xorg-x11-server-Xvfb-21.1.11-150600.5.3.1<>,fxg yp9|G pvظW9}Dܓ0D*OiGFܺ3H+yrp _U;Vk=ӟRcӴh LbYz 4ݹ~%9!f\R{9ɩ3Mv;Mʋp<}$mr#y#J23prއ-R=bMy\ \g֚B?2tⱯWR#21xv%K2=jI@ܵy)›#ޚv>D?d , Atx  $ & ( , m pty~%%`%(89 :BFGHIX YZH[L\P]T^Ybcc defluvwxyz,04:|Cxorg-x11-server-Xvfb21.1.11150600.5.3.1Virtual Xserver XvfbThis package contains the virtual Xserver Xvfb.g yh01-ch3ccSUSE Linux Enterprise 15SUSE LLC MIThttps://www.suse.com/System/X11/Servers/XF86_4http://xorg.freedesktop.org/linuxx86_64cg s7076eb8b6fd8fbcf10b4897a8eac2c9214643a5637ddfcdb5afbe7b70305b5fdrootrootxorg-x11-server-21.1.11-150600.5.3.1.src.rpmxorg-x11-Xvfbxorg-x11-server-Xvfbxorg-x11-server-Xvfb(x86-64)xorg-x11-server:/usr/bin/Xvfb@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    MesalibGL.so.1()(64bit)libXau.so.6()(64bit)libXdmcp.so.6()(64bit)libXfont2.so.2()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.26)(64bit)libc.so.6(GLIBC_2.27)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.2)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.32)(64bit)libc.so.6(GLIBC_2.33)(64bit)libc.so.6(GLIBC_2.34)(64bit)libc.so.6(GLIBC_2.38)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.7)(64bit)libc.so.6(GLIBC_2.8)(64bit)libc.so.6(GLIBC_2.9)(64bit)libcrypto.so.3()(64bit)libcrypto.so.3(OPENSSL_3.0.0)(64bit)libm.so.6()(64bit)libm.so.6(GLIBC_2.2.5)(64bit)libm.so.6(GLIBC_2.29)(64bit)libm.so.6(GLIBC_2.35)(64bit)libpixman-1.so.0()(64bit)libsystemd.so.0()(64bit)libsystemd.so.0(LIBSYSTEMD_209)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)xkbcompxkeyboard-config3.0.4-14.6.0-14.0-15.2-14.14.3g@f@fe@eȶeȶee@eoe@e@em@e9@d(dc=@cT@cccR@c@c.cEch@ch@cb[cb[cObγbγbγby@bzSbDF@b-b@b@b@a@a@aa@a@a@aaaaay?@a`]`]`:@`9@``P@`}p`u`t6@`?z@_@_@_0@_ts@_s!_q@_l@_a@_X_G@_D@_$^)@^@^^@^W@^%@^@]@]@]@]@]]y@]i]@1@\\O\@\v{\I\A\,[@[@[@[ā@[t[i[\Z[Xf@[P}@[D[:[2*[*A[@Z@ZZԐ@ZJ@Z2@ZZ Z}@ZTZ?Z/Z@Z YY@YY@Yh@Yg`Y_wY[@Y;@Y:Y6@XX @X+X@XpXXwoXN@X,J@XW@W@W@WDB@W9@W/*@W'A@W#LW @W @W @WKWW@V@Vn@V3VVm@VxVVV&@VV@V@VV@VGVVVUVA@V0V0V7@UU@U@UUzUuUn@Ui@U0U:T!TTTԬT[@T[@Tk4T`TN3sndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.combjorn.lie@gmail.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.commgorse@suse.comdmueller@suse.comdmueller@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comtzimmermann@suse.desndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comdmueller@suse.commeissner@suse.comsndirsch@suse.combjorn.lie@gmail.comsndirsch@suse.comdmueller@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comtzimmermann@suse.detzimmermann@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comdmueller@suse.comsndirsch@suse.combjorn.lie@gmail.comismail@i10z.compatrik.jakobsson@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comtobias.klausmann@freenet.desndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.commgorse@suse.combjorn.lie@gmail.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comfcrozat@suse.combjorn.lie@gmail.combjorn.lie@gmail.combjorn.lie@gmail.comsndirsch@suse.combjorn.lie@gmail.comsndirsch@suse.comsndirsch@suse.comtobias.johannes.klausmann@mni.thm.demliska@suse.czjengelh@inai.desndirsch@suse.comsndirsch@suse.comsndirsch@suse.commsrb@suse.comsndirsch@suse.commsrb@suse.comsndirsch@suse.comtobias.johannes.klausmann@mni.thm.demsrb@suse.comtobias.johannes.klausmann@mni.thm.dejdelvare@suse.desndirsch@suse.comtiwai@suse.defcrozat@suse.comsndirsch@suse.commsrb@suse.comsndirsch@suse.commsrb@suse.comtobias.johannes.klausmann@mni.thm.demsrb@suse.commsrb@suse.commsrb@suse.commsrb@suse.comfcrozat@suse.combwiedemann@suse.comsndirsch@suse.commwilck@suse.comtobias.johannes.klausmann@mni.thm.demsrb@suse.comrbrown@suse.commsrb@suse.comtobias.johannes.klausmann@mni.thm.detobias.johannes.klausmann@mni.thm.deilya@ilya.pp.uasndirsch@suse.comsndirsch@suse.commsrb@suse.comsndirsch@suse.comsndirsch@suse.comopensuse@dstoecker.desndirsch@suse.comtobias.johannes.klausmann@mni.thm.detobias.johannes.klausmann@mni.thm.dedenis.kondratenko@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comtobias.johannes.klausmann@mni.thm.defbui@suse.comtobias.johannes.klausmann@mni.thm.dezaitor@opensuse.orgtobias.johannes.klausmann@mni.thm.detobias.johannes.klausmann@mni.thm.demstaudt@suse.comeich@suse.comeich@suse.comeich@suse.comsndirsch@suse.comsndirsch@suse.comeich@suse.comeich@suse.comeich@suse.comeich@suse.comtobias.johannes.klausmann@mni.thm.detobias.johannes.klausmann@mni.thm.deeich@suse.comeich@suse.comtobias.johannes.klausmann@mni.thm.delbsousajr@gmail.comeich@suse.comeich@suse.comeich@suse.comeich@suse.comtobias.johannes.klausmann@mni.thm.deeich@suse.comeich@suse.comfcrozat@suse.comeich@suse.comeich@suse.comeich@suse.comhrvoje.senjan@gmail.comeich@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comeich@suse.comtiwai@suse.deeich@suse.comtobias.johannes.klausmann@mni.thm.detobias.johannes.klausmann@mni.thm.demsrb@suse.comantoine.belvire@laposte.netmsrb@suse.comeich@suse.comnormand@linux.vnet.ibm.commsrb@suse.comdimstar@opensuse.orgsndirsch@suse.comtobias.johannes.klausmann@mni.thm.deeich@suse.comtobias.johannes.klausmann@mni.thm.demsrb@suse.comsndirsch@suse.comledest@gmail.comsndirsch@suse.com- U_xkb-Fix-buffer-overflow-in-_XkbSetCompatMap.patch * Heap-based buffer overflow privilege escalation in _XkbSetCompatMap (CVE-2024-9632, bsc#1231565)- U_render-Avoid-possible-double-free-in-ProcRenderAddGl.patch * fixes regression for security fix for CVE-2024-31083 (bsc#1222312, boo#1222442, gitlab xserver issue #1659)- U_CVE-2024-31080-Xi-ProcXIGetSelectedEvents-needs-to-use-unswapped-le.patch * Xi: ProcXIGetSelectedEvents needs to use unswapped length (CVE-2024-31080, bsc#1222309) - U_CVE-2024-31081-Xi-ProcXIPassiveGrabDevice-needs-to-use-unswapped-le.patch * Xi: ProcXIPassiveGrabDevice needs to use unswapped length to send reply (CVE-2024-31081, bsc#1222310) - U_CVE-2024-31082-Xquartz-ProcAppleDRICreatePixmap-needs-to-use-unswap.patch * Xquartz: ProcAppleDRICreatePixmap needs to use unswapped length to send reply (CVE-2024-31082, bsc#1222311) - U_CVE-2024-31083-render-fix-refcounting-of-glyphs-during-ProcRenderAd.patch * render: fix refcounting of glyphs during ProcRenderAddGlyphs (CVE-2024-31083, bsc#1222312)- Release 21.1.11 also covers fixes for security issue CVE-2022-46340 and bug numbers bsc#1205874, bsc#1217765- Release 21.1.11 covers fixes for the following bug numbers, which are not mentioned in this changelog before: bsc#1218845, bsc#1218846, bsc#1216261, bsc#1216133, bsc#1216135- Release 21.1.11 supersedes the following patches still used with xorg-x11-server 21.1.4 on sle15-sp5/Leap 15.5 and not mentioned in this changelog as superseded before: * U_Xext-fix-invalid-event-type-mask-in-XTestSwapFakeInp.patch * U_bsc1216133-mi-reset-the-PointerWindows-reference-on-screen-swit.patch * U_bsc1216135-Xi-randr-fix-handling-of-PropModeAppend-Prepend.patch * U_bsc1216261-0001-mi-fix-CloseScreen-initialization-order.patch * U_bsc1216261-0002-fb-properly-wrap-unwrap-CloseScreen.patch * U_bsc1216261-0003-dix-always-initialize-pScreen-CloseScreen.patch * bsc1218582-0001-dix-allocate-enough-space-for-logical-button-maps.patch * bsc1218583-0001-dix-Allocate-sufficient-xEvents-for-our-DeviceStateN.patch * bsc1218583-0002-dix-fix-DeviceStateNotify-event-calculation.patch * bsc1218583-0003-Xi-when-creating-a-new-ButtonClass-set-the-number-of.patch * bsc1218584-0001-Xi-flush-hierarchy-events-after-adding-removing-mast.patch * bsc1218585-0001-Xi-do-not-keep-linked-list-pointer-during-recursion.patch * bsc1218585-0002-dix-when-disabling-a-master-float-disabled-slaved-de.patch * U_bsc1218845-glx-Call-XACE-hooks-on-the-GLX-buffer.patch * U_bsc1218846-ephyr-xwayland-Use-the-proper-private-key-for-cursor.patch- xserver sources of this release fixes segfault in Xvnc (bsc#1219311)- no longer (build-)require obsolete Xprint/XprintUtil- Update to version 21.1.11 * This release contains fixes for the issues reported in today's security advisory: https://lists.x.org/archives/xorg/2024-January/061525.html * CVE-2023-6816 (bsc#1218582) * CVE-2024-0229 (bsc#1218583) * CVE-2024-21885 (bsc#1218584) * CVE-2024-21886 (bsc#1218585) * CVE-2024-0408 * CVE-2024-0409 - supersedes the following patches * U_xephyr-Don-t-check-for-SeatId-anymore.patch * U_bsc1217765-Xi-allocate-enough-XkbActions-for-our-buttons.patch * U_bsc1217766-randr-avoid-integer-truncation-in-length-check-of-Pr.patch- u_miCloseScreen_check_for_null_pScreen_dev_private.patch * miCloseScreen check for null pScreen dev private (bsc#1218176); another regression introduced by U_bsc1216261-0002-fb-properly-wrap-unwrap-CloseScreen.patch- n_xserver-optimus-autoconfig-hack.patch u_randr-Do-not-crash-if-slave-screen-does-not-have-pro.patch u_xfree86-activate-GPU-screens-on-autobind.patch * check dixPrivateKeyRegistered(rrPrivKey) before calling rrGetScrPriv() to avoid xserver crash when Xinerama is enabled (boo#1218240) - ------------------------------------------------------------------- U_bsc1217765-Xi-allocate-enough-XkbActions-for-our-buttons.patch * Out-of-bounds memory write in XKB button actions (CVE-2023-6377, ZDI-CAN-22412, ZDI-CAN-22413, bsc#1217765) - U_bsc1217766-randr-avoid-integer-truncation-in-length-check-of-Pr.patch * Out-of-bounds memory read in RRChangeOutputProperty and RRChangeProviderProperty (CVE-2023-6478, ZDI-CAN-22561, bsc#1217766)- Update to version 21.1.9 * This release contains fixes for CVE-2023-5367, CVE-2023-5380 and CVE-2023-5574 as reported in today's security advisory: https://lists.x.org/archives/xorg-announce/2023-October/003430.html - adjusted u_Use-better-fallbacks-to-generate-cookies-if-arc4rand.patch- Update to version 21.1.8 (CVE-2023-1393): * This release contains the fix for CVE-2023-1393 * composite: Fix use-after-free of the COW * xkbUtils: use existing symbol names instead of deleted deprecated ones - Drop U_xserver-composite-Fix-use-after-free-of-the-COW.patch: Fixed upstream - Switch back to tarball release, drop source service, add keyring and sig files.- U_xserver-composite-Fix-use-after-free-of-the-COW.patch * overlay window use-after-free (CVE-2023-1393, ZDI-CAN-19866, bsc#1209543)- Update to version xorg-server-21.1.7: * This release contains the fix for CVE-2023-0494 in today's security advisory: https://lists.x.org/archives/xorg-announce/2023-February/003320.html It also fixes a second possible OOB access during EnqueueEvent and a crasher caused by ResourceClientBits not correctly honouring the MaxClients value in the configuration file. - supersedes U_Xi-fix-potential-use-after-free-in-DeepCopyPointerCl.patch, U_xorg-server-oob-read-enqueue-event.patch- U_Xi-fix-potential-use-after-free-in-DeepCopyPointerCl.patch * DeepCopyPointerClasses use-after-free (CVE-2023-0494, ZDI-CAN-19596, bsc#1207783)- rename u_xorg-server-oob-read-enqueue-event.patch to U_xorg-server-oob-read-enqueue-event.patch since it's already upstream- Add u_xorg-server-oob-read-enqueue-event.patch: fix an out-of-bounds read in EnqueueEvent.