM ]6ܐm{WsyyuVMS4W\ `n*kv)6wGܵzmJlQv}uQr'%(ƞJ&T$ 55.c6E]+eյrw[Ս+ yfs.`~i]Q+8&RHFEexNl޿K.},lblhakvwCnћ-,i /A9i66ziIGż9@Xn#"B!{D=,|gAoMo}o{-"ƭimebLBC_6:Fj91Jiu5كFѲ0f؎aΦ FIr8ڦEM9D԰[FXZ"j6x@lcMOy{tg=w2[рY$`NXa+IE`H#"JIkUWIR.cLBj3CA~}w.p(3@2b]<#9fS! @D[{}%x2 3䅥 "eusXdžo}|S~cQ"BG6$4DAl))m"m4lcĝW7[ק dI F/GYk*.-S9m2m yoc$eimT{g} ,Nf5#3rוVb z[z:Jzlp pm+qYi'QjY$Z6hM<9k^je(iδbG({U(uhsq3kNX)Xqn E-܏Ŕ   h>ߜM&" ~sw+|ʾ8)Q(i2I,)dRR‚4J D1>WoI@p TbV1D#mƆ.[he `>?~ғ;hrR5 *gY$ U $-*{^fHDF"j(]~{ \3©d+gb*St=o}DE45TFhI+u]? ^l(3>W`<ϣfo?oJƏ6f2[D Ԑq~Mw@ Ak<@&KW"vrj"KPċ!"qg?AK=Oy0!\m3m։œvE{qyWi+mWk)K4%՚suϕwwɾ/OoqI:vs7mjffcYZgGB $@9PKj.褂DAD#39o30i mt×giLWWi۷[PХ%P IM T ^0ERYr"0-P16p Ch>,=oO+f1(&fK^ABD4j`U͏n!J$ mh7W&w~Oռb5XljZ'%mX` trunl> ?5c"H2"RHSz3KDSr!:=86͏$E6v(s$ח\zܷvvr9[نdTZDe2d<;?7ݞZDfC7[B!a# c$j ԐbnU-Gā+OLը,\0216fN(6jZ#oUַu VbcF$E:% BGQ1CUeA>/×uH0Ȓ&9n^w )#'[؀D@;ߒ/\Wq&XCLǮpx y}4v&0"4bRDmœǖe˫դ sh,bص*TjkU}禹>;CXi6ܡפf]mmlI Yr$!(*Q@A[ZZ5mIjK@mN<J䖨Wsm{rXZJED[lZɭVlTmbm[b*5Igh}NdV`4. aFc OK*>lrLG}LC~ߞڹ?qM;GZX%2|$&*O@3 ߛqNXoW'Ado(@L<]Oa:`bf†{;]]@L!f "BNfYkLFj*7VUUB*)[]@#;׫S T;:@F/91ٸzi$^R&Rc$U/XY( btne۲mboBؐ:nF$) Y5&cHV %PlQ4a5_#ѽ - A WAl6HT+0Ia|4ݘ̦bJB )ucv+ Ɗe]/unwׇ_kx/zNO? smXFd*Ppb[#"5|-j0S1C_,4 Hl !^p1ëhZ;1N姣O~ XU:476>@ )" wj6K$kյE1s~N?CJ,YA֘$4 ?Ҷ$#x\$̕rnj^K[#v;c HA!,&~bϡטP5B䈁`C<"0TH( % RpDB-4,EP㺫`y(0u" ,ꃬ:EqU޳~=sZ ʋr*:9Yx%WXƯZ=>k,T7SGȦ.vQ^8{A8} @4"HBI4ߺ2 "HHȸgP~,/!cˎ 'qEf(&8c8Y(" $`iXc (!v '\QvA,CH@ ]"  1*` Ԁ*'a,JZT҈b=@=R5H[KM $E"4$%+3}3.nN'0(prg놘kOظ;\GʻO !wX?$BJHx@n.NaӦ*rT1{l}iAKT6j:/44 D#lNq]P唾,_ d3'.X˽>&FoQy(&ʖyy.IZ^qmjգD.TF+Eg$$abjrk>Y+o3_P` B p RR^fq\5v=n;.>W T8L.N ĄI$RE9ҖH[F6caTW&l\PNh*R2ZX*BBZ$fa}/Z2d( I *P5!VdPJ#)VD7=7^jpCab@# Tʍ41#kN{ rt0a0kȟa~ίx èphaz݋^.l{,rVSUr_7ؘ D AWeXC:~r4ԨAwz8gՙuIn{׍;y!i{<錔LFn6T<{zIa$FF@*eIW/:X ZfU6;t@H $" C`@94x)ZiF 6A DD{mM }Đ}kPJNAAC0'm),lY!]-nգjZ+Fv""(e!xڽ ^t}^PoO+gioٌ|HQ@Bcz𱈎$T}9К򐘝9(}W7b."7{`sHK>2sp÷4Es !; ,Fږ4R!"PnYܶU|WL(݅1$hJVl@ b|zaTغj6əb1[ ,Tp'Ny"1 b" 5h":WbU@8(ۑBD ߊ40`:=:cx>Ȑ9֑ѽ72 paIi֢_{|7r?υwn\|jn$)$*?|h/uNWœCL5׈5A 8V#Sn\cFVR Ia%_er$}>#?yl )O,Es@UUDn2FDqF5!;@6.dzHdJ A\,EB h-,P(TE$t,˳+<%􎬝Т>5y@AoD$1Vѐo׬sr t>X)epҮ+[L:lj#q*՗RR8 DPڀHPorCZB@DYD (csҘϻue -Ƅ|]wEgdAVm+YQt <5;ABAH0HHP^n@N\zvdAN{rBupݝ7)^d*x,$]Z7"t""Tzm;uIղۛ 8XN| nu,t& & TUEҫIFۼ>:r}3/:-QFF8!!|,'jG.˚or TӪ_Kv{YO$.bk&@ W|1,vg`+lu`lv͂QFE zQ Fٍ*ͭm2*ɤMMFd1F-$db'ֱ-͙H$mlvGL 03Y=XU5xk7 XbfDv!lB\vz߬gW@*ڔ  DnZ⇧^=m_Ws5zz׽waJp݂t@'9{/FAI`lh{mJUmJc`ɔTPdhرhF $LlcF@Fh 6cm ^ EqdJgkf}P%i><(.Z0h=*cQ9u!A6f݀޸B|-S 0 e;H5VBF4|Y);=p'jHg͢: pR~ 2[,?-==WGVv/9?*Sqx8Uxur}~ /_u&Q HIM9%Z_D`d&\{8 Cgϯ$uRMȪ\D! o*noy9E0ѵy;!B a>4{3IXNWcgrC#'D9NqfS)jtG*xp@wt7nDQ(cʍxCc iN|ع>`&0K SxTM8-[e^ ̞쳜;_f+D,|$/7Uto!^*7{gi/|ǣR=Go2Nkq}\Gsoij<8X}hh qxNns|{ccs736+S⦸ ğ9G5~5p+~ aэq:[ MTCz\O?F*pWݾ|sDɾ"ɴDa1Eee-(b_ߖs>/AMmmm;ţEyԡ픁lHP@!@P4Y6u4>gu\meEAbZfH&!x`u_5-1$rbA   ,ԩpz.齎$m~O;β: x*Oist;' HV.l`n "K-Ohu Żi mT($JJ%c}ȝ!kvΣ5Sv? DqėG{E5Jfm>'w&_9I/>62yuϧףFDrc)*7Ĩ5(Q>G~_CK$FBLyЙQۺĨ~fհ_`UݹA`}H ȒYDNE3NӀL<oܬKrIqɀ+>ɜ1 cLH͐P`Yzh9R[Xg csLtӦh]KᢙZ02 Pp HkL$1m`@ĢEB. 6ٰ6;[TȄAf{%@.C6;y~-UTƋ kS3 FG^M+;ȀGhpOhٛ=7Ej3$Q-8hHqy-wuuD]|.Ц9ܻBZ1պSd(iQɕ6%u iYf74aǻI0 B !y"KK,^r\>slF@\qN,GKN . 4Kf>Zd֋<}b;G%s6UWrݲV?Cr I JRl26(`K#o! d3AcWqiC H fdRnbcT16A7ӢP!m$I( (W'qfrvm?og>4\!\*hR:3eTN uhໄ01Dv^^h8;:bcM!mR-Q V1IsVhIǖj y8,VUM ̈@‘jFۂ"Cc 4 Ĉi45'l =ԝ:d#l gSe o>]eMBFsU@[HZU%2Kf f~n&LDGs5]bUD`ijH2C&]42;s[d e¤"B2"(2FD])K0ۀ&lǰsaQ GH V8 &ӘXWiVMU6ZDZU R5RXUjehtBB&m1XhdKt AgwX~jOtW&!5\]=YqέI?s1BB"-u QQW;'Řz Ŕ>vztB%!^6_ *RFφCt"A 3*[>6iJ欼^LpH {"+gvNWJ+-F*>s)%)*٧;l*NmsQ4p{KvRˮىv]m.N>+uuJW pQId:c5:3x'ѨԐjꪪTF*bUdeQr歨*h>Ќ7Z(N3#ej+nFUuPUJseֽ !:K,uol ɥxɃ!#lzsh~}T7S2p(ʯ[䇏 ͞!"bA_O/k7DLFG6bpMka sRP~  fogs>+*H$ >I[d˾+zgraG9-U+EˍJT  I IJI"AL7-kA@NT8{'hEU|f/s}]!iFšj,:@$X,zD GG_іsA8hϴ٪7- 7`&KmfJ J()I]%+)hh)9Y T`q%7ux7 YsI!t`s .sUunG,!kje]}{dZ4E%$n%U *$h PR4RZ(P?