samba-3.4.2-1.1.3.1>t  DH`pJ縋/=„Iؿdً߃ #jhWcyy#mwV"#D'1 tH` rUx{LnWR#c钃ʨug-'* _V,ψ&~.lm`gDGy+CщocD$igGD5iP}^hv_:g-ZhM)QAVO;DžZKjB="vamd>DZҚosO14d26a16eed57c140b402762cba9894adce92781[J縋/=„R tL Կ>$ֱ  C"*9  5L,'^a6ӐWGI湤|O˩rVzr+'!dUԓqِNa|'P<Ӏ{}E-Ŷ۲-}IY'/nI,٘i3KssejEКoWO{9]Yw6pYkR,=ce]X]d~TJ[ uBi'.=%΍W&L>>$?d  H ,29q      <  !$u$&) :*:/:(/8/E95E:JTE=?@!F)G<HlIX(Y\]^5!bcudeflz  Csamba3.4.21.1.3.1A SMB/CIFS File, Print, and Authentication ServerSamba is a suite of programs that allows SMB/CIFS clients to use the Unix file space, printers, and authentication subsystem. The package named samba contains all programs that are needed to act as a server. The binaries expect the configuration file to be found in /etc/samba/smb.conf For a more detailed description of Samba, check the samba-doc package or the Samba.org Web page at http://www.Samba.org/ Please check http://en.openSUSE.org/Samba for general information on Samba as part of SUSE Linux Enterprise or openSUSE products, links to binary packages of the most current Samba version, and a bug reporting how to. Authors: -------- The Samba Team Source Timestamp: 2229 Branch : trunk Source Timestamp: 2229 Branch : trunk Source Timestamp: 2229 Branch : trunk Source Timestamp: 2229 Branch : trunkJ$build20&7openSUSE 11.2openSUSEGPL v3 or laterhttp://bugs.opensuse.orgProductivity/Networking/Sambahttp://www.samba.org/linuxx86_64/usr/sbin/groupadd -g 71 -o -r ntadmin 2>/dev/null || : test -n "$FIRST_ARG" || FIRST_ARG=$1 if test "$FIRST_ARG" = "0" ; then test -f /etc/sysconfig/services && . /etc/sysconfig/services if test "$YAST_IS_RUNNING" != "instsys" -a "$DISABLE_STOP_ON_REMOVAL" != yes ; then for service in smb nmb ; do /etc/init.d/$service stop > /dev/null done fi fi test -n "$FIRST_ARG" || FIRST_ARG=$1 if test "$FIRST_ARG" -ge 1 ; then test -f /etc/sysconfig/services && . /etc/sysconfig/services if test "$YAST_IS_RUNNING" != "instsys" -a "$DISABLE_RESTART_ON_UPDATE" != yes ; then for service in nmb smb ; do /etc/init.d/$service try-restart > /dev/null || : done fi fi sbin/insserv etc/init.d  !!{u(6D)%610p84P0?1ZI)(J()9)`99p(Y@Yp)Z9II)0Y`+t(T 'z Z`9C N 1NP6 L " (JJv;  ,m`F;쁤A큤AAA큤A큤A큤AAA큤A큤A큤AAA큤AAAAA큤A큤AAAAAAAAAAAAJtJtJuJuJtJtJuJuJuJuJuJzJ欚JjJ欥J欥JTJjJjJjJjJjJjJjJjJTJjJjJ欯J欦J欦J欦J欧J欧J欧J欧J欧J欨J欨J欭J欭J欭J欭J欭J欭J欮J欮J欮J欮J欮J欯J欯J欯J欲JtJtJ欴J欶JgJgJgJhJhJhJhJhJhJhJhJhJhJhJhJhJhJhJhJhJhJhJhJhJhJhJhJhJhJhJhJhJtJtJTJxJxJjJjJjJjJjJjJjJjJjJjJjJjJjJjJjJjJjJjJjJjJjJjJjJjJjJjJjJjJjJjJjJjJjJjJjJTJTJTJTJTJTJTJTJTJTa3b330ca5ab736c731516a38f7d07e33a24b810bd2445f214b41de7473b7dc9757667c1370225a2868393c810c3f7e0867846acdac1a847c961931257ee2200588ab95ed4a0d4bff4b186392ec5e41f2858741c17da5a9887e95524f6feee48bc6d22b378680ba5e789f556dc133ed909fc9132927cc853adfb0160c4ed4acf06473db4d2f60cc2cc9cd00bd7f505d15e681e8658ad978e4be84923e0eaf8d8c3b7a4f0363264a534674421a2af8678aabafae85d3ecb4f2e90fcbfee32027e2ae625e0977b07e3120fa76ac3c2aeabec920117f8265cd2568787a27c432fc4dcad06404016dab9adfb957d3ad22701d8e8da5f3d85dac8e8999502e1d54d14a0cc7c921f0405be05f95afa116a93627e4d41ad7d59603fe4ed87c94e08849900f1aeaad42a7975744bb373ac56b60bb55130c04cddb28ae98d4979f04b46b142c604776df7692c9c19e68a5fa92bd1a1f6cc4180328c311c426d729ddfe14f8ef986d951387c47068d3a46986e2c61146ccacda515e480f6a5355c835b249d060f765e4805fe4bade44b77bc4cf75374d2ff0e94de669b650c493f730d0e6fb8127ab34d2515fbb91c31e5f332f95315a8aa63691ae6018f88ab0ac0610e86f59f23fc26f7a3c1d2386db9b975d3121629ff83c5b2491df705964caf01398beb5d6765c2d40eb07f02f18c42a93574c7f8bbdb8f99b67877abb1c10231b5f0c94b38b52855b98b883c0b14446338c8cfd00bf22580d813f8803efd6079e4e01eb8c7a7eefa0c0ac4a55b41cda9bb0ec500a2b3bef32e6fff4c3b2df2a3406a9232cf53a3010e1151ab4031c81a8df11455dfb379498c160e12fac2f09501e9dace49d391b0fd32a54b3ebb761b60f61ac4e256b12aa4a51720c09c54f93e04e8951373c90a126b3b059db6c6d0a134188ff9a7a81a29c924b2ecc9cd8927743b1070aea8511f5fa4a4bfd915aa1c46a108e86f5664323aab5b10beda48d637bd5b9e4166e728191799c3bfeaa322a878284932724a69008f1c8014c59667f7031ae047d7962ce02fb1568049cc07481198832de989eaa746876748101c74e9509d674a8226b33b712b2a9e232f9f5150a8eb6cdcff3d2b89db402aa30b85a16a4fe80e26bf254a372d6530dbfeeb1d3579d177a7b9eadf5ca84bc33db9d5c3665399ee6db453bc2214d9137754bd31d83d022ceaf03e570e187523a776090dc43d9978fba4a5946805282c69d8fc0e639608160f0dc527339622b2ff964d3a4be090050fc22ed1f485366ed4bb96ba809baccd8c8d59d525bb04237acdcf26f43a40c5a7330984a1210292b6eec18fa9b282fb7b2e24fe3a1bd6eded7d70872c8584489ec974e6db30ae5b7f6123822339ff29d552fcffdda0523386530ff473491905ce8cc13dcdd17b9399ca3ff1d5db2d39cfaa802ab9ba155da29f7353d6b86ab87853762f6367607715312d8f33443e54e29ece597e22f0f94ed44108f773ea2ae22ddd8a2be9be9a4782609280c0877fc0460a5422f9405ed810452120a9061883c5169a747e94542fde1d945da7604f1e0a6daf845146ecbc7ebf8d31eb6a421161f18703b049fb29cc4dffa4dd6d7fbe92b8bdd8f5fa13b64fb0af142d88b7f2be3c363428f73e566bd6316a2b0885cd6d556fd1538d4a0f857efe202c34422b6db33f0800b79384bd6fe4bf94895c4da0cb58292fa214f46d19402e6fe2fc3e3cae1da1f0a75a92328ce90c3555a100ee3aec38111e3860041579c4cd5ca6e3427d01eb248c878893dd39741bd225e521075357ecb15ae4f38c086714c388cd2618aae034a7748347ed791e885ae8dedf2af1b3548697376856647c493e6a6e0f6df7aa08edc395b9742ced293f1d7f745a105b3ae7c5cfc914666cd58e18d89621a5015fb95247412fb95f31a9da20120b6fd52a9d7edf1172fcc799346e0ed9caed4d4281719369f0bf1c505a08e4751c0426d9f3410524976efc9deab68261ad16639f86588588f47a8928b643b94d76a0fa02f3644cc81999aaadaf1f81e16a341b9725d93ac5ba54662c2497f97f60dc8784689a63d82f6552875261acd08b035a57b9a8766b0608cadbd9d00864adddbcaffae9c0ab080d8c229937a144e2a74f5b41ec7f079bd86594424bb410f36669545df4e85161127ceea92de6ae17baf6c6eb4cea48812e0e42b8f7c2606b58412fa22bdea18244420edcc69bfd80c6ad5515e17094664c381d222ae1c20e84adc9f369620d2d3d5ce3572ceb463eff74b26a1c21e5f293f3bda2f28413b59adf0b922d240807b2f928b643b94d76a0fa02f3644cc81999a1e3c83c19aca994ace4a2f1791f7a0154579033db5543428dca6e9da8ba81f7f9d6d52181b2a6a7107bab571121da12e/etc/init.d/nmb/etc/init.d/smb@rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootntadminntadminntadminntadminntadminntadminntadminntadminrootuserssamba-3.4.2-1.1.3.1.src.rpmacl_tdb.so()(64bit)acl_xattr.so()(64bit)audit.so()(64bit)cacheprime.so()(64bit)cap.so()(64bit)default_quota.so()(64bit)dirsort.so()(64bit)expand_msdfs.so()(64bit)extd_audit.so()(64bit)fake_perms.so()(64bit)fileid.so()(64bit)full_audit.so()(64bit)netatalk.so()(64bit)pam_smbpass.so()(64bit)preopen.so()(64bit)readahead.so()(64bit)readonly.so()(64bit)recycle.so()(64bit)script.so()(64bit)shadow_copy.so()(64bit)shadow_copy2.so()(64bit)smb_traffic_analyzer.so()(64bit)streams_depot.so()(64bit)streams_xattr.so()(64bit)syncops.so()(64bit)xattr_tdb.so()(64bit)sambasamba(x86-64)    @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ samba-clientcoreutilsgrep/usr/sbin/groupadd/usr/bin/getent/bin/sh/bin/sh/bin/shrpmlib(PayloadFilesHavePrefix)rpmlib(CompressedFileNames)/bin/shlibacl.so.1()(64bit)libacl.so.1(ACL_1.0)(64bit)libattr.so.1()(64bit)libattr.so.1(ATTR_1.0)(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.2)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.5)(64bit)libc.so.6(GLIBC_2.8)(64bit)libcom_err.so.2()(64bit)libcrypt.so.1()(64bit)libcrypto.so.0.9.8()(64bit)libcups.so.2()(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.2.5)(64bit)libgssapi_krb5.so.2()(64bit)libgssapi_krb5.so.2(gssapi_krb5_2_MIT)(64bit)libk5crypto.so.3()(64bit)libk5crypto.so.3(k5crypto_3_MIT)(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libm.so.6()(64bit)libnscd.so.1()(64bit)libnscd.so.1(LIBNSCD_1.0)(64bit)libnsl.so.1()(64bit)libnsl.so.1(GLIBC_2.2.5)(64bit)libpam.so.0()(64bit)libpam.so.0(LIBPAM_1.0)(64bit)libpam.so.0(LIBPAM_EXTENSION_1.0)(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libresolv.so.2()(64bit)libresolv.so.2(GLIBC_2.2.5)(64bit)libssl.so.0.9.8()(64bit)libtalloc.so.1()(64bit)libtdb.so.1()(64bit)libwbclient.so.0()(64bit)libz.so.1()(64bit)rpmlib(PayloadIsLzma)3.4.24.0-13.0.4-14.4.6-14.7.1JJJ@JH@JJ JjJ0@J@J@JJ@JJ JzJzJt.@JmJ_@J\s@JT@JT@JMJL@JI@JCfJB@JB@J@J;}J:,@J8J7@J7@J2C@J2C@J,@J'@J'@J'@J+@JMJp@IIIo@Io@IԨIW@IW@III@IV@II2I@IIIl@II@I1I@IHI~@Iy@Iy@IuId@Ia@IVISuISuIFFIBR@IBR@IAI?@I6tI6tI3I3I3I1.I.I.I.I.I-:@I+I%Q@I%Q@IsI@IP@IH@H,H,H,H@H @H @H @H @H @HHHf@H@H׈HHBHe@H|@HAHH@H@H@H@HHc@H@HnH@Hz@H4@HsVHnHkmHkmHj@Hj@Hj@Hj@Hj@HhHhHcHb3@HXHO@HNlHNlHM@HI&HG@H?@H?@H=I@H=I@H;H6H6H6H.H-w@H-w@H-w@H-w@H,%H*@H*@H)H$= 10 and libc segfaults if printf is passed NULL for a "%s" arg.- Use a conditional suse_version macro in front of the SUSE_ASNEEDED export.- lookupname failed, cannot find domain when attempt to change password; (bnc#520645); (bso#6560).- Don't link with --as-needed flag on post-11.1 systems.- Stop the smbfs service if an interface goes down; (bnc#517768).- Disable build of static libraries on post-11.1 systems; (bnc#509945).- Fix missing zlibs for cifs.upcall and test_shlibs.- Update to 3.4.0. + BUG 6431: Local groups from 3.0 setups no longer found. + BUG 6459: Fix build of pam_smbpass on some distributions. + BUG 6481: 'net ads leave' needs to try account deletion, NetUnjoinDomain not. + BUG 6497: Fix calling of 'test' in configure. + BUG 6498: Add workaround for MS KB932762. + BUG 6499: Fix building of pam_smbpass. + BUG 6509: Use gid (not uid) cache in fetch_gid_from_cache(). + BUG 6512: Fix support for enumerating user forms. + BUG 6514: Improve error message in 'net' when smb.conf is not available. + BUG 6520: Fix time stamps when "unix extensions = yes". + BUG 6521: Fix building tevent_ntstatus without config.h. + BUG 6526: Fix notifies in the share root directory. + BUG 6531: Fix pid file name.- Package /etc/samba/smbpasswd as %ghost on post-11.1 systems.- Fix net ads leave; (bnc#511695).- Supplement pam-32bit/pam-64bit in baselibs.conf (bnc#354164). - Supplement glibc-32bit/glibc-64bit in baselibs.conf (bnc#354164).- Update to 3.2.13, 3.3.6. + In Samba 3.2.0 to 3.2.12 (inclusive), the smbclient commands dealing with file names treat user input as a format string to asprintf. With a maliciously crafted file name smbclient can be made to execute code triggered by the server; CVE-2009-1886; (bnc#513360); (bso#6478).- Update to 3.0.35. + In Samba 3.0.31 to 3.3.5 (inclusive), an uninitialized read of a data value can potentially affect access control when "dos filemode" is set to "yes"; CVE-2009-1888; (bnc#515479).- Uninitialized read of a data value; CVE-2009-1888 (bnc#515479).- Update to 3.4.0rc1. + BUG 4699: Remove pidfile on clean shutdown. + BUG 5456: Fix "net ads testjoin". + BUG 6081: Make it possible to change machine account sids. + BUG 6253: Use correct value for password expiry calculation in pam_winbind. + BUG 6297: Owner of sticky directory cannot delete files created by others. + BUG 6305: Correctly prompt for a password when a username was given. + BUG 6328: Add support for multiple rights to "net sam rights grant/revoke". + BUG 6333: Consolidate create/delete account paths in pdbedit. + BUG 6449: 'net rap user add' crashes without -C option. + BUG 6451: net/libnetapi user rename using wrong access bits. + BUG 6458: Fix uninitialized variable in local_password_change(). + BUG 6465: Fix enumeration of empty aliases. + BUG 6476: Fix smbd-zombies in memory when using [x]inetd. + BUG 6487: Add missing DFS call in trans2 mkdir call. + BUG 6488: acl_group_override() call in posix acls references an uninitialized variable. + Improve pam_winbind documentation. - Install a vendor copy of samba-common.dhcp as dhcpcd-hook-samba-functions.- Samba 3.2.0 - 3.2.12 smbclient commands dealing with file names treat user input as a format string to asprintf; CVE-2009-1886; (bnc#513360).- Fix a bad memleak in vfs_full_audit; (bnc#510035).- Update to 3.3.5. + Fix SAMR and LSA checks (bug #6089, #6289) + Fix posix acls when setting an ACL without explicit ACE for the owner (bug #2346). + Fix joining of Win7 into Samba domain (bug #6099). + Fix joining of Win2000 SP4 clients (bug #6301). + BUG 2346: Fix posix acls when setting an ACL without explicit ACE for the owner. + BUG 5832: Fix build on RHEL when ccache is not available. + BUG 5853: Add keyutils-devel to build requires to fix build on RHEL. + BUG 5897: Fix shutdown script example in the smb.conf manpage. + BUG 6089: Revert the extra SAMR and LSA checks. + BUG 6099: Fix joining of Win7 into Samba domain. + BUG 6157: Fix handling of multi-value attribute "uid". + BUG 6289: Revert the extra SAMR and LSA checks. + BUG 6297: Owner of sticky directory cannot delete files created by others. + BUG 6301: Fix joining of Win2000 SP4 clients. + BUG 6309: Support remote unjoining of Windows 2003 or greater. + BUG 6315: smbd crashes doing vfs_full_audit on IPC$ close event. + BUG 6320: Handle registry config source in file_list. + BUG 6330: Fix DFS on AIX. + BUG 6336: Fix 'net groupmap set' segfault. + BUG 6361: Make --rcfile work in smbget. + BUG 6365: Re-Add the "dropbox" functionality with -wx rights on a directory. + BUG 6372: Fix usermanager only displaying 1024 groups and aliases. + BUG 6382: Fix case insensitive access to DFS links. + BUG 6415: Filter out of range mappings in default idmap config in idmap_tdb. + BUG 6416: Filter out of range mappings in default idmap config in idmap_tdb2. + BUG 6417: Filter out of range mappings in default idmap config in idmap_ldap. + BUG 6441: Fix the compile with --enable-dnssd. + BUG 6449: 'net rap user add' crashes without -C option. + BUG 6465: Fix enumeration of empty aliases (ldb backend). + Prevent infinite include nesting. + Mark registry shares without path unavailable. + Also handle DirX return codes. + Fix Coverity ID 897. + Do not crash in ctdbd_traverse if ctdbd is not around. + Fix a race condition in winbind leading to a panic. + Some man pam_winbind improvements. + Zero an uninitialized array.- Update to 3.2.12. + Fix SAMR and LSA checks (bug #6089, #6289) + Fix posix acls when setting an ACL without explicit ACE for the owner (bug #2346). + Fix "force user" (bug #6291). + Fix Winbind crash (bug #6279). + Fix joining of Win7 into Samba domain (bug #6099). + BUG 2346: Fix posix acls when setting an ACL without explicit ACE for the owner. + BUG 5798: CFLAGS info lost in configure. + BUG 5832: Fix build on RHEL when ccache is not available. + BUG 5835: Add keyutils-devel to build requires. + BUG 5945: Fix out of memory error with Winbind idmap. + BUG 6089: Revert the extra SAMR and LSA checks. + BUG 6099: Fix joining of Win7 into Samba domain. + BUG 6279: Fix Winbind crash. + BUG 6289: Revert the extra SAMR and LSA checks. + BUG 6291: Fix "force user". + BUG 6301: Fix samr_ConnectVersion enum which is 32bit not 16bit. + BUG 6372: Fix usermanager only displaying 1024 groups and aliases. + BUG 6386: Groupdb mapping fix. + BUG 6382: Fix case insensitive access to DFS links. + BUG 6465: Fix enumeration of empty aliases (ldb backend). + Prevent creation of keys containing the '/' character. + Fix bug in processing of open modes in POSIX open. + Protect netlogon_creds_server_step() against NULL creds. + Also handle DirX return codes. + Fix a race condition in winbind leading to a panic. + Fix a crash bug if we timeout in net rpc trustdom list. + Fix profile acls in some corner cases.- Default with passdb backend to smbpasswd for SUSE products older than 11.2.- Explicitly use 'tdbsam' as passdb backend in the default smb.conf file.