knot-module-geoip-3.2.9-1.el7> 6 6`d63!}|J^>j/5,ddk j/5,dqs&5L$Mm}BڒfwѴd]zo5E̞"LW4jxgY )y~{l:նZY'J>.`yxщ4Is 7 ZmeLz;g\'Ӏn!/K}&Ug'NݟVU Z9Ղl0%)|Jfid`tb}z$?3OphJ'7dW"F)%LD SGf(>SQA=|O1J9Hg4͘Խ&?9^ϑEYZ1K{CA1s# 'j0+\(QsMQ{t c~MM<e%֓#XSGF?8`}JX1p붩u! ̃+BBp&C35]eVy[6*k Qnp{O(AvZadb766de2d5fc5ffdfe9013f19a3903b19dcd4073!}|J^>j/5,ddk j/5,dCxw'ƻaGx3y&V: gfUjb}#̳,>r'Ƚu,nLS؜̞}6c&2,'TWicI`煱WNω2-j<Aj Ic>Y_^ i9\՟i,/U[a pz43[Z} fM?Xs6H 0}b{}h79^&J(c9=0X-QOZ_}_޽~׾#`{[]#ОfJCֿu0!0mC„V:K~ƝեAs^61R9I 9tl%췏HoC`/~)4VEk_uA_ʸ δE!*Ÿsxn3:z ƋW9Άr#L/PakBAH\/$ޖ`aN/קgh}6s̸0­KjK6{S_Y2ZAj>:o?od  : $( * , 0 q tx}((8G9G:XGGm@HmDImHXmLYmT\ml]mp^mybmdn[en`fnclnetnunvnwoxoyo oholCknot-module-geoip3.2.91.el7geoip module for Knot DNSThe package contains geoip Knot DNS module for geography-based responses.desbuildvm-x86-18.iad2.fedoraproject.orgiFedora ProjectFedora ProjectGPL-3.0-or-laterFedora ProjectUnspecifiedhttps://www.knot-dns.czlinuxx86_64ide4886d3bf8336a552e174d5f4300bde8fde0013569a5b7a52a01dd59270d01050arootrootknot-3.2.9-1.el7.src.rpmknot-module-geoipknot-module-geoip(x86-64)@@@@@@@@@@@@@@@@@   @ knotlibc.so.6()(64bit)libc.so.6(GLIBC_2.10)(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.8)(64bit)libgcc_s.so.1()(64bit)libgcc_s.so.1(GCC_3.0)(64bit)libgcc_s.so.1(GCC_3.3.1)(64bit)libmaxminddb.so.0()(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libpthread.so.0(GLIBC_2.3.2)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)rpmlib(PayloadIsXz)3.2.9-1.el73.0.4-14.6.0-14.0-15.2-14.11.3d\@d}dd.@cۥcc{h@ca @c*cobjbDF@b@aՈ@a@an@a9@aj@a @a@`t`9@`f@`c`@_H@_@_E@_m_Z@_O@^˳@^U@^^F]}@]ʞ]@]]2@]'$[ @[H@[E@ZnZZZZ}@Zz@Ze@ZNYYYXƉXX@XAXJX-W#WhWWV&@VUUUUa@UG_@T@T@Jakub Ružička - 3.2.9-1Jakub Ružička - 3.2.8-1Jakub Ružička - 3.2.7-1Jakub Ružička - 3.2.6-1Jakub Ružička - 3.2.5-1Jakub Ružička - 3.2.4-1Jakub Ružička - 3.2.3-1Jakub Ružička - 3.2.2-1Jakub Ružička - 3.2.1-1Jakub Ružička - 3.2.0-1Jakub Ružička - 3.1.8-1Jakub Ružička - 3.1.7-1Jakub Ružička - 3.1.6-1Jakub Ružička - 3.1.5-1Jakub Ružička - 3.1.4-1Jakub Ružička - 3.1.3-1Jakub Ružička - 3.1.2-1Jakub Ružička - 3.1.1-1Jakub Ružička 3.1.0-2Jakub Ružička - 3.1.0-1Jakub Ružička - 3.0.8-1Jakub Ružička - 3.0.7-1Jakub Ružička - 3.0.6-1Jakub Ružička 3.0.5-1Jakub Ružička - 3.0.4-1Jakub Ružička - 3.0.3-1Jakub Ružička - 3.0.2-1Jakub Ružička - 3.0.1-1Jakub Ružička 3.0.0-2Jakub Ružička 3.0.0-1Jakub Ružička 2.9.6-1Tomas Krizek - 2.9.5-1Tomas Krizek - 2.9.4-1Tomas Krizek - 2.9.3-1Tomas Krizek - 2.9.2-1Tomas Krizek - 2.9.1-1Tomas Krizek - 2.8.4-1Tomas Krizek - 2.8.3-1Tomas Krizek - 2.8.2-1Tomas Krizek - 2.6.9-1Fedora Release Engineering - 2.6.8-2Tomas Krizek - 2.6.8-1Tomas Krizek - 2.6.7-1Tomas Krizek - 2.6.6-1Iryna Shcherbina - 2.6.5-2Tomas Krizek - 2.6.5-1Igor Gnatenko - 2.6.4-3Fedora Release Engineering - 2.6.4-2Tomas Krizek - 2.6.4-1Petr Špaček - 2.6.1-1Petr Spacek - 2.5.3-1Petr Spacek - 2.5.3-2Petr Spacek - 2.5.3-1Petr Spacek - 2.4.1-2Petr Spacek - 2.4.1-1Fedora Release Engineering - 2.4.0-2Petr Spacek - 2.4.0-1Jan Vcelak - 2.3.3-1Jan Vcelak - 2.3.2-1Jan Vcelak - 2.3.0-3Jan Vcelak - 2.3.0-2Jan Vcelak - 2.3.0-1Jan Vcelak - 1.6.8-1Jan Vcelak 1.6.7-1Jan Vcelak 1.6.6-1Jan Vcelak 1.6.5-1Jan Vcelak 1.6.4-1Fedora Release Engineering - 1.99.1-4Kalev Lember - 1.99.1-3Jan Vcelak 1.99.1-2Jan Vcelak 1.99.1-1- Update to 3.2.9- Update to 3.2.8- Update to 3.2.7- Update to 3.2.6- Update to 3.2.5- Update to 3.2.4 - Use devtoolset-12-gcc on EPEL 7- Update to 3.2.3- Update to 3.2.2- Update to 3.2.1 - Remove patches included upstream - Update Conflicts and move to knot-libs- Update to 3.2.0 - Patch: fix tests on 32-bit platforms - Patch: revert problematic hardening of service file - Patch: revert config improvement to support EL 7 - New knot-dnssecutils subpackage - Debian compat (knot-utils vs knot-dnsutils) - Remove bundled(jquery) version as it differes between distros- Update to 3.1.8- Update to 3.1.7- Update to 3.1.6 - Use _sharedstatedir for home- Update to 3.1.5- Update to 3.1.4- Update to 3.1.3- Update to 3.1.2- Update to 3.1.1 - Enable XDP on ARM and improve XDP config macros - Remove patch included upstream- Introduce a patch to fix tests on ppc64le - Use autosetup macro to apply patches- Update to 3.1.0 - Add missing BuildRequires including new libmnl for kxdpgun - Temporarily disable XDP on ARM until issues are resolved- Update to 3.0.8 - Print failed tests during check- Update to 3.0.7- Update to 3.0.6- Update to 3.0.5 - Properly escape BASE_VERSION macro - Include module dirs in main package- Update to 3.0.4 - Move dnstap module to subpackage - Move geoip module to subpackage - Remove redundant VERSION macro- Update to 3.0.3- Update to 3.0.2- Update to 3.0.1 - Sync packaging from upstream- Rebuild- New major upstream release 3.0.0 - Sync