- Update to version xorg-server-21.1.6: * xserver 21.1.6 * Xext: fix invalid event type mask in XTestSwapFakeInput * xkb: fix some possible memleaks in XkbGetKbdByName * xkb: proof GetCountedString against request length attacks * xquartz: Fix some formatting * XQuartz: stub: Call LSOpenApplication instead of fork()/exec() - drop the following upstream patches: U_xkb-proof-GetCountedString-against-request-length-at.patch U_xkb-fix-some-possible-memleaks-in-XkbGetKbdByName.patch- Update to version xorg-server-21.1.5: * xkb: reset the radio_groups pointer to NULL after freeing it * Xi: avoid integer truncation in length check of ProcXIChangeProperty * Xi: return an error from XI property changes if verification failed * Xext: free the screen saver resource when replacing it * Xext: free the XvRTVideoNotify when turning off from the same client * Xi: disallow passive grabs with a detail > 255 * Xtest: disallow GenericEvents in XTestSwapFakeInput * meson: Don't build COMPOSITE for XQuartz * xquartz: Move default applications list outside of the main executable * xquartz: Remove unused macro (X11LIBDIR) - drop the following upstream patches: U_0007-xkb-reset-the-radio_groups-pointer-to-NULL-after-fre.patch U_0002-Xi-return-an-error-from-XI-property-changes-if-verif.patch U_0003-Xi-avoid-integer-truncation-in-length-check-of-ProcX.patch U_0004-Xi-disallow-passive-grabs-with-a-detail-255.patch U_0005-Xext-free-the-screen-saver-resource-when-replacing-i.patch U_0006-Xext-free-the-XvRTVideoNotify-when-turning-off-from-.patch U_0001-Xtest-disallow-GenericEvents-in-XTestSwapFakeInput.patch- U_0007-xkb-reset-the-radio_groups-pointer-to-NULL-after-fre.patch * XkbGetKbdByName use-after-free (ZDI-CAN-19530, CVE-2022-4283, bsc#1206017)- U_0001-Xtest-disallow-GenericEvents-in-XTestSwapFakeInput.patch * Server XTestSwapFakeInput stack overflow (ZDI-CAN 19265, CVE-2022-46340, bsc#1205874) - U_0002-Xi-return-an-error-from-XI-property-changes-if-verif.patch * Xi: return an error from XI property changes if verification failed (no ZDI-CAN id, no CVE id, bsc#1205875) - U_0003-Xi-avoid-integer-truncation-in-length-check-of-ProcX.patch * Server XIChangeProperty out-of-bounds access (ZDI-CAN 19405, CVE-2022-46344, bsc#1205876) - U_0004-Xi-disallow-passive-grabs-with-a-detail-255.patch * Server XIPassiveUngrabDevice out-of-bounds access (ZDI-CAN 19381, CVE-2022-46341, bsc#1205877) - U_0005-Xext-free-the-screen-saver-resource-when-replacing-i.patch * Server ScreenSaverSetAttributes use-after-free (ZDI-CAN 19404, CVE-2022-46343, bsc#1205878) - U_0006-Xext-free-the-XvRTVideoNotify-when-turning-off-from-.patch * Server XvdiSelectVideoNotify use-after-free (ZDI-CAN 19400, CVE-2022-46342, bsc#1205879)- Release 21.1 covers bugfixes and JIRA tickets for bsc#1176015,bsc#1182510,bsc#1182884,bsc#1184072,bsc#1184543,bsc#1184906,bsc#1186092,bsc#1188970,bsc#1194159,bsc#1196577,bsc#1197046,bsc#1197269,bsc#1200076,fdo#574,jsc#SLE-18653,jsc#SLE-8470- Release 21.1 supersedes the following patches still used with xorg-x11-server 1.20.3 on sle15-sp4/Leap 15.4: * U_0002-DRI2-Add-another-Coffeelake-PCI-ID.patch * U_0002-Fix-crash-on-XkbSetMap.patch * U_0003-Fix-crash-on-XkbSetMap.patch * U_0003-dri2-Sync-i965_pci_ids.h-from-mesa.patch * U_0004-dri2-Set-fallback-driver-names-for-Intel-and-AMD-chi.patch * U_0005-dri2-Sync-i965_pci_ids.h-from-mesa-iris_pci_ids.h.patch * U_build-glx-Lower-gl-version-to-work-with-libglvnd.patch * U_glamor-Make-pixmap-exportable-from-gbm_bo_from_pixma.patch * U_hw_do-not-include-sys-io-with-glibc.patch * U_meson-Fix-another-reference-to-gl-9.2.0.patch * U_modesetting-Fix-broken-manpage-in-autoconf-build.patch * U_present-wnmd-Fix-use-after-free-on-CRTC-removal.patch * U_present-wnmd-Relax-assertion-on-CRTC-on-abort_vblank.patch * U_xfree86-Change-displays-array-to-pointers-array-to-f.patch * U_xfree86-Fix-NULL-pointer-dereference-crash.patch * U_xkbsetdeviceinfo.patch * u_sync-pci-ids-with-Mesa-21.2.4.patch * u_xf86-Accept-devices-with-the-simpledrm-driver.patch * u_xichangehierarchy-CVE-2020-14346.patch * u_xkb-CVE-2020-14345.patch * u_xkb-CVE-2020-14360.patch- removed N_Disable-HW-Cursor-for-cirrus-and-mgag200-kernel-modules.patch * meanwhile cirrus and mgag200 Kernel drivers have been rewritten multiple times and no longer have (broken) hardware cursor- u_xf86-Accept-devices-with-the-kernels-ofdrm-driver.patch * Add workaround to support ofdrm- U_xkb-proof-GetCountedString-against-request-length-at.patch * security update for CVE-2022-3550 (bsc#1204412) - U_xkb-fix-some-possible-memleaks-in-XkbGetKbdByName.patch * security update for CVE-2022-3551 (bsc#1204416)- rename u_sync-pci-ids-with-Mesa-22.0.0.patch to u_sync-pci-ids-with-Mesa.patch (currently synced with Mesa 22.1.3)- u_sync-pci-ids-with-Mesa-22.0.0.patch * synced with Mesa 22.1.3; just adding a PCI ID for vmware was needed- Update to version 21.1 * This release fixes 2 recently reported security vulnerabilities in xkb, several regressions since 1.20.x and a number of miscellaneous bugs. - supersedes the following security patches * U_boo1194181-001-xkb-swap-XkbSetDeviceInfo-and-XkbSetDeviceInfoCheck.patch * U_boo1194179-001-xkb-rename-xkb_h-to-xkb-procs_h.patch * U_boo1194179-002-xkb-add-request-length-validation-for-XkbSetGeometry.patch - supersedes U_Fix-build-with-gcc-12.patch- U_boo1194181-001-xkb-swap-XkbSetDeviceInfo-and-XkbSetDeviceInfoCheck.patch * Out-Of-Bounds Access in CheckSetDeviceIndicators() (CVE-2022-2320, ZDI-CAN-16070, bsc#1194181) - U_boo1194179-001-xkb-rename-xkb_h-to-xkb-procs_h.patch, U_boo1194179-002-xkb-add-request-length-validation-for-XkbSetGeometry.patch * Out-Of-Bounds Access in _CheckSetSections() (CVE-2022-2319, ZDI-CAN-16062, bsc#1194179)- add n_raise_default_clients.patch- disable -z now linking for now, as there are some missing symbol issues. (boo#1197994)- u_sync-pci-ids-with-Mesa-22.0.0.patch * sync pci ids with Mesa 22.0.0- U_Fix-build-with-gcc-12.patch * render: Fix build with gcc 12 (glfdo#xorg/xserver!853).- U_xephyr-Don-t-check-for-SeatId-anymore.patch * fix mouse/keyboard focus in Xephyr (boo#1194658, github issue#1289)- fix bashisms in pre_checkins.sh (bsc#1195391)- u_xfree86-activate-GPU-screens-on-autobind.patch * Part of the original patch by Dave Airlie has landed 078277e4d92f05a90c4715d61b89b9d9d38d68ea, this contains the remainder of what was in SUSE before Xorg 21.1. (github issue#1254, boo#1192751)- Update to version 21.1.3 * This release fixes several regressions since 1.20.x and 21.1.1 + glx/dri: Filter out fbconfigs that don't have a supported pixmap format + xf86/logind: Fix compilation error when built without logind/platform bus + xf86/logind: fix missing call to vtenter if the platform device is not paused + Convert more funcs to use InternalEvent. + os: Try to discover the current seat with the XDG_SEAT var first- Update to version 21.1.2 * This release fixes 4 recently reported security vulnerabilities and several regressions. * In particular, the real physical dimensions are no longer reported by the X server anymore as it was deemed to be a too disruptive change. X server will continue to report DPI as 96. - supersedes U_hw-xfree86-Propagate-physical-dimensions-from-DRM-co.patch - supersedes U_rendercompositeglyphs.patch - supersedes U_xfixes-Fix-out-of-bounds-access-in-ProcXFixesCreateP.patch - supersedes U_Xext-Fix-out-of-bounds-access-in-SProcScreenSaverSus.patch - supersedes U_record-Fix-out-of-bounds-access-in-SwapCreateRegiste.patch- U_xfixes-Fix-out-of-bounds-access-in-ProcXFixesCreateP.patch * CVE-2021-4009/ZDI-CAN-14950 (bsc#1190487) The handler for the CreatePointerBarrier request of the XFixes extension does not properly validate the request length leading to out of bounds memory write. - U_Xext-Fix-out-of-bounds-access-in-SProcScreenSaverSus.patch * CVE-2021-4010/ZDI-CAN-14951 (bsc#1190488) The handler for the Suspend request of the Screen Saver extension does not properly validate the request length leading to out of bounds memory write. - U_record-Fix-out-of-bounds-access-in-SwapCreateRegiste.patch * CVE-2021-4011/ZDI-CAN-14952 (bsc#1190489) The handlers for the RecordCreateContext and RecordRegisterClients requests of the Record extension do not properly validate the request length leading to out of bounds memory write.- U_rendercompositeglyphs.patch * X.Org Server SProcRenderCompositeGlyphs Out-Of-Bounds Access Privilege Escalation Vulnerability [CVE-2021-4008, ZDI-CAN-14192] (boo#1193030)- u_Support-configuration-files-under-run-X11-xorg.conf..patch - u_Add-udev-scripts-for-configuration-of-platform-devic.patch - u_Add-udev-rule-for-HyperV-devices.patch * Remove udev-based configuration - u_Revert-xf86-Accept-devices-with-the-simpledrm-driver.patch * Restore simpledrm workaround - u_xf86-Accept-devices-with-the-hyperv_drm-driver.patch * Add workaround to support hyperv_drm- u_pci-primary-Fix-up-primary-PCI-device-detection-for-the-platfrom-bus.patch * Fix SEGFAULT when parsing bus IDs of NULL (boo#1193250) - u_Support-configuration-files-under-run-X11-xorg.conf..patch * Support configuration files under /run. Required for generating configuration files via udev. (boo#1193250) - u_Add-udev-scripts-for-configuration-of-platform-devic.patch * Generate configuration files for platform devices (boo#1193250) - u_Revert-xf86-Accept-devices-with-the-simpledrm-driver.patch * Code has been obsoleted by udev patchset (boo#1193250) - u_Add-udev-rule-for-HyperV-devices.patch * Same as for platform devices, but on HyperV (boo#1193250)- enable build of Xorg on s390x (jira#SLE-18632)- U_hw-xfree86-Propagate-physical-dimensions-from-DRM-co.patch * reverse apply this one to go back to fixed 96 dpi (gitlab fdo/xserver issue#1241) - N_fix-dpi-values.diff * back to version for xserver < 21.1.0- Update to version 21.1.1 * s/__/@/ in inputtestdrv manpage * Make xf86CompatOutput() return NULL when there are no privates * Makefile.am: Add missing meson build files to release tarball- Update to version 21.1.0 * The meson support is now fully mature. While autotools support will still be kept for this release series, it will be dropped afterwards. * Glamor support for Xvfb. * Variable refresh rate support in the modesetting driver. * XInput 2.4 support which adds touchpad gestures. * DMX DDX has been removed. * X server now correctly reports display DPI in more cases. This may affect rendering of client applications that have their own workarounds for hi-DPI screens. * A large number of small features and various bug fixes. - updated xorg-server-provides - supersedes patches * U_Fix-segfault-on-probing-a-non-PCI-platform-device-on.patch * U_dix-window-Use-ConfigureWindow-instead-of-MoveWindow.patch * U_glamor_egl-Reject-OpenGL-2.1-early-on.patch * u_render-Cast-color-masks-to-unsigned-long-before-shifting-them.patch - refreshed patches * N_fix-dpi-values.diff * N_zap_warning_xserver.diff * u_modesetting-Fix-dirty-updates-for-sw-rotation.patch * u_randr-Do-not-crash-if-slave-screen-does-not-have-pro.patch * u_vesa-Add-VBEDPMSGetCapabilities-VBEDPMSGet.patch - disabled n_xserver-optimus-autoconfig-hack.patch, which I believe is superseded by: commit 078277e4d92f05a90c4715d61b89b9d9d38d68ea Author: Dave Airlie Date: Fri Aug 17 09:49:24 2012 +1000 xf86: autobind GPUs to the screen - added pkgconfig(libxcvt) - cvt binary moved to libxcvt0 package- Update to version 1.20.13 * bugfix release - supersedes U_present-get_crtc-should-not-return-crtc-when-its-scr.patch, U_modesetting-unflip-not-possible-when-glamor-is-not-s.patch- U_modesetting-unflip-not-possible-when-glamor-is-not-s.patch * this should fixes crashes of xfce when running under qemu (boo#1188559)- add U_present-get_crtc-should-not-return-crtc-when-its-scr.patch (bsc#1188559) https://gitlab.freedesktop.org/xorg/xserver/-/issues/1195- Update to version 1.20.12 * bugfix release- Drop U_xwayland-Allow-passing-a-fd.patch: We build xwayland in a separate package now, so no need to keep this patch here.