these 53 derivations will be built: /nix/store/182mzx542yqk3hlbfnvx7a5isr1qi7i6-nftables-cleanup-deletions.drv /nix/store/1xclyh137a4ah483bjciqxpbmd55n44c-system-path.drv /nix/store/5d34ahi37bihkidmigra157v15svixhf-nginx.conf.drv /nix/store/s8lfkg9az6rry55pspmark1zxg9np9dc-extra-hosts.drv /nix/store/i45nxdah96m62z2px82j85ivwh0k0w4i-hosts.drv /nix/store/mnjky27kd9qqn9ggghikjld3y09zx519-dbus-1.drv /nix/store/fynqsm74vnx0arcv5nd2k8xryxg71x1a-X-Restart-Triggers-dbus-broker.drv /nix/store/m5jww0r31akxhys77xqqhdc5xpra649q-unit-dbus-broker.service.drv /nix/store/k9bh6mdj3x38jmz4i75j7x9wpqd68w49-user-units.drv /nix/store/9cw2b32lkywr7lmzjfyzadsp72m83m78-unit-dbus-broker.service.drv /nix/store/w3dyjlnn08a4m3i6bh451mhqmfbvcx4w-unit-script-setup-wg0-interface-start.drv /nix/store/9vgmyx6ff3wh9qd2x3j7a8vsix6gr18p-unit-setup-wg0-interface.service.drv /nix/store/fsr7dv2fm1p2vag4yiky47pvh5q94311-unit-script-nginx-pre-start.drv /nix/store/f7lfw13vcxy3sj4val6rib6wj9ajbk6g-unit-nginx.service.drv /nix/store/3c81zwfyx5m9pxww49p0hkmijd71i9ki-nftables-deletions.drv /nix/store/r4gnmq8s4z7ls1zxll7gslsa2r3lg1x3-passwd.drv /nix/store/bkhnvfkysx9fkfck1fbydry7y52kzbws-nftables-rules.drv /nix/store/d8gkkasnh7p1d63cz0xl1wvz5mprzkva-nftables-save-deletions.drv /nix/store/zvfgk0i2my6l5dwlz8gmk5fy4jghq66a-nftables-ensure-deletions.drv /nix/store/j96dp4wrq92cf26x5m60l8ddgbc86xmf-unit-nftables.service.drv /nix/store/w072vai52gh4q773k52d1dazrrzvijpm-system-units.drv /nix/store/1gkvixrb7byv4j6nsr87p2gjqmgc09i0-etc.drv /nix/store/27qp7sdfll8dljj02vdlx4qpfjxm0p1w-nginx.conf.drv /nix/store/345v23r4x62c7wv5ylnyl05lbpdc9him-string-hosts.drv /nix/store/wn8xmw45a8wwzm7gf84cg8ya71p9nm75-X-Reload-Triggers-systemd-networkd.drv /nix/store/4n5kpda9dna6km3cmlrxp0hcp9cn3899-unit-systemd-networkd.service.drv /nix/store/fjmxbz8a0qxff881jfm7x3r9829lkn9r-system-path.drv /nix/store/kw4vfgzyyyll3sykacbh1clpf2x2m2qb-dbus-1.drv /nix/store/ww6054n4czgxjajzpra4yx201m0snim5-X-Restart-Triggers-dbus-broker.drv /nix/store/shar6yhqbf5biw3k3dj8yl8s8cjarqgh-unit-dbus-broker.service.drv /nix/store/bm5y5ylq134bbpjcmcynfpi8mqi9m0rl-unit-script-nginx-pre-start.drv /nix/store/x79y2317km0rkl452wm976y8g2zpi0bm-unit-nginx.service.drv /nix/store/y9cja7pjn3x5h6n2hrqpnvbssr7j10sq-unit-systemd-networkd-wait-online.service.drv /nix/store/9dv76bfb1zzp3nvjdq7rzb5sfa57mf3b-system-units.drv /nix/store/gvdd4a1pydc5m7q8z9awm3m4d6qkr2s3-etc-hostname.drv /nix/store/nibmgm5pama8yj1hzna18ljkbny4yhh7-hosts.drv /nix/store/l8h36vhavf6f3i44jmdkk9gm6na48zbg-unit-dbus-broker.service.drv /nix/store/pa7nxs3bxqvgfz1zm499xbkqnkcfsn2j-user-units.drv /nix/store/4dqz4dxyfnx6hvmyx6fj64hg2b7q9xcn-etc.drv /nix/store/z947zivva45sffh0ia5dpdrikdk2gh2m-users-groups.json.drv /nix/store/ayyzrjhlcma3sx37i9a8s5azzjhsclm9-dry-activate.drv /nix/store/q8gmsybc42qqkcvcwrci5r42is2ci8rj-activate.drv /nix/store/56lddz74k9dln9xa6md2g753i964214y-nixos-system-machine-test.drv /nix/store/g45612ykiz6pfjsasyk4fdwa05xlx9p1-run-machine-nspawn.drv /nix/store/gj8yfl8bxb0gp9nvmi419xj2gaxr3gpw-users-groups.json.drv /nix/store/50bpan0dawy44zgr6ka67syz8m0n922r-activate.drv /nix/store/k6x3lv79qm5gxqr6gx8npjn651rfjmdi-dry-activate.drv /nix/store/xsgjm37lgfidk7w4b71q0pdzpq3g60l4-nixos-system-router-test.drv /nix/store/lrg4hcmlj810ax222a9mhd07v2wh1gcd-run-router-nspawn.drv /nix/store/s5y02lnx9fyk7in26409xxb45h3m57yw-test-script.drv /nix/store/nsz4z3hl57v4fcagq602gaphlisi3w2h-driverConfiguration.json.drv /nix/store/f6ym42dfspfhqq8jkbfb1xmbn4w6v3k0-nixos-test-driver-user-firewall-nftables.drv /nix/store/4f4k8dv96n9bs08wgalh3aqvbjrschgz-container-test-run-user-firewall-nftables.drv this path will be fetched (18.1 MiB download, 52.1 MiB unpacked): /nix/store/shpvivs3i9y1hf59mh17lkqj0f6mwi34-lkl-2025-11-13-lib building '/nix/store/s5y02lnx9fyk7in26409xxb45h3m57yw-test-script.drv' building '/nix/store/1xclyh137a4ah483bjciqxpbmd55n44c-system-path.drv' building '/nix/store/fjmxbz8a0qxff881jfm7x3r9829lkn9r-system-path.drv' building '/nix/store/gvdd4a1pydc5m7q8z9awm3m4d6qkr2s3-etc-hostname.drv' building '/nix/store/27qp7sdfll8dljj02vdlx4qpfjxm0p1w-nginx.conf.drv' building '/nix/store/5d34ahi37bihkidmigra157v15svixhf-nginx.conf.drv' building '/nix/store/s8lfkg9az6rry55pspmark1zxg9np9dc-extra-hosts.drv' building '/nix/store/345v23r4x62c7wv5ylnyl05lbpdc9him-string-hosts.drv' building '/nix/store/y9cja7pjn3x5h6n2hrqpnvbssr7j10sq-unit-systemd-networkd-wait-online.service.drv' building '/nix/store/wn8xmw45a8wwzm7gf84cg8ya71p9nm75-X-Reload-Triggers-systemd-networkd.drv' nginx.conf> structuredAttrs is enabled nginx.conf> structuredAttrs is enabled system-path> structuredAttrs is enabled system-path> created 1579 symlinks in user environment system-path> structuredAttrs is enabled system-path> created 1566 symlinks in user environment unit-systemd-networkd-wait-online.service> structuredAttrs is enabled building '/nix/store/182mzx542yqk3hlbfnvx7a5isr1qi7i6-nftables-cleanup-deletions.drv' building '/nix/store/3c81zwfyx5m9pxww49p0hkmijd71i9ki-nftables-deletions.drv' building '/nix/store/zvfgk0i2my6l5dwlz8gmk5fy4jghq66a-nftables-ensure-deletions.drv' building '/nix/store/w3dyjlnn08a4m3i6bh451mhqmfbvcx4w-unit-script-setup-wg0-interface-start.drv' building '/nix/store/i45nxdah96m62z2px82j85ivwh0k0w4i-hosts.drv' building '/nix/store/nibmgm5pama8yj1hzna18ljkbny4yhh7-hosts.drv' building '/nix/store/r4gnmq8s4z7ls1zxll7gslsa2r3lg1x3-passwd.drv' building '/nix/store/kw4vfgzyyyll3sykacbh1clpf2x2m2qb-dbus-1.drv' building '/nix/store/mnjky27kd9qqn9ggghikjld3y09zx519-dbus-1.drv' building '/nix/store/d8gkkasnh7p1d63cz0xl1wvz5mprzkva-nftables-save-deletions.drv' nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> building '/nix/store/4n5kpda9dna6km3cmlrxp0hcp9cn3899-unit-systemd-networkd.service.drv' building '/nix/store/ww6054n4czgxjajzpra4yx201m0snim5-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/9vgmyx6ff3wh9qd2x3j7a8vsix6gr18p-unit-setup-wg0-interface.service.drv' building '/nix/store/gj8yfl8bxb0gp9nvmi419xj2gaxr3gpw-users-groups.json.drv' building '/nix/store/z947zivva45sffh0ia5dpdrikdk2gh2m-users-groups.json.drv' unit-setup-wg0-interface.service> structuredAttrs is enabled unit-systemd-networkd.service> structuredAttrs is enabled building '/nix/store/fynqsm74vnx0arcv5nd2k8xryxg71x1a-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/bkhnvfkysx9fkfck1fbydry7y52kzbws-nftables-rules.drv' building '/nix/store/l8h36vhavf6f3i44jmdkk9gm6na48zbg-unit-dbus-broker.service.drv' building '/nix/store/shar6yhqbf5biw3k3dj8yl8s8cjarqgh-unit-dbus-broker.service.drv' building '/nix/store/bm5y5ylq134bbpjcmcynfpi8mqi9m0rl-unit-script-nginx-pre-start.drv' building '/nix/store/fsr7dv2fm1p2vag4yiky47pvh5q94311-unit-script-nginx-pre-start.drv' unit-dbus-broker.service> structuredAttrs is enabled unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/ayyzrjhlcma3sx37i9a8s5azzjhsclm9-dry-activate.drv' building '/nix/store/k6x3lv79qm5gxqr6gx8npjn651rfjmdi-dry-activate.drv' building '/nix/store/9cw2b32lkywr7lmzjfyzadsp72m83m78-unit-dbus-broker.service.drv' building '/nix/store/m5jww0r31akxhys77xqqhdc5xpra649q-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/j96dp4wrq92cf26x5m60l8ddgbc86xmf-unit-nftables.service.drv' building '/nix/store/f7lfw13vcxy3sj4val6rib6wj9ajbk6g-unit-nginx.service.drv' building '/nix/store/x79y2317km0rkl452wm976y8g2zpi0bm-unit-nginx.service.drv' building '/nix/store/pa7nxs3bxqvgfz1zm499xbkqnkcfsn2j-user-units.drv' unit-dbus-broker.service> structuredAttrs is enabled unit-nftables.service> structuredAttrs is enabled unit-nginx.service> structuredAttrs is enabled unit-nginx.service> structuredAttrs is enabled building '/nix/store/9dv76bfb1zzp3nvjdq7rzb5sfa57mf3b-system-units.drv' building '/nix/store/w072vai52gh4q773k52d1dazrrzvijpm-system-units.drv' building '/nix/store/k9bh6mdj3x38jmz4i75j7x9wpqd68w49-user-units.drv' building '/nix/store/1gkvixrb7byv4j6nsr87p2gjqmgc09i0-etc.drv' building '/nix/store/4dqz4dxyfnx6hvmyx6fj64hg2b7q9xcn-etc.drv' building '/nix/store/q8gmsybc42qqkcvcwrci5r42is2ci8rj-activate.drv' building '/nix/store/50bpan0dawy44zgr6ka67syz8m0n922r-activate.drv' building '/nix/store/56lddz74k9dln9xa6md2g753i964214y-nixos-system-machine-test.drv' building '/nix/store/xsgjm37lgfidk7w4b71q0pdzpq3g60l4-nixos-system-router-test.drv' nixos-system-machine-test> structuredAttrs is enabled building '/nix/store/g45612ykiz6pfjsasyk4fdwa05xlx9p1-run-machine-nspawn.drv' nixos-system-router-test> structuredAttrs is enabled building '/nix/store/lrg4hcmlj810ax222a9mhd07v2wh1gcd-run-router-nspawn.drv' building '/nix/store/nsz4z3hl57v4fcagq602gaphlisi3w2h-driverConfiguration.json.drv' driverConfiguration.json> structuredAttrs is enabled building '/nix/store/f6ym42dfspfhqq8jkbfb1xmbn4w6v3k0-nixos-test-driver-user-firewall-nftables.drv' nixos-test-driver-user-firewall-nftables> Running type check (enable/disable: config.skipTypeCheck) nixos-test-driver-user-firewall-nftables> See https://nixos.org/manual/nixos/stable/#test-opt-skipTypeCheck nixos-test-driver-user-firewall-nftables> All checks passed! nixos-test-driver-user-firewall-nftables> Linting test script (enable/disable: config.skipLint) nixos-test-driver-user-firewall-nftables> See https://nixos.org/manual/nixos/stable/#test-opt-skipLint nixos-test-driver-user-firewall-nftables> All checks passed! building '/nix/store/4f4k8dv96n9bs08wgalh3aqvbjrschgz-container-test-run-user-firewall-nftables.drv' on 'ssh-ng://builder@build-x86-01.clan.lol' building '/nix/store/4f4k8dv96n9bs08wgalh3aqvbjrschgz-container-test-run-user-firewall-nftables.drv' container-test-run-user-firewall-nftables> Machine state will be reset. To keep it, pass --keep-machine-state container-test-run-user-firewall-nftables> start all VLans container-test-run-user-firewall-nftables> (finished: start all VLans, in 0.00 seconds) container-test-run-user-firewall-nftables> container-test-run-user-firewall-nftables> Test will time out and terminate in 3600.0 seconds container-test-run-user-firewall-nftables> run the VM test script container-test-run-user-firewall-nftables> additionally exposed symbols: container-test-run-user-firewall-nftables> machine, router, container-test-run-user-firewall-nftables> vlan1, container-test-run-user-firewall-nftables> start_all, test_script, machines, machines_qemu, machines_nspawn, vlans, driver, log, os, create_machine, subtest, run_tests, join_all, retry, serial_stdout_off, serial_stdout_on, polling_condition, BaseMachine, QemuMachine, NspawnMachine, t, debug, dump_machine_ssh container-test-run-user-firewall-nftables> start all VMs container-test-run-user-firewall-nftables> machine: systemd-nspawn running (pid 52) container-test-run-user-firewall-nftables> machine: Waiting for journal at /build/vm-state-machine/var/log/journal... container-test-run-user-firewall-nftables> router: systemd-nspawn running (pid 53) container-test-run-user-firewall-nftables> router: Waiting for journal at /build/vm-state-router/var/log/journal... container-test-run-user-firewall-nftables> (finished: start all VMs, in 0.00 seconds) container-test-run-user-firewall-nftables> router: waiting for unit multi-user.target container-test-run-user-firewall-nftables> nixos-nspawn(router): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-user-firewall-nftables> nixos-nspawn(router): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-user-firewall-nftables> nixos-nspawn(machine): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-user-firewall-nftables> nixos-nspawn(machine): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-user-firewall-nftables> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-user-firewall-nftables> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-user-firewall-nftables> ░ Spawning container router on /build/vm-state-router. container-test-run-user-firewall-nftables> ░ Spawning container machine on /build/vm-state-machine. container-test-run-user-firewall-nftables> machine # [7466863.715967] machine systemd-journald[54]: Journal started container-test-run-user-firewall-nftables> machine # [7466863.715997] machine systemd-journald[54]: Runtime Journal (/run/log/journal/953be6d9f0004ba98d8094dd9374766c) is 8M, max 3.7G, 3.7G free. container-test-run-user-firewall-nftables> machine # [7466863.720417] machine systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-user-firewall-nftables> machine # [7466863.720714] machine systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-user-firewall-nftables> machine # [7466863.725907] machine systemd-journald[54]: Time spent on flushing to /var/log/journal/953be6d9f0004ba98d8094dd9374766c is 1.103ms for 4 entries. container-test-run-user-firewall-nftables> machine # [7466863.725907] machine systemd-journald[54]: System Journal (/var/log/journal/953be6d9f0004ba98d8094dd9374766c) is 8M, max 4G, 3.9G free. container-test-run-user-firewall-nftables> machine # [7466863.728621] machine systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-user-firewall-nftables> machine # [7466863.728745] machine systemd[1]: Reached target Preparation for Local File Systems. container-test-run-user-firewall-nftables> machine # [7466863.728795] machine systemd[1]: Reached target Local File Systems. container-test-run-user-firewall-nftables> machine # [7466863.729222] machine systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-user-firewall-nftables> machine # [7466863.729250] machine systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-user-firewall-nftables> machine # [7466863.729697] machine systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-user-firewall-nftables> machine # [7466863.729713] machine systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-user-firewall-nftables> machine # [7466863.880247] machine systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-user-firewall-nftables> machine # [7466863.880976] machine systemd[1]: Starting Create System Files and Directories... container-test-run-user-firewall-nftables> machine # [7466863.906254] machine systemd-tmpfiles[66]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-user-firewall-nftables> machine # [7466863.906456] machine systemd-tmpfiles[66]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-user-firewall-nftables> machine # [7466863.906585] machine systemd-tmpfiles[66]: fchmod() of /var/log/journal/953be6d9f0004ba98d8094dd9374766c failed: Operation not permitted container-test-run-user-firewall-nftables> machine # [7466863.906767] machine systemd-tmpfiles[66]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-user-firewall-nftables> machine # [7466863.908073] machine systemd[1]: Finished Create System Files and Directories. container-test-run-user-firewall-nftables> machine # [7466863.909008] machine systemd[1]: Starting Rebuild Journal Catalog... container-test-run-user-firewall-nftables> machine # [7466863.909666] machine systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-user-firewall-nftables> machine # [7466863.918323] machine systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-user-firewall-nftables> machine # [7466863.923485] machine systemd[1]: Finished Rebuild Journal Catalog. container-test-run-user-firewall-nftables> machine # [7466863.924118] machine systemd[1]: Starting Update is Completed... container-test-run-user-firewall-nftables> machine # [7466863.930320] machine systemd[1]: Finished Update is Completed. container-test-run-user-firewall-nftables> machine # [7466863.930392] machine systemd[1]: Reached target System Initialization. container-test-run-user-firewall-nftables> machine # [7466863.930455] machine systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-user-firewall-nftables> machine # [7466863.930483] machine systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-user-firewall-nftables> machine # [7466863.930500] machine systemd[1]: Reached target Timer Units. container-test-run-user-firewall-nftables> machine # [7466863.930593] machine systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-user-firewall-nftables> machine # [7466863.930687] machine systemd[1]: Listening on Nix Daemon Socket. container-test-run-user-firewall-nftables> machine # [7466863.930778] machine systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-user-firewall-nftables> machine # [7466863.930794] machine systemd[1]: Reached target Socket Units. container-test-run-user-firewall-nftables> machine # [7466863.930824] machine systemd[1]: Reached target Basic System. container-test-run-user-firewall-nftables> machine # [7466863.931610] machine systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-user-firewall-nftables> machine # [7466863.932104] machine systemd[1]: Starting nftables firewall... container-test-run-user-firewall-nftables> machine # [7466863.932654] machine systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-user-firewall-nftables> machine # [7466863.942898] machine systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-user-firewall-nftables> machine # [7466863.979998] machine nsncd[76]: Aug 25 20:08:41.345 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-user-firewall-nftables> machine # [7466863.980031] machine systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-user-firewall-nftables> machine # [7466863.980084] machine systemd[1]: Reached target Host and Network Name Lookups. container-test-run-user-firewall-nftables> machine # [7466863.980125] machine systemd[1]: Reached target User and Group Name Lookups. container-test-run-user-firewall-nftables> machine # [7466863.980912] machine systemd[1]: Starting User Login Management... container-test-run-user-firewall-nftables> machine # [7466863.986185] machine systemd[1]: Finished nftables firewall. container-test-run-user-firewall-nftables> router # [7466863.716172] router