these 19 derivations will be built: /nix/store/2qjv8nqhdv7ykwqjhaa0y6ky1ag2rwfl-system-path.drv /nix/store/i8wz8h821qv77s47rx9wnbjncxdanwn3-dbus-1.drv /nix/store/0gk43cwd4lwslrlvpkjz1waliip6dg5p-X-Restart-Triggers-dbus-broker.drv /nix/store/0hsyifvil86vrw5d5xlgavqjyglpvadi-firewall-stop.drv /nix/store/v822c8i5zhq7qv1ga8ajjkybg6z0xvgp-unit-dbus-broker.service.drv /nix/store/1y9hi4kf8xls62zbn2ifx54w3lp8445v-user-units.drv /nix/store/351j6kk4j85ylj6avwg1y9zaa9a350i3-unit-dbus-broker.service.drv /nix/store/416phh4ardhmd20nhg0jmjp0cpy2bw18-test-script.drv /nix/store/lkg9y3hrqp0z6dp1qkj4a4dcrb8swaf8-firewall-start.drv /nix/store/vamss6avf51ya7dx4q4vkvlbs7lcbrxb-firewall-reload.drv /nix/store/p2km9lp0fmjaqvg03c1zip11c78q2a79-unit-firewall.service.drv /nix/store/xyd0mafyhhy2qw9rza89qjzq40395nzr-system-units.drv /nix/store/gr17ma8yrgi7w34dvwfn3mnrgm2vcx37-etc.drv /nix/store/rlmazy9l7jw9cac1h4qvqxcwdq0y41lq-activate.drv /nix/store/rcn9wsqkm1yzl1pnlqin5yab11sd32y6-nixos-system-machine-test.drv /nix/store/rbf8azljcq0h830ki35pg0lb3v65fdgq-run-machine-nspawn.drv /nix/store/ic8yvsqrqrmwaa5vxr0lglv242n86j1w-driverConfiguration.json.drv /nix/store/7ws2q7bwb791z2bhjnk4sbg580z6b0pb-nixos-test-driver-user-firewall-iptables.drv /nix/store/rh6lyl3rr2w8db8ijri2qgm6ss52g0l1-container-test-run-user-firewall-iptables.drv building '/nix/store/416phh4ardhmd20nhg0jmjp0cpy2bw18-test-script.drv' building '/nix/store/2qjv8nqhdv7ykwqjhaa0y6ky1ag2rwfl-system-path.drv' building '/nix/store/lkg9y3hrqp0z6dp1qkj4a4dcrb8swaf8-firewall-start.drv' building '/nix/store/0hsyifvil86vrw5d5xlgavqjyglpvadi-firewall-stop.drv' system-path> structuredAttrs is enabled building '/nix/store/vamss6avf51ya7dx4q4vkvlbs7lcbrxb-firewall-reload.drv' system-path> created 1660 symlinks in user environment building '/nix/store/p2km9lp0fmjaqvg03c1zip11c78q2a79-unit-firewall.service.drv' unit-firewall.service> structuredAttrs is enabled building '/nix/store/i8wz8h821qv77s47rx9wnbjncxdanwn3-dbus-1.drv' building '/nix/store/0gk43cwd4lwslrlvpkjz1waliip6dg5p-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/351j6kk4j85ylj6avwg1y9zaa9a350i3-unit-dbus-broker.service.drv' building '/nix/store/v822c8i5zhq7qv1ga8ajjkybg6z0xvgp-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/xyd0mafyhhy2qw9rza89qjzq40395nzr-system-units.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/1y9hi4kf8xls62zbn2ifx54w3lp8445v-user-units.drv' building '/nix/store/gr17ma8yrgi7w34dvwfn3mnrgm2vcx37-etc.drv' building '/nix/store/rlmazy9l7jw9cac1h4qvqxcwdq0y41lq-activate.drv' building '/nix/store/rcn9wsqkm1yzl1pnlqin5yab11sd32y6-nixos-system-machine-test.drv' nixos-system-machine-test> structuredAttrs is enabled building '/nix/store/rbf8azljcq0h830ki35pg0lb3v65fdgq-run-machine-nspawn.drv' building '/nix/store/ic8yvsqrqrmwaa5vxr0lglv242n86j1w-driverConfiguration.json.drv' driverConfiguration.json> structuredAttrs is enabled building '/nix/store/7ws2q7bwb791z2bhjnk4sbg580z6b0pb-nixos-test-driver-user-firewall-iptables.drv' nixos-test-driver-user-firewall-iptables> Running type check (enable/disable: config.skipTypeCheck) nixos-test-driver-user-firewall-iptables> See https://nixos.org/manual/nixos/stable/#test-opt-skipTypeCheck nixos-test-driver-user-firewall-iptables> All checks passed! nixos-test-driver-user-firewall-iptables> Linting test script (enable/disable: config.skipLint) nixos-test-driver-user-firewall-iptables> See https://nixos.org/manual/nixos/stable/#test-opt-skipLint nixos-test-driver-user-firewall-iptables> All checks passed! building '/nix/store/rh6lyl3rr2w8db8ijri2qgm6ss52g0l1-container-test-run-user-firewall-iptables.drv' on 'ssh-ng://builder@build-x86-01.clan.lol' building '/nix/store/rh6lyl3rr2w8db8ijri2qgm6ss52g0l1-container-test-run-user-firewall-iptables.drv' container-test-run-user-firewall-iptables> Machine state will be reset. To keep it, pass --keep-machine-state container-test-run-user-firewall-iptables> start all VLans container-test-run-user-firewall-iptables> (finished: start all VLans, in 0.00 seconds) container-test-run-user-firewall-iptables> container-test-run-user-firewall-iptables> Test will time out and terminate in 3600.0 seconds container-test-run-user-firewall-iptables> run the VM test script container-test-run-user-firewall-iptables> additionally exposed symbols: container-test-run-user-firewall-iptables> machine, router, container-test-run-user-firewall-iptables> vlan1, container-test-run-user-firewall-iptables> start_all, test_script, machines, machines_qemu, machines_nspawn, vlans, driver, log, os, create_machine, subtest, run_tests, join_all, retry, serial_stdout_off, serial_stdout_on, polling_condition, BaseMachine, QemuMachine, NspawnMachine, t, debug, dump_machine_ssh container-test-run-user-firewall-iptables> start all VMs container-test-run-user-firewall-iptables> machine: systemd-nspawn running (pid 52) container-test-run-user-firewall-iptables> router: systemd-nspawn running (pid 53) container-test-run-user-firewall-iptables> machine: Waiting for journal at /build/vm-state-machine/var/log/journal... container-test-run-user-firewall-iptables> router: Waiting for journal at /build/vm-state-router/var/log/journal... container-test-run-user-firewall-iptables> (finished: start all VMs, in 0.00 seconds) container-test-run-user-firewall-iptables> router: waiting for unit multi-user.target container-test-run-user-firewall-iptables> nixos-nspawn(machine): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-user-firewall-iptables> nixos-nspawn(machine): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-user-firewall-iptables> nixos-nspawn(router): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-user-firewall-iptables> nixos-nspawn(router): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-user-firewall-iptables> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-user-firewall-iptables> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-user-firewall-iptables> ░ Spawning container machine on /build/vm-state-machine. container-test-run-user-firewall-iptables> ░ Spawning container router on /build/vm-state-router. container-test-run-user-firewall-iptables> machine # [7466868.398946] machine systemd-journald[54]: Journal started container-test-run-user-firewall-iptables> machine # [7466868.398995] machine systemd-journald[54]: Runtime Journal (/run/log/journal/42575e1543ab4fc6872fa5d4d49936b3) is 8M, max 3.7G, 3.7G free. container-test-run-user-firewall-iptables> machine # [7466868.427449] machine systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-user-firewall-iptables> machine # [7466868.428271] machine systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-user-firewall-iptables> machine # [7466868.435958] machine systemd-journald[54]: Time spent on flushing to /var/log/journal/42575e1543ab4fc6872fa5d4d49936b3 is 1.902ms for 4 entries. container-test-run-user-firewall-iptables> machine # [7466868.435958] machine systemd-journald[54]: System Journal (/var/log/journal/42575e1543ab4fc6872fa5d4d49936b3) is 8M, max 4G, 3.9G free. container-test-run-user-firewall-iptables> machine # [7466868.441831] machine systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-user-firewall-iptables> machine # [7466868.442931] machine systemd[1]: Reached target Preparation for Local File Systems. container-test-run-user-firewall-iptables> machine # [7466868.443094] machine systemd[1]: Reached target Local File Systems. container-test-run-user-firewall-iptables> machine # [7466868.443741] machine systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-user-firewall-iptables> machine # [7466868.443778] machine systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-user-firewall-iptables> machine # [7466868.444571] machine systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-user-firewall-iptables> machine # [7466868.444606] machine systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-user-firewall-iptables> machine # [7466868.519795] machine systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-user-firewall-iptables> machine # [7466868.531845] machine systemd[1]: Starting Create System Files and Directories... container-test-run-user-firewall-iptables> machine # [7466868.544619] machine systemd-tmpfiles[161]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-user-firewall-iptables> machine # [7466868.544786] machine systemd-tmpfiles[161]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-user-firewall-iptables> machine # [7466868.544891] machine systemd-tmpfiles[161]: fchmod() of /var/log/journal/42575e1543ab4fc6872fa5d4d49936b3 failed: Operation not permitted container-test-run-user-firewall-iptables> machine # [7466868.545510] machine systemd-tmpfiles[161]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-user-firewall-iptables> machine # [7466868.546712] machine systemd[1]: Finished Create System Files and Directories. container-test-run-user-firewall-iptables> machine # [7466868.547796] machine systemd[1]: Starting Rebuild Journal Catalog... container-test-run-user-firewall-iptables> machine # [7466868.548349] machine systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-user-firewall-iptables> machine # [7466868.572511] machine systemd[1]: Finished Rebuild Journal Catalog. container-test-run-user-firewall-iptables> machine # [7466868.572708] machine systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-user-firewall-iptables> machine # [7466868.574512] machine systemd[1]: Starting Update is Completed... container-test-run-user-firewall-iptables> machine # [7466868.579073] machine systemd[1]: Finished