samba-client-libs-4.19.8+git.430.a10fe64854c-150600.3.18.2<>, (hvTp9|/4u[]TT>(ٯ9?ϝ@\( 7L(FQ#S@Y:ڟpO՗X@ SdE`~4hQU95Ϥ`D}?vӂ `482(=ta(C?>-eWG3Ƅ}zV)^Xf,`fOj^se1b=%m&H9F4VtK2x\Md5uXF NE0rAO(.:iܭwP,qn|j~,e!>7zJ>CX?Hd/ = T 9PV`v8v $v v v v !v#v&v(l(v*|`d(8$'9':a'>L@LBM FNEGN\vHP4vIR vXRYVZY[Z\\dv]^<v^hbhci\dieifiliuivvkdwvxvyt zDCsamba-client-libs4.19.8+git.430.a10fe64854c150600.3.18.2Samba client librariesThe samba-libs package contains the libraries needed by samba client programs.hvTh01-armsrv3yÐSUSE Linux Enterprise 15SUSE LLC GPL-3.0-or-laterhttps://www.suse.com/Development/Libraries/C and C++https://www.samba.org/linuxaarch64 :yx  P 8(H px #`8 !` h `AhvTJhvThvTKhvThvTJhvThvTJhvThvTJhvThvTJhvThvTJhvThvTKhvThvTJhvThvTJhvThvTJhvThvTJhvThvTJhvThvTJhvThvTKhvThvTJhvThvTKhvThvTJhvThvTJhvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvThvTbccab8af4806ca7125b7ffd20864ec9c64970dde6806e4d2bb8917ac2b97d292bbdf553896ca6cd4c4bf24488cde541bc7f59cb1f3313c717c077ec7cf61e950567246d117e7639d3296ed34dcea19edbca2bb4f8f8c9c9740aad2dbd42abc0ec67d0cf5c483f62afc54b4371f72ed784e3331cf46e8acc44fd5d20be5a7d0db9784a7434834a1c290b6fd502d45f1b045ee0043f9ba727bb9a418cf34d1870699b93fba81dd1dcdeb6a8ee6becbeb069524cbec51d107944f13a3750a0b03e0cadb2b54922b053cfb17a7bb18affffb2dd4bba9e489e422e59a98de0c1bec620467f09c5f7e4dacd0d8ac47b7435cf741f2bde09afb2101d77a20274f421174a340dde14d4a10cc357926a127f4e5a16b00a7cf97837b3f83c0b7c307f3028f7d0f15d6a16a0b9f8a4fbf4e62dcd815da5a11f0af03a8217f450f2ff39b6bee769035d1828048f226575dd6f7ad43093ee318cb795eea4366b55ccb2b2540765a71c107677349c793d96292de105256d0fc383f6070489c4a0a6652e13a7b41596431784a2e7da536954ba2da253ae657c76200c9b129bcfb6f5c9f4f88031d2095aed9bd3c4c7d9eba77cfbb1433d3f0ce4edac83d92013d65650276491f3aa759da38a9d2be9546631ce422b0bf998b4f1c72f5da022fe8877cc3282459143abfbe4911c9e460f909ac6f858abd4bed186013ef018c381a2587956afa69f448f1ce1103a478b3a1074e2e58afaca08d2a7d2c8630470df74a822750bd0bd68cded7da36dde44f726e8f1ae6035cea867fe78200541d7b40f32548aed7f1c0486d7ff94f1efb0933c7f6c7f477d65783cc974bb6029f8443422e4c48d2240969af12875d7e8dc2abf6395312fad05ff49cad1011e08682b83c2ff6f39bde41c37843f29f06b7390dfda379f5150ed1567fc3b2b69f8bdc1deb65df51ccdb15136946e050dbbaa0032177d9cd65bb1810e5c442bab26b871052456b13c737c15d2a41eff75af122c5f06b123f0fceae1e8942e947a627d773fee70caf3ebf2ec0ad0a3f3b3aaf1550ed6c90e0c1b855f2f85dd96220e845c5599f4c72f693ef550f400763a168083534b41dc273630f3fbfaca50843ba7db84eb24aa6976884e2064dbfa695e3447d25293b94d222a6d55181f4d3ebb6a48f66c9817c42c53d3cfd30ed61b737dd09e2e96d9cadd1066f49f1cd90d9b365723dbb0ac13e5702f023f188039834e550fcb9d4297583d9023e3fa672e1d524884a94519928f43e90245f71569fd500ee701f48965ca1b0e58a3e95229d9f4c75b14c0bb5d73708743e54a7ba2c99e47f67790dad0e0201249cbb6a9f9a5b5a971fba7965d7a149ccef67450fe930103ed1f35f60734c9b86f6e09cc82476d7b84fbc9373dba794e36781be9340765e559a972169bc046209e8984d93f0e2a6c78143c294e78e349b4ffbc55033ef2465893fe808fb2bb2627f9842ff36c70715eb787aea80a8fdda7c49db360a60c956357028dde18bc945aee137e8eb6e0ef34e69f980b7dde331e858106000f5bcfdf4d3c02664293b91864f2f8f129919e3d1e9ed8688ad848b84b6133621daca013c4f8a2ab438eacdb2a48562c2e072055b21940f0a4dbe82ae14eacb6260f7927ae2fbf2271d099ec945a3a5813db687260f03f4c070befa9ae02a8d659818ff0959aa8d3b44f9ec29d0d2111130c86f7563bedb3d76f4edc74d799057e7524d3543a640d6fa424d420af0566a6481ec0a794fb57a0cc05ef35fb1a511d09a353c9765808032e5c4afd6323dc0630431c1d2f6c4c394da1e5b3070d07d0803149cfc70bf59c7a493d56e994038d09ad3e2217521e9749c8e061433f8b3b92ed2b8e444833658c4e2d62c47e891322c141563bde186d4c4588f00e12c29ece2e75080213a53e588103111feb8b92e53fa1c256b8d47b94ed4475cddb1965341ab10cbd59271e8df3ed4f9bb6650bd9478316d3c667d996e194dcecd419db06132753550f3c763e487708320ce9176c5c096fb620000f252b9fed9719624c90c339fe57a46c39be5e754d65c4225defbe486d78ea418b3f62266762cda9df95f5431d996328efc3efd4fca39f4d7b105f265bd9f7681ec2d17c0e5eeb6d5c0232471174b5f88fbbf78a360f2b7a4602773a92dc7a76ac8729f859ce5faf216cc53f173c24f5a471038566936f150e619cc233fa7986d223d8b893a6fee0fe6a5c50a413bfac3f35da6d61cba3b80277b512e9f676c0cec6bb0d03dc8de9ee3e66aa2e697b9342579db4d8cb7fd40366ea2634ee438d06cb922006d0e6cb41e8fc17edc8520c72e4c1f90370c144b906b79236518edab969255cf2512733e37fb0f295c78ba20719eaf8bccc7f479dcf0cb9ab0ca62e18f270a53621264533f9a851790f8fb3978c8d4d245cde0ca8571a24fe1b4101d4f9d7493bd4ce2859b3bfc7f714b648f7c8b93d1eac35489889dbb9482bbcac9f9bbb143f9e29b71dfd26fae096e12fa2d1fd1357cb0c6945279e614e34aef652c7f0423010df9d9061a9501542060d413223289e5bc55f2719ffa006dd49b87ca18d2802cea91509ff53928f7897fda9553da5c2749dfdadb420f5b3d0bd08c304d88e7942a1a19fda7cb6cab34728d283faa0ccabeca8b77dbd605617fb58b7e0faa2ff524e4eea16016222467a4f07682526907dac4fa29cf3513654ba6ba8b2663e1426fa334c76032c0deaf373c72a5d2392f7b61b8374417c9e814084da8cdf9ee9bc3ff3fb226f2b5ad5048eded5c3d57beb3fc926722ae37fa9d46b92a5761ae0d798e1c3695c8c2a49273bd9d2bc42f1fc9b10c2ba484b1bdf03fa0914cda0c51a3f558d2f9fc1439fe02eeaeb162352516d933a9974c738b4a99470d36a6f3c4f0807f26bea7a07376d73cb4f20e7a6ddd00402bf49310cd5d7a94063e61ac422cb2fdfdc2795b816d7dd55f9a65a99fd10c851028ef4122d0f037bce8fe3ea43573fcddda116e76c3344a4eacd251d031b0f7b4219ae03eace80e09967929b2f87b8cb61f1e613578e423882bffc119ed2b69d896c96e74d21b2d5176309cd1fa76840acd040a053dac327240656793778cfd1a0aac83db2ac878ad08717b7fd45717d0ca91b4d8b8cde4f772a3ffb05b64fc8dca548cc1581fe8d0548acb530d6c9baaebbd2fee5153c3a340669bf9111d1e6df983acd1141ee52d70193d785f630bf1ce3e51a253fc5e78ce4aba067c40167b1e987edf1b5528603081a3fd9ea23468bd62b8befdb56ce63d8fd8c81bf53de58c00540f928c377f81f61548696e7cbec352ab3b61bc8c626c0292bdd98b360755725d80c7ab1b3d505d81e21a9b42443796341fcf4ca38ef00ba23328841150ed0825e6eb846a8e30b3a6c8f464579b2b44c249320be270a2bc8d0d59dd64b7cf70b8cb5528cb90b169f66970742e0c42a7c6375376708962658ad8e9296bc3bb907450489944f6d33f7dc3299e69d395e1b0cb354f3b8f63a04c2dda850546537e7483d59c4ad56935c50114e11ba077aa0d3516623a8e21463ee26a83b6683926e84421b119c172055c490ce8ec587fb35ca6e141d10cdc819d1ea51a41a561ea24c1a4e860580de259f8c0ed782e1307a44dc3a23b0138f16a8dd1bf65ae0fc4010ab65881ed4d4283c31766259fb3c0561dd9fe34f07473bf9dfa18124697bf59f96a2add68edefe23f6435906cfe6ee1092dddc9b958474b271b3e7e4d1294ed3dc6065de849a25f818e9d8a371efbb509d3d78351a4d0d891bed6bf5ee4ff12925adce084aa2b03fa653729dee01df57c35e910d3e88705c31f7d20fc592dfc5db0b8a006fba9e052e07090d959cb324706e1d1d995f99c557fcbd0f2e112d3b5f7dca63000f81442e2f3ad592db45a7085d0d2647afc772f333823b9949715d4aabef71f9d67cca2ab8497372928b02cafabac76e8f4b6ab072f344d1260715038910049830782d45e0dee04b7dbb421127f160171e5f6683f6ffd1c3f8edd9c431c5d8bbcfae15f310e49715df19b7590cd0ec2e7e0e0056f362a4a8fb198038902206357864d569f202c2fbf65f798a4832adee1c686bc6293ea92635135b58b641de2a8eb0ed9c195343b916c3797d7637ca9d0837eb9e3889485a204acbf4f49aca67e835dde2eac5a816200ecafb02c83e875051fb41effcc28ac0814bfbb3e572d042c9e36d5a7a260f08ec46b3060c11e2b8c04315b3b95c35a307adcc8934953e5d2fe0cdadb51e7727d4493c86d4467cff11e16081be2e7b3e5116316c71bc7985503796cd70299108c83e32652981b480a3728dcb5e4ec5425328a1732f443a6580938f2fd7cf3b408cc9ca65d4f0f5a2d5c97b6deb9db9872fb200b991102b478dadf65a96b1eee1874345b5a0986e1c5b388b88054f1a51e7da163a4f7ef40libdcerpc-binding.so.0.0.1libdcerpc-server-core.so.0.0.1libdcerpc.so.0.0.1libndr-krb5pac.so.0.0.1libndr-nbt.so.0.0.1libndr-standard.so.0.0.1libndr.so.3.0.1libnetapi.so.1.0.0libsamba-credentials.so.1.0.0libsamba-errors.so.1.0.0libsamba-hostconfig.so.0.0.1libsamba-passdb.so.0.28.0libsamba-util.so.0.0.1libsamdb.so.0.0.1libsmbclient.so.0.7.0libsmbconf.so.0.0.1libsmbldap.so.2.1.0libtevent-util.so.0.0.1libwbclient.so.0.16rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsamba-4.19.8+git.430.a10fe64854c-150600.3.18.2.src.rpmlibCHARSET3-samba4.so()(64bit)libCHARSET3-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libMESSAGING-SEND-samba4.so()(64bit)libMESSAGING-SEND-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libMESSAGING-samba4.so()(64bit)libMESSAGING-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libaddns-samba4.so()(64bit)libaddns-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libads-samba4.so()(64bit)libads-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libasn1util-samba4.so()(64bit)libasn1util-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libauth-samba4.so()(64bit)libauth-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libauthkrb5-samba4.so()(64bit)libauthkrb5-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libcli-cldap-samba4.so()(64bit)libcli-cldap-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libcli-ldap-common-samba4.so()(64bit)libcli-ldap-common-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libcli-ldap-samba4.so()(64bit)libcli-ldap-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libcli-nbt-samba4.so()(64bit)libcli-nbt-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libcli-smb-common-samba4.so()(64bit)libcli-smb-common-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libcli-spoolss-samba4.so()(64bit)libcli-spoolss-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libcliauth-samba4.so()(64bit)libcliauth-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libclidns-samba4.so()(64bit)libclidns-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libcluster-samba4.so()(64bit)libcluster-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libcmdline-contexts-samba4.so()(64bit)libcmdline-contexts-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libcmdline-samba4.so()(64bit)libcmdline-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libcommon-auth-samba4.so()(64bit)libcommon-auth-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libdbwrap-samba4.so()(64bit)libdbwrap-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libdcerpc-binding.so.0()(64bit)libdcerpc-binding.so.0(DCERPC_BINDING_0.0.1)(64bit)libdcerpc-binding0libdcerpc-pkt-auth-samba4.so()(64bit)libdcerpc-pkt-auth-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libdcerpc-samba-samba4.so()(64bit)libdcerpc-samba-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libdcerpc-samba4.so()(64bit)libdcerpc-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libdcerpc-server-core.so.0()(64bit)libdcerpc-server-core.so.0(DCERPC_SERVER_CORE_0.0.1)(64bit)libdcerpc.so.0()(64bit)libdcerpc.so.0(DCERPC_0.0.1)(64bit)libdcerpc0libevents-samba4.so()(64bit)libevents-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libflag-mapping-samba4.so()(64bit)libflag-mapping-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libgenrand-samba4.so()(64bit)libgenrand-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libgensec-samba4.so()(64bit)libgensec-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libgpo-samba4.so()(64bit)libgpo-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libgse-samba4.so()(64bit)libgse-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libhttp-samba4.so()(64bit)libhttp-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libinterfaces-samba4.so()(64bit)libinterfaces-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libiov-buf-samba4.so()(64bit)libiov-buf-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libkrb5samba-samba4.so()(64bit)libkrb5samba-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libldbsamba-samba4.so()(64bit)libldbsamba-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)liblibcli-lsa3-samba4.so()(64bit)liblibcli-lsa3-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)liblibcli-netlogon3-samba4.so()(64bit)liblibcli-netlogon3-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)liblibsmb-samba4.so()(64bit)liblibsmb-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libmessages-dgm-samba4.so()(64bit)libmessages-dgm-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libmessages-util-samba4.so()(64bit)libmessages-util-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libmscat-samba4.so()(64bit)libmscat-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libmsghdr-samba4.so()(64bit)libmsghdr-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libmsrpc3-samba4.so()(64bit)libmsrpc3-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-krb5pac0libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-nbt0libndr-samba-samba4.so()(64bit)libndr-samba-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libndr-samba4.so()(64bit)libndr-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libndr-standard.so.0()(64bit)libndr-standard.so.0(NDR_STANDARD_0.0.1)(64bit)libndr-standard0libndr.so.3()(64bit)libndr.so.3(NDR_0.0.1)(64bit)libndr.so.3(NDR_0.0.2)(64bit)libndr.so.3(NDR_0.0.3)(64bit)libndr.so.3(NDR_0.0.4)(64bit)libndr.so.3(NDR_0.0.5)(64bit)libndr.so.3(NDR_0.0.6)(64bit)libndr.so.3(NDR_0.0.7)(64bit)libndr.so.3(NDR_0.0.8)(64bit)libndr.so.3(NDR_0.0.9)(64bit)libndr.so.3(NDR_0.1.0)(64bit)libndr.so.3(NDR_0.1.1)(64bit)libndr.so.3(NDR_0.1.2)(64bit)libndr.so.3(NDR_0.2.0)(64bit)libndr.so.3(NDR_0.2.1)(64bit)libndr.so.3(NDR_1.0.0)(64bit)libndr.so.3(NDR_1.0.1)(64bit)libndr.so.3(NDR_1.0.2)(64bit)libndr.so.3(NDR_2.0.0)(64bit)libndr.so.3(NDR_3.0.0)(64bit)libndr.so.3(NDR_3.0.1)(64bit)libndr2libnet-keytab-samba4.so()(64bit)libnet-keytab-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libnetapi.so.1()(64bit)libnetapi.so.1(NETAPI_1.0.0)(64bit)libnetapi0libnetif-samba4.so()(64bit)libnetif-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libnpa-tstream-samba4.so()(64bit)libnpa-tstream-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libprinting-migrate-samba4.so()(64bit)libprinting-migrate-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libregistry-samba4.so()(64bit)libregistry-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libreplace-samba4.so()(64bit)libreplace-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsamba-cluster-support-samba4.so()(64bit)libsamba-cluster-support-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsamba-credentials.so.1()(64bit)libsamba-credentials.so.1(SAMBA_CREDENTIALS_1.0.0)(64bit)libsamba-credentials1libsamba-debug-samba4.so()(64bit)libsamba-debug-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsamba-errors.so.1()(64bit)libsamba-errors.so.1(SAMBA_ERRORS_1.0.0)(64bit)libsamba-errors0libsamba-hostconfig.so.0()(64bit)libsamba-hostconfig.so.0(SAMBA_HOSTCONFIG_0.0.1)(64bit)libsamba-hostconfig0libsamba-modules-samba4.so()(64bit)libsamba-modules-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsamba-passdb.so.0()(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.2.0)(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.24.1)(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.24.2)(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.25.0)(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.26.0)(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.27.0)(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.27.1)(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.27.2)(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.28.0)(64bit)libsamba-passdb0libsamba-security-samba4.so()(64bit)libsamba-security-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsamba-sockets-samba4.so()(64bit)libsamba-sockets-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsamba-util.so.0()(64bit)libsamba-util.so.0(SAMBA_UTIL_0.0.1)(64bit)libsamba-util0libsamba3-util-samba4.so()(64bit)libsamba3-util-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsamdb-common-samba4.so()(64bit)libsamdb-common-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsamdb.so.0()(64bit)libsamdb.so.0(SAMDB_0.0.1)(64bit)libsamdb0libsecrets3-samba4.so()(64bit)libsecrets3-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libserver-id-db-samba4.so()(64bit)libserver-id-db-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libserver-role-samba4.so()(64bit)libserver-role-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsmb-transport-samba4.so()(64bit)libsmb-transport-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsmbclient-raw-samba4.so()(64bit)libsmbclient-raw-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsmbclient.so.0()(64bit)libsmbclient.so.0(SMBCLIENT_0.1.0)(64bit)libsmbclient.so.0(SMBCLIENT_0.2.0)(64bit)libsmbclient.so.0(SMBCLIENT_0.2.1)(64bit)libsmbclient.so.0(SMBCLIENT_0.2.2)(64bit)libsmbclient.so.0(SMBCLIENT_0.2.3)(64bit)libsmbclient.so.0(SMBCLIENT_0.3.0)(64bit)libsmbclient.so.0(SMBCLIENT_0.3.1)(64bit)libsmbclient.so.0(SMBCLIENT_0.3.2)(64bit)libsmbclient.so.0(SMBCLIENT_0.3.3)(64bit)libsmbclient.so.0(SMBCLIENT_0.4.0)(64bit)libsmbclient.so.0(SMBCLIENT_0.5.0)(64bit)libsmbclient.so.0(SMBCLIENT_0.6.0)(64bit)libsmbclient.so.0(SMBCLIENT_0.7.0)(64bit)libsmbclient0libsmbconf.so.0()(64bit)libsmbconf.so.0(SMBCONF_0.0.1)(64bit)libsmbconf0libsmbd-base-samba4.so()(64bit)libsmbd-base-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsmbd-shim-samba4.so()(64bit)libsmbd-shim-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsmbldap.so.2()(64bit)libsmbldap.so.2(SMBLDAP_0)(64bit)libsmbldap.so.2(SMBLDAP_1)(64bit)libsmbldap.so.2(SMBLDAP_2)(64bit)libsmbldap.so.2(SMBLDAP_2.1.0)(64bit)libsmbldap2libsmbldaphelper-samba4.so()(64bit)libsmbldaphelper-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsocket-blocking-samba4.so()(64bit)libsocket-blocking-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libstable-sort-samba4.so()(64bit)libstable-sort-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsys-rw-samba4.so()(64bit)libsys-rw-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libtalloc-report-printf-samba4.so()(64bit)libtalloc-report-printf-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libtdb-wrap-samba4.so()(64bit)libtdb-wrap-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libtevent-util.so.0()(64bit)libtevent-util.so.0(TEVENT_UTIL_0.0.1)(64bit)libtevent-util0libtime-basic-samba4.so()(64bit)libtime-basic-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libtrusts-util-samba4.so()(64bit)libtrusts-util-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libutil-reg-samba4.so()(64bit)libutil-reg-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libutil-setid-samba4.so()(64bit)libutil-setid-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libutil-tdb-samba4.so()(64bit)libutil-tdb-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libwbclient.so.0()(64bit)libwbclient.so.0(WBCLIENT_0.10)(64bit)libwbclient.so.0(WBCLIENT_0.11)(64bit)libwbclient.so.0(WBCLIENT_0.12)(64bit)libwbclient.so.0(WBCLIENT_0.13)(64bit)libwbclient.so.0(WBCLIENT_0.14)(64bit)libwbclient.so.0(WBCLIENT_0.15)(64bit)libwbclient.so.0(WBCLIENT_0.16)(64bit)libwbclient.so.0(WBCLIENT_0.9)(64bit)libwbclient0samba-client-libssamba-client-libs(aarch-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    /sbin/ldconfig/sbin/ldconfigld-linux-aarch64.so.1()(64bit)ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)libCHARSET3-samba4.so()(64bit)libCHARSET3-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libMESSAGING-SEND-samba4.so()(64bit)libMESSAGING-SEND-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libMESSAGING-samba4.so()(64bit)libMESSAGING-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libacl.so.1()(64bit)libacl.so.1(ACL_1.0)(64bit)libaddns-samba4.so()(64bit)libaddns-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libads-samba4.so()(64bit)libads-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libasn1util-samba4.so()(64bit)libasn1util-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libauth-samba4.so()(64bit)libauth-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libauthkrb5-samba4.so()(64bit)libauthkrb5-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libavahi-client.so.3()(64bit)libavahi-common.so.3()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.27)(64bit)libc.so.6(GLIBC_2.32)(64bit)libc.so.6(GLIBC_2.33)(64bit)libc.so.6(GLIBC_2.34)(64bit)libc.so.6(GLIBC_2.38)(64bit)libcli-cldap-samba4.so()(64bit)libcli-cldap-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libcli-ldap-common-samba4.so()(64bit)libcli-ldap-common-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libcli-ldap-samba4.so()(64bit)libcli-ldap-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libcli-nbt-samba4.so()(64bit)libcli-nbt-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libcli-smb-common-samba4.so()(64bit)libcli-smb-common-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libcli-spoolss-samba4.so()(64bit)libcli-spoolss-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libcliauth-samba4.so()(64bit)libcliauth-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libclidns-samba4.so()(64bit)libclidns-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libcluster-samba4.so()(64bit)libcluster-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libcom_err.so.2()(64bit)libcommon-auth-samba4.so()(64bit)libcommon-auth-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libdbwrap-samba4.so()(64bit)libdbwrap-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libdcerpc-binding.so.0()(64bit)libdcerpc-binding.so.0(DCERPC_BINDING_0.0.1)(64bit)libdcerpc-pkt-auth-samba4.so()(64bit)libdcerpc-pkt-auth-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libdcerpc-samba-samba4.so()(64bit)libdcerpc-samba-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libdcerpc.so.0()(64bit)libdcerpc.so.0(DCERPC_0.0.1)(64bit)libflag-mapping-samba4.so()(64bit)libflag-mapping-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libgenrand-samba4.so()(64bit)libgenrand-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libgensec-samba4.so()(64bit)libgensec-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libgnutls.so.30()(64bit)libgnutls.so.30(GNUTLS_3_4)(64bit)libgnutls.so.30(GNUTLS_3_6_10)(64bit)libgnutls.so.30(GNUTLS_3_6_13)(64bit)libgnutls.so.30(GNUTLS_3_6_3)(64bit)libgse-samba4.so()(64bit)libgse-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libgssapi_krb5.so.2()(64bit)libgssapi_krb5.so.2(gssapi_krb5_2_MIT)(64bit)libhttp-samba4.so()(64bit)libhttp-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libinterfaces-samba4.so()(64bit)libinterfaces-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libiov-buf-samba4.so()(64bit)libiov-buf-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libk5crypto.so.3()(64bit)libk5crypto.so.3(k5crypto_3_MIT)(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libkrb5samba-samba4.so()(64bit)libkrb5samba-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)liblber-2.4.so.2()(64bit)libldap_r-2.4.so.2()(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libldb.so.2(LDB_0.9.15)(64bit)libldb.so.2(LDB_0.9.16)(64bit)libldb.so.2(LDB_0.9.23)(64bit)libldb.so.2(LDB_1.1.1)(64bit)libldb.so.2(LDB_1.1.19)(64bit)libldb.so.2(LDB_1.1.30)(64bit)libldb.so.2(LDB_1.3.0)(64bit)libldb.so.2(LDB_2.6.1)(64bit)libldb.so.2(LDB_2.8.0)(64bit)libldbsamba-samba4.so()(64bit)libldbsamba-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)liblibcli-lsa3-samba4.so()(64bit)liblibcli-lsa3-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)liblibcli-netlogon3-samba4.so()(64bit)liblibcli-netlogon3-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)liblibsmb-samba4.so()(64bit)liblibsmb-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libmessages-dgm-samba4.so()(64bit)libmessages-dgm-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libmessages-util-samba4.so()(64bit)libmessages-util-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libmsghdr-samba4.so()(64bit)libmsghdr-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libmsrpc3-samba4.so()(64bit)libmsrpc3-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-samba-samba4.so()(64bit)libndr-samba-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libndr-samba4.so()(64bit)libndr-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libndr-standard.so.0()(64bit)libndr-standard.so.0(NDR_STANDARD_0.0.1)(64bit)libndr.so.3()(64bit)libndr.so.3(NDR_0.0.1)(64bit)libndr.so.3(NDR_0.0.3)(64bit)libndr.so.3(NDR_0.0.4)(64bit)libndr.so.3(NDR_0.0.5)(64bit)libndr.so.3(NDR_0.0.6)(64bit)libndr.so.3(NDR_0.0.7)(64bit)libndr.so.3(NDR_0.0.8)(64bit)libndr.so.3(NDR_0.0.9)(64bit)libndr.so.3(NDR_0.1.1)(64bit)libndr.so.3(NDR_0.1.2)(64bit)libndr.so.3(NDR_0.2.0)(64bit)libndr.so.3(NDR_0.2.1)(64bit)libndr.so.3(NDR_1.0.0)(64bit)libndr.so.3(NDR_1.0.1)(64bit)libndr.so.3(NDR_1.0.2)(64bit)libndr.so.3(NDR_2.0.0)(64bit)libndr.so.3(NDR_3.0.1)(64bit)libnetif-samba4.so()(64bit)libnetif-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libnpa-tstream-samba4.so()(64bit)libnpa-tstream-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libnscd.so.1()(64bit)libnscd.so.1(LIBNSCD_1.0)(64bit)libpam.so.0()(64bit)libpam.so.0(LIBPAM_1.0)(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libreplace-samba4.so()(64bit)libreplace-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsamba-cluster-support-samba4.so()(64bit)libsamba-cluster-support-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsamba-credentials.so.1()(64bit)libsamba-credentials.so.1(SAMBA_CREDENTIALS_1.0.0)(64bit)libsamba-debug-samba4.so()(64bit)libsamba-debug-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsamba-errors.so.1()(64bit)libsamba-errors.so.1(SAMBA_ERRORS_1.0.0)(64bit)libsamba-hostconfig.so.0()(64bit)libsamba-hostconfig.so.0(SAMBA_HOSTCONFIG_0.0.1)(64bit)libsamba-modules-samba4.so()(64bit)libsamba-modules-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsamba-passdb.so.0()(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.2.0)(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.27.1)(64bit)libsamba-security-samba4.so()(64bit)libsamba-security-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsamba-sockets-samba4.so()(64bit)libsamba-sockets-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsamba-util.so.0()(64bit)libsamba-util.so.0(SAMBA_UTIL_0.0.1)(64bit)libsamba3-util-samba4.so()(64bit)libsamba3-util-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsamdb-common-samba4.so()(64bit)libsamdb-common-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsamdb.so.0()(64bit)libsamdb.so.0(SAMDB_0.0.1)(64bit)libsecrets3-samba4.so()(64bit)libsecrets3-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libserver-id-db-samba4.so()(64bit)libserver-id-db-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libserver-role-samba4.so()(64bit)libserver-role-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsmb-transport-samba4.so()(64bit)libsmb-transport-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsmbclient-raw-samba4.so()(64bit)libsmbclient-raw-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsmbconf.so.0()(64bit)libsmbconf.so.0(SMBCONF_0.0.1)(64bit)libsmbd-shim-samba4.so()(64bit)libsmbd-shim-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsmbldap.so.2()(64bit)libsmbldap.so.2(SMBLDAP_0)(64bit)libsmbldap.so.2(SMBLDAP_1)(64bit)libsmbldaphelper-samba4.so()(64bit)libsmbldaphelper-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsocket-blocking-samba4.so()(64bit)libsocket-blocking-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libstable-sort-samba4.so()(64bit)libstable-sort-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsys-rw-samba4.so()(64bit)libsys-rw-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsystemd.so.0()(64bit)libsystemd.so.0(LIBSYSTEMD_209)(64bit)libtalloc-report-printf-samba4.so()(64bit)libtalloc-report-printf-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtalloc.so.2(TALLOC_2.1.0)(64bit)libtalloc.so.2(TALLOC_2.3.5)(64bit)libtasn1.so.6()(64bit)libtasn1.so.6(LIBTASN1_0_3)(64bit)libtdb-wrap-samba4.so()(64bit)libtdb-wrap-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtdb.so.1(TDB_1.2.2)(64bit)libtdb.so.1(TDB_1.2.5)(64bit)libtdb.so.1(TDB_1.3.0)(64bit)libtdb.so.1(TDB_1.3.11)(64bit)libtdb.so.1(TDB_1.3.17)(64bit)libtevent-util.so.0()(64bit)libtevent-util.so.0(TEVENT_UTIL_0.0.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.11.0)(64bit)libtevent.so.0(TEVENT_0.12.0)(64bit)libtevent.so.0(TEVENT_0.13.0)(64bit)libtevent.so.0(TEVENT_0.15.0)(64bit)libtevent.so.0(TEVENT_0.9.12)(64bit)libtevent.so.0(TEVENT_0.9.13)(64bit)libtevent.so.0(TEVENT_0.9.16)(64bit)libtevent.so.0(TEVENT_0.9.20)(64bit)libtevent.so.0(TEVENT_0.9.30)(64bit)libtevent.so.0(TEVENT_0.9.31)(64bit)libtevent.so.0(TEVENT_0.9.37)(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libtime-basic-samba4.so()(64bit)libtime-basic-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libtrusts-util-samba4.so()(64bit)libtrusts-util-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libutil-reg-samba4.so()(64bit)libutil-reg-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libutil-setid-samba4.so()(64bit)libutil-setid-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libutil-tdb-samba4.so()(64bit)libutil-tdb-samba4.so(SAMBA_4.19.9_GIT.430.A10FE64854C150600.3.18.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libwbclient.so.0()(64bit)libwbclient.so.0(WBCLIENT_0.13)(64bit)libwbclient.so.0(WBCLIENT_0.9)(64bit)libz.so.1()(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-14.14.3hm@g`@gRgR@gMgp@fٝ@fxfteԔ@ee5@ede6`@e-%e'e%ascabrero@suse.denopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comddiss@suse.comscabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comdmulder@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comscabrero@suse.dedmulder@suse.comscabrero@suse.denopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedimstar@opensuse.orgscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.denopower@suse.comscabrero@suse.deddiss@suse.comddiss@suse.comddiss@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comscabrero@suse.descabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comdmulder@suse.comscabrero@suse.denopower@suse.comddiss@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comddiss@suse.comddiss@suse.comnopower@suse.comnopower@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comddiss@suse.comscabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comjengelh@inai.dedmulder@suse.comscabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comdmulder@suse.comdmulder@suse.comjmcdonough@suse.comdmulder@suse.comscabrero@suse.dedmulder@suse.comscabrero@suse.dedmulder@suse.comdmulder@suse.comvcizek@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.dejmcdonough@suse.comscabrero@suse.deaaptel@suse.comjengelh@inai.dedimstar@opensuse.orgdmulder@suse.comjmcdonough@suse.comdavid.mulder@suse.comjmcdonough@suse.comaaptel@suse.comdmulder@suse.comscabrero@suse.comscabrero@suse.comkukuk@suse.dedavid.mulder@suse.comscabrero@suse.comrbrown@suse.comdmulder@suse.comscabrero@suse.comdimstar@opensuse.orgscabrero@suse.comaaptel@suse.comnopower@suse.comnopower@suse.comaaptel@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comddiss@suse.comnopower@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comdmulder@suse.comnopower@suse.comjmcdonough@suse.comaaptel@suse.comkukuk@suse.comkukuk@suse.denopower@suse.comaaptel@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comddiss@suse.comjmcdonough@suse.comddiss@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comtchvatal@suse.comlmuelle@suse.comnopower@suse.comcrrodriguez@opensuse.orglmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnoel.power@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.commpluskal@suse.comlmuelle@suse.comnopower@suse.deddiss@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.denopower@suse.delmuelle@suse.comnopower@suse.deddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.com- Windows security hardening locks out schannel'ed netlogon dc calls like netr_DsRGetDCName; (bsc#1246431); (bso#15876).- Fix Samba printers reporting invalid sid during print jobs; (bsc#1234210); (bso#15792).- Fix crossing automounter mount points; (bsc#1215212); (bsc#1236803);- Update shipped /etc/samba/smb.conf to point to smb.conf man page;(bsc#1233880).- Update to 4.19.9 * libldb: performance issue with indexes (ldb 2.8.2 is already released); (bso#15590). * DH reconnect error handling can lead to stale sharemode entries; (bso#15624). * Incorrect FSCTL_QUERY_ALLOCATED_RANGES response when truncated; (bso#15699). * irpc_destructor may crash during shutdown; (bso#15280). * Compound SMB2 requests don't return NT_STATUS_NETWORK_SESSION_EXPIRED for all requests, confuses MacOSX clients; (bso#15696). * Crash when readlinkat fails; (bso#15700).- Adjust spec to split out rpcd_* binaries into a separate sub package; (bsc#1231414).- Incorrect FSCTL_QUERY_ALLOCATED_RANGES response when truncated; (bso#15699); (bsc#1229684). - Update to 4.19.8 * Invalid client warning about command line passwords; (bso#15671); * Version string is truncated in manpages; (bso#15672); * --version-* options are still not ergonomic, and they reject tilde characters; (bso#15673); * cmdline_burn does not always burn secrets; (bso#15674); * Samba doesn't parse SDDL found in defaultSecurityDescriptor in AD_DS_Classes_Windows_Server_v1903.ldf; (bso#15685); * We have added new options --vendor-name and --vendor-patch- revision arguments to ./configure to allow distributions and packagers to put their name in the Samba version string so that when debugging Samba the source of the binary is obvious; (bso#15654); * When claims enabled with heimdal kerberos, unable to log on to a Windows computer when user account need to change their own password; (bso#15655); * Fix clock skew error message and memory cache clock skew recovery; (bso#15676); * CTDB RADOS mutex helper misses namespace support; (bso#15665); * The images don't build after the git security release and CentOS 8 Stream is EOL; (bso#15660); * Fix unnecessary delays in CTDB while processing requests under high load; (bso#15678); * Dynamic DNS updates with the internal DNS are not working; (bso#13019); * s4:nbt_server: does not provide unexpected handling, so winbindd can't use nmb requests instead cldap; (bso#15620); * Panic in vfs_offload_token_db_fetch_fsp(); (bso#15664); * "client use kerberos" and --use-kerberos is ignored for the machine account; (bso#15666); * Regression DFS not working with widelinks = true; (bso#15435); * ntlm_auth make logs more consistent with length check; (bso#15677);- Fix a crash when joining offline and 'kerberos method' includes keytab; (bsc#1228732); - Fix reading the password from STDIN or environment vars if it was already given in the command line; (bsc#1228732);- Update to 4.19.7 * ldb qsort might r/w out of bounds with an intransitive compare function (ldb 2.8.1 is already released); (bso#15569). * Many qsort() comparison functions are non-transitive, which can lead to out-of-bounds access in some circumstances (ldb 2.8.1 is already released); (bso#15625). * Need to change gitlab-ci.yml tags in all branches to avoid CI bill; (bso#15638). * netr_LogonSamLogonEx returns NR_STATUS_ACCESS_DENIED with SysvolReady=0; (bso#14981). * Anonymous smb3 signing/encryption should be allowed (similar to Windows Server 2022); (bso#15412). * Panic in dreplsrv_op_pull_source_apply_changes_trigger; (bso#15573). * winbindd, net ads join and other things don't work on an ipv6 only host; (bso#15642). * Smbcacls incorrectly propagates inheritance with Inherit-Only flag; (bso#15636). * http library doesn't support 'chunked transfer encoding'; (bso#15611). - Update to 4.19.6 * fd_handle_destructor() panics within an smbd_smb2_close() if vfs_stat_fsp() fails in fd_close(); (bso#15527). * samba-gpupdate: Correctly implement site support; (bso#15588). * libgpo: Segfault in python bindings; (bso#15599). * Packet marshalling push support missing for CTDB_CONTROL_TCP_CLIENT_DISCONNECTED and CTDB_CONTROL_TCP_CLIENT_PASSED; (bso#15580).- Update to 4.19.5 * Windows 2016 fails to restore previous version of a file from a shadow_copy2 snapshot; (bso#13688). * Symlinks on AIX are broken in 4.19 (and a few version before that); (bso#15549). * Fake directory create times has no effect; (bso#12421). * ctime mixed up with mtime by smbd; (bso#15550). * samba-gpupdate --rsop fails if machine is not in a site; (bso#15548). * gpupdate: The root cert import when NDES is not available is broken; (bso#15557). * samba-gpupdate should print a useful message if cepces-submit can't be found; (bso#15552). * samba-gpupdate logging doesn't work; (bso#15558). * smbpasswd reset permissions only if not 0600; (bso#15555).- Remove -x from bash shebang update-apparmor-samba-profile; (bsc#1218431).- Update to 4.19.4 * net changesecretpw cannot set the machine account password if secrets.tdb is empty; (bso#13577). * For generating doc, take, if defined, env XML_CATALOG_FILES; (bso#15540). * Trivial C typo in nsswitch/winbind_nss_netbsd.c; (bso#15541). * vfs_linux_xfs is incorrectly named; (bso#15542). * systemd stumbled over copyright-message at smbd startup; (bso#15377). * Following intermediate abolute share-local symlinks is broken; (bso#15505). * ctdb RELEASE_IP causes a crash in release_ip if a connection to a non-public address disconnects first; (bso#15523). * shadow_copy2 broken when current fileset's directories are removed; (bso#15544). * smbd does not detect ctdb public ipv6 addresses for multichannel exclusion; (bso#15534). * 'force user = localunixuser' doesn't work if 'allow trusted domains = no' is set; (bso#15469). * smbget debug logging doesn't work; (bso#15525). * smget: username in the smburl and interactive password entry doesn't work; (bso#15532). * smbget auth function doesn't set values for password prompt correctly; (bso#15538). * Unable to copy and write files from clients to Ceph cluster via SMB Linux gateway with Ceph VFS module; (bso#15440). * Multichannel refresh network information; (bso#15547).- Update to 4.19.3 * sid_strings test broken by unix epoch > 1700000000; (bso#15520). * smbd crashes if asked to return full information on close of a stream handle with delete on close disposition set; (bso#15487). * smbd: fix close order of base_fsp and stream_fsp in smb_fname_fsp_destructor(); (bso#15521). * Improve logging for failover scenarios; (bso#15499). * Files without "read attributes" NFS4 ACL permission are not listed in directories; (bso#15093). * CVE-2018-14628 [SECURITY] Deleted Object tombstones visible in AD LDAP to normal users; (bso#13595). * Kerberos TGS-REQ with User2User does not work for normal accounts; (bso#15492). * vfs_gpfs stat calls fail due to file system permissions; (bso#15507). * Samba doesn't build with Python 3.12; (bso#15513).- packaging: samba-tool domain provision requires python3-Markdown; (bsc#1216519).