xorg-x11-server-Xvfb-21.1.4-150500.7.29.1<>, g 'p9|g," )+K[SH7'Fs ӵ H+hEI-^|]XO4AٸEsә4 DJSR Z9vz6P6Ef=c Zvc#yHa,΅{rkV?5\pxd-W2nlazxHei nI ;|cӪZƢJ63hzd95Yr"¬E :Z\]ZiE :k>D?d , Atx  $ & ( , m pty~%%^%(89 : BF'G<H@IDXHYXZ[\]^bcHdefluvwxyz8HL`dhnCxorg-x11-server-Xvfb21.1.4150500.7.29.1Virtual Xserver XvfbThis package contains the virtual Xserver Xvfb.g 's390zp33!SUSE Linux Enterprise 15SUSE LLC MIThttps://www.suse.com/System/X11/Servers/XF86_4http://xorg.freedesktop.org/linuxs390x!؁g f7d5deee306827b847208b3c608bb95ce6e0d835bc3c9c0d7dc720661072cf58rootrootxorg-x11-server-21.1.4-150500.7.29.1.src.rpmxorg-x11-Xvfbxorg-x11-server-Xvfbxorg-x11-server-Xvfb(s390-64)xorg-x11-server:/usr/bin/Xvfb@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    MesalibGL.so.1()(64bit)libXau.so.6()(64bit)libXdmcp.so.6()(64bit)libXfont2.so.2()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.2)(64bit)libc.so.6(GLIBC_2.25)(64bit)libc.so.6(GLIBC_2.26)(64bit)libc.so.6(GLIBC_2.27)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.2)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.7)(64bit)libc.so.6(GLIBC_2.8)(64bit)libc.so.6(GLIBC_2.9)(64bit)libcrypto.so.1.1()(64bit)libcrypto.so.1.1(OPENSSL_1_1_0)(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.2)(64bit)libm.so.6()(64bit)libm.so.6(GLIBC_2.2)(64bit)libm.so.6(GLIBC_2.29)(64bit)libpixman-1.so.0()(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.12)(64bit)libpthread.so.0(GLIBC_2.2)(64bit)libsystemd.so.0()(64bit)libsystemd.so.0(LIBSYSTEMD_209)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)xkbcompxkeyboard-config3.0.4-14.6.0-14.0-15.2-14.14.3g@ffe@ee@e@eyem@e7e-%e)1@dd@cT@c.cEch@ch@cb[cb[cObγbγbγby@bzSbDF@b-b@b@b@a@a@aa@a@a@aaaaay?@a`]`]`:@`9@``P@`}p`u`t6@`?z@_@_@_0@_ts@_s!_q@_l@_a@_X_G@_D@_$^)@^@^^@^W@^%@^@]@]@]@]@]]y@]i]@1@\\O\@\v{\I\A\,[@[@[@[ā@[t[i[\Z[Xf@[P}@[D[:[2*[*A[@Z@ZZԐ@ZJ@Z2@ZZ Z}@ZTZ?Z/Z@Z YY@YY@Yh@Yg`Y_wY[@Y;@Y:Y6@XX @X+X@XpXXwoXN@X,J@XW@W@W@WDB@W9@W/*@W'A@W#LW @W @W @WKWW@V@Vn@V3VVm@VxVVV&@VV@V@VV@VGVVVUVA@V0V0V7@UU@U@UUzUuUn@Ui@U0U:T!TTTԬT[@T[@Tk4T`TN3sndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comjoan.torres@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comtzimmermann@suse.desndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comdmueller@suse.commeissner@suse.comsndirsch@suse.combjorn.lie@gmail.comsndirsch@suse.comdmueller@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comtzimmermann@suse.detzimmermann@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comdmueller@suse.comsndirsch@suse.combjorn.lie@gmail.comismail@i10z.compatrik.jakobsson@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comtobias.klausmann@freenet.desndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.commgorse@suse.combjorn.lie@gmail.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comfcrozat@suse.combjorn.lie@gmail.combjorn.lie@gmail.combjorn.lie@gmail.comsndirsch@suse.combjorn.lie@gmail.comsndirsch@suse.comsndirsch@suse.comtobias.johannes.klausmann@mni.thm.demliska@suse.czjengelh@inai.desndirsch@suse.comsndirsch@suse.comsndirsch@suse.commsrb@suse.comsndirsch@suse.commsrb@suse.comsndirsch@suse.comtobias.johannes.klausmann@mni.thm.demsrb@suse.comtobias.johannes.klausmann@mni.thm.dejdelvare@suse.desndirsch@suse.comtiwai@suse.defcrozat@suse.comsndirsch@suse.commsrb@suse.comsndirsch@suse.commsrb@suse.comtobias.johannes.klausmann@mni.thm.demsrb@suse.commsrb@suse.commsrb@suse.commsrb@suse.comfcrozat@suse.combwiedemann@suse.comsndirsch@suse.commwilck@suse.comtobias.johannes.klausmann@mni.thm.demsrb@suse.comrbrown@suse.commsrb@suse.comtobias.johannes.klausmann@mni.thm.detobias.johannes.klausmann@mni.thm.deilya@ilya.pp.uasndirsch@suse.comsndirsch@suse.commsrb@suse.comsndirsch@suse.comsndirsch@suse.comopensuse@dstoecker.desndirsch@suse.comtobias.johannes.klausmann@mni.thm.detobias.johannes.klausmann@mni.thm.dedenis.kondratenko@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comtobias.johannes.klausmann@mni.thm.defbui@suse.comtobias.johannes.klausmann@mni.thm.dezaitor@opensuse.orgtobias.johannes.klausmann@mni.thm.detobias.johannes.klausmann@mni.thm.demstaudt@suse.comeich@suse.comeich@suse.comeich@suse.comsndirsch@suse.comsndirsch@suse.comeich@suse.comeich@suse.comeich@suse.comeich@suse.comtobias.johannes.klausmann@mni.thm.detobias.johannes.klausmann@mni.thm.deeich@suse.comeich@suse.comtobias.johannes.klausmann@mni.thm.delbsousajr@gmail.comeich@suse.comeich@suse.comeich@suse.comeich@suse.comtobias.johannes.klausmann@mni.thm.deeich@suse.comeich@suse.comfcrozat@suse.comeich@suse.comeich@suse.comeich@suse.comhrvoje.senjan@gmail.comeich@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comeich@suse.comtiwai@suse.deeich@suse.comtobias.johannes.klausmann@mni.thm.detobias.johannes.klausmann@mni.thm.demsrb@suse.comantoine.belvire@laposte.netmsrb@suse.comeich@suse.comnormand@linux.vnet.ibm.commsrb@suse.comdimstar@opensuse.orgsndirsch@suse.comtobias.johannes.klausmann@mni.thm.deeich@suse.comtobias.johannes.klausmann@mni.thm.demsrb@suse.comsndirsch@suse.comledest@gmail.comsndirsch@suse.com- U_xkb-Fix-buffer-overflow-in-_XkbSetCompatMap.patch * Heap-based buffer overflow privilege escalation in _XkbSetCompatMap (CVE-2024-9632, bsc#1231565)- U_render-Avoid-possible-double-free-in-ProcRenderAddGl.patch * fixes regression for security fix for CVE-2024-31083 (bsc#1222312, boo#1222442, gitlab xserver issue #1659)- U_CVE-2024-31080-Xi-ProcXIGetSelectedEvents-needs-to-use-unswapped-le.patch * Xi: ProcXIGetSelectedEvents needs to use unswapped length (CVE-2024-31080, bsc#1222309) - U_CVE-2024-31081-Xi-ProcXIPassiveGrabDevice-needs-to-use-unswapped-le.patch * Xi: ProcXIPassiveGrabDevice needs to use unswapped length to send reply (CVE-2024-31081, bsc#1222310) - U_CVE-2024-31082-Xquartz-ProcAppleDRICreatePixmap-needs-to-use-unswap.patch * Xquartz: ProcAppleDRICreatePixmap needs to use unswapped length to send reply (CVE-2024-31082, bsc#1222311) - U_CVE-2024-31083-render-fix-refcounting-of-glyphs-during-ProcRenderAd.patch * render: fix refcounting of glyphs during ProcRenderAddGlyphs (CVE-2024-31083, bsc#1222312)- U_bsc1218845-glx-Call-XACE-hooks-on-the-GLX-buffer.patch * SELinux unlabeled GLX PBuffer (CVE-2024-0408, bsc#1218845) - U_bsc1218846-ephyr-xwayland-Use-the-proper-private-key-for-cursor.patch * SELinux context corruption (CVE-2024-0409, bsc#1218846)- bsc1218582-0001-dix-allocate-enough-space-for-logical-button-maps.patch * Heap buffer overflow in DeviceFocusEvent and ProcXIQueryPointer (CVE-2023-6816, bsc#1218582) - bsc1218583-0001-dix-Allocate-sufficient-xEvents-for-our-DeviceStateN.patch bsc1218583-0002-dix-fix-DeviceStateNotify-event-calculation.patch bsc1218583-0003-Xi-when-creating-a-new-ButtonClass-set-the-number-of.patch * Reattaching to different master device may lead to out-of-bounds memory access ((CVE-2024-0229, bsc#1218583) - bsc1218584-0001-Xi-flush-hierarchy-events-after-adding-removing-mast.patch * Heap buffer overflow in XISendDeviceHierarchyEvent (CVE-2024-21885, bsc#1218584) - bsc1218585-0001-Xi-do-not-keep-linked-list-pointer-during-recursion.patch bsc1218585-0002-dix-when-disabling-a-master-float-disabled-slaved-de.patch * Heap buffer overflow in DisableDevice (CVE-2024-21886, bsc#1218585)- u_miCloseScreen_check_for_null_pScreen_dev_private.patch * miCloseScreen check for null pScreen dev private (bsc#1218176); another regression introduced by U_bsc1216261-0002-fb-properly-wrap-unwrap-CloseScreen.patch- n_xserver-optimus-autoconfig-hack.patch u_randr-Do-not-crash-if-slave-screen-does-not-have-pro.patch u_xfree86-activate-GPU-screens-on-autobind.patch * check dixPrivateKeyRegistered(rrPrivKey) before calling rrGetScrPriv() to avoid xserver crash when Xinerama is enabled (boo#1218240)- Add missing fixes on U_bsc1217765-Xi-allocate-enough-XkbActions-for-our-buttons.patch (bsc#1217765).- U_bsc1217765-Xi-allocate-enough-XkbActions-for-our-buttons.patch * Out-of-bounds memory write in XKB button actions (CVE-2023-6377, ZDI-CAN-22412, ZDI-CAN-22413, bsc#1217765) - U_bsc1217766-randr-avoid-integer-truncation-in-length-check-of-Pr.patch * Out-of-bounds memory read in RRChangeOutputProperty and RRChangeProviderProperty (CVE-2023-6478, ZDI-CAN-22561, bsc#1217766)- U_bsc1216261-0003-dix-always-initialize-pScreen-CloseScreen.patch * fixes a regresion, which can trigger a segfault in Xwayland on exit, introduced by U_bsc1216261-0002-fb-properly-wrap-unwrap-CloseScreen.patch (CVE-2023-5574, ZDI-CAN-21213, bsc#1216261)- U_bsc1216261-0001-mi-fix-CloseScreen-initialization-order.patch U_bsc1216261-0002-fb-properly-wrap-unwrap-CloseScreen.patch * Server Damage Object Use-After-Free Local Privilege Escalation Vulnerability (CVE-2023-5574, ZDI-CAN-21213, bsc#1216261)- U_bsc1216133-mi-reset-the-PointerWindows-reference-on-screen-swit.patch * Use-after-free bug in DestroyWindow (CVE-2023-5380, ZDI-CAN-21608, bsc#1216133) - U_bsc1216135-Xi-randr-fix-handling-of-PropModeAppend-Prepend.patch * fix handling of PropModeAppend/Prepend ((CVE-2023-5367, ZDI-CAN-22153, bsc#1216135)- U_xserver-composite-Fix-use-after-free-of-the-COW.patch * overlay window use-after-free (CVE-2023-1393, ZDI-CAN-19866, bsc#1209543)- U_Xext-fix-invalid-event-type-mask-in-XTestSwapFakeInp.patch * fixes regression introduced with security update for CVE-2022-46340 (bsc#1205874)- U_Xi-fix-potential-use-after-free-in-DeepCopyPointerCl.patch * DeepCopyPointerClasses use-after-free (CVE-2023-0494, ZDI-CAN-19596, bsc#1207783)- U_0007-xkb-reset-the-radio_groups-pointer-to-NULL-after-fre.patch * XkbGetKbdByName use-after-free (ZDI-CAN-19530, CVE-2022-4283, bsc#1206017)- U_0001-Xtest-disallow-GenericEvents-in-XTestSwapFakeInput.patch * Server XTestSwapFakeInput stack overflow (ZDI-CAN 19265, CVE-2022-46340, bsc#1205874) - U_0002-Xi-return-an-error-from-XI-property-changes-if-verif.patch * Xi: return an error from XI property changes if verification failed (no ZDI-CAN id, no CVE id, bsc#1205875) - U_0003-Xi-avoid-integer-truncation-in-length-check-of-ProcX.patch * Server XIChangeProperty out-of-bounds access (ZDI-CAN 19405, CVE-2022-46344, bsc#1205876) - U_0004-Xi-disallow-passive-grabs-with-a-detail-255.patch * Server XIPassiveUngrabDevice out-of-bounds access (ZDI-CAN 19381, CVE-2022-46341, bsc#1205877) - U_0005-Xext-free-the-screen-saver-resource-when-replacing-i.patch * Server ScreenSaverSetAttributes use-after-free (ZDI-CAN 19404, CVE-2022-46343, bsc#1205878) - U_0006-Xext-free-the-XvRTVideoNotify-when-turning-off-from-.patch * Server XvdiSelectVideoNotify use-after-free (ZDI-CAN 19400, CVE-2022-46342, bsc#1205879)- Release 21.1 covers bugfixes and JIRA tickets for bsc#1176015,bsc#1182510,bsc#1182884,bsc#1184072,bsc#1184543,bsc#1184906,bsc#1186092,bsc#1188970,bsc#1194159,bsc#1196577,bsc#1197046,bsc#1197269,bsc#1200076,fdo#574,jsc#SLE-18653,jsc#SLE-8470- Release 21.1 supersedes the following patches still used with xorg-x11-server 1.20.3 on sle15-sp4/Leap 15.4: * U_0002-DRI2-Add-another-Coffeelake-PCI-ID.patch * U_0002-Fix-crash-on-XkbSetMap.patch * U_0003-Fix-crash-on-XkbSetMap.patch * U_0003-dri2-Sync-i965_pci_ids.h-from-mesa.patch * U_0004-dri2-Set-fallback-driver-names-for-Intel-and-AMD-chi.patch * U_0005-dri2-Sync-i965_pci_ids.h-from-mesa-iris_pci_ids.h.patch * U_build-glx-Lower-gl-version-to-work-with-libglvnd.patch * U_glamor-Make-pixmap-exportable-from-gbm_bo_from_pixma.patch * U_hw_do-not-include-sys-io-with-glibc.patch * U_meson-Fix-another-reference-to-gl-9.2.0.patch * U_modesetting-Fix-broken-manpage-in-autoconf-build.patch * U_present-wnmd-Fix-use-after-free-on-CRTC-removal.patch * U_present-wnmd-Relax-assertion-on-CRTC-on-abort_vblank.patch * U_xfree86-Change-displays-array-to-pointers-array-to-f.patch * U_xfree86-Fix-NULL-pointer-dereference-crash.patch * U_xkbsetdeviceinfo.patch * u_sync-pci-ids-with-Mesa-21.2.4.patch * u_xf86-Accept-devices-with-the-simpledrm-driver.patch * u_xichangehierarchy-CVE-2020-14346.patch * u_xkb-CVE-2020-14345.patch * u_xkb-CVE-2020-14360.patch- removed N_Disable-HW-Cursor-for-cirrus-and-mgag200-kernel-modules.patch * meanwhile cirrus and mgag200 Kernel drivers have been rewritten multiple times and no longer have (broken) hardware cursor- u_xf86-Accept-devices-with-the-kernels-ofdrm-driver.patch * Add workaround to support ofdrm- U_xkb-proof-GetCountedString-against-request-length-at.patch * security update for CVE-2022-3550 (bsc#1204412) - U_xkb-fix-some-possible-memleaks-in-XkbGetKbdByName.patch * security update for CVE-2022-3551 (bsc#1204416)- rename u_sync-pci-ids-with-Mesa-22.0.0.patch to u_sync-pci-ids-with-Mesa.patch (currently synced with Mesa 22.1.3)- u_sync-pci-ids-with-Mesa-22.0.0.patch * synced with Mesa 22.1.3; just adding a PCI ID for vmware was needed- Update to version 21.1 * This release fixes 2 recently reported security vulnerabilities in xkb, several regressions since 1.20.x and a number of miscellaneous bugs. - supersedes the following security patches * U_boo1194181-001-xkb-swap-XkbSetDeviceInfo-and-XkbSetDeviceInfoCheck.patch * U_boo1194179-001-xkb-rename-xkb_h-to-xkb-procs_h.patch * U_boo1194179-002-xkb-add-request-length-validation-for-XkbSetGeometry.patch - supersedes U_Fix-build-with-gcc-12.patch- U_boo1194181-001-xkb-swap-XkbSetDeviceInfo-and-XkbSetDeviceInfoCheck.patch * Out-Of-Bounds Access in CheckSetDeviceIndicators() (CVE-2022-2320, ZDI-CAN-16070, bsc#1194181) - U_boo1194179-001-xkb-rename-xkb_h-to-xkb-procs_h.patch, U_boo1194179-002-xkb-add-request-length-validation-for-XkbSetGeometry.patch * Out-Of-Bounds Access in _CheckSetSections() (CVE-2022-2319, ZDI-CAN-16062, bsc#1194179)- add n_raise_default_clients.patch- disable -z now linking for now, as there are some missing symbol issues. (boo#1197994)- u_sync-pci-ids-with-Mesa-22.0.0.patch * sync pci ids with Mesa 22.0.0- U_Fix-build-with-gcc-12.patch * render: Fix build with gcc 12 (glfdo#xorg/xserver!853).- U_xephyr-Don-t-check-for-SeatId-anymore.patch * fix mouse/keyboard focus in Xephyr (boo#1194658, github issue#1289)- fix bashisms in pre_checkins.sh (bsc#1195391)- u_xfree86-activate-GPU-screens-on-autobind.patch * Part of the original patch by Dave Airlie has landed 078277e4d92f05a90c4715d61b89b9d9d38d68ea, this contains the remainder of what was in SUSE before Xorg 21.1. (github issue#1254, boo#1192751)- Update to version 21.1.3 * This release fixes several regressions since 1.20.x and 21.1.1 + glx/dri: Filter out fbconfigs that don't have a supported pixmap format + xf86/logind: Fix compilation error when built without logind/platform bus + xf86/logind: fix missing call to vtenter if the platform device is not paused + Convert more funcs to use InternalEvent. + os: Try to discover the current seat with the XDG_SEAT var first- Update to version 21.1.2 * This release fixes 4 recently reported security vulnerabilities and several regressions. * In particular, the real physical dimensions are no longer reported by the X server anymore as it was deemed to be a too disruptive change. X server will continue to report DPI as 96. - supersedes U_hw-xfree86-Propagate-physical-dimensions-from-DRM-co.patch - supersedes U_rendercompositeglyphs.patch - supersedes U_xfixes-Fix-out-of-bounds-access-in-ProcXFixesCreateP.patch - supersedes U_Xext-Fix-out-of-bounds-access-in-SProcScreenSaverSus.patch - supersedes U_record-Fix-out-of-bounds-access-in-SwapCreateRegiste.patch- U_xfixes-Fix-out-of-bounds-access-in-ProcXFixesCreateP.patch * CVE-2021-4009/ZDI-CAN-14950 (bsc#1190487) The handler for the CreatePointerBarrier request of the XFixes extension does not properly validate the request length leading to out of bounds memory write. - U_Xext-Fix-out-of-bounds-access-in-SProcScreenSaverSus.patch * CVE-2021-4010/ZDI-CAN-14951 (bsc#1190488) The handler for the Suspend request of the Screen Saver extension does not properly validate the request length leading to out of bounds memory write. - U_record-Fix-out-of-bounds-access-in-SwapCreateRegiste.patch * CVE-2021-4011/ZDI-CAN-14952 (bsc#1190489) The handlers for the RecordCreateContext and RecordRegisterClients requests of the Record extension do not properly validate the request length leading to out of bounds memory write.- U_rendercompositeglyphs.patch * X.Org Server SProcRenderCompositeGlyphs Out-Of-Bounds Access Privilege Escalation Vulnerability [CVE-2021-4008, ZDI-CAN-14192] (boo#1193030)- u_Support-configuration-files-under-run-X11-xorg.conf..patch - u_Add-udev-scripts-for-configuration-of-platform-devic.patch - u_Add-udev-rule-for-HyperV-devices.patch * Remove udev-based configuration - u_Revert-xf86-Accept-devices-with-the-simpledrm-driver.patch * Restore simpledrm workaround - u_xf86-Accept-devices-with-the-hyperv_drm-driver.patch * Add workaround to support hyperv_drm- u_pci-primary-Fix-up-primary-PCI-device-detection-for-the-platfrom-bus.patch * Fix SEGFAULT when parsing bus IDs of NULL (boo#1193250) - u_Support-configuration-files-under-run-X11-xorg.conf..patch * Support configuration files under /run. Required for generating configuration files via udev. (boo#1193250) - u_Add-udev-scripts-for-configuration-of-platform-devic.patch * Generate configuration files for platform devices (boo#1193250) - u_Revert-xf86-Accept-devices-with-the-simpledrm-driver.patch * Code has been obsoleted by udev patchset (boo#1193250) - u_Add-udev-rule-for-HyperV-devices.patch * Same as for platform devices, but on HyperV (boo#1193250)- enable build of Xorg on s390x (jira#SLE-18632)- U_hw-xfree86-Propagate-physical-dimensions-from-DRM-co.patch * reverse apply this one to go back to fixed 96 dpi (gitlab fdo/xserver issue#1241) - N_fix-dpi-values.diff * back to version for xserver < 21.1.0- Update to version 21.1.1 * s/__/@/ in inputtestdrv manpage * Make xf86CompatOutput() return NULL when there are no privates * Makefile.am: Add missing meson build files to release tarball- Update to version 21.1.0 * The meson support is now fully mature. While autotools support will still be kept for this release series, it will be dropped afterwards. * Glamor support for Xvfb. * Variable refresh rate support in the modesetting driver. * XInput 2.4 support which adds touchpad gestures. * DMX DDX has been removed. * X server now correctly reports display DPI in more cases. This may affect rendering of client applications that have their own workarounds for hi-DPI screens. * A large number of small features and various bug fixes. - updated xorg-server-provides - supersedes patches * U_Fix-segfault-on-probing-a-non-PCI-platform-device-on.patch * U_dix-window-Use-ConfigureWindow-instead-of-MoveWindow.patch * U_glamor_egl-Reject-OpenGL-2.1-early-on.patch * u_render-Cast-color-masks-to-unsigned-long-before-shifting-them.patch - refreshed patches * N_fix-dpi-values.diff * N_zap_warning_xserver.diff * u_modesetting-Fix-dirty-updates-for-sw-rotation.patch * u_randr-Do-not-crash-if-slave-screen-does-not-have-pro.patch * u_vesa-Add-VBEDPMSGetCapabilities-VBEDPMSGet.patch - disabled n_xserver-optimus-autoconfig-hack.patch, which I believe is superseded by: commit 078277e4d92f05a90c4715d61b89b9d9d38d68ea Author: Dave Airlie Date: Fri Aug 17 09:49:24 2012 +1000 xf86: autobind GPUs to the screen - added pkgconfig(libxcvt) - cvt binary moved to libxcvt0 package- Update to version 1.20.13 * bugfix release - supersedes U_present-get_crtc-should-not-return-crtc-when-its-scr.patch, U_modesetting-unflip-not-possible-when-glamor-is-not-s.patch- U_modesetting-unflip-not-possible-when-glamor-is-not-s.patch * this should fixes crashes of xfce when running under qemu (boo#1188559)- add U_present-get_crtc-should-not-return-crtc-when-its-scr.patch (bsc#1188559) https://gitlab.freedesktop.org/xorg/xserver/-/issues/1195- Update to version 1.20.12 * bugfix release- Drop U_xwayland-Allow-passing-a-fd.patch: We build xwayland in a separate package now, so no need to keep this patch here.