xorg-x11-server-Xvfb-21.1.11-150600.5.9.1<>,gdgڲp9|gF]1Ei⪅gV\ ۹0wh@+㫞6a$b}H1*i)xH6KиnCOMdk {fe ynT Jr `(y9π2B;d$ľX<35 dl[YSڛ적>{+-LU\!tKnus:P̨uL0rxGS 2ӥ3w.[&F0:l9 C =px76IcHJhh(I[|D>D D? 4d , Atx (, . 0 4 u x|@(t8|9:BFGHIXYZ[\] ^%b/cdbegfjlluvw \x `y dz        0Cxorg-x11-server-Xvfb21.1.11150600.5.9.1Virtual Xserver XvfbThis package contains the virtual Xserver Xvfb.gڲibs-power9-20*HSUSE Linux Enterprise 15SUSE LLC MIThttps://www.suse.com/System/X11/Servers/XF86_4http://xorg.freedesktop.org/linuxppc64le*Hgڲcf8e689bc7b776fb951021cb90041ecaf30d6eacd99c733b5a1bb054bcff19derootrootxorg-x11-server-21.1.11-150600.5.9.1.src.rpmxorg-x11-Xvfbxorg-x11-server-Xvfbxorg-x11-server-Xvfb(ppc-64)xorg-x11-server:/usr/bin/Xvfb@@@@@@@@@@@@@@@@@@@@@    MesalibGL.so.1()(64bit)libXau.so.6()(64bit)libXdmcp.so.6()(64bit)libXfont2.so.2()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.26)(64bit)libc.so.6(GLIBC_2.27)(64bit)libc.so.6(GLIBC_2.32)(64bit)libc.so.6(GLIBC_2.33)(64bit)libc.so.6(GLIBC_2.34)(64bit)libc.so.6(GLIBC_2.38)(64bit)libcrypto.so.3()(64bit)libcrypto.so.3(OPENSSL_3.0.0)(64bit)libm.so.6()(64bit)libm.so.6(GLIBC_2.17)(64bit)libm.so.6(GLIBC_2.29)(64bit)libm.so.6(GLIBC_2.35)(64bit)libpixman-1.so.0()(64bit)libsystemd.so.0()(64bit)libsystemd.so.0(LIBSYSTEMD_209)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)xkbcompxkeyboard-config3.0.4-14.6.0-14.0-15.2-14.14.3g`@g@g@f@fe@eȶeȶee@eoe@e@em@e9@d(dc=@cT@cccR@c@c.cEch@ch@cb[cb[cObγbγbγby@bzSbDF@b-b@b@b@a@a@aa@a@a@aaaaay?@a`]`]`:@`9@``P@`}p`u`t6@`?z@_@_@_0@_ts@_s!_q@_l@_a@_X_G@_D@_$^)@^@^^@^W@^%@^@]@]@]@]@]]y@]i]@1@\\O\@\v{\I\A\,[@[@[@[ā@[t[i[\Z[Xf@[P}@[D[:[2*[*A[@Z@ZZԐ@ZJ@Z2@ZZ Z}@ZTZ?Z/Z@Z YY@YY@Yh@Yg`Y_wY[@Y;@Y:Y6@XX @X+X@XpXXwoXN@X,J@XW@W@W@WDB@W9@W/*@W'A@W#LW @W @W @WKWW@V@Vn@V3VVm@VxVVV&@VV@V@VV@VGVVVUVA@V0V0V7@UU@U@UUzUuUn@Ui@U0U:T!TTTԬT[@T[@Tk4T`TN3sndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.combjorn.lie@gmail.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.commgorse@suse.comdmueller@suse.comdmueller@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comtzimmermann@suse.desndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comdmueller@suse.commeissner@suse.comsndirsch@suse.combjorn.lie@gmail.comsndirsch@suse.comdmueller@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comtzimmermann@suse.detzimmermann@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comdmueller@suse.comsndirsch@suse.combjorn.lie@gmail.comismail@i10z.compatrik.jakobsson@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comtobias.klausmann@freenet.desndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.commgorse@suse.combjorn.lie@gmail.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comfcrozat@suse.combjorn.lie@gmail.combjorn.lie@gmail.combjorn.lie@gmail.comsndirsch@suse.combjorn.lie@gmail.comsndirsch@suse.comsndirsch@suse.comtobias.johannes.klausmann@mni.thm.demliska@suse.czjengelh@inai.desndirsch@suse.comsndirsch@suse.comsndirsch@suse.commsrb@suse.comsndirsch@suse.commsrb@suse.comsndirsch@suse.comtobias.johannes.klausmann@mni.thm.demsrb@suse.comtobias.johannes.klausmann@mni.thm.dejdelvare@suse.desndirsch@suse.comtiwai@suse.defcrozat@suse.comsndirsch@suse.commsrb@suse.comsndirsch@suse.commsrb@suse.comtobias.johannes.klausmann@mni.thm.demsrb@suse.commsrb@suse.commsrb@suse.commsrb@suse.comfcrozat@suse.combwiedemann@suse.comsndirsch@suse.commwilck@suse.comtobias.johannes.klausmann@mni.thm.demsrb@suse.comrbrown@suse.commsrb@suse.comtobias.johannes.klausmann@mni.thm.detobias.johannes.klausmann@mni.thm.deilya@ilya.pp.uasndirsch@suse.comsndirsch@suse.commsrb@suse.comsndirsch@suse.comsndirsch@suse.comopensuse@dstoecker.desndirsch@suse.comtobias.johannes.klausmann@mni.thm.detobias.johannes.klausmann@mni.thm.dedenis.kondratenko@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comtobias.johannes.klausmann@mni.thm.defbui@suse.comtobias.johannes.klausmann@mni.thm.dezaitor@opensuse.orgtobias.johannes.klausmann@mni.thm.detobias.johannes.klausmann@mni.thm.demstaudt@suse.comeich@suse.comeich@suse.comeich@suse.comsndirsch@suse.comsndirsch@suse.comeich@suse.comeich@suse.comeich@suse.comeich@suse.comtobias.johannes.klausmann@mni.thm.detobias.johannes.klausmann@mni.thm.deeich@suse.comeich@suse.comtobias.johannes.klausmann@mni.thm.delbsousajr@gmail.comeich@suse.comeich@suse.comeich@suse.comeich@suse.comtobias.johannes.klausmann@mni.thm.deeich@suse.comeich@suse.comfcrozat@suse.comeich@suse.comeich@suse.comeich@suse.comhrvoje.senjan@gmail.comeich@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comeich@suse.comtiwai@suse.deeich@suse.comtobias.johannes.klausmann@mni.thm.detobias.johannes.klausmann@mni.thm.demsrb@suse.comantoine.belvire@laposte.netmsrb@suse.comeich@suse.comnormand@linux.vnet.ibm.commsrb@suse.comdimstar@opensuse.orgsndirsch@suse.comtobias.johannes.klausmann@mni.thm.deeich@suse.comtobias.johannes.klausmann@mni.thm.demsrb@suse.comsndirsch@suse.comledest@gmail.comsndirsch@suse.com- U_CVE-2022-49737-dix-Hold-input-lock-for-AttachDevice.patch * Xorg may crash when client applications use easystroke for mouse gestures (CVE-2022-49737, bsc#1239750)- U_CVE-2025-26594-0001-Cursor-Refuse-to-free-the-root-cursor.patch U_CVE-2025-26594-0002-dix-keep-a-ref-to-the-rootCursor.patch * Use-after-free of the root cursor (CVE-2025-26594, bsc#1237427) - U_CVE-2025-26595-0001-xkb-Fix-buffer-overflow-in-XkbVModMaskText.patch * Buffer overflow in XkbVModMaskText() (CVE-2025-26595, bsc#1237429) - U_CVE-2025-26596-0001-xkb-Fix-computation-of-XkbSizeKeySyms.patch * Heap overflow in XkbWriteKeySyms() (CVE-2025-26596, bsc#1237430) - U_CVE-2025-26597-0001-xkb-Fix-buffer-overflow-in-XkbChangeTypesOfKey.patch * Buffer overflow in XkbChangeTypesOfKey() (CVE-2025-26597, bsc#1237431) - U_CVE-2025-26598-0001-Xi-Fix-barrier-device-search.patch * Out-of-bounds write in CreatePointerBarrierClient() (CVE-2025-26598, bsc#1237432) - U_CVE-2025-26599-0001-composite-Handle-failure-to-redirect-in-compRedirect.patch U_CVE-2025-26599-0002-composite-initialize-border-clip-even-when-pixmap-al.patch * Use of uninitialized pointer in compRedirectWindow() (CVE-2025-26599, bsc#1237433) - U_CVE-2025-26600-0001-dix-Dequeue-pending-events-on-frozen-device-on-remov.patch * Use-after-free in PlayReleasedEvents() (CVE-2025-26600, bsc#1237434) - U_CVE-2025-26601-0001-sync-Do-not-let-sync-objects-uninitialized.patch U_CVE-2025-26601-0002-sync-Check-values-before-applying-changes.patch U_CVE-2025-26601-0003-sync-Do-not-fail-SyncAddTriggerToSyncObject.patch U_CVE-2025-26601-0004-sync-Apply-changes-last-in-SyncChangeAlarmAttributes.patch * Use-after-free in SyncInitTrigger() (CVE-2025-26601, bsc#1237435)- U_xkb-Fix-buffer-overflow-in-_XkbSetCompatMap.patch * Heap-based buffer overflow privilege escalation in _XkbSetCompatMap (CVE-2024-9632, bsc#1231565)- U_render-Avoid-possible-double-free-in-ProcRenderAddGl.patch * fixes regression for security fix for CVE-2024-31083 (bsc#1222312, boo#1222442, gitlab xserver issue #1659)- U_CVE-2024-31080-Xi-ProcXIGetSelectedEvents-needs-to-use-unswapped-le.patch * Xi: ProcXIGetSelectedEvents needs to use unswapped length (CVE-2024-31080, bsc#1222309) - U_CVE-2024-31081-Xi-ProcXIPassiveGrabDevice-needs-to-use-unswapped-le.patch * Xi: ProcXIPassiveGrabDevice needs to use unswapped length to send reply (CVE-2024-31081, bsc#1222310) - U_CVE-2024-31082-Xquartz-ProcAppleDRICreatePixmap-needs-to-use-unswap.patch * Xquartz: ProcAppleDRICreatePixmap needs to use unswapped length to send reply (CVE-2024-31082, bsc#1222311) - U_CVE-2024-31083-render-fix-refcounting-of-glyphs-during-ProcRenderAd.patch * render: fix refcounting of glyphs during ProcRenderAddGlyphs (CVE-2024-31083, bsc#1222312)- Release 21.1.11 also covers fixes for security issue CVE-2022-46340 and bug numbers bsc#1205874, bsc#1217765- Release 21.1.11 covers fixes for the following bug numbers, which are not mentioned in this changelog before: bsc#1218845, bsc#1218846, bsc#1216261, bsc#1216133, bsc#1216135- Release 21.1.11 supersedes the following patches still used with xorg-x11-server 21.1.4 on sle15-sp5/Leap 15.5 and not mentioned in this changelog as superseded before: * U_Xext-fix-invalid-event-type-mask-in-XTestSwapFakeInp.patch * U_bsc1216133-mi-reset-the-PointerWindows-reference-on-screen-swit.patch * U_bsc1216135-Xi-randr-fix-handling-of-PropModeAppend-Prepend.patch * U_bsc1216261-0001-mi-fix-CloseScreen-initialization-order.patch * U_bsc1216261-0002-fb-properly-wrap-unwrap-CloseScreen.patch * U_bsc1216261-0003-dix-always-initialize-pScreen-CloseScreen.patch * bsc1218582-0001-dix-allocate-enough-space-for-logical-button-maps.patch * bsc1218583-0001-dix-Allocate-sufficient-xEvents-for-our-DeviceStateN.patch * bsc1218583-0002-dix-fix-DeviceStateNotify-event-calculation.patch * bsc1218583-0003-Xi-when-creating-a-new-ButtonClass-set-the-number-of.patch * bsc1218584-0001-Xi-flush-hierarchy-events-after-adding-removing-mast.patch * bsc1218585-0001-Xi-do-not-keep-linked-list-pointer-during-recursion.patch * bsc1218585-0002-dix-when-disabling-a-master-float-disabled-slaved-de.patch * U_bsc1218845-glx-Call-XACE-hooks-on-the-GLX-buffer.patch * U_bsc1218846-ephyr-xwayland-Use-the-proper-private-key-for-cursor.patch- xserver sources of this release fixes segfault in Xvnc (bsc#1219311)- no longer (build-)require obsolete Xprint/XprintUtil- Update to version 21.1.11 * This release contains fixes for the issues reported in today's security advisory: https://lists.x.org/archives/xorg/2024-January/061525.html * CVE-2023-6816 (bsc#1218582) * CVE-2024-0229 (bsc#1218583) * CVE-2024-21885 (bsc#1218584) * CVE-2024-21886 (bsc#1218585) * CVE-2024-0408 * CVE-2024-0409 - supersedes the following patches * U_xephyr-Don-t-check-for-SeatId-anymore.patch * U_bsc1217765-Xi-allocate-enough-XkbActions-for-our-buttons.patch * U_bsc1217766-randr-avoid-integer-truncation-in-length-check-of-Pr.patch- u_miCloseScreen_check_for_null_pScreen_dev_private.patch * miCloseScreen check for null pScreen dev private (bsc#1218176); another regression introduced by U_bsc1216261-0002-fb-properly-wrap-unwrap-CloseScreen.patch- n_xserver-optimus-autoconfig-hack.patch u_randr-Do-not-crash-if-slave-screen-does-not-have-pro.patch u_xfree86-activate-GPU-screens-on-autobind.patch * check dixPrivateKeyRegistered(rrPrivKey) before calling rrGetScrPriv() to avoid xserver crash when Xinerama is enabled (boo#1218240) - ------------------------------------------------------------------- U_bsc1217765-Xi-allocate-enough-XkbActions-for-our-buttons.patch * Out-of-bounds memory write in XKB button actions (CVE-2023-6377, ZDI-CAN-22412, ZDI-CAN-22413, bsc#1217765) - U_bsc1217766-randr-avoid-integer-truncation-in-length-check-of-Pr.patch * Out-of-bounds memory read in RRChangeOutputProperty and RRChangeProviderProperty (CVE-2023-6478, ZDI-CAN-22561, bsc#1217766)- Update to version 21.1.9 * This release contains fixes for CVE-2023-5367, CVE-2023-5380 and CVE-2023-5574 as reported in today's security advisory: https://lists.x.org/archives/xorg-announce/2023-October/003430.html - adjusted u_Use-better-fallbacks-to-generate-cookies-if-arc4rand.patch- Update to version 21.1.8 (CVE-2023-1393): * This release contains the fix for CVE-2023-1393 * composite: Fix use-after-free of the COW * xkbUtils: use existing symbol names instead of deleted deprecated ones - Drop U_xserver-composite-Fix-use-after-free-of-the-COW.patch: Fixed upstream - Switch back to tarball release, drop source service, add keyring and sig files.