Docs: steamvrDebugger is automatic; LAN forwards come from Developer Mode

Explain the steamvrDebugger default in plain words, and replace the
"mask the port forwards" advice: SteamOS only enables them with Steam's
Developer Mode, which none of the patches need.
This commit is contained in:
Pierre Kisters committed 2026-09-27 23:35:11 +02:00
1 parent dfcb244596
commit b579cb89e8
2 files changed
+24 -22

No files matched your search

+16 -15
View File
@@ -244,7 +244,7 @@ menu list every desktop entry, including terminals such as Konsole;
| `steamFrame.dashboard.frameControls.inBar` | list of control names | `[ ]` | Controls that start in the bar: `keyboard`, `float`, `dashboard`, `theater`, `dockLeft`, `dockRight`, `close`, `curvature`, or `"icon:<n>"`. A popup choice wins until the entry changes. |
| `steamFrame.dashboard.frameControls.inMenu` | list of control names | `[ ]` | Controls that start in the three-dot menu (same names). |
| `steamFrame.dashboard.frameControls.floatInTheater` | bool | `false` | Give theater windows the "Float" control (stock only shows it for dashboard-docked windows). |
| `steamFrame.steamvrDebugger.enable` | bool | `true` if a UI patch uses port 8087, else `false` | SteamVR dashboard DevTools on `127.0.0.1:8087` (`VRWebHelper/DebuggerEnabled`), needed by dashboard patches. See [SteamVR debugger](#steamvr-debugger-steamvrdebuggerenable). |
| `steamFrame.steamvrDebugger.enable` | bool | automatic | SteamVR dashboard DevTools on `127.0.0.1:8087` (`VRWebHelper/DebuggerEnabled`), needed by the dashboard patches (window control bar, curvature, close button, dashboard windows). Turned on automatically when one of them is enabled; there is normally no need to set it. See [SteamVR debugger](#steamvr-debugger-steamvrdebuggerenable). |
| `steamFrame.hiddenApps` | list of str | `[ ]` | Desktop entry ids (without `.desktop`) to hide from the "+" and KDE menus. |
| `steamFrame.clipboardSync.enable` | bool | `true` | Clipboard bridge between the Steam session and the nested desktop. |
| `steamFrame.clipboardSync.package` | package | built from `dnut/clipboard-sync` | The clipboard-sync package. |
@@ -293,15 +293,17 @@ steamFrame.uiPatches.patches = [ {
} ];
```
**DevTools on the LAN:** SteamOS images also forward these ports to all
interfaces: `steam-web-debug-portforward.service` (`0.0.0.0:8081` →
`8080`) and `steamvr-web-debug-portforward.service` (`0.0.0.0:8088` →
`8087`), and firewalld's `public` zone allows ports 1024-65535. Anyone on
the same network can then run code in Steam's UI. Masking both units is
recommended; it is a system-level change, outside Home Manager (e.g. with
[system-manager](https://github.com/numtide/system-manager): links
`/etc/systemd/system/<unit>` → `/dev/null`). The injector itself only uses
`127.0.0.1`.
**DevTools on the LAN:** Steam's **Developer Mode** (via
`steamos-devkit-mode`) enables `steam-web-debug-portforward.service`
(`0.0.0.0:8081` → `8080`) and `steamvr-web-debug-portforward.service`
(`0.0.0.0:8088` → `8087`), besides sshd, xrdp and the devkit service;
firewalld's `public` zone allows ports 1024-65535, so anyone on the same
network could then run code in Steam's UI. None of the patches need
Developer Mode (they only use `127.0.0.1`; for the full "+" menu use
`launcherMenu.showAllApps`), so keep it off. If it was on while those units
were masked, turning it off can leave them enabled: check with
`systemctl is-enabled steam-web-debug-portforward steamvr-web-debug-portforward`
and `sudo systemctl disable` them.
**Caveat:** patches depend on Steam UI internals and can break with a Steam
update. Find modules by signature rather than by id (below).
@@ -971,11 +973,10 @@ only if this module set it (marker in
`~/.local/state/steam-frame-nix/`); a setting you made yourself is left
alone.
**Security:** SteamOS's `steamvr-web-debug-portforward.service` forwards
`0.0.0.0:8088` to this port, so with the debugger on, anyone on the same
network could run code in the SteamVR dashboard. Masking it is recommended
(see "DevTools on the LAN" in [UI patches](#ui-patches-uipatchespatches));
the patches only use `127.0.0.1`.
**Security:** the port listens on `127.0.0.1` only. With Steam's Developer
Mode on, SteamOS also forwards it to `0.0.0.0:8088` (LAN); keep Developer
Mode off (see "DevTools on the LAN" in
[UI patches](#ui-patches-uipatchespatches)).
### Hidden apps (`hiddenApps`)
+8 -7
View File
@@ -21,9 +21,9 @@
# false at the next SteamVR start and removes the marker; otherwise it
# leaves the file alone (a setting made by hand is kept).
#
# Security: SteamOS's steamvr-web-debug-portforward.service forwards
# 0.0.0.0:8088 to this port (see README, "DevTools on the LAN"); masking it
# is recommended. Our patches only use 127.0.0.1.
# Security: the port listens on 127.0.0.1 only; Steam's Developer Mode makes
# SteamOS forward it to 0.0.0.0:8088 (README, "DevTools on the LAN"), so keep
# Developer Mode off. Our patches only use 127.0.0.1.
{ config, lib, pkgs, ... }:
let
cfg = config.steamFrame.steamvrDebugger;
@@ -71,16 +71,17 @@ in {
options.steamFrame.steamvrDebugger.enable = lib.mkOption {
type = lib.types.bool;
default = false;
defaultText = lib.literalMD "`true` if a patch in `steamFrame.uiPatches.patches` uses port 8087, else `false`";
defaultText = lib.literalMD "on automatically when a dashboard patch (a `steamFrame.uiPatches.patches` entry on port 8087) is enabled";
description = ''
Enable SteamVR's web helper debugger (DevTools of the SteamVR dashboard
on 127.0.0.1:8087, setting VRWebHelper/DebuggerEnabled in
~/.config/openvr/config/steamvr.vrsettings), needed by patches of the
SteamVR dashboard. Set before each SteamVR start, so it takes effect
after SteamVR is restarted once. Turning it off sets the key back to
false at the next SteamVR start. Note: SteamOS's
steamvr-web-debug-portforward.service exposes the port on 0.0.0.0:8088;
masking it is recommended.
false at the next SteamVR start. Normally there is no need to set it:
it is turned on automatically when a dashboard patch is enabled. The
port listens on 127.0.0.1; keep Steam's Developer Mode off, which would
also forward it to the LAN (0.0.0.0:8088).
'';
};