samba-client-32bit-3.6.3-141.1e>UAHINYŽ?W$j~Wv'^_aNʊLfi7k>8?d ! 8( A_u{     0&&&(89(:'>G$H(I,X0Y<\X]\^mbscdeflCsamba-client-32bit3.6.3141.1Samba Client UtilitiesSamba is a suite of programs that allows SMB/CIFS clients to use the Unix file space, printers, and authentication subsystem. The package named samba-client contains all programs that are needed to act as a Samba client. The binaries expect the configuration file to be found in /etc/samba/smb.conf For a more detailed description of Samba, check the samba-doc package or the Samba.org Web page at http://www.Samba.org/ Please check http://en.openSUSE.org/Samba for general information on Samba as part of SUSE Linux Enterprise or openSUSE products, links to binary packages of the most current Samba version, and a bug reporting how to. Source Timestamp: 3640 Branch: 3.6.3.SLE11_SP2Wwildcard2PopenSUSE 11.4openSUSEGPL-3.0+http://bugs.opensuse.orgProductivity/Networking/Sambahttp://www.samba.org/linuxx86_64/sbin/ldconfigPW5fe4a2026e3c6c5c061a4af46306da7frootrootsamba-3.6.3-141.1.src.rpmlibnss_wins.so.2samba-client-32bitsamba-client-32bit(x86-32)  @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ /bin/shrpmlib(PayloadFilesHavePrefix)rpmlib(CompressedFileNames)libc.so.6libc.so.6(GLIBC_2.0)libc.so.6(GLIBC_2.1)libc.so.6(GLIBC_2.1.3)libc.so.6(GLIBC_2.11)libc.so.6(GLIBC_2.2)libc.so.6(GLIBC_2.2.3)libc.so.6(GLIBC_2.2.4)libc.so.6(GLIBC_2.3)libc.so.6(GLIBC_2.3.3)libc.so.6(GLIBC_2.3.4)libc.so.6(GLIBC_2.4)libc.so.6(GLIBC_2.5)libc.so.6(GLIBC_2.8)libcom_err.so.2libdl.so.2libdl.so.2(GLIBC_2.0)libdl.so.2(GLIBC_2.1)libgssapi_krb5.so.2libk5crypto.so.3libkeyutils.so.1libkrb5.so.3liblber-2.4.so.2libldap-2.4.so.2libnsl.so.1libnsl.so.1(GLIBC_2.0)libresolv.so.2libresolv.so.2(GLIBC_2.2)librt.so.1librt.so.1(GLIBC_2.2)libtalloc.so.2libtdb.so.1libtevent.so.0libz.so.1rpmlib(PayloadIsLzma)4.0-13.0.4-14.4.6-14.8.0W @S@RpRg@R^R].@R].@R>QY@Q@QQɆ@Q@@QKQ(@Q@QQ>@Q>@Qzl@Qzl@Qo@QkQ\QAQ+R@Q@QQ@QEQ \QQPP9@PP@P+PP@PBPBPPP@P*P6@PoPoPoP{@PWPQPP@OjOjO O O@O!O@O@OOO@O OoOc+@OaO`@OKp@OB5O>A@Oanswers[]; (bso#9402).- s4:torture/smb2: improve the smb2.create.blob tes; (bso#9209). - lib/krb5_wrap: request enc_types in the correct order; (bso#9272). - Fix net ads join message for the dns domain; (bso#9326). - docs-xml: fix use of tag; (bso#9345). - s3-aio_pthread: Optimize aio_pthread_handle_completion; (bso#9359). - s3:winbind: Failover if netlogon pipe is not available; (bso#9386).- Ensure adding the winbind group never can fail.- Create ntadmin group only if it doesn't yet exist.- quota: Don't force the block size to 512; (bso#3272). - Fix poll replacement to become a msleep replacement; (bso#8107). - Fix wrong test == syntax in configure; (bso#8146). - Fix --with(out)-sendfile-support option handling in autoconf; (bso#8344). - Fix builtin forms order to match Windows again; (bso#8632). - Fix RAW printing for normal users; (bso#8769); (bnc#790741). - Initialise ticket to ensure we do not invalid memory; (bso#8788). - Fix 'net rpc share allowedusers' to work with 2008r2; (bso#8966). - Fix crash on null pam change pw response; (bso#9013). - Connection to outbound trusted domain goes offline; (bso#9016). - Increase debug level for info that the db is empty; (bso#9112). - 'smbclient' can't connect to a Windows 7 server using NTLMv2; (bso#9117). - Winbind can't fetch user or group info from AD via LDAP; (bso#9147). - Open printers with the right access mask; (bso#9154). - Fix makerpms.sh on RHEL; (bso#9165). - Remove non-existent option '-Y' from winbindd manpage; (bso#9171). - Add quota support for gfs2; (bso#9172). - Make SMB2 compound request create/delete_on_close/close work as Windows; (bso#9173). - Empty SPNEGO packet can cause smbd to crash; (bso#9174). - pam_winbind: Match more return codes when wbcGetPwnam has failed; (bso#9177). - Fix crash bug in idmap_hash; (bso#9188); (bnc#788159). - SMB2 Create doesn't return correct MAX ACCESS access mask in blob; (bso#9189). - Fix service control for non-internal services; (bso#9192). - Don't take 'state->te' as indication for "was_deferred"; (bso#9196). - Parse of invalid SMB2 create blob can cause smbd crash; (bso#9209). - Bad ASN.1 NegTokenInit packet can cause invalid free; (bso#9213). - Fix segfault in smbd if user specified ports out for range; (bso#9218). - Signing cannot be disabled for SMB2 by design, so fix the documentation instead; (bso#9222). - Fix NT_STATUS_IO_TIMEOUT during slow import of printers into registry; (bso#9231). - When setting a non-default ACL, don't forget to apply masks to SMB_ACL_USER and SMB_ACL_GROUP entries; (bso#9236). - lib-addns: ensure that allocated buffer are pre set to 0; (bso#9259). - Make tdb robust against shrinking tdbs and improper CLEAR_IF_FIRST restart; (bso#9268). - Add support for reloading systemd services; (bso#9280).- Warn via the smbd log if AppArmor and "wide links" are in use; (bnc#783719).- Backport FSCTL codes and fix segfault in smbstatus from master; (bso#9058). - Fix bad call to memcpy source3/registry/regfio.c; (bso#9065). - "Domain Users" incorrectly added as additional group on domain members; (bso#9066). - Use correct RID for "Domain Guests" primary group; (bso#9067). - Fix crash bug in smbd caused by a blocking lock followed by close; (bso#9084). - Fix smbclient/tarmode panic when connecting to Windows 2000 clients; (bso#9088). - Fix refreshing of Kerberos tickets in Winbind; (bso#9098). - Fix identification of idle clients in Winbind to avoid crashes and NDR parsing errors; (bso#9104). - Fix compilation with newer MIT Kerberos which hides internal symbols; (bso#9111). - Fix flooding the logs with records we don't find in pcap; (bso#9112). - Initialize the print backend after we setup winreg; (bso#9122). - Fix lprng job tracking errors; (bso#9123). - Fix setting of "inherited" bit on inherited ACE's; (bso#9124). - Fix Winbind panic if we couldn't find the domain; (bso#9135). - Make 'smbclient allinfo' show the snapshot list; (bso#9137). - Fix nfs quota support with Linux nfs4 mounts; (bso#9144). - Valid open requests can cause smbd assert due to incorrect oplock handling on delete requests; (bso#9150).- NMB registration for a duplicate workstation fails with registration refuse; (bso#9085); (bnc#770056).- Correct documentation of "case sensitive"; (bso#8552). - Printing fails in function cups_job_submit; (bso#8719). - Fix kernel oplocks when uid(file) != uid(process); (bso#8974). - Send correct responses to NT Transact Secondary when no data and no params for the Trans2 calls are set; (bso#8989). - Fix build without ads support; (bso#8996). - Don't turn negative cache entries into valid idmappings; (bso#9002). - Fix posix acl on gpfs; (bso#9003). - Make vfs_gpfs less verbose in get/set_xattr functions; (bso#9022). - Fix migrating printers while upgrading from 3.5.x; (bso#9026). - Fix typo in set_re_uid() call when USE_SETRESUID selected in configure; (bso#9034). - Using asynchronous IO with SMB2 can return NT_STATUS_FILE_CLOSED in error instead ofNT_STATUS_FILE_LOCK_CONFLICT; (bso#9040). - Fix resolving our own "Domain Local" groups; (bso#9052); (bnc#779269). - Fix build against CUPS 1.6; (bso#9055). - Fix bugs in SMB2 credit handling code; (bso#9057). - rpcclient: Fix bad call to data_blob_const; (bso#9062).- BuildRequire gcc, make, and patch; (bnc#771516).- ndr: fix push/pull DATA_BLOB with NDR_NOALIGN; (bso#9026); (bnc#770262).- Fix shell syntax in dhcpcd hook script; (bnc#769957).- resolve_ads() code can return zero addresses and miss valid DC IP addresses; (bso#8910). - Can't join XP Pro workstations to 3.6.1 DC; (bso#8373); (bnc#787983). - winbind can hang as nbt_getdc() has no timeout; (bso#8953). - Fix crash bug in dns_create_probe when dns_create_update fails; (bso#8627) - s3-pid: Catch with pid filename's change when config file is not smb.conf; (bso#8714). - Possible memory leaks in the main Samba process; (bso#8970). - s3: Fix uninitialized memory read in talloc_free(); (bnc#764577). - Treat exit_server_cleanly() as a "clean" shutdown; (bso#8971). - Avoid crash with MIT krb5 1.10.0 in gss_get_name_attribute(); (bso#8988). - Winzip occasionally can not read files out of an open winzip dialog; (bso#8311). - s3-winbindd: call dump_core_setup after command line option has been parsed; (bso#8975). - Directory group write permission bit is set if unix extensions are enabled; (bso#8972). - s3: remove dependency on automake for "make everything"; (bso#8978). - sd_has_inheritable_components segfaults on an SD that se_access_check accepts; (bso#8811). - smbclient's tarmode insists on listing excluded directories; (bso#8922). - Notify code can miss a ChDir; (bso#8998). - s3:smbd: add a fsp_persistent_id() function; (bso#8995).- s3: Fix a segfault with debug level 3 on Solaris; (bso#8861). - s3: wbinfo --lookup-sids "" crashes winbind; (bso#8904). - smbd crashes when deleting directory and veto files are enabled; (bso#8837). - winbind_krb5_locator only returns one IP address; (bso#8897). - Wrong assertion/comparison: Compare value not pointer; (bso#8859). - Inconsistent (with manpage) command-line switch for "help" in smbtree; (bso#8831). - Fix incorrect debug statement. - Setting traverse rights fails to enable directory traversal when acl_xattr in use; (bso#8857). - Syslog broken owing to mistyping of debug_settings.syslog; (bso#8877). - s3/ldap: remove outdated netscape ds 5 schema file; (bso#8869). - s3-docs: fixes several typos; (bso#7938). - s3-VFS: Fix building out-of-tree modules; (bso#8822). - s3-docs: Add hint that setting "profile acls = yes" on normal shares can cause trouble; (bso#7930). - s3-pam_winbind: Fix the build with a newer iniparser library; (bso#8915). - Avoid null dereference in initialize_password_db(); (bso#8920). - s3:registry: implement values_need_update and subkeys_need_update in the smbconf backend. - s3:registry:reg_api: fix reg_queryvalue to not fail when values are modified while it runs. - s4:torture:rpc:spoolss: also initialize driverName before checking it in test_PrinterData_DsSpooler(). - s3:registry: multiple cleanups, fixes, and optimisations. - s3:auth/server_info: the primary rid should be in the groups rid array; (bso#8798). - s3-printing: Add new printers to registry; (bso#8554); (bso#8612); (bso#8748). - Fix the overwriting of errno before use in a DEBUG statement and use the return value from store_acl_blob_fsp rather than ignoring it; (bso#8945). - s3-auth: Don't lookup the system user in pdb; (bso#8944). - s3-passdb: Fix negative SID->uid/gid cache handling; (bso#8952). - Fix typo in pam_winbindd code; (bso#8957). - Fix remove_duplicate_addrs2 previously it could leave zero addresses in the list; (bso#8910). - Slow but responsive DC can lock up winbindd; (bso#8943). - Broken processing of %U with vfs_full_audit when force user is set; (bso#8882).- Attempt to use samlogon validation level 6; (bso#7945); (bnc#741623).- Add PreReq /etc/init.d/nscd to the winbind package; (bnc#759731).- Recover from ncacn_ip_tcp ACCESS_DENIED/SEC_PKG_ERROR lsa errors; (bso#7944); (bnc#755663). - Fix lsa_LookupSids3 and lsa_LookupNames4 arguments.- docs-xml: fix default name resolve order; (bso#7564). - s3-aio-fork: Fix a segfault in vfs_aio_fork; (bso#8836). - docs: remove whitespace in example samba.ldif; (bso#8789). - s3-smbd: move print_backend_init() behind init_system_info(); (bso#8845); (bnc#730769). - s3-docs: Prepend '/' to filename argument; (bso#8826).- Restrict self granting privileges where security=ads for Samba post-3.3.16; CVE-2012-2111; (bnc#757576).- Remove all precompiled idl output to ensure any pidl changes take effect; (bnc#757080).- Samba pre-3.6.4 are affected by a vulnerability that allows remote code exe- cution as the "root" user; PIDL based autogenerated code allows overwriting beyond of allocated array; CVE-2012-1182; (bso#8815); (bnc#752797).- s3-winbindd: Only use SamLogonEx when we can get unencrypted session keys; (bso#8599). - Correctly handle DENY ACEs when privileges apply; (bso#8797).- s3:smb2_server: fix a logic error, we should sign non guest sessions; (bso8749). - Allow vfs_aio_pthread to build as a static module; (bso#8723). - s3:dbwrap_ctdb: return the number of records in db_ctdb_traverse() for persistent dbs; (#bso8527). - s3: segfault in dom_sid_compare(bso#8567). - Honor SeTakeOwnershiPrivilege when client asks for SEC_STD_WRITE_OWNER; (bso#8768). - s3-winbindd: Close netlogon connection if the status returned by the NetrSamLogonEx call is timeout in the pam_auth_crap path; (bso#8771). - s3-winbindd: set the can_do_validation6 also for trusted domain; (bso#8599). - Fix problem when calculating the share security mask, take priviliges into account for the connecting user; (bso#8784).- Fix crash in dcerpc_lsa_lookup_sids_noalloc() with over 1000 groups; (bso#8807); (bnc#751454).- Remove obsoleted Authors lines from spec file for post-11.2 systems.- Make ldapsmb build with Fedora 15 and 16; (bso#8783). - BuildRequire libuuid-devel for post-11.0 and other systems. - Define missing python macros for non SUSE systems. - PreReq to fillup_prereq and insserv_prereq only on SUSE systems. - Always use cifstab instead of smbfstab on non SUSE systems.- Ensure AndX offsets are increasing strictly monotonically in pre-3.4 versions; CVE-2012-0870; (bnc#747934).- Add SERVERID_UNIQUE_ID_NOT_TO_VERIFY; (bso#8760); (bnc#741854).- s3-printing: fix crash in printer_list_set_printer(); (bso#8762); (bnc#746825).- s3:winbindd fix a return code check; (bso#8406).- s3: Add rmdir operation to streams_depot; (bso#8733).- s3:smbd:smb2: fix an assignment-instead-of-check bug conn_snum_used(); (bso#8738); CVE-2013-0454; (bnc#811975).- s3:auth: fill the sids array of the info3 in wbcAuthUserInfo_to_netr_SamInfo3(); (bso#8739).- s3:client: ignore SMBecho errors (the server may not support it); (bso#8139).- Be more strict when using PAM_AUTH API from winbind if Kerberos auth is enabled and don't unintentionally use a bogus domain name; (bso#8734).- smbclient fails with posix large reads; (bso#8727).- Use the smbfs init script on versions pre-11.3, or cifs in later versions; (bnc#744614).- s3: Compile IDL files in autogen, some configure tests need this.- Fixes various deadlocks in if-up.d / if-down.d when running under systemd; (bnc#732395).- Update to 3.6.3. + Fix memory leak in parent smbd on connection; CVE-2012-0817; (bso#8724); (bnc#743986).- Use spdx.org compliant license names for all packages.- Update to 3.6.2. + Make Winbind receive user/group information (bug #8371). + Several SMB2 fixes. + Fix a crash bug in the spoolss code. + Add new contributing FAQ announcing acceptance of corporate (C). + DeletePrinterDriverEx deletes files in use; (bso#4942); (bnc#742504). + Fix cli_write_and_x() against OS/2 print shares; (bso#5326). + Fix 'smbclient tar' for files greater than 8GB on BE machines; (bso#563); (bnc#726145). + Remove pointless use_memory_krb5_ccache; (bso#7465). + Fix perl path; (bso#8176). + Grant credits in async interim responses (SMB2); (bso#8357). + Make Winbind receive user/group information; (bso#8371). + Fix Windows XP clients crashing smbd process every once in a while; (bso#8384); (bnc#731571). + Make VFS op "streaminfo" stackable; (bso#8419). + Add an allocation pool to idmap_autorid; (bso#8444). + Fix SEGFAULT from net registry export on not zero terminated REG_SZ values; (bso#8528). + Make DSO_EXPORTS_CMD more portable; (bso#8531). + readlink() on Linux clients fails if the symlink target is outside of the share; (bso#8541). + smbclient posix_open command fails to return correct info on open file; (bso#8542). + winbind_samlogon_retry_loop ignores logon_parameters flags; (bso#8548). + Fix setting the machine account password; (bso#8550). + Make SMB2 handle compound request headers in the same way as Windows; (bso#8560). + Password change settings not fully observed; (bso#8561). + Fix double free error in talloc; (bso#8562). + Fix alignment in the non-extended-security negprot; (bso#8573). + Add systemd service files; (bso#8575). + Add systemd service files; (bso#8575). + smb2_flush: Don't send uninitialized memory; (bso#8579). + Enable inotify if sys or kernel inotify is available; (bso#8580). + Increase a debug level; (bso#8585). + libsmb: Only align unicode pipe_name; (bso#8586). + Fix marshalling of samr_ChangePasswordUser3; (bso#8591). + Don't limit the number of open dptrs for SMB2; (bso#8592). + Fix a crash bug in cldap_socket_recv_dgram(); (bso#8593). + Make cldap work over IPv6; (bso#8600). + Fix intermittent print job failures caused by character conversion errors; (bso#8606). + Improve configure.in so it can be used outside the Samba source tree; (bso#8607). + Winbind: Don't fail on users without a uid; (bso#8608). + Ensure we correctly calculate reply credits over all returned SMB2 replies; (bso#8614). + Fix migrate printer code; (bso#8618). + Fix crash bug when trying to browse Samba printers; (bso#8623). + libsmb: Don't duplicate Kerberos service tickets; (bso#8628). + POSIX ACE x permission becomes rx following mapping to and from a DACL; (bso#8631). + When returning an ACL without SECINFO_DACL requested, we still set SEC_DESC_DACL_PRESENT in the type field; (bso#8636). + Fix the vfs_commit module; (bso#8639). + Add an update function for Winbind cache; (bso#8643). + vfs_acl_xattr and vfs_acl_tdb modules can fail to add inheritable entries on a directory with no stored ACL; (bso#8644). + Document the "ignore system acls" option of vfs_acl_xattr and vfs_acl_tdb vfs modules; (bso#8652). + Fix deleting a symlink if the symlink target is outside of the share; (bso#8663). + Fix renaming a symlink if the symlink target is outside of the share; (bso#8664). + Fix NT ACL issue; (bso#8673). + Fix buffer overflow issue with AES encryption in samba traffic analyzer; (bso#8674). + Fix Winbind segfault if we can't map the last user; (bso#8678). + recvfile code path using splice() on Linux leaves data in the pipe on short write; (bso#8679). + Try ctdbd_init_connection() as root; (bso#8684). + Packet validation checks can be done before length validation causing uninitialized memory read; (bso#8686). + Fix typo in 'net memberships' usage; (bso#8687). + libads: Fix malloc/talloc mismatch in ads_keytab_verify_ticket(); (bso#8692). + Make DeletePrinterDriverEx remove printer driver files; (bso#8697) (bnc#740810). + Fix major leak with SMB2 in connections.tdb; (bso#8710).- s3-spoolss: Pass the right pointer type; (bso#4942); (bnc#742504).- Use simplified smb signing infrastructure; (bnc#741623).