these 53 derivations will be built: /nix/store/0kj35yyp2hbmrpdpibr40jmfj512idb7-unit-systemd-networkd-wait-online.service.drv /nix/store/67sllgv1v180ryqrq154dg166vpn0m9g-X-Reload-Triggers-systemd-networkd.drv /nix/store/291pa7k7mraj44xxx687sscgrwdcwqnc-unit-systemd-networkd.service.drv /nix/store/g897x8vmghhgvg1kfg1n82ds7jsxq1c1-system-path.drv /nix/store/21pxdm21f4zib9i7i346nfs0mfhjyqal-dbus-1.drv /nix/store/m80gy76b5bx1lxhl1c47kx89g0768zx9-X-Restart-Triggers-dbus-broker.drv /nix/store/p2lpsnfhih6706cdbvyal9amzwmwyyhn-unit-dbus-broker.service.drv /nix/store/q2hskaw5kv5jjdk0m5xb22z0ywhbfik0-nginx.conf.drv /nix/store/62rriyswbd1ys07fwblcvijnnb2m66np-unit-script-nginx-pre-start.drv /nix/store/rkzipr1pbws5h4z01l7iyrk571rrk8pd-unit-nginx.service.drv /nix/store/06yyhcf99dgz7yj3f79ik7px91pq3k84-system-units.drv /nix/store/lxcxqy92ss6qrzfl1rxkivawsgha79qp-users-groups.json.drv /nix/store/7q5ym165s64kzai1dihw478a4dq24xiz-dry-activate.drv /nix/store/s2ikmfj72ipjnvfy478h4xg445x08mfa-system-path.drv /nix/store/h8z28r16ki3n9vzfpwf665cym00c3wj9-dbus-1.drv /nix/store/9yv84jzz0zwjp0iq40hkq2i8wj0kak2d-X-Restart-Triggers-dbus-broker.drv /nix/store/jbyfamvxfhv53nnrbayfz1hqk1yrimp9-unit-dbus-broker.service.drv /nix/store/4pib893wl8inaisy6b9g2vzbg69v6qyr-user-units.drv /nix/store/szajcfqg9zy5amixfxhfrrsiqvjq9gqh-extra-hosts.drv /nix/store/a115hzfvm8chgwafzp778iqcgn43aqqs-hosts.drv /nix/store/prbjyzi7yk7sk9xwylvjp5hl3yw3rrna-nginx.conf.drv /nix/store/ia82w0c6aj96b17c85gy9v5mpi4sp6x7-unit-script-nginx-pre-start.drv /nix/store/f79139hw85schla5zg5a7mp3y6g8ga05-unit-nginx.service.drv /nix/store/k2n82gai5f4yq2y66cgcwal6phsnqidy-nftables-deletions.drv /nix/store/psl5p7wk92mk9dfjy8a9d7nvd61g7wbq-passwd.drv /nix/store/6gdff2cbd9r8nx5l0q3dc789hc6yymmr-nftables-rules.drv /nix/store/fli4qsl9lhla1p9p7i6lmd475w9ldwy9-nftables-cleanup-deletions.drv /nix/store/k59b0xylhnvmkrlaj734cklfl3snqw37-nftables-ensure-deletions.drv /nix/store/vjlavc9lzfs7kn98cqp21q82bdw8h5fd-nftables-save-deletions.drv /nix/store/fbjrpmry00y8wzxxlrp66w05qc1b833j-unit-nftables.service.drv /nix/store/479m3rf3kw6zgcrp6krvzcyansygg3sw-unit-script-setup-wg0-interface-start.drv /nix/store/ggripf59ims2qmi02kzxdw9yrf1k68rw-unit-setup-wg0-interface.service.drv /nix/store/ifpacgjbf6phw45prbqmxkymm0ifav8v-unit-dbus-broker.service.drv /nix/store/bk221f3wpn380fmyssaw6ffpjaavi36l-system-units.drv /nix/store/wv41qndnqpc656ffamnrfbp8nv1llxcf-etc.drv /nix/store/glpb4hd7lvxjshj4v1g0amba86036q7l-activate.drv /nix/store/209pj4l32vhr2ilzpacz8w353phlx1k9-nixos-system-machine-test.drv /nix/store/565lqc4fbjvb5y79vrhglxpsrybcgj52-test-script.drv /nix/store/lmf0n6irw3vwyls79446hz0lsvl4vf6d-etc-hostname.drv /nix/store/iz32qamvrcf697cxx6iqfqgacjafrjv5-string-hosts.drv /nix/store/yy2mspx7sbwijzgf7zkba6h97nwi5r7x-hosts.drv /nix/store/p13ziwl3xrzqs5fpbas0a3hm2jfq6brw-unit-dbus-broker.service.drv /nix/store/z6f5frzvkm74hjjlm2dapy2qi4pq27jd-user-units.drv /nix/store/7v7a9rdvsf6i5zwiq8ldpx6wgyq739hb-etc.drv /nix/store/dzdxm9qsw9za0cgvax0q8wix78jzwan9-users-groups.json.drv /nix/store/mm547wh71iyd0qaljdlpw9q3xqfid58c-dry-activate.drv /nix/store/n3fnvwgwihf6i72iygx6zjwd00znmbrx-activate.drv /nix/store/v611ld59wmwinj46nivfrlvv6hr0lpzc-nixos-system-router-test.drv /nix/store/w4yny9n92jsvmv0f8awgah18qr7gc25b-run-router-nspawn.drv /nix/store/z3bsb7n5jd9hdwsxm15rgalqns54si3z-run-machine-nspawn.drv /nix/store/iq25grp7hjiakbl9j7gbw3mzwh0zyhka-driverConfiguration.json.drv /nix/store/3jwb574dr6s37qxwla3qf8s90py2xil7-nixos-test-driver-user-firewall-nftables.drv /nix/store/rrcw3h3c6mjxf9mhp37qmr74z64wcmh5-container-test-run-user-firewall-nftables.drv this path will be fetched (18.1 MiB download, 52.1 MiB unpacked): /nix/store/9fah46rsmy98m0knlxv936rds741d2nk-lkl-2025-11-13-lib building '/nix/store/565lqc4fbjvb5y79vrhglxpsrybcgj52-test-script.drv' building '/nix/store/g897x8vmghhgvg1kfg1n82ds7jsxq1c1-system-path.drv' building '/nix/store/s2ikmfj72ipjnvfy478h4xg445x08mfa-system-path.drv' building '/nix/store/lmf0n6irw3vwyls79446hz0lsvl4vf6d-etc-hostname.drv' building '/nix/store/prbjyzi7yk7sk9xwylvjp5hl3yw3rrna-nginx.conf.drv' building '/nix/store/q2hskaw5kv5jjdk0m5xb22z0ywhbfik0-nginx.conf.drv' building '/nix/store/dzdxm9qsw9za0cgvax0q8wix78jzwan9-users-groups.json.drv' building '/nix/store/lxcxqy92ss6qrzfl1rxkivawsgha79qp-users-groups.json.drv' building '/nix/store/szajcfqg9zy5amixfxhfrrsiqvjq9gqh-extra-hosts.drv' building '/nix/store/iz32qamvrcf697cxx6iqfqgacjafrjv5-string-hosts.drv' nginx.conf> structuredAttrs is enabled nginx.conf> structuredAttrs is enabled system-path> structuredAttrs is enabled system-path> created 1572 symlinks in user environment system-path> structuredAttrs is enabled system-path> created 1585 symlinks in user environment building '/nix/store/67sllgv1v180ryqrq154dg166vpn0m9g-X-Reload-Triggers-systemd-networkd.drv' building '/nix/store/fli4qsl9lhla1p9p7i6lmd475w9ldwy9-nftables-cleanup-deletions.drv' building '/nix/store/k2n82gai5f4yq2y66cgcwal6phsnqidy-nftables-deletions.drv' building '/nix/store/k59b0xylhnvmkrlaj734cklfl3snqw37-nftables-ensure-deletions.drv' building '/nix/store/psl5p7wk92mk9dfjy8a9d7nvd61g7wbq-passwd.drv' building '/nix/store/479m3rf3kw6zgcrp6krvzcyansygg3sw-unit-script-setup-wg0-interface-start.drv' building '/nix/store/0kj35yyp2hbmrpdpibr40jmfj512idb7-unit-systemd-networkd-wait-online.service.drv' building '/nix/store/21pxdm21f4zib9i7i346nfs0mfhjyqal-dbus-1.drv' nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> unit-systemd-networkd-wait-online.service> structuredAttrs is enabled building '/nix/store/h8z28r16ki3n9vzfpwf665cym00c3wj9-dbus-1.drv' building '/nix/store/7q5ym165s64kzai1dihw478a4dq24xiz-dry-activate.drv' building '/nix/store/mm547wh71iyd0qaljdlpw9q3xqfid58c-dry-activate.drv' building '/nix/store/a115hzfvm8chgwafzp778iqcgn43aqqs-hosts.drv' building '/nix/store/yy2mspx7sbwijzgf7zkba6h97nwi5r7x-hosts.drv' building '/nix/store/vjlavc9lzfs7kn98cqp21q82bdw8h5fd-nftables-save-deletions.drv' building '/nix/store/ggripf59ims2qmi02kzxdw9yrf1k68rw-unit-setup-wg0-interface.service.drv' building '/nix/store/291pa7k7mraj44xxx687sscgrwdcwqnc-unit-systemd-networkd.service.drv' building '/nix/store/9yv84jzz0zwjp0iq40hkq2i8wj0kak2d-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/m80gy76b5bx1lxhl1c47kx89g0768zx9-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/6gdff2cbd9r8nx5l0q3dc789hc6yymmr-nftables-rules.drv' building '/nix/store/62rriyswbd1ys07fwblcvijnnb2m66np-unit-script-nginx-pre-start.drv' building '/nix/store/ia82w0c6aj96b17c85gy9v5mpi4sp6x7-unit-script-nginx-pre-start.drv' unit-setup-wg0-interface.service> structuredAttrs is enabled unit-systemd-networkd.service> structuredAttrs is enabled building '/nix/store/ifpacgjbf6phw45prbqmxkymm0ifav8v-unit-dbus-broker.service.drv' building '/nix/store/jbyfamvxfhv53nnrbayfz1hqk1yrimp9-unit-dbus-broker.service.drv' building '/nix/store/p13ziwl3xrzqs5fpbas0a3hm2jfq6brw-unit-dbus-broker.service.drv' building '/nix/store/p2lpsnfhih6706cdbvyal9amzwmwyyhn-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled unit-dbus-broker.service> structuredAttrs is enabled unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/fbjrpmry00y8wzxxlrp66w05qc1b833j-unit-nftables.service.drv' building '/nix/store/f79139hw85schla5zg5a7mp3y6g8ga05-unit-nginx.service.drv' building '/nix/store/rkzipr1pbws5h4z01l7iyrk571rrk8pd-unit-nginx.service.drv' unit-dbus-broker.service> structuredAttrs is enabled unit-nftables.service> structuredAttrs is enabled unit-nginx.service> structuredAttrs is enabled building '/nix/store/4pib893wl8inaisy6b9g2vzbg69v6qyr-user-units.drv' building '/nix/store/z6f5frzvkm74hjjlm2dapy2qi4pq27jd-user-units.drv' unit-nginx.service> structuredAttrs is enabled building '/nix/store/bk221f3wpn380fmyssaw6ffpjaavi36l-system-units.drv' building '/nix/store/06yyhcf99dgz7yj3f79ik7px91pq3k84-system-units.drv' building '/nix/store/wv41qndnqpc656ffamnrfbp8nv1llxcf-etc.drv' building '/nix/store/7v7a9rdvsf6i5zwiq8ldpx6wgyq739hb-etc.drv' building '/nix/store/glpb4hd7lvxjshj4v1g0amba86036q7l-activate.drv' building '/nix/store/209pj4l32vhr2ilzpacz8w353phlx1k9-nixos-system-machine-test.drv' building '/nix/store/n3fnvwgwihf6i72iygx6zjwd00znmbrx-activate.drv' nixos-system-machine-test> structuredAttrs is enabled building '/nix/store/z3bsb7n5jd9hdwsxm15rgalqns54si3z-run-machine-nspawn.drv' building '/nix/store/v611ld59wmwinj46nivfrlvv6hr0lpzc-nixos-system-router-test.drv' nixos-system-router-test> structuredAttrs is enabled building '/nix/store/w4yny9n92jsvmv0f8awgah18qr7gc25b-run-router-nspawn.drv' building '/nix/store/iq25grp7hjiakbl9j7gbw3mzwh0zyhka-driverConfiguration.json.drv' driverConfiguration.json> structuredAttrs is enabled building '/nix/store/3jwb574dr6s37qxwla3qf8s90py2xil7-nixos-test-driver-user-firewall-nftables.drv' nixos-test-driver-user-firewall-nftables> Running type check (enable/disable: config.skipTypeCheck) nixos-test-driver-user-firewall-nftables> See https://nixos.org/manual/nixos/stable/#test-opt-skipTypeCheck nixos-test-driver-user-firewall-nftables> All checks passed! nixos-test-driver-user-firewall-nftables> Linting test script (enable/disable: config.skipLint) nixos-test-driver-user-firewall-nftables> See https://nixos.org/manual/nixos/stable/#test-opt-skipLint nixos-test-driver-user-firewall-nftables> All checks passed! building '/nix/store/rrcw3h3c6mjxf9mhp37qmr74z64wcmh5-container-test-run-user-firewall-nftables.drv' container-test-run-user-firewall-nftables> Machine state will be reset. To keep it, pass --keep-machine-state container-test-run-user-firewall-nftables> start all VLans container-test-run-user-firewall-nftables> (finished: start all VLans, in 0.00 seconds) container-test-run-user-firewall-nftables> container-test-run-user-firewall-nftables> Test will time out and terminate in 3600 seconds container-test-run-user-firewall-nftables> run the VM test script container-test-run-user-firewall-nftables> additionally exposed symbols: container-test-run-user-firewall-nftables> machine, router, container-test-run-user-firewall-nftables> vlan1, container-test-run-user-firewall-nftables> start_all, test_script, machines, machines_qemu, machines_nspawn, vlans, driver, log, os, create_machine, subtest, run_tests, join_all, retry, serial_stdout_off, serial_stdout_on, polling_condition, BaseMachine, QemuMachine, NspawnMachine, t, debug, dump_machine_ssh