- U_xserver-composite-Fix-use-after-free-of-the-COW.patch * overlay window use-after-free (CVE-2023-1393, ZDI-CAN-19866, bsc#1209543)- Update to version xorg-server-21.1.7: * This release contains the fix for CVE-2023-0494 in today's security advisory: https://lists.x.org/archives/xorg-announce/2023-February/003320.html It also fixes a second possible OOB access during EnqueueEvent and a crasher caused by ResourceClientBits not correctly honouring the MaxClients value in the configuration file. - supersedes U_Xi-fix-potential-use-after-free-in-DeepCopyPointerCl.patch, U_xorg-server-oob-read-enqueue-event.patch- U_Xi-fix-potential-use-after-free-in-DeepCopyPointerCl.patch * DeepCopyPointerClasses use-after-free (CVE-2023-0494, ZDI-CAN-19596, bsc#1207783)- rename u_xorg-server-oob-read-enqueue-event.patch to U_xorg-server-oob-read-enqueue-event.patch since it's already upstream- Add u_xorg-server-oob-read-enqueue-event.patch: fix an out-of-bounds read in EnqueueEvent.- Update to version xorg-server-21.1.6: * xserver 21.1.6 * Xext: fix invalid event type mask in XTestSwapFakeInput * xkb: fix some possible memleaks in XkbGetKbdByName * xkb: proof GetCountedString against request length attacks * xquartz: Fix some formatting * XQuartz: stub: Call LSOpenApplication instead of fork()/exec() - drop the following upstream patches: U_xkb-proof-GetCountedString-against-request-length-at.patch U_xkb-fix-some-possible-memleaks-in-XkbGetKbdByName.patch- Update to version xorg-server-21.1.5: * xkb: reset the radio_groups pointer to NULL after freeing it * Xi: avoid integer truncation in length check of ProcXIChangeProperty * Xi: return an error from XI property changes if verification failed * Xext: free the screen saver resource when replacing it * Xext: free the XvRTVideoNotify when turning off from the same client * Xi: disallow passive grabs with a detail > 255 * Xtest: disallow GenericEvents in XTestSwapFakeInput * meson: Don't build COMPOSITE for XQuartz * xquartz: Move default applications list outside of the main executable * xquartz: Remove unused macro (X11LIBDIR) - drop the following upstream patches: U_0007-xkb-reset-the-radio_groups-pointer-to-NULL-after-fre.patch U_0002-Xi-return-an-error-from-XI-property-changes-if-verif.patch U_0003-Xi-avoid-integer-truncation-in-length-check-of-ProcX.patch U_0004-Xi-disallow-passive-grabs-with-a-detail-255.patch U_0005-Xext-free-the-screen-saver-resource-when-replacing-i.patch U_0006-Xext-free-the-XvRTVideoNotify-when-turning-off-from-.patch U_0001-Xtest-disallow-GenericEvents-in-XTestSwapFakeInput.patch- U_0007-xkb-reset-the-radio_groups-pointer-to-NULL-after-fre.patch * XkbGetKbdByName use-after-free (ZDI-CAN-19530, CVE-2022-4283, bsc#1206017)- U_0001-Xtest-disallow-GenericEvents-in-XTestSwapFakeInput.patch * Server XTestSwapFakeInput stack overflow (ZDI-CAN 19265, CVE-2022-46340, bsc#1205874) - U_0002-Xi-return-an-error-from-XI-property-changes-if-verif.patch * Xi: return an error from XI property changes if verification failed (no ZDI-CAN id, no CVE id, bsc#1205875) - U_0003-Xi-avoid-integer-truncation-in-length-check-of-ProcX.patch * Server XIChangeProperty out-of-bounds access (ZDI-CAN 19405, CVE-2022-46344, bsc#1205876) - U_0004-Xi-disallow-passive-grabs-with-a-detail-255.patch * Server XIPassiveUngrabDevice out-of-bounds access (ZDI-CAN 19381, CVE-2022-46341, bsc#1205877) - U_0005-Xext-free-the-screen-saver-resource-when-replacing-i.patch * Server ScreenSaverSetAttributes use-after-free (ZDI-CAN 19404, CVE-2022-46343, bsc#1205878) - U_0006-Xext-free-the-XvRTVideoNotify-when-turning-off-from-.patch * Server XvdiSelectVideoNotify use-after-free (ZDI-CAN 19400, CVE-2022-46342, bsc#1205879)- Release 21.1 covers bugfixes and JIRA tickets for bsc#1176015,bsc#1182510,bsc#1182884,bsc#1184072,bsc#1184543,bsc#1184906,bsc#1186092,bsc#1188970,bsc#1194159,bsc#1196577,bsc#1197046,bsc#1197269,bsc#1200076,fdo#574,jsc#SLE-18653,jsc#SLE-8470- Release 21.1 supersedes the following patches still used with xorg-x11-server 1.20.3 on sle15-sp4/Leap 15.4: * U_0002-DRI2-Add-another-Coffeelake-PCI-ID.patch * U_0002-Fix-crash-on-XkbSetMap.patch * U_0003-Fix-crash-on-XkbSetMap.patch * U_0003-dri2-Sync-i965_pci_ids.h-from-mesa.patch * U_0004-dri2-Set-fallback-driver-names-for-Intel-and-AMD-chi.patch * U_0005-dri2-Sync-i965_pci_ids.h-from-mesa-iris_pci_ids.h.patch * U_build-glx-Lower-gl-version-to-work-with-libglvnd.patch * U_glamor-Make-pixmap-exportable-from-gbm_bo_from_pixma.patch * U_hw_do-not-include-sys-io-with-glibc.patch * U_meson-Fix-another-reference-to-gl-9.2.0.patch * U_modesetting-Fix-broken-manpage-in-autoconf-build.patch * U_present-wnmd-Fix-use-after-free-on-CRTC-removal.patch * U_present-wnmd-Relax-assertion-on-CRTC-on-abort_vblank.patch * U_xfree86-Change-displays-array-to-pointers-array-to-f.patch * U_xfree86-Fix-NULL-pointer-dereference-crash.patch * U_xkbsetdeviceinfo.patch * u_sync-pci-ids-with-Mesa-21.2.4.patch * u_xf86-Accept-devices-with-the-simpledrm-driver.patch * u_xichangehierarchy-CVE-2020-14346.patch * u_xkb-CVE-2020-14345.patch * u_xkb-CVE-2020-14360.patch- removed N_Disable-HW-Cursor-for-cirrus-and-mgag200-kernel-modules.patch * meanwhile cirrus and mgag200 Kernel drivers have been rewritten multiple times and no longer have (broken) hardware cursor- u_xf86-Accept-devices-with-the-kernels-ofdrm-driver.patch * Add workaround to support ofdrm- U_xkb-proof-GetCountedString-against-request-length-at.patch * security update for CVE-2022-3550 (bsc#1204412) - U_xkb-fix-some-possible-memleaks-in-XkbGetKbdByName.patch * security update for CVE-2022-3551 (bsc#1204416)- rename u_sync-pci-ids-with-Mesa-22.0.0.patch to u_sync-pci-ids-with-Mesa.patch (currently synced with Mesa 22.1.3)- u_sync-pci-ids-with-Mesa-22.0.0.patch * synced with Mesa 22.1.3; just adding a PCI ID for vmware was needed- Update to version 21.1 * This release fixes 2 recently reported security vulnerabilities in xkb, several regressions since 1.20.x and a number of miscellaneous bugs. - supersedes the following security patches * U_boo1194181-001-xkb-swap-XkbSetDeviceInfo-and-XkbSetDeviceInfoCheck.patch * U_boo1194179-001-xkb-rename-xkb_h-to-xkb-procs_h.patch * U_boo1194179-002-xkb-add-request-length-validation-for-XkbSetGeometry.patch - supersedes U_Fix-build-with-gcc-12.patch- U_boo1194181-001-xkb-swap-XkbSetDeviceInfo-and-XkbSetDeviceInfoCheck.patch * Out-Of-Bounds Access in CheckSetDeviceIndicators() (CVE-2022-2320, ZDI-CAN-16070, bsc#1194181) - U_boo1194179-001-xkb-rename-xkb_h-to-xkb-procs_h.patch, U_boo1194179-002-xkb-add-request-length-validation-for-XkbSetGeometry.patch * Out-Of-Bounds Access in _CheckSetSections() (CVE-2022-2319, ZDI-CAN-16062, bsc#1194179)- add n_raise_default_clients.patch- disable -z now linking for now, as there are some missing symbol issues. (boo#1197994)- u_sync-pci-ids-with-Mesa-22.0.0.patch * sync pci ids with Mesa 22.0.0- U_Fix-build-with-gcc-12.patch * render: Fix build with gcc 12 (glfdo#xorg/xserver!853).- U_xephyr-Don-t-check-for-SeatId-anymore.patch * fix mouse/keyboard focus in Xephyr (boo#1194658, github issue#1289)- fix bashisms in pre_checkins.sh (bsc#1195391)- u_xfree86-activate-GPU-screens-on-autobind.patch * Part of the original patch by Dave Airlie has landed 078277e4d92f05a90c4715d61b89b9d9d38d68ea, this contains the remainder of what was in SUSE before Xorg 21.1. (github issue#1254, boo#1192751)- Update to version 21.1.3 * This release fixes several regressions since 1.20.x and 21.1.1 + glx/dri: Filter out fbconfigs that don't have a supported pixmap format + xf86/logind: Fix compilation error when built without logind/platform bus + xf86/logind: fix missing call to vtenter if the platform device is not paused + Convert more funcs to use InternalEvent. + os: Try to discover the current seat with the XDG_SEAT var first- Update to version 21.1.2 * This release fixes 4 recently reported security vulnerabilities and several regressions. * In particular, the real physical dimensions are no longer reported by the X server anymore as it was deemed to be a too disruptive change. X server will continue to report DPI as 96. - supersedes U_hw-xfree86-Propagate-physical-dimensions-from-DRM-co.patch - supersedes U_rendercompositeglyphs.patch - supersedes U_xfixes-Fix-out-of-bounds-access-in-ProcXFixesCreateP.patch - supersedes U_Xext-Fix-out-of-bounds-access-in-SProcScreenSaverSus.patch - supersedes U_record-Fix-out-of-bounds-access-in-SwapCreateRegiste.patch- U_xfixes-Fix-out-of-bounds-access-in-ProcXFixesCreateP.patch * CVE-2021-4009/ZDI-CAN-14950 (bsc#1190487) The handler for the CreatePointerBarrier request of the XFixes extension does not properly validate the request length leading to out of bounds memory write. - U_Xext-Fix-out-of-bounds-access-in-SProcScreenSaverSus.patch * CVE-2021-4010/ZDI-CAN-14951 (bsc#1190488) The handler for the Suspend request of the Screen Saver extension does not properly validate the request length leading to out of bounds memory write. - U_record-Fix-out-of-bounds-access-in-SwapCreateRegiste.patch * CVE-2021-4011/ZDI-CAN-14952 (bsc#1190489) The handlers for the RecordCreateContext and RecordRegisterClients requests of the Record extension do not properly validate the request length leading to out of bounds memory write.- U_rendercompositeglyphs.patch * X.Org Server SProcRenderCompositeGlyphs Out-Of-Bounds Access Privilege Escalation Vulnerability [CVE-2021-4008, ZDI-CAN-14192] (boo#1193030)- u_Support-configuration-files-under-run-X11-xorg.conf..patch - u_Add-udev-scripts-for-configuration-of-platform-devic.patch - u_Add-udev-rule-for-HyperV-devices.patch * Remove udev-based configuration - u_Revert-xf86-Accept-devices-with-the-simpledrm-driver.patch * Restore simpledrm workaround - u_xf86-Accept-devices-with-the-hyperv_drm-driver.patch * Add workaround to support hyperv_drm- u_pci-primary-Fix-up-primary-PCI-device-detection-for-the-platfrom-bus.patch * Fix SEGFAULT when parsing bus IDs of NULL (boo#1193250) - u_Support-configuration-files-under-run-X11-xorg.conf..patch * Support configuration files under /run. Required for generating configuration files via udev. (boo#1193250) - u_Add-udev-scripts-for-configuration-of-platform-devic.patch * Generate configuration files for platform devices (boo#1193250) - u_Revert-xf86-Accept-devices-with-the-simpledrm-driver.patch * Code has been obsoleted by udev patchset (boo#1193250) - u_Add-udev-rule-for-HyperV-devices.patch * Same as for platform devices, but on HyperV (boo#1193250)- enable build of Xorg on s390x (jira#SLE-18632)- U_hw-xfree86-Propagate-physical-dimensions-from-DRM-co.patch * reverse apply this one to go back to fixed 96 dpi (gitlab fdo/xserver issue#1241) - N_fix-dpi-values.diff * back to version for xserver < 21.1.0- Update to version 21.1.1 * s/__/@/ in inputtestdrv manpage * Make xf86CompatOutput() return NULL when there are no privates * Makefile.am: Add missing meson build files to release tarball- Update to version 21.1.0 * The meson support is now fully mature. While autotools support will still be kept for this release series, it will be dropped afterwards. * Glamor support for Xvfb. * Variable refresh rate support in the modesetting driver. * XInput 2.4 support which adds touchpad gestures. * DMX DDX has been removed. * X server now correctly reports display DPI in more cases. This may affect rendering of client applications that have their own workarounds for hi-DPI screens. * A large number of small features and various bug fixes. - updated xorg-server-provides - supersedes patches * U_Fix-segfault-on-probing-a-non-PCI-platform-device-on.patch * U_dix-window-Use-ConfigureWindow-instead-of-MoveWindow.patch * U_glamor_egl-Reject-OpenGL-2.1-early-on.patch * u_render-Cast-color-masks-to-unsigned-long-before-shifting-them.patch - refreshed patches * N_fix-dpi-values.diff * N_zap_warning_xserver.diff * u_modesetting-Fix-dirty-updates-for-sw-rotation.patch * u_randr-Do-not-crash-if-slave-screen-does-not-have-pro.patch * u_vesa-Add-VBEDPMSGetCapabilities-VBEDPMSGet.patch - disabled n_xserver-optimus-autoconfig-hack.patch, which I believe is superseded by: commit 078277e4d92f05a90c4715d61b89b9d9d38d68ea Author: Dave Airlie Date: Fri Aug 17 09:49:24 2012 +1000 xf86: autobind GPUs to the screen - added pkgconfig(libxcvt) - cvt binary moved to libxcvt0 package- Update to version 1.20.13 * bugfix release - supersedes U_present-get_crtc-should-not-return-crtc-when-its-scr.patch, U_modesetting-unflip-not-possible-when-glamor-is-not-s.patch- U_modesetting-unflip-not-possible-when-glamor-is-not-s.patch * this should fixes crashes of xfce when running under qemu (boo#1188559)- add U_present-get_crtc-should-not-return-crtc-when-its-scr.patch (bsc#1188559) https://gitlab.freedesktop.org/xorg/xserver/-/issues/1195- Update to version 1.20.12 * bugfix release- Drop U_xwayland-Allow-passing-a-fd.patch: We build xwayland in a separate package now, so no need to keep this patch here.