libnetapi-devel-3.2.7-11.8.1>t  DH`pL`C/=„d< UM@r|Lt !\tiZvza,oXT3{gb iΠ3 us!SRMFaf- s~&cݮdجzbw5p71 o%|.DkU; qʾͧLe#虧.+b9){Ud1+4}f$p%yB`]]̳uϐI'Ǣ+QO.T];ߜI,{5$ffBJ/1"lO?TԳ`5򠵗zʱuUض`XYݷ!ap7RϨUxQڌ,iGF?S ,xc aKӓ Y->6?d  b\`hlz     W ht8(T8\19 1:01FG,H8IDXHYL\\]h^bc-defklzClibnetapi-devel3.2.711.8.1Libraries and Header Files to Develop Programs with netapi SupportThis package contains the static libraries and header files needed to develop programs which make use of the netapi programming interface. Authors: -------- The Samba Team Source Timestamp: 2426 Branch : 3.2.7.SLE11_GAL_grinckyopenSUSE 11.1openSUSEGPL v3 or laterhttp://bugs.opensuse.orgDevelopment/Libraries/C and C++http://www.samba.org/linuxi586<ٖL_L_L_8f394477e4bc3171b00c2a40c1d695bb335cf7567937b5bb84a0448f7ede03b9libnetapi.so.0rootrootrootrootrootrootsamba-3.2.7-11.8.1.src.rpmlibnetapi-develJJJlibnetapi0rpmlib(PayloadFilesHavePrefix)rpmlib(CompressedFileNames)rpmlib(PayloadIsLzma)3.2.74.0-13.0.4-14.4.2-14.4.2.3LzLrbLmLi(@LgL[@L0K@K@KK[K@KqN@KqN@KoKoKn@Kn@KD{@K;@K/c@K?K3@J@JJ`@JH@JJ JjJJzJmJ\s@JI@J@J:,@J8J'@J'@J'@J+@JMI2IIl@II1I@IHIy@Iy@Id@Ia@IVISuISuIBR@IBR@I?@I?@I6tI6tI3I2@I1.I.I.I.I.I-:@I+I%Q@I%Q@IsI@IP@IH@H,H,H@H @H @H @HHHH@H}@H׈HHHBHe@H|@HAHH@H@H@H@HHc@H@HnH@Hz@H4@HsVHnHkmHkmHj@Hj@Hj@Hj@Hj@HhHhHcHb3@HXHO@HNlHNlHM@HI&HG@H?@H?@H=I@H=I@H;H6H6H6H2@H.H-w@H-w@H-w@H-w@H*@H*@H*@H)H$. + Fix Coverity IDs 456, 574, 592, 606 and 607. + Fix net rpc vampire. + Use the same prerequisite for DDNS update as Windows XP. + Make "lwinet ads dns register" honor the "interfaces" parameter. + Fix extended DN parse error when AD object does not have a SID. + BUG 5888: Fix PNP_GetHwProfInfo(). + BUG 5957: Do not abort rename process on valid rename script. + BUG 5898: Fix 'net rpc shutdown'. + Fix duplicate installation of cifs.upcall. + Fix _srvsvc_NetShareAdd segfault. + Ensure consistency when reporting password complexity. + Fix _lsa_GetUserName. + Fix access check in _samr_QuerySecurity(). + _samr_DeleteUser needs to wipe out the user_handle on success. + NetGroupEnum_r needs to handle servers with no groups. + Search for gpfs functions in both libgpfs_gpl.so an libgpfs.so. + BUG 5908: Fix internal change notify on shared directory. + BUG 5135 and 5446: Prevent calling POSIX ACL vfs methods on zfs share. + BUG 5929: Fix building of vfs_prealloc with option --with-cluster-support and GPFS. + Add new VFS module to analyze SMB traffic + BUG 5928: Fix 'testparm --version'. + Have uppercase_string return success on NULL pointer in mount.cifs. + Make mount.cifs return codes match the return codes for /bin/mount. + Use lock/unlock_mtab scheme from util-linux-ng mount prog in mount.cifs. + BUG 5778: Check if strlcpy and strlcat are already defined. + BUG 5840: Fix segfault in "rpcclient lsaaddacctrights". + BUG 5860: Fix nasty error message for overlong strings in safe_strcpy. + Fix a potential NULL deref in found by the IBM Checker. + Fix an uninitialized variable found by the IBM Checker. + Fix an unlikely memleak found by the IBM Checker. + Fix some missing error handlings. + Add workaround for domain joins using a netbios name which is different from the hostname. + Fix crash bug when freeing a non-malloc'ed buffer if the client sends a non-encrypted packet with the crypto state set. + Fix trans2findfirst for the large directory optimization. + Fix checking for presence of cups-devel and correct cups-devel test for HAVE_IPRINT. + BUG 5805: Don't close stdout when calling setup_logging multiple times. + Fix setting of trust password using 'net rpc trustdom add'. + Fix several issues in vfs_streams_xattr and vfs_stream_depot. + Return an error instead of crashing when no realm is given (trigerred by "net ads info -S 127.8.7.6" (where 127.8.7.6 doesn't exist) and "disable netbios = yes"). + Fix the new vfs_smb_traffic_analyzer build for static links. + BUG 5901: Fix default for streams_depot location. + Fix several build warnings. + Delete the krb5 ccname variable from the PAM environment if set. + Fix circular dependency error with autoconf 2.6.3. + Add @CIFSUPCALL_PROGS@ to "all" target so cifs.upcall gets built at compile time rather than install time. + BUG 5906: Fix Winbind crash when calling 'getent group'. + Fix logging to syslog. + Allow SYSLOG_FACILITY to be modified with a new configure option called - -with-syslog-facility. + BUG 5909: Fix MS-DFS on Vista clients. + BUG 5944: Fix starting of nmbd with "socket address" set to "". + Fix segfault on startup with trusted domains. + Re-add "winbind:ignore domains" parameter. + Avoid freeing fsp twice when opening new_file fails (Debian #431696).- Fix the conditional macro to start smbfs by default; (bnc#456469).- Readd libsmbclient to baselibs.conf for pre 11.0 distributions.- Use %__install macro to install files with the right permissions instead of cp.- Remove patch for bnc#336854, which doesn't exist in 3.2.x or higher.- Use %{NET_CFGDIR} define instead of a fixed path to the network conf.- Update to 3.2.5. + Samba 3.0.29 to 3.2.4 can potentially leak arbitrary memory contents to malicious clients; CVE-2008-4314; (bnc#446971).- Update baselibs.conf.- Fix circular dependency error with autoconf 2.6.3.- Fix the dhcp hook script and support CODE11; (bnc#442335).- Fix perl v5.10 warnings in nmbstatus; (bnc#448225).- Include the missing spec file change mentioned the previous commit.- Make cifs-mount depend on keyutils, keyutils-libs packages as they are required to support dfs and kerberos; (bnc#432494).- Fix the offset checks in the trans routines; CVE-2008-4314; (bnc#446971).- Change the runlevel description for winbindd to use "Microsoft Windows" instead of "NT"; (bnc#446154).- Directory/Filenames get truncated when 3.2.0 client acesses old server; (bnc#432471).- Add SuSEfirewall2 services config file to open Netbios and Samba ports on post-10.2 systems; (bnc#247344).- Remove unrecognized configure options.- Fix the pam_winbind build.- Delete the krb5 ccname variable from the PAM environment if set.- Move the nss_info modules to the samba-winbind package.- Add version branding for CODE 11.- Restart smbfs even with the traditional network setup; (bnc#425058).- Only call the stop_on_removal, restart_on_update, or insserv_cleanup macro if available.- Only call the fillup_and_insserv or fillup_only macro if available.- Use package names instead of macros for cp, mkdir, mv, rm, and grep or instead of the full path to the binary for ln, find and xargs.- Introduce NET_CFGDIR to fit the needs for a differing location of the network configuration per vendor.- Use path macros for cp, mkdir, mv, rm, and grep.- Only use SUSE rpm macros and SuSEconfig.permissions if available.- Adopt samba-vscan to build after the change to the bool type define.- Fix winbindd crash in an unusual failure mode; (bnc#416598).- Build cifs.upcall for CentOS 5, Fedora 8 and RHEL 5 and newer too.- Call mkinitrd_setup during %post and %postun for post-9.2 systems only.- Update to 3.2.4. + BUG 5590: Fix binary stripping on older OS. + Fix linking of cifs.upcall when nscd_flush_cache() is found. + BUG 5052: Allow inheritable permissions. + BUG 5697: Fix spinning of nmbd in reload_interfaces when only loopback has an IPv4 address. + BUG 5698: Fix non guest connections to shares when "security = share" is used. + BUG 5729: Explicitly allow "-valid". + BUG 5745: Fix Kerberos authentication with (lib)smbclient. + BUG 5751: Fix showing of ACLs on DFS in (lib)smbclient. + BUG 5761: Fix opening of mangled directory name (resulted 'is a stream name'). + Fix the wcache_invalidate_samlogon calls. + Clarify usage of "force create mode". + Write times code update. + Fix Winbind crash. + idmap_ad: Fix a segfault when calling nss_get_info() with a NULL ads structure. + Fix build warnings. + Cleanup of DC enumeration in get_dcs(). + BUG 5710: Fix changing of machine account passwords. + Fix several build warnings. + Fix invalid sid copy (hit when enumerating sibling domains) in Winbind. + BUG 5736: Fix Winbind crash bug with trusted domains. + Correct the netsamlogon_clear_cached_user function. + Fix handling of MSKRB5 OID in cifs.upcall. + Fix build warnings in cifs.upcall. + Change default install location of cifs.upcall to EPREFIX/sbin. + Enable building of cifs.upcall by default on Linux. + BUG 5707: Do proper error handling if the socket is closed. + Fix calculation of useable_space for trans2 and nttrans replies. + Fix Coverity ID 587. + Add mapping of generic bits when setting an NFSv4 ACL. + Some write time fixes. + BUG 4516: No IPv6 on Solaris 2.6. + BUG 5571: Fix group memeberships in Winbind. + Fix cut and paste error in quota code. + Fix display of POSIX ACLs. + Avoid a race condition in glibc between AIO and setresuid(). + Add missing become root for AIO operations. + Fix logic of tsmsm_sendfile(). + Fix an errno handling bug that could lead to an infinite loop. + Fix handling of arbitrary new PAC types.