packaging from upstream- Update to 2.9.6- new upstream release 2.9.5- new upstream release 2.9.4- new upstream release 2.9.3- new upstream release 2.9.2- New upstream release 2.9.1 - add EPEL8 compatibility - fix unsafe PGP keyring permissions- new upstream release 2.8.4- new upstream release 2.8.3- rebase to latest upstream version 2.8.2Knot DNS 2.6.9 (2018-08-14) =========================== Improvements: ------------- - Added zone wire size to zone loading log message - Added debug log message for each unsuccessful remote address operation Bugfixes: --------- - Zone not flushed after re-signing during zone load #594 - Server crashes when committing empty zone transaction - Incoming IXFR with on-slave signing sometimes leads to memory corruption #595- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_RebuildKnot DNS 2.6.8 (2018-07-10) =========================== Features: --------- - New 'import-pkcs11' command in keymgr Improvements: ------------- - Unixtime serial policy mimics Bind – increment if lower #593 Bugfixes: --------- - Creeping memory consuption upon server reload #584 - Kdig incorrectly detects QNAME if 'notify' is a prefix - Server crashes when zone sign fails #587 - CSK->KZSK rollover retires CSK early #588 - Server crashes when zone expires during outgoing multi-message transfer - Kjournalprint doesn't convert zone name argument to lower-case - Cannot switch to a previously used ksk-shared dnssec policy #589Knot DNS 2.6.7 (2018-05-17) =========================== Features: --------- - Added 'dateserial' (YYYYMMDDnn) serial policy configuration (Thanks to Wolfgang Jung) Improvements: ------------- - Trailing data indication from the packet parser (libknot) - Better configuration check for a problematical option combination Bugfixes: --------- - Incomplete configuration option item name check - Possible buffer overflow in 'knot_dname_to_str' (libknot) - Module dnsproxy doesn't preserve letter case of QNAME - Module dnsproxy duplicates OPT and TSIG in the non-fallback modeKnot DNS 2.6.6 (2018-04-11) =========================== Features: --------- - New EDNS option counters in the statistics module - New '+orphan' filter for the 'zone-purge' operation Improvements: ------------- - Reduced memory consuption of disabled statistics metrics - Some spelling fixes (Thanks to Daniel Kahn Gillmor) - Server no longer fails to start if MODULE_DIR doesn't exist - Configuration include doesn't fail if empty wildcard match - Added a configuration check for a problematical option combination Bugfixes: --------- - NSEC3 chain not re-created when SOA minimum TTL changed - Failed to start server if no template is configured - Possibly incorrect SOA serial upon changed zone reload with DNSSEC signing - Inaccurate outgoing zone transfer size in the log message - Invalid dname compression if empty question section - Missing EDNS in EMALF responses- Update Python 2 dependency declarations to new packaging standards (See https://fedoraproject.org/wiki/FinalizingFedoraSwitchtoPython3)- New upstream release 2.6.5 Knot DNS 2.6.5 (2018-02-12) =========================== Features: --------- - New 'zone-notify' command in knotc - Kdig uses '@server' as a hostname for TLS authenticaion if '+tls-ca' is set Improvements: ------------- - Better heap memory trimming for zone operations - Added proper polling for TLS operations in kdig - Configuration export uses stdout as a default output - Simplified detection of atomic operations - Added '--disable-modules' configure option - Small documentation updates Bugfixes: --------- - Zone retransfer doesn't work well if more masters configured - Kdig can leak or double free memory in corner cases - Inconsistent error outputs from dynamic configuration operations - Failed to generate documentation on OpenBSD- Escape macros in %changelog- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild- Added PGP signature verification - Added integration test - New upstream release 2.6.4 Knot DNS 2.6.4 (2018-01-02) =========================== Features: --------- - Module synthrecord allows multiple 'network' specification - New CSK handling support in keymgr Improvements: ------------- - Allowed configuration for infinite zsk lifetime - Increased performance and security of the module synthrecord - Signing changeset is stored into journal even if 'zonefile-load' is whole Bugfixes: --------- - Unintentional zone re-sign during reload if empty NSEC3 salt - Inconsistent zone names in journald structured logs - Malformed outgoing transfer for big zone with TSIG - Some minor DNSSEC-related issues Knot DNS 2.6.3 (2017-11-24) =========================== Bugfixes: --------- - Wrong detection of signing scheme rollover Knot DNS 2.6.2 (2017-11-23) =========================== Features: --------- - CSK algorithm rollover and (KSK, ZSK) <-> CSK rollover support Improvements: ------------- - Allowed explicit configuration for infinite ksk lifetime - Proper error messages instead of unclear error codes in server log - Better support for old compilers Bugfixes: --------- - Unexpected reply for DS query with an owner below a delegation point - Old dependencies in the pkg-config file- New upstream release 2.6.1 Knot DNS 2.6.1 (2017-11-02) =========================== Features: --------- - NSEC3 Opt-Out support in the DNSSEC signing - New CDS/CDNSKEY publish configuration option Improvements: ------------- - Simplified DNSSEC log message with DNSKEY details - +tls-hostname in kdig implies +tls-ca if neither +tls-ca nor +tls-pin is given - New documentation sections for DNSSEC key rollovers and shared keys - Keymgr no longer prints useless algorithm number for generated key - Kdig prints unknown RCODE in a numeric format - Better support for LLVM libFuzzer Bugfixes: --------- - Faulty DNAME semantic check if present in the zone apex and NSEC3 is used - Immediate zone flush not scheduled during the zone load event - Server crashes upon dynamic zone addition if a query module is loaded - Kdig fails to connect over TLS due to SNI is set to server IP address - Possible out-of-bounds memory access at the end of the input - TCP Fast Open enabled by default in kdig breaks TLS connection Knot DNS 2.6.0 (2017-09-29) =========================== Features: --------- - On-slave (inline) signing support - Automatic DNSSEC key algorithm rollover - Ed25519 algorithm support in DNSSEC (requires GnuTLS 3.6.0) - New 'journal-content' and 'zonefile-load' configuration options - keymgr tries to run as user/group set in the configuration - Public-only DNSSEC key import into KASP DB via keymgr - NSEC3 resalt and parent DS query events are persistent in timer DB - New processing state for a response suppression within a query module - Enabled server side TCP Fast Open if supported - TCP Fast Open support in kdig Improvements: ------------- - Better record owner compression if related to the previous rdata dname - NSEC(3) chain is no longer recomputed whole on every update - Remove inconsistent and unnecessary quoting in log files - Avoiding of overlapping key rollovers at a time - More DNSSSEC-related semantic checks - Extended timestamp format in keymgr Bugfixes: --------- - Incorrect journal free space computation causing inefficient space handling - Interface-automatic broken on Linux in the presence of asymmetric routing Knot DNS 2.5.5 (2017-09-29) =========================== Improvements: ------------- - Constant time memory comparison in the TSIG processing - Proper use of the ctype functions - Generated RRSIG records have inception time 90 minutes in the past Bugfixes: --------- - Incorrect online signature for NSEC in the case of a CNAME record - Incorrect timestamps in dnstap records - EDNS Subnet Client validation rejects valid payloads - Module configuration semantic checks are not executed - Kzonecheck segfaults with unusual inputs Knot DNS 2.5.4 (2017-08-31) =========================== Improvements: ------------- - New minimum and maximum refresh interval config options (Thanks to Manabu Sonoda) - New warning when unforced flush with disabled zone file synchronization - New 'dnskey' keymgr command - Linking with libatomic on architectures that require it (Thanks to Pierre-Olivier Mercier) - Removed 'OK' from listing keymgr command outputs - Extended journal and keymgr documentation and logging Bugfixes: --------- - Incorrect handling of specific corner-cases with zone-in-journal - The 'share' keymgr command doesn't work - Server crashes if configured with query-size and reply-size statistics options - Malformed big integer configuration values on some 32-bit platforms - Keymgr uses local time when parsing date inputs - Memory leak in kdig upon IXFR query- new upstream release WARNING: Automatic upgrade from versions 1.y.z is no longer possible. To migrate, upgrade your packages gradually or use contacts listed on https://www.knot-dns.cz/support/ (if you are in trouble).