systemd-journald[54]: Journal started container-test-run-user-firewall-nftables> machine # [7466863.986327] machine systemd[1]: Reached target Preparation for Network. container-test-run-user-firewall-nftables> router # [7466863.716198] router systemd-journald[54]: Runtime Journal (/run/log/journal/9542999fc6f24d13bcf2c5a7236d909a) is 8M, max 3.7G, 3.7G free. container-test-run-user-firewall-nftables> machine # [7466863.986957] machine systemd[1]: Starting Address configuration of eth1... container-test-run-user-firewall-nftables> router # [7466863.717642] router systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-user-firewall-nftables> machine # [7466863.987638] machine systemd[1]: Starting Extra networking commands.... container-test-run-user-firewall-nftables> router # [7466863.722785] router systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-user-firewall-nftables> machine # [7466863.988112] machine systemd[1]: Starting Setup wg0 dummy interface... container-test-run-user-firewall-nftables> router # [7466863.723161] router systemd[1]: Starting Network Name Resolution... container-test-run-user-firewall-nftables> machine # [7466863.998499] machine network-addresses-eth1-start[107]: adding address 192.168.1.1/24... done container-test-run-user-firewall-nftables> machine # [7466863.998919] machine systemd[1]: Finished Setup wg0 dummy interface. container-test-run-user-firewall-nftables> router # [7466863.723449] router systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-user-firewall-nftables> machine # [7466863.999924] machine network-addresses-eth1-start[107]: adding address 2001:db8:1::1/64... done container-test-run-user-firewall-nftables> router # [7466863.727784] router systemd-journald[54]: Time spent on flushing to /var/log/journal/9542999fc6f24d13bcf2c5a7236d909a is 1.254ms for 6 entries. container-test-run-user-firewall-nftables> machine # [7466864.002451] machine systemd[1]: Finished Address configuration of eth1. container-test-run-user-firewall-nftables> router # [7466863.727784] router systemd-journald[54]: System Journal (/var/log/journal/9542999fc6f24d13bcf2c5a7236d909a) is 8M, max 4G, 3.9G free. container-test-run-user-firewall-nftables> machine # [7466864.022530] machine systemd[1]: Stopped target Host and Network Name Lookups. container-test-run-user-firewall-nftables> router # [7466863.730915] router systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-user-firewall-nftables> machine # [7466864.022577] machine systemd[1]: Stopping Host and Network Name Lookups... container-test-run-user-firewall-nftables> router # [7466863.731039] router systemd[1]: Reached target Preparation for Local File Systems. container-test-run-user-firewall-nftables> router # [7466863.731080] router systemd[1]: Reached target Local File Systems. container-test-run-user-firewall-nftables> machine # [7466864.022604] machine systemd[1]: Stopped target User and Group Name Lookups. container-test-run-user-firewall-nftables> router # [7466863.731471] router systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-user-firewall-nftables> machine # [7466864.022622] machine systemd[1]: Stopping User and Group Name Lookups... container-test-run-user-firewall-nftables> router # [7466863.731496] router systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-user-firewall-nftables> machine # [7466864.022758] machine systemd[1]: Stopping Name Service Cache Daemon (nsncd)... container-test-run-user-firewall-nftables> router # [7466863.731875] router systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-user-firewall-nftables> machine # [7466864.025100] machine systemd[1]: nscd.service: Deactivated successfully. container-test-run-user-firewall-nftables> router # [7466863.731894] router systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-user-firewall-nftables> machine # [7466864.025237] machine systemd[1]: Stopped Name Service Cache Daemon (nsncd). container-test-run-user-firewall-nftables> router # [7466863.732343] router systemd[1]: Starting Network Management... container-test-run-user-firewall-nftables> machine # [7466864.027433] machine systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-user-firewall-nftables> router # [7466863.879051] router systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-user-firewall-nftables> router # [7466863.880392] router systemd[1]: Starting Create System Files and Directories... container-test-run-user-firewall-nftables> machine # [7466864.045266] machine systemd[1]: Finished Extra networking commands.. container-test-run-user-firewall-nftables> router # [7466863.904395] router systemd-tmpfiles[70]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-user-firewall-nftables> machine # [7466864.045610] machine systemd[1]: Reached target Network. container-test-run-user-firewall-nftables> router # [7466863.904559] router systemd-tmpfiles[70]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-user-firewall-nftables> machine # [7466864.053672] machine systemd[1]: Starting Nginx Web Server... container-test-run-user-firewall-nftables> router # [7466863.904662] router systemd-tmpfiles[70]: fchmod() of /var/log/journal/9542999fc6f24d13bcf2c5a7236d909a failed: Operation not permitted container-test-run-user-firewall-nftables> machine # [7466864.099954] machine nsncd[174]: Aug 25 20:08:41.465 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-user-firewall-nftables> router # [7466863.904827] router systemd-tmpfiles[70]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-user-firewall-nftables> machine # [7466864.100088] machine systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-user-firewall-nftables> machine # [7466864.100153] machine systemd[1]: Reached target Host and Network Name Lookups. container-test-run-user-firewall-nftables> router # [7466863.906133] router systemd[1]: Finished Create System Files and