Եvz0.8,T\} $/b!J3a]fZSp(+\~8f5ӕ7@]\My_]3F-Om%XɞE @"TPKJ+۔̪ntr%*6eAmah麟?{XZEEhM$6׍wGou}(n W`gBr(e43=qqk?Vڨ9/*GX[U@MrF*Iʡ$ m=$H0D "H֊MŒ֣ch[bb! H#q 9C3p5p&*%s@!daA$\Z/:#o 3|YdXCAn$(RU1(GMv Yf +-fR 鬺cÐ$$)%Q$&؏Jƒ[0,ՎS4/qe%Q < %NR"RD(1A"Ab afZZR~uգ"xkV8FmP߸R`NU -:*2D*Aq}9:RLB $ PH$a&Z'/,X;-U -Hma倬0„" bEHbE@GKU$P5cd6բ,!$z|u*Y_Z̜-~N-9cq `ľ6-ThP]D:\ccMSmk}UDE6Sm3lE&B+R H6d$_kgSҙ$ `A񌍱JPZU9.ZpScMTrr(7cO6#[ۮm56 V@Cq{kjw6vm=֞3'8t{,胿A1=ȃJ DaJb"D[FE9kx7i}wgrmTuG^ʪ ҆;P%\" fE"X5r.TICYѡ$$mys 8iTZ"3Zڷs[ yfUoJ!O~n J'T^ĚxI3!ĉD.^/D]Mkwth,D:$#| aD0$4*Pr_\9;spV9khWl)sb-~{lj"¢w(6e`&ݤ}y= ,0A1ELbKHH$#!"çn7QMfjII#v8aEZMՅAx GbʫF4@hB͚Y (#pd(Nk Xܑq۞daGcGw\x۞uڷ|Twcdjč@I&m,$ۋЊ* e@;6 ͩW\w[zְ@THU!P* a (5%a(C546Ē.6",'/0x#l:l9J-Us-Ne`L57ǻS&2;uu^F|հ"(A N^8B@6L=ؔ G|UeW{c[Ph~)7Z5O QWI)30׎EVI XjPoQz}_. @ ׯV`$@%lPT4H!@f3Bx  נf@(*CQ1ocG* {h3EGX:vBjE^ 9YL.TL6/7'.sY?{7=O$@!QAON PGzHqlmbn: ]]ܫ@Ko,f.Q*uXAvt7_NMFM4SJPCn_ї,lk(ڋBIl`EՊ"ֈEV6H6#Z- Ed2=9WַݾD杂ƿ&$&Q@Ae#/ɵnϷZpMĚ&*к9% Axx/%*0HK/>+fF=gԫFh=:I<I$r *(B @` WlӢtk8CNXdtGs+cLCc'AF m " ui9F6$ DDn⛿G zanť@'PAeI;qѣokjhi@a *]!#."mѴ FH,J=$TMM)nͨ65Uյ̤=4_ɦeyw%XQՓ"LN qlxWTQcDEm*-- wob@ӹ 1 W70` =7wMkfm}ތ_/?DIjL5 YAHF:z]PQ)Y(#o*$1iK;ׇ0Z qNH;W ծlY =02}Ah#z?gXZcxWɑu+ftU7ƹA~2gd}"yFHM' >]t?-Y^S3а(B6A6,"$Xhz&uT';ˤog!ջAIDlB1%mtM9^ ɢk-LQjE kRe_oϮZuW4K].(ь]%κܝ99Âl5"muUv(ilXSmilWJKU.BsM3ߚ[MBHppR) CT8%b홢UDOqwt?OqMhbs]!^^k$P 1O](%%gZ # #d]@K⁹@уz1DrARi[KtR 1ЪoRE uD ]1FŻljqkZ5ҷTTֺV5kE[XTFڒ+_1Wf6ͬUEzVt{ -k\QQqq? a { a55'䣯J>7Z*?=>7 bm(A^igڛ N3@TW0 PlX{ϹU87l9Kfu!.fUZh{[V-p$ֈ IIP U99ƌw)n6NJw?Ns}=^_#(ٗFF @-7R}j@xт! m4LT˼,.r1CH*#1L?fDB}D@Z8:Gv_K3Ώ@ix%o7+}ѻͱ}3'ҫo߇eu3U ctض nF=Uũ;3Ш^{١޳`Hm@\QTOUW}la?Wm.}KSsshDD|33zo. qǥVbn:B@%ɕ&s?7?67D5 ,;icDD+^b{STa BDD"ڮYgpDDu9K/s?OwG QueeQ;I;hs´zB'龿z[AE_Ɉ=lQ8 =}X ((rz|]r~J@/ss[s5h*xT@*z9|c? ܂?sJ =75嗓0ADN(u|˷v>d @A~~( =m?x@A]O]ddIa^MD;bQA/7*Σ@}%*ID7):X\"+|M@T"#Y(Wg (ty0DUC"j=>ǗG"LT^mGuy~er/o*)zHPn4>GeED=/eL/TG'wl|.*C('P}e6u)֠_s}OPWv4}Z@ڊԥv?orog-#@6oJ<;J.pV* g̈"oIHx;,'d]9ޠ./;e@P3Юh #t{X⭣`Mbˤ_IhHR,>0 '܊p-a?zw? tSEwz/! B!o0o9Vx5e@W~g8-*uUS* #[{PO&@6F"sR.=罠?}f*ݎzi!; ]} b~׼;Uepdz%ytXSƑ7L dIag}}o* Au'(;.3d&m>7&I/rx>DPoW( J)N9i @*7D-C\,SS0Fu#vF@MwmqP%Zx|KUtph!6@*Ayr/@U&'9mAT }0)c8qsq>NJ8Fyx߼ߘ]a7{oBÂ)@K0_/_1dZ.ߺם$$*=]~ˮUFzJ~,bӢD{[Zx>7O%PU*"-j<=q@k5=@[pt6\L6+k}ʹ;;n4'\Q";ٻ@PËg M&Jdy)⍮"46`'T[ȯv8`.G/-A뵟}}V{T|*{~=/2j5t'cH N]M)qtwtݚFVq^S%,$RRA@Ho@/w޺8/8SqM7t6ռ҈:a"8F\P!s9ZmHɮ\J4HI ۍY[IE&.5(cͯD URYW%|HlnA 01q9A.A&׃N_Ɖ.Ѳ񪈼C"ax0-/f Q H%TQL("K ׃Ca@aL :3ߘb笲ѨϪbQ R(Q2eƤ.k"4ѿ b {n:Mq-\xl TވcV *|-ixh 5*Z7i|+uY5)u=3~qk2y\[ؿF**9gh *9ir 9 H?fW9ٵ{uW0Ub>!R9][MζS.nJ紀č({qoRÚ}/u;0qq]QCA# J:31@x|j$uBO=̩ԪD@Ѕ$@r ԫfvXE]nuQ|>;ؒ@ Nj$9ewor_0()* aBe GEг;Gs "mY_C Hn"t"2[ R8*C~<9Knۮ(&x(jnt͐N A W7q[ }+S[Z' HyPC"<U3ED &b %cP !P" ހ>hL@̬"z D䀨N"( E.@Z.h|89b-ClRB`(^AZ1D*{tx@4 % jQ*-c׊h&P)"!DChDTGE qEpLpP6AABTWz "EkM `b>"^`Ǣ:8 ` x)&P48*((h#|83Dցՙ"'AWj.H"|`L<D ެ tA3Pڈ9PP hVn <ϊ|.}1 V2?FUCω:|7;Ӌ_Y B* AB@JIϯ>z"cp1=Ȭgkɼ_tR7P R3wv=XOQN(Pbbpu:ױTW `" z]5hms9٤WK",,c6V2)bP"m)AfRz.'T6(OQxgMJ(3"{"}7}Ti21WYv8O$HzMHf|S;Eب?꽛7|t io\@A@*#j `v1u4nFD|;0H/-6 4:!\^}.F oYhvU;Ϡ?짿jU . ^WpP\Y ҹ.NsD)EDs_Vvm_Aw\N.y&$`HZ6*-4EmLHHH['sxak?fI`G7:/,'xmbc*EGu,%SZҦiRIcHD+|Yjɇە cP S_[1îf @+F/aְka!k&m€ٝtsV!1q[~n YG xc]%#xt3Ml+BI-bBtB3e?jQN، Ax;qaSvPH3''ךȹya}4行(H$A$!|_F—~#8 o]BkZ87utvw񷆦~Oc?/yDeزfM_RTX.3k99T{/\uk?kn;[}yucby_f7ޏΠ@解Cy1L6C}Rp~ Dax7P=,ngn7"ħ€v%O>{(~T/ۈ(?byXeuO;Vo`Swm]7y[;,<1W'@^s{0(^BlS~C P6(7ۙsyJVh9cqڱ7Ff>t/.v\ <99I5eU`=}.4{ /4_sh Q"*QHgsyQb+Ois&( k^nݤ2p GMJL4]gi sI,96<* v ki~։t 3u7n>~uӓ6qK޽hm̑QGמc&qΔeՄ \M@ga%y>OSCwEmU(0ܳy*ŞӮ87Dj˜򾱊&gUܨg -<9]܄Wnqq.w>g{lymƪ W47]_k־?Wբ ((eH 0vG(>r#i1{4.̈y*t TgN<[Nh+ϩw `ϢlYn/+PSnzoL-q}daZa<mLiy7mx]O{9HJM+-ki\x{gצ嘋(`z_3vuoϏO}Vv J7m/=Oju٪QEi} \A"[w}DDAJ&`'>~3]y,'1WFkLw78iB!PD!