- Create a link to the html manpages so that they can be accesses in swat; (bnc#426182).- "Password last set" timestamp update from admin pw change; (bnc#420407).- Call mkinitrd_setup during %post and %postun for package cifs-mount; (bnc#413709).- Update to 3.2.3. + Force the permissions on group_mapping.ldb to 0600; CVE-2008-3789; (bnc#420634).- Update to 3.2.2. + BUG 5592: Fix creation and installation of shared libraries. + Fix replacement of random seed generator. + Fix a race condition in idmap_tdb2_allocate_id(). + Fix unix_convert() for "*" after changing map_nt_error_from_unix(). + Make sure to always set errno on error path in OpenDir. + BUG 5675: Fix smbspool program assuming Kerberos authentication by mistake. + BUG 5686: Fix segfaults in libsmbclient. + BUG 5692: Fix coredump in full_audit.so. + BUG 5696: Fix "force group" in setups using Winbind. + Rename cifs.spnego to cifs.upcall. + Fix segfault in cifs.upcall when it is called without any arguments. + Fix coverity ID 594 (resource leak on error path). + Fix assigning of primary group memberships when authenticating via Winbind. + BUG #5617: Fix freezing Windows Explorer on WinXP while browsing Samba shares. + Include stdlib.h to get a prototype for free(). + Solve an IBM XL C/C++ compiler error encountered in get_exit_code() auth_errors array initialization in client/smbspool.c. + Use NGROUPS_MAX instead of 32 for the max group value in rep_initgroups(). + Add add c++ guard to netapi. + Fix compile warning in cifs.upcall. + Add "dns_resolver" key type to cifs.upcall. + BUG 5688: Fix orphaned LPQ processes if socket address is invalid. + BUG 5684: Fix removal of dead records in tdb files. + Fix coverity IDs 595, 596. + Fix smb_len calculation for chained requests. + Fix output of test status. + Fix smbclient connections to older servers. + Fix a fd leak when trying to regain contact to a domain controller in Winbind. + Fix permissions on ctdb databases. + Fix passing back success when a function had in fact failed in two places. - Add --enable-static to the configure options to get the statical libraries installed by the install Makefile target. - Add --with-cifsupcall to build the cifs.upcall binary for post 10.2 systems.- Set Required- and Should-Stop in the init info part of all init scripts.- Fix libsmbclient to older servers; (bnc#402776).- Update to 3.2.1. + BUG 5594: Fix "make test" by adding and using a new testparm switch "--skip-logic-checks". + Fix creation of libaddns.a, libsmbclient.a and libsharemodes.a. + Update the section about net conf in the net(8) manpage. + Improve processing of registry shares. + Fix listing of registry shares with testparm. + Fix several build issues. + BUG 5578: Fix error from strlcat. + BUG 5613: Fix flushing of smb.conf when creating a new share using SWAT. + Ensure consistent use of pdb_get_nt_passwd instead of pdb_get_lanman_passwd. + Remove worrying warning message when safe_strcpy tries to copy a pseaudo interface name that's too long. + Canonicalize servername in the printer functions to remove leading '\\' characters. + Fix option processing in smbcacls - add POPT_COMMON_CONNECTION. + Fix bug creating files using DOS clients with mixed case files. + Fix uninitialized variable. + BUG 5616: Fix session keys also in rpccli_netr_LogonSamLogonEx wrapper. + BUG 5570: Fix bogus error message during AD domain join. + Fix trusted domain handling in Winbindd. + Fix build warning. + BUG 5202: Fix setting of ACEs for users/groups with write access in setups with 'dos filemode = yes'. + Re-activate 'acl group control' parameter and make it only apply to owning group. + Make ntimes function more like POSIX and allow NULL arg. + BUG 5512: Fix alignment problems on sparc. + BUG 5616: Fix share connections in setups with "server signing = mandatory" or SMB signing set on the client side. + Fix a race condition in Winbind leading to a crash. + Fix a segfault in base64_encode_data_blob. + Fix some uninitialized variable references via ndr_print. + Fix error message if trying to join with a non-privileged user. + Fix setups using "include = registry" without [global] settings in the registry. + Fix "net sam rights" on domain member servers. + Add documentation for the vfs streams modules. + Cleanup some duplicate code by passing the password to the wbinfo_auth* functions. + Allow SID with 0 in subauthority to be converted properly. + Set sin[6]_family instead of ss_family in in[6]_addr_to_sockaddr_storage. + Fix realpath() check so that it doesn't generate a core() when it fails. + Fix overwriting of winbind logfiles. + Fix "vfs_full_audit.c: name table not in sync with vfs.h" panic. + Add broadcasting of the debug message to all winbindd children. + BUG 5635: Fix updating of printer queues. + Release still reachable memory if the smbclient context is freed. + Remove trailing withespace from wbinfo -m which breaks gdm auth. + BUG 5540: Fix "set primary group script" user option substitution. + Fix regression in Winbindd offline mode. + Allow authentication and memory credential refresh after password change from gdm/xdm. + Allow %u parameters for print job username.- Fix a race condition in winbind leading to a crash; (bnc#406623).- Use the configure option to enable debugging. This fixes the creation of the debuginfo and debugsource package.- Fix emptying the printing queue; (bnc#411493).- Remove trailing withespace from wbinfo -m which breaks gdm auth.- Add a recommendation to the samba and samba-winbind package to install logrotate for openSUSE 11.0 and later.- Include mkinitrd scriptlets.- Allow %u parameters for print job username - use advanced sub; (bnc#374389).- Update to 3.0.31. + BUG 5504: Fix SIGTERM handling in Winbind children so that they do not remove the unix domain socket used to field client requests. + Split the winbindd_passdb backend into a 'builtin' and a 'sam' backend. + When allocating client buffers for large read/write - make sure we take account of the large read/write SMB headers as well as the buffer space. + Memory leak fixes in DC location code. + BUG 5533: Winbindd fails to cope correctly with a workgroup name containing a '.' + BUG 5555: Don't return NT_STATUS_PASSWORD_MUST_CHANGE error on machine account logon. + BUG 5551: smbd recursing back into winbindd from a winbindd call. + Fix usage message for "net rpc trustdom add". + Ensure consistent use of pdb_get_nt_passwd instead of pdb_get_lanman_passwd. + BUG 5578: Bad (non-Samba) use of strlcat gives error. + Canonicalize servername in the printer functions to remove leading '\\' characters. + Documentation build fixes. + [DOCS] Fix use of smbconfoption in samba.entities. + Return NULL in sitename_fetch() if gencache_init() fails. + Use machine account and machine password from our domain when contacting trusted domains. + SPNEGO SPN fix when contacting trusted domains. + BUG 5285: Fix libcap header mismatch. + Fix joining NT4 domains. + Don't let winbind getgroups crash when we have no gids in the token. + Fallback to level 24 pwd set while joining. + Fix joining w2k domains in "security = ads". + Fix pam_sm_chauthtok for storing modified cached creds. + BUG 5202: Re-activate "acl group control" parameter and make it only apply to owning group. + BUG 5531: Fix conversion of ns units when converting from nttime to timespec. + BUG 4974: Map NT_STATUS_OBJECT_PATH_NOT_FOUND to ENOENT in libsmbclient. + Fix a segfault in base64_encode_data_blob. + AIX build fixes. + ENODATA is not defined in freeBSD 4.6.2. + Don't reset password last set time just because the expired flag is set to 0. + Fix usage message for 'net idmap dump'. + Miscellaneous man page fixes. + BUG 4203: Samba3-HOWTO: Add improvements/fixes submitted by Pete Boyd. + Fixes to man pages. + Add tdb file documentation. + Ensure that winbindd trusted domain children keep primary domain online status up to date. + Update cached creds during password change. + Ensure that Winbind always uses set_domain_offline() to mark a domain offline. + Allow authentication and memory credential refresh after password change from gdm/xdm. + Memory leak fixes.- Allow authentication and memory credential refresh after password change from gdm/xdm; [bnc#395578].- Add SMB_VFS_OP_RECVFILE to vfs_op_names to get it in sync with vfs.h.- Call the libsmbclient testsuite from the %check instead of the %build script.- Use machine account and machine password from our domain when contacting trusted domains; [bnc#404667].- Add a %check section move the test of the PAM modules to this section and add more tests.- Add a recommendation to the samba and samba-winbind package to install cron for openSUSE 11.0 and later.- Use a variable for syslog and add missing $remote_fs dependency for Require-Start in the init information of the init scripts.