- Update to 4.19.2 * Use-after-free in aio_del_req_from_fsp during smbd shutdown after failed IPC FSCTL_PIPE_TRANSCEIVE; (bso#15423). * clidfs.c do_connect() missing a "return" after a cli_shutdown() call; (bso#15426). * macOS mdfind returns only 50 results; (bso#15463). * GETREALFILENAME_CACHE can modify incoming new filename with previous cache entry value; (bso#15481). * libnss_winbind causes memory corruption since samba-4.18, impacts sendmail, zabbix, potentially more; (bso#15464). * ctdbd: setproctitle not initialized messages flooding logs; (bso#15479). * CVE-2023-5568 Heap buffer overflow with freshness tokens in the Heimdal KDC in Samba 4.19; (bso#15491). * The heimdal KDC doesn't detect s4u2self correctly when fast is in use; (bso#15477).- use systemd-logind rather than utmp for y2038 safety; (bsc#1216159).- CVE-2023-4091: samba: Client can truncate file with read-only permissions; (bsc#1215904); (bso#15439). - CVE-2023-42669: samba: rpcecho, enabled and running in AD DC, allows blocking sleep on request; (bso#1215905); (bso#15474). - CVE-2023-42670: samba: The procedure number is out of range when starting Active Directory Users and Computers; (bsc#1215906); (bso#15473). - CVE-2023-3961: samba: Unsanitized client pipe name passed to local_np_connect(); (bsc#1215907); (bso#15422). - CVE-2023-4154: samba: dirsync allows SYSTEM access with only "GUID_DRS_GET_CHANGES" right, not "GUID_DRS_GET_ALL_CHANGES; (bsc#1215908); (bso#15424).- Update to 4.19.0 * File doesn't show when user doesn't have permission if aio_pthread is loaded; (bso#15453). * ctdb_killtcp fails to work with --enable-pcap and libpcap ≥ 1.9.1; (bso#15451). * Logging to stdout/stderr with DEBUG_SYSLOG_FORMAT_ALWAYS can log to syslog; (bso#15460). * ‘samba-tool domain level raise’ fails unless given a URL; (bso#15458). * reply_sesssetup_and_X() can dereference uninitialized tmp pointer; (bso#15420). * missing return in reply_exit_done(); (bso#15430). * TREE_CONNECT without SETUP causes smbd to use uninitialized pointer; (bso#15432). * Avoid infinite loop in initial user sync with Azure AD Connect when synchronising a large Samba AD domain; (bso#15401). * Samba replication logs show (null) DN; (bso#15407). * 2-3min delays at reconnect with smb2_validate_sequence_number: bad message_id 2; (bso#15346). * DCERPC_PKT_CO_CANCEL and DCERPC_PKT_ORPHANED can't be parsed; (bso#15446). * CID 1539212 causes real issue when output contains only newlines; (bso#15438). * KDC encodes INT64 claims incorrectly; (bso#15452). * mdssvc: Do an early talloc_free() in _mdssvc_open(); (bso#15449). * Windows client join fails if a second container CN=System exists somewhere; (bso#9959). * regression DFS not working with widelinks = true; (bso#15435). * Heimdal fails to build on 32-bit FreeBSD; (bso#15443). * samba-tool ntacl get segfault if aio_pthread appended; (bso#15441). - Update to 4.18.6 * reply_sesssetup_and_X() can dereference uninitialized tmp pointer; (bso#15420); * Missing return in reply_exit_done(); (bso#15430); * post-exec password redaction for samba-tool is more reliable for fully random passwords as it no longer uses regular expressions containing the password value itself; (bso#15289); * Windows client join fails if a second container CN=System exists somewhere; (bso#9959); * Spotlight sometimes returns no results on latest macOS; (bso#15342); * Renaming results in NT_STATUS_SHARING_VIOLATION if previously attempted to remove the destination; (bso#15417); * Spotlight results return wrong date in result list; (bso#15427); * "net offlinejoin provision" does not work as non-root user; (bso#15414); * rpcserver no longer accepts double backslash in dfs pathname; (bso#15400); * cm_prepare_connection() calls close(fd) for the second time; (bso#15433); * 2-3min delays at reconnect with smb2_validate_sequence_number: bad message_id 2; (bso#15346); * samba-tool ntacl get segfault if aio_pthread appended; (bso#15441); * DCERPC_PKT_CO_CANCEL and DCERPC_PKT_ORPHANED can't be parsed; (bso#15446); * Python tarfile extraction needs change to avoid a warning (CVE-2007-4559 mitigation); (bso#15390); * Regression DFS not working with widelinks = true; (bso#15435); * mdssvc: Do an early talloc_free() in _mdssvc_open(); (bso#15449); - Update to 4.18.5 * CVE-2022-2127: lm_resp_len not checked properly in winbindd_pam_auth_crap_send; (bso#15072); (bsc#1213174). * CVE-2023-34966: Samba Spotlight mdssvc RPC Request Infinite Loop Denial-of-Service Vulnerability; (bso#15340); (bsc#1213173). * CVE-2023-34967: Samba Spotlight mdssvc RPC Request Type Confusion Denial-of-Service Vulnerability; (bso#15341); (bsc#1213172). * CVE-2023-34968: Spotlight server-side Share Path Disclosure; (bso#15388); (bsc#1213171). * CVE-2023-3347: Samba doesn't require SMB2+ signing if `server signing = mandatory` is set; (bso#15397); (bsc#1213170). * secure channel faulty since Windows 10/11 update 07/2023; (bso#15418); (bsc#1213384). - Update to 4.18.4 * Backport --pidl-developer fixes; (bso#15404). * Named crashes on DLZ zone update; (bso#14030). * smbcacls and smbcquotas do not check // before the server; (bso#2312). * cli_list loops 100% CPU against pre-lanman2 servers; (bso#15382). * smbclient leaks fds with showacls; (bso#15391). * smbd returns NOT_FOUND when creating files on a r/o filesystem; (bso#15402). * NSS_WRAPPER_HOSTNAME doesn't match NSS_WRAPPER_HOSTS entry and causes test timeouts; (bso#15355). * net ads lookup (with unspecified realm) fails; (bso#15384). * Register Samba processes with GPFS; (bso#15381). * Python tarfile extraction needs change to avoid a warning (CVE-2007-4559 mitigation); (bso#15390). * The winbind child segfaults when listing users with `winbind scan trusted domains = yes`; (bso#15398). * Remove comments about deprecated 'write cache size'; (bso#15383). * smbget memory leak if failed to download files recursively; (bso#15403). - Update to 4.18.3 * Symlinks to files can have random DOS mode information in a directory listing; (bso#15375). * vfs_fruit might cause a failing open for delete; (bso#15378). * winbind recurses into itself via rpcd_lsad; (bso#15361). * wbinfo -u fails on ad dc with >1000 users; (bso#15366). * DS ACEs might be inherited to unrelated object classes; (bso#15338). * a lot of messages: get_static_share_mode_data: get_static_share_mode_data_fn failed: NT_STATUS_NOT_FOUND; (bso#15362). * aes256 smb3 encryption algorithms are not allowed in smb3_sid_parse(); (bso#15374). * Setting veto files = /.*/ break listing directories; (bso#15360). * "samba-tool domain provision" does not run interactive mode if no arguments are given; (bso#15363). * dsgetdcname: assumes local system uses IPv4; (bso#15325). - Update to 4.18.2 * Log flood: smbd_calculate_access_mask_fsp: Access denied: message level should be lower; (bso#15302). * Floating point exception (FPE) via cli_pull_send at source3/libsmb/clireadwrite.c; (bso#15306). * test_tstream_more_tcp_user_timeout_spin fails intermittently on Rackspace GitLab runners; (bso#15328). * Reduce flapping of ridalloc test; (bso#15329). * large_ldap test is unreliable; (bso#15351). * New filename parser doesn't check veto files smb.conf parameter; (bso#15143). * mdssvc may crash when initializing; (bso#15354). * large directory optimization broken for non-lcomp path elements; (bso#15313). * streams_depot fails to create streams; (bso#15357). * shadow_copy2 and streams_depot don't play well together; (bso#15358). * Flapping tests in samba_tool_drs_show_repl.py; (bso#15316). * winbindd idmap child contacts the domain controller without a need; (bso#15317). * idmap_autorid may fail to map sids of trusted domains for the first time; (bso#15318). * idmap_hash doesn't use ID_TYPE_BOTH for reverse mappings; (bso#15319). * net ads search -P doesn't work against servers in other domains; (bso#15323). * Temporary smbXsrv_tcon_global.tdb can't be parsed; (bso#15353). * Tests use depricated and removed methods like assertRegexpMatches; (bso#15343). - Update to 4.18.1 * CVE-2023-0225: AD DC "dnsHostname" attribute can be deleted by unprivileged authenticated users. (bso#15276);(bsc#1209483). * CVE-2023-0614: Access controlled AD LDAP attributes can be discovered (bso#15270); (bsc#1209485). * CVE-2023-0922: Samba AD DC admin tool samba-tool sends passwords in cleartext(bso#15315);(bsc#1209481). * ldb wildcard matching makes excessive allocations; (bso#15331). * large_ldap test is inefficient; (bso#15332). - Update to 4.18.0 * SMB server performance improvements * More succinct samba-tool error messages * Color output with samba-tool --color The NO_COLOR environment variable will disable colour output * New samba-tool dsacl subcommand for deleting ACEs * New wbinfo option --change-secret-at * Net option to change the NT ACL default location * Azure AD / Office365 synchronization improvements- Fix DFS not working with widelinks enabled; (bsc#1213607); (bso#15435);- Move libcluster-samba4.so from samba-libs to samba-client-libs; (bsc#1213940);- net ads lookup with unspecified realm fails; (bso#15384); (bsc#1213826);- secure channel faulty since Windows 10/11 update 07/2023; (bso#15418); (bsc#1213384).- CVE-2022-2127: lm_resp_len not checked properly in winbindd_pam_auth_crap_send; (bso#15072); (bsc#1213174). - CVE-2023-34966: Samba Spotlight mdssvc RPC Request Infinite Loop Denial-of-Service Vulnerability; (bso#15340); (bsc#1213173). - CVE-2023-34967: Samba Spotlight mdssvc RPC Request Type Confusion Denial-of-Service Vulnerability; (bso#15341); (bsc#1213172). - CVE-2023-34968: Spotlight server-side Share Path Disclosure; (bso#15388); (bsc#1213171). - CVE-2023-3347: Samba doesn't require SMB2+ signing if `server signing = mandatory` is set; (bso#15397); (bsc#1213170).- Update to 4.17.9 * Backport --pidl-developer fixes; (bso#15404). * smbd_scavenger crashes when service smbd is stopped; (bso#15275). * vfs_fruit might cause a failing open for delete; (bso#15378). * named crashes on DLZ zone update; (bso#14030). * winbind recurses into itself via rpcd_lsad; (bso#15361). * cli_list loops 100% CPU against pre-lanman2 servers; (bso#15382). * smbclient leaks fds with showacls; (bso#15391). * aes256 smb3 encryption algorithms are not allowed in smb3_sid_parse(); (bso#15374). * winbindd gets stuck on NT_STATUS_RPC_SEC_PKG_ERROR; (bso#15413). * smbget memory leak if failed to download files recursively; (bso#15403).- Update to 4.17.8 * log flood: smbd_calculate_access_mask_fsp: Access denied: message level should be lower; (bso#15302). * Floating point exception (FPE) via cli_pull_send at source3/libsmb/clireadwrite.c; (bso#15306). * test_tstream_more_tcp_user_timeout_spin fails intermittently on Rackspace GitLab runners; (bso#15328). * Reduce flapping of ridalloc test; (bso#15329). * large_ldap test is unreliable; (bso#15351). * New filename parser doesn't check veto files smb.conf parameter; (bso#15143). * mdssvc may crash when initializing; (bso#15354). * Large directory optimization broken for non-lcomp path elements; (bso#15313). * streams_depot fails to create streams; (bso#15357). * shadow_copy2 and streams_depot don't play well together; (bso#15358). * wbinfo -u fails on ad dc with >1000 users; (bso#15366). * winbindd idmap child contacts the domain controller without a need; (bso#15317). * idmap_autorid may fail to map sids of trusted domains for the first time; (bso#15318). * idmap_hash doesn't use ID_TYPE_BOTH for reverse mappings; (bso#15319). * net ads search -P doesn't work against servers in other domains; (bso#15323). * DS ACEs might be inherited to unrelated object classes; (bso#15338). * Temporary smbXsrv_tcon_global.tdb can't be parsed; (bso#15353). * Setting veto files = /.*/ break listing directories; (bso#15360); (bsc#1212375). * CVE-2020-25720 [SECURITY] Create Child permission should not allow full write to all attributes (additional changes); (bso#14810). * dsgetdcname: assumes local system uses IPv4; (bso#15325).- Update to 4.17.7 * CVE-2023-0922: Samba AD DC admin tool samba-tool sends passwords in cleartext; (bso#15315); (bsc#1209481). * CVE-2023-0225: Samba AD DC "dnsHostname" attribute can be deleted by unprivileged authenticated users; (bso#15276); (bsc#1209483). * CVE-2023-0614: samba: Access controlled AD LDAP attributes can be discovered; (bso#15270); (bsc#1209485). * large_ldap test is inefficient; (bso#15332). * CVE-2020-25720 [SECURITY] Create Child permission should not allow full write to all attributes (additional changes); (bso#14810). - Update to 4.17.6 * streams_xattr is creating unexpected locks on folders; (bso#15314). * Use of the Azure AD Connect cloud sync tool is now supported for password hash synchronisation, allowing Samba AD Domains to synchronise passwords with this popular cloud environment; (bso#10635). * Spotlight doesn't work with latest macOS Ventura; (bso#15299). * New samba-dcerpc architecture does not scale gracefully; (bso#15310). * vfs_ceph incorrectly uses fsp_get_io_fd() instead of fsp_get_pathref_fd() in close and fstat; (bso#15307). * With clustering enabled samba-bgqd can core dump due to use after free; (bso#15293). * fd_load() function implicitly closes the fd where it should not; (bso#15311). - Update to 4.17.5 * smbc_getxattr() return value is incorrect; (bso#14808). * Compound SMB2 FLUSH+CLOSE requests from MacOSX are not handled correctly; (bso#15172). * synthetic_pathref AFP_AfpInfo failed errors; (bso#15210). * samba-tool gpo listall fails IPv6 only - finddcs() fails to find DC when there is only an AAAA record for the DC in DNS; (bso#15226). * smbd crashes if an FSCTL request is done on a stream handle; (bso#15236). * DFS links don't work anymore on Mac clients since 4.17; (bso#15277). * vfs_virusfilter segfault on access, directory edgecase (accessing NULL value); (bso#15283). * CVE-2022-38023 [SECURITY] Samba should refuse RC4 (aka md5) based SChannel on NETLOGON (additional changes); (bso#15240). * %U for include directive doesn't work for share listing (netshareenum); (bso#15243). * Shares missing from netshareenum response in samba 4.17.4; (bso#15266). * ctdb: use-after-free in run_proc; (bso#15269). * irpc_destructor may crash during shutdown; (bso#15280). * auth3_generate_session_info_pac leaks wbcAuthUserInfo; (bso#15286). * smbclient segfaults with use after free on an optimized build; (bso#15268). * smbstatus leaking files in msg.sock and msg.lock; (bso#15282). * Leak in wbcCtxPingDc2; (bso#15164). * Access based share enum does not work in Samba 4.16+; (bso#15265). * Crash during share enumeration; (bso#15267). * rep_listxattr on FreeBSD does not properly check for reads off end of returned buffer; (bso#15271). * Avoid relying on C89 features in a few places; (bso#15281).- Make (32bit) samba-libs conflict with old samba-ad-dc-libs package to satisfy installcheck.- Make samba-libs conflict with old samba-ad-dc-libs package to satisfy installcheck.- Remove non functioning ifup/ifdown samba-winbindd scripts; (bsc#1207414).- libdsdb-module-samba4 should be packaged as part of samba-libs and not samba-ad-dc-libs. Additionally no need for it to be removed conditionally.- Clean up logic for PAM migration settings in spec file.- Change with_dc default to 0 (for non TW builds), ADDC feature is deprecated and will no longer be included in >= SLE15-SP5; (jsc#PED-1122).- Update to 4.17.4 * CVE-2022-44640 Upstream Heimdal free of user-controlled pointer in FAST; (bsc#14929); * CVE-2021-20251 Bad password count not incremented atomically; (bsc#14611); * CVE-2022-42898 krb5_pac_parse() buffer parsing vulnerability; (bsc#15203); * CVE-2022-37966 rc4-hmac Kerberos session keys issued to modern servers; (bso#15237); * CVE-2022-37967 Kerberos constrained delegation ticket forgery possible against Samba AD DC; (bso#15231); * CVE-2022-38023 RC4/HMAC-MD5 NetLogon Secure Channel is weak and should be avoided; (bso#15240); * pam_winbind uses time_t and pointers assuming they are of the same size; (bso#15224); * Heimdal session key selection in AS-REQ examines wrong entry; (bso#15219); * filter-subunit is inefficient with large numbers of knownfails; (bso#15258); * smbd allows setting FILE_ATTRIBUTE_TEMPORARY on directories; (bso#15252); * The KDC logic arround msDs-supportedEncryptionTypes differs from Windows; (bso#13135); * libnet: change_password() doesn't work with dcerpc_samr_ChangePasswordUser4(); (bso#15206); * Heimdal session key selection in AS-REQ examines wrong entry; (bso#15219); * Memory leak in snprintf replacement functions; (bso#15230); * RODC doesn't reset badPwdCount reliable via an RWDC (CVE-2021-20251 regression); (bso#15253); * Prevent EBADF errors with vfs_glusterfs; (bso#15198); * %U for include directive doesn't work for share listing (netshareenum); (bso#15243); * Stack smashing in net offlinejoin requestodj; (bso#15257); * Windows 11 22H2 and Samba-AD 4.15 Kerberos login issue; (bso#15197); * Heimdal session key selection in AS-REQ examines wrong entry; (bso#15219); - Remove deprecated if-{down,up} scripts; (bsc#1206444); - Adjust the systemd drop-in file for named service; (bsc#1201689); * Paths are additive so do not repeat paths from named.service * Prefix the samba DLZ directory with "-" to ignore this path if it does not exists- Introduce without-smb1-server spec flag; (bsc#1205104); - Update to 4.17.3 * CVE-2022-42898: Samba buffer overflow vulnerabilities on 32-bit systems; (bsc#1205126); (bso#15203); - Replace obsolete python-gpgme with python-gpg * Upstream replaced it in v4.9.5 -- bso#13728 - Update to 4.17.2 * CVE-2022-3592 [SECURITY] samba: Wide links protection broken; (bso#15207); (bsc#1204499). * CVE-2022-3437 [SECURITY] samba: Buffer overflow in Heimdal unwrap_des3();(bso#15134); (bsc#1204254). - Update to 4.17.1 * CVE-2021-20251 [SECURITY] Bad password count not incremented atomically; (bso#14611). * smbXsrv_connection_shutdown_send result leaked; (bso#15174). * Flush on a named stream never completes; (bso#15182). * Permission denied calling SMBC_getatr when file not exists; (bso#15195). * Samba 4.5 sometimes cannot be upgraded to Samba 4.6 or later over DRS: WERROR_DS_DRA_MISSING_PARENT due to faulty GET_ANC; (bso#15189). * pytest: add file removal helpers for TestCaseInTempDir; (bso#15191). * CVE-2021-20251 [SECURITY] Bad password count not incremented atomically; (bso#14611). * Samba 4.5 sometimes cannot be upgraded to Samba 4.6 or later over DRS: WERROR_DS_DRA_MISSING_PARENT due to faulty GET_ANC; (bso#15189). * Flush on a named stream never completes; (bso#15182). * vfs_gpfs silently garbles timestamps > year 2106; (bso#15151). * CVE-2021-20251 [SECURITY] Bad password count not incremented atomically; (bso#14611). * multi-channel socket passing may hit a race if one of the involved processes already existed; (bso#15200). * memory leak on temporary of struct imessaging_post_state and struct tevent_immediate on struct imessaging_context (in rpcd_spoolss and maybe others); (bso#15201). * Since popt1.19 various use after free errors using result of poptGetArg are now exposed; (bso#15205); (boo#1204279). * Remove special case for O_CREAT in SMB_VFS_OPENAT from vfs_glusterfs; (bso#15192). * GETPWSID in memory cache grows indefinetly with each NTLM auth; (bso#15169). * CVE-2021-20251 [SECURITY] Bad password count not incremented atomically; (bso#14611). - Install a systemd drop-in file for named service to allow read/write access to the DLZ directory; (bsc#1201689); - Fix use after free errors resulting from using return of poptGetArg exposed since popt-1.19; (boo#1204279); (bso#15205). - s3: smbd: Fix memory leak in smbd_server_connection_terminate_done(); (bso#15174). - Disable SMB1 for tumbleweed builds. - Update to 4.17.0 * acl_xattr VFS module may unintentionally use filesystem permissions instead of ACL from xattr; (bso#15126). * Missing SMB2-GETINFO access checks from MS-SMB2 3.3.5.20.1; (bso#15153). * assert failed: !is_named_stream(smb_fname)") at ../../lib/util/fault.c:197; (bso#15161). * acl_xattr VFS module may unintentionally use filesystem permissions instead of ACL from xattr; (bso#15126). * assert failed: !is_named_stream(smb_fname)") at ../../lib/util/fault.c:197; (bso#15161). * Cross-node multi-channel reconnects result in SMB2 Negotiate returning NT_STATUS_NOT_SUPPORTED; (bso#15159). * winbind at info level debug can coredump when processing wb_lookupusergroups; (bso#15160). * Make use of glfs_*at() API calls in vfs_glusterfs; (bso#15157). * Possible use after free of connection_struct when iterating smbd_server_connection->connections; (bso#15128). * `net usershare add` fails with flag works with --long but fails with -l; (bso#15145). * acl_xattr VFS module may unintentionally use filesystem permissions instead of ACL from xattr; (bso#15126). * Performance regression on contended path based operations; (bso#15125). * Missing READ_LEASE break could cause data corruption; (bso#15148). * libsamba-errors uses a wrong version number; (bso#15141). * SMB1 negotiation can fail to handle connection errors; (bso#15152). * New filename parser doesn't check veto files smb.conf parameter; (bso#15143). * 4.17.rc1 still uses symlink-race prone unix_convert(); (bso#15144). * Backport fileserver related changed to 4.17.0rc2; (bso#15146). * Manpage for smbstatus json is missing; (bso#15147). * Backport fileserver related changed to 4.17.0rc2; (bso#15146). * Performance regression on contended path based operations; (bso#15125). * Backport fileserver related changed to 4.17.0rc2; (bso#15146). * Fix issues found by coverity in smbstatus json code; (bso#15140). * Backport fileserver related changed to 4.17.0rc2; (bso#15146). - Migration to /usr/etc: Saving user changed configuration files in /etc and restoring them while an RPM update. - Update to 4.16.4 * CVE-2022-2031: Samba AD users can bypass certain restrictions associated with changing passwords; (bsc#1201495); (bso#15047); * CVE-2022-32744: Samba AD users can forge password change requests for any user; (bsc#1201493); (bso#15074); * CVE-2022-32745: Samba AD users can crash the server process with an LDAP add or modify request; (bsc#1201492); (bso#15008); * CVE-2022-32746: Samba AD users can induce a use-after-free in the server process with an LDAP add or modify request; (bsc#1201490); (bso#15009); * CVE-2022-32742: Server memory information leak via SMB1; (bsc#1201496); (bso#15085); - Update to 4.16.3 * Using vfs_streams_xattr and deleting a file causes a panic; (bso#15099); * Add support for bind 9.18; (bso#14986); * logging dsdb audit to specific files does not work; (bso#15076); * Problem when winbind renews Kerberos; (bso#14979); (bsc#1196224); * Samba with new lorikeet-heimdal fails to build on gcc 12.1 in developer mode; (bso#15095); * Crash in streams_xattr because fsp->base_fsp->fsp_name is NULL; (bso#15105); * Crash in rpcd_classic - NULL pointer deference in mangle_is_mangled(); (bso#15118); * smbclient commands del & deltree fail with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556); * Fix check for chown when processing NFSv4 ACL; (bso#15120); * The pcap background queue process should not be stopped; (bso#15082); * testparm: Fix typo in idmap rangesize check; (bso#15097); * net ads info returns LDAP server and LDAP server name as null; (bso#15106); * ldconfig: /lib64/libsmbconf.so.0 is not a symbolic link; (bso#15108); * CTDB child process logging does not work as expected; (bso#15090); - Update spec file to fix the optional Heimdal DC build - Fix external trusts with MIT Kerberos 1.20 - Add missing samba-client requirement to samba-winbind package; (bsc#1198255); - Move pdb backends from package samba-libs to package samba-client-libs and remove samba-libs requirement from samba-winbind; (bsc#1200964); (bsc#1198255); - Add sysuser-shadow requirement for packages using systemd-sysusers - Use the canonical realm name to refresh the Kerberos tickets; (bsc#1196224); (bso#14979); - Moved logrotate files from user specific directory /etc/logrotate.d to vendor specific directory /usr/etc/logrotate.d. - Update to 4.16.2 * Use pathref fd instead of io fd in vfs_default_durable_cookie; (bso#15042); * vfs_gpfs with vfs_shadowcopy2 fail to restore file if original file had been deleted; (bso#15069); * Reintroduce netgroups support; (bso#15087); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); * Update from 4.15 to 4.16 breaks discovery of [homes] on standalone server from Win and IOS; (bso#15062); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * smbclient -E doesn't work as advertised; (bso#15075); * The samba background daemon doesn't refresh the printcap cache on startup; (bso#15081); * Out-by-4 error in smbd read reply max_send clamp; (bso#14443); - Fix samba4.blackbox.net_ads_dns_async test with bind9 >= 9.17.7 - Support building with MIT Kerberos 1.20 - Bronze bit and S4U support with MIT Kerberos 1.20 for Samba AD DC; (CVE-2020-17049); - Resource Based Constrained Delegation (RBCD) for Samba AD DC - Support building with gcc 12.1 - Use requires_eq macro to require the libldb2 version available at samba-dsdb-modules build time; (bsc#1199362); - Update to 4.16.1 * Share and server swapped in smbget password prompt; (bso#14831); * Durable handles won't reconnect if the leased file is written to; (bso#15022); * rmdir silently fails if directory contains unreadable files and hide unreadable is yes; (bso#15023); * SMB2_CLOSE_FLAGS_FULL_INFORMATION fails to return information on renamed file handle; (bso#15038); * Need to describe --builtin-libraries= better (compare with - -bundled-libraries); (bso#8731); * vfs_shadow_copy2 breaks "smbd async dosmode" sync fallback; (bso#14957); * shadow_copy2 fails listing snapshotted dirs with shadow:fixinodes; (bso#15035); * PAM Kerberos authentication incorrectly fails with a clock skew error; (bso#15046); * Username map - samba erroneously applies unix group memberships to user account entries; (bso#15041); * KVNO off by 100000; (bso#14951); * Uninitialized litemask in variable in vfs_gpfs module; (bso#15027); * vfs_gpfs recalls=no option prevents listing files; (bso#15055); * smbd doesn't handle UPNs for looking up names; (bso#15054); - Update update-apparmor-samba-profile script, replace non-printable delimiter with more human readable separator as sed can accept separators that can appear in the input data. - Fix update-apparmor-samba-profile script, sed doesn't like multibyte separators; (bsc#1198309). - Update to 4.16.0 * New samba-dcerpcd binary to provide DCERPC in the member server setup * Certificate Auto Enrollment * Ability to add ports to dns forwarder addresses in internal DNS backend * No longer using Linux mandatory locks for sharemodes * SMB1 protocol has been deprecated, particularly older dialects * SMB1 protocol SMBCopy command removed * SMB1 server-side wildcard expansion removed - Add python3-dnspython to samba-ad-dc recommens; (bsc#1187101); - Use systemd-sysusers to create system users; (bsc#1182847);- Install a systemd drop-in file for named service to allow read/write access to the DLZ directory; (bsc#1201689);- Update to 4.15.12 * CVE-2022-42898: samba: heimdal: Samba buffer overflow vulnerabilities on 32-bit systems; (bso#15203); (bsc#1205126). - Update to 4.15.11 * Allow rebuild of Centos 8 images after move to vault for Samba 4.15; (bso#15193). * CVE-2022-3437: samba: Buffer overflow in Heimdal unwrap_des3(); (bso#15134); (bsc#1204254)- Update to 4.15.10 * Possible use after free of connection_struct when iterating smbd_server_connection->connections; (bso#15128); (bsc#1200102). * smbXsrv_connection_shutdown_send result leaked; (bso#15174). * Spotlight RPC service returns wrong response when Spotlight is disabled on a share; (bso#15086). * acl_xattr VFS module may unintentionally use filesystem permissions instead of ACL from xattr; (bso#15126). * Missing SMB2-GETINFO access checks from MS-SMB2 3.3.5.20.1; (bso#15153). * assert failed: !is_named_stream(smb_fname)") at ../../lib/util/fault.c:197; (bso#15161). * Missing READ_LEASE break could cause data corruption; (bso#15148). * rpcclient can crash using setuserinfo(2); (bso#15124). * Samba fails to build with glibc 2.36 caused by including in libreplace; (bso#15132). * SMB1 negotiation can fail to handle connection errors; (bso#15152). * samba-tool domain join segfault when joining a samba ad domain; (bso#15078). - Update to 4.15.9 * CVE-2022-32742:SMB1 code does not correct verify SMB1write, SMB1write_and_close, SMB1write_and_unlock lengths; (bso#15085); (bsc#1201496). * CVE-2022-32746: samba: Use-after-free occurring in database audit logging; (bso#15009); (bso#15096); (bsc#1201490). * CVE-2022-2031: samba, ldb: AD users can bypass certain restrictions associated with changing passwords; (bso#15047); (bsc#1201495); * CVE-2022-32745: samba: ldb: AD users can crash the server process with an LDAP add or modify request; (bso#15008); (bso#15096); (bsc#1201492). * CVE-2022-2031: samba, ldb: AD users can bypass certain restrictions associated with changing passwords; (bso#15047); (bsc#1201495); * CVE-2022-32744: samba, ldb: AD users can forge password change requests for any user; (bso#15074); (bso#15047); (bsc#1201493).- CVE-2022-1615: Do not ignore errors in random number generation; (bso#15103); (bsc#1202976); - CVE-2022-32743: Implement validated dnsHostName write rights; (bso#14833); (bsc#1202803);- Fix Use after free when iterating smbd_server_connection->connections after tree disconnect failure; (bso#15128); (bsc#1200102).- CVE-2022-32746: samba: Use-after-free occurring in database audit logging; (bso#15009); (bso#15096); (bsc#1201490). - CVE-2022-32745: samba: ldb: AD users can crash the server process with an LDAP add or modify request; (bso#15008); (bso#15096); (bsc#1201492). - CVE-2022-2031: samba, ldb: AD users can bypass certain restrictions associated with changing passwords; (bso#15047); (bsc#1201495); - CVE-2022-32742:SMB1 code does not correct verify SMB1write, SMB1write_and_close, SMB1write_and_unlock lengths; (bso#15085); (bsc#1201496). - CVE-2022-32744: samba, ldb: AD users can forge password change requests for any user; (bso#15074); (bso#15047); (bsc#1201493).- Update to 4.15.8 * Use pathref fd instead of io fd in vfs_default_durable_cookie; (bso#15042); * Setting fruit:resource = stream in vfs_fruit causes a panic; (bso#15099); * Add support for bind 9.18; (bso#14986); * logging dsdb audit to specific files does not work; (bso#15076); * vfs_gpfs with vfs_shadowcopy2 fail to restore file if original file had been deleted; (bso#15069); * netgroups support removed; (bso#15087); (bsc#1199247); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); (bsc#1199734); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * smbclient commands del & deltree fail with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556); * vfs_gpfs recalls=no option prevents listing files; (bso#15055); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * Compile error in source3/utils/regedit_hexedit.c; (bso#15091); * ldconfig: /lib64/libsmbconf.so.0 is not a symbolic link; (bso#15108); * smbd doesn't handle UPNs for looking up names; (bso#15054); * Out-by-4 error in smbd read reply max_send clamp; (bso#14443); - Move pdb backends from package samba-libs to package samba-client-libs and remove samba-libs requirement from samba-winbind; (bsc#1200964); (bsc#1198255); - Use the canonical realm name to refresh the Kerberos tickets; (bsc#1196224); (bso#14979);- Fix smbclient commands del & deltree failing with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556).- Revert NIS support removal; (bsc#1199247);- Use requires_eq macro to require the libldb2 version available at samba-dsdb-modules build time; (bsc#1199362);- Add missing samba-client requirement to samba-winbind package; (bsc#1198255);- Update to 4.15.7 * Share and server swapped in smbget password prompt; (bso#14831); * Durable handles won't reconnect if the leased file is written to; (bso#15022); * rmdir silently fails if directory contains unreadable files and hide unreadable is yes; (bso#15023); * SMB2_CLOSE_FLAGS_FULL_INFORMATION fails to return information on renamed file handle; (bso#15038); * vfs_shadow_copy2 breaks "smbd async dosmode" sync fallback; (bso#14957); * shadow_copy2 fails listing snapshotted dirs with shadow:fixinodes; (bso#15035); * PAM Kerberos authentication incorrectly fails with a clock skew error; (bso#15046); * username map - samba erroneously applies unix group memberships to user account entries; (bso#15041); * NT_STATUS_ACCESS_DENIED translates into EPERM instead of EACCES in SMBC_server_internal; (bso#14983); * Simple bind doesn't work against an RODC (with non-preloaded users); (bso#13879); * Crash of winbind on RODC; (bso#14641); * uncached logon on RODC always fails once; (bso#14865); * KVNO off by 100000; (bso#14951); * LDAP simple binds should honour "old password allowed period"; (bso#15001); * wbinfo -a doesn't work reliable with upn names; (bso#15003); * Simple bind doesn't work against an RODC (with non-preloaded users); (bso#13879); * Uninitialized litemask in variable in vfs_gpfs module; (bso#15027); * Regression: create krb5 conf = yes doesn't work with a single KDC; (bso#15016);- Add provides to samba-client-libs package to fix upgrades from previous versions; (bsc#1197995);- Add missing samba-libs requirement to samba-winbind package; (bsc#1198255);- Update to 4.15.6 * Renaming file on DFS root fails with NT_STATUS_OBJECT_PATH_NOT_FOUND; (bso#14169); * Samba does not response STATUS_INVALID_PARAMETER when opening 2 objects with same lease key; (bso#14737); * NT error code is not set when overwriting a file during rename in libsmbclient; (bso#14938); * Fix ldap simple bind with TLS auditing; (bso#14996); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); * Problem when winbind renews Kerberos; (bso#14979); (bsc#1196224); * pam_winbind will not allow gdm login if password about to expire; (bso#8691); * virusfilter_vfs_openat: Not scanned: Directory or special file; (bso#14971); * DFS fix for AIX broken; (bso#13631); * Solaris and AIX acl modules: wrong function arguments; (bso#14974); * Function aixacl_sys_acl_get_file not declared / coredump; (bso#7239); * Regression: Samba 4.15.2 on macOS segfaults intermittently during strcpy in tdbsam_getsampwnam; (bso#14900); * Fix a use-after-free in SMB1 server; (bso#14989); * smb2_signing_decrypt_pdu() may not decrypt with gnutls_aead_cipher_decrypt() from gnutls before 3.5.2; (bso#14968); * Changing the machine password against an RODC likely destroys the domain join; (bso#14984); * authsam_make_user_info_dc() steals memory from its struct ldb_message *msg argument; (bso#14993); * Use Heimdal 8.0 (pre) rather than an earlier snapshot; (bso#14995); * Samba autorid fails to map AD users if id rangesize fits in the id range only once; (bso#14967);- Fix mismatched version of libldb2; (bsc#1196788). - Drop obsolete SuSEfirewall2 service files.- Drop obsolete Samba fsrvp v0->v1 state upgrade functionality; (bsc#1080338).- Fix ntlm authentications with "winbind use default domain = yes"; (bso#13126); (bsc#1173429); (bsc#1196308).- Fix samba-ad-dc status warning notification message by disabling systemd notifications in bgqd; (bsc#1195896); (bso#14947).- libldb version mismatch in Samba dsdb component; (bsc#1118508);- Update to 4.15.5 * CVE-2021-44141: UNIX extensions in SMB1 disclose whether the outside target of a symlink exists; (bso#14911); (bsc#1193690). * CVE-2021-44142: Out-of-Bound Read/Write on Samba vfs_fruit module; (bso#14914); (bsc#1194859). * CVE-2022-0336: Re-adding an SPN skips subsequent SPN conflict checks; bso#14950); (bsc#1195048).- CVE-2021-44141: Information leak via symlinks of existance of files or directories outside of the exported share; (bso#14911); (bsc#1193690); - CVE-2021-44142: Out-of-bounds heap read/write vulnerability in VFS module vfs_fruit allows code execution; (bso#14914); (bsc#1194859); - CVE-2022-0336: Samba AD users with permission to write to an account can impersonate arbitrary services; (bso#14950); (bsc#1195048);- Update to 4.15.4 * Duplicate SMB file_ids leading to Windows client cache poisoning; (bso#14928); * Failed to parse NTLMv2_RESPONSE length 95 - Buffer Size Error - NT_STATUS_BUFFER_TOO_SMALL; (bso#14932); * kill_tcp_connections does not work; (bso#14934); * Can't connect to Windows shares not requiring authentication using KDE/Gnome; (bso#14935); * smbclient -L doesn't set "client max protocol" to NT1 before calling the "Reconnecting with SMB1 for workgroup listing" path; (bso#14939); * Cross device copy of the crossrename module always fails; (bso#14940); * symlinkat function from VFS cap module always fails with an error; (bso#14941); * Fix possible fsp pointer deference; (bso#14942); * Missing pop_sec_ctx() in error path inside close_directory(); (bso#14944); * "smbd --build-options" no longer works without an smb.conf file; (bso#14945);- Use pkgconfig(krb5) as dependency for the -devel package: allow OBS to pick the right flavor of krb5-devel (full vs mini). - Do not require the 'krb5' symbol by samba-client-libs: this package has an automatic dependency due to linkage on libgssapi_krb5.so.2. Automatic deps are always better. - Do not require the 'krb5' symbol from samba-libs: samba-libs requires samba-client-libs, which in turn requires krb5 libraries. Samba-libs itself has no need for krb5 (but get it indirectly anyway).- Reorganize libs packages. Split samba-libs into samba-client-libs, samba-libs, samba-winbind-libs and samba-ad-dc-libs, merging samba public libraries depending on internal samba libraries into these packages as there were dependency problems everytime one of these public libraries changed its version (bsc#1192684). The devel packages are merged into samba-devel. - Rename package samba-core-devel to samba-devel - Add python-rpm-macros to build requirements - Update the symlink create by samba-dsdb-modules to private samba ldb modules following libldb2 changes from /usr/lib64/ldb/samba to /usr/lib64/ldb2/modules/ldb/samba- Update to 4.15.3 * Recursive directory delete with veto files is broken in 4.15.0; (bso#14878); * A directory containing dangling symlinks cannot be deleted by SMB2 alone when they are the only entry in the directory; (bso#14879); * SIGSEGV in rmdir_internals/synthetic_pathref - dirfsp is used uninitialized in rmdir_internals(); (bso#14892); * MaxQueryDuration not honoured in Samba AD DC LDAP; (bso#14694); * The CVE-2020-25717 username map [script] advice has undesired side effects for the local nt token; (bso#14901); (bsc#1192849); * User with multiple spaces (eg FredNurk) become un-deletable; (bso#14902); * Avoid storing NTTIME_THAW (-2) as value on disk; (bso#14127); * smbXsrv_client_global record validation leads to crash if existing record points at non-existing process; (bso#14882); * Crash in vfs_fruit asking for fsp_get_io_fd() for an XATTR call; (bso#14890); * Samba process doesn't log to logfile; (bso#14897); * set_ea_dos_attribute() fallback calling get_file_handle_for_metadata() triggers locking.tdb assert; (bso#14907); * Kerberos authentication on standalone server in MIT realm broken; (bso#14922); * Segmentation fault when joining the domain; (bso#14923); * Support for ROLE_IPA_DC is incomplete; (bso#14903); * rpcclient cannot connect to ncacn_ip_tcp services anymore; (bso#14767); * winexe crashes since 4.15.0 after popt parsing; (bso#14893); * net ads status -P broken in a clustered environment; (bso#14908); * Memory leak if ioctl(FSCTL_VALIDATE_NEGOTIATE_INFO) fails before smbd_smb2_ioctl_send; (bso#14788); * winbindd doesn't start when "allow trusted domains" is off; (bso#14899); * smbclient login without password using '-N' fails with NT_STATUS_INVALID_PARAMETER on Samba AD DC; (bso#14883); * A schannel client incorrectly detects a downgrade connecting to an AES only server; (bso#14912); * Possible null pointer dereference in winbind; (bso#14921); * Fix -k legacy option for client tools like smbclient, rpcclient, net, etc.; (bso#14846); * Add Debian 11 CI bootstrap support; (bso#14872); * Crash in recycle_unlink_internal(); (bso#14888);- Fix dependency problem upgrading from libndr0 to libndr2 and from libsamba-credentials0 to libsamba-credentials1; (bsc#1192684);- Fix regression introduced by CVE-2020-25717 patches, winbindd does not start when 'allow trusted domains' is off; (bso#14899); - Update to 4.15.2 * CVE-2016-2124: SMB1 client connections can be downgraded to plaintext authentication; (bso#12444); (bsc#1014440); * CVE-2020-25717: A user on the domain can become root on domain members; (bso#14556); (bsc#1192284); * CVE-2020-25718: Samba AD DC did not correctly sandbox Kerberos tickets issued by an RODC; (bso#14558); (bsc#1192246); * CVE-2020-25719: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets; (bso#14561); (bsc#1192247); * CVE-2020-25721: Kerberos acceptors need easy access to stable AD identifiers (eg objectSid); (bso#14557); (bsc#1192505); * CVE-2020-25722: Samba AD DC did not do suffienct access and conformance checking of data stored; (bso#14564); (bsc#1192283); * CVE-2021-3738: Use after free in Samba AD DC RPC server; (bso#14468); (bsc#1192215); * CVE-2021-23192: Subsequent DCE/RPC fragment injection vulnerability; (bso#14875); (bsc#1192214); - Update to 4.15.1 * vfs_shadow_copy2: core dump in make_relative_path; (bso#14682); * Log clutter from filename_convert_internal; (bso#14685); * MacOSX compilation fixes; (bso#14862); * rodc_rwdc test flaps; (bso#14868); * Provide a fix for MS CVE-2020-17049 in Samba [SECURITY] 'Bronze bit' S4U2Proxy Constrained Delegation bypass in Samba with embedded Heimdal; (bso#14642); * Python ldb.msg_diff() memory handling failure; (bso#14836); * "in" operator on ldb.Message is case sensitive; (bso#14845); * Release LDB 2.4.1 for Samba 4.15.1; (bso#14848); * samldb_krbtgtnumber_available() looks for incorrect string; (bso#14854); * Fix Samba support for UF_NO_AUTH_DATA_REQUIRED; (bso#14871); * Allow special chars like "@" in samAccountName when generating the salt; (bso#14874); * Correctly ignore comments in CTDB public addresses file; (bso#14826); * Fix transit path validation; (bso#12998); * Fix that child winbindd logs to log.winbindd instead of log.wb-; (bso#14852); * SMB3 cancel requests should only include the MID together with AsyncID when AES-128-GMAC is used; (bso#14855); * Prepare to operate with MIT krb5 >= 1.20; (bso#14870); * Heimdal prefers RC4 over AES for machine accounts; (bso#14864);- Enable samba-tool without ad dc.- Adjust spec to use pam macros; (bsc#1191046).- Adjust spec for size * allow some Recommends instead Requires to be configured for cifs-utils, samba-libs-python3 & samba-gpupdate; (bsc#1182847). * remove fam, undocumented and unneeded.- Add missing build dependency on bison when building with the embedded Heimdal Kerberos- Update to 4.15.0 * Removed SMB development dialects SMB2_22, SMB2_24 and SMB3_10 * VFS layer modernized. * Add the ability to set allow/deny lists for zone transfer clients in Bind DLZ plugin * Server multi-channel support no longer experimental * Improved command line user experience, unifying the options in different commands * Winbindd no longer scans trusted domains on startup and will use enterprise principals by default. * The net utility is now able to support the offline domain join feature * New options for 'samba-tool dns zoneoptions' for aging control and to mark old records as static or dynamic * DNS tombstones are now deleted as appropriate and use a consistent timestamp format * The 'samba-tool dns update' command validates and rejects now malformed IPv4 and IPv6 addresses * The 'samba-tool domain backup' command correctly takes out locks against concurrent modification during backup when using the LMDB backend * TruACL support has been removed * NIS support has been removed- Fix 'net rpc' authentication when using the machine account; (bsc#1189017); (bso#14796);- Fix dependency problem upgrading from libndr0 to libndr1; (bsc#1189875); - Fix dependency problem upgrading from libsmbldap0 to libsmbldap2; (bsc#1189875); - Fix wrong kvno exported to keytab after net ads changetrustpw due to replication delay; (bsc#1188727); - Add Certificate Auto Enrollment Policy; (jsc#SLE-18456). - Update to 4.13.10 * s3: smbd: Ensure POSIX default ACL is mapped into returned Windows ACL for directory handles; (bso#14708); * Take a copy to make sure we don't reference free'd memory; (bso#14721); * s3: lib: Fix talloc heirarcy error in parent_smb_fname(); (bso#14722); * s3: smbd: Remove erroneous TALLOC_FREE(smb_fname_parent) in change_file_owner_to_parent() error path; (bso#14736); * samba-tool: Give better error information when the 'domain backup restore' fails with a duplicate SID; (bso#14575); * smbd: Correctly initialize close timestamp fields; (bso#14714); * Spotlight RPC service doesn't work with vfs_glusterfs; (bso#14740); * ctdb: Fix a crash in run_proc_signal_handler(); (bso#14475); * gensec_krb5: Restore ipv6 support for kpasswd; (bso#14750); * smbXsrv_{open,session,tcon}: Protect smbXsrv_{open,session,tcon}_global_traverse_fn against invalid records; (bso#14752); * samba-tool domain backup offline doesn't work against bind DLZ backend; (bso#14027); * netcmd: Use next_free_rid() function to calculate a SID for restoring a backup; (bso#14669); - Update to 4.13.9 * s3: smbd: SMB1 SMBsplwr doesn't send a reply packet on success; (bso#14696); * Add documentation for dsdb_group_audit and dsdb_group_json_audit to "log level", synchronise "log level" in smb.conf with the code; (bso#14689); * Fix smbd panic when two clients open same file; (bso#14672); * Fix memory leak in the RPC server; (bso#14675); * s3: smbd: Fix deferred renames; (bso#14679); * s3-iremotewinspool: Set the per-request memory context; (bso#14675); * rpc_server3: Fix a memleak for internal pipes; (bso#14675); * third_party: Update socket_wrapper to version 1.3.2; (bso#11899); * third_party: Update socket_wrapper to version 1.3.3; (bso#14639); * idmap_rfc2307 and idmap_nss return wrong mapping for uid/gid conflict; (bso#14663); * Fix the build on OmniOS; (bso#14288); - Update to 4.13.8 * CVE-2021-20254: Fix buffer overrun in sids_to_unixids(); (bso#14571 - Update to 4.13.7 * Release with dependency on ldb version 2.2.1.- CVE-2021-20254 Buffer overrun in sids_to_unixids(); (bnc#14571); (bsc#1184677).- Fix offline domain backup not possible using lmdb version >= 0.9.26; (bso#14676); - Require libldb >= 2.2.1; (bsc#1183572); (bsc#1183574); - Update to 4.13.6 * CVE-2020-27840: samba: Unauthenticated remote heap corruption via bad DNs; (bso#14595); (bsc#1183572). * CVE-2021-20277: samba: out of bounds read in ldb_handler_fold; (bso#14655); (bsc#1183574). - Update to 4.13.5 * s3:modules:vfs_virusfilter: Recent talloc changes cause infinite start-up failure; (bso#14634); * s3: libsmb: Add missing cli_tdis() in error path if encryption setup failed on temp proxy connection; (bso#13992); * smbd: In conn_force_tdis_done() when forcing a connection closed force a full reload of services; (bso#14604); * dbcheck: Check Deleted Objects and reduce noise in reports about expired tombstones (bso#14593); * s3: Fix fcntl waf configure check; (bso#14503); * s3/auth: Implement "winbind:ignore domains"; (bso#14602); * smbd: Use fsp->conn->session_info for the initial delete-on-close token; (bso#14617); * s3: VFS: nfs4_acls. Add missing TALLOC_FREE(frame) in error path; (bso#14648); * classicupgrade: Treat old never expires value right; (bso#14624); * g_lock: Fix uninitalized variable reads; (bso#14636); * s3:pysmbd: Fix fd leak in py_smbd_create_file(); (bso#13898); * lib:util: Avoid free'ing our own pointer; (bso#14625); * HEIMDAL: krb5_storage_free(NULL) should work; (bso#12505);- Spec file fixes around systemd and requires; (bsc#1182830); - Align systemd service unit files with upstream provided ones.- Update to 4.13.4 * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * lib: Avoid declaring zero-length VLAs in various messaging functions; (bso#14605); * Do not create an empty DB when accessing a sam.ldb; (bso#14579); * vfs_fruit may close wrong backend fd; (bso#14596); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * vfs_virusfilter: Allocate separate memory for config char*; (bso#14606); * vfs_fruit may close wrong backend fd; (bso#14596); * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * The cache directory for the user gencache should be created recursively; (bso#14601); * Be more flexible with repository names in CentOS 8 test environments; (bso#14594);- Uninstalling samba-client: Failed to disable unit, cifs.service does not exists; (bsc#1180388);- Update to 4.13.3 + libcli: smb2: Never print length if smb2_signing_key_valid() fails for crypto blob; (bso#14210); + s3: modules: gluster. Fix the error I made in preventing talloc leaks from a function; (bso#14486); + s3: smbd: Don't overwrite contents of fsp->aio_requests[0] with NULL via TALLOC_FREE(); (bso#14515); + s3: spoolss: Make parameters in call to user_ok_token() match all other uses; (bso#14568); + s3: smbd: Quiet log messages from usershares for an unknown share; (bso#14590); + samba process does not honor max log size; (bso#14248); + vfs_zfsacl: Add missing inherited flag on hidden "magic" everyone@ ACE; (bso#14587); + s3-libads: Pass timeout to open_socket_out in ms; (bso#13124); + s3-vfs_glusterfs: Always disable write-behind translator; (bso#14486); + smbclient: Fix recursive mget; (bso#14517); + clitar: Use do_list()'s recursion in clitar.c; (bso#14581); + manpages/vfs_glusterfs: Mention silent skipping of write-behind translator; (bso#14486); + vfs_shadow_copy2: Preserve all open flags assuming ROFS; (bso#14573); + interface: Fix if_index is not parsed correctly; (bso#14514);- Update to 4.13.2 + s3: modules: vfs_glusterfs: Fix leak of char **lines onto mem_ctx on return; (bso#14486); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471); + smb.conf.5: Add clarification how configuration changes reflected by Samba; (bso#14538); + daemons: Report status to systemd even when running in foreground; (bso#14552); + DNS Resolver: Support both dnspython before and after 2.0.0; (bso#14553); + s3-vfs_glusterfs: Refuse connection when write-behind xlator is present; (bso#14486); + provision: Add support for BIND 9.16.x; (bso#14487); + ctdb-common: Avoid aliasing errors during code optimization; (bso#14537); + libndr: Avoid assigning duplicate versions to symbols; (bso#14541); + docs: Fix default value of spoolss:architecture; (bso#14522); + winbind: Fix a memleak; (bso#14388); + s4:dsdb:acl_read: Implement "List Object" mode feature; (bso#14531); + docs-xml/manpages: Add warning about write-behind translator for vfs_glusterfs; (bso#14486); + nsswitch/nsstest.c: Avoid nss function conflicts with glibc nss.h. + vfs_shadow_copy2: Avoid closing snapsdir twice; (bso#14530); + third_party: Update resolv_wrapper to version 1.1.7; (bso#14547); + examples:auth: Do not install example plugin; (bso#14550); + ctdb-recoverd: Drop unnecessary and broken code; (bso#14513); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471);- Adjust smbcacls '--propagate-inheritance' feature to align with upstream; (bsc#1178469).- Update to samba 4.13.1 + CVE-2020-14383: An authenticated user can crash the DCE/RPC DNS with easily crafted records; (bsc#1177613); (bso#14472); + CVE-2020-14323: Unprivileged user can crash winbind; (bsc#1173994); (bso#14436); + CVE-2020-14318: Missing handle permissions check in SMB1/2/3 ChangeNotify; (bsc#1173902); (bso#14434); - Adjust systemd tmpfiles.d configuration, use /run/samba instead of /var/run/samba; (bsc#1177355);- Fix vfs_ceph query_directory regression; (bso#14519) - Drop liburing-devel for SLE15-SP2; (bsc#1177245)- Register CTDB recovery lock holder with ceph-mgr - Add liburing-devel dependency- Update to samba 4.13.0 + Require Python 3.6 + Move wide links functionality into VFS module + Deprecate NT4-like 'classic' Samba domain controllers + Deprecate SMBv1 only protocol options + Remove deprecated "ldap ssl ads" option + Unify asynchronous DCE-RPC server; (jsc#SES-645) + Replay multichannel lease break requests; (bso#11897); (jsc#SES-655) + Drop internal byteorder.h header from util-devel package + Remove final code for the AD DC LDAP backend + Add AD DC Group Policy Scripts + Only use gnutls_aead_cipher_encryptv2() for GnuTLS > 3.6.14; (bso#14399) + Fix %U substitutions if it contains a domain name; (bso#14467) + Fix krb5.conf creation for 'net ads join'; (bso#14479) + Fix build problem if libbsd-dev is not installed; (bso#14482) + Toggle vfs_snapper using "--with-shared-modules"; (bso#14437) + Fix idmap_ad RFC4511 response handling; (bso#14465) + Fix panic in get_lease_type(); (bso#14428)- Update to samba 4.11.13 + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Protect netr_ServerPasswordSet2 against unencrypted passwords; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Support "server require schannel:WORKSTATION$ = no" about unsecure configurations; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s4 torture rpc: repeated bytes in client challenge; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): libcli/auth: Reject weak client challenges in netlogon_creds_server_init() "server require schannel:WORKSTATION$ = no"; (bsc#1176579); (bso#14497); - Update to samba 4.11.12 + s3: libsmb: Fix SMB2 client rename bug to a Windows server; (bso#14403); + dsdb: Allow "password hash userPassword schemes = CryptSHA256" to work on RHEL7; (bso#14424); + dbcheck: Allow a dangling forward link outside our known NCs; (bso#14450); + lib/debug: Set the correct default backend loglevel to MAX_DEBUG_LEVEL; (bso#14426); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + lib/util: do not install "test_util_paths"; (bso#14370); + lib:util: Fix smbclient -l basename dir; (bso#14345); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + util: Allow symlinks in directory_create_or_exist; (bso#14166); + docs: Fix documentation for require_membership_of of pam_winbind; (bso#14358); + s3:winbind:idmap_ad: Make failure to get attrnames for schema mode fatal; (bso#14425);- Add obsoletes to libsmbldap2 package to fix upgrades from previous versions; (bsc#1172810);- Fix net command unable to negotiate SMB2; (bsc#1174120);- Update to samba 4.11.11 + CVE-2020-10730: NULL de-reference in AD DC LDAP server when ASQ and VLV combined; (bso#14364); (bsc#1173159] + CVE-2020-10745: invalid DNS or NBT queries containing dots use several seconds of CPU each; (bso#14378); (bsc#1173160). + CVE-2020-10760: Use-after-free in AD DC Global Catalog LDAP server with paged_result or VLV; (bso#14402); (bsc#1173161) + CVE-2020-14303: Endless loop from empty UDP packet sent to AD DC nbt_server; (bso#14417); (bsc#1173359). - Update to samba 4.11.10 + Fix segfault when using SMBC_opendir_ctx() routine for share folder that contains incorrect symbols in any file name; (bso#14374). + vfs_shadow_copy2 doesn't fail case looking in snapdirseverywhere mode; (bso#14350) + ldb_ldap: Fix off-by-one increment in lldb_add_msg_attr; (bso#14413). + Malicous SMB1 server can crash libsmbclient; (bso#14366) + winbindd: Fix a use-after-free when winbind clients exit; (bso#14382) + ldb: Bump version to 2.0.11, LMDB databases can grow without bounds. (bso#14330) - Update to samba 4.11.9 + nmblib: Avoid undefined behaviour in handle_name_ptrs(); (bso#14242). + 'samba-tool group' commands do not handle group names with special chars correctly; (bso#14296). + smbd: avoid calling vfs_file_id_from_sbuf() if statinfo is not valid; (bso#14237). + Missing check for DMAPI offline status in async DOS attributes; (bso#14293). + smbd: Ignore set NTACL requests which contain S-1-5-88 NFS ACEs; (bso#14307). + vfs_recycle: Prevent flooding the log if we're called on non-existant paths; (bso#14316) + smbd mistakenly updates a file's write-time on close; (bso#14320). + RPC handles cannot be differentiated in source3 RPC server; (bso#14359). + librpc: Fix IDL for svcctl_ChangeServiceConfigW; (bso#14313). + nsswitch: Fix use-after-free causing segfault in _pam_delete_cred; (bso#14327). + Fix fruit:time machine max size on arm; (bso#13622) + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294). + ctdb: Fix a memleak; (bso#14348). + libsmb: Don't try to find posix stat info in SMBC_getatr(). + ctdb-tcp: Move free of inbound queue to TCP restart; (bso#14295); (bsc#1162680). + s3/librpc/crypto: Fix double free with unresolved credential cache; (bso#14344); (bsc#1169095) + s3:libads: Fix ads_get_upn(); (bso#14336). + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294) + Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680). + ctdb-recoverd: Avoid dereferencing NULL rec->nodemap; (bso#14324) - Update to samba 4.11.8 + CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850); + CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - Update to samba 4.11.7 + s3: lib: nmblib. Clean up and harden nmb packet processing; (bso#14239). + s3: VFS: full_audit. Use system session_info if called from a temporary share definition; (bso#14283) + dsdb: Correctly handle memory in objectclass_attrs; (bso#14258). + ldb: version 2.0.9, Samba 4.11 and later give incorrect results for SCOPE_ONE searches; (bso#14270) + auth: Fix CIDs 1458418 and 1458420 Null pointer dereferences; (bso#14247). + smbd: Handle EINTR from open(2) properly; (bso#14285) + winbind member (source3) fails local SAM auth with empty domain name; (bso#14247) + winbindd: Handling missing idmap in getgrgid(); (bso#14265). + lib:util: Log mkdir error on correct debug levels; (bso#14253). + wafsamba: Do not use 'rU' as the 'U' is deprecated in Python 3.9; (bso#14266). + ctdb-tcp: Make error handling for outbound connection consistent; (bso#14274). - Update to samba 4.11.6 + pygpo: Use correct method flags; (bso#14209). + vfs_ceph_snapshots: Fix root relative path handling; (bso#14216); (bsc#1141320). + Avoiding bad call flags with python 3.8, using METH_NOARGS instead of zero; (bso#14209). + source4/utils/oLschema2ldif: Include stdint.h before cmocka.h; (bso#14218). + docs-xml/winbindnssinfo: Clarify interaction with idmap_ad etc; (bso#14122). + smbd: Fix the build with clang; (bso#14251). + upgradedns: Ensure lmdb lock files linked; (bso#14199). + s3: VFS: glusterfs: Reset nlinks for symlink entries during readdir; (bso#14182). + smbc_stat() doesn't return the correct st_mode and also the uid/gid is not filled (SMBv1) file; (bso#14101). + librpc: Fix string length checking in ndr_pull_charset_to_null(); (bso#14219). + ctdb-scripts: Strip square brackets when gathering connection info; (bso#14227).- Add libnetapi-devel to baselibs conf, for wine usage; (bsc#1172307);- Installing: samba - samba-ad-dc.service does not exist and unit not found; (bsc#1171437);- Fix samba_winbind package is installing python3-base without python3 package; (bsc#1169521);- Require libldb2 >= 2.0.10 after security release.- CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850);- Fix smbclient crash with double free (with unresolved krb5 credential cache); (bso#14344); (bsc#1169095).- Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680).- CTDB doesn't retry outgoing connections on bind (and some other) failures; (bso#14274); (bsc#1162680).- Revert: Allow idmap_rid to have primary group other than "Domain Users"; (bsc#1087931).- Fix nmbstatus not reporting detailed information about workgroups; (bsc#1159464); - Fix querying all names registered within broadcast area; (bso#8927);- Update to samab 4.11.5 + CVE-2019-14902: Replication of ACLs down subtree on AD Directory is not automatic; (bso#12497); (bsc#1160850). + CVE-2019-19344: Fix server crash with dns zone scavenging = yes; (bso#14050); (bsc#1160852). + CVE-2019-14907: server-side crash after charset conversion failure (eg during NTLMSSP processing); (bso#14208); (bsc#1160888). - Update to samba 4.11.4 + Ensure SMB1 cli_qpathinfo2() doesn't return an inode number; (bso#14161). + Ensure we don't call cli_RNetShareEnum() on an SMB1 connection; (bso#14174). + NT_STATUS_ACCESS_DENIED becomes EINVAL when using SMB2 in SMBC_opendir_ctx; (bso#14176). + SMB2 - Ensure we use the correct session_id if encrypting an interim response; (bso#14189). + Prevent smbd crash after invalid SMB1 negprot; (bso#14205). + printing: Fix %J substition; (bso#13745). + Remove now unneeded call to cmdline_messaging_context(); (bso#13925). + Fix incomplete conversion of former parametric options; (bso#14069). + Fix sync dosmode fallback in async dosmode codepath; (bso#14070). + vfs_fruit returns capped resource fork length; (bso#14171). + libnet_join: Add SPNs for additional-dns-hostnames entries; (bso#14116). + smbd: Increase a debug level; (bso#14211). + Prevent azure ad connect from reporting discovery errors reference-value-not-ldap-conformant; (bso#14153). + krb5_plugin: Fix developer build with newer heimdal system library; (bso#14179). + replace: Only link libnsl and libsocket if required; (bso#14168); + ctdb: Incoming queue can be orphaned causing communication; breakdown; (bso#14175). + ldb: Release ldb 2.0.8. Cross-compile will not take cross-answers or cross-execute; (bso#13846). + heimdal-build: Avoid hard-coded /usr/include/heimdal in asn1_compile-generated code; (bso#13856).- Fix Ceph snapshot root relative path handling; (bso#14216); (bsc#1141320).- Update to samba 4.11.3 + CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). + CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). - CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- Update to samba 4.11.2 + CVE-2019-10218: Client code can return filenames containing path separators; (bsc#1144902); (bso#14071). + CVE-2019-14833: Samba AD DC check password script does not receive the full password; (bso#12438). + CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040). - Fixes from 4.11.1 + Overlinking libreplace against librt and pthread against every binary or library causes issues; (bso#14140); + kpasswd fails when built with MIT Kerberos; (bso#14155); + Fix spnego fallback from kerberos to ntlmssp in smbd server; (bso#14106); + Stale file handle error when using mkstemp on a share; (bso#14137); + non-AES schannel broken; (bso#14134); + Joining Active Directory should not use SAMR to set the password; (bso#13884); + smbclient can blunder into the SMB1 specific cli_RNetShareEnum() call on an SMB2 connection; (bso#14152); + Deleted records can be resurrected during recovery; (bso#14147); + getpwnam and getpwuid need to return data for ID_TYPE_BOTH group; (bso#14141); + winbind does not list forest trusts with additional trust attributes; (bso#14130); + fault report points to outdated documentation; (bso#14139); + pam_winbind with krb5_auth or wbinfo -K doesn't work for users of trusted domains/forests; (bso#14124); + classicupgrade results in uncaught exception - a bytes-like object is required, not 'str'; (bso#14136); + pod2man is not longer required, stop checking at build time; (bso#14131); + Exit code of ctdb nodestatus should not be influenced by deleted nodes; (bso#14129); + username/password authentication doesn't work with CUPS and smbspool; (bso#14128); + smbc_readdirplus() is incompatible with smbc_telldir() and smbc_lseekdir(); (bso#14094);- CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040); (bsc#1154598); - CVE-2019-10218: Client code can return filenames containing path separators; (bso#14071); (bsc#1144902);- CVE-2019-14833: samba: Accent with "check script password" Samba AD DC check password script does not receive the full password; (bso#12438); (bsc#1154289).- Update to samba 4.11.0 + For details on all items see WHATSNEW.txt in samba-doc package + Python2 runtime support removed; python 3.4 or later required + Security improvements: - SMB1 disabled by default - lanman and plaintext authentication deprecated - winbind: PAM_AUTH and NTLM_AUTH events logged - GnuTLS 3.2 required; system FIPS mode setting honored + CephFS Snapshot integration, exposed as previous file versions + ctdb changes: - onnode -o option removed - ctdbd logs when using more than 90% of a CPU thread - CTDB_MONITOR_SWAP_USAGE variable removed + AD Domain controller improvements: - Upgrade AD databse format - BIND9_FLATFILE deprecated - default process model chagned to prefork - bind9 dns operation duration logging - Default schema updated to 2012_R2; function level is unchanged - many performance improvements + Configuration webserver support removed- Fix broken username/password authentication with CUPS and smbspool; (bsc#1152143); (bso#14128).- Fix auth problems when printing via smbspool backend with kerberos; (bnc#1148539); (bso#13832).- Update to samba 4.10.8 + CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267);- Fix build on newer systems by modifying samba.spec to use consistent non-relative paths for pammodules in configure line and specification of pam_winbind.so library to package.- Update to samba 4.10.7 + Unable to create or rename file/directory inside shares configured with vfs_glusterfs_fuse module; (bso#14010). + build: Allow build when '--disable-gnutls' is set; (bso#13844) + samba-tool: Add 'import samba.drs_utils' to fsmo.py; (bso#13973). + Fix 'Error 32 determining PSOs in system' message on old DB with FL upgrade; (bso#14008). + s4/libnet: Fix joining a Windows pre-2008R2 DC; (bso#14021) + join: Use a specific attribute order for the DsAddEntry nTDSDSA object; (bso#14046). + vfs_catia: Pass stat info to synthetic_smb_fname(); (bso#14015). + lookup_name: Allow own domain lookup when flags == 0; (bso#14091). + s4 librpc rpc pyrpc: Ensure tevent_context deleted last; (bso#13932). + DEBUGC and DEBUGADDC doesn't print into a class specific log file; (bso#13915). + Request to keep deprecated option "server schannel", VMWare Quickprep requires "auto"; (bso#13949). + dbcheck: Fallback to the default tombstoneLifetime of 180 days; (bso#13967). + dnsProperty fails to decode values from older Windows versions; (bso#13969). + samba-tool: Use only one LDAP modify for dns partition fsmo role transfer; (bso#13973). + third_party: Update waf to version 2.0.17; (bso#13960). + netcmd: Allow 'drs replicate --local' to create partitions; (bso#14051). + ctdb-config: Depend on /etc/ctdb/nodes file; (bso#14017).- CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267).- Prepare for use future use of kernel keyrings, modify /etc/pam.d/samba to include pam_keyinit.so; (bsc#1144059).- Update samba-winbind script to work with systemd; (bsc#1132739); - Drop samba dhcpcd hook scripts - Update to samba 4.10.6 + s3: winbind: Fix crash when invoking winbind idmap scripts; (bso#13956). + smbd does not correctly parse arguments passed to dfree and quota scripts; (bso#13964). + samba-tool dns: use bytes for inet_ntop; (bso#13965). + samba-tool domain provision: Fix --interactive module in python3; (bso#13828). + ldb_kv: Skip @ records early in a search full scan; (bso#13893). + docs: Improve documentation of "lanman auth" and "ntlm auth" connection; (bso#13981). + python/ntacls: Use correct "state directory" smb.conf option instead of "state dir"; (bso#14002). + registry: Add a missing include; (bso#13840). + Fix SMB guest authentication; (bso#13944). + AppleDouble conversion breaks Resourceforks; (bso#13958). + vfs_fruit makes direct use of syscalls like mmap() and pread(); (bso#13968). + s3:mdssvc: Fix flex compilation error; (bso#13987). + s3/vfs_glusterfs[_fuse]: Avoid using NAME_MAX directly; (bso#13872). + dsdb:samdb: schemainfo update with relax control; (bso#13799). + s3:util: Move static file_pload() function to lib/util; (bso#13964). + smbd: Fix a panic; (bso#13957). + ldap server: Generate correct referral schemes; (bso#12478). + s4 dsdb/repl_meta_data: fix use after free in dsdb_audit_add_ldb_value; (bso#13941). + s4 dsdb: Fix use after free in samldb_rename_search_base_callback; (bso#13942). + dsdb/repl: we need to replicate the whole schema before we can apply it; (bso#12204). + ldb: Release ldb 1.5.5; (bso#12478). + Schema replication fails if link crosses chunk boundary backwards; (bso#13713). + 'samba-tool domain schemaupgrade' uses relax control and skips the schemaInfo update provision; (bso#13799). + dsdb_audit: avoid printing "... remote host [Unknown] SID [(NULL SID)] ..."; (bso#13916). + python/ntacls: We only need security.SEC_STD_READ_CONTROL in order to get the ACL; (bso#13917). + s3:loadparm: Ensure to truncate FS Volume Label at multibyte boundary; (bso#13947). + Using Kerberos credentials to print using spoolss doesn't work; (bso#13939). + wafsamba: Use native waf timer; (bso#13998). + ctdb-scripts: Fix tcp_tw_recycle existence check; (bso#13984).- Update to samba-4.10.5 (including updates for 4.10.4, 4.10.3) + CVE-2019-12435 rpc/dns: Avoid NULL deference if zone not found in DnssrvOperation2; (bso#13922); (bsc#1137815). + CVE-2019-12436 dsdb/paged_results: Ignore successful results without messages; (bso#13951); (bsc#1137816). - Update to samba-4.10.4 + s3: SMB1: Don't allow recvfile on stream fsp's; (bso#13938). + py/provision: Fix for Python 2.6; (bso#13882). + netcmd: Fix 'passwordsettings --max-pwd-age' command; (bso#13873). + s3-libnet_join: 'net ads join' to child domain fails when using "-U admin@forestroot"; (bso#13861). + vfs_ceph: Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245). + vfs_ceph: Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). + ctdb-common: Avoid race between fd and signal events; (bso#13895). + ctdb-common: Fix memory leak in run_proc; (bso#13943). + lib: Initialize getline() arguments; (bso#13892). + winbind: Fix overlapping id ranges; (bco#13903). + lib util debug: Increase format buffer to 4KiB; (bso#13902). + nsswitch pam_winbind: Fix Asan use after free; (bso#13927). + s4 lib socket: Ensure address string owned by parent struct; (bso#13929). + s3 rpc_client: Fix Asan stack use after scope; (bso#13936). + s3:smbd: Handle IO_REPARSE_TAG_DFS in SMB_FIND_FILE_FULL_DIRECTORY_INFO; (bso#10097). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#10344). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#12845). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#13698). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#13796). + dbcheck: Fix the err_empty_attribute() check; (bso#13843). + vfs_snapper: Drop unneeded fstat handler; (bso#13858). + vfs_default: Fix vfswrap_offload_write_send() NT_STATUS_INVALID_VIEW_SIZE check; (bso#13862). + smb2_server: Grant all 8192 credits to clients; (bso#13863). + smbd: Implement SMB_FILE_NORMALIZED_NAME_INFORMATION handling; (bso#13919). + s3/vfs_glusterfs: Dynamically determine NAME_MAX; (bso#13872). + s3: modules: ceph: Use current working directory instead of share path; (bso#13918); (bsc#1134452). + winbind: Use domain name from lsa query for sid_to_name cache entry; (bso#13831). + memcache: Increase size of default memcache to 512k; (bso#13865). + docs: Update smbclient manpage for "--max-protocol"; (bso#13857). + s3:utils: If share is NULL in smbcacls, don't print it; (bso#13937). + s3:smbspool: Fix regression printing with Kerberos credentials; (bso#13939). + ctdb-scripts: CTDB restarts failed NFS RPC services by hand, which is incompatible with systemd; (bso#13860). + ctdb-daemon: Revert "We can not assume that just because we could complete a TCP handshake"; (bso#13888). + ctdb-daemon: Never use 0 as a client ID; (bso#13930). + ctdb-common: Fix memory leak; (bso#13943). + s3:debug: Enable logging for early startup failures; (bso#13904) - Update to samba-4.10.3 + CVE-2018-16860: Heimdal KDC: Reject PA-S4U2Self with unkeyed checksum; (bso#13685); (bsc#1134024).- CVE-2019-12435: zone operations can crash rpc server; (bso#13922); (bsc#1137815).- Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). - Add ceph_snapshots VFS module; (jsc#SES-183).- Fix vfs_ceph realpath; (bso#13918); (bsc#1134452).- Update to samba-4.10.2: + CVE-2019-3870 (World writable files in Samba AD DC private/ dir); (bso#13834). + CVE-2019-3880 (Save registry file outside share as unprivileged user); (bso#13851). + py/kcc_utils: py2.6 compatibility; (bso#13837). + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869). + regfio: Improve handling of malformed registry hive files; (bso#13840). + ctdb-version: Simplify version string usage; (bso#13789). + lib: Make fd_load work for non-regular files; (bso#13859). + dbcheck: in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816). + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818). + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854). + acl_read: Fix regression for empty lists; (bso#13836). + s4:dlz make b9_has_soa check dc=@ node; (bso#13841). + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832). + s4:librpc: Fix installation of Samba; (bso#13847). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853). * ctdb-build: Drop creation of .distversion in tarball; (bso#13789). * ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838). - Update to samba-4.10.1: + py/kcc_utils: py2.6 compatibility; (bso#13837); + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869); + regfio: Improve handling of malformed registry hive files; (bso#13840); + ctdb-version: Simplify version string usage; (bso#13789); + lib: Make fd_load work for non-regular files; (bso#13859); + dbcheck in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816); + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818); + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854); + acl_read: Fix regression for empty lists; (bso#13836); + s4:dlz make b9_has_soa check dc=@ node; (bso#13841); + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832); + s4:librpc: Fix installation of Samba; (bso#13847); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853); + ctdb-build: Drop creation of .distversion in tarball; (bso#13789); + ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838); - Update to samba-4.10.0: + s4-server: Open and close a transaction on sam.ldb at startup; (bso#13760); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s4/scripting/bin: Open unicode files with utf8 encoding and write + unicode string. + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + Fix idmap cache pollution with S-1-22- IDs on winbind hickup; (bso#13813); + passdb: Update ABI to 0.27.2. + lib/winbind_util: Add winbind_xid_to_sid for --without-winbind; (bso#13813); + lib:util: Move debug message for mkdir failing to log level 1; (bso#13823);- MacOS credit accounting breaks with async SESSION SETUP; (bsc#1125601); (bso#13796). - Mac OS X SMB2 implmenetation sees Input/output error or Resource temporarily unavailable and drops connection; (bso#13698)- Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245).- CVE-2019-3880: Save registry file outside share as unprivileged user; (bso#13851); (bsc#1131060 ).- CVE-2019-3870 pysmbd: missing restoration of original umask after umask(0); (bso#13834); (bsc#1130703);- Update to samba-4.9.5 + audit_logging: Remove debug log header and JSON Authentication: prefix; (bso#13714); + Fix upgrade from 4.7 (or earlier) to 4.9; (bso#13760); + s3: lib: nmbname: Ensure we limit the NetBIOS name correctly; (bso# CID: 1433607; (bso#11495); + smbd: uid: Don't crash if 'force group' is added to an existing share connection; (bso#13690); + s3: VFS: vfs_fruit. Fix the NetAtalk deny mode compatibility code; (bso#13770); + s3: SMB1 POSIX mkdir does case insensitive name lookup; (bso#13803); + s3:utils/smbget fix recursive download with empty source directories; (bso#13199); + samba-tool drs showrepl: Do not crash if no dnsHostName found; (bso#13716); + s3:libsmb: cli_smb2_list() can sometimes fail initially on a connection; (bso#13736); + join: Throw CommandError instead of Exception for simple errors; (bso#13747); + ldb: Avoid inefficient one-level searches; (bso#13762); + s3: libsmb: use smb2cli_conn_max_trans_size() in cli_smb2_list(); (bso#13736); + tldap: Avoid use after free errors; (bso#13776); + Fix idmap xid2sid cache churn; (bso#13802); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s3-smbd: Avoid assuming fsp is always intact after close_file call; (bso#13720); + s3-vfs-fruit: Add close call; (bso#13725); + s3-smbd: Use fruit:model string for mDNS registration; (bso#13746); + s3-vfs: add glusterfs_fuse vfs module; (bso#13774); + printing: Check lp_load_printers() prior to pcap cache update; (bso#13766); + vfs_ceph: vfs_ceph strict_allocate_ftruncate calls (local FS) ftruncate and fallocate; (bso#13807); + lib/audit_logging: Actually create talloc; (bso#13737); + netcmd/user: python[3]-gpgme unsupported and replaced by python[3]-gpg; (bso#13728); + dns: Changing onelevel search for wildcard to subtree; (bso#13738); + samba-tool: Don't print backtrace on simple DNS errors; (bso#13721); + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + ctdb: Print locks latency in machinereadable stats; (bso#13742); + messages_dgm: Messaging gets stuck when pids are recycled; (bso#13786); + audit_logging: auth_json_audit required auth_json; (bso#13715); + man pages: Document prefork process model; (bso#13765); + CVE-2019-3824 ldb: Release ldb 1.4.6; (bso#13773); + s3:auth: ignore create_builtin_guests() failing without a valid idmap configuration; (bso#13697); + s3:auth_winbind: Ignore a missing winbindd as NT4 PDC/BDC without trusts; (bso#13722); + s3:auth_winbind: return NT_STATUS_NO_LOGON_SERVERS if winbindd is not available; (bso#13723); + s4:server: Add support for 'smbcontrol samba shutdown' and 'smbcontrol debug/debuglevel'; (bso#13752); + Python: Ensure ldb.Dn can doesn't rencoded str with py2; (bso#13616); + vfs_glusterfs: Adapt to changes in libgfapi signatures; (bso#13330); + s3-vfs: Use ENOATTR in errno comparison for getxattr; (bso#13774); + notifyd: Fix SIGBUS on sparc; (bso#13704); + waf: Check for libnscd; (bso#13787); + s3:vfs: Correctly check if OFD locks should be enabled or not; (bso#13770); + lib/util: Count a trailing line that doesn't end in a newline; (bso#13717); + Recovery lock bug fixes; (bso#13800); + s3: net: Do not set NET_FLAGS_ANONYMOUS with -k; (bso#13726); + s3:libsmb: Honor disable_netbios option in smbsock_connect_send; (bso#13727); + vfs_fileid: Fix get_connectpath_ino; (bso#13741); + vfs_fileid: Fix fsname_norootdir algorithm; (bso#13744);- Fix vfs_ceph ftruncate and fallocate handling; (bso#13807); (bsc#1127153).- Fix update-apparmor-samba-profile script after apparmor switched to using named profiles. The change is backwards compatible; (bsc#1126377);- LoadParm().load_default() fails with "Unable to load default file"; (bsc#1089758);- Abide by load_printers smb.conf parameter; (bso#13766); (bsc#1124223);- Update to samba-4.9.4 + libcli/smb: Don't overwrite status code; (bso#9175). + wbinfo --group-info 'NT AUTHORITY\System' does not work; (bso#12164). + Session setup reauth fails to sign response; (bso#13661). + vfs_fruit: Validation of writes on AFP_AfpInfo stream; (bso#13677). + vfs_shadow_copy2: Nicely deal with attempts to open previous version for writing; (bso#13688). + Restoring previous version of stream with vfs_shadow_copy2 fails with NT_STATUS_OBJECT_NAME_INVALID fsp->base_fsp->fsp_name; (bso#13455). + CVE-2018-16853: Fix S4U2Self crash with MIT KDC build; (bso#13571). + s3-vfs: Prevent NULL pointer dereference in vfs_glusterfs; (bso#13708) + PEP8: fix E231: missing whitespace after ','. + winbindd: Fix crash when taking profiles;(bso#13629) + CVE-2018-14629 dns: Fix CNAME loop prevention using counter regression; (bso#13600) + 'samba-tool user syscpasswords' fails on a domain with many DCs; (bso#13686). + CVE-2018-16853: Do not segfault if client is not set; (bso#13571). + lib:util: Fix DEBUGCLASS pointer initializiation; (bso#13679) + ctdb-daemon: Exit with error if a database directory does not exist; (bso#13696). + s3:libads: Add net ads leave keep-account option; (bso#13498).- Drop more %if..%endif guards which are idempotent. - Drop requires on ldconfig which are already auto-discovered. - Do not ignore errors from useradd/groupadd.- Remove python2 build dependency from samba-libs; (bsc#1116900);- Update update-apparmor-samba-profile script to ignore the shares's paths containing substitution variables in any place, not only at the beginning of the path.- Update to samba-4.9.3 + CVE-2018-14629: Unprivileged adding of CNAME record causing loop in AD Internal DNS server; (bso#13600); (bsc#1116319); + CVE-2018-16841: Double-free in Samba AD DC KDC with PKINIT; (bso#13628); (bsc#1116320); + CVE-2018-16851: NULL pointer de-reference in Samba AD DC LDAP server; (bso#13674); (bsc#1116322); + CVE-2018-16852: NULL pointer de-reference in Samba AD DC DNS servers; (bso#13669); (bsc#1116321); + CVE-2018-16853: Samba AD DC S4U2Self crash in experimental MIT Kerberos configuration (unsupported); (bso#13678); (bsc#1116324); + CVE-2018-16857: Bad password count in AD DC not always effective; window; (bso#13683); (bsc#1116323);- Update to samba-4.9.2 + dsdb: Add comments explaining the limitations of our current backlink behaviour; (bso#13418); + Fix problems running domain backups (handling SMBv2, sites); (bso#13621); + testparm: Fix crashes with PANIC: Messaging not initialized on SLES 12 SP3; (bso#13465); + Make vfs_fruit able to cleanup AppleDouble files; (bso#13642); + File saving issues with vfs_fruit on samba >= 4.8.5; (bso#13646); + Enabling vfs_fruit looses FinderInfo; (bso#13649); + Cancelling of SMB2 aio reads and writes returns wrong error NT_STATUS_INTERNAL_ERROR; (bso#13667); + Fix CTDB recovery record resurrection from inactive nodes and simplify vacuuming; (bso#13641); + examples: Fix the smb2mount build; (bso#13465); + libtevent: Fix build due to missing open_memstream on Illiumos; (bso#13629); + winbindd_cache: Fix timeout calculation for sid<->name cache; (bso#13662); + dsdb encrypted_secrets: Allow "ldb:// and "mdb://" in file path; (bso#13653); + Extended DN SID component missing for member after switching group membership; (bso#13418); + Return STATUS_SESSION_EXPIRED error encrypted, if the request was encrypted; (bso#13624); + python: Allow forced signing via smb.SMB(); (bso#13621); + lib:socket: If returning early, set ifaces; (bso#13665); + ldb: Bump ldb version to 1.4.3, Python: Ensure ldb.Dn can accept utf8 encoded unicode; (bso#13616); + smbd: Fix DELETE_ON_CLOSE behaviour on files with READ_ONLY attribute; (bso#13673); + waf: Add -fstack-clash-protection; (bso#13601); + winbind: Fix segfault if an invalid passdb backend is configured; (bso#13668); + Fix bugs in CTDB event handling; (bso#13659); + Misbehaving nodes are sometimes not banned; (bso#13670);- lib:socket: If returning early, set ifaces; (bso#13665); (bsc#1111373);- winbind requires latest version of libtevent-util0 to start- Backport latest gpo code from master + Read policy from local gpt cache + Offline policy application + Make group policy extensible via register/unregister gpext + gpext's run via a process_group_policy method- Enable profiling data collection- Change samba-kdc package name to samba-ad-dc - Move samba-ad-dc.service to the samba-ad-dc package- Update to samba-4.9.1 + s3: nmbd: Stop nmbd network announce storm; (bso#13620); + s3-rpcclient: Use spoolss_init_spoolss_UserLevel1 in winspool cmds; (bso#13597); + CTDB recovery lock has some race conditions; (bso#13617); + s3-rpc_client: Advertise Windows 7 client info; (bso#13597); + ctdb-doc: Remove PIDFILE option from ctdbd_wrapper man page; (bso#13610);- Tumbleweed doesn't define the sle_version macro, so we must include a check for suse_version also. Otherwise python3 is disabled on Tumbleweed.- Update to samba-4.9.0 + samba_dnsupdate: Honor 'dns zone scavenging' option, only update if needed; (bso#13605); + wafsamba: Fix 'make -j'; (bso#13606);- Update to samba-4.9.0rc5 + s3: VFS: vfs_full_audit: Ensure smb_fname_str_do_log() only returns absolute pathnames; (bso#13565); + s3: util: Do not take over stderr when there is no log file; (bso#13578); + Durable Reconnect fails because cookie.allow_reconnect is not set; (bso#13549); + krb5-samba: Interdomain trust uses different salt principal; (bso#13539); + vfs_fruit: Don't unlink the main file; (bso#13441); + smbd: Fix a memleak in async search ask sharemode; (bso#13602); + Fix Samba GPO issue when Trust is enabled; (bso#11517); + samba-tool: Add "virtualKerberosSalt" attribute to 'user getpassword/syncpasswords'; (bso#13539); + Fix CTDB configuration issues; (bso#13589); + ctdbd logs an error until it can successfully connect to eventd; (bso#13592);- Update to samba-4.9.0rc4 + s3: smbd: Ensure get_real_filename() copes with empty pathnames; (bso#13585); + samba domain backup online/rename commands force user to specify password on CLI; (bso#13566); + wafsamba/samba_abi: Always hide ABI symbols which must be local; (bso#13579); + Fix a panic if fruit_access_check detects a locking conflict; (bso#13584); + Fix memory and resource leaks; (bso#13567); + python: Fix print in dns_invalid.py; (bso#13580); + Aliasing issue causes incorrect IPv6 checksum; (bso#13588); + Fix CTDB configuration issues; (bso#13589); + s3: vfs: time_audit: fix handling of token_blob in smb_time_audit_offload_read_recv(); (bso#13568);- Add missing zlib-devel dependency which was previously pulled in by libopenssl-devel- Update to samba-4.9.0rc3+git.22.3fff23ae36e + CVE-2018-10858: libsmb: Harden smbc_readdir_internal() against returns from malicious servers; (bso#13453); + CVE-2018-1140: ldbsearch '(distinguishedName=abc)' and DNS query with escapes crashes, ldb: Release LDB 1.3.5 for CVE-2018-1140; (bso#13374); + CVE-2018-10918: cracknames: Fix DoS (NULL pointer de-ref) when not servicePrincipalName is set on a user; (bso#13552); + CVE-2018-10919: acl_read: Fix unauthorized attribute access via searches; (bso#13434); + ctdb_mutex_ceph_rados_helper: Set SIGINT signal handler; (bso#13540); + CVE-2018-1139 libcli/auth: Do not allow ntlmv1 over SMB1 when it is disabled via "ntlm auth"; (bso#13360); + s3-tldap: do not install test_tldap; (bso#13529); + ctdb_mutex_ceph_rados_helper: Fix deadlock via lock renewals; (bso#13540); + CVE-2018-1140 Add NULL check for ldb_dn_get_casefold() in ltdb_index_dn_attr(); (bso#13374); + ctdb-eventd: Fix CID 1438155; (bso#13554); + Fix CIDs 1438243, (Unchecked return value) 1438244 (Unsigned compared against 0), 1438245 (Dereference before null check) and 1438246 (Unchecked return value); (bso#13553); + ctdb: Fix a cut&paste error; (bso#13554); + systemd: Only start smb when network interfaces are up; (bso#13559); + Fix quotas don't work with SMB2; (bso#13553); + s3/smbd: Ensure quota code is only called when quota support detected; (bso#13563); + s3/libsmb: Explicitly set delete_on_close token for rmdir; (bso#13204); + s3:waf: Install eventlogadm to /usr/sbin; (bso#13561); + Shorten description in vfs_linux_xfs_sgid manual; (bso#13562);- Update to samba-4.9.0rc2+git.21.a1069afb007 + s3: smbd: Using "sendfile = yes" with SMB2 can cause CPU spin; (bso#13537); + s3: smbd: Fix path check in smbd_smb2_create_durable_lease_check(); (bso#13535); + samba-tool trust: Support discovery via netr_GetDcName; (bso#13538); + s4-dsdb: Only build dsdb Python modules for AD DC; (bso#13542); + Fix portability issues on freebsd; (bso#13520); + DNS wildcard search does not handle multiple labels correctly; (bso#13536); + samba-tool domain trust: Fix trust compatibility to Windows Server 1709 and FreeIPA; (bso#13308); + Fix portability issues on freebsd; (bso#13520); + ctdb-protocol: Fix CTDB compilation issues; (bso#13545); + ctdb-docs: Replace obsolete reference to CTDB_DEBUG_HUNG_SCRIPT option; (bso#13546); + ctdb-doc: Provide an example script for migrating old configuration; (bso#13550); + ctdb-event: Implement event tool "script list" command; (bso#13551);- Update to samba-4.8.4+git.37.a7a861d7982; + CVE-2018-1139: Weak authentication protocol allowed; (bsc#1095048); (bsc#13360); + CVE-2018-1140: Denial of Service Attack on DNS and LDAP server; (bsc#1095056); (bso#13466); (bso#13374); + CVE-2018-10858: Insufficient input validation on client directory listing in libsmbclient; (bsc#1103411); (bso#13453); + CVE-2018-10918: Denial of Service Attack on AD DC DRSUAPI server; (bsc#1103414); (bso#13552); + CVE-2018-10919: Confidential attribute disclosure from the AD LDAP server; (bsc#1095057); (bso#13434); + s3:winbind: winbind normalize names' doesn't work for users; (bso#12851); + winbind: Fix UPN handling in canonicalize_username(); (bso#13369); + s3: smbd: Fix SMB2-FLUSH against directories; (bso#13428); + samdb: Fix building Samba with gcc 8.1; (bso#13437); + s3:utils: Do not segfault on error in DoDNSUpdate(); (bso#13440); + smbd: Flush dfree memcache on service reload; (bso#13446); + ldb: Save a copy of the index result before calling the + lib/util: No Backtrace given by Samba's AD DC by default; (bso#13454). + s3: smbd: printing: Re-implement delete-on-close semantics for print files missing since 3.5.x; (bso#13457). + python: Fix talloc frame use in make_simple_acl(); (bso#13474). + krb5_wrap: Fix keep_old_entries logic for older Kerberos libraries;(bso#13478). + krb5_plugin: Add winbind localauth plugin for MIT Kerberos; (bso#13480).- Add missing package descriptions; (bsc#1093864); - Fix dependency issue between samba-python and samba-kdc; (bsc#1062876); - Call update-apparmor-samba-profile when running samba-ad-dc; (bsc#1092099);- Update to 4.8.2 + After update to 4.8.0 DC failed with "Failed to find our own NTDS Settings objectGUID" (bso#13335). + fix incorrect reporting of stream dos attributes on a directory (bso#13380). + vfs_ceph: add asynchronous fsync; fake synchronous call (bso#13412). + vfs_ceph: add fake async pwrite/pread send/recv hooks; (bso#13425) + vfs_ceph: Fix memory leak; (bso#13424). + libsmbclient: Fix hard-coded connection error return of ETIMEDOUT; (bso#13419). + s4-lsa: Fix use-after-free in LSA server; (bso#13420). + winbindd: Do re-connect if the RPC call fails in the passdb case; (bso#13430). + cleanupd: Sends MSG_SMB_UNLOCK twice to interested peers; (bso#13416). + cleanupd: Use MSG_SMB_BRL_VALIDATE to signal cleanupd unclean process shutdown; (bso#13414). + ctdb-client: Remove ununsed functions from old client code; (bso#13411). + printing: Return the same error code as windows does on upload failures; (bso#13395). + nsswitch: Fix memory leak in winbind_open_pipe_sock() when the privileged pipe is not accessable; (bso#13400). + s4:lsa_lookup: remove TALLOC_FREE(state) after all dcesrv_lsa_Lookup{Names,Sids}_base_map() calls; (bso#13420). + rpc_server: Fix NetSessEnum with stale sessions; (bso#13407). + s3:smbspool: Fix cmdline argument handling; (bso#13417).- Move libdfs-server-ad-samba4.so library from kdc to libs package, as it is required by some client libs; (bsc#1074135); - Update to 4.8.1; (bsc#1091179); + s3: ldap: Ensure the ADS_STRUCT pointer doesn't get freed on error, we don't own it here; (bso#13244); + s3: smbd: Fix possible directory fd leak if the underlying OS doesn't support fdopendir(); (bso#13270); + Round-tripping ACL get/set through vfs_fruit will increase the number of ACE entries without limit; (bso#13319); + s3: smbd: SMB2: Add DBGC_SMB2_CREDITS class to specifically debug credit issues; (bso#13347); + s3: smbd: Files or directories can't be opened DELETE_ON_CLOSE without delete access; (bso#13358); + s3: smbd: Fix memory leak in vfswrap_getwd(); (bso#13372); + s3: smbd: Unix extensions attempts to change wrong field in fchown call; (bso#13375); + ms_schema/samba-tool visualize: Fix python2.6 incompatibility; (bso#13337); + Fix invocation of gnutls_aead_cipher_encrypt(); (bso#13352); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + winbindd: Recover loss of netlogon secure channel in case the peer DC is rebooted; (bso#13332); + s3:smbd: Don't use the directory cache for SMB2/3; (bso#13363); + ctdb-client: Fix bugs in client code; (bso#13356); + ctdb-scripts: Drop "net serverid wipe" from 50.samba event script; (bso#13359); + s3: lib: messages: Don't use the result of sec_init() before calling sec_init(); (bso#13368); + libads: Fix the build '--without-ads'; (bso#13273); + winbind: Keep "force_reauth" in invalidate_cm_connection, add 'smbcontrol disconnect-dc'; (bso#13332); + vfs_virusfilter: Fix CIDs 1428738-1428740; (bso#13343); + dsdb: Fix CID 1034966 Uninitialized scalar variable; (bso#13367); + rpc_server: Fix core dump in dfsgetinfo; (bso#13370); + smbclient: Fix notify; (bso#13382); + Fix smbd panic if the client-supplied channel sequence number wraps; (bso#13215); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + lib/util: Remove unused '#include ' from tests/tfork.c; (bso#13342); + Fix build errors with cc from developerstudio 12.5 on Solaris; (bso#13343); + Fix the picky-developer build on FreeBSD 11; (bso#13344); + s3:modules: Fix the build of vfs_aixacl2.c; (bso#13345); + s3:smbd: map nterror on smb2_flush errorpath; (bso#13338); + lib:replace: Fix linking when libtirpc-devel overwrites system headers; (bso#13341); + winbindd: 'wbinfo --name-to-sid' returns misleading result on invalid query; (bso#13312); + s3:passdb: Do not return OK if we don't have pinfo set up; (bso#13376); + Allow AESNI to be used on all processor supporting AESNI; (bso#13302);- Use new foreground execution flags for systemd samba daemons; (bsc#1088574); (bsc#1071090); (bsc#1065551); + Add %post scriptlet to clear old sysconfig flags - Update vendor-files to commit 880b3e7. + Set samba sysconfig template variables to "" + Add required daemon flags directly to systemd unit- Specfile cleanup + Remove %if..%endif guards which don't affect the build + Remove redundant %clean section + Replace old $RPM_* shell vars with macros- BuildRequire pkgconfig(systemd) and pkgconfig(libsystemd) in place of systemd and systemd-devel: Allow OBS to optimize the workload by allowing the usage of the 'build-optimized' systemd packages.- Enable building samba with python3, and create a samba-python3 package.- Update to 4.8 + New GUID Index mode in sam.ldb for the AD DC + GPO support for samba KDC + Time machine support with vfs_fruit + Encrypted secrets + AD Replication visualization + Improved trust support - ability to not scan global trust list - AD external trusts have limited support - verbose trusted domain listing + VirusFilter VFS module + NT4-style replication removed + vfs_aio_linux removed- Disable samba-pidl package, due to the removal of dependency perl-Parse-Yapp; (bsc#1085150);- Update to 4.7.6; + CVE-2018-1050: DOS vulnerability when SPOOLSS is run externally; (bso#11343); (bsc#1081741); + CVE-2018-1057: Authenticated users can change other users' password; (bso#13272); (bsc#1081024).- Disable python until full python3 port is done; (bsc#1082139); + Remove contents of package samba-python + Remove contents of package libsamba-policy0 + Remove contents of package libsamba-policy-devel + Remove library libsamba-python-samba4.so from samba-libs package + Remove library libsamba-net-samba4.so from samba-libs package + Remove smbtorture binary and manpage from samba-test- samba fails to build with glibc2.27; (bsc#1081042);- Update to 4.7.5; (bsc#1080545); + smbd tries to release not leased oplock during oplock II downgrade; (bso#13193); + Fix copying file with empty FinderInfo from Windows client to Samba share with fruit; (bso#13181); + build: Deal with recent glibc sunrpc header removal; (bso#10976); + Make Samba work with tirpc and libnsl2; (bso#13238); + vfs_ceph: Add fs_capabilities hook to avoid local statvfs; (bso#13208); (bsc#1075206); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + ctdb-recovery-helper: Deregister message handler in error paths; (bso#13188); + samba: Only use async signal-safe functions in signal handler; (bso#13240); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + repl_meta_data: Fix linked attribute corruption on databases with unsorted links on expunge. dbcheck: Add functionality to fix the corrupt database; (bso#13228); + Fix smbd panic when chdir returns error during exit; (bso#13189); + Make Samba work with tirpc and libnsl2; (bso#13238); + Fix POSIX ACL support on HPUX and possibly other big-endian OSs; (bso#13176);- Update to 4.7.4; (bsc#1080545); + s3: smbclient: Implement 'volume' command over SMB2; (bso#13140); + s3: libsmb: Fix valgrind read-after-free error in cli_smb2_close_fnum_recv(); (bso#13171); + s3: libsmb: Fix reversing of oldname/newname paths when creating a reparse point symlink on Windows from smbclient; (bso#13172); + Build man page for vfs_zfsacl.8 with Samba; (bso#12934); + repl_meta_data: Allow delete of an object with dangling backlinks; (bso#13095); + s4:samba: Fix default to be running samba as a deamon; (bso#13129); + Performance regression in DNS server with introduction of DNS wildcard, ldb: Release 1.2.3; (bso#13191); + vfs_zfsacl: Fix compilation error; (bso#6133); + "smb encrypt" setting changes are not fully applied until full smbd restart; (bso#13051); + winbindd: Fix idmap_rid dependency on trusted domain list; (bso#13052); + vfs_fruit: Proper VFS-stackable conversion of FinderInfo; (bso#13155); + winbindd: Dependency on trusted-domain list in winbindd in critical auth codepath; (bso#13173); + repl_meta_data: Fix removing of backlink on deleted objects; (bso#13120); + ctdb: sock_daemon leaks memory; (bso#13153); + TCP tickles not getting synchronised on CTDB restart; (bso#13154); + winbindd: winbind parent and child share a ctdb connection; (bso#13150); + pthreadpool: Fix deadlock; (bso#13170); + pthreadpool: Fix starvation after fork; (bso#13179); + messaging: Always register the unique id; (bso#13180); + s4/smbd: set the process group; (bso#13129); + Fix broken linked attribute handling; (bso#13095); + The KDC on an RWDC doesn't send error replies in some situations; (bso#13132); + libnet_join: Fix 'net rpc oldjoin'; (bso#13149); + g_lock conflict detection broken when processing stale entries; (bso#13195); + s3:smb2_server: allow logoff, close, unlock, cancel and echo on expired sessions; (bso#13197); + s3:libads: net ads keytab list fails with "Key table name malformed"; (bso#13166); (bsc#1067700); + Fix crash in pthreadpool thread after failure from pthread_create; (bso#13170); + s4:samba: Allow samba daemon to run in foreground; (bso#13129); (bsc#1065551); + third_party: Link the aesni-intel library with "-z noexecstack"; (bso#13174); + vfs_glusterfs: include glusterfs/api/glfs.h without relying on "-I" options; (bso#13125);- Re-enable usage of libnsl (did got lost with glibc change) - Use TI-RPC (sunrpc is deprecated and will be removed soon from glibc)- smbc_opendir should not return EEXIST with invalid login credentials; (bnc#1065868).- Update to 4.7.3; (bsc#1069666); + Non-smbd processes using kernel oplocks can hang smbd; (bso#13121); + python: use communicate to fix Popen deadlock; (bso#13127); + smbd on disk file corruption bug under heavy threaded load; (bso#13130); + tevent: version 0.9.34; (bso#13130); + s3: smbd: Fix delete-on-close after smb2_find; (bso#13118); + CVE-2017-14746: s3: smbd: Fix SMB1 use-after-free crash bug; (bsc#1060427);(bso#13041); + CVE-2017-15275: s3: smbd: Chain code can return uninitialized memory when talloc buffer is grown; (bsc#1063008); (bso#13077); - Build with AD DC support only in openSUSE.- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- samba-tool requires samba-python; (bnc#1067771).- Run all daemons in the foreground and let systemd handle it; (bsc#1065551). - Update to 4.7.1; + Fix exporting subdirs with shadow_copy2; (bso#13091); + Currently if getwd() fails after a chdir(), we panic; (bso#13027); + Ensure default SMB_VFS_GETWD() call can't return a partially completed struct smb_filename; (bso#13068); + sys_getwd() can leak memory or possibly return the wrong errno on older systems; (bso#13069); + smbclient doesn't correctly canonicalize all local names before use; (bso#13093); + Fix broken linked attribute handling; (bso#13095); + Missing LDAP query escapes in DNS rpc server; (bso#12994); + Link to -lbsd when building replace.c by hand; (bso#13087); + Cannot delete non-ACL files on Solaris/ZFS/NFSv4 ACL filesystem; (bso#6133); + Map SYNCHRONIZE acl permission statically in zfs_acl vfs module; (bso#7909); + Samba fails to honor SEC_STD_WRITE_OWNER bit with the acl_xattr module; (bso#7933); + Missing assignment in sl_pack_float; (bso#12991); + Wrong Samba access checks when changing DOS attributes; (bso#12995); + samba_runcmd_send() leaves zombie processes on timeout; (bso#13062); + groupmap cleanup should not delete BUILTIN mappings; (bso#13065); + Enabling vfs_fruit results in loss of Finder tags and other xattrs; (bso#13076); + man pages: Properly ident lists; (bso#9613); + smb.conf.5: Sort parameters alphabetically; (bso#13081); + Fix GUID string format on GetPrinter info; (bso#12993); + Remote serverid check doesn't check for the unique id; (bso#13042); + CTDB starts consuming memory if there are dead nodes in the cluster; (bso#13056); + ctdb-common: Ignore event scripts with multiple '.'s; (bso#13070); + libgpo doesn't sort the GPOs in the correct order; (bso#13046); + Remote serverid check doesn't check for the unique id; (bso#13042); + vfs_catia: Fix a potential memleak; (bso#13090); + Fix file change notification for renames; (bso#12903); + Samba DNS server does not honour wildcards; (bso#12952); + Can't change password in samba from a Windows client if Samba runs on IPv6 only interface; (bso#13079); + vfs_fruit: Replace closedir() by SMB_VFS_CLOSEDIR; (bso#13086); + Apple client can't cope with SMB2 async replies when creating symlinks; (bso#13047); + s4:rpc_server:backupkey: Move variable into scope; (bso#12959); + Fix ntstatus_gen.h generation on 32bit; (bso#13099); + Fix a double free in vfs_gluster_getwd(); (bso#13100); + Fix resouce leaks and pointer issues; (bso#13101); + vfs_solarisacl: Fix build for samba 4.7 and up; (bso#13049);- Add samba-kdc to baselibs.conf. - Do not wrap samba-kdc's package definition into if/endif: the package won't be generated simply based on the fact that there is no files section for the package. Allows the source validator to ensure samba-kdc is a built package.- Update to 4.7.0; + Whole DB read locks: Improved LDAP and replication consistency; (bso#12858). + Samba AD with MIT Kerberos + Dynamic RPC port range: Default range changed from "1024-1300" to "49152-65535". + Authentication and Authorization audit support: New auth_audit debug class. + Multi-process LDAP Server: The LDAP server in the AD DC now honours the process model used for the rest of the 'samba' process. + Improved Read-Only Domain Controller (RODC) Support; (bso#12977). + Additional password hashes stored in supplementalCredentials. + Improvements to DNS during Active Directory domain join. + Significant AD performance and replication improvements. + Query record for open file or directory. + Removal of lpcfg_register_defaults_hook(). + Change of loadable module interface. + SHA256 LDAPS Certificates: The self-signed certificate generated for use on LDAPS will now be generated with a SHA256 self-signature, not a SHA1 self-signature. + CTDB no longer allows mixed minor versions in a cluster. + CTDB now ignores hints from Samba about TDB flags when attaching to databases. + New configuration variable CTDB_NFS_CHECKS_DIR. + The CTDB_SERVICE_AUTOSTARTSTOP configuration has been removed. + The CTDB_SCRIPT_DEBUGLEVEL configuration variable has been removed. + The example NFS Ganesha call-out has been improved. + A new "replicated" database type is available.- CVE-2017-12163: Prevent client short SMB1 write from writing server memory to file; (bso#13020); (bsc#1058624).- CVE-2017-12150: Some code path don't enforce smb signing, when they should; (bso#12997); (bsc#1058622).- CVE-2017-12151: Keep required encryption across SMB3 dfs redirects; (bso#12996); (bsc#1058565).- Clean specfile assuming SUSE-only system and product >=SLE11 + %{ul_version}, %{rhel_version}, %{mandriva_version}, %{centos_version} are always undefined + %{_vendor} is "suse" and %{suse_version} is at least 1100- Update to 4.6.7; (bsc#1054017) + Joining a Huawai storage fails: empty CLDAP ping answer; (bso#11392). + smbcacls can fail against a directory on Windows using SMB2.; (bso#12937). + vfs_ceph provides inconsistent directory listings; (bso#12911). + Misused talloc context can cause a user to crash their smbd by chaining SMB1 commands.; (bso#12836). + Use-after free can crash libsmbclient code.; (bso#12927). + Server exit with active AIO can crash.; (bso#12925). + Ensure notifyd doesn't return from smbd_notifyd_init; (bso#12910). + fd leak to ctdb sub-processes leads to SELinux AVC denial in audit logs; (bso#12898). + vfs_fruit shouldn't send MS NFS ACEs to Windows clients; (bso#12897). + smbspool_krb5_wrapper does not tell CUPS that it requires negotiate for authentication; (bso#12886). + finder sidebar showing question mark instead of icon when using ip to connect with vfs_fruit; (bso#12840). + Winbind stops obtaining the 'unixHomeDirectory' & 'loginShell' attributes from AD.; (bso#12720). + KCC run at selftest startup can fail spuriously due to a race; (bso#12869). + winbindd changes the local password and gets NT_STATUS_WRONG_PASSWORD for the remote change; (bso#12782). + rpc_pipe_client memory leaks due to long term memory context passed to rpc_pipe_open_interface(); (bso#12890). + CVE-2017-2619 breaks accessing previous versions of directories with snapshots in subdirectories of the share; (bso#12885). + dns_name_equal doing OOB read; (bso#12813). + replica_sync tests flap; (bso#12753). + Selftest should not call 'net cache flush' and wipe important winbind entries; (bso#12868). + Old Samba versions don't support using recent ldb versions (>=1.1.30); (bso#12859). + pam_winbind fails with kerberos method = secrets and keytab; (bso#10490). + race starting winbindd against posixacl test; (bso#12843). + Crash in the reentrant smbd_smb2_create_send() if the something fails in the subsequent try; (bso#12832). + spnego.c passes the wrong argument order to gensec_update_ev() for the FALLBACK case; (bso#12788). + Clients with SMB3 support can't connect with "server max protocol = SMB2_02"; (bso#12772). + A log message of samb-tool user syncpasswords reverses string arguments in a debug message "Call Popen[...".; (bso#12768). + The smb tarmode tests kills the share dir contents; (bso#12867). + Fix for a bug in MacOS X Sierra NTLMv2 processing; (bso#12862). + CVE-2017-2619 regression with non-wide symlinks to directories; (bso#12860). + manpage/index.html lists links not in alphabetical order; (bso#12854). + smbcacls got error NT_STATUS_NETWORK_NAME_DELETED; (bso#12831). + If a record is locked in a database, then recovery does not complete; (bso#12857). + debug_locks.sh script does not log any information; (bso#12856). + SIGSEGV in cm_connect_lsa_tcp dereferencing conn->lsa_tcp_pipe->transport after error; (bso#12852). + smbclient can't parse DOMAIN+username if a different winbind separator is used; (bso#12849). + Related requests with SessionSetup fail with INTERNAL_ERROR; (bso#12845). + Related requests with TreeConnect fail with NETWORK_NAME_DELETED; (bso#12844). + cli->server_os not filled correctly; (bso#12779). + REGRESSION: smbclient doesn't print the session setup anymore; (bso#12824). + smblcient doesn't handle STATUS_NOT_SUPPORTED gracefully for FSCTL_VALIDATE_NEGOTIATE_INFO; (bso#12808). + CTDB NFS call-out failures do not cause event failures; (bso#12837). + net command fails due to incorrectly return code; (bso#12828). + Fix building Samba with GCC 7.1; (bso#12827).- Fix duplicate CTDB_LOGGING params when downgraded and upgraded again; (bsc#1048339).- fix cephwrap_chdir(); (bsc#1048790). - Update to 4.6.6 + CVE-2017-11103: Orpheus' Lyre KDC-REP service name validation; (bsc#1048278).- Fix ctdb logs to /var/log/log.ctdb instead of /var/log/ctdb; (bsc#1048339).- Fix inconsistent ctdb socket path; (bsc#1048352). - Fix non-admin cephx authentication; (bsc#1048387).- Update to 4.6.5; (bsc#1040157) + Specifying CTDB_LOGGING=syslog:nonblocking causes ctdbd to crash at startup; (bso#12814). + vfs_expand_msdfs tries to open the remote address as a file path; (bso#12687). + PANIC (pid 1096): assert failed: lease_type_is_exclusive(e_lease_type); (bso#12798). + With clustering get update_num_read_oplocks failed and PANIC: num_share_modes == 1 assertion failure; (bso#11844). + contend_level2_oplocks_begin_default oplock optimisation doesn't carry over to leases; (bso#12766). + `ctdb nodestatus` incorrectly displays status for all nodes with wrong exit code; (bso#12802). + CTDB can spin hard on revoking readonly delegations if a node becomes disconnected; (bso#12697). + Printing a share mode entry with leases can crash in the ndr code; (bso#12793). + Fix flakey unit tests for eventd; (bso#12792). + CTDB daemon crashes if built with clang; (bso#12770). + smbcacls fails if no password is specified; (bso#12765). + idmap_rfc2307: Lookup of more than two SIDs fails; (bso#12757). + samba-tool user syncpasswords doesn't trigger the script when a user gets removed; (bso#12767). + systemd: fix detection of libsystemd; (bso#12764). + Notify subsystem only maps first inotify mask to Windows notify filter; (bso#12760). + Allow passing trusted domain password as plain-text to PASSDB layer; (bso#12751). + Can't case-rename files with vfs_fruit; (bso#12749). + wrong sid->uid mapping for SIDs residing in sIDHistory; (bso#12702). + vfs_acl_common should force "create mask = 0777", not 0666; (bso#12562). + Ordering of notify responses broken; (bso#12756).- s3: libsmb: Fix error where short name length was read as 2 bytes, should be 1; (bso#11822); (bsc#1042419).- Revert explicit winbind %{version}-%{release} dependency. + The ABI has stabilized since (bsc#936909), so remove to fix cross-media dependencies; (bsc#1037899).- Fix CVE-2017-7494 remote code execution from a writable share; (bso#12780); (bsc#1038231).- Update to 4.6.3; (bsc#1036011) + s3:vfs:shadow_copy2: vfs_shadow_copy2 fails to list snapshots from shares with GlusterFS backend; (bso#12743). + Fix for Solaris C compiler; (bso#12559). + s3: locking: Update oplock optimization for the leases era; (bso#12628). + Make the Solaris C compiler happy; (bso#12693). + s3: libgpo: Allow skipping GPO objects that don't have the expected LDAP attributes; (bso#12695). + Fix buffer overflow caused by wrong use of getgroups; (bso#12747). + lib: debug: Avoid negative array access; (bso#12746). + cleanupdb: Fix a memory read error; (bso#12748). + streams_xattr and kernel oplocks results in NT_STATUS_NETWORK_BUSY; (bso#7537). + winbindd: idmap_autorid allocates ids for unknown SIDs from other backends; (bso#11961). + vfs_fruit: Resource fork open request with flags=O_CREAT|O_RDONLY; (bso#12565). + manpages/vfs_fruit: Document global options; (bso#12615). + lib/pthreadpool: Fix a memory leak; (bso#12624). + Lookup-domain for well-known SIDs on a DC; (bso#12727). + winbindd: Fix error handling in rpc_lookup_sids(); (bso#12728). + winbindd: Trigger possible passdb_dsdb initialisation; (bso#12729). + credentials_krb5: use gss_acquire_cred for client-side GSSAPI use case; (bso#12611). + lib/crypto: Implement samba.crypto Python module for RC4; (bso#12690). + ctdb-readonly: Avoid a tight loop waiting for revoke to complete; (bso#12697). + ctdb_event monitor command crashes if event is not specified; (bso#12723). + ctdb-docs: Fix documentation of "-n" option to 'ctdb tool'; (bso#12733). + smbd: Fix smb1 findfirst with DFS; (bso#12558). + smbd: Do an early exit on negprot failure; (bso#12610). + winbindd: Fix substitution for 'template homedir'; (bso#12699). + s4:kdc: Disable principal based autodetected referral detection; (bso#12554). + idmap_autorid: Allocate new domain range if the callers knows the sid is valid; (bso#12613). + LINKFLAGS_PYEMBED should not contain -L/some/path; (bso#12724). + PAM auth with WBFLAG_PAM_GET_PWD_POLICY returns wrong policy for trusted domain; (bso#12725). + rpcclient: Allow -U'OTHERDOMAIN\user' again; (bso#12731). + winbindd: Fix password policy for pam authentication; (bso#12725). + s3:gse: Correctly handle external trusts with MIT; (bso#12554). + auth/credentials: Always set the realm if we set the principal from the ccache; (bso#12611). + replace: Include sysmacros.h; (bso#12686). + s3:vfs_expand_msdfs: Do not open the remote address as a file; (bso#12687). + s3:libsmb: Only print error message if kerberos use is forced; (bso#12704). + winbindd: Child process crashes when kerberos-authenticating a user with wrong password; (bso#12708). + vfs_fruit: Office document opens as read-only on macOS due to CNID semantics; (bso#12715). + vfs_acl_xattr: Fix failure to get ACL on Linux if memory is fragmented; (bso#12737).- Generate and update vendor-files tarball from Git + SuSEfirewall2 service samba-client only setup IPv4 rule; (bsc#1034416).- Generate source tarball directly from Git using OBS tar_scm + use version string derived from parent Git tag and commit hash - remove obsolete vendor-files/tools/package-data version ID + explicitly generate ctdb manpages, needed without "make dist"- Update to 4.6.2 + remove bso#12721 patches now upstream- Enable samba-ceph build for openSUSE and SLE12SP3+; (fate#321622). + x86-64 and aarch64- Enable librados CTDB lock helper for samba-ceph package; (fate#321622).- Build and install the html man pages (bsc#1021907).- Fix CVE-2017-2619 regression with "follow symlinks = no"; (bso#12721).- Update to 4.6.1 + symlink race permits opening files outside share directory; CVE-2017-2619; (bso#12496); (bsc#1027147) + testparm checks for valid idmap parameters + add new krb client encryption types + support for printer driver upload from windows 10 + inherit owner = 'unix only' for improved quota support + improved CTDB event support + new primary group support for idmap_ad + idmap_hash deprecated + mvxattr added to recursively rename extended attributes- Remove chkconfig requirements for systemd systems- Don't call insserv if systemd is used- Fix check if we need to require insserv- async_req: make async_connect_send() "reentrant"; (bso#12105); (bsc#1024416).- Force usage of ncurses6-config thru NCURSES_CONFIG env var; (bsc#1023847).- add missing patch for libnss_wins segfault; (bsc#995730).- Fix vfs_ceph builds against recent Ceph versions; (bsc#1021933).- Document "winbind: ignore domains" parameter; (bsc#1019416).- Add base Samba dependency to samba-ceph package.- Update to 4.5.3 + Heap-based Buffer Overflow Remote Code Execution Vulnerability; CVE-2016-2123; (bso#12409); (bsc#1014437). + Don't send delegated credentials to all servers; CVE-2016-2125; (bso#12445); (bsc#1014441). + denial of service due to a client triggered crash in the winbindd parent process; CVE-2016-2126; (bso#12446); (bsc#1014442). - 4.5.1 and 4.5.2 updates + various streams vfs fixes + various printing fixes + ntlm_auth: do not map explicitly empty domain + various stability fixes in smbd + match file compression ReFS behavior- Add missing ldb module directory; (bnc#1012092).- s3/client: obey 'disable netbios' smb.conf param, don't connect via NBT port; (bsc#1009085); (bso#12418).- Include vfstest in samba-test; (bsc#1001203).- s3/winbindd: using default domain with user@domain.com format fails; (bsc#997833).- Fix segfault in libnss_wins; (bso#12277); (bso#12269); (bsc#995730).- Update to 4.5.0 + NTLM1 Authentication disabled by default + SMB2.1 leases enabled by default + Support for OFD locks + ctdb tool rewritten + Added shadow copy snapshot prefix parameter- Fix illegal memory access after memory has been deleted; (bso#11836); (bsc#975299).- Prevent core, make sure response->extra_data.data is always cleared out; (bsc#993692).- Don't package man pages for VFS modules that aren't built; (boo#993707).