samba-x86-3.6.3-141.1e>UAf}6[8($hu?W$jԦ[>//J v#O3=VD>8?d   J #, Ecy     .HT'''(:8@9:(k>GHIXY\]^bCcd_edfilk{Csamba-x863.6.3141.1A SMB/CIFS File, Print, and Authentication ServerSamba is a suite of programs that allows SMB/CIFS clients to use the Unix file space, printers, and authentication subsystem. The package named samba contains all programs that are needed to act as a server. The binaries expect the configuration file to be found in /etc/samba/smb.conf For a more detailed description of Samba, check the samba-doc package or the Samba.org Web page at http://www.Samba.org/ Please check http://en.openSUSE.org/Samba for general information on Samba as part of SUSE Linux Enterprise or openSUSE products, links to binary packages of the most current Samba version, and a bug reporting how to. Source Timestamp: 3640 Branch: 3.6.3.SLE11_SP2Wwildcard2^openSUSE 11.4openSUSEGPL-3.0+http://bugs.opensuse.orgProductivity/Networking/Sambahttp://www.samba.org/linuxia64/sbin/ldconfig -r /emul/ia32-linux /sbin/ldconfig^AAWWW85e5a81efd7f5ada437cdd01a2f85e37rootrootrootrootrootrootsamba-3.6.3-141.1.src.rpmpam_smbpass.sosamba-x86samba-x86(x86-32)   @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ glibc-x86ia32el/bin/shrpmlib(PayloadFilesHavePrefix)rpmlib(CompressedFileNames)libc.so.6libc.so.6(GLIBC_2.0)libc.so.6(GLIBC_2.1)libc.so.6(GLIBC_2.1.3)libc.so.6(GLIBC_2.11)libc.so.6(GLIBC_2.2)libc.so.6(GLIBC_2.2.3)libc.so.6(GLIBC_2.2.4)libc.so.6(GLIBC_2.3)libc.so.6(GLIBC_2.3.3)libc.so.6(GLIBC_2.3.4)libc.so.6(GLIBC_2.4)libc.so.6(GLIBC_2.5)libc.so.6(GLIBC_2.8)libdl.so.2libdl.so.2(GLIBC_2.0)libdl.so.2(GLIBC_2.1)liblber-2.4.so.2libldap-2.4.so.2libnscd.so.1libnscd.so.1(LIBNSCD_1.0)libnsl.so.1libnsl.so.1(GLIBC_2.0)libpam.so.0libpam.so.0(LIBPAM_1.0)libpam.so.0(LIBPAM_EXTENSION_1.0)libresolv.so.2librt.so.1librt.so.1(GLIBC_2.2)libtalloc.so.2libtdb.so.1libtevent.so.0libwbclient.so.0rpmlib(PayloadIsLzma)4.0-13.0.4-14.4.6-14.8.0W @S@RpRg@R^R].@R].@R>QY@Q@QQɆ@Q@@QKQ(@Q@QQ>@Q>@Qzl@Qzl@Qo@QkQ\QAQ+R@Q@QQ@QEQ \QQPP9@PP@P+PP@PBPBPPP@P*P6@PoPoPoP{@PWPQPP@OjOjO O O@O!O@O@OOO@O OoOc+@OaO`@OKp@OB5O>A@Oanswers[]; (bso#9402).- s4:torture/smb2: improve the smb2.create.blob tes; (bso#9209). - lib/krb5_wrap: request enc_types in the correct order; (bso#9272). - Fix net ads join message for the dns domain; (bso#9326). - docs-xml: fix use of tag; (bso#9345). - s3-aio_pthread: Optimize aio_pthread_handle_completion; (bso#9359). - s3:winbind: Failover if netlogon pipe is not available; (bso#9386).- Ensure adding the winbind group never can fail.- Create ntadmin group only if it doesn't yet exist.- quota: Don't force the block size to 512; (bso#3272). - Fix poll replacement to become a msleep replacement; (bso#8107). - Fix wrong test == syntax in configure; (bso#8146). - Fix --with(out)-sendfile-support option handling in autoconf; (bso#8344). - Fix builtin forms order to match Windows again; (bso#8632). - Fix RAW printing for normal users; (bso#8769); (bnc#790741). - Initialise ticket to ensure we do not invalid memory; (bso#8788). - Fix 'net rpc share allowedusers' to work with 2008r2; (bso#8966). - Fix crash on null pam change pw response; (bso#9013). - Connection to outbound trusted domain goes offline; (bso#9016). - Increase debug level for info that the db is empty; (bso#9112). - 'smbclient' can't connect to a Windows 7 server using NTLMv2; (bso#9117). - Winbind can't fetch user or group info from AD via LDAP; (bso#9147). - Open printers with the right access mask; (bso#9154). - Fix makerpms.sh on RHEL; (bso#9165). - Remove non-existent option '-Y' from winbindd manpage; (bso#9171). - Add quota support for gfs2; (bso#9172). - Make SMB2 compound request create/delete_on_close/close work as Windows; (bso#9173). - Empty SPNEGO packet can cause smbd to crash; (bso#9174). - pam_winbind: Match more return codes when wbcGetPwnam has failed; (bso#9177). - Fix crash bug in idmap_hash; (bso#9188); (bnc#788159). - SMB2 Create doesn't return correct MAX ACCESS access mask in blob; (bso#9189). - Fix service control for non-internal services; (bso#9192). - Don't take 'state->te' as indication for "was_deferred"; (bso#9196). - Parse of invalid SMB2 create blob can cause smbd crash; (bso#9209). - Bad ASN.1 NegTokenInit packet can cause invalid free; (bso#9213). - Fix segfault in smbd if user specified ports out for range; (bso#9218). - Signing cannot be disabled for SMB2 by design, so fix the documentation instead; (bso#9222). - Fix NT_STATUS_IO_TIMEOUT during slow import of printers into registry; (bso#9231). - When setting a non-default ACL, don't forget to apply masks to SMB_ACL_USER and SMB_ACL_GROUP entries; (bso#9236). - lib-addns: ensure that allocated buffer are pre set to 0; (bso#9259). - Make tdb robust against shrinking tdbs and improper CLEAR_IF_FIRST restart; (bso#9268). - Add support for reloading systemd services; (bso#9280).- Warn via the smbd log if AppArmor and "wide links" are in use; (bnc#783719).- Backport FSCTL codes and fix segfault in smbstatus from master; (bso#9058). - Fix bad call to memcpy source3/registry/regfio.c; (bso#9065). - "Domain Users" incorrectly added as additional group on domain members; (bso#9066). - Use correct RID for "Domain Guests" primary group; (bso#9067). - Fix crash bug in smbd caused by a blocking lock followed by close; (bso#9084). - Fix smbclient/tarmode panic when connecting to Windows 2000 clients; (bso#9088). - Fix refreshing of Kerberos tickets in Winbind; (bso#9098). - Fix identification of idle clients in Winbind to avoid crashes and NDR parsing errors; (bso#9104). - Fix compilation with newer MIT Kerberos which hides internal symbols; (bso#9111). - Fix flooding the logs with records we don't find in pcap; (bso#9112). - Initialize the print backend after we setup winreg; (bso#9122). - Fix lprng job tracking errors; (bso#9123). - Fix setting of "inherited" bit on inherited ACE's; (bso#9124). - Fix Winbind panic if we couldn't find the domain; (bso#9135). - Make 'smbclient allinfo' show the snapshot list; (bso#9137). - Fix nfs quota support with Linux nfs4 mounts; (bso#9144). - Valid open requests can cause smbd assert due to incorrect oplock handling on delete requests; (bso#9150).- NMB registration for a duplicate workstation fails with registration refuse; (bso#9085); (bnc#770056).- Correct documentation of "case sensitive"; (bso#8552). - Printing fails in function cups_job_submit; (bso#8719). - Fix kernel oplocks when uid(file) != uid(process); (bso#8974). - Send correct responses to NT Transact Secondary when no data and no params for the Trans2 calls are set; (bso#8989). - Fix build without ads support; (bso#8996). - Don't turn negative cache entries into valid idmappings; (bso#9002). - Fix posix acl on gpfs; (bso#9003). - Make vfs_gpfs less verbose in get/set_xattr functions; (bso#9022). - Fix migrating printers while upgrading from 3.5.x; (bso#9026). - Fix typo in set_re_uid() call when USE_SETRESUID selected in configure; (bso#9034). - Using asynchronous IO with SMB2 can return NT_STATUS_FILE_CLOSED in error instead ofNT_STATUS_FILE_LOCK_CONFLICT; (bso#9040). - Fix resolving our own "Domain Local" groups; (bso#9052); (bnc#779269). - Fix build against CUPS 1.6; (bso#9055). - Fix bugs in SMB2 credit handling code; (bso#9057). - rpcclient: Fix bad call to data_blob_const; (bso#9062).- BuildRequire gcc, make, and patch; (bnc#771516).- ndr: fix push/pull DATA_BLOB with NDR_NOALIGN; (bso#9026); (bnc#770262).- Fix shell syntax in dhcpcd hook script; (bnc#769957).- resolve_ads() code can return zero addresses and miss valid DC IP addresses; (bso#8910). - Can't join XP Pro workstations to 3.6.1 DC; (bso#8373); (bnc#787983). - winbind can hang as nbt_getdc() has no timeout; (bso#8953). - Fix crash bug in dns_create_probe when dns_create_update fails; (bso#8627) - s3-pid: Catch with pid filename's change when config file is not smb.conf; (bso#8714). - Possible memory leaks in the main Samba process; (bso#8970). - s3: Fix uninitialized memory read in talloc_free(); (bnc#764577). - Treat exit_server_cleanly() as a "clean" shutdown; (bso#8971). - Avoid crash with MIT krb5 1.10.0 in gss_get_name_attribute(); (bso#8988). - Winzip occasionally can not read files out of an open winzip dialog; (bso#8311). - s3-winbindd: call dump_core_setup after command line option has been parsed; (bso#8975). - Directory group write permission bit is set if unix extensions are enabled; (bso#8972). - s3: remove dependency on automake for "make everything"; (bso#8978). - sd_has_inheritable_components segfaults on an SD that se_access_check accepts; (bso#8811). - smbclient's tarmode insists on listing excluded directories; (bso#8922). - Notify code can miss a ChDir; (bso#8998). - s3:smbd: add a fsp_persistent_id() function; (bso#8995).- s3: Fix a segfault with debug level 3 on Solaris; (bso#8861). - s3: wbinfo --lookup-sids "" crashes winbind; (bso#8904). - smbd crashes when deleting directory and veto files are enabled; (bso#8837). - winbind_krb5_locator only returns one IP address; (bso#8897). - Wrong assertion/comparison: Compare value not pointer; (bso#8859). - Inconsistent (with manpage) command-line switch for "help" in smbtree; (bso#8831). - Fix incorrect debug statement. - Setting traverse rights fails to enable directory traversal when acl_xattr in use; (bso#8857). - Syslog broken owing to mistyping of debug_settings.syslog; (bso#8877). - s3/ldap: remove outdated netscape ds 5 schema file; (bso#8869). - s3-docs: fixes several typos; (bso#7938). - s3-VFS: Fix building out-of-tree modules; (bso#8822). - s3-docs: Add hint that setting "profile acls = yes" on normal shares can cause trouble; (bso#7930). - s3-pam_winbind: Fix the build with a newer iniparser library; (bso#8915). - Avoid null dereference in initialize_password_db(); (bso#8920). - s3:registry: implement values_need_update and subkeys_need_update in the smbconf backend. - s3:registry:reg_api: fix reg_queryvalue to not fail when values are modified while it runs. - s4:torture:rpc:spoolss: also initialize driverName before checking it in test_PrinterData_DsSpooler(). - s3:registry: multiple cleanups, fixes, and optimisations. - s3:auth/server_info: the primary rid should be in the groups rid array; (bso#8798). - s3-printing: Add new printers to registry; (bso#8554); (bso#8612); (bso#8748). - Fix the overwriting of errno before use in a DEBUG statement and use the return value from store_acl_blob_fsp rather than ignoring it; (bso#8945). - s3-auth: Don't lookup the system user in pdb; (bso#8944). - s3-passdb: Fix negative SID->uid/gid cache handling; (bso#8952). - Fix typo in pam_winbindd code; (bso#8957). - Fix remove_duplicate_addrs2 previously it could leave zero addresses in the list; (bso#8910). - Slow but responsive DC can lock up winbindd; (bso#8943). - Broken processing of %U with vfs_full_audit when force user is set; (bso#8882).- Attempt to use samlogon validation level 6; (bso#7945); (bnc#741623).- Add PreReq /etc/init.d/nscd to the winbind package; (bnc#759731).- Recover from ncacn_ip_tcp ACCESS_DENIED/SEC_PKG_ERROR lsa errors; (bso#7944); (bnc#755663). - Fix lsa_LookupSids3 and lsa_LookupNames4 arguments.- docs-xml: fix default name resolve order; (bso#7564). - s3-aio-fork: Fix a segfault in vfs_aio_fork; (bso#8836). - docs: remove whitespace in example samba.ldif; (bso#8789). - s3-smbd: move print_backend_init() behind init_system_info(); (bso#8845); (bnc#730769). - s3-docs: Prepend '/' to filename argument; (bso#8826).- Restrict self granting privileges where security=ads for Samba post-3.3.16; CVE-2012-2111; (bnc#757576).- Remove all precompiled idl output to ensure any pidl changes take effect; (bnc#757080).- Samba pre-3.6.4 are affected by a vulnerability that allows remote code exe- cution as the "root" user; PIDL based autogenerated code allows overwriting beyond of allocated array; CVE-2012-1182; (bso#8815); (bnc#752797).- s3-winbindd: Only use SamLogonEx when we can get unencrypted session keys; (bso#8599). - Correctly handle DENY ACEs when privileges apply; (bso#8797).- s3:smb2_server: fix a logic error, we should sign non guest sessions; (bso8749). - Allow vfs_aio_pthread to build as a static module; (bso#8723). - s3:dbwrap_ctdb: return the number of records in db_ctdb_traverse() for persistent dbs; (#bso8527). - s3: segfault in dom_sid_compare(bso#8567). - Honor SeTakeOwnershiPrivilege when client asks for SEC_STD_WRITE_OWNER; (bso#8768). - s3-winbindd: Close netlogon connection if the status returned by the NetrSamLogonEx call is timeout in the pam_auth_crap path; (bso#8771). - s3-winbindd: set the can_do_validation6 also for trusted domain; (bso#8599). - Fix problem when calculating the share security mask, take priviliges into account for the connecting user; (bso#8784).- Fix crash in dcerpc_lsa_lookup_sids_noalloc() with over 1000 groups; (bso#8807); (bnc#751454).- Remove obsoleted Authors lines from spec file for post-11.2 systems.- Make ldapsmb build with Fedora 15 and 16; (bso#8783). - BuildRequire libuuid-devel for post-11.0 and other systems. - Define missing python macros for non SUSE systems. - PreReq to fillup_prereq and insserv_prereq only on SUSE systems. - Always use cifstab instead of smbfstab on non SUSE systems.- Ensure AndX offsets are increasing strictly monotonically in pre-3.4 versions; CVE-2012-0870; (bnc#747934).- Add SERVERID_UNIQUE_ID_NOT_TO_VERIFY; (bso#8760); (bnc#741854).- s3-printing: fix crash in printer_list_set_printer(); (bso#8762); (bnc#746825).- s3:winbindd fix a return code check; (bso#8406).- s3: Add rmdir operation to streams_depot; (bso#8733).- s3:smbd:smb2: fix an assignment-instead-of-check bug conn_snum_used(); (bso#8738); CVE-2013-0454; (bnc#811975).- s3:auth: fill the sids array of the info3 in wbcAuthUserInfo_to_netr_SamInfo3(); (bso#8739).- s3:client: ignore SMBecho errors (the server may not support it); (bso#8139).- Be more strict when using PAM_AUTH API from winbind if Kerberos auth is enabled and don't unintentionally use a bogus domain name; (bso#8734).- smbclient fails with posix large reads; (bso#8727).- Use the smbfs init script on versions pre-11.3, or cifs in later versions; (bnc#744614).- s3: Compile IDL files in autogen, some configure tests need this.- Fixes various deadlocks in if-up.d / if-down.d when running under systemd; (bnc#732395).- Update to 3.6.3. + Fix memory leak in parent smbd on connection; CVE-2012-0817; (bso#8724); (bnc#743986).- Use spdx.org compliant license names for all packages.- Update to 3.6.2. + Make Winbind receive user/group information (bug #8371). + Several SMB2 fixes. + Fix a crash bug in the spoolss code. + Add new contributing FAQ announcing acceptance of corporate (C). + DeletePrinterDriverEx deletes files in use; (bso#4942); (bnc#742504). + Fix cli_write_and_x() against OS/2 print shares; (bso#5326). + Fix 'smbclient tar' for files greater than 8GB on BE machines; (bso#563); (bnc#726145). + Remove pointless use_memory_krb5_ccache; (bso#7465). + Fix perl path; (bso#8176). + Grant credits in async interim responses (SMB2); (bso#8357). + Make Winbind receive user/group information; (bso#8371). + Fix Windows XP clients crashing smbd process every once in a while; (bso#8384); (bnc#731571). + Make VFS op "streaminfo" stackable; (bso#8419). + Add an allocation pool to idmap_autorid; (bso#8444). + Fix SEGFAULT from net registry export on not zero terminated REG_SZ values; (bso#8528). + Make DSO_EXPORTS_CMD more portable; (bso#8531). + readlink() on Linux clients fails if the symlink target is outside of the share; (bso#8541). + smbclient posix_open command fails to return correct info on open file; (bso#8542). + winbind_samlogon_retry_loop ignores logon_parameters flags; (bso#8548). + Fix setting the machine account password; (bso#8550). + Make SMB2 handle compound request headers in the same way as Windows; (bso#8560). + Password change settings not fully observed; (bso#8561). + Fix double free error in talloc; (bso#8562). + Fix alignment in the non-extended-security negprot; (bso#8573). + Add systemd service files; (bso#8575). + Add systemd service files; (bso#8575). + smb2_flush: Don't send uninitialized memory; (bso#8579). + Enable inotify if sys or kernel inotify is available; (bso#8580). + Increase a debug level; (bso#8585). + libsmb: Only align unicode pipe_name; (bso#8586). + Fix marshalling of samr_ChangePasswordUser3; (bso#8591). + Don't limit the number of open dptrs for SMB2; (bso#8592). + Fix a crash bug in cldap_socket_recv_dgram(); (bso#8593). + Make cldap work over IPv6; (bso#8600). + Fix intermittent print job failures caused by character conversion errors; (bso#8606). + Improve configure.in so it can be used outside the Samba source tree; (bso#8607). + Winbind: Don't fail on users without a uid; (bso#8608). + Ensure we correctly calculate reply credits over all returned SMB2 replies; (bso#8614). + Fix migrate printer code; (bso#8618). + Fix crash bug when trying to browse Samba printers; (bso#8623). + libsmb: Don't duplicate Kerberos service tickets; (bso#8628). + POSIX ACE x permission becomes rx following mapping to and from a DACL; (bso#8631). + When returning an ACL without SECINFO_DACL requested, we still set SEC_DESC_DACL_PRESENT in the type field; (bso#8636). + Fix the vfs_commit module; (bso#8639). + Add an update function for Winbind cache; (bso#8643). + vfs_acl_xattr and vfs_acl_tdb modules can fail to add inheritable entries on a directory with no stored ACL; (bso#8644). + Document the "ignore system acls" option of vfs_acl_xattr and vfs_acl_tdb vfs modules; (bso#8652). + Fix deleting a symlink if the symlink target is outside of the share; (bso#8663). + Fix renaming a symlink if the symlink target is outside of the share; (bso#8664). + Fix NT ACL issue; (bso#8673). + Fix buffer overflow issue with AES encryption in samba traffic analyzer; (bso#8674). + Fix Winbind segfault if we can't map the last user; (bso#8678). + recvfile code path using splice() on Linux leaves data in the pipe on short write; (bso#8679). + Try ctdbd_init_connection() as root; (bso#8684). + Packet validation checks can be done before length validation causing uninitialized memory read; (bso#8686). + Fix typo in 'net memberships' usage; (bso#8687). + libads: Fix malloc/talloc mismatch in ads_keytab_verify_ticket(); (bso#8692). + Make DeletePrinterDriverEx remove printer driver files; (bso#8697) (bnc#740810). + Fix major leak with SMB2 in connections.tdb; (bso#8710).- s3-spoolss: Pass the right pointer type; (bso#4942); (bnc#742504).- Use simplified smb signing infrastructure; (bnc#741623).- Use correct license, LGPLv3+ for libwbclient packages.- When returning an ACL without SECINFO_DACL requested, we still set SEC_DESC_DACL_PRESENT in the type field; (bso#8636).- Fix incorrect types in the full_audit VFS module. Add null terminators to audit log enums; (bnc#742885).- Prefix print$ path on driver file deletion; (bso#8697); (bnc#740810). - Fix printer_driver_files_in_use() call ordering; (bso#4942); (bnc#742504).- Buffer overflow issue with AES encryption in samba traffic analyzer; (bso#8674). - NT ACL issue; (bso#8673). - Deleting a symlink fails if the symlink target is outside of the share; (bso#8663). - connections.tdb - major leak with SMB2; (bso#8710).- Renaming a symlink fails if the symlink target is outside of the share; (bso#8664).