knot-module-geoip-3.2.1-1.el7> 6 6`d63!}|J^>j/5,dch= j/5,d)/ʡ4I8SqFߑ2,ĸ4W|m /4r@䠾e]xj2ťTI_Ą""JmۇBs+3;LwJ}RޗH-]@b˵֥[͒mYz9y)U)?:6%HtSa^Tuav37UUry.1Cΰ62+Xp=zwחJml3k/uU O"X -%| ۆuLH垓ԦonEV Od9Nƻ82d7dff2c054ba6c5dda1ce19f36ceee6d64789c`3!}|J^>j/5,dch= j/5,dz8W'oJ j@Z9,ֱ b#,JQ擺3|V.SAݕ5v|f+,IKo'eM޳"ϼ?r8!NrA,m0L %/!kXPm Sja&uݜ׋&Zbl湠43{2!|[! %U -IXL\%/9UaQ n/dY!s﹝{B܆\qǑ+t ^wh9?:5'r4'WPw{"ڿJD$Ɋ"g[fo09>ÖfPT 8Ec \) {N;^|9H8@m"(N)j)xǜӾ\H8O$ȈLѣbweCZVy;p%Xʥ1+rQgWYe"Z{KV݆1nH}KwF&MhDM@-JeS=[>:mH?m8d  : $( * , 0 q tx}((8?9?:?GjHjIjXjYj\k]k^k!bk>dlelfl ll tl(ul,vl0wlxlylmmCknot-module-geoip3.2.11.el7geoip module for Knot DNSThe package contains geoip Knot DNS module for geography-based responses.cWbuildvm-x86-04.iad2.fedoraproject.orgZFedora ProjectFedora ProjectGPL-3.0-or-laterFedora ProjectUnspecifiedhttps://www.knot-dns.czlinuxx86_64ZcWW733f2e353f69b53fc8e5166b9700cb499a412657d73587eea3fb6af2fecf9b63rootrootknot-3.2.1-1.el7.src.rpmknot-module-geoipknot-module-geoip(x86-64)@@@@@@@@@@@@@@@@@   @ knotlibc.so.6()(64bit)libc.so.6(GLIBC_2.10)(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.8)(64bit)libgcc_s.so.1()(64bit)libgcc_s.so.1(GCC_3.0)(64bit)libgcc_s.so.1(GCC_3.3.1)(64bit)libmaxminddb.so.0()(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libpthread.so.0(GLIBC_2.3.2)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)rpmlib(PayloadIsXz)3.2.1-1.el73.0.4-14.6.0-14.0-15.2-14.11.3c*cobjbDF@b@aՈ@a@an@a9@aj@a @a@`t`9@`f@`c`@_H@_@_E@_m_Z@_O@^˳@^U@^^F]}@]ʞ]@]]2@]'$[ @[H@[E@ZnZZZZ}@Zz@Ze@ZNYYYXƉXX@XAXJX-W#WhWWV&@VUUUUa@UG_@T@T@Jakub Ružička - 3.2.1-1Jakub Ružička - 3.2.0-1Jakub Ružička - 3.1.8-1Jakub Ružička - 3.1.7-1Jakub Ružička - 3.1.6-1Jakub Ružička - 3.1.5-1Jakub Ružička - 3.1.4-1Jakub Ružička - 3.1.3-1Jakub Ružička - 3.1.2-1Jakub Ružička - 3.1.1-1Jakub Ružička 3.1.0-2Jakub Ružička - 3.1.0-1Jakub Ružička - 3.0.8-1Jakub Ružička - 3.0.7-1Jakub Ružička - 3.0.6-1Jakub Ružička 3.0.5-1Jakub Ružička - 3.0.4-1Jakub Ružička - 3.0.3-1Jakub Ružička - 3.0.2-1Jakub Ružička - 3.0.1-1Jakub Ružička 3.0.0-2Jakub Ružička 3.0.0-1Jakub Ružička 2.9.6-1Tomas Krizek - 2.9.5-1Tomas Krizek - 2.9.4-1Tomas Krizek - 2.9.3-1Tomas Krizek - 2.9.2-1Tomas Krizek - 2.9.1-1Tomas Krizek - 2.8.4-1Tomas Krizek - 2.8.3-1Tomas Krizek - 2.8.2-1Tomas Krizek - 2.6.9-1Fedora Release Engineering - 2.6.8-2Tomas Krizek - 2.6.8-1Tomas Krizek - 2.6.7-1Tomas Krizek - 2.6.6-1Iryna Shcherbina - 2.6.5-2Tomas Krizek - 2.6.5-1Igor Gnatenko - 2.6.4-3Fedora Release Engineering - 2.6.4-2Tomas Krizek - 2.6.4-1Petr Špaček - 2.6.1-1Petr Spacek - 2.5.3-1Petr Spacek - 2.5.3-2Petr Spacek - 2.5.3-1Petr Spacek - 2.4.1-2Petr Spacek - 2.4.1-1Fedora Release Engineering - 2.4.0-2Petr Spacek - 2.4.0-1Jan Vcelak - 2.3.3-1Jan Vcelak - 2.3.2-1Jan Vcelak - 2.3.0-3Jan Vcelak - 2.3.0-2Jan Vcelak - 2.3.0-1Jan Vcelak - 1.6.8-1Jan Vcelak 1.6.7-1Jan Vcelak 1.6.6-1Jan Vcelak 1.6.5-1Jan Vcelak 1.6.4-1Fedora Release Engineering - 1.99.1-4Kalev Lember - 1.99.1-3Jan Vcelak 1.99.1-2Jan Vcelak 1.99.1-1- Update to 3.2.1 - Remove patches included upstream - Update Conflicts and move to knot-libs- Update to 3.2.0 - Patch: fix tests on 32-bit platforms - Patch: revert problematic hardening of service file - Patch: revert config improvement to support EL 7 - New knot-dnssecutils subpackage - Debian compat (knot-utils vs knot-dnsutils) - Remove bundled(jquery) version as it differes between distros- Update to 3.1.8- Update to 3.1.7- Update to 3.1.6 - Use _sharedstatedir for home- Update to 3.1.5- Update to 3.1.4- Update to 3.1.3- Update to 3.1.2- Update to 3.1.1 - Enable XDP on ARM and improve XDP config macros - Remove patch included upstream- Introduce a patch to fix tests on ppc64le - Use autosetup macro to apply patches- Update to 3.1.0 - Add missing BuildRequires including new libmnl for kxdpgun - Temporarily disable XDP on ARM until issues are resolved- Update to 3.0.8 - Print failed tests during check- Update to 3.0.7- Update to 3.0.6- Update to 3.0.5 - Properly escape BASE_VERSION macro - Include module dirs in main package- Update to 3.0.4 - Move dnstap module to subpackage - Move geoip module to subpackage - Remove redundant VERSION macro- Update to 3.0.3- Update to 3.0.2- Update to 3.0.1 - Sync packaging from upstream- Rebuild- New major upstream release 3.0.0 - Sync packaging from upstream- Update to 2.9.6- new upstream release 2.9.5- new upstream release 2.9.4- new upstream release 2.9.3- new upstream release 2.9.2- New upstream release 2.9.1 - add EPEL8 compatibility - fix unsafe PGP keyring permissions- new upstream release 2.8.4- new upstream release 2.8.3- rebase to latest upstream version 2.8.2Knot DNS 2.6.9 (2018-08-14) =========================== Improvements: ------------- - Added zone wire size to zone loading log message - Added debug log message for each unsuccessful remote address operation Bugfixes: --------- - Zone not flushed after re-signing during zone load #594 - Server crashes when committing empty zone transaction - Incoming IXFR with on-slave signing sometimes leads to memory corruption #595- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_RebuildKnot DNS 2.6.8 (2018-07-10) =========================== Features: --------- - New 'import-pkcs11' command in keymgr Improvements: ------------- - Unixtime serial policy mimics Bind – increment if lower #593 Bugfixes: --------- - Creeping memory consuption upon server reload #584 - Kdig incorrectly detects QNAME if 'notify' is a prefix - Server crashes when zone sign fails #587 - CSK->KZSK rollover retires CSK early #588 - Server crashes when zone expires during outgoing multi-message transfer - Kjournalprint doesn't convert zone name argument to lower-case - Cannot switch to a previously used ksk-shared dnssec policy #589Knot DNS 2.6.7 (2018-05-17) =========================== Features: --------- - Added 'dateserial' (YYYYMMDDnn) serial policy configuration (Thanks to Wolfgang Jung) Improvements: ------------- - Trailing data indication from the packet parser (libknot) - Better configuration check for a problematical option combination Bugfixes: --------- - Incomplete configuration option item name check - Possible buffer overflow in 'knot_dname_to_str' (libknot) - Module dnsproxy doesn't preserve letter case of QNAME - Module dnsproxy duplicates OPT and TSIG in the non-fallback modeKnot DNS 2.6.6 (2018-04-11) =========================== Features: --------- - New EDNS option counters in the statistics module - New '+orphan' filter for the 'zone-purge' operation Improvements: ------------- - Reduced memory consuption of disabled statistics metrics - Some spelling fixes (Thanks to Daniel Kahn Gillmor) - Server no longer fails to start if MODULE_DIR doesn't exist - Configuration include doesn't fail if empty wildcard match - Added a configuration check for a problematical option combination Bugfixes: --------- - NSEC3 chain not re-created when SOA minimum TTL changed - Failed to start server if no template is configured - Possibly incorrect SOA serial upon changed zone reload with DNSSEC signing - Inaccurate outgoing zone transfer size in the log message - Invalid dname compression if empty question section - Missing EDNS in EMALF responses- Update Python 2 dependency declarations to new packaging standards (See https://fedoraproject.org/wiki/FinalizingFedoraSwitchtoPython3)- New upstream release 2.6.5 Knot DNS 2.6.5 (2018-02-12) =========================== Features: --------- - New 'zone-notify' command in knotc - Kdig uses '@server' as a hostname for TLS authenticaion if '+tls-ca' is set Improvements: ------------- - Better heap memory trimming for zone operations - Added proper polling for TLS operations in kdig - Configuration export uses stdout as a default output - Simplified detection of atomic operations - Added '--disable-modules' configure option - Small documentation updates Bugfixes: --------- - Zone retransfer doesn't work well if more masters configured - Kdig can leak or double free memory in corner cases - Inconsistent error outputs from dynamic configuration operations - Failed to generate documentation on OpenBSD- Escape macros in %changelog- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild- Added PGP signature verification - Added integration test - New upstream release 2.6.4 Knot DNS 2.6.4 (2018-01-02) =========================== Features: --------- - Module synthrecord allows multiple 'network' specification - New CSK handling support in keymgr Improvements: ------------- - Allowed configuration for infinite zsk lifetime - Increased performance and security of the module synthrecord - Signing changeset is stored into journal even if 'zonefile-load' is whole Bugfixes: --------- - Unintentional zone re-sign during reload if empty NSEC3 salt - Inconsistent zone names in journald structured logs - Malformed outgoing transfer for big zone with TSIG - Some minor DNSSEC-related issues Knot DNS 2.6.3 (2017-11-24) =========================== Bugfixes: --------- - Wrong detection of signing scheme rollover Knot DNS 2.6.2 (2017-11-23) =========================== Features: --------- - CSK algorithm rollover and (KSK, ZSK) <-> CSK rollover support Improvements: ------------- - Allowed explicit configuration for infinite ksk lifetime - Proper error messages instead of unclear error codes in server log - Better support for old compilers Bugfixes: --------- - Unexpected reply for DS query with an owner below a delegation point - Old dependencies in the pkg-config file- New upstream release 2.6.1 Knot DNS 2.6.1 (2017-11-02) =========================== Features: --------- - NSEC3 Opt-Out support in the DNSSEC signing - New CDS/CDNSKEY publish configuration option Improvements: ------------- - Simplified DNSSEC log message with DNSKEY details - +tls-hostname in kdig implies +tls-ca if neither +tls-ca nor +tls-pin is given - New documentation sections for DNSSEC key rollovers and shared keys - Keymgr no longer prints useless algorithm number for generated key - Kdig prints unknown RCODE in a numeric format - Better support for LLVM libFuzzer Bugfixes: --------- - Faulty DNAME semantic check if present in the zone apex and NSEC3 is used - Immediate zone flush not scheduled during the zone load event - Server crashes upon dynamic zone addition if a query module is loaded - Kdig fails to connect over TLS due to SNI is set to server IP address - Possible out-of-bounds memory access at the end of the input - TCP Fast Open enabled by default in kdig breaks TLS connection Knot DNS 2.6.0 (2017-09-29) =========================== Features: --------- - On-slave (inline) signing support - Automatic DNSSEC key algorithm rollover - Ed25519 algorithm support in DNSSEC (requires GnuTLS 3.6.0) - New 'journal-content' and 'zonefile-load' configuration options - keymgr tries to run as user/group set in the configuration - Public-only DNSSEC key import into KASP DB via keymgr - NSEC3 resalt and parent DS query events are persistent in timer DB - New processing state for a response suppression within a query module - Enabled server side TCP Fast Open if supported - TCP Fast Open support in kdig Improvements: ------------- - Better record owner compression if related to the previous rdata dname - NSEC(3) chain is no longer recomputed whole on every update - Remove inconsistent and unnecessary quoting in log files - Avoiding of overlapping key rollovers at a time - More DNSSSEC-related semantic checks - Extended timestamp format in keymgr Bugfixes: --------- - Incorrect journal free space computation causing inefficient space handling - Interface-automatic broken on Linux in the presence of asymmetric routing Knot DNS 2.5.5 (2017-09-29) =========================== Improvements: ------------- - Constant time memory comparison in the TSIG processing - Proper use of the ctype functions - Generated RRSIG records have inception time 90 minutes in the past Bugfixes: --------- - Incorrect online signature for NSEC in the case of a CNAME record - Incorrect timestamps in dnstap records - EDNS Subnet Client validation rejects valid payloads - Module configuration semantic checks are not executed - Kzonecheck segfaults with unusual inputs Knot DNS 2.5.4 (2017-08-31) =========================== Improvements: ------------- - New minimum and maximum refresh interval config options (Thanks to Manabu Sonoda) - New warning when unforced flush with disabled zone file synchronization - New 'dnskey' keymgr command - Linking with libatomic on architectures that require it (Thanks to Pierre-Olivier Mercier) - Removed 'OK' from listing keymgr command outputs - Extended journal and keymgr documentation and logging Bugfixes: --------- - Incorrect handling of specific corner-cases with zone-in-journal - The 'share' keymgr command doesn't work - Server crashes if configured with query-size and reply-size statistics options - Malformed big integer configuration values on some 32-bit platforms - Keymgr uses local time when parsing date inputs - Memory leak in kdig upon IXFR query- new upstream release WARNING: Automatic upgrade from versions 1.y.z is no longer possible. To migrate, upgrade your packages gradually or use contacts listed on https://www.knot-dns.cz/support/ (if you are in trouble).- disable dnstap on RHEL (depedencies are missing)- new upstream release WARNING: Automatic upgrade from versions 1.y.z is no longer possible. To migrate, upgrade your packages gradually or use contacts listed on https://www.knot-dns.cz/support/ (if you are in trouble). Knot DNS 2.5.3 (2017-07-14) =========================== Features: --------- - CSK rollover support for Single-Type Signing Scheme Improvements: ------------- - Allowed binding to non-local adresses for TCP (Thanks to Julian Brost!) - New documentation section for manual DNSSEC key algorithm rollover - Initial KSK also generated in the submission state - The 'ds' keymgr command with no parameter uses all KSK keys - New debug mode in kjournalprint - Updated keymgr documentation Bugfixes: --------- - Sometimes missing RRSIG by