From 812c4b9c8075c1dc23cd45083501a35b9c24b84e Mon Sep 17 00:00:00 2001 From: AI Dev Date: Sat, 19 Sep 2026 13:14:42 +0000 Subject: [PATCH] dropbear-openipc: name the hash file so buildroot reads it Buildroot resolves a package's checksums to .hash, which for this package is dropbear-openipc.hash. The file shipped as dropbear.hash and was therefore never opened: check-hash printed "WARNING: no hash file for dropbear-2022.82.tar.bz2" and returned 0, so the tarball was fetched from sources.buildroot.net over plain HTTP and built with no integrity check at all. BR2_DOWNLOAD_FORCE_CHECK_HASHES is off, so nothing ever failed and the gap stayed invisible -- the .hash file is present in the tree and looks right, which is exactly why this survived review. The contents were already correct, all four hashes verifying against the released tarball, so this is a rename and verification simply starts working. Found while reviewing #2449, which had introduced the same mistake in a new package. --- .../dropbear-openipc/{dropbear.hash => dropbear-openipc.hash} | 0 1 file changed, 0 insertions(+), 0 deletions(-) rename general/package/dropbear-openipc/{dropbear.hash => dropbear-openipc.hash} (100%) diff --git a/general/package/dropbear-openipc/dropbear.hash b/general/package/dropbear-openipc/dropbear-openipc.hash similarity index 100% rename from general/package/dropbear-openipc/dropbear.hash rename to general/package/dropbear-openipc/dropbear-openipc.hash