kubernetes1.20-kubelet-common-1.20.13-lp154.1.7 >  A bi)`/=„9bgN0`bpӰX0QdQtMjٻZHmQX9rRY"=]uE|؄ h\j[pCZJuk;A1v/j*?^ .&K"0cBJtwf@Nˏ-&.| e5{ AT D1<-/B+?v qzc(ὒ 3 uVR҄Ȇoq/nHmy3c0abfd17f21e19dd8992c1ad0412c0d7ac70629a55ed725a018cc9b68757eaa64edf16ea3c337ece70d0da48510069bdb4c8a9eHbi)`/=„qhodyaʷ@z!9$tEb@i6{~oݽĢy(b6 dǨb 21.,s>'JhCGD(I,k>h>nݺwvIXivWLsZe(ʧF?;v9`u=%}CyUeԓEG<3B0",:(XZ w0 l) t ~Z+=aŨvtH(Ӷ]_>pI0? d ( 2 L  6<De  4 X |   0x,X ,  (8( 9\ :i =>"?*@2F:GPHIXY\,]t^bcdefluvPw,xtyzCkubernetes1.20-kubelet-common1.20.13lp154.1.7Kubernetes kubelet daemonManage a cluster of Linux containers as a single system to accelerate Dev and simplify Ops. kubelet daemonbi"obs-arm-7TopenSUSE Leap 15.4openSUSEApache-2.0https://bugs.opensuse.orgSystem/Managementhttps://kubernetes.io/linuxaarch64 if [ -x /usr/bin/systemctl ]; then test -n "$FIRST_ARG" || FIRST_ARG="$1" [ -d /var/lib/systemd/migrated ] || mkdir -p /var/lib/systemd/migrated || : for service in kubelet.service ; do sysv_service=${service%.*} if [ ! -e /usr/lib/systemd/system/$service ] && [ ! -e /etc/init.d/$sysv_service ]; then mkdir -p /run/systemd/rpm/needs-preset touch /run/systemd/rpm/needs-preset/$service elif [ -e /etc/init.d/$sysv_service ] && [ ! -e /var/lib/systemd/migrated/$sysv_service ]; then /usr/sbin/systemd-sysv-convert --save $sysv_service || : mkdir -p /run/systemd/rpm/needs-sysv-convert touch /run/systemd/rpm/needs-sysv-convert/$service fi done fi PNAME=kubelet SUBPNAME=-kubernetes1.20 SYSC_TEMPLATE=/usr/share/fillup-templates/sysconfig.$PNAME$SUBPNAME # If template not in new /usr/share/fillup-templates, fallback to old TEMPLATE_DIR if [ ! -f $SYSC_TEMPLATE ] ; then TEMPLATE_DIR=/var/adm/fillup-templates SYSC_TEMPLATE=$TEMPLATE_DIR/sysconfig.$PNAME$SUBPNAME fi SD_NAME="" if [ -x /bin/fillup ] ; then if [ -f $SYSC_TEMPLATE ] ; then echo "Updating /etc/sysconfig/$SD_NAME$PNAME ..." mkdir -p /etc/sysconfig/$SD_NAME touch /etc/sysconfig/$SD_NAME$PNAME /bin/fillup -q /etc/sysconfig/$SD_NAME$PNAME $SYSC_TEMPLATE fi else echo "ERROR: fillup not found. This should not happen. Please compare" echo "/etc/sysconfig/$PNAME and $TEMPLATE_DIR/sysconfig.$PNAME and" echo "update by hand." fi if [ -x /usr/bin/systemctl ]; then test -n "$FIRST_ARG" || FIRST_ARG="$1" [ -d /var/lib/systemd/migrated ] || mkdir -p /var/lib/systemd/migrated || : if [ "$YAST_IS_RUNNING" != "instsys" ]; then /usr/bin/systemctl daemon-reload || : fi for service in kubelet.service ; do sysv_service=${service%.*} if [ -e /run/systemd/rpm/needs-preset/$service ]; then /usr/bin/systemctl preset $service || : rm "/run/systemd/rpm/needs-preset/$service" || : elif [ -e /run/systemd/rpm/needs-sysv-convert/$service ]; then /usr/sbin/systemd-sysv-convert --apply $sysv_service || : rm "/run/systemd/rpm/needs-sysv-convert/$service" || : touch /var/lib/systemd/migrated/$sysv_service || : fi done fi [ -z "${TRANSACTIONAL_UPDATE}" -a -x /usr/bin/systemd-tmpfiles ] && /usr/bin/systemd-tmpfiles --create /usr/lib/tmpfiles.d/kubelet.conf || : test -n "$FIRST_ARG" || FIRST_ARG="$1" if [ "$FIRST_ARG" -eq 0 -a -x /usr/bin/systemctl ]; then # Package removal, not upgrade /usr/bin/systemctl --no-reload disable kubelet.service || : ( test "$YAST_IS_RUNNING" = instsys && exit 0 test -f /etc/sysconfig/services -a \ -z "$DISABLE_STOP_ON_REMOVAL" && . /etc/sysconfig/services test "$DISABLE_STOP_ON_REMOVAL" = yes -o \ "$DISABLE_STOP_ON_REMOVAL" = 1 && exit 0 /usr/bin/systemctl stop kubelet.service ) || : fi test -n "$FIRST_ARG" || FIRST_ARG="$1" if [ $1 -eq 0 ]; then # Package removal for service in kubelet.service ; do sysv_service="${service%.*}" rm "/var/lib/systemd/migrated/$sysv_service" || : done fi if [ -x /usr/bin/systemctl ]; then /usr/bin/systemctl daemon-reload || : fi if [ "$FIRST_ARG" -ge 1 ]; then # Package upgrade, not uninstall if [ -x /usr/bin/systemctl ]; then ( test "$YAST_IS_RUNNING" = instsys && exit 0 test -f /etc/sysconfig/services -a \ -z "$DISABLE_RESTART_ON_UPDATE" && . /etc/sysconfig/services test "$DISABLE_RESTART_ON_UPDATE" = yes -o \ "$DISABLE_RESTART_ON_UPDATE" = 1 && exit 0 /usr/bin/systemctl try-restart kubelet.service ) || : fi fi$Dfp :,^AAA큤A큤A큤A큤AAbi"bi"bi"_кbi"bi"bi"bi"bi"aaabi"bi"abi"bi"bi"99d46822bfd663c2fce039b3520e3498cbd5b984d507be6ff98dc258fed2eb5844478b1888bd17c731d97eec3365b26ad48109c9ccee8d7945c263fa2f2f7c45e9767f9b208f06da2b25422284782b5f26aeac4a37354d59a43890e559d2fc47273c3bbc7fa2878ec5e9fabc04c2683cea5e39bf876488855923b1141f62027cb65ae13792e1364a958ff4da3ee80038968ae98b12f855dfcfa22ed12d7e2c680179b1d7fb6d6d8c9149504fc04d8d423e04b5dab7216a7172429d55e4f56bea464f92d1801d481ed47074b91cd7221f8b7e11747ac554f697cce6b3af4729e9cfc7749b96f63bd31c3c42b5c471bf756814053e847c10f3eb003417bc523d306b40137adb17dcf085006345a754500f95140f10f59155a5c647cadb806ef975service@rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootkubernetes1.20-1.20.13-lp154.1.7.src.rpmkubernetes-kubelet-commonkubernetes1.20-kubelet-commonkubernetes1.20-kubelet-common(aarch-64) @    /bin/sh/bin/sh/bin/sh/bin/sh/bin/shcri-runtimekubernetes-kubelet1.20rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-1kubernetes-kubelet-common4.14.3a@aC1a&0`t`@`x*`v@`u`@_T__м@_м@rbrown@suse.comrbrown@suse.comrbrown@suse.comrbrown@suse.comalexandre.vicenzi@suse.comrbrown@suse.comRichard Brown rbrown@suse.comdmueller@suse.comrbrown@suse.comRichard Brown rbrown@suse.comRichard Brown - Update to version 1.20.13: * defer close the rotated log open * Add tests for checking bind mounts * Check subpath file * Add check for subpaths * Manual cherry pick of kube-openapi changes for release-1.20 Bump kube-openapi against kube-openapi/release-1.20 branch * Update bazel * Fixed unit test SELinux support * Add shortcut for SELinux detection * Don't guess SELinux support on error * Use separate pathSpec for local and remote to properly handle cleaning paths * support more than 100 disk mounts on Windows * Support cgroupv2 in node problem detector test * Update debian, debian-iptables images to pick up CVEs fixes * Fixing how EndpointSlice Mirroring handles Service selector transitions * Fix race condition in logging when request times out * Update CHANGELOG/CHANGELOG-1.20.md for v1.20.12 * Run storage hostpath e2e test client pod as privileged * Ignore VMs in vmss delete backend pools * fix: skip not found nodes when reconciling LB backend address pools * fix: consolidate logs for instance not found error * Revert 102925: Fix Node Resources plugins score when there are pods with no requests * e2e scheduling priorities: do not reference control loop variable * tests: Wait for the network connectivity first * 'New' Event namespace validate failed * Update CHANGELOG/CHANGELOG-1.20.md for v1.20.11 * Refine locking in API Priority and Fairness config controller * kube-controller-manager: properly check generic ephemeral volume feature * Fix null JSON round tripping * Propagate conversion errors * integration test * fix 104329: check for headless before trying to release the ClusterIPs * Fix use variables in the loop in vsphere_util * Address review comments * Add docs about process of discovering disks from new nodes * Fix unknown dangling volumes * fix detach disk issue on deleting node * fix: ignore the case when comparing azure tags in service annotation * fix: ignore the case when updating tags * backported PR#97721 from v1.21 ("fix slice controller logging for services ipfamily") * remove listx from OWNERS, OWNERS_ALIASES * Add explicit capability for online volume expansion * Bump golang.org/x/text to v0.3.6- Update to version 1.20.11: * Fix a small regression in Service updates * Service: Fix semantics for Update wrt allocations * Fix buckets initialization * fix: ensure InstanceShutdownByProviderID return false for creating Azure VMs * fix: skip case sensitivity when checking Azure NSG rules * Keep MakeMountArgSensitive and add a new signature that receives flags * Update the unit tests to handle mountFlags * Add missing interface method in mount_unsupported.go * Pass additional flags to subpath mount to avoid flakes in certain conditions * Update CHANGELOG/CHANGELOG-1.20.md for v1.20.10 * Copy golang license to staging copies * delete stale UDP conntrack entries for loadbalancer IPs * job controller: don't mutate shared cache object * Set idle and readheader timeouts- Update to version 1.20.10: * Bump to golang 1.15.15 in build/** * Bump to golang 1.15.15 in cluster/** and staging/** * Bump to golang 1.15.15 in test/** * Avoid spurious calls to update/delete validation * Fix metrics reporting for the deprecated watch path * Update configure-helper.sh * Update configure-helper.sh * Update configure-helper.sh * Fix: ignore not a VMSS error for VMAS nodes in reconcileBackendPools * feat: Provide IPv6 support for internal load balancer * Update to using apiserver-network-proxy v1.22 * Make CSR cleaner tolerate objects with invalid status.certificate * disable aufs module * update comments and owners file for pkg/util/removeall * kubelet: do not call RemoveAll on volumes directory for orphaned pods * APF e2e: wait for steady state before proceeding * Update CHANGELOG/CHANGELOG-1.20.md for v1.20.9 * Updated to use konnectivity client v0.0.21, and implemented placeholder context * include google/go-cmp in client-go/dynamic/fake/BUILD * Simplify use of the fake dynamic client * fix: return empty VMAS name if using standalone VM * Fix race in attachdetach tests * Fix frameworkImpl.extenders being not set * Fix closing of decorated watcher channel on timeout * update bazel * (scheduler e2e) Create balanced pods in parallel- Update to version 1.20.9: * Bump to golang 1.15.14 in build/** * Bump to golang 1.15.14 in cluster/** and staging/** * Bump to golang 1.15.14 in test/** * Update debian-iptables image to buster-v1.6.5 * Update debian-base image to buster-v1.8.0 * Bump SMD to v4.1.2 to pick up #102749 fix * generate scheduler merge patches on the pod status instead of the full pod * p&f e2e test: log response header for better troubleshooting * Loadbalancer IngressIP policy should be configured as non-DSR to enable routing mesh by default * Do not throw error when we can't get canonical path * Fix Node Resources plugins score when there are pods with no requests * Update CHANGELOG/CHANGELOG-1.20.md for v1.20.8 * Remove error wrap from logs * staging/publishing: Set default go version to go1.15.13 * build: Update to k/repo-infra@v0.1.8 (supports go1.15.13) * Use go-runner:v2.3.1-go1.15.13-buster.0 image (built on go1.15.13) * Update to go1.15.13 * feat: remove ephemeral-storage etcd requirement * endpointslicemirroring controller mirror address status * sched: fix a bug that a preemptor pod exists as a phantom * Revert "Cleanup portforward streams after their usage" * Remove unnecessary snapshot ability check * serviceOwnsFrontendIP shouldn't report error when the public IP doesn't match * Fix VolumeAttachment garbage collection for migrated PVs * Return UnschedulableAndUnresolvable when looking up volume-related resources returns NotFound error * Return UnschedulableAndUnresolvable instead of Error when failing to lookup pvc or storageclass in VolumeZone plugin * Ignore transient errors when gather stats * Speed up PV provisioning for vsphere driver * fix error of setting negative value for containerLogMaxSize * Upgrade konnectivity-client for GRPC connection fixes * Update etcd image revision * Update debian-base to buster-v1.7.0 * Update debian-iptables to buster-v1.6.1 * Respect annotation size limit for SSA last-applied. * Remove unnecessary quotes from get-kube scripts * Fix expired unit test certs * fix: delete non existing disk issue * Azure: avoid setting cached Sku when updating VMSS and VMSS instances * Update cos-gpu-installer image * Ref counting is only applicable to Remote endpoints * Make watch order conformance test reliable * Update CHANGELOG/CHANGELOG-1.20.md for v1.20.7 * fix removing pods from podTopologyHints mapping * fix: avoid nil-pointer panic when checking the frontend IP configuration * Use CSI driver to determine unique name for migrated in-tree plugins * Add jitter to lease controller * Avoid caching the VMSS instances whose network profile is nil * chunk target operatation for aws targetGroup * Fix watchForLockfileContention memory leak * Fix cleanupMountpoint issue for Windows * Fixed the Dockerfile for the build-image to build from KUBE_BASE_IMAGE_REGISTRY- Update to version 1.20.7: * staging/publishing: Set default go version to go1.15.12 * build: Update to k/repo-infra@v0.1.7 (supports go1.15.12) * Use go-runner:v2.3.1-go1.15.12-buster.0 image (built on go1.15.12) * Update to go1.15.12 * fix: not tagging static public IP * Add test create service with ns * Set namespace when using kubectl create service * Automated cherry pick of #101377: Fix validation in kubectl create ingress (#101428) * Updating EndpointSlice controllers to avoid duplicate creations * Update pkg/volume/azure_file/azure_provision.go * Normalize share name to not include capital letters * Extend pod start timeout to 5min for storage subpath configmap test * fix: set "host is down" as corrupted mount * no watch endpointslice in userpace mode * Ensure service deleted when the Azure resource group has been deleted * Updating EndpointSlice validation to match Endpoints validation * Make parallel build memory threshold configurable * fix: azure file namespace issue in csi translation * pkg/kubelet: improve the node informer sync check * Additional CVE-2021-3121 fix * Fix startupProbe behaviour changed * Fix test * staging/publishing: Set default go version to go1.15.10 * build: Update to k/repo-infra@v0.1.6 (supports go1.15.11) * Use go-runner:v2.3.1-go1.15.11-buster.0 image (built on go1.15.11) * Update to go1.15.11 * add duration encoder to structured logger * Update CHANGELOG/CHANGELOG-1.20.md for v1.20.6 * exec test should not run in Parallel as feature gate is not locked * hack/update-bazel.sh * respect ExecProbeTimeout * apf: exempt probes /healthz /livez /readyz * DelegatingAuthenticationOptions TokenReview request timeout * list pod list once to avoid timeout * Cleanup portforward streams after their usage * fix smb mount issue on Windows- Update to version 1.20.6: * azure: fix node public IP not able to fetch issues from IMDS * Fix test now that empty struct are tracked in mangaed fields * make generated_files * Update bazel and dependencies. * Update to use cliflag.NamedFlagSets * Address comments. * Update NodeIPAM wrapper * Delete build file based on latest changes. * Update extension mechanism and related sample. * Address review comments * Address review comments * Modify integration test to fill CCM test gap * Update test * Move initialize cloud provider with client builder reference inside controller start func * Separate example func and add README.md * Separate func * Add demonstration of wiring nodeIPAMController config object * Remove cloud provider name as input parameter. * Fix flag passing in CCM. * Use apply to create objects in TestApplyStatus * Stop skipping APIService in apply test * Stop clearing OpenAPIConfig for kube-aggregator * Declare TCP default for service port protocol * Add ability to skip OpenAPI handler installation * do not tag user created public IPs * apf: fix test flake * update gogo/protobuf to v1.3.2 * Fixed describe ingress causing SEGFAULT * Update sigs.k8s.io/structured-merge-diff to v4.0.3 * Stop probing a pod during graceful shutdown * apf: handle error from PollImmediateUntil * staging/publishing: Set default go version to go1.15.10 * webhook config manager: HasSynced returns true when the manager is synced with existing webhookconfig objects at startup * update metadata-concealment to 1.6 for removing legacy checking * slice mirroring controller mirror annotations * additional subnet configuration for AWS ELB * Revert "Automated cherry pick of #97417: fix azure file secret not found issue" * Use the correct volum handle format for GCE regional PD. * Increasing maximum number of ports allowed in EndpointSlice * Support > 5 ports in L4 ILB. * build: Update to k/repo-infra@v0.1.5 (supports go1.15.10) * Use go-runner:v2.3.1-go1.15.10-buster.0 image (built on go1.15.10) * Update to go1.15.10 * Update CHANGELOG/CHANGELOG-1.20.md for v1.20.5 * fix a bug where only service with less than 100 ports can have GCE load balancer * bazel * deepcopy statefulsets * full deepcopy on munged pod