these 50 derivations will be built: /nix/store/z4canbzsr3xkgdv34rczjn6kyvxjn3zx-system-path.drv /nix/store/l9a050lf20anh4c736syandjnsyza09s-dbus-1.drv /nix/store/mxs4wcvw4j40wvdk45488mv3y4j7l8nl-X-Restart-Triggers-dbus-broker.drv /nix/store/0dz7fz5wrk0lbfizxkbiwp8c4jll6xr6-unit-dbus-broker.service.drv /nix/store/27dkpv1f96zs41q1h8gldnm15agfq8l7-nginx.conf.drv /nix/store/cfr0lqw6jwgzhhqkgkikgqy8zx3ccc8b-X-Reload-Triggers-systemd-networkd.drv /nix/store/382fbgsrjgjailswigc9is5ps3hg1b2q-unit-systemd-networkd.service.drv /nix/store/p82a94vpprwbv7n0lax51q8sn0j23kv1-extra-hosts.drv /nix/store/5vvain32v3whhzndkb2r6m6mx41lqzyg-hosts.drv /nix/store/807603xp8mv16mgg213n0i9iwajjs9lp-system-path.drv /nix/store/m8abqc4l40im36wi1k8kys22klll33qn-dbus-1.drv /nix/store/sflhz3ci1qrigjldg1qawmx8wzy33k99-X-Restart-Triggers-dbus-broker.drv /nix/store/hkiiga7vn1rh56avd8mah6adqfh3yihs-unit-dbus-broker.service.drv /nix/store/5x6cifk325wp0p9w7h73w6q9wyf46k0v-user-units.drv /nix/store/dardgpy7693vy4kd1qmmqcqzifia1rav-nginx.conf.drv /nix/store/hsb145w9p41mb1381ks35vay1cvyib6q-firewall-start.drv /nix/store/sslm3kg3w2w4xv3nd78aippqkvj0sqs8-firewall-stop.drv /nix/store/4rcjblqa8g96816j0093i519jihjx27r-firewall-reload.drv /nix/store/hzfvbyc0bqi0c4kc3q6010nnrj58815z-unit-firewall.service.drv /nix/store/dxla9x9xkhvixvnd0ym6dv4adlr4b6vx-unit-script-setup-wg0-interface-start.drv /nix/store/najx12xkv2y5s41xrxarxamrzi4sbfd2-unit-setup-wg0-interface.service.drv /nix/store/f6jd5wm82zdn4k7i20kb30qc150qbshf-unit-script-nginx-pre-start.drv /nix/store/qf2ba1vrzibf05x4mfl1lwl0gjgf1w59-unit-nginx.service.drv /nix/store/x5qkgv4966gw4dfppfa88j22p5fkgkr9-unit-dbus-broker.service.drv /nix/store/y3gq5rny2pbgzv3q7n6bq4ab4arxlfz7-system-units.drv /nix/store/46iqddq9izj7890djgnvykj3yz06ljmz-etc.drv /nix/store/4g3s4k48bb6jpmgi8lhj97x6bvbg12ar-unit-script-nginx-pre-start.drv /nix/store/rgb6l4nnwr51dk0shr3khdgxy3daygr0-users-groups.json.drv /nix/store/jzpprx9c5l1x22f58sxsw3d5zzksqc1i-activate.drv /nix/store/waxjpxcvg7265qzdbv2h0s7xs2cqc72a-dry-activate.drv /nix/store/lxwa6dg7hazbaswcjkspn1gmw06c3fq7-nixos-system-machine-test.drv /nix/store/4rf7xnz4n62rgb8fkfwadl9cy5rq61jx-run-machine-nspawn.drv /nix/store/7h92jlxw2wz02q0hjcsa4fylj9v2cn6j-string-hosts.drv /nix/store/5nzx4g4l4sb653wz32jspybks6gp1cq3-hosts.drv /nix/store/d4v05yyasjs136dwnjw9dg6w1v9wmybp-etc-hostname.drv /nix/store/w8sbnv1hqdjv388w1akx70v1nd44klaw-user-units.drv /nix/store/6x9mvjfxkpapr9ss2ld08hilbpw4lapy-unit-nginx.service.drv /nix/store/gz7pqmzzprvz2c8xif4wn13azyg7lhf3-unit-systemd-networkd-wait-online.service.drv /nix/store/wv7bcxh7w7kmmxj3a218r0mkym39qi6j-unit-dbus-broker.service.drv /nix/store/wbrir5ga35148j8sxmpk5gci7si3gqn8-system-units.drv /nix/store/6xv0kwiky2wrp2wdp53m0ljjqq4l4w51-etc.drv /nix/store/7x2b650rl8mprxfygk4m8zlfmkh4yd3f-users-groups.json.drv /nix/store/b3avn16lam8w9x2arwqsa5v7mj3zfd7b-dry-activate.drv /nix/store/f0qb0jdxzq0dq64wbw5ys6lzl5ba6hfg-activate.drv /nix/store/6qg0diii18lhx47lf67d95i4z90v76yw-nixos-system-router-test.drv /nix/store/bhhrff7zysl1bcc9bvv4in2mbcmak6yh-test-script.drv /nix/store/j4irsqa37cvwzzl2laic626bq47b7mi8-run-router-nspawn.drv /nix/store/pivzg087ai6mj5v1sxvyh8wgzbs922mm-driverConfiguration.json.drv /nix/store/l18bzd9dcyjm6m0yrnk8k6qkr2gxyzac-nixos-test-driver-user-firewall-iptables.drv /nix/store/z3glnpm327m3452m26fdv8w9rs667p18-container-test-run-user-firewall-iptables.drv building '/nix/store/bhhrff7zysl1bcc9bvv4in2mbcmak6yh-test-script.drv' building '/nix/store/807603xp8mv16mgg213n0i9iwajjs9lp-system-path.drv' building '/nix/store/z4canbzsr3xkgdv34rczjn6kyvxjn3zx-system-path.drv' building '/nix/store/d4v05yyasjs136dwnjw9dg6w1v9wmybp-etc-hostname.drv' building '/nix/store/27dkpv1f96zs41q1h8gldnm15agfq8l7-nginx.conf.drv' building '/nix/store/dardgpy7693vy4kd1qmmqcqzifia1rav-nginx.conf.drv' building '/nix/store/p82a94vpprwbv7n0lax51q8sn0j23kv1-extra-hosts.drv' building '/nix/store/7h92jlxw2wz02q0hjcsa4fylj9v2cn6j-string-hosts.drv' building '/nix/store/gz7pqmzzprvz2c8xif4wn13azyg7lhf3-unit-systemd-networkd-wait-online.service.drv' building '/nix/store/cfr0lqw6jwgzhhqkgkikgqy8zx3ccc8b-X-Reload-Triggers-systemd-networkd.drv' nginx.conf> structuredAttrs is enabled nginx.conf> structuredAttrs is enabled system-path> structuredAttrs is enabled system-path> created 1660 symlinks in user environment system-path> structuredAttrs is enabled system-path> created 1566 symlinks in user environment unit-systemd-networkd-wait-online.service> structuredAttrs is enabled building '/nix/store/hsb145w9p41mb1381ks35vay1cvyib6q-firewall-start.drv' building '/nix/store/dxla9x9xkhvixvnd0ym6dv4adlr4b6vx-unit-script-setup-wg0-interface-start.drv' building '/nix/store/sslm3kg3w2w4xv3nd78aippqkvj0sqs8-firewall-stop.drv' building '/nix/store/5nzx4g4l4sb653wz32jspybks6gp1cq3-hosts.drv' building '/nix/store/5vvain32v3whhzndkb2r6m6mx41lqzyg-hosts.drv' building '/nix/store/l9a050lf20anh4c736syandjnsyza09s-dbus-1.drv' building '/nix/store/m8abqc4l40im36wi1k8kys22klll33qn-dbus-1.drv' building '/nix/store/najx12xkv2y5s41xrxarxamrzi4sbfd2-unit-setup-wg0-interface.service.drv' building '/nix/store/382fbgsrjgjailswigc9is5ps3hg1b2q-unit-systemd-networkd.service.drv' building '/nix/store/7x2b650rl8mprxfygk4m8zlfmkh4yd3f-users-groups.json.drv' nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> unit-setup-wg0-interface.service> structuredAttrs is enabled unit-systemd-networkd.service> structuredAttrs is enabled building '/nix/store/rgb6l4nnwr51dk0shr3khdgxy3daygr0-users-groups.json.drv' building '/nix/store/mxs4wcvw4j40wvdk45488mv3y4j7l8nl-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/sflhz3ci1qrigjldg1qawmx8wzy33k99-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/4rcjblqa8g96816j0093i519jihjx27r-firewall-reload.drv' building '/nix/store/b3avn16lam8w9x2arwqsa5v7mj3zfd7b-dry-activate.drv' building '/nix/store/4g3s4k48bb6jpmgi8lhj97x6bvbg12ar-unit-script-nginx-pre-start.drv' building '/nix/store/f6jd5wm82zdn4k7i20kb30qc150qbshf-unit-script-nginx-pre-start.drv' building '/nix/store/waxjpxcvg7265qzdbv2h0s7xs2cqc72a-dry-activate.drv' building '/nix/store/0dz7fz5wrk0lbfizxkbiwp8c4jll6xr6-unit-dbus-broker.service.drv' building '/nix/store/hkiiga7vn1rh56avd8mah6adqfh3yihs-unit-dbus-broker.service.drv' building '/nix/store/wv7bcxh7w7kmmxj3a218r0mkym39qi6j-unit-dbus-broker.service.drv' building '/nix/store/x5qkgv4966gw4dfppfa88j22p5fkgkr9-unit-dbus-broker.service.drv' building '/nix/store/hzfvbyc0bqi0c4kc3q6010nnrj58815z-unit-firewall.service.drv' unit-dbus-broker.service> structuredAttrs is enabled unit-dbus-broker.service> structuredAttrs is enabled unit-dbus-broker.service> structuredAttrs is enabled unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/6x9mvjfxkpapr9ss2ld08hilbpw4lapy-unit-nginx.service.drv' building '/nix/store/qf2ba1vrzibf05x4mfl1lwl0gjgf1w59-unit-nginx.service.drv' unit-firewall.service> structuredAttrs is enabled unit-nginx.service> structuredAttrs is enabled building '/nix/store/5x6cifk325wp0p9w7h73w6q9wyf46k0v-user-units.drv' building '/nix/store/w8sbnv1hqdjv388w1akx70v1nd44klaw-user-units.drv' unit-nginx.service> structuredAttrs is enabled building '/nix/store/wbrir5ga35148j8sxmpk5gci7si3gqn8-system-units.drv' building '/nix/store/y3gq5rny2pbgzv3q7n6bq4ab4arxlfz7-system-units.drv' building '/nix/store/6xv0kwiky2wrp2wdp53m0ljjqq4l4w51-etc.drv' building '/nix/store/46iqddq9izj7890djgnvykj3yz06ljmz-etc.drv' building '/nix/store/f0qb0jdxzq0dq64wbw5ys6lzl5ba6hfg-activate.drv' building '/nix/store/jzpprx9c5l1x22f58sxsw3d5zzksqc1i-activate.drv' building '/nix/store/6qg0diii18lhx47lf67d95i4z90v76yw-nixos-system-router-test.drv' building '/nix/store/lxwa6dg7hazbaswcjkspn1gmw06c3fq7-nixos-system-machine-test.drv' nixos-system-router-test> structuredAttrs is enabled building '/nix/store/j4irsqa37cvwzzl2laic626bq47b7mi8-run-router-nspawn.drv' nixos-system-machine-test> structuredAttrs is enabled building '/nix/store/4rf7xnz4n62rgb8fkfwadl9cy5rq61jx-run-machine-nspawn.drv' building '/nix/store/pivzg087ai6mj5v1sxvyh8wgzbs922mm-driverConfiguration.json.drv' driverConfiguration.json> structuredAttrs is enabled building '/nix/store/l18bzd9dcyjm6m0yrnk8k6qkr2gxyzac-nixos-test-driver-user-firewall-iptables.drv' nixos-test-driver-user-firewall-iptables> Running type check (enable/disable: config.skipTypeCheck) nixos-test-driver-user-firewall-iptables> See https://nixos.org/manual/nixos/stable/#test-opt-skipTypeCheck nixos-test-driver-user-firewall-iptables> All checks passed! nixos-test-driver-user-firewall-iptables> Linting test script (enable/disable: config.skipLint) nixos-test-driver-user-firewall-iptables> See https://nixos.org/manual/nixos/stable/#test-opt-skipLint nixos-test-driver-user-firewall-iptables> All checks passed! building '/nix/store/z3glnpm327m3452m26fdv8w9rs667p18-container-test-run-user-firewall-iptables.drv' on 'ssh-ng://builder@build-x86-01.clan.lol' building '/nix/store/z3glnpm327m3452m26fdv8w9rs667p18-container-test-run-user-firewall-iptables.drv' container-test-run-user-firewall-iptables> Machine state will be reset. To keep it, pass --keep-machine-state container-test-run-user-firewall-iptables> start all VLans container-test-run-user-firewall-iptables> (finished: start all VLans, in 0.00 seconds) container-test-run-user-firewall-iptables> container-test-run-user-firewall-iptables> Test will time out and terminate in 3600.0 seconds container-test-run-user-firewall-iptables> run the VM test script container-test-run-user-firewall-iptables> additionally exposed symbols: container-test-run-user-firewall-iptables> machine, router, container-test-run-user-firewall-iptables> vlan1, container-test-run-user-firewall-iptables> start_all, test_script, machines, machines_qemu, machines_nspawn, vlans, driver, log, os, create_machine, subtest, run_tests, join_all, retry, serial_stdout_off, serial_stdout_on, polling_condition, BaseMachine, QemuMachine, NspawnMachine, t, debug, dump_machine_ssh container-test-run-user-firewall-iptables> start all VMs container-test-run-user-firewall-iptables> machine: systemd-nspawn running (pid 52) container-test-run-user-firewall-iptables> router: systemd-nspawn running (pid 53) container-test-run-user-firewall-iptables> machine: Waiting for journal at /build/vm-state-machine/var/log/journal... container-test-run-user-firewall-iptables> router: Waiting for journal at /build/vm-state-router/var/log/journal... container-test-run-user-firewall-iptables> (finished: start all VMs, in 0.00 seconds) container-test-run-user-firewall-iptables> router: waiting for unit multi-user.target container-test-run-user-firewall-iptables> nixos-nspawn(router): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-user-firewall-iptables> nixos-nspawn(router): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-user-firewall-iptables> nixos-nspawn(machine): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-user-firewall-iptables> nixos-nspawn(machine): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-user-firewall-iptables> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-user-firewall-iptables> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-user-firewall-iptables> ░ Spawning container router on /build/vm-state-router. container-test-run-user-firewall-iptables> ░ Spawning container machine on /build/vm-state-machine. container-test-run-user-firewall-iptables> router # [7812195.961989] router systemd-journald[54]: Journal started container-test-run-user-firewall-iptables> machine # [7812195.948178] machine systemd-journald[54]: Journal started container-test-run-user-firewall-iptables> router # [7812195.962028] router systemd-journald[54]: Runtime Journal (/run/log/journal/cd7816bfb911485289a869858f6764fe) is 8M, max 3.7G, 3.7G free. container-test-run-user-firewall-iptables> machine # [7812195.948207] machine systemd-journald[54]: Runtime Journal (/run/log/journal/6d773c779ef3434f9ff8278872285b2d) is 8M, max 3.7G, 3.7G free. container-test-run-user-firewall-iptables> router # [7812196.006069] router systemd[1]: Finished Apply Kernel Variables. container-test-run-user-firewall-iptables> machine # [7812196.006029] machine systemd[1]: Finished Apply Kernel Variables. container-test-run-user-firewall-iptables> router # [7812196.030243] router systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-user-firewall-iptables> machine # [7812196.030271] machine systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-user-firewall-iptables> router # [7812196.038768] router systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-user-firewall-iptables> machine # [7812196.037981] machine systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-user-firewall-iptables> router # [7812196.039332] router systemd[1]: Starting Network Name Resolution... container-test-run-user-firewall-iptables> machine # [7812196.038400] machine systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-user-firewall-iptables> router # [7812196.039717] router systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-user-firewall-iptables> machine # [7812196.059506] machine systemd-journald[54]: Time spent on flushing to /var/log/journal/6d773c779ef3434f9ff8278872285b2d is 1.100ms for 6 entries. container-test-run-user-firewall-iptables> router # [7812196.061182] router systemd-journald[54]: Time spent on flushing to /var/log/journal/cd7816bfb911485289a869858f6764fe is 1.024ms for 7 entries. container-test-run-user-firewall-iptables> machine # [7812196.059506] machine systemd-journald[54]: System Journal (/var/log/journal/6d773c779ef3434f9ff8278872285b2d) is 8M, max 4G, 3.9G free. container-test-run-user-firewall-iptables> router # [7812196.061182] router systemd-journald[54]: System Journal (/var/log/journal/cd7816bfb911485289a869858f6764fe) is 8M, max 4G, 3.9G free. container-test-run-user-firewall-iptables> machine # [7812196.118544] machine systemd[1]: Finished Firewall. container-test-run-user-firewall-iptables> router # [7812196.118543] router systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-user-firewall-iptables> machine # [7812196.118660] machine systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-user-firewall-iptables> router # [7812196.118839] router systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-user-firewall-iptables> machine # [7812196.118959] machine systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-user-firewall-iptables> router # [7812196.119564] router systemd[1]: Reached target Preparation for Local File Systems. container-test-run-user-firewall-iptables> machine # [7812196.120760] machine systemd[1]: Reached target Preparation for Local File Systems. container-test-run-user-firewall-iptables> router # [7812196.119642] router systemd[1]: Reached target Local File Systems. container-test-run-user-firewall-iptables> machine # [7812196.120827] machine systemd[1]: Reached target Local File Systems. container-test-run-user-firewall-iptables> router # [7812196.120288] router systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-user-firewall-iptables> machine # [7812196.120878] machine systemd[1]: Reached target Preparation for Network. container-test-run-user-firewall-iptables> router # [7812196.120326] router systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-user-firewall-iptables> machine # [7812196.121469] machine systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-user-firewall-iptables> router # [7812196.120950] router systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-user-firewall-iptables> machine # [7812196.121511] machine systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-user-firewall-iptables> router # [7812196.121358] router systemd[1]: Starting Create System Files and Directories... container-test-run-user-firewall-iptables> machine # [7812196.122108] machine systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-user-firewall-iptables> router # [7812196.121376] router systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-user-firewall-iptables> machine # [7812196.122469] machine systemd[1]: Starting Create System Files and Directories... container-test-run-user-firewall-iptables> router # [7812196.121986] router systemd[1]: Starting Network Management... container-test-run-user-firewall-iptables> machine # [7812196.122488] machine systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-user-firewall-iptables> router # [7812196.135892] router systemd-tmpfiles[68]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-user-firewall-iptables> machine # [7812196.134750] machine systemd-tmpfiles[197]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-user-firewall-iptables> router # [7812196.136109] router systemd-tmpfiles[68]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-user-firewall-iptables> machine # [7812196.134912] machine systemd-tmpfiles[197]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-user-firewall-iptables> machine # [7812196.135023] machine systemd-tmpfiles[197]: fchmod() of /var/log/journal/6d773c779ef3434f9ff8278872285b2d failed: Operation not permitted container-test-run-user-firewall-iptables> machine # [7812196.135189] machine systemd-tmpfiles[197]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-user-firewall-iptables> machine # [7812196.136725] machine systemd[1]: Finished Create System Files and Directories. container-test-run-user-firewall-iptables> machine # [7812196.137230] machine systemd[1]: Starting Rebuild Journal Catalog... container-test-run-user-firewall-iptables> machine # [7812196.137609] machine systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-user-firewall-iptables> machine # [7812196.145582] machine systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-user-firewall-iptables> machine # [7812196.152314] machine systemd[1]: Finished Rebuild Journal Catalog. container-test-run-user-firewall-iptables> machine # [7812196.153148] machine systemd[1]: Starting Update is Completed... container-test-run-user-firewall-iptables> machine # [7812196.160223] machine systemd[1]: Finished Update is Completed. container-test-run-user-firewall-iptables> machine # [7812196.160347] machine systemd[1]: Reached target System Initialization. container-test-run-user-firewall-iptables> machine # [7812196.160409] machine systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-user-firewall-iptables> machine # [7812196.160432] machine systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-user-firewall-iptables> machine # [7812196.160447] machine systemd[1]: Reached target Timer Units. container-test-run-user-firewall-iptables> machine # [7812196.160525] machine systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-user-firewall-iptables> machine # [7812196.160609] machine systemd[1]: Listening on Nix Daemon Socket. container-test-run-user-firewall-iptables> machine # [7812196.160697] machine systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-user-firewall-iptables> machine # [7812196.160711] machine systemd[1]: Reached target Socket Units. container-test-run-user-firewall-iptables> machine # [7812196.160732] machine systemd[1]: Reached target Basic System. container-test-run-user-firewall-iptables> machine # [7812196.161396] machine systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-user-firewall-iptables> machine # [7812196.161833] machine systemd[1]: Starting Address configuration of eth1... container-test-run-user-firewall-iptables> machine # [7812196.162758] machine systemd[1]: Starting Extra networking commands.... container-test-run-user-firewall-iptables> machine # [7812196.163431] machine systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-user-firewall-iptables> machine # [7812196.163966] machine systemd[1]: Starting Setup wg0 dummy interface... container-test-run-user-firewall-iptables> machine # [7812196.173441] machine network-addresses-eth1-start[206]: adding address 192.168.1.1/24... done container-test-run-user-firewall-iptables> machine # [7812196.173925] machine systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-user-firewall-iptables> machine # [7812196.175080] machine network-addresses-eth1-start[206]: adding address 2001:db8:1::1/64... done container-test-run-user-firewall-iptables> machine # [7812196.176624] machine systemd[1]: Finished Setup wg0 dummy interface. container-test-run-user-firewall-iptables> machine # [7812196.177801] machine systemd[1]: Finished Address configuration of eth1. container-test-run-user-firewall-iptables> machine # [7812196.198598] machine systemd[1]: nscd.service: Deactivated successfully. container-test-run-user-firewall-iptables> machine # [7812196.198745] machine systemd[1]: Stopped Name Service Cache Daemon (nsncd). container-test-run-user-firewall-iptables> machine # [7812196.200254] machine systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-user-firewall-iptables> machine # [7812196.223226] machine systemd[1]: Finished Extra networking commands.. container-test-run-user-firewall-iptables> machine # [7812196.223438] machine systemd[1]: Reached target Network. container-test-run-user-firewall-iptables> machine # [7812196.224171] machine systemd[1]: Starting Nginx Web Server... container-test-run-user-firewall-iptables> machine # [7812196.305026] machine systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-user-firewall-iptables> router # [7812196.136260] router systemd-tmpfiles[68]: fchmod() of /var/log/journal/cd7816bfb911485289a869858f6764fe failed: Operation not permitted container-test-run-user-firewall-iptables> router # [7812196.136478] router systemd-tmpfiles[68]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-user-firewall-iptables> router # [7812196.142734] router systemd[1]: Finished Create System Files and Directories. container-test-run-user-firewall-iptables> router # [7812196.143633] router systemd[1]: Starting Rebuild Journal Catalog... container-test-run-user-firewall-iptables> router # [7812196.144283] router systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-user-firewall-iptables> router # [7812196.153396] router systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-user-firewall-iptables> router # [7812196.159503] router systemd[1]: Finished Rebuild Journal Catalog. container-test-run-user-firewall-iptables> router # [7812196.160336] router systemd[1]: systemd-update-done.service: Failed to spawn executor: No such file or directory container-test-run-user-firewall-iptables> router # [7812196.160353] router systemd[1]: systemd-update-done.service: Failed to spawn 'start' task: No such file or directory container-test-run-user-firewall-iptables> router # [7812196.160388] router systemd[1]: systemd-update-done.service: Failed with result 'resources'. container-test-run-user-firewall-iptables> router # [7812196.160430] router systemd[1]: Failed to start Update is Completed. container-test-run-user-firewall-iptables> router # [7812196.304579] router systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-user-firewall-iptables> router # [7812197.008745] router systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-user-firewall-iptables> machine # [7812197.006501] machine systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-user-firewall-iptables> machine # [7812197.177274] machine nsncd[280]: Aug 29 20:04:14.542 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-user-firewall-iptables> machine # [7812197.177376] machine systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-user-firewall-iptables> machine # [7812197.177426] machine systemd[1]: Reached target Host and Network Name Lookups. container-test-run-user-firewall-iptables> machine # [7812197.177459] machine systemd[1]: Reached target User and Group Name Lookups. container-test-run-user-firewall-iptables> machine # [7812197.178495] machine systemd[1]: Starting User Login Management... container-test-run-user-firewall-iptables> machine # [7812197.178910] machine systemd[1]: Starting Permit User Sessions... container-test-run-user-firewall-iptables> machine # [7812197.185591] machine systemd[1]: Finished Permit User Sessions. container-test-run-user-firewall-iptables> machine # [7812197.186230] machine systemd[1]: Started Console Getty. container-test-run-user-firewall-iptables> machine # [7812197.186252] machine systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-user-firewall-iptables> machine # [7812197.186263] machine systemd[1]: Reached target Login Prompts. container-test-run-user-firewall-iptables> router # [7812199.364494] router systemd-networkd[69]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-user-firewall-iptables> router # [7812199.364604] router systemd-networkd[69]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-user-firewall-iptables> router # [7812199.376468] router systemd-networkd[69]: lo: Link UP container-test-run-user-firewall-iptables> router # [7812199.376476] router systemd-networkd[69]: lo: Gained carrier container-test-run-user-firewall-iptables> router # [7812199.376672] router systemd-networkd[69]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-user-firewall-iptables> router # [7812199.377089] router systemd[1]: Started Network Management. container-test-run-user-firewall-iptables> router # [7812199.377181] router systemd-networkd[69]: eth1: Link UP container-test-run-user-firewall-iptables> router # [7812199.377378] router systemd-networkd[69]: eth1: Gained carrier container-test-run-user-firewall-iptables> router # [7812199.378634] router systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-user-firewall-iptables> router # [7812199.407602] router systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-user-firewall-iptables> machine # [7812199.581025] machine nginx-pre-start[309]: nginx: the configuration file /nix/store/pn78ibz0jl5fciqc1jh9cq8k3m729427-nginx.conf syntax is ok container-test-run-user-firewall-iptables> machine # [7812199.581025] machine nginx-pre-start[309]: nginx: configuration file /nix/store/pn78ibz0jl5fciqc1jh9cq8k3m729427-nginx.conf test is successful container-test-run-user-firewall-iptables> machine # [7812199.584486] machine systemd[1]: Started Nginx Web Server. container-test-run-user-firewall-iptables> machine # [7812200.109041] machine systemd-logind[299]: New seat seat0. container-test-run-user-firewall-iptables> machine # [7812200.109276] machine systemd[1]: Started User Login Management. container-test-run-user-firewall-iptables> machine # [7812200.110739] machine systemd[1]: Starting D-Bus System Message Bus... container-test-run-user-firewall-iptables> machine # [7812200.111417] machine systemd[1]: Starting linger-users.service... container-test-run-user-firewall-iptables> machine # [7812200.157010] machine systemd[1]: linger-users.service: Deactivated successfully. container-test-run-user-firewall-iptables> machine # [7812200.157197] machine systemd[1]: Finished linger-users.service. container-test-run-user-firewall-iptables> machine # [7812200.157356] machine systemd[1]: Reached target Multi-User System. container-test-run-user-firewall-iptables> router # [7812200.765114] router systemd-networkd[69]: eth1: Gained IPv6LL container-test-run-user-firewall-iptables> router # [7812201.316505] router systemd-resolved[61]: Positive Trust Anchors: container-test-run-user-firewall-iptables> router # [7812201.316516] router systemd-resolved[61]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-user-firewall-iptables> router # [7812201.316520] router systemd-resolved[61]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-user-firewall-iptables> router # [7812201.316547] router systemd-resolved[61]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-user-firewall-iptables> router # [7812201.332806] router systemd-resolved[61]: Using system hostname 'router'. container-test-run-user-firewall-iptables> router # [7812201.333955] router systemd[1]: Started Network Name Resolution. container-test-run-user-firewall-iptables> router # [7812201.334025] router systemd[1]: Reached target Network. container-test-run-user-firewall-iptables> router # [7812201.334071] router systemd[1]: Reached target System Initialization. container-test-run-user-firewall-iptables> router # [7812201.334103] router systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-user-firewall-iptables> router # [7812201.334125] router systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-user-firewall-iptables> router # [7812201.334135] router systemd[1]: Reached target Timer Units. container-test-run-user-firewall-iptables> router # [7812201.334228] router systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-user-firewall-iptables> router # [7812201.334300] router systemd[1]: Listening on Nix Daemon Socket. container-test-run-user-firewall-iptables> router # [7812201.334374] router systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-user-firewall-iptables> router # [7812201.334385] router systemd[1]: Reached target Socket Units. container-test-run-user-firewall-iptables> router # [7812201.334408] router systemd[1]: Reached target Basic System. container-test-run-user-firewall-iptables> router # [7812201.335143] router systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-user-firewall-iptables> router # [7812201.335799] router systemd[1]: Starting Nginx Web Server... container-test-run-user-firewall-iptables> router # [7812201.336366] router systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-user-firewall-iptables> router # [7812201.338977] router systemd[1]: Starting D-Bus System Message Bus... container-test-run-user-firewall-iptables> router # [7812201.359220] router systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-user-firewall-iptables> machine # [7812201.157598] machine dbus-broker-launch[315]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-user-firewall-iptables> machine # [7812201.158088] machine dbus-broker-launch[315]: NSS returned no entry for 'systemd-timesync' container-test-run-user-firewall-iptables> machine # [7812201.158088] machine dbus-broker-launch[315]: Invalid user-name in /nix/store/4kx1hyx2iymh1pcsxj6mkbqjvgm466m7-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-user-firewall-iptables> machine # [7812201.158422] machine systemd[1]: Started D-Bus System Message Bus. container-test-run-user-firewall-iptables> machine # [7812201.158642] machine systemd[1]: Startup finished in 5.511s. container-test-run-user-firewall-iptables> machine # [7812201.162695] machine dbus-broker-launch[315]: Ready container-test-run-user-firewall-iptables> router # [7812201.621369] router nsncd[82]: Aug 29 20:04:18.987 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-user-firewall-iptables> router # [7812201.621537] router systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-user-firewall-iptables> router # [7812201.621611] router systemd[1]: Reached target Host and Network Name Lookups. container-test-run-user-firewall-iptables> router # [7812201.621667] router systemd[1]: Reached target User and Group Name Lookups. container-test-run-user-firewall-iptables> router # [7812201.622795] router systemd[1]: Starting User Login Management... container-test-run-user-firewall-iptables> router # [7812201.623589] router systemd[1]: Starting Permit User Sessions... container-test-run-user-firewall-iptables> router # [7812201.646274] router systemd[1]: Finished Permit User Sessions. container-test-run-user-firewall-iptables> router # [7812201.647959] router systemd[1]: Started Console Getty. container-test-run-user-firewall-iptables> router # [7812201.648311] router systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-user-firewall-iptables> router # [7812201.648331] router systemd[1]: Reached target Login Prompts. container-test-run-user-firewall-iptables> router # [7812201.801664] router dbus-broker-launch[83]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-user-firewall-iptables> router # [7812201.803017] router dbus-broker-launch[83]: NSS returned no entry for 'systemd-timesync' container-test-run-user-firewall-iptables> router # [7812201.803017] router dbus-broker-launch[83]: Invalid user-name in /nix/store/xjqr1rr6dvby76rk5bqpdpxpi2kcc01c-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-user-firewall-iptables> router # [7812201.803124] router systemd[1]: Started D-Bus System Message Bus. container-test-run-user-firewall-iptables> router # [7812201.808070] router dbus-broker-launch[83]: Ready container-test-run-user-firewall-iptables> router # [7812202.466320] router nginx-pre-start[112]: nginx: the configuration file /nix/store/0v75lyzd1xza7xgrwxmaakdh2509cqgb-nginx.conf syntax is ok container-test-run-user-firewall-iptables> router # [7812202.466638] router nginx-pre-start[112]: nginx: configuration file /nix/store/0v75lyzd1xza7xgrwxmaakdh2509cqgb-nginx.conf test is successful container-test-run-user-firewall-iptables> router # [7812202.471277] router systemd[1]: Started Nginx Web Server. container-test-run-user-firewall-iptables> router # [7812202.597792] router systemd-logind[101]: New seat seat0. container-test-run-user-firewall-iptables> router # [7812202.597999] router systemd[1]: Started User Login Management. container-test-run-user-firewall-iptables> router # [7812202.599102] router systemd[1]: Starting linger-users.service... container-test-run-user-firewall-iptables> router # [7812202.629460] router systemd[1]: linger-users.service: Deactivated successfully. container-test-run-user-firewall-iptables> router # [7812202.629655] router systemd[1]: Finished linger-users.service. container-test-run-user-firewall-iptables> router # [7812202.630064] router systemd[1]: Reached target Multi-User System. container-test-run-user-firewall-iptables> router # [7812202.630460] router systemd[1]: Startup finished in 6.982s. container-test-run-user-firewall-iptables> router: (finished: waiting for unit multi-user.target, in 7.65 seconds) container-test-run-user-firewall-iptables> router: waiting for unit nginx.service container-test-run-user-firewall-iptables> router: (finished: waiting for unit nginx.service, in 0.01 seconds) container-test-run-user-firewall-iptables> machine: waiting for unit multi-user.target container-test-run-user-firewall-iptables> machine: (finished: waiting for unit multi-user.target, in 0.01 seconds) container-test-run-user-firewall-iptables> machine: waiting for unit nginx.service container-test-run-user-firewall-iptables> machine: (finished: waiting for unit nginx.service, in 0.01 seconds) container-test-run-user-firewall-iptables> router: must succeed: ip -4 addr show eth1 | grep -oP '(?<=inet\s)\d+(\.\d+){3}' container-test-run-user-firewall-iptables> router: (finished: must succeed: ip -4 addr show eth1 | grep -oP '(?<=inet\s)\d+(\.\d+){3}', in 0.01 seconds) container-test-run-user-firewall-iptables> router: must succeed: ip -6 addr show eth1 | grep -oP '(?<=inet6\s)[0-9a-f:]+' | grep -v '^fe80' | head -1 container-test-run-user-firewall-iptables> router: (finished: must succeed: ip -6 addr show eth1 | grep -oP '(?<=inet6\s)[0-9a-f:]+' | grep -v '^fe80' | head -1, in 0.01 seconds) container-test-run-user-firewall-iptables> Router IPv4: 192.168.1.2 container-test-run-user-firewall-iptables> Router IPv6: 2001:db8:1::2 container-test-run-user-firewall-iptables> machine: must succeed: systemctl restart firewall container-test-run-user-firewall-iptables> machine # [7812202.996395] machine systemd[1]: Stopping Firewall... container-test-run-user-firewall-iptables> machine # [7812203.180542] machine systemd[1]: firewall.service: Deactivated successfully. container-test-run-user-firewall-iptables> machine # [7812203.180720] machine systemd[1]: Stopped Firewall. container-test-run-user-firewall-iptables> machine # [7812203.181918] machine systemd[1]: Starting Firewall... container-test-run-user-firewall-iptables> machine: (finished: must succeed: systemctl restart firewall, in 0.72 seconds) container-test-run-user-firewall-iptables> machine: waiting for unit firewall.service container-test-run-user-firewall-iptables> machine: (finished: waiting for unit firewall.service, in 0.01 seconds) container-test-run-user-firewall-iptables> machine: must succeed: iptables -L user-firewall-output >&2 container-test-run-user-firewall-iptables> Chain user-firewall-output (1 references) container-test-run-user-firewall-iptables> target prot opt source destination container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> REJECT all -- anywhere anywhere owner UID match bob reject-with icmp-port-unreachable container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> machine: (finished: must succeed: iptables -L user-firewall-output >&2, in 0.00 seconds) container-test-run-user-firewall-iptables> machine: waiting for success: runuser -u alice -- curl -s http://127.0.0.1:8080 container-test-run-user-firewall-iptables> machine: (finished: waiting for success: runuser -u alice -- curl -s http://127.0.0.1:8080, in 0.01 seconds) container-test-run-user-firewall-iptables> machine: must succeed: runuser -u alice -- curl -s http://192.168.1.2 container-test-run-user-firewall-iptables> machine: output: container-test-run-user-firewall-iptables> !!! Traceback (most recent call last): container-test-run-user-firewall-iptables> !!! File "", line 22, in container-test-run-user-firewall-iptables> !!! machine.succeed(f"runuser -u alice -- curl -s http://{router_ip}") container-test-run-user-firewall-iptables> !!! container-test-run-user-firewall-iptables> !!! RequestedAssertionFailed: command `runuser -u alice -- curl -s http://192.168.1.2` failed (exit code 7) container-test-run-user-firewall-iptables> cleanup container-test-run-user-firewall-iptables> kill NspawnMachine (pid 52) container-test-run-user-firewall-iptables> Container machine terminated by signal KILL. container-test-run-user-firewall-iptables> kill NspawnMachine (pid 53) container-test-run-user-firewall-iptables> Container router terminated by signal KILL. container-test-run-user-firewall-iptables> (finished: cleanup, in 0.23 seconds) error: path '/nix/store/gqhmwh4njc5v1r9xggbwfl2rn70bb614-container-test-run-user-firewall-iptables' is not valid error: Cannot build '/nix/store/z3glnpm327m3452m26fdv8w9rs667p18-container-test-run-user-firewall-iptables.drv'. Reason: builder failed with exit code 1. Output paths: /nix/store/gqhmwh4njc5v1r9xggbwfl2rn70bb614-container-test-run-user-firewall-iptables