Skip to content

[BUG] KMS: DRM_IOCTL_MODE_CREATE_DUMB failed: Permission denied #3

Description

@Joly0

Is there an existing issue for this?

  • I have searched the existing issues

Current Behavior

Hey, i just read that nvidia support should be included. I had this container previously running without nvidia support (or any GPU passed at all) and the container run without issues (if you call 0.5-1 fps "running").
Now after running the command nvidia-modprobe --modeset on my unraid host and then running the container with the nvidia gpu passed through like shown in my docker run, the container is not starting correctly anymore.

Expected Behavior

Should run with nvidia support

Steps To Reproduce

  1. Install the cotnainer with nvidia gpu on unraid
  2. See error

Environment

- OS: Unraid
- How docker service was installed:

CPU architecture

x86-64

Docker creation

docker run
  -d
  --name='steam'
  --net='bridge'
  --pids-limit 2048
  -e TZ="Europe/Berlin"
  -e HOST_OS="Unraid"
  -e HOST_HOSTNAME="Tower"
  -e HOST_CONTAINERNAME="steam"
  -e 'PUID'='99'
  -e 'PGID'='100'
  -e 'UMASK'='022'
  -l net.unraid.docker.managed=dockerman
  -l net.unraid.docker.webui='https://[IP]:[PORT:3001]'
  -l net.unraid.docker.icon='https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/steam-logo.png'
  -p '30001:3000/tcp'
  -p '30011:3001/tcp'
  -v '/mnt/cache/appdata/steam':'/config':'rw'
  --shm-size=1gb
  --security-opt seccomp=unconfined
  --gpus all
  --runtime nvidia 'lscr.io/linuxserver/steam'

Container logs

thread '<unnamed>' panicked at src/lib.rs:354:14:
Failed to allocate GBM buffer: Os { code: 13, kind: PermissionDenied, message: "Permission denied" }
note: run with `RUST_BACKTRACE=1` environment variable to display a backtrace
[svc-de] Wayland mode: Waiting for socket at /config/.XDG/wayland-1...
[svc-de] /config/.XDG/wayland-1 found launching de
No desktop processes found to terminate.
INFO:selkies.__main__:Starting mode 'websockets'...
INFO:selkies.__main__:Starting Selkies in 'websockets' mode.
INFO:data_websocket:pcmflux library found. Audio capture is available.
INFO:data_websocket:pixelflux library found. Striped encoding modes available.
[Wayland] Initializing GL Renderer using device: /dev/dri/renderD128
[svc-de] Wayland mode: Waiting for socket at /config/.XDG/wayland-1...
[svc-de] /config/.XDG/wayland-1 found launching de
INFO:root:Expected C js_config_t size (from ctypes): 1354 bytes
No desktop processes found to terminate.
[Wayland] Warning: Failed to bind EGL to Wayland Display (Optional): EglExtensionNotSupported(["EGL_WL_bind_wayland_display"])
KMS: DRM_IOCTL_MODE_CREATE_DUMB failed: Permission denied

thread '<unnamed>' panicked at src/lib.rs:354:14:
Failed to allocate GBM buffer: Os { code: 13, kind: PermissionDenied, message: "Permission denied" }
note: run with `RUST_BACKTRACE=1` environment variable to display a backtrace
[svc-de] Wayland mode: Waiting for socket at /config/.XDG/wayland-1...
[svc-de] /config/.XDG/wayland-1 found launching de
No desktop processes found to terminate.
INFO:selkies.__main__:Starting mode 'websockets'...
INFO:selkies.__main__:Starting Selkies in 'websockets' mode.
INFO:data_websocket:pcmflux library found. Audio capture is available.
INFO:data_websocket:pixelflux library found. Striped encoding modes available.
[Wayland] Initializing GL Renderer using device: /dev/dri/renderD128
INFO:root:Expected C js_config_t size (from ctypes): 1354 bytes
[Wayland] Warning: Failed to bind EGL to Wayland Display (Optional): EglExtensionNotSupported(["EGL_WL_bind_wayland_display"])
KMS: DRM_IOCTL_MODE_CREATE_DUMB failed: Permission denied

Activity

  1. github-actions commented on Jan 19, 2026

    @github-actions

    Thanks for opening your first issue here! Be sure to follow the relevant issue templates, or risk having this issue marked as invalid.

  2. thelamer commented on Jan 25, 2026

    @thelamer
    Member

    I test on Trixie and Arch with a 3060 and 580.126.09 proprietary drivers.

    Make sure your nvidia card is /dev/dri/renderD128 and make sure you are running the latest proprietary driver for your card.

    Also I do not know unraid but you might need apparmor unconfined.

  3. LinuxServer-CI commented on Feb 25, 2026

    @LinuxServer-CI
    Contributor

    This issue has been automatically marked as stale because it has not had recent activity. This might be due to missing feedback from OP. It will be closed if no further activity occurs. Thank you for your contributions.

  4. Joly0 commented on Feb 26, 2026

    @Joly0
    Author

    Hey, i am sorry for letting this stale.
    So yes, i made sure my nvidia gpu is renderD128:
    Image

    Should also be latest available driver:
    Image

    and as far as i know, unraid doesnt contain anything like apparmor

  5. thelamer commented on Mar 19, 2026

    @thelamer
    Member

    Updated docs from an unraid user that got it working

    1. Driver: Proprietary drivers 580 or higher are required. Crucially, you should install the driver using the .run file downloaded directly from the Nvidia website.

      • Unraid: Use the production branch from the Nvidia Driver Plugin.
    2. Kernel Parameter: You must set nvidia-drm.modeset=1 in your host bootloader.

