libcurl-mini-devel-7.66.0-lp152.3.24.1<>,@a]˞/=„O9%U;z' F3LEcS\5"iLyH.ՙvv VM[n,g\$0"cԁ qNO@n>ri;e⧽_P ofswW> hd'hZuXPYqNX"7z}mxFM @Q|%D?d ) PTXdh{   h    xx8  |  U |(8k9Dk:$kBvFvGvH}IXYZ [\]^ bc~defl!u4v4 wxxxyxzӄӔӘӞClibcurl-mini-devel7.66.0lp152.3.24.1Development files for the curl libraryCurl is a client to get documents and files from or send documents to a server using any of the supported protocols (HTTP, HTTPS, FTP, GOPHER, DICT, TELNET, LDAP, or FILE). The command is designed to work without user interaction or any kind of interactivity.a]˞armbuild24 A[openSUSE Leap 15.2openSUSEcurlhttp://bugs.opensuse.orgDevelopment/Libraries/C and C++https://curl.haxx.se/linuxaarch64? ;AS@H`=+s+YM+)m@+ "Q| A9g~!U=psu2Kx ;e@,Z^KxC[ZyX,a$iVSmbu vHA<(`r<+$ Y3FNL` v y>~S!bg9yMb|G2QU6 , 1>r3AfUH)gJl8DYle u IMp|[~\ ^_SBiiM hKGSSA]RMr2 3\x/]<<Xoe8USa@ s >lQD:`/ @+epIPP 1X- D u2 9ge 6d7RsA큤A큤A큤a]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˎa]ˏa]ˏa]ˏa]˚]v?a]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏa]ˏ56b6679c72d261535a232f8b0bf31e88c72a0ccaf494a0e4e77a041c8cb8f5afcaa5ee7f711459c10eb625da1d5187a2e58e719414d71d60b51ad573eee5f4d59efc49c3a3f7306baf020eceb88d5418948d64566152735cdabc4e92d8f72ae9811c06e240958f648bc09baebf6ef6bbc5b8e288aaceb3946377366c77e4dcc0e17fd77a1bd6031eb62de4a8f60f9dd58744d9914cbd99fbb1c6fdd5a33a9e355974f41bdb0245479dc3deb6b0df9278313ee08f58c8db1baad397d8c6a6f275c082be5cbdeadc0b4f67ba610a2b3ef3f67a700b5e8df568f8cb404699a81a92211d4569ed9f583be8339f61cdfb2e880441aa90761dd7bab648a7fe279d16776b5441fa93d58e671eabfb401a9f88a243ba27db9caa2d566eea4917f8036f87e70d89fa3e30135c7d1c6c0b2ed452a08494c6db9ee9b36a92cb7e8214cf686e2f63da9b72282d9a5dcc853c87cfa79ab5294ba91548bd4583ad85a5864fa03f84caa4319d7a2dd52a9e3578931fcb7d6d5edbad296981dcf7d49b81ab0177c62cece9ec744f7d8677941eb1cb48469fe36d1316a41b5cc0c876d5cb4ea6c95c2895a9142e8bc5d704aeba38c9a1a64f9da0e966fd7fcbc4eb05e7ee027cf44f8ee211c1f5d3077a7e393e10a6fbaa5aaefa585608a165eef69f52c05c249c9511df7f845a26f8e46c61fc73d1d41d8e9d90505377a669aa5c4d6ac86a9fccdfe9a28a7d0bf6b13bc4252cefae2938d9f1fa1b25806f01f4ca7a32389d911d3a2094c716bf4fd7603e3e0b2b563aa013600582f622cb463d6b1b939a121c3f6c186ea44abccb62a2c85d572745c7bc7e0172239496c02251185cb1e4caa4e96fb55a3e62d52a3bc7bc071b66bec4cdbf1d85185969e5fa789468359331dab6cb5e38d43ae1efad651b1dd7c917f74f0335704bbc451918d8ad2f0d3e79f9edb7c5218b1447f44e085ce5a40d6256ed01548dedb4e8bf1e070af1d7b7cfd81a95339c9e9a84f30213591c8c6a352b36678f5dce000ae1382227dee0b65881625c49b1369e2cf26112a06561883287ba3e45717e8fea4683c14aa278f767225f9c34e31dab8a04567147ad38558c0670f9c41f1c5c53c33d13b655e09ef42c2aa46ecd22a41a0212a72d760e773e91aba99461bd17fe3aafc0f819093b03d5779ae2f3525c81f3fde2bcd4b23a1bc827e6e76d45afdc117f61617a30d68565e1497d659abedfd811fea3c6897c5f291780ebe64cc99209a2d91166ea87e2ced4379fa5f0c01a154955837719a20a37d609a044a8e33227b5d10c1a9ea21c09791c4143814d128e5430392e1c84fb36d45cc69dd307067a2302dd18e7d93ff4b95e9d6c36a4601e7b34137b813fd04c32cc4d81292006771c64f1fa758a69d481139ae608b557d778d35172074196daaaefbea161f832d78e2dcac016cf012bb570e29732182e3fd5d40d558c53916669c833d69f73138b205eb53f899f1a787d48abddb04de7283cc760b1c93eb96e6ffdd98d01e695daede974f4547e68cb41cf7a8cba0d5fed39d5cec81e42793a4fdf495ba53869fde448c7239cd60c048f223aa9902510fa7be34ecab736dd1ee8afcdaf53ea640da260d9e13872661fd6e8adfa959e19b3d585b08cc3b7cfd4344876c3c37b3f9ca46fd602a1c3f44038026be1620c5b914fb994910910a0c7378437a83da4c3c7625df4b2d72b051d3eaf6b57b6076becd0b208f4946db405395cd366bc1b89503cef59fd1312f69096961cd99c3103cc55dc9162654d57a15e8756a07a5dfe0956536a596e1d1ab71e8d9891e6be80a0efe763e063b38a11cdc2f79011c7ef77d3e71a18466de616452b58d2382241c2a8247bc5f3e5fe8b8d24956acb0d83c22812b0ba2fc6e828ad6270674eeea6bcfdc6d1d6caa6c1a35089b420b0c8e7c45f928af3efcb5f4d329e1e68dff401c170786aaf34fe9b7579bda9a0d1ae42feaaa25e096537fc482cffbb05127cd6884253ebeb1bbe9c4b585f20d11fce30b7a54d04bb35fd2ff7e0f5a0cae608ba27e8201e5cb137fb5f1af7131cf5824749825c3b64f1bcafb030d8d30a4aea3e62478b8686c3a8a4f3ace61a3f1ddd43a2c442477abc4c2e1c6e17473621eede488782f2517316d149055a28f18733381071f6f5f6311d764eda9a1ab4cdad7841950eab9cc6556d874ac38ca33a3b1d875f82fb94487bfa52bf5af96c1c67c2b1f9b9bd6001655f87483693e50610044f7c1c39166482a4c6abf798f900a3460110f7476c071a106615cb2dbb591ef647d6f1ed09c79bd4972440b7299a4f393997e5e146b8f11f9cf5800fcec610ac5b5bac1d3184746ca794d16ee7b57904ff8680e8a4225b3e641efcd379eacfd2be858126076bc9e8e8b8cfb948123bfe7b9a8fd9a2bbdebf94ff6349e8a0bf68f39732fa5db6d810072b6575a5bc5d1de13ec334babb6a47352addfca70da548db0975db1199dd275379411e029ed653a3b66e58d000b1ab9a75147bbbc139a739856632026468be27451e05194aa1b070df1c52e9d0a09191b93b39c22ca75b7616e302e398edff06df387ad0ee88d6b9aabe3d8d8a4e7b75fbf803fb5e39e3368f52288a9ddb5c46d7fa680d91cc268e25abfbbcea95fd89dcd752d813466bb36439db3d9bb392ad461f2c662227a649b5881f78a4ed4c233a341946c1b63eacd441ae143a175b4c40e0afb4415274784f4c00169d061c31e299d7371ebf080fa3eb230a241ec74d9b4b386aa959cbb7633962eee9d3c53db08ca44539d23f64e14e7d642a71a50c588bb6256181cc2483e8363dd55c29d0e80cd9f8161e5b4881b466939a8b438d5baa03fc731683bebbf41798d53331bc0f0388b6c77b57d5be85fcf54aab073b17b284b6bd4ca153fd976b026e70d7d7ad9cf39ec40c37101b80a48cc419d51df6b01ca92a2aaaf64a22bce5d716cb8acdf93f8ce4e24a3684b5b34735725600278a997a1dafffe183d9038a17d4f6b5ac709d4be38f68186bc065f83c0ed807242aaa1c9e106a25802c09e3d05e7b3c9a3d0a8cf60bb8c910a3dde52c49cab0f13574bbf70936bb953d857f9ab94873719d3e4b78e8e72f8fb109d2fef52609f033b1ee73f0e60f04eafa28a1f9986b109390fd20cc51b6dc2194a588fd5bb6bfde711287ef9b192a04a17acb32f3ab5a9980b995a194adcdbf76733d30995605a380b0b9c541cf8a72b3fabff450f59578666cf219563f2b88f4956428d8a4f412b83c762e36255a4b68f2430e51709ae871725c50c514df61e3c227a1d3861a16bc24d67940d22aa4ffd74cf89916068fa0cceff90fdc6ca5f59ca7a055bcbe65f174a95d999efdd0474244d6ca9e19da74b9318cddb63f71a9067630f45e47f4d7c185087d41ed3e0174b69230b92499dd6b47002ea36fe996c29d0200c7f259cee07cf9b6c2dc9aa2469801421976876febecd09a42fb89aaa7af08e68202771a2482d3afd17afcb8b8f17de1047d17132d200d3c04d8b2f9188255edae50d68e320c0ebe29df2d9aa77bf5b64ecc74eef3a9f9109f1ccbea2453ebfa456db9ddc86f623973deb887c88245005461e295aa5feb392167d7d55c7f12c2ab5f6ed44cc12c412a3f2bcd915ff624173f6ae3530073eaf55c1b3ebb98abe609fe7b4a3a3615236b003d4b0d9d20824d6af1ebd889531449af2b341db8985c2ef76940dd65fae8db0142e967e35f0e07113174401e12b364ab80cc7eb2aff2ac0e6e890ade25929a6bf6cf776a5faee11078d59c3d37b403d7fd2bb84cc9dfdc3b7d8ffab995803207490f41620fc71739dcfefda38be58cb3ade4991286dd154ecd9f0e927f78ece265bed0ba78bb9c6151e18c5d8b463463c9272e8254a4ec93ae565ef49687c52c0bd4777b378b4fb5fd77f1abdff7aec02ceba6932c44b81d3fe88aaafd987e6a72cfebdda086070fb0a3e7f8e8259335762c3b2da16efba37ffc421af73f22f5af5b09755dc29f04d7e869f895267db09659fbbbb7074d08e4ed81c39c9571ce8e9539e2ba2dfa87b69cbc803dfe59ee85d56185cdeff4f341192e1974ba2c964c6920370a4ca547f13c4944c1abebd57094bf6602a1772fc4cd9a4dbfe9f4910c33c55765cb2cbb2ca01b0a541ee002125faa8ae18594e3f22712db508693ae081a9f22d6debdbe9ce437c59e6c52f432503c4cfa9fa02d60c3357de2b861168e65c1ba152b32529265b7578aea6f3747481263860a5f8035719a77340c0f7c348ff974081b2dcf05e9a90eb8aeef4ac87c164e18a01c38334fc71557904ffe397f64cadccc866760c45a0f52b07804fe2bdc8c2332a29fd547ace45089cd075eef9ce3a7fedd0dd718cc473d8a515ec3d38cfd5c85d6ce25cd3b2f7024c17286e16a050293becbc2d94305fc1638bdc4774fcf9f64f512ad9cd8842fef5137f85567c3c8b43176cb706a7544829cce2b85f5d4fef33121ce3592e93bde4fdfef2879626f06fc9f9f2228ee3547649ba2dce74768e8e424c81b725eaa67d444d602308ab16bfb3e734f5df5eba904e699dc5d6b85a01b061250e620c98786ed93f2c6fbf7ab2b3ece638f7221903ec5b0decd38c2fe446572f24eab19216790a3b890e32b03a18b9131d83ea92e9b2f2b9f083c0022f94347be8c762c700b36a4707d460592c890503b9ead302d0726f520103eaf7741bdbc91d0f9a557c0dec8b85e19ed407f0c791fe039d856097d13ffc0dfe03821318c5f894e26708786a6f9d5ecf11529e18f60c311c8436278a47a776e5df7e3a01dc94339be7facc2fa499d7466007cb47cda43648a57238dac17e5115bf9cd42f8872131ce70b7100701514a92448a561f700b9f6ac22bb80d1029bcf9bf890749121116ef2bf1ad6f7257004403c62b2e86f17da4159d3b662c1584a4c978b19ad8e9bb826e2598a32fa2f184d24f9b92678d908bda774e60947583ff5864aecdf8ebedb9b8bac27b6da17d97a3c0ca8cd381473e4103d8563ed8f419bf9ca710b3e937d961fafcf47057e659a18b19454d6ac2c3f82ac5505bc7e2cb1be3065504109721b729a7295c0f6eb3fed220a188126bb57fdcec141cf5132905f42c6e08cda4f58eee56e17385f22d7fe0788db3da2b4a6ff4b19e5b7ce461db8eff694c4a01275e561e362bd0057b804851885eba4f782967228f70fafbf804a67557b7533fa98f006e951ea358f32f6fc59fbb00ebc1ed7d16254b9c5734a0acd3d75c653a9e0123511250a6e14c64d97a12bcfb3ca4ac403aa99e94c373eccffdf091f265f2260a050c50864c4cc001811a85e27aec0a6763489e6c5b0736d7a0227a353e411c10ad4149047a0fc6d243cf7f2e5c0660533eab2ab22718c9a4853240b709bb0cd132513c44eee9344a3b9025b2103f3152b549f123098e341126c201f1eaf0c69f0ec7c74e78aa8d3d5c97fe805cb8fdf8762d7bcff20de88a3c4f6a9164542e04df916f59b47a2236ab89a4b91b882ec544a3598a79e21b90ac2999853be7106056132db9a7f0a90741ae0897fc5bf7daa9f5bb8285ae6d479b3f4808cce0f4aff5316f2011ec6eda876870ca74697f41b1b3e2fb4fbb4a87588d2834afbe45f159326ddf120a319675d929a7138de6da0d3fd6c3bd755f33738439eb8cf82f9724261c98fde8660821492482a072380ec03024a35dc7ab2afa232145d6df095640b8545df57d5f024d119b5ac7dfa49c74e998b9dd07e925074bc934b9ae41464611a5fb239fefa34edd7ed36380e4a19bb5f3023c24e310a086fbe660b7a5ff673356e8f446d2056d26d999bd016197441fff689d24f8c1402e6264c9d9bb5633f083caddfc9573f8a5d1e04de31202cbadbaef30cc37e477597dc67be2282cae6400e77e1581076567321f44edf684f6496b1f8ea1c24447dedceb62aa1b28b7e0c7d67eeb6e880883c7b57053f7d73063cec257075c821070ab6555099901368fc78b39a4ee8e271333fbbb0f54032ed91fba968a50c1a05d8d3548e1457a64828c4fa062fd9756573827fc6ad124c3837d41bf4bad214c9834330f3fb32dae4d8087782a7df380b4603afe6bde396581300bd8789c1dd50e6e7006692bda608ff48b8c21ab2a190a49a1dd4bb7550cc2fd233689536e7fd0d79b080a29368d8d8748f7fbe6f964f1359e5b8657c8d35daf50b9e85172032be1d7bffa4b601b24935cf7c8080ef81d1a01071447a73516542e9b825aa3d257e65edf288cde2a85911d5f2875b96d01d82b7287472ef11fad77d5b61e0820cbc854ab728a95f00cbf3aed6466a3951883068eb053a157963dbe50796a2eb816aca1edcf7b27cbbbbf8a9183b6a1e8b59a80844d54465e8c7408428559562475b15bd695fe30341cb9ba414c7aa6e7610b11a4fb43c7cee316cecf66f7f55e6025d5ceaec407d51906e6ab7934594cf447bf7d89a444549cc6d03dcd629a046e27b306abaf5d3258236cbaf0847b92a47b1bb3c80dbb395e41f854825d8718706ae74de6845a696cd033ebcaf7566839807cf0d5f063eca6146ba6d1ce8ebc4ca1ab37fc53ffc1bf6b86faa36ced7b47a986d31aa7c66b0311818e4f7df0d30731fa331bf507fa7fb6e64a74453d5c68075c94e9e6e98cc15ac7c12f6c69babdd616f33ed36e15224fc6fdc5dd13ce804fd5674b89efe3aec227cda235bb0da6faa072ff08a7d9a72ff98b0c8497ff774c65d1f5347ac4437909e0d8e0bd3ddb8ee0775fa350e16196d1add6bd74f2910599dbe4e378bea94de37b24a6aa8167d612403516233c85e4f8cb058a545c8a91e77e011d5cd0ae478d1e45e98255f65df677f5644b5b45512ce447cd30ed019d1e325b4c2ce6d1da1f3dd57797d9fc013bc045bd9e7c9a4abc6e4d60f3c8745f03aed99ce1727184c4f582ce93d2e79929ffb4fc36c9cf4bcaea434abe44859cdc986d7f3e2a596e20034765ce773d1704ebafd0c8dcc90981e0ec4d4a9c65198798f6f035cfe7188293ce7443f6139a5c12091ba6dc6df96bb43fcca76ee6dbf5779c6c865fedb95433943e1ccb4dc4b39b58713da34f207741860006871a135d409bb9d01dc279bbcbf607db966d21f5635c232c4ddbc37803ddaeb77a958e562652713bb6c38b3a68aafdafc236d24e9a552c23b9f4819fc3c8240ecf09e18c5bf476a8e966a75fb1f026f5d13229d2ec69e27eab2493dc5a7436976c8ed603a566975b324afddc3b7ad79c5c35d1053a9eda6a7b91d78a3df2b7ebf73732c1014d859244c64bc57649d415bcc3708760587ee50bb5831ce6cf4d10889cc6e20c4d986208095df871d0e419fb8b0ee7000c3a8aa91a98f4a7756f8b69590170b87977f4e0b157268f9e322da626402048655cdab2f8a0df09c2d02403cdfcdc1b9799233a89aa0c36ca1761884abc3c07b10cc2f2b56fee3e6f510e029de0d9b3adc680c9d47c4087f2b0b8a2db018b1c5c2499065d49dd898e1154fc1edbbabb3f6a41ab8ba0ed07dffe4420164faa441f5b041e32e9b363512e6175e140c2481e70c9d6ef7db10773a622096ed2acfb7865c7a92b8a605a8a649090ee036c0b95e5410313c7b4b1bb820482b317e10743f57aed957084684d85617f2fe0d76669204c0d5a8c6a5a834ae7f99aff2de87579663948731ec388a970c2ad94d85a4b85120d78f8578217248ddd14d4ec03a16273a43d092056aa46ab796cec48c895e67f866ad870f093161b7df160c8f079c2ed01a16ad1447b7e232f81b28b0ddb2f0ce8b4f7b56e54667d0388e603b89e3f99fd7ede61841c0a5dd757e03c98fe199adbdd4b8a7394812ff2749e6d5f5e044ef313985428577e76865e2cbb04870489014275302f174393739ef694af74b27f4933d4cc1622145bdeb8195c1b1cf451bcdbc22bb1d1d8443d246589c3091d35b7056a40de24f8851b49e213b1fef040d77469e777a2ab9d16058ec16a0abcd03c0affab767e0dd1c28fe4a08678a106bfc2104cee079f82282c7cde0a4bd0787cc7e2998245aa2059700e9d774cd6dc511693cf8efa668d683c6b63c6d8942558d1c3e2e8f0f243cc33ae21fd4abb66d0f990f7b7bbf098c2161211b15393e9007e966f61bc70001478763b2eb5441451beed52a5a6cc8aaaa72b595c66c21f661bc190c0780798f8cd09197f4ba1d6c830dc172b4866c4e9c3f8dce0f58b19196b54adf8d2d48dd2afcf3493a0fc2d8af7ddf6fc8e445324dfc5b623d75a3fb5a78ccc876192dc6e95d23fe747d8649eb7c141d6fc93d34653df3c78f729ca55cb75dc28ba976661efc3efd14e4a646917f1d5e5ecdb4c1e053e3f1df74e2e12a4e233aca75efb1a6739bf024940a8153d134db590efbbf826559837beca1a783459a693bac9457a837c705d16e5f3517f667d6bb09bf1c8825281749f759763a343e4a16faad62c041dd5130e0e32a6969257d292da97abec474a6d3e0b7dc104960aec0bea2bf1931e4fe011aed58e052fc5ab128b1341c1a5c26a3b21220aa27b8fdbbed02039484141cffb110fb27ef2e4f92f8bf19b1e5439af7483e7f05ebf86f48aa6cc702658aa5f1bff616c710d59ae0323ade007f78dcca3386ea3540b78b6874944e9d8887d1fcd323b9c641c63ab3dbabb87644f7a6a1cf1ac07a7075f05d255541000fd3953d380758a05a6ba1bbb85549a2904d754837e9a397876f67a925db8fa70a8809dabcb22b283da68781d82fbb445cba2bedf2baf33027c7fdacfdd8416c9ab6ac428529c86e11ac90565d4e9451693ba5e863956544af3a0b017c1e59d54f39a9eb6156ee068cc50b0f9dc4dd7fb8737293320d82f815c5e59b81bdbabfc248bf209cd3592db14ffca5247711a7a64f24c99a3120ccea89024fcbc786c696cc58a22c0aec6b3743530880862d045a5a4c6800dd3887845358f81ac643fe78a66851a8de7316974436b6454d552c95b83a5ad9e7abb639cb65183a54bc9741268d5bcb57bd7439ff4be32aee79e04d07f6edbd68619bda86529ac362a8dd456300b6de6bd4dbd114f8a002359cefe5c5247ac09d800e7ee455845d5124fd49ddf61d58170a2e913ce95061f51ec2591d00c9c69c38a9203e7d70244e8f09bedeb6b42dbb1d3bbfc0ad055c40545702d8e2794108e9cad669ac32e16b5e3f07d772c7d9615107c0a4444719db1c9e00c1140c190a347f9a8bdfd15cb17c191e79cc53fc0d83b67e22a5ea8729fc52af7025572f2006015a5c4cfa0ad1efbbc6278c731cb40dab6c8983a1241885efc676afe6fa8ea1749392248b7d5cef4876766645ba7b2883de4573f44d65d11de1ab4f46376d49e6873266950bd60de1eb57f7c8b8878b091ec924c6fcc4f7a47f27fae0409e46a6350b2c56a6a7abcd67a433dc1dee37413f69359edd938c7f0c84000d626b53851ea1bcd02aba286949aae0920e470e6c442d910ba46334ed5ea96c0df90173e3da164739c3b9a1dd62bd31a74d699e6cc096f4e814e1e3596f72f0f9ed93789af5da6be2b6749a6db666d4fad5c38147d2d88e4e5f621f33e12ca147ed3d8b6966d835445677d2c0629865e6cc0ddd0a3b143d398ccafced419f49884258b17c579513aa3db06e3b942e61a8458ba4ed4a9863854616bd868f1c9534a87519a9ccefe2c3f24473e0608a778ce00a0708c10e5f58f07a300fb3dda057f51b8365f71d9c1c0027839299590c53b9b37b6c27bb30bc2abce36f7f467bf3d30dfdc109925ae3e914554185b4de1063f52b74b18decbe8bb7167f84ebe908b00d077a9ff899a6d6033d8bfe34ef6c67e6acc30eb811e3e33c208d66dacdcea78af4bbbb51dcd759940cb136604f1552629a9154c7f71b044f06285d45b17642b9a499aa204d0dcfd95b5c3874190f6bcf15a9e2a6d4a1fda9f64b796f9d28983e8de7e8aab1c65d391d3b3239004a7f1abeee645d96d75b640c0c8b182d9551d99b53e4bdca8c86bb9662a987ca930c0c73ca9bc72fcc2fbdcc5269bd4397d0ada58d9ebcc400f4c44b3e30dce875228d8722d852e0b09ec8272ce817a55c5ecc4a01d7daa9f4d28c136cf0553c2ae745ef38467e8499dbceb6deccc48b9295ebe845fc7f19abaf29f8a94298f13fdc1762359f9aa39e3d1ab9f7ef4d909efb32103e4698efbd72ce9c4e30a337ae5944c1a6882855340ae9953fc33bcf7e2d49a955bd21e7bc1236d26fa978b8afe1f86ffa8d4d719f16092bd13c4e60b394ddfdb6d38634692f17b15f0085d2ecb22d73b975357708f166e85a50bd4e4b635543ae73a342f122921f5700b58e338d8e6a11abffd46169fdeeee72b7c4c0e7d4d3b954069c22e3382cbb4e73fe348a629b25c0488b0378926bef3b980ead3894a6897ba31fc0305f32b996ce680d45a21ca9fb8d18f29491bb1d3457fce6eb04db078b6b7421155f7ec63b9985d3e1861a874b2db7da2f490d9c4068d14ca0551015a7610678f42a001f4880a8b7e146b3d7ab9c0be5f57441c01dc2d770bd1f625a2cbc553ef40cd852f64f86fb05efedccaf0b32fcb981828ff8839848a4ad5ca31859f7001fc5efc981b919ddf2683a7d7aa3d8428f6610d2c0ae444071391d2ad9ce6f961e3c1218f5bfa92b80e6efd9a96443d809da7b1260b87802bd98738be11df29e511704ca4d25e0e92d36468b30c0b7680493c42a7a12f81a7f732ac7a32037f1ecf1e83781aeb61764a236b366b32891900c753dd39229d6fbb4112df810204b633a4ddc4fc61e6fdd621289cfe9544af360d5f57eeb1a333d43b2d7fbdaac95f0c8737ea406191c48c0d1b74a11673f4e8590afa9e87c738d7182f14e11700f6d8fc7e1f1380fceac660816eeba187d6aad664da7755d2972173db688d0dfbc5f5bbeb5891230cb47a39d063fb71e949768a3fa6c740c16d5f99ca5fa36fc65e4c5381602e40a823d552ce83512a9f9bc0971288425c4148fd101d468a3a3686da0d2961c1e9e929fb561b15c6876ef61c56f974f17b9dbea3b2f9c47e44167bbe19edfc0208a33e2a21fc3364390b3a5ca4af756a8e9757d942a3f9f06547745c6be2ba7ed9b64fc22f852b01a0703f810b9d129e759a5c93dc4dfadd702ff1e17e1833650671b11fb1b8a44772678b6a79149127291f4bd4670f161f44c7470f58515e1e2f6b514d0937f02b33c20404dd7160a5429b303a11f87c6c35f7f2861ed4417ea0531c50cc8aa7209555c9c899bd22052c91d374c384decf4cdfc16a49bb0e440e65768c98f16ad37084dd024ddd5c42fa5bf73037800736e9e19e6502210fadfa6c7a5d33b6f6558680895948ac36711759cc623e51d8647bc4a38d780ec6c73ee9473d2bb44bf331090ed237a32b7477a193308318fc896f0302e7084624860c16dabe53373d89305facae67647b94f787e76d1b2e5d9577cb5d4415efb93ee3476c1bc7b2fa0d87147cb02688c6d8aa57b31e6cf0928d37f7471c027418f13609c1339b7ea5f76feadec89ca2def44152dd41e3a320fa9f0a8a89bae7d268517b75d7f73562b15dc5060072d16999c7fa51536aca3da013caa7bfd09c44ac1232de3a45f9fc7b30dc563a1cf41498e29de1bd8f7412d430124f33d8098eec6edadd590c074150a874e899d192095c74f9560dde864e99c05bf51deb32ddb67d5213ca583b5f739903f18d4182d1ac1685f079917ac75903f7e5b9f3867a3dc18fad2b49771e4fbe12924def3fb9efd616b5c71c07e95ca57ef00df4ceb75b79c6daf7aa8654e0740233dccdfbe113100538a8f3f0a03ec5ba7876278161587ff78597c2bf52618457095d670a088ecfe4b4d27846ac80972c9fadde3a21abb2e92ce4497f5fa1d799daad842e8f85b406fa30f34cb466854293cfb5f9cf57218bbe9b231fdf05decb69dd670859eb65ec75dd891614c2533447e15afa663036cb77a55050fa5cb654a2f95e7cc82a4f8e773c9fdb3bcdab47add4468edb1e2ad442085887c34bf4081bd0714d94842d4cea78ee3e935625324b55415bd15c1ddc1279f5428367ff6fe9ec8c7321f63462bf2b2b41eb4f3403fc98134f970940a97bed455099f0948ebd715eab4ac67b4f06d803442abb63eab1be363704eb2b3ae812e1896b88eaca02dec60041d445933dbddaf1be61272620b760fe6d5a3992cca04e8296040da2611119871f6339a15d1aa3ce1c37fd9117d3b65ca220936bbca64e46e6ce1f1c593291ec91274a1a9a474a1fbc0467ae2da016de8999f8be99714638749701d926df30bafc509c1c4781e8108db871fe94e437936d4185090ac56517a1f223ede8c4922ba8886b28a23af1f819c4bd2c790d004efe3698a156b87b3e6397ff102ec7d406a402e4fd4c0b4f3eb9eb0f941ff624ec08bb083971812c1a72b9dae3ebd1140e2835b5392e36022af02bc83a81a8ee5c68bbd414f29af8a7b242dc27fbf240790ba7b66bf1e34f36cb0cacab96e9c801b075b858c27680cadac18636a88e9094bc78839db2b6ddc09258db49c91c8393c6f0e1b8f5ce824b87893f4233247de4c2a9e451b70f01d1a10f5dee1d3d5aa066d4c8d771209d7c67254e17cb02bf79e4b2269df61c8ff846133065281c8b7146b882b0e99b4f3339f3320368e544cdd19391c8672765fd386b4820065c2e92d13f65392360d045e02a2d4059f70689439b432505324b1434a5f9b36ce1e6d8311e9d788b955033a320d946fb90bc955543a085296ea617fa15af54a44c7967d5da6f22cd978480399102bffbf20570b22e52a486ff22af5185c15b05dd4debb9aa071dfc9c40c19a2453e4fb2656ef4c2c5e378af9493eb774f39022eff05d47da1a5032953fa3a61143584e2063a0c206189346a6c52d77d1a248f569733507557768a6a38682ea2924a15f25cf65bfb111338650bca75bec3ef40d997a4177faa3a89cd02f61e40a52a2b5fd18673c8c14