xorg-x11-server-wayland-1.20.3-150200.22.5.63.1<>,;clp9|ӂ|=wxξ|B31H |jkU0+IqZrOzSu Z8WZvCPo@XbOҔg*a@5wtQ2z[1P?ˣ|GQmFF[쑍ϕY\u*_TBb4GӼ 5FJOX"MX*!I>)*yV1VHj^ӏ+O"$o5*  X ?4*>up>A<?,d! 2 C +18< > @ D  '''(89:8FGHIXY\]^b cd>eCfFlHu\v`w$x(y,!z(Cxorg-x11-server-wayland1.20.3150200.22.5.63.1Xwayland XserverThis package contains the Xserver running on the Wayland Display Server.cls390zp32'SUSE Linux Enterprise 15SUSE LLC MIThttps://www.suse.com/System/X11/Servers/XF86_4http://xorg.freedesktop.org/linuxs390x'clk958b2c40e367c40b3207d880c94ffedd288a3a3f946ece65734807d03801dc1brootrootxorg-x11-server-1.20.3-150200.22.5.63.1.src.rpmxorg-x11-server-waylandxorg-x11-server-wayland(s390-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    libGL.so.1()(64bit)libXau.so.6()(64bit)libXdmcp.so.6()(64bit)libXfont2.so.2()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.2)(64bit)libc.so.6(GLIBC_2.25)(64bit)libc.so.6(GLIBC_2.26)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.2)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.7)(64bit)libc.so.6(GLIBC_2.8)(64bit)libc.so.6(GLIBC_2.9)(64bit)libcrypto.so.1.1()(64bit)libcrypto.so.1.1(OPENSSL_1_1_0)(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.2)(64bit)libdrm.so.2()(64bit)libepoxy.so.0()(64bit)libgbm.so.1()(64bit)libm.so.6()(64bit)libm.so.6(GLIBC_2.2)(64bit)libpixman-1.so.0()(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.12)(64bit)libpthread.so.0(GLIBC_2.2)(64bit)libsystemd.so.0()(64bit)libsystemd.so.0(LIBSYSTEMD_209)(64bit)libwayland-client.so.0()(64bit)libxshmfence.so.1()(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)xkbcompxkeyboard-config3.0.4-14.6.0-14.0-15.2-14.14.1c.cEcOby@b4t@b-b+9b!@b a@az`D`@`v@`v@`t6@`@`<@_^@_^@_@_O@_D@_*@_"@^^W@]@]m@\A\,[@[@[@[ā@[t[i[\Z[Xf@[P}@[D[:[2*[*A[@Z@ZZԐ@ZJ@Z2@ZZ Z}@ZTZ?Z/Z@Z YY@YY@Yh@Yg`Y_wY[@Y;@Y:Y6@XX @X+X@XpXXwoXN@X,J@XW@W@W@WDB@W9@W/*@W'A@W#LW @W @W @WKWW@V@Vn@V3VVm@VxVVV&@VV@V@VV@VGVVVUVA@V0V0V7@UU@U@UUzUuUn@Ui@U0U:T!TTTԬT[@T[@Tk4T`TN3sndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comtzimmermann@suse.desndirsch@suse.comsndirsch@suse.compatrik.jakobsson@suse.comyu.daike@suse.comsndirsch@suse.comyu.daike@suse.comsndirsch@suse.comsndirsch@suse.comdmueller@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comtiwai@suse.desndirsch@suse.comsndirsch@suse.comsndirsch@suse.comfcrozat@suse.comsndirsch@suse.comsndirsch@suse.commsrb@suse.comsndirsch@suse.commsrb@suse.comsndirsch@suse.comtobias.johannes.klausmann@mni.thm.demsrb@suse.comtobias.johannes.klausmann@mni.thm.dejdelvare@suse.desndirsch@suse.comtiwai@suse.defcrozat@suse.comsndirsch@suse.commsrb@suse.comsndirsch@suse.commsrb@suse.comtobias.johannes.klausmann@mni.thm.demsrb@suse.commsrb@suse.commsrb@suse.commsrb@suse.comfcrozat@suse.combwiedemann@suse.comsndirsch@suse.commwilck@suse.comtobias.johannes.klausmann@mni.thm.demsrb@suse.comrbrown@suse.commsrb@suse.comtobias.johannes.klausmann@mni.thm.detobias.johannes.klausmann@mni.thm.deilya@ilya.pp.uasndirsch@suse.comsndirsch@suse.commsrb@suse.comsndirsch@suse.comsndirsch@suse.comopensuse@dstoecker.desndirsch@suse.comtobias.johannes.klausmann@mni.thm.detobias.johannes.klausmann@mni.thm.dedenis.kondratenko@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comtobias.johannes.klausmann@mni.thm.defbui@suse.comtobias.johannes.klausmann@mni.thm.dezaitor@opensuse.orgtobias.johannes.klausmann@mni.thm.detobias.johannes.klausmann@mni.thm.demstaudt@suse.comeich@suse.comeich@suse.comeich@suse.comsndirsch@suse.comsndirsch@suse.comeich@suse.comeich@suse.comeich@suse.comeich@suse.comtobias.johannes.klausmann@mni.thm.detobias.johannes.klausmann@mni.thm.deeich@suse.comeich@suse.comtobias.johannes.klausmann@mni.thm.delbsousajr@gmail.comeich@suse.comeich@suse.comeich@suse.comeich@suse.comtobias.johannes.klausmann@mni.thm.deeich@suse.comeich@suse.comfcrozat@suse.comeich@suse.comeich@suse.comeich@suse.comhrvoje.senjan@gmail.comeich@suse.comsndirsch@suse.comsndirsch@suse.comsndirsch@suse.comeich@suse.comtiwai@suse.deeich@suse.comtobias.johannes.klausmann@mni.thm.detobias.johannes.klausmann@mni.thm.demsrb@suse.comantoine.belvire@laposte.netmsrb@suse.comeich@suse.comnormand@linux.vnet.ibm.commsrb@suse.comdimstar@opensuse.orgsndirsch@suse.comtobias.johannes.klausmann@mni.thm.deeich@suse.comtobias.johannes.klausmann@mni.thm.demsrb@suse.comsndirsch@suse.comledest@gmail.comsndirsch@suse.com- U_0007-xkb-reset-the-radio_groups-pointer-to-NULL-after-fre.patch * XkbGetKbdByName use-after-free (ZDI-CAN-19530, CVE-2022-4283, bsc#1206017)- U_0001-Xtest-disallow-GenericEvents-in-XTestSwapFakeInput.patch * Server XTestSwapFakeInput stack overflow (ZDI-CAN 19265, CVE-2022-46340, bsc#1205874) - U_0002-Xi-return-an-error-from-XI-property-changes-if-verif.patch * Xi: return an error from XI property changes if verification failed (no ZDI-CAN id, no CVE id, bsc#1205875) - U_0003-Xi-avoid-integer-truncation-in-length-check-of-ProcX.patch * Server XIChangeProperty out-of-bounds access (ZDI-CAN 19405, CVE-2022-46344, bsc#1205876) - U_0004-Xi-disallow-passive-grabs-with-a-detail-255.patch * Server XIPassiveUngrabDevice out-of-bounds access (ZDI-CAN 19381, CVE-2022-46341, bsc#1205877) - U_0005-Xext-free-the-screen-saver-resource-when-replacing-i.patch * Server ScreenSaverSetAttributes use-after-free (ZDI-CAN 19404, CVE-2022-46343, bsc#1205878) - U_0006-Xext-free-the-XvRTVideoNotify-when-turning-off-from-.patch * Server XvdiSelectVideoNotify use-after-free (ZDI-CAN 19400, CVE-2022-46342, bsc#1205879)- U_xkb-proof-GetCountedString-against-request-length-at.patch * security update for CVE-2022-3550 (bsc#1204412) - U_xkb-fix-some-possible-memleaks-in-XkbGetKbdByName.patch * security update for CVE-2022-3551 (bsc#1204416)- U_boo1194181-001-xkb-swap-XkbSetDeviceInfo-and-XkbSetDeviceInfoCheck.patch * Out-Of-Bounds Access in CheckSetDeviceIndicators() (CVE-2022-2320, ZDI-CAN-16070, bsc#1194181) - U_boo1194179-001-xkb-rename-xkb_h-to-xkb-procs_h.patch, U_boo1194179-002-xkb-add-request-length-validation-for-XkbSetGeometry.patch * Out-Of-Bounds Access