- Use correct license, LGPLv3+ for libwbclient packages.- When returning an ACL without SECINFO_DACL requested, we still set SEC_DESC_DACL_PRESENT in the type field; (bso#8636).- Fix incorrect types in the full_audit VFS module. Add null terminators to audit log enums; (bnc#742885).- Prefix print$ path on driver file deletion; (bso#8697); (bnc#740810). - Fix printer_driver_files_in_use() call ordering; (bso#4942); (bnc#742504).- Buffer overflow issue with AES encryption in samba traffic analyzer; (bso#8674). - NT ACL issue; (bso#8673). - Deleting a symlink fails if the symlink target is outside of the share; (bso#8663). - connections.tdb - major leak with SMB2; (bso#8710).- Renaming a symlink fails if the symlink target is outside of the share; (bso#8664).- Intermittent print job failures caused by character conversion errors; (bso#8606). - ads_keytab_verify_ticket mixes talloc allocation with malloc free; (bso#8692). - libcli/cldap: fix a crash bug in cldap_socket_recv_dgram(); (bso#8593). - s3:lib/ctdbd_conn: try ctdbd_init_connection() as root; (bso#8684). - s3-printing: fix migrate printer code; (bso#8618). - Packet validation checks can be done before length validation causing uninitialized memory read; (bso#8686).- net memberships usage info was wrong; (bso#8687). - s3-libsmb: Don't duplicate kerberos service tickets; (bso#8628). - Recvfile code path using splice() on Linux leaves data in the pipe on short write; (bso#8679). - s3-winbind: Fix segfault if we can't map the last user; (bso#8678). - vfs_acl_xattr and vfs_acl_tdb modules can fail to add inheritable entries on a directory with no stored ACL; (bso#8644). - s3/doc: document the ignore system acls option of vfs_acl_xattr and vfs_acl_tdb; (bso#8652). - Winbind can't receive any user/group information; (bso#8371). - s3-winbind: Add an update function for winbind cache; (bso#8643). - s3: Attempt to fix the vfs_commit module. - POSIX ACE x permission becomes rx following mapping to and from a DACL; (#bso#8631). - s3:libsmb: only align unicode pipe_name; (bso#8586). - s3-winbind: Don't fail on users without a uid; (bso#8608). - Crash when trying to browse samba printers; (bso#8623). - talloc: double free error; (bso#8562). - cldap doesn't work over ipv6; (bso#8600). - s3:libsmb: fix cli_write_and_x() against OS/2 print shares; (bso#5326). - SMB2: not granting credits for all requests in a compound request; (bso#8614). - smb2_flush sends uninitialized memory; (bso#8579). - Password change settings not fully observed; (bso#8561). - s3:smb2_server: grant credits in async interim responses; (bso#8357). - s3:smbd: don't limit the number of open dptrs for smb2; (bso#8592). - samr_ChangePasswordUser3 IDL incorrect; (bso#8591). - idmap_autorid does not have allocation pool; (bso#8444). - Add systemd service files. - s3:libsmb: the workgroup in the non-extended-security negprot is not aligned; (bso#8573). - s3-build: Fix inotify detection; (bso#8580). - SMB2 doesn't handle compound request headers in the same way as Windows; (#bso8560). - Disconnecting clients swamp the logs; (bso#8585). - s3-netlogon: Fix setting the machinge account password; (bso#8550). - winbind_samlogon_retry_loop ignores logon_parameters flags; (#bso8548). - smbclient posix_open command fails to return correct info on open file; (bso#8542). - readlink() on Linux clients fails if the symlink target is outside of the share; (bso#8541). - s3-netapi: remove pointless use_memory_krb5_ccache; (bso#7465). - s3:Makefile: make DSO_EXPORTS_CMD more portable; (bso#8531). - s3:registry: fix the test for a REG_SZ blob possibly being a zero terminated ucs2 string; (bso#8528). - Make VFS op "streaminfo" stackable; (bso#8419).- Fix incorrect perfcount array length calculations; (bnc#739258).- BuildRequire autoconf to avoid implicit dependency for post-11.4 systems.- Remove call to suse_update_config macro for post-11.4 systems.- Use samba.org for the ldapsmb source location.- Fixing libsmbsharemode dependency on ldap and krb5 libs in Makefile; (bnc #729516).- Do not map POSIX execute permission to Windows FILE_READ_ATTRIBUTES; (bso#8631); (bnc#732572).- Add ldap to Should-Start and Stop of the smb init script; (bnc#730046).- Fix smbd srv_spoolss_replycloseprinter() segfault; (bso#8384); (bnc#731571).- Fix pam_winbind.so segfault in pam_sm_authenticate(); (bso#8564).- Fix smbclient >8GB tars on big endian machines; (bso#563); (bnc#726145).- Fix typo in net ads join output; (bnc#713135).- Ignore a potentially missing AppArmor snippet helper script; (bnc#725256).- Update to 3.6.1. + Fix smbd crashes triggered by Windows XP clients; (bso#8384). + Fix a Winbind race leading to 100% CPU load; (bso#8409). + Several SMB2 fixes. + The VFS ACL modules are no longer experimental but production-ready. + Fix 'net ads join -k' when KRB5CCNAME is not set; (bso#7465). + smb_acl_to_posix: ACL is invalid for set (Invalid argument); (bso#7509). + Return error of cli_push when 'put - /some/file' is used; (bso#7551). + Fix usage of cli_errstr(); (bso#7864). + Fix 'widelinks' regression; (bso#8229). + Empty notify servername; (bso#8236). + Add man vfs_aio_fork; (bso#8256). + smb2: smbd logs "Invalid SMB packet: first request: 0x0008" and crashes; (bso#8334). + Add a fallback for missing open&x support in MAC OS/X Lion; (bso#8338). + While migrating forms, don't fail if the form already exists; (bso#8351). + OS/2 sends an unexpected write&x/read&x chain; (bso#8360). + Fix build of vfs_prealloc on SLES8; (bso#8363). + Fix the build of gpfs.c on RHEL 6.0 with gpfs 3.4.0-4; (bso#8364). + Fix the fallback to the deprecated spelling idmap:script; (bso#8368). + Fix vfs_chown_fsp; (bso#8370). + Fix smbd crashes triggered by Windows XP clients; (bso#8384). + Fix smbclient access to NT4 shares; (bso#8385). + Optimize serverid_exists() for Solaris; (bso#8395). + registry/reg_format.c must include includes.h; (bso#8401). + SMB2 server can return requests out-of-order when processing a compound request; (bso#8407). + Fix a Winbind race leading to 100% CPU load; (bso#8409). + Fix "saving as" of MS Office 2007 (Word) documents on Samba shares with SMB2; (bso#8412). + Fix 'getent group' if trusted domains are not reachable; (bso#8420). + Fix infinite loop in ACL module code; (bso#8422). + Fix wrong reply to DHnC (durable handle reconnect); (bso#8428). + Compound SMB2 requests on an IPC connection can corrupt the reply stream; (bso#8429). + Fix segfault in iconv.c; (bso#8433). + NFSv4 DENY ACLs always include SYNCHRONIZE flag - blocking renames; (bso#8442). + Be smarter about setting default permissions when a ACL_USER_OBJ isn't given; (bso#8443). + Check the wct of the incoming SMBnegprot responses; (bso#8452). + Fix smbclient segfaults when dialect option -m is used for legacy dialects; (bso#8453). + Fix uninitialized memory problem in group_sids_to_info3; (bso#8455). + Samba PDC is looking up only primary user group; (bso#8455). + IE9 on Windows 7 cannot download files to samba 3.5.11 share; (bso#8458). + smb2_find uses a hard coded max reply size of 0x10000 instead of smb2_max_trans; (bso#8473). + SMB2 create doesn't cope with an Apple client using NULL blob in create; (bso#8474). + Don't call smbd_terminate_connection in smb2_validate_message_id(); (bso#8476). + Samba asserts when SMB2 client breaks the crediting rules; (bso#8476). + Map to guest can return uninitialized blob of data; (bso#8477). + acl_xattr can free an invalid pointer if no blob is loaded; (bso#8480). + DFS breaks zip file extracting unless "follow symlinks = no" set; (bso#8493). + Remove "experimental" label on VFS ACL modules; (bso#8494). + SMB2_OP_CANCEL requests don't have to be signed; (bso#8503). + smbd doesn't correctly honor the "force create mode" bits from a cifsfs create; (bso#8507). + Read-only handles on SAMR allow SAMR_DOMAIN_ACCESS_CREATE_USER; (bso#8509). + Disallow "." in can_set_delete_on_close(); (bso#8515). + SMB2 create call returns incorrect file allocation size; (bso#8518). + Fix SMB2 SMB2_OP_GETINFO and SMB2_OP_IOCTL parsing requirements; (bso#8520). + Winbind cache timeout expiry test was reversed; (bso#8521).- s3/doc: add man page for aio_fork vfs module.- Fix uninitialized memory problem in group_sids_to_info3; (bso#8455).- s3: Samba PDC is looking up only primary user group; (bso#8455).- Add script to create or update an AppArmor sniplet with permissions for all Samba shares; (bnc#688040).- Add "ldapsam:login cache" parameter to allow explicit disabling of the login cache; (bnc#723261).- Retain the smbd startproc return value for correct startup status reporting. unset was incorrectly being called prior to rc_status; (bnc#723724).- Prevent deadlock in systemd triggered by if-down.d handler on shutdown; (bnc#721598).- smb2_find uses a hard coded max reply size of 0x10000 instead of smb2_max_trans; changed defaults and documentation (bso8473).- Empty CIFS share can be blocked for other clients by deleting it via empty path (DELETE_PENDING until the last client); (bso#8515).- winbindd cache timeout expiry test was reversed; (bso#8521).- Fix SMB2 SMB2_OP_GETINFO and SMB2_OP_IOCTL parsing requirements; (bso#8520).- s3:smb2_create: fix allocation size return value when opening existing files; (bso#8518).- SMB2 create doesn't cope with an Apple client using NULL blob in create; (bso#8474).- NFSv4 DENY ACLs always include SYNCHRONIZE flag - blocking renames; (bso#8442).- s3-docs: Fix bug (bso#7908) and typo.- Return error of cli_push when 'put - /some/file' is used; (bso#7551).- Read-only handles on SAMR allow SAMR_DOMAIN_ACCESS_CREATE_USER; (bso#8509).- smbd doesn't correctly honor the "force create mode" bits from a cifsfs create; (bso#8507).- Default user entry is set to minimal permissions on incoming ACL change with no user specified; (bso#8443).- smb_acl_to_posix: ACL is invalid for set (Invalid argument); (bso#7509).- Handle the SECINFO_LABEL flag in the same was as Win2k3; enable Microsoft Internet Explorer 9 on Windows 7 to download files; (bso#8458).- DFS breaks zip file extracting unless "follow symlinks = no" set; (bso#8493).- s3-docs: Fix typos.- s3:smb2_server: SMB2_OP_CANCEL requests don't have to be signed; (bso#8503).- Remove "experimental" label on VFS ACL modules; (bso#8494).- acl_xattr can free an invalid pointer if no blob is loaded; (bso#8480).- s3-smbd: asserts when SMB2 client breaks the crediting rules; (bso#8476).- s3-libnet: allow to use default krb5 ccache in libnet_Join/libnet_Unjoin; (bso#7465).- smb2_find uses a hard coded max reply size of 0x10000 instead of smb2_max_trans; (bso#8473).- s3-netapi: allow to use default krb5 credential cache for libnetapi users.- s3-docs: document -k switch in net manpage.- Map to guest can return uninitialized blob of data; (bso#8477).- s3-registry: registry/reg_format.c must include includes.h; (bso#8401).- smbclient segfaults when option -m is used for legacy dialects; (bso#8453).- Fix 'widelinks' regression intro'd in 3.2; (bso#8229).- Compound SMB2 requests on an IPC connection can corrupt the reply stream; (bso#8429).- s3-spoolss: Fix bug forms migration; (bso#8351).- s3:libsmb: check the wct of the incoming SMBnegprot responses; (bso#8452).- s3: Do not fork the echo handler for smb2; (bso#8334).- s3-spoolss: Fix bug empty notify servername; (bso#8236).- SMB2 server can return requests out-of-order when processing a compound request; (bso#8407).- Remove smb child crash fix. The issue had been fixed upstream differently.- BuildRequire ctdb-devel version greater than 1.0.105 for post-10.0 systems.- Fix samba duplicates file content on appending. Move posix case semantics out from under the VFS; (bso#6898); (bnc#681208).- Make winbind child reconnect when remote end has closed, fix failing sudo; (bso#7295); (bnc#569721).- Spec file cleanup as suggested by the spec-cleaner tool. + Make all BuildRequires, PreReq, and Provides a separate line. + Use %{buildroot} instead of ${RPM_BUILD_ROOT}. + Use straight commands instead of macros (make, install). + Use -p in post and postun if we only call one command. + Use %{_localstatedir} instead of %{_var} in the filelist. + Remove superfluous AutoReqProv on lines.- Remove %release from all Provides.- Fix segfault in iconv.c which caused a null pointer dereference; (bso#8433).- Use /var/run for the cifs state file in the init script too; (bnc#710304).- Microsoft Word from Microsoft Office 2007 fails to save as on a share with SMB2; (bso#8412).- Use sys_write and sys_read in fork_domain_child to fix a winbind race leading to 100% CPU usage; (bso#8409).- Fix wrong reply to smb2 durable handle reconnect (DHnC) request; (bso#8428).- Fix infinite loop in ACL module code; (bso#8422).- Fix getent group if trusted domains are not reachable; (bso#8420).- smbclient can't access a NT4 share since 3.6.0; (bso#8385).- Optimize serverid_exists() for Solaris; (bso#8395).- talloc: + check block count after references test. + added test suite for talloc_free_children(). + license info erratum in the manpage. + fix typos and better differentiation between versions 1 and 2. + preserve context name on talloc_free_children(). + ensure the sibling linked list remains valid during a free.- vfs_chown_fsp returned in the wrong directory; (bso#8370).- Remove irritating "." targets when recent system libs exist; (bso#8369).- Correctly initialize "idmap config * : script" with NULL; (bso#8368).- Add missing include to suppress compiler warnings; (bso#8365).- Point the chain offset beyond the current request; (bso#8360).- Fix gpfs vfs module build; (bso#8364).- Make vfs_prealloc even build on older systems; (bso#8363).- Do central cli_set_error and return the actual NTSTATUS; (bso#7864).- Add a fallback for missing open&x support in OS/X Lion; (bso#8338).- Update to 3.6.0. + BUG 7462: Make SA_RESETHAND conditional on its existance. + BUG 8303: db_ctdb_send_schedule_for_deletion() is not defined. + BUG 8324: smbclient cannot list directories from a big-endian machine. + BUG 8326: WinXP cannot join a Samba3 domain with a 'even' hostname. + BUG 8327: Fix the reload of the configuration, also reload activated registry shares. + BUG 8328: Cleanup of idmap_tdb2 code. + BUG 8330: Fix NFSv4 ACL merging logic. + BUG 8335: File copy aborts with smb2_validate_message_id: bad message_id. + BUG 8341: Fix segfault in libsmbclient. + BUG 8343: Fix SMB2 crash reading with aio_fork beyond the end of file. + BUG 8347: Fix regression for HP-UX, AIX and OSF. + BUG 8357: Make sure we grant credits on async read/write operations. + BUG 8358: Fix a bug in run_poll_events(). + BUG 8362: Fix build issue on old glibc systems.- Remove references to disabled vscan build.- Add missing define, includes, and initialization to get_printing_ticket.- Use /var/run for the cifs state file; (bnc#710304).- Fix #ifdef CTDB_CONTROL_SCHEDULE_FOR_DELETION issue; (bso#8303).- File copy aborts with smb2_validate_message_id: bad message_id; (bso#8335).- Fix reload of the configuration and also reload activated registry shares; (bso#8327).- WinXP cannot join a Samba3 domain with a 'even' hostname; (bso#8326).- smbclient cannot list directories from a big-endian machine; (bso#8324).- Update to 3.6.0rc3. + BUG 7841: Explicitly pass domain_sid to wbint_LookupRids(). + BUG 7888: Deal with buggy 3.0 based PDCs. + BUG 8083: Fix "inherit owner = yes" with vfs_acl_xattr or vfs_acl_tdb module. + BUG 8102: Do not allow to change file ACLs from normal domusers. + BUG 8102: Do not allow to change file ACLs from normal domusers. + BUG 8193: Add new command 'enumerate_recursive'. + BUG 8195: Make rpc client code working against NT4 servers. + BUG 8211: Fix "inherit owner = yes" when "inherit permissions = yes" is set. + BUG 8213: Fixes in idmap_autorid. + BUG 8214: Fix smbd crash on printer driver upgrade. + BUG 8215: Fix Winbind unix username lookup. + BUG 8216: Make Winbind returning correct results with 'sids2xids'. + BUG 8217: Do not stat-check the share path in 'net conf addshare'. + BUG 8219: Fix SMB Panic from Windows 7 client. + BUG 8224: Fix the build on FreeBSD. + BUG 8226: Use c99 initializers which are supported by old gcc 2.95 compilers. + BUG 8230: Move .nmbd socket directory to non-hidden name PREFIX/var/nmbd. + BUG 8231: Fix crash bug in 'net cache get'. + BUG 8235: Fix smbd crash on startup caused by migrate_printer(). + BUG 8240: Fix Valgrind warnings in winreg/spoolss code. + BUG 8244: Fix copying files larger than 2 GB to a Samba share. + BUG 8247: Fix Coverity ID 2582: FORWARD_NULL. + BUG 8253: Fix Winbind panic if verify_idpool() fails. + BUG 8254: Fix "acl check permissions = no". + BUG 8260: Fix DCERPC responses with fragments larger than 1024 bytes. + BUG 8262: Fix build of vfs_commit. + BUG 8263: Fix build with --with-fake-kaserver or --with-vfs-afsacl. + BUG 8264: Fix Valgrind bugs in svcctl. + BUG 8276: Close all sockets attached to a subnet in close_subnet(). + BUG 8278: Fix smbd panic when CTDB is unhealthy. + BUG 8281: Fix build of examples/VFS/*. + BUG 8286: Fix smbd crash on premature end of smb2 conn. + BUG 8292: Fix a major architectural flaw in the SMB2 server code. + BUG 8293: Fix log file rotating in SMB2. + BUG 8304: Fix uninitialized variable in error path. + BUG 8305: Fix segfault in nmbd when using 'smbtree ...'.. + BUG 8307: brl_close_fnum does not call SMB_VFS_BRL_UNLOCK_WINDOWS on all locks. + BUG 8310: toupper_ascii() is broken on big-endian systems. + BUG 8314: Fix smbd crash with unknown user. + Mark 'time offset' parameter as deprecated.- The Samba Web Administration Tool (SWAT) versions 3.0.x to 3.5.9 are affected by a cross-site scripting vulnerability; CVE-2011-2694; (bso#8289); (bnc#708503).- The Samba Web Administration Tool (SWAT) versions 3.0.x to 3.5.9 are affected by a cross-site request forgery; CVE-2011-2522; (bso#8290); (bnc#705241).- Fixed the DFS referral response for msdfs root; (bnc#703655).- Fix CUPS print job IDs; (bso#7288); (bnc#701257).- Make use of the actual library version as part of the package name on post-11.3 systems only.- Fix winbind internal error; (bso#7636); (bnc#659424).- Improve ctdb vacuuming performance with use of SCHEDULE_FOR_DELETION; (bnc#705170).- Specify nmbdsocketdir at configure time; (bnc#700953).- Build the tdb, talloc, and tevent libraries ahead of anything else.