126cddc03d988fb4a885b8cea126e0ec00f34a55afa374fdd40c28c3f8d63c954859c6f2fc2ec8d60d73660e35aa38b871e3451c5c78134d91cf56a4d14eaf1f4b77bc7055d2b5f3b5539161c8e713e5d5715c446cc085858c9a10008b32d32a1dd0099e4db931986a5c728bd3bfcadb44c8fa0090c298145bf2f82d8207017058037af269840fc405fb5ab9e2489621bfd1f55db4df6e3c8500e8fb998b337f15402fec0a2e247539e94cd0d1791200e4ea7d13329dd55e76d2345b77d34ba4644763aec20e6489b4b013693a58655f6d2cf77f3fa8553dcc17a609296abfa70464c78070c4359622c38eb9a3005c0c42bc5426ba5d7b315d3d70f4eb2ade1e401ed629f0e6753a11a7409d44bbcda6911faae8019df85e513ec87a16f9fbd15072a6ccea5f791547f0f1f8b407dde8a9e89fc80e36c7a1c14ece7eb1967372486fc3f2e609881d4c628f0d1bb6d473e119545bf69b1000f8d7642473ec3a7f232b4959ec10bfae334bf0a3aafd36d2011f4742e1bbee2c4250a195eca04825b9bbfff9580ac9d62affd5ab8d697b0c7d1ce413d85c810f851e19107de6b6223ed5c1b9572644926f5f1fb50c7c7a7aaf86b4af00f1de041765d5f634617c6bce8da06794dfd970163b677a56dbd9afbab7754f80dfa613cba7dacefda1388ed3994fd939357826f91f780b43ff8a8d5f3518e4f4b285f441299201f600c8f8647c796243769ab561715ebe116377465930010d841f38607758f9674accdbb8533ad8f92a9a3f381231d30df3e562f36ddd652403d26a528cdd7c1cf55ee9993685a41167901e73ae425cd6848d899bc26525020242b5e031c978b7225ff8bbd469647d5d73dfb08ec0f02f0605751e2896c985c5e53d09d14d108e74388b317e2f4fd46374798496798e15ccb0cb40f93e37a4cf4e0bcabe9b215d57b01a9804dd13ef8a8f4af7424b205bbc6945879b90a7f0230a795f24a876fff69a68bd1f96e5c842a6837b63a67123f09abdb1f072175a10ea218ad973be0c56635b7b9abc860fe158699ce8b77ce8316604607001c8abee41c206053f5a2d8807b10792493295fc0959980b99ffaf2d140b13f2278e9d1cd97ea055069e78a4096e5cb63af03e4b049ca5386acbb22f2edb7b552f809ff20c46597145bda616a167a50d661f78cbf9027ffa04d079ce4e6a5a3cb51f5344980b7df529f2b39e36dac54577da66bdfc3fcb3feb87b375c73c7d4667c7098a893acd09404e7074ddab1bae100719df2adf1cff5a50e88024a804db174e6211c1c0c74b68df58e0e58016b5c937109517338ac6185aaafb453d2e916f28b5eed645177afb9143860a75491abb39671667437815f9b1022f2563eefc51d653bb718a337212e1e4061c615349bd91d02cb95a50ac1711a48a48ad4a604323684f0f1e72d17dd68b517139452728ba8d403edf7d04eb958ea1e5547046609d29441df84672deed5021ec110ffb9e084b30f53fa45b8029f991fd3ddeabf0743d8974e8a54f937f5661396999514bc2d299c7b34bcc82173e9aacc3a4de7f98bf1f809ba166b1beaa08b5b97a2ae186f8b10cacfac87fe0c309d1a05144a25115aefaec291cbc22ed7cdaec73932115b70d841fa3518f5177e23968fbdb96dba02365489edc19c838d77332c7edd0c069d847a58364d26c35088421efff11d0933c148b962f376f66bff0e2ebf646c288dc0dc03832c85cfdfcf5f01aa3805eaf477b1c76764cef531ab3debba0fb3cc96e198d985fa0e86107efe7a9a03408cc0f4df588e44701721809e3e0c7cd0147dedd89f970898393fd09ccacc6ac20b6d3010e7e6c4153779f4372d6018e9e3319d211b805b8150a13c65d3e0d1c8433e017e58bdabeeedc522d2f22d53491843b0c930dc4363b1e0deb0dc87f43c89ff7919211923bfee0c15deb9aabfadaa5fb511bd8ffff59258af6530bab12b341cc144fb681a27c6f5363fb13fd7f0f75f9d9f55bd336fdc31c8da895b147fabc781a8fa8f90824d2bbe024ad609654736cd44ef90ad6a0c3381d03b6a176005d7364705f6bc983fe5b5e28fce7eb589acf633b96b8e90367655655a177f433858981d330b29d34f29ba42d35c97ce6b179aea90bdec5dbfcc7c76dfe394ebc94418c8c3fcc6d814e6b53c0ce7adac44ea5c8139817eff005b4351ad12191bc840e785b29bbe5ffcc44296acfa9d96246b528df9782cfeb4626e976fe9404e894c34ff33aea6445a4304781b92e030820d3f42f016c3c059e3f4d167ebbe44a5d9c1bbb87cf5720b7005b378491d95908e0ba05311eeefa6a51f34f0a5a05c494ae8eef53f741cab7475355b535fbc0bcb2ade73f4f99b16b52c797ebb5c02f7f8681e8e09f8f9b7d087bb9c56b76e05389ac508b176ce681e86a0d4e306a84fe6a841c9ec3849573c3edc0e2fe3fd0433753d9f3b156d1fa14b9bbbdb183ad3183c41e2c5a5a74f392366125bcd565571c696a3dda08d7dc6d3919965121fc34f988c4a10d60530f258099b5d885186ef05e96ca94b8458f5de1559faaa89f779c3f84a4f323525cb2f7465eaa88be2fd9286771caade1a0742d6e92a3b2f4a4a96387c93a53e9548c32d15cdcfb8ee4d7b91dd38bdea04c2eec214b5e1d46f71bdb8aae212db872374e3e45b1b7acefa408c5d14657be308f662de1c131a33d4a34661843d2cd680043a74ba9269eb7cd0156e3d958cb2d436ee0f4650029c5f3a95c0c857b36a2cf33d78f66ae604801cfe78adacc485c01b19e68dbbafc80ab929588f37957984d7a486d5fdb7626a714448f03ab76c9313deca3687143dcf66b03233c65ff1140125fbdf506b33f8ff4339dac884a85a4949f33646eec3c8fac7db8073e58b7348ef95562f8e1d394f8cac6c4d382ae69ed2bfedfd85cda224c0fdfe14776fa95b0f04923360c118a24bb33c387cad65c31f5e533a0180054d07b983d2a65d2fcf7c75b561d988fbace037a1039c68fa919abebafd9030c988cf4e62320c9cb072d36bf317ed58423f9495c4350926331a1198d82edab3510cb6d98b5408df5f4e02a4ab477d2fe88cb55146c6f19c9415373958cfc992fbc0b031b36c16ea53ed93b59e6944459059d6a8e16a05442d610e15e0ff4bc4092b951bbde375858c16ae2ec48d3a42b6da849278b89372eccd735f037ce9b05e5fc53b32d248003e1f03fcf547b8395ec2fd0b984adc2ff14b116c6e02ec5c794a3abfdf091486e23de5098bca5ef6567889eace9f0d6d57da67594cef25dcc60960f19a42b578ffb5758a89c2faca74449d9518debd8cd4cff1f25d6048c4dcc9e80a75590716fa28160ebe9bec3e1b74414fbcb089f9eee2ab38d39df9652774434f78ff92503705e0a948967ae9a9d3dc5e02532373bd7964c5f0e608b9a1521844ab60f54971fca5e49df540022b4f069414ead4a3a33956d3d8e69b19b5233f5071d1a4ac699cd719cf0e8e7e49d0825fe7a890c9bffc488f5c479fab3ef0355a127ae73b790a424aca3577ff65723f382a95623f6032dbfa95d05e177ee7f0bf32d0e22e23b2d86b0d9931d3b8b895f7051f8e2cd253a6cee1a602c911434b487ab904e1f33ccea658bb3dc6234c579fe2dee6dd155d28877b25e7b58873cfab839180530097cfcaf3f2e6b3236247ecd9a0b796f2dc793c6f38ddf70f62c1d4090968b68881d1661f905b44e40a145d3b498fa19c84ab1fab552a6b5abb4d02e82d1d5878c0144b13749ff1cdf06496034f15431762e9ee5037a113c92332e19328d21bbc1f49f6f56ac1772a1eb7e831281469fafb293faf105b0f3dcedf3049c98fe9ae514d1e146d1f94cb3f4b3d1e2fe0edc078dde1339a0717d940e24a916224d2e0a341fbbd0f5a964df43ecbcc40668c9956e2120b6d07f848aa164285d3b2ad60c07d0cedfc339d1f05a55ef813176e89f86c193c71e098b11fd201a7138f25068c53515d415c4318c45367eec5f81600be050c49c45f05d815922dcedbc85daea627d3ead35a919eb31601250ecc94f054531a683887d7faec6f873dbc268da5438eadc3a5e5128fc22536378abed7be799b7f6970d3a9879b12ba4171bb4707ffc4dc697a18f884ff328c5302fa790b4f9ca75058c65bc4431ba21509e066007df6bc3ec0339578ddc81e71a9a9132f5300d03e4d633528f6f137bd0c9f0503cd15691fe63741045744fbbd1e29558b0f23abdcc1dd1f7c61bb303f5ce52fec4523e3e73848bc91e526e7087126c3b5a4d7f1e0f516ab4b576f870485275230d77d68fd2225fe0cce5799717b0c8061c11729df5f8bb6e32a0c70688f79eaa2b4e7decffea0e1cdecbe597a381f10be5437fca3fcdc01fc5095980265b978d4e8f634d9141ce6eed10f59cb4e1dba6babe60a8e881cb9e1674291e3fbe60f005e17d3eeaa2e88e7da5d3ac9f3ff1296a52e3c23eff51576c1b6c433325ff3a05b470cc70b9a50737500337e57d9a6c97ec102a88fa1f8bd33ca270c495d33fd1ba5ba70b9e65cfe886912da8b407b0db5a34f310e1f2ee44476d46342af6bcb533b325e9c29ab6a4ce0dd6d6a454491bb1f9910e58a06a38e060afc80b8f2de6946fc3b04397ae64a3da719d8ea1029e310ad1ccdf582f5dca2ec4b3a139c778d0e8166090706f460523a5d3ce68571e3deeb463087bd9b5ad0f442d1fd800d04c4c60ef982bd498be9d441a76c3dc29c11ae169c4b268034addd7e57568fea35607bcc9ac15daad821b2045b898d07db7ba0cdcc52fe3527ab47a5b8973e7c2aa8862cc46ad5be2ccc896f49009d4cd3de359cd8e2e10a497a49dc696b98be2b2553c489eb8c177ad3d5a228e1257d31f937e6d9d2e51989db384728185739638a8f2f154f0dcba97a3463ad9388ec4973baa0f3fdacf28773eb5fd0948724203c201f73e7c5343d05a9d930c8903f5f5c8226ce544cc22a97fffaac00243f6a60904553686d5dd30490f61b8e78afabb18264bf824386888c4c2dd33511951aef181afac1a10ab1028ab2bfd8a2d8881c2daa5fa1940692798f0c6316bbefa535c7de005149df40a9407fd9f52a80c6ff0c224e7d16eb66bb694c8d210d12ed47c21aa8f387c3110a8979da88ddf2582b2343abefd88919c43dfc905f6d5939b073ba768004d1d880007c302535af3f45c0750d1f06681720d555344d9833b98da7eaca33b02e349685c0881441269b077c580e0b256d4117ea3af9ef9859443aa5ba24416e4beb59b4c1c7eca27fb3ef159889e1c300922c438dd3d67ee965fb97b863980a94519ba51eb6d1c33a4fe418e85181f09eb72e85963b3a200ee71e07f3f402dc20fdf2bd8e2a47628c247fb8a27c266917230adae113d50876d97cb489947869f4b7a0b702bbafb8882b141ba55d65a925d6a4538480a71a4c04019de0c48e2183bfd90fcefa02b5f2cb1d83dd2b6d2f8efe0cfbd80d5fdd879c42082f3983accf5762da1059f18cbeb1809c658d6df606f1d3715099334aba1028ac1484bcc361dab8709e023372d7d393735fbba234e9a3f3b40538d5f386048ffd58be263324d973bb77e7d7af7c0941fd4f10bf14515e71c698705819aedbf033b7987b23ed706c8735b8bee379925b332965ca40c93357d637fcce825533dcc5738e1291d4c8fdc32745694f9cf5f628bd8ff5736adc06c5d6221df6971813ffd608c0bf64e23767779ba9c3fa76f5a5f5df0a865cf28cd3fac6ad35b2669e909913202e70aa195b7d58e9bd0d1a7b0df00e06b36c7d147f85e052ed5cc32d3879d656180a8f5b9f0fd6f01d0a23c3936fefb366722a910db54072a3a1f34bb40e0d7f28b36da6a7eb90c82474aff3da40404cc3aff1b544bfb2c6a0ee2e1d59dce3f93515277da40d21d451989abc1febb45a42b814c5fcdcd8a32238eb21b3feefdb622f0dcfc77348295f1f00a6e990a33adf0caef0b567df6c85070d98ac056fad221a7aea3cf797540f6afd45d743e4fc9f68461c697f579bfcbdcf9b0895e5d7114b66ba9f1ef0f64146d6b1503c427bef80e160bb725d882eaa1a4cfc64953766a20c6c98cc25cd1f548f509726218bf45cf30c3ad867bd3a0a912377375712b4952de80fe9222c8877e81f922b098d4b173d2af83f24dc967046c045e0c5776b842646f6a257ec79ca49b932dd3c3f80e8a8b8ab82bb0602dad6dd57db0267bf4d8ee085ee4436832dc67cb64b6936c5093c1139c6fb2c23b61fa4e13e3a28b782d31fa17785350d54ef543dd712f9afb137ffe8256e1ef175247ae8fa661ed42bbc56c6daf17b28608ace28a77e7d3256ababeb54a5ced73cfb8aed5c74bf33af99281f585937b81ee0494265f5074dceddda6b07204357f907918b1483dba6a588d564b976dee184cc8ccdf04aadd38aa4af668615a72e0e5014de42124315fb169aa77ce9ede13ff31ce4c7cffc02fb6e8a3c617dca5c6651bd8025c42d265ca1962ece5c55a06a3c8bb07b7a9e47f146a43ae1575a51398e6dbc54f5d759922d4ccffbb874432eaa89b2840c2963e51270cd0d1e9474cf1288d723bae37b1b9ff0548844346dacc9b4f9369e2a0e9fbb3bc13813c9ff769afbfd8d5a33c6aacd020a2ed381876de8ccf64f5163288ea9fe708180df4ef0d42f2d0c29afa3d9ee0bc75b415bbc7a4ed34c87b5670386fce559d2d6f3938f42bc7697cb83947f719d68b47af6cc88b3f51bb68e4290ab5da171428fe1357c9cc9b2bc6426a91754718a12a279164e7dd2f0547d104c9e632703c5b64f61bcf4498eeac11c37d613d37443ba84121943f57bc0dc04c7da7bedb7c11a92244051ee8cd71e4242d4a1a24d1f2c1da3cc6fa49b765315a3d588d352085c0e5dbd4e734320ddd3688f042bd600f37a2271087d7a0c84b2d3ff28ed42823887338af22aad26ef2ad6bc08ad31b91447da3ec99038bc780d0f1e7663c23aa10d83acbd30f0d128534b6405feb594593995bfb15d0f87b87fdba6784b5297225c7fa3810fc4ab5f70c6ae390136a49ad42e4a176f963603257d20b9061f2a62c5c3818ea44980ab55328fab996a0fae819b70b81ce65274efcd45d82936fa0c460dd9850062ceb400e65255f64dea2291cc7c818fea23a7209537a85b743509027fa804elibcurl.so.4.6.0rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootcurl-mini-7.66.0-lp152.3.24.1.src.rpmcurl-devellibcurl-devellibcurl-mini-devellibcurl-mini-devel(aarch-64)pkgconfig(libcurl)@@    /bin/sh/usr/bin/pkg-configglibc-devellibcurl4-minirpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)this-is-only-for-build-envs7.66.03.0.4-14.6.0-14.0-15.2-1libcurl-devel4.14.1aKa?=@a?=@`@`.`.`Z``]`[)_@_@_@_5+@^^]A]x]p]p]1]/ \\9\P\@\@\@\Y@\v{\Z@\P@@\P@@\N\N\A\$[ٙ@[@[^[^[@[@[}P@[O+[M@Z@Z@ZZZ ZiZhu@Zhu@ZTZ@YYYW@YYJYJY@YS@YMYI@YA%@Y?XQ@X @X}@XX]XZnX@W;WRWW@W_WUeW+5V@V@VT@V@VV^@V$@V#VUݪ@U@UUc@Uy@U@U\w@U@U7@UQT T8Tq@T6TeTHPedro Monreal Pedro Monreal Pedro Monreal Pedro Monreal Pedro Monreal Pedro Monreal Pedro Monreal Pedro Monreal Pedro Monreal Pedro Monreal Pedro Monreal Pedro Monreal Pedro Monreal Pedro Monreal Pedro Monreal Gonzalez Pedro Monreal Gonzalez Pedro Monreal Gonzalez Pedro Monreal Gonzalez Pedro Monreal Gonzalez Pedro Monreal Gonzalez Pedro Monreal Gonzalez Pedro Monreal Gonzalez Pedro Monreal Gonzalez Pedro Monreal Gonzalez Pedro Monreal Gonzalez Pedro Monreal Gonzalez Pedro Monreal Gonzalez Pedro Monreal Gonzalez Fabian Vogt Stephan Kulow Pedro Monreal Gonzalez Pedro Monreal Gonzalez Pedro Monreal Gonzalez Jan Engelhardt Pedro Monreal Gonzalez Vítězslav Čížek sean@suspend.netPedro Monreal Gonzalez Pedro Monreal Gonzalez Pedro Monreal Gonzalez Pedro Monreal Gonzalez pmonrealgonzalez@suse.comKarol Babioch kbabioch@suse.compgajdos@suse.compgajdos@suse.comvcizek@suse.compmonrealgonzalez@suse.compmonrealgonzalez@suse.compmonrealgonzalez@suse.comtchvatal@suse.comnormand@linux.vnet.ibm.comasn@cryptomilk.orgpmonrealgonzalez@suse.comnormand@linux.vnet.ibm.compmonrealgonzalez@suse.compmonrealgonzalez@suse.compmonrealgonzalez@suse.comzaitor@opensuse.orgschwab@suse.depmonrealgonzalez@suse.compmonrealgonzalez@suse.compmonrealgonzalez@suse.comdimstar@opensuse.orgdimstar@opensuse.orgidonmez@suse.comidonmez@suse.comlnussel@suse.deidonmez@suse.comidonmez@suse.comidonmez@suse.comastieger@suse.comidonmez@suse.comidonmez@suse.comidonmez@suse.comidonmez@suse.comidonmez@suse.compjanouch@suse.devcizek@suse.comastieger@suse.comidonmez@suse.comalarrosa@suse.comidonmez@suse.comastieger@suse.commpluskal@suse.comvcizek@suse.comidonmez@suse.comidonmez@suse.comvcizek@suse.comcrrodriguez@opensuse.orgmpluskal@suse.comvcizek@suse.comvcizek@suse.comschwab@suse.denormand@linux.vnet.ibm.comvcizek@suse.commpluskal@suse.comvcizek@suse.comvcizek@suse.comvcizek@suse.comlnussel@suse.desor.alexei@meowr.rumpluskal@suse.comvcizek@suse.commeissner@suse.comvcizek@suse.comcrrodriguez@opensuse.org- MIME: Properly check Content-Type even if it has parameters * Add curl-check-content-type.patch [bsc#1190153]- Security fix: [bsc#1190374, CVE-2021-22947] * STARTTLS protocol injection via MITM * Add curl-CVE-2021-22947.patch- Security fix: [bsc#1190373, CVE-2021-22946] * Protocol downgrade required TLS bypassed * Add curl-CVE-2021-22946.patch- Security fix: [bsc#1188220, CVE-2021-22925] * TELNET stack contents disclosure again * Add curl-CVE-2021-22925.patch- Security fix: [bsc#1188219, CVE-2021-22924] * Bad connection reuse due to flawed path name checks * Add curl-CVE-2021-22924.patch- Security fix: Disable the metalink feature: * Insufficiently Protected Credentials [bsc#1188218, CVE-2021-22923] * Wrong content via metalink not discarded [bsc#1188217, CVE-2021-22922]- Security fix: [bsc#1186114, CVE-2021-22898] * TELNET stack contents disclosure - Add curl-CVE-2021-22898.patch- Allow partial chain verification [jsc#SLE-17956] * Have intermediate certificates in the trust store be treated as trust-anchors, in the same way as self-signed root CA certificates are. This allows users to verify servers using the intermediate cert only, instead of needing the whole chain. * Set FLAG_TRUSTED_FIRST unconditionally. * Do not check partial chains with CRL check. - Add curl-X509_V_FLAG_PARTIAL_CHAIN.patch- Security fix: [bsc#1183934, CVE-2021-22890] * When using a HTTPS proxy and TLS 1.3, libcurl can confuse session tickets arriving from the HTTPS proxy but work as if they arrived from the remote server and then wrongly "short-cut" the host handshake. - Add curl-CVE-2021-22890.patch- Security fix: [bsc#1183933, CVE-2021-22876] * The automatic referer leaks credentials - Add curl-CVE-2021-22876.patch- Security fix: [bsc#1179593, CVE-2020-8286] * Inferior OCSP verification: libcurl offers "OCSP stapling" via the 'CURLOPT_SSL_VERIFYSTATUS' option that, when set, verifies the OCSP response that a server responds with as part of the TLS handshake. It then aborts the TLS negotiation if something is wrong with the response. The same feature can be enabled with '--cert-status' using the curl tool. * As part of the OCSP response verification, a client should verify that the response is indeed set out for the correct certificate. This step was not performed by libcurl when built or told to use OpenSSL as TLS backend. - Add curl-CVE-2020-8286.patch- Security fix: [bsc#1179399, CVE-2020-8285] * FTP wildcard stack overflow: The wc_statemach() internal function has been rewritten to use an ordinary loop instead of the recursive approach. - Add curl-CVE-2020-8285.patch- Security fix: [bsc#1179398, CVE-2020-8284] * Trusting FTP PASV responses: When curl performs a passive FTP transfer, it first tries the 'EPSV' command and if that is not supported, it falls back to using 'PASV'. A malicious server can use the 'PASV' response to trick curl into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed. * The IP address part of the response is now ignored by default, by making 'CURLOPT_FTP_SKIP_PASV_IP' default to '1L'. The same goes for the command line tool, which then might need '--no-ftp-skip-pasv-ip' set to prevent curl from ignoring the address in the server response. - Add curl-CVE-2020-8284.patch- Security fix: [bsc#1175109, CVE-2020-8231] * An application that performs multiple requests with libcurl's multi API and sets the 'CURLOPT_CONNECT_ONLY' option, might in rare circumstances experience that when subsequently using the setup connect-only transfer, libcurl will pick and use the wrong connection and instead pick another one the application has created since then. - Add curl-CVE-2020-8231.patch- Security fix: [bsc#1173027, CVE-2020-8177] * curl can be tricked my a malicious server to overwrite a local file when using '-J' ('--remote-header-name') and '-i' ('--head') in the same command line. - Add curl-CVE-2020-8177.patch- Security fix: [bsc#1173026, CVE-2020-8169] * Partial password leak over DNS on HTTP redirect - Add curl-CVE-2020-8169.patch- Fix segfault in zypper ref: [bsc#1156481] * remove_handle: clear expire timers after multi_done() * Add patch curl-expire-clear.patch- Update to 7.66.0 [bsc#1149496, CVE-2019-5482][bsc#1149495, CVE-2019-5481] [bsc#1149604, bsc#1149572, jsc#SLE-9295] * Changes: - CURLINFO_RETRY_AFTER: parse the Retry-After header value - HTTP3: initial (experimental still not working) support - curl: --sasl-authzid added to support CURLOPT_SASL_AUTHZID from the tool - curl: support parallel transfers with -Z - curl_multi_poll: a sister to curl_multi_wait() that waits more - sasl: Implement SASL authorisation identity via CURLOPT_SASL_AUTHZID * Bugfixes: - CVE-2019-5481: FTP-KRB double-free - CVE-2019-5482: TFTP small blocksize heap buffer overflow - CMake: remove needless newlines at end of gss variables - CMake: use platform dependent name for dlopen() library - CURLINFO docs: mention that in redirects times are added - CURLOPT_ALTSVC.3: use a "" file name to not load from a file - CURLOPT_ALTSVC_CTRL.3: remove CURLALTSVC_ALTUSED - CURLOPT_HEADERFUNCTION.3: clarify - CURLOPT_HTTP_VERSION: seting this to 3 forces HTTP/3 use directly - CURLOPT_READFUNCTION.3: provide inline example - CURLOPT_SSL_VERIFYHOST: treat the value 1 as 2 - Curl_addr2string: take an addrlen argument too - Curl_fillreadbuffer: avoid double-free trailer buf on error - HTTP: use chunked Transfer-Encoding for HTTP_POST if size unknown - alt-svc: add protocol version selection masking - alt-svc: fix removal of expired cache entry - alt-svc: make it use h3-22 with ngtcp2 as well - alt-svc: more liberal ALPN name parsing - alt-svc: send Alt-Used: in redirected requests - alt-svc: with quiche, use the quiche h3 alpn string - asyn-thread: create a socketpair to wait on - cleanup: move functions out of url.c and make them static - cleanup: remove the 'numsocks' argument used in many places - configure: avoid undefined check_for_ca_bundle - curl.h: add CURL_HTTP_VERSION_3 to the version enum - curl: cap the maximum allowed values for retry time arguments - curl: handle a libcurl build without netrc support - curl: make use of CURLINFO_RETRY_AFTER when retrying - curl: use CURLINFO_PROTOCOL to check for HTTP(s) - curl_global_init_mem.3: mention it was added in 7.12.0 - curl_version: bump string buffer size to 250 - curl_version_info.3: mentioned ALTSVC and HTTP3 - curl_version_info: offer quic (and h3) library info - curl_version_info: provide nghttp2 details - defines: avoid underscore-prefixed defines - docs/ALTSVC: remove what works and the experimental explanation - docs/EXPERIMENTAL: explain what it means