libnetapi0-3.2.7-11.3.2<>,ᶉJD5츋/=„۔[\həBHhwcUu9,}t bA 1f:nl8[٥V#s4^- i+Y[9c4az5 :i]_Awe:?TWD11}2^4p㙜@Fo"i$5*ޫ\}M(yh bНdT[-ǡ>p>fmB_Zki6dZ*1A׏KAZ- (kwuO@>: ?d   / .DJO^pt v x |  )))(89 0:>y@FGHIXY\]^bchdefklzClibnetapi03.2.711.3.2Samba netapi LibraryThis package includes the netapi library. Authors: -------- The Samba Team Source Timestamp: 2154 Branch : 3.2.7JB5wagner> openSUSE 11.1openSUSEGPL v3 or laterhttp://bugs.opensuse.orgProductivity/Networking/Sambahttp://www.samba.org/linuxi586/sbin/ldconfig/sbin/ldconfig> JB532e5f4c46a94d16737ce9d835d876b0rootrootsamba-3.2.7-11.3.2.src.rpmlibnetapi.so.0libnetapi0@@@JJ@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@J/sbin/ldconfig/bin/sh/bin/shrpmlib(PayloadFilesHavePrefix)rpmlib(CompressedFileNames)libc.so.6libc.so.6(GLIBC_2.0)libc.so.6(GLIBC_2.1)libc.so.6(GLIBC_2.1.3)libc.so.6(GLIBC_2.2)libc.so.6(GLIBC_2.2.3)libc.so.6(GLIBC_2.2.4)libc.so.6(GLIBC_2.3)libc.so.6(GLIBC_2.3.4)libc.so.6(GLIBC_2.4)libc.so.6(GLIBC_2.5)libc.so.6(GLIBC_2.8)libcom_err.so.2libcrypt.so.1libdl.so.2libdl.so.2(GLIBC_2.0)libdl.so.2(GLIBC_2.1)libgssapi_krb5.so.2libgssapi_krb5.so.2(gssapi_krb5_2_MIT)libk5crypto.so.3libk5crypto.so.3(k5crypto_3_MIT)libkeyutils.so.1libkrb5.so.3libkrb5.so.3(krb5_3_MIT)liblber-2.4.so.2libldap-2.4.so.2libnscd.so.1libnscd.so.1(LIBNSCD_1.0)libnsl.so.1libnsl.so.1(GLIBC_2.0)libresolv.so.2libresolv.so.2(GLIBC_2.2)libtalloc.so.1libtdb.so.1libwbclient.so.0rpmlib(PayloadIsLzma)4.0-13.0.4-14.4.2-14.4.2.3J@J:,@J8J'@J'@J'@J+@I2IIl@II1I@IHIy@Iy@Id@Ia@IVISuISuIBR@IBR@IAI?@I6tI6tI3I3I1.I.I.I.I.I-:@I+I%Q@I%Q@IsI@IP@IH@H,H,H@H @H @H @H @H @HH@H}@H׈HHHBHe@H|@HAHH@H@H@H@HHc@H@HnH@Hz@H4@HsVHnHkmHkmHj@Hj@Hj@Hj@Hj@HhHhHcHb3@HXHO@HNlHNlHM@HI&HG@H?@H?@H=I@H=I@H;H6H6H6H2@H.H-w@H-w@H-w@H-w@H,%H*@H*@H)H$. + Fix Coverity IDs 456, 574, 592, 606 and 607. + Fix net rpc vampire. + Use the same prerequisite for DDNS update as Windows XP. + Make "lwinet ads dns register" honor the "interfaces" parameter. + Fix extended DN parse error when AD object does not have a SID. + BUG 5888: Fix PNP_GetHwProfInfo(). + BUG 5957: Do not abort rename process on valid rename script. + BUG 5898: Fix 'net rpc shutdown'. + Fix duplicate installation of cifs.upcall. + Fix _srvsvc_NetShareAdd segfault. + Ensure consistency when reporting password complexity. + Fix _lsa_GetUserName. + Fix access check in _samr_QuerySecurity(). + _samr_DeleteUser needs to wipe out the user_handle on success. + NetGroupEnum_r needs to handle servers with no groups. + Search for gpfs functions in both libgpfs_gpl.so an libgpfs.so. + BUG 5908: Fix internal change notify on shared directory. + BUG 5135 and 5446: Prevent calling POSIX ACL vfs methods on zfs share. + BUG 5929: Fix building of vfs_prealloc with option --with-cluster-support and GPFS. + Add new VFS module to analyze SMB traffic + BUG 5928: Fix 'testparm --version'. + Have uppercase_string return success on NULL pointer in mount.cifs. + Make mount.cifs return codes match the return codes for /bin/mount. + Use lock/unlock_mtab scheme from util-linux-ng mount prog in mount.cifs. + BUG 5778: Check if strlcpy and strlcat are already defined. + BUG 5840: Fix segfault in "rpcclient lsaaddacctrights". + BUG 5860: Fix nasty error message for overlong strings in safe_strcpy. + Fix a potential NULL deref in found by the IBM Checker. + Fix an uninitialized variable found by the IBM Checker. + Fix an unlikely memleak found by the IBM Checker. + Fix some missing error handlings. + Add workaround for domain joins using a netbios name which is different from the hostname. + Fix crash bug when freeing a non-malloc'ed buffer if the client sends a non-encrypted packet with the crypto state set. + Fix trans2findfirst for the large directory optimization. + Fix checking for presence of cups-devel and correct cups-devel test for HAVE_IPRINT. + BUG 5805: Don't close stdout when calling setup_logging multiple times. + Fix setting of trust password using 'net rpc trustdom add'. + Fix several issues in vfs_streams_xattr and vfs_stream_depot. + Return an error instead of crashing when no realm is given (trigerred by "net ads info -S 127.8.7.6" (where 127.8.7.6 doesn't exist) and "disable netbios = yes"). + Fix the new vfs_smb_traffic_analyzer build for static links. + BUG 5901: Fix default for streams_depot location. + Fix several build warnings. + Delete the krb5 ccname variable from the PAM environment if set. + Fix circular dependency error with autoconf 2.6.3. + Add @CIFSUPCALL_PROGS@ to "all" target so cifs.upcall gets built at compile time rather than install time. + BUG 5906: Fix Winbind crash when calling 'getent group'. + Fix logging to syslog. + Allow SYSLOG_FACILITY to be modified with a new configure option called - -with-syslog-facility. + BUG 5909: Fix MS-DFS on Vista clients. + BUG 5944: Fix starting of nmbd with "socket address" set to "". + Fix segfault on startup with trusted domains. + Re-add "winbind:ignore domains" parameter. + Avoid freeing fsp twice when opening new_file fails (Debian #431696).- Fix the conditional macro to start smbfs by default; (bnc#456469).- Readd libsmbclient to baselibs.conf for pre 11.0 distributions.- Use %__install macro to install files with the right permissions instead of cp.- Remove patch for bnc#336854, which doesn't exist in 3.2.x or higher.- Use %{NET_CFGDIR} define instead of a fixed path to the network conf.- Update to 3.2.5. + Samba 3.0.29 to 3.2.4 can potentially leak arbitrary memory contents to malicious clients; CVE-2008-4314; (bnc#446971).- Update baselibs.conf.- Fix circular dependency error with autoconf 2.6.3.- Fix the dhcp hook script and support CODE11; (bnc#442335).- Fix perl v5.10 warnings in nmbstatus; (bnc#448225).- Include the missing spec file change mentioned the previous commit.- Make cifs-mount depend on keyutils, keyutils-libs packages as they are required to support dfs and kerberos; (bnc#432494).- Fix the offset checks in the trans routines; CVE-2008-4314; (bnc#446971).- Change the runlevel description for winbindd to use "Microsoft Windows" instead of "NT"; (bnc#446154).- Directory/Filenames get truncated when 3.2.0 client acesses old server; (bnc#432471).- Add SuSEfirewall2 services config file to open Netbios and Samba ports on post-10.2 systems; (bnc#247344).- Remove unrecognized configure options.- Fix the pam_winbind build.- Delete the krb5 ccname variable from the PAM environment if set.- Move the nss_info modules to the samba-winbind package.- Add version branding for CODE 11.- Restart smbfs even with the traditional network setup; (bnc#425058).- Only call the stop_on_removal, restart_on_update, or insserv_cleanup macro if available.- Only call the fillup_and_insserv or fillup_only macro if available.- Use package names instead of macros for cp, mkdir, mv, rm, and grep or instead of the full path to the binary for ln, find and xargs.- Introduce NET_CFGDIR to fit the needs for a differing location of the network configuration per vendor.- Use path macros for cp, mkdir, mv, rm, and grep.- Only use SUSE rpm macros and SuSEconfig.permissions if available.- Adopt samba-vscan to build after the change to the bool type define.- Fix winbindd crash in an unusual failure mode; (bnc#416598).- Build cifs.upcall for CentOS 5, Fedora 8 and RHEL 5 and newer too.- Call mkinitrd_setup during %post and %postun for post-9.2 systems only.