in _CheckSetSections() (CVE-2022-2319, ZDI-CAN-16062, bsc#1194179)- U_glamor-Make-pixmap-exportable-from-gbm_bo_from_pixma.patch * avoid consequently failing page flip (boo#1197269)- u_sync-pci-ids-with-Mesa-20.2.4.patch * sync pci ids with Mesa 20.2.4 (related to boo#1197046)- U_0002-DRI2-Add-another-Coffeelake-PCI-ID.patch U_0003-dri2-Sync-i965_pci_ids.h-from-mesa.patch U_0004-dri2-Set-fallback-driver-names-for-Intel-and-AMD-chi.patch U_0005-dri2-Sync-i965_pci_ids.h-from-mesa-iris_pci_ids.h.patch * sync GL driver PCI IDs with Mesa (boo#1197045)- U_xfree86-Fix-NULL-pointer-dereference-crash.patch * Fix a regression in u_xfree86-Change-displays-array-to-pointers-array-to-f.patch (boo#1196577) * Credits go to Simon Lees (sflees@suse.de) for finding the fix! - renamed u_xfree86-Change-displays-array-to-pointers-array-to-f.patch to U_xfree86-Change-displays-array-to-pointers-array-to-f.patch since it's a backport from an upstream patch- u_xfree86-Change-displays-array-to-pointers-array-to-f.patch Fix segmentation fault during terminal switches with multiple attached displays (bsc#1188970)- U_xfixes-Fix-out-of-bounds-access-in-ProcXFixesCreateP.patch * CVE-2021-4009/ZDI-CAN-14950 (bsc#1190487) The handler for the CreatePointerBarrier request of the XFixes extension does not properly validate the request length leading to out of bounds memory write. - U_Xext-Fix-out-of-bounds-access-in-SProcScreenSaverSus.patch * CVE-2021-4010/ZDI-CAN-14951 (bsc#1190488) The handler for the Suspend request of the Screen Saver extension does not properly validate the request length leading to out of bounds memory write. - U_record-Fix-out-of-bounds-access-in-SwapCreateRegiste.patch * CVE-2021-4011/ZDI-CAN-14952 (bsc#1190489) The handlers for the RecordCreateContext and RecordRegisterClients requests of the Record extension do not properly validate the request length leading to out of bounds memory write.- U_rendercompositeglyphs.patch * X.Org Server SProcRenderCompositeGlyphs Out-Of-Bounds Access Privilege Escalation Vulnerability [CVE-2021-4008, ZDI-CAN-14192] (boo#1193030)- u_modesetting-Fix-dirty-updates-for-sw-rotation.patch * Fixes broken rotation support for DRM drivers without hardware rotation support or direct vram access (bsc#1182955)- U_xwayland-glamor-gbm-Handle-DRM_FORMAT_MOD_INVALID-gracefully.patch * xwayland: Fix invisible window produced by Xwayland (boo#1186092, boo#1184906)- U_build-glx-Lower-gl-version-to-work-with-libglvnd.patch, U_meson-Fix-another-reference-to-gl-9.2.0.patch * fix build on sle15-sp3 with updated libglvnd/Mesa and their new pkgconfig files (https://gitlab.freedesktop.org/xorg/xserver/-/issues/893)- U_xwayland-Do-not-crash-if-gbm_bo_create-fails.patch * xwayland: Do not crash if gbm_bo_create() fails (boo#1184072) (boo#1184543)- U_Fix-XChangeFeedbackControl-request-underflow.patch * Fix XChangeFeedbackControl() request underflow (CVE-2021-3472, ZDI-CAN-1259, bsc#1180128)- U_modesetting-Fix-broken-manpage-in-autoconf-build.patch * modesetting: Fix broken manpage in autoconf build (boo#1182510)- add U_hw_do-not-include-sys-io-with-glibc.patch (bsc#1182884)- u_xkb-CVE-2020-14360.patch * Avoid out of bounds memory accesses on too short request (ZDI-CAN-11572/CVE-2020-14360, bsc#1174908)- update U_xkbsetdeviceinfo.patch * fixed broken patch (bsc#1177596, comment#18, ZDI-CAN-11839/CVE-2020-25712)- U_xkbsetdeviceinfo.patch (bsc#1177596, ZDI-CAN-11839/CVE-2020-25712) * fix for Heap-based Buffer Overflow Privilege Escalation Vulnerability- U_present-wnmd-Fix-use-after-free-on-CRTC-removal.patch * fix crash in XWayland when undocking laptop (bsc#1176015) - U_present-wnmd-Relax-assertion-on-CRTC-on-abort_vblank.patch * fix for Xwayland abort in Present code (bsc#1176015) - U_xwayland-Avoid-a-crash-on-pointer-enter-with-a-grab.patch, U_xwayland-Check-status-in-GBM-pixmap-creation.patch, U_xwayland-Do-not-free-a-NULL-GBM-bo.patch, U_xwayland-Update-screen-pixmap-on-output-resize.patch * various xwayland crashes fixes from 1.20 branch (bsc#1176015)- U_0003-Fix-XkbSelectEvents-integer-underflow.patch * Fix XkbSelectEvents() integer underflow [CVE-2020-14361 / ZDI-CAN 11573, boo#1174910] - U_0004-Fix-XRecordRegisterClients-Integer-underflow.patch * Fix XRecordRegisterClients() Integer underflow [CVE-2020-14362 / ZDI-CAN-11574, boo#1174913]- u_xkb-CVE-2020-14345.patch: * Fix XKB out-of-bounds access privilege escalation vulnerability (CVE-2020-14345, bsc#1174635, ZDI-CAN-11428) - u_xichangehierarchy-CVE-2020-14346.patch: * Fix XIChangeHierarchy integer underflow privilege escalation vulnerability (CVE-2020-14346, bsc#1174638, ZDI-CAN-11429)- U_FixForZDI-11426.patch * Leak of uninitialized heap memory form the X server to clients on pixmap allocation (ZDI-CAN-11426, CVE-2020-14347, bsc#1174633)- provide/obsoletes cirrus and ast usermode driver also on openSUSE (jsc#SLE-12127)- specfile: reenabled XFree86-VidModeExtension (boo#1164020)- Build XWayland also on s390.- added patches required for NVIDIA's PRIME render offload support, which is available since release 435.xx (jira#SLE-8470) 0001-xsync-Add-resource-inside-of-SyncCreate-export-SyncC.patch, 0002-GLX-Add-a-per-client-vendor-mapping.patch, 0003-GLX-Use-the-sending-client-for-looking-up-XID-s.patch, 0004-GLX-Add-a-function-to-change-a-clients-vendor-list.patch, 0005-GLX-Set-GlxServerExports-major-minor-Version.patch- provide/obsolete no longer existing xf86-video-ast, xf86-video-cirrus on sle15 (bsc#1120282)- u_xfree86-Do-not-claim-pci-slots-if-fb-slot-is-already.patch * X server does not support mixing fbdev with other drivers, so claiming pci slots when a fb slot is already claimed only leads to quiting with fatal error. (bsc#1119431)- xorg-server 1.20.3 (see changelog below) superseded the following patch we used in sle15 before (bsc#1112020, CVE-2018-14665): - U_Disable-logfile-and-modulepath-when-running-with-ele.patch- U_dix-window-Use-ConfigureWindow-instead-of-MoveWindow.patch * Fix abort triggered by some uses of screensaver. (bsc#1114822)- Update to version 1.20.3 * Disable -logfile and -modulepath when running with elevated privileges (bsc#1112020) * LogFilePrep: add a comment to the unsafe format string. * xfree86: fix readlink call- Update to version 1.20.2: Lots of bugfixes all over the map especially for modesetting, glamor and xwayland!