samba-client-x86-3.6.3-141.1e>UAP;8oK?W$jJrr%Jha۶8Ĺ?ׄ̇|>8l?\d  6$ =[qw|     $,h(((( 8(9|:(S>mGxHIXY\]^bcdefl!1TXCsamba-client-x863.6.3141.1Samba Client UtilitiesSamba is a suite of programs that allows SMB/CIFS clients to use the Unix file space, printers, and authentication subsystem. The package named samba-client contains all programs that are needed to act as a Samba client. The binaries expect the configuration file to be found in /etc/samba/smb.conf For a more detailed description of Samba, check the samba-doc package or the Samba.org Web page at http://www.Samba.org/ Please check http://en.openSUSE.org/Samba for general information on Samba as part of SUSE Linux Enterprise or openSUSE products, links to binary packages of the most current Samba version, and a bug reporting how to. Source Timestamp: 3640 Branch: 3.6.3.SLE11_SP2Wwildcard2PopenSUSE 11.4openSUSEGPL-3.0+http://bugs.opensuse.orgProductivity/Networking/Sambahttp://www.samba.org/linuxia64/sbin/ldconfig -r /emul/ia32-linux /sbin/ldconfigPAWW5fe4a2026e3c6c5c061a4af46306da7frootrootrootrootsamba-3.6.3-141.1.src.rpmlibnss_wins.so.2samba-client-x86samba-client-x86(x86-32)   @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ glibc-x86ia32el/bin/shrpmlib(PayloadFilesHavePrefix)rpmlib(CompressedFileNames)libc.so.6libc.so.6(GLIBC_2.0)libc.so.6(GLIBC_2.1)libc.so.6(GLIBC_2.1.3)libc.so.6(GLIBC_2.11)libc.so.6(GLIBC_2.2)libc.so.6(GLIBC_2.2.3)libc.so.6(GLIBC_2.2.4)libc.so.6(GLIBC_2.3)libc.so.6(GLIBC_2.3.3)libc.so.6(GLIBC_2.3.4)libc.so.6(GLIBC_2.4)libc.so.6(GLIBC_2.5)libc.so.6(GLIBC_2.8)libcom_err.so.2libdl.so.2libdl.so.2(GLIBC_2.0)libdl.so.2(GLIBC_2.1)libgssapi_krb5.so.2libk5crypto.so.3libkeyutils.so.1libkrb5.so.3liblber-2.4.so.2libldap-2.4.so.2libnsl.so.1libnsl.so.1(GLIBC_2.0)libresolv.so.2libresolv.so.2(GLIBC_2.2)librt.so.1librt.so.1(GLIBC_2.2)libtalloc.so.2libtdb.so.1libtevent.so.0libz.so.1rpmlib(PayloadIsLzma)4.0-13.0.4-14.4.6-14.8.0W @S@RpRg@R^R].@R].@R>QY@Q@QQɆ@Q@@QKQ(@Q@QQ>@Q>@Qzl@Qzl@Qo@QkQ\QAQ+R@Q@QQ@QEQ \QQPP9@PP@P+PP@PBPBPPP@P*P6@PoPoPoP{@PWPQPP@OjOjO O O@O!O@O@OOO@O OoOc+@OaO`@OKp@OB5O>A@Oanswers[]; (bso#9402).- s4:torture/smb2: improve the smb2.create.blob tes; (bso#9209). - lib/krb5_wrap: request enc_types in the correct order; (bso#9272). - Fix net ads join message for the dns domain; (bso#9326). - docs-xml: fix use of tag; (bso#9345). - s3-aio_pthread: Optimize aio_pthread_handle_completion; (bso#9359). - s3:winbind: Failover if netlogon pipe is not available; (bso#9386).- Ensure adding the winbind group never can fail.- Create ntadmin group only if it doesn't yet exist.- quota: Don't force the block size to 512; (bso#3272). - Fix poll replacement to become a msleep replacement; (bso#8107). - Fix wrong test == syntax in configure; (bso#8146). - Fix --with(out)-sendfile-support option handling in autoconf; (bso#8344). - Fix builtin forms order to match Windows again; (bso#8632). - Fix RAW printing for normal users; (bso#8769); (bnc#790741). - Initialise ticket to ensure we do not invalid memory; (bso#8788). - Fix 'net rpc share allowedusers' to work with 2008r2; (bso#8966). - Fix crash on null pam change pw response; (bso#9013). - Connection to outbound trusted domain goes offline; (bso#9016). - Increase debug level for info that the db is empty; (bso#9112). - 'smbclient' can't connect to a Windows 7 server using NTLMv2; (bso#9117). - Winbind can't fetch user or group info from AD via LDAP; (bso#9147). - Open printers with the right access mask; (bso#9154). - Fix makerpms.sh on RHEL; (bso#9165). - Remove non-existent option '-Y' from winbindd manpage; (bso#9171). - Add quota support for gfs2; (bso#9172). - Make SMB2 compound request create/delete_on_close/close work as Windows; (bso#9173). - Empty SPNEGO packet can cause smbd to crash; (bso#9174). - pam_winbind: Match more return codes when wbcGetPwnam has failed; (bso#9177). - Fix crash bug in idmap_hash; (bso#9188); (bnc#788159). - SMB2 Create doesn't return correct MAX ACCESS access mask in blob; (bso#9189). - Fix service control for non-internal services; (bso#9192). - Don't take 'state->te' as indication for "was_deferred"; (bso#9196). - Parse of invalid SMB2 create blob can cause smbd crash; (bso#9209). - Bad ASN.1 NegTokenInit packet can cause invalid free; (bso#9213). - Fix segfault in smbd if user specified ports out for range; (bso#9218). - Signing cannot be disabled for SMB2 by design, so fix the documentation instead; (bso#9222). - Fix NT_STATUS_IO_TIMEOUT during slow import of printers into registry; (bso#9231). - When setting a non-default ACL, don't forget to apply masks to SMB_ACL_USER and SMB_ACL_GROUP entries; (bso#9236). - lib-addns: ensure that allocated buffer are pre set to 0; (bso#9259). - Make tdb robust against shrinking tdbs and improper CLEAR_IF_FIRST restart; (bso#9268). - Add support for reloading systemd services; (bso#9280).- Warn via the smbd log if AppArmor and "wide links" are in use; (bnc#783719).- Backport FSCTL codes and fix segfault in smbstatus from master; (bso#9058). - Fix bad call to memcpy source3/registry/regfio.c; (bso#9065). - "Domain Users" incorrectly added as additional group on domain members; (bso#9066). - Use correct RID for "Domain Guests" primary group; (bso#9067). - Fix crash bug in smbd caused by a blocking lock followed by close; (bso#9084). - Fix smbclient/tarmode panic when connecting to Windows 2000 clients; (bso#9088). - Fix refreshing of Kerberos tickets in Winbind; (bso#9098). - Fix identification of idle clients in Winbind to avoid crashes and NDR parsing errors; (bso#9104). - Fix compilation with newer MIT Kerberos which hides internal symbols; (bso#9111). - Fix flooding the logs with records we don't find in pcap; (bso#9112). - Initialize the print backend after we setup winreg; (bso#9122). - Fix lprng job tracking errors; (bso#9123). - Fix setting of "inherited" bit on inherited ACE's; (bso#9124). - Fix Winbind panic if we couldn't find the domain; (bso#9135). - Make 'smbclient allinfo' show the snapshot list; (bso#9137). - Fix nfs quota support with Linux nfs4 mounts; (bso#9144). - Valid open requests can cause smbd assert due to incorrect oplock handling on delete requests; (bso#9150).- NMB registration for a duplicate workstation fails with registration refuse; (bso#9085); (bnc#770056).- Correct documentation of "case sensitive"; (bso#8552). - Printing fails in function cups_job_submit; (bso#8719). - Fix kernel oplocks when uid(file) != uid(process); (bso#8974). - Send correct responses to NT Transact Secondary when no data and no params for the Trans2 calls are set; (bso#8989). - Fix build without ads support; (bso#8996). - Don't turn negative cache entries into valid idmappings; (bso#9002). - Fix posix acl on gpfs; (bso#9003). - Make vfs_gpfs less verbose in get/set_xattr functions; (bso#9022). - Fix migrating printers while upgrading from 3.5.x; (bso#9026). - Fix typo in set_re_uid() call when USE_SETRESUID selected in configure; (bso#9034). - Using asynchronous IO with SMB2 can return NT_STATUS_FILE_CLOSED in error instead ofNT_STATUS_FILE_LOCK_CONFLICT; (bso#9040). - Fix resolving our own "Domain Local" groups; (bso#9052); (bnc#779269). - Fix build against CUPS 1.6; (bso#9055). - Fix bugs in SMB2 credit handling code; (bso#9057). - rpcclient: Fix bad call to data_blob_const; (bso#9062).- BuildRequire gcc, make, and patch; (bnc#771516).- ndr: fix push/pull DATA_BLOB with NDR_NOALIGN; (bso#9026); (bnc#770262).- Fix shell syntax in dhcpcd hook script; (bnc#769957).- resolve_ads() code can return zero addresses and miss valid DC IP addresses; (bso#8910). - Can't join XP Pro workstations to 3.6.1 DC; (bso#8373); (bnc#787983). - winbind can hang as nbt_getdc() has no timeout; (bso#8953). - Fix crash bug in dns_create_probe when dns_create_update fails; (bso#8627) - s3-pid: Catch with pid filename's change when config file is not smb.conf; (bso#8714). - Possible memory leaks in the main Samba process; (bso#8970). - s3: Fix uninitialized memory read in talloc_free(); (bnc#764577). - Treat exit_server_cleanly() as a "clean" shutdown; (bso#8971). - Avoid crash with MIT krb5 1.10.0 in gss_get_name_attribute(); (bso#8988). - Winzip occasionally can not read files out of an open winzip dialog; (bso#8311). - s3-winbindd: call dump_core_setup after command line option has been parsed; (bso#8975). - Directory group write permission bit is set if unix extensions are enabled; (bso#8972). - s3: remove dependency on automake for "make everything"; (bso#8978). - sd_has_inheritable_components segfaults on an SD that se_access_check accepts; (bso#8811). - smbclient's tarmode insists on listing excluded directories; (bso#8922). - Notify code can miss a ChDir; (bso#8998). - s3:smbd: add a fsp_persistent_id() function; (bso#8995).- s3: Fix a segfault with debug level 3 on Solaris; (bso#8861). - s3: wbinfo --lookup-sids "" crashes winbind; (bso#8904). - smbd crashes when deleting directory and veto files are enabled; (bso#8837). - winbind_krb5_locator only returns one IP address; (bso#8897). - Wrong assertion/comparison: Compare value not pointer; (bso#8859). - Inconsistent (with manpage) command-line switch for "help" in smbtree; (bso#8831). - Fix incorrect debug statement. - Setting traverse rights fails to enable directory traversal when acl_xattr in use; (bso#8857). - Syslog broken owing to mistyping of debug_settings.syslog; (bso#8877). - s3/ldap: remove outdated netscape ds 5 schema file; (bso#8869). - s3-docs: fixes several typos; (bso#7938). - s3-VFS: Fix building out-of-tree modules; (bso#8822). - s3-docs: Add hint that setting "profile acls = yes" on normal shares can cause trouble; (bso#7930). - s3-pam_winbind: Fix the build with a newer iniparser library; (bso#8915). - Avoid null dereference in initialize_password_db(); (bso#8920). - s3:registry: implement values_need_update and subkeys_need_update in the smbconf backend. - s3:registry:reg_api: fix reg_queryvalue to not fail when values are modified while it runs. - s4:torture:rpc:spoolss: also initialize driverName before checking it in test_PrinterData_DsSpooler(). - s3:registry: multiple cleanups, fixes, and optimisations. - s3:auth/server_info: the primary rid should be in the groups rid array; (bso#8798). - s3-printing: Add new printers to registry; (bso#8554); (bso#8612); (bso#8748). - Fix the overwriting of errno before use in a DEBUG statement and use the return value from store_acl_blob_fsp rather than ignoring it; (bso#8945). - s3-auth: Don't lookup the system user in pdb; (bso#8944). - s3-passdb: Fix negative SID->uid/gid cache handling; (bso#8952). - Fix typo in pam_winbindd code; (bso#8957). - Fix remove_duplicate_addrs2 previously it could leave zero addresses in the list; (bso#8910). - Slow but responsive DC can lock up winbindd; (bso#8943). - Broken processing of %U with vfs_full_audit when force user is set; (bso#8882).- Attempt to use samlogon validation level 6; (bso#7945); (bnc#741623).- Add PreReq /etc/init.d/nscd to the winbind package; (bnc#759731).- Recover from ncacn_ip_tcp ACCESS_DENIED/SEC_PKG_ERROR lsa errors; (bso#7944); (bnc#755663). - Fix lsa_LookupSids3 and lsa_LookupNames4 arguments.- docs-xml: fix default name resolve order; (bso#7564). - s3-aio-fork: Fix a segfault in vfs_aio_fork; (bso#8836). - docs: remove whitespace in example samba.ldif; (bso#8789). - s3-smbd: move print_backend_init() behind init_system_info(); (bso#8845); (bnc#730769). - s3-docs: Prepend '/' to filename argument; (bso#8826).- Restrict self granting privileges where security=ads for Samba post-3.3.16; CVE-2012-2111; (bnc#757576).- Remove all precompiled idl output to ensure any pidl changes take effect; (bnc#757080).- Samba pre-3.6.4 are affected by a vulnerability that allows remote code exe- cution as the "root" user; PIDL based autogenerated code allows overwriting beyond of allocated array; CVE-2012-1182; (bso#8815); (bnc#752797).- s3-winbindd: Only use SamLogonEx when we can get unencrypted session keys; (bso#8599). - Correctly handle DENY ACEs when privileges apply; (bso#8797).- s3:smb2_server: fix a logic error, we should sign non guest sessions; (bso8749). - Allow vfs_aio_pthread to build as a static module; (bso#8723). - s3:dbwrap_ctdb: return the number of records in db_ctdb_traverse() for persistent dbs; (#bso8527). - s3: segfault in dom_sid_compare(bso#8567). - Honor SeTakeOwnershiPrivilege when client asks for SEC_STD_WRITE_OWNER; (bso#8768). - s3-winbindd: Close netlogon connection if the status returned by the NetrSamLogonEx call is timeout in the pam_auth_crap path; (bso#8771). - s3-winbindd: set the can_do_validation6 also for trusted domain; (bso#8599). - Fix problem when calculating the share security mask, take priviliges into account for the connecting user; (bso#8784).- Fix crash in dcerpc_lsa_lookup_sids_noalloc() with over 1000 groups; (bso#8807); (bnc#751454).- Remove obsoleted Authors lines from spec file for post-11.2 systems.- Make ldapsmb build with Fedora 15 and 16; (bso#8783). - BuildRequire libuuid-devel for post-11.0 and other systems. - Define missing python macros for non SUSE systems. - PreReq to fillup_prereq and insserv_prereq only on SUSE systems. - Always use cifstab instead of smbfstab on non SUSE systems.- Ensure AndX offsets are increasing strictly monotonically in pre-3.4 versions; CVE-2012-0870; (bnc#747934).- Add SERVERID_UNIQUE_ID_NOT_TO_VERIFY; (bso#8760); (bnc#741854).- s3-printing: fix crash in printer_list_set_printer(); (bso#8762); (bnc#746825).- s3:winbindd fix a return code check; (bso#8406).- s3: Add rmdir operation to streams_depot; (bso#8733).- s3:smbd:smb2: fix an assignment-instead-of-check bug conn_snum_used(); (bso#8738); CVE-2013-0454; (bnc#811975).- s3:auth: fill the sids array of the info3 in wbcAuthUserInfo_to_netr_SamInfo3(); (bso#8739).- s3:client: ignore SMBecho errors (the server may not support it); (bso#8139).- Be more strict when using PAM_AUTH API from winbind if Kerberos auth is enabled and don't unintentionally use a bogus domain name; (bso#8734).- smbclient fails with posix large reads; (bso#8727).- Use the smbfs init script on versions pre-11.3, or cifs in later versions; (bnc#744614).- s3: Compile IDL files in autogen, some configure tests need this.- Fixes various deadlocks in if-up.d / if-down.d when running under systemd; (bnc#732395).- Update to 3.6.3. + Fix memory leak in parent smbd on connection; CVE-2012-0817; (bso#8724); (bnc#743986).- Use spdx.org compliant license names for all packages.- Update to 3.6.2. + Make Winbind receive user/group information (bug #8371). + Several SMB2 fixes. + Fix a crash bug in the spoolss code. + Add new contributing FAQ announcing acceptance of corporate (C). + DeletePrinterDriverEx deletes files in use; (bso#4942); (bnc#742504). + Fix cli_write_and_x() against OS/2 print shares; (bso#5326). + Fix 'smbclient tar' for files greater than 8GB on BE machines; (bso#563); (bnc#726145). + Remove pointless use_memory_krb5_ccache; (bso#7465). + Fix perl path; (bso#8176). + Grant credits in async interim responses (SMB2); (bso#8357). + Make Winbind receive user/group information; (bso#8371). + Fix Windows XP clients crashing smbd process every once in a while; (bso#8384); (bnc#731571). + Make VFS op "streaminfo" stackable; (bso#8419). + Add an allocation pool to idmap_autorid; (bso#8444). + Fix SEGFAULT from net registry export on not zero terminated REG_SZ values; (bso#8528). + Make DSO_EXPORTS_CMD more portable; (bso#8531). + readlink() on Linux clients fails if the symlink target is outside of the share; (bso#8541). + smbclient posix_open command fails to return correct info on open file; (bso#8542). + winbind_samlogon_retry_loop ignores logon_parameters flags; (bso#8548). + Fix setting the machine account password; (bso#8550). + Make SMB2 handle compound request headers in the same way as Windows; (bso#8560). + Password change settings not fully observed; (bso#8561). + Fix double free error in talloc; (bso#8562). + Fix alignment in the non-extended-security negprot; (bso#8573). + Add systemd service files; (bso#8575). + Add systemd service files; (bso#8575). + smb2_flush: Don't send uninitialized memory; (bso#8579). + Enable inotify if sys or kernel inotify is available; (bso#8580). + Increase a debug level; (bso#8585). + libsmb: Only align unicode pipe_name; (bso#8586). + Fix marshalling of samr_ChangePasswordUser3; (bso#8591). + Don't limit the number of open dptrs for SMB2; (bso#8592). + Fix a crash bug in cldap_socket_recv_dgram(); (bso#8593). + Make cldap work over IPv6; (bso#8600). + Fix intermittent print job failures caused by character conversion errors; (bso#8606). + Improve configure.in so it can be used outside the Samba source tree; (bso#8607). + Winbind: Don't fail on users without a uid; (bso#8608). + Ensure we correctly calculate reply credits over all returned SMB2 replies; (bso#8614). + Fix migrate printer code; (bso#8618). + Fix crash bug when trying to browse Samba printers; (bso#8623). + libsmb: Don't duplicate Kerberos service tickets; (bso#8628). + POSIX ACE x permission becomes rx following mapping to and from a DACL; (bso#8631). + When returning an ACL without SECINFO_DACL requested, we still set SEC_DESC_DACL_PRESENT in the type field; (bso#8636). + Fix the vfs_commit module; (bso#8639). + Add an update function for Winbind cache; (bso#8643). + vfs_acl_xattr and vfs_acl_tdb modules can fail to add inheritable entries on a directory with no stored ACL; (bso#8644). + Document the "ignore system acls" option of vfs_acl_xattr and vfs_acl_tdb vfs modules; (bso#8652). + Fix deleting a symlink if the symlink target is outside of the share; (bso#8663). + Fix renaming a symlink if the symlink target is outside of the share; (bso#8664). + Fix NT ACL issue; (bso#8673). + Fix buffer overflow issue with AES encryption in samba traffic analyzer; (bso#8674). + Fix Winbind segfault if we can't map the last user; (bso#8678). + recvfile code path using splice() on Linux leaves data in the pipe on short write; (bso#8679). + Try ctdbd_init_connection() as root; (bso#8684). + Packet validation checks can be done before length validation causing uninitialized memory read; (bso#8686). + Fix typo in 'net memberships' usage; (bso#8687). + libads: Fix malloc/talloc mismatch in ads_keytab_verify_ticket(); (bso#8692). + Make DeletePrinterDriverEx remove printer driver files; (bso#8697) (bnc#740810). + Fix major leak with SMB2 in connections.tdb; (bso#8710).- s3-spoolss: Pass the right pointer type; (bso#4942); (bnc#742504).- Use simplified smb signing infrastructure; (bnc#741623).- Use correct license, LGPLv3+ for libwbclient packages.- When returning an ACL without SECINFO_DACL requested, we still set SEC_DESC_DACL_PRESENT in the type field; (bso#8636).