nvidia-smi驱动故障修复

使用nvidia-smi查看报错如下

nvidia-smi NVIDIA-SMI has failed because it couldn't communicate with the NVIDIA driver. Make sure that the latest NVIDIA driver is installed and running.

故障原因
安装的版本和内核不对应
解决方法
自动安装驱动版本

ubuntu-drivers autoinstall

2026-09-22补充开始
有一台Ubuntu22.04服务器出现同样的问题使用上面方法无法修复
问了workbuddy给了一个脚本
脚本如下

#!/usr/bin/env bash
# ==============================================================================
# nvidia-fix.sh - fix "nvidia-smi: couldn't communicate with the NVIDIA driver"
#
# Verified root cause on host xiaoxing-MS-7D22:
#   Secure Boot is enabled -> kernel is in LOCKDOWN mode -> unsigned kernel
#   modules are refused. The nvidia.ko built by DKMS is unsigned, so modprobe
#   dies with "Operation not permitted" and the module never loads.
#
# Modes:
#   check    (default) read-only verdict + environment snapshot
#   verify   run nvidia-smi now and after a fix
#   signed   [RECOMMENDED] install Canonical-signed 595 modules, keep Secure Boot
#   dkms     rebuild + load the DKMS module (ONLY after Secure Boot is off)
#   clean    nuclear: purge every nvidia remnant, reinstall nvidia-driver-595-server
#
# Usage:  sudo bash nvidia-fix.sh check
#         sudo bash nvidia-fix.sh signed
#
# Nothing is modified unless you pass a mutating mode AND answer y at the prompt.
# ==============================================================================

set -u
MODE="${1:-check}"
DRIVER_BRANCH=595

b()  { printf '\n\033[1m%s\033[0m\n' "$*"; }
l()  { printf '%s\n' "--------------------------------------------------------------"; }
need_root() { [ "$(id -u)" -eq 0 ] || { echo "!! run this mode as root:  sudo bash $0 $MODE"; exit 1; }; }
confirm() { printf '%s [y/N] ' "$1"; read -r a; case "$a" in y|Y|yes|YES) return 0;; *) return 1;; esac; }

verdict() {
cat <<'EOF'
================================================================
 VERDICT - root cause is confirmed, not guessed
================================================================

  Secure Boot ........ enabled
  Kernel ............. 5.15.0-142-generic
  Driver installed ... 595.91.07 (nvidia-driver-595)
  DKMS module ........ BUILT OK for the running kernel
  Actual failure ..... modprobe: could not insert 'nvidia': Operation not permitted
                       Lockdown: modprobe: unsigned module loading is restricted

  THE CHAIN
    Secure Boot enabled
      -> kernel enters kernel_lockdown mode
      -> lockdown refuses to load UNSIGNED kernel modules
      -> DKMS compiled /lib/modules/.../updates/dkms/nvidia.ko WITHOUT a
         signature the firmware trusts
      -> the load is rejected before the module ever executes
      -> nvidia-smi has nothing to talk to

  This is why dmesg contains ZERO 'NVRM:' lines. The module is neither
  missing nor broken - it is being blocked at the door.

  !! SEPARATE FINDING - please confirm !!
  lspci reports  [10de:1e07] TU102 = GeForce RTX 2080 Ti, NOT an RTX 4090.
  That PCI ID is burned into the silicon and cannot be faked by a driver.
  Either this is not the machine you meant, or the card is not what you think.
  Check with:  sudo lspci -nn | grep -iE 'vga|3d|display'
EOF
}

snapshot() {
  b "environment snapshot"
  l
  echo "kernel        : $(uname -r)"
  echo "driver pkgs   : $(dpkg -l 2>/dev/null | grep -cE '^ii +(nvidia|libnvidia)-')"
  echo "dkms          : $(dkms status 2>/dev/null | tr '\n' ' ')"
  echo "secureboot    : $(mokutil --sb-state 2>&1)"
  echo "lockdown      : $(cat /sys/kernel/security/lockdown 2>/dev/null || echo 'n/a')"
  echo "module loaded : $(lsmod 2>/dev/null | grep -c '^nvidia')"
  echo "signed avail  : $(apt-cache policy linux-modules-nvidia-${DRIVER_BRANCH}-generic 2>/dev/null | grep Candidate | sed 's/^ *//')"
  echo "leftover trees: $(ls -d /lib/modules/$(uname -r)/kernel/nvidia-* 2>/dev/null | tr '\n' ' ')"
  echo "kernels       : $(ls -1 /lib/modules/ 2>/dev/null | tr '\n' ' ')"
}

do_verify() {
  b "verification"
  l
  echo "--- /proc/driver/nvidia/version ---"
  cat /proc/driver/nvidia/version 2>/dev/null || echo "  (unavailable - module still not loaded)"
  echo "--- lsmod ---"
  lsmod 2>/dev/null | grep '^nvidia' || echo "  (no nvidia module)"
  echo "--- nvidia-smi ---"
  nvidia-smi 2>&1 | head -15
}

case "$MODE" in

# ------------------------------------------------------------------------------
check)
  verdict
  snapshot
  b "what to do next"
  l
  cat <<'EOF'
  Option A (recommended, keeps Secure Boot ON, no BIOS trip needed):
      sudo bash nvidia-fix.sh signed
      sudo reboot
      sudo bash nvidia-fix.sh verify

  Option B (simplest, requires BIOS access):
      BIOS -> Security -> Secure Boot -> Disabled
      sudo bash nvidia-fix.sh dkms
      sudo reboot
      sudo bash nvidia-fix.sh verify