- Update to 3.6.0rc2. + BUG 6911: Fix Kerberos authentication from Vista to Samba. + BUG 8166: Don't lockout users when offline. + BUG 8200: Add support for multiple writeable ldap idmap domains. + BUG 8148: Default to protocol version 2 for SMB Traffic Analyzer. + BUG 7054: Fix X account flag when "pwdlastset" is "0". + BUG 8144: Fix setting timestamp when touching files with CIFS clients. + BUG 8153: Fix setting up getaddrinfo on IPv6-only machines. + BUG 8156: Fix 'net ads join' using the user's Kerberos ticket. + BUG 8157: Fix parsing a cups printcap file. + BUG 8175: Fix smbd deadlock. + BUG 8189: Support shadow copy display over SMB2. + BUG 8197: Winbind does not properly detect when a DC connection is dead. + BUG 8203: Winbind needs to reset the DC connection if an RPC times out.- Make cupsaddsmb fill printers location; (bso#8132); (bnc#698209).- Add "winbind max clients" parameter to remove 200-client limit; (bnc#697461).- Disable logon cache for password lockout consistency when running in a cluster; (bnc#694836).- Fix logon of AD users with many group memberships; (bso#6911); (bnc#657026).- Don't lockout users while offline; (bso#8166); (bnc#692607).- Update to 3.6.0rc1. + BUG 8111: CIFS VFS: Fix unexpected error on SMB posix open. + BUG 8112: POSIX extension opens of a directory are denied with EISDIR. + BUG 8132: Fix filling printers location field when using cups. + Remove fstrings from client struct. + BUGFIX when converting from safe_strcpy to strlcpy. + Fix off-by-one calculations with strlcpy. + Ensure we always write the correct incoming mid into the share mode table entries. + Fix the SMB2 oplock showstopper. + Convert user-specified domain to uppercase in libsmb. + Fix Coverity CID #2302: FORWARD_NULL. + Fix cups_pull_comment_location(). + Fix double free of cups request. + Make cups_pull_comment_location() work again. + Fix potential crash bug in display_print_driver3(). + Properly clean up in pthreadpool_init in case of failure. + Make plaintext session setup async. + Reduce fd load in Winbind children. + Avoid a potential 100% CPU loop in Winbind. + Tune broadcast namequeries for unique names. + Properly deal with exited winbind children. + Fix dup_smb2_vec3. + Fix return check in nss_wins.- Fix to renew the kerberos ticket in samba after expiry; (bnc#669949).- Fix a 100% CPU loop when ctdbd dies during a traverse; (bnc#693945).- Make dhcpcd hook BOOTPROTO check cover dhcp6 too; (bnc#691969).- Handling of large (> 256 bytes) ntlmv2 blobs in winbind; (bnc#529946).- Package static libraries with 0644 permissions.- Add Requires libtalloc-devel to libldb-devel and libtevent-devel.- Rename libldb0 to libldb1 as 1 is the current major version of the library. - Add libldb1 and libtevent0 to baselibs.conf.- Don't call the suse_update_config macro before building lib ldb and tevent.- Update to 3.6.0pre3. + Listen on IPv6 addresses with IPV6_ONLY; (bso#7383). + Fix wrong output in 'smbget'; (bso#8066). + "inherit owner = yes" doesn't interact correctly with vfs_acl_xattr or vfs_acl_tdb module; (bso#8083). + rpccli_samr_chng_pswd_auth_crap segfaults if any input blobs are null; (bso#8088). + setpwent() actually does endpwent() and vice versa on FreeBSD; (bso#8099). + Fix the build of 'smbget' on HP NonStop; (bso#8106). + Fix build of tdb2. + Correctly detect and deny symlinks anywhere in a path (not just the last component) if "follow symlinks = no". + Fix timeout in rpc_pipe_open_tcp_port(). + Fix the build of "--with-profiling-data". + Fix Coverity IDs 986, 1340, 2047, 2299, 2307, 2325, 2335, 2336, 2470, 2471, 2478. + nsswitch: Add 'wbinfo --lookup-sids'. + nsswitch: Add 'wbinfo --sids-to-unix-ids'. + Fix smbd with the async echo responder. + Fix the build of vfs_gpfs.c. + Add a 10-second timeout for the 445 or netbios connection to a DC. + Many pthreadpool fixes. + Fix transaction recovery area for converted tdbs.- Add PreReq permissions to the krb-printing package.- Remove _libdir ldb and tevent from file list. - Explicitly state not to bundle talloc or tdb while ldb and tevent build.- Always use the actual library version as part of the package name. - Exclude shared python modules.- Fix printing from Windows 7 clients; (bso#7567); (bnc#687535).- Update pidl and always compile IDL at build time; (bnc#688810).- Update to 3.6.0pre2. + ID Mapping changes. + Implement SMB2 support. + Add an Endpoint Mapper daemon. + Make "rlimit_max below minimum Windows limit" notification less scary; (bso#6837). + Quota only shown when logged as root; (bso#7080). + Fix printing from Windows 7; (bso#7567). + Retry DNS updates when connection to one nameserver has failed; (bso#7690). + Unlink may unlink wrong file when hardlinks are involved; (bso#7863). + Fix 'nmbd --port'; (bso#7875). + cmd_spoolss_deletedriver() returned without checking all architectures; (bso#7880). + Don't return "-1" on success in 'net rpc vampire keytab'; (bso#7899). + Fix cups pcap reload with no printers; (bso#7915). + Fix bug in chain_reply; (bso#7917). + Fix problems with "kernel oplocks" option set to "no"; (bso#7928). + Fall back for utimes calls; (bso#7940). + Catch lookup_names/sids schannel errors over ncacn_ip_tcp; (bso#7944). + Let winbind try to use samlogon validation level 6; (bso#7945). + Sgid bit lost on folder rename; (bso#7996). + Fix getting username in 'net rap session'; (bso#8009). + Fix inode generation so nautilus can count total dir size correctly; (bso#8010). + Use jenkins hash for str_checksum; (bso#8010). + Add explicit configure option whether or not to enable dmapi support; (bso#8033). + Fix smbclient segfault with Cyrillic netbios names; (bso#8040). + Fix file creation on OS/X; (bso#8042). + Add "--option" to 'testparm'. + Fix crash bug on smbd shutdown when using FOPENDIR(). + Ensure we don't return an incorrect access mask. + Fix bug against the new Mac client. + Fix leak in error path. + Fix error where Windows client spoolss returns WERR_INVALID_DATA. + Fix a segfault in the krb5 locator plugin. + Enable sharesec for registry shares. + Fix memory leak in "security=share" and "force user". + Add "net idmap check", a check and repair tool for the id mapping database. + Add new 'net idmap delete' command. + Fix segfault on missing input file in 'net idmap restore'. + Fix 'net usersidlist' not to skip every other user. + Fix potential crash bug in spoolss_PrinterEnumValues push path. + Internal restructuring. + Don't wipe out all printer drivers when only one should be deleted. + Fix winbindd_dual_pam_auth_samlogon() for NT4 domains. + Fix memory leak in print_cups.c. + Remove duplicate cups response processing code. + Follow force user/group for driver IO. + Initiate pcap reload from parent smbd. + Reload shares after pcap cache fill. + Fix numerous Coverity IDs (2041 and others). + Fix a memory leak in check_sam_security_info3. + Fix a segfault in the nss wrapper when libnss_winbind.so is not loadable. + Make "net sam list [users|workstations]" list only the right things. + Fix a potential memleak in secrets_fetch_trusted_domain_password. + Use the right credentials in check_netlogond_security. + Add support for AF_NETLINK addr notifications. + Fork multiple Winbind children per domain. + Fix a deadlock between smbd and ctdbd. + Add 'wbinfo --dc-info'. + Make "nmbd socket dir" configurable. + Fixed valgrind errors. + Fix a memleak in receive_getdc_response. + Don't grant SEC_STD_DELETE always to the owner of a file. + Fix segfaults on addrchange errors in Winbind. + Allow machine accounts as members in groupdb. + Add IPv6 support for the endpoint mapper. + Free unused memory in the rpc server. + Fix possible segfaults in svcctl server. + Fix possible segfault with client_id in rpc server. + Add a 'svcctl shutdown' function to rpc server. + Fix a resource leak in net_afs. + Fix a resource leak in smbta-util. + Fix possible resource leak in net_usershare. + Fix possible resource leak in 'smbget'. + Fix possible resource leak in 'smbfilter'. + Fix a possible null pointer dereference in smbd. + Ensure we send the direct levelII oplock break to the correct fid. + Fix private libdir and codepages paths. - Add RFC 3454 to the vendor files.- Fix idmap_tdb for big-endian systems such as ppc and s390; (bso#6901); (bnc#675978).- Fix smbclient -M NT_STATUS_PIPE_BROKEN failure; (bso#7635); (bnc#681913).- Replace jobs by _smp_mflags macro while calling make on post-11.4 systems.- Don't crash when publishing a single printer; (bnc#643119).- Carry error status in printer list IPC message, do not refresh printers if cups is unavailable; (bso#7994); (bnc#675478).- Define the libwbclient packages ahead of packages with a different version.- Use %_smp_mflags for parallel building.- Update to 3.5.8. + Fix Winbind crash bug when no DC is available; (bso#7730). + Fix finding users on domain members; (bso#7743). + Fix memory leaks in Winbind; (bso#7879). + Fix printing with Windows 7 clients; (bso#7567). + Fix 'testparm' return code when EOF in encountered in param name; (bso#3185). + Make "rlimit_max below minimum Windows limit" notification less scary; (bso#6837). + Fix "Your Password expires today" message for users of trusted domains; (bso#7066). + Fix maintaining of users' groups via UsrMgr; (bso#7262). + Fix 'net ads dns register' in Windows 2008 R2 domains; (bso#7356). + Raise debug level for "reduce_name: couldn't get realpath" messages; (bso#7409). + Fix updating the time on close in vfs_gpfs; (bso#7498). + Fix "log=>ndr_pull_error" in 'wbinfo -u' and 'wbinfo -g'; (bso#7594). + Handle Windows 9x adddriver calls without config file; (bso#7641). + Fix scalability problem with hundreds of printers; (bso#7656). + Fix memory leak in the netapi routines; (bso#7665). + Store unmodified copies of security descriptors in acl_xattr and acl_tdb modules; (bso#7716). + Fix incorrect unix mode_t caused by invalid client DOS attributes on create; (bso#7733). + Apply appropriate create masks when creating files with "inherit ACLs" set to true; (bso#7734). + Fix "dfree cache time" parameter; (bso#7744). + Fix a getgrent crash with many groups; (bso#7774). + Fix requesting lookups for BUILTIN sids; (bso#7777). + Fix smbd crash caused by expand_msdfs; (bso#7779). + Fix atime limit; (bso#7785). + vfs_scannedonly: Switch from mtime to ctime which is more reliable; (bso#7789). + Fix copying files from a SMB share using Gnome vfs and SMB signing; (bso#7791). + Make Winbind recover from a signing error; (bso#7800). + ACL inheritance cannot be disabled in vfs_acl_xattr/vfs_acl_tdb; (bso#7812). + Fix "force group" with ntlmssp guest session setup; (bso#7817). + vfs_fill_sparse() doesn't use posix_fallocate when strict allocate is on; (bso#7835). + Make WINBINDD_LOOKUPRIDS asking the right domain; (bso#7841). + Make WINBINDD_LOOKUPRIDS returning the domain name; (bso#7842). + Expand the local SAMs aliases; (bso#7843). + ntlm_auth: Support clients which offer a spnego mechs we don't support; (bso#7855). + Fix 'net ads dns register' in cluster setups; (bso#7871). + Fix 'nmbd --port'; (bso#7875). + Make 'rpcclient deldriver' delete drivers for all architectures; (bso#7880). + Fix flaky Winbind against Windows 2008; (bso#7881). + Fix SMB session setups with Kerberos against some closed source SMB servers; (bso#7883). + Fix stale lock in open_file_fchmod(); (bso#7892). + Fix sporadic Winbind panic in rpc query_user_list; (bso#7894). + Don't set SAMR_FIELD_FULL_NAME if we just want to set the account name; (bso#7896). + Don't return "-1" on success in 'net rpc vampire keytab'; (bso#7899). + Fix connections from WinCE; (bso#7917). + Fix opening MS Powerpoint files; (bso#7940). + Fix endless loops caused by inotify; (bso#7942). + Catch lookup_names/sids schannel errors over ncacn_ip_tcp; (bso#7944). + Let Winbind try to use samlogon validation level 6; (bso#7945). + Revalidate the pathname once re-constructed from a root fsp; (bso#7950).- Require a particular library version even if the major version is part of the package name. Using the same major version does not guarantee forward compatibility.- Fix a fd-leak in libwbclient at dlclose-time; (bso#7684); (bnc#668773).- Update to 3.5.7 + Protect against possible denial of service caused by memory corruption; CVE-2011-0719; (bso#7949); (bnc#670431).- Disable separate build of samba-doc for post-11.1 systems.- Protect against possible denial of service caused by memory corruption; CVE-2011-0719; (bso#7949); (bnc#670431).- Increase the log level for missing PIDs on SIGCHLD, printcap child processes are not added to the children PID list; (bnc#666460).- Do not require a particular library version if the major version is part of the package name.- Use the actual version numbers of the ldb, talloc, tdb, and tevent libraries on post-11.3 systems.- Abide by print$ share 'force user' & 'force group' settings when handling AddprinterDriver and DeletePrinterDriver requests; (bso#7921); (bnc#653353).- Remove pcap_cache_loaded asserts from (re)load_printers. pcap_cache_loaded() returns false if the pcap cache contains no printer entries. correct call ordering is already enforced. (bso#7836); (bnc#625936).- No longer force activation of the cifs service on post-11.3 systems. - Add X-UnitedLinux-Default-Enabled to the cifs init script on pre-11.4 systems. - Move the cifs init script nfs dependencies from Required to Should.- Recommend to install samba-krb-printing from samba-winbind on post-10.3 systems; (bnc#661845).- Fix error paths in cups_async_callback(), an empty cups printer list should not be treated as an error; (bnc#661842).- Abide by printcap cache time, reload parent smbd pcap cache on expiry; (bso#7836); (bnc#625936).- Fix race in cups async printer services reload; (bso#7836); (bnc#625936).- Don't tweak with baselibs.conf during %post if not present; (bnc#652620).- Don't make use of baselibs.conf on SUSE Linux Enterprise 10; (bnc#652620).- Don't use --tmpdir as this option isn't known by mktemp of SUSE Linux Enterprise 10; (bnc#652620).- vfs_fill_sparse() doesn't use posix_fallocate when strict allocate is on; (bso#7835).- Replace Requires samba-client by samba-gplv3-client in the gplv3 packages; (bnc#652620).- Fix Dolphin SMB share IO with SMB signing enabled; (bso#7791); (bnc#656112).- Add Conflicts to the samba-gplv3 main, client, doc, krb-printing, winbind, client-gplv2, and doc-gplv2 packages; (bnc#652620).- Add Provides samba-client-gplv2 and samba-doc-gplv2 to pre-3.2 versions; (bnc#652620).- Obsolete samba-client-gplv2 and samba-doc-gplv2; (bnc#652620).- Remove Provides samba-client:/usr/sbin/winbindd from the samba-gplv3-winbind package to avoide an accidental install trigger; (bnc#652620).- Add Provides samba-client to the samba-gplv3-client package; (bnc#652620).- Remove all Obsoletes from the samba-gplv3 packages and only keep the Provides samba; (bnc#652620).- Add fitting Conflicts to all samba-gplv3 packages; (bnc#652620).- Reduce unnecessary ldap round trips and eliminate invalid DN messages; (bnc#654719).- Exclude cifs-mount and ldapsmb from the samba-gplv3 build of SUSE Linux Enterprise 10 SP 3 and 4.- Add the _build_arch at the end of the vendor version suffix.- Provide and Obsolete samba-gplv3 to replace potentially installed packages.- Change package base name to samba-gplv3 for SUSE Linux Enterprise 10 SP 4. - Do not package libsmbclient and libsmbsharemodes.- Update to 3.5.6 + Fix auto printers with registry config; (bso#7280); (bnc#617153). + Fix SPNEGO auth when contacting Win7 system using Microsoft Live Sign-in Assistant; (bso#7577). + Fix 'net idmap restore' setting HWM to avoid duplicates; (bso#7578). + Fix "admin users" when using vfs_acl_xattr; (bso#7581). + Fix using cached credentials in ntlm_auth; (bso#7589). + Fix Winbind offline login; (bso#7590). + Fix Winbind internal error; (bso#7636). + Fix mknod/mkfifo failing with "No such file or directory"; (bso#7651). + Fix smbd changing mode of files on rename; (bso#7693). + Fix crash bug with invalid SPNEGO token; (bso#7694). + Fix smbd panic on invalid NetBIOS session request; (bso#7698). + Fix smbd crash caused by "%D" in "printer admin"; (bso#7541). + Fix 'smbclient -M'; (bso#7635). + Fix scalability problem with hundreds of printers; (bso#7656). + Fix crash bug in rpcclient; (bso#7688). + Fix file corruption when setting Samba "write wache wize"; (bso#7715).- Let startproc wait for nmb, smb and winbind pid files getting created on post-11.1 systems; (bnc#520036).- Include the reviewed french translation for pam_winbind; (bnc#499233).- Fix smbd crash with CUPS printers and no [printers] share defined; (bso#7297); (bnc#637755).- Fix printing from 64-bit windows clients; (bso#6888); (bnc#640870).- Fix baselibs.conf for libtalloc.- Fix buffer overflow in sid_parse() to correctly check the input lengths when reading a binary representation of a Windows Security ID (SID); CVE-2010-3069; (bso#7669); (bnc#637218).- Use cached ntlm password in libsmbclient. Prevent lockouts when kerberos tickets are lost; (bnc#602418); (bnc#606304).- Add a dependency on nfs to the smbfs/ cifs init scripts as they require the en_US locale and /usr might be on NFS.- Complete fix for trusts with Windows 2008R2 DCs.- Fix authentication dialogs when connecting to older systems; (bnc#632055).- Adjust position of conditional ldapsmb %package and %files definition.- Create the /var/run/samba directory on the fly and package it as %ghost.- Fix preexec scripts; (bso#7104); (bnc#632852).- Add missing netapi, smbclient, smbsharemodes, talloc, tevent, and wbclient pkgconfig files and BuildRequire pkgconfig; (bnc#632770).- BuildRequire python-devel for post-9.3 systems.- Only create precompiled headers for post-10.2 systems. - Remove mkinitrd scriptlets.- Add vfs_crossrename man page. - Call make basic and remove conditional proto target. - Increase libtevent version to 0.9.9. - Remove wbc_async header from the file list. - Remove remaining cifs-mount pieces from the spec file.- Fix printers not auto loading with registry config; (bso#7280); (bnc#617153).- Update to 3.6.0pre1. + SMB2 support is fully functional despite managing quota using the Microsoft management tools. + Internal Winbind passdb changes to use samr and lsa rpc pipe to get local user and group information. + The spoolss and the old RAP printing code have been completely overhauled and refactored. + The SMB Traffic Analyzer (SMBTA) VFS module got added.- Intilize workgroup of nmblookup as empty string.- Fix net ads join when using parent domain users; (bso#6364); (bnc#630812).- cifs: do not restart during dhcp lease renewal when IPaddress remains the same; (bnc#573246).- Fix "Too many open files" when trying to access large number of files; (bso#6837); (bnc#619787).