- Update to 3.2.4. + BUG 5590: Fix binary stripping on older OS. + Fix linking of cifs.upcall when nscd_flush_cache() is found. + BUG 5052: Allow inheritable permissions. + BUG 5697: Fix spinning of nmbd in reload_interfaces when only loopback has an IPv4 address. + BUG 5698: Fix non guest connections to shares when "security = share" is used. + BUG 5729: Explicitly allow "-valid". + BUG 5745: Fix Kerberos authentication with (lib)smbclient. + BUG 5751: Fix showing of ACLs on DFS in (lib)smbclient. + BUG 5761: Fix opening of mangled directory name (resulted 'is a stream name'). + Fix the wcache_invalidate_samlogon calls. + Clarify usage of "force create mode". + Write times code update. + Fix Winbind crash. + idmap_ad: Fix a segfault when calling nss_get_info() with a NULL ads structure. + Fix build warnings. + Cleanup of DC enumeration in get_dcs(). + BUG 5710: Fix changing of machine account passwords. + Fix several build warnings. + Fix invalid sid copy (hit when enumerating sibling domains) in Winbind. + BUG 5736: Fix Winbind crash bug with trusted domains. + Correct the netsamlogon_clear_cached_user function. + Fix handling of MSKRB5 OID in cifs.upcall. + Fix build warnings in cifs.upcall. + Change default install location of cifs.upcall to EPREFIX/sbin. + Enable building of cifs.upcall by default on Linux. + BUG 5707: Do proper error handling if the socket is closed. + Fix calculation of useable_space for trans2 and nttrans replies. + Fix Coverity ID 587. + Add mapping of generic bits when setting an NFSv4 ACL. + Some write time fixes. + BUG 4516: No IPv6 on Solaris 2.6. + BUG 5571: Fix group memeberships in Winbind. + Fix cut and paste error in quota code. + Fix display of POSIX ACLs. + Avoid a race condition in glibc between AIO and setresuid(). + Add missing become root for AIO operations. + Fix logic of tsmsm_sendfile(). + Fix an errno handling bug that could lead to an infinite loop. + Fix handling of arbitrary new PAC types.- Create a link to the html manpages so that they can be accesses in swat; (bnc#426182).- "Password last set" timestamp update from admin pw change; (bnc#420407).- Call mkinitrd_setup during %post and %postun for package cifs-mount; (bnc#413709).- Update to 3.2.3. + Force the permissions on group_mapping.ldb to 0600; CVE-2008-3789; (bnc#420634).- Update to 3.2.2. + BUG 5592: Fix creation and installation of shared libraries. + Fix replacement of random seed generator. + Fix a race condition in idmap_tdb2_allocate_id(). + Fix unix_convert() for "*" after changing map_nt_error_from_unix(). + Make sure to always set errno on error path in OpenDir. + BUG 5675: Fix smbspool program assuming Kerberos authentication by mistake. + BUG 5686: Fix segfaults in libsmbclient. + BUG 5692: Fix coredump in full_audit.so. + BUG 5696: Fix "force group" in setups using Winbind. + Rename cifs.spnego to cifs.upcall. + Fix segfault in cifs.upcall when it is called without any arguments. + Fix coverity ID 594 (resource leak on error path). + Fix assigning of primary group memberships when authenticating via Winbind. + BUG #5617: Fix freezing Windows Explorer on WinXP while browsing Samba shares. + Include stdlib.h to get a prototype for free(). + Solve an IBM XL C/C++ compiler error encountered in get_exit_code() auth_errors array initialization in client/smbspool.c. + Use NGROUPS_MAX instead of 32 for the max group value in rep_initgroups(). + Add add c++ guard to netapi. + Fix compile warning in cifs.upcall. + Add "dns_resolver" key type to cifs.upcall. + BUG 5688: Fix orphaned LPQ processes if socket address is invalid. + BUG 5684: Fix removal of dead records in tdb files. + Fix coverity IDs 595, 596. + Fix smb_len calculation for chained requests. + Fix output of test status. + Fix smbclient connections to older servers. + Fix a fd leak when trying to regain contact to a domain controller in Winbind. + Fix permissions on ctdb databases. + Fix passing back success when a function had in fact failed in two places. - Add --enable-static to the configure options to get the statical libraries installed by the install Makefile target. - Add --with-cifsupcall to build the cifs.upcall binary for post 10.2 systems.- Set Required- and Should-Stop in the init info part of all init scripts.- Fix libsmbclient to older servers; (bnc#402776).- Update to 3.2.1. + BUG 5594: Fix "make test" by adding and using a new testparm switch "--skip-logic-checks". + Fix creation of libaddns.a, libsmbclient.a and libsharemodes.a. + Update the section about net conf in the net(8) manpage. + Improve processing of registry shares. + Fix listing of registry shares with testparm. + Fix several build issues. + BUG 5578: Fix error from strlcat. + BUG 5613: Fix flushing of smb.conf when creating a new share using SWAT. + Ensure consistent use of pdb_get_nt_passwd instead of pdb_get_lanman_passwd. + Remove worrying warning message when safe_strcpy tries to copy a pseaudo interface name that's too long. + Canonicalize servername in the printer functions to remove leading '\\' characters. + Fix option processing in smbcacls - add POPT_COMMON_CONNECTION. + Fix bug creating files using DOS clients with mixed case files. + Fix uninitialized variable. + BUG 5616: Fix session keys also in rpccli_netr_LogonSamLogonEx wrapper. + BUG 5570: Fix bogus error message during AD domain join. + Fix trusted domain handling in Winbindd. + Fix build warning. + BUG 5202: Fix setting of ACEs for users/groups with write access in setups with 'dos filemode = yes'. + Re-activate 'acl group control' parameter and make it only apply to owning group. + Make ntimes function more like POSIX and allow NULL arg. + BUG 5512: Fix alignment problems on sparc. + BUG 5616: Fix share connections in setups with "server signing = mandatory" or SMB signing set on the client side. + Fix a race condition in Winbind leading to a crash. + Fix a segfault in base64_encode_data_blob. + Fix some uninitialized variable references via ndr_print. + Fix error message if trying to join with a non-privileged user. + Fix setups using "include = registry" without [global] settings in the registry. + Fix "net sam rights" on domain member servers. + Add documentation for the vfs streams modules. + Cleanup some duplicate code by passing the password to the wbinfo_auth* functions. + Allow SID with 0 in subauthority to be converted properly. + Set sin[6]_family instead of ss_family in in[6]_addr_to_sockaddr_storage. + Fix realpath() check so that it doesn't generate a core() when it fails. + Fix overwriting of winbind logfiles. + Fix "vfs_full_audit.c: name table not in sync with vfs.h" panic. + Add broadcasting of the debug message to all winbindd children. + BUG 5635: Fix updating of printer queues. + Release still reachable memory if the smbclient context is freed. + Remove trailing withespace from wbinfo -m which breaks gdm auth. + BUG 5540: Fix "set primary group script" user option substitution. + Fix regression in Winbindd offline mode. + Allow authentication and memory credential refresh after password change from gdm/xdm. + Allow %u parameters for print job username.- Fix a race condition in winbind leading to a crash; (bnc#406623).- Use the configure option to enable debugging. This fixes the creation of the debuginfo and debugsource package.- Fix emptying the printing queue; (bnc#411493).- Remove trailing withespace from wbinfo -m which breaks gdm auth.- Add a recommendation to the samba and samba-winbind package to install logrotate for openSUSE 11.0 and later.- Include mkinitrd scriptlets.- Allow %u parameters for print job username - use advanced sub; (bnc#374389).- Update to 3.0.31. + BUG 5504: Fix SIGTERM handling in Winbind children so that they do not remove the unix domain socket used to field client requests. + Split the winbindd_passdb backend into a 'builtin' and a 'sam' backend. + When allocating client buffers for large read/write - make sure we take account of the large read/write SMB headers as well as the buffer space. + Memory leak fixes in DC location code. + BUG 5533: Winbindd fails to cope correctly with a workgroup name containing a '.' + BUG 5555: Don't return NT_STATUS_PASSWORD_MUST_CHANGE error on machine account logon. + BUG 5551: smbd recursing back into winbindd from a winbindd call. + Fix usage message for "net rpc trustdom add". + Ensure consistent use of pdb_get_nt_passwd instead of pdb_get_lanman_passwd. + BUG 5578: Bad (non-Samba) use of strlcat gives error. + Canonicalize servername in the printer functions to remove leading '\\' characters. + Documentation build fixes. + [DOCS] Fix use of smbconfoption in samba.entities. + Return NULL in sitename_fetch() if gencache_init() fails. + Use machine account and machine password from our domain when contacting trusted domains. + SPNEGO SPN fix when contacting trusted domains. + BUG 5285: Fix libcap header mismatch. + Fix joining NT4 domains. + Don't let winbind getgroups crash when we have no gids in the token. + Fallback to level 24 pwd set while joining. + Fix joining w2k domains in "security = ads". + Fix pam_sm_chauthtok for storing modified cached creds. + BUG 5202: Re-activate "acl group control" parameter and make it only apply to owning group. + BUG 5531: Fix conversion of ns units when converting from nttime to timespec. + BUG 4974: Map NT_STATUS_OBJECT_PATH_NOT_FOUND to ENOENT in libsmbclient. + Fix a segfault in base64_encode_data_blob. + AIX build fixes. + ENODATA is not defined in freeBSD 4.6.2. + Don't reset password last set time just because the expired flag is set to 0. + Fix usage message for 'net idmap dump'. + Miscellaneous man page fixes. + BUG 4203: Samba3-HOWTO: Add improvements/fixes submitted by Pete Boyd. + Fixes to man pages. + Add tdb file documentation. + Ensure that winbindd trusted domain children keep primary domain online status up to date. + Update cached creds during password change. + Ensure that Winbind always uses set_domain_offline() to mark a domain offline. + Allow authentication and memory credential refresh after password change from gdm/xdm. + Memory leak fixes.