- Intermittent print job failures caused by character conversion errors; (bso#8606). - ads_keytab_verify_ticket mixes talloc allocation with malloc free; (bso#8692). - libcli/cldap: fix a crash bug in cldap_socket_recv_dgram(); (bso#8593). - s3:lib/ctdbd_conn: try ctdbd_init_connection() as root; (bso#8684). - s3-printing: fix migrate printer code; (bso#8618). - Packet validation checks can be done before length validation causing uninitialized memory read; (bso#8686).- net memberships usage info was wrong; (bso#8687). - s3-libsmb: Don't duplicate kerberos service tickets; (bso#8628). - Recvfile code path using splice() on Linux leaves data in the pipe on short write; (bso#8679). - s3-winbind: Fix segfault if we can't map the last user; (bso#8678). - vfs_acl_xattr and vfs_acl_tdb modules can fail to add inheritable entries on a directory with no stored ACL; (bso#8644). - s3/doc: document the ignore system acls option of vfs_acl_xattr and vfs_acl_tdb; (bso#8652). - Winbind can't receive any user/group information; (bso#8371). - s3-winbind: Add an update function for winbind cache; (bso#8643). - s3: Attempt to fix the vfs_commit module. - POSIX ACE x permission becomes rx following mapping to and from a DACL; (#bso#8631). - s3:libsmb: only align unicode pipe_name; (bso#8586). - s3-winbind: Don't fail on users without a uid; (bso#8608). - Crash when trying to browse samba printers; (bso#8623). - talloc: double free error; (bso#8562). - cldap doesn't work over ipv6; (bso#8600). - s3:libsmb: fix cli_write_and_x() against OS/2 print shares; (bso#5326). - SMB2: not granting credits for all requests in a compound request; (bso#8614). - smb2_flush sends uninitialized memory; (bso#8579). - Password change settings not fully observed; (bso#8561). - s3:smb2_server: grant credits in async interim responses; (bso#8357). - s3:smbd: don't limit the number of open dptrs for smb2; (bso#8592). - samr_ChangePasswordUser3 IDL incorrect; (bso#8591). - idmap_autorid does not have allocation pool; (bso#8444). - Add systemd service files. - s3:libsmb: the workgroup in the non-extended-security negprot is not aligned; (bso#8573). - s3-build: Fix inotify detection; (bso#8580). - SMB2 doesn't handle compound request headers in the same way as Windows; (#bso8560). - Disconnecting clients swamp the logs; (bso#8585). - s3-netlogon: Fix setting the machinge account password; (bso#8550). - winbind_samlogon_retry_loop ignores logon_parameters flags; (#bso8548). - smbclient posix_open command fails to return correct info on open file; (bso#8542). - readlink() on Linux clients fails if the symlink target is outside of the share; (bso#8541). - s3-netapi: remove pointless use_memory_krb5_ccache; (bso#7465). - s3:Makefile: make DSO_EXPORTS_CMD more portable; (bso#8531). - s3:registry: fix the test for a REG_SZ blob possibly being a zero terminated ucs2 string; (bso#8528). - Make VFS op "streaminfo" stackable; (bso#8419).- Fix incorrect perfcount array length calculations; (bnc#739258).- BuildRequire autoconf to avoid implicit dependency for post-11.4 systems.- Remove call to suse_update_config macro for post-11.4 systems.- Use samba.org for the ldapsmb source location.- Fixing libsmbsharemode dependency on ldap and krb5 libs in Makefile; (bnc #729516).- Do not map POSIX execute permission to Windows FILE_READ_ATTRIBUTES; (bso#8631); (bnc#732572).- Add ldap to Should-Start and Stop of the smb init script; (bnc#730046).- Fix smbd srv_spoolss_replycloseprinter() segfault; (bso#8384); (bnc#731571).- Fix pam_winbind.so segfault in pam_sm_authenticate(); (bso#8564).- Fix smbclient >8GB tars on big endian machines; (bso#563); (bnc#726145).- Fix typo in net ads join output; (bnc#713135).- Ignore a potentially missing AppArmor snippet helper script; (bnc#725256).- Update to 3.6.1. + Fix smbd crashes triggered by Windows XP clients; (bso#8384). + Fix a Winbind race leading to 100% CPU load; (bso#8409). + Several SMB2 fixes. + The VFS ACL modules are no longer experimental but production-ready. + Fix 'net ads join -k' when KRB5CCNAME is not set; (bso#7465). + smb_acl_to_posix: ACL is invalid for set (Invalid argument); (bso#7509). + Return error of cli_push when 'put - /some/file' is used; (bso#7551). + Fix usage of cli_errstr(); (bso#7864). + Fix 'widelinks' regression; (bso#8229). + Empty notify servername; (bso#8236). + Add man vfs_aio_fork; (bso#8256). + smb2: smbd logs "Invalid SMB packet: first request: 0x0008" and crashes; (bso#8334). + Add a fallback for missing open&x support in MAC OS/X Lion; (bso#8338). + While migrating forms, don't fail if the form already exists; (bso#8351). + OS/2 sends an unexpected write&x/read&x chain; (bso#8360). + Fix build of vfs_prealloc on SLES8; (bso#8363). + Fix the build of gpfs.c on RHEL 6.0 with gpfs 3.4.0-4; (bso#8364). + Fix the fallback to the deprecated spelling idmap:script; (bso#8368). + Fix vfs_chown_fsp; (bso#8370). + Fix smbd crashes triggered by Windows XP clients; (bso#8384). + Fix smbclient access to NT4 shares; (bso#8385). + Optimize serverid_exists() for Solaris; (bso#8395). + registry/reg_format.c must include includes.h; (bso#8401). + SMB2 server can return requests out-of-order when processing a compound request; (bso#8407). + Fix a Winbind race leading to 100% CPU load; (bso#8409). + Fix "saving as" of MS Office 2007 (Word) documents on Samba shares with SMB2; (bso#8412). + Fix 'getent group' if trusted domains are not reachable; (bso#8420). + Fix infinite loop in ACL module code; (bso#8422). + Fix wrong reply to DHnC (durable handle reconnect); (bso#8428). + Compound SMB2 requests on an IPC connection can corrupt the reply stream; (bso#8429). + Fix segfault in iconv.c; (bso#8433). + NFSv4 DENY ACLs always include SYNCHRONIZE flag - blocking renames; (bso#8442). + Be smarter about setting default permissions when a ACL_USER_OBJ isn't given; (bso#8443). + Check the wct of the incoming SMBnegprot responses; (bso#8452). + Fix smbclient segfaults when dialect option -m is used for legacy dialects; (bso#8453). + Fix uninitialized memory problem in group_sids_to_info3; (bso#8455). + Samba PDC is looking up only primary user group; (bso#8455). + IE9 on Windows 7 cannot download files to samba 3.5.11 share; (bso#8458). + smb2_find uses a hard coded max reply size of 0x10000 instead of smb2_max_trans; (bso#8473). + SMB2 create doesn't cope with an Apple client using NULL blob in create; (bso#8474). + Don't call smbd_terminate_connection in smb2_validate_message_id(); (bso#8476). + Samba asserts when SMB2 client breaks the crediting rules; (bso#8476). + Map to guest can return uninitialized blob of data; (bso#8477). + acl_xattr can free an invalid pointer if no blob is loaded; (bso#8480). + DFS breaks zip file extracting unless "follow symlinks = no" set; (bso#8493). + Remove "experimental" label on VFS ACL modules; (bso#8494). + SMB2_OP_CANCEL requests don't have to be signed; (bso#8503). + smbd doesn't correctly honor the "force create mode" bits from a cifsfs create; (bso#8507). + Read-only handles on SAMR allow SAMR_DOMAIN_ACCESS_CREATE_USER; (bso#8509). + Disallow "." in can_set_delete_on_close(); (bso#8515). + SMB2 create call returns incorrect file allocation size; (bso#8518). + Fix SMB2 SMB2_OP_GETINFO and SMB2_OP_IOCTL parsing requirements; (bso#8520). + Winbind cache timeout expiry test was reversed; (bso#8521).- s3/doc: add man page for aio_fork vfs module.- Fix uninitialized memory problem in group_sids_to_info3; (bso#8455).- s3: Samba PDC is looking up only primary user group; (bso#8455).- Add script to create or update an AppArmor sniplet with permissions for all Samba shares; (bnc#688040).- Add "ldapsam:login cache" parameter to allow explicit disabling of the login cache; (bnc#723261).- Retain the smbd startproc return value for correct startup status reporting. unset was incorrectly being called prior to rc_status; (bnc#723724).- Prevent deadlock in systemd triggered by if-down.d handler on shutdown; (bnc#721598).- smb2_find uses a hard coded max reply size of 0x10000 instead of smb2_max_trans; changed defaults and documentation (bso8473).- Empty CIFS share can be blocked for other clients by deleting it via empty path (DELETE_PENDING until the last client); (bso#8515).- winbindd cache timeout expiry test was reversed; (bso#8521).- Fix SMB2 SMB2_OP_GETINFO and SMB2_OP_IOCTL parsing requirements; (bso#8520).- s3:smb2_create: fix allocation size return value when opening existing files; (bso#8518).- SMB2 create doesn't cope with an Apple client using NULL blob in create; (bso#8474).- NFSv4 DENY ACLs always include SYNCHRONIZE flag - blocking renames; (bso#8442).- s3-docs: Fix bug (bso#7908) and typo.- Return error of cli_push when 'put - /some/file' is used; (bso#7551).- Read-only handles on SAMR allow SAMR_DOMAIN_ACCESS_CREATE_USER; (bso#8509).- smbd doesn't correctly honor the "force create mode" bits from a cifsfs create; (bso#8507).- Default user entry is set to minimal permissions on incoming ACL change with no user specified; (bso#8443).- smb_acl_to_posix: ACL is invalid for set (Invalid argument); (bso#7509).- Handle the SECINFO_LABEL flag in the same was as Win2k3; enable Microsoft Internet Explorer 9 on Windows 7 to download files; (bso#8458).- DFS breaks zip file extracting unless "follow symlinks = no" set; (bso#8493).- s3-docs: Fix typos.- s3:smb2_server: SMB2_OP_CANCEL requests don't have to be signed; (bso#8503).- Remove "experimental" label on VFS ACL modules; (bso#8494).- acl_xattr can free an invalid pointer if no blob is loaded; (bso#8480).- s3-smbd: asserts when SMB2 client breaks the crediting rules; (bso#8476).- s3-libnet: allow to use default krb5 ccache in libnet_Join/libnet_Unjoin; (bso#7465).- smb2_find uses a hard coded max reply size of 0x10000 instead of smb2_max_trans; (bso#8473).- s3-netapi: allow to use default krb5 credential cache for libnetapi users.- s3-docs: document -k switch in net manpage.- Map to guest can return uninitialized blob of data; (bso#8477).- s3-registry: registry/reg_format.c must include includes.h; (bso#8401).- smbclient segfaults when option -m is used for legacy dialects; (bso#8453).- Fix 'widelinks' regression intro'd in 3.2; (bso#8229).- Compound SMB2 requests on an IPC connection can corrupt the reply stream; (bso#8429).- s3-spoolss: Fix bug forms migration; (bso#8351).- s3:libsmb: check the wct of the incoming SMBnegprot responses; (bso#8452).- s3: Do not fork the echo handler for smb2; (bso#8334).- s3-spoolss: Fix bug empty notify servername; (bso#8236).- SMB2 server can return requests out-of-order when processing a compound request; (bso#8407).- Remove smb child crash fix. The issue had been fixed upstream differently.- BuildRequire ctdb-devel version greater than 1.0.105 for post-10.0 systems.- Fix samba duplicates file content on appending. Move posix case semantics out from under the VFS; (bso#6898); (bnc#681208).- Make winbind child reconnect when remote end has closed, fix failing sudo; (bso#7295); (bnc#569721).- Spec file cleanup as suggested by the spec-cleaner tool. + Make all BuildRequires, PreReq, and Provides a separate line. + Use %{buildroot} instead of ${RPM_BUILD_ROOT}. + Use straight commands instead of macros (make, install). + Use -p in post and postun if we only call one command. + Use %{_localstatedir} instead of %{_var} in the filelist. + Remove superfluous AutoReqProv on lines.- Remove %release from all Provides.- Fix segfault in iconv.c which caused a null pointer dereference; (bso#8433).- Use /var/run for the cifs state file in the init script too; (bnc#710304).- Microsoft Word from Microsoft Office 2007 fails to save as on a share with SMB2; (bso#8412).- Use sys_write and sys_read in fork_domain_child to fix a winbind race leading to 100% CPU usage; (bso#8409).- Fix wrong reply to smb2 durable handle reconnect (DHnC) request; (bso#8428).- Fix infinite loop in ACL module code; (bso#8422).- Fix getent group if trusted domains are not reachable; (bso#8420).- smbclient can't access a NT4 share since 3.6.0; (bso#8385).- Optimize serverid_exists() for Solaris; (bso#8395).- talloc: + check block count after references test. + added test suite for talloc_free_children(). + license info erratum in the manpage. + fix typos and better differentiation between versions 1 and 2. + preserve context name on talloc_free_children(). + ensure the sibling linked list remains valid during a free.- vfs_chown_fsp returned in the wrong directory; (bso#8370).- Remove irritating "." targets when recent system libs exist; (bso#8369).- Correctly initialize "idmap config * : script" with NULL; (bso#8368).- Add missing include to suppress compiler warnings; (bso#8365).- Point the chain offset beyond the current request; (bso#8360).- Fix gpfs vfs module build; (bso#8364).- Make vfs_prealloc even build on older systems; (bso#8363).- Do central cli_set_error and return the actual NTSTATUS; (bso#7864).- Add a fallback for missing open&x support in OS/X Lion; (bso#8338).- Update to 3.6.0. + BUG 7462: Make SA_RESETHAND conditional on its existance. + BUG 8303: db_ctdb_send_schedule_for_deletion() is not defined. + BUG 8324: smbclient cannot list directories from a big-endian machine. + BUG 8326: WinXP cannot join a Samba3 domain with a 'even' hostname. + BUG 8327: Fix the reload of the configuration, also reload activated registry shares. + BUG 8328: Cleanup of idmap_tdb2 code. + BUG 8330: Fix NFSv4 ACL merging logic. + BUG 8335: File copy aborts with smb2_validate_message_id: bad message_id. + BUG 8341: Fix segfault in libsmbclient. + BUG 8343: Fix SMB2 crash reading with aio_fork beyond the end of file. + BUG 8347: Fix regression for HP-UX, AIX and OSF. + BUG 8357: Make sure we grant credits on async read/write operations. + BUG 8358: Fix a bug in run_poll_events(). + BUG 8362: Fix build issue on old glibc systems.- Remove references to disabled vscan build.- Add missing define, includes, and initialization to get_printing_ticket.- Use /var/run for the cifs state file; (bnc#710304).- Fix #ifdef CTDB_CONTROL_SCHEDULE_FOR_DELETION issue; (bso#8303).- File copy aborts with smb2_validate_message_id: bad message_id; (bso#8335).- Fix reload of the configuration and also reload activated registry shares; (bso#8327).- WinXP cannot join a Samba3 domain with a 'even' hostname; (bso#8326).- smbclient cannot list directories from a big-endian machine; (bso#8324).- Update to 3.6.0rc3. + BUG 7841: Explicitly pass domain_sid to wbint_LookupRids(). + BUG 7888: Deal with buggy 3.0 based PDCs. + BUG 8083: Fix "inherit owner = yes" with vfs_acl_xattr or vfs_acl_tdb module. + BUG 8102: Do not allow to change file ACLs from normal domusers. + BUG 8102: Do not allow to change file ACLs from normal domusers. + BUG 8193: Add new command 'enumerate_recursive'. + BUG 8195: Make rpc client code working against NT4 servers. + BUG 8211: Fix "inherit owner = yes" when "inherit permissions = yes" is set. + BUG 8213: Fixes in idmap_autorid. + BUG 8214: Fix smbd crash on printer driver upgrade. + BUG 8215: Fix Winbind unix username lookup. + BUG 8216: Make Winbind returning correct results with 'sids2xids'. + BUG 8217: Do not stat-check the share path in 'net conf addshare'. + BUG 8219: Fix SMB Panic from Windows 7 client. + BUG 8224: Fix the build on FreeBSD. + BUG 8226: Use c99 initializers which are supported by old gcc 2.95 compilers. + BUG 8230: Move .nmbd socket directory to non-hidden name PREFIX/var/nmbd. + BUG 8231: Fix crash bug in 'net cache get'. + BUG 8235: Fix smbd crash on startup caused by migrate_printer(). + BUG 8240: Fix Valgrind warnings in winreg/spoolss code. + BUG 8244: Fix copying files larger than 2 GB to a Samba share. + BUG 8247: Fix Coverity ID 2582: FORWARD_NULL. + BUG 8253: Fix Winbind panic if verify_idpool() fails. + BUG 8254: Fix "acl check permissions = no". + BUG 8260: Fix DCERPC responses with fragments larger than 1024 bytes. + BUG 8262: Fix build of vfs_commit. + BUG 8263: Fix build with --with-fake-kaserver or --with-vfs-afsacl. + BUG 8264: Fix Valgrind bugs in svcctl. + BUG 8276: Close all sockets attached to a subnet in close_subnet(). + BUG 8278: Fix smbd panic when CTDB is unhealthy. + BUG 8281: Fix build of examples/VFS/*. + BUG 8286: Fix smbd crash on premature end of smb2 conn. + BUG 8292: Fix a major architectural flaw in the SMB2 server code. + BUG 8293: Fix log file rotating in SMB2. + BUG 8304: Fix uninitialized variable in error path. + BUG 8305: Fix segfault in nmbd when using 'smbtree ...'.. + BUG 8307: brl_close_fnum does not call SMB_VFS_BRL_UNLOCK_WINDOWS on all locks. + BUG 8310: toupper_ascii() is broken on big-endian systems. + BUG 8314: Fix smbd crash with unknown user. + Mark 'time offset' parameter as deprecated.- The Samba Web Administration Tool (SWAT) versions 3.0.x to 3.5.9 are affected by a cross-site scripting vulnerability; CVE-2011-2694; (bso#8289); (bnc#708503).- The Samba Web Administration Tool (SWAT) versions 3.0.x to 3.5.9 are affected by a cross-site request forgery; CVE-2011-2522; (bso#8290); (bnc#705241).- Fixed the DFS referral response for msdfs root; (bnc#703655).- Fix CUPS print job IDs; (bso#7288); (bnc#701257).- Make use of the actual library version as part of the package name on post-11.3 systems only.- Fix winbind internal error; (bso#7636); (bnc#659424).- Improve ctdb vacuuming performance with use of SCHEDULE_FOR_DELETION; (bnc#705170).- Specify nmbdsocketdir at configure time; (bnc#700953).- Build the tdb, talloc, and tevent libraries ahead of anything else.- Update to 3.6.0rc2. + BUG 6911: Fix Kerberos authentication from Vista to Samba. + BUG 8166: Don't lockout users when offline. + BUG 8200: Add support for multiple writeable ldap idmap domains. + BUG 8148: Default to protocol version 2 for SMB Traffic Analyzer. + BUG 7054: Fix X account flag when "pwdlastset" is "0". + BUG 8144: Fix setting timestamp when touching files with CIFS clients. + BUG 8153: Fix setting up getaddrinfo on IPv6-only machines. + BUG 8156: Fix 'net ads join' using the user's Kerberos ticket. + BUG 8157: Fix parsing a cups printcap file. + BUG 8175: Fix smbd deadlock. + BUG 8189: Support shadow copy display over SMB2. + BUG 8197: Winbind does not properly detect when a DC connection is dead. + BUG 8203: Winbind needs to reset the DC connection if an RPC times out.- Make cupsaddsmb fill printers location; (bso#8132); (bnc#698209).- Add "winbind max clients" parameter to remove 200-client limit; (bnc#697461).- Disable logon cache for password lockout consistency when running in a cluster; (bnc#694836).- Fix logon of AD users with many group memberships; (bso#6911); (bnc#657026).- Don't lockout users while offline; (bso#8166); (bnc#692607).- Update to 3.6.0rc1. + BUG 8111: CIFS VFS: Fix unexpected error on SMB posix open. + BUG 8112: POSIX extension opens of a directory are denied with EISDIR. + BUG 8132: Fix filling printers location field when using cups. + Remove fstrings from client struct. + BUGFIX when converting from safe_strcpy to strlcpy. + Fix off-by-one calculations with strlcpy. + Ensure we always write the correct incoming mid into the share mode table entries. + Fix the SMB2 oplock showstopper. + Convert user-specified domain to uppercase in libsmb. + Fix Coverity CID #2302: FORWARD_NULL. + Fix cups_pull_comment_location(). + Fix double free of cups request. + Make cups_pull_comment_location() work again. + Fix potential crash bug in display_print_driver3(). + Properly clean up in pthreadpool_init in case of failure. + Make plaintext session setup async. + Reduce fd load in Winbind children. + Avoid a potential 100% CPU loop in Winbind. + Tune broadcast namequeries for unique names. + Properly deal with exited winbind children. + Fix dup_smb2_vec3. + Fix return check in nss_wins.