KSK in submission state. - Minor DNSSEC-related issues Knot DNS 2.5.2 (2017-06-23) =========================== Security: --------- - CVE-2017-11104: Improper TSIG validity period check can allow TSIG forgery (Thanks to Synacktiv!) Improvements: ------------- - Extended debug logging for TSIG errors - Better error message for unknown module section in the configuration - Module documentation compilation no longer depends on module configuration - Extended policy section configuration semantic checks - Improved python version compatibility in pykeymgr - Extended migration section in the documentation - Improved DNSSEC event timing on 32-bit systems - New KSK rollover start log info message - NULL qtype support in kdig Bugfixes: --------- - Failed to process included configuration - dnskey_ttl policy option in the configuration has no effect on DNSKEY TTL - Corner case journal fixes (huge changesets, OpenWRT operation) - Confusing event timestamps in knotc zone-status output - NSEC/NSEC3 bitmap not updated for CDS/CDNSKEY - CDS/CDNSKEY RRSIG not updated Knot DNS 2.5.1 (2017-06-07) =========================== Bugfixes: --------- - pykeymgr no longer crash on empty json files in the KASP DB directory - pykeymgr no longer imports keys in the "removed" state - Imported keys in the "removed" state no longer makes knotd to crash - Including an empty configuration directory no longer makes knotd to crash - pykeymgr is distributed and installed to the distribution tarball Knot DNS 2.5.0 (2017-06-05) =========================== Features: --------- - KASP database switched from JSON files to LMDB database - KSK rollover support using CDNSKEY and CDS in the automatic DNSSEC signing - Dynamic module loading support with proper module API - Journal can store full zone contents (not only differences) - Zone freeze/thaw support - Updated knotc zone-status output with optional column filters - New '[no]crypto' option in kdig - New keymgr implementation reflecting KASP database changes - New pykeymgr for JSON-based KASP database migration - Removed obsolete knot1to2 utility Improvements: ------------- - Added libidn2 support to kdig (with libidn fallback) - Maximum timer database switched from configure to the server configuration Knot DNS 2.4.4 (2017-06-05) =========================== Improvements: ------------- - Improved error handling in kjournalprint Bugfixes: --------- - Zone flush not replanned upon unsuccessful flush - Journal inconsistency after deleting deleted zone - Zone events not rescheduled upon server reload (Thanks to Mark Warren) - Unreliable LMDB mapsize detection in kjournalprint - Some minor issues found by AddressSanitizer Knot DNS 2.4.3 (2017-04-11) =========================== Improvements: ------------- - New 'journal-db-mode' optimization configuration option - The default TSIG algorithm for utilities input is HMAC-SHA256 - Implemented sensible default EDNS(0) padding policy (Thanks to D. K. Gillmor) - Added some more semantic checks on the knotc configuration operations Bugfixes: --------- - Missing 'zone' keyword in the YAML output - Missing trailing dot in the keymgr DS owner output - Journal logs 'invalid parameter' in several cases - Some minor journal-related problems Knot DNS 2.4.2 (2017-03-23) =========================== Features: --------- - Zscanner can store record comments placed on the same line - Knotc status extension with version, configure, and workers parameters Improvements: ------------- - Significant incoming XFR speed-up in the case of many zones Bugfixes: --------- - Double OPT RR insertion when a global module returns KNOT_STATE_FAIL - User-driven zscanner parsing logic inconsistency - Lower serial at master doesn't trigger any errors - Queries with too long DNAME substitution do not return YXDOMAIN response - Incorrect elapsed time in the DDNS log - Failed to process forwarded DDNS request with TSIG- configuration checking was fixed to be compatible with Knot 2.4.x- new upstream release 2.4.1 replaces old 1.6.x series which is not supported - configuration should be upgraded automatically using knot1to2 tool - make sure you reviewed the new configuration in /etc/knot directory!- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- new upstream release: + fix: False positive semantic-check warning about invalid bitmap in NSEC + fix: Unnecessary SOA queries upon notify with up to date serial + fix: Timers for expired zones are reset on reload + fix: Zone doesn't expire when the server is down + fix: Failed to handle keys with duplicate keytags + fix: Per zone module and global module insconsistency + fix: Obsolete online signing module configuration + fix: Malformed output from kjournalprint + fix: Redundant SO_REUSEPORT activation on the TCP socket + fix: Failed to use higher number of background workers + improvement: Lower memory consumption with qp-trie + improvement: Zone events and zone timers improvements + improvement: Print all zone names in the FQDN format + improvement: Simplified query module interface + improvement: Shared TCP connection between SOA query and transfer + improvement: Response Rate Limiting as a module with statistics support + improvement: Key filters in keymgr + features: New unified LMDB-based zone journal + features: Server statistics support + features: New statistics module for traffic measuring + features: Automatic deletion of retired DNSSEC keys + features: New control logging category- new upstream release: + fix: double free when failed to apply zone journal + fix: zone bootstrap retry interval not preserved upon zone reload + fix: DNSSEC related records not flushed if not signed + fix: false semantic checks warning about incorrect type in NSEC bitmap + fix: memory leak in kzonecheck + improvement: all zone names are fully-qualified in log + features: new kjournalprint utility- new upstream release: + fix: missing glue in some responses + fix: knsupdate prompt printing on non-terminal + fix: configuration policy item names in documentation + fix: segfault on OS X Sierra + fix: incorrect %s expansion for the root zone + fix: refresh not existing slave zone after restart + fix: immediate zone refresh upon restart if refresh already scheduled + fix: early zone transfer after restart if transfer already scheduled + fix: not ignoring empty non-terminal parents during delegation lookup + fix: CD bit clearing in responses + fix: compilation error on GNU/kFreeBSD + fix: server crash after double zone-commit if journal error + improvement: significant speed-up of conf-commit and conf-diff operations + improvement: new EDNS Client Subnet API + improvement: better semantic-checks error messages + improvement: speed-up of knotc if control operation and known socket + improvement: zone purge operation purges also zone timers + feature: print TLS certificate hierarchy in kdig verbose mode + feature: new +subnet alias for +client + feature: new mod-whoami and mod-noudp modules + feature: new zone-purge control command + feature: new log-queries and log-responses options for mod-dnstap + feature: simple modules don't require empty configuration section + feature: new zone journal path configuration option + feature: new timeout configuration option for module dnsproxy- fix post-installation scriptlet (RHBZ #1370939)- endian independent DNS cookies (fixes build on ppc64 and s390x)- new upstream release: + fix: No wildcard expansion below empty non-terminal for NSEC signed zone + fix: Don't ignore non-existing records to be removed in IXFR + fix: Fix kdig IXFR response processing if the transfer content is empty + fix: Avoid multiple loads of the same PKCS #11 module + improvement: Refactored semantic checks and better error messages + improvement: Set TC flag in delegation only if mandatory glue doesn't fit the response + improvement: Separate EDNS(0) payload size configuration for IPv4 and IPv6 + feature: Zone size limit restriction for DDNS, AXFR, and IXFR (CVE-2016-6171)- new upstream release: + fix: Transfer of a huge rrset goes into an infinite loop + fix: Huge response over TCP contains useless TC bit instead of SERVFAIL + fix: Failed to build utilities with disabled daemon + fix: Memory leaks during keys removal + fix: Rough TSIG packet reservation causes early truncation + fix: Minor out-of-bounds string termination write in rrset dump + fix: Server crash during stop if failed to open timers DB + fix: Failed to compile on OS X older than Sierra + fix: Poor minimum UDP-max-size configuration check + fix: Failed to receive one-record-per-message IXFR-style AXFR + fix: Kdig timeouts when receiving RCODE != NOERROR on subsequent transfer message + improvement: Speed-up of rdata addition into a huge rrset + improvement: Introduce check of minumum timeout for next refresh + improvement: Dnsproxy module can forward all queries without local resolving- new upstream release: + improvement: Log change of the zone serial number after IXFR transfer + improvement: Document operational impact of various RRL settings + improvement: Add support for rate-limit-slip zero + improvement: Add 'timer-db' configuration option- new upstream release: + security fix: out-of-bound read in packet parser for malformed NAPTR record + fix: systemd startup notifications- new upstream release: + fix: don't load expired