- Allow authentication and memory credential refresh after password change from gdm/xdm; [bnc#395578].- Add SMB_VFS_OP_RECVFILE to vfs_op_names to get it in sync with vfs.h.- Call the libsmbclient testsuite from the %check instead of the %build script.- Use machine account and machine password from our domain when contacting trusted domains; [bnc#404667].- Add a %check section move the test of the PAM modules to this section and add more tests.- Add a recommendation to the samba and samba-winbind package to install cron for openSUSE 11.0 and later.- Use a variable for syslog and add missing $remote_fs dependency for Require-Start in the init information of the init scripts.- Update to 3.2.0. + Support for establishing interdomain trust relationships with Windows 2008. + All changes from the pre and rc releases as noted in here earlier.- Move header files from the devel sub package to lib*-devel.- Work around bad use of autoconf interna.- Build Samba with debug symbols to get working debuginfo packages.- Add /etc/openldap to the file list and not only the schema directory.- Improve samba-winbindd and dhcpcd-hook-samba interface scripts for faster booting; [fate#304967], [fate#304965].- Move sysconfig variable DHCLIENT_MODIFY_SMB_CONF from Other to 'Network/DHCP/DHCP client'; [bnc#400467].- pam_winbind: Update cached creds during password change; [bnc#395578].- Update to 3.2.0rc2. + BUG 5504: Fix behaviour of winbindd children receiving a SIGTERM. + BUG 5489: Split the winbindd_passdb backend into a 'builtin' and a 'sam'. + Make sure we take account of the large read/write SMB headers as well as the buffer space when allocating cli buffers for large read/write. + Fix tag as a goto target we were not reinitializing the array counts. + BUG 5451: Fix for using the correct machine domain when looking up trust credentials in our tdb. + Fix spnego SPN when contacting trusted domains. + BUG 5285: Fix libcap header mismatch. + Fix pam_sm_chauthtok for storing modified cached creds. + Fix joining issue in setups with "config backend = registry". + BUG 4544: Add new parameter 'ldap connection timeout' to prevent waiting for TCP connection timeouts if no LDAP server is available. + BUG 5502: Fix security=server. + Fix coverity IDs 552, 553, 570, 571, 572. + Shrink ldbtools. + Fix reset of password last set time just because the expired flag is set to 0. + Remove support for symbol versioning in shared libraries. + Fix autogen for autoconf 2.62. + BUG 5515: Fix empty input fields in SWAT. + BUG 5516: Fix saving of the config file in SWAT. + Fix winbindd trusted domain child not keeping primary domain online status up to date.- pam_winbind: fix pam_sm_chauthtok for storing modified cached creds; [bnc#395578].- Don't reset "password last set time" when unlocking an autolocked account; [bnc#382111].- Fix winbind sigterm handling and make init script send sighup to all child winbind processes; [bnc#382027].- Fix bug with winbindd trusted domain child not keeping primary domain online status up to date, merge to trunk from reversion 1801; [bnc#373560].- Make winbind children reopen logs on SIGHUP; [bnc#382027].- Set only CONFIGDIR and LIBDIR while make everything and install. No longer set CONFIGFILE, DRIVERFILE, LMHOSTSFILE, and SMB_PASSWD_FILE; [bnc#395877].- Update to 3.0.30. + Fix for CVE-2008-1105. + Remove man pages for ldb tools not included in Samba 3.0.- Fix vulnerability that allows for the execution of arbitrary code in smbd; CVE-2008-1105; SA30228; [#391168].- Follow the rename of libtdb0 in baselibs.conf.- Rename sub package libtdb0 to libtdb1.- Update to 3.2.0rc1. + Move the posix pending close functionality down into the VFS layer. + Fix activation of registry globals in loadparm. + BUG 5452: Fix smbclient put. + BUG 5434: Ensure the loaded password doesn't contain the '\n' at the end. + BUG 5456: Fix missing echo if we ^C at the prompt. + BUG 5464: Fix timeout in winbindd. + Fix returning a directory value for a QPATHINFO on a msdfs link with a non-dfs path. + Use more error-prone form of testing dm_destroy_session() return code. + BUG 5453: Fix winbindd and smbd crash when dsgetdcname is used. + BUG 5465: Fix joining with createcomputer=ou1/ou2/ou3. + BUG 5461: Fix issue with Citrix on Samba DCs with more than 900 groups. + Fix wins null pointer crash in nss_wins module. + Fix lm session key length in _netr_LogonSamLogon. + Add -f switch for DsGetDCName() example and be more verbose on output. + BUG 5429: Clarify log msgs re: failure to create BUILTIN\{Administrators,Users} + Fix the DNS Update option of "net ads join". + BUG 5184: Add Missing HAVE_UPDWTMPX check before using updwtmpx(). + Recognize and allow longer UA keys in winbindd_cache. + BUG 5436: Fix signing problem in the client with transs requests. + Fix a valgrind bug in the new [ug]id2sid cache. + Fix Coverity IDs 565 and 222. + Fix dfs_Enum: In form_junctions, correctly check for malloc failure. + Add support for symbol versioning in shared libraries (can be disabled with - -disable-sysmbol-versioning). + Add new function wbcLibraryDetails() to libwbclient. + Cleanup size_t return values in convert_string_allocate. + Fix Kerberos support for CUPS 1.3 in smbspool. + Fix printing with Vista. + Fix deletion of files when they're in use by other drivers.- Update to 3.0.29. + Fix a crash in tdb_wrap_log(). + BUG 5267: Fix for nmbd termination problems when no interfaces found. + BUG 5326: OS/2 servers give strange "high word" replies for print jobs. + Remove MS-DFS check that required the target host be ourself. + BUG 5372: Fix high CPU usage of cupsd on large print servers by using more efficient CUPS queries in smbd. + BUG 5095: Fix the enforcement of the "Manage Documents" access right. + BUG 5460: Fix MS-DFS referral problem in server code. + Fix bug in Winbind that caused the parent to ignore dead children. + BUG 4235: Improve compliance to the Squid helper protocol. Original patch from Pawel Worach . + Prevent cycle in Wibind's list of children when reaping dead processes. + BUG 5419: Fix memory leak in ads_do_search_all_args() (merge from v3-2). + Fix winbind NETLOGON credential chain on a samba dc for w2k8 trusts. + Fix client connections and negotiation with Windows 2008 DCs in member server code. + Add NT_STATUS_DOWNGRADE_DETECTED error code (merge from v3-2). + BUG 5430: Fix pam_winbind.so on Solaris (requires -lsocket). + Re-add samr getdispinfoindex parsing which got lost in the glue commit. + BUG 5461: Implement a very basic _samr_GetDisplayEnumerationIndex(). Corrects interop problem between Citrix PM and a Samba DC. + BUG 3840: Fix smbclient connecting to NetApp filers when using whitespace in the user's password. + BUG 4901: Fix behavior of "ldap passwd sync = only". + BUG 5317: Fix debug output from domain_client_validate(). + BUG 5338: Fix format string bug in rpcclient. + Ensure that "wbinfo -a trusted\\user%password" works correctly on a Samba DC with trusts. + BUG 5336: Fix SetUsetrInfo(level 25) to update the pwdLastSet attribute. + BUG 5350: Fallback to anonymous sessions if not trust password could be obtained on Samba DCs and member servers. + Fix signing problem in the client with trans requests. + Enable winbind child processes to do something with signals, in particular closing and reopening logs on SIGHUP. + Add implementation of machine-authenticated connection to netlogon pipe used when connecting to win2k and newer domain controllers. + Fix trusted users on a DC that uses the old idmap syntax. + Only have Winbind cache domain password policies that were successfully retrieved. + Fix alignment bug when marshalling printer data replies. + Fix DeleteDriverDriverEx() checks to prevent removing in use files.