- Update to 3.4.0pre2. + The default passdb backend has been changed to 'tdbsam'! + Samba4 and Samba3 sources are included in the tarball. + Changed the way smbd handles untrusted domain names given during user authentication. + Various fixes including printer change notificiation for Samba spoolss print servers. + The remaining hand-marshalled DCE/RPC services (ntsvcs, svcctl, eventlog and spoolss) were replaced by autogenerated code based on PIDL. + Samba3 and Samba4 do now share a common tevent library. + The code has been cleaned up and the major basic interfaces are shared with Samba4 now. + An asynchronous API has been added. + Made parameter syntax of the net command more consistent. + BUG 2346: Fix posix ACLs when setting an ACL without explicit ACE for the owner. + BUG 4271: testparm should not print includes. + BUG 4831: Don't call openlog() or closelog() from pam_smbpass. + BUG 5681: Do not limit the number of network interfaces. + BUG 5859: Fix renaming of samr objects failed due to samr setuserinfo access checks. + BUG 6099: Fix NETLOGON credential chain. + BUG 6136: New AFS syscall conventions. + BUG 6157: Fix handling of multi-value attribute "uid". + BUG 6253: Use correct value for password expiry calculation. + BUG 6291: Fix 'force user'. + BUG 6292: Update config.guess from gnu.org. + BUG 6302: Give the VFS a chance to read from 0-byte files. + BUG 6309: Support remote unjoining of Windows 2003 or greater. + BUG 6313: ldapsam_update_sam_account() crashes while doing talloc_free on malloced memory. + BUG 6315: Fix smbd crashes when doing vfs_full_audit on IPC$ close event. + BUG 6320: Handle registry config source in file_list. + BUG 6330: Fix DFS on AIX. + BUG 6336: Fix segfault in 'net groupmap set'. + BUG 6340: Don't segfault when cleartext trustdom pwd could not be retrieved. + BUG 6357: Use Samba default command line arguments in 'net'. + BUG 6359: smbclient -L does not list workgroup for hosts with both IPv4 and IPv6 addresses + BUG 6361: Make --rcfile work in smbget. + BUG 6371: Unsuccessful 'net conf setparm' leaves empty share. + BUG 6372: usermanager only displaying 1024 groups and aliases. + BUG 6387: Fix a crash bug in idmap_ldap_unixids_to_sids. + BUG 6415: Filter out of range mappings in default idmap config (idmap_tdb). + BUG 6416: Filter out of range mappings in default idmap config (idmap_tdb2). + BUG 6417: Filter out of range mappings in default idmap config (idmap_ldap). + Change the way smbd handles untrusted domain names given during user authentication. + Replace the hand-marshalled DCE/RPC services ntsvcs, svcctl, eventlog and spoolss by autogenerated code based on PIDL. + Fix several printing issues and improve support for printer change notificiations. + Add 'net eventlog'. + Add asynchronous API. + Make Samba3 and Samba4 share a tevent library. + Add two new parameters to control how we verify kerberos tickets. + Add 'net rpc service' subcommands 'create' and 'delete'. + Fix the core of the SAMR access functions. + Fix SAMR server for winbindd access. + Add dbwrap_tool - a tdb tool that is CTDB-aware. + Hide "config backend" from swat. + Fix linking with --disable-shared-libs. + Fix issue with missing entries when enumerating directories. + Map NULL domains to our global sam name. + Fix driver upload for Xerox 4110 PS printer driver. + Add "net dom renamecomputer" to rename machines in a domain. + Inspect the correct computername string before enabling/disabling the change button in netdomjoin-gui. + Fix join prompt dialog test in netdomjoin-gui. + Only gray out labels when not root and not connecting to remote machines (netdomjoin-gui). + Allow to switch between workgroups/domains with the same name (netdomjoin-gui). + Add NetShutdownInit and NetShutdownAbort. + Fix samr access checks. + Add a security model to LSA. + Also handle DirX return codes. + Do not crash in ctdbd_traverse if ctdbd is not around. + Fix Coverity ID 897. + Fix a race condition in vfs_aio_fork with gpfs share modes. + Fix bug disclosed by lock8 torture test. + Fix a race condition in winbind leading to a panic. + Detect tight loop in tdb_find(). + Fix chained sesssetupAndX/tconn messages. + Fix strict locking with chained reads. + Fix two bugs in sendfile. + Fix memory leak. + Fix file descriptor leak. + Fallback to the legacy sid_to_(uid|gid) instead of returning NULL. + Always allocate memory in dptr_ReadDirName. + Fix 'net' crash during domain join. + Zero an uninitialized array. + Allow child processes to exit gracefully if we are out of fds.- Enable cifs.upcall on versions newer than SUSE 10.0.- Add BuildRequires to keyutils-devel.- Remove redundant Requires to keyutils-libs for cifs-mount.- Detect tight loop in tdb_find(); (bnc#450974).- Fix lp printing with kerberos; (bnc#476913).- Add BuildRequires to ctdb-devel for systems newer than SUSE 10.0 and all other build targets.- Update to 3.4.0pre1. + Samba4 and Samba3 sources are included in the tarball + Changed the way smbd handles untrusted domain names given during user authentication. + Various fixes including printer change notificiation for Samba spoolss print servers. + The remaining hand-marshalled DCE/RPC services (ntsvcs, svcctl, eventlog and spoolss) were replaced by autogenerated code based on PIDL. + Samba3 and Samba4 do now share a common tevent library. + The code has been cleaned up and the major basic interfaces are shared with Samba4 now. + An asynchronous API has been added. + Change the way smbd handles untrusted domain names given during user authentication. + Replace the hand-marshalled DCE/RPC services ntsvcs, svcctl, eventlog and spoolss by autogenerated code based on PIDL. + Fix several printing issues and improve support for printer change notificiations. + Add 'net eventlog'. + Add asynchronous API. + Make Samba3 and Samba4 share a tevent library. + Add two new parameters to control how we verify kerberos tickets. + Add 'net rpc service' subcommands 'create' and 'delete'. + Make merged build possible. + Move common libraries to the shared lib/ directory.- Update to 3.3.4. + Fix domain logins for WinXP clients pre SP3 (bug #6263). + Fix samr_OpenDomain access checks (bug #6089). + Fix usrmgr.exe creating a user (bug #6243). + BUG 6089: Fix samr_OpenDomain access checks. + BUG 6254: Fix IPv6 PUT/GET errors to an SMB server (3.3) with "msdfs root" set to "yes". + BUG 6279: Fix Winbind crash. + BUG 5329: Add "net rpc service delete/create". + BUG 6238: Make sure wbcLogoffUserParams are properly initialized before freed. + BUG 6263: Fix domain logins for WinXP clients pre SP3. + BUG 6286: Call init function for builtin idmap modules before probing for them as shared modules. + BUG 6243: Fix usrmgr.exe creating a user. + net conf: Save share name as given, not as lower case only. + Prevent creation of registry keys containing the '/' character. + Allow pdbedit to change a user rid/sid. + When doing a cli_ulogoff don't invalidate the cnum, invalidate the vuid. + Don't access a freed structure when logging off and re-using a vuid. + Try to to fix password_expired flag handling. + Make sure to grey out change fields in the netdomjoin-gui when not running as root. + Don't look up local user for remote changes, even when root. + Use procid_str in debug messages for better cluster-debuggability. + Use cluster-aware procid_is_me instead of comparing pids. + Fix smbd crash for close_on_completion. + Fix a memleak in an unlikely error path in change_notify_create(). + Do not use the file system GET_REAL_FILENAME for mangled names. + Fix a crash bug if we timeout in net rpc trustdom list. + Add '--request-timeout' option to net. + In net_conf_import, start a transaction when importing a single share. + Fix writing of roaming profiles with "profile acls" set to "yes".- Update to 3.2.11. + Fix domain logins for WinXP clients pre SP3 (bug #6263). + Fix samr_OpenDomain access checks (bug #6089). + Fix smbd crash for close_on_completion. + BUG 6089: Fix samr_OpenDomain access checks. + BUG 6205: Correct sample smb.conf share configuration. + BUG 6254: Fix IPv6 PUT/GET errors to an SMB server (3.3) with "msdfs root" set to "yes". + BUG 6263: Fix domain logins for WinXP clients pre SP3. + Allow pdbedit to change a user rid/sid. + When doing a cli_ulogoff don't invalidate the cnum, invalidate the vuid. + Fix resume command typo for "printing = vlp". + Fix smbd crash for close_on_completion. + Fix a memleak in an unlikely error path in change_notify_create(). + Don't look up local user for remote changes, even when root.- Don't lookup local user for remote password changes; (bnc#493507).- Update to 3.3.3. + Migrating from 3.0.x to 3.3.x can fail to update passdb.tdb correctly (bug #6195). + Fix serving of files with colons to CIFS/VFS client (bug #6196). + Fix "map readonly" (bug #6186). + BUG 6195: Don't let smbd child processes panic. + Add backend_requires_messaging() method to libsmbconf. + Add methods is_writeable() and wrapper smbconf_is_writeable() to libsmbconf. + Fall back to file backend when no valid backend was found. + Fix a memleak in dbwrap_rbt. + Provide transaction_start|commit|cancel fns for the registry tdb. + Speed up "net conf drop". + Speed up "net conf import". + Add transactions to the libsmbconf API. + Reduce memory usage of "net conf import". + Registry cleanup. + Fix handling of SAMBA_VERSION_VENDOR_PATCH. + Fix build of pam_winbind.so with static linking. + Tidy up some convert_string_internal error cases. + BUG 6224: nmbd waits 5 minutes at startup before checking if it needs to run elections. + Allow DFS client paths to work when POSIX pathnames have been selected. + Try and fix the build farm RAW-STREAMS errors. + Ensure files starting with multiple dots are hidden. + BUG 6102: NetQueryDisplayInformation could return wrong information. + BUG 6193: Avoid messing with sync_context in libnet_samsync_delta(). + Fix notify_printer_status_byname. + Fix Coverity IDs 722, 762, 774, 775, 776. + Fix build on old Heimdal based systems. + Fix compile warning. + Use parentheses in if condition to make negation clear. + Add dirsort module. + BUG 6147: Fix detection of the GNU ld version. + BUG 6097: Fix smbd segfault. + BUG 6130: Don't crash in winbindd_rpc lookup_groupmem() on unmapped members. + BUG 6139: Add missing whitespace in mount.cifs error message. + Fix a malloc/talloc mismatch when cli_initialise() fails. + Fix a valgrind error. + Speed up "net conf list". + Add sorted subkey cache. + Use StrCaseCmp in the dirsort module. + Document the dirsort module. + Disable dns_sd by default. + Add avahi detection to configure. + Add event avahi binding. + Use avahi to register _smb._tcp in smbd. + Fix two memleaks in the encryption code. + Fix a scary "fill_share_mode_lock failed" message. + BUG 6228: Fix SMBC_open_ctx failure due to path resolve failure doesn't set errno. + Don't use reserved words in smbconftort. + Fix smb signing for fragmented trans/trans2/nttrans requests. + Parse_packet can return NULL which is then dereferenced in match_mailslot_name. + Format the header check for netinet/ip.h more nicely. + Missing break in conversion function prevents tdb password database update.- Update to 3.2.10. + BUG #6195: Don't let smbd child processes panic.- BUG 6195: Fix crash on passdb conversion.- Update to 3.2.9. + BUG 5920: The length of the memcpy was calculated wrong. + BUG 6097: Fix smbd segfault. + BUG 6098: Fix ads_find_dc() with "security = domain" when the DNS server is invalid. + BUG 6099: Samba returns incurrate capabilities list. + BUG 6100: Implement _netr_LogonGetCapabilities() with NT_STATUS_NOT_IMPLEMENTED. + BUG 6102: NetQueryDisplayInformation could return wrong information. + BUG 6130: Fix crash in winbindd_rpc lookup_groupmem() on unmapped members. + BUG 6133: Cannot delete non-ACL files on NFSv4 ACL filesystem. + BUG 6161: smbclient corrupts source path in tar mode. + BUG 6193: Avoid messing with sync_context in fetch_database_to_ldif(). + BUG 6196: Unable to serve files with colons to Linux CIFS/VFS client. + BUG 6224: nmbd waits 5 minutes before checking to run elections. + BUG 6228: Fix SMBC_open_ctx failure when path failure doesn't set errno. + Numerous Coverity fixes + Fix double free caused by incorrect talloc_steal usage. + Backport delete semantics of alternate data streams on a file truncate. + Allow set attributes on a stream fnum to redirect to the base filename. + Fix use of streams modules with CIFSFS client. + Fix more POSIX path lstat calls. + Allow DFS client paths to work with POSIX pathnames. + Ensure files starting with multiple dots are hidden. + Fix guest auth when Winbind is running. + Fix memleak in get_remote_printer_publishing_data(). + cifs mount fix for handling -V parameter. + Fix guest mounts. + Clean-up entries in /etc/mtab after unmount. + Add fakemount (-f) and nomtab (-n) flags to mount.cifs. + Enable total anonymization in vfs_smb_traffic_analyzer. + Don't try and delete a default ACL from a file. + Fix remotely adding a share via MMC. + Fix resume handle for _samr_EnumDomainGroups. + Fix a buffer handling bug when adding lots of registry keys. + Fix a O(n^2) algorithm in regdb_fetch_keys(). + Fix a valgrind error / segfault in dns_register_smbd(). + Don't log NDR_PRINT_DEBUG at level 0, this always ends up in syslog. + Fix a malloc/talloc mismatch when cli_initialise() fails. + Fix two memleaks in the encryption code. + Fix "fill_share_mode_lock failed" message. + Add S-1-22-X-Y sids to the local token. + Fix smb signing for fragmented trans/trans2/nttrans requests. + Don't miss an absolute pathname as a kerberos keytab path. + Have nmbd check all available interfaces for WINS before failing. + Initialize the id_map status in idmap_ldap to avoid surprise.- Obsolete change from 2008-03-05 by removing the needless examples cleanup.- Update to 3.3.2. + Fix "force group" (bug #6155). + Fix saving of files on Samba share using MS Office 2007 (bug #6160). + Fix guest authentication in setups with "security = share" and "guest ok = yes" when Winbind is running. + Fix corruptions of source path in tar mode of smbclient (bug #6161). + BUG 6082: Fix renaming and deleting of directories using Windows clients. + BUG 6154: Make ZFS honor admin users. + BUG 6155: Fix "force group". + BUG 6160: Fix saving of files on Samba share using MS Office 2007. + BUG 6161: Fix corruptions of source path in tar mode of smbclient. + Fix some NetBSD warnings. + Fix bug in processing of open modes in POSIX open. + Fix use of streams modules with CIFSFS client. + Ensure ACL modules work with POSIX paths. + Use fsp->posix_open in preference if we have it. + Fix more POSIX path lstat calls. + Fix a bug in message handling for the change notify code. + Fix guest authentication in setups with "security = share" and "guest ok = yes" when Winbind is running. + BUG 4640: Fix guest mounts in mount.cifs. + Fix displaying the version string properly when no other parameters passed in in mount.cifs. + Prefer gssapi header files from subdirectory. + BUG 6176: winbindd -n should disable the winbind idmap cache. + Add a vfs_preopen module to hide fs latencies. + Don't log NDR_PRINT_DEBUG at level 0, this always ends up in syslog. + Fix a valgrind error / segfault in dns_register_smbd(). + Fix build on SLES8. + Decremented by 1 for ntcancel requests. + Fix creation of core files. + Fix first mapping of uids/gids in Winbind. + Initialize the id_map status in idmap_ldap to avoid surprise. + Fix initialization of idmap status.- Only call '%find_lang pam_winbind' in the samba spec file, not samba-doc.- Ignore return value from subshell to fix build.- Make libsmbclient work with DFS, backported from 3.3; (bnc#475995).