zones on reload and startup + fix: remove race condition in scheduling causing delaying of events + fix: NSEC proof construction in zones with many delegations + fix: TC flag setting in RRL slipped answers + fix: disable domain name compression for root label + fix: check if executed under systemd before using journald log sink + feature: write persistent timers on server shutdown for better performance + feature: support time unit specification for 'max-conn-idle', 'max-conn-handshake', 'max-conn-reply', and 'notify-timeout' config options + feature: add 'request-edns-config' config option- new upstream release: + fix: lost NOTIFY message if received during zone transfer + fix: kdig, record correct dnstap SocketProtocol when retrying over TCP + fix: kdig, hide TSIG section with +noall + fix: do not set AA flag for AXFR/IXFR queries + feature: new configuration format in YAML, binary store im LMDB + feature: DNSSEC, separate library, switch to GnuTLS, new utilities + feature: DNSSEC, basic KASP support (generate initial keys, ZSK rollover) + feature: zone parser, split long TXT/SPF strings into multiple strings + feature: kdig, add generic dump style option (+generic) + feature: try all master servers on failure in multi-master environment + feature: improved remotes and ACLs (multiple addresses, multiple keys) + feature: basic support for zone file patterns (%s to substitute zone name) + improvement: do not write class for SOA record (unified with other RR types) + improvement: do not write master server address into the zone file + documentation: manual pages also in HTML and PDF format- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Rebuilt for nettle soname bump- fix BuildRequires for systemd integration- new upstream pre-release version: + DNSSEC: switch from OpenSSL to GnuTLS + DNSSEC: initial support for KASP - split package into subpackages - add documentation building - restart daemon on updated3.2.1-1.el73.2.1-1.el7geoip.so/usr/lib64/knot/modules-3.2/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericcpioxz2x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=3bd7e2f54c1bc1819a814d4e938b5562b4513a72, strippedR R RRR RRR RRRRRRRR RRhttps://bugz.fedoraproject.org/knot?`7zXZ !#,[] b2u y-iSqk,Rl 0xYY(ŽiM?'/*ṗR[u-GyҤٲ3tPw5? nQIz'=ONvM;)hPa2A^]T =fMypϘm2GuW*dKxt_A%y]7,6iz_ ʼ`sԗ9$N{ fKN8c3>nAh'2+*=>O %sQg6~3V F5$} Uw28;7>.;jRĻHbX2&| "e,Ð :])dv!ͤ=VY)6?=5hm; p{5HlÌ-gkto}s1 |y5z,AOU ˓]|FKԅʨCiǛ쓳-:P|)jB+,*NP_9miq+YcV`s,YK?φI띘;Z (:3Э[sK>SV 骔E_&GK֥g A%V)h ϔ]8Ġ_Y<{`; >$6}BlE ~'Vp-dvlqo\q("ewlAz" /6v 2Ft+N"u)'Ȥr4®qCUmŪƏ?% {/ǻ!/>L(4"HVS "x92nVTwSͫ6B_+C>w v` Ju-/+JoM:lqa8(fqfpnhwg7ݓW!DKeT+Rś^tU:&;2ӚFw}4\rڛe] xV-0 Ԓ Zt)T=%IWa.b~`mdcUJLj!D|e׳<0Hj ?ݱ6'{MJ^uCEt]sq8s(Y軯vy?e[fue>w4$G T, "B ٕJ!  oȐ ;HjxOY >!Lah[Cp>I]4i'̓wWb`8 {ۼ5oi3("#ΫJgPc24zl'9*il1f7䢵(}BR::2\Z"%v2-t3-՝ i>"ܹ|BE ;IM'(Wo2&ε͢Qn{ؼMFz؄n?wJ7mR!6>nU,]ge|JLu[ g i@ DzȢTL~*-I #g1o?)nO YcĉCtAh(COMxS6[彪nP`YHcÔ*-c &X&jPhcPw2)\(wfVU7Lr|qod`ү*Cf2Q>ΌՄv2dN{eH/Hk߽hEe d3 *?6Is {X(bS 'ٴ#Q+_^i7&fn yĢ<=sׄ#^1iʑɘ00!J߃ 3 ~輻Zq8 C 욗eۼ?ٶ㾒Xi9O!?Ca)9d5/ى$֪9]RlTcy)0bz$\`ڣ0*6@]IMn~3`\"YdȰYl3WHA)v#H]F9?ZZ2)y =xLKjƧ _2"lzx`A`iJu/o1.wyfU: mJ/^vI7]Q ZmFaIW0bs 0ClM ݜI>WxN­0ͩ1jwi _OKdnl[ި @=OLN/U,h-G};Y*tL.jklimͷ=}+9|5! 'l[|- $=h4UF>፮/-Xa{cn`/-~ԎIx{,+]+j` {VpR68U$IOAW=\_̘کL3YeT= Дj:-Z0Ur}XPL9Lp]KJɭ ר[FYoV!u$j&&:su³x#2I-4^f E`;ZE ͦ(+wVe&$Foq `|YෞJӽ̯Io9y4JUC4#*竧h4 XT ^~a7 P#hU-bMB[P XB hr6"EʳWu0q6o%4boK@ m(Vr#=3u(6AӾTA3QbJm,* m PMWU덁"I͝b`.$Vb R8]TiSJrV&;Sb9$:EwCJzoJzY;_ےl'PBJR*U-o>ëw leqL_t.d 8xۯ =źj5*ۧzEy[tqɴok59F=Oo. MbdSre-Nj 1 ^_0 9me¥G H6(߯,_)>ɐ g!5E^=j6xC#\@nA-JOzƁPWr +?nЈ04UAG?7x;]xq.c ;|Bc5J!d1(@s4KAkVƷDNY!IL s{lz F@FX{ wXfn%qޖ=IXMۍՙ4nzRj&ieC,2 V|pz ֆ49abp&={c΁b p^a-`c'}7v 7x+t|{IеYP8aCn+c9Rn6ӏF)w2I~wɟAւ9ƿ{]@B$ASHX, Dw阥r$-޳DmҏsfNʅ6zB>BFv4?tD~W"G)c&{r<G^1P8e_ p_e6c;ŀ? 4[gfwN'fׁ]E%uMUqhYQmvjm CN*Ϫ KHg<$JZufNQ C\ `]k.{T)/+ϲ"RXIQ_56PPe uVRsG%䶛 EH{A2(`]vPwϐW e@g;c~h0\ZXQ %):DG"7-\itGغZ+ I:g,[ Y{5iQ2UhҳJT{k!Y&e矸\?L7LuI̅- +(אo/M(8Z)ҼE%,cZؾPiqYWc7cZ 0"o}vl0lFS><= igb%S_KCEP'AET̂N60hύra,$LhK2P%؇/ :t qoDozW#DQEp/ŃU8ڕci@Cc }y3Wr+8 SSӛb Nˊ/g:rp֑RzcODJ%Ň vfl#}eT#Ğ<57=>DНF2!f4Njja fYJ;G3Cnj[ jhu7DŚ gT;_KxI Y &rr  / ^ @!fm%, їصgTPAҮ0 8Q&&f:qzU!G1ݟew"5 %2pMtŮ!0a:ky&h} Z'dښ2a5#yלu Լ.w2w朥<[}Ca%+99)r@woT]* ]E/JٻUg 'Ѻ"oÇ*B& dUPMVE7ĥ3Xu2`ai4Q42 5۵1T|wT&<?lxUrs&1n/~fȟ~agsBӯ7u3m[EoGH!`;Um&;Gr1}Jq;b}>t9xcBX(Zm9V?yxJco1]oDxs'P}ղ$2X"G'|JOSzG20)n5um spvDNrczD4'!"|`eGrJ= ֵt{Gګf.n˪E,>;YɧnB`NPJ*szͼF61G_!}AS'P2˸lݓV% fDkm&"1f0qL+U-n՛GOC Bw0}-:?TTa^jd>_0ugWWyk>2Pz^ANk %Rw~X63MI{- įT- J&f_J!b%ITZͯE,("#6_)Hٙ#جǾBKG$ 8uASb60.wȀshgP&o=k$X>F1u`TOQ#UzIJHa'kLjuI_! a5G8 g l#|W1Z߅ c`TX|w#KCv"VVYÔ ﴲ'TߕvAnhG^ԊG-ȊJq TXEMG5=-qq[ =$_:7Z$?