knot-module-geoip-3.2.10-1.el7> 6 6`d63!}|J^>j/5,deY j/5,dQF6 rZI=uٗJ3Ly!vStש?G΃t6f[g@ڂc ޅi.(?{RL-uR R,u9N$HOtV :Q"&GlܐP mӡp$e2!I7396451809c708ad09194eab9257c80d89dd683b@3!}|J^>j/5,deY j/5,d0LF ﻖ0l~oO̓{7N2<3@`%|r)t:NJX{A=\>JyCZ b^Ջ>ooVʩ Bξ9VI[{]7Rm.><]s0 K6$gF@[̯JZ(?wZ:3ٴO˞,3-X^BVO/GQĢ}T>=t)H_X@b{Ϯ·]#{#g7YЌIQ¤ZjyiF-o[-췆Y3]3OH@ȣ`&DU;icToG0b?M}ꍸD* דi*~rFϰ¿ɍi4!]luHtғr=˞Ϊ;5C @Z:I鋭`$ob\X_%k#/oA>(-&~f m:C:cj>:o?od ! ;  (, . 0 4 u x|,(8H9H:HGmHmImXmYm\m]m^mbmdnenfnlntnunvnwohxolyopooCknot-module-geoip3.2.101.el7geoip module for Knot DNSThe package contains geoip Knot DNS module for geography-based responses.eUbuildhw-x86-02.iad2.fedoraproject.orgiFedora ProjectFedora ProjectGPL-3.0-or-laterFedora ProjectUnspecifiedhttps://www.knot-dns.czlinuxx86_64ieU[d08fcfb6961a131001e1d6d40fef93f327ddd34022825be51546646ba7174a91rootrootknot-3.2.10-1.el7.src.rpmknot-module-geoipknot-module-geoip(x86-64)@@@@@@@@@@@@@@@@@   @ knotlibc.so.6()(64bit)libc.so.6(GLIBC_2.10)(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.8)(64bit)libgcc_s.so.1()(64bit)libgcc_s.so.1(GCC_3.0)(64bit)libgcc_s.so.1(GCC_3.3.1)(64bit)libmaxminddb.so.0()(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libpthread.so.0(GLIBC_2.3.2)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)rpmlib(PayloadIsXz)3.2.10-1.el73.0.4-14.6.0-14.0-15.2-14.11.3eRd\@d}dd.@cۥcc{h@ca @c*cobjbDF@b@aՈ@a@an@a9@aj@a @a@`t`9@`f@`c`@_H@_@_E@_m_Z@_O@^˳@^U@^^F]}@]ʞ]@]]2@]'$[ @[H@[E@ZnZZZZ}@Zz@Ze@ZNYYYXƉXX@XAXJX-W#WhWWV&@VUUUUa@UG_@T@T@Jakub Ružička - 3.2.10-1Jakub Ružička - 3.2.9-1Jakub Ružička - 3.2.8-1Jakub Ružička - 3.2.7-1Jakub Ružička - 3.2.6-1Jakub Ružička - 3.2.5-1Jakub Ružička - 3.2.4-1Jakub Ružička - 3.2.3-1Jakub Ružička - 3.2.2-1Jakub Ružička - 3.2.1-1Jakub Ružička - 3.2.0-1Jakub Ružička - 3.1.8-1Jakub Ružička - 3.1.7-1Jakub Ružička - 3.1.6-1Jakub Ružička - 3.1.5-1Jakub Ružička - 3.1.4-1Jakub Ružička - 3.1.3-1Jakub Ružička - 3.1.2-1Jakub Ružička - 3.1.1-1Jakub Ružička 3.1.0-2Jakub Ružička - 3.1.0-1Jakub Ružička - 3.0.8-1Jakub Ružička - 3.0.7-1Jakub Ružička - 3.0.6-1Jakub Ružička 3.0.5-1Jakub Ružička - 3.0.4-1Jakub Ružička - 3.0.3-1Jakub Ružička - 3.0.2-1Jakub Ružička - 3.0.1-1Jakub Ružička 3.0.0-2Jakub Ružička 3.0.0-1Jakub Ružička 2.9.6-1Tomas Krizek - 2.9.5-1Tomas Krizek - 2.9.4-1Tomas Krizek - 2.9.3-1Tomas Krizek - 2.9.2-1Tomas Krizek - 2.9.1-1Tomas Krizek - 2.8.4-1Tomas Krizek - 2.8.3-1Tomas Krizek - 2.8.2-1Tomas Krizek - 2.6.9-1Fedora Release Engineering - 2.6.8-2Tomas Krizek - 2.6.8-1Tomas Krizek - 2.6.7-1Tomas Krizek - 2.6.6-1Iryna Shcherbina - 2.6.5-2Tomas Krizek - 2.6.5-1Igor Gnatenko - 2.6.4-3Fedora Release Engineering - 2.6.4-2Tomas Krizek - 2.6.4-1Petr Špaček - 2.6.1-1Petr Spacek - 2.5.3-1Petr Spacek - 2.5.3-2Petr Spacek - 2.5.3-1Petr Spacek - 2.4.1-2Petr Spacek - 2.4.1-1Fedora Release Engineering - 2.4.0-2Petr Spacek - 2.4.0-1Jan Vcelak - 2.3.3-1Jan Vcelak - 2.3.2-1Jan Vcelak - 2.3.0-3Jan Vcelak - 2.3.0-2Jan Vcelak - 2.3.0-1Jan Vcelak - 1.6.8-1Jan Vcelak 1.6.7-1Jan Vcelak 1.6.6-1Jan Vcelak 1.6.5-1Jan Vcelak 1.6.4-1Fedora Release Engineering - 1.99.1-4Kalev Lember - 1.99.1-3Jan Vcelak 1.99.1-2Jan Vcelak 1.99.1-1- Update to 3.2.10- Update to 3.2.9- Update to 3.2.8- Update to 3.2.7- Update to 3.2.6- Update to 3.2.5- Update to 3.2.4 - Use devtoolset-12-gcc on EPEL 7- Update to 3.2.3- Update to 3.2.2- Update to 3.2.1 - Remove patches included upstream - Update Conflicts and move to knot-libs- Update to 3.2.0 - Patch: fix tests on 32-bit platforms - Patch: revert problematic hardening of service file - Patch: revert config improvement to support EL 7 - New knot-dnssecutils subpackage - Debian compat (knot-utils vs knot-dnsutils) - Remove bundled(jquery) version as it differes between distros- Update to 3.1.8- Update to 3.1.7- Update to 3.1.6 - Use _sharedstatedir for home- Update to 3.1.5- Update to 3.1.4- Update to 3.1.3- Update to 3.1.2- Update to 3.1.1 - Enable XDP on ARM and improve XDP config macros - Remove patch included upstream- Introduce a patch to fix tests on ppc64le - Use autosetup macro to apply patches- Update to 3.1.0 - Add missing BuildRequires including new libmnl for kxdpgun - Temporarily disable XDP on ARM until issues are resolved- Update to 3.0.8 - Print failed tests during check- Update to 3.0.7- Update to 3.0.6- Update to 3.0.5 - Properly escape BASE_VERSION macro - Include module dirs in main package- Update to 3.0.4 - Move dnstap module to subpackage - Move geoip module to subpackage - Remove redundant VERSION macro- Update to 3.0.3- Update to 3.0.2- Update to 3.0.1 - Sync packaging from upstream- Rebuild- New major upstream release 3.0.0 - Sync packaging from upstream- Update to 2.9.6- new upstream release 2.9.5- new upstream release 2.9.4- new upstream release 2.9.3- new