Merge pull request #288 from outis1one/claude/ionos-script-integration-x32ofw
Claude/ionos script integration x32ofw
This commit is contained in:
+8
-3
@@ -27,14 +27,19 @@ install_base() {
|
|||||||
|
|
||||||
run_cmd apt-get update -y
|
run_cmd apt-get update -y
|
||||||
|
|
||||||
# Core utilities present on every install. cifs-utils here (not lazily
|
# Core utilities present on every install. cifs-utils/keyutils here (not
|
||||||
# installed on first use, the way tools/mount-network-drive.sh and
|
# lazily installed on first use, the way tools/mount-network-drive.sh and
|
||||||
# vpn-data-mount.sh's own local-mount step would otherwise do it) so SMB
|
# vpn-data-mount.sh's own local-mount step would otherwise do it) so SMB
|
||||||
# mounts work immediately whenever they're set up later, same reasoning
|
# mounts work immediately whenever they're set up later, same reasoning
|
||||||
# as Docker/Compose being unconditional here instead of on-demand.
|
# as Docker/Compose being unconditional here instead of on-demand.
|
||||||
|
# keyutils explicitly, not left to cifs-utils' Recommends — some minimal
|
||||||
|
# cloud VPS images disable install-recommends, and without keyutils'
|
||||||
|
# /etc/request-key.d handlers every mount.cifs call (guest or fully
|
||||||
|
# credentialed) fails with "mount error(79): Can not access a needed
|
||||||
|
# shared library" regardless of the password being correct.
|
||||||
run_cmd apt-get install -y \
|
run_cmd apt-get install -y \
|
||||||
net-tools ncdu git curl wget htop btop tree zip unzip \
|
net-tools ncdu git curl wget htop btop tree zip unzip \
|
||||||
ca-certificates gnupg jq rsync ssh-import-id cifs-utils \
|
ca-certificates gnupg jq rsync ssh-import-id cifs-utils keyutils \
|
||||||
|| log_warning "Some essential packages failed to install"
|
|| log_warning "Some essential packages failed to install"
|
||||||
|
|
||||||
# glow — terminal markdown reader (charmbracelet). Not in Ubuntu repos,
|
# glow — terminal markdown reader (charmbracelet). Not in Ubuntu repos,
|
||||||
|
|||||||
@@ -43,12 +43,34 @@
|
|||||||
# Mounts use real Samba credentials (a username/password you provide for
|
# Mounts use real Samba credentials (a username/password you provide for
|
||||||
# an account that already exists on the home box), stored locally in a
|
# an account that already exists on the home box), stored locally in a
|
||||||
# root-only credentials file, same convention tools/mount-network-drive.sh
|
# root-only credentials file, same convention tools/mount-network-drive.sh
|
||||||
# already uses — never guest access. A CIFS guest mount with no explicit
|
# already uses — never guest access.
|
||||||
# security mode can hit "mount error(79): Can not access a needed shared
|
#
|
||||||
# library" — a misleadingly-worded cifs-utils message for errno 79
|
# "mount error(79): Can not access a needed shared library" is NOT a
|
||||||
# (ENOKEY), a known rough edge in the kernel cifs.ko keyring/upcall path
|
# credentials problem, guest-vs-authenticated problem, or a mislabeled
|
||||||
# for anonymous sessions. Credentialed mounts with an explicit sec=ntlmssp
|
# ENOKEY — errno 79 is literally ELIBACC, and mount.cifs prints glibc's
|
||||||
# take the normal NTLMSSP auth path instead and don't hit it.
|
# literal strerror() text for it. Confirmed live: this recurred identically
|
||||||
|
# with a real Samba account and a verified, correctly-captured password
|
||||||
|
# (see the read()/IFS note above — that was a real bug too, just not this
|
||||||
|
# one), and again after keyutils was already installed — so it's not that
|
||||||
|
# either, at least not on every host. Two independent real causes share
|
||||||
|
# this exact errno/message, both fixed defensively below:
|
||||||
|
# 1. `keyutils` missing on the client. cifs-utils hard-depends on the
|
||||||
|
# libkeyutils1 *library* but only Recommends the keyutils *package*
|
||||||
|
# (/sbin/request-key + /etc/request-key.d/*.conf, what the kernel's
|
||||||
|
# upcall actually invokes) — minimal cloud images that disable
|
||||||
|
# install-recommends silently skip it.
|
||||||
|
# 2. The hardcoded `iocharset=utf8` mount option needs the kernel's
|
||||||
|
# nls_utf8 module. Confirmed live on a stock Ubuntu 6.8.0-137-generic
|
||||||
|
# VPS kernel: `modprobe nls_utf8` → "FATAL: Module nls_utf8 not found"
|
||||||
|
# — not loadable, not built in, just absent from that kernel build.
|
||||||
|
# Every mount asking for that codepage fails with errno 79 regardless
|
||||||
|
# of credentials. `_vdm_mount_local` probes for it with a harmless
|
||||||
|
# `modprobe` and only adds `iocharset=utf8` if it actually loads;
|
||||||
|
# otherwise it warns and mounts without it (kernel falls back to its
|
||||||
|
# build's nls_default — fine for ASCII-heavy filenames, the common
|
||||||
|
# case for a home-data share; non-ASCII filenames may not round-trip
|
||||||
|
# perfectly on a kernel missing this module, which is a kernel
|
||||||
|
# limitation this script can't paper over further).
|
||||||
|
|
||||||
# ── Standalone bootstrap ──────────────────────────────────────────────────────
|
# ── Standalone bootstrap ──────────────────────────────────────────────────────
|
||||||
if [[ "${BASH_SOURCE[0]}" == "${0}" ]]; then
|
if [[ "${BASH_SOURCE[0]}" == "${0}" ]]; then
|
||||||
@@ -322,6 +344,10 @@ _vdm_mount_local() {
|
|||||||
local host="$1" share_name="$2" mount_point="$3" label="$4" smb_user="$5" smb_pass="$6"
|
local host="$1" share_name="$2" mount_point="$3" label="$4" smb_user="$5" smb_pass="$6"
|
||||||
|
|
||||||
command -v mount.cifs >/dev/null 2>&1 || apt-get install -y cifs-utils -qq
|
command -v mount.cifs >/dev/null 2>&1 || apt-get install -y cifs-utils -qq
|
||||||
|
# Explicit, not left to cifs-utils' Recommends — see file header on
|
||||||
|
# errno 79/ELIBACC. dpkg -s (not command -v: keyutils ships no binary
|
||||||
|
# this script calls directly, just the request-key handler files).
|
||||||
|
dpkg -s keyutils >/dev/null 2>&1 || apt-get install -y keyutils -qq
|
||||||
|
|
||||||
mkdir -p "$mount_point"
|
mkdir -p "$mount_point"
|
||||||
|
|
||||||
@@ -336,8 +362,18 @@ CREDS
|
|||||||
chmod 600 "$creds_file"
|
chmod 600 "$creds_file"
|
||||||
chown root:root "$creds_file"
|
chown root:root "$creds_file"
|
||||||
|
|
||||||
# sec=ntlmssp explicitly — see the file header on errno 79/ENOKEY.
|
# sec=ntlmssp explicitly — see the file header on errno 79.
|
||||||
local opts="credentials=${creds_file},sec=ntlmssp,uid=$(id -u "$ACTUAL_USER"),gid=$(id -g "$ACTUAL_USER"),iocharset=utf8,nofail,_netdev"
|
local opts="credentials=${creds_file},sec=ntlmssp,uid=$(id -u "$ACTUAL_USER"),gid=$(id -g "$ACTUAL_USER"),nofail,_netdev"
|
||||||
|
|
||||||
|
# iocharset=utf8 only if the kernel can actually load nls_utf8 — see
|
||||||
|
# the file header. modprobe on an already-loaded/built-in module is a
|
||||||
|
# harmless no-op, so this is safe to call unconditionally.
|
||||||
|
if modprobe nls_utf8 >/dev/null 2>&1; then
|
||||||
|
opts="${opts},iocharset=utf8"
|
||||||
|
else
|
||||||
|
log_warning "This kernel ($(uname -r)) has no nls_utf8 module — mounting without iocharset=utf8. Non-ASCII filenames may not display correctly; try 'sudo apt-get install --reinstall linux-modules-$(uname -r)' to see if it restores the module."
|
||||||
|
fi
|
||||||
|
|
||||||
local share="//${host}/${share_name}"
|
local share="//${host}/${share_name}"
|
||||||
|
|
||||||
log_info "Testing mount..."
|
log_info "Testing mount..."
|
||||||
|
|||||||
@@ -29,7 +29,14 @@ ACTUAL_GID="$(id -g "$ACTUAL_USER")"
|
|||||||
ensure_packages() {
|
ensure_packages() {
|
||||||
local pkgs=()
|
local pkgs=()
|
||||||
case "$1" in
|
case "$1" in
|
||||||
smb) command -v mount.cifs &>/dev/null || pkgs+=(cifs-utils) ;;
|
smb)
|
||||||
|
command -v mount.cifs &>/dev/null || pkgs+=(cifs-utils)
|
||||||
|
# keyutils explicitly, not left to cifs-utils' Recommends — on
|
||||||
|
# images with install-recommends disabled, missing keyutils
|
||||||
|
# makes every mount.cifs call fail with "mount error(79): Can
|
||||||
|
# not access a needed shared library" regardless of credentials.
|
||||||
|
dpkg -s keyutils &>/dev/null || pkgs+=(keyutils)
|
||||||
|
;;
|
||||||
nfs) command -v mount.nfs &>/dev/null || pkgs+=(nfs-common) ;;
|
nfs) command -v mount.nfs &>/dev/null || pkgs+=(nfs-common) ;;
|
||||||
esac
|
esac
|
||||||
if [[ ${#pkgs[@]} -gt 0 ]]; then
|
if [[ ${#pkgs[@]} -gt 0 ]]; then
|
||||||
@@ -114,7 +121,19 @@ CREDS
|
|||||||
local ver_opt=""
|
local ver_opt=""
|
||||||
[[ -n "$smb_ver" ]] && ver_opt=",vers=${smb_ver}"
|
[[ -n "$smb_ver" ]] && ver_opt=",vers=${smb_ver}"
|
||||||
|
|
||||||
local opts="uid=${ACTUAL_UID},gid=${ACTUAL_GID},${creds_opt}${ver_opt},iocharset=utf8,nofail,_netdev"
|
local opts="uid=${ACTUAL_UID},gid=${ACTUAL_GID},${creds_opt}${ver_opt},nofail,_netdev"
|
||||||
|
|
||||||
|
# iocharset=utf8 only if the kernel can actually load nls_utf8 — some
|
||||||
|
# kernels (confirmed live: a stock Ubuntu 6.8.0-137-generic VPS) don't
|
||||||
|
# ship that module at all, and mount.cifs fails every such mount with
|
||||||
|
# "mount error(79): Can not access a needed shared library" regardless
|
||||||
|
# of credentials. modprobe on an already-loaded/built-in module is a
|
||||||
|
# harmless no-op, so this check is safe to run unconditionally.
|
||||||
|
if modprobe nls_utf8 >/dev/null 2>&1; then
|
||||||
|
opts="${opts},iocharset=utf8"
|
||||||
|
else
|
||||||
|
warn "This kernel ($(uname -r)) has no nls_utf8 module — mounting without iocharset=utf8. Non-ASCII filenames may not display correctly; try 'sudo apt-get install --reinstall linux-modules-$(uname -r)' to see if it restores the module."
|
||||||
|
fi
|
||||||
|
|
||||||
_do_mount "cifs" "$share" "$mount_point" "$opts"
|
_do_mount "cifs" "$share" "$mount_point" "$opts"
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user