php5-suhosin-5.2.14-0.2.1<>,Lٸ/=„!%X}w>O 7Ktcol}pTZY1u73C(w+mXdPI,BeV@qlFiu?mخl0{ 5dBg63o#-Ww3S;=RQK )0J"P.p4Nk*3Ae. A;%&J)|I\P!q'a>]X&^>61?!d  2$(04BK     : <DNXt|   (8O9O: OFsGHIXY\]^bcdefklzCphp5-suhosin5.2.140.2.1PHP5 Extension ModuleSuhosin is an advanced protection system for PHP installations. It was designed to protect servers and users from known and unknown flaws in PHP applications and the PHP core. Suhosin is binary compatible to normal PHP installation, which means it is compatible to 3rd party binary extension like ZendOptimizer. Authors: -------- Stefan Esser Peter Prochaska Christopher Kunz L0kuckuk}openSUSE 11.1openSUSE"The PHP License, version 3.1. ..."; The PHP License, version 3.1.http://bugs.opensuse.orgDevelopment/Libraries/PHPhttp://www.php.netlinuxi586O``LLf02f7d72349dd21a117d8c07755769f3ff521570f95a4d4172dcf6078a28088erootrootrootrootphp5-5.2.14-0.2.1.src.rpmphp-suhosinsuhosin.sophp5-suhosinJJ@@@@@@@Jphp5rpmlib(PayloadFilesHavePrefix)rpmlib(CompressedFileNames)libc.so.6libc.so.6(GLIBC_2.0)libc.so.6(GLIBC_2.1)libc.so.6(GLIBC_2.1.3)libc.so.6(GLIBC_2.3)libc.so.6(GLIBC_2.3.4)libc.so.6(GLIBC_2.4)rpmlib(PayloadIsLzma)5.2.144.0-13.0.4-14.4.2-14.4.2.3L*@LZK]KqN@J@J/@J_@J8J+@I@ImIk0I@I@I@I@H@HH|@H"@H@G@G GZ@G@GsGaG^{G8@@Fֱ@F@FōF @FF;@FF@F@F} @FnF` @F]g@FQFP8@FHO@FDZF=@Faffected_rows on no connection causes segfault). - Fixed bug php#50680 (strtotime() does not support eighth ordinal number). - Fixed bug php#50661 (DOMDocument::loadXML does not allow UTF-16). - Fixed bug php#50657 (copy() with an empty (zero-byte) HTTP source succeeds but returns false). - Fixed bug php#50636 (MySQLi_Result sets values before calling constructor). - Fixed bug php#50632 (filter_input() does not return default value if the variable does not exist). - Fixed bug php#50576 (XML_OPTION_SKIP_TAGSTART option has no effect). - Fixed bug php#50575 (PDO_PGSQL LOBs are not compatible with PostgreSQL 8.5). - Fixed bug php#50558 (Broken object model when extending tidy). - Fixed bug php#50540 (Crash while running ldap_next_reference test cases). - Fixed bug php#50508 (compile failure: Conflicting HEADER type declarations). - Fixed bug php#50394 (Reference argument converted to value in __call). - Fixed bug php#49851 (http wrapper breaks on 1024 char long headers). - Fixed bug php#49600 (imageTTFText text shifted right). - Fixed bug php#49585 (date_format buffer not long enough for >4 digit years). - Fixed bug php#49463 (setAttributeNS fails setting default namespace). - Fixed bug php#48667 (Implementing Iterator and IteratorAggregate). - Fixed bug php#48590 (SoapClient does not honor max_redirects). - Fixed bug php#48190 (Content-type parameter "boundary" is not case-insensitive in HTTP uploads). - Fixed bug php#47601 (defined() requires class to exist when testing for class constants). - Fixed bug php#47409 (extract() problem with array containing word "this"). - Fixed bug php#47002 (Field truncation when reading from dbase dbs with more then 1024 fields). - Fixed bug php#45599 (strip_tags() truncates rest of string with invalid attribute). - Fixed bug php#44827 (define() allows :: in constant names). - depracated really-with-libedit.patch, bnc-518300.patch,php5-alignment.patch, arrayobject-mess.patch, BNC-457056_2.patch CVE-2008-5557.patch, CVE-2008-5498.patch, CVE-2008-2829.patch, CVE-2009-4017.patch, CVE-2009-2626.patch, CVE-2009-2687.patch, CVE-2009-0754.patch, CVE-2009-1271.patch, CVE-2009-1272.patch, CVE-2009-3291.patch, CVE-2009-3292.patch, CVE-2009-3293.patch, CVE-2008-5624.patch, CVE-2008-5625.patch, CVE-2008-5814.patch, CVE-2009-3546.patch, CVE-2009-4142.patch, - reworked bnc-435595.patch (change grabbed from php 5.3.2) - added patch php5-session.patch to fix build - fix CVE-2010-0397 [bnc#588975]- fix CVE-2008-5624, CVE-2008-5625, CVE-2008-5814 [bnc#568527] - fix CVE-2009-3546 [bnc#547525] - fix CVE-2009-4142 [bnc#565924] - fix CVE-2009-2626,,CVE-2009-4017 [bnc#557157]- VUL-0: php5: 5.2.11 release [bnc#540242] - L3: Problem with xmlparse in PHP5- VUL-1: php5: exif module denial of service [bnc#513080] - PHP read_exif_data() only returns the first letter of UTF-16 strings [bnc#518300]- PHP5: json_decode not working correctly after update [bnc#521033]- fix CVE-2009-1271, CVE-2009-1272 [bnc#493122]- missing timezone hard dependency [bnc#486359]- VUL-0: php5: memory disclosure by imagerotate() [bnc#480850] - VUL-0: php5: mbstring.func_overload set in .htaccess becomes global [bnc#471419]- libxml version detection of previous fix will never work. 11.1 version is 2.7.2 not 2.7.3 and presence of XML_PARSE_OLDSAX enumeration value cannot be tested with defined()..