and what's experimental now - docs/MANUAL.md: converted to markdown from plain text - docs/examples/curlx: fix errors - docs: s/curl_debug/curl_dbg_debug in comments and docs - easy: resize receive buffer on easy handle reset - examples: Avoid reserved names in hiperfifo examples - examples: add http3.c, altsvc.c and http3-present.c - http09: disable HTTP/0.9 by default in both tool and library - http2: when marked for closure and wanted to close == OK - http2_recv: trigger another read when the last data is returned - http: fix use of credentials from URL when using HTTP proxy - http_negotiate: improve handling of gss_init_sec_context() failures - md4: Use our own MD4 when no crypto libraries are available - multi: call detach_connection before Curl_disconnect - nss: use TLSv1.3 as default if supported - openssl: build warning free with boringssl - openssl: use SSL_CTX_set__proto_version() when available - plan9: add support for running on Plan 9 - progress: reset download/uploaded counter between transfers - readwrite_data: repair setting the TIMER_STARTTRANSFER stamp - scp: fix directory name length used in memcpy - smb: init *msg to NULL in smb_send_and_recv() - smtp: check for and bail out on too short EHLO response - source: remove names from source comments - spnego_sspi: add typecast to fix build warning - src/makefile: fix uncompressed hugehelp.c generation - ssh-libssh: do not specify O_APPEND when not in append mode - ssh: move code into vssh for SSH backends - sspi: fix memory leaks - tests: Replace outdated test case numbering documentation - tftp: return error when packet is too small for options - timediff: make it 64 bit (if possible) even with 32 bit time_t - travis: reduce number of torture tests in 'coverage' - url: make use of new HTTP version if alt-svc has one - urlapi: verify the IPv6 numerical address - urldata: avoid 'generic', use dedicated pointers - vauth: Use CURLE_AUTH_ERROR for auth function errors * Removed patches: - curl-CVE-2018-0500.patch - curl-CVE-2018-14618.patch - curl-CVE-2018-16839.patch - curl-CVE-2018-16840.patch - curl-CVE-2018-16842.patch - curl-CVE-2018-16890.patch - curl-CVE-2019-3822.patch - curl-CVE-2019-3823.patch - curl-CVE-2019-5436.patch - curl-CVE-2019-5481.patch - curl-CVE-2019-5482.patch- Security fix: [bsc#1149496,CVE-2019-5482] * TFTP small blocksize heap buffer overflow * Added curl-CVE-2019-5482.patch- Security fix: [bsc#1149495,CVE-2019-5481] * FTP-KRB: double-free during kerberos FTP data transfer * Added curl-CVE-2019-5481.patch- Update to 7.65.3 * progress: make the progress meter appear again- Update to 7.65.2 * Bugfixes: - CIPHERS.md: Explain Schannel error SEC_E_ALGORITHM_MISMATCH - CMake: Fix finding Brotli on case-sensitive file systems - CURLOPT_RANGE.3: Caution against using it for HTTP PUT - CURLOPT_SEEKDATA.3: fix variable name - bindlocal: detect and avoid IP version mismatches in bind() - build: fix Codacy warnings - c-ares: honor port numbers in CURLOPT_DNS_SERVERS - config-os400: add getpeername and getsockname defines - configure: --disable-progress-meter - configure: fix --disable-code-coverage - configure: more --disable switches to toggle off individual features - configure: remove CURL_DISABLE_TLS_SRP - conn_maxage: move the check to prune_dead_connections() - curl: skip CURLOPT_PROXY_CAPATH for disabled-proxy builds - docs: Explain behavior change in --tlsv1. options since 7.54 - docs: Fix links to OpenSSL docs - docs: fix string suggesting HTTP/2 is not the default - headers: Remove no longer exported functions - http2: call done_sending on end of upload - http2: don't call stream-close on already closed streams - http2: remove CURL_DISABLE_TYPECHECK define - http: allow overriding timecond with custom header - http: clarify header buffer size calculation - krb5: fix compiler warning - lib: Use UTF-8 encoding in comments - libcurl: Restrict redirect schemes to HTTP, HTTPS, FTP and FTPS - multi: enable multiplexing by default (again) - multi: fix the transfer hashes in the socket hash entries - multi: make sure 'data' can present in several sockhash entries - netrc: Return the correct error code when out of memory - nss: don't set unused parameter - nss: inspect returnvalue of token check - nss: only cache valid CRL entries - openssl: define HAVE_SSL_GET_SHUTDOWN based on version number - openssl: disable engine if OPENSSL_NO_UI_CONSOLE is defined - openssl: fix pubkey/signature algorithm detection in certinfo - os400: make vsetopt() non-static as Curl_vsetopt() for os400 support - quote.d: asterisk prefix works for SFTP as well - runtests: keep logfiles around by default - runtests: report single test time + total duration - test1165: verify that CURL_DISABLE_ symbols are in sync - test1521: adapt to SLISTPOINT - test1523: test CURLOPT_LOW_SPEED_LIMIT - test153: fix content-length to avoid occasional hang - test188/189: fix Content-Length - tests: have runtests figure out disabled features - tests: support non-localhost HOSTIP for dict/smb servers - tests: update fixed IP for hostip/clientip split - tool_cb_prg: Fix integer overflow in progress bar - typecheck: CURLOPT_CONNECT_TO takes an slist too - typecheck: add 3 missing strings and a callback data pointer - unit1654: cleanup on memory failure - unpause: trigger a timeout for event-based transfers - url: Fix CURLOPT_MAXAGE_CONN time comparison - Rebased patch curl-use_OPENSSL_config.patch - Disable new added failing test1165- Update to 7.65.1 * Bugfixes: - CURLOPT_LOW_SPEED_* repaired - NTLM: reset proxy "multipass" state when CONNECT request is done - PolarSSL: deprecate support step 1. Removed from configure - cmake: check for if_nametoindex() - cmake: support CMAKE_OSX_ARCHITECTURES when detecting SIZEOF variables - conncache: Remove the DEBUGASSERT on length check - conncache: make "bundles" per host name when doing proxy tunnels - curl_share_setopt.3: improve wording - dump-header.d: spell out that no headers == empty file - example/http2-download: fix format specifier - examples: cleanups and compiler warning fixes - http2: Stop drain from being permanently set - http: don't parse body-related headers in bodyless responses - md4: build correctly with openssl without MD4 - md4: include the mbedtls config.h to get the MD4 info - multi: track users of a socket better - nss: allow to specify TLS 1.3 ciphers if supported by NSS - parse_proxy: make sure portptr is initialized - parse_proxy: use the IPv6 zone id if given - sectransp: handle errSSLPeerAuthCompleted from SSLRead() - singlesocket: use separate variable for inner loop - ssl: Update outdated "openssl-only" comments for supported backends - tests: add HAProxy keywords - tests: make test 1420 and 1406 work with rtsp-disabled libcurl - tls13-docs: mention it is only for OpenSSL >= 1.1.1 - tool_setopt: for builds with disabled-proxy, skip all proxy setopts() - url: fix bad feature-disable #ifdef - url: use correct port in ConnectionExists()- Update to 7.65.0 [bsc#1135176, CVE-2019-5435][bsc#1135170, CVE-2019-5436] * Changes: - CURLOPT_DNS_USE_GLOBAL_CACHE: removed - CURLOPT_MAXAGE_CONN: set the maximum allowed age for conn reuse - pipelining: removed * Bugfixes: - CVE-2019-5435: Integer overflows in curl_url_set - CVE-2019-5436: tftp: use the current blksize for recvfrom() - --config: clarify that initial : and = might need quoting - CURLMOPT_TIMERFUNCTION.3: warn about the recursive risk - CURLOPT_ADDRESS_SCOPE: fix range check and more - CURLOPT_CHUNK_BGN_FUNCTION.3: document the struct and time value - CURLOPT_READFUNCTION.3: see also CURLOPT_UPLOAD_BUFFERSIZE - CURL_MAX_INPUT_LENGTH: largest acceptable string input size - Curl_disconnect: treat all CONNECT_ONLY connections as "dead" - OS400/ccsidcurl: replace use of Curl_vsetopt - OpenSSL: Report -fips in version if OpenSSL is built with FIPS - WRITEFUNCTION: add missing set_in_callback around callback - altsvc: Fix building with cookies disabled - auth: Rename the various authentication clean up functions - base64: build conditionally if there are users - cmake: avoid linking executable for some tests with cmake 3.6+ - cmake: clear CMAKE_REQUIRED_LIBRARIES after each use - cmake: set SSL_BACKENDS - configure: avoid unportable '==' test(1) operator - configure: error out if OpenSSL wasn't detected when asked for - configure: fix default location for fish completions - cookie: Guard against possible NULL ptr deref - curl: make code work with protocol-disabled libcurl - curl: report error for "--no-" on non-boolean options - curlver.h: use parenthesis in CURL_VERSION_BITS macro - docs/INSTALL: fix broken link - doh: acknowledge CURL_DISABLE_DOH - doh: disable DOH for the cases it doesn't work - examples: remove unused variables - ftplistparser: fix LGTM alert "Empty block without comment" - hostip: acknowledge CURL_DISABLE_SHUFFLE_DNS - http: Ignore HTTP/2 prior knowledge setting for HTTP proxies - http: acknowledge CURL_DISABLE_HTTP_AUTH - http: mark bundle as not for multiuse on < HTTP/2 response - http_digest: Don't expose functions when HTTP and Crypto Auth are disabled - http_negotiate: do not treat failure of gss_init_sec_context() as fatal - http_ntlm: Corrected the name of the include guard - http_ntlm_wb: Handle auth for only a single request - http_ntlm_wb: Return the correct error on receiving an empty auth message - lib509: add missing include for strdup - lib557: initialize variables - mbedtls: enable use of EC keys - mime: acknowledge CURL_DISABLE_MIME - multi: improved HTTP_1_1_REQUIRED handling - netrc: acknowledge CURL_DISABLE_NETRC - nss: allow fifos and character devices for certificates - nss: provide more specific error messages on failed init - ntlm: Fix misaligned function comments for Curl_auth_ntlm_cleanup - ntlm: Support the NT response in the type-3 when OpenSSL doesn't include MD4 - openssl: mark connection for close on TLS close_notify - openvms: Remove pre-processor for SecureTransport - parse_proxy: use the URL parser API - parsedate: disabled on CURL_DISABLE_PARSEDATE - pingpong: disable more when no pingpong protocols are enabled - polarssl_threadlock: remove conditionally unused code - progress: acknowledge CURL_DISABLE_PROGRESS_METER - proxy: acknowledge DISABLE_PROXY more - resolve: apply Happy Eyeballs philosophy to parallel c-ares queries - revert "multi: support verbose conncache closure handle" - sasl: Don't send authcid as authzid for the PLAIN mechanism as per RFC 4616 - sasl: only enable if there's a protocol enabled using it - singleipconnect: show port in the verbose "Trying ..." message - socks5: user name and passwords must be shorter than 256 - socks: fix error message - socksd: new SOCKS 4+5 server for tests - spnego_gssapi: fix return code on gss_init_sec_context() failure - ssh-libssh: remove unused variable - ssh: define USE_SSH if SSH is enabled (any backend) - ssh: move variable declaration to where it's used - test1002: correct the name - test2100: Fix typos in test description - tests: Run global cleanup at end of tests - tests: make Impacket (SMB server) Python 3 compatible - tool_cb_wrt: fix bad-function-cast warning - tool_formparse: remove redundant assignment - tool_help: Warn if curl and libcurl versions do not match - tool_help: include for strcasecmp - url: always clone the CUROPT_CURLU handle - url: convert the zone id from a IPv6 URL to correct scope id - urlapi: add CURLUPART_ZONEID to set and get - urlapi: increase supported scheme length to 40 bytes - urlapi: require a non-zero host name length when parsing URL - urlapi: stricter CURLUPART_PORT parsing - urlapi: strip off zone id from numerical IPv6 addresses - urlapi: urlencode characters above 0x7f correctly - vauth/cleartext: update the PLAIN login to match RFC 4616 - vauth/oauth2: Fix OAUTHBEARER token generation - vauth: Fix incorrect function description for Curl_auth_user_contains_domain - vtls: fix potential ssl_buffer stack overflow - wildcard: disable from build when FTP isn't present - xattr: skip unittest on unsupported platforms- Security fix [bsc#1135170, CVE-2019-5436] * A heap buffer overflow exists in tftp_receive_packet that receives data from a TFTP server * Added curl-CVE-2019-5436.patch- Install curl.fish completions file from curl rather than from the fish package- update to version 7.64.1 * Changes: - alt-svc: experiemental support added - configure: add --with-amissl * Bugfixes: - AppVeyor: switch VS 2015 builds to VS 2017 image - CURLU: fix NULL dereference when used over proxy - Curl_easy: remove req.maxfd - never used! - Curl_resolv: fix a gcc -Werror=maybe-uninitialized warning - DoH: inherit some SSL options from user's easy handle - Secure Transport: no more "darwinssl" - Secure Transport: tvOS 11 is required for ALPN support - cirrus: Added FreeBSD builds using Cirrus CI - cleanup: make local functions static - cli tool: do not use mime.h private structures - cmdline-opts/proxytunnel.d: the option tunnnels all protocols - configure: add additional libraries to check for LDAP support - configure: remove the unused fdopen macro - configure: show features as well in the final summary - conncache: use conn->data to know if a transfer owns it - connection: never reuse CONNECT_ONLY connections - connection_check: restore original conn->data after the check - connection_check: set ->data to the transfer doing the check - cookie: Add support for cookie prefixes - cookies: dotless names can set cookies again - cookies: fix NULL dereference if flushing cookies with no CookieInfo set - curl.1: --user and --proxy-user are hidden from ps output - curl.1: mark the argument to --cookie as - curl.h: use __has_declspec_attribute for shared builds - curl: display --version features sorted alphabetically - curl: fix FreeBSD compiler warning in the --xattr code - curl: remove MANUAL from -M output - curl_easy_duphandle.3: clarify that a duped handle has no shares - curl_multi_remove_handle.3: use at any time, just not from within callbacks - curl_url.3: this API is not experimental anymore - dns: release sharelock as soon as possible - docs: update max-redirs.d phrasing - examples/10-at-a-time.c: improve readability and simplify - examples/cacertinmem.c: use multiple certificates for loading CA-chain - examples/crawler: Fix the Accept-Encoding setting - examples/ephiperfifo.c: various fixes - examples/externalsocket: add missing close socket calls - examples/http2-download: cleaned up - examples/http2-serverpush: add some sensible error checks - examples/http2-upload: cleaned up - examples/httpcustomheader: Value stored to 'res' is never read - examples/postinmemory: Potential leak of memory pointed to by 'chunk.memory' - examples/sftpuploadresume: Value stored to 'result' is never read - examples: only include - examples: remove recursive calls to curl_multi_socket_action - examples: remove superfluous null-pointer checks - file: fix "Checking if unsigned variable 'readcount' is less than zero." - fnmatch: disable if FTP is disabled - gnutls: remove call to deprecated gnutls_compression_get_name - gopher: remove check for path == NULL - gssapi: fix deprecated header warnings - hostip: make create_hostcache_id avoid alloc + free - http2: multi_connchanged() moved from multi.c, only used for h2 - http2: verify :athority in push promise requests - http: make adding a blank header thread-safe - http: send payload when (proxy) authentication is done - http: set state.infilesize when sending multipart formposts - makefile: make checksrc and hugefile commands "silent" - mbedtls: make it build even if MBEDTLS_VERSION_C isn't set - mbedtls: release sessionid resources on error - memdebug: log pointer before freeing its data - memdebug: make debug-specific functions use curl_dbg_ prefix - mime: put the boundary buffer into the curl_mime struct - multi: call multi_done on connect timeouts, fixes CURLINFO_TOTAL_TIME - multi: remove verbose "Expire in" ... messages - multi: removed unused code for request retries - multi: support verbose conncache closure handle - negotiate: fix for HTTP POST with Negotiate - openssl: add support for TLS ASYNC state - openssl: if cert type is ENG and no key specified, key is ENG too - pretransfer: don't strlen() POSTFIELDS set for GET requests - rand: Fix a mismatch between comments in source and header - runtests: detect "schannel" as an alias for "winssl" - schannel: be quiet - remove verbose output - schannel: close TLS before removing conn from cache - schannel: support CALG_ECDH_EPHEM algorithm - scripts/completion.pl: also generate fish completion file - singlesocket: fix the 'sincebefore' placement - source: fix two 'nread' may be used uninitialized warnings - ssh: fix Condition '!status' is always true - ssh: loop the state machine if not done and not blocking - strerror: make the strerror function use local buffers - test578: make it read data from the correct test - tests: Fixed XML validation errors in some test files - tests: add stderr comparison to the test suite - tests: fix multiple may be used uninitialized warnings - threaded-resolver: shutdown the resolver thread without error message - tool_cb_wrt: fix writing to Windows null device NUL - tool_getpass: termios.h is present on AmigaOS 3, but no tcgetattr/tcsetattr - tool_operate: build on AmigaOS - tool_operate: fix typecheck warning - transfer.c: do not compute length of undefined hex buffer - travis: add build using gnutls - travis: add scan-build - travis: bump the used wolfSSL version to 4.0.0 - travis: enable valgrind for the iconv tests - travis: use updated compiler versions: clang 7 and gcc 8 - unit1307: require FTP support - unit1651: survive curl_easy_init() fails - url/idnconvert: remove scan for <= 32 ascii values - url: change conn shutdown order to ensure SOCKETFUNCTION callbacks - urlapi: reduce variable scope, remove unreachable 'break' - urldata: convert bools to bitfields and move to end - urldata: simplify bytecounters - urlglob: Argument with 'nonnull' attribute passed null - version.c: silent scan-build even when librtmp is not enabled - vtls: rename some of the SSL functions - wolfssl: stop custom-adding curves - x509asn1: "Dereference of null pointer" - x509asn1: cleanup and unify code layout - zsh.pl: escape ':' character - zsh.pl: update regex to better match curl -h output - Dropped patches fixed upstream: * 0001-connection_check-set-data-to-the-transfer-doing-the-.patch * 0002-connection_check-restore-original-conn-data-after-th.patch * curl-singlesocket-sincebefore-placement.patch- Fix variable placement that wasn't properly reset within a loop missing to notify sockets. [bsc#1129083, bsc#1129470] * Added curl-singlesocket-sincebefore-placement.patch- Add patches to fix use-after-free (boo#1127849): * 0001-connection_check-set-data-to-the-transfer-doing-the-.patch * 0002-connection_check-restore-original-conn-data-after-th.patch- BuildRequire libcurl4-mini for !bootstrap to avoid build cycles due to cmake pulling libcurl4- update to version 7.64.0 [bcs#1123371, CVE-2018-16890][bcs#1123377, CVE-2019-3822] [bcs#1123378, CVE-2019-3823] * Changes: - cookies: leave secure cookies alone - hostip: support wildcard hosts - http: Implement trailing headers for chunked transfers - http: added options for allowing HTTP/0.9 responses - timeval: Use high resolution timestamps