- Update n_xserver-optimus-autoconfig-hack.patch to v5. * Fixes provider auto-configuration with nvidia proprietary driver. (bsc#1103816)- Update to version 1.20.1: This bugfix release fixes several issues in RANDR, Xwayland, glamor, the modesetting driver, and elsewhere. - Packaging changes: + Adapt patch N_Install-Avoid-failure-on-wrapper-installation.patch to work with the new version + Remove patch U_Xext-shm-Refuse-to-work-for-remote-clients.patch + Remove patch U_modesetting-use-drmmode_bo_import-for-rotate_fb.patch + Remove patch u_modesetting-Fix-cirrus-24bpp-breakage.patch + Remove patch U_exa-use-picturematchformat.patch- U_exa-use-picturematchformat.patch * Fix breakage of Xfce (bsc#1102979)- fixed build on s390(x)- u_modesetting-Fix-cirrus-24bpp-breakage.patch * Fix breakage of cirrus 24bpp support on modesetting driver (bsc#1101699)- Remove /var/lib/X11 and its symlink, it is no longer needed and doesn't work with transaction-updates (FATE#325524). - Move README.compiled to another location and use tmpfiles to copy it at runtime.- U_modesetting-use-drmmode_bo_import-for-rotate_fb.patch * fixes rotation in modesetting driver (regression with xorg-server 1.20.0, fdo#106715) * might also fix boo#1099812 ...- U_xkb-Fix-heap-overflow-caused-by-optimized-away-min.patch * Fix heap overflow caused by unexpected optimization, which was possible because of relying on undefined behavior. (boo#1099113)- U_Xext-shm-Refuse-to-work-for-remote-clients.patch * Avoid access to System V shared memory segment on the X server side for clients forwarded via SSH. Also prevent them from hanging while waiting for the reply from the ShmCreateSegment request. (boo#1097227)- Remove n_add-dummy-xf86DisableRandR.patch * After upgrade to 1.20.0 the API officially no longer includes xf86DisableRandR, so there is no need to add it back.- Update to version 1.20.0: New features: + RANDR 1.6, which enables leasing RANDR resources to a client for its exclusive use (e.g. head mounted displays) + Depth 30 support in glamor and the modesetting driver + A meson-based build system, parallel to autotools + Pageflipping support for PRIME output sinks + OutputClass device matching for xorg.conf + Input grab and tablet support in Xwayland - Remove upstream patches: + u_xorg-x11-server-reproducible.patch Solved slightly different + u_os-inputthread-Force-unlock-when-stopping-thread.patch + u_xfree86-add-default-modes-for-16-9-and-16-10.patch + U_xwayland-Don-t-process-cursor-warping-without-an-xwl.patch + U_xwayland-Give-up-cleanly-on-Wayland-socket-errors.patch + U_xwayland-avoid-race-condition-on-new-keymap.patch + U_xwayland-remove-dirty-window-unconditionally-on-unre.patch + U_0001-animcur-Use-fixed-size-screen-private.patch + U_0002-animcur-Return-the-next-interval-directly-from-the-t.patch + U_0003-animcur-Run-the-timer-from-the-device-not-the-screen.patch + U_0004-animcur-Fix-transitions-between-animated-cursors.patch + U_xfree86-Remove-broken-RANDR-disabling-logic-v4.patch + U_glx-Do-not-call-into-Composite-if-it-is-disabled.patch - Adapt patches to work with the new release: + N_zap_warning_xserver.diff + N_fix_fglrx_screendepth_issue.patch + n_xserver-optimus-autoconfig-hack.patch + u_Use-better-fallbacks-to-generate-cookies-if-arc4rand.patch + u_xorg-wrapper-build-Build-position-independent-code.patch- U_glx-Do-not-call-into-Composite-if-it-is-disabled.patch * Fixes crash when GLX is enabled and Composite disabled. (bnc#1079607)- n_add-dummy-xf86DisableRandR.patch * Add dummy xf86DisableRandR to fix linking with drivers that still call it. See explanation inside the patch. (bnc#1089601)- U_xfree86-Remove-broken-RANDR-disabling-logic-v4.patch * Fix crash on initialization when fbdev and modesetting are used together. (bnc#1068961) - u_randr-Do-not-crash-if-slave-screen-does-not-have-pro.patch * Fix crash when using randr when fbdev and modesetting are used together. (bnc#1068961)- Update and re-enable n_xserver-optimus-autoconfig-hack.patch. (bnc#1084411)- U_xwayland-Don-t-process-cursor-warping-without-an-xwl.patch, U_xwayland-Give-up-cleanly-on-Wayland-socket-errors.patch, U_xwayland-avoid-race-condition-on-new-keymap.patch, U_xwayland-remove-dirty-window-unconditionally-on-unre.patch: * Various crash and bug fixes in XWayland server (bgo#791383, bgo#790502).- Add u_xorg-x11-server-reproducible.patch to make build reproducible (boo#1047218)- U_0001-animcur-Use-fixed-size-screen-private.patch, U_0002-animcur-Return-the-next-interval-directly-from-the-t.patch, U_0003-animcur-Run-the-timer-from-the-device-not-the-screen.patch, U_0004-animcur-Fix-transitions-between-animated-cursors.patch * There is a bug in version 1.19 of the X.org X server that can cause an infinite recursion in the animated cursor code, which has been fixed by these patches (boo#1080312) - supersedes u_cursors-animation.patch (boo#1020061)- Added u_xfree86-add-default-modes-for-16-9-and-16-10.patch (boo#1075249) Improve user experience for users with 16:9 or 16:10 screens- Update to version 1.19.6: Another collection of fixes from master. There will likely be at east one more 1.19.x release in 2018.- Depend on pkgconfig's gl, egl and gbm instead of Mesa-devel. * Those dependencies are what xorg-x11-server really needs. Mesa-devel is too general and is a bottleneck in distribution build. (bnc#1071297)- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- u_os-inputthread-Force-unlock-when-stopping-thread.patch * Prevent dead lock if terminating while on inactive VT. (bnc#1062977)- Update to version 1.19.5: One regression fix since 1.19.4, and fixes for CVE-2017-12176 through CVE-2017-12187.