- Update to 3.2.0. + Support for establishing interdomain trust relationships with Windows 2008. + All changes from the pre and rc releases as noted in here earlier.- Move header files from the devel sub package to lib*-devel.- Work around bad use of autoconf interna.- Build Samba with debug symbols to get working debuginfo packages.- Add /etc/openldap to the file list and not only the schema directory.- Improve samba-winbindd and dhcpcd-hook-samba interface scripts for faster booting; [fate#304967], [fate#304965].- Move sysconfig variable DHCLIENT_MODIFY_SMB_CONF from Other to 'Network/DHCP/DHCP client'; [bnc#400467].- pam_winbind: Update cached creds during password change; [bnc#395578].- Update to 3.2.0rc2. + BUG 5504: Fix behaviour of winbindd children receiving a SIGTERM. + BUG 5489: Split the winbindd_passdb backend into a 'builtin' and a 'sam'. + Make sure we take account of the large read/write SMB headers as well as the buffer space when allocating cli buffers for large read/write. + Fix tag as a goto target we were not reinitializing the array counts. + BUG 5451: Fix for using the correct machine domain when looking up trust credentials in our tdb. + Fix spnego SPN when contacting trusted domains. + BUG 5285: Fix libcap header mismatch. + Fix pam_sm_chauthtok for storing modified cached creds. + Fix joining issue in setups with "config backend = registry". + BUG 4544: Add new parameter 'ldap connection timeout' to prevent waiting for TCP connection timeouts if no LDAP server is available. + BUG 5502: Fix security=server. + Fix coverity IDs 552, 553, 570, 571, 572. + Shrink ldbtools. + Fix reset of password last set time just because the expired flag is set to 0. + Remove support for symbol versioning in shared libraries. + Fix autogen for autoconf 2.62. + BUG 5515: Fix empty input fields in SWAT. + BUG 5516: Fix saving of the config file in SWAT. + Fix winbindd trusted domain child not keeping primary domain online status up to date.- pam_winbind: fix pam_sm_chauthtok for storing modified cached creds; [bnc#395578].- Don't reset "password last set time" when unlocking an autolocked account; [bnc#382111].- Fix winbind sigterm handling and make init script send sighup to all child winbind processes; [bnc#382027].- Fix bug with winbindd trusted domain child not keeping primary domain online status up to date, merge to trunk from reversion 1801; [bnc#373560].- Make winbind children reopen logs on SIGHUP; [bnc#382027].- Set only CONFIGDIR and LIBDIR while make everything and install. No longer set CONFIGFILE, DRIVERFILE, LMHOSTSFILE, and SMB_PASSWD_FILE; [bnc#395877].- Update to 3.0.30. + Fix for CVE-2008-1105. + Remove man pages for ldb tools not included in Samba 3.0.- Fix vulnerability that allows for the execution of arbitrary code in smbd; CVE-2008-1105; SA30228; [#391168].- Follow the rename of libtdb0 in baselibs.conf.- Rename sub package libtdb0 to libtdb1.- Update to 3.2.0rc1. + Move the posix pending close functionality down into the VFS layer. + Fix activation of registry globals in loadparm. + BUG 5452: Fix smbclient put. + BUG 5434: Ensure the loaded password doesn't contain the '\n' at the end. + BUG 5456: Fix missing echo if we ^C at the prompt. + BUG 5464: Fix timeout in winbindd. + Fix returning a directory value for a QPATHINFO on a msdfs link with a non-dfs path. + Use more error-prone form of testing dm_destroy_session() return code. + BUG 5453: Fix winbindd and smbd crash when dsgetdcname is used. + BUG 5465: Fix joining with createcomputer=ou1/ou2/ou3. + BUG 5461: Fix issue with Citrix on Samba DCs with more than 900 groups. + Fix wins null pointer crash in nss_wins module. + Fix lm session key length in _netr_LogonSamLogon. + Add -f switch for DsGetDCName() example and be more verbose on output. + BUG 5429: Clarify log msgs re: failure to create BUILTIN\{Administrators,Users} + Fix the DNS Update option of "net ads join". + BUG 5184: Add Missing HAVE_UPDWTMPX check before using updwtmpx(). + Recognize and allow longer UA keys in winbindd_cache. + BUG 5436: Fix signing problem in the client with transs requests. + Fix a valgrind bug in the new [ug]id2sid cache. + Fix Coverity IDs 565 and 222. + Fix dfs_Enum: In form_junctions, correctly check for malloc failure. + Add support for symbol versioning in shared libraries (can be disabled with - -disable-sysmbol-versioning). + Add new function wbcLibraryDetails() to libwbclient. + Cleanup size_t return values in convert_string_allocate. + Fix Kerberos support for CUPS 1.3 in smbspool. + Fix printing with Vista. + Fix deletion of files when they're in use by other drivers.- Update to 3.0.29. + Fix a crash in tdb_wrap_log(). + BUG 5267: Fix for nmbd termination problems when no interfaces found. + BUG 5326: OS/2 servers give strange "high word" replies for print jobs. + Remove MS-DFS check that required the target host be ourself. + BUG 5372: Fix high CPU usage of cupsd on large print servers by using more efficient CUPS queries in smbd. + BUG 5095: Fix the enforcement of the "Manage Documents" access right. + BUG 5460: Fix MS-DFS referral problem in server code. + Fix bug in Winbind that caused the parent to ignore dead children. + BUG 4235: Improve compliance to the Squid helper protocol. Original patch from Pawel Worach . + Prevent cycle in Wibind's list of children when reaping dead processes. + BUG 5419: Fix memory leak in ads_do_search_all_args() (merge from v3-2). + Fix winbind NETLOGON credential chain on a samba dc for w2k8 trusts. + Fix client connections and negotiation with Windows 2008 DCs in member server code. + Add NT_STATUS_DOWNGRADE_DETECTED error code (merge from v3-2). + BUG 5430: Fix pam_winbind.so on Solaris (requires -lsocket). + Re-add samr getdispinfoindex parsing which got lost in the glue commit. + BUG 5461: Implement a very basic _samr_GetDisplayEnumerationIndex(). Corrects interop problem between Citrix PM and a Samba DC. + BUG 3840: Fix smbclient connecting to NetApp filers when using whitespace in the user's password. + BUG 4901: Fix behavior of "ldap passwd sync = only". + BUG 5317: Fix debug output from domain_client_validate(). + BUG 5338: Fix format string bug in rpcclient. + Ensure that "wbinfo -a trusted\\user%password" works correctly on a Samba DC with trusts. + BUG 5336: Fix SetUsetrInfo(level 25) to update the pwdLastSet attribute. + BUG 5350: Fallback to anonymous sessions if not trust password could be obtained on Samba DCs and member servers. + Fix signing problem in the client with trans requests. + Enable winbind child processes to do something with signals, in particular closing and reopening logs on SIGHUP. + Add implementation of machine-authenticated connection to netlogon pipe used when connecting to win2k and newer domain controllers. + Fix trusted users on a DC that uses the old idmap syntax. + Only have Winbind cache domain password policies that were successfully retrieved. + Fix alignment bug when marshalling printer data replies. + Fix DeleteDriverDriverEx() checks to prevent removing in use files.- Prevent errors during the cache validation when ua keys reach a size larger than 1024; [bnc#372558].- Expand baselibs.conf to match pre SUSE 11.0 products.- Remove obsoletes and provides 3 for all packages and systems.- Cleanup the use of the suse_version macro to achieve consistent defaults.- Set CODEPAGEDIR while make to fit the install location.- Prevent errors during the cache validation when ua keys reach a size larger than 1024; [bnc#372558].- Package man page files independent of the used compression method (gz,lzma).- Rewrite spec file to build packages for Fedora, Redhat, CentOS, and Mandriva in the OBS too.- Add a script to restart smbfs if NetworkMangaer gets an IP address; [bnc#373075].- Remove all references to the obsoleted samba-pdb package.- Compose the BuildRequires in a more flexible way to fit the openSUSE build service (OBS) requirements to support different operating system targets.- Use _libdir macro instead of a local define of LIBDIR.- Remove PreReq /sbin/ldconfig from the libtdb-devel package.- Install the shared libraries with the same name as used as soname.