- Update to 3.3.1. + Fix net ads join when "ldap ssl = start tls" (bug #6073). + Fix renaming/deleting of files using Windows clients (bug #6082). + Fix renaming/deleting a "not matching/resolving" symlink (bug #6090). + Fix remotely adding a share via the Windows MMC. + BUG 6082: Fix renaming/deleting of files using Windows clients. + BUG 6069: Fix build with too many arguments. + BUG 6090: Fix renaming/deleting a "not matching/resolving" symlink. + BUG 6099: Try to fix domain join of Win7 Beta. + BUG 6117: Fix core dump of pdbedit -a. + BUG 6133: Fix deletion of non-ACL files on Solaris/ZFS/NFSv4 ACL filesystem. + Fix Coverity IDs 115, 116, 117, 602. + Fix warning (bad handler prototype). + Unify the detection of the timespec code in configure.in, and the application of it in time.c. + Correctly use chroot(). + Parameterize in local.h the MAX_RPC_DATA_SIZE, and ensure that "offered" read from the rpc packet in spoolss is under that size. + Backport the semantics of when to delete alternate data streams on a file truncate. + Fix printf warnings. + BUG 6073: Prevent ads_connect() from using SSL unless explicitly requested. + Fix 'getent passwd' to allocate new uids. + Fix 'getent group' to allocate new gids. + Remove check for sharename being a username in 'net conf addshare'. + Fix Coverity ID 848. + Remove unused ENUM_HND from 'net'. + Fix getform command asprintf return code in rpcclient. + Fix memleak in get_remote_printer_publishing_data(). + Remove duplicate prototypes for generated rpc server functions. + Enable total anonymization in vfs_smb_traffic_analyzer. + Fix build with external dns_sd libraries. + Fix configure check "sub-second timestamps without struct timespec". + Use correct BSD evironment variable. + Don't try and delete a default ACL from a file. + BUG 5798: CFLAGS info lost in configure. + Fix Coverity IDs 740, 742, 744, 745, 876, 879, 880. + Fix remotely adding a share via the Windows MMC. + Avoid valgrind errors. + Fix 'net rpc join' for users with the SeMachineAccountPrivilege. + Fix resume handle for _samr_EnumDomainGroups. + Fix a buffer handling bug when adding lots of registry keys. + Fix a O(n^2) algorithm in regdb_fetch_keys(). + Initialize rc to 0 in main in mount.cifs. + BUG 6069: Add a fstatvfs function for libsmbclient. + Eliminate compiler warnings. + Don't miss an absolute pathname as a kerberos keytab path. + BUG 6100: Implement _netr_LogonGetCapabilities() with NT_STATUS_NOT_IMPLEMENTED. + Make Samba work with older ctdb versions. + Add S-1-22-X-Y sids to the local token. + Conditional install of the cifs.upcall man page. + Adjust regex to match variable names including underscores. + BUG 4370: Clean-up entries in /etc/mtab after unmount. + Add fakemount (-f) and nomtab (-n) flags to mount.cifs. + Fix a crash during name resolution. + Fix "assignment discards qualifiers from pointer target type" warnings. + Fix SMB_VFS_RECVFILE/SENDFILE macros. + Change "ldap ssl:ads" parameter to "ldap ssl ads". + Add manpages for vfs_acl_xattr and vfs_acl_tdb. + Fix double free caused by incorrect talloc_steal usage. + Build ldbrename. + Make nmbd check all available interfaces for WINS before failing. + Fix compilation of vfs_default on systems that do not support utimes(). + BUG 5920: Fix the calculation of the memcpy length. + BUG 6098: Fix ads_find_dc() in setups with "security = domain". + Make libsmbclient work with DFS.- Define init_samba_module in all samba-vscan modules; (bnc#469218).- Add GPLv3 header to all init scripts; (bnc#459766).- Backport of the clean event context after fork and krb5 refresh chain fixes; (bnc#415026).- Revert accidental partial strict allocate upstream commit- Update to 3.2.8. + Fix and streamline join and DC detection + BUG 4308: Excel save operation corrupts file ACLs. + BUG 5933: Fix incrementing/decrementing num_validated_vuids. + BUG 5953: Fix smbclient crashes. + BUG 5953: Make cli_send_smb_direct_writeX use writev. + BUG 5965: Fix creation of the first share using SWAT. + BUG 5969: Optimize smbclient put command. + BUG 5979: Fix level 2 oplocks. + BUG 5980: Fix race condition when granting level2 oplocks + BUG 5986: Fix renaming of streams. + BUG 5990: Strict allocate should be checked before ftruncate. + BUG 6000: Avoid bashism in perfcount.init. + BUG 6009: Setting "min receivefile size = 1" breaks writes. + BUG 6014: mget shouldn't segfault without arguments. + BUG 6016: Alternate Data Streams / Extended Attributes seem to conflict. + BUG 6017: Fix magic scripts. + BUG 6021: smbclient du command does not recuse properly. + BUG 6030: Add missing header in Status page. + BUG 6035: Fix possible race between fcntl F_SETLKW and alarm delivery. + BUG 6040: Calling Samba print server with an aliased DNS-name fails. + BUG 6058: Use 'make distclean' instead of 'make clean' in build_docs. + Fix "allow trusted domain" so it disables trusted domains. + Fix error code when smbclient puts a file over an existing directory. + Don't return 0 on error in smbcacls - bad for scripts. + Determine case sensitivity based on file system attributes. + Add vfs_fileid manpage. + Adjust regex to match variable names including underscores. + Fix stream marshalling to return the correct streaminfo status. + Fix a delete on close divergence from Windows. + Allow renames of streams via NTRENAME and fix stream error codes. + Fix a segfault if ? is there but the options are NULL. + Avoid flooding of syslog with failing pam_putenv messages. + Document default of the printing config variable. + Change default value for "ldap ssl" to "start tls". + Check if Unix account exists before asking for the password in smbpasswd. + Add manpage for vfs_shadow_copy2. + Clean event context after child is forked. + Refresh sequence number as soon as possible. + Don't set child->requests to NULL in parent after fork. + Clean event context after fork and fix krb5 refresh chain. + Fix null pointer refrence in event context. + Don't send message to any other child in child process. + Fix bug in get_dc_name_via_netlogon(), null pointer refrence.- Backport 3.2.8 fixes. + cups leaks and crashes + various winbind child handling fixes + join fixes + ACL fixes for Excel + allow usrmgr with non-root- Replace cifs.upcall Makefile patches by the upstream version.- Only add ccache to BuildRequires if it is used.- Update to 3.3.0. + The passdb tdbsam version has been raised. + Splitting of library directory into library directory and separate modules directory. + The default value of "ldap ssl" has been changed to "start tls". + Extended Cluster support. + New experimental VFS modules "vfs_acl_xattr" and "vfs_acl_tdb" to store NTFS ACLs on Samba file servers. + Simplified idmap configuration. + New idmap backends "adex" and "hash". + Added new parameter "winbind reconnect delay". + Added support for user and group aliasing. + Added support for multiple domains to idmap_ad. + The destination "all" of smbcontrol does now affect all running daemons including nmbd and winbindd. + New 'net rpc vampire keytab' and 'net rpc vampire ldif' commands. + The 'net' utility can now use kerberos for joining and authentication. + The 'wbinfo' utility can now add, modify and remove identity mapping entries. + NetApi library implements various new calls for User- and Group Account Management. + libsmbclient does now determine case sensitivity based on file system attributes.- Replace all chkconfig calls with rc_active calls to improve performance during boot.- Add SuSEfirewall2 service config file to allow samba browsing on post-10.2 systems; (bnc#460902).- Update to 3.0.34. + Fix update of machine account passwords. + Fix SMB signing issue on Windows Vista with MS Hotfix KB955302. + Fix Winbind crashes. + Correctly detect if the current dc is the closest one. + Add saf_join_store() function to memorize the dc used at join time. This avoids problems caused by replication delays shortly after domain joins. + Fix write list in setups using "security = share".- Obsolete old -XXbit packages; (bnc#437293).- Update to 3.2.7. + Samba 3.2.0 to 3.2.6 can potentially give root filesystem access to older versions of smbclient; CVE-2009-0022; (bnc#460764).- Samba 3.2.0 to 3.2.6 can potentially give root filesystem access to older versions of smbclient; CVE-2009-0022; (bnc#460764).- Fix nmbstatus dipslay when workgroup parameter is given; (bnc#459785).- Fix Mounting failure when there is white spaces in service; (bnc#460793).- Update to 3.3.0rc2. + Splitting of library directory into library directory and separate modules directory. + Extended Cluster support. + Simplified idmap configuration. + New idmap backends "adex" and "hash". + Added new parameter "winbind reconnect delay". + Added support for user and group aliasing. + Added support for multiple domains to idmap_ad. + The destination "all" of smbcontrol does now affect all running daemons including nmbd and winbindd. + New 'net rpc vampire keytab' and 'net rpc vampire ldif' commands. + The 'net' utility can now use kerberos for joining and authentication. + The 'wbinfo' utility can now add, modify and remove identity mapping entries. + NetApi library implements various new calls for User- and Group Account Management.- Fix all remaining conditional macro calls; (bnc#456469).- Add IPv6 support for mount.cifs.- Update to 3.2.6. + Fix potential segfault in vfs_tsmsm. + Don't list the domain twice when expanding internal aliases. + Fix the output of "getent group" when "winbind use default domain = yes" with "security = ads". + Add domain prefix to username in lookup_groupmem(). + Prevent negative GM/ cache entries due to broken connections. + Fix crash in sync_eventlog_params(). + Fix timeouts when calling 'getgrent'. + BUG 1254: Fix "write list" in setups using "security = share". + BUG 5080: Fix access to cups-printers with cups 1.3.4. + BUG 5737: Fix Winbind crash in an unusual failure mode. + BUG 5783: Fix FindFirst where search pattern equals the mangled filename. + BUG 5790: Fix returning of STATUS_OBJECT_NAME_NOT_FOUND on set file disposition. + BUG 5797: Fix moving of readonly files. + BUG 5814: Fix Winbind crash bug while doing "rescan_trusted_domain". + BUG 5818: Sort ACEs in smbcacl output properly and honor inheritance. + BUG 5825: Fix account locking with LDAP backend. + BUG 5826: Fix truncated filenames when accessing old servers. + BUG 5889: Fix "delete veto files = no". + BUG 5891: Fix smbd crash when viewing the eventlog exported by "eventlog list". + BUG 5900: Fix vfs_readonly. + BUG 5903: Fix vfs_streams_xattr breaking contents of files. + BUG 5904: Fix libnss_wins causing SIGABRT while servicing getaddrinfo() request. + BUG 5914: Fix build failure: redefinition of struct name_list. + BUG 5937: Fix filenames with "*" char hiding other files. + BUG 5953: Fix smbclient crashes. + Fix rename_open_files. + Restructure VFS SMB traffic analyzer VFS module. + Correctly fix smbclient to terminate on eof from server. + Unify access checks for lsa server functions. + Remove the requirement for ldap call made as root. + Cope with MAXIMUM_ALLOWED_ACCESS requests when opening handles. + Fix net rpc vampire, based on an *amazing* piece of debugging work by "Cooper S. Blake" . + Fix Coverity IDs 456, 574, 592, 606 and 607. + Fix net rpc vampire. + Use the same prerequisite for DDNS update as Windows XP. + Make "lwinet ads dns register" honor the "interfaces" parameter. + Fix extended DN parse error when AD object does not have a SID. + BUG 5888: Fix PNP_GetHwProfInfo(). + BUG 5957: Do not abort rename process on valid rename script. + BUG 5898: Fix 'net rpc shutdown'. + Fix duplicate installation of cifs.upcall. + Fix _srvsvc_NetShareAdd segfault. + Ensure consistency when reporting password complexity. + Fix _lsa_GetUserName. + Fix access check in _samr_QuerySecurity(). + _samr_DeleteUser needs to wipe out the user_handle on success. + NetGroupEnum_r needs to handle servers with no groups. + Search for gpfs functions in both libgpfs_gpl.so an libgpfs.so. + BUG 5908: Fix internal change notify on shared directory. + BUG 5135 and 5446: Prevent calling POSIX ACL vfs methods on zfs share. + BUG 5929: Fix building of vfs_prealloc with option --with-cluster-support and GPFS. + Add new VFS module to analyze SMB traffic + BUG 5928: Fix 'testparm --version'. + Have uppercase_string return success on NULL pointer in mount.cifs. + Make mount.cifs return codes match the return codes for /bin/mount. + Use lock/unlock_mtab scheme from util-linux-ng mount prog in mount.cifs. + BUG 5778: Check if strlcpy and strlcat are already defined. + BUG 5840: Fix segfault in "rpcclient lsaaddacctrights". + BUG 5860: Fix nasty error message for overlong strings in safe_strcpy. + Fix a potential NULL deref in found by the IBM Checker. + Fix an uninitialized variable found by the IBM Checker. + Fix an unlikely memleak found by the IBM Checker. + Fix some missing error handlings. + Add workaround for domain joins using a netbios name which is different from the hostname. + Fix crash bug when freeing a non-malloc'ed buffer if the client sends a non-encrypted packet with the crypto state set. + Fix trans2findfirst for the large directory optimization. + Fix checking for presence of cups-devel and correct cups-devel test for HAVE_IPRINT. + BUG 5805: Don't close stdout when calling setup_logging multiple times. + Fix setting of trust password using 'net rpc trustdom add'. + Fix several issues in vfs_streams_xattr and vfs_stream_depot. + Return an error instead of crashing when no realm is given (trigerred by "net ads info -S 127.8.7.6" (where 127.8.7.6 doesn't exist) and "disable netbios = yes"). + Fix the new vfs_smb_traffic_analyzer build for static links. + BUG 5901: Fix default for streams_depot location. + Fix several build warnings. + Delete the krb5 ccname variable from the PAM environment if set. + Fix circular dependency error with autoconf 2.6.3. + Add @CIFSUPCALL_PROGS@ to "all" target so cifs.upcall gets built at compile time rather than install time. + BUG 5906: Fix Winbind crash when calling 'getent group'. + Fix logging to syslog. + Allow SYSLOG_FACILITY to be modified with a new configure option called - -with-syslog-facility. + BUG 5909: Fix MS-DFS on Vista clients. + BUG 5944: Fix starting of nmbd with "socket address" set to "". + Fix segfault on startup with trusted domains. + Re-add "winbind:ignore domains" parameter. + Avoid freeing fsp twice when opening new_file fails (Debian #431696).- Fix the conditional macro to start smbfs by default; (bnc#456469).- Readd libsmbclient to baselibs.conf for pre 11.0 distributions.- Use %__install macro to install files with the right permissions instead of cp.- Update to 3.3.0rc1. + Splitting of library directory into library directory and separate modules directory. + Extended Cluster support. + Simplified idmap configuration. + New idmap backends "adex" and "hash". + Added new parameter "winbind reconnect delay". + Added support for user and group aliasing. + The destination "all" of smbcontrol does now affect all running daemons including nmbd and winbindd. + New 'net rpc vampire keytab' and 'net rpc vampire ldif' commands. + The 'net' utility can now use kerberos for joining and authentication. + The 'wbinfo' utility can now add, modify and remove identity mapping entries. + NetApi library implements various new calls for User- and Group Account Management. - Added German translation for pam_winbind.- Remove patch for bnc#336854, which doesn't exist in 3.2.x or higher.- Use %{NET_CFGDIR} define instead of a fixed path to the network conf.- Update to 3.2.5. + Samba 3.0.29 to 3.2.4 can potentially leak arbitrary memory contents to malicious clients; CVE-2008-4314; (bnc#446971).- Update baselibs.conf.- Fix circular dependency error with autoconf 2.6.3.- Fix the dhcp hook script and support CODE11; (bnc#442335).- Fix perl v5.10 warnings in nmbstatus; (bnc#448225).- Include the missing spec file change mentioned the previous commit.- Make cifs-mount depend on keyutils, keyutils-libs packages as they are required to support dfs and kerberos; (bnc#432494).