- Fix typo in %post: xbb.conf -> xkb.conf- u_modesetting-Fix-dirty-updates-for-sw-rotation.patch * Fixes broken rotation support for DRM drivers without hardware rotation support or direct vram access (bsc#1182955)- disable build of Xwayland, which is now being built in separate xwayland package with more recent sources (boo#1182677)- Update to version 1.20.11 * bugfix release - supersedes U_Fix-XChangeFeedbackControl-request-underflow.patch, U_xkb-Fix-heap-overflow-caused-by-optimized-away-min.patch- U_Fix-XChangeFeedbackControl-request-underflow.patch * Fix XChangeFeedbackControl() request underflow (CVE-2021-3472, ZDI-CAN-1259, bsc#1180128)- reenabled LTO (boo#1133294) * u_no-lto-for-tests.patch disables LTO in test/ subtree, since "-Wl,-wrap" is not supported by LTO * added "%global _lto_cflags %{?_lto_cflags} -ffat-lto-objects"- Update to version 1.20.10: * Check SetMap request length carefully. * Fix XkbSetDeviceInfo() and SetDeviceIndicators() heap overflows * present/wnmd: Translate update region to screen space * modesetting: keep going if a modeset fails on EnterVT * modesetting: check the kms state on EnterVT * configure: Build hashtable for Xres and glvnd * xwayland: Create an xwl_window for toplevel only * xwayland: non-rootless requires the wl_shell protocol * glamor: Update pixmap's devKind when making it exportable * os: Fix instruction pointer written in xorg_backtrace * present/wnmd: Execute copies at target_msc-1 already * present/wnmd: Move up present_wnmd_queue_vblank * present: Add present_vblank::exec_msc field * present: Move flip target_msc adjustment out of present_vblank_create * xwayland: Remove pending stream reference when freeing * xwayland: use drmGetNodeTypeFromFd for checking if a node is a render one * xwayland: Do not discard frame callbacks on allow commits * present/wnmd: Remove dead check from present_wnmd_check_flip * xwayland: Check window pixmap in xwl_present_check_flip2 * present/wnmd: Can't use page flipping for windows clipped by children * xfree86: Take second reference for SavedCursor in xf86CursorSetCursor * glamor: Fix glamor_poly_fill_rect_gl xRectangle::width/height handling * include: Increase the number of max. input devices to 256. * Revert "linux: Make platform device probe less fragile" * Revert "linux: Fix platform device PCI detection for complex bus topologies" * Revert "linux: Fix platform device probe for DT-based PCI" - Remove included pachtes * U_xfree86_take_second_ref_for_xcursor.patch * U_Revert-linux-Fix-platform-device-probe-for-DT-based-.patch * U_Revert-linux-Fix-platform-device-PCI-detection-for-c.patch * U_Revert-linux-Make-platform-device-probe-less-fragile.patch * U_Fix-XkbSetDeviceInfo-and-SetDeviceIndicators-heap-ov.patch * U_Check-SetMap-request-length-carefully.patch- remove unneeded python2 script 'fdi2iclass.py' from xorg-x11-server-sources subpackage (boo#1179591)- U_Check-SetMap-request-length-carefully.patch * XkbSetMap Out-Of-Bounds Access: Insufficient checks on the lengths of the XkbSetMap request can lead to out of bounds memory accesses in the X server. (ZDI-CAN 11572, CVE-2020-14360, bsc#1174908) - U_Fix-XkbSetDeviceInfo-and-SetDeviceIndicators-heap-ov.patch * XkbSetDeviceInfo Heap-based Buffer Overflow: Insufficient checks on input of the XkbSetDeviceInfo request can lead to a buffer overflow on the head in the X server. (ZDI-CAN 11389, CVE-2020-25712, bsc#1177596)- n_xorg-wrapper-anybody.patch * replace default config /etc/X11/Xwrapper, which allows anybody to use the wrapper, by a patch for the code, i.e. [#] rootonly, console, anybody allowed_users=anybody [#] yes, no, auto needs_root_rights=auto is now the default without any Xwrapper config (needs_root_rights=auto was already the default before)- u_xorg-wrapper-Xserver-Options-Whitelist-Filter.patch * replaced by improved version written by Matthias Gerstner of our security team + simplified the option parsing code a bit + changed the "ignore forbidden argument" logic into an "abort on forbidden argument" logic. This is safer and avoids surprises on the user's end that could occur if the desired command line arguments aren't effective but the Xorg server is still started. + tried to adjust to the coding style present in the file (mostly the function name) + added some logic to apply the option filtering only to non-root users when Xorg is actually started as root. This should allow for full flexibility if root calls the wrapper or if the Xorg server only runs with user privileges.- U_Fix-segfault-on-probing-a-non-PCI-platform-device-on.patch, U_Revert-linux-Fix-platform-device-PCI-detection-for-c.patch, U_Revert-linux-Fix-platform-device-probe-for-DT-based-.patch, U_Revert-linux-Make-platform-device-probe-less-fragile.patch * fix Xserver startup on Raspberry Pi 3 (boo#1176203)- n_xorg-wrapper-rename-Xorg.patch * moved Xorg to Xorg.bin and Xorg.sh to Xorg (boo#1175867) - change default for needs_root_rights to auto in Xwrapper.config (boo#1175867)- reenabled SUID wrapper for TW (boo#1175867) - u_xorg-wrapper-Xserver-Options-Whitelist-Filter.patch * Xserver option whitelist filter (boo#1175867)-Add U_xfree86_take_second_ref_for_xcursor.patch: fix use-after-free when switching VTs.- Update to version 1.20.9: * Fix XRecordRegisterClients() Integer underflow * Fix XkbSelectEvents() integer underflow * Fix XIChangeHierarchy() integer underflow * Correct bounds checking in XkbSetNames() * linux: Fix platform device probe for DT-based PCI * linux: Fix platform device PCI detection for complex bus topologies * linux: Make platform device probe less fragile * fix for ZDI-11426 * xfree86: add drm modes on non-GTF panels * present: Check valid region in window mode flips * xwayland: Handle NULL xwl_seat in xwl_seat_can_emulate_pointer_warp * xwayland: Propagate damage x1/y1 coordinates in xwl_present_flip * doc: Update URLs in Xserver-DTrace.xml * xwayland: Use a fixed DPI value for core protocol * xwayland: only use linux-dmabuf if format/modifier was advertised * hw/xfree86: Avoid cursor use after free * Update URL's in man pages * xwayland: Disable the MIT-SCREEN-SAVER extension when rootless * xwayland: Hold a pixmap reference in struct xwl_present_event * randr: Check rrPrivKey in RRHasScanoutPixmap() * modesetting: Fix front_bo leak at drmmode_xf86crtc_resize on XRandR rotation * xwayland: Store xwl_tablet_pad in its own private key * xwayland: Initialise values in xwlVidModeGetGamma() * xwayland: Fix crashes when there is no pointer * xwayland: Clear private on device removal * xwayland: Free all remaining events in xwl_present_cleanup * xwayland: Always use xwl_present_free_event for freeing Present events * present/wnmd: Free flip_queue entries in present_wnmd_clear_window_flip * present/wnmd: Keep pixmap pointer in present_wnmd_clear_window_flip * xwayland: import DMA-BUFs with GBM_BO_USE_RENDERING only * xwayland: Fix infinite loop at startup * modesetting: Disable pageflipping when using a swcursor * dix: do not send focus event when grab actually does not change - Drop patches fixed upstream: * U_0001-Correct-bounds-checking-in-XkbSetNames.patch * U_0002-Fix-XIChangeHierarchy-integer-underflow.patch * U_0003-Fix-XkbSelectEvents-integer-underflow.patch * U_0004-Fix-XRecordRegisterClients-Integer-underflow.patch * U_FixForZDI-11426.patch- U_0001-Correct-bounds-checking-in-XkbSetNames.patch * Correct bounds checking in XkbSetNames() [CVE-2020-14345 / ZDI 11428, boo#1174635] - U_0002-Fix-XIChangeHierarchy-integer-underflow.patch * Fix XIChangeHierarchy() integer underflow [CVE-2020-14346 / ZDI-CAN-11429, boo#1174638] - U_0003-Fix-XkbSelectEvents-integer-underflow.patch * Fix XkbSelectEvents() integer underflow [CVE-2020-14361 / ZDI-CAN 11573, boo#1174910] - U_0004-Fix-XRecordRegisterClients-Integer-underflow.patch * Fix XRecordRegisterClients() Integer underflow [CVE-2020-14362 / ZDI-CAN-11574, boo#1174913]- U_FixForZDI-11426.patch * Leak of uninitialized heap memory form the X server to clients on pixmap allocation (ZDI-CAN-11426, CVE-2020-14347, bsc#1174633)- move xorg_pci_ids dir from /etc/X11 to /usr/share/X11 and xorg-x11-server.macros from /etc/rpm to /usr/lib/rpm/macros.d; no longer package /etc/X11/xorg.conf.d (boo#1173056)- U_glamor_egl-Reject-OpenGL-2.1-early-on.patch * GLAMOR: no longer bail out for OpenGL drivers < 2.1 (boo#1172321)- provide/obsoletes cirrus and ast usermode driver also on openSUSE (jsc#SLE-12127)- Update to version 1.20.8+0: * Revert "dri2: Don't make reference to noClientException" * dix: Check for NULL spriteInfo in GetPairedDevice * os: Ignore dying client in ResetCurrentRequest * modesetting: remove unnecessary error message, fix zaphod leases * Fix building with `-fno-common` * xwayland: clear pixmaps after creation in rootless mode * glamor: Fix a compiler warning since the recent OOM fixes. * Restrict 1x1 pixmap filling optimization to GXcopy * Add xf86OSInputThreadInit to stub os-support as well * Fix old-style definition warning for xf86OSInputThreadInit() * xwayland/glamor-gbm: Handle DRM_FORMAT_MOD_INVALID gracefully * configure: Define GLAMOR_HAS_EGL_QUERY_DRIVER when available * modesetting: Disable atomic support by default * modesetting: Explicitly #include "mi.h" * xfree86/modes: Bail from xf86RotateRedisplay if pScreen->root is NULL * xwayland: Split up xwl_screen_post_damage into two phases * xwayland: Call glamor_block_handler from xwl_screen_post_damage * xwayland: Add xwl_window_create_frame_callback helper * xwayland: Use single frame callback for Present flips and normal updates * xwayland: Use frame callbacks for Present vblank events * xwayland: Delete all frame_callback_list nodes in xwl_unrealize_window * glamor: Propagate FBO allocation failure for picture to texture upload * glamor: Error out on out-of-memory when allocating PBO for FBO access * glamor: Propagate glamor_prepare_access failures in copy helpers * glamor: Fallback to system memory for RW PBO buffer allocation - supersedes u_fno-common.patch- specfile: reenabled XFree86-VidModeExtension (boo#1164020)- u_fno-common.patch * fix build with gcc's -fno-common option (boo#1160423)- Update to version 1.20.7+0: * xserver 1.20.7 * ospoll: Fix Solaris ports implementation to build on Solaris 11.4 * os-support/solaris: Set IOPL for input thread too * Add xf86OSInputThreadInit call from common layer into os-support layer * Add ddxInputThread call from os layer into ddx layer * os-support/solaris: Drop ExtendedEnabled global variable * glamor: Only use dual blending with GLSL >= 1.30 * modesetting: Check whether RandR was initialized before calling rrGetScrPriv * Xi: return AlreadyGrabbed for key grabs > 255 * xwayland: Do flush GPU work in xwl_present_flush * modesetting: Clear new screen pixmap storage on RandR resize * xfree86/modes: Call xf86RotateRedisplay from xf86CrtcRotate * modesetting: Call glamor_finish from drmmode_crtc_set_mode * modesetting: Use EGL_MESA_query_driver to select DRI driver if possible * glamor: Add a function to get the driver name via EGL_MESA_query_driver- Build XWayland also on s390.