these 46 derivations will be built: /nix/store/qsvfnkc9pck4hi5gahfp9zks6nlib8qr-system-path.drv /nix/store/y7vi6m3dyi1lpnk2kjcrixqg4mz23ir7-dbus-1.drv /nix/store/ddxasy5jnxv591xnxqpipw42bqaphm14-X-Restart-Triggers-dbus-broker.drv /nix/store/19zppvfs81wvbvhg32w3a47ibvis3frx-unit-dbus-broker.service.drv /nix/store/nv3x5mljzndvzglfm1l2rwdjkvhp0wsn-nginx.conf.drv /nix/store/7r6fmb4ncb6m83s9h1z26m7jngs7lw4n-unit-script-nginx-pre-start.drv /nix/store/i3wf7qc0dk5aqmdypbb0r99lr5gwww33-unit-nginx.service.drv /nix/store/0lipnmawl4901i04alnshjm7iggw3q8m-system-units.drv /nix/store/pb2dg79gh0iqiyql8fsgivg3wd30j5wq-unit-dbus-broker.service.drv /nix/store/1vip8xm1qac41wlba9ci9hhlq895h847-user-units.drv /nix/store/g4x6jm606g0mgskbd2j304y4wr6zncaa-system-path.drv /nix/store/mm4zq7qvx1g1j16w5s7cvgmjmlcb0h9g-dbus-1.drv /nix/store/6kaj527q0inwr9yd4pg26dsyix4lnbk6-X-Restart-Triggers-dbus-broker.drv /nix/store/2by9nz7zf73kmnc5iil6i7h2sy9ypdjz-unit-dbus-broker.service.drv /nix/store/5a02pcyq2yzqbvfnjq7vjxvfribakfj1-unit-script-setup-wg0-interface-start.drv /nix/store/3ar2idh74f0b72a25rgmz2wz44ydw8dd-unit-setup-wg0-interface.service.drv /nix/store/3hf99ky5vhim3yhz1dg5cndssb710rdz-users-groups.json.drv /nix/store/n3y4jhcdv2sz0n0j63dvpnnwgl2hs7pc-unit-dbus-broker.service.drv /nix/store/jd31akaskgkkiyd2h7jd59g7wslxyzgn-firewall-stop.drv /nix/store/wff4rm0bp4a5baa0ab1scwr7pf7m7c9n-firewall-start.drv /nix/store/f2nf9acghlckkkzq7cwjmanxc0vfb2qx-firewall-reload.drv /nix/store/w1zw9mwsby3xdxkkvxbgqyv9p1bdxzq1-unit-firewall.service.drv /nix/store/dqvsjibh6ll9i19nbh6avfjipjrb9pbh-nginx.conf.drv /nix/store/85jbsmc7qkxhxs5kwxkqfbi409i3hc24-unit-script-nginx-pre-start.drv /nix/store/w3p0iiy0ix7garmpgwrllfy7xv8fqpa7-unit-nginx.service.drv /nix/store/lxil0biyxk2rpp0lny991198qxbgpq7w-system-units.drv /nix/store/xsxpvvxaayws4h62pjkasajrmszmdb6h-extra-hosts.drv /nix/store/ysnsjf4phbcdw0s6rya3xgrjd7bahq09-hosts.drv /nix/store/zn65c47vjq6wj389g4y508car6wqz43f-user-units.drv /nix/store/6iy2hxhby3pl0d82wwvnsxvdzklrmpgr-etc.drv /nix/store/pmjnkha7rah5sc44a7rhq612abp21h9l-users-groups.json.drv /nix/store/3m3a111kvzrcf21zqphlm301lqmmih31-activate.drv /nix/store/czk914n3z4bwbsb4wngbhazgwqy4rj62-testScript.drv /nix/store/84ljdrnvaigq214q5zxzy6g1rwfplqkr-etc-hostname.drv /nix/store/dnpyr47pc3lrnhv8pycdna0xircsihb8-string-hosts.drv /nix/store/sb7g36yjbc354yqkrqchh7a50kx50hmq-hosts.drv /nix/store/syr47rvrv05rw5yllznspsfi4yxknm3p-etc.drv /nix/store/70j485c5c6cipflbi367dimajw1nl5pi-activate.drv /nix/store/xk2kbd8vr0h783zjfcjgha83i90fv6hn-dry-activate.drv /nix/store/s3jikp19gp41lhcfddvn4mj5pv5i8s6s-nixos-system-router-test.drv /nix/store/4wcndn5wijzp268lldqn8bg57wyf2zh2-closure-info.drv /nix/store/vmks18yw3n96mjjv5hqiy3zn6x0wccw9-dry-activate.drv /nix/store/j14c4j6jl1fa46is1n1fgwkzdq6xc4nc-nixos-system-machine-test.drv /nix/store/l2fjjjxpk5kq922bbkrc6amy43giqi75-closure-info.drv /nix/store/z4vgdhzy5zl2b79rv7angzyh81r5w9f6-nixos-test-driver-user-firewall-iptables.drv /nix/store/sh24fwlvhs48ah6z4zs4pl27k0qzvwmf-container-test-run-user-firewall-iptables.drv