- VUL-0: php: buffer overflow in ext/mbstring [BNC#462499] - VUL-0: php5: dir traversal vulnerability in ZipArchive [BNC#464048] - PHP5: ext/xml is broken due to libxml2 2.7.x changes [BNC#457056] * Note that this MUST be submitted AFTER libxml2 update- fix ext/imap buffer overflows, old API used [#BNC402665]- QA Results fixed * array_pad "succeeds" when padding with large negative number [BNC#435595]- QA Results: fix PPC64 regression of gd module [BNC#364518]- update system timezone support patch to r4 * added "System/Localtime" tzname which uses /etc/localtime- Using the ArrayObject class leaks and corrupt memory, causing a really nasty undefined behaviour in userspace code, whatever can happend due to corruption of the symbol table. see http://bugs.php.net/bug.php?id=46222 where martian variables get created as example.- update suhosin to version 0.9.27 * Fixed problem with suhosin.perdir Thanks to Hosteurope for tracking this down * Fixed problems with ext/uploadprogress Reported by: Christian Stocker * Added suhosin.srand.ignore and suhosin.mt_srand.ignore (default: on) * Modified rand()/srand() to use the Mersenne Twister algorithm with separate state * Added better internal seeding of rand() and mt_rand()- do not restart apache after update of mod_php5 [BNC#419508]- Don't try to replace libtool. - Fix alignment violation. - Don't define feature test macros after system headers.- update to PHP 5.2.6 * Fixed possible stack buffer overflow in the FastCGI SAPI identified by Andrei Nigmatulin. * Fixed integer overflow in printf() identified by Maksymilian Aciemowicz. * Fixed security issue detailed in CVE-2008-0599 identified by Ryan Permeh. * Fixed a safe_mode bypass in cURL identified by Maksymilian Arciemowicz. * Properly address incomplete multibyte chars inside escapeshellcmd() identified by Stefan Esser. * Fixed two possible crashes inside the posix extension. * Fixed bug #44069 (Huge memory usage with concatenation using . instead of .=) * Fixed bug #44141 (private parent constructor callable through static function). * Fixed bug #43589 (a possible infinite loop in bz2_filter.c). * Fixed bug #43450 (Memory leak on some functions with implicit object __toString() call). * Fixed bug #43201 (Crash on using uninitialized vals and __get/__set). * Fixed bug #42978 (mismatch between number of bound params and values causes a crash in pdo_pgsql). * Fixed bug #42937 (__call() method not invoked when methods are called on parent from child class). * Fixed bug #42736 (xmlrpc_server_call_method() crashes). * Fixed bug #42369 (Implicit conversion to string leaks memory). * Fixed bug #41562 (SimpleXML memory issue). * Fixed bug #43606 (define missing depencies of the exif extension). (crrodriguez at suse dot de) * Fixed bug #43498 (file_exists() on a proftpd server got SIZE not allowed in ASCII mode). (Ilia, crrodriguez at suse dot de) * Over 120 bug fixes.- update suhosin extension to version 0.9.23 - Fixed suhosin extension now compiles with snapshots of PHP 5.3 - Fixed crypt() behaves like normal again when there is no salt supplied - wrong Obsoletes causes upgrade trouble [bnc #355618]- use %%_with_ming and %%_with_qdbm instead of %%opensuse_bs, enables building in the bs in other projects than server:php (bnc#357917)- Try patch recently published by Redhat that allows PHP to use the system timezone database instead of the bundled one.- Do not hard require php5-timezonedb, instead provide a capability php(tzdatabase) = builtin_tz_ver so it gets installed via rpm Supplements only when needed.- PHP is leaking file descriptors badly on relative includes (php-5.2.5-fdleak.patch)- suhosin 0.9.22 - Fixed function_exists() now checks the Suhosin permissions - Fixed crypt() salt no longer uses Blowfish by default - Fixed .htaccess/perdir support - Fixed compilation problem on OS/X - Added protection against some attacks through _SERVER variables - Added suhosin.server.strip and suhosin.server.encode- use /dev/urandom for generating session-IDs [#337005] - L3: PHP: Venezuela Time Zone Update starting date changed to December 9 [#345548]- update to PHP 5.2.5 * Fixed dl() to only accept filenames. reported by Laurent Gaffie. * Fixed dl() to limit argument size to MAXPATHLEN (CVE-2007-4887). * Fixed htmlentities/htmlspecialchars not to accept partial multibyte sequences. * Fixed possible triggering of buffer overflows inside glibc implementations of the fnmatch(), setlocale() and glob() functions. Reported by Laurent Gaffie. * Fixed "mail.force_extra_parameters" php.ini directive not to be modifiable in .htaccess due to the security implications reported by SecurityReason. * Fixed bug #42869 (automatic session id insertion adds sessions id to non-local forms). * Fixed bug #41561 (Values set with php_admin_* in httpd.conf can be overwritten with ini_set()). * Upgraded PCRE to version 7.3 (Nuno) * Added optional parameter $provide_object to debug_backtrace(). (Sebastian) * Added alpha support for imagefilter() IMG_FILTER_COLORIZE. (Pierre) * Added ability to control memory consumption between request using ZEND_MM_COMPACT environment variable. (Dmitry) * Improved speed of array_intersect_key(), array_intersect_assoc(), array_uintersect_assoc(), array_diff_key(), array_diff_assoc() and array_udiff_assoc(). (Dmitry) * Fixed move_uploaded_file() to always set file permissions of resulting file according to UMASK. (Andrew Sitnikov) * Fixed possible crash in ext/soap because of uninitialized value. (Zdash Urf) * Fixed regression in glob() when enforcing safe_mode/open_basedir checks on paths containing '*'. (Ilia) * Fixed PDO crash when driver returns empty LOB stream. (Stas) * Fixed iconv_*() functions to limit argument sizes as workaround to libc bug (CVE-2007-4783, CVE-2007-4840 by Laurent Gaffie). (Christian Hoffmann, Stas) * Fixed missing brackets leading to build warning and error in the log. Win32 code. (Andrey) * Fixed leaks with multiple connects on one mysqli object. (Andrey) * Fixed imagerectangle regression with 1x1 rectangle (libgd #106). (Pierre) * Fixed bug #43196 (array_intersect_assoc() crashes with non-array input). (Jani) * Fixed bug #43139 (PDO ignores ATTR_DEFAULT_FETCH_MODE in some cases with fetchAll()). (Ilia) * Fixed bug #43137 (rmdir() and rename() do not clear statcache). (Jani) * Fixed bug #43130 (Bound parameters cannot have - in their name). (Ilia) * Fixed bug #43099 (XMLWriter::endElement() does not check # of params). (Ilia) * Fixed bug #43020 (Warning message is missing with shuffle() and more than one argument). (Scott) * Fixed bug #42976 (Crash when constructor for newInstance() or newInstanceArgs() fails) (Ilia) * Fixed bug #42917 (PDO::FETCH_KEY_PAIR doesn't work with setFetchMode). (Ilia) * Fixed bug #42890 (Constant "LIST" defined by mysqlclient and c-client). (Andrey) * Fixed bug #42818 ($foo = clone(array()); leaks memory). (Dmitry) * Fixed bug #42817 (clone() on a non-object does not result in a fatal error). (Ilia) * Fixed bug #42785 (json_encode() formats doubles according to locale rather then following standard syntax). (Ilia) * Fixed bug #42783 (pg_insert() does not accept an empty list for insertion). (Ilia) * Fixed bug #42773 (WSDL error causes HTTP 500 Response). (Dmitry) * Fixed bug #42772 (Storing $this in a static var fails while handling a cast to string). (Dmitry) * Fixed bug #42767 (highlight_string() truncates trailing comment). (Ilia) * Fixed bug #42739 (mkdir() doesn't like a trailing slash when safe_mode is enabled). (Ilia) * Fixed bug #42703 (Exception raised in an iterator::current() causes segfault in FilterIterator) (Marcus) * Fixed bug #42699 (PHP_SELF duplicates path). (Dmitry) * Fixed bug #42654 (RecursiveIteratorIterator modifies only part of leaves) (Marcus) * Fixed bug #42643 (CLI segfaults if using ATTR_PERSISTENT). (Ilia) * Fixed bug #42637 (SoapFault : Only http and https are allowed). (Bill Moran) * Fixed bug #42627 (bz2 extension fails to build with -fno-common). (dolecek at netbsd dot org) * Fixed bug #42596 (session.save_path MODE option does not work). (Ilia) * Fixed bug #42590 (Make the engine recognize \v and \f escape sequences). (Ilia) * Fixed bug #42587 (behavior change regarding symlinked .php files). (Dmitry) * Fixed bug #42579 (apache_reset_timeout() does not exist). (Jani) * Fixed bug #42549 (ext/mysql failed to compile with libmysql 3.23). (Scott) * Fixed bug #42523 (PHP_SELF duplicates path). (Dmitry) * Fixed bug #42512 (ip2long('255.255.255.255') should return 4294967295 on 64-bit PHP). (Derick) * Fixed bug #42506 (php_pgsql_convert() timezone parse bug) (nonunnet at gmail dot com, Ilia) * Fixed bug #42462 (Segmentation when trying to set an attribute in a DOMElement). (Rob) * Fixed bug #42453 (CGI SAPI does not shut down cleanly with -i/-m/-v cmdline options). (Dmitry) * Fixed bug #42452 (PDO classes do not expose Reflection API information). (Hannes) * Fixed bug #42468 (Write lock on file_get_contents fails when using a compression stream). (Ilia) * Fixed bug #42488 (SoapServer reports an encoding error and the error itself breaks). (Dmitry) * Fixed bug #42378 (mysqli_stmt_bind_result memory exhaustion). (Andrey) * Fixed bug #42359 (xsd:list type not parsed). (Dmitry) * Fixed bug #42326 (SoapServer crash). (Dmitry) * Fixed bug #42214 (SoapServer sends clients internal PHP errors). (Dmitry) * Fixed bug #42189 (xmlrpc_set_type() crashes php on invalid datetime values). (Ilia) * Fixed bug #42139 (XMLReader option constants are broken using XML()). (Rob) * Fixed bug #42086 (SoapServer return Procedure '' not present for WSIBasic compliant wsdl). (Dmitry) * Fixed bug #41822 (Relative includes broken when getcwd() fails). (Ab5602, Jani) * Fixed bug #39651 (proc_open() append mode doesn't work on windows). (Nuno)- update to PHP 5.2.4, no relevant changes since RC3.