upstream release 2.9.2- New upstream release 2.9.1 - add EPEL8 compatibility - fix unsafe PGP keyring permissions- new upstream release 2.8.4- new upstream release 2.8.3- rebase to latest upstream version 2.8.2Knot DNS 2.6.9 (2018-08-14) =========================== Improvements: ------------- - Added zone wire size to zone loading log message - Added debug log message for each unsuccessful remote address operation Bugfixes: --------- - Zone not flushed after re-signing during zone load #594 - Server crashes when committing empty zone transaction - Incoming IXFR with on-slave signing sometimes leads to memory corruption #595- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_RebuildKnot DNS 2.6.8 (2018-07-10) =========================== Features: --------- - New 'import-pkcs11' command in keymgr Improvements: ------------- - Unixtime serial policy mimics Bind – increment if lower #593 Bugfixes: --------- - Creeping memory consuption upon server reload #584 - Kdig incorrectly detects QNAME if 'notify' is a prefix - Server crashes when zone sign fails #587 - CSK->KZSK rollover retires CSK early #588 - Server crashes when zone expires during outgoing multi-message transfer - Kjournalprint doesn't convert zone name argument to lower-case - Cannot switch to a previously used ksk-shared dnssec policy #589Knot DNS 2.6.7 (2018-05-17) =========================== Features: --------- - Added 'dateserial' (YYYYMMDDnn) serial policy configuration (Thanks to Wolfgang Jung) Improvements: ------------- - Trailing data indication from the packet parser (libknot) - Better configuration check for a problematical option combination Bugfixes: --------- - Incomplete configuration option item name check - Possible buffer overflow in 'knot_dname_to_str' (libknot) - Module dnsproxy doesn't preserve letter case of QNAME - Module dnsproxy duplicates OPT and TSIG in the non-fallback modeKnot DNS 2.6.6 (2018-04-11) =========================== Features: --------- - New EDNS option counters in the statistics module - New '+orphan' filter for the 'zone-purge' operation Improvements: ------------- - Reduced memory consuption of disabled statistics metrics - Some spelling fixes (Thanks to Daniel Kahn Gillmor) - Server no longer fails to start if MODULE_DIR doesn't exist - Configuration include doesn't fail if empty wildcard match - Added a configuration check for a problematical option combination Bugfixes: --------- - NSEC3 chain not re-created when SOA minimum TTL changed - Failed to start server if no template is configured - Possibly incorrect SOA serial upon changed zone reload with DNSSEC signing - Inaccurate outgoing zone transfer size in the log message - Invalid dname compression if empty question section - Missing EDNS in EMALF responses- Update Python 2 dependency declarations to new packaging standards (See https://fedoraproject.org/wiki/FinalizingFedoraSwitchtoPython3)- New upstream release 2.6.5 Knot DNS 2.6.5 (2018-02-12) =========================== Features: --------- - New 'zone-notify' command in knotc - Kdig uses '@server' as a hostname for TLS authenticaion if '+tls-ca' is set Improvements: ------------- - Better heap memory trimming for zone operations - Added proper polling for TLS operations in kdig - Configuration export uses stdout as a default output - Simplified detection of atomic operations - Added '--disable-modules' configure option - Small documentation updates Bugfixes: --------- - Zone retransfer doesn't work well if more masters configured - Kdig can leak or double free memory in corner cases - Inconsistent error outputs from dynamic configuration operations - Failed to generate documentation on OpenBSD- Escape macros in %changelog- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild- Added PGP signature verification - Added integration test - New upstream release 2.6.4 Knot DNS 2.6.4 (2018-01-02) =========================== Features: --------- - Module synthrecord allows multiple 'network' specification - New CSK handling support in keymgr Improvements: ------------- - Allowed configuration for infinite zsk lifetime - Increased performance and security of the module synthrecord - Signing changeset is stored into journal even if 'zonefile-load' is whole Bugfixes: --------- - Unintentional zone re-sign during reload if empty NSEC3 salt - Inconsistent zone names in journald structured logs - Malformed outgoing transfer for big zone with TSIG - Some minor DNSSEC-related issues Knot DNS 2.6.3 (2017-11-24) =========================== Bugfixes: --------- - Wrong detection of signing scheme rollover Knot DNS 2.6.2 (2017-11-23) =========================== Features: --------- - CSK algorithm rollover and (KSK, ZSK) <-> CSK rollover support Improvements: ------------- - Allowed explicit configuration for infinite ksk lifetime - Proper error messages instead of unclear error codes in server log - Better support for old compilers Bugfixes: --------- - Unexpected reply for DS query with an owner below a delegation point - Old dependencies in the pkg-config file- New upstream release 2.6.1 Knot DNS 2.6.1 (2017-11-02) =========================== Features: --------- - NSEC3 Opt-Out support in the DNSSEC signing - New CDS/CDNSKEY publish configuration option Improvements: ------------- - Simplified DNSSEC log message with DNSKEY details - +tls-hostname in kdig implies +tls-ca if neither +tls-ca nor +tls-pin is given - New documentation sections for DNSSEC key rollovers and shared keys - Keymgr no longer prints useless algorithm number for generated key - Kdig prints unknown RCODE in a numeric format - Better support for LLVM libFuzzer Bugfixes: --------- - Faulty DNAME semantic check if present in the zone apex and NSEC3 is used - Immediate zone flush not scheduled during the zone load event - Server crashes upon dynamic zone addition if a query module is loaded - Kdig fails to connect over TLS due to SNI is set to server IP address - Possible out-of-bounds memory access at the end of the input - TCP Fast Open enabled by default in kdig breaks TLS connection Knot DNS 2.6.0 (2017-09-29) =========================== Features: --------- - On-slave (inline) signing support - Automatic DNSSEC key algorithm rollover - Ed25519 algorithm support in DNSSEC (requires GnuTLS 3.6.0) - New 'journal-content' and 'zonefile-load' configuration options - keymgr tries to run as user/group set in the configuration - Public-only DNSSEC key import into KASP DB via keymgr - NSEC3 resalt and parent DS query events are persistent in timer DB - New processing state for a response suppression within a query module - Enabled server side TCP Fast Open if supported - TCP Fast Open support in kdig Improvements: ------------- - Better record owner compression if related to the previous rdata dname - NSEC(3) chain is no longer recomputed whole on every update - Remove inconsistent and unnecessary quoting in log files - Avoiding of overlapping key rollovers at a time - More DNSSSEC-related semantic checks - Extended timestamp format in keymgr Bugfixes: --------- - Incorrect journal free space computation causing inefficient space handling - Interface-automatic broken on Linux in the presence of asymmetric routing Knot DNS 2.5.5 (2017-09-29) =========================== Improvements: ------------- - Constant time memory comparison in the TSIG processing - Proper use of the ctype functions - Generated RRSIG records have inception time 90 minutes in the past Bugfixes: --------- - Incorrect online signature for NSEC in the case of a CNAME record - Incorrect timestamps in dnstap records - EDNS Subnet Client validation rejects valid payloads - Module configuration semantic checks are not executed - Kzonecheck segfaults with unusual inputs Knot DNS 2.5.4 (2017-08-31) =========================== Improvements: ------------- - New minimum and maximum refresh interval config options (Thanks to Manabu Sonoda) - New warning when unforced flush with disabled zone file synchronization - New 'dnskey' keymgr command - Linking with libatomic on architectures that require it (Thanks to Pierre-Olivier Mercier) - Removed 'OK' from listing keymgr command outputs - Extended journal and keymgr documentation and logging Bugfixes: --------- - Incorrect handling of specific corner-cases with zone-in-journal - The 'share' keymgr command doesn't work - Server crashes if configured with query-size and reply-size statistics options - Malformed big integer configuration values on some 32-bit platforms - Keymgr uses local time when parsing date inputs - Memory leak in kdig upon IXFR query- new upstream release WARNING: Automatic upgrade from versions 1.y.z is no longer possible. To migrate, upgrade your packages gradually or use contacts listed on https://www.knot-dns.cz/support/ (if you are in trouble).