building '/nix/store/g4x6jm606g0mgskbd2j304y4wr6zncaa-system-path.drv' building '/nix/store/qsvfnkc9pck4hi5gahfp9zks6nlib8qr-system-path.drv' building '/nix/store/84ljdrnvaigq214q5zxzy6g1rwfplqkr-etc-hostname.drv' building '/nix/store/xsxpvvxaayws4h62pjkasajrmszmdb6h-extra-hosts.drv' building '/nix/store/dnpyr47pc3lrnhv8pycdna0xircsihb8-string-hosts.drv' building '/nix/store/wff4rm0bp4a5baa0ab1scwr7pf7m7c9n-firewall-start.drv' building '/nix/store/jd31akaskgkkiyd2h7jd59g7wslxyzgn-firewall-stop.drv' building '/nix/store/dqvsjibh6ll9i19nbh6avfjipjrb9pbh-nginx.conf.drv' building '/nix/store/nv3x5mljzndvzglfm1l2rwdjkvhp0wsn-nginx.conf.drv' building '/nix/store/5a02pcyq2yzqbvfnjq7vjxvfribakfj1-unit-script-setup-wg0-interface-start.drv' system-path> structuredAttrs is enabled system-path> created 1752 symlinks in user environment system-path> structuredAttrs is enabled system-path> created 1660 symlinks in user environment building '/nix/store/f2nf9acghlckkkzq7cwjmanxc0vfb2qx-firewall-reload.drv' building '/nix/store/sb7g36yjbc354yqkrqchh7a50kx50hmq-hosts.drv' building '/nix/store/ysnsjf4phbcdw0s6rya3xgrjd7bahq09-hosts.drv' building '/nix/store/mm4zq7qvx1g1j16w5s7cvgmjmlcb0h9g-dbus-1.drv' building '/nix/store/y7vi6m3dyi1lpnk2kjcrixqg4mz23ir7-dbus-1.drv' building '/nix/store/3ar2idh74f0b72a25rgmz2wz44ydw8dd-unit-setup-wg0-interface.service.drv' nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> building '/nix/store/6kaj527q0inwr9yd4pg26dsyix4lnbk6-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/w1zw9mwsby3xdxkkvxbgqyv9p1bdxzq1-unit-firewall.service.drv' building '/nix/store/czk914n3z4bwbsb4wngbhazgwqy4rj62-testScript.drv' building '/nix/store/3hf99ky5vhim3yhz1dg5cndssb710rdz-users-groups.json.drv' building '/nix/store/pmjnkha7rah5sc44a7rhq612abp21h9l-users-groups.json.drv' building '/nix/store/ddxasy5jnxv591xnxqpipw42bqaphm14-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/2by9nz7zf73kmnc5iil6i7h2sy9ypdjz-unit-dbus-broker.service.drv' building '/nix/store/n3y4jhcdv2sz0n0j63dvpnnwgl2hs7pc-unit-dbus-broker.service.drv' building '/nix/store/7r6fmb4ncb6m83s9h1z26m7jngs7lw4n-unit-script-nginx-pre-start.drv' building '/nix/store/85jbsmc7qkxhxs5kwxkqfbi409i3hc24-unit-script-nginx-pre-start.drv' building '/nix/store/vmks18yw3n96mjjv5hqiy3zn6x0wccw9-dry-activate.drv' building '/nix/store/xk2kbd8vr0h783zjfcjgha83i90fv6hn-dry-activate.drv' building '/nix/store/19zppvfs81wvbvhg32w3a47ibvis3frx-unit-dbus-broker.service.drv' building '/nix/store/pb2dg79gh0iqiyql8fsgivg3wd30j5wq-unit-dbus-broker.service.drv' building '/nix/store/zn65c47vjq6wj389g4y508car6wqz43f-user-units.drv' building '/nix/store/i3wf7qc0dk5aqmdypbb0r99lr5gwww33-unit-nginx.service.drv' building '/nix/store/w3p0iiy0ix7garmpgwrllfy7xv8fqpa7-unit-nginx.service.drv' building '/nix/store/1vip8xm1qac41wlba9ci9hhlq895h847-user-units.drv' building '/nix/store/0lipnmawl4901i04alnshjm7iggw3q8m-system-units.drv' building '/nix/store/lxil0biyxk2rpp0lny991198qxbgpq7w-system-units.drv' building '/nix/store/syr47rvrv05rw5yllznspsfi4yxknm3p-etc.drv' building '/nix/store/6iy2hxhby3pl0d82wwvnsxvdzklrmpgr-etc.drv' building '/nix/store/70j485c5c6cipflbi367dimajw1nl5pi-activate.drv' building '/nix/store/3m3a111kvzrcf21zqphlm301lqmmih31-activate.drv' building '/nix/store/s3jikp19gp41lhcfddvn4mj5pv5i8s6s-nixos-system-router-test.drv' building '/nix/store/j14c4j6jl1fa46is1n1fgwkzdq6xc4nc-nixos-system-machine-test.drv' nixos-system-router-test> structuredAttrs is enabled building '/nix/store/4wcndn5wijzp268lldqn8bg57wyf2zh2-closure-info.drv' nixos-system-machine-test> structuredAttrs is enabled building '/nix/store/l2fjjjxpk5kq922bbkrc6amy43giqi75-closure-info.drv' closure-info> structuredAttrs is enabled closure-info> structuredAttrs is enabled building '/nix/store/z4vgdhzy5zl2b79rv7angzyh81r5w9f6-nixos-test-driver-user-firewall-iptables.drv' nixos-test-driver-user-firewall-iptables> Running type check (enable/disable: config.skipTypeCheck) nixos-test-driver-user-firewall-iptables> See https://nixos.org/manual/nixos/stable/#test-opt-skipTypeCheck nixos-test-driver-user-firewall-iptables> Success: no issues found in 1 source file building '/nix/store/sh24fwlvhs48ah6z4zs4pl27k0qzvwmf-container-test-run-user-firewall-iptables.drv' on 'ssh-ng://builder@build-x86-01.clan.lol' building '/nix/store/sh24fwlvhs48ah6z4zs4pl27k0qzvwmf-container-test-run-user-firewall-iptables.drv' container-test-run-user-firewall-iptables> additionally exposed symbols: container-test-run-user-firewall-iptables> machine, router, container-test-run-user-firewall-iptables> start_all, machines, driver, Machine, wait_for_signal container-test-run-user-firewall-iptables> Starting machine container-test-run-user-firewall-iptables> Starting router container-test-run-user-firewall-iptables> container-test-run-user-firewall-iptables> container-test-run-user-firewall-iptables> container-test-run-user-firewall-iptables> <<< NixOS Stage 2 >>> container-test-run-user-firewall-iptables> container-test-run-user-firewall-iptables> booting system configuration /nix/store/b48vbsidrimsz89sf6lcj3afgwgb08pf-nixos-system-machine-test container-test-run-user-firewall-iptables> running activation script... container-test-run-user-firewall-iptables> setting up /etc... container-test-run-user-firewall-iptables> 2: host0@if4: mtu 1500 qdisc noop state DOWN mode DEFAULT group default qlen 1000 container-test-run-user-firewall-iptables> link/ether 0e:74:26:22:81:c2 brd ff:ff:ff:ff:ff:ff link-netnsid 0 container-test-run-user-firewall-iptables> starting systemd... container-test-run-user-firewall-iptables> systemd 260.2 running in system mode (+PAM +AUDIT -SELINUX +APPARMOR +IMA +IPE +SMACK +SECCOMP +GCRYPT -GNUTLS +OPENSSL +ACL +BLKID +CURL +ELFUTILS +FIDO2 +IDN2 +KMOD +LIBCRYPTSETUP +LIBCRYPTSETUP_PLUGINS +LIBFDISK +PCRE2 +PWQUALITY +P11KIT +QRENCODE +TPM2 +BZIP2 +LZ4 +XZ +ZLIB +ZSTD +BPF_FRAMEWORK -BTF -XKBCOMMON +UTMP +LIBARCHIVE) container-test-run-user-firewall-iptables> Detected virtualization systemd-nspawn. container-test-run-user-firewall-iptables> Detected