- Update to version 1.20.6+0: * xfree86: Test presence of isastream() * present/wnmd: Relax assertion on CRTC on abort_vblank() * os: Don't crash in AttendClient if the client is gone * dix: Call SourceValidate before GetImage * mi: Add a default no-op miSourceValidate * compiler.h: Do not include sys/io.h on ARM with glibc * xfree86: Call ScreenInit for protocol screens before GPU screens * modesetting: - Implement ms_covering_randr_crtc() for ms_present_get_crtc() - Fix ms_covering_crtc() segfault with non-xf86Crtc slave- Update to version 1.20.5+24: * Fix crash on XkbSetMap - Drop unneeded obsinfo file and tweak _service.- Update to version 1.20.5+22: * miext/sync: - Make struct _SyncObject::initialized fully ABI compatible - Fix needless ABI change * xf86: Disable unused crtc functions when a lease is revoked * xwayland: - Handle the case of windows being realized before redirection - Refactor surface creation into a separate function - Separate DamagePtr into separate window data - Do not free a NULL GBM bo - Expand the RANDR screen size limits - Update screen pixmap on output resize - Reset scheduled frames after hiding tablet cursor - Check status in GBM pixmap creation - Avoid a crash on pointer enter with a grab * GLX: - Fix previous context validation in xorgGlxMakeCurrent - Set GlxServerExports::{major,minor}Version - Add a function to change a clients vendor list - Use the sending client for looking up XID's - Add a per-client vendor mapping * xsync: Add resource inside of SyncCreate, export SyncCreate * dri2: Sync i965_pci_ids.h from mesa * Xi: Use current device active grab to deliver touch events if any * Revert "present/scmd: Check that the flip and screen pixmap pitches match" * glamor: Make pixmap exportable from `gbm_bo_from_pixmap()` - Drop patches fixed upstream: * U_xwayland-Separate-DamagePtr-into-separate-window-data.patch * 0001-xsync-Add-resource-inside-of-SyncCreate-export-SyncC.patch * 0002-GLX-Add-a-per-client-vendor-mapping.patch * 0003-GLX-Use-the-sending-client-for-looking-up-XID-s.patch * 0004-GLX-Add-a-function-to-change-a-clients-vendor-list.patch * 0005-GLX-Set-GlxServerExports-major-minor-Version.patch - Switch to gitcheckout via source service, use the stable released branch but set explicit commit used in _service.- reintroduce Xvfb subpackage (boo#1151457)- Add U_xwayland-Separate-DamagePtr-into-separate-window-data.patch and U_xwayland-Allow-passing-a-fd.patch: Needed for gnome 3.34 new and experimental xwayland on demand feature. - Rebase patches with quilt.- added patches required for NVIDIA's PRIME render offload support, which is available since release 435.xx: 0001-xsync-Add-resource-inside-of-SyncCreate-export-SyncC.patch, 0002-GLX-Add-a-per-client-vendor-mapping.patch, 0003-GLX-Use-the-sending-client-for-looking-up-XID-s.patch, 0004-GLX-Add-a-function-to-change-a-clients-vendor-list.patch, 0005-GLX-Set-GlxServerExports-major-minor-Version.patch- move xorg.conf.d snippets from /etc/X11/xorg.conf.d to /usr/share/X11/xorg.conf.d (boo#1139692)- Update to version 1.20.5: Minor bugfix release to fix some input, Xwayland, glamor, and Present issues. Thanks to all who contributed fixes and testing.- Disable LTO (boo#1133294).- Add systemd-rpm-macros BuildRequire for %tmpfiles_*.- xorg-server 1.20.4 * A variety of bugfixes across the board, but primarily in Xwayland. Thanks to all who contributed with testing and fixes!- get rid of meta packages still requiring/recommending obsolete drivers packages (boo#1121525)- provide/obsolete no longer existing xf86-video-ast, xf86-video-cirrus on sle15 (bsc#1120282)- u_xfree86-Do-not-claim-pci-slots-if-fb-slot-is-already.patch * X server does not support mixing fbdev with other drivers, so claiming pci slots when a fb slot is already claimed only leads to quiting with fatal error. (bsc#1119431)- xorg-server 1.20.3 (see changelog below) superseded the following patch we used in sle15 before (bsc#1112020, CVE-2018-14665): - U_Disable-logfile-and-modulepath-when-running-with-ele.patch- U_dix-window-Use-ConfigureWindow-instead-of-MoveWindow.patch * Fix abort triggered by some uses of screensaver. (bsc#1114822)- Update to version 1.20.3 * Disable -logfile and -modulepath when running with elevated privileges (bsc#1112020) * LogFilePrep: add a comment to the unsafe format string. * xfree86: fix readlink call- Update to version 1.20.2: Lots of bugfixes all over the map especially for modesetting, glamor and xwayland!- Update n_xserver-optimus-autoconfig-hack.patch to v5. * Fixes provider auto-configuration with nvidia proprietary driver. (bsc#1103816)- Update to version 1.20.1: This bugfix release fixes several issues in RANDR, Xwayland, glamor, the modesetting driver, and elsewhere. - Packaging changes: + Adapt patch N_Install-Avoid-failure-on-wrapper-installation.patch to work with the new version + Remove patch U_Xext-shm-Refuse-to-work-for-remote-clients.patch + Remove patch U_modesetting-use-drmmode_bo_import-for-rotate_fb.patch + Remove patch u_modesetting-Fix-cirrus-24bpp-breakage.patch + Remove patch U_exa-use-picturematchformat.patch- U_exa-use-picturematchformat.patch * Fix breakage of Xfce (bsc#1102979)- fixed build on s390(x)- u_modesetting-Fix-cirrus-24bpp-breakage.patch * Fix breakage of cirrus 24bpp support on modesetting driver (bsc#1101699)- Remove /var/lib/X11 and its symlink, it is no longer needed and doesn't work with transaction-updates (FATE#325524). - Move README.compiled to another location and use tmpfiles to copy it at runtime.- U_modesetting-use-drmmode_bo_import-for-rotate_fb.patch * fixes rotation in modesetting driver (regression with xorg-server 1.20.0, fdo#106715) * might also fix boo#1099812 ...- U_xkb-Fix-heap-overflow-caused-by-optimized-away-min.patch * Fix heap overflow caused by unexpected optimization, which was possible because of relying on undefined behavior. (boo#1099113)- U_Xext-shm-Refuse-to-work-for-remote-clients.patch * Avoid access to System V shared memory segment on the X server side for clients forwarded via SSH. Also prevent them from hanging while waiting for the reply from the ShmCreateSegment request. (boo#1097227)- Remove n_add-dummy-xf86DisableRandR.patch * After upgrade to 1.20.0 the API officially no longer includes xf86DisableRandR, so there is no need to add it back.- Update to version 1.20.0: New features: + RANDR 1.6, which enables leasing RANDR resources to a client for its exclusive use (e.g. head mounted displays) + Depth 30 support in glamor and the modesetting driver + A meson-based build system, parallel to autotools + Pageflipping support for PRIME output sinks + OutputClass device matching for xorg.conf + Input grab and tablet support in Xwayland - Remove upstream patches: + u_xorg-x11-server-reproducible.patch Solved slightly different + u_os-inputthread-Force-unlock-when-stopping-thread.patch + u_xfree86-add-default-modes-for-16-9-and-16-10.patch + U_xwayland-Don-t-process-cursor-warping-without-an-xwl.patch + U_xwayland-Give-up-cleanly-on-Wayland-socket-errors.patch + U_xwayland-avoid-race-condition-on-new-keymap.patch + U_xwayland-remove-dirty-window-unconditionally-on-unre.patch + U_0001-animcur-Use-fixed-size-screen-private.patch + U_0002-animcur-Return-the-next-interval-directly-from-the-t.patch + U_0003-animcur-Run-the-timer-from-the-device-not-the-screen.patch + U_0004-animcur-Fix-transitions-between-animated-cursors.patch + U_xfree86-Remove-broken-RANDR-disabling-logic-v4.patch + U_glx-Do-not-call-into-Composite-if-it-is-disabled.patch - Adapt patches to work with the new release: + N_zap_warning_xserver.diff + N_fix_fglrx_screendepth_issue.patch + n_xserver-optimus-autoconfig-hack.patch + u_Use-better-fallbacks-to-generate-cookies-if-arc4rand.patch + u_xorg-wrapper-build-Build-position-independent-code.patch- U_glx-Do-not-call-into-Composite-if-it-is-disabled.patch * Fixes crash when GLX is enabled and Composite disabled. (bnc#1079607)- n_add-dummy-xf86DisableRandR.patch * Add dummy xf86DisableRandR to fix linking with drivers that still call it. See explanation inside the patch. (bnc#1089601)- U_xfree86-Remove-broken-RANDR-disabling-logic-v4.patch * Fix crash on initialization when fbdev and modesetting are used together. (bnc#1068961) - u_randr-Do-not-crash-if-slave-screen-does-not-have-pro.patch * Fix crash when using randr when fbdev and modesetting are used together. (bnc#1068961)- Update and re-enable n_xserver-optimus-autoconfig-hack.patch. (bnc#1084411)- U_xwayland-Don-t-process-cursor-warping-without-an-xwl.patch, U_xwayland-Give-up-cleanly-on-Wayland-socket-errors.patch, U_xwayland-avoid-race-condition-on-new-keymap.patch, U_xwayland-remove-dirty-window-unconditionally-on-unre.patch: * Various crash and bug fixes in XWayland server (bgo#791383, bgo#790502).- Add u_xorg-x11-server-reproducible.patch to make build reproducible (boo#1047218)- U_0001-animcur-Use-fixed-size-screen-private.patch, U_0002-animcur-Return-the-next-interval-directly-from-the-t.patch, U_0003-animcur-Run-the-timer-from-the-device-not-the-screen.patch, U_0004-animcur-Fix-transitions-between-animated-cursors.patch * There is a bug in version 1.19 of the X.org X server that can cause an infinite recursion in the animated cursor code, which has been fixed by these patches (boo#1080312) - supersedes u_cursors-animation.patch (boo#1020061)- Added u_xfree86-add-default-modes-for-16-9-and-16-10.patch (boo#1075249) Improve user experience for users with 16:9 or 16:10 screens- Update to version 1.19.6: Another collection of fixes from master. There will likely be at east one more 1.19.x release in 2018.