(${7~xEEG_>oԣj˯$ 9"HAիu~&kU$P4H!"eX E)HIE]JdHP>bxe!3Yn5@/| 4dI%^/ou 9wГb=M Le)F-4PxvW] {oA<|@ IClk接Ug }`fBCɣ{'sE|x@dHjTWN2Σ+}Cm`8#KDqք-+E|Ҋ*3^g9>G=_UXZzoK?1x_Wcny,LJ<k窼>:]gP ]Oi}|" IH$ɫ"To>OhxKGvҧh_؏Ogz.4$2`/:x *\s`Ք=ow_gAxSfk>YбjsiνڝV@xQ@$N(j:#@s8Hrgqw3GPGI#*H9=xo? QVO7Lk׿ ,AGR͗]ʋM$fD`}7VV1#8ގk \T8 c Hq;Hi>Pt]oۖ5:KӋL9Ԗ@348܇̘|$Qd5Gy5|^0 xy|lFv~6Cw㳨R;PZ'ݪ룳@DqSCy6 h.3/)ңD{pʬ+&tPSEU296򢪆9_>@@8 mroXy VɠSmqbI{G: :! x)4u1&-}KPzQ{*COq7y1m[Oj!iqߍ??ak )A6E-Q.ԊMby9C\y}wN Q /*!iʝwUǤJynP5 bWj FD{*#w*3 +^DF2jֈ,1pل-x:#eŶ9{Y8l8Q"cIʁ[[3kqgaxQˮWݔnm9#eK{!ZH8#^gOﯩoZ' A?~u= _U.ޖVzNۭ.U]8z~-5'w-;_"mWE@@6!s<[Ee HX0yT=]O,"P[΁m D;XTHdm{ޒ mTP{vA}joKOV}c8J|8)}9ao}%qei!1ݮT+w~:{H=6|>O<^' GGCh DC^^5"Ņٍ;itc엶=Z(ygZ@|dby4'ZQt;@X(,1 QR6BxܙYPDOœ5kR()J"=uhu~0TD g/pOE1@EfXOŁD4 t6+R 72Ƅ [ 2,']b ؑRmM eHP R4K ?7n;>' 룥XI_QDLSABceKyC9z<!87_ĮbI`gP s7Vg=#N)shVfֱw~5W-WEbmR$ 7QR̶EX% ͨ5>x}|HEG8ORZ^Eƀ!u_\D œzP !_C=?)-=_$ QM)N:_3gI]/Zk7u<%SJ`0Wwǩ!)2>>'@?m3DJ`7 )/O VvDH;:U<"%{ocXu@AD2@x @ZU_GYMNѫ=ZgH'RC8e kx)w3|Ěkˀ8;Hf)$ Zureq@o<%I{N#82S#"D۝߸eQC?N B}ѢqC Z)j TU)i bu f +|yST:?7kLڷMR`%&#¸Mvy-?^0[\) eQ,HBP&,"h j?ӊ>;`(y?/&q4B#}@>ɂxῆmb"$ p0<`&0-p,XH-4%°t,I0oM-DHfǶQߟy"QܢYS uj2*CHh' 2 %tяsW$@IiBF[ab"bEiۖtCW(m'ofmܴX֒r}ϫy]-yea)9|^o2e Ozf8DKgMu/r1 |Ex}u`$YG7>ډZn[* L$w!HhA8#E4['g Yuh@6VھqmD/xFd6!5\X`\{G\Y$EdI$ddI?d~w76&8Pkڷ.c ܮFEdD'-՘卹|8g4h'8ԟkQK  מ翭NoFjWC<@k^D9 9}YO?t.1Vob"U1:m4xHےΎ{8\?--o_{:)3\c/*HaF1 OeCO4 BI eLQ1 .,ue lG־`ï%_2^jVڊBV CEa>SmƢn1\krfVXЈkqW9ljٵt:h\W{?NlRq@Wv3-ewP@!"@H<\ c ~ M=uۧ1 5<ȼfDDXԫkju&o#Qپv3m+ F^6PFCLyE!ЈxyPLϸƍkb@<`dz?<Dr 1/%A=O1J*P(ECbdRth;۟Q_{*mmc:w\5R'3pi5#%q!m!IBDR@YmR $lH3"mE{f(D!G Xf䃞?Q;Fe<;?b]ݖOi0!O._$FE4P⇐y*)eXht@*t@v6 Y϶mdG 3;7uyk 7[na0>"1q +4_rԈ?ZD!(%##_՗KGP? pIlD; ۅ% @ZZK1ʴ6Yfa^hf??]hH5i5AqCO1Ud[ȐC_n!txN A~U^׵cl:YFu١iu4[ܩ3/׉")B@!_uRD:P#⊡Ĉ+by1;v=/0Q1PÔ wOyCNL R3޺Ca2Ԁ{X=`(v N )O1=aj$E|N:  o~$ЅFnsZe2"BJC*ի¶";LPbEaR?O ~}kt *ߡ?E=@| * zx**_(YR`tZo!MD_aro~7gU{ᬨ/ҽ @n*{n:q )w}/7 n'75"+?bq0$AP$M .|?ﯱqi2=R~0I^5E^{{ 6vVL{r@?l6j< \rP]ĩ\EM'Y'GIaU?2wX@5Y a2۳fkyZz[K$Ps3ãC gL۹M`s|a>8DB@ys-bFz 5m4JZZENwNv6!wlb7F˿n]dB X:΁Vy?w~赁`V¨lSH 5; kgpwne՟;}, 1 UmoWUWlW /إ "X!$Bq]eAyx>MO\gozo."yb ӫaQOSg%u.{~{_:lK3*X w(}/D4pqP6PȵSb$_δ6-ޫ]aݢQ#e $9^w=j-Л`in@p+l-FŏUTU2{s`~rml:_<Ǐb+"~dA&U|^?AېlAHmFDd X$H(l /W,"CLjy{/ 'rKm|׹sTɶq-39jsv~EyBv uUvX/um 㼔1@x!'B0H_f!\O$Ι @:J0@vqzxJ7b~Q*޹CODfO* ̊Ys!`4`.S]Ey'k[{|7wxby"j,iѲf/OƕpH$B)sh$ Id U}& $1(c"(AN".CӿEU4P+[U 8ʉBjZ R 0 bD-&F'Нx|ogjg~zU>PeB֊('$QbmH-D̰鳟+)~[KbP'y~Pܳ/h '! g@!%j?y0hAb}x Е1x^WcNݡe5HgB (>+Dwj]ofQ6-'@?""cɫx*+ ,cb(dC`" W:<5貵 l+[+j/kW.A.Gsk9STZ)K!ia疵҂\( Tg{jV)_ l(Fr?x(nOJ۪.,;|`N _)ex/ `G|Bz.]#̠Q<1Pӥ"" ) CKy;hW.t0@0e>ƈz((ϟI~h/Â(X[Lz6Itr} hd;Ђl _@G!ʕ1j湟G;~" 9vC]bGS0zTSjՃ #S@S #Dm1I$APE1;e@ @e(CObQwxeQ4jz<4.jra?Ƕ:4oA͍ Aaij;\ߎh8L' JM =F\!/Y&hj=N\D4"%UlaAe]^;۷G:n^x#~o]}s_0/]"U_'mr`=E!z!߹UB~(AWx2!#vd:շ~YUdNx^0W] zߚ{Oˆ6z_;7gk3.M]Mw9?Cԧ%3`O -ך %cHǙtIj(kjXŞVpEdkC- |r*;rrx-Ѧq_:s3FCZT7sD[>dzn"{;^=jZ<ўuu/?)SeQWQS(UG elb+( A@h *B$[  bjP| dopJ 3Ob +9|iFe 2 z 0Ă]MH ,*Ȣ9hw;D%cV`.n HEwnu鄐j9]7HAo!{vA3e-\*{ݎ'0Y3c n΁ ѤlA3tSHZρɣ?'՞*\BIS.dQDWD&JzQ !"EM@4*WAEGw7hZncX+6Ŕ?yz" c꠨ q"(@WFO|dRɮjVZ׈ Ɇ /݀{B ゘Bs(k䶞?.} σ4\-->N2Q<@@Q /*Q2h*,.ԱD8eP*( aWl߂s+cycdpqH-<(ΐ]GY~"!&^)y.Dm`Xֹl-Ư)u ɿk5q vɥjK_&:f&gÀ3](P_fO$@>֙RxxZ%i?*e,_uEϼvINݪ\srZ Z8`BEfm]6Boa y.gV9U`ybSEԙngM[!$UvvA IM9)#Hsf0k v ;JV 2> NR2*Scך9.Xu6o6)5=X\`iI[Nlw(aDSd<G1X%ߒjd) Vb#Rҍܷ5T o(0y@7Wޑ4yX-a;{ś E{djx2,1@A :L DWXL? J7NZVE#m"s7xG4७m0rfXB:@7j% %T#PUt,٠IA]DbGTw/yDesA1%LLmbбG)RYbk 35U)'G].Zt*nI"1#cdbPˁEoި8ˉvI-4;rI ]8e}k\@ęVaVJ2zBqjS:חa)eP6CrTk+?;_/B3^ahDN3? [9)@Rٱ}A,4zVSڹjmN(Yoq$c5 &wtWJZ3&DLe#}6tu(  c,QJD,p |Njb`;ֳ9;دg f"s'y"HA|8>[l%FF Kf>=0vMQ 2{g.ES ǩs [6a\1CC͊ZG]R#mnn#Uۼc.]@ِ݊SEMJ4c )2_u7-)7/-,:W O{QK0lފo6}m8Vi=^6w4b`n#h@Q-8XLnme =~ԼC&.