#801598 nvidia-graphics-drivers: nvidia devices created with permissions 0666 on boot

Package:
src:nvidia-graphics-drivers
Source:
nvidia-graphics-drivers
Submitter:
Andreas Beckmann
Date:
2025-08-17 17:48:01 UTC
Severity:
normal
Tags:
Blocked By:
Bug Title
801869

  11

nvidia-graphics-drivers: setting /dev/nvidia* to root:video 0660 breaks gdm3, sddm, ...

normal stable testing unstable 11 months ago

#801598#5
Date:
2015-10-12 11:53:45 UTC
From:
To:
Even though /etc/modprobe.d/nvidia-kernel-common.conf sets the
permissions and owner to root:video 0660, the devices are created
acessible by all local users: root:root 0666.


Andreas

#801598#10
Date:
2015-10-13 22:25:36 UTC
From:
To:
[CC'ed 801598 so that relevant info appears there too]

Downgraded and booted with "debug", and systemd got A LOT more
verbose :-)

But it was very useful, as digging through the log I figured out what is
loading the module. As you suspected, it's udev. More precisely, it's
this systemd unit at boot:

/lib/systemd/system/systemd-udev-trigger.service

And even more precisely, this udevadm call by that unit:

udevadm trigger --type=devices --action=add

If I remove that command from the service and reboot, the nvidia module
is still loaded and the devices are still created but with 660
root:video permissions/ownership (so Gnome oopses as expected).

So, how are we going to deal with this?

Kind regards,
Luca Boccassi

#801598#15
Date:
2015-10-14 10:29:18 UTC
From:
To:
Thanks for verifying.

Can you check whether the behavior is the same if the system runs under
sysv instead of systemd?


Andreas

#801598#20
Date:
2015-10-14 11:36:15 UTC
From:
To:
Ok, I'll give it a shot later tonight.

Kind regards,
Luca Boccassi

#801598#25
Date:
2015-10-14 21:04:37 UTC
From:
To:
It is. The equivalent when booting with sysv is the /etc/init.d/udev
script. By commenting out the "udevadm trigger --action=add" call (line
206) the exact same happens as with systemd, the module is loaded and
the devices have permissions 660 root:video.

Kind regards,
Luca Boccassi

#801598#32
Date:
2015-10-15 17:57:35 UTC
From:
To:
A proper solution will probably include patching nv-reg.h to set our
preferred defaults.


Andreas

#801598#37
Date:
2015-10-15 18:02:28 UTC
From:
To:
The uploads I did today have disabled the aliases in
nvidia-modprobe.conf again to better investigate this issue without
breaking to many systems out there ...
That also means co-installation of current and legacy packages is not
working as intended because the wrong kernel module will be loaded.


Andreas

#801598#44
Date:
2015-10-21 14:44:11 UTC
From:
To:
Control: severity -1 normal
since restricting this to root:video 0660 causes too much trouble.
Therefore downgrading the severity. But we would still be interested in
a working solution with more restricted permissions.


Andreas

#801598#59
Date:
2022-04-17 03:35:13 UTC
From:
To:
First Capital Bank.
7575 Poplar Avenue Garmantown, TN 38138,
United States of America.


Date: 15 th April, 2022.

From the desk of: Mr. Greg Wingo
                  Executive Vice President / Senior Lender,
                  First Capital Bank, Germantown TN - United States.

A t t n :,

This is to officially inform you that we have concluded as promised,
regarding your fund as instructed, in order to release your funds
immediately as already approved, well note that your funds have been
approved for immediate release via online, soon we hear from you we will
provide you with the online details for instant access.

As a matter of urgency, we urgently needs you to reconfirm the below
details while you attach scan copy of your identity for final
documentations which is the final stage of your fund transfer as your
online account details will be provided to you.

F u l l Name:
Address:
P h o n e:
Date of Birth:
Scan Copy of your valid I d e n t i t y:
Your f u l l Bank D e t a i l s:

Thank you for choosing to bank in your best interest while in
anticipation of your response, soon we hear from you, we will update you
with the next procedure since all the legal documentations have been
properly documented.

Yours in service,

Mr. Greg Wingo