Directories. container-test-run-user-firewall-nftables> machine # [7466864.100199] machine systemd[1]: Reached target User and Group Name Lookups. container-test-run-user-firewall-nftables> router # [7466863.907173] router systemd[1]: Starting Rebuild Journal Catalog... container-test-run-user-firewall-nftables> machine # [7466864.100987] machine systemd[1]: Starting Permit User Sessions... container-test-run-user-firewall-nftables> router # [7466863.907559] router systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-user-firewall-nftables> machine # [7466864.120896] machine systemd[1]: Finished Permit User Sessions. container-test-run-user-firewall-nftables> router # [7466863.916705] router systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-user-firewall-nftables> machine # [7466864.121720] machine systemd[1]: Started Console Getty. container-test-run-user-firewall-nftables> router # [7466863.921062] router systemd[1]: Finished Rebuild Journal Catalog. container-test-run-user-firewall-nftables> machine # [7466864.121764] machine systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-user-firewall-nftables> router # [7466863.921577] router systemd[1]: Starting Update is Completed... container-test-run-user-firewall-nftables> machine # [7466864.121785] machine systemd[1]: Reached target Login Prompts. container-test-run-user-firewall-nftables> router # [7466863.928382] router systemd[1]: Finished Update is Completed. container-test-run-user-firewall-nftables> router # [7466863.982997] router systemd-networkd[66]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-user-firewall-nftables> router # [7466863.983101] router systemd-networkd[66]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-user-firewall-nftables> router # [7466863.989197] router systemd-networkd[66]: lo: Link UP container-test-run-user-firewall-nftables> router # [7466863.989200] router systemd-networkd[66]: lo: Gained carrier container-test-run-user-firewall-nftables> router # [7466863.989411] router systemd-networkd[66]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-user-firewall-nftables> router # [7466863.989703] router systemd[1]: Started Network Management. container-test-run-user-firewall-nftables> router # [7466863.989767] router systemd-networkd[66]: eth1: Link UP container-test-run-user-firewall-nftables> router # [7466863.989924] router systemd-networkd[66]: eth1: Gained carrier container-test-run-user-firewall-nftables> router # [7466863.990682] router systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-user-firewall-nftables> router # [7466864.006621] router systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-user-firewall-nftables> router # [7466864.201398] router systemd-resolved[61]: Positive Trust Anchors: container-test-run-user-firewall-nftables> router # [7466864.201410] router systemd-resolved[61]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-user-firewall-nftables> router # [7466864.201414] router systemd-resolved[61]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-user-firewall-nftables> router # [7466864.201435] router systemd-resolved[61]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-user-firewall-nftables> router # [7466864.214392] router systemd-resolved[61]: Using system hostname 'router'. container-test-run-user-firewall-nftables> router # [7466864.215625] router systemd[1]: Started Network Name Resolution. container-test-run-user-firewall-nftables> router # [7466864.215740] router systemd[1]: Reached target Network. container-test-run-user-firewall-nftables> router # [7466864.215806] router systemd[1]: Reached target System Initialization. container-test-run-user-firewall-nftables> router # [7466864.215873] router systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-user-firewall-nftables> router # [7466864.215910] router systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-user-firewall-nftables> router # [7466864.215931] router systemd[1]: Reached target Timer Units. container-test-run-user-firewall-nftables> router # [7466864.216090] router systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-user-firewall-nftables> router # [7466864.216225] router systemd[1]: Listening on Nix Daemon Socket. container-test-run-user-firewall-nftables> router # [7466864.216335] router systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-user-firewall-nftables> router # [7466864.216349] router systemd[1]: Reached target Socket Units. container-test-run-user-firewall-nftables> router # [7466864.216379] router systemd[1]: Reached target Basic System. container-test-run-user-firewall-nftables> router # [7466864.217535] router systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-user-firewall-nftables> router # [7466864.218170] router systemd[1]: Starting Nginx Web Server... container-test-run-user-firewall-nftables> router # [7466864.218676] router systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-user-firewall-nftables> router # [7466864.219614] router systemd[1]: Starting D-Bus System Message Bus... container-test-run-user-firewall-nftables> router # [7466864.245701] router systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-user-firewall-nftables> router # [7466864.300841] router nsncd[83]: Aug 25 20:08:41.666 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-user-firewall-nftables> router # [7466864.300869] router systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-user-firewall-nftables> router # [7466864.300949] router systemd[1]: Reached target Host and Network Name Lookups. container-test-run-user-firewall-nftables> router # [7466864.301013] router systemd[1]: Reached target User and Group Name Lookups. container-test-run-user-firewall-nftables> router # [7466864.310327] router systemd[1]: Starting User Login Management... container-test-run-user-firewall-nftables> router # [7466864.311051] router systemd[1]: Starting Permit User