architecture x86-64. container-test-run-user-firewall-iptables> Detected first boot. container-test-run-user-firewall-iptables> Initializing machine ID from container UUID. container-test-run-user-firewall-iptables> Applying preset policy. container-test-run-user-firewall-iptables> Populated /etc with preset unit settings. container-test-run-user-firewall-iptables> Queued start job for default target Multi-User System. container-test-run-user-firewall-iptables> container-test-run-user-firewall-iptables> container-test-run-user-firewall-iptables> container-test-run-user-firewall-iptables> <<< Welcome to NixOS test (x86_64) - console >>> container-test-run-user-firewall-iptables> + systemd-run /bin/sh -c '/nix/store/gph17gb73p6qbrqqjnypfjj5npf0ldyx-coreutils-9.11/bin/sleep 999999999 && echo 999dcd42-5fd9-47f7-be15-ba37a7c09001' container-test-run-user-firewall-iptables> Running as unit: run-p346-i94530734.service; invocation ID: 3962e326aeb446e1956780717011df7f container-test-run-user-firewall-iptables> To attach to container machine run on the same machine that runs the test: container-test-run-user-firewall-iptables> sudo nsenter --user --target $(\pgrep -f '^/bin/sh.*999dcd42-5fd9-47f7-be15-ba37a7c09001') --mount --uts --ipc --net --pid --cgroup /bin/sh -c bash container-test-run-user-firewall-iptables> container-test-run-user-firewall-iptables> To inject external network and continue test, run: container-test-run-user-firewall-iptables> sudo /nix/store/xqnbm0vgqcq9b1b54c80qj9s0qhbwa08-python3-3.13.15/bin/python3.13 /nix/store/vqjq3jq1b3k8d0fwp154mbdy9h3gxmdn-test-driver-0.0.1/lib/python3.13/site-packages/test_driver/inject_network.py 999dcd42-5fd9-47f7-be15-ba37a7c09001 container-test-run-user-firewall-iptables> container-test-run-user-firewall-iptables> <<< NixOS Stage 2 >>> container-test-run-user-firewall-iptables> container-test-run-user-firewall-iptables> booting system configuration /nix/store/bjj1db0bq2gd2fyl55rhvsdp8nw01kqy-nixos-system-router-test container-test-run-user-firewall-iptables> running activation script... container-test-run-user-firewall-iptables> setting up /etc... container-test-run-user-firewall-iptables> 2: host0@if3: mtu 1500 qdisc noop state DOWN mode DEFAULT group default qlen 1000 container-test-run-user-firewall-iptables> link/ether a6:24:31:fe:b9:6d brd ff:ff:ff:ff:ff:ff link-netnsid 0 container-test-run-user-firewall-iptables> starting systemd... container-test-run-user-firewall-iptables> systemd 260.2 running in system mode (+PAM +AUDIT -SELINUX +APPARMOR +IMA +IPE +SMACK +SECCOMP +GCRYPT -GNUTLS +OPENSSL +ACL +BLKID +CURL +ELFUTILS +FIDO2 +IDN2 +KMOD +LIBCRYPTSETUP +LIBCRYPTSETUP_PLUGINS +LIBFDISK +PCRE2 +PWQUALITY +P11KIT +QRENCODE +TPM2 +BZIP2 +LZ4 +XZ +ZLIB +ZSTD +BPF_FRAMEWORK -BTF -XKBCOMMON +UTMP +LIBARCHIVE) container-test-run-user-firewall-iptables> Detected virtualization systemd-nspawn. container-test-run-user-firewall-iptables> Detected architecture x86-64. container-test-run-user-firewall-iptables> Detected first boot. container-test-run-user-firewall-iptables> Initializing machine ID from container UUID. container-test-run-user-firewall-iptables> Applying preset policy. container-test-run-user-firewall-iptables> Populated /etc with preset unit settings. container-test-run-user-firewall-iptables> Queued start job for default target Multi-User System. container-test-run-user-firewall-iptables> container-test-run-user-firewall-iptables> container-test-run-user-firewall-iptables> container-test-run-user-firewall-iptables> <<< Welcome to NixOS test (x86_64) - console >>> container-test-run-user-firewall-iptables> + systemd-run /bin/sh -c '/nix/store/gph17gb73p6qbrqqjnypfjj5npf0ldyx-coreutils-9.11/bin/sleep 999999999 && echo 45f7db5c-1584-4fec-9ea6-dde0df868825' container-test-run-user-firewall-iptables> Running as unit: run-p209-i94530737.service; invocation ID: 4316ac30e8104cae9f900a7aa6999c61 container-test-run-user-firewall-iptables> To attach to container router run on the same machine that runs the test: container-test-run-user-firewall-iptables> sudo nsenter --user --target $(\pgrep -f '^/bin/sh.*45f7db5c-1584-4fec-9ea6-dde0df868825') --mount --uts --ipc --net --pid --cgroup /bin/sh -c bash container-test-run-user-firewall-iptables> container-test-run-user-firewall-iptables> To inject external network and continue test, run: container-test-run-user-firewall-iptables> sudo /nix/store/xqnbm0vgqcq9b1b54c80qj9s0qhbwa08-python3-3.13.15/bin/python3.13 /nix/store/vqjq3jq1b3k8d0fwp154mbdy9h3gxmdn-test-driver-0.0.1/lib/python3.13/site-packages/test_driver/inject_network.py 45f7db5c-1584-4fec-9ea6-dde0df868825 container-test-run-user-firewall-iptables> + systemctl --no-pager show multi-user.target container-test-run-user-firewall-iptables> + systemctl --no-pager show nginx.service container-test-run-user-firewall-iptables> + systemctl --no-pager show multi-user.target container-test-run-user-firewall-iptables> + systemctl --no-pager show nginx.service container-test-run-user-firewall-iptables> + ip -4 addr show eth1 container-test-run-user-firewall-iptables> + grep -oP '(?<=inet\s)\d+(\.\d+){3}' container-test-run-user-firewall-iptables> + ip -6 addr show eth1 container-test-run-user-firewall-iptables> + grep -oP '(?<=inet6\s)[0-9a-f:]+' container-test-run-user-firewall-iptables> + grep -v '^fe80' container-test-run-user-firewall-iptables> + head -1 container-test-run-user-firewall-iptables> Router IPv4: 192.168.1.2 container-test-run-user-firewall-iptables> Router IPv6: 2001:db8:1::2 container-test-run-user-firewall-iptables> + systemctl restart firewall container-test-run-user-firewall-iptables> + systemctl --no-pager show firewall.service container-test-run-user-firewall-iptables> + iptables -L user-firewall-output container-test-run-user-firewall-iptables> Chain user-firewall-output (1 references) container-test-run-user-firewall-iptables> target prot opt source destination container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> REJECT all -- anywhere anywhere owner