- Fix typo in %post: xbb.conf -> xkb.conf- u_modesetting-Fix-dirty-updates-for-sw-rotation.patch * Fixes broken rotation support for DRM drivers without hardware rotation support or direct vram access (bsc#1182955)- disable build of Xwayland, which is now being built in separate xwayland package with more recent sources (boo#1182677)- Update to version 1.20.11 * bugfix release - supersedes U_Fix-XChangeFeedbackControl-request-underflow.patch, U_xkb-Fix-heap-overflow-caused-by-optimized-away-min.patch- U_Fix-XChangeFeedbackControl-request-underflow.patch * Fix XChangeFeedbackControl() request underflow (CVE-2021-3472, ZDI-CAN-1259, bsc#1180128)- reenabled LTO (boo#1133294) * u_no-lto-for-tests.patch disables LTO in test/ subtree, since "-Wl,-wrap" is not supported by LTO * added "%global _lto_cflags %{?_lto_cflags} -ffat-lto-objects"- Update to version 1.20.10: * Check SetMap request length carefully. * Fix XkbSetDeviceInfo() and SetDeviceIndicators() heap overflows * present/wnmd: Translate update region to screen space * modesetting: keep going if a modeset fails on EnterVT * modesetting: check the kms state on EnterVT * configure: Build hashtable for Xres and glvnd * xwayland: Create an xwl_window for toplevel only * xwayland: non-rootless requires the wl_shell protocol * glamor: Update pixmap's devKind when making it exportable * os: Fix instruction pointer written in xorg_backtrace * present/wnmd: Execute copies at target_msc-1 already * present/wnmd: Move up present_wnmd_queue_vblank * present: Add present_vblank::exec_msc field * present: Move flip target_msc adjustment out of present_vblank_create * xwayland: Remove pending stream reference when freeing * xwayland: use drmGetNodeTypeFromFd for checking if a node is a render one * xwayland: Do not discard frame callbacks on allow commits * present/wnmd: Remove dead check from present_wnmd_check_flip * xwayland: Check window pixmap in xwl_present_check_flip2 * present/wnmd: Can't use page flipping for windows clipped by children * xfree86: Take second reference for SavedCursor in xf86CursorSetCursor * glamor: Fix glamor_poly_fill_rect_gl xRectangle::width/height handling * include: Increase the number of max. input devices to 256. * Revert "linux: Make platform device probe less fragile" * Revert "linux: Fix platform device PCI detection for complex bus topologies" * Revert "linux: Fix platform device probe for DT-based PCI" - Remove included pachtes * U_xfree86_take_second_ref_for_xcursor.patch * U_Revert-linux-Fix-platform-device-probe-for-DT-based-.patch * U_Revert-linux-Fix-platform-device-PCI-detection-for-c.patch * U_Revert-linux-Make-platform-device-probe-less-fragile.patch * U_Fix-XkbSetDeviceInfo-and-SetDeviceIndicators-heap-ov.patch * U_Check-SetMap-request-length-carefully.patch- remove unneeded python2 script 'fdi2iclass.py' from xorg-x11-server-sources subpackage (boo#1179591)- U_Check-SetMap-request-length-carefully.patch * XkbSetMap Out-Of-Bounds Access: Insufficient checks on the lengths of the XkbSetMap request can lead to out of bounds memory accesses in the X server. (ZDI-CAN 11572, CVE-2020-14360, bsc#1174908) - U_Fix-XkbSetDeviceInfo-and-SetDeviceIndicators-heap-ov.patch * XkbSetDeviceInfo Heap-based Buffer Overflow: Insufficient checks on input of the XkbSetDeviceInfo request can lead to a buffer overflow on the head in the X server. (ZDI-CAN 11389, CVE-2020-25712, bsc#1177596)- n_xorg-wrapper-anybody.patch * replace default config /etc/X11/Xwrapper, which allows anybody to use the wrapper, by a patch for the code, i.e. [#] rootonly, console, anybody allowed_users=anybody [#] yes, no, auto needs_root_rights=auto is now the default without any Xwrapper config (needs_root_rights=auto was already the default before)- u_xorg-wrapper-Xserver-Options-Whitelist-Filter.patch * replaced by improved version written by Matthias Gerstner of our security team + simplified the option parsing code a bit + changed the "ignore forbidden argument" logic into an "abort on forbidden argument" logic. This is safer and avoids surprises on the user's end that could occur if the desired command line arguments aren't effective but the Xorg server is still started. + tried to adjust to the coding style present in the file (mostly the function name) + added some logic to apply the option filtering only to non-root users when Xorg is actually started as root. This should allow for full flexibility if root calls the wrapper or if the Xorg server only runs with user privileges.- U_Fix-segfault-on-probing-a-non-PCI-platform-device-on.patch, U_Revert-linux-Fix-platform-device-PCI-detection-for-c.patch, U_Revert-linux-Fix-platform-device-probe-for-DT-based-.patch, U_Revert-linux-Make-platform-device-probe-less-fragile.patch * fix Xserver startup on Raspberry Pi 3 (boo#1176203)- n_xorg-wrapper-rename-Xorg.patch * moved Xorg to Xorg.bin and Xorg.sh to Xorg (boo#1175867) - change default for needs_root_rights to auto in Xwrapper.config (boo#1175867)- reenabled SUID wrapper for TW (boo#1175867) - u_xorg-wrapper-Xserver-Options-Whitelist-Filter.patch * Xserver option whitelist filter (boo#1175867)-Add U_xfree86_take_second_ref_for_xcursor.patch: fix use-after-free when switching VTs.- Update to version 1.20.9: * Fix XRecordRegisterClients() Integer underflow * Fix XkbSelectEvents() integer underflow * Fix XIChangeHierarchy() integer underflow * Correct bounds checking in XkbSetNames() * linux: Fix platform device probe for DT-based PCI * linux: Fix platform device PCI detection for complex bus topologies * linux: Make platform device probe less fragile * fix for ZDI-11426 * xfree86: add drm modes on non-GTF panels * present: Check valid region in window mode flips * xwayland: Handle NULL xwl_seat in xwl_seat_can_emulate_pointer_warp * xwayland: Propagate damage x1/y1 coordinates in xwl_present_flip * doc: Update URLs in Xserver-DTrace.xml * xwayland: Use a fixed DPI value for core protocol * xwayland: only use linux-dmabuf if format/modifier was advertised * hw/xfree86: Avoid cursor use after free * Update URL's in man pages * xwayland: Disable the MIT-SCREEN-SAVER extension when rootless * xwayland: Hold a pixmap reference in struct xwl_present_event * randr: Check rrPrivKey in RRHasScanoutPixmap() * modesetting: Fix front_bo leak at drmmode_xf86crtc_resize on XRandR rotation * xwayland: Store xwl_tablet_pad in its own private key * xwayland: Initialise values in xwlVidModeGetGamma() * xwayland: Fix crashes when there is no pointer * xwayland: Clear private on device removal * xwayland: Free all remaining events in xwl_present_cleanup * xwayland: Always use xwl_present_free_event for freeing Present events * present/wnmd: Free flip_queue entries in present_wnmd_clear_window_flip * present/wnmd: Keep pixmap pointer in present_wnmd_clear_window_flip * xwayland: import DMA-BUFs with GBM_BO_USE_RENDERING only * xwayland: Fix infinite loop at startup * modesetting: Disable pageflipping when using a swcursor * dix: do not send focus event when grab actually does not change - Drop patches fixed upstream: * U_0001-Correct-bounds-checking-in-XkbSetNames.patch * U_0002-Fix-XIChangeHierarchy-integer-underflow.patch * U_0003-Fix-XkbSelectEvents-integer-underflow.patch * U_0004-Fix-XRecordRegisterClients-Integer-underflow.patch * U_FixForZDI-11426.patch- U_0001-Correct-bounds-checking-in-XkbSetNames.patch * Correct bounds checking in XkbSetNames() [CVE-2020-14345 / ZDI 11428, boo#1174635] - U_0002-Fix-XIChangeHierarchy-integer-underflow.patch * Fix XIChangeHierarchy() integer underflow [CVE-2020-14346 / ZDI-CAN-11429, boo#1174638] - U_0003-Fix-XkbSelectEvents-integer-underflow.patch * Fix XkbSelectEvents() integer underflow [CVE-2020-14361 / ZDI-CAN 11573, boo#1174910] - U_0004-Fix-XRecordRegisterClients-Integer-underflow.patch * Fix XRecordRegisterClients() Integer underflow [CVE-2020-14362 / ZDI-CAN-11574, boo#1174913]- U_FixForZDI-11426.patch * Leak of uninitialized heap memory form the X server to clients on pixmap allocation (ZDI-CAN-11426, CVE-2020-14347, bsc#1174633)- move xorg_pci_ids dir from /etc/X11 to /usr/share/X11 and xorg-x11-server.macros from /etc/rpm to /usr/lib/rpm/macros.d; no longer package /etc/X11/xorg.conf.d (boo#1173056)- U_glamor_egl-Reject-OpenGL-2.1-early-on.patch * GLAMOR: no longer bail out for OpenGL drivers < 2.1 (boo#1172321)- provide/obsoletes cirrus and ast usermode driver also on openSUSE (jsc#SLE-12127)- Update to version 1.20.8+0: * Revert "dri2: Don't make reference to noClientException" * dix: Check for NULL spriteInfo in GetPairedDevice * os: Ignore dying client in ResetCurrentRequest * modesetting: remove unnecessary error message, fix zaphod leases * Fix building with `-fno-common` * xwayland: clear pixmaps after creation in rootless mode * glamor: Fix a compiler warning since the recent OOM fixes. * Restrict 1x1 pixmap filling optimization to GXcopy * Add xf86OSInputThreadInit to stub os-support as well * Fix old-style definition warning for xf86OSInputThreadInit() * xwayland/glamor-gbm: Handle DRM_FORMAT_MOD_INVALID gracefully * configure: Define GLAMOR_HAS_EGL_QUERY_DRIVER when available * modesetting: Disable atomic support by default * modesetting: Explicitly #include "mi.h" * xfree86/modes: Bail from xf86RotateRedisplay if pScreen->root is NULL * xwayland: Split up xwl_screen_post_damage into two phases * xwayland: Call glamor_block_handler from xwl_screen_post_damage * xwayland: Add xwl_window_create_frame_callback helper * xwayland: Use single frame callback for Present flips and normal updates * xwayland: Use frame callbacks for Present vblank events * xwayland: Delete all frame_callback_list nodes in xwl_unrealize_window * glamor: Propagate FBO allocation failure for picture to texture upload * glamor: Error out on out-of-memory when allocating PBO for FBO access * glamor: Propagate glamor_prepare_access failures in copy helpers * glamor: Fallback to system memory for RW PBO buffer allocation - supersedes u_fno-common.patch- specfile: reenabled XFree86-VidModeExtension (boo#1164020)- u_fno-common.patch * fix build with gcc's -fno-common option (boo#1160423)- Update to version 1.20.7+0: * xserver 1.20.7 * ospoll: Fix Solaris ports implementation to build on Solaris 11.4 * os-support/solaris: Set IOPL for input thread too * Add xf86OSInputThreadInit call from common layer into os-support layer * Add ddxInputThread call from os layer into ddx layer * os-support/solaris: Drop ExtendedEnabled global variable * glamor: Only use dual blending with GLSL >= 1.30 * modesetting: Check whether RandR was initialized before calling rrGetScrPriv * Xi: return AlreadyGrabbed for key grabs > 255 * xwayland: Do flush GPU work in xwl_present_flush * modesetting: Clear new screen pixmap storage on RandR resize * xfree86/modes: Call xf86RotateRedisplay from xf86CrtcRotate * modesetting: Call glamor_finish from drmmode_crtc_set_mode * modesetting: Use EGL_MESA_query_driver to select DRI driver if possible * glamor: Add a function to get the driver name via EGL_MESA_query_driver- Build XWayland also on s390.