on Windows * Bugfixes: - CVE-2018-16890: NTLM type-2 out-of-bounds buffer read - CVE-2019-3822: NTLMv2 type-3 header stack buffer overflow - CVE-2019-3823: SMTP end-of-response out-of-bounds read - FAQ: remove mention of sourceforge for github - OS400: handle memory error in list conversion - OS400: upgrade ILE/RPG binding. - README: add codacy code quality badge - Revert http_negotiate: do not close connection - THANKS: added several missing names from year <= 2000 - build: make 'tidy' target work for metalink builds - cmake: added checks for variadic macros - cmake: updated check for HAVE_POLL_FINE to match autotools - cmake: use lowercase for function name like the rest of the code - configure: detect xlclang separately from clang - configure: fix recv/send/select detection on Android - configure: rewrite --enable-code-coverage - conncache_unlock: avoid indirection by changing input argument type - cookie: fix comment typo - cookies: allow secure override when done over HTTPS - cookies: extend domain checks to non psl builds - cookies: skip custom cookies when redirecting cross-site - curl --xattr: strip credentials from any URL that is stored - curl -J: refuse to append to the destination file - curl/urlapi.h: include "curl.h" first - curl_multi_remove_handle() don't block terminating c-ares requests - darwinssl: accept setting max-tls with default min-tls - disconnect: separate connections and easy handles better - disconnect: set conn->data for protocol disconnect - docs/version.d: mention MultiSSL - docs: fix the --tls-max description - docs: use $(INSTALL_DATA) to install man page - docs: use meaningless port number in CURLOPT_LOCALPORT example - gopher: always include the entire gopher-path in request - http2: clear pause stream id if it gets closed - if2ip: remove unused function Curl_if_is_interface_name - libssh: do not let libssh create socket - libssh: enable CURLOPT_SSH_KNOWNHOSTS and CURLOPT_SSH_KEYFUNCTION for libssh - libssh: free sftp_canonicalize_path() data correctly - libtest/stub_gssapi: use "real" snprintf - mbedtls: use VERIFYHOST - multi: multiplexing improvements - multi: set the EXPIRE_*TIMEOUT timers at TIMER_STARTSINGLE time - ntlm: fix NTMLv2 compliance - ntlm_sspi: add support for channel binding - openssl: adapt to 3.0.0, OpenSSL_version_num() is deprecated - openssl: fix the SSL_get_tlsext_status_ocsp_resp call - openvms: fix OpenSSL discovery on VAX - openvms: fix typos in documentation - os400: add a missing closing bracket - os400: fix extra parameter syntax error - pingpong: change default response timeout to 120 seconds - pingpong: ignore regular timeout in disconnect phase - printf: fix format specifiers - runtests.pl: Fix perl call to include srcdir - schannel: fix compiler warning - schannel: preserve original certificate path parameter - schannel: stop calling it "winssl" - sigpipe: if mbedTLS is used, ignore SIGPIPE - smb: fix incorrect path in request if connection reused - ssh: log the libssh2 error message when ssh session startup fails - test1558: verify CURLINFO_PROTOCOL on file:// transfer - test1561: improve test name - test1653: make it survive torture tests - tests: allow tests to pass by 2037-02-12 - tests: move objnames-* from lib into tests - timediff: fix math for unsigned time_t - timeval: Disable MSVC Analyzer GetTickCount warning - tool_cb_prg: avoid integer overflow - travis: added cmake build for osx - urlapi: Fix port parsing of eol colon - urlapi: distinguish possibly empty query - urlapi: fix parsing ipv6 with zone index - urldata: rename easy_conn to just conn - winbuild: conditionally use /DZLIB_WINAPI - wolfssl: fix memory-leak in threaded use - spnego_sspi: add support for channel binding- Security fix [bsc#1123378, CVE-2019-3823] * SMTP end-of-response out-of-bounds read * Added patch curl-CVE-2019-3823.patch- Security fix [bsc#1123377, CVE-2019-3822] * NTLMv2 type-3 header stack buffer overflow * Added patch curl-CVE-2019-3822.patch- Fix wrong summary, curl is at version 7, not 4.- Security fix [bsc#1123371, CVE-2018-16890] * NTLM type-2 out-of-bounds buffer read * Added patch curl-CVE-2018-16890.patch- Provide libcurl4 = %version in the mini library package- Update to version 7.63.0 Changes: * curl: add %{stderr} and %{stdout} for --write-out * curl: add undocumented option --dump-module-paths for w32 * setopt: add CURLOPT_CURLU Bugfixes: * (lib)curl.rc: fixup for minor bugs * CURLINFO_REDIRECT_URL: extract the Location: header field unvalidated * CURLOPT_HEADERFUNCTION.3: match 'nitems' name in synopsis/desc * CURLOPT_WRITEFUNCTION.3: spell out that it gets called many times * Curl_follow: accept non-supported schemes for "fake" redirects * KNOWN_BUGS: add --proxy-any connection issue * NTLM: Remove redundant ifdef USE_OPENSS * NTLM: force the connection to HTTP/1.1 * OS400: add URL API ccsid wrappers and sync ILE/RPG bindings * SECURITY-PROCESS: bountygraph shuts down again * TODO: Have the URL API offer IDN decoding * ares: remove fd from multi fd set when ares is about to close the fd * axtls: removed * checksrc: add COPYRIGHTYEAR check * cmake: fix MIT/Heimdal Kerberos detection * configure: include all libraries in ssl-libs fetch * configure: show CFLAGS, LDFLAGS etc in summary * connect: fix building for recent versions of Minix * cookies: create the cookiejar even if no cookies to save * cookies: expire "Max-Age=0" immediately * curl: --local-port range was not "including" * curl: fix --local-port integer overflow * curl: fix memory leak reading --writeout from file * curl: fixed UTF-8 in current console code page (Win) * curl_easy_perform: fix timeout handling * curl_global_sslset(): id == -1 is not necessarily an error * curl_multibyte: fix a malloc overcalculation * curle: move deprecated error code to ifndef block * docs: curl_formadd field and file names are now escaped * docs: escape "\n" codes * doh: fix memory leak in OOM situation * doh: make it work for h2-disabled builds too * examples/ephiperfifo: report error when epoll_ctl fails * ftp: avoid unsigned int overflows in FTP listing parser * host names: allow trailing dot in name resolve, then strip it * http2: Upon HTTP_1_1_REQUIRED, retry the request with HTTP/1.1 * http: don't set CURLINFO_CONDIITON_UNMET for http status code 204 * http: fix HTTP DIgest auth to include query in URI * http_negotiate: do not close connection until negotiation is completed * impacket: add LICENSE * infof: clearly indicate truncation * ldap: fix LDAP URL parsing regressions * libcurl: stop reading from paused transfers * mprintf: avoid unsigned integer overflow warning * netrc: don't ignore the login name specified with "--user" * nss: Fall back to latest supported SSL version * nss: Fix compatibility with nss versions 3.14 to 3.15 * nss: fix fallthrough comment to fix picky compiler warning * nss: remove version selecting dead code * nss: set default max-tls to 1.3/1.2 * openssl: Remove SSLEAY leftovers * openssl: do not log excess "TLS app data" lines for TLS 1.3 * openssl: do not use file BIOs if not requested * openssl: fix unused variable compiler warning with old openssl * openssl: support session resume with TLS 1.3 * openvms: fix example name * os400: Add curl_easy_conn_upkeep() to ILE/RPG binding * os400: add CURLOPT_CURLU to ILE/RPG binding * os400: fix return type of curl_easy_pause() in ILE/RPG binding * packages: remove old leftover files and dirs * pop3: only do APOP with a valid timestamp * runtests: use the local curl for verifying * schannel: be consistent in Schannel capitalization * schannel: better CURLOPT_CERTINFO support * schannel: use Curl_prefix for global private symbols * snprintf: renamed and now we only use msnprintf() * ssl: fix compilation with OpenSSL 0.9.7 * ssl: replace all internal uses of CURLE_SSL_CACERT * symbols-in-versions: add missing CURLU_symbols * test328: verify Content-Encoding: none * tests: disable SO_EXCLUSIVEADDRUSE for stunnel/Win * tests: drop http_pipe.py script no longer used * tests: drop http_pipe.py script no longer used * tool_cb_wrt: Silence function cast compiler warning * tool_doswin: Fix uninitialized field warning * travis: build with clang sanitizers * travis: remove curl before a normal build * url: a short host name + port is not a scheme * url: fix IPv6 numeral address parser * urlapi: only skip encoding the first '=' with APPENDQUERY set - refreshed curl-disabled-redirect-protocol-message.patch- Update to version 7.62.0 Changes: * multiplex: enable by default * url: default to CURL_HTTP_VERSION_2TLS if built h2-enabled * setopt: add CURLOPT_DOH_URL * curl: --doh-url added * setopt: add CURLOPT_UPLOAD_BUFFERSIZE: set upload buffer size * imap: change from "FETCH" to "UID FETCH" * configure: add option to disable automatic OpenSSL config loading * upkeep: add a connection upkeep API: curl_easy_upkeep() * URL-API: added five new functions * vtls: MesaLink is a new TLS backend Bugfixes: * CVE-2018-16839: SASL password overflow via integer overflow [bsc#1112758] * CVE-2018-16840: use-after-free in handle close [bsc#1113029] * CVE-2018-16842: warning message out-of-buffer read [bsc#1113660] * CURLOPT_DNS_USE_GLOBAL_CACHE: deprecated * Curl_dedotdotify(): always nul terminate returned string * Curl_follow: Always free the passed new URL * Curl_http2_done: fix memleak in error path * Curl_retry_request: fix memory leak * Curl_saferealloc: Fixed typo in docblock * FILE: fix CURLOPT_NOBODY and CURLOPT_HEADER output * GnutTLS: TLS 1.3 support * SECURITY-PROCESS: mention the bountygraph program * VS projects: add USE_IPV6: * certs: generate tests certs with sha256 digest algorithm * checksrc: enable strict mode and warnings * checksrc: handle zero scoped ignore commands * cmake: Backport to work with CMake 3.0 again * cmake: Improve config installation * cmake: add support for transitive ZLIB target * cmake: disable -Wpedantic-ms-format * cmake: don't require OpenSSL if USE_OPENSSL=OFF * cmake: fixed path used in generation of docs/tests * cmake: remove unused *SOCKLEN_T variables * cmake: suppress MSVC warning C4127 for libtest * cmake: test and set missed defines during configuration * config: Remove unused SIZEOF_VOIDP * configure: force-use -lpthreads on HPUX * configure: remove CURL_CONFIGURE_CURL_SOCKLEN_T * configure: s/AC_RUN_IFELSE/CURL_RUN_IFELSE * cookies: Remove redundant expired check * cookies: fix leak when writing cookies to file * curl-config.in: remove dependency on bc * curl.1: --ipv6 mutexes ipv4 (fixed typo) * curl: update the documentation of --tlsv1.0 * curl_multi_wait: call getsock before figuring out timeout * curl_ntlm_wb: check aprintf() return codes * data-binary.d: clarify default content-type is x-www-form-urlencoded * docs/CIPHERS: Mention the options used to set TLS 1.3 ciphers * docs/CIPHERS: fix the TLS 1.3 cipher names * docs/CIPHERS: mention the colon separation for OpenSSL * docs/examples: URL updates * docs: add "see also" links for SSL options * example/asiohiper: insert warning comment about its status * example/htmltidy: fix include paths of tidy libraries * examples/http2-pushinmemory: receive HTTP/2 pushed files in memory * examples/parseurl.c: show off the URL API * examples: Fix memory leaks from realloc errors * examples: do not wait when no transfers are running * ftp: include command in Curl_ftpsend sendbuffer * gskit: make sure to terminate version string * gtls: Values stored to but never read * hostip: fix check on Curl_shuffle_addr return value * http2: fix memory leaks on error-path * http: fix memleak in rewind error path * krb5: fix memory leak in krb_auth * memory: add missing curl_printf header * memory: ensure to check allocation results * multi: Fix error handling in the SENDPROTOCONNECT state * multi: fix memory leak in content encoding related error path * multi: make the closure handle "inherit" CURLOPT_NOSIGNAL * netrc: free temporary strings if memory allocation fails * nss: try to connect even if libnssckbi.so fails to load * ntlm_wb: Fix memory leaks in ntlm_wb_response * ntlm_wb: bail out if the response gets overly large * openssl: assume engine support in 0.9.8 or later * openssl: enable TLS 1.3 post-handshake auth * openssl: fix gcc8 warning * openssl: load built-in engines too * openssl: make 'done' a proper boolean * openssl: output the correct cipher list on TLS 1.3 error * openssl: return CURLE_PEER_FAILED_VERIFICATION on failure to parse issuer * openssl: show "proper" version number for libressl builds * pipelining: deprecated * rand: add comment to skip a clang-tidy false positive * rtmp: fix for compiling with lwIP * runtests: ignore disabled even when ranges are given * schannel: unified error code handling * sendf: Fix whitespace in infof/failf concatenation * ssh: free the session on init failures * ssl: deprecate CURLE_SSL_CACERT in favour of a unified error code * system.h: use proper setting with Sun C++ as well * test1299: use single quotes around asterisk * test1452: mark as flaky * test1651: unit test Curl_extract_certinfo() * test320: strip out more HTML when comparing * tests/negtelnetserver.py: fix Python2-ism in neg TELNET server * tests: add unit tests for url.c * tool_cb_hdr: handle failure of rename() * travis: add a "make tidy" build that runs clang-tidy * travis: add build for "configure --disable-verbose" * travis: bump the Secure Transport build to use xcode * travis: make distcheck scan for BOM markers * unit1300: fix stack-use-after-scope AddressSanitizer warning * urldata: Fix "connecting" comment * urlglob: improve error message on bad globs * vtls: fix ssl version "or later" behavior change for many backends * x509asn1: Fix SAN IP address verification * x509asn1: always check return code from getASN1Element() * x509asn1: return CURLE_PEER_FAILED_VERIFICATION on failure to parse cert * x509asn1: suppress left shift on signed value - Rebased patches after update: * curl-disabled-redirect-protocol-message.patch * curl-use_OPENSSL_config.patch- Security fix [bsc#1113660, CVE-2018-16842] * Fixed Out-of-bounds Read in tool_msgs.c * Added curl-CVE-2018-16842.patch- Security fix [bsc#1113029, CVE-2018-16840] * use-after-free in handle close * Added curl-CVE-2018-16840.patch- Security fix [bsc#1112758, CVE-2018-16839] * SASL password overflow via integer overflow * Added curl-CVE-2018-16839.patch- Security fix [CVE-2018-14618, bsc#1106019] * NTLM password overflow via integer overflow * Added patch curl-CVE-2018-14618.patch- Update to version 7.61.1 Bugfixes: * CVE-2018-14618: NTLM password overflow via integer overflow (bsc#1106019) * CURLINFO_SIZE_UPLOAD: fix missing counter update * CURLOPT_ACCEPT_ENCODING.3: list them comma-separated * CURLOPT_SSL_CTX_FUNCTION.3: might cause accidental connection reuse * Curl_getoff_all_pipelines: improved for multiplexed * DEPRECATE: remove release date from 7.62.0 * HTTP: Don't attempt to needlessly decompress redirect body * INTERNALS: require GnuTLS >= 2.11.3 * README.md: add LGTM.com code quality grade for C/C++ * SSLCERTS: improve the openssl command line * Silence GCC 8 cast-function-type warnings * ares: check for NULL in completed-callback * asyn-thread: Remove unused macro * auth: only pick CURLAUTH_BEARER if we *have* a Bearer token * auth: pick Bearer authentication whenever a token is available * cmake: CMake config files are defining CURL_STATICLIB for static builds * cmake: Respect BUILD_SHARED_LIBS * cmake: Update scripts to use consistent style * cmake: bumped minimum version to 3.4 * cmake: link curl to the OpenSSL targets instead of lib absolute paths * configure: conditionally enable pedantic-errors * configure: fix for -lpthread detection with OpenSSL and pkg-config * conn: remove the boolean 'inuse' field * content_encoding: accept up to 4 unknown trailer bytes after raw deflate data * cookie tests: treat files as text * cookies: support creation-time attribute for cookies * curl: Fix segfault when -H @headerfile is empty * curl: add http code 408 to transient list for --retry * curl: fix time-of-check, time-of-use race in dir creation * curl: use Content-Disposition before the "URL end" for -OJ * curl: warn the user if a given file name looks like an option * curl_threads: silence bad-function-cast warning * darwinssl: add support for ALPN negotiation * docs/CURLOPT_URL: fix indentation * docs/CURLOPT_WRITEFUNCTION: size is always 1 * docs/SECURITY-PROCESS: mention bounty, drop pre-notify * docs/examples: add hiperfifo example using linux epoll/timerfd * docs: add disallow-username-in-url.d and haproxy-protocol.d to dist * docs: clarify NO_PROXY env variable functionality * docs: improved the manual pages of some callbacks * docs: mention NULL is fine input to several functions * formdata: Remove unused macro HTTPPOST_CONTENTTYPE_DEFAULT * gopher: Do not translate `?' to `%09' * header output: switch off all styles, not just unbold * hostip: fix unused variable warning * http2: Use correct format identifier for stream_id * http2: abort the send_callback if not setup yet * http2: avoid set_stream_user_data() before stream is assigned * http2: check nghttp2_session_set_stream_user_data return code * http2: clear the drain counter in Curl_http2_done * http2: make sure to send after RST_STREAM * http2: separate easy handle from connections better * http: fix for tiny "HTTP/0.9" response * http_proxy: Remove unused macro SELECT_TIMEOUT * lib/Makefile: only do symbol hiding if told to * lib1502: fix memory leak in torture test * lib1522: fix curl_easy_setopt argument type * libcurl-thread.3: expand somewhat on the NO_SIGNAL motivation * mime: check Curl_rand_hex's return code * multi: always do the COMPLETED procedure/state * openssl: assume engine support in 1.0.0 or later * openssl: fix debug messages * projects: Improve Windows perl detection in batch scripts * retry: return error if rewind was necessary but didn't happen * reuse_conn(): memory leak - free old_conn->options * schannel: client certificate store opening fix * schannel: enable CALG_TLS1PRF for w32api >= 5.1 * schannel: fix MinGW compile break * sftp: don't send post-qoute sequence when retrying a connection * smb: fix memory leak on early failure * smb: fix memory-leak in URL parse error path * smb_getsock: always wait for write socket too * ssh-libssh: fix infinite connect loop on invalid private key * ssh-libssh: reduce excessive verbose output about pubkey auth * ssh-libssh: use FALLTHROUGH to silence gcc8 * ssl: set engine implicitly when a PKCS#11 URI is provided * sws: handle EINTR when calling select() * system_win32: fix version checking * telnet: Remove unused macros TELOPTS and TELCMDS * test1143: disable MSYS2's POSIX path conversion * test1148: disable if decimal separator is not point * test1307: (fnmatch testing) disabled * test1422: add required file feature * test1531: Add timeout * test1540: Remove unused macro TEST_HANG_TIMEOUT * test214: disable MSYS2's POSIX path conversion for URL * test320: treat curl320.out file as binary * tests/http_pipe.py: Use /usr/bin/env to find python * tests: Don't use Windows path %PWD for SSH tests * tests: fixes for Windows line endlings * tool_operate: Fix setting proxy TLS 1.3 ciphers * travis: build darwinssl on macos 10.12 to fix linker errors * travis: execute "set -eo pipefail" for coverage build * travis: run a 'make checksrc' too * travis: update to GCC-8 * travis: verify that man pages can be regenerated * upload: allocate upload buffer on-demand * upload: change default UPLOAD_BUFSIZE to 64KB * urldata: remove unused pipe_broke struct field * vtls: reinstantiate engine on duplicated handles * windows: implement send buffer tuning * wolfSSL/CyaSSL: Fix memory leak in Curl_cyassl_random - Remove patch included upstream: * curl-switch-off-all-styles.patch- Added curl-switch-off-all-styles.patch: Fix output of wrong escape sequences, which might mess up the terminal (bsc#1105624)- security update * CVE-2018-0500 [bsc#1099793] + curl-CVE-2018-0500.patch- Update to version 7.61.0 [bsc#1099793, CVE-2018-0500] Changes: * getinfo: add microsecond precise timers for seven intervals * curl: show headers in bold, switch off with --no-styled-output * httpauth: add support for Bearer tokens * Add CURLOPT_TLS13_CIPHERS and CURLOPT_PROXY_TLS13_CIPHERS * curl: --tls13-ciphers and --proxy-tls13-ciphers * Add CURLOPT_DISALLOW_USERNAME_IN_URL * curl: --disallow-username-in-url Bugfixes: * CVE-2018-0500: smtp: fix SMTP send buffer overflow * schannel: disable client cert option if APIs not available * schannel: disable manual verify if APIs not available * tests/libtest/Makefile: Do not unconditionally add gcc-specific flags * openssl: acknowledge --tls-max for default version too * stub_gssapi: fix 'unused parameter' warnings * examples/progressfunc: make it build on both new and old libcurls * docs: mention it is HA Proxy protocol "version 1" * curl_fnmatch: only allow two asterisks for matching * docs: clarify CURLOPT_HTTPGET * configure: replace a AC_TRY_RUN with CURL_RUN_IFELSE * configure: do compile-time SIZEOF checks instead of run-time * checksrc: make sure sizeof() is used *with* parentheses * CURLOPT_ACCEPT_ENCODING.3: add brotli and clarify a bit * schannel: make CAinfo parsing resilient to CR/LF * tftp: make sure error is zero terminated before printfing it * http resume: skip body if http code 416 (range error) is ignored * configure: add basic test of --with-ssl prefix * cmake: set -d postfix for debug builds * multi: provide a socket to wait for in Curl_protocol_getsock * content_encoding: handle zlib versions too old for Z_BLOCK * winbuild: only delete OUTFILE if it exists * winbuild: In MakefileBuild.vc fix typo DISTDIR->DIRDIST * schannel: add failf calls for client certificate failures * cmake: Fix the test for fsetxattr and strerror_r * curl.1: Fix cmdline-opts reference errors * cmdline-opts/gen.pl: warn if mutexes: or see-also: list non-existing options * cmake: check for getpwuid_r * configure: fix ssh2 linking when built with a static mbedtls * psl: use latest psl and refresh it periodically * fnmatch: insist on escaped bracket to match * KNOWN_BUGS: restore text regarding #2101 * INSTALL: LDFLAGS=-Wl,-R/usr/local/ssl/lib * configure: override AR_FLAGS to silence warning * os400: implement mime api EBCDIC wrappers * curl.rc: embed manifest for correct Windows version detection * strictness: correct {infof, failf} format specifiers * tests: update .gitignore for libtests * configure: check for declaration of getpwuid_r * fnmatch: use the system one if available * CURLOPT_RESOLVE: always purge old entry first * multi: remove a potentially bad DEBUGF() * curl_addrinfo: use same #ifdef conditions in source as header * build: remove the Borland specific makefiles * axTLS: not considered fit for use * cmdline-opts/cert-type.d: mention "p12" as a recognized type * system.h: add support for IBM xlc C compiler * tests/libtest: Add lib1521 to nodist_SOURCES * mk-ca-bundle.pl: leave certificate name untouched * boringssl + schannel: undef X509_NAME in lib/schannel.h * openssl: assume engine support in 1.0.1 or later * cppcheck: fix warnings * test 46: make test pass after year 2025 * schannel: support selecting ciphers * Curl_debug: remove dead printhost code * test 1455: unflakified * Curl_init_do: handle NULL connection pointer passed in * progress: remove a set of unused defines * mk-ca-bundle.pl: make -u delete certdata.txt if found not changed * GOVERNANCE.md: explains how this project is run * configure: use pkg-config for c-ares detection * configure: enhance ability to build with static openssl * maketgz: fix sed issues on OSX * multi: fix memory leak when stopped during name resolve * CURLOPT_INTERFACE.3: interface names not supported on Windows * url: fix dangling conn->data pointer * cmake: allow multiple SSL backends * system.h: fix for gcc on 32 bit OpenServer * ConnectionExists: make sure conn->data is set when "taking" a connection * multi: fix crash due to dangling entry in connect-pending list * CURLOPT_SSL_VERIFYPEER.3: Add performance note * netrc: use a larger buffer to support longer passwords * url: check Curl_conncache_add_conn return code * configure: Add dependent libraries after crypto * easy_perform: faster local name resolves by using *multi_timeout() * getnameinfo: not used, removed all configure checks * travis: add a build using the synchronous name resolver * CURLINFO_TLS_SSL_PTR.3: improve the example * openssl: allow TLS 1.3 by default * openssl: make the requested TLS version the *minimum* wanted * openssl: Remove some dead code * telnet: fix clang warnings * DEPRECATE: new doc describing planned item removals * example/crawler.c: simple crawler based on libxml2 * libssh: goto DISCONNECT state on error, not SESSION_FREE * CMake: Remove unused functions * darwinssl: allow High Sierra users to build the code using GCC * scripts: include _curl as part of CLEANFILES * examples: fix -Wformat warnings * curl_setup: include before * schannel: make more cipher options conditional * CMake: remove redundant and old end-of-block syntax * post303.d: clarify that this is an RFC violation - refreshed libcurl-ocloexec.patch- Use OPENSSL_config instead of CONF_modules_load_file() to avoid crashes due to openssl engines conflicts (bsc#1086367) * add curl-use_OPENSSL_config.patch- Update to version 7.60.0 [bsc#1092094, CVE-2018-1000300][bsc#1092098, CVE-2018-1000301] Changes: * Add CURLOPT_HAPROXYPROTOCOL, support for the HAProxy PROXY protocol * Add --haproxy-protocol for the command line tool * Add CURLOPT_DNS_SHUFFLE_ADDRESSES, shuffle returned IP addresses Bugfixes: * FTP: shutdown response buffer overflow CVE-2018-1000300 * RTSP: bad headers buffer over-read CVE-2018-1000301 * FTP: fix typo in recursive callback detection for seeking * test1208: marked flaky * HTTP: make header-less responses still count correct body size * user-agent.d:: mention --proxy-header as well * http2: fixes typo * cleanup: misc typos in strings and comments * rate-limit: use three second window to better handle high speeds * examples/hiperfifo.c: improved * pause: when changing pause state, update socket state * multi: improved pending transfers handling => improved performance * curl_version_info.3: fix ssl_version description * add_handle/easy_perform: clear errorbuffer on start if set * cmake: add support for brotli * parsedate: support UT timezone * vauth/ntlm.h: fix the #ifdef header guard * lib/curl_path.h: added #ifdef header guard * vauth/cleartext: fix integer overflow check * CURLINFO_COOKIELIST.3: made the example not leak memory * cookie.d: mention that "-" as filename means stdin * CURLINFO_SSL_VERIFYRESULT.3: fixed the example * http2: read pending frames (including GOAWAY) in connection-check * timeval: remove compilation warning by casting * cmake: avoid warn-as-error during config checks * travis-ci: enable -Werror for CMake builds * openldap: fix for NULL return from ldap_get_attribute_ber() * threaded resolver: track resolver time and set suitable timeout values * cmake: Add advapi32 as explicit link library for win32 * docs: fix CURLINFO_*_T examples use of CURL_FORMAT_CURL_OFF_T * test1148: set a fixed locale for the test * cookies: when reading from a file, only remove_expired once * cookie: store cookies per top-level-domain-specific hash table * openssl: fix build with LibreSSL 2.7 * tls: fix mbedTLS 2.7.0 build + handle sha256 failures * openssl: RESTORED verify locations when verifypeer==0 * file: restore old behavior for file:////foo/bar URLs * FTP: allow PASV on IPv6 connections when a proxy is being used * build-openssl.bat: allow custom paths for VS and perl * winbuild: make the clean target work without build-type * build-openssl.bat: Refer to VS2017 as VC14.1 instead of VC15 * curl: retry on FTP 4xx, ignore other protocols * configure: detect (and use) sa_family_t * examples/sftpuploadresume: Fix Windows large file seek * build: cleanup to fix clang warnings/errors * winbuild: updated the documentation * lib: silence null-dereference warnings * travis: bump to clang 6 and gcc 7 * travis: build libpsl and make builds use it * proxy: show getenv proxy use in verbose output * duphandle: make sure CURLOPT_RESOLVE is duplicated * all: Refactor malloc+memset to use calloc * checksrc: Fix typo * system.h: Add sparcv8plus to oracle/sunpro 32-bit detection * vauth: Fix typo * ssh: show libSSH2 error code when closing fails * test1148: tolerate progress updates better * urldata: make service names unconditional * configure: keep LD_LIBRARY_PATH changes local * ntlm_sspi: fix authentication using Credential Manager * schannel: add client certificate authentication * winbuild: Support custom devel paths for each dependency * schannel: add support for CURLOPT_CAINFO * http2: handle on_begin_headers() called more than once * openssl: support OpenSSL 1.1.1 verbose-mode trace messages * openssl: fix subjectAltName check on non-ASCII platforms * http2: avoid strstr() on data not zero terminated * http2: clear the "drain counter" when a stream is closed * http2: handle GOAWAY properly * tool_help: clarify --max-time unit of time is seconds * curl.1: clarify that options and URLs can be mixed * http2: convert an assert to run-time check * curl_global_sslset: always provide available backends * ftplistparser: keep state between invokes * Curl_memchr: zero length input can't match * examples/sftpuploadresume: typecast fseek argument to long * examples/http2-upload: expand buffer to avoid silly warning * ctype: restore character classification for non-ASCII platforms * mime: avoid NULL pointer dereference risk * cookies: ensure that we have cookies before writing jar * os400.c: fix checksrc warnings * configure: provide --with-wolfssl as an alias for --with-cyassl * cyassl: adapt to libraries without TLS 1.0 support built-in * http2: get rid of another strstr * checksrc: force indentation of lines after an else * cookies: remove unused macro * CURLINFO_PROTOCOL.3: mention the existing defined names * tests: provide 'manual' as a feature to optionally require * travis: enable libssh2 on both macos and Linux * CURLOPT_URL.3: added ENCODING section * wolfssl: Fix non-blocking connect * vtls: don't define MD5_DIGEST_LENGTH for wolfssl * docs: remove extraneous commas in man pages * URL: fix ASCII dependency in strcpy_url and strlen_url * ssh-libssh.c: fix left shift compiler warning * configure: only check for CA bundle for file-using SSL backends * travis: add an mbedtls build * http: don't set the "rewind" flag when not uploading anything * configure: put CURLDEBUG and DEBUGBUILD in lib/curl_config.h * transfer: don't unset writesockfd on setup of multiplexed conns * vtls: use unified "supports" bitfield member in backends * URLs: fix one more http url * travis: add a build using WolfSSL * openssl: change FILE ops to BIO ops * travis: add build using NSS * smb: reject negative file sizes * cookies: accept parameter names as cookie name * http2: getsock fix for uploads * all over: fixed format specifiers * http2: use the correct function pointer typedef- Added message about protocol redirection not supported or disabled to the function findprotocol() [bsc#1076446] * Added curl-disabled-redirect-protocol-message.patch- Update to version 7.59.0 [bsc#1084521, CVE-2018-1000120][bsc#1084524, CVE-2018-1000121] [bsc#1084532, CVE-2018-1000122] Changes: * curl: add --proxy-pinnedpubkey * added: CURLOPT_TIMEVALUE_LARGE and CURLINFO_FILETIME_T * CURLOPT_RESOLVE: Add support for multiple IP addresses per entry * Add option CURLOPT_HAPPY_EYEBALLS_TIMEOUT_MS * Add new tool option --happy-eyeballs-timeout-ms * Add CURLOPT_RESOLVER_START_FUNCTION and CURLOPT_RESOLVER_START_DATA Bugfixes: * openldap: check ldap_get_attribute_ber() results for NULL before using * FTP: reject path components with control codes * readwrite: make sure excess reads don't go beyond buffer end * lib555: drop text conversion and encode data as ascii codes * lib517: make variable static to avoid compiler warning * lib544: sync ascii code data with textual data * GSKit: restore pinnedpubkey functionality * darwinssl: Don't import client certificates into Keychain on macOS * parsedate: fix date parsing for systems with 32 bit long * openssl: fix pinned public key build error in FIPS mode * SChannel/WinSSL: Implement public key pinning * cookies: remove verbose "cookie size:" output * progress-bar: don't use stderr explicitly, use bar->out * build: open VC15 projects with VS 2017 * curl_ctype: private is*() type macros and functions * configure: set PATH_SEPARATOR to colon for PATH w/o separator * curl_easy_reset: clear digest auth state * curl/curl.h: fix comment typo for CURLOPT_DNS_LOCAL_IP6 * range: commonize FTP and FILE range handling * progress-bar docs: update to match implementation * fnmatch: do not match the empty string with a character set * fnmatch: accept an alphanum to be followed by a non-alphanum in char set * build: fix termios issue on android cross-compile * getdate: return -1 for out of range * formdata: use the mime-content type function * openssl: Don't add verify locations when verifypeer==0 * fnmatch: optimize processing of consecutive *s and ?s pattern characters * schannel: fix compiler warnings * content_encoding: Add "none" alias to "identity" * get_posix_time: only check for overflows if they can happen * http_chunks: don't write chunks twice with CURLOPT_HTTP_TRANSFER_DECODING * README: language fix * sha256: build with OpenSSL < 0.9.8 * smtp: fix processing of initial dot in data * --tlsauthtype: works only if libcurl is built with TLS-SRP support * tests: new tests for http raw mode * libcurl-security.3: man page discussion security concerns when using libcurl * curl_gssapi: make sure this file too uses our *printf() * BINDINGS: fix curb link (and remove ruby-curl-multi) * nss: use PK11_CreateManagedGenericObject() if available * travis: add build with iconv enabled * ssh: add two missing state names * CURLOPT_HEADERFUNCTION.3: mention folded headers * http: fix the max header length detection logic * header callback: don't chop headers into smaller pieces * CURLOPT_HEADER.3: clarify problems with different data sizes * curl --version: show PSL if the run-time lib has it enabled * examples/sftpuploadresume: resume upload via CURLOPT_APPEND * Return error if called recursively from within callbacks * sasl: prefer PLAIN mechanism over LOGIN * winbuild: Use CALL to run batch scripts * curl_share_setopt.3: connection cache is shared within multi handles * projects/README: remove reference to dead IDN link/package * lib655: silence compiler warning * configure: Fix version check for OpenSSL 1.1.1 * docs/MANUAL: formfind.pl is not accessible on the site anymore * unit1307: proper cleanup on OOM to fix torture tests * curl_ctype: fix macro redefinition warnings * build: get CFLAGS (including -werror) used for examples and tests * NO_PROXY: fix for IPv6 numericals in the URL * krb5: use nondeprecated functions * http2: mark the connection for close on GOAWAY * limit-rate: kick in even before "limit" data has been received * HTTP: allow "header;" to replace an internal header with a blank one * http2: verbose output new MAX_CONCURRENT_STREAMS values * SECURITY: distros' max embargo time is 14 days * curl tool: accept --compressed also if Brotli is enabled and zlib is not * WolfSSL: adding TLSv1.3 * checksrc.pl: add -i and -m options * CURLOPT_COOKIEFILE.3: "-" as file name means stdin - Refreshed patch libcurl-ocloexec.patch- Sort a bit with spec-cleaner - Install license with the library- ignore all test failures for PowerPC as bypass boo#1075219 (not only the 1501 previously skipped) * Added patch ignore_runtests_failure.patch- Build curl with libssh.org libssh offers a lot more features than libssh2, for example: * Key Exchange Methods: curve25519-sha256@libssh.org * Hostkey Types: ssh-ed25519 * Authentication: gssapi-with-mic- Update to version 7.58.0 [bsc#1076360,CVE-2018-1000005][bsc#1077001,CVE-2018-1000007] Changes: * new libssh-powered SSH SCP/SFTP back-end * curl-config: add --ssl-backends Bugfixes: * http2: fix incorrect trailer buffer size * http: prevent custom Authorization headers in redirects * travis: add boringssl build * examples/xmlstream.c: don't switch off CURL_GLOBAL_SSL * SSL: Avoid magic allocation of SSL backend specific data * lib: don't export all symbols, just everything curl_* * libssh2: send the correct CURLE error code on scp file not found * libssh2: return CURLE_UPLOAD_FAILED on failure to upload * openssl: enable pkcs12 in boringssl builds * libssh2: remove dead code from SSH_SFTP_QUOTE * sasl_getmesssage: make sure we have a long enough string to pass * conncache: fix several lock issues * threaded-shared-conn.c: new example * conncache: only allow multiplexing within same multi handle * configure: check for netinet/in6.h * URL: tolerate backslash after drive letter for FILE: * openldap: add commented out debug possibilities * include: get netinet/in.h before linux/tcp.h * CONNECT: keep close connection flag in http_connect_state struct * BINDINGS: another PostgreSQL client * curl: limit -# update frequency for unknown total size * configure: add AX_CODE_COVERAGE only if using gcc * curl.h: remove incorrect comment about ERRORBUFFER * openssl: improve data-pending check for https proxy * curl: remove __EMX__ #ifdefs * CURLOPT_PRIVATE.3: fix grammar * sftp: allow quoted commands to use relative paths * CURLOPT_DNS_CACHE_TIMEOUT.3: see also CURLOPT_RESOLVE * RESOLVE: output verbose text when trying to set a duplicate name * multi_done: prune DNS cache * tests: update .gitignore for libtests * tests: mark data files as non-executable in git * CURLOPT_DNS_LOCAL_IP4.3: fixed the "SEE ALSO" to not self-reference * curl.1: documented two missing valid exit codes * curl.1: mention http:// and https:// as valid proxy prefixes * vtls: replaced getenv() with curl_getenv() * setopt: less *or equal* than INT_MAX/1000 should be fine * examples/smtp-mail.c: use separate defines for options and mail * curl: support >256 bytes warning messsages * conncache: fix a return code * krb5: fix a potential access of uninitialized memory * rand: add a clang-analyzer work-around * CURLOPT_READFUNCTION.3: refer to argument with correct name * brotli: allow compiling with version 0.6.0 * content_encoding: rework zlib_inflate * curl_easy_reset: release mime-related data * examples/rtsp: fix error handling macros * curl: Support size modifiers for --max-filesize * examples/cacertinmem: ignore cert-already-exists error * brotli: data at the end of content can be lost * curl_version_info.3: call the argument 'age' * openssl: fix memory leak of SSLKEYLOGFILE filename * build: remove HAVE_LIMITS_H check * --mail-rcpt: fix short-text description * scripts: allow all perl scripts to be run directly * progress: calculate transfer speed on milliseconds if possible * system.h: check __LONG_MAX__ for defining curl_off_t * easy: fix connection ownership in curl_easy_pause * setopt: reintroduce non-static Curl_vsetopt() for OS400 support * setopt: fix SSLVERSION to allow CURL_SSLVERSION_MAX_ values * configure.ac: append extra linker flags instead of prepending them * HTTP: bail out on negative Content-Length: values * docs: comment about CURLE_READ_ERROR returned by curl_mime_filedata * mime: clone mime tree upon easy handle duplication * openssl: enable SSLKEYLOGFILE support by default * smtp/pop3/imap_get_message: decrease the data length too... * CURLOPT_TCP_NODELAY.3: fix typo * SMB: fix numeric constant suffix and variable types * ftp-wildcard: fix matching an empty string with "*[^a]" * curl_fnmatch: only allow 5 '*' sections in a single pattern * openssl: fix potential memory leak in SSLKEYLOGFILE logic * SSH: Fix state machine for ssh-agent authentication * examples/url2file.c: add missing curl_global_cleanup() call * http2: don't close connection when single transfer is stopped * libcurl-env.3: first version * curl: progress bar refresh, get width using ioctl() * CONNECT_TO: fail attempt to set an IPv6 numerical without IPv6 support- disable 1501 test for PowerPC as byass boo#1075219- Update to version 7.57.0 [bsc#1069226, CVE-2017-8816] [bsc#1069222, CVE-2017-8817] [bsc#1069714, CVE-2017-8818] Changes: * auth: add support for RFC7616 - HTTP Digest access authentication * share: add support for sharing the connection cache * HTTP: implement Brotli content encoding Bugfixes: * CVE-2017-8816: NTLM buffer overflow via integer overflow * CVE-2017-8817: FTP wildcard out of bounds read * CVE-2017-8818: SSL out of buffer access * curl_mime_filedata.3: fix typos * libtest: Add required test libraries for lib1552 and lib1553 * fix time diffs for systems using unsigned time_t * ftplistparser: memory leak fix: free temporary memory always * multi: allow table handle sizes to be overridden * wildcards: don't use with non-supported protocols * curl_fnmatch: return error on illegal wildcard pattern * transfer: Fix chunked-encoding upload too early exit * resolvers: only include anything if needed * setopt: fix CURLOPT_SSH_AUTH_TYPES option read * Curl_timeleft: change return type to timediff_t * cmake: Export libcurl and curl targets to use by other cmake projects * curl: in -F option arg, comma is a delimiter for files only * curl: improved ";type=" handling in -F option arguments * timeval: use mach_absolute_time() on MacOS * curlx: the timeval functions are no longer provided as curlx_* * mkhelp.pl: do not generate comment with current date * memdebug: use send/recv signature for curl_dosend/curl_dorecv * cookie: avoid NULL dereference * url: fix CURLOPT_POSTFIELDSIZE arg value check to allow -1 * include: remove conncache.h inclusion from where its not needed * CURLOPT_MAXREDIRS: allow -1 as a value * tests: Fixed torture tests on tests 556 and 650 * http2: Fixed OOM handling in upgrade request * url: fix CURLOPT_DNS_CACHE_TIMEOUT arg value check to allow -1 * CURLOPT_INFILESIZE: accept -1 * curl: pass through [] in URLs instead of calling globbing error * curl: speed up handling of many URLs * ntlm: avoid malloc(0) for zero length passwords * url: remove faulty arg value check from CURLOPT_SSH_AUTH_TYPES * HTTP: support multiple Content-Encodings * travis: add a job with brotli enabled * url: remove unncessary NULL-check * fnmatch: remove dead code * connect: store IPv6 connection status after valid connection * imap: deal with commands case insensitively * --interface: add support for Linux VRF * content_encoding: fix inflate_stream for no bytes available * cmake: Add missing setmode check * connect.c: remove executable bit on file * SMB: fix uninitialized local variable * zlib/brotli: only include header files in modules needing them * URL: return error on malformed URLs with junk after IPv6 bracket * openssl: fix too broad use of HAVE_OPAQUE_EVP_PKEY * macOS: Fix missing connectx function with Xcode version older than 9.0 * --resolve: allow IP address within [] brackets * examples/curlx: Fix code style * ntlm: remove unnecessary NULL-check to please scan-build * Curl_llist_remove: fix potential NULL pointer deref * mime: fix "Value stored to 'sz' is never read" scan-build error * openssl: fix "Value stored to 'rc' is never read" scan-build error * http2: fix "Value stored to 'hdbuf' is never read" scan-build error * http2: fix "Value stored to 'end' is never read" scan-build error * Curl_open: fix OOM return error correctly * url: reject ASCII control characters and space in host names * examples/rtsp: clear RANGE again after use * connect: improve the bind error message * make: fix "make distclean" * connect: add support for new TCP Fast Open API on Linux * metalink: fix memory-leak and NULL pointer dereference * URL: update "file:" URL handling * ssh: remove check for a NULL pointer * global_init: ignore CURL_GLOBAL_SSL's absense- Update to version 7.56.1 [bsc#1063824] Bugfixes: * imap: if a FETCH response has no size, don't call write callback [CVE-2017-1000257] * ftp: UBsan fixup 'pointer index expression overflowed * failf: skip the sprintf() if there are no consumers * fuzzer: move to using external curl-fuzzer * lib/Makefile.m32: allow customizing dll suffixes * docs: fix typo in curl_mime_data_cb man page * darwinssl: add support for TLSv1.3 * build: fix --disable-crypto-auth * openssl: fix build without HAVE_OPAQUE_EVP_PKEY * strtoofft: Remove extraneous null check * multi_cleanup: call DONE on handles that never got that * tests: added flaky keyword to tests 587 and 644 * pingpong: return error when trying to send without connection * remove_handle: call multi_done() first, then clear dns cache pointer * mime: be tolerant about setting the same header list twice in a part * mime: improve unbinding top multipart from easy handle * mime: avoid resetting a part's encoder when part's contents change * mime: refuse to add subparts to one of their own descendants * RTSP: avoid integer overflow on funny RTSP responses * curl: don't pass semicolons when parsing Content-Disposition * openssl: enable PKCS12 support for !BoringSSL * FAQ: s/CURLOPT_PROGRESSFUNCTION/CURLOPT_XFERINFOFUNCTION * CURLOPT_NOPROGRESS.3: also refer to xferinfofunction * CURLOPT_XFERINFODATA.3: fix duplicate see also * test298: verify --ftp-method nowcwd with URL encoded path * FTP: URL decode path for dir listing in nocwd mode * smtp_done: fix memory leak on send failure * ftpserver: support case insensitive commands * test950; verify SMTP with custom request * openssl: don't use old BORINGSSL_YYYYMM macros * setopt: update current connection SSL verify params * curl: reimplement stdin buffering in -F option * mime: keep "text/plain" content type if user-specified * mime: fix the content reader to handle >16K data properly * configure: remove the C++ compiler check * memdebug: trace send, recv and socket * runtests: use valgrind for torture as well * ldap: silence clang warning * makefile.m32: allow to override gcc, ar and ranlib * setopt: avoid integer overflows when setting millsecond values * setopt: range check most long options * ftp: reject illegal IP/port in PASV 227 response * mime: do not reuse previously computed multipart size * vtls: change struct Curl_ssl `close' field name to `close_one' * os400: add missing symbols in config file * mime: limit bas64-encoded lines length to 76 characters * mk-ca-bundle: Remove URL for aurora * mk-ca-bundle: Fix URL for NSS- Update to 7.56.0 [bsc#1061876, CVE-2017-1000254] Changes: * curl: enable compression for SCP/SFTP with --compressed-ssh * libcurl: enable compression for SCP/SFTP with CURLOPT_SSH_COMPRESSION * vtls: added dynamic changing SSL backend with curl_global_sslset() * new MIME API, curl_mime_init() and friends * openssl: initial SSLKEYLOGFILE implementation Security fixes: * CVE-2017-1000254 FTP PWD response parser out of bounds read Bugfixes: * FTP: zero terminate the entry path even on bad input * examples/ftpuploadresume.c: use portable code * runtests: match keywords case insensitively * strtoofft: reduce integer overflow risks globally * zsh.pl: produce a working completion script again * cmake: remove dead code for CURL_DISABLE_RTMP * progress: Track total times following redirects * configure: fix --disable-threaded-resolver * configure: fix clang version detection * darwinssi: fix error: variable length array used * configure: check for __builtin_available() availability * http_proxy: fix build error for CURL_DOES_CONVERSIONS * examples/ftpuploadresume: checksrc compliance * ftp: fix CWD when doing multicwd then nocwd on same connection * system.h: remove all CURL_SIZEOF_* defines * http: Don't wait on CONNECT when there is no proxy * system.h: check for __ppc__ as well * http2_recv: return error better on fatal h2 errors * tftp: fix memory leak on too long filename * system.h: fix build for hppa * cmake: enable picky compiler options with clang and gcc * makefile.m32: add support for libidn2 * curl: shorten and clean up CA cert verification error message * imap: support PREAUTH * CURLOPT_USERPWD.3: see also CURLOPT_PROXYUSERPWD * examples/threaded-ssl: mention that this is for openssl before 1.1 * tests: Make sure libtests & unittests call curl_global_cleanup() * system.h: include sys/poll.h for AIX * darwinssl: handle long strings in TLS certs * strtooff: fix build for systems with long long but no strtoll * asyn-thread: Improved cleanup after OOM situations * curl.h: CURLSSLBACKEND_WOLFSSL used wrong value * unit1301: fix error message on first test * ossfuzz: moving towards the ideal integration * http: fix a memory leakage in checkrtspprefix() * examples/post-callback: stop returning one byte at a time * schannel: return CURLE_SSL_CACERT on failed verification * http-proxy: treat all 2xx as CONNECT success * openssl: use OpenSSL's default ciphers by default * runtests.pl: support attribute "nonewline" in part verify/upload * configure: remove --enable-soname-bump and SONAME_BUMP * vtls: fix WolfSSL 3.12 build problems * http-proxy: when not doing CONNECT, that phase is done immediately * configure: fix curl_off_t check's include order * configure: use -Wno-varargs on clang 3.9[.X] debug builds * rtsp: do not call fwrite() with NULL pointer FILE * * mbedtls: enable CA path processing * checksrc: verify more code style rules * HTTP proxy: on connection re-use, still use the new remote port * tests: add initial gssapi test using stub implementation * rtsp: Segfault when using WRITEDATA * docs: clarify the CURLOPT_INTERLEAVE* options behavior * non-ascii: use iconv() with 'char **' argument * server/getpart: provide dummy function to build conversion enabled * conversions: fix several compiler warnings * openssl: add missing includes * schannel: Support partial send for when data is too large * socks: fix incorrect port number in SOCKS4 error message * curl: fix integer overflow in timeout options * cookies: reject oversized cookies instead of truncating * cookies: use lock when using CURLINFO_COOKIELIST * curl: check fseek() return code and bail on error * examples/post-callback: use long for CURLOPT_POSTFIELDSIZE * openssl: only verify RSA private key if supported * tests: make the imap server not verify user+password * imap: quote atoms properly when escaping characters * tests: fix a compiler warning in test 643 * file_range: avoid integer overflow when figuring out byte range * reuse_conn: don't copy flags that are known to be equal * http: fix adding custom empty headers to repeated requests * docs: link CURLOPT_CONNECTTIMEOUT and CURLOPT_CONNECTTIMEOUT_MS * connect: fix race condition with happy eyeballs timeout * cookie: fix memory leak if path was set twice in header * vtls: compare and clone ssl configs properly * proxy: read the "no_proxy" variable only if necessary - Refreshed patches: * libcurl-ocloexec.patch - Removed patches fixed upstream: * curl-man3.patch * ppc-build.patch * curl-http-Don-t-wait-on-CONNECT-when-there-is-no-proxy.patch * curl-disable-test1427-i586.patch- Add curl-http-Don-t-wait-on-CONNECT-when-there-is-no-proxy.patch: Fix NetworkManagers connectivity test.- ppc-build.patch: Fix build for powerpc- Upstream fix to build libcurl man3 pages * Added patch curl-man3.patch- Disabled test1425 that fails in i586 architecture * Added patch curl-disable-test1427-i586.patch- Update to 7.55.0 Changes: * curl: allow --header and --proxy-header read from file * getinfo: provide sizes as curl_off_t * curl: prevent binary output spewed to terminal * curl: added --request-target * curl: added --socks5-{basic,gssapi}: control socks5 auth * libcurl: added CURLOPT_REQUEST_TARGET * libcurl: added CURLOPT_SOCKS5_AUTH Bugfixes: * Security Fixes: - glob: do not parse after a strtoul() overflow range (CVE-2017-1000101, bsc#1051643) - tftp: reject file name lengths that don't fit (CVE-2017-1000100, bsc#1051644) - file: output the correct buffer to the user (CVE-2017-1000099, bsc#1051645) * includes: remove curl/curlbuild.h and curl/curlrules.h * dist: make the hugehelp.c not get regenerated unnecessarily * timers: store internal time stamps as time_t instead of doubles * progress: let "current speed" be UL + DL speeds combined * http-proxy: do the HTTP CONNECT process entirely non-blocking * lib/curl_setup.h: remove CURL_WANTS_CA_BUNDLE_ENV * fuzz: bring oss-fuzz initial code converted to C89 * configure: disable nghttp2 too if HTTP has been disabled * mk-ca-bundle.pl: Check curl's exit code after certdata download * test1148: verify the -# progressbar * tests: stabilize test 2032 and 2033 * HTTPS-Proxy: don't offer h2 for https proxy connections * http-proxy: only attempt FTP over HTTP proxy * curl-compilers.m4: enable vla warning for clang * curl-compilers.m4: enable double-promotion warning * curl-compilers.m4: enable missing-variable-declarations clang warning * curl-compilers.m4: enable comma clang warning * CURLOPT_PREQUOTE: not supported for SFTP * http2: fix OOM crash * PIPELINING_SERVER_BL: cleanup the internal list use * mkhelp.pl: fix script name in usage text * lib1521: add curl_easy_getinfo calls to the test set * travis: do the distcheck test build out-of-tree as well * if2ip: fix compiler warning in ISO C90 mode * lib: fix the djgpp build * typecheck-gcc: add support for CURLINFO_OFF_T * travis: enable typecheck-gcc warnings * maketgz: switch to xz instead of lzma * CURLINFO_REDIRECT_URL.3: mention the CURLOPT_MAXREDIRS case * curl/system.h: add check for XTENSA for 32bit gcc * test1537: fixed memory leak on OOM * test1521: fix compiler warnings * curl: fix memory leak on test 1147 OOM * libtest/make: generate lib1521.c dynamically at build-time * curl_strequal.3: fix typo in SYNOPSIS * progress: prevent resetting t_starttransfer * openssl: improve fallback seed of PRNG with a time based hash * http2: improved PING frame handling * test1450: add simple testing for DICT * make: build the docs subdir only from within src * gtls: fix build when sizeof(long) < sizeof(void *) * url: make the original string get used on subsequent transfers * timeval.c: Use long long constant type for timeval assignment * tool_sleep: typecast to avoid macos compiler warning * travis.yml: use --enable-werror on debug builds * test1451: add SMB support to the testbed * configure: remove checks for 5 functions never used * configure: try ldap/lber in reversed order first * smb: fix build for djgpp/MSDOS * travis: install nghttp2 on linux builds * smb: add support for CURLOPT_FILETIME * select.h: avoid macro redefinition harder * runtests: support "threaded-resolver" as a feature * test506: skip if threaded-resolver * cmake: remove spurious "-l" from linker flags * cmake: add CURL_WERROR for enabling "warning as errors" * memdebug: don't setbuf() if the file open failed * curl_easy_escape.3: mention the (lack of) encoding * test1452: add telnet negotiation * CURLOPT_POSTFIELDS.3: explain the 100-continue magic better * cmake: offer CMAKE_DEBUG_POSTFIX when building with MSVC * tests/valgrind.supp: supress OpenSSL false positive seen on travis * curl_setup_once: Remove ERRNO/SET_ERRNO macros * rtspd: fix MSVC level 4 warning * sockfilt: suppress conversion warning with explicit cast * libtest: fix MSVC warning C4706 * tests/server/resolve.c: fix deprecation warning * nss: fix a possible use-after-free in SelectClientCert() * checksrc: escape open brace in regex * multi: mention integer overflow risk if using > 500 million sockets * timeval: struct curltime is a struct timeval replacement * curl_rtmp: fix a compiler warning * include.d: clarify that it concerns the response headers * cmake: support make uninstall * include.d: clarify --include is only for response headers * libcurl: Stop using error codes defined under CURL_NO_OLDIES * http: fix response code parser to avoid integer overflow * configure: fix the check for IdnToUnicode * multi: fix request timer management * curl_threads: fix MSVC compiler warning * cmake: set MSVC warning level to 4 * netrc: skip lines starting with '#' * FTP: skip unnecessary CWD when in nocwd mode * gssapi: fix memory leak of output token in multi round context * getparameter: avoid returning uninitialized 'usedarg' * curl (debug build) easy_events: make event data static * curl: detect and bail out early on parameter integer overflows - Removed patch curl-invalid-free.patch- Update License to 'curl' as per review on OBS sr#505976.- Have the -mini packages conflict the real ones.- Add curl-invalid-free.patch to fix an invalid free in curl_multi_setopt function.