- disable dnstap on RHEL (depedencies are missing)- new upstream release WARNING: Automatic upgrade from versions 1.y.z is no longer possible. To migrate, upgrade your packages gradually or use contacts listed on https://www.knot-dns.cz/support/ (if you are in trouble). Knot DNS 2.5.3 (2017-07-14) =========================== Features: --------- - CSK rollover support for Single-Type Signing Scheme Improvements: ------------- - Allowed binding to non-local adresses for TCP (Thanks to Julian Brost!) - New documentation section for manual DNSSEC key algorithm rollover - Initial KSK also generated in the submission state - The 'ds' keymgr command with no parameter uses all KSK keys - New debug mode in kjournalprint - Updated keymgr documentation Bugfixes: --------- - Sometimes missing RRSIG by KSK in submission state. - Minor DNSSEC-related issues Knot DNS 2.5.2 (2017-06-23) =========================== Security: --------- - CVE-2017-11104: Improper TSIG validity period check can allow TSIG forgery (Thanks to Synacktiv!) Improvements: ------------- - Extended debug logging for TSIG errors - Better error message for unknown module section in the configuration - Module documentation compilation no longer depends on module configuration - Extended policy section configuration semantic checks - Improved python version compatibility in pykeymgr - Extended migration section in the documentation - Improved DNSSEC event timing on 32-bit systems - New KSK rollover start log info message - NULL qtype support in kdig Bugfixes: --------- - Failed to process included configuration - dnskey_ttl policy option in the configuration has no effect on DNSKEY TTL - Corner case journal fixes (huge changesets, OpenWRT operation) - Confusing event timestamps in knotc zone-status output - NSEC/NSEC3 bitmap not updated for CDS/CDNSKEY - CDS/CDNSKEY RRSIG not updated Knot DNS 2.5.1 (2017-06-07) =========================== Bugfixes: --------- - pykeymgr no longer crash on empty json files in the KASP DB directory - pykeymgr no longer imports keys in the "removed" state - Imported keys in the "removed" state no longer makes knotd to crash - Including an empty configuration directory no longer makes knotd to crash - pykeymgr is distributed and installed to the distribution tarball Knot DNS 2.5.0 (2017-06-05) =========================== Features: --------- - KASP database switched from JSON files to LMDB database - KSK rollover support using CDNSKEY and CDS in the automatic DNSSEC signing - Dynamic module loading support with proper module API - Journal can store full zone contents (not only differences) - Zone freeze/thaw support - Updated knotc zone-status output with optional column filters - New '[no]crypto' option in kdig - New keymgr implementation reflecting KASP database changes - New pykeymgr for JSON-based KASP database migration - Removed obsolete knot1to2 utility Improvements: ------------- - Added libidn2 support to kdig (with libidn fallback) - Maximum timer database switched from configure to the server configuration Knot DNS 2.4.4 (2017-06-05) =========================== Improvements: ------------- - Improved error handling in kjournalprint Bugfixes: --------- - Zone flush not replanned upon unsuccessful flush - Journal inconsistency after deleting deleted zone - Zone events not rescheduled upon server reload (Thanks to Mark Warren) - Unreliable LMDB mapsize detection in kjournalprint - Some minor issues found by AddressSanitizer Knot DNS 2.4.3 (2017-04-11) =========================== Improvements: ------------- - New 'journal-db-mode' optimization configuration option - The default TSIG algorithm for utilities input is HMAC-SHA256 - Implemented sensible default EDNS(0) padding policy (Thanks to D. K. Gillmor) - Added some more semantic checks on the knotc configuration operations Bugfixes: --------- - Missing 'zone' keyword in the YAML output - Missing trailing dot in the keymgr DS owner output - Journal logs 'invalid parameter' in several cases - Some minor journal-related problems Knot DNS 2.4.2 (2017-03-23) =========================== Features: --------- - Zscanner can store record comments placed on the same line - Knotc status extension with version, configure, and workers parameters Improvements: ------------- - Significant incoming XFR speed-up in the case of many zones Bugfixes: --------- - Double OPT RR insertion when a global module returns KNOT_STATE_FAIL - User-driven zscanner parsing logic inconsistency - Lower serial at master doesn't trigger any errors - Queries with too long DNAME substitution do not return YXDOMAIN response - Incorrect elapsed time in the DDNS log - Failed to process forwarded DDNS request with TSIG- configuration checking was fixed to be compatible with Knot 2.4.x- new upstream release 2.4.1 replaces old 1.6.x series which is not supported - configuration should be upgraded automatically using knot1to2 tool - make sure you reviewed the new configuration in /etc/knot directory!- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- new upstream release: + fix: False positive semantic-check warning about invalid bitmap in NSEC + fix: Unnecessary SOA queries upon notify with up to date serial + fix: Timers for expired zones are reset on reload + fix: Zone doesn't expire when the server is down + fix: Failed to handle keys with duplicate keytags + fix: Per zone module and global module insconsistency + fix: Obsolete online signing module configuration + fix: Malformed output from kjournalprint + fix: Redundant SO_REUSEPORT activation on the TCP socket + fix: Failed to use higher number of background workers + improvement: Lower memory consumption with qp-trie + improvement: Zone events and zone timers improvements + improvement: Print all zone names in the FQDN format + improvement: Simplified query module interface + improvement: Shared TCP connection between SOA query and transfer + improvement: Response Rate Limiting as a module with statistics support + improvement: Key filters in keymgr + features: New unified LMDB-based zone journal + features: Server statistics support + features: New statistics module for traffic measuring + features: Automatic deletion of retired DNSSEC keys + features: New control logging category- new upstream release: + fix: double free when failed to apply zone journal + fix: zone bootstrap retry interval not preserved upon zone reload + fix: DNSSEC related records not flushed if not signed + fix: false semantic checks warning about incorrect type in NSEC bitmap + fix: memory leak in kzonecheck + improvement: all zone names are fully-qualified in log + features: new kjournalprint utility- new upstream release: + fix: missing glue in some responses + fix: knsupdate prompt printing on non-terminal + fix: configuration policy item names in documentation + fix: segfault on OS X Sierra + fix: incorrect %s expansion for the root zone + fix: refresh not existing slave zone after restart + fix: immediate zone refresh upon restart if refresh already scheduled + fix: early zone transfer after restart if transfer already scheduled + fix: not ignoring empty non-terminal parents during delegation lookup + fix: CD bit clearing in responses + fix: compilation error on GNU/kFreeBSD + fix: server crash after double zone-commit if journal error + improvement: significant speed-up of conf-commit and conf-diff operations + improvement: new EDNS Client Subnet API + improvement: better semantic-checks error messages + improvement: speed-up of knotc if control operation and known socket + improvement: zone purge operation purges also zone timers + feature: print TLS certificate hierarchy in kdig verbose mode + feature: new +subnet alias for +client + feature: new mod-whoami and mod-noudp modules + feature: new zone-purge control command + feature: new log-queries and log-responses options for mod-dnstap + feature: simple modules don't require empty configuration section + feature: new zone journal path configuration option + feature: new timeout configuration option for module dnsproxy- fix post-installation scriptlet (RHBZ #1370939)- endian independent DNS cookies (fixes build on ppc64 and s390x)- new upstream release: + fix: No wildcard expansion below empty non-terminal for NSEC signed zone + fix: Don't ignore non-existing records to be removed in IXFR + fix: Fix kdig IXFR response processing if the transfer content is empty + fix: Avoid multiple loads of the same PKCS #11 module + improvement: Refactored semantic checks and better error messages + improvement: Set TC flag in delegation only if mandatory glue doesn't fit the response + improvement: Separate EDNS(0) payload size configuration for IPv4 and IPv6 + feature: Zone size limit restriction for DDNS, AXFR, and IXFR (CVE-2016-6171)- new upstream release: + fix: Transfer of a huge rrset goes into an infinite loop + fix: Huge response over TCP contains useless TC bit instead of SERVFAIL + fix: Failed to build utilities with disabled daemon + fix: Memory leaks during keys removal + fix: Rough TSIG packet reservation causes early truncation + fix: Minor out-of-bounds string termination write in rrset dump + fix: Server crash during stop if failed to open timers DB + fix: Failed to compile on OS X older than Sierra + fix: Poor minimum UDP-max-size configuration check + fix: Failed to receive one-record-per-message IXFR-style AXFR + fix: Kdig timeouts when receiving RCODE != NOERROR on subsequent transfer message + improvement: Speed-up of rdata addition into a huge rrset + improvement: Introduce check of minumum timeout for next refresh + improvement: Dnsproxy module can forward all queries without local resolving- new upstream release: + improvement: Log change of the zone serial number after IXFR transfer + improvement: Document operational impact of various RRL settings + improvement: Add support for rate-limit-slip zero + improvement: Add 'timer-db' configuration option- new upstream release: + security fix: out-of-bound