- Depend on pkgconfig's gl, egl and gbm instead of Mesa-devel. * Those dependencies are what xorg-x11-server really needs. Mesa-devel is too general and is a bottleneck in distribution build. (bnc#1071297)- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- u_os-inputthread-Force-unlock-when-stopping-thread.patch * Prevent dead lock if terminating while on inactive VT. (bnc#1062977)- Update to version 1.19.5: One regression fix since 1.19.4, and fixes for CVE-2017-12176 through CVE-2017-12187.- Update to version 1.19.4: A collection of stability fixes from the development branch, including two minor CVEs (CVE-2017-13721, CVE-2017-13723). - Remove upstream patches: + U_Xi-Do-not-try-to-swap-GenericEvent.patch + U_Xi-Verify-all-events-in-ProcXSendExtensionEvent.patch + U_Xi-Zero-target-buffer-in-SProcXSendExtensionEvent.patch + U_dix-Disallow-GenericEvent-in-SendEvent-request.patch - Adapt patches to work with the new release: + u_Use-better-fallbacks-to-generate-cookies-if-arc4rand.patch- u_cursors-animation.patch fix cursors animation (boo#1020061)- disable Xwayland for s390x again; it was wrong to enable it; there is no Wayland on s390x and will most likely never exist, since there is no gfx card on such systems and no gfx emulation either (bsc#1047173)- u_Use-better-fallbacks-to-generate-cookies-if-arc4rand.patch If arc4random_buf() is not available for generating cookies: * use getentropy(), if available (which was only recently added to glibc) * use getrandom() via syscall(), if available (there was no glibc wrapper for this syscall for a long time) * if all else fails, directly read from /dev/urandom as before, but employ O_CLOEXEC, do an OsAbort() in case the random data couldn't be read to avoid unsecure situations. Don't know if that's too hard a measure but it shouldn't actually occur except on maximum number of FDs reached (bsc#1025084)- U_Xi-Do-not-try-to-swap-GenericEvent.patch, U_Xi-Verify-all-events-in-ProcXSendExtensionEvent.patch, U_Xi-Zero-target-buffer-in-SProcXSendExtensionEvent.patch, U_dix-Disallow-GenericEvent-in-SendEvent-request.patch * Fix security issues in event handling. (bnc#1035283, CVE-2017-10971, CVE-2017-10972)- enable Xwayland also for s390x (bsc#1047173)- includes everything needed for additional sle issue entries: CVE-2017-2624, bnc#1025029, bnc#1025084, bnc#1025035- update build requirements- modesetting.ids: no longer hardcode Intel's Skylake, Broxton, and Kabylake IDs to modesetting driver; xf86-video-intel is no longer installed by default on these, so it will fallback to modesetting driver anyway; still you now can easily switch back to intel driver by installing xf86-video-intel package (boo#1042873)- Update to version 1.19.3: A couple more minor fixes, most notably a revert of a page-flipping change that regressed some drivers. - Remove upstreamd patches: + u_busfault_sigaction-Only-initialize-pointer-when-matched.patch- Update to version 1.19.2: A collection of stability fixes here across glamor, Xwayland, input, and Prime support. Also a security fix for CVE-2017-2624, a timing attack which can brute-force MIT-MAGIC-COOKIE authentication. - Remove upstream patches: + U_xfree86-Take-the-input-lock-for-xf86RecolorCursor.patch + U_xfree86-Take-the-input-lock-for-xf86ScreenCheckHWCursor.patch + U_xfree86-Take-the-input-lock-for-xf86TransparentCursor.patch- U_xfree86-Take-the-input-lock-for-xf86ScreenCheckHWCursor.patch * Add the missing input_lock() around the call into the driver's UseHWCursor() callback (bnc #1023845). - U_xfree86-Take-the-input-lock-for-xf86TransparentCursor.patch * The new input lock is missing for the xf86TransparentCursor() entry point (bnc #1023845).- U_xfree86-Take-the-input-lock-for-xf86RecolorCursor.patch * fixes random crashes in X in multihead mode if one of the monitors is vertically oriented (bnc #1023845)- N_driver-autoconfig.diff: No longer try to load "amdgpu" DDX by default for all GPUs with ATI vendor ID; this is now handled instead by an "OutputClass" section via kernel driver match, which has been added as config file to xf86-video-amdgpu driver package (bnc#1023385)- N_driver-autoconfig.diff: FGLRX does not support new x-server. This change fixes bad behavior(with empty config) when radeon ddx loads with amdgpu kernel module on SI and CIK cards, and x-server cannot start. Radeon ddx with radeon kernel module loads without any problem.- Update to version 1.19.1: First stable 1.19 release, including a few regression fixes.- Replace pkgconfig(libsystemd-*) with pkgconfig(libsystemd) Nowadays pkgconfig(libsystemd) replaces all libsystemd-* libs, which are obsolete.- Update to final 1.19.0- Exchange xorg-x11-fonts-core Requires for Recommends. The corefonts and cursors are not strickly required as long as one have a substitute such as Adwaita installed.- Update to version 1.18.99.901: - Remove upstream pachtes: + U_glamor-Remove-the-FBO-cache.patch + U_kdrive-fix-up-NewInputDeviceRequest-implementation.patch + U_kdrive-set-evdev-driver-for-input-devices-automatica.patch + U_ephyr-don-t-load-ephyr-input-driver-if-seat-option-i.patch + U_kdrive-don-t-let-evdev-driver-overwrite-existing-dev.patch + U_ephyr-ignore-Xorg-multiseat-command-line-options.patch + U_ephyr-enable-option-sw-cursor-by-default-in-multi-se.patch + U_kdrive-introduce-input-hot-plugging-support-for-udev.patch + U_kdrive-add-options-to-set-default-XKB-properties.patch + U_config-udev-distinguish-between-real-keyboards-and-o.patch - Disable u_os-connections-Check-for-stale-FDs.patch (not applicable anymore) - Adapt patches to work with the new release: + n_xserver-optimus-autoconfig-hack.patch (disabled for now as it causes problems) - Remove X.org stack version prefix. We are already atleast at verion 7.7. Plus we are updating individual components anyway. So the stack version is misleading.- Update to version 1.18.4: Another pile of backports from the devel branch, primarily in glamor, xwayland, and the modesetting driver. - Remove included patches: + u_x86emu-include-order.patch + U_modesetting-set-driverPrivate-to-NULL-after-closing-fd.patch - Update patches to reflect upstream changes: + U_glamor-Remove-the-FBO-cache.patch- U_glamor-Remove-the-FBO-cache.patch Fixes (bsc#983743) by not keeping >1 GB of VRAM busy.- U_modesetting-set-driverPrivate-to-NULL-after-closing-fd.patch: modesetting: Avoid crash in FreeRec() by NULLing a pointer which may still be used (boo#981268).- Replace N_Force-swcursor-for-KMS-drivers-without-hw-cursor-sup.patch by N_Disable-HW-Cursor-for-cirrus-and-mgag200-kernel-modules.patch Only disable HW cursor for cirrus and mgag200. This should fix a regression introduced by using modesetting for Intel gen9+ (boo#980124).- modesetting.ids: Add file for PCI IDs of ASICs which the modesetting rather than the native driver should be used for. This includes all Intel Gen9+ hardware (boo#978954).- removed u_exa-only-draw-valid-trapezoids.patch; no longer needed since pixman 0.32.0- removed no longer needed patch u_ad-hoc-fix-for-mmap-s-truncated-offset-parameter-on-.patch, see https://lists.x.org/archives/xorg-devel/2016-April/049493.html for upstream discussion; obsoleted by upstream patch https://cgit.freedesktop.org/xorg/xserver/commit/?id=4962c8c08842d9d3ca66d254b1ce4cacc4fb3756, which is already in xorg-server 1.18.3- Add permission verification for SUID wrapper - Disable SUID wrapper per default until reviewed- n_Install-Avoid-failure-on-wrapper-installation.patch: rename to: N_Install-Avoid-failure-on-wrapper-installation.patch - u_xorg-wrapper-Drop-supplemental-group-IDs.patch: Drop supplementary group privileges. - u_xorg-wrapper-build-Build-position-independent-code.patch: Build position independent.- n_Install-Avoid-failure-on-wrapper-installation.patch: Fix up build for wrapper. - Place SUID wrapper into a separate package: xorg-x11-server-wrapper- Set configure option --enable-suid-wrapper for TW: This way, the SUID wrapper is built which allows to run the Xserver as root even though the the DM instance runs as user. This allows to support drivers which require direct HW access.- Update to version 1.18.3: A few fixes relative to 1.18.2, including one fairly important performance fix to the Present extension. - Remove U_present-Only-requeue-for-next-MSC-after-flip-failure.patch The patch is included in this release.- Add patch U_present-Only-requeue-for-next-MSC-after-flip-failure.patch Fix a hang while using the present extension Bugzilla: https://bugs.freedesktop.org/show_bug.cgi?id=94515 https://bugs.freedesktop.org/show_bug.cgi?id=94596- Add automake, autoconf, libtool, c_compiler, pkgconfig(xorg-macros), pkgconfig(libudev), pkgconfig(libevdev), pkgconfig(mtdev) to Requires: of the SDK. This simplifies the build of Xserver modules.- Add support for a driver specific PCI IDs files supplementing what's in xf86VideoPtrToDriverList(). PCI ID lists may be held in /etc/X11/xorg_pci_ids (boo#972126).- Update version to 1.18.2: A big pile of updates in this one. Highlights include: * glamor is updated to use OpenGL core profiles if available, which should improve memory usage and performance on modern hardware, and got some other performance improvements for rpi and other GLES platforms * DRI2, DRI3, and Present all received correctness fixes for hangs, crashes, and other weirdness * Xwayland server has been updated to support the Xv and the xf86vidmode extensions for better compatibility, and fixed some bugs with output hotplug and pointer updates * Xwin saw improvements to window and clipboard management, and a few new keyboard layouts - Remove upstreamed patches: + U_kdrive-evdev-update-keyboard-LEDs-22302.patch- Backport upstream patches for Xephyr input hot-plugging / single-GPU multi-seat support: * U_kdrive-fix-up-NewInputDeviceRequest-implementation.patch * U_kdrive-set-evdev-driver-for-input-devices-automatica.patch * U_ephyr-don-t-load-ephyr-input-driver-if-seat-option-i.patch * U_kdrive-don-t-let-evdev-driver-overwrite-existing-dev.patch * U_ephyr-ignore-Xorg-multiseat-command-line-options.patch * U_ephyr-enable-option-sw-cursor-by-default-in-multi-se.patch * U_kdrive-introduce-input-hot-plugging-support-for-udev.patch * U_kdrive-add-options-to-set-default-XKB-properties.patch * U_kdrive-evdev-update-keyboard-LEDs-22302.patch * U_config-udev-distinguish-between-real-keyboards-and-o.patch- u_os-connections-Check-for-stale-FDs.patch Ignore file descriptor if socket or devices dies. This prevents the Xserver to loop at 100% when dbus dies (boo#954433).