- Prevent errors during the cache validation when ua keys reach a size larger than 1024; [bnc#372558].- Expand baselibs.conf to match pre SUSE 11.0 products.- Remove obsoletes and provides 3 for all packages and systems.- Cleanup the use of the suse_version macro to achieve consistent defaults.- Set CODEPAGEDIR while make to fit the install location.- Prevent errors during the cache validation when ua keys reach a size larger than 1024; [bnc#372558].- Package man page files independent of the used compression method (gz,lzma).- Rewrite spec file to build packages for Fedora, Redhat, CentOS, and Mandriva in the OBS too.- Add a script to restart smbfs if NetworkMangaer gets an IP address; [bnc#373075].- Remove all references to the obsoleted samba-pdb package.- Compose the BuildRequires in a more flexible way to fit the openSUSE build service (OBS) requirements to support different operating system targets.- Use _libdir macro instead of a local define of LIBDIR.- Remove PreReq /sbin/ldconfig from the libtdb-devel package.- Install the shared libraries with the same name as used as soname.- Update to 3.2.0pre3. + Use of IDL generated parsing layer for several DCE/RPC interfaces. + Removal of the 1024 byte limit on pathnames and 256 byte limit on filename components to honor the MAX_PATH setting from the host OS. + Introduction of a registry based configuration system. + Improved CIFS Unix Extensions support. + Experimental support for file serving clusters. + Support for IPv6 in the server, and client tools and libraries. + Support for storing alternate data streams in xattrs. + Encrypted SMB transport in client tools and libraries, and server. + Support for Vista clients authenticating via Kerberos. + Full support for Windows 2003 cross-forest, transitive trusts and one-way domain trusts. + Support for userPrincipalName logons via pam_winbind and NSS lookups. + Expansion of nested domain groups via NSS calls. + Support for Active Directory LDAP Signing policy. + New LGPL Winbind client library (libwbclient.so). + New NetApi library for domain join related queries (libnetapi.so) and example GTK+ Domain join gui. + New client and server support for remotely joining and unjoining Domains. + Support for joining into Windows 2008 domains. + New ldb backend for local group mapping tables + Raised level of security defaults for authentication operations. + Inclusion of an HTML version of the 3rd edition of "Using Samba" from O'Reilly Publishing.- Add libtalloc1, libtdb0, and libwbclient0 to baselibs.conf.- Remove obsoletes and provides samba3 for post 10.3 systems.- Let libsmbsharemodes-devel require libsmbsharemodes0 for post 10.3 systems.- Rename the libsmbsharemodes package to libsmbsharemodes0 to follow the shared library packaging policy for post 10.3 systems.- Update kdc dns-only lookup patch to IPv6.- Move mount.cifs and umount.cifs from /sbin/ to /usr/sbin/ and create sym links in /sbin/; [bnc#380693].- Enable the build of vfs_cacheprime and vfs_readahead modules.- Update to 3.2.0pre2. + Add library for access to the registry configuration data. + BUG 5023: Separate NFS4 and POSIX ACL code in file access checks. + BUG 4308: Fix Excel save operation ACL bug. + BUG 4801: Correctly implement LSA lookup levels for LookupNames. + Add new option "debug class" to control printing of the debug class. + Enable building of the zfsacl and notify_fam vfs modules. + BUG 5083: Fix memleak in solarisacl module. + BUG 5063: Fix build on RHEL5. + New smb.conf parameter "config backend = registry" to enable registry only configuration. + Added support for IPv6 client and server connections. + Remove unused utilities: smbctool and rpctorture. + Fix service principal detection to match Windows Vista (based on work from Andreas Schneider). + Encrypted SMB transport in client tools and libraries, and server. + Added support for an SMB_CONF_PATH environment variable containing the path to smb.conf. + Various fixes to ntlm_auth. + Correctly handle mixed-case hostnames in NTLMv2 authentication. + Add Winbind client library. + Enhance client and server remote registry access. + Add client calls for remotely joining a computer to a domain (including calls from "net dom" command). + Add libnetapi.so library for joining domains including sample GTK+ app. + Fixes for Vista SP1 Kerberos authdata handling to only pickup the PAC. + Various fixes for DsGetDcName and conversion to IDL based structures. + Add ads_get_joinable_ous() to libads to get list of joinable ous. + Add get_logon_hours_from_pdb() to comply with new IDL based structures. + Migration of the entire client and server DCE/RPC code to IDL based structures and autogenerated code for DSSETUP, LSA, SAMR and NETLOGON. + Started migration of client and server DCE/RPC code to IDL based structures and autogenerated code for NTSSVC, SVCCTL and EVENTLOG. + Use IDL and autogenerated code for samlogoncache and Kerberos PAC handling. + Add remote join/unjoin server-side implementation. + Import the Linux red-black tree implementation. + Support for storing xattrs in tdb files. + Support for storing alternate data streams in xattrs. + Implement a generic in-memory cache based on rb-trees. + Speed up the smbclient "get" command. + Add the aio_fork module. + Modified libsmbclient API for more easily maintaining ABI compatibility while adding new features to libsmbclient. + Refactor Winbind internal parent-child interface tables to achieve better unit testing support. + Networking fixes to the libreplace library. + Add support for DNS Service Discovery. Based on work from Rishi Srivatsavai . + Don't restart winbind if a corrupted tdb is found during initialization. + Add share parameter "administrative share". + Improve error messages of net subcommands. + Add 'net rap file user'. + Change LDAP search filter to find machine accounts which are not located in the user suffix. + Remove smbmount. + BUG 5073: Allow "delete readonly = yes" to correctly override deletion of a file. + Register the smb service with mDNS if mDNS is supported. + Add smbclient support for basic mDNS browsing. + Fix padding between Winbind 32bit/64bit client library in the request/ response structures. + Added a syncops VFS module for file systems which do not guarantee meta-data operations are immediately committed to disk in stable form. + Additional portability support for building shared libraries. + Get Samba version or capability information from Windows user space. - Add new sub packages libnetapi0, libnetapi-devel, libtalloc1, libtalloc-devel, libtdb0, libtdb-devel, libwbclient0, libwbclient-devel.- Fix build with glibc 2.8.- Added baselibs.conf file to build xxbit packages for multilib support for post 10.3 systems.- Only cache password policy results that worked, otherwise we cannot login until the cache expires even if a connection to a DC has been restored; [bnc#373552].- Remove dir /usr/share/omc/svcinfo.d as it is provided now by filesystem.- Prevent tdb lock call getting interrupted by sig alarm; [bnc#364200].- Update to 3.0.28a. + Failure to join Windows 2008 domains. + Windows Vista (including SP1 RC) interop issues.- Rename the libsmbclient package to libsmbclient0 to follow the shared library packaging policy and remove provides libsmbclient3 for post 10.3 systems.- Add variable to define if a share should be an administrative share; [bnc#358841].