      • Standard Linux (GRUB): Edit /etc/default/grub and add the parameter to your existing GRUB_CMDLINE_LINUX_DEFAULT line:
        GRUB_CMDLINE_LINUX_DEFAULT="<other existing options> nvidia-drm.modeset=1"
        
        Then apply the changes by running:
        sudo update-grub
      • Unraid (Syslinux): Edit the file /boot/syslinux/syslinux.cfg and add nvidia-drm.modeset=1 to the end of the append line for the Unraid OS boot entry.
    3. Hardware Initialization: On headless systems, the Nvidia video card requires a physical dummy plug inserted into the GPU so that DRM initializes properly.

    4. Docker Runtime: Configure the host docker daemon to use the Nvidia runtime:

      sudo nvidia-ctk runtime configure --runtime=docker
      sudo systemctl restart docker

    Compose Configuration:

    ---
    services:
      {{ project_name }}:
        image: lscr.io/{{ lsio_project_name_short }}/{{ project_name }}:{{ release_tag }}
        environment:
          - PIXELFLUX_WAYLAND=true
          # Ensure these point to the rendered node injected by the runtime (usually renderD128)
          - DRINODE=/dev/dri/renderD128
          - DRI_NODE=/dev/dri/renderD128
        deploy:
          resources:
            reservations:
              devices:
                - driver: nvidia
                  count: 1
                  capabilities: [compute,video,graphics,utility]
    • Unraid: Ensure you're properly setting the DRINODE, DRI_NODE and adding --gpus all --runtime nvidia to your extra parameters.
  6. Joly0 commented on Mar 21, 2026

    @Joly0
    Author

    Hey @thelamer thanks for letting me know, but everythign was already configured for me exactly as you described.
    I have the hdmi dummy in the nvidia gpu, the driver is correct, the nvidia-drm.modeset=1 boot option is set and even rebooted, all the env variables are set properly and yet i am still getting the same error as initially posted.

  7. thelamer commented on Mar 21, 2026

    @thelamer
    Member

    check dmesg you are looking for

    [   14.365976] [drm] [nvidia-drm] [GPU ID 0x00000700] Loading driver
    [   16.311576] [drm] Initialized nvidia-drm 0.0.0 for 0000:07:00.0 on minor 1
    [   16.476157] fbcon: nvidia-drmdrmfb (fb0) is primary device
    [   16.572517] nvidia 0000:07:00.0: [drm] fb0: nvidia-drmdrmfb frame buffer device
    

    Just in general post the output of sudo dmesg |grep -i nvidia |grep -i drm

    Also use a bare run command from cli to test.

    docker run --rm -it -p 3001:3001 -e DRINODE=/dev/dri/renderD129 -e DRI_NODE=/dev/dri/renderD129 --runtime nvidia --gpus all --shm-size=1gb linuxserver/eden bash
    

    my card is 129 on my system, you open a terminal and run vkcube as a smoke test (that is if you do not get permission denied. )

    2026-03-18.19-06-52.mp4

    It can work and the user that confirmed it was on 580.142 and running a 4070 so it is not your card series or anything.

  8. Joly0 commented on Mar 21, 2026

    @Joly0
    Author
    root@Tower:~# dmesg |grep -i nvidia |grep -i drm
    [    0.000000] Command line: BOOT_IMAGE=/bzimage pcie_acs_override=downstream,multifunction vfio_iommu_type1.allow_unsafe_interrupts=1 initrd=/bzroot amd_pstate=guided initcall_blacklist=acpi_cpufreq_init nvidia-drm.modeset=1
    [    0.059183] Kernel command line: BOOT_IMAGE=/bzimage pcie_acs_override=downstream,multifunction vfio_iommu_type1.allow_unsafe_interrupts=1 initrd=/bzroot amd_pstate=guided initcall_blacklist=acpi_cpufreq_init nvidia-drm.modeset=1
    [   61.338106] [drm] [nvidia-drm] [GPU ID 0x00000100] Loading driver
    [   62.719948] [drm] Initialized nvidia-drm 0.0.0 for 0000:01:00.0 on minor 0
    [   62.832020] nvidia 0000:01:00.0: [drm] fb1: nvidia-drmdrmfb frame buffer device
    

    your example docker run command has the same problem.

  9. thelamer commented on Mar 21, 2026

    @thelamer
    Member

    bump from 126 to 142 (is the production driver in unraid)

    Confirm you ran the command with render node 128 and double check that is your nvidia card.

    [   16.476157] fbcon: nvidia-drmdrmfb (fb0) is primary device
    

    This is not in dmesg I do not know if that matters or not.

    If you have discord review this back and forth see if anything is missing they do have a primary device message in their logs, this is the user that confirmed functionality:

    https://discord.com/channels/354974912613449730/1433842457048514684/1484231076418424854

    I am just diffing out from the user that got it working vs your setup.

  10. thelamer commented on Mar 21, 2026

    @thelamer
    Member

    Another thing make sure kernel is above 6.6 (it should be). The working user was on 6.12.54-Unraid

  11. Joly0 commented on Mar 21, 2026

    @Joly0
    Author

    Yes, i am also on 6.12.54-Unraid
    I have now added a comment referencing the original reporter on github, maybe he can bring light into this

  12. thelamer commented on Apr 14, 2026

    @thelamer
    Member

    Just FYI I have discovered that unraid nvidia runtime is not compatible with wayland based solutions:

    linuxserver/docker-jenkins-builder#393

    Readme will be updated soon.

  13. moved this from Issues to Done in Issue & PR Trackeron Apr 14, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions