samba-test-4.19.8+git.404.38b26805d4-150600.3.12.2<>, k`g.p9|i*.g +~b ?6rbcj\/u#nTD| HLxr>$Ť荐}8Tic ݱ߳*à"=&z o-ZqnW`u?@PalR|X`peo eQ/<NYӆgx_!JH~4δJcT1-S9Fdag_ X@j(X2~dU 񢳫#Y$|XÒk;T QiB2PV>@|?ld ' 5 a -AX^h     *p 9;(:o8:x%9? %:R%>A@PF_GtHIXY\L]^7bkcdefluvwxxyz  &hCsamba-test4.19.8+git.404.38b26805d4150600.3.12.2Testing tools for Samba servers and clientssamba-test provides testing tools for both the server and client packages of Samba.g.h03-ch2bSUSE Linux Enterprise 15SUSE LLC GPL-3.0-or-laterhttps://www.suse.com/Applications/Systemhttps://www.samba.org/linuxx86_64B(Hh8@G Sс큤g.pg.pg.pg.pg.pg.qg.4g.4g.4g.0g.3g.4g.1g.1209d5dc382a7354125d1f8d140e202cd23661f809eee4e54a891da598e925cac7199ef0fba39c91108cccc249e2f6f3afd172e4ba8ca27a0dd8c655846ff9cde9df6a343e5840eb4eddc01fd4d19ab5327a0063e6bc2631bdc869d0f51a5b84a7c96af3186e54e5bec467e40dc8b2735a7601bce353acd064eea914e5ca5ce396ebdcaf1d7e2bd67f475e0ccdc8cd93b16f06f734c934704a6399d1b788616834192f7ed0ba805d6e599039be9b89cdfaa0c76d3c16c61a645e6bda3d0a0f71a438bcf84f2efc53401881f56fec827d2b45e122b0656bdf341f0e99d7dbba977cf6c249c630c384c4f3de001ea54a8bc3a4ffb241e7b69214f92639a54afdb2315e18f7bfaeddce2eaa53e69466a38e2ae0fb2f20f96a200b9b3da85be90294ea380cf047ffbe0400b1e143dfc2c3248583584627c4dfcad0dd21afc3a051795f8bcc2c26c354f3a9a89b45b25f9ee62a7bd26a5c65bd539a62be1385530f01da96e9e825c7de506afbbcd15edba17c36dd670cd79312254509c176684581901e4659aca2d00b679ecdf4fc981886d59b57f9fd297f100e2b38df30456a7d587d94ba66fe1ade6d58d303112310095c3975a6e9ca1c4a5923bc76c8e19f4a8ferootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsamba-4.19.8+git.404.38b26805d4-150600.3.12.2.src.rpmsamba-testsamba-test(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    /sbin/ldconfig/sbin/ldconfiglibLIBWBCLIENT-OLD-samba4.so()(64bit)libLIBWBCLIENT-OLD-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libMESSAGING-SEND-samba4.so()(64bit)libMESSAGING-SEND-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libMESSAGING-samba4.so()(64bit)libMESSAGING-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libRPC-SERVER-LOOP-samba4.so()(64bit)libRPC-SERVER-LOOP-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libads-samba4.so()(64bit)libads-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libasn1util-samba4.so()(64bit)libasn1util-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libauth-samba4.so()(64bit)libauth-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libauthkrb5-samba4.so()(64bit)libauthkrb5-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.2)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.32)(64bit)libc.so.6(GLIBC_2.33)(64bit)libc.so.6(GLIBC_2.34)(64bit)libc.so.6(GLIBC_2.38)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.8)(64bit)libcli-cldap-samba4.so()(64bit)libcli-cldap-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libcli-ldap-common-samba4.so()(64bit)libcli-ldap-common-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libcli-ldap-samba4.so()(64bit)libcli-ldap-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libcli-nbt-samba4.so()(64bit)libcli-nbt-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libcli-smb-common-samba4.so()(64bit)libcli-smb-common-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libcliauth-samba4.so()(64bit)libcliauth-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libcluster-samba4.so()(64bit)libcluster-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libcmdline-contexts-samba4.so()(64bit)libcmdline-contexts-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libcmdline-samba4.so()(64bit)libcmdline-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libcom_err.so.2()(64bit)libcommon-auth-samba4.so()(64bit)libcommon-auth-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libdbwrap-samba4.so()(64bit)libdbwrap-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libdcerpc-binding.so.0()(64bit)libdcerpc-binding.so.0(DCERPC_BINDING_0.0.1)(64bit)libdcerpc-samba-samba4.so()(64bit)libdcerpc-samba-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libdcerpc-samba4.so()(64bit)libdcerpc-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libdcerpc-server-core.so.0()(64bit)libdcerpc-server-core.so.0(DCERPC_SERVER_CORE_0.0.1)(64bit)libdcerpc.so.0()(64bit)libdcerpc.so.0(DCERPC_0.0.1)(64bit)libdsdb-module-samba4.so()(64bit)libdsdb-module-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libevents-samba4.so()(64bit)libevents-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libflag-mapping-samba4.so()(64bit)libflag-mapping-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libgenrand-samba4.so()(64bit)libgenrand-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libgensec-samba4.so()(64bit)libgensec-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libgnutls.so.30()(64bit)libgnutls.so.30(GNUTLS_3_4)(64bit)libgnutls.so.30(GNUTLS_3_6_13)(64bit)libgnutls.so.30(GNUTLS_3_6_3)(64bit)libgse-samba4.so()(64bit)libgse-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libidmap-samba4.so()(64bit)libidmap-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libk5crypto.so.3()(64bit)libk5crypto.so.3(k5crypto_3_MIT)(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libkrb5samba-samba4.so()(64bit)libkrb5samba-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libldb.so.2(LDB_0.9.15)(64bit)libldb.so.2(LDB_0.9.16)(64bit)libldb.so.2(LDB_1.1.14)(64bit)libldb.so.2(LDB_2.0.1)(64bit)libldb.so.2(LDB_2.8.0)(64bit)libldbsamba-samba4.so()(64bit)libldbsamba-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)liblibcli-lsa3-samba4.so()(64bit)liblibcli-lsa3-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)liblibcli-netlogon3-samba4.so()(64bit)liblibcli-netlogon3-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)liblibsmb-samba4.so()(64bit)liblibsmb-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libmsrpc3-samba4.so()(64bit)libmsrpc3-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-samba-samba4.so()(64bit)libndr-samba-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libndr-samba4.so()(64bit)libndr-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libndr-standard.so.0()(64bit)libndr-standard.so.0(NDR_STANDARD_0.0.1)(64bit)libndr.so.3()(64bit)libndr.so.3(NDR_0.0.1)(64bit)libndr.so.3(NDR_0.0.3)(64bit)libndr.so.3(NDR_0.0.4)(64bit)libndr.so.3(NDR_0.0.8)(64bit)libndr.so.3(NDR_0.0.9)(64bit)libndr.so.3(NDR_0.2.0)(64bit)libndr.so.3(NDR_1.0.0)(64bit)libnetapi.so.1()(64bit)libnetapi.so.1(NETAPI_1.0.0)(64bit)libnetif-samba4.so()(64bit)libnetif-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libnss-info-samba4.so()(64bit)libnss-info-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libprinter-driver-samba4.so()(64bit)libprinter-driver-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libreadline.so.7()(64bit)libregistry-samba4.so()(64bit)libregistry-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libreplace-samba4.so()(64bit)libreplace-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsamba-credentials.so.1()(64bit)libsamba-credentials.so.1(SAMBA_CREDENTIALS_1.0.0)(64bit)libsamba-debug-samba4.so()(64bit)libsamba-debug-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsamba-errors.so.1()(64bit)libsamba-errors.so.1(SAMBA_ERRORS_1.0.0)(64bit)libsamba-hostconfig.so.0()(64bit)libsamba-hostconfig.so.0(SAMBA_HOSTCONFIG_0.0.1)(64bit)libsamba-modules-samba4.so()(64bit)libsamba-modules-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsamba-net.cpython-36m-x86-64-linux-gnu-samba4.so()(64bit)libsamba-net.cpython-36m-x86-64-linux-gnu-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsamba-passdb.so.0()(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.2.0)(64bit)libsamba-security-samba4.so()(64bit)libsamba-security-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsamba-sockets-samba4.so()(64bit)libsamba-sockets-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsamba-util.so.0()(64bit)libsamba-util.so.0(SAMBA_UTIL_0.0.1)(64bit)libsamba3-util-samba4.so()(64bit)libsamba3-util-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsamdb-common-samba4.so()(64bit)libsamdb-common-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsamdb.so.0()(64bit)libsamdb.so.0(SAMDB_0.0.1)(64bit)libsecrets3-samba4.so()(64bit)libsecrets3-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libserver-id-db-samba4.so()(64bit)libserver-id-db-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libshares-samba4.so()(64bit)libshares-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsmbclient-raw-samba4.so()(64bit)libsmbclient-raw-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsmbclient.so.0()(64bit)libsmbclient.so.0(SMBCLIENT_0.1.0)(64bit)libsmbclient.so.0(SMBCLIENT_0.3.1)(64bit)libsmbclient.so.0(SMBCLIENT_0.3.2)(64bit)libsmbclient.so.0(SMBCLIENT_0.3.3)(64bit)libsmbclient.so.0(SMBCLIENT_0.5.0)(64bit)libsmbclient.so.0(SMBCLIENT_0.6.0)(64bit)libsmbconf.so.0()(64bit)libsmbconf.so.0(SMBCONF_0.0.1)(64bit)libsmbd-shim-samba4.so()(64bit)libsmbd-shim-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsmbpasswdparser-samba4.so()(64bit)libsmbpasswdparser-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsocket-blocking-samba4.so()(64bit)libsocket-blocking-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsys-rw-samba4.so()(64bit)libsys-rw-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtalloc.so.2(TALLOC_2.0.8)(64bit)libtalloc.so.2(TALLOC_2.1.0)(64bit)libtalloc.so.2(TALLOC_2.3.5)(64bit)libtdb-wrap-samba4.so()(64bit)libtdb-wrap-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtevent-util.so.0()(64bit)libtevent-util.so.0(TEVENT_UTIL_0.0.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.11.0)(64bit)libtevent.so.0(TEVENT_0.12.0)(64bit)libtevent.so.0(TEVENT_0.13.0)(64bit)libtevent.so.0(TEVENT_0.15.0)(64bit)libtevent.so.0(TEVENT_0.9.12)(64bit)libtevent.so.0(TEVENT_0.9.13)(64bit)libtevent.so.0(TEVENT_0.9.16)(64bit)libtevent.so.0(TEVENT_0.9.20)(64bit)libtevent.so.0(TEVENT_0.9.26)(64bit)libtevent.so.0(TEVENT_0.9.30)(64bit)libtevent.so.0(TEVENT_0.9.31)(64bit)libtevent.so.0(TEVENT_0.9.36)(64bit)libtevent.so.0(TEVENT_0.9.37)(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libtime-basic-samba4.so()(64bit)libtime-basic-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libtorture-samba4.so()(64bit)libtorture-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libtrusts-util-samba4.so()(64bit)libtrusts-util-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libutil-reg-samba4.so()(64bit)libutil-reg-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libutil-tdb-samba4.so()(64bit)libutil-tdb-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_X86_64_SAMBA4)(64bit)libwbclient.so.0()(64bit)libwbclient.so.0(WBCLIENT_0.10)(64bit)libwbclient.so.0(WBCLIENT_0.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)sambasamba-winbind3.0.4-14.6.0-14.0-15.2-14.19.8+git.404.38b26805d44.19.8+git.404.38b26805d44.14.3gRgR@gMgp@fٝ@fxfteԔ@ee5@ede6`@e-%e'e%ascabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comddiss@suse.comscabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comdmulder@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comscabrero@suse.dedmulder@suse.comscabrero@suse.denopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedimstar@opensuse.orgscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.denopower@suse.comscabrero@suse.deddiss@suse.comddiss@suse.comddiss@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comscabrero@suse.descabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comdmulder@suse.comscabrero@suse.denopower@suse.comddiss@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comddiss@suse.comddiss@suse.comnopower@suse.comnopower@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comddiss@suse.comscabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comjengelh@inai.dedmulder@suse.comscabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comdmulder@suse.comdmulder@suse.comjmcdonough@suse.comdmulder@suse.comscabrero@suse.dedmulder@suse.comscabrero@suse.dedmulder@suse.comdmulder@suse.comvcizek@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.dejmcdonough@suse.comscabrero@suse.deaaptel@suse.comjengelh@inai.dedimstar@opensuse.orgdmulder@suse.comjmcdonough@suse.comdavid.mulder@suse.comjmcdonough@suse.comaaptel@suse.comdmulder@suse.comscabrero@suse.comscabrero@suse.comkukuk@suse.dedavid.mulder@suse.comscabrero@suse.comrbrown@suse.comdmulder@suse.comscabrero@suse.comdimstar@opensuse.orgscabrero@suse.comaaptel@suse.comnopower@suse.comnopower@suse.comaaptel@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comddiss@suse.comnopower@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comdmulder@suse.comnopower@suse.comjmcdonough@suse.comaaptel@suse.comkukuk@suse.comkukuk@suse.denopower@suse.comaaptel@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comddiss@suse.comjmcdonough@suse.comddiss@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comtchvatal@suse.comlmuelle@suse.comnopower@suse.comcrrodriguez@opensuse.orglmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnoel.power@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.commpluskal@suse.comlmuelle@suse.comnopower@suse.deddiss@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.denopower@suse.delmuelle@suse.comnopower@suse.deddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.com- Fix crossing automounter mount points; (bsc#1215212); (bsc#1236803);- Update shipped /etc/samba/smb.conf to point to smb.conf man page;(bsc#1233880).- Update to 4.19.9 * libldb: performance issue with indexes (ldb 2.8.2 is already released); (bso#15590). * DH reconnect error handling can lead to stale sharemode entries; (bso#15624). * Incorrect FSCTL_QUERY_ALLOCATED_RANGES response when truncated; (bso#15699). * irpc_destructor may crash during shutdown; (bso#15280). * Compound SMB2 requests don't return NT_STATUS_NETWORK_SESSION_EXPIRED for all requests, confuses MacOSX clients; (bso#15696). * Crash when readlinkat fails; (bso#15700).- Adjust spec to split out rpcd_* binaries into a separate sub package; (bsc#1231414).- Incorrect FSCTL_QUERY_ALLOCATED_RANGES response when truncated; (bso#15699); (bsc#1229684). - Update to 4.19.8 * Invalid client warning about command line passwords; (bso#15671); * Version string is truncated in manpages; (bso#15672); * --version-* options are still not ergonomic, and they reject tilde characters; (bso#15673); * cmdline_burn does not always burn secrets; (bso#15674); * Samba doesn't parse SDDL found in defaultSecurityDescriptor in AD_DS_Classes_Windows_Server_v1903.ldf; (bso#15685); * We have added new options --vendor-name and --vendor-patch- revision arguments to ./configure to allow distributions and packagers to put their name in the Samba version string so that when debugging Samba the source of the binary is obvious; (bso#15654); * When claims enabled with heimdal kerberos, unable to log on to a Windows computer when user account need to change their own password; (bso#15655); * Fix clock skew error message and memory cache clock skew recovery; (bso#15676); * CTDB RADOS mutex helper misses namespace support; (bso#15665); * The images don't build after the git security release and CentOS 8 Stream is EOL; (bso#15660); * Fix unnecessary delays in CTDB while processing requests under high load; (bso#15678); * Dynamic DNS updates with the internal DNS are not working; (bso#13019); * s4:nbt_server: does not provide unexpected handling, so winbindd can't use nmb requests instead cldap; (bso#15620); * Panic in vfs_offload_token_db_fetch_fsp(); (bso#15664); * "client use kerberos" and --use-kerberos is ignored for the machine account; (bso#15666); * Regression DFS not working with widelinks = true; (bso#15435); * ntlm_auth make logs more consistent with length check; (bso#15677);- Fix a crash when joining offline and 'kerberos method' includes keytab; (bsc#1228732); - Fix reading the password from STDIN or environment vars if it was already given in the command line; (bsc#1228732);- Update to 4.19.7 * ldb qsort might r/w out of bounds with an intransitive compare function (ldb 2.8.1 is already released); (bso#15569). * Many qsort() comparison functions are non-transitive, which can lead to out-of-bounds access in some circumstances (ldb 2.8.1 is already released); (bso#15625). * Need to change gitlab-ci.yml tags in all branches to avoid CI bill; (bso#15638). * netr_LogonSamLogonEx returns NR_STATUS_ACCESS_DENIED with SysvolReady=0; (bso#14981). * Anonymous smb3 signing/encryption should be allowed (similar to Windows Server 2022); (bso#15412). * Panic in dreplsrv_op_pull_source_apply_changes_trigger; (bso#15573). * winbindd, net ads join and other things don't work on an ipv6 only host; (bso#15642). * Smbcacls incorrectly propagates inheritance with Inherit-Only flag; (bso#15636). * http library doesn't support 'chunked transfer encoding'; (bso#15611). - Update to 4.19.6 * fd_handle_destructor() panics within an smbd_smb2_close() if vfs_stat_fsp() fails in fd_close(); (bso#15527). * samba-gpupdate: Correctly implement site support; (bso#15588). * libgpo: Segfault in python bindings; (bso#15599). * Packet marshalling push support missing for CTDB_CONTROL_TCP_CLIENT_DISCONNECTED and CTDB_CONTROL_TCP_CLIENT_PASSED; (bso#15580).- Update to 4.19.5 * Windows 2016 fails to restore previous version of a file from a shadow_copy2 snapshot; (bso#13688). * Symlinks on AIX are broken in 4.19 (and a few version before that); (bso#15549). * Fake directory create times has no effect; (bso#12421). * ctime mixed up with mtime by smbd; (bso#15550). * samba-gpupdate --rsop fails if machine is not in a site; (bso#15548). * gpupdate: The root cert import when NDES is not available is broken; (bso#15557). * samba-gpupdate should print a useful message if cepces-submit can't be found; (bso#15552). * samba-gpupdate logging doesn't work; (bso#15558). * smbpasswd reset permissions only if not 0600; (bso#15555).- Remove -x from bash shebang update-apparmor-samba-profile; (bsc#1218431).- Update to 4.19.4 * net changesecretpw cannot set the machine account password if secrets.tdb is empty; (bso#13577). * For generating doc, take, if defined, env XML_CATALOG_FILES; (bso#15540). * Trivial C typo in nsswitch/winbind_nss_netbsd.c; (bso#15541). * vfs_linux_xfs is incorrectly named; (bso#15542). * systemd stumbled over copyright-message at smbd startup; (bso#15377). * Following intermediate abolute share-local symlinks is broken; (bso#15505). * ctdb RELEASE_IP causes a crash in release_ip if a connection to a non-public address disconnects first; (bso#15523). * shadow_copy2 broken when current fileset's directories are removed; (bso#15544). * smbd does not detect ctdb public ipv6 addresses for multichannel exclusion; (bso#15534). * 'force user = localunixuser' doesn't work if 'allow trusted domains = no' is set; (bso#15469). * smbget debug logging doesn't work; (bso#15525). * smget: username in the smburl and interactive password entry doesn't work; (bso#15532). * smbget auth function doesn't set values for password prompt correctly; (bso#15538). * Unable to copy and write files from clients to Ceph cluster via SMB Linux gateway with Ceph VFS module; (bso#15440). * Multichannel refresh network information; (bso#15547).- Update to 4.19.3 * sid_strings test broken by unix epoch > 1700000000; (bso#15520). * smbd crashes if asked to return full information on close of a stream handle with delete on close disposition set; (bso#15487). * smbd: fix close order of base_fsp and stream_fsp in smb_fname_fsp_destructor(); (bso#15521). * Improve logging for failover scenarios; (bso#15499). * Files without "read attributes" NFS4 ACL permission are not listed in directories; (bso#15093). * CVE-2018-14628 [SECURITY] Deleted Object tombstones visible in AD LDAP to normal users; (bso#13595). * Kerberos TGS-REQ with User2User does not work for normal accounts; (bso#15492). * vfs_gpfs stat calls fail due to file system permissions; (bso#15507). * Samba doesn't build with Python 3.12; (bso#15513).- packaging: samba-tool domain provision requires python3-Markdown; (bsc#1216519).- Update to 4.19.2 * Use-after-free in aio_del_req_from_fsp during smbd shutdown after failed IPC FSCTL_PIPE_TRANSCEIVE; (bso#15423). * clidfs.c do_connect() missing a "return" after a cli_shutdown() call; (bso#15426). * macOS mdfind returns only 50 results; (bso#15463). * GETREALFILENAME_CACHE can modify incoming new filename with previous cache entry value; (bso#15481). * libnss_winbind causes memory corruption since samba-4.18, impacts sendmail, zabbix, potentially more; (bso#15464). * ctdbd: setproctitle not initialized messages flooding logs; (bso#15479). * CVE-2023-5568 Heap buffer overflow with freshness tokens in the Heimdal KDC in Samba 4.19; (bso#15491). * The heimdal KDC doesn't detect s4u2self correctly when fast is in use; (bso#15477).- use systemd-logind rather than utmp for y2038 safety; (bsc#1216159).- CVE-2023-4091: samba: Client can truncate file with read-only permissions; (bsc#1215904); (bso#15439). - CVE-2023-42669: samba: rpcecho, enabled and running in AD DC, allows blocking sleep on request; (bso#1215905); (bso#15474). - CVE-2023-42670: samba: The procedure number is out of range when starting Active Directory Users and Computers; (bsc#1215906); (bso#15473). - CVE-2023-3961: samba: Unsanitized client pipe name passed to local_np_connect(); (bsc#1215907); (bso#15422). - CVE-2023-4154: samba: dirsync allows SYSTEM access with only "GUID_DRS_GET_CHANGES" right, not "GUID_DRS_GET_ALL_CHANGES; (bsc#1215908); (bso#15424).- Update to 4.19.0 * File doesn't show when user doesn't have permission if aio_pthread is loaded; (bso#15453). * ctdb_killtcp fails to work with --enable-pcap and libpcap ≥ 1.9.1; (bso#15451). * Logging to stdout/stderr with DEBUG_SYSLOG_FORMAT_ALWAYS can log to syslog; (bso#15460). * ‘samba-tool domain level raise’ fails unless given a URL; (bso#15458). * reply_sesssetup_and_X() can dereference uninitialized tmp pointer; (bso#15420). * missing return in reply_exit_done(); (bso#15430). * TREE_CONNECT without SETUP causes smbd to use uninitialized pointer; (bso#15432). * Avoid infinite loop in initial user sync with Azure AD Connect when synchronising a large Samba AD domain; (bso#15401). * Samba replication logs show (null) DN; (bso#15407). * 2-3min delays at reconnect with smb2_validate_sequence_number: bad message_id 2; (bso#15346). * DCERPC_PKT_CO_CANCEL and DCERPC_PKT_ORPHANED can't be parsed; (bso#15446). * CID 1539212 causes real issue when output contains only newlines; (bso#15438). * KDC encodes INT64 claims incorrectly; (bso#15452). * mdssvc: Do an early talloc_free() in _mdssvc_open(); (bso#15449). * Windows client join fails if a second container CN=System exists somewhere; (bso#9959). * regression DFS not working with widelinks = true; (bso#15435). * Heimdal fails to build on 32-bit FreeBSD; (bso#15443). * samba-tool ntacl get segfault if aio_pthread appended; (bso#15441). - Update to 4.18.6 * reply_sesssetup_and_X() can dereference uninitialized tmp pointer; (bso#15420); * Missing return in reply_exit_done(); (bso#15430); * post-exec password redaction for samba-tool is more reliable for fully random passwords as it no longer uses regular expressions containing the password value itself; (bso#15289); * Windows client join fails if a second container CN=System exists somewhere; (bso#9959); * Spotlight sometimes returns no results on latest macOS; (bso#15342); * Renaming results in NT_STATUS_SHARING_VIOLATION if previously attempted to remove the destination; (bso#15417); * Spotlight results return wrong date in result list; (bso#15427); * "net offlinejoin provision" does not work as non-root user; (bso#15414); * rpcserver no longer accepts double backslash in dfs pathname; (bso#15400); * cm_prepare_connection() calls close(fd) for the second time; (bso#15433); * 2-3min delays at reconnect with smb2_validate_sequence_number: bad message_id 2; (bso#15346); * samba-tool ntacl get segfault if aio_pthread appended; (bso#15441); * DCERPC_PKT_CO_CANCEL and DCERPC_PKT_ORPHANED can't be parsed; (bso#15446); * Python tarfile extraction needs change to avoid a warning (CVE-2007-4559 mitigation); (bso#15390); * Regression DFS not working with widelinks = true; (bso#15435); * mdssvc: Do an early talloc_free() in _mdssvc_open(); (bso#15449); - Update to 4.18.5 * CVE-2022-2127: lm_resp_len not checked properly in winbindd_pam_auth_crap_send; (bso#15072); (bsc#1213174). * CVE-2023-34966: Samba Spotlight mdssvc RPC Request Infinite Loop Denial-of-Service Vulnerability; (bso#15340); (bsc#1213173). * CVE-2023-34967: Samba Spotlight mdssvc RPC Request Type Confusion Denial-of-Service Vulnerability; (bso#15341); (bsc#1213172). * CVE-2023-34968: Spotlight server-side Share Path Disclosure; (bso#15388); (bsc#1213171). * CVE-2023-3347: Samba doesn't require SMB2+ signing if `server signing = mandatory` is set; (bso#15397); (bsc#1213170). * secure channel faulty since Windows 10/11 update 07/2023; (bso#15418); (bsc#1213384). - Update to 4.18.4 * Backport --pidl-developer fixes; (bso#15404). * Named crashes on DLZ zone update; (bso#14030). * smbcacls and smbcquotas do not check // before the server; (bso#2312). * cli_list loops 100% CPU against pre-lanman2 servers; (bso#15382). * smbclient leaks fds with showacls; (bso#15391). * smbd returns NOT_FOUND when creating files on a r/o filesystem; (bso#15402). * NSS_WRAPPER_HOSTNAME doesn't match NSS_WRAPPER_HOSTS entry and causes test timeouts; (bso#15355). * net ads lookup (with unspecified realm) fails; (bso#15384). * Register Samba processes with GPFS; (bso#15381). * Python tarfile extraction needs change to avoid a warning (CVE-2007-4559 mitigation); (bso#15390). * The winbind child segfaults when listing users with `winbind scan trusted domains = yes`; (bso#15398). * Remove comments about deprecated 'write cache size'; (bso#15383). * smbget memory leak if failed to download files recursively; (bso#15403). - Update to 4.18.3 * Symlinks to files can have random DOS mode information in a directory listing; (bso#15375). * vfs_fruit might cause a failing open for delete; (bso#15378). * winbind recurses into itself via rpcd_lsad; (bso#15361). * wbinfo -u fails on ad dc with >1000 users; (bso#15366). * DS ACEs might be inherited to unrelated object classes; (bso#15338). * a lot of messages: get_static_share_mode_data: get_static_share_mode_data_fn failed: NT_STATUS_NOT_FOUND; (bso#15362). * aes256 smb3 encryption algorithms are not allowed in smb3_sid_parse(); (bso#15374). * Setting veto files = /.*/ break listing directories; (bso#15360). * "samba-tool domain provision" does not run interactive mode if no arguments are given; (bso#15363). * dsgetdcname: assumes local system uses IPv4; (bso#15325). - Update to 4.18.2 * Log flood: smbd_calculate_access_mask_fsp: Access denied: message level should be lower; (bso#15302). * Floating point exception (FPE) via cli_pull_send at source3/libsmb/clireadwrite.c; (bso#15306). * test_tstream_more_tcp_user_timeout_spin fails intermittently on Rackspace GitLab runners; (bso#15328). * Reduce flapping of ridalloc test; (bso#15329). * large_ldap test is unreliable; (bso#15351). * New filename parser doesn't check veto files smb.conf parameter; (bso#15143). * mdssvc may crash when initializing; (bso#15354). * large directory optimization broken for non-lcomp path elements; (bso#15313). * streams_depot fails to create streams; (bso#15357). * shadow_copy2 and streams_depot don't play well together; (bso#15358). * Flapping tests in samba_tool_drs_show_repl.py; (bso#15316). * winbindd idmap child contacts the domain controller without a need; (bso#15317). * idmap_autorid may fail to map sids of trusted domains for the first time; (bso#15318). * idmap_hash doesn't use ID_TYPE_BOTH for reverse mappings; (bso#15319). * net ads search -P doesn't work against servers in other domains; (bso#15323). * Temporary smbXsrv_tcon_global.tdb can't be parsed; (bso#15353). * Tests use depricated and removed methods like assertRegexpMatches; (bso#15343). - Update to 4.18.1 * CVE-2023-0225: AD DC "dnsHostname" attribute can be deleted by unprivileged authenticated users. (bso#15276);(bsc#1209483). * CVE-2023-0614: Access controlled AD LDAP attributes can be discovered (bso#15270); (bsc#1209485). * CVE-2023-0922: Samba AD DC admin tool samba-tool sends passwords in cleartext(bso#15315);(bsc#1209481). * ldb wildcard matching makes excessive allocations; (bso#15331). * large_ldap test is inefficient; (bso#15332). - Update to 4.18.0 * SMB server performance improvements * More succinct samba-tool error messages * Color output with samba-tool --color The NO_COLOR environment variable will disable colour output * New samba-tool dsacl subcommand for deleting ACEs * New wbinfo option --change-secret-at * Net option to change the NT ACL default location * Azure AD / Office365 synchronization improvements- Fix DFS not working with widelinks enabled; (bsc#1213607); (bso#15435);- Move libcluster-samba4.so from samba-libs to samba-client-libs; (bsc#1213940);- net ads lookup with unspecified realm fails; (bso#15384); (bsc#1213826);- secure channel faulty since Windows 10/11 update 07/2023; (bso#15418); (bsc#1213384).- CVE-2022-2127: lm_resp_len not checked properly in winbindd_pam_auth_crap_send; (bso#15072); (bsc#1213174). - CVE-2023-34966: Samba Spotlight mdssvc RPC Request Infinite Loop Denial-of-Service Vulnerability; (bso#15340); (bsc#1213173). - CVE-2023-34967: Samba Spotlight mdssvc RPC Request Type Confusion Denial-of-Service Vulnerability; (bso#15341); (bsc#1213172). - CVE-2023-34968: Spotlight server-side Share Path Disclosure; (bso#15388); (bsc#1213171). - CVE-2023-3347: Samba doesn't require SMB2+ signing if `server signing = mandatory` is set; (bso#15397); (bsc#1213170).- Update to 4.17.9 * Backport --pidl-developer fixes; (bso#15404). * smbd_scavenger crashes when service smbd is stopped; (bso#15275). * vfs_fruit might cause a failing open for delete; (bso#15378). * named crashes on DLZ zone update; (bso#14030). * winbind recurses into itself via rpcd_lsad; (bso#15361). * cli_list loops 100% CPU against pre-lanman2 servers; (bso#15382). * smbclient leaks fds with showacls; (bso#15391). * aes256 smb3 encryption algorithms are not allowed in smb3_sid_parse(); (bso#15374). * winbindd gets stuck on NT_STATUS_RPC_SEC_PKG_ERROR; (bso#15413). * smbget memory leak if failed to download files recursively; (bso#15403).- Update to 4.17.8 * log flood: smbd_calculate_access_mask_fsp: Access denied: message level should be lower; (bso#15302). * Floating point exception (FPE) via cli_pull_send at source3/libsmb/clireadwrite.c; (bso#15306). * test_tstream_more_tcp_user_timeout_spin fails intermittently on Rackspace GitLab runners; (bso#15328). * Reduce flapping of ridalloc test; (bso#15329). * large_ldap test is unreliable; (bso#15351). * New filename parser doesn't check veto files smb.conf parameter; (bso#15143). * mdssvc may crash when initializing; (bso#15354). * Large directory optimization broken for non-lcomp path elements; (bso#15313). * streams_depot fails to create streams; (bso#15357). * shadow_copy2 and streams_depot don't play well together; (bso#15358). * wbinfo -u fails on ad dc with >1000 users; (bso#15366). * winbindd idmap child contacts the domain controller without a need; (bso#15317). * idmap_autorid may fail to map sids of trusted domains for the first time; (bso#15318). * idmap_hash doesn't use ID_TYPE_BOTH for reverse mappings; (bso#15319). * net ads search -P doesn't work against servers in other domains; (bso#15323). * DS ACEs might be inherited to unrelated object classes; (bso#15338). * Temporary smbXsrv_tcon_global.tdb can't be parsed; (bso#15353). * Setting veto files = /.*/ break listing directories; (bso#15360); (bsc#1212375). * CVE-2020-25720 [SECURITY] Create Child permission should not allow full write to all attributes (additional changes); (bso#14810). * dsgetdcname: assumes local system uses IPv4; (bso#15325).- Update to 4.17.7 * CVE-2023-0922: Samba AD DC admin tool samba-tool sends passwords in cleartext; (bso#15315); (bsc#1209481). * CVE-2023-0225: Samba AD DC "dnsHostname" attribute can be deleted by unprivileged authenticated users; (bso#15276); (bsc#1209483). * CVE-2023-0614: samba: Access controlled AD LDAP attributes can be discovered; (bso#15270); (bsc#1209485). * large_ldap test is inefficient; (bso#15332). * CVE-2020-25720 [SECURITY] Create Child permission should not allow full write to all attributes (additional changes); (bso#14810). - Update to 4.17.6 * streams_xattr is creating unexpected locks on folders; (bso#15314). * Use of the Azure AD Connect cloud sync tool is now supported for password hash synchronisation, allowing Samba AD Domains to synchronise passwords with this popular cloud environment; (bso#10635). * Spotlight doesn't work with latest macOS Ventura; (bso#15299). * New samba-dcerpc architecture does not scale gracefully; (bso#15310). * vfs_ceph incorrectly uses fsp_get_io_fd() instead of fsp_get_pathref_fd() in close and fstat; (bso#15307). * With clustering enabled samba-bgqd can core dump due to use after free; (bso#15293). * fd_load() function implicitly closes the fd where it should not; (bso#15311). - Update to 4.17.5 * smbc_getxattr() return value is incorrect; (bso#14808). * Compound SMB2 FLUSH+CLOSE requests from MacOSX are not handled correctly; (bso#15172). * synthetic_pathref AFP_AfpInfo failed errors; (bso#15210). * samba-tool gpo listall fails IPv6 only - finddcs() fails to find DC when there is only an AAAA record for the DC in DNS; (bso#15226). * smbd crashes if an FSCTL request is done on a stream handle; (bso#15236). * DFS links don't work anymore on Mac clients since 4.17; (bso#15277). * vfs_virusfilter segfault on access, directory edgecase (accessing NULL value); (bso#15283). * CVE-2022-38023 [SECURITY] Samba should refuse RC4 (aka md5) based SChannel on NETLOGON (additional changes); (bso#15240). * %U for include directive doesn't work for share listing (netshareenum); (bso#15243). * Shares missing from netshareenum response in samba 4.17.4; (bso#15266). * ctdb: use-after-free in run_proc; (bso#15269). * irpc_destructor may crash during shutdown; (bso#15280). * auth3_generate_session_info_pac leaks wbcAuthUserInfo; (bso#15286). * smbclient segfaults with use after free on an optimized build; (bso#15268). * smbstatus leaking files in msg.sock and msg.lock; (bso#15282). * Leak in wbcCtxPingDc2; (bso#15164). * Access based share enum does not work in Samba 4.16+; (bso#15265). * Crash during share enumeration; (bso#15267). * rep_listxattr on FreeBSD does not properly check for reads off end of returned buffer; (bso#15271). * Avoid relying on C89 features in a few places; (bso#15281).- Make (32bit) samba-libs conflict with old samba-ad-dc-libs package to satisfy installcheck.- Make samba-libs conflict with old samba-ad-dc-libs package to satisfy installcheck.- Remove non functioning ifup/ifdown samba-winbindd scripts; (bsc#1207414).- libdsdb-module-samba4 should be packaged as part of samba-libs and not samba-ad-dc-libs. Additionally no need for it to be removed conditionally.- Clean up logic for PAM migration settings in spec file.- Change with_dc default to 0 (for non TW builds), ADDC feature is deprecated and will no longer be included in >= SLE15-SP5; (jsc#PED-1122).