diff --git a/CHANGELOG.md b/CHANGELOG.md
--- a/CHANGELOG.md
+++ b/CHANGELOG.md
@@ -1,5 +1,14 @@
 # Revision history for sha256
 
+## 0.1.0.2 -- 2025-01-21
+
+* Duplicate a C function used from the hash-string package, because hackage's
+  build infrastructure had a problem finding hs_hashstring_memcmp.h header file
+
+## 0.1.0.1 -- 2025-01-20
+
+* Original release was accidentally categorized as Graphics, not Cryptography
+
 ## 0.1.0.0 -- 2025-01-20
 
 * Rewrite of the FFI portions of the cryptohash-sha256 bindings, in order
diff --git a/csrc/hs_sha256.c b/csrc/hs_sha256.c
--- a/csrc/hs_sha256.c
+++ b/csrc/hs_sha256.c
@@ -30,7 +30,6 @@
 #include <string.h>
 #include <ghcautoconf.h>
 
-#include "hs_hashstring_memcmp.h"
 #include "hs_sha256.h"
 
 #define ptr_uint32_aligned(ptr) (!((uintptr_t)(ptr) & 0x3))
@@ -409,6 +408,34 @@
   return out;
 }
 
+/*
+
+  FIXME:
+
+  This function is a duplicate of hs_hashstring_const_memcmp. This duplication
+  was introduced to work around an issue with hackage's build infrastructure,
+  as the C compiler couldn't find hs_hashstring_memcmp.h
+
+  A more proper fix would avoid this duplication.
+
+*/
+static inline
+int
+hs_sha256_const_memcmp
+( const uint8_t *const a,
+  const uint8_t *const b,
+  size_t const n )
+{
+  int d, out = 0;
+  size_t i = n;
+  while (i > 0) {
+    i--;
+    d = a[i] - b[i];
+    out = d == 0 ? out : d;
+  }
+  return out;
+}
+
 // constant-ish time memcmp, could be better, but should be pretty good
 // doesn't handle nulls, must be passed a non-null argument!
 int
@@ -421,10 +448,14 @@
   int x = a->count & 0x3F;
   int y = b->count & 0x3F;
   int n = (x < y) ? x : y;
-  if ( (d = hs_hashstring_const_memcmp(a->buffer, b->buffer, n)) ) return d;
+  if ( (d = hs_sha256_const_memcmp(a->buffer, b->buffer, n)) ) return d;
   if ( (d = x - y) ) return d;
   // does this last comparison even matter in practice?
   if (a->count == b->count) return 0;
+  // It is of course trivial to reach this location if you simply take a SHA256
+  // context structure and change the length, but this should be effectively
+  // unreachable without constructing at least one state synthetically.
+  // A difference in length implies a cryptographically non-trivial collision.
   if (a->count < b->count) return -1;
   return 1;
 }
diff --git a/sha256.cabal b/sha256.cabal
--- a/sha256.cabal
+++ b/sha256.cabal
@@ -1,5 +1,5 @@
 name:                sha256
-version:             0.1.0.1
+version:             0.1.0.2
 synopsis:
   A modern binding to SHA256, HMAC, HKDF, and PBKDF2
 description:
@@ -46,6 +46,11 @@
   cc-options:        -Wall  
   install-includes:  csrc/hs_sha256.h
   c-sources:         csrc/hs_sha256.c
+
+source-repository head
+  type:     git
+  location: http://github.com/auth-global/self-documenting-cryptography
+  subdir:   sha256
 
 test-suite test
   type:              exitcode-stdio-1.0