- Update to 7.54.1 Changes: * curl now shows release date in --version output Bugfixes: * Fixes CVE-2017-9502: default protocol drive letter buffer overflow bsc#1044243 * openssl: fix memory leak in servercert * curl: set a 100K buffer size by default * nss: do not leak PKCS #11 slot while loading a key * nss: load libnssckbi.so if no other trust is specified * curl: use utimes instead of obsolescent utime when available * url: fixed a memory leak on OOM while setting CURLOPT_BUFFERSIZE * CURLOPT_BUFFERSIZE: 1024 bytes is now the minimum size * curl: non-boolean command line args reject --no- prefixes * telnet: Write full buffer instead of byte-by-byte * curl: remove --environment and tool_writeenv.c * curl: generate the --help output * curl.1: clarify --config * curl.1: mention --oauth2-bearer's argument * ssh: fix memory leak in disconnect due to timeout * redirect: store the "would redirect to" URL when max redirs is reached * file: make speedcheck use current time for checks * urlglob: fix division by zero- Create curl-mini for bootstrapping (boo#1042919)- Update to 7.54.0 Changes: * Add CURL_SSLVERSION_MAX_* constants to CURLOPT_SSLVERSION * Add --max-tls * Add CURLOPT_SUPPRESS_CONNECT_HEADERS * Add --suppress-connect-headers Bugfixes: * CVE-2017-7468: switch off SSL session id when client cert is used * bsc#1033413 * tests: use consistent environment variables for setting charset * proxy: fixed a memory leak on OOM * ftp: removed an erroneous free in an OOM path * ftp: fixed a NULL pointer dereference on OOM * gopher: fixed detection of an error condition from Curl_urldecode * url: fix unix-socket support for proxy-disabled builds * fix potential use of uninitialized variables * ares: return error at once if timed out before name resolve starts * URL: return error on malformed URLs with junk after port number * http2: Fix assertion error on redirect with CL=0 * --insecure: clarify that this option is for server connections * authneg: clear auth.multi flag at http_done * curl_easy_reset: Also reset the authentication state * proxy: skip SSL initialization for closed connections * http_proxy: ignore TE and CL in CONNECT 2xx responses * multi: fix streamclose() crash in debug mode * openssl: fall back on SSL_ERROR_* string when no error detail * asiohiper: make sure socket is open in event_cb * curl: check for end of input in writeout backslash handling * openssl: exclude DSA code when OPENSSL_NO_DSA is defined * http: Fix proxy connection reuse with basic-auth * pause: handle mixed types of data when paused * http: do not treat FTPS over CONNECT as HTTPS * conncache: make hashkey avoid malloc * multi: fix queueing of pending easy handles * low_speed_limit: improved function for longer time periods * nss: load CA certificates even with --insecure * Curl_expire_latest: ignore already expired timers * http2: fix handle leak in error path * openssl: make SSL_ERROR_to_str more future-proof * openssl: fix thread-safety bugs in error-handling * openssl: don't try to print nonexistant peer private keys- Update to 7.53.1 Bugfixes: * url: Improve CURLOPT_PROXY_CAPATH error handling * urldata: include curl_sspi.h when Windows SSPI is enabled * formdata: check for EOF when reading from stdin * tests: Set CHARSET & LANG to UTF-8 in 1035, 2046 and 2047 * url: Default the proxy CA bundle location to CURL_CA_BUNDLE * rand: added missing #ifdef HAVE_FCNTL_H around fcntl.h header- Update to 7.53.0 Changes: * unix_socket: added --abstract-unix-socket and CURLOPT_ABSTRACT_UNIX_SOCKET * CURLOPT_BUFFERSIZE: support enlarging receive buffer Bugfixes: * CVE-2017-2629: make SSL_VERIFYSTATUS work again * gnutls-random: check return code for failed random * openssl-random: check return code when asking for random * http: remove "Curl_http_done: called premature" message * cyassl: use time_t instead of long for timeout * build-wolfssl: Sync config with wolfSSL 3.10 * ftp-gss: check for init before use * configure: accept --with-libidn2 instead * ftp: failure to resolve proxy should return that error code * curl.1: add three more exit codes * docs/ciphers: link to our own new page about ciphers * vtls: s/SSLEAY/OPENSSL - fixes multi_socket timeouts with openssl * darwinssl: fix iOS build * darwinssl: fix CFArrayRef leak * cmake: use crypt32.lib when building with OpenSSL on windows * curl_formadd.3: CURLFORM_CONTENTSLENGTH not needed when chunked * digest_sspi: copy terminating NUL as well * curl: fix --remote-time incorrect times on Windows * curl.1: several updates and corrections * content_encoding: change return code on a failure * curl.h: CURLE_FUNCTION_NOT_FOUND is no longer in use * docs: TCP_KEEPALIVE start and interval default to 60 * darwinssl: --insecure overrides --cacert if both settings are in use * TheArtOfHttpScripting: grammar * CIPHERS.md: document GSKit ciphers * wolfssl: support setting cipher list * wolfssl: display negotiated SSL version and cipher * lib506: fix build for Open Watcom * asiohiper: improved socket handling * examples: make the C++ examples follow our code style too * tests/sws: retry send() on EWOULDBLOCK * cmake: Fix passing _WINSOCKAPI_ macro to compiler * smtp: Fix STARTTLS denied error message * imap/pop3: don't print response character in STARTTLS denied messages * rand: make it work without TLS backing * url: fix parsing for when 'file' is the default protocol * url: allow file://X:/path URLs on windows again * gnutls: check for alpn and ocsp in configure * IDN: Use TR46 'non-transitional' for toASCII translations * url: Fix NO_PROXY env var to work properly with --proxy option * CURLOPT_PREQUOTE.3: takes a struct curl_slist*, not a char* * docs: Add note about libcurl copying strings to CURLOPT_* manpages * curl: reset the easy handle at --next * --next docs: --trace and --trace-ascii are also global * --write-out docs: 'time_total' is not always shown with ms precision * http: print correct HTTP string in verbose output when using HTTP/2 * docs: improved language in README.md HISTORY.md CONTRIBUTE.md * http2: disable server push if not requested * nss: use the correct lock in nss_find_slot_by_name() * usercertinmem.c: improve the short description * CURLOPT_CONNECT_TO: Fix compile warnings * docs: non-blocking SSL handshake is now supported with NSS * *.rc: escape non-ASCII/non-UTF-8 character for clarity * mbedTLS: fix multi interface non-blocking handshake * PolarSSL: fix multi interface non-blocking handshake * VC: remove the makefile.vc6 build infra * telnet: fix windows compiler warnings * cookies: do not assume a valid domain has a dot * polarssl: fix hangs * gnutls: disable TLS session tickets * mbedtls: disable TLS session tickets * mbedtls: implement CTR-DRBG and HAVEGE random generators * openssl: Don't use certificate after transferring ownership * cmake: Support curl --xattr when built with cmake * OS400: Fix symbols * docs: Add more HTTPS proxy documentation * docs: use more HTTPS links * cmdline-opts: Fixed build and test in out of source tree builds * CHANGES.0: removed * schannel: Remove incorrect SNI disabled message * darwinssl: Avoid parsing certificates when not in verbose mode * test552: Fix typos * telnet: Fix typos * transfer: only retry nobody-requests for HTTP * http2: reset push header counter fixes crash * nss: make FTPS work with --proxytunnel * test1139: Added the --manual keyword since the manual is required * polarssl, mbedtls: Fix detection of pending data * http_proxy: Fix tiny memory leak upon edge case connecting to proxy * URL: only accept ";options" in SMTP/POP3/IMAP URL schemes * curl.1: ftp.sunet.se is no longer an FTP mirror * tool_operate: Show HTTPS-Proxy options on CURLE_SSL_CACERT * http2: fix memory-leak when denying push streams * configure: Allow disabling pthreads, fall back on Win32 threads * curl: fix typo in time condition warning message * axtls: adapt to API changes * tool_urlglob: Allow a glob range with the same start and stop * winbuild: add note on auto-detection of MACHINE in Makefile.vc * http: fix missing 'Content-Length: 0' while negotiating auth * proxy: fix hostname resolution and IDN conversion * docs: fix timeout handling in multi-uv example * digest_sspi: Fix nonce-count generation in HTTP digest * sftp: improved checks for create dir failures * smb: use getpid replacement for windows UWP builds * digest_sspi: Handle 'stale=TRUE' directive in HTTP digest - Remove curl-7.52.1-idn-fixes.patch, fixed upstream.- build with libidn2 for IDNA2008 support FATE#321897 CVE-2016-8625 bsc#1005649 add curl-7.52.1-idn-fixes.patch to fix test, among other things - re-enable tests that are no longer failing, remove curl-disable_failing_tests.patch- Update to 7.52.1 Bugfixes: * CVE-2016-9594: unititialized random bsc#1016738- Update to 7.52.0 Changes: * nss: map CURL_SSLVERSION_DEFAULT to NSS default * vtls: support TLS 1.3 via CURL_SSLVERSION_TLSv1_3 * curl: introduce the --tlsv1.3 option to force TLS 1.3 * curl: Add --retry-connrefused * proxy: Support HTTPS proxy and SOCKS+HTTP(s) * add CURLINFO_SCHEME, CURLINFO_PROTOCOL, and %{scheme} * curl: add --fail-early Bugfixes: * CVE-2016-9586: printf floating point buffer overflow * curl -w: added more decimal digits to timing counters * easy: Initialize info variables on easy init and duphandle * http2: Don't send header fields prohibited by HTTP/2 spec * ssh: check md5 fingerprints case insensitively (regression) * openssl: initial TLS 1.3 adaptions * SPNEGO: Fix memory leak when authentication fails * realloc: use Curl_saferealloc to avoid common mistakes * openssl: make sure to fail in the unlikely event that PRNG seeding fails * URL-parser: for file://[host]/ URLs, the [host] must be localhost * timeval: prefer time_t to hold seconds instead of long * glob: fix [a-c] globbing regression * curl.1: Clarify --dump-header only writes received headers * http2: Fix address sanitizer memcpy warning * http2: Use huge HTTP/2 windows * connects: Don't mix unix domain sockets with regular ones * url: Fix conn reuse for local ports and interfaces * x509: Limit ASN.1 structure sizes to 256K * http2: check nghttp2_session_set_local_window_size exists * http2: Fix crashes when parent stream gets aborted * CURLOPT_CONNECT_TO: Skip non-matching "connect-to" entries * URL parser: reject non-numerical port numbers * CONNECT: reject TE or CL in 2xx responses * CONNECT: read responses one byte at a time * curl: support zero-length argument strings in config files * openssl: don't use OpenSSL's ERR_PACK * curl.1: generated with the new man page system * curl_easy_recv: Improve documentation and example program * Curl_getconnectinfo: avoid checking if the connection is closed * CIPHERS.md: attempt to document TLS cipher names- Update to 7.51.0 Changes: * nss: additional cipher suites are now accepted by CURLOPT_SSL_CIPHER_LIST * New option: CURLOPT_KEEP_SENDING_ON_ERROR Bugfixes: * CVE-2016-8615: cookie injection for other servers * CVE-2016-8616: case insensitive password comparison * CVE-2016-8617: OOB write via unchecked multiplication * CVE-2016-8618: double-free in curl_maprintf * CVE-2016-8619: double-free in krb5 code * CVE-2016-8620: glob parser write/read out of bounds * CVE-2016-8621: curl_getdate read out of bounds * CVE-2016-8622: URL unescape heap overflow via integer truncation * CVE-2016-8623: Use-after-free via shared cookies * CVE-2016-8624: invalid URL parsing with '#' * CVE-2016-8625: IDNA 2003 makes curl use wrong host * openssl: fix per-thread memory leak using 1.0.1 or 1.0.2 * http: accept "Transfer-Encoding: chunked" for HTTP/2 as well * LICENSE-MIXING.md: update with mbedTLS dual licensing * examples/imap-append: Set size of data to be uploaded * test2048: fix url * darwinssl: disable RC4 cipher-suite support * CURLOPT_PINNEDPUBLICKEY.3: fix the AVAILABILITY formatting * openssl: don’t call CRYTPO_cleanup_all_ex_data * libressl: fix version output * easy: Reset all statistical session info in curl_easy_reset * curl_global_cleanup.3: don't unload the lib with sub threads running * dist: add CurlSymbolHiding.cmake to the tarball * docs: Remove that --proto is just used for initial retrieval * configure: Fixed builds with libssh2 in a custom location * curl.1: --trace supports % for sending to stderr! * cookies: same domain handling changed to match browser behavior * formpost: trying to attach a directory no longer crashes * CURLOPT_DEBUGFUNCTION.3: fixed unused argument warning * formpost: avoid silent snprintf() truncation * ftp: fix Curl_ftpsendf * mprintf: return error on too many arguments * smb: properly check incoming packet boundaries * GIT-INFO: remove the Mac 10.1-specific details * resolve: add error message when resolving using SIGALRM * cmake: add nghttp2 support * dist: remove PDF and HTML converted docs from the releases * configure: disable poll() in macOS builds * vtls: only re-use session-ids using the same scheme * pipelining: skip to-be-closed connections when pipelining * win: fix Universal Windows Platform build * curl: do not set CURLOPT_SSLENGINE to DEFAULT automatically * maketgz: make it support "only" generating version info * Curl_socket_check: add extra check to avoid integer overflow * gopher: properly return error for poll failures * curl: set INTERLEAVEDATA too * polarssl: clear thread array at init * polarssl: fix unaligned SSL session-id lock * polarssl: reduce #ifdef madness with a macro * curl_multi_add_handle: set timeouts in closure handles * configure: set min version flags for builds on mac * INSTALL: converted to markdown => INSTALL.md * curl_multi_remove_handle: fix a double-free * multi: fix inifinte loop in curl_multi_cleanup() * nss: fix tight loop in non-blocking TLS handhsake over proxy * mk-ca-bundle: Change URL retrieval to HTTPS-only by default * mbedtls: stop using deprecated include file * docs: fix req->data in multi-uv example * configure: Fix test syntax for monotonic clock_gettime * CURLMOPT_MAX_PIPELINE_LENGTH.3: Clarify it's not for HTTP/2 - Refresh libcurl-ocloexec.patch- update to 7.50.3 Bugfixes: * CVE-2016-7167: escape and unescape integer overflows * mk-ca-bundle.pl: use SHA256 instead of SHA1 * checksrc: detect strtok() use * errors: new alias CURLE_WEIRD_SERVER_REPLY * http2: support > 64bit sized uploads * openssl: fix bad memory free (regression) * CMake: hide private library symbols * http: refuse to pass on response body when NO_NODY is set * cmake: fix curl-config --static-libs * mbedtls: switch off NTLM in build if md4 isn't available * curl: --create-dirs on windows groks both forward and backward slashes- update to 7.50.2 Bugfixes: * mbedtls: Added support for NTLM * SSH: fixed SFTP/SCP transfer problems * multi: make Curl_expire() work with 0 ms timeouts * mk-ca-bundle.pl: -m keeps ca cert meta data in output * TFTP: Fix upload problem with piped input * CURLOPT_TCP_NODELAY: now enabled by default * mbedtls: set verbose TLS debug when MBEDTLS_DEBUG is defined * http2: always wait for readable socket * cmake: Enable win32 large file support by default * cmake: Enable win32 threaded resolver by default * winbuild: Avoid setting redundant CFLAGS to compile commands * curl.h: make CURL_NO_OLDIES define CURL_STRICTER * docs: make more markdown files use .md extension * docs: CONTRIBUTE and LICENSE-MIXING were converted to markdown * winbuild: Allow changing C compiler via environment variable CC * rtsp: accept any RTSP session id * HTTP: retry failed HEAD requests on reused connections too * configure: add zlib search with pkg-config * openssl: accept subjectAltName iPAddress if no dNSName match * MANUAL: Remove invalid link to LDAP documentation * socks: improved connection procedure * proxy: reject attempts to use unsupported proxy schemes * proxy: bring back use of "Proxy-Connection:" * curl: allow "pkcs11:" prefix for client certificates * spnego_sspi: fix memory leak in case *outlen is zero * SOCKS: improve verbose output of SOCKS5 connection sequence * SOCKS: display the hostname returned by the SOCKS5 proxy server * http/sasl: Query authentication mechanism supported by SSPI before using * sasl: Don't use GSSAPI authentication when domain name not specified * win: Basic support for Universal Windows Platform apps * nss: fix incorrect use of a previously loaded certificate from file, https://curl.haxx.se/docs/adv_20160907.html * nss: work around race condition in PK11_FindSlotByName() * ftp: fix wrong poll on the secondary socket * openssl: build warning-free with 1.1.0 (again) * HTTP: stop parsing headers when switching to unknown protocols * test219: Add http as a required feature * TLS: random file/egd doesn't have to match for conn reuse * schannel: Disable ALPN for Wine since it is causing problems * http2: make sure stream errors don't needlessly close the connection * http2: return CURLE_HTTP2_STREAM for unexpected stream close * darwinssl: --cainfo is intended for backward compatibility only * speed caps: not based on average speeds anymore * configure: make the cpp -P detection not clobber CPPFLAGS * http2: use named define instead of magic constant in read callback * http2: skip the content-length parsing, detect unknown size * http2: return EOF when done uploading without known size * darwinssl: test for errSecSuccess in PKCS12 import rather than noErr * openssl: fix CURLINFO_SSL_VERIFYRESULT- update to 7.50.1 Bugfixes: * TLS: switch off SSL session id when client cert is used * TLS: only reuse connections with the same client cert * curl_multi_cleanup: clear connection pointer for easy handles * include the CURLINFO_HTTP_VERSION man page into the release tarball * include the http2-server.pl script in the release tarball * test558: fix test by stripping file paths from FD lines * spnego: Corrected miss-placed * in Curl_auth_spnego_cleanup() declaration * tests: Fix for http/2 feature * cmake: Fix for schannel support * curl.h: make public types void * again * win32: fix a potential memory leak in Curl_load_library * travis: fix OSX build by re-installing libtool * mbedtls: Fix debug function name - removed 0001-tests-distribute-the-http2-server.pl-script-too.patch- update to 7.50.0 Changes: * http: add CURLINFO_HTTP_VERSION and %{http_version} Bugfixes: * openssl: fix build with OPENSSL_NO_COMP * cmake: Added missing mbedTLS support * URL parser: allow URLs to use one, two or three slashes * curl: fix -q [regression] * openssl: Use correct buffer sizes for error messages * curl: fix SIGSEGV while parsing URL with too many globs * vtls: fix ssl session cache race condition * http: Fix HTTP/2 connection reuse [regression] * checksrc: Add LoadLibrary to the banned functions list * configure: occasional ignorance of --enable-symbol-hiding with GCC * http2: test17xx are the first real HTTP/2 tests * resolve: add support for IPv6 DNS64/NAT64 Networks on OS X + iOS * curl_multi_socket_action.3: rewording * CURLOPT_POSTFIELDS.3: Clarify what happens when set empty * cmake: Fix build with winldap * openssl: fix cert check with non-DNS name fields present * curl.1: mention the units for the progress meter * openssl: use more 'const' to fix build warnings with 1.1.0 branch * cmake: now using BUILD_TESTING=ON/OFF * vtls: Only call add/getsession if session id is enabled * headers: forward declare CURL, CURLM and CURLSH as structs * configure: improve detection of CA bundle path on FreeBSD * SFTP: set a generic error when no SFTP one exists * curl_global_init.3: expand on the SSL and WIN32 bits purpose * conn: don't free easy handle data in handler->disconnect * cookie.c: Fix misleading indentation * library: Fix memory leaks found during static analysis * CURLMOPT_SOCKETFUNCTION.3: fix typo * curl_global_init: moved the "IPv6 works" check here * connect: disable TFO on Linux when using SSL * vauth: Fixed memory leak due to function returning without free - refresh libcurl-ocloexec.patch - disable tests 1139 and 1140 which fail due to missing manpage * add curl-disable_failing_tests.patch - ship http2_server.pl for testing * add 0001-tests-distribute-the-http2-server.pl-script-too.patch- curl 7.49.1: * http2: use HTTP/2 in the HTTP/1.1-alike response * ssh: fix build for libssh2 before 1.2.6 * a number of bug and build fixes - curl 7.49.0: * schannel: Add ALPN support * SSH: support CURLINFO_FILETIME * SSH: new CURLOPT_QUOTE command "statvfs" * wolfssl: Add ALPN support * http2: added --http2-prior-knowledge * http2: added CURL_HTTP_VERSION_2_PRIOR_KNOWLEDGE * libcurl: added CURLOPT_CONNECT_TO * curl: added --connect-to * libcurl: added CURLOPT_TCP_FASTOPEN * curl: added --tcp-fastopen * curl: remove support for --ftpport, -http-request and --socks * a number of bug and build fixes - update upstream signing key and download URLs - 0001-Fix-invalid-Network-is-unreachable-errors.patch is upstream- Depend on libssh2 >= 1.6.0 since curl depends on the libssh2_scp_recv2 symbol now. Fixes boo#983170- Add 0001-Fix-invalid-Network-is-unreachable-errors.patch. Fixes "Network is unreachable" errors in valid situations when ipv6 is not available but ipv4 is working fine. This also fixes the same error from happening in applications using libcurl4 (like zypper). (bsc#915846)- Update to 7.48.0 * configure: --with-ca-fallback: use built-in TLS CA fallback * TFTP: add --tftp-no-options to expose CURLOPT_TFTP_NO_OPTIONS * getinfo: CURLINFO_TLS_SSL_PTR supersedes CURLINFO_TLS_SESSION * Lots of bugfixes, see https://curl.haxx.se/changes.html#7_48_0 - Drop curl-7.41.0-use-openssl-s-built-in-verify-path-as-fallback.diff, superseded by --with-ca-fallback configure option.