Claude handoff audit
Read the local conversation Steam CLI path configuration, reviewed its repository history through d689672, and examined the untracked cmd/_diffprobe utility. The latest commit already contained all four write paths, despite its read-only description. The utility compared leaves after parsing, so it could not detect data discarded by the parser. It has been retained under ignored .references/audit-tools/claude-diffprobe/.
The review concentrated on the unfinished library settings, the shared VDF writer and affected server commands, with targeted checks of status and the existing integration boundaries. It is not a claim that every Steam API or every historical change has been live-tested.
Findings and corrections
- Potential whole-file data loss: the general VDF dependency accepts truncated objects, ignores trailing roots, merges duplicate sections, and can loop on an EOF comment. A rewrite-oriented bounded parser now rejects ambiguous syntax and excessive depth, handles multiple roots and EOF comments, and checks semantic equality after rendering. Existing real files passed on temporary copies. Unsupported syntax causes an error, not a best-effort rewrite. The existing general dependency remains in other packages; this focused replacement is needed for safe configuration rewriting.
- Backup confidentiality: backups used mode 0644. New backups use 0600 and exclusive creation, check write/sync errors, retain the first original, and reject non-regular backup paths. Config-file symlinks are rejected at replacement; root-directory aliases are canonicalised.
- Account/root ambiguity: launch reads previously searched for the first nonempty value while writes selected differently. Account-specific reads/writes now use the same selection rule, error on ambiguity, and deduplicate physical paths. Configuration writes reject multiple distinct installations. Branch and DLC inspection do not require an account selection.
- Case-sensitive readers: the compatibility reader disagreed with the writer about lower-case ancestor names. They now share traversal; partially existing ancestor spelling is retained.
- Concurrency: library and server CLI edits take a per-file flock. Steam process detection covers Linux, macOS and Windows and fails closed if inspection is unavailable. Server writes previously warned only after changing the file; they now refuse by default. Process checks cannot prevent Steam starting during an edit.
- DLC re-enable failure: disabled selections are retained even when no installed depot refers to them. Ownership and runtime behavior are not inferred from this local data.
- Compatibility tools: symlinked custom directories were skipped. Discovery follows directory links and reads internal names from tool manifests; removed unreliable hardcoded AppID/name guesses. Existing mappings alone are not proof of an installed working tool.
- Incomplete branch workflow: added
library branch downloadby reusing the existing managed SteamCMD command, including login, argument validation, bootstrap, timeouts, success-marker and manifest checks.branch setremains a preference-only operation. - Server editing/data preservation: added
server edit; unknown fields on retained favorites/history entries survive list rewrites. - Status accuracy: CM discovery failures are retained as warnings. HTTP 4xx no longer means healthy. Empty coordinator payloads fail explicitly, and CM results identify their probe as TCP connection checks. These are local observations, not authenticated CM logons or SteamDB’s private monitoring backend.
Research and boundaries
Valve’s Proton repository documents custom tools under compatibilitytools.d; its manifest template carries internal tool names. The find-steam-app manifest definition independently models UserConfig.DisabledDLC and depot DLC AppIDs. Real local files were checked without publishing their contents.
Native Steamworks SDK invocation remains outstanding from the original broader project request. No native SDK invocation or complete API-conformance claim is made by this audit. SteamWebAPI.com remains excluded as requested. Steam status uses direct checks, not steamstat.us’s private backend.