- Fix typo in %post: xbb.conf -> xkb.conf- u_modesetting-Fix-dirty-updates-for-sw-rotation.patch * Fixes broken rotation support for DRM drivers without hardware rotation support or direct vram access (bsc#1182955)- disable build of Xwayland, which is now being built in separate xwayland package with more recent sources (boo#1182677)- Update to version 1.20.11 * bugfix release - supersedes U_Fix-XChangeFeedbackControl-request-underflow.patch, U_xkb-Fix-heap-overflow-caused-by-optimized-away-min.patch- U_Fix-XChangeFeedbackControl-request-underflow.patch * Fix XChangeFeedbackControl() request underflow (CVE-2021-3472, ZDI-CAN-1259, bsc#1180128)- reenabled LTO (boo#1133294) * u_no-lto-for-tests.patch disables LTO in test/ subtree, since "-Wl,-wrap" is not supported by LTO * added "%global _lto_cflags %{?_lto_cflags} -ffat-lto-objects"- Update to version 1.20.10: * Check SetMap request length carefully. * Fix XkbSetDeviceInfo() and SetDeviceIndicators() heap overflows * present/wnmd: Translate update region to screen space * modesetting: keep going if a modeset fails on EnterVT * modesetting: check the kms state on EnterVT * configure: Build hashtable for Xres and glvnd * xwayland: Create an xwl_window for toplevel only * xwayland: non-rootless requires the wl_shell protocol * glamor: Update pixmap's devKind when making it exportable * os: Fix instruction pointer written in xorg_backtrace * present/wnmd: Execute copies at target_msc-1 already * present/wnmd: Move up present_wnmd_queue_vblank * present: Add present_vblank::exec_msc field * present: Move flip target_msc adjustment out of present_vblank_create * xwayland: Remove pending stream reference when freeing * xwayland: use drmGetNodeTypeFromFd for checking if a node is a render one * xwayland: Do not discard frame callbacks on allow commits * present/wnmd: Remove dead check from present_wnmd_check_flip * xwayland: Check window pixmap in xwl_present_check_flip2 * present/wnmd: Can't use page flipping for windows clipped by children * xfree86: Take second reference for SavedCursor in xf86CursorSetCursor * glamor: Fix glamor_poly_fill_rect_gl xRectangle::width/height handling * include: Increase the number of max. input devices to 256. * Revert "linux: Make platform device probe less fragile" * Revert "linux: Fix platform device PCI detection for complex bus topologies" * Revert "linux: Fix platform device probe for DT-based PCI" - Remove included pachtes * U_xfree86_take_second_ref_for_xcursor.patch * U_Revert-linux-Fix-platform-device-probe-for-DT-based-.patch * U_Revert-linux-Fix-platform-device-PCI-detection-for-c.patch * U_Revert-linux-Make-platform-device-probe-less-fragile.patch * U_Fix-XkbSetDeviceInfo-and-SetDeviceIndicators-heap-ov.patch * U_Check-SetMap-request-length-carefully.patch- remove unneeded python2 script 'fdi2iclass.py' from xorg-x11-server-sources subpackage (boo#1179591)- U_Check-SetMap-request-length-carefully.patch * XkbSetMap Out-Of-Bounds Access: Insufficient checks on the lengths of the XkbSetMap request can lead to out of bounds memory accesses in the X server. (ZDI-CAN 11572, CVE-2020-14360, bsc#1174908) - U_Fix-XkbSetDeviceInfo-and-SetDeviceIndicators-heap-ov.patch * XkbSetDeviceInfo Heap-based Buffer Overflow: Insufficient checks on input of the XkbSetDeviceInfo request can lead to a buffer overflow on the head in the X server. (ZDI-CAN 11389, CVE-2020-25712, bsc#1177596)- n_xorg-wrapper-anybody.patch * replace default config /etc/X11/Xwrapper, which allows anybody to use the wrapper, by a patch for the code, i.e. [#] rootonly, console, anybody allowed_users=anybody [#] yes, no, auto needs_root_rights=auto is now the default without any Xwrapper config (needs_root_rights=auto was already the default before)- u_xorg-wrapper-Xserver-Options-Whitelist-Filter.patch * replaced by improved version written by Matthias Gerstner of our security team + simplified the option parsing code a bit + changed the "ignore forbidden argument" logic into an "abort on forbidden argument" logic. This is safer and avoids surprises on the user's end that could occur if the desired command line arguments aren't effective but the Xorg server is still started. + tried to adjust to the coding style present in the file (mostly the function name) + added some logic to apply the option filtering only to non-root users when Xorg is actually started as root. This should allow for full flexibility if root calls the wrapper or if the Xorg server only runs with user privileges.- U_Fix-segfault-on-probing-a-non-PCI-platform-device-on.patch, U_Revert-linux-Fix-platform-device-PCI-detection-for-c.patch, U_Revert-linux-Fix-platform-device-probe-for-DT-based-.patch, U_Revert-linux-Make-platform-device-probe-less-fragile.patch * fix Xserver startup on Raspberry Pi 3 (boo#1176203)- n_xorg-wrapper-rename-Xorg.patch * moved Xorg to Xorg.bin and Xorg.sh to Xorg (boo#1175867) - change default for needs_root_rights to auto in Xwrapper.config (boo#1175867)- reenabled SUID wrapper for TW (boo#1175867) - u_xorg-wrapper-Xserver-Options-Whitelist-Filter.patch * Xserver option whitelist filter (boo#1175867)-Add U_xfree86_take_second_ref_for_xcursor.patch: fix use-after-free when switching VTs.- Update to version 1.20.9: * Fix XRecordRegisterClients() Integer underflow * Fix XkbSelectEvents() integer underflow * Fix XIChangeHierarchy() integer underflow * Correct bounds checking in XkbSetNames() * linux: Fix platform device probe for DT-based PCI * linux: Fix platform device PCI detection for complex bus topologies * linux: Make platform device probe less fragile * fix for ZDI-11426 * xfree86: add drm modes on non-GTF panels * present: Check valid region in window mode flips * xwayland: Handle NULL xwl_seat in xwl_seat_can_emulate_pointer_warp * xwayland: Propagate damage x1/y1 coordinates in xwl_present_flip * doc: Update URLs in Xserver-DTrace.xml * xwayland: Use a fixed DPI value for core protocol * xwayland: only use linux-dmabuf if format/modifier was advertised * hw/xfree86: Avoid cursor use after free * Update URL's in man pages * xwayland: Disable the MIT-SCREEN-SAVER extension when rootless * xwayland: Hold a pixmap reference in struct xwl_present_event * randr: Check rrPrivKey in RRHasScanoutPixmap() * modesetting: Fix front_bo leak at drmmode_xf86crtc_resize on XRandR rotation * xwayland: Store xwl_tablet_pad in its own private key * xwayland: Initialise values in xwlVidModeGetGamma() * xwayland: Fix crashes when there is no pointer * xwayland: Clear private on device removal * xwayland: Free all remaining events in xwl_present_cleanup * xwayland: Always use xwl_present_free_event for freeing Present events * present/wnmd: Free flip_queue entries in present_wnmd_clear_window_flip * present/wnmd: Keep pixmap pointer in present_wnmd_clear_window_flip * xwayland: import DMA-BUFs with GBM_BO_USE_RENDERING only * xwayland: Fix infinite loop at startup * modesetting: Disable pageflipping when using a swcursor * dix: do not send focus event when grab actually does not change - Drop patches fixed upstream: * U_0001-Correct-bounds-checking-in-XkbSetNames.patch * U_0002-Fix-XIChangeHierarchy-integer-underflow.patch * U_0003-Fix-XkbSelectEvents-integer-underflow.patch * U_0004-Fix-XRecordRegisterClients-Integer-underflow.patch * U_FixForZDI-11426.patch- U_0001-Correct-bounds-checking-in-XkbSetNames.patch * Correct bounds checking in XkbSetNames() [CVE-2020-14345 / ZDI 11428, boo#1174635] - U_0002-Fix-XIChangeHierarchy-integer-underflow.patch * Fix XIChangeHierarchy() integer underflow [CVE-2020-14346 / ZDI-CAN-11429, boo#1174638] - U_0003-Fix-XkbSelectEvents-integer-underflow.patch * Fix XkbSelectEvents() integer underflow [CVE-2020-14361 / ZDI-CAN 11573, boo#1174910] - U_0004-Fix-XRecordRegisterClients-Integer-underflow.patch * Fix XRecordRegisterClients() Integer underflow [CVE-2020-14362 / ZDI-CAN-11574, boo#1174913]- U_FixForZDI-11426.patch * Leak of uninitialized heap memory form the X server to clients on pixmap allocation (ZDI-CAN-11426, CVE-2020-14347, bsc#1174633)- move xorg_pci_ids dir from /etc/X11 to /usr/share/X11 and xorg-x11-server.macros from /etc/rpm to /usr/lib/rpm/macros.d; no longer package /etc/X11/xorg.conf.d (boo#1173056)- U_glamor_egl-Reject-OpenGL-2.1-early-on.patch * GLAMOR: no longer bail out for OpenGL drivers < 2.1 (boo#1172321)- provide/obsoletes cirrus and ast usermode driver also on openSUSE (jsc#SLE-12127)- Update to version 1.20.8+0: * Revert "dri2: Don't make reference to noClientException" * dix: Check for NULL spriteInfo in GetPairedDevice * os: Ignore dying client in ResetCurrentRequest * modesetting: remove unnecessary error message, fix zaphod leases * Fix building with `-fno-common` * xwayland: clear pixmaps after creation in rootless mode * glamor: Fix a compiler warning since the recent OOM fixes. * Restrict 1x1 pixmap filling optimization to GXcopy * Add xf86OSInputThreadInit to stub os-support as well * Fix old-style definition warning for xf86OSInputThreadInit() * xwayland/glamor-gbm: Handle DRM_FORMAT_MOD_INVALID gracefully * configure: Define GLAMOR_HAS_EGL_QUERY_DRIVER when available * modesetting: Disable atomic support by default * modesetting: Explicitly #include "mi.h" * xfree86/modes: Bail from xf86RotateRedisplay if pScreen->root is NULL * xwayland: Split up xwl_screen_post_damage into two phases * xwayland: Call glamor_block_handler from xwl_screen_post_damage * xwayland: Add xwl_window_create_frame_callback helper * xwayland: Use single frame callback for Present flips and normal updates * xwayland: Use frame callbacks for Present vblank events * xwayland: Delete all frame_callback_list nodes in xwl_unrealize_window * glamor: Propagate FBO allocation failure for picture to texture upload * glamor: Error out on out-of-memory when allocating PBO for FBO access * glamor: Propagate glamor_prepare_access failures in copy helpers * glamor: Fallback to system memory for RW PBO buffer allocation - supersedes u_fno-common.patch- specfile: reenabled XFree86-VidModeExtension (boo#1164020)- u_fno-common.patch * fix build with gcc's -fno-common option (boo#1160423)- Update to version 1.20.7+0: * xserver 1.20.7 * ospoll: Fix Solaris ports implementation to build on Solaris 11.4 * os-support/solaris: Set IOPL for input thread too * Add xf86OSInputThreadInit call from common layer into os-support layer * Add ddxInputThread call from os layer into ddx layer * os-support/solaris: Drop ExtendedEnabled global variable * glamor: Only use dual blending with GLSL >= 1.30 * modesetting: Check whether RandR was initialized before calling rrGetScrPriv * Xi: return AlreadyGrabbed for key grabs > 255 * xwayland: Do flush GPU work in xwl_present_flush * modesetting: Clear new screen pixmap storage on RandR resize * xfree86/modes: Call xf86RotateRedisplay from xf86CrtcRotate * modesetting: Call glamor_finish from drmmode_crtc_set_mode * modesetting: Use EGL_MESA_query_driver to select DRI driver if possible * glamor: Add a function to get the driver name via EGL_MESA_query_driver- Build XWayland also on s390.