- Fix patch errors with dcerpc and idmap_global; [bnc#280452].- Fix safe_strcpy error caused by duplicate domain name fix; [bnc#356025].- Fix two memleaks if num_validated_vuids exceeds its maximum; [bnc#349581].- Fix ACL inheritance; [bnc#351570].- Fix a gcc 4.3 buffer overflow warning.- Remove duplicate domain name prepend when user SID is in winbindd cache; [#336854].- Prevent winbindd from segfaulting due to corrupted cache tdb on flushing caches; [#340332].- Fix kerberos authentication with Vista; [#350032].- Update to 3.0.28. + Fix send_mailslot overflow: CVE-2007-6015; [#343702].- Additional cases and problems caused by fix for CVE-2007-4572; [#337823].- Fix send_mailslot overflow: CVE-2007-6015; [#343702].- Added default printing system information to README.vendor; [#113759].- Add missing define of AI_ADDRCONFIG for systems with older glibc versions.- Update to 3.0.27. + Stack buffer overflow in nmbd's logon request processing; CVE-2007-4572; [#326261]. + Remote code execution in Samba's WINS server daemon (nmbd) whe processing name registration followed name query requests; CVE-2007-5398; [#337823].- Change the spec file to get debug packages again.- Additional case for overflow: CVE-2007-4572; [#326261].- Fix process_logon_packet overflow; CVE-2007-4572; [#326261].- Fix reply_netbios_packet vulnerability; CVE-2007-5398; [#337823].- Fix missing getpwent mutex unlock; [#329796], [#331754], [#336854].- Fix the alignment of 32 and 64-bit winbind requests; [#331754].- Add dmapi-devel and xfsprogs-devel to the BuildRequires for post 10.0 systems; [#289599], fate [#302668].- Fix possible segfault in winbind which could be caused by uninitialized variables; [#253862c223].- Use FQDN in KDC DNS lookup; [#295284].- Update to 3.2.0pre1. + Use of IDL generated parsing layer for several DCE/RPC interfaces. + Removal of the 1024 byte limit on pathnames and 256 byte limit on filename components to honor the MAX_PATH setting from the host OS. + Introduction of a registry based configuration system. + Improved CIFS Unix Extensions support. + Experimental support for file serving clusters. + Full support for Windows 2003 cross-forest, transitive trusts and one-way domain trusts + Support for userPrincipalName logons via pam_winbind and NSS lookups. + Support in pam_winbind for logging on using the userPrincipalName. + Expansion of nested domain groups via NSS calls. + Support for Active Directory LDAP Signing policy. + New ldb backend for local group mapping tables + Raised level of security defaults for authentication operations. + Inclusion of an HTLM version of the 3rd edition of "Using Samba" from O'Reilly Publishing. - Update samba-vscan to 0.3.6c-beta5. - Disable dcerpc-funnel and idmap_ad-Global_Catalog as both currently don't apply to Samba 3.2.- Make nss_winbind thread-safe; [#293907, #329796].- Perform KDC lookup using DNS only; [#295284].- Handle smb child crash; [#294895].- Add a global lock inside nss_winbind as workaround; [#293907].- Merge ranged retrieval optimization to winbindd.- Update to 3.0.26a. + Memory leaks in Winbind's IDMap manager. - Update to 3.0.26. + Incorrect primary group assignment for domain users using the rfc2307 or sfu winbind nss info plugin; CVE-2007-4138; [#307623].- Fix two memleaks in idmap_cache.c; bso [#4917]. - Correct failure of libsmbclient against a version of Windows. - Make read_sock return the total number of bytes read instead. - Fix error in enum_dom_groups. - Fix logic error in timeout of blocking lock processing. - Add parameter "directory name cache size". - Fix use of pwrite in tdb code.- Also ensure to initialize ip_srv_site and count_site even if we are not on site; [#230963#c124]. - Use an off site DC if we're not online and talking to the KDC of our domain; [#230963#c106].- Fix a bug where samba writes the wrong default value of max_passwd_expire to an LDAP server; [#298469].- Fix if statements where we still expected cli_connect() to return BOOL.- Update to 3.0.25c. + File sharing with Widows 9x clients. + Winbind running out of file descriptors due to stalled child processes. + MS-DFS inter-operability issues.- Update the cache tdb validation patch which improves the backup handling trying to end up with a useable cache tdb. This applies mostly to the situation that disk space is short; [#256166c82].- Update the cache tdb validation patch to support backup and corrupted file handling; [#256166c77].- Fix a bug that causes smbd to 'hang' intermittently; [#289599].- Fix event based krb5 ticket refreshing in winbindd.- Limit the LDAP expression in lookup_usergroups_member() to security groups; [253862c209].- Don't reset the num_names counter in lookup_groupmem(); [253862c198].- Make the days before the password expiry warning appears configurable in pam_winbind.conf; [#287871].- Don't link shared libraries of vscan with -pie.- Increase LOOKUP_SIDS_HUNK_SIZE for rpccli_lsa_lookup_sids_all() from 1000 to 20480; [#253862c175].- Update to 3.0.25b. + Offline caching of files with Windows XP/Vista clients. + Improper cleanup of expired or invalid byte range locks on files. + Crashes is idmap_ldap and idmap_rid.- Fix reply when no dfs share is configured. - Fix the DFS code to work with Vista clients; [#286937].- Migrate old if-up/down scripts to new names on update; [#283706, #285187].- Introduced prefix numbering of if-up/down scripts that they get executed in the right order; [#283706, #285187].- Restart nscd on winbind update to load the new libnss_winbind.so.2 library. This will not resolve every problem with nss modules; [#174589c88].- Fix winbind segfaults with idmap_rid; bso [#4624].- Add missed 'c' character to the list of valid ones in escape_shell_string(); [#273611].- Let lookup_groupmem() only resolve not yet cached SIDs; [#253862c106].- Remove superfluous requires to samba from the devel package.- Ensure the returned structure size from _samr_query_dispinfo() is smaller than the total size; [#203833].- Remove 'unset CONFIGURE_OPTIONS' in front of the configure call to vscan. - Install header files with 0644 instead of 0755 permissions. - Enable build of the python package.- Branch a samba-devel package for post 10.2 systems. - Install .a library files with 0644 instead of 0755 permissions.- Update to 3.0.25a. + Missing supplementary Unix group membership when using "force·group". + Premature expiration of domain user passwords when using a·Samba domain controller. + Failure to open the Windows object picker against a server configured to use "security = domain". + Authentication failures when using security = server.- Add %dir /usr/share/samba to the client package. - Remove samba-classic{,-client}, samba-ldap{,-client}, sambaxp{,-client}, and smbclnt from Provides and Obsoletes of the main or client package.- Add /sbin/ldconfig to %post and %postun of libsmbsharemode.- Update samba-vscan to 0.3.6c-beta4.- In some cases PRS_ALLOC_MEM was called with zero count; [#273613]; bso [#4637].- Enhance the patch to the ads version of lookup_groupmem(); [#253862c89].- Don't use current_user to prep the security ctx in change_to_user(); [#273613].- Prevent winbindd segfaulting due to corrupted cache tdb; [#256166].- Use WORKGROUP instead of TUX-NET as default workgroup setting in smb.conf.- No longer check in the pre package scripts if swat or winbindd of version 2.2 are updated; [#273160].- Update to 3.0.25. + Significant improvements in the winbind off-line logon support. + Support for secure DDNS updates as part of the 'net ads join'·process. + Rewritten IdMap interface which allows for TTL based caching and·per domain backends. + New plug-in interface for the "winbind nss info" parameter. + New file change notify subsystem which is able to make use of·inotify on Linux. + Support for passing Windows security descriptors to a VFS·plug-in allowing for multiple Unix ACL implements to running side·by side on the Same server. + Improved compatibility with Windows Vista clients including·improved read performance with Linux servers. + Man pages for IdMap and VFS plug-ins. + Security Fixes CVE-2007-2444, CVE-2007-2446, and CVE-2007-2447. - Disable build of the python package.