- PHP 5.2.4RC3 - Fixed version_compare() to support "rc" as well as "RC" for release candidate version numbers. - Fixed bug #42368 (Incorrect error message displayed by pg_escape_string). (Ilia) - Fixed phpbug #42365 and Novell bugzilla #292998 (glob() crashes and/or accepts way too many flags). (Jani) - Fixed bug #42183 (classmap causes crash in non-wsdl mode). (Dmitry) - Fixed bug #42009 (is_a() and is_subclass_of() should NOT call autoload, in the same way as "instanceof" operator). (Dmitry) - Fixed bug #41904 (proc_open(): empty env array should cause empty environment to be passed to process). (Jani) - Fixed bug #37273 (Symlinks and mod_files session handler allow open_basedir bypass). (Ilia) - remove wrong hardcoded requirement on libedit - devel package at least does not need libtool the php build enviroment uses a private copy. - drop no longer needed patches already in upstream- updated to version 5.2.4RC2 - Fixed oci8 and PDO_OCI extensions to allow configuring with Oracle 11g client libraries. (Chris Jones) - Fixed bug #42292 ($PHP_CONFIG not set for phpized builds). (Jani) - Fixed bug #42261 (header wrong for date field). (roberto at spadim dot com dot br, Ilia) - Fixed bug #42259 (SimpleXMLIterator loses ancestry). (Rob) - Fixed bug #42247 (ldap_parse_result() not defined under win32). (Jani) - Fixed bug #42243 (copy() does not output an error when the first arg is a dir). (Ilia) - Fixed bug #42242 (sybase_connect() crashes). (Ilia) - Fixed bug #42237 (stream_copy_to_stream returns invalid values for mmaped streams). (andrew dot minerd at sellingsource dot com, Ilia) - Fixed bug #42222 (possible buffer overflow in php_openssl_make_REQ). (Pierre) - Fixed bug #42211 (property_exists() fails to find protected properties from a parent class). (Dmitry) - Fixed bug #42208 (substr_replace() crashes when the same array is passed more than once). (crrodriguez at suse dot de, Ilia) - Fixed bug #42198 (SCRIPT_NAME and PHP_SELF truncated when inside a userdir and using PATH_INFO). (Dmitry) - Fixed bug #42195 (C++ compiler required always). (Jani) - Fixed bug #42117 (bzip2.compress loses data in internal buffer). (Philip, Ilia) - Fixed bug #42082 (NodeList length zero should be empty). (Hannes) - Fixed bug #36492 (Userfilters can leak buckets). (Sara) - Fixed bug #31892 (PHP_SELF incorrect without cgi.fix_pathinfo, but turning on screws up PATH_INFO). (Dmitry)- updated to version 5.2.4RC1 - dropped obsoleted PHP_5_2-CVS-2007-07-30.patch.bz2- updated to latest state of PHP_5_2 branch; highlights from the NEWS file: - Upgraded PCRE to version 7.2 (Nuno) - Updated timezone database to version 2007.6. (Derick) - Improved openssl_x509_parse() to return extensions in readable form. (Dmitry) - Changed "display_errors" php.ini option to accept "stderr" as value which makes the error messages to be outputted to STDERR instead of STDOUT with CGI and CLI SAPIs (FR #22839). (Jani) - Changed error handler to send HTTP 500 instead of blank page on PHP errors. (Dmitry, Andrei Nigmatulin) - Added check for unknown options passed to configure. (Jani) - Added persistent connection status checker to pdo_pgsql. (Elvis Pranskevichus, Ilia) - Added support for ATTR_TIMEOUT inside pdo_pgsql driver. (Ilia) - Added php_ini_loaded_file() function which returns the path to the actual php.ini in use. (Jani) - Added GD version constants GD_MAJOR_VERSION, GD_MINOR_VERSION GD_RELEASE_VERSION, GD_EXTRA_VERSION and GD_VERSION_STRING. (Pierre) - Added missing open_basedir checks to CGI. (anight at eyelinkmedia dot com, Tony) - Added missing format validator to unpack() function. (Ilia) - Added missing error check inside bcpowmod(). (Ilia) - Added CURLOPT_PRIVATE & CURLINFO_PRIVATE constants. (Andrey A. Belashkov, Tony) - Added missing MSG_EOR and MSG_EOF constants to sockets extension. (Jani) - Added PCRE_VERSION constant. (Tony) - Added ReflectionExtension::info() function to print the phpinfo() block for an extension. (Johannes) - Implemented FR #41884 (ReflectionClass::getDefaultProperties() does not handle static attributes). (Tony) - plus lots of bugfixes - fixed the pear phar archive to run with 5.2.4 [http://bugs.php.net/bug.php?id=42146]- added /var/lib/pear to php5-pear.rpm- fix nasty deadlock in pear - update php5-ze2-fixes.patch and actually apply it.