- Update to version 1.19.4: A collection of stability fixes from the development branch, including two minor CVEs (CVE-2017-13721, CVE-2017-13723). - Remove upstream patches: + U_Xi-Do-not-try-to-swap-GenericEvent.patch + U_Xi-Verify-all-events-in-ProcXSendExtensionEvent.patch + U_Xi-Zero-target-buffer-in-SProcXSendExtensionEvent.patch + U_dix-Disallow-GenericEvent-in-SendEvent-request.patch - Adapt patches to work with the new release: + u_Use-better-fallbacks-to-generate-cookies-if-arc4rand.patch- u_cursors-animation.patch fix cursors animation (boo#1020061)- disable Xwayland for s390x again; it was wrong to enable it; there is no Wayland on s390x and will most likely never exist, since there is no gfx card on such systems and no gfx emulation either (bsc#1047173)- u_Use-better-fallbacks-to-generate-cookies-if-arc4rand.patch If arc4random_buf() is not available for generating cookies: * use getentropy(), if available (which was only recently added to glibc) * use getrandom() via syscall(), if available (there was no glibc wrapper for this syscall for a long time) * if all else fails, directly read from /dev/urandom as before, but employ O_CLOEXEC, do an OsAbort() in case the random data couldn't be read to avoid unsecure situations. Don't know if that's too hard a measure but it shouldn't actually occur except on maximum number of FDs reached (bsc#1025084)- U_Xi-Do-not-try-to-swap-GenericEvent.patch, U_Xi-Verify-all-events-in-ProcXSendExtensionEvent.patch, U_Xi-Zero-target-buffer-in-SProcXSendExtensionEvent.patch, U_dix-Disallow-GenericEvent-in-SendEvent-request.patch * Fix security issues in event handling. (bnc#1035283, CVE-2017-10971, CVE-2017-10972)- enable Xwayland also for s390x (bsc#1047173)- includes everything needed for additional sle issue entries: CVE-2017-2624, bnc#1025029, bnc#1025084, bnc#1025035- update build requirements- modesetting.ids: no longer hardcode Intel's Skylake, Broxton, and Kabylake IDs to modesetting driver; xf86-video-intel is no longer installed by default on these, so it will fallback to modesetting driver anyway; still you now can easily switch back to intel driver by installing xf86-video-intel package (boo#1042873)- Update to version 1.19.3: A couple more minor fixes, most notably a revert of a page-flipping change that regressed some drivers. - Remove upstreamd patches: + u_busfault_sigaction-Only-initialize-pointer-when-matched.patch- Update to version 1.19.2: A collection of stability fixes here across glamor, Xwayland, input, and Prime support. Also a security fix for CVE-2017-2624, a timing attack which can brute-force MIT-MAGIC-COOKIE authentication. - Remove upstream patches: + U_xfree86-Take-the-input-lock-for-xf86RecolorCursor.patch + U_xfree86-Take-the-input-lock-for-xf86ScreenCheckHWCursor.patch + U_xfree86-Take-the-input-lock-for-xf86TransparentCursor.patch- U_xfree86-Take-the-input-lock-for-xf86ScreenCheckHWCursor.patch * Add the missing input_lock() around the call into the driver's UseHWCursor() callback (bnc #1023845). - U_xfree86-Take-the-input-lock-for-xf86TransparentCursor.patch * The new input lock is missing for the xf86TransparentCursor() entry point (bnc #1023845).- U_xfree86-Take-the-input-lock-for-xf86RecolorCursor.patch * fixes random crashes in X in multihead mode if one of the monitors is vertically oriented (bnc #1023845)- N_driver-autoconfig.diff: No longer try to load "amdgpu" DDX by default for all GPUs with ATI vendor ID; this is now handled instead by an "OutputClass" section via kernel driver match, which has been added as config file to xf86-video-amdgpu driver package (bnc#1023385)- N_driver-autoconfig.diff: FGLRX does not support new x-server. This change fixes bad behavior(with empty config) when radeon ddx loads with amdgpu kernel module on SI and CIK cards, and x-server cannot start. Radeon ddx with radeon kernel module loads without any problem.- Update to version 1.19.1: First stable 1.19 release, including a few regression fixes.- Replace pkgconfig(libsystemd-*) with pkgconfig(libsystemd) Nowadays pkgconfig(libsystemd) replaces all libsystemd-* libs, which are obsolete.- Update to final 1.19.0- Exchange xorg-x11-fonts-core Requires for Recommends. The corefonts and cursors are not strickly required as long as one have a substitute such as Adwaita installed.- Update to version 1.18.99.901: - Remove upstream pachtes: + U_glamor-Remove-the-FBO-cache.patch + U_kdrive-fix-up-NewInputDeviceRequest-implementation.patch + U_kdrive-set-evdev-driver-for-input-devices-automatica.patch + U_ephyr-don-t-load-ephyr-input-driver-if-seat-option-i.patch + U_kdrive-don-t-let-evdev-driver-overwrite-existing-dev.patch + U_ephyr-ignore-Xorg-multiseat-command-line-options.patch + U_ephyr-enable-option-sw-cursor-by-default-in-multi-se.patch + U_kdrive-introduce-input-hot-plugging-support-for-udev.patch + U_kdrive-add-options-to-set-default-XKB-properties.patch + U_config-udev-distinguish-between-real-keyboards-and-o.patch - Disable u_os-connections-Check-for-stale-FDs.patch (not applicable anymore) - Adapt patches to work with the new release: + n_xserver-optimus-autoconfig-hack.patch (disabled for now as it causes problems) - Remove X.org stack version prefix. We are already atleast at verion 7.7. Plus we are updating individual components anyway. So the stack version is misleading.- Update to version 1.18.4: Another pile of backports from the devel branch, primarily in glamor, xwayland, and the modesetting driver. - Remove included patches: + u_x86emu-include-order.patch + U_modesetting-set-driverPrivate-to-NULL-after-closing-fd.patch - Update patches to reflect upstream changes: + U_glamor-Remove-the-FBO-cache.patch- U_glamor-Remove-the-FBO-cache.patch Fixes (bsc#983743) by not keeping >1 GB of VRAM busy.- U_modesetting-set-driverPrivate-to-NULL-after-closing-fd.patch: modesetting: Avoid crash in FreeRec() by NULLing a pointer which may still be used (boo#981268).- Replace N_Force-swcursor-for-KMS-drivers-without-hw-cursor-sup.patch by N_Disable-HW-Cursor-for-cirrus-and-mgag200-kernel-modules.patch Only disable HW cursor for cirrus and mgag200. This should fix a regression introduced by using modesetting for Intel gen9+ (boo#980124).