- Fix to renew the kerberos ticket in samba after expiry; (bnc#669949).- Fix a 100% CPU loop when ctdbd dies during a traverse; (bnc#693945).- Make dhcpcd hook BOOTPROTO check cover dhcp6 too; (bnc#691969).- Handling of large (> 256 bytes) ntlmv2 blobs in winbind; (bnc#529946).- Package static libraries with 0644 permissions.- Add Requires libtalloc-devel to libldb-devel and libtevent-devel.- Rename libldb0 to libldb1 as 1 is the current major version of the library. - Add libldb1 and libtevent0 to baselibs.conf.- Don't call the suse_update_config macro before building lib ldb and tevent.- Update to 3.6.0pre3. + Listen on IPv6 addresses with IPV6_ONLY; (bso#7383). + Fix wrong output in 'smbget'; (bso#8066). + "inherit owner = yes" doesn't interact correctly with vfs_acl_xattr or vfs_acl_tdb module; (bso#8083). + rpccli_samr_chng_pswd_auth_crap segfaults if any input blobs are null; (bso#8088). + setpwent() actually does endpwent() and vice versa on FreeBSD; (bso#8099). + Fix the build of 'smbget' on HP NonStop; (bso#8106). + Fix build of tdb2. + Correctly detect and deny symlinks anywhere in a path (not just the last component) if "follow symlinks = no". + Fix timeout in rpc_pipe_open_tcp_port(). + Fix the build of "--with-profiling-data". + Fix Coverity IDs 986, 1340, 2047, 2299, 2307, 2325, 2335, 2336, 2470, 2471, 2478. + nsswitch: Add 'wbinfo --lookup-sids'. + nsswitch: Add 'wbinfo --sids-to-unix-ids'. + Fix smbd with the async echo responder. + Fix the build of vfs_gpfs.c. + Add a 10-second timeout for the 445 or netbios connection to a DC. + Many pthreadpool fixes. + Fix transaction recovery area for converted tdbs.- Add PreReq permissions to the krb-printing package.- Remove _libdir ldb and tevent from file list. - Explicitly state not to bundle talloc or tdb while ldb and tevent build.- Always use the actual library version as part of the package name. - Exclude shared python modules.- Fix printing from Windows 7 clients; (bso#7567); (bnc#687535).- Update pidl and always compile IDL at build time; (bnc#688810).- Update to 3.6.0pre2. + ID Mapping changes. + Implement SMB2 support. + Add an Endpoint Mapper daemon. + Make "rlimit_max below minimum Windows limit" notification less scary; (bso#6837). + Quota only shown when logged as root; (bso#7080). + Fix printing from Windows 7; (bso#7567). + Retry DNS updates when connection to one nameserver has failed; (bso#7690). + Unlink may unlink wrong file when hardlinks are involved; (bso#7863). + Fix 'nmbd --port'; (bso#7875). + cmd_spoolss_deletedriver() returned without checking all architectures; (bso#7880). + Don't return "-1" on success in 'net rpc vampire keytab'; (bso#7899). + Fix cups pcap reload with no printers; (bso#7915). + Fix bug in chain_reply; (bso#7917). + Fix problems with "kernel oplocks" option set to "no"; (bso#7928). + Fall back for utimes calls; (bso#7940). + Catch lookup_names/sids schannel errors over ncacn_ip_tcp; (bso#7944). + Let winbind try to use samlogon validation level 6; (bso#7945). + Sgid bit lost on folder rename; (bso#7996). + Fix getting username in 'net rap session'; (bso#8009). + Fix inode generation so nautilus can count total dir size correctly; (bso#8010). + Use jenkins hash for str_checksum; (bso#8010). + Add explicit configure option whether or not to enable dmapi support; (bso#8033). + Fix smbclient segfault with Cyrillic netbios names; (bso#8040). + Fix file creation on OS/X; (bso#8042). + Add "--option" to 'testparm'. + Fix crash bug on smbd shutdown when using FOPENDIR(). + Ensure we don't return an incorrect access mask. + Fix bug against the new Mac client. + Fix leak in error path. + Fix error where Windows client spoolss returns WERR_INVALID_DATA. + Fix a segfault in the krb5 locator plugin. + Enable sharesec for registry shares. + Fix memory leak in "security=share" and "force user". + Add "net idmap check", a check and repair tool for the id mapping database. + Add new 'net idmap delete' command. + Fix segfault on missing input file in 'net idmap restore'. + Fix 'net usersidlist' not to skip every other user. + Fix potential crash bug in spoolss_PrinterEnumValues push path. + Internal restructuring. + Don't wipe out all printer drivers when only one should be deleted. + Fix winbindd_dual_pam_auth_samlogon() for NT4 domains. + Fix memory leak in print_cups.c. + Remove duplicate cups response processing code. + Follow force user/group for driver IO. + Initiate pcap reload from parent smbd. + Reload shares after pcap cache fill. + Fix numerous Coverity IDs (2041 and others). + Fix a memory leak in check_sam_security_info3. + Fix a segfault in the nss wrapper when libnss_winbind.so is not loadable. + Make "net sam list [users|workstations]" list only the right things. + Fix a potential memleak in secrets_fetch_trusted_domain_password. + Use the right credentials in check_netlogond_security. + Add support for AF_NETLINK addr notifications. + Fork multiple Winbind children per domain. + Fix a deadlock between smbd and ctdbd. + Add 'wbinfo --dc-info'. + Make "nmbd socket dir" configurable. + Fixed valgrind errors. + Fix a memleak in receive_getdc_response. + Don't grant SEC_STD_DELETE always to the owner of a file. + Fix segfaults on addrchange errors in Winbind. + Allow machine accounts as members in groupdb. + Add IPv6 support for the endpoint mapper. + Free unused memory in the rpc server. + Fix possible segfaults in svcctl server. + Fix possible segfault with client_id in rpc server. + Add a 'svcctl shutdown' function to rpc server. + Fix a resource leak in net_afs. + Fix a resource leak in smbta-util. + Fix possible resource leak in net_usershare. + Fix possible resource leak in 'smbget'. + Fix possible resource leak in 'smbfilter'. + Fix a possible null pointer dereference in smbd. + Ensure we send the direct levelII oplock break to the correct fid. + Fix private libdir and codepages paths. - Add RFC 3454 to the vendor files.- Fix idmap_tdb for big-endian systems such as ppc and s390; (bso#6901); (bnc#675978).- Fix smbclient -M NT_STATUS_PIPE_BROKEN failure; (bso#7635); (bnc#681913).- Replace jobs by _smp_mflags macro while calling make on post-11.4 systems.- Don't crash when publishing a single printer; (bnc#643119).- Carry error status in printer list IPC message, do not refresh printers if cups is unavailable; (bso#7994); (bnc#675478).- Define the libwbclient packages ahead of packages with a different version.- Use %_smp_mflags for parallel building.- Update to 3.5.8. + Fix Winbind crash bug when no DC is available; (bso#7730). + Fix finding users on domain members; (bso#7743). + Fix memory leaks in Winbind; (bso#7879). + Fix printing with Windows 7 clients; (bso#7567). + Fix 'testparm' return code when EOF in encountered in param name; (bso#3185). + Make "rlimit_max below minimum Windows limit" notification less scary; (bso#6837). + Fix "Your Password expires today" message for users of trusted domains; (bso#7066). + Fix maintaining of users' groups via UsrMgr; (bso#7262). + Fix 'net ads dns register' in Windows 2008 R2 domains; (bso#7356). + Raise debug level for "reduce_name: couldn't get realpath" messages; (bso#7409). + Fix updating the time on close in vfs_gpfs; (bso#7498). + Fix "log=>ndr_pull_error" in 'wbinfo -u' and 'wbinfo -g'; (bso#7594). + Handle Windows 9x adddriver calls without config file; (bso#7641). + Fix scalability problem with hundreds of printers; (bso#7656). + Fix memory leak in the netapi routines; (bso#7665). + Store unmodified copies of security descriptors in acl_xattr and acl_tdb modules; (bso#7716). + Fix incorrect unix mode_t caused by invalid client DOS attributes on create; (bso#7733). + Apply appropriate create masks when creating files with "inherit ACLs" set to true; (bso#7734). + Fix "dfree cache time" parameter; (bso#7744). + Fix a getgrent crash with many groups; (bso#7774). + Fix requesting lookups for BUILTIN sids; (bso#7777). + Fix smbd crash caused by expand_msdfs; (bso#7779). + Fix atime limit; (bso#7785). + vfs_scannedonly: Switch from mtime to ctime which is more reliable; (bso#7789). + Fix copying files from a SMB share using Gnome vfs and SMB signing; (bso#7791). + Make Winbind recover from a signing error; (bso#7800). + ACL inheritance cannot be disabled in vfs_acl_xattr/vfs_acl_tdb; (bso#7812). + Fix "force group" with ntlmssp guest session setup; (bso#7817). + vfs_fill_sparse() doesn't use posix_fallocate when strict allocate is on; (bso#7835). + Make WINBINDD_LOOKUPRIDS asking the right domain; (bso#7841). + Make WINBINDD_LOOKUPRIDS returning the domain name; (bso#7842). + Expand the local SAMs aliases; (bso#7843). + ntlm_auth: Support clients which offer a spnego mechs we don't support; (bso#7855). + Fix 'net ads dns register' in cluster setups; (bso#7871). + Fix 'nmbd --port'; (bso#7875). + Make 'rpcclient deldriver' delete drivers for all architectures; (bso#7880). + Fix flaky Winbind against Windows 2008; (bso#7881). + Fix SMB session setups with Kerberos against some closed source SMB servers; (bso#7883). + Fix stale lock in open_file_fchmod(); (bso#7892). + Fix sporadic Winbind panic in rpc query_user_list; (bso#7894). + Don't set SAMR_FIELD_FULL_NAME if we just want to set the account name; (bso#7896). + Don't return "-1" on success in 'net rpc vampire keytab'; (bso#7899). + Fix connections from WinCE; (bso#7917). + Fix opening MS Powerpoint files; (bso#7940). + Fix endless loops caused by inotify; (bso#7942). + Catch lookup_names/sids schannel errors over ncacn_ip_tcp; (bso#7944). + Let Winbind try to use samlogon validation level 6; (bso#7945). + Revalidate the pathname once re-constructed from a root fsp; (bso#7950).- Require a particular library version even if the major version is part of the package name. Using the same major version does not guarantee forward compatibility.- Fix a fd-leak in libwbclient at dlclose-time; (bso#7684); (bnc#668773).- Update to 3.5.7 + Protect against possible denial of service caused by memory corruption; CVE-2011-0719; (bso#7949); (bnc#670431).- Disable separate build of samba-doc for post-11.1 systems.- Protect against possible denial of service caused by memory corruption; CVE-2011-0719; (bso#7949); (bnc#670431).- Increase the log level for missing PIDs on SIGCHLD, printcap child processes are not added to the children PID list; (bnc#666460).- Do not require a particular library version if the major version is part of the package name.- Use the actual version numbers of the ldb, talloc, tdb, and tevent libraries on post-11.3 systems.- Abide by print$ share 'force user' & 'force group' settings when handling AddprinterDriver and DeletePrinterDriver requests; (bso#7921); (bnc#653353).- Remove pcap_cache_loaded asserts from (re)load_printers. pcap_cache_loaded() returns false if the pcap cache contains no printer entries. correct call ordering is already enforced. (bso#7836); (bnc#625936).- No longer force activation of the cifs service on post-11.3 systems. - Add X-UnitedLinux-Default-Enabled to the cifs init script on pre-11.4 systems. - Move the cifs init script nfs dependencies from Required to Should.- Recommend to install samba-krb-printing from samba-winbind on post-10.3 systems; (bnc#661845).- Fix error paths in cups_async_callback(), an empty cups printer list should not be treated as an error; (bnc#661842).- Abide by printcap cache time, reload parent smbd pcap cache on expiry; (bso#7836); (bnc#625936).- Fix race in cups async printer services reload; (bso#7836); (bnc#625936).- Don't tweak with baselibs.conf during %post if not present; (bnc#652620).- Don't make use of baselibs.conf on SUSE Linux Enterprise 10; (bnc#652620).- Don't use --tmpdir as this option isn't known by mktemp of SUSE Linux Enterprise 10; (bnc#652620).- vfs_fill_sparse() doesn't use posix_fallocate when strict allocate is on; (bso#7835).- Replace Requires samba-client by samba-gplv3-client in the gplv3 packages; (bnc#652620).- Fix Dolphin SMB share IO with SMB signing enabled; (bso#7791); (bnc#656112).- Add Conflicts to the samba-gplv3 main, client, doc, krb-printing, winbind, client-gplv2, and doc-gplv2 packages; (bnc#652620).- Add Provides samba-client-gplv2 and samba-doc-gplv2 to pre-3.2 versions; (bnc#652620).- Obsolete samba-client-gplv2 and samba-doc-gplv2; (bnc#652620).- Remove Provides samba-client:/usr/sbin/winbindd from the samba-gplv3-winbind package to avoide an accidental install trigger; (bnc#652620).- Add Provides samba-client to the samba-gplv3-client package; (bnc#652620).- Remove all Obsoletes from the samba-gplv3 packages and only keep the Provides samba; (bnc#652620).- Add fitting Conflicts to all samba-gplv3 packages; (bnc#652620).- Reduce unnecessary ldap round trips and eliminate invalid DN messages; (bnc#654719).- Exclude cifs-mount and ldapsmb from the samba-gplv3 build of SUSE Linux Enterprise 10 SP 3 and 4.- Add the _build_arch at the end of the vendor version suffix.- Provide and Obsolete samba-gplv3 to replace potentially installed packages.- Change package base name to samba-gplv3 for SUSE Linux Enterprise 10 SP 4. - Do not package libsmbclient and libsmbsharemodes.- Update to 3.5.6 + Fix auto printers with registry config; (bso#7280); (bnc#617153). + Fix SPNEGO auth when contacting Win7 system using Microsoft Live Sign-in Assistant; (bso#7577). + Fix 'net idmap restore' setting HWM to avoid duplicates; (bso#7578). + Fix "admin users" when using vfs_acl_xattr; (bso#7581). + Fix using cached credentials in ntlm_auth; (bso#7589). + Fix Winbind offline login; (bso#7590). + Fix Winbind internal error; (bso#7636). + Fix mknod/mkfifo failing with "No such file or directory"; (bso#7651). + Fix smbd changing mode of files on rename; (bso#7693). + Fix crash bug with invalid SPNEGO token; (bso#7694). + Fix smbd panic on invalid NetBIOS session request; (bso#7698). + Fix smbd crash caused by "%D" in "printer admin"; (bso#7541). + Fix 'smbclient -M'; (bso#7635). + Fix scalability problem with hundreds of printers; (bso#7656). + Fix crash bug in rpcclient; (bso#7688). + Fix file corruption when setting Samba "write wache wize"; (bso#7715).- Let startproc wait for nmb, smb and winbind pid files getting created on post-11.1 systems; (bnc#520036).- Include the reviewed french translation for pam_winbind; (bnc#499233).- Fix smbd crash with CUPS printers and no [printers] share defined; (bso#7297); (bnc#637755).- Fix printing from 64-bit windows clients; (bso#6888); (bnc#640870).- Fix baselibs.conf for libtalloc.- Fix buffer overflow in sid_parse() to correctly check the input lengths when reading a binary representation of a Windows Security ID (SID); CVE-2010-3069; (bso#7669); (bnc#637218).- Use cached ntlm password in libsmbclient. Prevent lockouts when kerberos tickets are lost; (bnc#602418); (bnc#606304).- Add a dependency on nfs to the smbfs/ cifs init scripts as they require the en_US locale and /usr might be on NFS.- Complete fix for trusts with Windows 2008R2 DCs.- Fix authentication dialogs when connecting to older systems; (bnc#632055).- Adjust position of conditional ldapsmb %package and %files definition.- Create the /var/run/samba directory on the fly and package it as %ghost.- Fix preexec scripts; (bso#7104); (bnc#632852).- Add missing netapi, smbclient, smbsharemodes, talloc, tevent, and wbclient pkgconfig files and BuildRequire pkgconfig; (bnc#632770).- BuildRequire python-devel for post-9.3 systems.- Only create precompiled headers for post-10.2 systems. - Remove mkinitrd scriptlets.- Add vfs_crossrename man page. - Call make basic and remove conditional proto target. - Increase libtevent version to 0.9.9. - Remove wbc_async header from the file list. - Remove remaining cifs-mount pieces from the spec file.- Fix printers not auto loading with registry config; (bso#7280); (bnc#617153).- Update to 3.6.0pre1. + SMB2 support is fully functional despite managing quota using the Microsoft management tools. + Internal Winbind passdb changes to use samr and lsa rpc pipe to get local user and group information. + The spoolss and the old RAP printing code have been completely overhauled and refactored. + The SMB Traffic Analyzer (SMBTA) VFS module got added.- Intilize workgroup of nmblookup as empty string.- Fix net ads join when using parent domain users; (bso#6364); (bnc#630812).- cifs: do not restart during dhcp lease renewal when IPaddress remains the same; (bnc#573246).- Fix "Too many open files" when trying to access large number of files; (bso#6837); (bnc#619787).- Update to 3.5.4. + Fix smbd crash when sambaLMPassword and sambaNTPassword entries missing from ldap (bug #7448). + Fix init_sam_from_ldap storing group in sid2uid cache (bug #7507). + Allow previous password to be stored and use it to check tickets; (bso#7099). + Make ea data checks identical for trans2open and trans2mkdir; (bso#7188). + Fix editing users' groups via UsrMgr; (bso#7262). + Fix Winbind over IPv6; (bso#7341). + Samba sends "raw" inode number as uniqueid with unix extensions; (bso#7410). + Fix printing large formats; (bso#7423). + Fix spnego returning incorrect mechListMIC string; (bso#7449). + Fix some crash bugs and missing error codes in AddDriver paths; (bso#7459). + Fix crash bug in _samr_QueryUserInfo{2} level 18; (bso#7479). + Fix 'not a string literal' warning in netdomjoin-gui; (bso#7500). + Fix calculation of st_blocks in vfs_streams_xattr; (bso#7503). + Fix numerous build issues; (bso#7504). + Fix session setup from linux kernel cifs clients with "sec=ntlmv2"; (bso#7517).- Remove all provides and obsoletes samba3 from the spec file. Packages with this base name have not been offered as part of a product.- Fix a NULL pointer dereference in smbd of the 3.4 code base; CVE-2010-1635; (bso#7229); (bnc#605935).- Address possible buffer overrun in chain_reply code of pre-3.4 versions; CVE-2010-2063; (bso#7494); (bnc#611927).- Update of the SMB Traffic Analyzer v2 VFS module- Fix trusts with Windows 2008R2 DCs; (bnc#613459); (bnc#599873); (bnc#592198); (bso#6697).- Update to 3.5.3. + Fix MS-DFS functionality; (bso#7339). + Fix a Winbind crash when scanning trusts; (bso#7389). + Fix problems with SIGCHLD handling in Winbind; (bso#7317). + Add replacement for IPV6_V6ONLY on linux systems with broken headers; (bso#7196). + Fix cups encryption setting; (bso#7263). + Fix exporting printers via 'cupsaddsmb' command; (bso#7277). + Fix SMB job IDs in CUPS job names; (bso#7288). + Fix segfault in mount.cifs; (bso#7315). + Make TIME_T_MAX defines consistent; (bso#7352). + Re-fix a bug with smbd serving a windows terminal server; (bso#7357). + Display an error on 'net conf import' failures; (bso#7378). + Fix bitmap leak in dptr_Close; (bso#7384). + Fix rename problems with full_audit VFS module; (bso#7398). + Fix setting of passwords via 'net rpc user password' command; (bso#7417). + Fix 'net rpc printer list' command; (bso#7418). + Rename mod_name to module_name; (bso#7421). - Fix unnecessary traversing winbindd_cache.tdb in SIGHUP handler. - Added EN ISO 216, A0 and A1 to builtin forms; (bso#7423). - Winbind not working over IPv6; (bso#7341).