*BPw#ENU;ZzmM1'޷⏤ _,OT3? A8?vن犦GĢĴa)_ ~^->scJA㇛U D^ʼ aڤF% C[^Ex`c\ 7~ېwnrtچQV/EF],jăT! `mýKj?ưR4["ubzcVpqS }Ffa\Ǧ+Zyjvtb{8Tnj5p 7dWW6ߤ\c[~ezՙ Y_ L}ԋq/CF@~cb2aR.ڻ\[ .\Acfw]=)FI ]K2TSyS&1ؠBSYۉOʷ.cIdO5G1B{eQ\~'}ă[\h46O zD4YBA3CVdM 3zj#]REʣuw~d5{=s!o~-^EbEJs=yΦ[dƢ #&2G Į^UXTh'FN"R4[`vHŪ&L?{!Rڔ" ͖ŢZga#` 8HOzc![u^bζ;[%7iZa ˍXqġQ;ҪVE#.QQ)$¾;\яLqkۆU@FjG,)rM]ADo|z!' `u4l}뷔ٳzVQ>wh$NW)F7+CIbvcRX2B8qIlڤ ,/& OƂwY@0HaaWF6RJE)=!G0o5*,/Kx {449vY"(3!R£Q "X% x=FnSaΤ=Oэܱ>X_4u];*ZzМ }I >dp#^0å 0_/#>Wg8 ޾!ՊE[&4N)ceom raMO|>dN qiWyO"rezbcHoˑ#iIhD>GbO?O+~ih\Ӷr&16g0B>sР_4҂YF g-qNù$.^{ӿ6q3Nʶ@IYj?,$JGDZQpJ"D< FĦY0+յ ͔&[OF[E&)w°\6H?qBsɾ֭G'u#&|@K9FRH}wb&2.OR2nmDa?}FYNފ_g7LlN˧] Jȓp4swToN` Z1P^880;?We:ͼV-gS嘫{ዶ1m53#f221Ƈ<6" s)|{[Ĺ2dkZebx\ZUx||2LQ:~lhMF[6~.ւ~j؋ ; jj=w;@m51 @YGВl尯ZWGe(n^09p,M::j>6>&mS|J5۝~!psj/s v{29B闋%Ae,p0z AIuhdP[$ (q]'fptf=w"\_(lEۖz%>\ގwv sA\ {|Ё0mo3 y,ɺ[0Zͼb4\YMDH{P<8R^~(1Z<"]X 'mjW UjLm,=O9Ͻ;] zv`k?r*>;s9LBɋ[lcX,O-vjuO4~V8a8n tk.VHYk|},?W2J[ͯQ6ܾL/$<3Du棔@1Y(r J˒klS2TW»vDbJ?K!p(8Oy3lUPgDLJ}{3F)G - O,rCe`jcdOdUۨ֙c+#솭rGe _RЀ l}2#39Q5u݇.}XGB;v\(OtѾ<>JjNBĿO[r"n՝ǻ%?e^HThZ0ކMfEtG3~wduK{k>E׏>?5r+M~l֠+MD_,+ՂR%K ;}q`⵳->! (PjP_bΐ]l?b=3n6W޷dCp<ە#p(ꀺ%{q!빚0Gj$A#^8E9|C̿9Z_[9L0.zT qQksqE鐟 =58#!feK%Mg6ΠxWTM~@׻0cMu%^3(wzh؀ʟ&vk7slf; ^9Pڭ@yp`AT0dSvдx5 8E`!&n65xoVs=7(bGkfk1?5(&Gx^(>Fы! eF9Z)MyĦ+ }]d9xoU4aWqF*R FZ`,N{4BF@"SzIh_393"PMTqKmugk(~Q䶑G#O6ﵱ0~{!ԣ,QDt%: r+  evҟnXk9Mi 8&w(=$beƺ ~ۋs&JorO;a?AJ߯k%O3n c ] A CV7xVm -GZ%cDȫnedbK]v }cd3M9a;WTB'ZGmLν: !(p:Zöܯ-Vm> xF\/5.=om X5\GH9 ‘Ff,Ўx Հ.rdƬ!Ø5zRu%-[ % fOq['${@C1mVAG؀5zȻɗM!Qb$F5&e= Z^x\- z0uGօDJ [ Ep-}ƈ ܛcGGvfl3ZzGT:kRO5V@r2:iW4IFLS>U.>5Q+r~lw:~*H+Hќe$chBeKdzΈ$׊Ȏ2*w4ۤ@% WNߟd8_WhX\>@=fek†>͜a!1'p!Dk7~;Mg'T%,d)\j+OoBUZڽ٢ -3Rҹfёo }^69fqaBJFeHø^\˗Gx0-F[@iϲ~a 0sx} $> RJrnRˢEV麊taxద7,QD3k`׵!:JZiq8x'eHYܕE_J} xʧIcѸH'ZJS3 B^r:d'vu 6h`pJD& ):R'˸MRIE5-;A W\hSg1iA] 0+Bv*e_4Q;YTZ.83MېD$LM aaɟ;}@(wIj2 r71 Z=:&!Vj5Ga5qsq*"5d}s_N?JD>{G&nFeǍ+ǀGAe)]a}dM땔1VуO2ٝ;+|aC=8~j ACzofA(?F8p$ĚQ3˻9h?*z͇8oDD>6~=x,tb$y‰ +꫉;flE/>G #y㞕ĉiw6.)2H=qӖ.TI{d׾TSiF:j$LĞ .5 9abOT%=Y@eQJl(γj ,(ӽe[(*?Q|^kV];m zS~JuGI)@fN-ZR`c:X@J^$z$Va;TPXTFO |xB-qedƎ-_?I^U!SSG+xdH8c-E/d3E'ߝhj[Dh 펱@OKVtڽU.jxxEz ۡ, ҭbdT|-ERP#~L+lp/+La]q QJGDg|Ѕ~A?_l||~E2G:2J(c"EYhH ê =L1|]۾)#/˭8fʃ ^Dm4wc{[hNWPJA]tC8G*O7\A-\{ I ?\! i-%X\P&@1idL 2^nŹS3AC #ۼBψFٳ9`BWU{J-e!'[.;O.OSwiİaN1w ۠zI|>ݣy`ƛqn߉KrkI~2 j6܋YnONk""\N*BeHd;{K[mUҸ 6X6s7wJ @׿+,PP5:${ 4|~d.ۍ~oi:3r3ۄ y,2gjg?g{A20< ^{hxFV x:oãp"5a'P{xae&0ЗWO`MCx7BwˬaRj|bW| U zXLqIN2ŕ]p} gCA[0r-P#+!ϑkԶ7GRZX6I5d|̚1~?i_''ys9K7%Uٚ9kus<H/>Ks. HUVH|J[jD=W+ ҈4,-k?N읤oxt& 9 743'\rVj PM{r߂oHF4OQς+nlaK}+qx0tYuFnWDd%rL?㙈 zҠ9Tzp\[ eu8le/n+IFR!o?7W#E>PTCvXKJ=3µ&T+ʡY8qΣZ †kT $'u\`!>F6%/ eJ)d#PtHqmet0;z k)&c5`S38CS[Ld G+έZz:zLMF'gibI]>7}-#:+y?I2 H~6n$2w,fQ rYq&T ]rB6!B;P`},VfUFnXY릑A[g0;$"9ѱM&7T sX7U6o l54nZX`wKDR}."(`Ji')k` d.@Żng,Z,Njy{hk?wd<(9*^x]*p{lUg aXv)kwּ, '( /%=BΡր{3 R"P bo HT(rRoh'&;\tX&>&bP ccf̏h#LTm>D|gY$G% O3kRޟK4~S28,Xcޑ&#:~4zŶ!T<Aފ{J?"BC~wQ!*Yi0vw}t 䁭|ֻ22EaÈ+cF6;7ܯhW҇9h̿͘:}USoGT拜q. z)G9DTیy;&Tpƭf|B_0St5c&:e~$=c;i*N Cm/\8 f%ZJz2QGUFq̖zٸT& ,/kyUhVE)\Te>=]5 !Ď|csx~n6⁖ss.P@ ބ;jg?{͖ѤxsC>bvFU^k{$sFgipkXנ{E,i# ۹#jJ~Z:8 RLhs[0x {Oi [ӱsun;]RzUT0 :܇L7]o WG&|M- ]`amF! crNLos{ܻ'n TM1{NmowȒ @ koJiJ9%$qICiC[Tэm:C܍"q R.Uh0MA`mL_ONc?T ґ9$0lҜhɥslB[yLI?ҟN Ή(1~${|j:- <8':\n}Ozh<+C({,Uw kK -=Bj~ɣ*"U~E2ZB"V<zy7rb.%$ߚ+YIa LXƘߚ t[Sέ2ue,`U$%KC8ԳUH/iGJAA=r{yIi_)LșGxt`gFL7( a;V U;kcg{lJ1 qbFɥA1FƻRh%TsiM9u4IJ%W U9YN7Uޭ:jͥuJ'* VX F`@G/úxb𐒩iTD('Qlyx.6[u{;܉Oϭʘ͓;38?/2଄>~`3oUQEcy&wRFqiE.O =T[U}K'*b^L}G>o2& U3=X8 -\7zG,D#Q9-٨ސ|T, y-6XWV\{mSp' N7HHӕ Ҷsm1(da#>7yu\ '-t>r?]R̪ xTաrՆ©ަ*ð4d '$'8j(U*dGd>W*lŢNAPM*҅"l&J"UtmcleXh{7SbSI2@j7A e<W7KUBf33CѠ+DC%FVй܍:~:'K]T.2˃kN6`Vk+ N#jg䚒ixQ ?,Ջ##1)TC*zr/>L@2}ja_dn_Qr͵SxdPxbA8*u7?+Nxfc.!