these 3 derivations will be built: /nix/store/6fr1rvnqc404shys27mxwkin10aivwfz-integration-proton-authcmd.drv /nix/store/vlhj1iphymn76mr444nmq18i3ypvg9y4-python3-3.14.7-env.drv /nix/store/2c7fk64z25swlak5z7r3ag4wxkgqr2kr-spaces-integration-proton-tls.drv building '/nix/store/6fr1rvnqc404shys27mxwkin10aivwfz-integration-proton-authcmd.drv' building '/nix/store/vlhj1iphymn76mr444nmq18i3ypvg9y4-python3-3.14.7-env.drv' integration-proton-authcmd> structuredAttrs is enabled python3-3.14.7-env> structuredAttrs is enabled python3-3.14.7-env> created 234 symlinks in user environment building '/nix/store/2c7fk64z25swlak5z7r3ag4wxkgqr2kr-spaces-integration-proton-tls.drv' spaces-integration-proton-tls> PASS: serving cert carries Basic Constraints CA:TRUE (mimics Proton Bridge) spaces-integration-proton-tls> === generate himalaya.toml via integration_proton._build_config === spaces-integration-proton-tls> GENERATED himalaya.toml spaces-integration-proton-tls> === generated config: integration pins imap.tls.cert + smtp.tls.cert === spaces-integration-proton-tls> PASS: generated himalaya config pins imap.tls.cert at the Bridge cert spaces-integration-proton-tls> PASS: generated himalaya config pins smtp.tls.cert at the Bridge cert spaces-integration-proton-tls> === IMAP positive: himalaya trusts the CA:TRUE cert via the integration's pin === spaces-integration-proton-tls> PASS: himalaya completed TLS against the CA:TRUE cert (integration pin works) spaces-integration-proton-tls> PASS: no CaUsedAsEndEntity / cert error from himalaya when pinned spaces-integration-proton-tls> === IMAP negative: strip the integration's pin -> default verifier rejects CA:TRUE === spaces-integration-proton-tls> PASS: without the pin himalaya rejects the CA:TRUE cert (the hazard is real) spaces-integration-proton-tls> === SMTP positive: himalaya trusts the CA:TRUE cert via the integration's pin === spaces-integration-proton-tls> PASS: himalaya trusted the CA:TRUE cert via smtp.tls.cert (no cert error) spaces-integration-proton-tls> === SMTP negative: strip the integration's pin -> default verifier rejects CA:TRUE === spaces-integration-proton-tls> PASS: without the pin himalaya rejects the CA:TRUE cert over SMTP spaces-integration-proton-tls> spaces-integration-proton-tls> RESULT: ALL-PASS post-build step Upload to niks3: ok time=2026-09-13T04:28:56.528Z level=INFO msg="Uploading 0 paths to 127.0.0.1 (1 already cached)" time=2026-09-13T04:28:57.124Z level=INFO msg="Uploading 1 narinfos" time=2026-09-13T04:28:58.282Z level=INFO msg="Upload complete. (1.818s)"