From f36d13e3719df4ccd1d4dfc2da93b6a6243b43de Mon Sep 17 00:00:00 2001 From: enricobuehler Date: Tue, 21 Jul 2026 21:56:13 +0200 Subject: [PATCH] fix(steamdeck/install): prompt for sudo instead of requiring passwordless MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The system-tuning block (UDP buffers, gamepad udev rule, vhci-hcd autoload, input group) was gated on `sudo -n true` — passwordless sudo — so on a stock SteamOS box (the deck account needs a password) the whole block was silently skipped: /dev/uhid stayed root-only so the gamepad degraded to an Xbox 360 pad, and the UDP buffers stayed at the 416 KB default. Video was unaffected because Game Mode/gamescope needs none of it, which masked the skip on-glass. - install.sh + update.sh: acquire sudo interactively (`sudo -v` prompt on a TTY) instead of requiring passwordless; skip only when there's no TTY or auth fails, and then print the exact manual block plus a `passwd` hint — a stock SteamOS 'deck' account has no password, so sudo can't work until one is set. - update.sh: also retrofit the UDP-buffer sysctl for older/skipped installs, and loudly nag to reboot when the input group was just added (a --user restart does not pick up the new group; only a fresh login does). - steamos-host.md: note this step prompts for the sudo password. Root is unavoidable: the udev rule, input group, and vhci-hcd module are all kernel operations with no user-space alternative. Co-Authored-By: Claude Opus 4.8 (1M context) --- docs-site/content/docs/steamos-host.md | 4 +-- scripts/steamdeck/install.sh | 25 +++++++++++++++--- scripts/steamdeck/update.sh | 35 +++++++++++++++++++++----- 3 files changed, 52 insertions(+), 12 deletions(-) diff --git a/docs-site/content/docs/steamos-host.md b/docs-site/content/docs/steamos-host.md index d0a3da46..e7fb48aa 100644 --- a/docs-site/content/docs/steamos-host.md +++ b/docs-site/content/docs/steamos-host.md @@ -60,8 +60,8 @@ It is idempotent — safe to re-run. In one pass it: 3. writes config to `~/.config/punktfunk/` (a generated web-console login password), 4. raises the UDP socket buffers to 32 MB, installs the gamepad udev rule + the `vhci-hcd` autoload and adds you to the `input` group (virtual gamepads / **native Steam Deck controller passthrough**), - and seeds the KDE RemoteDesktop grant for Desktop-mode input (needs `sudo`; skipped with a warning - if unavailable), + and seeds the KDE RemoteDesktop grant for Desktop-mode input — this step **prompts for your `sudo` + password** (a stock Steam Deck requires one; without it gamepad passthrough and the UDP tuning are skipped), 5. installs + starts the `punktfunk-host` and `punktfunk-web` **systemd user services** (with linger, so they run without a login session). diff --git a/scripts/steamdeck/install.sh b/scripts/steamdeck/install.sh index 148bc545..f1544042 100755 --- a/scripts/steamdeck/install.sh +++ b/scripts/steamdeck/install.sh @@ -189,9 +189,19 @@ else [ "$WITH_WEB" = 1 ] && ok "web.env exists (login password unchanged)" fi -# --- 4. system tuning (needs sudo; skipped gracefully if unavailable) ------ +# --- 4. system tuning (needs sudo: UDP buffers + gamepad udev rule + vhci-hcd + input group) -------- log "System tuning (UDP buffers + gamepad rules + vhci-hcd + input group) — needs sudo" +# Acquire sudo. A stock Steam Deck requires a sudo PASSWORD, so `sudo -n` (non-interactive) fails — +# we must PROMPT on a TTY, not silently skip. Skipping here is exactly what leaves gamepad passthrough +# dead (no udev rule / input group / vhci-hcd) and streaming lossy (stock 416 KB UDP buffers). +SUDO_OK=0 if sudo -n true 2>/dev/null; then + SUDO_OK=1 +elif [ -t 0 ]; then + warn "sudo needs your password to set up the gamepad udev rule, vhci-hcd, the input group, and UDP buffers:" + sudo -v && SUDO_OK=1 || true +fi +if [ "$SUDO_OK" = 1 ]; then printf 'net.core.wmem_max=33554432\nnet.core.rmem_max=33554432\n' \ | sudo tee /etc/sysctl.d/99-punktfunk-net.conf >/dev/null sudo sysctl -q -p /etc/sysctl.d/99-punktfunk-net.conf >/dev/null @@ -217,9 +227,16 @@ if sudo -n true 2>/dev/null; then warn "added $USER to the 'input' group (applies on next login)" fi else - warn "passwordless sudo unavailable — skipping UDP-buffer + udev tuning." - warn "Without it, high-bitrate streaming drops packets. Apply manually later:" - warn " echo -e 'net.core.wmem_max=33554432\\nnet.core.rmem_max=33554432' | sudo