these 58 derivations will be built: /nix/store/0hsyifvil86vrw5d5xlgavqjyglpvadi-firewall-stop.drv /nix/store/27qp7sdfll8dljj02vdlx4qpfjxm0p1w-nginx.conf.drv /nix/store/345v23r4x62c7wv5ylnyl05lbpdc9him-string-hosts.drv /nix/store/dx6vrzz0p2ja0c62ckdvpjzngljg8m1v-system-path.drv /nix/store/gvdd4a1pydc5m7q8z9awm3m4d6qkr2s3-etc-hostname.drv /nix/store/wn8xmw45a8wwzm7gf84cg8ya71p9nm75-X-Reload-Triggers-systemd-networkd.drv /nix/store/4n5kpda9dna6km3cmlrxp0hcp9cn3899-unit-systemd-networkd.service.drv /nix/store/pqlv5py8m2byf3vc1kh5dgf5vx0i5mpw-nix.conf.drv /nix/store/skaf8szy3l3s46izq7w49pgw0nk3aza3-X-Restart-Triggers-nix-daemon.drv /nix/store/k37pwzkm9p0av0jzvcqq6jshds12ch0j-unit-nix-daemon.service.drv /nix/store/sb1hf464gablgmy1b3a6kl323hj969mk-dbus-1.drv /nix/store/j68mic8jqjsiy7xbapfmwp35qgpacr7z-X-Restart-Triggers-dbus-broker.drv /nix/store/vajilbv47nv99hnrij340sh6l4bp8vhi-unit-dbus-broker.service.drv /nix/store/bm5y5ylq134bbpjcmcynfpi8mqi9m0rl-unit-script-nginx-pre-start.drv /nix/store/x79y2317km0rkl452wm976y8g2zpi0bm-unit-nginx.service.drv /nix/store/y9cja7pjn3x5h6n2hrqpnvbssr7j10sq-unit-systemd-networkd-wait-online.service.drv /nix/store/n650ddf0z3r4xib9bj940a4pigzvlqi6-system-units.drv /nix/store/s8lfkg9az6rry55pspmark1zxg9np9dc-extra-hosts.drv /nix/store/nibmgm5pama8yj1hzna18ljkbny4yhh7-hosts.drv /nix/store/g9cnb2x3ywa5s6x7sp7v95sa5vhqgz5d-unit-dbus-broker.service.drv /nix/store/y7824jf80ryffsjc91rhvxmkbmldnly5-user-units.drv /nix/store/dmjz212xbh416jzb2bp34l80mig0jrsj-etc.drv /nix/store/gj8yfl8bxb0gp9nvmi419xj2gaxr3gpw-users-groups.json.drv /nix/store/7pvvp5sy0pw90kdjprpdzrr5rfgg5a2s-activate.drv /nix/store/k6x3lv79qm5gxqr6gx8npjn651rfjmdi-dry-activate.drv /nix/store/39k9zdx2jkpr4dwgkjxc2k54zw3jkp3z-nixos-system-router-test.drv /nix/store/3x42kbdmkvzqnkasy7j6caj60r7j3n15-run-router-nspawn.drv /nix/store/416phh4ardhmd20nhg0jmjp0cpy2bw18-test-script.drv /nix/store/5d34ahi37bihkidmigra157v15svixhf-nginx.conf.drv /nix/store/b8sb0q1jqah7727fw49bdrv120cxhidc-unit-script-network-addresses-eth1-start.drv /nix/store/k0816sm0w6hrmr8r86xr4iq9hh8x0w3d-unit-script-network-addresses-eth1-pre-stop.drv /nix/store/82a2d5hdh6qbs1n585c5x49jbnzml4m1-unit-network-addresses-eth1.service.drv /nix/store/ssyriiz3nxa6vk64f4mq7wx8ygd3q71l-system-path.drv /nix/store/q9bqic83my6185xy47c0srh4cqfpszw4-dbus-1.drv /nix/store/89crwnij5afsb5h4hrixqd0bncn0m7pw-X-Restart-Triggers-dbus-broker.drv /nix/store/w3dyjlnn08a4m3i6bh451mhqmfbvcx4w-unit-script-setup-wg0-interface-start.drv /nix/store/9vgmyx6ff3wh9qd2x3j7a8vsix6gr18p-unit-setup-wg0-interface.service.drv /nix/store/z947zivva45sffh0ia5dpdrikdk2gh2m-users-groups.json.drv /nix/store/ayyzrjhlcma3sx37i9a8s5azzjhsclm9-dry-activate.drv /nix/store/nnkv5h59kdkqz1c9vz0qbfg7dndljlwy-string-hosts.drv /nix/store/i45nxdah96m62z2px82j85ivwh0k0w4i-hosts.drv /nix/store/fsr7dv2fm1p2vag4yiky47pvh5q94311-unit-script-nginx-pre-start.drv /nix/store/f7lfw13vcxy3sj4val6rib6wj9ajbk6g-unit-nginx.service.drv /nix/store/jia3ah144s1h35swi1mjq136zhxhqscg-unit-dbus-broker.service.drv /nix/store/lkg9y3hrqp0z6dp1qkj4a4dcrb8swaf8-firewall-start.drv /nix/store/vamss6avf51ya7dx4q4vkvlbs7lcbrxb-firewall-reload.drv /nix/store/p2km9lp0fmjaqvg03c1zip11c78q2a79-unit-firewall.service.drv /nix/store/rg3srmp4b1fxp72kdwz1ws97159sff1b-system-units.drv /nix/store/qvmmpa29l7fai4mbk0hvr6qj0dryz5k4-unit-dbus-broker.service.drv /nix/store/ww1vxg8rqy8n6dk34kmnq9jk3chlj08g-user-units.drv /nix/store/zhsljz1wal4xd5q41fb0zbwm6p7ayvwv-unit-40-eth1.link.drv /nix/store/ml0pxfsfzl10j0nsc9c2s28l23l4bg3k-etc.drv /nix/store/wb130pgkd2l7nw31kwnmsx4v5wi407qi-activate.drv /nix/store/bir37cvz0h2dr2qai6qkm21gvk7rv3nx-nixos-system-machine-test.drv /nix/store/q2dk01py6k5wyk955jmrjipbmaqs78d7-run-machine-nspawn.drv /nix/store/nw01nf21cvkw59pvplrgmjx3hmyw5d52-driverConfiguration.json.drv /nix/store/l8kk37pkx4d5mb2j50bgcass2lpmy9qr-nixos-test-driver-user-firewall-iptables.drv /nix/store/gvy96dx8h5i505xf28zyii7hjcisc638-container-test-run-user-firewall-iptables.drv this path will be fetched (127.1 KiB download, 628.9 KiB unpacked): /nix/store/zij9b46pjc9bsrqij0kqcb8kl96syfa3-nixos-test-driver-1.1 building '/nix/store/416phh4ardhmd20nhg0jmjp0cpy2bw18-test-script.drv' building '/nix/store/dx6vrzz0p2ja0c62ckdvpjzngljg8m1v-system-path.drv' building '/nix/store/ssyriiz3nxa6vk64f4mq7wx8ygd3q71l-system-path.drv' building '/nix/store/gvdd4a1pydc5m7q8z9awm3m4d6qkr2s3-etc-hostname.drv' building '/nix/store/27qp7sdfll8dljj02vdlx4qpfjxm0p1w-nginx.conf.drv' building '/nix/store/5d34ahi37bihkidmigra157v15svixhf-nginx.conf.drv' building '/nix/store/pqlv5py8m2byf3vc1kh5dgf5vx0i5mpw-nix.conf.drv' building '/nix/store/zhsljz1wal4xd5q41fb0zbwm6p7ayvwv-unit-40-eth1.link.drv' building '/nix/store/s8lfkg9az6rry55pspmark1zxg9np9dc-extra-hosts.drv' building '/nix/store/345v23r4x62c7wv5ylnyl05lbpdc9him-string-hosts.drv' nginx.conf> structuredAttrs is enabled nginx.conf> structuredAttrs is enabled nix.conf> Validating generated nix.conf system-path> structuredAttrs is enabled system-path> created 1566 symlinks in user environment system-path> structuredAttrs is enabled system-path> created 1660 symlinks in user environment unit-40-eth1.link> structuredAttrs is enabled building '/nix/store/nnkv5h59kdkqz1c9vz0qbfg7dndljlwy-string-hosts.drv' building '/nix/store/y9cja7pjn3x5h6n2hrqpnvbssr7j10sq-unit-systemd-networkd-wait-online.service.drv' building '/nix/store/0hsyifvil86vrw5d5xlgavqjyglpvadi-firewall-stop.drv' building '/nix/store/k0816sm0w6hrmr8r86xr4iq9hh8x0w3d-unit-script-network-addresses-eth1-pre-stop.drv' building '/nix/store/b8sb0q1jqah7727fw49bdrv120cxhidc-unit-script-network-addresses-eth1-start.drv' building '/nix/store/w3dyjlnn08a4m3i6bh451mhqmfbvcx4w-unit-script-setup-wg0-interface-start.drv' nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> unit-systemd-networkd-wait-online.service> structuredAttrs is enabled building '/nix/store/skaf8szy3l3s46izq7w49pgw0nk3aza3-X-Restart-Triggers-nix-daemon.drv' building '/nix/store/lkg9y3hrqp0z6dp1qkj4a4dcrb8swaf8-firewall-start.drv' building '/nix/store/nibmgm5pama8yj1hzna18ljkbny4yhh7-hosts.drv' building '/nix/store/wn8xmw45a8wwzm7gf84cg8ya71p9nm75-X-Reload-Triggers-systemd-networkd.drv' building '/nix/store/q9bqic83my6185xy47c0srh4cqfpszw4-dbus-1.drv' building '/nix/store/sb1hf464gablgmy1b3a6kl323hj969mk-dbus-1.drv' building '/nix/store/i45nxdah96m62z2px82j85ivwh0k0w4i-hosts.drv' building '/nix/store/gj8yfl8bxb0gp9nvmi419xj2gaxr3gpw-users-groups.json.drv' building '/nix/store/z947zivva45sffh0ia5dpdrikdk2gh2m-users-groups.json.drv' building '/nix/store/82a2d5hdh6qbs1n585c5x49jbnzml4m1-unit-network-addresses-eth1.service.drv' building '/nix/store/bm5y5ylq134bbpjcmcynfpi8mqi9m0rl-unit-script-nginx-pre-start.drv' unit-network-addresses-eth1.service> structuredAttrs is enabled building '/nix/store/fsr7dv2fm1p2vag4yiky47pvh5q94311-unit-script-nginx-pre-start.drv' building '/nix/store/9vgmyx6ff3wh9qd2x3j7a8vsix6gr18p-unit-setup-wg0-interface.service.drv' building '/nix/store/89crwnij5afsb5h4hrixqd0bncn0m7pw-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/j68mic8jqjsiy7xbapfmwp35qgpacr7z-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/ayyzrjhlcma3sx37i9a8s5azzjhsclm9-dry-activate.drv' building '/nix/store/k6x3lv79qm5gxqr6gx8npjn651rfjmdi-dry-activate.drv' building '/nix/store/vamss6avf51ya7dx4q4vkvlbs7lcbrxb-firewall-reload.drv' building '/nix/store/k37pwzkm9p0av0jzvcqq6jshds12ch0j-unit-nix-daemon.service.drv' unit-setup-wg0-interface.service> structuredAttrs is enabled building '/nix/store/4n5kpda9dna6km3cmlrxp0hcp9cn3899-unit-systemd-networkd.service.drv' building '/nix/store/g9cnb2x3ywa5s6x7sp7v95sa5vhqgz5d-unit-dbus-broker.service.drv' building '/nix/store/jia3ah144s1h35swi1mjq136zhxhqscg-unit-dbus-broker.service.drv' building '/nix/store/qvmmpa29l7fai4mbk0hvr6qj0dryz5k4-unit-dbus-broker.service.drv' building '/nix/store/vajilbv47nv99hnrij340sh6l4bp8vhi-unit-dbus-broker.service.drv' building '/nix/store/f7lfw13vcxy3sj4val6rib6wj9ajbk6g-unit-nginx.service.drv' building '/nix/store/x79y2317km0rkl452wm976y8g2zpi0bm-unit-nginx.service.drv' unit-dbus-broker.service> structuredAttrs is enabled unit-dbus-broker.service> structuredAttrs is enabled unit-dbus-broker.service> structuredAttrs is enabled unit-dbus-broker.service> structuredAttrs is enabled unit-nginx.service> structuredAttrs is enabled unit-nix-daemon.service> structuredAttrs is enabled unit-systemd-networkd.service> structuredAttrs is enabled building '/nix/store/p2km9lp0fmjaqvg03c1zip11c78q2a79-unit-firewall.service.drv' unit-nginx.service> structuredAttrs is enabled building '/nix/store/ww1vxg8rqy8n6dk34kmnq9jk3chlj08g-user-units.drv' building '/nix/store/y7824jf80ryffsjc91rhvxmkbmldnly5-user-units.drv' unit-firewall.service> structuredAttrs is enabled building '/nix/store/n650ddf0z3r4xib9bj940a4pigzvlqi6-system-units.drv' building '/nix/store/rg3srmp4b1fxp72kdwz1ws97159sff1b-system-units.drv' building '/nix/store/dmjz212xbh416jzb2bp34l80mig0jrsj-etc.drv' building '/nix/store/ml0pxfsfzl10j0nsc9c2s28l23l4bg3k-etc.drv' building '/nix/store/7pvvp5sy0pw90kdjprpdzrr5rfgg5a2s-activate.drv' building '/nix/store/wb130pgkd2l7nw31kwnmsx4v5wi407qi-activate.drv' building '/nix/store/39k9zdx2jkpr4dwgkjxc2k54zw3jkp3z-nixos-system-router-test.drv' building '/nix/store/bir37cvz0h2dr2qai6qkm21gvk7rv3nx-nixos-system-machine-test.drv' nixos-system-router-test> structuredAttrs is enabled building '/nix/store/3x42kbdmkvzqnkasy7j6caj60r7j3n15-run-router-nspawn.drv' nixos-system-machine-test> structuredAttrs is enabled building '/nix/store/q2dk01py6k5wyk955jmrjipbmaqs78d7-run-machine-nspawn.drv' building '/nix/store/nw01nf21cvkw59pvplrgmjx3hmyw5d52-driverConfiguration.json.drv' driverConfiguration.json> structuredAttrs is enabled building '/nix/store/l8kk37pkx4d5mb2j50bgcass2lpmy9qr-nixos-test-driver-user-firewall-iptables.drv' nixos-test-driver-user-firewall-iptables> Running type check (enable/disable: config.skipTypeCheck) nixos-test-driver-user-firewall-iptables> See https://nixos.org/manual/nixos/stable/#test-opt-skipTypeCheck nixos-test-driver-user-firewall-iptables> All checks passed! nixos-test-driver-user-firewall-iptables> Linting test script (enable/disable: config.skipLint) nixos-test-driver-user-firewall-iptables> See https://nixos.org/manual/nixos/stable/#test-opt-skipLint nixos-test-driver-user-firewall-iptables> All checks passed! building '/nix/store/gvy96dx8h5i505xf28zyii7hjcisc638-container-test-run-user-firewall-iptables.drv' on 'ssh-ng://builder@build-x86-01.clan.lol' building '/nix/store/gvy96dx8h5i505xf28zyii7hjcisc638-container-test-run-user-firewall-iptables.drv' container-test-run-user-firewall-iptables> Machine state will be reset. To keep it, pass --keep-machine-state container-test-run-user-firewall-iptables> start all VLans container-test-run-user-firewall-iptables> (finished: start all VLans, in 0.00 seconds) container-test-run-user-firewall-iptables> container-test-run-user-firewall-iptables> Test will time out and terminate in 3600.0 seconds container-test-run-user-firewall-iptables> run the VM test script container-test-run-user-firewall-iptables> additionally exposed symbols: container-test-run-user-firewall-iptables> machine, router, container-test-run-user-firewall-iptables> vlan1, container-test-run-user-firewall-iptables> start_all, test_script, machines, machines_qemu, machines_nspawn, vlans, driver, log, os, create_machine, subtest, run_tests, join_all, retry, serial_stdout_off, serial_stdout_on, polling_condition, BaseMachine, QemuMachine, NspawnMachine, t, debug, dump_machine_ssh container-test-run-user-firewall-iptables> start all VMs container-test-run-user-firewall-iptables> machine: systemd-nspawn running (pid 52) container-test-run-user-firewall-iptables> router: systemd-nspawn running (pid 53) container-test-run-user-firewall-iptables> machine: Waiting for journal at /build/vm-state-machine/var/log/journal... container-test-run-user-firewall-iptables> router: Waiting for journal at /build/vm-state-router/var/log/journal... container-test-run-user-firewall-iptables> (finished: start all VMs, in 0.00 seconds) container-test-run-user-firewall-iptables> router: waiting for unit multi-user.target container-test-run-user-firewall-iptables> nixos-nspawn(router): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-user-firewall-iptables> nixos-nspawn(router): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-user-firewall-iptables> nixos-nspawn(machine): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-user-firewall-iptables> nixos-nspawn(machine): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-user-firewall-iptables> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-user-firewall-iptables> ░ Spawning container router on /build/vm-state-router. container-test-run-user-firewall-iptables> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-user-firewall-iptables> ░ Spawning container machine on /build/vm-state-machine. container-test-run-user-firewall-iptables> router # [7257743.721519] router systemd-journald[54]: Journal started container-test-run-user-firewall-iptables> router # [7257743.721545] router systemd-journald[54]: Runtime Journal (/run/log/journal/9fd36d8791354649a4bb20bb5f59b60e) is 8M, max 3.7G, 3.7G free. container-test-run-user-firewall-iptables> router # [7257743.722734] router systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-user-firewall-iptables> router # [7257743.728058] router systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-user-firewall-iptables> router # [7257743.728488] router systemd[1]: Starting Network Name Resolution... container-test-run-user-firewall-iptables> router # [7257743.728800] router systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-user-firewall-iptables> router # [7257743.753672] router systemd-journald[54]: Time spent on flushing to /var/log/journal/9fd36d8791354649a4bb20bb5f59b60e is 1.218ms for 6 entries. container-test-run-user-firewall-iptables> router # [7257743.753672] router systemd-journald[54]: System Journal (/var/log/journal/9fd36d8791354649a4bb20bb5f59b60e) is 8M, max 4G, 3.9G free. container-test-run-user-firewall-iptables> router # [7257743.757418] router systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-user-firewall-iptables> router # [7257743.757860] router systemd[1]: Reached target Preparation for Local File Systems. container-test-run-user-firewall-iptables> router # [7257743.757920] router systemd[1]: Reached target Local File Systems. container-test-run-user-firewall-iptables> router # [7257743.758445] router systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-user-firewall-iptables> router # [7257743.758482] router systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-user-firewall-iptables> router # [7257743.759018] router systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-user-firewall-iptables> router # [7257743.759040] router systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-user-firewall-iptables> router # [7257743.759622] router systemd[1]: Starting Network Management... container-test-run-user-firewall-iptables> router # [7257743.759858] router systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-user-firewall-iptables> router # [7257743.760730] router systemd[1]: Starting Create System Files and Directories... container-test-run-user-firewall-iptables> router # [7257743.770758] router systemd-tmpfiles[69]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-user-firewall-iptables> router # [7257743.770945] router systemd-tmpfiles[69]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-user-firewall-iptables> router # [7257743.771081] router systemd-tmpfiles[69]: fchmod() of /var/log/journal/9fd36d8791354649a4bb20bb5f59b60e failed: Operation not permitted container-test-run-user-firewall-iptables> router # [7257743.771266] router systemd-tmpfiles[69]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-user-firewall-iptables> router # [7257743.772128] router systemd[1]: Finished Create System Files and Directories. container-test-run-user-firewall-iptables> router # [7257743.772698] router systemd[1]: Starting Rebuild Journal Catalog... container-test-run-user-firewall-iptables> router # [7257743.773166] router systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-user-firewall-iptables> router # [7257743.780672] router systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-user-firewall-iptables> router # [7257743.796652] router systemd[1]: Finished Rebuild Journal Catalog. container-test-run-user-firewall-iptables> router # [7257743.797142] router systemd[1]: Starting Update is Completed... container-test-run-user-firewall-iptables> router # [7257743.805290] router systemd[1]: Finished Update is Completed. container-test-run-user-firewall-iptables> router # [7257743.811505] router systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-user-firewall-iptables> router # [7257744.060065] router systemd-networkd[67]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-user-firewall-iptables> router # [7257744.060150] router systemd-networkd[67]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-user-firewall-iptables> router # [7257744.065408] router systemd-networkd[67]: lo: Link UP container-test-run-user-firewall-iptables> router # [7257744.065416] router systemd-networkd[67]: lo: Gained carrier container-test-run-user-firewall-iptables> router # [7257744.065582] router systemd-networkd[67]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-user-firewall-iptables> router # [7257744.065885] router systemd[1]: Started Network Management. container-test-run-user-firewall-iptables> router # [7257744.065953] router systemd-networkd[67]: eth1: Link UP container-test-run-user-firewall-iptables> router # [7257744.066102] router systemd-networkd[67]: eth1: Gained carrier container-test-run-user-firewall-iptables> router # [7257744.066626] router systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-user-firewall-iptables> router # [7257744.086992] router systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-user-firewall-iptables> machine # [7257743.717837] machine systemd-journald[54]: Journal started container-test-run-user-firewall-iptables> machine # [7257743.717866] machine systemd-journald[54]: Runtime Journal (/run/log/journal/0fc8b5b569824b38b19a4aa40527e12b) is 8M, max 3.7G, 3.7G free. container-test-run-user-firewall-iptables> machine # [7257743.718977] machine systemd[1]: Finished Apply Kernel Variables. container-test-run-user-firewall-iptables> machine # [7257743.722684] machine systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-user-firewall-iptables> machine # [7257743.728129] machine systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-user-firewall-iptables> machine # [7257743.728675] machine systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-user-firewall-iptables> machine # [7257743.753675] machine systemd-journald[54]: Time spent on flushing to /var/log/journal/0fc8b5b569824b38b19a4aa40527e12b is 915us for 6 entries. container-test-run-user-firewall-iptables> machine # [7257743.753675] machine systemd-journald[54]: System Journal (/var/log/journal/0fc8b5b569824b38b19a4aa40527e12b) is 8M, max 4G, 3.9G free. container-test-run-user-firewall-iptables> machine # [7257743.757398] machine systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-user-firewall-iptables> machine # [7257743.757802] machine systemd[1]: Reached target Preparation for Local File Systems. container-test-run-user-firewall-iptables> machine # [7257743.757854] machine systemd[1]: Reached target Local File Systems. container-test-run-user-firewall-iptables> machine # [7257743.758348] machine systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-user-firewall-iptables> machine # [7257743.758377] machine systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-user-firewall-iptables> machine # [7257743.758888] machine systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-user-firewall-iptables> machine # [7257743.758906] machine systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-user-firewall-iptables> machine # [7257743.759581] machine systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-user-firewall-iptables> machine # [7257743.759990] machine systemd[1]: Starting Create System Files and Directories... container-test-run-user-firewall-iptables> machine # [7257743.770706] machine systemd-tmpfiles[111]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-user-firewall-iptables> machine # [7257743.770878] machine systemd-tmpfiles[111]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-user-firewall-iptables> machine # [7257743.770988] machine systemd-tmpfiles[111]: fchmod() of /var/log/journal/0fc8b5b569824b38b19a4aa40527e12b failed: Operation not permitted container-test-run-user-firewall-iptables> machine # [7257743.771163] machine systemd-tmpfiles[111]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-user-firewall-iptables> machine # [7257743.772244] machine systemd[1]: Finished Create System Files and Directories. container-test-run-user-firewall-iptables> machine # [7257743.772782] machine systemd[1]: Starting Rebuild Journal Catalog... container-test-run-user-firewall-iptables> machine # [7257743.773164] machine systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-user-firewall-iptables> machine # [7257743.780272] machine systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-user-firewall-iptables> machine # [7257743.796611] machine systemd[1]: Finished Rebuild Journal Catalog. container-test-run-user-firewall-iptables> machine # [7257743.797297] machine systemd[1]: Starting Update is Completed... container-test-run-user-firewall-iptables> machine # [7257743.805307] machine systemd[1]: Finished Update is Completed. container-test-run-user-firewall-iptables> machine # [7257743.805405] machine systemd[1]: Reached target System Initialization. container-test-run-user-firewall-iptables> machine # [7257743.805447] machine systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-user-firewall-iptables> machine # [7257743.805465] machine systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-user-firewall-iptables> machine # [7257743.805476] machine systemd[1]: Reached target Timer Units. container-test-run-user-firewall-iptables> machine # [7257743.805539] machine systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-user-firewall-iptables> machine # [7257743.805780] machine systemd[1]: Listening on Nix Daemon Socket. container-test-run-user-firewall-iptables> machine # [7257743.805879] machine systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-user-firewall-iptables> machine # [7257743.805894] machine systemd[1]: Reached target Socket Units. container-test-run-user-firewall-iptables> machine # [7257743.805921] machine systemd[1]: Reached target Basic System. container-test-run-user-firewall-iptables> machine # [7257743.806563] machine systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-user-firewall-iptables> machine # [7257743.806996] machine systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-user-firewall-iptables> machine # [7257743.811257] machine systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-user-firewall-iptables> machine # [7257743.815803] machine systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-user-firewall-iptables> machine # [7257743.859654] machine nsncd[160]: Aug 23 10:03:21.225 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-user-firewall-iptables> machine # [7257743.859731] machine systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-user-firewall-iptables> machine # [7257743.859932] machine systemd[1]: Finished Firewall. container-test-run-user-firewall-iptables> machine # [7257743.860329] machine systemd[1]: Reached target Preparation for Network. container-test-run-user-firewall-iptables> machine # [7257743.860372] machine systemd[1]: Reached target Host and Network Name Lookups. container-test-run-user-firewall-iptables> machine # [7257743.860394] machine systemd[1]: Reached target User and Group Name Lookups. container-test-run-user-firewall-iptables> machine # [7257743.861052] machine systemd[1]: Starting Address configuration of eth1... container-test-run-user-firewall-iptables> machine # [7257743.861615] machine systemd[1]: Starting Extra networking commands.... container-test-run-user-firewall-iptables> machine # [7257743.862116] machine systemd[1]: Starting Setup wg0 dummy interface... container-test-run-user-firewall-iptables> machine # [7257743.862801] machine systemd[1]: Starting User Login Management... container-test-run-user-firewall-iptables> machine # [7257743.893147] machine network-addresses-eth1-start[222]: adding address 192.168.1.1/24... done container-test-run-user-firewall-iptables> machine # [7257743.894417] machine systemd[1]: Finished Setup wg0 dummy interface. container-test-run-user-firewall-iptables> machine # [7257743.894543] machine network-addresses-eth1-start[222]: adding address 2001:db8:1::1/64... done container-test-run-user-firewall-iptables> machine # [7257743.897183] machine systemd[1]: Finished Address configuration of eth1. container-test-run-user-firewall-iptables> machine # [7257743.910251] machine systemd[1]: Stopped target Host and Network Name Lookups. container-test-run-user-firewall-iptables> machine # [7257743.910278] machine systemd[1]: Stopping Host and Network Name Lookups... container-test-run-user-firewall-iptables> machine # [7257743.910298] machine systemd[1]: Stopped target User and Group Name Lookups. container-test-run-user-firewall-iptables> machine # [7257743.910314] machine systemd[1]: Stopping User and Group Name Lookups... container-test-run-user-firewall-iptables> machine # [7257743.910416] machine systemd[1]: Stopping Name Service Cache Daemon (nsncd)... container-test-run-user-firewall-iptables> machine # [7257743.912506] machine systemd[1]: nscd.service: Deactivated successfully. container-test-run-user-firewall-iptables> machine # [7257743.912600] machine systemd[1]: Stopped Name Service Cache Daemon (nsncd). container-test-run-user-firewall-iptables> machine # [7257743.913861] machine systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-user-firewall-iptables> machine # [7257743.931143] machine systemd[1]: Finished Extra networking commands.. container-test-run-user-firewall-iptables> machine # [7257743.931317] machine systemd[1]: Reached target Network. container-test-run-user-firewall-iptables> machine # [7257743.932013] machine systemd[1]: Starting Nginx Web Server... container-test-run-user-firewall-iptables> machine # [7257743.982926] machine nsncd[294]: Aug 23 10:03:21.348 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-user-firewall-iptables> machine # [7257743.982962] machine systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-user-firewall-iptables> machine # [7257743.982997] machine systemd[1]: Reached target Host and Network Name Lookups. container-test-run-user-firewall-iptables> machine # [7257743.983035] machine systemd[1]: Reached target User and Group Name Lookups. container-test-run-user-firewall-iptables> machine # [7257743.983505] machine systemd[1]: Starting Permit User Sessions... container-test-run-user-firewall-iptables> machine # [7257744.007400] machine systemd[1]: Finished Permit User Sessions. container-test-run-user-firewall-iptables> machine # [7257744.007972] machine systemd[1]: Started Console Getty. container-test-run-user-firewall-iptables> machine # [7257744.007997] machine systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-user-firewall-iptables> machine # [7257744.008016] machine systemd[1]: Reached target Login Prompts. container-test-run-user-firewall-iptables> machine # [7257744.202224] machine systemd-logind[225]: New seat seat0. container-test-run-user-firewall-iptables> machine # [7257744.202934] machine systemd[1]: Starting D-Bus System Message Bus... container-test-run-user-firewall-iptables> machine # [7257744.203020] machine systemd[1]: Started User Login Management. container-test-run-user-firewall-iptables> machine # [7257744.203500] machine systemd[1]: Starting linger-users.service... container-test-run-user-firewall-iptables> machine # [7257744.231155] machine systemd[1]: linger-users.service: Deactivated successfully. container-test-run-user-firewall-iptables> machine # [7257744.231274] machine systemd[1]: Finished linger-users.service. container-test-run-user-firewall-iptables> router # [7257744.263190] router systemd-resolved[61]: Positive Trust Anchors: container-test-run-user-firewall-iptables> router # [7257744.263198] router systemd-resolved[61]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-user-firewall-iptables> router # [7257744.263202] router systemd-resolved[61]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-user-firewall-iptables> router # [7257744.263220] router systemd-resolved[61]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-user-firewall-iptables> router # [7257744.274391] router systemd-resolved[61]: Using system hostname 'router'. container-test-run-user-firewall-iptables> router # [7257744.275405] router systemd[1]: Started Network Name Resolution. container-test-run-user-firewall-iptables> router # [7257744.275457] router systemd[1]: Reached target Network. container-test-run-user-firewall-iptables> router # [7257744.275493] router systemd[1]: Reached target System Initialization. container-test-run-user-firewall-iptables> router # [7257744.275527] router systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-user-firewall-iptables> router # [7257744.275546] router systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-user-firewall-iptables> router # [7257744.275561] router systemd[1]: Reached target Timer Units. container-test-run-user-firewall-iptables> router # [7257744.275644] router systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-user-firewall-iptables> router # [7257744.275712] router systemd[1]: Listening on Nix Daemon Socket. container-test-run-user-firewall-iptables> router # [7257744.275782] router systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-user-firewall-iptables> router # [7257744.275792] router systemd[1]: Reached target Socket Units. container-test-run-user-firewall-iptables> router # [7257744.275813] router systemd[1]: Reached target Basic System. container-test-run-user-firewall-iptables> router # [7257744.276439] router systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-user-firewall-iptables> router # [7257744.276801] router systemd[1]: Starting Nginx Web Server... container-test-run-user-firewall-iptables> router # [7257744.277141] router systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-user-firewall-iptables> router # [7257744.277949] router systemd[1]: Starting D-Bus System Message Bus... container-test-run-user-firewall-iptables> router # [7257744.305744] router systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-user-firewall-iptables> machine # [7257744.291266] machine nginx-pre-start[323]: nginx: the configuration file /nix/store/l3cd84w4xgf1kji8qqry6kj3fknp5iv2-nginx.conf syntax is ok container-test-run-user-firewall-iptables> router # [7257744.363437] router nsncd[84]: Aug 23 10:03:21.729 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-user-firewall-iptables> machine # [7257744.291510] machine nginx-pre-start[323]: nginx: configuration file /nix/store/l3cd84w4xgf1kji8qqry6kj3fknp5iv2-nginx.conf test is successful container-test-run-user-firewall-iptables> router # [7257744.363489] router systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-user-firewall-iptables> machine # [7257744.296394] machine systemd[1]: Started Nginx Web Server. container-test-run-user-firewall-iptables> router # [7257744.363532] router systemd[1]: Reached target Host and Network Name Lookups. container-test-run-user-firewall-iptables> machine # [7257744.296566] machine systemd[1]: Reached target Multi-User System. container-test-run-user-firewall-iptables> router # [7257744.363563] router systemd[1]: Reached target User and Group Name Lookups. container-test-run-user-firewall-iptables> machine # [7257744.337058] machine dbus-broker-launch[319]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-user-firewall-iptables> router # [7257744.364314] router systemd[1]: Starting User Login Management... container-test-run-user-firewall-iptables> machine # [7257744.337323] machine dbus-broker-launch[319]: NSS returned no entry for 'systemd-timesync' container-test-run-user-firewall-iptables> router # [7257744.364692] router systemd[1]: Starting Permit User Sessions... container-test-run-user-firewall-iptables> router # [7257744.369664] router systemd[1]: Finished Permit User Sessions. container-test-run-user-firewall-iptables> machine # [7257744.337323] machine dbus-broker-launch[319]: Invalid user-name in /nix/store/jshk752vhikhzxpx3frmapd83b6b4kwb-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-user-firewall-iptables> machine # [7257744.337578] machine systemd[1]: Started D-Bus System Message Bus. container-test-run-user-firewall-iptables> router # [7257744.370179] router systemd[1]: Started Console Getty. container-test-run-user-firewall-iptables> router # [7257744.370200] router systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-user-firewall-iptables> machine # [7257744.340965] machine dbus-broker-launch[319]: Ready container-test-run-user-firewall-iptables> machine # [7257744.341238] machine systemd[1]: Startup finished in 854ms. container-test-run-user-firewall-iptables> router # [7257744.370213] router systemd[1]: Reached target Login Prompts. container-test-run-user-firewall-iptables> router # [7257744.416393] router dbus-broker-launch[85]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-user-firewall-iptables> router # [7257744.417018] router dbus-broker-launch[85]: NSS returned no entry for 'systemd-timesync' container-test-run-user-firewall-iptables> router # [7257744.417018] router dbus-broker-launch[85]: Invalid user-name in /nix/store/x8rih55gvrw055am8ag442ndfckw4y6p-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-user-firewall-iptables> router # [7257744.417401] router systemd[1]: Started D-Bus System Message Bus. container-test-run-user-firewall-iptables> router # [7257744.421862] router dbus-broker-launch[85]: Ready container-test-run-user-firewall-iptables> router: (finished: waiting for unit multi-user.target, in 1.64 seconds) container-test-run-user-firewall-iptables> router: waiting for unit nginx.service container-test-run-user-firewall-iptables> router: (finished: waiting for unit nginx.service, in 0.01 seconds) container-test-run-user-firewall-iptables> machine: waiting for unit multi-user.target container-test-run-user-firewall-iptables> machine: (finished: waiting for unit multi-user.target, in 0.01 seconds) container-test-run-user-firewall-iptables> machine: waiting for unit nginx.service container-test-run-user-firewall-iptables> machine: (finished: waiting for unit nginx.service, in 0.01 seconds) container-test-run-user-firewall-iptables> router: must succeed: ip -4 addr show eth1 | grep -oP '(?<=inet\s)\d+(\.\d+){3}' container-test-run-user-firewall-iptables> router: (finished: must succeed: ip -4 addr show eth1 | grep -oP '(?<=inet\s)\d+(\.\d+){3}', in 0.00 seconds) container-test-run-user-firewall-iptables> router: must succeed: ip -6 addr show eth1 | grep -oP '(?<=inet6\s)[0-9a-f:]+' | grep -v '^fe80' | head -1 container-test-run-user-firewall-iptables> router: (finished: must succeed: ip -6 addr show eth1 | grep -oP '(?