From 6bc8efdd7ba2d5237ad56b99e83b639b4c74a53c Mon Sep 17 00:00:00 2001 From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com> Date: Fri, 2 Oct 2026 06:32:29 +0000 Subject: [PATCH 1/2] chore(deps): update morrownr/rtl8852cu-20251113 digest to fcb70aa --- package/rtl8852cu-morrownr/rtl8852cu-morrownr.mk | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/package/rtl8852cu-morrownr/rtl8852cu-morrownr.mk b/package/rtl8852cu-morrownr/rtl8852cu-morrownr.mk index a85943d..5ff3343 100644 --- a/package/rtl8852cu-morrownr/rtl8852cu-morrownr.mk +++ b/package/rtl8852cu-morrownr/rtl8852cu-morrownr.mk @@ -99,7 +99,7 @@ # non-prompt, select-only bool -- net/wireless/Kconfig:2-3 -- which is the # P1.3 hazard. So the WEXT-only code above simply compiles out; no wrapper and # no kernel `select` hack is needed. -RTL8852CU_MORROWNR_VERSION = 08b136aa8c1322d4a4e10f2f4c8a542ea7b957c9 +RTL8852CU_MORROWNR_VERSION = fcb70aac55585a8e63c72da4e6d24c39d7494307 RTL8852CU_MORROWNR_SITE = $(call github,morrownr,rtl8852cu-20251113,$(RTL8852CU_MORROWNR_VERSION)) RTL8852CU_MORROWNR_LICENSE = GPL-2.0 RTL8852CU_MORROWNR_LICENSE_FILES = LICENSE From b348e24acaa77e4628bb430158aa6602fafea988 Mon Sep 17 00:00:00 2001 From: "renovate-hash-sync[bot]" Date: Fri, 2 Oct 2026 06:33:00 +0000 Subject: [PATCH 2/2] renovate-hash-sync: refresh companion hash(es) for this PR Recomputed from a freshly-fetched artifact: - driver/firmware/libchdr package pins: sha256sum of the github archive tarball at the new pinned owner/repo/ref (same "locally computed" practice this tree's own .hash file headers already document) - kernel pins (stable 6.18.y and the RT/beta 7.2 line): kernel.org's signed sha256sums.asc for each pin's own vN.x series. An -rc is never refreshed here -- no signed manifest exists for one - ip7z/7zip pins (lzma-sdk, 7zip): sha256sum of the release ASSET for the new version (upstream publishes no checksums at all -- see package/lzma-sdk/lzma-sdk.hash's header), PLUS the files each package's *_LICENSE_FILES names, hashed from that same asset. A changed license file is refreshed AND diffed into the step log with a ::warning:: -- read that diff before merging; it is the only thing standing between an automated hash refresh and a silent relicense - sdcard payload pins (update_all.sh, wifi.sh): sha256 + size of the raw file at the new pinned commit, rewritten in place in scripts/fetch-sdcard-payload.sh - Buildroot pin (BUILDROOT_SHA256, root Makefile): transcribed from buildroot.org's GPG-signed release manifest (buildroot-.tar.gz.sign) -- the same signed file `make buildroot-showsig` prints, never a locally-computed sha256sum of the tarball (that remains forbidden; see the Makefile's own header comment) - azcopy pin: REBUILT, not fetched. Buildroot's own support/download/go-post-process re-ran `go mod vendor` over the newly pinned tag with the Go version the pinned Buildroot tree pins, and the resulting azcopy--go2.tar.gz was hashed -- the only way this value can be derived, since no URL serves that file (see package/azcopy/azcopy.hash's header). LICENSE and NOTICE.txt were re-hashed from the same tarball --- package/rtl8852cu-morrownr/rtl8852cu-morrownr.hash | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/package/rtl8852cu-morrownr/rtl8852cu-morrownr.hash b/package/rtl8852cu-morrownr/rtl8852cu-morrownr.hash index c443d2f..830f1df 100644 --- a/package/rtl8852cu-morrownr/rtl8852cu-morrownr.hash +++ b/package/rtl8852cu-morrownr/rtl8852cu-morrownr.hash @@ -10,5 +10,5 @@ # value is exactly what Buildroot will re-verify. Recomputed on every fetch, so # a tampered or rewritten upstream ref fails the build rather than being # silently accepted. -sha256 7bf0b0aa5b8d85c306bc52a5ccc62de1d4d0e8c994920039ba262f223dbc51ec rtl8852cu-morrownr-08b136aa8c1322d4a4e10f2f4c8a542ea7b957c9.tar.gz +sha256 73077ea70492f5d48b5df8201a469d5fe58061575e7e45c4cec9e6a686e30cdd rtl8852cu-morrownr-fcb70aac55585a8e63c72da4e6d24c39d7494307.tar.gz sha256 821deb3a5d7eb3794e6d3f7ba710b2ce09db04eddb4c25005c7a0a741ab8597f LICENSE