- Fix the offset checks in the trans routines; CVE-2008-4314; (bnc#446971).- Change the runlevel description for winbindd to use "Microsoft Windows" instead of "NT"; (bnc#446154).- Directory/Filenames get truncated when 3.2.0 client acesses old server; (bnc#432471).- Add SuSEfirewall2 services config file to open Netbios and Samba ports on post-10.2 systems; (bnc#247344).- Remove unrecognized configure options.- Fix the pam_winbind build.- Delete the krb5 ccname variable from the PAM environment if set.- Move the nss_info modules to the samba-winbind package.- Activate the idmap backends "adex" and "hash".- Add version branding for CODE 11.- Restart smbfs even with the traditional network setup; (bnc#425058).- Only call the stop_on_removal, restart_on_update, or insserv_cleanup macro if available.- Only call the fillup_and_insserv or fillup_only macro if available.- Use package names instead of macros for cp, mkdir, mv, rm, and grep or instead of the full path to the binary for ln, find and xargs.- Introduce NET_CFGDIR to fit the needs for a differing location of the network configuration per vendor.- Use path macros for cp, mkdir, mv, rm, and grep.- Only use SUSE rpm macros and SuSEconfig.permissions if available.- Update to 3.3.0pre2. + BUG 5729: Explicitly allow "-valid". + BUG 5737: Fix winbindd crash in an unusual failure mode. + BUG 5751: Fix showing of ACLs on DFS in (lib)smbclient. + BUG 5762: Fix opening of mangled directory name (resulted 'is a stream name'). + BUG 5783: Fix FindFirst where search pattern == mangled filename. + BUG 5790: Fix returning of STATUS_OBJECT_NAME_NOT_FOUND on set file disposition. + BUG 5797: Fix moving of readonly files. + Fix crashes when looking up a non-existant uid. + Fix getting/setting of NT ACLs on a file. + Fix the wcache_invalidate_samlogon calls. + Clarify usage of "force create mode". + Get smbd to look (read-only) into the winbindd cache for uid/gid <--> sid mappings. + Write times code update. + Add experimental version of VFS module acl_xattr. + Fix rename_open_files. + Make SMB traffic analyzer VFS module more efficient. + Fix segfault when calling nss_get_info() with a NULL ads structure. + Add support for name aliasing in Winbind. + Add the idmap/nss-info provider from Likewise Open. + Allow an admin to define the "uid" attribute for a RFC2307 user object in AD to be the username alias. + Add new idmap backend "adex" to support RFC2307 enabled AD forests. + Add new idmap backend "hash". + Fix build warnings. + Cleanup of DC enumeration in get_dcs(). + BUG 5710: Fix changing of machine account passwords. + BUG 5784: Fix pam_winbind build issue on Solaris. + Fix invalid sid copy (hit when enumerating sibling domains) in Winbind. + Fix double installation of cifs.upcall. + Add change-user-password command to wbinfo. + Fix segfault in _srvsvc_NetShareAdd. + BUG 5736: Fix Winbind crash bug with trusted domains. + Correct the netsamlogon_clear_cached_user function. + Add new VFS module to analyze SMB traffic to record write and read operations on the Samba server. + Fix build warnings in cifs.upcall. + BUG 5707: Do proper error handling if the socket is closed. + BUG 5778: Don't define 'strlcat' and 'strlcpy' if it's already defined. + Fix Coverity IDs 587 and 589. + Increase the default positive idmap cache time to a week. + Fix calculation of useable_space for trans2 and nttrans replies. + Add mapping of generic bits when setting an NFSv4 ACL. + Some write time fixes. + Add new parameter "cups connection timeout". + Fix enumeration of nested group memberships in Winbind. This affected only setups using "security = ads". + Fix cut and paste error in quota code. + Fix display of POSIX ACLs. + Fix permissions of group_mapping.ldb (CVE-2008-3789). + Avoid a race condition in glibc between AIO and setresuid(). + Add missing become root for AIO operations. + Fix an errno handling bug that could lead to an infinite loop. + Fix logic of tsmsm_sendfile(). + Fix handling of arbitrary new PAC types. + Fix segfault on startup with trusted domains. + Fix segfault on the CTDB destructor code. + Re-add "winbind:ignore domains". + BUG 5609: Remove configure option "--with-libdir" and add "--with-modulesdir". + Extend "net rpc vampire keytab" to support differential replication and storing of kerberos keys. + Rework internal logic of registry tdb code. + Freeze autogenerated prototype headers (good bye "make proto"). + Add new "winbind reconnect delay" parameter. + Make the change to smbcontrol for "all" to mean broadcast, and "smbd" to mean the main smb daemon. + Allow an admin to define the "uid" attribute for a RFC2307 user object in AD to be the username alias. + Add "net rpc vampire keytab" and "net rpc vampire ldif". + Rework of the Winbind idmap backend.- Define PAM_AUTHTOK_RECOVERY_ERR when not available on older Linux products.- Adopt samba-vscan to build after the change to the bool type define.- Build cifs.upcall for CentOS 5, Fedora 8 and RHEL 5 and newer too.- Call mkinitrd_setup during %post and %postun for post-9.2 systems only.- Create a link to the html manpages so that they can be accesses in swat; (bnc#426182).- "Password last set" timestamp update from admin pw change; (bnc#420407).- Call mkinitrd_setup during %post and %postun for package cifs-mount; (bnc#413709).- Update to 3.3.0pre1. + Splitting of library directory into library directory and separate modules directory. + Extended Cluster support. + Simplyfied idmap configuration. + Added new parameter "winbind reconnect delay". + The destination "all" of smbcontrol does now affect all running daemons including nmbd and winbindd. + New 'net rpc vampire keytab' and 'net rpc vampire ldif' commands.- Update to 3.2.2. + BUG 5592: Fix creation and installation of shared libraries. + Fix replacement of random seed generator. + Fix a race condition in idmap_tdb2_allocate_id(). + Fix unix_convert() for "*" after changing map_nt_error_from_unix(). + Make sure to always set errno on error path in OpenDir. + BUG 5675: Fix smbspool program assuming Kerberos authentication by mistake. + BUG 5686: Fix segfaults in libsmbclient. + BUG 5692: Fix coredump in full_audit.so. + BUG 5696: Fix "force group" in setups using Winbind. + Rename cifs.spnego to cifs.upcall. + Fix segfault in cifs.upcall when it is called without any arguments. + Fix coverity ID 594 (resource leak on error path). + Fix assigning of primary group memberships when authenticating via Winbind. + BUG #5617: Fix freezing Windows Explorer on WinXP while browsing Samba shares. + Include stdlib.h to get a prototype for free(). + Solve an IBM XL C/C++ compiler error encountered in get_exit_code() auth_errors array initialization in client/smbspool.c. + Use NGROUPS_MAX instead of 32 for the max group value in rep_initgroups(). + Add add c++ guard to netapi. + Fix compile warning in cifs.upcall. + Add "dns_resolver" key type to cifs.upcall. + BUG 5688: Fix orphaned LPQ processes if socket address is invalid. + BUG 5684: Fix removal of dead records in tdb files. + Fix coverity IDs 595, 596. + Fix smb_len calculation for chained requests. + Fix output of test status. + Fix smbclient connections to older servers. + Fix a fd leak when trying to regain contact to a domain controller in Winbind. + Fix permissions on ctdb databases. + Fix passing back success when a function had in fact failed in two places. - Add --enable-static to the configure options to get the statical libraries installed by the install Makefile target. - Add --with-cifsupcall to build the cifs.upcall binary for post 10.2 systems.- Set Required- and Should-Stop in the init info part of all init scripts.- Fix libsmbclient to older servers; (bnc#402776).- Update to 3.2.1. + BUG 5594: Fix "make test" by adding and using a new testparm switch "--skip-logic-checks". + Fix creation of libaddns.a, libsmbclient.a and libsharemodes.a. + Update the section about net conf in the net(8) manpage. + Improve processing of registry shares. + Fix listing of registry shares with testparm. + Fix several build issues. + BUG 5578: Fix error from strlcat. + BUG 5613: Fix flushing of smb.conf when creating a new share using SWAT. + Ensure consistent use of pdb_get_nt_passwd instead of pdb_get_lanman_passwd. + Remove worrying warning message when safe_strcpy tries to copy a pseaudo interface name that's too long. + Canonicalize servername in the printer functions to remove leading '\\' characters. + Fix option processing in smbcacls - add POPT_COMMON_CONNECTION. + Fix bug creating files using DOS clients with mixed case files. + Fix uninitialized variable. + BUG 5616: Fix session keys also in rpccli_netr_LogonSamLogonEx wrapper. + BUG 5570: Fix bogus error message during AD domain join. + Fix trusted domain handling in Winbindd. + Fix build warning. + BUG 5202: Fix setting of ACEs for users/groups with write access in setups with 'dos filemode = yes'. + Re-activate 'acl group control' parameter and make it only apply to owning group. + Make ntimes function more like POSIX and allow NULL arg. + BUG 5512: Fix alignment problems on sparc. + BUG 5616: Fix share connections in setups with "server signing = mandatory" or SMB signing set on the client side. + Fix a race condition in Winbind leading to a crash. + Fix a segfault in base64_encode_data_blob. + Fix some uninitialized variable references via ndr_print. + Fix error message if trying to join with a non-privileged user. + Fix setups using "include = registry" without [global] settings in the registry. + Fix "net sam rights" on domain member servers. + Add documentation for the vfs streams modules. + Cleanup some duplicate code by passing the password to the wbinfo_auth* functions. + Allow SID with 0 in subauthority to be converted properly. + Set sin[6]_family instead of ss_family in in[6]_addr_to_sockaddr_storage. + Fix realpath() check so that it doesn't generate a core() when it fails. + Fix overwriting of winbind logfiles. + Fix "vfs_full_audit.c: name table not in sync with vfs.h" panic. + Add broadcasting of the debug message to all winbindd children. + BUG 5635: Fix updating of printer queues. + Release still reachable memory if the smbclient context is freed. + Remove trailing withespace from wbinfo -m which breaks gdm auth. + BUG 5540: Fix "set primary group script" user option substitution. + Fix regression in Winbindd offline mode. + Allow authentication and memory credential refresh after password change from gdm/xdm. + Allow %u parameters for print job username.- Fix a race condition in winbind leading to a crash; (bnc#406623).- Use the configure option to enable debugging. This fixes the creation of the debuginfo and debugsource package.- Fix emptying the printing queue; (bnc#411493).- Remove trailing withespace from wbinfo -m which breaks gdm auth.- Add a recommendation to the samba and samba-winbind package to install logrotate for openSUSE 11.0 and later.- Include mkinitrd scriptlets.- Allow %u parameters for print job username - use advanced sub; (bnc#374389).- Update to 3.0.31. + BUG 5504: Fix SIGTERM handling in Winbind children so that they do not remove the unix domain socket used to field client requests. + Split the winbindd_passdb backend into a 'builtin' and a 'sam' backend. + When allocating client buffers for large read/write - make sure we take account of the large read/write SMB headers as well as the buffer space. + Memory leak fixes in DC location code. + BUG 5533: Winbindd fails to cope correctly with a workgroup name containing a '.' + BUG 5555: Don't return NT_STATUS_PASSWORD_MUST_CHANGE error on machine account logon. + BUG 5551: smbd recursing back into winbindd from a winbindd call. + Fix usage message for "net rpc trustdom add". + Ensure consistent use of pdb_get_nt_passwd instead of pdb_get_lanman_passwd. + BUG 5578: Bad (non-Samba) use of strlcat gives error. + Canonicalize servername in the printer functions to remove leading '\\' characters. + Documentation build fixes. + [DOCS] Fix use of smbconfoption in samba.entities. + Return NULL in sitename_fetch() if gencache_init() fails. + Use machine account and machine password from our domain when contacting trusted domains. + SPNEGO SPN fix when contacting trusted domains. + BUG 5285: Fix libcap header mismatch. + Fix joining NT4 domains. + Don't let winbind getgroups crash when we have no gids in the token. + Fallback to level 24 pwd set while joining. + Fix joining w2k domains in "security = ads". + Fix pam_sm_chauthtok for storing modified cached creds. + BUG 5202: Re-activate "acl group control" parameter and make it only apply to owning group. + BUG 5531: Fix conversion of ns units when converting from nttime to timespec. + BUG 4974: Map NT_STATUS_OBJECT_PATH_NOT_FOUND to ENOENT in libsmbclient. + Fix a segfault in base64_encode_data_blob. + AIX build fixes. + ENODATA is not defined in freeBSD 4.6.2. + Don't reset password last set time just because the expired flag is set to 0. + Fix usage message for 'net idmap dump'. + Miscellaneous man page fixes. + BUG 4203: Samba3-HOWTO: Add improvements/fixes submitted by Pete Boyd. + Fixes to man pages. + Add tdb file documentation. + Ensure that winbindd trusted domain children keep primary domain online status up to date. + Update cached creds during password change. + Ensure that Winbind always uses set_domain_offline() to mark a domain offline. + Allow authentication and memory credential refresh after password change from gdm/xdm. + Memory leak fixes.- Allow authentication and memory credential refresh after password change from gdm/xdm; [bnc#395578].- Add SMB_VFS_OP_RECVFILE to vfs_op_names to get it in sync with vfs.h.- Call the libsmbclient testsuite from the %check instead of the %build script.- Use machine account and machine password from our domain when contacting trusted domains; [bnc#404667].- Add a %check section move the test of the PAM modules to this section and add more tests.- Add a recommendation to the samba and samba-winbind package to install cron for openSUSE 11.0 and later.- Use a variable for syslog and add missing $remote_fs dependency for Require-Start in the init information of the init scripts.- Update to 3.2.0. + Support for establishing interdomain trust relationships with Windows 2008. + All changes from the pre and rc releases as noted in here earlier.- Move header files from the devel sub package to lib*-devel.- Work around bad use of autoconf interna.- Build Samba with debug symbols to get working debuginfo packages.- Add /etc/openldap to the file list and not only the schema directory.- Improve samba-winbindd and dhcpcd-hook-samba interface scripts for faster booting; [fate#304967], [fate#304965].- Move sysconfig variable DHCLIENT_MODIFY_SMB_CONF from Other to 'Network/DHCP/DHCP client'; [bnc#400467].- pam_winbind: Update cached creds during password change; [bnc#395578].- Update to 3.2.0rc2. + BUG 5504: Fix behaviour of winbindd children receiving a SIGTERM. + BUG 5489: Split the winbindd_passdb backend into a 'builtin' and a 'sam'. + Make sure we take account of the large read/write SMB headers as well as the buffer space when allocating cli buffers for large read/write. + Fix tag as a goto target we were not reinitializing the array counts. + BUG 5451: Fix for using the correct machine domain when looking up trust credentials in our tdb. + Fix spnego SPN when contacting trusted domains. + BUG 5285: Fix libcap header mismatch. + Fix pam_sm_chauthtok for storing modified cached creds. + Fix joining issue in setups with "config backend = registry". + BUG 4544: Add new parameter 'ldap connection timeout' to prevent waiting for TCP connection timeouts if no LDAP server is available. + BUG 5502: Fix security=server. + Fix coverity IDs 552, 553, 570, 571, 572. + Shrink ldbtools. + Fix reset of password last set time just because the expired flag is set to 0. + Remove support for symbol versioning in shared libraries. + Fix autogen for autoconf 2.62. + BUG 5515: Fix empty input fields in SWAT. + BUG 5516: Fix saving of the config file in SWAT. + Fix winbindd trusted domain child not keeping primary domain online status up to date.