- Update to 4.17.4 * CVE-2022-44640 Upstream Heimdal free of user-controlled pointer in FAST; (bsc#14929); * CVE-2021-20251 Bad password count not incremented atomically; (bsc#14611); * CVE-2022-42898 krb5_pac_parse() buffer parsing vulnerability; (bsc#15203); * CVE-2022-37966 rc4-hmac Kerberos session keys issued to modern servers; (bso#15237); * CVE-2022-37967 Kerberos constrained delegation ticket forgery possible against Samba AD DC; (bso#15231); * CVE-2022-38023 RC4/HMAC-MD5 NetLogon Secure Channel is weak and should be avoided; (bso#15240); * pam_winbind uses time_t and pointers assuming they are of the same size; (bso#15224); * Heimdal session key selection in AS-REQ examines wrong entry; (bso#15219); * filter-subunit is inefficient with large numbers of knownfails; (bso#15258); * smbd allows setting FILE_ATTRIBUTE_TEMPORARY on directories; (bso#15252); * The KDC logic arround msDs-supportedEncryptionTypes differs from Windows; (bso#13135); * libnet: change_password() doesn't work with dcerpc_samr_ChangePasswordUser4(); (bso#15206); * Heimdal session key selection in AS-REQ examines wrong entry; (bso#15219); * Memory leak in snprintf replacement functions; (bso#15230); * RODC doesn't reset badPwdCount reliable via an RWDC (CVE-2021-20251 regression); (bso#15253); * Prevent EBADF errors with vfs_glusterfs; (bso#15198); * %U for include directive doesn't work for share listing (netshareenum); (bso#15243); * Stack smashing in net offlinejoin requestodj; (bso#15257); * Windows 11 22H2 and Samba-AD 4.15 Kerberos login issue; (bso#15197); * Heimdal session key selection in AS-REQ examines wrong entry; (bso#15219); - Remove deprecated if-{down,up} scripts; (bsc#1206444); - Adjust the systemd drop-in file for named service; (bsc#1201689); * Paths are additive so do not repeat paths from named.service * Prefix the samba DLZ directory with "-" to ignore this path if it does not exists- Introduce without-smb1-server spec flag; (bsc#1205104); - Update to 4.17.3 * CVE-2022-42898: Samba buffer overflow vulnerabilities on 32-bit systems; (bsc#1205126); (bso#15203); - Replace obsolete python-gpgme with python-gpg * Upstream replaced it in v4.9.5 -- bso#13728 - Update to 4.17.2 * CVE-2022-3592 [SECURITY] samba: Wide links protection broken; (bso#15207); (bsc#1204499). * CVE-2022-3437 [SECURITY] samba: Buffer overflow in Heimdal unwrap_des3();(bso#15134); (bsc#1204254). - Update to 4.17.1 * CVE-2021-20251 [SECURITY] Bad password count not incremented atomically; (bso#14611). * smbXsrv_connection_shutdown_send result leaked; (bso#15174). * Flush on a named stream never completes; (bso#15182). * Permission denied calling SMBC_getatr when file not exists; (bso#15195). * Samba 4.5 sometimes cannot be upgraded to Samba 4.6 or later over DRS: WERROR_DS_DRA_MISSING_PARENT due to faulty GET_ANC; (bso#15189). * pytest: add file removal helpers for TestCaseInTempDir; (bso#15191). * CVE-2021-20251 [SECURITY] Bad password count not incremented atomically; (bso#14611). * Samba 4.5 sometimes cannot be upgraded to Samba 4.6 or later over DRS: WERROR_DS_DRA_MISSING_PARENT due to faulty GET_ANC; (bso#15189). * Flush on a named stream never completes; (bso#15182). * vfs_gpfs silently garbles timestamps > year 2106; (bso#15151). * CVE-2021-20251 [SECURITY] Bad password count not incremented atomically; (bso#14611). * multi-channel socket passing may hit a race if one of the involved processes already existed; (bso#15200). * memory leak on temporary of struct imessaging_post_state and struct tevent_immediate on struct imessaging_context (in rpcd_spoolss and maybe others); (bso#15201). * Since popt1.19 various use after free errors using result of poptGetArg are now exposed; (bso#15205); (boo#1204279). * Remove special case for O_CREAT in SMB_VFS_OPENAT from vfs_glusterfs; (bso#15192). * GETPWSID in memory cache grows indefinetly with each NTLM auth; (bso#15169). * CVE-2021-20251 [SECURITY] Bad password count not incremented atomically; (bso#14611). - Install a systemd drop-in file for named service to allow read/write access to the DLZ directory; (bsc#1201689); - Fix use after free errors resulting from using return of poptGetArg exposed since popt-1.19; (boo#1204279); (bso#15205). - s3: smbd: Fix memory leak in smbd_server_connection_terminate_done(); (bso#15174). - Disable SMB1 for tumbleweed builds. - Update to 4.17.0 * acl_xattr VFS module may unintentionally use filesystem permissions instead of ACL from xattr; (bso#15126). * Missing SMB2-GETINFO access checks from MS-SMB2 3.3.5.20.1; (bso#15153). * assert failed: !is_named_stream(smb_fname)") at ../../lib/util/fault.c:197; (bso#15161). * acl_xattr VFS module may unintentionally use filesystem permissions instead of ACL from xattr; (bso#15126). * assert failed: !is_named_stream(smb_fname)") at ../../lib/util/fault.c:197; (bso#15161). * Cross-node multi-channel reconnects result in SMB2 Negotiate returning NT_STATUS_NOT_SUPPORTED; (bso#15159). * winbind at info level debug can coredump when processing wb_lookupusergroups; (bso#15160). * Make use of glfs_*at() API calls in vfs_glusterfs; (bso#15157). * Possible use after free of connection_struct when iterating smbd_server_connection->connections; (bso#15128). * `net usershare add` fails with flag works with --long but fails with -l; (bso#15145). * acl_xattr VFS module may unintentionally use filesystem permissions instead of ACL from xattr; (bso#15126). * Performance regression on contended path based operations; (bso#15125). * Missing READ_LEASE break could cause data corruption; (bso#15148). * libsamba-errors uses a wrong version number; (bso#15141). * SMB1 negotiation can fail to handle connection errors; (bso#15152). * New filename parser doesn't check veto files smb.conf parameter; (bso#15143). * 4.17.rc1 still uses symlink-race prone unix_convert(); (bso#15144). * Backport fileserver related changed to 4.17.0rc2; (bso#15146). * Manpage for smbstatus json is missing; (bso#15147). * Backport fileserver related changed to 4.17.0rc2; (bso#15146). * Performance regression on contended path based operations; (bso#15125). * Backport fileserver related changed to 4.17.0rc2; (bso#15146). * Fix issues found by coverity in smbstatus json code; (bso#15140). * Backport fileserver related changed to 4.17.0rc2; (bso#15146). - Migration to /usr/etc: Saving user changed configuration files in /etc and restoring them while an RPM update. - Update to 4.16.4 * CVE-2022-2031: Samba AD users can bypass certain restrictions associated with changing passwords; (bsc#1201495); (bso#15047); * CVE-2022-32744: Samba AD users can forge password change requests for any user; (bsc#1201493); (bso#15074); * CVE-2022-32745: Samba AD users can crash the server process with an LDAP add or modify request; (bsc#1201492); (bso#15008); * CVE-2022-32746: Samba AD users can induce a use-after-free in the server process with an LDAP add or modify request; (bsc#1201490); (bso#15009); * CVE-2022-32742: Server memory information leak via SMB1; (bsc#1201496); (bso#15085); - Update to 4.16.3 * Using vfs_streams_xattr and deleting a file causes a panic; (bso#15099); * Add support for bind 9.18; (bso#14986); * logging dsdb audit to specific files does not work; (bso#15076); * Problem when winbind renews Kerberos; (bso#14979); (bsc#1196224); * Samba with new lorikeet-heimdal fails to build on gcc 12.1 in developer mode; (bso#15095); * Crash in streams_xattr because fsp->base_fsp->fsp_name is NULL; (bso#15105); * Crash in rpcd_classic - NULL pointer deference in mangle_is_mangled(); (bso#15118); * smbclient commands del & deltree fail with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556); * Fix check for chown when processing NFSv4 ACL; (bso#15120); * The pcap background queue process should not be stopped; (bso#15082); * testparm: Fix typo in idmap rangesize check; (bso#15097); * net ads info returns LDAP server and LDAP server name as null; (bso#15106); * ldconfig: /lib64/libsmbconf.so.0 is not a symbolic link; (bso#15108); * CTDB child process logging does not work as expected; (bso#15090); - Update spec file to fix the optional Heimdal DC build - Fix external trusts with MIT Kerberos 1.20 - Add missing samba-client requirement to samba-winbind package; (bsc#1198255); - Move pdb backends from package samba-libs to package samba-client-libs and remove samba-libs requirement from samba-winbind; (bsc#1200964); (bsc#1198255); - Add sysuser-shadow requirement for packages using systemd-sysusers - Use the canonical realm name to refresh the Kerberos tickets; (bsc#1196224); (bso#14979); - Moved logrotate files from user specific directory /etc/logrotate.d to vendor specific directory /usr/etc/logrotate.d. - Update to 4.16.2 * Use pathref fd instead of io fd in vfs_default_durable_cookie; (bso#15042); * vfs_gpfs with vfs_shadowcopy2 fail to restore file if original file had been deleted; (bso#15069); * Reintroduce netgroups support; (bso#15087); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); * Update from 4.15 to 4.16 breaks discovery of [homes] on standalone server from Win and IOS; (bso#15062); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * smbclient -E doesn't work as advertised; (bso#15075); * The samba background daemon doesn't refresh the printcap cache on startup; (bso#15081); * Out-by-4 error in smbd read reply max_send clamp; (bso#14443); - Fix samba4.blackbox.net_ads_dns_async test with bind9 >= 9.17.7 - Support building with MIT Kerberos 1.20 - Bronze bit and S4U support with MIT Kerberos 1.20 for Samba AD DC; (CVE-2020-17049); - Resource Based Constrained Delegation (RBCD) for Samba AD DC - Support building with gcc 12.1 - Use requires_eq macro to require the libldb2 version available at samba-dsdb-modules build time; (bsc#1199362); - Update to 4.16.1 * Share and server swapped in smbget password prompt; (bso#14831); * Durable handles won't reconnect if the leased file is written to; (bso#15022); * rmdir silently fails if directory contains unreadable files and hide unreadable is yes; (bso#15023); * SMB2_CLOSE_FLAGS_FULL_INFORMATION fails to return information on renamed file handle; (bso#15038); * Need to describe --builtin-libraries= better (compare with - -bundled-libraries); (bso#8731); * vfs_shadow_copy2 breaks "smbd async dosmode" sync fallback; (bso#14957); * shadow_copy2 fails listing snapshotted dirs with shadow:fixinodes; (bso#15035); * PAM Kerberos authentication incorrectly fails with a clock skew error; (bso#15046); * Username map - samba erroneously applies unix group memberships to user account entries; (bso#15041); * KVNO off by 100000; (bso#14951); * Uninitialized litemask in variable in vfs_gpfs module; (bso#15027); * vfs_gpfs recalls=no option prevents listing files; (bso#15055); * smbd doesn't handle UPNs for looking up names; (bso#15054); - Update update-apparmor-samba-profile script, replace non-printable delimiter with more human readable separator as sed can accept separators that can appear in the input data. - Fix update-apparmor-samba-profile script, sed doesn't like multibyte separators; (bsc#1198309). - Update to 4.16.0 * New samba-dcerpcd binary to provide DCERPC in the member server setup * Certificate Auto Enrollment * Ability to add ports to dns forwarder addresses in internal DNS backend * No longer using Linux mandatory locks for sharemodes * SMB1 protocol has been deprecated, particularly older dialects * SMB1 protocol SMBCopy command removed * SMB1 server-side wildcard expansion removed - Add python3-dnspython to samba-ad-dc recommens; (bsc#1187101); - Use systemd-sysusers to create system users; (bsc#1182847);- Install a systemd drop-in file for named service to allow read/write access to the DLZ directory; (bsc#1201689);- Update to 4.15.12 * CVE-2022-42898: samba: heimdal: Samba buffer overflow vulnerabilities on 32-bit systems; (bso#15203); (bsc#1205126). - Update to 4.15.11 * Allow rebuild of Centos 8 images after move to vault for Samba 4.15; (bso#15193). * CVE-2022-3437: samba: Buffer overflow in Heimdal unwrap_des3(); (bso#15134); (bsc#1204254)- Update to 4.15.10 * Possible use after free of connection_struct when iterating smbd_server_connection->connections; (bso#15128); (bsc#1200102). * smbXsrv_connection_shutdown_send result leaked; (bso#15174). * Spotlight RPC service returns wrong response when Spotlight is disabled on a share; (bso#15086). * acl_xattr VFS module may unintentionally use filesystem permissions instead of ACL from xattr; (bso#15126). * Missing SMB2-GETINFO access checks from MS-SMB2 3.3.5.20.1; (bso#15153). * assert failed: !is_named_stream(smb_fname)") at ../../lib/util/fault.c:197; (bso#15161). * Missing READ_LEASE break could cause data corruption; (bso#15148). * rpcclient can crash using setuserinfo(2); (bso#15124). * Samba fails to build with glibc 2.36 caused by including in libreplace; (bso#15132). * SMB1 negotiation can fail to handle connection errors; (bso#15152). * samba-tool domain join segfault when joining a samba ad domain; (bso#15078). - Update to 4.15.9 * CVE-2022-32742:SMB1 code does not correct verify SMB1write, SMB1write_and_close, SMB1write_and_unlock lengths; (bso#15085); (bsc#1201496). * CVE-2022-32746: samba: Use-after-free occurring in database audit logging; (bso#15009); (bso#15096); (bsc#1201490). * CVE-2022-2031: samba, ldb: AD users can bypass certain restrictions associated with changing passwords; (bso#15047); (bsc#1201495); * CVE-2022-32745: samba: ldb: AD users can crash the server process with an LDAP add or modify request; (bso#15008); (bso#15096); (bsc#1201492). * CVE-2022-2031: samba, ldb: AD users can bypass certain restrictions associated with changing passwords; (bso#15047); (bsc#1201495); * CVE-2022-32744: samba, ldb: AD users can forge password change requests for any user; (bso#15074); (bso#15047); (bsc#1201493).- CVE-2022-1615: Do not ignore errors in random number generation; (bso#15103); (bsc#1202976); - CVE-2022-32743: Implement validated dnsHostName write rights; (bso#14833); (bsc#1202803);- Fix Use after free when iterating smbd_server_connection->connections after tree disconnect failure; (bso#15128); (bsc#1200102).- CVE-2022-32746: samba: Use-after-free occurring in database audit logging; (bso#15009); (bso#15096); (bsc#1201490). - CVE-2022-32745: samba: ldb: AD users can crash the server process with an LDAP add or modify request; (bso#15008); (bso#15096); (bsc#1201492). - CVE-2022-2031: samba, ldb: AD users can bypass certain restrictions associated with changing passwords; (bso#15047); (bsc#1201495); - CVE-2022-32742:SMB1 code does not correct verify SMB1write, SMB1write_and_close, SMB1write_and_unlock lengths; (bso#15085); (bsc#1201496). - CVE-2022-32744: samba, ldb: AD users can forge password change requests for any user; (bso#15074); (bso#15047); (bsc#1201493).- Update to 4.15.8 * Use pathref fd instead of io fd in vfs_default_durable_cookie; (bso#15042); * Setting fruit:resource = stream in vfs_fruit causes a panic; (bso#15099); * Add support for bind 9.18; (bso#14986); * logging dsdb audit to specific files does not work; (bso#15076); * vfs_gpfs with vfs_shadowcopy2 fail to restore file if original file had been deleted; (bso#15069); * netgroups support removed; (bso#15087); (bsc#1199247); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); (bsc#1199734); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * smbclient commands del & deltree fail with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556); * vfs_gpfs recalls=no option prevents listing files; (bso#15055); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * Compile error in source3/utils/regedit_hexedit.c; (bso#15091); * ldconfig: /lib64/libsmbconf.so.0 is not a symbolic link; (bso#15108); * smbd doesn't handle UPNs for looking up names; (bso#15054); * Out-by-4 error in smbd read reply max_send clamp; (bso#14443); - Move pdb backends from package samba-libs to package samba-client-libs and remove samba-libs requirement from samba-winbind; (bsc#1200964); (bsc#1198255); - Use the canonical realm name to refresh the Kerberos tickets; (bsc#1196224); (bso#14979);- Fix smbclient commands del & deltree failing with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556).- Revert NIS support removal; (bsc#1199247);- Use requires_eq macro to require the libldb2 version available at samba-dsdb-modules build time; (bsc#1199362);- Add missing samba-client requirement to samba-winbind package; (bsc#1198255);- Update to 4.15.7 * Share and server swapped in smbget password prompt; (bso#14831); * Durable handles won't reconnect if the leased file is written to; (bso#15022); * rmdir silently fails if directory contains unreadable files and hide unreadable is yes; (bso#15023); * SMB2_CLOSE_FLAGS_FULL_INFORMATION fails to return information on renamed file handle; (bso#15038); * vfs_shadow_copy2 breaks "smbd async dosmode" sync fallback; (bso#14957); * shadow_copy2 fails listing snapshotted dirs with shadow:fixinodes; (bso#15035); * PAM Kerberos authentication incorrectly fails with a clock skew error; (bso#15046); * username map - samba erroneously applies unix group memberships to user account entries; (bso#15041); * NT_STATUS_ACCESS_DENIED translates into EPERM instead of EACCES in SMBC_server_internal; (bso#14983); * Simple bind doesn't work against an RODC (with non-preloaded users); (bso#13879); * Crash of winbind on RODC; (bso#14641); * uncached logon on RODC always fails once; (bso#14865); * KVNO off by 100000; (bso#14951); * LDAP simple binds should honour "old password allowed period"; (bso#15001); * wbinfo -a doesn't work reliable with upn names; (bso#15003); * Simple bind doesn't work against an RODC (with non-preloaded users); (bso#13879); * Uninitialized litemask in variable in vfs_gpfs module; (bso#15027); * Regression: create krb5 conf = yes doesn't work with a single KDC; (bso#15016);- Add provides to samba-client-libs package to fix upgrades from previous versions; (bsc#1197995);- Add missing samba-libs requirement to samba-winbind package; (bsc#1198255);- Update to 4.15.6 * Renaming file on DFS root fails with NT_STATUS_OBJECT_PATH_NOT_FOUND; (bso#14169); * Samba does not response STATUS_INVALID_PARAMETER when opening 2 objects with same lease key; (bso#14737); * NT error code is not set when overwriting a file during rename in libsmbclient; (bso#14938); * Fix ldap simple bind with TLS auditing; (bso#14996); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); * Problem when winbind renews Kerberos; (bso#14979); (bsc#1196224); * pam_winbind will not allow gdm login if password about to expire; (bso#8691); * virusfilter_vfs_openat: Not scanned: Directory or special file; (bso#14971); * DFS fix for AIX broken; (bso#13631); * Solaris and AIX acl modules: wrong function arguments; (bso#14974); * Function aixacl_sys_acl_get_file not declared / coredump; (bso#7239); * Regression: Samba 4.15.2 on macOS segfaults intermittently during strcpy in tdbsam_getsampwnam; (bso#14900); * Fix a use-after-free in SMB1 server; (bso#14989); * smb2_signing_decrypt_pdu() may not decrypt with gnutls_aead_cipher_decrypt() from gnutls before 3.5.2; (bso#14968); * Changing the machine password against an RODC likely destroys the domain join; (bso#14984); * authsam_make_user_info_dc() steals memory from its struct ldb_message *msg argument; (bso#14993); * Use Heimdal 8.0 (pre) rather than an earlier snapshot; (bso#14995); * Samba autorid fails to map AD users if id rangesize fits in the id range only once; (bso#14967);- Fix mismatched version of libldb2; (bsc#1196788). - Drop obsolete SuSEfirewall2 service files.- Drop obsolete Samba fsrvp v0->v1 state upgrade functionality; (bsc#1080338).- Fix ntlm authentications with "winbind use default domain = yes"; (bso#13126); (bsc#1173429); (bsc#1196308).- Fix samba-ad-dc status warning notification message by disabling systemd notifications in bgqd; (bsc#1195896); (bso#14947).- libldb version mismatch in Samba dsdb component; (bsc#1118508);- Update to 4.15.5 * CVE-2021-44141: UNIX extensions in SMB1 disclose whether the outside target of a symlink exists; (bso#14911); (bsc#1193690). * CVE-2021-44142: Out-of-Bound Read/Write on Samba vfs_fruit module; (bso#14914); (bsc#1194859). * CVE-2022-0336: Re-adding an SPN skips subsequent SPN conflict checks; bso#14950); (bsc#1195048).- CVE-2021-44141: Information leak via symlinks of existance of files or directories outside of the exported share; (bso#14911); (bsc#1193690); - CVE-2021-44142: Out-of-bounds heap read/write vulnerability in VFS module vfs_fruit allows code execution; (bso#14914); (bsc#1194859); - CVE-2022-0336: Samba AD users with permission to write to an account can impersonate arbitrary services; (bso#14950); (bsc#1195048);- Update to 4.15.4 * Duplicate SMB file_ids leading to Windows client cache poisoning; (bso#14928); * Failed to parse NTLMv2_RESPONSE length 95 - Buffer Size Error - NT_STATUS_BUFFER_TOO_SMALL; (bso#14932); * kill_tcp_connections does not work; (bso#14934); * Can't connect to Windows shares not requiring authentication using KDE/Gnome; (bso#14935); * smbclient -L doesn't set "client max protocol" to NT1 before calling the "Reconnecting with SMB1 for workgroup listing" path; (bso#14939); * Cross device copy of the crossrename module always fails; (bso#14940); * symlinkat function from VFS cap module always fails with an error; (bso#14941); * Fix possible fsp pointer deference; (bso#14942); * Missing pop_sec_ctx() in error path inside close_directory(); (bso#14944); * "smbd --build-options" no longer works without an smb.conf file; (bso#14945);- Use pkgconfig(krb5) as dependency for the -devel package: allow OBS to pick the right flavor of krb5-devel (full vs mini). - Do not require the 'krb5' symbol by samba-client-libs: this package has an automatic dependency due to linkage on libgssapi_krb5.so.2. Automatic deps are always better. - Do not require the 'krb5' symbol from samba-libs: samba-libs requires samba-client-libs, which in turn requires krb5 libraries. Samba-libs itself has no need for krb5 (but get it indirectly anyway).- Reorganize libs packages. Split samba-libs into samba-client-libs, samba-libs, samba-winbind-libs and samba-ad-dc-libs, merging samba public libraries depending on internal samba libraries into these packages as there were dependency problems everytime one of these public libraries changed its version (bsc#1192684). The devel packages are merged into samba-devel. - Rename package samba-core-devel to samba-devel - Add python-rpm-macros to build requirements - Update the symlink create by samba-dsdb-modules to private samba ldb modules following libldb2 changes from /usr/lib64/ldb/samba to /usr/lib64/ldb2/modules/ldb/samba- Update to 4.15.3 * Recursive directory delete with veto files is broken in 4.15.0; (bso#14878); * A directory containing dangling symlinks cannot be deleted by SMB2 alone when they are the only entry in the directory; (bso#14879); * SIGSEGV in rmdir_internals/synthetic_pathref - dirfsp is used uninitialized in rmdir_internals(); (bso#14892); * MaxQueryDuration not honoured in Samba AD DC LDAP; (bso#14694); * The CVE-2020-25717 username map [script] advice has undesired side effects for the local nt token; (bso#14901); (bsc#1192849); * User with multiple spaces (eg FredNurk) become un-deletable; (bso#14902); * Avoid storing NTTIME_THAW (-2) as value on disk; (bso#14127); * smbXsrv_client_global record validation leads to crash if existing record points at non-existing process; (bso#14882); * Crash in vfs_fruit asking for fsp_get_io_fd() for an XATTR call; (bso#14890); * Samba process doesn't log to logfile; (bso#14897); * set_ea_dos_attribute() fallback calling get_file_handle_for_metadata() triggers locking.tdb assert; (bso#14907); * Kerberos authentication on standalone server in MIT realm broken; (bso#14922); * Segmentation fault when joining the domain; (bso#14923); * Support for ROLE_IPA_DC is incomplete; (bso#14903); * rpcclient cannot connect to ncacn_ip_tcp services anymore; (bso#14767); * winexe crashes since 4.15.0 after popt parsing; (bso#14893); * net ads status -P broken in a clustered environment; (bso#14908); * Memory leak if ioctl(FSCTL_VALIDATE_NEGOTIATE_INFO) fails before smbd_smb2_ioctl_send; (bso#14788); * winbindd doesn't start when "allow trusted domains" is off; (bso#14899); * smbclient login without password using '-N' fails with NT_STATUS_INVALID_PARAMETER on Samba AD DC; (bso#14883); * A schannel client incorrectly detects a downgrade connecting to an AES only server; (bso#14912); * Possible null pointer dereference in winbind; (bso#14921); * Fix -k legacy option for client tools like smbclient, rpcclient, net, etc.; (bso#14846); * Add Debian 11 CI bootstrap support; (bso#14872); * Crash in recycle_unlink_internal(); (bso#14888);- Fix dependency problem upgrading from libndr0 to libndr2 and from libsamba-credentials0 to libsamba-credentials1; (bsc#1192684);- Fix regression introduced by CVE-2020-25717 patches, winbindd does not start when 'allow trusted domains' is off; (bso#14899); - Update to 4.15.2 * CVE-2016-2124: SMB1 client connections can be downgraded to plaintext authentication; (bso#12444); (bsc#1014440); * CVE-2020-25717: A user on the domain can become root on domain members; (bso#14556); (bsc#1192284); * CVE-2020-25718: Samba AD DC did not correctly sandbox Kerberos tickets issued by an RODC; (bso#14558); (bsc#1192246); * CVE-2020-25719: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets; (bso#14561); (bsc#1192247); * CVE-2020-25721: Kerberos acceptors need easy access to stable AD identifiers (eg objectSid); (bso#14557); (bsc#1192505); * CVE-2020-25722: Samba AD DC did not do suffienct access and conformance checking of data stored; (bso#14564); (bsc#1192283); * CVE-2021-3738: Use after free in Samba AD DC RPC server; (bso#14468); (bsc#1192215); * CVE-2021-23192: Subsequent DCE/RPC fragment injection vulnerability; (bso#14875); (bsc#1192214); - Update to 4.15.1 * vfs_shadow_copy2: core dump in make_relative_path; (bso#14682); * Log clutter from filename_convert_internal; (bso#14685); * MacOSX compilation fixes; (bso#14862); * rodc_rwdc test flaps; (bso#14868); * Provide a fix for MS CVE-2020-17049 in Samba [SECURITY] 'Bronze bit' S4U2Proxy Constrained Delegation bypass in Samba with embedded Heimdal; (bso#14642); * Python ldb.msg_diff() memory handling failure; (bso#14836); * "in" operator on ldb.Message is case sensitive; (bso#14845); * Release LDB 2.4.1 for Samba 4.15.1; (bso#14848); * samldb_krbtgtnumber_available() looks for incorrect string; (bso#14854); * Fix Samba support for UF_NO_AUTH_DATA_REQUIRED; (bso#14871); * Allow special chars like "@" in samAccountName when generating the salt; (bso#14874); * Correctly ignore comments in CTDB public addresses file; (bso#14826); * Fix transit path validation; (bso#12998); * Fix that child winbindd logs to log.winbindd instead of log.wb-; (bso#14852); * SMB3 cancel requests should only include the MID together with AsyncID when AES-128-GMAC is used; (bso#14855); * Prepare to operate with MIT krb5 >= 1.20; (bso#14870); * Heimdal prefers RC4 over AES for machine accounts; (bso#14864);- Enable samba-tool without ad dc.- Adjust spec to use pam macros; (bsc#1191046).- Adjust spec for size * allow some Recommends instead Requires to be configured for cifs-utils, samba-libs-python3 & samba-gpupdate; (bsc#1182847). * remove fam, undocumented and unneeded.- Add missing build dependency on bison when building with the embedded Heimdal Kerberos- Update to 4.15.0 * Removed SMB development dialects SMB2_22, SMB2_24 and SMB3_10 * VFS layer modernized. * Add the ability to set allow/deny lists for zone transfer clients in Bind DLZ plugin * Server multi-channel support no longer experimental * Improved command line user experience, unifying the options in different commands * Winbindd no longer scans trusted domains on startup and will use enterprise principals by default. * The net utility is now able to support the offline domain join feature * New options for 'samba-tool dns zoneoptions' for aging control and to mark old records as static or dynamic * DNS tombstones are now deleted as appropriate and use a consistent timestamp format * The 'samba-tool dns update' command validates and rejects now malformed IPv4 and IPv6 addresses * The 'samba-tool domain backup' command correctly takes out locks against concurrent modification during backup when using the LMDB backend * TruACL support has been removed * NIS support has been removed- Fix 'net rpc' authentication when using the machine account; (bsc#1189017); (bso#14796);- Fix dependency problem upgrading from libndr0 to libndr1; (bsc#1189875); - Fix dependency problem upgrading from libsmbldap0 to libsmbldap2; (bsc#1189875); - Fix wrong kvno exported to keytab after net ads changetrustpw due to replication delay; (bsc#1188727); - Add Certificate Auto Enrollment Policy; (jsc#SLE-18456). - Update to 4.13.10 * s3: smbd: Ensure POSIX default ACL is mapped into returned Windows ACL for directory handles; (bso#14708); * Take a copy to make sure we don't reference free'd memory; (bso#14721); * s3: lib: Fix talloc heirarcy error in parent_smb_fname(); (bso#14722); * s3: smbd: Remove erroneous TALLOC_FREE(smb_fname_parent) in change_file_owner_to_parent() error path; (bso#14736); * samba-tool: Give better error information when the 'domain backup restore' fails with a duplicate SID; (bso#14575); * smbd: Correctly initialize close timestamp fields; (bso#14714); * Spotlight RPC service doesn't work with vfs_glusterfs; (bso#14740); * ctdb: Fix a crash in run_proc_signal_handler(); (bso#14475); * gensec_krb5: Restore ipv6 support for kpasswd; (bso#14750); * smbXsrv_{open,session,tcon}: Protect smbXsrv_{open,session,tcon}_global_traverse_fn against invalid records; (bso#14752); * samba-tool domain backup offline doesn't work against bind DLZ backend; (bso#14027); * netcmd: Use next_free_rid() function to calculate a SID for restoring a backup; (bso#14669); - Update to 4.13.9 * s3: smbd: SMB1 SMBsplwr doesn't send a reply packet on success; (bso#14696); * Add documentation for dsdb_group_audit and dsdb_group_json_audit to "log level", synchronise "log level" in smb.conf with the code; (bso#14689); * Fix smbd panic when two clients open same file; (bso#14672); * Fix memory leak in the RPC server; (bso#14675); * s3: smbd: Fix deferred renames; (bso#14679); * s3-iremotewinspool: Set the per-request memory context; (bso#14675); * rpc_server3: Fix a memleak for internal pipes; (bso#14675); * third_party: Update socket_wrapper to version 1.3.2; (bso#11899); * third_party: Update socket_wrapper to version 1.3.3; (bso#14639); * idmap_rfc2307 and idmap_nss return wrong mapping for uid/gid conflict; (bso#14663); * Fix the build on OmniOS; (bso#14288); - Update to 4.13.8 * CVE-2021-20254: Fix buffer overrun in sids_to_unixids(); (bso#14571 - Update to 4.13.7 * Release with dependency on ldb version 2.2.1.- CVE-2021-20254 Buffer overrun in sids_to_unixids(); (bnc#14571); (bsc#1184677).- Fix offline domain backup not possible using lmdb version >= 0.9.26; (bso#14676); - Require libldb >= 2.2.1; (bsc#1183572); (bsc#1183574); - Update to 4.13.6 * CVE-2020-27840: samba: Unauthenticated remote heap corruption via bad DNs; (bso#14595); (bsc#1183572). * CVE-2021-20277: samba: out of bounds read in ldb_handler_fold; (bso#14655); (bsc#1183574). - Update to 4.13.5 * s3:modules:vfs_virusfilter: Recent talloc changes cause infinite start-up failure; (bso#14634); * s3: libsmb: Add missing cli_tdis() in error path if encryption setup failed on temp proxy connection; (bso#13992); * smbd: In conn_force_tdis_done() when forcing a connection closed force a full reload of services; (bso#14604); * dbcheck: Check Deleted Objects and reduce noise in reports about expired tombstones (bso#14593); * s3: Fix fcntl waf configure check; (bso#14503); * s3/auth: Implement "winbind:ignore domains"; (bso#14602); * smbd: Use fsp->conn->session_info for the initial delete-on-close token; (bso#14617); * s3: VFS: nfs4_acls. Add missing TALLOC_FREE(frame) in error path; (bso#14648); * classicupgrade: Treat old never expires value right; (bso#14624); * g_lock: Fix uninitalized variable reads; (bso#14636); * s3:pysmbd: Fix fd leak in py_smbd_create_file(); (bso#13898); * lib:util: Avoid free'ing our own pointer; (bso#14625); * HEIMDAL: krb5_storage_free(NULL) should work; (bso#12505);- Spec file fixes around systemd and requires; (bsc#1182830); - Align systemd service unit files with upstream provided ones.- Update to 4.13.4 * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * lib: Avoid declaring zero-length VLAs in various messaging functions; (bso#14605); * Do not create an empty DB when accessing a sam.ldb; (bso#14579); * vfs_fruit may close wrong backend fd; (bso#14596); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * vfs_virusfilter: Allocate separate memory for config char*; (bso#14606); * vfs_fruit may close wrong backend fd; (bso#14596); * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * The cache directory for the user gencache should be created recursively; (bso#14601); * Be more flexible with repository names in CentOS 8 test environments; (bso#14594);- Uninstalling samba-client: Failed to disable unit, cifs.service does not exists; (bsc#1180388);- Update to 4.13.3 + libcli: smb2: Never print length if smb2_signing_key_valid() fails for crypto blob; (bso#14210); + s3: modules: gluster. Fix the error I made in preventing talloc leaks from a function; (bso#14486); + s3: smbd: Don't overwrite contents of fsp->aio_requests[0] with NULL via TALLOC_FREE(); (bso#14515); + s3: spoolss: Make parameters in call to user_ok_token() match all other uses; (bso#14568); + s3: smbd: Quiet log messages from usershares for an unknown share; (bso#14590); + samba process does not honor max log size; (bso#14248); + vfs_zfsacl: Add missing inherited flag on hidden "magic" everyone@ ACE; (bso#14587); + s3-libads: Pass timeout to open_socket_out in ms; (bso#13124); + s3-vfs_glusterfs: Always disable write-behind translator; (bso#14486); + smbclient: Fix recursive mget; (bso#14517); + clitar: Use do_list()'s recursion in clitar.c; (bso#14581); + manpages/vfs_glusterfs: Mention silent skipping of write-behind translator; (bso#14486); + vfs_shadow_copy2: Preserve all open flags assuming ROFS; (bso#14573); + interface: Fix if_index is not parsed correctly; (bso#14514);- Update to 4.13.2 + s3: modules: vfs_glusterfs: Fix leak of char **lines onto mem_ctx on return; (bso#14486); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471); + smb.conf.5: Add clarification how configuration changes reflected by Samba; (bso#14538); + daemons: Report status to systemd even when running in foreground; (bso#14552); + DNS Resolver: Support both dnspython before and after 2.0.0; (bso#14553); + s3-vfs_glusterfs: Refuse connection when write-behind xlator is present; (bso#14486); + provision: Add support for BIND 9.16.x; (bso#14487); + ctdb-common: Avoid aliasing errors during code optimization; (bso#14537); + libndr: Avoid assigning duplicate versions to symbols; (bso#14541); + docs: Fix default value of spoolss:architecture; (bso#14522); + winbind: Fix a memleak; (bso#14388); + s4:dsdb:acl_read: Implement "List Object" mode feature; (bso#14531); + docs-xml/manpages: Add warning about write-behind translator for vfs_glusterfs; (bso#14486); + nsswitch/nsstest.c: Avoid nss function conflicts with glibc nss.h. + vfs_shadow_copy2: Avoid closing snapsdir twice; (bso#14530); + third_party: Update resolv_wrapper to version 1.1.7; (bso#14547); + examples:auth: Do not install example plugin; (bso#14550); + ctdb-recoverd: Drop unnecessary and broken code; (bso#14513); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471);- Adjust smbcacls '--propagate-inheritance' feature to align with upstream; (bsc#1178469).