- Update to 3.2.0pre3. + Use of IDL generated parsing layer for several DCE/RPC interfaces. + Removal of the 1024 byte limit on pathnames and 256 byte limit on filename components to honor the MAX_PATH setting from the host OS. + Introduction of a registry based configuration system. + Improved CIFS Unix Extensions support. + Experimental support for file serving clusters. + Support for IPv6 in the server, and client tools and libraries. + Support for storing alternate data streams in xattrs. + Encrypted SMB transport in client tools and libraries, and server. + Support for Vista clients authenticating via Kerberos. + Full support for Windows 2003 cross-forest, transitive trusts and one-way domain trusts. + Support for userPrincipalName logons via pam_winbind and NSS lookups. + Expansion of nested domain groups via NSS calls. + Support for Active Directory LDAP Signing policy. + New LGPL Winbind client library (libwbclient.so). + New NetApi library for domain join related queries (libnetapi.so) and example GTK+ Domain join gui. + New client and server support for remotely joining and unjoining Domains. + Support for joining into Windows 2008 domains. + New ldb backend for local group mapping tables + Raised level of security defaults for authentication operations. + Inclusion of an HTML version of the 3rd edition of "Using Samba" from O'Reilly Publishing.- Add libtalloc1, libtdb0, and libwbclient0 to baselibs.conf.- Remove obsoletes and provides samba3 for post 10.3 systems.- Let libsmbsharemodes-devel require libsmbsharemodes0 for post 10.3 systems.- Rename the libsmbsharemodes package to libsmbsharemodes0 to follow the shared library packaging policy for post 10.3 systems.- Update kdc dns-only lookup patch to IPv6.- Move mount.cifs and umount.cifs from /sbin/ to /usr/sbin/ and create sym links in /sbin/; [bnc#380693].- Enable the build of vfs_cacheprime and vfs_readahead modules.- Update to 3.2.0pre2. + Add library for access to the registry configuration data. + BUG 5023: Separate NFS4 and POSIX ACL code in file access checks. + BUG 4308: Fix Excel save operation ACL bug. + BUG 4801: Correctly implement LSA lookup levels for LookupNames. + Add new option "debug class" to control printing of the debug class. + Enable building of the zfsacl and notify_fam vfs modules. + BUG 5083: Fix memleak in solarisacl module. + BUG 5063: Fix build on RHEL5. + New smb.conf parameter "config backend = registry" to enable registry only configuration. + Added support for IPv6 client and server connections. + Remove unused utilities: smbctool and rpctorture. + Fix service principal detection to match Windows Vista (based on work from Andreas Schneider). + Encrypted SMB transport in client tools and libraries, and server. + Added support for an SMB_CONF_PATH environment variable containing the path to smb.conf. + Various fixes to ntlm_auth. + Correctly handle mixed-case hostnames in NTLMv2 authentication. + Add Winbind client library. + Enhance client and server remote registry access. + Add client calls for remotely joining a computer to a domain (including calls from "net dom" command). + Add libnetapi.so library for joining domains including sample GTK+ app. + Fixes for Vista SP1 Kerberos authdata handling to only pickup the PAC. + Various fixes for DsGetDcName and conversion to IDL based structures. + Add ads_get_joinable_ous() to libads to get list of joinable ous. + Add get_logon_hours_from_pdb() to comply with new IDL based structures. + Migration of the entire client and server DCE/RPC code to IDL based structures and autogenerated code for DSSETUP, LSA, SAMR and NETLOGON. + Started migration of client and server DCE/RPC code to IDL based structures and autogenerated code for NTSSVC, SVCCTL and EVENTLOG. + Use IDL and autogenerated code for samlogoncache and Kerberos PAC handling. + Add remote join/unjoin server-side implementation. + Import the Linux red-black tree implementation. + Support for storing xattrs in tdb files. + Support for storing alternate data streams in xattrs. + Implement a generic in-memory cache based on rb-trees. + Speed up the smbclient "get" command. + Add the aio_fork module. + Modified libsmbclient API for more easily maintaining ABI compatibility while adding new features to libsmbclient. + Refactor Winbind internal parent-child interface tables to achieve better unit testing support. + Networking fixes to the libreplace library. + Add support for DNS Service Discovery. Based on work from Rishi Srivatsavai . + Don't restart winbind if a corrupted tdb is found during initialization. + Add share parameter "administrative share". + Improve error messages of net subcommands. + Add 'net rap file user'. + Change LDAP search filter to find machine accounts which are not located in the user suffix. + Remove smbmount. + BUG 5073: Allow "delete readonly = yes" to correctly override deletion of a file. + Register the smb service with mDNS if mDNS is supported. + Add smbclient support for basic mDNS browsing. + Fix padding between Winbind 32bit/64bit client library in the request/ response structures. + Added a syncops VFS module for file systems which do not guarantee meta-data operations are immediately committed to disk in stable form. + Additional portability support for building shared libraries. + Get Samba version or capability information from Windows user space. - Add new sub packages libnetapi0, libnetapi-devel, libtalloc1, libtalloc-devel, libtdb0, libtdb-devel, libwbclient0, libwbclient-devel.- Fix build with glibc 2.8.- Added baselibs.conf file to build xxbit packages for multilib support for post 10.3 systems.- Only cache password policy results that worked, otherwise we cannot login until the cache expires even if a connection to a DC has been restored; [bnc#373552].- Remove dir /usr/share/omc/svcinfo.d as it is provided now by filesystem.- Prevent tdb lock call getting interrupted by sig alarm; [bnc#364200].- Update to 3.0.28a. + Failure to join Windows 2008 domains. + Windows Vista (including SP1 RC) interop issues.- Rename the libsmbclient package to libsmbclient0 to follow the shared library packaging policy and remove provides libsmbclient3 for post 10.3 systems.- Add variable to define if a share should be an administrative share; [bnc#358841].- Fix patch errors with dcerpc and idmap_global; [bnc#280452].- Fix safe_strcpy error caused by duplicate domain name fix; [bnc#356025].- Fix two memleaks if num_validated_vuids exceeds its maximum; [bnc#349581].- Fix ACL inheritance; [bnc#351570].- Fix a gcc 4.3 buffer overflow warning.- Remove duplicate domain name prepend when user SID is in winbindd cache; [#336854].- Prevent winbindd from segfaulting due to corrupted cache tdb on flushing caches; [#340332].- Fix kerberos authentication with Vista; [#350032].- Update to 3.0.28. + Fix send_mailslot overflow: CVE-2007-6015; [#343702].- Additional cases and problems caused by fix for CVE-2007-4572; [#337823].- Fix send_mailslot overflow: CVE-2007-6015; [#343702].- Added default printing system information to README.vendor; [#113759].- Add missing define of AI_ADDRCONFIG for systems with older glibc versions.- Update to 3.0.27. + Stack buffer overflow in nmbd's logon request processing; CVE-2007-4572; [#326261]. + Remote code execution in Samba's WINS server daemon (nmbd) whe processing name registration followed name query requests; CVE-2007-5398; [#337823].- Change the spec file to get debug packages again.- Additional case for overflow: CVE-2007-4572; [#326261].- Fix process_logon_packet overflow; CVE-2007-4572; [#326261].- Fix reply_netbios_packet vulnerability; CVE-2007-5398; [#337823].- Fix missing getpwent mutex unlock; [#329796], [#331754], [#336854].- Fix the alignment of 32 and 64-bit winbind requests; [#331754].- Add dmapi-devel and xfsprogs-devel to the BuildRequires for post 10.0 systems; [#289599], fate [#302668].- Fix possible segfault in winbind which could be caused by uninitialized variables; [#253862c223].- Use FQDN in KDC DNS lookup; [#295284].- Update to 3.2.0pre1. + Use of IDL generated parsing layer for several DCE/RPC interfaces. + Removal of the 1024 byte limit on pathnames and 256 byte limit on filename components to honor the MAX_PATH setting from the host OS. + Introduction of a registry based configuration system. + Improved CIFS Unix Extensions support. + Experimental support for file serving clusters. + Full support for Windows 2003 cross-forest, transitive trusts and one-way domain trusts + Support for userPrincipalName logons via pam_winbind and NSS lookups. + Support in pam_winbind for logging on using the userPrincipalName. + Expansion of nested domain groups via NSS calls. + Support for Active Directory LDAP Signing policy. + New ldb backend for local group mapping tables + Raised level of security defaults for authentication operations. + Inclusion of an HTLM version of the 3rd edition of "Using Samba" from O'Reilly Publishing. - Update samba-vscan to 0.3.6c-beta5. - Disable dcerpc-funnel and idmap_ad-Global_Catalog as both currently don't apply to Samba 3.2.- Make nss_winbind thread-safe; [#293907, #329796].- Perform KDC lookup using DNS only; [#295284].- Handle smb child crash; [#294895].- Add a global lock inside nss_winbind as workaround; [#293907].- Merge ranged retrieval optimization to winbindd.- Update to 3.0.26a. + Memory leaks in Winbind's IDMap manager. - Update to 3.0.26. + Incorrect primary group assignment for domain users using the rfc2307 or sfu winbind nss info plugin; CVE-2007-4138; [#307623].