Sessions... container-test-run-user-firewall-nftables> router # [7466864.319449] router systemd[1]: Finished Permit User Sessions. container-test-run-user-firewall-nftables> router # [7466864.320462] router systemd[1]: Started Console Getty. container-test-run-user-firewall-nftables> router # [7466864.320503] router systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-user-firewall-nftables> router # [7466864.320523] router systemd[1]: Reached target Login Prompts. container-test-run-user-firewall-nftables> router # [7466864.360838] router dbus-broker-launch[84]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-user-firewall-nftables> router # [7466864.361352] router dbus-broker-launch[84]: NSS returned no entry for 'systemd-timesync' container-test-run-user-firewall-nftables> router # [7466864.361352] router dbus-broker-launch[84]: Invalid user-name in /nix/store/s43s9pc0c6rxp0mgpnk467qpc5v3xh50-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-user-firewall-nftables> router # [7466864.361696] router systemd[1]: Started D-Bus System Message Bus. container-test-run-user-firewall-nftables> router # [7466864.365778] router dbus-broker-launch[84]: Ready container-test-run-user-firewall-nftables> machine # [7466864.289982] machine systemd-logind[99]: New seat seat0. container-test-run-user-firewall-nftables> machine # [7466864.291906] machine systemd[1]: Starting D-Bus System Message Bus... container-test-run-user-firewall-nftables> machine # [7466864.291961] machine systemd[1]: Started User Login Management. container-test-run-user-firewall-nftables> machine # [7466864.292537] machine systemd[1]: Starting linger-users.service... container-test-run-user-firewall-nftables> machine # [7466864.316372] machine systemd[1]: linger-users.service: Deactivated successfully. container-test-run-user-firewall-nftables> machine # [7466864.316500] machine systemd[1]: Finished linger-users.service. container-test-run-user-firewall-nftables> machine # [7466864.410918] machine nginx-pre-start[202]: nginx: the configuration file /nix/store/l3cd84w4xgf1kji8qqry6kj3fknp5iv2-nginx.conf syntax is ok container-test-run-user-firewall-nftables> machine # [7466864.411330] machine nginx-pre-start[202]: nginx: configuration file /nix/store/l3cd84w4xgf1kji8qqry6kj3fknp5iv2-nginx.conf test is successful container-test-run-user-firewall-nftables> machine # [7466864.414330] machine systemd[1]: Started Nginx Web Server. container-test-run-user-firewall-nftables> machine # [7466864.414441] machine systemd[1]: Reached target Multi-User System. container-test-run-user-firewall-nftables> machine # [7466864.432206] machine dbus-broker-launch[198]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-user-firewall-nftables> machine # [7466864.432642] machine dbus-broker-launch[198]: NSS returned no entry for 'systemd-timesync' container-test-run-user-firewall-nftables> machine # [7466864.432642] machine dbus-broker-launch[198]: Invalid user-name in /nix/store/45ig1bdphk6d7l2z6yj5idgx5diwykr8-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-user-firewall-nftables> machine # [7466864.432924] machine systemd[1]: Started D-Bus System Message Bus. container-test-run-user-firewall-nftables> machine # [7466864.436922] machine dbus-broker-launch[198]: Ready container-test-run-user-firewall-nftables> router # [7466864.620771] router systemd-logind[102]: New seat seat0. container-test-run-user-firewall-nftables> router # [7466864.620912] router systemd[1]: Started User Login Management. container-test-run-user-firewall-nftables> router # [7466864.622645] router systemd[1]: Starting linger-users.service... container-test-run-user-firewall-nftables> router # [7466864.628930] router nginx-pre-start[113]: nginx: the configuration file /nix/store/k17m2x3wxsyn2jq4da2kfb895cfhbhlk-nginx.conf syntax is ok container-test-run-user-firewall-nftables> router # [7466864.629326] router nginx-pre-start[113]: nginx: configuration file /nix/store/k17m2x3wxsyn2jq4da2kfb895cfhbhlk-nginx.conf test is successful container-test-run-user-firewall-nftables> router # [7466864.650319] router systemd[1]: Started Nginx Web Server. container-test-run-user-firewall-nftables> router # [7466864.657639] router systemd[1]: linger-users.service: Deactivated successfully. container-test-run-user-firewall-nftables> router # [7466864.657859] router systemd[1]: Finished linger-users.service. container-test-run-user-firewall-nftables> router # [7466864.658237] router systemd[1]: Reached target Multi-User System. container-test-run-user-firewall-nftables> router # [7466865.981164] router systemd-networkd[66]: eth1: Gained IPv6LL container-test-run-user-firewall-nftables> router: still waiting for container 'router' to reach ready state... container-test-run-user-firewall-nftables> machine # [7466874.953353] machine systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-user-firewall-nftables> machine # [7466874.954197] machine systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-user-firewall-nftables> machine # [7466874.954354] machine systemd[1]: Startup finished in 11.497s. container-test-run-user-firewall-nftables> router # [7466874.956014] router systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-user-firewall-nftables> router # [7466874.956637] router systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-user-firewall-nftables> router # [7466874.956840] router systemd[1]: Startup finished in 11.504s. container-test-run-user-firewall-nftables> router: (finished: waiting for unit multi-user.target, in 12.15 seconds) container-test-run-user-firewall-nftables> router: waiting for TCP port 80 on localhost container-test-run-user-firewall-nftables> Connection to localhost (::1) 80 port [tcp/http] succeeded! container-test-run-user-firewall-nftables> router: (finished: waiting for TCP port 80 on localhost, in 0.01 seconds) container-test-run-user-firewall-nftables> machine: waiting for unit multi-user.target container-test-run-user-firewall-nftables> machine: (finished: waiting for unit multi-user.target, in 0.01 seconds) container-test-run-user-firewall-nftables> machine: waiting for unit nginx.service container-test-run-user-firewall-nftables> machine: (finished: waiting for unit nginx.service, in 0.01 seconds) container-test-run-user-firewall-nftables> router: must succeed: ip -4 addr show eth1 | grep -oP '(?