- Add 50-extensions.conf Disable the DGA extension by default (boo#947695).- Replaced u_confine_to_shape.diff by u_01-Improved-ConfineToShape.patch and u_02-DIX-ConfineTo-Don-t-bother-about-the-bounding-box-when-grabbing-a-shaped-window.patch.- u_pci-primary-Fix-up-primary-PCI-device-detection-for-the-platfrom-bus.patch Fix up primary device detection for the platform bus to fix the Xserver on older iMacs (boo#835975).- Update to version 1.18.1: First release in the 1.18 stable branch. Major themes are bugfixes in glamor, the modesetting driver, and the Present extension. Xwayland users may want to apply the following pair of patches in addition to this release: https://patchwork.freedesktop.org/patch/72945/raw/ https://patchwork.freedesktop.org/patch/72951/raw/ which combined fix an input issue when hotplugging monitors. Both are likely to be included in a future release unless testing discovers further problems. - Remove upstreamed patches: + ux_xserver_xvfb-randr.patch + U_systemd-logind-do-not-rely-on-directed-signals.patch + U_kdrive-UnregisterFd-Fix-off-by-one.patch + U_modesetting-should-not-reference-gbm-when-it-s-not-d.patch- u_Panning-Set-panning-state-in-xf86RandR12ScreenSetSize.patch Fix panning when configured in xorg.conf* (boo#771521).- Handle source-file-list in build not prep - N_xorg-x11-server-rpmmacros.patch: Delete: Process xorg-x11-server.macros in install- U_modesetting-should-not-reference-gbm-when-it-s-not-d.patch: fix build when gbm is not defined.- u_busfault_sigaction-Only-initialize-pointer-when-matched.patch Only initialize pointer when matched (boo#961439). - u_kdrive-UnregisterFd-Fix-off-by-one.patch -> U_kdrive-UnregisterFd-Fix-off-by-one.patch- Add test for defined macro %build_xwayland This can be used to enable the build of Xwayland and the package xorg-x11-server-wayland using a macro in projconf (boo#960487).- Split out Xwayland: * Build a package xorg-x11-server-wayland * Limit build to Factory (boo#960487).- Enable XWayland on Leap also (boo#960487)- u_kdrive-UnregisterFd-Fix-off-by-one.patch * Copy open file table correctly by avoiding an off-by-one error (boo#867483).- Update to version 1.18.0 - refreshed N_zap_warning_xserver.diff, N_Force-swcursor-for-KMS-drivers-without-hw-cursor-sup.patch - supersedes u_fbdevhw.diff, U_linux-Add-linux_parse_vt_settings-and-linux_get_keep.patch, U_linux-Add-a-may_fail-paramter-to-linux_parse_vt_sett.patch, U_systemd-logind-Only-use-systemd-logind-integration-t.patch- Update to version 1.17.4: Minor brown-bag release. The important fix here is Martin's clientsWritable change which fixes a crash when built against xproto 7.0.28. - supersedes u_0001-os-make-sure-the-clientsWritable-fd_set-is-initializ.patch- Update to version 1.17.3: Various bugfixes across the board.  The most visible changes include fixing GLX extension setup under Xwayland and other non-Xorg servers (enabling core contexts in more scenarios), and various stability fixes to glamor and the Present extension. - supersededs the following patches: * u_randr_allow_rrselectinput_for_providerchange_and_resourcechange_events.patch * u_CloseConsole-Don-t-report-FatalError-when-shutting-down.patch - removed evdev xorg.conf.d snippet since it's meanwhile shipped with evdev driver itself (since version 2.10.0)- u_vesa-Add-VBEDPMSGetCapabilities-VBEDPMSGet.patch Add VBEDPMSGetCapabilities() and VBEDPMSGet() functions (bsc#947356, boo#947493).- Backport a few upstream fixes for systemd/VT handling (boo#939838): U_linux-Add-linux_parse_vt_settings-and-linux_get_keep.patch U_linux-Add-a-may_fail-paramter-to-linux_parse_vt_sett.patch U_systemd-logind-Only-use-systemd-logind-integration-t.patch U_systemd-logind-do-not-rely-on-directed-signals.patch- Improve conditional enablement of XWayland.- Add patch u_0001-os-make-sure-the-clientsWritable-fd_set-is-initializ.patch Prevent segmentation faults with more than 256 clients (introduced by xproto 7.0.28 increasing the max client count 256 -> 512) Fdo Bug: https://bugs.freedesktop.org/show_bug.cgi?id=91316- Update to version 1.17.2: Pick up a pile of fixes from master. Notable highlights: + Fix for CVE-2015-3164 in Xwayland + Fix int10 setup for vesa + Fix regression in server-interpreted auth + Fix fb setup on big-endian CPUs + Build fix for for gcc5 - Dropped patches: + Patch110: u_connection-avoid-crash-when-CloseWellKnownConnections-gets-called-twice.patch + Patch113: u_symbols-Fix-sdksyms.sh-to-cope-with-gcc5.patch + Patch116: U_os-XDMCP-options-like-query-etc-should-imply-listen.patch + Patch118: U_int10-Fix-error-check-for-pci_device_map_legacy.patch + Patch119: U_xwayland-enable-access-control-on-open-socket.patch + Patch120: U_os-support-new-implicit-local-user-access-mode.patch + Patch121: U_xwayland-default-to-local-user-if-no-xauth-file-given.patch + Patch2000: U_systemd-logind-filter-out-non-signal-messages-from.patch + Patch2001: U_systemd-logind-dont-second-guess-D-Bus-default-tim.patch - Changed patches to work with the new version: + Patch114: u_ad-hoc-fix-for-mmap-s-truncated-offset-parameter-on-.patch- U_os-support-new-implicit-local-user-access-mode.patch, U_xwayland-default-to-local-user-if-no-xauth-file-given.patch, U_xwayland-enable-access-control-on-open-socket.patch * Prevent unauthorized local access. (bnc#934102, CVE-2015-3164)- Fix GNOME X Session for some hybrid graphics (rh#1209347): + add U_systemd-logind-filter-out-non-signal-messages-from.patch + add U_systemd-logind-dont-second-guess-D-Bus-default-tim.patch- Fix build of s390/s390x (bnc#933503)- U_int10-Fix-error-check-for-pci_device_map_legacy.patch * int10: Fix error check for pci_device_map_legacy pci_device_map_legacy returns 0 on success (bsc#932319).- Add xorg-x11-server-byte-order.patch to correctly set X_BYTE_ORDER when compiling tigervnc on ppc64 architecture. Related to bnc#926201- U_os-XDMCP-options-like-query-etc-should-imply-listen.patch * Enable listening on tcp when using -query. (bnc#924914)- Enable systemd-logind integration support: + Add pkgconfig(libsystemd-logind) and pkgconfig(dbus-1) BuildRequires. + Pass --enable-systemd-logind to configure.- u_ad-hoc-fix-for-mmap-s-truncated-offset-parameter-on-.patch * ad hoc fix for mmap's truncated offset parameter on 32bit (bnc#917385) - N_Force-swcursor-for-KMS-drivers-without-hw-cursor-sup.patch * hwcursor still considered broken in cirrus KMS ((bnc#864141, bnc#866152)- Update to version 1.17.1: Fixes for CVE 2015-0255. + xkb: Don't swap XkbSetGeometry data in the input buffer + xkb: Check strings length against request size- u_symbols-Fix-sdksyms.sh-to-cope-with-gcc5.patch Fix sdksyms.sh to work with gcc5 (bnc#916580).- Update to version 1.17.0: + Continued work to strip out stale code and clean up the server. Thousands of lines of unnecessary code have disappeared yet again. + The modesetting driver has been merged into the server code base, simplifying ongoing maintenance by coupling it to the X server ABI/API release schedule. This now includes DRI2 support (so that GLX works correctly) along with Glamor support (which handles DRI3). + Lots of Glamor improvements, including a rewrite of the core protocol rendering functions. - Remove upstream patches: + Patch130: U_BellProc-Send-bell-event-on-core-protocol-bell-when-requested.patch + Patch131: U_fb-Fix-invalid-bpp-for-24bit-depth-window.patch + Patch200: U_kdrive_extend_screen_option_syntax.patch + Patch201: U_ephyr_enable_screen_window_placement.patch + Patch202: U_ephyr_add_output_option_support.patch- Add xorg-x11-server-source package that contains patched xserver sources used to build xorg-x11-Xvnc.- Update to version 1.16.2 - Fix present_pixmap when using present_notify_msc - Fix present_notify to return right away when querying current or past msc.Xext/shm: Detach SHM segment after Pixmap is released - xkb: ignore floating slave devices when updating from master (#81885) - fb: Fix invalid bpp for 24bit depth window - supersedes U_fb-Fix-invalid-bpp-for-24bit-depth-window.patch- fix bashism in post script- XServer looks for dri.pc during configure. dri.pc is currently provided by a Mesa devel package, which is pulled in by other requirements, but it might be better to explicitly require dri.pc.xorg-x11-Xvfbs390zp33 172949789521.1.4-150500.7.29.121.1.4-150500.7.29.1Xvfb/usr/bin/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:36104/SUSE_SLE-15-SP5_Update/74a747c8b0fd803f2b9eee04c275741e-xorg-x11-server.SUSE_SLE-15-SP5_Updatedrpmxz5s390x-suse-linuxELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, interpreter /lib/ld64.so.1, BuildID[sha1]=e9297b28103c4232a762af3dacc061c23c344098, for GNU/Linux 3.2.0, strippedRRRRRRRR RRRR R RR RR RRRRRRRRRRRRRYEӚO]=8} xorg-x11-fonts-coreutf-84c90d74f8284405d21befdc642d033c50cde27d61093ce868716fb6ae17b18f9?7zXZ !t/m]"k% #4ղS@џ="9q({׈:]Fx}Q(q[Sy)2ʖOS$Okj+(4಼+OTEm[_0W@j\z*sUi1'#BtWS@@t0wK+&ѭ3aXEh0[bRr6 є9r VS7g:'M패՗̹&3l?F1)-\!61{1?R*Z[]@h&tL&W,kb7[n7Bwsb߬;d17?ps*hM>yY\9x@)7]OzD*}lۡ0>=Jl{vkD>8֘=f`ܙ04[ڞZ';bВu+ I)mHakvcSOC/! RZ[.1++~ ZA;sqgfğ.i[;\.؆< .d5np=xr蚢IqW^r| $"h,Fne&U4rQK`&&~<iNb/+ }4Bl%PFdmw墇]0]ώ+U5͆[7,nON>7@SEYVfLVۤ Ez}}&71\ծy1ULZIfNI5lKEX)u91qH1 SIU2|<ӥ0e2y8gtIVxE%:6Rd hHznzQ7iLFNmGDRGiT退Z,bVQ Nn/xո.6]G08{T-]zZD' tWM!">t,X^(qT0Z'2HeAT.Os*(KM&5W)w[RT}f`^kQ"V]}<b?;닌 <ie`iCW5!y>}ի},'gg PJXT0[dAJLJVoL|"s+ Ⱂ}&(3bdV֢.[>=i0 pp*P#-~K-""N2X \l5LL+*X_{s(3Q"zb!EE=サO/a!)- y;/ަ 2!