Merge pull request #288 from outis1one/claude/ionos-script-integration-x32ofw
Claude/ionos script integration x32ofw
This commit is contained in:
+8
-3
@@ -27,14 +27,19 @@ install_base() {
|
||||
|
||||
run_cmd apt-get update -y
|
||||
|
||||
# Core utilities present on every install. cifs-utils here (not lazily
|
||||
# installed on first use, the way tools/mount-network-drive.sh and
|
||||
# Core utilities present on every install. cifs-utils/keyutils here (not
|
||||
# lazily installed on first use, the way tools/mount-network-drive.sh and
|
||||
# vpn-data-mount.sh's own local-mount step would otherwise do it) so SMB
|
||||
# mounts work immediately whenever they're set up later, same reasoning
|
||||
# as Docker/Compose being unconditional here instead of on-demand.
|
||||
# keyutils explicitly, not left to cifs-utils' Recommends — some minimal
|
||||
# cloud VPS images disable install-recommends, and without keyutils'
|
||||
# /etc/request-key.d handlers every mount.cifs call (guest or fully
|
||||
# credentialed) fails with "mount error(79): Can not access a needed
|
||||
# shared library" regardless of the password being correct.
|
||||
run_cmd apt-get install -y \
|
||||
net-tools ncdu git curl wget htop btop tree zip unzip \
|
||||
ca-certificates gnupg jq rsync ssh-import-id cifs-utils \
|
||||
ca-certificates gnupg jq rsync ssh-import-id cifs-utils keyutils \
|
||||
|| log_warning "Some essential packages failed to install"