- fixed YOU honors Recommends, breaks php update [#291551] (moved php-suhosin from Recommends to Suggests)- provide /srv/www/cgi-bin/php5 compat symlink instead of patching config files- fixed a mess with update-alternatives PreReq uncovered by newer build versions. actually every subpackage that uses update-alternatives should PreReq it. - fix some ZE2 bugs.- drop php5.xpm and the Icon: line from the specfile (the icon is not used at all and it breaks rpm -q --specfile php5.spec)- PHP version 5.2.3 see http://www.php.net/releases/5_2_3.php - important: PHP-cgi now lives in /usr, package attempts to fix both lighttpd and apache2 fastcgi config files.- use system re2c in factory. - enable support for qbdm in the dba extension (build service only) - enable the ming extension (build service only)- fixed the dba extension adding -ldb-4.x to global LDFLAGS, causing unnecessary dependency in /usr/bin/php5 [http://bugs.php.net/bug.php?id=41455]- updated suhosin to version 0.9.20, security fix + bugfixes see http://www.hardened-php.net/suhosin/changelog.html for more detail.- fix devel package, in the reality PHP does not currenly require expat. headers provides a expat compatibility layer but it is no longer in use by our packages as libxml2 is always prefered, (and HAVE_LIBEXPAT is not defined)- update php5-test-fixes fixing another bug in zend_compile.c - use rpm macros in the spec file - when removing apache2-mod_php5, unload it from apache first. - when updating apache2-mod_php5 restart apache with restart on update macro.- HTTP_RAW_POST_DATA superglobal broken (php5-phpbug-41293.patch) - better fix for MOPB 41.- remove --enable-memory-limit configure flag, it disappeared in 5.2.1, nowdays memory_limit is always enabled.- changed expat to libexpat-devel in Requires of devel subpackage- add php5-test-fixes.patch fixing a test case that wont pass on i586 as well a real fix for Zend/tests/bug41117_1.phpt problem, that was commited after the release was done. there is another test case that fails in 10.2 ext/pcre/tests/bug40195.phpt but this is not a PHP problem but a bug in PCRE. - added missing fix for PMOPB-45-2007 PHP ext/filter Email Validation Vulnerability (minor)- php5-devel package now requires pcre-devel for > 10.1 as 5.2.2 installs php_pcre.h header that needs it.- fixed some new compiler warnings- upgrade to PHP 5.2.2, fixed hundreds of bugs including MOPB ones if you need the complete changes see http://www.php.net/ChangeLog-5.php#5.2.2- Upgrade suhosin extension to version 0.9.19 see http://www.hardened-php.net/suhosin/changelog.html for details- added bison to BuildRequires, removed update-desktop-files- fixed unpack() on big-endian 64bit (revert-phpbug38770.patch) - blacklist more env variables when safe_mode is on (php5-config.patch)- fix Requires of -devel package to include only what is really needed for operation of the pecl tool as well the neccesary headers to compile php extensions. - Fix MOPB 24 "PHP array_user_key_compare() Double DTOR Vulnerability" - note that fix for MOPB 23 was included in the previous patchset.- add security fixes for MOPB 20, 21 and 22. - RPM_BUILD_ROOT is never defined in %post.- fix/workaround for php5-gd problem with typo3 [#236680] - add fix for MOPB-14-2007 PHP substr_compare() Information Leak Vulnerability. - add secfix for import_request_variables() ancient problem, users of suhosin extension are not affected. - Run the test suite here- Update suhosin extension to version 0.9.18 fixing a session problem.- Update suhosin extension to version 0.9.17. see http://www.hardened-php.net/suhosin/changelog.html for details.- add t1lib support in php5-gd (10.3 and up only) - an off-by-one in str_replace may cause a crash.- PHP 5.2.1. for a full list of changes see http://www.php.net/ChangeLog-5.php#5.2.1 - add Obsoletes for extensions we dont ship anymore- fix getenv() modifing $_POST, breaks suhosin badly when register_* is On and variables orde is "GPCS" (default). - change/remove obsoleted patches- synced with BuildService * file "session_mm_apache2handler0.sem" written at boot [#229200] (php5-config.patch) * for certain functionality php5-exif requires php5-mbstring * php5-ldap requires php5-openssl * remove LDAP_DEPRECATED from CFLAGS, module already takes care of this. * patch potential HTTP_SESSION_VARS et all hijack when register_globals is On users from suhosin extension are not affected.