@n@pԿVsuZ "bU9P~=EH*tK)j~\71+!r5#(6\ۛr8oJT.A( U)o%o/~RRѼ?A'F9(у'SqAO\dOЅ7H{M,s:={ i< q9CD WYF| B &%e+4/+)yqk@({qJHa?l \K"" ߞjEVTqE巿g.Wj|ۼS\paϠSMhgܑr NQ76rstHw^0s{0h􇆱,+p͕ JCT&V藌'F_ͪEw'.U^SVbt mv6*cW4@Bd%h%lҘyTsHumI1DvYv%/M,9{c4r^d)@, nxctc#Ld2gK(B(=쬶|sՁaGěp>>ÅSI>j}Sny f]34)΋>PDҽTc$3O4M󭢜o; iR+Ԧ +T TJ0LвZZŜ)u= :/j\,eÉʀ L6Ӊ,0CuGmVkӬ .)@frޤGFmJ x=L?,(f;Y~pK4k'q6mvSm.if3lUb  b*c_)ЙL:=- '!]c5HW:L'tg{JFQ4坄`,nXy?'"xD#1@|LEsEU<y>,o~:,Ko<*ĕȘ*`O;_ 9VrOPFݻB'xQݩ|%"èm.}?kv> a&-| vӏCB'GuGQdnHY:z8v@n(M>r(d~;?&+x;xׁO6zPsznC_$76w\l|V;;&۴x'Ƌ# tWk<<𞂮_Kir4B>U.elDIxNF(~">؍wϪÕ}^L㱊BH,ӡAE(3K(lǵR9 wx nXR/&HQ[L^L=Q=p맘߫guϴ)cLiGFgW$9̜JV;NZPrV;/^gE?XTU]hbfw,:s^*1z]e طA4)(/gT:I3bMB0NIgJZ)}R[z.jS“r\em&P9X?8Mr',ЇJv3I>AP)flQ.*4~ݖnۘp1D y4,.)[E3ww- evo< %ݕ$OV޽0Y^7,v~D/og} 9u5R: Q8P.? 2d(yFMtX uEe-|VJ !r tw:!L$ A |f/ȒtYEϹC# q G=?سuP˳X&'^bS1!|Q!"{LP򝅉,"ʕ.C?:LP`hս(G = C]󫭼KC{<*U\7D!K\9 ٬0Ah}\!~샴Z Oe0yi^7bê% (5*;O ZI=keg>Ƕ.7 FU01S9:`'YWԞa6cq0~W<&0%m`JCZGӎ3 mL2= )܅,z3 =D QYZ1x&oO/ӸKOˈ!~JRqREY:&P3!t+]y@PoJh1doW;p{9g鋦!O,җNs2f^Up?*n[:`m2o|38#[jʬx K=sp?ӳQ$T3cK=7eQtڹNɰ(86"A'΄ᾁ/Y;Bwgb2 ,;#0~}& I=vҥKS#!tӉRr7d;_IPNGO>9DR[ר1OZ-/iFؚեt|'e8Z5{QLtm!V`GVW WB#e}&CV$aMGh9GS b&@ì= dԊ<!z|uc":,P_RI SeriW+҇'C{3K?Y7†Nlj iPƻ!>y RGUIEyۏa6ÙAWRxbv{ym5\sI O`ÅADȈm5T4yiPn0DݘrCOےQ,ԯQ,e 5x9,çzB+jA `svzt}d-}>0|;lC~1KSt>ltzeuy֫m"krc,BvEH#԰]v\|yd,h+$8ŏCz}c]t8Padg\\Y.C{`4A-s@>ue=q@SU͎C^eGUzM|B[h :a.oĴj/~߂ I MW"<򻸡6*%]/.uQ]#շx#9~xפBdik^eVVc8ɔ˼ml53ڎc!abKQ5;eBl+`GK#.a֫ h'PvKGRo+xO-;1uBt>}\"gCī_?BSU"֯ƪkF<2€qq"׌1`|L7DSzg+ΜIK$\t-(XBJ۫!D ]FR[z~}VfS֤gzJ% [Jp98 &p3ye(a&@:G3/컕UӒ}d4,>Za\`/WHeNx @E"vifz{ds#})#ӨE` Cֈ;5 M3k̕,}Y]8,nexK^\":x L#^ 1W8`[k:'MJf "Pdd5 0E$%CFnu9AjVAl6q$%ܐwsqވYRbqv0SN$AC˗8&X [kRdo nM 27NPZ^܇~+kԈҟ%p,!{QֲKfB먿؛ęWy* sJЌab_ QT!#'oBQ~5HqG^+Lj3GmE8rk5;IC\::HP&p U䡈W8Uuaޠcmr_gL3Q?Z1;zl9sbu 4+aM5Jg=Mg 7ɤoχ Q M{󲎁/a(gMAlar/3W:zj|]ԬU/mCX=+{c q韰GONsNKdpjp-aYּ8nQJ9PJQFzn5ۃ`D8%ғeI1̲qj@LC1M>~P]0%#=!Hij瀌|H6?-HK?ZPl†QFiؼ.0NV9V4H$;m51I#X5͂kd$Ϧ YSZȭ%]+Ɔ!KOd>&3z<`#_vdkjlVLCGqg{p骳&Vc J=ycL`tPP߮T}xtC9Wnk^/`26z%=D̓Ωoh@Ԡ k5sLX*gSZn{z%KbeBz.QMU`iR3bףnR2ݿv1@y4@I;mal'ao.О{$zH0e|,-}WÅB'}נ3'a1*C?c@jx4w٘_dk8> &ƙ0[VUNgY./]J4ߣj0AGujb<kTP:dB[k:DI rΕ4`jW0@ (DPwL*Y x~\'cdKRk!x{ h>_2.'#D?hz'+;.K<"DN Ͳ/\;@jWrvZb@iAw#6{en(3B/& .87T9F4 ({obogh%)Ծ]H*,2 Mz1G7+il.Oed˜d73CMcWHCk94eF]+!m$`'NDHx [\鸩 U3A <3%@ |n-8(:Stc@EcS4o3R|y]z@츸x:vXh+TS\rniiifC{LOymڌ`5Sꧾ~v;yhlC1y.?Vs^]0oX4g1XJ%*!*b5s˜#Sa&-\a_h++F{K' Sf*x6(pQc*;x iƯt1/{{)Mv]9:|iT\A  K~ppUO@p76M n^f_V c,ρDr0tai@LB'YQĊ v>kC"6}x%Du,!=u 1/~#_pDJ2?E2n8~'a$k?+-.A6-$|gq`fLNh2c֍+2 ,w >#"60Рw|F+m~  ԩGFI W4F:L. t*L!Fh⼰esTx] ۯ0'!i!7 ߙ@#j‡). S[WӘ?TL tǮlBylp4װTT o-8 G/dw]I* P'6b0L/qB ߅Y:~߶5`>\Ql6.?|t-MQuxZpK!cʅ 6깴bvpš]Y VPLw!p)߈*|<]PHK+f+Ʃn"x&(z#$+JkNi&q5jx~*7STN3`*m?^NnL˦HK^\O45πńÅ!?~*Fs?0В]ySώkfεcլ bLXgh4=?k,c4BxiQJ@99!]m~gծ8"At~ ""~6s# ~_ 0[={Flď=tىպpn\ҽ~.\<%48 דqnGCNtƼ V%b#)9e{9(yU?s=g3Y8+FCsK 9k֮A"!{ hsղm,)kKڧ辿rhvgTbp>=4W0/⤼*HΛ)d ܧ"Cyce0NJc@D%Ro1́H7Մ VpeLЁo]!F3j DC1>Cc+]9a_rBH#g,8{j!'#%U:Xd / :K UwQ|[b&}(դ@ O_\GB\ \nw_/ ƪzAfW"OYbc77;yIEـ~M!炸Pߟl]}4?Pƺv$}47KSpJguuXZHwfHF=$ ?;þj4NCp9KjFD Bije1[6[Lz7w4w]\eWh_ D/SO_wk53wDS>A"I1ˆJ#'͟4(m%j܈^sdQN]7v ჏@nSJ Ԝe~%5W/Xv//FOR=~k{ck &HxS7,QL 6~,G ognp$Fheu|BjR[@+Ⱥ'FTϋ窌@{9U*Ԟ[>Io: STAxٺꞞh8oĴo jO&k+ܧȰ_˿8!a\"Ml*~R Q_[O##'FЇM5[rH/+H7DyX.rf~6`?VƖK#e,2mG|5L@֎Kbbׄez)~3'!4WD79_ %k|Mk+g%'݁M xHW%戨&M ݟ"E0NA^+q49b?"u PaPj7.EvzN8 NYۧGˮΈbn֓r".XsOIV~5ÿOYϷDf[ KAz۴GS+hH#n.)򋔯ȉi9#h(nI(QI,iqyMU#g$" 93+-UNmFLnGKrDK=#y/G M^KBbo_n(#1 Qh/E }L>(;KpaPwOdo^E``=~RpՍ8Q1TUWwH"^zGC^+6\FMF:56;rbOJ{v5R!.NmRUj}6r4o݀_5mK|q}=fsO ʍ9()GyXb.Sڤ\%e5j VȇKگ8<`V%ss[z R2|YL0Z ~7REP#(!ahY}M#gÏf;=Mkeq#.u;#LLWUܵXuVMm)!ISnKBxM3Zv9Ǫ̧Vviro=LEqe'd 1$,'Tp?3]WU;z۟&$l:/VI!6VXe]pdWn Fa ވd4-&yepB +@tR{Y~1F t5 l>ʺo" h. Ɲ[mbn&Tm&L` 0 ͷǼiN1엶6,Fy2UHMDXW._y7H +.YP8iXX (OKEdׇ3p-1A]Y56.:. #ra(Rzݼڢ;K"Lu*؃Qݳ-MMaL;H| iX7R$9"+&qb)Jျttf^'`ȡ2=O}PK/v 5?FԾ{lv'='7!YbXK&W->ᓏψWW"3̈߀L/ BIjSPQL#^3I=7HbG/ ;}s/mn/i0ŔB¡$^WKQAj߮g90d|>A6>4Guw췃?x tjl2a¸ %}/ٰh ,D&>@9\V  L{9Lr|PuxD9(= ZiRzv#.HMxybJE[<;_P[7Xf{"TLP`h߯Z&6&6sR_؀(lcwe^|uo H zpw!T5 $]8{HC68fUܘu&2 }bhwCVO( 7$5Ws@MH[B~aU3M-.