- Update to version 1.20.6+0: * xfree86: Test presence of isastream() * present/wnmd: Relax assertion on CRTC on abort_vblank() * os: Don't crash in AttendClient if the client is gone * dix: Call SourceValidate before GetImage * mi: Add a default no-op miSourceValidate * compiler.h: Do not include sys/io.h on ARM with glibc * xfree86: Call ScreenInit for protocol screens before GPU screens * modesetting: - Implement ms_covering_randr_crtc() for ms_present_get_crtc() - Fix ms_covering_crtc() segfault with non-xf86Crtc slave- Update to version 1.20.5+24: * Fix crash on XkbSetMap - Drop unneeded obsinfo file and tweak _service.- Update to version 1.20.5+22: * miext/sync: - Make struct _SyncObject::initialized fully ABI compatible - Fix needless ABI change * xf86: Disable unused crtc functions when a lease is revoked * xwayland: - Handle the case of windows being realized before redirection - Refactor surface creation into a separate function - Separate DamagePtr into separate window data - Do not free a NULL GBM bo - Expand the RANDR screen size limits - Update screen pixmap on output resize - Reset scheduled frames after hiding tablet cursor - Check status in GBM pixmap creation - Avoid a crash on pointer enter with a grab * GLX: - Fix previous context validation in xorgGlxMakeCurrent - Set GlxServerExports::{major,minor}Version - Add a function to change a clients vendor list - Use the sending client for looking up XID's - Add a per-client vendor mapping * xsync: Add resource inside of SyncCreate, export SyncCreate * dri2: Sync i965_pci_ids.h from mesa * Xi: Use current device active grab to deliver touch events if any * Revert "present/scmd: Check that the flip and screen pixmap pitches match" * glamor: Make pixmap exportable from `gbm_bo_from_pixmap()` - Drop patches fixed upstream: * U_xwayland-Separate-DamagePtr-into-separate-window-data.patch * 0001-xsync-Add-resource-inside-of-SyncCreate-export-SyncC.patch * 0002-GLX-Add-a-per-client-vendor-mapping.patch * 0003-GLX-Use-the-sending-client-for-looking-up-XID-s.patch * 0004-GLX-Add-a-function-to-change-a-clients-vendor-list.patch * 0005-GLX-Set-GlxServerExports-major-minor-Version.patch - Switch to gitcheckout via source service, use the stable released branch but set explicit commit used in _service.- reintroduce Xvfb subpackage (boo#1151457)- Add U_xwayland-Separate-DamagePtr-into-separate-window-data.patch and U_xwayland-Allow-passing-a-fd.patch: Needed for gnome 3.34 new and experimental xwayland on demand feature. - Rebase patches with quilt.- added patches required for NVIDIA's PRIME render offload support, which is available since release 435.xx: 0001-xsync-Add-resource-inside-of-SyncCreate-export-SyncC.patch, 0002-GLX-Add-a-per-client-vendor-mapping.patch, 0003-GLX-Use-the-sending-client-for-looking-up-XID-s.patch, 0004-GLX-Add-a-function-to-change-a-clients-vendor-list.patch, 0005-GLX-Set-GlxServerExports-major-minor-Version.patch- move xorg.conf.d snippets from /etc/X11/xorg.conf.d to /usr/share/X11/xorg.conf.d (boo#1139692)- Update to version 1.20.5: Minor bugfix release to fix some input, Xwayland, glamor, and Present issues. Thanks to all who contributed fixes and testing.- Disable LTO (boo#1133294).- Add systemd-rpm-macros BuildRequire for %tmpfiles_*.- xorg-server 1.20.4 * A variety of bugfixes across the board, but primarily in Xwayland. Thanks to all who contributed with testing and fixes!- get rid of meta packages still requiring/recommending obsolete drivers packages (boo#1121525)- provide/obsolete no longer existing xf86-video-ast, xf86-video-cirrus on sle15 (bsc#1120282)- u_xfree86-Do-not-claim-pci-slots-if-fb-slot-is-already.patch * X server does not support mixing fbdev with other drivers, so claiming pci slots when a fb slot is already claimed only leads to quiting with fatal error. (bsc#1119431)- xorg-server 1.20.3 (see changelog below) superseded the following patch we used in sle15 before (bsc#1112020, CVE-2018-14665): - U_Disable-logfile-and-modulepath-when-running-with-ele.patch- U_dix-window-Use-ConfigureWindow-instead-of-MoveWindow.patch * Fix abort triggered by some uses of screensaver. (bsc#1114822)- Update to version 1.20.3 * Disable -logfile and -modulepath when running with elevated privileges (bsc#1112020) * LogFilePrep: add a comment to the unsafe format string. * xfree86: fix readlink call- Update to version 1.20.2: Lots of bugfixes all over the map especially for modesetting, glamor and xwayland!- Update n_xserver-optimus-autoconfig-hack.patch to v5. * Fixes provider auto-configuration with nvidia proprietary driver. (bsc#1103816)- Update to version 1.20.1: This bugfix release fixes several issues in RANDR, Xwayland, glamor, the modesetting driver, and elsewhere. - Packaging changes: + Adapt patch N_Install-Avoid-failure-on-wrapper-installation.patch to work with the new version + Remove patch U_Xext-shm-Refuse-to-work-for-remote-clients.patch + Remove patch U_modesetting-use-drmmode_bo_import-for-rotate_fb.patch + Remove patch u_modesetting-Fix-cirrus-24bpp-breakage.patch + Remove patch U_exa-use-picturematchformat.patch- U_exa-use-picturematchformat.patch * Fix breakage of Xfce (bsc#1102979)- fixed build on s390(x)- u_modesetting-Fix-cirrus-24bpp-breakage.patch * Fix breakage of cirrus 24bpp support on modesetting driver (bsc#1101699)- Remove /var/lib/X11 and its symlink, it is no longer needed and doesn't work with transaction-updates (FATE#325524). - Move README.compiled to another location and use tmpfiles to copy it at runtime.- U_modesetting-use-drmmode_bo_import-for-rotate_fb.patch * fixes rotation in modesetting driver (regression with xorg-server 1.20.0, fdo#106715) * might also fix boo#1099812 ...- U_xkb-Fix-heap-overflow-caused-by-optimized-away-min.patch * Fix heap overflow caused by unexpected optimization, which was possible because of relying on undefined behavior. (boo#1099113)- U_Xext-shm-Refuse-to-work-for-remote-clients.patch * Avoid access to System V shared memory segment on the X server side for clients forwarded via SSH. Also prevent them from hanging while waiting for the reply from the ShmCreateSegment request. (boo#1097227)- Remove n_add-dummy-xf86DisableRandR.patch * After upgrade to 1.20.0 the API officially no longer includes xf86DisableRandR, so there is no need to add it back.- Update to version 1.20.0: New features: + RANDR 1.6, which enables leasing RANDR resources to a client for its exclusive use (e.g. head mounted displays) + Depth 30 support in glamor and the modesetting driver + A meson-based build system, parallel to autotools + Pageflipping support for PRIME output sinks + OutputClass device matching for xorg.conf + Input grab and tablet support in Xwayland - Remove upstream patches: + u_xorg-x11-server-reproducible.patch Solved slightly different + u_os-inputthread-Force-unlock-when-stopping-thread.patch + u_xfree86-add-default-modes-for-16-9-and-16-10.patch + U_xwayland-Don-t-process-cursor-warping-without-an-xwl.patch + U_xwayland-Give-up-cleanly-on-Wayland-socket-errors.patch + U_xwayland-avoid-race-condition-on-new-keymap.patch + U_xwayland-remove-dirty-window-unconditionally-on-unre.patch + U_0001-animcur-Use-fixed-size-screen-private.patch + U_0002-animcur-Return-the-next-interval-directly-from-the-t.patch + U_0003-animcur-Run-the-timer-from-the-device-not-the-screen.patch + U_0004-animcur-Fix-transitions-between-animated-cursors.patch + U_xfree86-Remove-broken-RANDR-disabling-logic-v4.patch + U_glx-Do-not-call-into-Composite-if-it-is-disabled.patch - Adapt patches to work with the new release: + N_zap_warning_xserver.diff + N_fix_fglrx_screendepth_issue.patch + n_xserver-optimus-autoconfig-hack.patch + u_Use-better-fallbacks-to-generate-cookies-if-arc4rand.patch + u_xorg-wrapper-build-Build-position-independent-code.patch- U_glx-Do-not-call-into-Composite-if-it-is-disabled.patch * Fixes crash when GLX is enabled and Composite disabled. (bnc#1079607)- n_add-dummy-xf86DisableRandR.patch * Add dummy xf86DisableRandR to fix linking with drivers that still call it. See explanation inside the patch. (bnc#1089601)- U_xfree86-Remove-broken-RANDR-disabling-logic-v4.patch * Fix crash on initialization when fbdev and modesetting are used together. (bnc#1068961) - u_randr-Do-not-crash-if-slave-screen-does-not-have-pro.patch * Fix crash when using randr when fbdev and modesetting are used together. (bnc#1068961)- Update and re-enable n_xserver-optimus-autoconfig-hack.patch. (bnc#1084411)- U_xwayland-Don-t-process-cursor-warping-without-an-xwl.patch, U_xwayland-Give-up-cleanly-on-Wayland-socket-errors.patch, U_xwayland-avoid-race-condition-on-new-keymap.patch, U_xwayland-remove-dirty-window-unconditionally-on-unre.patch: * Various crash and bug fixes in XWayland server (bgo#791383, bgo#790502).- Add u_xorg-x11-server-reproducible.patch to make build reproducible (boo#1047218)- U_0001-animcur-Use-fixed-size-screen-private.patch, U_0002-animcur-Return-the-next-interval-directly-from-the-t.patch, U_0003-animcur-Run-the-timer-from-the-device-not-the-screen.patch, U_0004-animcur-Fix-transitions-between-animated-cursors.patch * There is a bug in version 1.19 of the X.org X server that can cause an infinite recursion in the animated cursor code, which has been fixed by these patches (boo#1080312) - supersedes u_cursors-animation.patch (boo#1020061)- Added u_xfree86-add-default-modes-for-16-9-and-16-10.patch (boo#1075249) Improve user experience for users with 16:9 or 16:10 screens- Update to version 1.19.6: Another collection of fixes from master. There will likely be at east one more 1.19.x release in 2018.- Depend on pkgconfig's gl, egl and gbm instead of Mesa-devel. * Those dependencies are what xorg-x11-server really needs. Mesa-devel is too general and is a bottleneck in distribution build. (bnc#1071297)- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- u_os-inputthread-Force-unlock-when-stopping-thread.patch * Prevent dead lock if terminating while on inactive VT. (bnc#1062977)- Update to version 1.19.5: One regression fix since 1.19.4, and fixes for CVE-2017-12176 through CVE-2017-12187.