spec * remove pod toleration toleration seconds mutation * add markers for inspected validation mutation hits * move secret mutation from validation to prepareforupdate * remove unnecessary mutations in validation * tweak validation to avoid mutation * For LoadBalancer Service type don't create a HNS policy for empty or invalid external loadbalancer IP * Moving docker options to daemon.json * e2e fix: loosen configmap to 10 in resource quota * api-server add --lease-max-object-count * apiserver add metric etcd_lease_object_counts * apiserver add --lease-reuse-duration-seconds to config lease reuse duration * Bump Cluster Autoscaler to v1.20.0- Rebase opensuse-version-checks.patch- Update to version 1.20.5: * Updating EndpointSliceMirroring controller to wait for cache to be updated * Updating EndpointSlice controller to wait for cache to be updated * Add tests for populated volumes * Fix comment on getPodVolumeSubpathListFromDisk * Fix tests to test for new behavior * Add warnings after cleanup back * Automatically remove orphaned pod's dangling volumes * Count pod overhead as an entity's resource usage * Ensure only one LoadBalancer rule is created when HA mode is enabled * Fix issue in checking domain socket for plugin watcher * Use Lstat in plugin watcher to avoid Windows problem * Skip visiting empty secret and configmap names * Number of sockets is assumed to be same as NUMA nodes * disables APF if the aggregated apiserver cannot locate the core kube-apiserver * Fix repeatedly aquire the inhibit lock * Sync node status during kubelet node shutdown * remove executable permission bits * Upgrading vendored dependencies * Upgrading cAdvisor to 0.38.8 * Update CHANGELOG/CHANGELOG-1.20.md for v1.20.4 * build/OWNERS: Add Dan and Sascha as reviewers * OWNERS(CHANGELOG): Move reviewers/approvers to CHANGELOG/ dir * Bump konnectivity-client to v0.0.15 in release-1.20 * Storage e2e: Remove pd csi driver installation in GKE * Update CHANGELOG/CHANGELOG-1.20.md for v1.20.3 * kube-cross: update image to use v1.15.8-legacy-1 * [go1.15] build: Update to k/repo-infra@v0.1.4 (supports go1.15.8) * Use go-runner:buster-v2.3.1 image (built on go1.15.8) * staging/publishing: Set default go version to go1.15.8 * Update to go1.15.8 * Fix dbus shutdown events not continuing if they are not valid * Revert "make hostPort match test linuxonly" * Revert "conformance changes" * kube-proxy: clear conntrack entries after rules are in place * Use -LiteralPath instead of -Path * Escape the special character in vsphere windows path * Include unit test * Adjust defer to correctly call * do not remove volume dir when saveVolumeData fails * kubeadm: drop explicit constant override in version test * kubeadm: get k8s CI version markers from k8s infra bucket * dockershim hostport respect IPFamily * dockershim hostport manager use HostIP * Balance nodes in scheduling e2e * e2e: Pod should avoid nodes that have avoidPod annotation: clean remaining pods * Cherry pick of #98254:Fix the kube-scheduler binary's description of the --config parameter is inaccurate * fix kube-scheduler cannot send event because the Note field is too large * Fix nil pointer dereference in disruption controller * Update region_pd e2e test to support PV have GA topology * Recover CSI volumes from dangling attachments * IsVolumeAttachedToNode() renamed to GetAttachState(), and returns 3 states instead of combining "uncertain" and "detached" into "false" * Fixes Attach Detach Controller reconciler race reading ActualStateOfWorld and operation pending states; fixes reconciler_test mock detach to account for multiple attaches on a node * Fix translation of Cinder storage classess to CSI * OWNERS(CHANGELOG): Add release-engineering-reviewers as reviewers * OWNERS(CHANGELOG): Add release-engineering-reviewers as approvers * Resolve IP addresses of host-only in filtered dialer * Deflake ingress updates * make podTopologyHints protected by lock * ignore cgroup driver check in windows node upgrade * OWNERS(sig-release): Add CHANGELOG aliases * OWNERS(build-image): Add Release Managers as reviewers * OWNERS(releng): Sync Release Managers * OWNERS(sig-release): Remove SIG Release approvers alias * aggregate errors when putting vmss * fix azure file migration issue * kubelet: Fix mirrorPodTerminationMap leak * kubelet: Delete static pods gracefully * kubeadm: change the default image repository for CI images from gcr.io/kubernetes-ci-images to gcr.io/k8s-staging-ci-images * kubelet logs print 'kubelet nodes sync' frequently * reduce buckets for etcd_request_duration_seconds * Merge pull request #96876 from howieyuen/no-execute-taint-missing * cleanup subnet in frontend ip configs * conformance changes * make hostPort match test linuxonly * Clean up namespaced children of missing virtual parents with incorrectly cluster-scoped nodes * Add unit test for child scope mismatch with missing parent * vendor: update cAdvisor to v0.38.7 * Use volumeHandle as PV name when translating EBS inline volume * Update CHANGELOG/CHANGELOG-1.20.md for v1.20.2 * kubectl-convert import known versions * Revert "Merge pull request #92817 from kmala/kubelet" * WIP: node sync at least once * fixes nil panic for nil delegated auth options * Lower the frequency of volume plugin deprecation warning * handle webhook authenticator and authorizer error * fix the panic when kubelet registers if a node object already exists with no Status.Capacity or Status.Allocatable * Avoid checking the entire backend service URL for FR equality. * Use non privileged ports- Update to version 1.20.2: * move all variables in sampleAndWaterMarkHistograms::innerSet * use default unkown sock for kubeadm cmd if cri detect is not needed * cherry-pick part of #97451: fix nodeport quota check failure during creating clusterip * Release reserved GCE IP address after ensure completes. * Ensure reproducible builds when build through docker * Fix cadvisor machine metrics * Create OWNERS for most of the API Priority and Fairness impl * fix the deadlock in priority and fairness config controller * Cherry pick 443 and 448 from cloud provider azure * Fix bug in CPUManager with race on map acccess * clean up executing request on panic * fix azure file secret not found issue * fix: azure file latency issue for metadata-heavy workload * Update CHANGELOG/CHANGELOG-1.20.md for v1.20.1 * Add more logging for Mount error- Update to version 1.20.1: * Revert "Use host IP instead of localhost for control plane component kubeconfig files." * etcd version for 1.19 is 3.4.13 for cve fixes * Flush FibreChannel devices before deleting * Fix FibreChannel volume plugin corrupting filesystem on detach * vendor: update cAdvisor to v0.38.6 * Update CHANGELOG/CHANGELOG-1.20.md for v1.20.0 * Revert "iAdd host IP to etcd listen client URLs." * fix migration logic * Add AcceleratorStats to cri_stats_provider- Add obsoletes to -client-common to facilitate smooth upgrades from older versions- Rebase opensuse-version-checks.patch - Update to version 1.20.0: * APF e2e: disable drown-out tests temporarily * coredns dep.Severity is newdefault, not newDefault * addressing review comments and supports parallel run * Update ingress conformance test for finalizers * vendor: update cAdvisor to v0.38.5 * fix: change disk client API version for Azure Stack * service.spec.AllocateLoadBalancerNodePorts followup * [go1.15] Use go-runner:buster-v2.2.2 image (built on go1.15.5) * [go1.15] staging/publishing: Set default go version to go1.15.5 * [go1.15] Update to go1.15.5 * [go1.15] hack/tools: Update to k/repo-infra@v0.1.3 (supports go1.15.5) * [go1.15] build: Update to k/repo-infra@v0.1.3 (supports go1.15.5) * Restore beta os/arch labels on initial node registration * matches specific usernames instead of "*" * range_allocator: Test (lack of) double counting * cidrset: Add test for double counting * Fix double counting of IP addresses * ap&f e2e: eliminates client-side rate-limiting * fix bug: concurrent map writes error * Bump node-problem-detector to v0.8.5 * Revert "check volume directories instead of mounts for cleanupOrphanedPodDirs" * Revert "plumb context with request deadline" * Revert "use default value when the specified timeout is 0s" * Revert "add e2e tests for request timeout" * Deflake ThrottledLogger test * fix: resize Azure disk issue when it's in attached state * kube-aggregator: fix apiservice availability gauge * Fix TestStartingResourceVersion flakiness * make sure managedFields are written * generated * unit and integration tests * apiserver dedups owner references and adds warning * Add linuxonly on one multivolume test * gce: move iptables rule to mangle * APF e2e tests: add request drown-out fairness test * add e2e tests for request timeout * use default value when the specified timeout is 0s * CHANGELOG: Update error link in 1.20 * CHANGELOG: Update directory for v1.20.0-beta.2 release * APF e2e tests: rename request drown-out priority client names * Mark some storage tests as LinuxOnly * Add GC unit tests * Log cluster-scoped owners referencing namespaced owners, avoid retrying lookups forever * Queue non-matching children for deletion when a virtual node is marked as observed * Handle virtual delete events when children don't agree on owner coordinates * Make node removal conditional in processGraphChanges * Enqueue dependents for deletion when their ownerReference does not match observed parent coordinates * Short-circuit attemptToDelete loop for virtual nodes that are removed or observed * Replace virtual node with observed node if identity differs * Refactor identityFromEvent * Avoid marking virtual nodes as observed when they haven't been * Switch GC absentOwnerCache to full reference * Add GC integration race test * Plumb event recorder to garbage collector controller * e2e SCTP test not depend on kubenet * e2e/node: increase timeouts seconds to 5 for liveness probe restart test * correct e2e test predicates conflict hostport * Add a deprecation note to k/k/cluster/log-dump directory * Update topology tests for windows * kubelet: dockershim should return grpc status with DeadlineExceeded code * e2e dualstack test fixes * convert the runtimeclass API tests to conformance * APF e2e tests: use snake_case label * APF e2e tests: move common code into helper functions * Reduce volume name length for vsphere * CHANGELOG: add a hyperlink to issue 86282 * allow configuring ReadIdelTimeout and PingTimeout via env var * Add a unit test testing the HTTP/2 health check help the REST client detects broken TCP connections. * plumb context with request deadline * Fixes fake client test generation * Integrate defaults marker and remove ContainerPort defaulter * Remove StripDefaults from BuildSwagger * Add default for protocol and test that it works * Strip defaults in new places * Re-generate with defaults * Update kube-openapi * flowcontrol bootstrap: give catch-all PL more concurrency share * APF matching: fallback to catch-all if nothing matches * flowcontrol bootstrap: make exempt PL last * APF: graduate API and types to beta * Mixed protocol support for Services with type=LoadBalancer (#94028) * Fix test name in e2e resource metrics api test * Test CRUD operations on RuntimeClasses API * vendor: cadvisor v0.38.4 * Relax matching on pod_memory_working_set_bytes metrics * configure the ReadIdleTimeout and PingTimeout of the h2 transport * Match pod resource metrics to pod not container * add more e2e sctp tests * remove wrong test for SCTP connectivity * Update the route table tag in the route reconcile loop * Fixes sigfault in case of empty TopologyInfo * Update generated files * Add service.spec.AllocateLoadBalancerNodePorts * update golang.org/x/net and golang.org/x/sys * Update 1.18 changelog with changes from v1.18.11 * fixup! unblock resources that the storage version manager depends on * fixup! add storage version garbage collector * generated * GC integration test * unblock resources that the storage version manager depends on * make storage version manager wait for lease creation * add storage version garbage collector * Fix cacheWatcher leak when time jump to the future and jump back * Correct rebase issues * Implement shutdown manager in kubelet * Add systemd package to interface with dbus * Corrected CSIDriver validation rebase issues * Remove duplicate CSIDriver name validation * Adjust CSIDriver validation to check objectmeta * Enable logging and drop permissive targets for CSI mock driver * Update the mock driver to use 4.0.2 * Included e2e test for CSIDriver FSGroupPolicy * Move CSIVolumeFSGroupPolicy to beta * Relax validation for CSIVolumeFSGroupPolicy * Fixed quantization and made monotic time reversal not panic * Log defaulted kube-scheduler component config at startup * Updates related to PR feedback * core/v1: document that topologyKeys requires the ServiceTopology feature gate * Use K8s in the README * stop serving deleted APIs * Increase watch timeout when scaling Deployment Replicas * CHANGELOG: Update directory for v1.18.12 release * scheduler: Implement resource metrics at /metrics/resources * quantity: Allow quantity to be converted to float64 * plumb service account token down to csi driver * remove generator from service in kubectl * add myself to sig-network-api-reviewers * Add datapolicy tags to staging/src/k8s.io/client-go/ * cleanup: fix log capitalization in scheduler * Add --experimental-logging-sanitization flag to Kubelet * Run ./update-all.sh * Implement e2e tests for pod scope alignment * Add tests for getPodDeviceRequest() for devicemanager * Add tests for GetPodTopologyHints() for devicemanager * Update topology hints tests to use pod object for devicemanager * Add tests for GetPodTopologyHints() for cpumanager * Refactor topology hints tests for cpumanager * Move scope specific tests from topologymanager under particular scopes * Move common tests from topologymanager under scope * Update topologymanager tests after adding scopes * Implement devicemanager.GetPodLevelTopologyHints() function * Implement the cpumanager.GetPodTopologyHints() function * Update logging to use a format util * Implement topology manager scopes * Add GetPodTopologyHints() interface to Topology/CPU/Device Manager * Add flag value validation of TopologyManagerPolicy * Add flag value validation of TopologyManagerScope * Add kubelet configuration flag 'topology-manager-scope' * Support custom tags for cloud provider managed resources * use uncommon ports for e2e network test * fix pull image error from multiple ACRs using azure managed identity * add e2e test for dual-stack secondary service IPs * Verify iptable rules are applied for tcp, udp and icmp * Choosing the right source VIP for local endpoints * Configure StackdriverLogging Windows service to restart on failure. * Adding sample files to demonstrate how cloud provider leverage CCM. * Updating EndpointSlice strategy to cover alpha NodeName field * Support high availability ports * Allow debugging kubelet image pull times * Separate in-tree gcepd driver for windows * Cleaning up EndpointSlice update validation tests * Removing "IP" from supported EndpointSlice address types in kube-proxy * Updating ControlPlane to support NodeName field * Updating EndpointSlice controllers to support NodeName field * Adding EndpointSliceNodeName feature gate * Adding NodeName to EndpointSlice API, deprecation updates * update bazel * Promote Deployment lifecycle e2e test to Conformance * CHANGELOG: Update directory for v1.19.4 release * handle the case for slow cronjob lister, add unit tests * convert to stardard lister, use []*batchv1.Job instead of []batchv1.Job * actually retry if we failed to reconcile some objects * Update storage test suits for Windows * Promote Pod/PodStatus lifecycle e2e test to Conformance * Fix failures in TestBindPlugin and TestPreemptWithPermitPlugin * Set 0 sync period in scheduler integration test * CHANGELOG: Update directory for v1.17.14 release * GA of RuntimeClass feature gate and API * put a message, not a stack, in the log on a timeout * Update snapshot CRDs * Set priority of Event v1 higher than v1beta1 * Implement TopologyInfo and cpu_ids in podresources * Convert podDevices to struct * Generate podresources API for TopologyInfo and cpu_ids * Add TopologyInfo and cpu_ids into podresources * Change GetDevices interface * Revert "Merge pull request #92312 from