- pam_winbind: fix pam_sm_chauthtok for storing modified cached creds; [bnc#395578].- Don't reset "password last set time" when unlocking an autolocked account; [bnc#382111].- Fix winbind sigterm handling and make init script send sighup to all child winbind processes; [bnc#382027].- Fix bug with winbindd trusted domain child not keeping primary domain online status up to date, merge to trunk from reversion 1801; [bnc#373560].- Make winbind children reopen logs on SIGHUP; [bnc#382027].- Set only CONFIGDIR and LIBDIR while make everything and install. No longer set CONFIGFILE, DRIVERFILE, LMHOSTSFILE, and SMB_PASSWD_FILE; [bnc#395877].- Update to 3.0.30. + Fix for CVE-2008-1105. + Remove man pages for ldb tools not included in Samba 3.0.- Fix vulnerability that allows for the execution of arbitrary code in smbd; CVE-2008-1105; SA30228; [#391168].- Follow the rename of libtdb0 in baselibs.conf.- Rename sub package libtdb0 to libtdb1.- Update to 3.2.0rc1. + Move the posix pending close functionality down into the VFS layer. + Fix activation of registry globals in loadparm. + BUG 5452: Fix smbclient put. + BUG 5434: Ensure the loaded password doesn't contain the '\n' at the end. + BUG 5456: Fix missing echo if we ^C at the prompt. + BUG 5464: Fix timeout in winbindd. + Fix returning a directory value for a QPATHINFO on a msdfs link with a non-dfs path. + Use more error-prone form of testing dm_destroy_session() return code. + BUG 5453: Fix winbindd and smbd crash when dsgetdcname is used. + BUG 5465: Fix joining with createcomputer=ou1/ou2/ou3. + BUG 5461: Fix issue with Citrix on Samba DCs with more than 900 groups. + Fix wins null pointer crash in nss_wins module. + Fix lm session key length in _netr_LogonSamLogon. + Add -f switch for DsGetDCName() example and be more verbose on output. + BUG 5429: Clarify log msgs re: failure to create BUILTIN\{Administrators,Users} + Fix the DNS Update option of "net ads join". + BUG 5184: Add Missing HAVE_UPDWTMPX check before using updwtmpx(). + Recognize and allow longer UA keys in winbindd_cache. + BUG 5436: Fix signing problem in the client with transs requests. + Fix a valgrind bug in the new [ug]id2sid cache. + Fix Coverity IDs 565 and 222. + Fix dfs_Enum: In form_junctions, correctly check for malloc failure. + Add support for symbol versioning in shared libraries (can be disabled with - -disable-sysmbol-versioning). + Add new function wbcLibraryDetails() to libwbclient. + Cleanup size_t return values in convert_string_allocate. + Fix Kerberos support for CUPS 1.3 in smbspool. + Fix printing with Vista. + Fix deletion of files when they're in use by other drivers.- Update to 3.0.29. + Fix a crash in tdb_wrap_log(). + BUG 5267: Fix for nmbd termination problems when no interfaces found. + BUG 5326: OS/2 servers give strange "high word" replies for print jobs. + Remove MS-DFS check that required the target host be ourself. + BUG 5372: Fix high CPU usage of cupsd on large print servers by using more efficient CUPS queries in smbd. + BUG 5095: Fix the enforcement of the "Manage Documents" access right. + BUG 5460: Fix MS-DFS referral problem in server code. + Fix bug in Winbind that caused the parent to ignore dead children. + BUG 4235: Improve compliance to the Squid helper protocol. Original patch from Pawel Worach . + Prevent cycle in Wibind's list of children when reaping dead processes. + BUG 5419: Fix memory leak in ads_do_search_all_args() (merge from v3-2). + Fix winbind NETLOGON credential chain on a samba dc for w2k8 trusts. + Fix client connections and negotiation with Windows 2008 DCs in member server code. + Add NT_STATUS_DOWNGRADE_DETECTED error code (merge from v3-2). + BUG 5430: Fix pam_winbind.so on Solaris (requires -lsocket). + Re-add samr getdispinfoindex parsing which got lost in the glue commit. + BUG 5461: Implement a very basic _samr_GetDisplayEnumerationIndex(). Corrects interop problem between Citrix PM and a Samba DC. + BUG 3840: Fix smbclient connecting to NetApp filers when using whitespace in the user's password. + BUG 4901: Fix behavior of "ldap passwd sync = only". + BUG 5317: Fix debug output from domain_client_validate(). + BUG 5338: Fix format string bug in rpcclient. + Ensure that "wbinfo -a trusted\\user%password" works correctly on a Samba DC with trusts. + BUG 5336: Fix SetUsetrInfo(level 25) to update the pwdLastSet attribute. + BUG 5350: Fallback to anonymous sessions if not trust password could be obtained on Samba DCs and member servers. + Fix signing problem in the client with trans requests. + Enable winbind child processes to do something with signals, in particular closing and reopening logs on SIGHUP. + Add implementation of machine-authenticated connection to netlogon pipe used when connecting to win2k and newer domain controllers. + Fix trusted users on a DC that uses the old idmap syntax. + Only have Winbind cache domain password policies that were successfully retrieved. + Fix alignment bug when marshalling printer data replies. + Fix DeleteDriverDriverEx() checks to prevent removing in use files.- Expand baselibs.conf to match pre SUSE 11.0 products.- Remove obsoletes and provides 3 for all packages and systems.- Cleanup the use of the suse_version macro to achieve consistent defaults.- Set CODEPAGEDIR while make to fit the install location.- Prevent errors during the cache validation when ua keys reach a size larger than 1024; [bnc#372558].- Package man page files independent of the used compression method (gz,lzma).- Rewrite spec file to build packages for Fedora, Redhat, CentOS, and Mandriva in the OBS too.- Add a script to restart smbfs if NetworkMangaer gets an IP address; [bnc#373075].- Remove all references to the obsoleted samba-pdb package.- Compose the BuildRequires in a more flexible way to fit the openSUSE build service (OBS) requirements to support different operating system targets.- Use _libdir macro instead of a local define of LIBDIR.- Remove PreReq /sbin/ldconfig from the libtdb-devel package.- Install the shared libraries with the same name as used as soname.- Update to 3.2.0pre3. + Use of IDL generated parsing layer for several DCE/RPC interfaces. + Removal of the 1024 byte limit on pathnames and 256 byte limit on filename components to honor the MAX_PATH setting from the host OS. + Introduction of a registry based configuration system. + Improved CIFS Unix Extensions support. + Experimental support for file serving clusters. + Support for IPv6 in the server, and client tools and libraries. + Support for storing alternate data streams in xattrs. + Encrypted SMB transport in client tools and libraries, and server. + Support for Vista clients authenticating via Kerberos. + Full support for Windows 2003 cross-forest, transitive trusts and one-way domain trusts. + Support for userPrincipalName logons via pam_winbind and NSS lookups. + Expansion of nested domain groups via NSS calls. + Support for Active Directory LDAP Signing policy. + New LGPL Winbind client library (libwbclient.so). + New NetApi library for domain join related queries (libnetapi.so) and example GTK+ Domain join gui. + New client and server support for remotely joining and unjoining Domains. + Support for joining into Windows 2008 domains. + New ldb backend for local group mapping tables + Raised level of security defaults for authentication operations. + Inclusion of an HTML version of the 3rd edition of "Using Samba" from O'Reilly Publishing.- Add libtalloc1, libtdb0, and libwbclient0 to baselibs.conf.- Remove obsoletes and provides samba3 for post 10.3 systems.- Let libsmbsharemodes-devel require libsmbsharemodes0 for post 10.3 systems.- Rename the libsmbsharemodes package to libsmbsharemodes0 to follow the shared library packaging policy for post 10.3 systems.- Update kdc dns-only lookup patch to IPv6.- Move mount.cifs and umount.cifs from /sbin/ to /usr/sbin/ and create sym links in /sbin/; [bnc#380693].- Enable the build of vfs_cacheprime and vfs_readahead modules.- Update to 3.2.0pre2. + Add library for access to the registry configuration data. + BUG 5023: Separate NFS4 and POSIX ACL code in file access checks. + BUG 4308: Fix Excel save operation ACL bug. + BUG 4801: Correctly implement LSA lookup levels for LookupNames. + Add new option "debug class" to control printing of the debug class. + Enable building of the zfsacl and notify_fam vfs modules. + BUG 5083: Fix memleak in solarisacl module. + BUG 5063: Fix build on RHEL5. + New smb.conf parameter "config backend = registry" to enable registry only configuration. + Added support for IPv6 client and server connections. + Remove unused utilities: smbctool and rpctorture. + Fix service principal detection to match Windows Vista (based on work from Andreas Schneider). + Encrypted SMB transport in client tools and libraries, and server. + Added support for an SMB_CONF_PATH environment variable containing the path to smb.conf. + Various fixes to ntlm_auth. + Correctly handle mixed-case hostnames in NTLMv2 authentication. + Add Winbind client library. + Enhance client and server remote registry access. + Add client calls for remotely joining a computer to a domain (including calls from "net dom" command). + Add libnetapi.so library for joining domains including sample GTK+ app. + Fixes for Vista SP1 Kerberos authdata handling to only pickup the PAC. + Various fixes for DsGetDcName and conversion to IDL based structures. + Add ads_get_joinable_ous() to libads to get list of joinable ous. + Add get_logon_hours_from_pdb() to comply with new IDL based structures. + Migration of the entire client and server DCE/RPC code to IDL based structures and autogenerated code for DSSETUP, LSA, SAMR and NETLOGON. + Started migration of client and server DCE/RPC code to IDL based structures and autogenerated code for NTSSVC, SVCCTL and EVENTLOG. + Use IDL and autogenerated code for samlogoncache and Kerberos PAC handling. + Add remote join/unjoin server-side implementation. + Import the Linux red-black tree implementation. + Support for storing xattrs in tdb files. + Support for storing alternate data streams in xattrs. + Implement a generic in-memory cache based on rb-trees. + Speed up the smbclient "get" command. + Add the aio_fork module. + Modified libsmbclient API for more easily maintaining ABI compatibility while adding new features to libsmbclient. + Refactor Winbind internal parent-child interface tables to achieve better unit testing support. + Networking fixes to the libreplace library. + Add support for DNS Service Discovery. Based on work from Rishi Srivatsavai . + Don't restart winbind if a corrupted tdb is found during initialization. + Add share parameter "administrative share". + Improve error messages of net subcommands. + Add 'net rap file user'. + Change LDAP search filter to find machine accounts which are not located in the user suffix. + Remove smbmount. + BUG 5073: Allow "delete readonly = yes" to correctly override deletion of a file. + Register the smb service with mDNS if mDNS is supported. + Add smbclient support for basic mDNS browsing. + Fix padding between Winbind 32bit/64bit client library in the request/ response structures. + Added a syncops VFS module for file systems which do not guarantee meta-data operations are immediately committed to disk in stable form. + Additional portability support for building shared libraries. + Get Samba version or capability information from Windows user space. - Add new sub packages libnetapi0, libnetapi-devel, libtalloc1, libtalloc-devel, libtdb0, libtdb-devel, libwbclient0, libwbclient-devel.- Fix build with glibc 2.8.- Added baselibs.conf file to build xxbit packages for multilib support for post 10.3 systems.- Only cache password policy results that worked, otherwise we cannot login until the cache expires even if a connection to a DC has been restored; [bnc#373552].- Remove dir /usr/share/omc/svcinfo.d as it is provided now by filesystem.- Prevent tdb lock call getting interrupted by sig alarm; [bnc#364200].- Update to 3.0.28a. + Failure to join Windows 2008 domains. + Windows Vista (including SP1 RC) interop issues.- Rename the libsmbclient package to libsmbclient0 to follow the shared library packaging policy and remove provides libsmbclient3 for post 10.3 systems.- Add variable to define if a share should be an administrative share; [bnc#358841].- Fix patch errors with dcerpc and idmap_global; [bnc#280452].- Fix safe_strcpy error caused by duplicate domain name fix; [bnc#356025].- Fix two memleaks if num_validated_vuids exceeds its maximum; [bnc#349581].- Fix ACL inheritance; [bnc#351570].- Fix a gcc 4.3 buffer overflow warning.- Remove duplicate domain name prepend when user SID is in winbindd cache; [#336854].- Prevent winbindd from segfaulting due to corrupted cache tdb on flushing caches; [#340332].- Fix kerberos authentication with Vista; [#350032].- Update to 3.0.28. + Fix send_mailslot overflow: CVE-2007-6015; [#343702].- Additional cases and problems caused by fix for CVE-2007-4572; [#337823].- Fix send_mailslot overflow: CVE-2007-6015; [#343702].- Added default printing system information to README.vendor; [#113759].- Add missing define of AI_ADDRCONFIG for systems with older glibc versions.- Update to 3.0.27. + Stack buffer overflow in nmbd's logon request processing; CVE-2007-4572; [#326261]. + Remote code execution in Samba's WINS server daemon (nmbd) whe processing name registration followed name query requests; CVE-2007-5398; [#337823].- Change the spec file to get debug packages again.- Additional case for overflow: CVE-2007-4572; [#326261].- Fix process_logon_packet overflow; CVE-2007-4572; [#326261].- Fix reply_netbios_packet vulnerability; CVE-2007-5398; [#337823].- Fix missing getpwent mutex unlock; [#329796], [#331754], [#336854].- Fix the alignment of 32 and 64-bit winbind requests; [#331754].- Add dmapi-devel and xfsprogs-devel to the BuildRequires for post 10.0 systems; [#289599], fate [#302668].- Fix possible segfault in winbind which could be caused by uninitialized variables; [#253862c223].- Use FQDN in KDC DNS lookup; [#295284].- Update to 3.2.0pre1. + Use of IDL generated parsing layer for several DCE/RPC interfaces. + Removal of the 1024 byte limit on pathnames and 256 byte limit on filename components to honor the MAX_PATH setting from the host OS. + Introduction of a registry based configuration system. + Improved CIFS Unix Extensions support. + Experimental support for file serving clusters. + Full support for Windows 2003 cross-forest, transitive trusts and one-way domain trusts + Support for userPrincipalName logons via pam_winbind and NSS lookups. + Support in pam_winbind for logging on using the userPrincipalName. + Expansion of nested domain groups via NSS calls. + Support for Active Directory LDAP Signing policy. + New ldb backend for local group mapping tables + Raised level of security defaults for authentication operations. + Inclusion of an HTLM version of the 3rd edition of "Using Samba" from O'Reilly Publishing. - Update samba-vscan to 0.3.6c-beta5. - Disable dcerpc-funnel and idmap_ad-Global_Catalog as both currently don't apply to Samba 3.2.