(php5-session-rgon-hijack.patch) * on 10.2 and up php5-devel should require pcre-devel sqlite-devel sqlite2-devel * php5-devel is mostly useless without autoconf automake libtool bison make gcc. * added patches: phpbug-39350.patch oldhat-phpinputdata-secfix.patch ze2-fixes.patch filter.patch ext-lib64again.patch- fixed string comparison in xmlrpc module (strcmp.patch) - allways apply %%patch9- updated the curl module from cvs to fix build with curl-7.16 (curl-cvs-fix.patch, dropped gcc.patch)- fixed VUL-0: php session.save_path open_basedir bypass [#227569] (save_path-secfix.patch)- synced with BuildService * updated Suhosin patch to 0.9.6.2 * updated Suhosin extension to 0.9.16 * fixed php5-devel should provide PECL tool [#204006] * use bundled sqlite in suse versions =< 10.1 (pdo_sqlite stopped working properly with older sqlite3 libs) * do not use zend-multibyte anymore, please refer to phpbug #36711 and associated links, no applications uses this feature in the real world since it is disabled in all other distributions/OS.seems to cause more problems than solutions. * change php.ini, back to short_open_tag =off (the default) the package that depended on this setting no longer does. Also explicitely set the upload_tmp_dir in php.ini to deal with open_basedir recent changes (please refer to phpbug #39123) for the details. * suhosin.ini uses just the default recommended settings- created symlinks /usr/bin/php and /usr/bin/pear [#216166]- fixed implicit function decls in suhosin patch (keep the original patch intact and put fixes into separate patch)- updated to 5.2.0 final - merged changes from buildservice (by soporte@onfocus.cl): - updated suhosin to 0.9.10 - added suhosin patch - build with system PCRE if suse_release > 10.1 only [#215610] - suhosin extension does not require PDO - suhosin added to the reccommended list - php5-pspell to require at least aspell-en otherwise is useless [#217272]- php5-sqlite now uses our sqlite and sqlite2 packages to build and not bundled ones [#201440] - updated suhosin to 0.9.9- update to 5.2.0RC6- reset right path in extension_dir (php5-php-config.patch)- update to version 5.2.0RC5 - added suhosin extension (the hardened php replacement) [#210886]- update to version 5.2.0RC4 * added DSA key generation support to openssl_pkey_new() * updated PCRE to version 6.7 * increased default memory limit to 16 megabytes to accommodate for a more accurate memory utilization measurement * added support for httpOnly flag for session extension and cookie setting functions * added version specific registry keys to allow different configurations for different php version * added "PHPINIDir" Apache directive to apache and apache_hooks SAPIs * added an optional boolean parameter to memory_get_usage() and memory_get_peak_usage() to get memory size allocated by emalloc() or real size of memory allocated from system * moved extensions to PECL (filepro and hwapi) * improved SNMP, OpenSSL extension * improved the Zend memory manager, FastCGI SAPI, CURL, PCRE, PDO, SPL, xmlReader - merged changes from openSUSE build service * build without --enable-sigchild [#206533, php#28294, php#38342] * build CLI with libedit support (really-with-libedit.patch) * tweaked the default config a bit, to make it more secure * removed ini entries related to extensions we don't ship * t1lib is not currently needed for build, we need t1lib5 to do something useful * removeed --enable-ucd-snmp-hack (needed for ucd-snmp, but we use net-snmp) * pdo_odbc provided by php-odbc * php-suse-addons : o PHP5 is unlikely to parse php3 code, remove the file association o corrected apache directive is AddHandler not AddType * dropped extensions: o mysql, mysqli and pdo_mysql provided by php-mysql (reduce package count) o php-pdo_sqlite provided by php-sqlite o php-pdo_pgsql provided by php-pgsql o filepro dropped by upstream * new extension: o filter (kept static and cannot be unloaded, due security reasons) o json (added as Recommended) o zip (it uses a bundled library) - fixed gcc issues (gcc.patch) - droped obsoleted patches: include_path.patch, bug-37720.patch, bug-37306.patch, cgi_bugs.patch, bug-37587.patch, gd-fixes.patch, bug-37416.patch, main_bugs.patch, soap.patch, standard.patch, mbstring_bugs.patch, ze2_bugs.patch, xsl_bugs.patch, curl.patch- fixed build with X11R7- updated to version 5.1.4 * FastCGI interface was completely reimplemented * multitude of improvements to the SPL, SimpleXML, GD, CURL and Reflection extensions * support for many additional date formats added to the strtotime() * a performance improvements added to the engine and core extensions * added imap_savebody() that allows message