<=inet6\s)[0-9a-f:]+' | grep -v '^fe80' | head -1, in 0.01 seconds) container-test-run-user-firewall-iptables> Router IPv4: 192.168.1.2 container-test-run-user-firewall-iptables> Router IPv6: 2001:db8:1::2 container-test-run-user-firewall-iptables> machine: must succeed: systemctl restart firewall container-test-run-user-firewall-iptables> machine # [7257744.712134] machine systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-user-firewall-iptables> machine # [7257744.920136] machine systemd[1]: Stopping Firewall... container-test-run-user-firewall-iptables> router # [7257744.641017] router nginx-pre-start[114]: nginx: the configuration file /nix/store/k17m2x3wxsyn2jq4da2kfb895cfhbhlk-nginx.conf syntax is ok container-test-run-user-firewall-iptables> router # [7257744.641017] router nginx-pre-start[114]: nginx: configuration file /nix/store/k17m2x3wxsyn2jq4da2kfb895cfhbhlk-nginx.conf test is successful container-test-run-user-firewall-iptables> router # [7257744.645042] router systemd[1]: Started Nginx Web Server. container-test-run-user-firewall-iptables> router # [7257744.695794] router systemd-logind[103]: New seat seat0. container-test-run-user-firewall-iptables> router # [7257744.696047] router systemd[1]: Started User Login Management. container-test-run-user-firewall-iptables> router # [7257744.697405] router systemd[1]: Starting linger-users.service... container-test-run-user-firewall-iptables> router # [7257744.712284] router systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-user-firewall-iptables> router # [7257744.721054] router systemd[1]: linger-users.service: Deactivated successfully. container-test-run-user-firewall-iptables> router # [7257744.721259] router systemd[1]: Finished linger-users.service. container-test-run-user-firewall-iptables> router # [7257744.721526] router systemd[1]: Reached target Multi-User System. container-test-run-user-firewall-iptables> router # [7257744.721632] router systemd[1]: Startup finished in 1.239s. container-test-run-user-firewall-iptables> machine # [7257745.153201] machine systemd[1]: firewall.service: Deactivated successfully. container-test-run-user-firewall-iptables> machine # [7257745.153373] machine systemd[1]: Stopped Firewall. container-test-run-user-firewall-iptables> machine # [7257745.154401] machine systemd[1]: Starting Firewall... container-test-run-user-firewall-iptables> machine: (finished: must succeed: systemctl restart firewall, in 0.73 seconds) container-test-run-user-firewall-iptables> machine: waiting for unit firewall.service container-test-run-user-firewall-iptables> machine: (finished: waiting for unit firewall.service, in 0.01 seconds) container-test-run-user-firewall-iptables> machine: must succeed: iptables -L user-firewall-output >&2 container-test-run-user-firewall-iptables> Chain user-firewall-output (1 references) container-test-run-user-firewall-iptables> target prot opt source destination container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> REJECT all -- anywhere anywhere owner UID match bob reject-with icmp-port-unreachable container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> machine: (finished: must succeed: iptables -L user-firewall-output >&2, in 0.01 seconds) container-test-run-user-firewall-iptables> machine: waiting for success: runuser -u alice -- curl -s http://127.0.0.1:8080 container-test-run-user-firewall-iptables> machine: (finished: waiting for success: runuser -u alice -- curl -s http://127.0.0.1:8080, in 0.01 seconds) container-test-run-user-firewall-iptables> machine: must succeed: runuser -u alice -- curl -s http://192.168.1.2 container-test-run-user-firewall-iptables> router # [7257745.406218] router systemd-networkd[67]: eth1: Gained IPv6LL container-test-run-user-firewall-iptables> machine: (finished: must succeed: runuser -u alice -- curl -s http://192.168.1.2, in 0.01 seconds) container-test-run-user-firewall-iptables> machine: must succeed: runuser -u alice -- curl -s http://[2001:db8:1::2] container-test-run-user-firewall-iptables> machine # [7257745.645644] machine systemd[1]: Finished Firewall. container-test-run-user-firewall-iptables> machine # [7257745.663894] machine runuser[482]: pam_unix(runuser:session): session opened for user alice(uid=1001) by (uid=0) container-test-run-user-firewall-iptables> machine # [7257745.670155] machine runuser[482]: pam_unix(runuser:session): session closed for user alice container-test-run-user-firewall-iptables> machine # [7257745.675407] machine runuser[484]: pam_unix(runuser:session): session opened for user alice(uid=1001) by (uid=0) container-test-run-user-firewall-iptables> machine # [7257745.681049] machine runuser[484]: pam_unix(runuser:session): session closed for user alice container-test-run-user-firewall-iptables> machine # [7257745.686247] machine runuser[486]: pam_unix(runuser:session): session opened for user alice(uid=1001) by (uid=0) container-test-run-user-firewall-iptables> machine: (finished: must succeed: runuser -u alice -- curl -s http://[2001:db8:1::2], in 1.08 seconds) container-test-run-user-firewall-iptables> machine: must succeed: runuser -u bob -- curl -s http://127.0.0.1:8080 container-test-run-user-firewall-iptables> machine: (finished: must succeed: runuser -u bob -- curl -s http://127.0.0.1:8080, in 0.06 seconds) container-test-run-user-firewall-iptables> machine: must succeed: runuser -u bob -- curl -s --connect-timeout 2 http://192.168.1.2 2>&1 || echo 'EXIT_CODE='$? container-test-run-user-firewall-iptables> machine: (finished: must succeed: runuser -u bob -- curl -s --connect-timeout 2 http://192.168.1.2 2>&1 || echo 'EXIT_CODE='$?, in 0.04 seconds) container-test-run-user-firewall-iptables> machine: must succeed: runuser -u bob -- curl -s --connect-timeout 2 http://[2001:db8:1::2] 2>&1 || echo 'EXIT_CODE='$? container-test-run-user-firewall-iptables> machine # [7257746.756286] machine runuser[486]: pam_unix(runuser:session): session closed for user alice container-test-run-user-firewall-iptables> machine # [7257746.795127] machine runuser[488]: pam_unix(runuser:session): session opened for user bob(uid=1002) by (uid=0) container-test-run-user-firewall-iptables> machine # [7257746.808830] machine runuser[488]: pam_unix(runuser:session): session closed for user bob container-test-run-user-firewall-iptables> machine # [7257746.831063] machine runuser[491]: pam_unix(runuser:session): session opened for user bob(uid=1002) by (uid=0) container-test-run-user-firewall-iptables> machine # [7257746.848938] machine runuser[491]: pam_unix(runuser:session): session closed for user bob container-test-run-user-firewall-iptables> machine # [7257746.863264] machine runuser[494]: pam_unix(runuser:session): session opened for user bob(uid=1002) by (uid=0) container-test-run-user-firewall-iptables> machine: (finished: must succeed: runuser -u bob -- curl -s --connect-timeout 2 http://[2001:db8:1::2] 2>&1 || echo 'EXIT_CODE='$?, in 1.06 seconds) container-test-run-user-firewall-iptables> machine: must succeed: iptables -L user-firewall-output -n -v container-test-run-user-firewall-iptables> machine: (finished: must succeed: iptables -L user-firewall-output -n -v, in 0.02 seconds) container-test-run-user-firewall-iptables> machine: must succeed: ip6tables -L user-firewall-output -n -v container-test-run-user-firewall-iptables> machine: (finished: must succeed: ip6tables -L user-firewall-output -n -v, in 0.02 seconds) container-test-run-user-firewall-iptables> machine: waiting for unit setup-wg0-interface.service container-test-run-user-firewall-iptables> machine: (finished: waiting for unit setup-wg0-interface.service, in 0.03 seconds) container-test-run-user-firewall-iptables> machine: waiting for unit nginx.service container-test-run-user-firewall-iptables> machine: (finished: waiting for unit nginx.service, in 0.03 seconds) container-test-run-user-firewall-iptables> machine: waiting for TCP port 8081 on 10.100.0.2 container-test-run-user-firewall-iptables> Connection to 10.100.0.2 8081 port [tcp/sunproxyadmin] succeeded! container-test-run-user-firewall-iptables> machine: (finished: waiting for TCP port 8081 on 10.100.0.2, in 0.02 seconds) container-test-run-user-firewall-iptables> machine: must succeed: ip link show wg0 container-test-run-user-firewall-iptables> machine: (finished: must succeed: ip link show wg0, in 0.02 seconds) container-test-run-user-firewall-iptables> machine: must succeed: ip addr show wg0 container-test-run-user-firewall-iptables> machine: (finished: must succeed: ip addr show wg0, in 0.01 seconds) container-test-run-user-firewall-iptables> machine: must succeed: runuser -u alice -- curl -s --interface wg0 http://10.100.0.2:8081/ container-test-run-user-firewall-iptables> machine: (finished: must succeed: runuser -u alice -- curl -s --interface wg0 http://10.100.0.2:8081/, in 0.04 seconds) container-test-run-user-firewall-iptables> machine: must succeed: runuser -u alice -- curl -s --interface wg0 http://[fd00::2]:8081/ container-test-run-user-firewall-iptables> machine: (finished: must succeed: runuser -u alice -- curl -s --interface wg0 http://[fd00::2]:8081/, in 0.03 seconds) container-test-run-user-firewall-iptables> machine: must succeed: runuser -u bob -- curl -s --interface wg0 http://10.100.0.2:8081/ container-test-run-user-firewall-iptables> machine # [7257747.906221] machine runuser[494]: pam_unix(runuser:session): session closed for user bob container-test-run-user-firewall-iptables> machine # [7257748.080195] machine runuser[503]: pam_unix(runuser:session): session opened for user alice(uid=1001) by (uid=0) container-test-run-user-firewall-iptables> machine # [7257748.097338] machine runuser[503]: pam_unix(runuser:session): session closed for user alice container-test-run-user-firewall-iptables> machine # [7257748.110058] machine runuser[505]: pam_unix(runuser:session): session opened for user alice(uid=1001) by (uid=0) container-test-run-user-firewall-iptables> machine # [7257748.124174] machine runuser[505]: pam_unix(runuser:session): session closed for user alice container-test-run-user-firewall-iptables> machine # [7257748.145296] machine runuser[507]: pam_unix(runuser:session): session opened for user bob(uid=1002) by (uid=0) container-test-run-user-firewall-iptables> machine # [7257748.160820] machine runuser[507]: pam_unix(runuser:session): session closed for user bob container-test-run-user-firewall-iptables> machine: (finished: must succeed: runuser -u bob -- curl -s --interface wg0 http://10.100.0.2:8081/, in 0.04 seconds) container-test-run-user-firewall-iptables> machine: must succeed: runuser -u bob -- curl -s --interface wg0 http://[fd00::2]:8081/ container-test-run-user-firewall-iptables> machine: (finished: must succeed: runuser -u bob -- curl -s --interface wg0 http://[fd00::2]:8081/, in 0.03 seconds) container-test-run-user-firewall-iptables> machine: must succeed: iptables -L user-firewall-output -n -v | grep -E 'wg0|wg\+' >&2 container-test-run-user-firewall-iptables> 0 0 RETURN all -- * wg+ 0.0.0.0/0 0.0.0.0/0 container-test-run-user-firewall-iptables> machine: (finished: must succeed: iptables -L user-firewall-output -n -v | grep -E 'wg0|wg\+' >&2, in 0.02 seconds) container-test-run-user-firewall-iptables> (finished: run the VM test script, in 4.97 seconds) container-test-run-user-firewall-iptables> test script finished in 5.04s container-test-run-user-firewall-iptables> cleanup container-test-run-user-firewall-iptables> kill NspawnMachine (pid 52) container-test-run-user-firewall-iptables> Container machine terminated by signal KILL. container-test-run-user-firewall-iptables> kill NspawnMachine (pid 53) container-test-run-user-firewall-iptables> Container router terminated by signal KILL. container-test-run-user-firewall-iptables> (finished: cleanup, in 0.29 seconds) post-build step Upload to niks3: ok time=2026-08-23T10:03:26.468Z level=INFO msg="Uploading 0 paths to niks3.clan.lol (1 already cached)" time=2026-08-23T10:03:27.689Z level=INFO msg="Uploading 1 narinfos" time=2026-08-23T10:03:28.679Z level=INFO msg="Upload complete. (2.267s)"