|
||||
|
||||
# glow — terminal markdown reader (charmbracelet). Not in Ubuntu repos,
|
||||
|
||||
@@ -43,12 +43,34 @@
|
||||
# Mounts use real Samba credentials (a username/password you provide for
|
||||
# an account that already exists on the home box), stored locally in a
|
||||
# root-only credentials file, same convention tools/mount-network-drive.sh
|
||||
# already uses — never guest access. A CIFS guest mount with no explicit
|
||||
# security mode can hit "mount error(79): Can not access a needed shared
|
||||
# library" — a misleadingly-worded cifs-utils message for errno 79
|
||||
# (ENOKEY), a known rough edge in the kernel cifs.ko keyring/upcall path
|
||||
# for anonymous sessions. Credentialed mounts with an explicit sec=ntlmssp
|
||||
# take the normal NTLMSSP auth path instead and don't hit it.
|
||||
# already uses — never guest access.
|
||||
#
|
||||
# "mount error(79): Can not access a needed shared library" is NOT a
|
||||
# credentials problem, guest-vs-authenticated problem, or a mislabeled
|
||||
# ENOKEY — errno 79 is literally ELIBACC, and mount.cifs prints glibc's
|
||||
# literal strerror() text for it. Confirmed live: this recurred identically
|
||||
# with a real Samba account and a verified, correctly-captured password
|
||||
# (see the read()/IFS note above — that was a real bug too, just not this
|
||||
# one), and again after keyutils was already installed — so it's not that
|
||||
# either, at least not on every host. Two independent real causes share
|
||||
# this exact errno/message, both fixed defensively below:
|
||||
# 1. `keyutils` missing on the client. cifs-utils hard-depends on the
|
||||
# libkeyutils1 *library* but only Recommends the keyutils *package*
|
||||
# (/sbin/request-key + /etc/request-key.d/*.conf, what the kernel's
|
||||
# upcall actually invokes) — minimal cloud images that disable
|
||||
# install-recommends silently skip it.
|
||||
# 2. The hardcoded `iocharset=utf8` mount option needs the kernel's
|
||||
# nls_utf8 module. Confirmed live on a stock Ubuntu 6.8.0-137-generic
|
||||
# VPS kernel: `modprobe nls_utf8` → "FATAL: Module nls_utf8 not found"
|
||||
# — not loadable, not built in, just absent from that kernel build.
|
||||
# Every mount asking for that codepage fails with errno 79 regardless
|
||||
# of credentials. `_vdm_mount_local` probes for it with a harmless
|
||||
# `modprobe` and only adds `iocharset=utf8` if it actually loads;
|
||||
# otherwise it warns and mounts without it (kernel falls back to its
|
||||
# build's nls_default — fine for ASCII-heavy filenames, the common
|
||||
# case for a home-data share; non-ASCII filenames may not round-trip
|
||||
# perfectly on a kernel missing this module, which is a kernel
|
||||
# limitation this script can't paper over further).
|
||||
|
||||
# ── Standalone bootstrap ──────────────────────────────────────────────────────
|
||||
if [[ "${BASH_SOURCE[0]}" == "${0}" ]]; then
|
||||
@@ -322,6 +344,10 @@ _vdm_mount_local() {
|
||||
local host="$1" share_name="$2" mount_point="$3" label="$4" smb_user="$5" smb_pass="$6"
|
||||
|
||||
command -v mount.cifs >/dev/null 2>&1 || apt-get install -y cifs-utils -qq
|
||||
# Explicit, not left to cifs-utils' Recommends — see file header on
|
||||
# errno 79/ELIBACC. dpkg -s (not command -v: keyutils ships no binary
|
||||
# this script calls directly, just the request-key handler files).
|
||||
dpkg -s keyutils >/dev/null 2>&1 || apt-get install -y keyutils -qq
|
||||
|
||||
mkdir -p "$mount_point"
|
||||
|
||||
@@ -336,8 +362,18 @@ CREDS
|
||||
chmod 600 "$creds_file"
|
||||
chown root:root "$creds_file"
|
||||
|
||||
# sec=ntlmssp explicitly — see the file header on errno 79/ENOKEY.
|
||||
local opts="credentials=${creds_file},sec=ntlmssp,uid=$(id -u "$ACTUAL_USER"),gid=$(id -g "$ACTUAL_USER"),iocharset=utf8,nofail,_netdev"
|
||||
# sec=ntlmssp explicitly — see the file header on errno 79.
|
||||
local opts="credentials=${creds_file},sec=ntlmssp,uid=$(id -u "$ACTUAL_USER"),gid=$(id -g "$ACTUAL_USER"),nofail,_netdev"
|
||||
|
||||
# iocharset=utf8 only if the kernel can actually load nls_utf8 — see
|
||||
# the file header. modprobe on an already-loaded/built-in module is a
|
||||
# harmless no-op, so this is safe to call unconditionally.
|
||||
if modprobe nls_utf8 >/dev/null 2>&1; then
|
||||
opts="${opts},iocharset=utf8"
|
||||
else
|
||||
log_warning "This kernel ($(uname -r)) has no nls_utf8 module — mounting without iocharset=utf8. Non-ASCII filenames may not display correctly; try 'sudo apt-get install --reinstall linux-modules-$(uname -r)' to see if it restores the module."
|
||||
fi
|
||||
|
||||
local share="//${host}/${share_name}"
|
||||
|
||||
log_info "Testing mount..."
|
||||
|
||||
@@ -29,7 +29,14 @@ ACTUAL_GID="$(id -g "$ACTUAL_USER")"
|
||||
ensure_packages() {
|
||||
local pkgs=()
|
||||
case "$1" in
|
||||
smb) command -v mount.cifs &>/dev/null || pkgs+=(cifs-utils) ;;
|
||||
smb)
|
||||
command -v mount.cifs &>/dev/null || pkgs+=(cifs-utils)
|
||||
# keyutils explicitly, not left to cifs-utils' Recommends — on
|
||||
# images with install-recommends disabled, missing keyutils
|
||||
# makes every mount.cifs call fail with "mount error(79): Can
|
||||
# not access a needed shared library" regardless of credentials.
|
||||
dpkg -s keyutils &>/dev/null || pkgs+=(keyutils)
|
||||
;;
|
||||
nfs) command -v mount.nfs &>/dev/null || pkgs+=(nfs-common) ;;
|
||||
esac
|
||||
if [[ ${#pkgs[@]} -gt 0 ]]; then
|
||||
@@ -114,7 +121,19 @@ CREDS
|
||||
local ver_opt=""
|
||||
[[ -n "$smb_ver" ]] && ver_opt=",vers=${smb_ver}"
|
||||
|
||||
local opts="uid=${ACTUAL_UID},gid=${ACTUAL_GID},${creds_opt}${ver_opt},iocharset=utf8,nofail,_netdev"
|
||||
local opts="uid=${ACTUAL_UID},gid=${ACTUAL_GID},${creds_opt}${ver_opt},nofail,_netdev"
|
||||
|
||||
# iocharset=utf8 only if the kernel can actually load nls_utf8 — some
|
||||
# kernels (confirmed live: a stock Ubuntu 6.8.0-137-generic VPS) don't
|
||||
# ship that module at all, and mount.cifs fails every such mount with
|
||||
# "mount error(79): Can not access a needed shared library" regardless
|
||||
# of credentials. modprobe on an already-loaded/built-in module is a
|
||||
# harmless no-op, so this check is safe to run unconditionally.
|
||||
if modprobe nls_utf8 >/dev/null 2>&1; then
|
||||
opts="${opts},iocharset=utf8"
|
||||
else
|
||||
warn "This kernel ($(uname -r)) has no nls_utf8 module — mounting without iocharset=utf8. Non-ASCII filenames may not display correctly; try 'sudo apt-get install --reinstall linux-modules-$(uname -r)' to see if it restores the module."
|
||||
fi
|
||||
|
||||
_do_mount "cifs" "$share" "$mount_point" "$opts"
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user