From: Daniel Campos Ramos <Capitain_Jack@yahoo.com>
To: Jim Cromie <jim.cromie@gmail.com>
Cc: Lyude Paul <lyude@redhat.com>, Danilo Krummrich <dakr@kernel.org>,
Maarten Lankhorst <maarten.lankhorst@linux.intel.com>,
Maxime Ripard <mripard@kernel.org>,
Thomas Zimmermann <tzimmermann@suse.de>,
David Airlie <airlied@gmail.com>, Simona Vetter <simona@ffwll.ch>,
dri-devel@lists.freedesktop.org, nouveau@lists.freedesktop.org,
linux-kernel@vger.kernel.org, Zhenhao Wan <whi4ed0g@gmail.com>
Subject: Re: [PATCH 2/2] drm/nouveau: Fix NULL pointer dereference in GET_ZCULL_INFO ioctl
Date: Fri, 2 Oct 2026 14:18:17 -0300 [thread overview]
Message-ID: <20261002171818.281885-1-Capitain_Jack@yahoo.com> (raw)
In-Reply-To: <20260815-null-fixes-v1-2-0df9dda951fb@gmail.com>
Hi Jim, Lyude,
This one repeats here every time.
Setup: an RTX 3060 (GA106) passed through to a VM, kernel 7.3-rc1,
Mesa 26.1.6 (Debian testing), firmware-nvidia-gsp not installed.
nouveau probes with "gr: firmware unavailable", so nvxx_gr() is NULL.
As soon as KWin starts, Mesa's NVK asks for the zcull info and the
kernel oopses:
BUG: kernel NULL pointer dereference, address: 00000000000000f0
RIP: 0010:nouveau_abi16_ioctl_get_zcull_info+0x17/0xa0 [nouveau]
Comm: kwin_wayland
kwin_wayland dies with it, so the whole session goes, not only
acceleration.
With this patch alone the zcull oops is gone, but the next NULL
dereference follows right away, in GETPARAM with
NOUVEAU_GETPARAM_GRAPH_UNITS:
RIP: 0010:nvkm_gr_units+0x9/0x30 [nouveau]
With this patch plus Zhenhao Wan's "drm/nouveau: prevent NULL deref of
gr in GETPARAM_GRAPH_UNITS", there is no oops: KWin starts and
composites, and NVK refuses the device cleanly (vkEnumeratePhysicalDevices
returns VK_ERROR_INITIALIZATION_FAILED).
To reproduce: a Turing or newer card on nouveau without
firmware-nvidia-gsp, then start any Vulkan or zink client.
Both fixes are needed for a desktop to survive a missing firmware
package.
Whatever helped find it, the bug is real, it repeats, and the check is
the obvious one.
Disclosure: I did this testing with an AI assistant, Claude Code
(Claude Opus 5.5). It built the kernels, ran the VM and read the
traces under my direction; I checked the results on the hardware.
For this patch, tested together with Zhenhao's:
Tested-by: Daniel Campos Ramos <Capitain_Jack@yahoo.com>
Daniel
next prev parent reply other threads:[~2026-10-02 17:18 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-15 17:30 [PATCH 0/2] drm/nouveau: Fix NULL pointer dereferences in GETPARAM and GET_ZCULL_INFO ioctls Jim Cromie
2026-08-15 17:30 ` [PATCH 1/2] drm/nouveau: Fix NULL pointer dereferences in GETPARAM ioctl Jim Cromie
2026-09-17 20:26 ` lyude
2026-09-18 4:52 ` jim.cromie
2026-08-15 17:30 ` [PATCH 2/2] drm/nouveau: Fix NULL pointer dereference in GET_ZCULL_INFO ioctl Jim Cromie
2026-10-02 17:18 ` Daniel Campos Ramos [this message]
2026-10-02 19:10 ` jim.cromie
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261002171818.281885-1-Capitain_Jack@yahoo.com \
--to=capitain_jack@yahoo.com \
--cc=airlied@gmail.com \
--cc=dakr@kernel.org \
--cc=dri-devel@lists.freedesktop.org \
--cc=jim.cromie@gmail.com \
--cc=linux-kernel@vger.kernel.org \
--cc=lyude@redhat.com \
--cc=maarten.lankhorst@linux.intel.com \
--cc=mripard@kernel.org \
--cc=nouveau@lists.freedesktop.org \
--cc=simona@ffwll.ch \
--cc=tzimmermann@suse.de \
--cc=whi4ed0g@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®