openldap2-devel-static-2.4.46-lp151.10.24.1<>,`D/=„ $gb=4{UBFdvoT|3a^:BTqQ $OCo,x8$Ibڵ-|MnAU-݁ty[;qOl›#g|XlQ۠f61.Gkʸ8%VR>(!Ó]D1M8X-V&R{>Bx>侅^5bcuZϝp35"HC/hsk gUOxo BV,5vu>;F?F d  . Z '?EP\ b h t 7 <HWf(8494:4FCGCHCICXCYC\C]D^D bD,cDdEneEsfEvlExuEvEzEEEEFCopenldap2-devel-static2.4.46lp151.10.24.1Static libraries for the OpenLDAP librariesThis package provides the static versions of the OpenLDAP libraries for development.`Dobs-power8-05Kc`openSUSE Leap 15.1openSUSEOLDAP-2.8http://bugs.opensuse.orgDevelopment/Libraries/C and C++http://www.openldap.orglinuxppc64le{n!%`r`DK`DM`DN9cb469981b92b13b4953fb6b5b392205cbce214cc593ef5257619cd951d135271f57b7259034111023acce834005558bee520c65852f22ea76d0e411328f8ccdb8637ae6a30229881e3eac5bec9c8cf1773be6acfdeb8deac87662da23f3d475rootrootrootrootrootrootopenldap2-2.4.46-lp151.10.24.1.src.rpmopenldap2-devel-staticopenldap2-devel-static(ppc-64)    cyrus-sasl-devellibopenssl-developenldap2-develrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)2.4.463.0.4-14.6.0-14.0-15.2-14.14.1_@_@_/@_FN_?@^^^*@]B@\ڭ\r@[H[@[vZ@Za@Z@ZZ.s@Z@Y*@Y*@Y@Y@YYp@Yf@Y7Y6@X@X7@X$a@XWk@WbW;VVɦVŲ@VŲ@V@V@V@V@Vf@V^@V\:@V@V @U4@T@TuWilliam Brown William Brown William Brown William Brown William Brown William Brown William Brown William Brown William Brown William Brown Peter Varkoly varkoly@suse.comckowalczyk@suse.comckowalczyk@suse.comzsolt.kalmar@suse.comzsolt.kalmar@suse.commichael@stroeder.comfvogt@suse.commichael@stroeder.comrbrown@suse.comjengelh@inai.demrueckert@suse.demichael@stroeder.commichael@stroeder.commichael@stroeder.commichael@stroeder.commichael@stroeder.comhguo@suse.comhguo@suse.comjengelh@inai.dekukuk@suse.comhguo@suse.comhguo@suse.comjengelh@inai.dehguo@suse.comhguo@suse.comhguo@suse.comjengelh@inai.dehguo@suse.comlmuelle@suse.comhguo@suse.commpluskal@suse.commichael@stroeder.comhguo@suse.commichael@stroeder.comhguo@suse.comhguo@suse.comhguo@suse.comhguo@suse.comhguo@suse.comrguenther@suse.comjengelh@inai.de- bsc#1178909 CVE-2020-25709 CVE-2020-25710 - Resolves two issues where openldap would crash due to malformed inputs. * patch: 0209-ITS-9383-remove-assert-in-certificateListValidate.patch * patch: 0210-ITS-9384-remove-assert-in-obsolete-csnNormalize23.patch- bsc#1179503 - fix proxy retry binds to a remote server * patch: 0208-ITS-9400-back-ldap-fix-retry-binds.patch- bsc#1178387 (CVE-2020-25692) - unauthenticated remote denial of service due to incorrect validation of modrdn equality rules. * patch: 0207-ITS-9370-check-for-equality-rule-on-old_rdn.patch- bsc#1175568 CVE-2020-8027 openldap_update_modules_path.sh has a number of issues in it's design that lead to security issues. This file has been removed, from the