- Update to 3.5.4. + Fix smbd crash when sambaLMPassword and sambaNTPassword entries missing from ldap (bug #7448). + Fix init_sam_from_ldap storing group in sid2uid cache (bug #7507). + Allow previous password to be stored and use it to check tickets; (bso#7099). + Make ea data checks identical for trans2open and trans2mkdir; (bso#7188). + Fix editing users' groups via UsrMgr; (bso#7262). + Fix Winbind over IPv6; (bso#7341). + Samba sends "raw" inode number as uniqueid with unix extensions; (bso#7410). + Fix printing large formats; (bso#7423). + Fix spnego returning incorrect mechListMIC string; (bso#7449). + Fix some crash bugs and missing error codes in AddDriver paths; (bso#7459). + Fix crash bug in _samr_QueryUserInfo{2} level 18; (bso#7479). + Fix 'not a string literal' warning in netdomjoin-gui; (bso#7500). + Fix calculation of st_blocks in vfs_streams_xattr; (bso#7503). + Fix numerous build issues; (bso#7504). + Fix session setup from linux kernel cifs clients with "sec=ntlmv2"; (bso#7517).- Remove all provides and obsoletes samba3 from the spec file. Packages with this base name have not been offered as part of a product.- Fix a NULL pointer dereference in smbd of the 3.4 code base; CVE-2010-1635; (bso#7229); (bnc#605935).- Address possible buffer overrun in chain_reply code of pre-3.4 versions; CVE-2010-2063; (bso#7494); (bnc#611927).- Update of the SMB Traffic Analyzer v2 VFS module- Fix trusts with Windows 2008R2 DCs; (bnc#613459); (bnc#599873); (bnc#592198); (bso#6697).- Update to 3.5.3. + Fix MS-DFS functionality; (bso#7339). + Fix a Winbind crash when scanning trusts; (bso#7389). + Fix problems with SIGCHLD handling in Winbind; (bso#7317). + Add replacement for IPV6_V6ONLY on linux systems with broken headers; (bso#7196). + Fix cups encryption setting; (bso#7263). + Fix exporting printers via 'cupsaddsmb' command; (bso#7277). + Fix SMB job IDs in CUPS job names; (bso#7288). + Fix segfault in mount.cifs; (bso#7315). + Make TIME_T_MAX defines consistent; (bso#7352). + Re-fix a bug with smbd serving a windows terminal server; (bso#7357). + Display an error on 'net conf import' failures; (bso#7378). + Fix bitmap leak in dptr_Close; (bso#7384). + Fix rename problems with full_audit VFS module; (bso#7398). + Fix setting of passwords via 'net rpc user password' command; (bso#7417). + Fix 'net rpc printer list' command; (bso#7418). + Rename mod_name to module_name; (bso#7421). - Fix unnecessary traversing winbindd_cache.tdb in SIGHUP handler. - Added EN ISO 216, A0 and A1 to builtin forms; (bso#7423). - Winbind not working over IPv6; (bso#7341).- Honor "interfaces" list in net ad dns register; (bnc#606947).- Exclude the RPM release from the vendor tag for openSUSE Factory; (bnc#604049).- Enable the build of the idmap tdb2 module; (bnc#600822).- BuildRequire keyutils-libs-devel for Fedora and post-RHEL4.- BuildRequire pkg-config for post-10.2 systems and else pkgconfig.- Add "net conf import" error messages; (bso#7378, bnc#598189).- Define cups_lib_dir %{_prefix}/lib/cups for post-11.2 systems; (bnc#575544).- Update to 3.5.2. + Fix smbd segfaults in _netr_SamLogon for clients sending null domain; (bso#7237). + Fix smbd segfaults in "waiting for connections" message; (bso#7251). + Fix an uninitialized variable read in smbd; (bso#7254); (bnc#605935); CVE-2010-1642. + Fix a memleak in Winbind; (bso#7278). + Fix Winbind reconnection to it's own domain; (bso#7295). + Fix segfault if hide files or veto files has no ".AppleDouble"; (bso#1206). + Fix parsing of the gecos field; (bso#5198). + Fix several printing issues; (bso#6727). + Fix valgrind warning; (bso#6814). + Fix race condition in mount.cifs that allows user to replace mountpoint with a symlink; (bso#6853). + Fix bug in vfs_scannedonly rmdir implementation; (bso#7075). + Fix handling of bad server data returns in client rpc_transport; (bso#7159). + Never mark external domains as internal in Winbind; (bso#7170). + Fix access by multi-threaded applications; (bso#7202). + Fix 'net share' command; (bso#7203). + Fix DN parsing name was always null; (bso#7204). + Signals are processed twice in child; (bso#7206). + Fix returning of group members with 'getent group'; (bso#7212). + Fix the build of net_afs.c with --fake-kaserver=yes; (bso#7216). + Make Winbind logs more verbose for troubleshooting; (bso#7225). + Fix a NULL pointer dereference in smbd; CVE-2010-1635; (bso#7229); (bnc#605935). + Fix automatic building of vfs_tsmsm if gpfs and dmapi are present; (bso#7231). + Fix race conditions in CTDB persistent transactions; (bso#7232). + Symlink delete fails but incorrectly reports success to client; (bso#7234). + Fix "printer admin" functionality; (bso#7255). + Fix value-needed calculation in_spoolss_EnumPrinterData(); (bso#7256). + Fix _winreg_QueryValue crash bugs and implement Windows behavior; (bso#7258). + Fix job management commands for CUPS queues; (bso#7269). + Fix smbd segfault if using vfs_acl_tdb; (bso#7283). + Fix core dump in 'ntlm_auth' with "gss-spnego" helper; (bso#7290). + Fix smbd crashes with CUPS printers and no [printers] share defined; (bso#7297). + Fix DOS attribute inconsistency with MS Office; (bso#7310). + Many disconnecting clients render clustered Samba unusuable for some time; (bso#7312). + Make 'net conf addshare' atomic; (bso#7313). + Eliminate race condition in creating/scanning sorted subkeys in the registry backend; (bso#7314). + Winbind possibly segfaults when trying a trusted domain without inbound trust; (bso#7316).- Add SMB Traffic Analyzer v2 VFS module.- Document "wide links" defaults to "no" in the smb.conf man page for versions pre-3.4.6; (bnc#577868).- Fix workgroup enumeration, for client printer and file share selection; (bso#6880); (bnc#586215).- Fix tdb validation for offline auth; (bnc#587014).- Fix "printer admin" functionality; (bso#7255).- An uninitialized variable read could cause an smbd crash; (bso#7254); (bnc#605935); CVE-2010-1642.- Ensure to have a valid talloc stackframe; (bso#7251).- _netr_SamLogon segfaults for clients sending NULL domain; (bso#7237).- Merge missing pam_winbind message translations; (bnc#499233).- Remove cifs-mount subpackage for post-11.2 systems as the tools are now part of the independent cifs-utils package.- Fix join of Windows 2008 domains; (bnc#567013).- Update to 3.5.1 and 3.4.7. + Fix security flaw on Linux platforms if built with libcap support allowing file system access even when permissions should have denied it; CVE-2010-0728; (bso#7222); (bnc#586683).- Fixed libldb.so link in libldb-devel.- Fix argc handling in net_share, making the command "net share" work again; (bso#7203); (bnc#584253).- Update to 3.5.0. + Fix duplicate sam and unix accounts; (bso#7145). + Keep the the correct negotiate_flags on the cli->dc structure; (bso#7160). + Avoid calling cli_alloc_mid twice in cli_smb_req_iov_send; (bso#7166). + Fix 'net ads dns' usage calls; (bso#7181). + Fix uninitialized variable in wkssvc_enumerateusers; (bso#7182).- Update to 3.4.6. + Change parameter "wide links" to default to "no"; it's also incompatible with "unix extensions"; (bso#7104); (bnc#577868). + Fix printing with 64 bit clients (bso#6888). + Fix core dump on 64 bit Linux (bso#7063). + Fix failing of smbd to respond to a read or a write caused by Linux asynchronous IO (aio) (bso#7067). + Fix string buffer overflow causing heap corruption in smbd (bso#7096). + Fix bogus ip address in SWAT; (bso#5885). + Fix vfs_full_audit; (bso#6557). + Use the first "uid" value; (bso#6157). + Fix large paged search with DirX LDAP servers; (bso#6981). + Fix crash bug in 'cifs.upcall'; (bso#6868). + Add cross option to samba_cv_linux_getgrouplist_ok; (bso#7047). + Fix DFS on AIX (maybe others); (bso#7052). + Fix pdb_search crash as non-root user; (bso#7068). + Fix unlocking of accounts from ldap; (bso#7072). + Fix vfs_expand_msdfs; (bso#7081). + Fix results of 'smbclient -L' with a large browse list; (bso#7098). + Normalize "Changing password for" msg IDs and STRs; (bso#7102). + Fix malformed require_membership_of_sid; (bso#7106). + Fix reading of large browselist; (bso#7122). + "mangling method = hash" can crash storing a name containing a '.'; (bso#7154). + Valgrind Conditional jump or move depends on uninitialised value(s) error when "mangling method = hash"; (bso#7155). + Fix listing of printjobs in Windows 7; (bso#7130). + Spoolss getprinterdriver2 level 101 marshalling is bad; (bso#7136). + Make idmap cache persistent for "ldapsam:trusted". + Also fill the memcache with sid<->id mappings in ldapsam_sid_to_id() not only the persistent idmap cache. + Shortcut uid_to_sid when "ldapsam:trusted = yes". + Make pdb_copy_sam_account also copy the group sid. + Shortcut gid_to_sid when "ldapsam:trusted = yes". + Speed up pdb_get_group_sid(). + Try to build the full unix_pw structure with ldapsam:trusted support. + Optimize ldapsam_alias_memberships() and cache ldap searches.- Update to 3.5.0rc3. + Change parameter "wide links" to default to "no"; it's also incompatible with "unix extensions"; (bso#7104); (bnc#577868). + Fix vfs_full_audit; (bso#6557). + Fix crash bug in 'cifs.upcall'; (bso#6868). + Fix duplicate initializer in the rmdir module; (bso#6876). + Fix printing with 64 bit clients; (bso#6888). + Add cross option to samba_cv_linux_getgrouplist_ok; (bso#7047). + Fix core dump on Ubuntu 8.04 64 bit; (bso#7063). + Fix failing of smbd to respond to a read or a write caused by Linux asynchronous IO (aio); (bso#7067). + Fix 'smbget' error status; (bso#7069). + Fix build of 'smbfilter'; (bso#7071). + Fix unlocking of accounts from ldap; (bso#7072). + Cliconnect gets realm wrong with trusted domains; (bso#7079). + Fix vfs_expand_msdfs; (bso#7081). + Fix storing of create time on directories in an EA in new create time code; (bso#7084). + Fix an early release of the global lock that can cause data corruption in libtdb; (bso#7085). + Fix string buffer overflow causing heap corruption in smbd; (bso#7096). + Fix results of 'smbclient -L' with a large browse list; (bso#7098). + Normalize "Changing password for" msg IDs and STRs; (bso#7102). + Fix malformed require_membership_of_sid; (bso#7106). + Add pdb_ldap performance fixes; (bso#7116). + Change ldap filter to what really was intended; (bso#7116). + Add new "nmbd bind explicit broadcast" parameter; (bso#7118). + Fix nmbd problems with socket address; (bso#7118). + Support large browselist; (bso#7119). + Fix reading of large browselist; (bso#7122). + Fix listing of printjobs in Windows 7; (bso#7130). + Owner of file not available with Kerberos; (bso#7139). + Fix IPv4/IPv6 problems; (bso#7140). + Fix get_acl_blob in the acl_tdb VFS module; (bso#7148). + "mangling method = hash" can crash storing a name containing a '.'; (bso#7154). + Valgrind Conditional jump or move depends on uninitialised value(s) error when "mangling method = hash"; (bso#7155). + Fix some wrong newlines in de translation strings.- Take extra care that a mount point of mount.cifs isn't changed during mount and don't allow it to be run as setuid root program; CVE-2010-0787; (bso#6853); (bnc#550002).- Check in mount.cifs for invalid characters in device name and mountpoint; CVE-2010-0547; (brc#562156); (bnc#577925).- Don't invalidate cache for uninitialized domains; (bnc#538923).- Signals are processed twice in child; (bnc#538923).- Allow forced pw change even with min pw age; (bnc#561894).- Change parameter "wide links" to default to "no"; it's also incompatible with "unix extensions"; CVE-2010-0926; (bso#7104); (bnc#577868).- Fix enumerate domain local groups for primary domain; (bnc#573813).- Fix malformed require_membership_of_sid; (bnc#525123); (bso#7106).- Normalize "Changing password for" msg IDs and STRs; (bnc#499233).- Build libtevent and libldb and put them into separate subpackages.- Update to 3.5.0rc2. + The Using Samba HTML book has been removed. + 'net', 'smbclient' and libsmbclient can use logon credentials cached by Winbind; (bso#7062). + New vfs_scannedonly module has been added; (bso#7028). + Check password history before increasing "badPasswordCount"; (bso#4347). + Fix changing of ACLs on writable file with "dos filemode=yes"; (bso#5202). + Restore Samba 3.0.x behavior and use the first "uid" value in pdb_ldap; (bso#6157). + Fix deletion of an object whose parent folder does not have delete rights fails even if the delete right is set on the object in vfs_acl_xattr and vfs_acl_tdb; (bso#6876). + Fix large paged search with DirX LDAP servers; (bso#6981). + Fix a segfault in winbindd_dual_ccache_ntlm_auth(); (bso#7027). + Disable sanity check in NetShareEnum for better compatibility with Windows; (bso#7029). + Fix SMBrmdir error message when deleting a directory fails; (bso#7033). + Fix segfault in vfs_cap; (bso#7034). + Fix 'net rpc getsid' in hardened Windows environments; (bso#7036). + Fix a Winbind segfault in "trusted_domains"; (bso#7037). + Complete and improve some German translation of 'net'; (bso#7039). + Fix compile error with WITH_DNS_UPDATE. Update .po files; (bso#7039). + Fix crash bug in libsmbclient; (bso#7043). + Fix bad (non memory copying) interfaces in smbc_setXXXX calls; (bso#7045). + Fix libsmbclient crash against OpenSolaris CIFS server; (bso#7046). + Lock down some srvsvc calls according to what w2k3 seems to do.- Update to 3.4.5. + Fix memory leak in smbd (bug #7020). + Fix changing of ACLs on writable files with "dos filemode=yes" (bug #5202). + BUG 6642: Fix opening the quota magic file. + BUG 6919: Fix remote quota management. + BUG 7034: Fix internal error caused by vfs_cap. + BUG 7036: Fix 'net rpc getsid' in hardened Windows environments. + BUG 7043: Fix crash bug in "SMBC_parse_path". + BUG 7045: Fix bad (non memory copying) interfaces in smbc_setXXXX calls. + BUG 7046: Fix a crash in libsmbclient used against the OpenSolaris CIFS server.- Free unused memory after a packet got processed; (bso#7020).- Add timeout to rpc call to prevent infinite loop when network is down; (bnc#538923).- Update to 3.5.0rc1. + BUG 6837: Fix "Too many open files" when trying to access large number of files with Windows 7; (bnc#619787). + BUG 6939: Fix long filenames when "mangling method" is set to "hash". + BUG 6991: Create symbol links to shared libraries. + BUG 6992: make test for getgrouplist cacheable. + BUG 7014: Fix Winbind crash when retrieving empty group members. + BUG 7020: Fix smbd using 2G memory. + Ensure dos_mode can return FILE_ATTRIBUTE_NORMAL, then filter the returned attributes by protocol level. + Vector correctly through reply_openerror() (which uses the same logic). + Fix bugs with the full Windows ACL support. + Add a few missing gettext calls to the 'net' command. + Fix up a share type translation and translate some more strings in 'net'. + Allow to call "pdbedit -N description -u user" without specifiyng "-r". + Add spoolss_DriverInfo7. + Fix rpcclient after setprinter IDL fixes. + Use generated krb5.conf in 'net ads testjoin'. + Add some German translations for the 'net' command. + Update mount.cifs man page with nounix option. + Fix _samr_GetAliasMembership for results with 0 rids. + Fix an error case in cli_negprot. + Add a lower-cost alternative to wbinfo -t: wbinfo --ping-dc. + Restore correct timeouts for SMB requests. + Fix a 64-bit error in libsmb. + Replace IS_DOMAIN_OFFLINE by a function in Winbind. + Simplify/cleanup Winbind code. + Fix write behind memory block in libtalloc. + Fix result check for getaddrinfo(). + Add tsocket_address_bsd_sockaddr() and tsocket_address_bsd_from_sockaddr() to tsocket. + Always set tdb->tracefd to -1 to be safe on goto fail in libtdb. + Add TDB_DISALLOW_NESTING and make TDB_ALLOW_NESTING the default behavior. + Fix standalone 'make installdocs'. + Output %p as unsigned in snprintf replacement. + New attempt at TDB transaction nesting allow/disallow. + Remove swig stuff from libtdb. + Reset tdb->fd to -1 in tdb_close() in libtdb. + Change the way mksysms work in libtalloc. + Also build and install tdb manpages from standalone tdb. + Fix infinite loop in NCACN_IP_TCP as there is no timeout. + Make winbindd_cache.c aware of domain offline to avoid unnecessary backend query. + List trusted domains from wcache when domain is offline.- Update to 3.4.4. + Fix interdomain trust relationships with Win2008R2 (bug #6697). + Fix Winbind crashes when queried from nss (bug #6889). + Fix Winbind crash when retrieving empty group members (bug #7014). + Fix "UID range full" error in Winbind (bug #6901). + Fix multiple LDAP servers in "idmap backend" and "idmap alloc backend" (bug #6910). + BUG 4832: Fix iconv checks. + BUG 6338: Do not always display "none" in 'net rpc trustdom list'. + BUG 6851: Add pdbedit --kickoff-time/-K to set the user's kickoff time. + BUG 6828: Fix infinite timeout when byte lock held outside of samba. + BUG 6837: Fix "Too many open files" message when trying to access a large number of files with Windows 7; (bnc#619787). + BUG 6841: Fix "map acl inherit = yes". + BUG 6850: Fix shadow copy display on Windows 7. + BUG 6867: Fix listing of directories with a lot of files. + BUG 6868: Support building with Heimdal we well as with MIT. + BUG 6875: Fix DOS attributes on OS/2 clients. + BUG 6880: Fix listing of workgroup servers in libsmbclient. + BUG 6898: Samba duplicates file content on appending. + BUG 6918: Fix krb5 build problem on Ubuntu karmic. + BUG 6929: Fix build with recent heimdal. + BUG 6939: Fix long filenames with "mangling method = hash". + BUG 6967: Fix 'net ads join' with OU. + BUG 6981: Fix paged search with DirX LDAP server. + BUG 6982: Remove erroneous out of memory error path in lookup_sid. + BUG 6997: Fix _samr_GetAliasMembership for results with 0 rids. + BUG 7005: Fix "mangle method = hash" truncates files with dot "." character. + Fix the build of the winbind krb5 locator plugin. + Fix enumprinter key client and server.- Readjust the _libdir/cups/backend/smb sym link only on uninstall of the samba-krb-printing package; (bnc#568603).- Add BuildRequires to fam-devel; (bnc#564260).- Prevent winbind crash; (bso#7014); (bnc#566119).- Fix processing of open modes in POSIX open; (bnc#530683).- Add baselibs.conf as a source.