Sh4d1/kep_1860" * fix all Sting method not check nil in "k8s.io/apimachinery" * fix the validation logic for Job/CronJob RestartPolicy field * fix note delete to update according to code * Fix a bug that DefaultPreemption plugin is disabled when using scheduler policy * fix(test::npd): provide NPD with proper kubeconfig * Bump kas to v0.0.14 * Capture defaulted plugin configs from framework * move lease controller to k8s.io/component-helpers/apimachinery * Bug Fix for process_start_time_metric initialization * add V(4) log when apiserver lease was deleted before this controller reacts * generated * integration test * add apiserver lease garbage collector * update violation_exceptions.list and make generated * add cronjob_controllerv2.go * Add CRI v1 proto * dualstack: Use Agnhost in place of BusyBox * Downward API hugepages * added new runtimeclass test and changed Disruptive to Serial * kubeadm: mark the "master" label/taint as deprecated * dualstack: use correct IPFamily list for conntrack checks in e2e * move service controller config to k8s.io/cloud-provider/controllers/service/config * Use FilteredDialContext with quobyte API * Update quobyte client API to v0.1.8 * import restrictions: allow k8s.io/kubelet to import credentialprovider apis * hack/.golint: ignore golint for new kubelet and credentialprovider APIs package * pkg/credentialprovider: export URL parsing and matching helper functions * pkg/credentialprovider: add initial exec-based credential provider plugin * kubelet: add initial credentialprovider v1alpha1 APIs * feature gates: add KubeletCredentialProviders feature gate * kubelet: support alpha credential provider exec plugins * kubelet: update pkg/kubelet/apis/config/OWNERS to include api approvers and reviewers * kubelet: add CredentialProviderConfig API * Change at which level klog.Fatal is invoked * Forbid creating clusters with more than 100 nodes without vpc-native * Change the logic of pod volumes existence check during kubelet cleanupOrphanedPodDirs, cleanupOrphanedPodCgroups and PodResourcesAreReclaimed * remove label dependency on k8s api in Azure * Remove duplicate import * Add --experimental-logging-sanitization flag to control plane components * FsgroupChange policy test suite * Improve observability of node authorizer: * Adding some metrics to the graph * Adding log message when node authorizer has synced * Remove ready directory which created in empty volumeMounter setUp func * cloud-provider: update docs and guidance for InstanceV2 and Zones * fixing issue where SMB share paths cannot resolve with CRI-containerD on Windows * Ignore specific Pod update events in scheduler * Support customize load balancer health probe protocol * Move fsGroupChangePolicy feature to beta * Add WindowsContainerResources to UpdateContainerResourcesRequest * Change snapshot test to use v1 apis * Modify storage snapshottable and disruptive test for Windows * fix: change storage account client API version for Azure Stack * Fixed failure: ProvisioningFailed: Failed to provision volume with StorageClass "standard": invalid AccessModes [ReadWriteOnce ReadOnlyMany ReadWriteMany]: only AccessModes [ReadWriteOnce ReadOnlyMany] are supported * Set enable konnectivity service to true by default * fixup! apiserver correctly validates encoding/decodable versions * HTTP Prove: Removes Accept-Encoding header from http probe * Update snapshot CRDs to v1 * Enable ConfigurableFSGroupPolicy feature gate * Add dangling volume check for vsphere * update e2e kubectl test * prune type in preserve-unknown-fields objects * Add AddedAffinity to the NodeAffinityArgs * Remove --redirect-container-streaming functionality (#95935) * Fix go lint on folder apimachinery/pkg/runtime/serializer/protobuf * Graduating AppProtocol to GA * Fix command and arg in NPD e2e * Call MountDevice only once * Mark MountDevice as uncertain after failed resize * Restore staging path creation * Add unit test for staging path creation * kubelet: move pkg/kubelet/cri/.import-restrictions to pkg/kubelet/cri/streaming * kubelet: add feature gate check for exec probe timeouts * features: add ExecProbeTimeout feature gate * kubelet: allow dockershim exec timeouts to be longer than 10s * kubelet: add e2e test for exec readiness probe timeout * kubelet: stop skipping docker exec livenessprobe timeout test * kubelet: respect probe exec timeout from CRI by returning utilexec.CodeExitError * kubelet: respect dockershim exec timeout * Implement log sanitization * Update bazel * apiextensions: adapt error tests to fixed validation messages * apiextensions: switch validation to kube-openapi * bump(k8s.io/kube-openapi) * stops puting a stacktrace of aborted requests in the logs * require APIServerIdentity to be enabled to run StorageVersionAPI * apiserver correctly validates encoding/decodable versions * updater correctly updates storageversion status * return a Status formatted JSON response * generated * Add an integration test. * make some rbac and scheduling post start hooks tolerate the apiserver bootstrap delay caused by installing storage versions. * Add a generic filter that blocks certain write requests before StorageVersions are updated during apiserver bootstrap. * Collect storage versions as ResourceInfo when installing API endpoints. * Add a feature gate * add andyzhangx as reviewer * Add nodeSelector for konnectivity daemonSet * fix ingress comparaison * fix defaulting * add nil case in proxy * fix build * fix nit in validation * fix tests * Update generated * fix reviews * Update generated * fix review * fix typo * add owner for feature gate * fix rebase * fix review * Add tests * Add route type field to loadbalancer status ingress * Update docs and fix redundant logic of scheduler perf * remove kube-proxy/config/v1alpha1 from .golint_failures * Fix go lint on folder apimachinery/pkg/runtime/serializer/json * Change the features removal note * Promote TokenRequest e2e test to Conformance * cleanup dated wording "NominatedNodeName annotation" * fix formatting * generated * add kube-apiserver-lease-controller poststart hook * Add constant PodReadyTimeout to e2e test * Adjusted timings and management of pods in e2e test * Create Pod+PodStatus resource lifecycle test * Update UTs * Fixing expected pod subdomain to match framework.TestContext.ClusterDNSDomain * e2e: add APF flowcontrol request drown-out test * Less restrictions for AWS NLB health check config * scheduler: remove FrameworkFactory. * PV e2e: fix race in NFS recycling test * Add support to size memory backed volumes * update max azure data disk count map * kubeadm: fix the lint failure where return value is not checked * Generated changes * Move the remaining kubectl bits to k8s.io/kubectl * Introduce kubectl-convert plugin * Adding config extension to CCM. * remove annotation cache sync because of code removed * Increase the timeout to allow summary test pod to start * removes filter metrics test retries * Use topology labels instead of old beta names (#96033) * CRs: Default non-nullable nulls * Move kubectl get-context validate logic to Validate function * endpointslice API: rename 'accepting' condition to 'serving' condition * endpointslice controller: add test cases to TestSyncServiceFull for terminating endpoints * endpointslice controller: refactor TestSyncServiceFull to use test tables * endpointslice API strategy: drop disabled fields 'accepting' and 'terminating' * endpointslice controller: set new conditions 'accepting' and 'terminating' * feature gate: add gate EndpointSliceTerminatingCondition * endpointslice API: add accepting and terminating conditions * kubelet: Use CRI SecurityProfile for Seccomp * Switch GCP list calls to paginated calls. * dualstack: cleanup IsIPv4 duplicates in favor of utils * dualstack: incorporate IsIPv4 updates from utils repo * abort if namespace doesn't exist or terminating * proxy: validate each CIDR config seperately and check for errors * minor changes in adding tests for checking metrics labels * make flags of TokenRequest required * default `service-account-extend-token-expiration` to true * E2E stress test suite for VolumeSnapshots * Update Microsoft/go-winio to released version * APF metrics: set StabilityLevel to ALPHA * kubectl debug: allow set-image-only invocation * Introduce a simple datapolicy library * Remove the dependency between create priorityclass command and generators * Deflake existing configmap count * update features to indicate beta in comment * cleanup: use i18n.T on all command descriptions * Revert "add e2e test for Service ExternalIPs" * CHANGELOG:Fix kubelet flag enable-cadvisor-json-endpoints * client-go/rest: fix finalURLTemplate for url base == "/" * Correctly fix clearing conntrack entry on endpoint changes (nodeport) * Remove Const IPVSProxyMode * update changelog-1.20 * test images: Authenticate in order to push images * Support multiple standard load balancers in one cluster * Use user facing field names in validation message * report UnschedulableAndUnresolvable status instead of an error when PVCs can't find bound persistent volumes * separate RootCAConfigMap from BoundServiceAccountTokenVolume * Add mrunalp as node approver * test images: Removes -p yes flag from qemu-user-static script call * optimise defaultpreemption: enumerate fewer candidates * apiserver/filters test: fix data race and do not leak goroutines * APF: use snake_case in metric labels * Volume snapshot e2e test to validate VolumeSnapshotContent and PVC finalizer * minor changes to tests for checking metrics labels based on review comments * check if kubectl version required values are empty * Exclude KEP-1933 from verify-all.sh until after alpha status. * add GVK to fake dynamic client to match actual behavior * demonstrate existing generated client and fake client behavior is consistent * remove dead apiserver field * Adding an owner for addon/dns folder * fix: pass bearer token to curl using -H instead of --oauth2-bearer * Remove alpha from kubectl debug * do not allow inflight watermark histograms to fall too far behind * test images: set DOCKER_CLI_EXPERIMENTAL=enabled * Remove maximum volume limit comment which is easily outdated. * DelegatingAuthenticationOptions: allows for setting a timeout for the TokenReview client that is used by for the webhook authenticator * Update staging/src/k8s.io/kubectl/pkg/cmd/create/create_rolebinding_test.go * pause image: Disable DiagTrack service on Windows image * replace string casting with fmt.sprintf in test * Fix paging issues when Azure API returns empty values with non-empty nextLink * change plugin name in fsgroupapplymetrics of csi and flexvolume to distinguish different driver * test images: sets HOME=/root in cloudbuild.yaml * Update CHANGELOG link of older releases * Remove TaintBasedEvictions Feature Gate * Replace calls to cs.CoreV1().Nodes().Create() with createNode() * Add a function to ensure created nodes are present in scheduler cache * local-up-cluster.sh: Use config file instead of flags for kubelet * Add a verbosity option to exec * KEP-1933: add static analysis target to hack/ * kubectl debug: Allow mutating image names * Increasing withTimeout for ReplicationController Lifecycle test steps * Propose seccomp/apparmor protobuf type definitions for CRI graduation * Update Klog dependency * Remove service load balancer feature gate * resource-metrics: add pod metrics e2e test * reenable e2e_node services & debugging improvements * resource-metrics: add pod/sandbox metrics to endpoint * Removing Alpha annotation as the feature is graduating to Beta in v1.20 * Add runtime representation of []v1.PreferredSchedulingTerm * Move pkg/kubectl/cmd/auth under staging/src/k8s.io/kubectl/pkg/cmd/auth * use patch instead of replace to test the dry-run option * CHANGELOG: Update directory for v1.20.0-beta.1 release * fix CPU time of pod stats with cs.CPU.Time * Skip the sig-storage e2e test as early as possible * Remove useless variable and if * kubectl debug: add tests for Complete,Validate * Move Snapshot to GA * register controllermanager.config.k8s.io group. * fix(test::npd): fix node problem detector test * fix n to nodeInfo easy to understand * Update cobra dependency to v1.1.1 * Adjusted e2e test watch timeouts, logging and pod management * Update usage information for --http-override * Bump agnhost version * Add override option to netexec * Add a redirect handler to netexec * Add optional code to netexec echo endpoint * Honor disabled LocalStorageCapacityIsolation in scheduling * Build files * [kubelet] Allow priority to be set for kubelet process on Windows * add e2e test for Service ExternalIPs * e2e cases for apf * Move helpers from pkg/registry/rbac/reconciliation and pkg/registry/rbac/validation under k8s.io/component-helpers * Add runtime representation of v1.NodeSelector * Remove variadic argument from storage interface * Revert "Updated golang/x/net. Also updated golang.org/x/sys" * Add multi request test * Fix issue in missing metrics of terminated requests * Fix bug in JSON path parser where an error occurs when a range is empty * set webhook retry backoff parameters for kubelet * thorw error if webhook retry backoof is not specified * make backoff parameters configurable for webhook * fix vendor/k8s.io/apimachinery/pkg/api/meta staticcheck * Updated golang/x/net. Also updated golang.org/x/sys, as required by hack/lint-dependencies.sh. * Disable watchcache for events * local-up-cluster.sh: Remove ineffective parameters * Pass all packages to conversion-gen * refactor: migrate health checks of control-plane off insecure port in tests * Implementing ExternalTrafficPolicy: local in winkernel kube-proxy via DSR * add a jitter to bound token renewal * Add datapolicy tags to cmd/kubeadm directory * devicemanager: fix race in stub * Add datapolicy tags to pkg/volume/ * change bucket from 0.0s to 0.0001s * refector service some e2e cases to make it runing in multi providers * Added tests to check metrics labels * Move CCM to staging k8s.io/cloud-provider * mv TokenRequest and TokenRequestProjection to GA * Populate ClusterIPs on read * test: remove flacky ut * Add json-response flag to porter * local-up-cluster.sh: Pass CLUSTER_CIDR to kube-proxy * HTTP Probe: Add 'Accept' header by default * Add keep_time_key setting to fluentd configuration * Enable filter latency tracking for request filters * Measure how much time a request spends in server filter(s): * hack/local-up-cluster.sh: fix API_PORT * exec credential provider: exec -> client.authentication.k8s.io/exec * kubectl flush profiling when get a sigterm * Cleanup non-namespaced objects in e2e test during interrupts * remove dead negotiation methods * fake dynamic client: support *List kinds * Move informer_factory to staging * Remove behaviors * add tests that update services while gate is off * Add datapolicy tags to staging/src/k8s.io/kubectl * Add datapolicy tags to staging/src/k8s.io/legacy-cloud-providers * Mark SecondaryRangeName as deprecated. * Move MatchNodeSelectorTerms to k8s.io/component-helpers * exec credential provider: k8s.io/client-go/tools/auth/exec helper * exec credential provider: ProvideClusterInfo and kubeconfig shadow * Remove FieldMatchingFlags * Adjust conversion generator to new converter changes * Add datapolicy tags to pkg/scheduler/ * Add datapolicy tags to staging/src/k8s.io/kube-aggregator/ * Add datapolicy tags to test/e2e/framework * Add datapolicy tags to pkg/apis * kubeconfig: add explicit path, if specified to loading precedence * Introduce api-extensions category in k8s apiserver * refactor(apiserver): ignore the insecure flags * Allow for configuring etcd progress notify interval on GCE * Fix seccomp PSP docker/default annotation handling * fixes max-min fairness * local-up-cluster.sh: Pass SERVICE_CLUSTER_IP_RANGE to controller manager * fix kubectl debug link error * Added config parameter for CPU threads * Updating EndpointSliceMirroring e2e test to accept multiple slices * pin to latest k8s version * more versions * rev versions * use current method signatures * Update csi-proxy version * add audit-log-compress to apiserver * Update PriorityClass conformance test to cover DeleteCollection * SetCondtion updates generation * Update testing-manifests/storage-csi owners file * CHANGELOG: Update directory for v1.20.0-beta.0 release * Re-add the event recorder in the release