- Fix two memleaks in idmap_cache.c; bso [#4917]. - Correct failure of libsmbclient against a version of Windows. - Make read_sock return the total number of bytes read instead. - Fix error in enum_dom_groups. - Fix logic error in timeout of blocking lock processing. - Add parameter "directory name cache size". - Fix use of pwrite in tdb code.- Also ensure to initialize ip_srv_site and count_site even if we are not on site; [#230963#c124]. - Use an off site DC if we're not online and talking to the KDC of our domain; [#230963#c106].- Fix a bug where samba writes the wrong default value of max_passwd_expire to an LDAP server; [#298469].- Fix if statements where we still expected cli_connect() to return BOOL.- Update to 3.0.25c. + File sharing with Widows 9x clients. + Winbind running out of file descriptors due to stalled child processes. + MS-DFS inter-operability issues.- Update the cache tdb validation patch which improves the backup handling trying to end up with a useable cache tdb. This applies mostly to the situation that disk space is short; [#256166c82].- Update the cache tdb validation patch to support backup and corrupted file handling; [#256166c77].- Fix a bug that causes smbd to 'hang' intermittently; [#289599].- Fix event based krb5 ticket refreshing in winbindd.- Limit the LDAP expression in lookup_usergroups_member() to security groups; [253862c209].- Don't reset the num_names counter in lookup_groupmem(); [253862c198].- Make the days before the password expiry warning appears configurable in pam_winbind.conf; [#287871].- Don't link shared libraries of vscan with -pie.- Increase LOOKUP_SIDS_HUNK_SIZE for rpccli_lsa_lookup_sids_all() from 1000 to 20480; [#253862c175].- Update to 3.0.25b. + Offline caching of files with Windows XP/Vista clients. + Improper cleanup of expired or invalid byte range locks on files. + Crashes is idmap_ldap and idmap_rid.- Fix reply when no dfs share is configured. - Fix the DFS code to work with Vista clients; [#286937].- Migrate old if-up/down scripts to new names on update; [#283706, #285187].- Introduced prefix numbering of if-up/down scripts that they get executed in the right order; [#283706, #285187].- Restart nscd on winbind update to load the new libnss_winbind.so.2 library. This will not resolve every problem with nss modules; [#174589c88].- Fix winbind segfaults with idmap_rid; bso [#4624].- Add missed 'c' character to the list of valid ones in escape_shell_string(); [#273611].- Let lookup_groupmem() only resolve not yet cached SIDs; [#253862c106].- Remove superfluous requires to samba from the devel package.- Ensure the returned structure size from _samr_query_dispinfo() is smaller than the total size; [#203833].- Remove 'unset CONFIGURE_OPTIONS' in front of the configure call to vscan. - Install header files with 0644 instead of 0755 permissions. - Enable build of the python package.- Branch a samba-devel package for post 10.2 systems. - Install .a library files with 0644 instead of 0755 permissions.- Update to 3.0.25a. + Missing supplementary Unix group membership when using "force·group". + Premature expiration of domain user passwords when using a·Samba domain controller. + Failure to open the Windows object picker against a server configured to use "security = domain". + Authentication failures when using security = server.- Add %dir /usr/share/samba to the client package. - Remove samba-classic{,-client}, samba-ldap{,-client}, sambaxp{,-client}, and smbclnt from Provides and Obsoletes of the main or client package.- Add /sbin/ldconfig to %post and %postun of libsmbsharemode.- Update samba-vscan to 0.3.6c-beta4.- In some cases PRS_ALLOC_MEM was called with zero count; [#273613]; bso [#4637].- Enhance the patch to the ads version of lookup_groupmem(); [#253862c89].- Don't use current_user to prep the security ctx in change_to_user(); [#273613].- Prevent winbindd segfaulting due to corrupted cache tdb; [#256166].- Use WORKGROUP instead of TUX-NET as default workgroup setting in smb.conf.- No longer check in the pre package scripts if swat or winbindd of version 2.2 are updated; [#273160].- Update to 3.0.25. + Significant improvements in the winbind off-line logon support. + Support for secure DDNS updates as part of the 'net ads join'·process. + Rewritten IdMap interface which allows for TTL based caching and·per domain backends. + New plug-in interface for the "winbind nss info" parameter. + New file change notify subsystem which is able to make use of·inotify on Linux. + Support for passing Windows security descriptors to a VFS·plug-in allowing for multiple Unix ACL implements to running side·by side on the Same server. + Improved compatibility with Windows Vista clients including·improved read performance with Linux servers. + Man pages for IdMap and VFS plug-ins. + Security Fixes CVE-2007-2444, CVE-2007-2446, and CVE-2007-2447. - Disable build of the python package.- Fix heap overflows to prevent remote code execution; CVE-2007-2446; [#273613]. - Fix remote command injection vulnerability; CVE-2007-2447; [#273611].- Remove obsolete samba-pdb package and required packages from BuildRequires for post 10.2 systems.- Remove X-UnitedLinux- prefix from init scripts for post 9.0 systems.- Remove requires on release from devel packages.- Reduces the number of queries made to the DC in the ads version of lookup_groupmem(); [#253862].- Allow winbindd to take local shortcut on secondary DCs in case dce funnel directory is set; [#266853].- Really remove Should-Start smb in smbfs init script; [#242918].- Disable 'msdfs root' by default again; [#268004].- Build libsmbsharemodes and create libsmbsharemodes and corresponding devel package; [#264623].- Let idmap_ad search in the Global Catalog in case dce funnel directory is set; [#266049].- Allow share names with a lengths greater than 32 chars; bso [#4512].- Check the euid and call become_root() to get write access to dump a core.- Add pwdutils BuildRequires for post 10.2 systems.- Do not restart winbindd under any if-up circumstances; [#227942].- Replace unneeded become_root_uid_only() by refactored become_root(); CVE-2007-2444; [#262090].- Add repository version and branch to the spec file via build-source-timestamp mechanism.- Allow applications to set the share mode while opening a file using libsmbclient; bso [#3684]; [#203737].- Fix for fd leak on error path in winbindd; bso [#3204], [#258737].- Add gdbm-devel BuildRequires for post 10.2 systems.- Remove setlocale(LC_ALL, "C") calls; bso [#2926], [#247728].- Fix segfault and memleak in wb_lookup_rids(); bso [#4434].- Fixes a known bottleneck under very high load situations; [#247984].- Avoid passdb builtin group membership calls in the DCERPC funnel patch; [#248556].- Allow pre 3.0.23 multi passdb backend configurations to work with post 3.0.22 by using the first backend only; [#245167].- Prevent nscd crash in NSS winbind initgroups(); [#237719]. - Fix pam_winbind cached login for samba/NT4 domains; bso [#4225]. - Various pam_winbind fixes; bso [#4094, #4288]. - Fix DCERPC funnel patch; [#245278]. - Fix vista and share level security. - Fix vista variable expansion; bso [#4093]. - Fix vista DFS support; bso [#4356]. - Fix vista backup tool; bso [#4361]. - Fix vista deletion on shares; bso [#4188]. - Fix vista spoolss problems.- Fix crash bug in rpc_pipe_bind(); [#244892].- Enable DCERPC funnel patch.- Fix accumulation of expired LDAP connections when winbind in ads mode; bso [#4009].- Fix all lp_dce_funnel_directory() callers; [#242833].- Disable broken DCERPC funnel patch; [#242833].- Update to 3.0.24. + Potential Denial of Service bug in smbd; CVE-2007-0452; [#240265].- Fix logic error in the deferred open code; CVE-2007-0452; [#240265].- Avoid winbind event handler for internal domains.- Fix smbcontrol winbind offline; [#223418]. - Fail on offline pwd change attempts; [#223501]. - Register check_dom_handler when coming from offline mode. - Fix pam_winbind passwd changes in online mode. - Call set_domain_online in init_domain_list(). - Winbind cleanup after failure and fix crash bug. - Don't register check domain handler for all trusts. - Add separate logfile for dc-connect wb child. - Only write custom krb5 conf for own domain. - Move check domain handler to fork_domain_child.- Fix pam_winbind text string typo; [#238496]. - Support sites without DCs (automatic site coverage); [#219793]. - Fix invalid krb5 cred cache deletion; [#227782]. - Fix invalid warning in the PAM session close; - Fix DC queries for all DCs; [#230963]. - Fix sitename usage depending on realm; [#195354].- Add DCERPC funnel patch; fate [#300768].- Fix pam password change with w2k DCs; [#237281].