- Fix incorrect types in the full_audit VFS module. Add null terminators to audit log enums; (bnc#742885).- Prefix print$ path on driver file deletion; (bso#8697); (bnc#740810). - Fix printer_driver_files_in_use() call ordering; (bso#4942); (bnc#742504).- Buffer overflow issue with AES encryption in samba traffic analyzer; (bso#8674). - NT ACL issue; (bso#8673). - Deleting a symlink fails if the symlink target is outside of the share; (bso#8663). - connections.tdb - major leak with SMB2; (bso#8710).- Renaming a symlink fails if the symlink target is outside of the share; (bso#8664).- Intermittent print job failures caused by character conversion errors; (bso#8606). - ads_keytab_verify_ticket mixes talloc allocation with malloc free; (bso#8692). - libcli/cldap: fix a crash bug in cldap_socket_recv_dgram(); (bso#8593). - s3:lib/ctdbd_conn: try ctdbd_init_connection() as root; (bso#8684). - s3-printing: fix migrate printer code; (bso#8618). - Packet validation checks can be done before length validation causing uninitialized memory read; (bso#8686).- net memberships usage info was wrong; (bso#8687). - s3-libsmb: Don't duplicate kerberos service tickets; (bso#8628). - Recvfile code path using splice() on Linux leaves data in the pipe on short write; (bso#8679). - s3-winbind: Fix segfault if we can't map the last user; (bso#8678). - vfs_acl_xattr and vfs_acl_tdb modules can fail to add inheritable entries on a directory with no stored ACL; (bso#8644). - s3/doc: document the ignore system acls option of vfs_acl_xattr and vfs_acl_tdb; (bso#8652). - Winbind can't receive any user/group information; (bso#8371). - s3-winbind: Add an update function for winbind cache; (bso#8643). - s3: Attempt to fix the vfs_commit module. - POSIX ACE x permission becomes rx following mapping to and from a DACL; (#bso#8631). - s3:libsmb: only align unicode pipe_name; (bso#8586). - s3-winbind: Don't fail on users without a uid; (bso#8608). - Crash when trying to browse samba printers; (bso#8623). - talloc: double free error; (bso#8562). - cldap doesn't work over ipv6; (bso#8600). - s3:libsmb: fix cli_write_and_x() against OS/2 print shares; (bso#5326). - SMB2: not granting credits for all requests in a compound request; (bso#8614). - smb2_flush sends uninitialized memory; (bso#8579). - Password change settings not fully observed; (bso#8561). - s3:smb2_server: grant credits in async interim responses; (bso#8357). - s3:smbd: don't limit the number of open dptrs for smb2; (bso#8592). - samr_ChangePasswordUser3 IDL incorrect; (bso#8591). - idmap_autorid does not have allocation pool; (bso#8444). - Add systemd service files. - s3:libsmb: the workgroup in the non-extended-security negprot is not aligned; (bso#8573). - s3-build: Fix inotify detection; (bso#8580). - SMB2 doesn't handle compound request headers in the same way as Windows; (#bso8560). - Disconnecting clients swamp the logs; (bso#8585). - s3-netlogon: Fix setting the machinge account password; (bso#8550). - winbind_samlogon_retry_loop ignores logon_parameters flags; (#bso8548). - smbclient posix_open command fails to return correct info on open file; (bso#8542). - readlink() on Linux clients fails if the symlink target is outside of the share; (bso#8541). - s3-netapi: remove pointless use_memory_krb5_ccache; (bso#7465). - s3:Makefile: make DSO_EXPORTS_CMD more portable; (bso#8531). - s3:registry: fix the test for a REG_SZ blob possibly being a zero terminated ucs2 string; (bso#8528). - Make VFS op "streaminfo" stackable; (bso#8419).- Fix incorrect perfcount array length calculations; (bnc#739258).- BuildRequire autoconf to avoid implicit dependency for post-11.4 systems.- Remove call to suse_update_config macro for post-11.4 systems.- Use samba.org for the ldapsmb source location.- Fixing libsmbsharemode dependency on ldap and krb5 libs in Makefile; (bnc #729516).- Do not map POSIX execute permission to Windows FILE_READ_ATTRIBUTES; (bso#8631); (bnc#732572).- Add ldap to Should-Start and Stop of the smb init script; (bnc#730046).- Fix smbd srv_spoolss_replycloseprinter() segfault; (bso#8384); (bnc#731571).- Fix pam_winbind.so segfault in pam_sm_authenticate(); (bso#8564).- Fix smbclient >8GB tars on big endian machines; (bso#563); (bnc#726145).- Fix typo in net ads join output; (bnc#713135).- Ignore a potentially missing AppArmor snippet helper script; (bnc#725256).- Update to 3.6.1. + Fix smbd crashes triggered by Windows XP clients; (bso#8384). + Fix a Winbind race leading to 100% CPU load; (bso#8409). + Several SMB2 fixes. + The VFS ACL modules are no longer experimental but production-ready. + Fix 'net ads join -k' when KRB5CCNAME is not set; (bso#7465). + smb_acl_to_posix: ACL is invalid for set (Invalid argument); (bso#7509). + Return error of cli_push when 'put - /some/file' is used; (bso#7551). + Fix usage of cli_errstr(); (bso#7864). + Fix 'widelinks' regression; (bso#8229). + Empty notify servername; (bso#8236). + Add man vfs_aio_fork; (bso#8256). + smb2: smbd logs "Invalid SMB packet: first request: 0x0008" and crashes; (bso#8334). + Add a fallback for missing open&x support in MAC OS/X Lion; (bso#8338). + While migrating forms, don't fail if the form already exists; (bso#8351). + OS/2 sends an unexpected write&x/read&x chain; (bso#8360). + Fix build of vfs_prealloc on SLES8; (bso#8363). + Fix the build of gpfs.c on RHEL 6.0 with gpfs 3.4.0-4; (bso#8364). + Fix the fallback to the deprecated spelling idmap:script; (bso#8368). + Fix vfs_chown_fsp; (bso#8370). + Fix smbd crashes triggered by Windows XP clients; (bso#8384). + Fix smbclient access to NT4 shares; (bso#8385). + Optimize serverid_exists() for Solaris; (bso#8395). + registry/reg_format.c must include includes.h; (bso#8401). + SMB2 server can return requests out-of-order when processing a compound request; (bso#8407). + Fix a Winbind race leading to 100% CPU load; (bso#8409). + Fix "saving as" of MS Office 2007 (Word) documents on Samba shares with SMB2; (bso#8412). + Fix 'getent group' if trusted domains are not reachable; (bso#8420). + Fix infinite loop in ACL module code; (bso#8422). + Fix wrong reply to DHnC (durable handle reconnect); (bso#8428). + Compound SMB2 requests on an IPC connection can corrupt the reply stream; (bso#8429). + Fix segfault in iconv.c; (bso#8433). + NFSv4 DENY ACLs always include SYNCHRONIZE flag - blocking renames; (bso#8442). + Be smarter about setting default permissions when a ACL_USER_OBJ isn't given; (bso#8443). + Check the wct of the incoming SMBnegprot responses; (bso#8452). + Fix smbclient segfaults when dialect option -m is used for legacy dialects; (bso#8453). + Fix uninitialized memory problem in group_sids_to_info3; (bso#8455). + Samba PDC is looking up only primary user group; (bso#8455). + IE9 on Windows 7 cannot download files to samba 3.5.11 share; (bso#8458). + smb2_find uses a hard coded max reply size of 0x10000 instead of smb2_max_trans; (bso#8473). + SMB2 create doesn't cope with an Apple client using NULL blob in create; (bso#8474). + Don't call smbd_terminate_connection in smb2_validate_message_id(); (bso#8476). + Samba asserts when SMB2 client breaks the crediting rules; (bso#8476). + Map to guest can return uninitialized blob of data; (bso#8477). + acl_xattr can free an invalid pointer if no blob is loaded; (bso#8480). + DFS breaks zip file extracting unless "follow symlinks = no" set; (bso#8493). + Remove "experimental" label on VFS ACL modules; (bso#8494). + SMB2_OP_CANCEL requests don't have to be signed; (bso#8503). + smbd doesn't correctly honor the "force create mode" bits from a cifsfs create; (bso#8507). + Read-only handles on SAMR allow SAMR_DOMAIN_ACCESS_CREATE_USER; (bso#8509). + Disallow "." in can_set_delete_on_close(); (bso#8515). + SMB2 create call returns incorrect file allocation size; (bso#8518). + Fix SMB2 SMB2_OP_GETINFO and SMB2_OP_IOCTL parsing requirements; (bso#8520). + Winbind cache timeout expiry test was reversed; (bso#8521).- s3/doc: add man page for aio_fork vfs module.- Fix uninitialized memory problem in group_sids_to_info3; (bso#8455).- s3: Samba PDC is looking up only primary user group; (bso#8455).- Add script to create or update an AppArmor sniplet with permissions for all Samba shares; (bnc#688040).- Add "ldapsam:login cache" parameter to allow explicit disabling of the login cache; (bnc#723261).- Retain the smbd startproc return value for correct startup status reporting. unset was incorrectly being called prior to rc_status; (bnc#723724).- Prevent deadlock in systemd triggered by if-down.d handler on shutdown; (bnc#721598).- smb2_find uses a hard coded max reply size of 0x10000 instead of smb2_max_trans; changed defaults and documentation (bso8473).- Empty CIFS share can be blocked for other clients by deleting it via empty path (DELETE_PENDING until the last client); (bso#8515).- winbindd cache timeout expiry test was reversed; (bso#8521).- Fix SMB2 SMB2_OP_GETINFO and SMB2_OP_IOCTL parsing requirements; (bso#8520).- s3:smb2_create: fix allocation size return value when opening existing files; (bso#8518).- SMB2 create doesn't cope with an Apple client using NULL blob in create; (bso#8474).- NFSv4 DENY ACLs always include SYNCHRONIZE flag - blocking renames; (bso#8442).- s3-docs: Fix bug (bso#7908) and typo.- Return error of cli_push when 'put - /some/file' is used; (bso#7551).- Read-only handles on SAMR allow SAMR_DOMAIN_ACCESS_CREATE_USER; (bso#8509).- smbd doesn't correctly honor the "force create mode" bits from a cifsfs create; (bso#8507).- Default user entry is set to minimal permissions on incoming ACL change with no user specified; (bso#8443).- smb_acl_to_posix: ACL is invalid for set (Invalid argument); (bso#7509).- Handle the SECINFO_LABEL flag in the same was as Win2k3; enable Microsoft Internet Explorer 9 on Windows 7 to download files; (bso#8458).- DFS breaks zip file extracting unless "follow symlinks = no" set; (bso#8493).- s3-docs: Fix typos.- s3:smb2_server: SMB2_OP_CANCEL requests don't have to be signed; (bso#8503).- Remove "experimental" label on VFS ACL modules; (bso#8494).- acl_xattr can free an invalid pointer if no blob is loaded; (bso#8480).- s3-smbd: asserts when SMB2 client breaks the crediting rules; (bso#8476).- s3-libnet: allow to use default krb5 ccache in libnet_Join/libnet_Unjoin; (bso#7465).- smb2_find uses a hard coded max reply size of 0x10000 instead of smb2_max_trans; (bso#8473).- s3-netapi: allow to use default krb5 credential cache for libnetapi users.- s3-docs: document -k switch in net manpage.- Map to guest can return uninitialized blob of data; (bso#8477).- s3-registry: registry/reg_format.c must include includes.h; (bso#8401).- smbclient segfaults when option -m is used for legacy dialects; (bso#8453).- Fix 'widelinks' regression intro'd in 3.2; (bso#8229).- Compound SMB2 requests on an IPC connection can corrupt the reply stream; (bso#8429).- s3-spoolss: Fix bug forms migration; (bso#8351).- s3:libsmb: check the wct of the incoming SMBnegprot responses; (bso#8452).- s3: Do not fork the echo handler for smb2; (bso#8334).- s3-spoolss: Fix bug empty notify servername; (bso#8236).- SMB2 server can return requests out-of-order when processing a compound request; (bso#8407).- Remove smb child crash fix. The issue had been fixed upstream differently.- BuildRequire ctdb-devel version greater than 1.0.105 for post-10.0 systems.- Fix samba duplicates file content on appending. Move posix case semantics out from under the VFS; (bso#6898); (bnc#681208).- Make winbind child reconnect when remote end has closed, fix failing sudo; (bso#7295); (bnc#569721).- Spec file cleanup as suggested by the spec-cleaner tool. + Make all BuildRequires, PreReq, and Provides a separate line. + Use %{buildroot} instead of ${RPM_BUILD_ROOT}. + Use straight commands instead of macros (make, install). + Use -p in post and postun if we only call one command. + Use %{_localstatedir} instead of %{_var} in the filelist. + Remove superfluous AutoReqProv on lines.- Remove %release from all Provides.- Fix segfault in iconv.c which caused a null pointer dereference; (bso#8433).- Use /var/run for the cifs state file in the init script too; (bnc#710304).- Microsoft Word from Microsoft Office 2007 fails to save as on a share with SMB2; (bso#8412).- Use sys_write and sys_read in fork_domain_child to fix a winbind race leading to 100% CPU usage; (bso#8409).- Fix wrong reply to smb2 durable handle reconnect (DHnC) request; (bso#8428).- Fix infinite loop in ACL module code; (bso#8422).- Fix getent group if trusted domains are not reachable; (bso#8420).- smbclient can't access a NT4 share since 3.6.0; (bso#8385).- Optimize serverid_exists() for Solaris; (bso#8395).- talloc: + check block count after references test. + added test suite for talloc_free_children(). + license info erratum in the manpage. + fix typos and better differentiation between versions 1 and 2. + preserve context name on talloc_free_children(). + ensure the sibling linked list remains valid during a free.- vfs_chown_fsp returned in the wrong directory; (bso#8370).- Remove irritating "." targets when recent system libs exist; (bso#8369).- Correctly initialize "idmap config * : script" with NULL; (bso#8368).- Add missing include to suppress compiler warnings; (bso#8365).- Point the chain offset beyond the current request; (bso#8360).- Fix gpfs vfs module build; (bso#8364).- Make vfs_prealloc even build on older systems; (bso#8363).- Do central cli_set_error and return the actual NTSTATUS; (bso#7864).- Add a fallback for missing open&x support in OS/X Lion; (bso#8338).- Update to 3.6.0. + BUG 7462: Make SA_RESETHAND conditional on its existance. + BUG 8303: db_ctdb_send_schedule_for_deletion() is not defined. + BUG 8324: smbclient cannot list directories from a big-endian machine. + BUG 8326: WinXP cannot join a Samba3 domain with a 'even' hostname. + BUG 8327: Fix the reload of the configuration, also reload activated registry shares. + BUG 8328: Cleanup of idmap_tdb2 code. + BUG 8330: Fix NFSv4 ACL merging logic. + BUG 8335: File copy aborts with smb2_validate_message_id: bad message_id. + BUG 8341: Fix segfault in libsmbclient. + BUG 8343: Fix SMB2 crash reading with aio_fork beyond the end of file. + BUG 8347: Fix regression for HP-UX, AIX and OSF. + BUG 8357: Make sure we grant credits on async read/write operations. + BUG 8358: Fix a bug in run_poll_events(). + BUG 8362: Fix build issue on old glibc systems.- Remove references to disabled vscan build.- Add missing define, includes, and initialization to get_printing_ticket.- Use /var/run for the cifs state file; (bnc#710304).- Fix #ifdef CTDB_CONTROL_SCHEDULE_FOR_DELETION issue; (bso#8303).- File copy aborts with smb2_validate_message_id: bad message_id; (bso#8335).- Fix reload of the configuration and also reload activated registry shares; (bso#8327).- WinXP cannot join a Samba3 domain with a 'even' hostname; (bso#8326).- smbclient cannot list directories from a big-endian machine; (bso#8324).- Update to 3.6.0rc3. + BUG 7841: Explicitly pass domain_sid to wbint_LookupRids(). + BUG 7888: Deal with buggy 3.0 based PDCs. + BUG 8083: Fix "inherit owner = yes" with vfs_acl_xattr or vfs_acl_tdb module. + BUG 8102: Do not allow to change file ACLs from normal domusers. + BUG 8102: Do not allow to change file ACLs from normal domusers. + BUG 8193: Add new command 'enumerate_recursive'. + BUG 8195: Make rpc client code working against NT4 servers. + BUG 8211: Fix "inherit owner = yes" when "inherit permissions = yes" is set. + BUG 8213: Fixes in idmap_autorid. + BUG 8214: Fix smbd crash on printer driver upgrade. + BUG 8215: Fix Winbind unix username lookup. + BUG 8216: Make Winbind returning correct results with 'sids2xids'. + BUG 8217: Do not stat-check the share path in 'net conf addshare'. + BUG 8219: Fix SMB Panic from Windows 7 client. + BUG 8224: Fix the build on FreeBSD. + BUG 8226: Use c99 initializers which are supported by old gcc 2.95 compilers. + BUG 8230: Move .nmbd socket directory to non-hidden name PREFIX/var/nmbd. + BUG 8231: Fix crash bug in 'net cache get'. + BUG 8235: Fix smbd crash on startup caused by migrate_printer(). + BUG 8240: Fix Valgrind warnings in winreg/spoolss code. + BUG 8244: Fix copying files larger than 2 GB to a Samba share. + BUG 8247: Fix Coverity ID 2582: FORWARD_NULL. + BUG 8253: Fix Winbind panic if verify_idpool() fails. + BUG 8254: Fix "acl check permissions = no". + BUG 8260: Fix DCERPC responses with fragments larger than 1024 bytes. + BUG 8262: Fix build of vfs_commit. + BUG 8263: Fix build with --with-fake-kaserver or --with-vfs-afsacl. + BUG 8264: Fix Valgrind bugs in svcctl. + BUG 8276: Close all sockets attached to a subnet in close_subnet(). + BUG 8278: Fix smbd panic when CTDB is unhealthy. + BUG 8281: Fix build of examples/VFS/*. + BUG 8286: Fix smbd crash on premature end of smb2 conn. + BUG 8292: Fix a major architectural flaw in the SMB2 server code. + BUG 8293: Fix log file rotating in SMB2. + BUG 8304: Fix uninitialized variable in error path. + BUG 8305: Fix segfault in nmbd when using 'smbtree ...'.. + BUG 8307: brl_close_fnum does not call SMB_VFS_BRL_UNLOCK_WINDOWS on all locks. + BUG 8310: toupper_ascii() is broken on big-endian systems. + BUG 8314: Fix smbd crash with unknown user. + Mark 'time offset' parameter as deprecated.- The Samba Web Administration Tool (SWAT) versions 3.0.x to 3.5.9 are affected by a cross-site scripting vulnerability; CVE-2011-2694; (bso#8289); (bnc#708503).- The Samba Web Administration Tool (SWAT) versions 3.0.x to 3.5.9 are affected by a cross-site request forgery; CVE-2011-2522; (bso#8290); (bnc#705241).- Fixed the DFS referral response for msdfs root; (bnc#703655).- Fix CUPS print job IDs; (bso#7288); (bnc#701257).- Make use of the actual library version as part of the package name on post-11.3 systems only.- Fix winbind internal error; (bso#7636); (bnc#659424).- Improve ctdb vacuuming performance with use of SCHEDULE_FOR_DELETION; (bnc#705170).- Specify nmbdsocketdir at configure time; (bnc#700953).- Build the tdb, talloc, and tevent libraries ahead of anything else.- Update to 3.6.0rc2. + BUG 6911: Fix Kerberos authentication from Vista to Samba. + BUG 8166: Don't lockout users when offline. + BUG 8200: Add support for multiple writeable ldap idmap domains. + BUG 8148: Default to protocol version 2 for SMB Traffic Analyzer. + BUG 7054: Fix X account flag when "pwdlastset" is "0". + BUG 8144: Fix setting timestamp when touching files with CIFS clients. + BUG 8153: Fix setting up getaddrinfo on IPv6-only machines. + BUG 8156: Fix 'net ads join' using the user's Kerberos ticket. + BUG 8157: Fix parsing a cups printcap file. + BUG 8175: Fix smbd deadlock. + BUG 8189: Support shadow copy display over SMB2. + BUG 8197: Winbind does not properly detect when a DC connection is dead. + BUG 8203: Winbind needs to reset the DC connection if an RPC times out.