Firewall. container-test-run-user-firewall-iptables> machine # [7466868.580450] machine systemd[1]: Reached target Preparation for Network. container-test-run-user-firewall-iptables> machine # [7466868.585073] machine systemd[1]: Finished Update is Completed. container-test-run-user-firewall-iptables> machine # [7466868.585230] machine systemd[1]: Reached target System Initialization. container-test-run-user-firewall-iptables> machine # [7466868.585299] machine systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-user-firewall-iptables> machine # [7466868.585337] machine systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-user-firewall-iptables> machine # [7466868.585354] machine systemd[1]: Reached target Timer Units. container-test-run-user-firewall-iptables> machine # [7466868.585473] machine systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-user-firewall-iptables> machine # [7466868.585555] machine systemd[1]: Listening on Nix Daemon Socket. container-test-run-user-firewall-iptables> machine # [7466868.585645] machine systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-user-firewall-iptables> machine # [7466868.585663] machine systemd[1]: Reached target Socket Units. container-test-run-user-firewall-iptables> machine # [7466868.585695] machine systemd[1]: Reached target Basic System. container-test-run-user-firewall-iptables> machine # [7466868.586797] machine systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-user-firewall-iptables> machine # [7466868.587628] machine systemd[1]: Starting Address configuration of eth1... container-test-run-user-firewall-iptables> machine # [7466868.588541] machine systemd[1]: Starting Extra networking commands.... container-test-run-user-firewall-iptables> machine # [7466868.589524] machine systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-user-firewall-iptables> machine # [7466868.590382] machine systemd[1]: Starting Setup wg0 dummy interface... container-test-run-user-firewall-iptables> machine # [7466868.606517] machine network-addresses-eth1-start[206]: adding address 192.168.1.1/24... done container-test-run-user-firewall-iptables> machine # [7466868.606750] machine systemd[1]: Finished Setup wg0 dummy interface. container-test-run-user-firewall-iptables> machine # [7466868.608478] machine network-addresses-eth1-start[206]: adding address 2001:db8:1::1/64... done container-test-run-user-firewall-iptables> machine # [7466868.612519] machine systemd[1]: Finished Address configuration of eth1. container-test-run-user-firewall-iptables> machine # [7466868.612742] machine systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-user-firewall-iptables> machine # [7466868.643457] machine systemd[1]: nscd.service: Deactivated successfully. container-test-run-user-firewall-iptables> machine # [7466868.643668] machine systemd[1]: Stopped Name Service Cache Daemon (nsncd). container-test-run-user-firewall-iptables> machine # [7466868.645705] machine systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-user-firewall-iptables> machine # [7466868.662595] machine systemd[1]: Finished Extra networking commands.. container-test-run-user-firewall-iptables> machine # [7466868.662814] machine systemd[1]: Reached target Network. container-test-run-user-firewall-iptables> machine # [7466868.663801] machine systemd[1]: Starting Nginx Web Server... container-test-run-user-firewall-iptables> machine # [7466868.722143] machine nsncd[278]: Aug 25 20:08:46.087 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-user-firewall-iptables> machine # [7466868.722283] machine systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-user-firewall-iptables> machine # [7466868.722365] machine systemd[1]: Reached target Host and Network Name Lookups. container-test-run-user-firewall-iptables> machine # [7466868.722421] machine systemd[1]: Reached target User and Group Name Lookups. container-test-run-user-firewall-iptables> machine # [7466868.723740] machine systemd[1]: Starting User Login Management... container-test-run-user-firewall-iptables> machine # [7466868.724682] machine systemd[1]: Starting Permit User Sessions... container-test-run-user-firewall-iptables> machine # [7466868.755295] machine systemd[1]: Finished Permit User Sessions. container-test-run-user-firewall-iptables> machine # [7466868.756688] machine systemd[1]: Started Console Getty. container-test-run-user-firewall-iptables> machine # [7466868.756724] machine systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-user-firewall-iptables> machine # [7466868.756741] machine systemd[1]: Reached target Login Prompts. container-test-run-user-firewall-iptables> router # [7466868.397673] router systemd-journald[54]: Journal started container-test-run-user-firewall-iptables> router # [7466868.397739] router systemd-journald[54]: Runtime Journal (/run/log/journal/fcbf4b77b8f643ddb6dd875849c233a6) is 8M, max 3.7G, 3.7G free. container-test-run-user-firewall-iptables> router # [7466868.401693] router systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-user-firewall-iptables> router # [7466868.402226] router systemd[1]: Starting Network Name Resolution... container-test-run-user-firewall-iptables> router # [7466868.402584] router systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-user-firewall-iptables> router # [7466868.434693] router systemd-journald[54]: Time spent on flushing to /var/log/journal/fcbf4b77b8f643ddb6dd875849c233a6 is 1.401ms for 5 entries. container-test-run-user-firewall-iptables> router # [7466868.434693] router systemd-journald[54]: System Journal (/var/log/journal/fcbf4b77b8f643ddb6dd875849c233a6) is 8M, max 4G, 3.9G free. container-test-run-user-firewall-iptables> router # [7466868.438773] router systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-user-firewall-iptables> router # [7466868.439837] router systemd[1]: Reached target Preparation for Local File Systems. container-test-run-user-firewall-iptables> router # [7466868.439979] router systemd[1]: Reached target Local File Systems. container-test-run-user-firewall-iptables> router # [7466868.440941] router systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-user-firewall-iptables> router # [7466868.441013] router systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-user-firewall-iptables> router # [7466868.441993] router systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-user-firewall-iptables> router # [7466868.442033] router systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-user-firewall-iptables> router # [7466868.443217] router systemd[1]: Starting Network Management... container-test-run-user-firewall-iptables> router # [7466868.513496] router systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-user-firewall-iptables> router # [7466868.514927] router systemd[1]: Starting Create System Files and Directories... container-test-run-user-firewall-iptables> router # [7466868.544774] router systemd-tmpfiles[70]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-user-firewall-iptables> router # [7466868.545009] router systemd-tmpfiles[70]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-user-firewall-iptables> router # [7466868.545147] router systemd-tmpfiles[70]: fchmod() of /var/log/journal/fcbf4b77b8f643ddb6dd875849c233a6 failed: Operation not permitted container-test-run-user-firewall-iptables> router # [7466868.545369] router systemd-tmpfiles[70]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-user-firewall-iptables> router # [7466868.546610] router systemd[1]: Finished Create System Files and Directories. container-test-run-user-firewall-iptables> router # [7466868.548571] router systemd[1]: Starting Rebuild Journal Catalog... container-test-run-user-firewall-iptables> router # [7466868.549234] router systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-user-firewall-iptables> router # [7466868.572711] router systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-user-firewall-iptables> router # [7466868.572903] router systemd[1]: Finished Rebuild Journal Catalog. container-test-run-user-firewall-iptables> router # [7466868.574629] router systemd[1]: Starting Update is Completed... container-test-run-user-firewall-iptables> router # [7466868.585383] router systemd[1]: Finished Update is Completed. container-test-run-user-firewall-iptables> router # [7466868.941011] router systemd-networkd[66]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-user-firewall-iptables> router # [7466868.941099] router systemd-networkd[66]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-user-firewall-iptables> router # [7466868.946625] router systemd-networkd[66]: lo: Link UP container-test-run-user-firewall-iptables> router # [7466868.946631] router systemd-networkd[66]: lo: Gained carrier container-test-run-user-firewall-iptables> router # [7466868.946793] router systemd-networkd[66]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-user-firewall-iptables> router # [7466868.947139] router systemd[1]: Started Network Management. container-test-run-user-firewall-iptables> router # [7466868.947168] router systemd-networkd[66]: eth1: Link UP container-test-run-user-firewall-iptables> router # [7466868.947345] router systemd-networkd[66]: eth1: Gained carrier container-test-run-user-firewall-iptables> router # [7466868.948179] router systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-user-firewall-iptables> router # [7466868.971073] router systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-user-firewall-iptables> router # [7466869.174833] router systemd-resolved[61]: Positive Trust Anchors: container-test-run-user-firewall-iptables> router # [7466869.174840] router systemd-resolved[61]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-user-firewall-iptables> router # [7466869.174843] router systemd-resolved[61]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-user-firewall-iptables> router # [7466869.174861] router systemd-resolved[61]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-user-firewall-iptables> router # [7466869.187202] router systemd-resolved[61]: Using system hostname 'router'. container-test-run-user-firewall-iptables> router # [7466869.188205] router systemd[1]: Started Network Name Resolution. container-test-run-user-firewall-iptables> router # [7466869.188274] router systemd[1]: Reached target Network. container-test-run-user-firewall-iptables> router # [7466869.188324] router systemd[1]: Reached target System Initialization. container-test-run-user-firewall-iptables> router # [7466869.188367] router systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-user-firewall-iptables> router # [7466869.188387] router systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-user-firewall-iptables> router # [7466869.188402] router systemd[1]: Reached target Timer Units. container-test-run-user-firewall-iptables> router # [7466869.188504] router systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-user-firewall-iptables> router # [7466869.188594] router systemd[1]: Listening on Nix Daemon Socket. container-test-run-user-firewall-iptables> router # [7466869.188688] router systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-user-firewall-iptables> router # [7466869.188703] router systemd[1]: Reached target Socket Units. container-test-run-user-firewall-iptables> router # [7466869.188731] router systemd[1]: Reached target Basic System. container-test-run-user-firewall-iptables> router # [7466869.189539] router systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-user-firewall-iptables> router # [7466869.189942] router systemd[1]: Starting Nginx Web Server... container-test-run-user-firewall-iptables> router # [7466869.190401] router systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-user-firewall-iptables> router # [7466869.191205] router systemd[1]: Starting D-Bus System Message Bus... container-test-run-user-firewall-iptables> machine # [7466869.134777] machine systemd-logind[298]: New seat seat0. container-test-run-user-firewall-iptables> machine # [7466869.135642] machine systemd[1]: Starting D-Bus System Message Bus... container-test-run-user-firewall-iptables> machine # [7466869.135713] machine systemd[1]: Started User Login Management. container-test-run-user-firewall-iptables> machine # [7466869.136261] machine systemd[1]: Starting linger-users.service... container-test-run-user-firewall-iptables> machine # [7466869.144915] machine systemd[1]: linger-users.service: Deactivated successfully. container-test-run-user-firewall-iptables> machine # [7466869.145067] machine systemd[1]: Finished linger-users.service. container-test-run-user-firewall-iptables> machine # [7466869.148278] machine nginx-pre-start[310]: nginx: the configuration file /nix/store/l3cd84w4xgf1kji8qqry6kj3fknp5iv2-nginx.conf syntax is ok container-test-run-user-firewall-iptables> machine # [7466869.148609] machine nginx-pre-start[310]: nginx: configuration file /nix/store/l3cd84w4xgf1kji8qqry6kj3fknp5iv2-nginx.conf test is successful container-test-run-user-firewall-iptables> machine # [7466869.156226] machine systemd[1]: Started Nginx Web Server. container-test-run-user-firewall-iptables> machine # [7466869.156356] machine systemd[1]: Reached target Multi-User System. container-test-run-user-firewall-iptables> machine # [7466869.280306] machine dbus-broker-launch[308]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-user-firewall-iptables> machine # [7466869.287974] machine dbus-broker-launch[308]: NSS returned no entry for 'systemd-timesync' container-test-run-user-firewall-iptables> machine # [7466869.287974] machine dbus-broker-launch[308]: Invalid user-name in /nix/store/b3xc8y4pr5xk7hwjf6xbkl4kz95x9cjq-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-user-firewall-iptables> machine # [7466869.281096] machine systemd[1]: Started D-Bus System Message Bus. container-test-run-user-firewall-iptables> machine # [7466869.285774] machine dbus-broker-launch[308]: Ready container-test-run-user-firewall-iptables> router # [7466869.213137] router systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-user-firewall-iptables> router # [7466869.273428] router nsncd[83]: Aug 25 20:08:46.639 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-user-firewall-iptables> router # [7466869.273509] router systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-user-firewall-iptables> router # [7466869.273563] router systemd[1]: Reached target Host and Network Name Lookups. container-test-run-user-firewall-iptables> router # [7466869.273595] router systemd[1]: Reached target User and Group Name Lookups. container-test-run-user-firewall-iptables> router # [7466869.277242] router systemd[1]: Starting User Login Management... container-test-run-user-firewall-iptables> router # [7466869.278048] router systemd[1]: Starting Permit User Sessions... container-test-run-user-firewall-iptables> router # [7466869.286068] router systemd[1]: Finished Permit User Sessions. container-test-run-user-firewall-iptables> router # [7466869.286872] router systemd[1]: Started Console Getty. container-test-run-user-firewall-iptables> router # [7466869.286900] router systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-user-firewall-iptables> router # [7466869.286915] router systemd[1]: Reached target Login Prompts. container-test-run-user-firewall-iptables> router # [7466869.360797] router dbus-broker-launch[84]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-user-firewall-iptables> router # [7466869.361444] router dbus-broker-launch[84]: NSS returned no entry for 'systemd-timesync' container-test-run-user-firewall-iptables> router # [7466869.361444] router dbus-broker-launch[84]: Invalid user-name in /nix/store/s43s9pc0c6rxp0mgpnk467qpc5v3xh50-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-user-firewall-iptables> router # [7466869.361786] router systemd[1]: Started D-Bus System Message Bus. container-test-run-user-firewall-iptables> router # [7466869.368413] router dbus-broker-launch[84]: Ready container-test-run-user-firewall-iptables> router # [7466869.680209] router nginx-pre-start[113]: nginx: the configuration file /nix/store/k17m2x3wxsyn2jq4da2kfb895cfhbhlk-nginx.conf syntax is ok container-test-run-user-firewall-iptables> router # [7466869.680537] router nginx-pre-start[113]: nginx: configuration file /nix/store/k17m2x3wxsyn2jq4da2kfb895cfhbhlk-nginx.conf test is successful container-test-run-user-firewall-iptables> router # [7466869.683027] router systemd[1]: Started Nginx Web Server. container-test-run-user-firewall-iptables> router # [7466869.684169] router systemd-logind[102]: New seat seat0. container-test-run-user-firewall-iptables> router # [7466869.684259] router systemd[1]: Started User Login Management. container-test-run-user-firewall-iptables> router # [7466869.685077] router systemd[1]: Starting linger-users.service... container-test-run-user-firewall-iptables> router # [7466869.709473] router systemd[1]: linger-users.service: Deactivated successfully. container-test-run-user-firewall-iptables> router # [7466869.709626] router systemd[1]: Finished linger-users.service. container-test-run-user-firewall-iptables> router # [7466869.709898] router systemd[1]: Reached target Multi-User System. container-test-run-user-firewall-iptables> router # [7466870.525125] router systemd-networkd[66]: eth1: Gained IPv6LL container-test-run-user-firewall-iptables> machine # [7466874.960066] machine systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-user-firewall-iptables> machine # [7466874.973289] machine systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-user-firewall-iptables> machine # [7466874.978086] machine systemd[1]: Startup finished in 6.902s. container-test-run-user-firewall-iptables> router # [7466874.959010] router systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-user-firewall-iptables> router # [7466874.973288] router systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-user-firewall-iptables> router # [7466874.978081] router systemd[1]: Startup finished in 6.898s. container-test-run-user-firewall-iptables> router: (finished: waiting for unit multi-user.target, in 7.65 seconds) container-test-run-user-firewall-iptables> router: waiting for unit nginx.service container-test-run-user-firewall-iptables> router: (finished: waiting for unit nginx.service, in 0.01 seconds) container-test-run-user-firewall-iptables> machine: waiting for unit multi-user.target container-test-run-user-firewall-iptables> machine: (finished: waiting for unit multi-user.target, in 0.01 seconds) container-test-run-user-firewall-iptables> machine: waiting for unit nginx.service container-test-run-user-firewall-iptables> machine: (finished: waiting for unit nginx.service, in 0.01 seconds) container-test-run-user-firewall-iptables> router: must succeed: ip -4 addr show eth1 | grep -oP '(?<=inet\s)\d+(\.\d+){3}' container-test-run-user-firewall-iptables> router: (finished: must succeed: ip -4 addr show eth1 | grep -oP '(?<=inet\s)\d+(\.\d+){3}', in 0.01 seconds) container-test-run-user-firewall-iptables> router: must succeed: ip -6 addr show eth1 | grep -oP '(?