- Update to samba 4.13.1 + CVE-2020-14383: An authenticated user can crash the DCE/RPC DNS with easily crafted records; (bsc#1177613); (bso#14472); + CVE-2020-14323: Unprivileged user can crash winbind; (bsc#1173994); (bso#14436); + CVE-2020-14318: Missing handle permissions check in SMB1/2/3 ChangeNotify; (bsc#1173902); (bso#14434); - Adjust systemd tmpfiles.d configuration, use /run/samba instead of /var/run/samba; (bsc#1177355);- Fix vfs_ceph query_directory regression; (bso#14519) - Drop liburing-devel for SLE15-SP2; (bsc#1177245)- Register CTDB recovery lock holder with ceph-mgr - Add liburing-devel dependency- Update to samba 4.13.0 + Require Python 3.6 + Move wide links functionality into VFS module + Deprecate NT4-like 'classic' Samba domain controllers + Deprecate SMBv1 only protocol options + Remove deprecated "ldap ssl ads" option + Unify asynchronous DCE-RPC server; (jsc#SES-645) + Replay multichannel lease break requests; (bso#11897); (jsc#SES-655) + Drop internal byteorder.h header from util-devel package + Remove final code for the AD DC LDAP backend + Add AD DC Group Policy Scripts + Only use gnutls_aead_cipher_encryptv2() for GnuTLS > 3.6.14; (bso#14399) + Fix %U substitutions if it contains a domain name; (bso#14467) + Fix krb5.conf creation for 'net ads join'; (bso#14479) + Fix build problem if libbsd-dev is not installed; (bso#14482) + Toggle vfs_snapper using "--with-shared-modules"; (bso#14437) + Fix idmap_ad RFC4511 response handling; (bso#14465) + Fix panic in get_lease_type(); (bso#14428)- Update to samba 4.11.13 + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Protect netr_ServerPasswordSet2 against unencrypted passwords; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Support "server require schannel:WORKSTATION$ = no" about unsecure configurations; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s4 torture rpc: repeated bytes in client challenge; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): libcli/auth: Reject weak client challenges in netlogon_creds_server_init() "server require schannel:WORKSTATION$ = no"; (bsc#1176579); (bso#14497); - Update to samba 4.11.12 + s3: libsmb: Fix SMB2 client rename bug to a Windows server; (bso#14403); + dsdb: Allow "password hash userPassword schemes = CryptSHA256" to work on RHEL7; (bso#14424); + dbcheck: Allow a dangling forward link outside our known NCs; (bso#14450); + lib/debug: Set the correct default backend loglevel to MAX_DEBUG_LEVEL; (bso#14426); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + lib/util: do not install "test_util_paths"; (bso#14370); + lib:util: Fix smbclient -l basename dir; (bso#14345); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + util: Allow symlinks in directory_create_or_exist; (bso#14166); + docs: Fix documentation for require_membership_of of pam_winbind; (bso#14358); + s3:winbind:idmap_ad: Make failure to get attrnames for schema mode fatal; (bso#14425);- Add obsoletes to libsmbldap2 package to fix upgrades from previous versions; (bsc#1172810);- Fix net command unable to negotiate SMB2; (bsc#1174120);- Update to samba 4.11.11 + CVE-2020-10730: NULL de-reference in AD DC LDAP server when ASQ and VLV combined; (bso#14364); (bsc#1173159] + CVE-2020-10745: invalid DNS or NBT queries containing dots use several seconds of CPU each; (bso#14378); (bsc#1173160). + CVE-2020-10760: Use-after-free in AD DC Global Catalog LDAP server with paged_result or VLV; (bso#14402); (bsc#1173161) + CVE-2020-14303: Endless loop from empty UDP packet sent to AD DC nbt_server; (bso#14417); (bsc#1173359). - Update to samba 4.11.10 + Fix segfault when using SMBC_opendir_ctx() routine for share folder that contains incorrect symbols in any file name; (bso#14374). + vfs_shadow_copy2 doesn't fail case looking in snapdirseverywhere mode; (bso#14350) + ldb_ldap: Fix off-by-one increment in lldb_add_msg_attr; (bso#14413). + Malicous SMB1 server can crash libsmbclient; (bso#14366) + winbindd: Fix a use-after-free when winbind clients exit; (bso#14382) + ldb: Bump version to 2.0.11, LMDB databases can grow without bounds. (bso#14330) - Update to samba 4.11.9 + nmblib: Avoid undefined behaviour in handle_name_ptrs(); (bso#14242). + 'samba-tool group' commands do not handle group names with special chars correctly; (bso#14296). + smbd: avoid calling vfs_file_id_from_sbuf() if statinfo is not valid; (bso#14237). + Missing check for DMAPI offline status in async DOS attributes; (bso#14293). + smbd: Ignore set NTACL requests which contain S-1-5-88 NFS ACEs; (bso#14307). + vfs_recycle: Prevent flooding the log if we're called on non-existant paths; (bso#14316) + smbd mistakenly updates a file's write-time on close; (bso#14320). + RPC handles cannot be differentiated in source3 RPC server; (bso#14359). + librpc: Fix IDL for svcctl_ChangeServiceConfigW; (bso#14313). + nsswitch: Fix use-after-free causing segfault in _pam_delete_cred; (bso#14327). + Fix fruit:time machine max size on arm; (bso#13622) + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294). + ctdb: Fix a memleak; (bso#14348). + libsmb: Don't try to find posix stat info in SMBC_getatr(). + ctdb-tcp: Move free of inbound queue to TCP restart; (bso#14295); (bsc#1162680). + s3/librpc/crypto: Fix double free with unresolved credential cache; (bso#14344); (bsc#1169095) + s3:libads: Fix ads_get_upn(); (bso#14336). + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294) + Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680). + ctdb-recoverd: Avoid dereferencing NULL rec->nodemap; (bso#14324) - Update to samba 4.11.8 + CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850); + CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - Update to samba 4.11.7 + s3: lib: nmblib. Clean up and harden nmb packet processing; (bso#14239). + s3: VFS: full_audit. Use system session_info if called from a temporary share definition; (bso#14283) + dsdb: Correctly handle memory in objectclass_attrs; (bso#14258). + ldb: version 2.0.9, Samba 4.11 and later give incorrect results for SCOPE_ONE searches; (bso#14270) + auth: Fix CIDs 1458418 and 1458420 Null pointer dereferences; (bso#14247). + smbd: Handle EINTR from open(2) properly; (bso#14285) + winbind member (source3) fails local SAM auth with empty domain name; (bso#14247) + winbindd: Handling missing idmap in getgrgid(); (bso#14265). + lib:util: Log mkdir error on correct debug levels; (bso#14253). + wafsamba: Do not use 'rU' as the 'U' is deprecated in Python 3.9; (bso#14266). + ctdb-tcp: Make error handling for outbound connection consistent; (bso#14274). - Update to samba 4.11.6 + pygpo: Use correct method flags; (bso#14209). + vfs_ceph_snapshots: Fix root relative path handling; (bso#14216); (bsc#1141320). + Avoiding bad call flags with python 3.8, using METH_NOARGS instead of zero; (bso#14209). + source4/utils/oLschema2ldif: Include stdint.h before cmocka.h; (bso#14218). + docs-xml/winbindnssinfo: Clarify interaction with idmap_ad etc; (bso#14122). + smbd: Fix the build with clang; (bso#14251). + upgradedns: Ensure lmdb lock files linked; (bso#14199). + s3: VFS: glusterfs: Reset nlinks for symlink entries during readdir; (bso#14182). + smbc_stat() doesn't return the correct st_mode and also the uid/gid is not filled (SMBv1) file; (bso#14101). + librpc: Fix string length checking in ndr_pull_charset_to_null(); (bso#14219). + ctdb-scripts: Strip square brackets when gathering connection info; (bso#14227).- Add libnetapi-devel to baselibs conf, for wine usage; (bsc#1172307);- Installing: samba - samba-ad-dc.service does not exist and unit not found; (bsc#1171437);- Fix samba_winbind package is installing python3-base without python3 package; (bsc#1169521);- Require libldb2 >= 2.0.10 after security release.- CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850);- Fix smbclient crash with double free (with unresolved krb5 credential cache); (bso#14344); (bsc#1169095).- Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680).- CTDB doesn't retry outgoing connections on bind (and some other) failures; (bso#14274); (bsc#1162680).- Revert: Allow idmap_rid to have primary group other than "Domain Users"; (bsc#1087931).- Fix nmbstatus not reporting detailed information about workgroups; (bsc#1159464); - Fix querying all names registered within broadcast area; (bso#8927);- Update to samab 4.11.5 + CVE-2019-14902: Replication of ACLs down subtree on AD Directory is not automatic; (bso#12497); (bsc#1160850). + CVE-2019-19344: Fix server crash with dns zone scavenging = yes; (bso#14050); (bsc#1160852). + CVE-2019-14907: server-side crash after charset conversion failure (eg during NTLMSSP processing); (bso#14208); (bsc#1160888). - Update to samba 4.11.4 + Ensure SMB1 cli_qpathinfo2() doesn't return an inode number; (bso#14161). + Ensure we don't call cli_RNetShareEnum() on an SMB1 connection; (bso#14174). + NT_STATUS_ACCESS_DENIED becomes EINVAL when using SMB2 in SMBC_opendir_ctx; (bso#14176). + SMB2 - Ensure we use the correct session_id if encrypting an interim response; (bso#14189). + Prevent smbd crash after invalid SMB1 negprot; (bso#14205). + printing: Fix %J substition; (bso#13745). + Remove now unneeded call to cmdline_messaging_context(); (bso#13925). + Fix incomplete conversion of former parametric options; (bso#14069). + Fix sync dosmode fallback in async dosmode codepath; (bso#14070). + vfs_fruit returns capped resource fork length; (bso#14171). + libnet_join: Add SPNs for additional-dns-hostnames entries; (bso#14116). + smbd: Increase a debug level; (bso#14211). + Prevent azure ad connect from reporting discovery errors reference-value-not-ldap-conformant; (bso#14153). + krb5_plugin: Fix developer build with newer heimdal system library; (bso#14179). + replace: Only link libnsl and libsocket if required; (bso#14168); + ctdb: Incoming queue can be orphaned causing communication; breakdown; (bso#14175). + ldb: Release ldb 2.0.8. Cross-compile will not take cross-answers or cross-execute; (bso#13846). + heimdal-build: Avoid hard-coded /usr/include/heimdal in asn1_compile-generated code; (bso#13856).- Fix Ceph snapshot root relative path handling; (bso#14216); (bsc#1141320).- Update to samba 4.11.3 + CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). + CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). - CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- Update to samba 4.11.2 + CVE-2019-10218: Client code can return filenames containing path separators; (bsc#1144902); (bso#14071). + CVE-2019-14833: Samba AD DC check password script does not receive the full password; (bso#12438). + CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040). - Fixes from 4.11.1 + Overlinking libreplace against librt and pthread against every binary or library causes issues; (bso#14140); + kpasswd fails when built with MIT Kerberos; (bso#14155); + Fix spnego fallback from kerberos to ntlmssp in smbd server; (bso#14106); + Stale file handle error when using mkstemp on a share; (bso#14137); + non-AES schannel broken; (bso#14134); + Joining Active Directory should not use SAMR to set the password; (bso#13884); + smbclient can blunder into the SMB1 specific cli_RNetShareEnum() call on an SMB2 connection; (bso#14152); + Deleted records can be resurrected during recovery; (bso#14147); + getpwnam and getpwuid need to return data for ID_TYPE_BOTH group; (bso#14141); + winbind does not list forest trusts with additional trust attributes; (bso#14130); + fault report points to outdated documentation; (bso#14139); + pam_winbind with krb5_auth or wbinfo -K doesn't work for users of trusted domains/forests; (bso#14124); + classicupgrade results in uncaught exception - a bytes-like object is required, not 'str'; (bso#14136); + pod2man is not longer required, stop checking at build time; (bso#14131); + Exit code of ctdb nodestatus should not be influenced by deleted nodes; (bso#14129); + username/password authentication doesn't work with CUPS and smbspool; (bso#14128); + smbc_readdirplus() is incompatible with smbc_telldir() and smbc_lseekdir(); (bso#14094);- CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040); (bsc#1154598); - CVE-2019-10218: Client code can return filenames containing path separators; (bso#14071); (bsc#1144902);- CVE-2019-14833: samba: Accent with "check script password" Samba AD DC check password script does not receive the full password; (bso#12438); (bsc#1154289).- Update to samba 4.11.0 + For details on all items see WHATSNEW.txt in samba-doc package + Python2 runtime support removed; python 3.4 or later required + Security improvements: - SMB1 disabled by default - lanman and plaintext authentication deprecated - winbind: PAM_AUTH and NTLM_AUTH events logged - GnuTLS 3.2 required; system FIPS mode setting honored + CephFS Snapshot integration, exposed as previous file versions + ctdb changes: - onnode -o option removed - ctdbd logs when using more than 90% of a CPU thread - CTDB_MONITOR_SWAP_USAGE variable removed + AD Domain controller improvements: - Upgrade AD databse format - BIND9_FLATFILE deprecated - default process model chagned to prefork - bind9 dns operation duration logging - Default schema updated to 2012_R2; function level is unchanged - many performance improvements + Configuration webserver support removed- Fix broken username/password authentication with CUPS and smbspool; (bsc#1152143); (bso#14128).- Fix auth problems when printing via smbspool backend with kerberos; (bnc#1148539); (bso#13832).- Update to samba 4.10.8 + CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267);- Fix build on newer systems by modifying samba.spec to use consistent non-relative paths for pammodules in configure line and specification of pam_winbind.so library to package.- Update to samba 4.10.7 + Unable to create or rename file/directory inside shares configured with vfs_glusterfs_fuse module; (bso#14010). + build: Allow build when '--disable-gnutls' is set; (bso#13844) + samba-tool: Add 'import samba.drs_utils' to fsmo.py; (bso#13973). + Fix 'Error 32 determining PSOs in system' message on old DB with FL upgrade; (bso#14008). + s4/libnet: Fix joining a Windows pre-2008R2 DC; (bso#14021) + join: Use a specific attribute order for the DsAddEntry nTDSDSA object; (bso#14046). + vfs_catia: Pass stat info to synthetic_smb_fname(); (bso#14015). + lookup_name: Allow own domain lookup when flags == 0; (bso#14091). + s4 librpc rpc pyrpc: Ensure tevent_context deleted last; (bso#13932). + DEBUGC and DEBUGADDC doesn't print into a class specific log file; (bso#13915). + Request to keep deprecated option "server schannel", VMWare Quickprep requires "auto"; (bso#13949). + dbcheck: Fallback to the default tombstoneLifetime of 180 days; (bso#13967). + dnsProperty fails to decode values from older Windows versions; (bso#13969). + samba-tool: Use only one LDAP modify for dns partition fsmo role transfer; (bso#13973). + third_party: Update waf to version 2.0.17; (bso#13960). + netcmd: Allow 'drs replicate --local' to create partitions; (bso#14051). + ctdb-config: Depend on /etc/ctdb/nodes file; (bso#14017).- CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267).- Prepare for use future use of kernel keyrings, modify /etc/pam.d/samba to include pam_keyinit.so; (bsc#1144059).- Update samba-winbind script to work with systemd; (bsc#1132739); - Drop samba dhcpcd hook scripts - Update to samba 4.10.6 + s3: winbind: Fix crash when invoking winbind idmap scripts; (bso#13956). + smbd does not correctly parse arguments passed to dfree and quota scripts; (bso#13964). + samba-tool dns: use bytes for inet_ntop; (bso#13965). + samba-tool domain provision: Fix --interactive module in python3; (bso#13828). + ldb_kv: Skip @ records early in a search full scan; (bso#13893). + docs: Improve documentation of "lanman auth" and "ntlm auth" connection; (bso#13981). + python/ntacls: Use correct "state directory" smb.conf option instead of "state dir"; (bso#14002). + registry: Add a missing include; (bso#13840). + Fix SMB guest authentication; (bso#13944). + AppleDouble conversion breaks Resourceforks; (bso#13958). + vfs_fruit makes direct use of syscalls like mmap() and pread(); (bso#13968). + s3:mdssvc: Fix flex compilation error; (bso#13987). + s3/vfs_glusterfs[_fuse]: Avoid using NAME_MAX directly; (bso#13872). + dsdb:samdb: schemainfo update with relax control; (bso#13799). + s3:util: Move static file_pload() function to lib/util; (bso#13964). + smbd: Fix a panic; (bso#13957). + ldap server: Generate correct referral schemes; (bso#12478). + s4 dsdb/repl_meta_data: fix use after free in dsdb_audit_add_ldb_value; (bso#13941). + s4 dsdb: Fix use after free in samldb_rename_search_base_callback; (bso#13942). + dsdb/repl: we need to replicate the whole schema before we can apply it; (bso#12204). + ldb: Release ldb 1.5.5; (bso#12478). + Schema replication fails if link crosses chunk boundary backwards; (bso#13713). + 'samba-tool domain schemaupgrade' uses relax control and skips the schemaInfo update provision; (bso#13799). + dsdb_audit: avoid printing "... remote host [Unknown] SID [(NULL SID)] ..."; (bso#13916). + python/ntacls: We only need security.SEC_STD_READ_CONTROL in order to get the ACL; (bso#13917). + s3:loadparm: Ensure to truncate FS Volume Label at multibyte boundary; (bso#13947). + Using Kerberos credentials to print using spoolss doesn't work; (bso#13939). + wafsamba: Use native waf timer; (bso#13998). + ctdb-scripts: Fix tcp_tw_recycle existence check; (bso#13984).- Update to samba-4.10.5 (including updates for 4.10.4, 4.10.3) + CVE-2019-12435 rpc/dns: Avoid NULL deference if zone not found in DnssrvOperation2; (bso#13922); (bsc#1137815). + CVE-2019-12436 dsdb/paged_results: Ignore successful results without messages; (bso#13951); (bsc#1137816). - Update to samba-4.10.4 + s3: SMB1: Don't allow recvfile on stream fsp's; (bso#13938). + py/provision: Fix for Python 2.6; (bso#13882). + netcmd: Fix 'passwordsettings --max-pwd-age' command; (bso#13873). + s3-libnet_join: 'net ads join' to child domain fails when using "-U admin@forestroot"; (bso#13861). + vfs_ceph: Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245). + vfs_ceph: Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). + ctdb-common: Avoid race between fd and signal events; (bso#13895). + ctdb-common: Fix memory leak in run_proc; (bso#13943). + lib: Initialize getline() arguments; (bso#13892). + winbind: Fix overlapping id ranges; (bco#13903). + lib util debug: Increase format buffer to 4KiB; (bso#13902). + nsswitch pam_winbind: Fix Asan use after free; (bso#13927). + s4 lib socket: Ensure address string owned by parent struct; (bso#13929). + s3 rpc_client: Fix Asan stack use after scope; (bso#13936). + s3:smbd: Handle IO_REPARSE_TAG_DFS in SMB_FIND_FILE_FULL_DIRECTORY_INFO; (bso#10097). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#10344). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#12845). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#13698). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#13796). + dbcheck: Fix the err_empty_attribute() check; (bso#13843). + vfs_snapper: Drop unneeded fstat handler; (bso#13858). + vfs_default: Fix vfswrap_offload_write_send() NT_STATUS_INVALID_VIEW_SIZE check; (bso#13862). + smb2_server: Grant all 8192 credits to clients; (bso#13863). + smbd: Implement SMB_FILE_NORMALIZED_NAME_INFORMATION handling; (bso#13919). + s3/vfs_glusterfs: Dynamically determine NAME_MAX; (bso#13872). + s3: modules: ceph: Use current working directory instead of share path; (bso#13918); (bsc#1134452). + winbind: Use domain name from lsa query for sid_to_name cache entry; (bso#13831). + memcache: Increase size of default memcache to 512k; (bso#13865). + docs: Update smbclient manpage for "--max-protocol"; (bso#13857). + s3:utils: If share is NULL in smbcacls, don't print it; (bso#13937). + s3:smbspool: Fix regression printing with Kerberos credentials; (bso#13939). + ctdb-scripts: CTDB restarts failed NFS RPC services by hand, which is incompatible with systemd; (bso#13860). + ctdb-daemon: Revert "We can not assume that just because we could complete a TCP handshake"; (bso#13888). + ctdb-daemon: Never use 0 as a client ID; (bso#13930). + ctdb-common: Fix memory leak; (bso#13943). + s3:debug: Enable logging for early startup failures; (bso#13904) - Update to samba-4.10.3 + CVE-2018-16860: Heimdal KDC: Reject PA-S4U2Self with unkeyed checksum; (bso#13685); (bsc#1134024).- CVE-2019-12435: zone operations can crash rpc server; (bso#13922); (bsc#1137815).- Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). - Add ceph_snapshots VFS module; (jsc#SES-183).- Fix vfs_ceph realpath; (bso#13918); (bsc#1134452).- Update to samba-4.10.2: + CVE-2019-3870 (World writable files in Samba AD DC private/ dir); (bso#13834). + CVE-2019-3880 (Save registry file outside share as unprivileged user); (bso#13851). + py/kcc_utils: py2.6 compatibility; (bso#13837). + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869). + regfio: Improve handling of malformed registry hive files; (bso#13840). + ctdb-version: Simplify version string usage; (bso#13789). + lib: Make fd_load work for non-regular files; (bso#13859). + dbcheck: in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816). + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818). + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854). + acl_read: Fix regression for empty lists; (bso#13836). + s4:dlz make b9_has_soa check dc=@ node; (bso#13841). + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832). + s4:librpc: Fix installation of Samba; (bso#13847). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853). * ctdb-build: Drop creation of .distversion in tarball; (bso#13789). * ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838). - Update to samba-4.10.1: + py/kcc_utils: py2.6 compatibility; (bso#13837); + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869); + regfio: Improve handling of malformed registry hive files; (bso#13840); + ctdb-version: Simplify version string usage; (bso#13789); + lib: Make fd_load work for non-regular files; (bso#13859); + dbcheck in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816); + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818); + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854); + acl_read: Fix regression for empty lists; (bso#13836); + s4:dlz make b9_has_soa check dc=@ node; (bso#13841); + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832); + s4:librpc: Fix installation of Samba; (bso#13847); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853); + ctdb-build: Drop creation of .distversion in tarball; (bso#13789); + ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838); - Update to samba-4.10.0: + s4-server: Open and close a transaction on sam.ldb at startup; (bso#13760); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s4/scripting/bin: Open unicode files with utf8 encoding and write + unicode string. + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + Fix idmap cache pollution with S-1-22- IDs on winbind hickup; (bso#13813); + passdb: Update ABI to 0.27.2. + lib/winbind_util: Add winbind_xid_to_sid for --without-winbind; (bso#13813); + lib:util: Move debug message for mkdir failing to log level 1; (bso#13823);- MacOS credit accounting breaks with async SESSION SETUP; (bsc#1125601); (bso#13796). - Mac OS X SMB2 implmenetation sees Input/output error or Resource temporarily unavailable and drops connection; (bso#13698)- Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245).- CVE-2019-3880: Save registry file outside share as unprivileged user; (bso#13851); (bsc#1131060 ).- CVE-2019-3870 pysmbd: missing restoration of original umask after umask(0); (bso#13834); (bsc#1130703);- Update to samba-4.9.5 + audit_logging: Remove debug log header and JSON Authentication: prefix; (bso#13714); + Fix upgrade from 4.7 (or earlier) to 4.9; (bso#13760); + s3: lib: nmbname: Ensure we limit the NetBIOS name correctly; (bso# CID: 1433607; (bso#11495); + smbd: uid: Don't crash if 'force group' is added to an existing share connection; (bso#13690); + s3: VFS: vfs_fruit. Fix the NetAtalk deny mode compatibility code; (bso#13770); + s3: SMB1 POSIX mkdir does case insensitive name lookup; (bso#13803); + s3:utils/smbget fix recursive download with empty source directories; (bso#13199); + samba-tool drs showrepl: Do not crash if no dnsHostName found; (bso#13716); + s3:libsmb: cli_smb2_list() can sometimes fail initially on a connection; (bso#13736); + join: Throw CommandError instead of Exception for simple errors; (bso#13747); + ldb: Avoid inefficient one-level searches; (bso#13762); + s3: libsmb: use smb2cli_conn_max_trans_size() in cli_smb2_list(); (bso#13736); + tldap: Avoid use after free errors; (bso#13776); + Fix idmap xid2sid cache churn; (bso#13802); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s3-smbd: Avoid assuming fsp is always intact after close_file call; (bso#13720); + s3-vfs-fruit: Add close call; (bso#13725); + s3-smbd: Use fruit:model string for mDNS registration; (bso#13746); + s3-vfs: add glusterfs_fuse vfs module; (bso#13774); + printing: Check lp_load_printers() prior to pcap cache update; (bso#13766); + vfs_ceph: vfs_ceph strict_allocate_ftruncate calls (local FS) ftruncate and fallocate; (bso#13807); + lib/audit_logging: Actually create talloc; (bso#13737); + netcmd/user: python[3]-gpgme unsupported and replaced by python[3]-gpg; (bso#13728); + dns: Changing onelevel search for wildcard to subtree; (bso#13738); + samba-tool: Don't print backtrace on simple DNS errors; (bso#13721); + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + ctdb: Print locks latency in machinereadable stats; (bso#13742); + messages_dgm: Messaging gets stuck when pids are recycled; (bso#13786); + audit_logging: auth_json_audit required auth_json; (bso#13715); + man pages: Document prefork process model; (bso#13765); + CVE-2019-3824 ldb: Release ldb 1.4.6; (bso#13773); + s3:auth: ignore create_builtin_guests() failing without a valid idmap configuration; (bso#13697); + s3:auth_winbind: Ignore a missing winbindd as NT4 PDC/BDC without trusts; (bso#13722); + s3:auth_winbind: return NT_STATUS_NO_LOGON_SERVERS if winbindd is not available; (bso#13723); + s4:server: Add support for 'smbcontrol samba shutdown' and 'smbcontrol debug/debuglevel'; (bso#13752); + Python: Ensure ldb.Dn can doesn't rencoded str with py2; (bso#13616); + vfs_glusterfs: Adapt to changes in libgfapi signatures; (bso#13330); + s3-vfs: Use ENOATTR in errno comparison for getxattr; (bso#13774); + notifyd: Fix SIGBUS on sparc; (bso#13704); + waf: Check for libnscd; (bso#13787); + s3:vfs: Correctly check if OFD locks should be enabled or not; (bso#13770); + lib/util: Count a trailing line that doesn't end in a newline; (bso#13717); + Recovery lock bug fixes; (bso#13800); + s3: net: Do not set NET_FLAGS_ANONYMOUS with -k; (bso#13726); + s3:libsmb: Honor disable_netbios option in smbsock_connect_send; (bso#13727); + vfs_fileid: Fix get_connectpath_ino; (bso#13741); + vfs_fileid: Fix fsname_norootdir algorithm; (bso#13744);- Fix vfs_ceph ftruncate and fallocate handling; (bso#13807); (bsc#1127153).- Fix update-apparmor-samba-profile script after apparmor switched to using named profiles. The change is backwards compatible; (bsc#1126377);- LoadParm().load_default() fails with "Unable to load default file"; (bsc#1089758);- Abide by load_printers smb.conf parameter; (bso#13766); (bsc#1124223);- Update to samba-4.9.4 + libcli/smb: Don't overwrite status code; (bso#9175). + wbinfo --group-info 'NT AUTHORITY\System' does not work; (bso#12164). + Session setup reauth fails to sign response; (bso#13661). + vfs_fruit: Validation of writes on AFP_AfpInfo stream; (bso#13677). + vfs_shadow_copy2: Nicely deal with attempts to open previous version for writing; (bso#13688). + Restoring previous version of stream with vfs_shadow_copy2 fails with NT_STATUS_OBJECT_NAME_INVALID fsp->base_fsp->fsp_name; (bso#13455). + CVE-2018-16853: Fix S4U2Self crash with MIT KDC build; (bso#13571). + s3-vfs: Prevent NULL pointer dereference in vfs_glusterfs; (bso#13708) + PEP8: fix E231: missing whitespace after ','. + winbindd: Fix crash when taking profiles;(bso#13629) + CVE-2018-14629 dns: Fix CNAME loop prevention using counter regression; (bso#13600) + 'samba-tool user syscpasswords' fails on a domain with many DCs; (bso#13686). + CVE-2018-16853: Do not segfault if client is not set; (bso#13571). + lib:util: Fix DEBUGCLASS pointer initializiation; (bso#13679) + ctdb-daemon: Exit with error if a database directory does not exist; (bso#13696). + s3:libads: Add net ads leave keep-account option; (bso#13498).- Drop more %if..%endif guards which are idempotent. - Drop requires on ldconfig which are already auto-discovered. - Do not ignore errors from useradd/groupadd.- Remove python2 build dependency from samba-libs; (bsc#1116900);- Update update-apparmor-samba-profile script to ignore the shares's paths containing substitution variables in any place, not only at the beginning of the path.- Update to samba-4.9.3 + CVE-2018-14629: Unprivileged adding of CNAME record causing loop in AD Internal DNS server; (bso#13600); (bsc#1116319); + CVE-2018-16841: Double-free in Samba AD DC KDC with PKINIT; (bso#13628); (bsc#1116320); + CVE-2018-16851: NULL pointer de-reference in Samba AD DC LDAP server; (bso#13674); (bsc#1116322); + CVE-2018-16852: NULL pointer de-reference in Samba AD DC DNS servers; (bso#13669); (bsc#1116321); + CVE-2018-16853: Samba AD DC S4U2Self crash in experimental MIT Kerberos configuration (unsupported); (bso#13678); (bsc#1116324); + CVE-2018-16857: Bad password count in AD DC not always effective; window; (bso#13683); (bsc#1116323);- Update to samba-4.9.2 + dsdb: Add comments explaining the limitations of our current backlink behaviour; (bso#13418); + Fix problems running domain backups (handling SMBv2, sites); (bso#13621); + testparm: Fix crashes with PANIC: Messaging not initialized on SLES 12 SP3; (bso#13465); + Make vfs_fruit able to cleanup AppleDouble files; (bso#13642); + File saving issues with vfs_fruit on samba >= 4.8.5; (bso#13646); + Enabling vfs_fruit looses FinderInfo; (bso#13649); + Cancelling of SMB2 aio reads and writes returns wrong error NT_STATUS_INTERNAL_ERROR; (bso#13667); + Fix CTDB recovery record resurrection from inactive nodes and simplify vacuuming; (bso#13641); + examples: Fix the smb2mount build; (bso#13465); + libtevent: Fix build due to missing open_memstream on Illiumos; (bso#13629); + winbindd_cache: Fix timeout calculation for sid<->name cache; (bso#13662); + dsdb encrypted_secrets: Allow "ldb:// and "mdb://" in file path; (bso#13653); + Extended DN SID component missing for member after switching group membership; (bso#13418); + Return STATUS_SESSION_EXPIRED error encrypted, if the request was encrypted; (bso#13624); + python: Allow forced signing via smb.SMB(); (bso#13621); + lib:socket: If returning early, set ifaces; (bso#13665); + ldb: Bump ldb version to 1.4.3, Python: Ensure ldb.Dn can accept utf8 encoded unicode; (bso#13616); + smbd: Fix DELETE_ON_CLOSE behaviour on files with READ_ONLY attribute; (bso#13673); + waf: Add -fstack-clash-protection; (bso#13601); + winbind: Fix segfault if an invalid passdb backend is configured; (bso#13668); + Fix bugs in CTDB event handling; (bso#13659); + Misbehaving nodes are sometimes not banned; (bso#13670);- lib:socket: If returning early, set ifaces; (bso#13665); (bsc#1111373);- winbind requires latest version of libtevent-util0 to start- Backport latest gpo code from master + Read policy from local gpt cache + Offline policy application + Make group policy extensible via register/unregister gpext + gpext's run via a process_group_policy method- Enable profiling data collection- Change samba-kdc package name to samba-ad-dc - Move samba-ad-dc.service to the samba-ad-dc package- Update to samba-4.9.1 + s3: nmbd: Stop nmbd network announce storm; (bso#13620); + s3-rpcclient: Use spoolss_init_spoolss_UserLevel1 in winspool cmds; (bso#13597); + CTDB recovery lock has some race conditions; (bso#13617); + s3-rpc_client: Advertise Windows 7 client info; (bso#13597); + ctdb-doc: Remove PIDFILE option from ctdbd_wrapper man page; (bso#13610);- Tumbleweed doesn't define the sle_version macro, so we must include a check for suse_version also. Otherwise python3 is disabled on Tumbleweed.- Update to samba-4.9.0 + samba_dnsupdate: Honor 'dns zone scavenging' option, only update if needed; (bso#13605); + wafsamba: Fix 'make -j'; (bso#13606);- Update to samba-4.9.0rc5 + s3: VFS: vfs_full_audit: Ensure smb_fname_str_do_log() only returns absolute pathnames; (bso#13565); + s3: util: Do not take over stderr when there is no log file; (bso#13578); + Durable Reconnect fails because cookie.allow_reconnect is not set; (bso#13549); + krb5-samba: Interdomain trust uses different salt principal; (bso#13539); + vfs_fruit: Don't unlink the main file; (bso#13441); + smbd: Fix a memleak in async search ask sharemode; (bso#13602); + Fix Samba GPO issue when Trust is enabled; (bso#11517); + samba-tool: Add "virtualKerberosSalt" attribute to 'user getpassword/syncpasswords'; (bso#13539); + Fix CTDB configuration issues; (bso#13589); + ctdbd logs an error until it can successfully connect to eventd; (bso#13592);- Update to samba-4.9.0rc4 + s3: smbd: Ensure get_real_filename() copes with empty pathnames; (bso#13585); + samba domain backup online/rename commands force user to specify password on CLI; (bso#13566); + wafsamba/samba_abi: Always hide ABI symbols which must be local; (bso#13579); + Fix a panic if fruit_access_check detects a locking conflict; (bso#13584); + Fix memory and resource leaks; (bso#13567); + python: Fix print in dns_invalid.py; (bso#13580); + Aliasing issue causes incorrect IPv6 checksum; (bso#13588); + Fix CTDB configuration issues; (bso#13589); + s3: vfs: time_audit: fix handling of token_blob in smb_time_audit_offload_read_recv(); (bso#13568);- Add missing zlib-devel dependency which was previously pulled in by libopenssl-devel- Update to samba-4.9.0rc3+git.22.3fff23ae36e + CVE-2018-10858: libsmb: Harden smbc_readdir_internal() against returns from malicious servers; (bso#13453); + CVE-2018-1140: ldbsearch '(distinguishedName=abc)' and DNS query with escapes crashes, ldb: Release LDB 1.3.5 for CVE-2018-1140; (bso#13374); + CVE-2018-10918: cracknames: Fix DoS (NULL pointer de-ref) when not servicePrincipalName is set on a user; (bso#13552); + CVE-2018-10919: acl_read: Fix unauthorized attribute access via searches; (bso#13434); + ctdb_mutex_ceph_rados_helper: Set SIGINT signal handler; (bso#13540); + CVE-2018-1139 libcli/auth: Do not allow ntlmv1 over SMB1 when it is disabled via "ntlm auth"; (bso#13360); + s3-tldap: do not install test_tldap; (bso#13529); + ctdb_mutex_ceph_rados_helper: Fix deadlock via lock renewals; (bso#13540); + CVE-2018-1140 Add NULL check for ldb_dn_get_casefold() in ltdb_index_dn_attr(); (bso#13374); + ctdb-eventd: Fix CID 1438155; (bso#13554); + Fix CIDs 1438243, (Unchecked return value) 1438244 (Unsigned compared against 0), 1438245 (Dereference before null check) and 1438246 (Unchecked return value); (bso#13553); + ctdb: Fix a cut&paste error; (bso#13554); + systemd: Only start smb when network interfaces are up; (bso#13559); + Fix quotas don't work with SMB2; (bso#13553); + s3/smbd: Ensure quota code is only called when quota support detected; (bso#13563); + s3/libsmb: Explicitly set delete_on_close token for rmdir; (bso#13204); + s3:waf: Install eventlogadm to /usr/sbin; (bso#13561); + Shorten description in vfs_linux_xfs_sgid manual; (bso#13562);- Update to samba-4.9.0rc2+git.21.a1069afb007 + s3: smbd: Using "sendfile = yes" with SMB2 can cause CPU spin; (bso#13537); + s3: smbd: Fix path check in smbd_smb2_create_durable_lease_check(); (bso#13535); + samba-tool trust: Support discovery via netr_GetDcName; (bso#13538); + s4-dsdb: Only build dsdb Python modules for AD DC; (bso#13542); + Fix portability issues on freebsd; (bso#13520); + DNS wildcard search does not handle multiple labels correctly; (bso#13536); + samba-tool domain trust: Fix trust compatibility to Windows Server 1709 and FreeIPA; (bso#13308); + Fix portability issues on freebsd; (bso#13520); + ctdb-protocol: Fix CTDB compilation issues; (bso#13545); + ctdb-docs: Replace obsolete reference to CTDB_DEBUG_HUNG_SCRIPT option; (bso#13546); + ctdb-doc: Provide an example script for migrating old configuration; (bso#13550); + ctdb-event: Implement event tool "script list" command; (bso#13551);- Update to samba-4.8.4+git.37.a7a861d7982; + CVE-2018-1139: Weak authentication protocol allowed; (bsc#1095048); (bsc#13360); + CVE-2018-1140: Denial of Service Attack on DNS and LDAP server; (bsc#1095056); (bso#13466); (bso#13374); + CVE-2018-10858: Insufficient input validation on client directory listing in libsmbclient; (bsc#1103411); (bso#13453); + CVE-2018-10918: Denial of Service Attack on AD DC DRSUAPI server; (bsc#1103414); (bso#13552); + CVE-2018-10919: Confidential attribute disclosure from the AD LDAP server; (bsc#1095057); (bso#13434); + s3:winbind: winbind normalize names' doesn't work for users; (bso#12851); + winbind: Fix UPN handling in canonicalize_username(); (bso#13369); + s3: smbd: Fix SMB2-FLUSH against directories; (bso#13428); + samdb: Fix building Samba with gcc 8.1; (bso#13437); + s3:utils: Do not segfault on error in DoDNSUpdate(); (bso#13440); + smbd: Flush dfree memcache on service reload; (bso#13446); + ldb: Save a copy of the index result before calling the + lib/util: No Backtrace given by Samba's AD DC by default; (bso#13454). + s3: smbd: printing: Re-implement delete-on-close semantics for print files missing since 3.5.x; (bso#13457). + python: Fix talloc frame use in make_simple_acl(); (bso#13474). + krb5_wrap: Fix keep_old_entries logic for older Kerberos libraries;(bso#13478). + krb5_plugin: Add winbind localauth plugin for MIT Kerberos; (bso#13480).- Add missing package descriptions; (bsc#1093864); - Fix dependency issue between samba-python and samba-kdc; (bsc#1062876); - Call update-apparmor-samba-profile when running samba-ad-dc; (bsc#1092099);- Update to 4.8.2 + After update to 4.8.0 DC failed with "Failed to find our own NTDS Settings objectGUID" (bso#13335). + fix incorrect reporting of stream dos attributes on a directory (bso#13380). + vfs_ceph: add asynchronous fsync; fake synchronous call (bso#13412). + vfs_ceph: add fake async pwrite/pread send/recv hooks; (bso#13425) + vfs_ceph: Fix memory leak; (bso#13424). + libsmbclient: Fix hard-coded connection error return of ETIMEDOUT; (bso#13419). + s4-lsa: Fix use-after-free in LSA server; (bso#13420). + winbindd: Do re-connect if the RPC call fails in the passdb case; (bso#13430). + cleanupd: Sends MSG_SMB_UNLOCK twice to interested peers; (bso#13416). + cleanupd: Use MSG_SMB_BRL_VALIDATE to signal cleanupd unclean process shutdown; (bso#13414). + ctdb-client: Remove ununsed functions from old client code; (bso#13411). + printing: Return the same error code as windows does on upload failures; (bso#13395). + nsswitch: Fix memory leak in winbind_open_pipe_sock() when the privileged pipe is not accessable; (bso#13400). + s4:lsa_lookup: remove TALLOC_FREE(state) after all dcesrv_lsa_Lookup{Names,Sids}_base_map() calls; (bso#13420). + rpc_server: Fix NetSessEnum with stale sessions; (bso#13407). + s3:smbspool: Fix cmdline argument handling; (bso#13417).