- Honor "interfaces" list in net ad dns register; (bnc#606947).- Exclude the RPM release from the vendor tag for openSUSE Factory; (bnc#604049).- Enable the build of the idmap tdb2 module; (bnc#600822).- BuildRequire keyutils-libs-devel for Fedora and post-RHEL4.- BuildRequire pkg-config for post-10.2 systems and else pkgconfig.- Add "net conf import" error messages; (bso#7378, bnc#598189).- Define cups_lib_dir %{_prefix}/lib/cups for post-11.2 systems; (bnc#575544).- Update to 3.5.2. + Fix smbd segfaults in _netr_SamLogon for clients sending null domain; (bso#7237). + Fix smbd segfaults in "waiting for connections" message; (bso#7251). + Fix an uninitialized variable read in smbd; (bso#7254); (bnc#605935); CVE-2010-1642. + Fix a memleak in Winbind; (bso#7278). + Fix Winbind reconnection to it's own domain; (bso#7295). + Fix segfault if hide files or veto files has no ".AppleDouble"; (bso#1206). + Fix parsing of the gecos field; (bso#5198). + Fix several printing issues; (bso#6727). + Fix valgrind warning; (bso#6814). + Fix race condition in mount.cifs that allows user to replace mountpoint with a symlink; (bso#6853). + Fix bug in vfs_scannedonly rmdir implementation; (bso#7075). + Fix handling of bad server data returns in client rpc_transport; (bso#7159). + Never mark external domains as internal in Winbind; (bso#7170). + Fix access by multi-threaded applications; (bso#7202). + Fix 'net share' command; (bso#7203). + Fix DN parsing name was always null; (bso#7204). + Signals are processed twice in child; (bso#7206). + Fix returning of group members with 'getent group'; (bso#7212). + Fix the build of net_afs.c with --fake-kaserver=yes; (bso#7216). + Make Winbind logs more verbose for troubleshooting; (bso#7225). + Fix a NULL pointer dereference in smbd; CVE-2010-1635; (bso#7229); (bnc#605935). + Fix automatic building of vfs_tsmsm if gpfs and dmapi are present; (bso#7231). + Fix race conditions in CTDB persistent transactions; (bso#7232). + Symlink delete fails but incorrectly reports success to client; (bso#7234). + Fix "printer admin" functionality; (bso#7255). + Fix value-needed calculation in_spoolss_EnumPrinterData(); (bso#7256). + Fix _winreg_QueryValue crash bugs and implement Windows behavior; (bso#7258). + Fix job management commands for CUPS queues; (bso#7269). + Fix smbd segfault if using vfs_acl_tdb; (bso#7283). + Fix core dump in 'ntlm_auth' with "gss-spnego" helper; (bso#7290). + Fix smbd crashes with CUPS printers and no [printers] share defined; (bso#7297). + Fix DOS attribute inconsistency with MS Office; (bso#7310). + Many disconnecting clients render clustered Samba unusuable for some time; (bso#7312). + Make 'net conf addshare' atomic; (bso#7313). + Eliminate race condition in creating/scanning sorted subkeys in the registry backend; (bso#7314). + Winbind possibly segfaults when trying a trusted domain without inbound trust; (bso#7316).- Add SMB Traffic Analyzer v2 VFS module.- Document "wide links" defaults to "no" in the smb.conf man page for versions pre-3.4.6; (bnc#577868).- Fix workgroup enumeration, for client printer and file share selection; (bso#6880); (bnc#586215).- Fix tdb validation for offline auth; (bnc#587014).- Fix "printer admin" functionality; (bso#7255).- An uninitialized variable read could cause an smbd crash; (bso#7254); (bnc#605935); CVE-2010-1642.- Ensure to have a valid talloc stackframe; (bso#7251).- _netr_SamLogon segfaults for clients sending NULL domain; (bso#7237).- Merge missing pam_winbind message translations; (bnc#499233).- Remove cifs-mount subpackage for post-11.2 systems as the tools are now part of the independent cifs-utils package.- Fix join of Windows 2008 domains; (bnc#567013).- Update to 3.5.1 and 3.4.7. + Fix security flaw on Linux platforms if built with libcap support allowing file system access even when permissions should have denied it; CVE-2010-0728; (bso#7222); (bnc#586683).- Fixed libldb.so link in libldb-devel.- Fix argc handling in net_share, making the command "net share" work again; (bso#7203); (bnc#584253).- Update to 3.5.0. + Fix duplicate sam and unix accounts; (bso#7145). + Keep the the correct negotiate_flags on the cli->dc structure; (bso#7160). + Avoid calling cli_alloc_mid twice in cli_smb_req_iov_send; (bso#7166). + Fix 'net ads dns' usage calls; (bso#7181). + Fix uninitialized variable in wkssvc_enumerateusers; (bso#7182).- Update to 3.4.6. + Change parameter "wide links" to default to "no"; it's also incompatible with "unix extensions"; (bso#7104); (bnc#577868). + Fix printing with 64 bit clients (bso#6888). + Fix core dump on 64 bit Linux (bso#7063). + Fix failing of smbd to respond to a read or a write caused by Linux asynchronous IO (aio) (bso#7067). + Fix string buffer overflow causing heap corruption in smbd (bso#7096). + Fix bogus ip address in SWAT; (bso#5885). + Fix vfs_full_audit; (bso#6557). + Use the first "uid" value; (bso#6157). + Fix large paged search with DirX LDAP servers; (bso#6981). + Fix crash bug in 'cifs.upcall'; (bso#6868). + Add cross option to samba_cv_linux_getgrouplist_ok; (bso#7047). + Fix DFS on AIX (maybe others); (bso#7052). + Fix pdb_search crash as non-root user; (bso#7068). + Fix unlocking of accounts from ldap; (bso#7072). + Fix vfs_expand_msdfs; (bso#7081). + Fix results of 'smbclient -L' with a large browse list; (bso#7098). + Normalize "Changing password for" msg IDs and STRs; (bso#7102). + Fix malformed require_membership_of_sid; (bso#7106). + Fix reading of large browselist; (bso#7122). + "mangling method = hash" can crash storing a name containing a '.'; (bso#7154). + Valgrind Conditional jump or move depends on uninitialised value(s) error when "mangling method = hash"; (bso#7155). + Fix listing of printjobs in Windows 7; (bso#7130). + Spoolss getprinterdriver2 level 101 marshalling is bad; (bso#7136). + Make idmap cache persistent for "ldapsam:trusted". + Also fill the memcache with sid<->id mappings in ldapsam_sid_to_id() not only the persistent idmap cache. + Shortcut uid_to_sid when "ldapsam:trusted = yes". + Make pdb_copy_sam_account also copy the group sid. + Shortcut gid_to_sid when "ldapsam:trusted = yes". + Speed up pdb_get_group_sid(). + Try to build the full unix_pw structure with ldapsam:trusted support. + Optimize ldapsam_alias_memberships() and cache ldap searches.- Update to 3.5.0rc3. + Change parameter "wide links" to default to "no"; it's also incompatible with "unix extensions"; (bso#7104); (bnc#577868). + Fix vfs_full_audit; (bso#6557). + Fix crash bug in 'cifs.upcall'; (bso#6868). + Fix duplicate initializer in the rmdir module; (bso#6876). + Fix printing with 64 bit clients; (bso#6888). + Add cross option to samba_cv_linux_getgrouplist_ok; (bso#7047). + Fix core dump on Ubuntu 8.04 64 bit; (bso#7063). + Fix failing of smbd to respond to a read or a write caused by Linux asynchronous IO (aio); (bso#7067). + Fix 'smbget' error status; (bso#7069). + Fix build of 'smbfilter'; (bso#7071). + Fix unlocking of accounts from ldap; (bso#7072). + Cliconnect gets realm wrong with trusted domains; (bso#7079). + Fix vfs_expand_msdfs; (bso#7081). + Fix storing of create time on directories in an EA in new create time code; (bso#7084). + Fix an early release of the global lock that can cause data corruption in libtdb; (bso#7085). + Fix string buffer overflow causing heap corruption in smbd; (bso#7096). + Fix results of 'smbclient -L' with a large browse list; (bso#7098). + Normalize "Changing password for" msg IDs and STRs; (bso#7102). + Fix malformed require_membership_of_sid; (bso#7106). + Add pdb_ldap performance fixes; (bso#7116). + Change ldap filter to what really was intended; (bso#7116). + Add new "nmbd bind explicit broadcast" parameter; (bso#7118). + Fix nmbd problems with socket address; (bso#7118). + Support large browselist; (bso#7119). + Fix reading of large browselist; (bso#7122). + Fix listing of printjobs in Windows 7; (bso#7130). + Owner of file not available with Kerberos; (bso#7139). + Fix IPv4/IPv6 problems; (bso#7140). + Fix get_acl_blob in the acl_tdb VFS module; (bso#7148). + "mangling method = hash" can crash storing a name containing a '.'; (bso#7154). + Valgrind Conditional jump or move depends on uninitialised value(s) error when "mangling method = hash"; (bso#7155). + Fix some wrong newlines in de translation strings.- Take extra care that a mount point of mount.cifs isn't changed during mount and don't allow it to be run as setuid root program; CVE-2010-0787; (bso#6853); (bnc#550002).- Check in mount.cifs for invalid characters in device name and mountpoint; CVE-2010-0547; (brc#562156); (bnc#577925).- Don't invalidate cache for uninitialized domains; (bnc#538923).- Signals are processed twice in child; (bnc#538923).- Allow forced pw change even with min pw age; (bnc#561894).- Change parameter "wide links" to default to "no"; it's also incompatible with "unix extensions"; CVE-2010-0926; (bso#7104); (bnc#577868).- Fix enumerate domain local groups for primary domain; (bnc#573813).- Fix malformed require_membership_of_sid; (bnc#525123); (bso#7106).- Normalize "Changing password for" msg IDs and STRs; (bnc#499233).- Build libtevent and libldb and put them into separate subpackages.- Update to 3.5.0rc2. + The Using Samba HTML book has been removed. + 'net', 'smbclient' and libsmbclient can use logon credentials cached by Winbind; (bso#7062). + New vfs_scannedonly module has been added; (bso#7028). + Check password history before increasing "badPasswordCount"; (bso#4347). + Fix changing of ACLs on writable file with "dos filemode=yes"; (bso#5202). + Restore Samba 3.0.x behavior and use the first "uid" value in pdb_ldap; (bso#6157). + Fix deletion of an object whose parent folder does not have delete rights fails even if the delete right is set on the object in vfs_acl_xattr and vfs_acl_tdb; (bso#6876). + Fix large paged search with DirX LDAP servers; (bso#6981). + Fix a segfault in winbindd_dual_ccache_ntlm_auth(); (bso#7027). + Disable sanity check in NetShareEnum for better compatibility with Windows; (bso#7029). + Fix SMBrmdir error message when deleting a directory fails; (bso#7033). + Fix segfault in vfs_cap; (bso#7034). + Fix 'net rpc getsid' in hardened Windows environments; (bso#7036). + Fix a Winbind segfault in "trusted_domains"; (bso#7037). + Complete and improve some German translation of 'net'; (bso#7039). + Fix compile error with WITH_DNS_UPDATE. Update .po files; (bso#7039). + Fix crash bug in libsmbclient; (bso#7043). + Fix bad (non memory copying) interfaces in smbc_setXXXX calls; (bso#7045). + Fix libsmbclient crash against OpenSolaris CIFS server; (bso#7046). + Lock down some srvsvc calls according to what w2k3 seems to do.- Update to 3.4.5. + Fix memory leak in smbd (bug #7020). + Fix changing of ACLs on writable files with "dos filemode=yes" (bug #5202). + BUG 6642: Fix opening the quota magic file. + BUG 6919: Fix remote quota management. + BUG 7034: Fix internal error caused by vfs_cap. + BUG 7036: Fix 'net rpc getsid' in hardened Windows environments. + BUG 7043: Fix crash bug in "SMBC_parse_path". + BUG 7045: Fix bad (non memory copying) interfaces in smbc_setXXXX calls. + BUG 7046: Fix a crash in libsmbclient used against the OpenSolaris CIFS server.- Free unused memory after a packet got processed; (bso#7020).- Add timeout to rpc call to prevent infinite loop when network is down; (bnc#538923).- Update to 3.5.0rc1. + BUG 6837: Fix "Too many open files" when trying to access large number of files with Windows 7; (bnc#619787). + BUG 6939: Fix long filenames when "mangling method" is set to "hash". + BUG 6991: Create symbol links to shared libraries. + BUG 6992: make test for getgrouplist cacheable. + BUG 7014: Fix Winbind crash when retrieving empty group members. + BUG 7020: Fix smbd using 2G memory. + Ensure dos_mode can return FILE_ATTRIBUTE_NORMAL, then filter the returned attributes by protocol level. + Vector correctly through reply_openerror() (which uses the same logic). + Fix bugs with the full Windows ACL support. + Add a few missing gettext calls to the 'net' command. + Fix up a share type translation and translate some more strings in 'net'. + Allow to call "pdbedit -N description -u user" without specifiyng "-r". + Add spoolss_DriverInfo7. + Fix rpcclient after setprinter IDL fixes. + Use generated krb5.conf in 'net ads testjoin'. + Add some German translations for the 'net' command. + Update mount.cifs man page with nounix option. + Fix _samr_GetAliasMembership for results with 0 rids. + Fix an error case in cli_negprot. + Add a lower-cost alternative to wbinfo -t: wbinfo --ping-dc. + Restore correct timeouts for SMB requests. + Fix a 64-bit error in libsmb. + Replace IS_DOMAIN_OFFLINE by a function in Winbind. + Simplify/cleanup Winbind code. + Fix write behind memory block in libtalloc. + Fix result check for getaddrinfo(). + Add tsocket_address_bsd_sockaddr() and tsocket_address_bsd_from_sockaddr() to tsocket. + Always set tdb->tracefd to -1 to be safe on goto fail in libtdb. + Add TDB_DISALLOW_NESTING and make TDB_ALLOW_NESTING the default behavior. + Fix standalone 'make installdocs'. + Output %p as unsigned in snprintf replacement. + New attempt at TDB transaction nesting allow/disallow. + Remove swig stuff from libtdb. + Reset tdb->fd to -1 in tdb_close() in libtdb. + Change the way mksysms work in libtalloc. + Also build and install tdb manpages from standalone tdb. + Fix infinite loop in NCACN_IP_TCP as there is no timeout. + Make winbindd_cache.c aware of domain offline to avoid unnecessary backend query. + List trusted domains from wcache when domain is offline.- Update to 3.4.4. + Fix interdomain trust relationships with Win2008R2 (bug #6697). + Fix Winbind crashes when queried from nss (bug #6889). + Fix Winbind crash when retrieving empty group members (bug #7014). + Fix "UID range full" error in Winbind (bug #6901). + Fix multiple LDAP servers in "idmap backend" and "idmap alloc backend" (bug #6910). + BUG 4832: Fix iconv checks. + BUG 6338: Do not always display "none" in 'net rpc trustdom list'. + BUG 6851: Add pdbedit --kickoff-time/-K to set the user's kickoff time. + BUG 6828: Fix infinite timeout when byte lock held outside of samba. + BUG 6837: Fix "Too many open files" message when trying to access a large number of files with Windows 7; (bnc#619787). + BUG 6841: Fix "map acl inherit = yes". + BUG 6850: Fix shadow copy display on Windows 7. + BUG 6867: Fix listing of directories with a lot of files. + BUG 6868: Support building with Heimdal we well as with MIT. + BUG 6875: Fix DOS attributes on OS/2 clients. + BUG 6880: Fix listing of workgroup servers in libsmbclient. + BUG 6898: Samba duplicates file content on appending. + BUG 6918: Fix krb5 build problem on Ubuntu karmic. + BUG 6929: Fix build with recent heimdal. + BUG 6939: Fix long filenames with "mangling method = hash". + BUG 6967: Fix 'net ads join' with OU. + BUG 6981: Fix paged search with DirX LDAP server. + BUG 6982: Remove erroneous out of memory error path in lookup_sid. + BUG 6997: Fix _samr_GetAliasMembership for results with 0 rids. + BUG 7005: Fix "mangle method = hash" truncates files with dot "." character. + Fix the build of the winbind krb5 locator plugin. + Fix enumprinter key client and server.- Readjust the _libdir/cups/backend/smb sym link only on uninstall of the samba-krb-printing package; (bnc#568603).- Add BuildRequires to fam-devel; (bnc#564260).- Prevent winbind crash; (bso#7014); (bnc#566119).- Fix processing of open modes in POSIX open; (bnc#530683).- Add baselibs.conf as a source.- Update to 3.5.0pre2. + BUG 2350: Add LDAP Alias Dereferencing support. + BUG 6288: SWAT adds a second share when changing parameters of an existing share. + BUG 6435: Fix minor memory corruption. + BUG 6710: Only install the cifs.upcall man page if CIFSUPCALL_PROGS was set while configure. + BUG 6802: A created folder does not properly inherit permissions from parent in vfs_acl_xattr. + BUG 6837: "Too many open files" when trying to access large number of files from Windows 7; (bnc#619787). + BUG 6860: Fix shared library build on QNX. + BUG 6879: Fix crash in Winbind. + BUG 6929: Fix build with recent heimdal. + BUG 6938 : No hook exists to check creation rights when using acl_xattr module. + BUG 6967: Prevent glibc error on 'net ads join'. + Fix vfs_acl_xattr which was failing to call the NEXT connect function. + Restructure the ACL code. + Refactor reply_rmdir to use handle based code. + Fix the build when no external talloc and tdb are installed. + Fix detection of CTDB headers on systems without system-libtalloc. + Fix several printing issues. + Fix the build on Mac OS X 10.6.2. + Fix net and rpcclient after setprinterdataex changes. + Add full support for level 8 printer drivers. + Add more spoolss architectures to IDL. + Fix enumprinter key client and server. + Fix crash in EnumPrinterDataEx. + Prefer posix_fallocate for doing "strict allocate". + Restore "fake directory create times" as a share parameter. + Fix explicit stat64 support. + Add support for NetWkstaGetInfo 101 and 102. + Add rpcclient wkssvc_enumerateusers. + De-deprecate "write cache size" to prevent its removal without a proper alternative. + Allow more than 1000 users in BUILTIN\Users. + Complete support for NetWkstaGetInfo/NetWkstaEnumUsers. + Fix the build of the example VFS modules. + Fix crash in free_file_list(). + Give the user a chance to change password when password will expire soon.- Store the smbfs service state if enabled and restore it for cifs while upgrade on post-11.2 systems.- Prevent cifstab from being overwritten while upgrade on post-11.2 systems.- Give the user a chance to change password when password will expire soon; (FATE#302414).- Rename smbfs init script to cifs for post-11.2 systems.- Allow Windows 7 to connection to samba domain controllers and member servers; (bnc#551811); (bso#6099); (bso#6100); (bso#6680).- Error on joining windows domain (invalid pointer); (bso#6967); (bnc#553622).- Add PreReq /usr/sbin/groupadd to the winbind package; (bnc#559165). - Simplify the winbind package %pre script and suppress stdout only.- Update to 3.5.0pre1 + Add support for full Windows timestamp resolution. + Experimental implementation of SMB2. + Add encryption support for connections to a CUPS server. + Major windbind asynchronous refactoring. - Remove using_samba from the doc package. - Increase major version of libtalloc to 2.- Fix kerberos refresh chain; (bnc#546162); (bso#6872).- Hardlink duplicate files on post-11.1 systems.- Add BuildArch noarch to samba-doc on post-11.1 systems.- Use full 16byte session key in make_user_info_netlogon_interactive(); (bnc#551811).