- Update to version 1.19.4: A collection of stability fixes from the development branch, including two minor CVEs (CVE-2017-13721, CVE-2017-13723). - Remove upstream patches: + U_Xi-Do-not-try-to-swap-GenericEvent.patch + U_Xi-Verify-all-events-in-ProcXSendExtensionEvent.patch + U_Xi-Zero-target-buffer-in-SProcXSendExtensionEvent.patch + U_dix-Disallow-GenericEvent-in-SendEvent-request.patch - Adapt patches to work with the new release: + u_Use-better-fallbacks-to-generate-cookies-if-arc4rand.patch- u_cursors-animation.patch fix cursors animation (boo#1020061)- disable Xwayland for s390x again; it was wrong to enable it; there is no Wayland on s390x and will most likely never exist, since there is no gfx card on such systems and no gfx emulation either (bsc#1047173)- u_Use-better-fallbacks-to-generate-cookies-if-arc4rand.patch If arc4random_buf() is not available for generating cookies: * use getentropy(), if available (which was only recently added to glibc) * use getrandom() via syscall(), if available (there was no glibc wrapper for this syscall for a long time) * if all else fails, directly read from /dev/urandom as before, but employ O_CLOEXEC, do an OsAbort() in case the random data couldn't be read to avoid unsecure situations. Don't know if that's too hard a measure but it shouldn't actually occur except on maximum number of FDs reached (bsc#1025084)- U_Xi-Do-not-try-to-swap-GenericEvent.patch, U_Xi-Verify-all-events-in-ProcXSendExtensionEvent.patch, U_Xi-Zero-target-buffer-in-SProcXSendExtensionEvent.patch, U_dix-Disallow-GenericEvent-in-SendEvent-request.patch * Fix security issues in event handling. (bnc#1035283, CVE-2017-10971, CVE-2017-10972)- enable Xwayland also for s390x (bsc#1047173)- includes everything needed for additional sle issue entries: CVE-2017-2624, bnc#1025029, bnc#1025084, bnc#1025035- update build requirements- modesetting.ids: no longer hardcode Intel's Skylake, Broxton, and Kabylake IDs to modesetting driver; xf86-video-intel is no longer installed by default on these, so it will fallback to modesetting driver anyway; still you now can easily switch back to intel driver by installing xf86-video-intel package (boo#1042873)- Update to version 1.19.3: A couple more minor fixes, most notably a revert of a page-flipping change that regressed some drivers. - Remove upstreamd patches: + u_busfault_sigaction-Only-initialize-pointer-when-matched.patch- Update to version 1.19.2: A collection of stability fixes here across glamor, Xwayland, input, and Prime support. Also a security fix for CVE-2017-2624, a timing attack which can brute-force MIT-MAGIC-COOKIE authentication. - Remove upstream patches: + U_xfree86-Take-the-input-lock-for-xf86RecolorCursor.patch + U_xfree86-Take-the-input-lock-for-xf86ScreenCheckHWCursor.patch + U_xfree86-Take-the-input-lock-for-xf86TransparentCursor.patch- U_xfree86-Take-the-input-lock-for-xf86ScreenCheckHWCursor.patch * Add the missing input_lock() around the call into the driver's UseHWCursor() callback (bnc #1023845). - U_xfree86-Take-the-input-lock-for-xf86TransparentCursor.patch * The new input lock is missing for the xf86TransparentCursor() entry point (bnc #1023845).- U_xfree86-Take-the-input-lock-for-xf86RecolorCursor.patch * fixes random crashes in X in multihead mode if one of the monitors is vertically oriented (bnc #1023845)- N_driver-autoconfig.diff: No longer try to load "amdgpu" DDX by default for all GPUs with ATI vendor ID; this is now handled instead by an "OutputClass" section via kernel driver match, which has been added as config file to xf86-video-amdgpu driver package (bnc#1023385)- N_driver-autoconfig.diff: FGLRX does not support new x-server. This change fixes bad behavior(with empty config) when radeon ddx loads with amdgpu kernel module on SI and CIK cards, and x-server cannot start. Radeon ddx with radeon kernel module loads without any problem.- Update to version 1.19.1: First stable 1.19 release, including a few regression fixes.- Replace pkgconfig(libsystemd-*) with pkgconfig(libsystemd) Nowadays pkgconfig(libsystemd) replaces all libsystemd-* libs, which are obsolete.- Update to final 1.19.0- Exchange xorg-x11-fonts-core Requires for Recommends. The corefonts and cursors are not strickly required as long as one have a substitute such as Adwaita installed.- Update to version 1.18.99.901: - Remove upstream pachtes: + U_glamor-Remove-the-FBO-cache.patch + U_kdrive-fix-up-NewInputDeviceRequest-implementation.patch + U_kdrive-set-evdev-driver-for-input-devices-automatica.patch + U_ephyr-don-t-load-ephyr-input-driver-if-seat-option-i.patch + U_kdrive-don-t-let-evdev-driver-overwrite-existing-dev.patch + U_ephyr-ignore-Xorg-multiseat-command-line-options.patch + U_ephyr-enable-option-sw-cursor-by-default-in-multi-se.patch + U_kdrive-introduce-input-hot-plugging-support-for-udev.patch + U_kdrive-add-options-to-set-default-XKB-properties.patch + U_config-udev-distinguish-between-real-keyboards-and-o.patch - Disable u_os-connections-Check-for-stale-FDs.patch (not applicable anymore) - Adapt patches to work with the new release: + n_xserver-optimus-autoconfig-hack.patch (disabled for now as it causes problems) - Remove X.org stack version prefix. We are already atleast at verion 7.7. Plus we are updating individual components anyway. So the stack version is misleading.- Update to version 1.18.4: Another pile of backports from the devel branch, primarily in glamor, xwayland, and the modesetting driver. - Remove included patches: + u_x86emu-include-order.patch + U_modesetting-set-driverPrivate-to-NULL-after-closing-fd.patch - Update patches to reflect upstream changes: + U_glamor-Remove-the-FBO-cache.patch- U_glamor-Remove-the-FBO-cache.patch Fixes (bsc#983743) by not keeping >1 GB of VRAM busy.- U_modesetting-set-driverPrivate-to-NULL-after-closing-fd.patch: modesetting: Avoid crash in FreeRec() by NULLing a pointer which may still be used (boo#981268).- Replace N_Force-swcursor-for-KMS-drivers-without-hw-cursor-sup.patch by N_Disable-HW-Cursor-for-cirrus-and-mgag200-kernel-modules.patch Only disable HW cursor for cirrus and mgag200. This should fix a regression introduced by using modesetting for Intel gen9+ (boo#980124).- modesetting.ids: Add file for PCI IDs of ASICs which the modesetting rather than the native driver should be used for. This includes all Intel Gen9+ hardware (boo#978954).- removed u_exa-only-draw-valid-trapezoids.patch; no longer needed since pixman 0.32.0- removed no longer needed patch u_ad-hoc-fix-for-mmap-s-truncated-offset-parameter-on-.patch, see https://lists.x.org/archives/xorg-devel/2016-April/049493.html for upstream discussion; obsoleted by upstream patch https://cgit.freedesktop.org/xorg/xserver/commit/?id=4962c8c08842d9d3ca66d254b1ce4cacc4fb3756, which is already in xorg-server 1.18.3- Add permission verification for SUID wrapper - Disable SUID wrapper per default until reviewed- n_Install-Avoid-failure-on-wrapper-installation.patch: rename to: N_Install-Avoid-failure-on-wrapper-installation.patch - u_xorg-wrapper-Drop-supplemental-group-IDs.patch: Drop supplementary group privileges. - u_xorg-wrapper-build-Build-position-independent-code.patch: Build position independent.- n_Install-Avoid-failure-on-wrapper-installation.patch: Fix up build for wrapper. - Place SUID wrapper into a separate package: xorg-x11-server-wrapper- Set configure option --enable-suid-wrapper for TW: This way, the SUID wrapper is built which allows to run the Xserver as root even though the the DM instance runs as user. This allows to support drivers which require direct HW access.- Update to version 1.18.3: A few fixes relative to 1.18.2, including one fairly important performance fix to the Present extension. - Remove U_present-Only-requeue-for-next-MSC-after-flip-failure.patch The patch is included in this release.- Add patch U_present-Only-requeue-for-next-MSC-after-flip-failure.patch Fix a hang while using the present extension Bugzilla: https://bugs.freedesktop.org/show_bug.cgi?id=94515 https://bugs.freedesktop.org/show_bug.cgi?id=94596- Add automake, autoconf, libtool, c_compiler, pkgconfig(xorg-macros), pkgconfig(libudev), pkgconfig(libevdev), pkgconfig(mtdev) to Requires: of the SDK. This simplifies the build of Xserver modules.- Add support for a driver specific PCI IDs files supplementing what's in xf86VideoPtrToDriverList(). PCI ID lists may be held in /etc/X11/xorg_pci_ids (boo#972126).- Update version to 1.18.2: A big pile of updates in this one. Highlights include: * glamor is updated to use OpenGL core profiles if available, which should improve memory usage and performance on modern hardware, and got some other performance improvements for rpi and other GLES platforms * DRI2, DRI3, and Present all received correctness fixes for hangs, crashes, and other weirdness * Xwayland server has been updated to support the Xv and the xf86vidmode extensions for better compatibility, and fixed some bugs with output hotplug and pointer updates * Xwin saw improvements to window and clipboard management, and a few new keyboard layouts - Remove upstreamed patches: + U_kdrive-evdev-update-keyboard-LEDs-22302.patch- Backport upstream patches for Xephyr input hot-plugging / single-GPU multi-seat support: * U_kdrive-fix-up-NewInputDeviceRequest-implementation.patch * U_kdrive-set-evdev-driver-for-input-devices-automatica.patch * U_ephyr-don-t-load-ephyr-input-driver-if-seat-option-i.patch * U_kdrive-don-t-let-evdev-driver-overwrite-existing-dev.patch * U_ephyr-ignore-Xorg-multiseat-command-line-options.patch * U_ephyr-enable-option-sw-cursor-by-default-in-multi-se.patch * U_kdrive-introduce-input-hot-plugging-support-for-udev.patch * U_kdrive-add-options-to-set-default-XKB-properties.patch * U_kdrive-evdev-update-keyboard-LEDs-22302.patch * U_config-udev-distinguish-between-real-keyboards-and-o.patch- u_os-connections-Check-for-stale-FDs.patch Ignore file descriptor if socket or devices dies. This prevents the Xserver to loop at 100% when dbus dies (boo#954433).- Add 50-extensions.conf Disable the DGA extension by default (boo#947695).- Replaced u_confine_to_shape.diff by u_01-Improved-ConfineToShape.patch and u_02-DIX-ConfineTo-Don-t-bother-about-the-bounding-box-when-grabbing-a-shaped-window.patch.- u_pci-primary-Fix-up-primary-PCI-device-detection-for-the-platfrom-bus.patch Fix up primary device detection for the platform bus to fix the Xserver on older iMacs (boo#835975).- Update to version 1.18.1: First release in the 1.18 stable branch. Major themes are bugfixes in glamor, the modesetting driver, and the Present extension. Xwayland users may want to apply the following pair of patches in addition to this release: https://patchwork.freedesktop.org/patch/72945/raw/ https://patchwork.freedesktop.org/patch/72951/raw/ which combined fix an input issue when hotplugging monitors. Both are likely to be included in a future release unless testing discovers further problems. - Remove upstreamed patches: + ux_xserver_xvfb-randr.patch + U_systemd-logind-do-not-rely-on-directed-signals.patch + U_kdrive-UnregisterFd-Fix-off-by-one.patch + U_modesetting-should-not-reference-gbm-when-it-s-not-d.patch- u_Panning-Set-panning-state-in-xf86RandR12ScreenSetSize.patch Fix panning when configured in xorg.conf* (boo#771521).