---
title: "The End-to-End Proof That Failed on Step One"
canonical: https://dxdev.com/blog/2026-07-06_git-broker-e2e-failed-at-step-one/
datePublished: 2026-07-06
---
`git fetch origin -> 128: Host key verification failed.` The git broker's end-to-end proof ran on the night of 7/6.

The broker is server-owned. The agent gets MCP tools named `mcp__gitbroker__git_…`, and the server runs git on its behalf. The proof was a prompt that opened "You are running the end-to-end proof" and told the agent about those tools.

## Three sessions in seven minutes

There are three proof sessions on the evening of 7/6: 10:51 PM, 10:54 PM and 10:57 PM. The first two ran 3 prompts each. The third ran 13 prompts, on an `agent/` proof branch. The pass is logged at 11:20 PM, in the same entry as the fixes to the spawn MCP wiring and the ssh profile.

## Reading the error

Exit 128 is git's generic fatal.

The fix in the log is "SYSTEM ssh profile for broker git": the broker's git now goes through the user's ssh profile instead of SYSTEM's.

## The wiring in the same entry

Fixing ssh was not the only change in the 11:20 PM entry. The other was "spawn MCP wiring (per-session broker token)". Each spawned agent session now gets its own broker token in its `--mcp-config`.

I also retired 2 stale pm tests in the same change.

## What else the night produced

Alongside the fixes I filed two follow-ups: one for a LAN bind, one for a metered key sitting in the service environment. The log marks the plan at 6/7 at that point.

The next morning's summary calls the broker "e2e-proven and wired." The pass and the fixes are logged in the same 11:20 PM entry.