- Update to 3.4.3. + Fix trust relationships to windows 2008 (2008 r2) (bug #6711). + Fix file corruption using smbclient with NT4 server (bug #6606). + Fix Windows 7 share access (which defaults to NTLMv2) (bug #6680). + BUG 4675: mount.cifs: Do not attempt to update /etc/mtab if it is a symbolic link. + BUG 6529: Offline files conflict with Vista and Office 2003. + BUG 6532: Fix domain enumeration if master browser has space in name. + BUG 6606: Fix file corruption using smbclient with NT4 server. + BUG 6690: Fix wrong error check in profile. + BUG 6703: Allow smbstatus as non-root. + BUG 6704: Fix syntax error in avahi configure test. + BUG 6707: Fix an occasional segfault in config file parsing. + BUG 6710: Adjust regex to match variable names including underscores. + BUG 6711: Fix trust relationships to windows 2008 (2008 r2). + BUG 6726: SIVAL should have been an SVAL. + BUG 6728: BSD needs sys/sysctl.h included to build properly. + BUG 6731: Fix reading beyond the end of a named stream in xattr_streams. + BUG 6735: Don't overwrite password in pam_winbind, subsequent pam modules might use the old password and new password. + BUG 6764: Fix timeval calculation. + BUG 6765: Add a "hidden" parameter "share:fake_fscaps". + BUG 6769: Fix symlink unlink. + BUG 6772: Allow outstanding_aio_calls to be decremented. + BUG 6774: smbd crashes if "aio write behind" is set. + BUG 6776: Fix core dump caused by running overlapping Byte Lock test. + BUG 6781: Fix renaming subfolders in Explorer view. + BUG 6791: Fix linking order in cifs.upcall. + BUG 6793: Fix Winbind crash with "INTERNAL ERROR: Signal 6". + BUG 6793: Fix segfault in winbindd_pam_auth. + BUG 6796: Deleting an event context on shutdown can cause smbd to crash. + BUG 6797: Fix a memleak in libwbclient. + BUG 6804: Fix hpux compiler issue. + BUG 6805: Correctly handle aio_error() and errno. + BUG 6807: Fix a segfault in "net rpc trustdom list" for long domain names. + BUG 6810: Add support for finding alternate credcaches to cifs.upcall. + BUG 6811: Fix reference to freed memory in pam_winbind. + BUG 6815: Fix Windows 2008 R2 SPNEGO negTokenTarg parsing failure. + BUG 6824: Fix avahi activation. + BUG 6826: Don't fail authentication when one or some group of require-membership-of is invalid. + BUG 6828: Fix infinite timeout when byte lock held outside of Samba. + BUG 6829: Fix displaying of multibyte characters in smbclient. + BUG 6840: Fix crash in pam_winbind. + Fix an uninitialized variable. + Only ever handle one event after a select call. + Conditional install of the cifs.upcall man page. + Fix warning occuring when building the manpages.- Let smbclient show special characters properly; (bso#6829); (bnc#544204).- Don't fail authentication when one or some group of require-membership-of is invalid; (bnc#525123); (bso#6826).- Allow winbind to ignore certain domains; (bnc#539506).- Update to 3.4.2. + Fix unresolved home path; CVE-2009-2813; (bso#6763); (bnc#539517). + Fix potential denial of service; CVE-2009-2906; (bso#6768); (bnc#543115). + Fix potential mount.cifs password leaks; CVE-2009-2948; (bnc#542150).- Fix potential denial of service; CVE-2009-2906; (bnc#543115).- Fix potential mount.cifs password leaks; CVE-2009-2948; (bnc#542150).- Fix unresolved home path; CVE-2009-2813; (bnc#539517).- Don't overwrite password in pam_winbind; (bnc#515444).- mods for winbind (when used with squid - ntlm_auth) o winbind adds group 'winbind' o permission 0750,root,winbind LOCKDIR/winbindd_privileged- Merge two fixes from 3.2.8 and 3.3.1. + Adjust regex to match variable names including underscores. + Conditional install of the cifs.upcall man page.- Remove supplements from baselibs.conf while %clean for pre-11.1 systems; (bnc#520579).- Update to 3.4.1. + Fix authentication on member servers without Winbind (bug #6650). + Nautilus fails to copy files from an SMB share (bug #6649). + Fix connections of Win98 clients (bug #6551). + Fix interdomain trusts with Windows 2008 R2 DCs (bug #6697). + Fix Winbind authentication issue (bug #6646). + BUG 5879: Update LDAP schema for Netscape DS 5. + BUG 5886: Fix password change propagation with ldapsam. + BUG 6105: Make linking of cifs.upcall and rpcclient --as-needed safe. + BUG 6222: Default to DRSUAPI replication for net rpc vampire keytab. + BUG 6437: Make open_udp_socket() IPv6 clean. + BUG 6496: MS-DFS cannot follow multibyte char link name in libsmbclient. + BUG 6506: Smbd server doesn't set EAs when a file is overwritten in NT_TRANSACT_CREATE. + BUG 6532: Fix the build with external talloc. + BUG 6538: Cancel all locks that are made before the first failure. + BUG 6560: Fix lookupname. + BUG 6564: SetPrinter fails (panics) as non root. + BUG 6568: Fix _spoolss_GetPrintProcessorDirectory() implementation. + BUG 6585: Fix unqualified "net join". + BUG 6593: Correctly implement SMB_INFO_STANDARD setfileinfo. + BUG 6601: Avoid global fd limits. + BUG 6607: Fix crash bug in spoolss_addprinterex_level_2. + BUG 6611: Fix a valgrind error in chain_reply. + BUG 6615: Fix browsing of DFS when using kerberos in libsmbclient. + BUG 6627: Raise the timeout for lsa_Lookup*() calls from 10 to 35 seconds. + BUG 6650: Fix authentication on member servers without Winbind. + BUG 6651: Fix smbd SIGSEGV when breaking oplocks. + BUG 6655: Fix 'smbcontrol smbd ping'. + BUG 6620: Fix a bug in renames of directories. + BUG 6664: Fix truncation of the session key. + BUG 6673: Fix 'smbpasswd' with "unix password sync = yes". + BUG 6680: Fix authentication failure from Windows 7 when domain joined. + BUG 6688: Fix crash in 'net usershare list'. + BUG 6693: Check we read off the complete event from inotify. + BUG 6700: Use dns domain name when needing to guess server principal.- Update to 3.2.14. + Fix SAMR access checks (e.g. bugs #6089 and #6112). + Fix 'force user' (bug #6291). + Improve Win7 support (bug #6099). + Fix posix ACLs when setting an ACL without explicit ACE for the owner (bug #2346). + BUG 6387: Fix Winbind crash when multiple IDmappings exist in the LDAP directory. + BUG 6509: Use gid (not uid) cache in fetch_gid_from_cache(). + BUG 6089: Fix SAMR access checks. + BUG 6112: Fix SAMR access checks. + BUG 6279: Fix Winbind crash. + BUG 6291: Fix 'force user'. + BUG 6099: Try to fix domain join of Win7 Beta. + BUG 6386: Groupdb mapping fix. + BUG 6421: Fix POSIX read-only open on read-only shares. + BUG 6476: Fix more smbd-zombies in memory. + BUG 6488: acl_group_override() call in posix acls references an uninitialized variable. + BUG 6504: Fix SAMR server for Winbind access. + BUG 6520: Fix time stamps. + BUG 6301: Fix samr_ConnectVersion enum which is 32bit not 16bit. + BUG 6340: Don't segfault when cleartext trustdom pwd could not be retrieved. + BUG 6372: Fix usermanager only displaying 1024 groups and aliases. + BUG 6465: Fix enum_aliasmem in ldb branch. + BUG 6484: Fix searching for users while adding them to groups via Windows usermanager. + BUG 2346: Fix posix ACLs when setting an ACL without explicit ACE for the owner. + BUG 6526: Let parent_dirname() correctly return toplevel filenames. + BUG 6627: Raise the timeout for lsa_Lookup*() calls from 10 to 35 seconds. + BUG 5798: Preserve CFLAGS info in configure. + BUG 6382: Case insensitive access to DFS links broken. + BUG 6481: Don't require "Modify property" perms to unjoin. + BUG 6628: 'smbpasswd -a' uses algorithmic rid base with 'passdb backend = tdbsam'. + BUG 6560: Lookupname failed, cannot find domain when attempt to change password. + Prevent creation of keys containing the '/' character. + Fix join of Windows 7 RC to a Samba3 DC. + Fix bug in processing of open modes in POSIX open. + Fix the negotiate flags. + Protect netlogon_creds_server_step() against NULL creds. + Also handle DirX return codes. + Fix a crash bug if we timeout in net rpc trustdom list. + Add '--request-timeout' option to 'net'. + Fix a race condition in Winbind leading to a panic. + Add workaround for MS KB932762. + 5945: Fix out of memory error with Winbind idmap. + Avoid duplicate ACEs. + Fix profile ACLs in some corner cases. + Zero an uninitialized array.- Unable to browse DFS when using kerberos in libsmbclient; (bnc#528271); (bso#6615).- check in .po files for pam_winbind; (bnc#499233); (bso#6602).- Add ntp and network-remotefs as Should-Start dependency to the winbind init script; (bnc#515629).- Update to 3.0.36. + Fix Winbind crash on 'getent group' (bug #5906). + Excel save operation corrupts file ACLs (bug #4308). + Prevent segmentation fault on joining a very long domain name. + BUG 4308: Excel save operation corrupts file ACLs. + BUG 4370: Clean-up entries in /etc/mtab after unmount. + BUG 4640: Fix guest mounts in mount-cifs. + BUG 5906: Fix Winbind crash on 'getent group'. + BUG 6066: netinet/ip.h present but cannot be compiled on Solaris. + BUG 6099: In order to allow Win7 to connect to a Samba NT style. + BUG 6279: Fix Winbind crash. PDC we set the flags before we know if it's an error or not. + BUG 6085: Fix build of vfs_default. + BUG 6098: When the DNS server is invalid, the ads_find_dc() does not work correctly. + Fix logic error in try_chown. + Correctly use chroot(). + Fix bug in processing of open modes in POSIX open. + Don't install the cifs.upcall binary twice. + Fix mount.cifs handling of -V option. + Prevent segmentation fault on joining a very long domain name. + Don't try and delete a default ACL from a file. + Add workaround for MS KB932762. + Add fakemount (-f) and nomtab (-n) flags to mount.cifs. + Fix a crash during name resolution when log level >= 10 and libc segfaults if printf is passed NULL for a "%s" arg.- Use a conditional suse_version macro in front of the SUSE_ASNEEDED export.- lookupname failed, cannot find domain when attempt to change password; (bnc#520645); (bso#6560).- Don't link with --as-needed flag on post-11.1 systems.- Stop the smbfs service if an interface goes down; (bnc#517768).- Disable build of static libraries on post-11.1 systems; (bnc#509945).- Fix missing zlibs for cifs.upcall and test_shlibs.- Update to 3.4.0. + BUG 6431: Local groups from 3.0 setups no longer found. + BUG 6459: Fix build of pam_smbpass on some distributions. + BUG 6481: 'net ads leave' needs to try account deletion, NetUnjoinDomain not. + BUG 6497: Fix calling of 'test' in configure. + BUG 6498: Add workaround for MS KB932762. + BUG 6499: Fix building of pam_smbpass. + BUG 6509: Use gid (not uid) cache in fetch_gid_from_cache(). + BUG 6512: Fix support for enumerating user forms. + BUG 6514: Improve error message in 'net' when smb.conf is not available. + BUG 6520: Fix time stamps when "unix extensions = yes". + BUG 6521: Fix building tevent_ntstatus without config.h. + BUG 6526: Fix notifies in the share root directory. + BUG 6531: Fix pid file name.- Package /etc/samba/smbpasswd as %ghost on post-11.1 systems.- Fix net ads leave; (bnc#511695).- Supplement pam-32bit/pam-64bit in baselibs.conf (bnc#354164). - Supplement glibc-32bit/glibc-64bit in baselibs.conf (bnc#354164).- Update to 3.2.13, 3.3.6. + In Samba 3.2.0 to 3.2.12 (inclusive), the smbclient commands dealing with file names treat user input as a format string to asprintf. With a maliciously crafted file name smbclient can be made to execute code triggered by the server; CVE-2009-1886; (bnc#513360); (bso#6478).- Update to 3.0.35. + In Samba 3.0.31 to 3.3.5 (inclusive), an uninitialized read of a data value can potentially affect access control when "dos filemode" is set to "yes"; CVE-2009-1888; (bnc#515479).- Uninitialized read of a data value; CVE-2009-1888 (bnc#515479).- Update to 3.4.0rc1. + BUG 4699: Remove pidfile on clean shutdown. + BUG 5456: Fix "net ads testjoin". + BUG 6081: Make it possible to change machine account sids. + BUG 6253: Use correct value for password expiry calculation in pam_winbind. + BUG 6297: Owner of sticky directory cannot delete files created by others. + BUG 6305: Correctly prompt for a password when a username was given. + BUG 6328: Add support for multiple rights to "net sam rights grant/revoke". + BUG 6333: Consolidate create/delete account paths in pdbedit. + BUG 6449: 'net rap user add' crashes without -C option. + BUG 6451: net/libnetapi user rename using wrong access bits. + BUG 6458: Fix uninitialized variable in local_password_change(). + BUG 6465: Fix enumeration of empty aliases. + BUG 6476: Fix smbd-zombies in memory when using [x]inetd. + BUG 6487: Add missing DFS call in trans2 mkdir call. + BUG 6488: acl_group_override() call in posix acls references an uninitialized variable. + Improve pam_winbind documentation. - Install a vendor copy of samba-common.dhcp as dhcpcd-hook-samba-functions.- Samba 3.2.0 - 3.2.12 smbclient commands dealing with file names treat user input as a format string to asprintf; CVE-2009-1886; (bnc#513360).- Fix a bad memleak in vfs_full_audit; (bnc#510035).- Update to 3.3.5. + Fix SAMR and LSA checks (bug #6089, #6289) + Fix posix acls when setting an ACL without explicit ACE for the owner (bug #2346). + Fix joining of Win7 into Samba domain (bug #6099). + Fix joining of Win2000 SP4 clients (bug #6301). + BUG 2346: Fix posix acls when setting an ACL without explicit ACE for the owner. + BUG 5832: Fix build on RHEL when ccache is not available. + BUG 5853: Add keyutils-devel to build requires to fix build on RHEL. + BUG 5897: Fix shutdown script example in the smb.conf manpage. + BUG 6089: Revert the extra SAMR and LSA checks. + BUG 6099: Fix joining of Win7 into Samba domain. + BUG 6157: Fix handling of multi-value attribute "uid". + BUG 6289: Revert the extra SAMR and LSA checks. + BUG 6297: Owner of sticky directory cannot delete files created by others. + BUG 6301: Fix joining of Win2000 SP4 clients. + BUG 6309: Support remote unjoining of Windows 2003 or greater. + BUG 6315: smbd crashes doing vfs_full_audit on IPC$ close event. + BUG 6320: Handle registry config source in file_list. + BUG 6330: Fix DFS on AIX. + BUG 6336: Fix 'net groupmap set' segfault. + BUG 6361: Make --rcfile work in smbget. + BUG 6365: Re-Add the "dropbox" functionality with -wx rights on a directory. + BUG 6372: Fix usermanager only displaying 1024 groups and aliases. + BUG 6382: Fix case insensitive access to DFS links. + BUG 6415: Filter out of range mappings in default idmap config in idmap_tdb. + BUG 6416: Filter out of range mappings in default idmap config in idmap_tdb2. + BUG 6417: Filter out of range mappings in default idmap config in idmap_ldap. + BUG 6441: Fix the compile with --enable-dnssd. + BUG 6449: 'net rap user add' crashes without -C option. + BUG 6465: Fix enumeration of empty aliases (ldb backend). + Prevent infinite include nesting. + Mark registry shares without path unavailable. + Also handle DirX return codes. + Fix Coverity ID 897. + Do not crash in ctdbd_traverse if ctdbd is not around. + Fix a race condition in winbind leading to a panic. + Some man pam_winbind improvements. + Zero an uninitialized array.- Update to 3.2.12. + Fix SAMR and LSA checks (bug #6089, #6289) + Fix posix acls when setting an ACL without explicit ACE for the owner (bug #2346). + Fix "force user" (bug #6291). + Fix Winbind crash (bug #6279). + Fix joining of Win7 into Samba domain (bug #6099). + BUG 2346: Fix posix acls when setting an ACL without explicit ACE for the owner. + BUG 5798: CFLAGS info lost in configure. + BUG 5832: Fix build on RHEL when ccache is not available. + BUG 5835: Add keyutils-devel to build requires. + BUG 5945: Fix out of memory error with Winbind idmap. + BUG 6089: Revert the extra SAMR and LSA checks. + BUG 6099: Fix joining of Win7 into Samba domain. + BUG 6279: Fix Winbind crash. + BUG 6289: Revert the extra SAMR and LSA checks. + BUG 6291: Fix "force user". + BUG 6301: Fix samr_ConnectVersion enum which is 32bit not 16bit. + BUG 6372: Fix usermanager only displaying 1024 groups and aliases. + BUG 6386: Groupdb mapping fix. + BUG 6382: Fix case insensitive access to DFS links. + BUG 6465: Fix enumeration of empty aliases (ldb backend). + Prevent creation of keys containing the '/' character. + Fix bug in processing of open modes in POSIX open. + Protect netlogon_creds_server_step() against NULL creds. + Also handle DirX return codes. + Fix a race condition in winbind leading to a panic. + Fix a crash bug if we timeout in net rpc trustdom list. + Fix profile acls in some corner cases.- Default with passdb backend to smbpasswd for SUSE products older than 11.2.- Explicitly use 'tdbsam' as passdb backend in the default smb.conf file.- Update to 3.4.0pre2. + The default passdb backend has been changed to 'tdbsam'! + Samba4 and Samba3 sources are included in the tarball. + Changed the way smbd handles untrusted domain names given during user authentication. + Various fixes including printer change notificiation for Samba spoolss print servers. + The remaining hand-marshalled DCE/RPC services (ntsvcs, svcctl, eventlog and spoolss) were replaced by autogenerated code based on PIDL. + Samba3 and Samba4 do now share a common tevent library. + The code has been cleaned up and the major basic interfaces are shared with Samba4 now. + An asynchronous API has been added. + Made parameter syntax of the net command more consistent. + BUG 2346: Fix posix ACLs when setting an ACL without explicit ACE for the owner. + BUG 4271: testparm should not print includes. + BUG 4831: Don't call openlog() or closelog() from pam_smbpass. + BUG 5681: Do not limit the number of network interfaces. + BUG 5859: Fix renaming of samr objects failed due to samr setuserinfo access checks. + BUG 6099: Fix NETLOGON credential chain. + BUG 6136: New AFS syscall conventions. + BUG 6157: Fix handling of multi-value attribute "uid". + BUG 6253: Use correct value for password expiry calculation. + BUG 6291: Fix 'force user'. + BUG 6292: Update config.guess from gnu.org. + BUG 6302: Give the VFS a chance to read from 0-byte files. + BUG 6309: Support remote unjoining of Windows 2003 or greater. + BUG 6313: ldapsam_update_sam_account() crashes while doing talloc_free on malloced memory. + BUG 6315: Fix smbd crashes when doing vfs_full_audit on IPC$ close event. + BUG 6320: Handle registry config source in file_list. + BUG 6330: Fix DFS on AIX. + BUG 6336: Fix segfault in 'net groupmap set'. + BUG 6340: Don't segfault when cleartext trustdom pwd could not be retrieved. + BUG 6357: Use Samba default command line arguments in 'net'. + BUG 6359: smbclient -L does not list workgroup for hosts with both IPv4 and IPv6 addresses + BUG 6361: Make --rcfile work in smbget. + BUG 6371: Unsuccessful 'net conf setparm' leaves empty share. + BUG 6372: usermanager only displaying 1024 groups and aliases. + BUG 6387: Fix a crash bug in idmap_ldap_unixids_to_sids. + BUG 6415: Filter out of range mappings in default idmap config (idmap_tdb). + BUG 6416: Filter out of range mappings in default idmap config (idmap_tdb2). + BUG 6417: Filter out of range mappings in default idmap config (idmap_ldap). + Change the way smbd handles untrusted domain names given during user authentication. + Replace the hand-marshalled DCE/RPC services ntsvcs, svcctl, eventlog and spoolss by autogenerated code based on PIDL. + Fix several printing issues and improve support for printer change notificiations. + Add 'net eventlog'. + Add asynchronous API. + Make Samba3 and Samba4 share a tevent library. + Add two new parameters to control how we verify kerberos tickets. + Add 'net rpc service' subcommands 'create' and 'delete'. + Fix the core of the SAMR access functions. + Fix SAMR server for winbindd access. + Add dbwrap_tool - a tdb tool that is CTDB-aware. + Hide "config backend" from swat. + Fix linking with --disable-shared-libs. + Fix issue with missing entries when enumerating directories. + Map NULL domains to our global sam name. + Fix driver upload for Xerox 4110 PS printer driver. + Add "net dom renamecomputer" to rename machines in a domain. + Inspect the correct computername string before enabling/disabling the change button in netdomjoin-gui. + Fix join prompt dialog test in netdomjoin-gui. + Only gray out labels when not root and not connecting to remote machines (netdomjoin-gui). + Allow to switch between workgroups/domains with the same name (netdomjoin-gui). + Add NetShutdownInit and NetShutdownAbort. + Fix samr access checks. + Add a security model to LSA. + Also handle DirX return codes. + Do not crash in ctdbd_traverse if ctdbd is not around. + Fix Coverity ID 897. + Fix a race condition in vfs_aio_fork with gpfs share modes. + Fix bug disclosed by lock8 torture test. + Fix a race condition in winbind leading to a panic. + Detect tight loop in tdb_find(). + Fix chained sesssetupAndX/tconn messages. + Fix strict locking with chained reads. + Fix two bugs in sendfile. + Fix memory leak. + Fix file descriptor leak. + Fallback to the legacy sid_to_(uid|gid) instead of returning NULL. + Always allocate memory in dptr_ReadDirName. + Fix 'net' crash during domain join. + Zero an uninitialized array. + Allow child processes to exit gracefully if we are out of fds.