- Make cupsaddsmb fill printers location; (bso#8132); (bnc#698209).- Add "winbind max clients" parameter to remove 200-client limit; (bnc#697461).- Disable logon cache for password lockout consistency when running in a cluster; (bnc#694836).- Fix logon of AD users with many group memberships; (bso#6911); (bnc#657026).- Don't lockout users while offline; (bso#8166); (bnc#692607).- Update to 3.6.0rc1. + BUG 8111: CIFS VFS: Fix unexpected error on SMB posix open. + BUG 8112: POSIX extension opens of a directory are denied with EISDIR. + BUG 8132: Fix filling printers location field when using cups. + Remove fstrings from client struct. + BUGFIX when converting from safe_strcpy to strlcpy. + Fix off-by-one calculations with strlcpy. + Ensure we always write the correct incoming mid into the share mode table entries. + Fix the SMB2 oplock showstopper. + Convert user-specified domain to uppercase in libsmb. + Fix Coverity CID #2302: FORWARD_NULL. + Fix cups_pull_comment_location(). + Fix double free of cups request. + Make cups_pull_comment_location() work again. + Fix potential crash bug in display_print_driver3(). + Properly clean up in pthreadpool_init in case of failure. + Make plaintext session setup async. + Reduce fd load in Winbind children. + Avoid a potential 100% CPU loop in Winbind. + Tune broadcast namequeries for unique names. + Properly deal with exited winbind children. + Fix dup_smb2_vec3. + Fix return check in nss_wins.- Fix to renew the kerberos ticket in samba after expiry; (bnc#669949).- Fix a 100% CPU loop when ctdbd dies during a traverse; (bnc#693945).- Make dhcpcd hook BOOTPROTO check cover dhcp6 too; (bnc#691969).- Handling of large (> 256 bytes) ntlmv2 blobs in winbind; (bnc#529946).- Package static libraries with 0644 permissions.- Add Requires libtalloc-devel to libldb-devel and libtevent-devel.- Rename libldb0 to libldb1 as 1 is the current major version of the library. - Add libldb1 and libtevent0 to baselibs.conf.- Don't call the suse_update_config macro before building lib ldb and tevent.- Update to 3.6.0pre3. + Listen on IPv6 addresses with IPV6_ONLY; (bso#7383). + Fix wrong output in 'smbget'; (bso#8066). + "inherit owner = yes" doesn't interact correctly with vfs_acl_xattr or vfs_acl_tdb module; (bso#8083). + rpccli_samr_chng_pswd_auth_crap segfaults if any input blobs are null; (bso#8088). + setpwent() actually does endpwent() and vice versa on FreeBSD; (bso#8099). + Fix the build of 'smbget' on HP NonStop; (bso#8106). + Fix build of tdb2. + Correctly detect and deny symlinks anywhere in a path (not just the last component) if "follow symlinks = no". + Fix timeout in rpc_pipe_open_tcp_port(). + Fix the build of "--with-profiling-data". + Fix Coverity IDs 986, 1340, 2047, 2299, 2307, 2325, 2335, 2336, 2470, 2471, 2478. + nsswitch: Add 'wbinfo --lookup-sids'. + nsswitch: Add 'wbinfo --sids-to-unix-ids'. + Fix smbd with the async echo responder. + Fix the build of vfs_gpfs.c. + Add a 10-second timeout for the 445 or netbios connection to a DC. + Many pthreadpool fixes. + Fix transaction recovery area for converted tdbs.- Add PreReq permissions to the krb-printing package.- Remove _libdir ldb and tevent from file list. - Explicitly state not to bundle talloc or tdb while ldb and tevent build.- Always use the actual library version as part of the package name. - Exclude shared python modules.- Fix printing from Windows 7 clients; (bso#7567); (bnc#687535).- Update pidl and always compile IDL at build time; (bnc#688810).- Update to 3.6.0pre2. + ID Mapping changes. + Implement SMB2 support. + Add an Endpoint Mapper daemon. + Make "rlimit_max below minimum Windows limit" notification less scary; (bso#6837). + Quota only shown when logged as root; (bso#7080). + Fix printing from Windows 7; (bso#7567). + Retry DNS updates when connection to one nameserver has failed; (bso#7690). + Unlink may unlink wrong file when hardlinks are involved; (bso#7863). + Fix 'nmbd --port'; (bso#7875). + cmd_spoolss_deletedriver() returned without checking all architectures; (bso#7880). + Don't return "-1" on success in 'net rpc vampire keytab'; (bso#7899). + Fix cups pcap reload with no printers; (bso#7915). + Fix bug in chain_reply; (bso#7917). + Fix problems with "kernel oplocks" option set to "no"; (bso#7928). + Fall back for utimes calls; (bso#7940). + Catch lookup_names/sids schannel errors over ncacn_ip_tcp; (bso#7944). + Let winbind try to use samlogon validation level 6; (bso#7945). + Sgid bit lost on folder rename; (bso#7996). + Fix getting username in 'net rap session'; (bso#8009). + Fix inode generation so nautilus can count total dir size correctly; (bso#8010). + Use jenkins hash for str_checksum; (bso#8010). + Add explicit configure option whether or not to enable dmapi support; (bso#8033). + Fix smbclient segfault with Cyrillic netbios names; (bso#8040). + Fix file creation on OS/X; (bso#8042). + Add "--option" to 'testparm'. + Fix crash bug on smbd shutdown when using FOPENDIR(). + Ensure we don't return an incorrect access mask. + Fix bug against the new Mac client. + Fix leak in error path. + Fix error where Windows client spoolss returns WERR_INVALID_DATA. + Fix a segfault in the krb5 locator plugin. + Enable sharesec for registry shares. + Fix memory leak in "security=share" and "force user". + Add "net idmap check", a check and repair tool for the id mapping database. + Add new 'net idmap delete' command. + Fix segfault on missing input file in 'net idmap restore'. + Fix 'net usersidlist' not to skip every other user. + Fix potential crash bug in spoolss_PrinterEnumValues push path. + Internal restructuring. + Don't wipe out all printer drivers when only one should be deleted. + Fix winbindd_dual_pam_auth_samlogon() for NT4 domains. + Fix memory leak in print_cups.c. + Remove duplicate cups response processing code. + Follow force user/group for driver IO. + Initiate pcap reload from parent smbd. + Reload shares after pcap cache fill. + Fix numerous Coverity IDs (2041 and others). + Fix a memory leak in check_sam_security_info3. + Fix a segfault in the nss wrapper when libnss_winbind.so is not loadable. + Make "net sam list [users|workstations]" list only the right things. + Fix a potential memleak in secrets_fetch_trusted_domain_password. + Use the right credentials in check_netlogond_security. + Add support for AF_NETLINK addr notifications. + Fork multiple Winbind children per domain. + Fix a deadlock between smbd and ctdbd. + Add 'wbinfo --dc-info'. + Make "nmbd socket dir" configurable. + Fixed valgrind errors. + Fix a memleak in receive_getdc_response. + Don't grant SEC_STD_DELETE always to the owner of a file. + Fix segfaults on addrchange errors in Winbind. + Allow machine accounts as members in groupdb. + Add IPv6 support for the endpoint mapper. + Free unused memory in the rpc server. + Fix possible segfaults in svcctl server. + Fix possible segfault with client_id in rpc server. + Add a 'svcctl shutdown' function to rpc server. + Fix a resource leak in net_afs. + Fix a resource leak in smbta-util. + Fix possible resource leak in net_usershare. + Fix possible resource leak in 'smbget'. + Fix possible resource leak in 'smbfilter'. + Fix a possible null pointer dereference in smbd. + Ensure we send the direct levelII oplock break to the correct fid. + Fix private libdir and codepages paths. - Add RFC 3454 to the vendor files.- Fix idmap_tdb for big-endian systems such as ppc and s390; (bso#6901); (bnc#675978).- Fix smbclient -M NT_STATUS_PIPE_BROKEN failure; (bso#7635); (bnc#681913).- Replace jobs by _smp_mflags macro while calling make on post-11.4 systems.- Don't crash when publishing a single printer; (bnc#643119).- Carry error status in printer list IPC message, do not refresh printers if cups is unavailable; (bso#7994); (bnc#675478).- Define the libwbclient packages ahead of packages with a different version.- Use %_smp_mflags for parallel building.- Update to 3.5.8. + Fix Winbind crash bug when no DC is available; (bso#7730). + Fix finding users on domain members; (bso#7743). + Fix memory leaks in Winbind; (bso#7879). + Fix printing with Windows 7 clients; (bso#7567). + Fix 'testparm' return code when EOF in encountered in param name; (bso#3185). + Make "rlimit_max below minimum Windows limit" notification less scary; (bso#6837). + Fix "Your Password expires today" message for users of trusted domains; (bso#7066). + Fix maintaining of users' groups via UsrMgr; (bso#7262). + Fix 'net ads dns register' in Windows 2008 R2 domains; (bso#7356). + Raise debug level for "reduce_name: couldn't get realpath" messages; (bso#7409). + Fix updating the time on close in vfs_gpfs; (bso#7498). + Fix "log=>ndr_pull_error" in 'wbinfo -u' and 'wbinfo -g'; (bso#7594). + Handle Windows 9x adddriver calls without config file; (bso#7641). + Fix scalability problem with hundreds of printers; (bso#7656). + Fix memory leak in the netapi routines; (bso#7665). + Store unmodified copies of security descriptors in acl_xattr and acl_tdb modules; (bso#7716). + Fix incorrect unix mode_t caused by invalid client DOS attributes on create; (bso#7733). + Apply appropriate create masks when creating files with "inherit ACLs" set to true; (bso#7734). + Fix "dfree cache time" parameter; (bso#7744). + Fix a getgrent crash with many groups; (bso#7774). + Fix requesting lookups for BUILTIN sids; (bso#7777). + Fix smbd crash caused by expand_msdfs; (bso#7779). + Fix atime limit; (bso#7785). + vfs_scannedonly: Switch from mtime to ctime which is more reliable; (bso#7789). + Fix copying files from a SMB share using Gnome vfs and SMB signing; (bso#7791). + Make Winbind recover from a signing error; (bso#7800). + ACL inheritance cannot be disabled in vfs_acl_xattr/vfs_acl_tdb; (bso#7812). + Fix "force group" with ntlmssp guest session setup; (bso#7817). + vfs_fill_sparse() doesn't use posix_fallocate when strict allocate is on; (bso#7835). + Make WINBINDD_LOOKUPRIDS asking the right domain; (bso#7841). + Make WINBINDD_LOOKUPRIDS returning the domain name; (bso#7842). + Expand the local SAMs aliases; (bso#7843). + ntlm_auth: Support clients which offer a spnego mechs we don't support; (bso#7855). + Fix 'net ads dns register' in cluster setups; (bso#7871). + Fix 'nmbd --port'; (bso#7875). + Make 'rpcclient deldriver' delete drivers for all architectures; (bso#7880). + Fix flaky Winbind against Windows 2008; (bso#7881). + Fix SMB session setups with Kerberos against some closed source SMB servers; (bso#7883). + Fix stale lock in open_file_fchmod(); (bso#7892). + Fix sporadic Winbind panic in rpc query_user_list; (bso#7894). + Don't set SAMR_FIELD_FULL_NAME if we just want to set the account name; (bso#7896). + Don't return "-1" on success in 'net rpc vampire keytab'; (bso#7899). + Fix connections from WinCE; (bso#7917). + Fix opening MS Powerpoint files; (bso#7940). + Fix endless loops caused by inotify; (bso#7942). + Catch lookup_names/sids schannel errors over ncacn_ip_tcp; (bso#7944). + Let Winbind try to use samlogon validation level 6; (bso#7945). + Revalidate the pathname once re-constructed from a root fsp; (bso#7950).- Require a particular library version even if the major version is part of the package name. Using the same major version does not guarantee forward compatibility.- Fix a fd-leak in libwbclient at dlclose-time; (bso#7684); (bnc#668773).- Update to 3.5.7 + Protect against possible denial of service caused by memory corruption; CVE-2011-0719; (bso#7949); (bnc#670431).- Disable separate build of samba-doc for post-11.1 systems.- Protect against possible denial of service caused by memory corruption; CVE-2011-0719; (bso#7949); (bnc#670431).- Increase the log level for missing PIDs on SIGCHLD, printcap child processes are not added to the children PID list; (bnc#666460).- Do not require a particular library version if the major version is part of the package name.- Use the actual version numbers of the ldb, talloc, tdb, and tevent libraries on post-11.3 systems.- Abide by print$ share 'force user' & 'force group' settings when handling AddprinterDriver and DeletePrinterDriver requests; (bso#7921); (bnc#653353).- Remove pcap_cache_loaded asserts from (re)load_printers. pcap_cache_loaded() returns false if the pcap cache contains no printer entries. correct call ordering is already enforced. (bso#7836); (bnc#625936).- No longer force activation of the cifs service on post-11.3 systems. - Add X-UnitedLinux-Default-Enabled to the cifs init script on pre-11.4 systems. - Move the cifs init script nfs dependencies from Required to Should.- Recommend to install samba-krb-printing from samba-winbind on post-10.3 systems; (bnc#661845).- Fix error paths in cups_async_callback(), an empty cups printer list should not be treated as an error; (bnc#661842).- Abide by printcap cache time, reload parent smbd pcap cache on expiry; (bso#7836); (bnc#625936).- Fix race in cups async printer services reload; (bso#7836); (bnc#625936).- Don't tweak with baselibs.conf during %post if not present; (bnc#652620).- Don't make use of baselibs.conf on SUSE Linux Enterprise 10; (bnc#652620).- Don't use --tmpdir as this option isn't known by mktemp of SUSE Linux Enterprise 10; (bnc#652620).- vfs_fill_sparse() doesn't use posix_fallocate when strict allocate is on; (bso#7835).- Replace Requires samba-client by samba-gplv3-client in the gplv3 packages; (bnc#652620).- Fix Dolphin SMB share IO with SMB signing enabled; (bso#7791); (bnc#656112).- Add Conflicts to the samba-gplv3 main, client, doc, krb-printing, winbind, client-gplv2, and doc-gplv2 packages; (bnc#652620).- Add Provides samba-client-gplv2 and samba-doc-gplv2 to pre-3.2 versions; (bnc#652620).- Obsolete samba-client-gplv2 and samba-doc-gplv2; (bnc#652620).- Remove Provides samba-client:/usr/sbin/winbindd from the samba-gplv3-winbind package to avoide an accidental install trigger; (bnc#652620).- Add Provides samba-client to the samba-gplv3-client package; (bnc#652620).- Remove all Obsoletes from the samba-gplv3 packages and only keep the Provides samba; (bnc#652620).- Add fitting Conflicts to all samba-gplv3 packages; (bnc#652620).- Reduce unnecessary ldap round trips and eliminate invalid DN messages; (bnc#654719).- Exclude cifs-mount and ldapsmb from the samba-gplv3 build of SUSE Linux Enterprise 10 SP 3 and 4.- Add the _build_arch at the end of the vendor version suffix.- Provide and Obsolete samba-gplv3 to replace potentially installed packages.- Change package base name to samba-gplv3 for SUSE Linux Enterprise 10 SP 4. - Do not package libsmbclient and libsmbsharemodes.- Update to 3.5.6 + Fix auto printers with registry config; (bso#7280); (bnc#617153). + Fix SPNEGO auth when contacting Win7 system using Microsoft Live Sign-in Assistant; (bso#7577). + Fix 'net idmap restore' setting HWM to avoid duplicates; (bso#7578). + Fix "admin users" when using vfs_acl_xattr; (bso#7581). + Fix using cached credentials in ntlm_auth; (bso#7589). + Fix Winbind offline login; (bso#7590). + Fix Winbind internal error; (bso#7636). + Fix mknod/mkfifo failing with "No such file or directory"; (bso#7651). + Fix smbd changing mode of files on rename; (bso#7693). + Fix crash bug with invalid SPNEGO token; (bso#7694). + Fix smbd panic on invalid NetBIOS session request; (bso#7698). + Fix smbd crash caused by "%D" in "printer admin"; (bso#7541). + Fix 'smbclient -M'; (bso#7635). + Fix scalability problem with hundreds of printers; (bso#7656). + Fix crash bug in rpcclient; (bso#7688). + Fix file corruption when setting Samba "write wache wize"; (bso#7715).- Let startproc wait for nmb, smb and winbind pid files getting created on post-11.1 systems; (bnc#520036).- Include the reviewed french translation for pam_winbind; (bnc#499233).- Fix smbd crash with CUPS printers and no [printers] share defined; (bso#7297); (bnc#637755).- Fix printing from 64-bit windows clients; (bso#6888); (bnc#640870).- Fix baselibs.conf for libtalloc.- Fix buffer overflow in sid_parse() to correctly check the input lengths when reading a binary representation of a Windows Security ID (SID); CVE-2010-3069; (bso#7669); (bnc#637218).- Use cached ntlm password in libsmbclient. Prevent lockouts when kerberos tickets are lost; (bnc#602418); (bnc#606304).- Add a dependency on nfs to the smbfs/ cifs init scripts as they require the en_US locale and /usr might be on NFS.- Complete fix for trusts with Windows 2008R2 DCs.- Fix authentication dialogs when connecting to older systems; (bnc#632055).- Adjust position of conditional ldapsmb %package and %files definition.- Create the /var/run/samba directory on the fly and package it as %ghost.- Fix preexec scripts; (bso#7104); (bnc#632852).- Add missing netapi, smbclient, smbsharemodes, talloc, tevent, and wbclient pkgconfig files and BuildRequire pkgconfig; (bnc#632770).- BuildRequire python-devel for post-9.3 systems.- Only create precompiled headers for post-10.2 systems. - Remove mkinitrd scriptlets.- Add vfs_crossrename man page. - Call make basic and remove conditional proto target. - Increase libtevent version to 0.9.9. - Remove wbc_async header from the file list. - Remove remaining cifs-mount pieces from the spec file.- Fix printers not auto loading with registry config; (bso#7280); (bnc#617153).- Update to 3.6.0pre1. + SMB2 support is fully functional despite managing quota using the Microsoft management tools. + Internal Winbind passdb changes to use samr and lsa rpc pipe to get local user and group information. + The spoolss and the old RAP printing code have been completely overhauled and refactored. + The SMB Traffic Analyzer (SMBTA) VFS module got added.- Intilize workgroup of nmblookup as empty string.- Fix net ads join when using parent domain users; (bso#6364); (bnc#630812).- cifs: do not restart during dhcp lease renewal when IPaddress remains the same; (bnc#573246).- Fix "Too many open files" when trying to access large number of files; (bso#6837); (bnc#619787).- Update to 3.5.4. + Fix smbd crash when sambaLMPassword and sambaNTPassword entries missing from ldap (bug #7448). + Fix init_sam_from_ldap storing group in sid2uid cache (bug #7507). + Allow previous password to be stored and use it to check tickets; (bso#7099). + Make ea data checks identical for trans2open and trans2mkdir; (bso#7188). + Fix editing users' groups via UsrMgr; (bso#7262). + Fix Winbind over IPv6; (bso#7341). + Samba sends "raw" inode number as uniqueid with unix extensions; (bso#7410). + Fix printing large formats; (bso#7423). + Fix spnego returning incorrect mechListMIC string; (bso#7449). + Fix some crash bugs and missing error codes in AddDriver paths; (bso#7459). + Fix crash bug in _samr_QueryUserInfo{2} level 18; (bso#7479). + Fix 'not a string literal' warning in netdomjoin-gui; (bso#7500). + Fix calculation of st_blocks in vfs_streams_xattr; (bso#7503). + Fix numerous build issues; (bso#7504). + Fix session setup from linux kernel cifs clients with "sec=ntlmv2"; (bso#7517).