- modesetting.ids: Add file for PCI IDs of ASICs which the modesetting rather than the native driver should be used for. This includes all Intel Gen9+ hardware (boo#978954).- removed u_exa-only-draw-valid-trapezoids.patch; no longer needed since pixman 0.32.0- removed no longer needed patch u_ad-hoc-fix-for-mmap-s-truncated-offset-parameter-on-.patch, see https://lists.x.org/archives/xorg-devel/2016-April/049493.html for upstream discussion; obsoleted by upstream patch https://cgit.freedesktop.org/xorg/xserver/commit/?id=4962c8c08842d9d3ca66d254b1ce4cacc4fb3756, which is already in xorg-server 1.18.3- Add permission verification for SUID wrapper - Disable SUID wrapper per default until reviewed- n_Install-Avoid-failure-on-wrapper-installation.patch: rename to: N_Install-Avoid-failure-on-wrapper-installation.patch - u_xorg-wrapper-Drop-supplemental-group-IDs.patch: Drop supplementary group privileges. - u_xorg-wrapper-build-Build-position-independent-code.patch: Build position independent.- n_Install-Avoid-failure-on-wrapper-installation.patch: Fix up build for wrapper. - Place SUID wrapper into a separate package: xorg-x11-server-wrapper- Set configure option --enable-suid-wrapper for TW: This way, the SUID wrapper is built which allows to run the Xserver as root even though the the DM instance runs as user. This allows to support drivers which require direct HW access.- Update to version 1.18.3: A few fixes relative to 1.18.2, including one fairly important performance fix to the Present extension. - Remove U_present-Only-requeue-for-next-MSC-after-flip-failure.patch The patch is included in this release.- Add patch U_present-Only-requeue-for-next-MSC-after-flip-failure.patch Fix a hang while using the present extension Bugzilla: https://bugs.freedesktop.org/show_bug.cgi?id=94515 https://bugs.freedesktop.org/show_bug.cgi?id=94596- Add automake, autoconf, libtool, c_compiler, pkgconfig(xorg-macros), pkgconfig(libudev), pkgconfig(libevdev), pkgconfig(mtdev) to Requires: of the SDK. This simplifies the build of Xserver modules.- Add support for a driver specific PCI IDs files supplementing what's in xf86VideoPtrToDriverList(). PCI ID lists may be held in /etc/X11/xorg_pci_ids (boo#972126).- Update version to 1.18.2: A big pile of updates in this one. Highlights include: * glamor is updated to use OpenGL core profiles if available, which should improve memory usage and performance on modern hardware, and got some other performance improvements for rpi and other GLES platforms * DRI2, DRI3, and Present all received correctness fixes for hangs, crashes, and other weirdness * Xwayland server has been updated to support the Xv and the xf86vidmode extensions for better compatibility, and fixed some bugs with output hotplug and pointer updates * Xwin saw improvements to window and clipboard management, and a few new keyboard layouts - Remove upstreamed patches: + U_kdrive-evdev-update-keyboard-LEDs-22302.patch- Backport upstream patches for Xephyr input hot-plugging / single-GPU multi-seat support: * U_kdrive-fix-up-NewInputDeviceRequest-implementation.patch * U_kdrive-set-evdev-driver-for-input-devices-automatica.patch * U_ephyr-don-t-load-ephyr-input-driver-if-seat-option-i.patch * U_kdrive-don-t-let-evdev-driver-overwrite-existing-dev.patch * U_ephyr-ignore-Xorg-multiseat-command-line-options.patch * U_ephyr-enable-option-sw-cursor-by-default-in-multi-se.patch * U_kdrive-introduce-input-hot-plugging-support-for-udev.patch * U_kdrive-add-options-to-set-default-XKB-properties.patch * U_kdrive-evdev-update-keyboard-LEDs-22302.patch * U_config-udev-distinguish-between-real-keyboards-and-o.patch- u_os-connections-Check-for-stale-FDs.patch Ignore file descriptor if socket or devices dies. This prevents the Xserver to loop at 100% when dbus dies (boo#954433).- Add 50-extensions.conf Disable the DGA extension by default (boo#947695).- Replaced u_confine_to_shape.diff by u_01-Improved-ConfineToShape.patch and u_02-DIX-ConfineTo-Don-t-bother-about-the-bounding-box-when-grabbing-a-shaped-window.patch.- u_pci-primary-Fix-up-primary-PCI-device-detection-for-the-platfrom-bus.patch Fix up primary device detection for the platform bus to fix the Xserver on older iMacs (boo#835975).- Update to version 1.18.1: First release in the 1.18 stable branch. Major themes are bugfixes in glamor, the modesetting driver, and the Present extension. Xwayland users may want to apply the following pair of patches in addition to this release: https://patchwork.freedesktop.org/patch/72945/raw/ https://patchwork.freedesktop.org/patch/72951/raw/ which combined fix an input issue when hotplugging monitors. Both are likely to be included in a future release unless testing discovers further problems. - Remove upstreamed patches: + ux_xserver_xvfb-randr.patch + U_systemd-logind-do-not-rely-on-directed-signals.patch + U_kdrive-UnregisterFd-Fix-off-by-one.patch + U_modesetting-should-not-reference-gbm-when-it-s-not-d.patch- u_Panning-Set-panning-state-in-xf86RandR12ScreenSetSize.patch Fix panning when configured in xorg.conf* (boo#771521).- Handle source-file-list in build not prep - N_xorg-x11-server-rpmmacros.patch: Delete: Process xorg-x11-server.macros in install- U_modesetting-should-not-reference-gbm-when-it-s-not-d.patch: fix build when gbm is not defined.- u_busfault_sigaction-Only-initialize-pointer-when-matched.patch Only initialize pointer when matched (boo#961439). - u_kdrive-UnregisterFd-Fix-off-by-one.patch -> U_kdrive-UnregisterFd-Fix-off-by-one.patch- Add test for defined macro %build_xwayland This can be used to enable the build of Xwayland and the package xorg-x11-server-wayland using a macro in projconf (boo#960487).- Split out Xwayland: * Build a package xorg-x11-server-wayland * Limit build to Factory (boo#960487).