- disable dnstap on RHEL (depedencies are missing)- new upstream release WARNING: Automatic upgrade from versions 1.y.z is no longer possible. To migrate, upgrade your packages gradually or use contacts listed on https://www.knot-dns.cz/support/ (if you are in trouble). Knot DNS 2.5.3 (2017-07-14) =========================== Features: --------- - CSK rollover support for Single-Type Signing Scheme Improvements: ------------- - Allowed binding to non-local adresses for TCP (Thanks to Julian Brost!) - New documentation section for manual DNSSEC key algorithm rollover - Initial KSK also generated in the submission state - The 'ds' keymgr command with no parameter uses all KSK keys - New debug mode in kjournalprint - Updated keymgr documentation Bugfixes: --------- - Sometimes missing RRSIG by KSK in submission state. - Minor DNSSEC-related issues Knot DNS 2.5.2 (2017-06-23) =========================== Security: --------- - CVE-2017-11104: Improper TSIG validity period check can allow TSIG forgery (Thanks to Synacktiv!) Improvements: ------------- - Extended debug logging for TSIG errors - Better error message for unknown module section in the configuration - Module documentation compilation no longer depends on module configuration - Extended policy section configuration semantic checks - Improved python version compatibility in pykeymgr - Extended migration section in the documentation - Improved DNSSEC event timing on 32-bit systems - New KSK rollover start log info message - NULL qtype support in kdig Bugfixes: --------- - Failed to process included configuration - dnskey_ttl policy option in the configuration has no effect on DNSKEY TTL - Corner case journal fixes (huge changesets, OpenWRT operation) - Confusing event timestamps in knotc zone-status output - NSEC/NSEC3 bitmap not updated for CDS/CDNSKEY - CDS/CDNSKEY RRSIG not updated Knot DNS 2.5.1 (2017-06-07) =========================== Bugfixes: --------- - pykeymgr no longer crash on empty json files in the KASP DB directory - pykeymgr no longer imports keys in the "removed" state - Imported keys in the "removed" state no longer makes knotd to crash - Including an empty configuration directory no longer makes knotd to crash - pykeymgr is distributed and installed to the distribution tarball Knot DNS 2.5.0 (2017-06-05) =========================== Features: --------- - KASP database switched from JSON files to LMDB database - KSK rollover support using CDNSKEY and CDS in the automatic DNSSEC signing - Dynamic module loading support with proper module API - Journal can store full zone contents (not only differences) - Zone freeze/thaw support - Updated knotc zone-status output with optional column filters - New '[no]crypto' option in kdig - New keymgr implementation reflecting KASP database changes - New pykeymgr for JSON-based KASP database migration - Removed obsolete knot1to2 utility Improvements: ------------- - Added libidn2 support to kdig (with libidn fallback) - Maximum timer database switched from configure to the server configuration Knot DNS 2.4.4 (2017-06-05) =========================== Improvements: ------------- - Improved error handling in kjournalprint Bugfixes: --------- - Zone flush not replanned upon unsuccessful flush - Journal inconsistency after deleting deleted zone - Zone events not rescheduled upon server reload (Thanks to Mark Warren) - Unreliable LMDB mapsize detection in kjournalprint - Some minor issues found by AddressSanitizer Knot DNS 2.4.3 (2017-04-11) =========================== Improvements: ------------- - New 'journal-db-mode' optimization configuration option - The default TSIG algorithm for utilities input is HMAC-SHA256 - Implemented sensible default EDNS(0) padding policy (Thanks to D. K. Gillmor) - Added some more semantic checks on the knotc configuration operations Bugfixes: --------- - Missing 'zone' keyword in the YAML output - Missing trailing dot in the keymgr DS owner output - Journal logs 'invalid parameter' in several cases - Some minor journal-related problems Knot DNS 2.4.2 (2017-03-23) =========================== Features: --------- - Zscanner can store record comments placed on the same line - Knotc status extension with version, configure, and workers parameters Improvements: ------------- - Significant incoming XFR speed-up in the case of many zones Bugfixes: --------- - Double OPT RR insertion when a global module returns KNOT_STATE_FAIL - User-driven zscanner parsing logic inconsistency - Lower serial at master doesn't trigger any errors - Queries with too long DNAME substitution do not return YXDOMAIN response - Incorrect elapsed time in the DDNS log - Failed to process forwarded DDNS request with TSIG- configuration checking was fixed to be compatible with Knot 2.4.x- new upstream release 2.4.1 replaces old 1.6.x series which is not supported - configuration should be upgraded automatically using knot1to2 tool - make sure you reviewed the new configuration in /etc/knot directory!- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- new upstream release: + fix: False positive semantic-check warning about invalid bitmap in NSEC + fix: Unnecessary SOA queries upon notify with up to date serial + fix: Timers for expired zones are reset on reload + fix: Zone doesn't expire when the server is down + fix: Failed to handle keys with duplicate keytags + fix: Per zone module and global module insconsistency + fix: Obsolete online signing module configuration + fix: Malformed output from kjournalprint + fix: Redundant SO_REUSEPORT activation on the TCP socket + fix: Failed to use higher number of background workers + improvement: Lower memory consumption with qp-trie + improvement: Zone events and zone timers improvements + improvement: Print all zone names in the FQDN format + improvement: Simplified query module interface + improvement: Shared TCP connection between SOA query and transfer + improvement: Response Rate Limiting as a module with statistics support + improvement: Key filters in keymgr + features: New unified LMDB-based zone journal + features: Server statistics support + features: New statistics module for traffic measuring + features: Automatic deletion of retired DNSSEC keys + features: New control logging category- new upstream release: + fix: double free when failed to apply zone journal + fix: zone bootstrap retry interval not preserved upon zone reload + fix: DNSSEC related records not flushed if not signed + fix: false semantic checks warning about incorrect type in NSEC bitmap + fix: memory leak in kzonecheck + improvement: all zone names are fully-qualified in log + features: new kjournalprint utility- new upstream release: + fix: missing glue in some responses + fix: knsupdate prompt printing on non-terminal + fix: configuration policy item names in documentation + fix: segfault on OS X Sierra + fix: incorrect %s expansion for the root zone + fix: refresh not existing slave zone after restart + fix: immediate zone refresh upon restart if refresh already scheduled + fix: early zone transfer after restart if transfer already scheduled + fix: not ignoring empty non-terminal parents during delegation lookup + fix: CD bit clearing in responses + fix: compilation error on GNU/kFreeBSD + fix: server crash after double zone-commit if journal error + improvement: significant speed-up of conf-commit and conf-diff operations + improvement: new EDNS Client Subnet API + improvement: better semantic-checks error messages + improvement: speed-up of knotc if control operation and known socket + improvement: zone purge operation purges also zone timers + feature: print TLS certificate hierarchy in kdig verbose mode + feature: new +subnet alias for +client + feature: new mod-whoami and mod-noudp modules + feature: new zone-purge control command + feature: new log-queries and log-responses options for mod-dnstap + feature: simple modules don't require empty configuration section + feature: new zone journal path configuration option + feature: new timeout configuration option for module dnsproxy- fix post-installation scriptlet (RHBZ #1370939)- endian independent DNS cookies (fixes build on ppc64 and s390x)- new upstream release: + fix: No wildcard expansion below empty non-terminal for NSEC signed zone + fix: Don't ignore non-existing records to be removed in IXFR + fix: Fix kdig IXFR response processing if the transfer content is empty + fix: Avoid multiple loads of the same PKCS #11 module + improvement: Refactored semantic checks and better error messages + improvement: Set TC flag in delegation only if mandatory glue doesn't fit the response + improvement: Separate EDNS(0) payload size configuration for IPv4 and IPv6 + feature: Zone size limit restriction for DDNS, AXFR, and IXFR (CVE-2016-6171)- new upstream release: + fix: Transfer of a huge rrset goes into an infinite loop + fix: Huge response over TCP contains useless TC bit instead of SERVFAIL + fix: Failed to build utilities with disabled daemon + fix: Memory leaks during keys removal + fix: Rough TSIG packet reservation causes early truncation + fix: Minor out-of-bounds string termination write in rrset dump + fix: Server crash during stop if failed to open timers DB + fix: Failed to compile on OS X older than Sierra + fix: Poor minimum UDP-max-size configuration check + fix: Failed to receive one-record-per-message IXFR-style AXFR + fix: Kdig timeouts when receiving RCODE != NOERROR on subsequent transfer message + improvement: Speed-up of rdata addition into a huge rrset + improvement: Introduce check of minumum timeout for next refresh + improvement: Dnsproxy module can forward all queries without local resolving- new upstream release: + improvement: Log change of the zone serial number after IXFR transfer + improvement: Document operational impact of various RRL settings + improvement: Add support for rate-limit-slip zero + improvement: Add 'timer-db' configuration option- new upstream release: + security fix: out-of-bound read in packet parser for malformed NAPTR record + fix: systemd startup notifications- new upstream release: + fix: don't load expired zones on