- Enable cifs.upcall on versions newer than SUSE 10.0.- Add BuildRequires to keyutils-devel.- Remove redundant Requires to keyutils-libs for cifs-mount.- Detect tight loop in tdb_find(); (bnc#450974).- Fix lp printing with kerberos; (bnc#476913).- Add BuildRequires to ctdb-devel for systems newer than SUSE 10.0 and all other build targets.- Update to 3.4.0pre1. + Samba4 and Samba3 sources are included in the tarball + Changed the way smbd handles untrusted domain names given during user authentication. + Various fixes including printer change notificiation for Samba spoolss print servers. + The remaining hand-marshalled DCE/RPC services (ntsvcs, svcctl, eventlog and spoolss) were replaced by autogenerated code based on PIDL. + Samba3 and Samba4 do now share a common tevent library. + The code has been cleaned up and the major basic interfaces are shared with Samba4 now. + An asynchronous API has been added. + Change the way smbd handles untrusted domain names given during user authentication. + Replace the hand-marshalled DCE/RPC services ntsvcs, svcctl, eventlog and spoolss by autogenerated code based on PIDL. + Fix several printing issues and improve support for printer change notificiations. + Add 'net eventlog'. + Add asynchronous API. + Make Samba3 and Samba4 share a tevent library. + Add two new parameters to control how we verify kerberos tickets. + Add 'net rpc service' subcommands 'create' and 'delete'. + Make merged build possible. + Move common libraries to the shared lib/ directory.- Update to 3.3.4. + Fix domain logins for WinXP clients pre SP3 (bug #6263). + Fix samr_OpenDomain access checks (bug #6089). + Fix usrmgr.exe creating a user (bug #6243). + BUG 6089: Fix samr_OpenDomain access checks. + BUG 6254: Fix IPv6 PUT/GET errors to an SMB server (3.3) with "msdfs root" set to "yes". + BUG 6279: Fix Winbind crash. + BUG 5329: Add "net rpc service delete/create". + BUG 6238: Make sure wbcLogoffUserParams are properly initialized before freed. + BUG 6263: Fix domain logins for WinXP clients pre SP3. + BUG 6286: Call init function for builtin idmap modules before probing for them as shared modules. + BUG 6243: Fix usrmgr.exe creating a user. + net conf: Save share name as given, not as lower case only. + Prevent creation of registry keys containing the '/' character. + Allow pdbedit to change a user rid/sid. + When doing a cli_ulogoff don't invalidate the cnum, invalidate the vuid. + Don't access a freed structure when logging off and re-using a vuid. + Try to to fix password_expired flag handling. + Make sure to grey out change fields in the netdomjoin-gui when not running as root. + Don't look up local user for remote changes, even when root. + Use procid_str in debug messages for better cluster-debuggability. + Use cluster-aware procid_is_me instead of comparing pids. + Fix smbd crash for close_on_completion. + Fix a memleak in an unlikely error path in change_notify_create(). + Do not use the file system GET_REAL_FILENAME for mangled names. + Fix a crash bug if we timeout in net rpc trustdom list. + Add '--request-timeout' option to net. + In net_conf_import, start a transaction when importing a single share. + Fix writing of roaming profiles with "profile acls" set to "yes".- Update to 3.2.11. + Fix domain logins for WinXP clients pre SP3 (bug #6263). + Fix samr_OpenDomain access checks (bug #6089). + Fix smbd crash for close_on_completion. + BUG 6089: Fix samr_OpenDomain access checks. + BUG 6205: Correct sample smb.conf share configuration. + BUG 6254: Fix IPv6 PUT/GET errors to an SMB server (3.3) with "msdfs root" set to "yes". + BUG 6263: Fix domain logins for WinXP clients pre SP3. + Allow pdbedit to change a user rid/sid. + When doing a cli_ulogoff don't invalidate the cnum, invalidate the vuid. + Fix resume command typo for "printing = vlp". + Fix smbd crash for close_on_completion. + Fix a memleak in an unlikely error path in change_notify_create(). + Don't look up local user for remote changes, even when root.- Don't lookup local user for remote password changes; (bnc#493507).- Update to 3.3.3. + Migrating from 3.0.x to 3.3.x can fail to update passdb.tdb correctly (bug #6195). + Fix serving of files with colons to CIFS/VFS client (bug #6196). + Fix "map readonly" (bug #6186). + BUG 6195: Don't let smbd child processes panic. + Add backend_requires_messaging() method to libsmbconf. + Add methods is_writeable() and wrapper smbconf_is_writeable() to libsmbconf. + Fall back to file backend when no valid backend was found. + Fix a memleak in dbwrap_rbt. + Provide transaction_start|commit|cancel fns for the registry tdb. + Speed up "net conf drop". + Speed up "net conf import". + Add transactions to the libsmbconf API. + Reduce memory usage of "net conf import". + Registry cleanup. + Fix handling of SAMBA_VERSION_VENDOR_PATCH. + Fix build of pam_winbind.so with static linking. + Tidy up some convert_string_internal error cases. + BUG 6224: nmbd waits 5 minutes at startup before checking if it needs to run elections. + Allow DFS client paths to work when POSIX pathnames have been selected. + Try and fix the build farm RAW-STREAMS errors. + Ensure files starting with multiple dots are hidden. + BUG 6102: NetQueryDisplayInformation could return wrong information. + BUG 6193: Avoid messing with sync_context in libnet_samsync_delta(). + Fix notify_printer_status_byname. + Fix Coverity IDs 722, 762, 774, 775, 776. + Fix build on old Heimdal based systems. + Fix compile warning. + Use parentheses in if condition to make negation clear. + Add dirsort module. + BUG 6147: Fix detection of the GNU ld version. + BUG 6097: Fix smbd segfault. + BUG 6130: Don't crash in winbindd_rpc lookup_groupmem() on unmapped members. + BUG 6139: Add missing whitespace in mount.cifs error message. + Fix a malloc/talloc mismatch when cli_initialise() fails. + Fix a valgrind error. + Speed up "net conf list". + Add sorted subkey cache. + Use StrCaseCmp in the dirsort module. + Document the dirsort module. + Disable dns_sd by default. + Add avahi detection to configure. + Add event avahi binding. + Use avahi to register _smb._tcp in smbd. + Fix two memleaks in the encryption code. + Fix a scary "fill_share_mode_lock failed" message. + BUG 6228: Fix SMBC_open_ctx failure due to path resolve failure doesn't set errno. + Don't use reserved words in smbconftort. + Fix smb signing for fragmented trans/trans2/nttrans requests. + Parse_packet can return NULL which is then dereferenced in match_mailslot_name. + Format the header check for netinet/ip.h more nicely. + Missing break in conversion function prevents tdb password database update.- Update to 3.2.10. + BUG #6195: Don't let smbd child processes panic.- BUG 6195: Fix crash on passdb conversion.- Update to 3.2.9. + BUG 5920: The length of the memcpy was calculated wrong. + BUG 6097: Fix smbd segfault. + BUG 6098: Fix ads_find_dc() with "security = domain" when the DNS server is invalid. + BUG 6099: Samba returns incurrate capabilities list. + BUG 6100: Implement _netr_LogonGetCapabilities() with NT_STATUS_NOT_IMPLEMENTED. + BUG 6102: NetQueryDisplayInformation could return wrong information. + BUG 6130: Fix crash in winbindd_rpc lookup_groupmem() on unmapped members. + BUG 6133: Cannot delete non-ACL files on NFSv4 ACL filesystem. + BUG 6161: smbclient corrupts source path in tar mode. + BUG 6193: Avoid messing with sync_context in fetch_database_to_ldif(). + BUG 6196: Unable to serve files with colons to Linux CIFS/VFS client. + BUG 6224: nmbd waits 5 minutes before checking to run elections. + BUG 6228: Fix SMBC_open_ctx failure when path failure doesn't set errno. + Numerous Coverity fixes + Fix double free caused by incorrect talloc_steal usage. + Backport delete semantics of alternate data streams on a file truncate. + Allow set attributes on a stream fnum to redirect to the base filename. + Fix use of streams modules with CIFSFS client. + Fix more POSIX path lstat calls. + Allow DFS client paths to work with POSIX pathnames. + Ensure files starting with multiple dots are hidden. + Fix guest auth when Winbind is running. + Fix memleak in get_remote_printer_publishing_data(). + cifs mount fix for handling -V parameter. + Fix guest mounts. + Clean-up entries in /etc/mtab after unmount. + Add fakemount (-f) and nomtab (-n) flags to mount.cifs. + Enable total anonymization in vfs_smb_traffic_analyzer. + Don't try and delete a default ACL from a file. + Fix remotely adding a share via MMC. + Fix resume handle for _samr_EnumDomainGroups. + Fix a buffer handling bug when adding lots of registry keys. + Fix a O(n^2) algorithm in regdb_fetch_keys(). + Fix a valgrind error / segfault in dns_register_smbd(). + Don't log NDR_PRINT_DEBUG at level 0, this always ends up in syslog. + Fix a malloc/talloc mismatch when cli_initialise() fails. + Fix two memleaks in the encryption code. + Fix "fill_share_mode_lock failed" message. + Add S-1-22-X-Y sids to the local token. + Fix smb signing for fragmented trans/trans2/nttrans requests. + Don't miss an absolute pathname as a kerberos keytab path. + Have nmbd check all available interfaces for WINS before failing. + Initialize the id_map status in idmap_ldap to avoid surprise.- Obsolete change from 2008-03-05 by removing the needless examples cleanup.- Update to 3.3.2. + Fix "force group" (bug #6155). + Fix saving of files on Samba share using MS Office 2007 (bug #6160). + Fix guest authentication in setups with "security = share" and "guest ok = yes" when Winbind is running. + Fix corruptions of source path in tar mode of smbclient (bug #6161). + BUG 6082: Fix renaming and deleting of directories using Windows clients. + BUG 6154: Make ZFS honor admin users. + BUG 6155: Fix "force group". + BUG 6160: Fix saving of files on Samba share using MS Office 2007. + BUG 6161: Fix corruptions of source path in tar mode of smbclient. + Fix some NetBSD warnings. + Fix bug in processing of open modes in POSIX open. + Fix use of streams modules with CIFSFS client. + Ensure ACL modules work with POSIX paths. + Use fsp->posix_open in preference if we have it. + Fix more POSIX path lstat calls. + Fix a bug in message handling for the change notify code. + Fix guest authentication in setups with "security = share" and "guest ok = yes" when Winbind is running. + BUG 4640: Fix guest mounts in mount.cifs. + Fix displaying the version string properly when no other parameters passed in in mount.cifs. + Prefer gssapi header files from subdirectory. + BUG 6176: winbindd -n should disable the winbind idmap cache. + Add a vfs_preopen module to hide fs latencies. + Don't log NDR_PRINT_DEBUG at level 0, this always ends up in syslog. + Fix a valgrind error / segfault in dns_register_smbd(). + Fix build on SLES8. + Decremented by 1 for ntcancel requests. + Fix creation of core files. + Fix first mapping of uids/gids in Winbind. + Initialize the id_map status in idmap_ldap to avoid surprise. + Fix initialization of idmap status.- Only call '%find_lang pam_winbind' in the samba spec file, not samba-doc.- Ignore return value from subshell to fix build./bin/sh3.6.3-141.13.6.3-141.1libsecuritypam_smbpass.so/emul/ia32-linux//emul/ia32-linux/lib//emul/ia32-linux/lib/security/-fomit-frame-pointer -fmessage-length=0 -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector -funwind-tables -fasynchronous-unwind-tables -gobs://build.opensuse.org/openSUSE:Evergreen:Maintenance:4627/openSUSE_Evergreen_11.4/1af6c5bb952ae8b921021669103e3f44-samba.openSUSE_Evergreen_11.4drpmlzma5ia64-suse-linuxpackageand(samba:pam-x86)?]"k%b6 5ΫB}DgfVA8mY ;˚_@S7ݘti^l9zY`S*PCn.eT$:29J `Ew-)p⓻>8pb)T0򣊌W:ıPE2MTCJTja-zxbZ==<xqH=0xYzV\VB(]7{ ־H%p7_ޡfyЦ\rw m$4a9p%xB|"@Yp/Za-lSw;v2  7E( G,wX_ѓx .">2!9׍)'Rj_]4G[(/)agoTO^muups"} Vd޾pQH!-+lH )}$Tw-eV)%y "SN o9 P,6;kL :%x}zp1(% 稀"5)R8J<ﮬe\E)m+aL}e[zwnLYy)g@Wby}K"ʉ`*7΍GWs@ϖ̸26C%7-0rlT933VYrPJTVbN}?ºY`Fdn7l$2}QG(ڞS|KJ^`7 F-Co^(RT)/ᵃ+NC([5N`l TƓD-RGr( _r@=c}lN 5cTiїY. Ѡ= E"=/sp5ާcJuA@NG)6dRQIy)>4Ɍ)|hBW̡V Y2)Ի,X(쟟YA *𫪨9M ( $n= /O*tʗe',l3җ-ȸI̻}ښ _M>lMv.m2}J~ ְ-GES4DeU ;_B`/$7d SgV:MEYYj{~Kٶ34 >k&~2Bd 5OI-2ܯ]ڥy-^CE|?Rr[: qCdR7[%BєS죃 8{],-m/\oŴy5jż|&,rDN MAx*'k.KHB4Mc)Ko`y ~Ð` 6X#vua H)} (;;^N!Pb߹+mdBSv4jtL#bJb)J Q:ҩDpp )ckC$LH)w  ,CYI~2y쌣 ي%FلPl^ X'34^0X?(.М[;_:Aß?tln<!~p2SmR J#J+9yYe9`9L+NuzF+TUkV G` RιjXWK*u=ꤧ u!AMͬsJtR<*F S7ϯcZ52^rܗxhRe5Z"Xkv1xtayPaꌫ=wT[jf7(yʽ <䶨ȠT\̓?BF؊Hޓ Ԃ#`ts.FģvVd=UI<4+DVK3}xIK 919<ƃaBJ_k u4Dn@bYQ-֝J#;t/w]'hw̰,D"ʣ*YN3#y+Y&ٶߥhhk5dRQ-fݤYw꼿)oUg_@sӉ`h2"(Z){G$)~V/U)gkt|gZ4 LX1t3}˂Hv s??UŪĈ&yG!mܨi=Y׶M"Yar$Iχײzl&@%&fuڔ Ԧ"WF9]*,\B5 b4Be\!Q_d-Pe/9>)4KI 7Uj*] AEv YhR6M?;Pu:v<_O"C:zZw%y.vPx`S@:.?ң C"ljN뻘P9g IiWnTۉJÂRVN ul2xAe4`y7ѻbD3htR20df8Ïzޱhyl9;? ped/o huFR(U"gv8ұr%:`e~0!ݞ4NrZKBYґ0#F% 3Ӽ"m=QO'+}kx<erBǵ{?'L-pF_ˣ_W}ٷdAp m\d&8+,t nVϰxmEց {U?zǮCc"3=$hko8uw7pǔ6W/č);OZ@aИXx0ӎahk- n?~fF =*: 1/*#tɁ4"K/l#qGa. PϧqM>,Kv+{3#]ǰ7Fyž ̍HU)^yQ HryP߫Z2.F- Num Ϣ3e遈ƀin ;]wWb6UX_c%cp}͑$k ʮѾԫ!w;HI\ϥmB _Gy-ǭ6D"غ  =Ψ&^KKn6멍FZ.$cIdvjn\\cʐ ,)§ *Qg$ @V4"V̷x/J[p8rV,Sq IelW8;(g~X\濍ЋEjvhC g-7\S ! iJ%mWXrGlkgoU?ʬeAEF,!REO/OJ1k'q>l<=G5FGwMs $'(hD0ZnΝ JJB e3 n Y=:gԛYYB6gUnvvՊM<0!U'TB;h؎A]9=ѸjBǐ#!9H6t.HP-!_F6MP#QQ(巯wf6X+_0wC&6!'G:?`Gn~R=cb0G;jvdaP,$77 8^ 6foh]8|?CĖ(Ϳhᮗ[/Zv8%3)B0;Dϼؾ5~|Օ]1ˣLڵrX< DJY1 1} 6M*biגऑ+YE;;flw`Os>ꚒQh*P{|?wW@U;YGi/^>)2h>OT^O6sT %BxYuEv!*Rfx48a0L|ǏfE>MlNJcw&uJc,1b2Xֲ8 by+| FH"U'w5u* S[~ ǜh!Hl' rvAu(Xռoz_[sUǍݰqCO-)"A)?>Zk'=A<@uO~KfPoS#EV+}e8^a"mE\=SVZg3TG̈́͗Qu}+py mbgAZYKR>MCEucpz),=8-|ӢIP0dp!Y~r^}Գ+zu=XvP˞1ܪv{)XXFnKYJۅ')BbEn$ӿ 7t ݶg9HeP&/ܱ_uh>a?iW uZ6g,Fck / >FN!Ѫ#q`%LߚP 1/P3D;xBJ;Y'Ad.v 36+v JƶX&3STX6M蹼R\`L2",$0U;}'n _os*f^m(;pxH~x(2#C +!!b?ZT$ ;T\bn8[b(%d=(0?trF4ޕԨ{(ٳhc*$S rήQKUٮG+r08v$Z5B&eA;ZSi&oC'|+NRܥG)mZ,W9xy61+ {EDyRP;+ H䫁|m+|wK8İL0ˮ1ڴtF8UU$sD٧\^~IߝK WT YXQeZ%gHa 9Gn;\Y@ CKN@p!Z.H3 W_Yxq0Ik; "VvRq+qJ%w$$ [B=8h$¯ ʲL^/nxt 6K+`'qt^씷m#kn$b;%1CkkE&V|džg F^yr⁒b+,GHTD8,9@~H+xZf4M SyH syAi"NQ{8KyF`Al^<X'oF 7FÌL:Ewʧؖ-2IPv>lt*=VC30ܚhRuo t"љًC{li:0,?0Bc%!D7̹xTi+p.7(XלHrPP>lx_=ki x6;˗ߧ9%{!rG6hCEs&|˔7 C:xj:&2x$ry^d}ylo 'FQie Q>Y}!m׵ L d2i~5I7R Vx>8>#mQ";k_-Fu"ꈿpj.sYq va5ܻc(+|$ ,.ߙ^uYq4}R!S4^67 6V,AԢLr`ہP+gE |FP*DbP sib4X#6w55}ܝ_GQ2zEhA^~>tTg Lֱ4dTB wDGLߎ01WjmC M2&u'WDGqGꌊp-Y Hj7Z)MG½ Xp8Lw_9 i.Dy&nuYx+`)0xkZ}:0It(>8mE a-qqT%Gy:F, }“dc5 yYr)O_VV8:򚕄qRQ`r_.7}϶\Ǫu2TfmN%cYLI8(Q(rt֤$\)pXcq|bD5F?S!#i /K'5$e&eF2E3@*9:`=, d-?T#MK!ˮ&;B" ETp\SX ]M&Ea(pVO:`8u俵5N0,%KBSԭ[g̈́W̵+8˖뿜~3C"c$tr ^hd#:3 22F68ƼLmuBOLr+zGv/φ21EWQNOuרbk W&\F+ J_?^NCI?VN 4-FݵwÑdjnV%:T8ֶ ,qߓ1ܮ8VЂ*[eQPlBKX3ʉH$;xɲ^m*M[rĤxpBH=}uu gm \r ÏX[rȌy'!l9XjD?$#z+׻8l6$!(nP8G^;1-J.zm r|]wkW?c+j,(mjK#MaRZ]KB5LԤR;K^byݒ/'$*y[,[syZ$FfQ⭫B5J$PFwzr6XnMU*;C'{z@yp#!C*Z9<1{_)AէdvܙD.cZ_[YcR"# (كqJљ&AM ai;:""[&^E(Y$K|C_iZF6ٲH[oF ta99a Ji[S&.M&_޴!^GB{wZ_ 쬕`ǟ%OD~x7xj1$j x$Rm?C>>/a@I:H%wJ|z_ JTDa;9 |t;[ȟ°jB Θl2^VpqU5ǐቸGW%w_Tu=B2 u`ˠ${o0UP [{AlWu"j[]=qԛO{#AWoV>9R)%Si!C38O& x`\(1s#ɟ"YF&GKk n)E2{e7\;h|\ekъ"؏WV$u\ShXD6AMXJʋqq?脥UbI#1QPz3RKj Q}΀QTuR RwQp?SJ9Ï<6r5Xۭ lZ F&7B1@Zx넁N2˩`A 'P5zKW8RrDeᶊ*&ULZh‡U>@!""͂e{w+(u/ ȟ${Dae v׮qK8hwXFrFWY4+II:~ֹǬx dtZ;G,7z5RwtaZNf^ eB*,QL;p2:t@^kyI;ZLdŏ]YwCkt/$|pDb"}Hj"nAXS]^% 8[dZ*Sn"%o^JqϺT9Z\85c3^lV&LF {SQS jik@j\GjuxVգ4dbPȨlt}/]~} `SUc*gٻN>'m.VI1˜^|TTq` #^Nm:qf soؙ ,HUO>>s :QWqNr犚3ꉜ8^7oSmBNx5~BH9FLƌR{S$z򷆮~كbM=p,CK)D(D O9[2j' '[Q~MaPf5s q/P4Nɞ|ʠҹ[NWll,_'ʎY/]s# >WK^?s)6ʜEupɴբU6 do!bo-޴m?I د!5[-EG+ntDngd5| XUj]BZnKs>E/<97覕v7 4Wó ;{4|Rwp >򃡇!᧑X˫Uv:1rG֙0&Z؈p䬔`PSY֔7+>He).OmT`yO{Sn8Gz:5& { ޵u^Iӝ7'Az+m#>Udf1d(J\x<ʫ׷S BiY %T4#M6"M 38ʽ;ow YBA^COҹa=ּH e V"܄#>+Paͅ.֖pOldtcG ko*^Vd(+|W Q l䎗U2jn1v?R4[kg;g$c¨GLم% |A~bvX:/( Qpj.+RF%lq )Яb LAaQͬnU/S4.7qPU7bܟ/Áut7rZlTZsk_2CdZ`4AA9+JD#Ԋ=;6=@^jj :}u ʼnF̠!Պ§4o;\ڕv ZyEX$jβXi&ipvĉ[:ϛ>C`Ffz7!"e^Ae]fAvi×sY3BN0LU6kz)݅d'elx}Gbw134\p=dqcv CQM+`ԗ sL^pqSElG v"HVh=SoLrlIv^jYSЖ|+P}צ_ lڢ*"x H>o^rJZ2XOB6hheD |?{Rsc@UJVƄ츀ڱO~|WS$aގ׷ޗCdɲg R>VܭWjwݰQnԠAYvO+9 a'|[bXiW0L Ĵ`s=Y> Olp]@>>;O`B_'2Tx*DYYg@xR$W /*rx(K0loeUZTga㋳&vi(MQ;͙5Ĵנqs%TWv;ajpSC'B:6)IF #,%ZcC>f& ||*N9؛.eQJr?S}D!ܐGurQ g1ךZt'P)~VÑ;bKՇtzO,$J;ZIW4˝/%=#F8?C..δ||Q?5S 'X@P!jT.A AV=W'_nyo!7nkMp@oXԐSeeCdJN"Ff{_GiE%L\/*E`~6ɽ43I#z=x>v0Bۼ}.IQ1![4C9:㔅'c;U'l& QsN8l+DGP`#u+zb3quoqlM7bןM?A:CKkxRT Hra#:ecd&2:ɽÇ6۩PI5@!Ql bD/}^ ݧ|Z9y>f\Fޝ~!; BT΃CV e@5]L.i;6N&0xGH%#!O3|Ņ {G(]S,=#Lr|%[˨FlOϵL5a˅m*~'s0mCM8-D'"6ȣ!$;u2A4:ꍣ$LVOK L'e-𶓙Szu=8GxڔqLIWοnG03@cӨlŔ01~^{YshV28ƙzxפнBSֆU> _f2.8T{m;)4EE(aRPEK|)tpB{h0 FH82CGb1J_>s'}2:*;r13t=> YL|/+Hp*f[>0xI_f4w|pf(Fւo0?7U Aُ]uUM;뾣`EڼͶJT8E1M\w09&k'7$jhX ?QΒJ5dd6_:HG-[e3W5x@kߐCG.)gKԧ*aG"A|l+FШ^`bOhSݝ:eV8wM>(V.FkD"@'}rm2chD휯lDhp5}KS[D Vz6%~@d#-J gvt_hYKDdCzUX\Zo.`AR+&=M VN1v+=+*jLd._Nxu$Q{aCz9-Ot$ q,❮}/V1>pYl0CN}KJѩMy$ʖOw&o}S eT1҄x6adhP;IVlGfIPMp)uNÉ~$Lʛ޻3u/@334ROs*Ec8¹Gi%HtPػ[YQUyQR wtcc%RDO!aQ{Puϒu`DHK" oF̠1$ ӳ;+6ck:86~8R%w+pc-=XCa9BYoyĵBP[21'gW{N_mB?]"h׳vH=3IFʊ2oE[G9fu/]~fୂJ.(I67Ԁ:4J>|Fɥh>ޮۛO4UL%˓jEe^`bJp]qflVԋ6z^`XLNP_eWx)` 4To~į^1\)z uid&:Xy\Qh5%Aۜ󳷴:0%'>Ro_*Wv#tߓ챹l B0@H.̨Z'5 '5X2Iw¡誓M}6MrూL7I{I8d O8 sU$ 4&6-g1(x"Wn26}rdRg(T w=7Dُ_o65<У9g]Ka(k!gniJUOH4Crhzf^xٙZ7#%bخ&p07û_j7+%#'tO|FSB|]HiR=`M`t uts\xC5pHVWwty !i{%pm4<y7@fDC 6EN sZQkir̠!}p }h`)DM7<< DnzZ<ʻl>;_@ov"'6a۷ka#fw/ + ]nxPQ0 `)vsWQ&eD[coX`[~NA֋9XW.QGWd2t }O(Iu)bW'jiEX异0:'.x [d*3JEl)ڶf/ƈ,az׈eR 4|ϩ0_Z(٩ N f6OJ4T O*0Vafe;E d=1'B[J(jr,R4b!S$=FbUTB^͙z`Mh8쀃0B-U]VvsT ڵbIJR PYcѰ(fbHUu'PYȔ $).m$z~.L^ߝgE hE|^$HR~06$w'W5hRB&8]\o«Yй&7c.)Gy_^?o_gA i^<VX8ߒ8!oBR\\ly+-L@]ƖeBdJ_j@py~eod@v{@?ʆG5'*2]{JT?~P Wj F93z'%>]U-u49ϥjZ.тX2,b*ڌXO%uլFRGk;F1QN`9ȿFWUnM#_Nn)X~1RO)Χ^smv-O ~ ѿ'yuA0B BuI~ݲizA3 (HWVӬ& K9>N$o&5X⇘itN.Sv i<k_b J֛^li4leO!sl|;ZFٶ@M.DiW\[G"*4C!.5Pm{ˁ[!+jU NLpi6 v]9s'֟Fmoh#_Rx Aȷc΀wj G8 F!cJx_mEKh#r3VW*_ԆӥyWP]K.L),VBRvX_@[is@|jFmsҮNnG2m.xe1 Q{Y,x=vqkiM|=bl)䢴X(0зB$~Rv$f/ aH26{,: Hbl@yaɴ o% f_ a{yG.ȉSNUc;RWvb;OrQr6I`ifq}1)g%X%h1) %.z]O3"ΰxu3KjxzU@Vpt/!MńRAo` 7ubVz>?I+Kc!"-c,=#6c@Rcm!R>NXLXTT{wؕJojA3iCskǃlhR두B5Oni\侓MPxvqDu6JoO~%HIx M~#轌xutnc^ME,B ,8ێkO ܅k2 -OiP"1IiĽc<427;9REVwGm[ERp{KRhp8?zѮc'5'2S`)l ϼ)/Q4l8YxeqpC"sa-o9/n3 Q17r.FJ׳K+_U5E bqP]9Ƒ9i6]txhnFyG!#JκWJggav҇'A_9繤)m\8{$/b`=M?@56 671y3L#v"-?VAk$'1b^8bD>0vAN"vK?`3#2Oxo{怞K$|#pgܾcm=Y48oW=L%|/T4mLu;p'Ӂcr?ɱEڿhʿZh@c #Z]r09 XP4~Q iwAZIh _3≴(AԴ^Z{5((/3m]ܼn R딧-N{ut(J$YSf99Tt . ˣan4 a%4kA;"5"saRWpPUy+@bPQϿ &/,o)Vt"R fEKְ3MVA LG}0E6p/oO $SZf`#S9O5upAJ|cuhҕ"22j0b trx&nAu;_,׮ȱ5|c`|s3@f HˈpdŮ0i%83^R~'eSүBjCi@':mvRF-FCucpdTM`af2Ir/z=OF=g6?>qv[p @I (`_z"#eB ^|8,]zml"^37>tȮ[pxwYZimTf7uoA7~ʌwЛ[[N PpLhڒ`˧[D45(9S)ۮtl]}%rBٰ4K'"y(/*\0\9jLI=_ܦ2JFI]9 rv֘ C1DIk&MǛXO-Q0JؿirF{lhF![,]HpH'P>^qEV HW[W2zSM6 !r(B} .a |Œ6L"^NuofKUVs O+TZXc0G{9t <[LvnZm#pAz۹=i=R>2 :6VX}! ϽFCUw3g.i&Y6? 