- Check from the init script for SAMBA__ENV variable expected to be set in /etc/sysconfig/samba to export a particular environment variable before starting a daemon. See section 'Setup a particular environment for a Samba daemon' from the README file how this feature is to use.- Remove %config tag from /usr/share/omc/svcinfo.d/*.xml files.- Fix pam_winbind grace offline logins; [#223501]. - Fix password expiry message; [#231583].- Move XML service description documents; fate [#301712].- Disable smbmnt, smbmount, and smbumount for systems newer than 10.1.- Add XML service description documents; fate [#301712].- Move tdb utils to the client package.- Fix crash caused by deleting a message dispatch handler from inside the handler itself; [#221709].- Fix delays in winbindd access when on a non-home network; [#222595].- Fix client-side smb signing; [#222951]. - Fix imcomplete merge for firefox NTLM handling; [#198255].- Add IA64 and x64 printer drivers directory.- Update to 3.0.23d. + Stability fixes for winbindd.- Fix ldapsmb group and unicode issues; [#143417, #216606]. - Fix net ads account management; [#217046]. - Fix libnscd usage in passdb; [#217363]. - Add the "mega patch" + Add site support for winbind; [#195354], fate [#300909]. + Add site support for net; [#211281], fate [#300909]. + Fix winbind krb5 ticket handling from offline; [#178028]. + Fix "net ads leave"; [#196771]. + Fix winbind username case handling; [#184902]. + Fix winbind name canonicalisation; [#210174]. + Fix winbind online/offline handling; [#196859]. + Add NTLM cached credential handling for firefox; [#198255], fate [#300973]. + Fix winbind groupmembership handling; [#211324]. + Fix winbind site-support handling on reconnect; [#195354]. + Fix winbind child initialization and online/offline handling; [#196859]. + Fix winbind cached credential storage; [#185053]. + Fix winbind long login delays; [#184450]. + Fix winbind crash for new AD user; [#208454].- Fix pam_winbind overriding syslog settings; [#201756]. - Fix profilepath pam_set_data for other PAM modules; [#215707].- Fix timeout handling for winbindd (samr, netlogon). - Fix gencache access; [#209409, #211281]. - Fix libsmbclient accessing NetApp; bso [#4018]. - Fix error handling in ads printer code; [#209409]. - Fix passwd pam segfault; [#211719]. - Fix crash in winbind async child. - Fix winbind failure mode for trusted domains.- Add realm to username if missing in net ads join; [#211706].- Move the LOCKDIR to the client sub package.- Activate the libaddns.- Add version of the package subversion to Samba vendor version suffix.- Update to 3.0.23c. + Authentication failures in pam_winbind when the AD domain policy is set to not expire passwords. + Authorization failures when using smb.conf options such as "valid users" with the smbpasswd passdb backend.- Fix time value reporting in libsmbclient; [#195285].- Remove update-messages.- Store and restore NT hashes as string compatible values; [#185053].- Added winbindd null sid fix; [#185053].- Update to 3.0.23b. + Ambiguity with unqualified names in smb.conf parameters such as "force user" and "valid users". + Errors in 'net ads join' caused by bad IP address in the list of domain controllers. + SMB signing errors in the client and server code. + Domain join failures when using smbpasswd on a Samba PDC.- Fix from Alison Winters of SGI to build even if make_vscan is 0.- Update to 3.0.23a. + Failure to strip the domain name from groups when 'winbind use default domain = yes' + Bad token creation of local users on member servers not running winbindd. + Failure to add users or groups to ACLs using the Windows object picker. + Failure in file serving code when 'kernel oplocks = yes'. + New "createupn" option to "net ads join" + Rewritten Kerberos keytab generation when 'use kerberos keytab = yes'- Replace vendor-files/tools/dlopen.sh by test_pam_modules make rule.- Fix pam config file parsing in pam_winbind; bso [#3916].- Update to 3.0.23. + Improved 'make test' + New offline mode in winbindd. + New Kerberos support for pam_winbind.so. + New handling of unmapped users and groups. + New non-root share management tools. + Improved support for local and BUILTIN groups.- Prevent potential crash in winbindd's credential cache handling; [#184450].- Fix memory exhaustion DoS; CVE-2006-3403; [#190468].- Fix the munlock call, samba.org svn rev r16755 from Volker.rinck 1284464487   66i3.2.7-11.8.1netapi.hlibnetapi.alibnetapi.so/usr/include//usr/lib/-march=i586 -mtune=i686 -fmessage-length=0 -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector -funwind-tables -fasynchronous-unwind-tables -gobs://build.suse.de/SUSE:openSUSE:11.1:Update:Test/standard/b58f2aa7a1a202ca90400172318ac447-sambacpiolzma2i586i586-suse-linux6EoWS͙q?] c;mV;c #2+yrOp[c& ltYzO,X4}2jx~`( 6+ UthpWL)KȵvGy䚨2@ZRF)V!B&6NͺvN?t敒yQ*<5~=/q& HAEIp?$5"^l^7h JmD'L q"*АKtb{#5KN6ERu3 ZhQߠ%;BH-W(-?2o+HS 3^0&_$lzEgϱSpwՒs ymAk34 5NQ> ʍ處M{|YT1PC1(0q7"MoP%+Jk FLAo{%DV[8L&&G5e_mX@O.J )yGv.}h{V/Ƚnckl/[l7Unl@ 2¸ EӎR$B RRnj9YSrp_u E:j'h^$r!6*п,ffV#OA/}yA?~I/X"<7T@<3۳zcZ{[Om1^kVھ#X jp֒ܖŠ '9Mo]+DFByT1}eVpkgPLҴ.2~Go>>#G:(U&Qa,3(.gnP1y۾L߫lψˑf`$)F/6SO|"zq32b:{i!TEX-[Nrnk Z<2’8c( 4kr)js;F`S\c3O:o,$zQ^2o/qVDx"MrB #tq-e%$&hf7MBqwuSur]+/ f }#\U1UlM?m=ok:<T@2A]mѫo|fKzkE_Dx/dFnpDcu@Y}T_k JWte+ӒUpI yKW2*s"g]k<>FwnAsLN8BhfHVE~dԡ=cGa:*VZCݝXץYK#ÞP, O[irf\龝d ] I}z ȱ_܏ȗQfB/S2 @Sоu)"u̓)+Nb*W}K jZn^BIQ!`a-@"MS%w2-Whɑ`bbO% 4s8YÔ0kqim T&Rf[t2YzlA!('SAh6$i 3Y6+PT9ݗ qa SRB { ‰ߔY(Q5SFB*ň@æ54/Z[c3;S%zcʿ1a+ PIJ+\Z׷oV~XGT|>sa9OPZ@ ̃*%7VNT~)y EsBGѵ]:c>ě. N#|l̂R*wԦ,^$їmWg!$QRs;j^R~f[= B,]P7{P<\1KUzF3w$U|\C4ϯ"Rp|$аf#^=_lw.e7 ~q6`2 ;\ ;kpr 6t K ;1BYyf`4x_p1Qỳ16i;U,=U5nf_X=w uzU@]e-Ou;IE8krPL:6 +H0!ʃ76}2dž($歁Wsʙ%;>9OͶ lwMIK~lٯhtI:fB@kTmme_ bZRrWmgi Лs_h7n>Oqܞ{}ļ֟2]攁BQtY9Eo;G'(hu;lrp~u}}U;:d^>=g5WS$GԮj{c Q}# Gr %Z2:iOc u m!&5h.n[@ήؚW϶_DvSGX;-0JnoV#@5ZHޘ:^1 {3P:mɐ1$.tI,XѬ"~́njMHj,*W*!x;QIFqK)1`_./`IMFMDy, *u 꺍w-y|s.8g1ޮ (6D $v}4ap33pGVj7(͘|YS&C/2o_m?|ja]7YSgfO$hֹW 1j>D%&޶7 ]2z'ΨL:ͽL:؎IV@Y GY?/QmyTBl*? r\*ō`V5,KnLZsE!0x1+o+KgKy"k)np>--V\ׁʺJuDBBM˙c|tVZa  5ZuCʖ zmwT>0_n mh>PTaF玪"ͶP{XֿB D>Y-Xas. rFYFCJ9N}"jQ~؏fп51 f{6ٺ+pkiU:~waA[Ct&Ɲ*0AKtz۶bfùIق~u`+K(Eqӯ"P[:l:)u1|摔EM|Ý.G@~28?w'^g+ia(Q9[}vj/L )Ŭ\_ωcי@ygd)rbT3=0GZ64I>uFcL=ad1!5x1V0F%$-*﹓ *C~kd6f$mE>ɸKgX.A!)]n4tfԋً{sDZg .9LN_"m 1 ~n6)@#m≘]" ?5eH7P*%;^yNW C Y_'xWaS]VկĐMd 1~x逫Ɂ]Bw \np6BF_s=s|vgPG~~mni$ZfwVH% ;v~{&FOyjE- ۖTMnLDMw^X [-dS՟=`]^5x⁻wJi=@ $~Fpt*GϷ Fϸ;- *S'hςFСib#2 %Aw-cY0t԰4SK?KcGЅY EY_q|Ǝ(@A#,x?W3 2RܪkjL(YɦCh H3y=ޝpO|< z_h1?ajK#&FCmP&dmaۛ {}ߖXire鲕wrHxDiF?y}8G/!^v:*ҁSןgIhw؇ej$l>^~.gѢU -y%K x):*J]2'~Ur4vB>qylFx[t^k',RĤT-5}W?,u 6J(rT;Q48m1%Gzi]S?Z|W/ oØ@sXϿ̴)_:S+\ @@P]XcsHϓ SW-#ǨUoBV=⭇*䝛,& 4}0DŽq)'݇4 ͍P ժGeҡ0Oݭ㇉bjaHx PŠ3:VjĈ{QX|&=8=VMvObh2k+V$ 04*a|jqd1]Q™R6V\Fǥl(Q ~Oʈ wQ [w sUcbu) jkSS _d;n6Kw}+Um;/>lT%BtgkiaDsnzU‹X#›2c߲\We$VX,7q4[@6vPw9tR}Sސ.Fmk0nHLtRU70 Q骹Fo&_Xs.''PU%],{T(sl[5"0YFygFiwte&z$ Oky{7/_ՆD/[H_/e޻rn?t`Eyzǝ=u Mh'T^#FJCH뚕w?A蓙G'poRםq1(̷"E9@<Huq-*?+mG-gN->5Rd= `cђ.#:+H0*8cwUu:vJcѰ x8Es(#E9G` ]Ll.|:;̯hiǙlNScPd|<+DLGpCv!Fa1ю>za3^ sE{x &= >#ϲ )F 爩^EM˘gPɼW<{dnURʩk{vdnkzuP1C8+]$tL ,7C/OLS5K xP׋3I }՜TOB  1|)b$lSyn֚w*~^Ϻm_c!a'+KDQ}~E,|&S[hD(5RS$d0\1nb9<'1 N=2ӽ{'mYiP} `otN:3+xLluEA("|X|,9T{3t[Rh ;e-6KI z2o䳿Ok/W jEY9LJl0ZF*²$ 76^ŗ L&s`hu_K6σRwnvzsvgl3NܗzOt92ryf9$J*UpCDV꽶2%[k{ P_Mb[x'|Y7F+Hc|Q`]P.,ސ\1k9^+g[S/XޝkS)W4IhywI:PHY&XBTxzS0:3!qgJ4uJ* \0fN#?"_X}U?=GYIoVhAVj(q312-1Uvto*㚼T{9:)fFFiC*:A7ًُ{Js9*5z .+Q |C؄V*d3ET k;;h.$I*㞸b3B.fVhc|WwA8oJ.:6ۙCΣj-IDR!>4f9vHԂ)Y۸%)")nxR;^f} kJ+J|eY1.`>$=d~ f/9k)A׃|B48ܐa DTqB !׌9_.÷&]'];DillA3iB2(kPz#4Ο905[s[暅dh,="j=#嘴/Xm4_[&o| >ә;Ktdr;`D!µa6 CTt9GޓiJTҗ:d@~6?qzJMPA.l6'vB|َv 83T绋r_vS0GB'L91O$+y D|)KP7?!mHȗȼ}uvj!U2nԐ8s#q2 mP(.O[C{\"lY-G:lY:dE 3ot-QNF_̳Bͧ^;A̐HkVңg[s39"0JC=Ar rVfthNe6]򶫃a\c1?¯\T@ Sl||KQi1%m`iB0n`9( ÎJu ws H`j˘ktt