ҥўA'u4索n$'S&EW'/aQr n%ugUM&YKȍ[XlXV1h2`yj#co6[Ҁípr&n5i^*ܕ )7kfnXjP,B(:@y*BptydfAM3Flk rH~}%l&3{I:OSk 9y#{4>v|"k̕@JkR61o*#Kh0}(<\&j73x;$&L 7!]+k]"R!| Ĩu`$,!qܰ@>c ӞldzpN`Y,#߭l, @T A60YwZn-*/WOT9 $M+oQ N=4OSX ğIlC9BrDWn?ajsbƂ[aDs>5wv%<{~.o\\#ȕn"FUw®K1-H}cCfٸX$@JxPE" HCbRBShB~K** 9Ҹ!dZ̚"Ce픾R3~iΕi8בK6ƻjida_nT eQO,TqCJ*ٮyZ}J=fzOe҉~w.z6>5hw[^4eM$Fs| >%/?zb.5d$cFP7fU٢dK̓˶c!oRz "؛ />'@ܦמXʃMmP-Pѷx*E)v];L UÆ:!4 a22˨ghv}ȕ omNDyL mb9ħ+VeD+9pXՓQe(V2aa\3 ,HJh9lѣzvzw ƞ-& c';7?t4qٍBo/~j:KmG6kQ0v/:w.#؂S !{)96+$KO@Wa{8OeX 'k7[pqXGC_hx/?©tTCt*̺ ꤒ)őVA4E Q4&<9eg~,#U'N/pp-?h;Sf] E(+ RPUh})Jl@Y2t ߷ײ) ,4%:v] L^tg9P0z-ӎwUs=3b##PPVZ,?j^i8{v+caюHGzaX:/WsFIy0 *Z_".)}o$~Ͽ6Ɯ.˶Q{Ж1UX:a_B ^|=~0gLcFtu :Ze QVd,ڻ"C9K!zϻ,߳18}U !78jʃ )׀v2ɡUIX1)WϢ y8!ePJ:΄J{b],,>\tR(>5ǧ!${<#RQ3Sg/x=;?!lo>C|6w IcΙ.iYSé, $WǫWr -76fH 0H>*WC.>Eec'oa;ME5a8]wE)N,;Ni"@sd3_{L8-dnw-^17)+j(f#Du>rH9ZO3?35: R2iɃ0iQTz9m9s@]|= į H3Vؼtۂbsu| k]KxDQE!{*;rݷbMq[omdaPeay s_:;`Ml(ic(QK^1Y !f?bM7oT, vpaEº( _ށk_n# ^Uk3:r6}~79Q`;HsFl\".`_G5(CeAcSȠ-tE**!9@3D%F Μ/&rק2{X_S AܽA*MAB7n \-PG+nG%t86{Sx*c`aMUi;Q2*ZXh"yl8:RzSԜPPl 85t 7\.t1=ƴYF)\_Gb ;/(Ryk@ԡ94&sAQ*H@5?7'M4N?JLM{ vuP'/JNIt/-N&a̷%}drՀ xP;b(2-Fl;F0) -Acb;yj0߿3*WeeD?_%viJfO.kб̄@kjff:lVF a~}_'㹓E*Ք[)X6O$#zㅪ03P9 (R(d$ r>j='EUb5o^blm:-J HDòC^E[ZkG"ӔX  'RL@mge-/ fYq'+Y0sYh}9gRlT8! lM7|p)j(wext-L.u`w J"Q07taL4mqn|ՀZZˉ&JzPYI60; `Z v O9\׍phē| X$V&]P\īV,4^-[~zS8&8ٮn|S4w7ա[y+Cz!Qy\ ;@!srX0!F!jC6v3Iґ (6HviV^50Ѳjmi(@H\?&d @֯*ysu_D8s\w~uE@0+wv#qB8qXP֭ŞoS,"PA~R?5rH x6Ϻ4= hf$!qC;!O#z[v|HbeߕLDrzBX9Ր-NP;TT{nG*4La|eٺ׹з讛HWkqo!v|+H[GdJύ;BjD7s<dvud) 4+l-{%-w+vowHO"NlL&TzjjQXL-+16MŲyܰ#Qk5AG-~N"`Rv۷chʿgR*1dF}Òfe|zn_R){Vr2 xEϕgf"ᄊi# (Do5+鸴9C)Hyvw'+4ifk݀yCz|<ׇRBYcrἸ+Xbƒʗ'z/W DKhV~|;$]!3>YgcϏkIN2m`ʫO?L&TQ8i*FkZLJBZmT-j*4Rɑ[H:y]ZPRUqf]\z jcgȏGz62vo8SծQ"췝X/r&Z*3)[99)@@_"&YGv!G$:8fCillܫ jzu@rwkj1׹1@Xa6(CbPO\{$݆Ӌ&fI@6h}YjVM!Lv*~ d:f՝߇_ fV<xm̷W"'Z AH}ixUf#js!L{_d{o-cc7-﮼aXh?WAMGa5 ȧ=FZ:=H Gd!D],cZO]>3CЋc\Ff Cwaư,ƀkk,?z\ͳ$20وoAC"Qa!i6AgWQA83 1ыp1/5%`)7#b ߂Y9f"Qg2ِAEĊVCIrOVBYߦBR]b1x+M G㯋- gR\u&qGK%{ 6aC}*x]>^`z3N:WT+ceIE'O*4;KOcD̨js3Lym$[,U+ڷZ$8"9GGAX {o|* AŪOl-r݀& l| JGzWGxEHʫךޝNȠ3]W2RZLX|*2I#EMܪzwXp tV;\ur]v.OhA XADZ|4ZoBln\&7sѪ#byU&gNEtNۖs PⱮ±] >Lp+É3s\ϯSfcc\sTEXx\`(w~b DKUYtt9 |0GȆ|b4|Uf9xb ZZ:!`8LE ]zPk =p z8zȉ+#93)"E3}lkDx㔣P Ey~Fӯ[ JC<_Zn{>MQ/s\n۝Z}W}Eq[ gCY>5xr`d͑D2SK-#Ke 7M&دZtKĔvdoQHH0(E*)\HRք?V,0֋Lu", sA%VqiwEtoM7GFTc>-8n0J`X9cIqHP.;o$,ٯ!PV'cWI z)^6O _5I2Lސ?zwC*[7oi7Ӹ#MeM7M0(,~#jn-Gz9ɮjl)m\ha"Et:cGU- v|5?Q%}ǍE G`<U ๭OUG# V=s\f>(&z|)F)^˖!Bpf׆L"j~#DD~77чZӾjo\TӞ jEmf>>!DXRڀ|_t0aoo`NDb#˞22z`'hؙq7@!M|kZ 8z\&ߚ6Ut) c7#7\q>;{+[8?𩎓OGnۅco; ЫT&t%~m2%IKSng< 63aGk)۴fN(tݳ;t2 KflO_CWKAѭ"q_x_7j9 8?5urt9LW[@k7?w>w1CƮ;!/J2Ճo.Vvv4PyUsH( ߷\0Z0OĪbVO[W|IJiy\v"R8!1X<9PA'-36(bC7)$FK潙cIЧH5}(éo$}Zi1h%wyo@ed#@ROR_ Yَp7c*LnZ WO_͏]$T:LKBn7$:o\y)Faw㹫6`|6)O SR,֮^Q ieRDRcmxhQsynh8e[E( @5&]S@q&NbSOr#sv隗ۙ* h(lGa[% &iflcl98WM!ʉ'2pL.bg$%og[_zMºÇ$,% JFK{qW'c[7qJ3ti3h,Jc < :{r(j9ӭ6czc"_6|`nI:[Tæ%(Ef~ uV ( yaKh3q珡d$ @ᒛMvU^%Ekӭ]|IݸzID$dԼ3X(7&VEݔk{<ssQqJD;k3c:"e5?h/ߔ9ȑZR#v{3{y'ȈzHfvYDt%x[[G)B7:"q1. 4?˵j`5W1B{r~W7-D>]5! z[iD+0;;J5M+j^£0fG`a#TF VCJbTeC,,1t=$;@MՇ 2J)޼*>f &SHk.Kޔ 9G3#(B8R?$qᱻM>m(@ 2㞩H{j{~`Z#.@<ͪg=Anlu4ƔI)zGejBG3NM'W {a #6ol> >k* tCRs-J16D`HF#};m4ktxhюuW6ʀ&YB61`MR j[o!yˮذ̳}TLflJ13 #dfG&0ZvUNAӈO8sn 'ӥ2:$ƷʗqQR ב R&P"+h2pOmy\U^0i[PQ8ipu yⴓ|4t;֝ i\t,RI˔3#"M\{R hxsؼ#E4&ÇM{$C N0 <r߽Q2f(lR"H*)tj9`cHƪ>HPlg)g|Wy H7 f$e]Yh4Ϥ[ 3W/k<_< \[43v'rW! &xU+r:F"N/.:'] w_s1♨ڧM>A$@AӪWjOo1cY P@)N=؀#THzG.[MaEObs(ЂW  u) 3}FHlV%na4g^Ŵmp~%QKƷI5?60;/Zx2C'(Ȑbq UUOQm4;gVu(pzt68@v<$pe}ZJ!=x()wM];=#sʭd{ .Kw=t3>x/L-~u[f3Ts$wtC JS]cl1}4ߪy5^} [ӴQn۵_;Q3F\xzed*gzV$7= 7oH/~LE@& 50RYf=Pש-M=otb=i; .Rf~YA;K;wn1HsZkBicc95Yˏx Iw74%Tzwoe7T 8=?ì(sF5Mc׺|֏*r핢9;[)H&[P7֊ mOd|ja9c91S7`r eIiyV8%$&76#jo1?|164|}(ʁ)nN۔q"/3`n`NpԪE+IK~=;7Y& 1ɒ-,p!eiB$IIrcܒy=BhKv(ٸQ&GI fefD N_yOџ)BIgrlՁ (kzCB7K2H4?-N(W8Z ӽ9HQCTfTE c$k`C*D;l7oH:!:Ɲ1l@ώ$ffNJ {Ltt5=&92i/B&#떛ƛ)R|C?SO?Pk,R;=Pu% 3p"YU; |3 (3u{$׸zM!(Lm b^QvCE}a2LMYD$ز!bC5vOӂ~؏; %7 2Y  nN(:^|h'6}Q9c}0| GEM AG@5z[m+^K$~AFZILL瘹uz3_KsldбrsM@M̋!1` fL76̱~`AycZ.lj00/ߴ3꫷ʓllŏCH"FubGb%^gՓo_pd2_~[Q&<$=PE\U"߳+Ke`|a0zKb`\v–~qM{ ZgHg|6~JDbN!ÜߝmVP:\f C~gy^C/nzJ/jf >iՔjw`Qy&hjv3O9ǪM[ײ9 /"8 t ^ȩ;Y8Moz8E s)sp9D  mrʉh)6c;3ǩ''; Sc-%?ٮ YZ1u(.8:J <\*)7ydW3`bYMzⴈ<Ϸ"U-r4k9+%f,ܗ׹jW|,{Wfel*Y-t{sЋ;"GEEv-2iq]K<6W4|g26 gC5qd*R)q"vێ@b֋Kz3ʐm-}X;׹<El恵/:9) =!*}ì^Mm1A$t`DQT:"+_װfuHRxB_y\6JM`]Dh ;yGl`:c t w\-g{ 2%L܉BU o7^9yui2ғ-wT 1q{|dz oB92J;~} S`]_؈6Qh,ҾsቀZ~1'{O6idV\2ۉ8Q{EŸOݜĜXh2"o{b$Gy- boyꍡJNnRԄ $"G,nJt0rx=wu`[d“F.l}aj)rŻ ݤCB0Kv'Lxx`r ]ł@ iJaq}ILHYd3oSm5B \m<{Ln@j=]AFf`ŝ.Typꭶtfvk5(=l p8i,?Ը$kz>ƶw|Cun3 #L38oPgF`JH+UU% DDWxfOX.B\ĉihiO$(2ֵ2!C4F ?󨷸bNK8h72%`lJӜ5yn;vs=x+@ܾh%E|̈8yLNWٖ:Pާ:h{U:d^ڃ8bjbftur` ;QMDCB R/&& n6SV@ "CaT=JZq^R9$Ȉz{ݙo+Z~3^ BRz}K([a}T`"$)a#ХzAj j(]"g腏J_RюKӥ(f|N(_PMyأ-Q8 $XԳ ?2l$Jr!u?گ;E$% ̸GP. Ar:Ei{ Z%Yݺ [K>]fv~^3F9P_oX~DϬ A&luo+g,"ʱJ"ȶ,F~2u3iJ^l'(:¬. bJlv=$u!Dh,&]E(Imj&c4׿\[^yEɵD 8ZqcpXh>ʐr&"ZOߦHGW,[l5 H4#s4ƴ:^O9P*Dݼ6]xMׅc2TLv84*Yr:T-1$/ۃ]6 UXpRZgh򄟮^/[PՂ|g̎JT|u~-ry'ezxëՇ%8=CBVm 8t{`&ЃR;sTe_3vw e _\ਔ h*O@l>ױ xYAŪ[d-О dZ})4ik DKZL{uPًYMp*U)r}FdtúFШ(Xe^Ѥ-XDd?.2,n_gL%.WdfxdKyUy`ַ% q5oTEo|cl#"(VR,6Et ?Ѭ_BytId2 5: 9q\hL)h>Vc?KonmJ۬WK=+mybͱz5iYҥy?Ճsw 鞘}A74B{p(pVJ߳u4h2 k aLqC+bd FE8dVtJ~2(ئ>(- );- &M4UaL$C3^7-S-,.OĆF6^9T9YȐa4vXsFoUǐ<7+&'ٚfs`$zhw-KRb]o1ܾrbtpdg5'[I-Aa ߾%߃lrKz9)b{G~D].]Zl:X?WfS{k֧:6 i@?҇S3tH"jm;-"RŎQQ0<'YU*Ol'vS]I(OF4n^A!q(ٻ',@86cg]5N^4 jyڶu6 &ui,$Uπg9:Uज़ʶumgu^P j0JqK 4eJ0E4QmuR/>lCpc1e8 T]O +^ɕI=wT^;t]N:a+<ʛsJ鵩V%`Myԫ4g[ Тnf&մ߾`YgXiAi5YB[m^e?Z=s+ ~_:O]?Q`Q`d|%%az TyMT&i!kIq*+h[w߽&'#=[<@Z:e0`/~}!ȵ=dF=uAk>Ć8f߾K柍G Da蜄){okXEC 9|1YVHj -k<w8zt5DCP8g+JM^!LkW;T-@20 Ho!pIsEޞω G=Sy~9tsͰu)(-,.Td_|70ɇ$oEmzvoa#U\uZ.O3DkLgNA.S Vv[_gm h$kyl|Χ Mo@{i&6{kAGE X Cqp5UcQѾ#e͋[|THLO?#:* n[`CI ;22*3 jFtL@QO?_~VL2mr2O0t$U Zʉ YkgZҾ& 2*k6*]//Aa |i*5Ryh:xxH . 0$x/T>Xw͠@y3|>[/}3im)`(t!s/R6B6bXhϵEwB\MK4ٗjf iIV9 af~pף_eT|;39=Lt*5]^NH:cw0=Eɒ! 8.BNVOPyG`G:ktH%W= < JIxᄚq}(F@룕GC| H#ꍷtsQBaPInC']E@Jor7^DŽkTKG*3.JK,kb3&17*g#@#kUbzvJw>8 zU뺆v J5WurK>yZQF4Lo[ҷ[d"gQǟVU˟ۼ?Fuhk Je7?$B+ |OK*LP EĨ 92%cc3ᑼq9o,]n@+jm(E<9p ecCKRm=8nM{3Hqvyje%5AVy=8x1ko$ڬTgZ$_)@>4a-2n_}gDh".򬯌P*W6$G?9'U"85#|E"ȼFq$/#wG;<7_/FL(◦`rG;)? Q }O|l?<'Z9 F%KZƐ269{s4m k`\1nϱS,ӡGEp!L ?ѓU>oW)U $}gL` I{Hm3N_?t~q#%fe9+\?"zu6KVFUP(G%ܭ+1/wi Fug %ډ&xJ9'%Nǡ q~S\NxH Yp] ~}%!BU 2#1oAŽ9R5cXy)FpGr-S i;<)E6*=MaxdmDx Q ]0 s#xƫnH&Z+::S]\~р[O╙.WTX&_o?4Wksc'ޔɦ4[q7\zXݚ9Uٱ{sky0ϯWN4?!p:Թnx63vr-/oNCsSdN4'MysI8y_yT4{yE1B0{'`3rѣЇȴgbPAtR J}5syVkFN#}ѵpQ8M5 ]OH(=~y?DIrSdUwC3 Ci2'eRu>VGFާ:7Ph'hx (%[LHX[>V)>yBMMMݠZ9@R͟Tn'tp nYc-</"7{$d>=s$RFa>Բe7s/fkm3rG"IKjnou1};gR{eR^>jE_,X&1n9L.f‡{Cp:i8 Vxh) |]Pa!'C]ƆJECMgf 2p4D:Ac@eL.0#rǬ /sVkFC~*(Z:J0[&0( , "V5)<~/%+ɃZz 2WY" 7[B-*GcCSIOѬ4XI?0'm3E̮*af .-bE/ [f; 8jHcѧeO 0A Z)P6Y>0q3le3Qa識vlYߧqP@i3~ ɽtdm,}yP-~2[y?%ݼ Z(܅&}˟~oZC7h"HWT}}q(#Ʃ3wؤB檇xTлcn}x1r-˷fSn1xg2H5a F}>$ +uT}Xoڤ7y )|79K,$Eҵg7EŪu{P7a:^ THFARg+:@ x^iΞ6ȁ)QqY`26q§z;-!Ƀ:rd79 &e'+Tk% oapQ=5I[rș=c#Xfs Еҏ#hAB0/L޺'b*3VFSE{YdCQG*W?^3n3l&ϋ>W#^QrMh%?uEq*:!œמf=P,%HmeBeH4q.,B9c*inCz7&#?d_̲1ttL?7%4}RL0oXNW*YŰGԆږ0m>7SH'`}Z/hcъG?I{D(>|VBSj̧̍8cg ܝ%|s2z"(`\pI^!+XUxh /tZ_aۿBw ϴ5{);}G,UP>MR\ũ3C\M &=PET4'q8FMlE4-ȓSܓF7 "N~u[rH*{&a@p㓳} N5\bF#AEL.o :[9G{xLM> UD9{)QqLO;1رVU_P6}r83>5!\{X}ΞߓN(XFs[1gO-t%|&DFi>js7p1pCB]GT &@4Xjk#Z#&(@]y5YuW1z f!9ˁr1"&ұ|/ᗐ4e5?a-oIa~'ЃtdH6N=%X)(e9]zDU\-@S(p/ldݪGi~c ,ՐAӹ5|/?m ^it&cy|ija ,vꛔaWHe $]"a |5 V'w  >)K52 +e:[j)k״aϝ VI_Kz̤*6ӺnA ? R$sO^C#ъ"$l$ yG)Ba.}-ݑ-R\5j[v;0qT$3mH.F>N%[-~2V:$>*/xթف-Yz+BEЋ\։3unxʪB(1seB3ɲόFgrCCv5ttObL'A;D=ԗ#uG @a2!G_0C2u N<٫=$%jWSy 2*iCEi` 5S^v%LڃTEe2O ]:c"P,PM;baVUa8 aX%(k͵ mfZ(+򪒵uP#53~<.,oUڄ#ọ|0rݲèW@Aշ|x[goPK)3{Ò^X.$ϲ* 7o6|(&T NP Y$XM~ǿv=KYb.Fj1e<"ZH6UY#Ȑg2 LTaV-Sf+ ?g0_-(x^AY;#Ȯ[[E6V}~U$O^E<0{Js$9jaRܷ7sߎD$Y8Gڥԅ5MÉܗk\ N3k^ji^[Zz Oo/=>Kqe?png]N!jL gzŊ8ce#/:kY6CcePڢY/7^L_ ұw7p/!:p6eL4wvOwlICn ,cdh-8VF~XU?9.[\u~wPvJqO# /Sr[l125@\xxFZ>#̖a]%ܔp1Gg7`C s{2</jTqp0Կ@PrCBՇ1ܸ;"ڽ^H†\O% EH7;EX"L"o5`M! xB2V6w: ˕ e@T.3Ckk=vI3`'9PxޠE޺R1"X3O'˖rnbc/;#l2;G̓A)-fzKt`3fI"Z]TY!A @47>أ}9e%eT aOFXc PkZPS7/_yV.F,D%-͌/KaFGrI<9ʬv4h8թґ%&/|Sf \B}`JL=QQNL>&>=3DI#J4rE3 )&7Ɖo6:29rpd"vE#{lRǕ6,nDt. x"G{y8@U-kʧ&PP3@)Z=e-py|G6~y jEl5wtЭ(")t? ) u7` [a=*p#>_%΍3>V~K(HۚT$)Ku@]q"EĨXͣ5ܤGb"2:p9᧞6G\ iwɔqL90,Mz >9 ͻZ;$ :KY!Ak1J wl6€6lwdao=g{-مH[I7`uQRǹz5p]`ג,f{e^N5/@dKQZO07i[3M ֶ;c rl+Bn=@bSFW[ E+E۴HY%8!{x CϡCFI{w+#,.`E1/NpIv2kcL7,2SٍHet~Q:nHg9 oۈFh NI{ /b_QC6>m<8sk5jC8MR;i(FVjMӄIⷌ&w:R럌=}Y)PoM\ݽ}jR-x=ٹ&0:xnwdp޵:\67q)AF"8#wl Wt0'S5bk)á!k a*!V1oíh巽P`!7_BcJw%!f٥Uz?igqU1M:fGU.A)&w+s̋+@Ol^˩N6'2m0 aĢ.-/7Τjm5j{bTk1 {vG{4c%F'06ٵ}&<I$dX&'Gw/RkX)R.ka[veeRZha䚄&O̪ݰQU/wwوS"GFͮ#SȘx#yJ1ӃQ~w*‹^clLVMcBEPza q z+\ 0+a!!hNׂnn޸.Sh\AaJ\JS _W0i"x L9;())4+b]66(1PċX><-! Eh2WhG6\[ }}su'ҵjܭK$UvU !7i^xw(AcL$kMCzvt\qlY&sSAHMrJ7!s%v;8v۸-2E,`d0妯g-\Â~ vRrh {\_L7h >0ףS݁7kYx w d-*24f $0XwmF <- .̖-}:m#`'4јЩx=?hx \i; ":L oniU3^P-$h}!#0ݙ*KڌVMu3rmtyKӡjJU3 ҦKewy]SŘ;Z/%t(& >QC 9cEy{=D?ƻkŰY7S|maS$C١~V$Ƞ tDP2PUV{2۶T@BqP|,}+ `V{8§T QTt|1xA Ģ{ğ1]N9_sXgtOY~tBVJAfdvX/s ܨ[IŠM]̉iGXdzBÿ6;[rDzOv#O|n%Fq-u̩&WӲ^=k EQ<Pq# L% \1X>U(+r8rV#_``6=v؛31n) ԭ*Cՙb$mr㯐nޟPԐrZjHw{E pDx[[I@y7rS $~s 49&d YSMz߲hVsr9 &3uH?J#W7ny1Z _]L|jhqJypzpcF%,V*d2UmְּzaSÃdF$ξFeH[DkJ\SFClڔ,!2$h1JieA#x}=;T4Q ,8GKlAx0HKuh"ś"f{"9u3͎NF>>A(٥ W~3xY;>Hg#ЬVZ-B͉F~#@m 7)T{D_nЊ˧`c"vs'!o[= |m؂Θ$ffWʓTTDA]ߚ-#mRKZYÎ | ](?LL.+2zeB>  u@pi(/SV0鈼`?K8 j23E[@) j`G3U4*=s4fjAXof7*d {;Os(ꠚsNu㺤a 9s5lw72+dhi2)yBwVj QѠ/'72EYXboڋMF׷yn:,IW,qly(W3E,J5g/ЕGNxȫ*y!2&[aJw~wyK>gC&(pȾ̆#ՠ.۴;;%l$&yT_ӮuIBRz)xN-N$2&#Ԩi>ukgA>G)pOX^51sZGYǏTlA5kz)3=_zzBÜ$~?u],L?-C /l5AXDĂp}go~?#D2cy@=Z}lSy>ŃL~zd M>]P AڱE]+U VE^XǾ(e#A2#In<Ȕ7³|pţTBW6BXE׊X1N[q*Hz*qӌ]TpD܏Ҕ2bR4o1{7tE{Deew}P&09I>O0Vq]x8_osE9^!](w&684M5<#;y)ЃF9o^Q0D5Sߊ)ƹ*Ӱ ۿuq E+ҘhC@Qt3ҫ;.f\毞Sg5]Jx~yȣx|Ţߦ)1hh' o?aHA|n?Xdjbkxt;ҁS{[dvT;8d GKrґN]_HJFz1:SG]]\,*N7 ^3߾ (]8~׉(>`V)Dt̾gm SQ;Άha<ӿawjY6˶H4=Vc`P86j!!}[.Pee0f`nu[ݩT9ݪ.`]ϊLHY!czwHK#ԉNyC`QEyqԹ RWpѽt$ho芏/{Zڨ\Z,D:M1^_hG%eLHoU $W6Q'&Enzdm!rd0t#r@`6oeۻ1^I>=O[Z.xՅMv=mc?;M./խw"^2-my&s(+64HPo!T`G >9rs h?b\?y.ܝ~#<4u#X,]<[Zh&ZO"r{h Zja#( ([@[@~)wOˡ ) }s[PIgq,ǚ4Q1SȠFuo*k!ָN;a`$Y|>fO:O/fYN$2p^QTTtKda'=L[KXr/ (~_]}7{<}_) OpxfD-x4P[(dMwᕌKMz{ @)JW`]H m#=0tWbK:eҖi0SUymuo*sUd7kP34aJJDKpNZmىʯc!|^ɉڍV=gPݲqSMJar¼^*8!գgmҦ< gSF PWJ//೘1OC"I7Ga0$` |eX-5풇r$-ey\DԽVltg%*"Eqvke6(=M:$YJ~1̕`l6jc;a'AO#–zJWK 4B-]p$Ng\X_/fϥ]._8'NZ sl%.0 cj˜;6I;+7ՋֺߤrzH'"#Jf2lYzΡm;k} ;OiY~w?>~vGT$yS;:[q1׵fq( ,8_};L@XNO Bt6Z"Ts5sd1L;jqPùVwM/8G'vUYU׎D,Ga֭/VV/ԩ +r,jkg@.1kq54瓼qx.x7{7Aŷŝm~=Z7 y؉B{?!JV(v} B. !fl^N2Z~ 2^=b 3~)79,Xdo^m&5M{ Lo|~z*)Tዡ%#Śu#b@&}1&H{OS⊬H8eŵVH7Q=YNbz4)ݓ!j\09nddkQj/An ,ﶼ[S174~efL $5aPd~_ֲ6[E8s mY[Y"j5A 0̃USmKk葖Tt|$Zom2 lZ_,S>9;a 9ڈ]d7Db<]g=,?