9oBl{Ga4`q+,;m饔t |᥆5k*J2`)B.,k.H*p9^bQRU݁?U?,+JqBCS<率jepUM>9CfY/3?8QzQ6P|15f"XfQXS9WްBXٲFgzm̱;6[K 5 d r%ܘAX){X~2Z\ 㱗ƦWb$bQu׿ ddpÆ @DS_뉜=I <+"hH*Iёfe%)5]h9WWķ7TTEw`'ߒlr=ZOM5 gEpLwƳR9br00&{S1}R/rIAAR ΆɮЛP?G=B# kx?lF&'%镓.USO3T,jjUoWںdj9)^!JG gdZ,,N=Aˁpٝн$Pj÷s}o3ei_r|}FwۖA jȶ8w`̰6b'1eye# 5 t5N]61:c:N|=) hM=fN147H6B\T62&$hCr|IJAWT-+Y#3$ջ}eZ tJ^L|o%\ښk՘ϱSBߢ~V =xtٻ5UxBY\sL O+&[UR&OÇkt\%>wQZ-7[ҦH7%Y,ȩx*wonTH>.J*-L{HT>2ivZݫeShֽB&4G)+nphq95d9wrxkWC$:tqQ^ dFdto ?!TTFwkB󔧳#f :9*?dlEhhV7fˬ~ںtpb |ǘ#ܩu}֛ yO˚{h]hPyaBo|wuEÜp"=qD.-NC씊ε;`x?NvHNY3]TT3ݰ崭7wytd'HDiJ^cjΖqP;6AHg\f0FVNdPvGd@WiVdt91T˹⏚" c7 (y4s z0ˆÞܙlO!} @-r=17JSW[s2O0WSTЦV+^(aw`*XBI7J`H\?HNpSa]vK-` .6^w!I o_CX\ {ST0FYTƅj# ںX˻ښ1)$ύ0j<ϡqRwCP^7_8&Z}Mks+_~yE*5TXͼ-fpgk?K3%{@%w.P"S}K F6Kq RPw1e4q \8Pv&Sa6NHK#& t"{BcډRUƈ֨,(X_- € BU)أMZ{jwg(u ptN hNiSKK0vq00ZR=j)a{sr(e3{jONs1gԁV,iV]#r.. `z}HBd.nضAS%-%ԅi3nR͹ƿ9-~ˠuбrNE;hKEqGyqBf`MvpCvmG91nL>Q@9ʭ!pOor0ַ;_. n4=իsO<)#OXb@&x"uVӳJb䦠9|!P%jQ z Hɻk#'gL9 *o*f39`/;`"^0|Zɾ*7QFqЦJ[y3ۢ]{'ƕae`qFL5'OE2Q, ڶ+؏N(CTԖfߵFf_ )#on5Ry#fX DBZkp9BױEN6Ϟ Mk8% lv) 5&ʳWl*e]DnZBgHY"-# S#ͪ mp 'ZjHG@*Hѭĺ*!N0>͝JW`R5)lM ׀vOFPkP@;(\t~W,>Hy?VHڄdI 0v\ۣ:MnKE3\^eGA֋ ӳ7e /]+rW =U#c%0`k*:[߆7n ,݌߄ ,ӈ6, J2M6Ezt%lT2*TI:($y/0 #JkXNzpzfEܓYZ6 3XGueM]꜌6[aRYٌa 4 'jHy4BGs0L4IPwd=a aD I-@ A'`ߊ'<;K:}D]I8|Z[!9=cԍ蜸B/EYn*׀モ-1稢oD=aA>_F2Z^an٧྿Vs `;z1FVc1>ほ'Jj6=凪vx𹖔2ӈ刽0c:K,:Mk9[`6Y폢"<oZ=S ^7/_1ty.0UEonsbfyhLg5%av,װ3MV{fyچWRg"2DIA/cQeƧ26]:47R`Oې@͒lx?eMU%ja}J;/5"s/ *2n+3D<n bgg7,>k Rth_yc$92J4y Mɘլq"-IǁfTVo yXpc#RQj + ZD7hA7sXF(ޒg ޝ_oBUc'dGxs` *z _ř׿Xvj&'VWϖ( Zm(@TkNKC$_fqQehWdjK)ub6(sP#YHK4omN5 6\n Gc}X̮pLgܬN{ uJBuڞ.cHh7w Βpg*BcqGmr]Eܬ1!<$DʾZ߃QOK҈m@ၘQ9$lp UMŊz }e5M+'oĆiԻ:C vڟEp]\e튵y2(t[,XTfB-M21oMv)Ii#.QNط:t3yS̢lYfx@eOZpi'7k?p\Ve}6}2͵3 M X';jSMVN]^)C6Sł~/[0(>#?' &,wceFK?JvCQb0JY#ox-u(ClmCCtx9T^c"s@8J(ZY<&t||ȎXbo10@F[[BM]/G6 O0̞~}uv*MRXf-$Sy±r=X;A*#uE2tg7C2|sup፮-5,. ڰ;@ꇕVÖJ!DbORWr g#|v2.О<ȃ/nN^Tx ?χ)'+ɸrt֓ VC0?oA(䌶 :M=,C F}poGﶅ$&m4 f@/T,/0}s?t-wM Ж%Jγo3-mlBEG}Zf?wVDC{S #B=ŠLWBL8Ū9\4@7SB_?.[0m5 8NgzM#C:ŸIu5G|g>nv%c@ 'w/ܐur]vO9(6H`o7sV29_N;yPįBzqdTrbWڜ?Y llW۪ؠ`" _{W0ƅB7GaQw>87~2~*H9%[6ʄ"nxxဍL;(-a˒Nބ(sY]? ߏo"aNĸMӔ[\ 7l |5vt nd ξFC`f!e A)I"y\՗dB"!̧y50t(m"Y][-p w A bdM S9=$/GU1>VK\N8u S9Y8ПtM0 !5j˂3.l]'9џ= F pR~ !--LБ bl.זH8ndɔEDzh$ۂuV0e^SB;3y1SPИbBinP:>-= ~DׯfĪ+@Jh} 6_"BT3J)}ZژK'0\Y"\193F"~j!3fUa>w89Ehy/Tm*<}:]:,*Zte H=ug8!Un?Ʃj ,9( ~lvyٝ+dzQH}2mt^MD~nBq&͎+@7{l QAhZ"ٝ36DTl؝C)(ʔٽr냖%wb^ƯVDx*$|8Iĉ\>"Ujr_8$mf2G)UmbRu@L)p*44b="zo+N/Y(*vb~_g䬝W |:[z'iw~"֨w]KeJ{lrmf`}a1Ё8$77-/2y,l3 z s;l $+vыr>mY另emvZr萆[[a»gWXi?  Kfo;=#RߡNB/j PJÖ N#IL9\]t+{e,>*}=7}wt8_>h{" \+?uˎǦ23w4hRq7 ?.ϚUbC/J[*^Zy ˅#hس{epnUtWd8҈{d*'8l:RˏP*?z|8>W 1ƨebN5kN":7vzh9 4 UT{8fI`2C++s=FO V@D ۫67ծ2%aH/w%|)W{>֦ۨb(Qs ¹+luAu4:̓$ XT )cKLu`9qzZ- R$({$af;sĝw꘿/aLVq'n*Bz7sf.oD_u8Yw CLSOdVI3i )#w:X/[H b#Q9Q L΁p(oc7ӫXj0 "Q@mai YM7b_ .Ig&GҢ(w^X;#AI'[&VI>|U| rM[~U%#ўG)I.4x'M^faMIrV#52b ?GLzangC2srmO+6ski[/UDw%Փ=: J[xzN31;FKQٗƝLH& +N"?qKlz |h0|]EC7HmIgt&FoV tțq^vAO i/ZISŏ?ӝp4l[#km EŇhdVbk~y9,/&֪p؄n;0saA,ױQ46)?0B51|p}ݺ0rrӒ45TnuA082V 2Uc3! [6a#I0kQ Qwߢ>~Z~<60aF|!s6%mxJ|7#5VTν?Cߨ78d1M+{q e3I mzЇY>V<7-[o[[^7/Y^'J}ӯ@Hs1uyj"!;q|ja{vjfe}_3 l.U QzZz(ͫ0yvChiCdT3>?V1'{6Ůnn~>!ɵĐz½PWcSe&bʋ0'~1'dSyd$dcW% KRπ SI~ :Wh-I sT[mv+ <5c֜qw}:6¤%ۯ#pILq]a;(&&Z{$n *wAd]XCA?8.j.і#袭HdK|R|YHSzD׵ ~]ކL ]9'& u1LWwԜn%Ch$MK] Ymcpa>Zxr wn؞&K| POx@O@.)ؾmv̫۔ɤoȵh[%_!h?GF"۽DUqϻ2\(6X+҉=τCqib{'!럲Ɵ{ JEn#<)B_J^A[Bb8YG}HA`oEk ?gv1=NYj9nDMXsM$&pKH uȁr3/,B:'0CK]\p[Q&k+JcE&㎏pme֒מB5ysvTfj1UTY&yKa/Qu0YS>2r=,;mlJ$?~K*_%:}UWT oBr0!@Ș<w T.تԚ]6iVكV:X(7GkX*)~/zT~#9C$s%2DU;9Odl+C <Ј8<P38Uu`e|dw%15 Zw e48+P\q<>Dv rGKҦܯל6e\]>(j9N7nKG:]8p>!ߚ,8辶Oeq/0͘Ez)>+*xi9 o$s3-^-; s20F{wyj`>Iťw;!{r?W7b6{_G:+^I:nP3+$u,א C JZr741\1 nߙ?eG]-<>BaAط>SϖJ0sf*5 Ϲ\ ̷>NѰ^Y+d~ oC F~VGɒ6T$#D  (Ô\tS|UVxWEKL Y9W%Kcd,‘* N7e.T/W;82ӟ9ީKܛY0ەXٶ4u.̕7+Ψ+Uږa1b{ ;]_DX|A[E3m[XD>n#߄Tp}raTȧ"/;aO@Kc> In);:IC֛޸4aU=ŎT^4.H Hgr+7l OȗD;'UP*GdzGGGY.Mph1c#ccr@R*sxB~\]h1L !Q% Te8i1C$;ߤjy]⭆M#1@ͤJM!dMQxm5VI òӉYZ1Fs Uf'"iz(SYl i HR0Gв~8!6:Lw>)-&#eI3זMpv\O=DJݲM j$9إhbXHNJ00xɞf  0Z h]1ӳ_ "w`=P7s wdxJBGjRL (s\*Q\:5? sB y#V>)JA~H*`_I7`I]qdV;jeJ]2ܖ16/pAf.I6\[w8A!LVkK07V)p1_nڳs iOwj% z p9kuooMdksm[Ia*ppjfty ]GCлJ%tZ>Q2: ,iQzp_Ή d:=!*Y1؎vfDv,lBRU ~y&׎dk7)qx )"2'2خ#)Ѻ_Z Ziʼna"lEPS'%40*CTr]$['N> ÝF_{ !@#Dwek߈#bI ͔t%܈fbo l2ޟ _^ rjlp#cC0 S\YM31l-xBPxZ5i+YonYunD&aI\&y~d*^&^b@} R!B(98 N Dc1_݃ʷ\I 6 i~1""Ycx86L. Ў#Mll4WIK: Y:Lv#[fx?PS9e<7qyrcgLFuw@%җ_ꀡg)] SĬ0\[e `tshnOn~=MurΉ*@еF<:BYof 4Bo&m@pl*/ku3EO.Z3K=44Y5ffdr-beRcɀ d, O)ZV-%pCv>Ey# eהkmSdEM#[cD|1eQOgu(9yѦ z9 f'{j5'0~?VnakU/$jZG[PBZJP |2ǟl G{ĸl!~DYq}*vjJ^5fNfxBhoYfphsRh4+ G;Uا3;Re4.& ~,Gp>/漷,V_X, ,1+׀+#5`C-,#g_|gvuv\&@eX1 )fwr_6VbǻfNz/7(׌ J,e y]a(*DZHwlXFQM9YQ14LElv,1ٷfupŹInz도[LkE웮T 3$]e,cBn0K:y>>xarD1 s~^eVtϮRD?GɵO xg"]袛*0:ut=Ġ 0[9s L[zC+Iy6l||XvfX+s pAaֹ4== FPfմ.6l P$&sX: joPWf4A6KՏRិ/Q@-zGS?cSzN| cmFpldRQTr빕i+ONOgwͰ "ĕM*ۻϙCKb4c*)O{RNQ _pH:N̆. _$oȮvp&5thRǺf N&lL}{ ڭ nooȤ̹R2n\Gx亾̔D=϶|jcZ bOgeSt=Ezz2q@q۱_ ݊f{lsLB;3} .k&a uԲ´ bY:92uwm {|ѦdAš4eV Hø5’ oXBsF lf,a@􀌻fpZ̢=CB+^YC@Vj$=Ȼ2 A( S9V/W \qc0v;ۑ/ Ʈh\ Bch-Q!˛ /Cx|; 2!'Zuя"DdtY]VpoӃMY KnM8AR@wٚA]3(>1D@~| wΘaia}LD)D'Vo!UQd~N IV6i$1o=n pA]ۮ6JAoz9Vp^/$E|y~=.xi.j VwvgDsz5 !f9!@vՃQ_^)R˵>ԉ57j2А,`)IҤ>X {# HNڳAa\'PJ̍ 8Ǣ>y5N+S ؇h#A'%v Ҫ nW/8%?:_@T'/g: JF;ȡbL7EUN6]Hwa*S:Lڢ&u:;d>+_Au>EU~Xj)ϣ}s!lB4{~Um.^9e#WQqEPç5}rzy"FkirY(/6__br.cU៾r R-ík-ή?O &#Ir BthG%D8Aׇ4s[ _~VBxwTpMSc.-PHHd"j=>Pg CvN!N2>upXmэ{ $ӄqN88&եLY( 1[[K;YKmK.ff+l( ؞%9e,L ;85 RGЯhŕ{u;ə5z?Qb5<(U^ȁ,dPoc0XP*>"mԶ0B=M`Zz Q۱-f{UFc): VOmd$ Þѩf%uxgS#?)+yQU꽯j{g3 kVڢAPY$"F,AwS?ꉴnk/ Ekml?4L}pິihZ~=%s7N"[\@|"сQ McOni(Ρ-$do:kW 5i l'Z_Jd~o.B=BF!HHL:N.hHomc$9 94\s7O.\&Uu(QGM!C6(]LktRNY[;_fSz}G9̘ό&TM:7~7+t>MNeM2ͮ ҩZO6T ۏ25R6w7 6kOӤ};f#Tz}5)-&q03Ϥ{~Om]2a7Mc)̋#a˼6~^LvMT;F&YxͅwL{ ]/nAT!a0bt1h 1٫=ߋxxetxznuƄJ[8Ww4DeUY*[J,*]ڎwy P ǨR4R!󘊔&@3 Y78|e1)./v `WhÍLsԻjZM9|R kbбz !Zc>%CW2LrRn➦JU|Ex:ߤ-V$H#jd6a97+]\D+7>U{R?jš<|}HX o4SfyY #m7Hy>^Tyk]NvJrs^Us Z+~{׻X -;m(eӋIz qˑ+A,&Z]* Yfk-4kI4Qbw H-]Bfysr8=wT2qY~b[m<U=w0@^x%8,2˄.HEn]Dc:MP ?5X =u}<|ꁈњQ0d 575HGa8~L ]=sdLJnKdM QzrB;- #=w[5G}Oq"5de4Yr᧊kRMTUi`Y"K =Fj`.du0`wvB#뷊Mn5JJ6vfI:pgƖJIPiN,#5|~fEkgו&C0'$E`Bf#cyŵn̻b-x[N~7{0,dd=u OѭPSK{qί~1]S=XE*ްfh\so묁,Gai:) 0g!YZЛiJԀ^*M鏾#MAVN'45oj4kҗOG\C``cyۻ3UZ G'[(nk?RmT{<-n-S/0ԓjh7 +]" 22pnA(`GkD _#/0r6IGұZdI~MX]Ox7$)(o`ݭ3GbJ*tZ$_@{$ dr Fn3q6jPۏz\9@̛MUT~*QafFr2a-3XBUX((C q~2[K׵]ǻ'㶃@LuD$,0p Q8tա)YӰ=@U8|Z26݅L9|pENI~Җo=-Au^ԏ]F}`!5$p`DGQeF Í3ߵkԒpt ȕ9^$9&'XVՓps_->)h#wX ׊1դD n P쾛uЂ`IS.;"$C1R`⋵6hl{-$mـ F]'p)>*Ls S+0~2TX`s5Dl17x^߱[ _9c)&Ʉ\%#G~x=:vt-N+]Elr.x4[imz~ϚS^dLvKy_yr=ꞼB"hbj)5רŲ}:LBrJ .ЩQ: Kr.K96xk/a10װןhĸ@D*/5w[ɦ4ofl1J<51nSi6M(KژoRCvһF'Y9CK,\hGvuljJ<Iט}Nʂ 3)>;5E!.Z%U1r1ؑ3殪;7ryG+[ ~e9 &S#"lHR,^;̶8RAp#؜u+ +{w &޲)i$B/I!anI:I]7k.,B|;_&2Q(H6=bsԧmB#)z;%6'Jx AV'Q?Gka= 6 hp!2 {9 oĤD'N q6WɺYoZyiOЪ` ^;AT_֔ a9a-F$p'/X2YlB=ٞ_ .WF}*Y_w{!0?Aqކ^ȋH7~b;Uvd+ c_'UR)̷jed0;Ծ/+OkE ?uPXm w:$#Vz$ɻw:A 8YBT)LsCAp5ƃu߇ LBWDwI|iu1o)?NJY~fA =DLKYwae$>p#.G_Nr+y|j1$x_^iEiwwe`HfE0 WG.Kxe<9V5jun𕠞j(% D*wґpmu[uƛλ&SjϡP5IG`e53@f9yMl;S[0 uR|5.ݞ~rx./I*TzhKÏ1\V jWP<{LG+yet%M6eJ5_mINuvQBkK~" dž%*( ^c~ZK*Qo Hb>f`j_)#T4NNrؖzL%Fa$3DXpf+(,A ]`5U3-yuݽ*i8‰?r~a?,-$-3@RX9M ,K ̯yyIT 2#<|e Ex DꢽjoΙVEvɣ纃ރI@Wj_O}̗;lOUCI}gT[38kRف87IϏN,ЬMS& 4flR" B"֩t;BꄿAFW%9hrj#?mʇFd:S;̲gd467-Man'S1  #]p" KQH -Se.y[_O'*ӲSqZ%#n*([CX~pqtbB6黅MMV\oeV Vueu펐^ยXn1`c;C,5.=޻N;<'-^ 7`^9Q4r^|ڰMM]P`~Ǡ~oXgߙhKĸ.p!/&xS Mf4Z!_942|\^;c꾮v4_z Im!t8.s̗SOWTmp+@/& 4[*63@aiXrK큵\%gu *2gK/hLwU؎5xOc/ /!1Av2s10?nE^='6Y,- smz؎<+ƌAdcc;QgG.'KSNHJTm#u 7* :.ejUICo֐ͦDRc$Ëe2Ig.8 |y"/,ynJMq@$Mݿ`X>*%^ƃU`)Ywe%Q^Ѝv•y-O8cDr'{Zԁ%C45gq2cGa{>.BGl6$Ť~3&} +mDH#I [V #Fؓqc 1N6͝Wb~E~\j z-U>LՕU=Yc_"a`-[>#?!7N>Ś׭?R4Ǩռ.FK>I~ݰwB|Vn=dPǷ L1ܺ|Bbyv>tثm*@YpfPWeIG < 8e~q_#EV]2ONEq􌣙lAhD9=oF!aKQJA_}aFxG·rLAP"G6&hu6/{jk\ C YDy r'yBI70-DBCn,ꌅqAo)IPdW.0mo^| Ң,#62k3pvR)bfc\Ha I .ӈ6p#},h`BU"VȝFy-u^RLwOp4] -p"/]'\xͱgL1K!,C7M59+/wɳpw_ _Diܲg& =(U^F,t1yɕKivȗ7Lzv RDf+V1{PPBɒRćwzCpQ+^餲ʀYwK2`"ۓ8L =a9#wWTlQjw40Py`&7yg}Dîշ9훛 N)+ ӵG5M?m-*agzPQY{56^76\K +2.s#+uD +!;?l#pE?T+kae|^Fwd(&G$DƁm )b_7l =BZjOst@@PS]j)4qIGʕ*>H/xpC^BR>&]t_U:{ Fp4DZ*mEA#ۡE{[CPC\Ͳ)+iƕ|#]z@2% -#HEw e$vO3 Y 02kdJѥeuy:r^|Z8p*,u?Gxfqj;2 (!)JmRI4LIy]zTs7ݷy 6Z+#xvB"Eq;J5yXIB:y ၩDY3n2O8?;'yD͊c1a=9e,]))0ݝVAHAvˤRi%֓{GphaOB 9"$|D7Aۡw(Xq}~` kU,XG'ՕAv*3]iV\_5-7؃ E8lё6DNަHU>hǴp&==^s 53^w1iIU5LfZe鑞քMFlĬ*#3p׸tIE>\G338d)Of4LЯ*}jm.j$r8%MK$C;鋺a$'HzhOH7G*+`DZ&"׊>حqjw_qO_T#%ŁU<#]E2ӖY(FjTw]+0;6Lpw5R{j*Nj-&KK5.Fѝ\1 v%RdN;5g,m.!ĻlD}0VslFG*sjn'Ks] $kRRd8H Ơh m D+G@OsLs[iF;磰!Cb`yNA ԶK,l7>ߒ!L J7 _BrmHL1ԯ.1~^Wr N]e_r L#hϬ(֍\a>0?S?HeiĢC@O%O׷/ {)0z0?K7 )#G$(;"9MP7ltby3Ktb`14&S-1Ku =;k;X88*vh;O:ɎajղPI-%m!c Ϙ6` "K~.t׏׈ݥ {ZމܝviOgϗoàHtxH7}8̩‡ϫW\IÌĤa\鍹pk&څ ԇl 41}q5Z̈2-zj!p{h bw-L1Cu}he‰ .i M^t٬[L %]9d @i8~3e+]1Cqne*'"?x MĈ BStR[][z8J!o@]}i Z$-8h2X5N?l>:ܽg#k9-Bf4]kwPAy*{!2R$Ar'܎Y]4pW<_t3rHݞ>7_{$v[zDǎwq 0gQO0Nbtneٓ$oPmE,%,Z^JЉN Fj) B/, )7=]UώGW=*KFC*/ l @סxM5 Z-v 3 j1&t̪y̙1|SEn:=ay=i}g _գ[@a 7)D9#5T͘ Uq8M_@||\xX[5rxe 1D=Fjv3Ua r3h Š!B,~Ջje4FC >i4R?aJ稬5LHi1K/G(AwbY V+mIl DM fSWNT[b`TeK߷Tu>U-`LGwʾ.44ު^FĐ^u6t`dP̧v8V&{9h<(vP94XYtN)&E;iã|D{'CT񊆦lҰ`\UUhv;oBAw^`Y#G&'/YSnux͕͚} EyxGH3 m-RrN1˾c ??00͕Qsxb{xoLl^J3٨q%t0|K WG-b0owW`0W[Y1չS܆JHxxrg%ʋgϗR#6*u%oT*} km'U @"B0JÇ}7eCbvy4g+`hΣ8 8Iy1Qg~Oׄ'1>ڵalJ%x[X/aZMUyR* v/Hѯb(l|ZE VOR6H" f;esܬQ%O0Ľ۷IK je e )Җ ',dB| N2XqU:w+O"|4xD@*I=Qe7g1!;0٠J0he`F(&3M0(ZH,h(E`es|6Nsq#'7DЭ;ݕ`X5]@Oɺ:Hv8'A*~.KtEvbɂߢ*36(j_`I+ 6R۴jpqqд$6.m*A)&!b1:`~](S>ˀa%w= N$l{~:`:)㻰 f=d|۳ƳuzXXHϳ՘mZ5}MNջaLͮR[~1@K>\~/'o2۱> &8U"b@mv4Dx[+7"ЕAưn[K["iCֳ= mYrVѸXؐĢW~bavR`![Ue"5+7kb"=i%d>tT/0-Jv] Ի *,5ZH&-ve;PRЄזjp!w+W$ũ?QR-)tB.Ga!*w{BԬ J=1fԮy~t3.~Ԯ1] $6m0LNfբH̟c\k+SR| 4a¡,8>,!ij0>Wcԫ KDZR/.BYҸpH Cw&a+〖ҀtƾwZ/l݃QbuMٟf>v]y~%hx2s3RAN4/a$ջxǮ L +ǭ׏ 1#6L!.m>  u\.KniM9"Dlktٴp[RfUk@-q\ÀWB6iAIkk+߲)ެ}$4rEtmr#hHHL. pXWW&r+d$q)ӝQSzP>Yuoe B=qMyGqrj:^xMLn؇+} eg{^I-3$P}ng'Igm~o4U<`9Ki'vQhhY(Uޕ_9[Sf>IئЁ͙G֐*;P?:z}iz@Biri|麩9$+-rC |Y.%Jp֨BEtdVtEkxG@/piH>XJK ZLq@ʀ%aiK=-syC #=Cji|futeKiD6Ps6bW@pc {COwE) Wʢ%"[|Eg)׌ f3'Ӟ֬dOLh.'v ť| ɇ%iToj޵>d8FCKf?zG .Bf͏3KOb[|zޣ@ޤ#(veJk~63QLD!K e\.V{ac2*p@(37dN.H˧JH1EvvVj ڗLql~t_|րeyn'(_kߢbf<K##%ߥb뙝OY\h [yIՆ)^Shҋb[l͊IǚTXsΈދBTk#a0W0nAi*_Vnʅ'w0if6NK?KлQ~!!JB 9FTv< ԛz?"=mlwNj]< ?b1=o?KPTB:U44kG0$ۆ/aS 8_!z)-t(%s6q&yPrI"rdb'WL,Sɱ4Nu[ѝlu?k:fFmBL2aGƹ|=8 ׃w?GHn{KO W}@ \ZHW.DSZR5BԊprRܵ|wx00ՠW݃9lK8H6*a[-PNFn/'$ݳ|B6ԞDxUYEOʧd0a+C5ωڂ-ɇzN@E؛uchȘHI)i 4m"XZfiJh{㶡WXak4 qbH~9?Q(51H)%C q8 oNAftfd`z{wp#F1s2Vr%`{\`Q\BEV[",)* "9,OYnmxߋmlʷm2ft B<'!ȺNOKhhf|2Vʜ\`1X}ΔEX pE|yAq2貄Ȋމ/} |&P)kr+7jn&$qm_^?PPu1eoe:t`wɐ}QhFn}ĔJvsNY5ai>ˡy-Kˤ2X(4Wح+gkCV){VzuiOAygvB%7+,ꑏ\fvߵ_BJ7EFp*þ/rM<`>P#/bY#[h$ތk.J]{}/n2z4`1xyeCbk$w`lϵ:]z& l+ ݖ'a+wx}//R~Á9R}U'^O5f!lT6LSaa:0x7@[*k`zO^q ޑj}uI&Dt;^3٤ β,fa^q͟.fAwn8*E'DZ_zni!xX'mSy3 Ca=_:= ea: >XK=NR7-$b4PmB A @9tJC&$`pd[a;4@ct!5I-R LBԕ ("y(N_ooWD;  #H0^@ṙfJc kCUyr|oCKSvlos`ͧ0<<_ãbǬ@f0K`,>o{h"OQo6 4>K+f[*D49ydEn|1amz3+A"t 4./yWueQF0[_:lg \YB_ɇG:7Ƒ~B4^pۊU[)tXC:Q,W9HtPRf?Vl .i߃ՅJ0wŻZ{4^]?UArNd!?r?(DD^RPϡ 4`ep|.߹ى9FҳzKTeMX~ B[5EOL._:;ːMcPӓ`ݏt/mvk&2sS챛j4TnZB/X:4~tk()Y~O\-.'uōIZvs6}W{[G6NvpG 촧N^G8{$-ԷUBtTy5{4CZ4Rw% LIU^ƧFsnɀc< ho$ꢊ~c-D"͏e<82b1eiLaDB[G{#v$CfSfӦ(uy3)T$GCw⎛M-E`.7ϕ-N\pn;NęTt2ŦvBޮ2=GHE( 8"6qKNe& P+)lN'2ʽP[\hl2ʅ@/S]I֞}Ǜc752*O:z dcY~CvÄ~?d̸Je#b^W>m\Qk1(*J]reeUReMm$6Dy@;n6g$!Es CKEN>,.W@S6Q#/ GQ~+j3u04B򂉣jgyr߉ +׵MZ '0n_z/;?Yd%D0]ԩsauZ׷ QAzqp aďv0m C:{/>NR|B$W c^, еes* 0-Cv&` u=x| +4?V>BbV G=AJ\"1F/f gN#j&?<'/d5nfęD|B4=)DVC 0-^0 37^ưF-惛 BfKπCtE ٠$w{Vmc"./TcT~;7_de5RV)&fHB`xh 檈 e͝dY]Xz:& ( &`ZvBY`wǵsln,"hLfjj3ub7ɜf(Kk~ҝ9t2 d!;B҆7S~2&avqoCFJ<|MmVw+c5 kyf84L b8ğ?Y˜ Ǻ%a qW=o9H~4KaHwWVb8(AG2(q>Mk^vHVՎp 5yϴ/m+^  [hQxN@v의EQֈ֖1P#ٰPɢV`d1%|1$f_⅞ _fw'n*To_MHMA9.TXe"%3Yn-($-V:Lk/ D봫҃KI2hKt7jX Lt5rl[>Sǝcf5dY pv*"Q)뺺 -g$VL,|/&L$oDl ltG=?蔥%TTo**xwQ6"9^Špe^?W*?Cgpj0?.̍bQc(Β}EB0ET+}*F#f >{b[VH.H׫=S@Ȝl)6óRrnU%r.D=˘(`A4֙G#jb\TLh*MFtK 0Ȯtܧ{ˢۗ2|`c-FtS4!\,$mI+#]V<]fyt\e_'<+FHҦ&&8%'?iM`.sjxkʌ =+G/&t4E)o<9TOijk-^$Ҵ= g`N9+;*'g8Q{`=*~ jf_ۮ9fLL^"'J:a#T*L;\X>Jγ]!$Q$XuHпN+KgY秫q($J [ .'zRTrczAb< /'`ɤ9{Bzej @VǾNz1o 퀪.PKf̟ 9+F G{8Ǒ#=[@1_6]A_J1p6cDŽ"quC1z{k\+ԨҎA]{NH6x b{,>J p$7 V7` Z 9eNxr aתAU1v ]-]5f}AfuFZ7U+Baz1M-emRG^z n +2 D\/B,\M>Åx6$N쭈OG k@k"[/_]dbE ) |i8DKϼ;SQpE.>}'oAf!." @юš4{ ;D]}jMtݸ>v!ʇW^[h@QO{:EyB&yGQ~̢ܔ". ? ;XT2FI]ɴ+UݡϏz0kYeITlOyYxnaF*%QeK̑N_Eÿ%]\Xw6f~{75)}B))&~zR6`>,6 {H2XaCMD;01z^Kg^K9(65grXՄ}ʖ ?n[zίl">ga =?)p3˒q&&s%" f+Qjzf.u37k`!Fp/`pK h}rɒ?*y̯Lm[-y앻M2ҡɽre ALlD_ e¥C&yS~!9r`_n5dC1oEN9nu-A1`;:/]V=aJ_bQ< R¼ >X{BlJOKޛZtZ'H;Z_HėZO4 fb].[9O]8TCaуM銝'h.hg$ȽN@@B-SJ&e$)CqH2#a(·j?B#`)zژ}dzK E&b/@QWpHXc o|V#Y&mvo\&4R :.8_S)K`Opg`Lo3Lbid^Ee 𾈃r\/"4Lj 2d] {l~?E5:+_hswWϫdWL'3e+h "0ޢB< ҃0F1hflτ.~Fn p:p#2l 0y:if!/Uy$Vk/‰X>'`Hu[! >V\` FS]3X3H6+Ql@ix@t}pa#kw[n~C)ܺ&+Otq>h;v68M=_ }7䱟!(gwe0ϕ2AA7Z r rfh\ ,n'MyuWijh3=⊖͠-f-$:t9 w^:J#; $oPHb1mF&ǚԵH.mYZ)OIJnB!фor" Y^r,l}ShP_4vtjx`4Ods'ts7W.}~>%o4Y5:R|~ZF{f.{ʲ/xר)i.TVT_ksDmpVITnJ>G8cfk:C̮dI,{Ӿ^5AU"5:M"L W){qcpѪ5DP .Rz]T[Ld4t&gP=:2XH2L=ΜB~="TYS~8+W9 1d{@].¦*M*n>I]B hjZvWށpJZV[eSfA5"Aˎ{^q '#&=X=*Jw"'Awϗ!OF #BنȩjX Nakwn֣=g(!,x9`u@ө$Xo_'\AA-{q_Kby,{b֕ !BԲ մ F`Z1Gi{E p6Pe.JWWq9A{l$R# zrFi>ҬV|KcRŨ2<ӁV=[I=WjAfr>%wLI)odUZxN.mUzSI״v}ic:2Te~HoG9P !l.1E=+(b+|vzܗ/ob3GO$䜿[m1ޒGGO.ҢM=ehȿ5/;Nz>xc4 1ױ'!f\ʠ؋ P)'#.H&~EYWVr]wB,"l.~7B֐j6e}1YjENPNv7 u@ExґB!ZUU^YAy6CRH>, chi]g^܀HEO9r-kB&)N| /]+4-ݤ` K/55WF0pSяS]v˳{w;4DXB %"5}9?Ykb e Xg)*WЉnQGtĢT?{}L[`6t ӕD/X$ U=D+\ G 6/2Ėm]VBl&@|u(Rz*zK #v0%~$|[,qNJxD!4y}PjtDc3NDAtܞ[yE ڼ=@*dLPpVjUzܑuWkxC 8!N1I #}[د@]1hUSƙh}(iG>8tU?,?tkqz LbKWp'; wIC>8ñ5Y;E@xg @QȒ\}=y=6-v\:Z-֎MWnBtҥ o֟bI{%#Dn *5Q.HC*\g=4e9ӱ'XN98%3jYlȣ?jivh6݃V9V<!$y)qbe?U~hTƅS65YtT[M¥TH9 /5槩xˉ!/ *ƒ2aӦ;K>4Q4Ak^s1f,9'OV9  ӾX"e-.@^7_1q. ذciBh3iۃbri#ܼU6I{@`8-5T"9_9} 1Pb^`6 R7eQȻR}ndq}finp_m 6@/ +D8;Vs,\Jap|?eVo*<[_ۢ1sAo8ƨIN;)uu,%Nps)`=-=iX"͇t>[\w1s c cNe-9~ŵ]p'ޘ"ReרfƵ>$?7jZ7!EK~D3xXvwchŝh oUc_"~g. q'>,M8I .QęHwȓmv<L#a$$__@ PEu_`+C_1@۬G;avt~ //o1h Xcxr-4ʣU1#koO :j#d3_@Ul4%@,ׅ r+{ d8\4PB 1%1] լ@n rB8,O7ࢪb8LucN_T;a'>~oVO@ya/Pg'w@?qy^cn,ݝváh2R݂8 baQ 1k>4*&Bk! _R{n;pشz\ֹ܉C/=֕^сWz6ani$A_q Nv䏸^G`Hog0k=lX~}|Ns5_b\O ۾2]MiO+áࡄ :4Ñ!a1JpIvo+Jqs[KMb#KМژf);uppBT|?MY})f2<>l̕*7[,;~&;ͷQaݓ 160ZrƯ̪yW {IQ\9y>6_b._'rc$}'2ޝM-st⎚ԇ)\C{9gcSxٗ(ap>v!l/effd nxqQoK ?3t߼heh(!Y22]axYӀnJ#VN,'[}֚GOH&J.U;EP|]-'3نB5d=}v)w]h1-9ftz'턁;£B{F 2Zb\iaQeU?} nشb> 9[be53k@APfTplo˶ |J~R2jvz5Tr&B+s `c}re92J[1oZ;V,\C#?PQwM@&²@ RIN4PEA/?[|>n)CY᜗kH ` )K.j#=dyFK߈ xG*D F㞼&OؒlXG׽!Ux@! _ɡoҥ&[3,UU3%& jҥO#ϡK4f-uA@p{ȽyNC^?*9pD^i/rq H;6V'G8 n-W]G&>ȳ5fNs)aj.' PN2}S!Md`~͏[nW4j[RNKX{l,*vMZ|VZ ]8@}d& )|,_kʨէ)fJ>ܣ6e!g,7~y &iÞ (i=,j9+|4PIGb[ t5iX[]SFpkq=2)E#["fBX~+Ef:c<8/C6_y DwH{ Еvd9T'v('h?}؄|UP`-x?\ރ:?ēn!aICҚvc.`RS"H~\v\N $R:YJWᖊ#i_n_5"n!'k/CG_ߵ~l7qw+>,_y'2=p>6*j'8J>bt8֯f kEMӾ6F63Wr..2bXfZL6S#AaN!8mvn#jbrs/'36wlu"|\kZ8 IhyS/eE/ w°18 A'Ka6H _ڞΘ]FKiA+& UghNC:酪2Ϳl-0gu6 ,1>B*~3_mտ7?h,``tzmn"&L14ƚ"ax ,Bc{u =#SK+FMǴ̰l_R})؝gɱ_pe@ѰKdJ`T(j!T W|44 %}VnfW~p%|L_!(ךdއj92c?[EqO[è2C}.b)UhkdOt Y'@9NӢ{}z'-\CǨ_1F4^7o5{BuɮWde]:4C!O=OLOJ6ҡ,)I)1^j1~?+}F37Q.aZICjG.) jxv鬽%NON’̇}=+K=j|5KځǭXU̪1"DHˠ)$¥vNe`ϗ }n ZTM q #0&cRY ]{%eAԁv^cb\t[HFKvOTk+ Q)F (Z\W^s" CdwfSf24I6Ep~ >[|'IN&DBSu}fuݕ0ͫJ)Ja$3,fu9Z0TOk{"ywumZOesPZfA`ܹK"gpbqPj ޫżo3+AzU=D/6%|~6ŐQN` j;xi('&&[bR1 N۞jSƫ]h:-AU yuD~5xdתᚫV]8M4ȥ_3U%cs1 (thȳ6i ݎ\q3ЎpL6sCxdjڄE:F$f,B`I?O֗螦hZ-m l(^;zIquSA4DTę?!S EY\s+_>)y 0[%d>?Pl@{Ej!\Ҭ̪;/U6/SIrlq  xsy9 (RJ'xb/聶;0&[Һ8&5qe2Y ILU4Ģ5l0NA}$9 VTT%>]}j~Smջ^rv/=5ѿGЙ<}FU);7՜M"320óOhDQX [`_]p]-jhBWq<'|pl 5V)%:'0"8GΖ1ϞO @`7I/'`]jNƎ@L\TP莽<=D ]:>Ɨ2\,}a9a[b%~wD OW#`$w݇kr%U;kMCH~uARUXʦk&7 _yA,e[#GRŰ"$-S&,L4sדy_L6Җ1AEL4wTikwpnZBujH^#:2OaG;7Q3)N(2\iMH@aVX D" A<2t;0u%߂ DElWbfg,+V\oq[MPZtY=^ScW~#ƴ׿ܔsO}?! [B'ZI'r4G_zI :s[e=<1 6TFwE=ڻfnBYå}ѣBuţWx}(`U.UdI'*$0(<c, cJ7b_:Dor2-$oZȐ R$XUYهHSMFGos!O7~W!ksˈZDEM =”![gdf,ݐmL2E q=m01z,`<ˁa+`#T}=4Ӄ@)uQ}aQX.:wCБeZL:^^ bS0 %vX*V-^ek9dŊק'`s[}~q엡 \m\ueFi)xY8iQ3–N_ҙ%'[{;!C+Ŝ,r:-UJں~X%nm؜[Η&M*:(=.{iPmDT5@mFY3t67|xm%_rY׺l42܉%΂vie>x/jB |QAoxLS0Usnb" ˃F7N -B:OX2CD=vsi2Obcu/a;| @[#T0+jBr#q}1+XcO?&W,*Dq&l6qr@RZUwUT^F/9dxFͧ΂]h{ 0L[_ހi!: Ei}BVuN|,501xgePl[g.=vS-w"|5qwQ#2(&y?NBgԇ f`P*)2xƆ(0{շ/Fan^ enkedؤQj #yȰT˩zGcufc}!XGĚ6;ӨNn4L>Տ?DdnW̝ FGBu͚$\ xs_5\X.}tmҁRۢ"Y`@y6.>8>pzq؂0"ˏlusma5Oi&@[ŲY\kSN"K3>BPZD+cu`}.!;dGrYF@˜)Eu/HDzu.4>̗eA]qI-4%/&yдPy\==_PΟ)QUrR^ÅYA'ȡ: ++6Z~fDG|(zmɾ!0X$w|)9e/ڇ`/2;Gr1?G?=*3'@=Mye Rd5fc9eN]~^tu>aw^Yo z-ق sqґvm&Vk˲V |_,叴-10\w ˘gD;¤ (η`QdKڞ4qƑ ^V=HB՝f|iDtL7Ztǹ _YEl#?U,Vhp+$CZGǫ@w3e`H 9@Y;.(vl˄mM LUJ"N"LxCtPi;:;B135)(8{;ypV6w ߪ A!Y$ ~wZ =dE7ƕ2L@["br3OTB:Y=&X`M@~fj$,|3\  W; D[lrz-áȣILc4*W04򵈺V{k󾊻!WY2N@U=å^yJpÁɿ S5,56- aF],MAʼv|1X|ӯU[q%MxR- HnuSpJ ?NJ" XaiI`4XQ?{+ ೖD%>n|_gŜyTpT=}?] "~2aI}LI5:c3jp!{pYB[jYm3'wrk/maYkHd$JfgY9؊Te83"\tƻ 'eFL&"1[TF#U9rђp-S zd&NHg]V l XY' , S dAhFbsS1%^g1!zU_7=b閉5♖8Jl m'|v5؉m\ m1*4x22B9-:KKr>@4=(HgFK3M9MX 2 Q(*8dRN破z uT2AbJMdC%=NGRx.S6_=ϖGq*ɚQ O(LHD176Z 4򈲪4}80o}7+B?W}?NT3 ;`,/Ww`iK(&_.Όڴfa2J-~Y} Hi/i6L(-FiHks3AsJSNWF(|=-8RZ,r-bϧYbh7޸y&΢o+namʬX;!j*rGo!8kR~pCo%:Vg:U!Cx|w4 0OZ( -u+Q.mqeBW.GSmf>MϚB[yӣDɊFu߿tuZ_-?JOla=~2ڇ}E%?58s&!~g)gjS|D֣kOmIn *}CJڃ+e61 /6b|wk[}yeΌ޸G 1cH-ؑ H0g`+^ V{8|4S7T(CfkRdSQ+ ;)> kM|yNYm"4gal/ |]*PʝSj^ VW) ٩-j(Z|3/˶ɹ&ҸZ YZqdQ!!Ibc!JqtAkh+ ?#*x@/Q4?}#|l)&U+T3 ,ө 3,z&J T5Pf3$=d kW|K[39EI&t#+ӔpfD Pp2ve6P8\g)>S6'υ )7lEgE°N1 97!/(5X Bk0:x~PC6s|,gv4˨ΘNp6XU8͑rW>;ynlW+3Bk>9z^4V_~bXu"M8U789ӢPzp!C\~X~KA{ՔOq"k @ε4:{B `*(-Y׿L( 9 ~e`li*ԮI u8F^LBZ KT*snmU(Io~N6C uͧ?З4)\UI09nEvϭt׼.J:v0duPSw>F6RS,SMճcèƱJs9n"e04!QP8~9'Db_ "DC}y`چTF<c'~HiPZ-͝LZ8 Ie;SOlTzB߻x>KGD6~Ku 3khBE%./SY+@:b.>xWՀR)#"yCp=ּ1U$"rx {R嚊.񠹓. z }2(ԯ+kO/kܴpf^d)ց^Wn8t]䷄GtM- ~Tc9_;u{_c/0̥ӸEmU/›8Tze@_/LBE&z[$6\=ߥ5yR3G)¸y!FoMSCBq= :-9Jm"\7 Ǟ!#4`uTYkűs, OJV,a1+C_3]aQaIbH>\~%'g@(IO"<`:ЦYJ5#p,hA$ D w|3 &[PO<''O&S[ %4ӃɿE$ฆ`NPUm_ \ƹNdmbi#uAQA)Icj50VEAXmx͈?FϤI8,s\8FAպZ:ȟu_xef%UFptaQl5jep-y>.мXx%rywO av tXB]4sy Ɗ0|C r8r<׊mX1vE{[^WjN ,8ʱ'6o6?j_^pav}a&!NيV;>Sqԛ$x ]P $p1 9kƯ?%Z"s5 nŚ@h31|!bץE+9HF7(1śCgdmvʋ"vzNZ ą7% rWM>zy !$":i䏪C:Xl~>64h 7;yD(l!~;[Fk(ʍCsaC/K /^ +M_og-"COSU@^amg5yf'AD+j$ba@pjwtAa@7:V|е,h SQ-uFbAuN *翊51'$÷A~.gt×ٝ&[l@<r.O`IR%֋3)ifR ;rp O4bb?lϋa1,b;?<4M-fE|X!7C;\D+);Qb !sX+RIu\̉8@p+]}4ݽAj9~3uM1J21YCھ VVI5W5PV="C!@(~)<(Ӝν@ʔhzwqv[3Cp=Ё6ۇk]kBO|&2 EE9 .:F.c1sD?`XuW>$E8"L0ffbcYt]H"2nV+m|M͵磩{ԬUGȱecoKui[ #3n凐nT7=Rk'oh vxjd;1A rAXK )h 5vI4 kcPfw $bSEB 7zVgOXu}9S9'izۯm}~S-"'ÕhKɥEQ@ XfɾsK:ki\&X.Uq [8zNtw9 CMvoDEjhSjRZTenJ2$xDĉ=p FkᨷkX^tH0Ry<}aݵY a- C۩Kц2pD }oȠ3AнGiG3 rCY4Kp1FaUZӮ UԳ9\Ӥ6X@n9)v.>JvT~P&Y&栠0?g\뚪dW'HVUų7忩 q): )'8b\d 0:%b:O'PQׄgTP #1 Z?Bu'Ώ&Z9OLZ1"LGD:&jXJϿH'._檩5`Gׄ%^p&s '# s1u#&=KB)pJ<:J0!,o o_.0Xx]'l?fpcæRh P:cnʲsN5˫{} {Z 5RZ5>xB=|p$d5暨1is3zzZaupSs|N$PL_Xɘc0zV s8&BK_N|Zq/nnEYvfXYXxe{iGm@|_{:b,/G*SZ9{ ֑_qG3lK뿾0#lr-rFzpBN2)xyeRj QS3sZd8~߀zȌҟMsD&-M%2$(ᘠ$&jPpAQTPQ }b\vG}Ar``ڳ굠([݇˱64q4A951yL#yw~ c,1QҾ dp d 8?LGwڈ)mjChٜ =g8̨u}\?x^iw6/>lcꓡfA<apS :IBXzދ錃㖜7ĜGn-4_֞$҄ ڃ+:eLPbXMWUVܰJ:I_pad'PWQ:|TӋ}>` *{ecE NG+K*V4a5^cX -f8a'_/ z*-Zo#VX^ŗsi슎 2'pn•;p>R̹]9$N<L?IK%?|FAƇШ*+r#EPLV5 |$ Q,'(hBV j> ˅Ut bhLr;n7mu(^OAFLU%O|H%XP9i \!Kü6 ҌǑ).3V(m~tpQu,[{(ێr$V>/ nnNm^ؘ!vD4D`HLC Cz 33qInޅe xH*】ӋόlȠ]-eWK#gC(=xSu?F'J](Q> U>26r^N!}>`qS"SX}<9#;WPjyRGc Hx G1IOVJ3x\q7Tx-0o6CgƴAeql!IuP4^C ]_0?Hy>;(BiO٨QZ/Mx1 E7VmTE ЙY|QiZ޷X v-sjhkq6ыoJ_SD?}IC E#8r2H}#[S?#+,{nfFkqWBmG1xR?JIw?A}^<+4ccu: ꞣ¾Y?#jqszTc:^uJS ]l󀾿J[F ģn8^u(yxv(ݎ,uys vt`> !!-C$ 37>ii1)>m+2s!9}Ak|>H.A Yp#(vr YmhE- ˖>{ [oHkE|=јhRI ku(K]৕^X@ '"Y9qzE7d.J)|E\:PmKgD0nl}\x߹sUH[LCWUA #-yS< _6-gsb|1W=+cu0 7xJ]1fiI8ʭg DY:U~X\[À`7=9.m; )wF {`0@ÎjKL0ou95 7,^QȀX{&Z/(h`IѨѐ[Rda^.TDb}3K}I ^p*u(uVzo k?cAc7`@֢|5AufDX4eЇ[ p h((byrH|q1b]u2(?*X0>8ku`J$-0^z">495mO2trWC^!*k7l>ao'6Kn*:o` H'd 1`-![Y 6[t+gg}s-Peĕ;T# ^p^*6DLJЕ}Gfb}x^2N1b].9φ-NEXȍʪMQ' ]>gx+\6tӷb鎡ھ.0)%*$h# EK%d($-Z|-y"{J !\gA<`)EHȼW4;r Q* v UU&їwt}#Hvj:HC49~=s_5Bi]ߓ./b߅C{"Q Q~>tse !k^ұ 8o=Ni%/26Q{Hmz-Ax,ۈ O3҉U5m`t]boq RA[Lۏz;0;K&Kۅr [iB`ƈf^`zk]<0= :℟\=sNXvֈU"<\w? PT`AvJ2]K* k!TLVҭϋµLEM!Љ9@PKzܒEEY`̭>v)6f;&!r¯F ^8{Zx}ȆǾEN^-?DŽB/-k @-TZΫ c Tzd&]PC Ӟ+OMdnd)"Q)oNsS?2::K^EgUq=W -lOyIqLhxZ<Eqºp?1L=/˄JL4 wxX ffW2Jx$4UsE),N,n+@"x}IJkRt;NNIMoV HھBRj.CANlޜTMt}zbŨX'Vlzuk-#[&p4k]mNRpRpWIX)R5 7Ӕ41B⠰sꤶtVqBGgq*|21 wH4![ϫKȍե^Cf:xF]…꿎-@2>Ӎ.m/[%,tZOW~AnA{s ~p8|EJuUo8ꥎ3W qBP"HJFJ+lDnj1K2 ʠ.ٷnO{Q~Z8I #\7rH5fkNxvA!cdٜ/a1es"$HaE!Vi^<[ luHܳj$HQ01rB}.T7z-c7wхc ^ݼ":KQ$,CjRI֟K f~B `pՇ ؇ B1c(CE Z`5> ;-'9=IVI*E; juQ!6 s~ >.64%5wÙ2feP-@G9a\ )OؖO<a貵d1C\u\]>gՋ!\D!0}[$LQ-ƞLz VW;Kz&rJKa\Nem{Qup~"kor9"[>9t[`V'׫O/- 2!H2+0,'Fw>ߵl̘ H,|Lep4¾F f'،zjǀ\%Y8ʴ(Fs5[LDc:.MҏQC &;uojeK."1AneL(㊯A&-И9L4 ~\ frlF;AݶC7"C!!