read in packet parser for malformed NAPTR record + fix: systemd startup notifications- new upstream release: + fix: don't load expired zones on reload and startup + fix: remove race condition in scheduling causing delaying of events + fix: NSEC proof construction in zones with many delegations + fix: TC flag setting in RRL slipped answers + fix: disable domain name compression for root label + fix: check if executed under systemd before using journald log sink + feature: write persistent timers on server shutdown for better performance + feature: support time unit specification for 'max-conn-idle', 'max-conn-handshake', 'max-conn-reply', and 'notify-timeout' config options + feature: add 'request-edns-config' config option- new upstream release: + fix: lost NOTIFY message if received during zone transfer + fix: kdig, record correct dnstap SocketProtocol when retrying over TCP + fix: kdig, hide TSIG section with +noall + fix: do not set AA flag for AXFR/IXFR queries + feature: new configuration format in YAML, binary store im LMDB + feature: DNSSEC, separate library, switch to GnuTLS, new utilities + feature: DNSSEC, basic KASP support (generate initial keys, ZSK rollover) + feature: zone parser, split long TXT/SPF strings into multiple strings + feature: kdig, add generic dump style option (+generic) + feature: try all master servers on failure in multi-master environment + feature: improved remotes and ACLs (multiple addresses, multiple keys) + feature: basic support for zone file patterns (%s to substitute zone name) + improvement: do not write class for SOA record (unified with other RR types) + improvement: do not write master server address into the zone file + documentation: manual pages also in HTML and PDF format- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Rebuilt for nettle soname bump- fix BuildRequires for systemd integration- new upstream pre-release version: + DNSSEC: switch from OpenSSL to GnuTLS + DNSSEC: initial support for KASP - split package into subpackages - add documentation building - restart daemon on updated3.2.9-1.el73.2.9-1.el7geoip.so/usr/lib64/knot/modules-3.2/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericcpioxz2x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=0adb9d10235eafd926531ab4bfc8edeaa7df2c45, strippedR R RRR RRR RRRRRRRR RRhttps://bugz.fedoraproject.org/knot?`7zXZ !#,jI] b2u y-iSqkia|"Mo&=r\NQ a7;4sLMsUH8FmtQW|bo|L<03LP”'M.F~Vq4 ԇ'KbiOq' od?Nkӑ-|\2{[z[pXԲvEGNg4G./5() 8[3W[d^us0nxaLCQk۳/ TU ư>Hޠ宆>|nXS{gp48p$Qsp  Yc[8Ay^WtlJ6$(vڑTށ6)pͼ%Wb-L"_Z)XoKhOWR<ѧܞ$מhK3n}{KD.O,vmqDz׭ZL7H! ࡶ_Wb4ݩ{23L 2}8sFZ{{ =YQWXTN`a̼5a'y2}5 XRͪ&ƂBH!io5y M^{zcQeu'Fڤn'TS}x=h<[ KaEpvu 5n_hcɋ'v8W)V|xΧ@Xc\|\G 2I2 n@%6cgBC80uFWFn_Ksi= 4D)4AOբ285.p}lsֆ wNBB)R=M6r/YkR%rnd) s[ћ yqDG@f1RtBk7'sYEjT!@?Ym^qȪ@x:VQVe= e6ŗ 22ᡆ: pl`EȫXz7ѧ"Qc5I|9ĚOUH.S k(R_j[)gOA<Ic5>pw7lqhvd%|,}ZП'yesQ7ywMߜWP:?n7Pca&Jm$ nlBD g`ci M].5iY`rzM䪦J@V}YqR(o طḭ/YЅڍSb oSk no1"=WvMhf; tB͖oe)f@$gNUlFXrvH((zwvPD[,<7:gqDܞ<9EUdj8O~Ti ccG],Q jچE=Zyb#BU$)3}# ,᢫IVMɊ¤FVWcΔx: ,/3.C#pa:&q;]~bMDP!]0 f5RnIx{<"cw̝JMGsBJ^a{5B^;蕔@ wK_"{G(AFHSP򫝫sVۼl{]O,|A'rv)ƺXЭEGK+0]~13tj)_]a܄0]q@G 2x p:FC.ZsP[oMg&u3tm; '(Jw=\tE׏B7Mk{T=Fiل=[%Cp)5sxۣji$bS@&rQ?Vg p'Q2>a>S{5?C)e̵yު\ - "!)Y3$ m9*rJ .><^~dgh7 ѡ?%iX68sb/CFvSKf<&{fYiwFF9[3n!~`=:aԺvcH'^䟲e-8N9{(Tc t0fb&֔dz0/@N停뇓_AxjpMBc[~ƊQ_tWnӴ12}ܷ!i*1 YPX>O+m!OG,XVXVɶj}#<+e l-&r- `-S0I ʃm+'ʿqoNE䓃 1 ^jt#@uBnE}{(@,Dc$K-i&S-~u"y"c_W,R+EӪF^W ޗ "1- rF*Kő+ \"q ~-Ʉ2% ᝙`1CR!ia'6 ^v?uS h]#}DksxqŹbFV@hM05,!R l)蹁в*-tRH t vzfhunBGyKڄ?HcCdf7}>n,˃-I1LFLsc _Bv 0 .jk, ~L"ɼéLa0.K I& }ڻ]x\AݮD#])y~]A<)` 'I UKνx?|B۳-4e;0a!/8LA#g7hpζR&/-m}p,ȉW -it fk4P60zdN WY z߅ O_EpŞ70$PZKè|q#EˋƧ53ݟIKy0 ]`BVwv8Sqe~@ҭNJ~`0U $C)Qp#.ޫ)/'3!䑛|^#%v}5|%E"+GdYr`%^7SRݩG5Kv=G/BLa 2'v&B5 D$|.|)CVbG; .~S\aH6*xn4D#;ypI'v]|Ң 8O94AiS[TX e7R{rf w5U@6JhU M$} 1ո4gA!\M?ÝI"p;S8ߑ6q^20=WqLHp.⳸E+@Q:~jb#^DRb[O*ۼQ |MGP|jr*83NjΈ^q? :><6NpJ0a[^tBo8nlHOC!}_MMX.Bn /aobpG,5p 9&B~;3! ?zMlp [QbTťf( ^֡,]EId*"U.\Z #l:c4ynP;/]}b<8K6!`43dO!zYag5SXCg)"̈́roxFȎKbXX6[A|wlaX0C"c55.zE8E$gjimQ#bPpez2#3K)w#(dHvskxho_j((m=яioȯwIsTŌ] ), G80kq]K\6w $g8+7;u%CEY;oiħy+i3mv#-ҮB!>jh]HV;j;1qM콏z;<١NDN#&ra{A[\m ԡjc`8 {(JOHлFJNwLY8Ygj^!05CeK #F(K?@j"(T`81w `:z=<ԟ3ތBDk?bzH+ӷj#oŞ7!Oإ&e\}-5W&mur#ñ&Š6,Ր'!@5GQ[!h0 4b\jIi (g!fwM{hIM$P7HHW֒밮+FW\آiL%M,GAd72hQOBY\pp\ > 8wr/ǩ5K0p\睹7h֠ 3qrm6D-nYsx{3.`qۿT)ET53ȳwUzicYItSkHy)jvXkGe uҾ .@ڒZ~`O)qYkf͠h  W3s758@UܓՕ*Fg^<toيꡙsV6ΰy7^SI/8JͦkGsKe.EBR,2+>$M77c%[fU;.Gn͒a:}U֐&@1{u`^xNc~ޓZ@bw|Qxh8Pu>)R>,6֎M5̸uqST`xCNưyjPyd?Mo*#e giBf4ׯ)0BP{Ю^PŢ:T3c>wvVn՛?EM^~3U؉+9"tN K4Xl+VNbf2j-Mlqy-:$?^h [,;+g~ y9PGRfAe4uMu\ߢ}MϱZ 'i[,Z[mVwq 6M?4,pVݵб ̙> |״J(GцHI3=>0W5sS>7J#3pB 3Z$`Õ17W]0o5ZJ,y8Q" x2Ij|EeF_fc b$壙 nz۽^u-^VfXZ>pUWvk̳'DBNS2-@ +Vg햤}!TMsI7ƿmfIs[#Э}YG͎-XE]]~CΔd~GM.