(-7SDX|:Բ -iޝgDDTX:jӡ70D%eO;\3!sۥHp+ano{SsKnQ\dJk{^ɯKD/@; ډE3IG^AsϷdcebՑPtuyfI^r`Bڪ$XZSB _|s-)jd7{+f5\i 1]g8mw^[$o5f atHS2qtbz|C Y~=J/g;>F$rpn4M Jse(XY$gDzJx;lm?žZnG^Bh*u.4$YZdP͢o|:PL YW bܳ!BMwT1Fg 9LmaQp/3.X'?wV}wHpD־dQMƤhF#!"ʱ5(=L L}$kMmOǑF]Elhl]ZWoQ u"=:Zh̨0v2ӿmBj(Cd=q(j,*pEuH(!(88#:_2]=`8$@kv;.NO“2n5[ykMΪ{Gv6c*-@&&lNR>~e ό%-?pfُS{;]*5FR8m΍c!u[d88"6ދ۾S)8^kLa$O3r"FXAmn*h| 7:TPŜ.9d(ƸvA@ĀqyTa'Qy;:-T#ˆ0XDFm@-eӀŠ'IʚL AI~AL>_9Ӟw)/4=+)殥Ih #TMXBȂӕE4oc.w;YLQΜauLkül g'd{k*e(W*s{Aۤ(Wu(#2FHA`X]`G}=B63Q_ 본ϓB\>,dj^1 P'j:%[TzXTGˌ!,0S`#5ƪtC {:]cvoxBI5lhꘚhdvhH(g2ND@F}7hp aVqeJ҅QZr;P]Y3| ΀'vxߦNUAAte|7 IɅؿ f2f4R&/ںx :+[ƈNtI*BVaUIw3U_zF3ճ]:Z5?{elxfOJz3cdiZJչ, Z+ F 'sw8J4xR؏֙R v4%%+2^N 2v<Ǽ ֨,jMΓRUuX,̧ _faaU.lqίI2S6؉ŠG)'QU%UG\iqN \pKO42* A 3^(ۓ`GL((Hbn1X#]VV\!*AvG,#J׾ kүŃGAe(iY%G 3ȷ"1n8*3FnLx) @$(JŢ it״Vu],'<Њ:qA;Y Լ#Y4D9Cu!g47Y{t*FT {Nb_H~pJ:84tVPr2 ŋ' U/B{Ϝ@y;8~TڰE+.C567s6y|ۯlWp֧e= qX z 3eŸ|Q/B!NDLXyUumv^ՏP=y7%1]ʰE,ity[R/W!Ł C*9imGbBO W-D\dDapݪ$!ΐOA:ж.u>Թ>őyXx)ʌI+Kxْ~04sXwBFuO^}b)ꀫ2<&VQJU5 T$t').v27<72`A5F j *dD_{7r{[wI.OZd"i>8e~G_?LбK=,D8191ս׿Fva99T:jݼ;+.Gh5p8 +j_b P9u ̤9~.0Ud:}z#%" EB^b'w=d0+ajأ!0&/ QXz =z2Aұ88(6̙Lr 4GU%qْ!dn4w4P[l,P/>r;+=Kq.92\P7~ȄD~ Nat%l {C2۽vBg6"Ǖ"09Pk= 3jӆnKG|Ѕ4"v 2Gēmh'Ԥ:~; vfޕ#9"-eg`xY4~2TM1Ȋ 2:v]} 3<8G:XxD.0lf4~tպ3os'X5=4{~{ܠ˂dE颅d9]0 w X3͉+x, JTJj{CwFUoV!ߩp0v$Ӡ.JGK8^dէ<|6iD(=ͼIH־O_bf(]/h ?r7ZAoLNK'ۊ& (PgW(X~v8\CNπ}G&d˥lO>/ś^ǧ1{<YCტbeA|ïˡk@ܐ4퐽%Q@d*Cˇ?xp֞4.]?ֈ^smWO e;6Mҹ˨oZ?7xʶ@GZ[4=j'3xЩ7qt3.mq1 ZRBǨd&[\ Bch77ω Cgl:wHJA|U94/h޾l/'fdxO5^. Iln4ٲ^}B[dOG 02%}9w:U{p/kЫtA W6cMG衵y >ݩvJ;?A fv# ב.Gڰ JdmܻGK>H8~S"ZnH:f, G b߼Bַb5a9䝊Q[H*2-0E?GIR(|MOY&3EDxK&vnO5 (2׾/z]8聇io/_ТXsDd(A6g~ȷ. $ˀ1I0.vXVGl^Gt b`?A*h/XHU%~B/R'^}=(3nG?^-4# h- xaG7: wZG p.5wgW뎐W׽;)ץ\-f}콊#SUDЏ1o.1H̪|g67ۄhID'og0s4[xm\F$ *©{=Fet#%ľ"(Ir&f|\g'3t8TWsԴԡϖMzOխuQ@wC~~Vs&3ED^V9n9Q7%ФJUġ[mN2ͥPI'R["kx|f'4n) ts/aAڠlXQ'|3.(h T[ȨT"dBR I?2NzZ[~8.@ Ps{` 0z0NbNOWG@f00K)ڱ{w1! QL4u?x_E65v:"/5.ϴB Q.RwʒV !BM$7Exmcks KɰK< *a4~i㡯/<*pyerTg0*~9Upݲi KZgޱ}>N#O?CI! &Xè:2 <_Lv!ĘLb` K$Ы5z[ŵi\#lx؍k8qƓA(d̃[CI-K߮q!-ّئ{Y\Ձ Qj*BCu<3Nz7.쀞VvE.PD[y G#7FFJ!. +I{T9Q'#(Az '+#XZfvf+]kV_,?f 5ϓ5@!7`RdT|ܚtlŬҶ)^T5 AWޠQ$ yU W~XP[:KwfyMVCe{J6;Cˏ7>v>! :?%ZucOl x^Tm?Ҵ鶞)u B9<8^3`QVV(ɒٖj3) 5Vyr~0Ƙ ^;C8WϢ^WHhhq,טt2OF1~5xE*Xo<ʳUˬp8wwjLK'{r6Dʛx)z!n74d Yl`XƚxTgVD1Rx˝F\NbAƌfH3B- NDrb"+6TO%7wxY>m]As1EPhէ@RX>Dn[%:"?J6G4 ?{tLw _S) ,]OhG[C5<%-|#EJB H7a0Bs+ d+ [4c4z,)b;Ud&+rUD `deh{zcY0zQ̓=lZ?&F #4 m#tьQdPfd#߰ikԦ`uuDְ}#5CWja{v=2ַrdlJJPʢbhij`TmwT]!e] #u2ZD( H8ޯ>[mz:ZWaHDQ|qDtQġpWJ.~޼k }sVBBPנW>(lEʗ>$\xH5xC[݀pnɚ  oJ%^9RvwjL  ] $nqF#)B.K7YIʗ;H{ UdF >Z|H *V#'l,hܥ7,nt ĹCf?|%I-1ThOIG }p!BHމ$Rr&viO19^4~+䦒Goc)/f*Ot?{c5chz)%9dj_E+z`ştPN5i8 zݔ+ϋZ?p6R*S5gs\ =A0 7!S5nv ?I}×)0^bO3)m0rcŇ㾧gEMzL'SBװtAk5}"tCL58wزmytcP8!w[gh16>ocy?h:i͑54[P;M'=YySiଉ>06ίkƯeuj6.wJںHFMlkא{Md*3 ҹ 6mŹ5 " YlM(;&$[?aDΤw+6B`T{w6 :Jh(f;` n{7nzْxcڊ)Eڪz8-J --k:Ed2ٺjv[#uZA?w{!GjeTsp4$'[_HPhD)]B8j1TuEZ 3p~8 ;` d^=đZJSHۑՓ٫D\Jqler}G&5Kq7 5s-*gD*l[uAWl{w K\hc o Fw;C=F8ST-G;fZ]X =K,s I|#rd:G_fXF0?.֕GILQgrmGR~@իg+g'(;G%')3KrQPGo<LbgHN}@P;wr+Zc R/"[C_;uaQ6:&l2=H! `fg&5*ѺviDз.a9/"p[=-F]!#O)[C`b b׏^ q=e$*@cl4>S8Y/69h Ɂ?G:ޛ15d4I0vF-Ӹ{_L6ӧ1ź||&Gvƽ+V5 &.|`81+-ws\ ~W bs$R@_հ"MDSxӮ:zhD9^M-Jpr[Չ%1eYz9๏C0o| /BAEn6]S):߇gZ3(2") `UfkGԻAFE({ /iAYy4N. "鿧#-C)-j(j X;a9^wq$3q.N䏸UB9(Kz=&D춊!Մk2~,}OG~q48W \{5ڜdNp[H!e.[Zb aYRa"7lMX e '`MsAaqF"buh 2tdI͟,i|WVtbAWOB&ЖElj{i;X'u]v;*)M6CWx'A? Tz^/55xL<%7;8 Í>b5W{;[ue 0SB<򫐉 Kk1b(qI0dA+𩘰C~OƧ>*l:?y$mBsߘܺPV[TKl "(;$^g˟jl3}YBHP]x+A6RL͜ـ6{L'aX4&Q CS/aibل\ {ͬ֒y} W0D>fG 8[ =Ŕ$ѐ1``n^K=?LMR=f^O!