- Update to version 1.20.6+0: * xfree86: Test presence of isastream() * present/wnmd: Relax assertion on CRTC on abort_vblank() * os: Don't crash in AttendClient if the client is gone * dix: Call SourceValidate before GetImage * mi: Add a default no-op miSourceValidate * compiler.h: Do not include sys/io.h on ARM with glibc * xfree86: Call ScreenInit for protocol screens before GPU screens * modesetting: - Implement ms_covering_randr_crtc() for ms_present_get_crtc() - Fix ms_covering_crtc() segfault with non-xf86Crtc slave- Update to version 1.20.5+24: * Fix crash on XkbSetMap - Drop unneeded obsinfo file and tweak _service.- Update to version 1.20.5+22: * miext/sync: - Make struct _SyncObject::initialized fully ABI compatible - Fix needless ABI change * xf86: Disable unused crtc functions when a lease is revoked * xwayland: - Handle the case of windows being realized before redirection - Refactor surface creation into a separate function - Separate DamagePtr into separate window data - Do not free a NULL GBM bo - Expand the RANDR screen size limits - Update screen pixmap on output resize - Reset scheduled frames after hiding tablet cursor - Check status in GBM pixmap creation - Avoid a crash on pointer enter with a grab * GLX: - Fix previous context validation in xorgGlxMakeCurrent - Set GlxServerExports::{major,minor}Version - Add a function to change a clients vendor list - Use the sending client for looking up XID's - Add a per-client vendor mapping * xsync: Add resource inside of SyncCreate, export SyncCreate * dri2: Sync i965_pci_ids.h from mesa * Xi: Use current device active grab to deliver touch events if any * Revert "present/scmd: Check that the flip and screen pixmap pitches match" * glamor: Make pixmap exportable from `gbm_bo_from_pixmap()` - Drop patches fixed upstream: * U_xwayland-Separate-DamagePtr-into-separate-window-data.patch * 0001-xsync-Add-resource-inside-of-SyncCreate-export-SyncC.patch * 0002-GLX-Add-a-per-client-vendor-mapping.patch * 0003-GLX-Use-the-sending-client-for-looking-up-XID-s.patch * 0004-GLX-Add-a-function-to-change-a-clients-vendor-list.patch * 0005-GLX-Set-GlxServerExports-major-minor-Version.patch - Switch to gitcheckout via source service, use the stable released branch but set explicit commit used in _service.- reintroduce Xvfb subpackage (boo#1151457)- Add U_xwayland-Separate-DamagePtr-into-separate-window-data.patch and U_xwayland-Allow-passing-a-fd.patch: Needed for gnome 3.34 new and experimental xwayland on demand feature. - Rebase patches with quilt.- added patches required for NVIDIA's PRIME render offload support, which is available since release 435.xx: 0001-xsync-Add-resource-inside-of-SyncCreate-export-SyncC.patch, 0002-GLX-Add-a-per-client-vendor-mapping.patch, 0003-GLX-Use-the-sending-client-for-looking-up-XID-s.patch, 0004-GLX-Add-a-function-to-change-a-clients-vendor-list.patch, 0005-GLX-Set-GlxServerExports-major-minor-Version.patch- move xorg.conf.d snippets from /etc/X11/xorg.conf.d to /usr/share/X11/xorg.conf.d (boo#1139692)- Update to version 1.20.5: Minor bugfix release to fix some input, Xwayland, glamor, and Present issues. Thanks to all who contributed fixes and testing.- Disable LTO (boo#1133294).- Add systemd-rpm-macros BuildRequire for %tmpfiles_*.- xorg-server 1.20.4 * A variety of bugfixes across the board, but primarily in Xwayland. Thanks to all who contributed with testing and fixes!- get rid of meta packages still requiring/recommending obsolete drivers packages (boo#1121525)- provide/obsolete no longer existing xf86-video-ast, xf86-video-cirrus on sle15 (bsc#1120282)- u_xfree86-Do-not-claim-pci-slots-if-fb-slot-is-already.patch * X server does not support mixing fbdev with other drivers, so claiming pci slots when a fb slot is already claimed only leads to quiting with fatal error. (bsc#1119431)- xorg-server 1.20.3 (see changelog below) superseded the following patch we used in sle15 before (bsc#1112020, CVE-2018-14665): - U_Disable-logfile-and-modulepath-when-running-with-ele.patch- U_dix-window-Use-ConfigureWindow-instead-of-MoveWindow.patch * Fix abort triggered by some uses of screensaver. (bsc#1114822)- Update to version 1.20.3 * Disable -logfile and -modulepath when running with elevated privileges (bsc#1112020) * LogFilePrep: add a comment to the unsafe format string. * xfree86: fix readlink call- Update to version 1.20.2: Lots of bugfixes all over the map especially for modesetting, glamor and xwayland!- Update n_xserver-optimus-autoconfig-hack.patch to v5. * Fixes provider auto-configuration with nvidia proprietary driver. (bsc#1103816)- Update to version 1.20.1: This bugfix release fixes several issues in RANDR, Xwayland, glamor, the modesetting driver, and elsewhere. - Packaging changes: + Adapt patch N_Install-Avoid-failure-on-wrapper-installation.patch to work with the new version + Remove patch U_Xext-shm-Refuse-to-work-for-remote-clients.patch + Remove patch U_modesetting-use-drmmode_bo_import-for-rotate_fb.patch + Remove patch u_modesetting-Fix-cirrus-24bpp-breakage.patch + Remove patch U_exa-use-picturematchformat.patch- U_exa-use-picturematchformat.patch * Fix breakage of Xfce (bsc#1102979)- fixed build on s390(x)- u_modesetting-Fix-cirrus-24bpp-breakage.patch * Fix breakage of cirrus 24bpp support on modesetting driver (bsc#1101699)- Remove /var/lib/X11 and its symlink, it is no longer needed and doesn't work with transaction-updates (FATE#325524). - Move README.compiled to another location and use tmpfiles to copy it at runtime.- U_modesetting-use-drmmode_bo_import-for-rotate_fb.patch * fixes rotation in modesetting driver (regression with xorg-server 1.20.0, fdo#106715) * might also fix boo#1099812 ...- U_xkb-Fix-heap-overflow-caused-by-optimized-away-min.patch * Fix heap overflow caused by unexpected optimization, which was possible because of relying on undefined behavior. (boo#1099113)- U_Xext-shm-Refuse-to-work-for-remote-clients.patch * Avoid access to System V shared memory segment on the X server side for clients forwarded via SSH. Also prevent them from hanging while waiting for the reply from the ShmCreateSegment request. (boo#1097227)- Remove n_add-dummy-xf86DisableRandR.patch * After upgrade to 1.20.0 the API officially no longer includes xf86DisableRandR, so there is no need to add it back.- Update to version 1.20.0: New features: + RANDR 1.6, which enables leasing RANDR resources to a client for its exclusive use (e.g. head mounted displays) + Depth 30 support in glamor and the modesetting driver + A meson-based build system, parallel to autotools + Pageflipping support for PRIME output sinks + OutputClass device matching for xorg.conf + Input grab and tablet support in Xwayland - Remove upstream patches: + u_xorg-x11-server-reproducible.patch Solved slightly different + u_os-inputthread-Force-unlock-when-stopping-thread.patch + u_xfree86-add-default-modes-for-16-9-and-16-10.patch + U_xwayland-Don-t-process-cursor-warping-without-an-xwl.patch + U_xwayland-Give-up-cleanly-on-Wayland-socket-errors.patch + U_xwayland-avoid-race-condition-on-new-keymap.patch + U_xwayland-remove-dirty-window-unconditionally-on-unre.patch + U_0001-animcur-Use-fixed-size-screen-private.patch + U_0002-animcur-Return-the-next-interval-directly-from-the-t.patch + U_0003-animcur-Run-the-timer-from-the-device-not-the-screen.patch + U_0004-animcur-Fix-transitions-between-animated-cursors.patch + U_xfree86-Remove-broken-RANDR-disabling-logic-v4.patch + U_glx-Do-not-call-into-Composite-if-it-is-disabled.patch - Adapt patches to work with the new release: + N_zap_warning_xserver.diff + N_fix_fglrx_screendepth_issue.patch + n_xserver-optimus-autoconfig-hack.patch + u_Use-better-fallbacks-to-generate-cookies-if-arc4rand.patch + u_xorg-wrapper-build-Build-position-independent-code.patch- U_glx-Do-not-call-into-Composite-if-it-is-disabled.patch * Fixes crash when GLX is enabled and Composite disabled. (bnc#1079607)- n_add-dummy-xf86DisableRandR.patch * Add dummy xf86DisableRandR to fix linking with drivers that still call it. See explanation inside the patch. (bnc#1089601)- U_xfree86-Remove-broken-RANDR-disabling-logic-v4.patch * Fix crash on initialization when fbdev and modesetting are used together. (bnc#1068961) - u_randr-Do-not-crash-if-slave-screen-does-not-have-pro.patch * Fix crash when using randr when fbdev and modesetting are used together. (bnc#1068961)- Update and re-enable n_xserver-optimus-autoconfig-hack.patch. (bnc#1084411)- U_xwayland-Don-t-process-cursor-warping-without-an-xwl.patch, U_xwayland-Give-up-cleanly-on-Wayland-socket-errors.patch, U_xwayland-avoid-race-condition-on-new-keymap.patch, U_xwayland-remove-dirty-window-unconditionally-on-unre.patch: * Various crash and bug fixes in XWayland server (bgo#791383, bgo#790502).- Add u_xorg-x11-server-reproducible.patch to make build reproducible (boo#1047218)- U_0001-animcur-Use-fixed-size-screen-private.patch, U_0002-animcur-Return-the-next-interval-directly-from-the-t.patch, U_0003-animcur-Run-the-timer-from-the-device-not-the-screen.patch, U_0004-animcur-Fix-transitions-between-animated-cursors.patch * There is a bug in version 1.19 of the X.org X server that can cause an infinite recursion in the animated cursor code, which has been fixed by these patches (boo#1080312) - supersedes u_cursors-animation.patch (boo#1020061)- Added u_xfree86-add-default-modes-for-16-9-and-16-10.patch (boo#1075249) Improve user experience for users with 16:9 or 16:10 screens- Update to version 1.19.6: Another collection of fixes from master. There will likely be at east one more 1.19.x release in 2018.- Depend on pkgconfig's gl, egl and gbm instead of Mesa-devel. * Those dependencies are what xorg-x11-server really needs. Mesa-devel is too general and is a bottleneck in distribution build. (bnc#1071297)- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- u_os-inputthread-Force-unlock-when-stopping-thread.patch * Prevent dead lock if terminating while on inactive VT. (bnc#1062977)- Update to version 1.19.5: One regression fix since 1.19.4, and fixes for CVE-2017-12176 through CVE-2017-12187.