- Handle source-file-list in build not prep - N_xorg-x11-server-rpmmacros.patch: Delete: Process xorg-x11-server.macros in install- U_modesetting-should-not-reference-gbm-when-it-s-not-d.patch: fix build when gbm is not defined.- u_busfault_sigaction-Only-initialize-pointer-when-matched.patch Only initialize pointer when matched (boo#961439). - u_kdrive-UnregisterFd-Fix-off-by-one.patch -> U_kdrive-UnregisterFd-Fix-off-by-one.patch- Add test for defined macro %build_xwayland This can be used to enable the build of Xwayland and the package xorg-x11-server-wayland using a macro in projconf (boo#960487).- Split out Xwayland: * Build a package xorg-x11-server-wayland * Limit build to Factory (boo#960487).- Enable XWayland on Leap also (boo#960487)- u_kdrive-UnregisterFd-Fix-off-by-one.patch * Copy open file table correctly by avoiding an off-by-one error (boo#867483).- Update to version 1.18.0 - refreshed N_zap_warning_xserver.diff, N_Force-swcursor-for-KMS-drivers-without-hw-cursor-sup.patch - supersedes u_fbdevhw.diff, U_linux-Add-linux_parse_vt_settings-and-linux_get_keep.patch, U_linux-Add-a-may_fail-paramter-to-linux_parse_vt_sett.patch, U_systemd-logind-Only-use-systemd-logind-integration-t.patch- Update to version 1.17.4: Minor brown-bag release. The important fix here is Martin's clientsWritable change which fixes a crash when built against xproto 7.0.28. - supersedes u_0001-os-make-sure-the-clientsWritable-fd_set-is-initializ.patch- Update to version 1.17.3: Various bugfixes across the board.  The most visible changes include fixing GLX extension setup under Xwayland and other non-Xorg servers (enabling core contexts in more scenarios), and various stability fixes to glamor and the Present extension. - supersededs the following patches: * u_randr_allow_rrselectinput_for_providerchange_and_resourcechange_events.patch * u_CloseConsole-Don-t-report-FatalError-when-shutting-down.patch - removed evdev xorg.conf.d snippet since it's meanwhile shipped with evdev driver itself (since version 2.10.0)- u_vesa-Add-VBEDPMSGetCapabilities-VBEDPMSGet.patch Add VBEDPMSGetCapabilities() and VBEDPMSGet() functions (bsc#947356, boo#947493).- Backport a few upstream fixes for systemd/VT handling (boo#939838): U_linux-Add-linux_parse_vt_settings-and-linux_get_keep.patch U_linux-Add-a-may_fail-paramter-to-linux_parse_vt_sett.patch U_systemd-logind-Only-use-systemd-logind-integration-t.patch U_systemd-logind-do-not-rely-on-directed-signals.patch- Improve conditional enablement of XWayland.- Add patch u_0001-os-make-sure-the-clientsWritable-fd_set-is-initializ.patch Prevent segmentation faults with more than 256 clients (introduced by xproto 7.0.28 increasing the max client count 256 -> 512) Fdo Bug: https://bugs.freedesktop.org/show_bug.cgi?id=91316- Update to version 1.17.2: Pick up a pile of fixes from master. Notable highlights: + Fix for CVE-2015-3164 in Xwayland + Fix int10 setup for vesa + Fix regression in server-interpreted auth + Fix fb setup on big-endian CPUs + Build fix for for gcc5 - Dropped patches: + Patch110: u_connection-avoid-crash-when-CloseWellKnownConnections-gets-called-twice.patch + Patch113: u_symbols-Fix-sdksyms.sh-to-cope-with-gcc5.patch + Patch116: U_os-XDMCP-options-like-query-etc-should-imply-listen.patch + Patch118: U_int10-Fix-error-check-for-pci_device_map_legacy.patch + Patch119: U_xwayland-enable-access-control-on-open-socket.patch + Patch120: U_os-support-new-implicit-local-user-access-mode.patch + Patch121: U_xwayland-default-to-local-user-if-no-xauth-file-given.patch + Patch2000: U_systemd-logind-filter-out-non-signal-messages-from.patch + Patch2001: U_systemd-logind-dont-second-guess-D-Bus-default-tim.patch - Changed patches to work with the new version: + Patch114: u_ad-hoc-fix-for-mmap-s-truncated-offset-parameter-on-.patch- U_os-support-new-implicit-local-user-access-mode.patch, U_xwayland-default-to-local-user-if-no-xauth-file-given.patch, U_xwayland-enable-access-control-on-open-socket.patch * Prevent unauthorized local access. (bnc#934102, CVE-2015-3164)- Fix GNOME X Session for some hybrid graphics (rh#1209347): + add U_systemd-logind-filter-out-non-signal-messages-from.patch + add U_systemd-logind-dont-second-guess-D-Bus-default-tim.patch- Fix build of s390/s390x (bnc#933503)- U_int10-Fix-error-check-for-pci_device_map_legacy.patch * int10: Fix error check for pci_device_map_legacy pci_device_map_legacy returns 0 on success (bsc#932319).- Add xorg-x11-server-byte-order.patch to correctly set X_BYTE_ORDER when compiling tigervnc on ppc64 architecture. Related to bnc#926201- U_os-XDMCP-options-like-query-etc-should-imply-listen.patch * Enable listening on tcp when using -query. (bnc#924914)- Enable systemd-logind integration support: + Add pkgconfig(libsystemd-logind) and pkgconfig(dbus-1) BuildRequires. + Pass --enable-systemd-logind to configure.- u_ad-hoc-fix-for-mmap-s-truncated-offset-parameter-on-.patch * ad hoc fix for mmap's truncated offset parameter on 32bit (bnc#917385) - N_Force-swcursor-for-KMS-drivers-without-hw-cursor-sup.patch * hwcursor still considered broken in cirrus KMS ((bnc#864141, bnc#866152)- Update to version 1.17.1: Fixes for CVE 2015-0255. + xkb: Don't swap XkbSetGeometry data in the input buffer + xkb: Check strings length against request size- u_symbols-Fix-sdksyms.sh-to-cope-with-gcc5.patch Fix sdksyms.sh to work with gcc5 (bnc#916580).- Update to version 1.17.0: + Continued work to strip out stale code and clean up the server. Thousands of lines of unnecessary code have disappeared yet again. + The modesetting driver has been merged into the server code base, simplifying ongoing maintenance by coupling it to the X server ABI/API release schedule. This now includes DRI2 support (so that GLX works correctly) along with Glamor support (which handles DRI3). + Lots of Glamor improvements, including a rewrite of the core protocol rendering functions. - Remove upstream patches: + Patch130: U_BellProc-Send-bell-event-on-core-protocol-bell-when-requested.patch + Patch131: U_fb-Fix-invalid-bpp-for-24bit-depth-window.patch + Patch200: U_kdrive_extend_screen_option_syntax.patch + Patch201: U_ephyr_enable_screen_window_placement.patch + Patch202: U_ephyr_add_output_option_support.patch- Add xorg-x11-server-source package that contains patched xserver sources used to build xorg-x11-Xvnc.- Update to version 1.16.2 - Fix present_pixmap when using present_notify_msc - Fix present_notify to return right away when querying current or past msc.Xext/shm: Detach SHM segment after Pixmap is released - xkb: ignore floating slave devices when updating from master (#81885) - fb: Fix invalid bpp for 24bit depth window - supersedes U_fb-Fix-invalid-bpp-for-24bit-depth-window.patch- fix bashism in post script- XServer looks for dri.pc during configure. dri.pc is currently provided by a Mesa devel package, which is pulled in by other requirements, but it might be better to explicitly require dri.pc.xorg-x11-Xvfbibs-power9-20 174238583721.1.11-150600.5.9.121.1.11-150600.5.9.1Xvfb/usr/bin/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:37975/SUSE_SLE-15-SP6_Update/65e01bc21f72e2e8a66e7be1dc197185-xorg-x11-server.SUSE_SLE-15-SP6_Updatedrpmxz5ppc64le-suse-linuxELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, interpreter /lib64/ld64.so.2, BuildID[sha1]=f96982b8951f463fbd47e966f3bdff3d17428b4e, for GNU/Linux 3.10.0, strippedRRRRRRR RR R R RR RRRRRRRR<&O8xorg-x11-fonts-coreutf-8a0afb062706d29a86f5c092221eeb1413cb12a4f152c501d8620222aa9222a74?7zXZ !t/]"k%#4ղS@џ="9q\vׄj0si0;ũda2:(֞`|boln"S ޭ4hp )䏎 7-k@ᯗ2XS `Pf$SD;gR„+$)=ƌ>(`s&GݗPׂFH󀯱Ϟ/rO|L5C,R{?xK\|^e`Uށ#OxFӹQĥlJŐv4YXr$ U7~0njCOL\Q.В NC@Vd 5ڻkqɺ>A!IFȋ$D:ULJ-^fP,jjIZg[wchy$^ucpgwҲF*~t[FWLReg3ڡwÒ(^ePKqf̜ɦtQ4VRp B]϶WHqVNٺ+sg9ƞT7ƘsyW*,xP m/g dw5R-2ȴP3CZAQ+S⮍U{p/_OgC.U$E, E=CfhgIKL#"7| GLjU`*PMfCϋb v0~o9B -BT9Rm$)֨݊JwgcŁֻ tEW/= F$a+SDĖ4_kH33~"F/^ -GGw65]B"hvf1seldR3͐>#N\8~+R]g!2}Ϩ2[!Ȉ "6s,/cޛx<|B+o:GTjd[[a)rDXfKdG!זm-3tuߵ MܷkW\z 6NP\PHTLJ,T*I<8rρmqVO}q0"GDT]3p X99b=%Xa՗7qNODH\xdBpv=js3ķ`;n' F/\& :f,bn'Lp[zaz> EϙP'1]DwSߕL0FYגe$@3;J7`Ę~xc'Fʡf|GCdg 8 : Lcvj6 e*LJ:1s2HFnqrEGA=7#DS}(v/ی 7.+1y [bZ=b?3jW 5+e)a# ; z5ШwӌF Elv% ERՄg bi,Iu[Y*3xCV,s@2'"c%*lf, {Rm;_?c;QHt⦓ĩF皘$.<gWI\`X.0.&WQb5ڠW!NH`3> ϵh787V^wEFGD~Ô90BΆ?.2M5̲ [ sp2l{Hf2YOE s6z- 27 H'3gtEq1O7|8`A %mLY".O(U<۳qf>8ߑOMy:d=HjvdiNܯje^v-e2SxwxQ=l{V䶜fKGGMJ1M?>dast@vpor೮ڜ MQ,c"WkAV³̥QcI@+C' p%a3[KI"peMc-`x*ESо1q%$[nbQJ6E 7po~V1Fh7ϐ~Ь-H鲞Z!`NZUlHRھ[9 ^XR`UO3 U;T+? u1r7*bv&(L(ON 7Y1$0črY?2 ׳V*cج7-$HS;3@ȉE;y"X~.׃\Mk"MoceCjra 溫.=*کB9*&a\'I;< )a}n*^tΛlƿq|)JXʅG;̊O_'gс(Ɉ "p6jS +N XiޥDu>olYiCClOPrˌ:fV2PY/cϤäڌny' !&U" k HΜ dȚ@ P|  1Rv۶ՁQRaW,n =RTwm-> *&hqVd&;xT5<+j&CKMIJ]5߅_QF3bڸ&F'ʦwvw;W%#=Bi^vr#Imm3ˀɌS< DoD~''UFA nJ33;9@ƻQK4X dpƢ:Q댹gdUˌhet=LdF{+PgopsP_2ek.@8pNS!-9LPG!qX Ѫvz<)OcϢQSabkP[(:dd.H(Rvd7r*gdġ׫~.@Fk\XN4C['-`]u,nhH{Z̋}^d#;dPQm|b"r66*| 4^p撻b 皊\JWdJeŸ!+|ǬP ]n vk{3LuȂ8QʡCTA2HaV48rAC(\KgP X4K_++;0knFei[l;faLccEl #f<;ob fK?%4Iּu]"o"w?Gy̢R*w+eoa+mq W݆o4yu#j_ S]CMrx_XErc$YD! 'WZ:aS?W`W畟m/_k5qIB9F _L6ܲIMƼ+"nJSr`֐r&~*A'gC\ l%P}VNl#HBM h}1՞1 O#J> 'Ֆo#.d2 L2nNW'Bdb!OT؈voj yCrŻ`:W9 NI>'Swj-ly>G|oM[#+]np\VZ"?(Vr2Dμ%:`r/Ƽ rw#-zzʽ'6X4h]cTQKd*R0JJlF*]IK"#5<3zzrޠ 3۹FդVCH.#h]JX>_V'RAӕ ФFeY4){%ŠOtaH4f{a]̙m -HbB/\v>ZfjLKf.qi$cf)R p9F-e&*1xt N!ZQ:~|^羸) K"h 4Ys-XYEaNߤT Ǯy8yPU4coHԁ[oiZ1j;,JxN者@2JE4HnQLDr)mOG {չ[9wlyپ j0fS,zdZt~M?eFG L\fd3oow? qWyGL 6ҶMNGPՍ?ҳ$^fWguqij1N?[4']}~'u!WydA9y 70` F+|,Ի\[i5Bh9:ynO4(]'ѺAYsŴ*[L4pذ7s6+ I3kf}hfZx® v30L. ,{ᅬe+AL+8?qpDDL{'JJQ.&`RGP/|z2WvLCڊp"3E3Id;$g7w"_&K⭰a'RPJz)bvj«fҜO%[WwW,|6Α%iik]x6 ?L3ɔK%89AcKޕa%1ܘ?<C !8^X-]c{j]>eW>+ݙv?|86!zE|{q 4؊ovwT{ ^0]8Ev#3m!KF)jn)eG$xW5kjz]{5%>w|, (=c@a贩sU\Ig8LޟL>}2|Oa/E\aKs:] a}=2't$j/ rGu3qd`߇25XbQ&+#=GXH ߻gJY(bxE5W^bTIޠڻκb1s#jj #ee)Z =hCJxWMsПL8nj0o"-A,Mv̨V?+"G7ա5\Ex\ N+\!C XC>b!iwRhu G>|ێQ#+d8i]ӌf1^w=0jc W VGOjbG~t:a/" mYVe(p=4koQ8BCW['29⼘a_5QS?cV >垮TY=.₦tM\!߰.T J}u_,e?nbFMeshj98 9;ރ-7pYx6^br]b wyJit/(CA#ym4'V Ѫb}GXrX>KQ/X܀ӲO 㹔/DfiY#zkc_wvH[!yH>[ خ~oHnӤp8xDJ<B @>6XЍ_;g?ijDZg|;-e=ጡmÛ#uddƹd^AJtݛ .fi-!VߤY%ce 8x𓂛FhI${#(踌/1 6=54ˆ*aTλ*0SD۷4r R:Α 3\&gWO.MDGcidrwg3[w}B} qm6,N7B M;u_F,N!-rI-!JLxs2PuK?P'Dh@LuLw4EfHz$<*mn&В¦U%'+B}nyW 5 QQהX4r hOveɤ~\Wk"y:`ѷ snGv1gC`YQK4gK\d0ɏ;KY 4H=Jw 5Us/猕EҺx `D8.ndB̖}pЪ'2ERwbSlt]7 nsƌ^y?][~ ΅T/\,3OtMY>e6&袅2MuՑ;<L+\)FQbGATOܫ3;!2H+y[_ [cj_:6zEbafm0Lkm7#jPiF."X9)Hѝ64NxAp{73xk.T<+~F&,f1c>xtXEVN ;Q19Tmb)VdOVcX#ߍbQů&YHSd, Ͳ$H|-OV$Ɲ{"p 6&Og0Cȯi<,7av ލӒd,N)%$7y= 6~|JCGu3 i' mN͝[-'!,nƥ0~(ZyJ3j~r+_ &a3ESpøR6{?*\ƚ:py[,s>zJ7{U*<gkv]cE6T$3GټJm.ioGÒZ8J(9ZVv554>TeW.HxC}X.\J[s9Oe0 Y_Xh vyȜK%{;.o/7Ƶ+[r5ÅɏX DǮ%jLBP@c׃*H($c-aˇw`"!d§*<>Tȩ6[\yK?0nr tpp`<7A]HB$[*Y#p i!w$Ƥ|k` =[qVRHggGẃӡf&|% l5PF+*wZ#/VU7?l?OkE@?͒c$< 墉_1 7mZ)[6=j'guÇ9:~w-R\r QӋo /?IR@4e[}Îiz~ _s[؄#b" y ZN=o֮BֲL뛅)/d B e NsW$lϭpAVi;eY::P\e F *mO|2evSFfڄh}!2hQSb>Îӄp۠Exu|U'2ɡ:%)廸a&)Lt1>Y5n!z~\7E}=%"[ NgLM(ggs gkFkp[NP oK(M $hlO`X(dc#Cb;|bSlUcL@iHŬ&F\ݏn#jCdC479J6G-nrX61;h<"`RAT:Q14>\",{A*{"ܿ-P7漙赩 hlGC~K*mf4ޜ*f3k/5'oNRys T=ϥI_M$:zaZBBDTf~KQGc>R 6h}UY3JtpY'(oq*58r+Kh]z]ѽ|@4r2c])` ,P 0cz9n{CʙꬱQ駪pO+O1. >N;n9e6һT3>{i,ؼ 6P=$[Cjj1=tPI/w|}2ۍZW/v>NI :fg DVq+!)TNj*OI$񩰪֒H9uj?^ -1=Uө]%,`F>SP{db@kǡ0|0MY91׊cOYd>樫eyXiNr 8i&OExE8pHMouXT6:&-mn1tcI9 lChIɹEzjG.C)oF|6D;{vP b#?4&\=Znf[289A_ǵ76FuV-7ur< Im| M*7.iieys!̭>߰!0J-c5֚+}O+2'-0n'?~';Wb?6 uy5UYaRzhr4keV& S-ǂEvj*{.c+i 8) ĔdP" IJe^96ݼ{,s?$ bg.l<*zǀZI \c%9̼,! &f;-Me=y$uc~Z*Dv8$0< 1-, t? B ̆oYMq4};$lT 1|DX!dʓsnl|pC@o8>ᖆ[#βR[2} ӖF)P"1XR+‡\;1+&t/q%MZxQ,Z/>߷ J=#8ӵ=ZRƿQS|1-F#boku? ʘllw8\1,/'$Ǥ4O8Q"SMv3'\ $PlAMvKc~Wo 6KʄNwniwih"rJE,UֿW %?