- Fix population of ctdb sysconfig after source merge; (bsc#981566).- Enable vfs_ceph builds for Factory (x86-64) + Package as samba-ceph to avoid Ceph dependency in base package.- Update to 4.4.5 + Prevent client-side SMB2 signing downgrade; CVE-2016-2119; (bso#11860); (bsc#986869).- Remove obsolete syslog.target; (bsc#983938).- Honor smb.conf socket options in winbind; (bsc#975131).- Don't use htons() with IP_PROTO_RAW; (bso#11705); (bsc#969522).- Update to 4.4.4 + SMB3 multichannel: Add implementation of missing channel sequence number verification; (bso#11809). + smbd:close: Only remove kernel share modes if they had been taken at open; (bso#11919). + notifyd: Prevent NULL deref segfault in notifyd_peer_destructor; (bso#11930). + s3:rpcclient: Make '--pw-nt-hash' option work; (bso#10796). + Fix case sensitivity issues over SMB2 or above; (bso#11438). + s3:smbd: Fix anonymous authentication if signing is mandatory. (bso#11910) + Fix NTLM Authentication issue with squid; (bso#11914). + pdb: Fix segfault in pdb_ldap for missing gecos; (bso#11530). + Fix memory leak in share mode locking; (bso#11934).- Update to 4.4.3 + Various post-badlock regressions; (bso#11841); (bso#11850); (bso#11858); (bso#11870); (bso#11872). + Only allow idmap_hash for default idmap config (bso#11786). + smbd: Avoid large reads beyond EOF; (bso#11878). + vfs_acl_common: Avoid setting POSIX ACLs if "ignore system acls" is set; (bso#11806). + libads: Record session expiry for spnego sasl binds; (bso#11852).- Fix NTLMSSP regressions caused by previous CVE fixes; (bso#11849); (bsc#975962); (bsc#979268), (bsc#977669).- Revert shared library packaging to comply with SLPP- Update to 4.4.2 + A man-in-the-middle can downgrade NTLMSSP authentication; CVE-2016-2110; (bso#11688); (bsc#973031). + Domain controller netlogon member computer can be spoofed; CVE-2016-2111; (bso#11749); (bsc#973032). + LDAP conenctions vulnerable to downgrade and MITM attack; CVE-2016-2112; (bso#11644); (bsc#973033). + TLS certificate validation missing; CVE-2016-2113; (bso#11752); (bsc#973034). + Named pipe IPC vulnerable to MITM attacks; CVE-2016-2115; (bso#11756); (bsc#973036). + "Badlock" DCERPC impersonation of authenticated account possible; CVE-2016-2118; (bso#11804); (bsc#971965). + DCERPC server and client vulnerable to DOS and MITM attacks; CVE-2015-5370; (bso#11344); (bsc#936862).- Fix samba.tests.messaging test and prevent potential tdb corruption by removing obsolete now invalid tdb_close call; (bsc#974629).- Obsolete libsmbclient from libsmbclient0 while not providing it; (bsc#972197).- Update to 4.4.0. + Read of uninitialized memory DNS TXT handling; (bso#11128); (bso#11686); CVE-2016-0771. + Getting and setting Windows ACLs on symlinks can change permissions on link target; (bso#11648); CVE-2015-7560. + Sockets with htons(IPPROTO_RAW); (bso#11705); CVE-2015-8543. + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystem with no ACL support; (bso#10489). + docs: Add example for domain logins to smbspool man page; (bso#11643). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + docs: Add smbspool_krb5_wrapper manpage; (bso#11690). + winbindd: Return trust parameters when listing trusts; (bso#11691). + ctdb: Do not provide a useless pkgconfig file for ctdb; (bso#11696). + Crypto.Cipher.ARC4 is not available on some platforms, fallback to M2Crypto.RC4.RC4 then; (bso#11699). + s3:utils/smbget: Set default blocksize; (bso#11700). + Streamline 'smbget' options with the rest of the Samba utils; (bso#11700). + s3:clispnego: Fix confusing warning in spnego_gen_krb5_wrap(); (bso#11702). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + s3:vfs:glusterfs: Fix build after quota changes; (bso#11715). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + lib:socket: Fix CID 1350010: Integer OVERFLOW_BEFORE_WIDEN; (bso#11723). + smbd: Fix CID 1351215 Improper use of negative value; (bso#11724). + smbd: Fix CID 1351216 Dereference null return value; (bso#11725). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + docs: Add manpage for cifsdd; (bso#11730). + param: Fix str_list_v3 to accept ; again; (bso#11732). + lib/socket: Fix improper use of default interface speed; (bso#11734). + lib:socket: Fix CID 1350009: Fix illegal memory accesses (BUFFER_SIZE_WARNING); (bso#11735). + libcli: Fix debug message, print sid string for new_ace trustee; (bso#11738). + Fix installation path of Samba helper binaries; (bso#11739). + Fix memory leak in loadparm; (bso#11740). + tevent: version 0.9.28: Fix memory leak when old signal action restored; (bso#11742). + smbd: Ignore SVHDX create context; (bso#11753). + Fix net join; (bso#11755). + s3:libads: setup the msDS-SupportedEncryptionTypes attribute on ldap_add; (bso#11755). + passdb: Add linefeed to debug message; (bso#11763). + s3:utils/smbget: Fix option parsing; (bso#11767). + libnet: Make Kerberos domain join site-aware; (bso#11769). + Reset TCP Connections during IP failover; (bso#11770). + ldb: Version 1.1.26; (bso#11772). + s3:smbd: Add negprot remote arch detection for OSX; (bso#11773). + vfs_glusterfs: Fix use after free in AIO callback; (bso#11774). + mkdir can return ACCESS_DENIED incorrectly on create race; (bso#11780). + "trustdom_list_done: Got invalid trustdom response" message should be avoided; (bso#11782). + Mismatch between local and remote attribute ids lets replication fail with custom schema; (bso#11783). + Quota is not supported on Solaris 10; (bso#11788). + Talloc: Version 2.1.6; (bso#11789). + smbd: Enable multi-channel if 'server multi channel support = yes' in the config; (bso#11796). + build: Fix build when '--without-quota' specified; (bso#11798). + lib/socket/interfaces: Fix some uninitialied bytes; (bso#11802). + Access based share enum: handle permission set in configuration files; (bso#8093). + See also WHATSNEW.txt from the samba-doc package.- Update to 4.3.6. + Getting and setting Windows ACLs on symlinks can change permissions on link target; CVE-2015-7560; (bso#11648); (bsc#968222). + Fix Out-of-bounds read in internal DNS server; CVE-2016-0771; (bso#11128); (bso#11686); (bsc#968223).- Upgrade on-disk FSRVP server state to new version; (bsc#924519).- Only obsolete but do not provide gplv2/3 package names; (bsc#968973).- Relocate existing lock files to /var/lib/samba/lock; (bsc#968963).- Obsolete no longer existing samba-32bit package; (bsc#967625).- Update to 4.3.5. + s3:utils/smbget: Fix recursive download; (bso#6482). + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystemi with no ACL support; (bso#10489). + s3:smbd/oplock: Obey kernel oplock setting when releasing oplocks; (bso#11400). + vfs_shadow_copy2: Fix case where snapshots are outside the share; (bso#11580). + smbclient: Query disk usage relative to current directory; (bso#11662). + winbindd: Handle expired sessions correctly; (bso#11670). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + smbcacls: Fix uninitialized variable; (bso#11682). + s3:smbd: Ignore initial allocation size for directory creation; (bso#11684). + s3-client: Add a KRB5 wrapper for smbspool; (bso#11690). + s3-parm: Clean up defaults when removing global parameters; (bso#11693). + Use M2Crypto.RC4.RC4 on platforms without Crypto.Cipher.ARC4; (bso#11699). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + ctdb: Remove error messages after kernel security update; CVE-2015-8543; (bso#11705). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + param: Fix str_list_v3 to accept ";" again; (bso#11732).- Shift samba-client sysconfig data into samba and samba-winbind; (bsc#947361).- Simplify shared library packaging; (bsc#966956).- Enable clustering (CTDB) support; (bsc#966271).- s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703); (bsc#964023).- Add quotes around path of update-apparmor-samba-profile; (bnc#962177).- Remove autoconf build-time requirement.- Update to 4.3.4. + vfs_fruit: Enable POSIX directory rename semantics; (bso#11065). + Crash: Bad talloc magic value - access after free; (bso#11394). + Copying files with vfs_fruit fails when using vfs_streams_xattr without stream prefix and type suffix; (bso#11466). + samba-tool: Fix uncaught exception if no fSMORoleOwner attribute is given; (bso#11613). + Fix a typo in the smb.conf manpage, explanation of idmap config; (bso#11619). + Correctly initialize the list head when keeping a list of primary followed by DFS connections; (bso#11624). + Reduce the memory footprint of empty string options; (bso#11625). + lib/async_req: Do not install async_connect_send_test; (bso#11639). + Fix typos in man vfs_gpfs; (bso#11641). + Make "hide dot files" option work with "store dos attributes = yes"; (bso#11645). + Fix a corner case of the symlink verification; (bso#11647); (bnc#960249). + Do not disable "store dos attributes" on-the-fly; (bso#11649). + Update lastLogon and lastLogonTimestamp; (bso#11659).- Prevent access denied if the share path is "/"; (bso#11647); (bnc#960249).- Update to 4.3.3. + Malicious request can cause Samba LDAP server to hang, spinning using CPU; CVE-2015-3223; (bso#11325); (bnc#958581). + Remote read memory exploit in LDB; CVE-2015-5330; (bso#11599); (bnc#958586). + Insufficient symlink verification (file access outside the share); CVE-2015-5252; (bso#11395); (bnc#958582). + No man in the middle protection when forcing smb encryption on the client side; CVE-2015-5296; (bso#11536); (bnc#958584). + Currently the snapshot browsing is not secure thru windows previous version (shadow_copy2); CVE-2015-5299; (bso#11529); (bnc#958583). + Fix Microsoft MS15-096 to prevent machine accounts from being changed into user accounts; CVE-2015-8467; (bso#11552); (bnc#958585).- Update to 4.3.2. + vfs_gpfs: Re-enable share modes; (bso#11243). + dcerpc.idl: Accept invalid dcerpc_bind_nak pdus; (bso#11327). + s3-smbd: Fix old DOS client doing wildcard delete - gives an attribute type of zero; (bso#11452). + Add libreplace dependency to texpect, fixes a linking error on Solaris; (bso#11511). + s4: Fix linking of 'smbtorture' on Solaris; (bso#11512). + s4:lib/messaging: Use correct path for names.tdb; (bso#11562). + Fix segfault of 'net ads (join|leave) -S INVALID' with nss_wins; (bso#11563). + async_req: Fix non-blocking connect(); (bso#11564). + auth: gensec: Fix a memory leak; (bso#11565). + lib: util: Make non-critical message a warning; (bso#11566). + Fix winbindd crashes with samlogon for trusted domain user; (bso#11569); (bnc#949022). + smbd: Send SMB2 oplock breaks unencrypted; (bso#11570). + ctdb: Open the RO tracking db with perms 0600 instead of 0000; (bso#11577). + s3:smb2_server: Make the logic of SMB2_CANCEL DLIST_REMOVE() clearer; (bso#11581). + s3-smbd: Fix use after issue in smbd_smb2_request_dispatch(); (bso#11581). + manpage: Correct small typo error; (bso#11584). + s3: smbd: If EAs are turned off on a share don't allow an SMB2 create containing them; (bso#11589). + Backport some valgrind fixes from upstream master; (bso#11597). + auth: Consistent handling of well-known alias as primary gid; (bso#11608). + winbind: Fix crash on invalid idmap configs; (bso#11612). + s3: smbd: have_file_open_below() fails to enumerate open files below an open directory handle; (bso#11615). + Changing log level of two entries to DBG_NOTICE; (bso#9912).- Ensure samlogon fallback requests are rerouted after kerberos failure; (bnc#953382); (bnc#953972).- Ensure to link with --as-needed flag by removing SUSE_ASNEEDED=0. - Always use the default optimization even on pre-9.2 systems.- Remove redundant configure options while adding with-relro.- Relocate the lockdir to the /var/lib/samba/lock directory.- Cleanup and enhance the pidl sub package.- Require renamed python-ldb-devel and python-talloc-devel at build-time. - Requires python-ldb and python-talloc from the python subpackage.- Update to 4.3.1. + s3: smbd: Fix our access-based enumeration on "hide unreadable" to match Windows; (bso#10252). + nss_winbind: Fix hang on Solaris on big groups; (bso#10365). + smbd: Fix file name buflen and padding in notify repsonse; (bso#10634). + kerberos: Make sure we only use prompter type when available; winbind: Fix 100% loop; (bso#11038). + source3/lib/msghdr.c: Fix compiling error on Solaris; (bso#11053). + s3:ctdbd_conn: make sure we destroy tevent_fd before closing the socket; (bso#11316). + s3: smbd: Fix mkdir race condition; (bso#11486). + pam_winbind: Fix a segfault if initialization fails; (bso#11502). + s3: dfs: Fix a crash when the dfs targets are disabled; (bso#11509). + s4:lib/messaging: Use 'msg.lock' and 'msg.sock' for messaging related subdirs; (bso#11515). + s3: smbd: Fix opening/creating :stream files on the root share directory; (bso#11522). + lib/param: Fix hiding of FLAG_SYNONYM values; (bso#11526). + net: Fix a crash with 'net ads keytab create'; (bso#11528). + s3: smbd: Fix a crash in unix_convert(); (bso#11535). + s3: smbd: Fix NULL pointer bug introduced by previous 'raw' stream fix (bso#11522); (bso#11535). + vfs_fruit: Return value of ad_pack in vfs_fruit.c; (bso#11543). + vfs_commit: set the fd on open before calling SMB_VFS_FSTAT; (bso#11547). + s3:locking: Initialize lease pointer in share_mode_traverse_fn(); (bso#11549). + s3:smbstatus: Add stream name to share_entry_forall(); (bso#11550). + s3:lib: Validate domain name in lookup_wellknown_name(); (bso#11555). + s3: lsa: lookup_name() logic for unqualified (no DOMAIN component) names is incorrect; (bso#11555).- Fix 100% CPU in winbindd when logging in with "user must change password on next logon"; (bso#11038).- Relocate the tmpfiles.d directory to the client package; (bnc#947552).- Do not provide libpdb0 from libsamba-passdb0 but add it to baselibs.conf instead; (bnc#942716).- Package /var/lib/samba/private/sock with 0700 permissions; (bnc#946051).- Package /var/lib/samba/msg with 0755 permissions; (bso#11515); (bnc#945502).- Require to install libfam0-gamin from samba-libs on post-12.1 and pre-13.15 systems; (bnc#945013).- Update to 4.3.0. + Samba "map to guest = Bad uid" doesn't work; (bso#9862). + revert LDAP extended rule 1.2.840.113556.1.4.1941 LDAP_MATCHING_RULE_IN_CHAIN changes; (bso#10493). + No objectClass found in replPropertyMetaData on ordinary objects (non-deleted); (bso#10973). + Stream names with colon don't work with fruit:encoding = native; (bso#11278). + NetApp joined to a Samba/ADDC cannot resolve SIDs; (bso#11291). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + "force group" with local group not working; (bso#11320). + strsep is not available on Solaris; (bso#11359). + smbtorture does not build when configured --with-system-mitkrb5; (bso#11411). + Build with GPFS support is broken; (bso#11421). + Build broken with --disable-python; (bso#11424). + net share allowedusers crashes; (bso#11426). + nmbd incorrectly matches netbios names as own name; (bso#11427). + Python bindings don't check integer types; (bso#11429). + Python bindings don't check array sizes; (bso#11430). + CTDB's eventscript error handling is broken; (bso#11431). + Fix crash in nested ctdb banning; (bso#11432). + Cannot build ctdbpmda; (bso#11434). + samba-tool uncaught exception error; (bso#11436). + Crash in notify_remove caused by change notify = no; (bso#11444). + Poor SMB3 encryption performance with AES-GCM; (bso#11451). + Poor SMB3 encryption performance with AES-GCM (part1); (bso#11451). + fix recursion problem in rep_strtoll in lib/replace/replace.c; (bso#11455). + --bundled-libraries=!ldb,!pyldb,!pyldb-util doesn't disable ldb build and install; (bso#11458). + xid2sid gives inconsistent results; (bso#11464). + ctdb: Fix the build on FreeBSD 10.1; (bso#11465). + Handling of 0 byte resource fork stream; (bso#11467). + AD samr GetGroupsForUser fails for users with "()" in their name; (bso#11488).- Configure with --bundled-libraries=NONE; (bso#11458).- Adapt net-kdc-lookup patch for post-3.3 Samba versions; (bnc#295284).- Remove libiniparser-devel build-time requirement.- Update to 4.2.3. + s4:lib/tls: Fix build with gnutls 3.4; (bso#8780). + s4.2/fsmo.py: Fixed fsmo transfer exception; (bso#10924). + winbindd: Sync secrets.ldb into secrets.tdb on startup; (bso#10991). + Logon via MS Remote Desktop hangs; (bso#11061). + s3: lib: util: Ensure we read a hex number as %x, not %u; (bso#11068). + tevent: Add a note to tevent_add_fd(); (bso#11141). + s3:param/loadparm: Fix 'testparm --show-all-parameters'; (bso#11170). + s3-unix_msg: Remove socket file after closing socket fd; (bso#11217). + smbd: Fix a use-after-free; (bso#11218); (bnc#919309). + s3-rpc_server: Fix rpc_create_tcpip_sockets() processing of interfaces; (bso#11245). + s3:smb2: Add padding to last command in compound requests; (bso#11277). + Add IPv6 support to ADS client side LDAP connects; (bso#11281). + Add IPv6 support for determining FQDN during ADS join; (bso#11282). + s3: IPv6 enabled DNS connections for ADS client; (bso#11283). + Fix invalid write in ctdb_lock_context_destructor; (bso#11293). + Excessive cli_resolve_path() usage can slow down transmission; (bso#11295). + vfs_fruit: Add option "veto_appledouble"; (bso#11305). + tstream: Make socketpair nonblocking; (bso#11312). + idmap_rfc2307: Fix wbinfo '--gid-to-sid' query; (bso#11313). + Group creation: Add msSFU30Name only when --nis-domain was given; (bso#11315). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + Build fails on Solaris 11 with "‘PTHREAD_MUTEX_ROBUST’ undeclared"; (bso#11319). + smbd/trans2: Add a useful diagnostic for files with bad encoding; (bso#11323). + Change sharesec output back to previous format; (bso#11324). + Robust mutex support broken in 1.3.5; (bso#11326). + Kerberos auth info3 should contain resource group ids available from pac_logon; winbindd: winbindd_raw_kerberos_login - ensure logon_info exists in PAC; (bso#11328); (bnc#912457). + s3:smb2_setinfo: Fix memory leak in the defer_rename case; (bso#11329). + tevent: Fix CID 1035381 Unchecked return value; (bso#11330). + tdb: Fix CID 1034842 and 1034841 Resource leaks; (bso#11331). + s3: smbd: Use separate flag to track become_root()/unbecome_root() state; (bso#11339). + s3: smbd: Codenomicon crash in do_smb_load_module(); (bso#11342). + pidl: Make the compilation of PIDL producing the same results if the content hasn't change; (bso#11356). + winbindd: Disconnect child process if request is cancelled at main process; (bso#11358). + vfs_fruit: Check offset and length for AFP_AfpInfo read requests; (bso#11363). + docs: Overhaul the description of "smb encrypt" to include SMB3 encryption; (bso#11366). + s3:auth_domain: Fix talloc problem in connect_to_domain_password_server(); (bso#11367). + ncacn_http: Fix GNUism; (bso#11371).- Disable rpath usage; (bnc#902421).- Make the winbind package depend on the matching libwbclient version and vice versa; (bnc#936909).- Backport changes to use resource group sids obtained from pac logon_info; (bso#11328); (bnc#912457).- Order winbind.service Before and Want nss-user-lookup target.- Remove fam-devel build-time dependency for post-6 RHEL systems.- Update to 4.2.2. + s3:smbXsrv: refactor duplicate code into smbXsrv_session_clear_and_logoff(); (bso#11182). + gencache: don't fail gencache_stabilize if there were records to delete; (bso#11260). + s3: libsmbclient: After getting attribute server, ensure main srv pointer is still valid; (bso#11186). + s4: rpc: Refactor dcesrv_alter() function into setup and send steps; (bso#11236). + s3: smbd: Incorrect file size returned in the response of "FILE_SUPERSEDE Create"; (bso#11240). + Mangled names do not work with acl_xattr; (bso#11249). + nmbd rewrites browse.dat when not required; (bso#11254). + vfs_fruit: add option "nfs_aces" that controls the NFS ACEs stuff; (bso#11213). + s3:smbd: Add missing tevent_req_nterror; (bso#11224). + vfs: kernel_flock and named streams; (bso#11243). + vfs_gpfs: Error code path doesn't call END_PROFILE; (bso#11244). + s4: libcli/finddcs_cldap: continue processing CLDAP until all addresses are used; (bso#11284). + ctdb: check for talloc_asprintf() failure; (bso#11201). + spoolss: purge the printer name cache on name change; (bso#11210); (bnc#901813). + CTDB statd-callout does not scale; (bso#11204). + vfs_fruit: also map characters below 0x20; (bso#11221). + ctdb: Coverity fix for CID 1291643; (bso#11201). + Multiplexed RPC connections are not handled by DCERPC server; (bso#11225). + Fix terminate connection behavior for asynchronous endpoint with PUSH notification flavors; (bso#11226). + ctdb-scripts: Fix bashism in ctdbd_wrapper script; (bso#11007). + ctdb: Fix CIDs 1125615, 1125634, 1125613, 1288201 and 1125553; (bso#11201). + SMB2 should cancel pending NOTIFY calls with DELETE_PENDING if the directory is deleted; (bso#11257). + s3:winbindd: make sure we remove pending io requests before closing client sockets; (bso#11141); (bnc#931854). + Fix panic triggered by smbd_smb2_request_notify_done() -> smbXsrv_session_find_channel() in smbd; (bso#11182). + 'sharesec' output no longer matches input format; (bso#11237). + waf: Fix systemd detection; (bso#11200). + CTDB: Fix portability issues; (bso#11202). + CTDB: Fix some IPv6-related issues; (bso#11203). + CTDB statd-callout does not scale; (bso#11204). + 'net ads dns gethostbyname' crashes with an error in TALLOC_FREE if you enter invalid values; (bso#11234). + libads: record service ticket endtime for sealed ldap connections; (bso#11267). + lib/util: Include DEBUG macro in internal header files before samba_util.h; (bso#11033).- Avoid a crash inside the tevent epoll backend; (bso#11141); (bnc#931854).- Remove the independently built libraries ldb, talloc, tdn, and tevent and the post-10.3 renamed libsmbclient from baselibs.conf.- Drop redundant doc attribute from man pages.- Update to 4.2.1. + s3:winbind:grent: Don't stop group enumeration when a group has no gid; (bso#8905). + Initialize dwFlags field of DNS_RPC_NODE structure; (bso#9791). + s3: lib: ntlmssp: If NTLMSSP_NEGOTIATE_TARGET_INFO isn't set, cope with servers that don't send the 2 unused fields; (bso#10016). + build:wafadmin: Fix use of spaces instead of tabs; (bso#10476). + waf: Fix the build on openbsd; (bso#10476). + s3: client: "client use spnego principal = yes" code checks wrong name; (bso#10888). + spoolss: Retrieve published printer GUID if not in registry; (bso#11018). + s3: lib: libsmbclient: If reusing a server struct, check every cli->timout miliseconds if it's still valid before use; (bso#11079). + vfs_fruit: Enhance handling of malformed AppleDouble files; (bso#11125). + backupkey: Explicitly link to gnutls and gcrypt; (bso#11135). + replace: Remove superfluous check for gcrypt header; (bso#11135). + Backport subunit changes; (bso#11137). + libcli/auth: Match Declaration of netlogon_creds_cli_context_tmp with implementation; (bso#11140). + s3-winbind: Fix cached user group lookup of trusted domains; (bso#11143). + talloc: Version 2.1.2; (bso#11144). + Update libwbclient version to 0.12; (bso#11149). + brlock: Use 0 instead of empty initializer list; (bso#11153). + s4:auth/gensec_gssapi: Let gensec_gssapi_update() return NT_STATUS_LOGON_FAILURE for unknown errors; (bso#11164). + docs/idmap_rid: Remove deprecated base_rid from example; (bso#11169); (bnc#913304). + s3: libcli: smb1: Ensure we correctly finish a tevent req if the writev fails in the SMB1 case; (bso#11173). + backupkey: Use ndr_pull_struct_blob_all(); (bso#11174). + Fix lots of winbindd zombie processes on Solaris platform; (bso#11175). + s3: libsmbclient: Add missing talloc stackframe; (bso#11177). + s4-process_model: Do not close random fds while forking; (bso#11180). + s3-passdb: Fix 'force user' with winbind default domain; (bso#11185).- Prevent samba package updates from disabling samba kerberos printing.- Add sparse file support for samba; (fate#318424).- Purge printer name cache on spoolss SetPrinter change; (bso#11210); (bnc#901813).- Correctly retain errno from Btrfs snapshot ioctls; (bnc#923374).- Simplify libxslt build requirement and README.SUSE install. - Remove no longer required cleanup steps while populating the build root.- Remove deprecated base_rid example from idmap_rid manpage; (bso#11169); (bnc#913304).- Update to 4.2.0. + smbd: Stop using vfs_Chdir after SMB_VFS_DISCONNECT; (bso#1115). + pam_winbind: fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Make 'profiles' work again; (bso#9629). + s3:smb2_server: protect against integer wrap with "smb2 max credits = 65535"; (bso#9702). + Make validate_ldb of String(Generalized-Time) accept millisecond format ".000Z"; (bso#9810). + Use -R linker flag on Solaris, not -rpath; (bso#10112). + vfs: Add glusterfs manpage; (bso#10240). + Make 'smbclient' use cached creds; (bso#10279). + pdb: Fix build issues with shared modules; (bso#10355). + s4-dns: Add support for BIND 9.10; (bso#10620). + idmap: Return the correct id type to *id_to_sid methods; (bso#10720). + printing/cups: Pack requested-attributes with IPP_TAG_KEYWORD; (bso#10808). + Don't build vfs_snapper on FreeBSD; (bso#10834). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3: smb2cli: query info return length check was reversed; (bso#10848). + s3: lib, s3: modules: Fix compilation on Solaris; (bso#10849). + lib: uid_wrapper: Fix setgroups and syscall detection on a system without native uid_wrapper library; (bso#10851). + winbind3: Fix pwent variable substitution; (bso#10852). + Improve samba-regedit; (bso#10859). + registry: Don't leave dangling transactions; (bso#10860). + Fix build of socket_wrapper on systems without SO_PROTOCOL; (bso#10861). + build: Do not install 'texpect' binary anymore; (bso#10862). + Fix testparm to show hidden share defaults; (bso#10864). + libcli/smb: Fix smb2cli_validate_negotiate_info with min=PROTOCOL_NT1 max=PROTOCOL_SMB2_02; (bso#10866). + Integrate CTDB into top-level Samba build; (bso#10892). + samba-tool group add: Add option '--nis-domain' and '--gid'; (bso#10895). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + Fix smbclient loops doing a directory listing against Mac OS X 10 server with a non-wildcard path; (bso#10904). + Fix print job enumeration; (bso#10905); (bnc#898031). + samba-tool: Create NIS enabled users and unixHomeDirectory attribute; (bso#10909). + Add support for SMB2 leases; (bso#10911). + btrfs: Don't leak opened directory handle; (bso#10918). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: fix keytab array NULL termination; (bso#10933). + s3:passdb: fix logic in pdb_set_pw_history(); (bso#10940). + Cleanup add_string_to_array and usage; (bso#10942). + dbwrap_ctdb: Pass on mutex flags to tdb_open; (bso#10942). + Fix RootDSE search with extended dn control; (bso#10949). + Fix 'samba-tool dns serverinfo ' for IPv6; (bso#10952). + libcli/smb: only force signing of smb2 session setups when binding a new session; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + socket_wrapper: Add missing prototype check for eventfd; (bso#10965). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + vfs_streams_xattr: Check stream type; (bso#10971). + s3: smbd: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + vfs_fruit: Add support for AAPL; (bso#10983). + Fix spoolss IDL response marshalling when returning error without clearing info; (bso#10984). + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279). + Fix IPv6 support in CTDB; (bso#10996). + ctdb-daemon: Use correct tdb flags when enabling robust mutex support; (bso#11000). + vfs_streams_xattr: Add missing call to SMB_VFS_NEXT_CONNECT; (bso#11005). + s3-util: Fix authentication with long hostnames; (bso#11008). + ctdb-build: Fix build without xsltproc; (bso#11014). + packaging: Include CTDB man pages in the tarball; (bso#11014). + pdb_get_trusteddom_pw() fails with non valid UTF16 random passwords; (bso#11016). + Make Sharepoint search show user documents; (bso#11022). + nss_wrapper: check for nss.h; (bso#11026). + Enable mutexes in gencache_notrans.tdb; (bso#11032). + tdb_wrap: Make mutexes easier to use; (bso#11032). + lib/util: Avoid collision which alread defined consumer DEBUG macro; (bso#11033). + winbind: Retry after SESSION_EXPIRED error in ping-dc; (bso#11034). + s3-libads: Fix a possible segfault in kerberos_fetch_pac(); (bso#11037). + vfs_fruit: Fix base_fsp name conversion; (bso#11039). + vfs_fruit: mmap under FreeBSD needs PROT_READ; (bso#11040). + Fix authentication using Kerberos (not AD); (bso#11044). + net: Fix sam addgroupmem; (bso#11051). + vfs_snapper: Correctly handles multi-byte DBus strings; (bso#11055); (bnc#913238). + cli_connect_nb_send: Don't segfault on host == NULL; (bso#11058). + utils: Fix 'net time' segfault; (bso#11058). + libsmb: Provide authinfo domain for encrypted session referrals; (bso#11059). + s3-pam_smbpass: Fix memory leak in pam_sm_authenticate(); (bso#11066). + vfs_glusterfs: Add comments to the pipe(2) code; (bso#11069). + vfs/glusterfs: Change xattr key to match gluster key; (bso#11069). + vfs_glusterfs: Implement AIO support; (bso#11069). + s3-vfs: Fix developer build of vfs_ceph module; (bso#11070). + s3: netlogon: Ensure we don't call talloc_free on an uninitialized pointer; (bso#11077); CVE-2015-0240; (bnc#917376). + vfs: Add a brief vfs_ceph manpage; (bso#11088). + s3: smbclient: Allinfo leaves the file handle open; (bso#11094). + Fix Win8.1 Credentials Manager issue after KB2992611 on Samba domain; (bso#11097). + debug: Set close-on-exec for the main log file FD; (bso#11100). + s3: smbd: leases - losen paranoia check. Stat opens can grant leases; (bso#11102). + s3: smbd: SMB2 close. If a file has delete on close, store the return info before deleting; (bso#11104). + doc:man:vfs_glusterfs: improve the configuration section; (bso#11117). + snprintf: Try to support %j; (bso#11119). + ctdb-io: Do not use sys_write to write to client sockets; (bso#11124). + doc-xml: Add 'sharesec' reference to 'access based share enum'; (bso#11127).- Update to 4.2.0rc5. + Ensure we don't call talloc_free on an uninitialized pointer; CVE-2015-0240; (bso#11077); (bnc#917376).- Fix usage of freed memory on server exit; (bso#11218); (bnc#919309).- Fix tdb_store_flag_to_ntdb() gcc5 build failure.- Fix vfs_snapper DBus string handling; (bso#11055); (bnc#913238).- Update to 4.1.16. + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279).- Adjust baselibs.conf due to libpdb0 package rename to libsamba-passdb0.- Fix libsmbclient DFS referral handling. + Reuse connections derived from DFS referrals; (bso#10123); (fate#316512). + Set domain/workgroup based on authentication callback value; (bso#11059).- Update to 4.2.0rc4. - Add libsamba-debug, libsocket-blocking, libsamba-cluster-support, and libhttp to the libs package; (boo#913547). - Rename libpdb packages to libsamba-passdb. - Drop libsmbsharemodes packages.- Enable avahi support on post-12.2 systems.- Update to 4.1.15. + pam_winbind: Fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Fix profiles tool; (bso#9629). + s3-lib: Do not require a password with --use-ccache; (bso#10279). + s4:dsdb/rootdse: Expand extended dn values with the AS_SYSTEM control; (bso#10949). + s4-rpc: dnsserver: Fix enumeration of IPv4 and IPv6 addresses; (bso#10952). + s3:smb2_server: Allow reauthentication without signing; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + s3: smbd/modules: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + Fix 'domain join' by adding 'drsuapi.DsBindInfoFallBack' attribute 'supported_extensions'; (bso#11006). + idl:drsuapi: Manage all possible lengths of drsuapi_DsBindInfo; (bso#11006). + winbind: Retry LogonControl RPC in ping-dc after session expiration; (bso#11034).- yast2-samba-client should be able to specify osName and osVer on AD domain join; (bnc#873922).- Lookup FSRVP share snums at runtime rather than storing them persistently; (bnc#908627).- Specify soft dependency for network-online.target in Winbind systemd service file; (bnc#889175).- Fix spoolss error response marshalling; (bso#10984).- Update to 4.1.14. + pidl/wscript: Remove --with-perl-* options; revert buildtools/wafadmin/ Tools/perl.py back to upstream state; (bso#10472). + s4-dns: Add support for BIND 9.10; (bso#10620). + nmbd fails to accept "--piddir" option; (bso#10711). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + S3: source3/smbd/process.c::srv_send_smb() returns true on the error path; (bso#10880). + vfs_glusterfs: Remove "integer fd" code and store the glfs pointers; (bso#10889). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + s3: libsmbclient-smb2. MacOSX 10 SMB2 server doesn't set STATUS_NO_MORE_FILES when handed a non-wildcard path; (bso#10904). + spoolss: Fix jobid in level 3 EnumJobs response; (bso#10905). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: Fix keytab array NULL termination; (bso#10933). + Cleanup add_string_to_array and usage; (bso#10942).- Remove and cleanup shares and registry state associated with externally deleted snaphots exposed as shadow copies; (bnc#876312).- Use the upstream tar ball, as signature verification is now able to handle compressed archives.- Fix leak when closing file descriptor returned from dirfd; (bso#10918).- Fix spoolss EnumJobs and GetJob responses; (bso#10905); (bnc#898031). + Fix handling of bad EnumJobs levels; (bso#10898).- Remove dependency on gpg-offline as signature checking is implemented in the source validator.- Update to 4.1.13. + s3-libnet: Add libnet_join_get_machine_spns(); (bso#9984). + s3-libnet: Make sure we do not overwrite precreated SPNs; (bso#9984). + s3-libads: Add all machine account principals to the keytab; (bso#9985). + s3: winbindd: Old NT Domain code sets struct winbind_domain->alt_name to be NULL. Ensure this is safe with modern AD-DCs; (bso#10717). + Fix unstrcpy; (bso#10735). + pthreadpool: Slightly serialize jobs; (bso#10779). + s3: smbd: streams - Ensure share mode validation ignores internal opens (op_mid == 0); (bso#10797). + s3: smbd:open_file: Open logic fix; Use a more natural check; (bso#10809). + vfs_media_harmony: Fix a crash bug; (bso#10813). + docs: Mention incompatibility between kernel oplocks and streams_xattr; (bso#10814). + nmbd: Send waiting status to systemd; (bso#10816). + libcli: Fix a segfault calling smbXcli_req_set_pending() on NULL; (bso#10817). + nsswitch: Skip groups we were not able to map; (bso#10824). + s3-winbindd: Use correct realm for trusted domains in idmap child; (bso#10826). + s3: nmbd: Ensure the main nmbd process doesn't create zombies; (bso#10830). + s3: lib: Signal handling - ensure smbrun and change password code save and restore existing SIGCHLD handlers; (bso#10831). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3-winbindd: Do not use domain SID from LookupSids for Sids2UnixIDs call; (bso#10838). + s3: smb2cli: Query info return length check was reversed; (bso#10848). + registry: Don't leave dangling transactions; (bso#10860).