reload and startup + fix: remove race condition in scheduling causing delaying of events + fix: NSEC proof construction in zones with many delegations + fix: TC flag setting in RRL slipped answers + fix: disable domain name compression for root label + fix: check if executed under systemd before using journald log sink + feature: write persistent timers on server shutdown for better performance + feature: support time unit specification for 'max-conn-idle', 'max-conn-handshake', 'max-conn-reply', and 'notify-timeout' config options + feature: add 'request-edns-config' config option- new upstream release: + fix: lost NOTIFY message if received during zone transfer + fix: kdig, record correct dnstap SocketProtocol when retrying over TCP + fix: kdig, hide TSIG section with +noall + fix: do not set AA flag for AXFR/IXFR queries + feature: new configuration format in YAML, binary store im LMDB + feature: DNSSEC, separate library, switch to GnuTLS, new utilities + feature: DNSSEC, basic KASP support (generate initial keys, ZSK rollover) + feature: zone parser, split long TXT/SPF strings into multiple strings + feature: kdig, add generic dump style option (+generic) + feature: try all master servers on failure in multi-master environment + feature: improved remotes and ACLs (multiple addresses, multiple keys) + feature: basic support for zone file patterns (%s to substitute zone name) + improvement: do not write class for SOA record (unified with other RR types) + improvement: do not write master server address into the zone file + documentation: manual pages also in HTML and PDF format- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Rebuilt for nettle soname bump- fix BuildRequires for systemd integration- new upstream pre-release version: + DNSSEC: switch from OpenSSL to GnuTLS + DNSSEC: initial support for KASP - split package into subpackages - add documentation building - restart daemon on updated3.2.10-1.el73.2.10-1.el7geoip.so/usr/lib64/knot/modules-3.2/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericcpioxz2x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=8b6ddc7305fafafd557d1c92e4f4bcce4f88b4ab, strippedR R RRR RRR RRRRRRRR RRhttps://bugz.fedoraproject.org/knot?`7zXZ !#,jH] b2u y-iSqlG 3H⇿ OUTt- jtA6d?ƮcbuX6*y ǒuǶM4(r Ef][C}" @+5+یU* ;ǚUK$F*[DUʢgCDׯióHlj0Ρn)նyU2mU6 Zz@>Uև 1 z6 y-B*hxNr$$R#>bVe%NCQz ,LBrWM9[MIoE)o8B0r/N'T7\yR!oSO[lf3U~M \PnSt~㐑2s]v< /|;O_M):aAȳ\3J5h-7=`n6]DXXzz<4Lq0pMY;*Z24f :0T:uٿ$5oo2~fh֟6ŢG%R["MKAB={ԔfƍD#k(պPAow`9*MxGeXL6X.`|h]5iF7C=uw#ΌAO؏'*Rw1,P夈ٶpJPm1炾!V?nK,?4,edZL&SYru2rȘ+2I_Ԇ"֫pa)}7fȸCosڬHwp "1m9N5g%Yk `2YƬ^y8ï /Wxn$7I=)m&BJ*'VeK8Ls[xRvcwg} 8-rhN!_V2'ۍ0xq0-fO4x&U`}|0dWJyUck=>F J쬮ūGtXZj"g5C.񀔓n ޝML'p{nRv^vxmimNQ"[563;~σgA` "IJW^ޛH2^H7M%5똀q{^Hz""bG5(.˄ܩH*R_gHlě⎥%pM/i'pY)˴77mn1u,AxEOhGҫDZ i;VU<?˹|]BPpa$~U*dp`k}bh 37uoЗ(݇!+:ɪ z,:ˬH1>FDM."AB-s=ۦE98+siD(& Iny,;، P1(B8b@{ ۣYr ǚ TI7RэNUD}.vtr%]H0y0l&J*=t扤ğ ɘ@ϸj .C;ra"~<4vOCd9AE7Jr> ۡJɠ>6ɰ%\!&<$=IzNg.j .10ålJY9$}˟Ľ̛pJ?Vrlt8_X͇|/~vƠ֕=[fz4#t`Jk[t3p2hBL/X2P̫{s:~2ܿ#u mZ6u/ | ly$qx[e| "  2,W̌&O -.>@ndzqGczzxc`@m!#vhXfpki?ys'ķo\2@˗{rxz2C{IgWrdZHܒWalol! dfQ [-n")!!3WNAE:R y:B-p5.c;⬐lYq0`aENԒۋ', 6aZ>83ۦ@:%7QiVpWf%R4*RKh )'l9NjIÆ8tT5K.qNostp^F3 Ɲ8:7n`2˩6suשd'@X-cbyX?pe߶F}~$nonͺ%ׂ f.H-LN>uKF*a>fi7fqo߶OgR$Ce?Z֌嬂LT4-xn`WB#2t1dq\-.RP 1iš=;d;]+bUm u ya`fdF) =^z5T4TϪhG*l08! [zU~~}ZY쏻 VSDB{ㄦF+ks~$,/E}}qe7 E_:"ǭuTʎ]Q#z錠M4R ;$nCu ^KYzdt+kf) PK)W 0}.bô6ԞEߖ>dpzºRʏ]UHn5%!=Y Kwiܟ5:@;ҕu/h- AY:Kk?ˎu4rFdMӭ4?*4a4[KmH|:&Fg6P.4bmtҋDYWy.6T+gVS_"e9 #`:+ke<{`X^֔,JDi`Ky$V\w7,(_cdkd}9%w j*W3@9 ō3wCf/3HI 4)"=tW6ؠw&8Qߟ0nc<H#c!'@v 6>5Z? 1fGL~封?h폫9hXFzˑKF BG Q_?} d8u1k+n11C ;`jϸ$sQJZC|R:|,f؃-8TAhv=^OGfV`oD\Sß?"{~jUyefܐ2ͬ?Z]Z|O`a'w*>ouKo[9҇{uy9cM7~dJ>i N_Hc׆M4%0 =Ye.eZ4m< H)xO眍*Vj|NoN;&WWԛ8$/qchg II ~3dhȱKj=Aި.I+aY>z7Я97bqopy]샌Zy :UsVõ쟏BL{y S˞qg@3I|.$wH΢/|V!yu!hӌ1 PG(?KdG@`1U ny (NipN WDZ\ ϱz=2T#/fF~b 7TXXY.DƢ> >=xVѳvR@$Pb%% apK9NZz):B<|ݨ~ưϓ ziGnS?&[@T4ktjtOyWE|uwzYGrJNsmA6l 09JvDE3!RK*2ܐ97O@{Cl<'ܦf矻B$``CcDdu.*L 2e,ʩV#Ԕ86S%"L6ô5fH\e9< y`:\p4;'joX\Ey'#ԔNIw@$ϳ9{BɼJA\`# &㠠drSB^Ptw`"<ʊ꧄y6|GaX/d;yz%veCrWp?wBTM'e@{|sYwO45b ?EĆ~M^N/l#8G4xieEvt^ИKl<,6fei:RxzkΪU](Y劶VZҫ;=2(_r'P}iƺBoPY.ɰu-N"d|lM Z5znPMB {HBb߯aJgj.]V Z!Za~#emq. 4C4&M2Am/`=Ƿ7 w%pDA`'Eq\㦟 ,@;ht$0\Yh9D%vyٳ,7I`S%ujWrX:,A Ot {.,yS/5(=7p\P{c!xQE:OK"n7<&^rhDw,i};{9\Y`rI":|jx P =v}5]#Y-nxC(RҡDFZ. Τ u,8+V /vl=+?kUݼwz -t­M].3ϕ.xLm&h鷫"VsuO>a ׃ڽhь7wwLZ<9BNAS? "# GE]S2Q'a+C7.qz K0EmڗW4_7n$vQi:c9ΕAƊ*)EV:|)ILBnkߞuq+Dw/1!N}6u/x. )QMqԨ2:uz^:fVmyrbp.(%oZVؘթ.1+4BiW#$\:wƀ!K Oa ,z yl(q@PbtMYnbe1o1~̘P8x>ދ8*'dYPw1훍jVsY?d jfy7n·M݀{!؋ $i׼.>Uha$3kIveXu!$dQfh( -XlpHt5J&b/~Q,YZQkYA?&2`0T4&t`G uf3kctm#|x4K}"qE*vQ4{2]eΧQzTTCFW>V7 W-z8iRTkmoFy[W,)@j';endͨX𠾴ͶLqmf.Ow$i̺Tkr N, f]L3M|;.o<6ǮHk =0٪<1х5O'yBe}]n/M.- -C#΅X{' NQi?z:B+PT]MȮ5zPR&&C6OZ+3R0'7IE`̭7LJq~(? cR<ŃzE)4P\KT0Gw\E,o/.){ѩZ#y 5CΌ׵m$݀Zj.