׳7 yɍr'M݂ՅIq_2a '{2x %0Zbxzf">}b9Xhl8O CYBٍkG^'jkJ??v~+Z_P ö́)F? GQ^D lX0w7$KcR}9.SD)j}|,?G)btbgmh;HP ٝ#(R66;#Z[Dީݷ}e2=LintD2< Kn# Rdg9{28ok\C{%CyLyLt6i^Y\c$XШ+.j`X6J!^z ړq?WA)0y"$ hoPo/N._ L( u¬M$n6=Z7) =2YZ^g*N6bmH /dQK ?= xU=F6aB~0BDuӨaM.])- }.T"c3\׊Ȕ <9 ţivc冃7ٜMJt{FZM=$(tߎf<N^7I; ΂$_ޕrPO>{I p &T?*@`3+#}R7i,UAJ 7)/{?eEi!L5=!sTre x#g2mLll4aݓC ;1W ZC&>[跺8wK=rZbлQr'[‰Zq]UHe0,"V$h6#7 Ņ A"bw``I(/n6c" ֘.GSamm s%sꤪSAja&Iȟ |±d v>`\h- EC>,KcSE|.ꔃ#)%0K~0ͫxjЬlgF Oto;#2^qf/P :e{uDX.ꋜX'BH5!aY/\*B2&p]ǂ;[:!X`_]z#HY~Tܰ O f[o 5>S> vdBs<.j_-aOPVzƑӄj-ЩwN~ֈvO&7:% V4@,#zd_'1YbX5kh&:_P \i4jG[/^t) d 念`S{+ڟq/GfxOSܦ$6ڗ{\  mq ^1BlKW5)Wx|Մ_?J,Ʊ|龡re>:1Vy8=g4sMmt V Y?6D"g[ ,yZ*qlah}S vI.H]%ve\L wyyV*n?x&O)p pjZ0ըI9Fi"oXTz8JcRWЛ0 S0c9č""eakr2 $@81ɍ BCݜ7stɑZ]W䈖p@@"jR;4J9@Leк07J!l4<2HL"b>, $u'Cq)cHp6[ "(|Zvہl Sq [ە?odq Яb.+abzTJ(D_GB*82Je}E$/}t裱>9I=o]o.;7G.^1y$)D$Qΐm ,Z4i\Re!3IT>Ӈ5ckΦԸO gOc{f«l"is*e&0QwmT'$C;Q)"1"03],Air+'cOb#Sgu} 4Rlz3M"cmX,S/k=>4)CZZh@hosӈ-Ǡmw+Sabrj+c2**34眰6V&W )K3^VzMaƎ&}_:<m |ن ͐.fP3CḰKjKM5P贉B1XVtKy9"˚fZe+mB+|퇟px (/w';Cҵc/]0,"1pi[bR\tAo0!\NB1TXJd"Ä;z;a:7gdHҙ캛 27@ gfh ׬ kҖ*wcrJcKSwv /ϝ\g|t҃30g^]w3X{B5>dΩ$!UL/"-W@Â;oH$xhpR׽pU65ژX^YREkQwנM"eR}P m-[ݞpLMQG3+y*K3%VTAݦH "aQgЀ-iQkCt!0V| nVEeӰ9H-VhR (A-L5O3-m#\m_݅*/~07G"~U=o mX^QJm0ENg*[sFg<3KoX`D"];|Ҕh 2vQ:TV\͸w(=N *0t~e6e^uD*F]-ܕ}eb߃LWQJ6t5y3@\A;&PH:j3D~zy zVGV@^6܆[VZH|}tE+.i`IYߐ[b]=\T" fY(Qr9a;v7{@<;5vޣ >:3MFQH 7 H( GK'W%#N`ny l$H N+}H4AnwJwM\"q~Y5t}P|OmP]0=Wr2?ȅsOQ/\mcFaqE顢})u.N(vdx0-b_1`da3v/9wN|Yͺ,.'Ugxp/_)DI'3=0SQs`[zjGN 8>9a:hՋ%3b9|2;P{qsQtMqFu'|.ǢV0gqYُjn4"qկUDN#}`2<|\VaM%GqXIkP8Y[6nv{ TQfv-҂UO"|Zٗ8Ť[1rob@ l&L@եTͥ!:5_{)| ^\`Jv Ǹ<ьD3hIE/fKrLq5c>ߺ5ȗ?YvO-@ک6AAJ~EmVqOf%D#K|WT KvPQd6C5ݐ\QzFh;eYn3yu(PO%قG#5nbCs4O'tm$RrUY.5K3;` ;:!TD@Oco򯚲aPPѨn5SQ<<'!;{J j|?QWd}0h±)b]b^pHQ .L&2iM2 XS:A+7ܒW `WHmzk!1SV egZwcK?ii'gɋXڮLa뻾bNrSà/j R#e 8+C@*3G* /@auf/;]ۑ HqL11woD+(!t фH$ȃ'~/%#[ס^NNxxIiy^zj{{͋pTO7gWҦM@ǜ;Az)s>m8& ?ǃHH;P7O}DC- F&nWޓ\/}4 ll*kCP/xҹwvܐ$\ ]‘C'ZR!ԊzųW?Z`^ai;9j ̔WUã($ x̖ M2>3#wT,5=!>,yy%0fRЯ.QV~NȁK'2YtF!%V_ @*TL]A[: k/=qBk.,(}E^^m*O9G-ڧIy'PөƖT!I5qoV5Ul=kHVͭkVW􍫭_xasdfāʘܰVRJv(i5`G!M?*8Uu6U'7C|=OhU\_zSs&EIi7A^KlGw`\O\ ͝Y`\É\]ǬP'?нd[; I c iD%y<;];_v<4;Xܶ7^eBd4cN1#W%G[1x~}Zs{j'٪_beOk.}(T;̅8_]N[(sޕܡE֌ODԤh,KMT2塅dae3=xӝ 8&YMř$όfM1ԤW?t^æE T<ް$Ĵ(8!7PhM(VvJ_R'lkX+|w.N2"uMqz.&qN757R=;l|b9LS, f*. yb6U(k oU=Ů黩$ߟ&«:QF%euHqJ!<Z>"GbW߶S2qibI0TUE/Wɮ-=3HXZ*0kߑI34Hu롖WmQL M~Θ~̦c*|suF]u@~SkXSV ._Mn - XB;:`tqm>jL<Ϫb0|*gtvj;׌B(q:t9LYX '5aX+x ɐ G{o;jX[Hu{$$G\t5xD#^!no EԾ Nړa{W3bsF>h2x=\UFkI ҋSv3҉,}e($.*E,,ke+XV$;I5U *m `l P;%MN n5Ǝ<^*aΉ2(+(j7Ts@O}7"CЧwK)Ъm`j8%`@uTB# ,<h"%5}űi8Y6 8nf(ty3(g!{8KP+jeb>7On)'*Ka/7?"2/ڵhfŬ+"BTntusE)>]QU:H-~ CܜG'dÒaAƂ~9 [!˖.0j%QM1HtS/ݒbٖ2_@!mco{ℹxOG9MPaVuYWί:AA< z,_@=~KQy;(&5#ұ_Ð|:'[}M^#q^ㄚ!кDucOTqpua-d 傲| /FW}^Ձ Hu!7^B5A볗V-3 ( eW#4Y-xOl|br *mVFUrQԏPFpR]=P3p.laZ Լd MYx M{." ݇cҿk>L`"wg_y|g"z&&W؁GBkCDJbո'#9^,i.Ǖwl%>P@OV_(Qqq?('y6& 5f7 r_@I$gwg9lE[EaDIn<\_H}-qB 68hԂNf^]{C Vz.22]c$~ 6FO6FʲIZA57A |'R 1dqDPZٞ%wQGoX¸+'5|ϋ-+1l լ2CҒ/bM=ssp,w/Ҹv$]Ʃ/EƮVnG0A?*$F /p2eĂvMNj7VHNഺa,̇X5h'H95VFCݮ ԦpJ Dm_hPpsDAeq!ԗQш&A_2_},Vj/u.#x 2~)7|z]/jpR|hLk=Lx-yŝMnL(j xf,87\Cӂ隌bΥd8ndLz ?^HtP1[N:$zSW rcZ@r;Y5gD"v ͐_l2ԓ]{Y.hy8*üIotQ<cx$^PeTs}a_I$\+5Iq/ކ^l1u!ZC~T^,S%w]=i2:Ϟo)l.+8=eNdВ‹ XY=r5l\բ{ќU~oIp\cR̰  2\U8FG mncv| {jN.Y 3ּMm+陏(N ~B] &Ȼ\NP~Ñ|穥Zb\ 3٭ijG%nZf,Yj}1qX]LAM&aNVq:4Rmޮ qݮ1V6fRl|Tdfz77Hb<$XցA;d]"Bߓ/@}'h900͸N0+V]ܭ\Q/FJhYfڌobi4Mٝji|7ɘ\o^}䙬A~vY}\./z Jա?'`{pEe-\M J/[D E ="d$/˓L7%vu ,G+nX.ǝӻkWQcݨkT B!|j))I9K~! 0`9Nb$Pz셭tA%tqQf-jw9ԓtYFVǏƍ j_LjUoyվ٥T[TJa$"yC#CE"(E@V&Gb|l{U W8CR+/dGyk>-F QyN+ue~[q+;ЦٵLa1yM[%C/oi7mg3IQ `;?FT*!n)wCߎB!