{r8:EƭNX[K vZS̚ow+v^EƳrjXٖYw<$SxW1%(5S^UƹesJj[w 1-{ Ļr161g!R>;rN͉p>9ѐ1~{yہ4iƓֺJ}8>ONeI?jشlIOsL9]4MHDI){S~[a<1$5c _b5(g/OX+H>,,Sք_oZ -cZOx͸C"05l\F吓!6]^[~D:{~C=W5멾m;KgxUw~ٰ2O p|˧Z_R@Dz#&K/GyuV%?:Pg=@X/+p>fUyye(Gr g|KXWzʍ/̷nSVd)`3S$j n/=n'T,""I +!Pޠ?dBpqu08L+L4T#Q Lnw&nqgpOfX SiY; 'IU黆3v`AR:+Q aGn2,zD!h)x+8r)H>ݲ 4xZde4r)zUJ2XPؒ iI`T<]Eb^\U|EgNI{E1eT3n"0YzdD /ŠM+GeϺC'-`f^؃>NHJ%Ε(\bOluYPi- bf?;C3NRgϥY&`$73ZB ^FmخQ '$"B8Gݱ&D1}Rr o6I)6b]b/2pt/cJÀtDž iM8Iaa9mnS]b%)|Fخ^յ?6q$AuP`LIBj]ÏwZ"UmdI;-fR;K#Ĥ$HQFBn1y虃brL ^nЇ;NLoa;tƱ^mr̲x7صC 8o4-mR%[HeS1L7EҿrQ1F۰Btr-W҈f1"zh\PH `ߢBq2Mi&j?ڽ07}l4fB~>*r]X1Qۈ\9҅Qanr8IJ3yibuyRyRkMᵋ+EMS7l%(G-,ʑHfqQi< VUv3 [%7F_S2m!r`Hs}hR?rg=].fkp0 iGѴ<lb绍czɨ0ɶ&r) 0,f!C hseoX6ԕ;s%6i(=+8k4m=|¨)h3;"h4^q56WY&*RMw%Ii%{!7 ߛcL؇l^$aGCNu}@b=8Т+ k̊#\qk{Vt9c~:I~Rզb,._Y ]}{ɻn e8Ħiƪ2nV 0wG)7L)vxTv,7 \hPk@벎:]vmb <ҿ?DiFt7uω6CZBy NE9уuܻ4V34Nt U鳘13y'#ޯ55mXgG(:D,ߊ #Z2kc#J}~WO +%A\V+7q`7Jzٕ7^8%c}c|~ *7 W<9JKT'{VfQ~KXyus!蛏:VQ{oOdgb$|uMY6D%dˡvrU< EMb RH|I䢛LIo:ƺ$\-2KAϱز6+&B}3a$76Z>/mX0 CG.܊C+:\&'M+_4[p_"TFTAΑ>za i>I~:GSl{LܮOa s(S)]?!݅^7Qb9PYnG)Oc_Tl]bgH(Xz{F,~'5ՠ0e& Byf;wϨ`J$2 z<$nzB ,Zz2m#\6XT\ɷDDb)fVRbѨ3 B9i鮁xL5?g!;݇:fJGaN?_`VEi?ikE1N#|Gl׳E?1)g徴 s'fLaJI`*\n+&n`U1(@ՕlI9dEK C1>[6uWM=L+F13a/` R:6ɚ4o̭^ ,7`N@8?ˌa!Fc_^of(|}5/F496i 3m< q/&<_lP;<ϣ%6^g9vD?!qÔoShY2Ů?VCF}̇)2M|mWx$T&I h@1r+t,R *_8yqU`‚Y|>`; _;vTFi~&exOIŃFi=տ@PHUor' hţ(k\3X#ȶV ,]m'"ON]sA1J6ZB:)vSe'';̪2@'Kv 0d%+]1&|fb)Z+do~lD!%ҞLAX HCEi59d%7PZw 55}e.)Pek[A:5eax܆xb",XiqݑT牠6 yT,O$1ƕC !O )lQ"hcg^0$? _aQ:IQ@O21Rή2(Შ=Y$Gܸ)Q``t|BaV p_+y}5$%BXKnz#rqV̢X0=2'+{j-uu+最M* rIZ͓?k_=cL.&~hqh,v : F}3qV?XɎ:Q~8m!SDbh3=YĽ>Oow }B.6)#)+n ["'2\Sׅ@ǍUIz0hN>j:vR*s@9 AE^{M51;ex6G`Ve|e_Iaަ^jhLfDe0@;$:V5R ?~|B8@FfO/hxCܺ]HL1>A~#/B #lD"o6oz){IC,Y 台t7\=`de7.&EЦLݾ N0; ba*o s*7o:S0ZHIfpsTn֔fKtdN)fuk*GC8{.\C&؝sCl=r&)4" KeR eVά?y8 Qk^Q<h`?OFC?g,9Y9 C1RjaԬ+KU999hSD!;:ä!w`vF(EeQ%+ 7W莘J@"6a,GI_fA٦b^4[0)wD%8=kI(`.lf;dH)] X*oKu/:Rֆod1W; ٗa|=(vPvx@vZ>yN8oNc Y~.{Ǔ >4 鞚@jjgDsOa$D3MtTPVºB6ď#O%+˥bAǍҠOFķeY?.A㐧<MX$@,'0xzjwzQbzP[V3 [ FA垎#,Y ?xͰ~i^lp5+EXJ<,eYJw~/ ~HH'.We71ӊۥ1q,Ow6bH4vMQZ1jQx6mX*2)r)Y37c'.m. %i[llwqJ*s, hzW$`@L87e%aM,1a` _AUDu$Vc ` l ^Nz?ffw@r80V187tm=`(a#DF*70=c"ΟS%x'%IQtѥ@+3<JZ,X"Ҥ>wpe$siz]ЪF8C (e /Ĥ =nLnU2)3Q7#Q•#F ;ő$n|k+e~/f  ]}m+ʜ>ЉN;Ͽqh _O ,s<9 Y ,PV- t]1{2O6  ݛd!󛜗\SlMX5c"Gj"P׬XtC}XZZsۤ{r_LQ(f'zt3N^mXʶWƟ/h7:)~sξZDxp~CLÉF8-R $JR )WCJoei!|8JUO%|\B=T}t_*eW%wܲ6"Mə,;&wA`%^uBE>UXҵ& =JMV̪vv_GZd*GN럔F|-~>C|Ş;N(Xp,)XQ>_zZ>X3z"t?kIP{o֦_TU]h#: hϪMxB8ނxȎM;=9w[i]lJVB=hbWEjpRk=k_r-. GыEB4"]9%^-vk%'5ВX||A=f@K/Ap. :C{UT{f+锊Lw,4xfAWKCsЌՀ{/N 'A>2ψTtnI{9OJݒn!V "uqaޝw؞M%-S;1tCahܲ!fb&̩Y|SpЊ>S,7ϡ$4MHU[_pH'ŃN9lxOIAeʦq*A8̘ HfGL ًcBCm1qqȨE&sl%]cn/uS|^^掀 w.Rм y]d{$ 4a҇CY<_)\2Jv?J!mwu9(466x*!DU r<\"D7ֲ^B2QPZlNrk=єstÿ\%M .@[B"K2YR_˂v}n)px9Sb/|9{oژLw~ MF_ R??A);CmTRu +[T>/="rS y؈UG&E3 (k:|8x,y33 k*&I m1poͻxwTE`rRBHWu,6R(ߍ>6&VP+)G<>9 OBl^Ijw~|Ũ|VSGMs{wR91sKcEyvj+iEC+hXey}FoXYo"6eۅZerM 2("7ՃG"ȭHdyR҇;p}H`lSWzKcւ>Utrq3Y"Ĩa Du1PTΣ`+Df>Ot:YovTS|҄%n.e,DZz0ťa/d~vtej;IcS kŸ%t!bʺu36XYhoz?=+%nX:B0i|4VA ¾,WnVCwFܭItEIU= OHB?yG4ycup6YNV!lCԟָ_MtM*l?N}et/[ ](oiwA:"l<0wiouﴒ͏;g4ry$k#!\y))*a]{<"4t5.\AAHV7\ =&縷}jcȏqz MyעF@$F`=P%*YsR-k8.MT9Iݍ_6!":}!ZC,oeC"`{ Sx?‘4R%FTYÏRi?rC+^,$ G-\߃c-bEV]=o^6P)nffH].GǛf#H"atɝtf[8e7mJʃǥjI3ds& K3/}Ң7lirԼٺ ZͤY?`KH <5Œ*j ~l; 2Ob(T^'L'6Ѕ+ɨ5Y4ڿ9 }(fûZ5Gqm7CyuHi7ain*9Vnh UV O Y^_3GN@Z!mKm]M/ 3ϯИAҍ%d@1>C5*H[] I15}-MQXg^)=(4$V+AJ8yJ@S) +tRh{gzmEog&"A |N6k(},~0*7'tb{nYQֶv?c'3 K(jlɃ"M!Cm.G!|@av@FpMzƩ9瞹Z/rmc#cc %N~56t\)jM;V/\˹7ޓՌ^uTƧNx>SMM`#8!2ڹq[Zjo$R@ tūc! ț%ۆ >m;?V׼CxL3Th HJӸ.ɗֹ9ӫ&U[aw&]~X1 46pL~!!6w5SJf0SVK/FWd-fFJyb|gjz;Fbjk hW:_.C 9jr}ܝ"|+_ȈlKor@*e?_HRiȡB^ř#т6f0t)i0e4P Ɉ(Ú6h"%[a#f~m9-_^ʰ'eV9$FTw K $@ntRFt<ݖc37m?əc@> W8 ~P^f&4) &MB#o]J#zd M-,WB;7iܭh .?t%+b^*zcfd>^k(ȄwW;HLwɘe*jw,1~n5IԛRŃ Q-!?S6&Ib{EnjXj~ 'J 0_VSÀ!7`P&3_|~:EV}Jć_3_ ZqS8x&ϴPl-) ~:Cfᆦ* *ԡ3n},(V+W9 e%a 82fj+(OԆA`[jkQr }>˅>U ?;G&jQl~.%k)i&>+7}9K . \|jA8&V;A W"X,}&4RXDP@g.|@{,  jWpLbN4zo`G(02q AkLJBgYGV,B?}܎+ëߟ7TBi}[HEa[vp-dQ_1^snXI>mRlgrN@'ovu9REJ\ g9*v yHL$~m%,L? ˵964Wl`wG%CT {BqC͚`t?D}X=Ũm "t=G % Bu5eY br*^?obBzkXּj"]b {y}#31u1gޡSn0\݅X(LnX3 Irm ?t3e@AigEK㠶2 NcFA=.@{y94 == _80䂏.U/h-1?;UL ְ@BNxO( xt3#ٓB~M+u?p\f 3V<j,ȵ𭍙*~HdSx%~`~Fkaѡ%R"x~XG;4:oYg:ųjQC癆/^%i ⥻P#^0i'ºnvjQk~H[' 4 ѠZM%42j)V]>0Pdh]c>S|0[٥[QlAAd+VQRZBx c:G#9ǸBbgGBHOqƪc" vID+aGoH=*ǽ̔-яk7c?'b΀86VG`iM 2y-JoP?<5ĜP1^22Q! gUpaAd˽Gr=Vk3\JЖ#_8m橖:S:R|s: JWq&2/u~8X=|oJn@:p_Ji2Nz-ciTkON!P%@=~IHӓ1 &K9?n?0,:$v>ɠ/yUgo93U+ B'tOytE.y& R(Ϝ$|3IhwlvuL<įzDe4߽{`#ȼA"h}1͒WFát5TIbBU)#.\ C8:J.ΐM PȞF֞zGJ;\_$ #zNE 󴿰Se ؏':l|/ԉx'4YAJlWD>籾-eCB* 5V:  /+/+V }@qprVe"Gl=3< uH+`D4b0Q%N:&4C;۰iC#cVr ١#8/Ee=!P{(1\;!&ώ8Y\%_Z5yڋ-H9k=  כA_ hB¿3~u3ӟX5=\_XБ65MJַ,V~/{/ ^31^>uyT,#dy" WovN%b;(@{bwqbHaJ>@V{ViEUʚOqWڐv\2s{6ObMnQ\yd3Lx gm#9VppΊe$I?6}ftA, ҏWH#yLqg,\} %^H׆9D$@we3? q񂑉iN4??Dk0"+ &ì wA&Dճ@Z  ™-@B>8 >Huf#A9 Qe΄1"'$ ^ua ˳E$QXj{^3F]/J r2鿢.iZC-: ߞ5Z_٬)vtއ.!