body to be written to a file * added lchown() and lchgrp() to change user/group ownership of symlinks * upgraded bundled PCRE library to version 6.6 - merged changes from openSUSE build service * removed unneeded sablot-devel,sqlite-devel,pcre-devel,fam-devel and libmcal from BuildRequires * added php-ctype,php-dom,php-iconv,php-pdo,php-pdo_sqlite,php-sqlite, php-tokenizer,php-xmlreader,php-xmlwriter to Recommends * added php-mbstring php-gd php-pear php-gettext php-mysqli to Suggests * added support for optional readline(libedit) for CLI (disabled by default) * patches for zendengine (ze2_bugs.patch), xsl (xsl_bugs.patch), curl (curl.patch) and mbstring bugs (mbstring_bugs.patch), big soap patch (soap.patch) * removed obsoleted patches * fixed Safe Mode Bypass [#188243] (standard.patch) * upstream patches [php#37306, php#37416, php#37587, php#37720] [php#37576, php#37496, php#37341, php#37313, php#37256] (cgi_bugs.patch) [php#37346, php#37360] (gd-fixes.patch) * fixed build inconsistences, added php-hash module [#173023] * added pdo_odbc.so to php-odbc module [#190614] * build without explicit safe_mode and magic_quotes (unneeded) * removed useless GD --with-ttf configure option, only suitable for freetype 1kuckuk 1286402096  { `5.2.14-0.2.1suhosin.inisuhosin.so/etc/php5/conf.d//usr/lib/php5/extensions/-march=i586 -mtune=i686 -fmessage-length=0 -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector -funwind-tables -fasynchronous-unwind-tables -gobs://build.suse.de/SUSE:openSUSE:11.1:Update:Test/standard/926377a39ed4811f1ebcbe614a568441-php5cpiolzma2i586i586-suse-linuxFȳpC.詔[?]"k%nS: ^j ܔR#1Y)(嬅L!P:fyqON;Yi#˴;6soLM}\ƌoW?5n?♉6qk@|*ә '6Fb6CevFFCY,N}-'$W*:X $639LQ1OFAHNH8Kq}p‰蚁Ew"Fh Ȋ_T](;Qd]Q.ԓm{TLTM&긠Uj⺱$ zAiSt ?!ѕ ![ L+K2ҡ9M\UoOf89vuQf&=Pݑ,M9Fm]foS"k)ꛁE)ڨYvA=`RqR{;PRe}K'}mJjGM4ق tR?q9݁.Xא5>= D!ߋ\ry,m'/lVҏ('VZ""y1n`W, ZJSn2S14NKc2!WO&?7eʭ, %Ӕh^/e9mG쳬Je ڶM$ih4`):G9B<(׃.RYrΈf U6ռt\q}(.`i;axnd̅)^աh?90v͹2PwdxHjgq^Y~2 NKV˴rqrB<-nR|/KECOϹ);:p7qz}E| }Ik J@VdͲ>F(L>vOF6WGsþ@ /rl=M/i.څ.[b.S|Ш;H:NFR4svn8~] {ޘA"n(?w(*6%IucꚈy:2Ny-ݛ1lG]WlGtMnOZ ,LrA5@/uAQ6"I{i ZۖD^f&qש*}DjV925vc`n 8`>R dݝ,k}ʗ'LuC̓SDuQ) MbAzQG exn /Wu.5m7ᯙt+hE:(ZJJY3>e 6 g&|-R\SЙ{ e,a\]<,nq%*x ZwTAGSZ UC61{2!nkI@dtS*`%uHբQgQAcXB{D s[(J;½^.DNlRh+[ep4:e7nѧ^(LPٳr$riO (%MHObnߧd'Mo7z|.ErGƒ%"0$_h{'Z}Ou1vLMAZ"׫D:㳌t-پ9Tfox=N+VQ'֡N+q\4u`@n^OY5!,Ga\͠]Ah? f|>(VE -3,RJq&s6Ld6R̝]r)NK_*XncʦCuVqe"И_mOiLm4\@Ԫn&4Jpcl]J;ً0Dˤ)A]d!}Z $̒QMr(i֎v1 v"><7&^.2I;{;y| Z/-SQNf +($PSk(3$r m,ϑ+78@k0r'SpI4; F ~)gZsJt,.qgSxALF:V1Ԓw_du&4P$uO;TT`r OkAL]aEF{)45숢`S$rtZ9p ʹKܬA>"Ѫ PZ{?f̣-BEQp ?"ޫ=y /M֓B !/$(3fLR(NWQZ7j">jV M]Fv6凼i;N%F&dug4PZƕz}[1 uU#82/y)eGՄl~lW~|6%5 b6=x#7|&(cTt,2s-s>c Q]oRNU;ve4vU'{\#.E\e@teSyG5,=sEC?{Az]ut4 C:\c!~0k7ے?3$ePD=^We:\aeRP$-(.T# <J$Eq6- +,MXLן'jOA0̸s!S cڒwեu~8S 4\\*:6WD*"C 6jHm" !$;C«XY12@o%A=-OG !NG@4'D}qAo2V%t YXl"M Lo3-*B[9ȯ`Ccf)zo5*.,)AU $[ׇ8[nfWY{ `1YIV}Ӣ;hi[~2tqR-8)(+IbHX8v״v4]ڌ2{ISI<y֧+YYHڿaulI0C/Y8B\͘,Fŀ}[qܮD<leJݡq'Ad.S>uV[_?9A}i2g{$TZ/%Z'&Q6Roٞd)~ T(D8+q/1-oQnV澱` YF_?F\ y$F_XD-*%-h)P+XPmʢc}Cn]ToC0;%zc8*L8uJ biXƉa*o[!@o5X␴pXcRQO9rt9o8_ CR] 3<μ9E4?n1ZeSCq2.} 1''DZݑL4=}J* V𖳭J7fWʑ3]X(kķ~/GwOyT-\crDߌPłjAGD.1䢌 3TCWؕYS6 RmBPd,jl' Al>[YT@OdQ0񖼟GY!u]%lͲ2vQ#Г m7o ;ﳂWzW Q8(Bem`\(TvVn5],p%7Δ-/+ƸӾGXF|6吲#^~N(:NJ-+ӂB׍ߜKR~(!k+@['9LuӖ#F!IXD7#8ABx%Mc[^3Z}' ̛ڑQ[{4qhwׄU7IDže~iboW? 9"dQ;:. H.3yULd|$g?ko7G, A c}N K6ڸZv_J+m`ϛCJn +^ g~P N%:բZ!HI"K%G2f6)ÓewȄHmꤱ!3BOMEO 9j^-b?@oHϞAǚ1d/l1bqΌ54B0,}1ʡ`9Қ}>D~SOh!V&ȌZ\3㙝Ϯ,.|i\'#f0fBN|wyA?EmQT)۲8LǐZ |z}1 SA5OtzF~:Uڿ%L8C-F u{ʚ9 ..g"rK*<7WͩF]qD)POزςXls.;ŗr).P+d@ЬRs_+ dO-idpnozr7mbƆkZ^QLdrL9A,@z7ɑЙ(źCN\I6у 07 'GSy&Ss#HG̉QMRxa.Wͷ=0> NM'[XQpEu9|>c#Dm0,s2{gWŪm M$g(DCG ݲSJh>V{}M5ƤÙg\SkB#EU m1M"_a*g  _/`F`/tIQ *ɠk>1HF>pHaS= ~5#ZNtyf&6ιlq2(C+<b2~mRo÷\Ӻx(\ɞn2@v{N%iP"[ñ#96XR.azHn~U!#g!_Jxs/&b Y]lzMs.ޗ236) T"JG>6*p֓xp* bτMW𮗭4P)DֶevA0":U-21Mqn/" M)JzeknUnZ*#oFKRE1۾c+q‘Mt#L2Ռp2JWp@+w!i0ňj5"\=pv Qg IU Q*-찵 4h ybj{a',!}幌`kō)+i Jmb$b{nV6ȎWfV'Ir , h,*Is6UG ]fbqiS|#@Qg`jBf!FHɴohDCD(܊2[e#m dHRDN`34@LXB˖yR?ho[5G(msްQY.M-൞AgMh 33\Ovcr!V  <0dbnΎM[r#5.o75'yt`,jW|!|ۉ4Ϭ% %$;XY4ꖪmR^xUHVZBiH?*-tΏ ZPl%A)k&2c7 S܀*KkpD۞eץο6oF I`:Vb|9\kQ:ÆplLjn[ JtPt~Ჱ7~4۫m8 ~6`TF"4%omƕ3nA'T~7Fb*+h~ W81QgYsEGRfǂVFՅᕸAL)Hu< ;8ۈ <ⳡ/|fq~Tg3XҴxNF59W=&se5O%*Scn1=8&mv8^n.P.dq쀔ċ~O{nN4PtVY^; 6RRwQ ݣs ,O4[ȅZ5eZI[kݔ ?,5A;aH[J "n4}!@2ls2^:t 0v#9_gXog|} G">=N"YjCptlI,g|p嫞. Z?.s\ SF<>GW&Wy&&"y:vYF|ogqOZ^4Nq8.ω ;VS{]# w} WLmkI MTgDT9=(?ZVnpf$Bَ׉+m;o0Ӻw밲0H?(׍Go8ɕ݀kSzN3nX,d]1 DwP.ثV9unXV.^+_r՝ Qce3m1\+)r߹(ݮ17Ʀ JRXM>5+^m;ޙZ ovuǖs lge\Ue|=ăfLQ&W,9>_&6Q@ !ygC/E!bwdl5z71|ႀ`4L<0 ])vݦW!td;[ Oj );/u%?M((b٘슛~c3V,HC6o޷|)@0ѲɦP"4Lv%a\ito,PEfgެbG.!d{@S`H鎠.~HrԗXc CIlRoGG1Δ-w^>v?Tq 3X6Q{ŏ凈fɡk"FEZc>=Ú ]Au8ol36:#L?P_ve1L/=Il0dN!R_o@rC2'#q̋B _DŽE͂7cȧpL0c"c0]:+v/*I,D6=I mq0rAJFRY[ջ`q5V+oKiXgWR|o*53n[Љ1컙;uX y׈#{!