` >VSJB߃pe-0+A֐>C]LBkM^ʚʇ"M^cr~}JDlRHO#]WͺUXPF$iX8`1ϵC+1|d]h?i9vXvXA¹Sh,h$dU:G9;M%5b%ڈlxcM/-BuIIa݊b<^Q EG-,Ur6] xS7W}6ΊWWR%L4MH؋'ЊVdT켸_A$lK@n#:oZxQ 垖ي ;=2:(X[_ClТc^Z;+&; sm!x RQ1MU"j_ /T@5aYY-~ͩ{&5wCB)!ߟӨ:SZe_0|{!3$@S/|:mْ ]D n,3fl}z==7 c.UX`O}&vykwUDS@Y|4#WzCu%p?/T H0Z`zQ*AlI!24zGpX%%CbU?̾_EyW6x1ӯ?.zdan}#LxzӺ:ypzT`[_IqCQryoY^ݠ{Zg/yWE3KՃ]A۾0{m"P8v\tv&Hp=JMq 4Tձ+Px)f%IRwG6P=2lOnqj8r,0یQᖡQ񚖶0N6@tnh;_ =a߷n>Ży/#{5]kQ˼7{I4yVx:#~zJWǓS23!U_'.V=b]* 1ӚLkJ0-@S1SHCi~CkS6 (۶gz%Rb/ӹu`/Gٙeӈcu#b|Mmh+8gP?US4T٧ҧm7º'}BCqhB]PLa[5 | Jqgʑr#a+vX #T'5ec-# W;Y# "pfGՔ7Gu` -7-|8?!jzok-ߛmIA `E"z~KQn+ p4tYWo !xK+J*ֈTj|@ 8{廪LhT:KTef@*xie/"TS{Խ|[zţ~q><4CA¬:_+1o ^BCҦՐF]DOz3`HWrg.+ӥ/eľʭ3:`CAbA$3NbX¾IPgG Uk;1e}E ax?1`oe8CWH, ƽZ#|$j J\jf8830`p-/̝(q6f%o}t L`^ xdS{@ as! ַP;Hqa5b.[-kwC=8$Hei`9옩j0q5!r~:"w/l\;5XMgVD:^)~6(7L}#=gw1oPvsH r[iMWtڇFV0` B ϿTރPr )iw\0ɑ?C[,"q CQ8^ewI玎-sșL#<JrTy%Dٞ.,gTU\6k >&YjnᅣMDv#(z`O>KgɅXJ^:ƳV'۶%ݚ v;s-}EԣJy6Y?u#iE2mji!IaAyݥ\( b![DJ}'ϵKpk{$H@Vt}=rDl[ݱ>.̢eO%̶6S >H1;Gig J`C&cww%; -^=\C[DuYek#|YvE]xDWZaك^ E3" 50-XԀ8  8KΉvzg[eh6-"6M3QpF @aÎv&:B^SǍ[RelnlO}XBj_$D~LezBf-VL4Q(b/)ܸDPX.InJ.)O>k{h۾$`ӌg)}# l mSFejKPߔDcO0}7+xx" 0AP]ײ/Gqre \yu1*`L.;2̸#ށi3ޔM!ٔ|}mbILx&d#CVuV;d2jU;;+b|H<_0n oP:FȵEf 4<}P#J@E}X( ͳ excKt>|:nQKv_1=xR2 = NQnx"D .%ܭk=3&R\#tx.%T㓐Lrƹ[*4C"TnܑÍ}U &/sڪrUTWa?PGYj. ?@설ɪmzpՕכ:}O ma3.WC Z&OD!ʜA}2_ai~X_*C,YUHml`9u# Gy=D'W }Fj+={_JS#$q?xԦ8\*ʦUN2Pv6j8*^NdǞsTfBrW XwmBwɯCq4zYq_F.K+Ľ`K 4 --%Xt߆Q[=iΣBbCcIi_U1׉mJ<6zE1gDbO=hcIબ~D5 In[],р㓊k>ȕ35mI@hגRY8J;D4N@c+/'n.N1\`trFID+?O{3:Oʭk' HZD^AL;xޤ3>>OBӠF.mOf#%)ʆU}?"C@掁~_ >)!-1 tor^R&x>*CJ$NH?jVKc ChE1C tұ+Ԅ]#os>80wڡT2x "˅.쀕k, jqVGoMc8_ۺ4y- IX\~+sle,jsmYdP(Kt&2,pSV˅;e_(z[ͻ2KzLE6%)jqLUP?CTKدĽ $.NMr3y;a^͵:X (A,Vn-&-l\EǢ:"[xn⭱S!Eh-+ǫ-'y$iwra}tEn*_P=mqA?G$48>gzD*bW,v $¼ ^xffbxޜ ഛZ ǯƑ) R*#=\sV@$t')ޭs*+L)gq\Fps-Ĥ,q)&j9}K Z&-\}kg@,9Z_Z .I̖zjԾ[^E_~}ldEBdǘb:EY A5{W %z/vPBHIj6" ''k)Ir*k%سQlD_τ1\ݿȀ=q#jܶnK' +匸j=k"s*}$}}e&h'i(C9$i%p&(*:k_:|+x;͐pLy'4* iak6ዚ hQFqo!%ڴrX@sb2$m!hQxp=A{ќ+vdC2f1t 33ΖB-, fė j|b_-T<gf<X_F{9ce?t\74[FPAAF6dSЉ+Jb0 AbɿnD+2lO_,MK+gg /Z 㸩%<[w%sBY^.!D3Oցw)TpUh%0&|?>ga!1,`eL޺={!4wz`/MM{*8{D+.+mw󜟉jRꞞG7RWG@kmJD+3V6Za.mω\v7pu!y/ֶDSONVo,=rY,^ Qr&${.ΕBϨ!h|@_ kG 銺XwF_^N{<fn gUFȦv%:RSMwKf{Nh%>ch ݻ"f#7Z?%(d?"F3suN@ TqSraJH&i,L?&\_3gt*yh]W(f"V-WidhRخ+*Lp IG,+Uưe]2zv _q-mwE/Urw25tBTJhT.[|0S7OG GKSWWnIe4C`fAh PT1!]Dʫ;^x85D19p'p#Ӥ5bn;_,Bk)b/)Za/i  >TӸu#20(nBk$VQ*e,*U.edψPR~b=%`DQ$06mr ]-|wNK=ڵK1bA\Uӥ m\d֟Cwc5fhKm 7*>0qe"s91'1v\>ooFV䔫5nbUxfEcgb&!b0fnS(:- 2V9 鿁,bJm/E+=JKhc1֏ jOUrRVU\>{CkHC RPrNL20|J#- ݊dx#'&mHUxhbQOz/fHz%/7r[4{c`vOyf2#wT`m ε, *OMg檿}M`Ɗyq]1 _p,W'E5 _3olJgj ?Aۺē=TS8cd!9~jj{J_9c-o,0} r4A0܆=sr< >YzL/.Jc"Ͱ8l,''ыX=).4œ U9E>=({|%6G*klMGObyM\ѿhW~^xFh2>T5n+|5@kk"˧t ;c štQ3\rd nB>)ܶfI >m9` [*auG&/oF-䆪hX~)Oy Dh{@%zn7~C@گxo5 +C(=x=Ɩ9ˋM|3 X.k w^,W#8~+ih96hCzCQpMoDrpN}&u{YH3.$0= i$Ao*=&ҽs8T{}[{4BlJA$S/; 7i%rUv*:TNR+D ߝ8p%0Oq :)EOmKvK0 @9.K[wb;Ii@sYrY"h`}G˾QjV"ٚ,9F^݉p<7 b=8yzYx'6N9;4EHx\Tv̩5j7 =j糺ŰV t;26"Wswb/mt-^G6ҥb OQ'}Et+V(huhU=/8!?_M"9#萺dNx(D;}"wuuXm&Ze`h hzg)CY/RtOI6/#jF^URPGyؙab[E=@T99!~V%58<򌸾_pT+Γ;| SéMGZ[f.T5̐U)mFau3Wϯn,c|rp6% -AWB,&Ev $e%zgD޳1j($ EQ7w"j݄r8f[K3c^x6zJ;I|:g|-2E smsbV IrhRaֱuFBB;,;g,GE12Eu|]d$)xk*~gv( #~*5)C2/8- me${\tAq6!>"? &bǴn'ɣCddؠj֘%K7?LޯR~<̛8m}F.^V񔁥A71,B)\r2$ڢf s4ȯPթ3yv2\|-f땕TåоBb4-!] Q#q&J=؟n.Ujܯ n6T0~slyJE"#KL{rt 3Gd)+Ry㱥\g)@NK*2.g栻J0Ro W9xrFA=T{G4/)֍P.P51YMǔ,.]<8wQf^b2fԧA XI!'9aHcllt2c f`%}) (1n~-H|uXkbFgQYoK0T"lzU2o:gx-k3>w=m8Yk4OTx04krd7C 6J+B\2{TQ\2O)Zo~${1#k,ç0H /ʀR,B,_d^F^1\Y1r4VZ2z/3w=|rboYtqv- qѓ5C>\NemGQɡЃhH ,^򙌭0?MGApq廐疮 ×Zm9Hf1C?NQbRe^rRAUHI.`BQcP9^h/X{'5؋: !ݫ-Wr-"wRݻ?1RǺ("ޅul!zS# O`B v32_ʘ/`N#0ـ[FH+YZÅ="@`VQa8 ge,Q~./GkH_@͈tH[.V(% 0nѺ5n=xɥ 2*E3 MKvg\|>ww3C-#FJ{&TkKb"+p^z>RE鍰ׁr}xg thFi}(XP3PXn+ 2<o9Տizo#;#|UPs&nT&tTQeu"I& {x!D%aQfu'*wH5i0r^a\tϦhX@Ӥ }Ao,}My+Wecէ?Ӵ+y!/)3_APWw[Z!";9$1Bm4MAU"^@"-cZ?6vzXBoyYB.Aa' U;z,A#) ;UHx~|ztN.pfk*BF5y޹|WzWSZ")q"\zЊZBVЛv(PtA7wMz^!uU9iMU{o|7:}Фb#+:K@*Gncjzbl~ 6T+{IY$MҥS) a ~骮-u'UVRJ˽[p 7k*,xkst͑z56-:rybNvW-Rujhxh^ܟ`Ahd&8_m+A`;!Ebbkg :3x SE!8Nk27v_MsVcoVP_xB--qQ!"ǽ>,4 IEwA¬np/:Qmby,(ʅYL3.5̉ ׈a%TFРn$xc<=e,sk)G,:ޞ"b 5  l_J:T̿SSSzBSP*Ej@x]-Ti{- Q|s!_+cЈEIT>>4+)X'OEԠ4W}Q'(׼]{˂J| 7}lg$Q%R쬆,gCB R F@3Bs|b^Ed{Rsfr>)E6?4Qe02/a;Qfzޜ^]b۱_l oNjĕ<4-{oa`ɡY$6Es9v|s]HAr"Sb2|pAĸMR`'N]Py̋gSXoݙcj%w(5 xCףB.Y`GX/}oQoeNTq~Sgc٣nQAho gFҋ~4>˩27%2#>`_ ,,`<NSn]f 'Nq. 䡯+ 4X`$tl@NYigq6o&vL/Zyo['5_Xɴ}ip` >1F.^jޣEb\yD t63L\Bob_aXӤh ] ?>e̾n>k_IuMYр=fp٣ظfܡxEcE4A9ģ(ۣWB]Vz3a;N+1-&5zzR\'0+> weKNOgR.E⮘ ѾYAeCE#OR KI$#ݫ/a'2Q (SgcVfsZ'_=`;߬3:MUejAݙ=S-N:%)[IX tPU4Ա\]" |Es֤Q&S0%EPayIC7 J{(TZuV"}G OWZd Wi IE*P(AyMX3P.B̠>,FTŔaHѓ!,KX34h Ð0q>ږ"`f"/\1M%ӓ{۠>JXWzgMӞ%8k9J(+[,V/ ԙeR3 +Yp.Iek8e|ąqlCVZl7X!M @(./>2xro"aHq NL0Y^  o/J@]"%P S~*d\%^O,B6/0(1Kx9MG!XީHXoz@W T3:& ǂCRDݓl % ȧ<WZ'ytHGˉƺ,-O^W30c څ0BQmҒA^FPSVd /WSb yi,φeTK̫_2m^Wtxto&9[FԭʠJ\;`?`wz,NkX7ů3>}'@@:6!\VҲ[B'~B1L_w}PW?