From f0040faee9d46046d971de39b6b3b549cf0fccf5 Mon Sep 17 00:00:00 2001 From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com> Date: Mon, 14 Sep 2026 01:44:26 +0000 Subject: [PATCH 1/2] chore(deps): update morrownr/rtl8852cu-20251113 digest to 08b136a --- package/rtl8852cu-morrownr/rtl8852cu-morrownr.mk | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/package/rtl8852cu-morrownr/rtl8852cu-morrownr.mk b/package/rtl8852cu-morrownr/rtl8852cu-morrownr.mk index 05eb292c..a85943d9 100644 --- a/package/rtl8852cu-morrownr/rtl8852cu-morrownr.mk +++ b/package/rtl8852cu-morrownr/rtl8852cu-morrownr.mk @@ -99,7 +99,7 @@ # non-prompt, select-only bool -- net/wireless/Kconfig:2-3 -- which is the # P1.3 hazard. So the WEXT-only code above simply compiles out; no wrapper and # no kernel `select` hack is needed. -RTL8852CU_MORROWNR_VERSION = 6e4ee1322fdbdc35a2cbc79f1eff9168001742e3 +RTL8852CU_MORROWNR_VERSION = 08b136aa8c1322d4a4e10f2f4c8a542ea7b957c9 RTL8852CU_MORROWNR_SITE = $(call github,morrownr,rtl8852cu-20251113,$(RTL8852CU_MORROWNR_VERSION)) RTL8852CU_MORROWNR_LICENSE = GPL-2.0 RTL8852CU_MORROWNR_LICENSE_FILES = LICENSE From 74d0de56c8bb86891716a9f3a2515970fa3a85f7 Mon Sep 17 00:00:00 2001 From: "renovate-hash-sync[bot]" Date: Mon, 14 Sep 2026 01:44:52 +0000 Subject: [PATCH 2/2] renovate-hash-sync: refresh companion hash(es) for this PR Recomputed from a freshly-fetched artifact: - driver/firmware/libchdr package pins: sha256sum of the github archive tarball at the new pinned owner/repo/ref (same "locally computed" practice this tree's own .hash file headers already document) - kernel pins (stable 6.18.y and the RT/beta 7.2 line): kernel.org's signed sha256sums.asc for each pin's own vN.x series. An -rc is never refreshed here -- no signed manifest exists for one - ip7z/7zip pins (lzma-sdk, 7zip): sha256sum of the release ASSET for the new version (upstream publishes no checksums at all -- see package/lzma-sdk/lzma-sdk.hash's header), PLUS the files each package's *_LICENSE_FILES names, hashed from that same asset. A changed license file is refreshed AND diffed into the step log with a ::warning:: -- read that diff before merging; it is the only thing standing between an automated hash refresh and a silent relicense - sdcard payload pins (update_all.sh, wifi.sh): sha256 + size of the raw file at the new pinned commit, rewritten in place in scripts/fetch-sdcard-payload.sh - Buildroot pin (BUILDROOT_SHA256, root Makefile): transcribed from buildroot.org's GPG-signed release manifest (buildroot-.tar.gz.sign) -- the same signed file `make buildroot-showsig` prints, never a locally-computed sha256sum of the tarball (that remains forbidden; see the Makefile's own header comment) - azcopy pin: REBUILT, not fetched. Buildroot's own support/download/go-post-process re-ran `go mod vendor` over the newly pinned tag with the Go version the pinned Buildroot tree pins, and the resulting azcopy--go2.tar.gz was hashed -- the only way this value can be derived, since no URL serves that file (see package/azcopy/azcopy.hash's header). LICENSE and NOTICE.txt were re-hashed from the same tarball --- package/rtl8852cu-morrownr/rtl8852cu-morrownr.hash | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/package/rtl8852cu-morrownr/rtl8852cu-morrownr.hash b/package/rtl8852cu-morrownr/rtl8852cu-morrownr.hash index 913737f6..c443d2f8 100644 --- a/package/rtl8852cu-morrownr/rtl8852cu-morrownr.hash +++ b/package/rtl8852cu-morrownr/rtl8852cu-morrownr.hash @@ -10,5 +10,5 @@ # value is exactly what Buildroot will re-verify. Recomputed on every fetch, so # a tampered or rewritten upstream ref fails the build rather than being # silently accepted. -sha256 610f48cc0f69de5ac03f46075b6d2f5df9192d2a7aa0f85bfd8093450f30d63c rtl8852cu-morrownr-6e4ee1322fdbdc35a2cbc79f1eff9168001742e3.tar.gz +sha256 7bf0b0aa5b8d85c306bc52a5ccc62de1d4d0e8c994920039ba262f223dbc51ec rtl8852cu-morrownr-08b136aa8c1322d4a4e10f2f4c8a542ea7b957c9.tar.gz sha256 821deb3a5d7eb3794e6d3f7ba710b2ce09db04eddb4c25005c7a0a741ab8597f LICENSE