/LnbF=i%@nǫZQ%kUiZ 0-%Zv۵]lcKL8]-}с>W#eiW;gRWr,nv~]ytJYg!ɜνұP@GNȯm%қssU t/xӣ3U}tL\T}|VY Teɐ]^v dԂB d=9oТM\{y H-^\ro̗^Y 왌A+Bbؚ3Ƞ7e2Ez>(M=-&k4ΠʰPյh (J!vϘSkCӏkɌ\H#1ȉy3=p_J>&FAD yFQq[]^@Ȓ'jI|qJ{4l(&]7nS3Bgؠ(K@%$wy>sM!6?|+#d`o.%C {!0ӲjB◨5a?!G/5y?^.0fÛ%! 8. Kr` 4Pkڜ vvS!Dzqp }'xC>7b]){q$+PZFhEN8Gbƶ>\ m7O!{+Hb0ooP%5S ܍bc$iѐB&iD7ь]f)SkVf0Ib 袱9` .=[cwkxvF!Lc~ I0ZI> 0Tgx&JaUׄIvtU(xLrz!WG\;erE_:'quXW;8\i8Ut9$ W>k" \317x,V62K3C۳u ߌY;,ak>6>iFXhp:}8 ^4?j!:qw)um¦"hǐӺ[Ӂϣ]Q[+3[/`.gC"Bힻ%&ϥ2ߩ 9L=OK.rT0՝5H3Z: lɑ ;os PlgUḔ# J~7a""1~15o&^jbh\lo.O6vlW )V)v(Q-ѿ}'w\,܇"bc۪H('|Nف +G7⮎췱w60ō{&?#bF%1mrNLG C朵B(tط$g,_"1I߅^"xUcib=|P_ r؆Ygꗨ#}]}|l(vdh:aq:m۵CSC(Lنtܾqs=ǜ Q ?=(n^U27V%є"\>VE_L#³<6ڋ h>!IcQR$7UsY];e7p Y/3J߸~.qt!~5yDuopw%/5""!A>+n.@l1 {YMhX{r7)[(ei`i}B5>dmfT<A#7PfL@{#ҪvΗ'Y_ń(n` cJiu12'湦qn^f1(gVɷwzvA\00KD] ºvywe̕G^?fjCYe*di߬7v*Ec|b*)HFuD',ѓA†A+JLgL\'Er pE\+`Nc Ӽ9`uLgh>a/%SgLl߹/fQW@9*ɺAzhC&JЁ;*4ޝoIlC-RyH& @)Gzק>> т"~`wo;kq̚-cۉwDru.m);pew<$><<,\,0Q[ &?mLj\X,FoI4x>,6 ;ȋo!&Xk~Ex{"*K+b?5KA`z먕Xabmi tk2^MkY|Ì1\٤3I Msߪ3oнS[I 7p]B\[/hQLГT\p8[Q2B+_zC DA!.=IPaވyt@##NE>_} Ww·8iak%rZWL;|C"fptab"Ĭ nё#{̈́HdnDh IA#% /!NT׭. "#u?#XBG [S0DB&? +$9J NldR%f޼ղ֬u?t*u*cgKvtLq{bNnI/0`wMj+8z |Rm`V@Ee nQ:8ªnw,HƲ--riܯjRzwh3;)E"T+ݖsoQk9h'FN?:*zBrbt$Q zq-<.F̼A!Z6X65~1[Hlq0lMU@Ę/ 2m4 pq\~T3v4pѬ1M8!\Pi]/}ҋ\s~͹I}^N#,"  *%B;5< |@mujm 'w^bNt*Տ$e*L/)^W+-' 1F\Z 5_;p+suNƹ ;){x9p$ ĘΊ7]S *XK̀T^v7B2/>)g|/|E7PE%{ c?\2rHݜ~r,RuO6o.h>U)3pلQ~ 68=,j.S;F ];-r}/<Ç#ʘf-IHcZGvⰹ @8A cmwG|:g@ƺYNX &*B_Ⱥۿp8%i6rt"D-1s*rj,:LWõuAh%9Po ١1sE?)k$EoN^M?5kwrȭڹƫ,H:}X sVF@ҺrJ..ICP];qLh\e.;PC Q ¨_{`ZDj$ ԇiEtU}I.̆,N3~ o :yBg3!fW绖4*ܪ8QgR=ƛhZ}?7= ).GVr[ XwM NF+uI>^$ufU 3y+="i|Wd4!a wG%ִb&whL+QUwaOv-i?hֳΖ.,*c&20Y;oT_y ݝ))ᾱ؁dڕ,Lm,Hn znJF; y-;eq 4& ca\Xyߍ8ߞr(|/Жk^;­zܝL>Vhf}F0_H0_b2B2u^1Bٰ&dDD`ļ`^1R+7;,K~ dyð"Xs d?K.,($$N'HfKKN;?uɬhs6t6:~$Tg@`7,AXIJKJG{e|ٯwHHx鑓\βNO{Xy','4L٘ܫZpMd:me]V'Ù|ɗO~,~7-MhW. DYp^>Njv"IGأ3Nvدo"4v֠Je7<Іf|ԍ';.}P`G2_H EvHhgW$Wo4B]p:my֪tw耝>;+\ bDˠ2^FrPF!n1fF+ BP}sZ濱-q*KzmʙmXz}vX:,}GVpgGS’!/RI IS~ؑfJTÆ^ȕoz;Q zzngR/۷D_ b}a❑:n {3(,>s(r yxLT懏Zen5]m&_sv{t4b K fsc +EVڝ%^ Զ+F 3)x\, `8:m!lXY1-=JݍeW9>JcQx7>wZv& OKÄU=i(~%JԊgSighg' l3Z+i?Ea;bƙuIы;n^q<eָ Po 9>@CGN3lZ#0ȁI`vJ|lPm~#j04ek-zc^]?0ǺGͪS& QTComoA!#֊ 1;v/c2ڻȅT/T NV.kK}V?a8"24P ϶+XFNDqQD1h Azc;>B³00/n]C\3sLH|d ri!NJERC x Ղ?M!$?ȅu/`7:;^I纎oYZɨG/v&ZqMU= reUV>]E}.-&m+)wލs9U9|.NS . 7`52!;jUƩ-:]&OU:&NԡаODQ۰v{#rY[M#"E~6(A65V$aNU !!3:P#7nC\iY6v'us(e,#4 Xɡkx ld~f)(5%ht.j,(mLmdK9@ݎ8C:c&659"Ҩ63CXOf7Y|*b6Mc4ͼ` :TЈGZre(._"H|;`F 8wn*װm1wдgoĠx{쳾x kɿȞVkHPCFm!;6r?*NMV03 6˽0їr>9M:('jQY3,Xďcq^ wdYUNI;';81:eTt-rXlޕ2Oc3w늦;pnQ| QI/iG}Nqlb젾5FDMP~ŋ>1 A\~A0@zpQȂT,ό1Dw`v&Id>1n`{x}J`~ZcL4OV%| ~ȆőB׾h^,1{q81>)Fӓd)ŷBP9UJ)j=/>>nqX" M/`x.|14MԛÅYze4Z0D PHl~O~cKPI'1jShJ3M`% sad_<8R3Olh;zUDWN n[caP*<CFƥ,ۺtʘ!96c*->pXt.nk{%X0\^y^]]z'^2#`N]$J$FԼqVFfUi Ү[-rhHØPOy;DVXk3@2w&$+_hgj~CZN>x^gD{Qνhz~:fXAz_H̲]dΎI^ZԎE3'Y n)ГƄN;\r4YpD9Ƒd74:i3eH G7\^u,t6 oD?%xnHg>@t K=0>Tzڪ"< ˸y@kVtMXΰ!zڨ\`_^$a٢,ܽT"Väg|9}^H%Emh1C|BYz6Nj_g\aݷ K?{(Qcgl%ņC;JCIO=Z>#ąӀVJ4S_~@ExrkM# ҫ a+KDzI>vʐ&h `^JTC*-9=ruפ^Ӭ=?Th@h;zab P=ۧr[b|~S_(fm -$߃f$[ޒb ݛizuYo IRn:GA%U_춖 }ZY4r5mٖSYqȋII&eNir15QLsWI@?\쁀064r ;(N"arrWHχoXxnGQl Y?XI}tkՄbVPd-:o 9#@'̘< mՓO@=(_ -T`'̖HgYol7Jݺ8a9>J'&"*<.C.e [p^aXxj;Ֆz|l\]Uyi)™&W{Z=}M U O`MwlGDenyX]/ Vii;?/$N.S|xQMYy+6lL3K+ƧF1*zcT9)Ḽ{ SFhHzz("_3L$6ͺzAk|Ε2f,"sVPQ-Ʌr5rSR6%K pi }Y$s 8:؍ykf&H1OL! Tcͪ];(db+XJXfkMk bٿs:yeA*[VnZUFD s܄6UC2$c&/ĭXCC>ˌ*KuqU$pF܉!Go@ UWDKAG'h† Y"&ڡ2^Iv|apHOs6{4Ծj[QOp*9Y2n`{fp[oz C52iw.RT7H. Be w[ x-]iף=067}:q%vtDlgl-L+oQf~zJ{'$4%SbbF_KdgvrPjspIaHlLxn̳7$Jݪq KN3h>w_#rlY OmKq\FRҜ}(/h:o`]s2Dm70z7%1@cRoE)U[f k_#$#9izqAmL~owr%h43PeaxgAV'JnҌ}&)Іfȧ3-1FS>@2õ^pt:\Va((™?xia$\9e_mIn,%QɟRRM݊w1z8j#({f/Mxí^D;~MT;glWwgJDOٵ2pQN>OPxP y62Uӥ_*h`tTm ˋ; §ॉ{y,/jֳp ZIqE‘-&ȡ#͌Q42l͋x<$Y:SPi'/߲}'ӖK oQm5GBuzos#DrcRMW?z*KηqļzsM`'xߙͳa@`oK}#t,q?(q޷O*Wwye"P|-%( g o2LFKo-ڣ=g!U d[!Icsq9KB6+dxR|T.7(65kD8HtK|(!+PʽOT{*S3~@ǎҐD*|:Ex좱},e%ļk1%"D.`ձ|]Y;'˞}0 jJK=3!Vo)+E0-Vas#Խq ylmF`OQf]ڗײ:vR~F{Z.Σ{6R#%4p Cfmȭ) 1f᭜KܰՂgA c)_rjG6`{-S>~&a`I3a/ݯ =Ok H 8VA@=Tr/S\+x$k{ R9킻yv/ wB"!Zv 8){ILϟL wp /:u^\`0Yh8p[/άݻq:&%^!Wpl&5`b i"RfJ%}KC!loz?":9^EӦPHW_~m R2VB8<"xYΘ/'ʟeߌ_ U\~!=2w/o gAH?M+hzpѸ`S&*5[=DP_ G"tfUvv1c?~gF:VY 3[S0o2 70 CᓱyJooJ5SD[#nx$2&ΘE&_cp!Yb 8c's2Pn9djf]Mo+K-Q:).|C|)wmnqn-[~.)vMv)g&H9Ҹn& צ+;iLo `OKaWx,V aQ""]5)蓛)_CDMlC^)HU֢"fVVko)]=pABJn'wFU ";gH=-TֽUo{Ϳꡱ_A2'U_>,&~`vzD=} =[%=|VzMCHr|Qymi-+-FFfD<07"! |aEA 7!g>j%UĢ(t,G3q&TloRVVNXWj{R#黐;{<"HJ'LfP+\<@0pv2n㾷XNMGwGpM2 SOc0䱷宇יZ[rB/^OL,B@Dqy RWZ}-(lޅ ppiy1L+/dHטּ[ i-<މjr,Ċ껋)WnCg3茴%e[ie.2Yr+k 71G|5m0N8`6 cHOnBƯlt1՛jNɳC#Lc(B#ya<9/SwJ9HfN M%kħInn#hK @U_u-fbT= W\SrraEz'?QFw$VU.&=\$؄ p*^]eL\+8UR54`+ 0 VyyfJ' 6hcՊж ȱY8ԨɈoRv٪Wfνyxm{DN6Tڥb(|ksH%Wgt@ʪ .m ('>I5|ɱl#u};HWZoq#yNAKDzPaBQO(qֺ{*u,q#