Fix CIFS mount error(79) caused by missing nls_utf8 kernel module

The keyutils fix alone didn't resolve it — confirmed live with keyutils
already installed, the same error persisted. Root cause: the hardcoded
iocharset=utf8 mount option requires the kernel's nls_utf8 module, which
some kernels don't ship at all (confirmed live: `modprobe nls_utf8` on a
stock Ubuntu 6.8.0-137-generic VPS kernel returns "FATAL: Module
nls_utf8 not found" — not loadable, not built in). Every such mount
fails with errno 79 (ELIBACC) regardless of credentials, which is why
this recurred identically after the keyutils fix.

Both vpn-data-mount.sh and mount-network-drive.sh now probe with a
harmless `modprobe nls_utf8` before adding the option, and mount without
it (falling back to the kernel's build-time nls_default) with a clear
warning if the module isn't available, instead of hard-failing.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01H4k6J1qXXyYxhGEgnJaMvn
This commit is contained in:
Claude
2026-08-10 20:11:05 +00:00
parent 2d9501a56c
commit 9e886ff9a7
2 changed files with 45 additions and 14 deletions
+32 -13
View File
@@ -51,17 +51,26 @@
# literal strerror() text for it. Confirmed live: this recurred identically # literal strerror() text for it. Confirmed live: this recurred identically
# with a real Samba account and a verified, correctly-captured password # with a real Samba account and a verified, correctly-captured password
# (see the read()/IFS note above — that was a real bug too, just not this # (see the read()/IFS note above — that was a real bug too, just not this
# one). Root cause is the `keyutils` package being missing on the client # one), and again after keyutils was already installed — so it's not that
# (VPS) side: mount.cifs dlopen()s libkeyutils.so.1 at runtime for the # either, at least not on every host. Two independent real causes share
# upcall path (idmapping/SPNEGO), and while cifs-utils hard-depends on the # this exact errno/message, both fixed defensively below:
# libkeyutils1 *library*, the keyutils *package* — which ships # 1. `keyutils` missing on the client. cifs-utils hard-depends on the
# /sbin/request-key and the /etc/request-key.d/*.conf handler # libkeyutils1 *library* but only Recommends the keyutils *package*
# registrations the kernel's upcall actually invokes — is only a Recommends. # (/sbin/request-key + /etc/request-key.d/*.conf, what the kernel's
# Plenty of minimal cloud VPS images (unlike a typical desktop/full-server # upcall actually invokes) — minimal cloud images that disable
# install) turn off APT's install-recommends, so `apt-get install # install-recommends silently skip it.
# cifs-utils` alone silently skips it and every mount — guest or fully # 2. The hardcoded `iocharset=utf8` mount option needs the kernel's
# credentialed — fails the same way. Install `keyutils` explicitly instead # nls_utf8 module. Confirmed live on a stock Ubuntu 6.8.0-137-generic
# of relying on it riding along. # VPS kernel: `modprobe nls_utf8` → "FATAL: Module nls_utf8 not found"
# — not loadable, not built in, just absent from that kernel build.
# Every mount asking for that codepage fails with errno 79 regardless
# of credentials. `_vdm_mount_local` probes for it with a harmless
# `modprobe` and only adds `iocharset=utf8` if it actually loads;
# otherwise it warns and mounts without it (kernel falls back to its
# build's nls_default — fine for ASCII-heavy filenames, the common
# case for a home-data share; non-ASCII filenames may not round-trip
# perfectly on a kernel missing this module, which is a kernel
# limitation this script can't paper over further).
# ── Standalone bootstrap ────────────────────────────────────────────────────── # ── Standalone bootstrap ──────────────────────────────────────────────────────
if [[ "${BASH_SOURCE[0]}" == "${0}" ]]; then if [[ "${BASH_SOURCE[0]}" == "${0}" ]]; then
@@ -353,8 +362,18 @@ CREDS
chmod 600 "$creds_file" chmod 600 "$creds_file"
chown root:root "$creds_file" chown root:root "$creds_file"
# sec=ntlmssp explicitly — see the file header on errno 79/ENOKEY. # sec=ntlmssp explicitly — see the file header on errno 79.
local opts="credentials=${creds_file},sec=ntlmssp,uid=$(id -u "$ACTUAL_USER"),gid=$(id -g "$ACTUAL_USER"),iocharset=utf8,nofail,_netdev" local opts="credentials=${creds_file},sec=ntlmssp,uid=$(id -u "$ACTUAL_USER"),gid=$(id -g "$ACTUAL_USER"),nofail,_netdev"
# iocharset=utf8 only if the kernel can actually load nls_utf8 — see
# the file header. modprobe on an already-loaded/built-in module is a
# harmless no-op, so this is safe to call unconditionally.
if modprobe nls_utf8 >/dev/null 2>&1; then
opts="${opts},iocharset=utf8"
else
log_warning "This kernel ($(uname -r)) has no nls_utf8 module — mounting without iocharset=utf8. Non-ASCII filenames may not display correctly; try 'sudo apt-get install --reinstall linux-modules-$(uname -r)' to see if it restores the module."
fi
local share="//${host}/${share_name}" local share="//${host}/${share_name}"
log_info "Testing mount..." log_info "Testing mount..."
+13 -1
View File
@@ -121,7 +121,19 @@ CREDS
local ver_opt="" local ver_opt=""
[[ -n "$smb_ver" ]] && ver_opt=",vers=${smb_ver}" [[ -n "$smb_ver" ]] && ver_opt=",vers=${smb_ver}"
local opts="uid=${ACTUAL_UID},gid=${ACTUAL_GID},${creds_opt}${ver_opt},iocharset=utf8,nofail,_netdev" local opts="uid=${ACTUAL_UID},gid=${ACTUAL_GID},${creds_opt}${ver_opt},nofail,_netdev"
# iocharset=utf8 only if the kernel can actually load nls_utf8 — some
# kernels (confirmed live: a stock Ubuntu 6.8.0-137-generic VPS) don't
# ship that module at all, and mount.cifs fails every such mount with
# "mount error(79): Can not access a needed shared library" regardless
# of credentials. modprobe on an already-loaded/built-in module is a
# harmless no-op, so this check is safe to run unconditionally.
if modprobe nls_utf8 >/dev/null 2>&1; then
opts="${opts},iocharset=utf8"
else
warn "This kernel ($(uname -r)) has no nls_utf8 module — mounting without iocharset=utf8. Non-ASCII filenames may not display correctly; try 'sudo apt-get install --reinstall linux-modules-$(uname -r)' to see if it restores the module."
fi
_do_mount "cifs" "$share" "$mount_point" "$opts" _do_mount "cifs" "$share" "$mount_point" "$opts"
} }