<=inet6\s)[0-9a-f:]+' | grep -v '^fe80' | head -1 container-test-run-user-firewall-iptables> router: (finished: must succeed: ip -6 addr show eth1 | grep -oP '(?<=inet6\s)[0-9a-f:]+' | grep -v '^fe80' | head -1, in 0.01 seconds) container-test-run-user-firewall-iptables> Router IPv4: 192.168.1.2 container-test-run-user-firewall-iptables> Router IPv6: 2001:db8:1::2 container-test-run-user-firewall-iptables> machine: must succeed: systemctl restart firewall container-test-run-user-firewall-iptables> machine # [7466875.486026] machine systemd[1]: Stopping Firewall... container-test-run-user-firewall-iptables> machine # [7466875.691311] machine systemd[1]: firewall.service: Deactivated successfully. container-test-run-user-firewall-iptables> machine # [7466875.691452] machine systemd[1]: Stopped Firewall. container-test-run-user-firewall-iptables> machine # [7466875.692616] machine systemd[1]: Starting Firewall... container-test-run-user-firewall-iptables> machine: (finished: must succeed: systemctl restart firewall, in 0.73 seconds) container-test-run-user-firewall-iptables> machine: waiting for unit firewall.service container-test-run-user-firewall-iptables> machine: (finished: waiting for unit firewall.service, in 0.01 seconds) container-test-run-user-firewall-iptables> machine: must succeed: iptables -L user-firewall-output >&2 container-test-run-user-firewall-iptables> Chain user-firewall-output (1 references) container-test-run-user-firewall-iptables> target prot opt source destination container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> REJECT all -- anywhere anywhere owner UID match bob reject-with icmp-port-unreachable container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> machine: (finished: must succeed: iptables -L user-firewall-output >&2, in 0.00 seconds) container-test-run-user-firewall-iptables> machine: waiting for success: runuser -u alice -- curl -s http://127.0.0.1:8080 container-test-run-user-firewall-iptables> machine: (finished: waiting for success: runuser -u alice -- curl -s http://127.0.0.1:8080, in 0.01 seconds) container-test-run-user-firewall-iptables> machine: must succeed: runuser -u alice -- curl -s http://192.168.1.2 container-test-run-user-firewall-iptables> machine: (finished: must succeed: runuser -u alice -- curl -s http://192.168.1.2, in 0.01 seconds) container-test-run-user-firewall-iptables> machine: must succeed: runuser -u alice -- curl -s http://[2001:db8:1::2] container-test-run-user-firewall-iptables> machine: (finished: must succeed: runuser -u alice -- curl -s http://[2001:db8:1::2], in 0.01 seconds) container-test-run-user-firewall-iptables> machine: must succeed: runuser -u bob -- curl -s http://127.0.0.1:8080 container-test-run-user-firewall-iptables> machine: (finished: must succeed: runuser -u bob -- curl -s http://127.0.0.1:8080, in 0.01 seconds) container-test-run-user-firewall-iptables> machine: must succeed: runuser -u bob -- curl -s --connect-timeout 2 http://192.168.1.2 2>&1 || echo 'EXIT_CODE='$? container-test-run-user-firewall-iptables> machine: (finished: must succeed: runuser -u bob -- curl -s --connect-timeout 2 http://192.168.1.2 2>&1 || echo 'EXIT_CODE='$?, in 0.01 seconds) container-test-run-user-firewall-iptables> machine: must succeed: runuser -u bob -- curl -s --connect-timeout 2 http://[2001:db8:1::2] 2>&1 || echo 'EXIT_CODE='$? container-test-run-user-firewall-iptables> machine # [7466876.203811] machine systemd[1]: Finished Firewall. container-test-run-user-firewall-iptables> machine # [7466876.223266] machine runuser[472]: pam_unix(runuser:session): session opened for user alice(uid=1001) by (uid=0) container-test-run-user-firewall-iptables> machine # [7466876.228482] machine runuser[472]: pam_unix(runuser:session): session closed for user alice container-test-run-user-firewall-iptables> machine # [7466876.233709] machine runuser[474]: pam_unix(runuser:session): session opened for user alice(uid=1001) by (uid=0) container-test-run-user-firewall-iptables> machine # [7466876.238428] machine runuser[474]: pam_unix(runuser:session): session closed for user alice container-test-run-user-firewall-iptables> machine # [7466876.242823] machine runuser[476]: pam_unix(runuser:session): session opened for user alice(uid=1001) by (uid=0) container-test-run-user-firewall-iptables> machine # [7466876.246997] machine runuser[476]: pam_unix(runuser:session): session closed for user alice container-test-run-user-firewall-iptables> machine # [7466876.251187] machine runuser[478]: pam_unix(runuser:session): session opened for user bob(uid=1002) by (uid=0) container-test-run-user-firewall-iptables> machine # [7466876.255535] machine runuser[478]: pam_unix(runuser:session): session closed for user bob container-test-run-user-firewall-iptables> machine # [7466876.259726] machine