- Update to 4.2.0rc2./sbin/ldconfig/sbin/ldconfiglibdcerpc-binding0libdcerpc0libndr-krb5pac0libndr-nbt0libndr-standard0libndr0libndr1libndr2libnetapi0libsamba-credentials0libsamba-credentials1libsamba-errors0libsamba-hostconfig0libsamba-passdb0libsamba-util0libsamdb0libsmbclient0libsmbconf0libsmbldap0libsmbldap2libtevent-util0libwbclient0h01-armsrv3 1752585390  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuv4.19.8+git.430.a10fe64854c4.19.8+git.430.a10fe64854c4.19.8+git.430.a10fe64854c4.19.8+git.430.a10fe64854c4.19.8+git.430.a10fe64854c4.19.8+git.430.a10fe64854c4.19.8+git.430.a10fe64854c4.19.8+git.430.a10fe64854c4.19.8+git.430.a10fe64854c4.19.8+git.430.a10fe64854c4.19.8+git.430.a10fe64854c4.19.8+git.430.a10fe64854c4.19.8+git.430.a10fe64854c4.19.8+git.430.a10fe64854c4.19.8+git.430.a10fe64854c4.19.8+git.430.a10fe64854c4.19.8+git.430.a10fe64854c4.19.8+git.430.a10fe64854c4.19.8+git.430.a10fe64854c-150600.3.18.24.19.8+git.430.a10fe64854c-150600.3.18.24.19.8+git.430.a10fe64854c4.19.8+git.430.a10fe64854c4.19.8+git.430.a10fe64854c4.19.8+git.430.a10fe64854c4.19.8+git.430.a10fe64854c4.19.8+git.430.a10fe64854c4.19.8+git.430.a10fe64854c4.19.8+git.430.a10fe64854c4.19.8+git.430.a10fe64854c4.19.8+git.430.a10fe64854c4.19.8+git.430.a10fe64854c4.19.8+git.430.a10fe64854c4.19.8+git.430.a10fe64854c4.19.8+git.430.a10fe64854c4.19.8+git.430.a10fe64854c4.19.8+git.430.a10fe64854c4.19.8+git.430.a10fe64854c4.19.8+git.430.a10fe64854c4.19.8+git.430.a10fe64854c4.19.8+git.430.a10fe64854c4.19.8+git.430.a10fe64854c4.19.8+git.430.a10fe64854clibdcerpc-binding.so.0libdcerpc-binding.so.0.0.1libdcerpc-server-core.so.0libdcerpc-server-core.so.0.0.1libdcerpc.so.0libdcerpc.so.0.0.1libndr-krb5pac.so.0libndr-krb5pac.so.0.0.1libndr-nbt.so.0libndr-nbt.so.0.0.1libndr-standard.so.0libndr-standard.so.0.0.1libndr.so.3libndr.so.3.0.1libnetapi.so.1libnetapi.so.1.0.0libsamba-credentials.so.1libsamba-credentials.so.1.0.0libsamba-errors.so.1libsamba-errors.so.1.0.0libsamba-hostconfig.so.0libsamba-hostconfig.so.0.0.1libsamba-passdb.so.0libsamba-passdb.so.0.28.0libsamba-util.so.0libsamba-util.so.0.0.1libsamdb.so.0libsamdb.so.0.0.1libsmbclient.so.0libsmbclient.so.0.7.0libsmbconf.so.0libsmbconf.so.0.0.1libsmbldap.so.2libsmbldap.so.2.1.0libtevent-util.so.0libtevent-util.so.0.0.1libwbclient.so.0libwbclient.so.0.16libCHARSET3-samba4.solibMESSAGING-SEND-samba4.solibMESSAGING-samba4.solibaddns-samba4.solibads-samba4.solibasn1util-samba4.solibauth-samba4.solibauthkrb5-samba4.solibcli-cldap-samba4.solibcli-ldap-common-samba4.solibcli-ldap-samba4.solibcli-nbt-samba4.solibcli-smb-common-samba4.solibcli-spoolss-samba4.solibcliauth-samba4.solibclidns-samba4.solibcluster-samba4.solibcmdline-contexts-samba4.solibcmdline-samba4.solibcommon-auth-samba4.solibdbwrap-samba4.solibdcerpc-pkt-auth-samba4.solibdcerpc-samba-samba4.solibdcerpc-samba4.solibevents-samba4.solibflag-mapping-samba4.solibgenrand-samba4.solibgensec-samba4.solibgpo-samba4.solibgse-samba4.solibhttp-samba4.solibinterfaces-samba4.solibiov-buf-samba4.solibkrb5samba-samba4.solibldbsamba-samba4.soliblibcli-lsa3-samba4.soliblibcli-netlogon3-samba4.soliblibsmb-samba4.solibmessages-dgm-samba4.solibmessages-util-samba4.solibmscat-samba4.solibmsghdr-samba4.solibmsrpc3-samba4.solibndr-samba-samba4.solibndr-samba4.solibnet-keytab-samba4.solibnetif-samba4.solibnpa-tstream-samba4.solibprinting-migrate-samba4.solibregistry-samba4.solibreplace-samba4.solibsamba-cluster-support-samba4.solibsamba-debug-samba4.solibsamba-modules-samba4.solibsamba-security-samba4.solibsamba-sockets-samba4.solibsamba3-util-samba4.solibsamdb-common-samba4.solibsecrets3-samba4.solibserver-id-db-samba4.solibserver-role-samba4.solibsmb-transport-samba4.solibsmbclient-raw-samba4.solibsmbd-base-samba4.solibsmbd-shim-samba4.solibsmbldaphelper-samba4.solibsocket-blocking-samba4.solibstable-sort-samba4.solibsys-rw-samba4.solibtalloc-report-printf-samba4.solibtdb-wrap-samba4.solibtime-basic-samba4.solibtrusts-util-samba4.solibutil-reg-samba4.solibutil-setid-samba4.solibutil-tdb-samba4.sopdbldapsam.sosmbpasswd.sotdbsam.so/usr/lib64//usr/lib64/samba//usr/lib64/samba/pdb/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:39674/SUSE_SLE-15-SP6_Update/aeeab13b449b36a000127e6292fbe0fc-samba.SUSE_SLE-15-SP6_Updatedrpmxz5aarch64-suse-linux  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=79a2f77efb91232282beb96609e2aa7386770070, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=cbdd8dbd4642e2a2774232e6c134f437abac283b, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=17fe20d9ba081ee322e7117b587e82eefe07e4cf, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=64ffeb61c06aef66a7aecca478b089f8d2456e47, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=d84dac2e75395f459f6c84220a5cb748a17a2e5f, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=5ad40666b787f91f5ac143705822cfea9cbbf25d, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=3d501d9ca5c3dfb368a7523cdb39d96a866f15af, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=d68fb1924087b4f69afba23a4369d5e2f6a0732d, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=d2abf812f1a8a57ed89b17e8fbe836e60fcdf758, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=a57fc08e51d9a09bd100cbbeba911d603e6ff068, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=f66a1e384b9063a92550ea0ffb6076318ec03ac3, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=967f60b8c0786b13a45cf38ffb236d614537c82b, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=214e62e4ff61fb20b7ebc1354b8db96db424285a, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=008a285d59a94dbcf7ed9da6267f7973e519f9c3, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=58950973003ce39c8567c40c46c868a2d05f8935, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=4579c928f0815e8413cd5f94e9284c46b5fb54a0, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=3163db7755fd770b8a376065121f8c53b840601a, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=0d0d767e79df1c231b1700a76b63f9cbf860f8f7, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=8e659a27e2e445d11d4270e6f975bb738ff2acc4, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=c31d52f0a5a3855b9e34a6688fa21c54364eb729, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=7df07b4805ec891824a48aca915eb9e7272ed430, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=40a44e5e3df6e0eedef5a38aa54400c1c5509200, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=72984860da4a850263b1c3501fafb99eac257f38, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=971a2333726cf39d2e08ad477a1e497775cedbf2, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=1719a536688576da929999a2dd214081ef010fbe, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=096e4e388871af3855cf241db4713c9b85908d6b, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=95f7a2b089fee31bb2a1e769797492f81e2f5ddd, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=918af106984bb3007cb6e3b9a7c37b625d39b020, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=0bc5ab08c830463f5f6c3d78a214caadc2dd0b7a, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=ff5a0e1fdb3b5ba154c0334ee4e123944c7b74f4, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=8df6c1fbb0cb0db5b322b4377162bad85eebbdb5, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=1d291efa9c631c26eb5f3da370e702ace5c1574e, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=86b9fce725b3f35288f883378a246caaac8f66dc, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=bfdf0d23401b249ece094a443c6284ad920c63f0, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=b524364e501debb85bddc486f5481b31624dbd00, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=98c721efab89243fbd50d4a1ddd409342c442db5, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=f78d6c347b97cdb5478b63e05ad97d84fe7eecd2, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=db3ed61464d882c6c6ad3ea36e3bd7174a21f329, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=1e65afbafbd8b4c64fa0a96c00b34040a91fe5c8, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=4c437b830c53b6a2a3d58504b7c1b121d74dd389, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=f66a3623c3f8064e1756f1b7ec1e4b4888cc4d0e, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=feff62cf179513381788b360c078265d88fb8c5e, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=91cda5046b5a729446c5f6a3f46c594c890707d7, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=57d2eac506bb302bc973d2c461c6d27862e5a8b0, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=af8b912684a0e149c825725336ce5ea4263b7dc7, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=1ab5e6415389e1c8f85951a52dfea2a1cd182591, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=5b37be67a7526a7f872c00a59ee91686b8bb0a7c, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=13b2719b566b001c5706c72a189110a0aa2b1348, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=1568851cbad0bd733d982e366175a97256e87632, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=13078c669b3379198cf9ce15b2a65bc33895b259, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=98d057da28c3ef2ce4ffcb3b6b2f87f36c019ecd, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=9d1ebd0cd93034a1bca7070d31b0686b3966c22d, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=b8dc0609bf9edd7bc3002962167039e2b92760e5, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=5754d5680f9148dbc26ac290e4936a3259255bd2, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=bff550cce84cbef4cad2035631da7aee18b1b4d3, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=70d1c9da5dda9297e323311de8e86a0254f4f21d, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=c933679e6e04d3291b85ace9fdd0592ef3acb2c9, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=fcf274f9172213a4eaefdbffe9641b06f1857897, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=667ff799228e8398cfbac2304d08d0f73261a024, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=2ea4044a66e28af915f621e0acaaa9864c7d045d, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=898614d35f1814ae89703ce22e07814de60ccc3b, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=06f9903675ab9abd64650fb8b8352f5844d8c01d, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=865737cf33662d6d557d2cf2ca4eaaf50caeec55, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=e4ee15853ed6d25fffd0ef1accb64f9421473b88, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=2a5dc6e9986f4d58e54073945a28cf8739e3e57a, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=2c2e960ce8cabb3d4e28321bbc57418c3acf7e76, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=80c7d110408a5fe31bc3b014ce8ff58fe140e799, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=5e0402456fe2dedfe5b7ca2429e8cd5dec3baf26, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=80f85d75a2789365b74de3d93c4fc6f4645f9927, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=ccb71c2e30e10be404d30a17d974aebfb1cd1563, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=836bed57cb3bb526239e33f9f8e772d3cae14d8f, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=5317e651e469d25079c96b14be422a64f065f902, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=b6db84bdaf64e14521c4bcd687910109818ab422, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=a6f842805d948469987debf0587b8b09b4c20ebf, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=80758556fcc4acbeba85de3932c5cb38d7efd516, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=d6e6185a38ce960d9a3c156dbeee4e9cdf68c2bc, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=709aa766c380557d5d62780258f9cd02cd89cde8, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=3993d225134f898413d0917d30d610d79e11e577, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=875b8fecb6cb45747cb1d67237f117c1676f21d0, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=4cb86515ab17ebe9b69161b2b6dbb6adb3665c90, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=7cd2995026e11dcea4096e79d22a7032349dd5b8, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=163f5a65dae2cada8a8839feacf60c46630d60b5, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=d235d73f0ce135f179a81708c2142f3542915411, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=3394e8ac5fd45c4e82111efe179b393b44350cc3, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=dac1c98265294102233e1797376b8a6228625ac2, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=2802464f8f827645a666259392230094601637dd, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=0cc25221016a2e33d6eef08ab2440d63ecab70d5, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=f0a5334c7d482c7a3349c0e6c05ae8ff42323643, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=941f1164e10f0c867f0ca1857a3c705244bb9e6f, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=8bd7c58873a53cf8808f877f7137d8b43b976681, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=22933986b97a4827d59b14343a315f714173e063, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=208dd60d6a852f1b8071630caeb1c3ad86aed031, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=aded02fbd0a05864a2af6d547df43c7afbeee6e9, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=6768868cd261588a3af750a5da77a130d505ff7c, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=933a746252232c09ee658447dc6857507fe359aa, strippeddirectoryELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=07e824d1967f6fee537554baf8397ff80c8fc17f, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=59690bda0078dcdc4f4353e76f9fa4cc47abd7d6, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=8fe6d25715d0cc816a083933c48b02fbb267bc09, stripped"K M}:(6Jt+U{ -Rky (c>Rt2Np   1 @ X v  >  ( 2 6 @ d ~")B7D0G!3L]*?I*&3+!%  ;(< .";G""'3*/   $P+P*RRARRRRRRRRRRRRRRRRRRRRRRRRRR@RRRRP4P3RR9RRRRRRRRRRRRRCR7RRR{RARRRR8R6RRRRBRRR@RRzRRRRRP6P5RRRR9RRR{RR$RRRNRRRR,R RRR;RRRRRRAR(RyRRRRRRCR7RR8R6RRRzRR'RRRR+RRxRRMRBR:RRRR~RR@R#RRRRP_P^RRRRRRRRRRRRRRRR~RRRRRRRRRPbPaRRRRRRRRRRRRRRRRPiPhRRRRRRRyRRRRRRRRRRRxRRRRPlPmPmPnPnPoPoPpPpPqPqPrPrPsPsPtPtPuPuPvPvPwPwPxPxPyPyPzPzP{P{P|P|P}P}P~P~PPkRARRRRRRRRRRRR@RRRPPRRRmR}R?RARRkRERGRRR,RRRJRiRRRRRRR(RR;RRRRRRuRRRRRjRRRRRRtRR:RRRR+RhRR>RRlRRRIR~R|R@RR'RRDRRPPRRARRERRRR5RgRRRRRRRRLR\RR,RXRRVRRRfR4RRRRWRRRRR+RR@RUR1RRKRDR[RRPPRRRRRRPPRRRRRRRRRRRERARRRRRRR@RRRDRRPPPPPPPPPPPPPPPPPRR}RRR,RRRARRRRRRR5R{RRRRRRRRRRRRRRRRRR+RRRR4RRR|RRRRzR@RRRRRRRRPPRRRRRRRRRRRRRARERRRRRR@RRRRRRDRRRRRPPRRARRXRLR0R,RRRRRRRR\RRRRR5RVR"RRRgRRRfRRRWRRRRRR!R+R4RR@R/RURRKR[RRRPPPPPPPPPPPPPPPPPPPPPPPPPRRuRRR;RARRRRRRRRJRRRiRRR(RRRmRRRRRRlRhRRtRRRRRIR'R:RRRR~RRR@RRRRRPPRRRRRRRRRRRRRRRRRRoRRRRRRRRRRRRRRRRRRRRRRqRPRRARRR5RRRRRRRRRRRRpRRR4RRRRRRRQRRnRORRRRRRRRRRR@RRRZRRRRYRRRPPPPPPPRRRRRRRRRRRARRR@RRRRRZRYRRRRPPRRRRRRRRRRRRRRPPPPPPPPPPPPPPPRRRRRRRPPRRARRRRRRR@RRRPPRRRARRRRqRRoRnRpRR@RRRRRPPR}RRqRRRRoR7RRRRRRRRRRRRARRRpRR|RRRRR6RRRR@RRnRRRRPPRARRLRRRRRRRR.RRRRRRRR-RRR@RRRRRKRRP PR RRRR}RRRR RRXRRRVRJRyRRRRmRAR"RRRRRRRCRRRRlRxRRRRRWR RRRR!RRIRBRR~R|RRR@RRZRUR1RRYRRP P RRARRRRRRRR@RRRRP P RRRRJRRRRRR3R RRRRRR,RkRRRiRRCRRwRRRRRRARRRRRRRRjRR2R+RhRRRRRRRRRRRBRRRRRRIRRR@RRvRRRRRRPPRRTRRRXRRRwRRRR3RRRLRRARVRERRR2RRWRRRRvRRR@RURSR1RRRKRDRRPPRR\RRRRRRRRRRRRRyRRRRR"RRxRRRRRRRR!RR[RRRRPPRRRR\RRRRRRRRRRRRRRRRR[RRPPRRR\RyRRRRR RRRR"RRRCRRR&RRRRRRRRRR RR%RRBRR!RRRRRxRRRRRRR[RRPPRRRRRRRRyRRRRRRRRxRRRRRRRRPPRRRRRRRRRRRRFRERRCRRRRRRRARRRRRRRBRRQRRRR@RRRRRDRRPPRRCRRRRRRRRR;RRRRRRRBR:RRRRRRRRR~RRRPPRRRRRRR5RRRERRRRR{RRARRRRR4RRzRRRRRR@RRRDRRPPRyRARRRRRRRRRRRRRxRRRR@RRRRP!P RR5RRRRRRR4RRRP#P"RRRRRRP%P$RRRRRRRRRRRRARRRRRRR@RRRRP'P&RRRRR{RRRRRRRRRRRRzRRRRRRRP)P(RRRRARRRRRRRRRRRRRRRRRRRR@RRRRRRP.P-RRRRRCR7RRBR6RRRRRP0P/RRRRRRR{RR7RRRR6R~RzRRRRRP2P1RRR}RRRRRR7R|RR6RRRRRP9P8RRRRRRP;P:RRRRP=PRRRR3RRRRXRRRLRRRRRRERRAR,R{RRRRRRRRRRRRRRRzRRRRRRR+RR2RWRRR@R1RRRKRDRRRPAP@RRRRRRRRRRmRRRRRRRJRRRRRRRRRRRRRRlRRIRRRRRPCPBRRRyRRRR RRRRRRRRRRCRLRRXRRR&RARR RRRVRRxRRRWR RRRRBRRRRRRRRRR@R%RZRUR1RRRKRRPEPDRRRRRRRRRRRR.RRRRCRBR-RRRRRRRRRRRPGPFRRRRRRRRRRRPIPHRRRRPKPJRRRRRRRTRARVRLRRR@RRRKRURSR1RRPMPLRRyRRRRRRRRRRRRR{RRaR`RcReR]RbR\RARRRRRRRRzRRRR@RRRxRRR[RRPOPNRRRRRRRRR;RR:RRRRRRRPQPPRRRRRRRRR,RRAR(RuRRRRRRtRR+RRRRR~RR@R'RRRPSPRRXRRRERARRRJRRRRR,RRRRR}RRRRRRCRR(RRRRRRRRIRWRR'RRRBRR+RRRRRRR@RR|R1RRRDRRPUPTRARRRRRRRRRRRRsRRRRRRR@RrRRRRQRRRRRPWPVRRRRPYPXRRRRRRRERRRRRRDRRP[PZRRRRQRP]P\RRRRRRARRRRJRRRRR5RRRR,RRRmRRRRRR{R(R;R7RRCR3RRRRR6RlR4RRRIRzRRRR+RRRR~RBR:RRRR'RRR@RRR2RRRRPePdRRRRRwRRRRRyRRRRRRRRR~RxRvRRRRRPgPfRRRRRRwRR{RRRyRRRRRRRRRRR~RRxRvRRzRRRRRPPRJRRRRRRRRXRVRARWRRRIRR@RRRUR1RRPPRRRPRRRRRRRORRRRRRRPPRRRRR{RRRRRRRRARRRzRRRRRRR@RRRRPPRRRR{RRR*RR;RRRRRRRR)RR:RzRRRRRRRRR~RRRPPR=RRRgRRARRRRRRR;RRR\RRRRRfRRRRzRR!RRRRRRRRR@RRR[RRRPPRRRXRRRRRR}RRRRRVR5RRRRRARR4RRRWRR|RRRRRRR@RRRUR1RRPPRRRRRRRRRRRRRRPPRRRRPPRRRRRRRRRRRRRQRRRRPPR,RRRRRERRRRRRRRRRRRyRCRRAR(RRRRRxRRRRR'RRRBRRR+RR@RRDRRRPPRXR3RRiRRRmRRARRoRqRRRRRuR}RRRRRJRRHRERRRCRRRRRRRRRRRRRRRRR5RRRRR RRR;RRRRRRRR{R,RRRRRR(RR*RRpR)RlRR4RRRzRWRRnRRRRRRRRRQRtRRRRRBR:RRIR'R+RRR~R@RRRRR|RRR2RhRR R1RRRDRRRRPPRRPPRRRRRRRRRRRRRRRRRRRRRRZRRPPRRPPRRRRPPRRRRRQRRPPRRRRRRRPPRRRRRRRRRRRRPPRRRRPPRRRRRRRRRRRuR7RRARRtRRRRR6RRRR@RRRPPRRRRRRRRPPRRPPRRRRRRRRR,RRRRRRRRRRRRRRARRRRRRR+RRRRRRR@RRRRZRYRRRRRARRRRRRRRRRRRRRRR@RRRRRRRRRRRRRRRRRRR5RRRRARR4RRRRRRR@RRRRRR2.:npGpVutf-8c2de902b7ca42b490f5c52bdaf8d6bfc391e980c1f0f52ca8d5eb06a580fffdd?7zXZ !t/]"k%~2_e#Ȅj((KytG1 @6InIv}%莛5>M^@|+KaNi/W۳|hLec{_ܾ/W3xҖ :c#8e('ѫ1o~/.So<=wpB:nD.|؈fW՜F+λsgYZ}j-2E~5R-feF:> ~ړvUr0(7W\$ݮnlo6`h!Y3A muZW]逭QXDBB8bФ={/\ͰWr FHst7=!J*ԏUt61\JU 5r&˜JOvC޲c9e3ؒT1L 8䮜D`e Ddi X@^yD,l8OP&pbyăAVW%Q%ֳp}b3bEh%@&{c]= #-$ìM$34 yX%pN=\-k nUϜ THG?rɻFS|CN$'M ^Z2TCPu#Gf7KۿG:6R5Nwx<7KJkRUx FaqMig qi^Rf=dyP 'q + Oz;rn> 4g09C~_BG@De1 $ eEf*8^gr4Tw>D dk) S7+&b^P;Ja㥊d*I4$ʦ2cz2B-/eHZP\Jб2DA4s#Èڮ1n낀5W p)̛+$ˉ~;<-~WNK4v72K;w״6nU8r4ԕkFs8|"`W[;k,c@KIXࣛ\UsEカ\$5P?/jC.,?ă*̚0N+B/kS̻xb67z^Aȝxf01"KGb6ZKVƹb4hzyB8 HQ^pFG{#ŀTUǼ4hS֭fw/e_xRvPhYcmMւ"=^Ӗ9h V䠮5R>]Pl~7bZ~ Y kAHA3ix=gu?dJ bnk]7 ,.jsT?vacb6;mJ\@i'~8_J:MdB*}jq4sY 4*R_qcBN"S4snlSN +"=~l74,ȣÖn`9^.L^8<* Q̖1;Oļ 38#v۩{lNxJt ~7EwH{T$a.V肅/e,VLF2P|c-60NFVs(#vyy1<`$ ,fȞxԳ_?7Um2I"i(ے)C(dKo3F.DkV RQ&& Ǻ"tn w64( 9 Јq=m B ɨH7nošVOֹy$W/TiFDL 81erח3=In,HdsnMh@5]7Kyܺg TbĐnV[-laKGE2l 񪪴]ƯDmhLo̭`y(`_h^^ORᷞgBu ~2hfa\(<|^V0O ]R3 54q%AwLT8HĞ~Ib pVq=R\Ԗ%(s&vP"Ƀᤢ 9΃ӌ7]qp݉w\1[5M'T3r"%xhV(A-{ _i<<Ԅy//pK-8aۯ#KC{?e)Jt`7-U%S,H>RЬ  FC>n5L*VI,c?-g:68ht= (zT/SPW燡Y:z~f7i5W42o=Gp"ـ Egj[X졙 |bh&iM)6J!MtzF땦<*Zӆ:h_1t4ҧ"b@ AϫްowZuExɏyAtc9?\S+KL ďz'!.@FmH";oKQ;Y%=jYyX6x%-5D&z2AQY c?[p$lhT?zR'jK5t藧g855Cv|y=] e2M&yp,vSN-E;)5?"S="wKRѕrui ٽAӀWkZg:gxֹMz$ɨFn@HɼTߛėN' ^i`m(GYN#b:8K"@0`r*n!IK,]1;B~ Ep:B$]ŭ_ZX7J7y2;WCJnEؙ$"{ql>C ģs3E}収P^}Q__Ӓdegz݈:i'^c1 š[S?T^Dqt!%ȪGeqQ>n, %Q;H>S MvFaF"Af OzGB8厩o"Nr!L$=?VdcÆ3 Bؙ+ңh!M>p J3IMT鞿m =y?1 BIq %R?B 8d3{ƶ( "Zθٙut V3C,;-䕅rB3\]U6͎@fiPL0Oi_'lt& ;,d2̴mݦj.>-J>Zj NKԲ{(m8kH$R{;8s09N!beJ˙x 5i-?\ca T _\3Lof}&T>6˸DdYsN~_._jNY|&ٗxkcHoF|NAC5=Leל#S8x.=wHE6^TsRњIn վPo\eR/umDne'Ѝ|5GLײPeѱ/ck PрrrZ} շz%OÀBJ8z $]Hp;:GE:P,Gc"kځ2n>N'|s񷙺LneCdQ#JmA2&|#B3ɇ}e&8pO7҆ ~g  1bm"E- bq'z|l A"0^hkByaP(Lrvu[!!paϪ5MBIy9 -^+ u3)t3B(`l퓓qsXÈ[NۋYA<]԰w&/pcz74sd,@?V\9Pz/[/T_;F¿j)wǷzbHy, m+MY]BᎦ2w8Y 0jҤ]@$H ږqO1 `pyҿ[ f[9 7C6PZMDI4pW_kR3OrV(^QlPTu;0bj>iqlg=A;E: RiqZNbpȑWn+\@5Ϩw =&jMo}fP׺MQn' 0z/ô,T?yA3=#I G. P{  2#a؄? # P*Fc8XR̆3n#A^_%٬1^=gI!"py0>Zȁim=;GOƟD6\>-S-f tmhIQlKD4;/TX'Zs.HUwG9` bW ;< ~}/H2FxY1m{2W, u[rW:J۵+UQ&cN<… (p%3E峆Ɋ"G srۛR\lJm{7 ﱲbMlEJtah~} ,n`__ݧ9rJv.!׀`65ܖWNuڷmfпq+0Q>V`av90tQ /6D*!KT+(!̂Ic PǭFxBW>J# @sAƱuY?<Rb'A% x5+Hqq`^ *v@ʝg')XǼ`'q}'H_)`<{Ԝޮ=e6q5䩇5P̥b2Β }0}Gy4DjR&>ZC'(aţ+WO5ҝD0;L=S"!V+g7O i%/}WI{ǛxHsk!x=Po^H(çf@ʯmk7 ,P^1; 6HzL/ˍ&.o5op!Kbr9.R듃}?z0Bҫy@ԖŰj1Ł ێ";^'nuTbZwJͭ%U߻t:Xȣ+Y>v|Eͽw, E~-auG!M\FM[v|:ĕ 3A2D]O:Il`1=:t9$#8HO$_L$ϧ9X0 r74eehٲbܰ8XM޶#rϭt9ΤG%JJw^I1qEAl9/>\[!=> 뀗~W g/!Hμڂt8w }uD@Va {V?)^P7FȲ~W.ϮB&R[5c(PjFj)~Sy~0lٺ6-o+e|Fq^k%ucth 藟wncxh<1rUuF&~,`+x^QoRA}d+mz7υ^{܈m 9kk2x:;T VH5rXs=u Zّm58cb@C5 3|jճTA딽Ӟ~_l@C?N>yHaEHA 3TESm.KnƝ/lC?nߎk i/0 X#H4 8{#rX02 w@Sn b >؄֘Ԉxmo+HZ)el7IQ\ǥ.<1Ka>k{+tpHmb !ޕ$wtHJ^3ݻa"/}6kt8LL=Co\p:x]IPi{X3CSs䥔7HѐPAo<a6%H /|R~d ގ?vRcX'U"9 R |ZS&}$ݫELYחZ S2|mJSsYT_c6qGfXsLl9]BEcW|J]oJ+Ιo{yw2{Uo".L \8bShg~M _eRl)gjWeN|1!)XZ LUДO1 R/L3E E}[m;Gqk^@nB]V'jV,~~϶Fc{}@I&hῥ&޳bCE5?j+sv)QP'Q듭@˙wZK\yQbEC7 z$+Kz0&cJ뺫.0.fӸ\2)oR~NNQ秭߸Y jip7I\y^Rﮧw!c /gtr *M64Цy|.ͅ[T '~ajbP4{ȌZT"Cb[_'Y[a@O,Ơtq2 w&Z|-㷑m3_EFu( 2G#`yzdz]J3&* $7ԿG%H053K +cxb8;MؖK9҅ m5m xt*mKڬ৪:f5Cg5ߨfb*]R3EdIfgN:KBtae-GUKxײ>n@N 8R;2 7(!x⁍5W\9{SrMT]˥ȅyQ4N v_1hjqp;i].\t3#a%JGΙ>̻.rE"0UYO)9NF&U8(;Qrl koCsCr=Fڰ :7WB~ _~S&_DwY# <ȑ }jHrHQ?[!138\yu‹IH &?S H_N"+LĶЪT = aU{t 6q>'*MV mSL i`Y[;CiA[f?TQ棨ϸ~5tBL֐WmvL~*N6iYcU *; וb\ 糗Ol;Cw-:hz{qvT8M=f)7^9AhWE c1\j2@j]X]Nd\#s a/}ߦcHUQ{mfp"m/ꏸ\LHseʬ"vp_Z@Հx# 8}~R@46u0 *>dt@y[ v^ _{FU? kZxw '[=ۨ?HV)Ӓ݀6:OQhX~vXzI}s햁S>gMQ'r8+"z1LgIdjBbY[ABFO Cˎ&NHaI0TN^wkf5z^̳>^WnDŽG+nո ǯIXo1t@;Q'͇T녽xe-jR(ڈb߀ ܓi&brv5S֗R&y֦1?AN>Cl]"vΗj6'vcؔ/L/u o69]0 eDk4C_Q snj7̾u߯K 5pdm)Yor*{@kTDঙ`/OݚnoŀNEeY-cC˜(AlTȅٜbh1;`H?F&>dQĈo}߮Me:sVޙò_a|(fb,Jw)A "욅)'R'@ R C׺d{k{W[&ohoS.G]cfmLba$;9wgؐYy7%;f#܂T;{t OwOYIW29CuggʹJ|S_:1#Uaw{yvY|me_RR{IvV==M(+c.Ab֞|qcҢ}U{hX,PH $)c)\0&FDWp_<ɦy5@&EA"3ޭ4? !W$aɱ%>HQ+Ot0'݂o.tgl)52=? eg;PK+G \Xlɣnug9c5qiIlm[&lЕqƫXF1i^)O߹cBLĒ :G5₻(,y"D7`>$]6^Tߴp)Yj?/=$s$V!G\><ݦHa;/2J'6  q=-F T} 8},X*$Yq2 SmvN-CtT8K Gr J~#ow UaߍzhOojPgwdOkch!w|pj=c l u9 L2;hkJk>WItFdC< E`|fY}@vbQT:.){g.n0l|l3ta<oȸ[lSʮ?=m !3xNJBEr2vG>#*~}mչn Qk>@ܥ׺:O憉8 OXM!.JEhK绊Uymf|K~7bJRb 4}Hս(I Of fvfAc$Gn 8Ҁ\URestug4>D03)^Z6/ R`– =$]]"7/2Mpn1`nRhvc:9b`rcOP7[n[\3Hߜ`W1 iGɌa4/hq_0U0gXM9eG_@&)bFKPB;b PrKj8(M l܇}B#R;-8bV~^jn} PL)TG~IH?DR Kk r,RYql 553wG5' & ep8W0L LNHaQѫh)BJx| @sV`G@ȳ;zn{CD+?_x #J׮2PK3m(-SYM-Fd7<Ƴ~FN; #m.5$Ϲa6D`^m^7b { ٹd睆0CՌ&xw$*mI*^"CHxp]VɩxARѶڿ;݌[)7w5^99T$hvՎ`5ы]p^7+[%[ên[yM) |Mk& E%[4")4嵚 KUDW:p}u"  ~R,&sۍgE$~ˠoEChe(%yf+2H&#g]֚c ͥ!\<%2yrL;t_# ,-JS*"֎*Y~=Bר1(etR?Kv:UFxd?Z%*J u W m, K7a?`#Ti!y,J!1"^TyDݰUHO?;Y@D򨷨J}X%xӡW-K3b{LNֿdD2Uj܁(6J9ᘆ˓\ٛy$pgNxlH<:龤 zD>}͖|u1 7lk˾)6 J(EPOdIƭIXLt?ؽr*i]w+a_&0ϳ1÷-NTJJwkG]E|d $[~4mz1!irLZ= 1{# ` l"ã/1X}75؎[rkij1dBURN-VGo{c &&0PtoۗM{ejE UnǭL>I8{|W04"KtUA jXx>; VJӳq;z2<đq!*guMLYn[/GqD/ ?!2axGAE#solh?s{Zy1܂r ;]O!w,#ee2a9p`j|z1c1EҖ9,'\_ )F&h 9=ETppiYiYhJ+0Y,-h_f p|pUV9x Tκ}ZožC*%dBYte_W8x?=H㿆X3i-j/{NYZX FԠ^"rQ6fUn`j#'(}_;qd2wqUg0FP@J#XŖӇ;a8}A]Bh F{aDs!\#ބa+\,aL:yv0f:":jmR\DƈRpta*5戟, AR規nہ\$<]GeOw!*(pҧ΂d8lI8EJ;˲ ~w!1^So랬PKfݐxza?ЦS=Q׃Cpl #Bi $Y DPY{8.@`Z$Z"s.^JyNʭ3UM7XzJH,pcmql)\=ʹljB#x8VT? #AQ}h(1*k<,{gmlwJǦca3#]pL6 Ͷ ,3ZVDy4j{ r[S;&,.GGb` "ɵ:y@&S ' =:/S9nb!Yh9]RX:aJDQ&Cá %m'Od]%gė7jU X?ŅʧS? &e#<~ 0ΗM@`yhMBӃT$P^ '&Z C/.j4}¶(h+)bUr!_-8jPtM+P<QI _aɴ@ LۜѷKŒ: ┅aOui$Wc]_EI3/e`KV4c <ݔWz3eL:k48^{eZs|zLT>wz8S$t"'XrIîğjjRQrhb]Id ^/A?&uƋq+QޯK% jY*{JdTBepUV&Y1g>J~lvĈ ɞS˼|^ɴڲ9:bgzː}Nc !NϺ72lRƚ`|]+nQa} l2wvEhʱ Q1nu@[A.XDB/0Dnӂ}xX?Жv 'q .z2D)Z۰̓ʨ\G]JxKGu-U` hNd+b<}']m^2kring&"^m+|=䂕I 5LfrnDj-79gupKs4+ :3¤reP *bNl pp`/%_}`esL7Tlȃ"5 eK0d!=c3DPaB]wȥ i*Ӱn \)Õ^"|Ob:C [GNMyذD:Z;6Ă{n$Vw1 6ɸtNw28``/A6 OGp:c?Ka^=S*mC ƱhLmh nos[vXjia#GA8aJ0s$j#b38zcz 􎭣_xG(U)FA~2x. zp:\D"vflkDAp*i_&*N,_U}5nR)/ֶ1qߞkNW.;U2-jt#gTQ!,-l蝣DDɀ =vBz :5"96g: qX,Nrž׬OOfYObwQI)W /` EZӱM OO |6?T]Jl ߒx=â3:Aʒ}FPţ{DxRܖz}GԌ$.r]V@Eɐ=W׽Vn/wdVFN/`Q4_ٱ+yeEB<#]C-B!DFwwPNU,DɁ#[EX[4 ^ X~Aɾ[lNQRiR>dյ 2*˙N2A#dq!8fZ]{Ҿ2n tu@V@5wxR-["뗧x*q7|<Rg {y[%219 1c,8.lg A2s>fUeK22r  YGŃ5ArH `,W 'n2QbMZP@W?m[fjV×fsV2^U_=k? rِwR]!hSo_AbaZP["$Y{dSkdj4͇eL ~bgǪe D{Lxi`Hg_7ŮwsUz^eԄ}Ʃq)u307CxCOc:Sv;˖4F9$#RCLyGp?hӫPe6_mbJ~30mʦALzˀnep5]O-!3<¤cQ?%$@`ba{z{80KMXQ-gBpό|-Ϗ;n+QnlwdN(Wu4%ߴb0W<^I}(tA+rٟ;19-^M{ њ46rך!d&\+QpCZ('x 6oBh,+?|Grl=.Ê7}"˟ZZin|s_W?02<9 \ɒ6.&B"|v]YJ#ߕ̌\$v~6z H;,DXb_d;A Pj@7j b:сEȬ2do:Wm>Ս͹_/WDC- m zhr>'~^Tk.ְ[Aln(Oˇ"+T(]4̗!֐\Rӯ}_jݰ~%cYخ' {8 lHɋFIO\ѝ s)lWһģ8duY1#b͜ bӯw'8ZGu!70Z4ʸ3B5'znxUӺO.6~0[2vKqe^+?Yf}B=N*͂ޗ kaYt7g7L$N68goLS)@/~B%%L. 5|ĺO^lSU`9SE$ 56/X9_u̶S _U+S 3j`jFoTHK.<Nh W bWQ"* =o}0mRB:^C[">3Mxcy^TKReXӎon5;QCasX 2V)"ŭ M3дR $5 eчRsܗK|Hc` N�ס;W+ʐ`ZԹwy2J3tiClN5( ~CV4/ttЖ24 6s=ϼ|R= Y)uOw %a1߳Ŷ_b#K`A㕬"99j!r#d?Z[k_ aaa.2!ׯ^MyՑj>eU$Q2B!QtSC%C W&m\-t8`I^c|^7z\iwj2bdRoE~yw(Y}ːG Pآ+կ)TՓ@b:N~3=29EO ^2nD~H'!&̖ 5մ(%=Xne%ղŸ˴'8ĨiHBaC%,#8a[9k.:vܿ_7~$bRx TBn:VHKxʉgbAukU ZY?6!Q/_b=S*Hq[!.0$KĤK:ʔGI_emwWDA z{FQO=i]X;2EWZEޅd"oB>@N1c[iA PA}:8ųU C ȼ (U~{rS_lgbH tӇ!ak=noz-KGJ;op2]}2r^T,a/כQKh90'mt(*3,)2n+Z4ct-7hnb ]" k8wi%ED}""Ԁš+^~~G!a(VGݮ7L{R{ݱ'PsG `mŕF rPҺ6@ qCx:e K2->(ԡA\ЙeXI9D,@} h>KÄ~\,fT} ױm}'RĻRig)#m ߙ7'ETJ+?U,cYܛQ9!rlԙ0#Fm壶fij!gpW[Lu 1B,C<P{t<Ǚ":a6ቿ(4%ߖO>ƚI,Uq_-ӂf`hq0nR}Uge__w-@寮ȃzfdVf6P@=ai=KDdv7ksMG4٫k ToN bo2m-f j/PF.T 4ŷ92UN9C,)*6/mLNZu""̱/ @F8J/tc%KNLĊ{_Lۂ>VXr鎘 ?ֆH {GE1X?*}1sHmlM,BjrL-E[ PdMLS<(ۿܔ4S%?zgt zct\dqиF|'T0׋w`zP؛>mNTE_LeLOF*TsCjKA9dD:)Fy3s]l2(~+܏\.ѷiDP<ۥY PE5{ 7!ɥO*4+}EN&e)Lmv]h{?Io9C?(՚اϕ}"!.YXM>¶22j[̩دns4[6Lpq*Rrn=4M\EN&[GkYWA&%J00qY輦=! [+*7սkYxnJ_CdFM,A^?ohHIǵ065Ȉ,w2gFaz 2l }~wo}YQg_wkF!3Ϩ^ J߂9zJVQDSD6tg9)N'  ԼƌtqTJءFYFYqvL:AH47[Y, !^@!bM<;@8.1"}*[hTw36 ,p7V"G ww&jA}i dڟR'p#>&֎dN3yatPT0H#zS,NNWG&-=Q!qftuXqe3n=OL[}_O[u>^f<`Y./e0A ch: {ʈ9uؠs*x A/ 6#Dj+.6wV5I|0N IժOzp bpܵ5\3ҶU$ ]E|#٭7J` @gi%_i:]iۡZJ @~!ߩvWvCx/0¤ہҎ&&fva™;Y1s,r_Azԅ/ULOo>my[ȝlo[TXn`>rC$14`>_>C#ݳz!Ny.T脻,KTÖQѬ%Ա,vM GF>Xj_ؼ!V0ۭ u. Bzmk[]YͫMcւr~RD.z+0BpŋNm&,&%?s cAqKf0r-湮q܄A|$5n% .3K;+)({g r'mC/^#`q@uR¦ۭN9>)`Zk=B~ _XA'5H==/#aX),ZYo*c;x*ė_!ߚaL@h[tx<|>OUDD7S[0i@ֱr T ݧ"rfuI`q4/ʼn&tSWMsF/c+vwuqwZY2X0S>UGO= hS|9[j Ok2| {m#v$ôT=Fgsy5C΋[qV҇lGeL22=Пj'/~W'I? vkMAtHc1n1u6]7P[!> )9*$U(UM.)XqWSz:9=JS L֬ߕFjo_k1k ~3K~՟w=(}ۛA~0%,Uvm"7 z4tIo߇ kRM䇇fr)mb|-0iC}Q + cWq`:ȁ?6ó|pyKK>r8oyE)O(}%#͟ $*zs/HM$j(FǺ\q7g&Ϙ 8!]r|vŃ5 ASG2`zIo.d (CY_BB!#[HEɖn Jv E3X? "ݫsz$\(t檰y;|0H }^Oh; s&A`ǥM] 7ۯ*Or!RZ@>DjnkN@'6r'칙;~h!KR 0FZzt^ZZf?8*zӓEg^$ CpfT꜍$) tוU@_n|?fP'cEyhǁ`փSCLwgpmja|?"̚2i2#6KdwmWlY 3ps0c73; f^IC27%Dyݼ-fVh\jLrg47(ҽ=s/\Y-RIUZD܅W [".2: |᳣.K 8MҝkB_ⱥsA8/k,AfqcnrTl`;6BϹaARUlUXG(QEPݻmōo3!ɎRΧ.ժ=YB*.Va+`&әVZcm! \>8w2тB#,5#qV:\($%;B["u] f.h֣3V{]#5 (rlkI]/Aȟ{^u\^M)\9\ihl# RGI:Nb&$Wb;GVEY2d%u !Emr)D+[L|\b<[#̹qhv8b5 *RHN ,\P ^:UUbR q ̽yTv,сanW(=usˡ5y"GeVQVl=C$q:\u\)K^KP.}F0P/ 2 wk_T.aqVnaW&imIة&La:?P= v22X*BciG S飪4xh;ؑWɏ=[ )<ʼT"x紦%}lqqwht|o h@׉(Ê»Ȣ6F*lPoM7X0#5/&p QrA'`%7(A^ݙ3P؊DbN(\2;oMN,r~5V|iT/ok1NHɂqw6 ~;e{]ͳbzOR{U⩘&ߓR! ʢ?9Þ}>>K}&U,ܡ~/f;HYt9vM1] $^u w|,%f N}Uc tUZ?c_:VTB>ל@ Dz\#fCFrz0"8' qmNZ|SS6oMT]B;1 t(q`Bs 슑QfEk4,do;V?\3%P&0/+fӈ$4JV%`Def@(->D3E]g{F;+ܫeHn'l&UoSBx܋`M]X]xۊen/4름ODlIT%3n@v(i![69_ukVr ULHLuLυ`f=^9oEgQ7 y/-wli3ز"g7:Lʓ"މ&T'\R'n~b1pb4FJ.56%ZxɃIG2z%*/;0O\B$vc Zޙ4aЁS@ϔ` Dq4F'އT(O}ĺ3e鬣Cct$'hMii9ȗ9Bli)յ*8oq,P.]iιlB@Du%ۉz,CWJ׏f^RmU$ݝWA^eFW1`^ςc;u{`h50q#(loGfs SΪ1caֺѰh.Da'Fz6&.3|Q*ouHJVLgʞkuV|J(KK K K w VG[6գqJ2U`|xt}tH-tͯHË{&-aSfs/!5v܁GD1նez,Ⓔsy8NW.ȱ(نcr7ϻ'd[,+[*]d0fJrQ j6p+Á?hbP#Mul֖FVG8`'P(gl#py~ gQȫVIj/eC MX%~\Tp:ix\%pi/y jF@%{-Q}6ؕ87J=+% N9$9[2ķz')QvNƶ~:g͸`jEa2Мi;AjxYy|+wnרm|]pAL ցW}䜇^;}n}A#lKD}^Y?[VJO,Q!({ '|Mr'#eRtʆy}l"x JSmHkSS012 VB}E-Lp*x; ػveK%KfMn__K(q)܈I}l>$U`O?%]D Sh%jb̸@fD:DQ/U;m؛gjL)?G_d24?=U^TkTjRC1VizlUpC;:16/0-}ʼ^ð #Wևb=vO?GγIsl;ynV&1z޻c48X{w?|QiX#˴\KL-33֥BwCXBNV0˖=Lj,7TXI}ЧLmzyLc}LR`$:s-vobCRj4!] .yEC2˄lOU2Ӕ TT(d>$ť3'+%IBF{{ Xʔ /j; $7cnDԉ^ VK- ]A~=w my'Yj V ;)sHbDGʂO?binG P4(l3M-yT&2\^odcKNNVoG#Sv3+Dx0m!*-jPScU_ Q!ޒCFA W7ԭ1CdGm[&ct|ޘ/* 4> :\ڸ1Zqv\O@ Ʀ>8jXuAZ7\ӮG!J{Zɘ4geQ; F*, vxkpL{Drg8Q<ϧ1^GS6Ik\wEn c'*6?` Kͷo}5IL6ȺtHدfh5w=n*!"b 8}y+qWfs1%Cd,RTE&N!qa6Vz0f @)LSK4c ;$SI~^Ht<'/6 /;~ Kj[lGˬ/.!|}KG%QM WyEZv<4!! XC(^Z$|!@`i!P-Ng嬒PQ ƻa@`H`.Y-=|ۑN@$JQ] {Xta;QU/u"+P>v4>b;9M`{Bē06| tQQFc!фgvإ~df;JW|pph8j"'/'FNa+UÊx} يia%p*Z'+*@c_+Dӓy6QjS;>JcbCPtԍSPmĥzBpi>Lb!*}}?KlggƏ+Csq:ga."Nݟvʧq(dS/yPs":{# fiSej`cs}#߲ 9:1dUòDr <%JEp蹧ĕ :'V=FEJx㴓ѭπrZ" fRMD} D-呩Tjx*"d褐{7yJn)*?%l[g‘2WkeCUw) 8$ qPԵ+L@Pۯu8qǒ=mۚ?mVAx&ryg39g+.[ K5}n-蛘S>— h,KTK1#A*iXمX^6}dlA[ VQlkG>A7l-:Y^|خU{_KOX5Q=Z^'wYC%4MQg6m?}G^;G֭ǑDG(R,ru*8noNEC~8reܢRF#l͸ͪ(r]v[ݳ"&-]wy"hUz%kK I@^%[+ KOwm~3XN,btSvtwƓ~ D'~l6& 13:i^jeURD&{@-_% & ъD͢>g8%7gvG0SU< N$_A%\x5Bszhi~YO;zHD% X UXyޒԢs%%yvӂ57aKCT#cOd V'+'%%#d^*d S; LmMh ԙb]iDC-UCRaY]Inġdw'_53 ):Ƕ\0Ҟ sf/vHpiSsE6N1H6eU<`o>-]_KTm) зшԋ{U#uB=|~Vzc8#\y!C MeJn>z5 * ; tњ`pAFF͹E ]&Q-LPFw(DcI{' "HnZ$䁿,fVK uJ`N,5K=o"=D 5~C?vC,ceKD!զi0T^jqVd@o-`9q5rloJTX`# p^& FmT+ِ+e) ŷ^ Xͼ¡8+252k-7hxrnQad t*@!#)/@Ȉ鑷3|i-+uT q|*[mN c)hιjoY?6͍tR^*s)d $D6N~xsy~-@YH<]8bBY'L4QiC9Beyz_B%|Ƈ?~O,؏<(12w;vY%ʦ5~咱Uc\@iKI CR> 2P k]nD:VmL D-j}L'# " j/p.o ]{nԐF톙+Li@kPQcK/?,Ώ#ec- NA&,C53,}?k5ȧT~/(5L_UY+}:֦F1[T6oyy  +5=񵘿_pUѢh Bp3Hү_84o1M*0*H1B o ŸL[w¶9 fuQsq~?+vxf{xOqD4/)c(rn_:BH@RQeڵQLSdOpҜbӕ%ro.p޺I zw;"W4f-/HƸqIWmj8Z^`fI+l@5/ *:lg^{;xo@*DJbE :Kyܗ:$nɗ÷j?ۥ ÌAː\.),Y(U7ֺ9Q(=o5gXmsRm™;~7 kB=\:ZFعرDI73s 6iE ?yvZ\.jZ p(~bR-'pK5=WFfߨQ* 0kr/l\3gf,qh`4[M)~ 96nzm+Զ&pJDS;I f7G}7r@|΍dD=hBW9kH\f#)[۩nn~Z\䔛̹kgVg/;&) :bue=,zߓ| au]]N@5Gzy>فV@N3̓Q_~ *̡Qv"m8UJLo L 3h[膲%P*>)eZ)*N`L>HGl(x=].]d^}-酽5בּFa PDh ' Y$ R_&:vf8_[a(yXC涝A3 8؟eݑ.U"pK{Enls5i(rA $(>;.юbCQ;QmSTz$t>iGAҳQl( R̟xvwcGkߕ53Jp]SKt3c.E$א}OaQo|¤XO'Wo 3b,]<~͏8/> mL]5+W@bEC}ӲZ.P z*TMKR;RpcXX4bGpKY kr/o6\#Btb8=bV-Ր9t)F\Qd I:NOO!\46PM)o108E؛ɒe#ypJ\䈅╣ ^'&o(; nTf*K}muB%>E7!pC HX!s;-B$Q&x;׳qN5`?^/<)s(icEYal6r6k-WCpa(Q>EZknNHj[36Mg" Uz)$X-§&+}gJ!x6'[~ :1 _!fN0ݑA*&[Y,u]b z=F>DC:#+ DF6tS3 >ħP)E]>^byzwxt{qz4צ PX{ HXH C-#{S}cVmQ*Cqb_bN[DWtc MŸ- TMTV#%([EK-͔XE(ex\VvDɥU9mcRf!Ó.AҐ`s2ZFD0`l9'z-|.%˘[8mRᗄš {?7SIe%ktX}рC[G=d۬ɾnqFT6͹jE>.9,#8dSyt\6&爋1 B ?V0' [ tQH"_?q{=۩]V(|rt#` _!J/#b*_Jr~ )F+sg|pwP"Xl(45085 .eMzӛO*v $+SElV(n'X<Ԅ@Nkp,7_;}ͬ6՜YçIfSiӠnEK^bҫc~bJ4:#:=!\zb,c/5+|@4nFzxAz4\gf\OAx*'m8J۴ѫ0"#\nS`ȄKv!d6$}_PΟU'ӍcS͍m2!48d0/Ʀ\Oj?#dZbs`/3s| )ۄ}WJ]}t}rXg?䊞0T((h$%> 32kg̴aX|luکZُ؝a6{MeϾ*v*G%׵Տ5iQEAzoa>NK$ऐN" ^;9Sr}䏌,]t`u5p]̮"RU[JOMw~BScTh{ﯻQݩbk7==]_{Igb(Zuf\< vٷ; ]#`-Ix*s/7RF8m=iz9UN &W!YyUYZF Lͧ$?~[n,@s!'^Xz5hg D1呆pҼ0{*j֘@$r=|KãAu9xG+8rFعe@6/.eaVD@_'TkNt=vRP:TӮIcA~ R;սK8|ȂW酩uvCZ%r9^X`}E{6N0!Đēe7dNds^1,c1z(Θ0tx/t(V'HvRH>PGJ 8A498hbi rr!~~NbДSQg|kz_ 5鬈kx. d}x9=Z/Ŗ.m͙V!s`~\ǯ3_ i\Adk0H/Oc~_sdK':ȑ0%xl+C/pD#H|E΋[xGRa`;݊\WS!qomW˦ _LN>4Z6I9S>dX#̗ |s󪯬,KB[= ̿ٳsM~vLU iNiyjZ("BwF%up̋D 'gWEOG۪6MOπyAn#Bc>O >XlFSq_?!f]asA+)o75Gt%M5!IDTq%E!/vD(1Laj3S"&@;hb*QY-@p0-7 F<6`YɈJIcM==&lXL׬r 0wsK 9TKȓ=WH Kuí, I,whǡkH"}?xGk "^ZU >T  9~>( ;n%fi,SKpĦ+[#6,-풿lA-pv;9'+Ų6PSh:." PwU0AnWVB[pH,M54KN83Ӱ856" A U2Q+G%_\)K))A_.#)lVPYW6%X68L*%a7<6'G\|MjʉQ++ʫ'5&dj6K`pb,wwPE:)oE>pUt5(80!5e4Pܷo;Mݪ6*T݄Mh][bC$Sj9DѴ#7x{}Ӹ?n]Qoh宾}XUo ܘ3Nm{?ЙاA;/ Ui]֣fjߓ}ߟ]YSbWѲie-G$V %| *Q C}F02$xp$ ;pөQ'z>O"Q|%F[:ߑX̀RDԬA2VS@1얝73 zIm"hH*NĬ&h2OЕIom0,m`Ț(]alB#X#Y-+`ULB` `Ž~rC5a+\Ƚ y{L% Ţp_ӽ&F6f/j8u-PmfqG )٨֍MB8J| Β//Y]LuLPwLu3tsGTz *v%:E;LvRkJI *1\>(*o`Cpod=:ne͑*bK:G4HGV]X{%)+? 9n x'~]9OppSv'ONV +߁(zwXq2X,ЃlVmDY^$5q6@N낊&Ef1ȠbN{0ubuLqikw\y3`9O-tuGtPK!_Ӆ!;5,}`ٿxiksj^=CjNPEbr Īs%қh]7H }3QZ2`zMO,f-or;:J LB_ղgb!HmnAt'#5}mށuBe1S^}GϚؖ[7cg>}A/޷h \v>6YY9k[$EC9`$]w:5G9 u`uH1Gml1is}c ό,y!qGK CȑK#Fjdοm9&GA,*'TCZͨ\ʌ;IU}eEo,jӋ(/O΄cF1x P-O #n/$&IQs0yf{V]V}MT5{[}Wz"oTG;<Uc@&a|IMݩ2 )4DWӴ8'Gm^ѵAܠ'K <RBPyKO7M5G*:<&nR!wc_ŕǪ܍ /i+g!.eltXؠfͧ@nu[LNgn\clqn!LQ9I؞ԝb7/hK)0Nl& עzrD}[NB,M\wT8Ze݋v<ӊ鑟Wvb^}% J2}켩fsV&raE(X¬~>hmWIѻ>![ۂr9b$u0]?.n-(c6K(W!64Z <T R˜ZfSu34&VԀXIaN:V".̹ulX(窰huٜy@Rm@6[(7KH!(ޑta\Ci=6 3ٹ`Ƙr4'}p9q/Oh ]Ϡ2$iӏΥл[g D%Wa0au +7Yfv0ׅB(X4 fu“ %Bl|]xb:CAwH3'pQ NIB$A_d xzq5j_ ?Kn&x?:h@JS,l%eK+&-r-/`n%<8hZ'!7j(ہ5)r, e@=5)T|͉njTI9.rHfnSBU})Q3r;pޓnv&1Mh|18E_Œ2P+4h 7ǭ!Z5E)t0b3P: 嚧M>/~Ŋv9/%n,^E[Aa):.I-K#EԷ˞5i#)gzAG=U;KHQdDfoj~WYh 쮵#5`.?ۍH*5ֲVap甏bR$ uB}0bk"DBG[\ !Hqhfgl^9#z39Фw&,(d<*!]y ]i*E=/~z:[[{-k.b:vjwfNS6[H|K((Ъj3X/:M=c@oܔ9JmϪOVظO]P-E8QTh1q:ݩ>ݻp?'M~ bȚ뺐@(d=9EyćZcUvO[u(znr10h|F9NxpOY/ f7SϾkJaot2;Nx_3h7DA8[ش7nT\# % AeSBmS>?.mQa┚UyPƀl+^,=ۑ[>#q=Ų\8jK QI Ҩ6-F>ׅ?;^yr-a&jt U!¤S>UBጎzf+g:@s^ 3Epi5ד>5GmYI8(4~uߊ6K*vUGv^=[Dx5wJhc"BDɟʦpLM~oE[Xz[ϤL6$.YzWɞLlj2$&+OJdk* v(U`c9.E5Ɩ6힢GL7.>8T?bo}wufFY˹7ukMٲ.b4jdwnp% Tow–1Yt% 0TOqY^sg1j@.tj@5qg.Mj:rXmdW' (Q@Hsiq 8ǵv%5:cC>M`{q%\K7c#&0e̟\fdh߼bZ(\Tŋu`|\ K+ן,V]2Od}ɢ`9̚]98 C̨͌'`M\>ʻ%:{Azj_°BhpW-ʱ"6>O)\LlgYz,蠡ǣW,FtWsU•N4fpu%NzW#d}UP_o$tKqA` !w81ߨ;ldl\'X7mv0LkJ IޔF bꃩLb9i o9p,'ZXW&`找Enic44^*/kmbNѨyaW{SoKHKWAK߃-wx鸱}׀nQh⻋wBDq,G&X ' ~~rbDr/I7L ]<; cZk-lx|',G-/l R6vu;k*ךcZa)TR $BJc] egvby,_Pv̈́Ej *2`ֱqnVѦ1|;ѧո:OinOy{};|Q4nN`ฏaO>b HX\xr`0,jgJvC@e8%$× ؊9~Ûi3A5F;~5l 9"[IGK͒unMiA^>|"Cj~3-EpB&Z$x)I;"c4ؠ+pDRw ;n$+IXƗ{V7Ge% v(_l_Lgv7aS=IgONIL[e7T #J O,YZrgʏM8oLKqa&Q4u3- 8¤i`KO 3ɽMȟեaD)=~M"8< 1m>JVf3u정&(!w&>cٮnF!m2 ||zP=z%P]5ct}ag0u`ܳ*W~:36l7 0H:{%\|}Yb; ߲y[\J|L+W{U_Y< 4=zd=33\A V<=M䰉VR#zffY 3Ě8u{T2 bVczA L39'.P_",SbexICmtOQ)i3z@Lm1<f1qH RDyw%'k)f1e.Luns.+GOw*&|שV,wUXKﬠ,Y7v)k̲Tq|Utճʹ-v1yP 2:KT,Ȟ:&xm+5mI|&"? t½`Uڄ+M÷ 7a+ڼ6 iOv3d3VX ޣzB/EӰ,5 ?G0ᾞ6\6bZLn[oH dM3qTҳeZTZPhF}e+6<9YvnAkW_ej މ;~ #|u6KLJߘuvU,:"/b}ƣi俼*)IMXeO ;ʡ'4،zV,xN/r3HW^Z7P Qc76kNtr=x vBc L^~&Q(*i)3! [vb*=w~!K|Y{Dʘcl'Õ/U8/a}Yn} #;\Ma07-=9:kZRBv%ܒ}67ÜrG8yNeJo;rv'pFX*񦎲6@UaشA#P3J5-(P PkIПa&>!ֈZS5ǻ ` wdI Qd%Hr߅}TC*r{#8kkH^5v`?z"MR=Iys{wΧ*rX 0HF'0a:agnITWqZQφ+owq 2szcu3hO0<*7tu@CNg zvGdƗb ֩Ih- ҂< A!WtU >V끲Y1$N_o|ej>ޫH_øHL0O:z-U܉g!dy?4>2cۭ֓ICz;|~}*,#`Q-ȶ@ kxjx"o#rnx*Dn޼Ŏ}IQ@go1͑-[ ^MG?%aQ6ԄEY>xN}mP.H#[:wssjʹūTLbC++T:ne鶳*Gž28@]rV(qnefUZDȦey_ J*C;rr@ ȉfna[W\EjS$ С}#htӍsM‡tKh 8 VuvΠh0r r1P=il'XSZ`Cr{Fzs;@dv00yuTt '@=QayZme5OWMŵp`54[Bp@G#[C 0RȚiO|7V,Ԣ?z,JdVС![@j֏a \&u|I>\No#+2iwŤX̥텛&~" d54Is`#\ƣHqLOrѨ^s''q@D7?{Hj Z 2.f|&(Xh&:g+\U;Vyic-,FeY$QjFQ"J?EN†2Jt`$W۱uσ3CSSDCkynfЍQ/6%ǕsdjCCcwc3I?f^cu\cH!e\ȶI`fc_O*?<}~6 `|625 /q%VƉEשWX.֨{2nn|)޸' `?U8j8r7׿ſȅ硝nG+#M-hcG[N-a}Lpt+A| Dv0733]w_vZ%J̦2*㝋^ iM2&f'6M4˴E.>>opm}@l$-hbG l5L.oyAbKO88]Nz㙦-m1I nB't$s!5+ܻIByٯ ûʝ>;*RI3+d t:YX,.:#J7tM: ^Z2WS'` }zJ#<13rYHռ>U F5k!& 1lE358C#iMcZQ ,]^g۲+P˾J`7]6vVf[̟MeK&qkcƈr̸/4dWY85~KΓ@_rf;a[#!xR=ds^Z%E N VeɸJk<͹wVR<ܨ2ec/(Cs>D詋KoP)Rw=wluoF};8TiVg4ZH݋ƆRPoI8TKRSJ ~mIl(.P+)۵b,SE_4BMߜE_lTMa 0p4U!'xDMNDk>U5kVɡZo6 "f+,eeP~RԏL Y$z(]%?K!Jn. ==ƈ!&ܝxyXY>YbEfS9&Kb"[' b*16E~`+^Bx`yΫlwoRThh\nuq"rSMhMQE{+|H[)Քy ;bs]u- ̥/gb#P'+LMt3 QݦW˜i` !6R\j[e;GSNB:.V:͉O6,SBK~Il'i,~V6E;Ś!Xi%#=pt R Gѫ~84bWರ{(F7e %[5-Sr!t}iTmV(o=z'@h:f2 u+rkxJWm p ([KY]e0S 14?Ԟ"TQeȍzFmUgo!S(l{Rŵ2]7%: "lb>e)|j3?[:%ȜU\7yE$r״5s$FjXtjE]c .pJgd/C få^%VS9ѻ{GW[ HPr02CJF݂3aF]- -Ī`8-oSS}9z xJr覤#ApN;+P%{cND;Dʇ+gjbT" 4GV$2xܐ Qj݂|=xG fEێ`?S=sQ^Y!ümDܨ[8)UpKbᾰ/{C/bqQ\ekmLVЌ5%xKH?+좒8{hhMr ?|ʦUo\xQқ7>0?<0Z3OQHY~2#a4ѵ[ &9yЂ>_L?w@W: ]t.. (BF-a]s-sXmoM@KD`-r!ad.&ɼԷ 'rL`8pKQht-*31޹ƶjpxU8>y B[x -lMy# ?TFϒ@r*^72_tHW_`SDa8Q0%I!)$}n@'zCtlqD s~:j6}Y16M[ɯ1|FO\p879FKM]_E` Diq9ɝD)`P1/sF hQ͆ l% ṽmy1ﳇ$:SV|`_LD-y tpY\x'׋͹qNQwKG|Rs9V48+` wL,ñdޮb]F#t_hvm2&lGH|^?+uA+ɷ݌-ɣaU:iO>~t@7K^6ڊh0Vbּahu|E r!lSVo82JŃYZ=y/[9 m00L7"fn!8ȈBһ1HZsr] /Q1 mhz 84"_Ӱ@dR NCe~RuC0|"lM5tHNyK. QH|dƧc|JD}9To_ҽ# #]67}o$thh鹰EތDkܨj9a%w|tFu쀦E#, S+u~*(Э_4 Mħh)N=b1B(# ɔM7HVAfܹ,\fFд>zI9yVUr|bO:˒=2xsM(U}qˍ^>*yoZXn#z=N%Ɍx RJzozD. 46ieOݽʻw=!U`J6goĻDS/rLM G|!]Bsls wMǠ^SH[,~4/{V@U tIt'A0dT1kVC t$eCnR;[Xw3"}EʊXsIFxLM L)0#O w@Ctd/u@X閞t \ zuRJd1z϶T^I Inbg=Y;M#4֡OtO@w 4o.Bw"立>#pN-L^?6t&CWmBš31Gn&yd* ݬ$^KD( 7_v@kfX܀ QX(ٞqIn wB]b霑Cme88{f`7*<"ddvO[ʬ`i =ZAdH ;@nIY0)f[=+hB{0CeXU8 1/Q)/ni@Mvzfy=V@P N;Y 瞌< &Q "XO'#dn8fo&,h\?a]ג\F"Y!pXzdPh!Yk KKpd6U+TKUķaț^`Pf:إ  9q<,+c1[#:6Zs@Gt1HԇB exdNidv9V74J߶|p ǷaWp3fM|ZU< %D"jno<ca4g񵷥F'e: C'O<|&Tk]-f@ۊb'ىܘ(ץۿ} Yrbf@;ys4yX EE}a ~>P*{EqX^ӡ#4Oʲv핌,&0 ydkG7/]D&N9HLaE`a|kO78-1,t[; n(pX]&Uj}ӂ2j[҇WTGE3j~K`C['LlOڙMyE^H] !E* -.oSJ)~iZXINXU}2AhEY ,#!`1妧40'W<#2M@-tE['M}Ķ@eyU"ĹCl`[pTcLEj_Yϑ@s#?rQЏ_s45?UG 8,5f076ZX H`D?+&JIBWC9$1zY~Mjn!AD~זB[jAv͕S;X\?[xG"j:@ G*kIsT u;!Ꞇؾ@k3ZeFw6+PzwRi jC |TߝWsD<^񫛣jVh$X~La*?raB$=q\zgx_%^b7jR^l:ZM4C JDUv4뷣0\*wOrr0v|%fb M S7Y<К}N_H^h mH5 е՟ ?fH:4p=GM@~ ȧ^sgKbE v_F`&׽;:t!{H ) ]B|.AYp!'qM7 gzGoc.?q&>Kgܳ"*+ eʿJD$-)x Sx )8`ΡO|> PO*pz} !| m_ ~  *mԤ܍Nmnd(Q/uSKMjフ^)#۷g U @i41mWщUd^M{$sv]JnA4+38}7rw1uTi'Q?aFZm$JW=7bj\@̦.i@'oRs/AȂ+dXeyU8,0!)FEv"Ё+%Z߮8wHRr œ鬎JU Jg4]8V.v['N;P;jzo]0'CX*Y<4&)*]"*mQ &n<)IG^Fs2{cP<3hAa91mrW' gwa8ˊaꟓZZĿ`多3W3 _h? RQtqXp*9*I#} yue|' Y*/e';oۙWCu'8$m&T`nKq V)]]`lnS :\*\N5Z[ Q~(?y 1V<#w=&Y#T|v(2/:@O+~~mgWݕ҈cؿFKj(D,1qa.AR"X*k/A㰹0rgmBxP~<{UR tw +YWRxqSѶ)Ŏip,g^$o(<]0N/czԡA88B+ dvh9bv:MÁ'dQ0^MSx&dždU.q='=ZO3tK #Zڮ9haOesNȺZlFڐϛ np6];nѝrj~ulvvLDܗhM m;AvݼN)=="G쇞 c0"4%]v2!]`ad k쒵KL`;~ RYWStQ;U \5*>=>V,膈v@aYDkyoVe{@CQ2O#9W(a[#|0Ր-46.Ο1GcXp%H2Z\I\zr|2Kȥ`2`9~GY̷~7/;IT >X7w_8?uJA @ep WWmdgaF [O-Ȼ^/*.qlj] _w4nVies7d[v"ae7ZC,"&kWCKS4q.M(8@Οm:xXlc $%1 kL.`FA 0]D,c=%]9qPv^Ktnv2aY&ƏCLi td{ $;A EG,^{1sl "u/J}>3i*$X;ׯM3,n6r^J#2DNVݑ֖G+O!t- GJ$֡| SgXb&?98%F|$D-凜Oa[qz~)wNxo7Q2~IV;tANљKoۿճ-8,Seg{{@UI C fNԪÀ$9 &q*ְξ O ~fb8R9곑k"8dx8_2w|5J#OB202ɨk(KٴF,8|뮚 ncmr9 \ڕfQiradąJJʼn'ɜI4#I-*~md A~3YF$1DV|2iwN=])ejCˬܛָ_w]~WTn4ŗO#XwqM!^gyC@f,PiҢ@*^G^1nrb,2Ի=KIA[؀:U6 WCGb5Aְ5 }(V*ǘ"q'e㨿gPr@BEc#w4 X~tbjÀp7ei5f.w0Gg\"|J3xgEQP6fݫZd{%@_ Pf@= su|&) 2?vW.c["WmE M͆NY 4AdGnVւܽsR D!\d!w !3j+iR|5zw{`$(S F|N9뙎,il1ձ A o׭ 6$}A B~!1#B@GwS%WQ^:4ԵEpnV!>7w#g";b*@RL&c$ `w#f{jˢ^v|API0L ϧ*YH]{g6JVU?Ra>$$#P4; 9Tn =;xI)џ>VB=!^6Ym{iw-Dܡ%4(_;buΐQM$vF3}<"]hNsHEeճ"zQi VUqUɌ!QY0)|rK^Q'dP=:gZLIOL3 .r?aOJKK8X V]T(;Y?FM\̈́"3*6 lx5"(jP_#dSjutYD4<UUgY=sW]X|hhH<'C@ač ! *铡F3&mq@`x@h*Od P-E*w&4M(6B3GO G[0;"F̫dCyZ1I8  bL q麍֝Tn]# %B)F?*߿yDr}ܳN%ܛoFdNo` I $:_gR̓3!L5T­Z]D!Ym rUOK4ǟY݄9aI 4ӭ*I;g'YpD,ϯƙn-ƗvYLa߾d36 Hi RR #\@/d'ogjż|N#1!X HJOSnj$BVb I!ÿZ ['$Y lXIY%aـNRO_^׆@$(@` .~rsI˗$cAXC>5axPi,-Zi6]H> %%ߪ% QV?8H4@ǸǿaQzHMUH)s$M;_fu+}{Z_+F/xd5:602ƒH@ܤ:H2 `@$uqi($TɭABE[Ocrkɍl TՃU P`{ Hv -ߪ];UѯCjbS0B-k,)4 C: [Mok)62GC] (M|چs+ǒrzP0T%VMSl/F\WUvu؂EK{ع+vl-G4cɴѕ~J!x0`ױF*J㶘fa&{^B J Zǻョ>Z{ Ї.QЁ) 4r-,#0im{ukd1_|WTۮt9YK[ ]\N\[EanUf* rH8lME6"̱yY-[ tofSuecjSNú zM1˃`sX{flBmߩ oKGCύ|=-!SI;,6q>,J u׆ŬoÏ[3-t@!r)JPd\I]cb5l2bs! W ptr<5djwr8\q6bD6㫮r]Uķvx"oݳT;K{6P+֩Cʠyы3)=',04E\Ӫ Mkvt*0&%PM|lufs?Ns.|BE͚̅2BDH7"|Ybs۸8Er]fZZ:ЅF/޶X% uSO:Vrd%ՆELf]D9LGYCZq[rE4{S*DjXHƷ'$$-#3ğ^It r{11nNzwHhHjZ3YJ  {Iaw2r6b)q c*R3]f6:l gV)cNO$jkWo;rdEzݎ\OMp;m ?e f,8`cGz7WTpi$=ꟽ8S sK)Ģ!5nd KeEд OӣjugvKb,d5DV2W &rwﰢ. PoXD"zZc2N, lmu'+gd€%,@$II6]h w΃@CB #:"md򼁰֜xo f~vnȝv7dܧf,Yo$;AT{@B@C`fxW}M6,Ȳ'2\Xֿa{a6'6۩Q(cl` @З#'eB bv"|5u]ҽf&S#ZRݩ6"cc#h=׀L:JcN GasD“aR;dw:wuUp! 1A x\MTt!܉~| L`3Xt5((x7xq(Ibs:0'dg{[n݋ {a},Qn5՝+hNA1DWɍ&n M9b덫cK 1zc:޷u.R1c a}qetcY[1%Dʲ{ P\B,EF 1c " EB"kC 2@P':;&d:4Y5XBB(Ctsl$$ | k4Bv:ܡ!;N7m=~~C`u'1Y$XHv ץYHpf8v $R@"HsdELL *d$lT,`Mv20Su`I)$BpRd@I 0H~Y&2/Hh r$*@8g~&LH P` X,RVF( #DX,R X DHdX2QQEJHVQc)iPQm)KXTUTeBjHQV*1EA ,X** b"Ȋ (E(EJ(h2nV kGl:eI;5"N IIF۫  "LVӅl$;EFibt:;+]\-$dclNOaz`nԀ0xZA>RlS+ dg !_.[\NfS*!Iⴰ #[ zb쵴9[mf@@" D AM+v\°arR`c#fCӑчJuMJhzG(8no*R81J`PN+ rܻ}VV rH8a<)+ٴl5s->1_KؽU׮0t &#9e !ܑ!wn P bT zinYsAhjbtyբj-ę,RJ^bVSoAt#Zֽq[-uA.n1ui-Cn$լDj}W\Q%ZJ bXlD%s.تxh9d-`^(ufW0nB9zwpOmV<4{ښzliQDV:7AJ2R(a]VHJPouh~ʆΧ lǏN+nS3~,TƑ*-ʄ 0\6.Ϯn EcAfrQqZ5~[aLݭk['݃v:0%O%:33b+|xvޜhѨ,AHKyÃTx^v;~С&UsR dzd5̽| 3PeP*Do|@tAHuRCu=`xv"VEE_ww;Sh"4:V[Wsx>y8Akon]TEmDHY'&=7rd_S09K>3Olft׹/p7V-҆ZͰx٢W<4W Ny³.秎is۞n]yWW)}^ѹlB-EDg$nG67Ik]ݎϣw* Y`|(5?majj|\H0 |a|Εru_lv݇_Gp8Nny:{I?Am$moWtd|OdY{+7{>}'{EtcSބ| ׭|\[|篾RܮCcӽڱf0 EYWɐiR?>c'X~+4mkMO DեۉY*b, T1,@b+mRƥOܠT3(iF%qDI EdP#}8bXcSDMsk!F(eq%s)[6V YԹk"´QUq/j ubRcKlM5BƨtLCEtcۦ\Ep AA` G&"!Rwvqw&e:ڀER""VCrTTQbF|_Qrc ҏO')j[UmR'ǯi4c=+e?dņf|GN[=姻|j|gP͵&x۪aԣBLibav]_'#呁ʅX گI?r#=ZkdeA~#kl1 }'sI* >˴HSY&0!rXN4K :ۮҌ}ӵxu s&hnXd 3م?ѯ&‚s@@,X9u>e ߼>ӎ%4嬌}͓m0+ +O~m|N'^=$쎙o KiRsQzAoඹdK;hTc@ KO0dc\-]QidKˤ/AjjH?\s.(_}\2lj$4֘CJ6wk1 |D3 ;!'wϼ퍛)Bg9< aVe[ `yUz q.??0,(?Wjpw/ oݗe{cKItb\ãWW"F ,U8ew2jpfƜgW 4 \c>J[cߛ!ke'BԘ +fJ /D`$LsA3G4(]堠iĄ@VE?UlʭMb*&U%A`b]!ITQ_[Z¨.V.pU~.XQMX6m({=?S!-{O{d/k՞ғ9I2Aýj!2VpiP-ikFBHEV,#3`!M`tv8.<͝oa"kKY( r,‡w)f~En=6J c! vX Ű>b Q/a?)}k{]y4JMdZ@+csHFKhp+}a`?>⎶-hz>r?\D֘XRmRaI̗d݈"K@Z/9.?[|y9ՌD|m*o^Z,Y^8't8EP,vޱoy0kѫ٩CP|q"iʾg oߞ`9xxDj+ܝevI &AHz1y}|fMaMh >ֿA/]|v\{e Tl1F>ZH-L3 qAy .i?^7>юDF@Z2vfҁH'J9X{" #gy[ jnP_nUam+љQU+PUPGpVt8֮*!D &~UxÇLV)Ţ0ձJ1rѶ#YS7tFEU.&3>XbiX{fCc+m4J̺0]\cqO-Hոu[^wO fЬ1*ΖJjc:kUfAPY1kZ,妓v•Kn ֢-yJ9t3Jm0aՑb>Ƶ7n/@Ym "L2b ] fSX!P]?kڋ--@0Y⸒AEQZȠcJBeE@ETXc 3VT,mE+4\ٚ :}롫b͸zDL0F1PS-rGb?nwgwaGRF#NTI2Bg:!v亻M(*+i{roa9;f?UP4˧vϖ6[~n.mĹb|f)E%NT_n3|D[e}i=ts0;cO?eo5y2fWSn >'ө eoQh`?)7gfG͎v=ư}CRآze);{9^B׺.Y3+Q7_yW㺶[ 1ժYdyKl_9/Ѫ}R1ⶵ_G[Zwf"^ v:Ҳ䳮n[gi:Uv'ڿ_{:1ۑ8S>Byb/ӔҖdUկJu=uK4瘥Hẘ7}>~7h~"ۗWgv& ^4~hh`EIRC$Y*H!>P %^R E'dX(װ `DlDty3Hx;d$b z,wһI17ذ=T >1^ր|еR Ο`0l[@=wg¯,t?XMsNq_2i%>ׇ܎Gh#mWޟعZ̷)z8:3LѾJYlw<' <E*H>Ku=W8|M[N{.zỀ(zB6OW{ipp.11!D-˲kSn֐ =sY,@@iŠiDx±RhS[w%}"Q >A 1` 9;+%y}uxKk[fo߇Ű` Q a#s~/X9wp OCM8x9Qs#) gW~M3zy}$|'GGGF[^U影PaJcS߾W omf_⭾%˒g^_\3]d2v<${?c]UΝa֋4~{vhhd̓mOƾ,o=Loweܟ=v}üZ;@:ϕ=MglyB q4Zcf $|kG[Qp[mua®  ~%m6iEhte5 NYV&-W;ֺT.w|߰8fGGJ~ ӀnmQ"3cdj.=(zuyNVQ!9⇮n~ԗ$ ʧ ϱ.ȩBDXЪDTPU"F<(ju>;s^S?LER8~v]Wf9g:=Qe 8TQ_XëRc3@~|X˿!u_XUHңb#Jk [LriO|7.sn{-AO&޷Rp㻣^l{K[ {wMwfTqdTj#DD3e~ 8vdb~m6gkC6<7YMkr7w%Oco =:e+ F9dZ"<lSF:e(Fa\ KW2[Sbj"UiY9@H*^dw`RΙcB?/;?OR$PDORpF ۀ?7nT> D4P"g`> )C=ou'cgW]^v[{UUX~Bq1M=;Ͱul2Yͷqf7@!sއZT] ™Sex}u977f`v)y@ ` ,d ?KI! ~("  12LCH~ђhl S)$}ϾB^znow 4ώ,g\k/frM5O 2 @񜉑~I YBxHgd (D C!Dx @ a?J"Jz7z$DqxľT 8hrjclnyۓn9mkmӘJC%00baq(ʼCF0 tfB%zFesڐVSڈTK4tx;ϰiqЃ\LI+S±5R[C+h5|C0l<2,M.pP%ixuT{3]M~bP9yEo/ky=R+]d^;بDķNc,.LN| M^W<#1g\Lfk;Xg?%'wܬG{Jv[烇;^ыwo&t΃ z];Lr~hk;7]8%Ns~lZ\VÍ`!!fs8.vwi1'[6?|.Y|x< >S{mӖ҄m,Ӈ sM~^u{,cs +vesyӕxt!kX*=5O7{кy8_F{z,XwzFBRjiqNU?Z??g0 Zb‰_~KDXGTşdhu?m7o[I8ϟȵ &H/l$=S2CrHȴX2V53-#">Vlnl=P(w1vGm͝Rh ކ`yvxLJjuePY ~0[zp^<栭2,r3>}D^ Z_Rⶆ0DHc"v̥;UAJjвc|N践 簣.VN W˴_ruu{d! PHE!?lMP0<tzT2HZoׇyd0`%6R#/G[FS_\ UK kKV/F!3K0ò)Dh=<X6ֵBhٷk>)QpJ34;~h~+{gCpS>8oR(`-ꑊ0P~E0!iz.$:NR#@P7ZLI 攛9p(J1Oh9$vjDydEFŭN-Y,S*̭apj)LuCPҸ] ~QY=6{Vig_A $(c ;N݄SbQ/gFwgG1*{۩@,`_m45z껻w EOaθ04h Bc:Э<K )A>ӧ.* Ffŷ n>MJwxW0T~q~].e4NV;aNN=Pv-*n`p4~Ĩur>s60Y ØʆY&:ݹ9ͼ_cWs'F*5Ĕ =$7%0F9eې9V^w2'He)9(\IJ@E| E*1)jF˝]?E{>nV \]oܒ#%+|둧j-sA~ou}/#~S.Lķ_{W2^Ӱ3uիɅ2M 325K7QYdE Ŋjʱ!{p\YڟMl׀0-$Q^!ޢ֭,,>oEN#E()cPBac%g<3i ef  @ZV:8Tq QicKb5K꟡ɧwiAUpDA址#d/i'I"u, E1FI_llrT$TuZ>8ĦȺDyp+b{hJѳ FDN(!#a*/LؤcX\ų6MR4EРpF+N3q01Znєkp;fF<~ʂl\ϵ:f~/`jQuG6'O9<ɯnpj2V P}Uʪ1ܐbv|*m99TH%0NX  }EEQ{_;AvcOw@N ijID,!)^Eȅ:m!9jr\FOF|CK-յQ6/<+t5ݰ4MA axHpJA >S&De~cIgaw}5c\jteKVvrڎ|f\ʰר@ Q)Xh?uZDR`;r&B`WLZ,qGMQ٠0Aoy|]n̾e#_P+}1JVSlqsm~p}Hv@!&lI,In~NjZH7V6Bxŧ28R W D  "1 FJXyy܅DDs  7?ǔ[=+;nZ\,ipؐnkۓGF5B zn^Is@9#3b12R3G=9!82;H=ԠJX<8_,f?mIˤ5[ke(^8ׇEE'  r9g4rmb0*\ e&R؁!ZSkV+u3CseW!郰еf͸\) >hNo\fH+"Ff٪;KhcV!ubMC2 ny+5)`gyQ,gxLG%(R]-M;t<>ROZ-H_T#}'Cx\>%똿c7a5HS9I/KgsֺoG'ю$Ϭmky ,{JhyeǽOE{\F&Hȏ#o`8%;Bk/AHg Zh7;E=%pRҲ9Av|3ۉ 670We: ^.hh?L0o{_{ދԨa e\GH~$S\ya]Ѷ:gP|0 Ua kp:G~+ : ҍkdq -!teQ#)m{C&2si qjѿȑ䖈{ 0;۵cZ&^U٧ǭmaT{gy4v:#O@~dȻ>ds `5y3?sΎWhZʄ0MbN'rye+DGz p^Cb_} w"-YA9udh'xk;P\Wڃ9xݷ] ~3ۙ#Mt(.y^.-$\"1ھ Y$ +DT,Tmg JrūCc5sә}i7k)6c˖efW6NÝۺ/8~+\+F7vK&6#hB'@E:lw2&M͵?h2d݄#yM;ݺ%4^Jò5zzũ35ɝģv%'Q+ݛ4pp]HD֒G'% CwSmD1YR;\=o?Lz$נ+|ޕ_W꿹3m9ܽQ?ָa,jb6v$2`/YWd/ h@ZBYո98zpF:DFޞO|89qjgQS Q̫N=.û=xQnxg׺ w|%KkhiaI{W dlIfI7;[?xCܢhO]R]{\ց]iZL992BsVTKKwh\|7ʹVlOjCrA}Vۺ>V- wDzK/Vf&mvT ~-]`": DD CԶ//holjjU t)m=<8m5jťş2F13JidIqdT4Y)@2V$&ClZߓx+G.uAw=ltY&2w:H*1bn8g=ǃ}lފonaaNaE[l(qfV)`xX?܆s њG`r?F $tCZg3z ĭ,tP/1%Rݼ߂d5 槤Kw]lޗ?+r#4㟫G<&8A3ə#}I;N6I$ H9V(sj.Z[V ts#qޞ> 96v"-7W@v^p6 ^QgKHȤ ]XovtI{^RSHBTLJ$~bZBMeBdu(mP%0?iq=* FX Qo)2BRʆ.ɦ暗c~Ov _Y)ngl.oq ClAے{JIty}u$ Hkd  t ) @ϫhu~ suؑM,Kfe``sݬձ8a_H٘1Rfw`!b5UuG+ŬRKL9 ,/Y $(¤*H1CBGĽj.S8 C!c|-8;mzx_Mx sH@"*ACXHj>v ҕa4dVd5r:zs7>^Sq𝋋A AzHw޿ \Q|Xq! hf0@_Њ "6Ғ挄 %OQ27;8ֿ|pfh.zax|x@soq۽z;2*07m~ѽ=nOG!٤ bVE2U4V (Ȼ (F ue"(EQ"bI`,R d $ Ck޾\yU78X'#_=7gYm-η޹Q]Ip_ss6=],Xl )lXT=NljbTz.2]IXmj ?iE]2tƦ# 0:\LQUSAQQ3f7ЌȻ)|дeaQdA$F*LF mIF1oe س- Cݵu&ѠzY]0hNk'܆DŹuE@rfջ8<^x^'K{)jHRDQյaiU7Qٞ"3g!у2efJ*+[>L|pJ>zm;\aOؤs.4Aqq{1$~L+x8s߈16ak°ꃚ(JE)Rg~ On"XBy,4RAKa)/Z{7YXZ}Drf_lJ*"e*+J4EZZͬ}7ﯱ v}wt \(t|w]yH01d ՠaKb"Kȑa{$I%11LPŎt[$ /2>nus'GY4 @fi6a FCJh= !Lv&g؞I;-h9pq[R@]gqp2I1ou+SsP7/+B I'{tAgF7ˤw'Sct^~ ue?i!L~&5@F=$ks$>!rQb$;1mrXWFSw\Fq&Dyka.V >m^TB5M ) )8A0Gl!