ѝOJqgsWT*^&iVK "x9!ٸL]ώ_9Sy$/Por}6a Wxr2f([n&fIdjCX Y 0t6u Pxzm^@"/'=ڂ;Ѹ1'aO"5T='}68bHHZ+:@bpغ#pBP7 ?dliY0'}BOZ";86Hʖ[u!cJ3_掦JQ}))#Q{DjMrUqI5fޏ=nW/m{JgPG/D5 S%cMؤ/exu(Ii೮D'C^pJPMkh?:&f¦N9;-[냆Dmz%^[n3UP i7<Ӷߎ v9@+`f'/wltۚ6U{_D)D dd>MY-Ew,*hՃ:_i#0ImAGm"jXn=:]pvK'F*$)7"f|h"J)n+F(5uv+pLL C*mʨ 9Kфb>6; }#Q.kh=zF/I+Z72' #|Y);"QZ-3{VF:VJ$Po{m= h@_px:1l}jPv?+bY4Tѣ=}|)e$K'nr= NC*p4@0'?b,}x*iZ\U[@ҡI6b\-$`nD] $1W9Q [[oQ!7dMHCHftPXܒ\TVOsG4oeQ@g8#x5hu:8;rD+t 2ʆfvbeoTFh3 .<Ư(C̵6upT'j@:ilye?l`/M3c8>אLuRaq= ՐlJϐ-bN(; q&b 8Ds ~:sKjkK\:S Czqm)[^V0#5Xq2"Je>Mmhsg(ɿ_N+L!ri3W2ݮ{;qwl01E+P Gxgi<7UD(d? /iv@O"J4^hμaJ)*G'T^29ry£Nąiiփف36lR4xć{f( 8D}gLĽfs5Aijk!2'&sזh}?ySoMO؋}Gʶw~4s"gè(d&(4IIڊa8.6Cgep*9f0aM4qQm0H㬸mn_~I.[#0BWOrWuH%ݖHϝjhqJ(\áN$+޹1= kt#d&j"FQ0SqOkj@sJ"QB^ 3P,{$=wV< #>Ve=OTvΏJt zh8EȪQ#}Ij5R)y[``{zy˚Vt)UG.䧅:&]k=Q=k{k{^$v w3' EBsb 3Z:?ne 9YW¾U1 | @; !E47Z{#%jP{02y:#y/Htز[Ge8\pV̔ f)<,p7e Jm^IZS`F$vڃ(Ѷt'jR2 )ߠlH/O a5u3ߪ<9sy+ 0 X]s/b-f`e=Įh=FPJj!Za&neYZ /L/}NH¹nM z=,:g9^w+F틮Y#(ج% =Y3LR#Vdd1RkvB;]p`c޻?;K[ Ѻw]Ba 7u Qơ*8}a@IĀ_X\_$˛ < +%Q<A<̉mBYE8=Ȼf{ߐeJ$ȯ3qhwFs=gqk!8ވl\t]m$o+-iH\tY7lV}W'Ƹdr=;wؔ1 8F@Q83V-lM} (ۄ:Qk*y}+#cMIk`ω-Ɋ;shB8Une?HhNpJNRG@cn0%ltW0,en bDXr.^}Jr>iBc9YDje4K71ŧN ZTk:^{ V7 dFx9g$hPs=.IWQD~m2IdHA0vMwIZޔWyY$*ViKVe_hhO^K@gbv1Lm ƯӸ|ԤvWx0?2B&6|!ZlVΉi $`彅bY (Z(v갖X뿯 ~Ƃ,K[IkQ%?@܌7j1$esȁ[m`akI<juE4"R v}?BߚA˜PA ̫2ˮG',@n1uׁw#'K;hLny?9\<  ,d8 d7 kl@GLJ.\ idYVlzN28[~vu10RȐ[|srFmƆxTcdxWue `Wm`N]K{tl>Rd*8Sz;gۭp8m[BɺBM u>tȽW7;=9 M=,ſ83'Ų J@~ȥI:蔋NrF5[K^}YvmW*+~|㕲AIDwy#*nw(ʾH[OѰH8,{6 1KYFs+ef#CQH:ݔPh" `avfqE_#l% 4lӬo(" MlaBB8^k?SPbQ#Vf9!Pi yƹ)L6qkBG׭X:V35|m\AQnz쟇WKGJ&t(ea2%*q0#{)S(Tfa(Hm:N I`D{DeR!'-~J< 8i>cc'$h+V>m`qh4L;DBP ir I(N͖#crN.'$yfu[ 6nqhN=|k?=N21/9خ6/tw|sܶBB0D^(Q6+ZǕ,t" G%c N;m_:G7` G)w=Be (MPP d[Mp*N}ԜlwRx0kIjV,_2&I(%;`Z+L6Gn(Z9RaL[&X7byTVtES( 0J[QL1 ƃ6fғ4B{B#(kXUsʩ\ړ%%76}E4N*tЃ"G)ڒ{?f:ߝ T!f-d5~{k_ܟVAbq3fF4Ϸ rC4vjp( z.mc:LϒJUFZgɦ9eLI0} /s0)%5U|mS)ZĜ4Bp }UI6qjO>ǙJә@0_CxN-G^|?Һ+N+χ{<'7PUMyiW@x'wKt*y;kޡA#2q[lYh/#<6$Xp~p:g3g0)%uRT 42tS=ܦU370$mPnSR6]FQ~,qkJ註z^T$i6WWDftrɅ*: jX]}^ Qݕip>j&>Uv;r{k_޻uk)֪JtL įYÝGe /WgNWC'p?g8-4Pg@ W#LW "0 p[#l oZkmvGt8Bd7LR%'~Ŭ5r8 7- MOZa; πeg* -لQ4Xw2,^kA6p_ F3K@rnmFJSh@acqS]T(:C_#@,d-"Ji0aؘ`d%ejGdhn:SRtGCdzAR( % ϡd9J=y>vi*v:KL^O3$I&HRmi;AǰE\RX\n0ԱCx5eA#ePZ;{؊Z%a32_`kxޞ߯j # =)nR`VI3k7wu>K*|8V$_]ݜ\\\a1rx ;8/ ;RKi+Ep20n`IPo_CZF$k(ī$-97ܱ/jzp@XDf?7d@D&PJwl7w 52(7vl/C=yB3쪙9h{5kGM,@/-2"Njp Z|eNы(n5`@#0_ A͗9PhAHPZ!ΔĴ:dǿ %{QF rL[] w{T}UaCvbxb8** C.4kcEpͦ a*lKT=˃T6vu+ɲ^^rX 8@j21\iH%RK[Vw4Uogn#F[k1jܰuTIsi\!(=c?]de {XB/^?KS3J Li`s*';`\86DmLF#Y2C`w[@"Ѿ~Y!/S+)Q9ףWYLF)@5$xj9ZsRX:a<ʭ黕-ahۖj^ixV//zϹoO6v)xFoj(J4;JDB6_^V*y$D#ҿ\:}<TSI3I;tG϶ݔݠ#Tg0cJ:ݯHZhM4Zs%|[;>5$gF'P UШ݁w+HRcqY!jOaT?S0ŀO "P&N4U$K*'ƪyk2R}b{,NǾc:!\SUyGkkGvHoq;/iMcÉG8|HNވJ.HB@Aj|Kj>>i$*R$s5p6$/4Px4gƊk$M;_lO58Q~sռsTZe ¡"#+m^ح8U+:)6AGLB%3\HpXoH[geٔViI1jojmp]r$@H?{)w`((& @GAL#)kraMi曯]0H[I1`f[o? aj ^Nl6pP$V44?%Y[EBWt9^l%e~X +}ZN|&ABCM6RgbH& MG?b%~7txĠIU_5&}wtVBzR\q1 ٟZ!FHܷpV_INy.Vb(t%CiƜf%(l"So8I-lj=sGWpD&MCqQ̈́}2*&`Ssi3ʍjx[<]^B$cHQSϡzeh߆p }v0x 7vo'P6ĽA*q; >;P.8RH>ZEW$Me:B7{;d&%\1wr;h[j{#tgݷeP?w?] P_G whErCbaΗ = rH+YĎ^H\aӝ {}טU0^?Q=ڼN\Ms:A-f}?F/TYS.0p[sN8CsT6p/$t~TȬk8v=9:)WfIIa,=POm#NzX^`#/e]{& C~OeZh/ PW`!?%d rG`<T70>?B9옢{ e#e_4P^2&qBh%_ED[sa3i+n׏}n[#VA ]nl" ָ>%zt/*wMJ?m-V,wQ't3GL[5+t[_o@3w[DA7_M@4Nȍs-C sfB<=^}Fl[u.[|\Mv_%t bsGɨ"`E7س[׾17,N\1Y¯+(/ySh6]%l}Ýܥ 5'(`/ ΎP*nْ%KlNC̤@s@e+9 `7Jw[}ZfG@^[\QΩ?`;T,Ǖ6^:j4x? at2bTkfU{ 2Gн xFdIqv}U9elGD2l,@q(;o[fZE[v u>:WbK6@gY7yP&ƿhMjPho jF9@ 1>H /G"-HDŽB!JwQ+Rm}_U>i{yJd͸_Mު0Ts0Lq7o(=,A bB~1t?Il-En $)asrsqA!>xnO,$ㄎ_PS$(F|2aJ.op ؅C0HK>M#{Tit% DOood1@ 1ϓ Y Ge(X%Jc_I"`|͗1{ZZO;wV9h `C:̵9Dit1 2^FRxN[4a +ԮV_jYF)\YODGǔn5BEt$ bHάbL(-OǘҜefopJ!)@N"t{?,AJFD RwE"k\Ӫ"e)4?Fn qU+O}$ӿE!p6WqTa7>:na1XA;T>N"9wf]S~,K'wDvR {n KOҐ kef?]BrOJEAcyΞ%aI$]-0s֙} lV8^nmS"Z8H dH c| b .@mCWl#|֢v(>2 @>!r.v7 FQ(,( BѪnǭҤ2w89 :fj$# K,+n4*4 nM[a 1gvJ,>v7p 29:TwX'nu}Q[`%XhoJ I-E2 Tq^&T(NS 67CdڜW3σM<-׷Mw/~Ԧ˳GEB9P _U{FLs72! [ݾ5`_j;cMgG]Β{GaWo|{a} "m;6.Gc_Ys&'80=Hp9ԚHYF4kPIn"TՁBizCbWϾg|cH[zU:%^,Y'Oەi[lS<2Hݝ&P?繬w3PQY̧OE.rd"mKfkkx xD}V2oEO`{`,k]~nn :,>ZՌ-6M;0;N͙N_)S 2U1~$c㠁,/CDD.RQt~w5H%2qlAw/d6ųnip OsJBZg-0 9-C}/m03Cؼ Unɪy Z<ç‡e>]-; K/j-GJ۝>̟o"vn<"p@ f/YEIͳ6d*[&^w隻A K^ rۼz/%:`\5=7# X\Vҥfb-4(hKY4jGyY5O}zY2-ʳ-u+uMhM.}%{.Ը!Jz-c?ja~;>ui>g D44Mg2NqT-8=gyNeRs.hPs66ʭG[x@.Ux 0-F͸2fe 9+N!13C#9YseKow~ "E!xѣ40`o 4La隫SU͸CŇIzM:n R䅁,Vl.̶-&dND SXݴc'ΎPe95S)!g'vty3=';"LHF2gD%>Gq&A0DV7IJl\*_.q93s/LlUбrcNOmʻjw]}Ԩ,?{%T M2St@ X5Z .½n6Rt-gxޱ\^ҿ5UzQ7p _h5ڭ1$A#4_9[4:HS1]q%~aI e̳W8̀dӹZDl(#U3[PRX˿A`H7ZqrqPNk](Bĵǿe9k.mPOк$E)aC^X)ě Q~1i]\{\NB2uF)i1λW^g5q}faE`d @CFco釻dL>?ނ6W+ڈE(tU:i` qv0!FvE%cZBGW҄xBcWv8YS9d]I5xAjgf_Vҹ`Sm9Eީfxo X<<7>\?I9^Xɟ8O ?~o(5Uv4?f*B&vST=)eЌÑ7L ס;_-m>-95ofG烢YX3Q-ijKIk/q":9=Y\ s>ScS|Yћ\ Ð>G&4N'(z4!k8a٪. 1X# q/(}LqSvnιpMl4Xvmr|5juS5n8Ek,ϣ=T"gLJ 䆲XY_ g Tj'iSy3N !-00W&龩xw̝ϕV%*)Ih`cRr$u{) Py#BA D~&j* ڧ?ZPP% dnb@6Q *obͲ}g#PA@a\[}g8K(.\&/EДֿRM0p/)!xؚS%i C^Du ޛ  3pEg=Aks3{$}y#C3}*ᦼAMT.JY U-Qܮ5t^ҵH]Lwz|W^Ȫ%4_ſmDrŃ%ȵ:Em_L`L)l^y>L+vpӸd(z I&[/pPe#JF_w{!$9?{ZJʗԭՏX }T ~*m [Ɗ%5r?2>ϡ.Z-eDD BJo?uk CM" GΡ.kxm= 2,;u_LɆPiS~FYԎ 7u'[vZ\z= -|qlf?ဩ30/%6NƋl; rJQ1AT|iOuz,^_f[Aj:s"Ⱥ_z{;yfgQUw,칟HTߖCdKwaNhxk.5(C `SdTpfq%WZt:=WI_ŷxJPUs^T"PҘp"z>k)4؄F|{wRZ]Mzھ΄Zl*,i~ I.Fwf9+!K1mi!N-)Ixщ%Ё&Xn{*h,C~qswO>T]*mn"DE Ӣ{KPPբ-O7s(;94 pm8;ZQo*H3)U&]vVxoD3,pp.!l2keMڹj$bz{,Y,h!B($ ڴ2wqXҡ#ppRSA 5ɼJB-"/`su iHKѰHJfm[櫌΍ Jt^oɔɭuUWmizO潤~:3֔No(<~//H}:0r!PWWךi}|bzBni nPѯ-}㨌 e-ҍgq7epe3C0Rm:J룻ʖ+ 0q"_5v9$fq},Y[A𥘋!@&$ko>ZQsW!1j_vSdM'H/I[:OA@k|Ll-|Ȓf)}"]m3iښ4r#Nȧs.KgMl( yYiY| i{yv1c]+Q?(}陸qx$Rk㠿 ΛMZg;WУA=KEu 219 :J!\ +eްSÏص*c۰i<ć>يѭ #d\"hd 9TbJTFBkUbrEpޮD%n A{a}lN(p B9z~g.cQLҪk{}Cws:$qK=B̄񩛝v_Ƙܯ4?o(Z?> cJ+T]XV|x~TcvRMr nI,}"Z;"Xbn;z4gm_':t ~L ^USlTbU3L ՈU(NB>z^t-s.]h3)>] T p`VFhci*c|cTXiQNorӦn֩{|\4 EMw_F)(}Ri5N1LeLUL.ExtW ) 8URAĮsD" c7cWt'AOȉ/J˴y`O7W?e  k Hgt1/0'2Jj2 4 s)l c`"ڃG=qd i^1lpG8 ^aUcf3Y %yyl_GR^Rؖt~m7C$6{`<~R|o9L n_ 1"BS36=>^?qTYic3HQy("ih"P`ou,/(bnoN՞\pX/l`b[ʏ 8< ωrc9r ;|~Jjﭓz6:z$6sU$ IBڎ8+־f65(8cK =ŝ,HԁR.izeᬃ1۽{ٿ9B@x Xw\} O:gTFUGV1v/GpY~)S8kc jH&*xd= d_,΍N 8Cb9Sz[@,bꥂmyt uP!ȟ{qa.EԂމ8U 7:&EXe Y}>@ηM~hƃ Lʘ \3-tGf$FG`%݃F"(nlێڒ~dt| ]`7@T^Ċ&#d7Ț,\F2y_Uk˪zHrj ̪ghVPenuBWDwr&'%(xfwR/ |v| 'gᛝ+=$!C i.Nd<ڒ#E[q ^`GYG)XmV̔D|F,q5Ԓ\?weՉ"\bJ/!dNCtl{(5'[,v {/jQ ǯ2D|nwi?ʭ{pĹ)蘼 n -VQ/; ڟG!5*+1=$5DD5ɝcq2Q'ғGIJ-~hd2bpL7XH?x2v҃ sU} dz}]9 ?Wڃ &X[il$TKvFE 6S~د"%+$O^a)02R.%,p[]o]%tSٿŇdi 㾟 L!4pEE孂qjkm)o@`Ssw[ -VƮp& \Aء{=S߿!p$N;u5d~PR2$u3!*I t zT2{?fF1BozqS#b,&*FՋ6hUb#QOrin5h";Z|LTD7m*NV.+9Rg!كk:EBbbOPh!T3׏) InFd߈ ;(sϱ JQ9zx&f 3Aew'~{\L5lײ&aVͲ ,=fXkDOۃVEw ct0mAbؼdۨQ0؅b]8زf'Hu&qxX:rZ7Z(7 FTjäA"C Bo{ʋde'bD' $:!sW.b,ּ8C,qz왁ݏKk襖o> a2*`NP5EMLh8Ҷu "}kd )N0?o7ep"L7ĵfߘ hlEvkX@ύmHo"8!S!1I]aƿ~ǃ\/N5f_;K߳CvYI)VVI{h~+>k><[ i'Z 6AX!HMw 8mzG &0Ǭ#Y. /S%k?Hظ|0H 2isߓIg稜 | !M%A,oO꛰@-a@6HGĪb ~>vFOo=S /id\ͽ=+ ֑~Xߕ4Yy yC8f֓d'ь O)P^O Оs܆?"OY+D|L=tle n5>'Tj26n̲u͠H(*I|J ·dSY;7^ՠ@C:_qZ$9iWu1v-!qGIhJK. _\M4iLs} gW< W (/oݡ.gb m~1rn\>KBs ¦>o(V$h>8 h^7D_ '`K2C{j܊1^&ʧolO= L.f!?UiːgLzjs߭*A:J`!a(x@h#A ˫$Y@BjEd}#G=˴|5ۺB=X^ѠBf9&k69:>Ns_)=3({ `R%i>QX$4$Y-Ew֞]K SqmMS(3PdY] ,죞'Q79G<(񯁉%f J€6Ac`MJ&T&m5j/i_a/Ჾ;BQ%~^n:J{Ǎ( rx,3uTf /nɄEIrzw|s bt8Vr(C6b̰/7]=W0Ngi!HEb3[=ȺwB8&#$aX.@柰w,Fbo]K-^\<[w<[f#T;ԗY!M2Ppygצ]dh*sF29$ȁ;RiRڠ ĈZ%9M*ŧϲ&]'tƴx.3ɻv`brR [W]÷j~$uU?x^V&Hw5k8PP5TsψʫLvz%dv.0)QT1uTu҈i <σL Kfu/.!4,*I ׷FzU=Lfմyj0[Y%mKSře^f.+#6Uet1O:*{+skheR2|)24- ts|-Ca }\a M[kH vo%{:G p=|v>pkS@<}Uοn"ÿǿ|i&Ӝrv;p|u#bakh対|xסQ5 !,Ρ[DV#Ŕ`*^)"6݊˙NAu!sVU3%#qݞr5{@z uQ4Ico?z])_-qXdF[)C4L1D+1-/܏^_;BeݬhcNSgR(k`b]7+w@Npv)V= B2B\2|lh?S #_Vm./M,68=Yx 4@uB7W wRSǑ݂lZ'F(ÂăB[_W(rt)#v/27M&% ؟  rhGf$If{#ykap4<|OjQΡk@c@@8h[~DJq3rg uoi1<%ˀgXEgj KA㻝((}6tU}vW#i4 ZD*5AyQѷcGG c(U?HFK%s zH/P}+lDS:R}\ >ic^zO?R=Vӄe,Bs6b@h8ՇGl5h Vyu|h c~ Ykcq|2Edj8?Yf:T[hawUJC->en)`C'U0G'u7Ea)C0:KhDWA4̻ysӼe͓R aC7B ZC'|8ZsP{l_dg.GʨG_LCFRf{}'TըҝsaҼ޽mT`?l!`K{4\bZea'DXf+%x zu8/f3kE2 iy0ZVw7gow?+!.R`kҙʢQO6%cXtcU`\~z@ ##D'8QC⧲C5G0-}!t#ɵ16 ]rY8 X5.:uSnɏdfxzqHi3Y688&F 쓩U; !H#~gh`/ )zo1Uy#:6 V/ϢoPl zr/gQ3DX͈`2Pm??sxnщJ;EiVVOǷrpބm҇P5TÉv%R)uʖ8yXtE b[@"X$QN^.#tG;Nݫ ʔzp~Hھc@УJ9ʄ C lj,AQ^ b<];P -g=!rCr:cV0ǰf^!rd.8@dH/;e?I1otm*`E(?^-^ab1h6y$1ei9q>GBఀm~s=s`Q7+6ybDĝj>ȴ$btOe\7GC(JSQ#`)XiODXy;͍8 'v QYr}Mi,=o<7OO9@J5ML 1E+IaS*5'SAK{J3!ߐ%E@`u7¡ho٭RfuXQT?ʎ8>. jFK|v̄7xH zCͳ &/c2#Yxn7uM3"fl6e7ӊ"3Jae{bWXeE^4ܰinoƗkWakFŸ<93AHUnz]k&Ƨ5@ə)8d++=gڠKb/bS[}HҢqśu$[+Z~즏o<.׌g/Iay~lE j?ʶ+rVT#Yqo yR>RI(jP[ ` N+ ޢ/avNz!̍&mҴqOp@8M1xGX 0)ۈYP>-Ϭ\*3LguLޗ2kcc:ODwVDȞi}'pup ((p+kp(!%v2&U«%ح!amH .=~Uͷ¨%ͲNҢ*w17h=G/TXc1޺z1?>? 31'p@X{nrg ?1'.5+؈;[: !$44NY'MDd]+oEX= .u'TXpggW ޞ{^I^/Bh 55{MvF);VGKp!Ɂh *M`/PS9qeQ^|rG4fBXt32Nhy}1㡲S[ɯup*6OcT&p$/Pm)x]ᲤuߍHC fb7͌Y ⺗}Ưsr5=0%E! ! ,q*# Y3& `pو*3圁<{ZU~£V Z/gnFYMf8zvXAщ!^8|0}$Y%M9wೣ On1x,@m,d na"1Wo*:?Pns>2(%DCWEKhA+ }uN9p+) p!>Y˭"Ӗ7.NGRJ0s<U 9"R `Ŋʁ!4O=Ӫ͘#sb^4LtVybب\"cqQIa2m +#עW Bǐ8W$צzڧ8rT8#wzp/?v5oFO tR?.ǣ2+` /&k6Xթ@PgZѨ.DLWUXvK&G PSOT@>1TW&0U5u?Ա&eYYO~d(JN+hXgc}>C"Ɩuaq$%-)MM(D?\iuς+{r7)5 7Mi^Esq>0'jBw_GI8YJpeEt[j`}&: 6|t$ٞEt)Pv=~ekqua9!~3}OzT?Sd<,9 w_EB VYR]^W vCPǒP$/ ߫LeQnZ4jvG{4[LKod&]YI^RM^o( CmLlOpSl_"1m& (E/5r߈AӳLb;tT::h-YmI,,Ҹͺ:YեGILUё.&FҦKM>X)?~GZʢPQUrňsB g0-ƣh1=F^KQC 1^Ucͻj=n ^fr.* &ш JT[x95.u''Nqaj?' ϳG]ܫ>BH,3$`I B# >`~CWx/ҫ::Qs%#%s:w9zӰ ~,LN)p{9z` b#W)' w0wˋE:AÁͣGfMʍgeD*;fq]Rmc"LDm*"!x%b@q)Tٳ ְdZ/-%;m'x[9{gn%tb׌zK454cۮUœfkPS4ؼsFw3-6~jY4{g*ID ^Φ{0-^`cdxi\@%':͒Ly_6 CU*ڢn &\r[yJ%ڌ1}?zh4 )w[PQ5I'ui]"aK`>gٟYwbLNǩ$l7A+?>27n0eK5 +*.׀tme DdC;\{?rYN4!m&H cpG/tv}y`RQ;07kuY} HK~')]{@E3Z@ot>Bij{\mevmkE2 {q%'J^1CLR#B#"rTOqĩZPs$s(z.D"ܥz]Ky6t d-д~ ArҬ.k1[Y m(0,+}$6D\vG<6W qH ѽ 0|s8ͪ"AuZoJ 0#N~f6X~㚽r.yjz.rN =?ó-FeLqRH==u}928O=uGÓ`T\MWq,@Q0r;=!%@i8oN&=ЮP5lN.qw;c ѹ8jg?L%WJE.o6y86wf˘2h_4,[ A,ꦢ/0X{%ʠ#dlsmɊR^f~g vεkw&ejw RIz2cl[=5Q<.rؾRMCvlEX{; M7D`_أ;v Ԫ'I'ZUc5b+'E;5y/A+4V-\{vQxyrI~A u*Ft 8?seop}ͪfѢ[c%)abd+Sgd$$f٭Z)#M9`YHv-Mţv.FMIZ烗:-#ZRŒ kVf}[N[A@ß@CF]՚Rz"V]Ŗ= ;Yy@6:Oۛz)w OuD&Weaƕc47 hu`ގ;{\ا^usP{򑌄)dY_4NdɥX>GNȤ#;RFID  V-N]Ԟ1#>2YY0B\KB<%ŁXVMX7np#{{0Us uq39#P{3҃R_N~Oa7# 0tN):W"xjٴ0(t 9Z,R ]z1p "#E+s:Q ۝Pgk Rو䧶/1; >ܽaY^Bʘ0Yy#;?׽xx mĤ)*w{&&_!!uYfWkZ QW9wٲ~0w" VgWTMQS9Eܑ0ٸW}Z2#qƊרx {#iVާd۸<aLdΈB D y%oq1aRjJn7$-a9'a8E21b#"lhCka`v0Zngi Nْ)`^|p Lc Dz7=uT\]0cdM \}"%3Wz xG,Kc?җ߈|%;a˵K0cmF*~[J c]ʏJٮlV>qN$ n9RدHSnIL_c#b!R٢Px{RJfV`ZgVw0_;BV8>ʋU-og6E놙y5JUe Љv.c<۬sT*] ҉[a7H)>ڵ[gF{@bg커цf6R>_k:TmB"$,+C(dDU~^m/zN0υimf%o$ MD'ʁ%+nԓAmwÚ>.xK´U2k$RŹ .ZJ}X&\O 4G2ָtiT 3|ddk*okmw\CeŖ@b)s멩VFK_r^eJA+\C  "6̲ cyƗ$n[kM]%o aA}=<3jRVOD-OX 둹=H}L(k  c,9pR\~C_gYtnks3i积\zjwH+B\RN6~-ay/6ߵt&A>B>zCtg=¾i=,"E"gYLdEq@M5*\*"/VLI.4wOT%2)7ѿ"Z-2&z=Z;iq78yi6Rmכyν6i)Py΀hJZa"Z]`_ 0Ʃ &bнݸv(ckeBZfR3b9*2U)pcOWw7RΡyYhkf C'3\]IRc8c$t9% I3QVB/jC5(̨ p֏>8WvO!&ju^+`C,ǣ/[)ۘ/ sDlo(`l*<ݓ2w$,geԢanhinhWroixaA-+g%ob B_" ŖhAClU"WRԐ3W_Uo{|O!'؆SU BS40?UAj *rP=y5 i\VHHFKfZ7U;IAK+ _$ٸy麗JV.S&ŸGD-;\g _fLȈ& D׸c&ɶ[,.ߑ9m:c1 *-wpV˲ipȃa2ưm (0>af{`q (V6^#PuQ/ 2R `X>bٛ ${"9Wl5&bQ9wo |xYΏdSW@h_6L"KС7I4"Z=`?bn a\cOӶ 筐FVBW)m cFMwh,S`Ŀ6%fC8ΈQ^&!DQiP3ph:]}x t7C~ hЮO7z7H TfԢlG"n+ 5,ݢ1ˣ /khN_Fnay<ƶeͩhH, a3?#J-f5# 󙰐=$nUP:`5q\ӲgK>tUԭJw`mӷlfC_Ͷn⫒7pozxL.Q*hlw;u*x98pD n}IرTYr{xhQa4_hb"ؔ} -缸"Qׯߔd#fGr;B{J3gI/ϕ.6JE|'?R?>|F{cf`*_qxKS$ l?a;Kx ҃S:s~?u43=Ee?8KU\ c8:6K4xrkYC&Q(C1ޭl @ie F=L[{ 'z| S>,dff0.'eVlW_i(8B$j2hWjJ9 pr$ְHkb 6vIN*yvmJB6LLi֛45$rnzQyҭc³ aQ lk:~t[iu#g"F\%#v[䮟k b* 'Ing%3 jC9:ȟ>UiZQ35mf:" o퉰^L-߸v"yrvg՘dL306n|N,ڡ8ַ-ƹv.˵ NIPfpesN| qqn٪ цtW5%}=T{?Odk2UQ5;Dojzt?>t X[هt! Wz8I&\$rPl9Rog&,£rğikVm:؉d>5!2QrZwWHl{-{tn.1KmUb!\:{JGHQ5͞g,B\C̹y>SĴhܓt$ޓ*iUU<7䈝pB9wڈTzثqG%>oTÝ5v [yAx :طn'QX9߾^~ eږ0Pۥ'2)(J\9Ֆ9,().q CkpѰsH!yYj (/x]'ߙ[34G i1 |(;E4^d{"n Mz;VQc@B SY) ~BjV$]UbHgLjSf[$uN+B7f{qqIx92+(hˮttt>gdY2n׏Ve YP.rvdR_rԂOVgAlknSq+\NÙ8^8P|C'>ä)t ]c~gpGJS,.