- Update to 3.5.0pre2. + BUG 2350: Add LDAP Alias Dereferencing support. + BUG 6288: SWAT adds a second share when changing parameters of an existing share. + BUG 6435: Fix minor memory corruption. + BUG 6710: Only install the cifs.upcall man page if CIFSUPCALL_PROGS was set while configure. + BUG 6802: A created folder does not properly inherit permissions from parent in vfs_acl_xattr. + BUG 6837: "Too many open files" when trying to access large number of files from Windows 7; (bnc#619787). + BUG 6860: Fix shared library build on QNX. + BUG 6879: Fix crash in Winbind. + BUG 6929: Fix build with recent heimdal. + BUG 6938 : No hook exists to check creation rights when using acl_xattr module. + BUG 6967: Prevent glibc error on 'net ads join'. + Fix vfs_acl_xattr which was failing to call the NEXT connect function. + Restructure the ACL code. + Refactor reply_rmdir to use handle based code. + Fix the build when no external talloc and tdb are installed. + Fix detection of CTDB headers on systems without system-libtalloc. + Fix several printing issues. + Fix the build on Mac OS X 10.6.2. + Fix net and rpcclient after setprinterdataex changes. + Add full support for level 8 printer drivers. + Add more spoolss architectures to IDL. + Fix enumprinter key client and server. + Fix crash in EnumPrinterDataEx. + Prefer posix_fallocate for doing "strict allocate". + Restore "fake directory create times" as a share parameter. + Fix explicit stat64 support. + Add support for NetWkstaGetInfo 101 and 102. + Add rpcclient wkssvc_enumerateusers. + De-deprecate "write cache size" to prevent its removal without a proper alternative. + Allow more than 1000 users in BUILTIN\Users. + Complete support for NetWkstaGetInfo/NetWkstaEnumUsers. + Fix the build of the example VFS modules. + Fix crash in free_file_list(). + Give the user a chance to change password when password will expire soon.- Store the smbfs service state if enabled and restore it for cifs while upgrade on post-11.2 systems.- Prevent cifstab from being overwritten while upgrade on post-11.2 systems.- Give the user a chance to change password when password will expire soon; (FATE#302414).- Rename smbfs init script to cifs for post-11.2 systems.- Allow Windows 7 to connection to samba domain controllers and member servers; (bnc#551811); (bso#6099); (bso#6100); (bso#6680).- Error on joining windows domain (invalid pointer); (bso#6967); (bnc#553622).- Add PreReq /usr/sbin/groupadd to the winbind package; (bnc#559165). - Simplify the winbind package %pre script and suppress stdout only.- Update to 3.5.0pre1 + Add support for full Windows timestamp resolution. + Experimental implementation of SMB2. + Add encryption support for connections to a CUPS server. + Major windbind asynchronous refactoring. - Remove using_samba from the doc package. - Increase major version of libtalloc to 2.- Fix kerberos refresh chain; (bnc#546162); (bso#6872).- Hardlink duplicate files on post-11.1 systems.- Add BuildArch noarch to samba-doc on post-11.1 systems.- Use full 16byte session key in make_user_info_netlogon_interactive(); (bnc#551811).- Update to 3.4.3. + Fix trust relationships to windows 2008 (2008 r2) (bug #6711). + Fix file corruption using smbclient with NT4 server (bug #6606). + Fix Windows 7 share access (which defaults to NTLMv2) (bug #6680). + BUG 4675: mount.cifs: Do not attempt to update /etc/mtab if it is a symbolic link. + BUG 6529: Offline files conflict with Vista and Office 2003. + BUG 6532: Fix domain enumeration if master browser has space in name. + BUG 6606: Fix file corruption using smbclient with NT4 server. + BUG 6690: Fix wrong error check in profile. + BUG 6703: Allow smbstatus as non-root. + BUG 6704: Fix syntax error in avahi configure test. + BUG 6707: Fix an occasional segfault in config file parsing. + BUG 6710: Adjust regex to match variable names including underscores. + BUG 6711: Fix trust relationships to windows 2008 (2008 r2). + BUG 6726: SIVAL should have been an SVAL. + BUG 6728: BSD needs sys/sysctl.h included to build properly. + BUG 6731: Fix reading beyond the end of a named stream in xattr_streams. + BUG 6735: Don't overwrite password in pam_winbind, subsequent pam modules might use the old password and new password. + BUG 6764: Fix timeval calculation. + BUG 6765: Add a "hidden" parameter "share:fake_fscaps". + BUG 6769: Fix symlink unlink. + BUG 6772: Allow outstanding_aio_calls to be decremented. + BUG 6774: smbd crashes if "aio write behind" is set. + BUG 6776: Fix core dump caused by running overlapping Byte Lock test. + BUG 6781: Fix renaming subfolders in Explorer view. + BUG 6791: Fix linking order in cifs.upcall. + BUG 6793: Fix Winbind crash with "INTERNAL ERROR: Signal 6". + BUG 6793: Fix segfault in winbindd_pam_auth. + BUG 6796: Deleting an event context on shutdown can cause smbd to crash. + BUG 6797: Fix a memleak in libwbclient. + BUG 6804: Fix hpux compiler issue. + BUG 6805: Correctly handle aio_error() and errno. + BUG 6807: Fix a segfault in "net rpc trustdom list" for long domain names. + BUG 6810: Add support for finding alternate credcaches to cifs.upcall. + BUG 6811: Fix reference to freed memory in pam_winbind. + BUG 6815: Fix Windows 2008 R2 SPNEGO negTokenTarg parsing failure. + BUG 6824: Fix avahi activation. + BUG 6826: Don't fail authentication when one or some group of require-membership-of is invalid. + BUG 6828: Fix infinite timeout when byte lock held outside of Samba. + BUG 6829: Fix displaying of multibyte characters in smbclient. + BUG 6840: Fix crash in pam_winbind. + Fix an uninitialized variable. + Only ever handle one event after a select call. + Conditional install of the cifs.upcall man page. + Fix warning occuring when building the manpages.- Let smbclient show special characters properly; (bso#6829); (bnc#544204).- Don't fail authentication when one or some group of require-membership-of is invalid; (bnc#525123); (bso#6826).- Allow winbind to ignore certain domains; (bnc#539506).- Update to 3.4.2. + Fix unresolved home path; CVE-2009-2813; (bso#6763); (bnc#539517). + Fix potential denial of service; CVE-2009-2906; (bso#6768); (bnc#543115). + Fix potential mount.cifs password leaks; CVE-2009-2948; (bnc#542150).- Fix potential denial of service; CVE-2009-2906; (bnc#543115).- Fix potential mount.cifs password leaks; CVE-2009-2948; (bnc#542150).- Fix unresolved home path; CVE-2009-2813; (bnc#539517).- Don't overwrite password in pam_winbind; (bnc#515444).- mods for winbind (when used with squid - ntlm_auth) o winbind adds group 'winbind' o permission 0750,root,winbind LOCKDIR/winbindd_privileged- Merge two fixes from 3.2.8 and 3.3.1. + Adjust regex to match variable names including underscores. + Conditional install of the cifs.upcall man page.- Remove supplements from baselibs.conf while %clean for pre-11.1 systems; (bnc#520579).- Update to 3.4.1. + Fix authentication on member servers without Winbind (bug #6650). + Nautilus fails to copy files from an SMB share (bug #6649). + Fix connections of Win98 clients (bug #6551). + Fix interdomain trusts with Windows 2008 R2 DCs (bug #6697). + Fix Winbind authentication issue (bug #6646). + BUG 5879: Update LDAP schema for Netscape DS 5. + BUG 5886: Fix password change propagation with ldapsam. + BUG 6105: Make linking of cifs.upcall and rpcclient --as-needed safe. + BUG 6222: Default to DRSUAPI replication for net rpc vampire keytab. + BUG 6437: Make open_udp_socket() IPv6 clean. + BUG 6496: MS-DFS cannot follow multibyte char link name in libsmbclient. + BUG 6506: Smbd server doesn't set EAs when a file is overwritten in NT_TRANSACT_CREATE. + BUG 6532: Fix the build with external talloc. + BUG 6538: Cancel all locks that are made before the first failure. + BUG 6560: Fix lookupname. + BUG 6564: SetPrinter fails (panics) as non root. + BUG 6568: Fix _spoolss_GetPrintProcessorDirectory() implementation. + BUG 6585: Fix unqualified "net join". + BUG 6593: Correctly implement SMB_INFO_STANDARD setfileinfo. + BUG 6601: Avoid global fd limits. + BUG 6607: Fix crash bug in spoolss_addprinterex_level_2. + BUG 6611: Fix a valgrind error in chain_reply. + BUG 6615: Fix browsing of DFS when using kerberos in libsmbclient. + BUG 6627: Raise the timeout for lsa_Lookup*() calls from 10 to 35 seconds. + BUG 6650: Fix authentication on member servers without Winbind. + BUG 6651: Fix smbd SIGSEGV when breaking oplocks. + BUG 6655: Fix 'smbcontrol smbd ping'. + BUG 6620: Fix a bug in renames of directories. + BUG 6664: Fix truncation of the session key. + BUG 6673: Fix 'smbpasswd' with "unix password sync = yes". + BUG 6680: Fix authentication failure from Windows 7 when domain joined. + BUG 6688: Fix crash in 'net usershare list'. + BUG 6693: Check we read off the complete event from inotify. + BUG 6700: Use dns domain name when needing to guess server principal.- Update to 3.2.14. + Fix SAMR access checks (e.g. bugs #6089 and #6112). + Fix 'force user' (bug #6291). + Improve Win7 support (bug #6099). + Fix posix ACLs when setting an ACL without explicit ACE for the owner (bug #2346). + BUG 6387: Fix Winbind crash when multiple IDmappings exist in the LDAP directory. + BUG 6509: Use gid (not uid) cache in fetch_gid_from_cache(). + BUG 6089: Fix SAMR access checks. + BUG 6112: Fix SAMR access checks. + BUG 6279: Fix Winbind crash. + BUG 6291: Fix 'force user'. + BUG 6099: Try to fix domain join of Win7 Beta. + BUG 6386: Groupdb mapping fix. + BUG 6421: Fix POSIX read-only open on read-only shares. + BUG 6476: Fix more smbd-zombies in memory. + BUG 6488: acl_group_override() call in posix acls references an uninitialized variable. + BUG 6504: Fix SAMR server for Winbind access. + BUG 6520: Fix time stamps. + BUG 6301: Fix samr_ConnectVersion enum which is 32bit not 16bit. + BUG 6340: Don't segfault when cleartext trustdom pwd could not be retrieved. + BUG 6372: Fix usermanager only displaying 1024 groups and aliases. + BUG 6465: Fix enum_aliasmem in ldb branch. + BUG 6484: Fix searching for users while adding them to groups via Windows usermanager. + BUG 2346: Fix posix ACLs when setting an ACL without explicit ACE for the owner. + BUG 6526: Let parent_dirname() correctly return toplevel filenames. + BUG 6627: Raise the timeout for lsa_Lookup*() calls from 10 to 35 seconds. + BUG 5798: Preserve CFLAGS info in configure. + BUG 6382: Case insensitive access to DFS links broken. + BUG 6481: Don't require "Modify property" perms to unjoin. + BUG 6628: 'smbpasswd -a' uses algorithmic rid base with 'passdb backend = tdbsam'. + BUG 6560: Lookupname failed, cannot find domain when attempt to change password. + Prevent creation of keys containing the '/' character. + Fix join of Windows 7 RC to a Samba3 DC. + Fix bug in processing of open modes in POSIX open. + Fix the negotiate flags. + Protect netlogon_creds_server_step() against NULL creds. + Also handle DirX return codes. + Fix a crash bug if we timeout in net rpc trustdom list. + Add '--request-timeout' option to 'net'. + Fix a race condition in Winbind leading to a panic. + Add workaround for MS KB932762. + 5945: Fix out of memory error with Winbind idmap. + Avoid duplicate ACEs. + Fix profile ACLs in some corner cases. + Zero an uninitialized array.- Unable to browse DFS when using kerberos in libsmbclient; (bnc#528271); (bso#6615).- check in .po files for pam_winbind; (bnc#499233); (bso#6602).- Add ntp and network-remotefs as Should-Start dependency to the winbind init script; (bnc#515629).- Update to 3.0.36. + Fix Winbind crash on 'getent group' (bug #5906). + Excel save operation corrupts file ACLs (bug #4308). + Prevent segmentation fault on joining a very long domain name. + BUG 4308: Excel save operation corrupts file ACLs. + BUG 4370: Clean-up entries in /etc/mtab after unmount. + BUG 4640: Fix guest mounts in mount-cifs. + BUG 5906: Fix Winbind crash on 'getent group'. + BUG 6066: netinet/ip.h present but cannot be compiled on Solaris. + BUG 6099: In order to allow Win7 to connect to a Samba NT style. + BUG 6279: Fix Winbind crash. PDC we set the flags before we know if it's an error or not. + BUG 6085: Fix build of vfs_default. + BUG 6098: When the DNS server is invalid, the ads_find_dc() does not work correctly. + Fix logic error in try_chown. + Correctly use chroot(). + Fix bug in processing of open modes in POSIX open. + Don't install the cifs.upcall binary twice. + Fix mount.cifs handling of -V option. + Prevent segmentation fault on joining a very long domain name. + Don't try and delete a default ACL from a file. + Add workaround for MS KB932762. + Add fakemount (-f) and nomtab (-n) flags to mount.cifs. + Fix a crash during name resolution when log level >= 10 and libc segfaults if printf is passed NULL for a "%s" arg.- Use a conditional suse_version macro in front of the SUSE_ASNEEDED export.- lookupname failed, cannot find domain when attempt to change password; (bnc#520645); (bso#6560).- Don't link with --as-needed flag on post-11.1 systems.- Stop the smbfs service if an interface goes down; (bnc#517768).- Disable build of static libraries on post-11.1 systems; (bnc#509945).- Fix missing zlibs for cifs.upcall and test_shlibs.- Update to 3.4.0. + BUG 6431: Local groups from 3.0 setups no longer found. + BUG 6459: Fix build of pam_smbpass on some distributions. + BUG 6481: 'net ads leave' needs to try account deletion, NetUnjoinDomain not. + BUG 6497: Fix calling of 'test' in configure. + BUG 6498: Add workaround for MS KB932762. + BUG 6499: Fix building of pam_smbpass. + BUG 6509: Use gid (not uid) cache in fetch_gid_from_cache(). + BUG 6512: Fix support for enumerating user forms. + BUG 6514: Improve error message in 'net' when smb.conf is not available. + BUG 6520: Fix time stamps when "unix extensions = yes". + BUG 6521: Fix building tevent_ntstatus without config.h. + BUG 6526: Fix notifies in the share root directory. + BUG 6531: Fix pid file name.- Package /etc/samba/smbpasswd as %ghost on post-11.1 systems.- Fix net ads leave; (bnc#511695).- Supplement pam-32bit/pam-64bit in baselibs.conf (bnc#354164). - Supplement glibc-32bit/glibc-64bit in baselibs.conf (bnc#354164).- Update to 3.2.13, 3.3.6. + In Samba 3.2.0 to 3.2.12 (inclusive), the smbclient commands dealing with file names treat user input as a format string to asprintf. With a maliciously crafted file name smbclient can be made to execute code triggered by the server; CVE-2009-1886; (bnc#513360); (bso#6478).- Update to 3.0.35. + In Samba 3.0.31 to 3.3.5 (inclusive), an uninitialized read of a data value can potentially affect access control when "dos filemode" is set to "yes"; CVE-2009-1888; (bnc#515479).- Uninitialized read of a data value; CVE-2009-1888 (bnc#515479).- Update to 3.4.0rc1. + BUG 4699: Remove pidfile on clean shutdown. + BUG 5456: Fix "net ads testjoin". + BUG 6081: Make it possible to change machine account sids. + BUG 6253: Use correct value for password expiry calculation in pam_winbind. + BUG 6297: Owner of sticky directory cannot delete files created by others. + BUG 6305: Correctly prompt for a password when a username was given. + BUG 6328: Add support for multiple rights to "net sam rights grant/revoke". + BUG 6333: Consolidate create/delete account paths in pdbedit. + BUG 6449: 'net rap user add' crashes without -C option. + BUG 6451: net/libnetapi user rename using wrong access bits. + BUG 6458: Fix uninitialized variable in local_password_change(). + BUG 6465: Fix enumeration of empty aliases. + BUG 6476: Fix smbd-zombies in memory when using [x]inetd. + BUG 6487: Add missing DFS call in trans2 mkdir call. + BUG 6488: acl_group_override() call in posix acls references an uninitialized variable. + Improve pam_winbind documentation. - Install a vendor copy of samba-common.dhcp as dhcpcd-hook-samba-functions.- Samba 3.2.0 - 3.2.12 smbclient commands dealing with file names treat user input as a format string to asprintf; CVE-2009-1886; (bnc#513360).- Fix a bad memleak in vfs_full_audit; (bnc#510035).- Update to 3.3.5. + Fix SAMR and LSA checks (bug #6089, #6289) + Fix posix acls when setting an ACL without explicit ACE for the owner (bug #2346). + Fix joining of Win7 into Samba domain (bug #6099). + Fix joining of Win2000 SP4 clients (bug #6301). + BUG 2346: Fix posix acls when setting an ACL without explicit ACE for the owner. + BUG 5832: Fix build on RHEL when ccache is not available. + BUG 5853: Add keyutils-devel to build requires to fix build on RHEL. + BUG 5897: Fix shutdown script example in the smb.conf manpage. + BUG 6089: Revert the extra SAMR and LSA checks. + BUG 6099: Fix joining of Win7 into Samba domain. + BUG 6157: Fix handling of multi-value attribute "uid". + BUG 6289: Revert the extra SAMR and LSA checks. + BUG 6297: Owner of sticky directory cannot delete files created by others. + BUG 6301: Fix joining of Win2000 SP4 clients. + BUG 6309: Support remote unjoining of Windows 2003 or greater. + BUG 6315: smbd crashes doing vfs_full_audit on IPC$ close event. + BUG 6320: Handle registry config source in file_list. + BUG 6330: Fix DFS on AIX. + BUG 6336: Fix 'net groupmap set' segfault. + BUG 6361: Make --rcfile work in smbget. + BUG 6365: Re-Add the "dropbox" functionality with -wx rights on a directory. + BUG 6372: Fix usermanager only displaying 1024 groups and aliases. + BUG 6382: Fix case insensitive access to DFS links. + BUG 6415: Filter out of range mappings in default idmap config in idmap_tdb. + BUG 6416: Filter out of range mappings in default idmap config in idmap_tdb2. + BUG 6417: Filter out of range mappings in default idmap config in idmap_ldap. + BUG 6441: Fix the compile with --enable-dnssd. + BUG 6449: 'net rap user add' crashes without -C option. + BUG 6465: Fix enumeration of empty aliases (ldb backend). + Prevent infinite include nesting. + Mark registry shares without path unavailable. + Also handle DirX return codes. + Fix Coverity ID 897. + Do not crash in ctdbd_traverse if ctdbd is not around. + Fix a race condition in winbind leading to a panic. + Some man pam_winbind improvements. + Zero an uninitialized array.- Update to 3.2.12. + Fix SAMR and LSA checks (bug #6089, #6289) + Fix posix acls when setting an ACL without explicit ACE for the owner (bug #2346). + Fix "force user" (bug #6291). + Fix Winbind crash (bug #6279). + Fix joining of Win7 into Samba domain (bug #6099). + BUG 2346: Fix posix acls when setting an ACL without explicit ACE for the owner. + BUG 5798: CFLAGS info lost in configure. + BUG 5832: Fix build on RHEL when ccache is not available. + BUG 5835: Add keyutils-devel to build requires. + BUG 5945: Fix out of memory error with Winbind idmap. + BUG 6089: Revert the extra SAMR and LSA checks. + BUG 6099: Fix joining of Win7 into Samba domain. + BUG 6279: Fix Winbind crash. + BUG 6289: Revert the extra SAMR and LSA checks. + BUG 6291: Fix "force user". + BUG 6301: Fix samr_ConnectVersion enum which is 32bit not 16bit. + BUG 6372: Fix usermanager only displaying 1024 groups and aliases. + BUG 6386: Groupdb mapping fix. + BUG 6382: Fix case insensitive access to DFS links. + BUG 6465: Fix enumeration of empty aliases (ldb backend). + Prevent creation of keys containing the '/' character. + Fix bug in processing of open modes in POSIX open. + Protect netlogon_creds_server_step() against NULL creds. + Also handle DirX return codes. + Fix a race condition in winbind leading to a panic. + Fix a crash bug if we timeout in net rpc trustdom list. + Fix profile acls in some corner cases.