From fdc562a1e2dfbd3cf46a51144ab5cc1aa4de343b Mon Sep 17 00:00:00 2001 From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com> Date: Fri, 2 Oct 2026 06:19:37 +0000 Subject: [PATCH 1/2] chore(deps): update rtissera/libchdr digest to 607694c --- package/libchdr/libchdr.mk | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/package/libchdr/libchdr.mk b/package/libchdr/libchdr.mk index a7b52c2..5196e0e 100644 --- a/package/libchdr/libchdr.mk +++ b/package/libchdr/libchdr.mk @@ -74,7 +74,7 @@ # project() still says 0.3.0, so this still produces libchdr.so.0.3 with # SONAME libchdr.so.0 (re-verified at the 2026-08-24 bump by cross-building # the pinned+patched source and reading the .so's SONAME). -LIBCHDR_VERSION = 8e7b8bd32bc676b7e5c6b42fe7d2daca986c4a0d +LIBCHDR_VERSION = 607694ca0812edfc9cc2030c64634fc2393668de LIBCHDR_SITE = $(call github,rtissera,libchdr,$(LIBCHDR_VERSION)) # LICENSE.txt is the standard BSD 3-clause text ("Copyright Romain # Tisserand", the three numbered conditions, the all-caps disclaimer -- From 3ee17464b87712107837b7de74ad2fa6a8e0905d Mon Sep 17 00:00:00 2001 From: "renovate-hash-sync[bot]" Date: Fri, 2 Oct 2026 06:20:05 +0000 Subject: [PATCH 2/2] renovate-hash-sync: refresh companion hash(es) for this PR Recomputed from a freshly-fetched artifact: - driver/firmware/libchdr package pins: sha256sum of the github archive tarball at the new pinned owner/repo/ref (same "locally computed" practice this tree's own .hash file headers already document) - kernel pins (stable 6.18.y and the RT/beta 7.2 line): kernel.org's signed sha256sums.asc for each pin's own vN.x series. An -rc is never refreshed here -- no signed manifest exists for one - ip7z/7zip pins (lzma-sdk, 7zip): sha256sum of the release ASSET for the new version (upstream publishes no checksums at all -- see package/lzma-sdk/lzma-sdk.hash's header), PLUS the files each package's *_LICENSE_FILES names, hashed from that same asset. A changed license file is refreshed AND diffed into the step log with a ::warning:: -- read that diff before merging; it is the only thing standing between an automated hash refresh and a silent relicense - sdcard payload pins (update_all.sh, wifi.sh): sha256 + size of the raw file at the new pinned commit, rewritten in place in scripts/fetch-sdcard-payload.sh - Buildroot pin (BUILDROOT_SHA256, root Makefile): transcribed from buildroot.org's GPG-signed release manifest (buildroot-.tar.gz.sign) -- the same signed file `make buildroot-showsig` prints, never a locally-computed sha256sum of the tarball (that remains forbidden; see the Makefile's own header comment) - azcopy pin: REBUILT, not fetched. Buildroot's own support/download/go-post-process re-ran `go mod vendor` over the newly pinned tag with the Go version the pinned Buildroot tree pins, and the resulting azcopy--go2.tar.gz was hashed -- the only way this value can be derived, since no URL serves that file (see package/azcopy/azcopy.hash's header). LICENSE and NOTICE.txt were re-hashed from the same tarball --- package/libchdr/libchdr.hash | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/package/libchdr/libchdr.hash b/package/libchdr/libchdr.hash index d30a0c8..a450c1e 100644 --- a/package/libchdr/libchdr.hash +++ b/package/libchdr/libchdr.hash @@ -11,7 +11,7 @@ # touch a comment, so a literal here goes stale on the first automatic bump. # Both of these had (they still named the 04a177ee pin, two bumps back), as # did the "verified at pin time (2026-07-17)" date this replaces. -sha256 04d6c61946c95addb78f4554740283b93249b81d8437e3d8a58ca1899c824dcc libchdr-8e7b8bd32bc676b7e5c6b42fe7d2daca986c4a0d.tar.gz +sha256 02e772a74c4e5ec110bb646e729e1910268d2dae2c76df2a1b35525cc3826a9c libchdr-607694ca0812edfc9cc2030c64634fc2393668de.tar.gz # LICENSE.txt -- the BSD-3-Clause text; see the LIBCHDR_LICENSE comment in # the .mk (the bundled dr_flac's public-domain/MIT-0 statements live inside # include/dr_libs/dr_flac.h itself, no separate file exists to hash)