package, and the %post execution of the install. The function is replaced by /usr/sbin/slapd-ldif-update-crc and /usr/lib/openldap/fixup-modulepath, through the addition of the source files: * fixup-modulepath.sh * slapd-ldif-update-crc.sh * update-crc.sh- bsc#1174154 - CVE-2020-15719 - This resolves an issue with x509 SAN's falling back to CN validation in violation of rfc6125. * 0206-openldap-tlso-use-openssl-api-to-verify-host.patch- bsc#1172704 - Change DB_CONFIG to root:ldap permissions. - bsc#1172698 (CVE-2020-8023) - local priv esc via start script chown -R on olcdbdirectory path. Remove chown -R on start to resolve.- bsc#1170771 (CVE-2020-12243) - recursive filters may crash server * patch: 0205-bsc-1170771-limit-depth-of-nested-filters.patch- bsc#1158921 libldap-data should be requires, not recommends to help prevent user confusion around configuration ownership.- bsc#1143194 (CVE-2019-13565) - ssf memory reuse leads to incorrect authorisation of another connection, granting excess connection rights (ssf). * patch: 0201-ITS-9052-zero-out-sasl_ssf-in-connection_init.patch - bsc#1143273 (CVE-2019-13057) - rootDN of a backend may proxyauth incorrectly to another backend, violating multi-tenant isolation. * patch: 0202-ITS-9038-restrict-rootDN-proxyauthz-to-its-own-DBs.patch * patch: 0203-ITS-9038-Update-test028-to-test-this-is-enforced.patch * patch: 0204-ITS-9038-Another-test028-typo.patch- bsc#1111388 - incorrect post script call causes tmpfiles create not to be run.- bsc#1114845 - broken shebang line in openldap_update_modules_path.sh - fix the script- Emergency fix: move tmpfiles_create post from the library package to the main package's post script, which ships the tmpfiles.d configuration. Fixes the post script of the library (-p /sbin/ldconfig does not allow more statements in the script). - bsc#1111388 openldap and /var/lib/ldap/DB_CONFIG* (transactional-update) * source: openldap2.conf - Added a patch to let slapd return the uniqueness check filter used before constraint violation to the client. Fixed broken memory handling in affecting error response of slapo-unique ITS#8866 slapo-unique to return filter used in diagnostic message * patch: 0001-ITS-8866-slapo-unique-to-return-filter-used-in-diagn.patch - Don't require systemd explicit, spec file can handle both cases correct and in containers we don't have systemd.- Fix CVE-2017-17740: when both the nops module and the memberof overlay are enabled, attempts to free a buffer that was allocated on the stack * patch: 0017-Fix-segfault-in-nops.patch (bsc#1073313)- Fix slapd segfaults in mdb_env_reader_dest with patch 0016-Clear-shared-key-only-in-close-function.patch (bsc#1089640)- bsc#1085064 Packaging issues have been discovered around the openldap_update_modules_path.sh which has been corrected: - the spec file was wrongly configured, therefore the script has never been called - the script should create the symlinks first, as slapcat is useless on a system which is already affected.