@.)SթZ-)0Mh I۠>AVWj٢a̪jVrƹƄ(~띁P= }GBQ Q9qD4|74{u*u )686yfezqYp"f9%Iƒ-nh+3!y>;!ϲ)"o$~Ʉ=0VUp[>3$J ZS?zbGAc-f/mt-l  zŭ|1*oZ4Tӓ:5=O}>ezqX+5ffӷBjKsuFqPh%PZWsبpEsyYChBBH>D5BsׯaҨ<|>ᚿ ۨO &B҉8sd6;]G"jiao,%d_u ^o88t ꚺr'K4o4-pc#{&m: {#ܕl x^0;-b2w`^Taw7ϛs0`ZptH*~++h@:Rs?]|G<,Vt;K-J,چ}2u/Xe7wJ_,Dʜ !y$P+ .(Ê2Q>+&$mCğݣI<H;/٨j'.|vjyanObJp;?P2bOw$9wOm'EvܱYQqˢ8cxQW ug7YO أstGZDYyΒ4cދLsgБ9$k \%H A;mCK6̅By&[8nrSI)M#/))[UϪ%^7bU/%`sRp{^KE:qM6gCZ2 #3#NnC^*%%: ÖN:8zs5clbi_*&գo2TTԭtutM;nwj |;YHo_00kϜAB ~tIv$Va@F:\Qlg`5W[Դ~A&,x& {Pƽ(Gz|_rjX"֪t!JnLj,&- ]֛2툅,/kܘ$~xg4! O^w35N$BVX*vK4ūޚ見g n0縴i͌Nala^K&IDIXV8ub4m/8qG{.B!ʟd]/ױRQ1B-h6M:*]FCXjW\ ¶z en*) 8wv0OdbHM;\/.%0v|V4k1]Y?I(Ӗ޳$mݓx}Z3Җ |G4 .aYΞ!ْM7 Ǽ:ߢ d oͥ` ݐT_xjk! g&)(ɋDjR EIKC4S8pΙf7{Rd;9 m|ٖ1o&geHpx+]dKDQeosﮂrhbH!~8h[꾴ͽ_-CmYǀlT\{? B Xkt%ݞ,1j1%_tܹU!;sN[$XTS`{ 3ё>28#h0og~%ܻ· MV{njVmsU[4@>7l ~Ow?IuLgHF69W̛^v@ugC< (#D9qW iQZX=,'F ?(5=@B%Ri ;qAk&GԾv' P(Ԉ>0V6Gwy;.3ad*"}A/9u'm^.@YIFtDLhZxBRuPeopubo>fqڹ #F B03Pʝ˃a~ ?釛C==,9pQ H&ua>.{e#[yڱOy)] )]Tb؁B<05qN5CZR(@.= ŠV[o_>rĶFQe$=ʙo{v-q11_;x}i[K˯a8ʦGuڂL݋b.傑0-hLDN6%ɟkE2BKR۟/wSRpdAI_.,񌛿<Ȍ)BIw\5"ҘFvzZrh%tR3=%6_zwؚ E0'2{g>rQ}9cY<81kҖ?ǫg(p]9_rn"#7񕛭e l-⋚לsS6GE᜝Oa^t 1<d1%t(y }%v,9=I;)+PCwh[6vee̚Ador!;=1*fX]H9@e>#/j^2lkG37ߌkƔ]&42/'t0CZ DMRdW-E!d?Vw1q;8Y](Isk:%xQ JI> t'z<2 uWT,>a"4BJ`L~4_ѬWXQZ;wl#l(MWAgc?OYA[%G^^PsLJo۲Y!g~vO+rx|y0"kN'Ubs2?DG/wZ/TِpRiɝBhB '7eb?[sji>f2vmS 崑pEW4s!,<5\zx3Nhv; ݻ5xji0^?;>íΟ-4v7Һ;T?o),Gq"0J,ciRVyc32e L^ U4{T/c0ΉZvNϞ~iVw^w,~5+w)̸3<\*'zfiM՞$Cܳn *P;[XŮcPi"@[GB7j<0o = ØY'"68\!TE"^Es#s`~f׍І`aū~>*ٰɭ$%5 $嵧QZdFga'IRZQD 9)i8`Ҳ8hJ79lPDoU Ʋ; .ˌ@c.%amC*sttc_T3t (/G&iV(KyxɫqWBYƭh".B􍯣Fn  9Ԝady4=-;ΉgCew7K幱U R3l+RђȖ<ޒ6Bk3B =}m_c6q6"7x$E{ގBdt|k^˽yҞp 9dti*]=S^>2A ^? RoUB5kFu}\tqBf?V ey6[pgHOR\")-4r'S܋,?!rU?LRc.N~L(g˄1"[T=L!uV{c;Ġ?ekhA./ωNxPir9͕އߕߕ>'p*jI(GN%m5~׉oe>\ PQ>6M+D[bg3sN5o>sIE:~&}ZYo~{=jPhu5n*ZGE94MEq%:Ty-`KP*D`cPq-2CWMRC,TF<Ӂߺζ"Pizn-D8b8O9 d]l6\ j|43P} XJ ;\ac,N9LOsUHԂp *|TVߐ{iV`.f+E>㚍 b%xC l+ ^͟SӺgTLdPp$K*kWd?ݼgN}0x0`B4 o$fb?׻eMԮc!Y<o9TYVC^ 3Qqۑ(y9B{ pMh|l-:!~ `ͷEIO"e 6(4Vx~bŰ "4iZM&,Z=S^А6@xEPȠ?VL {} xrN&*~o4v ԥ,g5#k.kJ٧mMGfltGKeD@md/^In{oLHhE4%0\Og -$>.m7fMB&5;>`4y1sMiy7+d`^=w {5 6r+a t@D9I;) C[A`p/r{W:W܎. `zyDs+fw ?VTSjEϗ+]y>l^2Uˎ ._2sI`FS'}y5v)VơkaEO6M$ i4A=FF}s=ʿ w"8)ov4Ok;=ZRhD[1␝He8GR4F7Mc'Xf}u=<LM|qDbli(w.&wk.V,?vA@/Es@bz?mv@ZM I\SC%=T[J5}$;p-%`т[Ò*9K]TH3׃,dpmPu#ұSU#C(q&)m B G kh)/JHy8BȘpc'4r9Ɖ~gqؗc"HIBMO#}OSn'.=1w -yЕF{+2$ Œx  17 L/%ƵOcɃްʙ7Yd;uÊb% FuO, ' ~]rB|B{ ̞dH`䯫E%6fa{bBfȶLU=w&8Q^wkݦgE,6ƮL^j8GU@zs;CR`Y 6&'Ϩt7)Oqr0a}u[D$dǵiGZŨecm=Lk×~wJI)`ФQa],XQr.\j;Z%2_C^I"1o|}Jt%5(R"+ٝ5`kѱ xYxYf\+;dvQnܝ?=DEɦ:a*?u˧nF>Nkuu//t:}NsG6®W|(G 1I0v È Գ)uNAH[Zo! i-27dPr:Adar?h ݕBƤ]:Mwrv~,`@oq9yɳϯd#Q~0Ǹݡ`l?%ck,+>lͪ0bxMtXEZL͛ӟ4peѺ4t/37nZSQ J O2.GiϾnv4ȹiJ "5(~-0< W,uB3Pg szp3C߶asb R88qY»gH?dX}E~g֠W/+ Ж@ybݓl[dTjQtd`att r;N@pnX Qf2UgaNa-ۍ 7 'a?FyͥLk >9[> F0p]u*'`;B+K5ɒ?9ǽ3׮R˷uAȥͰt]lpd¢tzSQ:|Lb<4ИRT鬎}%΋ W+nU՟t4@qlMͺ:.\9E으8aږ#ZEA N0ČPc0%/Qћ1P` #z\r0a\D;\y1]oR5R$ڥP'SnUXu ~nh5%̘ն9#{s^\}m]X2_|?S DVeT +]ң팶үuT/+Fqa(62p8qsW<砈Oc mFn:/pl=X@W >\FɞۏTJ&h]HP:hYW2MwnSo6equ M?mz]d/M4A[)O oɹpkR鿹o嵴 >gh iNGM!L%C(3U?v*~6l J:h#A$+vPrCLJDE9>R" cѻIR;#g1\Y7 /)a^f`}?:Os ?N\Bg%bQnohAg/Nlv!I|#<VWҐ^ ,]Jyfl[O|7I]5:g/P==W {I݈K#+ۊ h먂iJV`E*wv/!HG9yW#dFu9!jy_7YoG{uCzZ|x5]`*.5,(giEQJ$2r5c 5+%j_]yq7Ft5Dk"d]y&(Xq+_+7| Ä#;wH*ijLHc_jgWrb]vX-@ E,p4h,yk )  5&]pbvI:݆w|5nl9Vb\\8xۣl}fEďw߈B؞?U| 0D3-PxV; =!cR`m :\ezƊS'NM| .Dr?3]!D~,Rݦ, tGvxԒXJBKll2N14e4~w#gaˏ'm@3EG (6j4xyc-dr,)ZWbiR`G8 A&ûjk7 [&h+53: RuGY)5vkcX[tq`uxCCҏ-1"T֯!v:Na,|B>;nm\0!GU%8#OkO㫂mNk']w&G%z2 2{D]w?GBX"JT;@G*,zPNQm+7*d, J)$ `wkeec$:xU[pk\qLCBgvedSG-&D.Ǹ7)WMd>jY#=(K$Z;x"rs-Rri}}A4]s+H N7; qLs%G DIcP{S_.Fڰ7 IZ^FSaCbᗇ' hUgie\"qflLdf%G7vz4f<n֊%rGc}Ot$;f^ a!R ZLA i{wzA;vWi( G3U]!gSĿւ=Ltz떭YbZ us ]FjĊ>kc txabty1p%rvSK#\nZa5 ~1VȂ