this derivation will be built: /nix/store/v20r9yzpszxgn66nhln8qg9z9vrxh51s-spaces-integration-proton-tls.drv building '/nix/store/v20r9yzpszxgn66nhln8qg9z9vrxh51s-spaces-integration-proton-tls.drv' spaces-integration-proton-tls> PASS: serving cert carries Basic Constraints CA:TRUE (mimics Proton Bridge) spaces-integration-proton-tls> === generate himalaya.toml + msmtprc via integration_proton._build_config === spaces-integration-proton-tls> GENERATED himalaya.toml + msmtprc spaces-integration-proton-tls> === generated config: integration pins backend.encryption.cert + tls_trust_file === spaces-integration-proton-tls> PASS: generated himalaya config pins backend.encryption.cert at the Bridge cert spaces-integration-proton-tls> PASS: generated msmtprc carries tls_trust_file at the Bridge cert spaces-integration-proton-tls> === IMAP positive: himalaya trusts the CA:TRUE cert via the integration's pin === spaces-integration-proton-tls> FAIL: himalaya did NOT complete TLS (stub: IMAP_LISTEN 14143) spaces-integration-proton-tls> PASS: no CaUsedAsEndEntity / cert error from himalaya when pinned spaces-integration-proton-tls> === IMAP negative: strip the integration's pin -> default verifier rejects CA:TRUE === spaces-integration-proton-tls> FAIL: expected a TLS rejection without pin, got: Suggestions: - Run with --log-level to enable more verbose logs spaces-integration-proton-tls> === SMTP positive: msmtp trusts the CA:TRUE cert via the integration's tls_trust_file === spaces-integration-proton-tls> PASS: msmtp trusted the CA:TRUE cert via tls_trust_file (no cert error) spaces-integration-proton-tls> === SMTP negative: point trust_file at an unrelated cert -> msmtp must reject === spaces-integration-proton-tls> PASS: msmtp rejected the mismatched cert (trust_file is enforced) spaces-integration-proton-tls> spaces-integration-proton-tls> RESULT: FAILURES error: Cannot build '/nix/store/v20r9yzpszxgn66nhln8qg9z9vrxh51s-spaces-integration-proton-tls.drv'. Reason: builder failed with exit code 1. Output paths: /nix/store/z09h65sn4irf45iz9s6h15m8r3pin4fs-spaces-integration-proton-tls Last 17 log lines: > PASS: serving cert carries Basic Constraints CA:TRUE (mimics Proton Bridge) > === generate himalaya.toml + msmtprc via integration_proton._build_config === > GENERATED himalaya.toml + msmtprc > === generated config: integration pins backend.encryption.cert + tls_trust_file === > PASS: generated himalaya config pins backend.encryption.cert at the Bridge cert > PASS: generated msmtprc carries tls_trust_file at the Bridge cert > === IMAP positive: himalaya trusts the CA:TRUE cert via the integration's pin === > FAIL: himalaya did NOT complete TLS (stub: IMAP_LISTEN 14143) > PASS: no CaUsedAsEndEntity / cert error from himalaya when pinned > === IMAP negative: strip the integration's pin -> default verifier rejects CA:TRUE === > FAIL: expected a TLS rejection without pin, got: Suggestions: - Run with --log-level to enable more verbose logs > === SMTP positive: msmtp trusts the CA:TRUE cert via the integration's tls_trust_file === > PASS: msmtp trusted the CA:TRUE cert via tls_trust_file (no cert error) > === SMTP negative: point trust_file at an unrelated cert -> msmtp must reject === > PASS: msmtp rejected the mismatched cert (trust_file is enforced) > > RESULT: FAILURES For full logs, run: nix log /nix/store/v20r9yzpszxgn66nhln8qg9z9vrxh51s-spaces-integration-proton-tls.drv