- Enable XWayland on Leap also (boo#960487)- u_kdrive-UnregisterFd-Fix-off-by-one.patch * Copy open file table correctly by avoiding an off-by-one error (boo#867483).- Update to version 1.18.0 - refreshed N_zap_warning_xserver.diff, N_Force-swcursor-for-KMS-drivers-without-hw-cursor-sup.patch - supersedes u_fbdevhw.diff, U_linux-Add-linux_parse_vt_settings-and-linux_get_keep.patch, U_linux-Add-a-may_fail-paramter-to-linux_parse_vt_sett.patch, U_systemd-logind-Only-use-systemd-logind-integration-t.patch- Update to version 1.17.4: Minor brown-bag release. The important fix here is Martin's clientsWritable change which fixes a crash when built against xproto 7.0.28. - supersedes u_0001-os-make-sure-the-clientsWritable-fd_set-is-initializ.patch- Update to version 1.17.3: Various bugfixes across the board.  The most visible changes include fixing GLX extension setup under Xwayland and other non-Xorg servers (enabling core contexts in more scenarios), and various stability fixes to glamor and the Present extension. - supersededs the following patches: * u_randr_allow_rrselectinput_for_providerchange_and_resourcechange_events.patch * u_CloseConsole-Don-t-report-FatalError-when-shutting-down.patch - removed evdev xorg.conf.d snippet since it's meanwhile shipped with evdev driver itself (since version 2.10.0)- u_vesa-Add-VBEDPMSGetCapabilities-VBEDPMSGet.patch Add VBEDPMSGetCapabilities() and VBEDPMSGet() functions (bsc#947356, boo#947493).- Backport a few upstream fixes for systemd/VT handling (boo#939838): U_linux-Add-linux_parse_vt_settings-and-linux_get_keep.patch U_linux-Add-a-may_fail-paramter-to-linux_parse_vt_sett.patch U_systemd-logind-Only-use-systemd-logind-integration-t.patch U_systemd-logind-do-not-rely-on-directed-signals.patch- Improve conditional enablement of XWayland.- Add patch u_0001-os-make-sure-the-clientsWritable-fd_set-is-initializ.patch Prevent segmentation faults with more than 256 clients (introduced by xproto 7.0.28 increasing the max client count 256 -> 512) Fdo Bug: https://bugs.freedesktop.org/show_bug.cgi?id=91316- Update to version 1.17.2: Pick up a pile of fixes from master. Notable highlights: + Fix for CVE-2015-3164 in Xwayland + Fix int10 setup for vesa + Fix regression in server-interpreted auth + Fix fb setup on big-endian CPUs + Build fix for for gcc5 - Dropped patches: + Patch110: u_connection-avoid-crash-when-CloseWellKnownConnections-gets-called-twice.patch + Patch113: u_symbols-Fix-sdksyms.sh-to-cope-with-gcc5.patch + Patch116: U_os-XDMCP-options-like-query-etc-should-imply-listen.patch + Patch118: U_int10-Fix-error-check-for-pci_device_map_legacy.patch + Patch119: U_xwayland-enable-access-control-on-open-socket.patch + Patch120: U_os-support-new-implicit-local-user-access-mode.patch + Patch121: U_xwayland-default-to-local-user-if-no-xauth-file-given.patch + Patch2000: U_systemd-logind-filter-out-non-signal-messages-from.patch + Patch2001: U_systemd-logind-dont-second-guess-D-Bus-default-tim.patch - Changed patches to work with the new version: + Patch114: u_ad-hoc-fix-for-mmap-s-truncated-offset-parameter-on-.patch- U_os-support-new-implicit-local-user-access-mode.patch, U_xwayland-default-to-local-user-if-no-xauth-file-given.patch, U_xwayland-enable-access-control-on-open-socket.patch * Prevent unauthorized local access. (bnc#934102, CVE-2015-3164)- Fix GNOME X Session for some hybrid graphics (rh#1209347): + add U_systemd-logind-filter-out-non-signal-messages-from.patch + add U_systemd-logind-dont-second-guess-D-Bus-default-tim.patch- Fix build of s390/s390x (bnc#933503)- U_int10-Fix-error-check-for-pci_device_map_legacy.patch * int10: Fix error check for pci_device_map_legacy pci_device_map_legacy returns 0 on success (bsc#932319).- Add xorg-x11-server-byte-order.patch to correctly set X_BYTE_ORDER when compiling tigervnc on ppc64 architecture. Related to bnc#926201- U_os-XDMCP-options-like-query-etc-should-imply-listen.patch * Enable listening on tcp when using -query. (bnc#924914)- Enable systemd-logind integration support: + Add pkgconfig(libsystemd-logind) and pkgconfig(dbus-1) BuildRequires. + Pass --enable-systemd-logind to configure.- u_ad-hoc-fix-for-mmap-s-truncated-offset-parameter-on-.patch * ad hoc fix for mmap's truncated offset parameter on 32bit (bnc#917385) - N_Force-swcursor-for-KMS-drivers-without-hw-cursor-sup.patch * hwcursor still considered broken in cirrus KMS ((bnc#864141, bnc#866152)- Update to version 1.17.1: Fixes for CVE 2015-0255. + xkb: Don't swap XkbSetGeometry data in the input buffer + xkb: Check strings length against request size- u_symbols-Fix-sdksyms.sh-to-cope-with-gcc5.patch Fix sdksyms.sh to work with gcc5 (bnc#916580).- Update to version 1.17.0: + Continued work to strip out stale code and clean up the server. Thousands of lines of unnecessary code have disappeared yet again. + The modesetting driver has been merged into the server code base, simplifying ongoing maintenance by coupling it to the X server ABI/API release schedule. This now includes DRI2 support (so that GLX works correctly) along with Glamor support (which handles DRI3). + Lots of Glamor improvements, including a rewrite of the core protocol rendering functions. - Remove upstream patches: + Patch130: U_BellProc-Send-bell-event-on-core-protocol-bell-when-requested.patch + Patch131: U_fb-Fix-invalid-bpp-for-24bit-depth-window.patch + Patch200: U_kdrive_extend_screen_option_syntax.patch + Patch201: U_ephyr_enable_screen_window_placement.patch + Patch202: U_ephyr_add_output_option_support.patch- Add xorg-x11-server-source package that contains patched xserver sources used to build xorg-x11-Xvnc.