- Make nss_winbind thread-safe; [#293907, #329796].- Perform KDC lookup using DNS only; [#295284].- Handle smb child crash; [#294895].- Add a global lock inside nss_winbind as workaround; [#293907].- Merge ranged retrieval optimization to winbindd.- Update to 3.0.26a. + Memory leaks in Winbind's IDMap manager. - Update to 3.0.26. + Incorrect primary group assignment for domain users using the rfc2307 or sfu winbind nss info plugin; CVE-2007-4138; [#307623].- Fix two memleaks in idmap_cache.c; bso [#4917]. - Correct failure of libsmbclient against a version of Windows. - Make read_sock return the total number of bytes read instead. - Fix error in enum_dom_groups. - Fix logic error in timeout of blocking lock processing. - Add parameter "directory name cache size". - Fix use of pwrite in tdb code.- Also ensure to initialize ip_srv_site and count_site even if we are not on site; [#230963#c124]. - Use an off site DC if we're not online and talking to the KDC of our domain; [#230963#c106].- Fix a bug where samba writes the wrong default value of max_passwd_expire to an LDAP server; [#298469].- Fix if statements where we still expected cli_connect() to return BOOL.- Update to 3.0.25c. + File sharing with Widows 9x clients. + Winbind running out of file descriptors due to stalled child processes. + MS-DFS inter-operability issues.- Update the cache tdb validation patch which improves the backup handling trying to end up with a useable cache tdb. This applies mostly to the situation that disk space is short; [#256166c82].- Update the cache tdb validation patch to support backup and corrupted file handling; [#256166c77].- Fix a bug that causes smbd to 'hang' intermittently; [#289599].- Fix event based krb5 ticket refreshing in winbindd.- Limit the LDAP expression in lookup_usergroups_member() to security groups; [253862c209].- Don't reset the num_names counter in lookup_groupmem(); [253862c198].- Make the days before the password expiry warning appears configurable in pam_winbind.conf; [#287871].- Don't link shared libraries of vscan with -pie.- Increase LOOKUP_SIDS_HUNK_SIZE for rpccli_lsa_lookup_sids_all() from 1000 to 20480; [#253862c175].- Update to 3.0.25b. + Offline caching of files with Windows XP/Vista clients. + Improper cleanup of expired or invalid byte range locks on files. + Crashes is idmap_ldap and idmap_rid.- Fix reply when no dfs share is configured. - Fix the DFS code to work with Vista clients; [#286937].- Migrate old if-up/down scripts to new names on update; [#283706, #285187].- Introduced prefix numbering of if-up/down scripts that they get executed in the right order; [#283706, #285187].- Restart nscd on winbind update to load the new libnss_winbind.so.2 library. This will not resolve every problem with nss modules; [#174589c88].- Fix winbind segfaults with idmap_rid; bso [#4624].- Add missed 'c' character to the list of valid ones in escape_shell_string(); [#273611].- Let lookup_groupmem() only resolve not yet cached SIDs; [#253862c106].- Remove superfluous requires to samba from the devel package.- Ensure the returned structure size from _samr_query_dispinfo() is smaller than the total size; [#203833].- Remove 'unset CONFIGURE_OPTIONS' in front of the configure call to vscan. - Install header files with 0644 instead of 0755 permissions. - Enable build of the python package.- Branch a samba-devel package for post 10.2 systems. - Install .a library files with 0644 instead of 0755 permissions.- Update to 3.0.25a. + Missing supplementary Unix group membership when using "force·group". + Premature expiration of domain user passwords when using a·Samba domain controller. + Failure to open the Windows object picker against a server configured to use "security = domain". + Authentication failures when using security = server.- Add %dir /usr/share/samba to the client package. - Remove samba-classic{,-client}, samba-ldap{,-client}, sambaxp{,-client}, and smbclnt from Provides and Obsoletes of the main or client package.- Add /sbin/ldconfig to %post and %postun of libsmbsharemode.- Update samba-vscan to 0.3.6c-beta4.- In some cases PRS_ALLOC_MEM was called with zero count; [#273613]; bso [#4637].- Enhance the patch to the ads version of lookup_groupmem(); [#253862c89].- Don't use current_user to prep the security ctx in change_to_user(); [#273613].- Prevent winbindd segfaulting due to corrupted cache tdb; [#256166].- Use WORKGROUP instead of TUX-NET as default workgroup setting in smb.conf.- No longer check in the pre package scripts if swat or winbindd of version 2.2 are updated; [#273160].- Update to 3.0.25. + Significant improvements in the winbind off-line logon support. + Support for secure DDNS updates as part of the 'net ads join'·process. + Rewritten IdMap interface which allows for TTL based caching and·per domain backends. + New plug-in interface for the "winbind nss info" parameter. + New file change notify subsystem which is able to make use of·inotify on Linux. + Support for passing Windows security descriptors to a VFS·plug-in allowing for multiple Unix ACL implements to running side·by side on the Same server. + Improved compatibility with Windows Vista clients including·improved read performance with Linux servers. + Man pages for IdMap and VFS plug-ins. + Security Fixes CVE-2007-2444, CVE-2007-2446, and CVE-2007-2447. - Disable build of the python package.- Fix heap overflows to prevent remote code execution; CVE-2007-2446; [#273613]. - Fix remote command injection vulnerability; CVE-2007-2447; [#273611].- Remove obsolete samba-pdb package and required packages from BuildRequires for post 10.2 systems.- Remove X-UnitedLinux- prefix from init scripts for post 9.0 systems.- Remove requires on release from devel packages.- Reduces the number of queries made to the DC in the ads version of lookup_groupmem(); [#253862].- Allow winbindd to take local shortcut on secondary DCs in case dce funnel directory is set; [#266853].- Really remove Should-Start smb in smbfs init script; [#242918].- Disable 'msdfs root' by default again; [#268004].- Build libsmbsharemodes and create libsmbsharemodes and corresponding devel package; [#264623].- Let idmap_ad search in the Global Catalog in case dce funnel directory is set; [#266049].- Allow share names with a lengths greater than 32 chars; bso [#4512].- Check the euid and call become_root() to get write access to dump a core.- Add pwdutils BuildRequires for post 10.2 systems.- Do not restart winbindd under any if-up circumstances; [#227942].- Replace unneeded become_root_uid_only() by refactored become_root(); CVE-2007-2444; [#262090].- Add repository version and branch to the spec file via build-source-timestamp mechanism.- Allow applications to set the share mode while opening a file using libsmbclient; bso [#3684]; [#203737].- Fix for fd leak on error path in winbindd; bso [#3204], [#258737].- Add gdbm-devel BuildRequires for post 10.2 systems.- Remove setlocale(LC_ALL, "C") calls; bso [#2926], [#247728].- Fix segfault and memleak in wb_lookup_rids(); bso [#4434].- Fixes a known bottleneck under very high load situations; [#247984].- Avoid passdb builtin group membership calls in the DCERPC funnel patch; [#248556].- Allow pre 3.0.23 multi passdb backend configurations to work with post 3.0.22 by using the first backend only; [#245167].- Prevent nscd crash in NSS winbind initgroups(); [#237719]. - Fix pam_winbind cached login for samba/NT4 domains; bso [#4225]. - Various pam_winbind fixes; bso [#4094, #4288]. - Fix DCERPC funnel patch; [#245278]. - Fix vista and share level security. - Fix vista variable expansion; bso [#4093]. - Fix vista DFS support; bso [#4356]. - Fix vista backup tool; bso [#4361]. - Fix vista deletion on shares; bso [#4188]. - Fix vista spoolss problems.- Fix crash bug in rpc_pipe_bind(); [#244892].- Enable DCERPC funnel patch.- Fix accumulation of expired LDAP connections when winbind in ads mode; bso [#4009].- Fix all lp_dce_funnel_directory() callers; [#242833].- Disable broken DCERPC funnel patch; [#242833].- Update to 3.0.24. + Potential Denial of Service bug in smbd; CVE-2007-0452; [#240265].- Fix logic error in the deferred open code; CVE-2007-0452; [#240265].- Avoid winbind event handler for internal domains.- Fix smbcontrol winbind offline; [#223418]. - Fail on offline pwd change attempts; [#223501]. - Register check_dom_handler when coming from offline mode. - Fix pam_winbind passwd changes in online mode. - Call set_domain_online in init_domain_list(). - Winbind cleanup after failure and fix crash bug. - Don't register check domain handler for all trusts. - Add separate logfile for dc-connect wb child. - Only write custom krb5 conf for own domain. - Move check domain handler to fork_domain_child.- Fix pam_winbind text string typo; [#238496]. - Support sites without DCs (automatic site coverage); [#219793]. - Fix invalid krb5 cred cache deletion; [#227782]. - Fix invalid warning in the PAM session close; - Fix DC queries for all DCs; [#230963]. - Fix sitename usage depending on realm; [#195354].- Add DCERPC funnel patch; fate [#300768].- Fix pam password change with w2k DCs; [#237281].- Check from the init script for SAMBA__ENV variable expected to be set in /etc/sysconfig/samba to export a particular environment variable before starting a daemon. See section 'Setup a particular environment for a Samba daemon' from the README file how this feature is to use.- Remove %config tag from /usr/share/omc/svcinfo.d/*.xml files.- Fix pam_winbind grace offline logins; [#223501]. - Fix password expiry message; [#231583].- Move XML service description documents; fate [#301712].- Disable smbmnt, smbmount, and smbumount for systems newer than 10.1.- Add XML service description documents; fate [#301712].- Move tdb utils to the client package.- Fix crash caused by deleting a message dispatch handler from inside the handler itself; [#221709].- Fix delays in winbindd access when on a non-home network; [#222595].- Fix client-side smb signing; [#222951]. - Fix imcomplete merge for firefox NTLM handling; [#198255].- Add IA64 and x64 printer drivers directory.- Update to 3.0.23d. + Stability fixes for winbindd.- Fix ldapsmb group and unicode issues; [#143417, #216606]. - Fix net ads account management; [#217046]. - Fix libnscd usage in passdb; [#217363]. - Add the "mega patch" + Add site support for winbind; [#195354], fate [#300909]. + Add site support for net; [#211281], fate [#300909]. + Fix winbind krb5 ticket handling from offline; [#178028]. + Fix "net ads leave"; [#196771]. + Fix winbind username case handling; [#184902]. + Fix winbind name canonicalisation; [#210174]. + Fix winbind online/offline handling; [#196859]. + Add NTLM cached credential handling for firefox; [#198255], fate [#300973]. + Fix winbind groupmembership handling; [#211324]. + Fix winbind site-support handling on reconnect; [#195354]. + Fix winbind child initialization and online/offline handling; [#196859]. + Fix winbind cached credential storage; [#185053]. + Fix winbind long login delays; [#184450]. + Fix winbind crash for new AD user; [#208454].- Fix pam_winbind overriding syslog settings; [#201756]. - Fix profilepath pam_set_data for other PAM modules; [#215707].- Fix timeout handling for winbindd (samr, netlogon). - Fix gencache access; [#209409, #211281]. - Fix libsmbclient accessing NetApp; bso [#4018]. - Fix error handling in ads printer code; [#209409]. - Fix passwd pam segfault; [#211719]. - Fix crash in winbind async child. - Fix winbind failure mode for trusted domains.- Add realm to username if missing in net ads join; [#211706].- Move the LOCKDIR to the client sub package.- Activate the libaddns.- Add version of the package subversion to Samba vendor version suffix.- Update to 3.0.23c. + Authentication failures in pam_winbind when the AD domain policy is set to not expire passwords. + Authorization failures when using smb.conf options such as "valid users" with the smbpasswd passdb backend.- Fix time value reporting in libsmbclient; [#195285].- Remove update-messages.- Store and restore NT hashes as string compatible values; [#185053].- Added winbindd null sid fix; [#185053].- Update to 3.0.23b. + Ambiguity with unqualified names in smb.conf parameters such as "force user" and "valid users". + Errors in 'net ads join' caused by bad IP address in the list of domain controllers. + SMB signing errors in the client and server code. + Domain join failures when using smbpasswd on a Samba PDC.- Fix from Alison Winters of SGI to build even if make_vscan is 0.- Update to 3.0.23a. + Failure to strip the domain name from groups when 'winbind use default domain = yes' + Bad token creation of local users on member servers not running winbindd. + Failure to add users or groups to ACLs using the Windows object picker. + Failure in file serving code when 'kernel oplocks = yes'. + New "createupn" option to "net ads join" + Rewritten Kerberos keytab generation when 'use kerberos keytab = yes'- Replace vendor-files/tools/dlopen.sh by test_pam_modules make rule.- Fix pam config file parsing in pam_winbind; bso [#3916].- Update to 3.0.23. + Improved 'make test' + New offline mode in winbindd. + New Kerberos support for pam_winbind.so. + New handling of unmapped users and groups. + New non-root share management tools. + Improved support for local and BUILTIN groups.- Prevent potential crash in winbindd's credential cache handling; [#184450].- Fix memory exhaustion DoS; CVE-2006-3403; [#190468].- Fix the munlock call, samba.org svn rev r16755 from Volker.- Change the kerberos principal for LDAP authentication to netbios-name$@realm from host/name@realm; [#184450]./bin/sh/bin/sh/bin/shbuild20 1256631588M[!%"$#~}wUTu/T1ABC)IMS=:30L>.PGH"K$?D7V&(8+JK`nopqrstuvawxcdezfghijky{|}~lm3976854:2<3.4.2-1.1.3.13.4.2-1.1.3.1  nmbsmbsambasambasmbpasswdsmbusersslp.reg.dsamba.regnetbios-serversamba-serverswatpam_smbpass.sosmbstatussambaauthscript.soconfigde.msgen.msgfi.msgfr.msgit.msgja.msgnl.msgpl.msgrpcru.msgtr.msgvfsacl_tdb.soacl_xattr.soaudit.socacheprime.socap.sodefault_quota.sodirsort.soexpand_msdfs.soextd_audit.sofake_perms.sofileid.sofull_audit.sonetatalk.sopreopen.soreadahead.soreadonly.sorecycle.soshadow_copy.soshadow_copy2.sosmb_traffic_analyzer.sostreams_depot.sostreams_xattr.sosyncops.soxattr_tdb.sonmbdrcnmbrcsmbsmbdswatsmbstatus.1.gzsmbpasswd.5.gznmbd.8.gzsmbd.8.gzswat.8.gzvfs_acl_tdb.8.gzvfs_acl_xattr.8.gzvfs_audit.8.gzvfs_cacheprime.8.gzvfs_cap.8.gzvfs_catia.8.gzvfs_commit.8.gzvfs_default_quota.8.gzvfs_dirsort.8.gzvfs_extd_audit.8.gzvfs_fake_perms.8.gzvfs_fileid.8.gzvfs_full_audit.8.gzvfs_gpfs.8.gzvfs_netatalk.8.gzvfs_notify_fam.8.gzvfs_prealloc.8.gzvfs_preopen.8.gzvfs_readahead.8.gzvfs_readonly.8.gzvfs_recycle.8.gzvfs_shadow_copy.8.gzvfs_shadow_copy2.8.gzvfs_smb_traffic_analyzer.8.gzvfs_streams_depot.8.gzvfs_streams_xattr.8.gzvfs_xattr_tdb.8.gznmb.xmlsmb.xmlsambaswathelpwelcome-no-samba-doc.htmlimagesglobals.gifhome.gifpasswd.gifprinters.gifsamba.gifshares.gifstatus.gifviewconfig.gifwizard.gifincludefooter.htmlheader.htmllangjahelpwelcome.htmlimagesincludejstrhelpwelcome.htmlimagesglobals.gifhome.gifpasswd.gifprinters.gifsamba.gifshares.gifstatus.gifviewconfig.gifincludejsdriversIA64W32ALPHAW32MIPSW32PPCW32X86WIN40x64netlogonprofiles/etc/init.d//etc/logrotate.d//etc/pam.d//etc/samba//etc//etc/slp.reg.d//etc/sysconfig/SuSEfirewall2.d/services//etc/xinetd.d//lib64/security//usr/bin//usr/lib64//usr/lib64/samba//usr/lib64/samba/auth//usr/lib64/samba/vfs//usr/sbin//usr/share/man/man1//usr/share/man/man5//usr/share/man/man8//usr/share/omc/svcinfo.d//usr/share//usr/share/samba//usr/share/samba/swat//usr/share/samba/swat/help//usr/share/samba/swat/images//usr/share/samba/swat/include//usr/share/samba/swat/lang//usr/share/samba/swat/lang/ja//usr/share/samba/swat/lang/ja/help//usr/share/samba/swat/lang/tr//usr/share/samba/swat/lang/tr/help//usr/share/samba/swat/lang/tr/images//var/lib/samba//var/lib/samba/drivers/-fmessage-length=0 -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector -funwind-tables -fasynchronous-unwind-tables -gobs://build.opensuse.org/openSUSE:11.2/standard/a341106d4f75d114aefa374093ef4a1e-sambacpiolzma2x86_64-suse-linux#o@!3Ư /Icronlogrotate? ] b27!W ܺ_g$3sp .t^_V9ǿOJŌ5pQ;%엡i@دnȟz2 b=B">3uHJ O_dQ~0ud ґ!3RTʰ lVYNQ*TAyMz\V>YB%koeE a:OOTU0F[]J2ӔxyC)"\וϳ"{_uen2?"151op$< qgcO/="mZfn TQJ'^ ˹+،Z~2[HICfiyH3a68O\ U[(guJɌӟ2/8*.n,SIY\Մ 9QF~u}TnPv&;̒?lC)(r+ڡ;JVd\`8m=VOF$%3+LvcDTiەwEXSE koDy6ܺ~25#ҨP)pYXB v=ܔX5.