test * Don't clear the cached resourcelock when errors occurs on updates * Add failing test showing release is not working properly * Wipe some fields on service "type" updates * Make some methods into non-methods * If image has stackdriver agent installed, use it. * remove the deprecated client that we stopped generating * generated * Update function setting master node size for GCE * dualstack endpoints integration tests * fix case when HC timeout is 0 * pv controller test: more test cases * pv controller test: use sub tests * pv controller test: enable klog output * cleanup: fix some error log capitalization * fix unbound variable on upgrade * add godoc for events to events.k8s.io * Event: Document TTL and best-effort-ness * Add the pod_resources_endpoint_requests_total metric * Update podresources api e2e_node tests * tombstone-ing IPFamily field(15) * fake dynamic client: document that List does not preserve TypeMeta in UnstructuredList * Change function signature for MatchNodeSelectorTerms * Use host IP instead of 127.0.0.1 for kube-apiserver healthcheck. * Webhook: handle error when calling wait.ExponentialBackoff * Fix cacher test after bumping fakeBudget timeout to 2 seconds * Move pkg/apis/core/v1.IsScalarResourceName under pkg/scheduler/util * fixed addons fluentd-elasticsearch statefulset format error * PV controller: don't delete PVs when PVC is not known yet * follow up for #94109 * Enable Volume Expansion tests for Windows * scheduler: make Profile an interface. * Promote verify PriorityClass endpoints e2e test to Conformance * add e2e test for services with hostNetwork endpoints * e2e use functional options to configure NetworkingTest * fix e2e service test container listening port * dual stack services (#91824) * Kubelet now implements the V1 podresources API * Update generated files * Add podresources v1 API * Fix cacher test flakiness * Make versionconverter functions private * Reuse SSA type converter for resources in the same API Group * Change pvc describe test * add an APIServerIdentity feature gate * DelegatingAuthorizationOptions: exposes and sets a default timeout for SubjectAccessReview client * Fix the kube-proxy comment so that the document can be generated correctly * Fix a lot of typos in Azure codes * pause image: Stricter registry prefix regex * apiserver: use canonical egress selection names in EgressSelectorConfiguration API docs * apiserver: update TestReadEgressSelectorConfiguration to use 'controlplane' egress selector name * apiserver: add validation for EgressSelection names in EgressSelectorConfiguration API * apiserver: support egress selection name 'controlplane' and deprecate 'master' * Update test/e2e/storage owners file * Report a metric for time taken to perform recursive permission change * Log PodExec stdout + stderr * Add e2e test for the newPV Controller metric * removed whitspace * added xpack gem to enable ilm support in fluentd-es-image * Add yaml util to unmarshal numbers into int/float * Update the frontend IP config when the service's `pipName` annotation is changed * fix typo in e2e test * Add MrHohn as an owner of ip-masq-agent addon * Bump ip-masq-agent version to pick up CVE fixes * ipvs: check for existence of scheduler module and fail if not found * fix: do not hardcode nginx image URL in rc e2e test case * Grant group KUBE_POD_LOG_READERS_GROUP access to read pod logs on gke control-plane. * Add configuration options to specify --detect-local-mode on kube-proxy. * Fix static checks for pkg/controller/podautoscaler * proxy: label kube_proxy test with more unique label * Optimize NormalizeScore for PodTopologySpread * Add 5k nodes benchmark for pod topology spreading * PV Controller: PV plugin and mode metrics * style: update comments in topology manager * Optimize string building for NamespacedName * Clean code: optimize some logs of mount * extend request interval to make session affinity cases stable * Add jingxu97 to volume/util owners * Delete framework/v1alpha1 folder and change remaining import paths * Fix a bug that Pods with topologySpreadConstraints get scheduled to nodes without required labels * Fix staticcheck failures on apiserver/plugin/pkg/{authenticator, authorizer} * Alter wording to describe pods using a pvc * Deflake PostFilter integration test * allow component-helpers to import util and klog * generated * generalize lease controller * move node lease controller to component-helpers * Add integration test for Default PodTopologySpread * bump qemu version * Rename flags * Replacing factory tests with scheduler.New and options * Add SETUP_KONNECTIVITY_SERVICE flag * Separate network proxy flag for apiserver egress and starting pods * kubeadm: validate node-cidr-mask are correct * kubeadm validate maximum service subnet size * write checkpoint only when allocated devices updated. * kubeadm: validate podSubnet against node-cidr-mask * Properly quote flags passed to Cluster Autoscaler * Update nodelocaldns yaml to use 1.15.16 image * remove unused const failedExpiration * If we set SelectPolicy MinPolicySelect on scaleUp behavior or scaleDown behavior,Horizontal Pod Autoscaler doesn`t automatically scale the number of pods correctly * format incorrectAddresses in klog * fix: add missing patch flag for kubeadm init phase control-plane * fix loop bug for verify attached volume * test: Add service cluster IP range unit test * prepare node performance tests to move to separate job * ipset: Address a TODO, add test for TestEntry() with IPv6 address * Fix labels for spreading benchmark * Added functionality and API for pod autoscaling based on container resources * Add more Pods and relax skew in E2E spread test * Adjust the acceptable value of UsageNanoCores * Return non-zero code on logexporter failures * Fix default values for logrotate in /var/log/ * Add integration test for kubectl debug * Fix golint failures in client-go/transport * Update the PIP when it is not in the Succeeded provisioning state during the LB update. * Support cross compilation only on amd64. * Always set relevant variables for cross compiling * Use host IP instead of localhost for control plane component kubeconfig files. This is a part of work to allow control plane components to be moved off hostNetwork. * Allow deletion of unhealthy pods if enough healthy * iAdd host IP to etcd listen client URLs. Allow kube-apiserver to use host IP to connect to etcd. Update etcd/migrate to allow additional client listening URLs. * Add error detail in log * CHANGELOG: Update directory for v1.20.0-alpha.3 release * fix the fake cloud provider * Warn that hyper-v featuregate will be deprecated in 1.20 and will be removed in 1.21 * Do not skip externalLB update if some nodes are not found. * Promote Replication Controller lifecycle e2e test to Conformance * Promote Replication Controller Lifecycle * Move client_builder to k8s.io/controller-manager * Graduate DefaultPodTopologySpread to beta * e2e: topomgr: fix ginkgo log * netpol: Add CRUD tests for NetworkPolicy API * test images: Adds Windows support (part 2) * refactor: migrate node e2e tests off insecure port * Generated bazel * Generated conversions * exec credential provider: wire in cluster info * Fix dependency linting * Kube-proxy: Perf-fix: Shrink INPUT chain * Fix flaky unit test Test_Run_Positive_VolumeMountControllerAttachEnabledRace data race * conntrack log delete operations * Bump github.com/Azure/go-autorest/autorest/adal to 0.9.5 * kube-proxy: log stale services operations * staging/publishing: cleanup import restrictions for csi-translation-lib * tests: Refactor agnhost image pod usage - common (part 2) * test, e2e: Remove duplication when using PodClient.CreateSync * fix test flakes * kubectl: allow users to use args with KUBECTL_EXTERNAL_DIFF * e2e don't use hardcoded name for containers name * avoid apiserver/cloud-provider/controller-manager deps from k8s.io/csi-translation-lib * Add client listening URLs flag to etcd migrate. * test: Fix using deprecated default cluster IPs * Disable test for large clusters * The function shouldRecordEvent will panic when the value of input object is nil * Fix catch all regex and missing DryRun Options * fix unbound variable issue in verify.sh * support multiple bind records (fie nodelocaldns test regression), by first replacing PILLAR_ and then replacing other vars. * Add back openapi gen for generic types and clean up doc.go * fix a nil pointer ref in slice allocation * warn user about resource being deleted * Use gsutil to download kube binaries and release * staging/publishing: remove release-1.16 rules * test images: Switches to buildx * Add new way to generate leader election lock * fix staticcheck vendor/k8s.io/metrics/pkg/client/custom_metrics/multi_client.go:49:4: ineffective break statement. Did you mean to break out of the outer loop? (SA4011) vendor/k8s.io/metrics/pkg/client/custom_metrics/versioned_client.go:38:2: var codecs is unused (U1000) * kube-proxy ensure KUBE-MARK-DROP exist but not modify their rules * Remove redundant variable * Switch events conformance metadata from v1.19 to v1.20 * Fix windows node startup failures. * CHANGELOG: Update directory for v1.18.10 release * CHANGELOG: Update directory for v1.17.13 release * kubelet container status calculation doesn't handle suddenly missing data properly * enable benchmark by matching test config * remove debug print from create quota * Move SCTP to GA * remove secondary client retries in e2e tests * Add support for create ingress in kubectl * Fix metrics reporting in kube-apiserver * Fix --dry-run invocation in kubectl e2e * fix: smb valid path error * Fix staticchecks in vendor/k8s.io/client-go * Replace non-ascii string under test/ * add methods to deallocate and starts vms in a scale set * Removing flaky tag from test * Use fluentbit as logging agent. Replace stackdriver * e2e: node: topomgr: avoid plugin leak on test fail * add a local tlsTransportCache to available_controller * Move dirExists() to kubelet_test * Map SelectorSpreadPriority to PodTopologySpread plugin * CHANGELOG: Update directory for v1.19.3 release * Fix fcpath * Ignore deleted pods. * Make copied `localtime` file write-able * Reorder default Filter plugins to have UnschedulableAndUnresolvable first * Add unit tests for dockershim/exec.go * test: Fix deprecated --dry-run parameter * Enable XFS tests for recent GKE COS versions * CHANGELOG: Update directory for v1.20.0-alpha.2 release * PriorityClass lifecycle tests * Fix log dumping for GKE * Add `create ingress` command to `cmd/kubectl` * Support the node label `node.kubernetes.io/exclude-from-external-load-balancers` * Remove dependency between create rolebinding * kube-eviction: Fix SI of process quantity * add systemd mount options interface to support the no-systemd mount * Move scheduler interface to pkg/scheduler/framework * Fix vsphere disk detach failing * - fix golint errors by adding defition comments - remove /pkg/apiserverinternal from .golint_failures * [auth]Check verbs for nonresourceurls and resources * add a OWNERS file under storageversion * generated * add the storageversion.Manager interface * kubeadm: add some output to the generate-csr command * Fix the busybox image tag in kubemark hollow nodes * fix azure disk attach failure for disk size bigger than 4TB * Add PULL_REQUEST_TEMPLATE.md and state the repo does not accept any direct changes * Run hack/update-vendor.sh * Add rule for component-helpers into staging/publishing/rules.yaml * Removing GetPodPriority from pkg/api and importing PodPriority from k8s.io/component-helpers * Duplicate a single helper from pkg/apis * simpler addition of nodeport basic validation * Replace Branch Manager/Patch Release Team with Release Manager * OWNERS_ALIASES: Add xmudrii to release-engineering-reviewers * make new command functions to keep private when they are not required to be public * wrap errors from NodeLabel, NodePorts, NodePreferAvoidPods and NodeResourcesBalancedAllocation plugins * fix azure disk data loss issue on Windows * fix upgrade test * Add defaultingType to PodTopologySpreadArgs * Don't depend on DNS in NetworkPolicy tests * kubelet: fix iptables setup under dual-stack * Improve logging of iptables canary test * Update addons volumesnapshots owners file * Clarify that we don't audit events due to performance impact * don't cache transports for incomparable configs * Update write-pki-data to give read permissions to KUBE_PKI_READERS_GROUP, for components running as non-root to be able to read the credentials. * Update to Calico v3.16.2 * Update Windows Pause version to 1.4.0 * Move cmd/controller-manager to k8s.io/controller-manager and cloud specific configs to k8s.io/cloud-provider. * API server: fix default_konnectivity_socket_path typo. * cleanup: fix golint errors in /pkg/kubelet/stats * cloud node controller: handle empty providerID from getProviderID * always collect containerd logs * Upgrade snapshot controller to 3.0.0 * log-dump.sh: Fix shellcheck issues * test-integration: Fix using deprecated default cluster IPs * Initialize k8s.io/kubernetes/staging/src/k8s.io/component-helpers * Update the example for kubectl port-forward * Upgraded aws-sdk-go to v1.35.5 to include more regions, i.e. Millan * kubelet: Set dual-stack hostNetwork pod IPs on dual-stack nodes * utilnode: fix incorrect documentation about node name vs hostname * kubelet: allow specifying dual-stack node IPs on bare metal * kubelet: Remove unnecessary sorting in NodeAddress tests * allocate service-account flowschema to global-default * Fix reporting network_programming_latency metrics in kube-proxy * Allow configuration of etcd healthcheck timeout * add ipv6 support to the image issue-74839 * set lastterminationstate for container status even when CRI fails to return termination (or any) data * Remove the dependency between create quota command and generators * make download-or-bust compatible with both sha512/sha1 * Fix documentation on EndpointSliceCache map * Adding marosset to test/e2e/windows/OWNERS approver * Add SELinux labels for kubelet on Fedora CoreOS * add CAP_NET_RAW capability to CRI stats summery test * e2e hostexec commands does not need sudo * Update after code review * Update cluster/gce/util.sh * Fix some shellcheck warnings/errors in cluster/gce/util.sh * Mask bearer token in logs when logLevel >= 9 * Update test/e2e/framework/network/utils.go add logging about min/max interval Co-authored-by: Antonio Ojea * scheduler framework: document how to make plugins configurable * Send node startup scripts to console and journal * Disable the Accelerator metrics by default * Adding Bazel dependencies * Adding failure scenario for long FQDN and setHostnameAsFQDN feature * add unit tests for network plugin manager metrics * clarify help for --api-version: note it's API group/version * include APIVersion in output of 'kubectl api-resources' * Move cloud related feature gates to controller-manager * Replace AreLabelsInWhiteList with isSubset * mark node-problem-detector as serial * Cleaned up and fixed: the potentially misleading comments around Event struct * Update DialFromNode to return values as is done w/ other tests. Update comments to clarify missing probability check function (since they need to be updated anyways b/c of the return value introduced) * Azure: fix node removal race condition on VMSS deletion * removed links to soon deprecated helm stable repo & added artifact hub link * get kibana up to speed with es * rev version of stateful set * v1.18 support changes * kubectl: Update triage/support label references to kind/support * Fix golint failures in pkg/registry/core/replicationcontroller * kubelet: do dual-stack iptables rules * use new fluentd image in daemonset * updated fluentd and all plugins * fix staticcheck for kubectl pkg files * Add gate to install CSI proxy * SetHostnameAsFQDN will be beta in v1.20, enable feature gate by default. * test: e2e: fix race in pods test * Fixes high CPU usage in kubectl drain * proxy: Add tests for kube-proxy config defaulting * test/e2e/framework/:use the term 'Control Plane' in comment * Do not update managedFields timestamp when they don't change * reconcile NLB attributes on service creation * fix detach azure disk issue when vm not exist * Mask Ceph RBD adminSecrets in logs when logLevel >= 4 * Update triage/support label references to