¿?'MhwHg^> 4A+CaKr> =_QԨe8"viQ_*VXL߽c2gYz= q:rG8xviY~<$1_b*R,I_V t3aoJW KS5Գ*P:ش|_哼Q/E[ߺWAPznj4tv]c1Pl ,Pys.}MVj/F#PҷVa,KQG +\zW7d.Y ӐUY8bCSȢmO:RQVMXi¬+4f{lOQ„c*x'$Iks`†}܄-ToJn3.˳LCNWo.h:KȂ[gбE Lấ/GODC&_@ڌow{Xb*C.^kak􀙍,눯 UX3B[ըkU?wtB)vu.L]IRr>Q51۷ 7rT|'xP: xW&3wF:p^2X_`3R98EEF@ڧKM *1ufΝ$´-")o L-CZݍyK@>D0f1|YU6.VہHYʰaeC ΍1bYX\\uEGoC2ܧ7U_s7,XSY^=Zz5 %~9VeVhVPv2 ӁAY؆'[zrНGG8ߥ'9~`z+ف¤S;:MN'kJ^K/[IS , pkȨ Qx(pW؍wuCju`c$rcĊVdoN) 1 WN喒}X \ br(Pl,Ql= lVq,\DV_h*ThcJx!NkxT l2N&zt %]sZS ӍM)) _ *W=1}|mRBuD H17V9nm} МJ^cۅN$ʯzf1Tt2Cc*n4V`jYk; 剼q=S_Q"S+OQYBd7ǂ }gf',_PpB]HԦ@l P4c w[.]7D&ED; A+ rJOTa޿Fg OJ&o>S>%A]j鱜^!Q&yA?4$\ݐL1n. dNR$~k>jOaj߫FuË~ؙXb{1Aĩ%,%-,e7VO+]ns-H!CżDMcGKtbnaS ĕa?MGA:%qTޖNPD`dV+%EfV*~ uadR{7,9XNdt#>=~d) \IM#+xXVo:>I=5@߰OIi[vr A'=Bw?r!EV,dt3 .B-ޝOՃE;fz fs1HnFjRgJ{e~qt;zA=ahF|Ph՘"Z$b{SDeğ 8mP0*CX*fw[',BaMD$?K"6/|e6it?FjWgw-&0bٴ'@KP?ԓ(4\ep~ԧ2~7iJVh [M w4q7 MM"X9z@xJL^0yC-hڞ>Z"3Kun&qEd7|e\'D@3ғI8;|`Z#Y65=TUq c;*wbNn+qc]a^=(6pX)fU1Dmף-*RFB" juwg-eֲu%N.Q'|?+{6h0M΅1`*8" ۹gm|j#FqpWb$T.!O9ZYg/Vȧn<$Ɛ$[9&i 9TQlv Y6 b;wb*pqťttY\Ln 93Jt@M! 5!V5X!~ݜ{̓$zfsQ7$q my={'sɫ*qJPtG%2GƗU}@^:>)yCR<{XP]JGWN4vN6   -!n}*74 6wqR ]&vHG(Xw'lA9.x`BG׈$}û&a:S!^#a6?(q٣{~F:^oHRO?VY/k14:ꢀ]p) |-y2~ Z><1E(Ђu 5?B^b$D[-Yv1̬h*Lݘ䎋L/O)w#b[,<;=?7Cݔbl$5A[%: ;BvS2k rw0p{8߰$#SR嶾#)]ef*-*7vǣ{W鴿3ɣ Sf4BF"#J1#phOQ,-k8`#gvrݎF[dkX^1Myq~ Ɍpp6h\k;[Q̏nОR_GѫsA%*?n]*iG\2@0<漦 b\`5Nh#E0t+x{{D5QsZdD\.W_fBNﳠo0n;h*Q*fu՟DK%cLTH5vqJML9R2ZA;z>3y.#" hwb(}7q~AYKop>ڦx%sҜ3;8 !2X cȽ4m{zOGII WR!f |[;[GvP8$u{ux&73xȊד (k=?\|$r*HZ#Śs8C+ﴳm+k)lyz44aA$fUg $|jw9Iuɂ儡r[|ШC3sTy츤[nW3wrb@g`qdcaكE!T[p$[rvh%PfS8̞~uw:l1T%n]CU gwoLrS'}!]|ɲc<]tOXjNk=N\(ElRk!6ƀyx'g[d[١ׁ-`}b7QcB4o 0_Gn&e#%gO>d> o :S2*~{? tfXNm)"]uΝ(6 7}UƋUP K9ff!A0* t~&%q:"ɝp0OfR4%:&f,.rjR4} ӑ'd6,s )"e_ ])?nF(d8O( #?5\nDZV476I:חfQ^N-)A"KYfEsxLnZ] P[߰ (q 7;EL?FLXxH;q2J*|!8AsLKЧ~6b6w:²ߡOް9d8liňڡjkˑR>LG|}miǢǽk*{C7&, 6(ECUR%/BcŗWvӸт?g֦EuM0/"brBiU:nOHbY7A$AX# ,6,[ m0No|Ny#AUfJɤ*y@҂+9x- }# ݅yO@[p`@cSlC!KI/Nni Uf4s~Vsú%OAQM`(沒RHJ \nB8V\jʱ"o2!mV@OpMlv&e~odsm/9yg&M"ӥk5)^Ӣ.U!hߐH~N-N\#\-4X3ꁰEk'JcRo+KkْT$ϫjg &d;2i(Dtmrw>l.˔KfíA_PpGGN%[ƣrBˮOA]M=ɾl4)*N+ Ӏs\ N@?fUR'l9~}dzRO+eqFzN, p1f'4'o}SMm_Ԫ_!M>$1[1H : OGK(^=~l 0z^pev6a$q/1Bhp߹[46?+P1O,3xb`#%BaJHw-`ǚ{/D2]Y.dH6~~[ko+"kb0$D uVO !4l'6|o5e#gfvUp rΆR>tACJ^G⟤NHIҳf/gۡCPUbZ#"Ceo~5XV=;a 4.S!"684Hp;̭ʖře@K[cY!- kZ,{,}y-piⴸ)}zC:8܃?.G5u3[Չ0ZvƜ.t:v1*5e"c3~@ , D[b ??=<&8у"cՠe$9PZL9q ּ@ 9m5TLmf/ێT4L$6V"_搬Gfwa1 pM"/e"}M5c!'"TQL)27#C3AifV7G8+Ȥ}9AD<@XqňK=PU#M?wG$ʩ5 ֝Kߋ5.6]Z#8r| 2dbI_q3JsT }':VbkmFG}ûQ,C5و<mz~@'!KW2+Z`>S!GcVگVxEJ vZq0}f.bze8ؔ>5inD[mNS ֫jT^jhϯ/;R^fkkN![rI '[_o듶i~H!k*i%=c<=ƽPօ\M km;kWV}BN+VIWd?+)V@F57mPW сD f17 0!kC5P搇n!اj56 _IDEc6 8רM9j}ؤlNCi=+tHhs`7*rFDlӞ/?f0/t&u{{2.5}*h+$߷SJ) D )k܋kA Xa>w}7(oP%u-͘ H[i*A~%Հkoob/Z h%;4?YyU%l; <Վ D}jaAu}: H<"ιʯj}7k;Wt"ohH{h15k פc=SZ5<0 sن7&+@u9.r5zdh[B]vy7Ne/ ^*G( -_@5JUe5ymZxP<a-)nIu&ag3'y-Aȣ>V0Q :)2@,uU7 Pޏ>l3hg1 p8M3_#?!B]"tT SC}1#~bfnH{{=\Gy7x/PN">4_Ib׬,;ldּ\x_lY+*A|ZGh,P\Q_2Do. )4_s.Zhgs 4b1Cnձs%^MJćϾ I(~PZc|H³+uI$mx%t& @k'ð>r S"lkfW@zd ."~tĒϖv'/EPpwbsZE^SS=8|_juRlv}aJH:L$Yʟ> @գ0 Ț8$fL-s-1 ͔m\+YkJ `3+,z*?v4 %#s WB#Qׅ#"*$i7  $b@3౏j:F3?0VQX1TPmqgh` /Q99_Ђn4+6*튽EȚv>"Sֲ0ji?WWb e}a.n gH9^2aA2A 2+)qxJ|8P|r"(#!QtA1ɞ~g$VV;n n_?GBp^ - @}s~6=s\ilԨҁF 0)\ LCk2`e5&1KW}0uMz6l:6{( g ;'ho)XNPZZ`<Ġ|R$x- sjú}]qcܪҳ(ե 7W yn϶!kBE_q[:/,b?[F:D*]Q'9>TZ,g;[.̘W /yu-)7zoAd:aN^Uy=M%^]!il^PAН^Ƙ"}#ʠXYFo|1.p oXמP!9J:nUURIiU?"K4[H׍/dmixzDijVl #tgJْTp+Yv[)Ad2;?o@mDU2gᆋtQp;)jlyIA޴ҰPbȯPe#Q{u s$l!@D&@*\s9i1&78Z)0L\q7?Cm[{j +/XM~"q} 26G`ynſX*ۘ E86RӢyPcɒ0Srt-9#Rഥl,f<Ӭh!fSLIkxrSi|p%c$O)1!IuTJ`i b6mv, bFZ} A}QhCX/Ү-dߥvNw7.\e rq+9h9|<3V!|jonD\y %L2 XoS_&<#,.̈́i_Uqe;~ފa H[{n>EJŘ]H3x#/:F"8y°YG f~z @k5*4,p *놬5y:IsE@a ReȣF a$Fg&ݯhӱI#kNWN0( b?D!vu^L-nA6F=4@JONCwIY{bAЅZrf_[gؓz-ju4Iny%F+ IcpME5eOk:}CZcL!pcF}ˁ@̼ TmBz\Rns vSf_,FZgĮfaݦt/3ro'bl%OL͓`)(1X,n-&~i[&@z0" 0hN z63!y!6V IE x}"5H)%`džETG6)j7[UZv}6NG$ѝĆDuǣ60&K_dv M?[fBWlYƖΟ@6F,`%6Oυs.`Owh TH~XȗݑNRSe ~U+aV>S brI[P1yHܶ(޹9QظEu7WZ gȰ^B "1]]PA6.X, Ilh_&jl_ ̑2͗Urq2p^!ShAvk-+{D2Ȝ6$)R'W2;ȉAF?Q_KKѕ,ؓzaEKk;z@ؒl> @3BBoB߅xa:ԧ(v׬M F٧ s+URdN,H'Q:7B%/8=A@{Ŧ߾tՀ`M w.5lжtK9hJ aX#pO۲\W^tRO*Q^ʃB2\"j3&A`P8pd3ZWr!oz]:B/GZa%Zoξh6r[qDO u.t!Z` "aD\drm6І)k;))2@E t_}I yTYf+ =ZFt0k |wֳ%%hOnuKwjЬס~R(qCdoY(JP2/#3ATi zxu9wcو~뒿f"j;dB-.3by"L#Ήv"4ܽupD_:kr (Qa Xeh}ɖ,:R *R 뵲dbۢ)lZ!Lwk˦ + kݞ.M1(@?|;#Y/j pW7 #lJgؗ1 +8ʀjלalϧz&D QX |xtYɿY7C"_sdbVQvVo٫Y,[R9`)%5zWtn6tJצMxcNսTR[;-Ӹ TY!IJU)#s|96 gk*]Qjtvz3aN8-,%1*7S+pe+v f?xEG[m8:9*xol \>C@](W' Ex+&B_bQnv;N⇙ 3m:N:='+G{}$䐉"¶GؕjHAݥh ^ȶoZs\ڥNwȣn(9RZ>tY:Uey4]if/* p?8R3m !x߫G\"}~|W`"8?XO<:3˦R䚯# (+hߖ3"Uvp-I E.9yɞGf<{lJ1=n3::&|6ߚ *ӹd GN .PDaix f{{\yh7zegŤHTa) QBmGAh}sǔEgD,F9 b¸H2U\Pc5iX ,VNmsk.~Ȑbpߣs,>^6?Mrxh;M|WkQFt*]#mS1~㘄?BKZQ9/50i$izÐ7F*AL@ )tT.dIG͟z٭&=2ΌMZSQ^LFk%bЬ.]Z,tC1Xե[ 8ruIDN̸P8${ YR)6>M7lo 3F@0 F*@r'a,ojԤeࣛwPf0E{g <& ȌEgaU]/NB9X>(2X]l,3^M]ktJ,|mvF4QᶳD(PIcakVː茡%9pm{@I}<?bo 5(yzA(s#,N8X5;tvkzb,t67ŷUfa~2J:AC@{UͩmL%JՀ"MV.X *^Z"6p7#ܕפH#,h)t;*5ەY蠀㨚1i Qk~.fO ZqE-SH r/AYp܎7`G|qf(ç]o QY ?dQV5R5X `2W2jBxB(N&ΉtPy3}M xFΊwW>"OvaـpfeKJJWeU|DT_eyʳט-Ol ; Znnʜhm~t=^;K9J>r®_3+u;\:my*XmCLR4Q}~Oy{#߂ >b 4 2S;o>HecA}pMc%[Fݽ/V&Y"(~bY ӈ(9 Cm` O[B}c_\jB;tU6 _ ~2,H|OtZSko*i5-(qu^ o"A `15ldL%0#,xQ<˒Xd<;'y"t,Hr_u@4X!+߹49R0l=LNź3rwjt)FBHxX a5r֛BS2<9 f  .sBIW =u5uPj7y0\fd>;dj@C (~{vr|ԭĊdC,VOZuEzX=7P:mK(XT/ nqE&l " &/}!̃Q.)W:' 6'>;aI8@e/= M8OcMaCM}/+i5320MyC.5gR;:b$I8KpQh͇vA⒅9R:%8xH%6K&@OF|1̒ۢkQC5[lЯm1/s,wԶ)wd0O|!06S7|ɦ| vrd0VB Q)ꔴJGSQU]b$FrCj3x@ahyL̕]N 0CMB`v#c[/MW~>Bo7Mpb,(5Ơ P<TJC</5D[2{Cľ7Hr2P8Sv, sm >p"49Y}"4u(Cz'}ȳ]<?2o JxNd~WC’w1N%YDkf܃m9tI8[OI+GwžLrk P-ux/mSq~}"6cR D 㠗ά1[( )}B};}%', պ~PoѦ% %7^d'nX6 \G{ʍL[ τth\rn_Fݍ"{)bV>Kw9sxo_h9ƖZJ 3.M À2Rt!13 '5[VݳmB!dA"Z\iY3_56 %p_uۀ49J0*U7)?@2=iԒRLoe8Y;2DcRwmŹil>H3jBZ i2b?d}5d?,)P~RHR@"sٴGƴnd3vP= QbPLkj_6i{tm*fl0c) B>HdCiM{ZC{Tw%7ƈQDЊkX%NCIߴW{a@1HT)'-- 30^z!Ǖ$0pɕ`\B}mOloXKߞQ{ ƇFr6sucv1Uq:A\cpWj5`Y^'ԣ/K&NGȐA92L?܅ `*?^I28x05u:fQVmt XI4> w ['L@Q'lӢdJMk74GQgLRhQQ , -ZB 0 VV~zy9C{TECm E gv&u+4VըSsnk<OtOPҿ.j_Y4*Yi_ze)Dr7psvzZ|6)?\,ųf=esoz]x_E+914Ê TIz\)F;F?,ǐL<[I^4RLlle8u*Q)9$QCX}FF[-I|tZt4•; C3'r5'&qNL !|>|@8}DPT ˟D@߷͓%S_w^CZ922I=pȜ=Oti1V޵Q^LR`^1Yg҃{Wwb%! ƛHmjw?E.dz0w$Tedlw.kS8" h+6*F.RuNW,z1o6YR |oh!Fu{/9Y* {]Vڡ0@|L9ݫM/n8l xe r~' 6 sOA,\flљ5ږiAn J<9zO'dI'd@5b~ע4f 7%p [nIkAUsHuγg`TWa j+عA)31Dp@U8Qtz?d\sG?~:T0=pnt΁ei=@7Y$a>Om4։}dQ@YF Jh(JeR7WBe[нqR ~Jm7%׿*>JS*3l9y|KjPI]. 5Hx2=i:֝R#+K[U'GRabWؠ?﯃TٗM?AaӔɧVnr|3޶)hcl _W؊l*A?:c60I73 l>-]~̘S@(x4 m>hQƪJcĿsqdpax:[qčȯ@X'ʣ $j(lr oFegլT>'"Hr-g ٮ_i_V O 7&8?TAۢޑ,otU0'*"rZהi O2?E՟~^0bq\ͺ"y n,Dw{#Yr.y@[uJuZeb4lYhsjj7+O9gSad20 `+^-OS*ud+=;Uܳ&ft@wʹsVs5N6% YT7YenC s=}+q'Y7r/@:yyY6-J#~)g:6J&$}הrF6y*UhsGJvzbaحD.钝 9SH:6E18:AU9җZ{F{itA;+LL=oBklՃh"') S)FB9g͍uP4crI5Yy[4d)utj41nlvՕh4U;Ԣz|Z_3pyQt9l =6B .5Ҡm33ǫ%mIêJT#R!/c>%OH/қ`@ehwLo)4ku_*>"Щ)Rt쩮FBUg<Pn'zM8L<GxC#w{Γ:3l%oK:qPqI@a*q dy= ۆl $3E)f)\?ӆZD b$F-ꦐM8FEDK9 ٲN{ힹ&3gf:[.!GZTSNKS1rHoe_$>Tb߬w`}qI3*ƹ* UA0*I>`:X~װODHO Z-n| sz@[~%zHC{%>x->9a kD\{s-@h*3C<^;g@SɉEPrq9;05 eܾt!S'JY.'pƗwmo,XW32>HtjG4_T`Z$t3n'f?ہm5]4$G a¼&6zP3j&8E4cVq~{Y{x " OQ"sukҹLHrxD<@yx` ~AA_"ڰR_I"|\ b˸ :;( 7B DSƏXrhQkPstȲzDR \aϫ :Yf.0NYVx^QKҋJc5ZU_ ;3v4"G5υ^PPO|[Ҭ;[OI<Ƌ&BB}0ON]oa<_=jRP݇%1"XސfD@DaOZP< 5N2Xo6"1G` bpGzG1x,3Z` ոTa⫭ ft4|+_̞Ĕ&p{#CUC-#FvE "_{[=}/zKNz"'2v$1;Xe ր]q+6}1d8׈hXedϜzzm q&'Ũ% %k܌GŜ T vz [keu_y#ST,8RC4ID&6&dl77@)(~^! ڄh0Cvo+OȅǠ 0;)of ~1Xu*ophEy5KG?t~g=-XCĪHe}Jx+Msmɠ%W eT@m\U<3D<؍"^:pb$8sQt9$\d.8;+J&Mƺi:'OJMyx-e6ltʅrk|B:/ 00ߒ yTZKhD bÙY0aB8:cuz7vw#718), h_.Y;z'GU0+z7}`:rDSgRp4 H(GPrn Hj۳[*Mڏ}(>7Xt?OO])h$^)8q(~#EZz8Ea'^ukA1sBvS.:`x4ZZ86"O2'J+2ȕk6؜c'iЪTV2)#RXaS5:1شjLoc͟VW [Bi^Mʳl*DS5CGbvS <`?<}*i̿ 884!YT U6C*r(;I΀h9="姳p byT:տ{!̾]tH)y;`O:<.vwq dúMPZr5E]a4[VYPڝc=cDFdhLPywx ƭǴU =@/8C̥o,>W$Vi1(;0?3Q{?D&+'Њ Y_ڃc1lb+tvV}aSqFh]cLT'%(>ʼ`6.#a~!]#83p@Q8/_O'_B )uQ+/gix w߃6/E!FM?#CԳI͵pyWɧ+cykm]zuRJ7LDS0܋DTfDn O dl^uQOD&Yܬ0mOH |ibZv=sXP}H?0ٓ0#o9ПnGlydqJ^MLSJw]bVU|\z:̿Cޗ]++ ;IwY杘̴I#g7a9~VܑMтordh ,фs׵e.煲 sZǚLD$FCI po`aTE՟틅cƣ#>Z[Tp/qzzFU44۱aFQM>BQ/f- , ybq(3Q QE_ .cXC˕y]+(8r;#*D00*vzi0f7P\s(^5Bv&N`:?˖j<.}U`QP#ӫH? #^ΊBv@pat ] & GBQmh%f: "V $OkŀN;R=s7:$dIүǒK̃О6ܦ׆y$;rɔ|!`&e+1IIn;G91tme.#!F:X%r<3DK GtdZ!Γ.%4du`f3hDvؓz # Ù &usMX`O 2MlB}Wq{NQ-yoiҁ1_lsfPAPMGĪ% _`A߮H6(@N5y`me#`h168c)g~p*jΕ{ ^( ?}<["tk䤶|!}}esɼX$jgK)px6Jio*y;o`~X`p;IĞ˛aPU?dQ9ADϙgrszjbRMDvwĘh=(8=zhh2Ip@K쵤FζL-y?"Bؑ^&j4 \8~$; uNۊoF4~0X~0PtP6V7_ eu[[Vw;;9&E'xYPXNpFX;3CR2Y՛kob C?Ot9\6!YXuMB,Sh8"lz^4m ?M|xًxp!)}V=>r ү/]-eB,-PӋ5) ;y< (xGzWUq"%.}+kBcɽ~$Df!ے*])ȌEOUjTmO]yY:udЖnmܶOIAC*)N=hE\Qv_JK| `06CH]Lw3խ|Y|\$=}']l}"P^BdkF)sέzVA[/*8F3F"~ab`Bš,x(֋%v,! Ώ \=hO4só1DET 'n>#fwD7=v}Fyzևn?vMVJO>iO? (wS\Ic<ⱶ,MU#Yd;#M?x4&"W m -9E7E#Y.0j}xW4vFN!ud!lZSHȀ(>u\6%8+>nIgZt. [%I신IO]^ NaܧG5`{v.^:,bm 5ѠE失D|n +NS1|]I2jƸ0aV /JI܄~Iһ8v,g8r$cW%"J,ycf52f^[X\RO!<WDά¢ 2+˹EcypNc!C^K%OI1 ?rXCj{NL65^0?C1l!/¨ <Ḡd]&1r_vNԠ?[!`hZ*zV.+#Z.#ם7yѶރn=:|;C6aHŽW ,5B DiO?GeKR-9~HЗ֭ަʼnlgvA!4]Eb]2ZIƶl'ާ.3sJlIO]L$Ej"x_382&(YtZ|`e8:68J7{3(rYNulLfH2ӑtth`Gד{jw InlW)(gvU;bSQWAT,Ykpn7N?%[:rKOXʄ*4.)6 RW"ʻHd Ql5zǥ]j|IC3Hd%[Y zZO`ٌ"`VbVJ9h"j1x)'n +AH-F h*xɇEBҚ ψ5Ύ[GQwH i.ȥ\e*"3˜5Komw{ժ\g#57yg\}jX0T{0m/@ha\;@<6Sns;3mhmq?53Ӗ՞{]x@ |Cfc`[/&?ŇBe iDpsh| l)m!)yȒLKU|dĶNrR.ÝqΐNӬlEf]PKؿc1:]Q(c1m۠9_fn=QDi QMHW{y7oŊ%A4=n #q#bCgʸOz8@0I @@}؇48gHm<$JL,]S(<y}pzHp;Vcݞ 8${[Dg˫SG#W8m8ӈQU#%g̚W^yoktjDZm&v(KЮ" im,;5 RYUSBF\;iWb&g_W&7hLP9ƫ/ff\(@#\#!e| _sJ]ahMA+[iF~'ݱe%)o~p;SAUaD >K n1]mH<Ō&6,$·,ncd&7eoƆw0Z-(i=M~`Ė-hҍX.A-369\wA<־KtN@ºD=_2GҌ(u;# +=[Id<|>F҈ 2;M&`!|=gÔ j]JEڱE,f\!J ڧ:wCi~}9XdgWy;$Ѣͻb=\.3]1ĜoFhqSרvR49bő$~ Mjpm3ʏK e 1j+MO͟JRGZy@o[SDTu"5޾P!I&kR^.dF_%-W\tk\W\\PRbȝ1noSCGa`#{ۓ8~z؋(>(VdX@I6j+sz?Y) smoq32kMgsDCXl9L}(:Os&|Ho}O jA@N沁-+R(C sV pޣ҆/DŽ;uJ$A-?D1f@ծq%!E ^ixe[gXІqРٿjh_t4 7%\L+0Ǖs+Kv~I4sXys[>zt K0(6Ȁ&-su|%!qaHpSٌt',bm_I q} m]fM< AC&*{UyZ`M1o`Aԉ8T 1Gu+`L2 Lmwv#w[;>61p`%l_4ykT,cJF.3h゛d< kVdeUz?C L\VNX|%N``c%$]AcK;r **{E0g?iq8--W"UQ׭3K22缈eNa&5JE͘zBW^0YpREl'ɓNNg]C4wL,.=sQ"8x5 d9>su/ 84DS&NoF5Bq=U:AS)@pä:x(uoe1IEplFk`  _/~?Ծ}C'O1ߊTB nE^:t;|IR6mGnV(|̖) y<%sp( _4VcE5ܲ wn{B/gk1dh8tw*(%Xw jNa"v F$aCloGc2ig' >p p~OihӒ&!K TērP,A|H$yO;N<{@`_p6+>U.v܋Zʨ3MֵG݇|^[4dz08}jH#{D H>J[X)ҨvFbc8R PImJT#\Eu C4hp6ݫb2q72|D?2'G _NVWx C7 C/2--=_l:%Mk10Y\,DƛZxѫ^/ R3u{PPKى;' I~x/0.n孉ͼf;&5ڵ | eԙEMݾ,h}oo񃿾9| J*sItB* J=!4AOqAO4ΈMcqD=Âop."MQz{nn$UẊ+ZWA:U&Pv Q!1gn|;0'9K oD)8`߂N^E&fb7n'gihx4&who-n9Ǯ9i63  e1UٛQY YZ