%C'1⹺=r^rеxeY֡z"N5?AGʢ=Nd2s%Qs*Rd6͚IOg@ ɦڥ;e2ŕmtrg mUzSU\UVգ- p@ s_td kZ*i߰ɹA4M.qJ|"z+*>ɡ_v65IIConFjSI[v$ |CtBNI'<.c$~ l/ `38lwgZzPRt@kº:K5 evO*?rZ uhXr[w=]~±JU0 ץ кGPE W{*;S-6>H^ h`g~'V*,*%>'R^T1jF3 Z"P"ءIHi8rAdmA) #jjb;65[j4}NhN>s?R#YGI 6C(*I̯jN9BEoY ]FgN3$B:G̅28X\kS[.El 4|MLU#_`b{lDŰp! ^У$ঁ$s8'3QmDy}uj^ wd'ʴm@J;j^Gĉ!m.$n:D̍9ur3Fm+Jfm$O3(b6 xYo:i p>ה§Z2=a ^gZ]q[,Wr]%ecl mpQx'zˎ>󌾉Rf yzlͤN"w2oCz1'~: D=RVd'/'?\mjJbd0e鮚jqNE۩0cbaPoNN$Ӳ5PMd=l6DrC*Q-+V P@bZ("yib2/8o~=2;2u-mE8]5lG%.C*_"O,Y: v=EVU2)J\sfȃk ލQb"`ӣKz wItd bDVJ~dK`3|'DEe#͸v'*/^ QJ/n"L/K ef^;I1ыNKAKML[H;g. Mُ77&Rj^X*bC 駰qTOZܢި€ ey0:Of}'Q.҈-$F!గ5 r< mSjJ~ s37sZDFɈf(Io[ Dz]Y!Юu(\~L _0d'!!biǂce##Im+ éRk.Pk@-.ٸvIC6b뒐ΥB#yZٮ;|ßlNl zE"@/ eGF@TSCO R2] ԑǼ @/\"r3_ń~kvѾ}zqr9&Goi0ZX>C8qNGz4HMH[Io,o0Q29~Y>qnS##Xhds8S1n0"+k9F=zgSB(rI砾$\@`p)lb^ uNe pC'ܲj4rW2ʊkUkr6So(tM9nì1e4{d.6GmkKKV뫍 3d  G`[po q*|;| Qr%! FZ%,$%>LXꗶ`DΒ[0oxFH HRI.0p6~<Td\,5x"IQ+N<=*N}9% j}?IJf.D}Z$rylwx I.? R6p$I Oy6ʥ`a߆\% b`TLYp <`?w]TOQIzi 0⃄|[rG-ybht'h P{j{I* 6+vazU,2HD6In-@ʵywxW~sauf0ػUrtb$D(/mT&85aWf쓶wƿ>M@x߮YJX4G,3C+'v馋{%h !xY}[6O}Sgїs˧X?%%P8O A911ʳ ޜ̿HoQ b|*"{6JB8Ab(l70_6Ƴwҿ2 /fH)</ζn6;BLَM&O^ЀEnZXeo#ru) -`=!"lB 98C肝:qft2b?eu`".. f/$A,TH *&ݨt=Rӽ;y{wְ_Fae\꺭欣B1eZ#v>ѿm 3"o}G@NEguǵ٨Ǣe͜cΧ.W"I%Yͷc'h&]Q\nT>[^Ơ\?倏ҟ 29zbdy6w ͸j_8Nr黚@}ACm4`e/ܹ24F[8z,6DBЃL)j!Dz,* n:`h.ӰN6.NZ*^NubZ_b!}L.ݧ~=^兩zSzbA]HuS|#:ےZJD4F Ȩeo8ytjL[7"aN*i?Su -h |00A#WiD˻dfЌNdNȊH8 BHC~kf4+MreFF MpN:ri| p=\trPEUB%/bQ(¤#*n")2|5 (A!Otm^B72b.ǒ<,*?@_Pg6{o^Ԫ`K0GbA_n6oX2&;I(;Qr40fl>IeK%%bL3?1?&#E‡j. 1(BRSظ z1 ^[#a!W滩b{EH8;udO w(m$` J探n"=m}h:rM@%%a)j Owc}W(=p Jq8Rce4ũV£S2W4nJ\Cc;4|Q"#6^C&K>S?f;]vڻhs/T`REKX:0s:.&G\SV͊ȎF=fWϪͥz2CblW=pNa4ҧ=!VVK \ƸPc`|+Gq0 *sܜ筅x Q7è[ȽxҐE35TkjǵN* Ȇfh؋2$q(B .:Y-83b#LA&2cK-k˂p|WBnpɎ(ML6Eu|AUY~Gٞ6v֬ ][@qՊGNt_'..!b'3zp~53U{!!ΓDݵPFnVdj%doIlR:her~n3L'Gj%¦ή'5T=B2Ub۸PNLBOmJ_ * C2 lmF=,I tMa@"gsLu3T؛lGziC)Nj:$KRUVkd#yZ:Z;nϠ pQ\fbr +,2cN%],-C猷z-{u=x1>a~ ]=CiI RB Q RUhN\_:嫆>WQ95sM_*Q EolJ迶js DZםK8lm0eI>wsnW3/ۤ*䜰]$^8aSqBiT:Zw4N(u_Dc^DrN~Ϗr@ނ61sΟp=()?+BoYLJk!IAG٬VѸ6֥wb5m,dvAm/ʸtϗlA7v/Q+굮^賔"xR{'-g-ğ-nP[WJf--#LW!{{rW[y%zv9/;Ñ. ~ .f -iOwrPYoB WA^%1@lW_oTe_f >7(d4~Р}̾rͷfoc[8`KӫzQ2F`% SH"dp TڟhmTU'~h*84BV|P}櫏ߺ_F[ΔW-&LQ^xxBԄT*5,1vʮ%`]v37.4O#-P$|esE /%Rl6;#eooЙHNޒ`-$wIDj[. KyĘ^(&Dr1Li>R8.z^oCRw\$7ЮFjٜo<8Tp)瓎h^T8=B&H4ϣuF>wukN)=}+{h鏄Ͷކ%^ Խgan>\(R ![e uGi`zJE)Ts^$Sw@[BTe $> {r'kϜyZTh2ӝA!XT{JN0 Ǯ`pq8U$510Ee"ͥZY$J 7 c@X'w)ǿgB/g OcG ,0q&? hcPbdj{L8,Ue֋t< е}U#7hiH+"'Q}W'(S!n!~7xꁴfNq[i$)RmPVK;̔n)`_bW~*>PCyG]a& e',ySVMW!墝wόKy2\AXD=i+@݈W3 q`Q*c%YϤ'oY&ف.9jFOЫiq񤊜pƮ#+\IJ^C^Y@m nYmIu#* KYf8l)FJaҘ%PÎpST v ^-ۃ9TqXrHٿCW4j- iL@:9uea>i'}EMm)F|S_K$Mw (V~=It2挷jƱ"@ѺDpV5:lD]i-5, ,.u $Z<(@0%q2_j~%BD{Gjw]:& /atg}*L`j]eq-$x] #~s:OQ_?C,~Jη܇#pOg7ۋy26subUN Շ O`=Nf)_bOs뢋6w9!SVBUsϤ&QPTh8./'dGl|l+nM#2OZ?bt!>!Qml*Ǜβ['Ɋ3ǿC`+xAY#pVNjWW jm #ȯ+y=4i):SO/pIEfKfyR`&QK?7:Eu=R&Mw-y+ >JcP\5}f۵9 nDtū-OwW;Xy؆t yk$|WEs \;EZyud =9ritHIjJ_R&Īt&hNn"1-oԆ B%߬@qYo##*<>01ǪBxWQѳHK$"y{M1C?RD[Ts}ѝ׼>f9+dٓwOcV>R,4eK_>ũ87a%s~Cw͉P@q~9cgDռ\+ϋajY6ƚ-?;3bd , #\0KmVĿg2ؾe*iУGNr&Jn|x'SLv+q/WY3%RCsOC s+ug RM7[i(#Tn:@sgaAz$8O*9eX P*ɱ3*ԿwÚ'+'N~FXcX,ծ= g]K0v>)J7@sya 'hO޿嫍5`[EW8-l+%;wo0QwE ARl97 T9k+BH,@Ca, 2(6rX)ct&=9@b&;2*sdh&Sa>$=9dRNKf\-ȭ;f dlFWS:)$A<1{ɞ  )f0LU{zÏɋHv! Ow'?DBx 牗Fv0?N0OACE{"~Oଛ\d&*4rEkp9|j嘦ڻE@Pzr f׈~X#10e$CU.۞ȍJQfAREHT.^"PB|+<︳P |ak53ϜݽO8g\Gf_C? c1X"Qq/vQTv,[&*`%545':Y^伣3U]ž2D,Z3*H5ODI|9$h2ڽ/$F%bpV~uCPjWIi t^Mʰu.yoT4ߠ'VCcɕQP/.zDh60 f\/C5h_ps6,L˚ϕziJ̹Қw3` h Ν/ <@IvT#$$b(+xL"{+S#%.gj*@?fPp#}R߽ZLM`]6}x/DfQ-- w: Kync2AJ2QK&I4pW3QO&[QCMTq)Ȃm0lhnH"H#kU j1B ƐU~FZv4ezH 7 ѭsV6oT c=} k\Ti8Kw"!cR[-ɬ9+D{B~+O1}).mȹ]{D>3OEDz$S3U(Ӊ>F"3Ҽba(3Oϋ|.j^y_%iQ`Od;+H1^ +۾@!{R,ST>509!/'SNR=}m}ެ?<Q/=xHLtq _~谷Qmu T "Y}wWn3Y⡥ qT.GDhTd'_/7hq?:~KrbD 80˥OtUز+ȄI+QEN$pr ;(1 ؃2ۂٗm ˊK #~wc`h^TyC#x3)B7IN:HX|&" SL /IA[q}SqtDXbu*<9^M?=ӑ8 ,jA@uk}aAox; P=,MC!G)pq 8> X@f*@C`"(M=V#ir8z:a2R88 LZJ;sڮڥNMEStl9_LI?@Džǯ #N(x<KڭT ma.|7Kyi&ijtw0e5(/Ub5 N?r^^AHϻ:tܞ&o(b!bvDU˿Msىl? \vj7#*;fDe%h~Z1@by["He8˼s{w;Ɯ ^7\ڽ}mdȘ?*هeqy2uIF= .[Q5.<. -Vh%"1Š RU Ui^+X2h&ßIڕ+y&Q2D4PV:luc>7MRB"~0]OA*9 i+r9T3&%2U!aic'Pq5 @iltÃ\#D1Ltvt6<'F7{O2hv{^F@# o@s>U]%' +4$䫡o)~FWBz`I+~70{6ssu\8jIT-{?`n&/J>\' k, ɥZ η=a<-)W!$i&k{`4M #W+koJa#yTH#+Q֭c/RP~) qD81 /u׍I8y3-rH,kI0;7M̈́*Grp+ XMDoYmƲ,g!b+$n8A`%ky mjH31QWl@:/_^SC_Bf+{GHzR F0` Ih3 iQN>ZN[&d% ݒ2Jx:#l 2aT$ gU&8M DciFH.AEiJO=dL"ru5{@&[d./?nH[B/ ӆ%LbeV!XLMJ `OOj|gݝ% *K*>;9k>LxnӆQIJ] '[dZ$\}bAr3J%54DM$Ъ6×=J#1BƯ$b"Ƴ q+s8;#4%%fO:&|B3\PkVx^ ,Ӱ2f,))lBTY3^[B-kx+o"Ӊr}o|@[7AL]I"u#gJcz9 z kAQO?IBq;'f05Ps7z yk^JJo-:`HDeu(./Hjhusώu84FIp OR}|jbޤjpaπ:$I/¼&7^;"n1/5EOpJN% w71.6iHP~W@fCU?|fn 8IZx,P()I5 "w9 wG ^O,* tebKȧ"}J)Z+a`%e'nǘ(5 S,x @g];^6#-Ɩrbz[sj\1JfH0qpZT]d41Ξɗ`TG!5 $rr'g[M4"4|4vKDtB觙]ør3\IŒdb3"+PNuKDP>ɲSeyue#T5'{>-q*Nۏl0):OXj bv P~߄b 5OOIyqeP מ\EG&xJC󑟁h!= +hQԏi@ ΏHz ذ"Ek.