container-test-run-user-firewall-nftables> start all VMs container-test-run-user-firewall-nftables> machine: systemd-nspawn running (pid 52) container-test-run-user-firewall-nftables> router: systemd-nspawn running (pid 53) container-test-run-user-firewall-nftables> machine: Waiting for journal at /build/vm-state-machine/var/log/journal... container-test-run-user-firewall-nftables> router: Waiting for journal at /build/vm-state-router/var/log/journal... container-test-run-user-firewall-nftables> (finished: start all VMs, in 0.00 seconds) container-test-run-user-firewall-nftables> router: waiting for unit multi-user.target container-test-run-user-firewall-nftables> nixos-nspawn(router): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-user-firewall-nftables> nixos-nspawn(router): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-user-firewall-nftables> nixos-nspawn(machine): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-user-firewall-nftables> nixos-nspawn(machine): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-user-firewall-nftables> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-user-firewall-nftables> ░ Spawning container router on /build/vm-state-router. container-test-run-user-firewall-nftables> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-user-firewall-nftables> ░ Spawning container machine on /build/vm-state-machine. container-test-run-user-firewall-nftables> machine # [5013084.635834] machine systemd-journald[57]: Journal started container-test-run-user-firewall-nftables> machine # [5013084.635915] machine systemd-journald[57]: Runtime Journal (/run/log/journal/65586fa62ab4481baaf1453ccd291cfd) is 8M, max 4G, 3.9G free. container-test-run-user-firewall-nftables> machine # [5013084.645582] machine systemd[1]: Finished Apply Kernel Variables. container-test-run-user-firewall-nftables> machine # [5013084.659178] machine systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-user-firewall-nftables> machine # [5013084.698368] machine systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-user-firewall-nftables> machine # [5013084.698843] machine systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-user-firewall-nftables> machine # [5013084.706218] machine systemd-journald[57]: Time spent on flushing to /var/log/journal/65586fa62ab4481baaf1453ccd291cfd is 1.880ms for 6 entries. container-test-run-user-firewall-nftables> machine # [5013084.706218] machine systemd-journald[57]: System Journal (/var/log/journal/65586fa62ab4481baaf1453ccd291cfd) is 512B, max 4G, 3.9G free. container-test-run-user-firewall-nftables> machine # [5013084.719896] machine systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-user-firewall-nftables> machine # [5013084.724259] machine systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-user-firewall-nftables> machine # [5013084.725200] machine systemd[1]: Reached target Preparation for Local File Systems. container-test-run-user-firewall-nftables> machine # [5013084.725283] machine systemd[1]: Reached target Local File Systems. container-test-run-user-firewall-nftables> machine # [5013084.726420] machine systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-user-firewall-nftables> machine # [5013084.726461] machine systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-user-firewall-nftables> machine # [5013084.727125] machine systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-user-firewall-nftables> machine # [5013084.727654] machine systemd[1]: Starting Create System Files and Directories... container-test-run-user-firewall-nftables> machine # [5013084.727674] machine systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-user-firewall-nftables> machine # [5013084.743726] machine systemd-tmpfiles[69]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-user-firewall-nftables> machine # [5013084.743976] machine systemd-tmpfiles[69]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-user-firewall-nftables> machine # [5013084.744207] machine systemd-tmpfiles[69]: fchmod() of /var/log/journal/65586fa62ab4481baaf1453ccd291cfd failed: Operation not permitted container-test-run-user-firewall-nftables> machine # [5013084.744457] machine systemd-tmpfiles[69]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-user-firewall-nftables> machine # [5013084.745817] machine systemd[1]: Finished Create System Files and Directories. container-test-run-user-firewall-nftables> router # [5013084.640737] router systemd-journald[57]: Journal started container-test-run-user-firewall-nftables> machine # [5013084.746661] machine systemd[1]: Starting Rebuild Journal Catalog... container-test-run-user-firewall-nftables> router # [5013084.640816] router systemd-journald[57]: Runtime Journal (/run/log/journal/2048b440f9084953a197e0dc925d90ca) is 8M, max 4G, 3.9G free. container-test-run-user-firewall-nftables> machine # [5013084.747124] machine systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-user-firewall-nftables> router # [5013084.646740] router systemd[1]: Finished Apply Kernel Variables. container-test-run-user-firewall-nftables> machine # [5013084.757848] machine systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-user-firewall-nftables> router # [5013084.658976] router systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-user-firewall-nftables> machine # [5013084.765938] machine systemd[1]: Finished Rebuild Journal Catalog. container-test-run-user-firewall-nftables> router # [5013084.671258] router systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-user-firewall-nftables> machine # [5013084.766853] machine systemd[1]: Starting Update is Completed... container-test-run-user-firewall-nftables> router # [5013084.671858] router systemd[1]: Starting Network Name Resolution... container-test-run-user-firewall-nftables> machine # [5013084.775845] machine systemd[1]: Finished Update is Completed. container-test-run-user-firewall-nftables> router # [5013084.672328] router systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-user-firewall-nftables> machine # [5013084.775978] machine systemd[1]: Reached target System Initialization. container-test-run-user-firewall-nftables> router # [5013084.702698] router systemd-journald[57]: Time spent on flushing to /var/log/journal/2048b440f9084953a197e0dc925d90ca is 2.051ms for 7 entries. container-test-run-user-firewall-nftables> machine # [5013084.776048] machine systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-user-firewall-nftables> router # [5013084.702698] router systemd-journald[57]: System Journal (/var/log/journal/2048b440f9084953a197e0dc925d90ca) is 512B, max 4G, 3.9G free. container-test-run-user-firewall-nftables> machine # [5013084.776072] machine systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-user-firewall-nftables> router # [5013084.717082] router systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-user-firewall-nftables> machine # [5013084.776085] machine systemd[1]: Reached target Timer Units. container-test-run-user-firewall-nftables> router # [5013084.717849] router systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-user-firewall-nftables> machine # [5013084.776171] machine systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-user-firewall-nftables> router # [5013084.718428] router systemd[1]: Reached target Preparation for Local File Systems. container-test-run-user-firewall-nftables> machine # [5013084.776287] machine systemd[1]: Listening on Nix Daemon Socket. container-test-run-user-firewall-nftables> router # [5013084.718494] router systemd[1]: Reached target Local File Systems. container-test-run-user-firewall-nftables> machine # [5013084.776368] machine systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-user-firewall-nftables> router # [5013084.719077] router systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-user-firewall-nftables> machine # [5013084.776380] machine systemd[1]: Reached target Socket Units. container-test-run-user-firewall-nftables> router # [5013084.719110] router systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-user-firewall-nftables> machine # [5013084.776405] machine systemd[1]: Reached target Basic System. container-test-run-user-firewall-nftables> router # [5013084.720343] router systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-user-firewall-nftables> machine # [5013084.777256] machine systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-user-firewall-nftables> router # [5013084.721146] router systemd[1]: Starting Create System Files and Directories... container-test-run-user-firewall-nftables> machine # [5013084.777807] machine systemd[1]: Starting nftables firewall... container-test-run-user-firewall-nftables> router # [5013084.721176] router systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-user-firewall-nftables> machine # [5013084.778397] machine systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-user-firewall-nftables> router # [5013084.722052] router systemd[1]: Starting Network Management... container-test-run-user-firewall-nftables> machine # [5013084.791491] machine systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-user-firewall-nftables> router # [5013084.740762] router systemd-tmpfiles[71]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-user-firewall-nftables> machine # [5013084.852953] machine systemd[1]: Finished nftables firewall. container-test-run-user-firewall-nftables> router # [5013084.741076] router systemd-tmpfiles[71]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-user-firewall-nftables> machine # [5013084.853092] machine systemd[1]: Reached target Preparation for Network. container-test-run-user-firewall-nftables> router # [5013084.741234] router systemd-tmpfiles[71]: fchmod() of /var/log/journal/2048b440f9084953a197e0dc925d90ca failed: Operation not permitted container-test-run-user-firewall-nftables> machine # [5013084.853771] machine systemd[1]: Starting Address configuration of eth1... container-test-run-user-firewall-nftables> router # [5013084.741470] router systemd-tmpfiles[71]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-user-firewall-nftables> machine # [5013084.854376] machine systemd[1]: Starting Extra networking commands.... container-test-run-user-firewall-nftables> router # [5013084.743111] router systemd[1]: Finished Create System Files and Directories. container-test-run-user-firewall-nftables> machine # [5013084.855038] machine systemd[1]: Starting Setup wg0 dummy interface... container-test-run-user-firewall-nftables> router # [5013084.744007] router systemd[1]: Starting Rebuild Journal Catalog... container-test-run-user-firewall-nftables> machine # [5013084.869669] machine network-addresses-eth1-start[94]: adding address 192.168.1.1/24... done container-test-run-user-firewall-nftables> router # [5013084.744600] router systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-user-firewall-nftables> machine # [5013084.870970] machine systemd[1]: Finished Setup wg0 dummy interface. container-test-run-user-firewall-nftables> router # [5013084.755508] router systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-user-firewall-nftables> machine # [5013084.871929] machine network-addresses-eth1-start[94]: adding address 2001:db8:1::1/64... done container-test-run-user-firewall-nftables> router # [5013084.762196] router systemd[1]: Finished Rebuild Journal Catalog. container-test-run-user-firewall-nftables> machine # [5013084.874937] machine systemd[1]: Finished Address configuration of eth1. container-test-run-user-firewall-nftables> router # [5013084.763054] router systemd[1]: Starting Update is Completed... container-test-run-user-firewall-nftables> machine # [5013084.910449] machine systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-user-firewall-nftables> router # [5013084.771068] router systemd[1]: Finished Update is Completed. container-test-run-user-firewall-nftables> machine # [5013084.910695] machine systemd[1]: Finished Extra networking commands.. container-test-run-user-firewall-nftables> router # [5013084.911937] router systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-user-firewall-nftables> machine # [5013084.911520] machine systemd[1]: Reached target Network. container-test-run-user-firewall-nftables> machine # [5013084.912556] machine systemd[1]: Starting Nginx Web Server... container-test-run-user-firewall-nftables> machine # [5013084.912730] machine systemd[1]: nscd.service: Deactivated successfully. container-test-run-user-firewall-nftables> machine # [5013084.912856] machine systemd[1]: Stopped Name Service Cache Daemon (nsncd). container-test-run-user-firewall-nftables> machine # [5013084.928249] machine systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-user-firewall-nftables> machine # [5013085.083619] machine nsncd[167]: Jul 30 08:54:10.957 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-user-firewall-nftables> machine # [5013085.083713] machine systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-user-firewall-nftables> machine # [5013085.083764] machine systemd[1]: Reached target Host and Network Name Lookups. container-test-run-user-firewall-nftables> machine # [5013085.083803] machine systemd[1]: Reached target User and Group Name Lookups. container-test-run-user-firewall-nftables> machine # [5013085.084803] machine systemd[1]: Starting User Login Management... container-test-run-user-firewall-nftables> machine # [5013085.085418] machine systemd[1]: Starting Permit User Sessions... container-test-run-user-firewall-nftables> machine # [5013085.115883] machine systemd[1]: Finished Permit User Sessions. container-test-run-user-firewall-nftables> machine # [5013085.116619] machine systemd[1]: Started Console Getty. container-test-run-user-firewall-nftables> machine # [5013085.116642] machine systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-user-firewall-nftables> machine # [5013085.116657] machine systemd[1]: Reached target Login Prompts. container-test-run-user-firewall-nftables> machine # [5013085.635053] machine systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-user-firewall-nftables> router # [5013085.610767] router systemd-networkd[72]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-user-firewall-nftables> router # [5013085.610903] router systemd-networkd[72]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-user-firewall-nftables> router # [5013085.628124] router systemd-networkd[72]: lo: Link UP container-test-run-user-firewall-nftables> router # [5013085.628131] router systemd-networkd[72]: lo: Gained carrier container-test-run-user-firewall-nftables> router # [5013085.628713] router systemd-networkd[72]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-user-firewall-nftables> router # [5013085.629278] router systemd-networkd[72]: eth1: Link UP container-test-run-user-firewall-nftables> router # [5013085.629447] router systemd-networkd[72]: eth1: Gained carrier container-test-run-user-firewall-nftables> router # [5013085.636242] router systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-user-firewall-nftables> router # [5013085.636669] router systemd[1]: Started Network Management. container-test-run-user-firewall-nftables> router # [5013085.637406] router systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-user-firewall-nftables> router # [5013085.669775] router systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-user-firewall-nftables> machine # [5013085.946344] machine nginx-pre-start[192]: nginx: the configuration file /nix/store/nf6iq4xap4rarj1zyig617a3j5g2snrx-nginx.conf syntax is ok container-test-run-user-firewall-nftables> machine # [5013085.946743] machine nginx-pre-start[192]: nginx: configuration file /nix/store/nf6iq4xap4rarj1zyig617a3j5g2snrx-nginx.conf test is successful container-test-run-user-firewall-nftables> machine # [5013085.952090] machine systemd[1]: Started Nginx Web Server. container-test-run-user-firewall-nftables> machine # [5013085.994252] machine systemd-logind[182]: New seat seat0. container-test-run-user-firewall-nftables> machine # [5013085.994890] machine systemd[1]: Starting D-Bus System Message Bus... container-test-run-user-firewall-nftables> machine # [5013085.994967] machine systemd[1]: Started User Login Management. container-test-run-user-firewall-nftables> machine # [5013085.995492] machine systemd[1]: Starting linger-users.service... container-test-run-user-firewall-nftables> machine # [5013086.028193] machine systemd[1]: linger-users.service: Deactivated successfully. container-test-run-user-firewall-nftables> machine # [5013086.028403] machine systemd[1]: Finished linger-users.service. container-test-run-user-firewall-nftables> machine # [5013086.028550] machine systemd[1]: Reached target Multi-User System. container-test-run-user-firewall-nftables> machine # [5013086.338215] machine dbus-broker-launch[198]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-user-firewall-nftables> machine # [5013086.338780] machine dbus-broker-launch[198]: NSS returned no entry for 'systemd-timesync' container-test-run-user-firewall-nftables> machine # [5013086.338780] machine dbus-broker-launch[198]: Invalid user-name in /nix/store/bph0if3pjv7ni5ah929kmm18zqap0i7l-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-user-firewall-nftables> machine # [5013086.339390] machine systemd[1]: Started D-Bus System Message Bus. container-test-run-user-firewall-nftables> machine # [5013086.343924] machine dbus-broker-launch[198]: Ready container-test-run-user-firewall-nftables> machine # [5013086.344252] machine systemd[1]: Startup finished in 2.046s. container-test-run-user-firewall-nftables> router # [5013086.282148] router systemd-resolved[64]: Positive Trust Anchors: container-test-run-user-firewall-nftables> router # [5013086.282178] router systemd-resolved[64]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-user-firewall-nftables> router # [5013086.282182] router systemd-resolved[64]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-user-firewall-nftables> router # [5013086.282202] router systemd-resolved[64]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-user-firewall-nftables> router # [5013086.297795] router systemd-resolved[64]: Using system hostname 'router'. container-test-run-user-firewall-nftables> router # [5013086.299305] router systemd[1]: Started Network Name Resolution. container-test-run-user-firewall-nftables> router # [5013086.299379] router systemd[1]: Reached target Network. container-test-run-user-firewall-nftables> router # [5013086.299437] router systemd[1]: Reached target System Initialization. container-test-run-user-firewall-nftables> router # [5013086.299474] router systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-user-firewall-nftables> router # [5013086.299494] router systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-user-firewall-nftables> router # [5013086.299507] router systemd[1]: Reached target Timer Units. container-test-run-user-firewall-nftables> router # [5013086.299617] router systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-user-firewall-nftables> router # [5013086.299748] router systemd[1]: Listening on Nix Daemon Socket. container-test-run-user-firewall-nftables> router # [5013086.299837] router systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-user-firewall-nftables> router # [5013086.299849] router systemd[1]: Reached target Socket Units. container-test-run-user-firewall-nftables> router # [5013086.299876] router systemd[1]: Reached target Basic System. container-test-run-user-firewall-nftables> router # [5013086.300742] router systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-user-firewall-nftables> router # [5013086.301547] router systemd[1]: Starting Nginx Web Server... container-test-run-user-firewall-nftables> router # [5013086.302093] router systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-user-firewall-nftables> router # [5013086.302946] router systemd[1]: Starting D-Bus System Message Bus... container-test-run-user-firewall-nftables> router # [5013086.314690] router systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-user-firewall-nftables> router # [5013086.484784] router nsncd[87]: Jul 30 08:54:12.358 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-user-firewall-nftables> router # [5013086.484883] router systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-user-firewall-nftables> router # [5013086.484949] router systemd[1]: Reached target Host and Network Name Lookups. container-test-run-user-firewall-nftables> router # [5013086.485008] router