- Update to version 1.19.4: A collection of stability fixes from the development branch, including two minor CVEs (CVE-2017-13721, CVE-2017-13723). - Remove upstream patches: + U_Xi-Do-not-try-to-swap-GenericEvent.patch + U_Xi-Verify-all-events-in-ProcXSendExtensionEvent.patch + U_Xi-Zero-target-buffer-in-SProcXSendExtensionEvent.patch + U_dix-Disallow-GenericEvent-in-SendEvent-request.patch - Adapt patches to work with the new release: + u_Use-better-fallbacks-to-generate-cookies-if-arc4rand.patch- u_cursors-animation.patch fix cursors animation (boo#1020061)- disable Xwayland for s390x again; it was wrong to enable it; there is no Wayland on s390x and will most likely never exist, since there is no gfx card on such systems and no gfx emulation either (bsc#1047173)- u_Use-better-fallbacks-to-generate-cookies-if-arc4rand.patch If arc4random_buf() is not available for generating cookies: * use getentropy(), if available (which was only recently added to glibc) * use getrandom() via syscall(), if available (there was no glibc wrapper for this syscall for a long time) * if all else fails, directly read from /dev/urandom as before, but employ O_CLOEXEC, do an OsAbort() in case the random data couldn't be read to avoid unsecure situations. Don't know if that's too hard a measure but it shouldn't actually occur except on maximum number of FDs reached (bsc#1025084)- U_Xi-Do-not-try-to-swap-GenericEvent.patch, U_Xi-Verify-all-events-in-ProcXSendExtensionEvent.patch, U_Xi-Zero-target-buffer-in-SProcXSendExtensionEvent.patch, U_dix-Disallow-GenericEvent-in-SendEvent-request.patch * Fix security issues in event handling. (bnc#1035283, CVE-2017-10971, CVE-2017-10972)- enable Xwayland also for s390x (bsc#1047173)- includes everything needed for additional sle issue entries: CVE-2017-2624, bnc#1025029, bnc#1025084, bnc#1025035- update build requirements- modesetting.ids: no longer hardcode Intel's Skylake, Broxton, and Kabylake IDs to modesetting driver; xf86-video-intel is no longer installed by default on these, so it will fallback to modesetting driver anyway; still you now can easily switch back to intel driver by installing xf86-video-intel package (boo#1042873)- Update to version 1.19.3: A couple more minor fixes, most notably a revert of a page-flipping change that regressed some drivers. - Remove upstreamd patches: + u_busfault_sigaction-Only-initialize-pointer-when-matched.patch- Update to version 1.19.2: A collection of stability fixes here across glamor, Xwayland, input, and Prime support. Also a security fix for CVE-2017-2624, a timing attack which can brute-force MIT-MAGIC-COOKIE authentication. - Remove upstream patches: + U_xfree86-Take-the-input-lock-for-xf86RecolorCursor.patch + U_xfree86-Take-the-input-lock-for-xf86ScreenCheckHWCursor.patch + U_xfree86-Take-the-input-lock-for-xf86TransparentCursor.patch- U_xfree86-Take-the-input-lock-for-xf86ScreenCheckHWCursor.patch * Add the missing input_lock() around the call into the driver's UseHWCursor() callback (bnc #1023845). - U_xfree86-Take-the-input-lock-for-xf86TransparentCursor.patch * The new input lock is missing for the xf86TransparentCursor() entry point (bnc #1023845).- U_xfree86-Take-the-input-lock-for-xf86RecolorCursor.patch * fixes random crashes in X in multihead mode if one of the monitors is vertically oriented (bnc #1023845)- N_driver-autoconfig.diff: No longer try to load "amdgpu" DDX by default for all GPUs with ATI vendor ID; this is now handled instead by an "OutputClass" section via kernel driver match, which has been added as config file to xf86-video-amdgpu driver package (bnc#1023385)- N_driver-autoconfig.diff: FGLRX does not support new x-server. This change fixes bad behavior(with empty config) when radeon ddx loads with amdgpu kernel module on SI and CIK cards, and x-server cannot start. Radeon ddx with radeon kernel module loads without any problem.- Update to version 1.19.1: First stable 1.19 release, including a few regression fixes.- Replace pkgconfig(libsystemd-*) with pkgconfig(libsystemd) Nowadays pkgconfig(libsystemd) replaces all libsystemd-* libs, which are obsolete.- Update to final 1.19.0- Exchange xorg-x11-fonts-core Requires for Recommends. The corefonts and cursors are not strickly required as long as one have a substitute such as Adwaita installed.- Update to version 1.18.99.901: - Remove upstream pachtes: + U_glamor-Remove-the-FBO-cache.patch + U_kdrive-fix-up-NewInputDeviceRequest-implementation.patch + U_kdrive-set-evdev-driver-for-input-devices-automatica.patch + U_ephyr-don-t-load-ephyr-input-driver-if-seat-option-i.patch + U_kdrive-don-t-let-evdev-driver-overwrite-existing-dev.patch + U_ephyr-ignore-Xorg-multiseat-command-line-options.patch + U_ephyr-enable-option-sw-cursor-by-default-in-multi-se.patch + U_kdrive-introduce-input-hot-plugging-support-for-udev.patch + U_kdrive-add-options-to-set-default-XKB-properties.patch + U_config-udev-distinguish-between-real-keyboards-and-o.patch - Disable u_os-connections-Check-for-stale-FDs.patch (not applicable anymore) - Adapt patches to work with the new release: + n_xserver-optimus-autoconfig-hack.patch (disabled for now as it causes problems) - Remove X.org stack version prefix. We are already atleast at verion 7.7. Plus we are updating individual components anyway. So the stack version is misleading.- Update to version 1.18.4: Another pile of backports from the devel branch, primarily in glamor, xwayland, and the modesetting driver. - Remove included patches: + u_x86emu-include-order.patch + U_modesetting-set-driverPrivate-to-NULL-after-closing-fd.patch - Update patches to reflect upstream changes: + U_glamor-Remove-the-FBO-cache.patch- U_glamor-Remove-the-FBO-cache.patch Fixes (bsc#983743) by not keeping >1 GB of VRAM busy.- U_modesetting-set-driverPrivate-to-NULL-after-closing-fd.patch: modesetting: Avoid crash in FreeRec() by NULLing a pointer which may still be used (boo#981268).- Replace N_Force-swcursor-for-KMS-drivers-without-hw-cursor-sup.patch by N_Disable-HW-Cursor-for-cirrus-and-mgag200-kernel-modules.patch Only disable HW cursor for cirrus and mgag200. This should fix a regression introduced by using modesetting for Intel gen9+ (boo#980124).- modesetting.ids: Add file for PCI IDs of ASICs which the modesetting rather than the native driver should be used for. This includes all Intel Gen9+ hardware (boo#978954).- removed u_exa-only-draw-valid-trapezoids.patch; no longer needed since pixman 0.32.0- removed no longer needed patch u_ad-hoc-fix-for-mmap-s-truncated-offset-parameter-on-.patch, see https://lists.x.org/archives/xorg-devel/2016-April/049493.html for upstream discussion; obsoleted by upstream patch https://cgit.freedesktop.org/xorg/xserver/commit/?id=4962c8c08842d9d3ca66d254b1ce4cacc4fb3756, which is already in xorg-server 1.18.3- Add permission verification for SUID wrapper - Disable SUID wrapper per default until reviewed- n_Install-Avoid-failure-on-wrapper-installation.patch: rename to: N_Install-Avoid-failure-on-wrapper-installation.patch - u_xorg-wrapper-Drop-supplemental-group-IDs.patch: Drop supplementary group privileges. - u_xorg-wrapper-build-Build-position-independent-code.patch: Build position independent.- n_Install-Avoid-failure-on-wrapper-installation.patch: Fix up build for wrapper. - Place SUID wrapper into a separate package: xorg-x11-server-wrapper- Set configure option --enable-suid-wrapper for TW: This way, the SUID wrapper is built which allows to run the Xserver as root even though the the DM instance runs as user. This allows to support drivers which require direct HW access.- Update to version 1.18.3: A few fixes relative to 1.18.2, including one fairly important performance fix to the Present extension. - Remove U_present-Only-requeue-for-next-MSC-after-flip-failure.patch The patch is included in this release.- Add patch U_present-Only-requeue-for-next-MSC-after-flip-failure.patch Fix a hang while using the present extension Bugzilla: https://bugs.freedesktop.org/show_bug.cgi?id=94515 https://bugs.freedesktop.org/show_bug.cgi?id=94596- Add automake, autoconf, libtool, c_compiler, pkgconfig(xorg-macros), pkgconfig(libudev), pkgconfig(libevdev), pkgconfig(mtdev) to Requires: of the SDK. This simplifies the build of Xserver modules.- Add support for a driver specific PCI IDs files supplementing what's in xf86VideoPtrToDriverList(). PCI ID lists may be held in /etc/X11/xorg_pci_ids (boo#972126).- Update version to 1.18.2: A big pile of updates in this one. Highlights include: * glamor is updated to use OpenGL core profiles if available, which should improve memory usage and performance on modern hardware, and got some other performance improvements for rpi and other GLES platforms * DRI2, DRI3, and Present all received correctness fixes for hangs, crashes, and other weirdness * Xwayland server has been updated to support the Xv and the xf86vidmode extensions for better compatibility, and fixed some bugs with output hotplug and pointer updates * Xwin saw improvements to window and clipboard management, and a few new keyboard layouts - Remove upstreamed patches: + U_kdrive-evdev-update-keyboard-LEDs-22302.patch- Backport upstream patches for Xephyr input hot-plugging / single-GPU multi-seat support: * U_kdrive-fix-up-NewInputDeviceRequest-implementation.patch * U_kdrive-set-evdev-driver-for-input-devices-automatica.patch * U_ephyr-don-t-load-ephyr-input-driver-if-seat-option-i.patch * U_kdrive-don-t-let-evdev-driver-overwrite-existing-dev.patch * U_ephyr-ignore-Xorg-multiseat-command-line-options.patch * U_ephyr-enable-option-sw-cursor-by-default-in-multi-se.patch * U_kdrive-introduce-input-hot-plugging-support-for-udev.patch * U_kdrive-add-options-to-set-default-XKB-properties.patch * U_kdrive-evdev-update-keyboard-LEDs-22302.patch * U_config-udev-distinguish-between-real-keyboards-and-o.patch- u_os-connections-Check-for-stale-FDs.patch Ignore file descriptor if socket or devices dies. This prevents the Xserver to loop at 100% when dbus dies (boo#954433).- Add 50-extensions.conf Disable the DGA extension by default (boo#947695).- Replaced u_confine_to_shape.diff by u_01-Improved-ConfineToShape.patch and u_02-DIX-ConfineTo-Don-t-bother-about-the-bounding-box-when-grabbing-a-shaped-window.patch.- u_pci-primary-Fix-up-primary-PCI-device-detection-for-the-platfrom-bus.patch Fix up primary device detection for the platform bus to fix the Xserver on older iMacs (boo#835975).- Update to version 1.18.1: First release in the 1.18 stable branch. Major themes are bugfixes in glamor, the modesetting driver, and the Present extension. Xwayland users may want to apply the following pair of patches in addition to this release: https://patchwork.freedesktop.org/patch/72945/raw/ https://patchwork.freedesktop.org/patch/72951/raw/ which combined fix an input issue when hotplugging monitors. Both are likely to be included in a future release unless testing discovers further problems. - Remove upstreamed patches: + ux_xserver_xvfb-randr.patch + U_systemd-logind-do-not-rely-on-directed-signals.patch + U_kdrive-UnregisterFd-Fix-off-by-one.patch + U_modesetting-should-not-reference-gbm-when-it-s-not-d.patch- u_Panning-Set-panning-state-in-xf86RandR12ScreenSetSize.patch Fix panning when configured in xorg.conf* (boo#771521).- Handle source-file-list in build not prep - N_xorg-x11-server-rpmmacros.patch: Delete: Process xorg-x11-server.macros in install- U_modesetting-should-not-reference-gbm-when-it-s-not-d.patch: fix build when gbm is not defined.