Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

.dockerignore reinclusion retains unrelated files in a glob-excluded directory

Open
#3,449 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 4 days

Nobody has claimed this yet.

Assessment

Difficulty
3/5
Estimated time
1-2 days
Newbie friendliness
74/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Active
Tech stack
docker, python
Domain
build-system

Research direction

Start from docker.utils.tar and the exclude/reinclusion pattern matching behind it (docker/utils/build.py) to see how **/cache combined with !cache/keep.txt is evaluated. Run the reproducer script from the issue (reproduce-ancestor.py) to confirm the current output keeps cache/drop.txt, then compare with the stated BuildKit expectation: only cache/keep.txt survives while src/cache/drop.txt is dropped. Done means the reproducer prints ['cache/keep.txt'] for the fixture files and the existing unit tests for build-context tar creation still pass.

Written by the indexing model from the issue text.

Description

🤖 this issue description was generated by an LLM. i reviewed it before submitting. 🤖


I used Codex for the investigation, reproduction scripts, and this draft.

When I generate a build context with docker.utils.tar, the rules **/cache and !cache/keep.txt retain both cache/keep.txt and cache/drop.txt. Docker's BuildKit keeps only cache/keep.txt with the same input. The SDK therefore includes an unrelated file that the ignore rule excludes.

Reproduction

Save this script as reproduce-ancestor.py:

import tarfile
from pathlib import Path
from tempfile import TemporaryDirectory

import docker
from docker.utils import tar

patterns = ['**/cache', '!cache/keep.txt']
files = ['cache/drop.txt', 'cache/keep.txt', 'src/cache/drop.txt']
with TemporaryDirectory() as directory:
    root = Path(directory)
    (root / 'Dockerfile').write_text('FROM scratch\nCOPY . /\n')
    (root / '.dockerignore').write_text('\n'.join(patterns) + '\n')
    for relative in files:
        path = root / relative
        path.parent.mkdir(parents=True, exist_ok=True)
        path.write_text(relative)
    with tar(str(root), exclude=patterns.copy()) as context:
        with tarfile.open(fileobj=context) as archive:
            actual = sorted(name for name in archive.getnames() if name in files)
    print('docker:', docker.__version__)
    print('patterns:', patterns)
    print('SDK context files:', actual)

I ran it in an isolated uv environment, using commit 56343ddf8f0c44281e151c2dad016c16cdb8393d:

uv run --isolated --no-project --no-config --no-cache \
  --python /home/jyn/.local/share/mise/installs/python/3.14.7/bin/python3 \
  --with 'docker @ git+https://github.com/docker/docker-py@56343ddf8f0c44281e151c2dad016c16cdb8393d' \
  python reproduce-ancestor.py

The --python path selects my tested Python installation; use the path to your Python executable on another machine. The pinned requirement selects the upstream SDK rather than an installed copy. I did not modify the SDK or replace its modules with mocks. This reproducer creates disposable files and examines the SDK's context tar without contacting a Docker daemon.

Expected behavior

The SDK should retain only cache/keep.txt from the fixture payload files. It should exclude cache/drop.txt and src/cache/drop.txt. I built the same files with FROM scratch and COPY . / using BuildKit, and its local output retained only cache/keep.txt.

Actual output

docker: 7.2.1.dev26+g56343ddf8
patterns: ['**/cache', '!cache/keep.txt']
SDK context files: ['cache/drop.txt', 'cache/keep.txt']

BuildKit control

I ran the following standalone control with Docker's active lima context and lima builder. It creates the same input files, runs docker buildx build with a local filesystem export, and enumerates every exported regular file before removing the temporary directories. The command uses the active Docker context and builder; another machine can use its own working configuration.

Buildx command and exported-file inspection

Save this script as buildkit-control-ancestor.py:

import subprocess
from pathlib import Path
from tempfile import TemporaryDirectory

patterns = ['**/cache', '!cache/keep.txt']
files = ['cache/drop.txt', 'cache/keep.txt', 'src/cache/drop.txt']
with TemporaryDirectory() as directory:
    context = Path(directory) / 'input'
    context.mkdir()
    output = Path(directory) / 'output'
    (context / 'Dockerfile').write_text('FROM scratch\nCOPY . /\n')
    (context / '.dockerignore').write_text('\n'.join(patterns) + '\n')
    for relative in files:
        path = context / relative
        path.parent.mkdir(parents=True, exist_ok=True)
        path.write_text(relative)
    subprocess.run([
        'docker', 'buildx', 'build',
        '--progress=plain', '--provenance=false',
        '--output', f'type=local,dest={output}', str(context),
    ], check=True)
    print('BuildKit output files:', sorted(
        path.relative_to(output).as_posix()
        for path in output.rglob('*') if path.is_file()
    ))

Run it with:

python3 buildkit-control-ancestor.py

I got this stdout; Buildx wrote its progress log to stderr and exited successfully:

BuildKit output files: ['.dockerignore', 'Dockerfile', 'cache/keep.txt']

Environment

  • Docker SDK for Python: 7.2.1.dev26+g56343ddf8, using upstream commit 56343ddf8f0c44281e151c2dad016c16cdb8393d.
  • Python: 3.14.7 (main, Sep 29 2026, 15:01:40) [Clang 22.1.3 ].
  • OS/distribution: CachyOS Linux, rolling release (BUILD_ID=rolling; /etc/os-release does not define VERSION_ID).
  • Kernel/platform: Linux-7.2.9-1-cachyos-x86_64-with-glibc2.44.
  • Docker CLI: 29.8.2; Docker Engine: 29.8.0 (linux/amd64).
  • Buildx: github.com/docker/buildx 0.37.2 2d379c0c3f22da0d2759d132a0ec81ca949098f0.
  • The SDK tar reproducer requires no engine connection; the separate BuildKit comparison used the versions above.
Dominant language
Python
Stars
7.2k
Forks
1.7k
Avg merge
3d 19h
Merged PRs (30d)
1

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from docker/docker-py

All issues in docker/docker-py

Similar issues

More Python issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.