- Move libdfs-server-ad-samba4.so library from kdc to libs package, as it is required by some client libs; (bsc#1074135); - Update to 4.8.1; (bsc#1091179); + s3: ldap: Ensure the ADS_STRUCT pointer doesn't get freed on error, we don't own it here; (bso#13244); + s3: smbd: Fix possible directory fd leak if the underlying OS doesn't support fdopendir(); (bso#13270); + Round-tripping ACL get/set through vfs_fruit will increase the number of ACE entries without limit; (bso#13319); + s3: smbd: SMB2: Add DBGC_SMB2_CREDITS class to specifically debug credit issues; (bso#13347); + s3: smbd: Files or directories can't be opened DELETE_ON_CLOSE without delete access; (bso#13358); + s3: smbd: Fix memory leak in vfswrap_getwd(); (bso#13372); + s3: smbd: Unix extensions attempts to change wrong field in fchown call; (bso#13375); + ms_schema/samba-tool visualize: Fix python2.6 incompatibility; (bso#13337); + Fix invocation of gnutls_aead_cipher_encrypt(); (bso#13352); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + winbindd: Recover loss of netlogon secure channel in case the peer DC is rebooted; (bso#13332); + s3:smbd: Don't use the directory cache for SMB2/3; (bso#13363); + ctdb-client: Fix bugs in client code; (bso#13356); + ctdb-scripts: Drop "net serverid wipe" from 50.samba event script; (bso#13359); + s3: lib: messages: Don't use the result of sec_init() before calling sec_init(); (bso#13368); + libads: Fix the build '--without-ads'; (bso#13273); + winbind: Keep "force_reauth" in invalidate_cm_connection, add 'smbcontrol disconnect-dc'; (bso#13332); + vfs_virusfilter: Fix CIDs 1428738-1428740; (bso#13343); + dsdb: Fix CID 1034966 Uninitialized scalar variable; (bso#13367); + rpc_server: Fix core dump in dfsgetinfo; (bso#13370); + smbclient: Fix notify; (bso#13382); + Fix smbd panic if the client-supplied channel sequence number wraps; (bso#13215); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + lib/util: Remove unused '#include ' from tests/tfork.c; (bso#13342); + Fix build errors with cc from developerstudio 12.5 on Solaris; (bso#13343); + Fix the picky-developer build on FreeBSD 11; (bso#13344); + s3:modules: Fix the build of vfs_aixacl2.c; (bso#13345); + s3:smbd: map nterror on smb2_flush errorpath; (bso#13338); + lib:replace: Fix linking when libtirpc-devel overwrites system headers; (bso#13341); + winbindd: 'wbinfo --name-to-sid' returns misleading result on invalid query; (bso#13312); + s3:passdb: Do not return OK if we don't have pinfo set up; (bso#13376); + Allow AESNI to be used on all processor supporting AESNI; (bso#13302);- Use new foreground execution flags for systemd samba daemons; (bsc#1088574); (bsc#1071090); (bsc#1065551); + Add %post scriptlet to clear old sysconfig flags - Update vendor-files to commit 880b3e7. + Set samba sysconfig template variables to "" + Add required daemon flags directly to systemd unit- Specfile cleanup + Remove %if..%endif guards which don't affect the build + Remove redundant %clean section + Replace old $RPM_* shell vars with macros- BuildRequire pkgconfig(systemd) and pkgconfig(libsystemd) in place of systemd and systemd-devel: Allow OBS to optimize the workload by allowing the usage of the 'build-optimized' systemd packages.- Enable building samba with python3, and create a samba-python3 package.- Update to 4.8 + New GUID Index mode in sam.ldb for the AD DC + GPO support for samba KDC + Time machine support with vfs_fruit + Encrypted secrets + AD Replication visualization + Improved trust support - ability to not scan global trust list - AD external trusts have limited support - verbose trusted domain listing + VirusFilter VFS module + NT4-style replication removed + vfs_aio_linux removed- Disable samba-pidl package, due to the removal of dependency perl-Parse-Yapp; (bsc#1085150);- Update to 4.7.6; + CVE-2018-1050: DOS vulnerability when SPOOLSS is run externally; (bso#11343); (bsc#1081741); + CVE-2018-1057: Authenticated users can change other users' password; (bso#13272); (bsc#1081024).- Disable python until full python3 port is done; (bsc#1082139); + Remove contents of package samba-python + Remove contents of package libsamba-policy0 + Remove contents of package libsamba-policy-devel + Remove library libsamba-python-samba4.so from samba-libs package + Remove library libsamba-net-samba4.so from samba-libs package + Remove smbtorture binary and manpage from samba-test- samba fails to build with glibc2.27; (bsc#1081042);- Update to 4.7.5; (bsc#1080545); + smbd tries to release not leased oplock during oplock II downgrade; (bso#13193); + Fix copying file with empty FinderInfo from Windows client to Samba share with fruit; (bso#13181); + build: Deal with recent glibc sunrpc header removal; (bso#10976); + Make Samba work with tirpc and libnsl2; (bso#13238); + vfs_ceph: Add fs_capabilities hook to avoid local statvfs; (bso#13208); (bsc#1075206); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + ctdb-recovery-helper: Deregister message handler in error paths; (bso#13188); + samba: Only use async signal-safe functions in signal handler; (bso#13240); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + repl_meta_data: Fix linked attribute corruption on databases with unsorted links on expunge. dbcheck: Add functionality to fix the corrupt database; (bso#13228); + Fix smbd panic when chdir returns error during exit; (bso#13189); + Make Samba work with tirpc and libnsl2; (bso#13238); + Fix POSIX ACL support on HPUX and possibly other big-endian OSs; (bso#13176);- Update to 4.7.4; (bsc#1080545); + s3: smbclient: Implement 'volume' command over SMB2; (bso#13140); + s3: libsmb: Fix valgrind read-after-free error in cli_smb2_close_fnum_recv(); (bso#13171); + s3: libsmb: Fix reversing of oldname/newname paths when creating a reparse point symlink on Windows from smbclient; (bso#13172); + Build man page for vfs_zfsacl.8 with Samba; (bso#12934); + repl_meta_data: Allow delete of an object with dangling backlinks; (bso#13095); + s4:samba: Fix default to be running samba as a deamon; (bso#13129); + Performance regression in DNS server with introduction of DNS wildcard, ldb: Release 1.2.3; (bso#13191); + vfs_zfsacl: Fix compilation error; (bso#6133); + "smb encrypt" setting changes are not fully applied until full smbd restart; (bso#13051); + winbindd: Fix idmap_rid dependency on trusted domain list; (bso#13052); + vfs_fruit: Proper VFS-stackable conversion of FinderInfo; (bso#13155); + winbindd: Dependency on trusted-domain list in winbindd in critical auth codepath; (bso#13173); + repl_meta_data: Fix removing of backlink on deleted objects; (bso#13120); + ctdb: sock_daemon leaks memory; (bso#13153); + TCP tickles not getting synchronised on CTDB restart; (bso#13154); + winbindd: winbind parent and child share a ctdb connection; (bso#13150); + pthreadpool: Fix deadlock; (bso#13170); + pthreadpool: Fix starvation after fork; (bso#13179); + messaging: Always register the unique id; (bso#13180); + s4/smbd: set the process group; (bso#13129); + Fix broken linked attribute handling; (bso#13095); + The KDC on an RWDC doesn't send error replies in some situations; (bso#13132); + libnet_join: Fix 'net rpc oldjoin'; (bso#13149); + g_lock conflict detection broken when processing stale entries; (bso#13195); + s3:smb2_server: allow logoff, close, unlock, cancel and echo on expired sessions; (bso#13197); + s3:libads: net ads keytab list fails with "Key table name malformed"; (bso#13166); (bsc#1067700); + Fix crash in pthreadpool thread after failure from pthread_create; (bso#13170); + s4:samba: Allow samba daemon to run in foreground; (bso#13129); (bsc#1065551); + third_party: Link the aesni-intel library with "-z noexecstack"; (bso#13174); + vfs_glusterfs: include glusterfs/api/glfs.h without relying on "-I" options; (bso#13125);- Re-enable usage of libnsl (did got lost with glibc change) - Use TI-RPC (sunrpc is deprecated and will be removed soon from glibc)- smbc_opendir should not return EEXIST with invalid login credentials; (bnc#1065868).- Update to 4.7.3; (bsc#1069666); + Non-smbd processes using kernel oplocks can hang smbd; (bso#13121); + python: use communicate to fix Popen deadlock; (bso#13127); + smbd on disk file corruption bug under heavy threaded load; (bso#13130); + tevent: version 0.9.34; (bso#13130); + s3: smbd: Fix delete-on-close after smb2_find; (bso#13118); + CVE-2017-14746: s3: smbd: Fix SMB1 use-after-free crash bug; (bsc#1060427);(bso#13041); + CVE-2017-15275: s3: smbd: Chain code can return uninitialized memory when talloc buffer is grown; (bsc#1063008); (bso#13077); - Build with AD DC support only in openSUSE.- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- samba-tool requires samba-python; (bnc#1067771).- Run all daemons in the foreground and let systemd handle it; (bsc#1065551). - Update to 4.7.1; + Fix exporting subdirs with shadow_copy2; (bso#13091); + Currently if getwd() fails after a chdir(), we panic; (bso#13027); + Ensure default SMB_VFS_GETWD() call can't return a partially completed struct smb_filename; (bso#13068); + sys_getwd() can leak memory or possibly return the wrong errno on older systems; (bso#13069); + smbclient doesn't correctly canonicalize all local names before use; (bso#13093); + Fix broken linked attribute handling; (bso#13095); + Missing LDAP query escapes in DNS rpc server; (bso#12994); + Link to -lbsd when building replace.c by hand; (bso#13087); + Cannot delete non-ACL files on Solaris/ZFS/NFSv4 ACL filesystem; (bso#6133); + Map SYNCHRONIZE acl permission statically in zfs_acl vfs module; (bso#7909); + Samba fails to honor SEC_STD_WRITE_OWNER bit with the acl_xattr module; (bso#7933); + Missing assignment in sl_pack_float; (bso#12991); + Wrong Samba access checks when changing DOS attributes; (bso#12995); + samba_runcmd_send() leaves zombie processes on timeout; (bso#13062); + groupmap cleanup should not delete BUILTIN mappings; (bso#13065); + Enabling vfs_fruit results in loss of Finder tags and other xattrs; (bso#13076); + man pages: Properly ident lists; (bso#9613); + smb.conf.5: Sort parameters alphabetically; (bso#13081); + Fix GUID string format on GetPrinter info; (bso#12993); + Remote serverid check doesn't check for the unique id; (bso#13042); + CTDB starts consuming memory if there are dead nodes in the cluster; (bso#13056); + ctdb-common: Ignore event scripts with multiple '.'s; (bso#13070); + libgpo doesn't sort the GPOs in the correct order; (bso#13046); + Remote serverid check doesn't check for the unique id; (bso#13042); + vfs_catia: Fix a potential memleak; (bso#13090); + Fix file change notification for renames; (bso#12903); + Samba DNS server does not honour wildcards; (bso#12952); + Can't change password in samba from a Windows client if Samba runs on IPv6 only interface; (bso#13079); + vfs_fruit: Replace closedir() by SMB_VFS_CLOSEDIR; (bso#13086); + Apple client can't cope with SMB2 async replies when creating symlinks; (bso#13047); + s4:rpc_server:backupkey: Move variable into scope; (bso#12959); + Fix ntstatus_gen.h generation on 32bit; (bso#13099); + Fix a double free in vfs_gluster_getwd(); (bso#13100); + Fix resouce leaks and pointer issues; (bso#13101); + vfs_solarisacl: Fix build for samba 4.7 and up; (bso#13049);- Add samba-kdc to baselibs.conf. - Do not wrap samba-kdc's package definition into if/endif: the package won't be generated simply based on the fact that there is no files section for the package. Allows the source validator to ensure samba-kdc is a built package.- Update to 4.7.0; + Whole DB read locks: Improved LDAP and replication consistency; (bso#12858). + Samba AD with MIT Kerberos + Dynamic RPC port range: Default range changed from "1024-1300" to "49152-65535". + Authentication and Authorization audit support: New auth_audit debug class. + Multi-process LDAP Server: The LDAP server in the AD DC now honours the process model used for the rest of the 'samba' process. + Improved Read-Only Domain Controller (RODC) Support; (bso#12977). + Additional password hashes stored in supplementalCredentials. + Improvements to DNS during Active Directory domain join. + Significant AD performance and replication improvements. + Query record for open file or directory. + Removal of lpcfg_register_defaults_hook(). + Change of loadable module interface. + SHA256 LDAPS Certificates: The self-signed certificate generated for use on LDAPS will now be generated with a SHA256 self-signature, not a SHA1 self-signature. + CTDB no longer allows mixed minor versions in a cluster. + CTDB now ignores hints from Samba about TDB flags when attaching to databases. + New configuration variable CTDB_NFS_CHECKS_DIR. + The CTDB_SERVICE_AUTOSTARTSTOP configuration has been removed. + The CTDB_SCRIPT_DEBUGLEVEL configuration variable has been removed. + The example NFS Ganesha call-out has been improved. + A new "replicated" database type is available.- CVE-2017-12163: Prevent client short SMB1 write from writing server memory to file; (bso#13020); (bsc#1058624).- CVE-2017-12150: Some code path don't enforce smb signing, when they should; (bso#12997); (bsc#1058622).- CVE-2017-12151: Keep required encryption across SMB3 dfs redirects; (bso#12996); (bsc#1058565).- Clean specfile assuming SUSE-only system and product >=SLE11 + %{ul_version}, %{rhel_version}, %{mandriva_version}, %{centos_version} are always undefined + %{_vendor} is "suse" and %{suse_version} is at least 1100- Update to 4.6.7; (bsc#1054017) + Joining a Huawai storage fails: empty CLDAP ping answer; (bso#11392). + smbcacls can fail against a directory on Windows using SMB2.; (bso#12937). + vfs_ceph provides inconsistent directory listings; (bso#12911). + Misused talloc context can cause a user to crash their smbd by chaining SMB1 commands.; (bso#12836). + Use-after free can crash libsmbclient code.; (bso#12927). + Server exit with active AIO can crash.; (bso#12925). + Ensure notifyd doesn't return from smbd_notifyd_init; (bso#12910). + fd leak to ctdb sub-processes leads to SELinux AVC denial in audit logs; (bso#12898). + vfs_fruit shouldn't send MS NFS ACEs to Windows clients; (bso#12897). + smbspool_krb5_wrapper does not tell CUPS that it requires negotiate for authentication; (bso#12886). + finder sidebar showing question mark instead of icon when using ip to connect with vfs_fruit; (bso#12840). + Winbind stops obtaining the 'unixHomeDirectory' & 'loginShell' attributes from AD.; (bso#12720). + KCC run at selftest startup can fail spuriously due to a race; (bso#12869). + winbindd changes the local password and gets NT_STATUS_WRONG_PASSWORD for the remote change; (bso#12782). + rpc_pipe_client memory leaks due to long term memory context passed to rpc_pipe_open_interface(); (bso#12890). + CVE-2017-2619 breaks accessing previous versions of directories with snapshots in subdirectories of the share; (bso#12885). + dns_name_equal doing OOB read; (bso#12813). + replica_sync tests flap; (bso#12753). + Selftest should not call 'net cache flush' and wipe important winbind entries; (bso#12868). + Old Samba versions don't support using recent ldb versions (>=1.1.30); (bso#12859). + pam_winbind fails with kerberos method = secrets and keytab; (bso#10490). + race starting winbindd against posixacl test; (bso#12843). + Crash in the reentrant smbd_smb2_create_send() if the something fails in the subsequent try; (bso#12832). + spnego.c passes the wrong argument order to gensec_update_ev() for the FALLBACK case; (bso#12788). + Clients with SMB3 support can't connect with "server max protocol = SMB2_02"; (bso#12772). + A log message of samb-tool user syncpasswords reverses string arguments in a debug message "Call Popen[...".; (bso#12768). + The smb tarmode tests kills the share dir contents; (bso#12867). + Fix for a bug in MacOS X Sierra NTLMv2 processing; (bso#12862). + CVE-2017-2619 regression with non-wide symlinks to directories; (bso#12860). + manpage/index.html lists links not in alphabetical order; (bso#12854). + smbcacls got error NT_STATUS_NETWORK_NAME_DELETED; (bso#12831). + If a record is locked in a database, then recovery does not complete; (bso#12857). + debug_locks.sh script does not log any information; (bso#12856). + SIGSEGV in cm_connect_lsa_tcp dereferencing conn->lsa_tcp_pipe->transport after error; (bso#12852). + smbclient can't parse DOMAIN+username if a different winbind separator is used; (bso#12849). + Related requests with SessionSetup fail with INTERNAL_ERROR; (bso#12845). + Related requests with TreeConnect fail with NETWORK_NAME_DELETED; (bso#12844). + cli->server_os not filled correctly; (bso#12779). + REGRESSION: smbclient doesn't print the session setup anymore; (bso#12824). + smblcient doesn't handle STATUS_NOT_SUPPORTED gracefully for FSCTL_VALIDATE_NEGOTIATE_INFO; (bso#12808). + CTDB NFS call-out failures do not cause event failures; (bso#12837). + net command fails due to incorrectly return code; (bso#12828). + Fix building Samba with GCC 7.1; (bso#12827).- Fix duplicate CTDB_LOGGING params when downgraded and upgraded again; (bsc#1048339).- fix cephwrap_chdir(); (bsc#1048790). - Update to 4.6.6 + CVE-2017-11103: Orpheus' Lyre KDC-REP service name validation; (bsc#1048278).- Fix ctdb logs to /var/log/log.ctdb instead of /var/log/ctdb; (bsc#1048339).- Fix inconsistent ctdb socket path; (bsc#1048352). - Fix non-admin cephx authentication; (bsc#1048387).- Update to 4.6.5; (bsc#1040157) + Specifying CTDB_LOGGING=syslog:nonblocking causes ctdbd to crash at startup; (bso#12814). + vfs_expand_msdfs tries to open the remote address as a file path; (bso#12687). + PANIC (pid 1096): assert failed: lease_type_is_exclusive(e_lease_type); (bso#12798). + With clustering get update_num_read_oplocks failed and PANIC: num_share_modes == 1 assertion failure; (bso#11844). + contend_level2_oplocks_begin_default oplock optimisation doesn't carry over to leases; (bso#12766). + `ctdb nodestatus` incorrectly displays status for all nodes with wrong exit code; (bso#12802). + CTDB can spin hard on revoking readonly delegations if a node becomes disconnected; (bso#12697). + Printing a share mode entry with leases can crash in the ndr code; (bso#12793). + Fix flakey unit tests for eventd; (bso#12792). + CTDB daemon crashes if built with clang; (bso#12770). + smbcacls fails if no password is specified; (bso#12765). + idmap_rfc2307: Lookup of more than two SIDs fails; (bso#12757). + samba-tool user syncpasswords doesn't trigger the script when a user gets removed; (bso#12767). + systemd: fix detection of libsystemd; (bso#12764). + Notify subsystem only maps first inotify mask to Windows notify filter; (bso#12760). + Allow passing trusted domain password as plain-text to PASSDB layer; (bso#12751). + Can't case-rename files with vfs_fruit; (bso#12749). + wrong sid->uid mapping for SIDs residing in sIDHistory; (bso#12702). + vfs_acl_common should force "create mask = 0777", not 0666; (bso#12562). + Ordering of notify responses broken; (bso#12756).- s3: libsmb: Fix error where short name length was read as 2 bytes, should be 1; (bso#11822); (bsc#1042419).- Revert explicit winbind %{version}-%{release} dependency. + The ABI has stabilized since (bsc#936909), so remove to fix cross-media dependencies; (bsc#1037899).- Fix CVE-2017-7494 remote code execution from a writable share; (bso#12780); (bsc#1038231).- Update to 4.6.3; (bsc#1036011) + s3:vfs:shadow_copy2: vfs_shadow_copy2 fails to list snapshots from shares with GlusterFS backend; (bso#12743). + Fix for Solaris C compiler; (bso#12559). + s3: locking: Update oplock optimization for the leases era; (bso#12628). + Make the Solaris C compiler happy; (bso#12693). + s3: libgpo: Allow skipping GPO objects that don't have the expected LDAP attributes; (bso#12695). + Fix buffer overflow caused by wrong use of getgroups; (bso#12747). + lib: debug: Avoid negative array access; (bso#12746). + cleanupdb: Fix a memory read error; (bso#12748). + streams_xattr and kernel oplocks results in NT_STATUS_NETWORK_BUSY; (bso#7537). + winbindd: idmap_autorid allocates ids for unknown SIDs from other backends; (bso#11961). + vfs_fruit: Resource fork open request with flags=O_CREAT|O_RDONLY; (bso#12565). + manpages/vfs_fruit: Document global options; (bso#12615). + lib/pthreadpool: Fix a memory leak; (bso#12624). + Lookup-domain for well-known SIDs on a DC; (bso#12727). + winbindd: Fix error handling in rpc_lookup_sids(); (bso#12728). + winbindd: Trigger possible passdb_dsdb initialisation; (bso#12729). + credentials_krb5: use gss_acquire_cred for client-side GSSAPI use case; (bso#12611). + lib/crypto: Implement samba.crypto Python module for RC4; (bso#12690). + ctdb-readonly: Avoid a tight loop waiting for revoke to complete; (bso#12697). + ctdb_event monitor command crashes if event is not specified; (bso#12723). + ctdb-docs: Fix documentation of "-n" option to 'ctdb tool'; (bso#12733). + smbd: Fix smb1 findfirst with DFS; (bso#12558). + smbd: Do an early exit on negprot failure; (bso#12610). + winbindd: Fix substitution for 'template homedir'; (bso#12699). + s4:kdc: Disable principal based autodetected referral detection; (bso#12554). + idmap_autorid: Allocate new domain range if the callers knows the sid is valid; (bso#12613). + LINKFLAGS_PYEMBED should not contain -L/some/path; (bso#12724). + PAM auth with WBFLAG_PAM_GET_PWD_POLICY returns wrong policy for trusted domain; (bso#12725). + rpcclient: Allow -U'OTHERDOMAIN\user' again; (bso#12731). + winbindd: Fix password policy for pam authentication; (bso#12725). + s3:gse: Correctly handle external trusts with MIT; (bso#12554). + auth/credentials: Always set the realm if we set the principal from the ccache; (bso#12611). + replace: Include sysmacros.h; (bso#12686). + s3:vfs_expand_msdfs: Do not open the remote address as a file; (bso#12687). + s3:libsmb: Only print error message if kerberos use is forced; (bso#12704). + winbindd: Child process crashes when kerberos-authenticating a user with wrong password; (bso#12708). + vfs_fruit: Office document opens as read-only on macOS due to CNID semantics; (bso#12715). + vfs_acl_xattr: Fix failure to get ACL on Linux if memory is fragmented; (bso#12737).- Generate and update vendor-files tarball from Git + SuSEfirewall2 service samba-client only setup IPv4 rule; (bsc#1034416).- Generate source tarball directly from Git using OBS tar_scm + use version string derived from parent Git tag and commit hash - remove obsolete vendor-files/tools/package-data version ID + explicitly generate ctdb manpages, needed without "make dist"- Update to 4.6.2 + remove bso#12721 patches now upstream- Enable samba-ceph build for openSUSE and SLE12SP3+; (fate#321622). + x86-64 and aarch64- Enable librados CTDB lock helper for samba-ceph package; (fate#321622).- Build and install the html man pages (bsc#1021907).- Fix CVE-2017-2619 regression with "follow symlinks = no"; (bso#12721).- Update to 4.6.1 + symlink race permits opening files outside share directory; CVE-2017-2619; (bso#12496); (bsc#1027147) + testparm checks for valid idmap parameters + add new krb client encryption types + support for printer driver upload from windows 10 + inherit owner = 'unix only' for improved quota support + improved CTDB event support + new primary group support for idmap_ad + idmap_hash deprecated + mvxattr added to recursively rename extended attributes- Remove chkconfig requirements for systemd systems- Don't call insserv if systemd is used- Fix check if we need to require insserv- async_req: make async_connect_send() "reentrant"; (bso#12105); (bsc#1024416).- Force usage of ncurses6-config thru NCURSES_CONFIG env var; (bsc#1023847).- add missing patch for libnss_wins segfault; (bsc#995730).- Fix vfs_ceph builds against recent Ceph versions; (bsc#1021933).- Document "winbind: ignore domains" parameter; (bsc#1019416).- Add base Samba dependency to samba-ceph package.- Update to 4.5.3 + Heap-based Buffer Overflow Remote Code Execution Vulnerability; CVE-2016-2123; (bso#12409); (bsc#1014437). + Don't send delegated credentials to all servers; CVE-2016-2125; (bso#12445); (bsc#1014441). + denial of service due to a client triggered crash in the winbindd parent process; CVE-2016-2126; (bso#12446); (bsc#1014442). - 4.5.1 and 4.5.2 updates + various streams vfs fixes + various printing fixes + ntlm_auth: do not map explicitly empty domain + various stability fixes in smbd + match file compression ReFS behavior- Add missing ldb module directory; (bnc#1012092).- s3/client: obey 'disable netbios' smb.conf param, don't connect via NBT port; (bsc#1009085); (bso#12418).- Include vfstest in samba-test; (bsc#1001203).- s3/winbindd: using default domain with user@domain.com format fails; (bsc#997833).- Fix segfault in libnss_wins; (bso#12277); (bso#12269); (bsc#995730).- Update to 4.5.0 + NTLM1 Authentication disabled by default + SMB2.1 leases enabled by default + Support for OFD locks + ctdb tool rewritten + Added shadow copy snapshot prefix parameter- Fix illegal memory access after memory has been deleted; (bso#11836); (bsc#975299).- Prevent core, make sure response->extra_data.data is always cleared out; (bsc#993692).- Don't package man pages for VFS modules that aren't built; (boo#993707).- Fix population of ctdb sysconfig after source merge; (bsc#981566).- Enable vfs_ceph builds for Factory (x86-64) + Package as samba-ceph to avoid Ceph dependency in base package.- Update to 4.4.5 + Prevent client-side SMB2 signing downgrade; CVE-2016-2119; (bso#11860); (bsc#986869).- Remove obsolete syslog.target; (bsc#983938).- Honor smb.conf socket options in winbind; (bsc#975131).- Don't use htons() with IP_PROTO_RAW; (bso#11705); (bsc#969522).- Update to 4.4.4 + SMB3 multichannel: Add implementation of missing channel sequence number verification; (bso#11809). + smbd:close: Only remove kernel share modes if they had been taken at open; (bso#11919). + notifyd: Prevent NULL deref segfault in notifyd_peer_destructor; (bso#11930). + s3:rpcclient: Make '--pw-nt-hash' option work; (bso#10796). + Fix case sensitivity issues over SMB2 or above; (bso#11438). + s3:smbd: Fix anonymous authentication if signing is mandatory. (bso#11910) + Fix NTLM Authentication issue with squid; (bso#11914). + pdb: Fix segfault in pdb_ldap for missing gecos; (bso#11530). + Fix memory leak in share mode locking; (bso#11934).- Update to 4.4.3 + Various post-badlock regressions; (bso#11841); (bso#11850); (bso#11858); (bso#11870); (bso#11872). + Only allow idmap_hash for default idmap config (bso#11786). + smbd: Avoid large reads beyond EOF; (bso#11878). + vfs_acl_common: Avoid setting POSIX ACLs if "ignore system acls" is set; (bso#11806). + libads: Record session expiry for spnego sasl binds; (bso#11852).- Fix NTLMSSP regressions caused by previous CVE fixes; (bso#11849); (bsc#975962); (bsc#979268), (bsc#977669).- Revert shared library packaging to comply with SLPP- Update to 4.4.2 + A man-in-the-middle can downgrade NTLMSSP authentication; CVE-2016-2110; (bso#11688); (bsc#973031). + Domain controller netlogon member computer can be spoofed; CVE-2016-2111; (bso#11749); (bsc#973032). + LDAP conenctions vulnerable to downgrade and MITM attack; CVE-2016-2112; (bso#11644); (bsc#973033). + TLS certificate validation missing; CVE-2016-2113; (bso#11752); (bsc#973034). + Named pipe IPC vulnerable to MITM attacks; CVE-2016-2115; (bso#11756); (bsc#973036). + "Badlock" DCERPC impersonation of authenticated account possible; CVE-2016-2118; (bso#11804); (bsc#971965). + DCERPC server and client vulnerable to DOS and MITM attacks; CVE-2015-5370; (bso#11344); (bsc#936862).- Fix samba.tests.messaging test and prevent potential tdb corruption by removing obsolete now invalid tdb_close call; (bsc#974629).- Obsolete libsmbclient from libsmbclient0 while not providing it; (bsc#972197).- Update to 4.4.0. + Read of uninitialized memory DNS TXT handling; (bso#11128); (bso#11686); CVE-2016-0771. + Getting and setting Windows ACLs on symlinks can change permissions on link target; (bso#11648); CVE-2015-7560. + Sockets with htons(IPPROTO_RAW); (bso#11705); CVE-2015-8543. + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystem with no ACL support; (bso#10489). + docs: Add example for domain logins to smbspool man page; (bso#11643). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + docs: Add smbspool_krb5_wrapper manpage; (bso#11690). + winbindd: Return trust parameters when listing trusts; (bso#11691). + ctdb: Do not provide a useless pkgconfig file for ctdb; (bso#11696). + Crypto.Cipher.ARC4 is not available on some platforms, fallback to M2Crypto.RC4.RC4 then; (bso#11699). + s3:utils/smbget: Set default blocksize; (bso#11700). + Streamline 'smbget' options with the rest of the Samba utils; (bso#11700). + s3:clispnego: Fix confusing warning in spnego_gen_krb5_wrap(); (bso#11702). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + s3:vfs:glusterfs: Fix build after quota changes; (bso#11715). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + lib:socket: Fix CID 1350010: Integer OVERFLOW_BEFORE_WIDEN; (bso#11723). + smbd: Fix CID 1351215 Improper use of negative value; (bso#11724). + smbd: Fix CID 1351216 Dereference null return value; (bso#11725). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + docs: Add manpage for cifsdd; (bso#11730). + param: Fix str_list_v3 to accept ; again; (bso#11732). + lib/socket: Fix improper use of default interface speed; (bso#11734). + lib:socket: Fix CID 1350009: Fix illegal memory accesses (BUFFER_SIZE_WARNING); (bso#11735). + libcli: Fix debug message, print sid string for new_ace trustee; (bso#11738). + Fix installation path of Samba helper binaries; (bso#11739). + Fix memory leak in loadparm; (bso#11740). + tevent: version 0.9.28: Fix memory leak when old signal action restored; (bso#11742). + smbd: Ignore SVHDX create context; (bso#11753). + Fix net join; (bso#11755). + s3:libads: setup the msDS-SupportedEncryptionTypes attribute on ldap_add; (bso#11755). + passdb: Add linefeed to debug message; (bso#11763). + s3:utils/smbget: Fix option parsing; (bso#11767). + libnet: Make Kerberos domain join site-aware; (bso#11769). + Reset TCP Connections during IP failover; (bso#11770). + ldb: Version 1.1.26; (bso#11772). + s3:smbd: Add negprot remote arch detection for OSX; (bso#11773). + vfs_glusterfs: Fix use after free in AIO callback; (bso#11774). + mkdir can return ACCESS_DENIED incorrectly on create race; (bso#11780). + "trustdom_list_done: Got invalid trustdom response" message should be avoided; (bso#11782). + Mismatch between local and remote attribute ids lets replication fail with custom schema; (bso#11783). + Quota is not supported on Solaris 10; (bso#11788). + Talloc: Version 2.1.6; (bso#11789). + smbd: Enable multi-channel if 'server multi channel support = yes' in the config; (bso#11796). + build: Fix build when '--without-quota' specified; (bso#11798). + lib/socket/interfaces: Fix some uninitialied bytes; (bso#11802). + Access based share enum: handle permission set in configuration files; (bso#8093). + See also WHATSNEW.txt from the samba-doc package.- Update to 4.3.6. + Getting and setting Windows ACLs on symlinks can change permissions on link target; CVE-2015-7560; (bso#11648); (bsc#968222). + Fix Out-of-bounds read in internal DNS server; CVE-2016-0771; (bso#11128); (bso#11686); (bsc#968223).- Upgrade on-disk FSRVP server state to new version; (bsc#924519).- Only obsolete but do not provide gplv2/3 package names; (bsc#968973).- Relocate existing lock files to /var/lib/samba/lock; (bsc#968963).- Obsolete no longer existing samba-32bit package; (bsc#967625).- Update to 4.3.5. + s3:utils/smbget: Fix recursive download; (bso#6482). + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystemi with no ACL support; (bso#10489). + s3:smbd/oplock: Obey kernel oplock setting when releasing oplocks; (bso#11400). + vfs_shadow_copy2: Fix case where snapshots are outside the share; (bso#11580). + smbclient: Query disk usage relative to current directory; (bso#11662). + winbindd: Handle expired sessions correctly; (bso#11670). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + smbcacls: Fix uninitialized variable; (bso#11682). + s3:smbd: Ignore initial allocation size for directory creation; (bso#11684). + s3-client: Add a KRB5 wrapper for smbspool; (bso#11690). + s3-parm: Clean up defaults when removing global parameters; (bso#11693). + Use M2Crypto.RC4.RC4 on platforms without Crypto.Cipher.ARC4; (bso#11699). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + ctdb: Remove error messages after kernel security update; CVE-2015-8543; (bso#11705). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + param: Fix str_list_v3 to accept ";" again; (bso#11732).- Shift samba-client sysconfig data into samba and samba-winbind; (bsc#947361).- Simplify shared library packaging; (bsc#966956).- Enable clustering (CTDB) support; (bsc#966271).- s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703); (bsc#964023).- Add quotes around path of update-apparmor-samba-profile; (bnc#962177).- Remove autoconf build-time requirement.- Update to 4.3.4. + vfs_fruit: Enable POSIX directory rename semantics; (bso#11065). + Crash: Bad talloc magic value - access after free; (bso#11394). + Copying files with vfs_fruit fails when using vfs_streams_xattr without stream prefix and type suffix; (bso#11466). + samba-tool: Fix uncaught exception if no fSMORoleOwner attribute is given; (bso#11613). + Fix a typo in the smb.conf manpage, explanation of idmap config; (bso#11619). + Correctly initialize the list head when keeping a list of primary followed by DFS connections; (bso#11624). + Reduce the memory footprint of empty string options; (bso#11625). + lib/async_req: Do not install async_connect_send_test; (bso#11639). + Fix typos in man vfs_gpfs; (bso#11641). + Make "hide dot files" option work with "store dos attributes = yes"; (bso#11645). + Fix a corner case of the symlink verification; (bso#11647); (bnc#960249). + Do not disable "store dos attributes" on-the-fly; (bso#11649). + Update lastLogon and lastLogonTimestamp; (bso#11659).- Prevent access denied if the share path is "/"; (bso#11647); (bnc#960249).- Update to 4.3.3. + Malicious request can cause Samba LDAP server to hang, spinning using CPU; CVE-2015-3223; (bso#11325); (bnc#958581). + Remote read memory exploit in LDB; CVE-2015-5330; (bso#11599); (bnc#958586). + Insufficient symlink verification (file access outside the share); CVE-2015-5252; (bso#11395); (bnc#958582). + No man in the middle protection when forcing smb encryption on the client side; CVE-2015-5296; (bso#11536); (bnc#958584). + Currently the snapshot browsing is not secure thru windows previous version (shadow_copy2); CVE-2015-5299; (bso#11529); (bnc#958583). + Fix Microsoft MS15-096 to prevent machine accounts from being changed into user accounts; CVE-2015-8467; (bso#11552); (bnc#958585).- Update to 4.3.2. + vfs_gpfs: Re-enable share modes; (bso#11243). + dcerpc.idl: Accept invalid dcerpc_bind_nak pdus; (bso#11327). + s3-smbd: Fix old DOS client doing wildcard delete - gives an attribute type of zero; (bso#11452). + Add libreplace dependency to texpect, fixes a linking error on Solaris; (bso#11511). + s4: Fix linking of 'smbtorture' on Solaris; (bso#11512). + s4:lib/messaging: Use correct path for names.tdb; (bso#11562). + Fix segfault of 'net ads (join|leave) -S INVALID' with nss_wins; (bso#11563). + async_req: Fix non-blocking connect(); (bso#11564). + auth: gensec: Fix a memory leak; (bso#11565). + lib: util: Make non-critical message a warning; (bso#11566). + Fix winbindd crashes with samlogon for trusted domain user; (bso#11569); (bnc#949022). + smbd: Send SMB2 oplock breaks unencrypted; (bso#11570). + ctdb: Open the RO tracking db with perms 0600 instead of 0000; (bso#11577). + s3:smb2_server: Make the logic of SMB2_CANCEL DLIST_REMOVE() clearer; (bso#11581). + s3-smbd: Fix use after issue in smbd_smb2_request_dispatch(); (bso#11581). + manpage: Correct small typo error; (bso#11584). + s3: smbd: If EAs are turned off on a share don't allow an SMB2 create containing them; (bso#11589). + Backport some valgrind fixes from upstream master; (bso#11597). + auth: Consistent handling of well-known alias as primary gid; (bso#11608). + winbind: Fix crash on invalid idmap configs; (bso#11612). + s3: smbd: have_file_open_below() fails to enumerate open files below an open directory handle; (bso#11615). + Changing log level of two entries to DBG_NOTICE; (bso#9912).- Ensure samlogon fallback requests are rerouted after kerberos failure; (bnc#953382); (bnc#953972).