  Option C (only if A and B both fail, or the box is a version-sludge mess):
      sudo bash nvidia-fix.sh clean
EOF
  ;;

# ------------------------------------------------------------------------------
verify)
  do_verify
  ;;

# ------------------------------------------------------------------------------
signed)
  need_root
  verdict
  b "MODE: signed  -  install Canonical-signed ${DRIVER_BRANCH} modules"
  l
  PKG="linux-modules-nvidia-${DRIVER_BRANCH}-generic"
  CAND="$(apt-cache policy "$PKG" 2>/dev/null | awk '/Candidate:/{print $2}')"
  if [ -z "$CAND" ] || [ "$CAND" = "(none)" ]; then
    echo "!! $PKG is not available in the archive for this kernel."
    echo "   Canonical has not published signed ${DRIVER_BRANCH} modules for $(uname -r) yet."
    echo "   -> use Option B instead (disable Secure Boot in BIOS, then:"
    echo "        sudo bash $0 dkms )"
    exit 1
  fi
  echo "Will install: $PKG ($CAND)"
  echo "It ships a Canonical-signed nvidia.ko and Conflicts with nvidia-dkms-${DRIVER_BRANCH},"
  echo "so apt will swap the unsigned DKMS module for the signed one automatically."
  echo "The userspace libs (libnvidia-*-${DRIVER_BRANCH}, nvidia-utils, CUDA) are untouched."
  confirm "proceed?" || { echo "aborted."; exit 0; }
  apt-get update
  apt-get install -y "$PKG" || { echo "!! install failed - switch to Option B ('dkms' mode)."; exit 1; }
  b "done - now reboot"
  l
  echo "  sudo reboot && sudo bash $0 verify"
  ;;

# ------------------------------------------------------------------------------
dkms)
  need_root
  b "MODE: dkms  -  rebuild and load the DKMS module"
  l
  if mokutil --sb-state 2>/dev/null | grep -qi 'SecureBoot enabled'; then
    echo "!! Secure Boot is STILL ENABLED. The unsigned DKMS module will be refused again."
    echo "   Disable Secure Boot in BIOS first, then re-run this mode."
    echo "   (Or use:  sudo bash $0 signed  -  that path keeps Secure Boot on.)"
    exit 1
  fi
  echo "Secure Boot is off. Rebuilding nvidia-dkms-${DRIVER_BRANCH} for $(uname -r)."
  confirm "proceed?" || { echo "aborted."; exit 0; }
  apt-get install -y "linux-headers-$(uname -r)"
  apt-get install --reinstall -y "nvidia-dkms-${DRIVER_BRANCH}"
  dkms autoinstall
  depmod -a "$(uname -r)"
  b "trying to load the module now"
  l
  modprobe -v nvidia 2>&1 && echo "modprobe OK" || echo "modprobe FAILED (see message above)"
  do_verify
  b "if nvidia-smi works now, make the load persistent and reboot"
  l
  echo "  echo -e 'nvidia\nnvidia_uvm\nnvidia_drm\nnvidia_modeset' | sudo tee /etc/modules-load.d/nvidia.conf"
  echo "  sudo reboot && sudo bash $0 verify"
  ;;

# ------------------------------------------------------------------------------
clean)
  need_root
  verdict
  b "MODE: clean  -  purge ALL nvidia remnants and reinstall from scratch"
  l
  cat <<'EOF'
This machine carries a serious version sludge:
  installed driver ....... 595.91.07
  nvidia-settings ........ 510.47.03   <-- ancient leftover
  signed module trees .... nvidia-535, nvidia-570srv
  signed module objects .. linux-objects-nvidia-550-*
  8 kernels in /lib/modules (134..142 + 6.5.0-18)
  CUDA ................... 13.4

The purge below removes every nvidia package, then reinstalls
nvidia-driver-595-server (headless-correct variant).

WARNING: this breaks any currently working CUDA setup until the reinstall
finishes. Do NOT run this if the box is in production right now.
EOF
  confirm "purge everything and reinstall?" || { echo "aborted."; exit 0; }
  apt-get purge -y \
    '~nnvidia-.*' '~nlibnvidia-.*' \
    '~nlinux-modules-nvidia-.*' '~nlinux-objects-nvidia-.*' \
    '~nlinux-signatures-nvidia-.*' '~nxserver-xorg-video-nvidia-.*'
  apt-get autoremove -y --purge
  apt-get update
  apt-get install -y "linux-headers-$(uname -r)"
  if mokutil --sb-state 2>/dev/null | grep -qi 'SecureBoot enabled'; then
    echo
    echo "Secure Boot is still on -> installing the SIGNED module package."
    apt-get install -y "linux-modules-nvidia-${DRIVER_BRANCH}-generic" \
      || echo "!! signed modules unavailable; disable Secure Boot and re-run this mode."
  fi
  apt-get install -y "nvidia-driver-${DRIVER_BRANCH}-server" \
    || apt-get install -y "nvidia-driver-${DRIVER_BRANCH}"
  b "done - now reboot"
  l
  echo "  sudo reboot && sudo bash $0 verify"
  ;;

# ------------------------------------------------------------------------------
*)
  echo "unknown mode: $MODE"
  echo "valid modes: check | verify | signed | dkms | clean"
  exit 1
  ;;
esac

执行以下命令修复

sudo bash nvidia-fix.sh signed     # 装 Canonical 签名的 595 模块
sudo reboot
sudo bash nvidia-fix.sh verify

2026-09-22补充结束

posted @ 2026-06-30 09:26  minseo  阅读(16)  评论(0)    收藏  举报