- u_busfault_sigaction-Only-initialize-pointer-when-matched.patch Only initialize pointer when matched (boo#961439). - u_kdrive-UnregisterFd-Fix-off-by-one.patch -> U_kdrive-UnregisterFd-Fix-off-by-one.patch- Add test for defined macro %build_xwayland This can be used to enable the build of Xwayland and the package xorg-x11-server-wayland using a macro in projconf (boo#960487).- Split out Xwayland: * Build a package xorg-x11-server-wayland * Limit build to Factory (boo#960487).- Enable XWayland on Leap also (boo#960487)- u_kdrive-UnregisterFd-Fix-off-by-one.patch * Copy open file table correctly by avoiding an off-by-one error (boo#867483).- Update to version 1.18.0 - refreshed N_zap_warning_xserver.diff, N_Force-swcursor-for-KMS-drivers-without-hw-cursor-sup.patch - supersedes u_fbdevhw.diff, U_linux-Add-linux_parse_vt_settings-and-linux_get_keep.patch, U_linux-Add-a-may_fail-paramter-to-linux_parse_vt_sett.patch, U_systemd-logind-Only-use-systemd-logind-integration-t.patch- Update to version 1.17.4: Minor brown-bag release. The important fix here is Martin's clientsWritable change which fixes a crash when built against xproto 7.0.28. - supersedes u_0001-os-make-sure-the-clientsWritable-fd_set-is-initializ.patch- Update to version 1.17.3: Various bugfixes across the board.  The most visible changes include fixing GLX extension setup under Xwayland and other non-Xorg servers (enabling core contexts in more scenarios), and various stability fixes to glamor and the Present extension. - supersededs the following patches: * u_randr_allow_rrselectinput_for_providerchange_and_resourcechange_events.patch * u_CloseConsole-Don-t-report-FatalError-when-shutting-down.patch - removed evdev xorg.conf.d snippet since it's meanwhile shipped with evdev driver itself (since version 2.10.0)- u_vesa-Add-VBEDPMSGetCapabilities-VBEDPMSGet.patch Add VBEDPMSGetCapabilities() and VBEDPMSGet() functions (bsc#947356, boo#947493).- Backport a few upstream fixes for systemd/VT handling (boo#939838): U_linux-Add-linux_parse_vt_settings-and-linux_get_keep.patch U_linux-Add-a-may_fail-paramter-to-linux_parse_vt_sett.patch U_systemd-logind-Only-use-systemd-logind-integration-t.patch U_systemd-logind-do-not-rely-on-directed-signals.patch- Improve conditional enablement of XWayland.- Add patch u_0001-os-make-sure-the-clientsWritable-fd_set-is-initializ.patch Prevent segmentation faults with more than 256 clients (introduced by xproto 7.0.28 increasing the max client count 256 -> 512) Fdo Bug: https://bugs.freedesktop.org/show_bug.cgi?id=91316- Update to version 1.17.2: Pick up a pile of fixes from master. Notable highlights: + Fix for CVE-2015-3164 in Xwayland + Fix int10 setup for vesa + Fix regression in server-interpreted auth + Fix fb setup on big-endian CPUs + Build fix for for gcc5 - Dropped patches: + Patch110: u_connection-avoid-crash-when-CloseWellKnownConnections-gets-called-twice.patch + Patch113: u_symbols-Fix-sdksyms.sh-to-cope-with-gcc5.patch + Patch116: U_os-XDMCP-options-like-query-etc-should-imply-listen.patch + Patch118: U_int10-Fix-error-check-for-pci_device_map_legacy.patch + Patch119: U_xwayland-enable-access-control-on-open-socket.patch + Patch120: U_os-support-new-implicit-local-user-access-mode.patch + Patch121: U_xwayland-default-to-local-user-if-no-xauth-file-given.patch + Patch2000: U_systemd-logind-filter-out-non-signal-messages-from.patch + Patch2001: U_systemd-logind-dont-second-guess-D-Bus-default-tim.patch - Changed patches to work with the new version: + Patch114: u_ad-hoc-fix-for-mmap-s-truncated-offset-parameter-on-.patch- U_os-support-new-implicit-local-user-access-mode.patch, U_xwayland-default-to-local-user-if-no-xauth-file-given.patch, U_xwayland-enable-access-control-on-open-socket.patch * Prevent unauthorized local access. (bnc#934102, CVE-2015-3164)- Fix GNOME X Session for some hybrid graphics (rh#1209347): + add U_systemd-logind-filter-out-non-signal-messages-from.patch + add U_systemd-logind-dont-second-guess-D-Bus-default-tim.patch- Fix build of s390/s390x (bnc#933503)- U_int10-Fix-error-check-for-pci_device_map_legacy.patch * int10: Fix error check for pci_device_map_legacy pci_device_map_legacy returns 0 on success (bsc#932319).- Add xorg-x11-server-byte-order.patch to correctly set X_BYTE_ORDER when compiling tigervnc on ppc64 architecture. Related to bnc#926201- U_os-XDMCP-options-like-query-etc-should-imply-listen.patch * Enable listening on tcp when using -query. (bnc#924914)- Enable systemd-logind integration support: + Add pkgconfig(libsystemd-logind) and pkgconfig(dbus-1) BuildRequires. + Pass --enable-systemd-logind to configure.- u_ad-hoc-fix-for-mmap-s-truncated-offset-parameter-on-.patch * ad hoc fix for mmap's truncated offset parameter on 32bit (bnc#917385) - N_Force-swcursor-for-KMS-drivers-without-hw-cursor-sup.patch * hwcursor still considered broken in cirrus KMS ((bnc#864141, bnc#866152)- Update to version 1.17.1: Fixes for CVE 2015-0255. + xkb: Don't swap XkbSetGeometry data in the input buffer + xkb: Check strings length against request size- u_symbols-Fix-sdksyms.sh-to-cope-with-gcc5.patch Fix sdksyms.sh to work with gcc5 (bnc#916580).- Update to version 1.17.0: + Continued work to strip out stale code and clean up the server. Thousands of lines of unnecessary code have disappeared yet again. + The modesetting driver has been merged into the server code base, simplifying ongoing maintenance by coupling it to the X server ABI/API release schedule. This now includes DRI2 support (so that GLX works correctly) along with Glamor support (which handles DRI3). + Lots of Glamor improvements, including a rewrite of the core protocol rendering functions. - Remove upstream patches: + Patch130: U_BellProc-Send-bell-event-on-core-protocol-bell-when-requested.patch + Patch131: U_fb-Fix-invalid-bpp-for-24bit-depth-window.patch + Patch200: U_kdrive_extend_screen_option_syntax.patch + Patch201: U_ephyr_enable_screen_window_placement.patch + Patch202: U_ephyr_add_output_option_support.patch- Add xorg-x11-server-source package that contains patched xserver sources used to build xorg-x11-Xvnc.- Update to version 1.16.2 - Fix present_pixmap when using present_notify_msc - Fix present_notify to return right away when querying current or past msc.Xext/shm: Detach SHM segment after Pixmap is released - xkb: ignore floating slave devices when updating from master (#81885) - fb: Fix invalid bpp for 24bit depth window - supersedes U_fb-Fix-invalid-bpp-for-24bit-depth-window.patch- fix bashism in post script- XServer looks for dri.pc during configure. dri.pc is currently provided by a Mesa devel package, which is pulled in by other requirements, but it might be better to explicitly require dri.pc.xorg-x11-Xvfbh01-ch3c 172949746521.1.11-150600.5.3.121.1.11-150600.5.3.1Xvfb/usr/bin/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:36103/SUSE_SLE-15-SP6_Update/956149195c107d60d98804b3a2d233f8-xorg-x11-server.SUSE_SLE-15-SP6_Updatedrpmxz5x86_64-suse-linuxELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, BuildID[sha1]=4bbb4dc5d47480eefe31612c56bf08ae0d2e3f22, for GNU/Linux 3.2.0, strippedRRRRRR RRRRRRR R RRRRR RR RRRRRRRRRYgwIrExorg-x11-fonts-coreutf-8d144cc739e8a4960601d79b51faca132e7f19406e8cdc24c78d573dd392a1579?7zXZ !t/]"k%#4ղS@џ="9qN.긝ޱD0hft(= r@*)Jrw #Q`\1kl~Όb>/^?H'>o&KPìp7JalVB$陷 :U+%^8jss6dw|dFY3sl 6$r\ njp#+@pqA%njH~_7nD@.T{!iO(?'cm%iSsxC\¯ sf`[`´{  4F GT. Q7#^{ܮ(ucVkξ$~I )ulG7)N"SP9g[IbRJkfgXO߃ =u9P'fm:UWU9rn0㢉U|}$W1#lPyf^$t5 >0WUgQH\nO}>6fXM@dz'U-}-&v21|(z7233O2}ה1 j!UH$E5Oexz0 iAkl^,پ$Р\0[^с1س)$@ȥpw'JhNy@ikS<0W_,L=dq+@i-\3x?o{zgC-yЂe+&/]RMKayڬ^ȋ+Sp(eOt [{ŒUТFcdžA65QMk˶ ȕg_ BQ5NOpePJ;')gJAp59,N<9eB^6'XݥQu0_vCӵj2)B+G2 WWV#TNJ2 eA +T+fӗJ$&8F*p Jְal)]/W6l_"kjɹ 2P^(*0,d[AwTO]IA2alP:@Ŷ7,=N|Ţhb|o@3fbo-vth'<ױߋ_S)dÊ;BNGWY0G=B*-;bsv6m;?gT-^̤TISPH~wZٍ q״{18 gICԣ.r(H/ &֡*f]J BXAGooz傀v 7:EU>*=Ne̷1}͇*Я c)_`qĝ׬C,RCzEQRZv V.O*:3g o]Fw914L^w`pO3Qg/',2)gaedd; g{ʨM^d>Ysy^ZŤcu{E^ -Tp3;OX`h丟+(ji!{LW THF$ГL(ˋ4= oӖg'Q"hU244HL%+wiW޳C⍡@1Ӂ9꒠v D]nljK'.6P0k;|]0aUkP4={x#'RɞϘ'$#"rxLsq/؉7?J֒5 < T2)}g#{cLMх^1s-QʂOg5–WQ\JË:hO v&ƾ׌㉻8-HU`.I3F-`eÓ6j R%eQO-8D6ỶsT]Bɣ#DF%v; t1d M *wYtѐ|P4(L؃/SUÖZn0kWqSEpF> ',}a׮3Ҿm0YW Gnst%\y%\p1So Tf'1Wt@WaC-]론پFvyA5+b΄~9DI|Mc%8]][pME!\n?m7rQj]/2? XB[NLVSC~lQ_$3L"Zqpq]oD<4Jiǔ|l#XT0gA<yX@غdp:lk.h,C0廢g?و[g (!~1sD^Bk3+N:TN-j6'vׇh3(,Mc0hPy$hϱCf]Xq'7%J <FCJĚ>RpӽbIg}? , P~7Y ^ĺ jFP./u)k`[G}-72k;Sm746HyFNٙ|)(b ɝQ.IJߓY<+S'/Aǿ*.ŅUg;1`.|T@!dIM9815N5X(@Dz5]+w>pz*π[= |buעП(アKGF@zMCFBJElJl- QN# ` 6ܲm[aGbつ5 |#DHI%FC@cګWbpШR޼IJ%iVޟ9_0[g$ևex)rgl23iy(Wl춆1P_;? z\V!U058ǸOX1xM:G%Mxt]4z.+/7g`N0D N0> wqˆ@owTcl|j}nu#8GkySuBq^-blQq.(&u27ހ`y4LzՌbtsy&_W+"epTXE&ɀXUuVӆRls+G$"UO3V'$YelOnx](} S?:VB6 U`sɮ;Z}*VYy>*Z~wG*wJ4diѸ*&ᰚ2jHOgrX:ؖ#LN7zCŏeն.Н/<]2}b~WyG;U )6WQ:؀ƺDg>[:R54 _I z,k %ñ)ňYy2|'7WC\2|Eh="c Y"67ʘaE\F;aӑD@adBy=vII9$qw50toJ,;/@,ddE LT;Z ^$(qQt瞬_ $6)HZ@du͍t``|odQ!'쮥 cnv^T#VA_Op= +{R-:ӚZh@M1pE/?1}»+z/ >x@^jWBVoK<н~nx&,Ut7x7A>&¼& )o,Pgnxב D(f5ȯY玐6Ow oZ7ir55/A},HvI G3iPAohҵJG\ٝY63#e;u/4 3QZ/S;ĔrOүy󇻆]2BW76~Df;j+OdG4_,PWf3sIsk̄;ޑ$T([LZ;|ʍ ѴDg~Mϻ߆aԞz/60>ܓ{!CXR;AekVٛ4xi2 >3 UW=A>ۋU5+"?]mA[Y˗T8(T4j#`'k+_yW۾P_=m90J6B TʼiP0C4!S:-Tq#U ڀQ} '\eˁexKjW r.֧]Y ĥ)=Xj[iZnLh6yH 6މ2`_am81?-@ ,,g9k'-3:HpUi~PfǨ/[ĥ,9:Dѣ+Hc?qF}|ȁ;-bM'.{e ^O,X/鬁 ^ERcm,BXߌsun%sOm {DFI`f9jz V &O`^c'e{! 3]Ţ_ΑxUh}3db9'#$?U$HzhG6&+0ɍg8Pml_BclTH,d~ o@w4FaS jT}e̗LqvxbOu˳*溽nd|Ic̿Ki0B,9.U|Ul7,.tt WHIZigkTEVbݍqa PQ*T|~leċ0nV;~BJSK c#~:R77`.M 21I=dY(R_UyadF_B棶25}][ךVf銃~z•pgd~ l9{XlmlgF'I}0=*OPPmczߴJpǮk1\ rx\("g3Қ6E<PG8[g]@Nuk<\|zJE|;I09fI`xZuF)kK"qcϟ7dH([a]8wN;.t.;O"vl s5rdn V', B^ 94E~ףrZ"&ͪT0qXT:>Z@#)u1!4[.tJڮt#U&WK Xv' ez.m-W*KQ'zܠnsln01N$*ݬJYl.un7 wU>FI_Ю~)|j^dD$BЁk`oB#qKzʔyɹ>_usɷ7 #7+;~`apmwT]!=<*Q$˽YT]aDj+qsl2>7Ka`*zM~_Q6!rWۿP璛A| 7 E0)l߬}-q;F_E;y2o`ߎp٫w.%-|?~qʌ_LbwuBVSTgW7y:y}ANJdi'+_)[ 4ˈ4^;X^PFЭ;[,`$?H:%j5=s- 9J93>Hz;}J#f`2UN=w2y.}* v_=wExX ,;ZQ4!R[F}bV:( _*:P6FS@ Ϳ)g_UZ8o?>6æjDL59Mj, )?*"@mFZ)/29L?WCt dKf%ǹZ?5(# 3h#gVVЉ ZVE $B`MAUiZ2׾Xp1]ڻB\8e^2f0Ei[ 0#QMܸQG'rNWeڡ+{6A>2og!VhlK4f.8I _7Z+a3^ ޗϖǒP|MNjѯb]i4@*@Y:Uu(|n|!  d@U@}Fd l4mdO C0zA[CU*7yౣ6c<\X;ݢ>Tol(d{[NEo5‘"bG^|W#( hSos*, 9Ն/oB:[M h\6)pUw"a!MYlKW7Hz+ SM:27} `}H`QF ߏ "z⫭߇s.y2d@RG*}|9Ȳ~F)޼D>}~z"+ՃCXl 5ek^P P] iH65^;;lS}B&2(հ`Azä0ИKq”i4A`Y^pٵN,/cTMPhyP&kT92c5p _]x\8I,H@ǥ{f|INpR L Bܖ/#Fv2B^SXsJ/<6ڲ)I(BTxG䮸Y4:}D2v~(Vl DeFXCr A:)Lh2zWݨWiq]H{}Qt y^!G{`0 YaHAkuV'Nܥd{ۮa6r6esjb:'/hPs9"C/G3ddx˟s "&A2 {?zh_$+:x;X<~|oƁpٗ7s*u M""Vchkzqg?=Ê~>2ܷyV4o?AJ9@"F:(eu"!,uBr =?$?;K0-6t/u1G)Ʈ{6ܸ*:w9M:bz5|A~ TɑRt!}c/M8)> {I%Z2@CpiQ J]fd@RIrv8N!B1!Z{ʔ~D}޽L#޺IO8`~lv7L,Y),*Em Ֆ/OT}[5钨LjQe?MaG05*Y8$#[ˡVQ/r#%Tv~ꞎ,t5فs U/͚#`.L?qCb/FרD(E#!h #YP)g^/]q0iA ҮCz 4i-rO_KK.[;6YXFЬ0n:ŸUf|Y[]FPWjZ!=l\A?5u,69MMݨUP,}_aصS;?La RV-G=RT^1ǼPY&ai v;G8QD5J B| |Xb&3PR ŠOU>\8a G2mBըAXy"D~y3s^dٙUsgxpYTcOьwUE(xkYR[{q@O?/)ݮ3i肝Yh9 {YT6WRݺ BWze.5:*lBi#_-ϔa /gd gx7Wr } JđeC(RB[8&)4!ˆ06Ijo57ky2ʒa{5k1=/+l\p:=8-QNR(B~;EaNS=+DgFeܟ3O*D,<{/b/$Jc~I&j 6]y|pszXT"=yu8}ljtϖMHv5J"vNjٝmgƌVK[]1K|AOR(b;4X{Dj1ʌE-(/۬="JP$]a8b㔧H!30βi+QCG/zQ4qmBo]I p;tPn}?IgD{:m*MSi9/3dK`5z!MFt-ɶzUo _P]m]}iY`0©j[OR-YA]OfF=E`蘪M[r8Qy^BR+Srv[j 4'D/YK%4QMC{rARק)el\vԑތ?Dn*Z_OZNJ~TqSfI5{v T R[05nj)s{ ULiF-Yp .@&]xscYLm6_ Fg+U靊$G 87 $u8@56y`VV lFEHʻ 7l}=2sjiaWd-&$̽R;I ,}*/ pމ6+صU<6?'GAn/~|/(շi9;ǕwCiA,%פHm戫X4NNO(v}$j7IWD4ДH*aFطnMV@[:iߍw #8~qM\Tv 8Sr#3_j^].q#5 'sՉ薾{9{h9,Aڠĵf5hgi;CJ0 R!#Alqݼ@x*(^?,])kWǢ}qg Hdٵ#'?