- bsc#1085064 Add script "openldap_update_modules_path.sh" which which removes the configuration item olcModulePath in cn=config which is after upgrade from SLE12 to SLE15 holds inappropriate information. If the cn=config is being used on a system, the conflicting items in slapd.conf are ignored, despite of it, the backend DB configuration section has been also commented out in the default slapd.conf. In case of correct cn=config (the olcModulePath has been already removed), the script stops without touching anything.- Upgrade to upstream 2.4.46 release - removed obsolete back-port patches: * 0013-ITS-8692-let-back-sock-generate-increment-line.patch * 0016-ITS-8782-fix-cancel-memleak.patch OpenLDAP 2.4.46 Release (2018/03/22) Fixed libldap connection delete callbacks when TLS fails to start (ITS#8717) Fixed libldap to not reuse tls_session if TLS hostname check fails (ITS#7373) Fixed libldap cross-compiling with OpenSSL 1.1 (ITS#8687) Fixed libldap OpenSSL 1.1.1 compatibility with BIO_method (ITS#8791) Fixed libldap MozNSS CA certificate hash matching (ITS#7374) Fixed libldap MozNSS with PEM certs when also using an NSS cert db (ITS#7389) Fixed libldap MozNSS initialization (ITS#8484) Fixed libldap GnuTLS with GNUTLS_E_AGAIN (ITS#8650) Fixed libldap memory leak with cancel operations (ITS#8782) Fixed slapd Eventlog registry key creation on 64-bit Windows (ITS#8705) Fixed slapd to maintain SSF across SASL binds (ITS#8796) Fixed slapd syncrepl deadlock when updating cookie (ITS#8752) Fixed slapd syncrepl callback to always be last in the stack (ITS#8752) Fixed slapd telephoneNumberNormalize when the value is spaces and hyphens (ITS#8778) Fixed slapd CSN queue processing (ITS#8801) Fixed slapd-ldap TLS connection timeout with high latency connections (ITS#8720) Fixed slapd-ldap to ignore unknown schema when omit-unknown-schema is set (ITS#7520) Fixed slapd-mdb with an optimization for long lived read transactions (ITS#8226) Fixed slapd-meta assert when olcDbRewrite is modified (ITS#8404) Fixed slapd-sock with LDAP_MOD_INCREMENT operations (ITS#8692) Fixed slapo-accesslog cleanup to only occur on failed operations (ITS#8752) Fixed slapo-dds entryTTL to actually decrease as per RFC 2589 (ITS#7100) Fixed slapo-syncprov memory leak with delete operations (ITS#8690) Fixed slapo-syncprov to not clear pending operation when checkpointing (ITS#8444) Fixed