}h?88b27ʶ'4<2gm7ab7+-k#yw]\G+e$v^}/]4sڪjzU7̀H  1 Ja"I)%2x]|])~bHQ/Ɓ 6Z|=};۪4>k`RCӭĿ#?& nSM##?F*=zDßlMf;Xfgmh~!'H $RIoɵ}zSڐ`NHOﬞbغ@kZn[ 萬T@E93}O'IoPh z/mm\--SA=@ 0e*U<XxVi@qJ;͞5sPDSyhXHABxL ,+&mϸ^cT7`Mך>{Vek 5bsé,>fÝ"S#Jⳑ!WvyxTMia~U[2DcqW5Gh&;%O.g{)h,i @ܾQUaOj7l*V H?܃I-WN͙LknnEsB{[q1å;Soyf)g0@+qv#?+>(wH#rof@CU]*ߤcFrg2 Oj)-"6~{"E/iPd]PY0JC?WȻ9'%8mE ':2ȂPP(+묡H"Dd?o#+ɷI"1j[R&Mk$#r'xwG{[_eobRDD@BlkOjO%ngvY9vy{VOx"R1uI],.w@woVmji2ޯrLj7UoM: cR+?OHu0BJ эLD)Z qa+g@$O)Z b,^'r1.O|{A{U02w^2?ӎO1c#7YϱUi)d!Bj ) 8i$aL| 8eIXHO!Q`H9aRIԚa@9IDL @IWBi 1CErͰ, @m% Jcmh^]7  2yȼVM dui<l\N;xs߇fWM}Evf~ݿc+^U}6|v]>=S:O44Qql ،cnmط%ԕ|*{-UL.O},F:፡Oz6l}7XSg;ZƓ&  R@<|O*G9٬۩걻 c}G {Oj/O/E"= 3BI:_ɴ$BB@pT$$  $B] z$ '@ $!$M$)!` L!$tBJ%߂h Of-)v zeGJ}xvsBDFT`)b^3õ@ۏi{,k~RRsl(¹IZ$L]nF %XU<(:QZBƷ/ewg7o3f;Lw>lV?́G" ,8"Ӆ5tND?1dk@}//.&j:>4& "p,Hdl_躼d'x-n4q7wh(ќe1 a>k N~F[_Ѵ'"L{2#%{9qۉ;JSYJK(Wl8^Oco&A>7qzx <"U!56Jez_90ы5.EJ՞щFEҀwKP 1یs;) _o⟍ %OPf}$X&diHXLظf8O, PB'Y‰Aph+X>B+"C`PS5dR{ ٤QtÓ1gЇ=]%NrfBhГ3ָbJ@RS00H Ur]?HjŇӘg10(1<pC0MBGDqtQ-sk(!v l~9Nհ̺蓼>Ƽ n5` t 8Ոm6At9 ֹ$xt:)}17_ 3!F2y-!T0D1*&ՖչKδs=:'(B(B)!=ǻ Ș X^{U~=6 4b"*`]-]хTpxoet67^Jşe+qsK~Mjt\^}~Mco_ n#];%'$J\^:ffthU(GGFh_BP dR5700ԇj lPw=Wͨ:G[ḻ>} [u[r;ud:XdNYz daKߒ.ٙvo+z+W^֌w4VޓY33B(pr`NHqݕPRR`OT~mZRY_o8٪@Xzt"eݔAI%G?ǰ8~,*C1QZmFHTh}Sc=PP#I8SriѮi1S@2=:q%ݾdq`7Bpm.:}>l%sx{G`Cp2l1VΖFV(]d7A_[u0 f{xhTU}ь#(#N=epzEoCնAf,Q@%*R"0=6C&LI{hFA4i9"_ON3hFTvD?ܩ$R8~c!e~n >(.+Lcd%3R\#W|*bN3/Qo/H8C(qH ]ׅNxg棉dh D'an}o@ܿI 0!AYb֠EzX^;OJN{ Cl6(#T !Mjab)%M50 EKc0=ZTNc0)bb, уDwr-S na %ɓ_I\k:$) )S0(A`@X@$%HB,dP4îɡ夠2 @CC2>I Y($ WPKx}y&I/a$]C}9BNXJb@eJl-$ȁ5So}( B́52nc@R?b8_N|vk3ir-}!kD4kY4\dLǑJUXƉ|!~' 2ms7 'M긖jYB{8ɘ(b!cOgﻷiP{{HhZs= ?"t DY &?E.#hi6>5_V5mT@y6E{+l#',$DF)lDId$U! ZaXJ/?drB*c׎U!Pqd3ޑ۴XDuaw"6ݷ|'w<@ fK `МT:p|ĪN!ڜ| V@vK%pcL@[l'p~6C{N#o>K}?…+mjTPcKr_`7q%5[6`㒚}M}\QAgZE hq`]>2ur|oCE;1[Āf Ru&QIFAw2Iӻ_9$+he2:@\ JOR"ܶB~٤p<90tb = 1"BIr`0K,ds8N2r?6J4D:Q7egӧEݗɴ:7'AqK݂; Q.=-4<LMMm~MBf̊?}Ao+EQNJH"j+wLx$5S??7cn9 Ƣ$'/s'xy.,]O>lHF0n]ZNzlws 1 !'02P$ȴ`䟘|xIIJ?i^WdḞI6R@_8\oKVt['Ws" 6rwN.f{1qd%uvvO{gֺP F^{y"ߩ@3$Ƕ w[.b]rSX6|}_s9vά'>x6[8öl߽ڭUOwun7ARUrl_S9Ǿiuc S_`նX}{c:ӯ/暤I?Ҩi{_W[Xn!| ~'uppw1 6iayu+p ר&&|,VR?9kcr{" xyC:1|:%:Poͨiپxl@tԯOFDQ.yĂ3d;A\ziiI|H-{'x|.\"̧\#/~"Rׯ 眣+Z}hH$!̔C G[fٖzg~'nz^`09o0"uuXG1/á_ ~yk)M0 *lX rJ|U0|J$4jT%T#vNC5#g(FC U CL.,Y?iLo-c;Q4s!p:1RQN w7r"k@CGJ it>PA"ciYceJ¸ DVa|hTbs%ZS/=[|wՋP Tn^5a rrȾĺT` \O8;02#LKP"^,h ^ ߲^q=kn-M# Yt!3:f/I +aZN  PE*eyKVRƋrV '_xt 0VNS42x*x¡f8tXWXTɂR"%{\F([ыj~ OW@hO,ݽ{~:GeB'q)Օ[QMLMb'W`JQu3kxil3KXԨKj~K}OU=۠P[hg64h>>U_n1wZ)M";s?yiYm380Dւl<]LFX ]l ђr: ~[E ,P21"7 aeMv?LI\\1.->umSmtttZ3,24L#\XE9'8okTNfruqWvR6$ 3X"C.Ʀo V)+ VhQ5 {CZ>6vH̐uM{f0/ -h̭H-bB= +Fɵ@DN-`WE$B86$Ilw^ylEѾgQ!<Y:Ut{țʮ$!0 \@O{f\?ۡ ϻ| Pf3QQK~F\ Fr+ wQ(- koOn3j`S>qE>OŗߢBL+xlw>prN{ cˇSLž97ңx QodLl+cImzZ^ar5x60{ LmIx-=DFۏS_}޶Uީ4}p?-aHh}Kcc'`E {3]p&P >R_Gq&Y%p032m{NSt n> m A'nR@@$ D;BT1I8.b:텦2$ Jx,0\ `$/eLh\c}LG abl]./AZ!t~6""JQH̔(J[oFOœ LQV |fv}ÅŎk: Unп}[btnwPWG -{B=f1mhп{Vx!3߾;_k[ r/aj6ٹOhyW+LuM/ b>}\2bN"(3afbXyT4geLMH6QAw}8ސ@QLf~Ͽkz K? 3,g ^vKu.V#xa6uPĚLL}sn+}IB٢8 |q[y0D:Us:ÆH % _Ā6T*p8BJ*iYU،+QZz5Gm!E`%H@$1*2 q*^l>d@!T.j-U.OgG$nlGwʄ1&98gC1=ZmB߷​4G!l~~7WC@@87Osuma 9[s?<3zE'qe1, 1 *Y CC ha2H!$)/d &BBX@<_B!@I b3 oERR^GUp3][w߳e-|O[ϊzcoi Y6[ս~/?ؖ }e[Ds\D (.;!]uU?޶u+q|k{$ E$@ $ $"AHHHRBP~:B(I$,$HH!!6a$'BBN:V$? @a(d;k"jdD>`g1ɖ'L/16RfN5o>eP]/wVmI?ĉ*@4`j\-)cr?7A5'}7lߥnwL1_,Oc=Q&:x@2Zx97@Y@+n,AngAu4Fj “P Qv4 b!hzgh1a '\..Z6YG74 Ȅc񰠅6 õ0I2>j̃/9waH_#0wia27ا *"W!8 274,<7]W~,P,#:Q!av됺V7!هrCYDen|E+.~ & >o11 GjpS4#sT}ڽ5SK 9͜4PRRܳdYy/.$/ZwH(;_%^+@, OC P[$?Hr!$:@%̄@! h@ br 4!qHwuSۿk$ HE߫xhqtx7oؿ*٧}n%HyZKSOlkr/ {IA | B@r8t5dRtr~|X%5{S d$DE$@$'X@,a!,@Y! ;BB@@m ?Lb!uHvGoI ]{LowT~RqT۾R @ k 0V.[RSŋ}.ѭ3s *>sP d&a nU?iA tzEl⾷n>_"U$jIʾ &&&W?$ŷG%드6{~>Ӌ*s5 L(-"Z&0ї@ 0fJEjU`-Lqggr4T`kZwRU P4 Ĭ|2~((c&Q JQfJ"Ʈڬc},|U~/]W]8oGukvg,S)\ rF@*.]q^*mX&GR=DKQC_:#L@*D@}nT^uݏ1ReEi) Ced:[mPJ|j*"QD?iGWjs4Ua xۮ_'EH  Gذ 'q/U%Yuͮ/sղdVЋ8>Wm-'6P2Î4 nuez<4A$]rd8FQqBQ$wfƽ drBM|;]钐e89<W1}Ӫʯx T*6cR&l8f:orW|MOK}U+*i!TGt4|YfdQիӳ`po E3uxf> &bd}߯ x ,To,k4?>A0E #ߡ(}_.n{&¢ěai)em]p땂K@Hh z:/|۸m DemcK' .%xy'mTSU ݌eo?z^ڂQ2j<*= /j#aS`A Ś+3L14OCFãNt0h# GK.H6#EՏv; ']_[-Q}GI_X2j))*U廬ƙ2[Ĝ?y:~鯭v? +-!q@Dx.⻽%F1oWΫ(m/ FG~q{( +t{ xXEk?+}Ƈ AgUYhZM]t46|x5hh/U9r l(Dz"T4@-*H fťW&h=6X[k%{9xsj9h,!G_ywf@!i@P*>6eUh/O(O]ћzE5zOZO/5M׸!P÷[104+p <Ec2}ABx?)>Nl|' _q AgPD(mOKg5 zaTˠ-@뇐6A~IwlSC 4G;s+a?WG eӠ_lCcBk 1-W^*ӫmKUvQϪ4jMNZسE+k 2QVn &vLP'/Xy7">'4ƽj>d*@@|:~_E>mݣLV!nh%JG>}.-GbFF0'EnMXv D\-upIFC`{ hWv=IΕ?T&!M'?:H0JG GaCaFD݀0L6T i1/*We̒Ht)]`lvu7{#dۢ1:]G7!tÝ;]^~/,E8m&P"֩6Mp8Yo'?}&OśD :`, 8įhvę|Rf n3:S?]*q)HP8 Z<5 F7aE D &dMF VѵXZby:%f&jMoѺ^.CΪ\PsP, q-0mg H& @9ݩ~>6ց:e@iwiX|x-MQˎ N.}'mp5Ϲܛ0󣖞u9rrMkkܡ#u >!@4=Wܰؐ+e?-Ji<_Rqnz+>Gk3!hŲ~6ۇI$7t0-7^Fwfnֲc<J5G姗ul/KZ% 83Y#+e J&;9~4Mx MxTD[Gs†niGkp#4&{veCT y&J|=lK2H2` &?oߵ(+V/ʠшi'NkXuXem¥H|S EI!SV!+92y 2y0o@>wZ4RjRS!Rb0 淼K|fjA;l0XFjMt{<8O~L|>m^!({Y _* c!޴rK|UHDNMIfHw|wǵ\mWElֹ^ȶ9J_'Uu(?|0N5緢L!$@?$B`VH6H@?;BB CI$P> 0Pm, |z R*UnWw/9;.:6 S$N߉~:0T&II,@:D E̐$I۷0dd$B  I?谁&4H̞%h$n{]W98I—=JjȔX KUXs(Kb4 7Hz0A;/9BVˉs3)B!:d{iuro%P&!1bP@@mrD~omq.}B4; w2zW!v4;oA?u~hXY82WVV^gjj=}Gur}MEk[bL\a@Ĥ=܄ Bʵo}'7cR^3,|;r\b&1 8{+!Oܮ),ܦ4'k mS$pF2U@vLkv6'>9VQ5q*]2˸ݶXu13Kq 3[FWG0'USf\S7J1=YCp?pF v$ŭN%@v zm*t+mdNd'O SE bZy8ZKK}KId&-B75w9̈́,&{B!`Jo~ ԜR0% P%}]Lƭc=Gk.T>#{8ל:'F'B(_A+S}dVNIpD8S]ZLhг 2J=_, ! wI-JbG,{Ap{$? GSDi~@DZ,t{$@(̼*IrhOĨII 'd $3#ߤ'V@{!?Zd vcI:K@'d7lI !Є%$-1E65krjbn?yn>gUR(Xwr0H"z{8Zɖu EZDـķIzmvwuƇm{Jq8Se< 1J5#(^xR(̦.77"ڵThR1'Ult}<9tOgQɆ%7 *1z-Qy%?M28kX"2"ZMLxVfiB@LCp6!$HHdw@OW7}ouY;3= 3CBhկ>6ufwHHR i > 2HDװbud$!!Gh@Ē &́tC -'Sm4L.OC3ay aKn5}1m#IkAD:"\ G~*7 '/v/~Wi61XS/[M\m)Ll Z[CAot ȿc3#sE dLVT'xZKDfڒ ڍRA>6TyV% O}uv]7l" KL$$eѨq)"t8-+nVMjX?5Q"8VZ(M0~^Uu1fsd@̓ㄩZH̙"RRo|? :iw`;Bvun楢 C3Zڱe3C UWYCU$g2Rö>O;Dz_= ji <ƃ ` GA$ytCg)ADbf%L.KAϏp,fLP۱'\ܢB(H 'T@T!(BRDiHRӢ3}&̣uv=?_gJE4%Y*F nj@hLP$"%BHm0$02I/BAdVINrA$Ir*IPt '' ^Gk4plC\Oogf\fZ"l@D)LU[oy~0Zjk#šqrC?G}[Wf<24YXyʺCy6CDx{Iדo39;T3UMeBVd?N~BH[AB3ij7-%cD3yzU^^Ltѱn#TVҨȾ*6ln0)LHĠl 4o%XPP22U(9^!/~ fRXAaI <{'P :􁕐AHBQ[Y! =ל^wgmYsi;/p;}U ߿_]Gmv1lpvɇ >_ zI.<;r`a6~жXJeaUЋ -hږ (hB\ބޭBtkp2Mv$Kr d꼂!hJC'~a!|02Kz(D4e|ScbIZbR!HA[!o (#r&[N 1HcB"I?l SrdkWwBrP|}*V&E]"kZcV0C~Qɚ{3>(@Y dКMk};LYQaTT >x-Mfc2Vw[;IWWPE_k%"BHrR H<2ZT u.]cc`owݼs]~[W8RAk@(d$,<?P|Bv/gt@u,X#`I"IH=vRI B-So~]4{pstI fy+=!6hRKII[Y[ 3TM uLQsӂIMMHHX@ #5՞܊nGs]Q~:0N&`mUd8^~<"nD ,?w~Vn!.3&c>GX۟ҩ;"džnZIȢ?/-փI, ڭ/-^Bۓײ/U%ӆ_'% H6(YKyt|峲 vFO^Sd2./f4s/B27ʨ뾖ޅ>7fێa\t T6]=8SLP|#?ZFHxvCS`tl ~H~;=$)2Ə*˫10cvfo9Qm *JHd@?ĐV@?!C@"$@ #$B97 Ҋ5~Ǹs3y۽;uvߖ]E_/ژt<.lJ![@ϙSvw>'tuEqqӀNn3"W}ExHI ?5C?HtI4mE},cS K\{?K cbT6,NO^cN:A]z$+ʲ@l%ľl^4%foNuE_EF5U=p(Q2\׻Y) s\Y Np۷K9Ԩ9ki2!MЬxjR"*d+ ɉ0:R'E31?)bAգ Vn)_ef틴,G-QD@Dqي՜J\=޷aUȉ_>aC|v{Z,zmC>篣+`ֳ{Ou9fi4 9+ %%BwBv$!VH$r?%׆~<|$]V=4mN$i12 $`O@$ԠrI@'f H)>Jе$48tpϞ7pu |վU@ n~Q >v1Mi񁊊fZxEHX|zpfCjnlם>,V @LX:D[SLa8d-](I&N|rC: s1Db PbZfL@@2#`^Kµ4^Of!~Ǣ}ո[1 (J$pyߏ<ܔ j+3Fݝ=u/ZL(2@X'L9Ɓ@ h!⤂:%T)c}~ˉ͇aęʁ*H,TO$m'|K$? !!ф$XH~KMJ(MvCkQb_6[x:ĕIjcQ'Tf)l%k+fFG1ՆF'"s'W*%77h)C4˪$QHwbnkRDq[Ǹn|f:N9} _,~ouSK oD- YY|QmR"GU#Y0AKHu y6$蹚8X֥Z Q̸lb7^Z>_bRk֝ kibg6~iׁ,DN}\Xw,lݲjZ)ǍtW_+G"y.sH|P$aaGQβ6(!?Ł& e FVwI5y$/ L7OGEZ)RpJ`Fd?CAwh#QzǕhljN܏vJ; 49^2-a_wZxBCdd6 @ B<&zq_l_C 4@B`jXe2;[f!wQYErB8c|r[#"C~ O(bGO!H@~ʗ0}ɂlHn8D[~7?d1(ĄmrqG_x)v_ޮM2٭p$> <'m-_GtϻO]>kCutn[ M[Ժ' n%?m'aI%"*S =rjص{&KI 4]$B@}0P 0,E8:. Bc}S",6ZN5SHtS|QsJwm*0خ+S;x;ޭ "@|/lQvc ,;jP}[_Ym}HX aL-}}q}֊QևxУ`?"*@uJDK?50mR)dA?E*OVxAS>*R-T:c]ج/q͢*qI4]ZtI hZ!Y!? $@uH)isBa?OWȦFvY# RDN=YH$#}I]?:Mvm/۫JI^ JHp@CU!a|jfd)'!^G=cWWru9/?E{"e(u6ˎ@..|_aH?G=qHyq /aō+?u޽]|8:|o]TIm! w/ؾ5Q}# k#"ŀvZH^&:z{Ê+pf_j(IL "2 u~{3|}65Y3?eaݬY @?vM F@$/[8TtPyXlph=)QqCAH2sYFWZeqX{Y|jԬjR{xUu@T-dq:6kN>·KnP20D#ܿq~t`@Dhcuٞ_&5q!q)IxH"…v  y'^b-iAq *cHRG W64T[q2&PژмⱂwU60i Η'M(Վ (@s--(ZF3I3b q+qBfM=l$a! ?qdL>fa^ўk@ {Qa֪, $HH~'Cw} >3ذ, "d@.)Hk5{Q$;^>5'\\80B>O~V.8\̑#w|XeBk[s8B8roy=f._* (&3_/w6{^ss Z% 9[i m5]W6_#+GX?s~fPVKL)J R'yOxI\+w~o&h)@EY"]RPL_s W\#$ yǵEwۻ0GuAgȭL-H@2I O&t%BBY!Y,Ducv$ĎYvNSb#.ArKL/*>%()@Sx"}yݻ?r˂ mgn+ZHܔDU<7Ϳ A JmMLݘa;ORQ#9Lyóۏ_;D+nUrÁ?MJ*?ڗ (T?Pd=px (ݢ1~)?a|qyId>BڭEYC:U}ĶBrф` m}PH>u 2@!7l%wB$ҳE^-^mߏ.<A/l/D^zfGL#yoeAX VC+!nc70착s$h,*[}joO2f~867w#ѳ^;4xy31T@i DJ߷ɴVGG6>WvVzUyWzc ?bv.H.|S ΙG;Il/qd>= _+7/U2[WbdH`a)~u7EsҬ[]0`vZ>,TF0A(#z3$qM{Pl`AF}dz^aG_(]6F>گ{ 7[dF!E~JwsSUg"5{WW_VN2o_Ih"w"hbs.0"j;ySx*2! xB{r{kl]Yb p&VD]2<35@}BLY=քJؾWgAeEˆy |.>q_-6)H( >LOSe~5 +bL:'o O*+'p>~+ O}|d T֪ +arؾOLdY2E`) zt'd+'Lyh8Qj(>Ƹ~uחuo{5xK _2~?ɍ fQ nMIHti'/K E'+{Eo/>fdH!k/~(&-BRNpu@h=XNmF ))mYI!K[5:$eNr]!u9!~.) ;.wLET!՛gZ]P ۉ^zZd`#M("%[4- /`lO{T4:.h ek?l-=w5FjD 0| _xm?>ۿא5Xpm2 Ua`¾[_a_~xσE O\7%xح09X7ed;IK=wȷ BF@؏]dd#?+W{η3H0N>9M6-7*m]vf0ꅪi^b]g[>NS%F搳ّ0|t'=i7l=Ih"g^6qqJ (V( $>(T@ If@PkHM$D5{Z[z-ߗMtWk"+8kR5Er|bd< +h}%6$l?[=8Fhc96MdeDbermVX2]X+r1 ce0+^av-Cj^2qDúD $DORJ ~sdLĮ'za ۂ<*Enb]k7LiHL4oup4`9m ^=Mo(p9dS8:! [a[[i_< R{Zȥ~&csǙCURö&8u"XƸ}Ye4jЫ4Ăt#">9+4f۱QJIF|t̮(wjN! k*?%B\)J+yAwcEfV@~B1eF`GqPr|\ւ (.׾ukbo|y(>Xq2\LXbcH>,*υ#yOTrw81C?(VVo{^oY&s>6l_VjZ]%=}kU$V.)<#9{j4Ro.Ըs:l]w8$,,k?٠[2o=Kԗ$@J/2ŭnz.c뻞mb7韛$/1d`ٯQo~Ț/9?.:s=lI) Pc} 7[A#ȅ%ses>A q>ȌR[’֢% ~/Ooj, y $G3^S`mAC%TD%Cn3m V0GA\->,}/soOƿj;h.Nɧ"7m +q^wUO{ff(*Sjrtl̵B|Lr~[ <۳('ۤğ# H531`=rQ%\Z}[iq|Pm`ȋs!Hr'WH}nM9$1\ XdJ!֐6g^ү3džg2|˦]Z.n.nXd>~u?e%hj2<+\S_CY1b݋!ӸJιAk*i.lOka6h 8? $YD”49~!o~Q_`D&/P#J\~[h37\Kx"u79 L3ppoоϲ6tQdDU:[{gG=Vu]i_]/dgS9R'QJ{tpf1 M>qF\b}FwJ'p_lgY=̋_Z|#?яFFugPqEx%^+\E~kHv#nj hR`] fne!qf ]'wӀ22/H=_tWIr,x1[&Z@-΍a-ik`}iڠAOtj!@N 킾_Z﬈Ptx50)֦ <{dͫ9?vq`lfB!=&ŮU3&O^X$)3h;/g•ՖB~clzѬXGR0:kh& _Y8~:c_ɭHEI]Z }l va1;et]]m )$PwB}&S{GgB{ $,H9I]\en,jHJpQ?iD {@` &V*bց#T Xyq,uR2v3#yv{1'wQ]eEYf3w|ֶ[0% /`<'BUE ep1q`< U*hG\%FQPk=(!n7U7yʌcyVL<=f7an?b&C ۤD+U3C×B͖RuzO83ECY5·ipYw̠x=taEgGJr+=KԎobqlLe&&<{,J/jXKJX[=t7-2N6: ܹNV"K-]!p7Ip u ' Y#-i eq\>8DKR!詰-(LSX-)&&Af6XݭeeB2,@! I>uGNё#k*׮ut,pm+3,҉y^D%ă$Iz0 tFvɣ>.xY'S/O*.2IOUO{[y.uc`7)$Dwj[x@ߴE*F{e0'<^ٛ f [~硎 ^w)(/̱[_r0gU?3ѠWk_#Ӓ'nմXoN>wB#7ĜHaud}‰ʔ4 Q#ϭU>,gh*PTrƬ_?Ť(UInBRd&SK+-΀Q ln E +ò7P CmaAO'4"JK¾S=Lb5amco1ة?(CP]kEt,<;\㓢 wskԎj2\3}&i8n7:q}Cvxލ~ue@`'ά!} QmdMUoYvE m4XZ !3 ?6X$<_V24trNj'ɓ/6dⴒbc?ꖟ`1o:3F76eNG#8~ S\tP-ZaﱪaJrjMC*#?'%VZg5"p=u尿t bzʊԸiry6\ٓ&hv1T'B+W~(fOkh$ Gω(d+(.ihS龇p _g׷_u⠷y7V⑋1hk6`뒕WcFҖ NwYs![`V$}FuA'02XNը5@[pzw"=VtsH<O~xG's}Y ubu.*Qx9*6o XTw1A9uû;ۊ&c|h1XH@g})tPӁ)ɡ^* *zQ62^y_vNY,*J;sE.(oa}h nfV7$d8M2`VV.mHQ딌 +kb<w.ƙPnMU\j뵉/JvNv<Ҧ[vomgljEi㈾\{w~sC(ϯ"Hsώ=r(v=4$A-4vVEC0\hx܉Lk7/4LZp- b_#ؾ~W"ӷS !ǡyG>ǥ+ܰ?FE2Cbr=nv+S_=uU;DOA .^_')l?0]#2es3]$7U8PݛbF鶈bu>&E1JvX [Iy*=Y7-.IMb-D-VpGqтA;ݜ2_A ~R2AVōBY:{y\yܒ)u4Pd>x\\l\rzfE6E&TcM;.]3$# Dbn#?TDdԁ{$O˖[7/@p|Ӂd e?WoƈGD{9=֚v#p.T|GV(sg*zx9脍fiKG}:Nﱌ9EWYi!Nqi#WdZ0kmIsCVGr&V֗Fj݇t_L`6'/4T.LZU'ݿ ߫DojeSL@5) /a sSa;rI)32grb` JT"RRL!/Eж D} %VvK#,3UvtQk ȩԜ]/9%#  bև%<y|2}Iƃ ѿ3Y) ^-zX(bC,2,!t4;Qk`0I2 yJN f/tL$TđF@'J= _.Q RZ /lvK[S<̉Вd]q [nЧtq?Vq}kN#5cOyb<ހ”DF?[ouVy/UG*΄G' qT>e"'q^Bج=]Kf!c1P>&P'a1wK35UEw@AmZ,}y9F'{5pTTFFXtϵ鯹-_hi|xn.'R$,DetD@|f }On+Zdx 0 v+E/F?m!vRgZ^ڏo7|=B"i`txD""LlX@pE"PωR'Iy8~y&ftcEڨY~kNMf.M\u;n "|'HnBzf>fo殺͈nٯ5w-v!"f}Fըʊ c6I֝^?$G09zTtqf\7=1l햮3Cůp\N#rg9zphJ"bnņ&TNIQH% (2ҧ7?w28bnlE5oHeGٞЎ}r ^H6 b I 9O~icC.`q޺ Vn.IH>z?g͇ 7u׮NBWJW=oX\OvBq^ގzu%aݒ8s'*KdV' f1\ ]P3vV³FwWȈf 0@DfCw4׺b_43qMƅiY3K_S-XK.KM7"_P՜+Ŧk&(Z{b')8˳je+5 |Zlٷt44$ [C,'s]bUµaQ#ȭ/JN/@qRf l1;wNwo11jK9DtE|CzR(Ȫ˟|nbO[.E뮚EZ 5PxۡQ{w)у:S(!niy#|6Jr?y/S]ux) 7t ,%g/G昒1"6Oa9zs&Z*Ɗ׾mDי>[vǓϓfyI )"}~ϳA(^p-v ] ?TH J&IwZQ!ڰ-2LF0VAHb6 j(es P+рwqfl:|+n;{z7QӚx󶩗GM_Yw{6% kLۥ']>IV[~e>;s ؊cZ1YG^jv(9f6kvYD,_fi8#JPȉBvSVWYBÜ"ho#4G'L –-w҃yU\>^|JF݆㢨{D_0A^1J=i. ]cl*Ia\)F: ;3j>oG@3JwY_zn~!yE^{)T_jj'gK{ ,촺*0FytBxm"R雃淩&[-O}N)}C"jcjt{P6T5L22t4doIи =A9MCG~<.ĩ7j_ ҳ;7QU)?wAX*c9鬕JnTsTD%g@]F >:zkv[Y^Ng FxDA _Ƨ |XU,~y@l4nvb;;aз;|֞[EghzME*r.nepgyC$!`˻9޵-f'3)(qEc~XX/yM$i7V˱\['P˛PQ'7T'9@`)Sgȯ,D$%NW&Cil>$y oG?O>dVD LT \({!/K|7>O G% (0k:ȅuΎIc =l]n8fʌy{tOn=!_nU1/*ъ#_mg'>)䨰i@Q@Q ~@_"r>tQh6n]{o.Kw$`oRrWaR*_kH1"1MA]?Y9]QT'`IJ{vbv붱m͔PR׉mPۤ݇!-+-MUmE 8> ߟUyb&F^g9,=\o*o749-*]>u^HLU@uG!ǕqhE|/:.2 zp ݟ̴aضɳ+[ gJaObWƆL!ɺR޵Jm>ZX=-)Lw۩ҐGzf| Pm!p0/E"o-}wGFcCfKQo)OZꨗ-ڃMgpTQZIݒc~Z ڇ+%' ?7˞h##dyN{[xQ+1\;HL/M:y!+A|9')$l=Ri+LVlclX,DI,@dQ}mz_.xt y&}R/]%WZ~.=NsfVG$r{JSz~_%10-c^QJ3]vwc{߇mz7͔+~W(䏼l{l=i" \8g&A\V(_.DﰻRw?seZ۩4!z\F]lad,*(zn7yj@CUTOmU˷6VwK$p"^xW,d"AI(ŀJ,H11HQg/)H9S O521!6^K[-kpb@M.eh0MJ-w|扡AATcQ$"֮'<mY!2ۦdDs߳ *qK7u.{U!˺Z*E *@9ì߭ECX(413Ba@EeJ;iFG;>#h}t_]f4Ȫ9E"Na|PPܺݞ /ڊ>Ai"G&GQ d)dEVh@ dTt|zҏl6( ڸoĺG*ˋlւ5#ʢ't}n )@ݧ*N9*v: PR͎c懳p;1; Gвqryzh5/f*ܣ@ *SC xoƳw3i E!vݢ7,zݴg$ Z4tYWcಕD-LG-Z#ʂ~%\7]U'َ8!iW:譏/-hSV J1}L]N[WΜYեe;=HJwCcSkw:%Ww8er^ڇ;kNB8N(ĺe3TY}Fs6s۞ZUeIjm h3xv@8V> q2Gս7h۵ Rs@iu\VguĴ sm-k&=}4妨E6~H$‘z1a\&3ț>.\ƈ)//o"jnuq9.P΍(lqHd'\J+_V͵uϹY%cP -z"bc IP:KᜰҽIlج\~v` ({ܿ_"\ДDBWB*0ѥlbހ05lf^s'|uf:g/{?,TbuХ9 L.e~/* 27K5bz:01,EGֶ$J(:tk L6>ROqf6/) ,W:=+8R;]6]a-݌ll%0/PEVp=o9, dg dHjcM>{Ar{e-fIT^^R͂]hs?_A~A7~3hΎqb {^|6?Q0gFթC o!q p E ,.=E߈~_TN..Stz~ :9OMA`_ΕK[w>ځŁ=9l9^ zfvP, c4UQ R,Ĉͥ`p H7wÄڵfȒ=/=Co6$<։kz71c~0n#k2eR|"b=!3zK`hADV n52 `L m(\DH չDЇ)N"`91kУ*JîqQJ%] %|$=5%) x*҅6T+qI? rw600Af:cAA?Z,|u 0bmA#β_oΧIUAzֹQ9osf XXPTem Au6}UǴ* j%C- )/o#GL&qx.Ŕqw}t8_8TT,1sUNcwfοS++eߖ`L2:EX $={Gd i:}w}0fΗ0aY5&V`F_tXrJZ.-HKW\#F(Რfɵn I;k-w5v"a`ƘR۷ޔm$P@޴*rQ3N~lu6-vb3 csE|i'?S)*;mDw4> s@5';W< u{ב;u ׎¡V &P(@P  9$}q#$/Ȉ<,aqq7{Ñ J%+4&#\&\o~o"1{9:[znRں]:K?@^tvFW!кHzÓ QTuZp@w)!U`](! P;Ͽe7j(~|Ko›_ްbDn\k? &AGͦ0 VԄ%TfA@|e1DH58 xc>'!?1mcQs0JF-e/a"ꧬXPLCrϦBFDjWM Ɗ DJlh!tk/c7" Q=#RCpc#OP!I@B482Nɶp0ٻn7f&p?C7D68b(ڡvrg^MtTڧr\xOILZme Se¹dصTѼˉ"DFM4@( 0\siv{ELf;#-年+Ģ}]l2X̵MZUZx͖ԹGt(j0yҒb-wl}2\pbr S֧*z6- rã$eL>u i5Ņi?NHc2¦&00-Vv[Hfq͒" ̈́NR(k׷}Ej# #YU>Z >[ZTNQ n*z̽*Ku%P}%SvG&#Xwf̨Kz-\擢o/B>gXlE :"YrW+!OHܮJQb ‰GJ, oL穳T&q`0ˋյA4OU 71Õx\_ bEgja"߯ RehΧG\R^XPE?3%(7:x ٷc6wߡ0rQ\1kڇ?ZY Oو<qȠr7~݋Ӓ"⟿J}o^j~DT9%mf,2zm{a|9.N0` QLmPbRa $/R2:%K]4!/0JOᆱm{OƻZ;T,X y I=]ǿv켣Y*}+|KsU(r`}M:np] `s.v(UWW ?!*`Sj \JT]4ʞW43N31k +Sy;N4m 8r;[t7w9;Utz OE37pNR5K˵;j"2Moظ浖;h!}Ǐʓ,<70A:L#DZ,˩ipq)8iO~[a "#go۵Y@u dJ 6 I~B"pA $B"QI)șD"Hޢ?obtC6 yzYɺEVr˹Oc0J+O_护 YP,V|S }gЧ' m('< q;}}_ҟ0d@KkcujZ(!7}d "Qzwc|+WHutiN10HB3+gnWxZP ЕZ)71֜@B DZL}ЌB_\P3_#= P?u QFTuӓs}y~Tt+ٔ!!֮>OUTwCvýl|y+͉[[RN3Nƽ,35ZgV@%yIX ]z͵32JIiryn~(c{;֍J1-OgA ", |s7;󏏓˞<Ӿb SY2 Va˼djg#-mU#7KTEM% *ay%}};ӏLJ˶6tGIwaeR]e(u%d?FAg Y6w6#=#h Bty&蓚km7]s;GW u7I1> wb@ ,7bJQP?wP|7é{D?)OfQ gw?3`M&KhS>;iQ75Jk߫7OklDŽϥr|5S߹ߩ䜽{Q5^>@NG6|mhO @$(z =y^({AD"<$7tS0%g4סOPD+60|j.x~/Ş ),;(3hqfnB;3Ebѓtyp׬3^z.<Q*+  ՠ]y_S>&>>kz?5(d]BuNb\6?,ak˷ZL=#63ӍdIiH*ZxjVXi+~9WN((' kD83R/K.حJ 0f3ʏV;p ,jEC+f* [͓OWʦ{a!Y!"Z?W2yEv5{!-UIf[R=gmscڵ>≡Gv^k" mX[/"XC,*K-\pDEA&Secs>wo5:< $G ~. 0]_NR- aLȀ/^}PݳF9YG _ PM@(Pj)B요 &lV| 1ۘ&Oj:g97fkY՝zU_}U0( O ~Buo;;7 ۋ',qXݫ-2ʋ Kh2jOFXi3ky!Kʇ $HUǃu&ol|j U^X-XYK$*^R疄[EXv"I۵P6Vxq42 z)1bB^r#tv:X"4T+0P|2gmX B\,`]dI5,EVfLP}+Hx$v'bxյ#札5vŦ\Sgfb Ojd%(iGs&Ioֶjr.N~. N3︍X$UɶrP ̈[Z}ED 7wU)/"b3 [4v4$Dz j6[ьizE f \Ry\^#gҧaDuH嘆`uR^O_ɿ$pG٘T7Jߟ.*4by4rŬ5DiuNś}ÊusR'τ˲Ow+f=mi/ݬ)Xh#e&ȸ8fKtsUh(s\&,h{SchINi寶D_Y?[n@*X;R;9/#k dBƌ@͞2S<*8H勽C~]_Nk qlV%'a5NHȍgGM0nK \/}_-]Qm'p'y DtM8VVTEYa KlʓI`O_i4뛔Czz*QaAMg{ū[ۯCoy&Pb(=(BTTITQ$80 :ҽ8vӺ*Yԥmh=:o\R AATP<8Q |${stXP$L_NB^: @|{/?ׂhWw1< x&[R2'w3{_Gl}7;(" A*1b)F9k!V[PJ_;cUMf-1S0b%P+0hUDDkDk*,eUUda2JT"X1FF]؝ZC8&$pk F x?7q>?⦈rG9NYVrZ=,gk&}15A͒J{^;.(f Σ0Ef 6ȋ!N5ڧrGm`+Vt! OƆ<~mX(Z$BoxCn}FV &ҧ}G=ۻ~SBĦPmylE1@M2r@a,Scb#z,츟jNT&EY"%aN#wҐ P'!{V5dy] Y~9Q@ciqo~ R |t1ѱ7#|?n2G6$ N/oߪՖ([Tiek??u58쒙8XwuXO5xl-j)#8T~7fjz> F IcinPT-}j򵽯ȫ?e6(Em3`ZxoDHwcJHhKtlMc>/vmwxTNwZrg >׎ ǟoxu__p<(U'տ^dR Ru 8o8KKwjqkV8:iXX R+4^k{,Srr ;·GTX x@9izέSCI&jקC>gWujӂc{ˍf%e]2+M!LՙuoU,`  \J +°`p QM"my-{3-ًbUV(OPs։~A&ƅϒ\+; w,AܸOӍ;,f~ζuMֳO"rt=cX s !E>%mr"l=?j%-4EuiU AbP}0)ex&<44 @"[\ $l(㗒LL-jD@ Y h*za)߻ u@5\3aU A$\(%dq8mB5&ϷU£|gCWf^զ֫-s=.~|&$Rڿ#f{5J1Zf60[Oӭر}J{! "C٘_w fw?>E9z{O!̩8֛ss"~:<_ʦa'r֡?q/V-ϺIJ 0D~͟`oW>6q,i/ TY04|/t[e1%% |K`HW?g[c2dQY=scS[̢Bffv_'ŗ 5»_d1b[OϜYp4Ci/")Rhi=$q#2I ߗʩb%e֊5͢ i̒rotNzr516oa%r7mjnz{C /Iy{] p;w*F= 0e]+ DMxr"0zWJӫutrPPXU[UT[sU0"zvUey) >.?185юn]4;; 6.GmUҕzÚn_ayׂ\o]z߆6(iY q!Ǎc-]D) ~NxKnRɌ֑I1<-8E~#l] $kfdGwblgu\RS̊LPq%~`km?+=9!BP8^dEgu[Yg G5%AmFՃT3^l>7nqИ];ӫZa~=*!#I;BMA̺.['aہVAH'0kJpW{=|\cuq"'*%AqT#,|Duj"@޷&TTAU6؆]'׭[jKVw;ѭ%ɹỲJn*>v8t^^eӊwiխlr+hq[ $ngs=!|]}tDZ+.Z?Ѧl$”$#oaWy{=zonek(!! -Dn1gJS<qgzF- [ֻ//+Onnyzb nsx0 :S_ q{cO808XbI$'{Th*?*DLuJ0xi'}== T(Utāh!{(, I# a 'D_uBzo&Hfm?6პO!vc9Kx?C=92+,UQ`T;1|6<ɉ^=sNQ>k.Uo>t'Dh~'C:eMW]&zGEiPU >(p#UI͚‘RE7]tz) Yf)KfbTs%Ob}o8 %B0F:@x^D3Z0m`*`$*>^W[cϬuRiU2giIã#.7 'ȼ!$J@=}o=rWڹ*Tyz^%rRoo1잎y)b+_/ﰉZi!Xq%DX"h㩽)3О![!Fcg dRVQWH>_qA\Cbzd?;D`WHKdjn+dnncX0V2AF0DЉË[vwqrBhs@ @b=\4cv:ecaNw%kF\,amgˉܾ1ΎC>͑j1[UA)T8(bW$ݻft$(\˞[1"I8aA@D K<=ץ=@55b{RcLӚ'IEhi䅥iY|vl~@!]5=g=:-~l]=Bk6 Jt m-8cqpSѻKJD&rFtȣֵ ~ɾF74VWWgGut>{9WGvQ族3{w".r1cH|Z{l>bkсns [O@7䟉e-X]kak6j@7!YvYrs@*p@P7uZD96\5d3"U ?%i'4Um1_kF{']"wTS?B@tN:\խC[d:?zs)!Y, *?zߴjK;򵨕_#0"# #7KMm2)׾51 B~KOzI ј +sxXsW؂r I.xV9,wG (+]Ս<ԍgvE9(AE{b!'N y+ci58|CMDJm^뼿ROWf62:m0hS.BHyWKmqj}xE׽v>vM~vƏr,V%Gvh9 ۃ ^]3] 1`M֘0'["ek&cY# F0TŬpnĞp$ 5>/~vÔ#@@ ,LW{>.;] yX{VdVaW֡ɡvF(~N/+:-/{TQΥa43 ﻣ|$`W*ԺV:kv|\M7|/6o.#^zc)h3 :]̮#;Wrl4[_Ie9?yl^Cuߛ8WKw?oDAޡ]Ʀ}gr&jkWMƥ_65SkŶBpX` JVEe~,%JF]:%x|K;/ft #|9 E:ҵۡXz6/R $Ж=r{'r?v,A:Gjڵc}.o 6 DlT]2sSU OyBbWDl /ѓ@D`:05֭!]L@ VFI9{fdsFdNllDh^1@,{XHF 1<{xѭﶫa5.$ȳ 6ΣIĔEu 05 ([d@AY ]Xo.rl9ūQ:"=,82:BQQ^jx}LxV] Pu].-^+RuA,f?eX"1G]5-vHoRp&s_K}]3N?jҖV7_mUdiFzn[Bs*0otk>J\y1*uqpY2w?m(EL'xnpo}R>{FxOe&%Ha!*4G١t3&pA`Ykmd5-%7߷t=1Fl]٤ll;bDb\I*:si:ԗuUMIf}6D1\yց#S35$\0VOvOlXƽ59 |Ve * SD Svj8kwwH qUpѩ)VԊ"J#DaĖiq֜ުI[x3mTZLxy w: >SFMv4^wBĕ/¶演ʋgsu]nW<Fݘ =ogxzK7k;ISv&X!KtU`"||^߷g7?O,]Y]ڭh4H˜GID(Y+[m9?:wFinO0dzH$hxrNDR/-(րƲ Ki+:LC$pw>Kb?u}OʁI[-S?1CZrm)]@?N[m^G9b'LkWMgyib\M$IҎrg'ka`&:Z`Dr}TXO) r7?:.LYȩXH*{J8&dZh~6./6Xm}Ȕ{+wtDd"M}[rn}q5/"`u5.V#Ϋ- ;i[]4j'h8ؽS!9s}ϒ5cƒ?Й^y{fLv4G ~k![7W5!{;F$_"ߦzmF=Ƌb!kхۘ|6AkDr!1phugl G%)I/ۙQQrZGr1=k3Q7߽tR>;8Η*8 Ge_o(nQIjDx @蓄8ygeܨR(F- )3'-MfBRw3}`Q!Di( \0@Sb!$P}Ht)%H~[=^a 9l6ᒦ*UCh(5j)xqZ8=x `}}ĈRO;CNIr}I;fkk/z~ݿɋ M觺J+ܘa)5" "!y ]sVKjmds׷Norn^!O"#Ny76~KJפz9+uL"3hCjQ=JxJ2JVb؈, Ő ).8sf-a3B@Afwq=;_vOkGxJ_; -e g)ʾOu4?kvWg a` ^y Shk+m'UϪJ;j؝9R[[O͡)rhsm5ɺV'?n͋t~r[sp쉌އ?b'W:5fd*\@c @yX-gMt+V>IbhaI#y51c 1m\gj$8ac/)rB¢'$IPDHcVeMK Ok #T/f?T(p$@|A"BTG*O?2t>1vZS54aɵn+"*Ds˝>a[0|};~wA/{]qXpXa1MD+evD5R1hY/,j$ QS^XϿ-Hh{Z aBzP8yHpoZ6!6Y1YXLC=D6!]$٤ "t+9+!`tv~RZMdȊcq1Yb"d{<Ղ2x|Qz0=ayaϝw r|q$}A!3}ޞ ܹgxYAP{z# :&̥Ͻrz=g-'˰|p3? lsֹ핋yMwOw#?8 S 9Ϧ|7J.QH {N'.Bz!'kWadK;: Z?^ = ^V^1k~ɭ1rfc7հ̵ ,%(W;]L/McR<*=-n0A /q]mE+a+yi.·rqH]g~?DߴʒiѮyd9̷Iw9vC*.ğ mn;\R.Qx1Dᜇ(lv>P;n:;nF'UV׋;aV/G{![OJW3}SW: ,s+XuNGTø`p2,u#Yr+h9&PxVOֿNXϢԄ[ً2cFJvJd[&- Wk#bDpr;m%y||g DrITu4̧KPfjuA#ŽHLNkVJx4Q]΀vj5Y)@mY?tBϾNsu5(~1mx_F cX,( &j ,e es> tzx4q(}OYz(QX1J%:lj{:Q= "5:[l{CAcDTz gY"DC:e=[Ȃ|1i;읏Q5`xm5՗܊b0@ XF'gbGpaçum8d[J[F8Xƾ !r*|ǬLg->JPWH (8ka/B5=d_K [󝞲'νBu{_=jc%/HHK1jpyjr-O_4wjBo+4nGd_UL_>MNY۰ !ͅ˙KfVHD#Zc$uZiN.58,f[$ʒ4Xa|sOeŽp0iHdGYzC!d?bl`Q ˎCլa4Hn ZLzِ -@Y'DlYRn|8W-O){ӉSl6SXT?ȷ/ LTSbgV/+]ypEQ%y]Uvҿ )FDhBI4/$< &F9_=-R"~'qb-ek^r]оc+^7[KMf V,mxR|oXnId\"Wz%r m;ֱa˒_^l '{ay88[, 1 vYpF{ sL] ]j\ivwpȎDf<Ʃّ1qLēp AĻ#0jF?a5= P8w 0\~ΗDγ2#sKYDpo&{-jbn#qc˚˸||L)Vև0_q,x֐y FޮiIPyIT=q>Mmeyk_y<;ЊJ ;]J12emC9]rߏI)iw iek{~B\D`9yE,ZNT;=Kns"} )amR"Y6~7g ԊZzb{R7EŢ rW"bɾr{ L.{gԯz73#B_fPkJ*ڹo_ױ$z]]{%zB֭7vI3:k46͡W#`T.J3)\z=\zq{H$b"n|6moU}x~y5S#(}S+-Lz T1|;ge:hݶc>7N|.Z}ԶgY[`4W 8H8X$%@ !RpTТoރ_Ap aBꚘ(/@#2ja5m].6[D> }T玅@%̢alnqN钲 M׊qAK\xlW57]5/جO${w~t_w{*qR85+.Gu+v|XsZ j\qd- E%Ã+ץd^S) CawZ"m{4";L/ Ã=}o] 6 &s}uKIFixx< |V[GՁ 9G hZ/U5b1G\.+y#L(1F=*,&/Nxuхg;V̆:a+J"D`>fGEHe {Sn{ͫr#[LCщy]ӤAk?oR8,R"0WvQY"¾nXM&զzP8SxtDsE'ODۚ*SA33*'\cvF㜈BdQOcgrcow5MZmiv~tr"|8k,=KvG1Kgw+-9n_iլin6.eMC/l^nu!+rźX?W)߶2jg7Iڡ陃fWe˂)$+J o5RW4yQdIm@qQ ݦҳ5* u[Tڏi7约frlh%d*z>0J,#D(N8%J(:F770-9X97/vS]ZS:4p tN0FOӞ&3G~'6'"#[0;:OoE"VkinxxpEw/x6i:BMI h /߁n$Hĩf˦!Nl$jogM$ѳX/mz4 #ZzoDřUUjn n3it$qYUm: %MlϱУ,_$\Q) Xz=NbslfU9,R+Tor:%Чf6ݭw@@ߍʂ]!7⯙7e<ᙣUE]ƾ"bU!J*B۪Pm[=*J&uq LB!,pI˵9 %ŭ͎a: F++w'!2?mni[;D>L8) X1(Φv):MEu%Bn6-(o˲E TO=)xv/i ]q;Ne;0MJ^G*3;1ͽkrQ}`kKpsi"$˙7gݢ;ArɱCJ|dw"ZFꫯ{18si-%\i#tu8KKk; |}yaB :?p@;a7pnd'a5iOɒ. #+{SmZ*t;ҋq|ލJo)cwM%e'Hs=ݲ[mX)]Cj[V1NsӪ!H0yizsk籲uFMQ].'=X!5{ʮoҎ T+/ľwEx چ4J|ܔteZGuaK [ pA\|wCKø(oG<[[f'+GmۭɁι7<:.ifAn:-ay2^v"ޝYG@LU7z82 :9q)y/MŎLڄ˗Ú_{w`iXCRM::0]Ūs1*2YRӇ#;k]lwT "$a20)iPHca NG>F.W˘rH.o.Zr 췗Q ;z WyBi` {OqXw9UEzSnzoSW//lKZ' ʼn[Y;n ˭\âԪٗ^~^8h1XunłE#1˘>a]]#@B;5bwq?BLz|G'Ɨo}+Q?`c%`m&%fB=ʡ`tF0xJ}j嗛*7IXnR.߿'OSiuޮ6vVnX}|+2A8-[y=l4{=l܂" Ï-2O'ivS?} i酾z]k,Sҫk)"ÎQgV/ԯ]9thE {Fa]矽; Yf}"n=x}V:xދIvվj|rKkE C ,-EnkؖTj|t; S,G&w8tRn\'\)4Cw۵(4ڛnwJ=w[Fhƿoj<9sO p+SRHyO;^>]6*G.ksƿw^ Jn'\ũrxt1 D|s?S`g $e;RJӿl% mkK/j]uy1&%qpN쳔D~#1RQԮ_s7˘JW[S#%V\ߘW5;/l$Bn7^wj#$wH 6%A0ln,by] {~?hW=/: քQfF9;Ć3m#êW2 5$2&@ D-3ϞN8fiQc) D#-u)$[$ wItdYOn_}AL\Ta75\%41S; _F{xFfqgy3c`٣'Wmy}j9Or$/e/Sb:m}ˈ!}Z_Q6|ed~O W"vB zJ.]%ߍ]ʈ#״TVk7hE̘#mk1?}"*>T=AƧ_ vzc99V%!C+7 PAҺb~/C76?6p,=4lW _4}nK7AwRƛ=Ri|pxE(ͯrٿ΅Ic[?K;k{`<anBAE,V1vؤVsy`o? CNyQ7c#]rԥ I@9V8" -qpBH'ZOCEU!:_q}g|;3t;m/ѵOfu`zMͭn >@$_HN ;jCO{h_z»c8D!4$rBJlHwu! UVz*7-B9JGiMB5D (1) 5֩j=ݕ7v9R05'S-N՚dNx;ݗ:B=jc_Bpݟcד$8/(oV&Rn1xw'1 O; ~# !˷Rw]EǙW22@4af2U_2/:Ņui}V麉e4:[.jP LY@}F 0kUy9EF6_tޟ>T_%x1+}x/QlosXY򣂧Q|{>¾9Wªeo1?;|j8-^v?yXqqWos6_o~o{//9-4OWۿ}4^ '= ^?Cg~/^E)JSbAxu $'0-tm[8l.H{t)‰'㡆kFKLIIDC.J@m5f xऋRw3BhĀ$_<]!bYݡ3.Wa&tlB"qg=R" @TDX^!?JIo{ɶ$n_kM>/Rcy\^@Q(Z Ni7w %Rޝ&@3֜RWigmWDC|y{9"y;lݓ5H&NB7|9}G $2v+CWwmpcm8]+:T)Igbf&t™cu0Njɏ æ VlE UA% !)ouЌE eENBA8]k DD5˯Ղ}cS31]N{߅eb3l ,dyE*ܯ<|mru6Qefa*̗Zc!TyCU9wa,]kNTÿM-$=;QG/icRW;X/#$I6{LI{oG* !ThHȸܛۃQk}@<)fKZ;v<σ@0IHtV@<]lXF"iHzӵ"@X"X( )d0dX#ER)E IB,"EX@QbCt X[d[ΰe򻞾?#K•:yֱhyS2^݇eޡ fKݻ11*γw)a@0`@`W Jg%Wt~QΖ8$9j_\>UG=۷\ns2Ӊ¼(% <WY g1f=H˶f )J@y ?Ym\!8uYuu>) /VBCfK^Ǫkི\턗KxZbz}f7@hR3\< E$j>emJ{n#Zrd#,-\Te6[%'>:V!3#oU9w=+9È PtWmXy8܃tctڽK5VU`9BHlE;?Mkc<\rEF}?Q*#Ls~z1iGa"?7;sv@H]>#PB|XqW AbA>M`_JSDgM76} alz3¸{EGWyN>;{ X3D0;aq`Q#$$|..ySNݽ_v ';=Wm~Cgaz_ ͩ-V` D^8vNJx361kp> q , یG3( ufNCaL wz3k|fΥݒ?yzʒpEg8PGK3D*Ѣ.AAj"h@Caő;uyOC XUh4ρgTd!hЗ J pA$ahX4%xSyD"ywCWgtrJrdP+ wugЖm;s&}<56 T[|B[ĄIHf7<NoRa78?m7$acoSv׀`` b-S~h]:jQƗ ' m#\)/307O}1ʨK 6!_C-;?A1k;""_@%i}9(atܲuç˽Qѷv'/qCЌyM|<덺esv};aZR ,):0d~!޴R?"1íͬ'x9?Kޡvh=y+c ;dFPO{ po _ft╡ H;IčWeHo:YjƴQҖ<⺵.?O2NyH{< pd~ J1w$<>LyDBb_W&k_n#ƍD-[YGZEIaN/{{ncV' g NZRO & cԐ23_K]MLO>=W'H3iFv9/p+i_D;zzh:\'\RW!m qiL)M:^֋^TwKNo8[Eh7#U8 Ũ{yk#@7e6 $ YYHڶF%c}7[LSG?ӷttƓCt^~0JYh}Q8v\0 C/wֱ2q](Sw>vmr)+7x w4[q27o7oȨ qP߸ 2 ZAr\Џ:Ōvû*S*@S`D`w "8`& HR{Os.ߙ@vq J!mSG/sٗ^vkgŝ+b\ 5<fWvv olwIJn`.gK.7J΢}Oˀ#05O!O%$VeoU/Ww"JK ``b.K{ih*7yAq(@rC+q]~?q;ӛWs;W=dWPJOH> u^"e)& ffW_YP~ay5Y2jB9|VG*-)l"LPx2Z͈tZ̲?=#^` (uX#Mb8#>MB-$GJN@(iտ;BΘb= qF~Şf_Ǧ ֏a%%ʉ^Q?VY %ZkITp {1hi|ntNd:y'A/,\^@ O3Tƅ$99 /?]\{^88{ʲ`:[n)EEG|gil/HnǷ/.cotO:'y]@YF IHk0qw=u}~ 4Ͽ?lbK;@s=f~_x13<'(ThUw4s]~*G>7?_?3CX 9џ.W)XM;:/0㠍Nxd ҳFQ?|Z9PpL8 Qu2! OIHC){. Ρu-z޷gȱ^Sf0?<8"~W#&XQd`i"hj+}~M:9b4ﲄL{;2 ѠLڛ[P*#$<$lb ']=;oC9~??$Xk+zTOMN d-:oBs:IyJ>˝Źp3KG} md<(w>*C~z<FP*d76xxһT,aZFCoD/;Pl+?zˍ*-&y=^O >90=dv oEjOmղbj}t1pt\_3XdkJZBUVz}AiX{&+k;C7a5nYZ[rvv[d>~"\vtj~vQ{T.qun1};!-wC=[]},y]b~ƌI˖ |*W|p"J' HvZ>>/y/+udqvpDfn"@;r[[R- ,wb&tV-K/j~&gN'up/::0=_#w0X+c `[Vo6<EIG{MKAo"}mw wf|=K,nkɣ.Y6kk#-QhJAsI` 1s[|#=JEL;8zec"t)w.DB@v޿w$xF CO pP#(H2*" $J% C#d~c#+F]`G_ ;f[i4tϕF 6 i_g|oٜc2u4"#4QAU,XŊQ`1aO1EDV PAQEU*"Ŋ<FXn6;+$ΐ{ſ>}v!^w`rh Y)`4tqCE@ Eo'|ϟ͟n~^k-Z>!Ƭ=-2)d:[1`$Z\|Ƶ"oC33Zr;Yr@* ^ @g߰lˍ6B⦣]s/[ǝ';>uU0)}*> />>}ni؄~qľzSxu?;xEpK!P.a cI?!\)٠he١g~- ߒC-o@(S{I={j }\QфTR1):4 >ǿS+ku9(Yuz rVet od:.NryǼ9w?@"i>aV:#1C(,}p_c_3?Ľ[l0h9Y 'g9$oɡ2nJWsUKoP m:y%RdԳ¸pG?/{ڴRBfs 0 1/:vV8/!l9B2bvq9Od{t9I9U8̞1Yft#{Իbk\޾ܸl.kag/wWmoϳLLW#t_J(W=]/uV5e))Kλ2ᲠmէMqpue=N e .s6mn]*,m,}l95YM;] n;צHAK3 ki9y-~}ڜ]%$璉U>E{޿'3ﴷȘfIhdlJ)k\ =\vOfFe(BtSsLq74)DtbldPP+~ua5xW^qx^$s:p'm0;9HAY`HNLBE2diDVrM^ވ0?#;q5CQ2?$LCNEwx?d^Ru7QXL^uO+mӖ3N}84)fPh{{&'e{Wiz_GՄL@v ƧSwuC:d\i^`m}lcs<kzKO>۟{?')5 6H@O+l$I$$I#G $+ %5! ̐y禵zMد -uI|7ƁDIpǔ gE鄧A5Z@bBAfgCc~4Nwg*Dr/SD!h&l߸ͨcSsnGfz ݈RaLuoGW&)PENg Y%Av~T??'lR R9%%%Go%PRGꠎ+<))^THI@"9#nҺUGPa 0.T.JDsR,dqiN[p"K@J_CĞV R7Ua.u=FR"[˙M5Gs~w xL&7>sS{û5o)=9 u.5={!TXGw1J_cZAϕLͬh2@@:cD_vo92 Zgujf i%휪;}j/'(x MuvM\U7&]Րv%r[k7qerv]_/э;٣p~$[[{Rit*&jr||6Cm2W[qf2:em+5 >,}DٻϡKIoɳr)ȌDo:tzt7#YNNӍ@1mglBfbݔД@@I~@:NHmJ=j{>|vZځ:3uRd'7O>M"Mx$=w}RhmHv/l:G 2,A/nkNF@$hpǀN*Js-^exfXmr%v׬cR$ϗ%dr0eFxݏD9rF2yM{;7^ˈVS4F F:C tnO 0`/|ʗkM^*s^ (Ӡ@f6p=^c*+~c%gCIBj8{&a? 0EXCUNoèY;T {Y۽3 1_ !N?~x{f: zSQ)#: 9lW64l('?}bMQk9G 7C"e\wH4"d&i f@|~5rʲ1H4gRѭ7Lv־OlOԦy)M%, % G#~z>7okKF!A0ȼ0$7\iKgaeDRFI r%بl6 AE : roز|Tlgɫ5tV:fiцg7$:c*q/0M(3kH3%&+m!#"1[Dtx1s wa/ cgBE`CZdWO"'|YPĩuySy.+1wu͟xzbmY~ ӕYhr>[U;pdԋHť\9O\Gs߻[~7mՉ-"țs/|doOb#5lu[k5ƃ`n>O7O ȭuTCKÎY;q~UQz1Wkݐv-uyV#fc>K{oҴ>Vpkd.e=,os/K?h!m6kevVlݯ.!~?^ϓg]Rƣ<\w7.Ms< A &m$7k%\拼vku׷p%h}>wK|5tM\,|^f>w_?Χ 6'z=LS)2UHbG,ظۃzEencد9xe>m[xOLmO7(߷\Mlr vcŨsseux2!ّ?}E8 jI9KHmSt:o 绔WgUtjPY!EFnasLZ݊}I'EE4G53,SA:Vr˞]Q}vgG']{{:ٍu >0#n t/~:bwwyݗ/3J$q *h}),J띩6!=Cwp}Y餇 sEN 'N~t|/q%ptl]b5.OOp~{3;L,-{=W}W}m}k_hN4f JFN@D!ZV?S9<)#c@+GMt}k{M  ^a y߿`L. ҌF`ԞGg qc' `R[8̄"Z+w=7G?Y. m텨z[WʺzA :?"~ك3. nv=aAv"+X*~EDR("(UDTdXQTYhҢFSAb$D=YaԢ"A`)͗O?]"W?_шLϾ.P^%0T۩)PPb ,UQGţڑKb)_qJ rUHidU"EV6&0E pR4$XY/iYjm!6좓?8#AQ [LWxc__T瑠ȍ5@̛ >H?k1j'TAO|g0 N¡%ΓRŷ?|a%C9yrM3&"Qq1Jnqw궖TmbyYAF *Flkt3hiXqg1p8UzED'(nArhk!̭cStRxtSd0fu "q*+5dJ6U2 @dЃݳz傽 n83k}7\i}%K&ʒެ}Mv #1Fv \(A' J X)|FZށ+ sl_/:{SHk 0S^PjjÕhsl[q3V d4ֆA@\[_8SzCܿ-?3k}!Ѵݢ ZeIx: _#\uf6ID\D7ٝwsQK*YǨ ,a~_m`,pmre9lAm<=)}B4)9$"/LtkFg5]ߠZJGtH 5C{.6&ph o =di4Vb2Z ~5'EA*H(/5hem6lT5kهR549DpUP8Uͤ`ś>bpTج6Ug2Ku ͟G]ԫPl JcBpCʯ"6'AUlqr>\d޻6cv=@E gXk41a%#טH7v& kQx%ϖ`9 )83n>IYJӶL͓2OFN"%w[O[V=kLNUjڒAezmُ@t bGǷ_0?kքO}yXyoX[55wqIJskP4~>rK=Evp1m RMp=Q6ye%>?7wկP1h( AwAQ)/S=\֓bƩyR.J{c{v3 =7ř_q! qisﵝg9FWt)ON>\ @c+r\W_ҍWO 7xEA63 MWx}?3ڤi7ٵŎ*MgQqI8mHY.VUCM3"EQ/6A^U<)q-|&j"~˿א[nj~ c {Z*[zkw(A4փwENb/XǶSh^y“x6ruDgqv"Q"+Qj0zM'@лHŻ]0 ;N3>kM?zޚ:nʍ ѮkƱb-z D)qX{;Z`,نYv%^XGO21ZٵkYM!sA?|RqrOzNpQR^ lloTr`-loӥ]nͥ Y46-ZѾ Znf}C`~+܉ %<0Z/u58e&iX韇`Mmkq: B@6u}N jE*Bg9ݪ|#XmB;,FŻmk%PpЭ"咽o ccrL0/kA):?cc_Wk XAo^Kǧ7:?FpMo8^q7[.$8ϳcn/UJ-kqd&ӻO=n 6EU.4-xQV? y&<wr?_f8Mok2ۇ#|goc+={]_4~ǚ6&|VVq\X40 G]6hMTJGUmmFV<ZNG#4 w|S^}b\Џqoc" _v6V׷n õ'mΎ|8/~*L,Ngډ\系n^OlWlm,s29&}{zVum&3QnߧkY.K^o^{}nﳥWY j3q=껬>({y^yAΎ+OםdžF}xdْASt@@>p -y'@}i+m]W:l)nǀ)F]FWk@<{zouﳽͫ`}>5nqs^zO}[ &}^^ g(T)9mܴllsA9oh=РTNUIRdph  2)J$)Eʷmtإ3w}u88>뼂ywۙ}^Ut΁{^|D&FdM``0` <A L@4L4  &b0i&#FDLjcSSL(5= !i4#)L2 4dOFީ#ڍSOSƧOSi5=GSzC=&QOSLFdB4h 4)u  4-1%aDZ !Cl3ʱ0h_t $dXE̷gkFoC.Ƨi0kG OZncWʈ,!Ŵw".vB2st'tгpƚIe8Nx㜜h" c e-ddWMƒ0s^*j_+HC oIM:2PA@UDʚ x0]y]?(dNg$K%zuw$5.[ FO3Ǧ584xt0ɞ^?FpOy=KTFSÖJ`yǑ6YjPEJkJ^1d J(߃w_:, :ef~9̤RHReLDX8@ډ$W!j+ $ZL,ISaE,*QfӦ#{D\=)\t]!v<3氊=ChE!hsUueni01O~fx)_${S +Իw&zeφIkE-fn 1K?@?uw.tۘU |?Ylh{dǚ0m`{2#E?lH3h8R lQq"JTX!D-meVƳټM|:b!jBTveQGw9p-* fy,}ˈ$>(ͳLsX b9HDoCyf950 P?coDpȂyLZ*$4;d7%("g'|jm0Al.~Jd>c?bc?zY!Arm?Eȶ!3rHe_cBzN+l2فs-QǤ+`p18A8QF¹J/-^HldVEdn)$B(F =5}{ZYaOYΞ}WH./u wR}N^vu%%?sI҃{ S h@iV:v.נ )x)Ϗr"h)M?u&&?C)V7'Ϛ`&.=޼ {.uxŸu%GJUpH>"@NpI,.xUx"J"QSfk;K;^Eϸhx&j|~?ٗ';|=g% Tsj҅:)!/UKZ*Vj$D,8:/Q)(UN d|FI7;>[Ue^6 'w1U{}PçJ O`쀔%ݍQѠ,@d CC@?YMԈ/%ȹvt7)y:ÝLK:k58SP&__[.e S2Ua\BAۥf56l9)*}er"Yu4e=;Z epn<0+Uɢ4]:hc!'\o.bK "$bvN9g Uq\u 4 Q{K0rܳ@gࡲ_F]#-;UK_!Yu-pD5MVDK}l Q(8&*4##Ca5J'nJ.g!I .i(j]|I\bY۩X\rMZ)jRUP)oS"dYWMe,AAfNҍ9T QTQ*#f]L1a9M^Qpgh +OOTJl\l_E h-(0FIMgwQpLA1edj5` jz h^1B ֈ3.zl7>z €L0@V,Z }WCL%#jR>zO2^ jO~U34D$T bl)?L^6mF$Ҙ}yp҈i!K;4HDz|o^TtG+֔|fv79-Ncl ouYBҳ_o$#s2I<5Nz9Rc;vZx[6Y}q@5B45SӖ !)Z x5p|T BQpRtpvrdqS9Yg˅ߵbZ%TKSzqyqɓI5JU+8V`"N}*/0ѝix#_"Z7µ/` 0e݇"@7IW#r,@&s¯>Z fRs0TV@=OW_no:B++IvmF^Sj%9@i0CMrBMq)"=M9d,6GW˩9(H5͉Q"CbUo=2ݻ#TΤ="<6S ̝}q) #qvsg'N+Zh;YijqrMym~Yy PHJaQ[PXy;EѥVss{a gSշE! q~$i_1+oT)_TDϰ}8$jᐩ^?)mgeLfɷİ.i_+k, ՠ^mkIk"eP볷 Z?cZDg^aJH}N(YUB*0pN]V8NVo R];XzKy^L6S e!H`V^ζ9c Ƴ $4WYC)̑?TkZa?86-G'30N":$3^xnbעx02U9jR?Pǖ @ۢfP#G֝@kwns8џRZ5AUl#R2qȍ6:QgΐdOmh?0lK1bG r9+b B }c |UI#6Az5'lo]>U#C5{-R>r7OM{5V^=Qgoh'(#vu46HeBDZME$;ePhmHٸ<<"|Gbl؀P$m榀(9j(sjҦRQɜIf7B@͞>s=hXVR`ѲW y-*/k͇^Fz8 ]aR"#6ȥ|e5k%GT"Fqz-h(X̵ot{"]~bF0KgUhjV+YH5? x ǰG mny c\#,K˜C|%bjmȄ([Oke $}zx ʄi[~&^ 0ڊL+  b\ft98!ӱbh8eM.4] s&ڡb`%!$S,2 Zʙ5JIFo)Z#m#죕-Wt爝]=ON9RQL>˾#v[^yԉLO"n)tÑ~\G/afYr$B^뀣f8b/(vEHzњ]70Zu)AMoSMcYId|XOU[/?KwJ'l.fj! 6A{~vwL0ǎOb/IB<5eP Htdli0㣉;3>tCq# 7HM_W&hc !!N霁)$K[DtUS,USsS@4"v5ZP$^7aӞ .RUUMJ^@MWn7ޖᕱ; WJE]b ^v%-Z_mn9eBjU ")#J%S *d7_uз}5*N6Gx}- ~*"LXC]:N()߰B 6F9[Ha!Hy:DH~y]ţlen+n8kJ""J ?iԯA %D(Kd Y D237O b9fеbzUEu(6c>CAXI )1)2 VJPw~eʮƀ!J]~_0WꝖm!`SzP~ЖK9w,\k*ES}`±(њ2nhpR@Έ؋Z]8ʠ oݾ˯tA' mA7Z'޶uWӝ۝@!qf+[1eh?µ}zsVܬ"wKm#nO>?/wy6H$"HPei&2S Ԏ oSݘQW ׬_g{Xv] R, mSHп }ѷ`PG'%a` T;|eY_ 2'X ̸2IS.ZEֹ.avd6F+T"]j ]+"3bfy>oxݜj5})5kJ/ݹOU]de$C7Zk/ Y3wB!ȔbA+R2BƣCScnJ6kQ]mhꡐ[ы1j+bOM"ͻK@1dH(O3‰ ƕIՒGzB!x"q_]=[ " 1/oUQ\c*"FƴB'v^Bw4JSJ`\Gѷ7TD"sֺ m`S @wCs$'-3KQ|OYc<-?]EtԸ47!SK;myQ\1!R &vKy5oV}Ĺ5_58ӵidV5" sf¤[4U,#ǰ0I=P&AϒT9 W4 iTP+pV7I$L/UmԂˠşl3n'/rP:=nP }>9V BCʲRKpysZYY;//*vӷzuBaM3#oI͢ܫyͦ#G0lEiP#+9zHYHJۻZ͉"‹bbje?WݔPU չT'>"؉D#uh P;30'y2yi.~x7%S%6=\8jʩHU븁<<^[MX`YYA#s{,ӄJI 2hI"  pg Kx﷾6F"HGi@"N|. .2!e%6*Qs&]@2_B5Y TT"^HƅsbMadc&'FKXvosa '[j(>J!&X4edS+ \h2XFI# i0 $Q"Ql*0D`,DU" Z$DX") Q&3jm nr$7sePlh-@FU"OtjU!D-\_ȂA{P%ȥ4t~zEpyoRr(E)}"Aa$ |WoU=b9 2h;UiݖbQ<{w;_B#yA؏I[G•cmC3IWdLDd`I}s ubHŔ 5uCC_$>;5&C*wMI#Rf[ 9dJe6sJzL OsP9%!W ӊ]dEJ]`ߍQ e3+q9 x7҈G"(Q 3C  !ZzXxd݉~;!!4]O/+ С pN l[Q"0i !kg*Ċ.oSI ?aM+W$A!R4ro'GX6ҬV2l FV@B vFJW ^sŶmتi̭1 ژZU*VG"ЀHle`-!PgV~CFrؠ!fFӕ=cgzЋܩ5=<8ޚ[+*DcsE` Vp5QRۙsqy JǩfC é:V('^r:x pI9CPW {J`5nC]Y ΈO "\ٌr 0e""YΪw {ⅿ*{ts}jz{u0t3{A>,vm9)|`OB{Fb&"3JMB7,k5){`aCQ KB6`;_nC77}Dc̙A~425M^7$[DAMLЦ63'9aǟVh'̴W:HF]z"|ph7?I\#kͭFG.Ѩn[-Գ=ȫùPTqLD"E[BloIaNxc}{ k$x"Bhgz7Ph UʝsHSN7 XUx y˒BYK],u,Tn~S YpyUv /:ذmb"D`Tf`OXiP0d%[dR飯flW_zzsKZ'ѱqT}z~ya6> >+!ZJ 7Oc%5B03\8jw(w-YKUUm}E2 nYKsU8%d 'fit>~wT&i^S at*@:mkTtV N7RE Q='q=lPr綜Ns`w8:oZ²[Txqd{--qplS/ZƱ_^"fnK0"H ~~'G]{as 8k’{IJ M4=VIFӛI0L|;u9i2XE*@D $kPLL _f y YJE*lWb !q(f<*!aD17ި&71r&KEBDI̳)@5Nr[̚Uj :SFFyeqK%kxPTr`bf'K A1$8aYjQ"eCPL% Mli(Lmv*|<6yn5=}גϯyq75q}D^+DnQ>cAfU$!F4M&"u:gflS%{ y VH!D mW`o ƌ¯yl;kԛ(gJGVT["7N 5F&#,q)[3 ՈO5,Pw^<9وlks {Z>tcNg2̴#E\Q^K",r2Y]Ƿ|i@9h*͊b@TFTNf0)ˮ?wF._mԽ~c'O=RZ.^YwHdeR`C  jl\o߅+dB]wX0˚ !'8bV2COYkjjYk4mw& -(LJ!'yC*zZ^Eϖ8Z6.ֵ+l[pnP}VB?T:;y*2 =asHlj]R.1pnM1#^p^;Hr)&s!kP2.o;g&6'l]5p'K6Dkߥ!Er)eQ7HIQ*$sE>W7x ()5eЉ/leK__#w^ lPh,K4Q)ݺJ.e{/%]E[W4w%xF +6l< ߁%",r-fdUT&VǕ~!諮V@MhjX(mR$ϯfg5"H0gz8 ?fc#3b5S4DSoF0c C@,s4I ðx½ ܨTŊkvQ<(sؤS*P<zHZ:{Dmq4aզOa-Wkdk ro1NP qA[ OPd`0L@q~ey x{-C T"Hyj-(DiLSK &b%6܏"iqcS>u Cj WB]L/\寜}Rr,z"pRˁ0a;ph&j`T@UiZۘPvwgg,1ciU"@8#Xl HR ąHZŒ."k|i'(wfzP&ކJ2(#@g*A /2x]JٻKj i,pC_\Ͷd?1d7j!)dXrz|@!ϫ RZPX7QOaZIP=CcnШ 1&xzNG"#LT82!I:&殗H^B``*zMtm0h``xMo,7jP~+J @#" c7y^R9 QESq4W sƉ^=\R``{Vpy6&蠞f g``&eA1 8"7A.4ƧtR>>` V"HPF9HgŽ,;($rɆL"C>{C,"׫ T*QH jf V 8u(6ໃ"޽sPSu@)I 2 3A1WxeCJdsHCRT" 'aRVHh4+`LJwT!( iA=\7_RC2q|4㻜fL ) 3L IH YNߢ/4z-nm1 1HLEP-D0g~!)#"5qerk2mʕ XW&i0M0L#RcƘхEpgˬ}F [?g" 4E&︻=iDl92Ozs kJoƙ ,OW"ªOƮ*k4ңFe0DBàM[)E R<̉Áh'sڐI.řݧ2[#|+]3G<^91iyLyj"mNNsj˱ A"v F16`C]ɆՅWH4I6te%w"#d,0$<4PIZH&UEX-(gWoJ9K C!Hأ r9"3ݠXf"1&K0TK'ؽ\3t$n$cKZSkl;%Kf.ӵqB|&iE ]ZqTikJـR!1Tjf]-8'](( M"DbG󺮖(`s8u*hH)(Y(ŵD !r9CQC֭AB41g-l}j$"ƋPcL):*ALM6n G\?.[u; DFi"W!*$C3N'q שuW7hL+Y48&٩ɼ@9dɸë;-y 5 U &j%q l%Da=aHgD̻fI ty\" " O5<ȅ,@ *NyXVbK+G\lY*h)2kDlIv;AA'!d&0iM&-k@CMۗmeZ9n}P: d&fU0NIDx}.6]݂"֑nݭ1{I~xBPTzXH`)F¤\iNqK*[>) 9{BLBDc4Iqv)-~+b`5G.Xa @Y03[9@sF#M\matA%̕5TKVC|\=TwcM9ZYka%]xזQMשgJj$Q)ༀiɦڦoTYdDIY7`N,T1]zb* #8o5s NN2$ 4 C%E+ˤdl%9x{LIA4,EBE &B`6.B&SZRh"`P1(-ŜW6!WUQ"  PIE&C)1H ic)*$U5rYIJ#!AMIP@CܛYi)L̩K"J"N~07*9Dngڝ|eAPO[BMËrQ'V˓urma䮿a39&BJ(M%w*x7 AZ0DhÔk7#"M!pAU(gld tzsT"Ifh4ƨxvn3WWcmFFpIwhqMs013_jѫkfXmv5n*u0qT/H %&sw`Bi( le`BaQ%҃Y Qyּ)`$>] ԭ(C:oۢCa1,wDQ)`6VD게R8rCD!&H8*RK !UTk))AD`Ȕ8fH*e`&RL$EYlHLm.+8qo%f::9Rܿ0I I,6lrAAӺ[d#[L_.4kQ9ja+,)WhSTuL¦0F@V1J 8oQ-}CƺPbQ#+`%ZF0=җ*Bˠʓ ɿAE'LɎ9obD-OXlV2,1 :Hc-)PUQ"DNm`av,cV#ΡCBM{*lkc =Y0TGVˆ\ߡfL0nF/Mۋ$yLgd@D}_=;0 N@BϽݲcF8Xpj6x dl0oŘa` &&QV@+S,AT9 UۗP%D"[Y9rFͶ 4O%o|[Wo%Fݼ3`"+ehE"(rR'Ps9Hi_1Kz7*ޫh؄>m+dAlY,4(!-sD"M^ H2i\Ʉ-{$n @耮n{+{fG/_s6LfT<Ɣ)?zh. qϝ;Ձ%1ZQ !HdđAaۘvNUE_j+tQ &m !M jqm:%zU@dLI7B@ͭΙ !"Ұ ͶX:7Ť|+, ~C$FrPBãKj]"X^ 3Gl護z ـ%(fDX9 6*҂sM\Ɓ{r\YAl5CJX DBWYJ&*PPEtCbI JRtf+/utHnTV=q g5#\,$ SҀjd׮+xt#1>##7 :$#ꑪ0x6~m%aGFt,rqX DU4a3 `xH`ƌs/R̓^:؄ <@7U< QI!$ٵD:6vLuHH7x)GwjOv[GFBp el$NTHEr kb Yn޳΃2ߛ?OU_oi\dNHT cRYļ^c_K5FϏ''`Zf\~lcA0A'$Ȥub{ʓ}u:-pp(S @ҽ^uV>#f>f`/+nΉj(dES"#0TQo!geIby/// 323j H5v??W,2Evid8A4R/{}_4Oqz2rd̆C"Q")cm$͢z5ѣ:Wg?/ ( gb+n+;y:.YMu,%IJ!ӃV¡%Eh(63fj3?[)lӊ~tȋ$4͜=]lEbPCҝ)FE2spg6zbLdZyIkkObkOҜ?g-{`.D37Q5NSv\7X%>fy"+?}Ct^@3UF o~??^YQʕ.ULbڼ>"E9 .y֥nbgd N}Bm_oO=ƌR+ֱ*"rƔk! URUz 0&Qɫo9)js.^Z;"]AJ "\/Zݧ>說ŀ( N0\Qb  ]Y]uIU<(IsW7}@NQAIdp7a+?"fPaS1^3&~7hr 89(緵g¶yVrd!_u֭𗚽4*qCq}ANQlNBwxn<~篮kPZeǜUѦs[U-{*n&Dl1egx#D>Ha< VwA,w/jcM[R&>,+Z+% p'Ia3wfB+Z hR/q?ς ;* #1cRb JA I3=3+N%Gc S(usoo+gnRD T08o~Sp6xH:hpYa#adz>>j؞UʣO[r?}  .YXR{a\{}T)l*)CF ۉŏOyݷ tO$$HMV}$3L:ē(V"Ζ+0vwehn,s%IYG:J+yZ)` Vm\aCi.zAD/:Xb}M}I(&Dl?Kyd1%p0Z 9?Q,kC؀2(3iNSCLY!c ẙPԟr*)G*ZdN[ŦphC2LY!xрNM ޾xT}"V`9-;lyJ!"=O{F.Y,˭ׯbX ٯna35" U~4OYhQUP>.~]+iV M!|D^ymWah)ZV9'OIP0"u/αg=|ŵdčJ͋ iĘ$1N̄\Dlȸ4ʸ6* TI3ڔ< EwO/Ԋj!V֚άZk?Ly 35E #*|vee/[[ON)R/LΜ.A+_>˭HU@+Xp8 jJU*AZ% =h"Z6<3vAA/bi)B!4C <%ݨX.F!U^l5rʻWU(&,TkN\= ԎW1=jyPfQlb\㺭^dp9/^juʡY3m2+ӑS3WY,ZcŹi|v7|/{ol212l7Mm.Ue(=LC](5EUAT,7ec7+:}'8)uoInItĵx>*r 1,Y}.Z4Aݯ/'TɗsImL)QNS4މʬxo)T1, U/]Ta{ɿ=cӀ0*^}H\rgɝ] mV$Gٙ2So@?dӹH} P?X)q m/4ڥIR*0휋oltda@$ ѩN2S8eρWO=ǚɣ m1@jOF3(ΞqKj(Lɯ8lחZ+'\k!ɺw};(@Ա7>GGwFc]6z|j5Ru6#p.-o@^ EFTZh#^ ("볔(PW:{JT_qF9RRsIR`7hzd)(2* Vt2NX8I-G UbjG:(VLc+oy  c5UzsXQjv vͲ1ǵVYZ\w壅gaVj&5\]S40(Z';YHLTkWϪL~d Ga|;V.eUW<֯C^,5&bH(,0JQ Wa,3z,8UQ?5:\jgDTxb< rɣٹ&yUlG'~?Y>5bmNQ$4ʏåg3jhϺVzy#gBcdqfT*P|Kw+M|R =kUa?U`lWv҆ .<"y$=IN0x~)lj̖b !a@4*IԂe-?{O4HGoR]np?oU:jRIٚ~϶LNc]Wb۳KB+ R8 jμd`i|1O&9QL-  ZZbRV`+rC-wDz¬C>_9yF6URR_sn_䵞…ZVnj  ;$3OTZV׵7W+GM9=GgͶZ:l2Un#J'P`V w*-qҍծZ@:$li]T&TaD'V󃣙<LwY x`Zħqu,rW u0  O}Okظ^l2hERMCa)M zs)W7:_,c0URXrR, |tq\;T.9nydySf~nG:,1@1> y.g C[~6YX  6ɭ:l@yUF ?_0:$4{~2p&v/I1IzbճoXN ZNC==硽ÔTL2v%O:B* ߝi?'I`2L%GzxaV)DV1 UDb&EU`` AUPTJQUyu0QbȨAbe**V1LKP\-m7jj-B>bESaLAcp@P($AD "fڡ d)"$ )(EX aTdU"`,PBMV@R,AH@#@PL(DX!CdI U`SHc d"NXVNʍJ)`1ߦ *&YOX|(K֥~mc\Wi;21y KtycTkYeKZ nžŲtՂB"2h{pƠڃs|RE{&TQ]dLP;Krt"TLظ9wap'5 E>/PIU" Z e DJ S;JPvZ ?Sϳޤ22^$*R$XR"x#P)WZa" (9lݟs0rԨ e  h9'eJTe8+۩"nKoi/kq5+FLAFH ;Ui!CZ;y*Y [&8F ¢yi 7Kv#B[=NI@DgXQ`WȮXAAŸl}?]wm PU.e!C>m#'J5 +ՕޫRI JQDT'h,(Cu'K}sZ* jW嵪}ɿ4; c?^x%^+͏a[s=~ɋg4rd !Cst> (fg?]o'^8/>w]bOC`)hF^(m M6W676̑6L/tEQA&"_URM)by>ο?D>1Jx&`{nJ+T(x- y}H頗*"eV$ 46(LZmkFIP~"6,.~w7 S! ) vRrMP2VՖ} s lӺbԪX3`{/G22)''X=Mpojkjq! ({h̨/_*Ӣls{(?RǑPFHEk3f |v L.܎v|W ]T;Ixo 4(T|[ QBBroshGrXG5L ޖ\{yc#Ɠ}{af!U?|},DmY0AT6Ot,! Ƀ*&E"nm;Wc1IFg49+]l|Pxw}{m~5I-R8[Y?_vPœĢ0D.^#/?JH1x{S3#rm/:Nl0#|K:15,]+;0(\53 sa,qz-k썵8&] p˧M%!$쪦 KܺlrRf`Cn\q X6^exgEm7nŋ# ؚ8a#%/?g珱=wI6cs҅",2-37&X`Xޤ?b X4.*U4SQ.JmkbZl{ n}AK5dAO c<_>Owl (_ 润[JY.—3 D^k?WdJ>M stBbB%\TyGAtu}! fA^ #79%~3.4PԆ9Z6:i$er(!*VVώ᧴[p=*x[/g92$LvEv2Pz|;?c.uoVۨ?|ܩ.su|v ]ۇwof vzjc-B o;9iFTC!D7SotpVLgSԈIĿ\5x]_GT5EZj@2 IB}k>s`~(ɴw-/jl S0?gKyo9<;{&-`.ڽ&/ԨMoXsLsr7r\(h֛ ledBLVb~yށ51 b%XOnYD\|7n􌛈]n}[r[~nOY~D@6fcS{~|/ v\H=n}? ٭jJ DG+Β* N]v)?ztY uO5b_=h5qnӬŸNZ*`9SqX{YYݓ-2iQH[i[m1ۡ5ۅ91y 44@?u$qTwm!0Q,U1-k["a` Q; *vr2+l6o%oPr, G*5_<,L,R}b&RfhaRg'tҋݦ6UCZWQj7"R$X*oikf^(Iv0dpopa:f&H1al‡ae%qV 'cBVPsYQqޝ .[[}|͛'}~h6qqg96 |my{DDG׷0X՚$NA,1BjEUyӃA. Bj?łH٤]֐XRNicZ檀G78腦" Fif4B 0ȑKʆQE}l fA@TD [@¨ޡnMPץZl'r?lJ޷e ^xxu'"JEw]S@=1)L A8Sjs:C"MAE DPM@*՛Txjhr A? /\.]_c{"Uյ_|Qܑi X`) q`6E4Ty+;3FR 8&Xr$3Y Z RMP2/Tᱶn4Pќ)$5Y@z^v%cZ,J0hT ؎T&_}_37s΋kS.FbB$fͤ0 NCxD#`,$C"b.uT`+6ʩH]~!zW-;w=|q;6 CǙ֪d%gGuq:!LSgc`j7SI j%6Z y ;SԤSAdD\EDHV6\/~s"L/pQi8}3Q_'*!ˡ&YA,*>#b`2vXbyU Je9gӌ!۰gųCBJ Td=2fH?scKQaGNBC9UrTd(С'n8%L,ULG{;g5farn E,::M& ب+`%[gݷ쿓Zz2@:h#Yy<[:~6I YY \YBHޯ [7|"O=AJs5 EZEdxwl0R d$C 5q(ݟB*zj:Z ʾEef6_cOG_=MNTS,jn}4DnFfN90" rd&I@o&P0ԊTݴHR^ mlvJOQ #7E粼'_GoGK K>:d>ǥHLt?wkd{gUtJ$UH 8l;!l_{!7O]:Ir]fx8Hv?-uw0 Ys`s-!PLlDr5\K&rdn RQʦmTHf^K\H@D}:u]φ8eD# _DMrE7n;+GKP|Ajh.sIwUmVUK0M7X+,]]]C W=Q-|>UNn|2Tϥ "n5b p+N'*;X*j.iޓZC,889!%˭Mh+X8vtwCb-D۞!Om 'P*sᨓz /ŜrlG ;j-󈪅Y@&}C+ d^/maH4g<#^;WQKD`PJiD:<֘#Gzc`g)^T©59tjm8MU{9x{j>(E/"f1xI#P%ˣRǭiᘖRn-V5Sd||* V|( ""JEd\Y)+֑Zo[[*)ؾpXyզUR rb~T4j^ָ`98srTHܻ@3,\6%*GMAL S9'uϧ|=/_ej7ye{XOrbLRcܪTl7mt,LESйkGPJ'&XKU[5a*C`pBZ-f4@4΋^jBTThZZ 4٫=ͩѥ٣@Ι-63ςd6ͽKLef1N]ne&mI`"{a)wkۄ‰ag IGSrp~lngKY b?=A]iot*d_Euxf8M]2z\M4 [ޠ.J썿xzETP t0O]~r,= _q{R말Jf{ rڥ=R+ʭORY3ż:h9 l$,Ur0\vvb/}agѪ~GƮj/LCP1BBY[E(<ߥ@Mwhr" g%+P)<-a5z UJח}Ϣ/;H!0J(Ӷڒ{P8D]w[qf,Uܑh{WDsvsh!kHtoV+]e A3@(@f`RoϓYZ,Jƣ]ΐ! !Odl h%λb1[9gVp#\ TaͯhKZ1EN\^w oM(CaA^Hlf_]?}|/tz17CQ,FuF}hKR_.~ ^+8п3KJKAxXkձi3@p,7%u1j=3yЉz8( FR_Bik{ѺAaǬj6*+ou,<my];T_sf(y]@nBDl3ńsӶukaj!jO,>e)pK7q TK|NäVn3>1ݶ*2Dw)C*URxiD[13bH;WaT/0#_h$D@(%bGx1Ʉq>ewHFGG)=<[E]Zӎ~ߟ>aĥ?u&#bH6*V+{t('SXd= SVE5?AUL!WA:6e4ux e˜\" 4^(^L@4w=!o'&%(H&Ue5QDvUdqР\dWB*t# !j<}V Q~krQa((i9CZbpM %?w\mㆽGG!!)iEԳȇ}ОkIԪŴ2 UQ󱱳}n[ԕA#+@lIh!xC>K_GCDܠgE#H @ΚP V4b\`E84֢0?v-/@ qX|5X#Z`ܤ$ 7k#fڞU Uy)6"@6Q(, A@jRs)jV%bNcdDLf2ZĆ̕5 P6IP11EgFuuq\F{fta(HE 2)SIwAYݯX m/ismX4qDjLPH)Dh9f36looND,0px9.#Nz{ gTmf,An}x]tŶ+Q#$5ehNR{Ǭu_Icvo K]wg:cZr[K[4|jŶxݶRkt#|@qHz-a8۳fޣf]q :JPPWP9o il UF|م<]h8ܵ* SkjL!gLbdJpD1_823G+!%lpM/uzXs07vnwpD[IA4" j'QA|^ S{{Robf ` M [`F$mYa`FKfRӍWx2`!trUc2u2jc)_R(7&Bx~ir $+v&g'cob($e{v|\G3!B0oQ?/~4{bo1ڔG?9=@7..A056:Ź8Ou7AH灹 ӦH^! 92A-P,WD4{1*{ { eZiŹ׭ŌބQKC<{dOؗA#+J5E`$rbE;!or9`SEd +TnH%I g.͸oχ 6C2 ׌ˁ}h$<ۂ`X⽷μI}vN;Kt+9]4sSg 0 si̳!`qRl(Nq\3F[\'SajEgȥ9=1)dͯ<_6ރVݫS zc&i޴絗{V'9lo%3qznsjN+ҔQFA(CZnf3 y9B e5yL5BZbi[%2DޱD޶SQmR`k>.4@Lc 1f7Fvp! N)uꤟQВT~ %E)ɼy ,ٔ  J d) NѶzGMlӚ DD%@G)_OCmVrpAAϦngn(ztF4jilŚHR fhAj]xUWfQc1ܰ./zam^U[DU51C+K W5 E:j]eM*@; DM{V#ѣj*O&L=t< 4QY^2R.!+]ĸpr`+{vn( 8(#Dc#""u\5rXa`klpod7жLIBZ[md$Ti v$zRJ(6bLH$ ev[`k,2\rX(ceDPA ;veFbFjP{ d0HS& 8v,sJ9̢00D#Q@,۰꘤!g3JrDdmAvԀi\rbî'>I[M3u3q%#Ҽg5oIJY`ks2 Il "ha{udO9)҈ ӟ ޤ͘;[0զ4"" KfvS{ޡte|0Gl\WK;]4J{d@rfb}PH@Y@"p،a B)+> br}CI] i2O c߷>6bbA_x ̦?2kobIʄ:Z=$C#Cu;LDՏO.GoW{pE-:ebF,`ւb9-4b(鿻xQy^Qޕ+fSgF @W5$OB‘2٘<]|S=MFE1Ѩ.ΨPێ7MbvC}e64UDYHhX,&o=b*Hֺ" ]H2b8)K6,GPZ:.RL݄pdw4͜ŵU'r}^eJD )R ȂԣJ̰@^%E-9lô2jNI9 rxJ(õWEXPWPEQi `${~G1uaWX @ȻN[%I2 96F-b9A 1m**dؠL jJ}#AD`_uLDjL:Kl4Il\m0 4,4v \|`\\%5tĶ6)$BxU-Dpl)\NW1 >Z%@0Xg|Ϲ($ Ap(ő (c;Ɇ=H\CQeji6o">pAU} a!!t¡~5%L)d u]u,ֆOr 1jb#u܊Q(<j1a7[CgBL e2f ;q;+ @03,slƾ+kYP[md$A0 3M!S|eeaY0' F .Y&˦26e!G\AK 0m7&7KVcB"D\LDzw>el:g(@E9!|e#A}N} G-5NAZQ]; \sdKx^8}| DAn1{ Zۯ!}d`0Y$` P=VЕ*KV]h(Jlr!Pɚ @bCcUI2˂Ms6.mXl^ש:.ۊe fɡ,( )yJ3H09BTv9b8J`RISui[te.,p6 憳ƭ9l1U6ng2? R$\5(9U W4~7ʯLE&9y︅MW;qqa\Vv6ɫ BDbhAP&1=O'IGfK+҇ `i&]mpca7,8DSi4(I HfbĺV s[VPs] OdU䆑z-BiIy1Y9%=3{l-qt ok r|쓊6 ﴛ p _>7VȄQ` + 󻑋gb5 }o bdD!!;]0s;K 2zH{T6D+RX'Dq| =1!rx'r;O3N\WJ9z{d`*R!C4op5.,+'.4K(ߢc24<Ɍ׫j#DeZI` , KCVSD4 g4Xoh+g (!d#VB$Sp`³jV.k1QUbTF(+43- 啂JY,ů &P̡XPUA-i\k"b]SN֥JZZ,T˨B)ElV,TĤV,m*drֆ@QAlSWYMf<6W[+uo~qJPE`OaVXD#Ȋ恋+j1 // ArdrAeKHw1׼ÿ;>zNbmW|J>1:AD ")Ymwk((!:2D`i6eH,A`,`(EvGڼ||6$)H` ЏxE,Rgs\< r^R$ @`C$""5~ *h0CǞeGmfu׵Z / T+}:VqId)#a Aݨ7]4M@Du!3+k"H(,ΦđsfZ'`*B0}M:\Zr kD@'xAxݢ [x\XoFeCB,Ơc@1hPgiIKmL rE9wmv 6"oG1 Tw_=W#RDD)%{6EUT.#c>KeP)@UP*XV e@aI4GReK 0!4L 4S$AALM AuiyM{wR(X,1.EeiPР !àX@*LHI*u{1|[n{_]a<rH,2 rD8 K<k*]WG_owٿNA ":M|]\^\<Vy6 \::jNBI*k j!,-X\u*AרM v/\B`tAf{k}CA {]¢H`r`@ "bߵY"nn>LWN ˦AE: …:pNÍ@ Fa*+xwOS$(_hA Hƚ#!PMɻ4V(&z;h94[@J xQC=US II8k.}hhU2m|΋ĉK!G9nZ)^ uY.=UɧduWȘQ\+ZEVb@(DGN>RC(՞I"eQD N]/<76ǼE6m:%i&J$p= jte 67H^Ʒ^5kǎ\6 x~Ttfծu„.Gh(IE*qiK*b>8]L2@yZ0/uȝƑ/@M֔=C}J sK4uH,pjm!HzU/DBnHOިg3!``(`"p:zC tw`vveKlg>`@fA%Z'`!vB$DfPӦaOkbP/\?W̷WZt:;iVdZ_ӳ[*a';`+aMv֖m\~[ȑR{@Lmʼn[=g De½䩵jF<|ߐ9@ץ4p%CJ,Ebz4z(KSyfsY,O0ܢs#9.WzMZ!{ $5<* K Qɦmө\ jfD^Y|)ԣ8WLiCGTK؈[yXrߞFb~#UksvΫY J+W-u-ؖ.P 2K!80p9!R̩{ %P@l8h& J{C%d9eiLzCn*N/䫪j1 bو'ԐQ"4&HO7X_RfPV w[ 8/A*Kt^Õ]Fn]Ҭڶ!ԫJQeܧEoYow,z#hfAD4.p\t2)FΩC,z=^+]J)ؒJMP'R,)*܆ W&~y7`aYյ'fxHVXT);U3{mv,2f\Rf[c֌QPEO.cEb1U&NnYSZ]j;)JL$\[#p#9Kw-jnj na}PzuI'+1+PT';E΁3FOsz9TѠ4T8q9fV;8t>0V,@Cq%핪s$"CA AT&"^A$҂3x&WX 0*S5|Lʽ.F@ϐӠPd$VZo$mifF6D#rU/'ײX &o #)l9n쯃"GZݠ ːLP!QE- Ï{i4Ga 4!e.aBVCbBmIcGm6,i7GR(pa›M>7qdE4ܙ:X0O9{1Ԡޖd$\PRaPDx{9K;$RHThU2$$˳jb;bTgNNU"SY~{_!, l#kߦ>9=RFN& szHFtf/_ cY]sb(Y*͞cÍ~:9 Ύq VM'ֺǗPݔC)|&S Q}T3ˁ=tVܳf]tԵAXe^8>|}ЅT#MᎯ"C T:ftypظhջJo-FWNFFigMtmq[3cqP':I(TQSڦOylMjnqskX4Dݻ'ֹKup|vVu!(wm2]l5HPb~X޷xx:3Eġd"%U I|ǣiR4`r`st={Dz}slզ¢yw>}|u@wC[6s%ͽ޴" /c($zb.dqd,AWtaFY;;:ժ|:^6f.-!