В,$TU/Tk BU3teYJ—A%qI+Fd)>7^vXU"FqMZ<Ri#+MHJ8‹}eӒ|k!q3i/"ʆPe߅Ѽ=5tωO5\X/V'Ce>|52G̺[>ȧgAWz͓ф=-Ǎlkz@_Rq_खasa._A[Ss5ZeN41xWbd̒YC 4^qhuыءqdC JE9D^*XJCRCpr4VOv|Z6ȽwLe1ޢT^E $CgT [Ri%M%CDǀbm :UX'a}w;zprJuyԀ\A[xRښ4=ᘐ^WCl0WJ@Rx=~wvOjm;W$15c%m#XvSp ֛L:^Isf\^ԏfQ< "gLX*5na[j8[m?#L8H{;wI+d>(yɊPNU j,>`)Q'g87e~رdKTxPk6r.ozȫ΄5P79p5 whbdsRG!="AfIݵ DxYP3qmﳟ޵78f4ɔBhs$6Bʌ U_x\ [c`J% %!|k·aM1_t vWj ąShp5Ԡ<G-, )B@Fj6he+\Ql a!WסTJ}{B`[ZQWFEN9 eh}{ΐNVHDr4&wFvBfad"%ՔJiֵhvtF2n9O]ߕu7έ{GؒpjhKuKݎ={sc>moQek8֏v$ӤeӮ|%5>_АDfF'PM6UU!GB:ʺO*!7hBvZ ;L|яӀ[vh9n_I+_;]:=6 mB}8|Yj|ݥ%ÈSYbxƪyfZJ`GRUZ.NRp3Y- \!sJTK}?/|z,tc t)Wި.crA'ic|٩d/ C ]^8uH@d,$.w VnQGbVsv=;w,%;њD|2|1~Ƚ/ąCt* DoJ?Klݿ9Ɨ{`=Aڰe,Xfb(y@s3A)SGͰX ANm!sNF{#(B%Q?U嵥ZWq"lO4wӀD_`? L'wf`+|c}@ cpޡ>*.cpm}dk7ҕc?Kݓ{ńҭ؛̌һsr+v|J@zVQ,=F J!6Wt["@oJMkYC+*}P+;㰢 CNddb-_f7`j[쌮_KdIc:q3;خLyek@-ffVtW7;iAjafwe/۔SSul1R5z~ P%Iy5LtV//sODfdc6v)/f3ی3lFEb`#@i,+#JOn^[v๊Ӝ65чGԀ|=Hc!K];(T3Kb8S>; ݎ  m#Xr4z.bfTkCXG6!uR0~{'wAj\f[äKNBYh,TC&c͉JY2ܺWUQ@Q*{HͿX-7p0أ)7'sFtħݒyXA&s >p" &x IߢX1r6 {sXH6j &=8-~ &QasTta#X6o?(ڔ4L"9<:RepJP+h.e:f[ FgpW LH-!&cpkqz?1jڐO!J9ӷ׸ }")8꒻F=oL)VQj >5VaL,2arΐ?f:* 6C2 v'XhM ?꾽(`n7yNiJ{@*V BH"dYIgۓvI&bΰ,Z7*q,J:^ 3):ӓBw0\~㒢RUgs.fK)/&/%=KmD8UC`o؞#kLO1_(ɩB.O|L_XPR<3v j`.3р|FlKƒM/%T0b3o&g徑WG'k|>y?fP,d µKJ"ޚW8&JQ-]g̬XcoC[~(c/c*H]Fa~P*CT(0竓RFd`1N}yX}!vG9pP`QLN,xgoYuj?hЍl~BsYZ_^nH {n !#m|t٢(&Fp͵ MZrcڎ" AcrDT|I&|7_pX5Ne2(:- $Ls\pec\Ў}W,9*ۺSd':nJ|@|J0[Y϶e< m6 sps4W45d_ zn+UpF&#\ތؗļRnz2{ADR_}DC3/Є̄6{v_M!Yc{ayVv,Zlb%mz`.%Y]҄|1qq'R Ƞ"2RD|VE!`jМ\*e6Rz+-ޯߋWO}=#5VStj8i&pbj;-/"CC{3c^##xHKJ=Y1θLL9rNp"x@V`PLI[{Mrp]++'>EE ^Hbx_$܆҅PMc1s;, oH3pBA| tG$Ihx6.ugM]ީ7δ MzBA1" ZH_wb}p%pq5M`Q6.Dj=~>c NOLZHޔe\+iQX&= #VDߞ3UP{KGǻmfFm*#Uxy[/D@Kg=hUad8.E)zdfO;28ƼGni-흿@)' Q͇^߻jtT=oC:4o["7[L@j 68F1t $ +◡8I -+kA(A{di͝dmji.#I J‹LUg4QNJyMH ;vi[\@N,Ms⹩QP{+ꀽiQi F,r[''ؑTXozi*|'psњ%n_=tSf+Vj=Qdz@=Mh_2^V9D2YY`wu4T%TQx~"B6>"AG角@j@BNBlEy“)a|Lg7 JBm?BLM$kޑK.3M=*n NXOdRS2٤tXGߊ`Mz` }hTkW[fPB8q8Cy6| ef≥>#@#;d9 kHEZrYA3-0&Fb`fb[g=P)JH.|q˸{{ LR_Q)H ccB^yY(wL9=誊gq܂bIW\ Up4[T=k<] @ftJ g]7 lBVnL4B`Itqi%eG &-=dLx9qu4VagVL-P݂3|KK4TGs"|eS*wXh&q퀰ޣaC/3$6~ V=9LiMa(2Q_’{oM>x >uP%1'ȑ\Fe>%$(?`.I++K?qӋuL`7k^H6 B7`QO"rF15 [$iSfޑ(~gy&6]Ch ,/*EڸWgkkURUVʅ `yl714:o4eU3`_QE p?;vQ'ZZ8.#@S'ĥNkpc8iEcpNxڎH>y'-~ dilKS@uTQVkFPc9ЌQQ~W6hXJςc7\NcK&$]0 ͢T#ܱq r[}X_yjRJ|ܗTzm ΧkwdRH$HNptY3N=dhp$-:J\3J&yLmzjUqQtb&Z6:eo1)8g- {S6(؋7Q@B,s5 VRg1YDY.Hn#5npoHo ޴\|,+E67[R;$ kv^#Ժ*!2?(3Ԣd.Zuȋ`wzL6TYS(Z:윗m#pek]а| H_: En(/)04w;_Ik-пQMEVj,JwD8,FP{mL,bޅbӣ8khQLG9Mt&_&qVOQ4ߦ tL8i O'){9SA{)s$0X2Zc7<5D) $8mL s֟,{y[`cfGorׅ> <>? f\ Mroa9{L2r#[2}.S-b 2=) \NCE"_X՚(uB#tLZ9OF?0,Sgsp+#dKo (W`QkiT Ep~hu޸^RkCvu mT_QT *rߟ%4QjEd!Tb*aX jʛ,'7nbj,O.F\ ܛI* vu= O_0 AuxGeTnpנō̬R]/P@xhMrT\&TxTl]Nģ&TcLo^\>Xp)XF9Agu\+7= ͻe]kdys@{!$P"t?;Q;RzO`XnDS y&F U@]9V UA$>sym Dӂ!_rH`18l6|="~.e[ׂg(M Bb J.? aSŪ +ݹy(G+3/dWX55))T }:[*ś-٫eK|nAK.O`okd4d~ 2%ebq .ޘNr 6(xʏVs#n2ųޭ8g qk uᔝUdXz I\o^Ndςr4еݾ^5\7eSCӖo5c<k@aB;x׶ ς$N-ceuvl6=#~bHI"MCWM+jUBBCج B?Oe2nF*z 1nfis $>.R3PN"vǪ7kǟ>ls=q"%ϥNAd?}+m@ZF]^}V-(O޷h @pB#RckGwiI COZb8vO81uKlxS}qBRxyĽWl|B:#vƮJōP6dۄ; G's4("" bnBʄV !kuJQ-A)}nT;sxD?8AceuubR8~ǡ h8$z+DVUv@9&Rw!2G|y#'qQ1e rNMQQJJBP_l>@+D.n@ִeFf Wrr3MU($Q|e5{\]i&hv\MS TtbN vƱ0KOVᴍ /AMNQܕQUaͰkR1{ *8D|iaߑ ġ0GAF7+G#iR{ڽjtc=JQyNR  Ni5pR_N> =LҒWq w;6>I _9wld-ҞcBwRƃZ2+Hd83rPm?p@t((fi= =3KɗkZy6}ϩC`v={9L]Ir}%M |͍N{Uʢ;]pU; .y~GxL ӾKOvBݥFnI1$4|,.p*+⃟r϶i*Ə #I/] Ó^vz5tYfx"5ߡ&\LubQ}%LVRM-{o+_>nA܊B=>IE\TYV:Qjf bOZ&cUPEvwBFUVQ>w]= )\'(inn6<#`{Fwd0L t;3^e{LJOjǾ^"pbYnOXӁJTU/@R%"X| Ii;=7LcɽR}h^"ڑ5e^b7zB>~,gegu}ynh_oOWf~ |()^T{ݠ$?A=VnGP #*ߟZce0 fK\E.TZ޳ȼkjPdu7ԪyXiLc<,DWm͒$h}R:CCB\q?e\H|2HrC!jrĆ]˸,{@hjuܱ٣MK [N.a行-C\1N8 TD8fw̄p H_y3!:ͤ>GPẶ"١-uHt5q[| HpJ^(tL=D$G 6ŞABM[) MMԞW HY!}vVc>T 3%PWݽpK^quArPkӠtUBk% ~!۸BdAśn25d8iHr]t"j#2ih8:ݳיVi1fvYeP|I,KYeep{IMY1*-ʚG_tJR)` {Ȋ e NCiZBë:q fTffoVlI;gS&?Rvɮ 7,$(n ц;-I{ PGtpUl#kLG H[8SZ܌閟R~8ԏI蟻8sqOE:#Am ۾9nEJTɚF^K/xþ~!U#^(p5*_rPIqe:kKj 8e=:,g5*Zc=@z[8LCi#M);Fdϋ}9MZ!ɝw'eѺjlOM0wpk$s w'!S'ro[>$9o3!w*L T@,0V X{)#@6sPg>b@h8oRΞ-oZM@P5SXݵ:#ֽO 2u h462d) |rmCf˛L0y?fK|H(2q%lBUd;n<=q-^ǚY&҃X6tnՓ0UZqWɩ[qYgqP`D>o溳&p.0J FE܎_չ:!tf٦XycZdLt?_)6Mq:z^i3xUg(LH8;cmi+a~Z)+YڲZCvb(/Lѯ^9$RQhdeDTc%yT{ mnq +X.^=`ݩs|I}g&F! Pp/::Jn#Kv\Z_eA # Ÿ@F:q7(cF!2ͯ)JJs mle!O_ҥfm\}0W7/fAζ(k'Ϯpg^?Q{UWE5e;TsS` 6 u9g*N=kTL?+01ZAl(1t"8‹>&I  nERCH&. bcdq-ҧ) $~Gs8O K vd"qĝȗ#L#H]jJ?€O^6 R!lR t$*"@,AbGG42DWODrD&2bN΂L?($?!~6֌ⵇR*(''^K\2kQ61/JhRKnXԖ5W6v)i: ɨqzІ\2p׌}DKtulX-|E{ 9{u)eX :,y,́.;liDa@3IİgcOtU])o) ZTYlg?ή?q#=-U|ڥmLʌLfq#D3GJvJgCC d .,v-PB9&'sDbqbAS%*a9sgO?AcsV<9;m>'Fbm b)غ5F,?fߥ?od!:&zlF@Lg@}D,Cf|$${]֒z/e$o +y&^Mٚ5~ $҉Ni O4S][!Kh39O+dtUaHg ^N[bIu[_(U*e;7Mk-&mEÄ5eYRB-?J Қu7!A=]JS2b~YFǡHa^WF~o@V1q˳#0wM C?qHfSwNByg}\M~wV?@'{,nmLɌ+GEX|0{%p\J]?6yKΞGAà/ÏY hANE ěC۰p Lƅ$;Q%gKz Aul6UsW|jklyGB7'>tNS.bM{p3H^gAhC|7 &J $q -8e3}ekrGRtDEJP.WeTxruѳ`s2z>E?Y;= 0 sǷ^$|j)fI[Fh+MUO\^ s"ۧ6yTxeҬ۾EIл_K8<8l33uSƾ_!UI45/Bq-R`;E*\F *)wxr΋']\Xvtxn X6ܹ=<ҖW@%c)ow𐴜$:ZIx:!Ox"}q-8Y+BvXʧ DfG *+T6ọITѫٺܓKVB,8;3|Gpe/hd_E֡ %MN(9z%rӔkʴ}#W ʣa ;(2ff!#UON8Op3d Kx"aaS '&:A*j xywbZk->bYy)S"Y3s.5*KG"*#z';%0&Y9DAƙ2p|%mN l1:if'_RbmX 䶯՞>>\2k^x.pjxڇ'z$$]GVFP4qg폳N`I#-ofEpol71}X6 IU`:8rU5 ? (~SpXA5׳y#HS -`J.YRba玮 ak TϋA̾6^聜ITߥMzOtthl6@,5ߩ@P^`pmK(D@Zy}CI֠ke9.e̼ں5 &DnH,pf^QR}ƁR;^jHėP;_ꄞ+ wJ_8mpQ>qb`C1oOڪ DSkHVQFSe+`s&^$($Q?qfMS`. ?weC1]wq՗7chj]W~6m0G $r>FQ-,LjMwJLmE 9%A1'*)P0mж6іs׏;|%$XmkAYXY#fB5>{lqPօMnLlbRwP<-h GߕRRo}NmUU ?m\onCct^]q1nܯ7Kb7lSqCZ݅WVW˔l9RKHJٿvԫYʨ.h}\}in(sEˇpڰqBw#;D75U^}KE(' .iY_.+Gn` \Cl|~՗Vs\hBO^=l_cXUX\ch_nu;Щ`ÆDev8F+|))S԰SsG zrgV"z7ԟ5̝X`|8>WzOfT`if//u4Y:b۰s*F ϰJD@\ӏ6g8=)<+)]uA(.[u c!5Ү j]1[%ʃdvsN`ϔy7wj:y w!pl)8 nPP0 8])?H\^!xIe\B̿+Kh,vכ, 8T֯6TC=3h%Ͱ0/3vN{"W+{©Ɗ~ǔsVx8A E䶳d"urR} {7 ߼E "Ъ2Ȩ9#1,nA1Aφw=证/n'@`ӿâԘ T$o5P(7XҽS$|W>!;z@02jdO>5 /@d7!!->XQ{Udw{ Ě ŋNgZnɇbB;Ѝ*)Kzԡ!D {f:6b#/>zbè`Cg{QFzCl"q$VWW+x'$tȸU̟Kcɬ2gb>B {9sߑ`siA$2ȁ$v07FՀItT (O2³$ϽVd+klT(&O8gajhɰiR=&d{*W9+ڠ*$7%݄Y'RW7Op  ']|(kmv; ҕH pN V_ur2S_ Xm.ᦄ9r%B m x[N_ ~4r. h* @Oc>G"cxGTlrܛ-#eirt^;67  ~AbZ3d^aw&$4_= w?6\C{lvY#7+XϵZBU3OŁ_@_wnP"t J-8`ya|YZ!pcbiɌUHĵ?6?>j%<9bK݉6,̃꾴}X]ws+"[wk^$>9>oMɮ &F0YþYݽn˛5uu /wI8Jݫղ;JYc=> &Bu%~NKΏxN/H#}כ^-}$!? P̕24ʵ ѫ lɐׅ#Jmz k: ~{[F&ka:g6^7K& #KYRv)S$<Aӷ0`]~zީّ!`W;Kc! 7gW չa}x9- S&P)!j+]4Br6edz,P٢oaRoKK3OhO`dW\P6rn&Jޤ"xMl?A<\HhݩXGCI3|,tu:UՓF_D,SLK.hR̦q!2oc Ŗ&2];ʧ{! sb8d|mAe~;GSǪGdOmY.d6HXhA›}uK~= W'Y^91RN0@hR"-X*J3cz\p;_*)// .ڷ!iMRVtc E5cqΦ 8ƭ ,8*9,F,nt<@K;Xݰݙfmw[8WvAl3xͦT{KsBUy`=DfH-yKjesM'n*S2?>k=⾅ ]SM<PKҵ 8 s$nW 6%j4`sfYghR!r5,`IB*B%C_P>;/喿2o^qp)ta^kb\1ԏJ̑:߮ԗHB$ ]$$M1J"?CzL6,?/*9 &`λ23;zdGH&RwJ'걋轇2nTt'0cwǍ1U4;bqM5ЌBJ2y\@O`]_0Sw7'Gv\Hl i0I-=e9o&'i J@'|nZXH>T+>Xܿ4Щ!a[if6GJ?çi鉞 "L)˿ "5Xǽ",=_R\ތ6A[~~Sw~qsFX MQN6A=K,4E\ݥ΄LaYl[4]q[՗;EĀ4A~Ӳ@\ӧoY~B/# ,vjA ?vv띝KfWMR:Z{ h=x<<^-մ&'kRAYS~waT10yƈe -6A5cTt0 =>kO۶S|]saKt%ͩ;'wO+~wG)\{R`qIR͋'$],81/cpgV7.3%|I8+OOo"B&q%ȱ^jT[㞙mO S(:JH>qo@+9u8Tb jG 8hPFJi=B6ߞ8޹H-̿ɮ~,;PZ9p; Y-gaez; ٿT_Ф}s!ɂZ`(Ēprk~']_p|!& 'ݙw_SCE3+ U뾐RqS`| CyMMFA6}0p Zc<]Q)Z] QAatr Bh1ʾĠ= -*Ⲱ@兘`~Uf(vNkNQ7 $0C8/{pc I }a&yjT*Wjb:ZYl0KaMU#5sdxl{yb[HŮ| L8x*O7Hs *wXa:g$E==xfA'QHPk┥.93SL(?OǾjd;HjVanA0K'4s Qq.g;`Ğ`0,vkv D 6Ŭ HZ!uZ}çz+є[ ė%ًji(.}5O${%w3".P$7߭Zz^[VYfʒ^4aEEV†àΉ1~v)lucV !'k >Eq̗LG>=WET.o :=:c288/3'OHKZHe*y4Ϙgr%䇘Bhݜ>N׍ ܖG<qX0+.S}3v{Ce4? sCRԿC/V=Sq'UzQjSY5}rÈӼCmYMWzO eHڊ,׮9"M?zp/-UQRBWWw|o_.Źk5힔K$E|O ' V!(ĺJٓuQν%'@?!,$A Hb.;6ȡbS08< kT -Lu<ڛwy k%1*rp}$n<|-ߗ47\I\HͰpHڞX:yI~+N,fɈx-GH_VX0j<}NCY8M2-_BoFrD<̈́>:Aέ^}/Ps{y!tP np J@X }JeWkQ=gOHU% +]Տ !F*);V.\4Sh]>W~- r)H\w#l]K*q$KhjרIa> skb2{F){[,C,ru82ˉHG֣t-%XiE_9fU >iqjgA:u!2Q'"u\O ";a1ξނshbtւ}62C5sKtgG.Tlv7i=;jnJowa uF%zTmǍO]J5Zt;b23&A69i%X2#<;Z#7**vy,Ȟ|ܭd67jT=`)6gAڅC~/XN5/%7D\ټ@HEAuT),1ˮMKf PbH1;6DӔ#y* -_V%/ hSLw][WAɜߕGRޛbMYDCXk1Gz_psTQw]YEW ;ylW|bGozSMö#jؑB>0~Sݏ+N= ,8_n}lE潮@{(OV(74jCg( h-ޘ ״<4}O*cdYLnxHB|dخ-\zÀ#`ځ%$wsmv/9tS%VubD[:+=I?D6:Z」=cB_P^2dl.dTo*Ea)%3S$LbF:ӄ.iˆGK;Dyg` (ރZp/W;کYN\`O=Bzr@n6Y ,  ]+Xh)O(0DW9zfJtKR˼W>_B4Jj+Gpsp<*Ŷ/>ԩ"9Pa/t}w_Ba7ȕdΌ6g4b()hmwX/jDQ$e|L`٤]h0??}Qz,0&8' _| Bu|e֭@o|Gt }"?#6>k!z]Lj*C9Ծ5ٖ-?11qcnD,`iXln"9>k%Ĝt`^b'欆#*Qpߎ12A[][AV/u|5 d*T6H"ϫ>dį|e޼\w] b%89cřk":Ȍ h &ON(/TMjn`!>s& ==\TK_(xY]j$<3e(^Gئ1tP^D_RO6tsHcxJ$}4i!jD~ *VN+ܗs ]tL\f+Hg(& %akvށ66pWMu$A3uF o#gZ 7&#}j 8[r|AS5aE lSJe  zA;@ +1@=cC`BҭO{8oODohk  OjѦ]ÔpPd+%lĴ(vJ֍ ñ@ r)ѥ(Յ 7Oc^wRN0fqv#d4 TqU/\FOoSpt.iDd*RZTNuتT7\'C *Gw3D$#q_g/y.*9_cm })CU3-e\u4%R-\[)l~]gyf[k[{dC%@ 42\ MXnPEĵW2g ۬|@jy`bGLNQ ԚՔfG\= E]UI 61R6n$zN5K r7Rb NVNjxa!P~Iix+o3q13Ew30_.X NXC8^ L^ opFKμؚQ ѣ.[! Mn ÷TbmqOJ*99eu&fN?SL+KIz<|,J—1HeejqheL?g P6k+R2deeq,SQ!T! Y0P)iWK.;a"E }n41-q% U^6)6o͚$g#1Wk/:q=x:7n30DgoY1K&)?sjq⑄~WY6T&4Gxٙ:2l@;?u, *lp,5X=^jw;(hs1ԭs;> ~Q #0Uw`3`K(!}-,⣍nj+L0ò2@!]ǖҮ(1q9QݍG9qompZ p{g6"j jU2$QhĊ=%@dz%փ$k=\=񐤯"E%ؗsOh"˒N!L}t+_EU 1[R^~,jk EoXSZoݑdݛ=Ѧ1# Rhn#a, 7_zS3.>#:=p:2 $ IQmUa G䧨>dup8;-j-A$E>y:@9"cXjIM0"#4)?⊰wV/ /miVܡ_ߗ&6YԞ@" 9^(]sjLUEվ|!r?$$**^9-/923f I#*y+a쵥/[0{\F0o$^W&$zm % XUgpq9!nvܺÔݫbڢ;xnQC1?i]܆^/eʲߦo\736Mڤ݈|\MumBU(Qljٕ>&k\a}9¡aea՞+v?8i~@|X9eWXO~r;ǵRf {p4Ssۑ[U3_TNw6{J~/o8t}X8}p`OTu CwG_ .~7 7} Csۅ+"ԯ/&HV&rɤ Xj,r2莳l{q06B+",lT19(']Lٿ}UVOA5o&G0'g֯ U@ r|҉Zt.):K;wWq?] VSyMkkOq9p,a)QipD,$Pu͊kJRGt/6μTvwOn)Ņ؉=0j|ݸ/}ev1jXE6%Ys/A\"8C'.Ƿ@s ZdPR ͗Pif Ecx^k3ˠZ8jF_釴8k)ێt"CSf@ :eH5]g$1IVy~B>3! j a5*wQ< ?;x&%jh粣+=80 ,\GE/n Q0[u"L$,[zέUn"țnoy }BǬ?@>m.~#rEΏ۱՗U ՅLTU3YWYQyl:uS:#ș}cXa=_`Q,ܞeBr"Ԙ^Q+STZ:h_UTēz&]^ ,ӇV`*bc-&YK_;ÎiB/C LrSJcMH2#ma#jGt B@%7PrÊ@|r ꔫe:]]*b^gA cLʒ ,Ժe e-z**]p*i9 x ЙQ/1[5y|TZ^Y:> 'peZ߫iC'0*>oRU=j)\58ٶ93 ,gvx$6F%HqKk%L*ˈ8yn0PgdZ XWԍ3&US_~U^ϧ9xgyw |'T|7ֶ2S1D4C+a&o}6 3߫Ogd|S(J~gy#S6clZzXkn{t yɇEܽEU\MZoq~2 GuxCU(n>&7e87u&1#8P3B Vc[bNlwFjK,)j&v16Uԣy;]郬aѩrpOa}2lOW>[(5祁fȄ@WhM]uD(ց$0kL?a W `DmH\e3RYd tRHA.!'ME>]^tejb.f![qC $1[$%ӉĨ(shz5]uydSf!’IEMNG47 s1=GO\:(?Kr\=ZhON- :A` qعVM37r⁋`֨EXW  _OєQ+eH Yټ%UR%?FqHEqjC?jǨqo-Й=7"#%.=}HRfTsgcюZͧ=ژFa *B%ȦslUU[`5E+xZ-aL? 8؄_5Dɤ9[cu6 whQ7Y =wa;v ݝ*i Mjq@ ά`zeLAm,8ZԞeR||.D,>1@E1k>9BiOXy.ˡ|BA$yM哾<;`twErظ3Z9aXV@~~"LOn,7I,| WNxBPM+V."LLci#Iדb^&3vc<u{VN+_xp ۮ/R{H&:Ֆ^ͧP06旰PoE_RV6Y>QÙZ"w*^ɷBDavo~`2:F? SvMV7!_J;Ԩ\ F\=_f3Hb0V"򃢬ɢ~t׉&T:pRBPp%910$CO,5*|uLo8r ߿:,UA zoc ]s| #qz܄h'*俍 ~jW )i PҞq jD4Y%X{ ˸K;11pCZ$Z-#ۋVc_'39ٱ]M7j[Ш9&o aSc% БQ[iOjOR BvLJWTS,ex*_ekYnm65WBhj& $[(Xd(>nLn~&5n[x@BH~d>&nmc MwAA0XPy_e|@q'VQ9~-?&6^?cmAB؟]~d,~Kᡦq/|CwstctϫYjpT %ˮy5$XVS<ъ"aSnL etˎorrT)3HRc1`\ñ9q3KeZHmQ4-3p6Yn8T^iy^R),ɬE4ᚐ(e|o4哻lZq~ VD0e*Ů_Vp}#?MTVb6 LN\#5((b¿K`Le3< LDNb 6`j8a`y2ڡC^xxCLH#D9P,n|"R ]Ǻ|t >`}vxgR:igGfo^-0LKhBH"0[(lA՘ p0hlxbuHM-DX{P7N\~: p ~l80]׎]<<'=URO%COpi{]$ձ3Q 8?