=7ȿ L{i['Nz#Q^xm+En.9+!tRENs9Sjp1JSJ!Vآ{٭,jFԣCVxYhai$qSZ"Ո885?ӄ8N!#\_xv%/0IOo%;̪; #*\Rk(__4"jٱ-F`+|KT?~T%@m39 gZkdBtp0&&|yُQ|x-?kם0D'HɏT9?@ഗc|D_ iMԡ_REGu+/,"2ݛl[}2/BIɂ[%CN]2E׵7US gg" %&EF"rlԨܩm Ƕ /\Qæ^ٖ3/y|w `gy}̄0@'()bfRLVzoI$񼼩Q t!-3 [ӞOx2/k_eYĆ*fSpȥzl-_CÓD{)y )Oi4]&Ea_ҹT$t="݀~#{E5JX9Ǯ7C!ܯ )pWPߜ[US-;s٥~%l 3>IӲq5Pqr;J$ڴ~7^k`HF60^G=SYmc5; Wc*ZNlܫ 3{+#=K]Vb {:vru2.ʼzBĪjq2`>$'()Վ?]&&xrDuwaœFuon6hmeȏxy F5 y}̿zǗ*HSϠfLD慩I(dy; qãXz -͂wz󘑀 uV<KRC8TTPj\X^ٱKm-%VB[8 2ƹ1 `Ϫ%mRo wQƨ,WsbK[IfOqBKiIl1Cv9ePHx2=O1hcNuAZ>k0bG7TrS^nHOi?t6 /X'RwKKX).'8b-քϔ #JB Ok| a 51߰Pv(D!}pXfƻQ\lj \P{*j*H2'_ PSЕ,1PjZ~7)Գ5qLlMj$ ͇ leot0Fk/yB6RwO"+P;}% P]dk 3TLqM`f/|)h]uW4KPA5(&{Om:*Z'Vp݉_(:쾺7y_NC#R?-?ݱ # QCP׫Jx>H~5"~O<;(&C|-jN ܖ w֕;yhjAHCz5yp{Oc7zR&K9vUL\S߹Ӂj8Yڒd aX*O-J27%ς  7+){X)V\XdZGu:*6}yٳ= +Q3D>غͦ<3KIYb^ rvX/7.d騧*dn+)Fay,>y{?5$tIh EDEm 6r'4WQ6H&&88xZDPpÌ50z&qNp8g D0j5_ U7J ,j mgTɁHR#]4%㠈nqrw ȗy XpAJa"jtLni"~Au H7d<#*x>á wW< }*Dq}wc{ t?nBP:DFR)[*cꦥ-(p̈NDܚ*RA^J~-W F!YK(W2 -̌cg9NIp =M̺D{ڂsX[r| JE`AHILM8AUW(o"5PRFfdO1LvY"`Vs㛤@=U|Vzu?pF2S7ijD$'P^>#h34?0;\\-g^ yx%.`qgqv'I5?x m~v*s8M|0|I&QEH. S (=S.:?x:lwOlوh8^=WIf^8UOlДM ԍp~mScH(?&3 l`(c ׁ^ktaʄͰ)^tjE-h 1hw#KEUKQ9r8mrϙ_ۜQ:ٕ;!q+MUI-ח7#Z!lxẑgzQ89 i"eCR̡OƉsydچxD$Ҝ!*2! z 0VSdë6e&tey36I9,nֈ}>ѯ%h#[܏j ^P>3?t*>Uit%3X`ʙf՚$0 (#"fdFpK] $CHAcbZ*i0Nr *Et".@20åo3~I? R)$$6#'eӛ*MWyx]#Y\1 %|:i{hs I*C#9MӞe4 c>fӃܼ"z" W\J$އX8Fjv@ mrik ƝBXcD0&DldN/kV[1DމpxԿ?dxjvwZT5}-xv45彃:֒~g 3 9&Cz0(Cx MlMω<_p[(8FN=iQ_xc;gpq6|)v+%Eż'IH p&OwdҀ&q0OKٿ!r93yk ꂟpp*o4A-]η@Ҩ#F cwQmswrKPBKZ#j5T ߇U<n\JxqÕsp9ihބ%'yc*}XpȒ}szZDI"Vr]S1/: &Mٝ.ڼQ3Pcu /:J' *!X܁k9,_W[M'5k_F}-|xS`YNhwDLFkK~-l$PM@BH;tbm7锚1BsrkE dvE[t=.9.=7P0>EqbMbL'F,+F[}RxZ N BGtzN }Zws>'dgJ"'[LvS`QxJbԻ4$jQqhYJteŜ-m6/էQV+C\1}o =pN@eH'$mzi'pdBOG1 ey5$ ȤM5Qߤ E IJHխ*ʷL=U0>:ݐ9YmxCŤBS!\os`-Efe4dMvn|$,` V"h^ J+RTWv?l֔O?+mv +d=jys*8dU`êy: KCeNp P{ވGTNp~-O>QKPޓviNۛ Xߖp̧jo\`_p:(R诌5PƸKt}sC' >M_D$S}= 0zmC @8>B'~pӦWPZwee⯦y{¶) *ZB5o„MZPL/wI']gh`JCdCאn~7n֝Kmqҧ"8!=k*=p:`ƪ[">>z.PULdo: 5Ը"rF%j6aVpJ fJ8,KyYwqbb-C!kf21k <[7_>e@rV >ჰ[|'LQ8(ٖHPT-Iq|jf5 "P#D["lԈ@*ޟ?D 򴅳1nɒ/&xײfp S[eYT?+YrEc*RH/5]dm?'r"w@,ws:]$X!f<,޿`%Oh+a [{N[dz,"׭:"cV,F!K Чh"ȃعHx+Б "$@GҎUwږΎ4oq^m,Ou30hg=Ԟ9kf_RiT&Ry !S?:mhSdaW=yӔh͏.k~*nV%b^Zy^?e3u:;{k>O=2\\U))=tM}M3FcX!HiGٮ WcJFFԏ~P>ԗuu+K4<@PWlzY(9ƥgbweJX\tY0ݠHT$h_\q\:*ьvQ5Gx٩݅Tk=8]L 3_*s3y!Ȗ|,"vk/'Ŕ'%K/y#$wA!_?zCmD-y|  uJVE[k9 U<9BrNQGވTmp9vd?#_sY;mZݨ)~@&jW(Utń< hY'rX/S#/tL l[)k|x)-˔pȘO~/g! {CƂ^I*|oڍn֊oo"HJV6Ӫ.nr Cmvg !]E{$@Ť%@%d$*AO6=GGthiӯ}PӬSJQs$XahνYT"PKI 6#ec)20l֮ ˌS TGW"ssnmzp(+xˡu;(iopt :GY(9TQ}U#{0L?a!gƶ﷽'[r!;'mv2dÚ@q.ޛa 9WFr 縔ެ<4m6 H ?!z]igU[,Q2<2eTw+ٶ[3h lZ"F]gKT\:l%l}%_(lt]!br͒JGƫο>%oVBJM%ױ]7q1Q]2aB)ve0yo5&L彳vcs~ïr#U:>s+trT8k*q$s7yQZ/>0ȃL|s.|-;ƬQw:iAdQ:5Eqb3n힡mU,;¼6*i$[0 `Kf.4LDj|%Cv@f=,%_ ?.h>msf+:0++: }RZ"MlD';gB} vevy3)2)`".VF̷̸I,ncʱ 7OKlԺ>*ݱYE8 l3xG$@N'!&xUJT ̕c%%>%\KoڨEHHP Qd,ڙq޽d7Dc0*<}#hwB!w_ْ .!R5E?+(wAa8RLhW b41|.l,&swH&`^Cx؆^f2 _.whM ߈ąq={-RC!2AbPʂ镍D㨓y R^eiÁTYMiD;(}a+!3,W 2݈4h0vUi/4ӢsLS0iUўԧ JCR>Iyԅ-$-})J:KiPRDs>4W8ЮXؐs5(jY Tn6O2sLoHg;ܬ'[.{˞9Gm%Y)˲;3b 5%jS`p7T1rw]=tLl8 \T%+r#6Yn-~,;Zip ]GayL+tfܼ"[vPRoO`.nK7S6vb{7t5G1ǓmctRm.S^L7l\&-u-; 6 '4NGC#c[fی޹H@4 IJqBaJD NMtCd 򨽸bדl֨f $DMv;ppo%42k C9zAc,| ӕ&ُё >ZTnnsl1mM TTz3w*5ѣd=Ix%xO!ۅ}΅4` )^8}F K;+֨4)VQl'ٷ?Jɰm?DNV{*5pҡ}:lViT@bz`w8&({b,UcO0 #4HJ_e=y=I7:dY m$-ݶw79Spi|E?FCUJFBA Bյ$٫ eXHQ)ΗPu2**e:FFhuo0~PurC8Qv.Jc!8ly4V[HkgGjCaPΫGڋ ODc4O)|l v&>ss5~ض.IdK][Pi[{|cKWxiJg2 k8f=nvRvLO<h^ ,c FcMXEwìxƄR)A%Z]Lgi rA6av5ts+*1?B{,,B^VOl/uOVCO~ dvaCg꿐: 29_-^hʞE~Ԏl٧).o?i|sWWz/Cba.a0f%E0P$Zuj* g$ct թq,+!f< S)'E+ W)QX;KOf4 ]>Dm}yCc᩹bu3AsVB1"zSezW\U\Twvt|m[K"¥8nÈ,Xɋz=-dwC ք; Q;/)D$#}=^m0?NA @"!}rAGj$zW]Q-;NOx-MwBCï.-0D4Mi&{)fP:̦Ƒr["kј̖r' i]ۍ{THZ}ܛvڬWC vҳKҕx ࡩc߀i* ёa~m2(=|:zkۮ!5r3LQ ;9I,r{BVKBYv(-xfBi,\072ĐL΂RФmdWVޢR-Abt9`ojy(Q]A^J)b 0÷yL!k)5UM1vNWOĿk\9& |5өxZ2U4;wL^:͋zؚY>[>F˥~;Q߼}LEdjQ7 'S;ZeTy@<@ Q*?^GQQ]?HLG<5_ȷ#`n6H 9W_NJ'h'n!#EXyUTy80ayۃ.L@ NsgD)A\tQy}ۚr}NYzyU ,_$[ݎ o0ȴ2wV ' De9\BFr-~ B&[A/^>J?JǒdUB ʑxMWIvWɕc6sKq]aW*@upQ >JN^C?''Vf$%|#PCֆ]Z3obi2=;6u0k7l~1(#~FM]?K R<.O91H(?VxXAdعoɶ[<((evNٛAa1FuTQnd&/ګES' v֍+lesR_,bOXĒywD?CBuiz2"v;HiUohȘ}`~ 5pq+?J7EL|>=ߨqͻFeY O6瞮־뺽~vRR;"wH/kT9!U$z6ONa uV0lg|e"c$ $6!lo$o255APYɽdc䛞M'ݎC[<'L"]|sT8Z=4Ȟ`,3]hVu=ع@&?`%U婃 zǢ= ("gM [/JzH z(O^쐤J F[&>WtBfN gDDK¨|\%>`۞1|#+K= A*-ސĹ~oy\DEN̯֯a&]CIr ,mKˎ'&h eܦi%"(5"FGRGu>cYq,Ȓ-鑊""3 DWnH)nN{k1#3$ݢ/!4P~!TrGnJX֬u:\:Ct9O.d{Nv8Ebm(P3h-daMZƧ^sG`O0aԼy'9?kS*i-i RnW)1JIz[ - c>30M\-3l]}o=Smd !tfBixs-"elNvQƼYnYēQ"ٻꝧUf)Dr 5n7՘-8y4п b/Uhg%޶ L+|m4SS3Ni^ ș,BhE}h2&17P ^nt8Ϲ I/'GEg&U3@ 8'SA]r7GT8T-<NSR'LE2񄡧h6ƀX[cK#s _ޞlkZca$v<̡Fǻďy4E4d_aiV1 u֊aͩt;.FleBdnKQV|eIrtlUGҶ|6qWCk[a܊j*śNak.{ >x'~E1e!FVʻ6W_CQWS=S|q3q,oPQ4MZ+#O8U ]{u کㄖS.C쨯ݓ o6a 8yiKE҇ 5g|* $v[ ١jpZm>P[=~1k:!QE3zXzL)^)qaw1DaPQ~B28\< XW&l;,ΠvTVܨ1{ q3dٳlf>=YPCFA|rPihjP4b(2Wf(`QKoJFa6xsH]JHAT"QG.ȿHο&[#QksK%MqrŏVQdVnuQêB YZ