mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Daniel Campos Ramos <Capitain_Jack@yahoo.com>
To: Jim Cromie <jim.cromie@gmail.com>
Cc: Lyude Paul <lyude@redhat.com>, Danilo Krummrich <dakr@kernel.org>,
	Maarten Lankhorst <maarten.lankhorst@linux.intel.com>,
	Maxime Ripard <mripard@kernel.org>,
	Thomas Zimmermann <tzimmermann@suse.de>,
	David Airlie <airlied@gmail.com>, Simona Vetter <simona@ffwll.ch>,
	dri-devel@lists.freedesktop.org, nouveau@lists.freedesktop.org,
	linux-kernel@vger.kernel.org, Zhenhao Wan <whi4ed0g@gmail.com>
Subject: Re: [PATCH 2/2] drm/nouveau: Fix NULL pointer dereference in GET_ZCULL_INFO ioctl
Date: Fri,  2 Oct 2026 14:18:17 -0300	[thread overview]
Message-ID: <20261002171818.281885-1-Capitain_Jack@yahoo.com> (raw)
In-Reply-To: <20260815-null-fixes-v1-2-0df9dda951fb@gmail.com>

Hi Jim, Lyude,

This one repeats here every time.
Setup: an RTX 3060 (GA106) passed through to a VM, kernel 7.3-rc1,
Mesa 26.1.6 (Debian testing), firmware-nvidia-gsp not installed.
nouveau probes with "gr: firmware unavailable", so nvxx_gr() is NULL.
As soon as KWin starts, Mesa's NVK asks for the zcull info and the
kernel oopses:

  BUG: kernel NULL pointer dereference, address: 00000000000000f0
  RIP: 0010:nouveau_abi16_ioctl_get_zcull_info+0x17/0xa0 [nouveau]
  Comm: kwin_wayland

kwin_wayland dies with it, so the whole session goes, not only
acceleration.

With this patch alone the zcull oops is gone, but the next NULL
dereference follows right away, in GETPARAM with
NOUVEAU_GETPARAM_GRAPH_UNITS:

  RIP: 0010:nvkm_gr_units+0x9/0x30 [nouveau]

With this patch plus Zhenhao Wan's "drm/nouveau: prevent NULL deref of
gr in GETPARAM_GRAPH_UNITS", there is no oops: KWin starts and
composites, and NVK refuses the device cleanly (vkEnumeratePhysicalDevices
returns VK_ERROR_INITIALIZATION_FAILED).

To reproduce: a Turing or newer card on nouveau without
firmware-nvidia-gsp, then start any Vulkan or zink client.
Both fixes are needed for a desktop to survive a missing firmware
package.
Whatever helped find it, the bug is real, it repeats, and the check is
the obvious one.

Disclosure: I did this testing with an AI assistant, Claude Code
(Claude Opus 5.5). It built the kernels, ran the VM and read the
traces under my direction; I checked the results on the hardware.

For this patch, tested together with Zhenhao's:

Tested-by: Daniel Campos Ramos <Capitain_Jack@yahoo.com>

Daniel

  reply	other threads:[~2026-10-02 17:18 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-15 17:30 [PATCH 0/2] drm/nouveau: Fix NULL pointer dereferences in GETPARAM and GET_ZCULL_INFO ioctls Jim Cromie
2026-08-15 17:30 ` [PATCH 1/2] drm/nouveau: Fix NULL pointer dereferences in GETPARAM ioctl Jim Cromie
2026-09-17 20:26   ` lyude
2026-09-18  4:52     ` jim.cromie
2026-08-15 17:30 ` [PATCH 2/2] drm/nouveau: Fix NULL pointer dereference in GET_ZCULL_INFO ioctl Jim Cromie
2026-10-02 17:18   ` Daniel Campos Ramos [this message]
2026-10-02 19:10     ` jim.cromie

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261002171818.281885-1-Capitain_Jack@yahoo.com \
    --to=capitain_jack@yahoo.com \
    --cc=airlied@gmail.com \
    --cc=dakr@kernel.org \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=jim.cromie@gmail.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=lyude@redhat.com \
    --cc=maarten.lankhorst@linux.intel.com \
    --cc=mripard@kernel.org \
    --cc=nouveau@lists.freedesktop.org \
    --cc=simona@ffwll.ch \
    --cc=tzimmermann@suse.de \
    --cc=whi4ed0g@gmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®