- Fix heap overflows to prevent remote code execution; CVE-2007-2446; [#273613]. - Fix remote command injection vulnerability; CVE-2007-2447; [#273611].- Remove obsolete samba-pdb package and required packages from BuildRequires for post 10.2 systems.- Remove X-UnitedLinux- prefix from init scripts for post 9.0 systems.- Remove requires on release from devel packages.- Reduces the number of queries made to the DC in the ads version of lookup_groupmem(); [#253862].- Allow winbindd to take local shortcut on secondary DCs in case dce funnel directory is set; [#266853].- Really remove Should-Start smb in smbfs init script; [#242918].- Disable 'msdfs root' by default again; [#268004].- Build libsmbsharemodes and create libsmbsharemodes and corresponding devel package; [#264623].- Let idmap_ad search in the Global Catalog in case dce funnel directory is set; [#266049].- Allow share names with a lengths greater than 32 chars; bso [#4512].- Check the euid and call become_root() to get write access to dump a core.- Add pwdutils BuildRequires for post 10.2 systems.- Do not restart winbindd under any if-up circumstances; [#227942].- Replace unneeded become_root_uid_only() by refactored become_root(); CVE-2007-2444; [#262090].- Add repository version and branch to the spec file via build-source-timestamp mechanism.- Allow applications to set the share mode while opening a file using libsmbclient; bso [#3684]; [#203737].- Fix for fd leak on error path in winbindd; bso [#3204], [#258737].- Add gdbm-devel BuildRequires for post 10.2 systems.- Remove setlocale(LC_ALL, "C") calls; bso [#2926], [#247728].- Fix segfault and memleak in wb_lookup_rids(); bso [#4434].- Fixes a known bottleneck under very high load situations; [#247984].- Avoid passdb builtin group membership calls in the DCERPC funnel patch; [#248556].- Allow pre 3.0.23 multi passdb backend configurations to work with post 3.0.22 by using the first backend only; [#245167].- Prevent nscd crash in NSS winbind initgroups(); [#237719]. - Fix pam_winbind cached login for samba/NT4 domains; bso [#4225]. - Various pam_winbind fixes; bso [#4094, #4288]. - Fix DCERPC funnel patch; [#245278]. - Fix vista and share level security. - Fix vista variable expansion; bso [#4093]. - Fix vista DFS support; bso [#4356]. - Fix vista backup tool; bso [#4361]. - Fix vista deletion on shares; bso [#4188]. - Fix vista spoolss problems.- Fix crash bug in rpc_pipe_bind(); [#244892].- Enable DCERPC funnel patch.- Fix accumulation of expired LDAP connections when winbind in ads mode; bso [#4009].- Fix all lp_dce_funnel_directory() callers; [#242833].- Disable broken DCERPC funnel patch; [#242833].- Update to 3.0.24. + Potential Denial of Service bug in smbd; CVE-2007-0452; [#240265].- Fix logic error in the deferred open code; CVE-2007-0452; [#240265].- Avoid winbind event handler for internal domains.- Fix smbcontrol winbind offline; [#223418]. - Fail on offline pwd change attempts; [#223501]. - Register check_dom_handler when coming from offline mode. - Fix pam_winbind passwd changes in online mode. - Call set_domain_online in init_domain_list(). - Winbind cleanup after failure and fix crash bug. - Don't register check domain handler for all trusts. - Add separate logfile for dc-connect wb child. - Only write custom krb5 conf for own domain. - Move check domain handler to fork_domain_child.- Fix pam_winbind text string typo; [#238496]. - Support sites without DCs (automatic site coverage); [#219793]. - Fix invalid krb5 cred cache deletion; [#227782]. - Fix invalid warning in the PAM session close; - Fix DC queries for all DCs; [#230963]. - Fix sitename usage depending on realm; [#195354].- Add DCERPC funnel patch; fate [#300768].- Fix pam password change with w2k DCs; [#237281].- Check from the init script for SAMBA__ENV variable expected to be set in /etc/sysconfig/samba to export a particular environment variable before starting a daemon. See section 'Setup a particular environment for a Samba daemon' from the README file how this feature is to use.- Remove %config tag from /usr/share/omc/svcinfo.d/*.xml files.- Fix pam_winbind grace offline logins; [#223501]. - Fix password expiry message; [#231583].- Move XML service description documents; fate [#301712].- Disable smbmnt, smbmount, and smbumount for systems newer than 10.1.- Add XML service description documents; fate [#301712].- Move tdb utils to the client package.- Fix crash caused by deleting a message dispatch handler from inside the handler itself; [#221709].- Fix delays in winbindd access when on a non-home network; [#222595].- Fix client-side smb signing; [#222951]. - Fix imcomplete merge for firefox NTLM handling; [#198255].- Add IA64 and x64 printer drivers directory.- Update to 3.0.23d. + Stability fixes for winbindd.- Fix ldapsmb group and unicode issues; [#143417, #216606]. - Fix net ads account management; [#217046]. - Fix libnscd usage in passdb; [#217363]. - Add the "mega patch" + Add site support for winbind; [#195354], fate [#300909]. + Add site support for net; [#211281], fate [#300909]. + Fix winbind krb5 ticket handling from offline; [#178028]. + Fix "net ads leave"; [#196771]. + Fix winbind username case handling; [#184902]. + Fix winbind name canonicalisation; [#210174]. + Fix winbind online/offline handling; [#196859]. + Add NTLM cached credential handling for firefox; [#198255], fate [#300973]. + Fix winbind groupmembership handling; [#211324]. + Fix winbind site-support handling on reconnect; [#195354]. + Fix winbind child initialization and online/offline handling; [#196859]. + Fix winbind cached credential storage; [#185053]. + Fix winbind long login delays; [#184450]. + Fix winbind crash for new AD user; [#208454].- Fix pam_winbind overriding syslog settings; [#201756]. - Fix profilepath pam_set_data for other PAM modules; [#215707].- Fix timeout handling for winbindd (samr, netlogon). - Fix gencache access; [#209409, #211281]. - Fix libsmbclient accessing NetApp; bso [#4018]. - Fix error handling in ads printer code; [#209409]. - Fix passwd pam segfault; [#211719]. - Fix crash in winbind async child. - Fix winbind failure mode for trusted domains.- Add realm to username if missing in net ads join; [#211706].- Move the LOCKDIR to the client sub package.- Activate the libaddns.- Add version of the package subversion to Samba vendor version suffix.- Update to 3.0.23c. + Authentication failures in pam_winbind when the AD domain policy is set to not expire passwords. + Authorization failures when using smb.conf options such as "valid users" with the smbpasswd passdb backend.- Fix time value reporting in libsmbclient; [#195285].- Remove update-messages.- Store and restore NT hashes as string compatible values; [#185053].- Added winbindd null sid fix; [#185053].- Update to 3.0.23b. + Ambiguity with unqualified names in smb.conf parameters such as "force user" and "valid users". + Errors in 'net ads join' caused by bad IP address in the list of domain controllers. + SMB signing errors in the client and server code. + Domain join failures when using smbpasswd on a Samba PDC.- Fix from Alison Winters of SGI to build even if make_vscan is 0.- Update to 3.0.23a. + Failure to strip the domain name from groups when 'winbind use default domain = yes' + Bad token creation of local users on member servers not running winbindd. + Failure to add users or groups to ACLs using the Windows object picker. + Failure in file serving code when 'kernel oplocks = yes'. + New "createupn" option to "net ads join" + Rewritten Kerberos keytab generation when 'use kerberos keytab = yes'- Replace vendor-files/tools/dlopen.sh by test_pam_modules make rule.- Fix pam config file parsing in pam_winbind; bso [#3916].- Update to 3.0.23. + Improved 'make test' + New offline mode in winbindd. + New Kerberos support for pam_winbind.so. + New handling of unmapped users and groups. + New non-root share management tools. + Improved support for local and BUILTIN groups.- Prevent potential crash in winbindd's credential cache handling; [#184450].- Fix memory exhaustion DoS; CVE-2006-3403; [#190468].