(p Q_a6ƕ` H%ad,jZ榋&% ru^A/}'HVCɄHL~l\D<{# ^i^i7d%tӐWBs}'tZzEܫ1Hlk4Vg9OgDcNeÒї4c$UIf Qiy}Md@QVhT8A3Pz#W#[U6ӄa;ޞ0_V)Hԃ]鷙|<-*qcm*C є?cAYic൮cP. q'/_61Q+])[.hW\wE`\_N*Ux+h1mZQT. 꽌=8iG"A[OЯѯV~At➱ ׽ &8>5ꯢ?dd <ڣx5t,t%X8=UcW%^S{A#s7{j IU%y `{tJ( qVa-Y|{m-(ˈ,J)~d-Q4~ݓ2~nzg*-#u_jF=/?*3F)婎MNe+ulJ. |\ޯj"Ա֕+ {ᗝ̗! qdơ>Cm}jm'q]4\B$o.Tr6"΢Fq LeeT[s-R9쁎BuopT .}MM42AXl.0AkYb125s_PS 2UcL"/I9"Gi|l- 2uA,_^Q~_xRPVd,ҫhAo(mn8naYvF'8RtL9fOnnemշprw9ٺwH1w.芲1s(lkE&<ʱzSMI]VÎDˢLP_aqa=9%$4l-bՉ䑻ht)8F65Xč_(ru+JډV$;@D8#k'< ت }%a dFXD/ j~'#lطůʅzf`Z+g&^-I {B f'T14$&280?9f_sD7!Y^T$_e RJVǑaqlu`ٶvuj]@8cLU"&<IA8e4cD:+<`;97bʲЪ?HNؘ2d+Z 7xo2z%ί1Ĝ!Qh W<` %>F~n~dw]{X,V)lj.7e إVj9WƘ+-XiEt#ej$A 9 KbҢY*5su4榀_|=fy/ǑjdI,JBz˹lS| D-V69XNpݶ*`#,AdjQ^k| 24k z fls kzT15  8M‘o7JŲ>ӄ4 Sm x#CN(RqLFN)I;9" PvwK1hl.UKO~ٻL-Aj0eDDc iZlF.S$j~(̧")m{3^!8gC]5 ʐ^T~kNZSNN&xt =|hG;fj@"W%d?0oqN|lT<=Ug'R-] ɶ;Dc? ڵZk{cҰ][?dR~2pQsϋּ H͸xa;6,էtklkbe8risQ DO6b7Ɨ/iv߹,gM XkV{yS]}RxN혂 ._DxRS5V{ 1*=5[^H7>CS;?Dv/wf8ttӓfHDUt[Y8X9tUdu n$۞I贄oѰt1) ki.mi9枴~`Pvmr>! em=appXY̾9<$YʳMLz\Ba6nyOٱw@4d#/d禺 p}.(=h I8rF>Q}HEs/=ە7z ڕ~jͅX^kkw< @,Pֈ 5:cX29 23l)@?*T\kp)(ˌ^f! H ma3@䳖9|T/Տ1>Z((#b1N6F:xAЮϗ܏o}yX??}ފ34V.4l!+^Hx\jM+SyfB?Kl8r73&vtܱ?-鴻N1Rs3dȎf2.x3rt(= eGcZJmNV>+WDomwaBl3{fGMT urǨ>A?V"Q4vZ$ +A n^weioK8gh{ڜ_DB(}Hg Wl 9@i"52f"'vfā/RK$U馸X ֐JU/ &1wӠ6vc|%b0PSI '3Vպn&ByQ+]  9غ3 $o} :' ebҠk]_K"uO{W+U01f(!dFUZ ','B)=\nMqNC_(vR^rp"\w@@ œpR'Aw;= 2C>M;2jҦxnHJ=YǧBy1&Y=`vԟHl;C5n)ɞ\q `UMF{_iyN,y#$[$Ll}_҅-vaw"G|E#͑n_])˽CL_Ľ$b=u e5Lܚ"01^Έ od!a&{ w%VcVWC_Ǧ%]_ ik5M 2dߵ_uu-<-J}5='% N&LypDWI+C j@J_YƎyx&QuLPXnx%D0%0qE&B嗃F^L _ӛ H˞I`̇ AXм%1IV~ǰ@;[%ىNxwC!a [h8}*uFeDYd]B{5j,h{*Ox:7CA#mFJ`c]IӁL5Z,ljW ၞ@;W3O:D-YjCΔF;m~D|pP0ޗ^ͪp$xX8{ pڱ,'ѡ( T k ukBQĄЇldֳ&:y̯)N)"vn/): EIjDn;J!k;71 ܳЖ!^UuUNJ.d2CNTs]&Rk(*UTf=!F !ܫgM@1 t`P%E%4Sk4X>b{&{ߚ]B"Z%N^T[[IERn5cOe}6hr3LOMډKʀi`DHO8*аWtʌ6 _-R^eްu=e/^>BnA$2$rp!* ]\L4B4A]8MHe˵I_n$YiψbzbTCzM`GrkS}u<$3_ʔĔ_g08]?xGI*;t9_}r2%  TqDfϩ#j{Yɀ_!A;>:X|Ƞ \n2@܁pAM;;6ŁЌ{X*ĆELo\4eDHk(~j$Ra! 0dݍR7FW, MXx+tSt (v>H&.i mV-'848hbړR; f$@5:ϷQofuPz)(+'Kx3)aLJ쀚D>mnX" T72cWa7R[h)'nzs[ ii )%o߰ɿcdy6lQ_-x١f| ,΄1lwCh ;-c:҄B5eMrYKR,j͔k{HS4M!ѡtVQ_I9qX'QNKC'uD/Xᤑ!&gc<6qpe]OS(n˾ra4m'䇆Pg>޲u|z j4KUxJKJ13J ;˷TY*ZxMjr@ J÷eٕ8Ji ďP d\bI`71'`[ܖlUTx Ei|bT]7w7sn숚n$TUg~ ZgJdhLBiFaʼ1EHe q %9$=8B HGloI HZ%gΝB Er7̺` Ym)ODo/^Lu餉kT4)Uo`)F G7*w D-_^PNH*ckgjnMoI98OSRҨR 90pnqmX;T0%=ed&ZZ/P^;$w!A1RWzK CA #5݉qd,ozY#Sp=QW1=A&ZNbm&Ѿ6bfIR *x8 :[5%6TQƊFKS|R,RJd*M@^zgx^G8:YNǵ=\G 6fc<%԰Y Gmb'm[jkkbƔ:Ki+ޑ4WNy,QƴoeLnR.s z+*@)"i- 3I(JB}u6 [XI|N#_atnp?K{X o|+Fߝer t|nmjJQ7"x~PmOŋfI hD0,cpPd яaWib6bOaJGaN^ӗ9QOm.?C8Clc {IƆʚ_ _aW#.V M* x٨q,0L';]E&Zᢂ\po9}k̇{݃BgXV.q(!:wPRc/rYifb'>v9T(fAJꖉ}3 2Gg9{Acne<wZ`ӽYdyXoȘwfːY4>֫c%MRYϢ"Z-Vm[< %M7~))TOvL4$; pyPᅆ"w>o:f~Ww_gQhL_/Xm:W,,kPPJs=,YDAh3&@+1w<],+/,ЈU^$v-w`0L)%x}A|ur2 ? `ESɦ1!/IHXa4]6"~VC?_G*<(O(iۀ㣻n[7RnF W#gD$ BBઑZ8Zgk𞫳r?R@W>~`| ;"8LvybZHըQZZV2閅FKŖlqvF\[CƵ$h~@d2q7dS7 8o?n ֞^ @qf">E#4w}\yg@PaZ 3o W:gߧdQgŠ 0כ3. IebLI1l:1!ɦV}Rr r脸TZ^;:W4}o3)&Nm,,˝Y-p eX3a| D hComO,/7JQf <_ (ʤ/&=5[gx$tެBQQ󾠷0hPPp}HDEz&Rn|L ӄ}}c/ Q+Pq֥o ?z ke2"X=kM6w7h Ca>@ʦtހ\`dC xg<丌!f{+)W= yzvam׋WyU'?{%q/Zc W7 w tQ޷8ҟ5xT`h:Z#B,@8RCRHN @:aج\2[H_}5|C}0yܠN _XX?O.t܌c0c9#aZ} /(RGSPs4|`Fz(0ˈJ-RX!ZLLK!g+\5vf >SǺ( APT٩mG^w`˧#<'-bSM+JP#&fX`=oaE 2UnDL?aZ 8sd(I܇d+WY,O^y!bk%5WP=|dK ri f1$IȘiلV:4E8_<V]#-r`;QCeQ@gr #'Z 5eP=r߱U6VCdz5FDnz O*A-qC_W6MWmIlf neFkl͑2AgSEB1j{E4΢jd1qy3OD#s&(GnN]Sm=qS*PN:5 >Lb=|؟]dˉC?m,")&aChRRs2:"Eگ)V*Yx7èc,4\m<3E3,ZˬgP{2#k$6IWQ$HJf/ԩܺßx+eNMG?SNTo ߑ)mG-&]O4~fNxJR0_QL>P=-N|*$|i?Dk:bJtoD#)E^jƯX6p֖Ͱ\7.L 暩 ==To^*ؑ΅_Scv[z6zR0G>(Ӳ{/ȸ_tlKʤ"Q[ hM;u&hs /3뀁_U8$_ V4H>HL;OEyl0°; h!857RQmZ4N' vVo<=*Yɽbs8Q${s!Kw[<@VӄpZA ̋s g}DA>s; h2]e F:Sj[UM(z;Z{k 7r*0@ЏcNǪdO0"H_=bUpHtM*aBS9O hq5q#Ff\BFz2'Y`b5TApzS,e|cEOcoMObBk6Hպ{YeJ,h\bW q l]lDMwP`=wZ ӜL> nc,W[{b%BInC6b x{G%4 R ᣸!vd]!?#jпxpGk Բf |؛S}ɫbN(GckLkS} PPIHRuii,I(!LFK%!;7=z0u/#6ĞFw3[x۫ vMuww<2z6Lr/߈{I򱋒yæ].܃e0DOR\bfe%G"O!q^Y+gH]N{Kȫ՗>Wc/(Ԅ oXGx'P8B`F1+RwDIt#:+g nz̗#7ًlܟ7}_yŵ=f@^8R_ XoQlMfx2 u ~-vcMu,E]UVВ|ts,enT2[0 ^PeAR RN;~EM8?$>復:^9in7,_ǹזּ$3xZ&(S`mS{O%\f Pfi)7Nԝ(t»űxWRg7aA*-?2ҋk qfgtN1nK79;nIkj0 8Rw~Ƣhocl۽M30{ID:CU 0,E}Pv˕}G$k <.$?Cc@'WW>dk[c*ɭN1S*8<3{7FGWY)#Ԣ6ͣ|Ϝw?t_)\\Zo gg"5a ^3ܯ~OkL4xv,B"PLHR;?=rJI"9T (\e 6ebpyF#xA$r#`*z?:kw#;ф2rm^=LiQI`sgBK1A0ڏ`qdFeˀ] =J3S8Ȱc \]j$3sO07{Y0Ϝ,_|!o)cjUq&)ې_PpcRvyQZf.0uhfL<&&.WRZgi=U} s>BG{lϻ )b|Cã8Hҹt1qי.(>=.҉.DZ!xc6aX #M6$I7H.Ϝ)JuXX1 $:;=/x8 jP2R%jU0D/#-߼ bo4/j;a}c3]t-PԸvAEds2J=ɳ:D4Wـ]5*G%Um(Ikʂiz!t/51LNzM o;bA}?]5 M^m =F2aqhs:ĆF}X l(A+)]H|:ܩdHa?AT+%]G>O 8C@lHAOJWy$$;Sw#bv܄:0xK&+7x~>өk ?eZ@ۻaI|4kY&iuj ]̦<)$š6 pύ 2֨+3x>'^>d.xG; 2>#29UsE+[KpQ9{)'ɿ;qʰR;e݆δ[eʚ{z۹i890Mp؞a76 ͘%oOYXU-RM5,@c6@eϐW0są,3n!NSRv"nHʢI#cxK vo!.Aod(>O ej vsƙsS]N7ڿa)ȥMŵbܦ>Vuozo1*$z0Ԋ3th˪s 1/2,a2qSŭQZJ##CE~,o)q#}4vDH)Yߠ !OG$7V[,+trӀy#ږ#48L F$9?Ā5;^Ԏ4Xh*ƪ[u  8* + %SjEIGZ1}˺EQfȭH,0rT~8R^-_%YgehIE Nuط>T|v>KIDAH\- AK4׋Zkip Sso @ۧ_Tļ&f'u8H~J@XћjNDwy>,Pɷh\I" ;y[8u>2"'+#࿕Fӕ ӾY*ƚ:%gO%.eE)F;?q3eU#>^CI/RP5~;v/㮩*An4E1/!L i.EޓY=ZҠ/Qdؾ6O/Pl0/__R=/ڝ*Zټ9!ec|5Q-ؖ٨tCvz hɌLc<=SiL' [WF2]&vܗhtɜI!a^,DoSQR6TYxR `ŕhTpM~dVTNՂ^*4|;^ً|6dSa˄p.T88N8*4?-j&[ Y8V$3dLIt Z7bJVSdʍE–Wh; g7T0[,eK+`8QaɁ,A.M᎛SqU:21{#KZbEFd^4c]faps&YTƊlNyjtC3j^l*#Ԇ;K$\}9 Th=V/_a3j2^m,7蜒L# Q!9}V8Α૦cSmז.6#~5.rFsc̒^v:leI!W=nڂ;-ce9{LWng4?!m 0W5Pbqu$alVLRcih i8OdX3\ 0#Oɕ=<9gE XS6red\3qm :-Q˛AHCә!t#_ExW[a0BxG[Xdf $m߆ɵ3Qb(9:+!ض`J.1ؖz5`CGI:pp!dt>*M; djw`wS47JsE٠(>[ IM5rFʫ&P8ap52~{I?;!)OuJ M>'CPd@Wջ0i?3MgCU7+Vغgm/\z AxL2jv&K>5@L%]dF Qge3 ڄle+_\~{t/JƎ64 #QF"v\tzdn3#OV#1IOG[ 66ItP{N7Ry%dz'ΜtMt-\Qs lu"y_4i6ȟLBF@ 07zmg~z :ٖuE/)jsE<[xsI\'Xb#]62voW{qէgܑgoѦ~Av@Ħ㹼hHor1A۔/DzvWtmkeZoMUҡG4Ja.,1Ygvx[Ƽ$܅=(E9sY }>ijUȊ@󓨿cgp,ƚB@4b=P^VrC G*Ro.Ԯ*<[V}CT!EJ"!m|ʤ-@F Yߋ+F}WG#{]N}2 -Mj_Q,1gK9i{?ۥV8f7P"xwJSSoiNCNxq>~71b%Ҝij)$pqR,V؅M>hHZґ]Cv0&h'[WOrTSH gnl[YҜaq>W%tergJ]nS }I8 cdpt"JQ.Gl" n֨6dWh*$'M>mWR), SЗf8Z9 ysPF9C,{Y>[wDpJ7#I~B\Yؔ[t2F*e-m <&Ȇvx؈J XK(I FLMb"T峽ټnJbLVP  !7TH=ۇ7=bdN1f /ٴқ?h*ټ =֚1`4~(:zRpK1 m⦼;g_]l1n|C(K$X׷)i L՛bƼk44^؆-^0=FHHd@EዎJ[_?x÷u*a6M3CUfp2gڍM9 q@ ph({9\AA8JSaAʓNG`z%<vb(߳ʽ\t+S84+!;~yuJѨXID<!{^~Gjd\T69{Gb&I< á1PQ7 }|)(45l[kzAs'.T@2)+ſI/[ EkDU8$q"IS!T?4B+U4Y3$L$E1pi4bU"/8tn; հϩwZcNkg:2(hgɩuzM6)1,{݊e]Y~j>`g[=`{>q*SVm  B P/Hߟw?:\#]"F5ہu5LI7+^\wSjɛrH^ax&{o~o!).ho(ivFPH:E&972 ܇͏udY3{^jN5yND^K#[;}[nlg);JJq~) 쮋Y;DSUx-"˺ޟ 2MB<}>18e`z"b^΄47k5k\Jcwy n6wʗYG''E|K}.I"^ 03I3;[&6-yɂr6H}-f=䣥ȘDY8tY:^CVAp`\tcZ膎`eEZ y_=_iF=Q,ص1 ޮnF)"琢1Ѯ7?DCp~P\$rU҃u-'CFav"';QQm}rW> rs'u8`Z7Vt:d(bʾݛӹcmᾗj Oشҵ`2BPU}Q@2$ ,+wD{hW7ʄ)`%.  \ 'EUS.k$ 4^ Qg /g3y W6lbɶ\I{י)U"мefjb˂l+8=h$߸SQd42>>dym'Yx*綧Ԧ* flGU?@^F؄1iP~w^}zMS --;N+Է1rG}l}<bڨq ud8iݱQ5M's94NBTM8V3! P#FID'&,]gYaUr~LT;EaMzfOzCalyIΆo:դl(HuC'h05sy~<АVmp]'{ٗ>HRnՀ:av (wF5qouȉ%#^t)=g0*Lj\`D@ytkԌ?c F]x*7ӠW f} p=;G_|ẗX$m Y#S\U+aaxқodgnab|scj:>Z`]mWBhCTUGi\$Zn8Ewk1X=+}z %zMS=Qzה`|(VN=T4mX)<'v  ~[H h Ј*)mf7*CVu1nY/(+jАcĜVq[k?{jMQ5o>cZv/o֖.j*~c>SP&D&8}Y/+#=*uK,62O0z@[+ېCI#eiű G0(nb7ʖ$18 ,?G[@龼}A62kbt4*O*DN~ܔSg?cX ؾȳ\aLpC>`iQ&&Xzg[cU4o9-!,xradV9o]j)Y.\0LKάb8Xxy}0/IY  .h^' J@l T!eNjHD߲8pkz4mv͘J7C -ayfp":j_5RCHMm{3lf ױ[,gt{4[(5 x<̈4<_(Dә <\?P;2 N9>#;HaT_X:NşKM=V8Iz<%ˇGqCȍ?py2o)dY 0oK]<2^)LJ(Rj,1K{fLCY&A$BҷUŨi]*qn#-< L/o6Vߡ#,pmn;70(|5~L49;7F.OQ2ۧ#f2wk_dp](GP}Tap|s;8w7(㼚f  wx#c1c^ ɏ&E[BrC'+Gm>(1b7.7*ˊWԁ UF$4$}a6ܻ~S;w05؊Xj+ 7K: )%CsRy:y0BFm"'"s^~VQHSJ痙3sȪ)쉳qn&~9˺PhKQ `%}_`rQ$xZ'QngabRŚ(ѐx钡QL$i?͓1q059e+ܭE""EXӘ˧ Av.2׸MJS{p"%쳫6PD)h@; AA"w;\?w}ouL䧠>mOYZ .,̕qhԉcJ?g.*i\%y$f߹eD[SuĨqؿӦ;(Wh.]K{i7 u %7XHlzHMXPy4#NiJ{;K8#*;٧,{ KxbVW[ӮFї•vy#8iS6[jY2%f)nVnH,9kɆ%N/EP_``Guؤl\z52K'w#R8&Y4JWֆ?Dd Fp6eK`ig᪯=@MZw_M׿]g@blvNzWS_?X"va4' ȝ覸!W€0|)6oN Lf\iH |/]Sr0 jDk 'wC,KE=#o~#@R%K4F1 @?e#ݯyI\ͷ>>v$*@oJ9 j&?陋Xr/w V}"D1c@zZȳaNFŠőfш'x$ HTY[hk$5V1.ޡ H*]wrYo;M؉n\,dDOT?m֟ZPDG6I9e>w| fW3vKՒ4@;@cšG#!ICNLs3>⛋tmql 8jOnS_5 :!hQ b\wV9ܼK|H,&GgdSl73eXlD;XR$45ۄy bQ/43(RYv?΅faڔڼ'*RG ^a4Ksor^EtkΫX?T wz_yfKBN^ sr-7=-ƢTz=rv`!1cI5RZxmzZMTY8OˠnZ6$~*$=< A9'Ha<#.GsmH8vygDIGؖ%>l u)0cER*beK &lkք( _ e#8 *֎ÿb}ғa4 ՟27 !Sx,d`yuPzۨo"E@=C*Q ̨]6aZ:J[oͽ=ޱqEXQy)٦ѡ)Q}=g~hYRG+ {yȟ61ZfZE !ڝ F@'k7ra$2VM/UR#~LgK\U0j-ܿ2rN6* zЁɉHp1䜾^qt-=ULsNԬſLa \A:(fU{wX(pBصTWON؃0|S\.63L #OGJ UZ^&t(pŜR*i! B3ƪݺjF_+TPga&f#VSKJ)*U'in_]a뜔PAARiR|}]&NoA<~U<;HgшEd;bz*Cܸ[RB)G[ w(Z}$S?^roŻoJT8I%$`k33ՑPCKz3Nzλoeq{5]Z4+}^6<ڈzG틿fǹ#Pג=T 8xb[M1h#di tW3EKπq]9Z'UVI LtiՍ W\Ũ3e7,ݯ(.QA04<$k2fx 8vjP_gAL߃}tӐ~H`";lF4D=:|~ YmA*.2sGȒFq " w'BAFO1BmF"vq;`ъAC7c,@%n gifۀ\f~f(%FZM:F@ =~S;sqS/fm\7#%]̶$ƾJeU!J͐t 02ZR"Yo#Lwg|)KdR9$0X4E)E/hXhb|//̰SEd"*[Lz^k6`AJz |UlҲ[%*EǰmEIoV+`o* E _`椘ŗ"JBшDM5DŽ"^'j\>M>ofҁqBxtDlIGDqJ`5a#0sc |>wzwH-"֦aQ$(ě6JZ2nKY/7eXQ]|DyDL45.mE@oVJj)}ԉ',fuScn;qq˛j"#?0ZDe!m>*vM LY|ZhtFE0^ܒ`ئ8؛P=凷1gD3֑r{Îx/3ECvf_fޒ ݠX "<%: :sb{i87 qFEhzKY@>j7̓vqsQ8E+U?Wn_K#k-'}? ;9~pwJx E,dD,S%1x7`ҩQT8Z-=, {bh =^R$[JWcuB}S5T̯3`lUY!'zٷ9 :0Xu _˔u,0uuW9G3kwB. (v}"/zfe C#Tć?]AA\Ae w[Bϣ.$[@eAK"i%ȹ=6?t%))Iёd.1\lcOJTO]iE5F|67= 押EOѡͰA"M=kƃ(Ylg܏dBpO=aSn7HZM$gS}pOk '^nnKql0C<s A~!t4 2ej!0FT?I?U­$U(T1".>0m0.R'#S(' ? oLyK4s굂JSS).:nGrzSbI Jws4qCvvVHwrl_ A#3csIzyo b¯Izn *1Ff5^ڀCHB~,J"7 Lk6P^$ѳ͐={T%6d㐑TJ WB9DA9 1 ~}VHՁj"!s-Hb;'aeYX4*8!pUŷi.PcxufQeZ7GCH[Y|6^o @{kfҰl;gMg&DhuI2b/{)Lݦ~\mo{ݶh_DfXxd_J*UZ9% h㟀(xSA]Q*['|>2 :ˆ rb|krW=/nጠ'FeV\G{D:X8]lq'*ӟr#+Y/y~.-f6KP]"G*Ѡ0Aܾmɜa4\-鯩QQ",a> r-!sow5\VK|tz8̡A8($`/}_{TJ5LJ 8{Biu1XqlEq{zbWGf4h|ƊY \cj&X7]f3 9G3jsu\7oa ag[|nj0#[E~kO|D")]]2 ipvz&;pzkonz24ɳ `O]=zXgR=ϋ ȉ^W Y ( D,U3fsD*# |Mz>B<XEA-Kn4CaݪbYϻ({F^#B-krQO;4휄lj g ͪC?eїL\`\}-ztmJ8rf辉uf_ GhYTUz] tlm-R*TMju F38\קҬFhX?B:ષNv {%hR,B8^sL?"p(B?o_X# HXԉ휱L3a Nf\p9w,z $Ÿ~f`mT-U 6߭ :I<.y>z7'^'WDvH%_Ok{X.>q[r9u M:7&!lǡI|Gw * w. `ힸ}5 D^Sؓ&S-)ʷ]*~^7Lsvw}}ܬL(@wdg`M( d`ӗ[ߤd)& хHeh$eJ$z?nTK=kX̐qmakl^/Q㤴ʿE#4[Ê4k@UgIOﮌ!eDxڟr/yG1,NEYےõ^!ʼpq8xtي"R@+~ӾeQ%5[=Zs)sW7Z*\wth.D)xp}g8u/?qufٸKN \@NJп,\c"%߄%a@uL ~/ IR5, [S7PͮD0 [HOAx;WqHm"-heq:T]؛ ez[hwد|\Iuh(a9skIM<ΝL2CC!s8f ZLa'\S'FW) Qu"gEcvuD 'w!CWAz 5!Q5Xp{Y8gU:) wξZ[MZN?׶UuP}@W(ŁRum.'i7RrBbnA,Mw)5wcہrq &L@23c0*t>w*5 [% 8ѣV\)Lqӱ>a+/5䜍1;>nơHdw7{0&B!srnG46'&3䄌YWW0oR P3C2r$ WtT=Ov͘L0Usc#PJJQ]*{V k`Ѫ,ɝBMX~ߘfO"G1 ŤFC^)vSj)YeŜ4Yx .Ry,d?$Yg69n^ojU;%Ȋd]*Km1b\MT^>B`ri:~<"Cbp3u˜|eY:ښpZ40 8Pt3jF7vTTe[ict-+b*5.q{{ t~qaܱ"Ṿ/Gk/#_4癮/n){.W8*\;Q3ax|_Pf'{t?  5KtA%ѥ_hġآrpl^ae{ P'o)Xggng*(=r<c`'J9k;(":=M?duh7w , nS r&R@D?YbS+G*u,?3A $f!߃F&+Ƨ(L@hvn, D8l1G&48GбIau"C;kK2wZ^6@dn]d"3a\p;2mMqXփ:Z R鞝W.4涹)^ATJf2OPLSXjɢ2`|uMlO dpކf5ӎ tP{E Ag.QFpG6'-\!1iKTlW5;`B Z&Xn(+" Olۨ9e%( Pc_@ѱR3f1~w}R1.aW[<7@KM G5:49bʅ[>J#5bEQ E[|hto$1ԹVu&[C7y,[ᔉ;a]dp,gl$;tohM'm!$o8-hZ? >XJؿANO\,-1708!SMpX`f[;%=̘0lK3#)6s†*ZuwHA[VpX I/Gyp>^Q?v!V,&rƮ]/Ìn99g͆KiN`_{oZ&`;_ThB x Qyٯ`E& :E}n>[G (v4Ւi)Yٲ_ZCCS| nc[Q^YmGqԜu @&<^;7RMպI\U]V}>5, 6EF@upar$dN!)~< I"~i}cnXE*/W7Π)e1Mr3qZ1Pmb4Ր]DU7CkYRLޣ*l so1)1CV3,DHW͑Y{Uc7O>-|*ʉ6~-1ʖt0K=&R!yVB^+,f&>+)1Ё3/qQkm^k0Dr`85Nn]ljygw7:wo ϏsoQ"rA"jT=3Ϛxeَ}MPF<)(hy*n5J=8$'طav[t1CBҽ(kiGKNНrMFVu+%^*>nw$LI$-F1YI#y:#X #"ۣ:FI+d;b]m;+UXvElАw)?^X|wsZ.U[H%:G_؞9MVG6$։|ۘymraDG6tmqOxWV8!:%tH.y2pO'0FYƯ'vwIHfWTl@]CL*qގ QZxlB{ҝ3DICǃoˢr9p&@O{׫'D8>5:wEW&S[eӱXKq9An3aG|ڱÆu0H T4Wfߙ#E45.Olc YNJ?㗵zfx! '`銼擱Z+u̔"az;a|}@{3?NΫP8ǣ Ȋ)6B,#=?aR;hE^.ݡOXP%;lx IP|ʔ|j6WUZɅ̗,BzlaӁ:+v)N赋qCdkw?Z7Y/CkrZpsm պBa C$6d}nF1|z#kɱU2E2$Ys!zR*#*f{]G5I^E;勱3T/-CSYybEPKLsGC6*7E|BuHhb 9T+ f Β[ΰ5 ,}@{;ubi%(Iu  \-:Et4!jan( ɗ Tj|6i_m; !Tᒞh(+tujqe@BHdp0`bi۶=C:KBVu71_1VyjRlZ:}L'~mɞjd A$ w-ʡ&gwwosux\ gUZh˟o#^'vcx[TPC99rwpދ<|2 TdZs뉊Q/>#;Kg Y.VXdZSIeVZ6Ta(5Ǣ@At +NRҩTYL;\?cm,UMǂ]O ,8ڔ$YNr06).z@u6VM,#h&ɐS`ZMВ$>^!]FKo[8贝b[5QÂY.*d6n"U1c*=b|#Pm ti4z{ ٌ.!yaHdy~S85 0$AW\agQ}-)maP'UsFh@hIˠ4p.WFcj.4._.]:S\ZMr5UNdnkIsRԣ$$.yP&B`~ `.TR 0&z|D"Z+Ѳ1RDVBA 0농S|uέ~y\6'wZ[fNLKxY2鸜Vz=0dtORO~g]lA{/bxx" ?{:]d%Ikh9P*Pn?!7k!'n/.㼻{V(X:r_ >_cL yD-˯/1Ef,X=1eUHdjRɃ<🗕$WfU>TgoyE%cH"IFNaѪE['>1}oFW&c=*RJcc3L6j,y}v=^Z`\)  qmqmO('ԭmMB`B-;d>sAatr^ 9GN4y~?yfkw1 wtdyj֩??Qy6cxzn;=Yz+.jUBH/~A1l[>D$h虍h\7\1'˝ߕ:".e}p3L'ju xF錸e{9 l'z*Z {q7'K`͍Y^5*f')EvkR6zR7AazL 2e(z@'0n [V<)/gcN+Pv5X*zj\;n(Rq峏|'s5_?P %PW͜y=r5M@2nٝ-;kԿOs/ywس%Meqi{7>@fؽ:n\zqM>d&Z-$no=֨ xUkX5!$:"Q+\FH}%CO2T/Bw |*+hmJ 2CguLiS b jG@ޜK5R2&?aUg+&->)hCoK`l콃I(s1 7S;h?uZ%2z"*Sk2Qf<~ueAd,NP΋Ւ]-Um>;1P]tX!DB7.)|"ߧS =$ĥJ}mU(h: H5Q|k94(B^^B((T@3`Nu:{(u -gl9} i7;s62$VmNc$qJnQ(bV;Zs';#vc%w.6 Xdr~yYMxD $^os(ߜk"M> = -Zƪ<1]+a'(!0JvRⶰoh_ JLTwVWvS:kGۋ쪪ȚA?{6u?I$k2, 򪎺aC<2udNHcRH‚<]:Gdäy %P~;KtͯRaj:_lPXWBПѠp o-1bS>ݐ\dOݏlb[9f ZP*WӐbn~mp7)<,O<*pƒj+eںOTRCt X[l~&_zb:/$rdaSxv:RTrڅHu|ǔb=$'0pr2,%C*;QUϓ^P)}Ovל 6:ͧ#Uun}QA,CW{Os,bn9TD97ώmee4l|$֝Or(8/g;ԉ"vYؔQ{r%AP5W1֠eh3$/OwVKRH/J]\i 6l1䟽nR'#R71qGj0R_efW4  $+WGR=jd{ \pdd.7䚲'ޚ5ұBfgK,ZL df/Dܣk7E=)u6}Ļ,»MB[P0 ^Z3L+jރiB[OD ә*/늈;d*n|DC-STU[̫ ;C8lEȅ,dV+i_bjV* c~Ss%B 4I깵;pÎw+t*B~Y>iaRfYZ|g&rQ|`NŲ[Y%mpT0F(ap˱Aog~>ZJ])hη$EKO @ !ttn4X.*_9m5 ;#<' $+[WYd:];Qtm0Q;rӰNnGF%J9$k_v0sӧr98=!EcYdq`IfB|si{ø/wtu4 A4 x5k~CWSHR{th_WsKKS 3,-:6kPUO?M:}[3@ 9QOpm" 2($N9N*ŠLSb90 0}!'tK4ܓ]Gx(KyYV6L֓ .9%\iEDFP+WnA+rOv_Dߖ]{`T POד̈RN(-|>ZmXk3A CEıo+h<; :_L&jG4{kN$^A[oV&39[ժnjz.%a٭KʝGd{F(zu J5>~N 53T&~M k\N|?i3Cv.c #_X +߯ zs-6OU3YoPf6S';#tUD'7-aN߶]v~8RwӸiohs ,i \{x-D;ce0=1*\+a9y QQ[VČӠ,Ǝ8#6LZJ8ț\( ^Z؋Ѫ Nꡯ|ς{WM@y9_y,޵"U,mpZ ] ?l6h}{J @˝M,MTz\Siܭm(l&0FAmtv\' ç ~9Kk6'G `\wHe U n237'Fj--`YhiAgАk*&e3DɴoLF.*[S9X}xl Mzߎka̲Q:ʝ8S&GZ}Txׂ=GͲ& etޅ?Ɔ`֗Gb> 1R8#d2ѩѕD-]fWغ~̣]nܨm&sMp_/L^(pre%u%&`B A筙Yw.TK{^ LlQ smٮYRӫ-)# *z>ňO72DW@I6 B<8*H}|f֚/ɺg32jh{3y,g4G?,dEF=W蛨'µo B1%YzT h}W.;O񆡷v'AhDkh|Z~\۷ykD:}DPl{K285f'9{ꈝ'l"@ilݢ([t{Fj֌)c}KyșRTTc{p$gƒmr_;(޶0- EĘq`vG#>`L6u-h#gU ,sXm7\xf:EևnH+y ؖ8Dڈ-Qn%:OJZTg*6z$O% x:څӭݖGGn"w. Q6=?t#d gC4Ѝ QSzOCq7f#_{gD !`yqFb1G&bJw+r`^kų̅6B|+{m)i;4;u800xUwtExc{S2YÆ]$LX{ { fs_'V`[̿h౼ͺ-xK}􆍃EVyDۏ+M '8oG]5zܣ0d/ ʼnwP#P[xُVV+x^2OGԢAαa4)7/HL=#u/:J-х|;ˢ-r7fGp9YY~;x,4BigPJkmY.s$aG +Wl^o\fn0Kܳ 蓦}D)yVA%J E$J>}h}]!_^P5?a<]f13ֿT ˠR2Knc7at &7'?ܓ "Q-Qa`~>4-$[ 6x)Li/y{|[7l(J]u8g˘& z*x;_Z|·bj%MGl[b(SjVKWU*p.7I_6gQoLAL!kSTF:yV~X9pcM>Y݄]x A@z˹tKB\z@zHKefNb:V>5{@7}CBFrsџQ3MAy.ϵCQe.1@yNνl~=@Ql$~śjnpl$:ZA$ zB\3J2Zʢg{_sZZjxwXG6MD݅E!%iRB,MGk஥R qfp\?1f۟a H^[h AlksA*\qlT#:X/+)˵< oqi2e̾AYkҹ˛:*7,{{,ҿ|Գ`٩wI 9uj=4Gy^,GfJ5rz _q؎2MOjFP `*%+.\ov pMGN[ "őiJ9:HB ge|%"v2!1L-v):)_h/o%9E) mB0h'v#2_B9lׅ˗mϞQ{^wN tE ]8oKg?5@RT3hwQ(u0@"|Y+>۝N[݂v,IO} ƅM|˻QT<G/*Y,Aw44)6r{Fz[S~ґ |fdߒÍCZ?Spxv~gN]/5!E4:Bg!\9n랎R&isb7B qXAY(׆Hm"^bj$o\p -p? \CZ$RdwvtbO!QNLF(Z]5P[ Q2m^^RXzW??yrxF(rk' * uNC\v?[^~K~7j⛋V=K.E}=m p$'&\8C2luf0O`&ss l41_;Br饵(^JЛ¾4TLe(~Lb<:+TmaY+oJVNn4t%,)k=s(TטoT\=w*؇kӔaӲ]\Eom:6ϋ-LI({#?G]2Ӏ}/)>G;V(-jǃ[vp* Gt+~ɩ(oAa$)la7]^q 9 hC[N3DqJ=#2oF/>{B<$jv$Jp?<f)6/)M CUC8Z3IL_G!zR݄{Ԧ|uOy PO59ʎLoZpe]%)RW kx)Y)\ۘ,סH ѥnWpP˧e9Iޢe1%;l$z.o l N. Sp u,7;2"w ԂT{s>RH*n<p16Nےߥ?@atE1WG RPnfbĐut)QHf [rL`TTPs>%*^{Yߓa*BiGC5_.iu,Utj-HY3Kbj>]i3BΩK#Q` 9!ϝ2ch뿮'lL-'{s8BNE_^%Vl1˥I8n>hsQVOIv Zu$QTC j^³úm>c԰0!׮Ѳg Ζe~M+G᳍ʬG #Q-""b˶Nڒ}3bS3K"nZIb4⚩jw+  3 @c.IF/%+98~-(zi2mh 3R CG]`=V;f(Y6AϪBgz4/qB.ߋm}Mf T:WRBg]*EPm#FHV`yQ"XNS4 K{^/8#+L]#݄ꥸ 7$p.q]@(κ1ķ##`j"FC`un%dA@'RO6x/_S78-5/.HxvAB;][9nJ\tIۗCy#ba9v)^=!mk}\BX5!{nو'ukOo"60ߋ L. {,rlcC<-lf9^i )ˑܔ]ٓbpׯAM T(0ȲTe[,Lp(gH_ŴRϲI/Q\_imH\pUZ-PEÉA}!C}ELbx.@a0I5lWOK cdB1[AB~Ok0fjef鰇neθ Eȅ\$-vTb-PNlSҎJo1a)C'0}QNjpi;qqߕ q!o377wB}[Y'Zg9tORi/ Oca\VFȖmse~< >^\d>x-2u]]כ1*r̟'5jk6J$Ar]6?N%{c81_Ge "ZK;?rth$ F!X8>3&a5ƗC^i/ak?1'==v^XFf[ݘWo?Vq42d\>s/))4ڞS!P8e[bP8h27i(kP#i3Aˠ4,Jݿlr/`\QL l}ó3]F}/wrִzK-1^Yy'D@ce9–K`LB&K־iJvm8puLBct%ddٸr+0Fm7d( Y`?m>>c+M]F<{pƯBq?=SqI?imWxI;̓-cJXǶ;wN C +< 7{})NUazw.Hh3f4Q yp_t(ۍūլ2ljS9\[BԓWSK{ il2e0LPLram]Zcќ`i 5 oS( .rr럶34-+t&cʩd#TPU l7cn16T\zzХdHzpOՓkyVdM]+ޤUzmAN ,,{Ta԰Ԅ 'yd_;G liI'WG0+%Ac0(Pc2M< CUIdʍކ:Gf (L4,68M ,"AZh=S\^% &puߡux igC@<(G9,Cԫr,_LE7Lb0!R[$@h/R!@4F%~hm peQ\h޹㜦]PfhY'E5 yl^Mٍebsxl{┑)FٖŌK!.0K!