- Remove all provides and obsoletes samba3 from the spec file. Packages with this base name have not been offered as part of a product.- Fix a NULL pointer dereference in smbd of the 3.4 code base; CVE-2010-1635; (bso#7229); (bnc#605935).- Address possible buffer overrun in chain_reply code of pre-3.4 versions; CVE-2010-2063; (bso#7494); (bnc#611927).- Update of the SMB Traffic Analyzer v2 VFS module- Fix trusts with Windows 2008R2 DCs; (bnc#613459); (bnc#599873); (bnc#592198); (bso#6697).- Update to 3.5.3. + Fix MS-DFS functionality; (bso#7339). + Fix a Winbind crash when scanning trusts; (bso#7389). + Fix problems with SIGCHLD handling in Winbind; (bso#7317). + Add replacement for IPV6_V6ONLY on linux systems with broken headers; (bso#7196). + Fix cups encryption setting; (bso#7263). + Fix exporting printers via 'cupsaddsmb' command; (bso#7277). + Fix SMB job IDs in CUPS job names; (bso#7288). + Fix segfault in mount.cifs; (bso#7315). + Make TIME_T_MAX defines consistent; (bso#7352). + Re-fix a bug with smbd serving a windows terminal server; (bso#7357). + Display an error on 'net conf import' failures; (bso#7378). + Fix bitmap leak in dptr_Close; (bso#7384). + Fix rename problems with full_audit VFS module; (bso#7398). + Fix setting of passwords via 'net rpc user password' command; (bso#7417). + Fix 'net rpc printer list' command; (bso#7418). + Rename mod_name to module_name; (bso#7421). - Fix unnecessary traversing winbindd_cache.tdb in SIGHUP handler. - Added EN ISO 216, A0 and A1 to builtin forms; (bso#7423). - Winbind not working over IPv6; (bso#7341).- Honor "interfaces" list in net ad dns register; (bnc#606947).- Exclude the RPM release from the vendor tag for openSUSE Factory; (bnc#604049).- Enable the build of the idmap tdb2 module; (bnc#600822).- BuildRequire keyutils-libs-devel for Fedora and post-RHEL4.- BuildRequire pkg-config for post-10.2 systems and else pkgconfig.- Add "net conf import" error messages; (bso#7378, bnc#598189).- Define cups_lib_dir %{_prefix}/lib/cups for post-11.2 systems; (bnc#575544).- Update to 3.5.2. + Fix smbd segfaults in _netr_SamLogon for clients sending null domain; (bso#7237). + Fix smbd segfaults in "waiting for connections" message; (bso#7251). + Fix an uninitialized variable read in smbd; (bso#7254); (bnc#605935); CVE-2010-1642. + Fix a memleak in Winbind; (bso#7278). + Fix Winbind reconnection to it's own domain; (bso#7295). + Fix segfault if hide files or veto files has no ".AppleDouble"; (bso#1206). + Fix parsing of the gecos field; (bso#5198). + Fix several printing issues; (bso#6727). + Fix valgrind warning; (bso#6814). + Fix race condition in mount.cifs that allows user to replace mountpoint with a symlink; (bso#6853). + Fix bug in vfs_scannedonly rmdir implementation; (bso#7075). + Fix handling of bad server data returns in client rpc_transport; (bso#7159). + Never mark external domains as internal in Winbind; (bso#7170). + Fix access by multi-threaded applications; (bso#7202). + Fix 'net share' command; (bso#7203). + Fix DN parsing name was always null; (bso#7204). + Signals are processed twice in child; (bso#7206). + Fix returning of group members with 'getent group'; (bso#7212). + Fix the build of net_afs.c with --fake-kaserver=yes; (bso#7216). + Make Winbind logs more verbose for troubleshooting; (bso#7225). + Fix a NULL pointer dereference in smbd; CVE-2010-1635; (bso#7229); (bnc#605935). + Fix automatic building of vfs_tsmsm if gpfs and dmapi are present; (bso#7231). + Fix race conditions in CTDB persistent transactions; (bso#7232). + Symlink delete fails but incorrectly reports success to client; (bso#7234). + Fix "printer admin" functionality; (bso#7255). + Fix value-needed calculation in_spoolss_EnumPrinterData(); (bso#7256). + Fix _winreg_QueryValue crash bugs and implement Windows behavior; (bso#7258). + Fix job management commands for CUPS queues; (bso#7269). + Fix smbd segfault if using vfs_acl_tdb; (bso#7283). + Fix core dump in 'ntlm_auth' with "gss-spnego" helper; (bso#7290). + Fix smbd crashes with CUPS printers and no [printers] share defined; (bso#7297). + Fix DOS attribute inconsistency with MS Office; (bso#7310). + Many disconnecting clients render clustered Samba unusuable for some time; (bso#7312). + Make 'net conf addshare' atomic; (bso#7313). + Eliminate race condition in creating/scanning sorted subkeys in the registry backend; (bso#7314). + Winbind possibly segfaults when trying a trusted domain without inbound trust; (bso#7316).- Add SMB Traffic Analyzer v2 VFS module.- Document "wide links" defaults to "no" in the smb.conf man page for versions pre-3.4.6; (bnc#577868).- Fix workgroup enumeration, for client printer and file share selection; (bso#6880); (bnc#586215).- Fix tdb validation for offline auth; (bnc#587014).- Fix "printer admin" functionality; (bso#7255).- An uninitialized variable read could cause an smbd crash; (bso#7254); (bnc#605935); CVE-2010-1642.- Ensure to have a valid talloc stackframe; (bso#7251).- _netr_SamLogon segfaults for clients sending NULL domain; (bso#7237).- Merge missing pam_winbind message translations; (bnc#499233).- Remove cifs-mount subpackage for post-11.2 systems as the tools are now part of the independent cifs-utils package.- Fix join of Windows 2008 domains; (bnc#567013).- Update to 3.5.1 and 3.4.7. + Fix security flaw on Linux platforms if built with libcap support allowing file system access even when permissions should have denied it; CVE-2010-0728; (bso#7222); (bnc#586683).- Fixed libldb.so link in libldb-devel.- Fix argc handling in net_share, making the command "net share" work again; (bso#7203); (bnc#584253).- Update to 3.5.0. + Fix duplicate sam and unix accounts; (bso#7145). + Keep the the correct negotiate_flags on the cli->dc structure; (bso#7160). + Avoid calling cli_alloc_mid twice in cli_smb_req_iov_send; (bso#7166). + Fix 'net ads dns' usage calls; (bso#7181). + Fix uninitialized variable in wkssvc_enumerateusers; (bso#7182).- Update to 3.4.6. + Change parameter "wide links" to default to "no"; it's also incompatible with "unix extensions"; (bso#7104); (bnc#577868). + Fix printing with 64 bit clients (bso#6888). + Fix core dump on 64 bit Linux (bso#7063). + Fix failing of smbd to respond to a read or a write caused by Linux asynchronous IO (aio) (bso#7067). + Fix string buffer overflow causing heap corruption in smbd (bso#7096). + Fix bogus ip address in SWAT; (bso#5885). + Fix vfs_full_audit; (bso#6557). + Use the first "uid" value; (bso#6157). + Fix large paged search with DirX LDAP servers; (bso#6981). + Fix crash bug in 'cifs.upcall'; (bso#6868). + Add cross option to samba_cv_linux_getgrouplist_ok; (bso#7047). + Fix DFS on AIX (maybe others); (bso#7052). + Fix pdb_search crash as non-root user; (bso#7068). + Fix unlocking of accounts from ldap; (bso#7072). + Fix vfs_expand_msdfs; (bso#7081). + Fix results of 'smbclient -L' with a large browse list; (bso#7098). + Normalize "Changing password for" msg IDs and STRs; (bso#7102). + Fix malformed require_membership_of_sid; (bso#7106). + Fix reading of large browselist; (bso#7122). + "mangling method = hash" can crash storing a name containing a '.'; (bso#7154). + Valgrind Conditional jump or move depends on uninitialised value(s) error when "mangling method = hash"; (bso#7155). + Fix listing of printjobs in Windows 7; (bso#7130). + Spoolss getprinterdriver2 level 101 marshalling is bad; (bso#7136). + Make idmap cache persistent for "ldapsam:trusted". + Also fill the memcache with sid<->id mappings in ldapsam_sid_to_id() not only the persistent idmap cache. + Shortcut uid_to_sid when "ldapsam:trusted = yes". + Make pdb_copy_sam_account also copy the group sid. + Shortcut gid_to_sid when "ldapsam:trusted = yes". + Speed up pdb_get_group_sid(). + Try to build the full unix_pw structure with ldapsam:trusted support. + Optimize ldapsam_alias_memberships() and cache ldap searches.- Update to 3.5.0rc3. + Change parameter "wide links" to default to "no"; it's also incompatible with "unix extensions"; (bso#7104); (bnc#577868). + Fix vfs_full_audit; (bso#6557). + Fix crash bug in 'cifs.upcall'; (bso#6868). + Fix duplicate initializer in the rmdir module; (bso#6876). + Fix printing with 64 bit clients; (bso#6888). + Add cross option to samba_cv_linux_getgrouplist_ok; (bso#7047). + Fix core dump on Ubuntu 8.04 64 bit; (bso#7063). + Fix failing of smbd to respond to a read or a write caused by Linux asynchronous IO (aio); (bso#7067). + Fix 'smbget' error status; (bso#7069). + Fix build of 'smbfilter'; (bso#7071). + Fix unlocking of accounts from ldap; (bso#7072). + Cliconnect gets realm wrong with trusted domains; (bso#7079). + Fix vfs_expand_msdfs; (bso#7081). + Fix storing of create time on directories in an EA in new create time code; (bso#7084). + Fix an early release of the global lock that can cause data corruption in libtdb; (bso#7085). + Fix string buffer overflow causing heap corruption in smbd; (bso#7096). + Fix results of 'smbclient -L' with a large browse list; (bso#7098). + Normalize "Changing password for" msg IDs and STRs; (bso#7102). + Fix malformed require_membership_of_sid; (bso#7106). + Add pdb_ldap performance fixes; (bso#7116). + Change ldap filter to what really was intended; (bso#7116). + Add new "nmbd bind explicit broadcast" parameter; (bso#7118). + Fix nmbd problems with socket address; (bso#7118). + Support large browselist; (bso#7119). + Fix reading of large browselist; (bso#7122). + Fix listing of printjobs in Windows 7; (bso#7130). + Owner of file not available with Kerberos; (bso#7139). + Fix IPv4/IPv6 problems; (bso#7140). + Fix get_acl_blob in the acl_tdb VFS module; (bso#7148). + "mangling method = hash" can crash storing a name containing a '.'; (bso#7154). + Valgrind Conditional jump or move depends on uninitialised value(s) error when "mangling method = hash"; (bso#7155). + Fix some wrong newlines in de translation strings.- Take extra care that a mount point of mount.cifs isn't changed during mount and don't allow it to be run as setuid root program; CVE-2010-0787; (bso#6853); (bnc#550002).- Check in mount.cifs for invalid characters in device name and mountpoint; CVE-2010-0547; (brc#562156); (bnc#577925).- Don't invalidate cache for uninitialized domains; (bnc#538923).- Signals are processed twice in child; (bnc#538923).- Allow forced pw change even with min pw age; (bnc#561894).- Change parameter "wide links" to default to "no"; it's also incompatible with "unix extensions"; CVE-2010-0926; (bso#7104); (bnc#577868).- Fix enumerate domain local groups for primary domain; (bnc#573813).- Fix malformed require_membership_of_sid; (bnc#525123); (bso#7106).- Normalize "Changing password for" msg IDs and STRs; (bnc#499233).- Build libtevent and libldb and put them into separate subpackages.- Update to 3.5.0rc2. + The Using Samba HTML book has been removed. + 'net', 'smbclient' and libsmbclient can use logon credentials cached by Winbind; (bso#7062). + New vfs_scannedonly module has been added; (bso#7028). + Check password history before increasing "badPasswordCount"; (bso#4347). + Fix changing of ACLs on writable file with "dos filemode=yes"; (bso#5202). + Restore Samba 3.0.x behavior and use the first "uid" value in pdb_ldap; (bso#6157). + Fix deletion of an object whose parent folder does not have delete rights fails even if the delete right is set on the object in vfs_acl_xattr and vfs_acl_tdb; (bso#6876). + Fix large paged search with DirX LDAP servers; (bso#6981). + Fix a segfault in winbindd_dual_ccache_ntlm_auth(); (bso#7027). + Disable sanity check in NetShareEnum for better compatibility with Windows; (bso#7029). + Fix SMBrmdir error message when deleting a directory fails; (bso#7033). + Fix segfault in vfs_cap; (bso#7034). + Fix 'net rpc getsid' in hardened Windows environments; (bso#7036). + Fix a Winbind segfault in "trusted_domains"; (bso#7037). + Complete and improve some German translation of 'net'; (bso#7039). + Fix compile error with WITH_DNS_UPDATE. Update .po files; (bso#7039). + Fix crash bug in libsmbclient; (bso#7043). + Fix bad (non memory copying) interfaces in smbc_setXXXX calls; (bso#7045). + Fix libsmbclient crash against OpenSolaris CIFS server; (bso#7046). + Lock down some srvsvc calls according to what w2k3 seems to do.- Update to 3.4.5. + Fix memory leak in smbd (bug #7020). + Fix changing of ACLs on writable files with "dos filemode=yes" (bug #5202). + BUG 6642: Fix opening the quota magic file. + BUG 6919: Fix remote quota management. + BUG 7034: Fix internal error caused by vfs_cap. + BUG 7036: Fix 'net rpc getsid' in hardened Windows environments. + BUG 7043: Fix crash bug in "SMBC_parse_path". + BUG 7045: Fix bad (non memory copying) interfaces in smbc_setXXXX calls. + BUG 7046: Fix a crash in libsmbclient used against the OpenSolaris CIFS server.- Free unused memory after a packet got processed; (bso#7020).- Add timeout to rpc call to prevent infinite loop when network is down; (bnc#538923).- Update to 3.5.0rc1. + BUG 6837: Fix "Too many open files" when trying to access large number of files with Windows 7; (bnc#619787). + BUG 6939: Fix long filenames when "mangling method" is set to "hash". + BUG 6991: Create symbol links to shared libraries. + BUG 6992: make test for getgrouplist cacheable. + BUG 7014: Fix Winbind crash when retrieving empty group members. + BUG 7020: Fix smbd using 2G memory. + Ensure dos_mode can return FILE_ATTRIBUTE_NORMAL, then filter the returned attributes by protocol level. + Vector correctly through reply_openerror() (which uses the same logic). + Fix bugs with the full Windows ACL support. + Add a few missing gettext calls to the 'net' command. + Fix up a share type translation and translate some more strings in 'net'. + Allow to call "pdbedit -N description -u user" without specifiyng "-r". + Add spoolss_DriverInfo7. + Fix rpcclient after setprinter IDL fixes. + Use generated krb5.conf in 'net ads testjoin'. + Add some German translations for the 'net' command. + Update mount.cifs man page with nounix option. + Fix _samr_GetAliasMembership for results with 0 rids. + Fix an error case in cli_negprot. + Add a lower-cost alternative to wbinfo -t: wbinfo --ping-dc. + Restore correct timeouts for SMB requests. + Fix a 64-bit error in libsmb. + Replace IS_DOMAIN_OFFLINE by a function in Winbind. + Simplify/cleanup Winbind code. + Fix write behind memory block in libtalloc. + Fix result check for getaddrinfo(). + Add tsocket_address_bsd_sockaddr() and tsocket_address_bsd_from_sockaddr() to tsocket. + Always set tdb->tracefd to -1 to be safe on goto fail in libtdb. + Add TDB_DISALLOW_NESTING and make TDB_ALLOW_NESTING the default behavior. + Fix standalone 'make installdocs'. + Output %p as unsigned in snprintf replacement. + New attempt at TDB transaction nesting allow/disallow. + Remove swig stuff from libtdb. + Reset tdb->fd to -1 in tdb_close() in libtdb. + Change the way mksysms work in libtalloc. + Also build and install tdb manpages from standalone tdb. + Fix infinite loop in NCACN_IP_TCP as there is no timeout. + Make winbindd_cache.c aware of domain offline to avoid unnecessary backend query. + List trusted domains from wcache when domain is offline.- Update to 3.4.4. + Fix interdomain trust relationships with Win2008R2 (bug #6697). + Fix Winbind crashes when queried from nss (bug #6889). + Fix Winbind crash when retrieving empty group members (bug #7014). + Fix "UID range full" error in Winbind (bug #6901). + Fix multiple LDAP servers in "idmap backend" and "idmap alloc backend" (bug #6910). + BUG 4832: Fix iconv checks. + BUG 6338: Do not always display "none" in 'net rpc trustdom list'. + BUG 6851: Add pdbedit --kickoff-time/-K to set the user's kickoff time. + BUG 6828: Fix infinite timeout when byte lock held outside of samba. + BUG 6837: Fix "Too many open files" message when trying to access a large number of files with Windows 7; (bnc#619787). + BUG 6841: Fix "map acl inherit = yes". + BUG 6850: Fix shadow copy display on Windows 7. + BUG 6867: Fix listing of directories with a lot of files. + BUG 6868: Support building with Heimdal we well as with MIT. + BUG 6875: Fix DOS attributes on OS/2 clients. + BUG 6880: Fix listing of workgroup servers in libsmbclient. + BUG 6898: Samba duplicates file content on appending. + BUG 6918: Fix krb5 build problem on Ubuntu karmic. + BUG 6929: Fix build with recent heimdal. + BUG 6939: Fix long filenames with "mangling method = hash". + BUG 6967: Fix 'net ads join' with OU. + BUG 6981: Fix paged search with DirX LDAP server. + BUG 6982: Remove erroneous out of memory error path in lookup_sid. + BUG 6997: Fix _samr_GetAliasMembership for results with 0 rids. + BUG 7005: Fix "mangle method = hash" truncates files with dot "." character. + Fix the build of the winbind krb5 locator plugin. + Fix enumprinter key client and server.- Readjust the _libdir/cups/backend/smb sym link only on uninstall of the samba-krb-printing package; (bnc#568603).- Add BuildRequires to fam-devel; (bnc#564260).- Prevent winbind crash; (bso#7014); (bnc#566119).- Fix processing of open modes in POSIX open; (bnc#530683).- Add baselibs.conf as a source.- Update to 3.5.0pre2. + BUG 2350: Add LDAP Alias Dereferencing support. + BUG 6288: SWAT adds a second share when changing parameters of an existing share. + BUG 6435: Fix minor memory corruption. + BUG 6710: Only install the cifs.upcall man page if CIFSUPCALL_PROGS was set while configure. + BUG 6802: A created folder does not properly inherit permissions from parent in vfs_acl_xattr. + BUG 6837: "Too many open files" when trying to access large number of files from Windows 7; (bnc#619787). + BUG 6860: Fix shared library build on QNX. + BUG 6879: Fix crash in Winbind. + BUG 6929: Fix build with recent heimdal. + BUG 6938 : No hook exists to check creation rights when using acl_xattr module. + BUG 6967: Prevent glibc error on 'net ads join'. + Fix vfs_acl_xattr which was failing to call the NEXT connect function. + Restructure the ACL code. + Refactor reply_rmdir to use handle based code. + Fix the build when no external talloc and tdb are installed. + Fix detection of CTDB headers on systems without system-libtalloc. + Fix several printing issues. + Fix the build on Mac OS X 10.6.2. + Fix net and rpcclient after setprinterdataex changes. + Add full support for level 8 printer drivers. + Add more spoolss architectures to IDL. + Fix enumprinter key client and server. + Fix crash in EnumPrinterDataEx. + Prefer posix_fallocate for doing "strict allocate". + Restore "fake directory create times" as a share parameter. + Fix explicit stat64 support. + Add support for NetWkstaGetInfo 101 and 102. + Add rpcclient wkssvc_enumerateusers. + De-deprecate "write cache size" to prevent its removal without a proper alternative. + Allow more than 1000 users in BUILTIN\Users. + Complete support for NetWkstaGetInfo/NetWkstaEnumUsers. + Fix the build of the example VFS modules. + Fix crash in free_file_list(). + Give the user a chance to change password when password will expire soon.