- Fix the munlock call, samba.org svn rev r16755 from Volker.- Change the kerberos principal for LDAP authentication to netbios-name$@realm from host/name@realm; [#184450]./bin/sh/bin/shwagner 1245874229 \3.2.7-11.3.2libnetapi.so.0/usr/lib/-march=i586 -mtune=i686 -fmessage-length=0 -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector -funwind-tables -fasynchronous-unwind-tables -gobs://build.suse.de/SUSE:openSUSE:11.1:Update:Test/standard/7662268c1499d98d90f582e33deb9bc6-sambacpiolzma2i586i586-suse-linuxzhDג?`]"k%jjd響nR >Ѿ Y&Nc q g+Bڜ.d785Avi`o :vyOjyv9sl 聯Z|ZRԧ`;wQ>T@f mZ&'K(DVjY.-ʠ)~Aw@V ֢v`?HQRe1Wvu677TYvL8dZv chL4+$5et&$/h^ҴHρIWQs]Z`t\+n]u~uHܿK4{e$T°)aTMˈHʜ6?bZԁs ld({y4`~^xiWK R3??d4LY;hg& 8*wN16Jנ|*Ӹw uҕ$}Fz*"{nO&ie;AT GH"Ƣ< @:? {RYT]S={28?F PhBG"ceHű,$}N7<̝;w$U?؛yrVJ; KDk?**AuzP?#}>S$ ![@2vNol|b_^;~`<4mW5R! O㔊%`C^ qf>RMk?6iԈOځK3-eB}Jx7]Z<҃!CԎHgY~TbP_2՞ #kt`Mn_6N"o_"0^U55;?99fHφqKTcgSjЎ By)$jM}sh+T&Lx5ooH@i>3:SVsݸ"#wx-h-Ⱦ0}2LZbH_'q%X? oY%7Z7b`YY-܈vJSЃ|, E Sο6BDeKFO-H==+c ,2x鋡%*@)'0v JL[ 89Q(^e_u-dJMҘR<:OXH}Al(#Fх zWJU\/ZjKE>Ρ39uI)&CK2LRk x@RFh,8OgcF3rNIN|XrCz?k`nd "TFq1A5p7-"B|&t0g#@ЛqPޭDt ֜/N*k)m}=g(!!'I"A5{FL|z_YS+Y4`EQa]>~լ8uqJsd:l5/XɤQV8/;Ui%4 N8TDձG WSaΗ]}Q󩂻QχL5]Sˇg)8b ۘ8~DJIck4ͼv3hE  4jGtMؒ8!'2S[ȑ 'ovcVZ*:6l| d4z/x[nޢKJfgс$E.yHlehg%2&,W7aԸs?}j!-ENoWT,ʅX' 3 #0a* 3_UU;tsRѭpN3aTw1QOL(U6TPн'ERuFA~9B+|Uw|ǟV+ss i:_ںX×V.Ɲ:Wm9*buzѩPxE[VO4b2A97xNdMm6Qɒ>:XUji6C->!B2J)y,GIb}IM[~G $JIGE7o};7'0wZ?:JCSŦ(.!VA (%P/=Qu#(#"#uJSOq 4.w'1SA87:C!g0<`[.kCko/HijYOٯph =S3AxC&1YTn9F*{/m a^ x MO&ӯ40aswM~_ t8ѿ2=$np$pD K'yњþZ@`Q0MGyGÝa8Xz.FJE)ldȟYTM ^nqHu,j4OGۜ<msn?+ [6}pq;P6}E(7*'bF2j;?<d@PS ބS'POj%g6jѶٹEؗMfs#*vxAIc}!܆"8o:4 @Hpx%jNG۔)\r2~k"J<<3*GuU/_}Q[N]?3~p"zKH>] Hg\ ̙ՂtY[2$}r Pr0a =mTL /aUo]QŁ& LŽ9Um06R>`St礜+]?pi@fT/hj_mmc* BJu/Xo*e\{FڎsH_R~Ӗbd̃Xp719]}},aPSjT'R\w\Ilgu7 E}O#**\3Azc|O .#,b\ܲD_u}ԥ{=- |wϽ7<@Le?>TS( -{m2aeua9_(Ǟ uWԇ3о[ɬ$*A`LxAP4ڡL'X,8 )Sс`9 k!vkCȋ+]q8i2l1HT I~S&/˒u:!Qf&3HjMWv;ǠSFGR/_[9I;^P5ӖV^QX pc;ݯ;H ~ng{,Ww[WĽԎ#a99b֑,⎳ l& QRֱAT=[32V/cM_YaPiMk Su&X] v\ dk=>a :|/Rr劸-:PwX j\ѫ"~agerm-UDV:)\B_0su $ gHEzzÈ7&kc4feE3o$}r!2E =吳%6x:pr=Z d[m@D58#npUBJichg4K (esI ~TB2" N+4x3d> )̑4Qa: zLS~.7L̐RWXweچ4ų#56b0qA&ku|GjʰǕoQUn|֑-جdMsL`9Iaq\3d*]>-ߛt0X3FKt)l֫N?T5E;AI+{8jdtG3ureLyU8qT.|E/'O߯n/|a1C /)2IꟄqs:&PK"eṕrp)}$q)= p=7ؤ$-#bAGk( ")#V|.к{6@wVGhNf5(DOЇKM-H &=g쒮vCvj nVs}eS[3DtICljךod "A;N h&we8?&TYcVE)~`L+5{:|nSD6'~b3ܷ1-rۻ7~>#׿wÿBNasUG¡CsLTY?%MB՟AV4t"1Nn1m]Bhg $ΰ7JF88&n5#uX=Kt- {um|2Y3艻Wh.,R9]7ȃT->?4&ȯ"l; .jAӸIK6uey*J)b"Rs` y]SK RɁ›r=G=FFw$yΟreBdfVd>buZrcY>6yʎ@vpD7_rA RPKT%BԢrAB06Iږ"X7j$|iV~}2H6kR5R8mi0NkW@4Ⱥ\_WsM&M =JC7E- Yv 2,i8ZIlGEZɑ5e1/$QEKl[KW5Լ uO^2@?NAiIѪMފPD-r1#42 NͺؐA>l?*FPU1N{#'ntÎ تc ҍ.x@iQ%Sn1GmU j^9*/F# c rg1V>_kӥEp=JMҴr0߳|]/X۞ODH)#(Y9[ ma?.,@FRY@,m?n}uCVE31bl'+i~;8M~V QCNA*\`A79qͳ'{|0}dHl9~o* 1j5J bb vkO(q uxIjn&_g_[/S?0zx,D#aiг!$^3#08,GFծRxGDYy[lVZ4%49p"$}on\18#.pZx84j#o)ui,0R-%$l\A*ߢgb DUh!""K58ihte1+~o{ J)Tn0ڃqEh[ߕQLm fnD*ܼ^HX!`=^ }t PQT,7SuS6)A897R;宨"FwDDbN\APH; tW4!ubǨjTԝfپiHoJ(($8 :cNP!̝ެ?) =$޻bCA,C\o+KyJ0^w Gm/*Vuϔja 6+_gqf"Sߤ͵r!}s5,Fh@79MUjQ2)ޔ bQUn(~)[5ʷgCVCYپNmi$_&V/nb5;T%9HlNx9:I'zZ|4VUʟt.v> udVuЄ9{;$L\ a$I#s'DȪ ˋ :$8D5ퟅʊ_Z ,vѤRФthC̯&mvAN+6uG7xʺ.VYZ\{GݖtrL#ГA]`][i>GoD5o ĺi-~:]2?b{Ţ[*"5⋼ !We{7׼+M|OxH^:1!E^slFDsXJ)kߏ/AtzrZƔSLN+=9qkڟK^m1}|ͅ1-(u@=͢LIJC sEI3锻n@s!J&MX>k`,PKvW3ހOQ!Iƒ3];HL{+H@)*n%M1>+dT/#B6!_yڣI{ ;@Xd֎z%ru5T&n2gs:uD@<3nF~.ɤ@٥fxz"rBO;mAo( hnC?^lbhWa{a _3&?31Qj6M,owlG^`/:R;<qs<0rGJ@3ՄaG%< pDMw@-5]6 誴ล>lIR *mH(*%~J$$'laFΉg$^G!Ue$˖5Ysggqu#r~,`x }JF)Rh5 %zh" ($hpkUFsf&gN:g=]r=qmXl;B5߰cysP湪wdZX|T Ͼ~}YOߡ-GfxS׹Fx)$Ϙ0iڜYY([=iŽR >%EߵM!o_ _վo_ 8LԳo)};J *ǜl'iѷO/$JʚĈbo2bh`U0Pwk% {E'qқ 'EYEd2ѣ="Q@QUgF'XP_*7%^nylJo]wg :Xƭb_5P^˭vp ~,XدdJ q^zM| "%ߜ|jaw+svj4,[ $0)7|go2 !r͓w͈\[eݏ ܩߤmtdu3[Ӎ6Υ;&4iLWOy͏wGtu: cNc!i⺻$kCA&TLV,+W=}`Pc 88eo` ͗0~H6YЈ9T>Z+com R 3:8 gThlraX ݪBO961j2 >)ԤE*dj/9ia/Id # VHRqߟG-ꄁzs5}ڠ8J&jy(䍠Q2ԺEޚzY&OM_=Ͷ{ͱ=&/[0{dH >0ЩjJ\+¦?'vUTÉ Нշ}7%x>{1/a 6yb\2!8ÏGϧ!gttZȄh}Tf{Pl&!0<6*Y8%!mGNWYiK4h<[kCMD@{cCgd}ܸzsֽtjr76`4Vm./Y^$_OIvX={ūYd5lijdrX|:eg+hFv!; JI )~S CtMO /u'Z4؃)^j@5hΟ90 55Lœ0G",e>jtţM騕eV fb6lsCYI>Zgۊ35h%gkk'bLugTJvf{ӱw_M$L;w8T39|(mOEe-du6)ё cV%&tژȾ`\o6xQ;Q9QiK[ w,+m}˟:CFk4RċX|h.,ŧFV-HSM%Ce .2+ κ~KBz.$CW|f(Am:em'&SF9!mR2N('OH2nB]fgY[b܎mЫD܏\-Z΅'׸% IZ;~CSOnSxFq׵8Wz?W;Y$Vp O]0,'t% C$B`Il_W}CY8xDkRLAnMSeXZjsH.e1}beeW ۸,>=&"d4x|&0v1>;3tm[@cE .oƐho!#'YH!8Bl?|*KκSf ;+>&,yY1jSt!`l !ڿݭy'upk։J_ c.lCփ}%!1,+ƹP8a|\B'ӘP \O^<1`ga-L4fK0/( zZ]if uVNSCL;8Jay3.}BU#hUN TLȺO-Q n16vnqI%UƱ26 PmȜOmOZ~KH" v[YÙcҪG,3赃T5:Qj)F83BKoU*:&8%}،o8xm\\ pt>G gGN˫S̐wi8,i _3M(0|szP ON߱!-N%hS*IGcNV׾ז 4vTzP!͛%R  ]7hymV 7˸4g(2=ZIRIO2@릈f,Ё3$"\Px:T9 Sf>֟z{O}YDRQ'Ъm FZԂq?(}1Wy2(L KKo>Q|1z H04P M C pWfaL>Vz*>%<`PB 'Wrfך/4#C.Rم;m$+}:%Em6rÚpF #?my&/d lMPZ+OVަTS8Oqk2ÞBe009x<Ək֙%!{tU%st_0ϴ |a gmiwyYsi;&d;"g QIzguV О{C1k_QI"6H\OXuu>YP"7|?P$SϻzF74qNt8(oY3.a);OQ3ҋ:;9(&:OM`㗡/JD̉ܔp~r̵+ՎD7s52A+C9Vr>Gi:ϭ*;(J8Tꩌē6&m¯{-.e߀'ϖC5c7F(տAARX(f8)%vddhdN5:RӍp1@RFcQ*'BHx$B NݘW #j 7ƌe*wkҪ e+z[6#f`~? aςk3 UP&wK2@4}Ƴ?~F|smGUo`2F1 9MO}2р04ɼ#GftMj JnGjJ% ]׸2شK& ydVďy } SPr DRil!yB*ul3V< NncFKoT ̹RGl%'t<ېu M*8[pz !W}&]t(rqmh !x)ςwrM,eMM9O+2 -+$eLZanQ7ktvzѪ*>^H%"|1Ƕ0&_ʉ .5XM&S0Iz^ڻŐź]tn%tJʥKSo` qج9S|j~A#n ԰-[Sv\ʖaU|>:J=DA)p{K ꥾;O <|)y4VYSp狦dSUG?Ѕҷr['@l;BC4ۈH=$ȺhgI~2  ǹFiv[|xHb<~Ì*,ΥH!#2E),oAq A??lef6oeP 3뎻^;]ڐ[xV4ud<7h$㬼:+2̇DIHr]S-^m Tp@< xtS!>"Hk<2?ɠh.ߋ\|@Csۉ2(ؚؚB V.vk"*"{~i@WQӜ'sY4!sFlFsy,!uLpLl] ;"+z;huw kA#Oİ UG*^8m@" ުnMe!-"κ|x`Dpgi5 2{ {8;56n7AYC"U̝nQ(ǜl#N b&#i=rIb~E nwEL w+PD>(1T6B|œ;E$- KnA[I?4;h;ב7E?Dt |D wUWa͒tDPY17;SKژ Jq1@>Xb]8&M{1O^|TH!,} О3nFx!BPLip,6 @rF\G✾ a4gi=ĖMۀMG$؀\<in"swOy7>jC0Qu&XfYrɔ'.ҫh\/?}km)α,N+]HnjpX"K˚埬9K6 L*SlyX^/5~ִ}gU"ގ~zYhoFDůӵWBt"޲\l/՘ٮ7ݼ_+*KIq z|h/X<7GkVe,K68|ր1$zSը+O_K%|UYԆU QUi~&yZ3VSILkޡ:Vop>n&~Oy!%Gs 7Y-^l@E[\,#j G[ćw_vVFQ0e-71L6pz@'T'Ԑg-=9?҅t[DQb,bNcֈ@r. XՔi?UrDOn-кAX}Xoc_V<0*;VeFkEϸ jR .6X Wuju&W1J>Rr (`#Cx2QshKz+vҳpv` w-{ܚwn6"JGNT'2ܹbsUs@+);O?J:0M,^ǝ`y kRo[fhGzQeDB3~5P{maT*R\>zĴ/FtX >'^jA(#TAMcX(7J#_˵}>`hx iJ6y~6K}G(8]Qڋ|˩ !WFO1f60,xk"xAo- c'~nLXv"斧6r< LG~ sIz& x S4)8x6m!@4#_6!bQG`^,=ɎDƕ(#7 h B,¢xOU?Qd\7{ۧx!vIJo$@hخ.8,{$ˍhgll@EԈioum ?b3`8 ^OSDyu!=2)yʨkRֱa$lBdPXY4(DrYwG][̟*8S6pX8NRsٳA aO-쳾2\h.5ε=mH9|ۉrN-,M(Sͣۧ)X:B+  pNؚ3e"Sl.,Sr3MYF˚xT#|zU@< Jb.THwߦ7ٺ/f%W~:lS!v S0I -[;5-|ӟ\yFIPY:<ݿzCz~f_Yzx裍mNk^)t>hjVcy'??I(_*@Fv;m"4MyS?Ba`l/:頻)?Wc}>_!pYGcisҾk!7`Pdezz<O(% $DvQi4m}N8`nGߥwP {`p2gfY)?r$wY42}}ci?W3<]KTOu".FxGdIJ_, UV`@  H1z4=\'~>3!Ku̾h&О{@~ uBa3RpEWWFoPQ}lU:m'\W|Hoփ][m5.wˀԈT"H_- `sGP`$86j/Uuy4{tKF_ ooGH3'$%"p- =!B;9BupQoziΕ g3x(9Wd_FB6.$%%hZ{c0t6*ma FǛk[2Qm?rWX8-lY9}{F=|7܀*\oF{9Sg9u >wsEXD8I ܼCOsE" fl@W)P $=D>6pt3ig2cFh#rnFB1Ar/C<7@9[[KM>=QBLk#J)VHcqjEɠm[T{ZP6RXeQ6bWFd/Oi|1SHFƊ*opl KAR}|1S}ЅgEx/'Wڑϛ5uc0wJW9d$Vm4 |A>{| _NR>XOMz:V`ZW/Y>ۺVd{B!pu^K}PJd뎤YS}yJ>\L+ !k-I dӈqH)5xQ!^fY;1Aeڃ8d !B!rnԅAAT_!.B` +?5py T x^n3GI~*m@h;`b:a_'#5T|&Zk(m+ʀIJk2^><.[BkQ}R߭~,/ۦP8Ld= Z{@ܕxZH=UIz/|bhG[H8C6jP#'3f }n;pȪ?AiH}Eg/)@vQ;ՠD@JZ'*'q~ {_?J &b4Ȕ_>py1璬΂/i 9*+˿eB?NQý1?nhFN%CU*0ọ!3Vy~(]!K"65zlD(NJ35R 5o)Ɉ`6!œ=i"=Gk^c碱tSPǦa?RnlCF\^fWI L~&W9 iY) ڮ<^]il .=~bojB10ש,wHhtek?;čەsӸ1RAuLab'JiI 4=ǑO Jw"44|+]AFPis10)XWV*r^l vS ЌLlJ!Tt;i>ޕ?SFahټs\TĔ-_u0ƨΥi1z9yAۥ!)Q='lWo L %tp<)֗s|dnZRCjਃ̋V^1 FY]pZV-1rLL+Nclÿ́l&'{x#>l W@# Aw P']+oqzy"*oM4BjIݔr=S؊á>r/$xNf[ $|ʰO4ޚ˙4~^Ю?vEcmqǷ}Y搡S筶;Qhl ̎O];D.ʕ\ ieaiXe^y$d-%,#}~7dI9f}v_`2¶)w-X yi^u'C{`@ReG:9_):^^7F!מՉ}7GՆL" Vxϲ< =ˋOmfiyH)_1}7jDhx>Hۜa M32cʇ2Tt%qfׇu%3&[+Q4<C:M\Uڮ U}B9"Oﻉ, #G |W+N<RFԛ*S&Ց\`ﯮsqb瓏|";p?e;K?QWi /%7BHz2eW }:1>H4xwM5{ gJNVVTy랲0 +QLWT`"[8%]Q!\NddxU'Q޼`۴Ɠw0 .!,*fdȄB5{2#3M RAkb#`,XOryGǻLICLJ#$(!qAVWz@N;'RӨ區jn%W[|lWLbRRքW BZmiLcRF6] bh0}6- h\{UkZ*~zbt)DtAQ5l!0Skf6A"jRS%N<' %g"n]n@mсf9sj=){ i&oN8ra6CPUꐻbχ ( /K9ǸB}3,udl7[TKC5ѿvo+E쏤L;(G+6 sϨOn1 zַ) m_LKen\(;*NE23;C{'2c2 ix1)E5P<}!)gt̓A#-kR$&xCI'eA4d GNmBx\˯}m뚼U_;jmmk Y9>^*w1  (nIܭ,lx=z$H1qxPy+0p ^|gWicqᣚ*P͏-k LۃcրCvgOUdo_O;ɘJLe,M%5)TƋipG} Y DŽ9O\\x8.X~P"8Eisvz VLy%vOh_J}^+G*3;9{U 3-?_ b>r*h#$Ȣ[,D xx7 ShJm ȬM/[ulsCser=_H&f.bq)&Ie^/TX%wwf;{\7S%ҕy{ϥR㣉/,EB:L @*j zb꒩1BP`Zgn|WxHscuOQTus[my> ^[g_Rb[ےBZ~iCڜ>e3Md*/¹:Bj*Wr\ FR "a9S7oc1naG9 %Bvk]%{r7&ww|4h,ԭvEbhZf@r~(Gؑ#v|fUMSt'w8ď;=;w'jZ[kԬ-[n7pչF8>q!kk}v(?6)Yh{ϐ-<;+oXR8Q_CMR]$/oӊXmFY-lHQ?nqÌxγW)!+h.:ܔWI4w@!cuF|Gө"`Q[\gf\[ƵЭQ?SKP3BC}ݞ=g /ٌzIԚhC94(~D `v0 FWF0A{6orRgۓMԲv[ z 0c t`|`ާ{7zg~8eMť [Ɩ>S S\Q9XSGږy,{{[%D:Cឋ-MB^5m^eOG6zΟ B?ZY"D`Yys9bXRD)7׹>]Rk#)WM[x K`F<ֶ@8IS7*hk.5 3>*q~`c<ltO9 >M#I%ɲ2r"eVk՚[ Q#pim3R|ر4QŸҰ,\[73!y&_ST {Cݼ,'0* P|mGm8_4DXodZ.