slapo-syncprov to correctly record contextCSN values in the accesslog (ITS#8100) Fixed slapo-syncprov not to log checkpoints to accesslog db (ITS#8607) Fixed slapo-syncprov to process changes from this SID on REFRESH (ITS#8800) Fixed slapo-syncprov session log parsing to not block other operations (ITS#8486) Build Environment Fixed Windows build with newer MINGW version (ITS#8697) Fixed compiler warnings and removed unused variables (ITS#8578) Contrib Fixed ldapc++ Control structure (ITS#8583) Documentation Delete stub manpage for back-ldbm (ITS#8713) Fixed ldap_bind(3) to mention the LDAP_SASL_SIMPLE mechanism (ITS#8121) Fixed ldap.conf(5) to note SASL_MECH/SASL_REALM are no longer user-only (ITS#8818) Fixed slapd-config(5) typo for olcTLSCipherSuite (ITS#8715) Fixed slapo-syncprov(5) indexing requirements (ITS#5048)- Use %license (boo#1082318)- added 0016-ITS-8782-fix-cancel-memleak.patch- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- Add openldap-r-only.dif so that openldap2's own tools also link against libldap_r rather than libldap. - Make libldap equivalent to libldap_r (like Debian) to avoid crashes in threaded programs which unknowingly get both libraries inserted into their process image. [rh#1370065, boo#996551]- use existing groups instead of inventing new ones- added 0012-ITS8051-sockdnpat.patch- updated 0014-ITS-8714-Send-out-EXTENDED-operation-message-from-back-sock.patch- Added OpenLDAP new feature implementing OpenLDAP ITS#8714 0014-ITS-8714-Send-out-EXTENDED-operation-message-from-back-sock.patch- added overlay trace to package openldap2-contrib- Upgrade to upstream 2.4.45 release - removed obsolete 0010-Enforce-minimum-DH-size-of-1024.patch and 0012-use-system-wide-cert-dir-by-default.patch - added 0013-ITS-8692-let-back-sock-generate-increment-line.patch for supporting modify increment operations with back-sock - added overlay addpartial to package openldap2-contrib- Remove legacy daemon control that was used to migrate from SLE 11 to 12. (bsc#1038405)- There is no change made about the package itself, this is only copying over some changelog texts from SLE package: - bug#976172 owned by hguo@suse.com: openldap2 - missing /usr/share/doc/packages/openldap2/guide/admin/guide.html - bug#916914 owned by varkoly@suse.com: VUL-0: CVE-2015-1546: openldap2: slapd crash in valueReturnFilter cleanup - [fate#319300](https://fate.suse.com/319300) - [CVE-2015-1545](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1545) - bug#905959 owned by hguo@suse.com: L3-Question: Are multiple "Connection 0" in a Multi Master setup normal ? - [CVE-2015-1546](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1546) - bug#916897 owned by varkoly@suse.com: VUL-0: CVE-2015-1545: openldap2: slapd crashes on search with deref control and empty attr list- Drop binutils requirement; the code using /usr/bin/strings has been dropped in openSUSE:Factory/openldap2 revision 112.