Steam Machine · Guides
Steam Machine Desktop Mode: Sudo, Konsole, and Linux Basics
Summary
Set a local sudo password on Steam Machine, move between Gaming Mode and Desktop Mode, use Konsole and Discover safely, and understand common SteamOS permissions and filesystem warnings.
Steam Machine ships with no password on its desktop account, which means `sudo` does not work until you set one. Valve's Desktop Mode FAQ documents that setup for Steam Machine and Steam Deck. If that is all you need, jump to Set sudo password.
The rest of this page explains Desktop Mode, safe software installation, file locations, and commands to leave alone. Use it as a lookup when needed.
Contents
- Enter and leave Desktop Mode
- Open Konsole
- Set sudo password
- Why your password does not appear when typing
- Sudo password vs Steam account password and PIN
- Install software with Discover and Flatpak
- Files, hidden folders, and where things live
- Basic commands
- Permission denied
- The read-only filesystem
- What not to run
- Which tools need sudo
- Troubleshooting
Enter and leave Desktop Mode
Gaming Mode is the controller-driven interface you see by default. Desktop Mode is a full KDE Plasma desktop running underneath it, with a file manager, app store, and terminal.
To enter: press the Steam button, choose Power, then Switch to Desktop. Valve's Steam Machine feature guide describes the same path. No reboot is required. The interface just swaps.
To leave: double-click the Return to Gaming Mode icon on the desktop.
A keyboard and mouse make this far less painful than controller navigation. If you do not have one attached, Steam and X together brings up the on-screen keyboard.
Open Konsole
Konsole is the terminal application that ships with SteamOS. It is where every command on this page gets typed.
Find it in the application launcher at the bottom-left of the taskbar, or search for it. It is the standard KDE terminal.
Set sudo password
`sudo` means "run this one command as administrator". It is deliberately unavailable until you set a password, because Valve ships the desktop account without one. Valve's Desktop Mode FAQ explains that the desktop account needs a password before sudo can run.
In Konsole:
``` passwd ```
Enter a new password, then enter it again to confirm. That is the entire process.
The password you just set belongs to your desktop user account. There is no separate sudo password. `sudo` asks for your account password when needed.
To change it later, run `passwd` again. It will ask for the current password first.
To check that sudo accepts the password without changing files, run:
``` sudo -v ```
Enter the local password if prompted. A successful check returns without an error.
Why your password does not appear when typing
Konsole shows nothing while you type a password. No dots, no asterisks, no cursor movement.
This is normal Linux behavior, not a frozen terminal or a broken keyboard. The characters are being received. Type carefully and press Enter.
Sudo password vs Steam account password and PIN
Three different things, easy to confuse:
Sudo password is your local desktop account password. It is not managed by Steam's account-recovery service. Keep it private and store it securely.
Steam account password is your Steam login, tied to your account across every device. Setting a sudo password does not change it, and vice versa.
Steam PIN is the short parental or lock code inside Steam itself. Unrelated to both.
Forgetting your Steam password is recoverable by email. Forgetting your sudo password is not, at least not simply, since there is no account recovery for a local Linux user. Store it somewhere.
Install software with Discover and Flatpak
Discover is the app store in the taskbar. It is the recommended default for installing desktop software on SteamOS, and for most software it is all you need.
Discover provides Flatpak desktop applications on SteamOS. These packages use writable storage rather than changing the protected system image, so normal SteamOS image replacement does not remove them. Check the package source and requested permissions when installing.
Common installs: Firefox or Chrome for browsing, Heroic Games Launcher for Epic and GOG titles, VLC for media, ProtonUp-Qt or ProtonPlus for managing Proton versions.
User-installed Flatpaks normally do not need sudo. If a tutorial tells you to install something with `sudo pacman`, read the read-only section before you follow it.
Files, hidden folders, and where things live
Dolphin is the file manager. `~` is shorthand for your home folder, where many personal files and app settings live. External drives have their own paths.
Linux hides any file or folder starting with a dot. In Dolphin, Ctrl+H toggles them visible. A great deal of what you will look for is hidden by default, so this shortcut is worth memorizing.
Common paths:
| Path | What it holds |
|---|---|
| `~/.steam` | Steam's own files |
| `~/.local/share/Steam` | Steam data, including `steamapps` |
| `~/.local/share` | Roughly the equivalent of AppData |
| `~/.config` | Application configuration |
| `~/.var` | Flatpak application data |
| `~/.steam/steam/steamapps/compatdata` | Proton prefixes, one folder per game App ID |
| `/run/media` | External drives and storage |
That `compatdata` path is the one that matters if you ever switch Proton versions, since game saves can live inside those prefixes.
Your home folder path includes your username. SteamOS is built around a fixed default account name, so unless you deliberately changed it, `~` resolves correctly and you rarely need to type the full path.