%YykWRi eg (&`o-,E gZFRH%c!RYqVƁvyvDv#)7rG\S\>ں@tڤ=jOЇY+6_5]CSubn6h6P E< Fv; LXZd+L7n9ez]Qlj(Ixz {mBHIXDSBXxF'`7-Fp3sM a;=bBzp] vs^&) cJF%:ސR+ gY?ФPPaY -y^ZꆨPtKQ2<oX>9Q0jv6w#p0x!)S4{y!^|L$ɠ0Ƣڜ1h Ah^, Lq9 hĊ2ˋ~xc,wZ]*=Q:nBac^uQRCHR'y3&`M Eh` o ڬk(p}7z1f&dsƈm}s VtP@Hh%ZY ( %2s@9f?NzX\si g9-bg$ 6aQLb/9P3)IorY sH3`yȒrC jĹmA% ,q.BZ1OznH5nU6} (WF6I!!lƐٛW?&p K=- R#>XmiU|,EgΒ6uH]%'sP–>MAGVH0)Hu򺜺_m4<'si:9C!>]I\ 2E^ql}bF#Y<5E]*Uxg(ەjm4$6n~_EB[Ѝ96=|iIyLB/to.UFCw mx37r*LѸ" WO xMZwg9uF^IX9t/xCҘUM9<ӦLwWePq)l"cLC!Bh4Ao?kk,MVou!%pFZѶ:8ufS|`&,VGh%"ƍXj=I] N3O߃e5jFs4}Q+Ѯv^:@#g ck[i=Yn2ETϘJEIDx;@mH +KG4RC}ʽ~}CF%[9DfdZݨ˳W7 } Z|@yZGQ\V<%h.'`a1{an/b^[ԔKBGkøs/|f5ob}"hƋ /h8+U|i0Yf)=Vim&ҩn}BLrJRG;wʫ=.$i-`U|jM43|9}\%ݟ /9.G8YldK$Q1%MJ5EB!JqE9-_$5.6U/W^U6VZڍI#ҳD߹51PA ]'лkPx}زz0('=p w 6YoHFѭ3PɊ =? k͂7~"aTp6&WkgLAc\t:nsR,qjͅJ202ւP kmnXIDhQJOH&yLh*g}5:M5| J&ҀJM\ *ߏЩ*HQA5y _15q 'Tfwֺٽ.GAwbj ^?য়qY lryvVv~tTxDܠIZǸubF\ 'B 9b(U)VmPVՄo\i6`AזW?pPGYE<"B= !. [2b TL׻ 2N2jUע]FH¨mifAo'uD f6DlYiNdWMfPj3H`E[CT80`[INiyjwVC2AjN$bU(@mSnYߕпs^`%-y9,E#1Sj4e:As~Z7XekZ|E ]z|a,.4fYYQK .ʟlsJ} Ġ NB|!Ef`qOc[Ŏk,,Z4TiK{ q|I&)\j ] s֧>DtV5[e'0T7}RDAzĽg._cdzmlJPS *1͵LƑ=hA8 |lلdIB43]np[I2ASYuM1YhEE<T2KEog~ON?ГIu齑4yFw s>dwk9J(.''1L6Dy"؃LG13]V9[@QJRg4m 1K'+%L2~ŧdL6փA\<-|=lUru^^ ȶkKJl瀈=TṚbnPa47gp0Lvv@1*'هPP̵=.J?V5O乨eYe6( ہ{< n )' NSh;#Lٮ4i]H u**"rɼa;hPwZdq)RDR!mDH|$y)X\{cT-O93c.'ΕvQ uxmƥl7HBo0+ȵUQ|5fc ]o6@zdΐ҂d]¡"mU.m@: k3`~ j:>`g}A_+,;8!8Ѹɚ5.<OxU'EYҘO@qL}…eT"?I 7M5=8!j b2BҚgjmzjs_#JLǪW1UJ6p{ի&'g՟\*Bsj貀qJ:^65W?GS;țJ`Ҭɫ벳L%ÇOF}@k[9!j 7(iI!wlCH$9^%ІPcX''TLyMGm:u$Y~:1ɠseҩgzyO |0gq9}2ϲ@]Bp8SYl& #+ N3f\pZh#6'2 m?lAt#`6VLg3n4~7^f"nbxNoxvC/;yuT-/A5zU(\"O'oݗʽϟf_,6Kj\* Z: eeMH @M,t0P#pK7 ,Z>OB?WpKIȹ~d^98_|t9M֘qN^/VEJor9ڌ5ĜMEz~g9޻{̗YP%+u}mt} !2Zf&=ܜ\뷠#kV굙DVr0Vɳ~Am${/lٜ@8ߪńhˌII ԛ~5>F*!{d6)VqEDQ* W( -JF?=~Y UO%/u4+2lʲ>O]ʐRP_ N+FN\ql)v 5 gNBESIjCWg<6KmOː1QZ et&? ssbbRK):P6j0-jiV#]{-gbuq=Z!T?wJV -WMW"h`Tn`]i$Ö:.gѯ\UO(v=[9z|z NY\h&DpB"_I+=~KBQ̿6tc}( ?&CO ǦY↰ }s_|38/$](g$$>SGM8\H l%P w^?ɃL,'[2 k[<~ 8#Ze?C`az}bin4P.?O2/Æ̱54%>B]_U&n Ea3}w [)Pǖ=DM oB#%p_sF.d$ [lmG/dR\ˣ%CIc,]qgIVq(8-#ER=~/F+m/{0p.֥V~2%rp@(j> d,lvTU2ێnGt$Ciϟ6\27>P8Ji {NGΗ Ao3Y0$`6U)-F!m60[|"hg8aM/߾f5fn:C3k4> ~u(Bu{RfÐ,.?cv[w{F#D˘Ãz!c-f uM_zK{u%Dw)|Tf5?9YER=bGDT a45>Ė9d(k-+5ǿI&f)[b%$D'm4'zO- Oabr>7g#cqJҼNesUbie\fb$ά{m T@_N"ҫPЈ8 C5n~BlWMT%cͅWC$I$\"|M$vS܅e4MmJwB/Ug]f{yg _뱙QOwk&`y+Q<%˙O쌽sLuZf)XU>KyͬI4 m?*@dZ | V M0CBX?1 fʘ]/Iuhk6GM`0CW]jb2!BUi(I 8zVbFFnYnɋv=o`=3!`C>r9#wq{\CYG4z4~:++CX*q~δ|#vg";SU=HUHlMWQZ)F8DDsoEgXÂniDL@55Y衛-yL93Xf,╗Jw hOY DeuCo:u r֛bTONOP3FNc{\cJ4Hޒ콈 ]K4˳ ("`6K'̽M$uw( a(g%B92Z ]òX^2/5k4qIEKoˉK>NH>6ô[Q/*JK alQ^PiZTj Ý<7=tLU-ErKVRٖcбeNa"tg D?{ۑ` ݒPPR" 1 liFo 1ѧw/gi,.ojmDngtP>9ՅcaZ~%ez6V}=@={]4rZ*oSH  ̺5yM60ibl ~M(#/}Qw|ldH= JP'fuz4C$0q VV(|`ISʊQ\.[sqG>lK"r?r{#+~` Q-#b ,T(x_yCHv)b) w_Y  nEz6cU 4Ľg 7)RqLtuv}>x#5mxpվ!QKM h9a1:-ُYbfp:څ)hO7qn#1$Vl|N#R[Ych!agIH\ݟs OՉDOyO)~ gkw L2-WAI})|#who{[v1IGFTD? _5|y8%B'X Ȗnn{Bnp~7azd;fQ-CK?0TQ"d1!Kj[wz!6oy%ϰjR T 4/iv jZ)&BU}m`i3 uvL V>`?1'{OA'%.{kRxpxiixKC ՙc}$ɔcT3??OK->![&S,UwroLFD%9x~.]X T`5-?Vq.`q3 1yh8qI݄aW8Αk0uQ:VmP3=#J+w.T͹okD勭Ir$V+mJ'2=Rzzrƃ1)xA'* Fh(Yd0[AxH;2AhjQLU vm? c)&U^"wK1#T9F,[Ĭp 9$牠;@4aW!C@EX!& a_yC3 ~x4G 6|Q[^knjn#9csr0X'34n)y|,^6%@#T23tlc>v547x㖛>'-B,^9|5A}BK͗ \q l's'jTՖc71#8l4e-ڵ} N;N!x>jM |~E%lSOC!pFӣb/lM MLљKeYL/ KMT-"aMM=+]x'u"<9TB!=ĝ(y@`-ćbVИFFTL7i!۷#?|j֮.%ZYqxcnm`#K9kp/\벁/‹$ h٠1.s13 ߒEd\2 |yEc\V{k "_\j09Id}F(yX w>B}O)h[@KgL綇k\7 y! r^o$JI17I.J,p7H6~@X ei:7\5z(mJk/vի ߖ&ˇCl@Uv0u S@g*jkow JzUh჊*1Mߋi[*GH PUe|E{֕Z㟟}- CdQP, `;]\1Ԝ& Bg\ #]l W6"#ܕd1f¶7%N-3}sײ9>cu^ڏ/zhȚqo)G0u JWkd\G H[)g.!~Y/l†_f;L7 al92MI$sʢ(yV4OH-wFS(i6pB 5AލMCg=*J¦o=A=sP0+B4Vĺf 1#c<ſQ8Oz 6T:c# ad<.r=ukG/gvQ<zgÿ82A+calDa鏈o7CurVKQLgLbkl)&$5_Dw kmYڱ hu!ٰ D:(JE-G`߮19ӞH܋muw1'V>!\Flznf=X_z;DѐDÌx^ <-2 _pkB!!xitIom"Jܤ16oe\ -Gz]̡Z-UǺp)OB YLFh_}e/ 87`F'[+rvAzbxE@x;s2[X_91tp7QJ F-v'LNm B񏾯+_m!27|+bV$ Zq_%۵BLB}|E[b;Rs\cqH rNJ锖xuycDf }kU$hb'VY|qn5u^ ɴB{a hj6$)_g>@(|*ŠJg5Z8-j1,EˆUz&23&"Rbk28tYs|myiAuΆX5,s) zb˕s8DxIhiyXW⯻f jo)Vt똋X-nAڗ괤9a^:WӋ5AƜۅFs3bմ+lF)Kh geld^)1]wG۬NaPza{i/>QOu"ĴLlD*5RmF;*cfKV ~c' re`O԰0de-ӋDaQ":T5T]*NիTxژbf6]̫fq Ӥ4F/yZ <_DLrSг$mzKLpޅFkKKAw*z~曑Qq%N pb@!Rkd6 VZ^ źKQP'ʯqF4>HZw !ɸ7׋7ҨLV 7W\ fh~G >$aw~s="~.ɒn5Nn: YMʩxO̲vd{`bnN"}mTԯ= R );*9Mu4Fkm>.)5^7!ۄѤ9 gH  |5Q u*\1++ z i.ש;ςuhE X_L+6򲑢j'z;0ähK&qRcPq`(΄@"߮٧,q>L7~\MZJ`mQ> d]ïJ?v0: yE>q%z/;5׼Fa [j-#5>krIu w~ ]s7"0?/3⑫ s}`PD&mX Ka~;@ y^5qO@҂ت\BRdzB)sX6x_IM7٬ HCE%"[_g~Bw 央m?d @cW>( d *\䠆#cAh"Zmd>JAQ U4ZgڦwW+yON?sfƤ"t k61SP\%TQ"UvUz/^$c2r.9^Q@xP7aqPh4* —TFn}Հ8]%,;hEHqXªRJuu iG3 A Ԁd!ð? nsqy@95?GQ@og{i\Xŧ-SZq' XN)z')@:8ԝr/#a;CcF͉NvYbF &Q;hS ю)Y+]T?q0x3 '&Wzdg{9>+.G*JZ>Jq  ȿ:TpXpEgBU1pNeO~JZKd#4=9b B=Ra(, Ű+緡 6~_[\.6:̎ )BtlMZ}NV"x$Uۚ\s~@8Phzn|4Ndihs*U5iU2{k& X3Gűi&.#+ͶjLnzV yIoo9قuLV)]|D7Blf^}8[`Uf%'M ўu"f |\zRVid]bImg?aE\w2nW (l&3A;lmRcW-vN~hL4Pt8b j| ѕ,hnE(2IEԁ0) ;ٷnDug\uD/#bEQ97ɴ^D_4:`ܰy-~{Jm,>s'>ծ>4F GęTA$v4,u@}۠syqO 3XƓy|,6mByk]>է}z~՜0ojtHtH'QM> Şi΋^5t@@ʏ7K&c5=\Z!c0v 76XMV`] g0Ӻ Z,k7G;nud?5/YʳhfWf:7P5!‥oͫ/8]^%X0acO,;1AP>,i|,/FJqp[ HѥncP,^wC_-b  o{cۿ֜x{R p{$m_2݈SS& ddrp}d iW~-#͋Eڬs /*+yK yPu\ZiJ~(._Of\bB5^{oΖxnɿ$ؤo o`ewJ%뫴z\~d.,XIFBE\90/4=?7nIT2'<8[JrԾH[e}${;G̻"* \q dU %.gY0V:3UXO"\%,**0s.fmMÖKɱv5BdZAt𡝙>)u@ 2L$6XZz[F(`䐌"w#U*Ed-]ۯT xk2vBtKFHs%qvl/|h0ZNvt6λsrgÏ7:awDLJ[Wd=$20Wţy~{oEl8I޾7q%,de-\<"Hބ;[y‚pda~ޗM+^A>eF^WHypF=Ӓ&tǶܪy8<ÙĢTfZV~Gin- ֱkjX4ށE2^9K^ ?MEhUKȵh')z?,p?6*{ ^xQ>iD>opX&7)v. +W #Ss L(/O7eӁEYy߹uAmHX3<jo#0x"ˤ(Kc}@5?s$⃓LYꥎDmkV k#ag(8$*AE`MG*C YL2cof\ҙ{t]_=h~R\+o{[IJ@wvn8W4!0NRO%yVT tCvgy_j1zŌeԐF<; wn_e-wGGe&yE뵯DXl`W,Q6%H~U}l}(Ƀ32lS&cFqWg.Rajvf7 gھ 7);3W@  ġU۶pGZ[IaTIeQ!Ȯ /,vJE$eQ)ңߋӅY9Aw{ڑF quhɳ~łWL:sBXkPkK?4$Fls 5?w6!rE]tM ?@P<_cݍ% [43 _ hv+2$jjɩq4/ ^,ɓyd+#LTo 6/M2}~#~$79ZIp>JgD= Y "n8nA"mΑR >kq5q"߯A6*lyʘb6 +A|Sې4 rbe\"46yw'b[z $"S77{;kЭ=.Ix` ?hJ.A:q!^V@ u?4T\a\$Y(N׵"@QU&NvOXh~K64+7gt-h_>_ky Ja5bŶi!.L`YVVOkݎ(uu`zG {@Ɓg-['bNJ&[~58dt ~R]q#M#!1o>G Q\*?~8dPBF$I8لE)ʯ]m  W_uEnmA>%g)oU,]sٛϟqA|e}oO}6PKa/z+Z%0XlpNg sD-~Vb^2%.s 8Й0)6ׄޭS6֗V#"9-zw<rYsC\ 9w`+:xX:p4j6 Q9 |P@GyL>߰CM2uSnAkN28+gG?F``Ae+dƁߓ'5_7U;S4E}u ] YԱ#fB;N?&g9 W7 tJLC[35roK%̱$=| Ʀ{L#k`<ʹ}4:t:I7`E'itA?oObD.m(NE{%+JVG)vi0880zHQwMjNxHeіSdB.(|?OU},%_^`" VUqnP`;'Yg 98Pah.(=V>M̜wY] INn@ ŘE  r\v w^2FVm=ދk`M\Hk,WdCy.|uՙe\dӵJAmaں{us$pŎiCۘ,O_LUl2V9| Bq&FbX,XKc)+1cX `7y͈twr5}<%?&(N<"m5۬ОX %1­jbc+\1ej[E< qKNEJZhFZKuq`i:ʤۄ ^NJs4FKDSdQ^Bh_ 1Ŷ[W; Z04?*\$*)ڠr+n\\H^kwh5gg%MMlFՍ5DݏtO9~eˤv!Fxf]52w0Ci2IZM-CNvs`du_J'qvl@KB|QO*O~sمz#PR$'p {QBZ%S)>?J9Xk6HXZ6:"!w*QȪR+]n}V `TX-vu:ޥW kI;Ff%)d!rU~L[ ѬY2-cLYw 21{xv);HxA%o]sFDzk,œkv ]:^]LKuz V,ȲS~yod7)*qU  lwK%mC& =cJ,8鍃58DMĞyw~Sn#Fr~<6(q?׮es)TMT]Nj!|͋&Sw_Ck:>J }U+3QbMp:!WX(%1@ YYV+O gmnhXowߘh¤rVc3*= lewuȖo[n1+c;*jԧCB] $}HuҬ}@(A~,rCGa>-{*%f`;]ͭ:)CML}p n7~|^'?­P#AE #Ölc JWV!Bd- bb/ŶwUS \c",㥭c?vx6ZKt˕t; Idh_da&T,pSGQJh*;of%Мk6z?mJ3bwG!oD䐓@z {Sa>!BetQm$pDnN U g&E^PrrbhlŅX>mϓ]-e`pC„a&H|`讎΂&;SFEq0gUYHT h k lKzoJޮ2Chg`۫Y\Se,&} Z35FD^4S=["ƁEr%dKr)'^BoH#G-o$-J.Εarf5] lڐ;!JhH7"rջp1I47bÜnHۊB5@*'}^MFzrD: 3}^cz !*gQ |^KWr׍)j' OJt/+)K||":|DNg5?ѫVTz3ߴńjUBX,Wj@( %Ѯ=Ӏ2]$~ /O>eؕ NrY`6g瀵41F>-|h:ht%k#=A&%9]bm2֭Oyl] `LK}C^NR[Fdl0C3. Ќ~oC: סm%(Ŷ>IBou~$CBl3A3`Lf^iZ>qK;$^q+Q߅OMR`لaUa[/a\9iݍ3Rѭ$L ;BE;L٦Ewц1"59E叠rycmFNߣGΰWs P(HU!ٝd-m aZ[O>aYloo39? zp}&Q>ٝdmcԫ?9Y<e#4U3w╅ݱ3uvgP@C,5l1 a7#/Q ʐ$f?-*p84.,$˰Y.Z_}<+k*hb/Cytҭ4tI) Ҩ~6,WtTƖPNsTk/ۚpkMG.mc+bXXG`ӆ-jY&ZATR]Jjb\*??XU)~-!c.AqAQ9F_C*Qd:OZou0#ƕ[-HxxP]s8׷d7Q`f3zx4\Nn2 ]ɆXe4FS}3"f"`)C@(kMw%Z'[Ec%H|ʋQ0N!TvitF-&Vxu娙~jZZ[`MUMt$0U9ҥ:D.*KU@Rau<Ʈ8kԁˑO(H4B0Rŧw.Wa>/hݪηGE2P.OQXXcVf, #I2| [lI۟kvK;JBmo'@,dbo09ܡW9$V쮈=5X8}Qa$qTѹ?Ɏ\QN=ؓڴ$d) t}hL7I;zV#"t* j7Jn3e6^[k%:_mc;A?2N N`wGsլ*Y,$`ԜJyǂJ-$KkXǮˁ{GXnƭgSG`>Icwnd j "Tl`Ew>0RȗDx? Vb .~DC{[w/){7jЩC4#Ͳd2>5T!!1. ĢY]R}X7ᕔO;Hbu@~jE !Oi燮x*6J܊ D2lnYWwѱojmN׼3rbj ΢0|cLO"tB3[4IvvL}+nMa`S!lzgB4HuhzHkzZ/ZSu)qlۅ5)z"}7/NZ?fhB+<q~ѕKގa)9U}߾um|.utbJ7 T~4rUqN{EF`DY)`2!G+#Ѽ83O`W`<Z Rҵooὁ^O}GtXoɻWiԙ,0|3G: ?hU=L2{ 7/߀;e /}|Xҫ~g Zk ƥ\'#L.#΍ǟR^ mϯt*9:L (bB%ӰAzcPr^y=9X^PZU HF*(,~@Hb6jOrvȬ'RLr, ȆchN=vE ng$}%/agdd!XVٺ(W1Ppc|R8vd /UII(Tiªgx0@,ES%\c#U?34zp)rc[tAmMzAH A:wĠa紵#Nr%jMza~"/ ӷK?' T09 Aȶ=J642GJ Ӕ p{,@]c-`1{ @ x,K,u4Y.u@d.|@:R^@T&+Y2 1Fm"cu@3+/=6`hxko,.λ]NSD}jDȚ5 3To @9et FG{J쪡xTf/nǂ>f?/CMR"[H?gu#ݢzɆ_>(Ȉ0#;Vj"]^W q؈o }<-`_J1Sm!k]w _@ކڂR œT˭" *u¼=E R[V()Fu kERAʘWXIi}SY}4TG k 99wghE5zWIl $ݍd? M"sjz~?'Թ~K)e2}pP.H*x8 Ƀb61q@7r9L믎Hw-;[3EO2yU6&zϸq--P2[ oSB*8gIC R\G:( bA4+l诫~T&g^{H,/%uwJԾ&^Y82:i }dOEl`$Ui@%Z%o@0"%{\ѥHY'ӡubǑ"tiMcu-/蘎>3ͱ)P on]!զg~Ct'Dԥ=%AFenR'6Ͽ_ͣuf0Hyn?J׻q 2&F"]VkȈ2ڥ0 =͸b XuT6 ^vv?S/{ŽzbI\rvT7Ɗ(1 "*ňTTƍ2COְe?0"4?h@^ܟ,GKx6 qk'{DW.]i(7&J~l^DqĒ+RËVjT,Ҟ{Ov0h t}soSѳ/t"o{|fEHU 0ix" XM"YyN(/@w7^$ϕz WLg râ!iCHsro\̿("A7F~J:iBn%#ZeADݾ oz @\ O}"WA#_nx~?V0fz:]x) 戌jzaA =* ]UHÊ֞nM ӡlL1{ƪDLp8 R|FF JE$62lkoO4RݶR;i@"Y`JBQ } t> vH9&|I i-GDVc`6)-[PH` p@KXڰϠhp n{v,WZ<<0FVԪf8\o_5ft3Ǩ$q}:$%CF䨵LW'*nsx;SJRbrJ!u N\9)2CE\ˎ*ёyZEIS0O5fq!jm@,6 vN7QRH'Ы  BOQr$da<`)=rDtVC26~DD#zœG;S!J' =J\q$ˆ|^,Uf 8w쌖 hAMt/@jX1f+%ŢO~wcX(rd n\/ʅȭ# 25i>6ˀOLAB$O\D%M+x:tAFJb|4 "0-/`|Qt8/tz =RҢ:4͢'oJz2F޻]x8?IE%@T!ǣ؅ LL[Nr4NsLPěYbGېп-]7ژ c1pAr@ Q`:_|ZRvMUjeH| rASD_K$V\Y:)ƪ-xIuq6&PqH5Ftp9x<ݡ#tS&cۈy _ѠKW8c[baMrO~ޞ'+bkڹQTE l km9HL]^3ѵ0aYqJ HWOU$H