- Store the smbfs service state if enabled and restore it for cifs while upgrade on post-11.2 systems.- Prevent cifstab from being overwritten while upgrade on post-11.2 systems.- Give the user a chance to change password when password will expire soon; (FATE#302414).- Rename smbfs init script to cifs for post-11.2 systems.- Allow Windows 7 to connection to samba domain controllers and member servers; (bnc#551811); (bso#6099); (bso#6100); (bso#6680).- Error on joining windows domain (invalid pointer); (bso#6967); (bnc#553622).- Add PreReq /usr/sbin/groupadd to the winbind package; (bnc#559165). - Simplify the winbind package %pre script and suppress stdout only.- Update to 3.5.0pre1 + Add support for full Windows timestamp resolution. + Experimental implementation of SMB2. + Add encryption support for connections to a CUPS server. + Major windbind asynchronous refactoring. - Remove using_samba from the doc package. - Increase major version of libtalloc to 2.- Fix kerberos refresh chain; (bnc#546162); (bso#6872).- Hardlink duplicate files on post-11.1 systems.- Add BuildArch noarch to samba-doc on post-11.1 systems.- Use full 16byte session key in make_user_info_netlogon_interactive(); (bnc#551811).- Update to 3.4.3. + Fix trust relationships to windows 2008 (2008 r2) (bug #6711). + Fix file corruption using smbclient with NT4 server (bug #6606). + Fix Windows 7 share access (which defaults to NTLMv2) (bug #6680). + BUG 4675: mount.cifs: Do not attempt to update /etc/mtab if it is a symbolic link. + BUG 6529: Offline files conflict with Vista and Office 2003. + BUG 6532: Fix domain enumeration if master browser has space in name. + BUG 6606: Fix file corruption using smbclient with NT4 server. + BUG 6690: Fix wrong error check in profile. + BUG 6703: Allow smbstatus as non-root. + BUG 6704: Fix syntax error in avahi configure test. + BUG 6707: Fix an occasional segfault in config file parsing. + BUG 6710: Adjust regex to match variable names including underscores. + BUG 6711: Fix trust relationships to windows 2008 (2008 r2). + BUG 6726: SIVAL should have been an SVAL. + BUG 6728: BSD needs sys/sysctl.h included to build properly. + BUG 6731: Fix reading beyond the end of a named stream in xattr_streams. + BUG 6735: Don't overwrite password in pam_winbind, subsequent pam modules might use the old password and new password. + BUG 6764: Fix timeval calculation. + BUG 6765: Add a "hidden" parameter "share:fake_fscaps". + BUG 6769: Fix symlink unlink. + BUG 6772: Allow outstanding_aio_calls to be decremented. + BUG 6774: smbd crashes if "aio write behind" is set. + BUG 6776: Fix core dump caused by running overlapping Byte Lock test. + BUG 6781: Fix renaming subfolders in Explorer view. + BUG 6791: Fix linking order in cifs.upcall. + BUG 6793: Fix Winbind crash with "INTERNAL ERROR: Signal 6". + BUG 6793: Fix segfault in winbindd_pam_auth. + BUG 6796: Deleting an event context on shutdown can cause smbd to crash. + BUG 6797: Fix a memleak in libwbclient. + BUG 6804: Fix hpux compiler issue. + BUG 6805: Correctly handle aio_error() and errno. + BUG 6807: Fix a segfault in "net rpc trustdom list" for long domain names. + BUG 6810: Add support for finding alternate credcaches to cifs.upcall. + BUG 6811: Fix reference to freed memory in pam_winbind. + BUG 6815: Fix Windows 2008 R2 SPNEGO negTokenTarg parsing failure. + BUG 6824: Fix avahi activation. + BUG 6826: Don't fail authentication when one or some group of require-membership-of is invalid. + BUG 6828: Fix infinite timeout when byte lock held outside of Samba. + BUG 6829: Fix displaying of multibyte characters in smbclient. + BUG 6840: Fix crash in pam_winbind. + Fix an uninitialized variable. + Only ever handle one event after a select call. + Conditional install of the cifs.upcall man page. + Fix warning occuring when building the manpages.- Let smbclient show special characters properly; (bso#6829); (bnc#544204).- Don't fail authentication when one or some group of require-membership-of is invalid; (bnc#525123); (bso#6826).- Allow winbind to ignore certain domains; (bnc#539506).- Update to 3.4.2. + Fix unresolved home path; CVE-2009-2813; (bso#6763); (bnc#539517). + Fix potential denial of service; CVE-2009-2906; (bso#6768); (bnc#543115). + Fix potential mount.cifs password leaks; CVE-2009-2948; (bnc#542150).- Fix potential denial of service; CVE-2009-2906; (bnc#543115).- Fix potential mount.cifs password leaks; CVE-2009-2948; (bnc#542150).- Fix unresolved home path; CVE-2009-2813; (bnc#539517).- Don't overwrite password in pam_winbind; (bnc#515444).- mods for winbind (when used with squid - ntlm_auth) o winbind adds group 'winbind' o permission 0750,root,winbind LOCKDIR/winbindd_privileged- Merge two fixes from 3.2.8 and 3.3.1. + Adjust regex to match variable names including underscores. + Conditional install of the cifs.upcall man page.- Remove supplements from baselibs.conf while %clean for pre-11.1 systems; (bnc#520579).- Update to 3.4.1. + Fix authentication on member servers without Winbind (bug #6650). + Nautilus fails to copy files from an SMB share (bug #6649). + Fix connections of Win98 clients (bug #6551). + Fix interdomain trusts with Windows 2008 R2 DCs (bug #6697). + Fix Winbind authentication issue (bug #6646). + BUG 5879: Update LDAP schema for Netscape DS 5. + BUG 5886: Fix password change propagation with ldapsam. + BUG 6105: Make linking of cifs.upcall and rpcclient --as-needed safe. + BUG 6222: Default to DRSUAPI replication for net rpc vampire keytab. + BUG 6437: Make open_udp_socket() IPv6 clean. + BUG 6496: MS-DFS cannot follow multibyte char link name in libsmbclient. + BUG 6506: Smbd server doesn't set EAs when a file is overwritten in NT_TRANSACT_CREATE. + BUG 6532: Fix the build with external talloc. + BUG 6538: Cancel all locks that are made before the first failure. + BUG 6560: Fix lookupname. + BUG 6564: SetPrinter fails (panics) as non root. + BUG 6568: Fix _spoolss_GetPrintProcessorDirectory() implementation. + BUG 6585: Fix unqualified "net join". + BUG 6593: Correctly implement SMB_INFO_STANDARD setfileinfo. + BUG 6601: Avoid global fd limits. + BUG 6607: Fix crash bug in spoolss_addprinterex_level_2. + BUG 6611: Fix a valgrind error in chain_reply. + BUG 6615: Fix browsing of DFS when using kerberos in libsmbclient. + BUG 6627: Raise the timeout for lsa_Lookup*() calls from 10 to 35 seconds. + BUG 6650: Fix authentication on member servers without Winbind. + BUG 6651: Fix smbd SIGSEGV when breaking oplocks. + BUG 6655: Fix 'smbcontrol smbd ping'. + BUG 6620: Fix a bug in renames of directories. + BUG 6664: Fix truncation of the session key. + BUG 6673: Fix 'smbpasswd' with "unix password sync = yes". + BUG 6680: Fix authentication failure from Windows 7 when domain joined. + BUG 6688: Fix crash in 'net usershare list'. + BUG 6693: Check we read off the complete event from inotify. + BUG 6700: Use dns domain name when needing to guess server principal.- Update to 3.2.14. + Fix SAMR access checks (e.g. bugs #6089 and #6112). + Fix 'force user' (bug #6291). + Improve Win7 support (bug #6099). + Fix posix ACLs when setting an ACL without explicit ACE for the owner (bug #2346). + BUG 6387: Fix Winbind crash when multiple IDmappings exist in the LDAP directory. + BUG 6509: Use gid (not uid) cache in fetch_gid_from_cache(). + BUG 6089: Fix SAMR access checks. + BUG 6112: Fix SAMR access checks. + BUG 6279: Fix Winbind crash. + BUG 6291: Fix 'force user'. + BUG 6099: Try to fix domain join of Win7 Beta. + BUG 6386: Groupdb mapping fix. + BUG 6421: Fix POSIX read-only open on read-only shares. + BUG 6476: Fix more smbd-zombies in memory. + BUG 6488: acl_group_override() call in posix acls references an uninitialized variable. + BUG 6504: Fix SAMR server for Winbind access. + BUG 6520: Fix time stamps. + BUG 6301: Fix samr_ConnectVersion enum which is 32bit not 16bit. + BUG 6340: Don't segfault when cleartext trustdom pwd could not be retrieved. + BUG 6372: Fix usermanager only displaying 1024 groups and aliases. + BUG 6465: Fix enum_aliasmem in ldb branch. + BUG 6484: Fix searching for users while adding them to groups via Windows usermanager. + BUG 2346: Fix posix ACLs when setting an ACL without explicit ACE for the owner. + BUG 6526: Let parent_dirname() correctly return toplevel filenames. + BUG 6627: Raise the timeout for lsa_Lookup*() calls from 10 to 35 seconds. + BUG 5798: Preserve CFLAGS info in configure. + BUG 6382: Case insensitive access to DFS links broken. + BUG 6481: Don't require "Modify property" perms to unjoin. + BUG 6628: 'smbpasswd -a' uses algorithmic rid base with 'passdb backend = tdbsam'. + BUG 6560: Lookupname failed, cannot find domain when attempt to change password. + Prevent creation of keys containing the '/' character. + Fix join of Windows 7 RC to a Samba3 DC. + Fix bug in processing of open modes in POSIX open. + Fix the negotiate flags. + Protect netlogon_creds_server_step() against NULL creds. + Also handle DirX return codes. + Fix a crash bug if we timeout in net rpc trustdom list. + Add '--request-timeout' option to 'net'. + Fix a race condition in Winbind leading to a panic. + Add workaround for MS KB932762. + 5945: Fix out of memory error with Winbind idmap. + Avoid duplicate ACEs. + Fix profile ACLs in some corner cases. + Zero an uninitialized array.- Unable to browse DFS when using kerberos in libsmbclient; (bnc#528271); (bso#6615).- check in .po files for pam_winbind; (bnc#499233); (bso#6602).- Add ntp and network-remotefs as Should-Start dependency to the winbind init script; (bnc#515629).- Update to 3.0.36. + Fix Winbind crash on 'getent group' (bug #5906). + Excel save operation corrupts file ACLs (bug #4308). + Prevent segmentation fault on joining a very long domain name. + BUG 4308: Excel save operation corrupts file ACLs. + BUG 4370: Clean-up entries in /etc/mtab after unmount. + BUG 4640: Fix guest mounts in mount-cifs. + BUG 5906: Fix Winbind crash on 'getent group'. + BUG 6066: netinet/ip.h present but cannot be compiled on Solaris. + BUG 6099: In order to allow Win7 to connect to a Samba NT style. + BUG 6279: Fix Winbind crash. PDC we set the flags before we know if it's an error or not. + BUG 6085: Fix build of vfs_default. + BUG 6098: When the DNS server is invalid, the ads_find_dc() does not work correctly. + Fix logic error in try_chown. + Correctly use chroot(). + Fix bug in processing of open modes in POSIX open. + Don't install the cifs.upcall binary twice. + Fix mount.cifs handling of -V option. + Prevent segmentation fault on joining a very long domain name. + Don't try and delete a default ACL from a file. + Add workaround for MS KB932762. + Add fakemount (-f) and nomtab (-n) flags to mount.cifs. + Fix a crash during name resolution when log level >= 10 and libc segfaults if printf is passed NULL for a "%s" arg.- Use a conditional suse_version macro in front of the SUSE_ASNEEDED export.- lookupname failed, cannot find domain when attempt to change password; (bnc#520645); (bso#6560).- Don't link with --as-needed flag on post-11.1 systems.- Stop the smbfs service if an interface goes down; (bnc#517768).- Disable build of static libraries on post-11.1 systems; (bnc#509945).- Fix missing zlibs for cifs.upcall and test_shlibs.- Update to 3.4.0. + BUG 6431: Local groups from 3.0 setups no longer found. + BUG 6459: Fix build of pam_smbpass on some distributions. + BUG 6481: 'net ads leave' needs to try account deletion, NetUnjoinDomain not. + BUG 6497: Fix calling of 'test' in configure. + BUG 6498: Add workaround for MS KB932762. + BUG 6499: Fix building of pam_smbpass. + BUG 6509: Use gid (not uid) cache in fetch_gid_from_cache(). + BUG 6512: Fix support for enumerating user forms. + BUG 6514: Improve error message in 'net' when smb.conf is not available. + BUG 6520: Fix time stamps when "unix extensions = yes". + BUG 6521: Fix building tevent_ntstatus without config.h. + BUG 6526: Fix notifies in the share root directory. + BUG 6531: Fix pid file name.- Package /etc/samba/smbpasswd as %ghost on post-11.1 systems.- Fix net ads leave; (bnc#511695).- Supplement pam-32bit/pam-64bit in baselibs.conf (bnc#354164). - Supplement glibc-32bit/glibc-64bit in baselibs.conf (bnc#354164).- Update to 3.2.13, 3.3.6. + In Samba 3.2.0 to 3.2.12 (inclusive), the smbclient commands dealing with file names treat user input as a format string to asprintf. With a maliciously crafted file name smbclient can be made to execute code triggered by the server; CVE-2009-1886; (bnc#513360); (bso#6478).- Update to 3.0.35. + In Samba 3.0.31 to 3.3.5 (inclusive), an uninitialized read of a data value can potentially affect access control when "dos filemode" is set to "yes"; CVE-2009-1888; (bnc#515479).- Uninitialized read of a data value; CVE-2009-1888 (bnc#515479).- Update to 3.4.0rc1. + BUG 4699: Remove pidfile on clean shutdown. + BUG 5456: Fix "net ads testjoin". + BUG 6081: Make it possible to change machine account sids. + BUG 6253: Use correct value for password expiry calculation in pam_winbind. + BUG 6297: Owner of sticky directory cannot delete files created by others. + BUG 6305: Correctly prompt for a password when a username was given. + BUG 6328: Add support for multiple rights to "net sam rights grant/revoke". + BUG 6333: Consolidate create/delete account paths in pdbedit. + BUG 6449: 'net rap user add' crashes without -C option. + BUG 6451: net/libnetapi user rename using wrong access bits. + BUG 6458: Fix uninitialized variable in local_password_change(). + BUG 6465: Fix enumeration of empty aliases. + BUG 6476: Fix smbd-zombies in memory when using [x]inetd. + BUG 6487: Add missing DFS call in trans2 mkdir call. + BUG 6488: acl_group_override() call in posix acls references an uninitialized variable. + Improve pam_winbind documentation. - Install a vendor copy of samba-common.dhcp as dhcpcd-hook-samba-functions.- Samba 3.2.0 - 3.2.12 smbclient commands dealing with file names treat user input as a format string to asprintf; CVE-2009-1886; (bnc#513360).- Fix a bad memleak in vfs_full_audit; (bnc#510035).- Update to 3.3.5. + Fix SAMR and LSA checks (bug #6089, #6289) + Fix posix acls when setting an ACL without explicit ACE for the owner (bug #2346). + Fix joining of Win7 into Samba domain (bug #6099). + Fix joining of Win2000 SP4 clients (bug #6301). + BUG 2346: Fix posix acls when setting an ACL without explicit ACE for the owner. + BUG 5832: Fix build on RHEL when ccache is not available. + BUG 5853: Add keyutils-devel to build requires to fix build on RHEL. + BUG 5897: Fix shutdown script example in the smb.conf manpage. + BUG 6089: Revert the extra SAMR and LSA checks. + BUG 6099: Fix joining of Win7 into Samba domain. + BUG 6157: Fix handling of multi-value attribute "uid". + BUG 6289: Revert the extra SAMR and LSA checks. + BUG 6297: Owner of sticky directory cannot delete files created by others. + BUG 6301: Fix joining of Win2000 SP4 clients. + BUG 6309: Support remote unjoining of Windows 2003 or greater. + BUG 6315: smbd crashes doing vfs_full_audit on IPC$ close event. + BUG 6320: Handle registry config source in file_list. + BUG 6330: Fix DFS on AIX. + BUG 6336: Fix 'net groupmap set' segfault. + BUG 6361: Make --rcfile work in smbget. + BUG 6365: Re-Add the "dropbox" functionality with -wx rights on a directory. + BUG 6372: Fix usermanager only displaying 1024 groups and aliases. + BUG 6382: Fix case insensitive access to DFS links. + BUG 6415: Filter out of range mappings in default idmap config in idmap_tdb. + BUG 6416: Filter out of range mappings in default idmap config in idmap_tdb2. + BUG 6417: Filter out of range mappings in default idmap config in idmap_ldap. + BUG 6441: Fix the compile with --enable-dnssd. + BUG 6449: 'net rap user add' crashes without -C option. + BUG 6465: Fix enumeration of empty aliases (ldb backend). + Prevent infinite include nesting. + Mark registry shares without path unavailable. + Also handle DirX return codes. + Fix Coverity ID 897. + Do not crash in ctdbd_traverse if ctdbd is not around. + Fix a race condition in winbind leading to a panic. + Some man pam_winbind improvements. + Zero an uninitialized array.- Update to 3.2.12. + Fix SAMR and LSA checks (bug #6089, #6289) + Fix posix acls when setting an ACL without explicit ACE for the owner (bug #2346). + Fix "force user" (bug #6291). + Fix Winbind crash (bug #6279). + Fix joining of Win7 into Samba domain (bug #6099). + BUG 2346: Fix posix acls when setting an ACL without explicit ACE for the owner. + BUG 5798: CFLAGS info lost in configure. + BUG 5832: Fix build on RHEL when ccache is not available. + BUG 5835: Add keyutils-devel to build requires. + BUG 5945: Fix out of memory error with Winbind idmap. + BUG 6089: Revert the extra SAMR and LSA checks. + BUG 6099: Fix joining of Win7 into Samba domain. + BUG 6279: Fix Winbind crash. + BUG 6289: Revert the extra SAMR and LSA checks. + BUG 6291: Fix "force user". + BUG 6301: Fix samr_ConnectVersion enum which is 32bit not 16bit. + BUG 6372: Fix usermanager only displaying 1024 groups and aliases. + BUG 6386: Groupdb mapping fix. + BUG 6382: Fix case insensitive access to DFS links. + BUG 6465: Fix enumeration of empty aliases (ldb backend). + Prevent creation of keys containing the '/' character. + Fix bug in processing of open modes in POSIX open. + Protect netlogon_creds_server_step() against NULL creds. + Also handle DirX return codes. + Fix a race condition in winbind leading to a panic. + Fix a crash bug if we timeout in net rpc trustdom list. + Fix profile acls in some corner cases.- Default with passdb backend to smbpasswd for SUSE products older than 11.2.- Explicitly use 'tdbsam' as passdb backend in the default smb.conf file.