- Ensure to link with --as-needed flag by removing SUSE_ASNEEDED=0. - Always use the default optimization even on pre-9.2 systems.- Remove redundant configure options while adding with-relro.- Relocate the lockdir to the /var/lib/samba/lock directory.- Cleanup and enhance the pidl sub package.- Require renamed python-ldb-devel and python-talloc-devel at build-time. - Requires python-ldb and python-talloc from the python subpackage.- Update to 4.3.1. + s3: smbd: Fix our access-based enumeration on "hide unreadable" to match Windows; (bso#10252). + nss_winbind: Fix hang on Solaris on big groups; (bso#10365). + smbd: Fix file name buflen and padding in notify repsonse; (bso#10634). + kerberos: Make sure we only use prompter type when available; winbind: Fix 100% loop; (bso#11038). + source3/lib/msghdr.c: Fix compiling error on Solaris; (bso#11053). + s3:ctdbd_conn: make sure we destroy tevent_fd before closing the socket; (bso#11316). + s3: smbd: Fix mkdir race condition; (bso#11486). + pam_winbind: Fix a segfault if initialization fails; (bso#11502). + s3: dfs: Fix a crash when the dfs targets are disabled; (bso#11509). + s4:lib/messaging: Use 'msg.lock' and 'msg.sock' for messaging related subdirs; (bso#11515). + s3: smbd: Fix opening/creating :stream files on the root share directory; (bso#11522). + lib/param: Fix hiding of FLAG_SYNONYM values; (bso#11526). + net: Fix a crash with 'net ads keytab create'; (bso#11528). + s3: smbd: Fix a crash in unix_convert(); (bso#11535). + s3: smbd: Fix NULL pointer bug introduced by previous 'raw' stream fix (bso#11522); (bso#11535). + vfs_fruit: Return value of ad_pack in vfs_fruit.c; (bso#11543). + vfs_commit: set the fd on open before calling SMB_VFS_FSTAT; (bso#11547). + s3:locking: Initialize lease pointer in share_mode_traverse_fn(); (bso#11549). + s3:smbstatus: Add stream name to share_entry_forall(); (bso#11550). + s3:lib: Validate domain name in lookup_wellknown_name(); (bso#11555). + s3: lsa: lookup_name() logic for unqualified (no DOMAIN component) names is incorrect; (bso#11555).- Fix 100% CPU in winbindd when logging in with "user must change password on next logon"; (bso#11038).- Relocate the tmpfiles.d directory to the client package; (bnc#947552).- Do not provide libpdb0 from libsamba-passdb0 but add it to baselibs.conf instead; (bnc#942716).- Package /var/lib/samba/private/sock with 0700 permissions; (bnc#946051).- Package /var/lib/samba/msg with 0755 permissions; (bso#11515); (bnc#945502).- Require to install libfam0-gamin from samba-libs on post-12.1 and pre-13.15 systems; (bnc#945013).- Update to 4.3.0. + Samba "map to guest = Bad uid" doesn't work; (bso#9862). + revert LDAP extended rule 1.2.840.113556.1.4.1941 LDAP_MATCHING_RULE_IN_CHAIN changes; (bso#10493). + No objectClass found in replPropertyMetaData on ordinary objects (non-deleted); (bso#10973). + Stream names with colon don't work with fruit:encoding = native; (bso#11278). + NetApp joined to a Samba/ADDC cannot resolve SIDs; (bso#11291). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + "force group" with local group not working; (bso#11320). + strsep is not available on Solaris; (bso#11359). + smbtorture does not build when configured --with-system-mitkrb5; (bso#11411). + Build with GPFS support is broken; (bso#11421). + Build broken with --disable-python; (bso#11424). + net share allowedusers crashes; (bso#11426). + nmbd incorrectly matches netbios names as own name; (bso#11427). + Python bindings don't check integer types; (bso#11429). + Python bindings don't check array sizes; (bso#11430). + CTDB's eventscript error handling is broken; (bso#11431). + Fix crash in nested ctdb banning; (bso#11432). + Cannot build ctdbpmda; (bso#11434). + samba-tool uncaught exception error; (bso#11436). + Crash in notify_remove caused by change notify = no; (bso#11444). + Poor SMB3 encryption performance with AES-GCM; (bso#11451). + Poor SMB3 encryption performance with AES-GCM (part1); (bso#11451). + fix recursion problem in rep_strtoll in lib/replace/replace.c; (bso#11455). + --bundled-libraries=!ldb,!pyldb,!pyldb-util doesn't disable ldb build and install; (bso#11458). + xid2sid gives inconsistent results; (bso#11464). + ctdb: Fix the build on FreeBSD 10.1; (bso#11465). + Handling of 0 byte resource fork stream; (bso#11467). + AD samr GetGroupsForUser fails for users with "()" in their name; (bso#11488).- Configure with --bundled-libraries=NONE; (bso#11458).- Adapt net-kdc-lookup patch for post-3.3 Samba versions; (bnc#295284).- Remove libiniparser-devel build-time requirement.- Update to 4.2.3. + s4:lib/tls: Fix build with gnutls 3.4; (bso#8780). + s4.2/fsmo.py: Fixed fsmo transfer exception; (bso#10924). + winbindd: Sync secrets.ldb into secrets.tdb on startup; (bso#10991). + Logon via MS Remote Desktop hangs; (bso#11061). + s3: lib: util: Ensure we read a hex number as %x, not %u; (bso#11068). + tevent: Add a note to tevent_add_fd(); (bso#11141). + s3:param/loadparm: Fix 'testparm --show-all-parameters'; (bso#11170). + s3-unix_msg: Remove socket file after closing socket fd; (bso#11217). + smbd: Fix a use-after-free; (bso#11218); (bnc#919309). + s3-rpc_server: Fix rpc_create_tcpip_sockets() processing of interfaces; (bso#11245). + s3:smb2: Add padding to last command in compound requests; (bso#11277). + Add IPv6 support to ADS client side LDAP connects; (bso#11281). + Add IPv6 support for determining FQDN during ADS join; (bso#11282). + s3: IPv6 enabled DNS connections for ADS client; (bso#11283). + Fix invalid write in ctdb_lock_context_destructor; (bso#11293). + Excessive cli_resolve_path() usage can slow down transmission; (bso#11295). + vfs_fruit: Add option "veto_appledouble"; (bso#11305). + tstream: Make socketpair nonblocking; (bso#11312). + idmap_rfc2307: Fix wbinfo '--gid-to-sid' query; (bso#11313). + Group creation: Add msSFU30Name only when --nis-domain was given; (bso#11315). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + Build fails on Solaris 11 with "‘PTHREAD_MUTEX_ROBUST’ undeclared"; (bso#11319). + smbd/trans2: Add a useful diagnostic for files with bad encoding; (bso#11323). + Change sharesec output back to previous format; (bso#11324). + Robust mutex support broken in 1.3.5; (bso#11326). + Kerberos auth info3 should contain resource group ids available from pac_logon; winbindd: winbindd_raw_kerberos_login - ensure logon_info exists in PAC; (bso#11328); (bnc#912457). + s3:smb2_setinfo: Fix memory leak in the defer_rename case; (bso#11329). + tevent: Fix CID 1035381 Unchecked return value; (bso#11330). + tdb: Fix CID 1034842 and 1034841 Resource leaks; (bso#11331). + s3: smbd: Use separate flag to track become_root()/unbecome_root() state; (bso#11339). + s3: smbd: Codenomicon crash in do_smb_load_module(); (bso#11342). + pidl: Make the compilation of PIDL producing the same results if the content hasn't change; (bso#11356). + winbindd: Disconnect child process if request is cancelled at main process; (bso#11358). + vfs_fruit: Check offset and length for AFP_AfpInfo read requests; (bso#11363). + docs: Overhaul the description of "smb encrypt" to include SMB3 encryption; (bso#11366). + s3:auth_domain: Fix talloc problem in connect_to_domain_password_server(); (bso#11367). + ncacn_http: Fix GNUism; (bso#11371).- Disable rpath usage; (bnc#902421).- Make the winbind package depend on the matching libwbclient version and vice versa; (bnc#936909).- Backport changes to use resource group sids obtained from pac logon_info; (bso#11328); (bnc#912457).- Order winbind.service Before and Want nss-user-lookup target.- Remove fam-devel build-time dependency for post-6 RHEL systems.- Update to 4.2.2. + s3:smbXsrv: refactor duplicate code into smbXsrv_session_clear_and_logoff(); (bso#11182). + gencache: don't fail gencache_stabilize if there were records to delete; (bso#11260). + s3: libsmbclient: After getting attribute server, ensure main srv pointer is still valid; (bso#11186). + s4: rpc: Refactor dcesrv_alter() function into setup and send steps; (bso#11236). + s3: smbd: Incorrect file size returned in the response of "FILE_SUPERSEDE Create"; (bso#11240). + Mangled names do not work with acl_xattr; (bso#11249). + nmbd rewrites browse.dat when not required; (bso#11254). + vfs_fruit: add option "nfs_aces" that controls the NFS ACEs stuff; (bso#11213). + s3:smbd: Add missing tevent_req_nterror; (bso#11224). + vfs: kernel_flock and named streams; (bso#11243). + vfs_gpfs: Error code path doesn't call END_PROFILE; (bso#11244). + s4: libcli/finddcs_cldap: continue processing CLDAP until all addresses are used; (bso#11284). + ctdb: check for talloc_asprintf() failure; (bso#11201). + spoolss: purge the printer name cache on name change; (bso#11210); (bnc#901813). + CTDB statd-callout does not scale; (bso#11204). + vfs_fruit: also map characters below 0x20; (bso#11221). + ctdb: Coverity fix for CID 1291643; (bso#11201). + Multiplexed RPC connections are not handled by DCERPC server; (bso#11225). + Fix terminate connection behavior for asynchronous endpoint with PUSH notification flavors; (bso#11226). + ctdb-scripts: Fix bashism in ctdbd_wrapper script; (bso#11007). + ctdb: Fix CIDs 1125615, 1125634, 1125613, 1288201 and 1125553; (bso#11201). + SMB2 should cancel pending NOTIFY calls with DELETE_PENDING if the directory is deleted; (bso#11257). + s3:winbindd: make sure we remove pending io requests before closing client sockets; (bso#11141); (bnc#931854). + Fix panic triggered by smbd_smb2_request_notify_done() -> smbXsrv_session_find_channel() in smbd; (bso#11182). + 'sharesec' output no longer matches input format; (bso#11237). + waf: Fix systemd detection; (bso#11200). + CTDB: Fix portability issues; (bso#11202). + CTDB: Fix some IPv6-related issues; (bso#11203). + CTDB statd-callout does not scale; (bso#11204). + 'net ads dns gethostbyname' crashes with an error in TALLOC_FREE if you enter invalid values; (bso#11234). + libads: record service ticket endtime for sealed ldap connections; (bso#11267). + lib/util: Include DEBUG macro in internal header files before samba_util.h; (bso#11033).- Avoid a crash inside the tevent epoll backend; (bso#11141); (bnc#931854).- Remove the independently built libraries ldb, talloc, tdn, and tevent and the post-10.3 renamed libsmbclient from baselibs.conf.- Drop redundant doc attribute from man pages.- Update to 4.2.1. + s3:winbind:grent: Don't stop group enumeration when a group has no gid; (bso#8905). + Initialize dwFlags field of DNS_RPC_NODE structure; (bso#9791). + s3: lib: ntlmssp: If NTLMSSP_NEGOTIATE_TARGET_INFO isn't set, cope with servers that don't send the 2 unused fields; (bso#10016). + build:wafadmin: Fix use of spaces instead of tabs; (bso#10476). + waf: Fix the build on openbsd; (bso#10476). + s3: client: "client use spnego principal = yes" code checks wrong name; (bso#10888). + spoolss: Retrieve published printer GUID if not in registry; (bso#11018). + s3: lib: libsmbclient: If reusing a server struct, check every cli->timout miliseconds if it's still valid before use; (bso#11079). + vfs_fruit: Enhance handling of malformed AppleDouble files; (bso#11125). + backupkey: Explicitly link to gnutls and gcrypt; (bso#11135). + replace: Remove superfluous check for gcrypt header; (bso#11135). + Backport subunit changes; (bso#11137). + libcli/auth: Match Declaration of netlogon_creds_cli_context_tmp with implementation; (bso#11140). + s3-winbind: Fix cached user group lookup of trusted domains; (bso#11143). + talloc: Version 2.1.2; (bso#11144). + Update libwbclient version to 0.12; (bso#11149). + brlock: Use 0 instead of empty initializer list; (bso#11153). + s4:auth/gensec_gssapi: Let gensec_gssapi_update() return NT_STATUS_LOGON_FAILURE for unknown errors; (bso#11164). + docs/idmap_rid: Remove deprecated base_rid from example; (bso#11169); (bnc#913304). + s3: libcli: smb1: Ensure we correctly finish a tevent req if the writev fails in the SMB1 case; (bso#11173). + backupkey: Use ndr_pull_struct_blob_all(); (bso#11174). + Fix lots of winbindd zombie processes on Solaris platform; (bso#11175). + s3: libsmbclient: Add missing talloc stackframe; (bso#11177). + s4-process_model: Do not close random fds while forking; (bso#11180). + s3-passdb: Fix 'force user' with winbind default domain; (bso#11185).- Prevent samba package updates from disabling samba kerberos printing.- Add sparse file support for samba; (fate#318424).- Purge printer name cache on spoolss SetPrinter change; (bso#11210); (bnc#901813).- Correctly retain errno from Btrfs snapshot ioctls; (bnc#923374).- Simplify libxslt build requirement and README.SUSE install. - Remove no longer required cleanup steps while populating the build root.- Remove deprecated base_rid example from idmap_rid manpage; (bso#11169); (bnc#913304).- Update to 4.2.0. + smbd: Stop using vfs_Chdir after SMB_VFS_DISCONNECT; (bso#1115). + pam_winbind: fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Make 'profiles' work again; (bso#9629). + s3:smb2_server: protect against integer wrap with "smb2 max credits = 65535"; (bso#9702). + Make validate_ldb of String(Generalized-Time) accept millisecond format ".000Z"; (bso#9810). + Use -R linker flag on Solaris, not -rpath; (bso#10112). + vfs: Add glusterfs manpage; (bso#10240). + Make 'smbclient' use cached creds; (bso#10279). + pdb: Fix build issues with shared modules; (bso#10355). + s4-dns: Add support for BIND 9.10; (bso#10620). + idmap: Return the correct id type to *id_to_sid methods; (bso#10720). + printing/cups: Pack requested-attributes with IPP_TAG_KEYWORD; (bso#10808). + Don't build vfs_snapper on FreeBSD; (bso#10834). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3: smb2cli: query info return length check was reversed; (bso#10848). + s3: lib, s3: modules: Fix compilation on Solaris; (bso#10849). + lib: uid_wrapper: Fix setgroups and syscall detection on a system without native uid_wrapper library; (bso#10851). + winbind3: Fix pwent variable substitution; (bso#10852). + Improve samba-regedit; (bso#10859). + registry: Don't leave dangling transactions; (bso#10860). + Fix build of socket_wrapper on systems without SO_PROTOCOL; (bso#10861). + build: Do not install 'texpect' binary anymore; (bso#10862). + Fix testparm to show hidden share defaults; (bso#10864). + libcli/smb: Fix smb2cli_validate_negotiate_info with min=PROTOCOL_NT1 max=PROTOCOL_SMB2_02; (bso#10866). + Integrate CTDB into top-level Samba build; (bso#10892). + samba-tool group add: Add option '--nis-domain' and '--gid'; (bso#10895). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + Fix smbclient loops doing a directory listing against Mac OS X 10 server with a non-wildcard path; (bso#10904). + Fix print job enumeration; (bso#10905); (bnc#898031). + samba-tool: Create NIS enabled users and unixHomeDirectory attribute; (bso#10909). + Add support for SMB2 leases; (bso#10911). + btrfs: Don't leak opened directory handle; (bso#10918). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: fix keytab array NULL termination; (bso#10933). + s3:passdb: fix logic in pdb_set_pw_history(); (bso#10940). + Cleanup add_string_to_array and usage; (bso#10942). + dbwrap_ctdb: Pass on mutex flags to tdb_open; (bso#10942). + Fix RootDSE search with extended dn control; (bso#10949). + Fix 'samba-tool dns serverinfo ' for IPv6; (bso#10952). + libcli/smb: only force signing of smb2 session setups when binding a new session; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + socket_wrapper: Add missing prototype check for eventfd; (bso#10965). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + vfs_streams_xattr: Check stream type; (bso#10971). + s3: smbd: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + vfs_fruit: Add support for AAPL; (bso#10983). + Fix spoolss IDL response marshalling when returning error without clearing info; (bso#10984). + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279). + Fix IPv6 support in CTDB; (bso#10996). + ctdb-daemon: Use correct tdb flags when enabling robust mutex support; (bso#11000). + vfs_streams_xattr: Add missing call to SMB_VFS_NEXT_CONNECT; (bso#11005). + s3-util: Fix authentication with long hostnames; (bso#11008). + ctdb-build: Fix build without xsltproc; (bso#11014). + packaging: Include CTDB man pages in the tarball; (bso#11014). + pdb_get_trusteddom_pw() fails with non valid UTF16 random passwords; (bso#11016). + Make Sharepoint search show user documents; (bso#11022). + nss_wrapper: check for nss.h; (bso#11026). + Enable mutexes in gencache_notrans.tdb; (bso#11032). + tdb_wrap: Make mutexes easier to use; (bso#11032). + lib/util: Avoid collision which alread defined consumer DEBUG macro; (bso#11033). + winbind: Retry after SESSION_EXPIRED error in ping-dc; (bso#11034). + s3-libads: Fix a possible segfault in kerberos_fetch_pac(); (bso#11037). + vfs_fruit: Fix base_fsp name conversion; (bso#11039). + vfs_fruit: mmap under FreeBSD needs PROT_READ; (bso#11040). + Fix authentication using Kerberos (not AD); (bso#11044). + net: Fix sam addgroupmem; (bso#11051). + vfs_snapper: Correctly handles multi-byte DBus strings; (bso#11055); (bnc#913238). + cli_connect_nb_send: Don't segfault on host == NULL; (bso#11058). + utils: Fix 'net time' segfault; (bso#11058). + libsmb: Provide authinfo domain for encrypted session referrals; (bso#11059). + s3-pam_smbpass: Fix memory leak in pam_sm_authenticate(); (bso#11066). + vfs_glusterfs: Add comments to the pipe(2) code; (bso#11069). + vfs/glusterfs: Change xattr key to match gluster key; (bso#11069). + vfs_glusterfs: Implement AIO support; (bso#11069). + s3-vfs: Fix developer build of vfs_ceph module; (bso#11070). + s3: netlogon: Ensure we don't call talloc_free on an uninitialized pointer; (bso#11077); CVE-2015-0240; (bnc#917376). + vfs: Add a brief vfs_ceph manpage; (bso#11088). + s3: smbclient: Allinfo leaves the file handle open; (bso#11094). + Fix Win8.1 Credentials Manager issue after KB2992611 on Samba domain; (bso#11097). + debug: Set close-on-exec for the main log file FD; (bso#11100). + s3: smbd: leases - losen paranoia check. Stat opens can grant leases; (bso#11102). + s3: smbd: SMB2 close. If a file has delete on close, store the return info before deleting; (bso#11104). + doc:man:vfs_glusterfs: improve the configuration section; (bso#11117). + snprintf: Try to support %j; (bso#11119). + ctdb-io: Do not use sys_write to write to client sockets; (bso#11124). + doc-xml: Add 'sharesec' reference to 'access based share enum'; (bso#11127).- Update to 4.2.0rc5. + Ensure we don't call talloc_free on an uninitialized pointer; CVE-2015-0240; (bso#11077); (bnc#917376).- Fix usage of freed memory on server exit; (bso#11218); (bnc#919309).- Fix tdb_store_flag_to_ntdb() gcc5 build failure.- Fix vfs_snapper DBus string handling; (bso#11055); (bnc#913238).- Update to 4.1.16. + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279).- Adjust baselibs.conf due to libpdb0 package rename to libsamba-passdb0.- Fix libsmbclient DFS referral handling. + Reuse connections derived from DFS referrals; (bso#10123); (fate#316512). + Set domain/workgroup based on authentication callback value; (bso#11059).- Update to 4.2.0rc4. - Add libsamba-debug, libsocket-blocking, libsamba-cluster-support, and libhttp to the libs package; (boo#913547). - Rename libpdb packages to libsamba-passdb. - Drop libsmbsharemodes packages.- Enable avahi support on post-12.2 systems.- Update to 4.1.15. + pam_winbind: Fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Fix profiles tool; (bso#9629). + s3-lib: Do not require a password with --use-ccache; (bso#10279). + s4:dsdb/rootdse: Expand extended dn values with the AS_SYSTEM control; (bso#10949). + s4-rpc: dnsserver: Fix enumeration of IPv4 and IPv6 addresses; (bso#10952). + s3:smb2_server: Allow reauthentication without signing; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + s3: smbd/modules: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + Fix 'domain join' by adding 'drsuapi.DsBindInfoFallBack' attribute 'supported_extensions'; (bso#11006). + idl:drsuapi: Manage all possible lengths of drsuapi_DsBindInfo; (bso#11006). + winbind: Retry LogonControl RPC in ping-dc after session expiration; (bso#11034).- yast2-samba-client should be able to specify osName and osVer on AD domain join; (bnc#873922).- Lookup FSRVP share snums at runtime rather than storing them persistently; (bnc#908627).- Specify soft dependency for network-online.target in Winbind systemd service file; (bnc#889175).- Fix spoolss error response marshalling; (bso#10984).- Update to 4.1.14. + pidl/wscript: Remove --with-perl-* options; revert buildtools/wafadmin/ Tools/perl.py back to upstream state; (bso#10472). + s4-dns: Add support for BIND 9.10; (bso#10620). + nmbd fails to accept "--piddir" option; (bso#10711). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + S3: source3/smbd/process.c::srv_send_smb() returns true on the error path; (bso#10880). + vfs_glusterfs: Remove "integer fd" code and store the glfs pointers; (bso#10889). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + s3: libsmbclient-smb2. MacOSX 10 SMB2 server doesn't set STATUS_NO_MORE_FILES when handed a non-wildcard path; (bso#10904). + spoolss: Fix jobid in level 3 EnumJobs response; (bso#10905). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: Fix keytab array NULL termination; (bso#10933). + Cleanup add_string_to_array and usage; (bso#10942).- Remove and cleanup shares and registry state associated with externally deleted snaphots exposed as shadow copies; (bnc#876312).- Use the upstream tar ball, as signature verification is now able to handle compressed archives.- Fix leak when closing file descriptor returned from dirfd; (bso#10918).- Fix spoolss EnumJobs and GetJob responses; (bso#10905); (bnc#898031). + Fix handling of bad EnumJobs levels; (bso#10898).- Remove dependency on gpg-offline as signature checking is implemented in the source validator.- Update to 4.1.13. + s3-libnet: Add libnet_join_get_machine_spns(); (bso#9984). + s3-libnet: Make sure we do not overwrite precreated SPNs; (bso#9984). + s3-libads: Add all machine account principals to the keytab; (bso#9985). + s3: winbindd: Old NT Domain code sets struct winbind_domain->alt_name to be NULL. Ensure this is safe with modern AD-DCs; (bso#10717). + Fix unstrcpy; (bso#10735). + pthreadpool: Slightly serialize jobs; (bso#10779). + s3: smbd: streams - Ensure share mode validation ignores internal opens (op_mid == 0); (bso#10797). + s3: smbd:open_file: Open logic fix; Use a more natural check; (bso#10809). + vfs_media_harmony: Fix a crash bug; (bso#10813). + docs: Mention incompatibility between kernel oplocks and streams_xattr; (bso#10814). + nmbd: Send waiting status to systemd; (bso#10816). + libcli: Fix a segfault calling smbXcli_req_set_pending() on NULL; (bso#10817). + nsswitch: Skip groups we were not able to map; (bso#10824). + s3-winbindd: Use correct realm for trusted domains in idmap child; (bso#10826). + s3: nmbd: Ensure the main nmbd process doesn't create zombies; (bso#10830). + s3: lib: Signal handling - ensure smbrun and change password code save and restore existing SIGCHLD handlers; (bso#10831). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3-winbindd: Do not use domain SID from LookupSids for Sids2UnixIDs call; (bso#10838). + s3: smb2cli: Query info return length check was reversed; (bso#10848). + registry: Don't leave dangling transactions; (bso#10860).- Update to 4.2.0rc2./sbin/ldconfig/sbin/ldconfigh03-ch2b 1738944138 4.19.8+git.404.38b26805d4-150600.3.12.24.19.8+git.404.38b26805d4-150600.3.12.2gentestlocktestmasktestmdsearchndrdumpsmbtorturegentest.1.gzlocktest.1.gzmasktest.1.gzmdsearch.1.gzndrdump.1.gzsmbtorture.1.gztraffic_learner.7.gztraffic_replay.7.gz/usr/bin//usr/share/man/man1//usr/share/man/man7/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:37359/SUSE_SLE-15-SP6_Update/b6fb6fd06a0afae1f83ba160476a0246-samba.SUSE_SLE-15-SP6_Updatedrpmxz5x86_64-suse-linuxELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 3.2.0, BuildID[sha1]=03642ee010d8bbb45375df9f73dd0986d4e03971, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 3.2.0, BuildID[sha1]=6ff8ce734cb607e6f228193969e0b727e8c7212e, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 3.2.0, BuildID[sha1]=51bbbaf76d34638b68ec8d27551e28cae7e1e740, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 3.2.0, BuildID[sha1]=e04c3fd27892a16190d573024c75fe5787481221, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 3.2.0, BuildID[sha1]=f411b3cbc97d20d42b681a800776bbeb6b6da7e9, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 3.2.0, BuildID[sha1]=76fe5e80842888565085bfa961861c8a122fc37c, strippedtroff or preprocessor input, ASCII text (gzip compressed data, max compression, from Unix)troff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)6i634.RIR*R$RGR(RRRtR0RRlRRRRRR RRRCRRRRRRRRRRRsRBR)RkRRRR/RRR'RRRHRRRRRFR#RRRRRIR*R$R(RRRtR0RRlRRRRRRR RRRCRRRRRRRRRsRBR)RkRRRR/RRR'RRRHRRRRR#RRRRRIR*R$R(RRRtRRlRRRRRRRR RR0RCRRRRRRRRRRsRBR)RkRRRR/RRR'RRRHRRRRR#RRRRRfRyRtRRRnRR.R7RRRhRRRRRRRRRRRRR0RR-RgRR6ReRR/RmRRsRRRRRRRRRRRRRRRtR0RRRRRRRRRRRpRRsR/RoRRRRRRRRRRRRRSRR,RR3RARERRRGR RdRR~R"RRRRRhROR&R|R RR?RRRfR RRRRR=RRRbRRWR RRCRRRpR5RRjRRRRRRRRRRRlR$R0RRR(R^R]R\R[RYRZRURRRRRRRRRRRRRRRRRRRnRRRRR;RLRMRKRR`RQRrRRzRxRwRuRyRvRtRR*RIRRR7RRRRRRRRRRRRRR9RsRR@RR4RRR/R:RRRRRR_R RRRRR#R}R RRgR{RRHRRRR6RRRmRVRRRRRRiR)RRBRRkRRRPRRoR8RRRR!ReRaRFR2RRRDRRRNRqRcRRRR+RRXRRTRRR1RRRRJRRҵ~L\)Ѝutf-867024d231565dacde243a9a45d66da0f993940ad77b7e429835f0a19a4a814eb?7zXZ !t/c]"k%42_fR6mH> nBh]3JiBO!i4=ru!53_NJjYG$2lc%wL<-hev3T7 vBA51@nJ;K#HGؽ֋Q `|8`]exawp_h|| znD\ y7lN `tL%(I(VpJ8"\ߍ#P2>)!LF*m*!I=[p9ʛX;zK~ֶbhh]oD߸LNIIP7a(=Hz6ͨ `ޗM!@ }zbĊ/!^Eڿg=Wʒ) gʜ(=l&x6Z\&_/j6:S\3ŝ:rӦ D[FvѮȮ׭ _q.?2}ÏAgO3;r&!o5YVv;N׸MFX1BiDuwsf$%#Lz6Æ{dh ģANH k $YsA>%x/y#<K g`I'>0cʣύ%";lv^@.f΅KN?H;ޓ4?z^so' : NgK.Zv?YOB}A>"=BRd"#pl/Kr0GX"#NE"k%)j ģh n.LN}'oH0!y9LNg2:Zh$:F(;=DU1Z;aAf)VQ#m?͎ݍ,+)_S|}jP8"[[7GKK`60qĐ[x,uص'(t2g\/=EcK5z֟Z_Nj27ƱmCcY7ybŴO^ 4 #qxP9r2}oz -kH)p`k8/1*xj%2\޽3B61KQwF[Ojv>bzG*XiN`w|ryê͎Y)IS@#vK㡊1`YZ,Z4 7ə\=nu.USSw]<)$dƏHy3 0d{BOp#%ivL$o76%ݞP}U  ̔)?{Vm"oߛ)  B}9|6ML#:U /{К}Em1yl@tJֈxx, &$Q;F7p0@ge~WX|%}ay :jfiɆ(!d}\$[%O_j<] ,;2QA}!%<OKxY-uk_2+@24[N$JE?bLJH?u./=(h^GB咋 #&=>8*ZWpӴCqdyZ^oxjtg PӟG> ~{aϩ+bLvWk%TiBcugu22;45#?;;3M*Oj&F.LgC炓S6$tgCMixmDe ^_rlF `1HebϡtcmAK/'"lkk)sɌ}P(pE/]6gs{T- Pݬ8!NA%KaF.vNz!Y`G"0]W<]˟c{^pՈ#..dvg,]ue+X(shk!D Z9*w&y6WЅT!n!9"hdTܰɋay)U`4V%CK!Ɔ?/JwH}e'; Q~^\\1l#.08?e:)hlIw z86=8\7wlB:Dza&½羡OC&ɞ:QA6V(,» eATqX?"/fhڃdwI9![Ύ8h1fNq@lgK:i/# =C9OX ?+Xt& U@QXY+IӁ<*/f3 b%` oq* n9Dհ%Bh()5Μ;ȱgD~/$0']$JouDh6CCٛ|>VyQ7pN(jvq̝޻;f4oRE }HM1:n|X6CĈGLoh >@9#ܗwUq7!x*z?-kɵ FO9Eja0b_Le7uŒU_f)0drga9Ub2wb܆'jD3}k-3.)\sbCdһسD}[ lQڂ Y+;eǩ)gsb#'*E'c=%QՊ0#|`h#@=*K9C#}@0W61!7%hpc2me~Pg@h!  5#m4yf.ٿВmsqf[-0꽵P _i.a@Vkll*2x cpG1]֜SEDv^ܷX1{M2sӧ2%_K ,Y=?ʺQc[->|( kRҤZ jiO>|?T1/|fYo6C):ZN2@yӍɒ#ޜ W!.Cſ]]K8|iP@-C27lvR4^ݥ߰K`}j%$AsdÖs UEMT?@|-sjSCHDhB A_у2R|?e ^6p`*<9,¾MYkMm|?ۢ}cԞr2N<(zD5"Qhv&syș*{C0u77q*akhF/nGuP$Қ ?t&:LF AI~W$YHכ༉c3tV+Rr53]9@/ͯ_F oʣL&G'`B›vWH%̗jiaɍQM䮹3FR3敞4E36̳%K %R^8 zuB%w$/ñ3& `hEL\zҀsdbd0>1w:nsI@s}S@n2WW/85&cGO0Rz(^e#ly4kК#O!k ((; jkvݖR 1N\XwM R H:h6 2z~AL $sPXHe95deUǪPwj̻_n ԪkI XFÔ:^{ |lU<2EL^-.7|%*g:X\3P֩ eGjaSAer]^fq)ҼC؏,PCd7|5l,/^?cԄ[z]S܋Zv̸)>I DQ"ɾŵ.6ŐdMCxӋDd]>{4W9v"aHeڏ2&ӺK^ڔѹ@KDySy0 ߸OKKV1?UW=ftZcX<ģ+\A= p5'8Yi|.Ϳ~ׂ[*bR2\N 7V~liYX-;~JkYHyMvɵ! |?Э-rQH^<1Sy*qi;]A|,cT;2j{>| ?u5;fnyzDa~ţsꃴI #t3|mh)3̥.ǾYA!9PAiDr~;?e"$We0T!Zǒģ!uQm&f˸4k}:7Վt0kW/.<quuY?D, $y}w-JBBq2bX* AIXsMʷmw?2+ݻn,$$b$w}ԉ SAeU#)7v& \!mKs<)k=G?9{htA/H1%{]ZU.am"Qhj"QH g@x*& &8Pd5Xf)w"R6kyGzjy7M 1h 8 ɟReu#mf}hj|>.m=#AE;@pxޝ"DLAC`bMfJ#ެz@KĒQD[]o D]@bx-_~Osn_ K݌L\ݹxQ\wnV ~[Uf҇>F` ִGQj2(ͱXĎiOYXd en~r xy{Ngܧ45:<)%KͻZ}jVvJP| (PumtCW֯-nUF\|vyH\vNG-O΍G(1ਢ77?2`?Qhzo@fFLB̋z 睭Fvdl[CJGՀO/-nܯ G1-aP)894 W+n8h^~.zY;%=x)V^Vo !gѼ@QahJLw oAsj%n`U_'u.l4׼G;MѤ''=6c֟ZzDd죛aV+Ge'1XICs zJ7%DcN!Z?~/|^ ?Wj# S+݅> /Y$h{I$28ReO $0SȇV%Gro%+ {ёxYLְL8[8mwD`l{deHSMMHBRy^$'V%Mq2ߌ)}lPcš:2+i1#=q439}P<57kRmzhaX'(6^dqrny~z :nٖKn`-Ipi=ڥ&l̟_,U 1/uRiS,׍Яp^òD Z>x&T ,>5/xU̒95nz*C:IqOT FQ"Äo2Os6M8杂e_&!S` X<͊-bǦeR}yI@e,C\C|8)}Xz\v9]; :ԅ\Z ՘ W8|&[R/~yf,yO%_k2Rl2FɊdE2^ݫq:։ @0^,e-BMGNMmwퟪ-ALP~Rc6I0ˎ{9<-Q j BJ+hV?4j֍WaoŬq^(<sU?al3RM_WAPU (["E̢1k ][ϖs֨q8hR wٷjuxdGFeSx*P+١=W@^tnJsCOᢞU%bVIMeH[)v2KXZH824h nnL ?ױDC0duvxmBm4Zw[/X)ƆVS,g<\!h),cEa_&Z.5tur-02j.|yw&Uc+[iDJ-鴂4mVsF(f76 jZ!M(LVUuBE4s~4%9T(9-pmkv}Y路~Ԫza1IlrjͪESY Ħ"VJ:Wוȷ5܍։?ZKS7@SQiZ\c |Ur(qd! +SkSph<+Z!4Yeᘕk: (axaäP! o6Sp UI{k<{'_:M1Jr3\Femo1 6KSMLgѠ\Xr†wd[VLH dɪ5[ackB:?X_*elꕶAX&탰jZ+QYζVS"e!lFfXra?mxsw$B)?x#X9ר),nNn/%*B.^8n.;wE#XFLn&1c`Y~2=k Ӝ*Y= k7D-}YDAoovM[_Ty9Rh‚9#9Q]@I*g }% pGU(,[d[/*[s\r1u  Dwp?sU%zEQۿ} Sqi;TqOɎce>!ۉE¦8 9Lg#0z.h lI+wYT!G< mmce(bL" d">Vb_ѮǠ:j[0? NM97|]vsFp9qs5E<"=Z=vGqHzrhҙ_ݞ'A30+2O>v5$cĘ7-Num\}»;qa %I [J:({vC?9Qt?υS3BJNc4\}F,!p0C"qg+u~cV3w˟8No 1fO` J.X_B !b`L~;.5K0%YqxQ3/݌`*+W yp?ϢEⰏ&^S 9"Z%`p {#eM[?o}|nmqA%QW/Qm6$]YL^m G 3o3d3jwߦfb'68ܖlI񷋋EgemDDymI`k}q~Q%Γ~U:Y_D?2gӡCr*@0zF`|9Y`I5 T+^M b%HX7x?Z/uAX J.l6id<4L2nW{@[rx-R3QLyH@"މ_" |80 Z08ʼn C1#I'E%$Q nh̘GƙN*'Uxl F++ ay,\NHs ?Z&)+he[j5!=ߝc,_ٚmLOx:_ ɶRZCj:h('Џiw%-PD^GJD ׁ>À^R:虄pDVJr-vP‘[ eꎊ*ij]T6v p`/o2Uoǖ+X~˳htN<(+)F?CbC8xpjTd^tM#Dp6,o#g\A?{A'|\l5Z݊>Jo+\e3jhڵ.k,/e17F[>뾼F իat{({Pbnf 0Naq╤իT/Y vIoOMlhgAoILQ"ZfP!Y3%ßcfw`"t%P)[mmΙӰ?BqC(d.bƉ<`3PAlG ~ VXnܝ aypS"dg.[uu֦FdA{ |9$!>c2d<|F.kk E ˱dtVqfGvT4Qg$y&^Sb`|d\hupёXc߯AwxďPJ@ >x}=ңȳ8TV)0/\^z!K _6dCf\w)+~.[םBB` [9I[S]SqŷPW iU9^JͱFȡ%TV <y`l ӥCp׳>i iA< qHvPaH]_u&?ʦX+WW `LZi;ljLq$g.$TgKk*SnބCtooG ej skhVf?4SDFXY.veDH[r}XWsF!nMr ʓ\CeB{MMWJEdIipܻ85M(>oxѺyq^;X%ޮ[Y9 oYNݟ`u\ՌP bQP›b/A^?$A |毓% <i ݹܢ"|̡CR~T(h.<{lp693mɦ4͏蚍6:rtj,>O(Z(}A)qH9@# RmaQZaz. MѭVm/9GlrW?k٣3M4p"Aai ;J̬+9نƅч/qc!©Nynتl 'Ăݳl ?ӂB]5BucMvO@dS::U.&)˴%=*^r>&"٥PukAu S#8k`u!yyضV %sLkazj^|yLނO s~3\u:!*˧i :9]!L1*{'i|rC8Y2Cljlv/Xgb4?@ه/L@,Hxi@<;q]vG6Ӵ&= g r!Ikw)[Ʃ7i> 5ɫ*CO~?׆N*x|10K:[E3ᜉ@rPͲ$s<#+O?O+I$ѷΎrHGc'&p HZ{xjd0'Xw(PYo"0*d<ܺo2f3k98&?z2^d; ZӁjX&-Ig|l߹yj+,h|WjK{} [НeD$pLbhI[7=z<f4wep3}3֐e W:ǿNEYY.Wk!.ްbxՂ+H&Csh>[7)v3@\ӿ!axJC}/?( !#vS!Sy""TTeTo bclӟ_UaL5 Kn $UGS%C;fy{|W@y7! 3001^ V+62|y\1<>6S-RATC1ҁ'B>x!Cugհ)q AR%"y)ue/H8oܮU,_ȓqAܴ!zk$$μñreDɫNzSA W -/afiC3r*7PֶEϙ;Po%C:cLB)2d$ eb<Ġcrg>Df7C^>qM2΁HMt3 Ht[b?a(!xj* Ig;6Z[Gv!Ǔ0}I6ftL hE@|6+?HɒGstR c$L BcgH]muH5^6V)` qY~XN%.Dv>r[ArJ2fio%ϸ .=ƟSK!%mXqaDXj=ut#6tFnڌk|Ξ,R Đ<'d4AtYBp!0׌ߺscނu'CmP{}TT^PKi; ĹM3#1 7 &Grrɓ]]*nc9szD̸RCz| Zd-U웺QSN$5V{=uz_ffp[$(L\VR[^|=A,P^loc&dTD@to9(=^#CĤӢ ɑ{/ U|Ԭ,^1;rCWA .Ve7j3ׁK'*KU#^# Mp"A㻍e_с/8 g0h)& .nZ^*y5(D Ky>6ljPya 7r^=ϻEL/|/ӌ #8^22#HꍎM{ّƯ'(|OmEVP_tFlr1w#=u&iS MJIz/+3)V0USsJJR63(]!ۼPHO!&2ZٜtK5} YLjz$.V$9)h}U Mr hlTO]8.N&a1*>U޷ΌmԗVVm46.ЉM4̢$oY"Ҁ;^4u ٓZ6X|\Em;&UMI?|[*3.M@35^0}hd JWJMF JjuӁQ uGD";쌣7g=ɾPʩpZ">lNϒk[ ~q.Ǿ 8s z~ w 9 bƉ8N eML D%jU(2Oȃ@'thu3\7͝t]Jctv=xxL"0K~eɈOV@Х#p@^(&FTh[Lw\E[%vR}|fDnlFJfزR x7{]FyLhYدhs)MtP=T!J:ܬY¾9 UvcAH$c8R];'?4w;^qD/cqeLjn9@r2ނMluӾgQv̪hz) @j_' ߚ\9k;E'!.Db|W 6?yF rdy,E4i*zK:gu0_AF2.QR CcMFǍzqV:h:3f;$ V~||x;8LΚ#>HbqyΥG=(j pP"!@ݢ[ [7CP MMwM\OL&p΄Rˢ*Џv@" ΚGܹ&ﶆ`=ܧk=GȒ;ZgT0;<=Ɨ~pw$Xb h>21P!kH#ᦘ1!L i1viRso^Ahϟ\c)네a>v(Qt 󵫊:Jx=LZtjed0TȢVRB(CiUZu'lO Qzwz3b~= sT4ZPxX/Qjz`ql֝p ktbReU]]׭e}7ܡ!T+v? BhLSMnv)uT\UGkSLcYZuvJKxlnj֘IM꜅hsL|_Q;{jtRפqA=6gn S19 )eh5;rd~$8B^I-;7Z!?S!}!hH(ѮVOksv`γ2qsɩCV|e}7]:()Ф^ˏTQPlns*?45b 0~f7غo+ Rr}s@aY?^󍛉0OĂru7c/arܱn^-`m ]5}_C(kb*3T]lԘdp51CND]D:"Zƽꠠœ7 Ɏ"HtyG)W7a9ct'YoU#ij^a$S4C_C\w Ggs/#5Kx<7 y?Osc\ Mv7ȍ&7(ظz6_4d| $`۶>.n3i:!!Om rqw{΁P QkCE>m9a>L 6f jSdۏVS Hm i2}s Ӈb Qw'Eb#4Q_P\}Q4p҈0PNH}?Hg]P@`(p<⒭$kH<dԨWṶ]ɓWۗgl^'3}w^t$BTa ?㢀bQԓjV'X.7TV\ϴ22閼6z";`@ժJ+-dtɦP2Z#vsՉOp4gPUZ厄ҵֹ?0E|ou{ՄWDH1wh50'a`[i.Ws#جk98HT͋ЎX*9j,>NcqDԿCwk`=YU3'u֘eWY\qBit:mLV|UՆ_ޏׅȱ2 47;Cna_KQVd4j,8@q;;)C7v{,*2-LDf`Aϙ6Ց=ruFۚ\(^&_襣!몷ȏԲgczt#lEڶT޲b+g5:W[Z9Lp JU&ϋf$s |]2Aܲ_ n{:9up<. ̇ 6PUC goq6^q~bö@ Y+fWM‡]Ae[lYsm&d3\Q_*⧆Y[c WAyxcɩbi4 mҨV/!S'۞|yZ t}4Bȓ9Y"XY-Dd` wL w/zBQ:JTbo/ U6.)nIӀӥ4W(f"b7s^ޥKd 4i{/y:V*^VD9hJSeI~8~X!lf֎h^Yג0H=trpQEf 5#"v0 %{ʈ1kJs ߋ7tFbI:2TYg33]"_(FF7e恾oDM:V\ħ<Ǫ:Ѫ!1|ͱ0SG!%8eWsT8$%BIC$F7XLA\5#M.ùCr>2eai1zK`<1ߜdIab؃-)uRܕA,Ic"䋳+84? MSGuw.G82U,E34D9!T`51e6Zϑ s&۶kW;R}qe![#od~$ɒSfϩ:~='=ZjNFum|Yw qҦc(M%i'%T"%0rk=cfL0Α7à㙅dkЍ#5[ <\"-$Qgx*m*P`!僐wKS؇2J q`ܥ4`Tu?XeNd_!']3$J2Vk9F;\u)y"+f:~>IQxd⦵ˆ#4q?oY^Fa(q5nݫV,7޾J,$~km"?-tPhƞ|O)'x! 3xL L#bU8Gˊ.s^ VޣvCw'g-^0x8tk DUz{׽Q^NV|.r^RDM#ԣeFV|8|}ųb|UK}۝^WJ:Jp꿌!:CS Ox~D?1U bѰ@RjEfW <_dK(4"޳VVJu9Hp;vV>2! [e [92yePzqbµgxU>DC=RՏgDvNh6af VbvCR8 l f+Iz,rz~#VQ@S2m |Q^ $z8NI`cөxj&KCW;7=# ;D&6j)ZegNm lg>lxn4N"~qzɐ]0 }`kSk5x9xb=[Jϵ(Mj:D%m@3Gڪ6#DƋqbS@}A&̲M 0:Au>hDS|oFtLr5|pjc?/CTCfQ[]| 5i!N^as/c|Uhd'öģ?#އbhFϿ9߅YQɲм)⃹0ɿ!+L/.%9/i7SBaARHIżKdvFU| LW(ͷ)X-?j`#ZU(~?9x`T-cQeJPk |`4{ҴR?Z,$fznС_ c6Fee],uw@-_95@ryuWq<RBښ[3JsjN[+9Wv@fUf ,'P[e~S+ϮQ9-OtM PAC1pLMCf6LT/ f{fNU?VH"zBtHg_Cjyل%')Ad2_*Q j SրrJmn|(ڝq%N2{F}P5/tIƄ=q]djĠ/G:XdGP,G~qfҳa.4U^%n3dJsk'34J5Bdґ4/AzVĝ<'2.|-`&`͜JY Bm$l==pzOD6?!KTeoD}rBJLiߜm Ɇ@3͆ o}fY4)m6k[ ave $Pc}=`SϠєVW4SEm:żȱL˶E3:CX*{[+POTZ2yVUl*[9'E;x*@{DIZFJ NV#j!Yl6s#rM1\ i CQv[>' T 28+Y=Vx%A7*_ׅʍO;3(dV)?Yx%CKpynjǖ ~*pdvzO ΅ࡕ@B4P) L_*ڇ0s,sYU{7/̹&} 9~m*vOHuSxRmk4+WBT"NҶG2y1]}-4z@"̨Zded&Mʯ^1O3Xɀ}gPYΙZ; >zYz^`)^!:\@=;WOA;i 1y'dFz] C6߅~#5Eyj4ݣ`7}$[k[<^>a{ -ΎR¶lFمGj]o%oY$>:G2PqR5#OTʚD|N!Ev6#Z{83doUsgk49>WP2|@yt-?9bQį[9d4+2lgziBQ}k#VR!WUk=Cs T (Wn 8c,*5Cb*(^55] fF{`iooYVyC[ xeޠwvxyֿӉYbD><0<ڛͻm%&b9"2)K(T"^2QVE?] Eĥkr˜~8Cڛ$R ˃hA:U 59a^Z;:i>}>!u"؉ݰ8t)$`h)zQU!_}=־| vvV1yAhG# . х{P5m{k0Z<^aCwz!%xsُ ^+v ԚtqZhqqd=ũ֮qH8O)TdD_X?'&-Psrﱛ*-rtl^G +WDG_GaQ?Szii,l _*Uǂ7RCiAL]E\DI&k;CUKZ;cx ?, ><3H k0{[7.Gd|D@3wv1 7[hP|1)Ele? ԨǴ"Lxa^w6.i&ԙB 2ouU:re$Xب)ѧ'aZ]Aڼ'<t]U 9^c# 3Iwq| Qߘ"; &ɢ~!N[ShQ8Qm M3]//U 'wt4nXÙ)nhmcZLYɣᘉ2#t*?tT$/e-) [ZUx tObۅ08/`")D'"n`sŊ;Lmڸ|Zۉwَ%f4ve\5'Kܭ:v% ?k1Tmf9MW/L鮵V.NѭlgniTFCSMD82܄"zji2`ZĒ!?&O&jMU>Zq ﯍cia9b4x,O0{$%&4~OGǑepv7˨#+-):yR"9n{kOұ \9m2}7EfbnvEDe!E#AbP oХ?o/c,DY/UpȭS?& A]? (ˆ#Oa:851#Oqs0y4 }֕tW lU52'e9H};gTv'WƙHp-mBQigౙl2jB\ETњSFFU=W"[x-Ε\vW'h/c;.hw`7O9-~ۂ-0Gk^|axqR*doYwLmj ɿQ %) 5(U.Դ%Ͻ&I{"!ɗ1'nJh̓+PKr$zj8?`ϤeX*lٶN3 G9=@e"E /ځJgr`4Û!F_e.-;㷕;WuFB;Gg%_SY.eb_5e+R[JzF^y{3gI Jz`4Y f_ҍ⁠*xl$oBV9ZGSơɧ5@;74Jlr2/֠']o6M1)B\ $a6_jy9$۰yla[Wy'V xݓ ^::K0. P;k.Hq2m:$Q߶[HǨkw=R='8BBjIWf} bNNDc0Јk3jٮ0ٳ?tih 0~gy_g[y,66,xʩ3Id{9q7zܤŞX~W}T9ӓԏ|sCh&]gHgc,ܡe!|WypWHDۉΦJugOfJ&XKSD64_ vοpuv=O Qc|W1Bueȓ!:@)}^\X+R65c! c#mǚU4[6ߧ5B"rsGK7e0pDnn_DJل_:1E0os U.Va[w*t?,LɁWr<(MN[3@*RN rj5G+N?ZCPٸ~U(k r6(o"S4VۘгftY(je!EUi7 &?uFt:8=OCc|ul/|:;5cIQ@:iAzD\~S:am_=ȍh2уx{hbfl2e/0VB#vl^[s67bh\ ~_#pYʁ΂V'eib[TCUoե_ڳAR6S zhhK\%7H$.*لc!_wwB' Mާ_1T<@D{YdOʄ}tp ufYW|DBUJbǹf8iQ:ر]ETU7w\_x-im/DT' 3BZ)n:=︀\Yp}w$O}$K޲ q p_wRe܃NxTQ݌aڷqCAɌCwW٭߸'Ex0"#~oS, F+чhCEsG^E!{d)Gd! S3aчa:rF*?DVdžFbpoSOH#D#' z Y< bΒ0f z9 g7#x ̯˔i; v #n3PT: wTih"[cq:F Ū{lɦ}biE"`4,VCToDB%?#C!穂shnQ緋E9G·ښ_]pk/[OWz6?=y+4fZkOpZOvGz۪ޯnЅ"Z/GWIS*1Ok Ei,[& `g{}QId!L~ 0*=NvyT%ea+<͎_#oO>Ed4M j J?\d^en_[:[&|MObԙEw?R/8|#Ggr,2Zv!k7e+nfu kf1\@|R[l*Q44N>A&'2Ϩ4{X V,O,*s|r0-9o[C3wVyG ;79b̟@y-IJ6IpӖG7"(25YpS1"-KS*p.ç韣`)y<ԷwUG_dl8aXLf~TD>ʢT4aBfmm.D"A!JN&zXweHywpr-SC%4v ɗwQ8Y. j`4W%0$UI&$-P }u;QQW g_Nq@ϋQu;H=TQv,|)θJBz"a{TFg67!nkХFЁdЫShߩx6Y&\KZPGQQ74 E0F[G)ׄف90i`d-Y;h3=F}OaePK[LBsv#// V`H0*^cSA ЎAj49&-0!B չzMVFlBIBpKX5۸!s=6|c%,-sj|pe&Bj~3ױ!au[,DLF QmUp=E=r5a)nvs/`YS1y5ĆCIrK ԂzKݨ4L 5N:m x{sXqW8M+z.$p#JKd^߬ȸUk=%,buŋkj/iDUӁlc;o,EЦ[1'&J$YR?n7lRU#S&@] >U|[6 TɼJmZBӅ\mzi6η%6 Q2[ᒖWI#KhgEe y)73ӆ;nGZQ`B"(V0WZsIyKC|Vo[dqaVHљ0|F"xI60=A{!:$g^[&"TOjC*4?9Hr$uz(rd&ؗs]uT/E0\r2J-xQ%_KЬ.0MiǁVTu!iLJD̓XM6f6/F8Y^khݡ`>^НU^l)SjNi9ixHT ,N8n2huBǐ3mD,?͟jyI: hJbA*JlUvg x(+~a`ĉ/u 0[}Iu**5n߄9cUhyP>UxWLB$]Rðً(sxd<"Z]Ms\{X(&in{5Fp ='$- <1RcW4l:5W4JeSmv.i{Q@!#SBU?j8wcAg5畝_&yn+hM= ("ks ;.K5l:t0kV&'$ǽV5`Usc x6+АPm"C cy. JCTܜuC7֙Y-J씟C6lFVr03$Bs۩.T9غ[K癟IUűuf\?mY5sgy>g%,ۮ7 &$۴IہǷ t~NM;J t݇IAfr Ȫ&$H<+H~O^Ĝkhܚe/ \^RLh܎ȥhE`b_aHBrikA2IpbP0~˸Pu]# ӯ1y'Ce`X=~Ls[]CXu O;Is+[թz> JK,/r`0w؉Ѧ=hcP#i#!pAk؁@B:~Pʵdya|u5h<8 Ez>zTJ&ǃE'6Eȣ$sK=8oØ^q> x'3޻_˚~O+ύV7/9 iPI$0`{?ݫG19pPv)D)_˯H /kՋ3S=:ڬ7@ᕬ4U<݃؏=o#wu}\}G[9 <bQ36"Ƭ뒃rHoR=֢N;,3WH!=nm~7w"3iHSڴ},11VeRlޏQ~AIB1SL)}P'5sհ4k=TQ\w yWSVmCvgy"qʶP ?2FH᣽+ZV|ukFTÈ^i= jGFnxfKh׾Be%fp,y)iK ½p)^bANc y} Ja4*T&9Sef:oEXOk0V%J@q~cQyl2_B ќMWŋtL)L|Yq Гz"P y)|R[JB$v,Z ^@NGM%Zm̈j‹Ls;)ƓfngiPv2BMf 'J!& XʂF};|KŦXp3v+LVx.Fhn%LګJ(.Jތj)y]+wʫ:nUfy`f]`xoЄ禆$cɺkRPIJ3R U_ZC+n#$}mE ߴ襤aTm%{41+TjMge#֛h{]]%1 !QJ0Uّ;vú=F!8#N/%E6L:CdK6C~[eQ7d"٭g T:؄`_j9L{A [Ώ~Ջ2ej-7Ԡ}3 4xf;jO +*G{/q%Rl+2cyW 0^?V(~8}wo| hY-7~( vPY%}uG3(Uu3c?viw#,q+fEЂJ`x*EozͩԨY|sLw+ٲRݓv yn#1nʌ jnN$ w$CW @=&L'81 07YP W}zo&Q>^ZsC8aUJg)AŤ9ǁq aXZA-a0xƗoa5((XU̴-gYPl4 O7F|%$-4 CsN> wq]gCi !U1cuxAP#X 0޾;nw\Oecrr9}%L$*|KS 4w|u1 JlZ>!nƬ!Q {3LTJ|xX n8a Yuauق]Y44է<Ūweb^nG)e9YP;eh%w9mGx'rG^Q܈ ^~IgM{b51?SbU+mw̬M~hŠQW^Sl":G84Nv=:o I4 n Ùai<_.3Bxs-2|C1F+W³3yyᆷGD-CI^W23^^񪝺pSm TQ@k+%o{KԸ$jdI apk K,nmYk'?=eFިC ?'TG[#S+bs15;߃IHG^ ^`iט4E,+hf#/I y z,}D t*U,5fRX q*J+MݝP&VFT@ȼLo2Do]53hP(`hu$2 lldc^87Y xK(ܜ㋥ VM O4c^ꅺ%g >YY{[ZE[ 7R Z(u1,V B780D;y@RSn/ ><9"3#\Z8GQ+pxI:W,{Pp]~Xa;IO1KXsesB 㴱 hDDZ1 iQ@ \\}՜0 r] udy ™%yu{0; rJϝt'*"-t/eUaEep{RG ]L0$P~ [-зKXPkr i8^sqA5z?XԻ>'ծq/lHyY?Bo-jp}ÊUu[)dO;_$}8v}.侇t\EܝWz=L>>Eb; ϝ_DK*I#]U&5輜^qe$9ot/d4Ǻh%[[SUbȌ&p oSE|tfr0O+-7~GDZr%䧀j`䊕`lq䥥_3Ve'AznJ5lqLP4rѱ|BQ"3g"; DвsʌiZ?BA "CUjd ?gҮ1MȈcŶv[tOTΞ?&ۼæލ2dR`X$Ro'\`z.{ 尜!Rv$h#mV0 cgo2:2F>=CC>bL'AO43m!= #!Uhr%Ow҅U's}l:@7\6^b8@x?"O'nKF931Kp~EhR55]K) ڶTلuw+, OaƯÞT}/VZ 5 ֎rutlq~#+R㳐*hct;<=,7whCLc*+A?N Ⱦx`(]T[(_$HmUVfq;mc'l<[0 _PLÉ-ndƹy %&ɴ/S 7l))T_=O\?< &z˃ ;c`tZ3G_@늒sދXmz%eBp;sI4AΟ3xS|")T4^T[% g~95b 3#F'I FڥuLN>g1fKe`AB4Wк2#?aC&55V?6g5SC GIz-'4kMNgV)=lܹvE]K9YfQ4~Lxcqs No F+>rG .ͣIěoMUOrI)d1GӟUG].e\KR8J &G:bJz@#ݯuʕkLү TAhɦ"Lޔ_KԀApvڮk8On]hCY]X†w22m@+&,'v;:jAȏpkkzhxtNy_;/;om{g7K# ":z)q'`OajyI ϱ^ir"Jp =š "l~z!ZtNN'C_\02ԩ\S#9\Ȫܟ1s5#lx4s4 Pl}e\qc>36 "IWrf)*'!e9QBk%3m^=X]JGUcA_*R۔hJ֒`QSMҵDlH mѱF9VDfEG^S ϳ`#yڮԃ#EْE ]Y9?O dxM ^f=D# sP !F ÅPU =&rj$9,MWiG8V Ѫ\J mXi6NuXu+aq&ymbQ%^<en7qX/^Q~2-.b0h ۪1lj@VU_GE0{oa8ƌ|%긨9oUp?E5j74iW#Inlم f&2K$8n,$f/x9 J;&ItBL?SZa!^&N}`"t9ZVZEKD5Ÿ[W[3#`؉bvi20S[xfG3=":񎾋3!(~5n*{\wtUr(ܪ,I9;݉B9hг2u@&c@Ȧ-$WU,[*;_NVF2vpC?ZNu.;fM =tx܋@('8 3)~Oysdpg?7RU\#YL εG! e~Xy4[gఁzͼ#٣ &|g:Lb7vZw{_&_/4]iL$pLhy( Sy)Aޒ[`Kɿ:|p0Փy꘹q˹yl%[j`c|e>9fu x(7q(}:5zkL%/iYqPT]8X:[ؑIU\YuEl9Ԣ^f,Lf-+X!j]Xޟ}#K SUlDI@{+A:v}o&:% ( dd֐X_ߖg![-X^?](T!p ~94շl $)wXKT(RARP֌%r{\٪Ui>2m e>rbDVѝ6(e/8*wNy:-봥xG2!<֯_v0Ͱ9ND;=KJOOl$PEkQq/PP* B}1~ h~5 s.*+*$Yr-A }NtQ4$-LYyVϹ@Io4L_*{)cj !kx͉V8W38Vb|qkEl`-Й¼8QPjaVyTQ:n5ßr*d?n*e. o%<5> +j_bT@V8e`[st[yp^6h$y?Z1*f;d!#HIqMgo]bxj$\u1u6XuTK˸&tmmF, ~'QL,@%2>E֟#?ᔾa|`Q~Io5ՁdA%cxv%yy.3<#W7!aS$vqN$a"z^tKXwZ;BwR7mnMZBEcHRwEّv 5*Io-4 PXsa{u8W9SVZ^dm|v; BDWarU [ҨЇ[kjI.Hdh#Irv:VL0Eiztv> #u1%]eQvn5#' Sw 结;#mE+ )m2*V潝heG0}u^f챂?A0^lZQ4Kru֬YȈX5kut7#ƿLz_Xfa ӂp5.uAKxjI8˂!^+| 6z_J&?:ɹ?߃6Q@UÔ w߫˅kZ0a#-UA*$}C_`dnwEqN ,/$lIAc/5W!e~W!=ZZd;TsdR pcv8׀)!**+X('ʹ{9%zit#\K$U:OZZw̨0JD 0&^[02t+%5f BP^NiyR9ex6t/'b ۱Fn:'kx#dim"qlAknI_{E~Bd Ia/(F}_M=&(jV_POv51U 89|\:KKƭ$s%`ǎ|3CwnDC%x,POخH՝Xu/L*BŸ`.Sfvx";Mk+ 9ξf"aoɜڕ%z090Х81&֙&!h{}&<D泋G25{8-܇JjaYI`s-H#%ILMD8I,='x:*.)2oХ7^yz1Otiӑp{7ܢQZT%X&IdL#a?lWIijqP\T WSgAV UX۔X JGK =*L' %l:eՉsleFC|@O2 ]avK8]HM dO&3H)-xTi=֛xٖcS_ ȔKi V@낛n{İ#tmdVc ! K3gXCxrmW6U"AgB,#69J⭇t-׹y;OǾsH$4K%S*JƆR#K۶'Qy\}̘Q)E3\S ѿpT|u㇖|VtwmYtF>ɛX?ժ"Ww7G5dd-+i- "J7jtyp}6nM~O7K:ZeVC,>s-ShfxԲKsNqy0=HQZL#`ՊuJXw)- lsµ6YIj+R=Ď< @9KS6SG,Ew)6k5w̏Jc{h9 `B`:9_I?N>3"XQ@xRSdc^?ofET^J.p,;$j%PfO߭PV z_wh ݿjYՀ(fUCT&'9,E5yCŃ+5 4bDh\[(㲧6擾^D4PEGb#L_lh/[ it{5(Ҽ?X_;x>kh):ܸ+F]q!I sKcc{+oHͦ͘ivYI&8J{u\fuiNbhu=n׼7հ2y15Fwkzhc,WG90,:CUW&N6ޗ?nŅ>+hwh;oԧeFyFp'W6tۓK ;jmVTTʅycY?A &u d@%MK9`ĥ*57ߔAA Y\'u}MQqX<yBMM!z.UsDZ¤˶u+ǒ-^^pXm*)q80ECV%p-lC#,UO}Vs UTyM,p1Eac>bNzY u&d+ZCRhVd[459pivx.%G9 %v5ԍ2ayY_ E=A4i/C\d'ޛ> !XSYۑۧ; N/ I5K~ srkZg.D18KfrbUؓPv!F˯`߶GJ\*Cg'Իs)tQH`vw (/q%+A&Tuf 2FC>"=F*l9M)8VuكM#pKf("p54Csu։5 /TtٔʹsDC)c;] A`m=\rak/wl󼪱^t ВYhr-+*Ra̩2ģv6C{\r Ǐ1X *0|} U]4's*Ց)IZ(l1qLUӨ$9vNԠXy|vշ!X]iTCAOŠЇZO^9*d20h]1Hk&-$xZEv>E^ 6jnJ^l³"Q?+;&.w "0Wh7"~{Yè*n#_n[/RjPr"^# ȋz?;O40Qb<ĩ 5nt8%DU0ͫ|-eZ/I<%ɷz VH}YuDqOsZVyΓ!“˝KƾMz"V*(WfM%kmHBG ``WmO3LK9>6ky4(y(`\рugDSP7ݩzllB[ =\h~~]!tvI9d 0Ǣ485 ԰k*{~V<ӳĂ:ifvG-b5l%x>{](JFWRdd zTYoo iSݥFUP[cA6!(faޗP-TYC[*'"/Ȍ9X=^~{˫z'hah Xa&U3ψ.-W&FktFBΖgj+:69 zQgH]5\o.DQWK %i`h:~OD%8 4>~l*x ("ueGV a}4o~39ӌY|t,eǭ]͠>Lt~Q^]Q#P)uk )@v!fl2H%4S:(lL2WOzƘ_l?g~Bcl m#ָe0b0Os4}ֲ D %˷fw`B s )5([sʊYko]%$|W[mJnțO?s;4*.tV= B_Gr6Vi䜏!.xlo-َS< Ul_HMR8X63zܹwYXrg0p>7*IĢ;AYfOozV Pw{:yj_D~7zdԗ=)G_)4dYtQ9OCqT?v Bd(# )kO! mkI<~ xdR'Zƈ `\ؿIK g:xfR^S-72GZ\ z/5$5D9ū S _HZ6"ҘY,LMrLaoФƍ#[qpU+/@,zQc>^kK݆km 4 sr@Aԧ97 b)ӗjCw$&|*jwZ $gʖlǠ_k R='Bk|]Fi~Wia;Ѱv }!vxO\GL|VbJo|cd*=Sh[ t\`?ݲeҁP3fp'JΕKkhf D,\?Z{tǯ6Y{Ze,?igγz`}Ci=EOIuZʽ&ƪ8i4SvG7)H%ߐ3i3;Cwf#[W&pP+CI)C&zz r?VA}~OF|Z" ~M _mh-Zlc*kZ@_3˸o9O!ZcJb<"X"SEE3UU`T.gN̾NmA`Jb<;]~#ֺnpTS$zcO(LVuoeUw~~}K3Ob@O2akyGAn~k!mZNBfdjc Vv]' Μ.0/[&;][ 3FoXC7燹/`hAh-?9o/:q .AlžUHcp{\ D=ZjCmw#*|LmT8~tHfkMzw+1n P(o0]98)߷\m3Y'֣].Wo Y&J~ԽP ў N68b