%8/ q"5ZW,P,@p6-(!,a&.C2+\ ,.w6.DA==' \.rŌF(Qݾ3PVx`I%"Ur4I6hG (#z=JȕItM~U*9 \ej#T1z˱~"=#1Z,2#a@Q3wN,=x˲x սQ '- Yv=;!˓D^N9TUYI6ޗ@՛r]m mԫ VrrDrC2eBzh G(dt2lֽl"|5P`3_B 2uOŦ c;G's}F u6]:= V v.RM\NDb搈 77P |D(hC󷴁D/ %PT]쁆I4ub6ec&G6fɭ$1 ]|̵߆$SҨ9|b)r!G/CX)qĀõi0[АVЋVǶx( 4faYoֺP|;N\l L=ٔ$]g 4PN4>y ]Bl%rL] (nؓ) mi@sri ]M.vCMvvXĈUۍ;2Y]C3ws d`Aj={0EBI c|e"A0 tDE ȬِX,d`߸eAwpHYGu #y77 X,Rm c?GuW3KbMwp1I$6$線f.x( b#.VMX`&f0fgl$&7<5*KWk0ś* *˫lUbola=W&4"2]ojib uHӑ^44!AC_Nd~mu?#LAІڻ#~|`La@xYTEXo֨ZũE7҃. @$_ͧ;` 9=(HWFd1!=Uqc Ni22HiM%C!hRiq!$`1/̔昄m^\AX/F K$C֖ ΗW!!U|39iksPdVh*vMY +rg'!.!&fIT=!!x,څ CSɳiAEbTg(Ç@Ê2bK  SE\xBq^с(F$jAt)$T0n-uȍjtP7"V֣9Ddԭ@>;ByZIGe'ˏbԱJYR.t >s)ˍFq6yݯI24MsҢi ]~ @ރ@ K$)؅R2H P9c rDlP=C"@j&$""cVA\8U^\@mo& 6mO,Hꭾ;l0@!:8b%(*VхP]q,V~;sl/l/]X3P ; V |E^"1aBID D(Tċ>lCa~0sX u(0,b<еRŧcȻp,MgFmUePbHfC :ѡݪu,C\!&c]^Y&[AlPjI@-5uɮ-fs^lY6myL.8V9]!=W 'Zv6)M)&,Sۑ!PyL]DI: IMW4èJcOW͓fOLBkΘ \$P-$^M E9͓8l4$]wh3շx4;3&'!W=DXejP!5H$٤P&Lyf4wjcU 'b L Kj>h nnT J -'vՉͦ%YYX~*SOM͝891;݁<} AF ܳ%jiyLTZPM"g  j:(5L1H*DWsnDBdX̕=3;r&DcJBIu, i4Y۹+Aǃ.)'&%r *_gĻm%[u򺘣虲hAqBileQX2\g!"#f9V!ނIE Ri ClSh%T8W}ܺFeًT4`@xQeva/06f&m\l" QM%6sW7Sumo{XAZfgl"h (G Mg V )TT`a)X2C% $EpgѨ^21:k T dCgsB H=E F3]z3udͮ+Uʖ%\Lb1`fpPb;ڋW} Dנ=iV֪={3v(G9VJF:CSRAERQM-Ja`dBarp 9|H#IJ&mTJF$͔Q=D# m//7݌4;1nF x*"Cd^}_^O]Cd/ F"f- bGk"D~Wd6uvF@9 ¢ǥ٦5l He,@2S]^'fk`i<6&em et`XX3HrR/d m4TTFcXcvJxP .5RPɰЕQ0VVܷ~±-9z~cgPFY㽣|,_v9{!2j/kv7wam1>=W~>ן3PTPܼqaeفBȤ m.4%Z02 h= ޚ2TDzmY6t 4$ A$ )eS fktsraL6.Ttݴu)J+3]r$")nMEgQl!brf{eDNiA!P5!P$>}\ O$P0LA$"d94ph*.db#P|:326b }^JDY)f34*@5OG;`uNޗaC=mjz)}) ;j-H /39&sMܑ7<\6r΂W,|D|qs%'gl$^_+s) IHk&AG1)t1scD]ҷ]J7NiA3s { @Z\H!\G2D$n7Zվ۬.phrH܁ i#1VՏZFUT3w.Mh2@l_/VAt%{$ҏK2Qlժaԓ(h2 ȋX6" a5%pQ3*K\rS\H!}"'|~be7)zrK][]Mip~ܒ{9B|x|/D!H|JmGxe+!BJ2CP726S:{h +CRI$cBTr ѽRpY tSH">X~^B2&AgKAbʂD`7P0/q$2FBΒ:1zSr- M*k z Z3uS o*=v!dq,~F!be.^nAc/4$&w/E!T`LWPj.ӈK) l%NDwx:"!v{3BkP#K{l6D`jY].bSATO<`[%9Qd(X9ʷY jցCAóDot.~Dϩ6r9Rв濣{#^,ؼ'OL ֐ #H6Cۖ_b=ֶJb"lp"GG6ޢ(b !RdSDA3TXwULk Mfy,4i^י3S0%7/ĿYMpr 't N{}| v(u!rb2N a ߞޜAYۚ?oѻY086SE"#2 V>|U ,uKMe0 m&0Lk0,dгoVPfJ4|DTxIP7.H38,j޻oA* kӓֲU>$7CwT8μ`N0ah^0QuX髸xnؕGg]E0__bD :$b T]a]A.8^u2F" @;M!RR1}2ELf+AbcF>F$IZ e>7* =a^to٣ńI̡nZFC x c _laV]t\Z'P1 @^^R8QHFP/#K;:Ҽܙ+6 㶩)s!!,v:Jqrb 'sV"rlllUB"VO-N!",aG@!W4 /F/ͥM;N/;eg v(bkjcuEv}}w"P"sf:2$ Q5"cAZ2rTfAL,I)0F\Ʃzc`Bbڷ>-ݯc"Ȧ GJqI`o`Gx`M c:.x5jZԵ7<)ZL^Ʈ:Z&ȃ@DE! BDYJtYNݛ9Yb -RDJ!7q MYVC#^4!0 uz\V(M)^䉶]ucON\Yay8ux$U%+dm>Њ`|Ԑ˔>GzK6rxS7XAz}j&-i !AVgtMi<$5lWC@p/N~^"]1 (#\r ( )SyNiC~9HU\vT aa@R ٖ@Q$QaIJn}I^IIĦ{̦HҐDz0pWv;YȸlC@0o {Eoy93,ZkQN dߟo\;"]"lʺBGd+k HJ4"Y"}f2)G[jה&f$iU^)ZK*CA.ickS| qLz zv/$!9} R؀³*\Ϥ@YŌ}dՌ_,۾U˫.blH(r,5qDЪpX30^_G]xXQ klv+V]vN-w˘b H %f`CwEU FrYgnxJCxP8mbk^&%)bf}D0! J9^ Q`N̜9Zp9CyKsj3D*jgjRt.P9OZ*BAp*8@[%rA[̲׫za/>]e2=%pˡj^EӮ"}Ud}5:Zޛz 2})~\a@Pcwrmǰwl\n<6z>f;AӄS&%lϲÎA f᱆Z$@%-ckMBXByVB j* a>o-,0[Z.G[ P :֤[4\\= XqZ`I@0iA E*P9 m$ᗏ 풬\,!mq1GdhĜLhbMV\-xgq،C,& dx*Dz0}T7p>ݽBBzfE(i/Bt(5pջ47& twvχ3'xKBbbpFZ1t N>9oT'7Qu1f!Wi|1VgN,MIiZ$,HC* S[bm̞ye[%'5B"=bB*RM rƁD jx+W,) <8$8b#T8y[swuOQӹ*voOUpe65M\ !41{=k4Ẑ,GppBmf:{tb4Eקzӑ_yo8Bq PQZ09]36o(+RKҭaeN| {ua-RM3/22qYw=KP8'O>?F0xH¨Bt_ *z`I؀5r}raX("uLH+OVZ&yp@͗訤L6nk 9D8&Me dSy-Axrc`b|<{j(u(W8(B*PCJ0Q% JvMtG}џ@!=>=rУz3g* w6ȕI+q@@@JTEK]l{EFKlNpd_RJ| o pAhF!$!ut@[17`A4vuj؁}G,;J'Mnv d^`Q@@X7}vkt_J[s66 Ӽz1bj8 $>;Aއjɉ?g4 Ij%s뫵޶`j~^,@呌'=Dv%tv5]ZoMMN< ;W~ln̴KjeޛI$|J$$p7 IsQ)K-Asu;ե8*Io|LO_ڶ56 Cł TN qnp,-u bEeu doSylB&īV*/aP8O@ȏ]Cr=RZWLҗ-=5|_ZFq% ($\v`RSF#}D @p4rk[omjJx+! kmdkI7/~kSQB厼\]W&@a$""F@=┄#DQl{w us@B@w-*[6M}bn u9vսTW.vIP'̃}2y*~ yaJ{3d%$@A()z*bF鎗೴@I. y0dc#x۟]hiZM744iZCABEhtI@+{{8AKpӃJ ifw'գ(zOdBoL 1kHV\ FXEH$Hlji#z1a  _KwsfON @Ĺ"HncI\EAG g}i(TD,)BȅsX* aM_WtZw[l6 =v>m'G$ѐ'-lJ?w#QDm#d{շϣ@m NxX8(XRtf "N)Cڋ@Ox*l[CbLm掜b *o^ОO+dFJv{^l( fB f5tAZgغ (}ԁV4Pie#CPjBd;(r"X\W&jvD}l۠ZIU[|?cLO0iMeZPҒ`1G)\@2PIHs561\(Vh M+9}OSy>:Rf輵)Cy7bg5Ʌt -Y^Tֺ́њ1"j6 xk2nTAEjk56BBC3 z׌T?iXWe]F)h5D G8ݎd*~KS* C*ږlܮ;:(2C2RۜL1(,X,WMY;cfװr%x, $)lG,BM":*D0(Z$[Y h!AsD;I/?laKBG j,Y*sÇHŇ[Ƅ¬Ys1bwX鿠b:T" MOT|/b9+B0|(}b3ɸ(c?!(݁]4C朆 #_u' )( !0nM[H"2uC$A׵RYfH"/T<]grރUΑ%"ɮ`b+)R:[Bvז> ]zuЂJ_]vv.SDx蛡y\ERD@w0r8( 3@{Xpdž3 4iMdղSшZL!N y\ַ=ߋ]n >%6ؓI4ہe>IUѰW%;H@--%oqBƽB \^,~G]\בgz (S2w樒̂srGU?`(16(֐r~Yؕ n'L5}OIh3'SO= C88rJH[[<MZd $-&%#X\jfwPIc,p [&!@ LI*N;h,^2);UY'&'-&dP<l'u.aчP},XN(=MMY&O3!^Z}[$,Y){4 dC9! U ?Lt ؆ zLr@B7C MWѩ!myot,v Q҆@ A! Z{*~/'Ou@nb54H{B|bO'XN'ضys|1e h*Bi y7@>9V$.HlH9d@P|f@$@C$?> zhC@ :HHI!lD 0!> EH@g4%$%4"` yH|!4 HHpB@%aVLJOʤ i XTU%B"@Ra! Cd=Tǂ@IP$Hs@t`"ae-2 DL( ИFbr.>q#8b;'$U `iY˙ձl+p XSRܦMh}QGF땶Nª"3nj*I )1Z1XS0PG5?P@Z3ϯ6G4AA`f pDF+CIihA;b$dy `p)OR~m?T9>/#a~Q36~"ãIݬ:Xma|f]YWU=K`x$ƯS[eyCgEvZOP fǏRyrmS<16 ŌZ!zVO[;[~lŨmS E"E(,X,UI$U&̜XX"G _G1-$ʮ;uU`ZF@:BrN`W-$ H ??MwF/<{]n\|X|`Seәɶs ’bn!}=[IˑY:8i$4.6it/sOy5v5;u91iʍ D s!SB ^Iӓ$%w] w_/$ݼ/a;/+bBZ5{tm{Cmٻ%w'VH x=(*PH@ BONpovQlWr םvc${}E>qZAY>G|ūvNK vF]K3KފK+?:7̮^-|mZҐlB@Qɿ=1@!a3SPfY'R{z/GÇ6[rHȴ I >k7u%uIH5MGwſw{ I$pЀ lE}|=m(H gs_w%ZI%-_I8=+Y IgO[[IǮ=A!93~WP$%~/P ml{9v~+d$Wmosz|$s;Z8TH[K3w~y*}W/S/B基ĒG4}bP ?7]n{oW i/{Mm <@{6@< ^zlHB.ax_彦:?sewj t 6<w @1$_ .ysjn[qb@F%ПQ`"!/ĄF(hBB_Ѯ$C`#4|iT ?Wq}ױojG,ޛ +Gީ0@z6~?KPjb@徖v?fI#X'{,A@hOڣ:6y |vѥ$ ]|nf[I$$$9v~MSgͨKi߹='s!- .c`$$׫3+pG蘁HB/wq$v/M>_5BAD!$a~%ǴUHHqP<=VqWy:$!{z u! Ac $_474_{|]_Q0K?@1u$mptR}i|_iA{8;d/HI-a~_ŭB/w0{޲Z$l91.3Xl_;;F;[ԂAB?#{_BJLB4u;$x&^ҝ]"g~M\ѧy=r4Z Z!}i*Cդ0 O_@xLH1;~?X/!ZC`Z.S|lJAmLKRA޿'t"ٷƕ`!GgG'ȴ/!4h޿5=&_hAO?D,{?|uhI>>-/]&_gV,{s\0Hpۿf@VòWE_@9Ky@ }T#PkQo9B([3*HA˳iw{E<^ä/T^J$ W`>|cWk=2I{+w](~Jfs}5 qt6.g$>sdNݘ ÍsSv<@50iXidK9̾_@ %(广04Y;H ʟdNBj:X!S䔒8O#h,$ gp"2nAw4C\$sF!|sG[KVWk]GtБ/QJb7z+:^)A/wkN}Ϗ/xg4yfS Aނn\&ilF DH$)tOg¥gXX~~kJ_7쐀IB9a7{8Nq:sS& "F82}.8dmΧݵU@1 ugp5?Â:P"M>iBUc|-k?mA0KѿNU/#` a֠;I@8> 2w\ ŭ3#"$v73nw=~ya)}}d-~ ,}8(۔ Xh 度,A;G'Hq6mj;{Lz W]E(5D@NB$zFh`:#|=ߪg.ʌv= |GU%'HBqH"++Ec݈c[@{jqާID%ĭau,rs[XtEVT  ;ו0Q&L@XQOsJT؁DDQDDDJ!J52}^.䢃+QFb؅aT^["?CMwc{\,Pd1謞Ui 1Qo0>K{^kE O rSפ;OЪI}mqSKKy%s¥[ծyht2"P`[n@ cw't,`M@@ t+Of [ {ga'`kfa@ TIqD6VN\Tq{d?2d+[ފ8)E&Аd 7)p2M"J;\wR[Ԏg}>j"3uUr 5MwAUa'Ĕ B^ȫA HBdHB* AVJN afr\mAI ?Er pXFxUPZ EF\(f':ԙLRxR@#lVdG̵($+T7!Z%c a * 3,1 pO7Zæa_&/:o^$B}ƻݛ ,]غpL26g0Tq|Es^IʿbV͇xs +Z j` )`^gadxզ=lއ y2# T%!!]֛9Q<$#VY}=3,I|T2& H*xByd ɲ/a^f,^jow5RR9`#pndAJzTkƪI>db_3uCgS9.v)Mэ1Οw ɵi|2]x,=O_8gxQ6w%$߳S8vC&TaWĿ1mI$c{6vNQ&$MQ [>&{ϝJ2FWK[Еo;k혋xNaZȘ͉76xT!f*t'-3%҆miro-ϔW} AuM -iѩzFHP{z@Bd;:^Zw*Ť2DC$`y\FfYz˘kx*}gӵj%ヂ$wԴY΄krPI6A@]m}VxP?0G?Ό>_r_ji:k5QfJ˲Lar%+'~cvDBF72]2Eiy ϓq?o'C!gSYW!^‰g.%J=)\KHld[Vſ@af6LRB23m#&oqӲM%{d>Ů w,H,J$q db_q  V#,bru?S'$玊6W?Nwz A A , ;,LS$)'ޥݏ3 ́±d-F!G%q92PdoZ htؽ&ܗ ΍$)1*/5u9WoT]ѩH41Dd;RNlElMs$a ֒@HBpd'؁F7I $ NԚ0 &(g !dZ'rIPNL1;XC ,ـu0lz$@1@ԑaɮ2E*8Ҥ7:C${dCCI$.Vcab  BHM!'$$RjmM^{{z.*c48:2SEȮѫ)Qe97GE`fHm!$+$BBzL{$ĐѪܷQ{sI'F(Q>'~>BBvP;|ڛ>GP!$2@R HBC ̒>?bܧ?I>R՛m$>c?努]bIMvQ0b@k(AH`V(y_3$ 8$*ɻ4 `BdmsI {ouIR@" >O&N},;!&p)YH@%HBBCH]Y&avT1 ~9 ;Y8=HI!2Murg1lț9q'g]I7`I8fu ܦ C\mqtk$@*VlY  @f4Sde痒\^ΰhĬiIH JC HB3hA $@$Pxb @p$KˉY$彚OPCy8,2U'[ؐ&!:mg 7kc$^Ibsaؑgk6qcR,$'h^.Ǐ]9qHIlc$c4IrdUA[/hE}BJzڛ/[՘1 6N@:0=x&eU4&*cUd<1N (B!.$E\]̜lҿQ4%C)\:8}sWF,h3G$wB:  JczH1N 02D 6I 0ܵy3EɄHEP4(݅vK(Ma@^HfWyxTƈ6HP@1(l ΁+(^ςӊؓIW~ ~V 2Q2nekv4dcc>3~g 5zv D/1Gͅ,c`pf ڟ۔^v ? ejGQ#95ACNm1!Gh6$({& B!8XpiM1g `aCK_Pacfc%~Ff\$xjr,6vq5J1@Zǥ϶!l>F~GRr~~gGgE8Li$ $4 Cd LP Th, BxRI1) @HBSmj ĈxO-Og">U{<|_%GϲAd<+ &֢!R' xH&E#fݢQLh,S~frm*1)j4\A E}1|'[S.4@?{bT&6^ege |PZB{ Dq`Ku6!7{ទАX2exRI߱ve")>Ruh 8zQIơ/ZG&ܥy_ N} %̭v\w$3$/.8Gq^YyyUCtٟ9wغlzRšnJk&w5Se5W yTpd_bYjZҶ Q\6R1xזqNLư .bQB{V2HU+ʇ +RMf8.iNm|($o^ύ\[ZkLxʳIltghWqO>N˘[A .[x5A~&%cc٠SojRdA %d+$_HnOۍ6bFK._nθQjΑ鎙j¼X9ة7qmªTTt2O)D@,n^|hZ[EDD4(w߈X؄7d<7muB,$JMڟ0^)W$?&WH ~AUqlmU&u saDG=|Oc/t9DMeAhaf᭖萇?x$1x%U̬u-HB@:b#,~*1lj|Ud$@Uy18S.a =RI OU@ӲP&H~v&\KhĒI#i$##HI$u4e 4H`@z@l7B!2, Ƅ92A$ׯݒLB2,B.i!F+6O`x/A [*dVcM 5|҇):8y]SOϻj1pۯ4Q\)Y䋊Y !ȝVdE5 z—2Dsf:$"ӋUҊdyJ^󮜳Eێl]/:wک~r(Vsл[Yܮf f쁸 t}( `hp+"%#F("_SbI8ðk5C;%2އh-Aݙ)CcpCl#U˵q̛#dMSqv:z2SX^qd*dxen˕[vUbI;F^XT0l g};WM-e$)+ ֺ=Og-Cqޯ*Bٷ,\9.<LuL4 /qQ9{>=ޝ+f%{twd4[_;쎸-0 'hu3H]Ą44&ɐI! 7k `ӰX1+_ifWUNZh|&kۮ,>9N()YPT\9pb$ך!mh7ޅ3Ї#C.py5M$= @8[G yg䔏@4a'.4VBHb@^y`c !YRv0 {I28Rz Hc'ʒ@%dC;Nl-V!XۮkNUjЛUJrOU l!IST8*7 m]}r:K)!c8ǚ?w>t~Os$1XFs-;ĀL8̣ )%բϐ۝}G->׈  ԝg_q *½8 !AMS2cAaKcW5M5VU>~qT1gZypfDϼV3_JyakoׇZp&b q@kD+8PzyCuG^N]ש=vuS[IZez]y ۡOT:\z\B)V]7}?3JO6/k;TVwlSr8R,uW[6?#s\ _è]Yޏ/&"M8 Ul|/>r|X19O"w D^?_-C;&I z@G)u jq xD)-I`tJ'1jƌ 1y הacYY8rö ITn -JJh@K)%H?6R$mg6=:*Ex/VYK m1OWB4ktQz/ە$Ph8O7@¯&bn^@ | 6q:եiNoz|<z ipHB?еJ$ ;Z=h6\G(Lp3ʁ%h&(ժ[6:5Mj_l:6u6#A`tl昌AEZ(Yi}\`9__2=LAQj0;_]ڭ>`4cYSΜ}AE1*VS1.yjY/ݢ"䨓"v\Q(P$$WXxy ;_Vہ~JZsQ]I6K?J%s)Z;VۥbBНOq.sOPv{]-##M7_co\K_-k QF41X+ؓ67S4}X _ =8a*qvVml+?>f9v]3lӋkg] \ݗ?f)^S&cR Vsx|==8p62D>̯rٿ^86֜OΊ^\nG]$)亗{+? }bAE6l')w!{U09qmg1_}ͺG\k`+qxGV+rfI|YnlGтHL|)D/Nکgw=SUՔEE"~O_>,R/;aF}q M-"cGzF@(9@Ʀ:$`HQGH|Ǻ40%O&. cXDPEؿ#'">Uj"3t/CϺZoqwxbCa o,7"徐gd)!?>N (1 R05]&tԂ<1rYQhB>&y-](;ls r n~jOk26]w޳UJ5u5ym@٬S^{~~ӫƺz>bV@򊵒sՈ!iH`0L!"!KPy!zi 8(XWlMJ׍'8 I'?$/*6w4Y~E7lgm༞86T]Bm*wy)lx!*05 ۀ…@= dmm?}-tw@z B4|@Ҵ.4H΋kܧkEy_31v"=P1&J,P@'^٠"N ܛ@.7EհL>,2 W@ n ?6ٓ#]܏M@DLV;,BT# k3AI6&HjZAd @oMEn+b(hi69lT_1~R;h>TC`U V$.t {A82(%\`-Hwmw`_R:wx&SGҫ0cbyܗS8ְf :=F u*(gEt͙SgIM?`N Y&(m^|4V"K8D,~吘D_u֭^.,y,vCxa9W߳^K~Vu&K7)JWz '@ۮK7To~x6xsc*-$NUjOun2r͆\jro=햎Ǯr9Y̵OYK{<]Rp0VioMd ySy:w6bb mW.njq߬u8ڟK^˿Gt.])f#r%;ϟQn.ޮvmZ;L&75E5tryS`u?{F|WQυ^9ZJe֯ɷX; ֧`fٸ'#w1'n?2UV^}gOQ?6@@n_O$}O=Ƕ.y3K5!uб/Z~k>N7ӂ9^C10rշ0_}*YPb-. $%Gl*;?_ۀ}>C\"Z[sZ.U{O?[>2tkⷣUx^,6'}Zz ful\RS"}CB+vnk[lgl5Eڬ'kM਻"CE1c 3OG?Ǟ/I!ʌKtV)ug1oj{.Q.^.B8 GM\@5kz?\^H#10JXv[rO}>b+႙8g'$Hn\cZ(qڅp}W Z W e=u-s6_]FOPoynB/On+uouR 'xke*m+K*M{-UI]w].ދGGrP0Ww|wg.Y n O׾9x法~*~_oW~u5%,.;9^깏Xy5XwA!ٶEg6u,Gm_ Skl`|uCi^RDz\Y}zSK{~$Ck=?޶0GbZ!o\@Xb$U(" PFALOAX+(1Ͱb.">KX] ]cU:C w᭲L|2AaRXJOI ٯLyiL7vEuL-0)~rXaDO3tƱR,Q "@z pcR "LQLP(Mn6|5rzyިmR܇h3>zdl`}?įkĆ?7tcכ>:G'Zհ߿MN_^|qӻM&3{['w'?g`Yir?&yk'Zy0_mU1W}g rA5w*(C?Z~ŨLI=!)w!?vM7@d2$jXd 2M! ("@ 'kc$<&?IF;@kdQ Od ${Hb@?.c$aז?B P8 C9JP/+WiWڶB|( >/e]TP[טY '"'~PW{1 HBm-.u\73aiJ YJm 9"uBݴ ۸d^^]_!gPq,ʧL4uPB,J5BfL-Jp8 #YYYx5ױ"W@2ܻ?>nۛ~[皟pw/SP`$?g-?ݕvn~͗n+3~ݷ*sDz^EW|0ۗXaƀ |Ōe|/̛cksi"]8y'R۸mkYW_I p+5j}%n!̷*\ik\3[-P>Y(ۙH YH@ kwd϶˖wk^ IƲ 7MX:;eڲͶ-{e]ﲿB",v$UUjiyS߃C[Ҫ,U?Fw-hx&@~Y?BLdx i-cE #޳c0^!ɃIb* leSCg9 Sq$>j4S;6*};Q|/`2 Zm˦U^>UO{@rOY zWwpvWrU|%nt1s*v,F{uݽ+1Ne2yX{oڒUkD!r* IfI>R"~jVxʪ$'I$ X, tIRHIHIA@@11B(NхdH}8   2I+$*;Oذ HRI $)A_^ ͯ8YB閮#~iDYT&%ру_d7 RY2_ z*J.x ~@&WdK*TE%,r)J4Pe q˰'C`N η`W\yx:7%чkbJMX"( @DXPIx>[C;GwrֹJP CK k7[]8e }8H|EL_ } }0)&{npKs* 6'y}[U~Scɏz nQrڶ+u$wx&G!_QתPJLCRܷ?5r 9ÄIBWE^ҏʦ9{vBզ >9a*=vUYR*UTU(*A"EUdUb(UPDAA *R,Hő@Q`b UVUUEX*",UgͥV#E"Bް&V] GaR*?d*1-PEEH8I@9i!PIcW<*LP*Rq"G9UyIHW٧͔%) /#gveRe0}+.:w2 @{&'r>Ѐ4rb˷@)K)A8w6q7Rˇai*k Ɨ& 6DrHEz[Hm +驏Z;ǰXS#Av(W` \w'&ф4򩳾ܽgO;zع'3iGòzy br@Y^2益t棸[Fjݳ{5Lss2gJZB6onY0L}b " @IhO;6_gД^M M}.bH!  @"**1EFAcd",THR(*0*H(YX ,X"P X"@PH1`*1H"2+$AA@P (,Qхlϙ>&<Iv;|( @R4=}_Ƽ,sxOS Xhm61 DBkpP "9oɅ)\NbM_0Aalr;[k70d'y7 跨 j×WoG&>zJƮeygUjxFw^U*?נ:~[sU  !rc5S50>PKYfۥ!D!5ٴ@<(CRA !¾fX­)J>v+.eNEmMZwhFڽ4g̰~Nv rZGͼ;ꀈRҥ;s{ UKx7\_| ;p0 J={!gfz12ۉe.)*=(;U"9fA!ĒsyUGm=>ilbJg&VDl&`8L;-ɛCu[нyF+ g_&އ}v3_vs=-u8l[5Onu z? m=؈Kq.jKw4ly]PeJe볎a">?aO"C4^.DO^snTb+9,#!)O_4Jme/^xstG􇯝}>GN<'0|_^L, a1B<". Ư*`Wg;:q5`ÏO.5\RMxShLm]rw*x#Xc?Gke΀QYА70ЀnI!YjY #*ϳ'ڨ燵O8a nWCκE z{\QЎ{zm{bK#Зo|(P-""1*Ȯ@j4ްT dyL)DNBZ5[U8ؖMLܐL{CDP3{ՓZfe{um2/*[j4P͆'=iV}t;]Faځ#"g("V#nzY=t$!Qb:<X/%f dMh5G7ڗEY2Yʠ^!" ȀLP &/["9bLf6sc_f+֩겻薦g_iyZ`{#~!KTmuxt> l`ުaQ[&Jld;;{L^Č'KޅNcg͋5C/So EUj RCΛ"GYzkZw4􌶲m+TV- OљyyHm `_detZ;&}G*3,clm(Ռ3caJHllbK*$e^A2*0kcMìG˾F T%2#@BI+C{U#lzs1iS<(8na\Ĥ|tHR[ %?=.'e[鼡ѱn`AN@Db\sBʕ.0^PCe0VީSkZJGSAM7q\$ 4FhqޗVà`gelp~]`PS |Sסc$5/Fj$dS?:\P\D=2у}[͝ʴO(9& 7{]=&$"cDz~~/q?{Cr:e\qBy7IǏm |(XOX_iBqnB`%l2#B1,$\\ 4J{Y{5s/쐊>\J1wTHrPޕjd*;rAS<u܃i$ySJa˪9qxF9zM2c:⹌p_%[ÏTbp}fP+f9e "coE3cc6G27\9/$>$ά 8vnwGYl)?#b,^%vP}FXu|+_򾧬șT܃K{J?N&i3D$wDH7_ Sj.>(8~4ge3yd+R=n+P%1HW<]gHL=dսݲ78ǹXWեۙ\"X6h~SYd,8 EO' |Q{r;T1ں: Ai)bY,,$.9Ġl@SOSߴI=~Dp Taol֙c+eDfhd*J_TyAϣ;1&WܹviL2l?@)6@?@O$I F/F/ڼ2 p@oln7%V֜g/Yq_~swPGgc =˹w!ft[ў}m/r)"t}nzW3T!>W>Th\i_BCe`#E g{m7VS'Zp H'}f(ˡx)M;w/k.poK|l򤁊W NI&4IB67>}{.,Z{ K,NDzˈ&n]=2F%/[qϿ68$ìQP4*D*j1CYU)6Ŕ̙RWЯ*]NbNtjy\{&}nNEEtBXB-HtZe,̄;);sk/͙+C>PW_f.*X^ç  48DzIEϓ,语06 HaW\NxQKρ@8(rԹ.g{v'cEV6eVyl,lI\M;=G*S3?P_yM33/6@xwU"h+U@Pی4a<&qlr)4kPҙT|7`e3Tۙ {~]ڠ V ќSz'(odu4Mvl,Kq_`<Jz̬4(]6K{/S_4.l[svn&e8hFSMGy&EdE*/*f ШD%7sEiD~W_Djp˟ټ}kl\͏lDEUF" $zGg#Zwl'$!aÒxߣK9383(zرlH>y}i1HE(rE!S3?hS!2Oփ)z6h]-Ù=e)wQǂGlx߇B4xw.RܖHdtO;$jz+NdhLtـR" b?}c0?cn?@/t~ky!բyej55,rH+#\RbTgjD=A2|-4`_t8:>o -rsN༼J_@ak{q safzs2y-u1-u6~mJkBrz數f[2^|,co&XpOr\*YUv$nƿu:ߎ!m~{-ۦC~3ýin۔ajeː@P S4٠dD xIOuI1%^(LA v}Y " ֝-Nt@Њ?sd?Y.ؒ_a2UE[]ͭKlmҦ̓J䎞m+uu9^-/ߣfމq{McI 7?wđժI$/8߀);hmD.YqjěB0?TONl }~!hTl_ajCt<.2c$#$xi?6'$9 >sa$B`Cm0=ZHB<:O(4vߕ&#kP<E"@EAt#i(ې0n')jЀ/_fnoN|CͳY~A4 9@y,Mt9ݗΟbuP^>FJs%{W7bS+Ԏ5=k0 EпMX B"[鋒M_iqU0[֝b_*oPitO9-{X$2L>"hk2,}Lj @DB+Y9M)l a9]bqXZAdf`Ld%N&r2'ճԊy` e=&WF?H,)Uwwϭyi:3VS ,,9@uN1ˁ Ν*Q.eߟxo5:(~2Oaz;0},JE:\xدaGw?hsYܥɳ̬9zXs܁9 ,#HdNMae$Hv 3!VHC j3p4\71dZcNUK~T\ #ه&-NC!I6߳ B+)}Uso0@ ^b.TXp%x ^=` ͋(ޏt'a0z؀׳  I>ו٦ڐe,4Xi$~RdDcJz]$͓ਏV:tz BT &V{y.E۳h3/I*1ۥ1_${<Y(3 x;q1J0 O2C`Ԍ# '5zq$,'A.H\ N:ͽ 11гFd!6Mnf3޽ oP Dþ Jw@b\$>cRfqvpN'xd)FhacONoO\^ /1thmf|8Ce հӅg)[cNTVG'vݲjpJqm:Wk4st_ﯦ>REbcc![z(3P[}1a٧h)jG]O4RbQWJ :MMfS@Zmm# ;i=s|KTCzQЁԷ<(#Q!= N:d߿Eb6R{#ϯE|%75+nj |C (oF̿W݊MW6?`^"\Wn\MsSF\YEDjQ/ս@ R)RlJ ִ#i 0b 4b+jઞ ]`)UHdI#b8u |5| *+8t~F;b@6ocqHPa0:]3LA眮܁m5zR4$"ZR@P)4!h,wx(g)<G凴sԱMg%U@` hw"{Mor2ISb@L]RZ 1W 3V^`]& k}'νRz0|^uyz=o 8]$x7 |^?ƜaGl#H=y[9bam榰|;\y& x`01 J#g 1:NJ/}7sKӧW[1YU PRͳB_+Dh0Qw/vT,hl )oiNb Z@04(DB`#@86 ѭwx:%AF;2ONm~TATO}Þ1j=_:& _ZbQ1M^R{cc(1zA_PW+'[ҒȚViEF0mhAgkcg.+1 ` ߇-హwNJ"ױa23:4DGM[L`MCA!)#nЭ\wSe֢/m'Nq<#?^%ZA_jv]ͼk61 vyӴ\|z6ѼT@K3 [u/&*]?1g'я_q{nzoqE?E9 pQB>^)W@ A%X49ٮr!'8l)CFw5/&}hHvs.XBbQҥKfLsdWUhE@ݤ,ve;6c6ݎ 1a$'+ɛ<hB'  &!%b8bv$9 HB~At[/,˙N-ߧ^ c)TM+I}Md޲I|z l$T6hۺ/{SW"QHPcRK0x!Fg8į7 8chFL"T%Cgu|_mp;|2D,j=; j'jY~ec̪s]T3߻!!mwۈ!<Ö=!BfM@z8NE# rlCJqr;7wm~#*/\K'"獩5<ފCǹ hS:î+-MSy&:N̟/붳m=W} o @\IbgP,&tؠڑrxI-o"U1I,6BU}XHP ޕ2fyB &Qy>`]iTl7W"6%>p̠8')iʊ0mN\T0rۆY "40GWGPwKii.]@$<׫;fԚIMˠ %V5 9%k% vo(DDE'hChyH `;Y2=5+܆if&x\j/ux'f"?ƽ ؏ w Ub99^QxX*({{ydܠ^'9GgReASnljtk[F//hI_uy| _3Q>ƕܡY&&փ$.[C1@DcnIq찛'ࠕ/*S}GXq5[O//IQ`09~"!M@9~pݳ砓^t+y-+XNǽz;"BJ&$E$>پJd!Yy?d i$ @r}$PM$ ^wl,XI$n6K2D ${U\eGh ԋޣd`o?5MbÝeQa+ #-Ns G;}*H`P)Ax A@@=XKa&q$B&D!'ް $PdˠgV~ + BE$fB@"@!HIx:2C@"H $"aNmQ;&a^Sa-}eYX% /dF@l+ g]L'׌nJwa_" N:Je/tat"pGjW͚7t$%sELк`PĬv` 7*.K(;B(q 1op8u6b[p9G_{pԓ3h\u_ؓg,6y+_KwLFc~ijU\`Ѽ˱k5Wi~.e,;:qh@:cJU[6gޏ.5%8#>@̄XJ: tHaF >΅$Ree+e B81DluGG9#WTi/ &sN['x}g/^0Y3 Re CI*xY3;RHk x=G簫.rCYIWsd M Cy<pF#!YTAI$1W!ѦL˫YNB:FTr/jIM[[ YV~f^!ZBdj F%oyb㗗)9"'9h©m&Я3:1yedl=Wà;mY`]{IF=]ETsAӁ>4-_>4hBIQx2`OSV.l1_-)^\%""y"7j_9Y0x%@)V4djF(װWk@2,zwzvx7}h-t!Ni1)[K,82vwK!MFf]7 }B2$IB{E`H$Է?G2^ꥺ_^KIղ{4yx'eHA#ş>Z[ >KSfu)9f|Ad:؊f+Giя~;"Xq-ߠڸ@Ig0@aBމH¶~gܟ1ܦF!gC e.KcgCGpXzV.?9|"o.]̏AV)GJ3-A% Y_qvG]j$\f6GV Ğm;4bkCTnzq_A#_KUGGБ4ZkT{IVY%4E yJ1,0ȍƿ1Lc>[}cpF1~0nu`߿ݎ^HBDʏ4²m"vɔvɛR]zkzO\agӅKCG+C':V$tJb,b'w\%5>#+l<  S!O8 㰓 L 7 f8IyF2Hvb)SQIy, Z߼ͫ/i/ݖc`:x"Yiy cVxNLU#oY&;>v!kuj͌+&7,~iYvA3_$Ҩ?uTYƤzq?y3[|F*\~|%>&aExl>B! '& $?2+$%d @|V$/|ßi$vl@#% Bsd Oz'B@!O$!&0$HW(&1CkufH>}Ng)gp͜|@60Y܃q<oq܅c`@! I T2 I B@H(E"j@FI$O2%`!ylPL Sѝm}{D4 aKo9J ~SGv6Ɯ`5UjpSa'M,R ) $ jEez̸\U(6nQ1,ىDءvۂ|hz2WLf_Pu '̵D )U+ilJ_tbsMw(XH2@"A@ !e6*dzPG ؜K 57 u ˀg-k < B1-I6ϻfΞB7D:ie0P_edmV+Ry[p ֊JK~;dE2P,P I*Br6є Td&c* 1C,q0ȱ45'lQ#x܌9\4EP<B!K[K$uM)IW?S[1k2⭫=蚄d6x f\  >iOdPyc,wЋŵg<ƹ`cB@޽aq&eoBNO ֪P寿"z ˊH:/oGh0afP2?:s!1]ؠvIA5W.V(Ag%5nLĈz'䐯 OoK qP&iBq^8~( ͥBcƠB2aÎYݳ8D5=,ʍ F*ͳ<>-Tg]hDNL1wܓc_[N$jc,"]V0XrKcvU!=3jԵ@F>Uc"ˬ񒂵Dl*H`CTjр#kIH.kݽ:%ՈɱAUrACYGRTy5䆀JKB]3Rd(˝l06˷ϡf(UId.~QyeDB&-QȨ 5Sg)%́(@"6Ғl*΅:hv:歸-*٨QVA AbD(Z,"!TH"v`x_||?Чdt4݉[VC-V. ׂJ_GZՅj}I` x%X"~4 ,Ȏt)O @='1FQ~C[`T 2՞}*Zp :+)yh)`#<2q:zh1gF,.,(Hd !ɠ*QFӸ\&X0؉t,o|D{U qx| @ a bOg?Zzlq\RӮPɬ4N8^mjAba!R4̥!%1DH&Jq%YstCf6ă%Gq(蛇>hN#@Xmh^,x$qSin8bϦNkaZ*f[ H4*K[;D2\,+R򕻇mbA Wx8V)Bq8Ms5Qm$idO^p{5D#@mvҷ ˜gIFm҃`]iY cXJRr"FySM _= <8jiV\ĄC~$)Cl jX`*122)Tlz+ww=#5\Kd -Q/tX/ $jUvh ^^u}x-ׅ]hCbڞwupw"HJ39sYh'JP" 8vS?,˲(q<6+ڲ0(6;A}SZDv@AB68"`Y a1tFlʇ{]2|MœwSZzP sA}uxu mpy]PbcHsf/`")ȉ8=.d6uo_e$@rDJP2贻OIZW2㊘E~õjhlB)/we4 ܙuR(KvrVXo2[DhSM.Oa2NadHjPNI4(DgFdሁ+WREP?￷N}OyV(QFC-czfxXrMq B)v b(-tYcbEB$3:Ga÷B; yk#q Qd@G }i@}ҬXJ)ygdՆ ˎ>Is|}\|F߉ӎ/# ]rk.6܁CBx NFwY%~p˽<_qURj?tXT!UYCwD.r-dO{oޫpl !p&?k2HW6pHx*CLM7xlEfv0'-)%6[)RCBψ rbft+aaew!abeU=QffYZf=1 Eg]1$XDH(,qڴThՍ"'.cthu!6R,p\J$}#Q-|"{6YT )TδR">mYNtV50@<w'WE LL k]h,7ĺ EbJQޥbS BUU\D eW!^ͮ)xFi zTvB1dzlLnpPp{ N1GE:]yr_es3 Ă "NfTnK+"> .WަHavlk1)p$&aclyJ6`LqDJ^ݕkV[geksdzifL[oiX ͥ],*uH4r¼IG"E}tB= loRp`^&73@坂ɖ\;, L> W9eJDx+$= ,4dA(12Ha /0d+!8&a4OBdq~˜A%ʩ;ޥS]6GAN 5ޜ-Q^Dwx']&,ɼ{ ep2{ȡ8UCl&Fs4tf\r3^ 89l1xwpRz|$%xi&B pCv?>"k)pCդ{z"#MRS\47 `P0CHG<1WgH$v*8{@#; t!C#0g65hf+s5-|%&*RٰPڢ\Fl+ZǨR~\2`eԟOOj[%=&x7 2a0QKj”fmKOsڴ5r=>go99$K)Yl6v/˵`9j(Cj(ʺhGF\θ !|Q\72=kv-//Dfz(Py !鞫CLcl;mC0G uۗ\==8lI0$m:|SJbBQ~( _$T*Fn[y'3%oxW?SԵ<xWA&mi?O=>n&ϟЂH蠼]=9-nipI{l0c){24Go19U3rR?&GʎD0g6Xǒ/1,Ghmj3Ԯ`;G&j kCbӭ7K#rHDpkn˅u̲0|6&{J`V5KH Ӑ'P~~K9"OXU^ 8y\.\ h.\5Seh0D%;$wXҠzev;XHoEqɭb8.,JzSUaPeLYւ]ZHe!"M> /I-4i-| :8U ,0} R=/OOsW*y33#΢=}K ~׏9H7'p[ɖyG ldܺ"monյnY5zM__5{V4JԔޑA ɰ/z2nu[d6 ^T@ 7iN2U(XGA%-$4,ptl*t"ٕ>Ck+XmU x:Yr3J )(,\ 0fJkQ[Pelbb' f5ݝ#ýC˸)Ewee ×_%}ҹ/ofo׆FUеg@PЭ854,04p!M zS9NP0 _\|Ɓ K;}o'+PN?(=b+%~iNy7)@REIF" \.tHT&J @`mʮHRdJ4.9Sy&XM8],N n BC;P }["2F . ks ݉Ovo5ÞhO.H S'i0!߽,V;%/NT7w ʠȲ3@v~FdeN`~Eˎuľ9P ]=7zQ\?ШI{% RTRi]8;pZΈøS4Kj[֙N舐WLpH؊gnulchHf3"&KD2u@ӊ; p]^tov,HB$ X=1/Y Iw03cndډU^J-_C ]{vElS4/2]&%@/x(Huvʕ/Kѻ."V[{xۖLzf"Y'5]IXч@'QZz]F)"Es3O$Jd9ĠڃDtEo:ifiQY|{7rC~:pjbƴ4|16_+ ԡCJQ^WG蒓! f6Lu y;-ATH0A)Sus>V2E"!MQtc`эڪml,7kgZ5+:F85Pߏ SC T)᝗ґ=L1q̙]c/#aE&y'Ad/LZbfFIQIfOmr<7 3c) : u -w2n_K ` 30Jj0^ugjŁ#jPU>jfWL7/~z1 AB Y\jj2Ӑߞ 3@ia'9ۻDNbJ+Z 2|]/YfL2P9UDPis꾧2`f*?J*b\@jMuWx`NKي@N *~txqGxT l喨x)Nc–boa*|z.%IX1`0OwQt}af\5ˑP }u࿖\bCb{uM2++UfDQ^gg.<оa[~IB\("8'hD]ZmSyA)#j` kPhAq "[̜:"4x Ɗw]} ?)]m> %w 3[sOq:<&o>}fR3d$-rHzE(,ڗdy)shDmC! iɱM򞢿=Gɐjr ߇KX}j%'Ys,dMC)̒)!a,*@, E!ҽ0LZ['L") +|_y  xYOjP" qn_yͭHsȫBlJsz 5 @}F$y4c ~H$@=4! V@:5AB-, ~7=Ӿ?bm?^!|hCDAvhn.NTw焜vU%k? 9y24Ɛ'v*_kJE4A}%UIv+Myi(-k1v\Kz`m<,>!4Y  7:4Ҋf dt;nŒ_e>x}~MekOhZF8 ! _BTP%yܖ&H].[$lSu% 6o./&6zC$P>xmQVi:QniN'P}B9B>9ȱI-%d^®ˁjA y |qʗoVnmy` K>v & P U4Pᥪ2g!K(FxsbNo)sR.V6r#cP"8KHFš 4 6H ER,$U%M:~bg?uY8iW].ʯfzʢO;--M8l*Qo%+ސ &—&zOsM2<2"6%(ށ+\ 7+d+ȣJ4ƿm#>蠓ˇ•c"038РPN}1_m8^#inQl,j S5d0(RùscLgT<V*Xxuz룿ߋK_M៞ϰ|瑖2I 6@ HB)d$Ȑ4 $P1!~v &xjX}U!0e9=+<;z?T}$XIau9fE:v +[w"nu[XGokwChO &}.B xN7nw~BleX}gi cd2i ^Ⰵ`CJd 9L}{В:$^HIFI$ R`BB i!簒啇}NkO%&tAT * d$ !BH? X@B@d!;a$6+?xI(5BI?IM2x}7@Av@w[е]}*9'-P y$6BlfspHAՠ8OD]8K n1:Pr'D \i=ҿf~Щ;MaSչRv26~ԝZ߯|^c1 !uXu=ɉ&,*vNP9e<j#ҀLYs1v6;%CA1XЈAܴ"94#9`bu"V)i/rE;ATbB @n F[~hF=; 5`݆Flj\-ww6ǗNU}^Y:n\Z3H8  ()#~F@f{9d$ m<$ʲs_g:zd>eW l|c~`/VBM}væg)rd䌸~7U+GkJeUHx$&[HIILII~m^HQi 6&4oa!g k7Fn1>'%q]Ģn{i$+ xP! >Hjt=?`Hc$P!А  biavыwx,I'L}ۢ"϶<$ r22OJ֨M-׍Pl Xp _UjvKsk?iRT<ߎ"3*j_K%vV WNrVPKRim]$N_;_~Ma2a)jƯOFh\Fn3Q5h; BH޾=}o"E;^n4Kbb9lct˗jczG|)h+Z1Ia~ 0Ʉmvs MR+ik->Y"64gs ~YZv#FVnޖl/x o7K{l0P& UNv6Ԛf^;kҾ${EȳU爫}sm &Z>[@ۻ)R8 $6V)2 "TsїUp *gay~ vW 4A d'U0htSQ-~q1r88? GCY&܃"|̕0M%_C@$Ig?@@4$"@dCkWw_݇zoO ʠ]6ɈBHM$D Y$$Y" Od$ѕ(E(HECC!O!Iсi!)poIp#${tkc ;@0Taσ΀/tl S5". RZ\hI8gJ{h|]_`ni!2Po[˝6 m E|=ߢ;I_*elYдTY9F_ٹLl)XQ`B{NM__pW]gpE2фYѿ`Hm ;}/ Kdk_=ܲ<ת_ _B)JAE!EIO'R@!'ݒ{v@*@E$2I!XAd$=%d@\KaI!vK7TS=I4mswliANSMJ~k6O Ts%d"a!! gX@V46ll1[U#Ĝ̔󷋯•`/|s#IDdyҿpXM)]Eڨ+$ ϷXb+54֒i>=uCQDf|em2m2{z{{7_ЋCueh`JVD%2FqVsU~Cs/9֣+G07`?5فTۿGI|s2K\ߢcR"nхJ`d0]yߧIƥaWH@gG-Õǵ+E:fZ_YE$#6rG1X uNJԻ/K/Kn٘o $em`1yؐpqߒBUQS=8O鯳uX*DxHz*!!&XH,ZBOΤ T$U+  C$$,`CHC5[?|[Kqde 6UBM$ NyBI!da'6I+bHM$)<)ގR'U~MSU,*uА$Q׬ۇs 0XT5^e?^.|}3I*Gl=N:ئ&{=߂}8 "(Te Qu,mr@r1ȼt!_@mJ_OZg}.)W`g ~#" :Ehv_ݪk30#iK!x)*Hd"!R?F,?Z2b$&m!tQB/8~}yǓMt>"o0*HOd! |0"RH(H= 'ZI4I"xmBG,!3PP ps|>?:/ƣc%8Ÿ2iOɇύdKR(^)gr;O!;2M/^ҮŴ/k~QxvKОȍ`PD7 7^,ʛ;5)Odς ~㉛o9d,S:kd!Ү|S~4`I;}҈2@Mڄ?ػ?Y@ٝ> uJٝj󭳨ף)jdul͜A 2 TѲ?.DzR^kfƜ\͊i|j#t7hU^M6%g}#XDj>ih}Z[ѐJoWq % OYaVa3l5&LY}~ ÍlAς,Kx]l9]Iwauo\P]BQ[&VrvH3qQ>o<A 5poQ,Dp˺Ňeڣ۪Zp'Upofۛ ?L[c!:y9=}Mզh/UWB}ٔp?jR5oT(K9.%!)}:dZxm NOIc"ǻ){AiIٵtoE~{qY%ҥ(7;_%>grłٳltAH"c•)ޔ}&X0;};}l)tM!]EjWv&zǗ*m0jiZ2kHbM'M"$l>nM5JlH IRR)vJ )&Ğ""C1^9 [{͟Z#a &UN-٥ lw;R $"՚$ q)QdT48u09H2/ږ7D.HsDP1yd0=԰,8mN?YjEbN7wQQ A{q ë=~]pS^*mּIBIgj}"1Os8ulHmNYͱGZsT `F]9t1˯4#i=z ך\%Z緙%Y51zj-jefއ>ʭUc]#bJ HIUPS`⣺O}5G:Dtŏ vZ bzK(-S١!2C=-EK։ϴ,ײk-MYe5)s^BfVIA'pC#wVQd2y߉첌;=TF:_#zβrsY3tUNI4 x $Gwe5E LI%`CFB=;Syj?.lƕSBR%sIOLj*!6 I"O??tHn H ҄pCQlsiyE7Q7.pL9W*l_`@XVd'W/9B@4aV,bE`U78r_15m=VMq[ cS;oۺUD:d6N^s~ׇcwnoQSj1`9erq<L`(h|]:zBy+;/؍weܺe>-&<%O2 :bߵ/ȞgqqIG tM/4dxa *NY<^r5 l{P&"J=Lf6OAh4Hӕ%n4/g!5>Oki]JXaJ@8Hb .%ΧSc(Z9_^ ]R8nAӴU!8Luq6&\Q6 #Yqɛm1VG&O?4cU_6c3d㙛2.2ȉ Qq[fX,tb}zI#9To<Әg~LG7Fk9` I$0唒/֘ 9ߚkwͥis7<8;"$3I!$?Y$!$! Q I` y,xy9vr9Kv]k~< I[}"-(`=zzRʳvA؈up\;YϠEbзy AKlRlt>5ှ&x5a8ULb!$*E$2XqYk ՘5ϚMP@Ri'l}.t.yG~aZA {\,(Fnim>=3C Xp!DЛ4׈dCd1eRKa복kuh=.}BOʲ$X@?',/t'?҇PR@8mQ#QXAß;Zk U>jma!+BE?P',?w@Ԑ}0X8BI&RNA#j9 uzZh1Eӹ͠\3٬#*m'(J5GE `lUA}`cX6\] _afPR*]=k0fp]ʗ54tԎ+Sֿ,7 Q{Nzs#fñf+ϯ>?vv{pA4fU xDE6*"Dv}..+ z_C5T5* CZ`L% BIْ *ZАpXWLB# ;6$ oGT,&$6AP$Nyd~*zL?Yj3~ad# PW?/̝~E Tb1?.ǖac Ma'N8}\`! PY֣0IFLB7MEZ(+2 BI+9?A.( u6N_ɣ7, |[ *ʄP+Fm=ϟ{[qQ%%`< *OѭAXSb]VGo 9p&O!WE[Ҟw3_[rqy>Y94/&׳8 }RhwFQ5\߹('7L\sOGJL9#τIlkyx 9OQ};cSc]K{ A3 -ihC-<c- <9z~ߏqJnuhČB,*P'~ݡX~a_Z@X>ɁbdH'轮L@2FNkߟ%fqer3M ݍIBH\8Ԑ? Pr>TTBn6U6+:zz2r"wtyI֢("='UU{EB^R'~xSHfWjWjl]R锽Lp_oA?ʀ$C)3 ^X=OPxg=R7Zp5[: j^9!1uEr߭>]is `bVL?ރR2\zđB dέIy ߽HFʳ\^=ocE {qJ$lHʅ!ZNnL(2ʤ(as?Ҷ}"iD1KfLc}H(u Q b(oS"80~̐9p|:#a4~S1iBc 2gr4`j {5ڽFD*Ax[j>5I7E(mo1a]Wx==wv:t@GLi7O>N|˦ 'h,֡+?9]}Cw,~z2,RB~! Tʑ}&ID}]a%d uвHt];PYWTE4L+ #6,%מQDNQ"s/Ձë$"-s Q#b[7TFO*EL#'~SE;ir55pL2 H%JgRx9ɇ;l] +z/L~ Ue8yt;IS@;0G3RIˆן~7}m =|.vwM\ÿ`H,IRD?6~>[n*d =[BPm sD\g}OS|LlgKVCW/#JDjȓo{S3߽Iw8Cko~ݿSZTK`k*"<M^ĈL K3⧰tїBgv>+/0{$j`8| ^GgDN]'y #$ ^J&Lj~>/[nKR኉~ dAቢG~&/*?L{G3R" յZ.˨3ev(R=Qc/2vEDniAyYJ,p T@-#MDux{i$K52} (c`t)wtKlJ?BHbOtʿD&PB,BJ"0&tW5֟(k7ī{@wg/?puKܵ[N7F#Tekh\݊9xSh=LBgyŧfkׅ{Q{_}o^A>yhjXtAs¼d4תs_ĠIJp~i٢SO5,;] Ea.ehDLr嬓)uNL(-2(<rbū%`րdUX%{$<#H'?\"B"ӊx%O?a0\Xo3hG=0gvׄ[pmt1lccdY (a?PV2pjy>W2ANFk6!gD(aPAڲCmfѤDP`J$$*0D$ ʽ2IܭgX ֹjjc?@~ ¸;2Y9`$ W`GL`i_\uOzG` 6ƴ[:7%#y?J!G+HAbE8xhb\ _[W1EDVs;Xy}ݬpp=waw~˂J֊ . !R ⟄0 t ;yMV0.ώLvs$ڶֻ-5fL Lh Wa@lD -xǦ3ZcFDR3gXy8cv1ii^*uC +"±f͑d7k6@MY8qEwf)WdtcZ`6< g0d@}*{Z}ɞiEHpL> NV=DGt`GeRad~#;]TḈ ?=Te/ӷ_MsmcTf2ڿ}|{HS_iQj ) ^=WW6ZO&4ؑ2YK?C l͑ց@d~s.X|,q-#FȣS.i/?6n`}~YLwi&S[43i~k\d߳_o;Z GkFt[KƿD L-[EsWe,# 5e!>1c;~)?l:9i=ˇf-aKI lmdXH%[c8}%%x\;9s6}Kv8'eHTsƪ&NUr̞]*,7?,1; ! ؏́ɒsm7D4?%Ŕ1ViӬL!s_ۛ zŪ0)@gu.lRHLi/_v_./IBy+ E{Hz6Y}D?am|F;k;H}b#M…+dݠH^ pw A9b5xYZuxYr/U2k8?,.!}5I=I&s(ɘ*1_5}Rd&7{Nz" T!0hF҄`rWfiMFq/ܶ!>C*  wA7|oW/Yg22qͽhpk5JAIy:AdQ&4'g>{e X#H1$eO''|{RY' '9^7gP<19rjv4(:ѕl#+xǿL}voI|[H [d, W5`u5ھ]jK_:L( t,xL*.1Aj/mOzv" _w+V/⩹ِ@bR!?K$,~JoTUPsQ7jQ-S oFLN~Xʦrʡ]3܊J5[s=VM{JSPGB|x+cn^UI/fx Ih)bK}(Tf)VUq g^+m l5ÈJ™p&ay>5'(S4q6,>ʚ$0O0\RC_vK -A0J̎ؓ}i4S~n15I3tY ~:,\tCmaal:L@Ì}]H!t~mqͶ{Cģ}qYcl gl׬];\W~lU9q4Z!ⲐW \ʑL \ 7^+.'nAΑnik+>A?S6l_N($U]Q$MM9BG+Ct\vlU2VLӂiL-O|X-Ze+$٪F]$G0I [e*Ӏv8虻R`fh?Jg,7U3DTauoSe.[@yMԈl+il!{r_Ցh:'JaXMp{(\_6?*S-z[;P/+?OUsn$>eCsto!-ϣ |]?ߋdjqRWZ4lhߚkQ3[!~)K١kW0VO;ug06YzDl) !9 l2PC<^-XOeI2) ݗ s5$e۝:.Iliwzt3UZSIkMQ(>" dO8մ9l[m,s"LV{u^wpck#N.tO?)nS+iD ( /)vDUVK]U dzyVqkƱB9:̝y,.ODkA[2WwIHˮOfN2I-../  ɂ 5KYt9xtgM[fwɂB_I%XfӁ;N$_Ć-McQS[/7 v2 SsVl^݂(Ȥ>]~V~ uI<lAR3Kc%W\Xz00(@Hriȹu^=un[~%;6GϏׇ/F0y?H<;qys{~H)g{|y}=c_ܕ/1{IMo?^DO<'o32#ȋsQHrAM7",Fǡ>/||{qq%IȜrYkb1wʄkY:[v^ &Nx#k /")gOGf?v4Iidul${v?ĵtO;}-/a)cNwz:z" tLJ!qhM?QzyIۇM mgXJϾ5|BD($THt=-Wk)_otvLf$ZO}!K:2/qѼ"OǏz9zvpP;{gZmgK0kj?2G$E0)hO41lcRk}_QZM%anl6H=Ts5'[KR_`:zRK9b?֦NB [#BsBΩ:>BÄ$Kg6#mR! #2)JJW tE ȓSRdX~BD5=0Q 8ߛօK9#.zN5RpOs{}JN f::<϶OCW[YgzG}G l#++eEv‘TJIg?nAbHa@N,\qy9a/D%KrP9_c*aeOY>hƟH߿cY_Tv8$L $bZ5Oӻ c {o1OZ͜tWzz⥊DQ$lXR3T߈)3~3pl4YNz.?i,{ƈ#~0b':~6gٞ pve5 ƆC4"8h#,%96^Hy .B(st.[(58@Gt}{=Qhz?(k,ڧLS!s zF, ,k`/PjT=[=oU! ]LC=$/t.lS<)N 2X."juo~DMCAֻKQ"g3r? +sQ{WSf+;1S_~L*Sp%m%&6[w"vadp1 #24Y3(Z3.4be`,Yu=/CN-d)xhY+t8ۤfghGe8,oV%T,Ï\čib  Aj?R;73vȔ3Ktޫô_b *=]3Z+Q{ulPV dh=ս_yg}_[d\O7TVWɜAF ̺|WinAWs: !%u?=%=?HO{{CtJ$げcƺ65INkxUK)Rh:o.}B?مd0E>/3F2q8}vNH Y0wo=XIQqBIHo1CAp@whn%[Jߣ}w%Tj͖YF{wˈ+a=8*,J1U1RĪ(?yuU I)n".FL'[U\ %tQdH!A@SU+SB§XŚJ\# nI3bOo?D& [C!umv1"If@JJ~SxmZ㾿 U8tC9unϸg9a/o%ɞ򻟵au$SAcB@,~`|6_ݯ''z`~%ez¥FO dQA".=қ0 e;4&?,#1T ,$8:|ܗq(Ż6.fLܝp@ qeކL&@eKemz~i[Q߈$ rK"pQ%(>o(>˄5ʪXMb`" ͭ&B~ṃ5ņf!@c&S{~my3|:*t nyzx<ΆZE8zqLm(H. mZ2 s+,]'r,<;%0mO^h'%EFMAI,>~+;)T#2dVqӓo"3!'L^yef%WJR|yvvɳd ǧB;,lqB!SphHx/ 'sPxAke+>}g=VOYη> )cc?7? GbA ޖ͆k 9PQKeNe2 W{D8_q6 =c:=+!}>둂L]GzY5 af!ъ l~".TJ;s>/׾W_w=p΀R( FНS ʥI'^Rŵ%+u" V(X'iz6"d*ѫguGk`/<lvl@U/p10=E}r6B$}[G#>w5nc!Zm%UOU'(Lx:o?fk_T_59e[#<sηx[:X7ap$VSo(,ܐiD8T J& sqTnNsJqpUά\ {IeKr+U8xod B]%Z|sk3rleK0#U~z#MM: oph!5"''v] %Q8d"pt5zyUGU(QS.3&ˑE:5Z&s݀CXu%¨6 C#RY&#k8Xd%nua!a(X¦orXI6 j3-IF2 "*6Cs ZF,%mQ-lj[J)eFn2$mI7D1k3eCq[%:$10oWQT91$pSyUіCn4!'SNعbBubw L(ȔMϝEQJUGp1=?A}M!l8eR..'(%+S hG(}0u/k@Ȉ2gq>84qD򲞈$ \Q>x]hTUM]OtDN>%J{gx|,kGO,j1vJ99]?DVYms{1"ꕎS(K{EZSKJu'/R"DPݽS0 n'W[K7=ӦwrY"D{X/m|Bq7 u^?wc?~؋-`cmaoTk3?'M r^jq'WA7r2 \gP=>?A8eG߭~]U(__Bt!1ӫsL\T;Dχ!İyk/Jb9N"#757OE.G{| =i)aIkJ D TYߓȠ'U%IdL輬!KC}}_Oω*C?]tKWS.:7Z;"%"u2*)`uC #"-KfE5^j 7'K6BJ qIg:ȯŋIL~d&~N:GFuRhB煚 K|5oߞW"]9zLp^N$l] 5>r!Nl7C$~> to?;E?ܛDe%jI$㝑C/Tmiԑ/֜+nّ֦(V@UW xiQmQkwbf\'k 3f}i4翽hJyc`ݨ0fiܛ+;x.e%9\q?jb$IFү;{R9T'2,RwڻU2c.(1hlph?QW-϶y_OvE79ٗ۳s{8[gdik=:WݱK~< \oCE}I(mkޕ1aD]/~*6P(E  ^'B zj`8D>2ڻx{)8~}b&),ؗ3A~*%$ V͛q. c[ġSzG:՝in(2Owִ2BmB^#sGިp88.WIЩ^(wno Mtw7&a]FI-~ R#uVLHx8q1z< ~;7šnaަ#ֹ2GV\/7_] ~_KDѲou 6Y~?qi[w. tk NS[fMg5IO u<)?=/3DD!oZ~x:UIp_Ou ضPbD|?i}=BE >AjKw22 Y%MkB{dQ~ twSM]J]Gֵb8bϻ`O3NU;l,\ӈc]@M@,`AbaLLaL:Gv*f+|ga%YoU!Eˑ9VCY7;)ޙfgU{O+5/~eԯ?w8C+ #Ne.Knҷq6Mq2L{B +1ϬP/м0=uhSZKŔ~]xlۘ1$Q'YoSf$+k ks$CڧմæNYiĜs\fVq*[{uX {5]t(g2h*)/8\5s[}q0VE86k׬ -979&% >*#2EQ®m TA%ڮ,+d$(+@!~4s(:~e{fQdWDSYCmȎRa#mo~QsK{#V} 7LK>R0 ! HQ(hѰTxҀBƳRHsc\oKcnvR=@<;jQ٢G0GM޺S֝}!bWV$Hf` ^V4S*b;xdP/zKYBb@ yYDHJLSTNQ(5dI"y7Z v !KoI2%>)G& ecyۧZ{S{"i,PY%Kg=Ô"guqӍ?7=ѐe'\TBBWAM=)NB@:q\њ՝궣bX[F6"2#Eכh{J u4T23x-n]/DԀt1^{×PB@4~r5Лؕ^zj9B",bO$abB*S T۠av|P>~N$yqEx%{B~ (E,{ d}',roA-]q|+0 #B!(I (mANHakSY~b3ALadDRjFر\R_ckw '794mMr zԋz#m"rך/S8ڐ+H\|lAB}μϕNJ]MD DZy|[ k'nwp'[׊E*m'\mTuiYywB89I5s3`N}K;ww ?i! ii4AMy)T*'ju3͗ Nt Xq;U^34t"ŚZDQXՕ=-=c+EwiԔcowR~àa ~K#I9Q{,3Xyi: 6X\'-㿸up`Y6X1^٬!D7JBdWG[5~{SQ :]ĥX'뚿f\,2Ѝ;1EP_&k$ "$cF df5xNZWgm4+% d5)yۏyWpԥ-N*xP+ߏ~-]Ĥ6յս{E_n(kJDpש%wơKG.:G \ο;Yɶ}SuAd >~6+;dpb5n~_5EGqq6 %%}<{t: #uesst2sm>%aC/Ŏd6Cv%yԱoxeq9cQnǒ~I1ܫb߱`U^Hpr F%0,'Jn,TЙ#JW Gtq(moqo4æ=/U3Pzt2,\,]Lz ?Z[Wdt8-<_tB3h^"=$q_'woR2K?7>F(5E4$Tfx͋}wyEp/Y*G.pOl64H^ElՉb*ގ|xi6lv߇r}ӢMR~DV0O|ZVVx\QNNLZ*ќZl3j;dn_ʽ>P)eF+0T|fXO#!O}Y(6]%]ҊRW3Ǧ|<'ʦ4W۩@s5/tř5e 9oyG:j *beM>ο 5uܲLS+CD)Rn[IB $"~'0d%f82ƷeZFp{: $AOԭ~~Ty \"6Vy_g?_#MrM7.;1i?UdfR'vrU>jhִ9+L2JKRæI 5RS4K|=~n<:%8y4)t)? Hy!$w% .V|e5'[U`Iջ<*TW+ft>]ӏǬg5+6ыe7^?S"{+FQOM1qoG`3v7cMkc%:rW6'B{݈o╰vFYTO[IF"Hm6t$R՞ /݃[Zەj G\Ɲ*Vq"W3I6}_3Zzelʈq#F"y_m~nNg`gslT+qm@;uEt3ͮ7] %w="<}]4j5+'}#/1!>ZS럁 R2C,A{>} hzQ,,|Ow~$Lm4ϯ.{̙c+)y=+r~0؏,P Dpnln힆Y_A>ٳ.g5brIM:yGl.Cv׻|]  X"&S k//FscOP/eY7͵CD2׹쎩9 $ g/?N&*YXyÇu{+ß.>fԊs$jm0i D<~mqtw5sx\TehXKQR gH8)lr v뀐 NuV_@ {ѩLKE-Ks:{w38ϫ!Y1Ukj-&*W\pEXxQ,ҷghjCzႲí廷DѩX2|_&4cfebǿ7V V `H$ [Ұ FMΔ,K&aJJJ$|Ba{N-IWyA~2+)n1$,2c$*>]>ce}&c Q\|R~#ƓMe4uˋY+]!C|٥n\T泽k| |[mo? V!fJ ]Lq "k\fI E0:!;{^/[N`;yaO_z۹bLuH=뼇z ӽme cQ9tv/L S<ݒRyPR? ټe Ƨ?*.>ZSo ;hq VFTk;1{kdų'8MͭK%- w:[wqŽ}OvgtjE+ 8)X9[!i\ gԘ/z ZT_}-y)>x9!^iL_-sM@JW%ZD[}68̎pqݕb2DeQRfꦆ}MFlPeGDiV~'y}n%QFXxˎѸ5"1` fJH s7xg+uK|nj.s_OgS{;1hA /ޕ,;>*)=Cu1̝|v#S6P.[!Zߩh(e쬻007߾? ڠ={S17rlmM795NKno;TlSM׼4~>P*uj\0c)N Ljϋ, P|u_י2x!hʠAP"S=l<^x 5N?s1S1\uz)ےJs=J[x2B7vOU~y,IlÃӽI\i^GaWE8أ+;֑^Zܢw|F"t [$ӷDp}BaTd@4M!}Ba30?nۭ<"Lki \`rq4Tx)qTV#@ n*prىpI"XԄ1$KDT uW|M\.\"",;$]LENa/F'Z]=MiN铐VHu`]MBD{:ɬJ\H1>bm1: FNiF9EºEÔ 񜯟15#gRUJ6 J8JP(I" bB s8|{T5AH\K*oV]0LFmOO2q-_F:8G\b=Kg,%i]t7DO1dzڋjړ2me^TP+[a2J?h69zH1q4)HXem8FՇ(?"$ykMIűӺgkFR{3/ZWQe=$"cIj$PconGͯr3q&$z+ RiQh"? &8XGA0꟩_Xu^˙wy#%-(EC/󏑂#vlSAPh;k*1gմϠ ݁nq!ݫ?r\#aTiYi+b;Ĉ]  0nQA]"E%HXoD--13-74>ԧ+&6ڼ1 |<^ÜWڹr˜/8ϗ@2Ǘ7*jݬZ㾲ݞ#Vn%%,7cyr[5<7T(N޾>e7,jwg;ؑxKD3 ~[Q%ƺet>07°`=lλpS@ Vq0Rc+z L5^<1W8O@l CB% ^ԷȲT@hdY< aWl/U\W/*Ұ4@T{8Ûk>$·:%vĴM ,Ri/,JeT(f\&Bkp$0Dh13<兮b hmU_kM2CDj4$ v˙#ߐjnà ytN^rGo ko ђ):Tx=֖ɖ+UO.LZK'FV>R ZBM㢋4#[^ty)+Bk]pw7Q=q\^a=SVXb׊dbKz H  iZS\0/yI$JP9"-Ӛ  l{ hiD>9_ҎFfQJH߳s"E w",Id"81EP~857"^4ϵ|ǔ EdkTn6q#fe0^k+7ДBtM^C/Hv75ƥ&>w9Z r3䁴HH÷&حg7$V]<=] H㥢(R^l%VZ[vEލ2J-9瀑bj|: q60fᚍNFAUf>=:_Zej\ {vC=$䛜p%iPR7mͦH:QF=D6G~%UUoMVD P:#?$U;!CbEbsq]4C*% u b.IK9`k3^9[249X-G Bm YT,kPCϻ\?pa鈥 RQZ`|s,ThqXfmMdt>dп!lk2.v׾H-2>o%@4*}|\_ZN\Ut LZ9$b "+>d̂0{Ӈ؛saN `2Tp ͜UhEih\Yu`+$_5gl-o{ߖZm旃|H);3oe,HaSq@`(af;~_pkT;S ٛ}vY|8AaPԘhQr=z0^(cBCsw:!$Y@}/硛`= )s"YNecNSImM HѾu8q#ՆYKz\jn Gt.t Qg0N'!j1\9ein7% 9خfmm2Z& Qy:'7<ܬ.gL"0O4@ʮo%I4 !yMGll]^4 N➉]J+!Swvbi/a`DLHSjzXVX06 )]ټ8 \dA!%|bRUT(Mqo2K"ܾ"ϓ$&ΛZk?.GfUqA#84}7oyŐm͚5* YdViM[FS? @BFF%=džIT1رӐSޓ*ܮqh3) )m"B au%j9a0A$n˸v/԰pKݙj.:PO#<ͰĪe+GA@21BH8<@"BsM,7+:6fر$X'[՘R)q[4B*[nGZRKA1y lYRVu.,\u63"aM|`0o)"OsW! T$x~S^ &nVrxGQg16aS2!5 _(9L#D  G<':00Pci}:f=F=ħQ}%yLֵAh]k83Q)z\򛧍hV,*r`)PRn8m\d !rt6m;tBb-pu@ =ܰ/~CR-0|Ֆ?ʞ<e3g k@d Fi# t̥,m=R-/v>סd4C &+S?**7mV!bK]t:+$JEǙA  >0X|:q=76ZoezR8@HJ.4:MoC8|tT50GԄslD,1 "Rkvgw 8ADr4+ } spyNs~9~iWq" jXNr`P]' _Ȩ`R TM$o$sW >|yp#"J>q0цnlc aCMg <&ō Ra{e= oP4#̴Z\#AVmgM]mR77x3C.k!x(ܔ)`p,Ä9 Rc+ƙqHI6:ݞ~ǕAy Ӄl'SiJK4{^Fގn`܍ӈ(|xo~}}6ϲ척'b }(P EiZ.4bqQ|p )algtYg{Ā"Neߙ wR^^QUi}(`r(q.TT]y6_q!c̋0B> !G_~$ҵ+|O4렏ىa(㝺]z1Ogln#L6Oc>tk\Q&yQ,O%\KE-Ctip?`Kpl I|5dXơ۔9 "ER Hފ\1/^v=}@@V@DY1 " @ Hc `2I-{<۞O #t\W!veWW᫋4wc6/2ωû k1_ PRa4H`,Y~i|+9|-?O{imFJR՜fL6"DM@dFFhv4 34MS8"JVAT5E2 8C262cv(̶xojhC%1Lz8K %pƎif:Ƨ(ќxFcAUOs^ ,o)6ء01=o҆Q\ʹ tl}S11-)硣jœ2E%F9xZ˥>J@l慠1;=C!^wn-pϨ(?=]{2*t2Z "ĵqdžY=|/>̽<k',QMkdEMOtnFUAk AQ’(̔t#O.}9B R҉ "4:|VgϱK1=|rc5)#2&y fk(y N8 =hɷӛ&FfL3 JYfX y=dv;jFdP%U[ꅲ=/[EwUV.!\#vvmI|\D44TZ)&)&UYNsG{ػKh$@ ƌCVNQ *UO^مAN(;]!˭YI=|Wɫ$h/s2$ͤ "$-ibH!2 q $S4q\s?D잭\* ]ӔrFK~Ęژ}ZhZ9i?{ _UiJKƫ`+ieN{nT[tTysy u TR,FK[Y #Zf GykI28loh0/{&(ŋQyXAMd {TV)R98q;esܖ(/8CXL&q2[5nZ25Ifh {cF@%<m5F{6v۵ H.~w pvoKc^>ȡBoۀ߭ɹM|%=X/ɛI{\D'j0 9㯟3?\f׎XeʄX?kOU\mlL!vU5+|jrf v# kX=*@ݼ@tAo9(%M(H FriVUz4͎h'HdOu=ƞ,7uHe#c e:u^-0fXvq$Fڄ/k:r%S3TPnϴb `0;yp710R-3Q:kddbLхz!&" 5;ܛ,ÚIؼ 8!ͱLζ|ŗKX(Lݍ]pGwyz=6ܻu[S✆ȄۺgV#o.T{^3ќ]V׿߰kǖBm%6S+:FzVl[ [s1U&E'=-~=8˻%OE>rӧnkKق{wir;]/>rس^mٯN[cT7}f\9'3(}Xqx a3>GL=<vMG8^i,7F:W!,eԦ=LR/ٚw`?I:γ9scb;"žަyx/]Ϟ+!|]qn/QTpy߭׹P@7ϻ%_w7 kǯ1fKVzg[Xv>n$8- {źx35?YVlPĩvVxA.I+`l[ @2Cȫ?]9HDG6Ě0AIlzgk_DI=L YWT޶]u ?a7u]HJېHU;,cYCICAVm3HMZܸ<)B\434$,g:褹X`Ŏ*]'k_fսPgWĀ% V;i>\V3@})!I /eQD]ɒcV_c߮&gd p #c>%|0׬6z%.ِbRF A!g 3US#oM׋^T?FDh$B=HƁFP`>\9;B6œF= _+Y:@ o?+O"n9qȍlozOv<.J :N‛$%6+:6Y HF#n1 襊O`2M%&C,0}dݗn|Hh!$Cx1$P`؍u|$~'w_eYKraL\̤k#Λ˞1 NjI靺-ٶv&:€PϥwQ㥐t-#"SC"hX͎kEgЈ(9+'~Yu'7nwrK%!ْS>HB;wAh UOЌbA+(,|eN\$$ZBheYɒ5y4m+A%riRkق_FV8rƠDIŅı!2kк&df1+gmmpTg2E7v,˔K"8"dڅlO+e+ϴvw2ɀ&dme0S*t.xas]~-iT si^&Mfо2؝1VΣۍ< .'bUNd9%K1kHWbF,dԯ/횋si*'yڭ38pnasW:am3rP[wK(d#nQ' $"YQ~W}Yܧ}L7oQAd52&Pݹ}ġ8g&ߺsGwm0GQlo jd,f?x_O)?|xlD@9j$5~ח?˵WBKl%xQKcx^l9C $AzMyB LٓGbr)s}]͕!U/7ɤaYSLM A +R5M4C\n 7ڲ?ٵ+׭ -[) [&# U)Ȣ'wo ^ʚgoBYR|~\e cQ ;vA z> d>Fx/NEDnʝ)hB`zIz/kT KwL=$:F~2J]|b&6.ƋJ)^Χ6C%b}6xtf5cK,`  *  } >цӶEND!FL1um_J^RPFrRoRX GouK-ivǣYڝfnBI Ɔ?ض勜\* QūraN1prTTth+%Y66E\~Zd@1;?>}0HD8P$#:,R13Fп]Q HkT[UR ]/%BUx5Zq,af.)AFTgg  6$,VyV]2%o{7bʕ=Ba("QarʂyʡPy+'ZAk4v'5͗yHbسn(Q\J(:\?l ;.b:I3ݼ, kꦵq  ΞBP9ѵA(ߙ0;n(phGJI *Lr4ФnbC߶&Z"i?.lO~Q?PWN(/b~5ti{/B|cw)uʉ%.ҫ5{%bef+\NBg=?$GC&@?p|Zml_cw3Usz>ƙN9W9pV.h!zɑ7m."K؟Zi} vT~/2 bq-p|]J˒\8EsrA;tBv y zzQrx2+j.,*xW@v7 `Q?**C"R,BB?U#6g mzvqEmr)誉Ye%$lKc͡4 _"lg]߷޵JFU\]PWӉm/&L/4c#Un]fWdG^f8p$KܥDjk;j{T29)e^2T5kڣw'd&0;ٶ5€슉KIIEM9HZ B8SDD5N.:?_S֣ri+1qGm[?jY9G`C^8$ Zs_Y{gOV^8V[rC[h ,iC?F>eQi~jtC J4<kU9n~Tmd<_Jnb19pȬ1Dtq}Z#g9h?俳gv.H!I02NnH)KO7ٹNhIFH2w6M׮,_S٧V35hǣRDI.$ׯ qRP,_XJJ 9S;pN8}3 QhFD(%6!(=QjM,Y#+H}SoVd{[O{{? 8̝ YRh]ZMyDYU}rM\]67pHz $"ȵ%tCG@Cl )(ճM=Ɖţ jyb'<:ٓŏz{gj_xc`ǢTddGB^l|+;B}XlS^?m K|p$\mi4yIV4q{4׽C}RAAwzDž=NΒ^ߧ/XtXGz.ϏbV,F5ͧ[mQ}+ò]ȅrKܟvf]51erU-%ܷoPS:?{&$|݊{˃"x^˼# r$;6DWNa5 fO(1'OGGOb)?xrݑkVq馱ߣ9=,dkM.2}ʄ{wF104@'߲ءv'r@æSUo4raL; LK`ѷF1q仹0Af̸q "+^qikڗ[H* D~oWO?QvhwwsVv/v>NeFF:Or}5j>-BQ 4^UnRfm^Mg'ε=h⻘ g NPO_{d:gCbN2EBBZY8eUnAv鑁0?@u'bOjQa՘Ҟpp❣Km4T1Ժ/):1 |)a$DG%;gƍ"2])K9K1Uď+5tx+m:fŰ\E Y|eE-.T]\., mrd<.ł0Hot~ IˍS{6?vsvjL3M!/xX]E{krLџpɎ5`Z=9`[ݏqhWh+=M )3l ,Ġ !۸4(B78L=d <)o x~p)20XtqZbTr(R&WE}UA %.*NOۦ΋1Ah>:Qm7nǸfv y4L={J"ow4wT> o b;8{ N[>+ױL9z֒Wi%3sQGCYpE|'S CVQ" AH0R,:n6t@^L Om.#Wso&l ϰ($'\TcՏ]SO\=a9 ..5wvnmR=j-Cph*Oe#MLi5)8|Bm,CZStYͶLl6f}eG;û6 C鐊 GW'W(wpC܄t7FlIw} Q.>ZMbrj=ArOVaݩepcذfWs7tg/+OMS 4߫Ȑ)țf7;Sy>3 7o Pi"2LHH# @DjL^/:v#teluB @#.Rp9k"Xfk'!eۡ38jY&VNB)l󞲪i9C^.X!YNBZ51wɼ;s)^FS tb$ sC/\]wb90ؔaa”߽H?}j1iuˣ J0˱gWJOCO9ٲ[fv3^/ǐ7&-y s \UBu$>@A Ͼ>Ձo:L,ycGV3f`diQ)8 9iWsy4'uܖ- `cRʃLA$Hu服I dJkT5.WeVpoƟ~ 9?ۜ+q>E^R3Ph&I^8Նfꃂxs#!mSŮD t(d5ZNsCZ= /juqǻau!lM` 8/+Z}fwXwU5NQ*XSS&s)&DE0|M߈F9/9mYAEA-mUgUٚ p[W*.ۦHMǬ5W%p!I: J9\]+ 7lvX~L]lXmP]6f.HC+:sT*]⫦'UMEV4X˙MiܡsJ8tKD1MhnQ7IY|^:mg9j7J/M:.ּDΫnm#篃(Fs"A,qDc ٩lqYz](:"jz}ĭLOJVng.1* tbfZ(ᗡxh#+rOe$^/$)!?uZfqTr3եD֤p@7@79 cxV]eUVDq- -♱,x7L6^G{\ uԜ3mt4c_"LZ&ݻ%}1Ξce09MПula]JO9fnw۟E) #ЄYGϱI$Sh\*uN2O*z7~k V4H""AV,bX}fbτ,k%}Y<[Ut۲wBF Kyo!"Kְ6ř #,V FqW5=|cin3~Y]vKSw¨K `eQ~|اx|.-bךsq̿>U}sUV(DbOjX_un{o~^nPm *\њtĐ(WJ\=?YsA)}j^`٤_ۗ5THB+{iH^* OE1Ƞ[$Md̛v i Kowm\J>.~t.gg"F?'ZAEEcOOZןN?>O/I)>7O+_O}=7g>A>,LyGFY#>߷ҟI"9ccpDxZilQ DwC 1v I<6Aju(7Mepsu/EY'>m$0B(ͨ(Q24t3G<#(M[_W:E41^Ddт Sog!y$rghV``QY"*4 - K*?%z\&ZLP戟=iJ^mT$H~AD(J~)M[FP?:qN5V2EKT.0P7Y2LIl 7<g#&3Z %Xt5t=>S#dNK~Y6 J$ HYq0ԢA\}H=c%s|oaVQ_ҺOC_z061|XcmVm3Ii6F{cʄG6Kx-iSl 01?cN^rLy53H?_I+CcCIk)l LΥ/Bv5JՖW7sF-՞x`9191""RtY&g^' !U6y..Kq}JKR7)MϬ3ƈ)-G'é4(IhR|u8/щW؇7qgcN{s+{YP̒wfAQbT)0+G xK-bSOjԁ?%+싇go쨃 J9 k ,uLnG r|Kk\^ ,M"F!Tѩ:صQsck$r(QofDj|꘱Oȯg5 G=aG!s0]WT|=Q@ 3}O^cY*A%VLƒ8 EEk$'D3<ɖ2-7VU嗼깧½ƳO}n*gM`Z\ZܛE /phcְ#[ R]VU@{UѪ+#G(Ѿt7Z(j} SʊwY_aLK*]IJawj '%eꪎ܁.d2yCCEtxY!k€eBahv u߻&=9K8 B!4t3m3MѾ w]쪊HJ2#l  kߤE fFk 0c8tQɝ࿈פH t%TXɰ 1rinҠ9$xV2sGs[1 ؀rF qfG-vcdq Ubd*ڲ+F|u\/fiU]'7pt)I` ~˵㡼n,=l;tbqїĽ<]~ތ4f"wZMef m j$`6YǙ5I/I"KNW~STjh~ 'Z3?kR.^.n9$~?}vW{K%@V@  =K1⺵xE%p|;hzw&w+O~$ɲϘ)/?](.UYׯ{G^]UUST d s9<#i9ʻ!ek6lpNI8+tqXzKٸ>[a!&ܹAepk-vi!$:4\?7P-}B?G@9\IMZ| 2}x$2 v -# <17X >% ZBId İdD,Վw<4M$TQްʊ۹2=[8zu ڒWp/΀%"  Fdtbp|p!AN̛u:m.DdWH_m_RQBWqMHSEr: f&@P's+^n'OmJ!B=3W# /*JӔlӖ:_-YW{*Z* cҼi9z3F.47_QI +J,Ğ}2+)sf5'9j~BMIh&>e}A&=J+MU>WAn )1q2C˛4#Xng,Oo1S|fx̦`ع-ZHvp_Q-kw};u=dQ#3*ϐ+'pܸ$vԢ/K7 Or. BH Y@~Mx".ẘ5]I7jmH}] ޱ͐JVSkś^q=n U)MJIL=+P!24 %i`Ra8,v XFf.$D<{5&ڵjjSmmFL f<mSX -R#Lzސ^Ƕƌn.gr1oMԫŧx;lFor-!6q>v6 (뵖IFbpt@8ri,SV*Z[̽V&`itI)y1I gD.?#Hlu&W-Oa'syBzS&g:AD[:b=s}Er{l(ڐWCzۛ sQJPQ*.M+))|< %yp g%lL oI]AIf-l9T|gfuG--*+0o BVʒtG"\2zJ/lrp"N>'22$'n.2OL}#& {m)ĝʆ;5dAK3[Wb7`v!;;o>#L}~fO:Z WĶuc&6MѣA\QIE?" KTHnK}j@ZC\"i] Yo->[g6^o+m[{%_71B wsy}<?<8o!a -_<vցKz6m߫<)ΛXbW9pY_k#]To˯"5ٗNۚ *फ़yO^ DM»{#=ZT/x|x{h 8N<0UD#D 1F"MCK!$PYn:$(ΕfI |UH v񘔞y'{Њ \tJ1 W5~=zO&}!| c2+UUEr }I#X1G3Do>.v13luDIK4["e]j Ja<ՊӼ( &b~xޝ^ 1Xŷkwm@^{&]z' vٞOuKfPg툆U2qw>Vk}{x l9j|ɗ>q ^"#rS:~ܬ|pgoѭs([N[]5Y JsXo?/'?7oyUvofq|>o`7sw xH $ UXydM?7?uqHaGRNV4R!y/OyYd3BJ `n+yz{}rmߛw~v!  r6~,&@dL P4*N,%s"CQO>:91H" W ot&6UAdbE| `VSQcث UҾZk>Hi:Vf/Wj|%9|gwYwųIpmw*^>2j*NpJ dWU>rX ǝ-e6tھӯDo{rpx^_ٷByrKyvwKQ6uYzt'?cnk{ؘFRCl~iR=\=Oͳ>ӛN'$T3D3l0Y(d"!b$ʞ%/X\! Ei5]6'oS/Z6iHzKfqU"@ 7σH23S"7>(o6콳CT +ĕ2b$%!jԾvWUqIӎmڱՅ?$sOO1T틤.Rj`6;9jO{v523w`VlyDζZ{lO-9X~&w;~]ITO5Rܴ.gowSkӗ{zoG`m;*涧s6问u_T~%0eJRDF[كDF4./d?}W2JaSRI">*Gh_j*Pz撕 Au]ߖ,eXބ8%$NI,bK ,c ʐLmL:22H I *I xX >!$ $ }@$0=!)6R-O!s~=wbIp mvzM/"+4\ki#zA! z!l@.We #2[:a w!&s3%^id3$!O[*nͰڨK\;7h5XֿR)"َITh"oA]3ԬWerUy2Q?X1ED׍#ȡSpȡAD7lcN2Rjia=ruk:k Gd2⦆'n-jWH7 MW|߄O)lp+k6Zᱬ/.2B ARHtM9qXF_">y5/5OE0$.2M章EisҀgghE*G pi XDjW6UFQQ܈X WGkbsWpBs4jX?GrC׺d"_QR/IejR$hYc~'kqeC`7#/7_abbf`ː𳱧pF929+3{u%L2&$=S7 vę=jNq=[u +v.;;ݕ(5ˍKfso4Ռү+6,FoEzH!a[L,) w 3<r Yrr`q9vq8ĭŹrrUlr&aSD0ȡ f9:ee~^2UVG{e)7S`dggnK!5Z)Hfፊܒ3-S꭯sFT.[#M-wTfp2rs&HVHzSNEkKHa$)Htwo˸ZX:q-  h#όt69zՉ XNzV\wpΛJ`2W'ye{r>Y G;8}݋Kv .4ϗCdZGfe:VDcGW%Q55rCM+0C&k/^dx9? $!}Z>ćW,LofÏ>K;~Q3 QF :+Ĭe0&b0I'7'7VBgbnd' Z/GcX/9W|]m+]db6wKfR~G.Tavڷv;̟;~g~z6N TZ ڕߕ![V6} Km?_Zʝ>ÒI}#p:U[gc}*3U¿v1-D>e+7|FǢ 3atX.cQ,jXk?GICߨLyr_8WQ7STڷپ٦ (*a~{1 R:T 83ǫQPRIBG-AL~){9f>xNHK,_ٲ(wB_+$U8ekL =~Vn>>CJS>g}|ql@wF̒MDƽ9'tvRY' *if$b̲j$V m^=լ4؇C#e8 >5 q$Ib_:@ݻOS\͡*:&)ʴɒp)\4cf.[L̟$B^tS[ YGctck.N8A3H&yU~c˞ͤ`W6V]$;By̕3]PM^%ޥw! I62##!AQI ^^W).(Ivt|0Iqof  Ж^߻\P&(S(@ `qQK߰/g}TܧCk.h;^d2y6u Y 5 HJ@؏,<rAzZ rdWReA+&.&++De~D9M7+v[6Κg-q7 0'jT>S-\boNI91cqu8nڭ L]"Wv}_ >,2T \XزOcq1yFRG쾧.6; ϘhbY];'Q)<:JoRc-LRپ7aъ]ֿtQ'guC(LÚ0[IVj腲Z$tEIȫ{t\;98$pɐtt>^76TRl`|JT@ৄ1F] ѫҟcK=w~g2[|z٦AOZqnY.nl]MKoW~,L]Q9Rb ɼm mS ږ υYgeSvփ .ƏTM:?6H4FȪ|}xḼ9=ۊWr޵+.֪6zjuzp.'zmZ #M9W{Q潞{'Zj$[ȧ-s8$}VY7ٗoIP*̮T-A+FTGuNbE깄[dݵZpBMjyh hO_iM|A m6fcsv8DgMqJZd j(2$/rHEyJqO Ja,MnE_ӻPrJ͖֐SoR3eƩm͆޷ޫoWd5K^~\'G su)냳]-f#юZp>xea2wݔ^.+#/k'WnI>wfyyO 2'ia G P!mlo1׍[#(89k\&=5{y뻕_kn]:rHV4:12ovhӛkNlH/3 BBh,Rhu A==2DvW+1 ouRALh+;O6mpa220}k;v:?߭Zh~iU+w,]ge=W}z[k{& wz> o{1^]w!UަU]emku_ʫw ?{UbBHE݁WvZ\6G aW7 C^Λhp}fp\VKOⲷ/r|z} e_oU;OCM#V/[hҗ}(LOwv,ߤD( ewoLa ={+~[L[E'Χ7,2\+k3UDDye*eq&[*~ Ayd|U1 %~Mٷ+57a ^XBp3^k6YsK}ua1v g9\ɶH7#.seٽE*l?4_fHi@DDL4@ >%6]PEеT3?w'&֮VsT?˓#}?=G3G逫.>iM䢲g8 '5?̟}m@D!W?P?ȒC`Tƕ:Ibn%l&_Ӳcٳ"nZkVTx^q #o8_H)K~vМqLlfczZ|%IyqUg7;Mtʹcc=b*ϻgC|7:UwM[\?:G:l436խDM!vtwGNjy$c?|O'|?VW,b(,(bԟ_q1UU#䤪~ _O0Dׯwľį*6b&7j<_}V2Q#օsXҊ+tifLZeed-EKe@BvgX,+VD"QG`/cxg]?=oTy4?t puL~ )SpsV)E?ZPA;UT!j(z$#)]`IPs G|?z&PkCsP,@Ġ'Q%KF R"$(! ąŜd{ 8QYyCx^pcWujnk~UGOܗI}/Ww0~\嗙X_\ JCsFgƶVT>_}VPw^Z?Btـ C(#k w3g*;nhΧ06P.DŽX[M ;î/M5bBx՛@n% ?N b>>{dHR.JC)wEՕN@ ¬.0ƹ.b z J\ xQ=ol br :GF@T,"υ==RтD*A5 ` dRI*H%Q 2cC.C2"GR-R߳~ҽStCI_ϗ7>Q[ӫ*)rNIѝE\OXwf[eJůSux 4~6V^ C[o.{׆}"4 ]?ͿoDk!YӣY c4ij9Cx>"hj UX Q|z-.vn.|wގSiB苖h)c#rOn=v9~mƛ .Łr/0(ByW; AZ;dIc7F4JO|^3gO;**s Mx`Z&s- Z)*6-?D:VVRxT%?bn_޸o*!f%ل``~Q(:i'mk8uW_ج~%nZW;ho:^JZ.k zm9z(e^ok=wkEL-S,_;BѦO^{ L>V֣Ǚ]خ3#5;^LbMO#dqy];t?m]Ȫ$1n%t?X/5/?}`9 f2rwiKңaY8s HWTLV|tGc25?Kqϓ@wR8y~8Ȃ~`~ݥVx޴ll1כ7s!tB>j["1PSTAC%!A]%GY\g*".q=!.Lހw\.ۻ8Ęx99E/bm'F}S"KWyy,>̇V/!V4./fb8^l!I9iKa:1#IZ6QyTv2 kgx?n/"Qr ;NcMA x~Ʉ2~ N ɛC8qȊw}(Fmy|c ,t $8DHBI3J@?ܦSX2% ;jęyIQeW~ش] `/@#ͅb9soW CUZD.+ew§*sSU2LJR5P/ Bs5 xŠ9qq k/FQ( [Mdv_'V3J@ >kHw?^[״lv}F-7ie`vJ%*&Cxy݇/h *69Ә*Y|q,m*ipA(i@qJLPU8 m`x`4ȲsXh( I$ $6in2=7IO[ڢ뮺]*j l Q'ˡ7: 2!̬*' aRq CmMfLXol8Ĥ" MlG 4_IӖ-TzOAge;<잴dzխZ{Q/Oy5`C5ƫjS_6eg6tK4vY9';%cRLw 1RexjYmG-GknCciރI1٦]6ù>\06`6Ʊ 1CK&$cZE$25F)ʲ 9 3 5&z})H̒Bhb۬T-NfL!*0\k40BPN'ᙠAV w-Źzc<:<'kyʅejx=0Ÿ\3WHh"@Oet<xIC$ݑq?{# i _~ˮ7>/z{qD8p!'q;gWOXL։ԣ'sTI6z,MMN%ugX'h+@ma<1m3q{.#tE\[ -IBRM0C'Uo/g^" x09 @"t>\oϟK噂nJ2y_/uEi ZȂuOonؐ#,dbd"rGzrDDDDg1EuH=⧁ie!Wvnf $|z\)r#a}S+EI-kkU@˧y(@4^ ׼>4HE3eІ0y&Ͽǰ4JŦK5(seoMr!Fԟt]T&%*u]iq ^ѧAv-%єN=eΎ=I&1lc0>-q81n6T-0c4 ED`j-GPN6kJL Ȗ+Z夬b-9Ph?+:I`zÉ8 3f(q-brgqoM)Y]ŃMM޳Mo}<6^y)yZ&!hJSC6a,[?"]3XYY%|Z&U^7Hq3Fۿƨ2:?)V^{M\K}V0ux+reTkSܔlˁc{L J${0J`RyVPG˲ڭI/̺@uRK&-ȶ3`|`OH"hRlӬ/PҤS}SLݚjIM!LQ 5$դ. <Φ"]'JA\Jή8~ãuQ8~/w`2Wj `XiPQ'7IU3:pQb¨RS\nCkXԊUB(c"7  e%c r:J@f.Aף'YJJ #4w9R0`aDS{zDeSgd@^ XqEҠv V-oӶ)UQ`e)z" 5+=[-3d@uJʞC-"2n$QUjEj PUEcVeWdM7T b,%EZXQ^t -X,[wJ?%݅I/jC'YfO~Itѯ$_+(6o7)尩\O;6"w~Ҟ3rMSIw9|Ο}TO0^/*׈}w;4 _ `K&O|kDW_)<:NOmrOjJMg~l;ڭoXygw:-nm+%.^Ozw/=zu/ -‚g|'59l0n-ZnuoSKNJæX-*7mBijws6?znujw6](YOl`ꞥ=Փ].?{=O}*ã}-.{]v>~ʗXI+Qx JV)!05蘃崓kvN_=*vg&vHK& $$'ԧβ& RЛ fmط怬 \{0]J 0% qعrI8R^+* "əUl eVC(D_ZRʚ )@,.fbY ;=pɵ.CiHW% 1OCZ (PeMyc)_5r "L|ی $A9NEnHH4JUVdH\\f! 5Dw12g嫍r@ءE!/L !K @-)77>hbⱡyZSI!@aذ7 eQt1 غ 9`钛/\š! W]C3$$]ڙPDX@%jBI9/lB׋)3/+xiD80PV`2Z@``-RBb6KlP)Ц zQN]1ў *JP  EÂʤEJG稠{eF+ 1T' [-z-~-O {;- xF&+/jzy9BuE[RZ3W61MRcxآب2HM.^$k^\, ąwq D)"A!T ΠFEvs]TF ju  ՗:ZV&$X`NҰB*&G\NE1(,WPm&"Ct99%V.0G2IYwm;PZ(fFb6bд! &l6!BRI a.]I!m$S3RɣR1԰X%]Jd a2!\XAc:*oLWiJ[%䗽 qV,0 i\pUO$3aaRc (sV Pm9EY.Rf' Rl qz-I~NDpAG%fzI.c8Xk.xifܮl1EVJ%ZfZMKG2tyfl7O AZC@~ZXLMɱhImfsϝVfaNˆyjIo؜S#wק2J, mZ#4fr%x?P" DuOv*Z؎6KjiuvØÜ (;fw$iᨓ_%-zԺL.reUvjQ,iߌFw'J"J`N/ >xBU{* Ė4+ l)T!&=ת xƺ-]ܗ{ZrcCFܒ!\۝8VsqwStjz1QNӆ_t`a>CޑX:h{em%=BP ;. ^/~Ջukct;uksw p++m3s ssdUZZ7_U7;RoEת ;oJ+[KQec#kshNxa鐬3)`+Z!h4Ґ~Ǝ%뢇1^zn64d6H,ۦ6ŒAa2 ik[v s3.GJlx⛙ӷ--&Ӏ(.6d@TOo-#e΄_;4\ڼn\LKk瘟31XNx#ϵ3k㵻X\qӫ;wմLڲ ־4[ZLiKCT[oizU]=jqbsgKuBP_cygGza$ s'08-)7ψeQKM4hnOKhv޹Ci/bB1: *_nSjo_vjE -۟O~Ͼ#hŏo6{FYEҿ|j  u<|=|2Z}ΑzgrTRkH#"fѮ ,\I&Ks%~j2Ob;QtW4T4p+sfY@/"  #&[koT"i׸HP C S4 i -˜p,MoVÙo5P^óNp%f!&Bf )FPk PL f̢