runuser[481]: pam_unix(runuser:session): session opened for user bob(uid=1002) by (uid=0) container-test-run-user-firewall-iptables> machine # [7466876.264356] machine runuser[481]: pam_unix(runuser:session): session closed for user bob container-test-run-user-firewall-iptables> machine # [7466876.269703] machine runuser[484]: pam_unix(runuser:session): session opened for user bob(uid=1002) by (uid=0) container-test-run-user-firewall-iptables> machine: (finished: must succeed: runuser -u bob -- curl -s --connect-timeout 2 http://[2001:db8:1::2] 2>&1 || echo 'EXIT_CODE='$?, in 1.05 seconds) container-test-run-user-firewall-iptables> machine: must succeed: iptables -L user-firewall-output -n -v container-test-run-user-firewall-iptables> machine: (finished: must succeed: iptables -L user-firewall-output -n -v, in 0.00 seconds) container-test-run-user-firewall-iptables> machine: must succeed: ip6tables -L user-firewall-output -n -v container-test-run-user-firewall-iptables> machine: (finished: must succeed: ip6tables -L user-firewall-output -n -v, in 0.00 seconds) container-test-run-user-firewall-iptables> machine: waiting for unit setup-wg0-interface.service container-test-run-user-firewall-iptables> machine: (finished: waiting for unit setup-wg0-interface.service, in 0.01 seconds) container-test-run-user-firewall-iptables> machine: waiting for unit nginx.service container-test-run-user-firewall-iptables> machine: (finished: waiting for unit nginx.service, in 0.01 seconds) container-test-run-user-firewall-iptables> machine: waiting for TCP port 8081 on 10.100.0.2 container-test-run-user-firewall-iptables> Connection to 10.100.0.2 8081 port [tcp/sunproxyadmin] succeeded! container-test-run-user-firewall-iptables> machine: (finished: waiting for TCP port 8081 on 10.100.0.2, in 0.00 seconds) container-test-run-user-firewall-iptables> machine: must succeed: ip link show wg0 container-test-run-user-firewall-iptables> machine: (finished: must succeed: ip link show wg0, in 0.00 seconds) container-test-run-user-firewall-iptables> machine: must succeed: ip addr show wg0 container-test-run-user-firewall-iptables> machine: (finished: must succeed: ip addr show wg0, in 0.00 seconds) container-test-run-user-firewall-iptables> machine: must succeed: runuser -u alice -- curl -s --interface wg0 http://10.100.0.2:8081/ container-test-run-user-firewall-iptables> machine: (finished: must succeed: runuser -u alice -- curl -s --interface wg0 http://10.100.0.2:8081/, in 0.01 seconds) container-test-run-user-firewall-iptables> machine: must succeed: runuser -u alice -- curl -s --interface wg0 http://[fd00::2]:8081/ container-test-run-user-firewall-iptables> machine: (finished: must succeed: runuser -u alice -- curl -s --interface wg0 http://[fd00::2]:8081/, in 0.01 seconds) container-test-run-user-firewall-iptables> machine: must succeed: runuser -u bob -- curl -s --interface wg0 http://10.100.0.2:8081/ container-test-run-user-firewall-iptables> machine: (finished: must succeed: runuser -u bob -- curl -s --interface wg0 http://10.100.0.2:8081/, in 0.01 seconds) container-test-run-user-firewall-iptables> machine: must succeed: runuser -u bob -- curl -s --interface wg0 http://[fd00::2]:8081/ container-test-run-user-firewall-iptables> machine: (finished: must succeed: runuser -u bob -- curl -s --interface wg0 http://[fd00::2]:8081/, in 0.01 seconds) container-test-run-user-firewall-iptables> machine: must succeed: iptables -L user-firewall-output -n -v | grep -E 'wg0|wg\+' >&2 container-test-run-user-firewall-iptables> 0 0 RETURN all -- * wg+ 0.0.0.0/0 0.0.0.0/0 container-test-run-user-firewall-iptables> machine: (finished: must succeed: iptables -L user-firewall-output -n -v | grep -E 'wg0|wg\+' >&2, in 0.00 seconds) container-test-run-user-firewall-iptables> (finished: run the VM test script, in 9.61 seconds) container-test-run-user-firewall-iptables> test script finished in 9.75s container-test-run-user-firewall-iptables> cleanup container-test-run-user-firewall-iptables> kill NspawnMachine (pid 52) container-test-run-user-firewall-iptables> machine # [7466877.310106] machine runuser[484]: pam_unix(runuser:session): session closed for user bob container-test-run-user-firewall-iptables> kill NspawnMachine (pid 53) container-test-run-user-firewall-iptables> Container machine terminated by signal KILL. container-test-run-user-firewall-iptables> Container router terminated by signal KILL. container-test-run-user-firewall-iptables> (finished: cleanup, in 0.18 seconds) post-build step Upload to niks3: ok time=2026-08-25T20:08:55.331Z level=INFO msg="Uploading 0 paths to niks3.clan.lol (1 already cached)" time=2026-08-25T20:08:56.660Z level=INFO msg="Uploading 1 narinfos" time=2026-08-25T20:08:56.812Z level=INFO msg="Upload complete. (1.543s)"