$PV*Y#6nʮz*!♷ҭEN_mv~/Qrau͑oȠ3"v|aQς-͒r]: l)Wqen{Qasi{MIrV#KC1dz.j#:ĨY %[ S8Ka+ǹ/|o6R4SwcTbaGCP5ORlG ݧUh㽯o ~ӞZ yfI|ZKh/u cP=j",57D VX]ZwLw&ihmxi߇[&|XSׂHkwtD+yu"?sZ%S H+9 3։Ǻ?YGۼehh(!Լ}PwpC$)] bC{ ^M dA|Hz]x-$a' }}Aɀd5EGSP\ATdub:y?)o@/.y!W_gV$\W y`$3&x5kQdIs42R탓/ z%+e?6UJ|W~pL-sW$Z0#,l[;a򁉩v<;Ыj27fo/Bֶq-nVFo/$Gqƺi߃*z 1Y]7HƎ&]YB<>YiZ%bͳ BU_9iqrO>e 1Ӗqr5Ϙ'XoYEO )<1[ 4)OvO*b[n̡OW͎ &ÒW+=󄞝b:^=VfE6թV.ktXVx N~Bn]Sie vˀ T֮9$]>r}V']_UyV(R]`E <'p΍e!dh|8,{9R;kdQFkMԠWN.W'βV-D@j!]ؽOBdtTsQ]iPŭgOteT3 U5rz~Tv*ZꇸS hETz!([&:[τW]h\<Nr3ҭ0s/FT\V֨̐bıTnXմ=O&y:HgP|nJ#ZM( 0à3= L\ WtHALԌkuƃ J}g [^=F +v/;+/QW?* Q1%wnߋ]GlA|hԛ5ިQw=hFzsgĽPcH-X7]V.3.)gvTyRa+m豾Su+jȞ)6uk c,@C~p)%p,;IiS;HCPhA ̛Z4/Ɔ8 -V/H0:vb;[fJg5' )́2i1h Ҡ֧&t^/ߑk@{!^h;Sn.]aPk&B *' Sfjm=S2g67_(h_b"^>p4Sϗ['5I`w8ic w:ڛ}evxIZ?'R)jR=!*>%S1ecS].N' ETs>oT^ OG (ww6O~{&i,1։} Zϒ2'(A"iP܎x!9VVC:>`a8$eED=vj&Zd@Wgs" ))E[w*lֳl;Ҁ"Z佺rXqJ<>&=](DCCw/lV>v3@1r÷ RzB39e^3̩3klsSא" "SiTnh`Vսu?*ZI&[= [zx_*h ]|N }~Ūm!Wdq8AW[|+ۮŽZҮe.D̿ݔzȽN >mx7X`u5G` Z)cΊ; a?IM*|;ֿE]Bq+C i\9 LXF$vX5/Y3^dl Uv LItuUTL>VӻbFMRzFKN Y;%# 6:ebBJ n"V7,l% z*ϝ ]7['rhڀV|aFxދRgqa2D&dNwo3xZRM¶Ї~L9dV =O8TgTd (yC==&i*!uggyo0$%T]2Ҫ h CFvaBeiPJ "ti-m&4!I y& qcʿ+R%wRHn.lWDDb"GQbk!|h WP=aj&\Hl $@IvO\2g,~2`4a"qۺedMi%He3- VUa?E˝ ɺ$f`Dش[ig>۸W2_?|i!\5z&flLJ蔉jKY2Vr/aѥGWQB*.jF9A\0BY7ḓ.)T(vuυH.l=Q<5#Dr֘FC蝙2wNa#?!4B^v2o?f9yC;FEbWHwJO@QtpU6Oz+KUŨKxMrtt{Fq.Es- sGt/X DZZqFOZC! c6b¿ \3Z;0nY O(4 {ōaS&dɅ;A1ܘr[6了 kj|mi9J4yZ~`u 0F\QCZ,6/ o9 97j>igys)k;gG}݄;,`:1e5>"ho~ (SDtB'!^-LB{ZB5tp ޥ-khEA9!j-w.rBj@zÒ78w~A-}Ak$|'z}!$J]O/F/v Eѧ#YʦRk?cqrY`H$VMQ=}}RץO=p]6u:8oYttA"rbM~x%E44ݘuw3sr'BSɒZ/W%Sa|Jebz@ϋBcj_DwmQ-Dp&o6-WR~M"=;Eڋ+q)TEhK_~e(pPf:OJLhJ̢YX_{IJ fADfi :۽.h1B.Y!^lԲ6w P/Sn Q+(+fZNx ~OwKq+cxNJTL0? #5-/^,e#s7d[Ƒx78OIjpEByb*;n9+:#:AG$BHSA[:OkbB~By 8E眑 ᦈo/I@!4ٽNF$B3( 1DdK1Ym ՈRQz~j/) ɿtaS sN_[7 kUL> >5LG\=%$(eI,ר)ڮhfLHgov.ǜT nf-ZwT=B6*e%%{\VAz)PvM ^\4v;P))QPAZL[hZ)E:3&${% z *_&.6TSiQݼ^}o@=)=%2(7EP\BU=R[.+"e[zHb 1Wuh_ʻ׆t*'}x%Dhy4ׄLL!I:qha#wxg(GT`ސD*u/G+t`#쓀[ ѭH.5*%uO[; NdLkqHPST8ȦOWeZ!Eįw-!m(SBFG2ZR9:K-% `ɑLT_PwgVS'b7M.-]""(fy%lЫp{R}@5RgU0fPv\R?0&ʷ؇rs8Iَ~aљ]$ķa[zVIX9ZH|zccb$RJ T v<Жk*d^4nK@#mZTЭ}Уn3q-(Yi"p'L ߷';C ŤaEk#uqJ{ -`H :o'rL`0LRI Nn 7 S-J"d< aG; )ܻkՔZ XRnyJ0N|-,$/jPYQDM% auvԎ]nB{z.5ENu{ [|b@<ҫqIz.!ne bÜmwHw>nn-m*>kc=<<]ROjn7W uG,PƃElR2pR3}VOp_[t  "zn.sG$lIb>ּ +\ZSj;jTPP5\ֱ" ]ͯ8 }bW7w$r>,JGS}}8nik9lfⷯTбt?8®y;ֿbU=F}G(jYT: X[TALQ]gcԚ4^qTA h<@ºoVD;Y{;1INH3"X ̩X^ӾtY_5/d~jLhgE}ȝRh^1Ռ_0*h&Όާ[CK4-/B3 y-F/ׁ<|]'ڒO?uD8{-O)dPq''ʂoy9?0Bi1?(fF%3v'e6920j_?-gs+&`kPfnEE=vd$-2u'E2QE9a> DS}R<׼鼩"6?Y"IW%$P_7Y+aMj nՕԙcscV^Q~K10w(&و2c;>/ d+]m {1!#)㛄Ɵ~.fԊQh#w}97[s߆ZgYEx畔`.Vbc̄`B"Y aqI= fL< sfUg/Ack"T}`i4N6m=ν>ChSPn;p<2mbqL珪zM+d7GX(=Z(yƋH)тmR)]ͮr{rk ";U$UˑrP[ j#}BUZ/~'pE-DYq/-¤Y͊`:5obeIAwHvHWjmepշ/:b/!66#:tY {#>VLxƚv[t6AaLhBzI)ۥ%t[R9xX||. .OdIzr`Vzi\àŦITkJ!A=Po@~#L6UaOWh\ ^]$̄k+GJIQ Y[VԢPZpTStp!b`ˎ\^b"DӚILTgPIZ.WZ\sw25_ L`ĕ뺷n)ircRzp.ymZ[ˠEhwYttF7ѱ@Nzpb;w.r7+RpXqU# _tX9 +d?ww *kQ2iWi.b;Aە{8y[r:}NChݟG":dl:IH~ ~U)q![RgDOp,VR/"dP%ƒ!WQa>a).xg-ۥiAKH%'&T%]ïv?mNb*7N?\>Iz|I+(|VY wQ2Y˖Nt4X]E`O4(>k38:AcQ]*񳄳ޢ4epT3HΊk%aV,yuF,+0Lą}?>AWGv8{Flv STKׄN|0͐|* EfQE%^b(Ot# Cdϴ&< b`P2&E9AB,IKSF/tj" KH}u>_5]͌VDF_"Yaݷҩ%'VG![|oMUytP@!Q3@ԉXH2"%!?`ⷼ$l"V„} X,8PH6K S,08%u1"㯅tPb"d)SG-h&Xc_p"\nnpe!hsΫPT(!n}- c}DHյL?W"_` (dP2u¿qma_xFwqn|1=@"\6R2B9!U|c32n蕤;ޣ9/)H;RV0j+,1cfnAfGʠ?XJU-";1?ܻ z߄JZ~D|xz_e^ğ+@jcJkjiRqN.ĜJnU,+7Xv$gqcF?҅{#Wxjvct:,ڹaZ7.ayzl6JnNSauS7Cok.+˫{KˋN}Dȃkw(~3< r0ʛ9ݒ12\1Rfc-D$YmȎ%&8|Q|b`~>d,.$9+S?vK1,jշ Уę#yBvnMG[qoZߨҙi@)];+w(}=:ld]*Z<{>jnd ;Ӗ,zdSNx$^8ŠfwФ+62~2=@t^M1=%}n^}yD(uD.~/B ksi7 UuP Z?wds Dr=oixc.cа )q"X k֨ǙɿS򩞖x.+VՍku ܥRCF;@@}0_=rn(iȩђU%];.zԼ#g~w+5.>\`S95n#>U*'Q^ʨ_9@F!$ \5*V"xtif>r}:+b)e &K3[T@P&iǛ[a486&>lǿ1GZ)@joŐZ4-TAv S{JQOMɆH5bv烂TR: 6qK[!ȕqUzbv;$Sx]BX6 / QHߛفB%@V,?ب&c*H@9eC5VITYvoq#8zڕfZ*ނe֎a`>0+ ybH ToybFʮ؆E+Pa9ff Ul+(Knd/e{6u=,)ŗ +I]jdxx?dxJeZ]X%@lcڙȩ)YmVݪ!RMv/%^ǒb 2O4"zO=s)13 Ulwе zF,kž-03;;늣 hB>ȦN· `; 0E^_+):Cz5d.|a/=|=Yk*`3 rCFn |gm4|{*$أ2YH6KMޞ~4?xM=mËN"EaHicMgb>(.zG }|PdRKwWާ02mLjj-ڠf9!\~$j?{>CAA"Wv:lG?t*-x; ޮ4`H^ THR@m} r8Xլo#EsM3IeId Ӯ@2{R(v?`D$bKF7hn~ίP$ ݢؗe՗C,}QW+i酙@n mD#'TQnƧ7`)Zqt7 /_:"ڲ5(31 oW:r(hVB s0cSn (㫅F9,]H*-'g]˗F#(_w_WA@Lr ʾI|JU՚ʟ4eHl8%bc?y9P/U^_S(9)4l8l%';߷ 9(uMv񩆼qXz-#Z zREY:֔[O[jŠ~S6b˶`@Hl6,g,]*zJ4CÃ<4-yn隒N[ g;n?:owUy2>gۏy^yw Ю!-gkugC3\m{` n{vcɴ๱hOq lt2spHөȕ#T͚e7A1tnCcضҽ:/dU(:c kMl@(3ǻDr*s3'?| F׀S&͟5n~.5=J&HG5IPݖ@e!Jo0yb”4{i5^xڏ &{ތ3ic@ V4q+ހ4qJ,}I6k ߤ2u 4X w P?/{SSe^2~v/g즇B_mzwpv@J@|v}f>Nw 2Q<[_%90’Y0 `ϖ 6TR6ekjqVAd?es~ztYA 2Gs⺶ jJVP>t1H册'‹2o֞} 'a2%@=\38C/:AD|V Wb4@} iѠsL2D;5X7uwE`XvEP腗sro/56&OHA2(4%5@S6O~i+^lzZզ {vN{:dOpZv{7oGğ˳nutըbc+7J['Ծ&<Ħ/[cte߰42 ~{SȮ_2/6^[o0frb 8F.U{@uBG~jM^yg&Au)=:°aQ}CbH=H( YPG +*Y1V'." g 4t (^̃ޙHmm ǾƛC/T^( spиOaUOS'8H׀1t($5NxȆfX"ؕ.+g:EobCIss CefE= (g T2jǯ#ㅠǻ LL=Ƀk_pf(K.VIr49W^aMPT4w@oBJs]lԝlN$cŏEO]A^]˭@& a5'`X:nÈblw*2LF7e~ݞ!FZazPX莰(Lͼ|́VQĕW Q/)tM 5ޘ'&'g{C81mDڰ[ӟL~ԕZ#g6#8G/+;k^r@'a~]VU[;2-ē*^r/<ݧSs? =TQwſSq*4@HH^jL+8A"0$@@Nb_3985aLnW[@!?*'[0.| [ut24ik*Mu*?dv㘄!AaS>s :wo ؄5xKm.WD%kʸC:-e*A4rb H&۾-3a9[DAk^f`pU?,, <(_gla:A#F>4+ԼK*dN!Y%^.'NnI{q{fy36QQNn\M(mVc`;QKat}Hf̿i0dpEf7aC ceūMTKbM Q*(I*NgW6uyJ3"Gwpp$n}m/8z{ms s1=1a:EZia2oĦ If #EBm2c:"0oyS,͆JQ0u4CH V_:nˍxߚ3\T|FQmvi o cp6̍/L+:2B-qSރ+M"L>SKݺhzY.yàvk d?@&:my`<S2?( ,MÇPR2S "go˙)Qlȋϥ\q8P=3%Wp*r~X=OnaHMsm\ Az(O@IIFL㠨UPxcB%؍퓺ʑY&1݆.&TmI%#QG q5 {uy5^ ɍz !s^HA5 =­UB\4^IMAnU+B{ߎok.u&2$}i].}}n;XLj:a!"+VMn~oe>F#ή?ݧ]E (Ă#gE¬#۩&L+y sE|Ai``ѲB%3Y9b)Sm6رE&r܏+BV_6vc [ЇiBe_RzFw4L$rx[+VH|v7\Qzmn 4e$o|R1sH.{ڒϘ)O>RIĹ9y=.6 `$D_j%`dYnve<"$k%|{R6~*Y׈{Wv+Kͫ,ypNm1ՂW_eQh_8L+ nL~V9*WP5ifoڣǻˆ@Qj+IۨK`]"M˜еinֽ/ngBL#D9b?2uta-e_[#D;!)vI3m )c5́K'w$r7*XW4p?ʕؚ]KZUB3 3~x.Vk?0<:\ds^PK +Pf 1BQW.=[sU@o)YL NeByt˽b0pTbg6K筦iB!|m{o- !va(3җxCE n%ur6-9 {` SE?eZR! o5l%s4<쌌B ;Oc"HsuQsYETd^q Gd%F}YpJطG#(} &F[q00ą) CIq%g29,*Ϝ84Kq7j'gXL/e/jJR 7#bLXJ¾%W|~vIOm3x 0zq2J&/6!ʘ4 sоpgBm_K-@Hԓ|e;_tޭ`+6xy^1~_OlEۣ 7!s6 jA'2ԭsxpw9LUogg qg=КL#j}Z> *p\Wnw<$B0Аԑ,aqtq)*Q0&4@VE \rid"HUlb~`:![ `/Yڽ4ӳMY=wżOҒղΙq=I#iVceZv<('z7s5xq6ֱ.#r!xry]o:Dn|=] Wfڇ׏zS*W]gsƫdˈ^ھm6td4#*O%"(:Y7XjU^J{bzT pXCz\n Ȝ`iAi9yœXq0:ٱֹ&AS\Ч4,t0 [GG3lDEjSY M"@ƓDA鰅eə}Dv2]/PEu\U+:.fuj!ܵ4gp)O7Z!0KW>X /KnxtwAholl$1j0j$i1YeE[E_ `DY]~VKki~Ĕ.|¡l $ԋz?+t:r3s\m(5>z p8Y²nbը&) $j}_Lߠu@,R^{s$N ڼz"ֲӗd(rd:\ȚFv`Fσ.̃qfS0_=m%Y_o®9<%UCWKM3F6?}ia+M$Kr8!R4imi*X?lf"cFAfGtI<3"h2 J+M GvKNM Hzbp04$4eE/ rCt-ARM` l :B}Z{(x(݂m4a5}fdyliPD.N$TlzuYcyZo&mK8$`A ŅM]~[>yp03 1:6]{^f.zr9I~4Al ׮#T̷lOp#HncEd}0.jHlLLiO biϘ&] B3 I0 j`#t~l.lFEyZ+1ب_g2}(I<|`/(B dE*ƪ)wZ?zOC#BB%??/ @}$|ˉuΰ-@5ufc w.a;ŅEeGTD{n%ؓ(rxaiZhʣljinqx;xvLD2ci7Pf9do"`?/w֗?2LTn'0!MS~qJIӄKwM tFAϔ@NK(V҉-#~{˧)v&LhPsG\ou!zY ^|raH.4Rغ~\"9/:E6Je/4\ܞg]+兝xDA҅)/ZZTwsTWqF$.|dl_EoJ_dy.qlL>Uڐ?F]=e(Q/1yF^sdPڮtАVVцE`Ywk4Ƒ܋]"xl EU<g0KT[p=_n `to PV4{^kºXǚᐏ}hU{BgW,&79+Cw]ߗOު40TX{cp ̷VZ&y]3Xs_^@b#y)IAY; ՍMզ{)b,ϐҊ=rj+F{nx8i#J#ȳ7at|'!d7+>^r69TF3:yBl:Ac@nĖBmMB,q@݆(+pw/.a)-w4ȡ8n|R04H/<،Dj=z筸ħ2:H'R^(>Qѝ"Se{s- H D!mOYQ<9=0c{HU B/`ɸp e29NCw XXb$(VI8=%_B:]-&qiJʓ%- o )X o[?B줎tP3wDKNx wLq%7j!A ШYF\@I@nj."~k"by~!5p @!u`3X $7gjp)L x\^cS2oA, YkKOU*e ,I.76&[L4d ^4솶p-C.NZ=7⭚B]NnJ xn䧁cH$Oyn^qira4kLy.$rQ@8ؾW7*~_ۖ!&oc/[p= '%1t3#6#Լm·,Na_ *q&0Hpyٙ}g̫~9Vwu} (̰2OYMqQk9 +tcLO9#d$iBw- }bF)!Vbi-ƅ1wD+h볉7ay19aVY"ʢM:y6l&zOܵ@,,_q#T Lt!) =[it/*; NPǗVs#Tz(G}}PSRrJ?OGPWQk|3c␯whzC\|xNjșehEq 9"3QB iwsQ-FKBe~`s)i;>чU$uųbtT^+уJmᭊf|Tې2xEg~=H;ƌ9aFԴtୗŒ/D-C\8C^,IKjt-9}@Sg(#B:^cɲd_G2gu AE.&6;36@d mb' bvZ9숺y/,GhOr2Cl5'IC}a0꼛/W1B@ןs4#Q>ģAj.,BbytCPl.ODU9C~'yY-y.Xaa=VfT=ǻ|k kfݽޖB{T S,Z2*Y*BNWeJӰ ox}[2tm^AEi5e?}Ǿ!66G|هiK)Cg0=AY mÃ޵t=) ۝sΙSu#qs=XcĈVCs!4Ɖm/QmzgöIMq;#uCIϢcY4uybW{ڬ:N7Kʕo+]~SQB:4nD@N%cʓݽo= GNY*)%TN&t>V%?y]ijF6f a"y12; 5dD*F?uInrׂ5|P@ᲙqP", 7dbag!,%Su7Ig|W*9Y,"zAz}lLGtCPes~ܙxa7JJp3-w:E8yíO6< f]ЌwbIP8/0Fvz {ԍ"fC!(lHE="ڦRԡS^9ϰtټlEΕ2;okK=!fԽ֢69UUvr,O R'l:gʜQ;[ET/):ysF ˫wSݔA(-~d+7 awH ]7{ƽb'EÌ/FznrE,񠨎C`fmI颢3%=, ;%~;NmFo2Ӎ3B!5vYGlb {Lfw*ڷ\N5,rrP@i~@=pz7ڶnu|vŦc)~yD%bbĭdE+Ma-UCf|@8 )Ap_ոPXZH!W3͵]Ӎ {~BJӹ0~fj, GQnҪKO+F}[% !t[0`lrR3ي$jH<ڶӦbbhlZjN1# 0׾gJrfOd?Dt.*rr@VN>b w4pD $8@V #pP1xk)G4n.?N#dKbpݜH D&)>!kµܸq0) y&ʽ0M;ZCnawQ _92Eˠ:opupɥt\q`*"dF#}R&F(a#;ty{gKCX5I=Нl4 O^l,(r.HhzP͡NV oU^& (=n}~gl#z01u>w# )<ϊD\ `߶c~*^?6 H A=;EiWjirfTd ݧ۞zh)D3>K$]m0U£=2N \<FͬaVUiZ>eHr{.Y::9fTY2V-m C{H7^nUIdʾ5w"DШ{sXsU*]i!' ѨjAtLн\utJcC{uʠ(YME]5psY z.stpU nF"1Ρi.$/mX OKl]uxDHjEhטmW]I"zswU 4 7ܥ)yJahə+ d Pk(D _?}=@JVu#Γ #CH;yL'X&M^I7ƙ^AM>RD2yK&zMUObHga<֣hׂvT:{v_ѧ~M b >-ZӇA1RoIk:ӝ[I"5}JKWԽɘRٺ/6Ƞ {0J),h[D~/D֮'JIE&5vwB|ڐGD3INd :=Yd q8-ǍF1z 9\2x_mѸvGmی{v¬ CΧ"ُu w!M.U~¨DݢgB}y0cj [JVF;9T7LУݘI Zs'2=[f YkG;\oz\j53wL+=a^P* 'ҎUioH<3[CzʝĞx3'aΗ x;c4 -Gu8dCߩc?lא&w2Mn@,PՐ8a\̦d_.i_ pſVPqXi'vs0ȑ:9BB6&L۬Q;ܼI1D):nxET$NT=;B<ҥX;I൳LٓBC/DYXb_Qx:"~Ň'{ay.Yhh,J6 rOF~rtD-a0ǒIiA3$HV8-tB-} o۾y(\qezGl~vcd?)n%YHf1=ћrdz9|k< OMvA2Z'-px=&9 I Q991ZXh, {XߚpDqdL mE"n"ufښ=IM*jzP&'Lj  ^ k"G 8ֺq7E_$TA-f:.>zJI%>)Sa%/qbm]4 JF#a֥YJ0KxyAz!Tl^(!bB@_x92δYۊC{@0zNyxj>1A;Qb0`C@Z\8j,^k>Ǵb c2{/3M]7St8)9i–g-vSOsIYAOv@Asf< <۽,=ӉoزmG?OKl8Z>JW)ɑ'ZU&o MA7Cђz&={%k1C$ĚFOHɥ^r-lnv@T74Uƫ̆'NX>S(du`ݤg?,(1$P0MTzΘ8F!lEkx+ c>e1H pen=_0n`d&j8sq?Ԓ]C۟Dx@z̈DOC%ґ~5U~ߣ%LU jf9x8"ay;Uvx[F7b@XMtydHY;ʬK@φTfRvE :r] \L~TGp)m&Zb:Pg+ezw0`Jkֿ/9ɬPVKJodjɄжz5 `_3&MhGClAOt k^qC=J"4,.} A\ v0d_?br߅ C=AR b{n`_ >cAٍ%?6g% F",,2+?m>_UrgGFɃ7JLz\¬XAZ<3A1Vc9P˜x#?d(=udko@Cgujux,^D?~dN^Z}h.o]&>ŧ!jA| Dq_/"'#4,F.%/TCZ̆y =S{> XAS"!/50@?>m⒕7%BS@ceR3=@'>qyUȖa?=mtPbqVlZvou|VM^,J2MpĈ5 *P 8!SϏsH `=tRUљ;w>GMI-)hü) ^EuB~* < ?{bRP*u5dz,Payt~RַPf\L`Nzm8'b KT\kBw(nw-CI?"Xx`T+T}sY8koF_|4rEN>4\/7r ^ys|2CX/UGzO.ơCN6$ ,`J0d5Y7 ᅴ=" -H:[Ԓk)Z_Tb!VV@`8)b>!ˮj  J  H: EN|oLʦ<Վ>$"&#*KQfJ죲!)Y=3VR۩!o}QjQ2k預m Vl /iijBS7G!,1D5CvsCs02le FޭZ8;Ј0z&ppSy;k/EQ)J|]ݜ53FtGmYoawNxH, >בV硋 |u1Ȃr:ϼqAR19R03Ѓxρ5ޓ)0>nFhYA章'mn+2RϔTJYWz4ElB_lC>tUwbeW%7|/Jոu?%}b$smkz&Sm$9E~ d,<1WTͧaU=Nn}^꽧J2amz^S 1yCNŇ'Kц9PLgB]r`-rhrAlUc;f2ڧw" qHF:,q ^" b{;ΔRYU+:Bj`'Ѡk "Jԭ5(@C?*ձJ.j y= huw;kXHT3/LmV7 4qı忰# H喰I-^XbоY~ ̚'h:c3 tGVs`O@9N=Eif \Ѐt̏ ( (uwȜ@x|L7JN?H )p{T2Wox?+Z{)c<qIV!2W$#j>ɧd$&+SQzKK\Ƅ3_EMoCq-@ƅm PХR aM/!b7T E}"9Hi n#5]a@c&,Cm:M0n{fћ,@ zz4AD<ς"#ޗyGBej!rˁN#/zt/[iIFNj?pLqzj$,{1T e p=ۏ]CuS15Z Lr"d,Ң/LlON2_K_CMI6Hhj;oZV~bfB)BGp']Zg>߷+㨧m 7249l%ll׭ _qR]$- ئ#bu[m0O) 9Polrx֣A 2nvRQs}.rg+߮+ `Y?7J!.$l xQu,ŕ:s-կZAnpL\BXOU;: 됴Y,=k2d{ ڭk>p<=̘'U|mwhhs~m Ssw܋yR\mG@]Dҕ/QVVyir-{2~~㖬p8atM$i"jcb]U ~uG:Q@?j|`Qג+|D<?x('I<ۼ<1DҨ:gPqrt=@Vl],qԼh _ (xˢLs}ʡ@ WՍcnn{hK)0OQMN*tjB d=@8 d cŜ0H$kyWf!|?_Fc_U*(D𝬄o~.#*V_1_e>o`"@0Zɐ/l(' J>P# U抟f?K[XFZd,ס{VnY3oҠ/<͑<]*OzA0\W&ZFmqг.WbJ aT)UF{>hfp cc?!_u So65Ohw\NAL$y@c kיX? %?$[+l9}TMݺ]xv 1sVe [v)Ӑ0CTd#&i˼(*['aVl ,kj0H v)>[QGKä>,rn7p.bÖl=Ubi mM7 RטDŠ;:0 {+~Ǜ9f2ɍzDyHfn|/$X>S_]vbO,WJ/9ߡ˜:]-}F-BЭ~Xxc'Zf`ÃUT TkN }w87<)QC45oޓϻ&6"B[m^eѵ,[R;\܇lhc'6\;$mEXL3L_'fj'uZG)+Ez.ݚao"WR}=-߫!T UMj`D3^/1^W;=潫?Y|Ȍזǫ[χMA B`U4zQgZ*%! T9gQ*,v*uC'z,= EVü|G‰EǨCd9=84 ͗jҚc'TJ䗯މJN|b ddNZ*Jׂ"ȭ=ti;y_tt4٭N4*&b6J}ȋUڧqRBk*]_BH4'6uI'YD*Lv3),~Z NCUULJe.fO@UW1kQ|#Jح86̌0`5 >hy2NЉ4$K:=jٕnæ.߸8OSv[T;j QH3* n7p`;}U,VF8jSDSLz`{ZƜ$Lc{6c@aty PXq3%z,&q%4 8e2Kw 6x7=G 86ӽ T"}/G`z5F%v{!*ga'3PI w~S-Ck!:~T@4(Ep23'ѳrEg^?ruBGdž\8C>׎-ݺ #u֛j^=94Kаߢ|eU:'lqW#<* r"鿸U!kKdH`u(IS%mvݪ,63f \$Zx΍/E "/)H cSiv>A&Җvj$jG ^n[˜ұ*ݩ& z&ڵOo2'Fu< mnM[KX JgFv[MkVsWB!РKu5;򘑗[s0? zٌf T]7l{x7R:4XиheR?i NM<嬁 ^urb!F4lg3 R,*i"Jd(/s0&U3$uZ_.)%З#dޙ ɔّ-G+D$ul=AG䪐bgEbTZѫC761\F"W{UZT7p:P\EeW4•RgNRB2{5kH"Gv:shY}K-kh"i)Si3r"]OH,~˽>{@@P*oEyUW~m[v1؈$qnBh&B;?\E$kXI9&]ckU>/ƅr 9?}b??)x7VN<!f.IeAYԤ;|.4Iqy$%`Yrz JE꤫x*C-1 #<ԛ]MN"nNYC|2Y[q/'vrW ̈i{PrS2ωp32+Zx#3N >G֙3}9h4D&u$O|@nҚZw|i.#/insXzbK e^Ϙ.K;|/Zk(g{*LݩI4MF!8wpF$}Hiw%z^oNH+ݝTkM +a9RL7̷[l234<7E+.'L KU1HDyMj bGqepA m$4<;i@4$IG 6 !*s:;np,2m/==SU|{Qb>7:^JqRr&KtV }N 6.09S=\X\vcfl. $Nǃ5J@a_΁zep\fzn*ىs&GIA+;@q}dC5s+Z"@MWKVB"tC}*o-Wɥ@Į"tcg]S࿏H̳tYBjtkN-{܎LF2c.8:N$Emjkε D3_܊eѴN%%m,vEFaP<4Lլsf7'y_o2;#c >u?;75@X:TrV MR&;;/ee5𲤃RՀ 6\I x1Y5KƑ^CXiH(-P(;W85kƣَz=֙IN77G'Xqh6P6{r~QvS(P٤n2 ;!ޭ,)]ѓ3`*\Y {ngYI)_ gj)5ð߳˗BAj~ gVo张Q)"NqdiՂ֬f5qy^D!iض1"2j 'e]9GYye¨4ދ$ ޛNA@hb}mX4,F)jk16sUANH?.tpӪ"X=mKπ3L08U$=KT1LbZIʣW6jF aOP7 K`Ax_~qv>JfN?5eNHnM]QN`?;o.$O^847yI]@I!\Qk̯nb^ te"GbTM}MӚKb)U2?؟qpr_<;`tI/6" M?G6nL)@*lfjlJݐ^L>'J''/{qPcQ#}Yo3 Ty9' |D,#**(+LTw cěfi!\.*BԇTERV0*#lh^ms̆qq]9Ԯ˧#͔>x 7ktٞ5=-RZ`0Ջ_#u:&?>%j@"1.- e:?l͚Ab?/6S56a #&/B"Rej]bc *bԵN#ZjSIIDEctTCzC̸}mtaܧriwuQ%tO"Jn=nҡߩX9!S"8kO*-Y{ޫd]*txHشἑvzc=u|='׈4E6q8uxYGEy( gqKFtiOj_pLPUEUZUtʙh yA_Ŧ:s۔ Xv(K*ENF]/.CʪpPH&iҊMY9(fyzc+O.EiwS4 tnx9},eTpB&O+\[[b$3;Hɹ?MOVww,]Y<{F{z=tцD؄l&!F[F0Rhz#$:*5%!%}!CDKޅ빎B2a +JOs7f_17V&jSXg S;l4 ꤫we:%%Ic ]crja1zo/se 5 EBF) ֡+s%?6 +FFƮ}cjΕ,K ]:7iVslI/J 9rXRLiuICN&O˔H4:5B2WӑF&4y#]S)Fa('&h*1/].fUpiZF7C-F&F/9ɛ(Ԧ㞯+ptn(ȧ%`y* o6++ZNԝUƃ30ҢI#smwX/HP_7DHZ0Eƍo=,g̙֕:㔨jљq9I걡D( N'>Qi\ejz0&eڷQds4_s ڕ쟻IBs#Ny8_ {lNV:]1 7;[Kd[ {v,RY&?1 庞fGLD4 G G| Ƙ#T$핔xjh\&Q[{G}ޑ2Evt׋nqoq,} 吥9_Nyi&O/ '/ -P(.%RfB4y|PĈ[1"X2mv7ZL8{g`Dl_Hf-!MVDp"0K<tjo|)tu|&n6<3%}dVұ؞!wY-a|d 2 pزҖq@ÝѐhAd˥/S!G\e8Fpbnv#94ejXPanQ<%>n\^ "q+/kBW!/V┘=cHK2Sh{)KB8$f["GjKA4.A{G8=>M#6qҤUi A(w#o })g*j%҃1,Z9̼ſOr̛ٞ&Zo@TŇk9)UFi:KG7UMtمAw r o]8{? ɂ89C/UzH\Q Mn٩*}Da*kM4bgjAd~7k7X , iCKұ_/]ܿz5elVboB.i+L)ʕTׄJ!6L>U3q8 Tebdtߘܜ$K]o phAI|<5 BEPCOj vOGcAa@w ;=XSZZ :*'C fTDg!;N}OPNM ~ jDkiHD鉀di>z㺑hF_ /pӀmSsJϢPDV= γSP;Ɖ@-Aĉ[]=)B|Ɲ2C i(ȆƼ,ix CH9g$DN;2vdzVLqlzTn"`VO,/׽{ p?  :NupgtHj0ozZGOI=1|pE͋P_wia.kz+g&ߣmFa3*9MGMV]=.N[~懬GZ\C#+)`u$]`_TqQ#Є~o"@3!1=6WʔןL.Gj,Ūvct׀(˷0J D2㉧CC}I^3oZؒ9e\'Xrxx p,xBfc8 6"IJ3T\c^ }4M" :G[/}W5g$٧ũ)-Ҩv*zsAw?se1Yj2Mضl!̥gs֜[{ Ye\FTi?rD0笨yK^ߌ~ʈ8WOz7a2 *V=ܔ/[tƔK}d_?:[ຣm .E׼~&R r*D)Q>(0GfG|d>16lXh2I$fOaY?3.RU׀lM]o 4Lܛ}bL8PW@8-l< K-ApwÜЂ1Vj"~h!+TY9SCКCO՞&*Z) ZBlEB$\ bt D c mבg \μozBrMA*M L3Ho*T+&$W;?FB+(rτU UXٷ׈d RmJDpR#XC]=IҢ{3UT0Djnpb;I({`R'>g+rz6 +iHQR+t#TX/eͭf C9ib+'en+?s[@YO^cKLk~2%cz;m@ǕE?>H_ZSusQzd-@آg0Ɓ 0Tf\5X;X̓ЄxղD_.嚝`)![.$WFpgnp_xv۰ʹ뿆:&ַ$>a"jye~Ѡ*cpfF,}wۧD8E,eeʳ]C&'t{2Hd+<0d$ى'7˸Q59x'$INHn/^41&!'EanY¾)vSt*H>!#g>ެF&0I)-ѳjiaNhs;?giSZ|&2915P X׹#:I%}ˈѨ{|kأCt#4mHü weY!?\"(pJx/In֏bFSBN 'CS 5mƍUOW:'0(u bvp{[y^X=0- @;F߶y'SaW5unf mI9Oy:V꾌*!*b y{ڿ =r>!!3_.:} ap ?z>&?_Rl\!:$ XHI᝔{kq}= r9v0VTf~nIVoC>~QtNM}5SFP'؝8I{I VeQgp^xK碑S LMΰ|hp;<^nХ$ܦ[;ȋC*9FOw^S'N~ %AD+ѻ'SA$ U  (h}/R]B|&caD90mMǪz!wC&>c4*HU/X40=CM6^S)*nپf sץ NLC?i"^l"L0eW qi:y2[r'=ɂF'C c:).q隸u̻݇$m~IP;Hn(uwĹg vheYo"襤]pn+}5NSFZaY:Dj+B)҇3^-+bƠ灄Quy ̹F[ MYJs6BpS.8i,i eTt99Z ]?`xT>p!tJI%]%_F V/GҪsUƦ;~ش]3( :# k}mJ('uΙm24xrlg+ьBܶ} S">"qz/mܖft`dcG,adyNnIFcx3sht'7J ke[*k&=4Rke3Z(UQ5J"]E?7AtI|(p ɠL.jF0%Y >!~d#ou8b }}َ *^jQ(I4z~mˁ^yᙼ?1\US`DŽ~㬆pбȈ*>jIW|]F T 'HJ,+Ru7T^xw?3>}]'%-Wx-"{Ox`ɮ5μB9ݠY2D9n*w 0lĪ-S6ο>k3aZh k̕7M4z}2qZ!-L<_u"8싆s^i\5[gJCsO l+Z7u8A P7_hUɝ-hQ]鳂k̬Vlqdi|@?; K03G#F=C9<(mt)tzvb },7HEf:=ϻ\aZKf.zQ+EywP%c!R!\!˲ߨ&p3=RC r!JF8I $[dpᾓZ:vHq|]#^hNQCsC|#؉ HyJnTm巚Ԧ<Ŭ~8s+^'JDM{҄>G]XJU rcv^@0B:=GCu27McCńT.&l 2c3J7>oټ Yն>S!7NFzఈ- v @des{"M]+n0#˴['FZ|ɨHP\Ks[χ< tB];+tXzWAeA#z^ Zor{iCL ,8nŞ*()xMFX-P ]R/ ϊcjRo' rM|q;4/ڢ,16H~sᐎ+ļ#p^)`O&`,rO|]m-[I>pȻ֜cjo ӛ+f9;pF=L!‘q:O܊mxַQ {0AY`xkvգw@NSsծ/.9KS (ݒ.|/jćܰ2762ҩDc9`axUVs}],n_[ YH;>;/ĒjyO$E>z5J_ZR1]bȏ׏ff;[zE= V=Ƚv:S-9ڼX^ǛPC?H\:'ىcJ޳p*J15U-ǘ]].3t R7_^XAN e҈| 3}37TBs$ps!w5CwR/UmACmc3.䱨mK: Bމ_πKe,?YAz}jᤐaonb[uᔓ}zX2S9;'5rCWnUݏW/ v4dJ / ǔJ?*+F2;֊vH2j{B'CKq@jh|A|+Ldd-V{H4֤:ԙ6=}x3J޶>;(ZФ=[n/u}_DI@v Y/쒖-W, F h;)}V{kP˖5Lp̐nm2]P 0_3zĎy/Baζ (㐃Vx#܊Gjei ܪ3ѭlW&韇6[4%K sM>j%gkūb֣ڸ0P̿Z_5b<8rۧkGM~ˍ;5& ՘DjB55b_MA2S2?2vY4ܦdjbI2IjByAȯC`QKhxz6ˇK-qn3ҀgNm<$`%U̹=hTMs\w#D$MGv<4wmuZz=Am8Lm8Q~6u!lAY)8t)hT@ﴅiIٲLT.SbD%s`wD%^MLC[x7z3K:6b2aMFmNF6 y۫NH cn'ƛ@CCBZ} JoM}/+X6X2?kh-)nxp8as0֕0m0DAOofLZ80* x *0(bTvug8l%䘴ܮ,[6ڦ[^\U-9cS;-{PNI ey&_%8Bt+Tz>-)maL'P̠O(ckYv9'g63 Qґ|<; U YYmisd:1jD#`&XDZfT&!:-0n#|pH ȂgeeT c]3kp*̱Pe)x-.sX#B;(,+ 叚1_eɈ9RLeib EP;fe x}p>kKaK>cUk\=ߠlooo0&K@i\.09`_&g~Lp)y**ً[ޖ8Ɖeg&G&o霭r&THTAwNv{~ "Z*]3&(k?|f͹I2^1QP9+_Y_蠨uNF"Xׯa2MM2 { YCb|-09<֖rzCt#$ȆRz((U9E84z#D2FEZD]@f)qG )Um/0eUO۲QPk_f8%sjaTfԿH!GBJv'K*qO#6= fI/2l] C#=LBM^8Ȏ7zπ3کeҥy]b7rI=;u5\tړ5N)F?t~]L455̓^@< ٌO6K.SP/&a'& lò=1m/Pp^rO'Мh,Q=2/n#cJLި9 AeՇf?zuLk[g(,k'c'(ޯ=x]8_fv[]MgFDON i{ƫ<5dk{EzȨt!0 7'iN;ua\NYMfbj^6 tV?V̹-&׽B h3.!Ep\FWU>F:6dl'>Mo ~5k 7,;FAi {e&?]2-wkl8ChENxh H._}& %@(I" =_t>&!SIQixwlM>h;ELc!e}/K:ruDVv ˍ!-rB@`FTJ3mI^NI_oy9I|q`qM_N%*-?\ʦL()3*)'I[٭ƻ*^S!N< >X1#ɹ>T"4ũ2 J^vpzjR1l_(~n~Ԯ[0IݪDoTboWG@˕BD=|#85k+9>gbysPqګӌ I2Ҡa>As*%!>*~fpI˓ۜ8oJgeʌbCB/}h%-)`QWt*|Z{Ғ#4?]?Ur|ccU g,@$ Q؅]WSd7$$$|QTzDI|' J,*'e_Pw.kg|\B뿈tQOo {+Pfv+~3wqȯ8Ơ׌ i6#%Xp޸,9k]&ص.T/ {`.y&3OSG}w >aqp#[lx契BGYО0PF T3zFCo 3R\`k`S*ROtexˢiQ;ZH%cőMY^gA=FKd6ŮŅˍ4PFirq*f_taB%3ۊ%YܟĢ(6n{o8ahO}BCZFgϩ N4D5N&xH6Rl}s}Jd]鞗y!셈lLMS *g-JR2C ӱVJ݈+'Fn(DVU0KCoak-a/İϚ]2zf)䏧#k2 YOECc 7$}b]\~+7af%ӧ k!d;IHځ?f7b0F SI_71y4rm(e2#vu)イ+r &|]|`B>$iN|sѦzTq]: IFj3 y:GI'Я_͗2Q"c'D2Ւ34Tj'Bf*~ :.d1Cٹ-Uit!Z BEE^6eh7+Z۳&gyk@ _l RI%cR]hNI?Gvu/((z4ޘCMxʊH(t~n ңުsp|=ԏY 4+T?J%g*rv"B][^8W-\/Gk$Mi0&$vS%(X`zsՑꄯO0N}]_eŒH7D$/'/-̦ie>A[nqY0e9[EA9Lt4Hf [wIj;3UVBկgASO ,-i/A6٨m<339)Cz?Z=1/JPƳX /޹f=v[ށ}tX[S_kQee\LC Ts;LD‰;V!Ҩ hYYU{Oőr\i9}((^~pJOD eC/WcɧxD̘ϭdocefEJ`.a>RJ;6Q9LьX۫#Uڭk{|çGs(ăK IPqs>}vLB,]P$qCBa{B Јp#z[D{ :6±AI{aaU\e6s d5ʰ1l$~(Tog `!=Ϲ bh&}pAh]YO=$bځ/&worJϛER\Alg0c}TƦi._OyslvNA>;kwlbLH9LHJ$fƲ̴ @ZZS_/3zIPZ.&kHca'Z {y4eFNU#H B:LK\,cW~SPKS,|ŊN _e{hjYF:#7VT 5ncf p//\jP7Ŗ5T Me3vhD:Ay%cegGG?m+Oq7mQԍD T,iEmˆvέŋAȮ trtٝ٧ zOv/`a8rXO%c[ː<x915['ݾYջjSC:ʈ勝յ *pE;f%#,jIy5nBW u:5y)7oT!1L@$d4|'\WUg[B7J0B~dLm.e 5O+b9kZ朙ޣ}e29\ccha+Np2Â)s/l\g!h阦`Ӣ۪)tƋuY!g @jsTO1jO4F(:\:Uj ZQH"^Dd\giN(5#ba! 5 obR+`G~@.e!c8n|@g?W4쨺 j;f8iz00ȫTflU/ˆч%\ O5g{+f5:M \ԳježSgkRH||7/Ś ~Ao3 o|{3lR %i y_P95kd\z/]X^(2-?<Z'x Fu|[+X^Sf0w l ag*D:׸۷"N,pCFY)X|&>֓&Ӵ&3.$/1,=N #qx7^vCcpZh շ7+/8 >pZCIڽL5}9M$~aat/42]Ě䏥-!14>c^ jnj jbӎzlD ;hUݕ@V'q]saooԯ"6dq:oٙ?\Ja-e`I&$,q:<Z ؒ_ZݳZn:Xt?1U t㘓G+P `eww\)#j߀O^=ּ 535Yd ^3*M=3 S]phFLw 1ndK^n!#),lJ}4{Ȍ2H(WhL@2!{ V;V&ط\H.\xh EöAK,a⃥f`mm'?;̧Mȕe{^e%<0BES,YZQ҅ohcq%w1@ Muv S; x*9;~]ڱwۄMF=љF@J9,.v::mo υPLmo}@jwJU}y$n+PXp 6fMha`V- +3|4=*>%(Ag.mST/2e<@J~jKYwWF )ex?|÷3=JsǃJ`=IܪMMK{{9];+?X@8K2|f٠u[r¡{X5'3\? 5Z%19oUUD`)j S{ hݝYuL e1T7"MqWvS{`Xlٹ a(KzZR+ک~ &ӅBQ>6JǿBh>/F}.yG#Qk#=rhᷞ),Ұ^dMdQ{UYe!$.[ň Szn`-% t~]Nec":FqaHD55>F&ni׎33i 5s>OW;} ƸL8.{-ѾB*?Q(C),/uOO觺_a0 j2y(FȦ>U X h#Z:wxy{QujQl4R-A%ƝmU 2;ސC|,}s}kYK` 0&9mL +c"NϳB;)M_<0_'H| (0iX'IY@LXjE(o|NyYj_B؃*$"?{?h~岫:!6c*gZMt*ԭky`'?t;,i$ ?D˝G! e/p!u# Huj|_:$OuOCe .mԀ ۔.s=[?a_.<:Q#Y SdY2ǀw1 )0+ozCwKKWSǜN߿d%G83i[i5z+: !q`R&˟}@!d4n#T_t\U0¹91L.R%Y[\Ch'v@ASΗ hWTq,}(csWZ:*)n2rʠRA Z6cߡKT +PwG/G(V\Kz13^+!oP8HvMjMD6Y8M>~oߞ_~40Oj^k2bDDAEʏB6RR'4s?` *vwP0J}`#Zuc\c_k si)=LSeB!4;;ibjIcswEed(s@c̈d2|Ȑ1[Lyzbzp=+[=u̙|&NhzsRQpUcU{ _ˋ g|Y/.}6TDޔY X޻wm/ % ej Հ I\n1F8swB*%2X{̞FXgĘc;Prw|o\d{O,EgM'K ^dkɻȩ⪼:G.!#wH<(UL 5pUzmf, Ej ɋۇ6\b=!\n=*v2g\Ir[I7nr9~3|HOS JolnGb+Y .H'L< RfѮJx+5ٸfӂQZ2 Y p''G W+]$mc߅7"XlK'ؙmNкOdElF]5Q4 $i ,T]8`HprdW6e(:FǦ6L .rLޫ$ /sZ+yWv,O~LyC: S@#IU0 Bf,U#RrQLCS )R SĆטyH5Gf #/5Ub4,)Z_F*֚ oF:Vx 5܃e89('^הbEI'.0lIc&w|̞t96tUh`4gvY \҅d飾bY=&u{2B>w*} r1ͦET䦂70W"Q,}Æ|%z :PPbzA7DT#9<NA^"o8ˊQX|#qX C8N$_|`[Dcz2C~pq53q0uI.CFX'#7މ@X[rMy1"d`ncۃ?$DyN⸷`| 6('Jwyⴿ;r@gzKѯ$e@6"f%-{3ŋhUhs/}A0/ jtp_I5X%݁>{JE9u=3ڴZWxqm=Lo6څ;@4J$YC&h& FK >Eyh{Q7K*,A\b Jz L1.m _eO @; ~z s}>?LӽKRs--}a%-mMCEF< mCԯ+Wo>%mRyj;RQ.9jxV7.pS"Iھ""v+ٸLf" P,ׄ{Y=pOC0ZZB/Y I|$3f}6/dHE=jC;{lBŘ+]I(lHBɱذ7bu:bLnwgՙ!' MڡTyErIn+ lyjf*ߔAAnM&I1'!P)fp>\L.{w'UEб[k`k<z\gq?s%2oGX4/hm q YOhgP8cϢ.,F-%)5"xս%!znVIXF]uIBҭZikZ0Gj=wS4+O_: t/N_-:OSа¤O+dN6@a7) |R^_X0B-xFOo9nɍ1އ55!%Ĭ'aC'1YKMd4dwO45K_/䚝 ׺,񴠑4{HJ!jUGt+X: gyyצ|u)NN9 ~+Lý DN+;oծ|B#PZo*" D? mG#\ '4`j(d3˛V: 57d,5"=Vw2UA< Wh'ŒTy*ZuyzB~Cm 4bx q"LF-d|T7lē#gZhz_J%|1P+U!C';F `$)0GMeUH[m^W 8EbgLҤyXvwsvgoY ׳獰.rI/ CSY)̐^=avJ>'I+(iM^ s- I@jMN#Zk $IR X<3&ԱW5lEwlgN&pd Ȟ'<'S>SO1pemuT ,TB )݄Cfύs\EBԁᶀO0XU~cԍeyØ_,L}ᙴ8&>05e8:y+KVH9g Hy!譃Uqٝc&#o#l=|B:^;Tw? sW1q N%pl_.A)*=h8[R&E J)tp#*gOX SE;y"hԢ[CFr {U)ω͎msA86)e֨+ٛڥ 9`Ǘ "K^Ӊ&"!?}77>ʵfyY}e+n;qj_οYZ,u:0!1 -_# [|IזJ]1O eW W"b|sO[dli=}À y29$?n,864!\B6+n,+~+rⱯk1gDǞ`G#ͯR{f QhXKgw`#.5jJ8|/̔38H}J;'Dr'y!ao-:qHK$3nu@XPCA=<T'9c{2_M,x{f)ykFzLـ R Mݾľ |v)u4 L9tlU DE_4H[.TBBY8&4õRM ̖e]Ӹ}B plТ)6b^WɅKft0*eF-Ek'k婬qe2?r1[n;6E\j]4бM;f^3tw'&pqU蕬'9'CIbxˆwa]-A9kQ ȀE4ڼ 06[(@g~Zp697.N%VT|A=W'/lşOxPc0R9 wNt|̌*H zq~(]rOm4e^GÛG0K+\&p*l,,k* k,xi|('J^Ds`q#*B&œrE%u\uws0A0@*0A0d(;څGJI %S&*%9u* Rb.BKL_؎Pi o4:g14=̳^L3-i0a[oT0J^WK8ߞ˕1tibvuhmsR7C&ZT%5!\WX)!xUwZ끶uE41zPTj c83. =y~-|M8=Mw%$HۊCeɷ/l:sE