kind/support * Update addon-manager makefile to use the new staging repo - for real * Remove unused FailfWithOffset() * Verify pod termination with E2E PreStop hook * Move predicates and priorities configuration creation to Policy mapping * Make the creation of namespace using POST and PATCH consistent * vsphere: improve logging message on node cache refresh event * Tag LabelSelector with +structType=atomic * Bump to latest kube-openapi and SMD to pick up structType=atomic support * just log essential pod info * Add error text to kube-system wait error * Change kubectl clusterinfo to non offensive words * e2e can't use both pod.Name and pod.GenerateName * Fix test "[sig-windows] DNS should support configurable pod DNS servers" * Fix lint errors in pkg/contoller/endpoint * Update Makefile to point to the new addon manager gcr repo * Fixed percentage behavior in instr * remove dns_common.go delete configmap stuff * kubelet: remove some redundant iptables option checking * Remove federation tests entirely because they break clusters and aren't relevant anymore * Don't add empty AZ labels to OpenStack volumes * resolve PR comment ( add nil check ) * fixes test/integration/ttlcontroller staticcheck * Add CSI proxy log to fluentd * Update Windows image patch version * Updated symbol 'framework.GetAllMasterAddresses' to not use word 'master' * Updated symbol 'framework.GetMasterHost' to not use word 'master' * fix: use ">" instead of ">=" in resource allocation * add configuration for controller migration. * Watch bookmarks may contain version of objects of other types * Support sharing one IP address for multiple services * Add unit tests for feature "Support sharing one IP address for multiple services" * Graduate SelectorIndex to GA * correct 'information' spelling errors * correct 'admission' spelling errors * add note for kubeadm cert renew * Fix UpdateSnapshot when Node is partially removed * Add LookForStringInPodExecToContainer that takes container name parameter, modify LookForStringInPodExec to call the new function. * Fix test name TestDump * kubeadm: deprecate self-hosting support * make update * fix integration tests * fix error message * fix goroutine that lives too long * wrap errors in selectorspread and podtoplogyspread plugin * add unit tests for getStorageAccounts in azure_storageaccount.go * Lint ttl_controller * Fix staticcheck failure for vendor/k8s.io/client-go/discovery/cached/memory * kubectl: deprecate --delete-local-data * wrap errors in service affinity plugin * [pkg/watch/json]: remove dead code * wrap errors in taint-toleration plugin * pause image: moves wincat binary location * Adds support for building Windows pause image * tests: Refactors agnhost image pod usage - network * tests: Refactor agnhost image pod usage - common (part 1) * gce: redirect handshake server requests to metadata-concealment too * Disable one subpath test for windows * Add csiproxy log * Collect debugs before framework.Failf * Enable per-zone logexporter pods creation * e2e/storage: disable caching when writing/reading to block PVCs * e2e: add option to create pods with different image in pod.Config * Clean up nits in delete cascade * wrap errors from DefaultPreemption, ImageLocality and NodeAffinity plugins * Fix LookForStringInPodExec(...) to take container name as argument, and refactor function usage Ref: PR 92127 review discussion https://github.com/kubernetes/kubernetes/pull/92127/files#r447853904 * switching to stable version * Fix kube-addon-manager overwriting resources with EnsureExists * apiserver self request metric * address instance_test nits * It's an 'Instance' of apiserver * upgrade test for BoundServiceAccountTokenVolume * kubeadm: make the CP join handling of kubeconfig similar to "init" * kubeadm: warn but do not error out on missing CA keys on CP join * using structured logging in scheduler framework runtime * agnhost image: use actual DNS domain instead of hardcoded cluster.local * add aojea to test reviewers * Use the exported struct member directly * fix: correct glbc ClusterRole * Updated vendor by `hack/update-vendor.sh` * Update bazel * Update dependencies * Remove kubeconform * Remove dependency on behaviors for conformance generation * Fix typo & documentation on kustomize.md * Remove unmaintained stackdriver logging e2e test * replace sha1 with sha512 * Use pager's context instead of TODO * kubelet: add unit tests for imagePullSecrets keyring * Keep the imagePullPolicy of kubectl alpha debug consistent with the default * Remove ext2 + ext3 tests * Add failure logic to tests that rely on side-effect-free dial functions. * Adding back in the breadth-first-polling logic. "Revert "Merge pull request #93837 from jayunit100/DialFromContainerB"" * Update the use message for kubectl debug * Graduate kubeadm alpha certs command * Fail test when Cinder volume deletion fails * Add extra log when Cinder volume deletion fails * Delete pre-provisioned Cinder volume by ID * deprecate scheduler metrics BindingLatency and SchedulingAlgorithmPreemptionEvaluationDuration * modify static check * Replace e2essh on e2e service tests * using kubectl apply to create metric adapter * Allow the lifecycle of kube-proxy to be managed independently of the startup scripts for GCE * Fix `kubectl describe ingress` format * check readyz before adding endpoint for kube-apiserver * Bump network proxy images to v0.0.12 * Bump konnectivity-client to v0.0.12 * tests: Refactors agnhost image pod usage in tests * Revert "Merge pull request #93837 from jayunit100/DialFromContainerB" * CHANGELOG: Update directory for v1.20.0-alpha.1 release * Move Kubelet Summary API to staging repo * removing deprecated scheduler metrics * refactor(kubeadm): make `alpha kubeconfig user` command accpet --config * wait until the iptables rules are programmed * Add test for listing Leases from all namespace * use GetInstanceProviderID to get instance provider ID * Remove mattjmcnaughton as a sig-node reviewer * Enhance the prompt information of verifyRunAsNonRoot, add pod, container information * Update nodelocaldns yaml to use 1.15.14 image * handle longer vendor paths without go files * Show error in status if preserve unknown fields is true for nonstructural schemas * `find . -type f \( -name "*.go" -or -name "*.md" \) -print0 | xargs -0 gsed -i 's/the the /the /g'` * endpoinslices must mirror services labels * kubectl: add a space between effect and operator when printing tolerations * Return the Kubernetes version which stopped serving deprecated APIs by default * log-dump.sh: Do not modify logexporter-daemonset.yaml in-place. * Take into account latency incurred in server filters * test images: uses nanoserver * Remove kubeadm audit package * Do not assume storageclass is still in-tree after csi migration * fix kube-proxy cleanup * scheduler_perf: use time.Ticker in throughput measurement * Remove testcluster check for csi proxy * Add cheftako to KCM owners. * Add an unit test for requests including value after token * Limit the max number of splitting * fix: detach azure disk broken on Azure Stack * [pkg/api/podsecuritypolicy]: fixup typo * Add a check for crio service before starting node e2e tests * apiextensions: prune array type without items in published OpenAPI * test: add unit-test for TranslateCSIPVToInTree. * apiserver: fix healthz vs. livez vs. readyz log output * test(kubelet): deflake TestRotateShutsDownConnections * kubeadm: update vendor to exclude kustomize import * kubeadm: remove the --experimental-kustomize feature * update-bazel * use more granular buckets for azure api calls * fix duplicate testcase names * Adds filtering of hosts to DialContexts. * update storageos vendor for FilteredDial change * kubeadm: remove the --kubelet-version flag for "upgrade node" * Adding cheftako to CCM owners. * scheduler_perf: refactor to allow arbitrary workloads * Tests for empty constraints array when DefaultPodTopologySpread is enabled * cluster/images/etcd: Build etcd:3.4.13-1 image * build: Update to debian-base:buster-v1.2.0 * build: Update to debian-iptables:buster-v1.3.0 * test(apply): deflake run_kubectl_apply_tests * fix azure file migration panic * Add support for s390x * test images: Fixes echoserver s390x image * Change code to use staging/k8s.io/mount-utils * enable gce InstancesV2 * implement gce InstancesV2 interface * Update csi proxy to v0.2.1 * cloud node controller: implement with workqueues and node lister * CHANGELOG: Update directory for v1.19.2 release * CHANGELOG: Update directory for v1.18.9 release * CHANGELOG: Update directory for v1.17.12 release * test/e2e: Busybox image is not being templatized * move dashpole to emeritus in kubelet * LockToDefault the ExternalPolicyForExternalIP feature gate * Fix resource location for ipv6 pods * Refactor kubectl without stdin test * e2e sctp support for ipv6 * Fix e2e autoscaling namespace error * reduce cloud api calls in cloud-node-controller by passing instanceMetadata to updateNodeAddress * Ensuring EndpointSlices are recreated after Service recreation * Increasing acceptable timeout for EndpointSlice garbage collection * Delete namespace parameter in create adapter * verify-generated-swagger-docs: remove unnecessary build * kubeadm: relax the validation of kubeconfig server URLs * Graduate WinOverlay to Beta * count of etcd object should be limited to the specified resource * Run gofmt * run hack/update-vendor.sh * Move podresources api to k8s.io/kubelet/pkg/apis * optimize the use of informer for scheduler * Revert "conntrack e2e test debug connections" * ingore apparmor on non Linux operating systems. * test: ensure WaitForCacheSync is called after starting sharedInformerFacotry * Move the RuntimeClass tests out of node-kubelet-orphans * Test watchcache being updated in multietcd setup * Enable progress notify events in watchcache * Allow tracking resource version for reflector store * Implement etcd3 progress-notify feature in etcd3 layer * Pipe newFunc to etcd3 storage layer * Update kubeconfig command-line help message for kube-proxy * Clean up remaining ns flag * Revert "Revert "Switch cos version to M85"" * ubernetes_lite.go: remove image argument from SpreadServiceOrFail * Don't attempt to detach an FC device if we don't know its name * follow up cleanup after SupportPodPidLimits GA * Mount kubelet and container runtime rootdir on LSSD * avoid potential secret leaking while reading .dockercfg * clean up podpreset deprecated client * generated * remove generated podpreset * remove pod presets * test/{images,utils/image}: Add justaugustus as reviewer * cluster/images: Add justaugustus as reviewer * hack: Add justaugustus as reviewer * .github: Add justaugustus as reviewer * kubeadm init phase upload-certs: add flag --kubeconfig * portforward: Fix UDP-only ports calculation * chore: add network rule support in Azure account creation * Fix misusage of RLock in timeCache lru.Cache.Get() * e2e test support microk8s * test(iptables): deflake TestRestoreAllWaitOldIptablesRestore * feat(iptables): be able to override iptables-1.4-compatible lock path * test flake: fix data race in csi_test.go * Move podPassesBasicChecks() to VolumeBinding plugin * Remove pvcLister from genericScheduler * add retry for creating metrics grabber to fix test flakes * Remove tests related to HTTPS support for ingress-gce * make kube::util::find-binary not dependent on bazel-out/ structure * output go_binary rule directly from go_binary_conditional_pure * hack/lib/util.sh: some bash cleanups * bazel: Replace --features with Starlark build settings flag * [go1.15] staging/publishing: Set default go version to go1.15.2 * [go1.15] build: Use go-runner:buster-v2.0.1 (built using go1.15.1) * [go1.15] Update to go1.15.2 * [go1.15] hack/tools: Update to k/repo-infra@v0.1.1 (supports go1.15.2) * [go1.15] build: Update to k/repo-infra@v0.1.1 (supports go1.15.2) * Graduate ServiceAccountIssuerDiscovery to beta * avoid logging token in RunDeleteTokens * gpu device plugin uses EnsureExists addon mode * Non-zero cfs quota period duration requires feature flag * Use namespace flag passed to RunKubectl* methods * Update etcd to dd1b699fc489 * Fix some shellcheck warnings/errors in cluster/gce/util.sh * kubeadm: remove stray "alpha phase" command * kubeadm: remove the "alpha kubelet config enable-dynamic" command * Fix index out of range panic for kubectl alpha debug * rename some files * Fix minor comment in a script * Wrap errors on VolumeBinding plugin * Wrap errors on DefaultBinder plugin * Wrap errors when running Bind plugins * Wrap errors when running PreBind plugins * Remove field disablePreemption from internal scheduler codebase * Run unit tests 2 instead of 3 times via bazel * Add the storageversion.Manager interface * pillar_dns_server remove change so as not to break tooling in the near term in the kubernetes/dns repo * Fix staging/src/k8s.io/apimachinery/pkg/labels golint findings * Use EphemeralContainers for storage validation * Hold error in framework's Status * Increase time it takes for second pod to startup for offline resizing * Read PV object from apiserver to prevent flake * Migrate scheduler, controller-manager and cloud-controller-manager to lease lock. * fix the bug that kubeadm tries to call 'docker info' even if the CRI socket was for another CR * Update csi-proxy to use beta version * remove feature gate SupportIPVSProxyMode. * Revert "Switch cos version to M85" * bump the version of k8s.io/system-validators to 1.2 * kubeadm: Update versions for 1.20 * Handle nil elements when sorting, instead of panicking * kubeadm: print warnings on invalid cert period instead of erroring out * CHANGELOG: Update directory for v1.19.1 release * Prevent deletion of namespace again * Deprecate Dockershim * Tolerate NotFound errors when deleting snapshots * storage E2E: explicitly wait for PV deletion after ephemeral test * Add vCenter info metric * Avoid unnecessary calls if other error occurred * test(portforward): deflake TestGetListener * Add roundtrip tests for metrics repo * generated * Let kube-apiserver host the storage version API * fixup: add podLister as a member field of DefaultPreemption * Preemption plugin to fetch pod from informer cache * Switch cos version to M85 * generated * fix import paths * add internal.apiserver.k8s.io/v1alpha1 to known gvs * update doc.go and register.go * move apiserverinternal types to kube-apiserver * Initialize scheduler's podInformer in sharedInformerFactory * Sort list of formats for --logging-format description to make it deterministic * skip TestClientReceivedGOAWAY * Count storage requests as whole byte values in quota * Add Stephen Augustus as Reviewer for staging/publishing * e2e: fix deployment non-unique env vars to avoid SSA error * Remove pkg/api/endpoints * Stop container before remove for Docker * fix golint failures for staging/src/k8s.io/client-go/examples/workqueue * Revert "fix cluster/log-dump/log-dump.sh shellcheck failures" * deferredResponseWriter returns after calling the Close() method * test(tools::events): deflake TestEventSeriesf * Fix typo in comment of hack/verify-shellcheck.sh * Fix staticchecks ST1005,S1002,S1008,S1039 in pkg/kubelet * Remove unnecessary double-pointer * Add metrics for azure service operations (route and loadbalancer). * Add tests for daemonset view history * Add commend for printHistory function * test(watch-tool): deflake TestRetryWatcherToFinishWithUnreadEvents * dedup the printHistory logic in DaemonSetHistoryViewer,StatefulSetHistoryViewer * Describe sts on rollout history if the revision * kubectl: Use Fprintf * fix golint for pkg/volume/azure_dd * test(workqueue): deflake TestMetrics * build/lib/release: Explicitly use '--platform' in building server images * build/common.sh: Remove extraneous reference to debian-base image * test(kuberuntime): deflake TestRecordOperation * prefer NoError/Error over Nil/NotNil * Deflake serving options, avoid hard-coding ports * Deflake port forward tests to avoid hard-coded local ports * Deflake cpumanager checkpoint unit tests * Use unique socket name per cm test * fix(azure::cache): TimedCache.Getter should be called once on the same key * test(azure::cache): deflake TestCacheNoConcurrentGet * Run slow kubeadm upgrade tests in parallel * Ensure kubeadm tests have unique names * Avoid mutating global variables in kubeadm certs phases * test(iptables): deflake TestRestoreAllGrabOldLock * Skip TestGOAWAYConcurrency * test(apiserver): deflake TestClientReceivedGOAWAY * Deflake TestSetup * Deflake TestHTTPProbeProxy * kubelet: remove alpha warnings for CNI flags * Add more tests for LRU cache lookup * Move ResourceQuota admission to k8s.io/apiserver * do not mutate endpoints in the apiserver * remove DefaultIngressClass feature gate for 1.20 * Cleanup custom metrics conversion functions * feat(kubeadm): specify resource requests in etcd pod spec * Stop ignoring unit test flakes, require multiple successful passes * kubeadm: remove the CoreDNS check for supported image digests * Use ExpectNoError(err) * allow to map the same container port to different host ports * Updating winkernel kube-proxy OWNERS file * consistently use double quotes in proto files * Deflake TestServiceRegistryExternalTrafficHealthCheckNodePortUserAllocation * add more testcases for GOAWAY filter * prefer double quotes and consistent usage in .proto files. * Improve ability to debug Events e2e failure * Added support for register-with-taints setting #93608 * AWS NLB/ELB health check config based on service annotations * kubeadm: adjust the logic around etcd data directory creation * fix vendor/k8s.io/apimachinery/pkg/runtime/serializer/versioning staticcheck * test(csi): deflake TestAttacherWithCSIDriver * Remove HeadlessService label in endpoints controller before comparing * Remove default conversions * Update security contacts for sig-cli * Allow to disable logrotation of kubernetes and pod logs * Fix some shellcheck warnings/errors in cluster/gce/util.sh * Fix some shellcheck warnings/errors in cluster/gce/util.sh * Fix some shellcheck warnings/errors in cluster/gce/util.sh * Enhancement on the testcase to cover more possibilities * fix kubeadm update coredns with skip pending pod * address review comments * Update kubectl to use new vendored github.com/fvbommel/sortorder dependency * Fix broken dependency vbom.ml/util * Add exp backoff for connection refused errors * proxy/userspace: clean up and consolidate testcase setup * proxy/userspace: use waitgroups instead of sketchy atomic ops in testcases * Start CSI proxy as service * remove --verbose_failures from .bazelrc * fix a few missed references * CHANGELOG: Update directory for v1.16.15 release * update scripts * fix doc file * rename * partial * move port definitions to a common location * remove iperf e2e test ip family tags * modify DNS-1123 error messages to indicate that RFC 1123 is not followed exactly * kubeadm: Fix `upgrade plan` for air-gapped setups * Avoid the API call to update pod if nothing is changed * moving files from k8s.io/util/mount into staging/src/k8s.io/mount-utils * fix: return error with fewer mount options on Windows * fix: smb remount issue * Remove driver letter assignment during volume format * Revert "Merge pull request #166 from jingxu97/May/drivename" * chore: add more logging for mklink on Windows * fix: remove unnecessary readlink check in IsLikelyNotMountPoint on Windows * Remove driver letter assignment during volume format * Switch to klog v2 * ignore golint for some stutter that we want to keep as-is * fix bad spelling * Revert xfs_repair fix * Fix windows MountSensitive error * Fix subPath mountpint check * Fix mount_windows build error * Introduce paramater for sensitive mount options. * FormatAndMount unit test only checks for MountErrorValue now and closed gaps for some error values * Add more detailed error output when disk formatting fails * Split MajorMinor into two fields * update after review * use xfs_repair to check and repair xfs filesystem * Return typed error when Mount Fails * Validate the existence of filesystem before attempting to mount it (linux) * feature: implement Output method for FakeCmd * Fix golint errors * Update doc.go to show k8s.io/utils * Extract pkg/util/mount and drop BUILD * bind metadata proxy to 0.0.0.0 * Add e2e multiple endpoint services test * spdy: add optional periodic Pings on the connection * fix vendor/k8s.io/apimachinery/pkg/conversion staticcheck * Handle eviction of pods in deleted namespace * drain: eviction creates in a deleting namespace will throw a forbidden error * Fixed reflector not recovering from "Too large resource version" errors with API servers 1.17.0-1.18.5 * Stop setting SelfLink in kube-apiserver. * Fix FakeClock::Reset to always succeed * add myself to sig-node-reviewers * kubeadm: make the scheduler and KCM connect to local endpoint * kubeadm: Ensure etcd manifests are regenerated upon upgrade * Add WatchListPageSize to cache.Config * Allow 404 error on lb deletion in azure * add lock for csi node update * fix typos in cmd/kubeadm * clean up testutil/metrics content * Update comments in pkg/scheduler/framework/v1alpha1/interface.go * Update `kubectl diff --server-side` test. * Skip TestLoopbackHostPortIPv6 run on non-IPv6 env * relax matcher for ResourceMetricsAPI test * fix staticcheck errors in resourcequota * update test to match validation filter of pods * Omit optional field when empty * Update CNI plugins to v0.8.7 * fix golint failures * Mark SCTPConnectivity tests as disruptive. * Add tests for SCTP network policies. * Ensure getPrimaryInterfaceID not panic when network interfaces for Azure VMSS are null * Improve the prompt message when kubeadm init is successful * fixed golint error in pkg/apis/admissionregistration * Add 1.19.0 API testdata * Remove 1.17.0 API testdata * chore: 📦 update generated files * Update max data disk count with new instance types * Getting rid of the Salt DNS replacements, addded / back. * tests: Refactor agnhost image pod usage * Improve docs for client-go warning handlers * Override hostname with instance name * Fix testpattern check * chore(openapi-spec): 📦 regenerate * Moving e2e tests to e2e_node directory * Combine switch case into one case * Ran hack/update-bazel.sh but discarded changes to root build file * Move common portion of dynamic snapshot out of switch statement * Remove custom hash function, generate a random UUID for snapshot and snapcontent name instead * Stack snapshot tests into one to reuse snapshot resource and reduce time taken on prow. * Quick commit * Remove snapshot class from prepv test because it is not needed. * Combine two tests with overlap to reduce overall snapshot test suite time * Add pre provisioned snapshot tests * start kube-apiserver and webhook server only once to shorten the webhook audit test time * Minor cleanup in snapshot test suite. * Add a link to liggitt's deflake docs in Flake template (#94243) * Deprioritize extensions/v1beta1 in discovery * Update cri-tools to v1.19.0 * Update default etcd server to 3.4.13 * fix(azure): check error returned by scaleSet.getVMSS * fix cluster/log-dump/log-dump.sh shellcheck failures * Remove azure-load-balancer-disable-tcp-reset annotation * Remove duplicate nodeSelector * fix linter issues for pkg/kubelet/cri/remote and staging/src/k8s.io/cri-api/pkg/apis/testing * Fail early on stress test and improve logging * kubectl wait add ignore not found flag * Support kubectl delete foreground * remove deprecated kubelet endpoint /metrics/resource/v1alpha1 * Update options.go * Initialize candidate directly instead of iterating the array of candidates * Move brendandburns to to emeritus status. * fix vendor/k8s.io/apimachinery/pkg/apis/meta/v1/unstructured/unstructuredscheme staticcheck * only update Azure data disks when attach/detach * Enable IP Tags on Azure LoadBalancer public ips * Add PR #89069 Action Required * Update etcd makefile to build 3.4.13 image * Update etcd client to v3.4.13 * update drain message to include namespace for pod in kubectl get compatible format * CHANGELOG: Update directory for v1.19.0 release * Fix issue on skipTest in storage suits * Remove file_mode args for Windows test * Update Calico to v3.15.2 * Set snapshotType for tests with NTFS. * Update CHANGELOG-1.18.md * Add logging if container or pod fails to be killed * Adding label NodeAlphaFeature to include tests in Node Testgrid * Add impersonated user to system:authenticated group * Verify running mirror pod has running containers * Only process all nodes when incoming pod has no preferred affinity * test(endpointslice): deflake TestSyncEndpoints * Remove unnecessary conversion * Detect change of volume attachability in the middle of attaching * Promote PidLimits to GA * Ensure backoff step is set to 1 for Azure armclient * [pkg/registry/admissionregistration]: fixup wrong copy&paste godoc * Remove StartupProbe featuregate and related logic * Make ProjectedVolumeSource optional * Track pods with required anti-affinity * Updating kube-proxy to trim space from loadBalancerSourceRanges * let panics propagate up when processLoop panic * Allow to configure clustername in creation of kubeconfig using kubeadm command * Make similar buckets for api and etcd request duration histogram * .github: remove stackoverflow from support issue template * Refactored pkg/controllers/resourcequota * fix: use sensitiveOptions on Windows mount * Cleanup kubelet TODOs that are no longer pertinent. * kubelet, cgroupv2: do not create /sys/fs/cgroup/sys with cgroupfs * Update wait function w/ descriptions of global node states, TODO for kubelet API. * ARM client: survive empty response and error * delete tests which use container manager stub * tests: Use Windows absolute path on Windows pods * Only lock statuses map when status isn't successful * Do not allow manual changes to manageFields via subresources * Change nodeInfolist building logic in scheduler * do not create StatefulSet pods when PVC is being deleted * fix misleading comment in expand_volume.go * Simplify and de-lint GCE Windows kube-up docs. * Add context to x509 verify failures * Read ssh username from env variable * Fix the logging message * Use /usr/bin/env bash in Makefiles and scripts * Scheduler auth stop using legacy scheme * allow adding annotations to pod when using kubectl run and add tests * kubeadm: Separate argument key/value in log msg * update ResourceMetricsAPI node-e2e test * docs(api): 📝 Fix HPA docs with addition of "External" type * fix vendor/k8s.io/apimachinery/pkg/util/framer staticcheck * Removed broken link to Analytics * Make CSI mock driver log parse more flexible * Verify that an ingress with empty TLS is valid * Update client-go out of cluster example * Update yaml files to use seccomp GA syntax * go fmt fix * remove some notes about scheduler/algorithm * get: -o yaml, json set ServerPrint false * Add test for `pkg/kubelet/util/util_windows_test.go#GetAddressAndDialer` * back out conversion of DialFromNode->DialFromTestContainer * kubelet: assume that swap is disabled when /proc/swaps does not exist * e2e storage: skip multi-volume generic ephemeral volume test * Reduce test volume sizes * support ipv6 in e2e policy tests * modify the warning log format from %d to %v * Update snapshot controller to use k8s.gcr.io * Seperate registry and feature gates * names unnamed testcases, adds name to t.Errorf msg * Improve running time of TestSchedulerWithVolumeBinding * Add maxTries logging statement, otherwise the numbers are really hard to interpret * implement breadth first try * fix test/e2e_node staticcheck * Fix error messages * Fix Poll variable name * Fix waiting for PVCs to get Bound * Number of failed jobs should exceed the backoff limit and not big equal. Remove patch in e2e test of backoff limit due to usage of NumRequeues * fix vendor/k8s.io/apimachinery/pkg/apis/meta/v1/unstructured staticcheck * Fix some typo * golint * fix vendor/k8s.io/apimachinery/pkg/labels staticcheck * Enable completion for `kubectl config delete-context` * vsphere: remove inactive members from OWNERS * sig-network: remove inactive members from OWNERS_ALIASES * cluster/addons/dashboard: remove inactive members from OWNERS * apiserver: remove inactive members from OWNERS * Fast return when no any matched anti-affinity terms * Update seccomp e2e test for GA * Fix an error in NodeUnschedulable plugin comment * Format Codes * minor logic fix * e2e test intra-pod breadth first logging and summary * fix incorrect comment in runtime ObjectKind interface * Fix job's backoff limit for restart policy Never, rely on number of failures instead of number of NumRequeues * test(kubelet): add a regression test to verify kubelet would not panic * fix(kubelet): protect `containerCleanupInfos` from concurrent map writes * refactor(*): update pvc quota name typo in comment * fix: azure disk resize error if source does not exist * chore: add diskclient.Update interface * chore: add diskclient.ListByResourceGroup interface * Remove false positive warning in kubeadm cmd * cloud provider: add zone/region to InstanceMetadata * Sort kubectl top output when --sort-by and --containers are used together * add testcases for kubelet getters * fix a typo in the comment * Use v1helper.GetPersistentVolumeClass for compatibility * Add tests for managed fields tracking. * leaderelection: Remove doubled space in "attempting to acquire leader lease" log * benchmark-dockerized.sh: set KUBE_ROOT * kubeadm: reset don't unmount /var/lib/kubelet if it is mounted * PodReasonUnschedulable is not a pod condition type * Fix kubelet log message when starting a container * kubectl describe pod: use ReportingController as an event source * Fix TestScorePlugin: numScore should be accessed with atomic.LoadInt32 * expose Run[Pre]ScorePlugins functions in PluginRunner interface * Cleanup wait forever loops in pv_controller_test.go * Strip unnecessary security contexts on Windows * Updating the Reviewers / Approvers for WinKernel Proxier * fix the remote endpoint cleanup logic * Add chendave to sig-scheduling REVIEWERS * Adjust default replica count to 2 replicas * Run make verify with python3 to fix publishing bot issue * Document blocking behaviour of RunOrDie and Run * removed k8s-master label * Add example of using resource builder to load a manifest file * tests: Fixes variable expansion false positive test * revert auto-completed package names * remove legacy leftovers of portmapping functionality that was moved to CNI * mark this test serial due to race conditions * Clean up daemonset test names * Remove phantoms from dump_requests output * deps: opencontainers/go-digest -> v1.0.0 * Update k8s.io/utils dependency and use ebtables from there * kubectl: Allow --patch-file to be passed to `kubectl patch` * reduce type conversion and correct variable name * Fix verbs reporting in kube-apiserver metrics * kubectl: improve the warning message when doing kubectl apply to the resource without expected annotation * Fix label reference in deployment checks * Use NLB Subnet CIDRs instead of VPC CIDRs in updateInstanceSecurityGroupsForNLB * Update readiness checks * Update ready condition * chore: upgrade Azure/go-autorest to v14.2.0 use autorest v0.11.1 * extend ShouldCallHook benchmark to verify performance imporvement * [kubectl] Fail when local source file doesn't exist * nodelocaldns.yaml: remove force_tcp option which used for external dns query * Create Deployment resource lifecycle test * apf integration test: ensure no rejection * skip mismatched webhookAccessor and object * return err directly when nodename is not consistent in cert * add bootstrap policy for monitoring roles * unit test * move to cadvisor.MachineInfo * Delete ILB FR in case of changes to port/proto. * fix windows container root validate * hack: ensure go version is not specified for master in publishing rules * publishing: remove go 1.13.9 for master branch for controller-manager * add test case for kubeadm memory check * add more testing cases * Shorten watch restart test, run in parallel * ipvs: log error if scheduler does not exist and fallback to rr * fix golint failures in pkg/kubeapiserver/options, fix some incorrect replace of receiver name * fix golint failures in pkg/kubeapiserver/options, rename receiver name of BuiltInAuthorizationOptions to o * fix golint failures in pkg/kubeapiserver/options, use API Server in commemts instead of APIServer * e2e node: fix kubelet service restart failure * Mention background deletion in kubectl delete cascade help * fix bazel build file * correct the sandboxId attribute in unit tests * address review comments * add sandbox deletor to delete sandboxes on pod delete event * Check for sandboxes