From 6e73125cf74b501b10f5d88b1d674afdc59fac73 Mon Sep 17 00:00:00 2001 From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com> Date: Fri, 2 Oct 2026 17:31:55 +0000 Subject: [PATCH 1/2] chore(deps): update radxa-pkg/aic8800 digest to d13d079 --- package/aic8800/aic8800.mk | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/package/aic8800/aic8800.mk b/package/aic8800/aic8800.mk index 33ad930..0920631 100644 --- a/package/aic8800/aic8800.mk +++ b/package/aic8800/aic8800.mk @@ -102,7 +102,7 @@ # ambiguity is recorded here rather than resolved, because it cannot be # resolved from outside AICSemi. -AIC8800_VERSION = 516e3b087763d80c44f5e3b6d2dd63e0d925c91d +AIC8800_VERSION = d13d07963cd15d731e2895e8288a04cca6152ac9 AIC8800_SITE = $(call github,radxa-pkg,aic8800,$(AIC8800_VERSION)) AIC8800_LICENSE = GPL-2.0 (driver, per debian/copyright + MODULE_LICENSE), PROPRIETARY (AICSemi firmware blobs, redistributed) AIC8800_LICENSE_FILES = debian/copyright From 8b4b609e6037890db472441770318b9ad8ffcd08 Mon Sep 17 00:00:00 2001 From: "renovate-hash-sync[bot]" Date: Fri, 2 Oct 2026 17:32:39 +0000 Subject: [PATCH 2/2] renovate-hash-sync: refresh companion hash(es) for this PR Recomputed from a freshly-fetched artifact: - driver/firmware/libchdr package pins: sha256sum of the github archive tarball at the new pinned owner/repo/ref (same "locally computed" practice this tree's own .hash file headers already document) - kernel pins (stable 6.18.y and the RT/beta 7.2 line): kernel.org's signed sha256sums.asc for each pin's own vN.x series. An -rc is never refreshed here -- no signed manifest exists for one - ip7z/7zip pins (lzma-sdk, 7zip): sha256sum of the release ASSET for the new version (upstream publishes no checksums at all -- see package/lzma-sdk/lzma-sdk.hash's header), PLUS the files each package's *_LICENSE_FILES names, hashed from that same asset. A changed license file is refreshed AND diffed into the step log with a ::warning:: -- read that diff before merging; it is the only thing standing between an automated hash refresh and a silent relicense - sdcard payload pins (update_all.sh, wifi.sh): sha256 + size of the raw file at the new pinned commit, rewritten in place in scripts/fetch-sdcard-payload.sh - Buildroot pin (BUILDROOT_SHA256, root Makefile): transcribed from buildroot.org's GPG-signed release manifest (buildroot-.tar.gz.sign) -- the same signed file `make buildroot-showsig` prints, never a locally-computed sha256sum of the tarball (that remains forbidden; see the Makefile's own header comment) - azcopy pin: REBUILT, not fetched. Buildroot's own support/download/go-post-process re-ran `go mod vendor` over the newly pinned tag with the Go version the pinned Buildroot tree pins, and the resulting azcopy--go2.tar.gz was hashed -- the only way this value can be derived, since no URL serves that file (see package/azcopy/azcopy.hash's header). LICENSE and NOTICE.txt were re-hashed from the same tarball --- package/aic8800/aic8800.hash | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/package/aic8800/aic8800.hash b/package/aic8800/aic8800.hash index 7e6872e..78c3a5f 100644 --- a/package/aic8800/aic8800.hash +++ b/package/aic8800/aic8800.hash @@ -15,7 +15,7 @@ # The tarball is large (55 MiB) because it carries the PCIE and SDIO driver # trees and the vendor documentation alongside the USB tree this package # builds. Only src/USB/ is used; nothing prunes the download. -sha256 f79ff9b8b4dfed97c59fe6877b34406bbac042cc1091ada3bb17224fe62f1b39 aic8800-516e3b087763d80c44f5e3b6d2dd63e0d925c91d.tar.gz +sha256 8885bda125037cbaefd58828ac907a4036316a012cc72b5b1ae87a48f852113d aic8800-d13d07963cd15d731e2895e8288a04cca6152ac9.tar.gz # Licence file. debian/copyright, not the repo's top-level LICENSE: the # top-level file is the plain GPL-3 text covering radxa's packaging, while