- Remove superfluous insserv PreReq.- Introduce patch 0012-use-system-wide-cert-dir-by-default.patch to let OpenLDAP read system wide certificate directory by default and avoid hiding the error if user specified CA location cannot be read (bsc#1009470).- Add more details in the comments of slapd.conf concerning file permission and StartTLS capability.- Test for user/group existence before trying to add them. Summary spello update.- Move schema files into tarball addonschema.tar.gz: ldapns.ldif ldapns.schema rfc2307bis.ldif rfc2307bis.schema yast.ldif yast.schema - Package previously missing schema files in LDIF format: amavisd-new.ldif dhcp.ldif dlz.ldif dnszone.ldif samba3.ldif sudo.ldif suse-mailserver.ldif (bsc#984691) - Fix a minor issue in schema2ldif script that led to missing attribute in the generated LDIF.- Enable build flag LDAP_USE_NON_BLOCKING_TLS to fix bsc#978408.- Move ldap.conf into libldap-data package, per convention.- Move ldap.conf out of shlib package again, they are not allowed there for obvious reasons (conflict with future package).- Build password strength enforcer as an implementation of ppolicy password checker, introducing: ppolicy-check-password-1.2.tar.gz ppolicy-check-password.Makefile ppolicy-check-password.conf ppolicy-check-password.5 0200-Fix-incorrect-calculation-of-consecutive-number-of-c.patch (Implements fate#319461)- Remove redundant -n openldap2- package name prefix.- Remove openldap2-client.spec and openldap2-client.changes openldap2.spec now builds client utilities and libraries. Thus pre_checkin.sh is removed. - Move ldap.conf and its manual page from openldap2-client package to libldap-2_4-2 package, which is more appropriate. - Use RPM_OPT_FLAGS in build flags. - Macros dealing with old/unsupported distributions are removed. - Remove 0002-slapd.conf.dif and install improved slapd.conf from new source file slapd.conf. - Install slapd.conf.olctemplate to assist in preparing slapd.d for OLC. - Be explicit in sysconfig that by default openldap will use static file configuration. - Add the following schemas in LDIF format: * rfc2307bis.ldif * ldapns.ldif * yast.ldif - Other minor clean-ups in the spec file.