<=inet\s)\d+(\.\d+){3}' container-test-run-user-firewall-nftables> router: (finished: must succeed: ip -4 addr show eth1 | grep -oP '(?<=inet\s)\d+(\.\d+){3}', in 0.01 seconds) container-test-run-user-firewall-nftables> router: must succeed: ip -6 addr show eth1 | grep -oP '(?<=inet6\s)[0-9a-f:]+' | grep -v '^fe80' | head -1 container-test-run-user-firewall-nftables> router: (finished: must succeed: ip -6 addr show eth1 | grep -oP '(?<=inet6\s)[0-9a-f:]+' | grep -v '^fe80' | head -1, in 0.01 seconds) container-test-run-user-firewall-nftables> Router IPv4: 192.168.1.2 container-test-run-user-firewall-nftables> Router IPv6: 2001:db8:1::2 container-test-run-user-firewall-nftables> machine: must succeed: systemctl restart nftables container-test-run-user-firewall-nftables> machine: (finished: must succeed: systemctl restart nftables, in 0.11 seconds) container-test-run-user-firewall-nftables> machine: waiting for unit nftables.service container-test-run-user-firewall-nftables> machine: (finished: waiting for unit nftables.service, in 0.01 seconds) container-test-run-user-firewall-nftables> machine: must succeed: nft list table inet user-firewall >&2 container-test-run-user-firewall-nftables> table inet user-firewall { container-test-run-user-firewall-nftables> chain output { container-test-run-user-firewall-nftables> type filter hook output priority filter; policy accept; container-test-run-user-firewall-nftables> oifname "lo" counter packets 0 bytes 0 accept comment "allow lo" container-test-run-user-firewall-nftables> oifname "tun*" counter packets 0 bytes 0 accept comment "allow tun*" container-test-run-user-firewall-nftables> oifname "tap*" counter packets 0 bytes 0 accept comment "allow tap*" container-test-run-user-firewall-nftables> oifname "wg*" counter packets 0 bytes 0 accept comment "allow wg*" container-test-run-user-firewall-nftables> oifname "tailscale*" counter packets 0 bytes 0 accept comment "allow tailscale*" container-test-run-user-firewall-nftables> oifname "zt*" counter packets 0 bytes 0 accept comment "allow zt*" container-test-run-user-firewall-nftables> oifname "vpn*" counter packets 0 bytes 0 accept comment "allow vpn*" container-test-run-user-firewall-nftables> oifname "ipsec*" counter packets 0 bytes 0 accept comment "allow ipsec*" container-test-run-user-firewall-nftables> oifname "nebula*" counter packets 0 bytes 0 accept comment "allow nebula*" container-test-run-user-firewall-nftables> oifname "tinc*" counter packets 0 bytes 0 accept comment "allow tinc*" container-test-run-user-firewall-nftables> oifname "edge*" counter packets 0 bytes 0 accept comment "allow edge*" container-test-run-user-firewall-nftables> oifname "hyprspace" counter packets 0 bytes 0 accept comment "allow hyprspace" container-test-run-user-firewall-nftables> oifname "ham0" counter packets 0 bytes 0 accept comment "allow ham0" container-test-run-user-firewall-nftables> oifname "easytier" counter packets 0 bytes 0 accept comment "allow easytier" container-test-run-user-firewall-nftables> oifname "mycelium" counter packets 0 bytes 0 accept comment "allow mycelium" container-test-run-user-firewall-nftables> meta skuid 1002 counter packets 0 bytes 0 reject comment "blocked user bob" container-test-run-user-firewall-nftables> } container-test-run-user-firewall-nftables> } container-test-run-user-firewall-nftables> machine: (finished: must succeed: nft list table inet user-firewall >&2, in 0.01 seconds) container-test-run-user-firewall-nftables> machine: waiting for success: runuser -u alice -- curl -s http://127.0.0.1:8080 container-test-run-user-firewall-nftables> machine: (finished: waiting for success: runuser -u alice -- curl -s http://127.0.0.1:8080, in 0.02 seconds) container-test-run-user-firewall-nftables> machine: must succeed: runuser -u alice -- curl -s http://192.168.1.2 container-test-run-user-firewall-nftables> machine: (finished: must succeed: runuser -u alice -- curl -s http://192.168.1.2, in 0.02 seconds) container-test-run-user-firewall-nftables> machine: must succeed: runuser -u alice -- curl -s http://[2001:db8:1::2] container-test-run-user-firewall-nftables> machine: (finished: must succeed: runuser -u alice -- curl -s http://[2001:db8:1::2], in 0.01 seconds) container-test-run-user-firewall-nftables> machine: must succeed: runuser -u bob -- curl -s http://127.0.0.1:8080 container-test-run-user-firewall-nftables> machine: (finished: must succeed: runuser -u bob -- curl -s http://127.0.0.1:8080, in 0.01 seconds) container-test-run-user-firewall-nftables> machine: must succeed: runuser -u bob -- curl -s --connect-timeout 2 http://192.168.1.2 2>&1 || echo 'EXIT_CODE='$? container-test-run-user-firewall-nftables> machine: (finished: must succeed: runuser -u bob -- curl -s --connect-timeout 2 http://192.168.1.2 2>&1 || echo 'EXIT_CODE='$?, in 0.01 seconds) container-test-run-user-firewall-nftables> machine: must succeed: runuser -u bob -- curl -s --connect-timeout 2 http://[2001:db8:1::2] 2>&1 || echo 'EXIT_CODE='$? container-test-run-user-firewall-nftables> machine # [7466875.401280] machine systemd[1]: Stopping nftables firewall... container-test-run-user-firewall-nftables> machine # [7466875.430035] machine systemd[1]: nftables.service: Deactivated successfully. container-test-run-user-firewall-nftables> machine # [7466875.430217] machine systemd[1]: Stopped nftables firewall. container-test-run-user-firewall-nftables> machine # [7466875.431657] machine systemd[1]: Starting nftables firewall... container-test-run-user-firewall-nftables> machine # [7466875.499153] machine systemd[1]: Finished nftables firewall. container-test-run-user-firewall-nftables> machine # [7466875.524182] machine runuser[235]: pam_unix(runuser:session): session opened for user alice(uid=1001) by (uid=0) container-test-run-user-firewall-nftables> machine # [7466875.533387] machine runuser[235]: pam_unix(runuser:session): session closed for user alice container-test-run-user-firewall-nftables> machine # [7466875.543231] machine runuser[237]: pam_unix(runuser:session): session opened for user alice(uid=1001) by (uid=0) container-test-run-user-firewall-nftables> machine # [7466875.551855] machine runuser[237]: pam_unix(runuser:session): session closed for user alice container-test-run-user-firewall-nftables> machine # [7466875.558548] machine runuser[239]: pam_unix(runuser:session): session opened for user alice(uid=1001) by (uid=0) container-test-run-user-firewall-nftables> machine # [7466875.566219] machine runuser[239]: pam_unix(runuser:session): session closed for user alice container-test-run-user-firewall-nftables> machine # [7466875.572338] machine runuser[241]: pam_unix(runuser:session): session opened for user bob(uid=1002) by (uid=0) container-test-run-user-firewall-nftables> machine # [7466875.578776] machine runuser[241]: pam_unix(runuser:session): session closed for user bob container-test-run-user-firewall-nftables> machine # [7466875.585019] machine runuser[244]: pam_unix(runuser:session): session opened for user bob(uid=1002) by (uid=0) container-test-run-user-firewall-nftables> machine # [7466875.591807] machine runuser[244]: pam_unix(runuser:session): session closed for user bob container-test-run-user-firewall-nftables> machine # [7466875.598181] machine runuser[247]: pam_unix(runuser:session): session opened for user bob(uid=1002) by (uid=0) container-test-run-user-firewall-nftables> machine: (finished: must succeed: runuser -u bob -- curl -s --connect-timeout 2 http://[2001:db8:1::2] 2>&1 || echo 'EXIT_CODE='$?, in 1.01 seconds) container-test-run-user-firewall-nftables> machine: must succeed: nft list table inet user-firewall container-test-run-user-firewall-nftables> machine: (finished: must succeed: nft list table inet user-firewall, in 0.01 seconds) container-test-run-user-firewall-nftables> machine: waiting for unit setup-wg0-interface.service container-test-run-user-firewall-nftables> machine: (finished: waiting for unit setup-wg0-interface.service, in 0.01 seconds) container-test-run-user-firewall-nftables> machine: waiting for unit nginx.service container-test-run-user-firewall-nftables> machine: (finished: waiting for unit nginx.service, in 0.01 seconds) container-test-run-user-firewall-nftables> machine: waiting for TCP port 8081 on 10.100.0.2 container-test-run-user-firewall-nftables> Connection to 10.100.0.2 8081 port [tcp/sunproxyadmin] succeeded! container-test-run-user-firewall-nftables> machine: (finished: waiting for TCP port 8081 on 10.100.0.2, in 0.00 seconds) container-test-run-user-firewall-nftables> machine: must succeed: ip link show wg0 container-test-run-user-firewall-nftables> machine: (finished: must succeed: ip link show wg0, in 0.00 seconds) container-test-run-user-firewall-nftables> machine: must succeed: ip addr show wg0 container-test-run-user-firewall-nftables> machine: (finished: must succeed: ip addr show wg0, in 0.00 seconds) container-test-run-user-firewall-nftables> machine: must succeed: runuser -u alice -- curl -s --interface wg0 http://10.100.0.2:8081/ container-test-run-user-firewall-nftables> machine: (finished: must succeed: runuser -u alice -- curl -s --interface wg0 http://10.100.0.2:8081/, in 0.01 seconds) container-test-run-user-firewall-nftables> machine: must succeed: runuser -u alice -- curl -s --interface wg0 http://[fd00::2]:8081/ container-test-run-user-firewall-nftables> machine: (finished: must succeed: runuser -u alice -- curl -s --interface wg0 http://[fd00::2]:8081/, in 0.01 seconds) container-test-run-user-firewall-nftables> machine: must succeed: runuser -u bob -- curl -s --interface wg0 http://10.100.0.2:8081/ container-test-run-user-firewall-nftables> machine: (finished: must succeed: runuser -u bob -- curl -s --interface wg0 http://10.100.0.2:8081/, in 0.01 seconds) container-test-run-user-firewall-nftables> machine: must succeed: runuser -u bob -- curl -s --interface wg0 http://[fd00::2]:8081/ container-test-run-user-firewall-nftables> machine: (finished: must succeed: runuser -u bob -- curl -s --interface wg0 http://[fd00::2]:8081/, in 0.01 seconds) container-test-run-user-firewall-nftables> machine: must succeed: nft list table inet user-firewall | grep -E 'oifname.*wg' >&2 container-test-run-user-firewall-nftables> oifname "wg*" counter packets 1 bytes 56 accept comment "allow wg*" container-test-run-user-firewall-nftables> machine: (finished: must succeed: nft list table inet user-firewall | grep -E 'oifname.*wg' >&2, in 0.00 seconds) container-test-run-user-firewall-nftables> (finished: run the VM test script, in 13.48 seconds) container-test-run-user-firewall-nftables> test script finished in 13.62s container-test-run-user-firewall-nftables> cleanup container-test-run-user-firewall-nftables> kill NspawnMachine (pid 52) container-test-run-user-firewall-nftables> kill NspawnMachine (pid 53) container-test-run-user-firewall-nftables> Container machine terminated by signal KILL. container-test-run-user-firewall-nftables> Container router terminated by signal KILL. container-test-run-user-firewall-nftables> (finished: cleanup, in 0.18 seconds) post-build step Upload to niks3: ok time=2026-08-25T20:08:54.745Z level=INFO msg="Uploading 0 paths to niks3.clan.lol (1 already cached)" time=2026-08-25T20:08:55.127Z level=INFO msg="Uploading 1 narinfos" time=2026-08-25T20:08:55.272Z level=INFO msg="Upload complete. (596ms)"