_bNv1N,jr$+2`O9](EI]~Q+FioK/>t|[It-Q94/VX OF_+y6`ppB_m༂|}l_Fj̦fRLݖM uD-Z3BEe)/n:ũt}ٚov N:cgymf 9؏:n^QuCa8kد1=dv}LHO&Z?S]g7[pӧrFb'Sp %ɋApHJ1rAfeϿCVu9~IfGm`˂㭙f+$m sݺo ?9a*:ʆSr~"5`]xp0. 3C2%dxYhۓg}G[nUxf'` ZnsA3 дz0> wUP6o6n$3}-(|lȅ3aw7Ԕ )|:_0PFP_{Eyd*w|O}PKƯJ2w M+Z=~xs +HAU%鄤q.6\ ơ6'sF]LI/opP33AdVt$k Љ'Fn0aP_mM#A # R;(? 2U0k&ஞBic /λÈ>*r, * zܺ=7߬QFZGnK[1U,D制;xmui:,B$ XnQ).T(,AH.5^ F]Rc]w݅g/bdE>1k?"_1kJhM3`myXEt$݇ ڷ~E.r%|5x 3"/7`޺:C4&&Х?R"F#-4 i_yuڽg'"UܓLg>^"2`Z.SEMH6}~3[H4$T`:QF$۞l,*8}9W8| k'l躏 (lDNd## .͑'ҭj#`}ҝtLD;%2vRsa;eV1Q9t#[Qv]l ګdElUۂE2H1f~%{lFʏXw@%EX/8Gۓ(!E0S3``4kT z,C*˲{=Gw4Dx'a>~ Y47^]նq26kW(SJw6Iݬ߆D׳]g"Ԥ[~zvV. {&lB+m?rf 2oW ;b!'O%/_ZWew>{0NTcT+GwJx-Mj]ٕ6CuX ߄p-,D)]ּcC~ͅ~dF<h=S@C~=L<_IrQ/ g8N:/P*D=.";[aEKU76ډS&f1l찢-%hR><0l{bAw;hcRJ,k7?𚱍Lwׄ.,$ڮ?ÓD[BTKzNdÐќ^䰾'19s&dWLVžZ[U"ku#IX30t ?~%9a/ifT"JIҖX}r8 m<ɫjFF!s,?-k)s%A[I!G|CBp<_'na 6L!VcC#1u= tHM{(˼4!2VDjמ`K${6MWPW32Ep"hq8!i3,xK=ShOGRݮ9j/8g*Q1 oä-=c.o,\佒waP}F@Qb]}J9 ^&dS4B"ьk,iUZׄC 8zzN*0ȕAE&xݺaHKYFpiY|ۑmKr&פⲩh476Jze|voP8忭>)+l[xKǾz r=cF Ʌxڱ9| n4ܤiv+pD[q^;~;⮑濳ˋRK 0$HD BؼHF@ojIcu>gҮgyt2{DlMw+nsYu"R+7</5bFӔ3Ψg&!D~'P{i=* R^}gW$E WM&/! 0 y?xaMSѣJV>cG|<閨0N76Q( nJUw$ *+83MqC)P14s=g f<"j;DsP?3 UD S,DP/tq0{T9@;tV.7DxGWAz˪ID$k=sjPz k¸f0_ "B3 (Fƚx;X] LοӌvZtRO2*;\DO݉.C >DŽYW_򏡞PUC A9*1!˝X:gޥI]t遹lffyFF&Bc!eƜnowznt tbMh2&CXd/Hb)r7a`BՐ By_dO%AYW`~YoDE7Z[I<-O)dj i]I}nϫO6whՊtb5"\P).djc 1:NªϻJ5w$ |Pn V7^$mm@so6Fo鹇(O&lbvE=26E@nvqн:66J/̽/d6yCv(A`q.U&fy/n+,I[,?m,ÑR 5}@J:RvHq_ឯuKSxIxvQ5Cij+<&UfS$ˆ8ҭL< )f7![S;Q>}@R(eB{'Pڽo[HcMAsiqA1z=2F!9+jKoݏs~*u1ARa߅ѨIA _(y蹒01{AWW(~aQyui# n3ST>w8 ~!,3җE{.{H&<\N}pu<{H7 B2~ Ə^BLj@HFXl¼8w} ӝE)\6K%,ܖb#e;ҋoygF@Q!Op6k$!4;a >ۦL+8)z8RChTJ9kA2q 1ϣ1@wvt~xׂ\ތhЮb⪋Ac> Ԑ pc_xIAQK#:9'8(5(Q/$3R5.N}g?| F/a綿yيS͚b(N()^2fr\)t6U6=;_+UthB +֗$Մ8ƳEYCTfzh}Է ėڶyɋHG=RJ@SoKSO^ ƇAE$x>GvjÌbU )DȽ M8,'͌'M R?Usk0lIMMTD`"+Mh.@38* b|}\|Nt<@BԄMj ˈ[(? .p{n[|:!%'ը%U㇫iXbJjf`pvzK%@N(!4a?ɹ,8 LIy<%40ޛ$KWg~+}vZF{:q[U||Kqbȵ*cQZC`0%{UW@g )$ & yaȋm4f6PJ(4[A;,zkhL~Z1:r@J?Jf>.-;+JRUYGśQ T$&xhvazj8dBtЫh!En]xBlj#UeV<(5Eh_\Z\GfR@o{Nulr^0'aeF.*">;SбcYK>z`&MPT ;Wsj*y]Ϡ)Z>6m!D5 ں Dofa8wn?sRd2.n–]zubp_*!kO .j^j*zahAlQCu<Ø2)bPi 2w(_,0@ݪ%uљUi2jN~Fޅ."xSF9:_3ms&zqo(nW+, 1 IHX!KvzY9aذ@P=i7 OEpkZ_*(%pٛnnc֛3&ކbw5c7KE+1\hn~„`k=ER;.&!Ŏ`zp Ӷ_u (n=֠'RZܙ+2sXpЈIy$jUg a@{t?96Gn$7^{l%".9c,`xуG,7c($UT>mCV 'M1ݭx ˹L-FgU%`s\[wʡ KA1x' á Quqy (W/p vĘV(Ǐm)4 I]7Ч5*ȁzi-ouQyۘyvhfJE>bn{RZqB_6t!:Orfmq;2F.zRs(mh6u{j4o{Dq1K1'i _ jtb]wAn͒eQ(M@ph 0} xL|PSʭ^F`qO|!- $ꀤ7Lvqpq8 ȴ ^?9P_ w8')H/!Em% b++,L}FxfK,<(%(/_P('=pI,yWURb-ZYO[6Յs&}VL0$i7LvŅ"`sOSNImIYJYs0ABt{1-5B4i^vVQ=\Q`ˇuI!-.Fae`8v_g{ߍ肍 е0賹iJ1dv)ϫb_ 'Q ۔Sose׽ 6Hs<Ӭ?6ȫjz~WN(ːhbIP<_m2+XDI?Cpj*xܟY 8y3ÙFxNi{8)mMJn1okMn)ǁzCԐ쬟+U`]A2kWA6)!}MNx9kpagΚ7H a&1Znw285L]62>Uukt_)3OiȑjȤh>d@Li(R`` S>*^XLD۸(V!'6/uzg&#sagK2tc=*H._5=@F]!RXR5AG{(m515ӀFuP>LKtrwA`W\4Bs2g8 |k\%,=ybچ&]˦4(wCikyn?6afU7"R53r j)>j4$dVf 'nU~Ī/*$y K *߄%0_7mZD 98Ikt> 0܋eKآ@$7<3{mSl,*r^%x(hqJM:v9(HP7|@N.$TI,]"}QRE:ѺO 5տy{EGR, >1S^5K7 77,}P} |JEG h,-fa0#;i2 ò\AlgC`L/<,ҽd˙ T0YT֪O^$8rDN_MBnb΋ w3lizΗ/k bf+[n+-0J_QHMGd hV}Ij۔r@J?ã&0s6*ZhW/!FPDūhS\X|`ڒ,:-a.M8oTi9k 8d5*yu6r|XgFA;"t7Lf^8P+\2RH(؍oQV&"YA@bfh@jaDY6#L(lgλ# NNCy9ddxCQwGWL ᓬdb4S 02(otur7un+hTNewP)ީQU" (Q&?DMpM}fY͓ǚ3'ےvž\|r="M_$>K M9֏f[(|B!C=4zm!cT)%S͵qkb;E^n8d<ꩨEaix7ǜ/218.JH 6G.bIȯqW7oU eHmЇG7P^ bٽ<o\IcřV*0T(TsF*3&O8KnhtF)U,z4y4RQm1_H%~{?rsg]tS4ߛ^<:'JR>볾WeE-NtZ 5{gEA!I8U$Z R[dZMf̑ȣB=rn47 1&`#'{hd5 / Nv2+P5)Z=GK+YBup߻0ΘAvPNzҩ"Ku5hG  vwZɹol )ݙ@Tۚ4бGdDs"XN1UOVwT7AejN}ޫ" D\^}vObKˇ+TUٯF\g#w5"'M=GkmcO]8fS,KA$i ;YDiӺr[eUiЛsz axonޓKϢ. as0)$ 9@S o"ߢ$Eaݲ1:y?It (y :u²1îTx^M9օ= ` SnG> K WK@QJO!Imy#kܚ oژj:ܨAozX>.'JH%dyus' YUz. d6[:d>+DԕN1ށ(A絲'4I~C뿄 ̞!mIyKRm+nrz9kxʰ?J86\i#vfbJ@gJ7?Yo oE n%iZQV1iNly]4P~ ?0Dnf;Z!kH!њs) ^|q0|BEc̈Aӊ.7*Kjd"iPEu^DCA-ˏeg"丞([p_]C S&/R|;'vvj7gV!l(䪋 ~GUDiUdXIf{Ky:n uӻHJRcM1)׼mLwD"YtLv2l],Jk|:+A/><"h`U-FU,b:A=v!İnVVV @r)H$˴7l{38"4GYE%}?͓.?JT5a/IIaz=:|\+Sr`"u*89?{W@nIv.k5R-._+%oy \NK5Ǭȝ/X&6ҰbMiGm]GҀ(JJX\nT75&wx OOx:y߷rhl5uPaq.23o!#"I3";vڶv{wIؙX4$/*r ev:$@nIF^7[&J8QrC2etX:@XpWb"V7IXy-N@uZfU0ɑߪHH8}BEm.pk!Zg :ڟlaUNJvW5vbG0#Y]b3NBjt'ȊBM向 R5a|*q2DA ^zQۭxi#;f:&Be& TXFW0K~27r4͑DL$)ϟ`EҖ"Kd4$6>lfyS!e]N jWP ߙix/$ٙbPĹwq"]=ԺV =$,&=,*wy0`T6ho?yLcXJgCU;@j^DZ;A~~||SNg-C;A՘A#ODWН! iKnrfM0Fdn3Gউ!b[aAߪ/`'BGPhrD~ IH3f _25cgG6E)//c'/6TjvF,Fmuϗ=G%p&T;2Sʘ|k17}L*c.gT!=Kʈ~kn3\E*V % !xu2ԅa* z -y{Kͬ׮?tȚJJ1g79.RźM5.~,N[=7{Ny^ +HQFiI^X6 }$΅Pd]Gjх2) q\g4Wmm.qUafRthS5/-sF;d5@k "jX z8 etʴS*o5f"z$ZxVʤSVREѧgM(&9vЎ' K =;| э̔|+)*?: nѰua ^OW}f@y\މߘVA,Y~&fxr+%1fB;:Vz9*h?\s/j:._8"ҟJi"W @?wXPdlF]Y}*.gảqjNe~tIȊ#78ƃCa egJ'\~\oCBɹ%=U^K:#"릺ՑOAxj~}I~Ec뜓62Chb;DB:a)PKbAƓ:Kc潔UQ?:=`7c0lNJ#Zy#U:~+i>~HtR Yl/*tf8p["ᣣ'S2P5%Y skUyZ_g1P,}DgS^efu}u_;n2nאpox"y:߻:` 8 |N+V.eSO̕T> W9pD\@ѕ0Ta\h@ꊁYb\/ނt;Wa9:K >G+\mľ2ict$2E^*Z@:{$.L*1gZt1bzT·P΁x|Qcn,=%KS/8h\ayWB_xԆWV߶^E234`Zʽ+ duE8yӕʘo,*HMH 8O+jF㌳Nv]U(zѢ6޿A(pDd4HDB'siGD|/^8UIQۋU.}Z;6ǧ2`%kj~\c z}Ev e$WnymK.v ]N=yTBGDX N+,bCq?cܙ׭-DRNb|M c~j1)3 @ƞ]=9Waq(Ĩ