UID match bob reject-with icmp-port-unreachable container-test-run-user-firewall-iptables> RETURN all -- anywhere anywhere container-test-run-user-firewall-iptables> machine: waiting for success: runuser -u alice -- curl -s http://127.0.0.1:8080 container-test-run-user-firewall-iptables> + runuser -u alice -- curl -s http://127.0.0.1:8080 container-test-run-user-firewall-iptables> (finished: waiting for success: runuser -u alice -- curl -s http://127.0.0.1:8080, in 0.02 seconds) container-test-run-user-firewall-iptables> + runuser -u alice -- curl -s http://192.168.1.2 container-test-run-user-firewall-iptables> + runuser -u alice -- curl -s 'http://[2001:db8:1::2]' container-test-run-user-firewall-iptables> + runuser -u bob -- curl -s http://127.0.0.1:8080 container-test-run-user-firewall-iptables> + runuser -u bob -- curl -s --connect-timeout 2 http://192.168.1.2 container-test-run-user-firewall-iptables> + echo EXIT_CODE=7 container-test-run-user-firewall-iptables> + runuser -u bob -- curl -s --connect-timeout 2 'http://[2001:db8:1::2]' container-test-run-user-firewall-iptables> + echo EXIT_CODE=7 container-test-run-user-firewall-iptables> + iptables -L user-firewall-output -n -v container-test-run-user-firewall-iptables> + ip6tables -L user-firewall-output -n -v container-test-run-user-firewall-iptables> + systemctl --no-pager show setup-wg0-interface.service container-test-run-user-firewall-iptables> + systemctl --no-pager show nginx.service container-test-run-user-firewall-iptables> machine: waiting for success: nc -z 10.100.0.2 8081 container-test-run-user-firewall-iptables> + nc -z 10.100.0.2 8081 container-test-run-user-firewall-iptables> Connection to 10.100.0.2 8081 port [tcp/sunproxyadmin] succeeded! container-test-run-user-firewall-iptables> (finished: waiting for success: nc -z 10.100.0.2 8081, in 0.01 seconds) container-test-run-user-firewall-iptables> + ip link show wg0 container-test-run-user-firewall-iptables> + ip addr show wg0 container-test-run-user-firewall-iptables> + runuser -u alice -- curl -s --interface wg0 http://10.100.0.2:8081/ container-test-run-user-firewall-iptables> + runuser -u alice -- curl -s --interface wg0 'http://[fd00::2]:8081/' container-test-run-user-firewall-iptables> + runuser -u bob -- curl -s --interface wg0 http://10.100.0.2:8081/ container-test-run-user-firewall-iptables> + runuser -u bob -- curl -s --interface wg0 'http://[fd00::2]:8081/' container-test-run-user-firewall-iptables> + iptables -L user-firewall-output -n -v container-test-run-user-firewall-iptables> + grep -E 'wg0|wg\+' container-test-run-user-firewall-iptables> 0 0 RETURN all -- * wg+ 0.0.0.0/0 0.0.0.0/0 container-test-run-user-firewall-iptables> container-test-run-user-firewall-iptables> post-build step Upload to niks3: ok time=2026-09-02T15:03:53.446Z level=INFO msg="Uploading 0 paths to niks3.clan.lol (1 already cached)" time=2026-09-02T15:03:53.635Z level=INFO msg="Uploading 1 narinfos" time=2026-09-02T15:03:53.812Z level=INFO msg="Upload complete. (416ms)"