Re: [PATCH 2/2] drm/nouveau: Fix NULL pointer dereference in GET_ZCULL_INFO ioctl
From: jim . cromie
Date: Fri Oct 02 2026 - 15:10:50 EST
hi Daniel,
thanks for testing this -
I didnt want to screw with my firmware,
but you're clearly prepared to do so.
I just sent rev-3, with another null-ptr fix I need locally.
Im pretty certain the patch you tested is unchanged,
but if you could test rev3 that would be marvelous.
fwiw - mine is a GA107
01:00.0 VGA compatible controller: NVIDIA Corporation GA107M [GeForce
RTX 3050 Ti Mobile] (rev a1) (prog-if 00 [VGA controller])
Subsystem: ASUSTeK Computer Inc. Device 125c
Physical Slot: 0
Control: I/O+ Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr-
Stepping- SERR- FastB2B- DisINTx+
Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort-
<TAbort- <MAbort- >SERR- <PERR- INTx-
Latency: 0, Cache Line Size: 64 bytes
Interrupts: pin B disabled, MSI(X) routed to IRQ 101
IOMMU group: 10
Region 0: Memory at fb000000 (32-bit, non-prefetchable) [size=16M]
Region 1: Memory at fe00000000 (64-bit, prefetchable) [size=4G]
Region 3: Memory at ff00000000 (64-bit, prefetchable) [size=32M]
Region 5: I/O ports at f000 [size=128]
Expansion ROM at fc000000 [disabled] [size=512K]
Capabilities: <access denied>
Kernel driver in use: nouveau
Kernel modules: nouveau
On Fri, Oct 2, 2026 at 11:18 AM Daniel Campos Ramos
<Capitain_Jack@xxxxxxxxx> wrote:
>
> Hi Jim, Lyude,
>
> This one repeats here every time.
> Setup: an RTX 3060 (GA106) passed through to a VM, kernel 7.3-rc1,
> Mesa 26.1.6 (Debian testing), firmware-nvidia-gsp not installed.
> nouveau probes with "gr: firmware unavailable", so nvxx_gr() is NULL.
> As soon as KWin starts, Mesa's NVK asks for the zcull info and the
> kernel oopses:
>
> BUG: kernel NULL pointer dereference, address: 00000000000000f0
> RIP: 0010:nouveau_abi16_ioctl_get_zcull_info+0x17/0xa0 [nouveau]
> Comm: kwin_wayland
>
> kwin_wayland dies with it, so the whole session goes, not only
> acceleration.
>
> With this patch alone the zcull oops is gone, but the next NULL
> dereference follows right away, in GETPARAM with
> NOUVEAU_GETPARAM_GRAPH_UNITS:
>
> RIP: 0010:nvkm_gr_units+0x9/0x30 [nouveau]
>
> With this patch plus Zhenhao Wan's "drm/nouveau: prevent NULL deref of
> gr in GETPARAM_GRAPH_UNITS", there is no oops: KWin starts and
> composites, and NVK refuses the device cleanly (vkEnumeratePhysicalDevices
> returns VK_ERROR_INITIALIZATION_FAILED).
>
> To reproduce: a Turing or newer card on nouveau without
> firmware-nvidia-gsp, then start any Vulkan or zink client.
> Both fixes are needed for a desktop to survive a missing firmware
> package.
> Whatever helped find it, the bug is real, it repeats, and the check is
> the obvious one.
>
> Disclosure: I did this testing with an AI assistant, Claude Code
> (Claude Opus 5.5). It built the kernels, ran the VM and read the
> traces under my direction; I checked the results on the hardware.
>
> For this patch, tested together with Zhenhao's:
>
> Tested-by: Daniel Campos Ramos <Capitain_Jack@xxxxxxxxx>
>
> Daniel