- Update to version 1.16.2 - Fix present_pixmap when using present_notify_msc - Fix present_notify to return right away when querying current or past msc.Xext/shm: Detach SHM segment after Pixmap is released - xkb: ignore floating slave devices when updating from master (#81885) - fb: Fix invalid bpp for 24bit depth window - supersedes U_fb-Fix-invalid-bpp-for-24bit-depth-window.patch- fix bashism in post script- XServer looks for dri.pc during configure. dri.pc is currently provided by a Mesa devel package, which is pulled in by other requirements, but it might be better to explicitly require dri.pc.s390zp32 16704093511.20.3-150200.22.5.63.11.20.3-150200.22.5.63.1Xwayland/usr/bin/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:27009/SUSE_SLE-15-SP2_Update/27ed255d6c0f42c01e40581e46dbb05d-xorg-x11-server.SUSE_SLE-15-SP2_Updatedrpmxz5s390x-suse-linuxELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, interpreter /lib/ld64.so.1, BuildID[sha1]=c4b291d90940b44b3337da132e76cf643ac928e1, for GNU/Linux 3.2.0, stripped!RRRRRRRRRRR R R R R RRRRRRRRRRR RRRRRRR=L L^G (xorg-x11-fonts-coreutf-82f34de083a663dad5ba8dc861375053968cf90cdfca23153d5f4d7c088e16ef3?7zXZ !t/ె<]"k%#4ղۼK'l;tP ^S,mM4Ҧ0nWaojJEs~oP;;LId ]**fz}Gݘ^yM&(W`2Xp#B'tH}Qlh0)$eHbx//jfGca'^xk~U.i3/iZ"@|3L(Hb",G-2ݫ*`J(D&w[ &3<)s =~֘AGz5XN{tl8aA\{X rGhѵBqcn49|*{RS bWT*a/lڢחZQ{cܠY]l z #*(;m$|Ѣ&Mۇe0 b]n=|5)s9<@Z%li8Jtx'7EҥUR6B6pi d2:~#+% 0~gq盁mB/ےtQbORNx^;2SLhbd+䑧V/\\ɏx=izWW~uilOMp5o2CPqK>al , >۟¨=?XdžKd8B^?iCLS oTUv/D&3Lņ&a(7gD@4"oǙ끽`_*za:aWY3 ESi_1 0 ?pfB$7'gge+>`WА՞k]NC=MWͳhxzPC9[,f ׎Qp-AihK^J-ĝW*\?؏!)ͣL|=wics7(*qiA̴Sw O U]. nmXgh Z:IxRZ-a`6z}.l QЃ7JB7rHA;@v׈VHCDžY^DX4p8x!IUZ;, m~xηt~f6ڱR-_%T^X+2HBioo$p$;G﫜=B?1&7Jz[ҏIrU_w}WvbmJpVK۳p$d$Kܦޱ4+NY.T z~\Bz:8PϋB7/gsN:}蠇>='Q>d W#[LJ|Hol4,-j) Mh&js؏YrDoű\@0:H~;Zk6wqkrX>X"A8:~`tf$b} n3G}Dxc㸁Zan1ԡWXY>8utRd4.!`vi b-gxHlPgʀ7nyzTu-n=wooy!v?x(;]Ee'YNE&5$!#Q^3 $ĒVЈ "{@m^,q 7)h ҾY#dzR~3m8i8OCz,81xhxUj;B!m6:*n eؙ# 'aQHG@A35IVˤʉ33G+O9sM7 vMx(.m; . ~iTv[HlI󵺥482loԐw87˯h\'gẂ|;2$1o!]tEZAO9T&n. ț'rGW=@jdESR; KY}_NwAܾOA% F mY|u$ @#{=>̙z\.VU=M{RR {[42 ȍ#c;fu_ϔįX;&Y[KշerYCL=?G|mWM.LxM#^χov|e }v!Z~VAFo P qG2|r{f :4!ɃDí= XgWe6gâ#ߙ>PքQŅAՌ5*:3<7/r>߯^KK0n3H꒾j]𱤠VQ ܌:.\іky/{ D"rel=o"M  PYtB oE $$$G䭉 (fHdsdUL:b7;xyܒ]~,{ y]:̯A^/ؚ(j|eJc5[lr=X͌\:ݠb-N3YK;DnmO]"B`Wހ,_ Z S!V;(RI~MI8;,YqCY|X̂_C a3;]JoCXNZW$|Jj~8N p}oT }L1fm]p% >yijkavs<!"٫Ǧ֠FsxXhc/oBv oŒ(v<K 105xH|aآIl퀄Ġ,q[fR C0,me@AާO0k3ƃ՜ zO1fcB5'J R(ۻ xd\we)i_pEM<&ޤfSB;zkmQ^CmKÓL欢F<#"\ inX#E/nh4¤q %׏Qa>*¬Gp8ZЪFNaEVY d>1gvtҁ0hL{Q立+ i J  DRt|1ۤJ%_ YC펃c&tEk񲫭4ND>㮾gy5tC ~vN}qSYɬW!n' f|DdR~| ^#h>fvK% W0yw/W %J"sS;-d^ ӛ,Ss(Aϡ Dt $̄pg#j0$5w੝X@ Mʺ.H\ O5*0]YDGqs=xF 5)\Kbg$H\G!#LVb)lZBĦ@EN'⸦,wWtSSg%M6͋)u7r%5$L_,tO#[m9T \ $ iZisn0#δ*: L z]$'FU{ aЂ=' !e/W2Lzon$f`I'c ZhL~K'v2]f*FX%Q)aoQs1_,9H.Pef)`$~myX+* 7ĸl G㵙!`<:FOi,5gU#s|>Sr؈&WtK OЏz57lYʸ [/ꡙ,lF'lɶVJo 8`qDJ\W@rK~V 0MvOI+(f`!|ptog8uI0‡-JMl$ha@M;Hr@hМtDlۼ_k>ѱLS' ~|Fa'}PY]+B2C5(dQ%2KLI_H#2!`Juǃϟ.xk\qzbf6 B]W׃>1@08%6sh I@S&Ey%xgip- gd4R7jL-%7S`]3G불>PRl0(S'KW5)amQ lQTWy0fiƅՙ ]F/sD˰>DJeO#Il$-W?5uakN_h@'3ges PpVۓ,,QM"VKq}M>iG=Xu Bv&!!lYy3и0c!#k g0{Fji^B-]C ZFl}DzbD ^$],< I7r5〫^Lmi!-=rvJ3iRRg#UyX,xyɹb0rԺ [z*De囚ȁ}rwQBw.PjsmԼhp~r\=I} ;^%1I}fg*,UsHm]Xl(\1 V~AВSUXQyqmp59 FjHWy. ؉GUzs:4Y9:0=ol,`M ;K_{NWw *kRZܲu5CAn GR>kzۉVV~4=a[ d_ޫ$<# S%d*+ͅ$?!87\ .Q&G%go%a#`[>4źU#R| (ql6,VG y4 k+yrwE#04/< ]Fm!'3D!]# P?ʱ[h<>1i,i̲|W&GXWnkdvT@!t;:Ym+x\ظ;9%k*G[(/!)u*M\鸋vx־E.Weh-p'}V1}O6!!&K1IVron 3spƫ!j!{ejm)͹@yX["p:OIt`$?X³D%ןk`D8Tf v*Ӌ,җ&~JXa fw)IImLdt5n`Kb(>WyYj1<90:cI;~v\8:<ƶhXG7_T7rIV[wXpmA`ugbE7Pfۢ~MjTNIxk3 AK\ܤ__f,ٔeFWo!-RFQU$)0$W\Oi)+V3Rͩ)n15[nw{1w7I\[ucNDq>lڿfZd4K:G$⩆[7bQ*Uh_{fXG=e盱DxVlS1jJuN"V|!iݧ@tc_:b4 p f`pvm(m^bE{UFM% Nc42}IXZ Y&uPι(IN.0&VKҦ)]c^r8wEuv).N*ūm9Ne\)SbL9%[`z l3R q>~SL:I~lAZKi2tA70 Tm_?AHeZWࢾz2+HF&n7ڞ2sT.׉uy K?9pQUa k߼A}Y0YY{׾}C ì7Y} t)T<߻Ԃj7B٬6O$Ez4JlKWw&8 ly/VRsćgЭ8 .b;;H07_A\@J#nxRKZ$*4.(E# cӸ:ԌG]A;}Glx: K)kX+2iw͜5ԣY4Psh{gߥaH *I#q\>1e*B/oNGpI`Q{PZikfm89OGNT€`ҏZ\o,OR| ,t` Ku 6@VrKN; ?`=3ToYll| 9ZiOhΦǣ$G=> s`Բ6̈ M[A¿6.n-jofK_sDHptixu{H=ʳPuO3'M]Гixt}Ƒ A[Ѯ" 6d:苕'u"LVQ]lJ4 ۑK;4Ck^ i6>0bNXRǣdɓ-Ĺ 0UbR䢽Ah)~X:.l(D{{+5lW( u>,TFS%#zVXM<)hvI/aLGe?8&}"C*lkOƈ]J^-W)HO8)K-ϼg/O S^w^$O<+wϗmh"_lsPL=ǔs=ALd+*ndg2j5j6 B;?bGσ"Z2G7Bo14Oc`sR6Ҫ#/K;Bg|NKr~Ut3*-ߔ4(^qJKН Zi1F8=C!]$,TB0 nwm6>np/ML뫥=]~|䣲W<u#j20fsP϶D^֝aQP<_Μ!e [;d7_^?.DE&l՗kV|Qb2p|rl{wYvTi~ Fn%Lh%w!_yEu\9b;t> afuz/6c'%hYm;&ᯨг[H;(.Oiگ8h\,0:KN JlЫ6iC2R:sN f"f 0›)f}KrgMibTt8.E-ST =5&}|Or;36C?@&\ڔ'iy-{8p0]'+Ԣ'.gLb0{ҏĖ3n_#Y.$@}l̦!` {6]\NKrO|KD^|u xkϻ\UY2H v؁#/b9pjSH\%\TKI6jd)B/<[o~6YAyR*#nAE-ZU!Nd-wQ pcEߴۘ9Hv%kH~ ׺|> Wx*H#k$_t_8)Ew+B@`<#SA/

al7xbFh4ӊqJ܂F|BEnҢ|l9S-8o#ӁolIqJ{sHYK+hV~t`s'H[mYdqU"7=`ɖϟ(%F$z뮁XOבߘ^O&xڪQՍ֓qWv€sDTw<u.r&#T#AÂzp2| WnU,_mwF܃[6rrP3Cа@V D<,vvgcH.S㉝$4gB_4weU&gXN l{t+{-tP@pM ș@>(ieu@hDΠ$. !\[%{'jDQ6-=ڳUh>Tt~;_rNZZ2rVI@xd;f ox zMZH%>[Ytа(|ƙ2$PD'?4ӍN-mSE=o}zpu WD4zC|:7;m5 ^plJҍ‡ԯ·Z5:@.9XNȵUS^ҿP89eNlz%ї1zs; x"9^dNPB\LyB 9t>bŝ !\N4Ǫz]NSS\ډFŪ&XWTy$n}_͑b -O( -R4v%,|^"'KEqKY`W4#/ޡ{VY9EPVićjX1E:Ӕ otٞ*ʪ('7A crhrB!lr`h:t痕3<bzp?"H ⋤~y Uer3u{dBZݷd (LiOK^iPǻ8&ٱI[ҩ=$1.IV?|T~lmҧӡXS`O>Pe"7't!jw-h ;U٢Qh<<J#-+dj*ӭ>р$T#i2 u9A$"YUbAH@Q)FxI/zT2&߼x=N+T(SCGvh86 =?G#Jg@,BXhmPz_MR)"'XAǵ?,3yԐ"Gs# j_W^~8ر/fHL/þ !%SS7dl&P%|/fG\KOx: fW%"_p٠ eT{(rܨYa3D{TN%g \F~1nWrGz#-:yN!4SD,jۀ[HPm>XVFYwDRUZw9( r @kNQoWWhL#-H+B"[>CE V_g^EOD΂ϖF߽.߇Cdp#G1?4N|#qٺf_3-gRzsFz\+$ an/3!q a~=;ٙ(\wnC rk9^ce ^#ͺ`. "^qz bHvvʰ2 AbNdp0"Hɻ }sv\ƌ#3AN4P^j beRzh[zKU\53w^7V ݪGeMb@ ֪SBX^nXՔؑk² ܚmO~pyWIś+&hazG̊-O{ȓB]dy~7ݓta+kA9b5QFWӣՕ.I#Zfouӷ {4CpĆ{([O`. װ|2[O|mKuۿ۔=: R|:B] i{@7#juÆd޳[-5[NšERs"EBCg&kc}i&O_E'ay| zuJ]AF{^>^\x"o`9TgtRYn~ Gs!0AUM0raPy=OQ7|:q{]|/`v z h7J%_2\`Ȝз]Ky @(RW勗uC73G?ZkD页 @YȃWgm k{b+AMbNa[8C 9ZIn hIҩ 9wUg@wa739V&_k>׉^v^2xM4{ z.`_td +Cؑz[S^XstQMӏ/9P-{.V {͎ƺ;Л5Z5J 5Fy)aJj]κ~"Xr촵*KyXmجtcwK!|!3x9n_41kjy ]E_WC΁~@;gw>1ht P[{ͽ@ C;ߡ#A/ .? Q,4]A"Yזmhi\UI*Y$)Scu[$9 $mH E|YC8vt$ Fxt &hDrs,_FF)GXiqs]I;H_q 9_NS+Q*7umBr*O{="bumF{`k|r !+ \U}υ3;r=}F) /d׎鍅N<4w3_*׌@\onLN")D^hF9Ф5jf'xaH'oIDCX`rg(Ps:#,<_qjmzF8Dq00xp'vGԷo 8N :)mLd/݄&87a>VW"+o4v!4sїXL* =ZTK״IپOƔh!|i{lei؄?g3@fߠmCMn0X~.٪#{"[zfe=I"f c>Q\^q*C2%0JIo2V ^>q^صy߅JA@">lsS0̲ w#WÞE% I\ 17=JG!,l#yCk3 Nu*lAZ"36OUeKU&CKW3X{vfV`I'6TeP< 3_ >85"Eȃ8cV2ݻ~KGչ7<'LG ft]Du9)u 3u)!@*46 C370qDv"MgX0v lQ\YNhWkSKc/.Z,#9}w2o8xMm"'HzG]"?y)K7/ݴZcA9&߲թ?1ۄp՗UP`G'c\l3 ĚQ;Eddߘmgla FԞ9`F6J7CVnͰDڋFdN /8>:^vXtHp5a˫eBn]m乶d-1 D6fo}GzɘkD5}i0/2T7>.qH ŷGP,.-4ՎDB8y FYCM XtwƥoE73^IIC~HǏ:<fh=kT^?,YzVB] _g]=3cU@m甌B:C׽L7 [[ѵ1DPoU.GRs[rӌ4l5yAЊ o` L1ZcHvfֿc=Իb_:(>o梾PY{Px&hGK{e4ȥ-5y{V~ͅfޗڂd-(ERpɿ8 }U|L+8X F6 D>n Xwr}Τ8eRRhgIiFmyߺSR"FQ{O_9_h`f$2Ո_JjV}/Gɚ%.:e#aoOҬL.Eea`Uw 3^5ha%@m:t4$dWq$ 2t }G [V 8S=O?wQhܫCC7flXcWLm a'-i0j>CQ|>CvdD7E hxJ m-&"t!bT'/!