systemd[1]: Reached target User and Group Name Lookups. container-test-run-user-firewall-nftables> router # [5013086.486204] router systemd[1]: Starting User Login Management... container-test-run-user-firewall-nftables> router # [5013086.486661] router systemd[1]: Starting Permit User Sessions... container-test-run-user-firewall-nftables> router # [5013086.511915] router systemd[1]: Finished Permit User Sessions. container-test-run-user-firewall-nftables> router # [5013086.513188] router systemd[1]: Started Console Getty. container-test-run-user-firewall-nftables> router # [5013086.513214] router systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-user-firewall-nftables> router # [5013086.513225] router systemd[1]: Reached target Login Prompts. container-test-run-user-firewall-nftables> router # [5013086.682026] router dbus-broker-launch[88]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-user-firewall-nftables> router # [5013086.682808] router dbus-broker-launch[88]: NSS returned no entry for 'systemd-timesync' container-test-run-user-firewall-nftables> router # [5013086.682808] router dbus-broker-launch[88]: Invalid user-name in /nix/store/abgxk9gbw731n4ci91dqx51dvdlvp5ca-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-user-firewall-nftables> router # [5013086.683397] router systemd[1]: Started D-Bus System Message Bus. container-test-run-user-firewall-nftables> router # [5013086.688014] router dbus-broker-launch[88]: Ready container-test-run-user-firewall-nftables> router # [5013087.093099] router systemd-networkd[72]: eth1: Gained IPv6LL container-test-run-user-firewall-nftables> router: (finished: waiting for unit multi-user.target, in 3.65 seconds) container-test-run-user-firewall-nftables> router: waiting for unit nginx.service container-test-run-user-firewall-nftables> router: (finished: waiting for unit nginx.service, in 0.01 seconds) container-test-run-user-firewall-nftables> machine: waiting for unit multi-user.target container-test-run-user-firewall-nftables> machine: (finished: waiting for unit multi-user.target, in 0.01 seconds) container-test-run-user-firewall-nftables> machine: waiting for unit nginx.service container-test-run-user-firewall-nftables> machine: (finished: waiting for unit nginx.service, in 0.01 seconds) container-test-run-user-firewall-nftables> router: must succeed: ip -4 addr show eth1 | grep -oP '(?<=inet\s)\d+(\.\d+){3}' container-test-run-user-firewall-nftables> router: (finished: must succeed: ip -4 addr show eth1 | grep -oP '(?<=inet\s)\d+(\.\d+){3}', in 0.01 seconds) container-test-run-user-firewall-nftables> router: must succeed: ip -6 addr show eth1 | grep -oP '(?<=inet6\s)[0-9a-f:]+' | grep -v '^fe80' | head -1 container-test-run-user-firewall-nftables> router: (finished: must succeed: ip -6 addr show eth1 | grep -oP '(?<=inet6\s)[0-9a-f:]+' | grep -v '^fe80' | head -1, in 0.01 seconds) container-test-run-user-firewall-nftables> Router IPv4: 192.168.1.2 container-test-run-user-firewall-nftables> Router IPv6: 2001:db8:1::2 container-test-run-user-firewall-nftables> machine: must succeed: systemctl restart nftables container-test-run-user-firewall-nftables> router # [5013087.355553] router nginx-pre-start[117]: nginx: the configuration file /nix/store/j9cdgw4mc0vg78rgkjyrh9l4925xkh8m-nginx.conf syntax is ok container-test-run-user-firewall-nftables> router # [5013087.355891] router nginx-pre-start[117]: nginx: configuration file /nix/store/j9cdgw4mc0vg78rgkjyrh9l4925xkh8m-nginx.conf test is successful container-test-run-user-firewall-nftables> router # [5013087.360755] router systemd[1]: Started Nginx Web Server. container-test-run-user-firewall-nftables> router # [5013087.461000] router systemd-logind[106]: New seat seat0. container-test-run-user-firewall-nftables> router # [5013087.461184] router systemd[1]: Started User Login Management. container-test-run-user-firewall-nftables> router # [5013087.462320] router systemd[1]: Starting linger-users.service... container-test-run-user-firewall-nftables> router # [5013087.495391] router systemd[1]: linger-users.service: Deactivated successfully. container-test-run-user-firewall-nftables> router # [5013087.495639] router systemd[1]: Finished linger-users.service. container-test-run-user-firewall-nftables> router # [5013087.495913] router systemd[1]: Reached target Multi-User System. container-test-run-user-firewall-nftables> router # [5013087.496032] router systemd[1]: Startup finished in 3.199s. container-test-run-user-firewall-nftables> machine: (finished: must succeed: systemctl restart nftables, in 0.16 seconds) container-test-run-user-firewall-nftables> machine: waiting for unit nftables.service container-test-run-user-firewall-nftables> machine: (finished: waiting for unit nftables.service, in 0.01 seconds) container-test-run-user-firewall-nftables> machine: must succeed: nft list table inet user-firewall >&2 container-test-run-user-firewall-nftables> table inet user-firewall { container-test-run-user-firewall-nftables> chain output { container-test-run-user-firewall-nftables> type filter hook output priority filter; policy accept; container-test-run-user-firewall-nftables> oifname "lo" counter packets 0 bytes 0 accept comment "allow lo" container-test-run-user-firewall-nftables> oifname "tun*" counter packets 0 bytes 0 accept comment "allow tun*" container-test-run-user-firewall-nftables> oifname "tap*" counter packets 0 bytes 0 accept comment "allow tap*" container-test-run-user-firewall-nftables> oifname "wg*" counter packets 0 bytes 0 accept comment "allow wg*" container-test-run-user-firewall-nftables> oifname "tailscale*" counter packets 0 bytes 0 accept comment "allow tailscale*" container-test-run-user-firewall-nftables> oifname "zt*" counter packets 0 bytes 0 accept comment "allow zt*" container-test-run-user-firewall-nftables> oifname "vpn*" counter packets 0 bytes 0 accept comment "allow vpn*" container-test-run-user-firewall-nftables> oifname "ipsec*" counter packets 0 bytes 0 accept comment "allow ipsec*" container-test-run-user-firewall-nftables> oifname "nebula*" counter packets 0 bytes 0 accept comment "allow nebula*" container-test-run-user-firewall-nftables> oifname "tinc*" counter packets 0 bytes 0 accept comment "allow tinc*" container-test-run-user-firewall-nftables> oifname "edge*" counter packets 0 bytes 0 accept comment "allow edge*" container-test-run-user-firewall-nftables> oifname "hyprspace" counter packets 0 bytes 0 accept comment "allow hyprspace" container-test-run-user-firewall-nftables> oifname "ham0" counter packets 0 bytes 0 accept comment "allow ham0" container-test-run-user-firewall-nftables> oifname "easytier" counter packets 0 bytes 0 accept comment "allow easytier" container-test-run-user-firewall-nftables> oifname "mycelium" counter packets 0 bytes 0 accept comment "allow mycelium" container-test-run-user-firewall-nftables> meta skuid 1002 counter packets 0 bytes 0 reject comment "blocked user bob" container-test-run-user-firewall-nftables> } container-test-run-user-firewall-nftables> } container-test-run-user-firewall-nftables> machine: (finished: must succeed: nft list table inet user-firewall >&2, in 0.01 seconds) container-test-run-user-firewall-nftables> machine: waiting for success: runuser -u alice -- curl -s http://127.0.0.1:8080 container-test-run-user-firewall-nftables> machine: (finished: waiting for success: runuser -u alice -- curl -s http://127.0.0.1:8080, in 0.02 seconds) container-test-run-user-firewall-nftables> machine: must succeed: runuser -u alice -- curl -s http://192.168.1.2 container-test-run-user-firewall-nftables> machine: output: container-test-run-user-firewall-nftables> !!! Traceback (most recent call last): container-test-run-user-firewall-nftables> !!! File "", line 22, in container-test-run-user-firewall-nftables> !!! machine.succeed(f"runuser -u alice -- curl -s http://{router_ip}") container-test-run-user-firewall-nftables> !!! container-test-run-user-firewall-nftables> !!! RequestedAssertionFailed: command `runuser -u alice -- curl -s http://192.168.1.2` failed (exit code 7) container-test-run-user-firewall-nftables> cleanup container-test-run-user-firewall-nftables> kill NspawnMachine (pid 52) container-test-run-user-firewall-nftables> kill NspawnMachine (pid 53) container-test-run-user-firewall-nftables> Container machine terminated by signal KILL. container-test-run-user-firewall-nftables> Container router terminated by signal KILL. container-test-run-user-firewall-nftables> (finished: cleanup, in 0.23 seconds) error: Cannot build '/nix/store/rrcw3h3c6mjxf9mhp37qmr74z64wcmh5-container-test-run-user-firewall-nftables.drv'. Reason: builder failed with exit code 1. Output paths: /nix/store/ixj0mxp2cpkhz6m371ynhqkd7bmpqzmi-container-test-run-user-firewall-nftables Last 25 log lines: > oifname "tinc*" counter packets 0 bytes 0 accept comment "allow tinc*" > oifname "edge*" counter packets 0 bytes 0 accept comment "allow edge*" > oifname "hyprspace" counter packets 0 bytes 0 accept comment "allow hyprspace" > oifname "ham0" counter packets 0 bytes 0 accept comment "allow ham0" > oifname "easytier" counter packets 0 bytes 0 accept comment "allow easytier" > oifname "mycelium" counter packets 0 bytes 0 accept comment "allow mycelium" > meta skuid 1002 counter packets 0 bytes 0 reject comment "blocked user bob" > } > } > machine: (finished: must succeed: nft list table inet user-firewall >&2, in 0.01 seconds) > machine: waiting for success: runuser -u alice -- curl -s http://127.0.0.1:8080 > machine: (finished: waiting for success: runuser -u alice -- curl -s http://127.0.0.1:8080, in 0.02 seconds) > machine: must succeed: runuser -u alice -- curl -s http://192.168.1.2 > machine: output: > !!! Traceback (most recent call last): > !!! File "", line 22, in > !!! machine.succeed(f"runuser -u alice -- curl -s http://{router_ip}") > !!! > !!! RequestedAssertionFailed: command `runuser -u alice -- curl -s http://192.168.1.2` failed (exit code 7) > cleanup > kill NspawnMachine (pid 52) > kill NspawnMachine (pid 53) > Container machine terminated by signal KILL. > Container router terminated by signal KILL. > (finished: cleanup, in 0.23 seconds) For full logs, run: nix log /nix/store/rrcw3h3c6mjxf9mhp37qmr74z64wcmh5-container-test-run-user-firewall-nftables.drv