}+4KYn>4J/X8<Փ.Qq*Z-$:O)kLJZB)+S(3 yqRRQS>A/sK(#-G2 2wvei׈9^n2=QW5C/D@‰= +݇fij8[UX}<L-Q8cfaנj98By)P.k%0Jk>S~Irʂ6WJ<2q-X-îH1L[1_ָ=|8.Nՠ+ o!ɞ)g]T$>#]ϲ9B#[qIo8SwdhL=in'yWx &fk(P 3,E19|lVwP[K4GH$a6] Pn<_ِCQaegveKdDվRL&7hfgCaA=[qة}3q:&qH]Ow¡jpW;K;2vsq`ANvkMއӚ3JG3ƸXJ9l\#K /hL(Zb8Щ595` zm3f~gBd.[&g׬M{^={u!w樜f4Z?g=naP XKw> 7-vi2FKUiǐAE\m]9"ЎJRn :>Y\P R2cJC߿M*:(ցEeNU&u4}2T >_F/g^Q@6 >tͥ;!Zc_ՎPn(g,ǀj(A[?4vǬLj2|.LzD_,{ ,7e9o(Q| 4h˟FS>4$w@r7i?Bɸ:lkޏG &r /÷}5@CҠ Elp _E{ l >br,hɨ%1}n`)G?u7=:젿hRq]-kz q`SVZ1%@NxCx];AMC۹dO$mÊV= TwQ q: B- W}a@θ #}:f;:Nü 1k@_ c\C2L-v+4D;g<5Mwޕ Tb_ 7ٿeiZisPEW@P"{Uo>qm,Y-ޣԯè&T_ZlХRAcZuƮ.#_ >{"E^n{C}d5V>W[?oщ}Ҍ9Mc@˼dRi!R ǵ2gxa!Ym%BjfX:܎rl:p @Yl+K A\$b>X٣|O%րw=Pf4@zxj59y0b$X3p=ǶAp׻  py6;J:Q_Ml@*\ظJpv|W\@pD%O@D<1M!m}a~ }u2h"&[} -Eƣ b-@=my/"[IӤ^0,M%/ۇ[B HKmxY˱2/KEedMˠq*ގRF4>3^&1CI9R񠗣)tr(aCdBsga#oy6u_OAqjKI 0 E{U*'szw[iļ9om' t*QKт_lhfv?<$ 5Vdv顴Lޒ<;GGq+GV{O2#ٻ,6,LbWKj$8D[_!6ϙՁ8S nX5Ym@Nhb'-9 dkUO9>TY爍(VwwPOmÈyEnTv۳Bz7T8t6 Q[f"6dƝ"IeDe`owq ڃvoЄ:.}Hp"ڎJ.fVOĄ[%?T}425BȠ ȍNBE̒Bq2x*HV ^eHQQYT$jtxW@Y~\]QKpQd[zJI|67/R rɌc)@yPu g#TI[Jw:hTolRotDM` j1##(ld^})@'tab& H:Z]PTD׭}i6f vneܑCZ%hp?+ÝlP59f:![,0xţ /23ifߔ|ߚg3ÑB3qx9lDBxs܋qOυ-N*izrLJ]մRB,R 8`pskغ@45 RS痛C⃆-J2doGpitSÝǪZ#JkCK )#<00@I_Ҭ@W3΁Q1s/M<7C-Bo4eaRuWTo+[ &3Nܳ W^Q 7^\IxL؆V i=ҁ %uMul3"0YL(\!Fe] qa`:10e28cN/12b?E3QJnZ`+ `3Bwٙ} whd>à~u+_< k$aX?]?D& UB_j.gISOlm42m\䲔ȳU!jڂ9ߦ"ǎ@_)h6yƂῪYW}l=9g)6X7Կ> -nB^ywlO\ '@&}ԁ.%F]0zqBbzlt}K!GoX 0vʫ1Ch-;,]n,{\5h-f !]mN5Me8.`AiΡowIi wR暞ZW0#'xpj|yؗ# wiI)̙a ~.d!2Y&φd =(H՟>$QxS*O-p;5\ J? jcx>in}LR-*(FxQ["$QpHGc' '*zLNglL9tN=bR27?b<Wl~EdނOʉZE.&qNw%C/+qhHVP3ԜO,!B@+VWD;.|z퀧UFw~й\P焍N8bZX#.u37aWsX,aM,17 ap"gxb`4ȍpRQVzy9+qp+l`/ӕNj͋U.~#֑,m0Jfȹd im3 R.3 v}%_ɠc̶U^'7 U &z=:߳1DS|J2! {v 1$DA> K>lWTr;\Q ž+a랧[?X|1J?E#OmDRj5Sԕ!u|ќpdhc;$A[4ix["rYG$Az @yC+j>12 *C[3z6@N,~;E.DMVX>Ç{PkoU@ϊ.51xEk;׼7X[SI%r9%J?M͟~[2dX *Z6Qo}/Y+{{ݩAEUq-ؗCsٳ3ɵUtER^z4vMhް\&*tr&&ͫ9̈́dwN1-ٰd+DR sw~DAWiK}-{YM" 8W9TH\YX(tb둸~Ty>6A~DN1̟rby>w$ I;LV[T݆ F+C/dqsEѪ/n3=L^-**{,m`>#y{tѭVQ0XB߱T<8cd~d6{>*-ɼ5BϦg~QHTKc9mO,i{;}6E7v=Ӽms+5,0f)sR}T#\Ϻ ,ټSS~U MgQqZ! !eSrXW,(ev2 #}Bb jݜWc4.VCyެٯÚ0=_HޱOSž)1:B;Ӆ|5sV==' Zq˩#{P2Q! u͘LWc=jи֞fǟPbi~d4D? sHlƭ gC,4)ĶظLBVyjߜKe_=y|AJ\H$K%h\޻gr"G3慃nk|;_5wvI,i}2 =ţ2RU[ jdAh|M 6K՗'oE-W֘}Az֫8"aHkt|x YS_^9+ g+c496q.@.a$Awj҄6ȃgR\ԥ70 /egdV'ՖsORh`Y|M_Sgy rŞ(DlGz%:ꬳ=rý`A}՞:h" dty{sOCAȾ-f`GܾxD y,> Ļ_j$suVxX^P#o?yo7_Eoo/փLi1E2XX#kkYɶNYnMvYuVȽ` ' .rbxz$JUM檐M/A.=lid t gfo TozC>V5 It54nrfs1.=c+& :6$".o;^T9V9}'r"RuQ:P_}i|tr$x40~8Džc/%T vzT3(YC/A.R1LP ), H^*CvoF@ѯޙ6DjXˮ%S)G5 Ң*h!- w"|[S:o&Px%acXU8kEtQDvBjLcrh._NҌh9dgy>VOPJq1Б4B*q1NȔ;k CC?H GC3 4ۑ72y[qǫu,T Mrtf>7h@ˍRԑ[ FP W#>C:42m)A}O$&qy:(ԞvlȺLjc>l㦘8(Wd>&Qȡ{^Gk(H!fWZt`]o.cl=,#zHS;ʹd]C?>7Y8.2PHΣf-PtSRL'%^0vUɍ=yKWٹq1dZX'&Ȟb'ʶzI5 v{) WBtg &PPEdibŞ<.)y/hhKX^]%n.p|" xד)01NA t%CۄjcP85>atѨSBOX n4}5Dt.Yf9iMtSyu\B(0ȯ P/wܱl{lXm63=$^MQXb0S{D+ F=Hs"Z?T*hQM3Njm䀀J:u-ط=)a-ضY/w~wݨ4^bB`"1lJ]LKբ<k(^@{۵IJ=_-M6WWŁm!/d(i8j41g ό\`@+UT>ux|VÇp&qZz-Jh3ה Y2+sB3< r¹Q"$ 3߬9FT$I6ާd$L/m9{KT]܇,Pr7(_5*{6ϻtn.>2=?j$5m6R*Ӑ]lm: IZ-nDWs%u]/oX̠~#Ff4FeفrDq@ ݵWJeLf]~N;uz.vE =Ge8_={6#H":a&5UsIXQmgҁ=!@%xu۞ͷjLŗ}ZRkY"^w 4NǼ_I4e⸸TW-RP=HKgۆ~ĢXDm!`}PȘ*t_"D*B'JY$,y=l~r_O#.a2doP rFEP GIBO K:1H7JCsFF܊OJwLP*L>'nHm.F9~@t 3p@`8;!La&!|$V]qtc'y8BS!b|vD ^/]#Pƺb@AN_z& BhE|>0u5sAI!nMgiKm َɡ;&}o(?<P*.`Ob̉,ؙr+Yi!+kJ.$+o8QhU3^aӗ'ޒG]v[g$' [0uev`zaTTߥ2h\IaV<+zQ"ۙ ~ HVfޑz,F&5^_0)%fR^Hony:-ϛϷ]ƫv)GKۙ6@;oky <$/>P,E+D+X4/6HMGn0 8É{ SƏPyMtno%w*|-M+[˒?yoBv u8!mw;U3?10 Thgۡ4I;{OVR D# 0@S|ebزb H Û'^i7VPHtb̲BA4trHY5 N LF[ci?n 7Y EV%óُ2X?5F% m9 ź%CWMKJIHm~&rŵEM7T̪EQx'e󂹵X}8hMeᎋNdm87 Njw:psa' ލ,#"KŀThPD:`psE.$cPgFR?˸v6JBt@|V才/ѷ.c9 M e넡Al?X~YO3ک4@QU?G m~hQ &,ZT|{id, 7?B3S .0-^]&"3iԂNutfpy?zK+ &BU62tsmoq!x6k G\e+X䩧4!CAO19#4N53E<I뙕v9ӴJq&7p gq7J'R37H|Cfxb)Etm7xIWeKWz_b&,-AKxyICtkC#h?}9ߦV;C;2Fj`R}xBr ]da!oͣO^0M/ؖz8'8!+(S nI%$άѻT"W8F:#(Ei`v]ۢK%Gh}1C M- JDc0 bIR1?kea{7Oy63CFyah4O&ZS)Vn!E}0t|:0?Sֆ%gUl:е劷V*7ϥ_9&Ea/9,gMH39?c 7ŊO5W+XwDAƪ imJ4Ȓe D|e9⟕]%x\3;u]2THtAaMTm]M}ED(E2-r&!o<`I!O~uY1#j0Sy?U$TG9\nM}uh.t$nM {WYq@X0f[g.apxȗ+!gq7zq22y|eks>AعS5<%R7W&..LLLyK6=FfbpMK3g2֜WD(*:~qᗷ@W C6{Xd 9w(n29hL/ntPdgny!YD]$­Fv?ƒhϽqHPc^Թ@(KfoṔXu s|юkA 0l 0EÉBAvLԭYSχ]Bxm|5򱆠Ue+ZoLt"q<PDӼh1 uqfsx|: .7Mv#Q6oQj%׽ďx#]^狋/FZԞ%"Jz~P?PDcWH%-W޳!~ֽ eaaHːD<\P=z4NQ:ڐM/u.i.Tp]eʏ~fē}F@irt@{Cžz?4in$Bu?cc/3} Q3FZ+ ,3*P ,SNcȇ@\O{̩1DXx3@-}Z FB e^$babF ЛZ[YӤ*ӏ1!8ՋOz\%* &?@qq=T*Ҫٽ+9n7ڠ42܂wb-nߺ:=样ʙFJAxMrj1O=vkA]@"7=o:W11v/`zd^k]QJ*mӊ.gk4zRPp4WXq|N 3IK $7Utⴸnڈ{V+r$T,v+Sfw kޮ97i*] `vm}r!`e%ډD_: _u,vX4>Rcce_ZeTXpGo8&~e(=M@\c`IE(tC8S%$$~%ڐkuT3`Al!^p;7\%) oURA&Lcr|LLH_MEw?m\=jƣ}SrO;"W` rך]a̔ƨ 6ǎH!t҈#3@E0<4|&-f-,{5%|O Ɓjh&-[ NZ~0pnOzfN4?wUgbwKSs֥X܋ ( BE,'Aa=Т+H=,(PP/!,yCЛdeY_ w̏Lm(rR(OsEL= ۖA7|׭J\L:QaT|oCS.MC4&x#K2‰hdu}%!xȰ}w'$Y$&giKuk( dVg"r=m\s5 A [GF8>(uS`Ǫ =Ԙ5 ĥ`1;^鐲 _n8[Kf0׶ay;ܕ$!Ug=1nPFul:#)B0'ԢUeo=׬"b&2 !QgU>lQџtװq>pWZ6Ę r>NGМ[椏x6rLf6f= n›t@#@] V5!D\`RXTtR^^ԼR èғ#NE5H`]D &f gObE+t6l.=Myx3Z - go/Iah|%uh BTGpCV qavK!}8_$ 􇰩 g]3GYxx&EuBV,?@)S?Ji1>YieO{h ԑm(\cǯI68'v6@vtRwAU Q\;K`QH Q+F(Xe5s>z"tkd]&W_7{jc "FVY@#c@'*Sx zs-q 9ϭc 1}DHFgpɗmcgZ@`f{"l=]6 ψ]ՏzJV7 &'1۬E\7-۫[zM8(PesNOrA@ Ma䓘}:0j9,i!Hra@@^ȡ^Cُqyc~-K*wцAde%k#ryT %K\ɗ4H Kj-;϶K#ͱ UpʓI{Ƶho(b }9Z,`ҡŀ德۱+.ŒF98\Ps kcZCR4-ATx0'ĺ-G3P͔v]9uk䚄c^a<B]Q̀ =TúMA%d%`[RxZz{$B$,S=Y 4]rYkLǍqȿJe/8Ukk z8l>_ʙJ*rz+0e?}*_ N]aPsjB b}S␎rY޼8 1"5@ aWL<{2bY9+pMbfb/0NSyE&Ck:pEC?:duIU90ı @tT 7G"3*gS&h-ߡS[{[  m8q`*`2-{7)ЅT-ȦF~d|"swQZߚXJ`gQi:j1GWR 7pG$1]Kǡ[SC$(Έcq"zhy$XLz5k}9@Vq.gR6-=-+PzN]ȉU'+%, lzƲH" QfH C&- ;|9EiԨˆєV]^esk)v %,]ɹ_ (˧, 7|  Κ=G@D3|4’_T:L927 I \dU|8r NqދUyeC6Jo[ vs]E/חb.K[,L,sOΡƎ{夏%ap]u|1T(9H-(|ShQҭ 5uIKl ?{XO']Q??OȰx.T0FffB O_蘶΢K^M9Us>xтEo"k2~x=v|hGg=v Ƨ,f,/*Y{F @&(5S%B jyou*^#f,Q^ٝź!0 ";bb.VR"WVA%41 \8ğ6Ȓ]AuMj]_kfE݀ *?2_TYl˙f qݪpJ9S]S΂H}5a-/&{גu|.P-bl]rkZLM6nT+ܔ N-+Ϻp)\ӽÿtpTqή!~OxrF?CoM`ઈ þW`2<,STUx;9й#E1P*En+" vxڻOu/X{6'Cg]kpBg?QUs[b>hk8%h93[@1HTqͪTۋCרF/)Ǭak\RI˞y]^AćS9+;m^tyf!*^`[[$'Q4/&D,-ʿKif2!Dۢ~Oy  Y ʚK{1Po84, G=)ѷ{h2zJpm`PksO7:գLjlYZ)KdLTT& 9FycXtje'zXr~KP.^2`qg`F6pb+}Q8}3mpqiaEՙ%=$qipSÁr˓&SI/_nm}mx^en2[#,E]'ׅ!f3D}l1r8>ErdvjXNL kx=mtlz%!ȭyWf`8 j5c9d>U2W}i˚ b`J2"E_*OMgUY&ua:DRڬ[̵Ǣ´+yrP䀯PN1I!fb\ZM#M\UIwhpY [80$'H%°Dۼb@g~x10l5s0׎WFU)^Z4GD*&"[&!RUOPZZPsIaU #S+Ĉ‹63 z.;@e"lH_ #xY4ʖ O7[̫h 5:UֆQq/u0=E8qdE3%'}#F4:Oko1DL73~|0ܨ]ȑ@<wp `\$KHv#0D;rn[6^I>->b,%\,,\rL*]E ^mMrFTÒ8{khN`gœ_tk韛 1؁ݼrAET@}&}7Z6ƩnuZ'hT5N `jڻ3Ƚ! `eReU2MlzbFI$ý蛚46H"ԧL - 0[ĽXvshyyʶ!,2].g(y'O>Y7Zr}ܢI?Eb?OECga SYm>pN@݂#@>4ojq+Ds q @\F׻K=pSv(őٕF6slBg/o9X#;\! Wq'UQTہ iM@I[2ACZ!M>7a-mBgsuAK>×'H͞ËHc;6a[,uYH4\R;~m*2|.(L@ M2duү#p7(ۚR E`~obW1-au#*ΓuU+0^9+S,$A0ފIm.aoR:8ڙ,m{ⴗ?*hxo֐,!aT0 N_[X?Ĕ: gVs/uyo 3rq <4LJ_&\WAXgm ž};xAsBb)zfRH@w$M,(q,DL=GϽVєcZ;WyCd$>ᰦF^k [ŋ\Knf飿(365GU1# ܆Jɹ@Up Dٺ3; v !|@hB]0 TǓ߲C$QA7s3p1wTw`K9(PUyxZ\S 4s:5(CŽ\نEHhK^:ݛ#)Tv xS1,MVw0ᕯSF,?|Jpx:sՀE㙼rQbrǶX?H S^`{6{>>*ܻzz -$'h̓-@E>{QEz1z(.X.5*nCu6?bYęP!Ѹ J8"@7GL sH2MOP#lb,V\{iye,Npu:+а5ݢt uYUѨz28\U1m+f˽'kW y_t8~8>hI[C>MLu0aS vnA4Cʅᯠgx{ PJ J~Q+\JV9mh*0W̜0ˁ-¤\={uW#0|D-H/#(vҶX| m˳aM-+(4&ɉ|9 آ.aUv-!!~}bS+mS,QB\FuII gI=d<ن6Z39^6 W(eD;Vwy\sd8(vSW R.&\ܤAp wL8(ΙUW95ܗ+'װo[V/[u- !=ZfOP-cjo@Ou8wW!!bCJ(bB^qHo9 wY{*RPDy7aNXA"'u/ī^<,։G͏䍌C`Hrq[{raG+.6pt_*L|3k5iaF@riaQƜz)Dו3jLnL]:; -СE{ /cs! 0rw*830G2DT\'1\[!"G|%/z]ݷ2iU vApn<]cqΩվ_J Lr0z#aRR 0 Y\bbO߮ϢAU* iNm?;1cB5#Fb_kWdAm|>&BO CnbԄ. eaǙ[R`jc)=&msr7mˣ>IvUAۛ.J#kQc0tЅMGo$j@~d.B1M2^#839F'5!RȎԑ^M˽V pѡRKBn~|M|&'i;svNjbzc!DzaǷEp]K*訦lTSXQd(@,3/JҼ O_>c2-]kXWFT6;OZYI"/V)RQF $+j?3ѡ9E9/2]Ȧ&FZcϬ)XC3ls@8 ݄b72NvUr.[htkXx(/s)Eb4fpy5oeֆmT=R9ƾ[g5{٦5/DluEz4!a`CCRcxձi G\N3Ekf7QE$ψS?D!= ƚ.!Є0fE5yޥK70k _yUxIP<?gD7c QbZj*DF+P7zoݨ7OG25j&QﯸJұ—il`Y)[6.=5٬fm ܧKJxUʐxt+CutS1߯:5t!´j7dЕx@[YT/'aj7Hk2>+dRî\P z2kf.fIF2?"EN3k1op S,_ oaQ jEB)op[y/ѬE6HWGkDڸn~K:$6?HQRve*P̵u%tf&EQc 㱨kY^3=;K(l8VW = tEG( <@_=[ⶑrS۩Qӿ,}c@ۑᜟE$ZCal>XnIB=b5?:m%nwsXqJ}ؘg1(<׹vf[7NkO||9LjJxAsoR3jwQ\pWam=⏬tneEvE6cc/jgpas EHhY&z1i]8XR.ܡA\, _au蠲Ӵv\'3עu ݑȧk b:f_\׸b=9I)墰mgeD|p.!B|xHATQkpd=>#݅ΥpC:"FlxI'db8[Lai3 uiF=gZGW=3˴)5K) ˴jsHm,4,'mD^ POMȨ!LPEd첟sCof4!ko78P-fd.h"0qs` }~Elg!;t"gaʾgEe-J9B+L =k71ad֯uSc/t;݄ *Ȭ(Bz<,o A`y%RcKGLJb2 H;tx[69AAc~%""x< м|f_ÉzB-\ E?:95]X&8<m !29Wգws>As5*4aRMW1ŢtQ!ve=N5L=O&?;(p dFREa.k"--֍K]BZ\"#Qkm3 #k&f#)=OOՂ݄aB'j{2^9O>ooQ7Ƨu uaT*6YlkW8s?gl>M ғ8N8.Y:WVZNǽC_ޛAS;#uUQt1lL'ҏwB[s5^эMOi}I?,&v/hk[h>z0=rG84ۡI}6 )g\\CN S)wza<R% Uf}iɮC4F B:o8Z݄+[O[Fqtu0T0NkavgAkbP.zђD!MI1&}b%r$euH7Viz񛤞:?6;4ĉ-!BrZJ+#wŒ`Q޿%!Ta#¥}p3 ~~־*#G 6 euŰCaVŻP4ˊy=vJRBKt EAfwǃHu>2wͧr1cz+|8}Kzp<,շBSbgrg@M=\E"+@>]KvݷxB EJmW_(<'BRs!)f]{Kbd_+븤SqJZĠl#/  ŕ]OMySPBgӝc!s4\ǺK\탘~g;w$͡vMp=aeBY/hPO@T&l0Ս/Ju "Y8Kl߾0H s?Yy.s+oG@͉UlB᪅ a0K)畬-܏&OXޠXR1_v?HK_+R84'|Lcn~/#P9(`e4æb:̇d&A.А&9REE5Z-. w\ w AqG-'XS 5 uMg6C䁔 Tt+M? C;:vk{81 [ݲ4z_r{VфJ ]xo+z./ZbMd/P8x ܤ+";c5m!ytޕk7AYR(_?Q>APq)l ٷȌVix1S)(ta~W ٠b2w˦ɍIYIb7KFu` ! 5;5a~ -cP ]XD̻1`p`CXj$, Ua_vؑܕyپc)>ʗ#]V^%d]sD@HQȈ ':`ox:tvK{/F+э Ss!CK 48˩_맻/:@.a7$Z. 6'b&]=X}BBV෉Zl{2y\$oxA86p}f9xS>kйߴLJ u$+K11Xl}H)K06hxdJn=1FF>|X',kenfJ8wSLdM}liP" fAw:eC\[涑G.>b6k$0?˛9䄵Gvcdn'C|Kz˔X{RtS$5}t#׎FPL穔aђض'c`DYE_ڞ !>;nP^3,!.78FdgܴBUHk3-Cڄy]?K&E~ wVL]Yc˲5=vP<`݃V,]LeXZ E`uIBܚ0r! P6.` W^9 --8))C#+OIh\\ ԰BMNh0(Y΢H8)Z~eIv2ًwO`bֆ~<5bfDQ:3И=|L@˙K#V=}S+ξ8Xa.}objfTs1rjB?[իt9- |3mλU9Lg`o+ߖI#h< WE=w&2Y-~vcD-;g_W$a<еB"ZD:|_!${@ SC,nq7 mjDٞ60Kt6Ob,8=V! Қ b5)PaZqK^#z7VǤbV'X"bw^{ Gs8Lw͐OچgKDIxrD2M6n{]벏QbhW2ޝ@&_=;geYdHdH6ffr8FĻE׃+_v]R(@8j|M/čpG1pBǡӟq0a.EN!Kl 0:xSBu1}|=c69YPT+GIuP'R9;UEix ;,{^ D۳i]qp( ShG2;49Kʳ9c(En",a$K]N[Oq 2a0r;VLP#5JAw ҝewZgee u^)}SۀO3D;uo֟ VԉXvIJaJ& xc)A-aeD":Բ~Y>uLFAlԀ1t(E=x/RyEzYʅ+V{oAsjNO&/TG-k .8BOW 2y\ n9Z|F ln{6s&\>JXtY7P'rQKV5sWRu#a輐->HⅱO{3!/*tl㳏^{F"#n[a91 ]N()"#-U ]&_lS"?_CsG"`!}ށ])F0!]x1hn4!@;Ե%Xji!՗߼''(;4 S Ab+IqY Nƒ8>]Us 6c`5JZы,B`ZMx-EӒk~Y-Ďq-FmM%WW$M;hZ ^x~[^C#e`o\g$I =l(B@t.s4*jlux y;4ˬF 8iAVPbU!)97ltdabj照4H)%$[rj,n9 V BjcQ8N3je obPC#Ӣ )VL-Ǡ<^%'7f6eg{aR(f=FD&=ۇrFq0G^%3A pAVY{ ҅| o~X"@ź+0@9!Ҫi`aiD+,JO?ZPsbpy1Pn*;wy m y%勼 52>+-~߾n{r$TðEWi)Ӗ_Cg:QwŎ4Rig+ix)MA՘t-5셬6*<#T Y$^pLG,oGph0^h8Lq^|GhxHau] LU,,S;z(u?g ӱOZ2Oh}Bp[ePl" ʤbzQݽT?[F&Cd~:L^ۨsQ3snٻ7h,O!\)J{W,0"uXpGS4cMQ{SC<eI֗-!rN8eyq dD_,f&P'.-#D~i+SHxucMv?\+Oȫ{" \#ODX|>KUu m[0-5mO[ ɣ(hRqhMWDE_4k+@ TE Fa͛O D3S e/H9KY~t-*AY)(\*3C]@4Ŕ}7AA/^Xk XCTpFGM͘ϻ%(gmnZe(YrPڸW9_ CzLG>+ Uҫ8}]| 0,pzW8z+ѲjU'Lës:jhfXxFM3Αr}c!'N=!N N / vaF׳஛]C]^ɂ@mQERާuSXLo<s? Z1FYB#!W6 +7p^f72: SrVJFC-9xf&]b:vS"\$1|n1fàe=ţ&q>+wgշ+Z[*=>&%եZq+́.v)Qt܋OXa# <u}dYćK){7ң= pHf xP #h')$%⭸++p]`/#ip AOLk2f1Ng#GTuډp;4]ɒ :Uf}"ڃC\&T0ě<졺>61&Gz(~gW,KW~paDQ/Mvp^fMkN 5RS,"|z] "(&9Y֏L\ka ߲˷2X r}jwtȶ"+j6J zO&a-‚{|zi(beS/dHO-S}gJ%Ò- C-(H'XJ E@b?.# OD4_2WFj9K2Xӽ% >m@k"FI1ue:N\&Sp`i=umPEIb""9,ȒKK1qy,#\]%%jW3FL3$O)L>ʹk Xmŋd‚dBb?wzPTZÇ7A'"& 77' (a[ caFb1+Bx!źě>~u/,U#6 W?CWLZjGn0K{_x5ʱbjf C޶%E+ (d}%h ( 1][2ִHͯ 8{Ƥ f$A@DzitZ(R^1Cpד8RԒD[T8G$pשG[-QxSqƿ4u؉ζ|WN޺UE&Oww;KrLV"&}zo7uTvڰ+;hu-̞ p* yP~ 5wVj ouŠ/'rwT\LTdfԽ:7v-w@Ha6GꂗU9PV7}!\?x'je<-Tϴ\}Q&Y}lcqDH!2&+ 6Ys}GFՠ(z{fƼ(MoaHMxm%_B:VYV#H1,-^S~R ScV V#.%LBRJݖryTw] tH uK[?m5Y ,TN;z}7Ā!<8!۷Fd{ |P[ a<;e4<fA]t{1ĔF|.R%1-  Js9[(tO/(YbB\}s:jZÅpk׃Nr >]gƔ03-@Cx](jOy.HN򭘇hɾoPvJjNVH` PAzW8,苔ŏ>Oe/bӽf-IB?S*8֞vhfls*Zy!Ѫ& {9ou=JlL@, ;~P-4Ηݤ?C.u]HBG ]Z>V |=j)VV7WO@wzaSuh=Vt6v>/H2>2!T|~B>Vhb01H i09@)`;j ;e={S@\z1;XT3Ϸo&E600l4ד?sW2APZ9DVv\߿LA|Lk }UbJaA EÀ]&y<2V:Kyc,OH.\ i,I7 |'BrÂJT\Izq3l7]e0J^ Z _K1t.,t#yV Yhc[3siElL6gZIO{>cf̚i͕*,\` iF24Z,|<c~&DcTCJɟKK( d9X4-}C,DS8[X]ǓU>PejvʒT(3y,h.^c1ZBMݏ_zO(zB[5t/|5-koXAP&Dvdc~'9O w >#/ y+G3KQěxH6.&OnT⒐@xC/c>XMRTqK v*0/b~8P^uy9y2(?TsRW@q^b.̶ޖXEou\e'pz 7KC\@H g&^6'?/ [=tpѬj$ V0  ƖPL\Q ;o -}CJ0+~|%7|N8ml'S!ZKw4͸ 8X;SĈs "i!CZZUj ,JIVx:_bz;a"Pi2p:K9@7ղI4d 9 zK/06v,UV4/zr3dBtOw "=#GX)73U"7QzBПv dWY8ϪmI[kd8=k ^.