- Use optflags when building- Upgrade to upstream 2.4.44 release with accumulated bug fixes. - Specify source with FTP URL - Removed obsolete 0012-openldap-re24-its8336.patch- Relabel patch 0011-Enforce-minimum-DH-size-of-1024.patch into 0010-Enforce-minimum-DH-size-of-1024.patch- Upgrade to upstream 2.4.43 release with accumulated bug fixes. - Still build on SLES12 - Loadable backend and overlay modules are now installed into arch-specific path %{_libdir}/openldap - All backends and overlays as modules for smaller memory footprint on memory constrained systems - Added extra package for back-sock - Consequent use of %{_rundir} everywhere - Rely on upstream ./configure script instead of any other macro foo - Dropped linking with libwrap - Dropped 0004-libldap-use-gethostbyname_r.dif because this work-around for nss_ldap is obsolete - New sub-package openldap2-contrib with selected contrib/ overlays - Replaced addonschema.tar.gz with separate schema sources - Updated ldapns.schema from recent slapo-nssov source tree - Added symbolic link to slapd executable in /usr/sbin/ - Added more complex example configuration file /etc/openldap/slapd.conf.example - Set OPENLDAP_START_LDAPI="yes" in /etc/sysconfig/openldap - Set OPENLDAP_REGISTER_SLP="no" in /etc/sysconfig/openldap - Added patch for OpenLDAP ITS#7796 to avoid excessive "not index" logging: 0011-openldap-re24-its7796.patch - Replaced openldap-rc.tgz with single source files - Added soft dependency (Recommends) to cyrus-sasl - Added soft dependency (Recommends) to cyrus-sasl-devel to openldap2-devel - Added patch for OpenLDAP ITS#8336 (assert in liblmdb): 0012-openldap-re24-its8336.patch - Remove obsolete patch 0001-build-adjustments.dif- Introduce patch 0010-Revert-Revert-ITS-8240-remove-obsolete-assert.patch to fix CVE-2015-6908. (bsc#945582) - Introduce patch 0011-Enforce-minimum-DH-size-of-1024.patch to address weak DH size vulnerability (bsc#937766)- Introduce patch 0009-Fix-ldap-host-lookup-ipv6.patch to fix an issue with unresponsive LDAP host lookups in IPv6 environment. (bsc#955210)- Remove OpenLDAP 2.3 code and patches from build source. Compatibility libraries for OpenLDAP 2.3 are built in package: compat-libldap-2_3-0 Removed source files: openldap-2.3.37-liblber-length-decoding.dif openldap-2.3.37-libldap-ntlm.diff openldap-2.3.37-libldap-ssl.dif openldap-2.3.37-libldap-sasl-max-buff-size.dif openldap-2.3.37-libldap-tls_chkhost-its6239.dif openldap-2.3.37-libldap-gethostbyname_r.dif openldap-2.3.37-libldap-suid.diff openldap-2.3.37.dif openldap-2.3.37-libldap-ld_defconn-ldap_free_connection.dif openldap-2.3.37-libldap-ldapi_url.dif openldap-2.3.37.tgz openldap-2.3.37-libldap-utf8-ADcanonical.dif README.update check-build.sh- Upgrade to upstream 2.4.42 release with accumulated bug fixes.- Upgrade to upstream 2.4.41 release with accumulcated bug fixes and stability improvements. * Add patch 0008-In-monitor-backend-do-not-return-Connection0-entries.patch * Remove already applied patch 0008-ITS-7723-fix-reference-counting.patch * Remove already applied patch 0009-gcc5.patch (Implements fate#319301)- Add 0009-gcc5.patch to pass -P to the preprocessor in configure checks for Berkeley DB version- binutils is required for "strings" utility invocation in %pre [bnc#904028] - Remove SLE10 definitionsobs-power8-05 16106302902.4.46-lp151.10.24.12.4.46-lp151.10.24.1liblber.alibldap.alibldap_r.a/usr/lib64/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.opensuse.org/openSUSE:Maintenance:15533/openSUSE_Leap_15.1_Update_ports/eeb7863dd08c1646d5d31765333a924d-openldap2.openSUSE_Leap_15.1_Updatedrpmxz5ppc64le-suse-linuxcurrent ar archive R`z!ryI*utf-85b9e25acce9b09b798370fb6b0b1ccbad052dece20c1eb3ee92561ccd595b5a1?P7zXZ !t/P =h]"k%)N4JQ7'uPi,iAR8n?"R𴊣Զ=H, bcAbosUfa5md]G͖p1}MNli !Fe1R]+ vGzoK_qƻ5EΟ֯\rO[X߬QSZ8+EHX8#=`~Fw6TmC6( ML\#wM3C >[77pbC恗kǷ.Mn([!7?x8~^wdo%w@-wΖgQO۾XbyO5ɜX/#E n!0y‚NkwLc4KHB%@*6G!ަ >v`M QcOIn)c@h~mul@1li=1q կX=)̩7zL: ]j^V`ONj| iЁ(*8ߔYH"$o8p}WS8EsZLd!L)djR?ŎvCv)-X|]jb;4 c1 ˏN/P%qXP9VuڥhH.2]6== Z2%[oew&HV"zo MM!f]dkD5Ρb&Ix h0lU((U/!yI\f g<]tzW`]sEB*h! s˧ B(Vxbŋt y93{MV&Cut*> `X:ԁhyt83xDOWd#t2n JǯkԹ'o`mk aǣǷ/ymDASCS8H( 6cJ|OBpt3gm >PJ,WG/VE^(۲sT"#{N'* hhߦqSsȺuriH+T< aXbijwX?FE,1;UV=M{m$ՙeiӑߏ8CY:"13ݯG֡Gf3pja?{!Ϋya1&io\䣞# w'YʤKր'Qpk_]ǂ!]._R I*73d%W#$u(E[H9^|n<{;tZm-?i Б ]Y"ƸVNC+2[t~4QGISσ  ˳𙭗⮣zf~Uw俒5'F&9 Q>fUjc0( ϖ> ʸ=e9U4_. KnSʂ,!ڈo'TO2?*KYA_)#||p?{I?_U'{$gW]$L6 PNKl| |#rLMjSa=ꦔr@qSJ0sUO8P4n4ˍGn@fVS=ݘߎ֦)|*#gaiэ>`Җ }9%S@\G fA|S1(] ^k!%(G~-IXzLQT#nڟ^q,Zu6eng(jXei!{RcK Z{%ITlr{2~S}ӡeM׹-OiL?B\19"G%J@MpZD$S?3tHhZvh\~弲v0)ci0 0]*l7EVbUWT8ϙJgÞ1:Η>+_Ӛ.$6 >jJ"bWճS+I8RH T5{>M51I)GWkIHVSlD.Zw[o"ʉ6/sۿ5鍬ƪtuAr[q p{ ߷ 8%_t+ XmR$k06Vi,_ε?`kW񃉛n<9*.|W Jr"#U~inDѹ[cr\N@CxK587:hid2{Wڸ <M`_Xؿ Z#Ւ+JD mU{D4obc z#b+.O ^:ӯ 8 YQ7R4;Kh3Aq+$!Ǧge`R}["G~:*R "a(2vXuӂe*xK_h [7q?tQ+m*KŖ7=PrLP+F.DI[gF(2ݍ^x "LJccЁmIM8bs }Rv]OwcQr ]j;P}4T(.Fyyn@#`LBr5zGV;l%ZZZXxJ/췵&9&o5bȨN½.%:7L%ҟqD0C"TO,8yM~q5.*jQ9 ,F޿lY;b.ƌʉ"2/ 6}zpNwM<[ 5.JDصfȸPY{ͼn|u1@[fm3"F qh*wl6ꮍhxVM$ Y7;Qfe>$ iZ\Lp$sF+vXȇ 0)4t9NJ V@eQM.RFɗcw5#iJwL8$r( 왑Gs hzwefiwf~&Q`BlozvzWPR8J|9)a y¼+nn>[>OdO<*pbS9oꞥm?u W(4Bi+uڱGn{߫VQe&&ƅȤJy٧P}b#GV5BԼ8KI\E+2Edr)+apJ= k2T"̽',Y$DS9P4a^,n7Pѣ:7*zMg}ҖYJ:kr8z-&*\hkzͱz:+?\3YAWaZ \)n ,Xb,c{=2<7Pb>X=r'z.ᄴ]d-h\ a %RUkB](.LF̃2Բ @t@BfSCj^5I *)jT5ҹ<9Gvڧ*^ރ\Ѫ Z ۛE!HOP˰W87h: 0:%@p8 e "ZH1>}Gx=`eL{IyJUr^ɔ%,τhE㠙UH6"z FxB-ς(  Rc+z5 [e/dNEtgH> l7m~ ފ/l='T)6'i3Df(aU![ch% Od w1>(pw2K'quL;l2a~(`.6Y/Xyw-tHv8{48m"ש G|B|e6dw&41̥]??yk7f_Cv3(I⊔YCo:?;S5l+ dȵ#[Bn9F(PBA6V`3t{ةǴdzA k&xɜ~`WQr82gߜI@K!N syBLMs؊r_6OW}s eX򓑧HӺ@&Ӛ3&0s\97&hA(>`ӣ?8J"2! w)/hbOԔ)5ǵԨͱqZt_I`ywq#kJ6Xa< QGZKnwb6fk'KkӬpN|~ 'GVjfMM@PqZ/N1$ @=n˓w$#Ж~yv8`ެkGRa5&JQSaԱh\+cڰ an7b9I`8oeASx\}9?A C(lBgrZ x/&rk {e%埁'=Ϙ< $Xoz,#_hsOR" x Nd5+eTDYi cF }[iulM9 McWŘ[5 Uޫ7EHC3O/ĐV/tڂ_THn=;漿&6w@)\9&V"3 r̐/R@VELoݹm $TAo4گ~UR \k^ZFF; hYڢ.Nׇ+ɫd vVg%_h,pMĈ{4xe6bG Stkn]FPOtЌVW+ICO,xQn."vsXՋ/1L`֣Fݴ_\@3w,ZG_oH1zu my pGt6I䷸*J#'f R=]65 8ơ<1-w.ޏE0;Eqm4B+j6,_e LGo$]nrZ䢌dMDPBl-FTyȔ#^~H.T.ጾňY ٮ)45BF 䶑<}2٤@KzE%cь+ !NT10^#6 3q^0mr6%hc;' dwq]eŞQd(O |cQ j%1 1wOQN=ؕ9lU9 :IOp,5a[1a>eǩHB4,QRܳcVJG88j{P:1* u_tf$I?Wtr՚F6@ y.]~Meܫn 2i,SzDFB6,<8!Y(&E^5͎GaY6| F3'A ̰ "BYM!)i v\n'h.g} -mL8 <V8#V\GK)k7MPw- W=B^a ( *On0Ő:_:cOڡ1VgHo6o*ju;%7eԐtX @Q'xli{zL DK G>8Z7LQ8_>ͥ(4E3ɸeӧu>` |Ř*<smhlZ%LKCSq|y8j_lƉ Foӛ\co -\y-̽0"1EU 4.Z2ۛ R r}j?]m6"=ϺPzx;گtdRSA/+YUZNh%˶Ob KIP ψ7P8|݇x7fhn߿ճatjrUJv5]袹?K;Y%(15 Xm6qGzVͽ)mY݈AW9^6}Tg)Ϝig:ju;5?C!s|cHԔ됉 Oᢣk42i(ʃ(8:~2>}[mªN~}u,(6 ؏̚vCs!J2EpZNs%4T>/vnh-ⷺ.G8}dcPnذvSgmD!W3XJh8i#@ 9ǧodF? Q.)Q}amO, pFi3tCHz}˄'Bx@rRo̐STD>ו^W"[*؋aT4_&N#*-1.k *UGwdFYȚĹ =Y?3YP 8DHJ VG91 Jjpw=]sN٨vvB߬&_yJ.@((hVG2|He*oᕟO0 ۃiC+؈XOXe36)hts@!<T `R[3'DQx"3K0 uոUQ€^X87tJ$oOMvE{4(é2R@Ye>++d[G2wkxt?O"9z7dƮ\}\7k!fi2.Se77;|5Ӧ(lid.%JyQ䆱AKP͌paDgcTͭ;;MYiV:C竖5Q9p.]Y911VSi(fA7`4)s<1D|p|~kV߾eikX 4KPIܑӚ@AxT+ ~nJGOn)~ Y;l$9ɠK8WQQ(4Hp`/VnP@}pMRb^{#D^mb E7 4Ȓ2>7kBrVPm%Eb18*.SDTS}1yvHWɮ9gld垢.(j#<6j.t~T[6A 稿M~^5J{7X:zv{bKBDEޱQm ]iӦZ5 Gvo!56忪Iߘf!pnQjeT}NҷH4IMB02KJ ;wZ$<_S@H[RAh4ג^^rNFNۘ+DIQ*|X<171Q&'S{+s` H4+`2W[b={/w6/yo[Xg6m-8 j6їz Ї5[G"fā&DVs{Q,-átDbƚ{nvPS\` II=^wIҼˆWjrV#һ][ؚ99lBLp{+V.m4l@rqܚtr㙧qmJhԡ&16¯ېy/ɀ}BֹI0n 9(ֶߣy)5b4yHXsA 1ħ(npK#nYCRPv9RljF~c"h; +U%='u+. ̚"/=}%/zdNh>kijJ; ݣ]=7ќFLn>8A :eFk lbgD1K`_z+nH)!#,IN [5{NڐjE= Ӎ=?N% $ q%bf^MK"\K|c VL1 "K$kҾO o>{ؖ`D5kӋ-=An*?A9-I#Sg' 娧KDM0A(]SGUEViw ɰY)`+l@UHPԿ]Q/DWl%:Y-%?'=Cv d@ĢGyRʠICCmn^k7Qi 7I>, 4d=QexAףpai3,A,JsL(]7R' >?Y"<3rcpTFT:nUqU`4hV>q9S&ނvG@ë#nQń39i0Z%z=ȿFwBnv$|?/&C.W4<YCᎹ7 f꼑RW݃Kݱ/p+4>Agw%CO5cmuC OEPwP@+Q󙷆SQPoSљ ==JbTAOQK+tutp@%&$XyfbAnϛ]զ>f9ŇeaFK[ШihAERT["d/yڽ`RX3ZXoRslյFTRplyLk2rES'"+|MI;~N(cUso< xDoLl\静OOrc<5)%\#Mu3/q'R]V|kA8a^y)0aAa$v,v| C7ifRbBGg|0$ B5*.wW-rn$lvbMA ݻiwLm@ΰ=B c@҃2Ժ"*NġbWŻؠŽ?.m!U]2J&^ID3  T PQmU4Jv8͖0eεu\(c̒@׻8},Z:IɏLκgQzC%}USZ;ow[#::@]pCnӜd ׇtS86\% Lӵ;y{R24r EEZN41wpkyV=bJo$,Bo|>8?),?z [vgvYj'܇ #nZқeC}'_..t: 19QSq8?#EMKd3:zG|e|*6!^r,j<9q#dJ!L9ipAQ,͚W9e|?T,Z 4x9ٔb %jKPE{ZƵph0vj=Z\S;~%'4 C}s@#ˌnǣ<*' ˷:yCf\(rPWtՑL]eLF<}lprEm6m8v@?%vSI)VsgM4*~(N&bE(JW6 `Jgz 0n>:%W[~i4z(6ErZ'`AhX٪Tט G>@v ]\SVgȬ7ezzgp< t$vc$׾^ֳh=lϥsc-x;C?QQr,4!!ocRCMD[0OWn\6 psϘUhW.7'K 99.L+\^? :E4S:B9I-Mwuy>qo&6T%8_E;uB qCN;MJ!a0Pr@:Zմw :HBMUz7s-U!b +pMaS/?+(_Q4n ȟxYD]h{?[87OrlZI`\Uz>@{5yo>iI$b7rG[¾nA0ׯ`8oL:Ëȗ'V<Ηi֭@QJGUM/Fd:J60j:,߾OH 2kZf()/{L\g:6} 20J%[)C]p;n8ܾ. Plּ~:  ](3/ׅ%_lRwNЀV.VSҁ[pc.,W|;-rtWl>@lWtcO;$. ?Q7[yQw_ #f!?tţg \jg,镮XunΖN']0|rhz,Zl*9_k$x݀a71jeP !޶w Yh\꾇]\4Cnͪ|8- .&p9Iq^dYf"g%մ޳xTt#jۧC*$5=I4"+h֎Ԑla_@<<<' Vh G NxHSUF:evhK1eX4[Jo;^G