- Update to 3.4.0pre2. + The default passdb backend has been changed to 'tdbsam'! + Samba4 and Samba3 sources are included in the tarball. + Changed the way smbd handles untrusted domain names given during user authentication. + Various fixes including printer change notificiation for Samba spoolss print servers. + The remaining hand-marshalled DCE/RPC services (ntsvcs, svcctl, eventlog and spoolss) were replaced by autogenerated code based on PIDL. + Samba3 and Samba4 do now share a common tevent library. + The code has been cleaned up and the major basic interfaces are shared with Samba4 now. + An asynchronous API has been added. + Made parameter syntax of the net command more consistent. + BUG 2346: Fix posix ACLs when setting an ACL without explicit ACE for the owner. + BUG 4271: testparm should not print includes. + BUG 4831: Don't call openlog() or closelog() from pam_smbpass. + BUG 5681: Do not limit the number of network interfaces. + BUG 5859: Fix renaming of samr objects failed due to samr setuserinfo access checks. + BUG 6099: Fix NETLOGON credential chain. + BUG 6136: New AFS syscall conventions. + BUG 6157: Fix handling of multi-value attribute "uid". + BUG 6253: Use correct value for password expiry calculation. + BUG 6291: Fix 'force user'. + BUG 6292: Update config.guess from gnu.org. + BUG 6302: Give the VFS a chance to read from 0-byte files. + BUG 6309: Support remote unjoining of Windows 2003 or greater. + BUG 6313: ldapsam_update_sam_account() crashes while doing talloc_free on malloced memory. + BUG 6315: Fix smbd crashes when doing vfs_full_audit on IPC$ close event. + BUG 6320: Handle registry config source in file_list. + BUG 6330: Fix DFS on AIX. + BUG 6336: Fix segfault in 'net groupmap set'. + BUG 6340: Don't segfault when cleartext trustdom pwd could not be retrieved. + BUG 6357: Use Samba default command line arguments in 'net'. + BUG 6359: smbclient -L does not list workgroup for hosts with both IPv4 and IPv6 addresses + BUG 6361: Make --rcfile work in smbget. + BUG 6371: Unsuccessful 'net conf setparm' leaves empty share. + BUG 6372: usermanager only displaying 1024 groups and aliases. + BUG 6387: Fix a crash bug in idmap_ldap_unixids_to_sids. + BUG 6415: Filter out of range mappings in default idmap config (idmap_tdb). + BUG 6416: Filter out of range mappings in default idmap config (idmap_tdb2). + BUG 6417: Filter out of range mappings in default idmap config (idmap_ldap). + Change the way smbd handles untrusted domain names given during user authentication. + Replace the hand-marshalled DCE/RPC services ntsvcs, svcctl, eventlog and spoolss by autogenerated code based on PIDL. + Fix several printing issues and improve support for printer change notificiations. + Add 'net eventlog'. + Add asynchronous API. + Make Samba3 and Samba4 share a tevent library. + Add two new parameters to control how we verify kerberos tickets. + Add 'net rpc service' subcommands 'create' and 'delete'. + Fix the core of the SAMR access functions. + Fix SAMR server for winbindd access. + Add dbwrap_tool - a tdb tool that is CTDB-aware. + Hide "config backend" from swat. + Fix linking with --disable-shared-libs. + Fix issue with missing entries when enumerating directories. + Map NULL domains to our global sam name. + Fix driver upload for Xerox 4110 PS printer driver. + Add "net dom renamecomputer" to rename machines in a domain. + Inspect the correct computername string before enabling/disabling the change button in netdomjoin-gui. + Fix join prompt dialog test in netdomjoin-gui. + Only gray out labels when not root and not connecting to remote machines (netdomjoin-gui). + Allow to switch between workgroups/domains with the same name (netdomjoin-gui). + Add NetShutdownInit and NetShutdownAbort. + Fix samr access checks. + Add a security model to LSA. + Also handle DirX return codes. + Do not crash in ctdbd_traverse if ctdbd is not around. + Fix Coverity ID 897. + Fix a race condition in vfs_aio_fork with gpfs share modes. + Fix bug disclosed by lock8 torture test. + Fix a race condition in winbind leading to a panic. + Detect tight loop in tdb_find(). + Fix chained sesssetupAndX/tconn messages. + Fix strict locking with chained reads. + Fix two bugs in sendfile. + Fix memory leak. + Fix file descriptor leak. + Fallback to the legacy sid_to_(uid|gid) instead of returning NULL. + Always allocate memory in dptr_ReadDirName. + Fix 'net' crash during domain join. + Zero an uninitialized array. + Allow child processes to exit gracefully if we are out of fds.- Enable cifs.upcall on versions newer than SUSE 10.0.- Add BuildRequires to keyutils-devel.- Remove redundant Requires to keyutils-libs for cifs-mount.- Detect tight loop in tdb_find(); (bnc#450974).- Fix lp printing with kerberos; (bnc#476913).- Add BuildRequires to ctdb-devel for systems newer than SUSE 10.0 and all other build targets.- Update to 3.4.0pre1. + Samba4 and Samba3 sources are included in the tarball + Changed the way smbd handles untrusted domain names given during user authentication. + Various fixes including printer change notificiation for Samba spoolss print servers. + The remaining hand-marshalled DCE/RPC services (ntsvcs, svcctl, eventlog and spoolss) were replaced by autogenerated code based on PIDL. + Samba3 and Samba4 do now share a common tevent library. + The code has been cleaned up and the major basic interfaces are shared with Samba4 now. + An asynchronous API has been added. + Change the way smbd handles untrusted domain names given during user authentication. + Replace the hand-marshalled DCE/RPC services ntsvcs, svcctl, eventlog and spoolss by autogenerated code based on PIDL. + Fix several printing issues and improve support for printer change notificiations. + Add 'net eventlog'. + Add asynchronous API. + Make Samba3 and Samba4 share a tevent library. + Add two new parameters to control how we verify kerberos tickets. + Add 'net rpc service' subcommands 'create' and 'delete'. + Make merged build possible. + Move common libraries to the shared lib/ directory.- Update to 3.3.4. + Fix domain logins for WinXP clients pre SP3 (bug #6263). + Fix samr_OpenDomain access checks (bug #6089). + Fix usrmgr.exe creating a user (bug #6243). + BUG 6089: Fix samr_OpenDomain access checks. + BUG 6254: Fix IPv6 PUT/GET errors to an SMB server (3.3) with "msdfs root" set to "yes". + BUG 6279: Fix Winbind crash. + BUG 5329: Add "net rpc service delete/create". + BUG 6238: Make sure wbcLogoffUserParams are properly initialized before freed. + BUG 6263: Fix domain logins for WinXP clients pre SP3. + BUG 6286: Call init function for builtin idmap modules before probing for them as shared modules. + BUG 6243: Fix usrmgr.exe creating a user. + net conf: Save share name as given, not as lower case only. + Prevent creation of registry keys containing the '/' character. + Allow pdbedit to change a user rid/sid. + When doing a cli_ulogoff don't invalidate the cnum, invalidate the vuid. + Don't access a freed structure when logging off and re-using a vuid. + Try to to fix password_expired flag handling. + Make sure to grey out change fields in the netdomjoin-gui when not running as root. + Don't look up local user for remote changes, even when root. + Use procid_str in debug messages for better cluster-debuggability. + Use cluster-aware procid_is_me instead of comparing pids. + Fix smbd crash for close_on_completion. + Fix a memleak in an unlikely error path in change_notify_create(). + Do not use the file system GET_REAL_FILENAME for mangled names. + Fix a crash bug if we timeout in net rpc trustdom list. + Add '--request-timeout' option to net. + In net_conf_import, start a transaction when importing a single share. + Fix writing of roaming profiles with "profile acls" set to "yes".- Update to 3.2.11. + Fix domain logins for WinXP clients pre SP3 (bug #6263). + Fix samr_OpenDomain access checks (bug #6089). + Fix smbd crash for close_on_completion. + BUG 6089: Fix samr_OpenDomain access checks. + BUG 6205: Correct sample smb.conf share configuration. + BUG 6254: Fix IPv6 PUT/GET errors to an SMB server (3.3) with "msdfs root" set to "yes". + BUG 6263: Fix domain logins for WinXP clients pre SP3. + Allow pdbedit to change a user rid/sid. + When doing a cli_ulogoff don't invalidate the cnum, invalidate the vuid. + Fix resume command typo for "printing = vlp". + Fix smbd crash for close_on_completion. + Fix a memleak in an unlikely error path in change_notify_create(). + Don't look up local user for remote changes, even when root.- Don't lookup local user for remote password changes; (bnc#493507).- Update to 3.3.3. + Migrating from 3.0.x to 3.3.x can fail to update passdb.tdb correctly (bug #6195). + Fix serving of files with colons to CIFS/VFS client (bug #6196). + Fix "map readonly" (bug #6186). + BUG 6195: Don't let smbd child processes panic. + Add backend_requires_messaging() method to libsmbconf. + Add methods is_writeable() and wrapper smbconf_is_writeable() to libsmbconf. + Fall back to file backend when no valid backend was found. + Fix a memleak in dbwrap_rbt. + Provide transaction_start|commit|cancel fns for the registry tdb. + Speed up "net conf drop". + Speed up "net conf import". + Add transactions to the libsmbconf API. + Reduce memory usage of "net conf import". + Registry cleanup. + Fix handling of SAMBA_VERSION_VENDOR_PATCH. + Fix build of pam_winbind.so with static linking. + Tidy up some convert_string_internal error cases. + BUG 6224: nmbd waits 5 minutes at startup before checking if it needs to run elections. + Allow DFS client paths to work when POSIX pathnames have been selected. + Try and fix the build farm RAW-STREAMS errors. + Ensure files starting with multiple dots are hidden. + BUG 6102: NetQueryDisplayInformation could return wrong information. + BUG 6193: Avoid messing with sync_context in libnet_samsync_delta(). + Fix notify_printer_status_byname. + Fix Coverity IDs 722, 762, 774, 775, 776. + Fix build on old Heimdal based systems. + Fix compile warning. + Use parentheses in if condition to make negation clear. + Add dirsort module. + BUG 6147: Fix detection of the GNU ld version. + BUG 6097: Fix smbd segfault. + BUG 6130: Don't crash in winbindd_rpc lookup_groupmem() on unmapped members. + BUG 6139: Add missing whitespace in mount.cifs error message. + Fix a malloc/talloc mismatch when cli_initialise() fails. + Fix a valgrind error. + Speed up "net conf list". + Add sorted subkey cache. + Use StrCaseCmp in the dirsort module. + Document the dirsort module. + Disable dns_sd by default. + Add avahi detection to configure. + Add event avahi binding. + Use avahi to register _smb._tcp in smbd. + Fix two memleaks in the encryption code. + Fix a scary "fill_share_mode_lock failed" message. + BUG 6228: Fix SMBC_open_ctx failure due to path resolve failure doesn't set errno. + Don't use reserved words in smbconftort. + Fix smb signing for fragmented trans/trans2/nttrans requests. + Parse_packet can return NULL which is then dereferenced in match_mailslot_name. + Format the header check for netinet/ip.h more nicely. + Missing break in conversion function prevents tdb password database update.- Update to 3.2.10. + BUG #6195: Don't let smbd child processes panic.- BUG 6195: Fix crash on passdb conversion.- Update to 3.2.9. + BUG 5920: The length of the memcpy was calculated wrong. + BUG 6097: Fix smbd segfault. + BUG 6098: Fix ads_find_dc() with "security = domain" when the DNS server is invalid. + BUG 6099: Samba returns incurrate capabilities list. + BUG 6100: Implement _netr_LogonGetCapabilities() with NT_STATUS_NOT_IMPLEMENTED. + BUG 6102: NetQueryDisplayInformation could return wrong information. + BUG 6130: Fix crash in winbindd_rpc lookup_groupmem() on unmapped members. + BUG 6133: Cannot delete non-ACL files on NFSv4 ACL filesystem. + BUG 6161: smbclient corrupts source path in tar mode. + BUG 6193: Avoid messing with sync_context in fetch_database_to_ldif(). + BUG 6196: Unable to serve files with colons to Linux CIFS/VFS client. + BUG 6224: nmbd waits 5 minutes before checking to run elections. + BUG 6228: Fix SMBC_open_ctx failure when path failure doesn't set errno. + Numerous Coverity fixes + Fix double free caused by incorrect talloc_steal usage. + Backport delete semantics of alternate data streams on a file truncate. + Allow set attributes on a stream fnum to redirect to the base filename. + Fix use of streams modules with CIFSFS client. + Fix more POSIX path lstat calls. + Allow DFS client paths to work with POSIX pathnames. + Ensure files starting with multiple dots are hidden. + Fix guest auth when Winbind is running. + Fix memleak in get_remote_printer_publishing_data(). + cifs mount fix for handling -V parameter. + Fix guest mounts. + Clean-up entries in /etc/mtab after unmount. + Add fakemount (-f) and nomtab (-n) flags to mount.cifs. + Enable total anonymization in vfs_smb_traffic_analyzer. + Don't try and delete a default ACL from a file. + Fix remotely adding a share via MMC. + Fix resume handle for _samr_EnumDomainGroups. + Fix a buffer handling bug when adding lots of registry keys. + Fix a O(n^2) algorithm in regdb_fetch_keys(). + Fix a valgrind error / segfault in dns_register_smbd(). + Don't log NDR_PRINT_DEBUG at level 0, this always ends up in syslog. + Fix a malloc/talloc mismatch when cli_initialise() fails. + Fix two memleaks in the encryption code. + Fix "fill_share_mode_lock failed" message. + Add S-1-22-X-Y sids to the local token. + Fix smb signing for fragmented trans/trans2/nttrans requests. + Don't miss an absolute pathname as a kerberos keytab path. + Have nmbd check all available interfaces for WINS before failing. + Initialize the id_map status in idmap_ldap to avoid surprise.- Obsolete change from 2008-03-05 by removing the needless examples cleanup.- Update to 3.3.2. + Fix "force group" (bug #6155). + Fix saving of files on Samba share using MS Office 2007 (bug #6160). + Fix guest authentication in setups with "security = share" and "guest ok = yes" when Winbind is running. + Fix corruptions of source path in tar mode of smbclient (bug #6161). + BUG 6082: Fix renaming and deleting of directories using Windows clients. + BUG 6154: Make ZFS honor admin users. + BUG 6155: Fix "force group". + BUG 6160: Fix saving of files on Samba share using MS Office 2007. + BUG 6161: Fix corruptions of source path in tar mode of smbclient. + Fix some NetBSD warnings. + Fix bug in processing of open modes in POSIX open. + Fix use of streams modules with CIFSFS client. + Ensure ACL modules work with POSIX paths. + Use fsp->posix_open in preference if we have it. + Fix more POSIX path lstat calls. + Fix a bug in message handling for the change notify code. + Fix guest authentication in setups with "security = share" and "guest ok = yes" when Winbind is running. + BUG 4640: Fix guest mounts in mount.cifs. + Fix displaying the version string properly when no other parameters passed in in mount.cifs. + Prefer gssapi header files from subdirectory. + BUG 6176: winbindd -n should disable the winbind idmap cache. + Add a vfs_preopen module to hide fs latencies. + Don't log NDR_PRINT_DEBUG at level 0, this always ends up in syslog. + Fix a valgrind error / segfault in dns_register_smbd(). + Fix build on SLES8. + Decremented by 1 for ntcancel requests. + Fix creation of core files. + Fix first mapping of uids/gids in Winbind. + Initialize the id_map status in idmap_ldap to avoid surprise. + Fix initialization of idmap status.- Only call '%find_lang pam_winbind' in the samba spec file, not samba-doc.- Ignore return value from subshell to fix build./bin/sh3.6.3-141.13.6.3-141.1liblibnss_wins.so.2/emul/ia32-linux//emul/ia32-linux/lib/-fomit-frame-pointer -fmessage-length=0 -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector -funwind-tables -fasynchronous-unwind-tables -gobs://build.opensuse.org/openSUSE:Evergreen:Maintenance:4627/openSUSE_Evergreen_11.4/1af6c5bb952ae8b921021669103e3f44-samba.openSUSE_Evergreen_11.4drpmlzma5ia64-suse-linuxpackageand(samba-client:glibc-x86)?]"k%T6 ZE&G|G>(WY:k7s?Ë"lŠ4&~H;jNFSIs-yd>X+&.7A0zP0 Hj4:e%TdPQo^J/\eBhO?PDݫQHnd(@BToAl%8wHN "1h*`-Q`Ir9C]my͵$ [c"}P0Vx+9r?hgM3acre/j}Py* L$Ik Ҁ?a|d~,)Ԋ 1WES#̣)4 ,a,I2m .KN(䦟ITfaSAfg~"A%x: 8BBZøOӲnrB]dltB'{?|.x#Y%g}y#`rtPJhzʿxˤ:-s]ŠRn0j1luPH\7c WhcҪ;c-ΓV畡^N[9[]ϚWiB@Ywq@ҟ,u8CvE+r"o4](0G/?>!W&U8$pyh׎]nwb˜e]'S-Ų/X̋UV4zdv9&^A-d)ߕMdN]ΫVbpI-]WJE_8 =k)u}aL-;+ )Q lFɴߦ1?xĞJc]A;Edv9OdV @:'"+k:Gõu)Oŕ?5A^2P2h vev+k냙Il;= o ~~crmg6+[>0?Խa}CH)Jк<]'r>Wݨe ?OQ&d ^ӝFqpKl= %Q0\m~a8Z 2| Wa$'O {SCiasp{?G#NonSx|c?2:4[qgS{%]8p`8SMM\P OAȔg++P3KdMS,0.WNĕxX%glo۔k!Y;0C'ޱPy$ԕJ4KH;Q _S/%lM% VpM<Z\6}w;cCH#!-ڱTI"mSG֡DC }ŰtxQ{n\9e`_,9Zݟc?Y%|Swlx2GQ^q=-и7q&:|ڂ<1uV.lm ̝ Uz k8ӒϒdZRr> )pwu8arXFxv Ҳuڤ43drPd%#x;ݾ ƑәA Tl|uPJ*:W2\]O1*ܘDUU NH!s`PtXP iؘ_0Fy;ŕ"uK,-#zzB?Cuǡ}\e]k ɼ8P:Oλx.O::n eE ޢEzHZS]4fMǗEj[6y,~|Jkd΁RO>!Uʡ 25:M^:tqfG9l/#ĊU_ʽ]GF&mQNbrˑ/u dWMJS"6׭6qs 4m>3 cd=Ϫ=MQ.?xOSMt%L$-3$1ܓ^gGPApK83//t;C4K1,? Ԟd5gGBIlr/ ,bgO lVSIg}⮱q, 7)"Fm,hCQC-)1(`c\0(EuQ )e821JCk~Auu ɨ2U/ɿQ y{8}tN!a4GfOP$ CŐ.sC`M@Klu߶3RNm,i}NPgͩb16mW0ǥv+t/K¹ƲY}@Ҏ_ .HQ^(n|bH`y(&Qdew\||h"6c]d=eZxm"1+~%a#0kR`/ØISʧnE]aS;BmY0"#<'c3o:5A?*M%b3gҤx`W"Ûl̉!.ݭ "epgRY`  b f%kt$F5y[w&J{|ȶ= 2"P1z?A:73p*@}Q\Ih#VVDN zsG?Qrcr6cjQEZ\o5UZ[?|_tźWS٬ژ.o=O=I?jiQ\(aܮ2wLDP9~AF: *\| 3$ -x?¤K0(R$fDlKϲ;`+8)C?V;~4 .1ԲthQ =A ;2p)UM-Y/^ZIMdF ;듋HI? |XiQMOcc1}ʓsۄ[f`!)՚b<:NB5A\Aj[u@>]%*G ɒkf3Ԟ\vJUq$Fc#%K`h(?^.05 ^,8pW`PfowKo} H™ DR+4 5B쨧?j,E1ٮݼEa#{ZӪv2rRJ8lH!G[~+iLaWMBu=^l^%ͿS3N\Cc!(bTs4<ٜ824w;CZ(DvaTxƪ9$A|pб|ϧ׸8 偩F+tdB&Wt8y@q;Fw9Dy$L/ABqE2:*{$JVf8$I~݃,9R>qlbK.2oRU?^ (0DtN;2ot沯xAX  i>] "[J󦏿,\Rw eYلK;k wVy(aٽ**Gډ,4Z<DzZpz4#٤-JƖpo|\i ?r}VeLŭ=;.Y܀ot[]s&Qm8\<0K'b|GAC>6#g?>7rԩ$8 Zn+T\wPPI-e)*pvV&p|>G Jl'ch#ݻDݓqH}qT\W2Zo|!O3א<|y(_CrhKQxPYG%TE ;bl&S`2/{,kDuNDѵpk|NS؞h:G@DW%_ghCtɒW+1Ӹ^;-i pq+lv1u{oF[<ҫ B"͛zrt ڡ%(RBtnV!cm yˋe'B/}>DpdN1E,# ػYq$m4og5Klik%[ttT(= SJ}ۍRWj:kQK84#z(Y@Z)d)XõN(OL~(>XʊjUBQ*&ZJoaS-jd\^DYv 6O]q8!zia,G$1Tm%VvPs\0odbkR;PY HђvC:ݾC0/m'u_p3dKKU*]ǯKp.0 GbT|U 854AXVH,(x$FdSUw.)E q~= mʸ/TAY1=./e̲.kn=0Lo@*uQ(Ֆ!>pE"C9dk"}N m^N T] U@$ аՠ^ĹZ7mBẀGN+ ueNye{NХ(1J9ϯް= -^efbZ@2ŏ`baBNV*E+32\7Q` ,HK݈(0*ϡ%/'#s@kk2.@+Ć.\bYt2#(cC ѳXC1=SstS',RGf`9k2:@2G/}-/s°bV$ӛ\$v'YĢ6T:1l(A( bFւ¿~}nMǙp z)Voog989u)I)TA9ąFw,DJ mE[.Xf].P5e'npYb lHD4zhuntq-F *owēle9N2H|i]sVrSiI*y`UeZH{- 5e=^aՊSYVnF\c!Q]wc5p+Ty{o6YQs|?* `yfW)+tm 1CZ=.8+ `m!lLY^/ uYaJtlkjhoZ!(STWнuώWcqrLv} q<zҐ(!z{H_jlwmx\Yg)tw.!f 8a5nHUM8[ܦ:qĢ@~62j ; EI,c|S|1cZQJo ĆNԜV@ۘ>6awb ޞ]vZe+I13gZ/jZ=f(8/~b` KH3XȖZvgX?f 45)qҐy8זi{53mjRCHa^-5:\aF>\˜f9ex޸.Nوu5Ê4.YIcl~jOyPv9DB g;h.Y7gM$ɛte)SnރfHCH;G=o1)|NW'-_JkbsV%)5`VЦĪɭ,Y\XvΕW.n-8?g诨XE\KW>I-ņJ.GnkP^<7U۪sr~Y 'g{4IlG_3.#=6g'VtNWG 3U}z'=iH"7_>Y `K%θTE@vqҴwN fdnliM~n^\BH?'ᢼb7|$Dyy7sbYq#5[,A{e|G~>glm8tQ>柒Ҵ,Zݰ!=2TuTN"4Y [Kl4I|֌Gasskq25[lm]"5d4ݙU߈fPXkl b}vsɹIW;L "ovLGb.-im4wz#!KWQ)#DRg[& /&&: uIy|{.ki֙_ 1,Gb |~гMdf>{]U Exr;rt8#8M;.[?yce)'a 8>B~_jy`e@SPF C3n^ M8" @9f\&d [Gv*:?6.2z;Cm"4x^IA(mO ;u+=`ۤz~x!