¸PU\3@(r÷Z1^#0"OX,(7C4r|"*ߦSgt1A]5JĎt)ٶ&Nkf\41s,R? >D7'D7U[)O''Ud6I-U2ϔ:|/VEs"9 M*hi%Ӿ,J$9H׋QZ )Ѯ731h(r.n9VJ~Ƹxgt5y8+Ǖ)QltⰥ3t3KXE:F.%@MD>p(i8۲h /.:pzmj&dḠPeO_x=V)!8)Dܫj {ZqVk |@xB}TK^X,cpOh[G,LJvhSۙulκ|'Z&ܶb6ޜaiGY7?bB0vwo4|,%ǯcG/g'{qV ؀?lr#Ein=vPJ|K<ǻdxݩTJ~{o+&-%*%9,9HHWQdK`"҈]b$g{ͦJNr]Ϡ.yz,d#/Jt(Ӂ67KOu?W"h#7 3n O; {&׈!'[@W䴜ellZoIX0ବ8OxE!>m`'~>fƷ+`ab%^ WuSP(Yo8%m^sNi5G:LYk:Pa3ﭹLAbrFxc~H}`J<3kі.4FS$X/Ho83iC4m'IW?1`5]㹍<2zxg)$8>iq֔\1D.6R ;_Ɋv.A}H,*F- 0v&A3Mt樀kKy\V&Z)N2|,- GJO#8Nh x&K,m/2)O2Z5ۼ6{lm3[ntRƶQup\i7 ڸf)Mt]Ddd4>v^F7Ö˫ sD!f켬kH``R^#8_e'hL2ecKig'1_]b8 M IU;9zO Y>ZT,ˌģO?n|p HH;ftl`}7ݗfKg ќ\# ?ICBb+C> )plP1R2 L\duQ=x}N$E 0F4t?cV9r"/\f/yyLF 9Pak" ##rD@bL+}Y< (zc6LD@igQVe褏[˕@8; ( Ѵ[-@f\-W޾]ln+6 YyjjqMֈ 1o94iW=db5S*梩~.k-nJoKhLb?0&4i:6Ɛ5zUcF%EXqr,֢Iqtʬ`;# SZ[$ -&z7J!*8(&DJNM*=E NCAy^y@E@G3tsm} pĿ{9]q=t X-/JY#[LIIk1ix쉣8J.M `U/r>{Y!Lw8 Q:~Q_)L(Շ 2ٴSȩ>@ׁ*:ԏINlř(UC.@k|f'a@ Xt|&.Bt )lXg)dEf ss sfs~֛zG}a`V<8=l4[&".B2ȼF_75-[ER:o.w0-n=)ڜ5*5YT:t׸^+ o%Pi];ÜYYq;o>3R,rب4a210h׸5|8=D;yBn{&.al7 fBTXc7*s.g@9`R']Z DM 4@ke4*NV}JY}T{f]x&BI;$w>ߑe#;6aֶMg"> @Ki^ߎ%J}'FNA{_F\Ww a0tL` >j~p8V0}mb`^V+9~߇#v"PX,94 /Xݜ#o%Xh߰%YbsxWQ_y=RC$Jxڼ-7~ a.sQ.LFG.#NDp8:F 2.JPq"оzkm cSxcL}h'C/?7]{'k2Sؽ錳4r6̪eFҋ3<՚?X4R{-K7HZb [:] ?XƝŹ{RUawrPc%gThT4PA!TO%u^la<ե#̌5F+TQ_5{.c Eia,$PٖD Vy_ƇUܹzX ,ڂ z&ty)w. SMD$?JH5&1h9+;![M sGI="Kh08ҰBގM}pޣJ'J`*w喂jMB9[K%F*~ЯEhPm29޳x9%U9h: 8 V!D\`JR4:-EkN4K3e!NlԎV8}Gb*P;e~䦚fDCoDzDB/L:d+@\z,NܕBtRc<ĖZKe];9Еg7)vk#mv)r B$g&NWf &pxJObT[,_"Гk!co xSg֓}cZ}WC/m}|}j*OS_CE@7rP]ک|T~s pKp뼡ف{1CF " '(h j:ro P7D9 M87HΒKq._7_`-L%h.BG,<} ,HcU#ebH v@2ߢ_y6uB%,Y"у+~5Ҟ/Kr^z S(@L>˻hI LaI ҊOؖ >O!ٗh9ջڎev`jL({.G'BtrzO2Nڲ VA.-j&V_>"7/c'b+!NEemt"Efy{ʻ]3V1|fM.NA >-B?=&<(\3vY/<&~2K> m;246OPG^quX)_.e+̊1  w;.W ۋC?[ "#d´O2JԎD\e"`槛9)ϕyrՀbELi=xd΢-%ͽZQc_rps) .Y:d  qd0b-񷘡U;aVki_7L@ӰӇ7hc?&1I%(U/ydSKG܇O<6& l̯ӇġB4R΃C؛ &hM`4U`dNB,3@b̃=mÞ SMf9. iv&uYno!ry#h]$+|)LߖQ{0 CwNϧ7$I/ EkbiVnBow (,a<:'绿Lhʱ3 S.&`E˯6=ģ_mϓebuAqujeUsUk?IKہIeL=)sP#fnn~i(\On#]ⱪse>smK' $HII˂;p6?ʰ1A 2U!ƜT'BLַmKڏ5`[R8]YҬ500MXVۚሳ%mB@[2ж"0V~PO>dbW?E4#:΁[ W yz+;rWeYP#Dyhh rgi%UP&/\ا;QS>H-KB2X}}4?2:Fs1#NگNtXi9<_S3czo-M BF[^^&k>M1`Nc8TlSoćg_mj"X(Cz t~#pDs7`^Fq@5VgGӚdH뗟;&ci9C__]xvHHm#C33h:t p> =$嬒|DzDO;+.OimKύRJvNDQ8=\G7 b9)v Bx!Y% >$uex7 |&g 2_3<~(g_HX)fOFK&%0nY*~&ѐb!1ࣱZk>6<4mV{9]Xv|er)KuLytK/[ɘjGv1G{ϓ$$妜*h?aƈQo (ZtJ { heaNoаl /[Z+Z"iz(I^`ADFOPh)Фj̀<~lW'ӧ $8tCxGUyBp6{9&٫]||,; S68iT1̃~P}*:h. `@6k=ݻ>P8Ƨ=϶$ossK߶4 9;()fbC:'slv1[̓E)%bJ5O/mmpPRrVIEx&&xSsԊTb㈋6O9 JQI굉 $k3^AHC+S.@o|!P6{@~i]\H3 Ȥ40mI^FwU+_wa=f.|hz~]~AMjKXx^SG@+,O˦, CU`b?AҌDσj !9mt6oB|3kp}8GL!?ڰ\7$]T-g24rd=߫ rd\{#}Dzi@F:OT< 9B7##h\^}$œR蟔BVW߱ Ǖ !pL~VFppS3WU|a\1XմBRx 8:̋F^[,LTS3+b$%_Q;ԙKx5b7Th)̤^e  ;I 54TQkVsG8$r P_\ȞpZӨ ]8n$@ymsvMi0~eW琚Vr~ljWdstۣF^~O4LWk<'QFlFgW?THHڌh[[P /uUם8J߬ wycnB9˓WqGL \^EVjOmC(]pr7c3dz1'moš؍q(jß8niȝz݁Nmy)*NS)mF܈Of諝`ӷD]g<YU@b[0-h;BWm(vDVvIxJ2|;b'u[xԟHd;Sg5֙פx@x_ڄ#mrlφYE*= y}9Ue?O :8\OHTJ"qLO&jm9C $U§{ $!y2ɟaIՙOARTBuU,nE=d(HDhޡ`%N0l״;~Tc?9r!քKI`ݵQq{ڳ +hRz͸Vm:uݔ2|l.#ʕdI ͋m{H]ЬlOGI k '5޴&5Gz;8|?8\ei/ߣiZYh.l#eۗu lW N ۦ[s ԕn=|4%)EjJ˨mV#A7juEƻb 0Ylut0Tᄊ7$L2Dc XZzaf^Rs1l2›IkHQ*4뢵* 2ld%qZIfݭ$_B(ܑ @\sl<]juGfa=Yͪ7QUBv/\CרV)NY;srCTHY{q%a7/2j7nNWk3 hy]C/}m×2bRxӘ eZ bk?0~IC@ d@ɱU~o}لˋgĄ`i+E[h|'CߝRWn\;`f.(S<k,A[\@iyNaG}A2]A3Iz$p x 䠿5 hn1PFĽ ]2 ש5+}\MQNd6eEQ.6"ԛY;g~FryCփQms0^#}xk;+aQ1bZ1ՄsVh٧K(ë#-IVAh93 Ǟu6HKivAm&:! ͕b߶.-Zݱ -GLʮW,B4D{={; R'MY)x SF7 u߳G4MQq)BGq,t{&!lm{)%y-"% etNIYCߓCxeBֶuPNy #ɢEՁZ3صv4k/|Wwy;XB݅TYĤݸ)󕽡7D;4 96 @Ûߚ<g_*P:M(蔐hRJMJp\ff d;UF֘rY YT_h~`WcNX#p{&68 H^W%W?kxwl<*{Vaw 2np=#˺"'^ЮR} B6c6ׯ&=_U05;%]JzgU&o]V^B{nA{)b}j\dzUVN=4JͭrQ!!{ S={GyT/w_A8?ׂt~ W4P`Zo#]1G,%薭fU2jLwSck-0uliU~2"&:Z;%ēV1;WχzO=Qw{D*5 Tojf(B)WX)-۵37J}qrxUm ŒD&qC{zDx|vldb؋)v (Oݫx4j3+9uUp/?p.ry :8UN+,$Nt|d"-RA1v+VcJ`W8_+X3ڨNoҗBK`Ycm+ 0DM$xY\7 2ID_MzgFC8`fZb^opf0S vFMN"4"MX  Q9`Q%amM8}Z/L~R{ W\|uկU.a&_2j$ϲA]nо.\\Sh<$4%k.UV*Y#nG:ڪS%9^wX a26cf#C7j>8 ``'Ӗ`r"Sn&[5s(eE V`rW!wU;iO)3~iF hNp+w|/ n⣧s3 m๨`U1! DMHJgs ǢV(:n{X `y0EDFpYd%[!]knb+=*bt-tFLD=T݀ zZL#E% [dK~t߀wʓ=K&21j!Cs>Q< ؏%{ ,f4sbp~yH~A$p"䭟ڋ>GS^ z2Q񑸚u,#/G|\A D~"ԣ븚{C`pt:Nnfa2{`IϗFC2mLSZ/NlS3\}NR/~ԗf_Jtyi^2Y)ȿnj |!qzoFDJI/gK `JBӝRtQ.A8oo)w=]BӰ d91#8%r\fa?e U,l2R:Au+s"3An>{K(뤹jt/W&drb&?g;:o1'PL5"pg PXδ[N8u/賵u:# \+Riye#DZPJ ]f:Ah_IOK-Yǝ84$" hx*Ep,԰]c2)FN{[3682Z"C]4BnOoK׽DdЎk>,,΍:Ϧ#{y{EУSY0|ɘD.P=}>v9|iK]o^C(Z9!NRv8OBMC!A0l,_sB(U.gTR FeB\d^2Lt-Haն=Φȳwǫ{Nɳa#κH.nz'dEO3Sfq\)uuQ:ߠ>a7Y喫-W0Y '^)JP`Fidt8QSdB1[W[1䃝пPt׊MJ-/$_< i컙B'!ܯIg??@w'vbղЇBKXo{>mC& _^0hMR{*r3\[ tĈ(M!qw>(|}/z,kE-9O-)&3s7IVGqɡy뺘\JP9[qCQ{F8R9NLv؅ ɯ?oO ݢ_Y*JFrV/=r!l Nb+`fg2GW68|] !&Bw:ĿD/~AlGbINǻgAWhGDfJV8n_-Gao%`fBT:c@S)'#\f/Xz$LSa,9&,&ְgnң 3PM '"jZm #ɍX)<=c_]z<*C Pv֠HOCؖFfqDLBD+9XlDz:ȧNU Va)> ~qʹCqǯ{v=-z'?+o3feezNk ]yL_PUyTgKk]~Vpn] d]A7C8-g."kjfWnQ3́pcCRM5MA|$QH3~^'U*ƴ2; U[UNCʮ6Awyi?ܥξcYtM'^ BJHx29`p'L >)4ڲW%K#)$Pz 41He&uǮ:P ~>J|}K~\|W'XKpimMí)ltٔoR9}+ڛ50 %3coT>U%6EWVr !dr?ڶ.d ['7vH@}=ڼ8F5SBZ@1q~v8PHWHEC]ȸR/ԟhES5Hq#qi{siY˿\dv u@,K\4ߧN1q_9ziIt8):?e5㴥yhKq.c#78o*bkh(;rIW1'UχDbavuU}KlVEptYipG!߂,ܼav[|ʨ#)Q%bDi=h4*1y(rIa=Ssw:Օd.å ?`qn&8NA랭hDT4u_5 >&. p4];H ƹs86d&A@A"`Lgf|&?950fX1 q-S,KA P6c:Й Iž rzjN&~b;&$ q-.DZ޹pz>*Qt9eqQRPxfxӾNRF[v!3BFKf\qhNiL2L 6:GY…GdʯhWBsT2aۈ@ʊ<9b%sm$<>ʪ X7=5)8Inȇ Yq=3dJcjm$Rg.*嫨m.a9cK/4ЗMɬKRTl2mGsƵqƝ:AJ~O]ˡ),38,H\ۀ9uzKg(d+7yx,H yXsݰPUK$ {+ЂdœaІ1?ģ,. A0 Ւd̟(DJ(yxnR!D83 ]GqEJqʀѰ$d<[%e{(OWxAƭmZN+xK0sKqo mQc46Q_ګDY4/O*H8Uk n1̔$G82IQba*bQLǴ0n(3]sg^ mO2z\ݚ Ue)twʐ: #O͐-F{lolʟ>N?_32BS .Y_U-9ZE+uŴ ud}o]iAsZ/(ɀ+1;"lU&KGW !4\d Z}HRyapA|DT;Fo sX4g1|\{67Dh1Y8IC%PtGd8߃߬Kg ]l_QRcx77jҳ= AtoLii&2M# cP/M(w" De˞$.g }N3׌-y(s7EA[k{1*st8 3nJ l*5]cAvxPN:.c5ޕR ޜB2)pҒ8w^14ql>7n""[h(w7M1&ԏ9abv~z)z'r7>^<%ifx8%ɝ#G_H68 n&o y}J=_e>#bon"Ps)EJ]ʨ9C԰vޚ +oi8ݫ#.Ee0ZaE&nM[ic;n ~ӃKܷ{6o.A*N-nQEfr%-{@"3@N}>^C9o3{Z9\ 8  R=:W6CIvFO#y嬿y [yaԗ.LڦOZ\ YРd&lrӲ<V yUjs O.| Owf1R" $F.5 sM0Ж9DȐeڒx09Lq3M /N p]@2@^=u'wlӸ@adNW[[Ius2T 0(U ;f`RWeDhPy΋-$uQRΏN5:dg.J˗56ܨ OoHH#HOi 8YV71uҐ*u& 2'oM(bɢaXJ1Td])ƻ&,S^T$ry0+*k˗송٥sI2k .X=r:5IP L[CxE=N RN."ei|vf׈v2vVn$ϪqBg` 5%~p+зz[nnQAÚqv{3"cpсٌ08#Od=^WhyU6ߍV|,iJ:HgmȃJ0(]/l'c(CiM}/c6J{;v3G&-rSg;c~׫+d!VGpwg]\HzPw,&Xw K׬El-v |^dM~0h!kiT[߮T>%KrenB惚59#,%2\}7?&qRMHNņ"5U[aM<DkRD*$OQYTڊ<|7C c!<@IKLxi`@껇`HsMjsV]eNta+ ة<ō[IAVOV3uf0FVّ9JNNhJUSgtZ\6aWU^ #\1/MxN)&usy?4Ce]x 2\8Ɍ E%̟_a@iԎv"[50EI-I^NۉN ws-kL`c+7RAɞ yu:tpOtɢ= v,o#!k(J"u~xj*7^YP 2mdFO]'s5jc.q-rrqX*sPTwakaB^wؼ-+~Ow)ج.P4eф Y@"FoNZnZ%^ #۟YPr5{&8B>胎O0LV9oƱZV-~)!}yYylՓju>~嶋, CE q]3J165H[+ayE)$4wߥMl&.6, UFK73dPƔ捰V(cFc|!GșA~KJq'ؽdqH(ֲ S&eyEF6-y,@P$_L%=8J4ūޭ{ߍrF|f*}󜤵Yz-Y;e_Z',N|^oj|h<%gAQPd۠1ޚ̺L!_T7x?Y9ւ|Oy[i,.$ 𬎉,.WE,h_v"ޯ@ 1"IUwIpך?p\Y}NvDpeϦ+'Y Г@oa 4xiz椖+k`+@ϭl!u uҋukTM(aa^6,=KQZo3ᔀl;ec_'@JA=z3֬u=,?|8"rJ +P2 hv(U+~.~:L>^% ]ʉ. `_VXd(VҖ9bvF.$Ξ ;|)˟A}I&Izaf{X4Q\> q 5/(GMeogÐ]xdMk\mWP+*!CXR R1E%I EZS6ea~J4BΛ `3 ʎ0@cqo U6*""cln .v~Y=1`ٚFG^῟Ļ0s%{ŽMGP.PT'K,P䯧5KWPγawo -2H^!hO{*5MCN}!Uh=?.5[Ge @,\_CB8}5xy꩜ 1Dy| ;d79!䮳V`.?A>l>j3UkZÅKۮ}7lamqj:p ,,j|/}d5mkWn)졸P.?@{ӠG"ĸṑv*ڢf{Þ#͜QпyUÕ=]O>אe,&ǮgaOQ9X2 w y.G7!.F3YJZ"稤nqcAzp/'뵰FOa5lFcGݔ A,Ӊ_*)+Nk6`I 9P'# D0!xTD|\jBJ&M/ 2ɀ5gOh-K䩛ztɂBZ!ߥꁢM\P*"c>^`s#sY%Qυ2/!K_S^ahܙB6/PKI[L Mu.efw; I NĿLPx #8O>-$2]X&:œNtiͺ-I{`Ci(n޶-%Ȥ=~{|ImByRwY6?-f=X3obo5h-ed{GǠNL#ɔCO;ꟶ,>Ɔcƃ |rs㫓sehnF\go,:?OE$ 7# 1@N(ϿTp%b_V8F5 *EZ0_JZ@y\o$gEt?OȔ-ssS.s]~ 8׿ؾ6{.{GqA[|c}1,x)k/)F\&]t>afpHDS{?\1:&5e s/An%C -3H/ׯL,tx%+sN|a Ϸqx-iWF(=~YYxsWSсWa$8M ozEW6 hRhA\1[u}&k#9] -,\4ْDDml.PD ٓV'Wpڵm3#Tz1SS84_$9ACǍ-JJ>Ԃي5:O|$wEhI?|.v9C z"&}mϻY3dRU i'>\SU9ǣ+mS$V뫥SbB޻{͋EЛ{֒c7[7g TJԆT)^^yy>Ψe}LJ5|r[s-hζO n \aT$NT" Έ>~pB_zz3vS^a> p g ziVdp*sNY~l8@ĎI+0~4<c#p`ā)9H`,KU4(ک[N|7Z8F;lRߊ%p#mwod_Fe7Q /:bs\n;?`>W;w^OBLrY 8㡅_͔oԱtgOiqb1LJu E_ 5̪щaYW^imJg[4Ͱ،nUqC#U@x7}rXRpΨjim\P L^q8W^3\b 5_P mF< ZmersUQp!=g T i۹mVhwA2qrqU'Vd-z@Kw,xW9Gfe+X Jh4Q7:⬢{ _wE ŀE5:e'duj$^ڊy17U ^  )|"gd/x_$8L2I0%:{3odC/ \Mbh-CvIXP  Aio|Hf8as[~/]Z ځ*]Z)D28m5*}1(Kukͻ"`Ac#f1Jm%2 fD&T2ϐ=^'ŷВY-Rbq#d߆n[e u( ŚBL* Yw)Fuȵ񱌼~H,Ǧg^,‹G1F sjnPVwXv,iyܽ|ni'B-r1AȍV rY pFE!X/?-Wq{\DX$%۶;6љnwQ'U=_a1y5WI1]@Y1~> H][ao, eƹ$e$Q=ToCa,6Dޣ$ __;=:b/\2*Gce{MkD$>Pg¹bWzOD;6Ğ&]r!Д:oBR{ Y,eF nLkZ]? )ނZjfԎ¶Sam@MģlA"L^M$~?k hXU7f9%vH,Vit@RN6C175hNO vn:tJײq.{Zu|H\_[-)GԶ-o3 8 7d0W^ 妄޹/Yj:j~qH=GDi,qi%Q^ Q{M.*^h@~5MKu!; #Xh$1T&V)ׇTS%VA1"4핯~Ѝ 9)|8(O)bZ|X''~OBԴ|:=jXb`;mQUvՇB2=9!OBsA &GY],t@LKSO䥻 ,>n϶\HlGF!dّ .#qf62mDxVqe)ә ;ub`3ET^K MېJI d<a/,39g:g\ Մ9ݍ́بi09CA*(<ɒXUpBpm6yAzs)DŽ;O=pXүk_%ţHPO yu<.VU=i0)!b ɯ6~b&Ex `"v۽n$K= *0Q_}j0{ L7q,uO֮#RxIBw&RFҤFfϗs´y%1TۜNNiXa,7\T|!9wQF`؄2-r;tH^o>5RX4 f%p*]hqfߧ#zjDQg,˺+_i557|?| Iv;.ISxoQ0X@_,7Qܘ͜!5ˮ 7UB?>7ДsbÙf-%[)F!i:n@}CB@05nPI1,0߅pN(4떲@m eN b`]I^o-4XО؜&PM8\n EZ,>1BigG xpGY!M`E3XwyTz!~lC&ItJ߫7xrtNJt~DbNJ~Wu+n.ܵo%6pݕAfv ;BSwah墎°m+-H° G -5ˋ*{b VYwj Pj֣XݬHyVٰbU֤j 8?Щ-F?QnҀ@ Te&2pU9!C'P?}w{>U/4-YS6vi_sYmeyy>`UD<;n8ˍ|& S DK ŧ2A2$ܩ.H&^`$bڏ%~P<˸VPQeAEWb$:eLdHqdip;, ;:\kyM3 Qƈ,q` 1ۧ8a-ܬEPKVEt$xr#-F ŽϘಈ6")Mn?½Y*t0fie̲V?,wVZfyzh\Q:}tYATs?^Y<7FyuNB#7cA![W\I7BSIZ Ҏ&p}hO]?A>!-ܙ]LQq$*n=؅Wq=+|kƻ8F.=,Ohb*^3 FgXwYWK+D$~ mw~xoMZ^Mt|k6|)6ݯƑ2/3y"x_9):6,,=!O&lO7=3qYd:Y!v3}&P(Rm-%ڲ݁~ TH c#:W6 8MmRB:Ker8j[K[vs#UHd3 7q$dJoMwG"+ڥE7=$j{IQ{wx,N9E/'.]D3iKcvuSIO8N(HʢDn`(hS^ЭE‹+Tqi +䁱r5=彸7t@NK›RL)Z7ٸFY?ȸPR.v;g.vUVmJdrQrg*∀ }yB/cEqI?7yk DuʹO9G dW.ͦ䐲z Y ocu@,T~)1^X"ޛyNW]ͩc&w`u QF^ Mkj]X&9c8/T 2`\ï[ ˘_گVaRL%BC@!tyD*pB 8|GGb2Y,J$$ j-X}"fFeak,־i@gگ7il^JL8cҖޗB?O('0uB엟nuj+- ؝+5NaRWi 4)p:UEvYҤJ۰S΂V"&CV9*ddǮ* rpzO Qz]B {?L 7:}u Bm){(" [n'%Y> bts?ZW9gSuijkԍ h-Pr)3W0q"= p{Dqrh,7,oqFQ9:ћ+*:{z#_["%dNN%@Fg Y#sqOZrT垻D0hq2!f{U@rbV5#LA}60R1&߷[aݖ,.ma9| g J}rLMn>kPl2G{HȣΗIHҟ?M!0c"Ə̘ f'Ts[ԭ0W vzU8;)ZbР1u 6:F\{eׇK}~No7D̀ 2AB;-^<1h]"]f$>6m FύB?~< p, 2437, ڗK* ~HV ^Mx#9}ɫ>o)D,Oz|WCWFuB|@G ](-³gf ><ڲVQDk"nx:d[~؍6qKy"yy'14vIKz[!xPiĴ oJv>m"qAWJ !o?+׈if5ޞ@/2h9;d'`3Wb!ԉ Muyh ^r M{8HaCcRX7S~YKb}FE,;^oIdk&{g/ht(_ӅयẄ́* )uQj:H{wD*}Pq JkG A *bYlIח I*4%%i":uZ@jmp` <)΃lL=bQ'~h I}o{n/26#\,eIr KpJݜ9T|R4"KRܿ>Z[X;6TBjvیK:!~c_ψ/m㪡\ń/PEkXF9me-?#e yuz֖.oPK=)lanɧ4É}ȄՊt#:ͺ-@un=i$)HUͨ̅ !LN.lxGM"\x1mVT YOoV}' yPeg61gm?gKcʡy$5gdv8ni4y ܆^aok<t_w@e1B6-LbĒP~mے`څ8f.~7q͆X` Yȱ$ҿ1Ғ !Qb kjRY؂-?)h?Ph^{^4L7n/CC_e~fuEv'o|2ZW&1K“ԳX)³XM= cBr1o!z 5E*^w]Ox`6rK 9ʓ%2h{1|v,UjE;E1뎣Ңu=8xbrKV iGub?HR,Wz%gT rKIsmX! wlkQѠϟB׹s%$ǫ^0R3uG(5R`шR0?e ixqc=Gݍt2U4m#ao"KD+`KgS^7%6/lͣvj=6Mk}_@ ΒJ(IJ? ug )Ea{=9d 0g]1GQ{jC2ZQi`S7tJ?yDp`TAy`[o;(P< _@ֺyX(m]pwUO xT[U3FEK)- .+ qϰooqd y̓N)咬Nmto ϩ.:gٸ qlj囼ɲ Ru-]ȡoǓ'-M+2'IȣZA cRӞ]g]CMdxC)\TQ\)(G ĕ&zd+S|?tk!D騄ӈPhIG]x!BtBk&|(B-Ur:D=lX5Ď[=,vg| eΛEoHCTIO|'ᛏb؜ X_>SD-k`4BmmjQTwd֔xQ:@wƛAVZnEb_I"\!76`?b,IHOtē(6{fcϊ0K>qP_D_؊۴'5iB5j4`L'Ꮙz`d*z;V\}5Pj͈f2`," ˮk.tH|Ƥh;sw^uem=Ǿȉ,Z칿gP~]Ll{ |A:)jUp&)JoI델|<8;fq}%wEu;ABNtn@rؑ2 Pc P󸇫V2/>2ֻؔ?fh1hjSjC\P2nש߭*`Ϩ"sQ߀dE'xsQ$Io&9ӕA~}{s%YIQvE **쑹9֨Pz,PN-EEa& >zɧ#6y!IiG+%vF|6| jյϲ [Ej;I[-pskH(uܚ6ՉM^ g;\.fcdQ;}O7 ̰P̪o8 iboJv:LQRLa)S#B6Ǝ Rcx'ȇ§ 1es]x*$ y1!5T!7A9,m4߼I j!pdUb`*rHvqt)['ڋR>[퀫[@#UZ.RoCj%щ w4[{:R4}rl M&t@ƭjȴT!1Qa[{2Axx(hͪE 'SSӽ<~;  d.>@m]mw S3wz7w%ŧ+K^G6۬}15 .rEBm@^^LrEm K8FuR6XQaK"fw>!r9ͺ*&# #v0^ JÃd)zl\|OiYR7`]MvY3ďX/h <;1ReT1#|jRj _KIOd ;QKy(\ (LRw[>xCtDMւ#!3EWL 2ptwRsڐҩIÅrUϖ)Ht+^4 =E&o8N"W> ~DŸo/Kz-yBԊH=ODd_uw,/AgC7ֈ*dme+%sbc_ xF%<Ӓtj+jY d\#pTw <7` ]5Ҩd݁W]oy8Ep!Wd p1]M{^5#.2YC="7Koq~XN3re;!PeK'?}~$y@whEҞ0X\omo`KjmbT2`Ւݑ6..=3$A# z Q*VE<ڪ>"\}Seݦ]C~DlU( =n_ǁɋ-&&R&1/;.8Mo-k-Pz;{)m=aqש_rMd<\ ax]N(h0;mUe SL߹G،ě9 EiƱF s_c0hO[(xDVB>13[%N 'Ntev~8#7] E`Dܻ ӳHꞫ1Zj`>rS413Tfotȑ4%㩠mB_\ר@,.!eB}id VmzMlશa'=j ' JA =>+durT؝h}~W)CG*xLhwŀWF(ҳ珛L^q" ,`4\`ߓ"[iNbxp;p& ~;adzqZ";ö)-j5 =ckl_a! w 3͘i6Gݢ\6~,ܦTd :9֟8&5VM 9VS"´tbƜ -Gu J?KmUq$2PC|Y. }"tϨPFՈ+ &`Lmq\&g}[t,}b}1s }3<Ȟs֋UA̪{NPF>ld8beH}@IAP-80Mk8HNbkXꩍ fwxdDW$B\41OPg/vqAz 㻟 OϯU`9 gEgn*;IR;z&^W.Ab7bqSbv<к[˒@eZ7=tWqIk}O1k4?a9)5ăǮY YZ