Basic commands
These six navigation commands cover most directory lookups a guide will ask for. None modifies a file.
| Command | Purpose |
|---|---|
| `pwd` | Show the current folder |
| `ls` | List its contents |
| `ls -la` | Include hidden files and details |
| `cd Downloads` | Enter the Downloads folder, if it exists here |
| `cd ..` | Move up one level |
| `cd` | Return to your home folder |
Copying and moving can overwrite existing files. These examples use `-i` to ask before an overwrite, but that is not an undo function or a backup. Replace the example names with the exact paths you intend to use.
| Command | Purpose |
|---|---|
| `cp -i file.txt ~/Documents/` | Copy a file |
| `cp -ri folder/ ~/Documents/` | Copy a folder and its contents |
| `mv -i file.txt ~/Documents/` | Move a file |
| `mv -i old.txt new.txt` | Rename a file |
Press Tab to autocomplete paths and reduce typing mistakes. Check both source and destination before pressing Enter.
Permission denied
The requested action was blocked. That does not establish that the command is safe or that administrator access is the right fix.
Check the command and its target path before retrying. For an ordinary desktop app, check its file permissions and Flatpak access first. Use `sudo` only when you understand the operation and the tool's instructions require administrator rights. The sudo password section explains how to set the local password if needed.
If the target is SteamOS's read-only system, administrator access alone will not make it writable. Check for a supported user-space install before disabling protection.
`command not found` is different: the shell could not locate the program. Check whether it is installed and how its documentation says to launch it.
The read-only filesystem
SteamOS is built on Arch Linux, but with an immutable core. The system partition is read-only, and SteamOS updates overwrite it wholesale rather than patching it piece by piece.
Two consequences:
The system image is replaceable, not a backup. Updates replace the protected core. They do not undo damage to personal files or recover deleted saves.
System packages may disappear after an update. Packages added with `pacman` modify the system image. Software kept on writable storage, including some non-Flatpak apps, is a different case.
Leave protection enabled for ordinary desktop use. Only disable it for a specific, understood system change, and re-enable it when finished. Re-enabling protection does not undo the change or make its files survive an update.
The command to disable protection is:
``` sudo steamos-readonly disable ```
And restore it:
``` sudo steamos-readonly enable ```
Check the current state with `status` in place of either.
The practical rule: use Flatpaks when one is available. They use the writable portion of SteamOS and avoid touching the read-only system at all.
What not to run
`sudo rm -rf` on anything you are unsure about. It can permanently delete files without confirmation or a recycle bin. Do not run a deletion command until you understand its exact target; use Dolphin's recoverable Trash action where appropriate.
Random commands from forums and videos. Especially anything piping a downloaded script straight into a shell. Read what it does first, or do not run it.
`sudo pacman -S` for general software. It works, but it puts files on the read-only partition that the next update removes. Use Discover.
Changing your username. SteamOS is designed around its default account name and depends on it in ways that are not obvious. Attempts to change it typically fail, and the ways that succeed create problems later.
Leaving read-only disabled after you have finished whatever needed it.
If you follow a pacman tutorial anyway, you will likely hit keyring and signature errors, which is its own rabbit hole. Another reason Flatpak is the better default.
Which tools need sudo
Flatpak apps installed through Discover usually do not.
Decky Loader does need it. The installer sets up a system-level service, so it prompts for your password during installation.
EmuDeck is mostly user-space and installs emulators as Flatpaks, but parts of setup can ask for elevated access depending on what you enable.
ProtonUp-Qt and ProtonPlus generally do not. They install custom Proton versions into your user folder, which needs no special permission.
Drive and storage utilities usually do. Formatting, partitioning, and mounting a drive at a system path all touch hardware and system configuration.
Discover Flatpak apps normally install for your user without administrator access. A system-wide operation can have different permission requirements.
If a tool asks for your password and you did not expect it, that is worth a moment's thought rather than reflexive typing. Legitimate reasons exist, and so do bad ones.
Troubleshooting
"passwd: Authentication token manipulation error" means the password change failed. Return to a normal Desktop Mode session, reopen Konsole, and retry `passwd`. If it still fails, keep the exact error for support rather than changing account files or system protection at random.
Sudo says my password is wrong, but it is right. Check Caps Lock, and confirm you are entering your local desktop password rather than your Steam account password. They are different. See above.
I forgot my sudo password. Steam account recovery will not reset it. Follow the applicable SteamOS recovery instructions or contact support; recovery may require booting another environment. Back up personal files before considering any reset or reimage.
A guide told me to run something and it failed with read-only errors. The read-only system is doing its job. Check whether a Flatpak version of what you want exists before disabling it.
Software disappeared after an update. Check how it was installed. Packages added with `pacman` may have been replaced with the system image. Look for a Flatpak before reinstalling system packages.
Desktop Mode will not go back to Gaming Mode. Use the Return to Gaming Mode desktop icon rather than logging out. If it is unresponsive, a reboot returns to whichever mode is set as default.
One note on sources
Valve's Steam Machine feature guide and Desktop Mode FAQ are the references for device-specific Desktop Mode, password, and system-protection behavior. The file-navigation examples are general Linux commands. Check the current Valve guidance if a SteamOS update changes a menu or recovery procedure.