-g %7(:"Lk "Ê27H m>c;YO> )IWO}TTP&ziWu`y"a%B)18Y;w91RRx4qLk4 gyAɧE] !2嚱k}s(>]nghpJM[hބaAl5.*3_a#pSY*'Uභ,UMS i0"XI_`T!qx-~$nYiYÍm(Wx!/yH"8z &Egn?9GUpa|yTl2ƢvmCg!ElVߑ{ԘEqm8zʶK'3s>H_w\7$jUppd )&e@S_ō&⥪],m4RPZ2˓gKQԇ]v](VғA-gĒ*8"X5Be_WxD2s&|[X&g s`V./$/b{mN$Ï\̶O\ p݈\kUjf/ `c%2޼5Pr~ƺ\(h5LMp}R@ ,>icp& ,M<,k|1v|=GZg 3,(5<>{&7%7X<:0䫼ROP R X:Pmm5 : `!,KN `)$%4a>K0EԈQ,-l+1uD+YoC~uʸ_\4Vbəd 㓨+*x--G3̱Lr.^Tӯu&bC`рM2Ҿ})cT#O@ D܌|AƎ-}GzJXMjP/ħQ9M%r7 f,fpE'jQ%ɬ lbiU+ѶfBp3sžT,NjK@Fyu?GVʞ3dc ?;c{ 0_UEN="_L>gr8oqGq\iK=B:$m v}둔 ]rIBxS18cg mӦ` 4;o,w?DuYkՙ-T: CA`z:Ã3C ` Ua 2~!t>Sdjx_ 咓jf@iʹ+70ʛ|J rfF=t-wW[_i'x'HHErR㩳Y1xj?80FדC5eȼ:A&)d_r$`lLGP-wǁT+(]LAkF#h0Yϔz][ ]+h}S"w7%%ԤawM~,㪣{/VxAd=E)؄KFw) `RhXO;q *QjOlWgv)tUTf04HYcWe?žzE L=oDžIZajtd8F'@8vFc J U+xV d}@m_fjx2aHj1#Y9C)pG%Z0<a(y{39OS9-J^'nOLw/z] y`B8:~EA;iT/'/z[ߩM 10׵R9u"}ܞ`q:a8 Eew|Yxd9žڗV{s_hHbEa˛zz$-&bfGGҏ0BE +@,P8feNΥ6n~AQDXj,7UP'e4i ̃%wCE׀u9|+M; qp2tgΪb }J /쫧Z("ؓPME{<$->)9?LufD(1vƛ k6{h٩8Bcu|ULi:Gk]RAt8Q@(:t0ʢ0^vZ'V~ k^(F% J}IwpK@WNeYm8eO)*M;szFEqOS}l.Ue273L VLdKxĪ>%~:#wy˴8 +Aڒh"RĢV>ǣIQrDdPdڑ`H'xӋZn3I)>in]mo1[+f9>n䲑,  awbw`H&."5=X6:[bh23^Q6pǽ0k6 bpKm~i|CÒfTs3⦘YE'Uesh #e?*k:4EUjOCU HBէ,Ҟ9 VCX-9M^ڒtNo™jJ uKWU=P' *Փu,wu# lSJG$uR?^B+qY^`kjV} ]ˮaǔʢn|$ '(Cls|o}h:f+ v}h<~!uCRz~ $W;oӯhwGq>̒.^h.bkhL| YXq~y3VTp}E2ҁkMLW2.m'/t֭굃Et3JEm2϶Y^?gLL?eH 2q#q xHo[֚eH.saԇZ $>)1;R> bTry;<-\yhTsl nž ß>O.ɕ:Z=)q&A G`A] N0L}!fx V2)$ fWe'%}eBG3¬JSqݹ"WTG1 HQ5:n5dF>/cO~)W?$_kv@p/焊1[n.\$ϙkeݮ9fT-\O]s; f\k@7OEaE@srDm[̲ߨKa='Hei 9Qۗ mhPQ48jg_GWM;+QD EcR@jj Df`]\dh\oqSb ն| c`ޯ]*㸻J,H-Jr.*tW(8o&>D-,rDn+6Fc/2,3I#,9w%*DU30$:Z[cV+I6M0 [E =/˂ ́ it8< }:BY _/ʚj7U)ǾN;Rm']S᫉#LӐͿ:ɱ(‰;ў1x2 5&ډVn-<~ gU[}->g:%XVP(Q[fj T`tA޿ _46AR NY |뎳5Η+LSËTG)X顛FZDXfkL$y(8p B>l8h 4|`⻋KFEbGWnʅFitV YoÿI/J-$Q룂N; %CƬȆz\pi>J+ 9hQŜ\@VBJmy-p~7בg$'T*olQ8ʏSiYtڲPO/2cn4N-Kk#xQ-.c.OvP]^Q`(%" rMQN½w*wc[n ơ姠r_8<#Oj2Y\Ɗkt Id~kFo@8\C)_=.ҳpyP@&fȶu&L{n%f|b.z~zC\h-e?g:dC(ݨC6` uDkl\-tU"&$]߄;1_gσT_KiyGcԭb"X^'PO{H}E!˸ 8'tC!? Lonؚ*ڽ/GBNJo2m}`UXnx,BQ|/&q)gs;cho_k%{q)GETyN" v$N!8mٸtAި\Uj)q qͤ3R59!=3҇ .H FmI J9{|o%Pg` ԒL9tŻ p2|ڍl|m]cf¿ M@ -0)gVXK$o͆Wm&gyŊR.D)}1s,jD+oF3ω vNujf%Ko!h&ܴbϿD^`hr[qǗ%*y(-hQuH00X B:Hm MM7D!3˙ Q"bQ8̿}0)zDt9o5ѤVS ?\DN%E~[wzX{`F W*g+Щ uq/m+HsY8vܧmpRxp G,+f _%Ҟ|'*JwF4rNbƎ:Q9TBˎj=Ty!4S wr_QINngI̿^:g|tyJv/6  ,60oހW|fO-S_ nk@|ߑS߷X>ίLM/IA>̞` h/p(8YTQTR5_F9KUTܔE턇{nsBr1.q5Q#^8ET6HZ+#m`]okdw3g9. "bOow7iqN~%9bP?b K;37>ќ ̾ț.~ۤ'63/N:`0`݃+T[J"F,Ϻx_0.*U/b:}_z7AH5 X_nxUBQԑo4SԚقU)ߘDLU;P`ƃ1BH}uUB'9F$*j4`eK[8ޡF6Ɯ }V'|̳+݄TB,&Vț? ˧L"SI05"`*:y^XVoN%Eǡ5'ybk{UMH:)k;z(W$Wr>Diq;Mtt8ӄ}ڽ@#s k[She2C'r2tY? t>A.mۘ+ 5!cNu*?5 S \3E'14EP.e" KӱjPVhjF#-ݒ^J-y'5p b\IM;1;3g5nd?Q? FVfoU*L^DcD^NG[j&XN<`.KCP=R%Vח;$hh-  (ESk\>iح)N4 r/'kTMMlΑnM{Nnbllb̼ur`Kو&.jDi !\^>^;>}')ҊK_ kEh\?i/0dطy9*`* frh̾)>+=1Mv$}H mMAA0_&k\x]GL8{f;qO)V\Wu)mB.8uUB ʛK{F  r97?rOa5c4@PqA|4-9 >g FXu 9Ը/h-=М1a\$cK3q#*v1CDKDFt9qw?B5LٿQ{#m9bqoJNDT> M@e6A`[v?'?f.7wSB2`|4Qxա~T>Q@gDŽ>rU>SHP@ mfąd q;GYQA8B d\=A}+%fiվ gi;äJW?)az 2'_빐dYM0zV3!_G<>moΊ0+N Ae>"aKCtXb:uEBdfxnrL0i y d8.=Q祢/Xjݝ^5Nx3p|zt:d>!bT.4 SXnYʒg90e= @ULj3a*==bLz.AQu~*?T EL;M W(!(̠JE4۰9K<yh`Лj.,Oپsp VW 53z0X],>ew]"|Emm:H+rPOWIf2cfD`?p,pVO9>O~v65&j&ir#J.=̰ȰcgM9&Z~>ƪ8jyxz$+v?0{mG>FsBQ[ T47$L&<xhh%|7l*BmX/(lpvs}3?bϚ&|mH:t/M TZw6$ Ďv#ϲs9 OՀi.L0EX)D8:v;tN$eQ6粓 ZC^gGZYy/(GGxja)O}q(L.O.ԠcA]x؄;2Μo2S/'Ji(XIAgh2gtcEd?,~$;_ ';-n0n3olz{:@s@`^>ZB/|ܐ8LOǻoy6=#Ǒu1؈jiarU332?E^ՊP+p!%6)~Wh=t=NvV8$ڊ,D|Pɹ}7SҵSI\IUo^dRW?˺45VR%12Iۙz5gqt,WpQLvwe8e.LۚTZlrǛaZms<)ZM<tILdN.uԠ7EbI=ӳA{T-&#z8ǹ&*3%zub&wSwH_HDyJ-(eAT TD7:>l^}T_}w3-8\S97)!} E嬁rPNQ>|e7݃+cGv3pOFԚeAj/Wj^޳XjŨ_*o }]n>h7v_&]hX5\ܻqMԢ԰;PXYpyn(y+[\l%(UVqyChk.wR^}wˆޘ54 #T 7,5aeKȈҍZBTac %@srqzv j"bp6&A?8B}˵l=7:5xyZ_*e]mG{uy{ǐ9cDJ65:ŸX'?V9Wʩ ~{RTJŪ^ǩm6P3AcIuynnoQ B@wxOEY8.SI{e>S~]W0P]sIīS%i[\ft $>gl%ՆRcmP#|N>qtGZdU1:z| s K`eŏYTABIDJ$[}Ó0iLZ{p] ~ERШ3h~$7͎߮^̔ |o3{\'K54VK]zخ ޯhh6=k)l7O+kw/mG$@pМ/l>/JX0qhϰW'3vk3!eK~ўI/+;$1LF@,kCGy悜+ie7~O wڗGS!F!CDZ$G_7bc,Yr,>G1{u *?E~|E&c [.n-!NUǣ`Hnb8QC Uȝ(M ?#ˍ뻸:XzU/|eE˜?+n^Cth۱Lj.3"^[1A|te`FSh]4ۘ)J)'IP$IÈ-l%Rd=Xq[\ӓ"9Jd sd,Y!oI}(2RD~X,"ϭ=K #.x,Pm<y[k"ހf1<;7dZf\ݰtl+2F_շ{ &7-R^4@Y9Y7X ?YYxviE&A!C:U6nYyb76#C&`7rYB.'e ":;5ڹꀉL;kW ihWqF<60ˆ{3{>C{f+f9*CK?0F{N 6A&~@nl E^݂ PeF{v}ϖwEʗT /wU8=`i(Gl[Eǐ^)' \ Ox"=c@v|0D4v핔W\kz3 qP%,T)pò+̑:8uL#vFVt v EE;4i8Lۆv̾?˪BT2l%w=p a/ \N>M gs H: *'mhA_nEYRH07R:CYGu3cI6-0Ef9d0Wwepr!BgHxsWM 2DFtJBߊdT  A$R}ou  3…^N-إЂ71d0ѪZIjrEV!Nky[Ÿ`h4i~;"fr[GMNo5s'&턨bFԄc@.9zPSFWkbPb 8jTBJq4.%H|4J Y:_(Q0<0N%`Gmf)A2yG>W@]eRd^,t$ǰ#Hysѓm9 F\{[{FDsu8rٍŭ Sru^xr:3l7DZ?b;fa*^s=đٝa ^ѿ<-Nrʁ1-K & 0su.!V2oOJSe c9{ H.« lW%ut,嘢ݿlZ$x0=^PI \Q6bo7O RJ`Uen,X}RA _ `$؋z/56x?Ƿ)Wb3oJB VQ1wRŁ 0S>6{ MVsس3O^W%2.r#CQRr )d#tvx'o>6JBAbע2 /V"J3 w?]$U9mdO-7վ"*]  }x5p sA]4R|^Lemƈ :U$4i3bf2+:0 L,>b(5Z U"-`$W+)sf-gxx{9b$Vb`zS N`m>2*(LWFs~qo9X5kmIO* `l0R$Y;Ǩv[O쭲\sIĖpca_?W!rHAoiuN34O?(!rޢ%~ʒJ3!?]ZPoɔ/B%q;:t>e}Kx8m<;Dې4l[iGijVjGȀq5dd?yI+{Z@ m93ϫ$Gg&?h.\J;ꑡNhZn*3>'<&x~9|_7M=Lh5:޸#-i 31QJ| hP~يJz9XŽ\=j+.#󒚺xji'd.lLbe>I}=Nn7 ՁxC xOe.]>$/y(dX(tn;>D @ƄX?ϝ"K2<lH_fr$'J%,N ri>|1LL@-oKǿq;(IZƲa֯lI@ַF= 8{rs#yUsg9T[Z ,bC|E\ӷ) \dvqs;]Rt]4ηfýYG3 li R`'U`;لb`}qw{lYٌ+ɘK !'*V*vԏ<^V~V8+ɭ\IhK)y ?J e嘵2ϙG"B2M^8x쪋QeE*e  3yx= j0_:;QZ?dTTr[I<^kEɗEe<3^E "lzE8m\AUڎݰ `'Z5_.\+3u2jͻ:`J6n.22knSyIsC&d`Ll(MTV9I@Az^f#d~7#HRop *a^K&*(]]=w x+4/hT gy'cFєB-? F81  Y"#X-2`ތϖ]t0<\~ѕFmoQ15ϨiI%q!VwpaYPM^^9,fy b&'U6avs#Z%9g $[tyG9.kS8>޵Lg*;31j?A\stJ[1"(}%0{H~`>=NGT*7H^5_9zr&O(#k8U Ъ93&ѳ2] K v#h9RFccs(3'r\!%+5ԓjf5Mr.TF uдr>4ҡ. 8#bU G,cCG13*9&b" 2SH!ۊhE @ o;JjzL EBRx֢]EI8uW$qnL)g@Pڇ2_[V,ގ!kfAz[E}<$^0Q쎱\K16v 7|kvug 3nh5wBf>s~kW,X[?V u>^ >ױDu@k(U%X'rBVt*L1qM6FZh-8d^i%aCZx /y.r18gFτ+QϤuRӕYz;N\ѻ_Dch:f mأ5;+q9:`-qm;Rn;'Ln%#yBJ,VS!WHvSuE{ٕrBE4O,m7D@+UU~jCX  Fje.pznǤ_g'a3]F+/<,?(tyXu#?+=+F1tQh{ 0Z# s!(!z`K hD_uwr}GQŊcŞuZx3/ɳ7^rqgF1Dl1S EE8dТ֒ꕠ,ZR =f46BrsiƄCiH1Cը*b401 SS 0U~a\A9^<٘N.Hd$E93)N,R8"AyQC&/j:,}0&*K2Cоvla4 LMXz tDp6{y fCєA,&rSE [`&XB:c!}c3&9 !2XE7a'ܥg4l0omXVjoȷoe &. 8mO֓]pEOys=%ۂ?y1.(1ļ_ jTm7-fhOͧ?7T|srpKuލn mJdcb Ԉ /niQ&&lg[7WjcѪQ2iMXKMgy\{Md]p3ѦGTHn&v#Ԧ7$"Q*P1L]mk #VuRǖ?8Rm ſ@So T LP-D\|I*^MP\389%!Tz%@uWI0zi`ShK;y#at: BM~,7`M~?Υ=koĐ8Z'VM'D749`kp=%@/h" oj=R=~WkPԀE7bdW.VwB;/4⻪~rՎ?d&Ko#ߛq ћEN>qO"*У]d%s}e>q{pNwlcVYQs\yC("4IbVC{OZ_/X% "/ _~vYa}xň;sҶ,sfu4=kHd(w!k{dFL_cP,e1 Փ0\P 03Ux#"NdS~el\"iBy%!0D `((;fA$C JՎڳ8eD߽n66+Xs7}Oy~gkw_ezK;᧧vY~]'\($GEzԓLZ <`%luoj!H$mD?A/=&*CVZvg忞b+kg}T`%Y@1 >mAB,#) tSXۈVfT oQwX~sHzhGfece貾>װ1.0G9_lMB#KQ˵ʞD/6WH9$ e-"6jSrB *𙍴*Z{XUK mWf@P?a[3+չ;R1>|c&_Ґ$U: ׇ\,f7q(w"NlSP v[ };S3ϡddђ!'^?OP+$QrĮ5FOۻ`W- G>K%;fR=^M4OCJв"TZ_Đ~G3dIX'nu]1C<%$LV,oNMzvAC&\_ NvI^%ƚckhԛ3DFO|=dԑ devdoC9Po5-lς,OF 5yfk G՛=Zzt*L3 ݗC-ycn$>77;H䱻Oʳ&W"cx@㉳I.⿣Czk;z-S}EǡcSP92 zDE.!zgF}Xiu2]R%X`KnX:U r3Fl(KY`o4,@ݮԬ|ʸE`t.{IvhoI27o5Y u/:߅ KK.1@.O7| A3 n:ud 8`g }UK$$oÝp1DކvXnIݜ7HaHYaҌ(R.o8OF|uS) <:&0 !j[^@䢖BL]uU{$Q _S|hqSPcy0oM}Ûk`t_rWfYXYuff>3Zn  ⒥;ۇzVS}# !GWpw[᭨5c_uF-1-{>eue%P%O$[Mr¨6!udOT&]R!UHH2~ӹnD=Ym#aU2C6?!rͥ"9c&wDS?DTȓdq/8e|X<:HcP4)f* ͧYyIZt]Uzy35Y$"WA*QǓXZ;5 !$Wk5ïEQpW5WzHADH?7擉%[Ğ w:)2\Knڹ_2[=sZV ]S(2$%6)tZ!&8bѣcԎL#C=L@2%Y̒oaNsm G):q1fCMCD&6ɗDK̍M!YK]Hx 1G#'%^15X&cSVXwZZz;5˪Ͳӝe'hrFSXԘZ ;nSrml nwSn8X"W,HyZl`jfAK-Yym!\*QͽyI }|񬕠[m+UV!&'S6OӺN֢ؕS6fU3&N4`x7N&WMyf.Y\ܠ9~w;2Ho? .k߱Q2@ ttLss5'])OґhTsf$g1!!T׈Xi7f8r{[IiN}viEa]Οcu:oնfJI$3RM1I0վ4oz;UZƪMb\{gHN[t~*uf0d5G4sOO6K=FWozrg<aZ 3ym25HwNu8B0Vb QFX10S];p4@lFBDx<]nrWס lC\E7SD'fpX[ɤ:؆0ﷶtk NakNUgn/mmi@I7XxM %ǮN+Yߏ'f x`#'/]9*-R|;/=\j"ònorTo޺'&*Jmr2il}`=gȑ̤lL''L"%" =kHDRsO>μp @eMZKZ 6fR"0bhw(Ϡʝuv?<4?|);sȀ.v{ 7Z1{:? ~|Ycͪ )ZXFUm#c`֛bwm5lK3ܲNuiAC=="E_Mp)o\ϊ4ݐ=X 8- 2;>$I_ҊKܻ1zK͏Y)* Mo/;}Z[[V,G RDe(cCAXUkX7M6Xm:f5|WNtl(Jwu258t2uQ0 VWSE;9r&^o/yZ|˽&Urg֖k_K/W Z(Ŏ!B<6T*rm- [fQCh`S>DY:{^p=j/cr_~5?ݟ/@EIW*ׁ-ui8N;˩U4S $ۤLea4r[S) 4,`1*Eg$!UEH ]\Mt#aӉS]ӍDid$ٛX0n'|̟@}ym-Te(uCZSx#ɺ!smq53A_]l%3!E#<4r{4\x/1#P4gm=B=c V栵bCI^F/4ɤhۅ ygFz8j#p ~G:#Wy(|K]j.mAA|VV h 7,nj-'ֶZ>Gέ1X?N'U&%7*[bp2" j9dg> P{!AFOCf8^}wtrEo"BB ^eԟ5d[԰vT;n:aC_C^'˺rVTG=ds1t7p/=Yv*2 q#@yfԘ7ygE:G3;eXgS>>W/9?nqdfsZVggrϟ[J }9h}G&.aV$&w8Yg^/76t%AҌh )rŢDo~P }"KH>ϙ( u#ܵ#JV Y"/8l.*μ칁;>+%m7KtCvLB\#u2]dS\p|Ypz+ rN[w_B@hx#%}rJc{Q ;Ra#;yaBhME&ƢR@_3p¥@"JPIݮ[ ™#(~`4ql^'L4ئm:(p^9p؅D#h>4,0zgZrfsԙuZш5lJM NWmp X e@TjƋadh$tO/`UdAd.59! ņ`f1Y~&vx I!xh9mЂd6b `p ԥ~̉ql5R?b%6 8 SzWܪX:9ɠO޾|Kİ`>j^v(y~R=7'Jӛ!)Tr&jO&ט"hUpE1M/,Է(7ꛦq&nkq2Yౕl3| ܿi `E5xh6Xg8L#T&^ޡ#Ɓ7g%Cy,"AMDh줠X?PdWmjSVc^`rk'VhS8- tgqu)?, S C}XUe!$Mȑ,o[;M x{\Kqܱ (@Ӊw8Z(?F`鴐AhZgE>Yqgw 9>k ._Fwx:҄(] mIMW_FDӘ4mb#.w;@ #ڈ'WE@ MP ynNl-5!ޮa