_{7ٸjlKC__vQbAY_[^}AG$y٠[7K=C*8YHUB%]U7&|hdCRLJ3E(B U_ZK\ah: Q T+hW^G .7E48~ XuS>"V) xR'&rnWt3.y^Z5L6hۀ$K'ϿVל|jH9Ф w+JOmšq'o'Y w5R +!^i*qs'3:F`T$ܝPcQYas$N6Mܟ˿C/RuhR uq1# Ң5p,EymV ~zeaISP0G+F&l.)ؿ;8WӳbXxw Q6M#,^8f!қ6xmx&f_,!yl>a,,ZOv4yѧPm(ְM7Gʩ<.kbrZD.$h7⭸9yCH<3JV@^W]]#]˄ ~ƿ~, 8K!!&Z?70N>?`uM #=_fz)[UO b;zQxx/tduyrY,Xkl% E W @Q7.MRώ`w:ITw9#+i'ap^;mukǰ0@P89F[J=Ƕsd}jc&ꈠ0 -UkD\񃁰2NM'Ņql9~ĖE%O!Vj7lvKUdoOw[`@CZo 5yiZeg[rkB]A??5yBLR*T%o^' ,]"3JF¶(ׄ%ZͧUQ1T^tГRf-EPsΌ<|[g^>*%Ur J__~?[y,Cy>s,#4N" a'p-@; 3*IXRtzIJqޡ3}Pr*Zw~L56 D5S1 LA<*$$i48Vb}f̕[i 7έ6 .d7jTHI!i|tH4k>/P)㸔GBW$;KA +59j˟hdT~9UMI 4v"rR?`K+h/燤laOO\ۋxI'x!a'{pw׉M^-*yaNӜT"1]#hM`y:._3y4N.Cž|@8?x bj[jF,rOũڸn,7W35UVNEIuK%E |}O@>bltsF b v$U4B7u?omdo2gϛ}.]>D muߴ`vwۺG$֚2mzvUsW=a쾶HLl#bl9p+R"2'"[}F-˒9:{0yz_лςw_ПMnA"?,!&]wWR:xy1>D#&ӂ̪T`MwFKOV1P >[[]Mm/#9yf0ʤx0_ȂCQj;PZ,ϴLE7}晻D;:'Y51@3eg5WX̗=~dYlyy'a2vHj)¥׵"nO.,+=Ǫ,\dٓ@sqwОq:nP/j]&CM[xlDrڇ͚HI;cu?"ɋKJ rd XKVÈ =St~(qe5<EŹLlAԴ$;E1\X[&y%;Ĭ=Bsf}jËM0'wUnc6B(N AC=!&1$vڷ5pj5 !"꿩%{ lٍP:@P|ߣ*j/4HhQ /Do7|{](\ӣ+ע$:YBHFO.]{QRu Y뀑z`+S0ڥ媢"k$Q.%Fl&شŦlz#܄L&,9{׻d{0 y{qYqnzJfnОعLiu3:DU?fT]FriCúA_Ҕen֛bjK*[grYTF-}gM摻U!^56n"t, I& Rhv]C%jj!%9$˾Q5|btp_g'<\źwe$4XY~=Y,Bo/L(uRs.gj7*6NM;94Dd F™L 5D2^D>ű#%& |IFclok|4%NRj =TNub[T_ڌgGY{D9/1n왟1k4?w@~&x-@3~1>Nr|"%'A$(GI8v3*&u lĽf"Dj5va9?˱7ƄF/~N)h"mUXp亗D&SMμolTSZx✶$sK]J20kNxE1ElY"{[侐MI\3]y"Iɾ73G*4X`'q6 H~$F;E `5⪬cVl͊rM6--5y|@"{;:c0ljn)V'$C`C LHT}y*qKtQER@.M3"r Jb/`ցZiC?GѣLzB%Mby%E\K=`f޺XIGB6۲ _ևp%wY]vxAXxQ5D`7; nTfViq˦"82vWe'Drڨb RLW8 O=Ńߩ7 "'A6]w"lj¡7Tķfmg.V^uY N/2MSr\l5D&N\OSj,Ttw<G@hBd>l/""'^bߘ<tsKwOV)[|zæ5Ǜ4WI@1lfxq ޖl,J0 I>vI.D@H)&xiUq{~ΏaRl jHe+)tYkw?\vb8T%rJHzazO_9T8gg a_o?qs8s‡FB,M 3_e- mg.e]~B5m̦<126IŠN,(lnZHWm&Z"v=>']`MCՆα*b>\⽑yŷZdDebD6mkAfa'3iPcLhʐsAiz13(l])_o1Ropw043#zZOxrG|<cZcքBq5B3Hh%X.DX,)cV]J2ߨ-"2t,:QUk [nT/VgpKcrȬЅt{9,J_ߥSZ=`vUѺҧ\X[^\{]PogoڅD[O'Ca׆]naվHwo]ffwAjFo=RU Xw1O v@-qaQW8v}ЩJy| L:<+fbW➺G|Q cp)bb>.Ll2N^^9%„ҵC1Of`'۲A)RH^1mХg!yRMMp~^JTFp)zh'qX'Rm;9c3)F,")p!Ȏl<uEsUIzX#.0Ya9~0fH{f@ȵt’]]zak?ާLUBg{_yrhi-$- ;$`u"ڃUܬ1<4^Zl'HRduEL/"3Cg/p;k+ 6(}*`__Ă0h}vMwUB7ދF Q`{nj+{?+ J?uˁN$,|YB+<~N0-Hw7d"vdHpa޽E!8觮wP`=N^V|tAB;*qtR 88BN=BD GI%m9N8)!AWO$ãDkK'J4 :N&guE!P1X֏j-m|]5xGGĕi86A|i GvYac, m`Ywk!V=68`Ĭbui5xW߀׶0D+E!e=Z2!ֻHHTrD4B,Y1LJG.;;=/A$G"Vzdjkчr42/`ET @I d*ow|fxv+*Tή=L]O5QN+Ѭs e.ZhTx`CL`Ǭ{AJ~&t] qXvfOvnƞR{?TLCؖ'N![ta%VP aW TmރoΎ% JE>ભUnFäÄ\[ naTxF5E]v]G?9(cG_I!> 6kVmm:dؐ+U.Bz7U:j_7|/\ = 3l1 ^ќ}% VC>*FD_<5XbqL,sXzhҳi?|f{/6 RwyRr>-cr i|cZ꣨43j~н\'Ģe_.aj.B(:0u̽ ͷ̵8!zn9>:U-Tsyqſ!IfsL{ n"B:rkm &I#)Wb N84kGO#pz wuE;#$'wT{kKD[1P^9j$Bgv K/H_<'O7D`۞RHfL҃2K{Q]+hn8%Y5sӴ]$4~UCuIt+! `uam {vBEda z;rѱARxOs`,4(EZj0DڼҔ:ƫQ7GnH q|k^'Sx -kcsĀqaO9d?Q^ ŀrycn=ĉqmG,RM!{Ea}욚~MVU'!Jz?Iժ|] ]gS?[J , C"/J[%,=V\Q+oㄉvR)tب#fI/R7Ms\ koˆf]1k86nɷ<.IkUyځ$fShs}VT7gt˜:9)aBczCr!a-Dh hd.MJ?tej (&/e_[ o}&+y/9F/uv$2D!Q0^½'$˅2*+]CZ5xGζ5Dޢկ=-=[BγK4D{ 2agmELVr3o?FJ\J~1Ѧ rclHpp"D. X ʿg>SSI2G~0 7^q z"R:d j4J4D k}A,cF}hk oC P*\h*2 % qƫv(unYp)h\.Ro,/v<ءVkM4 Ytijc ` E?7;ʈP 7t6d;'.x37k}-bڍ9pukzU<+gڥ۞vAq ̶.i]̛T,EzVl opרk̸C`!&9 dۥ+u,g Ti@f;d(wjdX'UZf/8ʫeEy=aJzO $L1?;][q,띒Ȉe\}P6 }/+]C,vK%/fF {eNW X"}PU;-! KE3EK~*3 疒[>:RjlCv$l 9Q`.^|EJE zHqZ0/*aIPX7𔁙Xǰ0"r+wT=:i|:@AU;XWAc㏦dn ]A/C=c跦0Es,"Xej%EĶcD,ys!*{h&v"OFvD~#o5)YP'1 K[m"767Z`5M~QJMD5D1SYprKC%.xIqKef}(s-i;CD0l dfJSg.& Fuv`C- iKgTZ ; DYd!S;8c412L@@x9U)md TC/ao荼w!ƀ"\kϏ|FuR #ItYDq` kG\+W5gn PLj> #(2܏+"9Ҩ ";cF:vH9d\(}d* οf " )[ix6+4|w.&Py.j))J18MT|d1C96ҞRE>43. !dhu&8io9:- rhF˫8=[:B:OlqvxBJ!-p?m:8+&7-sVQ|(yTdiaivY0Rg$q#}g<}]#zSǽ\- m~(LsQHKî%| z+qKmN 刂2 QVZqƾ ~`a(#u#K+;Bt/^9<Ѷ7oa+?Y>04F2&u?hJ*cIȕ d=RlpKd 7Eμ:vhWwuͮ&f8Z?p=(Kf61_*꤄ ]ⵢOPwqɌ0k֣Ei"; F+"ὴb/@fE(m}!zlWЫͬ ^ 0zTivthej3'`xso"Z_2 5`p"ހ$?jK&d>=OI0i4K wDB+6@Rٖ4_mfAQeGt"/ؚ[wHeY?v:cB2͜ ݈}E,*r2ZOdIgOZW]X OIfHLbp҅*SЂ-~U!m>B3-5NcgF`(R͓#؋ʿBq%/g,@O(:i1.( [g~S36,%^KaEۂH6\,,XU(כKl~9c1!(S Ҫ -WyehK2 N!qQ TL{9e.BSDwl889(< 6CkYw쵍au;ڰ\SSd,muM^EMcI8e\}opŐ31ZבexiSt ]rjes?'`F;-z?,8t;mK?0!@\POCز0?锢=Pw)ΚwȂ/nH@K1 c6A3(RD9xĦd<.99N8 yD,X#AM5>x@T^i?FP@>5b]uZOвqW?aB~ڕci~M ghd ;/ZmW[C#kv]*n%'꩜i7rbu͇4l6ΊSxAp t6ʆ8j;+lq75Ħ"ʵtO0<ŗ`ۂ'(洳oofjU w,\`z3N1lD ؾ9цN9O> )|5)[9Z/i%[$МɉQ_}OI<@ _'#:WH5p3-T>OR`1 qRvEGd?$[mci@%ѰjrpG.|2 ;Cl})x?h"$0+x5uOEt`7H)_ z{#bV[2nGiAHGP=#r2 urw]n]0#K6^ħ8$VRHT1b- +MWZs0M6]H^& 8@v<@k*r :0\6(R#H`k񢠖ɶ\.FgR]=,^2r;qZw&C['ɺQ9Ԣa|㿻$@єF8xkc!caLZYܹѫ=;$ +ɯzRձ* =w`Bд(/j~M.A}B(Еf^w[hKOu7 In𳘷D` `r$QrA_+|hA%x0e,FJx[9y; KO-c:&nW$z~*5}+W-=n/kzRDRVO8" Oj 'a};N8<-8[!UbcnSu+GV 7%E]X0fᰊgzY&76>R|$s8L ϼS^W )x\d߲z~Q,Q _y=MN^."uI&]P”O˅i,; N;8hg RҸH9Tq( 騕G+*8 xx]WDd^*"zW@a4*-VZ6f ЖT/q͍HO \Yj<{_t?X[ؓ(fY%'r9>9|΅f? @OW+ɫc oBG Y@>H  "?)>p(' 6N^Nb7 9k"kCU0!XUA~2Cc=Va3uӎH8D5щb0  tM)-;#mHxxZ^$thILn-81Х\e8rOը-Ѻ mkEU8ᆔ~ܔݾ SC(8V~Pl=909MY62Up@[r@yY<̴}JC&j` Xy6H:8 a٬}-]Xo5iVx#tX=}͖Yk&#d})"d)hG4~?̫ EDH.4 1XM 0) %=@[k'VgKe{ankQ\I=c$үJpKE#pI Kt ?*(L3>@(J% q8`U3i]䪲N^^'f!J[ڗsIZ>3EViW}At.orU"fidJ ȱj[+qTcPvs oߙ"YA3ޯ5d  4?)7_IRK8jA%.iΜS1~Ko=f@ ݭd_`ptTÿK#PfN#WS3M'޴[ݴJz\o $ =aTJq+[m9XRJPWUq|Pfh%fXE76Q/*Zp'?%5p"C& HAҜ(弢QT/ÏsEKJe^E-wzLZ]0*xb̃c׀uɉ!E|ٮ2KIl}=g}4TPl}e?41+<oj)v{^c &?rXN^#ãV >U2Wh8 ~RPc ϒx;4RA5BmR<#93峛%#ODR45 , #kDBK%_G uP"=,;hSɈljpx˗Qֳn+ Wd=i<=$PeEmRqpD&+^/}|,b`(Kã*aR+P}'Iot),䍠[N*gBREK?8U͌hm?O%'W [MT.ߖm=h'1/6l(OJh>ZԘ}V&w1i}iwP7o|sB;נ9ZnGn_+q0ɱ._4l΍ A9MeX$MJs)vfRUy[RW\QW HD_%b$Z%Yw ,:k'lanF_|oy2)cp&/1M $ҸfC#-<C%XSY">D4w?DĖO 0 kL}[oyɡh} B=XY@ It~QΒ-;]'(Z~[@&K}*d+ڒ'KyһyC_H&8{{p df;?`G/&9a1Yi$?e*xg~?-xu $z*Z:q 0θ>MYy7f?*u tvov]?eX{hSېp3sЄ&Dͳ#8J&",%sJu<T wV|=ᢊKm^*a 3ʩǟdfG>Gi)4Hspo"KIN72lí鬲7 ɵB|VўU4PuEP3A͆,*G801Qp>r Ćܺ藱sqpXǀ S,IĖLV+)ak޸QoYiyԦ.O5Y o2tr@ 4f ra_ b~,[̑#]ܺ+DS`Q`+N>g/잺{ )4 2Zo/J>z#ag`9A1zeiIIe/0͖?:ư-HE@ݥI xa9@Og89Hn}2\&[bo~@+ԔX\dBRˊł6JIZ:ϛ/V)/Y1z}\t252&A򬂬FKCo&*:<-q8՘[BZy LW1zLvJCkQgd%ۛ&q\"1yqȝgq03ݒh0B tmAec{ ^=tCVĒ a1v͇Ud4A!(x^ 07*J"zҨ-w{]F]Lƃv|$|_ R'6" +בTʙ%o1%CH"\@/K{J"Ϫ+R8E*?m#UO!kvQI ٱ(C.{E]w Pɿ赐P1(Eͣ:ڈ'k":؃3ޗj.T61 tAL')?vޛxpE9x4yemXU +V|UQCl=H$/S<6 LĦۦ~O!> %@ϱ꽝lC^M4+1;9r[S{8 ڈYq+Sb,^)Ao45 TAc^U!-_ۓ]|v /u+`ɘ4i.m!m>p!V!v}wt{H.d^Hc̴|LͫGOyf-)9t‹F@DNRh /M ͭ͵c0%.H{T!(b1bv|r-zOG"?4(gXJяDB#yp3DPfp>w⛕f[aC5:q0 X~ƒIrw hCy #_K&M8M`bDI `8eke gB/7p%E>M @Ҡj? ~3'iM\=S/mtxR0X3f J|7êw<@N4ݽ9? pCѾw4V0B j"i"8CA%$J!PpeSPkO],^ 'RB T$^M8\Rh1Dq ._beLh n/xsT@ܷߔūL?|%;r\?m#~4,ȱ9?CoF\z$fJ'3T( s\ۢ[Aiug:Q?{iHHW]6R:ڦbNڽ3T,凟2rW$|,T6`G-NL4]MU8% zCV@W[Mxf!*5%ge gztllъz0U戢|$KE2G0eA,rI^3@:X뮥m(M!z=+I!%۪ԉM Ɠb?pd05_6hv4: qe0Ƒcp%OLl ws Zs S(/%ǦYbr.hX[+%R8e#X,1语9ɨ?,6lnw`Dj͘ ~>b]!s+m*X3"F~E6a.4E?YpOb!gI(ɴm`v IVQ fR!0hNp62p%cgno;AG/^JEYN)WT@to~a:0 Hˉ?+fji#-~**+m\fYUH0 lUA)"1]mU%AYa(8'{o+]@5wHsD\a&M35*ꝍ ʖyDY]SOEK9ZE$SZқ6XM~VO0{IfVb)ȴ~ZPΫ!dT0&WIZ-?wsm{%Ma?vTQD{@Hl/ׄhOua88FJК#knlS7tBaƝzFpn7aV5~Q]w*Mc樘 I (=::A#Tr46ǚ@( OO*T0|NȠ+[d̡w?{PE/ZYFReg@"weM|ciQ~VkmohK!+'wl{Ne{"ۍ죫q=㘔R$K;Ix>X1ȫ?ԟpϜ{/&@uO:# w̥t!$ܳ=g/ʆJHɈ {n񔕷ܐϢcՑ݈ a>rwrEN<>M>(.UH_ lJ}ճЩKs5U!;|Yapj> Ԩrw%TcRT4R J nNj l4Q"q<_37~ޑ$ZX@%dޯS-Ou2C: ,׹lH/B*>TwU I0c1&?Y#f8y7X% sE=8ԧՉyec"*eQ tfxT P Ώ+`½uZR`.e[J9^¿2^@MNl)bw߉\ifEK=, 2eO{QnvcƮ7;,b?ʾ6R0VXd8M&K}XB2!RDˤnLzy+{ {xKS~}{}#W?(K–yԸi>p;m @X-D~UϾ!nMGym8%YLX3q֬bu< 8*Lx)_WZr聿WSfަI]z04' pF,6@NM8$_$Q~E3Obԉ}W/Fz :-MMwnNՙ]rp :":%Qkp ~Ʌ4(v 01Y CBnauL|: i8 4Nt?I( AH줠q|yO&B?-W 翚rCA^4-}`9@mnD7ίW,[+t,WhK绮\_w֙|ѥq!$MBӮO3x} 48׷rdb曮M/v.RiN?|&\a+ĺ,#Kk$tFc<\ʲ"b7eɺГ<va'J<@qǷ۵lW8c@F| _۶uנz3g+nOB~i-:6#gVK{p،5 fQB B%G>&"~Imߟ!e1dF7oo#1rAWVWVuNCmnD( `MG0~zYPpj3l,  >Cv 9oΡNk=\)>ҲC\ڈQqUrx:̓&KjRR~ ֹ&X)4J 'ܶDGk٣ Iڏ703$R"ilk) PҰzɁQ,ztO^?GFT5B#]~i9f+՛+?^Ԧ'<x/0{ڪǥ2ڜ_H1ʿxJ [UC/9Yvh *ೈH!e?u, <x5RNrRM$'S~CVz(C2 դwX/PwOPlp!aOۙ_6.>VQ @'~9Ҷl B:ݘ$tII $*i̖1vfr.MU(DecIc }0y 02>BBVэbI=Oi3MDi/nEbC;2g nN)ضۼԚյ-$)VQVG*L d2f<[46g,R0~ ATe"f d>! ͢m~7x;.*.8F8⽌Ji%%-<֮¾VW?d6qψkƒ<׈>EQhX??}8'4!YѰsT&"@x 'F|#kKA%S9*tI! $ cKƗ *( }Up~%XZuƌ KʖZPEE RsQcSo7P@aQ6UK>D|5527&l.Ѽf&=MK_N'y {؆|j nLf;S<>XD~HP,%B-e+Cd / ͟5CD2A+V,H':J,q YTZRzj/uqe`q4Ug! 'm"t 4<Nj 3 F}*|*\|V-G͟[͔6F 1܅bAY4o0A޷]'[n%&9Vs L#X*0ҋ"XC)U,]OO 󆪩'1 I7svT֋ƑzAuk$?gH{vH]%D$ By)ODG[GyWz1U}PEw8 {u[c{$H!2(A\S(00u8e4:|Fـ!@YO{LϞ`>OHfEQ}woFydtvVj=:Tywy=xL3ԜCm- /!wNkU)96'p$Eus1awQg60.7>;Ɲ3!ՐnD&i3+$PS3AάڹbwefaܻVީ۸glqjNqӈ7?\7[ bȋRJ޼I_ƍTL$ic G xC^_`:F%k\_|ji඘ uvNpW$[>"1YRmL&=&>4eI7 Qd??|ӹ&jQ@+sk@|iloh&w;<OWʦ7$i45BtjOKoα.oAwo4 )<>@NZ2ĻPbW%؁~^LQ*0 Aou]؃2{obN ^]/~FS;(WS^t.H:r0S !\kf%d26ȗEhX8,v1"OC z5}iJ@ ~ 3w8Чs`F(1Ӡd]SY+ |TuG5FeObwmC }((_R\)X!DAXU&נ':Lj[|oXծ"f%pQRi`^3ef]  r4ttHc9%Bǫnf7"5Muq$P&A@x睏Mom_g6*sG@-)Jn")=–}Sz}i-c_C>rAoΕU6K=X㙲 /Jm6㍃X,O9K 4/J2Z?u|$p귟]&%8SRe=k\dyZzfBtlrBORW}8;{ލPSF\rUĠbɥb_OZls LE70( {oFl1iL˓aUǂr~b/.ŃNxDIZΠqRE[ĕ.^l5b:7g"f~i2MV5BAJB¢쭇 1&a]Ogm%jkX#}x yl")+Pk̉כ:JRY a5kZ0ΖPm@"F|L)LJ|~S͂SKarڣ38%bI.ZFeD@sC(<09A2(B6^& }K"9nzP0^EY(qR S53^v''WFp'M5, _fz]NFt/kI=HRbE8Da[s$E ,uzPn̠c3Qc$aIqvF9( EC_ex;q7aX:3WlNO0FT4Z9LjxIҟ"/?? zHL~O#zN% ߏ{<0w]knZLSa;^|Xzzm3Jdѭt /M 8<'kduβ#IkM_8W]8X3YxRv6Xoe/MBBω9,Kfo3@*s6!KQ,)…V;n6V݅='y |$[;m%ؼ|:oxSwD 7:6 g:I^Fefx#g@Ë!VPn:21<ݮD{Dn!&^ډB©)[J1h}T꺞me^ɯsD% XPAaM@j2泦w0ay߾{ҢlGϚo6Q1ԤGdH K_եk]o 293ftP@ G7,)v-(fwL?4jA*?kȑCUՓ<-wH70dK O_ YH-AVGW0<`k(ԡ1–{ m8rlJ%@D2ޑ қ;v׫Ma-[S0"D0O#`EYÂʜׄ1PL_6drģ-'FwohbA;t ā/n%XP~;1uv3i\ ]PQ|D a]4[a+KWb;O\._"he%[C@p,"3)}TFJŸU-ٕ+5QK~[}szruֈ,((MU CឿMKgoy_ ozv$gfS奍.ٲ_3ї@6KQ-836{CI<)I_+*O 6݅.^m!Tr 芷:Ngu C?gL S9hsE-|]F{Vԃ%+oR)Jo|ڜ,)SQct7:k/]tA3>߆rM?7qg}}4ѳM[XDޞYCmdyЯi2cqN¥U7d7D+ӄQQ>_@$z&Kzҳ}JdK[bb(F]EL$h ķgt=KJR[1i0ۛAT|XrRʘ/ x1~)1YF?R6J)нxPqY/ YS!:^icml Mt!@M/}Lٖaj2:L1} &Q}_ްCL:!ܖ}3`␋w1h ,x%/HHaeXl]6wb|\1;|s`sF3%;5jԩK ZJN` UZՎŻ'ށ`۽p S8G )ܧЛkoXIA³y.]xb4>,`rғL0%%&)}'3TH`3#LH7gCﳍhGүA|F9W?¥CrCbJD?'Af8H4?\HI[!2zeRXJǝt㮕gֵ΅}--<u[lAAl9;Kx`;.jN9%G"W׷'Ӏ $ 9j.p> ?R1/e< Պlf pܝEO?KU+H|CN'MyDJ f#c7ų&77-qO\ 5#t&#"J`TFoy|Z{ͦٿ,f~9CGm ί n<#k%lf*Z32Ƞ'`1*Z)S@|EϦ6P!FJpc8S02[OnܔIďcEePy,?ߨg?]?yDb' )7=?[4?KA%<`ydiiTә™'B*,M 3̂z0]9 aOu5ot$v#8]p1'ۧb7TӎN'ɋ/ִ*zac &SK+yTc#9mNƫwk4?=77S~PMdke8 ā&<&T|»r+'!lu+ip~)qO`YD}''ǔ}T6yIbm|PR~\'L-3>K{Wp1f*9W4 #h#w K0W\VK&‘Zy+MTsZJs4S-[b㦰s pt):'6|;ͼum?1wi1Wo2=v9.055O">'tae7I2'-ʟ~&[0Ú# `3PKG`mfs*?)2T).ཬdojJΜk3ͫ7vbpI# ֙HӛhaRSk?ɹz: 8T¨#ݡwbqN 8,x1۷RCjtMA D6C ګ-\f׆{aeL2 ;g[̷m67"AD.amg'CC< )4ea9 yu6{;-Q:8җb= 8E@tc5YcƬV%op?ЄQ"L'F2Փ]պ iS]lf;.!R# 'j?y1i[n4#i(w.MO"nN >`5%~ S*ӠA8tWUO:9VMtINpRg'o &Wv)P~aiFyԩPn!_y೙Sh$=,-{8fA$"Acxʡ2vk  qw'y=bU6)u9{l\ND8臛>(ӣ_./I;OY_ǡZ2W.Ia2q # TUϬm93-+[S2emo1a7(NG֊-p(4\IeO]\W ٵPn{%SÜ͵ pw BɑP8Ip=el5~$;_.Uz*0D^ڻ tþXez6 cmp n$BpjW(J fΡLQLřv'^i+ RKv\b'iWò@ZZD0xqSO,*>0lUsgĢ8GB E!RyR~lVVC*qgB{կb5iS6]Xx֧ʚ%qdԖDl?=>6 zNh$?;N}IӔ9|hK2z<*/&2 +r~gyx"w /V}@un|h^JbEZ xK'-޵  MT>htRD;};2[QJQ++bfQp,KRfߍe'_d->.Zp: ~\K1pF&%'~xJPyط@™|5XVA8+0ԹqW{I&JIRW| A ;IBbxMgq:hSbw2羽k;'fvu;` w.eTnާ jLycٺ*qAlѵ\XF 4`[LgQv;[i9I5u a_m$={}Abti5|h_sB<*]Տ: \#LDq[+"h-7jC)=:B'J91ʊ3 y %k%5bfTEv[v1:B`h3:s6$&{ $'/J79Hd^Q(vbPo,\Pk5R/?ڢRi\@BX),_%WFFҠDIskѪQ!Q>xȷ[ٴ0טhkI}<'hO1yM䈊CGa!TTMv"^f#=s?F6ϔF{9 m@ J>i2`z0="d |Yq);7kZh|Dj$Ժk4_x$}O-c.ܞY"Z/g w Tm?aQsk"P AH@hYizjKgգ|Ue acQ_11[d2siNʬPʌ?0c̞q}xB}mM]HsA,^&TJ&1kR%!{L:*|F`UzDqP 4ۺ򥩤zbqRʊ\^ Z`>|b'U5Ɍ}UFGjOr1.;Fga.n<~˟A^ZuvI{={SoCtd"OA-tķXiDV.9bI=Fʮ@|zp;8ITrpIy PIRZ3vFS^F (e6A8JÚtcaBVa3 iPgc509!(=?vG 7 b]G`.#e#Y`j5mO_h_gfI-56|ĨwZ#\Z /cC"K<իO2`t|]+$xTe_d~JVEQBƹ\Ө%;׷ǿFϷT6~* TcvM4+F)U33,z&:|*P=Dݏ|Icȅ6tRí:*tednBaɭWEVۿ7I~$ɈcA:HN5 dI4'MVd'U: ܛu&V.P}fLFZ< jpҹMSU6ݯvARo}ur ɭԟ*fʐ[MJ?.͞-J)1hGWG))7'Z Un5uԫ,k]inagaG ]% )fz9pst fN!~hz( Q ]yaw1htSn0%u7lN^`'<]xg"ACd y!Ќ HO]é N_{meR(p3O,>?Vk^Z]Ɵ.rj%cesjz478̐ط$8LGzppB6#+yuK=%_tj'?xUR }/+n /)詛?I v7 ٱrc2n a@KEཔjnЉ B?SO4q/Z46ɎOdxUU8v{6Ed@8̹-vEX'8PԂBo|nPfX?$abc{_\|gW&O@(Nm}rf>[0!jGݚ##!5F^R^0-{j;W]U|IcNULm[ d*<]97cˡ w|pԅ׻|`zwj;!3m s^qiep\`V'eu1$LSy\vۦnYsp<]XЂԉ1ڑ*IrC}"@0+8,x d"ra*dw1/jFuuX0Q%'s N Dg5$o;9|U)M|4Lɨ@4b.H8^*%> = Ly}caA1zÏZįouM*갇jK{ۊ2!ֈ;RW8?e8q&P㸼0Ti. ꥴ'z6l#?g/Ltk eA4nNXaXeYK1W|(큯X^bO^0Kgߊnq((CUӿxXZN-DDGz.Am;]\sǹ:ťܴjN4 k3ŒQa/]uA_MU/`Zހ7r˞MR 3Z(.f~3DzoO2}i7'0*#oT<Ug3sԓ>^9SVW0{)[wa@F:_MI)Q _b9gLeVzeWv͵s)ߌ*Lkȸ?RHzܶEx%64Iu:4|ک^*@X)HF08[&J4~Bj`gZI̱ZGY @;sYUuogdaVK˧ (4h`vp:*6|41Q9D^O;d 1!QMR#.ɾrye/ 1~6Am%ucЍ)3M 74a6@I /z֖녯 A׵vf}Gm (;ZuOGL^g- =D.Rxo-?e?b(BDuxeYPbQ`hvDCF]h1,I['\7i|{ovޣԲăY>[~cK`b##vdy ޾,7x5IuB*nk A 8c lV$^<!u~cCu&a]GUI> HFaϬ5k&7u"NKw ~}tT1`ų.AzRyD":>@u7""38>ϕOA.律',9TivWiw5GbN|κ=*fJ%WϬDP+PʠsZ43vQ[}(;J<]3Y ϱyFY KJe ޝ4\cfu%HQ&_ړN3`V!X6fgzrIiY7cڊa?r\KƃLNzOWs+&UZ95iCPQ /SH_#::2(OĘʼncmlOoàb՚+,Qo lGD])di?£qr<7ڻjK,]<Tq=,+<g?2N{&mpl՗)15{۩S&*p~X#yAZ4 ^.Ar bFsp6ٲvagɱ~.2*IVk~Nː>/]WS^Xu“!8u-KWOYؕ9^p6]~.WGkp*t<*?wչmc`RG/N*n5.  14=}b6@FK˖l& ^,j=71elK P֜I a@_~IDGdoR}| 2Onͬvc0@/`{/䏏ڂy߸bopJD=@jg,My5ȒzV\${o}gEm|| b#)"ɹpPjDäIN b-Y2^|ZL)<+4z Fi2 ߴ{ ~PRM&.B.VW_`aKĖ-I#ԥ8#% a6=d&O4,X?Pt<`(q<K?ǒ(ըŁk(Uכf%&8L۾Y9VК]%h˖dG"5m<ЫtL뭛w H+1#֣`S7jbA׷;wnv( Nnd)K~T>NksRpRe`<-V5o6(yJY!Hij񤘕y۾ᰆtW D;-DKH6!mf1%F0y7Ώ)][3_jgDc|w~ʡ@TfPҍF A:k{f%K ' 2n阌^ ۉX!Ji znwˤ܅b{( >~5!8fݿV@@Y:?^ω: !Gʖ EMGʭi-IVłڇJjs=>?@]i-M:ro&1&&Y#zݵËHOZC!׬3~ܧ!;|M}dC D +o@3^~& !ropVEmIEW=ik`s}OJ@(\'D?sո8hXv rmkrBoQe2G74?O[FV87:4+ҎjZwG NrH'q!!_Lt+O]%+7Qų + T,{ }ɻvs^r@ߋM+ bЋ[xۜ#&)WbX޶PpYݤunr*1!+v m0W#mou$5@r@w/ XFA@'8@*0tH@`јt=O淞M?U jw5 \ɫs=!m7gQ7)PHsPiF>R3샘SS:XA+D^Z,3]O790QO$b:1 xFE3zO)%OQa]٬$3TObЪbO͵ry fm>yޜN㯬6 nnAH"a1¯{q!dv+B,,P`HUZGUs.T%K&! 5'psH'0gkjT9ޟ3 9/M Xf tHEBRx\fӱK53@ ׸)>C6HuBX*P`stKE G]?*`}.28(-4 =?iO&'FV}L= Bk%,r힏+p jZ8aF a@yK~8w@J R=RFa?ZQ8X/.~)ePAFK»{I.TZٵ @lB?ϱu;_[jS A3">|FN`?wf Z!WͻBEUWDVJ2~,؃~FˆGϬXܿXNMw5ַzoR:nUCn3ƾbF }4- mcZ P]a1Y}/o4;*_*n-L}jLcXU-sJd=/2U8tC׶H`!㝾FkסYql%l#Pޗ@BzG(Ug؛)CRÎ^lwftՀ+f)ʼ%.1h={e~=ڐxaf a?E@UT,\Ӹ.@NGFn(a@0g\ųm~4r$Y%o3=!$3= V`6&iՔQ>c]]mGCE^ėp9o->"(dxVOIʲ'ىpQUX+E3R$?`-)A kҳ r0K*))DĔi}(%ϿP7ȑ(-zct?A&փ)_U`30HO8juHnoUXA/Ƙtxu4b պkTFD% sz Rֿ$P =DI 꼻IrlvKSA0B߉mEmV?ݸ\?} gf !XF Fwþ]( POt gC֑cĊ!7ş"+8ʔk_;lf76OckCM0<@ec6OLDQ8涴Ȃyߣڙ#gԳYp :h Atzc@l$c$6>/Vp;A+[&mwz!L1YխonyS 3vUY> E# OU5r?qil֐N_MT5:B1o|` ctY |o!ŅH7oT+ܐz\X۴*bWd#]]91Oj^bV(#?i37zRP3`sG!3T+{\ڏ:fpnF/Ԙ24,TxE!^hho4:^;Jz&b''Zqlx'"PK6Ncnl¼w Bd2d>>4[ IHyTy;ᱫg %E^ʹVu",z 6Jԗ+~hJ6?D|[+0pR`9U"]?vF=!2* W}E\x3?<1ƕH1{csAh?v)Y4Y1>z=,6S^IqȜ\K*ܟ q<35"Gv>UWk0,Oޠ{ BmQej%4j>Bba@MW l; llv{iHW^/]A/&>=垑,1 VX_ޟPVVI}ex%W'ZwGod,lD;L'+'o.*41RYU:h{Bx.[qLnE5`n F/R Eh^ 9JetML 8zrtZb$o?7I i~,= b(:a &(,-bvrC~Zb1f1;u>h:5Br|]a 9*#!`cbûuooݴX48]XږVqelЦeV:48$kxQS):F@}>5D@񠶫 b>`Q_n2uK3 nO::J3\eԟXOBڡ]Wr/ X$4ɘ ,!JθԀX : !P*LzKyd܍,J")rIFt1 1pUDmbYѢ3Vij+GJ.f|U(}<8G-) (-gi#;&>æA[+>wG kR:ɷhGY*,e2I4nZJl{1kL̹ϲӠ8d`G (:^d8"(Q?lzgUɧEr̎>G\_1VY>6H`q՟>yc}+K9+.BsNrRqoACKødko3kw_SƋS++k"W:)Pģ63sK AxY[v[Aa D r9]KWR1`;Qmb0#O:=)ɼXAU+~$_:/bϑ܍g]`s/ A_V33Wq3 ->!dnp9p\̱[.+-SHD Q&zNwlI5W2, m0T黄/)h@U;9*[^ jF[QuO5q?lYIu ӮCf~+ *Ezr"ɒЋ](O=XTPx[S-ߣ4i_EL˰8Q)\__&{楢mZz`/ГwI=&ow;Xgx0T!^ Xt+4cK?|` +HiN:&Dg\o}3T*'F(<1 4L ~gWF j"`gE52B߷u͓!E(a]xdK2v)Ag U\v|@O݋;H%y]i'Hs7$4gt}σo4M 9;+?5dz֎$3P~]NUFf\3{Tbf[b1ZmY؈~ΉERDaK8c*f#7)I?XC:j4iEW,CbH|aIxp4F( P(-F=lN`/X-PV!I!M[8w l2 22AdWB7W|o`GHe-9._ᕼK85pbIIƓޙ GfAk GErKGa7SWM^k-v +}|I2/CM=D %x p~`I`ƯMU3wI0k]?chK/ h h~?κZOձW [m%0 $z/Y؋4<T7g+(~,T~_*q ȪnGX5k7p <_K "cP}^Qؐ%r3ZsfT4YY%J"7g i9>C 6aV \f%"$0d!5W*dֱx*)\^}ϭU8] 2ww0Jq%g6;Vo XJVv&0:ܸc*mJɥjv! Evier) ➰0˩Ԍ(55C-v{*y>1dn'\[ GW]Ve뷛{3~o|sB?y̕k O<ڐ'_)&3Gھ <n([-E3 f%E27@F&`mNZ?lP#[Xh- ѷ(z{BZU &U1"3x-0yǩ,켬 WN x0Y'?֘džPDžnw>)sxV1~52 9AgrlRQ!xwʅ浼-NbgJ7a"{IƳ[?n2Sϙ{"EThd4[rAw+5ePI܂>jLWVQ7Ud ,ܛG[ hQEj Z9Id),٭s]bW]p_3p.N')`B3|{~hϹM;HhGaGRM͕cϺ]l q^h]#'$7A]ބ#d:Jr?:|MY-ױA^Sl缦-*E˨C?4t3ɮƲO_}#%f@~7* 6+HM;xhRJD|ݶ5UEI8%EAO'BDȍ(z! 8=ܗl5]€9`B)`](h(|-ѢZj(bhEp}7}f01 raHɳ oS<?!ˈM;Iw/u-vީ7 +uhXL&D+ֳ<[sE%vY"-RVw32w,sA[]J̝V ?u5`(1~Dqy fqR죂$2Oڪf4$]*ui3y50{\zn.<-c)$l8̋5uv*{p0Ca9p9f,h>p^9~V+q+/ R%-{h=ZT:Xfj]H۲crc?>%,t'$-Jډьl&AW>j-5׻Aoa⽴JEW9\ݕ6 cb=SLZ.$s8 IظwmIs?<*FAY(P/M7g//5 ,WXUfPs_i5[{4D r-*3aѻЇ6c3%d\: o K%4o>ę-",cW&GF <mnʚb G_Qhyq3FaBn=Gu3tz'IPx4ծJiPl<ՎmbJC:y>0ĚJ+*v! xEEy 3TⅲkPbܴe='wW j,!Jur3sc\0HG&Z=(363 !DkV)) ڽx?¿T< M6k'G/6Ke/l9k>p3 @6+KG#2]&}!Hly\yCVNNP;tr{ Q]4>1+j_=JsgA!&͋9ih?] >վ%Ur_ $'[f#A˙.bg'TEiDܳso??;ɕhs%QPK) BZfy*M>Ng B&$2;g*Idſ*G^XZ3'%?&>GX88ψք%瀫ڴO _:% hUk'"+\v'(yX h!Oca .4d?P+nhlEk0q Wu~ ,ܒ@W;`ّ'-@Fa˗ʻe&  Rf -vqw XUL}1Df鬅n<RsYa&(PLur I6ѕpH2ouT)ׂŭ&S*osϐ,lOT%Z.;סٛGQv泣4JGGYlMNRIw,ݹtqO:!,)3@UFF sі`"HՂ wc%4DFrã owL n0axt6x7t]6Lp(m\޺$e(ɚT=8xl-a +E&DN@2"htKygcuϔx xel PklmzBӢ2bK=Zij;I]~AGd)|0l(e8gQ\cXާ}ѝMQ-bV{Lwב8X+7'Fct|SuVϽ52E!kL1:dGw])##W(hn!] L{m2,xjt#\",_i+x֕]jT* =`G#(D;qA~?_)i#?4OGq!@G<5 swC\B5*í+w×1ҌB,KfWyJ8&8 \(B5n};I%C&m$dvr.H@:7,n>m '7`D |W-j;>!23%Л[+ԸձׁUq#:آnX.qل3;Xh(7+nYB]_):. 028>cK `_-wBOb(HECN;44 g(nd*jLIyD@L3UЊ} GM ȫk +,DcWIVp }N^z痚=^?_ J#t,T®$Ug FJRa* Y~\QD;EwvS>vBblFL)9k$]$òic9{V_'R0T+~Z9~n kLPZq:]| z4