(m٢:X@k*68cY5'xZMQ}ÁL@>0Cr/{~XNA׬^[܏dSBr KG׊ʪւCs ,*_a[qruȴXxh1kpIic#5bZ\׈ d1O.c_ݡHDvuܒ>ex[['^ Gr59¶iJH+ 8IP uyU1g_/)0/GqS&Fh^j-8y# KƩV(zb{W]v~?Hpe2 j* )ףZ[3F\R|daG!2-r*r. _}"o O3rn).@i)?5|{_h `;jýoME#Q!r5ZR~~VnbVH);7֞[)Ytӊ lHRg˩?8)NRr@XrOOqfN>T`V[K4, }hJEJ9h6K:DꥦR2wp#W&oIr |PA~b_2YP]f3%"i`͍’}ojwg\6p\|yBZP`%#^]fON(+J}$ AͻlBmR_7-RL)6  2VgG ެ0QhOLg"倀Er|*"p_YKM'jASK ʐfK.묤Rs@0,x~lQ [B6%W)&<;d_dLxపME}^r58l jpzwOoV-a6k1Lʇcw?#YvscȡA/@1S ?beN52 >|s?y2_G2jbTh\y\"v%aH\й~o=Y>5vh;"&׼CB`Tn_,PJdRX !"` %ݙ]wQee%=ϲp酒EA"l @903onk>!J=AhFpCm8A(X BUX a6<9F-/ԅ:ozEOTDzwhIMw܉tݗ_a=AX23)(ܪE|M ,[ؼ`Y35QGPh$sw#$cF"ͭJd1&Wt OP3Jfi;W) Fd%%W1& /U rG]NѪ[,Z0c8S,wqXOz(fa"̈ƷZ!wږxCQ ) U4D`ؤ7#> 3 °JJ&f?\_#t3밇'?Ù#T|gu] ;?q@&`'XkB/^_桶JFQ7/,3ln< '=~ʒ!:>|ҥaI㼽s)M,zx'V/6IClcX[̲.\p$2tmq!'+qeSd)n>Lr %h E5eYgAު0avOR (*?;{Ůw(B>qcRߢC ,eO61u]ȺբWfFԚMUQۑX_Sg [|Ta)>dgg{̙#2,{ӧIg!קBT4DkIP}Fҥt!:4KnRR>Kd=Wwh]sj%`lҲ!/<>5ꘖM;o/b>zـmਖ਼}66'(J^phfU :FA@u/d}!=w`r6ojW"g-UNV=Cx@:MT[#]j`Q}S 1=?5w0fRͣbEji;sfoNe|ȍ|7hVH4zfMr{7.96(zL te kNF9DV*ȽAz/E@BiRI31)V?%%gvH60HF** uvXe+?UTԀ UöLpʜĢ%˼"RAD,K:`}A\ ؜ʛUAvA1xE6b0iX8#HL#֓mU?BdXH/:'r<_zuxzPaBJLd]oQKR@,v((+ 9 rW,5qxiBq1x0~^y򆟔L/{&A$Mc |.,9W[ffCR^~[͑XqK׋.EY#,:tWv}s,'X݃F4g3" OF)?Pj $E|;BO'RؒDZf7kZ- _In26 /HD[ ;Q9[ݯhng@(6hvdOG;"wqu2*NmQD7+Oo" 9,s𫠊Ḧ?ߓ+*ѿ8$LUs4tߐ^žda07gJ. AEMK$Jy7 7¶F)$3&Q/7x9ˍ+0^0@EOSL-p.kykᭃ,ḨU:^?6U(RTD^+M:$cm̀AϨ k?찺^EM*갼Ui^0dzD%x!Ɩo`XXۙ烣 #p@yՅt4Lz?}vKǼO:Me߬Vbhϊ|,V?l& ;v&iqf'UϮ@Aq1^1"س>rXzium^-3zͫ*?0Jfa6$a{q=(,/or|ꍌYVƹ殌`0rW96t|dG#{}8粁3X,s L^63pflw$؂y^ b5E#r[DU g(1\%i^/T^,eoT$#FwOУ$u# TŻU)iBXG%4^vjPh :׍R_a .$D4҆[=,ZW\C:Zd%G5XsvNTAWebbyp:9VWH} ͂o4d:"x}*XCGȀԴS$>6-7fpniZ_EUꙸ,]V?C -GtP(I<'|F[vWٵ?/ǡDՔO%9 e{S_!_(ݧ* ?_B R\)`O?7(I;Y[>6z6m`4uA8ѪH)ALpnsl`8X7Rʝ{u3sI8"r;/`(=QU o~2,PP7VQ) G;+yMSV\F@Z?GIz+J!e]Ju~$U;a'9}zfnP ɮlyw@~D1-x"TqE=S bؑNub&^3uk RW^Ud>c YT;psZ*1CXwUwR3>> Y8Ĺ̜!d`Hyb@'B.Oۖ_^S6a `Pt SQ(s`yZr:ÊC^M3*Uޱ<(EG] T5'g:Ӫ/;ϹOhrĵw˺L1@PM;|i9|5\8[3o^?!7ʓj!_fŅ|WP; iXl?.gd3V놯Tbyd1`>{Cުmv)(X@{ߛ 6""Kͩ2#|z#1H6F13&%,vfѱ[rIZAX0I N4lcBYpٙЫ*;~Eb·|峕?-rI]JBj9# .:-瞬y!G'ɉC#iN5>n)͡x^Ll6~7_(~ ghsHwWpa!QLq>Z|sZG>a/pJt'!I XoOIaڠvtMlut@_Z zy_%[pGt-kC ATĚL J[OSSSﲙ0-Vo 9\dUVl+?j>ז,Kbjrqn:A^BxD!6]~3 \(Y[%5sin0(9MZ1<a5jP*)zSw$vp'{JXp쒏Il_@ u_?l:>kY^.p4PƷQ1A.wָ!. ݼ${b$n ՚a"W52]hH?+=Qo%7(V{uU?r@L5&S+Y-d0drK~ =ts ?Ϭ¶OU* tk}xlLzWkH Ȩu}ƽfӛ~25ZXT[ ;΃h"e#6{$;U?$*e!ٮdx;!o'Ac1Ov^ V^C#xq.k:-\$,E%N^Lг6av1JZ#^B Ee }ʁwq$a{usbp2{mR,8h3r?ɑv6gP3Wڮ Hl4r\RFҼ3L6 ͂u|dIT0ߩ %^o!K 6;l i6}i.5|-^Jj$]Nw QWn[E4G Vhl5W~܋,khG5ڦT(g(EQ$ަ\ù@~j ҞRD(@$ IS98ÓU:o]c D^RkD`8AcP8dYHd?y Dr&<# kXБųmFCUh3QeE֕Ψ ~qQfdj ,omDX̊ TI{r;Q)Ҿې4;>tԦ b|0 !.t~؜8Kk;˶<}_b|ޡld~<bGˀ*\(!_^ pxE/$$K߱jQmU&dP} y+j0t2۬8hr :d=*PH҅]y1 &9RF`.cI˓ QZi1}FQ.Cb^e瞾U"ʟU&rh4"@cޤ<xiWIMMN6sljA֐j'BƴVGCwG3*a3d:ED 1gԀ\cPPpe} i!Au$Ԁmur\{П- 4 SZB`^׸-na~&ޅh>SZ&C= nf掷tM7Rxd^͖G8jyq-kI 4u:ƥߧG3]ʼnf)-.^/TaP%W]VJIOe6x(#"jwAW7 n0Dt5g9 oS藭#cZtcՈE0FI>ضӠ]|Gyx*"_>85H0 A_t6"t?|4OZjg/./~l&]FtzW?_QFeϥpGCP;ÂllUR.ε1JɔRqMK!Cϥ. ɤWlbZv.{PB(kx'fe!Ԯq@_pld+}Mm"5 *@'<*ye uD._Ol#4O WM?'ng aۼ6o0-:kN#xc;]mV8F+[ vvFvuo Mu4(_%\GݰL%W\L0K; :csX. +xaIvg`co;[J&-p9. HW]oT%7āǷ@}HjxɡB^D:DO3WL_%(Y ;V1jQF}6Fu۽ (ꤪ<6PXiWI|+d Y{(, 46VpM+xæ,ٓDB=I/Dk]:'8 -"g`Bʟ}cq^a$G Cwr*r}BXtKvU"ܮjJ^/Uq4-Fgbr`$3*  V>,tsQ!d0:ftUHzlu M0K^3 YumNC=J-&2(e=9NR1F Juv!CU/WNM*(*%/n˞@af}]f̙5:n^L:+,B OJ,17\5X mh3Tl񋱤{ Ȓ_%,Z Q/9'*z'~ ki_*L_a(e{>̩^6WG6].cLփ0͖=΋Zw@#@c{=mr݉D"蒏'eTsvDL`ޕë8B mpT[a]c(mW4VP4!%tL4v&2j:D[Z9 oMo?@F@(& !OgEW86O}ZFLZlO;0|F|WBv).|Ծ@t(&#=xc׺lLirPq4ص-?K޷@yr 3$`qsI {NL uQ2/Rx 6YӷG3T3EUʩ5RuB';Q' B jϴ I{o(|zx/_R"_HPZQ<.kwp#8˼wyYrE ;-'KB5mU/Zk!@Ol[ve9 .:SuWfd~rOifdY-8^Q$0sdϷb[ e^W DИau؂9$0H;)a2¿6#Ho9MR 榃Uܞ'J*`8twzZ@_pl٢Q-"B5m*>=ns:\=5{ZF+"&ViLe̸z0\!i6-z-s*_TQGfσNoZsgyI84ZVrf+W/+at#a88ˬAƺ/ zx̕-lG[=fPa@tKR \ucJ?`Z_&Ǟ#cƚ塸 e27wA=MS8 ![+;!l0"K$rc}O^jџvQ$ Y{OHzW쭈$j}-7d~wb+`u AM׏55Ӣh.MR};ܬƒPQi]ԹzW͒w{KE.'WVVqu.cޥ=\`ԏV}!a * (-d:ݐ\쥠9?N5:sgճbI(Eo_vOR,H9@95@&~9;ےƲT:2[aȇmUL_LFm**9-7f,4Ghg0$P݇YɞCt.a G.,K'SMK_»-JXdםɶ\;ډA8P򑺝pse6vdD0{aV=ځ|d JF3BK[{ZXC6+`,xA8Y-T2]+EG~B{T7Uz1˿9o: fMN[sAE['* 0>@K RQf}E6YV3 m Vuݭ0-=( $W!SsR%O)n:ef#;MFpYɒ+scvx!,ҧ( ب}Sh#F;y1籅6ٟV;eh^oj@6xBժ&]f:f\ H/S,LPEdX?(jEYK`s_Ąy4<%@y`Tz:^TA8 XV2ANV0,H I77@N2*#s>.>]L6H(5tEг&Q-uLWo賞*r9A>t =-;S.4l&O;6|n} EtdSaSQtwQ.OLvQ&L{OeFZ#= 5mrZ P`YAAat m y(ɋrWC[_I ^VQ. zh &CX/ }}E2hswbK/ZY{krw⧕NM>ĴNUI}vSDet[d&6"GwocO/G3  },̺"zh[q tǰ^LJĭs=>m@:fp5ae>l[`GL[4%ڭ|Z0k}0zQ=X!_d_{v;I2 H߰D߬$yU`8;Cw@t&rG?é5FarΊIW2;mH?,}xb^1_۶[c񱙸/v:iG3"y'82{Bo;łLbt /`6oFG)bi~ǿo^r85xmFqN+LO8K#,͌/qH] C I¹u y7hsʥiE`>{kM`W`HR&}_m@ɖ,ӌ3 bI*cDJO9ߒ66*ԖN\x/S2=ҦMo*p !{J,E'zmh|VCAS;_0XrnYʺ- ?f0[9\,1 z֠]ZppR_𜀹sE]"ݭmcqT>Gb<+@7lZq-er_UNJPҸ N(15=] L@vANdKEgd4|n2SIS}g33`FA31A&U2d;V8~=^Bcoc0 }=ᣨ@DAȽWyu '?}ll}nz ľbyqEa+9$W-e-]5~Pt.?&Q8;鋛RߩBTC IЀVM铬"+K4lͦW0_$jzBcIJxȡ)&X ?8 ™zm<[v,Ia 1֏|=&;#]B}B]ln߈#c5T2#)U#'#ήkԂ6c|ZySUe _fW[__:1{r-8NF4MJָwf7͸grY\%HR?[x"d5lMEۺ6{6!1A@s ;na6į1&˻ `kp0&gT>_"hM>drQ 7ʄWӿ}{1^8 Q/Z$gW̻tKL5lA9izᚐnHP"B"@4>1+8}g xld`( ʟ=:kgeJY5af ȡlgիWJDZޅ,GUR78 $96Ϣ\;ī;=tlJ2&V$羱杖 CT?i|4е"fEY6CNOK w,߳ҊzIF3a%òz)2 NWJv@JGWH6҈cqLz#dC0פF<@TJKaHyVƒvv@;;vd)㢅q\ocUgѿ?.W lY a{w T\J -K*R$1S/fP7;џ:7̑չd5IXH(!fOP4 f]2$%nV* @\͊`9 Be3nH3'BFLg='Polfi췑K5uRjƾoV>{w){X=9"Y%4 n ^CQ,5餵QXx>%p@}hj>|%mto3 &f)}cҨmOQ!V B̾kkh-)k;W'gw}?'ďӡ ºu@n^Ȉ,oc_p3+ 6 =FUjx'rasW]J> PLdY>L<{KMZVBh#R4ib* AyvynY%Z]XBO\w)xoZh氚b,B.w!7nnc(,4tJEL~%=a%ob[r@|^-ageuYoy< K xa)͘ X+kw 6=6#{)xbzˆ9 JJ[8toDP9h=D[d-X]ԺwT⢳$s;iO`l9TD|'n'6Ԣ/;f&OhGmJhVd^ gkKO᾿V*'w) KX0b |"B A|Jt^|[_:qX"ݵQ`5"|i]1vxH]{^- a>vn;G4դ7 9=4P56HC’u<6\}[]cUt#d2׷AoNd;,nՁl _ \] yʡDKpqG!mFV䢥VD"-J&N(F(7F+ Y6KuHHwLqߕlG]}E2rhG{xXHv$j_vŵld&n$!`"`E#Y4o4qΏ ,cޗumZ]4 vK·e=qHٷ vRR'5F\@ .,Eeea!WMfACIf/)<\Ԙi

n6PW] ;L`KeZoV4L scB#_Q;_>$oo&v{vdEL,s6+#J[߬Cvt?2⤩t'- OZ>iKNY#kd3<9~jߜBR}" e|t h3hڛe$>)]tw>3aC02L.Rbё.REN3d)ڳ8TW8 >yU8yL9/L=1AM6U{] |<ܖ;5deg>MRK-eD2⠧} N_ٰ]l3=Y4N?M/Lu>m_ft >]6-S_/J1rGXnۂ.fTՍu#O{~QKL*Ai|3o!ƈnjpœpdf"o5T-J>B=~xܛQxjY(i hz-?+ysv2вȻX~atX'Lbgp_t $maJDzY$Dn<Կnz m+!WD*< 4SFhإ06G~{Khb%\* GDHRkq2]ͧ~`Șorzbn,C;̪~gRPůAW嶳 nY4D֤6 )ӟ6c]G*3u@{jYjAB45~h`LP|eG.@33PWuW2B[k U'o,z漠Ċ6K-k-ב+޵>( fo].ŃbV`)yn6X(;K%ciR0tC? UL5b18RDKAzanprn&jK?_{_c`Nq_=ڨB˴o;Jԉ~mTƗm4ydJ]=W(@Ed6ɔIr4p9\W V4*1eD5:OC'l8 seb{:u{W<<QD{RP![ʳ31OZX!`m<>2Y-( qǖoIEߏtԜpV F[Q9g]! ;l؟qZ z.K*hŠM B[7`6:YI}oQsiJ*q%6r)̴Rp|9^ϯ;ڛ ? lz7FUR{RE2ޜ*:qa$rx@Qd넿HUZ(]p!scλ6\@bN~hϔykRP^X#ev. Q` X{IL,u4 8*c>$dߴ`a 8s_K:Ƨ[|mXB]]]LR"kSz7b^juNo' U~.E^|y{ءh~8>h&CךjG|-wDԡ˩6 3# tYl-RFm >&r|3R/0q7.oh1rl#a$5<¯qGnwԲHvtVq^k soACX7x\NRDzO(ut$}YJJ:ՅN"NuY}L6!Q+UBD6wY!P;v퐹;I9h1VD6YHb{-|:\o oT+u²riA?6u `0m5YUcxG6*rf/"%W\ʈ!%lcfe|ȉրxU?fV`Iz2aM+r"b2Y:Wڬ-)a> n d9phg]e%}O $JsU@ؚbs `c3XD%5}f!drˮ@C]1\uW5}w)]Fdq50@~ܭ![!z@V'h"-i7Y1R"?#L{? -<د@ ݣµ^^ 7]* *kBWTVEdhDf}Vʿɪ\S/'T%Idk%&˅j'SuAtXNǺ`fؓ30M=Whƪ,r{͡ШqTZd^ jDvQ=gU`_y"m@$!ki܂8bqEPϡ uS4@|x-ʱlTTN:9t݃fI a$4W:<|r[̐^DY LǽQYMWm#1\wa'E^:`4v8Oz6JwX`Mq$1hLEG=“ω"nF^O둦醥b``"ʿ|~w|}5rq}2?1C~5k%Qm׷V9.܌\ȧϤ&$/0BMQK ǝ=܄ER;dmqf0fpӻie?4BW? ՝`>Ԏ]Xq*Z紼R:g{_[fنI. d?@Aw`( {B8wvk:$tw9*xсLFb; +Θ<DXa(6x魏0ZX"Ay2,Vi:ON <_uhåe/EX[?4it]?Ԓ]BV7ZL ؓf6IE*pQkWp|>pawE8?"J)}W\ K(@I@at #Q"BwEzVJ-U1}y {V@HnG+՟T85R=" IQBs] A̚muSŗL* Wh-S{H/PQq5;Aߺ\|i8Yv/YBwȄYP ڔ(KSwd'+p<: m~vTC\l/Vk ˥ Z>_6zm31lπVe/|x/a@ȆDK1%jq?x)'(hl OZ繢C#CXb-+5]Q$h5:Z10 3F #BpfCz VKc%e4_ |̰r8)rЊX89_F%6n2F,k L#pQ4pI(;T(( ZSEwI 7c~{F.P(eO[YbjzTzճdL!eH O{BCJ+&{Yjl&*VB.IgRIbaC]H4/ayo-OR$ݼP N1if4^7cs~ )@\ AP~m&NY|W!&u+yBMZ,Iy* ^8~m?3otוCYkQ,Azz8QC |5g4{{̿ϯySm(HGds @RO@xC|Y3dA#[hXuWcRi` |"Tn:K~R#{Zb3-Cd5sMEU??b02s$qºPɯ4!G"{&dP.7R6&"/ 7D*{ݕeA9ٟ$ ZI]!/#a.vP ls=]_# ) olJ, AȃS mcx(Jl[u r 4]\ϽW)p޴;\̰}:ei{IXo~bzOOrP\PkvM2cna$L>5?. "+-ym'|E?r/M2q"KKRHk,@!@Q HX_pF?ιXLso)ϱsd[p k\oiR]u$,I/WJfȈ+HZK䉩 _6wRfGឭr->ٌ@<6ݤFim##C[cM=#)HwrbVI8 ~Ǔ\J_*OPt`֩b11S!Qjb?!wa"X<6-QchKA%ŤlGqZb8yb-Œ4 B.P/'+ (qMe;b+ك;"% 2 0v&.e2E;>[D8uqؙdxu7|8,*Y>w$ 4PJ/8(TP6le}>Pu/^boےV#e2^p 2x34eI\X \%0 kqgg??{))`@[^7(`ێ$Y-Z_g~Ǩ$3v∠4j}Cح4WxDE[-̆c3qqlT*t@]yo/ϗlGOtU=FuB?og/9S8jBHwWjWb4ײB{0%itѱTr=^1[#EN ̏^0幡(hY*t,<ٍy`?;YN^w&r  pcR[6OԏMz+CpqE8~"OXN5VgR>>']Aq{9<4B O'CAXg‹(=cQ6'(YT-)WM h8͇Q^=׏\ ' ķAR-s>_3}}Ntj:T;Ru,]1䷤ ʺ^VS Rih4`Pc>]6h (Ԟa&ApV ӯbkm&9'zZ? pph蠪=c>Z+ޞvQi÷%0f{4G9,Eo(8RQ;~J%y"gvC!Ұ:[XNcۣG:Ԅ٨Wbn”%?O 9442"4f+vbЧt&*[琨rwvT|4#gU"Z0ެ4'T 錩T3H[pl5Z2_{2B,kx?`Y ZG PZxrI|] Ї mlDMc*piJo(;mn8NDQ31F?Z!#@N0mEʷ ,2:Py !ۓg" ^a`fK!g@n|GSB/K?-q=h dG,q-aJM3.K])"ND4 ?x]/u-0C4يA[gK`HvR:p -nP]20PW~h o CuSM>(£ƼXTFK`:vxM>l2z1!;u/^3N/\Y0G2U4FMzbOǤ92Yoݯ0v|y ֝zm_+=N%kɛ>&GW(2""1v,8̓C* 7}ƿ*- K#MX:7Zl^B Qqm(QWB<=_~Li p|УD2'#èzrV 6C:o>i{Lcw+# @2CC] *70Z$a24`ċ GH nNa_ {\ i}0#EdU. L : 02yq E"ٻeZ}xk]S_``gęz^PA0j6,XF2!9mr~3 c>G烏!{wJhi_]+ߙ۩ֶt^,Hٲ#y@" U30U 6RtɜXoB:&vF47psBN&ê>s yHН``MopXc̴;Zف0OlB8#CL3[*" tT:}DXŴro~gO-fUq۸]xe#UfWS5WĐ' n(LfaŔ4YƝh^ W ʬ֞CPbk c^18GbLT[Ab~dB~~h/'z. m{ѤlfXl% 1FMf\ͽOʔvH)"U -JATN](_*=%q'*[AıYZҼ\͜Aprڌ%_fvaVҗƮPhZСlԂ8 ,؈e1W3+]@a#MC\UBM*+K`9Nw lhJ? ,7'塔;1!@{>TN$Ŏ~c,BkN F4 n8=1x V#xKv2cM"`5c8|XGv1f U zLsAjF}K7XmJ(vqiCvEa8iGt8TmT4qt-R0ɛY $~l$XxťTiM\dx[ I0j+ S"h#kT8L4.[S86y}= ?#]"IU[+ht8cs*Ehd\f,{]vv>lհs9ѵcT? VvOޮTYWc]\Ih#tMp* g'~:[$`f-2)9)"[n"ghI7]Nr ,ӓ] -^$YgW!4vuYދbRzu1ؐ7{)=.>[ #.ϑn&>dcq>(WFLCUWIiڈƌ {/'_ .)_ؙ=5GrvՐV^cۅF`6\8K6Y۵o&`v3/ޙ'2ӕAkVG]*> ;+gȧR4.EzWj%}[VEߢƍ"!9`|׭OM]ay$:r.c{5úbķj>s!JQܕSw,_(hCUhEr.v-aeDmhFȲnK}ϑTLhkMY@¨NbP27 4\x<?؜9=&$p$J-Nopds.v}v0RU9Ad([^s8 ܠdX gUU'|=%Eg7Rqðo]PƓRtEmx\ %v@mn2ue}.`o'H_ R3W¿^#A BG>HړB2A-4'/)ޚi#)Dіd6:gUj'Z% o,3ʁx3,W p'U__^tc> ȐwJ 7j!ڷт=^=v&&\Q#3V!!)ep \FMqyig+)6JӍ( fQ:{5uecXnͬy :}$;U/nrV$^Wz`6͊s2mˤu3/@ 㦨pݐ&.=S_U[j>0C]ɉP^#3_2zWh1 qVѨBIqJ:neg|nD\&}%IӦ7\er[=4ALhKˍ]F,ӺU[hʩy;;_tYz-=K# :J$g+Bt T]'x)ŠUF$eR mluz.}Y9rՖl]1F]< 3_6ѕ@|NΈ.zfx:ζ$"9h(OzH{< DGG-_Gfé5bB٧Yiܨ+LӐUU{sz#49ԧ&PzGL4iq]BRiSr{=7;%R?x]jiԵ<GzGJ Yԑ@\3>L%GU=?˹];Mf z k^?Mf#T$͵b2.b  qH\ 4`dz/Eīu*O!_rS]i߰m$%zGes@L \{Wp&cAۚv1\][7?auDMS>'XGH[E/^u:y"$ZP`&D˴H{KMɰU g9!)|SIC^\AZ|.O1,g/$\JuZkV& tf7&ȫѴBwdHWٛ*]6aZZ O o>B%} |Le뾀q 2fGur5|0dzۓ9 4¯A!fC`Scrr'.!xxdDRps-\.պP஝:DI, @T.@_;Pt6oI /%fp|#`3O?nکROwT{)SbZwhÞxwnSW._dR Dg Ewk {P<OA_9a:,DZ9ؒ ecL,3j]|%ԯK u99bЦU$Y_*>#*eZ2)?Qj=B<(_ÌCK[b1Ie}J(Cǟ*sաE]cRa<`ABa3p&'DàA],fE} pVR ̋d="x9BRowG) GֻbWK- {_*%2-Gź RD9 kD6ܳE_Prv0sZ=z!e}1 {77z7*mKXB"ƍ0sFUQcxĢߋ]"%0mEJ2:?b_l$Zk2bDˆ@@|9Mvy" /ٽZJQs"J`(l{ bw۴tVOX`uԊaS %9C谢6Eɝ#ŪhRjºpkRJ+޵mG?X׉&{nR Ssl{ xo!yT[|;QKٿԨ݃o Pҽ&PZq [$Cd> |iR6?]UZ3ĂGJ`>zdߎ2\&ɓX tz0kU@g⵾Jyme`)~F5~h= ^:1K,HeӘ|nֽHDla]).RRX!5nxu)?Ծ#WrtF঩˔g蘭&<ɚf4 ћU hpʩtW$Pv?nrl4Gbx -$TIY`5.) aAR/n-9oxF&?${فK:d"egE<ⴵ,1>[cش8uQFO]1V]%Sہq*d<ǹ`?yeQʥL^ԃƘ6ٝ%_Ee;!3x(.w<:b^&ճ}|vӥ7[ ż94R(<@OPţB-B@Ozzwvx.dzZ̼R ӜD2sݢIQM]p$/EgHK}`wR7M{.a5HEё\lɄontZt|j]6xT6%,NV][='`;%MuY&cWq'2,)$t; )B1 ^Q(A@}_Wh  MzhGy;:kI3VͰ T4#rX̋š顢JBx8X}h٦ my$p9f)7\Ө'6pZRQdG4Pȧ(6jv;/8?ۨrս0VnoYyՔf92 bZ?(\ F &j= Ue>GVn;l9+ N=2FUE5鿐n: b079f^t123W2U$A>:d֦_! kp/GR_OXWqscBaWa'IW#5py(]X2JaC[KxTSL ^ie N7Eo~3yr:HG Yn Df Wd>+tfkԟ+>~x6L,gS\%Y n?uI,6?栋yD(qdMQ yBWH@aW$q9.&}^:2ǘ 0s р@⎒҅YWY2UO;_p"XIpfGyj(S7}n jm3dA⯱n'f;?J69U\& ^&b`\, h̟!{jG,)|ajc~wl" \_rIh 4t7ֹ*V"' ԻR&RzݑD\IΚNPq]:0u7 s>& <:aòr!y6:wJ2WއAH476 ~.-3XWe9xB*.SB[JCLKCMJW#}q_8Odl_n&MьϿV}T/t|[G@UC=.5G5x $I>jMC X g}cGS $n":J v8r6 ̸l%f,Frpm4k+G\ xjí\Kjb#d.D{kb&QO<>z} :fD"C]bG޹lAypZ}V[eX$y VQgW2MLmghsQ?BaRDvςBǗdu\;H31Ė v&7+Em _PHK96)3iTe|-Wrª*DaҩxUE6_y*p6g;w)XEpffe R%bβwyoh)/@YJ MTáJKxsɶM4Ņr\2}44!eǗɱ$ ] y|/#8205"\FĊ-Hkڕܧwʭ%닱k&`SEo+\F8!؆#$/9#-X0*\LZeg2-ϴ,5Q#;8g13/xVwZKQTX][(!5'vy#OۣiUq*Ɉbv#)h}=pswtyLxւ<뿠G <,{(:H;;PY DԵmb&͔9љ4!Ӓ vVb*pw7Sa7(sSQn#i=/氥}#w9 LGVP6C]^drҀorNz(XT>I H_Prr.%'mv+KQpYi } @rm}V7458v'mUKE׮#̳6" -[Q- :K,FYcH>h( $GJ z֌I:r?]"i`8F2l!m?7+&y@yKN h VP4cw2כ>6Zg Q4Rehfj|a~<\#-pt3-q4:uHAňAPML;QT}ЈN(=b b&|4jp+~4_Dyia r ]'7g睚uik-(6ÂPIA:9jMΈq|%J$dnC8Wyϙr֚;rI 4 $?|$z?+2hžƻ 4jؽ'1aj=C;,8";D=#a $a/milu:R0.ti/AƂu"sv(-3O%GrxIuwHMe_{+B{?]=5Nl()4O #U{j,Y#n# o:Kv[K^ߝ"Æo^w GN/Joy@^;{N,6\ȼh ;wΩ Auށ.7tUcٸmҞeԹ\}}bBc%cf_/бo:ҙ؞5`XbnRᅦYi޷7tx \Hd^\a(9OVo[7q7fV^,-~b_68%;x; H_B_U xLV$&")(m7[~H` 0&UOT3QS]L|3+0t(XvXD@L;(v̨>I<ϥD(Oll$*Gjٽ7]o73r'!!8j,I={P87;bx￸8P \aq(X`ms%X+ejJTkʛ2}FsI)#e@kA:[i&K!T0ffi$ZZ_|<9: