Fix CIFS mount error(79) caused by missing keyutils package

Errno 79 is ELIBACC ("Can not access a needed shared library"), not
ENOKEY as previously assumed — mount.cifs prints glibc's literal
strerror() text for it. It recurred with valid, correctly-captured
credentials because the real cause was never authentication: cifs-utils
hard-depends on the libkeyutils1 library but only Recommends the
keyutils package itself, which ships /sbin/request-key and the
/etc/request-key.d/*.conf handlers the kernel's upcall path invokes.
Minimal cloud VPS images commonly disable install-recommends, so
`apt-get install cifs-utils` alone silently skips it and every mount —
guest or fully credentialed — fails identically.

Install keyutils explicitly wherever cifs-utils is installed:
services/base.sh's unconditional package list, vpn-data-mount.sh's
lazy install-on-mount path, and tools/mount-network-drive.sh's SMB
branch.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01H4k6J1qXXyYxhGEgnJaMvn
This commit is contained in:
Claude
2026-08-10 20:00:24 +00:00
parent 1c1fa32b6f
commit 2d9501a56c
3 changed files with 39 additions and 10 deletions
+8 -3
View File
@@ -27,14 +27,19 @@ install_base() {
run_cmd apt-get update -y run_cmd apt-get update -y
# Core utilities present on every install. cifs-utils here (not lazily # Core utilities present on every install. cifs-utils/keyutils here (not
# installed on first use, the way tools/mount-network-drive.sh and # lazily installed on first use, the way tools/mount-network-drive.sh and
# vpn-data-mount.sh's own local-mount step would otherwise do it) so SMB # vpn-data-mount.sh's own local-mount step would otherwise do it) so SMB
# mounts work immediately whenever they're set up later, same reasoning # mounts work immediately whenever they're set up later, same reasoning
# as Docker/Compose being unconditional here instead of on-demand. # as Docker/Compose being unconditional here instead of on-demand.
# keyutils explicitly, not left to cifs-utils' Recommends — some minimal
# cloud VPS images disable install-recommends, and without keyutils'
# /etc/request-key.d handlers every mount.cifs call (guest or fully
# credentialed) fails with "mount error(79): Can not access a needed
# shared library" regardless of the password being correct.
run_cmd apt-get install -y \ run_cmd apt-get install -y \
net-tools ncdu git curl wget htop btop tree zip unzip \ net-tools ncdu git curl wget htop btop tree zip unzip \
ca-certificates gnupg jq rsync ssh-import-id cifs-utils \ ca-certificates gnupg jq rsync ssh-import-id cifs-utils keyutils \
|| log_warning "Some essential packages failed to install" || log_warning "Some essential packages failed to install"
# glow — terminal markdown reader (charmbracelet). Not in Ubuntu repos, # glow — terminal markdown reader (charmbracelet). Not in Ubuntu repos,
+23 -6
View File
@@ -43,12 +43,25 @@
# Mounts use real Samba credentials (a username/password you provide for # Mounts use real Samba credentials (a username/password you provide for
# an account that already exists on the home box), stored locally in a # an account that already exists on the home box), stored locally in a
# root-only credentials file, same convention tools/mount-network-drive.sh # root-only credentials file, same convention tools/mount-network-drive.sh
# already uses — never guest access. A CIFS guest mount with no explicit # already uses — never guest access.
# security mode can hit "mount error(79): Can not access a needed shared #
# library" — a misleadingly-worded cifs-utils message for errno 79 # "mount error(79): Can not access a needed shared library" is NOT a
# (ENOKEY), a known rough edge in the kernel cifs.ko keyring/upcall path # credentials problem, guest-vs-authenticated problem, or a mislabeled
# for anonymous sessions. Credentialed mounts with an explicit sec=ntlmssp # ENOKEY — errno 79 is literally ELIBACC, and mount.cifs prints glibc's
# take the normal NTLMSSP auth path instead and don't hit it. # literal strerror() text for it. Confirmed live: this recurred identically
# with a real Samba account and a verified, correctly-captured password
# (see the read()/IFS note above — that was a real bug too, just not this
# one). Root cause is the `keyutils` package being missing on the client
# (VPS) side: mount.cifs dlopen()s libkeyutils.so.1 at runtime for the
# upcall path (idmapping/SPNEGO), and while cifs-utils hard-depends on the
# libkeyutils1 *library*, the keyutils *package* — which ships
# /sbin/request-key and the /etc/request-key.d/*.conf handler
# registrations the kernel's upcall actually invokes — is only a Recommends.
# Plenty of minimal cloud VPS images (unlike a typical desktop/full-server
# install) turn off APT's install-recommends, so `apt-get install
# cifs-utils` alone silently skips it and every mount — guest or fully
# credentialed — fails the same way. Install `keyutils` explicitly instead
# of relying on it riding along.
# ── Standalone bootstrap ────────────────────────────────────────────────────── # ── Standalone bootstrap ──────────────────────────────────────────────────────
if [[ "${BASH_SOURCE[0]}" == "${0}" ]]; then if [[ "${BASH_SOURCE[0]}" == "${0}" ]]; then
@@ -322,6 +335,10 @@ _vdm_mount_local() {
local host="$1" share_name="$2" mount_point="$3" label="$4" smb_user="$5" smb_pass="$6" local host="$1" share_name="$2" mount_point="$3" label="$4" smb_user="$5" smb_pass="$6"
command -v mount.cifs >/dev/null 2>&1 || apt-get install -y cifs-utils -qq command -v mount.cifs >/dev/null 2>&1 || apt-get install -y cifs-utils -qq
# Explicit, not left to cifs-utils' Recommends — see file header on
# errno 79/ELIBACC. dpkg -s (not command -v: keyutils ships no binary
# this script calls directly, just the request-key handler files).
dpkg -s keyutils >/dev/null 2>&1 || apt-get install -y keyutils -qq
mkdir -p "$mount_point" mkdir -p "$mount_point"
+8 -1
View File
@@ -29,7 +29,14 @@ ACTUAL_GID="$(id -g "$ACTUAL_USER")"
ensure_packages() { ensure_packages() {
local pkgs=() local pkgs=()
case "$1" in case "$1" in
smb) command -v mount.cifs &>/dev/null || pkgs+=(cifs-utils) ;; smb)
command -v mount.cifs &>/dev/null || pkgs+=(cifs-utils)
# keyutils explicitly, not left to cifs-utils' Recommends — on
# images with install-recommends disabled, missing keyutils
# makes every mount.cifs call fail with "mount error(79): Can
# not access a needed shared library" regardless of credentials.
dpkg -s keyutils &>/dev/null || pkgs+=(keyutils)
;;
nfs) command -v mount.nfs &>/dev/null || pkgs+=(nfs-common) ;; nfs) command -v mount.nfs &>/dev/null || pkgs+=(nfs-common) ;;
esac esac
if [[ ${#pkgs[@]} -gt 0 ]]; then if [[ ${#pkgs[@]} -gt 0 ]]; then