` A8TSN w'_J<V2ied Ԭjgùr e:uxkhʪ]B"߲U.ַ]qeP=Ba:7R?"D 83B|{ ۶Ģ5zE_mhW׻ߣ4g H'Rm)yyscnL<eI[m$n`/jrcս %1,Zq`Lt8.ǩ'r>| WC^cF&wT5S"Oc}yXz"8_Α?c]-!ܿ$ @/X5F!GKhd0 Ox鴿635s(e"E[XIVV̱B`&ftF"Ǿ`Z8smz{I/RźkccLl S)4lRWRdv'( S~.MZs,ڛvdD{w2Ġց E䋔E1ˢq^٭Dw|\ʟ88<.©$[ۖ4jq%C8Tn~ r >?_\:Aڊ(e) PK?p06qIzKWEP{JX L/$wR4IׂSC*yȒJ9^*cg>Z:kVLND9>m۷H]Tnxx dzja3k%8NUoȃh.ySTw])Zf4«L.j ލIC?ʨ3z K ԑ+j%IJg9Ԁ[r5jD6"IdOn%܂\H rT%c}Wm. t1jBE={uc'iuBx09+]C(ԢW>Ic .7}Y19YįY;V/%{TU\EDdiI!rI49'EQk8&*\}2@ B+{-_$УqҠ@1 [#%O;\an<iB}|ސ]q6FEi"38cXUA ș*Wu##7.mc=7_NUVwR[sPff{ZG񱅢K*.e$ыUɳI.tR-4;=eTyM"U{xx ѵ$2k,1O~h[#e ǖ5t}qp>L*,q <j_Sn̻e3;Z f3-lG_"I OX3#W鯭ɥ ~:OO~@8Mrk%[ iVrb@J$(C=} gK8k[e!2$FPf X'7O ࡰ4a^ZfY A_zLE"cpog>V {>?.kxHrZzw=]'?܀F=.':?'޼)]:WR*|hJUu[F?h2 ܢCڢTzkTZCڧŨ֪hsLߓL{t!-f(u|T1Z4Ԩ{e_׍@6t/vKb A@nּbQ~Mj%CĿ{HcΉY [Ԏ1~:XCSw$4uCK|E\~TfM`RW3Sb<@ۜ܆of@+K #òC`}WIiKN%_(;FZy\6h--J&<3<8~;RBON2 O"3i"f i 5{0<Mg;6 r[Ԑ/YP\ /M:\Jt+R^-TYR y..7LYYFme8o%IJ̦ 9'n1\5u(!XJ |~Ԙ /mѢ-hv5A{_ĕ_aGT8s F %Z **Yb]}vbC}˙1Kȧy6#6j $>&֩駖:T:#]X0 3C|mSɁٴQ@C&9 2Y9#D춠D|0 NO־s>6?dXƽ=EY&,ZO=,iZ@1+|j ƕ?Ùh{j$nLvA;.z=u(SZ`ڧ"<ӊmuH5G3%04=bYݓ7RՙdGdRIRkCޝ0G =-+LLy8ၦ|%oߙv(5%?S啛fne7VVk_nTr JF0}v N B|))Y.ϮAJmM ۣƋ/0Snʳ ,|:HiA)8kJ/w-ޜg8AiLLcTg bHWQg  %ñ+HɅܦOy"c]Zf1Dzǰf9Ui5FIY-gK"_`Ywmc01ks S#oZ?[Vx3RW/W`In+Ob+%s"ZY7˸H_tBeC!Ltذ[dk1) @@`_Q"!hS A+ZI6tB 9 'jذt١t5% 4`)"2i2RxlA;n"L\ j }N˞nu;embs' L""}U1JAF3!msxc,P|t/1HC]clrD5:: z""O!w2!.(닿KnrO*|&P&`WЬ+Y3NׁyҜ_0Ч̼FyJѩpFj{pZe}]ry;19Ri[dx%3xNNi f~?XEOZJn:jC/-0+(ʱH@0dA2%EDKS}rm1l|m.*5cKPݕD*-M#K_4bUw=X(<{W.ZND1MI|o.@Po(=g'JC &wMF,@k迗1 bI8L& GsV0Rܰ jY XJg[$[/ZՖe QR[.Y_ӃB#8GغvL+KsFu@rH̽l2_~>nT?/nWt*o4v㊡cEwɇ! F`:$uxu7EĴC0%T K2:8}a 0@#i;AlSNkԎ< 8j5IB_q;R2h-Ļz0d7&̲A5UB& L#m]g P 2~G)@޽_7)Fs0ڧA{v\Ɉ^GF#SoM1몘@#<ŶYwR'7s`G\w  *g  #oԂ^0֩1_rǔFW2 3p?Ofk I8.$y"=>S:u&paZJP'%W9rԦ`ϮЊW|ߦUꌄoP ͈S &Qa/SE !ug~!F2 ^%e'jX] |qy[ A`}EHib֩R;sSzəyb`ݹ 4Ԫ+,RE5/?Yd;>5 %h . S$ BnF޷/29b)eK DVZWghv?{fb' ;`T̜T^uÓ/ICL;1NX|V6Ĩ铹ftʁO?lx"u nd,"z!2nnV?C~_rf\vA$&8q,ܷۣN5𱹵GmlbT6'u)#p? +L _y21N~/jiht#nE8E"U ~GY>yEcNn T8uFbkiW`7h X(U<7!9XQtOXP\?_lR§%~e&/wTmϠ@9_8=I%S23_y iCv{qpc3;q!jO#>yv{^`K>Ozei &>A _VMSfB(Z(ƀ]Lx6i D$I,s:e7 hYvoAxP$N&Ƙ~eLqj>bJB{ԜP T̺&Ш Fm /J'KzD՗#@\؅{`VEkajBo4.~':AU! [[S$XaFu U@)3Aq[zpST%h!/WIOu-֌]1a\a%zj,"xښǬ_J} ~rfa_f8ٲ0o=aN(0|k[`%}LJCJ'[va":a;"2!͍ݮ*7^N!UQ oXr |!c_Nm YNΩ\_"1YX-S ղxM;u"w}fkD?`D8= ':HaMzqΤ b+v};ZꄯctҢq!bEKoAPĂ4y =w$4tG^cŮIdЏPh/פBy8ɼB8 _Oo}ͧĻP2 к9u$Bg5&d}hjh5WKP`w8({oNQ^$8JCb;^[bS_J[-!q_Rq< -bc K*F*PU r=v.2uQ#.}R \q x͹ˈ)ÔgB&^>a1 9T)KS،uzjd}P*IYV˟|Q_:gS֑&B,KH )sQ Fx TMrN^P2>YP(Io@[<`G#&)VH= eDӂ'\&Pձ7 qHO~\gȵW]}^-ާ ="+;"2 J[ɏ`MРOݦRZ\iv6*yΫGu9%5cӠa*-IzR(p pSU u*Ơ`/Һ~վk,*V 2n;Z@6|>- -t ~ ]k*$cRa O%ƌ<6C>ɴ9OY{ n+**~]x0lU-D)<%&hم0NW^j 29dqrUK&Cy AOոO3ߝC ǪXX+5QOJdgÖآzNjL]v9]DئhMa),Jٻ4mFK pmik#~&W*XԬ xOL 9(VV˩>P^/U)QJ̞b$+.pTAg!9 q n&ONyE}.+1P'\FZH)vìCT P~y Ӧ`] $<[^~!1J IEz $adt̵|TĆ0`.wr+%Eө1?(e(>WydP/7RK&K=XoLcy&YMVKЖcLB7]e_jw9ZONUz0 i T7Q,\W^/zx%X[%r 9]6IUY&#"Xܾ2=j֥[8ͦvm8?lb#;t2i5hR ;U1\Ewps-ϨIVZQĹ숶RЏ|bpDw9C0,3)&Oua|Z8h}seX3K7_ vK`y0 3VwWEv3IJ7Ӎ$`E*uB2UI^@ yl i&^U_•cb5=$0yMtҊ -Rtv4t"*M:c (+2~Ffn!sLFc|(lq4,i8rMsIOvN{Cmb̘jラ nWeRL9#xQ$1͝5d:n ߒBlFG ; ԦwGc89=Ì5\§zCwYBhէ'I#H*ljOJ扝_6u3 sb SBC&,]̓P<F>paQ}z/Iu?jz#|"2«+%~ø0&L\f`f+ݕ Z,T OۤSdfKQ./1CיC QńC$|c/l|,Uy,cr@ ?wG3 6" %`?XHmAd;_` x=)|O.d`^n̳[ر@`U'B@LW0lq.Oﰯ]WoȊ>7%Yx nZ7 юzD ͙ : 1\JZ2R4 #|΂iLQC}pWt7,44WU>wO9aMeO <^/Yg%<3#1,i#2[i#$tnӆ5"-.m#Xʌ>{tA񟿆J &a;ejh!Hࠢ`%6?ڦKidBu|T-E\YWQŴ#Knsb%W;D`ZyMg{K5(%J))*+WL%γ GENЏZ~ I㒙ύa$O;WRLu䒀H)Sv5tN Sbf1?Hm!t %?|\ϜWɓ<\ 1c8Kj@""T[-襆h -XבΫ?\HƬT])|qPFUfJN(I`}hF KKdB'GQBBsh6Wl]bI1%E%2mOo9 w;b:xit]u%WC8iܒt]Ri%iR+l jNSɴ$諣ZNV7tJ!m#Ϭ\0u4yѭqA.*8,߬IpWS2>ϾgS·|  X;YF4w_wҲF*A1?Ȩ"k^( 6ζY*,1xX>a`=V\{펼igDU1Q*qzKӞ#;%DJ80՜i6ЌnO3ٯKc'p!>lsP\P1Pi6/]湈)׌L/ƴBF]>v1!'efaJ._qRDT=eB$ RեyG!6\jB:/b, uɝty;Ue'<}J+Y_ԩ Icw.6{A_r71ar\-ItqzKC!- h"Y >Mt?T=cRcz[ǔ[H^]6Ҵ9E洓l<0(SZs9mR8ð>4|lpZ|&@&_#OC*-_L Jq_[l)CfՇ^ݖ\"^e7C0Y2]DWt˜]72(N:Gi~1%0?UİEFwwiͿ}əS+Qek>i9qnP-)yc K^a7p"[)y\xJ1!2ȜHb:m0AɼR!Ig66kZ#T%#%ʑCw.e(#FjrY(AyPUO|0XS1S}= &HWu_&(Çg@ڟx qybn|XQoOli Winr-҉LS8f5n䪍'j,C2ypM+(2P eI?A^vq&ogF2&G_]ɺ16 c9k[cF1Շ5(U 8$~CNQl&͸ s(tt(l$ZtpT,y9?Ŋ9Qr|$wG:B} c+% <  ~>A-V !K,-dW4LezML @'~50t\3rAaTbw jwB,B@JDKܶU v:u#,~{D4}"9 .ܫ<.jX -B C`}ܳВ=(ŦQ!q |-;bw1͂P(,DP2%6xnzd3nBig96J$hva>+mK=n`{jMB(,]g ڌ/qsjZ+ |( :F(F $IT5O?bxSC&9.B0X K.ל>R;<aBQ.⁋|.ߞt0N7wn&,aڸ9sͭqE\bt .{5E["VDzM6lEV!7[ = JC}tʘz$]?.7 r\(ulQ`ݰ6hV?Y2;~޶R`^;{wLή@5-G\*-[\5<˝X;^IBw|Bv(N/aOҲ6r| ~Q nyVU>5{k_^`.5r%t%`{&csDN¬k,ZD_!'I=Jv ͝]o%5\"߆ܫ@5<2(Q3$8Ԯ)!<`Fzf4E< lhmtXeژ :_%MlnbC6- 4:)Z ʒ07 =8qf ]D eA'ziFSޠ=낹>W[-vj,$[JtZ2"T=4L\tlНZ3SbablZ~#9"4,9||Hv'l;LqBzV 9 phZ-!ajKa{9o0g#I3CJI{WT͕8 Jt|Pľ5K~)SJ06dJ 2ܟed ( 1焰At0N% LQxэ"{ZTd[tǙQ+m> ~uKHx˪ua HPnx@x®7%PC6G' KAlˑV% ԰>ƾu$f>WTe u*7<4fzxޘ. N_VG:P$UU,<џ\ "-] < ]j?EMQ nc\)B&U5fLwhE+MH![&1Gid/3ل5 ՟DVl]K6 90΃I@2:jg?Z)_wsȀ,\EVOaPvMRhN{ư4Dk"}BTݕGi Mކ[aZ~'g.̰Sȏ*=P"֋RETc͏D ^hN-ꩤ07y$ z~zTEwu.9-9mW=@ȅ2s/!?|,bPHTa%C\U1OaD@qNYTFT 4mw4e>c05_m:HyGMcun\8c :LdsMMPb$ڠjMY*݀y\[|(aVg̓>Jd9mƩfnCV`0LԂFqq[vGv*<+4h>uRemCϝF %f&5rhh=R -6lNzTE~u1n_ZA>5dVh-i2r~" ݄̀ vcV2qxҮ,?g2F-!I-tSA4Ea"_ag`>3f>>6$n"mahfbϗO笳'g6ʠ5s56̼2E烾/o\ەE713oyW k #U`Ӟ2Mw%qۘ+ߕ.t3{Q3-l1c̠BG@l\qxbjU׫2VߛeK8WTo41+uRT|r29QnluUfC5Yvൾ@ S1#|Pqx_lj,kQ'UxPHmi=%߭S,<|4ҝT''JhrqisǪF2F4R?P@pI $T"~G".TrN!3a^&hƇ*<*^y8)~d!.FqQtv@lsRlE JGvK-tlt,`qV9uczȲ|ip*"4})[Jur`=;fhQ_89l9DFX7Y%"U(zu4Mn4,E &^]}9٫6X.~z(Yd^*n%F?*KR$Ĵ)X@fұi2W_ 0|۱"CKXv^ڷΗbHEζu3pYVpZOŅϠLx[xtTb[}@Q^266Ԋ=q8ǡ ±^YplJi@ I*۶fWSb/X1T+d%-Ok#렎98dVּ$y95[9pTxZ:71q]˓3 w$Fz^ J"ǪvÆ/loaмl H3%֝JǕ1rt_Kc,Eu_v<| crt7[Ԑ =1 92 ;g<Id]B -A}feo~<ڣ 9cKՓi`|^O{+_DIX@&\l>Js6FP:iNt_J|lk$Ql="%_e5IP͂GuꍠS(#dEY)2 W1RД7 ^酳s!%*~0'Rc{2ڝ}ԕ7SI|E+Y!2wsz5PS] iKƤN)_RɖBgzJS%Ά9c7[4{KL(.''axOլsa'BHyjl5vMfm1FXFf%LfťNm+GWRD [{RB-QT E$NJV8?#iinmǃ䶁)&-5$ūj衑/iTa|,C|f}85FҺ~𖉴,,m#plKO)wXv?NKd:LK~Ane"/+!q-l݆hfA&T)Z{D60xʐ楂הsm6As|>,< Zq=Zhӟy1pNйvsq<`/RV5?;VmکS¶MqHX5~^?ϖy6E _;.ݿS;'ҸƅVQ =EXM#0("N c? {NC tb&ߖ@[Y FK cqj:2k V%p,cV^(Qab w9~FD!:BvE_~N/#Di^UTT\hZ,{ıŤ S˵̋"MЩS{02OZ+A1' ,)Q%#wU6GY_Qi H1eդgB+lB|5VW= zPtbOn gBxRTU\–JMz'csxogBF^ZmhH|;vr^ &'ʦa]2fFxmJ2gURJ66R\IlhDj+*t sO#AzÐ楴ǐ.{[mA{GV,[(8ra)k"Xnhkbd`{GA[ xap ><QB*qky߆<M'מxO '8Nc1`Út)Ԩs#To~I-߷j>Un%$odly31>[Z=n606ꄨFVjW;8eFG~5977q{< YZ