- Default with passdb backend to smbpasswd for SUSE products older than 11.2.- Explicitly use 'tdbsam' as passdb backend in the default smb.conf file.- Update to 3.4.0pre2. + The default passdb backend has been changed to 'tdbsam'! + Samba4 and Samba3 sources are included in the tarball. + Changed the way smbd handles untrusted domain names given during user authentication. + Various fixes including printer change notificiation for Samba spoolss print servers. + The remaining hand-marshalled DCE/RPC services (ntsvcs, svcctl, eventlog and spoolss) were replaced by autogenerated code based on PIDL. + Samba3 and Samba4 do now share a common tevent library. + The code has been cleaned up and the major basic interfaces are shared with Samba4 now. + An asynchronous API has been added. + Made parameter syntax of the net command more consistent. + BUG 2346: Fix posix ACLs when setting an ACL without explicit ACE for the owner. + BUG 4271: testparm should not print includes. + BUG 4831: Don't call openlog() or closelog() from pam_smbpass. + BUG 5681: Do not limit the number of network interfaces. + BUG 5859: Fix renaming of samr objects failed due to samr setuserinfo access checks. + BUG 6099: Fix NETLOGON credential chain. + BUG 6136: New AFS syscall conventions. + BUG 6157: Fix handling of multi-value attribute "uid". + BUG 6253: Use correct value for password expiry calculation. + BUG 6291: Fix 'force user'. + BUG 6292: Update config.guess from gnu.org. + BUG 6302: Give the VFS a chance to read from 0-byte files. + BUG 6309: Support remote unjoining of Windows 2003 or greater. + BUG 6313: ldapsam_update_sam_account() crashes while doing talloc_free on malloced memory. + BUG 6315: Fix smbd crashes when doing vfs_full_audit on IPC$ close event. + BUG 6320: Handle registry config source in file_list. + BUG 6330: Fix DFS on AIX. + BUG 6336: Fix segfault in 'net groupmap set'. + BUG 6340: Don't segfault when cleartext trustdom pwd could not be retrieved. + BUG 6357: Use Samba default command line arguments in 'net'. + BUG 6359: smbclient -L does not list workgroup for hosts with both IPv4 and IPv6 addresses + BUG 6361: Make --rcfile work in smbget. + BUG 6371: Unsuccessful 'net conf setparm' leaves empty share. + BUG 6372: usermanager only displaying 1024 groups and aliases. + BUG 6387: Fix a crash bug in idmap_ldap_unixids_to_sids. + BUG 6415: Filter out of range mappings in default idmap config (idmap_tdb). + BUG 6416: Filter out of range mappings in default idmap config (idmap_tdb2). + BUG 6417: Filter out of range mappings in default idmap config (idmap_ldap). + Change the way smbd handles untrusted domain names given during user authentication. + Replace the hand-marshalled DCE/RPC services ntsvcs, svcctl, eventlog and spoolss by autogenerated code based on PIDL. + Fix several printing issues and improve support for printer change notificiations. + Add 'net eventlog'. + Add asynchronous API. + Make Samba3 and Samba4 share a tevent library. + Add two new parameters to control how we verify kerberos tickets. + Add 'net rpc service' subcommands 'create' and 'delete'. + Fix the core of the SAMR access functions. + Fix SAMR server for winbindd access. + Add dbwrap_tool - a tdb tool that is CTDB-aware. + Hide "config backend" from swat. + Fix linking with --disable-shared-libs. + Fix issue with missing entries when enumerating directories. + Map NULL domains to our global sam name. + Fix driver upload for Xerox 4110 PS printer driver. + Add "net dom renamecomputer" to rename machines in a domain. + Inspect the correct computername string before enabling/disabling the change button in netdomjoin-gui. + Fix join prompt dialog test in netdomjoin-gui. + Only gray out labels when not root and not connecting to remote machines (netdomjoin-gui). + Allow to switch between workgroups/domains with the same name (netdomjoin-gui). + Add NetShutdownInit and NetShutdownAbort. + Fix samr access checks. + Add a security model to LSA. + Also handle DirX return codes. + Do not crash in ctdbd_traverse if ctdbd is not around. + Fix Coverity ID 897. + Fix a race condition in vfs_aio_fork with gpfs share modes. + Fix bug disclosed by lock8 torture test. + Fix a race condition in winbind leading to a panic. + Detect tight loop in tdb_find(). + Fix chained sesssetupAndX/tconn messages. + Fix strict locking with chained reads. + Fix two bugs in sendfile. + Fix memory leak. + Fix file descriptor leak. + Fallback to the legacy sid_to_(uid|gid) instead of returning NULL. + Always allocate memory in dptr_ReadDirName. + Fix 'net' crash during domain join. + Zero an uninitialized array. + Allow child processes to exit gracefully if we are out of fds.- Enable cifs.upcall on versions newer than SUSE 10.0.- Add BuildRequires to keyutils-devel.- Remove redundant Requires to keyutils-libs for cifs-mount.- Detect tight loop in tdb_find(); (bnc#450974).- Fix lp printing with kerberos; (bnc#476913).- Add BuildRequires to ctdb-devel for systems newer than SUSE 10.0 and all other build targets.- Update to 3.4.0pre1. + Samba4 and Samba3 sources are included in the tarball + Changed the way smbd handles untrusted domain names given during user authentication. + Various fixes including printer change notificiation for Samba spoolss print servers. + The remaining hand-marshalled DCE/RPC services (ntsvcs, svcctl, eventlog and spoolss) were replaced by autogenerated code based on PIDL. + Samba3 and Samba4 do now share a common tevent library. + The code has been cleaned up and the major basic interfaces are shared with Samba4 now. + An asynchronous API has been added. + Change the way smbd handles untrusted domain names given during user authentication. + Replace the hand-marshalled DCE/RPC services ntsvcs, svcctl, eventlog and spoolss by autogenerated code based on PIDL. + Fix several printing issues and improve support for printer change notificiations. + Add 'net eventlog'. + Add asynchronous API. + Make Samba3 and Samba4 share a tevent library. + Add two new parameters to control how we verify kerberos tickets. + Add 'net rpc service' subcommands 'create' and 'delete'. + Make merged build possible. + Move common libraries to the shared lib/ directory.- Update to 3.3.4. + Fix domain logins for WinXP clients pre SP3 (bug #6263). + Fix samr_OpenDomain access checks (bug #6089). + Fix usrmgr.exe creating a user (bug #6243). + BUG 6089: Fix samr_OpenDomain access checks. + BUG 6254: Fix IPv6 PUT/GET errors to an SMB server (3.3) with "msdfs root" set to "yes". + BUG 6279: Fix Winbind crash. + BUG 5329: Add "net rpc service delete/create". + BUG 6238: Make sure wbcLogoffUserParams are properly initialized before freed. + BUG 6263: Fix domain logins for WinXP clients pre SP3. + BUG 6286: Call init function for builtin idmap modules before probing for them as shared modules. + BUG 6243: Fix usrmgr.exe creating a user. + net conf: Save share name as given, not as lower case only. + Prevent creation of registry keys containing the '/' character. + Allow pdbedit to change a user rid/sid. + When doing a cli_ulogoff don't invalidate the cnum, invalidate the vuid. + Don't access a freed structure when logging off and re-using a vuid. + Try to to fix password_expired flag handling. + Make sure to grey out change fields in the netdomjoin-gui when not running as root. + Don't look up local user for remote changes, even when root. + Use procid_str in debug messages for better cluster-debuggability. + Use cluster-aware procid_is_me instead of comparing pids. + Fix smbd crash for close_on_completion. + Fix a memleak in an unlikely error path in change_notify_create(). + Do not use the file system GET_REAL_FILENAME for mangled names. + Fix a crash bug if we timeout in net rpc trustdom list. + Add '--request-timeout' option to net. + In net_conf_import, start a transaction when importing a single share. + Fix writing of roaming profiles with "profile acls" set to "yes".- Update to 3.2.11. + Fix domain logins for WinXP clients pre SP3 (bug #6263). + Fix samr_OpenDomain access checks (bug #6089). + Fix smbd crash for close_on_completion. + BUG 6089: Fix samr_OpenDomain access checks. + BUG 6205: Correct sample smb.conf share configuration. + BUG 6254: Fix IPv6 PUT/GET errors to an SMB server (3.3) with "msdfs root" set to "yes". + BUG 6263: Fix domain logins for WinXP clients pre SP3. + Allow pdbedit to change a user rid/sid. + When doing a cli_ulogoff don't invalidate the cnum, invalidate the vuid. + Fix resume command typo for "printing = vlp". + Fix smbd crash for close_on_completion. + Fix a memleak in an unlikely error path in change_notify_create(). + Don't look up local user for remote changes, even when root.- Don't lookup local user for remote password changes; (bnc#493507).- Update to 3.3.3. + Migrating from 3.0.x to 3.3.x can fail to update passdb.tdb correctly (bug #6195). + Fix serving of files with colons to CIFS/VFS client (bug #6196). + Fix "map readonly" (bug #6186). + BUG 6195: Don't let smbd child processes panic. + Add backend_requires_messaging() method to libsmbconf. + Add methods is_writeable() and wrapper smbconf_is_writeable() to libsmbconf. + Fall back to file backend when no valid backend was found. + Fix a memleak in dbwrap_rbt. + Provide transaction_start|commit|cancel fns for the registry tdb. + Speed up "net conf drop". + Speed up "net conf import". + Add transactions to the libsmbconf API. + Reduce memory usage of "net conf import". + Registry cleanup. + Fix handling of SAMBA_VERSION_VENDOR_PATCH. + Fix build of pam_winbind.so with static linking. + Tidy up some convert_string_internal error cases. + BUG 6224: nmbd waits 5 minutes at startup before checking if it needs to run elections. + Allow DFS client paths to work when POSIX pathnames have been selected. + Try and fix the build farm RAW-STREAMS errors. + Ensure files starting with multiple dots are hidden. + BUG 6102: NetQueryDisplayInformation could return wrong information. + BUG 6193: Avoid messing with sync_context in libnet_samsync_delta(). + Fix notify_printer_status_byname. + Fix Coverity IDs 722, 762, 774, 775, 776. + Fix build on old Heimdal based systems. + Fix compile warning. + Use parentheses in if condition to make negation clear. + Add dirsort module. + BUG 6147: Fix detection of the GNU ld version. + BUG 6097: Fix smbd segfault. + BUG 6130: Don't crash in winbindd_rpc lookup_groupmem() on unmapped members. + BUG 6139: Add missing whitespace in mount.cifs error message. + Fix a malloc/talloc mismatch when cli_initialise() fails. + Fix a valgrind error. + Speed up "net conf list". + Add sorted subkey cache. + Use StrCaseCmp in the dirsort module. + Document the dirsort module. + Disable dns_sd by default. + Add avahi detection to configure. + Add event avahi binding. + Use avahi to register _smb._tcp in smbd. + Fix two memleaks in the encryption code. + Fix a scary "fill_share_mode_lock failed" message. + BUG 6228: Fix SMBC_open_ctx failure due to path resolve failure doesn't set errno. + Don't use reserved words in smbconftort. + Fix smb signing for fragmented trans/trans2/nttrans requests. + Parse_packet can return NULL which is then dereferenced in match_mailslot_name. + Format the header check for netinet/ip.h more nicely. + Missing break in conversion function prevents tdb password database update.- Update to 3.2.10. + BUG #6195: Don't let smbd child processes panic.- BUG 6195: Fix crash on passdb conversion.- Update to 3.2.9. + BUG 5920: The length of the memcpy was calculated wrong. + BUG 6097: Fix smbd segfault. + BUG 6098: Fix ads_find_dc() with "security = domain" when the DNS server is invalid. + BUG 6099: Samba returns incurrate capabilities list. + BUG 6100: Implement _netr_LogonGetCapabilities() with NT_STATUS_NOT_IMPLEMENTED. + BUG 6102: NetQueryDisplayInformation could return wrong information. + BUG 6130: Fix crash in winbindd_rpc lookup_groupmem() on unmapped members. + BUG 6133: Cannot delete non-ACL files on NFSv4 ACL filesystem. + BUG 6161: smbclient corrupts source path in tar mode. + BUG 6193: Avoid messing with sync_context in fetch_database_to_ldif(). + BUG 6196: Unable to serve files with colons to Linux CIFS/VFS client. + BUG 6224: nmbd waits 5 minutes before checking to run elections. + BUG 6228: Fix SMBC_open_ctx failure when path failure doesn't set errno. + Numerous Coverity fixes + Fix double free caused by incorrect talloc_steal usage. + Backport delete semantics of alternate data streams on a file truncate. + Allow set attributes on a stream fnum to redirect to the base filename. + Fix use of streams modules with CIFSFS client. + Fix more POSIX path lstat calls. + Allow DFS client paths to work with POSIX pathnames. + Ensure files starting with multiple dots are hidden. + Fix guest auth when Winbind is running. + Fix memleak in get_remote_printer_publishing_data(). + cifs mount fix for handling -V parameter. + Fix guest mounts. + Clean-up entries in /etc/mtab after unmount. + Add fakemount (-f) and nomtab (-n) flags to mount.cifs. + Enable total anonymization in vfs_smb_traffic_analyzer. + Don't try and delete a default ACL from a file. + Fix remotely adding a share via MMC. + Fix resume handle for _samr_EnumDomainGroups. + Fix a buffer handling bug when adding lots of registry keys. + Fix a O(n^2) algorithm in regdb_fetch_keys(). + Fix a valgrind error / segfault in dns_register_smbd(). + Don't log NDR_PRINT_DEBUG at level 0, this always ends up in syslog. + Fix a malloc/talloc mismatch when cli_initialise() fails. + Fix two memleaks in the encryption code. + Fix "fill_share_mode_lock failed" message. + Add S-1-22-X-Y sids to the local token. + Fix smb signing for fragmented trans/trans2/nttrans requests. + Don't miss an absolute pathname as a kerberos keytab path. + Have nmbd check all available interfaces for WINS before failing. + Initialize the id_map status in idmap_ldap to avoid surprise.- Obsolete change from 2008-03-05 by removing the needless examples cleanup.- Update to 3.3.2. + Fix "force group" (bug #6155). + Fix saving of files on Samba share using MS Office 2007 (bug #6160). + Fix guest authentication in setups with "security = share" and "guest ok = yes" when Winbind is running. + Fix corruptions of source path in tar mode of smbclient (bug #6161). + BUG 6082: Fix renaming and deleting of directories using Windows clients. + BUG 6154: Make ZFS honor admin users. + BUG 6155: Fix "force group". + BUG 6160: Fix saving of files on Samba share using MS Office 2007. + BUG 6161: Fix corruptions of source path in tar mode of smbclient. + Fix some NetBSD warnings. + Fix bug in processing of open modes in POSIX open. + Fix use of streams modules with CIFSFS client. + Ensure ACL modules work with POSIX paths. + Use fsp->posix_open in preference if we have it. + Fix more POSIX path lstat calls. + Fix a bug in message handling for the change notify code. + Fix guest authentication in setups with "security = share" and "guest ok = yes" when Winbind is running. + BUG 4640: Fix guest mounts in mount.cifs. + Fix displaying the version string properly when no other parameters passed in in mount.cifs. + Prefer gssapi header files from subdirectory. + BUG 6176: winbindd -n should disable the winbind idmap cache. + Add a vfs_preopen module to hide fs latencies. + Don't log NDR_PRINT_DEBUG at level 0, this always ends up in syslog. + Fix a valgrind error / segfault in dns_register_smbd(). + Fix build on SLES8. + Decremented by 1 for ntcancel requests. + Fix creation of core files. + Fix first mapping of uids/gids in Winbind. + Initialize the id_map status in idmap_ldap to avoid surprise. + Fix initialization of idmap status.- Only call '%find_lang pam_winbind' in the samba spec file, not samba-doc.- Ignore return value from subshell to fix build./bin/sh3.6.3-141.13.6.3-141.1libnss_wins.so.2/lib/-fomit-frame-pointer -fmessage-length=0 -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector -funwind-tables -fasynchronous-unwind-tables -gobs://build.opensuse.org/openSUSE:Evergreen:Maintenance:4627/openSUSE_Evergreen_11.4/1af6c5bb952ae8b921021669103e3f44-samba.openSUSE_Evergreen_11.4drpmlzma5x86_64-suse-linuxpackageand(samba-client:glibc-32bit)?]"k%6 ZE%*]NDVP\` V$}dԱB=[c\g>pI|-]{lʉ,knnW;8a0c=WUKVvk&٨1v#^ež0ڬ[-e.E9c8/7nk2Os+;e!H!U.dx".a6TiF@phsN+wMs3hىJe-eO1Zrsc/!}&X̓OC/5= J4A(vF;GBf~ҭdzg4ۯ 뿤 ":*Jcsim =A{i xOI #tI5V ΠM%ka@23ǩ#kʨp)58,v3=cs̄yiU҆S`wU?0WΕX6ZS/1"o(*e$SawL3~-6Yך_* N.ԜC-`%,}𑗐uG*F-[as86 +6Sa2M=sKOSh[2]%48Hxãj`It%l œs_fGcnslW{FH' ϾGk&%v9b(\|^A8Zb|?)R8Eu8se+$P&rjDŰIVWOGdn9Cz K[H 18c>1'SLG A-LY5Ʊ# 8-w97gHJN:M)b@f*^CĖ.C5I;JPW/ 9Z4 F='w/Wl}gk6N/QG#8hI{c!1zHtװv鲜k8ezjAR+ *Վ W, (sΐ]^ʍxZ_͜t|Gr 8಑3f[S}>q#Ã'>Szν9#MɻJby0G;š/Q7G'9YZgǸLn^Ԛ€:ƀF5-y zSxf-3Fk? 2)\`xW=NFM\1|ZW;H5,*D_X|xP N7b*l"qsU*TeȎ`OCm9x¼P| jUgAP7t:0Nqni%sU$[UW tѪ@3S>kMUJ*MX^s6N<V0&Am-"O|F;BppL؅]Pa'ū PUbWtC O ]_m>/Be7ش*rK= iR뀒.'c A e{IcvD[?ύ>i(jЂ ܨ<=~ש:Or;{ TDYOԙfDߊ3P1pWdBbX%{ZRo6[\]tOd.Zd%4Jk)O ONU xr.k3h +XaYoE_HE0J@hViB Xy3x|xgOf*^RT)P 0'u"vj Bm^"$P}Dۖ#Ɵ eHHR:t{ە2n:{s uqp*A[D"Q7cpȰWNM'4O-};?|Z~`8E4be'Z!xrD%;jpo'\/@8b1K0A.?{5syu1^WNqrDe;k-Zؐp+@ԫ"ey9x Bl-뤇6zJY̑ZׇIMKڤk'.B}RK/"R {e:ꁭŌEH(3X֗HIDk>J`sr,gY"Y Q-KUA zM9*sVO)Ac݁xJ.,R/+ zPPcғE|90kM@TJ`53zKb1 ;~pW> QI7'bOyUN N{IfWX/S#UANT~:ڒ05=˳ws}q\L{ߔJ9N`\;evP|-Kݯ@.v%*z@r+|)\{DGXa/#9}Ed*-"}.3?A?ṡ0SCA2@^RB!$ɪ4XE V\;"^Ukf&P;SV-X;O  9CϗCrxl` AvRqT~FUJ[w=dU'rV Oa>gKoGv5Ϧa e:XBlJ%x녹{܉Gӆ nדl4ԁ~X)8ooo^Ƃ{ӘNm,ZSxc}+˕'7P&\#4Lc< o&>AYҝ&[ ;o%Yʏ#fLpeÿ]}"69{\'͝;X#({ yƔ3Ld VI-)O`jjb[V6x$KV.= 4Tf)~vB3S [RĀ59N+ 5AB\p S@+(snSChh,:O+?'z яmz^T;$eߠ'&-s/,mP&H}L-M|F07P"mdDgE c'}O;P3^" J>KpЁ:D}l&ZXk2Z\(/ gh` {"OQ`id:BCR!>@c ,Is3|_I+T4 {X髺pi$?clO(~Hg pNjQ=9-POWzS!uPa^-2ș}YUFai抺e)Jd!^*9ʲ,7A۠aZf-uS}-,Bh 'T=oPqt) ; oXk/W^#n@xnf˜E &LAOylxȉ+t1q\v@yg4D埂YH\Kai>R)ܱݤ&W.V{efGD唷_Pa)9R }xcmzɮ(ݓ16(jx̻Eƒ~[,e?9XE-RѺscuBS栿nG#ED(QGEV,PLD(Գ&~ ] A]7dp(57 $%Zs SԖa K5zfEY?JDEFo˔[ޙaް%W? #zY:7ν+S }Ytf$Yo8O&x]djΘ`v̲ Vmq($qnAbR*x!xu^LrmLNX ·_l%zei$7 ';^z$rJubqvx2zU>*n%?IO9 C{c 4-`e@z(3X;123*J lKfr&>mzK1׽ 8AaFO!k]Kr^neiEԩ2LJ2L"Kv" AydA~8sⱵ{קnm# k<n˰CYl 1xf] nW)U|'MrUڥ >fm l8hN3w]#Q tooFRl Y֞(cLllFvfo.9}ITN2 f:&w6b~;uyTJ%d-tOfq7> 3?Θ9onTs3::o}'m'V;%>KMSl+&O!AAv*b~IOIah9*Eӷ&ԞVPڝ &#%B]xˍt ĐoE[jo&&91kot %z y8--̃n7-S%̇ҽ.^ P^Orξ bF3FM]<"@qؠs"R?UXY zTl!넖vAl<:{26^^u>uL>BAF؛|8[qPQl,ThJRPQKNߝ³4a1TV Y~93Ֆ * cłٛ4ȱfqYsiȸJܧUr&̟B!ayqi1TْB. - 34{aѢvLpGV?֏ߘ.x LTgꚈD(A[m?lC\JP~J\-ZPyai(F7ԀqtLvrLARzSQnxܺ?"Z q"HSSiF2m<>ݩC"Pg.KV,N]ʥ4~-fL pij*Bn> Jm8Ņ6xf`hVoDA?wT9~^!3bR{hٗYb@['*,>JW˓YpD,{ZO)XN  `@u7t>L+v0F$jVa XX?sVDUX` }