Ǯ{aT }ZEgkw P{c.ug~6DH ֙x1=' REwGYM-\ NS6D}7gܦ٩>s5pG-cZx2=a5s# ,wzmYYzfJ;tAWo`̥,l1d]&jD5 0wퟄ:o7 M%k!& G夁&"5"EJ 5]ku}rYo>!ޒr՟Rgu"D5}ss|k*v"6Mޟq }'ԁɌX:0|Pv/sX؄ Dۓ9VD;*9ޡA%˯ ':j*u:Vh=ɏB<]I!$Zϓ߿JSF^hXAZ$qy7zwQL6kό5hr&%Jp-u+uxډFZ<^iUeS=TdZ[\LjihG@%*|~ȢmoЄ6M>9, lǫiZ`㺼N"Jp N2~!B3ma[B-˻Ձg K>kI l%Fj|<76$utp xhW1zR{NdV8[΁{8j]t$wh RO&36]-S w0)]Is42@ʂ{fR .j :Mr]}@~4r?^QN20Xq9천(E_Q>Fga_zrN-0S]hp!0d}X :axAahUy;6u>$?\Jl6h 庹:O+cRA/ڌ;&`52C72ꨜ/h,}DG a% cAFeJ "=7a xXvYDD>ߧ oSOF5LD{RФ4:mh`OOXڳ8\uDuUb9N)8f\y`VZ6??Q?+TX<)eu!Su/IEJ')L)qf5AIx)~|n2۲E%s 3z5^@q3xN223>m,q}B)gn9!/0 2 A,l_.XbI]WŠ+w9^P孢Xq6";Pӑ*pFs wMVVQ_cIv7uѥJ?JR'^$f9!2gbqSϠDT9NLv)AuBpͼA axO}BZP8&*Az*y>c@úOx l/(%Ŕ >=#Mo@5PO5;ޱ p+&^^v@"ܟ%QEYX]4M`F#ijtPљ\AӞz3dwmsVr "7~*X c@t ZD?3ggx꽉ީ#nKH0}5|HwaxѨb7ӏܟm])N:HƞX֫lE]M^DX4aI_ |`][t~,ֲ!Iȍ f$c$܎(X?z -",֒G>$:{/tUŔXDhnijқ=$ROG5P(W>9K~D6ꪝEFu{'.քiBR H2yA/`CU>?<]đѤq 嚞 Xj{_Ej vZL0wm3<{т-L"S hK|)!m_VM5Gh1*Vi= h}LON W=]caT#%ɒRze]{Ƃc[9 ݍ™<1 H@ɄV$`Î{u x"e ĘոG _S'J嶂Edr wgAH-<-emКYC^,O7fnvQGjrh#^`)j=6=yNbvo#_{y4M< uw %uĹ Nty{)1ւ,.7+̥VvlQUG ʡ,"+s dJP@OÜhM:nη~4Qc7q%Q%!.u`hH"wl ul ШF|;Ƽe}mq )Ė($ilŠMvbr{?yMdEV8rիd/ҳ{^txe Gi2o%LE-td?|^'lվ!V?< ͇nc u|N2yd( OŨlX1E4P{GS{i]MrZl_<76 NU*e"_Q` ELXB5h"QgN7eޗtWޅVň)!h95z'w-޵ C =qOp3ѦlHm"TaVcc-N7R%:I"2yb>sٵ轒WAű(0녉?80 i|ev#!WX4C'Vd:YHNT9s+Cj IZb )q'Hʄ߻=VW.pB->l$0JKŒT\$l pH} )X7$0ݶ{N fo!;* SVgfQJBbd^A~-  nVt9TWlz% @\>a/daSHj~corT!Fr' iVXaOrq,v4DUo&ECj`'!EHȑuPYF ?@4}l-,HSe_$Ψg-N5vl*j:"v-c] dgf+fKoVSXڮ&JOu'Hk<tF؛;Ӂwe!qm`@0*@Ԩ7Tv xK OHt3*$8ƭkkkfIL/F7^./Fβ3sÛ.>,KT SW?vcC]TdiQ1O6 NN/W7\)vU7 kSDNkD9X"^7Ր=v$mTvu] s'P%Z ZYJMzvxYӑV5>}- c2Ep%}h5`m6|UBה4En~r=LmlmDYLvRi܄5ĹI ]KV>@Ta}_ПSnB1zB&;[l))Dˀ~*Bc0mxq6TŴh*N2]v^!c)0D\GTt9U*1O s;_{F)X  oF&MEXE7\AH/)+ˆ,abBǫ#9Tm<(ɾ1S?Q(S ^ĕʼ^] c?r?8_!AydeMWAuQR>yKR=^Eb7.ݲ *f!Ɯ(*}KD'Zk 0o(>}u =8*oO6_zr| ZՒ1uj`ǹLl}q l.oC^At"TS(>a_rJ)d[kmV,D0򄝚/)jz{>E?dH@u H@3,!ƨmڢN K6Re:#"miYG$X;Ÿ#й[m/]rmLfhi]YwsTшm*,ɤI$oG H){ؗPƙITl%GJsZz}+#|$fEk@t"k\0b)F%mix .+UF) yRqo93%M *>JT@} x"}hhv>>!5A93bX+_K+=^B=W yH굂'ȞVOI@y彤)fXi"`_5z?EJ́+kJE۬SqE.)=`ѻG9ř2l{GisQeO'Ht* `'uq])"1#4ߓ[iphHDo>=[Uwrt%^Oy[5M4/\ePaFA%Wae;%8_4m -߱Ȕ{ y~nXX"y3A{2Ⴑ:mko|Pf-H&Ʈx[Y|/VJ{&82qR﷡x8c'EC++H%h#K Q޻'B+c,84Ǥ(}c;|_F.~[>Q|r#NB¯2?%iD4CTUf#+>v%ӓ;:F+$lo>*6&!_v%ǡ8|<A}BұJE_oMD|΋Jz=Lߗ}5RX!M0fv˙r䝤.@`I{hPp~FgL͍KixZ 1eZF?a GĚD[U/nywiBƝ;Hny0$9. ㄩ,wrW ,md&-t9y?(J$͔2u_% ͂2<yu֊/0W/_\:A֧hEBPAZ wC;s&-iv4E™ kFßbԌ p&Ȱ\'Q5i]RQenO~BuPbKfǰM" q : C=/R*um(sptU!B;\PVPS(ls[e*i/}5.2  |".>`'2/󫽗ok 'p\9T@sHyfE#:0.;@s)ϸ*_5ϫYG]݋k VP6F.c/16ƱWWzjwt-VڗiG#=Xs3C:g/,ڭ7gQ (09v"A*0({ofq[h?RA%tb,,ȅWshjOn*;Ւ!-j:1/tCK 5U06*Ϯ]vG{n lsR+0I T\UvgI`C4.F#=kKo~0&±V>l\y / Z-&1Sw~&x;-C['Yot  E }SnjLNс2o3| J"h+,c$V*{sJ^ Fmt>|PWӜ}l?)B|3jjN-ErbdPZG \4 {\zqT\X!B6^Pz6"+|f៛@7d}WXD2v^$(*Q~AA Y^QTJ Q6Հ7A@ҿ~xGimîj5iMQG CdbـT2C] Rr(raU7ҨU @kUo1n JROʉߨ61?&HetpAOPWfl+L pvCkn|[!Xg\܀: !8QжY5P qM'u2_O'JG Hd*E#u@_x 2ܬBWv+:Xgtf*^bJPkuՇ깐W"(܉2J n-kE[LM\eؖ5^H?ȹ##M[ *4ov˰&,Ym0{-) fzZ%Efs$Aeol> |;{Q.qFvnCG~:V`qǤ?E3d|#tZtj4[.cV\H[y{iLǜ//pCk؏S?ʔםdڗ9y&´M;U]!GsjcP4?" oY5ضg娹'( P0;`wɲ'=X'ZɆ^˿r=vςݴI͇ ~,VFvƎt23u 5[ lPKSaPBvXs*A5Ypz-tiω?k}見0,4]s}J[RsMrSIIZt&F[QW`TE&c*/Ҟm廀vgD n䤉R%mmӪ`"P 2J#/HID0n0Y@B%dMi<0UϣwX|9-g{22:W0v$k}H^x#6Pd@cHzہ6X\{εVJu9&[?,b)8&ҲK=brOs >ҭ?{&xE&6Bhe*CiNO%Q? ?~$xM,BAL)<&*ȳQzۧS~啂"ebg~5]Quנ pF$k.7Z)ةKϖgQO휮4E|bs{E +\Jy/ s,``!ј5(݀7WjL9^~gLY1Tp:85AF؊ny,n6?&'>)n[`=R;YaIt+zYix2.smmޚb8E|:x<"bӠ&MH6GT xcʐ=d]+4Y5@h\t\کoV̋ p*j~qPeo̟U /;+[g|f]P$rztm_1+o;5 O.:| s;qA簹CW57fM͗ӵtD(Hpi0gњ۽Lt;9jfp&ӂ}(Smحp|Pe UDW V(;ؠy%<{G(3:Ryk9e㽙6., LwٟY1WhCŸw7UMڀY_:i35TTe VG R(EK+ '"9eiHr͡vȃc; /WS/?`^{dhTߟ#ϲ}t3)|7r=5_Uu?e`ct^a%sGL6}ȖdSxr֦e˫zKJE$7Qӽ捫\cK|xvݺxۉ$HR6, -yĽ.S\dg/F/JSni$4}VLAڌΰI1H_Ӈ^n_QPD9 O9=ci]Vyp-aAvpc"m$~s\X*tL)S%:v&6s􊇉1 ?("9DBdtq"5f oRp2~qD®zΛѶOL@XRw5PVu}Yv]1z`B 9i̎!zx{aE=UcVa`}INm djK0OȈzZq w, 7\&*.}^b;0_vb s8 `q-<֜l*LZ161fph\"l@pj]0u_iMga$X.s[''-{`8L7RLmb͐a.P^C a=S{K2[FY, rջ~4ei:J}HB+ٳd%{Ycrl};WfN&`3SZd/ɼdx[ =Hʧא}>c#cez0-GU2#kZNҟI C(.8lb"Nt3xVwL@#>;;:9CoN=uaRrR >=MUJ7M8S;pMsYbT^ w5ߑv)R:Dըj$|& ؟Ec0,ࣉr=&5~+ynY6NB$/= ʽz-"? 7'ecmt͢KS pP .1GRq#0hJ.(n*c?hS:Y#d2L6?Z&4 ϫQQP>@i&` pơ{ -]O Wʂ7X۽5($GQEk'f*s(zmm eV']F9vSz8\($R 9o! AlWq[~DgheSfjJ?Xu(_!S?(뺃1 iskbj]oì6dInW*լ LZA-AM{6e:^@]tH̄>pvoX0.B*W*c)z8PОD  }\˟'T 5 H2(.bx$%܋ΑvoFբtd7܆O9iƭ\T5c70B2dcUT pqvz&<ɺq_o #.BS "J'Y u6Pĵ2DpƎa@ޤץC˘4UQRFCJx6Zs[6]lfqwr%i"!%)uR Tΐ]\Ṙi\QZ 9Lyv!A dܰ){CPT'fD}xˌ%<.E~j*}c/53YqK<P Zvi."dj!|)I5_%WEXOa'ɗAf8yu9-Į,Bˑɧe Jc"HlkS`>B_UjLR:y*cqMF(ӟ6U[|b. 'KQje;ݒh/$LLj%f>̌~O>ڦP`nLX;m>|˙\/uĭ1vymP [>@IrǮ.ߎJ7-uBr82 eeTn&St-~I+e^3{O09=NVtX> C8u:jC͚I"k-ÝA"@vyK7o%]5 >tC0{U^J 'Q?[$T#s$c=ђo5a:@?E2c8P/94 =`OlR\Ĩqʭeif].IZ?.>E) ܔggX;轾4>Ͽ>.mb/JnTb<ÚIMT(Mn352@q]~ #j\zU ?'XD Ns-hS~qj| Bcq'8gYdDlg/;u2k{*@dz @j^Aa*wTChӡ[C6HeFٮ/M1½/gÞ8%܊c6 czG-=;o6MbXU++u_rAڅtATٍFV`?Z'/q8"Єf=S7"7 3xJhY ILG^AXVn#VZNc|%0ܧ<\kL5m$3ZV]L_ HL*}T [ x P< pUn3yb{? y_=p?94g|(7'k?trh6IHS里!o`a@j"R yc1>o+L(eSTE F' ``I-`fGz>a<^aIԨDž{۩q$,yl|cצKkFUϹ&gy%MUD[ƥ5zǿnTkܭaJɐ≮Đ@&T##&~/4=*@dKz 6);/y`OEI/bN#ΦV<Ħll0$(_>鍢 k jbe'yɶ Q[}Q'mRxI/})XbB )4+eغ& uN 1ͷUl;jL`9LSPv=Wխ:ja)_|M՞*JoQ St_f\ʹ8 ~<iUwr0`̙sOMy y$]*Rg!rI'$!PA~ex8?#/^$(ڃB@]/濮Ϗr[C/Re0O |o0cr1_i*b8}s@H5J]Of]?էK-_R0Zt=&!o9Ec~|l0!,Q 67QΩrF\鼃,9lQ:xvGhg^wPwdyq7m*? Bdf=]p^vw@la&%dH W(,4:{*<@pt s[empHӶެ64aGm PqoF\ayB_g~<x_ԽQPN,׷u"~)2\g#v*.yf,wURd\0&*ʫU38^-6ϾF5`SR1%@ t~ w8ak~1 3fg>k|G$lpSp.:G uٝ{yELDI f-+xӤ(OLy[9`+~R:{QKf5pEvG{G\#dbn K'tӕ-8RmG!۩k -żVKz^p-4r%ҵ>$ZDǵ %uA ڞ}Ok媧z#>3GۃY+xҧqHIMH+)m#4ת4DE\YqsMexPz属צ?)|qH`6Z]P|$ _0I3@bo.푵61׉!1K3L9זnb[;ă0ar- T] { !IC*k2-{IGE"1qX @`G`c`rk ;" (f{Ut뛑-ؤy/n(dž_L/B\X(*JwP'aTqʮV ƼrljcPta3MJg[?,Sg-_mYdfuf8"t\̜:vc57;`wu4͏l ӆ(C"=UԺTYΞ9g:M#g] ^{n:/6)h2.O/[ C&2fd ] ߕUh3/$FSc2К)¸8bw6xĻVyHN`mzqz"6d/jǠ4 y/;?;>C464:~24͎m()OGqKG?cu n@j=$Mȓ"i'ڨ}os-~s*pvӱd7ʕtVɲy3!J!I ܲA.ʠ Ӕ[=tMYr$ORꨒ e+Fh8w*p}HY.L]$i;yQ9k"DR 7UM̼9uUO32ol\E^uEoLǵdf\A7aEQGH\3P"A)8xp߹ _QٯizҿoXTZ䝺gdj8g!e|F Y$p,xԥGշz7. p p_Բ{Hj|VG#s0SVExɧe`y?nINDf|:!<\+yTjy}?߷:Yvm&SX]4V!kŸ́x5\ufVbL}p*[r+y ݚh,Wwc;98+`4qFMpb*MBȮ;O*!?qr! 3;<.bW?Lb޾|) 5WNлOĔz,;£ϓ5a<Lrd-C]oq8 ǧ S`rdH\렵 mÐ!l 7nhg3&mf;M[BQ? Y-U$L³)gQ4ݳcO8Jv 9>2*K`uU?*\w?H7Q 'S5"vs}4Q㫓Š_E0bDwCh(/` 7Rjw+^]+Mog`ѾNrz ΁q1ho4'yř*<{*2#ReU}cjWNu(?pErnZo1=1qr)z (JB 4&Uި@$Z38A.DX.SGghbߒab"'[ HV)aO cF a8Jc&gB[Rr]<( ݿՀXZGm4(P0pթa J}*(+M!بG4_Pkuc_~5°*apK*'v7iHߏhsF@^! kHА-g36!atdK4숤IOjvj`cn%#%Ѳ4Ťh\xbw/8v@jJ!/NWˀXU}u9nxQfLkLJ>AJD̂r3uo'1p>&̇U\E#[" O3GQΫ#LB.0͐_&!Jn wNS .D.! \ ƙr[b- E c<3ρ b (~gp\k)Ba[ *[ @cϬ/hka|3a;77KD2UXI<"J tgI!KU'*fGh|\p[w:H% M.|jB`#۵`Ҵ s,?nxX}.65b,GC5OiaQ'J%C{G?ԱLwﮏk5iW ,<~_7w ޖ {G[s^&Ehz  ΈWA=9uu"rCM̞WVLNSTc2N%(zqfW{8EiZqOGo!x+Dlr&\iu8n5 0|DIQD6#K A%dm68NfMeJ=@6jW#]~YH+Q8j\`&bY~GZ]3'jMG25)>u*:ǒ.Xp,TSڛO6߽k/dgs*1E4V>^,֑2F͸12@N :4;m` M /hȇQrv /RS 8nvc RH]N儝duGr f?lMS> \ W#NxJR֗cLU\d6G0na36A%,ۦYћRP H\Hʪ:q 4m%@bV6u?tQșْJ>]b,-*Bpi$yj~|qVm aXdgk;Ǎ&SQu > _ιУp:I# MY۷*_ ?qD4AL7aei"n?jJ&w`|c-^L^} Lsxӥ@ .0{%nbF_wm)8%+>4ibABXPx0x.6v50_2&- ߻Kφ,Ҙl {u,LvNZBЪrkTlMdx|h+utML, Ք*a/:4fRnY4^x8;K3KB0FB٧stw`vRxY|/$iuc`5LǔQS!"ǒ'X<·+V؟խHixҟiMER"{WI=<{a;y|M,ˌ%.zj'NE9ZJ2T+֣ ~!i0ǖlMYMqeY;u}\,jREœA*uS"J"I|LK(ɭSZnq {>M[7gH*L/Xq?*ܒ8VMX4ʒT2ra 8VG7QDt} Qm O+ɺ/tR li!g[#>;OpT]M쵸PM;dcXO4VնR^tRG!< c_+m؆5Oe0Y1%N4i4[w H¥Q l1 -wB[ЙXBI .Ē?-3RY S-hW,)lx _3%sCѾ  S(0j"ac/[5Au^WꋡP"ysO僺X.+7/@ʜa3%~"t*_<|<p5NhHwZS8~傧yȁ_oo cw!Σv7opO(_0hЀUAG;K*P3)TZMY',֤eL&v9RP;QVggtҪ4yv^Q 6aNIt{fV ɱkKm,C~Қ+DALiSP{w(9n~w8~"ddD.zgE?\FO=ȌjťR_;@L;Kޗn^*Vcj6lDL@V&KV{WM5loeﯡK?LU_x}U%еv^=%z0O=&M1)Љ㵟0#Wۆ4:J"4l''Q'#dӰz$.0 TvWsInRdE(=vSĿnu^Ǩ J8/YV]^S &:/a+8{͛>.YzFM#VOO3՞2`4O`UT[RC=f˶i&bʔ uu85m 2V8&Oݖ #b%vVՑ3BE$7|7!D0o}pɌ3R~;>@pδD^wTheȠQ} J !79G 6^gm4nARC< %4FIlbxz֥[;0C|O`8T&Id#~%un>p4{-b+}_cѨ~YWk1HѮdDE)&Ꮜ>SX O!G]VP9A8KOaot`ǬM^YJw هBO1]R_L.y~ZIF)~O~g#&5GhaXt$k+'Dh췐cg6yJ (I!Ӑ_fJhFqyE]pgZL8Rsf)w5LA^[dӹ W?6o(y״B&mxǨU+t%Cos̾/oj%w7bi$7CiZe54E[V#]$:@<{gMԹ{'6byCp=H*CϣK +V 41<4AN߼n,( v&(i *va)tUdq2:ꚍOL _e4! + 6 {=S'58Dy~V[~1"ݲ֖c&:Hz6n#NrFc&IO i3?ĖJK+WMQ[tXP1Y(FC_u g~q'#27^jjK*ap(зc3;v%HBi]2Ӭ a+6GX;;4)WE`m3d5[^wL~MvzRWMRM.-U*lLʙonQ;^||Vh$2bO&Ԅ८x4Аo.(-402䊲h;w rn3s:P\"#3\SG 4EtaF)Yبi=c^֍y;J9V)# -wsce? TsܵM,`U=l߿WY'Acz/]ڿ2E/c `lO+uj'rŔQ0NUu,ʒ-;h )%bm6}srQWR(xK3y򋝝)!ȜE?" @]AC6:iRnT7 8ݝ1y0]YG#|P >εvD eud!-sh`ڑo WEe= ?4^mm`9)4xB ";ޙP埾Srtqʡj0~K`zD1B07DV7ۊt&^hD.zm)DZW[S$,\)f)KTEa%ȚH9Xv%BY5Tb+Aa OFv׃m Q܆)!Pd>ԀW(5UDni9:GU$,Ge P幯xs)ۧQy}J^nǰԒ GNb5V:vK^0H3%3梴W=xa'v9p6ޟ.Z7RW_$=9_γTqi9:~0JL5o堍0EfpJ^`t`5HydT-CvFGV< E*xwaH3Sa6QĿϲbV{xtns"]~ôUns.͝j* IW^eV|y1go˞ 8GZrĦTsL6͹L.=E3&B~dzL#$f lsHu_"kΙ[ Y) 6ۖF'ՅwivNqN#58gZrNBHa^-z:9WNwG)dp'd)PpDZ<Qlr/Ur(lvm#y-lU/z J˒ipU$t8:DhUOг%=M.ٞ bъx54+w2i<(r 9G+*Nrr>t Ml&?*<|BBPe1Hw%DzHgtT|V-߽*YV%hJҷUm8j;g∀J8Yϔ )4qw=끼ZT|&\u,B9#޵B[?GKB;Noi赞<G`?xi0߆hX%Ю#X?-̻e rk3!kE[, )(X?;YeݏG2@nݵ0צT4J,I#9U5Xޑ4,!mL@j!QEٸ-SFyĄ7 Vg~{7%PYDz3 B]JS{Z-~]J/dƷOL rGZfdg鱵2U4ՄF@cH T { 0*1cbX+&^z!rV,dW_rl;]CJYl'?ޏaTۜU !)?>zYG2IqS*Uգ񼅣TE,s^=:ރ<5l"T9wqKZ| 1`|!_C?Q=v5xhimÎǵt/85z*_B?>ZmԵ%hL $&L{+c LvF鬛#B!sP1ēܹru okǿR) vgrZ7G@[A'N1VڧZkڰ֡'(\@mxS^e߳ӊK F.ۜ-P6 @' L]mIR:Кr4%dznKTtJX3lfD2$%5x@R`8@Bq=DB5x4ͥ2Pr7? PɉȠ naGdBZ>=&G(m}9 1 7R@gJ4 m)x[2]A'wv q.9'նqP&N!ڢNm^]#bNFrBX2{V~YsF;*L{w@EcgW&IQMFς㞻Wވm@QP>|;)hKKW"7&jl)]{BspE댖X<+C:,"QΎF(_b /iTGS*G ԕ Ȉ ͤ,z2 Nx谱s|z>#ه->iAǧed*Wqp_-XǸ<^fk kKEeLwѯ1 cnQ2n}5xj CBZӁDTr|Iv7OV!O]y:ADhB2VܧɅCL"B揥^sK)3a6.d69%It-J;xo]niQVim&wx[Tt `\}A-x1b(ēMOc(_%SHȰ, rԚ=XpA6~;.VM^Ҿ'Ǐu 5ݥQ),U`Sohc|F %L(]&p[A)yW5|&G#A @;=UyzfoT~Lc'8GR fR6j$_d`޽7 7`!E@+ c]څdÂZsJ z459kj ۽Z@'SȰbu߭~^YL&,&J!SՍj` 3 BIxa2D)!Rr Ewy,Xzpm(1f3J({%?NiFcv5-.dNά`Qgb<5ka&;,Ҟhr)mwvAJk02(@Waryց삾XKmCsbwjtrJ $[?4N#5,MeOv+cS3G!n_}sMgZ05W(B6 :: .7ŧ?֧m-{}~OV܏X1 zlAԮsAJ]`ݱ^#fVmj>% ]ʲu*qJZ_R(ׇe%m6ةpVBV]#Wyʈ; tʇ+: S%R-܎N ?@w,8C4@a!aZ$Np[0'jVLE'*5C;=nnjư t!Y XSq=NƆt)I. qTcdt3(aoc},`~8t _`];MďFLr!y,5qqPs&hxЍ۶ RGqc.ФYC1*۰jȰ0R^h>(6)sT ,fwBcZs\F$tZ yKu Ofjaݯ#cZ %~xUԪ UW pt1i3̿ hg׽,&Y jlY?K]binZT:(H]Ǝ f9Or"c;~¦D@ Y\Ik.UVmXleςuxvrI*&F=3'SR -};֓H=T)ש556٫ pѢ95W4 Xe % 4DS tGtB `Q3;6QB[ $2OJN {':H QN^zC'ASMuڱ!A3;/"T&O)ZG-P'ⓄzI߳,qp43ci$}mV٤4~vQe6 gP}oVۢ+ p 7fk`xl3Hh=zGT5Sʖ"q3FNo?:Q?# 6$.4ksHزplM먫mV['[[IJ cJS]-7~9TS^/ ~aD:$9;q]7S``_:9bz5(swC41(|Rsm$Wf{ܡl;%Em&81Nkd>9eXpM[$uzرAi/=89.?r.6.o_UM!$s/Cy_?B^n*/ua(خH}e@FZ?g OZ >4V=1yT ö~cDF&M^\V1]@`:MKDoi\T-UYOUT~Kv;(E[8?GKhԍ{~=[lV V߲:}Bہågrqq\8CHsr}"Co3G)ҍ~M Yɭ~:ǀ7zjcɍS}$+dk"Y?J4钧F8$12,' .4o Zr0rY`#ĩ+\}'*NbcRpt"L#[HEH+O$+N K"IDٗVC|%v9ogR <]2Q=0(Pq9F!ЏRϿEڥAAQ|y 1|[JwcmzG*$Њ؇* n'->HҀQrBLH')}xiWfJ->>; \Wn8$8Y&#+aF:ac]Y젇*Kνtr 7UA4`HR9=ZUӑd?ʐCҰ2F1"PH(ɾwG_ꛮ4p/> U MP]c^:{dD%h99Dۀ|Ǩp ;q6#,OQ΍|wWoZ`_%x!xѸvXJp<7%0IP@< exO$dil^}bInfWbAZÒ՘a9UP~N=#XIMx#þ!cº!yp*x0ǒFtʈ!:ˑtveK0}v+Dڍ6XCCm*kGE L <6}ݩ {Vx0]쉄p)NIojDS:瑪EKkcp?>$ y}SώJG-ݾa*y1:̻hNq `drR_]?5{1S=wv{S:c 5SCZPޞyV1?H&?\ўbOJlۢzS*?0+[+NH6ڪ|ۡ+[=:T0U rA/Ln(1 e#,sH~z :-}0vC殼,E2INCqriD;ֶX>s8(^8o@ {w,x;T\y-k=RCp)ۤV;kӖbQD7ÂS{"f }LO%~Hrb1G=-ﯫ0we7 /hmnq؛m+g csXAL3t/ 0]`9h+W(h(3M>Fn@G*FBj g Ԉk_P房@g}Bf=kx$$Ǜ4]De<OIr fyO4`1u7]c F712$#dĉ({]4;fb/&Wc6O/DKI#U/04N$K{[RN9j;KBBg뤺m5!Q۳!J :B2bФΘ8ǡ3jް uPR'kx\*ς\t#_X:q,X%\OP<X5M¹j]l֌!~&,%w|5Q*+NYcal=ϼf#R 2Xr, TuL͓P7 ܫ\ܷ5N'໺_*{r׃l-9iقs94x=# SdbV{0\pg$X? 8rRG8`ԧ?EZW݋ǔ)3aa>}JkE L¡{%Lfaq74/K@؇M"m!3XLn/G&[&UPskB׿(TJ `Ԩ.gnb¥h|MWJNjk°+>9]t;ƣ/ P@f_Gj hd(u KsxeEh `va,C7w`3K*Ky ?IFkMrew9[G_ǾtO_jL_MmtzP#4,/o=D~ɽOAF%yq.q'X?,3N}}Q=]6"NA& 4m>Hl ?WX̤ ozWfnf:'%:feC5X\#،D饵YV>d s)P4ǝ_k; TSRO[!{wctcуM(E(e\ l(DpE{t@?6Ew?%RP.!6[g}uUV$Asxl|~U4!jUDL Sbݧ kGPEp!<LZ1-86YXBh}3!U X֙!71tʣq2At˄F&3Xk#C%ҖI7] Υ-!jNJ0oi{XnnV;b™26]ID]0 B\} > X)WPK}4umm&~ '"x<ՠVkW6))'HF 9f$5ɰ!Ց 3 |P5V'sx0dJ'@Pq}c# 'U zGm;Q5!bӾqx7a <p9"޲F.b2 y d(X̎ݩwD-P"})'tˏШqjUJ }G]B{.8sLpMV}N6<ы,w5 3FY ,>@? ]-'-SGr`ij!PRqXfZW#up{<"[QL /Xˁ*⢆cǰÝt6uBwxme2KZѤ‡l;N5)># ejnF=YB}W"?܎G4ᣈt|znFEOA^[qb {o>72(Pƾ'.hz^q"v}D0+Y,&)|V%wWܺDY*KuAh%ƪvp&U1<<G2c&1$_<Cj|pg}j!Gm8RB~1 aG1eLb]PE$dC;XVݨ[)oumeԏ*O>I"JXbɔxɮ|#k}JԌ7ZbQ=:ֈGav7+7! @hw?՚q|L->t08cFxZ ͋Bc<ޣ2jZ@ f)lWy$I<'؄L.ȕ L3k)}CoK\n/oҐ)& x03|unǛܰ#솱_o.yhL5&=T #]&7t!S? -wN~}ZVnBͲ[d.^yUzi;5\TuSVnLOo['һ=kX;=zhƐ,YKI}";HBS<g W2|'1*ܯ/Gf2|l_“ y[g1CG0INx՗ %rTij Q%p|Ğ.%.oՅ LTӂcq4[ &GiFz)^F7&R}%>}wM-E)*OZH<98g:|~}0.x;A"ETUbr;*PuW 1PLBWN{35jȂhh n3q1M4! 'b6cHZ!NWЩb边+fYxt٣<3`g^Q$߸[zz<˱&~}7 ImjZm6ۼ'2hgPc<oބ=i#tNA\A -(ۂn-3{I\Rt-,",Oav A3\ʾnlJFG.>9i:aᴋQcz0RU ,2j08 懣GFLmg0l]gZe!KbgV-Ha5\O{dXe]xdh/%&!srW١{7`yh%q^%{Pk{CeD@0P ޟ0|n}R3KLX jEGJ(v&8 /䯋_ٜd|'F$%Y|4W*(o@\#.'i@3&V#mK̛MY؈KN;<.TkiS"S1}PioⲜs_Y!i n;>}]>K͏ܒ⫝yk2ʿt}/Y/(r\~3.97&P0f}N?ޠN i޿^]X!3Q %xN5q|܃bI~Mk%]IKa>^`j r5-|Q g lP%!ZX]İ__K XvIH>6=awOV!dB^YV0m/u}Qߡdm-YoƯwtpNTd9ZS+P]x ahjw =! +RÍ/{ l2z FZd]> ïD9S*RFeVjMO6W;֪6>!KU/N̑ۤ8XT"DZNr؈J,豌q,v2m FHUTbW(-P4PP8!7(c`F+K;$\ﭏ?9j,Y2^mwFޙJTuUmڋԢ_Xꞕ@٢D%{bNjc64Ǚ [:drQPRKwkέH˂v~et X)+R8≣:?5|?b7yAѹ9#i9m*SNEW! Vf VBКYӰcWYc ZvC˵Yt$> t~=@<)1)"WvbHY#[Oo*\fbH[֡V@u!\ K[O 9[Ow9r,e772M|hK/"~vX8IGgv,](٥{ōWie;w*YQ皜TR7Y5O.@*F44,P^gr]i[SZXf EW@ ~rGVϴK9 *9̓5t9}G/^ ah 4kk($Xi!pjtPno2A(`֢8NYOdS'6Dj~͙-I& e&t{Ty3vv:5jҫuN6j՘%;2-_bnTwdVWIZЄ /DnW~ʮ) ir2V^x[~~R%2؄)UA)#7f۲MLc!q0;.sCSytqCN^JFf_py1>  ?:Qe+*HE?:9X'-g׈]Hc!^AI_LXzϗH{3!m=A30OE\c@0{h9#F᭕kNȮ5-~Om1!!"cE6Ɂ9 Al.496Q "a17E+3}Cc(xК]Cfӕi!=MYƯ}kþ̕B~7Y]RsÙ9_+f0.vIыbqHCC2k1:LGs&/h;IIq'0 )#thv,r'-7R6>2<+ڮ(,a#TL*4`ewa`۷g6*=u~?\UoM5.G`7 ‘hkrb_9.qhu\ 132ɹ :yȽ=1Fn\]#Vx 5 _)b nilp/ETtxNށt@Jf>Dd{uS_Pԗ^U%"MVcfe֜*NQ~xͦ%YYe&~Z&C4 wSl./E|6tL%h 3ښQUT#g6柬ܠ9^s$Bv\f{ֵa*/؜lOL9JH"|@h-| ӿerӻǕ^^̀lSSܞpJ28$hoVCg6]GRbT=n4A-H4F6:U M/p:.t"GAƁ;uUP68KGZ=2A;aќD.tҠJV=4XsoT\.+Q۟ &)i!G/79ߨ|LArj^=-:-8Q5ЭRzBdSml vvF%AwfmR]rV|*L"MCeYj{95.{ ;282-ŸkP5+ѯj:X nj_ob s _X숣naP3-m:QJҬIDN* j8X84FqKQ($#L$J$4G5 ]Vc%x=}OF5`A_sAƇ֎J&'<4|=]\+7]2R(u;2DئNjr: :}0odm ^o/L d5"';JSWM޾ ~ =g N'vqz,M!u*Q$ѱ6@ lrXqΉ#H$3>({WT FͶ6Z8ú )BŐ4CiЙi϶eT<;}q`$MO#yq`'$lQpURgZ^N]&t T%>X` ^lH4|ppk zW8t-⒊03sknP,ueV|M|VhUdNyR͈:,x6l4I0gdUu4N7a Tח< *AΥ?liU%ԅV7Y f, @s']60clM|7ô_1)cF˱otOLW%}u߇渊t(-I2-ќC'A,nniCS֖(=?Ǒrl+]V]fe/KX ;iHqC!7C<>܌ւ;X.1F[Ǎr@V-! yEUWFl4zJ_d%7GHve_Yy!J /Xs@u +p5%>HbBi"ޱѨ}VzWVO9o 8g`T"Y PS_P.z)L0jYퟕ K'Q` 47*x6gb=q.BrFN3Ugj C,PN}'7h"x]eNP0,~8TBnIX@ b98v~C`0-Cb)Xmnfr,=lDZJ[$NBvUqϋ;6tZK8WħQ2Y;) L%mk;$Y^`̙tlF1jkF16fb([Ћ)_C)0P|@o$V#%ه&ͱR8o0+Xb `]Iy*Rs5BZOVOy:F(-F^Ȅ&TUS=bu jrٚ?ݚZՠz p7kL~_Gd`NrɈfr1{'߫q4XMp6m!ڗ]X"|("?1@IsO ZcA`FB\p&Y=Zin@ɧwǟkWfLq?̜T "JڮE4Wm]cƕ1ͣK*PRKŃ"oNiaC4AMɯ>|{B.V`i"N{)ID t^ňq7۵i~AE 4 *N9,0F=1r{ه9v%W>Eg>ۣ8fFp>$O1YJ]8+reBխ~$\ۇ$튦Q<hCbj{nw4#x'ARÏh $a*Y7dui:/p >AOXt{K"#]!E=8gSB(YK:,=z wYfq[27I>֠`؈$RqX5~t'"֩(wj']^~d++[^ri撃.9.x! JNlܿXHAEF=%[gg 6dm?Y}u(iԤx/n_g͞.5^q\lm&KQ!rmQqrj?p_*'lkĿ+8`KǙ--|MpbUMQ=_vʼntշ;fx (t$寨+umOX/(aiy(:7[C˥_m!HhC+xr\x x͢Q`XU| u>!ht:WgZf:!rWbЎ(K .ȌPz21 '3]|Ͱx :.״lM$E 4"gHQ8GP01:ߒH|4,XCIɭnݛ:iF˷i 20>FŃ {Nf6 u@ 1֍"cIlؤqfŽ;GE+P^c D4$ KMgÈ({7 2;џg0RuR.x"nr @ό. niNۦ̬td6^"xSBd{A?gT,9}WzM p>$V{/5ʑZCKƟw # +Z~1`\^tʪ9iT'0h 6&Fy@lh %f_o#M4O%N| 9BޮXЛnDۗB-t]$yv`;vЁHK!GyW-PSusN8>S bʞ$b-:;gAFg]D 09S֋INyA`=#.B;f;Ijl4Ȭ'YބiyQ+mtAwP!c[W`*=~ˉ[+뚑w='Pff >iz9g[: я7bF{ w&ł)%n9LK_y d% "]"fEc?n~,Tzp=+ʮ0X44A3wmm֜FpI$Ix&!Nt6d"7 V~2yx˞iEl`*!w{8]m4E63d}p;+,Stk:5WdBb78}!6Z:Զ`m/ 2jd*D3)"jBZsiHqu++u✉#hKjimL> <3h],Vnhл*7.q]"$}SmE4[%ΕV[Vj#X:,Oi,]o/}LQTL:IN,9F6sP#L2D!\x>B}W)=pX[5:~jx$O8#]6C_ap#c˹ZĊ߇L3 ~Os\LmP xtnp_?3cz#rZDD 6>@BPzP ˰O';2ȫ+# JÕ`..XXiǗx󲸖,iݨvZlfĴ0N4'<62~ЃB v6TU4_s~Dx6{-,k΁@U 16N3[8BfdH &(y?\3Oڔw D7e }[bS4䬰r{չEAtEH곫EECoP" Mz5l|BЍaf_TK+D G 4+GXh~ W ՠbxm0Cbz&4SXC^9Ou|>q@@fcbk(! u\k*í 8f+v-܄c٫)8dnEE0 /h>+?RډJ\6*ʭpIf| L_`ӎ.6yd$g%SR:jy A;Ch`σ{ ۗ;VEʟ9\A'AiK vB9m`,{,pqxm=>2^Dh{a<}c` ֹI*X롚w#\9vweE6mT=ϛSKO[(FT .v Ui+2ܮ4!YX$T=l$6'iMpJ% 'g ݸۖ}y?=\"G#HqH(dj9h.'fRvurF BE9u-c9p1l{f^T'-vWV QщQ#@,4+!5zdHd`\M.Y4A!ՁՃΪwAovþShҶqbF$[e'jm†5퇥b P v2;7i2@&8"&lupIӚ9ǩ,w5wƎ^<"͗͐UM }<ԧ&D^O+g:kuą;|ΐ[1[J]T - |D*iݩ^FM=?Zj_'aO>:+5aM4 C\׀|>^eh,o~0y@=' iSo-п;Yu/q zAhfJU*sx=j h k.nq\hzTf9?b|jC4 ML#np Je+٭.AxUOޟ{v Eo-P`8-^\%:JfR`PI#\)YԆF' ct"s9~ Ƚ+e/v;tPM4K,.F ސ6/ñ2ىv/,43[m\o6 h+M#֓*QT-! LK7vE'ф,ʪEPW[(Ao lC~Ye>7^jEֈňq~O~dR˹ B(!mpS{WV;:(kHp7E]J)\Ksí_.f63՚w+t,(VXȾ6XqavN%lAce۞6'_ny`i/B`{n <œ&h9((D4ķR+4 #-Kڠ^i?~]\;El:r$ŌEqɆG_^ͧl(;/R@񮄑ZF^ `t"$fڼC0Ed5XQ::ž_'{b/| bVQ$qbY k/q'<3<,pX&P J廉mfO1% \TȄttCTPD׃9t#[c'/`(_k3Tnz鷛IK ̝np\둁Fv=@)QPwUbeU~4Yy$hyRKf&◛:m. /ѣ\ JW9B~yW]1:}n@qZ Fu N~•I/MRLאps {y!rǦb!g`TRxэ5Ke%|pw*djZ2?T/޸ّwޔ9Ч32J]2TjQvDNR_FZjEʵ/4wU 7Ų&\[ ml*42io֦>2ׅCr{zj1 ܋FBMoȱ/ eXQ԰Ad?}i0Q(oIHm YSDWuϴ2"ujsh^;5h䎫@s€K?%?4JI<.CdZUZ ^:ճ|wI(6.+ױNמs;OvN 6&iyp$ [|FR{([^- Yaogs15OPCVzS(L]K-@%w">t = ӆ[ y#7C̑m`@t`Eϙ{wjo?=N}?LzLMRq(b 4ϖ0vDnp7lSإD׫%M&'݂!b0km>Iy|"=6%u7aZ6] duVczeu px,gص[Mօ3u%ʨy#sX>2, S@LOF]wHr~9ケ85ۣ^x~%FT c!0+#)͂`UݸѵZ^-4Xk !#ʛh,ywTj%?"IYRrx_JeJ)5,lXP/{î}6D㕘A~7L|1bTFkWm5Hj$6uvڔӹ~#%K=:q g4H\͂OBߣ:48(m/"y5]aU+A% q:g Pנ 7-^@"!SBr=fx8hYOr]ȩ"XF6=NAɟfRS ׿ Bcyjxmwܛb]^ʦȤ`1Rz2]FC{]hʥE~vRK܄n'JLݾZCtS$2YLlM^oX'5jkWHiCK1U&_0ujIJ~@_yVK/h{߬5&K,;ؤ0$?`TZ<~.8G_/QD(F" gDS7ݣzYuڢ.Y:fsy?+4-:Ao8X=&4UHPd3|zD̵G,ρS8p63~T% 92< ǂ%;vڨaF+2PC㪃HmlcGX  ؾ &]xחjؤe6 JPNX6ny&'ntk(Xl&h.'$ A.%G㓘-#CtV?vsY7+1џ댬;" $qܝH4}!AIG]^< AP 1)e+㌚$?.COةփ?@LT۬]of-a/7N]X*!3/ Ng7=aktlJzA@J|Vv"=W3|PF7<N js>v]K^>F-&K 18-Tވo!$JS"ht(㛼Wz|d#T _Bbi+ C.g10ŕBL<25̚2X穓"pZֳCZ܀:soxLHp` UWmEH&09x߼4 GI){g -@ sfXRܚ 7?1X.EVlƣW.:m2 sY13/N4--JPkrj+Iкe<颜☿|W3T(ڑI\:A*jAԆ_-r榯/ k^"㋓ۜU:Qii.%nyP|<(U׭@O"oպ wO3L` $3Gr}p"\ $gj[> WvA XQFb_dӐH2^6u[>0OW$AH9JsAeõ@0=MQe\A>ho,F 2.g ;w)G~6B f d\Έ5vM8 cs3c(I $Xv7="ȪYkI :ma@ze@E]"Kպ[gӖ9%Ea) l<t:v(耽- >L~c™N6NnmyQ/1,B68(7= NȋU/շ8>%([biyʝo^}MZTqA6b@p\F m3D n-7rơnq>4$gA5ЃxBˆ4iuL7xZYb}0FŁr_WN6 3V೩0!S+qiir"`4o8nAi~·{-ٟDaO"m!^ *wv$wzoDdps 4:@d@Tu9WS+ !(٨&~C/f|l&8Yl&d|<7o`g hPgGRvC;g&{3nU-x$Rd@dl6#$t޻ OwAZ.5AQݨŬ*&P%:-ܤgBXBf"iYɌ`3x[^܋E,ZM_f ~I!ђ7[u9gkf]8M"kƉ1_:]ۙ7Q{/| l9 %1Ak舍u1 !̐hwcuD8  ZCB:tfωnnk z%v‰niyxv;JҬT`L)%XlFsBB{am"-Ê ..eYύѵ,vJ/thǫL![,6d< 7x|$kqrRoq\~ 0NeY<>Kpl07{n"ZU~7!3,k %/S\66W'甔 uв" ' Iga]{}Ad%='y}sZ UH|x?쏛u^GRIgmV|Bd(3,yhfF4C0qޥĜ#@X|Hh o-k94_ߏJ.SVn]L0J/ +s{q2B;L!<_4c1Rч ߬3xƎ^wf $>ڮxie Zě+}ͪ0)7q*vHB""o9=m*bNβՃEiFKvIWOd+N_t$telfBRa#M̯PdThF+֟1@o[uNF()Y ;g67teggv7Q܎ɯ[%u5,S;NBN.̹YS~'EAF84&q=vUʥl%Őӹ0>)sH8+X^_*ˆ`/+O"@D}uvI]%I_g**Oe4{+k} mJx^B? R݈h?XZyw _ǕV<]TfZXQ)ܞ %ꩾIf.*hMhy5u 5BMznQG\:K*inm bfӎ)(4VɜdzYd5^AA\ \ݟk.VOkB[ _P.qWQ XaҘY0Q<ߝxa 1>BvQNojA&m#cm,e5֯"6t#v!c#$V@1V ?tN['Rz j2 hVoeX8@)-:\X3Uؚ&TGKEE/6Gʅ.bY+^WJ.RV7JN~ #bޔ{қFDO=ECc2+vRϨ4q;NwCٍ+Dv\󇎁( vs>u{8m U~HT6696R5MC]WzEJ _ :Qvcõd| htmޟ vpj[uKBlKmy|y-ebsRsq7kNTUZw/M:Z5a W߮Y"u=Fn֤:|R'4Q.VZFǚI4܁f%oH@(M6MOa%UYAZuG7!钦"1Qh_UL7Es,ٕګ@-4ٌlZ,B>'"#'&!{=ot*͡A6 es^Н! YT@&i F oVP@F_>fz4xӃ4m*O+s'ɏe}C6KX:zPwH|0b%M4FMa&ՅQ0#TT7n*O(G+8үDbC<2ȍi^^k<]SqVɤtVD8HNvW)p)0< +-E :*``,gx Xqx_1q[ȠAlG纱<rF^Ǵ{I;%?V(PBD8hǏXYѼ/Ye)x=oHy>%#x}g^?1Ў 9MdL@ȈK||7k  r T8%|DڪM-cTJ\Z uO@7A,iʑb{s-~ۂNa :xhƛJ2V3\B5޵ :AZB aҎ<P=t¬URQ$K)IrM{L?y+Aʩ@"DKOR8yfTۍ kX;CB$P6råjl-zZ"ʪiM9 _h l:Xvw$Uc=s"U=dpRuց?2kJh9xvM/h&@R@"Egи0  . f"W+@[ +QGRjZzKx,D6q32Pn%{Flxg7[[v>x/z2x:>z6jn*pe๱W+#]0މ^^IkY2mܤ@|cի {@eX[ zDu6o)Lrr0R43̳`$618Eo2pZ!'+YdK8Uځitaǘ%%> [n9L{F"rn K%Hzڰ{ 󋝪]#=̤`siBף^]p@G1;GYDkZid6.UqxjOt]~rWb^2U05zea^_f(⠣$_G-Tf l3!HM@f*zH bRČs6lQAPHdX_2Ӭ,D0Ɍ(2cXZglE%sSg6byeE0QF''k1}ܥeOXP_[;/zń^L=͎8PjD\>wasF h~V:o8+iWZT-:P_Sç"3]qZ1Pk^M[@qTSHiBn>BX_1UanSoA̴gŒ:V~0C3[vd(1<_:_Qk~e{» 1NH Ξj=-NCt9]fX'3XLs E5,& f'9~%<InVԸաUo zۨr~Lc#0)$ >8Z\̃;1|[ZG:?r-jsO GwȻc,*$.rN6&Y'.ө?l^N%FR$ZܮL|OְՃ֣?0W|4\yzL[>h(E/7j&"{ugn#v֟nV\fTKѕ$[z33kXv"n7J%1fyb \1>Ophi P+Mjڲu>o.kJƢg$@&|L  *َ 4f2XTEtdKG467 ~\)6TOI")xJD&mzFҲ@Kiʖ\GFޖ6Jݴ)w`CP>]\,^ 7ҊW23"ӏg]YPPC0T^zN-gH<*DrfQf>T/ bwoڡY߭A@-mͫEV S"S"/d X,t[sl6أʨ(p5QJ],7TH U)j?yd@6=o(g. K@$ȹ *T$?Y!5_3Еh70=!H jո*7.Bɑڦu#z6@FP`nD79#su QW@4;lΖMzW ZhGy*Sp8>]zk5 P(O$}m,Εd0)E1r LuT!A=JQ;S2?]իg<%] l1=$SGX劣Ζv]=nڌw6qY. e55 Ujd-JF#a(=y2 ;[`f6 dնd9RKςvducj{+aG|o:px]4QR!6D;^bJFR,ve|T,9WSPig9NQ*2$1u 'h ;Q_N^tSےU^e v(b+#?5ʲ`-m^>+bV~EQ\i'6;ZCu'<1 LϷޡ$T>.A qPQD{2 2oS~0 *Pk!