+f֌A8VqX(xF:}sDRl%P iˬ=X--l@_ XUg;jKiz1KG\W^tL> + j$$:!owՋq\.`Mpn3VVWg<.M襹7@5qßyFkL|?trHv'}4B\q0XM.zWk)B ꝋ ηc F/"8>LRBqM-u&-J*I"źE:$UawP D@ڌfB 3&CB7/ا5JZO,3< k\4$acJ-m{:MDzrwq{Ձv7nj#n`zWӼOх(Y^]#A>)Lez(/S(5cj$UGXڂ\0ySAnm#+ 349-Y;t *'Vwi2=od'OIۃ6NCGq^x 7vk_䶤 4|3xoȂ:!,XV 8~ԧ88Wz]"ƥͪ? tL1+$^4l5pX9JVq1(m WGߛ@;f 1f@pgi BMX%ViaHeB.h( zTk R;E5Tխi$kzX:E*R~lG?/x1 ]rڗ'<{91Q ŢYh&4ۦw&o:}NOs(iuNܓ+s SB2[96FLO&?yMֆV>Ѝ2}3qNyxb@^ilPptA5`%A:b^wY4[`kzS^[=բ])L\V޴?i7Bp+H zTr174PMjo<:tA.4A+(-ukHJNp\s}7ҟ~!ɸXځ堞UTm 䲋Zvh.n+$ $V? z D&J{1_qCD$'(,F)`ER^ejPb{s<2K$ꆯ CO[Ih j5Sņʣ>gԤg>%U$+Oс9 ǘ]Y\p=̆J'U9`n-8]O;mca}#<){C?m"Tna|FRO}ަ_,+./bXP"5MSA!$fi{ ύ OM!=E>?Ya)b#V+{Ok*-;%8xw`&TyPW׎:n3J@e?I\+V8ΜNw?gryqM,-ed+"ܚçF|B>࠘)]=Waa.$gjDl`4L|7@@61~Ť5Dn=ePjI]Zmes%X*}{=G4#Fj>O{&ƀ? d1K}k~|G8/p?.L$7rE%cT _w?5Ɠ<Mb׸|۞ 2=a4c}wȪ5r jSc! SShu@4m j㛸6W{7fZXzG C?F z8n| xDXG0't{ +@#'=C- [}=|e~1/v.?qhILF.V9~@];#+v -嶉vQ>v0L\ w/yBMU;JV##^z?➃B"Z~n7 Guv`. E^ry@QL.<eW 3 ~Н&r"iƓv+:q'aV:Qـ;\pr⍨ZҶ3vL#R+InKo8=M&-tfύLB5?CkBX5s(︇z}LJh8QmͦR_6-Q/ 蜙*dB0}CfhG'%{NV~ssGSS9x ~(~毒!`nkFE#HrC wsQIǖ\h.]צcR2,6BA{k#z˾Q APJ늉bepL'Z he6]?5mdϗ㲛>ʬ[bḀѝFzx! =O6q|H5!E"T@c;1҃JQZ˩hG6 n ߡwo o~i Ш`ҙUnV*dA #ߺ &$b,SV,oUU\xKDU&%=^¢,~”zc\]YmnA&_ tO:}{):DlA{hP߇$)k/?7EnM}%p)IuQJN1Uze36V E SxJ?,x-#:#sT<ڹt:L3(W`~Rsy6jٙOr-6tH^YZ޽AQ ({?馍𱜻.ME[^UyE>m<~ʚ!`3|⻥j3{N6lAi)xL4iK.7Pv|4bOp[:3#axt<n7#Rj>:zNKqbkEqv$ﺒCGk1mwL:ӆ1T!X)d?TnF6Xύ%QNHi_Y,ܔ sAPoj\u Ú%=J|>PPǭdyan?[㭌'` / Jd : ~Aqm:i~EM3 ~Eduxe-hW;u%SА=q{F{ݽmЖRg nm| 5'a5TQzP m[G+~.Oس).ؑ%`3tc؁xCSicVpZ{kG=Cen6&h*[N.o(5kV=Hɮ:*e7E<_x=s>Tpi%\(uUuvTS}W_K]c!-X*eVH6r7밸& ,/dqXQJMl۴>Lz7K],r鰠!WX[K™C S/wA^o,{elm1IsI.9p4V @gGmYEDJ-\pUIZ=4.ٻr>wjGhqOr jğ[vybt =\B%Y'@ f ~S'9nJ/:l T3u]<>3 wSY '7xo :"uy"~ d|<349/hQNgOjwчUGȧ9.,""Wgfq`㌄0@$B%" bH#*PqAW۳ϣ#O4|0CQŇ]ҴQ@tA7kॼ<°䆜e;e(CB 5ⶩ,@gg]輐Gp,tPޟ,qm>\OCS]e^CWɵU^zUȧez;$ x]&Gay xd7WqߕNÌJؼ0y pwx|'CR߱O mP߆|7/x85TA oXy5OG{G-hvG MU^*tCDz !N.>V+T'37MT NRI&$[M6Y3<33s[=ZYnx'LLuM蜸ҋ㎯%p ''4M;{1艄6;7,:2Z'Eq5 ҭe}iW1TN :=DM]8&uFا,1Lo]^>ޤUU_ {x A/ſۄγ3fg3uG=1o͇iJu B3·I;,ׁr <yrl:içMX[:DȠ E7 zpsrsýze7(8S_`Pk2!Y+,+w0 /vy uYiAyy⇛s~'ݶ@]ΆZ򪾕$T9 b} /ϼbM5m!Zi : *GAIB 6@4u/lL[NM 32NV Tvk1%+Ŗ%wZ9|~~/:4:!쵸j'Bd;lԞ 6d y; y瞭NԶ83d kUIG^8POwzp!ϚA]Tt5^pA-) eo$r/^8/VÏfi ZoFK^ Ax51뾸Ƥ;ju&iԶa㙞ymȗN'2LpUҺOY*4Ie ';5yvbx_Mtx9C\3 ]5N|S`Tl2(L"|Zi)b)NXtC+d VGh tU{1UWרo`=&xmװw<3L5ϖ4CiZ"ʯSty2m\;Mwrkx"C;(O$۶Q"hA=* yTsf& tk΂ڄfV#3wDx@6Sz7)0Mzomʋ΢ڊzNy8I )ٿѰ٫f͖dX[X(e[#]YL ~CMbU s@Ӆ4߇\×HssѲ"XZHԆ}@g22B(_0<ꈝ]g ~A{z};mEυ szuՠy(A\I5S$z&a;;\E;yy|;M:swG6h_k6ށy8.'[e(EI NVZ zDWAdmBCc!fI"1ε ga&CYܦ+3e:cZNeZLb&d)..'~޵Ōx>bC,3K k@L[ [L&` RtVY V u tgdŃ=VrvU$v. 8nAvz>nfZx5/ £:Y0.gAM-=[b 2bP j1gCsZIMpJg\$ ;GPV)v+1\_0H`̘]`3wli̚(-N8tRcIH bT$ZުIQAҹ T y- r%1Kxf; BlC@$Awid羓kТd+ٶ6L=`]9¡\tXʹ+^ .Q%uzˆ  }E!j =۱}dXLyR]ν}YZ̊΄,ɂf再wC;IU$M 9Pp$ #DF5sх=uFP'vEXNUaXo ";xn̼DJM,0QC!&{g".b; JB:5y$a>zvxV",=QWUUWGi %#! Lθ]"#(.L ^2ܪ.*E!FRI0IwK(oQS Ќ$՟^^WUBXvj1+Zxg2h^⍻HDV F zwib.D&bEZ\TF7^^܊ "I$s͸ =/a=FZf5x !Y]RLY1A g/Yij-{n)}_OojϪ<3dGY:$;:CO[!*Z@H H*FF1Y" UH,4:٦6P(0YQ B(L;B*VFx āQݶ\ǸRr*S1N$|Qg_M;8hI5ɺ㾼cdxsըիW}s37{HySL:-t+,1'JI־Xaq@sN6<1տK̛.֮ #2КT =tM\5}W03 C:@-!H@V\12,B`m`M}I[;s,E ,A@ ,A` ze;;oi[m2OM귳N+UUU"y'Y7J,'=y竕s큔5D5lgUDN!PY"Ŋwi姤goc^ΝIڀG-~n}V$bsng0(8 ]05JX ̊ն5@cMVU`0B#ɑ`Yjg5zbC 4l$b~(ЁDeV ӣCY}KO#9Oo3uTg(3R vLI'G~9KrS[ ZZl&kk`uGjGDOO.vzz ٲvkǟ_UB5@w]&vճOcF$ƀ8L]poq.ޝ%<CtOL^>k4p}8c-`oMyg]{{W{V{ܳx WX^oeϔA4FDLPE~=N>az6>5ѴϱEjH4cܽ80]]봬`{h^<($9n^Cq ^I $rM$~ccmؐЋV,IW-+V8!/jq.s +2o ^On3.-H@%0HHH6MA`#ьR6 *dA(̤a5/˚x%c%wg7[R—!_$ 6M&B@B6KReHB*wXJWڜz{~'7iS۳W @3"u"g٤U3x_A_kWu{lo{M[o % nr5HI ml?~Wm31Ym'@hm1A!D!]#R:Əb| N[T׀B_ـ_3BBB-m,y$ UqBH"H1wRO58cC` Y,CB](x '> $TQEUm$6,sد VgDz|tu^׾B: W\4i 氖!e9Ũ "@!В=/ `P?LYiۤr"Ǝ!@ b#"Ƞ()"G$&I^V4֒6JkɤʚnUt!BU B~$*(^u2[wy[Ѭ$ !if`Ȍu:}x#0+];<o2 viXi6&m,w8gKc1 ѯ Erc̰F5J%5uegj=."vQKӴAxLmB夨G0in~vE쪠(,c IWd~pMY3/K\Z-$I"6/,Pik3smz(/ b" "A $$A lVIշ!DEgŋiH "&mlCb3᲻_fVgjʻO|A! Ս ђ2m7o)GogsXu16vV[ y5<_i*E`mmZFM+1_cUꘀS(qIg{h D "h$pjX7l[.20 $I*f0Wgsc}zM<ǻ<[\$@ BJlcmkzfb-0HBlCh6j_ewhzPLmm!%Rn_]qQ|]%j6E碳,/ׯ dH,CCbl>7'f*~ㇽa׍ƶ5崘B 11b3ˆv9~ qܫ˛#(`Zaag=|i5z&_6EqCAAIs mcmطܷl{uM3VҀhx l~T07ZۛNSqYr/BEk@lmqPaR7KYa+*lcc a+-n2}CG]^Hlccaod$u}_k@2UEUAE>uHO@"FhA!ǫ^bDIEτNeEUE@A`I=n/ $0qB )cmmlyoEĐTLmm66ͮ`x,>CgyX DUUQF/}П^_z$UU<>˄$aTTu<̩$cl`k-A JmmΗ4/򵜮?KV"Z DEK_]v$EEDTUjZƄ ml4N\/e -#$EQ}\QEܥC?F UAd!'*(?}[X/#oh**Hp "B XU?G7H$6趤QAz+wXI:^{Zql'Bt**UX?`,BCPTDRd!AV |E,&(, 1TUUEUX(OHdE}k}rV*" QIAEg Ǘ| ,X  dEUUU@|4 :C@0 Ƞ(,QT[9luǎu>z3ݖGq٘f$_dQb(B,*DDYk` ?HX*",AER=VUUTb$*DHxϒ QR$Uߤ" +.0()=¤>I$;qEUEX  F("" #RQCf@`$ UX"QHd,Xvd!UUQUbsX+!XUO~YdETT', vlKXQEE ~%U"Aden Qb V@`YU?a%E$x쇐*" JY, |_*LEUUƁ1@O͵C&옢U=UHEϐTU>l_h͕UEO5,YIRv*,X`@P4(1?̂*{/wY!5F`ȇ*"&*zlEgLN@?) UUTS̐*(F(H{~nk9,_:DSo:0&m=QT$PQTUdOI((Y H)$TUVi6$ h^  siGp_<*V*BJ QFg",DbGodb5^y+-_;S*4461:>='dV=>b*o4BOۡ}OztUUQMڨ, Am~!)XBM"]-Ȅ_3p>F鱌mg|؂m릣aw "LccEgkJvS@$H3 i $$bY0E0mڪX, {x!EUV)W>~ؒrX:yjicirn9 p6Ou m11;+2&'6lcR7IG&Ou͖X.QWIlX+\0sUI XUjGE?tX,G8A7}Plllm?䫾+/kE@~eD6ic!GC2@615jRvo&R(GlҧQTUC}=UU?{m]kE ֲhmI$o_?~+*I9>wQ8d}UUQT$@Sپ}Nd)_YC"*]m58H*?iOdTQ =λJ?>8c/7C qY:W\6̫lad O|Em\ W -f6Ca ݒR((EK?uwOmyCW8Ƌ6llb9Z?-:uUjMll0žo&3 fg]>kXSCLHűV&8$8!{淾bYh9llm6Um+Y-}lmeW?z,mg?LAaTmCxэiozv{BJ]VVLFKe{ǝ V1y/B\V"W<j^ZACcm .F\-r0٪hR4r cκoVsT&LH5{X466m $bX `02>+|Gt Ӹ2 &W]]^\Pp znWcX~0?Tg.\Ec1B`zj[jusk jVĀO@333~5̫w r7ҿMދs׉ie( 99+ڭޮ}ƽ;R䃡K6iFEU`008ϳ}5&iLi]Lð'M\iIk!K;% 8WfkT6 {eM7j#oB÷D+3iQq\%0b8-g =*F] w^ŅͰI,%Z6"-+TH D(eEVS2 PT!DJ% _PRSSv_ `\+Kل,a%Әn3ǁ5N~Eul&,@Ģ pm kؓi E k/B2HFNG38tp?[D1/SKJ m*l[AJUFXnӧv\ԥTsRb,2@Ur)aQB0,@Ο)rgRJmXEM[`cTY)C1ebV,4F0U`,-6QC~__woy@t:wjjzɽ%mr@0mѣ}xSʾU ݛ|SRaGkiTAeZa!bkx3RnśA7" `Ȉ",QA,QEb**Lcǧ Lܴk2\9o8NN\t2VXμyoa~LUĊ}GQbV0ADiiV^ F) ,DۆME` TœpvD9N<'qUJ˃"nL-H[a,m%rًW)W.&H([P2fb1ffl̓dA(M5;؝;f ƈAH'X vKe:a C\쫔FX(Xy $ ˶=ˋgB>~Z]:*AQ8̘O0~}mYuD&$XV>)oݹ\gcuwKWkͲ0?y4Ͷ3%(E[ɖ9p"B h禊P)@EΐBϠI"Mrjbbk<08-di&AdI7_~恺",|ƢT0oa& h{Lo/'`!ڞd5 xq7r":Q-/$Є eϬ<5p9KoX=\(T()/݀30m\2cL ri1[k-x?_F4lX#QQYd0'OD*S<=TYf=(rԻ?G/׬.-}C] 3 ?ۿr=lgrGuo_ut^:V"(s4>fٍǍkӆ:" oA/~I{|ǁؠIx*Yz{3S{$;os)9VJFπ㣦ӟ;,~yozkhoqz,#mx'O9k[pl~ ,wozì (asG4O7s1꿒<DZelm6&0llF_ctQAGo+2"t/^0*ʨe d6@1nW@Y]zJԑJQl#Kdw3.qlce|7$F~?_m}p]+j-7Vbs7wtհsRIll!// ,f lňT5}.3^tMM`ؕrZ@gTm呤k?i]3S1%e0u(i4+q-aE/ӂ͠[\vTn0 a~0L $ 0s}Q:W@*4KkF&cY_o9TDXM3Gh^+Wgr˦vw'ks2(\i'v*ӕ;}Dw}5Ov(8Sa9,v |N,뷤Wͮo`o|W6&CliM>_Q_( d2J7-MU;џxԾ{gze}) 㪶,mo x~"a!J*5Ef]: *,E, "V Ttn1Fzi9^~cq6S3[&uV/NgΑɓב|Kezj t #fin.(A (@XX DV(( {b /W\?><|Kh`dXE;aNOj(E1Aw{i#YJDTHݔG\A$k-~Ĥ|ߑvtfjʙA4EQXb-PMJyGf9S2f9#PgGp>xv'99T?LlP+J7벌PX "> 3s1ʢ6@f7!p\?tG{w 0qU}C.tقB2˂<DUdQ֖@)I)|G,FWZU&~TSҧ|Kg.O?&}^%ӮU"D_NMHz {F1zwq+Y??d{@lÝUHi!Qfڲ(|g}k_#shLśo?k7 (C=&BOe i{Mpo;Ƣ;ݻ 8Pƣj況W ݉j&*Tm>ԪoH(yo1EX*|!-p+gb,P ²WΞ;o?~g+2RkIrCEGk5?{T%Q=sR w3c4D2fJgk4`U LQQ`ƤOFLMӗ'{Nŵ.۫T؆9zb VՀ-HfY5Ek-wrFY'Nep'v)Fb֡{nRm i(;$eT bEE7^ߏ)9+(:󣆙 W~$ x' nVvEC~ctQ7nw62"R;3w^|9>s.+HN}csP}l'B4'^}^l8n$@Bp͒Vʤ,h^pJg Pu} t€۱T/Dk#g~cս,Q{,Jrepȷ!MY!zz/onI?@d-smP02x ~QX.?CJyՐf6R>{lY|i"~$g|$QB7H$/E͍ /_7#Έ>0ݙ߅a$ !J̩ /vͪEݜ-8 1[) 90@˰FjRh $ ~yMfE [8z_FgrtتO2(D}FE-[~f% mudֳ1X~^=p-84XM:=|\n=@dk36k{e4&.@9g⡩4Ʉ_F'ׂS-ccGX9k<1AiUh:2ł" ?*~˿5/P5e?Hy ڠB3 rͦ"r\[YH<Js Q_'Jm@(/\SNF95ͷi6MECs.muמn谒VXy;Mt}uI)j [4'Csn,{2a C9XZ0cd%#~r={dV,7] O]4:r_]-)> ^ߤkK&2Gӑ5^/yH %[rϜInx3&oϝr 1pSՋ }Xf-$/fm uw-9 %W^*CF kDFSIp'*)YDnJ+|qmxlUFsgӍÓO}1X0M 1#RZ2`vIm%ֶ96b[|/ًHiF`f#-ycƳmh ;ݿn,8f 5}Rv `ǪW|e}@h&$&|sYI_#eɜ53 Lϣ`E~]%Ys';Í)F F$`9\dTV>sV 0XEl.=6cHL F?*[S')BUSl{~i-]y}ۣߓt ++زD.\0&g\Eo8%JЈDl?n? H(6CbMcil D_Ι닆9יύlp@D@u"=GyR;6_uOX b{?=i铑[WSv,kR}Ym.#[}OcK_Oó mIAǻos=^chroƅa37M^G!xrB]vq=cOy[IpPIGfCPG^q7tpe7^n]%4ꤾ.6- :6s÷!p/m,֌%K|Rȿ;s\u(W8}';̳$O&?97c~?ݝ.9]qc5wvm"qz?YR^MN _!$`iT&L%$0;N6)]UsOyyZ[-w("IB n jEW[tK &/7.1zo@]jcxU#=ƗSt>]?G~O>_9yBn,S@)Xܰ/;|/7[^KǦ~Y,N񙒿v?Vy8H( Uw2JvYC!g/!ۣ7ѭ,9Mvhe l~ZL?EuO4cZ+Q a/%9uٽ%rޫ[5%ѪBLrE٦F@z(nR{|?oWVgF+o[:EA %A~lxTQ=+,9D@9QHi7fw։/Vr5CR㱼^F6)C2I뛷y:sjD߂xPuv[.:bjΓV2ޟssX,o*g}8=i ;W_}A#4޲j㴵of=>:?O;w28KYh_e^aK߳Sw)_\t;ޟiZr Z]7Goo>α=Un/oZ=~yXx;sy-K-;Q~h{ȏb;vwVϱ_/gU ۫YJul̬4b |?91ښ?Nnn%mYQ@, $>(4kl9ZմϩKb%`$X!B (1 cЁ"F!F-HUA[9/St\mZp~owL;: /F5 !AR "), ! l-؁"VlI Xl A~͕%D{!?>Kms\դ +ihhBI &#G$c@oL =Q4@nŽ4S "kjզ98B"B77Ҡ_?_~._QXjyv[τbVPS9{xy8g7M-ɋؗuՄ_$!eR|:'\㠸dzu5o|d_/ר,3>֭6٨c䦫*s]~~L^{׋KGK镹oꑪDznӥ;tдƆٽ !Ei 1 D TVŋ1(I)1!\fZER(,U ىUI3?Ё oP= Y$YOYI4WXikWDAymޤ$jt HNa7jL>X6-Y mEAd 54ԬPGHv X7k?MApĭdX%UT*UYlj`*(**[t0:0)ᗏS/76i!3o}²/G왹OCn {}y862vu@ƚ(k̓d, N@Oh#M@S h?1| UQ4E(AHCDBUՑLs}VCWF,>fn;ܢe9v.y>&S3V\ƺzGZ{ಜ +zRM%{Mk?-_6J6nWWku%MZNwgU{{l$E.q{ce/x mj&ןzw?m{vCE7{ry} ˠ]Z-}o{_FF{XMcp+~h9SuݥZ9[>ki^5_/?z+j[=O>[-%'㷙an__]֟߄{˻W˯׽%Nݗz貿/KƙϷ$v@!D>?dc9QnDhJ,I^H 阴tA#KMp3} xg>tE$@  sJ,Ch@ !~~ަrq~&Kgo+]@D;`x ޽@0]M 1QJOD~A {[_紲X4V4 "Ю%xi0F%bT`VHE鈳iFHI cX dA"pĐ ͩnJM\/Af=4|8;? G׆/3v̐}S=:o4tl{ "y7V*wW-eNX>uYZ  ]AHib2Q5|q -%;xך0m2NV4$@C@Ds'ϭ;^x}XP0Lis_g믘<H娹̤"1[(ϓ|#] t8, nATh Y NՄfzjb3Re!9M%I~UusvF7P׮1gCXԪ)3ZΦ?0)|Jh/mWGҀWW7wm:پ'̛#qw|L7olm,9|W^y$cy?}J1!jv{iT(o}ק/˯sҸ0tMhc.ww_ o2TʫWrvN@ <_ ^h0FP@9DCO(Ċ:w+H$#9)4ICڑ$H@epH[%kS m7eu̳k][H$(0@'AB|$,JG+h%"}M PgĦB[lcx(cɏIjyr@_>R@~zU\?G{^S-䳐6 R25#~G_ϏvF'e|>ֿ+b HXgGz`v!́Bs%@a?_<yԫvRj%:lK\*Jjv1dpFa>ƙsC3C[@P G(k},?ۉ|Wߣb9ɴ>UϜ֎*/jke{߶؏L/>%.Z"L_^X5xG8zrWaiz?N7J^;~V۞evwOض$כ{[Fg>Zݮ?7I;/kneZѷrFo{BL_|CHH R( R0Hx($c1y@3n3[[J7 EY0?oSg b@ػ«5~ O":aX6 B y;|TUITp"FjD x5z^{Ko3 ^(&o%ZyZ+ԝwE.R\cwZ,j"-_}wia:w-k;Mx粫#`?{IlZb9=eco>[vvka7Y<Ήh{o;oSBNc|[pԐM]ڬlNL[m9[~Sܼerc([~25s;]dw[=BwusYw#e~s{t[:O[ݻ/Fp vfeq9o]jTwSy][U^om-^gWx{Z_?^m=^Ic^'ՏsoZ~-t7_kkW~|}I"Gࠐv,S!#B(ҷi<(ԌI i=qt4JЀРEA7o`N+o=툆DBP"đh]_j;3_T+*']alV,옑4K.k|w&I U֌JFK1PA3 Fc)ltڰys^otl84Q=(L|UE__#޴_&? yw_;-nOw_^ALV4e=wvKfIhJB Q2Drb햢>94@O[eث_Uboq5l C>K2m 1>Uj,zyH`D X_o/EC_;,W2GsrAC q0PR7UU~.#Z7[O G3GL(ߵ9fYys}/>~s : -kW4sgx\>z6_%pur_pwxn#OFtd4|7}G\U+Dܹ'fĻw{2]OEvuV]Oë]z'އak?my~lK_q>I{?~{OymV]T R]J3J @'q7`dJB݀AJsb2\bTTlUPa$asP$MAz;%?dyU}R9R%o=90͞Y np TH( o f#ˇ%6 )`;ke97-RNH@DdQ]+@hQT  \8[Bz۵j댤|,oO24N$ dULА$Bge)fxkrWYLӤ $U;`Hil!$hXE$ T?ۓRoWTI[<@ PX0xX=$ Wp?uzןuX̧\Op~= m7w(Wk\o:UYO-#ƿ= ܡdO|ɐ eD s4HNND<\ >//]6טf6?knT_~qwuk0ỹCOєE ^]%.O ¥7.Cζ,nZ?ھ U|"Nҟ7)J?Ik#FrXLG.k~|q<6Oqviǂfӣ;wz[o{[{.z-ES\nzq}}[?L;G muݢ'=Smqbw1[@ F0~?l62 Dk?Ұ8$WuLH~сE8RAHE I@X0)<$*BH(HBkrp2R6VŨ_:ߞ{&b'nТhC;ldi $!`I_H/IѿBH |bR?Q4ܳ}iW129ai@8"[@H@}/q)_g%&*%Io}_mxF6o.-`.uC<$cISߏix̄sdӾk 07Vi0t})7W̲2~:\C :#0F&n~2H݉i'Q%]lVxL}MVNk.>g"&bm+>T+#I}y?|ʫBiito֓<淺m_5jn=w5b->u;^{~ftnli'v߾_t9_?orNo|~d ouv}7ZxncW?&eR>/o~+<<-Wr#ywUBxD@\z/]h9-`ޙ hJF~z>opEj DPPi4hs{v=-]ryߓܽqٟ^p߅Oo[ )V=6ccbNJIL DD{~kŽ y`";vvh<-B:I Ӳt B`h@W6 nݼZUd.~s‹m1va,e$&fsdm/ ?J;I֜jnoMuC#:|잂ˮxߊaʠexK7~~V*   cNPMd,T,U Zvft|iNݛq[ojQiX^e{ڏgaX(Ty|W1ѩr|u?{[ϓkb{X^?u.Ii;q]B A5`@DXlTO$ᤋ r\EQWUHh6i$;Z9Cx՞7Qxݮ*W?<;CTlok@`U\Rb ED{`5R Z ULs&pH@89L]gӼh4[g5fܛ"Gnnv}~sЇ{۔64RS$U~2x42 N F H_zwY2M,nB?1}.yڞ's"ig|9nN>g;}'<ਗ! CU㤶wkf*qp-,+~su%A`Y8OgMKS˷_WG~6K]&-}|4L.%|uf6 ^Y/ru)_ӧ⛺hK~\ߏI;<L8FVA16^uܽ%js#1H EG;qHD1I($!@UT綼ܽ&S7yWSm5=Vf7 $@HDN_2ؼVִD 4+{So@lI!;E ,,Yh < f)'-KRHٍn &h%C~9kT;|z1(?9H!Bnhr~ch@S(ఈ`TJ"x>P4;󙜻w1sj?Sy3{wNyScu~uYJ dž q~p֤o@ o` ,$B!,1+'&;:-KIk%eY4hA*>(WM"ޏCȄWC{Z./Hzy-;sG3MM,OD!A0xvYU^ .062Ct!OdaeŞudsO?aӰ✻v]VͽDc;s2thwYimt, a{}1Tkiy[ǝ[of3;ڞTgtZY&;BAh7?ʀN׽guj;_/ cCgOq!I d +U/rU%6V*VQg-lV;{]!pyv2%+ pЀS4kϟ]6^׳}]3]:|ۘ;{x>&$3B+i;!cʴ%a+81$Z;XЖ f5KMF(qN[Nf^I5_s9~BCCLo'{ya5L܋^ޟ_qu;.b9Z8nR AӛV1m, IzdͯG.kOgZGl9?Uۯyl6~r.ַoܵ u2v;knxIw`sϛt\`w_仿VؖW+i(+';ǷGpVhٿCw9܌@XclG5l,W>6J l5 .8+e2\c)* u XFXdp<B4T9q0pUGݭ GƳ0ahlIB^9o[!& Ld;>^0ÂuG:zRC+3:8877g~۾-qznoyG l+ 6BSUDWOVS;H˱.V{YVUǔGo%MJ)Z-w$VS"g%zUNf=Z@6Ɂ'#۰~g G`bAo0`,ʵVrpC]ehs]f'K+ҝ/MO@]ni vjZ=0Dg_x8x ˙k\sE7x=wޜeiro9Q%:k7 +t=-X}a= ŋ;flOy jT0%E_#f{um "/;y?{;_Yo:|yO)5jגL+w c tŅcNFwOp;NAP[գ|1*Su]]<-=BEلvxjE)qZV'b,\ s|=+ 0~)LRCq8>-]EDsg^H{V];ޢtMs<6rb;fэi2u{ʶvfi/3ֻ^n"(pSh:LїZ^ʯ%DZ{>70.$$&4f߾eC';NqX_KA &0cDJDQdyLWPq\* '>X*l,˟}:"¾c./( IAc>DKFDRE$Q @X+tʪ jՈ$ @HaNm{'8/9-~bQEX沊Ǟ@:$ a"R |}O_RI8!?F¢0!Y")X=+ "TxI#xp&BATmr\K;*ļ7Tk2r6s . 4DzS\ڢͶ:GHH7DWakByhȔxaDM) %%v HS>kNV svPXU.g/-kGm'f{/gKLlد-#Hf:%TWm PhK`!bJf*!%bH96$6 d8E+K[v6)k ^.N>MnN~^N~nP@@X))"dPI $ؒ]"Ih@r~~kyxjԓb!X4$%bF$"9whbIZm NhNp1=o->C931:iHB~k\(.Ø?w=_9)_q*y5){.1rߞXMsƽy~~ٺ=z,k{S}V\rwc|3G~&dwfd!`'c,Q>ń9[s.݀s?#14lFOQiS:m>NɦV"ii*D khXX@HIܸaKsi蟧ߟ ( E}]3?^okKݲ_.sw/τq{߯CKEzʪ(B-z*y\(& $,9W71 8BژZ@怂W+ ^kL>o|'c<\֭ د4x甈 -#l&a@9>羣r<}dv _6_s|j/ZlwR'}H繀`LC`ji*WϾ&$vO`_[=Gy%߿oM. #,{&5ۢH}H$> T"(Dc Hy>Xj:8f]"1(`*D`X TTXUEbDDX Ȱ 0f @(߇_֚S/&~{<*j[N,V>Ja (WԬ')"#elrkL$$.Q;*+V:iX$[$h/ߒp VZ`%Ú xyQ,2TCEa .\@G4Cm}Ȟ[[ޫ/wݍ|A ӆho;vR@+XH$`0AUQ`m li߻IP~&0n=ZD{vQXc"Ea0XPDEOPEUŊ6&l ²ad S|yk 6 7ydD $!fpu+T G"3%33')*2#33'%&2Fe$̌L^_ 6@ZAxJ ' Y8Rl0 lLqzϊ6/|Jۦع))]j3xn@ @M<Hй>R++v|WHOiAꧮ4L&di lt5U*0 kUWɹ*RvP-`%m%)4gCCz7qNU Ym1:j~BZ~~f}~~^~ju~^~N"mA#&8pÃ֬aÇ= d@d!X-s75 0s袁vB@med'RLBV5). p|ﱐz,:n&ڙ ^YD(bRD?dž9 n{Tu(#Eg)2$w.o΀\/E䷊A@-l X%?A,#3d:};==r]>JNmum_>< fGȐ0.f͛w۷nrڽsf×wn: ݋]]_'c/bXj߻v݋v~ۖו$Dt[Bem PinWuusN+18|rԜvE]ٶݚ#DB6gؾ y}+bMb1fԮFYU!( CJ`BeHb0Utz=y|~2^w7OGѧG|d -~VmZ巏0ھE&!(uVC^j^jc"1lK-aajDZ]Ld_g;䵴S/6hZ'Hxc<{S"$) Ph dRO.`>CDVJkT 4Ll;L$,ST\\TLlTwKV}g7ttuB uX~ޯrwmÎ:&!2|W}R)1 񰻔"mp ȲV<i|/CW}q wEUqS ?TV#ӄ^7>nf&1e(VWZLZ!-!L97q6+@M1&Z+#9VAHhnWL'vaYρBOYs!~g_2 FiTg6qmxc郣֭pI((Z844N;:b$ھgrhISW|\yykտw{Q^ l!bpOrWafVb-c5fQf1c J2? \R, N:y l݋w FY~XՒ)Wc+}[ ǯ!fk0EJ{~gRBdE u퐇zoC!&  ؕhX訅/r1ѱQr Ӏ@gemb,c{ְ{LXpC8Ǎlܱ5V-ٹ c%Mao 7KAfāIq,DުLH9 G\zzS tFFN}`0y R>\|>-GOTC[bKomEGkұ\]Ψ9aŗ :C6ᕾթ?AGk.8VA hpoݭ2EX3LLсgj =To^ʻܪB[z^w2H|sA,xq[)>nAH]ξ͕o˛uw z+XXKM~>7Ѿ3,.%|].*Y+ "̷zuE+s\r|~~E)XpbX*aQavߖ9aŞ#P2K*b#򨊲|#  󉕏43lY, 3f3nf"c9e[G}ibN#a0 {84"$DL@Q^r0_w&<#ǃcb6{Z,Q{B)a!A+$RBb|_?Ktsĉ [!V`Cp3O=2HЧZk|X!&a>x,ю_㿦L, '"YUPΎRD aC3LXgBzzݎ~3E]Wʵ#s=M*# D:f{N.4ZPDL;sWlw߫06ϻz*sL; 7r ګ%[kI%x3Riti2$FʳvYX1 B=JݥFjiv#m3 _Lb"(F"÷|=wSlA&lv pY2*k\nc=Ht<:A$LɚHA]D#!r))8Fc^k n]{E S?0ޗ!1W3%0%pc!t?>.f[qaY%R+&7ڥ6UJ9L<4LlyV,=+Zid+< adn0`2i, >K?![wH 3ط1&גTq? "B.W5i8~+ 3aR˫#ϻ*7G>+ dDK2V^@3T6t@9P7@FH"BF ),7.U^ ഞ?bG}g_ǽȵ,Z pɒܗ칞lQI4Sӳ$*uD "",Pe|d/JցX `0ZVFڤ|I Su '^F vpLKd M~?ͶpIX A9;JOf>i=u^׾ؒ-⇵f ~RLZK^Eň&D?7"a*T@#b@6ogo?o.;~3~woqv>dV'ˇ@*  (:!6}`43oϷw_%¡/uR$1N h@+k hcĴ$#@#,F 1Mg< CnI*#Id؁| #PLi6?ҥ Tȉ '(| Nx?y sT>JE.AJC?'BB.+pz ֌ebzZKzlwϊU !,ȁ!vb섂x/BTrAL7c$T_oYXi &@Bהo8'h? p/ SEheW_]W,ٰ?6yl=}|rdZ'(CՅD'WՆw =XB aLCj:2~kKH+c<'?.\Q3తI"$ r@0H~C5 :1ebz8[PoIHڢI),`Q"aE"<}-tv:tzMng_{\ _v2f;8bp+BHflqS @dypwup.-C~sq8Qd]7 dJYA倢:*sJ 9߁w|2gz`q)O3 fNqT-v `_Ec2­&(BTL\(HB]_aNF?"'Ďٶ%7yrtQtUZ(*"(UOF!SmM0%f0`,Գkܫ|T+ 1(2rD d@%@)Cz+gi^w-ܓ#Y"~ lF(OH *ȐlpmRBE3L){ q6BVDh&ds"[, [wҶ|jW(/׫ ir^OM{b~=m$ ؁+׈d(H} Dߜ$6 ~+#eH?lI-$D@ %I&J$% $>JAI"@! 3!~&H0c ^rf@.|Ͻɤ0ݺM30 0BbHO[d ,gYEgn*6D4Y771 w 2ȝ̙[ϠSc/9Ù BP{{i1p9yֹnWsp9a3PߊW'g{yVvJX;?Cy4=|0M Xiܐ1 P8 `jiY` kZȗB0}N _>tIYwVOe P7E@aХQ"o||<{\/ȳ7tx3Z~;nYc'0o~o~rH+R\L<^馉`@ÀV8x[PE7V{oZoOur:Z-?\+ qj̵b KfJ-G;'ZAA\ssގ>kyܸ拞s L34:&vn+ :i~U+f% ~ƃU O˾qQī9Wj(#W;\&iFXn%^(mӵB}pȀ~=NVO}gĤ7;_k! %@79Rù2XdhkoGVym^yP?,e#Y!r_G6[E 3+WX?-x_ly,>J҇If fQ`3Czϋ0/!5p/AM%E]w7wچ;n)fn|a#ԁ:D{X @OYլf!4!\< Ox3PЉYc?FsxxxO%G FU7mkbJl*NBp~R&N6>MY8]puIfP!=p ^@ Cn!M;J{|ݾt0G.9Wd|*ԩNzfӕ8i8AMBYo~eTK}7(>dDcU[sx- ҥ^Uٗ 2O,c63uhzpsp{QU‡=S>'^k_z8"LY?I"!,J 7k # D}rJR`;q>nÛea@٣ӱg'dzqŊ7]9P~/w*Ƽ)y'Uvh%?w 6 "R3a1SZ~TtA~t4?KF0 >ĹkKK6_2Iܠ ̈́"=apf.\HYݧ٣ĊbP*}'Jl728D^h[?ܔ\9t2UYu/"8 l;-:ا&UaǓEQѰ ڽgo' l8 mQcSo=`=NEYL9öT!~:~k3S!1,R9۔0I~=o&3OqSZE}X6}︺bJjZH ?eg{zO)#N1If'ŭ0rXm7"6ؐJ%xo}q<&ݫViGt/Q)$PJuk6::spdAEژζ(ӆ'p&Ee;9* 7]兰]" 5'6˗e@ո :huË9ر,ʰK': WOYzާW=dXiIz]}>.mΏ%o.|lBH@Cm~{<>۠!$sDUb" b76Ȋ* QPD|l f[C;ndȪ J z¸ Bj8n#Gt'U)l_]{U46m94ËTemVm'=7H} /qPg|DB I`f;oG{p&k[VBOc2k QDtcu,{:NmsPٲ*vv!c$XIԐY8Ƚ\u 7rqd8Qi|&zw=Ӑ$0D.8C5ҍner2l"%k4o gnD٥""elfJPg%e B% $`Bc:9+nL^rf}:*ܤabs0 !P Mm `R `t8"nQSo\oGQ6)?&r& &C~=g4pB{iKwH cNwHl H:6EDB3 XPe`Òdv83ޚE{kN;"<#'s|bwN 1\DzO]f.rIARlQjhhDzo"AG7NZk,v +jW5l"=)</{4?V>A-R` !V1HPaV4`* ,2$@HE@PB(  !~,$C3GQI 9FA59I;:0CI"ե@$2*öR0XBu`b, ,H(0b P$X(Z%$A RP2 EXJ,>{ݧ JR= 5)a EW)kLdRP f%Ԓ ((8}ܼE?aj*#RH( =v{ l}GfIP'8d?Z|tԚ.D+陘ǔ>s}.V/Gp.\ڿu,tz{<Χ+c椯)'IX=kwda~?;sAAPb +-~B[8pī;#~^Pյi /`\`ERt$XXJ@d!oITH"AAHI %lT JBd զ2Q @q$ّHAH #$?jX A(TIQ$H#Ad",V $YPYRH,EH @)l X+j !PATEI dNC?vUW{?UX"d*I%FuO{ qJ9E!$M]KP`^q4XUv@HqI,/;8L:JșHT]  V!!fYk,I5X0I5 Ҥ";" P Y$ Ad$T 5a3I1'aJQ{)WAo0"H,R 2 FI$Ԫ$n3t&哙 c Hta ! @-ܣ&j"] @U! 2 a(i29@ f,42(X "$dXdXB,YX(e1i1dC@&&"e@مVM2nٰ<4ȳ`6HHCN)+ NIXnŦAlD'Iab>_sAƴU4 Jb@e);,*LIJX.d*.bM%a l,v)6jH` lVmSHuܡvaŕ qa`xI`b73!O,̓SF |eMQ6\hl%# PbG[/$E$AMqWHQUL@FT`(,fʤ@gD '򢉦(=߬Ѣ@-dd1&oHI!YH1$!uåXE"@p&Y 6I i"$([eRi AB`;Xd'Z@@HNc`,)X!R~+!: ?2h>z \cOu# e)X!%'"JM]Q"Ts##<4K9¤Ycv%_ l8/c 5"?_z@0D[C_DPm/=GN˳ F>,*t(Ȳ,@A#"F1DdmIHA(!ؘ("lKz?ވmr 4NTlV$PG+5QYD^Lb%)&B" ' !&(J0 &0Y0FB@J /ܲoqSLMFB3  KUg F,fU|>@g $ 1K$D<-L"fQG60HT#FsTzH1jFKeIaS[:X=8uu~ bk!e:IR a@* ʮ+l "HFv8VxV7Wdw>{p`+łVl_]!@0E%t0 àv9Xӓ(|o{mhVӡ^KN "  Q^ą~ʄD QCG#n?,~o]@Bh /ϢiHB.b1=G*^B˳hɓV;ޭ=QB4 %̖6P?0LAET0h 0Ai D"D@wB !B82 ')bxDR|=]i0IV+ ↈ1BB0I+4+ EHȞ;1Cd򘍈@FU!ƅRt1FeBkPU I&wr0')^%b[FXkK6c XJP(6Y!5! ٦, zd씤eIQJI-6 H3@A$D` h2gҚR%Xy<Ѓ,Bp V%.@ S2+aQrմ2Rf9%gZ?wTm޹4GJo~{0IlĕPLF**[mޕX*0b,݁X*Af B6̈(wsw;<.rqod;[_5f^:-b^c05 Og9 L`=v] )`F\2V!)^GqOXJJ): d$ s?z{$g}q^̲_m _oB1򀂲|7fK '7qGyv^i;lO&[9{|ܜ+__)-_t`-Vfl|4{}ⷹh-m`e1)& {N\| .7 `tW5%#ClHAn{~?Ԟ,_} Hm<oYrɱb.G=)mF=2/(::8@ڱ<& Y_d cx^դ 9HiA5p3kqy|.'_ɗ˞ũ5`n2eȆhyT_-@P Dhb1+s<$ *&20ldyZJC+2:|W_\Jvދ́(-kP#0DB#]3w+60xY9^~PB'Ň=rO<%Zݘ"J&xZwmΰIe?Н2'QmF` kɯ,<NNnW'qw,ey#uA4DTZdj,YZ_ MS>̀ 'S"h3 X'U=*fEaH] ;?=SB=IԞ4lrl:XNg5sRyy\ePk _q@ VEJ0@?:dvl鎞5:WFGgguV#%)h8y?*%٣r9Uv;(FRPM[nͦzDǘhhB j,/nuI܎'+_5r;  WIw9] Pitn0gLhݎ֜8N>9yl(%F@$"!Lvd^ŗCT7ԮSYg $=CJ6gBUU9U0o6fV$ GYݎ%~dTV Ϗ@tٴYd{w+EF^xp)ag5ghҸbEM*[a?߲_=O=~v^ X3;>yG\S:q$c/RF-'SB:ՂHl8M"'6jg= I4!UTQi^ldf_:&B^?s}!W|C"h^QNmЦzxk''k>ո .!`G*CӁ8zI^2]ޏ}2veotl|>PocvɁ+?_M,uːrB1B*" DA{ *>L !!]VI( r_TBP1jSgOrkv"C(|?J'tU7Uq31uvW+kHqz(>!/W2@0"HFE  0QJ-f^JK4RWH$r-}.byVU(wl]gtcӽbȴ`15f'dHuz?- LCfg^Lg3Ukb2l^+X11H1e@cX}|/Zh/ X0Ѭ@.R V= O [2 ՀA赐^;]wsiٞ~evk~[AgdLr5%\:F.UC-]^I#8;iDb>?tz\w6knW1ݻ,~<ϯp;" 1wWomȻ~嗣VE|j/R`瑳FI9~`1Wٕ-lW&NffijezTjP"'^_>96ϛ;} %R33q/0UpYa~KC2 0dF q֛@mkn\F ~yw]Qc{q8u=͡:xv ΗBp9DI(?XxX vv"F€E!sN耥}r} L-߾$E+Qt)֚c 5' wR&zvSHyOն33p[E'+/*_o Ё>qzot'2?uEfBw怏w1ufKBPgeDXA8!U%JXD4 iS{}3gK7MggAf|M&m*L -C31,`JR"AN&I}:!NUH}(z0&[uuVxJ @BБEP/@5jZI1pX BhJ}d<@q0d $9;N%i7p}*=F [0QqAk,/3=tYM*L+Ul+4bju + %2Nۖw5U5jɇqceY._Yrk<EӉ 8Jp8Q|v*tHvݙ/!4wzL|}WQlR lPo!Qீ<~d2FE'|=cz")-/S@/VA$( $w8YUB~Xro H|nN_u"(lQKf{YK ^ave{bhdhlf%C@A}.Oد\`U%,YtE%"`@ٲHIqF!ik! kos ^UHj`B<`x+Wc>wPViS B  6YW~[sey-_RRRR(PHSI&!r:RVEY @@trpu\iQŘ>t2{ c3uh@8fDpX- d)4oK^q{zRgŎV"Ì_|Sƪ oE8 @0DλNέACNNENγΧpkwqwza0qI:  6nϩ<[}[{{iδ{ۗ@_0_K[1(22@\t wmPydMBI5u~#&Wm)?ڴL횵`Pdф"^rJp !Dxd * z  h ƈg[9mȸDkLZOhD#He` "672]v>sp~?1dXhjBѦիrYLs>z~=a?D)dQUEUGkUU ]89&SG{ oԒZRCI6~7NH, *0L̾L̹Lyg"r5n¥߹UUQ=˰4nV4b?~VZ!;>o-?*_sH@:a򿞟{ ց^SYC3Ijq6Py'И,a$ i)  #######c#############cU)eBxH DHŽj|N XD ~z<|)7L/Z@&qmD?."l P)@3GTVܖSZs 0a{DB /PB (PB 3f9E0'/M()AD*nK_rq\@ $nh߉oe\ qϖ--_4Gm! ))c f䜜lm9sDw.M0BԵ8)D 9hc4M'CDSδ x~W%觶[)-?×[! m4||||||||||||||||||||||||||||{<~:sNNBQG4B \*3!BYj} 4SxSN޵of)/u4ߓ 3( ^jJExILCS[r4 H C) +Z*TRԥJ*TRJ*Tz^W7W.~7CP:]PhȹzQ?, uv@Opπ.f 8 ?Jo 1Ov7&crq "@ghNaDyێ￙d4_{_Qc>:n*vԷOvx9KLfoko 牷{̬&&.PM>Ͼظ&k ʾ$W[4|hi(FHHz85?ɳV8 ~j(*#|n*x _ Jt :$SW ~>4 MnƉ3kh{N՘CVKZmU5ϋk) 7SS30c&oP=Ņ╩PEmJ5zO, uDjy[f8pCk301ID@j֡m(7U+3<}Gms@/|[:IJMR1]"(`B>Flme ?/]8Jsf|22 .sf?"(elցLB(-[b1a+٪hk75NGJu*tg!k.MG\/sn?G_|jgIi%Օ2'cg3x@$_z/ LXKw;}o~kώ]j]jS׼H*%TUu +/r, \vobf(;E}k^It&~vScކxZ|NR뵲v?켱&0-cH-{: X= *sv_d4Qf[")KhZ*;ZeV^'ءN]yI* /بDjȏg`h?y E󃺁 %~!eײ٫Rl߇_tZ}7R{S E՞@;H ΄Z]) -sӡi(ooOlm+MnpI&U{/^7|e  Dq MkeQС gZ Sxh1;ݶf~Q/zn ~mZPPgkUUP,R(@\j СJw8[r\ u.[m_O-^lŽosx+'X]ElH=蚰TGNOv{nX\DʡN(ZѬ0rz.sXiJW'=;aYjzNt}Uo)fmϦ#U?x񸺪*7t1O۵4{g&w.e>c~wa_3L O~2lO.%d3  סԔ;wj W@$'>uuI(Pl0Dq߮ZϷOt}UZQ,on§qihІ4QtxYVh[ޕm]J&/> +RbW ]Z=Lb 2%B!'%` &׹ wczX N?_ s,XB Aڸ|Zr=8m# ؗDII E#"ԍ n{w{A[ץLC,61H;V@p:)Ԟ+ 0@DD` m w Cys)Ђ"# ZPr=-_J%^![z&6|/~Tyآ\RV?s]dB QN`H-(PC (PCʇ \^zNS"y)LYVsiOqF_KЊ5R~vE1zոuLfC %!/&V]9c~o.ҔB!Ņ@u 5PB :PBZZaj3#bbPPƔ":dXQ,*,CO###############cSJBrJIH-Gcx}n`46!c2(cVHVK"a [籘jPvk|i!! i Fk 9O=& NcY~4zzm{={=:;=g>|u|l%fYόJmn SLxZS;urCE/gz>Ejޯpg J}Aߦ0SB `J4A\\\\\\\\\\\\\\\\\\^'& gR(Р.2-P|;7%d(=A~.|_4foӼ JwWDOC)$s9` U!@FR 0D-T(PB (PB (PB=oI0ٓ* U]Z(&Q]6ڏ-H?Xr"j%~>Wd G1 /;gZxђh@xm%&SSia%e<e4X_הX^f.{yі 4#, OdYfPk .Ekfy9;]i A)HD`@c[v ǽ}z*q~k{*~û҈HHItaI`0 ``pX(NşS_>`=}QX BڞiaOC\)ىC^ʆmVUO< wpvu-m)"1 h2b?5t5} e&Xk*&фCh"%j,;G [(PB =(Pm9D p M8$ HxNK9 qMJg  \GOy'gݨdO5Zzw|/ _3Lg (趈xYHF 龆Oakݲ:Q}d5G}+5? )qQ9R3n}ypEÕP'o92zQMnCsq @| Qa JQAtXz]..Kt].Kt].KZl~o)c22 0R%}8< D$Dû60OxKN >ǎz=Io!tX{.?q$TRJ*TRK+b*XTRJ5,SP 4 JH;7ZF@@>m_DE [B=/?1;(H'%'UHh.1/`ҐH" ߩAht*g(z|Ηxyh֪!':ʣ^v;{G@ C3 QeQSJiJ@@L4+fffD@Qet<&LU}@ܔm$ #cP %Y0q`T_7h~o.L'ro~8cD1DxB)@SLD:5////////.^^^^^^^^^^^^^^^^^^^]]ɱ{Np3>~c I:WNNcv_;ѾzZz[_?8&/>7q'"`H(R/k%D{IY-tדp잊O ,I6ۀ2ǠV <6QaA&qHE"HF`́XYs& ro {j8N!xԊ0dP,``/i`4& nH #R e`0 ̗=iB+Xpsw9z?fr`rez}naGIU?  >lS^eg/0pL5jGk|]HSՋccCKBS?v>$nG@ e*{2󘷸{YuKHĆ׺a wSe;J*j#$ȍvl>e~k^WI?b*4-1Jo&nI/d8&3d@_e~W<>@{ܳE]mu;Ovq A$FI~*O]|I+xxju:j'Wg=`%Wڼ\799 fΡ~ݬs* e_SЯWYBr@~S;XʼRtju;Qj۞Y0fRd"aCkFNK[r76 2CUoB^kHE?0;8V!>] > ^$-!f];\}zYPώZGR P~\k—QCTK.C@S%k#u6QDz-关T$+B&FЂ]q֨0;%O:Qu=S bWZh'gu3ّBlRU@45s @NW `ZQg^1O iZ]D*1'T_?\Y{F-05B 8lxR<(ƥ@kMi a£p%;5Lov^W…R\RҰv8Z܊i:!$ *CZV ˾ʍtke7o'10'o cr ;B b[H#Sy!\<*_w4 SqRAz><UT%t;`YRHB"wD`~J!XGu1Y"V#E`ri+ڙ{D c`q!RXD(UG9ԐwG7H%ͻԼ?59H/^q撘wYT eմXeͧPZmh  `+r$Z78 1i]4ZcLy0%)-{Ar\^=8TpP \y{T2~EVgGrkXWG:pb%vmMgBTYW3QhK)U&5&]ïb&:iMЧ/H!J|B(oTf(*Z2qNDZk>f.Ǻ*'k [[ewa2]_X6XoqzS2Xe 'cz&[:B# +e~i| }PoX32-=8 \RCr{Q\ìkyYνlpv`KTzAgXDmzStc9-ϿY=ϰ\#'!r58Rjkw ? Pݘ xpjZ7}5X|sJaקCn\mKAqЄL7fua>Ƴy'@\z |t<n1mB3c֚2_]|+?o i˼pe0|F!.85x-# I7 I΄VYhd隫Y*6۹|h͢6alEcEw{saD4W38eӽ-5F~jBj_,] U/< 5$L'+M/xDZY{Mc&vL :ӄ㱦)^M)8r% 8Y3$% [iWӅ*lGAѨrK&(,?4[w.]ϖJ@J'6?omϽ2T wmʹ3қ$'-գAfYqHiĤS32DHÝ2CN>; }[_ATb(snˡKou$5cyv39ꃗփu,ԑ 7AWb9D/I\8V=_!48SEd_2hùF.NwqY^WeCE*ϋbH.J/82Jv紜9U>Ƭ9x4p;}…L}Bd`Fun½DwK&X/ FlZƧd0͝յEy>/O sS$&D8BDWF{ێA]^WC) К&ZgMQA,_]2|Oz!獜7AWa]6+$qA;Pd\qEflo$JYo-X-'(]{'A[v>CGj8} == .~q'n%gXq>B_ ! uhhkV  e](gI$qV@'.%5v6V) TGmBxh'q;Epij$P`;oGjs[BSأo/*hѷ5灑& NXi3,⾪T4+ &_7k:J$<]5NPaBn ܸY?w0,D2` ",v_(CaiFgO#  I^&t 7T0S# )?xnX֒p-%+4=O)ý>'6:EGBΰFUT~ߋ5~Crܥ 1 Nu0cxxz_+ap]S@8\jM6T&ԺlB#LOI?_qDg.čs\S8*Kߣ־_dYA/Y Z0cqn6kn?Aܥ).p~6b52vX\YDưز*% a(mCICxx-A1~y^t"Cl]YG>R`'7cV f0M6&jGZV经]gVDd6>3MVײY=h ϐY}z^D4v5`qPStw\V_Q]1|5.)mcIc:}vwpjTZN$} ÷RN%S#ab= _"SRżx"wAd?- :k(!7bHs;~_`F-‡j02EtqЅGܹؔФWYxLktځO2h3!q2}ZrBK0a|c< R/-e"u!( > '}25(weW+9eNKSc#+8Zw0);W$]?EAd@QYR5ˁt7pT] Y<%_"fAէB[zE7P(FhȤ4ܕDVVxҨÎil k#KMIeWosX*]t7 .g$Dxmali(QM˓h޹Ip0lWL !d`Ict&v̩ЏiޘC,[!N컚>^屴U=Aey4{v,K2}`χ3R~l(!f (D5jI$kid*Q7wc<n[Փ`RSށ58%1zj@a Q5 n=#sCW;Y;{eB8LmdWe:O?2XxPe0zgN[h0W9Dl7y ^s ܅FY`eI]̴9N ^~NS?U SdMpշ̏?y:x>fUsqOdbv<<? %Ǿ>&0pIw%m#A6Hyl_hUG'Ņ b4Kd|4K䵯x;x`VdbdmcN^Z`wj+ s 'TSSO|hժE[ _>~Q;:h*ɌԕAz5RaUcJ@ȿ[|a:5-->!n jm+EϻL \0Rk9>8_zD0&OQ' 9xGȈ\er[W$v򕖬(/ܣ=$q嬳-@?+C9(h 2!lg_u{WrڊE˺@-ʨ} I8,!EI2T,N;._\|ߗq}A2Z|[V^ 6.#r9?d JW,3S=w)12  Nl-U6VIKQFJ[woVrӯ"?[3'uEx*5Zuq:SЏZ)]G&sO7{@A4aA8Gc:5}buu}g}Iʩ,cb &n+ĬA#,܋ vM1y[=Qynymm m ĚZp8m_Е|sDF}]+IH>/"dC h´Œ.P"5]𽺟=TM!";1Du#eSz%ubPCQO)ZMS1d Y-TFι_םRJWwql ?ėh~Wu Z57lG=Z-lݱ~N\jO}cvTDAW:l&Q;A}Y<>@OA|5uqy& XʳuHߦaӒ j#.7RCKdI܁vgF1u3S}t sS>P!k^]~Bo饛4osP>3NSslaPd J%7KW+q/l4~;zb$2v(Y)-+%rJDxo"x6Nv-Q 0Zx(-x<ϟ 't>!ܨi{Q&J8 ׶hZx̻TMm(VIuWU@ցklvRZh@M(}6^ }=Jm$4}R,?47Pqi(р'n(qj K~n+ǰ%]PA_Rn[7TicK8Hr?AIq]Z뢾>2Nq9ߤ2K ݎ{p5\ BmB,1!h=DcL r3Hyl6J[f&rbYkn4mԆF nt~b"GZu-ad)6:EhA7Եv@%_F$]Òð!^/?K̳ ~!G.l}M 7a:zxzwr_Eٜ~c ~;{ͳa(#VmI早vufzpNMesqhܾO+C{]~ܕ~B=h2܂}Ǹ^ف9GTVҼ P+?G3>&X]ܗbd,J[r/N VM$p:Qi#A`x9t26R;Q:{P&[1g-ݑ}%-7Ly_oLmk:ٖ'δ75).q}zM2`"x587jPڧb{0(>JC4 i, ё] WVGWAIѮ䆽RPtpeU[dhʕ~>ƬG-/K\%vE9?+'I`o C(_Hkj;ωr+_lcӮkbfL7\;[dȽTܐMʠG))Ki"՛Y0hgl v#QĖE+5 F31c\1(/MSd{Y#: cwF0emo6GPUYqH1 XVi$|héZ=p0gg3i` oo4P>-ؾOLݏC0Ӑ5a5psIz(,LR3]ha'" HÕuQ !L؄(_fO eG]:tu^l a*䆖H/V!%KHK_?_x H2]$$Sc_#& OIeǤ̻l:<Ɛ,,VЛW,gJ[ ?U7 C[n=V,=M*!xx|^:$ƃ%Xs8 -d.GhGV9B$f&[x6/;v}ƾ`l0h(?Lpy ݚ2OfQd ,•$31Qp~Mq7FEX fEb(FY'h(Xqڈ8xB9X{v֖.#{šk^pH[@LDEpG WJ{uFO !po基Cyk=CO).0 y`]saMHee.!: -6ڵ^.=ʟ{xm\Q*= vyvI\<f!qF d#f IANyf5RwULj ~v7/eTC.JVt,j(W ,^3psQ2e HBdF= D?3hY - fisvnx۫zh2](aQY-\PQ{LFQ>}M (`jV.LVAª`"ݻj7K5n=3. F';tRmcu Y4#,,s6RK.+:w)c͐C>tҺ.GM8Nβ\p6gïfSd?t־_h;s>0)Tjڜk؃PծdFBoX !҆DC%RgTEm[<#w ֋&^~>ܯnnem%-5ªyB'{] \ݟ[Lo)f4-ru"t 5ϜW{DX_I?ҾxDD]g\Үτq/q;YdOw͇x޷yH?i&=đS ,ȴك=VǬIh+t*.C }1nqyC}_o-$[Qw1#b#_c 3eni<|Zsٿ}}#A@-r,84?̃YM͛݋'lf<~yT&[)@3w l!YzIш#-M}I彁w#3hv==!΃}_}l@}=S*K< OM:g?X==PMyHD^Qۮ2go7mrf"f1W^+]LxA0'aN0ۖ|!n* $uܭC$jY7qwwPG5xV>w6_;/a 7:. .t/JJ1("/O9(>eC/X__ B@sH^[(OB<y:(87Q @jxVc^GE1{H .7bLPsS[/M 8\JA@Zfu}v%an#y K7jiQ<ލ}" HN R Yiڣw4hU,x>qbsޥA_)"y]:gxDyNR5Bނ_^߂p2 9T٤*yHff,_rJܜsS4*ɹBg[;gj2o?Ӗ'J :x3V[ɝG-':Se#  @@9PYVƿP{:=Iv1˜c/Rh&chF@ 0'K)PAjSGnC]ea.hC!GgHsA 2ZNuX=ꍤ%AtL|TTaLيԞƝ TC㦋V$Jj੃ `$B\J!$[ 9u|O |(볂,?O Fxe:0cg~QX1Ĝ>{+#Iɒ)Ҁad  V6?((W'"ˏec-w xn}## 0`x/pDJr^vs ,:]f.: q(aپt6|9on5Kj!fX)”|4?6]if?z?`:?iߒ!q▾QM7Ûsi>)VmC^{\1*X8y+X#eQ٤Gqe|UtÞr+уi. mӒٻ]Mq3e aNf]$v:m>;Fx6yQʡ|Xd#zt-'iT #6rTu_y ?%rÍrDo 9-#9]ܘ=Cεy2%>" y\>R 5H~1*ڀXSXkO  T~[WiObNC>k( ~QCa'oR_q8IRxrrN RTW[y!v+4V` ݹeqᶘ1SfxB0EvV2 r0, nUlopd`a #ou;BbckRrN%xEBm7\we`oﺀ Xu0qnsjVi@l DQoMR&3oY&6\1j͒PO-0L2q6.&¢t ˹:-^3ȲG{ Ȏx#@F7aܯurKT%RN"OYD"nzJp{:qh])RYB<ԷӉl!jڍǚa>dVMW̑VAS=oO ۅ%Q; <|Eq2HPxF^s)m<η5dXH{㏮<@@`[$G4KJ9(>6j_x]JU fޝ=XAD}?{d^a5d֡<֒<}*/u3ݳGHO[U4{}MnVd⟨{?B5~]6JuSZxܤl%b0 Pwp2 =)y>GA^rg2&O49XB_|OH7ySp%8FxN/AK VPsz,vp1Y m^A~L8Uk~ ޵Y'":U u3~F! SͶ\,K1k*OM{渃%H*!1O՟t_9`a7bя KoΓy螿lc *pCo}UI Zx3 ɄP٬D?y肚R 2!(ǜoiOsg(-\_ef7TP_u.~\.(u*yaciD~gv+v,.u>@O WC`РALZ)pei-h[}Zu8F0$O7ٻq_Q<*Ln;lS-2bsMl"Da5{LU_T~HT0Dq#c>K~Ȼ3~vP[S "gK_\yYRrw\hq7UmQ;("f#׽#_-"tNY]:Cc"( ы']ݹOzXZ0''SOhm}'/9V1CσsZ8u3".ik ׈[ fZF=D2z3/fhO| t\ i ׀d bx4H$}MA]-jWt;1K `THcՌxq\ëڛC]CN iSUD`Y՞e‚[g[Q=]MԑVȨ?.IFڍxtF3lw>dJ&ʩjsbKcq#Q~uHQrGqh# ZՖkR|L`" f%3*e{Hx6NP) •ً7~NlIȔ!fRAu$V2V,9rf [_WBBԸ$H~Qd8^WLe>ǧYM0sY+6H1!z-BM'#rھzi;$ɋW^b*aM4ox\5٬Lxygeb auekPGf-q\Z\@#z۾qÔu')Oio˘ xsY &lX=g ˦8R؝R+6D'aDղ&6b)m^ P~FUW ?R% ]AJQsg2Uj%( G[_8X A~PLSTvn`0n&W|VLSTGZp| i*\ABQD/T0btxYUrYPP |inM\SAwV3~kٰ'ҘB}t|DZlj$t[) T;9=o `ڥ)ZN@>8]5l>&pH&{4eqΔ7 on27Sa7;txRu/!pӏ2U 3 -R+TI=\3_P>e xLV$qm,^G^y7sP~x=ʹfs!RC^P moT^BM1Ņt Zݩo+ěJ$MWeyΤו!g_[$Pҳ\=BcZ[0p'Md>AmgPdvˍQDŽ잱9HkmK%X>!gDu_0& /9^O)ԩ$ш͘D\n7=o^'[Yi0 a&% f{ 1 ˪ݛS~$#+vaG"Zڕ:Gkx!Gv]*b(a<10y4@ Dc@gLWQ\wyDC+SYщPRʌx5b-PlY#䊱.rT Ni4pnCfX,S4)6w'X̹+yT6g~^@MMM"=:-u?6rd Nb}0ɝP"nۼqu<92.3יݺ٤1GO陱yq˦zTiE(` =yRHJl@&:'AkRq(&ݰdQz$*<ӡMfmH<^iw"PC$HFe&?Տ܄VS\`5k}^T7#7D;unѸU_ڥV+cD -P} jq`1Ϭ_(3jS.YciPNWͻm)Rb2(NA^kKTeI-ͫ #NhyfUmZ15IU;0xAֹ/5-+$TqH ^ԾBc+ O+E Tħ6} n Pm1]rnaz3=9.tw9Lfn~xePOrÊ޳sili)؍;nxsU#-3VdSJXcΖ~ 0KH"#|xmʐO`K9]h> v^ri9NjNOQl7Y0Մ_=톡w}=AJT1gIШgѰ *7Vvׅ&s-LajB*%?5X>E-ۯH9 ^ ~"|-n b5l͍]#8jW F2g@/{5&(EXǐU -\Utg lLHsfْO 5sZE៨jqwꟉIXt-2tHz gF礫v !'/*hezbZme%mMϻ)wsA$`MRfCŭ-P~U?V!F@9”Uu~٢K28Kq \SkYM%Ked([V+YR\oU5r@ P\wݡH(QgvԅXe G2^ 3YSr9m=`HO*\w^*~_=b>:6dyt)H03uFrOmtG*4Crs ,b +®+zKD =[ +* 8֡3?DD$s&}lBDHePSdv0fdŗa(h=ª.0}zBAAb "ǎ2t=]kyx"RHkYU\1t.ѝ%*7_CU} ZǻҨ':tm~,M1A6;Th :umrr><2w?~ns 1iyL]nvܯSY"h΁4)i>+q%we>7178n AGa*-cki*'!uYhg6eB\ZФ5%%3j9j>ʓ$UCG) Yp l..hf)Q {$2ш2`b &T%&vXH=hAUi G؂zJRcaџ]GpoH rdJ^e|b) %Rh` PIMR!y| it3!~x6@^i2YoIR \RxK`ԘJ1 Ɏ38cγtޞ^HS]rP@!i Ie(բ i=u2Orfu- Ƣ39g^V.)"o>@F3n™I9`k"X&؎fd"7L/ŲB/콮Į&*Z3X_v&6X$m` {j=FWS2 ~N_ .1%$eK~;dW>G+ׯTD0vPn/Rz#Fܭj]jR׿SCUg0hW6$CS IS],jqC aVԈSAOB" Mt*Th`{uV P5} ɥޛP{'C1i!5 e1ԓs76]5@afK腑!TEůS˺[Zp)+A4Mnz^覄q?+cu+Bӹ=jݞgxG *x^(oT%ρV?$ɸX_ g%Vuk>Lq k%0GDgx5䖕D{f`Qz"$0S5t1wnnό3鿿0@6PmkC0,ys{C͸z{/u#uBN}&fĄp!Bߟn=,ne-D1ީ"6,|h.bK1bWsYyoӊFϫhF6G1{)VKd ++Uio9ǁ7)z9T/`'6!~{^":AA.E.kE}ubk`& zNf6%f'UKǏ` }Jܢ]~gF>m2 ѤbvJo4&?FO9Gmj-u85 ]ܗ!è~_6=lO9?1^Y.upLR}KKSD7~"S߮fhGnXKY;ʮ`D.*KyaaZ%M3;8hZ1|޷:ۛv:}C_XCr0+*NrK "Hڋ8FtӣmyRc `ج<~Q8A4?ޱD5[–o'?} XwR~?8' ϑ] _! K]UR(dvu9h;0[Vٵֵvl7;S)3;OCStci.!BRROўwܡP(΍5(~Bμ ,X?>R&pn݉h?gn1?7 af ^j]iHVvZ:I*)¼Wx|H?]#Ѓb} Vy E( hlSMuD(ZfU!j`֓WS9csk a<} (uz 2䆬Py] Pi״4_TWՏm%U)3QYîLx]OA'ŕvɎJC{hKVjw]ujàzj4UH%>obcq'%DiutpG&b} o(23@7-#l]Ow$BKo]!Aψ- %"*o.iG"%~l9"/A<9ƢՄ=U| 1ɕPp&AZs2 q:iFcc$Q=Iޥƹ?JB u -tr<c<Q]{[ᵈͰכtwz|@E(6v7@to)uAKv{k|ih@R Ȝ3a(WftϊZ}tX.dT|MzၵϿh;f0'21Mo,<%fe!UeFAD|:`VCD7+}'K@ߝ̖<>\%-`I넨}6tD|Q~\aCN&<‹RFF:&qo e9xXÀq#8ob|6FpWiF*#aGە9egL;""gۄA%Cʹ4@ 18ԭ Ms{4m1^ ![2zkYꑎqw;j5%I3.A"mXf&X:30BC$#vg-BH Z{n24om/J!p"p}jsR2g*!xbXNԟԃb21Eya<):g+RT .  /?7(r>!Óf氯'I(_O.ISB p?xkq3ԺDžr{\;y9a8B ߿r+b5བ@ܡh\0>t.8(K%^dv 1E0KP(tbY$އ`j v wN5 XZюDBĝ"wxm%wҡK3s9'xĎj'Zk)^BII}CFm`ja;A+U i7̇BƵT"}8Q–T困 JDk>ue`>r_krx}ihW'!Ws8%iVnLnx6@XjьaTDÞڢy!E}qU$eud*G:nfRt.]I!9%Po:}&2S(/=N\9gm8;6(iãN\PTc0zoRGY7NZc|ιt-If`l/%tDu!$`U Gν :&li2y5;m un(qIl'Xdx-'Ch8QmJj0 GK_N]~p)󬱤lPqw%"(}Mvʹte|񺵯6f&No4ȩסevJ3!Bc=vDKZkGT1C4t9tfZhJ@>P)%$ݧO;5t䟠v :06vHIPS6rVSUqע^HX)3 ރ&qb.zjx7|#p+ZZr 2?iddsv./99̧#.{`Djq $]R̭_0np{%$V+ mi;kc0V`j`7 SޒӼEɗѐ]:U~Dla:æ!o/?H+H_f@ 1٬( >N 6ƒO=^ה_" d*SJͩ<:=iTsFF! p+ʢwq~u4 ՙECӴ- J*^NkYH*фֳycf|z(Yi#5"K56W')"ۏ.ݏΎ(4Q)1E]Ė_ 4`TCY2.kS-̈hplv:xwMZ&8JRvevK<\puZ| :$PU5 8նWڸg% <cuc"$q<.I8wǤQ̼"+/ -դΘrVW7g D5mW^?<8f>EV_Du;R O0ԵTyڷ>t:Jj)b$%Esʹ%3et+O4Q(÷̈ݴ{ց\>^%80FA "\{h*2mh)XE mlxg/YB9lsFx.c \G4n(e*)J{1b V% 6`%tP9j):]dKE8ly\4ehrkF@>V 2+EYx,aя^.o.n9R`$b$&m Jl T&__kį%骆h`n QYqq^ 1 +z~L*R?^,Xjq;9F$Z|;Keٕ͌iމ9ixg6۠Qq746F*Փ}@{$ +dq1–β~D%pb'P[#]FŁ}v"W'LIlMokJ5kVwbq`x09‡+b[# ^aE/I ٕOhfÑTܓ Ihiӑ1r0,PyoJPs<]ԙ[ ӡ20R J:j B@OTv>u~-I=y#*׸]8gΝoA-TcFk$ƍa]0u#RA:.{yWէ5_T3@ V]5ģSun`6r؆2 -,N~MK+e1_0Dlխ4 |)uE*$ bc#9bHC3l,T] ,֝n%AOYE'"n`Mmv% MuG,Ș f ԛ[ΉYw;V#4a5,h1 6Ig(LY5"kO [j9&sd6c#bۑg`s3#bW@gHǦG'\#_#@-ա<(}$ɱv_dj}CnPڤD) a yTI]Qⓩ9rcgDI{ Pl1;EڲummHVҊ%|{~$۞-4gEU^R[TDAq x'`<l$1 -+=UNK1Ld_@&RPdTN?jCaX{dgoOsN4{*|tZr{W+]?l,YS߀rΐAD U6ucBK7C=vrmmɨ8o: pY3m(2<<<нxFT1'G$MɤG.+?swSXr]X+:-S?V/ jt,'w*i`'YPcl c낅Tpbצ8쐇Av1ӊ3:V-a+?VaKZ$]A&aisH(IP:ZSKϖ=paԅ43CTy&h" 0(\Kԅ:#bLc_@?(=cڿ riRͭ[|'Fr#O~)'`E:˘=F]ôxu~(uD_2"..y0; bq 4o=}~t<)x2a`KS'q]pIzj TaX_aT0 ܙ 6VvX;=dn*Pr7,T}ޢR$aO:)?Zu IF>x1{R" @ ]O_Ʊ6+}M`DD+9SNV BjACQb?S 92]BdgkP# ڞ^b厺(%w-{A";cRIslC5b~vd/M#vq_Zg jIy,Nn, ]Nw]3\Ic{-QcES9Y 7 Ǟ%Dqh21k[i̦sUs$B(L;;4*|l& d\u-7~SٔIF WYf;&Pbf)|=;.=DF+~1sqMr`cnzq RKҨ8jjC*fÈ~$sw(y5yS r4_$غšnQ*MᒔBl)_HRdD b(eᬉ dJoʟpv}3䏷X -vAx6iFYĩ`r\ rV1xgoYrCiZ  ҏd2Ml̺b0L1ycZqf,5pLT4U$1!F4JdE] =!D7ܭjtC~9ep} c\.Z-Ґ>[.LV:q|GiOsL eM8 {es?y{>hv %IPhGzn'`#Zh?O2Yض%[-Œw|c=J bt= UCҷ4/( Lݡ oNF.-m4C9S7\>L7TSƑEtTwƳsr, !'pjwf33B%L]䵒Xx'Ht3BEo =9ap9z x5@J}=y/ M0"u/gS~1xn!:8AI0*K 5kF xU;cG#.&D]t*9>Ȏp텱T]vxK{Ium{ZNp.2Rꊅ:?a O؋I^CEޱڈX/d^RґŹ^] %R?FKEw $MIx wVp0KbQ~kM՟pT@+wK-]9<d8?; $1&eq;dFʂJ {NmUӷ-IQ"2A:Iv}JX&y +0kh,#95vUx?(tZEugEt-H֒ 5Ls2UUhnEP˂L@A(oNf dae-o;$`;LO^F=,/d_9B5AQ(^q8B!لj.hgdy\;m]EU{ɫGj!?2;I H[k c7JS %H[D(jU|TP: Ku>e}`x]|G8n5toxQ nu-{C=g+)*뫘!Wu[z F#9G%Ej͙}fŀ݌j`#q L񒟗y$~.pɩUx8|jjslb>1GilۃHyt #Nx]Z}EN_$6bAhY"CȸXx uћVvL 5-n 1vgF8A S13!<&8 =/DlۛD+E[ $*–x|99 a<*h}Z:I@-M>{L2eg'x(VFrċ6 MG>Ozt0iplH@)52_t{"A~%:Z3¦,o[YDjO+qtQu24NXjFmb]M$6 izhzW6}n92Z@ڜnܤR>nfU_Gt`2kߔWhmc'[K7e5$ԽObu tvT*gnt%e x&w(vx;q:(v2Z{chDʥofYx2>w5sVvpEADyqxf2g OH4L\6mWwjS"ԯeZ IrxntKH\S+5 K̏E7JEB6 K(~\LLOlꃸ97SZR07` yi? 2ӻH'迎Xe)퇭5vqQ G8yKk͕.]V, iƽ4af̈PQ Sw? Iq19{[3bYH蝲'KqJbRCPCO#,ɡ!7GfRܢenkBYcUݏ&0hn'A_sh.鉆R~{4 Xr.Hw#v,n?Bpl(9M!Ь*AM^GphNZcdIKa5 RuB:FU^Srg2뺾:·FvL KL=^n+g6/brB9LhChr) 2]v \ljWY/ĥ00or1=|4=5d`B]"ڶ07駥-r!^uZzDo,II8v]LF;ۦ@]\mas$%b5t&x(O0^3^f.O@wP\01+yA򧑍:i 2w˥3?W ?0YL\#G8"l GO!T$JF&]ZݲH9%mApq?~=r'HYbeW4xl2wKRiN8wU%l+G m=aHwBBJG*,qv-ndqêT7ϷdPUb^G49^#|@ŏˉ^2iهV 04oC,߰yaʭ o/CeA5U(@JvHJ‹-$ksdM'.3f鸏7¼HOݝo9 ;Uo&PPL ξDAcj'6F<4tZ33r YKb32K/ݫ.ěQ\*na ,CrT%m!0 ݡ׎]ڍF(dyA>b@Iߋ񁟨]MeqP Nul{:Ev]YV~{z5\i_M|EDN!+7(ȍDVgh:ɮSu3]GM +.sfm޻WTCK]{t{ PLp 2LNm5fJ005d3 0Z;|KMR>N|`q&k{p޾2fdCvąQ |4ZoA} 2 :5;dkqGΕ=M\L1q 88bPnVOߪUJf?- N!a#?m {T˜))Ԣ)7lKoIWDYjcB37 ;ʖp&eZ3Yh9}4 >P.(T%U4%X bK\1˵ڮ [nMBRCTIYw)o$S\7WWm"hP}mYz:Gȷ+rBՋO MwcaTLe UHنN_E ^_~Fí ta4e!'qOHZTBa u-dS+h{Y?(横4u朲Ӌu Iqa6Gˁ4UINkq{4 <X^t_slD{Y`[24'z b T 5m^Z J,C`yaCYʘߥ]?\ybzy@ifk]@xU}SFh?p=NyBu?祥n^Ԕr6xW$/YNWX|[3מۺ@!PM-yb$ɫ [(+ sb%^'Nx$+>`- R tGŔTA*d܈㒈 $_F{N \-qUl |Vd}SHQQQ*bpkE/+D+*`~.[M(_$Tg8 &ft? qIEqr5 `1Ahx|fQdu`j|7+Ig~J>;@:S"\Kd'<&!X-KzDۢ`O˜ļuw;гzsHoT-s:M8T喖 !q&Zb>Fz!~ O16`'u޻Z(!)bw$ (Q[|\qEIqk핔cH!x}> NZՋfc܂,6";{{)שJO& :o_lk$ vf -Ds M%$d@h ˌxaw; d3SgϹ͒n};l/+ xIin?!I0F0+4n.쑬SXү~q}hT\v>;lF, ohQTBSC:AǨqYO9 "IWdU_IW,)No$$(M!Xҡ ymb=T*S;k [J9~4fRf:gJ|ITKx-CZZ|"ph 2npߠ<QǧpgZ'd4'm'0-cby7n~d>1}@PoW?;5>T4!Ѵ9l,I5 v]lK\d DN^N⓴SkZ:_͇IiLrz;iG H&gh/˲ǸɩQ U }&L885JӻV6AG=Shc7Ow!嫀ZͼQ]衞f/XyQhkt6PX}b&F%iQ~nm.o0a;v; wƥQ~'='یU5 bUa.9uCꍲJ;a&›osΣ/ E~a1Y6Qυ!xL1v;@j:A1șeM>bZ{^,Uk g1aǰC4<)1/J'NظF`f6Te32 aSTUqf~nsgF㒓/L枷]WZ0`BƳqSq/^1T- saz3ݶe=.tZHG.jB<,icE%նVđ[ b2lED蝤w x±S1Z}J #oOA@Xxg1.mNn ?m^d-$.5κLrLD<7ƫo$_LU* KStqxdA$T6M]jѦ+oǟ$K zbHy}T~K}m3]V@kb*r޵ ^tQε:96O F@Eu#;K'|>=RYB^;;vY=ϐ{5cx*&FpL.1f$^6)ty}Fa^v FgG]V46>0U@þ= qyB=X$We)6r }cS"(g5 1YyX Ntm%c1KiK~w|ӳ/BurV(4.bM2:ŒvҺN1N˸!i9~ݙ N*+OO&˼k׳t|}{$=*3f=.`|qd]׀"D~D~:oْ aTVYoҫ4xqUq6Z}/949\O]<:#2adE<֤JO Cx*_ Q^+ўߜ?&Ahz0T=R+ Ě(;!*D0_P .e+`';mZu@''h0aĉ B*,0A>YKR{Z7 `b"#l?F>Am_'%nd ^{ |Y/+rpݳ˒Dm : &zI4QOXF=fʲg(:o^s,ܿd 0vNCK+qP%:;TxypqHfa؜K\!Ri`uINQC@e*Qω>>x lW8= GC7~b?Rs@83}Sr4׶2- kbNck?43wU#XQRd1*»4إ|}fS=˿RHXɌc\TwХJ bnmԘJ-#(>afYbRo-!e@ϛC,6fxٷ %zrP33 Jƒ{w}N*mz)5@L/;[hͪgfR '[VSFYE U {DFSbf3H"Noo5A,W̄}$=JІP:Ǐ.mOAdFA:n,)҄(z7ٶ׵N y[5[vv<0 CvJeT+>sw&zns-5I M?P(MoE47Az69Jv0ʳv =t^JMO'$fǻxə5woz@CsZG[$>-~E/9wIWRbJ߮^}C9II '4X T;). {{-cӍ$pd| +Oͼ^ ղX `4ř6]/Id9ls|mjq.Avѽ !oqsm%ukj V&Pqފ븠D{dtj*n4{+ViBC5'++XdJYt1fN7oۈ aO/4  HH-೴n7@Z{n`H~|@~eY.Zoj^hT3a{ဓV{>\)ȵVQ8rČ]E8h5+]~*MJF83[I*wKS:{Zݞ!,CI5zGe W. wm5%_:<ȏ?̍xtqT O w#lWgxe Ed図A0  ǡ~ͳ[i,Zዱ܅? KPZ %K<)dr" bl:i&t/{b~%AQ^Z$πly?`H)[¸G7 wIԀ0hW .ؒzW$f?#bjJ#v[< RœDQ9|"ڬR-Ր읾isZ@f=bpZի:Ӣyvz"VnI|b0f!=1-{~R"t m]BD?miz|.X~ ;`z"dP;yќ&ˊZ(c8 jn\K@9N-%{j;(:oogs" DVީcU^J%7k[/"1 ) Q[7\(i [ԫɁi%& arw~b9U8}%Q+^aR@NĆu7ߧWgmL°UPDYM_~5*llQĤZnL=պEǙIiHc^S~ :R@Xc?39v'T0Ŀ4uE /~PT&y< !B <ԜR1!{جO?gfb=.tہ<`&쨙@+S.𴛱d wRI29LȲebI-5p|3x34l${Xt8ӛM6w$![8?3i(vXʾ w y+8ůdeqڶ64쁠d9  OtܠicUmh[dPH̑O BnbxI *rPJҸ,܊,%kU`(O=~``bYpT r&oi +-)o׺d M.p*dݺ$j{[&:7f[ϐr>Pnrllx3eƶtYuLcS8P& hVUEjM̜znQٗ$_dIn B2Ne1 Lu[yuD i/m Vt&)~Ƚ{>$ M3$0ͩTxķa̝ B2Ci"7K rF#,Q _JZ#3/ku;Uq0bE7EuQGG7YM—wC\a\J&ކx  ֢vc͜8]hH+v}!aV㤔AZոv55:Bgz47e&c/C|cpF.>4$__ E4<ո`K,0 SE~üIE-z|cKpsn{rp< Gԫt♓Bx_Ѐ-s,WiN׎7U35@\Pb+ICbGRJĕ-{ ߑb]y.GU3S(O (s rGUA_ /"-Z i7Q:R i\1{r6|N;)DEϒ?t|q W!5"_say}_9G%e6sgh`X8]G֓E 9|,KTӜ忌72>4ŲXGZ dXʳrfJdjrWBv%zE D9 owZ / M ѰPZ6!ph}a%:]EceN"2AEl=;fxʽ.ղO6@bmh6 8K|V8z6:~(Yf;YD*nmʩSc򯏬Վ 6>')alV6q:q&9HR V]֯ {#7u`ٞU4Yꯍ7AP 9!fE-YXA4Lp7+M)z,O\%w)o3 :6Ć-x&Vr:kqC%'FR yA[wYQ@ƪ*l^YD==xPi1\,: ;i{< N")Bt'YFD~uy=Д +") };jJ/e 3lQspk? #ϰˡjlDYj1/IIB#<PNdK8rӿ"X@HD`K%NtN3㎲˚i=Vz*{?خjbb$LBImt, Iӯ)oeYDaBjLX^7\gם\`Kߺ͵R@(%[-R ]o??JUPdAt?'ROIcJ~AUp#Jnx,4Kziag!ӛ!ӾAhe?ED >Hm>݅* <a:_[BWHOA@7 tM֯}9m_!ۜ:r5VVv'4.3CLŠs63㠢)33[& sD>HŻ"a7O[HNFk;0$ $w0\6.sz{Ƽ&HGÉߍ<ŔNIb-eTjSv2$# V0=00QJj>)^uP4SDRn|lP&_yw,1ou,IWYɺIlC}C_j11^%WN]/v Đ[\f$QiJ,&ɸ}[E8{2^G|j !$^>/dnO]~9Vkj 0%nEO@[H91>ZM)VoaYkݚ%iu|e7_Za9ԩhyDC#FYB#);\cd Po)!CCґ!@? hh!w@O2S+48cDVqsjȍ/Ӿ_lю}\ӺHw9ўYݾv[+3~H-%z#pj* xSa: -P5ݺt2EKlbB]rs XukictNz2@wFkiK ìju A(n0p\-+ H0v%ER"e.5HV*|WH >H!®*LGEgc]WM)iuС@߈ Tz5B$@!=2XFm+kM^/B$6# XG.4;%"A@ת -9FB>x-7X!]J7yvbq($9G2l4J)f<\QR@ˎKp[v urӘxӌUԔ|W/yϒ6|!U}_ Ⱦ㔲iȸ%k m.Ǧnxfy}`d^Uϋ##;cqx;mö(W:m]A `HRXdKGA)x:o,ٵ%8[9 xF>9޹TluCNeʫVSPy:k FrDк EΆhυxt_\8KG GG!