tee /etc/sysctl.d/99-punktfunk-net.conf && sudo sysctl --system" + warn "no usable sudo — SKIPPED system tuning. Gamepad passthrough + clean streaming need root (udev" + warn "rule, 'input' group, vhci-hcd, UDP buffers) — there is no user-space way to do these." + warn "A stock SteamOS 'deck' account has NO password, so sudo can't work until you set one:" + warn " passwd # set a sudo password once, then re-run this script" + warn "Or apply it by hand (then reboot):" + warn " sudo install -m644 $SRC/scripts/60-punktfunk.rules /etc/udev/rules.d/ &&" + warn " sudo install -m644 $SRC/scripts/punktfunk-modules.conf /etc/modules-load.d/punktfunk.conf &&" + warn " sudo usermod -aG input $USER &&" + warn " printf 'net.core.wmem_max=33554432\\nnet.core.rmem_max=33554432\\n' | sudo tee /etc/sysctl.d/99-punktfunk-net.conf &&" + warn " sudo sysctl --system && sudo udevadm control --reload-rules && sudo udevadm trigger" fi # --- 5. systemd user services --------------------------------------------- diff --git a/scripts/steamdeck/update.sh b/scripts/steamdeck/update.sh index 4b45c545..bbd5c2b0 100755 --- a/scripts/steamdeck/update.sh +++ b/scripts/steamdeck/update.sh @@ -44,24 +44,47 @@ sed "s|^Exec=.*|Exec=$TARGET_DIR/release/punktfunk-host|" "$SRC/packaging/linux/ > "$HOME/.local/share/applications/io.unom.Punktfunk.Host.desktop" ok "KWin desktop-capture authorization refreshed" -# Retrofit the system bits install.sh now sets up but older installs predate (idempotent; the sudo -# parts are skipped if passwordless sudo isn't available). vhci-hcd = usbip transport for the native -# Steam Deck pad; 60-punktfunk.rules = /dev/uhid + vhci access; input group = uhid write; the -# kde-authorized grant (per-user, no root) = Desktop-mode input. A newly-added input group still needs -# a re-login to apply. +# Retrofit the system bits install.sh now sets up but older installs predate (idempotent). vhci-hcd = +# usbip transport for the native Steam Deck pad; 60-punktfunk.rules = /dev/uhid + vhci access; input +# group = uhid write; the kde-authorized grant (per-user, no root) = Desktop-mode input. A stock Deck +# needs a sudo PASSWORD, so PROMPT for it rather than silently skipping (skipping = gamepads stay dead). +SUDO_OK=0 if sudo -n true 2>/dev/null; then + SUDO_OK=1 +elif [ -t 0 ]; then + warn "sudo needs your password to (re)apply the gamepad udev rule, vhci-hcd, input group, and UDP buffers:" + sudo -v && SUDO_OK=1 || true +fi +if [ "$SUDO_OK" = 1 ]; then if [ -f "$SRC/scripts/60-punktfunk.rules" ]; then sudo install -m644 "$SRC/scripts/60-punktfunk.rules" /etc/udev/rules.d/60-punktfunk.rules sudo udevadm control --reload-rules >/dev/null 2>&1 || true sudo udevadm trigger >/dev/null 2>&1 || true + ok "gamepad udev rule ensured" fi if [ -f "$SRC/scripts/punktfunk-modules.conf" ]; then sudo install -m644 "$SRC/scripts/punktfunk-modules.conf" /etc/modules-load.d/punktfunk.conf sudo modprobe vhci-hcd 2>/dev/null || true ok "vhci-hcd autoload ensured (native Steam Deck controller)" fi - id -nG "$USER" | grep -qw input || { sudo usermod -aG input "$USER"; ok "added $USER to 'input' group — log out/in for it to apply"; } + # UDP buffers: older installs (or sudo-skipped ones) still run the stock 416 KB cap. + if [ ! -f /etc/sysctl.d/99-punktfunk-net.conf ]; then + printf 'net.core.wmem_max=33554432\nnet.core.rmem_max=33554432\n' | sudo tee /etc/sysctl.d/99-punktfunk-net.conf >/dev/null + sudo sysctl -q -p /etc/sysctl.d/99-punktfunk-net.conf >/dev/null 2>&1 || true + ok "UDP socket buffers raised to 32 MB (persisted)" + fi + if id -nG "$USER" | grep -qw input; then :; else + sudo usermod -aG input "$USER" + warn "added $USER to the 'input' group — REBOOT (or log out/in) for it to apply" + fi +else + warn "no usable sudo — SKIPPED gamepad/udev/vhci/UDP tuning (all root-only; no user-space alternative)." + warn "A stock SteamOS 'deck' account has NO password — set one with 'passwd', then re-run. Gamepads stay" + warn "Xbox-360 until this runs and you reboot." fi +echo +warn "If the controller still shows as an Xbox 360 pad, REBOOT the Deck once — the 'input' group and the" +warn "vhci-hcd module only become live for the host service on a fresh login." GRANT_SRC="$SRC/scripts/headless/kde-authorized" GRANT_DST="$HOME/.local/share/flatpak/db/kde-authorized" if [ ! -s "$GRANT_DST" ] && [ -s "$GRANT_SRC" ]; then