before deleting the pod from apiserver * fix(kubectl): warn users that flags cannot be placed before plugin * Avoid using socket for hints * regen * update build * remove serializers from codec factory * update * clean up unused var containerCache * cleanup: print warning message after timeout * Revert "cleanup: decrease log level from warn to v3" * cleanup: decrease log level from warn to v3 * AWS: increase io1 volume IOPs limit * Add a preflight check that the control-plane node has at least 2GB RAM * Handle int -> float conversion in FromUnstructured * Fixed potential nil dereference in hostpath unit test * Fixed error string should not be capitalized * add GetAddressAndDialer unit test * [k8s.io/apiserver/pkg/server/filters]: fixup go vet warning * [kubelet/dockershim] : Use local copy for range iterator * fix(staticcheck): fix static error of package `/pkg/volume/gcepd` * Filters on kubemark nodegroups when selecting node template to enable hollow node clusters that contain real nodes. * Move MasterUpgrade() out from e2e framework * Use temporary directory when creating temporary file in tests * generated * add vendorless to client-gen * use canonical import path in client-gen so that package comments are * ipvs: ensure selected scheduler kernel modules are loaded * Fix NetworkPolicy describe for egress-all policies * Export WaitForCSIDriverRegistrationOnAllNodes to be used by external csi driver repos * [e2e/storage] fix range issue in getCSINodeLimits * kubelet: add operations count and error count metrics to network plugin manager * fix HandleCrash() order * fix golint failures in pkg/kubeapiserver/options * remove duplicate path import * AWS cloudprovider allow nlb-ip and external type lbs to be managed externally * Move WatchUntilWithoutRetry() from e2e framework * Add metav1.SetMetaDataLabel func * Remove resize map code * lock-free broadcaster, use chan to ensure thread safety * [test/kubelet]: Fix deadlock in watch manager test * kubectl: remove the dependency between autoscale command and generators * cluster/addons/metadata-proxy: cleanup inactive members from OWNERS * test/images/pets: remove OWNERS to cleanup inactive members * apimachinery: remove inactive members from OWNERS * [pkg/controller/certificates]: remove staled func comments * Remove DeprecatedMightBeMasterNode() * TestCreateInvokeAdmissionControl: remove unnecessary goroutine in sequential processing * Add unittest coverage for boottime_util_linux.go * dual-stack: make nodeipam compatible with existing single-stack clusters when dual-stack feature gate become enabled by default * Adds additional documentation for job status * Set the oom_score_adj of guaranteed pod to -997 * Resolves staticcheck failures for component-base/metrics * Change the node name from "machine" to "node" * Fix a typo in PreBindPlugin comment * Replaced repair with returning error, in delta_fifo.go * Fix description of conversion generator * Don't create a new sandbox for pod with RestartPolicyOnFailure if all containers succeeded * add defer * SIG node owner files clean up * Refactoring: Reduce unnecessary lines * Fix a typo in comment * code clean for podgc * fixed e2e vsphere statefulsets test * Repair instead of panic when data corruption detected in DeltaFIFO * conntrack e2e test debug connections * disable goffuzz in binaries * Add get-users and delete-user to kubectl config * fix typo in runtime/interfaces.go * Return nil as error when instance is not found so that node_controller could delete the node * Cherry pick the fix https://github.com/kubernetes/kubernetes/pull/70291 * Find what fails pull-kubernetes-e2e-gce-ubuntu-containerd * Review update * Sync with master * Remove previously added '' no longer needed * No quotes needed/wanted for CURL_RETRY_CONNREFUSED * Add fix for run-kube-controller-manager-as-non-root * Updates after review * Update cluster/gce/gci/configure-helper.sh * Update cluster/gce/gci/configure-helper.sh * Update cluster/gce/gci/configure-helper.sh * Update cluster/gce/gci/configure-helper.sh * Mitigate newly added shellcheck issues * Updates after code review * Update after code review * Code review update * Fix shellcheck w/e in cluster/gce/gci/configure-helper.sh * changes in imports was unintentional * fix S1000 simplify ch switch cases * fix S1000 simplify ch switch cases * fix S1008 simplify bool returns * fix S1002 omit comp to bool * Warn when creating roles with custom verbs kubectl * Fix static check failures for staging/src/k8s.io/apiserver/pkg/server/healthz/healthz_test.go * cleanup tempfiles in unit test * Enhance apiextensions-apiserver in standalone mode * fix CHANGELOG typo * Mirror pod without OwnerReference should not be created * Add unit test to kubectl/cmd/run * remove stale TODO after this PR: #92204 * add line break when describe hpa * basic regression test of runDockershim * fix func name NewCreateCreateDeploymentOptions * Fix error check logic * Fix broken format in CHANGELOG-1.18 * Remove contemplation of invariant violations from delta_fifo.go * fix expanding rbd volumes without ceph.conf * Adding tests for Kubelet pod update functions * Update Calico cpva to v0.8.3 * cleanup: remove useless methods * Modify the kubelet document * fix golint errors for pkg/kubelet/dockershim * cleanup: no need nil check before range * Add lease release tests in leader election * Generate complete leader election record to resolve leader election issues with LeaseLocks * fix: comments(only create parent dir) * make kubectl/kubeadm completion script support busybox * Add node-local-dns headless service * Made containerd-namespace flag can be used when kubelet config start cmd * fix comments * fix: ignore dir check in csi node stage/publish * Link to krew's new project site * Remove --include-uninitialized flag documentation * Use canonical URL for the krew project * return success if cordon node by replace * kubectl/drain add support for custom pod filters * do not wait for node ready when starting kube-proxy in 'nokubelet' mode * validate KubeletCgroups and KubeReservedCgroup- Initial Package/bin/sh/bin/sh/bin/sh/bin/shobs-arm-7 1651057364 1.20.131.20.13-lp154.1.71.20.13-lp154.1.7 kubernetes1.20manifestskubernetes1.20kubeletkubelet.servicekubelet.service.dkubelet.confrckubeletkubernetes1.20-kubelet-commonCHANGELOG-1.20.mdCONTRIBUTING.mdREADME.mdsysconfig.kubelet-kubernetes1.20kubernetes1.20-kubelet-commonLICENSEkubelet.1.gzkubeletvolume-plugin/etc//etc/kubernetes1.20//run//usr/bin//usr/lib/systemd/system//usr/lib/tmpfiles.d//usr/sbin//usr/share/doc/packages//usr/share/doc/packages/kubernetes1.20-kubelet-common//usr/share/fillup-templates//usr/share/licenses//usr/share/licenses/kubernetes1.20-kubelet-common//usr/share/man/man1//var/lib//var/lib/kubelet/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.opensuse.org/openSUSE:Leap:15.4/standard/b79f7f7c2430259a79b4528b8280d09f-kubernetes1.20cpioxz5aarch64-suse-linuxdirectoryPOSIX shell script, ASCII text executableASCII textexported SGML document, UTF-8 Unicode text, with very long linestroff or preprocessor input, ASCII text (gzip compressed data, max compression, from Unix)Rw3rQutf-83d6b706fc97215de45c1f954331256b757ac979b1985a4b3b185335de85e8062?p7zXZ !t/] crt:bLL ?Гޚ2H̎alh#@f;>(>?&0Iv8l`DۡB=1;T P:.tp 'kQfðΕgIN,TP,r2Y` LzblW[s7s` 1gX_'bSx@F-UoHu;Do=-cVڨ1ܑDۣ'=/:s4Ӯ9lgNB)#V1bK MV.jۂJPfF"'R]pKIq bŧ$< 3]ye_cou- 5䤠7Ƙ'|mpo1p)c.[oV*lo6}ڞWz92Y{˜Dt(JrnڱƬEǼ(Ʃo4iߧ>2Hx2'njx_Ia}?mV٣E(+.ERMO+|[>ijdq=,c AХLqY\>j;Ex!̾9F̣ï.v Y[{]z Oiɜ } ֢?9HnE%@v &5.-zœ?; R9,`D5ԲSr>1fIpԖI('ϚJR|ZrwvS'h Y#J?ܵZuR:  Gb%Yn&mQ{}SWψ?< <YBJTv֘@N&Žou/=vw5iraJ$9$Z^Oo1'~3yD(6v2qW>@6NJ TuNH8(hM._騇v,rk]x%G972K/se1ܯOqj=HuBUs蕲- ~c.h\WX1g gW`KщUxӫ}hCt^.QСڂN!*I@U*c z.3Htm־ AH/ x1Y|S:-[d |Utk~SQ٥y'}J7f@a0=q+&ܡ ' =?.ur\P.bU9a5>?ZSmIK(%!yzQ9Đ#LXX 2,#Jawag!nGE+MOyHfǰ]]Qhfq{#sl/˜^O[2##uxZ7^0)юYg^ʤS7t%+6vXauC=2DHk/Xbz͐Ie6 znqd x'ϲ0͢3oz!gG7Ke'mNpDa6sؤ<{Jax(:O[[_)Iݹ7aj‘q%ܑ8^Ib]nV "|notGp\גy1;1f7.|@o]^IS`2fxcD?kr}h,3Cj+HpdbyAvV5bGbahI-0ਖ਼T'+Mc\qg`$ԅv wLrt,R3Δ%#_]K n8Asl FD~,b` u![%8>DN#@8Iخw;/z] 5t wh᧌Zk?f+^dx&Xo%ʟE%['S Ssؐhݩ;y|c\O? y)K:sݝ)*gMm7bVyoGk#. }c0)=I e!;u"Z庻^?J'$p" (o 6tc&QvwpPNssAv]L^}8*MKOO|lʩ3kT&~^Qw²ݬ(}7pxogU6.l 4ɻi j9[ dBWtϨKŸL nlnZHYk8L7iOй4? ɣ(K!t^ܕ^ b(~Jw۬Z([84l4/, [,ݨr2Bh;ogs'h@^haI-t"[+TǛ|a&Xsv YLAfMeA/d_w $ 7jdy>5bP6ֆrCMָ߇pp@ͼj=)a2S^y(_V[Mi dTu<`9Ж1ze־{TV0e$hҍ|U}Yˮ(zw%hŮ\+ iĚJq4h3 .> x8~FM} \*^gLm!KXL09;EYV~*~!. HHc7rjݭ&5dN*Zˉ~:Žud'-ОW{75=hObGP3' @eݙwROU{ܿ_b,ʆD-.#l ڹBBEU6AP7$ŜK!>SК54D3Q+#.fYCq-d}ÝjnqCQw6eF{+)"=O+>pf^;p~9o 7,}ujJ5yi.q4=Y>ü/ 9;]ƾ~DҞN{EҼcm NJ[$/zΟO7nA,`_Jڎ7NhPw0qy׻;L#%?2 ׍sy)]@;.yG1B>t.fΕXou<.\RJT8ط29);[apm.i˹=, G5@a`zf 6NQo\{y0ݯ+/3c}ْG2,;Jؒn0oِNz2Fy8xo3L\A澹7QCLJ,ZYE\c/Y!~~=>Q_ރ"bNT[lc,iopRQg(c _.IJʼFT!R8o g,t6lz!}Fo4W'dza(IՈ?|-S+- pyx["֦.q$m¸b?)vbzT;HNa gNyd%_\vsj`o"7at*{7Qo9& 3vӥ$fupdvD~×#'pC1 G*`f`< bƎM^pۮya*Dw_u|$8jPza}tTU)^W_6P9!∛) }Ne*D;E4\?&gHu+}DRo'c6 ɬ(wҊHφvy f7!= *P9*yaEo%1BI^Mfg0ɘkI?d(J"},Nx RRJ=\$~V6L`s9 v/2{fjKԆj'^*6Kx1u부g\\kuZɵd=Љ%2y+錠E9r5r'|~- mo4[!G#/;+1ey*>dە % uǮ dX 0׃"LĪخ4 ɘgRcV[zZV2Nq׺XExݴF!,%L]/A IOLH29]%&sh2/1򇒑XS|]ͮXϘwwd4q}6pFC҅2sLH0c262= Su^ŭvΒ7[c=$n.`P,fQƏ]kX g"L48_Hcu?d0k,4['ѷ=7h'Z T􄬿F"4oGؚZ`d^dCTlZ/tCۓ_Zdyefc4?6,-a֔+4 G۠>3*[aꘜ=2YfB6(G#_BSl驹6%S$SA{1@EuORZpQjF=".O΅9 t۠t[LK201.6=_ ~l&;K Ap^y`ɗq/M4B%H%ULtd E v)IvBlRe#W@j9îL ]b1I3'𾳕K KJFIV2qSЛ='?t"˟xOfzA}gca^Lg3P~"DCákQXPXa-mItH.@D=e.,9<:GL@gf[_ -K*QfxRw 4 X?-V)x+e`xkkF`Y "q2 `bb<;Z4|;z] JGkg,N?^:g0Ҥ⅓=`Od|Օhf^U={D0`u:*0NDUY?_E㟟d{%6L@shzM/] O7ĀM"tA<РfcbEwՇ<+M¨YF > b#1YTC"5җ}]떪3q &OB.-$.Ȣ%!8L/;NcF=}C;P {_hnjqzaɀ>=SN;bj7`.@^ʧ̜CnAQބuN㳲,휈hs Ӕݛ`.$Љ`'Ɖ8ћbE ej&U&53 kY3j&5 S|.:wѨ^yVH}ۦH{ѝ,Uz6zMm9?-xпLP@Zm2C G["fY p&iY!ڧ;a6>$Ej"h ѭ 譜İ{:WPkRn79O)"v=W&4Tp|vgL #9g'K;Ej~ 6ߪewZH?CZ!4XC G]P #U9u_ 3KP )5alI$#V)P6bnė\`,;$?4f)KSǁ5Ȳ.psLjr9LMe~lA:suPt)Ě,y( BuhkN-L"ƌx "~|7_`eO]yS1w}(0и}77"ڭLxy ="G&䪀YÌxa)d<yv%2%ރ{Քfc\ OȲ8w ?vAEV]SxbAF6I=ZDT%(QqG\ #3o/6aBƛHh 44SZ!7Jshz+ JelTq Ш`%}A>(%n몶uGtq9+T'Nb7}s\d[ g?5qJ 8a{ иmQU5۹s؄})Gt+)Aa<{VyKR#ҋ&*#HpщZӦ*flW+%wztj*YFKƢt%]69`N%Q{o;R}ZI®`v0vI3Զ-ۏjBH{=#i5y>lcXФt~P2B_/)$*I_Wc1T#)+AX$LGh|n܁lTvff/zZwY UXf6|Pg/!`mP@.{?y#eƱx9ݯMl):2.$'QSF &03f.2N'7"9"l-@{a֋tm)9Y#hjrL9R `Y-}+`DIBB@֛ѦEXBˆ٧2ڙbQo?q2reX>?IijC|Q'9˧#xTh9œ^ȸF>wEyl,, _B\FaeKqX91Z3׈kcû=|2pS W45Ay QoR.R{mX.(*k Q%P|o%&XAx_v$*&J|ΟZ19[d|VޜV;MTYg[gg%jADmf ɚ,Ӹ3W_q,%`7a(NHmhf-7޲Ux(0ϻ-xƻM"cU]N{ˆ1=ڿa Gz` /jR=mAB |CCb]V8ZB ? BU/zҽ##Fa|,UX(==. YX7GsBۣBFfo«w/Pzى|n5%7 5rt #Y(g_ |ds`އ{Fp(/lh9$$ Hub zQ~A-uՈ^CPh|Ejιm(ay]8a[0 ;_Wwv_bNod`ڋЁA#6M&vΫfՉwEzeE~K_B:mʧ%\^5$es=Q"i:BԮl ܬL;?oJaryE-2Χrc1RwMt7﯅=i QnR*02!i'P$ 3b!gK`5(%'(GdTPG8+v"s8lFC%PGE<0<Wl~oz~,U7e=ud3z&(ٕCօ# @|"3nbY(|* DdBr[ AxJ sW<\ Tդ #QZ'":Fz81 F v $ړR^pWLtjILW!FN묬jENg8E?*Ux]?]8ַxBp^&# ;^]T_jbōa5,ToȄ ':Rcr}݋F bA,ۇؽBo%Kbw:b;A@s"W;7B\d_Ʀru#YYzF cL᫒ Nc݅aߢ5 ^G]hڿG#6ys;Ϙ\% IVj)"g?X3l|>J!_5e"bqd) 6@$M &?K-ₚԛU? LjyzE^`]ѽeHcJZBI(?C{ p'q,3QQٕkΎ`)93%K :ݙw0΅ԥtSjZ ȁe1!6|08c`vbQ鉀_מEnq#Fd9%luRz^Ni:(BqfkwLd w7W? h3}(b_4nmRP뮎diN™ /,ƒVKDo59~sb`Z cm3t"-vg"O[0+Lr<B-wgp=]ieK-"FQdv=5%R>XJ7W"90-;/Mz*T8[ t ~9Obz\Շ"ٞ^x􅆂ՙʱwDBimLq^ D֙i'S:`ǖi`S5TRv=cLJ{ގn2}6ݶ YXo|$4)Es7SsSps턦:fdPΓoAr&yǡ "kҥt[39@rsnk‚@|y>gd<ןԹVo!$.<2򅦮.V.۠r}W(QY>=O*;k}vL3W n>g*%%;CGi\=JC e Lt\ޙZ1k u?fL:g%DkL/?8"9X}*sNMnN򘐏S$T_CTbj;DqjqȾ-EIś!5͊3~+?۩tu68   sr'Nv\Qk'gr`A+\TuTYFQZ>vm6osbsɰCpQX}ᮍ,Zړ_!;,Qgd*0Ϧ[`v"?S%?Z] %Q7/Q]`Q [D6G:z0B7)%țY\WK6 *Pp$Fn8I!+eOT2O<90(,Ѧ!!}jEĚ9G*&߁䎈ΰ:1 ጂG52G'!Yax56@6 i;dDMX{ZDԻv!zBt¸SWySm$A|vmW)@$׺E6ڷ9@ͫ(ɢ)> .A \!kao\?zɓ1Bb'KGI~m rdw`=e,@2Җ'&fYcuwzn-( $:egEu&8W.-<%mPLw L*Β>~E;Ө:M1STtQ.6&(*`\Spi@|ŘYahD8!q յf~T} $\.zPZ 0o"־xt(iZJ->U|ZUQ7^|ζ˱DRLMVP0M r( ;}̬@Me:lii? wDxHڜQ#  Oi:&Fek!-}ĭ9PywuWp?Ƌ*o&ZqXpK0@Y@To0 TAͮ=AxvĎׅoP)߫kq ܅_[mx\-vo sS.9@5%@a)6k-HO ήCK?Lc(o{ᙺ55KxgR"3EqQ&!J9 UNnբkd9Q C=c#jxR̼O1v)FS/>}{oqޖRp:4!meW|6{gc5<2 {-;8>U]'ם5T F|NY=;M 1,*pS]^kURCѰϹRDj[=b-u(¢!wh6b|KWlekYx@1)&&̸{#g⨮o=Q4BZrdBPCيEՕض#ءQ[~-lw፮iGV>s{`4u6\Am Q 84IuG$ M=Pt,ے ĸ#'/e:΃n1J8%Ɍa7S5(.-GX}\{dR$8ew`qlHУ?j~_BkZO%wpOxU'C1\t)7L X&G԰,ai|,[ndX_- H6 \hwLք8HbRي^qPcuʻ6p~&dgkYG&#mv:ț(=uV.Zmf Fݚn+^$J_-ࡽDN=4er VN4ᱎTrs1>5f@WzB%$D3Jߪ@0ZР HlBf)܇B֗"땤'f \%6ߦYpR?,(s{Zt©4ʸ۴27# g(Ƴ RkHLAi{߷w+?>^+Gg$ HwJGFB%c~ z AȣBIu Q3n厰3uo{h͞7#YThNi҈;1GL͆)舫I# 42#+S3edLp!M;+:δ"}ojEqV67LI!媍6ZDZ4&MW%eK}VG7!ˬ$(܍n{X}3ך>C`IRV@ 0.%0L{ Ky)c6C x uvbǛ;R%P οtZ~~VţRTv oAqpBi =ZEF`81Pϋb%gaN'@كc>O8=LCc hwhe soo[97Bč|N>uջ)n qxj1gl>ijX&KE”^g*IKmS8 ƴ _//Yߵ kovj9.vc@x,؜:e$qDǛ7t2 -D̊V<^3 ̖߯:>߲!^/譓WbƝpXXqKctƦg/W(c%&Cʸ"Bg4>#"a܋S#T5Zh `Rє2dqOP N+hTF+n/rgP{eg1|Vc?G`#D_ Y.]^656U R@ñQ/-+=cC`1M=:!Eph/ ܾ(?zB!6cn`j({A-v-RY,B#"04!qEn҆W(kT4*k0$QF4&NJw١@ߒQI¾k'TҐUof6k; w[_elh3&0WD/{KY{ 9[bF.zxc&/Q.LF[}N~O[QDa0;V/#&}侯'm}#ur;mO.9,FvbOneTD7:SC`}w0jYEIcE!uѩWC4 ϱLo뜖W54i$00 Η+/H3kMt!nw+| =or[]75)(]h %vT|@4p׭j &GwZ wK[lz*Bۑׇ{U]sl{;{C *xmCp҆_'z 0|04c̛O֍-/Lq.DQ=wc7O Yhď Z$c<a.YS+3 ~?֙ZhQ UH+ǹl ? LsVmbwCIϵ3F}Y P;Ən46OZ*O;> !Q)q S1QĚR=؜m,+Ԣhy!Es2\:ٕ9:_#<%OG]}J(^YV¤rJPd`c"qn *XNu )hGW7yG;^Zc{{}P(V t`FtR'1 T6G&vo5`F[pQ"a狂 vܮAz:#3jL'Y+En6 右0\ TM9-׎OcebZ6rwz$~ܓ[`yRty]AYN~'mNV_Z+9+ʴfC38ӳAB;!Ͻ)ڜ9Ŷ(_%${Ec1oKWS8`@ZnjpE-Þ(7w %eYܿGPƞw M]PDtfYeRQ^d郗phv miQuA3ԓnʺTY/D)xÕZ~cAGWxg9鱌R[IcgaMxyWeOyNS^)ZUЦAx鸘I3dXC0z Z$YDZ'.CAHghIX:vorcƕ5XdFӞ[7*SAXq94bfCJЛ_ef)7s.RzWTP<(9LC 4ML"{FDp-_jp]#gΑ.iNY8&>MwT U,=* ޯJaif>x!aDPGD؋$9vq)v`f8z?Ds x]+v6ijmU2ݮsJ9m;䳅itq$9)K´S t&]jy)Y2٬^OOnU"J8 ;]tg6 1)PiXFE9ŠGG V_]}H ?(\-']G7Ԝ29`w^fgiXIOA5!G]rns"/` dZx͘PUAܔ=iK5{I3PxE %2~Gg NLnm+Z$,+ɜKeRBzeM|M 5؋htR2iY4ԧnfҋA7/ IME;#}*Hk{H@?` ķrcgKPPGd3@5kXm 33nM:~9⼛B$J܏Sh́̈&Vfcu "'VҕmI|Xޮsh0p&hYRX-X72Uܸ0%T%@HҦlň8!#O63ҚZ $X U`^OOͩRtK2vh~x׾|96g1;?MW!OU|[/zïvK{|j "K56h&UDhOz|dF%5h-7Iiy̕2KU XV)U~rLBx}!} D=r\o6Q/b{B쪠'ꥄ[BS`ȵ  ٫T֡Cע~|]Ys!L=0kT ֯7x\ESg6[㠪$:T2g V/ @`ntaY}kk] Ht $H"w =K+Par=x- ȶje\n1 np=ʋgDtWao `CF#aNS6FV Q'T8e9*PϿ&H 2({> }NiYcUP#0ĩ1n{qʦ%f JF"6u$DLS:q}MY:Jl^:|pDn@{wk!\@Y Vgٶ΄#n}g+L7d&[{adGvR2!vWW-҄#m)J WݮCpCm@"`ѫ؄E $LFy*_4Kx+ :{gURϾ9A΄N7 1ud[%ol<,pl;JSy]Kq$Q/#>)c'϶p#H<ܐ@ b*ˆ5 g%Uט~}IF[pc{9*\jβ%ery94Sǔ@{xVM׫5Cp%CY9c /[#IS k'7Z;*2dȕ7kǑOt]!Ib^Wl N1L4$kwşVҏZTEy~AF`)_hK"[[w0 |r8q0'{R0n|x^II0%$厔!9)LKaos[zc6{M${zEn-P6f|Z e BY|i{Ik:3;זj>cP0TZwJj1Z\sߊ4R5R* n- o; .HSX'A^d`'X; BLmۦ~e]aJ$7s.FciL*# uz}o 4hR=8f,g9>_#e  CH>!(!-T ޡo9Z"|T)a5d''R-K;h`'h41]W^z؇StS-RFƘ~;J㼧\[Y{8=1b#2NMj3>` Xp ']؉ID\9iݝk\@(0Yl,3 9)X~:{FE/9p`a-;$fucg>bVhkXʮ`-iEKI(Zskz+OA5[o&G `GY""R8F/ wll?wd1KD|SmJ]A@xwusN3thn\#/w62]Su&P՛)+bXQêWkS`"&#D>[%H)r]WC|֚dtTɫϱe>j%c*Oq{W@+>A8!|*e*i˞-jhOI_(ɣ"IAu IDq`M"0!lxI^I~52o*vmI-Y8Sk;04]Pr3sOtu(.exsax)4`z<"".\\ o>A!d[t99A-8 4%A\WDc$-skpӁzEÄ(' ]yv~<8j5lnRpfTBR~ͭ 4 -+Rҗy\ڠfǥ#]8m:0+e7]kUDCMz՛~ȕ\ǒ,f7M Oh']nCSA]yK>~}' ,;Yr2y,.jCeQ/P|-Y|ҋG^Y$յ2~g)!iGj;83' 0Of<6La0p倰uDqn|5!qfRk<պvʢ\A'Br2x5"^ATSԵ'+0t)y@iUmC=6gb=,&a/Z!M @HBb*0o.\69+}4z{"E|B3c8;x Ei=tX'+[ڛ{ BRI 䚊L0#>4B2}:B1x2ơ[lV X"Md:' fi{Wud^i`!ُpe"lz*/uLRG5ӜqP#ܢE:Ē)VBFGU3"7v`x51Ѽiؤ+Ҵg#-R+ ]X?HqtLsN-&6_jGҼk1=J1΅f Ǧw,)A.JOkk/-;XgEqш"Z”2VV7< g9'ĭ40Eq/HDBt rZ#r_}mZlN9X#JH1ؑ=5- l*-Z?]+Jå$6ʙ>Jk9/G֝0d@7},O;ɿ(-]8N#+KUXiW⸀m4]bˠz-'w^```L@ Q(]^{zt2fsPOȫ`4eZHJ9̟˒A"Jt2[U|nw_@$V(޴5/| mQFܧVr#ͩ\B(i%7=4;l̡ΦT]~LEQn ,ϊij6\yq>eS:^rȹ87nO`~9 g[mD;`Mc~p0"WAYJɉ:9 :6 KmkAq`1TB8?m`u3kB XaJ6dnSwGi\xɹj뫝yD)5h1Gj(# `32Jݔ$y_ߚj;6z/`?/C{ ^d:PY@1~LN/.ˢ?節- Y}eR^% ݔ9L{Nѣ`[QǴ< m)Cߵ2"7hRLe˗@QWj W܂ L h\FlؤFG~*9*lV) nJ,X$]@ nWB/'<`]w07{۶G,`:04e:X-'5(!MF~|7&&^VM2l,D nۦS,O_C{k)E cD~AQp ;3-@HIVx޽uIa0IB֛X{Үc$Bh+ɖG!w6> Q ڛh'De2@C(Z`mR7G?nThN^-VF)piqkVszWQ'^,s\:p}kC*V3M")||빃ޞi$Oq4ӁWjdCqFb:M{3EJ"z>L' ՝yø[C֝[ k\˜,hȹ,E:x֞Ws@\HG#]uwXۢZL~c,@ꥈu}p*oeѮq>7/#w[\dJn~k"wn?=_QBrMysG#0ת,:Ϙ `ľp-ewkө!c񑶂]q3 o,I݊'%HG 8O.ȫE'rQK&)[(|QXScn54B/\VGjdѯ;4>ex(A ^ ,hwX+<\,vӽ̿Paո}tj/8}MuOk*5,2$ ى3^\ȳJ7T‰-3%%"8P>aF-̺%yYug=Qˤe<,٦'v\ R(I J[H-pj` {+rqJu1"a hΌ=:Pe1S1qLKMk?:/P+U|صX1fgܡ/' F<~[țJ,nM,322m6(p4c&v?.9#sJrSs\V [a]jiU6wCpjC1GQ>U.2YUi}1b!39ā%<jAI@f6 kw(V t%7 8T#]QoCN{ cfy ȷ }^-0?_-slle1 pmAð(ۊ`;wإű[T4%TU);#6h'QkpzHp V[]-\QIɡ ĪqS}cy 3r5Bנ9vJ@h?%#aw33_8Ybp,a?0mvԇ().e$Std~pTJS~?)K^Γ0jFz3~sX*(6K8|㛠_O*]\ls1xf'fv'+wM,19P'#8y" ab~$u:yǖ#F)'*B.H۾ACfqQ_2} ~ӡϝmcyP/Jy,dGiiU->98b8VZK#&_Eej ,zaܖX߉tbMR 4`|߭8 ).D}L?x%HHd;\a|~.a?wyǶ0"@B 8%*0ڔ1q0H] qڻHtS:PG%K݄L6W9~-%3ߐ|zt%JI4VP+4!A7lI˚.m:*ۊef3pbq/t "]NƇv!S4 -@zUNݠ2NOf@XlV`O>.t.TY,?| GEI %> i$d/ {">|IZ|4 ng˛N*\"I`W89{Ndn#L5<-|^onܑ\*Sb-䡿ټHf2+7u/)BXmqCW8Ʉa_좠|nx9rx- ̟blm4ΏO;Ҷ0uP]B_v'Yd+X' .n5,,<@$vl|V#&9!,D7 u"Xb _G{Hs8h)濥DGQ7QgORTJܗH iPBk5sǹt\Ϝ:,a}ɸ>%tar46!>)bu^|PIGV읐dvJ1 ŽͮGkih!z]Ӏv]y~2Ezg? ;xߝ#[GxjŔTL@@݈Q@O6_ :t><&7־ڜD絊1'_-܊6ۼ2õո0Vo{|H?GsXǸ0YX;:q:" ­5 o\K:[oѶ>%Of]~fӧ0a+b&pFd~xp:_;ItSW>#Ƈ@j.03 Q(s<$,༰J dJd va4ЮQNPc0'ċw X/?_ǾwQn“rSuubsc00;)*fcch4KnM. XD&@hTk)M,藩R+,FK3RL{Y,Ђ[{ }tȶ-):kQ,7fpoԯfTowE@n9ӷuKH^::eMDg|[88!XFS}=[O9:$$"fpRG/ {OgŸAk6teQ(M n0 -ôM#g*1GY`EyKV`kRɢ>wfRm]o ^@.j&C}V\|(9%آ_GFbiz>(,5? n2HFEHݎ0-OR=t[fQ`I.ِ}|Kr^9x!հ. 4j1eq„U՝Z_r)ҐfZקu}>sӡBlY.V,%6gRF`8c-y+9~^:,ңU/<6D|mVp9PYٰml lٵOϊxRƓMa6p-{IטDN^6ˢk =C'O0h=])Stl*p;W̌!L~F4Dž^@?lO.OtU4g$G( Hol[&FІo Vkb*9 2N܇#Fv(HH e(;^v#Kiy9X]T+|}F?=h2x1&tdŕJp6 dsfΝjpᮁg(Վ5=DbGMDuɊ KaKu A֬g#+\hO- DM lلgDP}M:OuCȆ~?.ꀁXԙ2\1V=nԣ36 wGP ɡ#j#XyDm"-dv}Z^ ʪvP@-&5@Fzh#NLvGto9Y !nŽğ, epo)칽$ ۡȺB1xfM06L;_ک24' ؋u;uzYV0&`΍ Sۦ|zIrPg|S{EX:sÃϣ1^q~'FpH*"y{ð̠*> ' cI1_%A=2p|/gola{&-սJV*D*pT-Yb3a FAt0QVێ&:5Eᬹk k :GƆL]{o Rb\q!Q8?Fk|G36*hLo|3HQ\%xwMbOM<--VEknB'}MBvv92 RՠZ = j̕nwxCMݼs7#5R2|i 7BN)Տ'm%|ȳ8.`tgh5rUWv}l_:7Z 7U Ow_?Td+$89|͌WXe xz@_ri@HK˧95R(>2*L h:}E=OC$N׿٠Z%)h¾>D^P jɬ:(z/bFOѻaQe"uF %LvM5[ogl21r~J8' ;l2zgV&q3sZVaM{7Kgu0=4Ѐ=zIKޒdћZI&=6?fP~]XT&0;ifZ$<\ֵA.UNcc߉wyfeZAS﫸Kd0"ᅵ5ԮKDL "2oٿ)!T]Dy^ J5 9OH:I.v'D 'ˆsXO,2|7|~8ZEs)@tcB: v*u(I3:Q 53p(iKu[yNBיR8Ut+MU`i۫Ait퍄m$+Y6f24?./9Wԅcy XSMM$6x5x ͜䤁$U5xJNv]D=铰{|KޡΎOCyZ^Aկx N ).)q 24>L?/i-&e5e|F_EӹkaǩQ" xxij H\ݾ H@v<*b;g[l4z;kbG *}Pœ*pl҉mluY+ }/L2+>%)k 0Ro@0/sEpv08"N/{ 4'^I-a{A3 `|pSucR6zmy:S8e:7g%L^QQ:#x<[d#2v"p|ns R|HI/ECjK%hʿS8D\ޏдyX\t䭴?@qtx{-˂Bu*<1gEa( Sg51 DwL#crAn+P10TEc]ѝ]lf<ݚqu); uw{P+]oՁy>[x NZm !?%\8aӀv5؛I*?ߪnl;^>#CVչޛ& lktx>T-m]py zZ~^I(LTE\u"q+M0TR/A#†VE4{ g[VXEl;+|Nũ;j8>o/t|>Ax4ųfNӳ)6!"ᐦUTˊi=NJ  zӛ hW4M}_Y۽TIW}x"m/ "9>oc?B2T皘 kR㞽 ReeT/d&RтmB.$QǁxK>2]v|>\o)[fЙ5? j+Xyzm%]xJR0H\NOWG8H q=9w(!B[˽n}UVY~gӶG\n:S!t=ɦ@ SEXZAjfG^/bm  XS%au5eWqr.+"&K;b}, }ۻYNJޡ粰Pt8m=-v}a.bFRYISIY-iA%[|D"1@mJj~GnНF5}8,hw5Q&zD}]}9w7@o EZ\M)Ҭn8k>%/= s#iV*z Pɴ\>K7mlЙRM kr=bץZz u$L2*B~p8aKCG>@K 0ƓHJ$s7}w[j"|Aըx u):fswRˡ(D3š-J7Y49}[1eVRY#1iGvۗ]) ̡[7l nPͤʪ/4o;5s),tz:IrЭϒԛrtDp(CKٸ,h:mWj4W}Rr;ޗYF7 o$P"?trjQᩈw@KTc.= >')!&Tm`*&uѣiq2o6gXhyR]AZF,>e:lͯpI\apmu&ttCrE">)`ļQ;㔛LW PŦjjW^{u4yelR5;g'HBǸɳlˆddm:,VⳕTzoF Jϸ:jArU(mEcK`Ti!]_ݣ7׏$geJ1M@pD:^_>-VRm R1dm Y83n뻺C0IΈ[9~~h`?Bf)\c+v PGzGm &5lX; ᬩ߁u4,vNY6O2+\~#brʲOa7_Ef& ߠ66=s&!?Kɠ3fT?TG|I/:1 }ٖeaoٟEˮW'G姗-۴$o+27`M}7@ ~k(NY(eקe"qӟX3JTw"۟Ɛ9#kaLtCk|VƆX<}Gpn@8h7A\i_CJ1WHNLiubqD^i6ioi"m n#[Ɠia4y('MmLtxDg/Q-V:0'Da*)ӝnT_TgW!V`YܖU1T/ej? gzYt34 16"Z&7ZJ^0Z0ڥFYQ"bZ+RdBZ^WD'L8oyBHɄR< U3]I.{؋F-j4 vAIu?'H}k:Fg>hzX76G;RetlUp3o10idG ?]~۱e(#!m`BaBtCq8tQ?{0au$6l;DoJt/sO٨KiSFllpbu*lۃI [5D 0!lA&UrפXStMf[A"I70iuAwRk8"l* {5Hy_-V*Vs`㽿@-v+' sotиhzN%Y!2T=Zy֪S;uW7‡&,Krq@H on/a*/W|c'E*;k^}2i▢ y= p{2z Ijajj9f<ޏC 554t?2 JH:> DG__(L*VRDz`ٲ6)W촻E;Pv3StZ `s-&>r)̄jq 3Y7N: mIa]2Bol_c5`c(+%f! Qyҁ SfoƭgC<=%ЄvP |Ľ-Gm }ގV"˙>3BeLGfz~]8IMIS -;"HJ 4LP2WX c&6HXlYRDf$0R %KWH$S@|ׂ s -\;%yrH[(w8"ϥ74.SY/nx۾+wGhu&)7040w d<“) T$?wfzJ^F+<᫪g zȼƶvK ~51_]c:?<ẻMZNdHf vE <Ӂ Jъ9-H{G ɉK=`J Īch){YVd+R҂ூ'.nK'#FtQe CR7e Nc(I*^Mt! w%_ lEOHj[sZb1?eHK5IM:O\3$Xx. Y>נA=4_&cg׹ xuzr>9/j nc"w1םͳBKn}NrKHi}y_:F/mil_<̚4G4v);-mO[D\uޛK).&6߉w+4-A&I0E 4YRǼzwcszWE~a4r,68 Q\|BFX93pp:FHyuh ́M>C(ÅfXŎ 5p_k@Zc샐~ ^w&# ci|coOQ/~zW0]zrXC #IzG>x&Oxb&~ji0Zz[̮ڔDz4dDvN%qf~t'WX;&T Љט=h>Ǚ z6TP1&"@Zq0(6JRR,d; v=(,Z0y;}I90 |Z]ʈ1uk:)`rh8^7ԧ#ՖʭlbٞYۑs§>@/_rMmY(LY3%l/lJ܉+-Qc}oF;$ۨY߹p !޹C: oAƆ3T0Hb.jPjfR=u)m3>(1#2,xq^fc(4x"]*^N-Nl][0뵡D̖pUuL;i%n[ úB{lC%AuuY{$U TU\`P1gW9n38՛b" h{5ܨ[YO:F6<&+`BlB/JU$~qxwBIߣF3zIszL_hSk&oDzu5rAw)(TΨgI_@zMҌ .Ym:Ե-wֶɆe0+3d25 @j =$|,h2 zo`;n=Ζy^WWI;=t+XAc S$ޱ$=XIT@~.RO`hвuh` '}B9^ȕ=F-G:=hq H+/MD⫘vd7 &xm9e;Qp$Z_h" 7Ygx2xX]*Ib9x~#igƻW-̲{aO;8 T?P0h(\y:P& ,њ~!J(0.&ԵFT!RY]EVtKO6d]lhK?JS6)-=V1;YGuF pCh}xɪxPK6&صyn.S&=R549)`h'TIb.*P[fn{뎸Kt Z.d`Q $VGهL*j~9.*T9azfjL)[ү_P#F_8AV1=*Kjp7}gXC/E_YAD06@ e {vPk-S0%#J]oTyR!wځMRt1*A`V] K3Û5 !-.C kCrD q[|'vv5P eXE,Dсƕk/!@vY.O?K3#k >޲\HMW(!BFFd eiU$&t@ @Ɵy`\:AWP ~x%ֆgrS0;)שN3'Vfwx26Dzf @GU1L"E4R|QZ7F}6 '݌gB.tutP y3^l{2OyȇE2^$Avn8F'?z)1ل bS+jjnoo݉_; H2w$3:<X3K>hX~:6_'@İKtcvhQ^=E *Km>b9AIiL*[F!"ZJobm8RWUGK7&fTwo|yCTO'K X՜ L*efLx !k/(-tx@rAG힄:]>dߩ&gXȴnr'*r1<Rs( S/8bzڒN"gZ'Jp-/&SG2M|kA7npF-e!ϼ/Ob P r uQ'G)9y.t *e0ÚG.\6*"%a z2Fu.tV aXS3[,ss&3ގ9ԧ?O.}k2ep^Ez( V;'! RJQ>$!n)^Wy9!QTd)CgG'" 9yIJ0A"ZY0!bJh ?rc'U1( Dđly߂Vd_ hoP\q!oV ޓA>Wy:Z,.=Q!N_;#B:؍2&g';XJ')h51Ry.-+ð;<Wsu3DѧnaVKV2>t^3Nxisꩺ(3z1w`>u4Ԣ@cs$)(4xcV*{xE_nhvLv%t ywq,s)VY`Ǭ8 (ZZ~<凞dl?gB!}(i(3sҕB`enh%;ҶWSN΄&#Ⱥ&T[pOim#B4ԁY aB cf_H CD5f0R_^@${0i|1a݃B(FrX<:x C$Y@/@-;bNvT"y)eWa&c i>E^Jf|C{zi/Qedԗ}ǟyɰBݤ-0I6^M=*i*eax#,%̸x/؇UK)G+QCK'O3t(q[ r0 LwL)͛ ˜ʟ)42/[;r[9U5| HAF?S[Ӷn,/.aܚW7g?pkԗQPJ RԲV?UQVgؼT ͖fbFL e] A͂['$VMV *aEPq<jZK3*ggPFrE*O25\G>9{ST>1XH$+ !,>KX dXʓ^Cû}2ݙ'HA\h !XHKF&Q$Fi6Ԣ H7?J"nqdB?* |V 3^i9jJݠ (a,;?ȋHeA+sw!!`v-?5l勁%.Jq8oǒH"+k:pYy5A&|dTFjŢ ?X:lfJkTQ<.}"d>C|WZᐓ7k^}p`)!oy[me7Vt(諣$8@ Y eBj0'F_*8{F/*EYG<I}rsb & WFpl~^hjeͣƋ0is@ ݱ6"LQ0\W=C<5.PQ1Ò9dd'oA.-unK2l.0 } ]ɁAm/,X `@CjϦ]1λ; `K񫐮:a.EUKܹ{tOpVK*8防@9z}dFFӛaaSARtDxk yۨsw`> 59(G+IS'1$P [|Sx{i4oh*DW7Ի/k8a(ϖT5l wVu5em`JvÄN8DG!*kT$I%MvbJZtQImNJ"ṠjDӈ+&o ^1Wqܽ0*f[0y ~'x#0z@C(kx-tZY/~aԍցҰC5) lH]1:-r~H,m9Jpq o浑&#n)Z vf޸{ZӐuy:|2{M65nZgIoڑY%Ok.<]rLlwe-&i0/ʎi'YDŐ=0-B9kU>ј*ȍ\XSg ) 4bt$w5d>1]+TX1dlh\xzļ 0)q r6<+<+nu{Bj%x;oxٹ_ˍݑњYr~qX noj%ѰZf( L-ͽů5_RF:fOz4ޥJDpD DO rU@u8fҽ:N:P-AcOکa.0l<揼w!59ogWCaH b8GV9V♼: YI[اZzTሽNs^~ .Y(zw@yi,[Ø S,xnz\ga|uǝzcjzb>F?8h 2p+>Y:= NJ>3C!O-;:ŝ3 *5e?}z@WjQY=GӺg񌪝~Ya[$KL{|'ZsI^z!yflzֻp/& @r +MD "dÜtvJq'O5y3.U*]fjGWo}TZ*2!nEDnj gH#YK9alB7[ef=D iC dy;Tc1buĉBn2|yv;yGcS8K ʦqtH,#N Ӣ%aޯ@=fHN7W H]k-?4ы8JCvk;ټgh;{0ˬϵִ;`2Wl#I.GΊG!=OlR2{O& BylH3P0KXn|@fB%l`=)jU +|i>Qe'hؗBJP)Sʥk,ǹQ][=7MAiz%<밢G+ֻs3J)m$/utͪ ErlbcE`yoi |vݦ;.yBzEQ  a,}vr)+B Qx= ~GX#z`ksЃ/I\>աeTrd&5vg%sbix1ĹPͥEaD%C﷕CNbЬ#̞/5ijx.߃ ! zBw6h9O~Z-_#zH)o}eknAA֛ Vh^Q:":wbv 9A$1 *} Тw~JwKGy*iOR8+0D3F JWHAZA,67թVOM'Γ{jy tcÛtM5([RY 1C_. |!=5(Z$au&d-pcS\'unsTtz Sx XPTn ?/iժ2c8{A]!b3#[|SJ=^]%o_e/dRf(GLK.ҋRp5;޸i髡3 F_F[8X L=yJQ}3oˉ!Ll [EƩ[R̕h]h:w' M#k{.=̲0wpA^'0Cf|L\:تi ڿfr *~Pxq ݚojIppwಢ/zjEsXګ;Xu.% WuG}g5MZ.'݉<{+v7\%EZr t R.-8rE`Uk'e$e1tn^ж HElΛH93q|9d#,"XcwE!;*3fq)i>'x Ŭ)kLh)$icIeق BsD;9pÃs2̒:coNKAh8[&@1D&B ԍA%ܯQ <0+ɗ |BW}~ ƵZbj' Lj4w=c[8`fYð86A>IM7KW|ڇbW< f:!Sn nE Y @r }'<7+AGA Ũgm4O5͓@/#?\GѠЀ6:˳!W^i}UaPMyEAƢNvE#Bd a~K:#UtFvlNIhy߀U `QH|OkH(x|J"zfMakn~p~#$ PrӟFl6% ̑}Tp5k<#@8 >MK'-~o1UI]@l .xw:jEY&z_ΈaUgf,#yn%P ccp3?LsUq{,TvXMHP0.iO*1ᇄ" e 'NjDeIjr7ݯx-$Wecli/D؋|)B}pԡ}j1YP{0Oȷ>NG8H{ef> $ ANuAT;*P0/vʊ>n;RRƢ6Hw{5 a9"*w%ޒQ#gL&`GC@ ?ᐞֈ Bkx|<ϑ W:b: sUATV=8*TPU>߾uQ kcy=>! %_CH?Jr~Y +:X jDzWJ*Dzzjnv=^b)׮|Þm͖r,rT6E6JYd\.^1CJCufH⭎p;lx1 {%,4]<=앒8"rIЇjiF +za!B7vV%닯jc0Lceu@f,=9VM^ʥYPS2<0b@Y-@Ne(if(Q{p.ăzGI56󠵖˫**їP XUH% "aIksVm"]WjRNs:aƘG7'xEunV1c1^C$A!5ܮRfo!_fQ &>lؚ!R/ԔXV#lV٘{_\~yS7z1=a?QIPC;Um% SL t20qs-qBX'WXI.S,gc9B]Yz?|c d#gy3>uLXYȈ 'ehZ),iS/xs m^&ǂ顆Р!^;sN_羪=ߋM&YxKjI<^QʼYk|fy1Sh$|D}{ZN[} p984WY ]`n'7,jiwhF,yrQ%\ B{ q-4Bϧ`[MUt6K><jz &`1xB~W7" {5SPv XgZTqUKμvڧbp90-%!H+OŔ 4)yѸ-_bHnDG[*P1I\H)yZ4DSu*4; jv(v(3r?#ʬJa9ILAYFy%T?qL'x\۰8A 應fseˬi*.2tf04RN S/mlRy{hKu sArRFïP]*}܎)>F:bF/XE?<$6ɡ*丕fB46Qy8vP:!oڷ#)3M⿨('y͉~UX% I_: 8b`F>uhZ'E_ #H\3d\xFǢ1)H1#~)Bj0B"0l4G)}:*-P_Q R[vmD/_C ]r=1~+@+%; Z -B0=.`O}ύT0 qxlGjTRf- g$Hr#1K fn[ܓJZ,9ZnžVNU]qȫu7WBoOP$k:Lw+|,rG±iciNJ v2['`@*CY 4dQϵZI^W&aOI8 ;:ܯ]LL&,uzW~;F#U ى)gx?CX\.>eg(h {j,rCIۗ2VYx|h鞋ctݕb@Ɯ8~,ɨC[ߧ[ÉG9E܌]gfŻ\ĠZyL"ϿWďHqoi }&,-/ k}Y&b匧ftiZLv {!d԰6%q`:6-fɤ =:..@B#vi}Zn⻵ eHhZ[HF΃_̼&<Ǎ?0Ud^]uwH{P?Pk;}'Ll0b j< _z n`E:oqkeC芎P5\2h*u6Hek~|h$=%x-KuaI~gDlP^(.my9:ylfiFn5Dw$CeUŋ ݣ'QK_a @Hhv zKgA^Fm_!}BV r rkl yK"Ƣ@OtҪ)cDPpL=f[0tO5B=/Rv0\Ș2HVvp{@K%!!Ae"&Sdv j,KFDKX׶\# g[s'&7F/Qvۄ -ɦT i (вIG9-҉ǣfYGu!y"27hߋ5F H9N r *Jqa i57П/ƮJD. 8ޔW :׸jV1`%P:.@~*1OID ^ki,7Wlro۵(WTɵi֫t+V\IY62du$0fd'j T307ve0ZS48~D0zQDmW"\4"ARNWyu~ /)c1}MErѹ[8S&]I 󩮵wNm/eqt52}SV7ˌOQt`^>#4wlx =rL GE^hξ4B$UN{yVK>ݛ4܎8:[bbou_9BսQ_c 9aa#TEt_F =B9-4''ym4~SRxJh1F'W4 ir{D a4_;{]ݺOBP-!Jdkuf{Rr&σ*3C0%fe:6mYW,:3gʛi@o76[lOܙOmϙTIGШ\sy{2W ޜd~CX+"sB>،+qN>4yo"U @GVת~h ]sG¹ ={t&x_["H-KN0tdF<ƕ)~SSq&cJ0 o/ݙ!^vUqC5e8 |:4/%Y*TּHwd[~mT!St*qX7>Y>jю#J3IF*P'R3'w$+]O_o4=ϙy*\'̰n!Jx^a: {x*hb{d*cxHy­l's\(1%D(,Hl:dVJ0pqB'&{ۙŜ {zZmVR 1]B=1!^R]PۧF?;2]EsLK@J1h,r(WGc(9-XdNU zZhJo28`&1ꏚ؄rFyO0cjxS#Gny#cA}RJKu@m7JrVd'1T}fơ#9 sGp}s= i[,x&M]`EMSMN<[0g" &w u$^$m'dMmOEQL!\[vnCWQ q9xR2h5smwWwmpEr2]SEBiSxvT4watx1!蒆J$pL69BSg[^0 \~8q m֔tbY- ɾ;#Y@F"ߠTkw:U}8J܁^ę=NPjt+kEp?ٰ h^G_AJ hB AQvm?a]ڂ.4>:6%Vl'j:Blb2 TMOr{QN[};7=igMbBnh4w }7YaߌYŢN3H6WFsnwۭ\c58n o5/&*i?~' ė4# R쥀 {rk1ՌHIίGm Oif939&u9O7F' o] 䢙2Ѵ$^ͫBL~5,gtHfH'L pO]lDK胊Dփu1-y[b/M&@LʼnRgS,nqdm B4bbSmz $ԗ(ፈw;;3BF%\|1Eޱ\'חp.x~cq*=d2^KEyYMeg"*:TEۤ2ys2Dsoۋ,8 (M& u&>@t OgdkۜPkv)Ǧ^iSNPlT'G͆'Pvp;W7$O7*)P8j]a}CplXCస+O6`OS7RvHc67.{<01!*/\^|!;wYDsy~5D5cL 9Hfy=L|T%J]gjx7tSa$O%~if=Hӣh@aЙ}wpj}8&CPkz{'H03sW(SOjw3# 8⛋ ~"Dɲ;%0q|}mz0x=CAHHކ RMz.0ɣ*ȅ5ڠ n4wŇ:VJ!i ڷ\YBX`%h#pgc6ëPA|ODN̪ aЎVh؟9ożF< +)W=jxD8OU@,_)"y zEzV5()M>w ϳRsYg1ؖV D즽ui)U21a|7:DxIJܶJ'Lhp;*2<Ok6C,R ܚZEX-Rdnu6板=AE-_H76d2O9hFJy^aFA@{so72QUSk_dae[,_s4?0 d&pHIqsG?Էc MM6ޝ9׆~T!1'ڊϡ0z ; S6tVw!UW^kߠCIhIReթ{3f:5ܑ tvLglq^9򯋣ͯlPM RV(N>!Ax@UX IL7":;@9ժҢҘbV . x=&ɐ^RzHh Q0DMpD»~`[%[ N 8rSrW ->nP8LDeDX!Fw{W9D^7y!޺'W-VLqfprR # FBAX)I[*鶈2:[Z륳)Ͼ`D~_uz>#XnX L)_r/$؞%?|\LޘVgě]T:q^u;Xؿ=)ll 2Z5tx{=3F(ļ bXc< қXLu܌.''%Snj!jM=^ (yL1nmFع96Y3B{>B;ծV=pCCg=[H̛?E J^ID$e` Я̫MF-ފF[R4s qRN8J;d9(tmavܾ֡( ղY\ΕJ;S|ܐ RyLAIyH]#vKe')N]tFxQ~N<+MWﶎx Z>Q P_PUOVI{ݬZJJb_iB\$k`P} ?%sUpbXqIHUUG֞ڨJ!dڡ ]^L^CNc鄡BȴB6fc}.[sjHQnD6Dڢ8g_d /K2U\ ^:'Mg՚&e<>f n:bR>rtvQ /{k콰ߓڻa?nxvˇT4\rB)aޏFW (2HueH.is;3L~86sQt lhJ- ,QiIϓIZVK9d6ggMKƮkՖZ%}(c0-ʢ;7a_s :ӋJ`KKf[n-,%(`}12wkڳqSyw<Э54>s"x_{d?Gq/crzZ@D<; *ck~N<>)ix9=+I8=t5jUi>cUWU@P?%no 3~]ђ ].mt[ >x޻V3lw44$|xXKamN]:{ҎȦfre8 o`:\gÕͪdqSq4y!1R!d#*,>8F5B6!G_OMŨ,h2-Ղ3Zqތ^2jxmxغt0=ϛ_М@so|(k/.e# <DOm~72{VWBWlkzZ $-v2[kLsӯŌR֘)L9󞗏[A_*\vDX$/k?? ykn1ekCw6,C ?} bK2=7Q,qbFO]3;*:V/9rg9vAF;oOn!d?YWv@&tX 3Yy{DžRD4 u7b"f  V^L}lx*?=KtCaX 4\T c0 `h"uiWd"B=u=UɖDM G_\i@X/B}ҾQw]j0*} [BF(Zd Zߍ\Z>ޖp:8g5uY=h* }a:dGKy95!s1JQ&`t] o5Z>s"ܗr]HBJԭ>=9jwxq""|ɏw? ϻ >6^JƺfYPOβv;[4,CoEV 2DN} !6Ji' JjZTS-ӽL.TEPcr_ɄNTM"_R3NUW9VRѨl)F4Y*pjInS +w\,dIQ{72vr#Ǧ>>p7w hϜ:c.$[F洃~~ ma)B"Ê^E7gx5*Nhnϡd>ʴjn 5!^U]4;/AQ;f4]L]ȊiZfm'` ٴoI4nm=fabt1n!@vjHxJ  JM0F5ڰ\EPyOU\3$<H~g|I,C7pbLnt v`bʢk^@wJB4 :î''"糃Og џ]Fxx+VΕ`?mq.&6Rےd~YT̍>຦Sġ)%TM]Xf)aZx:kӈԪؐ/(5I!}mF2gS'HF!'لW`kHؿT$aܜ2-5W#Ќ/x@1Hf1]'ʝ: Sc%*Q='3Kf>Q{`@@ z0~- lRd& #y l9b>Uedbk׬܏Wf%yUxFZy3zXOe1A؈yᚼ(tZrp'zey8T~aP]v-?;Bv,5~zߦ1+[kZ!|W!~h3ى<<l,#K1;&nƧ ؓQÆ CS׷&pd/Z j ~nw{~ .TBlD%YF2Of?6XpSWg"7=GdJ`!e@_k<^kE?;Tq{6\X.ͰQ6VK&hXF >5M_5c@~4z+)T8;%׋jbˏ‚2;CbؤVkcZ]`6)cWi QZH/Bg9ơPLឝڐy .F\h HRI7lP )O]e-Fx*t5x֤jǨíH\Z 3:vi]ꀈ8 &p ۈ),5,c|*^s'dŬpXЀq|τ{丆rW Rh6w֙ R R‘Ws~RM1UXd°".!BJþ!;g^XwC8uPaD^1"gT@F !Fv#R,/8tl7yިV(#yixjMwż&2DR6ίO8J4n9XFP;/_z 8k9B(@lsnAaB їi M)T&;&R0ajea'Dj}8`ġ,m6MێZ)\[SGM'dYCÄ=n&’Yo[2)r.^|G0Xt}V! S߯*D#[85۔+^:+*⊥e{)[ ߆=7Qմ"}Zy oy*j1xG!*eJ!L撖 Ҵ83IwF(amWz7"ĩ =UYJ~ATuKIFy{^Y6iqXiCUQ}XY;HV__/oc*t ~cPLxHp#T}k@MK7ܵ}8 727MĎ9E5Ӓ_`8Ў;çU}uSv4l]Tw0G%&576PݪBdNF/-B(+_}. $W5\yK2*!ήk ]ˎrgǑIe j)Bv4( <!}Ҵ"j2#d ;k6< 6EΛKÃwS=UDWR@],N *ӿ4[ A*6:`*fqt@VN0- 6 L"_Qxx\>AV,;ƫO\n$x-!uBknPKèu}Up|=p0'fUJ?.r _5K[ux/e-T? UY+qI#x 5P_VR%BQKШZWˆ 5HXk+oFm"$ ~"DU-I_6Ruaâ97)]&I6K^Zmb2do \'Gᩋ K']xg~B1GHBZ'}9jFIgh~BC=~+!E@>kjc1"rf޾wUGՀ2޳!RP_[׍C?+쉿9k5fP XdL$򛴿ҰSO$mw}jzۈn: >H#%trPI)EYx^l/ٷzf7آy ͬ2L=&dv;KbN,%$Af{59pKԀYEtU.W_[1 ;J^ܞ;_+ G*"43! 9"Y+^m %,`Sigܤ1:֩&_zkDh`˺IOSr$-7laAO[ӷwe8)ҁe;l.=s^8cLN/` ?I6o+AzdM=DSB՘cRneD'u\}ѵZS\@لj ,>|8FD':#KevqmUF7N8n-g QFrʰ-łxGipt+yu+ET_mC[.2MZa wFZ_ZT$UћY<'#]WVIB H4^mrG% yuHUZNF8LDP=08oօfo&n GN¾@1xb6ā13_ۣeǐ6QR7VnJpr6{>t`d kPru*R;.pbMQo(lkJF'T2S#Ca5F{`sXAFjqi"ʊrn6ZEC|:ޢ;NkF =Ŝf.q1p`2 ylM^zRB3cMO bٌ J8pJWȤQhЀU7aEqo.ZF98Tޓѫ.́t\ʲZKB@Amb10x~ Ծ{(mn;Րj7I}cgXLCGz2ّ? bcf)ikr޾0kb ziE5fHCs&"c .lQOL_v>hۮZ-iH^FkWq1\?%+6*v̲Wr7Ԩ)9sި$`9v-> )DLh8NԌAځ^(M|A%,1 v58%Ca*/*Ypv`5J,Fl[DS zf8I1IH+u6:+f:0S&.s>P.쫖.G>X,SkTvނI抬$\U JZZ gPbb[&\p4I=6?48S݋O);*FI^dza`;FNsᡔr<7|DHOT0qzqPCR zslApͣM`rV&],M`5 {F}ݱF`Ab,"UBiw>Y3cl*kQ dRl!ޚڛrv&o J[Ix*Lφ||4tJ#!R5 o pqL%˅O/Nv i?rU**K*1fSf>T\# sd^ ]`;霔\xM,ϳ+"'xOՂ$eR Ǘ9{x͝n/?H,__eu?\|#يaCuL,N6-0 X}loucSբ/WWV}BMn9ճ-+%Ƞ?,lsO?PHa:B}A!ļ†ZK^hƥ|("R2rƜEHzvZI".~0ɐ vպKѢ0 %}Hfl*$DML1,C6ŹfURjJ}X^̪ZFftC*R^{B~EVM2ߤ^Q`h`wQ_{%$5!, >wE-)kmh=@LV[fnQ+rn $1k,$3x>4=yhdOLV=쏱Wy/Sߚ/ + eaVXQ X؋1/ N')cbsu8mJ̟?\Yq0+bJ`EPL:7maޚ~=$J iNX'GR{Т2H?5,M`Dz}䘞#\;ԅ,km& .")rv7I=Y!UW& Uǘsqj"$ 4ͬ/eM$`4 z|Ek,Zu#ɖpF*;S:)uQZ持!c'(5پ&M[CHrxl5| !ß"&$&= 3Ps%u o+^ypl+)r1&}NSw.o5`ُ$O/(2N4Ʈ6*g7Q{e9i?fϝ]&V:aqTZ;VwGq}[Ǝ?ʧ$D UTh:u%A(oKEB]9ҝ}gT߬7C X4wl[1S F&-BT3L0xn?DDn~jjZŕZ @o}8?*qb'43ىפX5{ P{#})-T[W&:VٚyE ty荕>7n!%S-쎉t--Kh'x ,B[Ʋp?Ő"d ,)Bo{,55VFV^-<a+"$'$6AKN1F]=~F:i왓R :Q/_%W>O>E@FM|sr> # upD?cAg-bs/B\N׳AoyЗ_g6SnPn/;i;U}>,47M?] \u9.7َUԪ*{9$Xrw]ŭPɺ"61DT<䎂{O E ]4|tk f7ƴ4QӚOr:|v^pJ0OL6638זqw*,f=.iAKBB:nXnZctu!\\*m`hg"'"=Ɨ+[~ bMKBW PԺ5D<b lQїᗮFzd,ENDeaG*EU}uh̆K6|Le3uofʙ;[Hud"?qО c\Qt*yhjFB3r1Y, 80CTz#6leKm F8(I>R.Ю)튪ЪnG]u̻9$h\N- 椛$`|bvǫ@-M=Nr`#=_ٞA):WG q R/WN-P a?6,W=#6# ?da p-)+W1xl-(Tqi}NvֽWvG6't y'(\Qmfz}\[t찮>h{d[T<1yЕT&T~jpu|:h@GVYșr܁ j_ 7QTnR6Z#>Wf)^]ϕwMJ c+:4Dlc }_RKZMkE7?O"|MXDͫZll}fLWn<by^NG`ɬ{.s%Vwe[y"/nOT YaxV=PBg<7Gww̔lt)i'?J9h?_*[OT/* ٤~2~~yOk~ +;ߖ?8Hy?]B_Xo&x̟d:Ts\rET~JysIYP&Q8]wnbcs־t%S~k'|o2{Bn wL^4ea8&0m CsNKC124C {,bP69.V+iu.E0Dfa~0j "HrZՎpH|tžJ]XfA8 3 wRaѵ1;|΄ T <_v0ŸʪX-dX_!51.(`vii{yܛ1H8`R:wN$d!rZ % H`(Ţ fE?e= h&q4JW.CacVՌ.V3, iXn/U6PWIeT1\$ؼv }7 _AoD۔e! cpG8Qh~N3^ҸVLTW[R&`*6_jǕ^"ouWE5M38RjBN:=Ͱs{#mlo 57ZD5ި-(WaeL3w{#n4g+:^N7u [?NK-}#Mx=oqDI9._bt(~^E ?ۓ8YvedCUɑ_͒n]B cJ*gl<}SRٳ6AP:5y {e^_;/F{B׬:qͩo8iȨ۲kɈ1i6`Zϧ?l{QJ=DLqlxBuS  Wм 2>UپM`<2gPtJwNt m#NOZwOG0L~tC&GV Pinɵܼ!qAtZ"Ԟ˶F93v}j$e[Xhj˴)ޭ.̧?y"{uO=0?% b'PU06=c 3wS,ub`- 0dGBhvc9P-ވΖ[vȾ)iPRFa_?[,Zh.ziS̳V )xyBTDG3ưIOj{Mae,j ~ yBWGz=ǭ'5g̢a?q<鵼؏z Yqޞk۰qtE5I #vL_aIm p6)<$}N<ҍNT]B.>]- 1D}`sǢ4$̱r椎y g~6W)]|i#i>_{p8* Ce^0!\%᝾MsGGZMŗ1:(~+fC?M #hoԲ!ӃIC&gURGyEcє?TQr=2.n̰I'hn%Y;M[x2a~PjmIfqq9\|h5^t0v0-XReba{X9[d4\6VAd:Kq?cZ`tw?e/2H?z=)63&|8kzm 9:cuu"hmw|[m! ӹ@v<688 HT‰gZ^=i#oq㼕W((Cpf/`MQPEW6ïD}lOZ"%.Tnm Kb- ƞ4#5z;hä.x.li&u@srSMW8k9,T`t&T83ZJ&KkȒ vIV@aE +ݛ<čQMIq⠇Uwģ*CrF1OVB/dJo9_wLCr|3Ê5t&NQHR=J91fU voy2%8۰?t/G,<"H]H 9vE VO)u'cQB MizeOeBF7^S"g^.|c(Pktoɱf7055JG^H .-2>,|ݪg[>EFb&#TčquQ|"v^nZF㙟 ! ̸v)q %037lhZKeG ס Zd 'o`;mS JiGs~ߊ"[xI \}P˟Y'҆ШJNr1CWQ9h3Ù4Arͱ;! <`+wƼgfX鷰Ӈ àN&P="_ 3z jvS4@BCC*Og7u^u~[CaȤ3,akoɃt0w3~4.=.8C%ENKx,Rݽ14ҝ<  A>!sD 1cpJG7n,xᵫȈH c}Hq XyVd3dHlqBЬ+P'2=ecJc.IB K~ʡ5l:Gr^w 1,lǷA~zhNFde!\+ b I'*g XI!/#8e|;Y?=_#>_"QVNOg/by*x0Cq'U䨚qĨH}BOZ{߰B@5k3qkr".rg7CDPH׏dh iOif85bSfDT$衖SpWP;S 9†8a>>| uo{siGG|OuFEeY:ɓg9o>!#/KEZif8qOF(=>%KJ!%q?V,@s݂ ̘dR]©fmHY&֍yGm\Gȗv$" ?)sݴآoty {ihEHz5xt󌢡щc :UߺHAYBѢmi)3k&G0.z/=l_"c>>N xmU "[r(~ݩTt S9PgC[YKQBpw)bpvʽhWŔoȃ) 鿑DЖKUJH-][xFW) 7W2WH$If -GmG e´@A,/ߕGa5x/9!;J5]϶9vIn6#S3u8W/g\Y#m2 2N>Ty*}݂W{[@$NBãLNsno I0N3?ánB5؜;/#!Z(d PTՌ:8yYB8F`hx\u&|*k;LZ #+;;8tlmjwpI_¦6VM.@F5G'5*#SXPT(~hG2cb!g[==󥙍kcEY9SB)"iwS,j2c;S-7Ѓt_WpЂI5vBHtչqLNJ3fx4:T Q+A ui]i/ϟ(al_K%,I+~TCfe vͧ,f<ɡj@):5OlWa"˳-lF|Pʂ!>۞+.GJ)aDirkZ Rja?\+`ד>pC6IѢi_+R^-kȼ5?.X7ҚU4[^KX^E$_,v:پVwdRP~WG]:<=?)ρf4*\qnG]g_w GibR`M|$j`^qzWi@9 £l"+hP-Ř0Ӝp$ Xn&UpVRJ+3Q!E W~G"U+$5NQȊyyڥkoȝp!{HFdG6-yq ^q鿢x?_V&^%Z%D',]"Hʢ܆b,؞'A/7\^+~ >ut;ôޑs&{уLAUlIQ@K皹Atd$9/|xCK%C| -+ŧufQD8F}ɴ>g" B]\5_*Ft Uȼlsf [:\JGA9{r&;t$? dvýwSai-G+sT L ^V f>`z3ȭq3GV[&_&R}j)7ڽqOhF*y mtt 4b5ʣ`zuQqq}~JDbX;z!YP`$E6aʙ WUS6 0܇:`tE۳4ŽX/`e7ܺmnC}9 RBu.n j=po[)nh4P_SXR)p8J{.\nFgz%tz ?q2:DzV3C9RsDuʷzJ G@Up+4VͶCVZѺz DlJ]rNAB~JVa"uI>Ha<@6tE}[r♫>$$na6V_r «ѧNIxro9)EI{gQ#pI F I&u)W#Gmi*}'fDWt_vc& A (M]G\'iO ?[lBڦB^;Ԯh' W@ɍŒLx=EGk+8!QqD>g%7ڂ9%Af4՘| wźO)xL:6''K\ͷG}*(r\j8WA{G ߨ0†OfJf܋LDl9vhFV W$A;!T=K5LJk2(R$tj62/๮JOpk䂯Bv@D$5)נڐ>Fd\Ujbn׏8vvhRSsM1Po'PQTn:t/lCa1ʅtNjM 1ΨY2!h~qD+WǎUɰ]CءؕF]'b%Fږ҃޴chy0yW$JHhd-"nA$RgZ^L}TrTWv݉mC9O!{& }` \#3zˣR^R22 (R3evePRdv99$ʥ?v^ӽaW%/ȡ5W['ʴ|'O ͷa9oT-qL0Y*f1c{E'As?wDseY[l˝;Cr5%N?vڶ2p'/'N'긚ͪ\&͎g@$%՛ٕj7n TݩyHNк|YP$gOZpBbBʡ'y_LJ]CqZ[b DėܶŰ~qZIf}^@>v24?U.dK11RmWN'Tuhs;ёXUتD/!^" 9턜Z^-W3!B/t؄,"dMFֿ^I7Ň5䠝GHnu~~єQ9iEAWuDŽ6pF_bp<&.@ݮqqyr-hs,p"(1)E $>asevA@GQւ| c}gL,V^RLRٷd](t-j-NH~ ml" ]`ul~q̵%s)TBiW%pX`k.2hMȀѱ Lh1dY py)Wg '坬a{}H&.`EnFwl!MVWW _އ&KyX²eb(ѧ Bw~`Y|>/ )P(qNU/$1W;Zp7tZoӾ!J g5dKk=}8m@IFC(Kxo xCs *[~ݐ;gg/34S9a ?M![jl-{2WsL;=(ZG.μwR'uwn^W>R Y<%RX퓧qP{> nrx7 4~0b}E!. ^(nn '޵\2+`A4*{CI' H4A@iVJ ch!ׅI2&j[,C>Q/;aZ*kea򇎏,I[RsUB/wȓ5G+ ~_!/Ũ@IuEX3PXPeMmPs7?-qQ"F$q#BtCVȓot[rTǽ%E]sbxjl1wIKfpT0@VI oQ7&Gs-+aU~d+MSghӨt&˼ДcEHՏmt5}"ʼn*fA &A%wCqʷhtߢQFּOS(<'*VFt6 \KHlW."lkӁyh_7P(В煊].4e}Qv1˶0;!q,6xVi=J>敉rU(䱑Aҋ߁)U5r4 բ﯄No5κKB?T}(z;0 <ŒAcz@ ߣuGo;OGbá\鰸_> } NtnD1i/PDMn{KY&tD`?bQ 2vRbo|Ips)j(ުaOn2gHQ8e[jbܘnc*n4C9,"@.dX!.iU:X{jT d병¯tlkf!$fʩOX< v{uY\, 0yp(A&Œ7?db)dF0ʊwsKS4yΚ t˖aeWl2'vLFYz/@\Qk!BSձZ7=|Cv/lIx9t}Wqw޿d%̈BY͟ +& hRo4kOq|8ۤv2|w_"J)SV KxHMMn]swWw4? ^T VG=ߚmk|pAӿ?+J]T&5Vjksw[oQ;N nn<,OG$|X;uԏ4m ۽};bp,\8nR˰ˇjļ f B I$"?Ȥb3L(~0L-g0O_&UtEk1ɟ6.gCO2(2pz0f %-q4g["GP`NVpXCAϜԇ0%Aq}3 '0ʀ[ϚVq_d~b2-"f79dRk)uLGU)6K t __ZӼ/sKnW20{.jkJM:B^*|SPi(@Z"l8i 'NJ#aɡ3I  d ٕ_>Hdd\ *Pa5oȪ,֊bվIBV!9P8Fo80|qiZ36{0GjX=jgaj/?LU)3聭QS~I Kq } ?ҷ@3VW${ ijHcxUǼKo#C+ffz|牣?rx-=FOS)*]+aGh+xyeJx`N1Ԥ`kΏЇE][C"qRas8A@i kv!şɦ}*=T-Eor/QZfȴQRh ~,V}eKXI=!V:CB#|>at=\ ф>pƬߤ:l;jK[H . [87uQ,(uQ+ PlZUbt:*wy5l?m^5+Cd*Bj :fXU=cocDLiPi 9aSn# g)a5Q=R8 LgSXꐉaYͿ`.zYgMl`/>OBl탆"='})@4u(%%O82_>˿bm2o͗%4]roa֨Ө{W[Xh2Z6M{,=U] *IBsK";vuQS#'l}=YςɆCU{IΉ6R"qɷ ) nOͭ hDnPQl v"Y 4JJ $ژ7+yc.%z feHB3Kh]]e2R\ѯOW#A+EqJ%":3bl8|imh^ ouq'n)?ɢ&{'daX-Ͽ*c WУfGJC! ǶÌ9rSU'e0QZX3uJg05Xj\@ 70^0\՜H?)159Ʌzy6tRԜ]b~a|ܮB: ]ŔPICY>ο G9d+rmٝ}\$*Xp+=igҘ9]2g0˛ %IC4Z1ڞ:$:ۈjP}lm$0jV >4km3bς^8k#+J~{6\M@@DB`V^]Pdh}񅹇_wg4R  ͉ q~KToaH%s Z:ɹIFI d[dp?GcⶔT{:`QMwI7S=JNfn{QG\A׼'AN "P{Ԏ3 YZ