֢8;rjR7[T5unadvJL톥$8D'`6hJK 6h_p+sOw_A7{g*x)l 2FrHAw:[jU?h{ppP@lg)UqWh#=׏I!D^=2(Es޿wEJ­ʠ:4srˁi v+6,m8 9$q5R6C}n݅Eѭm2Y!NLI1FZ^(*;GLO-Ɋ%X!4Ǽs΢wrT::܃)\L$ g/O/-ShE0 74o8ymiSX!6Sҥ=,FSOżvm(PZ}K=}MkD i_&u<4˛;:Ao)r̓*%Gi:[P)5iC b u6í#gPmTKV&^Q76a-;]dfJ! f-^CmR?:xs`u=*biN%FEu^6wMd">:͕ B+R_ntHScݔ7W/=T ȉ`@BJa* >1?]%Xf3Y\ 9KBVbmL}AKم|HJ3:,M$iTn*HENmT7T[Exiqcr{_^|ȜokIfOGU/$|0K֥9*>uڙS>"h_ #5~:h&O_' u3+,"tS[ F>ahLdȶÀEz? yD2!"bR㽞654`8s4'TJd8`|ovus౛x:>Xd\/:{٩/\o\Y:;T XFj!/aN|̤9RRc1uf@^m=Ma37>U F޿Q[(270 ,%s \(F+rQL$nȗḾv!z L z5F+{I (+ 2>uk+!I;>mp>/-\xv۷\֬?<,UmDDC#\% ǣڇ L `)}?$nOBr%,*<E%D5S+jfvBﯹ=d^di΀w5aQT_#k;ъUxaŽ;xyei|@-Va -&n+֊(%IzIp&ຯ6 ̈{< _cھ?SV57@cxsaN=g8)"D*vB"ddb@:v*w2&1u0U4I4Vs(A?Lr'73p6 _zYg+P@P7}NR # V%SO/eJZ/q=bxhRG >AsqK " :TTÒpqjoس/q>lĉn|abx${5pkGXҬlH^HٻNCvoJ6cƈ4TuHgn1"a$"t<ͅnN ί-SH` U3t4 ~sA0$c)vZhM@gږ(epTiV- mBs)nX!^D"X SCAX7y]@ڒ}BtoB.]jM:ϖV'"8 TWpq(y? ʼ#1|'3Y?%Y_Űu*?%fnu=?H)!,\7ig":|KxlhD1<`j_jRV ) ZVC3{du6;o+GKՌ"Ufe}NSQvEyL3h ?2Ey@ !MG%[9.?cc͇t]eI݉{.21$e~{~0..$* HJ1n&;cq\+iHGn_Wsk̹r_nXVCB=JXlLhqu71!P yO"+>y1.BH^|]Aj\cU?Js:Zv]oGo.àHx"xl$}T_s|QtbP]\ƭS <3 qkQ3}*L|\sOtAt5 ~J1 Q Pk\M-ձeoGno2JSa^a{綦]:1ƚQɠt]@*ls17Lu:aRþvֲDki[#H$xNZDֹ7d/Ĕ-boSSfegO4y-By@4p?!|,Fe"!##\kTtGz/~x_0s6$|㍣qqonpo deϦ*n [0o(x.9,$>ӳhnީ]G3nK6\rV_Iwˊ^]-|1M@=@Y,_Sq2~Fgvn]]O/^0ZU,I4L&-b{Tb<]WY^K8wm;Ü Ž{{huLL>~,u w}CZu[).Dsy';T8JԄʤ2Џ'dsr_QM?2mµ̒sUHT}OK󂘇 hKP0zPF*?Dw"q0w񐍠egS3d 1Ҙ䄫(kϥO[JLy]AFڤT{Ql1|?[lg.ϴ$RID 9~=YK,t$,j~wpkMD2Q+( JEc']iغGUb>Q߃` ҿ 6<.!+@\F<&qب;Nρt9c?(V]Ƥ^0=YPI7*A)Ҍ>դ/!PqooOͭpe/H^stʦ~4tZ̷y~͠ 5J u|&;9jsN|D"}<>Sewètb8;(P%pjm,"ނp\c 4HwK7 CT| 鵤PaĤ6}ݣO" Dtb,F(3BF?Ũ\1 RF:) Nߌ*CjBEʏ1O(!Y!3)cv[Pc"AوzP3 fEBR#nhih^]C,˹ y~QAeRWAbHoc#p=s!گyRz8<㮾E?֥~fc*4>n~Jp>%DUhh;>k^ȍ.!<"mzC+Joh4umv%yw>Sl@&,a46#?/PBHrvwX~%u;ҏ@" 2#@Fq#Z%GKe)j L- [~Go^k0D܂V;wlp\6zͻv3\fg_Gk.tTA(='X? 8֒H߳~WWԍ2c̷ȁQr 1t S% "EOELMp$*_ 5dæ+IMLX%ي4kkY'<б+bV2l@EfTgq^㵠B5xP{H(9bj}z ^aB{j^JA}yMR {u ! _% 0K$vFpƮ9ν[5.wp=([aB+ʽj[O\@95b?#o>/u*YV}Mnn%= ^2ȐDi?d5?(AłƏ}I؟%vS'.B5WkL%*:{E5LJH)ۄcD0]#k![@=R6 c璃_cʿj$ߥ爏Vμ,@ bPŭju9Y)48Cm6z2BvyԳ͠{Jg>[ D[Mژ_LڋƵ/ |"/6uB-4&~ʤm.h"(6~Ąd)2ny?z/5jݣ|ŎROFzBu҃`&E o =D_dm$vzN"OO$4?&w !a ft^e%~zϺNZZ8˷ –k Oi@ω\QO^,S*ND:v.e-d︟'=RZ~_Ȍ?Jn.S'k8cP)OmԥB-|6^,ӕZ˞{MS7[s ĜWqȭTUvW|,^̌ ÊbwYa⑝)kd!'n^Ũ(Ƞܻg@?GٗFY~wa(6|F#M+=f˥-S{YZ>l 0bxݭ96<{_iL98>ꆛV݅"okA:u) J0YvI߿O[hYbsZ4vR?Oi-kl5s#/:zjs*W>|RhoMJ43JQkP1.?LAZKx* F_9Úuahz!ؚ'ݑ~/%~Bb«= 3{L9?H"2p8x dm7hk]MT^u W/1زQB*b) JDMg%Y1nHn`yFT+j=M/Wog;nWͲtd$+ i C5``VG3$f)Y=e˹ݒtHYk˃l0}$AcYh's?1S<];hS(!0.݁"X0H/%{):)NlNUOgr0R8E3e.CKHbrjRhIщPcz0GN(M l^\f.Kx B9:K(Cύ*kiY$NXD (Ȗх$59C8V>k5 pMq_@m2y6mllt ?pg:f*nbeA.[U_%n4s OSYGfҸS}:A8paW:r3' ׈'eҸ>UGlUQajf:&Aj4ٻp̳OWe[cM`AЏ%Q,w0Ud%)QpX[vIl"E{AAbϢ#ΈLj];{̅4X:oeSBBz -`JEQjG{9gR?jjRkw{]:--KHB*hA]քM1aSfZQoMޯ^f45B4ż Mte7P`Et|>no=u#\jJ@pF:FHHvF?9LEDXwբbke}GմՂ&RmNrĔș~|L\A }l4 SͯSp2"ϗ/mrZ>0l/HOD'e( ͥCC} pi"M0jqvJO ǃ҃aڸX@qfh'e2xoi<ku<˚3?xkIkRE5c&~z +]F4V' m@FШBsg=Te_9N v{-{8IF>r~NuV' ’>__|gy)Ѕ 8hX x:(BdCH7`rی%bFl[IZCgaEaOZQf %t s&OSp _SZ Wo)~t<,_1l |2W ATZ !sGMLb+ɗoKg8P^ Ξ] Dt*I`jwt}G&NJگ-Zwcr%2 K=T"$Pb`85ל3ys*Q`@KU!3َ@lIJ8ڱ}ˁXs@MW)CGmdJJW}4Y3R(fN-& R{a{ 0<ԈnV Vo< u`5[yōu9*LK l;Б++ğ)T<1MUs~ nKަTQAQv=JC̎}c: 4s~p"$8]KGn־%rnyYf qG'MG ;MfxcnrH._TcI?DDaUZBkJS)(-6/% V+0HA,:6x* uFQv5+_ ~Dе? #@fY*Mn\p8M!Ph·I")<~t1ÂONz^w3Gmx&dFlJn9U%O Trט_\U 1P?y8b JB 4Y;|`"݉jۄHd1!7\x4Fv-eWX;\qDdjLkK-K HR}kZ sCP#gi%Qqi\q|Lnu0vs~~r}Eڬj)է韣( ^j12Kd;tY]-jjD),ƀ8R:4:y2O !(g1q0 Kjm 瘡d6`1(%?>Gz:;}5-_".Tu_?}|f;-%җ$t@3D*jccަuj [OUe?č 4N;IW $KW{nAAB!OşX.{Ln;\Ȧ UNnҥ!)1RB17+"qt)!vؾ&'!-m!?94@$L,L{ %VT2͖OO}Ñ.T)l参}G[Űm6N8leYiœXTˢ r_^CP)\G4ͫ %UT?7%Ok!SIc c Kj_# ]ܨSܒ?uS3 0*s' U\8 C5K 4WIY.Q SZ͋ 傫]m}z<8J'B[Ip|~4e` UsqQGgϧhŒ77˖SS!a[)9?+»78s;[&$-g\W6AXmEC hd&;u;8 T*9֨p6؛a0Wb*IdK#DD6YCౄ{;~,zFJBJ;}!=lgq=t _K)߳d2<"OnC;+cjWH4uqmۑԪ RjEYFVҒ,kV b.bc!ǐ+^t g4/1<]A;Kك-4͇\3Dzc ,4T%">.ͩYSR|݊pj#[2;Ƕ#H̀sFV)(,-zȥ,;hLy ۑ8Kc'L^B*?JXjɾ @\"8$vv"[eH:Z%#ɱnMWqdq. $S3 ]7x*#H]B5OWWN bl Zվ O <pxδ|i 1ю5TEQ֏ս&oBܤ 7B]MzVlqb`~n53Y;rE˲/S@`6^RmfLd'ҝ $%;zjO$/ !}!8?FCh vh]Yt8b7-M_/E<&|SܸJNJ8M0!E[6ڪRKg@#Ƴ c\r)t.Nu.ߺ Z>ev].SXCg^1eh#jE"x d.rk#2eEE6,g2"IKQ3}޲DuNQg04eѱvՌq}bՕtuYȫ%Å~v"io澯QS9&' y4\D&l񎟃[,[;ʱ14_"Ci^BZyyb<,@SEPG*fG{QAzv1}YIM.bFd…RcU]~ fh hW/oPPvӀgz^@`ZDξqB7B{!Ymw|P=A'BOrU^^eDP%A+K,}0B1~_O ycaJ3mϖf4 8fmfp;Err fɋNjͰ1v.׀9v^A%J,~ A엡\Ÿ@;و΂ZxT Χ y;=&:ѴEO8m(Tz9 \'5{zV]VLE Yc|3ZiY:OEƻJh׏AuyEIMW.'..vpPmZIhcOO?iCP]ebĺ+r't{XcK/7vlXJ_Y(ȋwUB+[\4wT' `nЩ!a }͝c=: bb 鋫PSZ'J}>-4m91%6xsd 2Q3ƈf{`b4U.<:w> nSaLgWĭÏϧ1P江Z֦i͋ޟ`x.PE} ok9:T@ NS.!KC[V>X٦ELX}i/)H M4Rأ(aTd䩵ʹ+mև\R֙ٞ56 D#7jYT`x^ܳa?z BA"ԑ0x]TWVZEr|`F}97_Lhdt$!R|*6Id n+\]nZ`vN {@6}ʹ+Q]S+_Bݔ!IZ"1ؘ-wKTꦓh+1;slQԹbH5H ;)µQ&GeЇVC,0C~1L!oaӠ[ue8:n; 8kY׫(~.+>VZ\Dz,5&R>yޓ/C߅Dr)0a@x8D}ԝ\"$gb00S\ltsuooeDf؊/>. Sq,ɼvÃףxٕMs\"}Ej?-戶SZGh/uoʎ>539^|\t͐Y!'F/'\\LocHABGICOu,bqV^B6(?Trac<ͅ0QUUƁRa ͞p a0V \̝u)< HbEI 6?\ / 6O;xވIodݳF?dnk0PtGq,1/*I# h"?wf`T|Š,B++P^PQ35%@ߗ26ҘKDx-\"CKk#!C/&%r:q>VƝ?ѽ;O=>c4Oν pH p4j=#!4dafǫ%ѕsMQ_Ɨ0zA#_RlqՑ?k(Tk7<hr+ )cHY63;ie2cwJ:n3$)$3z%,r}gonŵMR^+|dsTkV'swҠ >N ); q YZ