o.Yw8Bњ:[Wpg(uEq┅Tx ]0!I^GzȣW3;QZ~iY=!A cCƣډuBC]X I_-~ɤ< P6XZD0;3`5Unq7.O c*E-,|` |Vt/}m4=#&eBwk\>iǾH &.H)깃cd?|y~k^& =)lRe&}= ؄ 6 !U}!N0&Zzb 4{x~m邲{#phNy;9ON :Q-촡3Ŕ\Bs>ewۊq{b8Y%WEb+5xK!c]0N+͘wev/ O tQ]b-iSGɂe"csU"g4nۗQ|*ʫ˼GiBԀ*":@^Ux4AQc;hWc= `*ɖt%`nYSy@w[ZWibǪXAw;Q zRhpPр~*EYsnbmO7KrF r8 %zeb%V;'v}EB8_Qpj|d=!bAt{[?8NbRg~lՍN^J$"\jC / \^'Qw)zt#M)|Jv#[^(v3.3N\ n'g:3']rljdm?w+IxBü=*kGէw`:Dik;T1sTW8wC=s.x.zj&&S^qDhJ;^\ c]$)qG߮`龑Y.PdGh%F<8z}P Lwu ĤE*67،YPJp3 (v =_6[V_xJF i @-㦎N0ARӼX4L'?w;X YpV)6 eFE@y f|OwY3EM 9= ^P2CUrE~-d#!:7{M b2I?ɥUW }H8M{crZ+gN%bkޗmߔzf" @n슢7wسHUY|`I1dUkFe`0 H/ºA/^!:TBfa|c!5ninM8@x m 9+ғDr=g1@~@ iGL#=]$JBco-vۨ8ɒók&xVDue?&6<@OZIS;{]\Ra(~8!ݲI0Y_CL -V,).o/gf sdg2mH]:#hbıSنHFW 21a s}GAZP*R 3w<ЄTX=hCOhWu~g7rS5ʾSaO ryXTxfDgg#ՅW~:cIӄ, C lpYӶB\E۝DoABJݬ$?d X0D[w\ HȲЁK492g8eo߾e^ 'U''F=x;E)6 ?D]ɲ ieщ!g_턵7 Q>\&*7.BcYu %%pPf:Cdu;]c~TV|aۖ\2d!@{ѸLPL)D!yϝ:ǵ A{;\&>wjó̂I9-=#˜ Ib$&VN+;(TNi㬐#2Qtqjآ~"u ̓V6T8>ʊ_,lt:8uڽ$տFT= -֘=ӵd{U%|j~Ep@NH"'WÌ+6fnf'l*X|Hv+\# .+Մ(/׈HM ewM6O>cX+ `PH&峐8JӦxEzOf JXԢ4ˤ*{(+hD lzh<%!S}tA=;0#j&P$j2>gZ\nOho2$k/,1sVLLse*q7˴M2o`->,ogjP`a3~`nV k0s?h<K,>#1on?{hA),^֪4'3XY/nH傩=&ţ 8/#Zl"@6>5JE3)iÃ4i,֏<I ^uMG Ä|les .Y_̢ȳ:ʿm\;K?Cn/_[#YSe8'5-[˱7O[v!8ZE ҲM13iǡ* J'/YR?π\>N]c7/d!(onO3~[+/'Q~QZVEu̍k EgpvU(l58}e[φ~e}!;IBԪ<f()VVa<@%`eUUGU'`QzjWFLsf-U 펐={a:-I6G-.t+19s Wo&=bϖ;>W[;; +$Kl⇃nvCV+$V3?*+Α~Xa?¸冒ke[!~h(pZ{'<7l!Kz,_/fQ7Cz]c( W[gW`|`@ojvzZ'ݸ,ّ]Rb|Y>Oۥ59C`NXY lO߬dz[i5 mqF 8%"E:At_tqW^tk=G\ y.HU8"c) '-Z$ F["bft BZsC؏fnbVqyك0* NxIz'+ٓ>P쉈_a*t FE|7XNJwpYHLk!{Tn(<@ P2R2nwH&|$ن*:{NHfFQ} CGe9u]-gEr61Mj97%nb،Ǣ: h<շ79n]>q~+T:n.ŵ6ds%oAͱ{"L۝"Z͘1P\c.Yy1bC2Va{4<ځO\e\\n쌮h7ZAo9$t Fưﱺn{ok2mӒohic$p]5z }+AuE"SDsЀp~@{~u#]2CiVזi Y=uCu4d_qSbl'a QV4u͆X.<%@o g"aBLg P⁋XL\e?f9?z'{ [ X6O}Z3\iB@xV^=[>Sq4r]d`XZGh *]Ծhe?0L"_?x/nAJ.t{Ip:Mڐd? mnߍuyYl$nŗ& wӮVKBg+$;nKvV XT=S p{.e,QW1?IT47j})+`'*4*_={v!I8Rl-Gh:ѷ/_56f4ߝj; Ge671Q]g>~y>˸6GX*΃eQuzghsgMPt0-aȍ y@[+֚>n1/ V*2(GG̴@i\|!K9ĭfI/oI3LgG_:d;CrVRƘcz"F/rEf0g笺9GvR82Ҷ860+oU=9bTla?h_JTP#IŜv-5F"]kTGpONSC5gy6HQ6U2k8pZ  2<)Upy_62غ+::&y1j?~`lNsJlСbK΋o3ۍa3~la#_TP.Ɨ+up{nFgWD3jXʁ4,锩=W&w JL TlXYJP67ΜXEUkS{P0GCXXh N_q+^57rPEh6 l()U UC >Y=Tbm7#ٶ00Ԑy-5'y X\:5Doik荑ԄrܫܸEHW&pBl&vkͻ^5^vslŚIRŐH-ܹ@&CoA(Tw~8fͅ^RQY?P ѐ\7Ӱ %Y4 krB64/-ML2WD]X aT'8Ʃ^w_<ay ggL"'iPݫ7ōNuNÊO\yrK=}S}};{ގQH|-Ȫ"`3u- !aS\h!aC_Xce>.PM4WO >Er7;_XLq2-XnJ ah5&ʞ\_IbJmڭ -rK4lI0vOY@1Z1+ZL% y`a k%I `ؚZY\X(a L ¿ock^Yr\l{d+>On׈hT?5R3Aa0;$o5eJyxy[.T~ ZQ-%*iQ6'X`X^uE&$/Hr5ӧ2?B!dyҩ8jRO' [y2%Q rZU:4 /j6~ȢQ(xNpCm婿Bq%HOۊ{8Tbs. ay#Q0SNT8֠6mc5f2dG'Aԗ6pt+`[w2i`ǟA ]?|DeͻJ/6oA.,X3lƠP:u9]%kWV4QP /7_"67frjtĵ!+*@ݼ<9So I +:ֆe(ã(w+Fѐfex'嫟jP&M$1`gG l I]s:5i +H3BG1*^cLGq2{~ ]6 DN¨9է-B1-p][ =5Y9MmGW@ۃZqCH4n9ϔyT>Vs}cRo( g,5M1l >*락Qx4jL@%|ٙ<3u0)k 3|!WW5#"(w('!L2S f:IIV#{d)mP^aB|z LoR!j\1wJAE+ g/*0b iUJ{RAiմ?~</ry)э,|7U~>pf@!ٷUvr4M:w+L @ܹUDc<¦oCT,!lOrXWuõSҼF9'>kNiH LkUؗÒ@cťu~+H%bS厓I H5K =@p5?ݶuq 5r\3āQ@G*h)cݢ*:D):jjW \wR3UPw x fkA fRUJQ' Wd{ c[[ ~ւc##w,NqA`x&,QoM!a)l"= &;PsU=t֊i ,A>4IEizU5 i#~ud`~ؕv I)@쫦Ҽ2r%ώӆ93o3HlwH~;6zJ쨊ؗ1h WԒW){yzGa5#&O5wAxP贳yc?8oks(W8sPzXsQH ^)b=Sl 5? 1P*ʗ!E%JWW% ߼h2Bh !'KTbJ7hh(r2# `#7pGc̾Xe+D%i.\RxyE^o ;*Gd9Xsȡ>82)w:t1opTMZ#$Pix~,*IvBZ{ߝ0WmcI61\{Jub%CiFѺL.'N}A4tᄿw(u*Y91 ;J)So:tgo"cUw=,D~l!x9$3`sK_MgaV`}39*<L݂ȐVQ搝!e3b]G-~~!6Ԕ{;5/_j ǭPDzQJZHxI&_0Lݮ߲{y8z2k9ɈFYDؼT$/pqn/gH3|^ln,t-tnw≃ ]ό OBYY)qyV az%8fTsyucho_)_%xલZۇ2D[E.muHTrqB:#_z @yK1<-mnjCCTGnIPL! 9/l ܱ#l2aW 70_ 7t5[$~ra0ܛD#Uw8mɇxt8I`pyul LqUJkwnW"im-8F_m},wx[/$vnP;l;w8LȬt"}٫'W-.t/Jh'r1I۲ ;0ҳ1Lw;r\g8^ 4꣸"yk>uS+PRKz3e4)ƚ6顾^Ue*\ju$>IqU`nWm=؎ SY$Cozlgq3v)kBl|cYlIO%Z%Y!s􃫃\ÿں/1SJS#UdvZ}8I'[{s)Xn y-;LqH[A6 NBE;SKVv-.V7l~(gyY3qžaM˗7h-Y~znb1=F18mAS[(CDžEXUR<GzߵF*ƛ`lhd)ްߥJM4~{S%@˛ztwNKAZlΗfZ 1#J93LUQ,08"3AuG8#o1+h~p]KQzr'l Wnm_O*^hup irҀ2k"≲. Sty9RpZĕyПrV2E&_!ն0 ~/È6xdf^0 sL;޿mXa\1[ 7w,s_yO7*z&' 8=)?]dx|?iMs9;Ee$L]%zjy x<"l ) +$*\Y%x9\[GRNaE~t_;GKQJfDI2 ƺAc{7W`6#mOa5;0ۯYnZ):WaȾn!t#]ErP~ڭ_ʪI#CPxP(P L}+QS-)Nrۜ{|Etq1~sfUUb'McBdVRه6P+#čkU a d{Qx=qIb+ӍL=n*6>iֶduq6О|I(KσJ,8/i]fc0Gn@tZY,dVSFH%(+g5bmuՙcO}dg5R! 85DP[Ϋc=E߉ʽ_IA3{PΰcTr5k" ,3o%U]bP2ņB)1jHBdο"zP:@%ꨆ{d )@OlłF O-㲎ضL:c:+k`bwMޝ*,5fC'xFl([ȜrV 'Xujv}^rss7LDu }1*oErt:c+K( ͗ʐ; 8Ё5pTjr+}ӓD/Ǽ<I1( q 8tmwm9 匛(]~KMֹrv?4X爬5 \J1qg4+[sٕd.n Kaʅ.' ҉-K:Nqq*Iv9<}|ZzOLn-ʡF7< WNX5+Ka܅i$?՞* *i,Y^ =;JyEt' F:HCaL0s#3)W˺yVEۤ?A0c1}suɹ*Fiq&fF1϶vnR> S=V_֌u׉֚A LmefH+``U oD^ Oۚ ]&ޝ舻MӭZj{kyeG€9:h?ݮ<4"&r=y%"W}dPSOQC]"N_=fY:xe؂P#mG- E*$oȨObİh_,6 LƓZ`m[q:GV/fk)x)!YVǂ+?H}yT=9JrPi9KDPE ?,3\I+Ϟ\"^np8\IepxLzƗ>w`D6d,^ΐ]!=@:MzE+@Vֶ=BX4$*Z^Qk' ʗ@T]y Q7i>z`?e(eN0A Ա$i ƈ i`6k%AIs*0Q 1lFs:Rnꍮ75L.>ym3l3)G[8ݞqeEP@-0!Q[ۦs^$cl/d k}9RO~>wl9@jl*pVMA 92]H%Eq>=L])5q%8-gFYSb!0?M"0?ѢI^!њKdjḂ]k:{Cz@R{Λ~pO ifr!H[WjOje)04%ʓ4(ߦMF:*x Px:AO!^ ў?g/Ajw!Y|6M$FzjgGշcZM E]s7]iKQKBŷbHɥhHUVOȨ"c =+EdXv!8_7z)ejfϿdz4!엨hws G*QM"-!mJX-5 A?v%01DD)w:pMqj0YZ]a@1p#c bDLVSf#wzkp5y I KnRoE1wpNuwGFx Qh@k0 PXq"QOY*q9D#Ym:]~mqZ.' _Km`/~mY)Q)@Q'K[kVĕ:* &F:EJķ G=@磃 {=Z@Trq/hwe'M 3b=g C k gFgt|M-Y^ .,|^Ef.RI 82yk⣔SQ} ɥ}|e Zˊe_ Vjφ,$k3dy_n{5dW> ZޥrpNuvl4z{a',GL&jzWegc<쁇NbWVc+SeQ}vȂSqcSP҄skX-`}<9_>¢DYi8܄`E@x<u4g ]V[R420Tψ:,tK]UcR1):25%0\B)XDq=e%'-S0i$pIР[sɆ >O^ۛh -GUx}E ;)#nx4Us&·k-65<ƒ=c=E{̵ξy:Y\$O^csԻ],("'ZMBTPzBN<1 H–뇧wU-+옣A˙`Kx/4Sw$RI:2#z$RQ8ne6xm,fp &SH?d.YnPT O@ I;:jCs$ 2̀pJªF@b>أ˱+%/f,dlH}~ߦ'pz#JJ<ҾLZEh,ઓy ]w_g'73yTb mD.X>v`z~zWe2%B:DbM8.9V0&Lu2rU^0ޑs")5pWQotv’0ғ W^8nѭMߋB~%iڮ!ÿ-_,/kpHb2`\V0QȜ>VEay)Z^>9_tף,bXy7 Io',pʜn,;i'*pCclͼu@hZJmɸPy'EPd]X& s; /<9*#?lyzx호OrVZ$Cra(}cP"J>Iִ'"KA^g|1Fֱ@)'Xէ嶗qXU\ K:ez=⩐-`ObwL \|`'{;GJ D.i@ Wj4: ăҨ9(tqz((f͎G=oӿ:KTҚc)(2{MeE&u.>\GJc,z0}uEK.x5LF}@GNa&`q$~kd)S=3Wo|xU@40usTü3V$Ab0Ehߠ.\۫aJ߯%1dn< 7au6<'|^!lo[@k-⊇Sxerݟ|V0\qRx]/Z kQ g'T~ ]?L΢hn̒WΑzp՘E^&4@wN0"I6"JĢ "#]!?z@XmukܬV&+gx_fqNP_}]@$gMYT( .Ƭ5B4| sAlC}ooO 7#w%{nJ.iW h. M*)2xp;3}^!:0A˷.#i#WqT]+ ٽה Dz6_kd̯939\O%*Oh̸V?RxJHHaO=w0a}*P?ԥoqw\w`jq-T?N612A4v,˾)]bi(FS"֋0v?drfA~@=v- c[4̯mL{'%|be-[W)ܸEHt>y$)6D4 /V1zM+bڰ1?S;>^ n@@ Ŵ ,} j37[_XIu]P QK B=q &ɔ)^A8\Kar԰ 3}KŬɽȐwEо io2(uqoqڞe{ʖfǨa>WLmRe`b}\0uG.D!~ %Բɝ NxҮZ0NiҼ K)^>B=>gz K[~"m:U @2ܐݨwRv.53͆~|("@E.,#g~2Rdg-:胚ޭvE; ij`>VO4/:za*doWBOW9۩֚}M2} Ss:n> r<0BFf:_oB9`jB$4>o5zMuHY C`SI$i}kk!]h.Boqq'jo3yr|.\~4oQ% 9P҉&>B3p)Eat \Ey0cs%ԲWŞ&Moj>-d(!8*r(zvݢT6 ԻpQ5#6K.}WWHˮ$O$o>+'2Ȍ&DĠ'#1ZO,҉W=r9έ"-j@߼ZnTcBW7t3l+|h;fVks}&G--a{\Nu)%um68?LV 2`5njF'!̅lXإo&=(#喪hEyбTx2ld:Lx\VYkʊ#h3CG_nhZ(2ۋ_Q06FCmf`)A[)EкUN+o>ÒK7ٵ E~w<+6S38V^[XqD}7.AZ#Tk 32ty5S8r` :OQ4 fLw`M\Nb~?e>: \ 1H -;ef` B6bHSz>d[)_/6NZK\Ƶ?8Ri M,p-++6yo_gcYN!X4ۋb:Ug:H/[V48\]Y9uZ+k-J(~ ̡ Wa,;SXCNHZ8YJsKܧm,XQ{6 ¶o<&4 2ѶxySKH,(nOaJ)NZ;4B~3b*@\ ;*-m-CÏ$!jfoÜmz,'d1Gl.n>gswp|7TQDa<<t׸[pg Gl e"ºɗo+o9K:ܫF+ғB_  @kG?EGtH\h҃vgH~TQ]Y["[B~9Q-6GP_p\ 3|&-[2Fm9HV.ۺr&;܅a|B7ac (Rx^W⨻>3QJl۰MƋ*JӇf)htaC,[=j9`('BD^doJ_B8T7WgbB;E}EVӐ?NN4kٿ4xPU [ҳ%DyetL~6eoH}j҆# Eۼ@ru=`Xm_aHMKH=Oor/I(CLA+lBpρLQjtQy\4l?u3IeT$UQr`&d7  `"FF$|-+./ l*&~DܷJaLsmN)fG%}C,RjI^ z=㗰tWrzl.7ANZ*4b- זpYY-ė= 7wXڶiWvNj)DTZ9\*D< , mѣ&9+kXxZOZh)# e}w+B<7 x_=#̟lC]I&:”(Iͥ~V䉲ԑщ -WHΆ"vKy.wI4{Xm`uMn|G֚Vպ؀2sR 2{]q4NGӃZ1zV63 <"lHQQQk+~J"Y5ٸ鏣}EȂ:~l ^×B$ f()._|Bq?t'TV8'n$a%;T|pSy[廀)vxsk@@ $nRQapR U@@.㞍ɰ+r(>L&tP6@~tNP!&+w:x=z4-[6Sq7ϝ,XE=-o!6u0pOS=~2 l(UzgD湒XõlA[?a(&A_;W5q4"K1J0M3%Z}fѻ"Ue?w,n q(\H,*eZb`vGtˠ?b .07ߖا-@FFe/]6'9wzi2o<ۙw!N$5H-,Z3ןM/-hUqTx]z+Ov]ߨV/! &T_i#~^F>?4RW'(kbHmf7LT6Sd<#a#= |DQT) p[ o||Fg_A[&V EʼnPcG.O8ARh%<}o$#ќP/|j5>$i'_Q (à=:|?+}1M>+׺~oWcW|3h0 ]wŵ Zdިv@hGHQ,+óD-F.!!;$c,@σawU]o*R(-Rzq!L>YE4h.`o4Ds6f2fyrym#`WhUJ G1^Fw=D;gq8 F, yQj|#D8$iL`:`a~lBM3x`qEl=Hp.N(-ֵ4[|\Gr\ԜѶvyswɝfIELGG#!.3,DIٻOy8e3*{GukFpCW}İ?bs7^g{:~:Be-q(΋L+?yyr܁APymwP:@XaolpSR; /:mnu nĚcT7[58?oH~la u8Zԇ1/=tVGR}3.WFs88Z=OE4U Ewm=O'2_lɀs=Or>HtF7j ym٪P6oWn 64tΞY+ElݗNWIj$g~=@IWzpMLȧm%ƂCAK|Ye$,&kGBnl!n/%ŮmIj-ܷhbhG )̧N625Ct%y)dٖ4O5 c5F\}4o+Y0>Sjf~Y/ʂr/|S}ډ#FEfM0Tp\Rҷ_@px=l!f]} bԽ#YO I cDf'E^lnBnz(r1g J]ςדJKh CɥKs bȼels` Z6[͹TvŒPKB܋^1]Azs /hʊ볿7RlZ͛=5D)ig'N(}gH:hg­IdW'c )XwpiwBE~iVh|8ߚ}?&̀e ,C uZt|hKWY) 4Ciɧ (Hz{/a50:=xWnmF[{*`jTmZF@ݸQEWsr~õH9(p9X[楉u?n?J#%ț/[:U*7#8wi#޵-In-Mdi+I2DKGjz 4{c %T*9PQ;[Ǎ,kRj!4tI[R wbW1:i?uT+ؑ7yogõW #*PئbbinVa+orkyyr-HuA56[L]S≋S~˸hm KZ6s:Qpנ;bssphR/HGbA#$`dFMAcl~xѻdX?%Lxu=8`RB3ciI&H{e-Fђkm\x6A/:*A`mL4v-;X蠷mϾH0@omv2JUn\S5xW sF?(} FǺ]-*Yg.q +kOF)³>0^w/n*k5mSh tp1b;CLגa+Mk_wGYqbKRK4&JvZɋBJEyS/ɘbn(8p{ XycCjC{4E\^߀I)D(z:~H V 4b?0BAG2&(e/-JQeOZ9ƥ`; r[_RVC^:O'B#`;H r^ݢ퇩-TXRO{6iف鴘ZuU:/ _`9xD7(' ~GALq(7NQ&PXar c ={0ND`٠ŏg۬uӲˀ_pVc^cQrE{ [+hDfz{ ѣ)Gsꇴ$5*Fٸ]" jf 2uh\!W ݙF0Vk5?N,gOGdS13Q0nΪY/W !~ [jFaeHfj =#2sm4{n v G cwy*L54)2}QA⎊ku5S(n+gv:sa?!ͪy2LSRo'_!XaƦ,mjgIƔ Ai3C.ɿWTuqVx>sAEUIi65:VK_գ4\T9:ijM Kg@,#v]1#N$ƀN 5ЈWeN>hCN$D?||ؑ(kyl VKLro4L'i'M_IlA"Yd'F]sY7I~ճji#ՇT͟& 4U.a݈x"g4ߔ1BKn)a ,{J#*pD'Hm!ZP>Q Yi/LN\'jƶ !xV! / UL:Kf>'Wap%)+?)IRUpR ! %÷?Ey>w=S\@#+y˿O5]~/ ;g7 @ + ?."K00pxC9rh*{+ I(_Kf!?伔.9WtC`06V S<&8 (:,O&*Oٟ|Obu+Y\ɱj /Areȕƥ(OaIdadrG:TyP1΅!ڔ뾗lO';L&h@eX%-39J:o9R7wh-x?+M;ܕ֗K<$7[t2[iV[qt2UQ$T~U w.B64L;S|S$}  ~3=_T7Qu&p2D<vl(ε,WO喐j?Wk(w&N,H[ c5M!닯g FSzp]9ҩefu}'mkzplB]zEEo{UW!@[ދ%8A6&#q` 8Ӕ7'.3R5n2wgg. }?dcpj[Mj^rƋwBWl}ٳUAt ki2# U:3 yX`d%o$h T!k|k^:0'ؑJ΍&='V"bHvKR7'=PU98tfؗPM" F D#p)`TiQQ NXA\ HE8x5QpʲI*-iVۚnF;.2v|vZSeݤ.~Ӵ,[<..LAۨHl ,X;Jݥi8o۽\ )P;wXbk]ވkƸ ȓIT#Ä:f\DxSǛB@k#)W ;OW_pcajwLDz?* E"PC1ю6S]x7j7ߨfYe IáoUxՃ' ?́N~/zF4 7.䋢}; ʰ! zv/!Gؠ˾4[Zƽ],Tzk3Y-JKؚE'qP{l2p4NY2C׾PSl1泟7mlr))a{wI;yH=cR\û@JӸZ,M(Ez65eQhOZ(|-[dTkRp >NKPvpy~l*oH>8f:;Sn+a\q`q 4Ct]u\#Xuj98/kzQ&8P_@9Cͻ #ėH4M,@hyk|oh d*> +if0X2δx=ݙJm6ԭ, /Zwػ=?"'>ķ~He(Jq8TI){~uq Q0'҇0$D8g4Xc So~B;&o&ydEk5X@:@s6w6{`veΠkܙg\wd_[Г~8S#q0$zPFj{0&r-lgޅM2yg!3LϺ6_[)>eVј*rE|Ьu2`cT%0P ^JW/h( EE/rճ. /E.6R*T/T9W@=(B.CowUf #id5>g,M< *'/m4ٛ<2(-{| l5 H:faAB\ ;E 1+;A(٭WS;U+!Clx=VG`H3.  C/6lV* hufZj&5BѱCEU;ya1X8"||T&4̻-~>R/4]!1^NJvB,Dʚu <҇Ï89hwsR%"/c7/hV_?KK,Xq CDIu [؛4cV5,*HV`AwUar0 J%8WםӦl4  "J%P ;^o}:C[ +!EᛐZvhNa=ʆRGVcJgU/P53y&b+o~/}Pfx\: vlT1zyșG^VQ(HHLo3nsYh[ Q$XpǪ@ [PI$B[ȒCo.ӣ>1'E`?#H Obm%195uA bjej=eA %Hr@y]9&EcZh:} @N#]xGOib{hYB#f3yY4C,`{3|5UӤQʱ/}ؑ(緊M45ܢɫ Wv/BFVOJ<>C],< Ux|j m&; ӌzS ^K>ou&gl/픠)zڅ}ϰ'dY R4w{S8V(pUB>L%.U˝e֒[RL \ܦ6IOH( 9TI@e%VF?YsKQ%C PpH~6Jga~KID0> T ^!|>ku4:8zYƧ-5P|n %2;,8E@/Ir~xz@ 8R%w;UJ8LE0[c;r,t#AVN9!xK[FT^C ;?WP!aB ›^KQNoæ}d&D}}/N7_zۻ2[7ERZw<8uPXukEw yhG&V_ozʁT`x~d ;zP92r 2Y$] VO=3Qu٘l:_ͷ9ÄY 1M Uxw@b8p^a6#v'с #`y4)2YgLvi.QlJCX_̶~"d^)mϧd{}3x-<}=/WHκûCunUg_@:Cgb։7!So'ݷĴ_]ԓAfLٛje r_1oV쀒kEQx٦&yOުU}NJx*yĞnMX2p  !%!KGp/jHѓZ.w V4oao *d%4cD- 56F&P}(7y\(ۤ3nB8W.DԿ/E6\ڪh mBX|Z0s=2vgaRiJ9M{f.e\4P,h]YmBhB(8Irˇ&VjB_;zHZC]侁=fw83B|d}-%1/xOF<\Ï9M1-Ρ:]i^_ס\5s%NBx1ȭw6zG~'u}Y3dXώ0(4;[n?"بzЊš%?@o<=ƕqstx3u`@BcB|Y^Y> 5KVV!X7Em#b5П"cF&L0I(4἖ʧO?j<ĹVvՃ>nح?NQF+']blYTۦ>aRXd]-y2BS{T8(֨r\;sgH4?^Ant2:+69[{]Q$q Flʞklb̡UAztpsw \V/bޤ e*ojD"&A2});^|$Sk\bb"+CκIG ,Ϣ?x6'DwnC j{ƩT5_hR.7Pq 3vrH >]ǹ2l5TN4R/-sSމU@(ahT2{:#[|M,H{q "+ǭ~vW-؞nCx&Kh!LΜjMKf*Fp~E!>Qoa M)H?͏njzϳ݄ė- &ۗ;&lqXu&/ :cƼ}j)\EO`#oX0B|kp]D=clژAf_( [sgz22lK5Wf %S~bas uNte[גϦhz P$=e(ؖאN_ożNh*V0I:lPKKz>ÛGv|y@|6M,$rqRnڲU"Ԩt /F(I(CmEKUqb`c %T1B --8",P2)7>Vf)X@uŽ4oά1z01J{utA!,T_+|O4|+7hpOixeh̆kFI@Z/S:.て~hĹ;I-q,C@!dsq@7r<$9.4UA FNƒ 9K a F8^gj/}Q^:5[*?pKJVo`TnVNֆv&;#\֯UYK~~B$'sapt=&0)aJ thg$ 2D"2y14`.e;ix "Gj'^n{uL\v5vNS*FE8Й 8Z7 \UV[N^bTOʤ8?;WPv}р1ڳ8Ak B5kfw$BGhE -m5 I:y-,\Y5 { ,]r%{˚<%?94zEy tp2 FiLo :Q1z{T~Tn;S&l- C_bDf -ॹU>&\ H,W(hpH{ŋC0B╭j_i 2pMc/ w%=#Y@ue IO Y]T^CJmV8Hh!Q1bMu`zvh Oŏ<\@E&{bO_^M4.Zm4h#vFg^Q  4V{[lUӄ_P})@0[UHBb/Zab귺պ7?41IO!迲5ǜBvY_'۠+,Cdr?GF'~ Ktszd`2 Y4t{x}zo b} C )_?(E|rv],Ssryho _[q\dm$[Ce\EG^Gl:vBRBp vjr/W*-!]5WpteNʃL#ueE*%;Y|4/հ̎`Li3ۅ&Hp-NkqUWCb0$+[0Tewwr͠.EAh!NכLuŎ*HS~f,wuZCWg/{IAd` lc|TaZywzxgH*_?Z7~@L.4]i?[axm}B8?;J!&ϞV˪U0E9/o}a@\0ȱd-Xms?[qH} skbL!e1W빔O`=2}TǧX漮3W~ւPcexcb6P1cJx$C41V.aKUC%D>Y%q1_qՔZce~cF27*,ڭN& d0Ygj{P)oR^F@א}c(1WWj2y%|M3? &t`N?l ' "t+r䑽˻C$hm“{8V%&rcx+e){ "π>EW'ǰy<3 [J{{Z{7<<"( ~Zb48PDkN֙ kV9+4IS/kxg7!nVBB UR)cLz_dH\x͟D ⚖^*,1h` Dw%ut$u!feEzk~&hZ DI[ߧ+M^ $t,Df'wV/`%bٔzPD{5DRƝ. #WC%rXGE=JNk1[RYe a8{7LnxȈ)2j }!}N;> #X=kk,ݳ>c66;$&\t}1U'8Dsnj5b5Qcқ pIaE wh7n{?rzu@ӕvAO: SR&N܋yZ EF(6n@+H̢6@z͒SeyzkFٳfH K75}[ ʦ}J[tqlWxW/GkͿK1M^Y) mA1ΨV֦q^a+ip1u=kZZ g ^~a{=Mis)bRhf/*>x@jn?keۿ Ʉf0i`IM0_ $>;3\S170@jq/[?/-$_-??Se*_ Ϫw(V@wm{+rtV19T_]1dup=*iyid Ҭ6}q5`),ST=2%uӭseJ򹿐7)&Wmљ~.߀%?m7Hm_ui޾B]Zpޟi0U+-X5DnnK""UZdng 3)˙=6z7U_TY̬tm8_+" xyYОjo7!8!<7LAyi+VY^/ww/?-GQ[Y[tǗߌLW>rY=' }Ma5Uu4$(i9Ak~(/\Et  q_QalG+}j Yy*-XR#P(ͯxgTd$@W{ "6{uRP)x nzŞg׭e{(=a1(sypA?>UA:5B:YW@o=HK uGO"6RQ"[K%n6خ n^lkB@\4eԀ)H;PWs#1"CgUn׃a<{IR*we Ee]n[8,I iN> 5b -o:Fr-2Vnh3 vnҹ*%;Ѿ;`:iȄdٔNu aȏ#I\O4T SǷ+z 鑗>tV8Ne8Tm=a`2 ={umD9nW9M~7% #^ғno|k`H 2'Uv_.lXYQ;WSY2KRiNf$DuupܧT9Іf]Gdn8R]ʌ[p\#v"kg{ZSp\bU_ 9|F$~jZη4KkC 2X|@o-Evܓj)wr̛=2 ?3ZS%er!=_XzzM\E1i'{%:]?og*[s͎6ucŸ*ƞ dGۦP#֜N{;-#ⅳszb09\1f- @݄Yt P56` <*H"(2 ySEq\zNS 0^6XU/es'(di'1N(1; t@Oq k`zѪ7r?'es5Pӭ0+t(VKfObtܤhHmW "S  s|UjQ!SD|4P)nOdױ?Ԯejk:ӫC2dʮe#}~p&YjΑN=8m C3aO6O2s oit?eVgOkFPQ1 3wqX ٭]i4eOT C6!3%H,"rLLXRC"g "۶? Hu|K\gj)w]*-ǫՖ\i,m>SOh)qʕPȷy3tuq&&4OUwjW-9/V3*wG%>\m\gt%ߵ>oJj)Nq4W6ZbKNˆ>fVö71>%.{[gdx\.Y Qs?xWz~J(/xI)UG`eTSq\Y5^B hhbޡARrQş#p6FNs.9I]npx2]%C9PLQ`B:/E{$/0<#Y)ԵPT0;<MRA?,Ƹ ɕU1 EUpmknKd~zL}c<>|!Ԟ>Dq$,' ]!NZ9>JPzcC9b1O Ԫon-}hn\Iڰ`;(3k!Ս~2:D' ˈusTS>L0!K*@ O0pY c(ä(4t1 *;[-qW5 fN@cwL2TN9چoE&1*; U/Ԫ*7Uwu'=L*1:br9A[TM?*$KW[I% vwT/Uq:bd Ց^fލ` ,Qۊ =+E8|U,sC Qes2V{` bm䚺jq׹3Zs*h~|Wj>H:hGFifؘe#BΜR/H&I1][_-Jjőql ޹Yhڷ%z,Ӟ$@juCiSb ROB[*k|(|ŞL_ RűbwT-qݺ~zJ .{N4dşfdJh,$=DoۂF*Vq)[^H"ϠAy3d:p.t15E%ږfae_Lk~ag|'qRԕo\5 ˆ3a,ZXOVۤET,Cv鼀7 CiI-K8cQU|nK~d-URjKhQ?<1QÏ2E1xi0ɹիFM#5ԼU|/q$ Яe+p8VgdHQ?30#1 3܊g4į~ûfOQ奋E {]r+t 2F\ra# 0;Mf[c%hJ6 5vI}OAVuƥ48pCѬO!.AG*"#qepm6`,l96h[ {"1m='f"*G K ]xmA΅4g%U< (eWVP,LGP/  ̰طC'p ͸~r9&yE&Θ~9N[bgr5*( &҅ߚu~bqg}?ZZt\ տ0hc5 pXRA,yS^5aRS8'a_Aw PF)` Bd}L9Vתoa!$=4328+XUL`g bᅲ>Z n1ݯCK(r Sq mbz?Y[mN%wJ!eCxaLeJ͊"8~)}49ǂJܴ, KDp$mq` W:ie%erXQASۙb_c5({.ka/`y^gH1lLe̯}1A4+Mt+_Nwo#١+/nd^2Ek#?{^֐ZvaqL'2d7,@ sqJ_SX2J7PJ%=9seޚ8 [ 9.͍K6`&!HFZ Ar'\6^ w$Jr{r9>RY@~N sǎeqq֜8:5G9'e.Uq2 `ϾU-JǪУ~"P ʛ=d,|mJq5{=&arx䉵a@X8kuN. L2htD)Do 3m =IrqshY־LgLxI[H ӰˆS.@?)Rh)r_``٠ޘ?MQqT(6KJTڹ]ɺ^dזm;hE}@y%Ɏuzi]?rvSozɃ<0,ﵖD{>,X:~mTMeG0aNH}.}^b##^?xSrhhFoo6rp}Ykp/&Ke +T7'_(Z:%B#ExA*"ʈaE }vQHvu+n'|ZX A[`1QHvJ KQj,Џ.?PrPC>EE֣Mg$yk>zWVkoe:m״Kd"A*r ep? 靉, k22mF/&/GFcEv"jq*`G9r{G5l4>ӡ=tcπb(|K1~eyޜx(]j@=/*A; kDhpGYGrV24bsV"2ң vydE@oY",8̞-#W9`t-~ 9҂6Ezm-FT}=9 IvEjmH-/2Dz!^L4F*8;yzzz* c)A 2k_s5 Ev=E_YxN/1]׼]z,HZi"X9x]r˒1-c%6¥To5")X ^#[6Hxz'_ѧ\R}:"V֩z՟r _]aGa,L]"n<]-AK6]d/릩L\2"U O؅cE:oz>Fd׈Dk $iֿ@kSoZ|^'6EOpAlt7v3y@ bE XW%h +kexhZ?|mEt 6!9HH*OuZ9N|YE s?G=|p%!.ɜ(?0{X]$L$SZ.ʙ[Oa2yj=6STVVYLYBM , G01}k}UI3fiM$18Mȇ2Pj[[g"ke-ƓFߺ7ZCvY|Zd kgBmKHl{9Bvυ@6W'`<,k !ƃd:'/9Tٷ6ԉ{}\ 6bvKo,I }ddH9ؕ}bJ[O@Ů_ahy吳њM^':@ܧ79# xGCn`јg JC--]o_k嘭kgZK U=ky[<!*slI:V E݊ mB~mEWCˣcz-F\]ns\@vq 1|G ÕuJs۹RWKG oS\s;Tzlj._8+LߪC2ŗG? 5d'Zԟ9wBs]vⶃ=("<w"k$+@pT&1i豐eG%1@ ɿgFIVy 03-͚^ݸӦФFNDb) Hm͡ヺeRwv}V_Tgm5+sD N169 -rPKjfbko(|(nׄI-R(jh'e!|gǕ[3E, RD_-UP8˯{-PfiݦHD]]0L8q:"]$I/)gw3)u`ҏw0hj!E*Y:bEɞ7 _Gے4K{+|ܕQd5@\I0 ן6$,X(LA#,Y̵r˳+/4<`j!zzP}PQ= DKcbʷHQ<#o.q5a'n(*XuU` {G #IfЛ'!D@9Uٲ3!~7˵%n.gB}2U. Z &B-n:ITґ@@PuX,ۂ">R {H`o9Ynˌ%B$ ~b5la: c)h;|/Ʀ]o6@Q~M=Jjˠgд=6N6K[UK1c/@ 4PUtٯ.2TI됩?vY?`{gk= /F,= ɈwIHd:{tKΑ|DZ`x0ʑ1w gՕ 6[X0ro U<VTGxK<|-LuC0oRS0NEmNn mUy +eH mA JqƠ-!P.G,?yKƁ3wp+pٍʕLƍ^coiQ.En?z;{fqo@?O#F8`aɇ4#.:wWю9'>8< Vo&nf84 Xh, R:%b/ +UǦ.}-V)]P*9 .[Wa[ Y.>d̞'XUqs+A,VPۺ iJ~ p~Xx*⦫$;' ògb:^!>HM\.OP"Qlׂ55d^F#HCaQ%TG~tɲHI$A1tp7*5  [2n[߆W/Zw[:`! wtRAMh$,|۲\8?-EW]d0 k{W=Lj)?D\"U s$-ȺKLG \@vtޜew-Ew10nWx>nߩ˲dIwNwfmWh7cf̰0ѱYU A"-Z0brOw16Z9bONX6J!٥%'" '૽9qnd:8u0b<=H ^_NP?[i@O3 <>H= 8QJ]h֧o6 f/##&7nq޹ik +̛X ΕJ <|n4PLܫSNg6q1n XFJץR^U{j$GVr37f WfF;׼ W)cmJ%MA Wk`Z%%l ft%ҒmI 4P#)@-BEJc>k$GNU-*"-H1>TS.f[MqI31S`"6KR"hniq8)rp:ARSObEs:Qь N0Xq=S4 > ղ9(>t烲BG"jѹ¿΂Mā "#Ifo#*s.%eҎ>+ƌ!x Zc< ,2q  \iKY7Y阖e S&-87%n9Zd AQ,Wn5 BO|S8ȁ(=dY 荆#\j6' XHQ9Mʦ!]U=*=sST/c6zq=YWnԴg2E%lDM &S4 oc Up31(\i0Z  ܵ̇}%Ť9a1Dh:Hg9fL*@624$->A!msRh RwIୄ5 -Od":+Z ]|\xA̼;i/_)Mw9Bt,";fse.MSƗH|KrK$xʄ/ f)uP{+-͘X RX?0g!OjUXO xFǘ<ѻ,N 9ԂkLb`8Ӓ^E,$^@fK"]T:z3g&'t/ F%J7MAtH-4ϛ _H-1t:}P-_i~.r \_[_U[C8( qΔӎ?B_dG𮒩;u:iZ9 !qEBqA5U.|B_! Fc]d^mHJcs=1R=48ޭwoy: fc 0]&Pw#r& f]4]ˏP%&"-3ڀJ`7%WS׌9eb.T\Md.0720Ua8eqpo:c+KlA8cHs \ ͌5h K¾۞sXyׁpUC:eU@_t*rX]͜33 ېBZ/r oIY=҄ń{ʿ$s0埨GYjG7/$u7XxBgψzkmɒĎ+p1K'բbo/`Uv$иh\%5=yCqy3Nibuwuc @[&j|9\ @>d:Rf7 HQIV Jaiޕy.?*GlU\D)Q /n|ТLOCҋOj18E&~oyt$Tv.ZEPLD8ʥcCdwȢ ?N*ZT Z/ȵex/7NC1;ޜzNX}3(&x5dy`N0SyPQӭX5wgaY2_Sn?@`D!ЕaEAU}XFP$(o rtޣNҊ9fA/έ; F u;uQ-Vs rPQP,h*<?™kaG"Y;Z}CdOWϡ N9*~# Ӈ @b S hsJQ0m"FwN>;.v nʋ7)*ͲK֯Xg -hOg(cM?kf:4F{`٨`7huw9UE5B55;3Q@4uDǷ=SsL,Ã"9Cyf"ԏ7cUN DždQJ֙Oe hkj*!Pp< YQgVE|I&\<( +D— )V4..t 3z+Xu{-ٱ"Qo?0` djF>gTǔIh@Ͳ1N hSziBG.'EsN N_`V(Tb 7-m|(@Ү$Kx}G>["-xW{OC2-a _94:en]QjU:6F#(ifMAt)yˎ\!ItXm&?S壅֝`^m747D8A7E K(Kַ? xC1txֹ#ܱ^4ѩI${rÐ҃iA(Nf>‘C<> r^q4<+u6w!\7<ݗI p@ sFxb6lG!$`٩h^/hN,+9{wӃ1 "˯2\Xk8KQ]_Uze:(Qz~XHQS <'}Hct4b,DZyܿq< t$zb\l/]<3BY>Ov{cmhjK`uT&5GQm#a٥@_Xhbyׁ˓M@o˿m`e?z!ˋ&Y1s7` =C:ҾWHBōC1tj Y`_mGc552yV0|4當J6PL~߇ae\Gsƥi z}_ɷP;ɇY .KQsrq^o1,( g2BkUPsBI0jj#[lˏY&b h%皪g >w5pY>0Tyeϼ?KSjS,}S]mW>k9ϐ^RLdԭk YJ2Wr ѻN j9Ec(.$PƖzh㣀M]K& a͹VS©"ӍgYwQFbqrT`q7><<ۡ, {A^}k!2RKe$vpLa]Ei>TɆɷ$,7ɫ ſ\Btѿ ~t*6{/3G偁%uw^$#l,'JU罻"b䳣14H5#wB;] ѱmK/v-魳\Y1QhHo>JlN^Ir-ͷ<Ԯ<]&*,}bҡz2>nz}nu5i>9RvzRaL$3mwq`TeH`SZҥE|l5^/9#N38oX ~wk1bp/fwk׌SUİ'X b,2;&AwӁ[|>oȊId"80u^v4a|S< :\v>τTSr5$ oȵ}%Nȧn(V+?A8гlcnI..isRDJF\ Ҡ芣 wt+S5o0T/rUvH_% #PUĽ9ATfHc5gw8&*PDJԨ W(cX ޠv ᒬ1pb2׍%n°~__8ͯZ p.D^?-uS (h#RDqֹHHX VmcM{}[eWؚeǠ5r|,vK&Mߧ#q#|fs=6ܧ\P" &ÄXV*uԠ5EζAD3{&rfARw^V0pԛI(i{&nEܨ,lr4cCl35?Ը0 TױfZ0A3R^~CFo]rȟ9w)s-V)6eT+MM;I*ҶVpZ<;=<QT}/nPR~(p-LW̏{~/E8Ӧ/"ʢ6/|(脑 gs.VHB8tF(oK?p81ޝ㍘%l# D^*t|H?PCoGzA&|^/Zy;evf{#!(Zn=8tV?(':U,CLg3UH؋|y%*?Aٍߔ`o B$Vz_{;eڱ蹦m=UTGdx ؇,=ye[ kt[F,զw铗@ɥ V]6(kҾ(8~C[tZ[(렑"ؠ*X8Aacp.ҫM2cfs7Z0fLe%8c5JF-ycO|&q!@JfR .V@R]R`yLQS/tܱ$8*2ko]Ѳgy^v*J,V0:Dy&]b~teXvtzV6NP+U[Zߪaޱ1ϞUΣHUCY?ji$aLn.#@g14A=0v71Sr[G˳SJ7[IxVA'}t0f歉SWm~e5/,n*2\h@Xt]8׶6q]ʇ(԰BJs/ t뜄X5Z6=:Z'T($m?;Zy?> 0OL TV2wc ck5 VFŨ+L"GeYܞcRr&1UBm3"~kd(Kk0Z E n@buAh$$L-Q%f"@,E'V!N[g hDPʙbJV@aekbih&]A8]6sqPoV,zd1Sp~#;foiA tl D(IqF Jt|pC dS 5}U StHZJc+CYbԝ'\v *ur5NDd%s1 ^(i=0[M,=.6L4;ٲ~X3Ȧ1EKMz[؞|,wYuV+*Y75zILMG0$H\uJ!.%`ٗHENU { ȸE=7kT!IvJEG?6c#_{" xV\o,4ڸJ@>E<42V^Ҁ92}(kI>!mH'4KR q[ 35p.:Bӎ2"Ly ǡn2a>)P/ ȢC vG"8|&LC?dly(/B;7, PaKjވuÂB '_9Urx"19 +hBnP%JiXW::Ed<}rd;.HLRlML#%kfՃa[ڒbf^N7g$$7Y C7pjXÛ"P:Jkb +ZIG0ZpV; n9OIɨۗF/K 7E*8|+WAǕX?-(,yZ_ wXQjˤCXrM,J:2p`UR?^YXz]`HOץIHwSj?ᰱ CNyߘrKzX2m2{R{з6aFC{zYo'Xm ;LD6!LZф2r[i=%osIAzvUD4)FܱDPmz6PQH߆UEΚ]m>d' ,<=pa { ij%>Ż7'ɮ"yc8<: 7aI~'&Uy#-g30yM.h#RB#<#0k߹RS#J7\A&=W~d<#{ps4hC -2OtPSTZCf\׉6^LήH[uAU{ͪFJzZ݄e,OzN,õ ZhmP./2`Ñ % )6Fø+l:E0Y{ln"* $x nKtyh"'2Sh .57_``S|:5n=6G!v'4m׬ +1rI~3όQO|Ԣ`/0`-^5cyFP-JְVuŎxp*,A=-kZ~8 dMEϟ3!h-EOָؖEVb&Q {۾u 1/)Eeq'9\ZMNh? -6"XesCZj:{P[QFKrkXiç޳wiumdΤF bd} yH7CMi^xkY/^zxweHG!ImcX (^IU%R)0`L7>mb=jgoB޼E"6(HW|k|X; Tg:,QJWQM~_ef%lLvnPTH@9Fݲ@oC{+T~m/dN߷/oi{Ę0-:[A v]lK|y!0%λjڪ3lLlG,J/&Le$V, g`womS[b6AB6sq]S(9m<ݜnmn9Y`T ] Y<&21tPo}Dݹ~CY_O,&xXX2kK&ljr:l$t7 " 2A%ـ ؍5dmmڽ&$ԡ&Ϩܞ,h_h!D6S%H_p6G9 aXuZ^R{3}T)HfõAMq<` HO#bG?fl*iLVa QIhXq^*"}9#< Ѿ811uj-*8)IsS<`xg0[=C|f!