_;!0xl=&q2կ$OE (6a؀u2io[ZX&}Uk0}}> >E/ g`vK>gZI D G%4۵瘀y!9p'<9J}v4\sc a󠤘;XY౟SfhT]*z4F5锥eiLqs[xx`4Ml`w@Stuì XyXےԂDZR\Y㱰ZK:|gP~ okU^gО xn..wPߨ b<2Y1x])mt ?*덩"WjJ@-k C6:^nOAk3Ia:|<&:=KsGɽen{Ԃm!|[Q!j$b2.?t2ޖ؈]*i~E0/fJyĹZDNq&nefդok&:MXiJ {wͦU7{2*5M?8Zڛ۳8Ɣr3L-+]ggt W~"{^tDY= %e zqwV_XXK BVʴ9K[&Y(mn&[fY^+ <N֟XOŅo,$i] kXЈd+GHhH-rnBK{N8E3jn`lHu%l )$IFgZԈQ=N/D9^pa$#iz2 hOrVɏGOx$hO* Y)d{ [^q"|55a|'@ דɎwb] /W# O^ec!q}|*9JܔV*lRr痘<$ "L-D] F(Hz]Ku3kk/5'v˙H{Q蛡;Dm z;RqR*s(4O AH%*]9i{stQL _^sOD+ml7qX.QQ@ܹpp\wAC,|ufL:|tPݳYil)[@A !AI%P9,8ψX^( ҪFDѐ{2{箥=6=+,',v~۰HѪdx' ޡ3"EcoxzImĥ;L_`Mqgoeva,k]s9 [t#aH7ǣfgi/>3~ɮ{{eZK5̺[$eג1QA.\k"u{['Fh߃%s=ڔ~u憪O|U T9Ԓ"9-LǿizU"d bi 0vn?X-109G+6Pc"'7ғ}@)ݟERIm=U|XC1Swcxe ZSc4ES[ֽ&X0`c3KQ!ZܧIrdU! V7f!!3I9D(c"}52{?b ,kطofM@,li'Z0tY ndggi((6½GZ=ދx$Dʾ__naLSlAFLc;G#з<۹?ۮ\R=,9_$j=FcqfZ`G>kWƋB@+9TczK L%P6Y-Yu2<~f-.,w>$ْ(zNܭ>m\;底E|aLn†{^UKQ -OגJv0 v{l'%Q&pHJ#2k>`2woM9L gGyě 45 w6%@cAEyL=-Q9hoG-dGv^lF.U r9Ь` ~kgAfZ +d:0!#zV&dDw"p(vYǎ~6y}os|icά,]^x"Z,|fRL,V*@ mҏ2/jt)! `>`_Qꐾ {-I'=٫v;Gd]yt vG좯WK2x*xqV rM:-m@E dq1E~&z{`[xzutNObƴ1Y&46qKܴ?-c۩_x2bm*C<7 DVdscVXIĥO ϝuAI:zA z&fRHg ڼDY??91Z.뎘Rch#_gJ6 Q!ptd& N7ŭ)VqSxie F&j |(I+ΰw@wVlr&$'LZKw6V3f>Rzce2 V>Æ*E/l)\+A5o=u.VFiJe4Шl)).uWӊpS>,uIcsFE\!5QMUʼnqow' ռ2#bY1pgs"oרC`$-[X&'8<,*,^j{D!٦B~YfP`~1g8W"aha>Y%2d:*jͱ90*&3t@+ :! C¶qVkE/aK@,Σ^U agH0Ns,Cbgԗi !39zx>?XKݧ@I H-CH;TcO?<ᎱMj~<9ZX\h_ p'O$XƳ+,UT73X|fq.J+ce;iP= xb,e(;H!Dۉ̖`PGl G ҿxzd6%dPIRn؏mN,}Ȫͼ.x[O)OH? _T)eKl?$ti_k@ދ%)F jb]eь[U-J\g4Yf,q׻r~B],MX}Uj ,1sNk2Ύx( cJwB~ 4uO3x8gx1Oڒܽ\M%R5F U]E'BBBpq:@ci3G8򔁲`^Mra#-SqA>72|[ΡFqPq)Ge ~`eIDkZ{ FRMgEF]wkSqd|>I(fT, .( ;=Sx59B`٢[1nnrJ_< <91: viU F HXdb/ߢޘVxk#P e#F@5̌KF+/;O-o ƞZU'8U1*9. m6q!QTȚb-9Wp߃*ig#tUMcy/qﯣcxk J|wG~yoBR赯_}ܼh ʓn &\e49!v!oL=9lQ P)ᴵue@3Vͺer$3,q(wG~i&n0ӀSp9҂I! $,@F}ܺ|r|1G4h6P\ab5>,ta6,[A;p"=Kw=e"INrAh%AAejd6?lGt//qNWxae QQSLBHV9^`WB-ґ5vl ט*Tr15آpN[6oٔ\Cۛ3 E1y{aqd}ֳJnfy1]rHX%6LLz ~o+ou!?|u6JGқ|2(6;3Y^i'yn>86eL7[d[/?x:G-lWg膕^ C@ h7҈]ɱ "\_hY6IJ0ċ"2{@]&@h/ɾJd33hmFl5 2o늖FETW/Y ;sOT"!_Ȱ{0b ÒNǘ 2SP" KkTe^ֹ$y`O)?tn=b߮ۏoƐre!ۋl }@X_YsLb_b«[t}v܊LMĬy%tKYѵzRZ Q?;2P2ƮuzFkKc6H`!|vL6ez`rsH{PMƑ5D̈/wlhb̭Cx7(kpDmNasf5ܑlHS֪>;0;R!t,Ni?Uޢ'̉Ettqy_x156Ŧ⾱e ;?"x1K4m yrfC'_ dBDdlqmġ[@=,X?vB̦.4 'GoIGe$$7L`рKedeD[nčE/G鯺vo-/X`‘P^΋8Ċ\1n>N\}]r*.5D*U6mRڐ&u&%slAif;*?W\o݅ͱo?}j5hL{ 5'6Y'S@asL+`{S^If wz|1Te-۔Q9ZKcsS9ֽ8 Y*G$3̩Q6N)4Rxwަƞq=";Ix3;65OҸH`k=MW9,9L|,\BJMhdVj>OBcxbY;t&+]O/d L5H>"z. c1)ܹegsՍX$ڂOfj $"@I smr `]yK'I`^Dh쐚zI\ؓn:˵^JTIP Aջi1AbTlqV_'=^#CMhUzF >2Y& J\2a!uaL~@Rjl&0ⱃXhStRT##ڪ&/-":lc𩸖+}v'GMF:8p E"t@0kg<6gg& gV:@j@TTfE0}܅`7C"t l+]wSZȑbo)r7!NOӫЦZ0!rz>:LHeyj!2K9h/!*X hL%ǻ%#4%vZsn%Hh$)#6"ZG_-R5Y]եlRh9ڠJ՜VsZJ[ɹlAL$s[hiʞţOIG$vRʈY¯vk}ܵU߹~Ҭz__8.5 r[NXʤrޟ6C4ص&.oIV0qNk!q%K92kaH0 Ӆ0e%B6;;2Uf68<\ O8}atI0-xˆ6glGyt{0#-OlHʼnI$&oxg)"mH?\`X=X30-|t)TimDJ J X8OzmhB4le}#2mǚ/GjK/%K ]&3;m. P~#9T} "]+/kU ?ݗ bP(ߨM Va!` ~eāB@r቎ˤb CSe't[m&=#-d:пR 6a=V;~0ټjkQ^ICB E9[{ Fi<0  j=}SzK8|ҭ17Mʍ/ǿ*cj*?-Kjײ:@ X{mifܗɢ?ٛ[(TqxT$x3r7zLo24lpHoզG6o6#bu5V].wTEB0o9.$Y=dz}MAv3mE$623~e5ihfXJLJXѸ"iZ(l#!|O&(NC2ޜAO$0ήS1}P\iQ9(itfGIjA)RݿDUkN%"ؐEN;1\ Sp򖿬w Տ~Fi1 iη#?]3G1꽜̋W=0]P}g&>SD2bk9P;Zޔ['od~#-lֈ,_3?v?4.yj2A%/7'[[ZHԠwFAȭii+[Yga= R͟x|43`|)?E}ٴRc2\\Gb 5OgcK h/ա󋆊4ogc)XE+1<[= S.rK YX4%&VEF8Gmb^+vy^f(emMFPS'E$gLD Ƚ*6Z2/c"T@GU~)־]vV̙jwOOZΟ H^P u>JD]0 Y&c Df;b7+ɶ7ë =E<p~%0QDQCsEa6 N=9rsgZzЉ_]aSm>+2X %:UȁflC3w"ٹ>c6mw 9[1V #ڗQٶBn^hO.|52u#ӔW Jg$ё xv؊-fHЈ|6=eτ)\\˨Y:gn `bF2ir aQ+:56x%,;QAӰN\ͱN2jUqZp'G׿^C*K!fhv̶%zwc qY=rE>M UmGV5wT$h_8?q7J[84m)>VgnxOc7|LEf?@D%6XMo~IKRsot uN좻XHcq[Êh楒ŋ7)W,mo-եm}A`.uP,:EWmM\PTUc',QS´D> ]]K im'YIqVjg<סUq "Z! ϊ ]O]âW!5WZTA=R"Mymo/{+^Бd?HǢ<ϕKfVۦGky+?.;qS * Gaf+jj}1Kw^r]Pl==9jh7D{#{!󥀈&0w׋JQH]rm0/9Ee[q':r;($A*XBwyoۏת4c~v2??a[+6UloyXËsÖ:Q_T@r]EYv}0>&2WzkX>!=Re}Dun;fWTu7`˭ wi'2?oMet %^]!LD^bsbT ECîޡѿ$Υ/5-(8ېi:#X%vS?v?i{1{L]g*m:,򟲔=Lb\b_n]n| b(pžbW`#)5K+ɞo@Ƿ4)s;**z%)ăCpu=!P*VLxePݪ?10O_睿WYQ+X8t /N!!+_uq)ib)fq( r!8 V\N[u"t%N#KPUS*xs _ż7z5?b0H%Ȧ} Cnф9B˄mEF/>_2:W7ucpuβ4haLJ{zz-t \}pr.z`^߽7B߮dEI҂6#_L|_I<w/*Tz]~f(Foᄡr3y;YÜ{v[3lg]>+yFO]}Q'DP^}Uf,=S cw="zl? y 0Z?Yr^DY6 I"?͛ugXN)6^}C+YgghA[ȈTnO(T`dtjͳ7]Qf]7i»pcu#Ε KB !W\ShH+@ZH" e|vzX#6ǐs|;Po+_"i/q*X;AZ} OYxi!?x`"~o#m(p=lunj ІIIruѻ')AHgO:Oy*a)P6dgq , 4되X?:A#0{=X3@; rIA4r$z@mi,27ZzN/\sK0*!lɌ}\ŊnkkCljj:o% %Aj~7,".Eq"*=; @̃>%1L\`R b+S&:D͠x]ǼߟWB׉=;Dw%h]~@CpE$Q9 iRQJ*yl,JW~+IU5bosB6o`JYɟ64C| S )BAix)w7Y2DPˈ/F$uaH W]5RR:"#8ŪwCFxe Y< dg(A7[տ-dJŤuC}y=#桵M @l2&|^ǵk)٘aN dz9*o17&)ӤbGL}J1:{$f҄=W ->o {y' j55ՓF~O{m%n;UNY5eէ :VTd"@y yP WpC ҇ !p MI6[y&t\^ x궚 3kgA+;:C4De/3 l{X✰7IZkPAcc92{ljW|&YA%z\W{<3*AJe36@_}:YGQ \ 8D$D6{-R|ew9PvaMBn -='d~tq5lkҺ6 @Mƌͤ8wXtg4M#+9Cuޜ\ 5:3\:[TGa{KCc7 j GzbWllpiF)}zr9}ӍXTI80:@F\x!*ZV9{QI=^lH$aV(/:*3N98C H@X^# .(fxk_r9 ]woikϟl[گ1 T*\bH(H햖z}]~_3I;Gqtjk++Z뫡@$ W߳zxYI Ygq4ca_PsDOu<{[\t)3U59G2`*?nx0 |v0O:_ {x]B-7|i{ H\YHB""1iű0^:Iz?}t:?I%"۳Wia_.SgBm~>5` $}Yv>?ݳ?֪oܓi[a-eƇc-Ǽ/v;=%Q}F3Jaj@ܖ0Y"@#i*ȧk)oSE9( z HlnvyN`e5y*Nh"cOu|wnzn?^U~^O3}G[x/OZ~w..o..oU0fi$Uczzfw0b4wr-9+:@B0?[_%]U_ΒR^=zW}._[J`ݪ8Uɱ9 Þɵzǒ1j\{ HBbJ (ʗ aI AMԡ*"!6f`e|zFSUΣZl{,uW|jB/ksTcUO% *wOz 2Ճ&iPE?,Q"ZU|{ޙ5i!N4݋QdErn<䞽k5_vH.1w̿/\k̵N2g3ًOYh۟M4ܷ5%m?ˍlsqq4o M?Uٚ'g-nn.5>^mqos7;Lnu穩nUoSus\^&w:\okEߓwwu[mwwwww~m?_yqUzM۬|wJT<~oej{vf/Z1yT`/3RmGk 'sɟ÷LړOvCiPPTݪ>gJ)Q} UH2Ǟtɶ6JE^ oĝKkt+Ƈ;HWVfj8%躸ѳJ$4ThoɯBX]imcbiAiڮvn&bˠ7g? LnŔrcbt Dn{s6_є{.G@SU~:o[mJu5_ @,3xVV4jv n)Mi0)C,Dx9 'U2TLWA+{FӗD_X|j)cR7iMms}Kh22)"Cqob Kժ9_2o2I-zo.}^)&Wk-?PF=AID~S_&ZL&Ӎg9;NK-4Z]k}[Z}{]ݮ9ߵ;ۋ[_Uv7;_#p9^gkȫͶ8}U#sr^<o^w_wUU*Z~?_e_V^*TٙWr~sH*u,h<ViA.s%}3]kZeul:B, m;q-Q  Cp> +W[M9rvr{?&C) rxC.yܾ?ݲ1jL)TNf<@L Q4*T+1aB 3 b8`/|pl(ux6gHD[?_JyVkOy_x} 7c#k5Xj0SlY1'6sfoҭpiOBz2#IQ~5r}$JD" n4@Ǎ!W 4f\űO0۩ }9Wt9t O 3IeuS|L1Ž #(2!p"$]:cs5oqtXO}7c#`>_/[%Af%Z _v~e_ȹ[z"a[mv?}oݗ)cr*m󼜝SmK{~J5p>σqqn5}]۝gs=.s{s}3s|ny^ouuw;=Ww~gwwzmyiymqosuomssqtRJo.-U=YVtY[}V`|3:|"ݲEbd7_/ ; ~v $"^D±t i_ eN1h!!{2w?X6e!WLgc Y;7O઴HZx95h0Ů4u[9)+Y<$: mnj8$2Ɵ\7}&y"c:ȯO[S`}[OyCmxc_5U9R~]'䖡Sa?eK_s7G0ˁHap.OtF(e?ߴwQ IPJw?`_F3=Spy ᣮh voWR1CEwN)HWkl 6oH ssR0H:!^(R%2(Vyܲyx6}7wH龾44yZeYC+.waDpanv]^nfCRQ#]sOo=In#:mEn㹡\pn4m;hFv˅W>/k\^{w]]ߓ૳s|?ϛxoy[ߗ6{{{{ݯ~o~_{O{R\wcjg2Q^c/9sNϙa90w4#˭[+̘(-G9~ B{.);x#i.R֨u\X]Ó.=֍C4zUa3t=t 6h&4ӹYYܶ7K[z9`EݰV=t7BY;d5IJ%~f1(SvfutOc&PS9l 4#0 |‚W]RLx d<+#u`41 (Ǩ}}g[^\Pe2kb4X,k竂ݴn"?Q^>t۷ʷB>3ڎw*\Zv ޒkLslduDoD9nju>NlMR5 a?JoJħ`KDt K!ׁ4auodgYޭ6z-sn w+1Z5c4[@U ܙxȵ}>gDfu63?щl'r~k;ktYȎw9m5Px-]oY։sqZbCl9=E? g[l> ߠ{7 ]aXVwf.V˪j}&oNSwpn7w|]_]}.kwwwz˽wGn}=w}w.wx.}<U|o?_Z/-ןۻګWW*8ױJ32T;n U'"om2'a}dp\q [lq|Hq܉Hӛ8+Ԣc!\@ 4JZ3 =_GirJkH=K"X}My11Ʒ>4KPfӚ׷9;{ZoJC6LX>=Χ c':~?qP ceI?X5I9CNm`t\ gnMܠXN#\!njZv{3~<'FFj7lw9LFKXNg'c co-q_O_ٛ+t)x5TR=}V;U+4/!r&BБΌ$$`ln6ˁ|=3^wIHuBHEP&h3M(I)'ljIpd̫R@UA>\7c?0c27Bx/9%.{zfuo%iJ3J(iXÉ]6_#~w>ӈvv >Æڻ"pFb }CTˍ`6M&']A/.ںC38|LS?i?tKGWסzY ƹws>#s %XGU$vY* Y]s&>Z軧z;#wiZZ^Owc赛s]û5?n1߰u˻G>~>]7_FwnwitM*{>>RW<=EJ*[|<߿/~b^~j_OTTU[#-=gj m/ n Wm}ܾ~Mj⤻[.aaVF Ǿ[ֹѪ8 ~#/<4 fF P$Kٹj&G6u'ҒCkdK8,'FTjޕo uacw;V}lHF%r\yN 6iTytܗ)'ujq,'EQ@pOfDH`I 9ʢU虶r ]Z_#jVhdWbO!6ȣ0e} M{9ĆKAa(Ao8Ї3MSzCcnNL+|ˋRF4 &usly*9#&spé^ܢHjiEg\]eY8.B5s%,_zƢpTj$ 4 %N)?>HbVhO\K׍D2K +Dƅ5țZf1fxƃ՗d>TCłݕ ~#U]Ėma69_SJ~մMrw-08 4nw2U 5Jk=7vQ!o}79\~awW=䚬6w>5`))4FN\!?iL>qiD+_MPj%5  !xY:2t74(F,G{5aGY˚P3:-'+)!g@Gȳ3k`]&sR<'  0wibj%9DIғT A$k0* Q°X4*򵀠YIT(Ub\/1cI0IVd/ [YA"P]@ 'nW6KO~@xBud7^,3.OQPT>\f4V.!yZ#&22k`l4`"b̩v2 ' Tq@H(PUPQ݀%lb fTeʳ=ZHDp $vpPA(A +!zawֺu3P8&]Ԓ^95@ڄ$xDF}t9*~5gۜf=>Q8-JVu7 (G&Ad);޲ZU tQ#fHY0%[ȹh^}1VTQ BH 7q@h_Z ZNHөXכJFHDz3D(JDLLl.("d@Sax.$Ο=3<a:MpƒivbB{SI B(*]8L) a+T*'+F*”ޓ($&գ+sYC.ޢUP`B0@El#Pt=ܰMˎkLP. ?M5,o лpo5dzbW,%]G'>ٮ͘x?\iH@l?YF}tyK YHma) a $j)=yr9R3~kA 0iCy!5Qe]i$VlΌQ m-SL*noj.6`H$ X͊4zr.“F[aHR*mǰtx5"*V1{})(!3**@qCNms L *L01eMEuw0sp\E4u(/ Y6Bx1~ {%oCׅ[{fti`y|tAզ+5jtk / Y.2r+!4@Uָ3[֪Mk\.Ljḃ (C+KrP2e@.Pd35(#.`f%r(€1g VM늀\/jw:Љ$)."I" QIz/$8$W}\.:YM3kCg[ё )Oit_:y1jW 2d32{ i%ʄs[/v2TD!nicѠ#3s̀څ )Evs_^AfTEF5iHgK|̀[ùԱqaix[psҧ@ k"EPB@k5e&KJ:Z VsoKbq&Y ϱYÇc%5G:@&7z98$=~wͧ @ Dz&;l'ض''źur^߁Fuw[|WU mh\*jndᘀogSoǩS~yW!gIc'VW՜}e] FVb>"j2VW+3AԴwv:nk>?tNQUxx}WuUs}*>?s}|_߮ixүgUU~->˵Wwvw*.nnn^^ː[vkA'Z-NUcrm8 T'돦-NUݷn(?{MCOnʗ 7YL˨%DAyE[$97z$" / m{suu#"N'Ri|ǿ!3(r$M2;J 2<d['{q;,vHF]j*"ikM,o.+$Is w;]5$@m3jT  bh9YƇ;q[Ql03~}hu m6"6"zaEbT?2^GCkctuK-/83a`Vhٵo, U7_W}_՚'4Y'{qHՍd5L3l| VjNvǃ7yGEkG^q.z*_ߍWӅJQ2^`'Mp1߿Bo?Ϣh [ORKQ5./#C rl2P&ϯ0A/cp^bGfv#08'R-嗂T3^6KXm8H#+aLc-+㡤z3~ݯj?=5w?/:0S)aV|@d)q{]szeqr4 v0+%ݭ*Xpi>;HK5Dui@6.R폅&sonM[&f7+[ <USsPas/x qz<3v,-|LqT:%bjBWQa7v{;%a~ns >Ҳr"%i\Qsn^& : eNtIw37󱽘 "Wh@9.%gжʕp!TCr)a']BD^%{3\HUu #:J˭d '2%  *0?J{3g/;l]l6^&,cvtNu$ 赜 n"~ywu{X>nw5yM\JPW;]Rvfs^}^nfn8v*My_hnw{ I}-qѨqD?ڑG@[3Yob^̶'}M.ҭ޻3` um,Y!m.qmzcgu3M˫YX<*jͥ\\`;46uPe L=kKZ+O7N ,̢c[7-W6,VN+L')>7.4zʴPo¿:s:.J?e3-W.yT۫;2BOƆ11 c7`{j@2 jrq(v*-;z8 |j><0Z׹5{kd"s'AGZa3!{䠥l>Xek IU[`\ `'Ĩ4N ._8bOxX~\0E @^WcuXV_M(^ÈJr`^sAb)K 3"ܨH tϿ# ]cZOCa2^ IK8@a͚$𿣻A~D> E F:SiPiwr*47 \5M@}x˨Y&V=2u~`p*еD ::Sn{ye:4OXESXlia;s6eI)SAD>=DׅW;xB/yᤀABI/Lmuqr{3m5?0gcIIJdZyT@ƐĆ40qf*rayN,3Cvs B`Y~͉ R",>a=`< i@Yf n6G4,%f9 ̾ښ" F*U|X؁ )H PdZdzqqЦo;j 37+%oc,"2,Nlad*}ms-Ubx^OY &KT$0#c"gՉ_E(g+| ~j܈L笥Qٸ8.t@@ {B(OpG0n{LqA%'MN8ԭV[SYyJpJCI$Ip(Vygok!iFASSB oЊrbIBa$rdZ@&0IH,&d)$&ӻK#!*,ڽm?{Sr?ȲnBT$<4\L0h]+#0I8hn/ Ǻnim=:rҪ_wSv^jI|K3 Go̢mkk,ln72$ ))f0fL_sE-$ݴ3jfH#V ! Jwr,5p!9B O w+]2zY_aQckNضBuV_JbÈb3Eu&NXjUrh-׿MH(6"n.$edJsEP})Jw6$+RDeյ8lrޞE5-wKfdQ]b~j܉N"0KN*v&KM7"[ pTʶpJ(ɘfi`FaALg 4\OhPӓ晲Ӵ@2ZAK̈́L: Kl}dVzvUDI|0 0(g` A<7t6)$)2GPzarF< +mj9+1?N@im/bmb2åq[yl*|5OSw/G@J@E= ͦC]2f s"P|YT+ qږQ*'~#xǝ y9ƣcޯ7{vȊ`5>E("fNb,e3(# ʸڀaZy!$Kl +@ ;\>mgF*`PY N7:ڇuҷ`3#S#<&C-גN [X@\"Ol|@c-{mݿ0֨m0f`}FJ#T2p㨯 @Z;BlQG%eI͖߼Jz@-?̧5DOV`" _/KUW "~c(t_Be$|gx{Z@kMXJ݆i|9]rzJ;CS0ٽwپqDv-q Xm}5?IyllyX^:ʷY+w-feIʊA^E*SdِC1Z,DjJ'­ٵ3`筎PW $9|樾QJi;tk f-A4Mgn9NGZq8_,~]X5l[VF75|Uu*6u X1rۈZ|w(pق|}Y&Ո]}!Dâtโrwߖ<6f)Jnwk%=BHK="~ y^IcP!igwi l9ۉ@:̝q /j_.Á]4vU Y 2  +rR5=ب$5k7ݥl/!ata̡C6T!1iZ[)g .z*b?€Hm;,cߺ:nY i!0t-ʌɔ7T?fHqx;mAM ka[d\mu짺Y_Ѐ8\"Y6V@9z &p.A}x C4}̩"B/X.dbsO[Q8&5P0Sk2 r*Ԣ #N[ }F/m\Zh\6ʸskFW@΍6KKP|6`tr &$ ,!sjnyPI{kK nXwt!8Rh,ͭQ@+A3m4`{/nE kLFZ}k BĉlZ"6SΪѲVݱ(mIȐыL3SyaNfgd#+FVyg.Smb)uj hϛPDzW UhquB e錄y]\ :d9lMgPKHİZ+V5bWA"r~$!آlR֍3oZf#:a%T"S %LNamUֹc'Z!kDOkiO:XmwA !UVnD3̲~ʫɛ9LOI7`&i˯{a<(<ʌ1cX߸qۍ2Ŏ|͚g* fb+' 6ASP5ΤEm&u En܏uG"IRkŮ5y^'kb;XVl|.͠V2tY$mʽݙ75AZ0O;ϔ-ِ *i;j?6#4\τnEխl, PQdS9<% X#n͜ 6< <_Pwf`biz[`8 3 2qS\ w.t Pb2' ,@tIxA0hן6lL gc_,galkwwڛB ̑;A9aTbA7iɉʄGbRD,el a\rC#bO@W5X|#5la͖װQl &@/AJ^ ȊBx%\P0)~Bg2dn@l;oe߸¯mPĽYW沬G k]s~#balC6{_l܃JcDU28ss [_z@ e[W] PW}ꥷ E Xoa@:;vVk ؎nsZi|Yb}YEE ys[M13eJH]࠳Ki3f9üY]c̳##w]F[.e]X8g;mxL͝ߛ æj72m7J,OUa7{~Xpk@7- .Qk뽽IVzxwAR]Z:IinE Qyz$ N*}MQ0>$#mZg;IID1I2tqia-AYZyX֔ $Kg3I3<:!EgDž'x.vЙ=dz`z^/ebcjwi^82C[yXrFϻme0_tm~& mg|yz|/k. y^w$ws>N&uPp+4~Ugnu.cMw[c]y.O);>wux[SxÉ\v= }ϟ8~Fi~w\Kg[yU\+[{˫nuWqZ.7_UyvW+t@  ꇿ 9d$]{,%S@ayagl5؛g$w@ |x}%zoyLZ/mL{ס=.?ٚ}cMqfGϏzmx[{zuo2LJs]h][=?{w7ˠ0.J00lk{,_}W'1j&Rc0z|soy o+p|CN{VgB%C8R&;YЀgf]*Ut 2]4Ϝ5۳~4<8/~q݅f[e5gI _'(meo]vxYmykf]+̬ϻ۫%wX`uvև=eP{Iр TΝuWti2cmS;ﯻwE 㝛ײw0 QW׺7gc(]}tuQ /z[=>F4޸X>gs׻zךz}窶ʰ!l4z_wy}mۣ+m;7>^흻QyMouroJ{mN{JT/`ӕs(gԮQ|twYAV\i;^k7JO=g+uy 6XCRyv]l"z4}Q]V49]ED= eٶwmi&*C6$f۶ 4`V&HBB ABQND-n( 'NWnwgܛGfwmCy)WoWK<+ﻯ|o8t)}}}y{r$3z wyx3Tx|ϻ{zR$z@_NHP`% TZ7B* z}_]/=744o]\{MlrqCsWѣ֙NAg|{|yum6kʼyb `3ƃVlSx9wkǧ{x{'ws}ײuXjgO=^;l-\`ȡ-զ}9{eۻeg\n$c=wl͚w;s襰tF얀@%l4P)RRT(HJpH@h4M4 dCA10 hji➙SS$Lh4i4LM #&h@h6SO@T3TI驽S'͔=&=F4S6S" 4ĘbdM5SbO"ex2(J<)=P)=AM4 = hPz=&mH'4@R"! LLz$SFҞSzz)iy4'm&ď)OP4ښ F=A&!4d#CFLL٪yMdG3Q=&A4h2h h=4OQyF ~4R(GY+vediO.56A~C@oK[:;oi414 E(1CH/89/vGC:6ihQ$ju`J֒+3h,&Ʃf-JhMRidѵEѱA `ƣ5)mFٚMh4P(x`-2J TFڳRF-VZlRQ&D@Sҍ PB R*(4( AHX|oJ!Y:\Ş 1_|vd{B=7|!t{d^|F|4X?ՒLA 4C0t/EUdzl"]G5u”#Qz C]nF6vUv{5)z)Te4F~q gXw{(AB9Uwt˱IXѐȂ`볕NVQUvIm)610~n/_A'*);!}#L"~Hn>GW+OS?KhYOS~NX,!H| u2L_&U g?L bioВ(u$o1 ŭ5d)UpW664Wܹ-r9|^NR[XLY8Օ ٜ`=;aIGŔKGCed'>Δ`gSW(6L:dLˌU}_|!y&xxs[=P |z_N9We&D {Ii 繱 U8E, ѩ53C?߻&󾩙Y0) _k^:F\jt2(,Y4@P@BA&D31MoQFCffg=Q:e) 4&[ $Hh4P)lTJPטfY+bUYa]_Q :%+ a,EX/^Wa]wQ;kPrrĖe2?`4HbjT7EwS?;6$;U,A`#_N9wSäEBq#FIH =嬸u)6QN'oB/upoH h&*P5@<.SeuqJn}w>_¢"t\P$( VKw hvAdcϗ~O{8'7Uן'={_NhR7fVbЅXvx$*8aĦ* mq\_Ff|mS`8tat}^v88,OF EF% OMfr, +wny|v3Fux0wv!Cy;F֩5T uY};W:p T*\-d1ûY-s'zCM @秀iUg fKBb{H*!۶.OSHgɾ@CCp\5{XS(~yR'C.Z6zZ*}D19uU!0lKY!!QJJ}P B6Տ];|tVnM1Ũd+5Zq9RX{AiC\-GW٫U+N\Z gs؝4pXq"Բ.d͢?[Qʴy *QCL O)ԇ%jT_lvwU\TZ2 dbm@wrH{xIy7<hh(d¡W3\X߶Fߟuv]DnQbT+IhfF-2NC(P NÉ7RITJ?_YA=ܐ8!5ђj4cclIPvm1/$JӃ(Vɥ9ɨI.Ol8Nsks8oxv3:CK!x٤*ʻnę?3hZ)iNS˞gݰpyq̶0{E C0&#%R2GKozpf|^w,ڼ#J~}~a ztNƸS$ȳ#{ok/#ݍggwv}co#vvx~(nOVWUo&fSjb-*Җr-}OyrDa$%_4kRZE6p8,I.2F jc5x֖ .nvZD֥y5[vIEL:'G\ٲZi,חz3D5@Z'2Mק+.s4I^Ư .=y8o3#uǽu yvJz$*ZHB8Y "J̳2D)I\IVBPVR]%.d-KHƖ#0jAmFU4-E)-M\\R(V4edJZg|J *"&Dť2@#sr.F1 d&rry]ݼЗ-EMJI38|'BX1AҨ42!b)b3I JY#eDU"\.Rz58 ?y"ˈI5_ TZ J5EEj5žWa?QoT!V%u39KxmznsŻ ]iu*rÉkyP.yRM\1%BIY bU['n:*U%`tL2HjGۿ(>უe]vw']sRTn匮Ai[anKm2]$FErVԍܷ#4'蜜3VeԌ ՖM cMC(DUw-8za`L!N'_ObimAbgU)KfVe>JoV*աXL"# b # ,'=%OsPIH_c|΂yYT)),߇7Lҙ0IF-˘]kK&uNgؿB,7|rSU9e&a/ 7*bCnj ,~kSIt\}|M4FƧ)4r]ɼnU1j!$ (RT2BH[B$Y $(\XAZ1VOPX4!68J7HA ~nڮwL h\1"[-YE Ue :a̭;ZhAjH)L'~YN6 -Ku܎UL)_>Vp2i#l#d`4oL(ZhX AIL(wP Vo:3E:8UFemR3Y6R͋c*eTlGm@)Dh@2eK@[ZI*HDtIF- "b2Ļ.[hIQB,KIB%3\(p1ou]FuE")l["D&$Xt/6-S[ NPƱ.U@I*IJ3XRܾAsPJe8 ՚ni#?BJЪnP@j^-&= I%9$"',A`޺PReCTTAm.Wkm4S9‡NAȄEa5XMhJ'SLgԣ[#ˑg ʒR% .vûк|^K ʢ\緽s!-ZbD&6@)$A6"TF*,u"w 0kV%VO~{Q* D{nѢU_-v7uuX.лHo,iCnF ĊKTBfK]11%%Zo1k۪|o.sco5,BXJST#t4-4ƋEn2*8q2B]ZR #2,%MYɊu&P&#rzjh%hjiT.'b̤V4KRzsL,Knɹ`"+QyUF[PâOۡ|ɲI5W0 !Hhq;M0Q0#J'd-!/(^5#%v"} #!oˣ8suEJ~5"S258vt]cxP:IJ UoBh% IJLF@!Q No4\%;:9L@$%`#̇\&I&'7{C[E)á7>Ͻhg`R:Vs9% CH9ť) 6Nk,Gomi-J)S#4QEF-_==#*R$N$dNs qC@x PDiS^^]QNVz=`MjNuIw6EP%>bx ՝ nBpi0<\iCkً?C>/ILJImfuGILRD6p̭"6*4m=ZUe&/iy6^nQbNފ(1_&&a ,N ٩IMf!놿Dp;PӷB{*SRnZR-mcIl&RTZcjI)tuN?`rEZBvt )PP$)S pvQ6#nPK`Pb_\>1ZEV! I{ºf{6s*) ZJQ$&u?ΰ_;~r^; P $HV?H@J?ڹng; 7} ޕ9D7!"V &%TNؽ4L(>~yZ"jxvnpRq  J)+CC^T̂35fqO*gW!=מ'=ԁd!fɐ9svlɭ`I,֧HW)6*<τF|5&@ uDq`VD9ljx]b@)(hD^M`ye D ݜlKΜnE࢓q&]ހgjHoCu5e=QkʬdR,XN^\ҽMdVXױH&Fm|D'r?L g\dqK%OtIm+K]9کCЊF9 [I 3dq'/M"*,7d;?f/pS4ХJNw{glS@.L %BE,lܛj5ч5( ' .5|*̈$* zZ,+^ zܖ a¼Y:u1yԈ@; D_s8P.j8vlqC|7\O'2PպiĨ:VnM*Lk zp]2_~U m [nYwcswFۅ\7уrv ^lUkBʈCҺw{r[={yW+r4&QUsѼyּBw[n]kvcJTh-JƉp5Ls^QwnOhXJPKB& [@ryQ6LQF@1spN]|Ma0>N²M*'C= s+fӑCP*IW{V~: Eҭݵ ƫIF JT/|M8935`n%6M@sE( V+QX@U)JK.DTfLi-ƭN2AdHErJH̖Dy*u:uj fW6 2b]ӑS$7d3uƂ4t1/e %h(L }Ǡj&.aZXP7ۻE10dS$nˇso7:8$]OdJ aW0[tiRFZT[ -Z)|ݩ2\ۺ}oa]9o+]3wD©U"5rDﶩhsB+Xq(!%ݫ87lnZ'E)O<Ѷ*BRW-*1 u@~$ ]יłOf[,_fagDzEWrR%F'wmp-;}+ƛLjXMabN=Wi$Ց7LUZ>iPei+`?j(;z/C|VγK\Os0qdv˅FbSJpIv̂vkMD5Ŗ8˕s֦Uiɟ '3g/dd9ԃsnnrfDϋjK-\{o2UJr%6鿋Au29p.E8t'gRxq1ߞaƣvrזk]!{5ҙ& ![W;2+6d tmDɪq;}wESQԝDjV *k<0{x1]Z/( F &sX֊*Ũ =֖`͟To՝w&BFBBiK.l Iu9˭0)hQr&4I$ɚs.dAgoⴔR*˻s^/KfgFʬ@}=ʆj>N/&jDTNj$ᶲ}幒UZk-'>]v* \W@ ,fz0W٥OMp#Oy¹D*g+ 9^BN {XR(D|nVIiwXZ:vӪor؅F XI4|8Nsp/Kss3?7ʣ]'rtC R` zAF,NL{ˊ5}3.5^@s(v|䕁>o,N,~@0 |gDL)#%Go.u|4:BFLNtGMj\EN,޵w.Fy+{~:ljeS,JbߟUT9T Ps7KN:Ifh_<~z~G EGy3DZB$z0E:2+y;.L)D  #Gx4 M-"Q4RPjL@E#w ![߭{x(1Vuvx'ٮp2%뮺aEdQ#$t]2I{B]rw^6G.[3Np%%c.s/vǗ,i])"K]tdWw\7sthr\]$לwnk!.$Wny=.׹ۧv=N빷B9Z"V3پdk\y}?߾[& _s d|0J<$Ʉe˄%eҭo}t2ZBя:i )))]]U*Bwr,1ZŸoCS4.TqLc;sq +[j{1 j)@1SYHpI v{?S{zhCi&=ϭ'1mU,t`f/8U)Eƹ/{~/Ԛ~uxǛB{yM:28|A?|M;|Zzޮ lˌuCݺÆ|,lPQlTZ,lkXj y(H Y}緡h|#* :$b*zt9պp :do~SV!Q `WLte^/=QQCSA}.|u<O9Ia5p(&n,C~5*3Sϛ^aN"2?EXIG?fm< &8JQtgћ~WnB:H'}D?Aec)jOY;]1h2~x,*S)gݶ2PbXyJw%gZ4yK&WVHļ Խ KꇂR䯃R*iS7W3pҭɾ^7*i@i-ò$ ߃-\fq ss'Ym̵y~nصƴmW"Thch(&mi*il0h*bk;\&fVMo_ŷI7-1Ք2_:˙T:f`CDAe瓃L3B_1%{aǥu !CbXg0KUm_ pz֋1a |y@>;RD\L@@sg ̋Wp Pݽ嗫jI>zT@Ivhj-?ٷA>h(j(TnmW6|E$F8ۈsx^FB"gL5УK,Z9Ev맙{װ1ƉUͷ׿WQP`Ě IXoOq`= ֌$br&=&- |AS2_Lz hhU`@ag2q^7{߮ !0zkA'|Xi3!iV&.0@y9SSּpKL-T0G 7vShsDXWD Z 9*b6ftsx;}83\|q;CC%2S 1& o\a\T|6O'CJ^{[u<>b=I2f!is::`6@_y}Z{}bw^mŶ?CH hj9L?πQ@i7bpb`I Η+S]ӈq!8˟2ȼq.P\Qz~#[XI s[ H!) - %7J沈!QN!UMMFH-繁n'Gj)6 +QSR`ULzzY ?aWen~+_-m-ws- &TTD$rԇ5#@܈@UX.vʈ8 5RR o3^ bݾ=O: V`)|MujFoL|.lQDio+IqII #/7dPIyur #8$V3y( ]XK2 6IUn#M`7ݟkt]٤׽5䌄)\6ƍ1wV%5_;']T4Ea'd9:T7VBTrbɄH~'jȤr#l:~ò ۥ 5,s;z1$ Q&tX{P^ޱ:GƳUAA[';xBA87M :vvb]3Rb OTklJBo-EZC, ѡ.qHd8(&q+s,?j/#iTq2I<.WF]ӭ%jB=-Gi1xܻ˂[3H:C/B6j c;ZVFiMg#/8;t7{q'<\9Ia [;Hwd-MA*(uF+4%8؞WhYH!sr9^tI4*3Ҷgw.aؽ:%;rlczCaә?=)$zßyf5VF}{ 1]Q XIEdigGFiDؕLj2۩pLiAh:UDx[ ?OO6MY miϰR$wzV,)Ji2OD Z2WM$PIq3&StAq(-1`~H5RSȻ;|@?RY#pߟk}sG;;=T5)uO)f_7BC*ݒHH$00M}yе^2|ߪF"wݚ=[e>/et%Fy(.ZR_y%NHE:'J4'=^A (R@.sr> ?;lz򭻒 ^$$,mv%>k?fZ_ 6MTb6F[d6߇ъ|f\Ҙ]h--YN&mY䮩L?5~,B?+|Qc*}sE % (vYtJc=?U27rlM!SQ*j,Jןwºk,c",gv{'ǜ¨AAVH@T8/֚fꐀycUQH-;kb^gM`rfu ,90rz&ƀ\4ORB|NK_uO㢴f]Ll٢9\*ąZ*@?^swDJm@X8{x!cpIBBvYW _>h%,Xty3U<GйItꘃ V^5e*J ˿(t A(';Gw`,bM.<ĜwȜh"46ϐ<5 M:+vpWnf YB%&WO *m4ZH$LFJ$X :A OvT',]#"q\&Kۍ. NP$ we$r>gׅl=.&w|İ2Hj2A`,,@9ZĢsHfS &C"Ly;)5Hn'Pr=9<>eIrbs*O5?OMVj?]y52֕2'؁ZPEVy]_R_5=HBUI" IB#eF$dA+XXb123dUI &A$}qt<Iѹl<;}͐bF]jX1Aѯvљ. /ݯz(JmYBc \1Z=מcHc|vw0tLh~tg̐US]f㸥(댡* OkoM_ M'I^bgvs0HWHȟDk˘u6stBP tgwP{ܔ^t뙎{\n1{hi4b5PVŶ( R c_m3g>nT7/I@ /saHPHU9iB Hɦ1/i{mFBJ(z0eEuy'>|>((jt鼾wRe=j!'߆xVEɠb\p! Ŀ@]Sk ܂ N_~/ʹvvquBѩlc5F,I\(Ka٣qJO$ 8>P=Ä# "& 16 DQ&ƾ|AA ?gj!`3 (Gyϼ*4-FSn@败P/O$(.Uy渓݈6W'vܩ,cAI9\%KF** sכi>6`PRxa4pv*mzW3E h܆ԭ +wtky6Uj7%![\5#[AV4nkh֯{ɯK {z07^puVJyxF?/_# !G{}W uUب yJ*HtܸJ J 5X*CMmE2N?rsܝ{ߚR15n^TfFyڕoI,&G}JbS:'h-am)HFuBJo.6(Z':نds=:xZ>: {8eK"ZE-88%΍6OM|A%O:—M*p&2,A a%<5Ѧ"~Y2VvM_YzUѷ.i%ɻ7- Ehħ(/W] A&]:7uLg9[d޴]V%""")A𫊪IL?+k#|Ǿt"<7ԫ/b1xO:B{FtrSQ,c҄FHπG凌0AhttY-N4҂$㤡lAEANYÍCp94ga|ϫ}hCr=SJ@10IKh);ЄJ9Xy,iJ\IۺZ@\ +0+O hAڤB b $y:)-]|;|Bə;k{=>y(<,ΊO-@OYUT~7>WL ( -DtU|'-5-)e2 PԐ-d\F2PcdVi LIxx\ubJ*F(ߔZ| \HUpʳo;A2sF7@h,OR_ONMe`픬X3E[+Oͥ۾L\++ѽc(jH%$}X.:/2sOlU` _ K/uoe+(A[JVc9=fF>)$=RkV6 g98Acy(6Bɒ;Bډ[E$)kubd_S6qC|w6]RiLF%Q=>bYe1fP j.T>5fY~K#+- h[qo$T˩h+ͻo'=ڣF[*1JDB:|_Xt6,F4s&}J/:[U~ ~TН?1U6N,A6hh#>4 dϭ۴+^n#LKe0XFL,y4˸A,6SJ2F]60?Fö@sgd]DZz_$)g9|cڊ,_IOMQ\܉Q(- Q=~n: 3\6%&2wmsI"%5TZ%}EK l!QGdV8wmzfmRK`W/_3 O P]w'"~ʉ'%O>EYzp~hÆ^rِnHV9`=+ݻpMUKA"t3)RH > hrg3TVLu[TE 92x3-ݫw_FVRN~'..d&ք9#P̤fN8yR\dC0)~u}37c? PS8jGkl@*s2qZ  IX5+Ƽ?m~ۈHjQRQvd t?x68d`N`=E ^x\t*TMdtAi^&)#4 dkT7xȊj8CmIA0o«s9p`gHA., .v:[ 5Mߍ{@!T"͸dwsM*^K1<u} Ӿ0}|U~]1k9BlR]d#5:" a L%ܳHQx{a~7?7FnF-jwh%RTe r6p(r9 .yܻ:I9\^H%+wvtsfwyC˺F [bnO;yúlML":`{t鋄qrut4;K1we317\p!f59dMo*ksEXڄE n]]ʔf.G{Pƣ*g5[$h j%5f'@J܇ (>PYcIEY|NN7j3:VF}3hsՊ*bxv4 oT[.{'c޹Sٌ. ?@MwhO583?)#!KP~9w ܠ~)#Nh7;6o*Ib?/F|`p^ fH 7a?ڹ ajU-P6߁ vܺ10boc_:=ZZE ,*3T7%G)K-U3!3P'oS%:YB\K4.qC֯i*a9!|lU1ryۗm%lcŜ]q->;n % ʽKeN9vbUA U|V=C_Sg/Kj4.QdY͜r35 z() ?#A mFU )0&иi|r̲_?Y}Xt: y]g*mC'Dxnb׵BPUyflk3e/SE\At_.2MR_/klƇ)wD,nTDun8PQk$DӍ/qSsV9EDv_|ŠA`O-h Dk}vߩc]q\A{!gMf ,zAqbzu "h?j1~BPT#>Xw}?X@Qj!$LjVK`&C6D򗻰}|yĀQ<!wiN@s|39n`fuXܓ$j⟹`J!ióB/?G×1!FL)łNcϹ NÇ EcvToןy3;Ycfd_S)Ix}vV!6>0ur7r=?z g#&i`Ґ?ÒH ɩTpXP)OH U ` xuVWv:w%L~5[WGˬuŴqa((v|~d_/f@UAi["^yo~`s\R9<,DG;A .}}'+bj|NB#ux8Q&*,2]#Tg] }_XOY֥D~R >j H< ~`9ʏ U0)V,x0sإ⪸!J:Vws}WN}604s3"ftZ@ Jzx[CK$ )*K_D:dָ310RH~!:`dqf@)0S8t?S3P &Ⅽy_0 yyD5,ʪ< ҉-봏FEAoï.xOjn,%vpdEvo)/~C>ϑ[msf|Rxvin|_gąc%G޴ )ahQ≃RCU_s//%LԦd7ƤnT}?Jo3[/D}񇬩Ob%\-D֍Qo20/eT!t7~ia?=\}S*ғ/−STۯx ˸P~ly݄g`b4 U*, [&5XheHʒr$Wn7?muQ¶2mOZ2Fx79yj er8{@@EZ*=[{.Bϊ\^rq4!-73R1gX}t‡F1 /"QFPyO2m]+jH-oYr"ASZ$*=ƲPP$}1 >K>|kyjnn@~6%W[ .qy3h;\H‹о7hK:*@k(~N[c0ٝ5-% % dP4E"@&ׯV^zG07{=mn/gत @6Pđ)&̖]PKI{oݮ[r_Xz]z1aʑLk3yDIP~oEEƢ%zac>˩S17|$ "lZƤ֣lVɵP% Pޱך^ZEEQR[bѶ6-bh5ܵZ1FmEj,c2-6Ƽ^VbkQEh6lbjj5 T66 6"En\DƋ \ֹŽUEb\ȭ\'jX'!uN~u6bI!"p1:FM~b:9Y(m UȬU>8ح!aʹy?+&}Lkag#w5r-x@5TWZe4i4UkQF>T~ƋF'od,@kׅ ( Wg}8IBn%ʜEjǔGE:V}߹)~ ~MDt~D)M]2зUYSm杧>-RF՘/3(;?5֘SO1edFV_Jp% 4F"K./K*rB#ϐ7}熟Q".+U喣C䊑?K z9USxM+Kr_K̍QD%?mlRt*ex'2q\7>Bf/25Wzj Щš47!GDF+U~{l5iR:䚖…}3!Yj,37:BYk\z @]*IA@ hq2'N~k yĐ;} R=8;Q+ ^R4ĪjIR |`]խD(Xok NUA"$oG֤~ڱ |>e,"Lb}ܨ/ϭ\}ηoZ RD3}g (M3xO,pTy:oɧT!" kbtLHHYw!#G\ !\AV ,m̙H}~QFZ״ &o$H-vS%+1"!k Λ4a$B{R-uAݞZ6M `+~RO_ť!'Q$ZIR~'zaa`: hDT8bˡYؔ`EuD7%8?kwMHr֚Xuea9CJkEdz5|3;[:*IRB) |kDd)tV/e@_R=6nV6wFVrP)MUa q5Y*?BB[Qs]vnk)6 T \T!Pe҂/iut7'ih@ lCqCvٮ$eh"4qB b~;98,޴A6Cu`$W;o_!D>>ß+YB/(Sm\h|Y`.`n?gY" g˓?EOQzJU^?`i+y_?0GY;@X=)5`XqIum"nQ9Hos?8bH-Ռ,3a%/) /imI @H%YL[i In0]n?|~r2U \8jeil 'TTU@au':r!!UǬP;A't j)*.};qg|9ȨbE_/?2vys?YT0 ~T>L'{ et.0.5 4G IT$Bw 5T.*{mF=)Dz*,ϿR ^jQS1p4RϸTSyF府7*Zbyc"p3p+HB5l+"6y,*omGcЪب^RwVCWnUX2h;|ۯĹ6_P_Ih`N#Ve ƪPPon7'ۀCT9!l"*}' P}=aVI2 鏇> 81`1r0`+V["ʿ3#!6$xs7@Ԩ, l:G ?4t~Vݻ-٥ic ZQ ˝{jBh=J*:fl>B+OagpW . uPDDeϜVgZyv(o)yʽ~[Mj%/00BH,l/_:΃[)Ƴ,-sNTtan$NVgDn/Ӳ~AQA'`V0) mAiOTA+d<'~km^egkV붵]]Oz$+D_xHeG3<x.Cſ Tk PQao:/Bs1X{A0N[y>Kf#Os&,D-ǯR8#A{^Uس186R!>Lɳ( OTSTR@PJʬ2T5(^phf(1TST=QOl{~Ny8 y'W%аJC+v?SzCzo.pz>9jaԙa­n7bYG/hJn9孂S ATa&.٭_.>G:j3:+&m PeΫd:w)e8yf؂{LfhucD,?-IS8a6FdyF"ШP4U; |+/$1Ȧ0)RsO*H(AH&R, *v;E3Q3wӴ<-~% CPBR ω_MF-/~[K} 28T^@v3K*o|4yO6AwWztև1WgvpC(g1JRs/тTNC#h`?. c@OOT 1{ˋR\[WR$YvA܉)DtqwfC=o4*((A 8(}m2=o{:vik(o`<'ݲ2/0P.P ί/sŽW0̧n,J) f>ligW BAwh ߐ'yjRPI. UtcgK?tr:u۳ӱUc~..ڨT#4zH ֖ KԬ|q>zpQ%;U( z¿nO]I!:|X8OmRWx(1%EZ@ @ 7H~b C\Np? x?,oU?_~T~WW9XHa#{mW+}$/܈BY (*|Rj Gq{/qz~ >򹟱=_X~ .w P9%TC/$'|7D|u9@!CCo`dBSi!^:b?X+W }^ T"P̆ :[ L3$d "{#ʍBP/C7*qJ+ڧEa1<+%~1مD\':eu URpgOYl?~ imeЀ6fOg;}  :%3ѓ%Գ%<J2U2/k/?:" b vY p߅!Ox]#Qfe `t3:Sݪ.$TS tTR4_MviL V_&JMP\쟝?` 'հGh$ʐFƖ@LQN1g;AjyHzE,<ݝ*۶/ XܻNyI ds}w)}  ?& ^]*[jcxu" P`VQZ g[Zg׃#((*X1g 9S}B9mx~w^]}?wS}?iSK;"ז/cO`2@<2}ݟj~Pv70}QY'Oʍ?(΃ݞnlO j:y_ŷ:--z푱QSRY jj_5;䈍]^nN|G594;e+kqU)h0hHQ| wUA! 8[J@w*0}@O0cDQ EN8 k@$R*׏=Ebq9'޴^ *@jxCcu^*:TV考쏘Z!dmݏn@H% D4V?-TTBmY>s14g&QK2Y}9'yX/~1f+UŒAN];x F.;v}*7@X g&yӏ`rY[D~fZE)Va ߄!DzHm2HP츛#Xل~9|qؾF~KT zKºҿ-_!| _!ø@e z9 ~U͹NƶZRH$%1*HuTT$XtƞNΘm+.\)c 9h}??NJ|N0z!1c[L½Ʉ0 2WEqH0T /7gzE.R*6YT6dPO㬮1>W(iRǑUA*K[4|(a{ COYOJ7*vB _$0+KΣǏ::VE 2>i6tu)X- }؇izJ(~0ۗ9y+CW&¢(!yd#SOѪo&%ymsm_gbߨ/ò3扴j{u_$;z!:q@&BJ)#_Rs,>@ǠwQ|_y%'24ew͊4o(ws3`<R}NWx '31Re%Byݯ |lS4_͜䫎6($~ʊsڔT-,*?p|@X v̿$(MLeWh=tg5L<-( Ǣ)?_Mb1bo_(iNL״:}OլHp@,aEE y.Q^)YEg\< ݒs `/KJe0<>:/?|fIu##JߗXlw(_$z5쁓)>^J'LO!{]Ԏ>rX+ӆ7`'eW6~ƫE_ɀZ@c$=^_trBf?.Ҽ56z?`L{[uz/*͋s_Y4G~[t*"ƷkRei=*~+,Ah?YmIs"5#lLWnXEiߣ*QhP(«3-4G27k! #(AIJ1 TDkO17* 12CRh }]D.w~H"k#-Ⱥ _SԥIC*i9ps>m JjJnJ|9H ~2'w*h92Q8{:@ʫl7"%0{!#f" §<]©4kR*1_j$/)mT BCصd(HS#$@3bKuG+p"JIOaWꪀH$Q(wa\?eD%=O51-0 `H\eU2W=RQҚ7M)\* %RT'g\zw#:_zǪ5V ʯB %۽l'Iu\_ɒȋ_{:n![vAݬop[P&HiD).J2#a韡4Be}7['?bCÈbGp[WzU:u<,,o~}9Ņ1^Ovw.}Ef_4g#?>cC JE,ig|)῱ٔZqqc)no' [ AӲi ٷ}`Yx1Xxx_70Yv+_@mA.G=(:'% a1pm SBHskTEփ'=ekFki-%? gԴG^] V̌b,w5fYXTOUڔ ׅ_`Pv>`{0Vm4 {B6L?NZxKW5DsykYM ܸɀ(P,h7gY5S!^rÓ 6Ed1;((߁w1%d̽:vW}z>)uomT@"-N'8 dGm@uX*ԕ~r6EH_5^ubwJUyXjj;ÅO:RNsuyM6{^<fWآ?B.^{E9A|I3'$G S.}U Obgµ4a\&P/?%Q]L#j솰a}+TPJ'Yy7ȑ1\=n LUuMbZKbs9iB~Nr/=3rJ a!^GdC#*Ө}@߾Y^6; cD{6tfN:,@|0Sa7WFZ7QX19C9Ou #zuڪb@MAyՙ TiylccHqS@p0c+RJŭ͞ /{Kʏ-sKOLlWC#qT~'mhi$>Ds$e^?mӤ GˍYI]5k;9L HDfYC PCHx<-]U,ЎRT?k)B}j-@G|%W)%W~&a9S1erjP NTA:W=fVTlTMT6O`{nmi˳"gU)^5VtbK7 Y7a]͆IAT. 0QEW뇧֩q,m u`~#~>pFUB5}|UZN%{>63Bha-QYKE@#{X d;NS'̬Idi>ٗ>2n"ؕdpy YW¤ @+4<#iW`ݲ9=I@ZX^aug@ڥ}DnwT'~0Ϳ@dw>w^j*}.=evfBPzZ#0ײTv ΘFϳرṘOW8Ѡ92κ*VfB{,@1H1&GJeB W&N͜~#Ge<+7,jj2:קP=߲!X)Gٕk"0[qaH]iW:%ls?C8j3;dwYL/?S.W(|~QLQD=Gh76vBp n#[?9vAs6|o;`YuAFj>ji(="CDǿ?7 lI1wU $4ܿGH6x+R7}Q:r&]6}E"őHsxoeq0aV1.$zEP^Q}Ÿ~<~Gc/r+zŵ,%nq{eT4AK@ 8'߂ +QXȭs#-W1 =ZOᮚ_cjkL:Rϭ ͅ`I%U1z(nq1(`_ 9%Cr7=?BT?N(}Dʦ~"_(IQ z1Aπmpsiky<A=~J2<[u6T! gX>^~7n鮘כ"*%B(xO6 )\D^Ub8h&kR/+Vj>|9.|T^WT@\G'/x0bQ}~e߸_]g#5KG}xs`G#6<@[_o4nFR?f.Ӄsxy"n5uo[e@_[=ԟ@U±V`^9-.' A˰envEl<`L!*$jpM1}k8"Vk7I\6]Ҵ5Kx}\`GS:15?bt y.=Y'$!H/p Czϭ }kۺh?Qk[ O!N:ŧ,Guxխ]-z3JXnQ<-'4i11r.9Es |o\.俑#nS[3(.sHL:UnH RhyBVd$G/:R' `}ԉU$:<*O/#v@WV )Hy@5f6ڽ C8ؿ͂<.j!j`54Y>EP)e̒JKg3LoB$bgq3{ĉ㊯U{1 O y;}?CL[_4n&?kyRʿ.ZXZw;J{>ԁLvR>XdbPW{~,~wyx(Eʗ玑|?/*/3J ]E8e"Q-O[~P}DkH)b&sus> i|cˡX:\e>E'& 0&W½8T/FύTm%ovrx]R]wŚ_C8T QR5+H֣[sd~e4(u-!}q\!+D,]4ݳtpُ7;{`$ke@yٮ!}\ف*i>ΣFCڭ$\aJ9J_l;n6hYv͗gsfE_M#?sN9TaM:fϏf7d>dkwLP:S)Ī||_qd6 f+,LG 2>MVksSMS2NMSN(bUY؁8 SԦۥr1Q')[zU|>?:}h>`NC?$ӒU85:2 IJhF^#6ȂMyt-MKli0m*fRUdm19\N)^Jn|g)'/}ޏlzZaHPCƾÂ\ϵK]~?]A@TD+EBݰKk[>$H%5,4Z؏!~I)>םZRvGDW6_֨A%N CQ   wB7SU>[ns`طM9= D'qXH#yi_-$a-Ʃ?w쵶]Y0*UufRCBQe켗exk~&g5˓Oeg:k9o.r/D㲣n[!ޔf.wG݆ مS@pK $NH~ߡP m2i;s79+?mKLByL}slE ?bToy %TiSsGv;2^ԚԣD"=20I3_/_-a/Wo2AglG>=rU +zd x6֧WG$row-9{,MZRMLy=׿iQԟkK(y=[^^:[MVR=,1l<3v3?< F;iOi;@oس?Dz BXs|?+gt$S]hܔ!}xhx<=Vmƪ 糫䶦Y13Yc^M E|̲-Lo%OO=mj[ٽi-"}Пҵy`gKp.>:"~"x0Xs䅮L>@=S#po2F2uD^3m J *=0G?~)O tq U.hkehb,n".vG(䌇-nՅ? u` fcj6 %eOvVbЂ%/ ƌwZ1##R`lӪASU$ C9f՚ .}w7nd |,ժUP$#E+q̎1{=tĕIﻖt8`K`X>+n˖}^"Bj~2@>=n=cf s-7?+-&鯇lzr Pb1D<ds7y>s /'{>aYEy)ft%6z+ Dc7~ZO4/?;fi4瀶cjt&JjQ`Hx#KwL/8^^Lm.αASkM% YS-0:ԟ,궭,֓/0$uuVԜSt3E^68kz [gy8 RH$!rdN*4_ƈUlh /f1zx-H \p sC*sB^7Jy&<?^~hpW >CSL }MY y@.跀˴a"d ^ceX0vY{i~_2&F\=ʺl 7"'5B ۚb #ՇǃI}_?,j"rclb1YR6eľK:e;5 @;v[P ]Oa ?}ECA63LH#HaZOUd*|;3W\%dc:k(~曹0PM\KgIߝW÷Yd\"qD"[Q#E "DV=w+3edV%I:#1Ta!Uչz_6t[D̊Ikz^X ?wrX?|Am B Eb0 }ͩo<*VtU=:~*_)0gx~Mzt֛G|ux򟋋5![PZY}_P7d/5CԕEO], df?ϻr/W͍XwӁ|i⪝e4撓ui˧rꗸL.~'Tկ3~_?Bf{ X@eaO܌='CWr9h>cU6÷Vw=J/'2QHtN Mi4LPNq3j= Q5:xZ#iί@_muC5v\!inzsJ83pşUfK|T*|WsFUAil #=,VXexP/`k_ԾnVzWewt=D '4/qe2|H%=֨ߩnھL|$|5HyC0V[ο[G:A]NQڼ;݉,ݟj7wdݭ ֘@T#w=enWUDpVdi~*>lzkDFcջ}#9Hw쟓.!jS7F]+t6j8Jzb_}Zb@9.㻎G/NVD]hClHgu+9ykTOVop Yثzg U0}1DNo>[`lY?*OIohrUQXqmx #,@ihZE8LQHwυ38`.̮{0_"p;IzϾ ,>oKc_7?>^VP{S_4Q .`"Σ-?3j"~+41b潆sZ&˵bZ43 [n|of[?k먑"Yo\Tw7bי4=W[ xgq9"_dYb{/60!'v%_v6oR{TjVKJ\K&}7"JMB*0HC`hqsa, 8=F x.mX<}FAnR1na9VvO˄X\ :n߳9z'K(ij=@' S>F~QRv#U.[DB2 Tv(74H+G#FсPG7cg9xjӿO \.x;P~R;Ҳ46,+:TEAO'B/IP7F a^[d2Ded27"VD\%WN7FHQM$@b@8հXI'( lݚě$7BAmPɅGs喎btL5(GdPS?YQ7J H:h.kEQX@9N)!PMI2#z0A&o j,DES͢; :oj_" 4nu#*bL12z2멛r^ri&l[XaDZGu fN -(Cu_eE1BIJBbo65E89* P?sIȂ# q LQ-iklm&8n)Ntr.\ U95(9laA҄IλL$ CվcB:AJ4ڬ{73rouלwu>pe -s*6-QC\z0c$?Fv nd$@QWeQ(AZY-,TMjV` JTJ)@B`ZPk[ґ1 -Zei#hѴC6LEB#+L$fXJP"[[[SEZ5L6X -ƋQj+cZQX&رJƭ*ڊ؍D2V4E E!Fƹ*R  4*5BYZTؒ +U֨܋E3F$E5&jk$* #@AؔTVTADERU_}яQ[UZS$E=ZMwL> O=yYoT; g9G{36e2zOQT&RЧCO\c8kxyx$qvՑM4q?_6|IN^U, apQ(ZiHD SlpIwB+ ɔY F7a.|ˬikFV"oQ)1s}hLX~g*],^[F3sJm5t|k4ETDQ86* (B.{=wTE .B Q-zUM$"ET%ۙajI%U#E(hhJCwӚ"hJ ar(ssQFZ\ܨQ[h1Ң4?(]\7xvF7Bo.cGxvs^EtSqa%+ bKUW;F\k)6η@ ɓ]DT@##ޭWB-9$˸g\Q+ݷs7vT1s2֜5ZMd:"{ cu/ý7i?iuPJ4a;v)D^8I~( V Aɇ |P4 }}*C5Y(jkQtzˈC(R=-Mz^ B섊>#]52PeJd*#ef!S-w֌JwlĜ1GEӃlpEu#0I{ŭ=_8Z֟}崋'"[^+po~aR-TQq]5 Z2Vh3UͿIRANpoSe{mQ#hZBɍV4crPr\9awv^cI" aFPY^iE8^dHv#[TS4n_y_JdO@AE }\c` 9{C?i AUb='b$|/ M@Ms3ۢĄyPk/_ޒ?mI) xXSRY#@C7X V]H+)IBK\5 ٛlmAbk$Zш#smrOٗ-5d`aTDI'& ]N-r0 5; rRzujYmTE>o[]=sP/!'i4p|Sg$Y)KwoJYz།LnqVee;H%twj&^s6LB2ڇJw4I;Zکn }&8FH!O؆ۻ.]ͻ^{ƻCHc+(.q3$]y{ony%5,r}}?c|ogLXWJZiAhD[F6VUQmED!\'~>Wz1xdOKE"`BT]%پJ=~aWY)vuKPVRA]SUv J[j B'DFYjSΙY,?i( Tz+Wznw{, XQZ7n%ϩHvZ:?%j bYJ9__NA>)8siIT- T-5V6FlblZ6TkE}4by׳76<= [G9kR]F>j1P5H8ze%FBy$y&.F8|j~^xN)$`T؂*TWc3)O;\kYGU2tGHT%XW@… k`-J>=|8 8v( j/QBա(T ''O++^5sPK\؅  7$_Q.2Ԭ J!^_,bw5QJLS-gv 6%DjEThMaWmb|R=y'a;qܜQ8쟘uF8"EmP9Xr+KWwХ?FxvۇgUȰ)!p1.$bFl+S.2prMף? Uxn*!|Ml7'wHZ셦hi ?]DT> v^9ʲ)v̽jy-kzӴ*M ~%Nd~6T,O'PK|1 ~o䑯یErG0YokE5rۑ8H[߳32BX.>, B i>ĞN YpYNϬqAߘeP'T`ga? _~/4}-5eH 3ԡfxؗMOK^6Iǭ,y]_= |`y} = 7d7ĀLR:Ogĵ̸%{8m;6ϱPut:yB%ff)k##ޏ",/Z (k#ճ|DirYyYa9:gH&lUA_j̩%y=3wpޛfW/)ZS(neX&r tŚ.j1%Ym4X-պvsU5AC~;=TVew+;.p2v$g1"ƘECma@?R 4BJ.=4x\@jI.VZ:7nZjQYLzF&"hv-M̦)@JP8(f-_>bnFo{WsJITTPHUƩJˢ *@QZ]^zQiR"JZWWw4gnW;*)rB2VT.D#~g1b)X zѻ?IdQDB=ֵCFSڇ?g*o'Wj|uuSl0n8}=%M H5a* -&_'~:YjӐ:ݸ߇5u''J<|wO2> ijc7ܽu(m޽c֓ʐ$7BI#Yy nZzô=Kz4_6V7} Vi_J߲Y0ЭhW؋O>mI?ZjC|c[lviDdוc]f 9eEJw੬o<::][?3Gx[+c4{B..Hygocr_߅!h!iGًRة[:/}FtDv~EVRog-Gwt&:QıeQp_7.mK/T;/|{qwkj&;g~ {o#n5_ uY--Uf}-jK PFqv݄4YCGxJ 칕674A_bZݿҞK5kz;w5䭡?oӧ/{۱ GփS$g܎s9ܚH%=UO&#W\r_KpF3ZS *C7ds3 Q W|vQW!LU ${vGϙ0)PgNpu:7RH@K ۜ74mW?s5 Is_ 1UdT˸d,&;,c} 1I  PLӶ0g8;7S'9<ڏ(1E/L@ʞGDxTS?E}8P^'d0EQID5DП{8E-Ƥvu<9&xkсj'jv]VMS 9$P1bIVD0& Ԕ4iJҬ؊( +G:apd-DEG| 1"FfRV&/v)D -J1*I Gw#I@,{l\P>R>m9*cs#!a $S@+>}t5ُTASIIoMZe54HsSqt5}5)qD<1 h ^A r!5G "QC,HҺ2@0j!3%ZIZeB~&-,&Mi<+8 eT򘡰d۷X"Üy|1 1FJJ<2pó9cȖj+#FŞW|e9ߛQ+7kЁ):J?O*ס[S>@I7@8mHuϿT p3@YiSCwtBR L7Uyw^A Hk{'Ë_;2hNuu }?lѫ棜 0?ܞ܏eX|{K̢!dw]?+2q8o;p}D:nCX24w8 5"deEe[m"0Huwaa1v_~G)-x7_;,~ʱr6Ez_,zZe>yZgsc~As޴75+Ey+5u{MZ1WSd}ZoE>bd(cuVb҃Mom7?3'`֮Ɗ:K` v?g+9ǝmvx(۝?>?eҖ:t.q:@_F.;G^_Ȣ.8뎜r\VO_Yqr >O^7<ϑM-WKj/k\bK^(4/(b[S9=>݃FC|w[h*]rirz|i̿cbZҏaOcjlץ6|;׵%6b6>ߛ'rKw؃&yW;>V?64pc@FЈ`oac<@b4/OZ8fbב ][FwJUR {_a(D \ڍ4y,W~e|y>#[>$J9QmqYermTT(Dx!(n4Z֬+Z` H1m @76P ?}ݴVPy\Z(Q;ATtUHRkp/db}yw?g"Kևz ~'2Wyt/@Q00G9~#k9Q^<+&-D"eFiAF3Xj5(5YoaG?{3l`Q `qqQQNص%\r>\@45>dr{Wccg:q7A׽,'][&0+ ɐ0&Ѥ'snIܖOr$% %AU9tl/=?ϱ5a^1Dv ^5Ӈ\> ŗ m~x|/=Wʚ"w?ޚ$c$P/yCߓs/fE !@ TДPwm#ȓ vfv+G`|R\ ';uE?&Wl2?yHQ4  hFI.naƒAe6 ͎*yI hDf (seݣZ23]#V(|8 $L 5(a"2R$UCͿl(|Q|mb6 KK,N|ywZd2Fݕ淚(R,-NJZ#[JW 6j`!@SDXz?DDx$B 9QP<̽{{y%DM)-?{05b;#D+5x`tTx 8^ӫT8`d㑉l8o2y],ɽV N* LJ24Px4f#() &ïE,M udryzNj곹c(z~"hQJ2(6"H`I#ɍvv&{uwqwrizyDƌi"3Fm|yڵ84#i@QgbN+9˵-fcK ֻ\8P,9R@$ZŸ;UPE]ʻmPV jТ˫_Ck_k??W쪏ScE`/9$l 恊 ls6&1{9}Bz4@JFC=y=nbνNF#˿!ǗYUL4xT"! Iѿe[Gs'ES'_=(g>#|\|xLMJaS9bδXkdդ5!oV '_$ۨDŽk=ksAOkD{+"S{ݏ˒n`DD,ÚH7}>ϣ8<8P "w><|=Sy):A aUu)c'ݞB0oly뫫ǽ;}墊JJgqVۊ-%lR wa-+~0efx<@-`v2$q.C(0J=0~3;>~tԤVTksoDywddO7tUW+6No~w5!庾|ۿ7/3><2a  g_Ẽ56%:BP#bk00;r1uH܋FiG|섃R[5p/=o?EQb|(4=UY553Z;tQM~'A{ [#Y\ue7M L, it!++$a> 6_U78bP%XtD(H]Z,s2-W>t#]H4ҿ&(g՛%L[Ae6\\9@Lqp~g=Ᏻ?lP^EIZc=4TbWiQMq^u@ݦJQs\)ȕJX3] z>69=| HrİDNeTη14{lBzH%{ņOs$`bjrj}Bb]xTr . H z<~DA!`rZY0o]6 qζ"%0@ V+ti_5)گ-q<{n%Cn<`NioM2ϱ 4+ݴ,^-x>$b,kz`~F7ٶq]e΍)ˍz/V%dݔ [tislɐ4;VWeX: 4M(m35URU] QmqE}* i#ӍΆh( (޺֠eM[Gu|dħq }hJ8˅62Q7jݛhY8ܒl#=z,-.p8ĐMoτJ)`ze8ܒ]<= 0v6=KQV,|)Kx^܉f8 urIMWZfA T{e`q}VvL€.GY;.-9C֯'ikz]p1QHyYR؞ Q/2JCIo.Z XUR ,T8o㴈'!QЍ, Cg?_Z܈1X"Dba+iZhZ u" V,WO.;uB"cp&H}*S.7nS5̰BB3ma*{?%PĐrS%xZ*[}aRՄ iNz=V!VԙDGwWV>ٷ5NcՎ'&ٸEjֆ ygQL< A[.L*HLHF, Wgjp~!)WΝX+tcIo6тPv6;EhO'tQT<ɳ 2Hw.Vg2}*[AE Z Hü0-p/r+l3!4@c@wos\ {[GlB${)00O w_gbJCt u'cNFik{DTQ,ɦi!,LFhaUh#2v 1ffÜz Ba%R!UDa<1(E`Q+1j]E/;F8Q_ΉS LO F 3@(nlױپՅ?%PR Je!7ýӤ{|&rlZ5qPqiWR3QKRb!_W ٴ|-J`ezx[(:2 !(UboQY"A4 ה/~&mus;݉09oϢ#h%~|ݫZE"jckj= wdrr ۨˎT~1V@ns5_qhEҏbaohZǣt||5A}0uG 9\;os\)vxϻm=ţDZ>,AQY~Z43 BEurp/zZYgԛ, Q(S]8Ѵͷ6Zjw5'߭'qo| |Ow|+%mk[ɧj<_,E{a_N=BW\|Z3m?:ޒ+yIq@x^ &Qf;*^@EpVې5?l IpGwUru#G=xIG#cG~N_OT86aɅwfvXmgsznZ 8nq3Xm}&AhA9s3VhzIeEBAUƈǔF{M{p.R0=Wz .Ybڞo, 0mX2$8K\ւҀO[ktUq4 plLQ~D&B SQC e) "HSHj\R_V5SwVHz4kz6{nyzi E<]HHUuDH2;M?9xZ":ku|9w7,}EX?/akڙÖF={~#d~St|lf[SX?NŞ˘;ZWՍ]#`& ҕ{@z UBl~ͪgK@KFy=+jKcv'uuV&PD|MXz .w^s[$ץě&vrͭuEN9(8M%ǡ1'p[oScB26ָSF^MStmNNH 1mWRPjeevA^ȹ47Lj:+׵cS8]0Vh*842:*v-Wd)ᦜ:|+pvbSWEb6jp&:z5<-h@G2ђiT OQ-RGy{gʚ+vYѱ([XOS1veB.ڃL39gsQ:4wggT=7\'c{躆y4O/43+luTiqF[ܳU>#U1kv57.ŏy+=H~y?j}}3+8);&i? \ԍl8G ̞Cﰯ,+1ŴgTS>?(ŠgL8Gϗ6@T!5bʵҨ"JL$QFmHBdj6MPFԌD0ږ-%bM&Ơ0-if̰Jf l$M ђm-%%b"Y1Yʼn!eM(Yf)5"bD&bCL2vdX;jt(nںX]c֓seMOw4[)d/ǵnaxʌkEEllY(60D\ݔwgz뻫-AS#I%5IcX1v컢k;lٱ)DTI$i$X"PLYDH31%4I"RAc]ӷ0h0{극 C=۷u5 5zY0wk&Pj9!pw25Kw%ܚi/zL:u%c$YJ'uE;&Gg!]{+f9;Ҥݮ1J [Y5Fd6+[XG[ č"%P4W%Ioviɣ@rDJ0G3 1Xp0 )#J56a0h#Mf)0KIez*I4ͩIm .RJPE &I4o]vȅ$:wLQ s93H|'u]I^Xѓ2bJR5A\x{ˊSkdE)F:ͨ/^hB}lݧKtt刻[.kҹFHDV6HZ*tuܣߒ^&"5F;l͚J*6Тb<$afHj I{mQPbZ5ikZHY5W-RM ]Z4A@Pѹ(h4ARM!"s! "őFɰ)YuDCo+obŢ(j1WQ`Ţ6 $SKnui*(صIi a,(J%L2Dؕ5(!DвN\aL1Ĕh.tnnjuڒӭxIRCIiS#!$ Lf}6JHhlو0a*,]*wnVQADRMlR4hKvݒF, UV-,RFC(5"i 3" 4#kXFՊRLU )@I5FE‰ Bb#E22P&o]6wq,DjeBeʙ#f]4D) jK ˜hjf()(_KPk&K M  Z2(U#TFI d5  ntQFZhMbIHbH}5ͪ65l#|Ui,F}v [(i=qkۧn "6Б%-4: -Ԥ>]=Fʩ$JdKwrŔi=TM B*MTUEXcIW|-q[vZ$č#"^oVyݾwLJcN5fW;Z [19_oM E9u*Z0`٪DfDe"9۱=*j(nSa;mּۚYK+ww;itܘr|tUF넣lM)#bi4k$[BHFhLj-%EL$"HbѶFWܨsfF9.od1%P% r 5JBkt+.![9N ƝSn:3~ҷ-j6(,`ئHzT*YfBS7^FWtiIlh-QQVi$"ѣHXQ 'ʟ;ק.pP[ik6ݪhIZH2`RT$2aI H($c)(ɉ$#b#C ҋ)3 $,Xf`P E"4h(! dȐI0b`$diE1iL¢)D6%$fJ$-d-(Q2K=כ* d" (MMD)anE0s Ip Bk1Jҳ4]yyzia7>+m#EB 5[&5Q[Ń%h]v`D\}}{lIF$}uޠ&ONZ]BܓI4XXBִBANWՉw%*Z䒋AF J7uhsگnwwBzֽ=9ڙjJU٣Q%wJ,5"+W LfH]ڻ]nz ]fHu뱆ƆKP)*dzuh#j 4mLRn\2uB$Al̬+cssCԽFuK}u!3FFRdEKJeJzO=v(-IBM,(;u;Y$ViP7]uP 6+^¦k滪M,G |Yu2l1)9rM2 HanLZjAidk[܀PY *>pL&s>+ 퉐M0-2^%>]׾wFwMMٲ r(wr:m|mYvW.DSr/.R)OIi}wfdt%M->P/:b{zIsf##Ds ԳV6fnQ$@W7)IQHf6PTXJgG*%!P^ut9&LUksAR1DhŚbM 4 9KƇ$B &Ȗ*iD)1 0cf͌fQbحaSQJJI&Je)Qd$mbуD*Qd(F#Zٕخ[(lmȐ؊,+bok55-ELW Ǘ1#6']0Cff 8 2ЉYFƾ]Nz"VX՘"CY6ųM m4TY-n q͉MHibduȑ1-I7ۻNҵ3,&3i4l($*Sf&>12F*&JLlI! RaE klZ>nZlFR4ئ40BM 'Z׻#1DͥCr{QdҼw]˔֎w]0T1 P9&J(|_=B1I|̌vI0{WMK, 4T4k"!#fB}OJIzq(ooD@!mlE  XD89U89'5jM7xAs l;1  3U1izSJ8qL31 W5]&2`cQ(H(@(2"aFXJI8.&$bG`41Lp)McFBf oX'с4a D)' 6'  :yw|er9[mM^jwY.]muW5bnOǸ}jP_p? oP8C QAFAI"RZ@ BP f"{:qEiAҀU"PI)TURR(F%e! P E`jJi@DAe$(WRM2J JBK"LTUmJ[XJSR@H (DK 4 ( 2r`4@&B BjPEh)PYeBP@iAB ҅k1)K[4S@bBZQdeM"4!2 "*CPS@2 2E@,2*VijViT!U@bh)bQmblV h߯?65O؊S0jĄ$qǙLꢈ\@سRic gǁ\lO<Xi*P=JN7χ!D)GuZ)h^j<_jV2MJ%qANo-hUJ,"Gm(9W'=dz1bzl) 8v9خ'?ƵV%V#AZ1vWyo]ۏMR_Gf>GRgSكz$rs֭Hm7>+q;į:2>WY3qd&Eqtʚe1XLX&ʻXg^"D>BŌn9[6+QLyD>#7kJĂSX$0yLbǯ.8Wq{ثX|jƙ{r˔燈g@@ӌfүPR!kg֕܎^+4o yK#0jS^N[*TL:euSq9829ܧfBq6 7¿,uiX+,z0hXi091gQsB2(/˜nE66| Or2- < ʣ ~w IQk6c -~PG6 /ܭԓ"(]G=#qR+:#:5!Ӑ`'}TwD5" 1І]WG!aJ3E0<;2νfTvx.-9m'yUjX.ͦpBHS^/?a=S2ˁ WGϬ13hWjL3(U'B5q←,YړI&V6w%u&B?l8[.wZWWk`ӛݴɅ9nNy :5ËnK`ٔ QVlJ>:Vp󶽭uYdV 7}4{V1yQktzUFP͌nNWlxo%l:ڼ夀뭻5E o5q9OnDهVB)+S]x"r~Y{N[z ZE8vΎ|m=m0rsqU ]ڨX뢘~;2%)eUXGǁ !w{?o~.Ok}/;=fq2޽ӵżvorWtkX|k~Vt=~NE((P2a CcT׉Y\½3^].c9d.uTɅg]جp˵LmѾ2s E*6Y^r='~N3GTae}58t^[-srCg띟QƶwEm MxU)Ggֹ*b-{s]; ;TMܐk/GS/S?yɿ#,xb kSi]Q RN@8ǩ>6Wfcs͎5@a,2$ fkQ/ v.ր$vUbyW >v9#Rݎ_ *U6O-HWMZ !jӴ*>&wu^jvHvwTuOy Uy'H[9  ,W‹ЧtgTW(Esy>YHH YwR^dU@*UHd1`ŁT|fwpɼĀ̩% CaEk8K۽> <>"|D{zI!&t< ^Ydﯻ qݹz2+b_1Do||Vv՜Vz*`JQQ.%rtCNhUl2,aѡV]zP}G#&~=]D@Qr@l?\j)/ yV k8-}xn)ͣ=)-.г_šK_ 8~ G|f0ͦv>c&ɒL y>ϱ [Oq׺j?\)z!b>̚NUetTP_s#UVt_bGtY ]yVf߿wQI%ܳK#3*ϥ3$\ǖs9Z"WrXf^v^Q׃+z=krq=nϦonEB@&VP㸺|΍/Gmu--ᝳkC#3׮5eWHZ`".8 ER/?w{: [9ܸ#S:Qt֒qB#Jh)R&!y^~&Y1Oo[;ԯ#л:oh1x㈶xNn˫f{]QclDC5 [ jϬ T@$=9~NsR>dH(ͫ@߆9=?C= |Z -&fH]#"m8h8{4CV("eurМ<g.HȻFb,.R򊇘0ZaE'ǔ{Lj]7ٯ>{.}`|p`0Ob CNڗ5pk ӂa4`ݳybMV|+b yi9@VY|=R?g'fE'2TnTo'y: .5+t|_Qcײz }sGʄ1 u4eiP"}gpny&y֞JU,:˵% lԏfa@)t^PҞ"+NϿ @#uƈx(@O`絜  ' b"Yu o# "xDa9{]ϷR1צ^ѧO[f+$N֫xBl /|d5In+خlֳ! /ݒeau|ZTӯ^7Vp|6'#p}>_bO;>ǻmt7}n+z?O"pAj;g ]~nNmA{[;~.hx #[AsDƗ^&k+z%lgۊ˫=i [?jM[B:PWnji9(AM,ol;*?PFsv5zE ^ , ύqfZ40%K#<ʐ+׈&Gz#j.jt*@qF18YGTu=82,A]7`4oRkC@!1"2')DhMB;a"f]Jm 䑃$.=ԄȴCBzk]Kuٮ`RFH LKU$$HKܒI5  mmJyF"֚4H+J!7/ZT:$zތMJ1.rdzF߸cv~a\>kE>/SWΟ< qCv!}oYx*WN>voC^fT@wv$eBIy~{ۚ)Q x˺EXsQ@tkkM({(uXIKhu ؘ!(BD:zteui9zk雊xk/}ow[7js~9 C/Ω}z #+'Cn{sBy k˻I"?ssJqb{oO܇ӳCJpfv:C( ;AJÉor@I-˚Aþ=ÓŔd$hJ*QQ   ~f Nm6lQf+tG2pMh>WO[[n(.B9#w+U廃Rkx}@y@\?N]F=Nz?b%ĆTR|۞AwkO/#vs{X^kY jߎ%J-5KtjuZ~Vp0_W_o?:ݷˢQ]|P} )F{ؒT]#5Ըy'q4O @د*d|:o;A9j4{W bxaD7PF 5dTPtPl@:b ⒢1mKlbT9*ܖƜ 2D` T(PC"jok8h&{s2yq3q09IC}T1lqwKtDsCkK\ ;l YďuY$8SG5JpD.NTFPQ?!%etJO-O&fQ/Pܨj eՎ5B'cFw*ơdd- <|6ֲ7H=^z9sQ`t]H+ ʞ" y~.BJj a7s[G}bWݾO zKkӦLaK}hst41&izA@AZjq|jP-`s~Yf93Q 1(ѹH "mf."@OOc~ܿ B= a[U|LbX |Ux bLP7}GRTTSI=x3^O/DusS{BDD(D(*=ڽpW}Dwh4 guo?dza|&nV.ܑ_%!M "pDDn"rGse^"Qn0 wa娆Z2eUTDf<5ەGo!~&EJ+2YG4B1q6s|gdpۼ-s=L_K?l`zJ>f O>u1(a|˗s494,{~C9lO>Й>GV 6S-ÆKM/YJ2ej6%tK 6ǭ0wѕ:gvg:4lR"Ǫ6py~gEϓ:Sm .ʱrgiAe9 } 1kݧ,?ru di(J(OOC^,dt͸s_j㩖vt]5׳鶕TZ{:?4G*W.b~gn5{_?}G`8U3ꤑq0be=3AdžV9ktڝux:z l1" 7ߣv=_c8_ESNkbJuR_9Ϡ`bZ@TI[9xwkaҶWQr($3cmΥzӽv9 D8 MP_Mhplۛh*63E);Q}IiPDGKrǛgn)[:u(r&Qys2+_]1<}Oeox6lKC3Ў ,tzЃ9GWgAxuϙޣmb[ܦ$ 0u*< ~5n0OU tw*}]ozkxT*<]_XYlG> :bpVH<>15WN+0t =m_ w~LO b5DI-vZKZ#?{|OWz5xF*=9,ť-3jS^kw;6Ŏ6;'s~d;h]L5 P徇~>SmVm׶}w{Fd%BuWwYz^uG#_aAz4ʈ[Lz("h,jRxXw]CbB>29{s{*S[RJF|J7\e>~+OV qDD"t~d.]C M Az4˕x&EdUۣSSmubxI00ë<~>?%PT݌-y'grsw^w:[mFϽ)T#7 ȯB5؀i%CrO%LڪC,۪KPj"> -s%-΄,1U̳Zr)l Do}F!Q#O {@d \aC܁_XH$$@* `Þ,0bD:#I&{MRT;ઢUVA%*VYve}!atH; "zq梫fV+*;%zA޷ f 8uέZzeE" %2= 2,+{WQ؏7xALTCϳ@+to:'//wE}UsJ3k,;:)!!,:IkKj5m{V%<^s^"X8;gcϝN93E ?N ~ y=]75CvQ艛0KtWl]W<̬apsoҝJz] st؟ڐkE4u;'b =;1+]g* YS7_4߬ "Q LLB( GguaF Ea%($Ҫ4/un  >Ƥ1SPKc^Hpк+ f}ou׉ujʽLެbk6XE|/s٫C494kM$/tb1Ż&yQZ?Wܸ;ފ4A{ _@ A\X >W9nm0W'NnfKX;QqG4/'GvkOWsԿE(R7l]a,DƠ0__F6G3saCw@J@l<%6 GVhC6!g9$5 2UTλs"q2/vzP|XĆYfJ0Oep3ESn\, |!rpH3@ċ,B;_lb/yZ)bK;[tv3kʖP)=Af6Qvԟ͉q/H&y5^y% .XU3)( H M}zH/M| u5 m6̊NI C ktѫWjd:z~Uߧm8m@Ssb۩yQq oܣ[_[ss:޾;ϙ3LEY #F }]oLhTvkCwrBC}6f䞽X9~V!98PQ!ul+pg7a>6>9"P/BpQvzP,WZeA6tpk3&qEp1 Ua!b"*ЂIf/0c\iJ1~!bZBXco=(wexKKefi>舊 -~?+ CYpAS!e64,^}gnf$Oo?/֧g) ?g{uz)6_yov>wϺ8>(l}!1fÉsR"<MUb9G~^c4tFЋtx:tҩ>gO?|3{Woz~Da~WI 2lltҫ}J7vQ]Bl/㯛\{Bߍ 1=] %W4IhQ픤َ,Q0)% }oyDM)3I_zѝkȊde@:Kv7r,Y׃ӿn. ߠk/9 Wjfj14;d*hA#=1ȼA[Ͽ}' eO^q~ -B#̨Ei@d m)ȭuѯlDl˫h7l0p ޵O@$ %*:떩ak{;#y1ݵ8{wRȲVrh|_zk˜**lK&e&ekH %% TA6Śl$cXeן iړX.-.5lԝWm7# $P֘)c+J#dXZ~h?vco[y,L][vȕXª_Rs `ǓG;ǵ9 vyUwyz:YId*R0Ϋg"c[[.')1IUPTaM"krkzkLfD^u5 `^іk'|v |`KS&~|å=3gS*Cм/n 6Sb?Z|m{/Z4jU3-7[9!ҳ?_[_AW~Q{c؀ @ZA> 00&k5|Fg&Yݎ՗$A^MZ\|[@QU#Y>Y$uR=oUеfY G()/Q܄% T eqHfӬ"Z3ܙHɷ]Us[slSiXJi$Ȋ@L2WWKhۥ7dYdz`|;;^3fؼw{HP?]qփnֆ>uD^}[ڱw|$ss'n^2c}r7iOVDy|WP!22P rmRx/0?7"/NjBmqd:(p߶Uswds#̊I"/`xmKt7݋K/Jm:l6F`w@X*OF\Se]C) yc}Pv9ESh~V[nn5+F׾ԡh@[d$Pƕ= ~owwjн"QJUTH"|N(H%(Bg~~:n]Yj/ d+\LmY0$A}.yQ}M hWԸ2^}R ˝ƭ`m~ 8n«׵ {.1ymVgUmvTK'HLNҟt}ϣ؋gOVMVo}Jۜ/BK+0ihl;/<5LƱ7ЧkOJ>XZ+]{E\'W'sCouvQb.mK:~% lM,Ewǵ奘&Ssg &G|w>{7k˓T3gL} `zun4Qĥ49p\]!έʗi[|_W_!|@:9% N=M, w 1P [ãGv)nK$fݑ<->~z!i5.$J!Cr0@Q(J.s>$ާliփn d@ĴhjP"s3, 5U1C;ld)ոل#Gu8KV|nRiv0C1#l%hFUƆaݷzaVzתU PVtJ=ooYN%.QJ.[ϳ_Dk5W/!z o ]ʣF#lQ,ؚ62kkSv_q.fupt^b(eqt\U2fQi3Wqh&%SYW*eY AFQ)^ir:-$Q iZcyеKuwe5 l.f4w*Iӫ 6ʽ]%%&9&ݵ{wt]d%^\.wyʋXɒbHV##  c_(ytgsf yuݭ7XQ tR줒\LTpN pG#Ya].aM +y+ʓ\ӷpSb{~ݯ`I@5@}_ dˀ_:B)BHI@C!LJXBIVe0fUVLcGP Rd"GćrP &LIi8)D &ԲD֍%ka$A Cr#mICZMY&*5YdԬjKifm,TkhѵUQT[!SIjUU5(f(YIoۚi#T9 K0(ar)$R;iEvzW>Pm$w2^jd$ Fdp2(eMܟY>tgoas|Ǔs< hSf\m "2B(J Apᯒx[~R=m3{ԝ,-+Bn9.{(mr-tim띙-hwۋw! QY@ƏN]=xP8> ffB& U(â|CSz1 BE(-Q/PWDՠ{%"Ȫ>*ˎs. 9|Q6kB&_**.fR}6`9 #QoNT̕!QQ3ndBv)њR0[|j0{çզ'c'ή̡@+?rV|d%LAogx$ "8԰ZUkl,L c'Qusmo6}m{h m2"y>iJ!ek*H`~`RD\ErMSyѷytu7wbuS2˟`?bt*e3";خ+)\;kW+ڢ/)_Fڧ/ |*}w5kݼWL2´0sV PͲ,e``b D[sE" pi_q JBU.T(&]л 5DK"=A}Xwdr @G9ElxyŊw l*]m(߭jD@ oGq;]^ odvyViLj]WFxELɍ^+;~j:]^3}ۇnA$وAB0qH{ )Y4As; H,NhqO0M_}d o A`ҷ, `%X֔['l %KՌѷ=z閿jp*FAB )u~69,n (."Ȩ~V.=lr4J¡̩:kqm^Ƣ)}Yo/ϵKqZ$z޴!?\c{2*TsfRhErGvuBGZBڻE'!# ( `Hg"2瀥;3Ta/Q XAB ̝֬1ijumls :@IuhÍ$61-v-J@SGx%QDIJ=MÓ'(j'g~Tq%$(!ZI$96u6IF6!w!U-fG4Y_[ٴtztq K7$bed0R;'FŋTGHTA-m+ ^uSdmmkM;2V7܂/ěŖ;>4ݟb8ι;6Qa M$V"Ɣx2&x[%ɩ𦆹w|\NH'Jtz4zD`TBɩM^bbX=!fՏ0 &S/ Rj[ piVk5pȜ+MYŔ Qri+^pZ%ȅG4"E]S&xeY *("NqTdsHc,J+P4 duOJ$: E6f*d/Wj#@limJcoѴȎT ,p3JfN ea;k$YQ@bYupAgwmQkR.PO.jͰ:2+ͼdZgn5Yٜ9\s'.!iAF>6M5T0(EK9a`&EqQP@P BRhk'XujT@Hwd iAMUxy"*Aeݛޱ;!ByNo' e1HW(,Q(V҉`֜*e:;FZv]y3::Nuǣ6!TGS9;7#\qesGvA]í-R dERuTX"#3M+L.L٧0C /)5(R m44w! JGG Nf ֘F*ukbD4(\j]SQK[gfKJse()QK+ ֎'{Fp@5K 5L9kh4I^&Ǎd)ig J4*%bӞ˰Vd5w> z UPJOe bͽuzQ|Ȭd-M,'gU!][ $i1*,YA] zy҃;/!Yc3S(O M-"E˻Tj,VZS]3`j4Rs7+BĀ Jd(. pWbyʛ0o7:佗Gv J gm0g{l@REɊ,ݐ,VLMJ)<ƲHu$5A".&!doeJƭrpyB"M^r΃9 @@rH4c 6ڣ.uy}ccuza;xCmLFY+Lz6=s) "wKׯ*ʳ}zdnW+ceޔ  Lak ycXaIPvDx :T- +ܱMu|qnz4XC9 izy=uU#Ym\ qbs"DAUզVjZC-0]KƗXq8 D9xM8̒m$5ᾧO+η"Nb-1!~<ݑ^:e]5PPw:RqC)jDu}y(%\J/X~Y9ӡ׊j{m03xnsj~wgVktT[I)SʘKL&!J Z@s3e8Ny}u]3Z$>bcb@XNTXUB򡒉fb)!Z F4Zܪ=3c9۟V bW *F8m4ۦj^۞]#'^N[lڵbuY}F' F^ّi(?8M*(v$՘1lgHO>,*-pkF}Ӟn&ߢ\-@hW&@"ypz=/Ewp1evJ.HG:` q&=A%$ud.IWE!t{է{WsT֧4W(HPho]R<7-[^ޗfʇt$6p;E(vHb ~!r%܏j7sltls 3 ~R—:ժlN^ElK^V/߾,Xo6|]~}wRJHRRJ`PhTwu`~=_wzxV՛^= O؋Nj_bPL}:_)Ndp=?mtӃ7Nv+(PTj7(b;lg6 w?