- curl 7.47.1: * getredirect.c: fix variable name * tool_doswin: silence unused function warning * curl.1: Explain remote-name behavior if file already exists * sasl_sspi: Fix memory leak in domain populate * openssl: Fix signed/unsigned mismatch warning in X509V3_ext- Enable PSL (Publix Suffix List) - Make building more verbose- update to 7.47.0 * fixes CVE-2016-0755 (bsc#962983) (NTLM credentials not-checked for proxy connection re-use) * drop curl-fix-zsh-completion.patch (upstream) Changes: * version: Add flag CURL_VERSION_PSL for libpsl * http: added CURL_HTTP_VERSION_2TLS to do HTTP/2 for HTTPS only * curl: use 2TLS by default * curl --expect100-timeout: added * Add .dir-locals and set c-basic-offset to 2 (for emacs)- Fix path to curl in zsh.pl to unbreak _curl completion * curl-fix-zsh-completion.patch- Update to 7.46.0 * Added CURLOPT_STREAM_DEPENDS * Added CURLOPT_STREAM_DEPENDS_E * Added CURLOPT_STREAM_WEIGHT * Added CURLFORM_CONTENTLEN * oauth2: Added support for OAUTHBEARER SASL mechanism to IMAP, POP3 and SNMP * Many bugfixes, see http://curl.haxx.se/changes.html#7_46_0 for the complete list.- revert the curl-config change for bsc#900419 until we have a better fix, because it was breaking builds of other packages- Enable HTTP/2 support, buildrequires pkgconfig(libnghttp2)- Update to 7.45.0 * added CURLOPT_DEFAULT_PROTOCOL * added new tool option --proto-default * getinfo: added CURLINFO_ACTIVESOCKET * turned CURLINFO_* option docs as stand-alone man pages * curl: point out unnecessary uses of -X in verbose mode - Drop curl-disable_failing_tests.patch as it is now part of upstream- drop a hack that made curl-config print only -lcurl (bsc#900419) * --as-needed is used by default now- update to 7.44.0 http2: added CURLMOPT_PUSHFUNCTION and CURLMOPT_PUSHDATA examples: added http2-serverpush.c http2: added curl_pushheader_byname() and curl_pushheader_bynum() docs: added CODE_OF_CONDUCT.md curl: Add --ssl-no-revoke to disable certificate revocation checks libcurl: New value CURLSSLOPT_NO_REVOKE for CURLOPT_SSL_OPTIONS makefile: Added support for VC14 - dropped unexpire-test46.patch (upstream)- unexpire-test46.patch: Unexpire test 46- do not run flaky tests for any architecture (bnc#940009) at least test 1510 do fail for i586 and ppc64le- fix a typo in curl-secure-getenv.patch (bsc#936676)- Update to 7.43.0 * Added CURLOPT_PROXY_SERVICE_NAME * Added CURLOPT_SERVICE_NAME * New curl option: --proxy-service-name * Mew curl option: --service-name * New curl option: --data-raw * Added CURLOPT_PIPEWAIT * Added support for multiplexing transfers using HTTP/2, enable this with the new CURLPIPE_MULTIPLEX bit for CURLMOPT_PIPELINING * HTTP/2: requires nghttp2 1.0.0 or later * scripts: add zsh.pl for generating zsh completion * curl.h: add CURL_HTTP_VERSION_2 * CVE-2015-3236: lingering HTTP credentials in connection re-use * CVE-2015-3237: SMB send off unrelated memory contents - Disable HTTP/2 as it would create build cycle- enable HTTP/2 support - make the testsuite failure fatal * added curl-disable_failing_tests.patch * added groff to BuildRequires to enable builtin manual (test 1026)- update to 7.42.1 * fixes CVE-2015-3153 (bnc#928533) - sensitive HTTP server headers also sent to proxies - rename curl-devel to libcurl-devel in baselibs.conf- update to 7.42.0 * refresh libcurl-ocloexec.patch - fixes security vulnerabilities: * CVE-2015-3143 (bnc#927556) - Re-using authenticated connection when unauthenticated * CVE-2015-3144 (bnc#927608) - host name out of boundary memory access * CVE-2015-3145 (bnc#927607) - cookie parser out of boundary memory access * CVE-2015-3148 (bnc#927746) - Negotiate not treated as connection-oriented- don't hardcode /etc/ssl/certs. Use openssl's default instead (curl-7.41.0-use-openssl-s-built-in-verify-path-as-fallback.diff)- update to 7.41.0: * Changes: NetWare build: added TLS-SRP enabled build winbuild: Added option to build with c-ares Added --cert-status Added CURLOPT_SSL_VERIFYSTATUS sasl: implement EXTERNAL authentication mechanism- Re-enable metalink supoort - Use pkgconfig() style dependencies- update to 7.40.0: * fixes CVE-2014-8150 (bnc#911363) * Changes: http_digest: Added support for Windows SSPI based authentication version info: Added Kerberos V5 to the supported features Makefile: Added VC targets for WinIDN config-win32: Introduce build targets for VS2012+ SSL: Add PEM format support for public key pinning smtp: Added support for the conversion of Unix newlines during mail send smb: Added initial support for the SMB/CIFS protocol Added support for HTTP over unix domain sockets, via CURLOPT_UNIX_SOCKET_PATH and --unix-socket sasl: Added support for GSS-API based Kerberos V5 authentication- build with PIE- update to 7.39.0: - changes: SSLv3 is disabled by default CURLOPT_COOKIELIST: Added "RELOAD" command build: Added WinIDN build configuration options to Visual Studio projects ssh: improve key file search SSL: public key pinning. Use CURLOPT_PINNEDPUBLICKEY and --pinnedpubkey vtls: remove QsoSSL support, use gskit! mk-ca-bundle: added SHA-384 signature algorithm docs: added many examples for libcurl opts and other doc improvements build: Added VC ssh2 target to main Makefile MinGW: Added support to build with nghttp2 NetWare: Added support to build with nghttp2 build: added Watcom support to build with WinSSL build: Added optional specific version generation of VC project files ... and a bunch of bugfixes - refreshed libcurl-ocloexec.patch - removed gpg-offline verification - spec-cleaned curl.spec- Ensure the curl command line tool always require the same libcurl it was used for build, even expert users got confused.curl-develarmbuild24 1633536926  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~ 7.15.57.66.0-lp152.3.24.17.66.0-lp152.3.24.17.66.0-lp152.3.24.17.66.07.16.2 curl-configcurlcurl.hcurlver.heasy.hmprintf.hmulti.hstdcheaders.hsystem.htypecheck-gcc.hurlapi.hlibcurl.solibcurl.pcaclocallibcurl.m4libcurl-mini-develsymbols-in-versionscurl-config.1.gzCURLINFO_ACTIVESOCKET.3.gzCURLINFO_APPCONNECT_TIME.3.gzCURLINFO_APPCONNECT_TIME_T.3.gzCURLINFO_CERTINFO.3.gzCURLINFO_CONDITION_UNMET.3.gzCURLINFO_CONNECT_TIME.3.gzCURLINFO_CONNECT_TIME_T.3.gzCURLINFO_CONTENT_LENGTH_DOWNLOAD.3.gzCURLINFO_CONTENT_LENGTH_DOWNLOAD_T.3.gzCURLINFO_CONTENT_LENGTH_UPLOAD.3.gzCURLINFO_CONTENT_LENGTH_UPLOAD_T.3.gzCURLINFO_CONTENT_TYPE.3.gzCURLINFO_COOKIELIST.3.gzCURLINFO_EFFECTIVE_URL.3.gzCURLINFO_FILETIME.3.gzCURLINFO_FILETIME_T.3.gzCURLINFO_FTP_ENTRY_PATH.3.gzCURLINFO_HEADER_SIZE.3.gzCURLINFO_HTTPAUTH_AVAIL.3.gzCURLINFO_HTTP_CONNECTCODE.3.gzCURLINFO_HTTP_VERSION.3.gzCURLINFO_LASTSOCKET.3.gzCURLINFO_LOCAL_IP.3.gzCURLINFO_LOCAL_PORT.3.gzCURLINFO_NAMELOOKUP_TIME.3.gzCURLINFO_NAMELOOKUP_TIME_T.3.gzCURLINFO_NUM_CONNECTS.3.gzCURLINFO_OS_ERRNO.3.gzCURLINFO_PRETRANSFER_TIME.3.gzCURLINFO_PRETRANSFER_TIME_T.3.gzCURLINFO_PRIMARY_IP.3.gzCURLINFO_PRIMARY_PORT.3.gzCURLINFO_PRIVATE.3.gzCURLINFO_PROTOCOL.3.gzCURLINFO_PROXYAUTH_AVAIL.3.gzCURLINFO_PROXY_SSL_VERIFYRESULT.3.gzCURLINFO_REDIRECT_COUNT.3.gzCURLINFO_REDIRECT_TIME.3.gzCURLINFO_REDIRECT_TIME_T.3.gzCURLINFO_REDIRECT_URL.3.gzCURLINFO_REQUEST_SIZE.3.gzCURLINFO_RESPONSE_CODE.3.gzCURLINFO_RETRY_AFTER.3.gzCURLINFO_RTSP_CLIENT_CSEQ.3.gzCURLINFO_RTSP_CSEQ_RECV.3.gzCURLINFO_RTSP_SERVER_CSEQ.3.gzCURLINFO_RTSP_SESSION_ID.3.gzCURLINFO_SCHEME.3.gzCURLINFO_SIZE_DOWNLOAD.3.gzCURLINFO_SIZE_DOWNLOAD_T.3.gzCURLINFO_SIZE_UPLOAD.3.gzCURLINFO_SIZE_UPLOAD_T.3.gzCURLINFO_SPEED_DOWNLOAD.3.gzCURLINFO_SPEED_DOWNLOAD_T.3.gzCURLINFO_SPEED_UPLOAD.3.gzCURLINFO_SPEED_UPLOAD_T.3.gzCURLINFO_SSL_ENGINES.3.gzCURLINFO_SSL_VERIFYRESULT.3.gzCURLINFO_STARTTRANSFER_TIME.3.gzCURLINFO_STARTTRANSFER_TIME_T.3.gzCURLINFO_TLS_SESSION.3.gzCURLINFO_TLS_SSL_PTR.3.gzCURLINFO_TOTAL_TIME.3.gzCURLINFO_TOTAL_TIME_T.3.gzCURLMOPT_CHUNK_LENGTH_PENALTY_SIZE.3.gzCURLMOPT_CONTENT_LENGTH_PENALTY_SIZE.3.gzCURLMOPT_MAXCONNECTS.3.gzCURLMOPT_MAX_HOST_CONNECTIONS.3.gzCURLMOPT_MAX_PIPELINE_LENGTH.3.gzCURLMOPT_MAX_TOTAL_CONNECTIONS.3.gzCURLMOPT_PIPELINING.3.gzCURLMOPT_PIPELINING_SERVER_BL.3.gzCURLMOPT_PIPELINING_SITE_BL.3.gzCURLMOPT_PUSHDATA.3.gzCURLMOPT_PUSHFUNCTION.3.gzCURLMOPT_SOCKETDATA.3.gzCURLMOPT_SOCKETFUNCTION.3.gzCURLMOPT_TIMERDATA.3.gzCURLMOPT_TIMERFUNCTION.3.gzCURLOPT_ABSTRACT_UNIX_SOCKET.3.gzCURLOPT_ACCEPTTIMEOUT_MS.3.gzCURLOPT_ACCEPT_ENCODING.3.gzCURLOPT_ADDRESS_SCOPE.3.gzCURLOPT_ALTSVC.3.gzCURLOPT_ALTSVC_CTRL.3.gzCURLOPT_APPEND.3.gzCURLOPT_AUTOREFERER.3.gzCURLOPT_BUFFERSIZE.3.gzCURLOPT_CAINFO.3.gzCURLOPT_CAPATH.3.gzCURLOPT_CERTINFO.3.gzCURLOPT_CHUNK_BGN_FUNCTION.3.gzCURLOPT_CHUNK_DATA.3.gzCURLOPT_CHUNK_END_FUNCTION.3.gzCURLOPT_CLOSESOCKETDATA.3.gzCURLOPT_CLOSESOCKETFUNCTION.3.gzCURLOPT_CONNECTTIMEOUT.3.gzCURLOPT_CONNECTTIMEOUT_MS.3.gzCURLOPT_CONNECT_ONLY.3.gzCURLOPT_CONNECT_TO.3.gzCURLOPT_CONV_FROM_NETWORK_FUNCTION.3.gzCURLOPT_CONV_FROM_UTF8_FUNCTION.3.gzCURLOPT_CONV_TO_NETWORK_FUNCTION.3.gzCURLOPT_COOKIE.3.gzCURLOPT_COOKIEFILE.3.gzCURLOPT_COOKIEJAR.3.gzCURLOPT_COOKIELIST.3.gzCURLOPT_COOKIESESSION.3.gzCURLOPT_COPYPOSTFIELDS.3.gzCURLOPT_CRLF.3.gzCURLOPT_CRLFILE.3.gzCURLOPT_CURLU.3.gzCURLOPT_CUSTOMREQUEST.3.gzCURLOPT_DEBUGDATA.3.gzCURLOPT_DEBUGFUNCTION.3.gzCURLOPT_DEFAULT_PROTOCOL.3.gzCURLOPT_DIRLISTONLY.3.gzCURLOPT_DISALLOW_USERNAME_IN_URL.3.gzCURLOPT_DNS_CACHE_TIMEOUT.3.gzCURLOPT_DNS_INTERFACE.3.gzCURLOPT_DNS_LOCAL_IP4.3.gzCURLOPT_DNS_LOCAL_IP6.3.gzCURLOPT_DNS_SERVERS.3.gzCURLOPT_DNS_SHUFFLE_ADDRESSES.3.gzCURLOPT_DNS_USE_GLOBAL_CACHE.3.gzCURLOPT_DOH_URL.3.gzCURLOPT_EGDSOCKET.3.gzCURLOPT_ERRORBUFFER.3.gzCURLOPT_EXPECT_100_TIMEOUT_MS.3.gzCURLOPT_FAILONERROR.3.gzCURLOPT_FILETIME.3.gzCURLOPT_FNMATCH_DATA.3.gzCURLOPT_FNMATCH_FUNCTION.3.gzCURLOPT_FOLLOWLOCATION.3.gzCURLOPT_FORBID_REUSE.3.gzCURLOPT_FRESH_CONNECT.3.gzCURLOPT_FTPPORT.3.gzCURLOPT_FTPSSLAUTH.3.gzCURLOPT_FTP_ACCOUNT.3.gzCURLOPT_FTP_ALTERNATIVE_TO_USER.3.gzCURLOPT_FTP_CREATE_MISSING_DIRS.3.gzCURLOPT_FTP_FILEMETHOD.3.gzCURLOPT_FTP_RESPONSE_TIMEOUT.3.gzCURLOPT_FTP_SKIP_PASV_IP.3.gzCURLOPT_FTP_SSL_CCC.3.gzCURLOPT_FTP_USE_EPRT.3.gzCURLOPT_FTP_USE_EPSV.3.gzCURLOPT_FTP_USE_PRET.3.gzCURLOPT_GSSAPI_DELEGATION.3.gzCURLOPT_HAPPY_EYEBALLS_TIMEOUT_MS.3.gzCURLOPT_HAPROXYPROTOCOL.3.gzCURLOPT_HEADER.3.gzCURLOPT_HEADERDATA.3.gzCURLOPT_HEADERFUNCTION.3.gzCURLOPT_HEADEROPT.3.gzCURLOPT_HTTP09_ALLOWED.3.gzCURLOPT_HTTP200ALIASES.3.gzCURLOPT_HTTPAUTH.3.gzCURLOPT_HTTPGET.3.gzCURLOPT_HTTPHEADER.3.gzCURLOPT_HTTPPOST.3.gzCURLOPT_HTTPPROXYTUNNEL.3.gzCURLOPT_HTTP_CONTENT_DECODING.3.gzCURLOPT_HTTP_TRANSFER_DECODING.3.gzCURLOPT_HTTP_VERSION.3.gzCURLOPT_IGNORE_CONTENT_LENGTH.3.gzCURLOPT_INFILESIZE.3.gzCURLOPT_INFILESIZE_LARGE.3.gzCURLOPT_INTERFACE.3.gzCURLOPT_INTERLEAVEDATA.3.gzCURLOPT_INTERLEAVEFUNCTION.3.gzCURLOPT_IOCTLDATA.3.gzCURLOPT_IOCTLFUNCTION.3.gzCURLOPT_IPRESOLVE.3.gzCURLOPT_ISSUERCERT.3.gzCURLOPT_KEEP_SENDING_ON_ERROR.3.gzCURLOPT_KEYPASSWD.3.gzCURLOPT_KRBLEVEL.3.gzCURLOPT_LOCALPORT.3.gzCURLOPT_LOCALPORTRANGE.3.gzCURLOPT_LOGIN_OPTIONS.3.gzCURLOPT_LOW_SPEED_LIMIT.3.gzCURLOPT_LOW_SPEED_TIME.3.gzCURLOPT_MAIL_AUTH.3.gzCURLOPT_MAIL_FROM.3.gzCURLOPT_MAIL_RCPT.3.gzCURLOPT_MAXAGE_CONN.3.gzCURLOPT_MAXCONNECTS.3.gzCURLOPT_MAXFILESIZE.3.gzCURLOPT_MAXFILESIZE_LARGE.3.gzCURLOPT_MAXREDIRS.3.gzCURLOPT_MAX_RECV_SPEED_LARGE.3.gzCURLOPT_MAX_SEND_SPEED_LARGE.3.gzCURLOPT_MIMEPOST.3.gzCURLOPT_NETRC.3.gzCURLOPT_NETRC_FILE.3.gzCURLOPT_NEW_DIRECTORY_PERMS.3.gzCURLOPT_NEW_FILE_PERMS.3.gzCURLOPT_NOBODY.3.gzCURLOPT_NOPROGRESS.3.gzCURLOPT_NOPROXY.3.gzCURLOPT_NOSIGNAL.3.gzCURLOPT_OPENSOCKETDATA.3.gzCURLOPT_OPENSOCKETFUNCTION.3.gzCURLOPT_PASSWORD.3.gzCURLOPT_PATH_AS_IS.3.gzCURLOPT_PINNEDPUBLICKEY.3.gzCURLOPT_PIPEWAIT.3.gzCURLOPT_PORT.3.gzCURLOPT_POST.3.gzCURLOPT_POSTFIELDS.3.gzCURLOPT_POSTFIELDSIZE.3.gzCURLOPT_POSTFIELDSIZE_LARGE.3.gzCURLOPT_POSTQUOTE.3.gzCURLOPT_POSTREDIR.3.gzCURLOPT_PREQUOTE.3.gzCURLOPT_PRE_PROXY.3.gzCURLOPT_PRIVATE.3.gzCURLOPT_PROGRESSDATA.3.gzCURLOPT_PROGRESSFUNCTION.3.gzCURLOPT_PROTOCOLS.3.gzCURLOPT_PROXY.3.gzCURLOPT_PROXYAUTH.3.gzCURLOPT_PROXYHEADER.3.gzCURLOPT_PROXYPASSWORD.3.gzCURLOPT_PROXYPORT.3.gzCURLOPT_PROXYTYPE.3.gzCURLOPT_PROXYUSERNAME.3.gzCURLOPT_PROXYUSERPWD.3.gzCURLOPT_PROXY_CAINFO.3.gzCURLOPT_PROXY_CAPATH.3.gzCURLOPT_PROXY_CRLFILE.3.gzCURLOPT_PROXY_KEYPASSWD.3.gzCURLOPT_PROXY_PINNEDPUBLICKEY.3.gzCURLOPT_PROXY_SERVICE_NAME.3.gzCURLOPT_PROXY_SSLCERT.3.gzCURLOPT_PROXY_SSLCERTTYPE.3.gzCURLOPT_PROXY_SSLKEY.3.gzCURLOPT_PROXY_SSLKEYTYPE.3.gzCURLOPT_PROXY_SSLVERSION.3.gzCURLOPT_PROXY_SSL_CIPHER_LIST.3.gzCURLOPT_PROXY_SSL_OPTIONS.3.gzCURLOPT_PROXY_SSL_VERIFYHOST.3.gzCURLOPT_PROXY_SSL_VERIFYPEER.3.gzCURLOPT_PROXY_TLS13_CIPHERS.3.gzCURLOPT_PROXY_TLSAUTH_PASSWORD.3.gzCURLOPT_PROXY_TLSAUTH_TYPE.3.gzCURLOPT_PROXY_TLSAUTH_USERNAME.3.gzCURLOPT_PROXY_TRANSFER_MODE.3.gzCURLOPT_PUT.3.gzCURLOPT_QUOTE.3.gzCURLOPT_RANDOM_FILE.3.gzCURLOPT_RANGE.3.gzCURLOPT_READDATA.3.gzCURLOPT_READFUNCTION.3.gzCURLOPT_REDIR_PROTOCOLS.3.gzCURLOPT_REFERER.3.gzCURLOPT_REQUEST_TARGET.3.gzCURLOPT_RESOLVE.3.gzCURLOPT_RESOLVER_START_DATA.3.gzCURLOPT_RESOLVER_START_FUNCTION.3.gzCURLOPT_RESUME_FROM.3.gzCURLOPT_RESUME_FROM_LARGE.3.gzCURLOPT_RTSP_CLIENT_CSEQ.3.gzCURLOPT_RTSP_REQUEST.3.gzCURLOPT_RTSP_SERVER_CSEQ.3.gzCURLOPT_RTSP_SESSION_ID.3.gzCURLOPT_RTSP_STREAM_URI.3.gzCURLOPT_RTSP_TRANSPORT.3.gzCURLOPT_SASL_AUTHZID.3.gzCURLOPT_SASL_IR.3.gzCURLOPT_SEEKDATA.3.gzCURLOPT_SEEKFUNCTION.3.gzCURLOPT_SERVICE_NAME.3.gzCURLOPT_SHARE.3.gzCURLOPT_SOCKOPTDATA.3.gzCURLOPT_SOCKOPTFUNCTION.3.gzCURLOPT_SOCKS5_AUTH.3.gzCURLOPT_SOCKS5_GSSAPI_NEC.3.gzCURLOPT_SOCKS5_GSSAPI_SERVICE.3.gzCURLOPT_SSH_AUTH_TYPES.3.gzCURLOPT_SSH_COMPRESSION.3.gzCURLOPT_SSH_HOST_PUBLIC_KEY_MD5.3.gzCURLOPT_SSH_KEYDATA.3.gzCURLOPT_SSH_KEYFUNCTION.3.gzCURLOPT_SSH_KNOWNHOSTS.3.gzCURLOPT_SSH_PRIVATE_KEYFILE.3.gzCURLOPT_SSH_PUBLIC_KEYFILE.3.gzCURLOPT_SSLCERT.3.gzCURLOPT_SSLCERTTYPE.3.gzCURLOPT_SSLENGINE.3.gzCURLOPT_SSLENGINE_DEFAULT.3.gzCURLOPT_SSLKEY.3.gzCURLOPT_SSLKEYTYPE.3.gzCURLOPT_SSLVERSION.3.gzCURLOPT_SSL_CIPHER_LIST.3.gzCURLOPT_SSL_CTX_DATA.3.gzCURLOPT_SSL_CTX_FUNCTION.3.gzCURLOPT_SSL_ENABLE_ALPN.3.gzCURLOPT_SSL_ENABLE_NPN.3.gzCURLOPT_SSL_FALSESTART.3.gzCURLOPT_SSL_OPTIONS.3.gzCURLOPT_SSL_SESSIONID_CACHE.3.gzCURLOPT_SSL_VERIFYHOST.3.gzCURLOPT_SSL_VERIFYPEER.3.gzCURLOPT_SSL_VERIFYSTATUS.3.gzCURLOPT_STDERR.3.gzCURLOPT_STREAM_DEPENDS.3.gzCURLOPT_STREAM_DEPENDS_E.3.gzCURLOPT_STREAM_WEIGHT.3.gzCURLOPT_SUPPRESS_CONNECT_HEADERS.3.gzCURLOPT_TCP_FASTOPEN.3.gzCURLOPT_TCP_KEEPALIVE.3.gzCURLOPT_TCP_KEEPIDLE.3.gzCURLOPT_TCP_KEEPINTVL.3.gzCURLOPT_TCP_NODELAY.3.gzCURLOPT_TELNETOPTIONS.3.gzCURLOPT_TFTP_BLKSIZE.3.gzCURLOPT_TFTP_NO_OPTIONS.3.gzCURLOPT_TIMECONDITION.3.gzCURLOPT_TIMEOUT.3.gzCURLOPT_TIMEOUT_MS.3.gzCURLOPT_TIMEVALUE.3.gzCURLOPT_TIMEVALUE_LARGE.3.gzCURLOPT_TLS13_CIPHERS.3.gzCURLOPT_TLSAUTH_PASSWORD.3.gzCURLOPT_TLSAUTH_TYPE.3.gzCURLOPT_TLSAUTH_USERNAME.3.gzCURLOPT_TRAILERDATA.3.gzCURLOPT_TRAILERFUNCTION.3.gzCURLOPT_TRANSFERTEXT.3.gzCURLOPT_TRANSFER_ENCODING.3.gzCURLOPT_UNIX_SOCKET_PATH.3.gzCURLOPT_UNRESTRICTED_AUTH.3.gzCURLOPT_UPKEEP_INTERVAL_MS.3.gzCURLOPT_UPLOAD.3.gzCURLOPT_UPLOAD_BUFFERSIZE.3.gzCURLOPT_URL.3.gzCURLOPT_USERAGENT.3.gzCURLOPT_USERNAME.3.gzCURLOPT_USERPWD.3.gzCURLOPT_USE_SSL.3.gzCURLOPT_VERBOSE.3.gzCURLOPT_WILDCARDMATCH.3.gzCURLOPT_WRITEDATA.3.gzCURLOPT_WRITEFUNCTION.3.gzCURLOPT_XFERINFODATA.3.gzCURLOPT_XFERINFOFUNCTION.3.gzCURLOPT_XOAUTH2_BEARER.3.gzcurl_easy_cleanup.3.gzcurl_easy_duphandle.3.gzcurl_easy_escape.3.gzcurl_easy_getinfo.3.gzcurl_easy_init.3.gzcurl_easy_pause.3.gzcurl_easy_perform.3.gzcurl_easy_recv.3.gzcurl_easy_reset.3.gzcurl_easy_send.3.gzcurl_easy_setopt.3.gzcurl_easy_strerror.3.gzcurl_easy_unescape.3.gzcurl_easy_upkeep.3.gzcurl_escape.3.gzcurl_formadd.3.gzcurl_formfree.3.gzcurl_formget.3.gzcurl_free.3.gzcurl_getdate.3.gzcurl_getenv.3.gzcurl_global_cleanup.3.gzcurl_global_init.3.gzcurl_global_init_mem.3.gzcurl_global_sslset.3.gzcurl_mime_addpart.3.gzcurl_mime_data.3.gzcurl_mime_data_cb.3.gzcurl_mime_encoder.3.gzcurl_mime_filedata.3.gzcurl_mime_filename.3.gzcurl_mime_free.3.gzcurl_mime_headers.3.gzcurl_mime_init.3.gzcurl_mime_name.3.gzcurl_mime_subparts.3.gzcurl_mime_type.3.gzcurl_mprintf.3.gzcurl_multi_add_handle.3.gzcurl_multi_assign.3.gzcurl_multi_cleanup.3.gzcurl_multi_fdset.3.gzcurl_multi_info_read.3.gzcurl_multi_init.3.gzcurl_multi_perform.3.gzcurl_multi_poll.3.gzcurl_multi_remove_handle.3.gzcurl_multi_setopt.3.gzcurl_multi_socket.3.gzcurl_multi_socket_action.3.gzcurl_multi_socket_all.3.gzcurl_multi_strerror.3.gzcurl_multi_timeout.3.gzcurl_multi_wait.3.gzcurl_share_cleanup.3.gzcurl_share_init.3.gzcurl_share_setopt.3.gzcurl_share_strerror.3.gzcurl_slist_append.3.gzcurl_slist_free_all.3.gzcurl_strequal.3.gzcurl_strnequal.3.gzcurl_unescape.3.gzcurl_url.3.gzcurl_url_cleanup.3.gzcurl_url_dup.3.gzcurl_url_get.3.gzcurl_url_set.3.gzcurl_version.3.gzcurl_version_info.3.gzlibcurl-easy.3.gzlibcurl-env.3.gzlibcurl-errors.3.gzlibcurl-multi.3.gzlibcurl-security.3.gzlibcurl-share.3.gzlibcurl-symbols.3.gzlibcurl-thread.3.gzlibcurl-tutorial.3.gzlibcurl-url.3.gzlibcurl.3.gz/usr/bin//usr/include//usr/include/curl//usr/lib64//usr/lib64/pkgconfig//usr/share//usr/share/aclocal//usr/share/doc/packages//usr/share/doc/packages/libcurl-mini-devel//usr/share/man/man1//usr/share/man/man3/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.opensuse.org/openSUSE:Maintenance:17014/openSUSE_Leap_15.2_Update_ports/066f019eb5731532664280eb7fbc5333-curl-mini.openSUSE_Leap_15.2_Updatedrpmxz5aarch64-suse-linuxPOSIX shell script, ASCII text executable, with very long linesdirectoryC source, ASCII textpkgconfig fileM4 macro processor script, ASCII textASCII texttroff or preprocessor input, ASCII text (gzip compressed data, max compression, from Unix)C source, ASCII text (gzip compressed data, max compression, from Unix)RPRuHJ } ~Putf-8c0d8f21307fb1109e1b14c81043fcb474a436bbf63f53800730fb662ba8c956c?7zXZ !t/ ]"k%۫., /r? /+Rz&"$YcKq-sY~Q7&Y\%;+Gn RX,cw i-ۚyR[wdELJٿ#YqKj  RM)ߥ ̏I9U)YfM[Nd4,&*ʆgV'k 2qd-o_᫳Mh$ OIx8 arŰDZ Ny+/{(rvįsp:O͡yRiU@c-2˽̌jx_ :ON$3^fB im"ۨO NQfK[ a'bp\D1Pg@T+"?7a ܤѭ9Tqq Hltv}It aS Ǚ3Shnrqoo\~}^6HOxH("s]QNה_ bZ%$Wr\6}*X$w}2V>c q"'/^w8Pa%9dMX;DQKo j`k.UdEBxBwN q3`g!V̩՜h Z.Tmpxu>0,Oz[$%IJf8Vt;Ȼ|:p=; OՏйv"w&) =O#e9r45Y~B}^ShcD3΋iG.ɅIS 3J}$9= C) H,tZuw-d(w ``p5EDf>hˌ~.Z՝ 1 JjDkqfRM]xp+ IWN k #i@ڤrAfʝs7HHTL|ZECѻEx -r(};2F cW&K!HUӹ85'$T0ܑwUa|JhSq_9Y9DQ|N*^kX8 WD —`_TVw&?* [| #! G3G{cW m byrZ6pbϳDZ»Pe5 wF=I>_/CQ;ak-¶_57J} :T#u[6N@rB^ n|kml30dt0z~95C1Ӕ,w՗Z&5$a@+haSH l&!̻r5tpmyp<98|=ӟrR6@iG[u Qz)K*}cYm>p,dKWf5lUr7nJDdثy 3Q!~{;~BsA;mm8^j2,ZT4y'%P.˟L6Њ]=a~&=FA)ӟSɂDRՠ,tZ-bhY #I$TGn92i/1|Mwߡ"[ecX$Tx_AhJ]EVvjLi6WI-_w=Ie38Est P.mhpihK9H{֭<$Ż09\}b>yĿ HSE :pK`#<"K>SPǷxv]%¾~ј (E#YKz;!xX;]"k/5BA>E_RyO