$hmR{jk$% :0P"xaM7v?`FJ9"?>*''vxB$YpC1`}bN!|2:Y Z^=s9d0h.BďĜehqJ΅n`|!s^[ 9Tvc'l%)ȿV]OE({y$k!(((h<b!q4N!>"-֌ok~t=}h%LAJ4Vf=͌v\ra+u;p(bc v8 Q! " ?a" 1p dO&OjqzDxs9fy3X0^[H;!2^]ƉuPAG֣j&ܹ)t)G .+~ 3:g3DÂZ5YipV.3lBuY'~'.HZiH_Oz0 pEA|ѷdt0{(zzearS{/2Or4F)E.ڶoc5w,[5*f$&8zQ&z p5n9Y}~egAǫᾼ8c6*4K%[kAXIz$*R?R=Y\ K\fy]gowD2V?I:eL. " ƠkB=!%! ~b DID7*s[ΘbAO!^2r#hFt?c쩡FxuP[љW=iz=Qd쀔^8*&W2=lpvĕUFKg҅#1c)U&_esxIP RKn=qO <)ddJ<8 2aIMmTRxFJITK2d8BP/b?HKV#ٹaEϢYjH=p$NR D?F_Ug6+6Awxw^Q%]]{uF]޲Ah1?.;x![FbJG:ph ϯ_#EX͞*Ш*: I|\ygDNE/~9?0u1Q,d;ȀU3 fi>Nt0? oCb׈SE`Vg>\Q:D&,'9]1yjJ"GTn~BQN:o55hEFU|v?vZ1Iը $ѯL? ,J'5!iӌ^42`-f[eT $aLUAglH.ݬ&y[Fdx!G|vmcΟ?X)Dkb_Cì_mx#<-6:K'-sOm}0h<=KO2RYgqEJ~@Zq 6Ohn%6o=8Q[ )<2=m V브~{gZ qL$hH }hVn:flҫZ5+u'C؞J09w;S"=30؛9ۘ.e i߲ GxsD`͟ r5HBsR:8V L%ccwwedϹcD3O'&mK;۫;d:%7  1&|=,A2c8 }~wZu˜Ru !pb$)oqi>Ll)پn֧]]5ĴeiیJDdf76Cް8D$np~0Zo/ƒp^H22 yd/rzA5];נr±/2DŽrKSAJ ASK .&++ "m5\&lGs%xhmseN+9 0-J)S,4)a^}lExBE1RhJyF#bZ5տ[9+͇RCry٣lӡCj~ G3YSd-Df P+5 8v'EM[BIFȑu/nD_&aNP]vRTt*?GnO:!^TJ$8}i =ʙK- 뢟(Ş?uh:S Lc; &!S6X\e4&z IuQQ9|"ZV:(ç'`X19tXN!ME"2 -pqV)h {rz`*-ĘQZH /_mڽ0sw"&E abrqb|N!Zū BIQ*[fc{Н6PtCt8"X{&wfkK1TJ?ju I삵2!XJ5!\8@f&q I&5p0R?;Sw?tG\;u 88ݒY;j,Ӗ| sq<0w/F)zВq\x3E33'Z#(y nTBq B'zɤT'҄M˕X 7?E ~p `TM Ofk~I7dݘ`A>#Lo +~FbhYUwi@] iK-HNԚ { RӄY,DyX n-atq?i\Z0å=:Dk2-C`/3Z&3Y7p UqۮQ򺶀J?nn@!Œi[^5A<tPGCpɐʕ=lUѐ_ٵڨXwy:i@Y3Dg@ # +I ) ~rBUUI];}=~7-{<\40 ~/l(x0e.|t^l4Ňŭ]nHt>KPcdAʌ{Jk(-Q2i0 4-Ź|k.Y{R 1'-HG8 $aPvgO8# $|0бST05LUeLP[/ @>h+:lIortN"a㢩xoDZz|cU&3gn붭#=R%m׮Gn^hnc_ֺ!dž4 qa[*Zp3ƑRz:_L'iq/|ثg-?=kFKh\|Zf'W,3+ߥT0=Ѕg`5g̦\~c+3&x13tݔ`g!БNC!m[apf!fuIZTv "*wzUdcuo:aHU]kAƼLf5Gzq0 %}:vwNnIB«!hK$i{ɳWC/p|9gBT-4WֽlmBB1{)ۥ*X|t tySKz ;dI[n9ꫣ˜>ªcسeLnAgڰA>W ѣ(A-1}W)\ Xb{&VʨҾN%({Yfd5dEj&soҠY2=fXN)"xho8Pž}W1I۩xt(.us%Ԃ0Ydp΀pؤPf:plW?h{&Cðg=?K ڣ+1u_=3>zaǨWABM_/{AgBkx~r,b! RR5[Nb՟NMhM"mZ%Ԃ.;#}U..0Z%hVx7N&Hm۵5ͪ7 &"eG-uK4g^'BnCKӁڳ40MӰ\ Aq} s.ry0(0 œB N1F著NIq|-%& bHܾb]2B KocdҎd_t.۵ .*\|oqg9fe1իCP }|1=3EN<*ҚFNi9/l7͆g1vq'%&qKf-[^D}d۳k݁Iy&cô_VGExV&7}8!V+l6VQh\/f xyqO~GwPnHzįZ5f(yI"xv6ם,@B6 '3N._2U8{L|ofxL6Ⲩsn2gKH2&+mB@ȷ @4ֳl A(3#FK}bcG;ܹ@itrOVrϋ*c&!AniI8Iw K `z >=!J SB"^k!CSsEiOyL, .@* aBR7a2gn\vn)_Ol‚eSˊJUJ2}y{RzRtYt2I'W6HC4Z [b\:]k&IAڹȺ5՜dSȝnqm޾1 xEM WHYZ'z޴Bķ#EHzl W$d)cO̞FH8jB5xXsA d F^bH\ vym+XسѺRϦuTOݴt`%nqZ$UF86R|mi>QC/T̛ \!c? @̰ׯ0ήͮ"OTyoBeaAK)|NL<[+p~ZwCJy[,Rg9esPԢEB'vugͪͅ휴mjRP1ܫ{c茏:^m_Xo݁_ GKDn>|ez* sHw7hߩ:O<51c*;-j@p:aPu[Kw-cmK $R&H XaMԂa۶ViKԓ"wAbUd!Ƚ_ыIpյZWE-p}KBA-p6;-b tXkZEQ PɳxUaN*Ƨ=0*Lytdv,كf2.lǕzANirwϼtS. E.,24=o@t=hmBe??R.R7; ~7 n7Ok \ inxrV8-'2谄H;- Xj$WCqhI nuG @IN"x-V uBK]5]ΟSpJOum34y'yd3z DH l묢Ex"-l0GL2+oAVp ΛA)c{LzWR hoTu$QݱLQ`x5 #t#d6]O_c ˞=\ #D{ol51%+.7|vtu\O۴\6h6!`!ɀff08d+`4XJK.)c&z,F#Bl%7l-!Ay~QNf`QCP"09e[0ݭ{UqXP耆SdҦކDai) %M7BX޳k &1o 8uiڳ)7 cBBI;$ohՐ(qݙL 9ekE܇3Pxn=t,zt644Ӵ/ܰC13rӷmxQ Lڷ;$b2j+QIDZ&8tv U/2iݟpڮc\k B[qS~Ej`} $kVƑ!XҲ?_JfIO>WJwm=w7 1Aw(IQ,Kp*RwY\g}n89%^ϝ#hjχG6Ȗala Gjq~o~j5 |ĵZ\7rFe4k9Bװ#u\N`\Lo(%U@CΗYnZ׀C⺅BQ_ Ռ冋!vS% a׈݈ Ed1:FGgd"5ѮΖe?g2+wvo23Ҹ7kda]/jS3+IcvuCm;|Ի)rҍ!f[J)^Ⱥ/3K 1(f[ew i4MPZKj;el,Wy}Hku_E#bɲwV k 6мEKݍ%zߛZ&q?I c>Ii'*w3xՄd*©:+n2|gq%dMT6UmiFS-Qz)9 ֢8˚ڳ>IuoIFƟð~ Cד0y˹Lp5C˄: ^a_ dɄtaJVA?ԅ상 \r&gԍ1\5fdNkx؛LO {ػD蔱e v zoHxo1,N ѷ?YW% BS"%ۭVmAy嗬)hD,xkp_xZgЄ%#Ϝ_gψm|y< Lf厈 sypA{#f0}iy_'nJO&u+\Z~_=T5Cb5NbQntMvu'D36ws {;a+rS-TE$|^f 2  "dtQmL ZrbiIz}0\jeUTxPx(rdUSxb#pb& BG}'o_IO ~]v Sz> V>,I·-/B;L2A )j eϣ[hhy*.uHbC3ɟzD=Pȼ[5wqlUj &Ͻ&ŏ C1L"*|%RO ޥt/NvGAbrz>pZ?{ 9T3`KBR2/xfVG>﮹efƪGl6GӮ|-k[LG:. y5m*z{z2N.NC ڢΙ؞'ohŰ0 ~:|+g\mzW&|bT&4Lrv߭i/5ȿ&ٴ^hl%4GŪD^.}Ž6$âWRtuC'*_JhJz1LzD-V L݂t7\&n:ܑ1jg&}=nUtwhj~7{ᬜX|SJ>83#[TlJSV&kKLs]*]ևlP9jYxeĞ!봓@( ,Ĕ#D?^gFː; E?.\N]À> qޝ5 (5& bOT3,3kq>}3y)}oٔx 8 )*:ܩF819qS'ܚ]ܻ90pNJʒEF^}@)C0ް$ $ynH# u*7N6b6jTAc5<&αp8DVkӂC'lTVob[YX)[Ы M{ 6);9y>@G,yҡlԈ5FVUDU_9)7A\7E Yi~PtEdn5Z%? Kľ*(70FF =wypvq.kP,Ι^f-}~* M+ʭٻJ,,he8.yX݈q|L' >UA/E+G(,d.c%O0ԥK<`GIv}}2ԬOMuU1c+Jh8f^C͓nsF -Pߵ@YnG Q1},f/m c5w Z3;7 C(:&0tu{A-97@0% nhZgjHNzb3'.JhaRزҚM=Gb+ߩ$& g`QTa| ;EuS /B18~*i35˃SVb@xjZUUɎU#T. 7/wOQւu מ:zNӥ(H:#v'X:=C},*$)S\O@UU7mT~,!DhKؤǣVP6d#8(cdI$/yo >i<#L \\ ۏ @,9'V +U_َ/6\'(Ay 3f֙Dnh_ s2 ,. ^]2>sf=nqy2 Ss I|UͳFw*)x0)LPJĀ`u+lIG I_X- 1fZv7˕9i}6W98wUbF$eKBꘁ"f }4 04CW}H u_.6 )$jxLO۱?Їrr%cQ,̉T .-xauD3 #nʺ$I2Eeu D'7+5O4+hT=␟dBSS$&dt^ᨚD}nTW]^&8a1pES! g)7#N[ Ĵa`>n&Z/p9*+|\u_@^c~ zW_u7p[ǤӞEEOv>> 1k,u؉y _'b[Fw9QJbMO:kKRܳJxJv ǧX9N:$yVPش_TY|!OM/_BJ Ny]Jeݖ4l \Č6ITX|HI[WdaG Tܸ6>oʡSm)vGsQcKo~D*fg2mTZ7m NR2Z?I#Yj e+벲3,a. WIN~/7 ޲1X[s\nʜʶ7EJ)v& x<*"75qÝ,PZ raNSZ/cIt v^1 zr>cE qF=v ^:c: {\OTȎ O~2'svrDRd./.U$4/>7n{,;lS5}ÕEoPĈrGoC:PR tr/'=N2*bo\F\K?r UF?&㘫8p~pSS3B JeXo-0\LHΦZ{٣`*FOɬa5L*07kuT#KiەwL6x-כU,A۫>h+Ey=MQ8j{.R9e+ 3þpNαذf+RVUw2ũQ%m4X0uXE6PHhY9콼լ,P@dsTx?in?/Mm}٢vw':PV^v_*9n8uA'tɧ{}F,Cmwq+nj4Y?8?˓r[#G-K;|+=$c+\cQ9şkkJ8OI3[ݨ$&k] >g,ZDZ] ?rөq!asTpcwF*۰ߏ %h=uV''+~v D̄"5AgDfZB鯙KV?8omKN :5w%qFRKp6ĺ@5$_>~TJa'σq;vGDzv^ Bi$tQ(N. -BbA[?6)ИNypNK:.!l0mqmsQvu^Zw7="( xPT}v} xAY*D#gRp nIZ~͍^ Xqc8sdN1{P{<&z]z$ &B!S=z0pKlܼ&ȣ59IS%̱tD?Ätv=%A9Q|XqR"hʋ<2jxOn˽@uI X/o8ZiAO~KY Aj-saqڕiLѦC=g$}o yƴўcac͉( LN瀪]-x )xl#En3e$fVVrg;5&wGi̘chxopkD\$Oִۿzuh*GTGGOgk-gjD&sU;էxEY$k[KV7jl:*tx87J{+ƅ"b]w%1֏xTp#K뇋Gб0v;l4wZr*)hӾ%LyqC-|ѡ SA4 dGW:44 zhtRENds$21$4 }HFk gPvB=b%]7j>P7u.a&QUқ~&XH2#zذn*wϰ802K!yW֩Apij;A9$ *N'nnJE,=Y|Y@x՚ DSX_fwM:6[ac@lSX32% i% >M4R+t*zR>> @CG*)DNm^D8M [T!_` /**@ZibY NDRqcװF3 a;ei1,G@%˲sti -QOB[O݁s4u1c>x@UOe+r FC{a ΕNuqzÏ?Ət93g+&T2cBqkQ{M80x5{_FyJK x&2SO㧙QogW3M4;frgi37t))sfOhGU7=RznA8j4B\0`= %2FF9*^x0J;|#CNbC8dNBBz$_@<)QMn +< Utf(DkV)UxWS:=}Fn#DKK< \kjF]>_o7\;YjH|4[!4J%@BqwL ҎECVD~. JXJFp'k'p/Č_> fdu\m0YҜ#$Hx,8I-skÊ1O>ut3g&X̑RsoXt[aލ1 3c6&kR#߰k`B6oxIÏ(vtE)bu F㇥zH6yv4Qde 6jDvmm8T$x.]+YI*QLj2m%gHiJ #ALCG|"N \J7nuZkA#Bu@ղ~wvg3N`ln'm3o\̺O:# 6~)\y2@LxQlM}Kb?o\*&&ow#_AȑjɖUˏIYAċKۛ{(CqB' #i]%1o=B(j4{+٬wVǿ9E;J}?u#~@lev8Ens屒}>֨ɪN Brh{ZyhY d qrA sԸ >Lszz@N'Nj\PϒJ2~<)1g~OG{9xE^bhčbW{#QL#>xU5}öL6c 2FVrY2ji;u2,p>lOМ -E /R"H uHwCv&e`exHxA}h 6XQHY!Pߺ3EXP$ز[*VP4ʶ1NhIa~?փ/&h7nJݝȩX@9 ՝?ٌ˔ue <}hN~y2@{%ЧZ //ا6^_KI@z(T[z#1\d;Kը{&<6&5lvcC VlH *J3oa/ 2© ^LN8$VVt@-:do4d5JA2Ԑ(D5S4k:p %,M%zʬ®MWb1K9rp0}^GvNP 5s}mO?[*KA]3"fo(K36XkwԹC RHZ=}YiGS/lPIh|"|sCp6Di+k#swtG/AB7}0 TBl j8>RvrF, ZW~g(I4pv/l],XNB( jysWƊ=[K.cE&#?[*Ÿ%iɏyK8ygWtS 0FTlZԡuBԭ64**A(>^rJYRA0ԛ wV 1QXD4s)O}225яZh VRE';֘O}B ]M5Dy{_hvL. 48mbC4fvBk.\Z!G Re\4E뚚;ҟ 埐Hvz#W><]EO( JsfX8iY <ҲN&\Nc|l;Sxd%] TNҼ'q6֘<3s=G@҄41˄xT-(ŭ @5Ե#XkCe:0O9zB2bzŝϲ\sprJ)筢~br NS ,䵾6~>a¸c""B뉟ƀ~]"h}ՃRQ5bqc?h7ZR|ɔ[h^>&{e1 <{wl BoL~!fc*I5vk MؓRmP٨xr"\ [ ?l T)-ĘhM&yҿ4`nF}AҟB)붍즵=gi:04ZCA*̘x[|G/UՅSrl{ՋZM%4${j~ژ"[Vd|q2W VyjuBkFT|RuZ)S`Rf$q4bj° ,_p(kog.j%ŷBh;u$WXjweuR1!as2}ۈהuGpԚ=)$. @@@\&yڶU-@h0GxqtXF\wx-D K tTT݈n+?nUͮ&m*w Zwfk@?S%]aa~YS$lvh3C J,mn,K۵ક=îӓ?Hw$0ٸ! M`G;sKE1P +o7//@8e)M3P*fJjZkSmoNiS쭐(iwX$V3-+?2GOMr${fv1԰R;lI\k 煞32o>o&#|%=5}9P{}Y $E}}vvS`u EMR[„m3)h|\9jToPmV5$(54x,@镹A0J6+v6stk1Tv~OykWvuDUN ]LI_b=*o'|3QbVm?jQ٨}nI9 AH7$Хv2nJG&7Jg4tzğߖQf]\BQ&ڶPO-HXk?R zyE|vl?@QCvѪU@KNxi0g4g'OH w)10lE]5\I { x^*/,9=]fz% M7,3QU,k?P־S]|ֳ$µ,XE6`vPX64OGlw*")22 6FmQ4j[YG23%6_4 Rs{N iԎ P15Ej 7+!lST[0-?"i:RNF-M3{ C=*~BuۯU+6+*xo1RI|o….Jb{Y~:/1=t#LwX{_]QNC&j0׭>N)EAWr|@ C}Q!ߘGX2X/~]%X۸ֱzL:PNE  00gi3:y&:`ve}Ʉ^h8 ZlL=/itTZ#]eȂ%qtYËJ(wEo(nY>9JT!nfzx=]EݭRa2Ae|!S.ĬB[> H@>⎒pxmc8,u ^{p?JQq9MI$Bt^bk3=PɝsPt ik|(ž e7W1av< O$J)R<Ѝ0m~ +PwqU;[c࿌ /Բ-:fy, 4>;W Ϣx![ki xRwq?]P|-\x$$ I/P|SŔiSt&Ç;s .\2آu#ψ!mp-wdl#Hܤ60c{0 Tpl=\eqco (-) r:`0((k,UeR'qHХPF XmDC17_M(s#XGtX`FlE> ≼t#;GKMa7+3uHuz\'4,ϧwlOFͬ0g>yȦB~Ə oLFk8}bWvo# c3= 3k^3Z# =9Q P70$t,e * DXK٘&&L;3k }c>51 =ai(Na pSfY8I+մt_Ȓ+t*.[,=U$(K&!]]K?v}ĘhR3+{c߇h=]#FɘzD5DIӇ{l9#ۼ"5ڃ nU,*pIsav("hyyQ"VAƣۍ,yJy%S:e- $i?-g1eTf.IJgFaWCT !L3ƗKh(ߍ_]o,v9aLYzxH:FUX@0N1W_ |FZ*0BC9@*QD{6tQQ e%۞Zz$7EgudrY\0 &0A7db$ w[r.xwN,#/H6ڋTs}N"&$0s8O\;Ǩ8` ) k\nȉ<p./b_Oj-).c_uX -:$O]ϩAr5HKB*V)tP(+vPPW9u%-b7Rڸa+LUqYjvuWۖiG1&9ӬQgW$lyG.u :oX߻L&H{FKw 2r JdD;N&^ya'T 5` V Yd&v%w @&gh&ifsFvԙ)[L] `K."Z4¸*ҫ/t}9kg&XS?w9Q3lh5VP҇SmYOzw F_ʪ NA94ҭEh‡:mCquiqyB_(ixz1ÚV- ݆`\s'?/]9f`5Z#`92nԡ.{"#hRa#?tLuJ>[jACzR$3OșhuƯ]MƄ)1;mJ68+'*=$i@#dn& ~!b$znxUd8; 0R>&ׇ諲hm] iG41@HEtAPu i/BG50iRqXL<4Aq}a|{:4L( I2C60"aZ[ròEeބw ;F;UOͪjq;whnm̥bljqqgXC {.f)NJ_psǏ.̷~yD4g 6CUYH]Ia^/ ǚdw=u| t\.uqirITVDRiuM=m&>FU}z%MзkFl:̱̰+2_ a7K$nR̷je WESt1\S)*=Q&6at>gvsGl'V s's3]8Iv-GZ Z8'$*+.;ΛOE}WC1ߨOPkJ -4&’ #F.Qn6ʈ-Yc[Qxd嬑9ggUTfԥ[*5p6BB8^~fsM`q[ÝBcU|`S}&/a_ґtjeZMc2L1q_ɭinSObiI|Ff?GNEn4xF%Vخ+ 8*x4Yeƴa'kxņ̏Dl~ z_S<ٰh2y-t֚S5M^CoMQ`&m4qH&R:r*9#4??"c(Z_j@O14@ SZgk_8׏g=Z7ӣq4$pYB\sh7._>zjtwYF? ]])$ ( + |c+ z Ax 5]t-SsVS\hmW_HؐV'ёNJj@C]ƶ)w-ɓ:]:w|97>KxMvJ]u,'jNM'2KnGy=Uk&X&vUڬbVI)%䕵H%Ͱ#O៑-)vB0`& ]DF, HOѤ ǥ}[L ȥo8o90>:pԐT<*qcbb?MU@b ؟Әu EC0HQ*CN'x?w'rVޠxWپ(8x'g sa2{q5Hbޖ |P{fsJK^U׈p4qi| 3 oD\yS)>#KqXR"`Il(-1Bl8n23`d*Q d= z9G3l;8]<-9_l &Ь;)*X9x1gjp~Y;gEk!׀#&\n_Eͦ kB`C -q">Brtb{yc;$ yuύѭ\e^꧸yd[L_3U^ _q>xyYoнozB>mAOϗgQ wgQxa&mGVf-'5x EγQQftØ3 `hA4E!#SAA!jN1zg),WԿ`(OL5m:w}YP/,X/ym,ӵ0=ߧF8l<i|[@j򋐏!fw(V`lOܥ j =#̕E[DԾv.SP"7›Q`z.4P)mYj @}ʶ7;PtN2kב}Zěw{=՝Zڎ< f@_QVZH&<:+sSʂ, ]ɬ @uRˮCdx/||.Z<,Jdˠ^ob0, 9[D{e7u_YuѠI6EE]RڅMyY69d q-ͮ -UZrfQL'd'rꨨ!_hw V$ffWw~S@U"UKvF3z%isi! poL|բXY mC9蓑F؇Gh/"]H}c6DU.)_3P^L8Jw ndZof!RڗLf r]T0H#5Z@t- eӒ֞F,]!KB^;L=dp݉xNeX【gn^* qs `9|'.xqu1ƈG, hjqyuSVV9Q1cJEfb`[SsBjCyA`3 m$Lr;BCqv~SƔſ:C's][{llbYc473IJ `ɳʨ?'\?ܕ(i<]+r͇ h 0Fx>8D%/ZXqXX8wNy`g8Pz^)ߚ*:Æ+ZjOBAޔd=Aۡ!ǤŪiEJg#z^<RUC3IdݖMOR KaHV+9m\7\[(/,FQe,9(6(oKq~tR\ـugB4?Mƾj`˝\7.ffNIǧ%3튞ei4k9x~#&_C$S:=3wii@7ʮ(a`b`_icƟ:%FTy;" %N[=ޏkm)j-DN {x \CTP]km4Jgy5SY\g7vf`h' mBu G=']66 @h~Rb=uVf90ƙVM~Ȁ Q,s7?6c3w4.n Of􇾁ְ@# j|\7 @bVCӆ/4UMxgh6I䝫n'^+{!~s\fҊ f ̘ebUk$=y\!/ˇ\ΰECm/OV=n oKi;rWT>i"}; A|uhCU}kLgO5=Chl]gB^Im>qZ8]6e4:VS#%ʒQI()dk3?g7sRc:)?2y~"HֽFNUY UVySYhv䜞fEƶZjG.TWy7>zw"wk=F2P}\j2 :l,(RaS%.J9ZbJ (yՓ`voЬ̣^k&]X$""s)nò8!'[+}9i%t3-]s ۯ6 "CʱQڕn8u/aê=N_ŽLZhWvyJUr G93jů|* wxa><04(f^5(0 ~`)Sn.(O@4x(Oȗ FQ$c#.7 FD{Uv/)-cluς0,WBtJjlmu?F/A`Ž7˼퓭tKY}TNYz$~sZT2o#@7UfNﯴ㵻6cv@#P} ȇB[iGSII=.}1enAE,wGWoY(e͔~+E_[nAcoZ#ʪ,^;ae cpו>P aN,pQ>qg!m^, ^RBzGm~,P>(aZy6\iߒZ b/2>JƎQFz eK.z,C Y7%RYV5NQMIovYRƄiPQWhWԍ >寵)qZm Tif@+XQ.͖n7F1b\e5PJ$gXPn(XmиqgvHʹgڷ,SEМU޽So,'wxDЂ]+kje%/9c-l=k)=7lX+ j'+a,w/Q;\8+zLL$‡$.h:"UFZPs`[Dg>G(ky~J g#K*O71ٞ#g[/Aܗm!EizP /޹Ϛ,b22I]=&]3u)v>'E =n\i9|׮Hz׀lMm(Ah)/vof ͊A̷~1FW*9f,i}M <%e2 =s~uE?PAоjwo1wSk؜zTjE|։D OŴ ,if1@zQ pAcDC3:N;jKsZ~tg^;+@RT24"3POθ`2 C_ͦ(c}=gPZa/Y@dl" ^l*ukr|Wz{~w-q:/ܰٸ뼁f!oBvQKӲ r0:kR0'2E}xE`-qǒX;[j|6k"* )DU:=}b$jDjL9,Jqfq}zȌFlUGMޱCY)޾>S|xz te`kd3_p& yi~2EU B&-\!xIJeGiC5䣰[CЛ%ltȈY? yQnC~ gk!W`?{.hGjRZr,AqT ӈw 54)3KپC{.{ e<=;rSW"@4V`)Ca! 5\̠"4*~l+!^ƶL:-qL=̈́`snl[3{6G7Uv<3оHn `+qB'ꐁ u1gHg]^^k" \,#BJOљiծ/s.-X"Y2\z |G3KWRKⳤd򡕢24(SEp Y%%r11|\@o76Ӆ41Kۆe\x:dTu3ؒLKJ6T&MEjVqGW`Kem91:ʤZo))BɅZ=%C,'[|&qQ8d8!HFyhҚ\H!umtRȸ]u {+? k =&xń;}8ٿ=Mewٯp@TkRm} ɄۈϻM["z;-nU8NJ*3< ss {g7j'T!u1y||f0%4'3dr-H;T戶V x59d]%@1;%AݯٴxD+r'&VXWCKV#aa`Pm)~!rE[kF*ҥFL+w2ȹ|}|1 Վ4K0PFL+3OmҲ* 3}S0{\NCb ,; ~JY<ȑ!kT/fY|d|­7lO wj0WP.ҏйez[_YLx<=pv\*w@VixߊJh#$2Tcz j&`h9Vah1͹A!)`U9&;`a~'hS ݖN@':N5Dj_耧mPr@ (5"f`S*|2}n G<]<I՜oDQL {xC{^z\9†3x3-VZɫh  U]h"kvbu "m:ϭ3UAmEH `r?ŧR-7iN\WUtSeyn)佡G#L!g y@Aʰ>In"HĊJFd|L Ȃaa#$ K;M!3~Ti!NϡQTb+l7`@? O"ja!1W3Ҧ blö9G"˞"K$š DL2@Q6A<ҩ[Жqۊo_l5cwCy6]:/@v$8&V S޸A&ȁu%Xذ tJOeyH{(XaUu~ʎR)lu=7ha|H?Sf#ܼƵ/~Y*&Q<^e5?\HhkHk]˔G9"xѻR ^h1^72!R Ւ*ts K\DӒCa;K`E5>_jFgA!L-%ױ%<Wa(eQ}ׄ~ Bԏ`BHI\Und HK)9h+&)6q|҈QC?/ D+:ڥ13k+}9b/UUqd Tt|%~`6˨HEMi,`8<HD5xXXDn*qRǨoc&}g>,!wεQ ߝ-'ƨ}΀&`y6X*y\KrϿܣo]o|O%_ N#g--ׄ4iQ% VmG-Fٕ,7Ěa.2z])Reϟ_">ȫրcq-([|~`VIFVbg!2liFpW",DKU~vrדA6mA}y_~Vx:wqq`čr^̟D`k.cc fmTxRT[MC7m$Chnd}Gxe52ZXxW㝳"f Nw {rQG~=2 ©PO˪;)p0y|*:2_ 2V8va ^Hn4 O|ͷJ`xڜOH@59 Wtp#HfbϊIB^fhf<9 zNivI9М3?lW"D`HkN[rѲGK0p{z5vCA(d\ng)OC|FHs١tWsVkh,].}71QMSI [ґq\im b[X_:ch|6"ВЯ#j ¡OmyRj]TPzRU S@%s8 >,M,[͚͍9!:|;^(fݨ4rC!#` x>!o٢z. t1\9`$hJx¥ZaQ6~-\O8Q y ܼ6.ِ'.&A #Ǒ- 8rb˪tH>MHɎUJ[CU6yIz+Ș=zM$cjm/+x3=QciWr䩇\)|RL+V#Rl裫{D d)y!w|9L${K3I¢b^gCs<1g_Mt0>Rɜa;6oVkK0Xt#gijy zOU(7n;c]B~t{`VѺR ͝`祕VB.F捓8)g/r N _ChpL~>&?@Q ҉^ 0r;w *]BL=n|CJ]`@fO*~8ںͲ].]A(OMy4 6u@L;SGGMf!|Fܼ2 ʚ~g5s<Ȇ~ 8mb R:3%}0:AR'=É>/;*Fz})nGvL.jƾ[A^#cKsXC1/ ="P`V}(l! gMw O-øpollyg' .1 G .,`-7i@P|ҥT?,~9lvH@oe7tgY?81Hk)4P$pn#g @iZ<،sT~ÅicT%x̮O{Ih+0'=InFr^BPVPPA:c* nðQ͛iW5jpFͲ@H]`ĕCY$zE~K+Z2/*8(uͿ ==O7(42LzFM=!<'+>bWk N^Ί03A;4>,: ?bAa.r + G =sW<hpGmNb&Mrdۧ.zV8VD4ULfCÐ/]Zkg]^E@D'OMǩ{f=TܶōMB;LKE];+5igE.ٽJ1w͏dr D_fh6.7M ;+eﳒ23c$Ws#?'yMiCe)CYng;kUЦGdž" |]j9]'Z}Lt|58p{m=vpuO`Tl3vL8G<.8muŁRX@lJf&N^Eۼr/7S5i)?fT}mz<">GN(r}B|Mbr-] lJ7|7&WZ% e9(P8O>q఼ "ԭd,VvT"*LՌ&'~6,ì F{c֐2i_ZR ,µ v^-~^C!ۅyǿøWŁmDsX7U *~NrP&yoIЊvV3xڨPp h"%` ZDH4ߥR^xjs5V l֡jby>5f^ W DĦp @Faa@ap)(;Zwth\Yk=RA9$ IT$n03GZu%KX^?iڗrl_X[梽5tBˆ0G+ƢMVl9z2}u{ ȲSg )JTQցIprf4bal vXaNOާctԠ'I[ [FaERg+ed6Sg}ӯ.' -wZFˈ{H&#N$UC.eQP}fb7YZ2=3 ۣFQCiTԡik-,YkU5ÿV޺2ˌ LPp=PebcKkO0 nIL?ƹDt=~)ߙb WB~^d`'[,xg3,c`6*R_OOVgL-ݳ.mӶ`k"h !qMf8؎ |VEYf%1`=uH%ޱ~wbؕ(vٖpwpAv]ë~8dҘV4y֕nOr跨|s()w%6u!bRPЃ'"34RGYt\^lr,I𭼇 oZB5UmWD;ܮ6; s)!0z_I!O,&g/d\6c2fgTi)^TA.LvɗY > xDz[B_9 *!`:->މ~GP/|2yfe9$X{ 0 NEӕ*+NL=T!85!W  9UDh@oB%Ж]̞g^x=4YYLM6E6RWIԷ3]qz-l&6 BޟqOg6X'أyZ!%+m@3Ra`|0#y';ل+j+ŽQ7wl(Dt?b`~ ׸lXWIër_P3v78T ؊Մ*% Ŕ![R[>-{֒13jݶB]S?ca*/5K/[@w0cRY^b΂%o7HpC{\CEW8tgpN)2ؿJ%OC耒C?~Rf O 48hJlq(_ Ae«ő rS)Uξ4W$Ycœj`,VQ:R@$礥V-' I\M3v;cSV%VlL؅'QvݠAvano͹:5Y}B[@hoTEćRH"`Z>.:@[I͓21>BwVS}acHi}Ipn(~/6u[] 4J~( 6U_x=P_2$Mk0sx&;8<H$B2{e.U`Lc@A0\KtQ`ŹU9X^SMA1pQ_զW _֎<4׹ M|֚yuE~}nQD'PdAWʮUJ[L vg] >Z1nhpch*03,0vo#d3Pғ]nnz;mRWcD! l' u_!ƺeRZEtGElK`7 w)Ee$"C i8x_O/kwb!`Q&bS)&r7^^&D҂bALBfo#PJ $mu.,\o}OptMז% ypvfGKNO׶ҌYŖ8k`&8o;m2ƌ59M3m]8GHdC%pC)|()* ?+c2/Sf7ni3_efOo{,ZtQcF}n?5}ā'2N Mѳ΢=x&2}Z8:*=ʈ$Xf '/2^Kt'x5ؕst]J#;<ZCR<蓒)nFi<ӶebaHJ_?[J@!=` p~Rɯ۷yK Q(q1꫱-n:1y S}K2 }VZO,ـ"bJRvC)@6[gn; $Sӯ ʱ&LaQ;r,;)X,LWIs;_6^פyiww^,v|qyXiOz$h՗D8k2S_FO سRCsG4?&I&qgYt9ySu >'_$ԅJ놄R5Đ{l6"s X& ᮫>jV# EvO?dAO-Ͳ otNa5$A ˺rh,9 BXJiJScQ}zjݜbmS#yU^y.[YE D[(U?ķ?Yy7M=n -x‘Њj#1S(&tP{Ӌt4ַ\ `j~q6ǩ}1{yC(#^ۗ\mww)'> ` - r 7_܊P[H&\fME# cغpM.5ׅe9@c00)^'s9ȁ: 9B˞lM; #{q @G"H,4Q9L^fǺ_&'h}J6NΒV4K׈ w ( Sz'+F=82A']ah SB9\aAIgZ .~SΜ.]éH{+W@S a%脹bsV Wxml܅Bq<}Zo eB!al<-uj_藢FEVԅrI%АM(EA hyrdK9 -*Rehԁ{lD CFaxR3^@eb1=`lAW蕧c Sңc׊4i$-2lGW+21uˣH20>˷gAlUc t,H:ZqԝLkR5-'j7V NKJ:G%i./>M@xg0#l}WpA((xtΡ,>wj:n15?9{ھSs3ʉ-fybp YLod|7<>epޭ N N9$'3-Tyb}-4[ŦFRLwV<3 @E{]zJ{dZ*K,nx@~Wtag íIHO=lj>quv nG[Њ rY<+_*_g]Jlֲ#;8q!ldX6n7Z4yh%g^~1ɪo7-XeTv]N M 毐" &X.B"*.NjS ySll!Hz1Fٚ}Zծj;ư~#q'*6s4rJwq᪁: ^Bb|8x#aTZ'ΙU ~$5uԊS OlaU֤>aM&}͈qab|?5%rd0 sOZdw߸~έBaxL#K٫ԏrƈ86 Ȩ<e7=ܟM̥-ڰP匽.Q MN[ 5-R&W3;O4PULi*i),+-H"b|<WC5d/Pm8rֶ.D1F&q~X}LN d|Xbǜ[L^4D|EzVQUZA(abЇ8\`kvk0O8F%e!+(\PjqT{[,v ~Wޝ;<4(NB QG؈ɎXgۜeG8l }6 񦁘#vGGOw)f/ Fs"Ӱc9YaVӃЎ^V`{/ꄉ,b;gf D38v.Z v+QI&2RCWmL< +3e3Q"E"9GxOuC#YW1| x{ : D[kJ)&5HC؇~޸HdY0~’ijfd-Z 9f!B6i q-! _~I|E.Ŧ3s(t +t ijs9nf/̋Ā"J}a|Hy Gq<8Yq")m WC0>ej|@ Dx}${rfRE rxY170b8 DΡ(iD+)zVY٭z0;RY@~W$]d࡙fwn65ՙƫSS@/e`P;//ю7`&ksַk^DMiH$`YZu '+C WL(a.(DY[[ ` & q Af(+93jVW {%Qjz9f)Q>q;wTp_2o&ik9 -P=u.V^H mcOؑx3іEzńWxlpśxI ױg 7Gt/= yM f}oe-u}X̅n y* D:_m{4̸[Fy4eW̉r%m.U_]@Xڃvdj.5l4n2x07ךy֩(;#SN;0\j$['y¹v;|,ymz8'NP{pb;&+U0&40*rZh#D <G=:]/);@sp=CȆɸ1&tO4p=u'h {WRiZK  y)_%f@%zYj+2%(*:}@ih/ ._u "n9saɊ"a<}%(n.3KvA.RπlW@NYi&U22bwJ;3zJ7iv\; Gk'ӁprM4m7 gE;E:@*KpYJmȀ'S }[NDږ 3 =7d:Nl5sM>%)r.vP`/X&)Tޚ`۪@DRաT48cys~6 oqhy{F~*T n)S1\#Sw Ϗ 5m#6>bmL 7̈ l-W0vCK PZVs5cU_r gc&{0V'2*r{{Ҽ5~q?+-3·ǧEc]=NEv# B¤&3[ +Pc ʻ@1%5h8B$뺠]BvjN;UλdR/Gf)B.EsDwO1{n]^oP0r,IJGu`\2Cx*ZC!/<`ꀨ33 Nɦ8AՏEm?^h0_pޝbC װ1,`|"CQ!&b )S,}ϹUtI|7eTmMXOBRˤ+ʈ*\x1q)'D n)6c0:FoH2ճo VCLUo"yoyXDE_()޴`4jq ig^'s'8~?9-+saZ쾅a70#:落jP/э-]")~i&zZ#q*O)œp"b2ᓵ|B@N* %Gm )I.-4yk6q䛓:pfk- 9ËfТ?oҺKFNu~(v.n"j̥sWs>ejj'TR(Nbe0R}#g_A :r Pl^%J ST#yDc:N7BŃhZm7ld}w=~&&FO:S瀓Si0 VG GR}P"[ 򩉙5u @]BD]s_B28H2*Ms6|_$P?&"M>ύy^;?TNF>ԝIB:P-5f`i#%( bp|ѨIjrFK"SF7MUوF >"+TLB˓D!8i梅2fd)nU\تٔ1^Ozpm4 ]ɖ߬ljί搽 e7.*V-8qm&K܅tO͹"fu :F9M,6ڠ yE\f fG:uΟ;Ȍ)VTn24xʑ1<XGT"ԋlLI Ar c^&~_KV}$nS>ḧ\*+.,|$N';6}?wCֽ!c(:$abO̢Thb)RٯgSx7du]*hAL 2">۲xEUEaR"g5ɇfنLHeb$ADzߥfss@ϬIGyB^1Ղux$be{JruԄUѧ9fD~2Xݯ91hWL,?wCkGA>˶pR}@#߇Wd$ |F|2i"R+_u^RV(TV-@=kv ~Q>o !ۄ(]j"c.5,fN^Tb G_W,;9EVh?+luֆI۾'=vZq\0[ C xߟP7;޲+¦Ѭ C Ȱ. cلk&pCSY[lṈ& &y_ a䝘JENilr4U~V>s86DjNq=^:e،Sc:ܣ9~jl;-% i'r%B80*Qo^tYb!GG= ǞGfC dg[ -T˽03]PNǒØ=F*MkOj;GWnje|@/[Kx{ gqnjƞSaU) ՏRTsj>tKBjᎢ(qKsSe |8'dI茥H[M",,w8L\8}( ?AF(ĘMG7srt'x#سՋ}ve"/mnr$4V}Bq= =D.4Y񔯋d]fds rg%Q摶7zErNCF/9J JzӎdDmgOQ! LfR*" D.$--W,TaK(LB%<ِRӦ2{EIMb9U.ImAx#p*Nة^]S*7Q= }+q98't=3=q\nx$xN#v|* 185C/nNINӹ `^z0gKǕLP(Z`ra1t])`*zLTύK] R2H#$@@&'ǐ UR]K4{pv/3'D3p=p&h4Uo[|=ʅԓZ I NH L3ZHW9kT\YAoVa -#jMOkҢz wɜ6,[V Vc!Dqp6/l4I ffTIhgʼnSw(CԼ'˓Sd9f_ŧ\s$_lO&"F+”Y'vS/ZMՂ5ϢOX e{E&PY4ή!fi-K8a{Ýb2w $кNF ؗD9hhD-ѐDaLkОm|sG le(Ԧ4>LJWO[Q祛mf]4ÀiMm|bN5~ѣʴ'3(Q[eS<.i@o2pxf#`*3YMV34sW"j<tFml4JQ*hbϘqL쎑HNU'&!$эf䧠=\n#b(asQA ywT.t#{Y{aLs1NY4BREV[{r/Y#Iq+[>N, ]5^{teӰ<~$, [/@v==yV4Ϳɭjy|m!*TN; eJ3Hz<\nLmahQwhд/aUtq`/dT4r0pko *VLg‚wscP[緖qfP p"ؔ]H%\7=fٳG8An;ܖR`ZΨyb _}ak+im+VHduGy|{} 4xVNP/0VF4xEFz,KBBr ~q"ktx羈uP( _Qi̦"P/bO5 AZ}"2it1Rs-*-G mbOdR#Ul]8MFNuic&O])ҬXB:8 )f17K ՝,g $gsH1M ul\N*X! ;Q3, &sfS!`* hukE.p4bw|g# Acr`mݭ C`#A'l1Gx 9AN GP@&{[>*NQ:Z99FRrIAM%p4N sRDnFxO2$(xʍpPI" H/1+o.A&9Û&0DcySdB<mfT&XH^Bƍ/o*JpH[VSA8&Uў#OJ|u} hviIo=T i/./In XA+%)3WXu Vu..krT ,U<ˋb7cz 4˺,θyV>X5. n!2]%kӵ# GY'+0b!^0CƢXOU =:ŏeBSі+2q&uOpc15Oαf ,%9E] cn"nkapHp5/`\ʺU)X[a8I])LPs1EUN:L%7|K#ΏU>qL<C?酨3N͌q;N&wyщl.s8F'j[LcylޞZJr~C yT'Aw%`wN.~=pp ,1eF/U*p*^*kI]X n|uiNG!rI>}vo=-J'+6RʜtFmI4*M;7 ٭?Dl>$16+Q5U\7G] ajjR75lK5ғdh#oVf^X~3xn< ' YyScp'Y.kz0|SfnkE9\Lv`C> t>J(uZBzZiR v)ٛf֒ƽV֞D(ԒŃ/-8+?JgV!OK&0jY©)(6W~.mӏ뿴1/ѧzbpc;lN< ͘=)qr^ ҅'(*/> #͠3A|[tksR'uA-~Y?699m#Ȗfa0sYg-[-^c˯_wrsٻwb >Zk5A wM=]XFQjzo2)N5 ̗AHP|㺝ł/ 2  Y p#-Ф#L7Y8 pCW~f&/K>oCUxӋIeg)[#:OY5]8Hí|;S 1~'ڇ["h3`fٚak}{H֍k1O-y໙/\ H*Q:MT{=E–B*% Gՙ)+BvސC 8K~;aUl 4C QVњ $σ7F-o0Ko~޹˼k v5}\d>[˱Yy@v8|6ں)v3Tv}VkxCEY-ξQoTw$.Ccut+y"J2e0zrs~BIa7Cl@&ֳ\E4bveRL gݱ$s!Hݟ(nM_(J$zWxq.?1E Jz+8y0xGscq9{ RkjUYqؿi S]:H>kr MOzt n;6a2Yhn6u LqsNA)@ 6j/-y-J/B>~l |Y&j7tY2Qn!i55hF. ԦNd5 Dݺdic3٨ȓn3j8k o3c]PBi?*DXPZL$Ck^HʞhbP LD;I"D T`P3.I%&V/T A ˧>Kcm0~$D>N&=@j@3@`g.55J7{)Divd8'-ƶJY8-DzT\h㻀3Wt2_Ers5u>S &OtD PCB:3WVk @J{پR){2JU.0`t "lNWpF5j\0U@kXA|Ff{žя_Pn>>=igKvM+-ȍ4eAs/ݝ٘yd2@%)AR20#fw< "ּZ(5i13r!V\P/߄9V݁6iNd/Y568BO~Hi潼+ ̚Jc&fߧ=,y2*4gۘBц:]pLS[Uiw|i Q?RZˢLa74w@ ż$Fpt(4CVրvVM9wB-2観+e.2 -[ –pimULX~¾ȭT;B٪(Ti^ڇI옶( ӻ|k6;KNՎX: 񸍞 +xdؑ/;bS9BC9l@6xBX H7 MEY=K,RxH .f"S€a>[ƥ~0%F&<ջW`ܧ4 v/+6hsBnѭ bO@AveDm(f̃ Y:Xz%mN1uX{W{|!S]lGo5C;+*H`KnqFNĩJd \OOLHڣ6y8l@H4"+$\)紅ߔR {s{t*aPyq"뗽 oY5$쟅V)m + :X$^w5(Z(W"ҶIiE,,<"8.tΥya@g6#'O<t,MA+4-~>r/][N(|Aq;ORD7Y(0|7<\=qph jKѱᏒcm.}9 Z{;qi%G 1Yv02زL1އ?NaPJt=~y;늢ul/_Oű_T)z&@6o=Yp-\x~KV|zU '3p dJ͆܋ʍg>!(Sb+ux7;Gdc2rkX:{ݹcϵMXjq*.TJhZ;ޚpЁ@z̧vw^~hF)-M$SC4 T W;94mh`I{1Q~hFC,;#3xj$,4[B'-]"GQP=zuo"ULgܪ̟">pqħ/`]iv2Oydpr HܗSӧ,MK޼",(ʈ~O˄0K% y )AVE! ޮDwR5Nw [ɓ\­a80_?#$5N j2wCڕ?/PF]x胖-b_}GEA/Cs` ƨA DqS/ҌŚ_GH(έɻ> eA|%˜1#fO=+CT-@[ZpYc_gٟAr\]'-:̷,+KI5T ~3Os:h1,$٘L5~;ZV_Ov6X8>K%hY/dӬN6}/.y$; E!"5N3jI)s*͇]4RSacLt z!M %k(49" rN_ IyV]"+PFqU<Ы)p:QnW"S;z_vC?)_WRV3v̐:Hɸy썲!LAϛ@ uurǥk=NaO5Q'[8W-߼T/ sk2AeMDz;z-vݱtx qF; `XGYՅL܋>helgQ):ipc@O܄mԛӢI?@kW)/Nj-|g#*Av-[pޗBz2@<*_"K~b: |vP[UHmPp8O~OJ |0+>_{)Xr 37f^Tﮒ/[TM?QkW>Gd "=L8j{c2ZWfrI@ B?~ݿxE犟 *EA1!GdT+Ag;0ƕœ 9cxL.e?jq`"ܵ+k-0RNY!9k_l"%cWiF@:̀.^$VYo% RH)&K.Bq qy!e7ENd5z&.i'ԇܴJ${ُ55B:N.ZXo/IT< ]Ʃd+.Nw-5~b~ZyΌu;%ޑcG^]IE eck8+Z,fjTg0>p |U?IJ`,dPE&^J@=mB |bepxP;%|9T~]KtEI9ձUzWs? DxاRE%H-Lǫ Az[nʺ=RCHT"pElp{X}Z QLK"W qΐLGf(L1^4G)Ctj })&DvUiA< 2!+mʱЕ;T@n#BλGwT>Kjg Mݏǎ^GL:G|$.ñH6([Y{I"hQ~j, $M i3 9LU8X>YVΜE&"EfB=ҿFƧu<+QR)݋9ۈNw-p?%ʝ'