/׽7(N_]Լ=qf`sC ak 8Vù)5u#/;^,(+*r+"PRO1Vb<1#Gu0i}h8HJ2YEZ}uh0;SKdgD~jb/cclzѴu?C =䣕<+,"OK߱`T4-Dlsw90YjT<"VX9 qj_4AЁS )Sd?;I;j W{{]~;6}-X*"( ~.7f <@Jk߯<22!?*>g۾Xn}xKb37~}%KbԖ@Ab_m<)kt@ ᕀDqldj?&F.m#KUQvEhqn P_7~Pna&*:{1)7FE_AGc \ڀg8yhH~-T% PPeS<Խf:Up"Q-e=[XUr->Kq-JgxJj@%=̕dkLs Q{ʒ&ׯ/w]֫XPu@X$QۿWlDe~^=ڷ_HDƑ+lU@J$R,b1bd:3sEIAo2&+УlZzZNճ wI3gi19"V[FYa pMdcPj*ߩN{rpٗ~P_F[Re<@:+,&`E|<_˙Kreg47kגNJC4+Ӥa2v_S%.@r۩pMŧUbLS ' DQh_oݽ`H7wWm^_MDS 9C"`SRK> \QH(J6I.u w-@QFH44Fr1e$W7H3m|ZHNV~ I:-ZZŧqa8)"h ]|!7ЙjBQg]( zBCB(!E}2$J"DBRzgS^+p'_Qzd@L;\̳])"ₙS_ 5rU?Csǡۛ`,QQbRk{@ ٵjtAZL0,  N7 w,22F,;r I={{4yEPDzjzMߴʒ U = a?Ύvs㭎YA@P(E?m)krx(*X ͔w/q2Ca iytyTv<§ ['Vxtr$1|CeO*|熹3dceE6ou X!ZmM5Io!7)}zȑ_Xz6͌~݇H4pe|{SݟrĽwjzR^%Bm^Wvum> -֜NI$.>ކ?C|k 2i網̠ - ]hZmXhMPR@gy/B˿bTJ T1($GsJzPH a2jӊ& >G";D>Y$T895nb PSAI>v/^x2 ;*DVXf"zeٙ۾I%_zsݿ$&8F qy6J.r:Y s~JPEcӱƌTV|$T\F)19uia˞oecؠ-{4Sx}5Nnv/R2 ݱ3ƇQm3xi 4KtR@MC~.ʋ,\" U6 m5K રj+w5y!-y1Ӄ \P&FJda;hMo7x\,b쯱*5pͺ6 oADY x *<>Ylڈ3ZK^3^ (VȚ"D8FFΌ,nd$ Vf.+Pfcݶen{IRk:U؞؄!&GbD-@@Vg|xK mY C nnhk6^Ul2iralZ˸A\o}uu9(4-.樰k|Q [-0`%Cluds]+q.+~[QW~ =񊞯f_wC%cU##"[sN?[͓תJcޢNňp >IUIF־%?Bqr5})0ٹ|:%WKPdłh-.斤:;Kt]fɟy1⯐ta9O{Us,\4,is9p~kxw23z0Y'{Z@Pڞa u8tI _] l õ4]fm;cTZX[b>(?* QJ^, ,@OQralrCQUsnFձgjz3!BUBE?6ހG(. +986|:/IXJɯMjjfQ'܉M-I9 hyܴ6gRfKIX+$SoXdPF@$N1nac %4͍a&61$F"4WszϩL֐Udy4pjg99H,|fp72PTX ɞ`%QC#CHFdQ-Ԓ>`b c!HjYah@^)fKۻ,D--1=)iU3O9~LZ7JQ/ 0U]Ѝ:cE _n} )=mJTVBPҹ=w%瓝TO|;h:AUU!X JnBFK6œ4Şl(mPcuou (㒝"ezhDP7Ȥr5 k8rÊl})*J:%%vgmfЂl\Dx/㬚5u&^mk [:5nrAj@,qo.Hm$ LԪЫ|駽RM<v/ͽ2ݜ3U׻?z:gC:m)sᘞł?=w/ruuֱ-r PXF۶BL %ɿ{QYdD+ဥZW>n)8d}:&1ΧruCy@?5RW<Ҵj_e 1J$Q(@]$FYG~1,JlVkYN%G1!7b$"VEBc:uv9#9*]t4EPRS#D !+ttFupR^,D$k:" +Ko!V@7JAsBLIt(! @今K$ŸC[)ŒT^e˓.*-*e(u5-Siu9]X:1լ h-{bhۑ̒!vd-ZSJkHD5 啾w{MgSk Ki F5 Jc3K@<|}NtE׵ӒE.h)v.# KiTu$m"[T mwKbj4H2(& ~W.;g_{JD fY]Z!i :S.48](Ң&/,IV˹ H%  esgZʊPŐkt2d}Gl9lKCRCutQ hireۥ׼zztKm _Kʌ˨#E Hf)wn]d>w10a,DFS|\7#sCW*&HW.ĕ&\HY!VIn˫BK*[,MTYWdal-%'6Q#r!槞Ƥ[RB,2V.38ՋҵVbbr5x1#Bj˂ \lH.7RIQ.lEܱf.J+ AWDUzZݞmT-ܴS_eM:&:~).PXݒ"e>5.[}qڨnmȩw%.FBIP5-Cna4Y5&\4q2?#>~B X`kӨD or)r(Qa]8,wY Pb3;|^LEc2DfZiӍ QtPR^r#F9Tڱrq֙ cV6Sc"5(^jnf7yW#llh+`mLr3L6Bjk=-W)ώ8 L0u}46F#=xF1gM#.:qQvL=<,|ߢ͚[3p$:zC_׍tds~X,A+zM ߄HfA hԍzX*Q*og@?j"B,-pv1TY=Ywvvo %ZC1POe_e^1㝭J1)oBL@rBK^M-ҩ{mm[7u6iE/X&PUx ˨q7}qsP-&iz׉FE+Kr+%$PU/Ӎ>n;bU*96wYzJ n,1~U_m>z"g.ѝ^H?N}刚5sE6P"˲Qb( WYYf[eGhn88KT{zWwWg羽B'>Z:(YԳyhÖfS BO*KRP]eں0 *]uA%6}/&  }@1z,wxy942Lת"Xy{#[>wy)b pxfEL*8{=yLGSJ*>F yfNn znR+?Q1}~(e8 :@"AD[Q3^%c-XMV:eDO^BB MCgѵ}}+qgTRQWH\2tI3wrDD8,YLe*ŕwR(UVi5Kx՗RAj2F|"4V` g{˥]dq+IDhܿJ#o !5Z%-CII  e5 #!.T,.U"$eJU\nҙ)Hr2HEp-I@Zidݹub-y,Wt]^zJLk7nEPHY d!KO 85vm=n:7L˅,2ݒ% 7=[i=V!׫̴@atjo̺pTωcS=4= dDLp .ou|"P*,҂e J79DSP5$΁x%E "[gظU?Sマ@zjޛm"(ev-ZRr1XU9zdzY1)O{!A]=mm;]=I.[#'0\g;MpeE@x7"(~lL34yH$ͺlim~ѐn^vf޹Fjigh Un6l61cAXVG"0'HvCj >\{ŪzXʭ臕jӿeUţy&ouweL c &͡r.ukd[CҨ&;6[Vqة_4g?2,HU10ZZ-αݝ}6(6ك"vyI*W]ck~̘,Iߟ=٪IXƞ_>~(1_97 Je6>2V9$%X6  CF:7e^{HCl%9N0twr2(|,'k_ K9H2`d  NIB4幂!l "%x10YQ"rkB>"}I^H7kMu`eb?d Ѭ3R~̄\jBGK{ ( q9#D%S]@6 OH,/ߕ|Xbx3BA!_h܏Un@;ݺԂ F(/eR1\[ǡMuٺQ6.&*\J%0{4ilIOYPRC4}?D`RPA !WÊ/ڗ蓻ݿK}gm%j DT0l_o?An2/;Z=Q hP}TE,6[W?6dHmD`;]9D<[= Xߵr*[<>VhYzjτ<[-G6gfy|wJ4sz=wQE0Ъ$LPD߻~ w) >cCF~^"{9fٓF4ݠX(l^D?ůof97; ?3GxzB[9 . `y]=w uM(mXx+wٮ9.T@⑙Yan16Hm>O_|/s,sxmYU,Ӂ ϑ(ŋK\4Zy뱴(6}rhK/u!nͮ=YAlJH-(Ut`a#>o]oCS+|;]4v߻ Gbj縠#)}K{rs;Ӄ=fj^.+tFZTmIg4_ у\g||O-y [[vmj(k7tTF&eZ:^3 2|cuVP~yoPk[@HfZDVG$jT!Ȗ\axAAn&=IߋJ;ai)eۖ8:ߛ=ޏcrTU/ժ PN3ESS8{k]c"HkpuFԵAS<c[r[ZԆۣ{/+ɵ?o2U{ﰜA ʨ:@KrN<}GL :#9ՎtGD{UEw:̣H _X>hP^T:00ןp$J`!~(`)i(\jz˄OC[ ~帒h c/`wsi,oS"ʀrcIMν[G* qhG]dxnLES ރ}F*Bӿԃ(43,9rc҇^9}ln^HưLOytI$|)W[Hp8+J~ܹ\ e,REA1EĤ<;:@q nLi) =k6_q`~ɗH< )RQ(}j)"A-"^w]BR,7 y\`Ϋ(Ue6w$UnЁc k{BXThy3 |\S>ZMR|t־W woz=Xcnu_ _wn& GAfQc2.A4ff+M䰂\#${|]=+v~3.v\?ٷ>pYyxxh4v c s<֩7 ԗ^nN9ZlHcJ*ac%R|(@E%mn<pRep\K(DCfv0x1YB)hEV8rghg&Y7?c/mY"**Aƨ*ب(ըnMO(7>ֻ/EEWgp:{_oKo~13AF⊏ b]JTv.,eE _ϯ~_k2mbh 4Z2:НCX2 RVpPEF4+ Pd)65{bQF>zx1Y ;=TZ~b˯="1V z4(Ggp){oqִ)Iڼ_(K]܄'b%ި׋KmZ+vǣ .EyN1+mbk@1(!,'P@pD9dך٦f[zvAn|!֫[s,3<(55Puu@Qw+vP19,:Yv?&AX:ß4J7{-ZrQZSofپ}*[֯K߳hn/˕!_Џ9&fm^ d\VP]/u]^g ͈*k'pT*iV-0֓Ҏmk&O$QC=m|nO4ө/_Sw:,c ֳY&-({"] _cnqbVA^ގNC0Ȣ$-,4gg17V'^ݗae\OZ7VśMl+7wҏ "ZO?|t!W|C5h>ŌX w9^Zg-Rn_{:[}.?F*Egל~6܀Ղ)п7ZՎO8* nRA(#c4^ n[\BϾ3yӦvʮ1ީsx?cHIV[!у0~~\ ?8ן֭FݟggBhGgGxA&^#t_5Y_y:3#7&w13NvWG08H҂Ji-Fv^gOKy"yX ysScF+z5/g5aYg1@Ol0@5+ *VpU"v<@$8jy=5x R]\ݏ안my ί-d;#$D u0Fo:.r |>UtNԧ-QB %2c_il&<@Oy@`v;в,$~X9WrnmL‹p Wfш7[!Je4HPU-{^5OE@3NU-__qQAjTU"ZMzY{k"$~ŠsXuEWfB0aiQ5fWܦ")\;QkF &SyX4qbxGݏt6H f-w$pp[2U,iE9P89BvJ-?>< r3sޔi7~-k?cfʯnع{Ch:]>)T䡅jd6.Kb;n޵lj^?_y]6róo M칙Ni%75} ysg6jjj?&׾7F]@t9~N{ݿŃv'J c$U;}Zf[m֛ ~ |͉CQD+ 7hp,B$ѕhlD st.=uZWw\2Sf0T񩂝i#[ŭTCHjѲ0t"zB0.v`Ë> hczp Iݡ.`i\vyɔE\sA(oc5s]'5V6jiDܬo ?Cݎ$~.6ڷobOsϗz7yjc1+W ,|Yvku ~.1X~`_^%tC<4eF:gL2[-=Mdl|oxe־uGmBcvFn'͝>w %sꗯ=D -9F^YѼ wͫc/^V/6m"|jlqjV_zK JDp~qor1Ƴ=ή&2jbǐ6NtMоji[HnC#֞j0‹7ų&de:uUႩ[+9 gB.F!@I θу}+d8UT)!2iAJ@0~ަWi3TPlXq!4j^伮edS5$n u=tJtmkYFo'B@xw9#-81S,cVX^*zD+[1Եj@ n/oVM)3zݍu*qrr|o}e2icA#덝Ga~qVLP a mSm `^ !&.گLM~Ϙ TX]{W󶭷u\n2gAC>; pmv7pzlP>Xw>j@m$jHٺ#͓z%Nbkavnf!I5u1\5~뫔t.BqeJ-Vlra`6L̅yv'K-\ip:cCYy Q#"]o_+j/lgaQ~K8oc/N܃#5s8==FkÛ:I58q Sxym5Od*ct ބ]Pfl峔ǍMZ5HڮQ=eHFWLXT06IJ@AA9ZU$f"P2@yPU0=($)T$ " &Wμ$4*;%&b*. :wo ("x(k3*-?kKEBNZLl ʄ" JW` [Y&vgJ'RC4e ϵh L;ogrj)s8$h d/x9s꓆:[Cn:EHl!/jS4JB0>+W~ i`dre}4CoLYLk^ye/svyㄔh{޿g+N՘ jh(𮴓ץ#܆nm\ᐉ>TrH! 4h|/iߡ]JԳL((,$QF J,TAa;{|>}3d " "Mu^_qkX_7b *?9r8 MlҿBʥ]C؏0(waղJF4z|YѱԽw3ϵ'G<}M $<U ڌA# a*.Rxk[ͽz:0;?AEDn-od>%mx j4Lu|±׉TzYi.8x'-sC$]&]{hI8h0n_{ {6ׯZ-uyC*ݸp3ɀ2 YΦpDvs]9@ӂ ^Mᆫ˺lbx޿?E]V_rno08v -zw^pߟqF tA(wnwQUji)9>@̱%)1Gq4"KfV{\g09b@]偛 htO*5&IllR SF(J[sAw{&T4n loCff0(u2byTv#@,<^̉ u2nN=mnw_Z+ 2]7eR86V@WE{U6yY)XgWI@P, {s_I !X#X2 D@ >}:(468ʘ0 u;q[:4k+B f3ra淂y8(kyyzYWjt!7xDC4ehxfdQG}byz,FڵX"QM`5&,T ;H~ɿ$2 QBhEĦ EFlآɴh6(a#*FBQ@Fԛ3%!EƊ*QhɌ[4##BűLMTkcKBES•8w4ُDPБL ߧ7maߚ=%?CmG㶲lc]≶jM~=cc׌ %*MO_$ET&c&a1XXߵue"-#1VHH- ﬞ龂6I} ؓz@Fb08QIR$!4Uʚ{][xTf*z>ӏ_aqfW7!ʶ0Qɐt!B/Da)I-QTM^3s.%{&j,pq*}$G_l[mLcwVj$$ F*%5WQ\% mue,j1R V׼SV%Rʑ)4'بOr)냸+y{,aG%X'uP(D%!YaXYx}oO6 |I*!~<|dj$J}]+MK;,: /o0>sN G"db:4 {)NHZpSInj+r В=>-bscLv(He[K"W!ie@x5lF ȗcP! v%kEة-ÞΧ"6{YPŒЫz,QWua!".sֿGܣz|C_PqKz(aԖr';y]yWF|Q*rPaV=ctϕwgJ qryύ7DD t`ȲXle &HEer#H7$_k(.).D;mn& ġ В@Q`M= 'ݛ1q16`C 14{Iy(jI !3u[ӗ@D [\QDP$B(<>g.6a_82ExϲօXыAcPB@Α@m6Uy. <~ls <u^&**G0ѿgvآM57>g!>J۫Cc3_Ěb U|j Qhxm?kq%![;rC/xCїZgmaNZ*ΐ¢WAImF(B~T|S{,u^?ʪ<^˩^ (6$f?g)+̻u~C2bVKc]آ\؟Ynᖙofh 8(woϯ2yWjv2u#*&wW:B_/Ɩ 8^(FmX(;Vqۧ˗8 pO따F?ܲBl˭vpCwwboET7WI`&yܪdFⷦ wW=2O%OvMLtuaXhև{FwH8>zzObF/"r 3,KgE?3czKXl\Lw. { S_g[sf\~5gz}bכ>.&n+/ձ7nM:^ ,x߳jٶ]:ig{Q3W  t#AѥG+vq^g_kkd~,X49%fBb~w?~3}?6^_z]8{1Ν*ƁяNӗ ywr$b p6Y@$0 $Z!G^w!+z~wK"": ?DARHYb+HE vH`_Ÿrȏi{Pzty․_+P>Z?z~o]-9#799K ?ݛXP .ٙMs+ :k3\_ES+?N{tykeiڲ[%)!Te[$9!5o8~?w,b'eu3Eșjl!S>vxά{Je(偎a&vlM@Ey H"#T""{t3ے_Tp{])] We 'mM lko))L׳5Q%QAvkdzg1)u'G=D,IIDEiadtR>Y)9{ 5ntTXص7E M0_WІg\c!E\ZAӔSoafҚn_SկfK P%zL{Ri1,cFLTXZ,F% 6($v29St{Vynظ:3 \^s451;U^z ƾ=7T_ #@vIb˄ఖ104OY-i-; Ք ", .w;,-D@I3*3b"c$:b]9efA% l`>ʶ.nh6gի8n0[.HΖ6t֎:l#9jWM ῱(YLĠZ}/1nMIV$Ťʣ9T\iCN:rVfBAB"~O|mO Ml$ͽE  BTFe/?=fvBwvVax i[joP u؆UQ/b!LSFCtyz<,[B^ D%=d/StydPX`U"价M1e߅i)C ) lXN7m z6-k]a.ׯ9t`t~P kKIezm=[[gj9.6JӯH<ޅY8oDFtSxT>US?=,<,Dm6wĒǧnH7,Q AoǼ+q0<8gé|D2_Z .lgd1_[?v[볡0LcY3.oIP*!=Wy*v|~aعh5Udd)>1wȓqsZS;]|'.\O;yIv@2oZ%TdO;3D(eXȳ~}';\~">Zy@וHj6I'/vnV^CF>oiF߷"^BP&[:}uGmq_[m!ef"8!5?n{P ~f/s~_^ A1$+b7;z,YWuH#:,}vJGם;bňU@I! JxpC&o+M{sZ3X>'6 PvwZ*wHt&. !==LNA]K']8-d4㏗'?@˜~gOkK>軿%zL-n֓ؽ:Σ rX_U Q 9R t0Jeo`rQpwJJlBPZQ$*;-~Ws_rF,I߆z«jҸ#FqĀ>Q[֘͵_ntkr 1(ؾv.j3UW}#}FqLPa6x#_&mޔ_s+wVkZTxYl :1RdDof[4V 2pbF+F[ fhCQs@Q2PTEH~cV @dQ MޏcVhxo.v+lM*F2#TfcIȊ*(6fF e "dBdNɨJԳBV LJ+ML]ԛF²獐}N(G oZل^ V} vYŇWhTk*M^r,APG)I%aT;\"]ܛr]EIr Y! aPHм~0"jAk_cAQSF߭3ݮ׊b픀bk=}BX!@vyxy; 4Q52dȀa(Evꯑʁ!}k_)B Ob8#Csht .} /2<49e_ | ]%ݶ_AuZ .<ՂOc_ss߮6 K-ZqJIeX|z9T&|6Z'>(NuWڑũ:A5QMcW" jzPK k6`tܥq!hןz d  K i#ǖ]jԩW%mjϕ\^ d1_d>kCK''_.J,c4|ع B,:aӇUX4QW?.Xy+%)4SU@, mF `Q25xʹĉkw~k΅}SL1hFHDEJ"V$F%Zvls(= c>2^WW0WGƂ1z/߇.!u,!}0I"1lT.iG\{/4A]ŊqibEAH 3b8uftD_4gf<ុ1|~cK_/?O.O dXRy&KVTEBSPfFYaeS]45_魹{P`z0>-2%o ذve0\9*.nPi7*ƲܾkM.RHMG4Jl 㝑G3 4=LТ)ٽAae:s̅JzK1{d:*NI{ݖ@keDk _0B)L]m.=Ԝc %@Y8(yhH12:JXXIǯ|/AFvXv*zT V4 5ݭ%/ !~ WPTLws8hb1}t eݲ1AТ$@sImv-W1FDf02CwE@ _N6 WƐyzRVBݨEm~H(GLKd.eXIJ0$Z63SaFguӆ *JUYʭ&yi 2=g$ <0—`}u-M$|YrpBT,$A"%Z:}K% E:2j>W.t+QAje Z%T@N#8  !)-``ᓭ8׉p RR `q%kww^dA.\DCw$G\]7*Jk{l.w=۽ Y7q>/9epu:S!mضˊ#`I$jII d)V˟]|M5y.CWgF4h2C.H*R^]HH#UZe)ăXuq( XXeJkVHbMeiQXD_Yw\U^S&Ήo;^D?|]\_\B(9N=6YHz*%Hq^D3QڷTW\drvptǒO @J{OQrhUoox! {vhcS ﹊߷;ϕC\ B,.BzozI`n(^Ƶݍ\`p0:&m݆Kzn\n$%YxOCA^N%[u*.|ޥtJO@ ղ(K9NJhtXK;N R9 UNgil"hrRQV<ۜ6scsM "RNR%Z#m򾏖}swۛI6+v)seM5ҸW'\{5*owJA56lq75IcL%dڇ;rہ &k\ػ"Enw8I&3Uwu\BX\*Tk?o]7PyF"R2(jNe&"V4bujZ+wEݻ{{#U5RXoSLre!C)3UؗM{7VW%ǙNq{RB"E#dRD+3Eԁ^j=/v4'1E4 ׸M;F)y lzjL0}k[6]Vt/P*قz{^_^/~_x|?/ϷA>$LU]rg"wG@Zs`o |w.VMB Pi2{18|r[<ȡԯVGzj]"嚽^j˒m͏h(0o_;MA\)#rtêyK N_m$OGmHE@Vq9ɜ2Uu(؅88U}~Ul@THnPF+Ri :zo@wr hjvzTe 7f&VΛ84Ꚍ5:=J*[xP* A=$8^euWl(}@8j`YPq֟5]hی2NU!D ʩUZNQSuF (|*_jVG \yS4~tXÞ.G~2.4qP9Mftlu^'ɸӈyj߆(ֳC~]>B%1|-|B!=J.z1)VxS6{9"mZ#R< |ݘ>򈬯'cҼ~GNTQQ`fB)&L҂P5w=m3.n睨 2JXZՅA#'6N|+۸`j$UeE˻CSd\zPTY znhYo_۬ؠՁa{qqrbоIko,z߬z:{chIZ`JV@_*&]^҅5pX=&a^rQ.`Bpe;g9]24N)<*-cimKެAx^2zJCA;rӱVf.(9yT2Hg i1&\qZV!EON<(Rۊ< vwK ser|q9)OZg<E1 CY05(f{uk4[ 3 V0)ם%$^e t(Dnl3=HyI< |+ ΍*ɍxoKv֍xm? <:R|MKX8yV*`ͭaf6!~HnM7nY\歙2y|uj[tx}JojԀu55vNB avڃ˂q=C()< LYIHD:89UMDĄ/Dn*#{5i^[ Ɉ+z1|(@ U:m3G#ו EEO5W\u|BA~_1́)Y"7˶ #|ː+sTڔCr#h50G$Oۑn+ \sgm?<ILu%}OOzq̀n+ oYL4APݮǤDدtW (I$Ƽ5h^#$y.L4 )eQA(J H ]xgDBTpgʾBe !JRˍk_1Q &`ߕ|:~k=YlFPwPRm$RD)N|4ڨf{u̷y@qklӒ%].7*ݲ|\;*i'r*IR(B4ndVu R [P)ְӨlq_0.[RGXܕP @7wӿVc5ZS`@#UYצiMqy92sM]nJYGo+fyX-!S[(v:E^P,+Oߒ4FD]ˤ!ƯR Q߲Qst"#T1 <^ȌC¯ec Z0))x"`Uf"C5ˇ<4RIt(hT6vH"eQoOUr\ɈJ Dh/k1H>MZrTHF+\\cEy Db9 v$|oaJ!SS;Ke:ryl&54f =]D{jZ\zL.UbAyn}xYhdTMzJ69Jh* テ]r,j e̮[-T0P8PнtWg=԰2%7envчv4 {9Ѿ˯t=fzgk%B8eoK*v[+ۗOirg+u_ a0J*ᨠdK[?=+=vJuBAR"(u +ךP+PpƗ@/RFLIU irB0E+[?.{akw '$NPl[a`NjZ7 )FP!f8b5V=H-2ѕRD,h *|AWD!S`[\FzY 0~7=Ee=yo ڋֲMhB![l00"ʢT=M{f+^"9 Ѫ4ˏóM)xut_\On^zo5nZ67.;am|#}0a'I|eoDQ,h#`-MP94ސ_םʲÔ"fl-&f?k}t$W2Vq!sS nm i0WNj$ԚfQt{۩HNBAQ J@B<_PsEe=׸`Xi5{Y2\(^8q*DVթ {ݐ4}U'w#n-x]uY.4Jlj3Xj+̛0݄ڈԀtWޒKco1D U9,҆s$:F׮`JN·t! *UFm%h;9ueC|p PPXffGL(tzD(7z%$ߒͰHhCFZ UK:l:g}E͸{2!J nt`0H'^:wg^}hꯃBq2<=15}l *JZ׍ln;&ϡq13 [opxh}X,ļ{5G:ibs{aƯe.7:wæfЫZ<uͯcOʽԇmGQV \LX:^moW{_lCOACZau͛+ܵ7n~9.G~ ܧ}] W 1[r}gs/7?urŏ~7\gi6;{x}p%*kvQ_ZQ'hkn?/{'=œ_aYeK/PyI'_;F̃kfw:>!=M"bsG?̰"wd:…Iرh?kL}xs~ڗqc'z}7q[{>NQ#~]j\v.>ud]3iXP i@ox:1r 6 xd~YvE.< F֓7FRG >9~:>n;+~0 {R/xρ*  $ MeT[qspسA*q~C}@f^~n0-Aoj?/x19{_1>հ4s ҉mJ" RTQ)HJ@ #ඤt5\CЇc h:$Aբ.սnHޛB, Xf!d;ZR gY͞;gZlHexݷl;nl=uHIScŽaM.W"`]#_eX:k_` ]XE 8USl'GߐK~O}NwKKv?=H]ګϪ}o'>OdTӠJusnmrQ,oJvf쫿a߯=o!0Kʌ QyRIC[m:[4f5aa Pxm֖@wlCf H3K\c)9؆g'n';wf ح VN.Zm7Z~=bDՖy^<0j6oCOpٟ^, ]C%61T7Rw]MٵpXxںo \rS3:iawV*eDx(N6WwTE)cV ۺǻ,7t{h乒C q*<.v-ۖZLX",3P!PsY~.<ZxT5޷@p} r3lV-u(yy[>.z҂Z0n$}jpQu953#SkbH3;8b`=?{vT,2"FB -enw)69xs5O)k=dy_>mvn"BN݋&wqa!#5k Z_@Bmy!{6㭹-*.ÿxYg6 -s2תewe0 Yu-PA( E苞}WH)!Dj~ǟܦvz  EO^[I*tz޷>24Pti N ozV0ϿcPVO;FoըGh+#hJ^uYOmD};x7> >#, V2 ( @jj1|lήЏ$`yd=*/Mw'AR ,k"ơ!ֹdY.&L7;nW!U‘پ!~{awW9vzlo!?t zmbVFf[V5I(C8o2ԙ+@h ՟ ?6C()bI$#+rđ$@B ?6SRN0{8L3ʂa(ܠJdӗߗ 3wp@।E7 wXB:[5\ 1 lZR >iؖ]I.c) }Y$td7k,igrP8]'N9!FSBj8˻ˍnP;x/mop @uN(E Uf,LggMhY\uFlYdvo9|o8A)4~n,* 3WA|6Z ƹ +PQE(bJAC4o ̓Ok&6J=iDᾩ3(f3~D6Rohn A0g긧e'3f;3S1іr4ӑ'72qaMR1wPFϋN2unwnΦ'װ{\*A6AP$&Ax, xBI*gYk!ʽM*=}H ADR PNQlR9/Sϯ[5^n=/ߜv5%jI`ư %W*# ͊xb(J&sM,ᅧ-Hn4@q47TÄۺ@9f05 KB:q{7H}ʆ8$m!$ݵipgC"9Z@3e)25 hV龜;W2+ӌFu do=ĢnÁU66$\9݉&^54v/.66BFs@U7ZמzPrwՏR;+Pg3D Dw((ifъ$Ӊu֑nKNɆ&]y\f_yEN%@(@ Y 63^a|g%/DxƉeɌ.9Q]!Н_@]kZQnH]iUJܩhK+2 H` ڢrHU H[Ulr*mp)9YQ0ͥpXAe/' 9 ̉&Vy:x!euYU:\t@QZ_~ ]`ro@8U]B]HE9 ZdU@]׃өrMwYX)Mx M!IR¡ 2)p EȇT36hB%.\-kYA(A;"U$hDC Zjci%S ,&X6]ַxLzW}B&/w|nV&'}JD9InvNZƶJ)txupkrUtk*%AKKu1P@9ąÀ+ayi Os~kTELkt;-b88v_ 8`b膣;&+ڄ$ Xd71=ʢ0b}ml*l5($Ssz=`R# mrY0!{>#"%xْbRTM*6ssr!WOmH5S7{9A"iY5=o~[/Oru+= +Bq&W]iiP j&Q`+]ѼH'Z-C}Ǐw\ƬĖoI :P~I7`L[+5~I2qKh^at+fN?TDlv6x_ Jc41PdE'ntߋO& d xxB.;|gdT%3 AָÞTocǯ@ZET_;;-N.64ԩE zAYsY'Wk mm$P(#J% ҇_T޹9zpHs7wZg+HruEB35腌XF J9DH,H%rnӁY7VnκDt1U(Cw09rӹkYy3sK1(rYv0Qc[ \d035L CeIV:Ᵹ7(5T-؇\ Eע G W1 )4FLb0! SWYK dAhϝSTQ+@I&ڧ%hthNZ7%Ȍ uMk* )X^·~v98PCBB )O_` 3 t.),.s8w ~kncoDOUIC}!}OFzNS^5!#^N)_Ȭp]DMs:oc&VDs TS Wo ^6gV7fAYgufWWP*!#ur͐LpXJ^AZpUoJ̺ B=]%9DiZ gsa4RSDE4EVt+ϔ{I9ݛ}* o -Q.2qpꋢU׾(@%$ѱ4gD&rB&gA\Cf,:?FXPBeUm:?WjgcM;\jII 7PairMpZ,Z,l@B-SZ|'╤IM%Օ2A΄;Gq( d9.f( rs! R`q© /Y6>ԁ$030JRA׷1 DvR'x@v:zӻ˼TS}Yr'5QNQ@ (;6ބҞVţ4y1 z؁+!,hɪ5Y,E̺q'F )ls]K-$Tߊ͊"f䇝XSgNRYT;o 1P*EQƉ u*]S c[(IHT)dCo"<(Az;C$ֿkNFڒVDNdZ+`",jBt8 vוb/ug3ml|EˉXͅSEP+6M^X7q؛t58gxϡ 5չX(*0c'Oͷ(UvjT5gaSZѶ,HߧGfQFIZ5F[/OUDvt A%tܯN&w Eb',ʿƱ]DqW]FI ̧7tEoTbPV"c'Øwʔaxr2q #Q$TQv8-67mfӨg=]Np" zαphOSCd@L=dTIK2ZDEE)}{ZGrk#| HL @0 ♞vU3lp-TT1+ћW>張WbR׏/ {4='mYHu'zטQ rkAjҮ`3oYS7RZJiKr@ ֲ gxxhb\K, BQ0:'3=y3`C3$Ϡ8 .J6֞+(TiQX9UH~l b|KQ?1PX}Y׏](H,%TqP"OKKҨ}T -u&Q7}Aō:2f`sbJ2C*(c^oCj?<Ձz@+'D%TkMCˤ]sPOyIPSosjT8UQϦY 4aCyV+i&.dLVHhP8̸28ZʒÖrV"!]iNc<'3-HY] Ԓ)RER  ן3}:N HD4 mWH@_PY@Q) C8W}tJc#'Iu3¼Wd,`y<((x|XQ<%|6"v$=MmژMZ$Ka ,E(f@T#1#획*n'`GU VC=aʡ@RτgJ`S ҅?5d[㩐<>lcnJHX6V/^5`!=evf'R׳H;4lF'j9Of4]~iNl'HO.is=?ҴY܄b,)#}z3fYɶ [ZANo\\oMa9vRo' 6ҋ6t@VP<(kI*n5 Xs7r-m}! l@ PïHBCu+ mIϰMe}*]It6u"6 *Eu?n ep'] u,xGGc=@Mģ2]96ݓqu9+eUPOe.֚G38>VKx:ФDu)ba}'jrlU(/nn5(A:pb ɝme¯: 22(WA.eTM2CR('EAe2 UiT~~; ._BNq\oTL:m2#IȜOaWC@"G^↪ٓz/b: aE;*Q(&p`ҤB= xK+ [B,g>*gBRȩ) 1F`?:}ZvzZdDY '`h554doPb[g)-^ ^ja!`%b%Mޯ,-`?7c] C+;T*("QvzpU]yX'`Q >T&» ʃ~;*_ylDD0@(`( lk͚ G Rv {ds\2-[ɲ8EvYպ"jڎ[|;/c`5i* W}|xHJL$GjOrA+AQ>O!yfw| IzL$Ӕ(b!0/W Lۓ,F9 Yk'+?'aIߚi[ech5b޻C]1ʏ^Nqڋc]zv뻹[w%|[~5lk|/iň<TN,!RIݾ|T؈j u%.e@eAU|pȸe0t.e4yɔj)SZUʓPⶩ֤yfYj=GY{dSm׭FUuk$:VS8ފc j;O"InIbo`mQ] C~i\rrv֢UE dӁ6RylCҍEQ09aa9+;o F)Y PS7bcV7Hdy?鮭W>W e1 A-eql v0~;J&^<=䏯VUfmV,tiJ9wJ)cnt3j㩶?ڀS+P!G8 Di-6!W\obϥ cҁH \󥧵x 0+&p EՒ)YNG-z STfw3[xPQ eABrB.pBmt>P[|G`1Mc`6;xK_lksX+ g諟AC/9)e:dX(a Hd<4˔SXI^s0oO!dedžQL7.N7F)8o{|Hb.׊i5l8.($-b I&v`iv:ѥs̀* b!}PZ P:W+P ˚RٵuC;( KFݙIC6DO*b[PP[5}=},Uc;|8 flqDn\GFueqpg` ?Ss-ɜ13 5]pYD)rp."2Uզ!#%adb%ǫl1 3P>m=H. >0\{ - UP/i`"ys[zЗ}{{ É8y$p; lŷV|W})jMi)Ψ|pe~9TcſzP 69uq[-ehEDHik`UЍϻf ",";/nau9 <l9Fբ R_O껂ꡃXF_bax<tY X gQHb^zkTՁF Z->^tfoWӟLijP Us#w>N=vFmSA.)Ot @ Wp%>ЛA$ðpՃ λ=6P6NNWyl/TK1#OM!6qO_Vx &1_@o>cgnK_r!$(H .'V}8!_ [ 4Dmj115iv^MqA΋LFN"-I$,>'2i,nSvNguN+sV%/ p߅FV֥߳%ˮlɖJ=x1dY߮GH~AOS{O |3ٳeiYkr孝P|Q8Qs {af%z )U{ <;e@kuYAD ?脑/(0%#o z/h2ʱ+/8qe:Rw/x`J#2wʜzS}Ƅ=WInUr#S~nC ߬a@rd_:w KrVzPz:$NckVCI9 2,fpeZv{P*F@ mۻZ| h`qÀgL&G-HF p?/ڨĨLwwul4;;+IH7`7 Ӌ$m(5j]+ԄO0,l/Av¶k,V_k|# ˯&b0G˄lKGeLup4O<`@!YDEߡU4[1LPQҠA8j/e1#1UUHxcbV/kCr7J,Ѹu0S1by9^iӝC0fLpfqbwdQ*Ap#ÚEbztriْHBɊ]B^$kËM[X8l`%Yb/>tu n\0rGalzX#58K3@q#oR;%1zte<*>kן$fS%3nU|ɅQVYS؅,F.}INʀVn ?;X3{8]aqA#Q #Ъ4~k}٭4&Cgy+e+A[S<`rN[n:pcز(ƖA_|lp֚XSJxj-@*]ux)oj!bC'~gYM|Ֆ|oگuuul7J@2;@{eKO־ۍ<|} m8v.)ľ ֝;::'í8&ҵn\5iSӀϾi3mRg ѽ/m7f㒒Yzۜ^ _)ZQYAȄSqU:5`p"DFy k `R'5Ӈe5ʠ(9){mJX=oCw'fIh Ͼ^{ݟ}yׅ{^{9m+ݯ}ζe>HIQ RٔpcusznJGP> ; ZlPM @*@=w({*_]/Z \¾l\$IVվ} {1޻X٠VI3U%N}AeG$z9m5>10՛'X-^}|zm;޾]; k"7m=w}}l|ʍOa{NyK@, j^载{ @{0t`:OxOOAzu1}Nu ۜ+TomE'`P@d4dL bi42+7IDQ I; ŴZ-=ͱ9e]\IMmĹɸX2C.Vrs'K /nι!*~B'PuKAUʀ;-PkȔ^.%wvhRsь7;$;NL!ݯWODb+ŧ_ D-?K,Gޯ}ou_1`+Xn{^RU3uz]~}F!]ԞGq6b Xk%Z7CE<b m$XI&/r $`l6 Bm7kYC^JSgO<}= (|_oU[ENqGd) rXGTRwZGRh,h 7Q&JUhB1 32ʬ[\wTWRONdȇ! LPog]ӅHB xy:3U>YLkAH$ E z2ƜroOWӿH腨le-+yE˖'WZiovyAA&9s:po?;,>)de'Ne:0' + MMmA]6AEY8p8i\tS 47aSK7)"ZDaǒ:g_Mnl4QjE &\"q+C 5~'3 fqaZjh(Syg9aA;otoT,JT%DK!Q$C=9{ k4KmtXPOWOopޯnbN%rEhwl ahv⣻ae =_t#b.|p܆7A /KPlՒ9ZnY|XQQZ" HLu(͸ #ۼy3t+#xU,idFlHƓ>t#]JU\̫2R1nYR ˒!12b-w/xT"tA A%Ku/g ;1DDE)?32xJQ1 F!>lqa\=lr7&F, YR+2ʀ]KJ<&]\%&ڂ `TTk7` (a`ڢ."R@zǪZQ' R-SZ~\+$L&Qg~˾T ꏻqދʞq".qGgM{Ճ:|+Q@ӎ(p 8G ÉQw}(E),B8+}ݓ5:j8XHqAт]>&{+IS ^Ub7P9GZ#4HVC=A[}{ș$$i&/a8Bk"*.[n܆xDu*1 $hDFL =K~F3=cCdhGq4MjPϦZXVg#:Ej.LnƢ: ˳%X-g^nGb^x9 uWRV*$*l ҼI}ITSN)MOuM5<*[Q6) {Kb2 81fVmX[jAInp78I {  T5T}QPxYޥ1F-:vjJ| 3 LBaϛP(#&'.  [kptm>N?FJI.hhlPQ_7w D/Vwzޗ`:>w}b\lGh $! ir3׼!6 DnF)Q!/-&&Z41E.*HK T4c"H(HM (O$!V+8rӡXD. ׁn#(qVC˭jG78T1B /(bD!2ǟwkH8}gI,Hydrh%!Zˊaでs$Nq;=ÈtOz7֛Må?oՓbN~gi8kn1!QAFOw|Qt .6" s[|$B1MgA}}VN,1(O0"v*UGb̜I88@gBH@WGo˾]p:ƆI n 7ɛyN]{:{5")"H%W>e8KiJCLҨȗ8 H?T4 #GT1$ M i另}VfH;ڽNNތ:`WV/TO-hG{ttC{ qہ/dNg_t`*l((7.J:U0GY/SdL\ʊ'n6Łi[Sz1J bU9_ښ/EA|mX9 tQ JՅdYYb%7p\@%&BD{* JI əPb`!!Ɖ8'* pBj7wo3OAUUY_wZhA;v!b㑤/I}U_Qc{QBlbDMrH)D\h`7CγO,_ᯛh*g"ז:Q@܏F*DU`w]1B}N)` r7 @"JX2a#XSX{ⲏ~.?OF, ?"ovbV\B׻YLr-QQQpxbc6v('y",5zM­tr&u iAfww}#@.Qiαtǁ *N:I% >*QARTP +_f QaU/\ L k 3VJ0)#5Tk!6zx?hJRfQ͚ZmNU]<|adqZ_CUt!XY>bFV8: .7f<~OL<05R.XZp $A뤢EZZ7 JSTLʈH@e^u8b]sjϿ0X+z*hb KRhvp6Ly}! "TGC3 J9 bTU@׋'bJ䏸*E;/Wqv0E_/|u+<>OvjŻsJUb K#DB& d ,K-ݾ!V`ƿJ+3'nTjO&{Bl,h_P +Wv0[:HDAzù(KCRF]x3]@Q!:,Z('z\ 8+nd)=FNK4/la\2.j̶>.'D~C $n@I0\ֶ[mBDPayr-\ 87wT!(b#s.;3CYRϫ7C8dTACEoGur샮{5 \jQqyV&JӺΈo&68'OJySƫAv!CB>PW33UFCMr'ou=.[a) {Kٵdfya {kXdCxΞG9q)Y6z"2q)1VQҨqfi?緭J6/Yx-vn,=0Aۙ.v y ;=hX]&kc†6NgA\*|ֻ Y($yxد*FƄ-`IUHI[IHT$t@k!HT$\mS.(T zMf}'x@(xyn{5CQA~\1ƓUp?B4I)Lmk|lQ:"5SnH̢!>W9>wy0 BZ6r \:;͖wB9ް?-0xݞHAQ8X{ݽr@#)̌Ig!k>f9$_G>hɜ@a8Π4Q7Aws ٴha: #(.Cʪױt'@DJMM~̽5 QhF )Jd3 >s{QߜGJ>uޮ,QLèyISM}~S-X[37{*7:oʱE8Z]h/5̑-)ox 3&E8ݔP*Wi2(Bp=m[(AVXS{!=AIJ7O$PH8"_=)e^զ*9W1Y/Ȗ,/'&:ʳEoS=́t3wEɽ8fU>fLσ]ζ[?΃dStc^E[%[FDt,+ vwRPU)KM>';uQ(Y-Xcۭ5Acx#2Hgx=S|e5OXi$0Iο4Cj-I8 pwԧ3( Av}[;E*ٍ_|=K uT&$LR6L7F{ ʡZm=.ɒ=NgzR Ϯ7S(aMo!c%;<^9*vϙ@$RAip!(Hd' rv~E0Ƞ;QM!v<9a NNʄaSb <1t&?ATom=*aDuۖ^ψ ML:;YmᓟӞ\,QA1-@uvɻzU p Z"PW]~ #B0g4 @#͜?u˾thx9r-+xm|!S=fA8=ݱux[i|v3<)JwVP8P<cm6 8TilBB>vLuTy 5釐0v~69s(@!FbA$Bh)dDYt11$GRPseWW T"} HJ Ź&D **9wt܀e҈O2/">MaeμkŸr2ш1 Ϋ5Ycp]fkHAu]yتMB5YpV$B~6tR!UN^ʮgOcObzވH({GO|6o@=R?xE{2r*ǿVP](PY17xp F(r,ƀ{f{wF"^ 1-#48d. UO:E|6tkG*;wjif`4|]TP9zFeKgqRO-DHloוW!&\+ {~W,*O[۶)R61yOTRN4SqpL!b9  %2!|@pr{bL`<̢KYFAJvkl$)KK., r;ڛhGk_V H$~Ew+ ' }G@V|6)FNtn*^~]QE($Ks~2| :, K[Ql״ r.UmKUi$~5HaWɬ-VWxg>/;ncv<ԭwT5C0Ȃ ILպYC廼pw9%&b'Z7:#$a"Zi X.|J!,!D r[qA>A P@LzN9mI JL3FF$bG/{Ƽ .b"[bFA&Т>+ܰ˦Iw' ~Xmւ@R2A&:R>%Bվ. !'THERd7/ # q ZxX-6(뎧تG~T;ˮ}t5$a\mP*4wa{_~qvk֛ue$viC~+v - n#]v$JH1Vi6Eزgʹe5cQ,S' YJ=DQ@Do-$Ѣ矻!u#eδu5\;: GMq@{FZwv-_4ZsE=|K&B^'ݻm4ѥ'[!.LIFqiUuĜb0߃`߉UG$,o>nGEGn6|\TFR/eѡWw֑5R^z.sbM662SuPbb]A%)@&5;&[.ha\׃7 ( 7D+RKU|lt@PS#>c(JG<.7=J#`{  B@2s[6FOLAj \Wno&1!!Q 2p y`IU1O3߫0s'=Ows8Q2elIdY¼vMLBe%$$k'(zr*Mkhw:oom,"~@e,lbB)A(+FdѵF2 &^$\m`*-Dh5*5AIr9IrJ>˪Ed*7N @k&m}IEk]:[ʌ̆wδ hh{l"f1,(!4QThi IIcj,jFѢѫ*(=ScDd6^[oy (qAE -=gD">Q4٤N䄢b}Tu8:ωY~u9Fcٖ!D8q':k7o>6a`LHe]("v~&.Sw JLhUH ,e. M@|r)86NW&ʏ[r*Vb$Ar-ܝ ;AB$(TTBEJ~jF 3Wmmv9ol t^tĴ4y2)Xւ4~ߘǙʏuwŨ%79eQ% D BRR}*PNśfM|̓ǿ;O ISj`YW hfYvĨ)uw!`rl-)"FI$8l AcT+fnb?j/'2PQӐ\vq`g3 #,IX5 X =~K|,m:ݰevv$2M4Xc(iD1`FH@$E  ϼRH LQt'ɷ-&8" ܠnsrqYM n}IyH0P;’. nw{f"u%\(Q[5${8VsoK@#5{駓g""Jc6D%a.{hr_ᢍPΏ'Gqy2~ "d̉@̑ukʯܬbNa0kϛ{*بY0E>+'⋤l =x{"?EGJO!<.@?orVS7pNRmcY65%$JF(4TFcE&,Q(RF5DE%-4k1I&M6jlZ)5EJEb&DclZHkllm,kcb)Dڊl1AY+Q` b6F,5cmXѪڍh(lm+`MJ`ѓbi60F6d%dbBLV-EXٌi,Q&*"RdUeQ2ر`H5cQEFBXE1b cD6mcF4bFllIH؊lE7}),ShUWd _Y"|KU3L%1j! P ({xz~Q@}Okp>ˤ>c8I$v yEllK6,B*(;SzϴD̓$Vާ|NWyZ+ДZcmfY6ňb6MTɂmF"FKcV4hDmb-Fcd-Rl[)" bFZ#hFdѣj1cb4li5AlZ"%4Z0V5*X1RIb1I"`ѨƱV Z1I(kb*6ƍ5Q-*-4RQ$ͣj45%*MklZ-dQe-IIAIFm QFK%X[ 0ςFBٞgJ6MTKl;Uc2R;T(^ǏV7`,T0Tˋ77GKX5DE*5kY4MF!)+ch6cAX6CD@4|Q_{?~_me{R&bS`C6&L4Ґc QdIF#fb!+zݥm@EJZflQc3c:W{A>7-S(Kā;Oȷ6 y^*,H-)H N~SiVvߞ"& MF aj0e E2B)hL #`IK% E$Z(,ȨL LlmFB0J l&Q2d*4"!KI" ("ICD )id2lBA j (JM EHA2lh(- F"eBA"%$ل `!"*#DC6FXх4Y4b* ( 2HȦ&4Z)R(ؑ4JBlb2AA%ŊJ ((&31I(DE$TL16?KgI|~UT0شJDĈ؍L c,bFAE\ۘAș(HPSA *42I TlRDX,f, eٚJa%FE)0K) R  B` `44i1H"i0 lIҊ`d`\ČPf DʖIQdLa$ L" ,a(PҤMfh 4 P 4e$h@bDD4DҚf`$0@Y $2(`0dQbwz&6eU)9o.粮|AwA;tDUFK-LbƠa^֩v7˱fU|l%?d_{Ub(QtsO\Ù=u+hED9Hu乷K%%k%2%(HLLQh4L#0M!BPflYHBQcj,l QFِ@CiP"H#hъ( #1I%6YDb&cY "ɮu"! "eNtLL@J) S)6 !Ɍ P4TRhLbhjY LIMr.3,bF$jPM!B)DTBD 5%5ɆLICTF dI*cbMlIEcDűh3B $&&L(Hɔ6(JTQ`fB`ca 4DcA5TDbHQ@Q&d:&QLQa64LK 4If(d$4j)b- X*J,Eh(F#QK a1`(4jKA1oO;T$$%noTaҝtTqh(HhY*Md6@,4hDF4)ƑcY,QQQ(,ă+بL@ 1d"`2j*jQ 6I (i(PAf6*J*PI- $bHћ34h,7&La D @Ab(656MPb 3Q)f$эF-CDDE2L(A2R&0HXA @*H6-bitˣh6E2ZEQSYCd-M&Ʉ-6ش&m34b1b3 %)bɥC dPR*E1=W`îŶqZ\7!d& W3CQxƝWxޯuZSc!D(SDɶS:QE"d&44,bMSV @ac CPF@Ԅ1d) )OW{\"}~{B ӵ\:҈ NMbLLj(M5YD޶f57℄1k9X. "[&=$xIQ# seШէ].^G>^k697T@Ym3p8VO'Јm;GXf!(C<|}|}㈘5} @/Tg{S %( % IuyŖ+j[Kujz~׷p!~xxy;>vT<AI6ETD =~rQA?J#TyTQS"HL*@XՒXU4 B()UAPC]h?_* @J-5H( "%*1 - 9)!(+% 2IJ򨩅QLiDJZE2[UfTVSA!&)DkVV6-ME[IJ hU FhU)I eP*جZ+TE(R24"*$)H@ЩRVj6Dژڪ؍TmQجV ZUljŪhV+EcjҋkQkEZTZ6Q40H#EH4  RȋH @y͵xE%Gy"G_U(2R HH@Rʠ( BdKBP(@ @H4 BjԂ#"B U"Lԩe "6 hTu A&@ҧsjbR h-FIvi yPEfk:4ʼn/yazy, oÄ=HJ+'L0|Miq{R˼? DVnTI$$?&~X SVhva%V.a4ЧT2$m65W^кVvSUS.$B"Cz'xe]"U"6wgVAm˫?Cw}oɀ@-::ni*HXyv`$#NUI$UłE3\c*C{&U͐7Rb4G[6A9{OG1a7SGa H& %Y@>*ܐdr΍Qt)yGqD=WrVĥ[EXf/R|1,\󻦑ɫW JwXq>8aZ=vdX7iA!C tRTO L9cWI.7lf̒2a?{MǸvLe-.iE9ݡ B$HHٌM.GJ7V{T%\U\Y<1m:8p]T ˆ%C4Tj7wwvwlfs]uA% c(D0:).q}5BU<̩NqP~B(Q((~sC5qRxh /bk 2ވCDkrw/a0AFbC?fzwԫ+q4MƢHmr.cS7\yS/]3&0N ]ʊhzSxosGl߭, aIJSbZM,4ut\K:w`jzRB0uR*N&&h_pn·<J'30\X ȱ$~S# WL?^JB "Ђ4&Y}XtvJuLv~ݰh.8a>yI[h2mo!Ri HcB(v/\9 (jT܋$Ď'ۈۃ!U!l[>0|&n"(**Bbk 21E$en{a/*me_zw6hELF,eF^]ߜԠN὿f?[5H@6]Vp6:_s2!V,$(ND@H@Fv „Qa]$]8{{v$[`F,T &saW%>cL>LFyr g$Wt%Z k=/EXYU2̢ 0UMV3eR`$ K2JX $qCro}S"!>@=쀀8'DED<{?7'Gp^ JLl8Gld\/zƊu@$?`5TzGCQj3 }D o7 0DEd9%UM )^4B\ q# n8 I5WMXENf!\-@Bļ.1~nLæb񽷭[B/%-$+@Nû{sL8K۫<)Q3<@m! p& bh8Jn:[h02`YC`α-&pmdȦs0~>U@ҔQ rFBH^U_W@6nVb,<ٵit$nێҤ) *d.ϧ?C|Pi%OS;"r!=}ǚT(0m^t1b NTJ""m$j!?j5Z$JSF;0D-$$}_p.\< |4Hl}Lҭ)"<a-dad[V3hX!ZM{/ǷǮ3H!0WeT.hտ'喳cUAt<>][A۳1|O$|oۏup7syÒa,lD׋b({WH чH#h}>}BmJqvN* ոByVuL'H?ߙU3vm}/Cu"/[P*8]dј$dӕ*ek{R?>1(  D$R,z9AO@*O9a}֭6beǖ=P1-McCO͹Q#ͫJEl}K3J͘d SS{u̧ rmy+D{aCٹ: yK'XDDDPɚe"l6} v}>Λz׊q/ m9aW> __fG};;ֶ[g˘ 2u6bּ{$ P @5ow;̿>=]+漫{ E(,n)QK^C%\ 1ݱ4r53tA.wcm@ *S}V6 n/TPENTWgھz =R^R#;VOCTx"<>-.zUdH0*| mJ$y^N⋦.gL/ݛ&;,<~,:~/Z.GP^YiXf O<R AՏpkWXSo]mYm#32!(zOÁkT օ8H7Dm <<5Q r@O܀'hrE4 $.^1űqDP}f_@|'<G;҉dZg\nX?p==8(Sb뿸ePS뫤QDD a$P0~?ޕ?0\yYA ~b^8\Ƣ^agm EJ(\shKbHdf_뷴"Ӭ޽DQy]ÜnwN@UIIFw~y[䙏îKDjN)(I! &ψjUS3L_ e{ ݧC֣Upsͳ0;x0HGqJ˹CW7*i5K.T" 7CHP72 =Hpn]u: QMͷ^kul FFI!?w6xX舝TSN P۶PW+Q>ǠU'31*#Q2rx EFJd

հJq}M J(,–kbպ)~ * [=NjyhUk&QCŰ5Ķmw/ h*Zk(J& JlV ]Rᶆ/?*e`ʴI5N{N6_4qveAݾ|݊( .T0T ߽8= @:7z}u?scF)~i3 jswW⸝L]_+zط\7!1BԠu1MTEJ6.%~`w %plq w^(ZáOHDЇ{"?PM$:_FM~;aN)DODR>|PWwcu3zNc֮_dV2vu Xbdo:ϥٿ%6>FOԾrg_[{ʚy>xByf-T.?^ Zߏc;fÿZD6}5=.TJZhV kϺyZժTVUPw ,e|n]y 5*B@$Ӧ5Z du͎{Z$9-\o/W#b ' mfDmڀY* m-DG$'B3BC5ʄ4='K s&ܷMgm"+ϹٻG'f3Zh/HBR4:z<0݆7.cßze1w.z-CyKg$8JW:Τ͹v8*t!QoZ6 DC]ײTM/k4}yWFɑR6!~x-3' #_k]"tR0mT[u^2~ XiJg';dMmQ]ߥX"~QDmM/jovQO8gi-k}7OFhb9xR XL]:__U޲ n2_pwy9NⴈV :.̌/4Eq.Jюg8i%+"t0Ut$ű|(|J4W|%9Jui2ƍ9+ڌNO(\7Ƥ#f͞q?MXY>g`V0NOwvz\_zִUVմ0sy GXy?> HTm2"/ƃ*{[Fn*'n])ηkt1&Vy\Y.nH̲e-Y\ѓ*\?2WڳN-so X$+`}nXz_i簆o?1w#bV>Qgjɘ ^wMHD P#h1SJs_qq $psڲ\C!V'>ýW!T8(1Ԡʓ&}|qڴ1il>NwoՒ _sˎ~_:v.X* V;+ l4CApI79} _vQh\W/'L[ńvh_]6C,6}ȼVZЅL n}hf\Vl$mNđ stS(c5q&(UZJItx{V!.;T+ ',߲uG &RkWXpS@IN[8TT/ejH`F~k0?7G<dJʳʲBbPM3]K Y8hpE~e]eM(QfCu3@֎ӝ*w/(ȼ74R}~PO:99QvV<#O܌eX2‚:>+>NCd -a: s2!.z0೤)©w']'{&Le+)HGU5'7|De1.qiaU7bn~ YWJлMKGEos9|@fv]LR^'1>+&E]ds6B}ؖZ7o:>W*-Z}FKl~VÃKhp1ejy;M#TNdٜ/@_27*|I)npdu";~b+?LエnaDmi[V8ơghu\1ye!5?(qJh2~Z/v1]k` HaG%7̕ڇ_$n>t)?emԋE乴|Yk{5Owc}1+suW mKjO3ى4Ƈyd#Y4ؕ5}JbkuWaZiV9t:N*1v1 %t9s kȧvL ┯tL4\,u R"&G.ⲝ90^q|!JVVC9goN(1rY X X"7H)0V@+2}h.7*93ezttBw쌚wܦ# 3&*^[¿$J2=l̟Tm 'mޝKŠa @Q5{'H !ԗiBb 嗕s-Z錁BTexNU?[h3OO˫mSNq9JP[Bi%hxI"?qᕷiYpl;,x̍&.#(*/* `qCp<`cuwԓUd(Ukp_az$EW G|VYdFBQI%y>!yѴ,C{FJ0> wAho!u#>O-ݼ&Z-^~n) uLpEꢴS| 2;@Cx8B,I1!?3BhDG79T/m8)~"e@"#+}jU ׍Gp :=Y\qEogRqMPow,6y()?:l?,I9TjKkzfݧ5"ć9i=А5 :a00\oui&.Jug?lĬ `-hds2Nb7׭wI}*N:-hHֽꤞtCԋ|a =I C]~23ua(eBF/xEw ;rT~Yb͢{L{<g2>0d$pѰJ>]蝍>ɚ~}Q:uz++LLq~FԥXNCMXqUV*s*E\{ J~;NUI{ #m->VN~/ uOG77vi1/Hn+ F.5$!oGWO">g̘>^Đpk9dEf(;++w.F|^?ikHQpuro+*T]O)wXRdn=h69Izv2 ]ܔB޾d;(VYKNlWVRӁWiXн<)$5 #6__̰?b imig˻=.f|R/A(z YhC͊d4#$@F)k} r%_ig5%ތּM8\:I]gN"fb*cd>}t3Ԏ*b=T-$XOjh:1gBI?X!#z[^ BB%|)Kxs t/Uؘ\q6pRe@+1d;ȇ{YO,8)ƿT]]3@b:4.f ~sn#y}II|4xTrÍ Mp%Acu2WǞ2 0 Qé&ž ]5*7T2`Mch5~E.`^IBrE-+ Ws㴙sq"&oyjVbge'Ϲ~n*V9=3:ۖjf2XN<ۧa%̍YY$&8kr@FA_aAH'f $bbO.cVo6X;XH5_bNo YCX.w_(UVMֆ-Riu%L&݅c5 Tdރm_u`qUǽOJ0,abPc|4Ese/$ ~RTVnkvdȢw!Xb{n/U DoՍ㞢bE <~bSD߾LT+5b/ؾ I:ࠟQ[tצ 2ɞ@2D j G$W0KR~6㠦߀OLd|*+dK/0 Abm5a`iR_cׅUHOvIiy8~|=U䩼N4pbp~!GEXfUbXRfzVQtm`Pྙg2]§f]'c~{phD$N!|:6DbGn$/?N# HR߳-W [_ReJœU0M \ oq +wLB^cI+P¦;aˮ1Ac[+DgjFO.m@e~i9w)wd )Hh+;gzFɕbWQ#5F6 f+,[nXz>&Gl/"qyM!Z]n֘ Ɨe0˛1ll?+wL5ZC4}+>&F;u)y\Cfl>BMLܩZz(n~0)op&^GZ3UB7wft2g0RNiP~֭l82WԏleFq.?SGC3Vi  >FufN /|}Uzm9C)G˯^uZ= xn`7wBBJfeȰJe~źaktfz&~ ^'V$!VW+e|Mg7Pe:zir&TاJuiOH'Q&CYZ=ϟs oPoP@U۶lqRr1QDoUאU`P\CLdicK[b)B/OdZPecÖ؆|5$6(e>|k=Ͼ]Ώ^>SA+K\(N68Λ [pvxL~^.iTKG<p _8iW!{EFRQb:woxq Ed 0ƺ/9lWSqBHɄ 7Ǔ{O)DTioTG|)UD l,t0w*QGMNIIV_Ra(' R`X+AEX+vh" KjGSo'a"z3vg"<#=J%{Fmj*9[Mfpk'2 c  ?^f,Z1x=r1^4B7lU5.)80ɓxI ޷4Nɠ·Bf&vEtho>C9PJ__QKZ“am(n=jYoȓ8oWFsCz& 0\:I:ݚҗtƜf%G&*-@O@Ll ZL>:=M=z>}S=g܎b{JOS]8^8yg@ג=?>(P<Ж(;zߝw%0̊p0_zpIW^#r/9\-1=#C ?>!q#kvWy4QLC.9K%# ?I>7lScHBf$B-c UT){ NgIl* d8(lVay P) {5$Q!K}Djt$\=Sp041肄=XU7=n$)44-=Md*P^2b}Mb$D&@·(/^GEA _ 2;/ߨr=E* z!e(ބ [uɨ䱆XY+J}b3vXЅe##e֐9Nhu0WhX?#4FzXKzA AG.7UlN*! ٌ)p)4oc%#עFG}mz3#O$L^@ţB9]߸U2$/ rOp2x~L $sfj/eOTuqJ]sݹOrufyVA1 A~*f =uz}sDhI$'c6dPIβR+042 ga //šI}(UQ' ~1S+ؒfZ'ŷYݩ-$.qh«<{ѷ]4p ׬4j-KwtdItP w=ayCߟs\g"TИgλ>BZm;'/k6,ngrwmb=UK#ɥQl}bf!4b]9|2Fϩ&U&VEP;lޱ 7HHї"GM}_B66DƁgq#9=Y%L&׈S vچq1@˶W*fj=Z,`Fb\!;>K'="'_2z 'D]G*%lg#CIdvOѪ>d>cKX_XvP>n}w\cHqz_҉D\k` b!o`2@ jc?[|5~q?^ Qmtb_!"%A煓^nguaC+'X01$?R`NGQV /ɡ RHAᗯ7h18E&xBGʖl.9qej&Ֆ ]I,ɽ7n5_WnGךp9q->E` gd˲2ty/ "x5 e=GgO5g he"D}̱^=.if+brCni\wNT=ɸ< rkjrQpmntE@mT1pUc *+ ʠv/iMvƳ(IUث@S;)fFU*4;H]ܕo'T Cngڡ9R55ɽ?Ɉ]Qu$J$ruM NʡLr˓lKzm'M$Yeuc$UD!@%\W4`t4"66LY@ cL2oS/Ox[~Y MHHrft2-+8"k8}6/)}xM::*_tdf8 ųlL)<%$M4m#Y;Q>7pNv{[C{> Tn<м0r1X RgGsInQVEb jiz` ռz a(7C^..\Hx?gU2+ݫ>}T-|mNH>hYVN Ӕ"]HH9Tu>]#)^yFRXX}O8sgT";W3V14ɯg6s͗줧 kN[Рgp ԚM0cDc,JHFQ-ξXD8o-DqlQ15M"C%.~107$p\~|UyW9Yh{]O/+_t$4PRXU綰O#w_&颽 R\tfVYCI-:lja-9W4H)f#r=h{C}'ʄ'^ћ&|S}WYپ`Or ,ǫ59:Eqk?0ɉiR(-HwY/5 [# #eHLViVOwg m9qy٬ :HE l&'[|qG9>ȱس28ųSDTV} <7T~EĴ)Twic$Pq$_ٞhյˠך}Y ׯZwQpgMv1![*Lֻ f}3NGsoW,PaDdٽ5n#vfg=$Ua^ >I1LIjN.v1@7F\{φ2 @vG[~: xFfnYS6GIhKˁk-$3t-@GL]k9`s0{[Qe]$&'ک@Q" V'lʭ],'k9UxbmAAc\*dW~˜0OtrR.vT CP= z*B/#gB wHٚ@<޹`nb'*YCdH%PGu&G@(ba(Tk> LdMxٲϓHI} O%4*/iE"v=pc~>!*@w ׽ȩMo=^ltu75!UXV n1%"VKl<9YSDagM3_?2.T{}V"O\7R/]hTՂqbv̪> T1_ И -M\?#&#Yy)W޷TP,ceS.Wg&U0Вvc}j6"PjWd,Tt.-"y_OgR~1 )!:X eJB:TDBav+9Z YM%-v"gХ0j~8V_";2 hǴ䋅ŕl;\|=~@e&[+7>oǪ\S| UpV$񄣁5/\k_\|,`bJ+u}2SUD`muw| !}H rk|{8g VXwbq &Pv+:F@Qlk'o[{eF4g]jHSkJ"<+5SFVάzj#$N2nwM?S^K\:Ip32A|Z0H5oZ߃ Xe(wFJ&/ n0p x9fT1DnwVKɆo@@9/)~?xz5$ywK,,:n09}@[|V;JFm26}Q*'\o?oE糃Ұ(?Ekg(~ Ki=NtPȥsPPzٵݿ 3FC 8Լ0(s5$cDQKUfFǡ|af2bO$m^uoa yST5}F:M D^PtF29;hX` T E\J>ʌYMY޴"F/=H{XpCH1jfٟAZbv~%U p개YfK:[gzb8`h"Լ#zs wV򋇣/{K Ah.D@0 |۾w0#Y[6:$%,s@? ryD )`rޗWE#\JVwTNCf~F1\7_-xc_#+J7mR蔉 <_B~&%EGR|[Bd%]][.cFfM̿Vkx$fܠU%͊MIz}dĒmЎlE:ץgE*Ү=Klisd(]P;k[Q5nq+ Z8fQGNA3*LVo\(I̴,f[@URi@C% ߚN*Mo)wΪAjH#Ŋx-3LzMtط;rNZU xZnI0DSzq [W!aK4oa; y'백y%w~ͨu h [ynN^UD`~L3s[C ;3doj1|3Ԍ^UZ"-h0d &mZBgoY˝"' h69콞;81{1fԼ ufȶx( 4&r= C1rܤU*( C96r!%T"8K%Hz8eUѼ(917^_B)O5,N݆=_r26Zpu1~P5 aϬZJysLHʫ@= e;h<8_cڶV`0x(7! {bC4ZK;b%͙>Ǹ68Ҽ=I,1h6>J$;5jM.Pkq0Bb) tPFs1̝W=~ؑW-~5:e[W.* i.-^8RDR!(F}xBcf9FJ PQ3O`#4 (gYa1-waBQLD,` 1EBˊVf\3H5Our ̨SZp#nGA opMbdbG\"[+xƹqfAvZ>ƉP'cP6Nj$[Tι.uq3_A_1D:OFҼ*{2>B Z}pRH+'1wu(>!o*dg%ç`+o~7a!ɗ jQ!H] 6n^)!k |gg@R@BVq| .Jyr΂$rZ4m;}0-HWmL¾1UvfQF8uۡ$#r<4j =7l0$/xywY & QLp{~> єsSw#7!@Kf>9wzEU}DrsJ!̏pgxoP(9yAL-on}s2ipeaf(l!:YBk s P`.[VC6x ,Íܐc>CkpO:)D|"HLSq0K_ma˷T^N~_ՆyrX5B.;17QKA.=[u7 U o$z+L3Ǽ%G2?KS`.=̒Ð4Q{snתNx4 C9/N4d/|_&`8Hu͡qg{vS_e^*QP#\uhG̳kTDz#dBN)bd_LʔTa&ոe0]B¹!0df3Fcn颯&J|+\t S%.յEGp‡J搸)V;" RwГ #zH"̀ ?*;gjw5wh87uTQҮ~B^^KgsMNz[bG`D({/q?0+]3^/,TX*9529wjx29СO#&`P QZ}TcTʜdo: 1 sA{W,U~Iq;nAc^׊$ߺ?- ԟgc4'W}3'2)A=u#z}^XȯC D \ }ed#Ay_e\l)~P ৮N7+]:)'ˍ\6A{[AQ$n'y|Xkf}P[ƉJ:C\9G!C͎"Ϳ+d@.4Q*ÛAH6[åD]LAF͍CVi Fq6dN[ wdMb5]v̂ aIXVz k{#z E7[Ҟ 0ǻ!KfA 1׿0Ci; QN%afM%6tZN j)ԍHŃ7XXRfTq]Zn Mچ&W1+/0*Mdϐ[󶝯w3иԴ?rR2 {FPiu(/Q352ط/mCxN}>f!nIԲi[xS@-@\xM?lHSu$soEGɉ( Onj#B SȘfVd VCvgo^nd/ 0ǽl87fʫ8mmzAiJ*$@@ۇX9(Z82@3{)bZ弴{ DhhȿHʔs[~+_xa_Uʫ[]"6Ӗ|d, J}ɹX5V4ÁR6͍K!ftz+} P'0ov!St$B*GgD-SFnR2v=N9MOtp( zj=^aT]t a}*}Uoi|bS5 " QN>{pjO5Lz ) huO}llQWNw^S 4-W.K‰vmdfGXRTe5,ƌ뵙i^膶F'uc?{:?aTћAb3Sf1j q o+}9K784 ڝmOS s~ ncaF#Tkjx+ގsއ% j([SEqU{(b5դR)%j༥jK{V {ՄU1 8x!:'0uim#{UBkCL?|R|Yc ]=7TZ(!޳]bXVƅ0n7ŰGr ηQqԼ@¼"`rn)`Jbxq SJ5b|eKNTo3αQ)zHdmS:=e ͪs !zl:93Ic.T 0IB(>k$^SvkX`XSZReНo%keJ&效IEˤa3B/-Wݿ~lo8~:EL*@3.Q`РtϪ{#Bc{KP\Ίt \@,|@TE w‡GiRwb{`, &'x Vx6wK&6lDgƼ?cG5:']f`JSs&t ]Sy0x4>厃"ܪ0_7wBo ʋl:;E$J%Mф5/èy( ׁ3XX7՗;T_x !-WёC1u }9ecg* m^ `دߺ5YGܫF&yLh]\1sln/?bɭDߜ^>Tוb>) 3E>n3?w}R-`ܽp]'O&ȹzʥ?ɺ{֨HdLvRirNRWkae -3<?@m~5/A"X M`7k w9$Qu9 q 5[^@tvM+B^=cLn[3CJUoY@HMݐDSjĐw=*1CK~F:qh%m[H )pG1)X:0aƀ3)j]%DŽXEZwi\Y>Jm9\!N6/b8'+'PSFwqt"O=+z "ʤ3}4({ A/h%$!9X/,)Gn}- ˙Fj/41O\qP+yv[|BtqDf猥x8^On ~q9uمr=KJ艵~Q9RbύR49:>J3yu;z .HVO[]؈'™[ 6&wNJFglrAX3%Ne2oY\݋qc$=&Kk,jMYI% 鱗lxYD|͟+r=SײQܡw<3V%qauݲ%u9 8DZ7 ƆYPID-K,$PŊl"|  du]q1 zr'Ƈ@r@#%=:SY+o>$HY(zt,0S~ϒT,H$ѦV1sPKw[[YɁb jVowLgJr(y&ЀɊ мq;D#kg|t*V(!c30#cb+)s8SG6~L@1N}Wb:Q-t{ġ) 00pa?*^R,4in6$gL4L^ZΫԘ9pz{ynKs5tS&޾bx)"kϒaKպs ,=k-6۹@ ur:8cyy6y)Y"~(DY1*VK-}稗J}DBlD7t(J;t$if[V7WsZUP2`,,I!NU[DSr6[00Tdㅃ/]ڥ8?ݮc"o+2O'`CDT@U P҉7J-_`~5AphPL(ZD.6kɈiVJ\(;/, &ab0d7#D6,s@zXP68Z&̅Ootr34yJ\X*y-򌩁,F3\sQ,Бs֪&5#TMef:B$I0{Pzބ&J@ YAbc|i`2{tYO{+rn 2ɁsyxMX5ݥ ­2"*4:JY2g&6m ]-`5Y)V0;{ݩK'! ֗[')~0ل˼Q'銞?[ufZ$otP9D=qx}UI)ԜbG}GŒy3qtoD\VT3X"J\֢}BiA[:[XBrs*:SY绝RG(R!1x.=cl_ ˓jVY{sB卓Ӟ&GctK7FmmU4s˽翎ܨaIy-wAFfv`Swhv3b^4 \&" >Pbs~Rz`f8['?`VQ|SQ1>PȪ ƳQ nY 8- H0VAly_'$VY%U \h4ͺ<P!G b]>31G}N|͓aC8qq{?vw WSKhs"*># jL-F☸(BK?^͜XATwa^z/zpl:,S6&0|Fef0>A'*7+ʋG}@=,"WLe0FTRX() "ťBŰ9Q/K 5sDB޿ί2MRO-t<3 (gȹ5'9t*Ge:@0QW/Lh3ݪY0emVa.]'(<Q4 ,J\E 5|krL`M wǎ[MPXrE3CC7"E]xH1 ͑Q0w (ڇB͋ŋN햍] t\F/#COqxp66s)P5/۴R.52s7)LqZc3 J' ?CH^|ZcFhh >T Wѡj%ʑAڎA :lU `Rqވ"tpYilq}r2cocwWl&T= M ðQ'-14V|;7-;ܞ 怏'U3@a(7~缻%ڂ@fLWvD*[^_'Hʃ?S 9+WmnuiCޒʼDe!PWZ* 2]!]}+iysBLL~6z+!(0b I'JN}367\!+4 IUhQXRtE>#Z|P:nrdߞMY(SyY zɇ6ː?UHE0GsN')p;~ t3  rڱ~pHه-;Cg !X֐5L5eg}5q`l*f3(S:d@`XovFd"> pD@v2qޗ2-r&z"r0˼2Yv0GZPƋZ+ 2@|ѱA2oA+)X1hTm"Ruc(lXDa]4LV$к]ݞ@s|岾e]ٝwhy6ĆhDڲڿͬi}aJșZb ܀꺪"-POїxȥ34ׂfګΤ%hqҦ&PʐW, i@(Ewc#x=rQf!(g\U5ҀhlW.#W0.%+ @xA@UIR5ϥX8r{td6zy!jɵz~z˳בՊ6?6y.EzA$./], (-!y&`ra Mgܙ7BOؙ18xc[QWChYx1B{:IU.k,fMB03󸳖\&UN]~@גD(8 5h9 y)@ڠ9U8))&Bϐu6CLl=bϜfYs[XKV> )*0@iMAF 6_Vf*F< !ۙuySy?FmjNӜzz{Q-KfO'XX.~*N[q̞!ۘU;oc-(⍜-HB ^TB5ӽwndfßsU2eI,Lj_ƤP \,,hfAAU@.*r܎!yJ1E%tMּRx\-Cz.Ic.p$13߽MтB.aYIsХ&&3Wݻdhq@anu:7c+ɭwaK(Kg˂Zޝ?E<^Z`C^e/"Y̚#%j*=A6G,CmTr0GmEve1J F-,n_5?(gjK:C-e(!qd|VX7:A_EJiy>vo$S߭t& _ő߯ `p:_Z/^^a αa8 q}l hO8G"XϚءI?^üݯy"jG"ć Ϊz/ R9Ӥhk5+|i8HώaF=Ff.j@jh,Vx[/<hC%`A^m꩏qDΔʕ^S#&^sݶ8Qn^dd &&WQi /CQ%'Pw e&[jUVe9ЌW%G1!./G`>aJV_9ėEɩwӗZ&5nTqYͨKj'2U qGŎ%(]m$ug,!%;`Ǿ4MǷzHQ+*.WSH ,2P A8U`TOE d<3Ͳdry܋ao$xܢEѻ {9=%-ϩ(ʼnnu$BSB7)^7܃{t\28J/9Z?4JοE>U|%NEidfQ]4PJ麯 _@+5cA`R{=!n.(ţ&kCY;@rrj) lGnH]{3Kz,$$Zl }qyT8~qks"#tl@X;R<%`(iUmEAgNGYSr3PO_`NU9an5dQYt6}f#bRw4zKϸ#Byj%I &;/|ݝ^}\e%( Ov96 *s姛od\ cJ'س/y㎆^Lz Z-w.X=Klj:JZހ:T!0j1H|gtc lL:7`=1?Olԟy0L >BKf3ʈEFV9UxU]{ydwÒ r$x4?غRe;Xr[}c#,$=T={Q90O\ZS2bGl1h JL_{m+^[4 hȻg-̝z˸,gsr.b\a/686F$ԩ1d\9kwԟmҴ,.L$~,|y?q9!]7#T%{'ϏV@aٲָQy3=p (BN40wrh)1O!+Bnz6@l|^tڬ#[-yd~mQ}Oha?C̈Ƿ2bW_8&C>'U)ٚU(|xk)eV'mӱ{B-n2qxĊZkv@{I"SꇳS7׏PE:}V$9ŷ濜S@T0@%MXs'pha:֮Oѽ&3R )B$VlGs?͹0xY?ZLiS'*pTKVU{fPStX5NjdlP8vj7ۮ9xjJ}IIonVٜC,ed9]|+[3=%?^w;Rd[N@m Tj-J'|ZxK(yd󽖰*]*PҐb"?Yh#86QVw5z\ayБ_t㞚].k XǜUf ] F][_ 86D)Z3=pL=4ggKҗ*2݆EZ0TU*BnMuYa{.~,4r/Ns3AҭF8LboGal޶;(/xm2M= Z2ž ӢnG:^Lc"X"x!Dd$Z ЏJKHgUSVXH%m^yT#3"׏W 5'\GeYG&iĂFאW?u/:au9t>O6tmjJ^VB@N&x<|^ƆKܴ·:gtUW}@?:"QiJ"7KXQU (R3521D6j[閣۬0'\^D5>#SUVt>쭯YGy@?:/AM쵁xN y.JK~gd7:y VI npWdmkLgPFQBa ma|l0p2Ǽt "!N'bĎʮ2E !'e=OQpr[X(?#nf0$ZLN0x5DSF9|w`V+RQ"W= j}E29- ^l .^a]ݓ|׹gmAyB|u{mR/g8kػqߡtDaػNvE8e2cK[9xF$>yݛ<_S+Mb|'FAgq;c1BpKÓ8:K{ƙDnaOꇗsvo,Ťo|E'#5]F<1zbOH&bG&x,+pXFxy㪣躟Jbj5F6"`SQL~Zؕ7`L[ɑ~]O_t&_+ El"hl+.O;P_EkAUP0\et_o; ne. ︊c5yW.z[kqVv\lB\km.SKM4֒CpS[q#3DPS O>-_I5?LXO#:cSз$Xu'j30kN]TbShAws3h Y|DH%& .fM> -Îu`<4Ϗke*=`:^@hFfh'b'nNދ֜}W\ʝjAhzsAپzC#0R@d!R­'D+-SS*;{MMĆN5bZ9 Q3էLד*iA:zWy%R )Nbo%EEGE^#ԄK9E&3)O6s8(q?s*Kz(iMwꅝN6BIhQB<0r8'OrS~?A2gH1 <ҏ`zSP{UƒMaSѾ[0INL*\rqSa+50800q/]v7Dn'W'ˠi>T77~N{Twad܋QN.U RUJ ΅Ôm0j,]eڐѦ2ؿ;~]_eLp#5+-!t4 6h٧<=?>, ViY9H K[ uvrG:[Vgow]^8v>*(2tpPN |$zl SQKȳ `N(yg_Camuy~7 "J;B i7oL"yt󋵄:)F[ZK#VK6ijVg t Yg Cp q>EGKl1ps]͕N]29U|uHnc줉ޝ+L3\ -pD@8Ie<0_5/~8˩yi $ZF]uG L{%';-O} /+ 6groe:my+pڙXޭ.çujڙ=m1ND7YG,U#O%vvOX-Ș9ᢟ ,QU/lP扵?H>1x(J&U~eOMuc3෭qOw`cP%?NFbAxreRA2  n~vۨfsP&a@ hR5.Y #Q!hvY) nlO(AzʧGL`̘[i 9r) ^U_9SK@8L li0̱'72?B$_7YΕj'&K3jǶa;?My K0 I Re >GW]#rּٰ،?\"̆J, )`V˴I0hI%d~b!h0H]1zHaV:ݦh_@4n44Lv&X(FPڄʉ~Ϯ5Z]& K9zl ݏ@QC640꺴8};ϝ>5G}o$h"]B^y,=[5$'x^ 2{޷Jo{RQ)<ģnh3`DOEž$^8L~ccHS[c<с7XPB/N$.&\S =D>_T5 ߍD~P+;y^q0.惴G+ fVt;B_\5Nt[Z2_j'Չ9(ů|R =Sp@WWwB F}>R2č̲,2X, 6k!GbJs/$5 _jw2C/fg Je麊MG]>(G`NO~rtM4j{^;N}rĝ=M!-A C1w V@WHJ[zr! ]f1ve/w;gl9gX.>!lF=4+l`]{":K_IRhVOUdGgZ-PQkd"F9UT-¿p){\9Hg,ۈ?# Z8F9Ī|{zA:GbU߸ߍccN0p=bqER68杆ތnKybJts>dpYh5-u?cH {Y$Xx I;YM^(cc>ע)cWQ 2n {#[^ueSp;=ZGUlhQ:y:ߣ߇IKQU)AuiS-`7l``Go2ϗwsf: &P1dQ^,9|d I7_~n a:*p܋[wˋ*Q"0JKLGpd2۪;P FKIx%g@?AL.ŜX2ѷa4jf!#4Z+Kg6Xj=.UFyhraQԢİQh94 C$'2]IFT"8zTc]6[+}{!z)l,26A>yE!a}UWH ssLqr&kn&WPXYx2YH^l%Fϸqe0DGmӁZkTt_ǩk%dh1w{LyU`$`KƿZ^dalW~(i PDXԈDLgM"4a٨N N-.@!T~yÍZoΑ( L\ldc Ft2$k/rt§Q!YQՏYVfB8m9FdwStd3C6=7w͸~So9Ch=#CBh}{:RMߐB8- ViU`9)rrP&Z&p85f4Y{kWWŸbl%kwGՍ4p_Ѱj67if+S6Ҳ燷[y'0WΗKRe{FLv`cMvfeueNaFfǨFaU_2x#p^0TIfN݆4w ʹ{MEYiﲠX'6j fw,O::BO0h1A-S^-RQi]+tQ ߚ0zw޵.E2pk-?c$As$m gj5;i#`cg1iȺw_@\-${PZyvUG@/mc8ߧE > |sx{6_9HFs貫XD84^ȳ"֓ij.oo>7>'/LoNVKsjQv㶪L ,YwXѤqݸ Ly=B4neQ5fQXVLm/,r&bg&!j.=H8d9s0>ެ@lČ |AJa2ΩuxŻ䝷g7 4K=}/'h3{!-e3K0x GhH#0;u*&!se7Yp%DL 3L^Gݏk9'mPWj-H3x2D U)Ƴht`D g\zֿk_33Pƴ+ZlWslE=Sf ;Iz>mI)dxuQF(~5;Bއ/s)ԋO]>BAȵ, D=&|6a,4&j\iтcE+<]hMB&Den&~@򠂻Ns ntV.=:+5keNS?VM/5VQhZPFqېA{BeZԲRUC Qtn'_GILfZ͞Xki|=N@;V8Ѝ y[hQ]f@о3ik瘟oawz{1ij9b%.BM*C\JI=|@~rQ $8z*b"A\*~PnyO{Ac{ o ?YgLUy \aW+FRg7lCbΏΓPFx 會{0(P6Ɨf*YO4OFz('}ƚd\Xmw٫C7%Ε,TA<2W:P =8T7ԞP,nȂ]7'Hr{p/u?j qhC{o+XGVF 2Ѽ%Aͨ OOܽw;m<3ݐP'J0{#IBuބ|IOɺ™qaqmhp7#3 )T4b{`TуݧkG =fM> ,c=ñP06s8W2J'}Z'cݗv!IKneSfJ1{kd[_E͸z\y{/{/,9qdV>.KΖnBm/6BɃH"< er7-W{ⶈ.k^Tz*N& DjU"/+?P<db&|HW}F,.i4Vѧb\@x m{A|8Ѕ U iDX׵)k48-r -1}TK7:ucNnn$3b;oW o)M$&qS:{T īxvn(^̢CzB|t$cz.9s]N^ܨ{\ n(6)%>/g aNh ^ÕX :MrQףaPﰴ~Bqv|w-k.<G:R4; y["ƎZy?fm(T2}0Dy{xmJ6ș6m="k<"p7 A0%.ޓW^ Dr/,T9Q΅ZGtµ ^u/H <՗E|-hKռ bQuF%+"N9 Y'P`RYYJ$֏֠3$;rA0|8O9IR">EZJu |?Q <s髟 2Zʣ"\I%R7 dkR%9P*LߋY"qz>!+e͸S8ɨýC*Vk,T›]jp$ Z3%,E԰̍(?МF@jrh!'; u% "ɜd^0Y̭b璣 Ds}@4L~0k'z#2u6zf8fkaZ-'NHf ͂^ݶ!̄L14(?k򉶳.GabW'7K/pGaQA&3Hh4߇je#aK@/;c?Sj@ tN[y}dCKqnEv#֊iWqp:k+m `\! XE>"Kz)PϋyPkwWabI L[}U;č DcmEp9?󵤸dp#e2\'iH9|`FcF 'Y6Ke3c=#<Փr2 ..`` #ߕ$k81a FtT9`9"|3:e/q釭?޸ͳ́Mohun봭RP,^V ɲkH^c<_`(@mշ,Neqn"kC%)G5Sl翄 ]Km2كXyPxi!@?+"IT ;E񶬼CY>MFd))0ȰJ:v-Iw[ _X$K+װY̲B4c=d>* *.R&wFFI֓ه6(*Zva3ZP RN2eͫOh^S5LW{I#iN7p:%$ ojѨ!6_7Vs3 Vc$*Tf2zbl 1,_M7WOW05.5ԕ-ա&q[M46BIGD{mU2z%Df/O4 3ez,j;T$SK<4&Mx_KB;o<5sg>_]B~:ϓ Y[fHz?pogZV 'QG!}2Ds3Hġ*%0*(ʇjEU<ڣ߆[@TS'<v8LLJ{H墯ނJ4MnOIU3c ]CN;Y?2b3jZhyJ;z[xA$c49ғ$(}teQ&7 {iPH&R߇;n!Q!x^ X-ͮbK$oNߔL5WW M#*|D+~Y RK\>zΏ B՟g?NR:YlgCuBC蕍cqs8  nے(B<>'#lsȆWM>uZE׫֖[H=3kGy:]%]o_0e>#!jՕW =m0 ?,cX/Rgטo (>gE(I!4u|F<*!E"ޛݐ tMY&h>\>+ dtl'2_ۏ[D@'$/-8c 6CJgzԕ =is«4*@hW6 + xxMdXQ7CɉI')0|vCygm:_bv\x dڢ-xAhzaU,ݺ-zŀMa7G>y"f+ Ƚ'#U~w#~w 4}o_6q2`寱#3¬D, -* Ot땤E>;~b7 e2~YD;aC B'1ԉC ۠ ?gGA WWqiJqL8dJsr:FR= |)Cǜ7It=F0gG;o3--s] O]{(݂[7 \>uìH#yi cmsw"'DUN]8+[W&)Ðeucsy1 npi:G+f̀yː!+@;Q4볛_VAZ/_ߗͻn^%gLJM>!u "e Y_Qh89F_{MN/R(KaAٛ5$!μMV僇 /W(e ##rZ3Qy;>)6RG~fg ٭ {𕄷~*IWE _Յ~ݓ 3&.ВA7Z-vUPuڲ٣4('&EÑ6 s^ Q:1n5bBdk(ʝ'4 UqbXFvTO^q"㉦}/|=QX7%\%a=mLCκ(gou)9POb,0LW,C`Ea07?Y}sEtTT:f*`frlQvIʴndн  Ï%LSt,0l%YR)Dσ:FA*Kj5H_2FI6sU`_# kY ?g-$mIr \i=q7v°XFoT#le/zض x*T\ϊ#l6Uq>'}&?XNvI%JO]$&K!u\M(r^*$b)mY(&ɼCh&k6q45?W2B~z_BTڷ|ME@;MI~tKqm#hgPrR<4;AppvܞS^IU#,9'ۙLDR8P@<(_h2 s—$ UD=1/n.[HWs} -zC%2;UZffۯ+>E(M _ vqRzTh#^?v&@5AF] "-o0~TjٸqP1ZyHG[w m =2Qݰp[\] LYo5E$CTIsTڛkksilWS>)xc8 чߥVFtGqT2L8/k?(9vӫ1DAePS#1)r) P'}cҭ+OǤsqJ9GS} #>Z{]1Nbv4FGe #I.&~/}z]A!n76e|sɂIP2G }ՒJ6t]°m ī3<+ "m!J/F%iJ8*}rΧcN݉~ce{v1%X.ܓl3U'D R7taWQSt)’q kC_, ^ zzC:`D%b`݋IT!1Р?6x|j}3:ڣ9F AS^qoKjs f-8`GrJ^px ^Jݓr|WqdGk wKx`wߦpEK:ۯ<"BWw UÙ0+r{~VqwsUFhҬ/{6R:mF|':nYH[v*g-ʾYGGǵ5"tv9D="pc:8UXcE.Yc\V#m2깭qhu;o=tOwB%b Lo7U~ ][;tLLO' WBTE:=N޶L.*vc>T!s:xݡWD[F`ac4.ՋP+bfO)l1QOB& fqK*?RT&-nuZ8Au\ ٘LxX$(+3-ztflFK5Aq]V,I= ,p̅`*`k]db^A1UAS4.x U%_=1AuA+Kr\Xc$btr!-KނcԧijdͪsL00bф&ghFS/""/Q\1TY~ 63/⋲ D~ceӖ `w>K1 *ײmOiȞ?\o5ɱ-J 2:#劻5ӤYq&1pC-Lb_LdxJZǪ#t2) y!߫fN]KSx uRL;(ӎ W [;QV,qe>E'q**m",CPݲD9'|&1 t7-Pi/ߴ<V%JqMV?T]زW|E^nNQ`sqݴpUݦ2[ĸ";>yny£kZ-/vʳ K]e>┦*]o`:N]AWzu\+UZr1p=u Faf3<1I:qDٕ=us|Id xbVH(q~FFK]N+]F(EWc.)p:P˓cZkvVJ)S.:,|.eAn!Z̧M ,A܇)(rPQ -WHf׍Ww~tQmYXI4P`$[j?ӚrbA&G$(BoNa8m;ISĿu:U̵n;˸[݊tH"P(2HPvdEo~D[:+*G^bAXhBV sq!ҍDWܜ 4>Ж۠+ɁҾYpAf$.8 g1p.'ECy[{>nۓq]{?!~Ec|ԁޢq1)+ch^<⒒r^J_'|5=x ͗u¦d%I 63d3W`;OB:;qWOrw=ސSeἹ2l&6X. $|5ӽW'O EӦ +r}.ڧJ~] 8 R>.@! cIh uJxINK@pyS5>uYJ(<׺@Nw% X&MC3#luOy1&Ƚjla KD R_ d )gF2&+ K}%ލ-al{0QjÒ/3@Q% 9õS6Hʘ\۳b-i2F!i$QJT= ,9[EAL) -D}p_f\,69{(ǂ *̛t9TO{V%LE#xBG,;`hUثP|HO['S~>ZZWfnjv#/Okf@_ݓ;)ZQm1[̥7i ƥ0>,/"yAsk^[}d&5mVhvWm˭ýXRĢO;"upʘ'wb6B^iª'^ +Q3P= :\SNovC:sKR-T.P Y^Аv%b <\߅`ҭWW B#Eha.{(=Ssvu88$h;tccbEeQ+66402EaNΎ񎤖~mqݎ#2Fp}D (.T'v >R*e.'ޑwf3c'MXI<]e㒆qبanV?b^'=n t~N?8ƞr "(}9GhpS_݂qY++J5"|[cSo#nBI 1a HM3K/t*m!`>ʅ#NSȳǔ=y>W8( .1C"BX/߶ ̓${<@ie< ]b G[%ߖcIjyոɀߎ*┻b[aWYYi5 9 Hhjx&C4LTAߞnѕѧcD"w7@ kK)6?IX]'NEP_eX{ hRu-d _() %S~u!: *EԖe 6RÔ/@`~vujc "Q쮂{4xV:2Uз"AXI渽ͷV/R^2%SYrx8^%E,~ot^ayoY0f *$I rtP?9X/I""QyeX̏C ɺdlIz4c0pLz (raJf*5 c˲JC0wcΪTaF 8w k+6w1냚]+tͶ-콫x36::O~A5/,CVשD3.mVX k}:9A pSQ5#(L̓A)F \J0,F^Ytou)dݓl- oP 1UD>8| +4d={J-h"[Dm!uhIRȟtD#6X# j annjKt?ƜʇNJfJcy@C(4*;u"M nTgZ}7WhJ5/!UG0k86ӟDsD0h:J҃j)Zz`ޘ&6!%;u2`=T֋eHn! NOK$4&,T[/UFg^O^[3.nϕTbx&JDe2$i~U(:PҗOgcgՀg5c˖ǦR2|W$P(Gs)i!$hI- *"*8E V fڃ !YYobjh]15ZOJi;֠xum ɱ6 _pjwD6)k%U{'VJגN>rB|`_e8 m0喖->_Wnf)2O(em"U!#({WxRR@\ryn~m{`xP,3Aض80'מk ]!/% (-Hޫ)n^i$4AҢ5?l}ˆYqAR* r쵑ِȧBF5H! rHaJ|>E=GߦYD/;`)*ز_ @'-#G 2_iaE)wG*kq)k68c Dqce16 :?TC+ Um<'iETXlfXĜC> P5ʢ<9}s\n޴c)LR _j&łQ5-Ņh(z'c/Kcc3nMҎ'nR%~(jKn \D"$˓o/5p*].%X0֫ƷSɦgy#;mQ 7Teɐum5\3n T-m80_TP<H=jA`CxI+c"k>G/ _C˂x ?R_\ 1}j%Iy)S.Sno\nɛ&ﲈSml6[Q J /@Ʌ;18E XsJ]S`"]nW*(U:70zn(bk.F(.m5ꃛ#Dqw8eX^Y`"1pN}^ u7K&moXTٟPz< 藔jn0+JBB)O4N@ [N>=3Pn)Ǭ16BC lz(jt;MIH )9H5"hky=_m~UZׁYFZ=ca9=Hbs ޸=6NCI qÔM~'{]6r;e+-"[75ИRbs.PAyǽLC#} 8[ԧfDW[+ J}XOx, :pWjߛ yk:U^;Gc'xSMbZP.E DlVVJ<ש5@x,SÒGkȁrf_5WVT6fJBhtWCgvnϿ E%b[W$vhm;)Eб4<tis/ B2[!0H| i;qF D|8FMncARv,#48/Hni3IkM]a!˓ I !e %o-&GK5OՉ"v1V%.ZU>A2`,~o NLEî5e PHFآБXewfO^Cuܘ2HVhv|RR^>&>FԺte\xb*&`t)V|_B @ m(Wru~ F'ur<1[VOϔF&pD6FLe7v 4 WGcMv`}>2*%W|]6B~)vn3_rhS?0R'VBF6eOOaZSh'xVdl'?| 8xПi? 5>Z52Z$8(}QpB_m"?#Z_Jnf)YRidq{ _B؟yOY~ }8h9_^~M9m[r;g|XԎ1rf8HZvO:6ohϘJpR󰕦1:A1$zhhh;e܀æ% YZ