˿ Tqɕtܛɵ#܂湷uC/=Go{/Eu6gj"ƀOMk`bal:/%s {FE7U&I*0dB$1(Y!2BFpv11M @F >O=Fu]饗ۚl"QBAd)S$0f<㞑bp Ne2pL(jƵ\'=WYwd*w.:jn:ݰ4=0uî6e$ ~97?9ƒJ#fz&*&*݅ |Z~ ?*۔cg%/`Ui?'߁]1qcV!$ y\@W+#5%vAcjKg'M!jbﷳK`!33Rq.V)-x Kr9ĿJ ˯ȗ)%«=|#yyӯK a(/X琹?F 4RRjEٱzJ#hV.ZJһ"F+=ydT+SCL3Lu3I:FD#_ i[=C[9JũtT"fsbP$=R|^uD9JyE]k-@X7dK9jSoGL hoTÓFcm*;ƭp@9~Re7?'d)Y+'8Nm9n![3?]i :޿etOWCA& =R?ٟhzIA1~?o۸1<a<ܺ*rl!0쪟gJ[;%V t#h3ܴc%g$͗lqlOYRXIƊ[kNGԔQhrEFwU;oY5;p]>G]hf\m@)*us%6ѮP$-9yRs?]QɠPL? %)e~/=jSq5S=G ϐ#%ugxq"i3\<s!\+%)f/WE)F8=xtAJۊ\B@4>VHD#xGH]vH(eέnF9M|SfX™>xPcd>! F5:\:  (PyC?7p1=boI۽qsje9nߑAJ۪ S3MPh]^X42+{VHzh z FP1^f䞟:)D$0 s+`Fi!v:)& 'Fj<~juspMRe$hm̉+/܏:}hvܨڴ}7Zr\᎕5uN͹q+E?x) e?ڏct=JŁN^jtLH1=k񎁹.fU%-",֑;w}[ x p4QeED!ƩPR TyrhJVX7C%fE.x*;ܡ>DC{NC,8JKZ0pp:(ZbE֚ n2NK8Z_ISn/'8Zu ӔOiqY_1* p2[vfE`3޲sJLF-mpOQX0`%?f0A@{%6`LWjvQ!vgg%.IUF~~11 &vN`APDS>g! P LUÒ7dϰnes;;`=NV}":͎ S<,zHX!Z&!2PSK2AWt  Cסtz:DV)0Dҷ=ϒ0OaSZ,J -m$vRbĴ*W7tR_=*mՆªHMZ8: &ҿ,(;pФnS~;_}jwr5$- V2F>RJQ1KQ`<6ĽppB4(mʈIé Qh1H\LX,&ZZ\d5FE:~mNէc~ȫѺ2]yB}KSe\6mRd4>F͈r i(7*2nUbRA|:šZ\ϫ۰*H QYhYr&" $}F}~'ZJY1!2Ļbu$m~IʉmUHjL;D jA6sB.lM#D)er(2`7$vϯ%L&̽fgie1T/s x u)4X;dXnb92\w8[-3y5"N\+ST:_\LGͭM!E˙}Q29 b,z6@04 FqfU$l0bpJSѥX/?];O#X94$?+P.Wܾ*x ^_ؠՔnqXEŊ*>uI 99y3kk [ H'ҫJJ|N1\gS vk9hQCp!QWh:A=<|V*G.{?wә+DZ2qAe-iI0t R)6N@&*yS9RiLoU&aȭtR Tda XP8mFY F9$b; 5`5|ּ(g5E6x%eHҫ/Jmіj9W@޽7K"ZC~Di\}󹺸wR$ j^>smpn Jj#}F7ETj7boV_ iJ^w'pc:~ ˴}Ww#@|`p13_dTQ$ @ !)yMWHq-l>{'ub谏ג}GjQlKI=i.TۂLlFtDU2X5JLpq|/1ROUCJNaEL=8H{78{lMtGҥya t Ek't_Prׂ"N}zdМɦf#(\nyKOѱo rFSF>A@ Z{uHgME`Qz q99FJ-'7IlT:uEC`=@IU^Cx\[aF!eEG1`bA!-gRl S+EjX6ZkΫgt3Qi.I+@5?m:Ah'.d5=ggWrZz?U튨ܰ'D~MYo4 87' 4MY \E!cz-$*M' Nyԁk$]}\Eh Q`K.D}G)>󨖸[{i sY*CZy& AQ+`Ry guV@>ÏXVş߉]bZF{("h^{\0[/&Q0!$^_!ڻSZSL9l6@Ga/P* \#:H .f7ʞ4ɃeXeK+c"T喯P Q}Xnnzw^groxFU)R4;z1Y60E3ݣ7C>V⯅2'd$ (狮^b?lϝ/h#WNG)iR2ML]sOpS RkS㋑plphԛԦ@S_@O L1RXѿ hNrL sVLmOU&tnS-cmȠ.?lϷ& )6Z@z;J phrlWb+ MP/މSMVu*=K%D}S* Iu7q9ó6Y~){N൜ftIbW0 FhKF8Ys (hmܥҐ'j}+h?E@ g@MyW|q&t}zT9LdGbr4k@$:ԧKfꊽưأ]?'1})YE2ssu5/CZ,^&:zGΆ n>msyS=n@͵3'dStAvɱ;W:$bziaQ K i:|xM vj-`UU&\ u#ZǴG@k[;wu:&]hYsdmV ڸ]{]Sq!82U _)A[AwQJɘ%2="O5E_M5)imS҆G|X?b/+cL7Z,6fuNʥ:w6%d%SR¦8G$M+LA ,?-w/'m QǴʭhVA (!s"/I])A֕S}nZ*6j"G"j.T `h{AM{Ae:GsU QT=gE_IJF KvUpSj`?x#@"v2fk#+O55v+m_3l N?~\p}vtϽ(wjy3P3ʈ1FN4lXN.S1bz?pmЦNeVE ~}T}}V.U %E8MGt?F9av]1[y턀C8gd Fxy:~_g=+Ї\w:t1& O ;aEOc~lͧh4Tm` oHVIkᵏq$CDLH:L#\JI)GnGDՏfTj] t9.vOt\Z"yK-H]/) }vM y =!PZ"?=PV)mhLF)A~Od#2vBۜO9_s?aMn%`ڏsh 3v7*$bo@ǮtBܲAŁ[F1ںPRз9"F-BH#] Ѿ-X.? T&[){$<0xc/pޘ+| hc τFԳ&fY `V~Ļ@ѓXխ Kd6-ޗ7{۟P!l2oфtΙ\,-P!H(7ǏE2¾ain2*IUƈ7y6őS6d潡9'Vّj5u{3K) :h252sJ %12F~InJ3/Cw1#'bM_6gܛH{,≈(D6RoX|7`^`#*ЫHTO_۟w>nb r0//?qt=y_J(\s ؇" KYTmV~G3w)ZrT8 \G1h1Nj7Go1t.7!14m5ʳτ p(Nd`|21Ԯy9Ul ĝ0΀l%يѕ\a^$D#>n ~-6߸=ЏeQE6oM*,ڨhez@}Er zVYlv:OXU(%޹glF۠OG<;jK&|(QZ 25&K;-L-ks9=>{IDK\/ ٦b퀰s"/EW9Po14l=([j-k|5 䑞-PP61UU_ XD.Hi9[lL1b=wyE Oʇ.6VA(Zj#4v+ׂ'K9 d#NQGF7~ Zw a5oWqFB!sX/^%'`ILPmp.gIztܯWQG\)Rh%ݶv*܍ݫbTvaAwdIsk9jHH0wT;?CmzN$k$=3ֻEnмHS!nsVWoj_ ?3 [ 갯lnb5HiCt8>hgSxʼnbՕWۨ 7FJzG}.Z !bqM #Ys"Snh ,qx)F 6L09W'#ߊF^̇gŗWk9N3;_hI$ѹH.pߙm^7ځ%t?[rb./6y1([>1wNEސ5eK 96tee͆bGt\ i"AVGs$]⨉_q礚ڈ T_^xR#=٪JWI BoIVnM߈{=R 3@qJ2\Z۽EG4Z2v#Q)rrZ?˂r:Z #@){;|}S_ev"VS1:2̎qlxFThga"qXkrAlu؂w,<⃶uN,*LR9ҙpu!z5zy;h{V3tn ha`pW(Qɡ ,[2,!v5$r,RX mB G 2aV(ﰝeĶ3_3Ƅy*c,g[ =S2\ 1A?4% TEvqRvz+Rq9Ϧz IE|;Ht=ƷtfmjVE+7 [ 912r38%6IdE :8{r]_{LޫrT!^ϪC@-XC+C;g%/^d3+5bYBQW}w(,ow.vwLĦ1?2Оcl!4~姿;- 0qc֗=}svc(@VG~hW[8N>s%,Nl4!|ԲF]$sSY|!Aq?ZE={,"Yѧ< =¹4ֵ$0ߌ:dswdjU88-PMq9嬩@fȴbdaaYyLDMj72Ǣ NZpѪJ`)^oGFgd(Uw-MO띭F5J,q]PF`XZ(j&)Xډ\:BMU eVzj] ZV`tjFIvpN;Ϳũ5ACxUm3ݽW6=HxmASZ^WųaT=@ad&u'I,/8G[PlZJ-D̆?ea;Ƞ:rHWS9\+NR\,uLs7ιKvgHQϕ =A|L-e(2ep GG[AG.n}{ݲX~ ڒ]!G|guHU+ĺsh3_{+$$}1pZ@yލ +S1wy[wU4(sr֥@5+*"Ekpz7B@@/2QlJ aE4,eɓ/ 9hE#C>/Hǽ^W^!(7-z nx^.A^0BEP { xAbaJIc/EuTkXp {~ul?&9qM],4nV|qlRwX&^8msø\y5Q$(_Z(%5mXY0mK7Y6\N6()Z/)8ٜxb2@m$<3m,{k_M?́d.yqA,*tw?T2ӱibȍtVLNq ۂ*>a)`K L w-P]j]B~N:Ûo+Y YtՌS?* NAa`HasK[B4Q_=kA⬁ ô❤sOr0wX17dsLwD!) Jͥx fC`uA:+C5^ԍNa;d aY^$\䴲qZΠ}Y o0&6pNQ(1 ?W0$W XSZl"K `X":w]Z$/qO0LԗeӚu}| m)OKhhF ZqSM3RUTd L֠e: 09ЍIRWY^(c1SUgH7^èpKw2e r4Wd˚"[<53~I ivYEkкzæ4V1G?[DmVzaMP?)v>39l-ɔLj9B4PyyuS+diDⷧҝ / y}vZxn?=շ.9'x,F12n:.qHExo5+M9P%sУ\m v"K|s] n,{"xq]Odl&b l0e!j^#+%jv+hK(ơq>B^: $^@WKOU"$_J  8'8PON8m0Z {dOκ=nnbK҄WHW%c+3T@!&y)K_MCހGpQaS61;Gzoe:@\~k=Hւ;: z=I*ӸYLDaw a^ 'Pr0% 쫜r8^8M+hЀS>foO٩<5ĞoK}n? nfnWܸ ${tPTCœ׺LsX}db6?6B&pIA-Ź|"]Hw1B~Z&"G3*2Qu@ a/AA ,Xh05TzL|7"ܭޮh3;ާ[|ue-W#ܕAC#ZQύ(pV/L6>b4{]M\jV.Omf? k 燞~WM[vrI4{&;JPI$ciR?ܰn0B_Ztd$I!A rgef'8". 1dtu4J?:OUcח|JmZV ć~7`qƹu}yzP9(;U/G{&wz08 MeqY#iiPTF!TpB4(Qb+3qѦ"Vscաt)*?YߔcfrR qĎ%QQ>.qF2a+[{6F%SڱP@ʲwA3Pi!)8 廠e'qO {=Lެ$eҁ¹6{rT?l 4goWj9 t_"@[%1z9`Ë.n6"WΡFвץ9CB@&$piGMDp3E 筹 ^ yʕ&:bɔz2}q2WU©svm`Pg-> [{.h{i9[RTm,2,snVI'f@c}@9mv6YJZHVH^@r6TQdzY R{+}+KWSY8D(,͞{3# Gh;~G+0?e%FHs#S"286B4C^A'ʷTX  ?.Sܲz- !~?,ub}&)օl :'XTg]:*Sיћ*ݿ ThU>Zɽ)aPNϟVH2R|7 s @tU4ܘz \f\*ĎzaT} C?)܇5E#S4@A %f_eV D&RF`ڂ<1ZW'r(^?pL44?Mߚ=^ ,5)M0pЃF- ;!)\?oII$ηcc&bD2'p umr(@O;Lcm8:7ys *B-\HlGAUw*cT>"tυ(y4&[,AL#../tY%骕%nrNj Qt.Cl{Sm1Rzsʼnyj /0.xK٭tdĴ6}dS@ i9n[`g߄'xx3|OiUJaxŀ4/00U!u Ԉ%K Ef*_stA=XJGeI RFXR&JN͔)&[95w'O9#&oȊH1,V]M*Ϲ $o{ ɀ"Fcp[V/NjyG .E+Q6031M<=̴8NN&pKJsJi*d!6ΣsC'2X?E;O=] t8?~6}5U(~8VҵW'rS˚uYjΝ/pĪˬL *;_Q`$΃;+iyU*&)5ǴSWIgmi &F1 oH%GX@J'2Wђ/ "15[n}arH=RͿ4zzB |:8}ZX̀.m} VXf =n5qZ]h/DGWo@ 1#1;_g"n&: ɂMyB`P7` gអ[ci: 6|NUA 6uCRsPG,BԪ?X FjbogZ0 'E;yl5/?$utsȣZƨ*߳e\Z3Q$7RLQn;hG VUU 7[N{Uk|%=;{.@1ϧ1B%{&?|D rf~:q QlY]?%:kT0,hj|sawtV uX'h,Jd\>K=)a5+,Մ8 OFY }z x|U,Ql:QVE\W.֕XvpI hcIm\WZi[LQ;.Lr)FU1peyPI&DYĞ09IN7"X7vr+H?=݂ŵ(ܺN"7GRͣہ]e$<$@9׼J4N" bz|~ " Xy׃KMpm" !vB^qۓ)kD\"7$e0.M=V0My5NB Jz07آj]g=2zN͛%Vja5t|tԒy*oCZ ZR%-V-u-?=#O[O0sA6_w1hH?(o#ҳ:h(_KQ?#j#}P&,Gk!]#E2[2$Ҽ0~iAqqÀ72SGK|K>c߬*գ@E2XyOS< gUfKI:F>|˪0p[bIԓM<=+>bW6d#.zNT^*JJeq/`*oj:VBZGo>7wt`$Z~+fF14e)l??8D ?'Ӏ'dji*_a&PamgP}{ R'xVP +u)XbXI=K%I|Z ␂Xlm~z|M4 n_Wiׄ_xM2W,]AM}w,Z Z$ХNdu O2a~'At o+RWAM) [CYesK*{Ȧ7<Զ-Q Lу;`Ӹ.1]5Di< .)L<>bϒny6޼_/%#XteIۧoI;]ANp@*/CQc=T}}~O6]9MsLӘTz:8 u_Zz[#{dU^NMd: fyyL $҅(hꡐz .95ь/Mp-&kb|}5b䭵6y_KqX.>])&/XK Mp:0BQ"TB7 Fo3횜mHha6CRu9^A$,qGKM)T rgAj]^;8'[⾇cxX B{ҋn?~ Yuڲvb`ywνt*|tճ\Y}տTݧS@B`E ^z잾<%E%ߴٱl*qt~ÓϧyCcu|y`p[F3Y]:C] zp b6v[ +K n=(̹\iyLQoÄDN[H>H*Қ!\?0GnE2?)hmp.YzJ1;t4{Uw eK mpWh@Z(+}$]ZRzT'"NtŜ2GPqJBe?|?>_Yb7|8QM]*10eqP b$#roPsuVg C F1/EpΗ"@qhA V *)BD?8P/9iR2wiDSo`ó5tix8!|l:A~b=_p x~0]+a VnQVݰ/AP@YCEK =a5{ںUrh!xq^ m] >PV9F〟x?Aw|] }&W:uVϱAa!&6tN,6mUL=أ)g D#~юdF|^U0̱䁉B `9ĥ^Mv?5:ig :/'ZCXRǭƕ突 Uyu,/L.<.XoV݊!ӻnv .3ca$;Q$󱷧6߸PN:T$/]8$h+[oFGg{o֚7đark+>oJC5'bjA׾AB& .`{#f4f?U$(-{|&FZ=oWKhbd m].ãs`Vƽ9˴##6qtbN-ɍwˤۡE{=}R8zz0j`frݨ}NPFjMΏzd- ^%fVzCmir1Oݭ:rYyuqú"Z N1dz_c(\ يyK5+._{X68oF͍D _G2rWڈ[_Dfve sYqjo-3__;Lk@tTV`zV-a?eٱlM9(UΞzݧ V`(ڜN1m u.w2joDgt㛉B?^b:yVցteꡥ[iu}L 3 t3WGBФg͔eT)yfG(E՗'*Ħt5ExX{6FlKcHN墌4̀&md7uy &f ZapWL9 t'5:nY,73!&WìĢf2/!סr;3a*Rj$H夹.*==nM^e:x\@\Ka!/D5:w2qHK˭S@Yr^#5Ptaj@q<nЧWu0{$)Nc!3z9 {b bo nNb0HxJ'jkx}bKg}z?th TFO,s/eLwUE!m'- }q)XNFKb K$C'&ha 63@K+jk_Q)gnS ZC[45*[$Ƥw61;9O >,>(=} JId }3&(Ivxs7^g#Z()QmF A4m#:u?a66F!qxp?_ H &Nn,EǘOxSEי)Y/Eh DSN &{ 3==rY cU-z˔7@Soҡo_:;[ $8G˂.um%HV8 GA$'y&.6EplC,!s>K/=9-xnc3o-];xU1Ɖ9woQ..LwJqFwc[r9a0 1Ao;:m^^ZGH-haU9k8>l~4jJ,KO(qndP0pSY"~O[; |ۦΓTIOH5- V-ʺ̠|xxx%MѺXv2 I9eS`NKvI"RीxCd08/v~Ҵ,Yb.Ay9P=QE~';gZVmqn5oCA7:i\ AaT fuZb&E/VtǕB`%ERom>OJ扽mZGJ9 ) 42-i6(*zі,Sygv-"DZ:\)ʓIglv8W'o%TxuHV=U=ݎa({c>#a+G .G6Q)m/KHMF@nYSLH)]JmF8=f@T-1 >dK` i͎%% fΛ C{+bϟ]5u5Gk,-3_[CU=|iZX|IGrD#S1Ktֳ!r[il7=h&mF*? 3Ѡ [4?A~.`z4*}KԦy2mk4V;~(3oSfA#o4!i>2cE|W5rʶj)n&^7>C++-kZu܂wן]hǽR<8|WcZ0w}|)жp2Vɩ'\SdwO RO#__&MiԟqzRp"ZZD3GyG^O;Px,CPJw ]o3#Qr )Dͭp2 x9Z`3kрMƗQ%UcJgWh 4E>Ulh 0 Bu]?- IÖ(":5&}'q*рuf7삤&)G5"1˩6]ĠPt.cYW}HYct'}>6!rT)BzHK Fš$_Dx +\Ö} #,F$>,x)~:W܀rZ_*綥Y- <ύ1y9؂8otA|IxWAPͣS4rukJPm/2z_)?Op,}v]()Aw|NyLحԦBA)w Yǽ搮bkpq8$]Wˠ:MhVx>#X'=yZ *ō08 VXD" ˆMFƀ&> |Lj%ӔȑU[6:=?,DwBKJR;;yej SK!rAB:/ p!lFڈ.7$?װ .H n?jAv$=Rs'e}5{0>IVSwPɶiԣXԵzUX cM+2,1ˎS7Z?K$~}C7 ~<:.(CHy&UeVRb~V\iX *T5ǃ۸{0|l!xΦ&ySH[ {xjpt@ނ,DL# kyϖdD?6R$YP֡6h\-2P_$6(G@O=RR&^3řW+Z5lIw281+a{:֨`I{H;eQ(W87fHJqƿxE hw%o[4&) c![d qKeRRKe0R`6ņ*75C7uE@&2v'sbsbh f>+# Gmj4m^+t.6 >dw߲䳄oOK,5}izf]̭}Qv% ^CFVqc]>$Tt ^bLqfDSZf..TQ.d sĝ7ZjĞ]g:r]O=ҲmnM]nA~GhMDdD4H9PyRH2>k^&ܹ>Md ?[%9/b{vǭPpUѠ"Ztˀ&'ðk Aɸ XmnGP, .CɯxXu0R4TjR5xQjݭ.-MLjSxx|"[e SD - P%zB/daC} .aRKU9ܻK =:ia%P9t*),ǖM`&siVləv+\i 0)GExŒ> 4[U2FgX8tAˢ6E!Z!DՍ);$>RK샌OL/{NgF'BRGo +i}65(08(9~0knv'B`?u7( ^$v n[M+Reu|I@#έ@I L&Xsfwl֬,Lhk8Ps٠[xt"t6x(3 Ź9C0[[f,"0t] od*g| v[~)BR !ڶspXYhCIμU{Td"#FK.R+L&s.F6r[t ]Kt`+봚-z(w-J_%n?D:f`L6Y}En;β`C4sjQܱKK. O^5a8CH3Y q2(-}irKzmhXvSmx_z˶l_>y7,u?ƽ>6HH()Se5T@H&t.j_ao d%DiG\>*Iƣw[4 )vɉr{4_O3}jrOAU(â}:KZG)9lѿ( xH|ۊCۢcd2`o#x$#p.>b#)r;ApH(aA1IuTw_O{_,"}P}x JdXﻤ|gqvTy&lgG6oeݦ33szYw $~T7)1a:%cz$W/dGމ] G#.69%;LE鍬$ ։jD9U>irmT%mC!1BKR<n:|!^AjwtI!Cv|C 8 #;!( bCn[b,$|8:j>^.6tiZg%͂$L1%Tq{PD[ E,RNf:aQQ h$e(V aVO; O]0͸IQ/<Ǣ?| %wQO%f,.nTݗPn Km S™"Zo"qoaJOӵI|$vyb7QכV}wO CsŚ^#O{%5^ưMh?B}?N6\Q'yB}wIBc8J9yW%dL{(dD说I]r005;%M4 C*F2mT2M49, !vWz!CDhe7rCjܢ$s7*R{MTIzOoK$_}^T=c;vK#]$ux0)z5̒gاf U?QO͉lMSJ?S4q oo?Vf T@PmvHUz3Eg"ٍPQMb4clؿ[me/g_]sȣ?1ƿڦ4Bw}W"\FWUϓ-"N%n@5fXR)axCM*l =&pn#p40 )7`9 k~$ׁ&io=RS֏Cf/drWiML}6))5pq0e.Pi1Fx*yo aMry'3@ZDcz/zH< wL^s#op'@Zr$טԡJM̠׸D2@5G/>1]J֮,>\4hܖ(*p3wa61FF#6A֎)-#t6KSpԽ9sJl^ZMܛA<1x*<1mqg-`E+઒2owݲ#xIvWf3,I1#;˗}Ǻ',t{&Iuv^d/(08I.HCyd߲MMff0VXIvZ 4 WJ3G羀PǢ `I~fG2N+39~d͸l s7fokm6GԴ|FЋG)`vO+ GW.o &}*zjV YG{iW5:]trN8$Yl1ϊLj\KmkNSSvX[/Td`qNd r LkFU#Q2hEfAkNb_?d>» /r%ds {*El_d3hc'.HNP8i%k yZxuبeVmPmCZ[]PJD)E$@pxBۚ`w)->2P\M; A\s'9%e6YL Q6A~6J돾9ԑ/z{KK,#ywtZ'\vO@L\eoގ=Ib׆uD|.& ZZKI'wB8rMJx]}[ ;/4 j v_^:8U#Xm+i8p/ Io&"a喪W1F¨0xbwUPbU`>+D Ċdow-~zH}p lNz ߦ #ߍ3?/'LP9l䯀Pi8\OUJYdT&&YՈv-B]H=u8a$!G43ܙvΕ4"|72Og 8- 6‡9Rؾo[D,Ĺ,P'j080VQpNYJ+iw5Y峆I(S M*aF{֜rey* ƊQKnLnp2$e_LB&zŴ,̙> bR>QpGiCg]&~34z?Q,s\]٨p,n94^R9$q{X<,QpC*IeuB5TLP9Q`j2}ilG{X3c6Re^KeȘK֓!K8guyJC;h-1=|i v}$Z$(F ϚFjymjrę|6~MF4fصh|.mocmRi]x`R6:h"ahk"M+=L|#)'w] I:fŵ8)x;V1DtH3B[ZmEa ~‡$~+B^MX/Uo:1cgVV! SсU7P*Pval3 dsZQ%[Y#ag}GG[:(%k"jR `gB8‹Hhh1G"0XVBp@i ݘMUa+ `I6'l6az@[)_KY~EJX~/jt7np%'ku1YI#6CQ$ b'nP~Vu1&pU4 &54=WhIPWkR`U+?olذgA'($!@WӌW;L3Xo@ӽkVpRO .U*dﶎ`. h*CYGj#Fjқ\ O"UB0Y/lL(FzNbvĩȥCWwy_`ž&ZHߔ`w,L4G}BH\v09WAB12GTx,]SiWP`6d,LS6ʝ%#ɪLҢPns6 NQ'KCPOCt?dh<BXVPb`؟E:-dߒ@3Wf]_DT˾ğhxOK5%I+2ݠdC=dr|`,z]Qni#[ Yk=J;Ba7*AK|>2?&J6g7u3& c$,ρE Y=w-b&BWK f(j@DIh^7as#9뚛ퟪ4<}vW5lsdlWXljs# $T ó!YM+ۈ*]i״J 0AWߚ3_˟0R5-;MR+DBґ$Qz3{Ȱ$/g5 A_ܣ]2R9RrB E E-K'$<(@%_Jae2q, -,_:V /s~-CA$1thZ`r `q|W 8pZi@:Qjި׊@_X|QWyg>!:i&=H돎;MaM`T.$Ee?A~f|$cOzzr)^`_fK^E-wH;#Jnv $N^m%-3t)>`8GP`n}[V2i*_ LaAn!7^ s݃2TP<ӵP&6N)d*6\O·4,Zݼ!:.6=Vdo\-@X]ΗչM[{84cDJ%vZ6lvGnS{^W48`i.+Scܶ]}vxZ0Gq~;f /Јa61_BQoﳗq(\ޟ۞FU}BOUSJ'Jg^y @pl)Ҽ YGɶ`pmn枠 Kx7nQlso$kԀ«xB=5w7y٠vjy k'z+h 6CA>7Ksnǘ̸VMC`R9) $.Uh*-^ρS1]SqE3X^Z29P'9>&ɱTVG-> 6sϞ<>#O4xNI(Si6f8 XX{7SffU_j9/T̿IItmu8Ia ^ZЎ^aqÁ;*p,$#Ì5k Xo0 Gn 42tŽYuUq?02]#k2ؾs~՟nZ)uaZ;?V- =`R8KIPz諮wazU]J2u$-:r?{ I۸ZgN58ܭWVcۧ-,7>/b_Ut!E$|=sâ  7?*X]hw}1X.ܔ{c@2dihydQ%GEݤEC Sdψ F[- $lKFL{ØBүy3֛UȤ){ǖNʱl?,Ò g鍄Ir_uU sml\O}-P׹C0gj =z{:E} 2&YMMgNFg^Ql p D=kU=:b_Q5}|ZM̸]}1u x2W3^NyekE {*'sy{L +7b&e[ "yF;fI_p}«_ߕyM-Fֳjw9o-\}/"N1O h_dߺk~MiR{tkwey ~cjbcmDԣC)& utuBPsrKݫ,t)2aL:ОɥvH+d<ԟ8~,F}XwWeum5 1lk$܋aT2OC7ɽJb"wgFEJP Lq؃/D |h+1dRgRPBl~D0r\`^ܑ _&wq1qBaU_~b;6{z`b ]kxNAWx.`3AOgIyQuտed/cHW~OH+6ՐY̩Z~RwM:_VMbUK#ȽSتqG՚]ؘߊ);2 2(٫7KCV o3 yŲmESƅnf7YW Ovwt˶b:M(NmIJs$Dx"q y-4HzLxefm='Vd yV h4LFenMegSj3AR}ƎV4RF!vIy]ŏL5T~6hFV+W [M4GtIm-{;1N:h֥TԐ|}zaK,,3J1IG d,J9vDH(G5ިZTclS8D0T`]bPeDV]pXRM6wۍ/ʹcLs,b!2H1Al3ŎեmA#@> 2'!͈D t `NKRqTFyՉFtk])3(x ؊L7n3Inrb @sY=í ט)@s5)~H7_ a}K,DҨuH&1|C(h{v>+_Ʒ횸cmcH;OXyϫ-]XPYDy ) YRC9un/  Gz7ZZe`4Ռ_6| ,$Vrkh]6C-d[~p gc1Uiv+cHmSᐖ_h r::eBmvfW\;s5u]%V!k*#U=6 zס]ZH dnT0\I{nU\h6aB9`MӬiߨ!o khƈ=``̸Y֘5_z/HLhqnhԜ;ȝlսx7UI`ҨW5ٷ)թ("'פIh>K·VNgZt`(^bWc֜4n~:C0-=S΢oW|a]Zwuz(b5'Vt"Yz3j8iDvgiW-:4VPm/ŏHX꯰/Ț0|?Ίm Oz_:mw~[X+2ʹ Qd鉝 MG ʱ[s[G31j!$sQIܳ{X}Gwڨ*ܛ`imLQn F]{2? `=WNٜVWJ` hVP\AH(jQKSsm&솆.HLJhZm ws Tk08E9jlNw˖t_9Z׆6TE\9+P)iKXD_r&d{TpR-=I{s \Wb F3тQُ"K b>R9?y[yR#8|K7 m8V{d-QRAVg6N}RIa/.lRlݒqcŽڤwˢgW;`{ Ͳn(=KGnwj}v%=n?R_-4%$ c[]&)l0܀ᐪ92h`W{^FG@F5jc2JBqr)G5;p_yiV,h,V$?]\ rPԸp.*;.D^Y ªpsiGkͻ!&eMM59C!u%b>A~鰌6G T/;֊ĕu\)ΈE5E0RYYؤ/äX}ilҐF?v TؔIJi } vf2a7}ՀR-F&1Z\:BJ|h2׎!ؒ(բ:X.CƑ`4Yr+U%2K~Xju]Zm7ӳRf"gC ?Кe@E6z{} ]ZZ2R*4BED1ڎD(|rk1Dz"!BD9v]ը 9rDime@c Iab8l Ry&тgGsGzR<r& DD`_6,Jl:Rj7B@{A_|̇^.^[2Q&A'7#``ꩳt@ԯY嫁T[.HU5*}d[ R)! oB/-"#E92m 3ȥ+gMZ/9Ɉ \L`^@b`5c0aJ\QoYu1d\ƶ G1?;JQwr:OOF?\EJvDD@7>V%N` y=ᮀZw&WY5dW:X=7Dgf AIKB,2W(h&4D-k#%:9yI_btl x ~!9o-Z-3ʉ"%NR+jy|Q+A_ jg}[(5BUZ2/D<sFz[WdjL)d gYgHE.&;_ Tg6Ԃ憉bGSoA:,,BL#ncɭiP8}O>=gA7ڧ2_ 21ffRmnE SD2ڴ=1ԏ20S0S\v{p&¿h^h祚;}L*olHtFE({vnΣ|VVEiew50tyX%]SO:ffNxz9u>YCWf~ߧݣ63En&f A}nշխoecīM(\z!:ﰴ:^c%{ITMlZC6fj:ż1Ujw`ndr` ;kS՜Pƕ+=;!rҺwz,O8;\pdemA[0)8QF:#ӷWk,,!Zx`<$n)^Bv$`GҊ"lvMd|w'y1;i`/o*zBW=NKܑgGRʷ!y<3B.8SO69!as&6[:oϡT]#jg.15bJiYR-ozIT9SHxkFd.B#HrH'YfYh_K1p :WF9wa}qefc|OU\i%aMVޫ+;d] {TpxH1$3g,j}Ћ+@(X6i3S,#4;C'a  biylzSqϝ. 2Fo~" <1/ .﬘3vYM-PSL5t\.ws`w%z:镖Ml[M]&r$6Lny/MrڴbmH l)He"F޲aRSƻ{ŶϣhF xg=aΤ'7Vq2Š,zۉ"- 9 R%"P LATV3 Հ^=6. HU^= BȽl#T?}0 N3GhK!Yg#Le'A5i/W]c !lImfFB~1N\]&tO+~sF);18Bꢚ}wD:Z s s0OΏ"^y[hV7 vx5ɭ*,,%r sGYO/8 D\܀Y$'=ou'uK6~$P5,sf#T2'XDv,w)IpʁA0+(8R\~noW@׎ SzKp61dleD5֭7|()%Eޣ]Lb#ZR`| S$Ch !ԔY+ A1sE:C/1;H;sW!7͕ ~V B-0ץ[  FE`e?Ka&ܝ՛s8%,QY_FyѸ`iXّIns)`N]; f;YB|ǽd vseh`wظKNKe1  c)[9px!u\e`%Z|{ 7M,NJ~bLYlf]2BYc F OC;&ju4GXtwH7<!nd aϼ]KT¯U+:?Ũ4+Rs*#siv\//75q2$ȋ}xr;S`/V(""@W5L}dnB7!):JHw5ZK&}MD'0.bU d`(9[b5xtΞW}3]'Ϙ=0:JX0jOD k~<ؾ6U(@vz#U`Cgw=|x~j*#Q:B'x4h!ӈVa K\u/dgڼ>f=p:0wftg 08ېui1Q5FRb~Z~=0IkK$eRd d؎mL&& vd9ɿ3K.gE6xe; |˻݁[Bwe9YZʭ'՞ A7 KїMNT4DݴiPuLxw%/+l$NفF-'q,qp i1p%2RnRů9 le(S3=l 9kTufN*|?nRؐI)غxԯ~ɧ|,>64H(XDɧ_퍼[Jȇϊ]wN(J2KBVԌި*V4Iֻ:k) EwJ-bnYE J3]OGYKzmᤁm͈:P3 1SRQfaN72e J $xg)O*mgggD-۪➡<]@rCPCqu܉M jfdթڕ7pNOh&}*26VTɊe/wtSy&RE?g _zMQg~v[u{3$E7#0Q n݅]tBT_#Öy8 *I/bV>k. t11g Q$E|xZau^)XAK!nSB6G?F/ñJoVIuP=_'K="ZnϤvnFVany6 9,CCʽNDN_ac+/+ތ6H N2QRLlA Q aSOlVa}97ɥbSD#v]/Wɴ@V *}M|1+m{_5N˺ n!WPI20 K bNn͜ȱ:ӈ3-7XhN9xU;ĸx{Q]Vwⴚ):{3'Sgwf l:TZ`>3P$H=&NoP^7LŘ@1q\_6g4)6W(8q$DK"a]y¡yMT {7CzgF%FzP G.9) Ȑ$ur7y.۸9NE4,r!f|4яilwJljG Mݱ-`{o&8(ՠu[vfz+KiCذ{!2/P|o=@X;`{ه"FƆT@Ose$U_;N]}!qt%X\ +6K :fW8|kA]>"o1 0Vh )5YPf{<ʰ~!?Y?51V=/IML$)eS}L sQ(0@3Q>ȪTG6590ྊw+%k `䕓EMkIT0)YטӤv bm< 0#;>x_ pjr-FJ~TyNC*}'$ѥ3;g,1½!05,Q SCr NӯWAp6( W1,LhG|ݥ>S_{3F_˥Jw r4x( 4dtm@MUg?5&GM/LutH5ʊFKhGU|bilۻbaYOZmhw1Um7ۥ,is)=x8`3_E?bpQO?RnH#HH>D.b 4|Z a; Vœ@M؂m}u= "rPsR=fL D/| ]jYΜ4 RRiBUwx6wut> ICX=݆ -IkYњξ$'*F%<"8U2_9hj8|UWdٳ+$uϮ/jlIEv]e`/?`lнToۧK*}&,=0[V)- F(SuOb>n2囵}P׹+$`X]{WO,QܟܺCI,HCbk$>BY_~@`!awo@0gyVGȜ6x?oڧN[{ښ cW_Sd5n\'.\t&}ŚnATq#:d_ &:삱Zb}vHgN@dǩ/1,T$?|}P-"CtBY`-%| 62nj5\g-S-ʗ s^ NsvN$ "w?eHjxoOP艆#H(?VljEqX~{@ڠ)q`e`I<_ǣ IO VF02W)SC 3l]|ֻ}NkSxh Ww~W)"*֯3 <leE$G\G~WrR,i$}0uyB!0*_jB8/c)|e-Ϩ.M G'K^{{t<2V9;%#XЯwQ&04QDˣ,\Ņ #gn;JpR_nȑ53cXζ^ ,rݕQ,;M)R#K%WAnSCrw9|դC|&9:o׽üP%*IEX.FL2g{TGBЇ1? ʹH d,qXpFJ{]+Uc($Co9x)C]\㯏LW]3- 6{9 Wj0U{*֐',B BnY:"!`}٢ߗ,@>c_wXN-"yxBky9BnӅȷm B3! }H7k\{]uIjuBXt"* tFee]„Ƽ3lENɼWL㎯4 uZIpk)FTDGivޯVмPPK4HgM~_N5J3]dĹqzHvLn+zk.k֥D{sc'X9kxʑkF7}ψeYk +R_}{ԓfLvV9'?r޹%.St{\MFĚ$ßr-k1RCJcDw҃ei8j Gɡ$_b< eRk%8]y@PD8b@ñce4f'rOkj$A.jm.d,HB1% +VJć]UII<5ViSMv%1b8-vOŷp1$$uI{s怼}W5*J }K}h-;;!/EΟ[8_wC7~{T/ ?1?$#- 0ʋ7f-*7@Pࢮ!7.l1U03}]x]W`]NqU,Z]\R{z4T Ĺ'Ms`ơ= +Þͯw)D@/@` ΠaK`9cR}5ܫ!_J;gUv҃!DXvۋ)/r$z0~ӆx)`70X ;éJ@lLΪRWi(fZ*To@q! +;ALV-9b`CƆWsֽUZRd E0lv"2I S˛+ԒkqP Q Ro5C掌I  ?MOMCƟq~o,9(TcKE8F}Ognu^jFƺ>;b ;;5r*\Ы Pk7? Aj BC۟b_9꠭#9#9{ ɾM ؄=ZwG,}^W1ƥ߁hפAL4oj ]-Uk[`bɃvwW^&AzǞsfw EB# H}F0˵f 6֔॑d{ c0qݩ1WQT4n|5׶[( fDGrULl3)KUrK1~ZrW B*?~7ˀS'=8a^E&Ћk2߿kBҭdҬIf$ S\ lorB30NN6W%d8x +HvzxPlr _[ً*#eS>2A$(Ya":)8hza{w}2LɄOn]hp5lɕŧFr@ ;3aGAEn=VqKOE>$Dx?v-vgs6F)9*FLx3,c[gC%w ^yN;0RLZ@ҡзs $TfRUOHeBXIg<qrIJ[۸ O}mPH.6{kv&끘w%H{s3u[eK"c٧ݲ}4CU}ç\KI^pGU1` gRZ)W .n26ߖX_+\As| ßؚ#t:\2wXL TE2LO ৬sո5inP!b7XChQu.9p4J{ / 5Z&qpq.رܽ%uQ4w&7$,h#+lis_F`n"O5Pk?k9E?35`bsQnA’d `(]XhA)O3AB2Ȟ^I`G iM4wlOpA^*}RY_3rNG:ƄTZ6HDPtO.x ON87&q]4[Lj0oj%!ˑq3DZn<ά 1Z^vCfUt.3M˘ܝwWz4Cmtimb^Mx9Owy(&rrwHcK9L^׷V kz$j8ao>'M#۞5 RѡU8aN)ڻ‚5]4xrdD{J%1^X@LA,+s\;=cI_`X*]\B%qpfK8c;^{?sZqYP@6xυWSh<8~گ߈a|VqEw(7*uur7ĚZ/ş$L8 f؞R򅓿3Rp(.bTTyOfyz .eHeHnj1 -LXw̹C`80j+!*u^*t47P< oF@)yTM,a.-v18l\#sL'YymR?rݑkNMNz륄 B(dUHBwn$ԝ| \[<űv@o>B[v$`^%]Ugs;B=!FBv0H)~0 w%kʯ 'V@ V ^= aD7e8G6XC7)Ugb/H0c;fI2;Tcx(JNkf | aV ],,{! 竦ʗ+YG; 8-Ov\2 s%` |'5X";If|) J hE(mIz' ^|:?Ș$QI1GdGv Mq9ecKP.Q6䨕z6pQϱ>pT9z--gBknpa`d(kF~W ^ 4#Dp|ͽr5S*"*4ЖIw{oO(S?C@;ݟVtIPBבs(~SЌX:8YQ?O+@]1nLZx.[NfJ//)UA7[gP(+ʦ`tUQT+!"L8zqaeCtos-b#!H#a 4%W'ФXu%[KQO}|Xxc=(M+klS71? Tt?aP̎0XLx=$;5yoYeCGִyje|$"x*eڇv4ϴ<iS{x4l9J+F@ M83[c߬@[T p Бnθ;+<Th&'2R}뷂GzC^-3vSJ]/ LjEũ)aQ± $Fޥ}y{ٯп!x4i˦#dh0Ҵj;Ma.`ŋD>3̍.BEw>?QQ$Anq0aeNJWH7V,7WE0 Ӯ?&cB'ecN#?~m%a*2/=x\ďw]N2UBĞ MiSF(bP!n:qC"R,@VJF{,krP%MIX),ϑZԒ=Bq sz>EJ YCZDet/Ü*.B2pTt89ʘKR\ tCKS|SPqN%zgϯl*Y8Hs/i*R<"ڞs}+GUt'u , BŅ g;*Oh `VM sp/oflĹ(,,X'UJ/z /={mY n-ܹTj?6_pChQX#Dk]!hB!z?Y%8`%U $:J1ُ6#~lͧok ֧TuhH}7[x"_YM12JᏣ qCGy '9p+ j|.e5`{ 0!w5*9hWUlV\[=~ J:Nx6ٯDֻxP!UYB5`A)Kw2Һ;4$¨]`*Rl ޓ%e] $N<|E9ɱk-=p5d\ ].ؚ[65:=5>Ex-.+Nvw-/;jNYϥ5ˣNaNdC4cHCus̀4!"R;ʣ)p"UīǞ=^j`Pw[ 2t W]ԉ@SaIsIiET0&f_BG^FtA!>o:Z7^iIb^1ewpɴhg5)3ƒTrd(j pw`hJ!.Trm$8c>iB놼jWYA.4O9twQ0VrM|tJP!BӭlT>f?J<3ƒ]=W }~!Z!kT/nP6WqXO{ֱ $?Ql1T @r p24QɼOuΝm 4-W>zMkCp}Z@PK3ȳɣl?zw?3p9_8F2p<ڡT+ P>'-+꫃^n58fw^L@ڹ+։;P\3{r0K#LzR>"ˍnzV:#zԶ_߫$jB@l" V\,|-@UvOZw8Y Eך(Q\VK8t!6<"&uXIS=5uLV.\b3gbiGu-ceSbkmVqhoV"Zq]TɐoH.aKaXoG[C ,ڀʜQcqcäۊWeXQ dQ<#KT=_?E֐0d5[w5J FoКv6~Nu\V|=EĸI=Bx$%wxW0 +ɹA-{bۣiPeu Tue:peyp[M#aep\K=`2|,]v@]qZv"؝`>1qllQ s BuCTT1y!մS5bofԼGՊ!x7q$9;ۺ8'ƾνFd?t(}43 I?WOBz:%GP qr'("jp Y۹.Cq-R"M,`>? Oj YS68ň/Q˴Nr !p㴄fzNOC~?/%-#WbmBZ!hRggݩ 9De@e|^v-BXN @U'+~+$sAh+}% R(Že)n ;oMu#D"Eb$POP b_75R=m1@> [58j*oN?/Gi #67KEᜐWkA}ȖQ21?{~)]ZFD7?J7|';5+׉QR>TE0},r՟C=4Xvg뉜px:ouԳ4TM"5$I)je Z%:LJ_K2Id&}SEx6xrH3z`]mgyx⮳|eFκ uu+;YI+LEsJ\pA4f/>TvzȂ\*#U_ 8T;e_"|J><_J;mw N&ʄBք-]Q#3*Zo%w#3zpݜx]{1:;Tk?zeƚI;D\1_91FJ@ >g2gKZO'/ZM]{܌Yj dosL +{EO03{d;_AS$v`^'}7䄌QOma-w (gҟqok/;WxQ8cD| U[ɺJi-vmy¾$$ɘ]ՃةZb肨 i̘òWha|5>CJZKTR3b$Aӡ~([l`h- S$MXdLSL/|կ٤S~eKy4L-$bj>jzbQ@9ژp,Bfi$P1iga 5. O6_uz ڒ+R2)^␾742*ǂR:RQx`5քʽ/cڤyZnⰲ:@(sHwH4F9˾DE$JM*?5 )8C9Pkf+Ϗ73~=˱D͓'ZV:ŀDan0pGF"x!"9[$?Q3]%?_Tչ&9jy/ Ah7]Gm9F J<m`UfXܗ9ԕgY%CM2ì0ˋؕi"D=B% m65RfKǾ8 wYg!x@;vsh_yx5Sqe(' aZS՛T.nfƂ$3\0):u4M@+jRV[yDjw[u{Ŧ4LҔ-pHІPn~Ɵ$A\;UR v|<7{[h2og.C;=MD u›?\?oJzYjJϦ8aOWz =[ɥ1ux5J]߸vg@yLh_7`6xODtks7 p|s;BO :;9x+IC#8tЉǝNGct ۰69>sv0JƌXϽzj.8!^ុzEJ#0;fD%C.2IY:w³RΘFƛH*Htoj+7Oև7[hݸrn8(im>2>#f$Xnw^A[4{a%m&X#2u+*^կj3}ORW7{564+FVY5MmwYP=WD[s&0uDY|D!C@*+ߕ@:Eޛ3!@QG4[kU ~4k*68'Ò 7\ xA6(+{:\ö%τ 絗ITSQ9u0XPNe_xY@.fA))?zӜC6: HLH7,F"&)Z*=ᯖH/WB(W&&R5A| Kt$C-y݅~^QKqg--fYwK JWX¿at"^9i鰴1pC'Y2pQT9$D@@AGsM d~ >sJdh&ٕo)ON' ^Žf`X$ՃEOݏr!J@ѓHc %2ۊP-O 4[C0 EKqwEK:Oz!2]:,b3.m/w5hFKbe|B(\i8H[{aS^r8V+EI$s-WJêAZeZR!9 !!8`:q'ə*z3 3<khG;&Зmf$X;dTϓj2 Nrjl=Y%ּ)±֯qב18C^ia9D@feeܝh!GQ!|Ez KÑMaBSV=_T\ixi˹ͩ:;XJ3X'zb#!J2L9Dl;Gb_FP[]#hq4]D d --Ltoi Θ/pV:AODEٍsu9kHW!2A^E":"Yc-JO[ -`5s><-޺q߬9HT )lD q:a}2A+#WhlEH$9wJBKc'{hQ/BdNiZq@s&RɚDY"⎿UPn[ϐH]*($R3͖ T@$!8̟ AʹzV/Ɔo遌Lov;9Wޯ4 8QX=%2XjVO^"Y)BzH]v#J+S%_AxDу[>HD9/l[`^G_ -qU^i+/ !FW~% }j<-m,ֶ<V Z--2k߯ w0 %n}Jl_-mӿ0#džvxK~*3P#}r/V_x3F@Yn2Oϔ-s4$5֙ #⾏8ϐ2 ^_R=^by(> c_&J>5>+Bo@d03|Ük|M.ےV|6; VbEd1dk}{-TgAiAyú$pb!Hb+=VɤnACa6RN}c\smZp86(v'1]eme@S"|Lh:.%EC).!( 9v}>';*uK+>xXy.of.x=*|j썯H |u1?$sj` 6P^txp<0@ld \ҍ!.r)WK\ioS5n|^I{c>oWvh=Ԥݬ~[Uc/Q;Pj꫷WuVXZ><} I~.#&jyZen4@0^2$}D^ć+Lޣz`ZBUqh\9S1+L xFunb州f eR!gARnA~>[w!43ȡbxގ3'/ڲ0x+^GoX]V&<R^5jKkb .'"=dl{<A%:j@J4 ݼ zya$ Q%GrȅnG#@Z;G\ewz$Zf}3U<ߦnAϪ#n~&<.{TL>ow:(X-[T7oԅ uz!V%U˻,6/(1uEg?M;މ&ZH[P4q'UٓDdWdB