Repository navigation
[Bug]: OrbStack systemd service misses SSH_AUTH_SOCK, causing worktree creation to fail at git fetch #10179
Description
Activity
- addedvia-triageFiled through npx t3 triageFiled through npx t3 triagebugSomething is broken or behaving incorrectly.Something is broken or behaving incorrectly.acceptedfeature request acceptedfeature request accepted
on Sep 5, 2026 Thanks for the careful repro. This looks like a real bug in the Linux systemd service environment, not an OrbStack or Git problem.
What we think is happening
t3code.serviceis generated byrenderBootServiceUnit()inapps/server/src/cloud/bootService.ts. The unit only setsT3CODE_HOMEandT3_BOOT_SERVICE_UNIT. It does not setSSH_AUTH_SOCK.Server startup (
fixPath()inapps/server/src/os-jank.ts) backfillsHOMEandPATHfrom a login shell, but notSSH_AUTH_SOCK. The desktop app already does that backfill inapps/desktop/src/shell/DesktopShellEnvironment.ts(see #971 / #972). Git children inheritprocess.env(GitVcsDriverCore), so a service with no agent socket fails SSHgit fetch.Worktree create with “start from origin” calls
gitWorkflow.fetchRemotebeforecreateWorktree(apps/server/src/ws.ts). That matches the UI error:Git command failed in GitVcsDriver.fetchRemote (...): git fetch origin failed/proc/<pid>/environis the exec-time environment, so it is a weak check for PATH (the server mutatesprocess.envlater). It is a fair check here: nothing in the service path writesSSH_AUTH_SOCK. Yourenv -u SSH_AUTH_SOCKvs explicit-socket comparison, and the drop-in restoring worktree create, pin the cause.Same family as #4913 (systemd PATH), #5740 (WSL
SSH_AUTH_SOCK), #3067 (devcontainer forwarded agent), and #971 (macOS desktop). Not a duplicate — this surface is the Linux user unit inside OrbStack.Workaround
The drop-in is the right workaround.
t3 service updaterewrites the unit file, nott3code.service.d/, so this should survive updates:sorry for the ai slop 😭
Thanks for the careful repro
From my clanker to yours, you're welcome @juliusmarminge 😂
I confirmed that current main cb9a6942 recovers PATH but not SSH_AUTH_SOCK in a controlled startup test. I haven't reproduced the full OrbStack setup yet.
One check will tell us whether adding socket backfill to that existing probe covers your environment. From the working Orb terminal, if your login shell is Bash or Zsh, could you run:
env -u SSH_AUTH_SOCK "$SHELL" -ilc 'test -n "${SSH_AUTH_SOCK:-}" && printf "present\n" || printf "absent\n"'
Please share only
presentorabsentand the shell name. For another shell, tell us its name instead. If it errors or hangs, report that rather than treating it asabsent.This removes the variable only in a child shell. It does not change your service, run Git or SSH, or print credentials.
presentsupports the small startup-backfill fix;absentmeans that alone won't recover OrbStack's agent. Keeping this open while we verify that distinction.GPT 6 Astra via Codex in T3 Code.
@juliusmarminge I ran the command in OrbStack login shell (which uses ZSH):
🐧 MAC5DEV ~ ⌚4:39:30 $ env -u SSH_AUTH_SOCK "$SHELL" -ilc 'test -n "${SSH_AUTH_SOCK:-}" && printf "present\n" || printf "absent\n"' absent
Context: I started using t3 connect inside OrbStack because it speeds up
pnpm installby 10x, making worktrees much faster to start: https://x.com/jachands/status/2096299607894491166The only thing I had issues with is git operations failing because the SSH_AUTH_SOCK env var isn't set in the service. I confirmed setting it fixed my issue, so for now I'm patching it after every update.
From the Clanker:
Before submitting
Related: #4913 (systemd service missing the user's PATH), #5740 (SSH_AUTH_SOCK missing in the WSL backend), #3067 (forwarded agents in devcontainers), and #971 (macOS desktop SSH-agent inheritance). This report concerns the Linux systemd user service inside OrbStack, failing to authenticate Git fetches through OrbStack's forwarded host agent.
Area
apps/server
Steps to reproduce
Run an Arch Linux ARM machine in OrbStack on macOS, with a working SSH identity available through OrbStack's forwarded host agent.
In the guest, use a repository whose
originis an SSH URL on GitHub. Confirm thatgit fetch --dry-run originsucceeds from a regular Orb shell. In this environment, the shell has:Run t3code using its
t3code.servicesystemd user unit, without a custom SSH-agent environment override.Open that guest-side repository in t3code and try to create a new worktree.
Expected behavior
Worktree creation can fetch the remote using the SSH agent already available inside the Orb, without a manual systemd override.
Actual behavior
Worktree creation fails with this UI message (repository path anonymized):
The running t3code server's
/proc/<pid>/environhad noSSH_AUTH_SOCK. The service unit also had no setting for it. A regular Orb shell had the working socket path above, andssh-add -lsuccessfully listed an identity.Impact
Major degradation or frequent failure: creating a worktree fails for the affected SSH remote, although fetching from the shell works.
Version or commit
t3@0.0.39-nightly.20260905.1285Environment
service-launcher.mjsLogs or stack traces
From the same repository in the guest, removing only the agent variable reproduces an authentication failure:
env -u SSH_AUTH_SOCK \ GIT_SSH_COMMAND='ssh -o BatchMode=yes -o ConnectTimeout=10' \ git fetch --dry-run originExit status: 128. Explicitly supplying the socket succeeds, with exit status 0:
SSH_AUTH_SOCK=/opt/orbstack-guest/run/host-ssh-agent.sock \ GIT_SSH_COMMAND='ssh -o BatchMode=yes -o ConnectTimeout=10' \ git fetch --dry-run originWorkaround
Create
~/.config/systemd/user/t3code.service.d/orbstack-ssh-agent.confcontaining:Then run:
After restarting, the running server had the variable, a fetch using that server's process environment succeeded, and worktree creation in t3code worked again.
This is a separate drop-in, not an edit to the generated service unit. Whether an update removes the drop-in has not been tested.
Suggested fix
Resolve the available SSH-agent environment for the Linux service, including OrbStack's forwarded host agent, so Git subprocesses can use it. Account for agent sockets that can change across sessions rather than assuming every socket path is permanent.
Also surface the underlying Git stderr in this failure:
Permission denied (publickey)would make the missing authentication context easier to diagnose thangit fetch origin failedalone.