`docker context export` writes a truncated tar archive
Les mainteneurs répondent en général sous 1 jour
Personne n'a encore pris cette issue.
Évaluation
- Difficulté
- 2/5
- Temps estimé
- 1-3 heures
- Accessibilité débutants
- 92/100
Piste de recherche
Commencez par Export() dans cli/context/store/store.go et examinez comment le tar writer et l’output writer sont fermés. Exécutez les tests existants dans cli/context/store, puis vérifiez qu’un contexte exporté contenant des fichiers TLS constitue une archive tar complète acceptée par Python tarfile et macOS tar.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Description
Description
docker context export writes a truncated tar file. The two zero blocks that end a tar archive are never written, and when the context has TLS files, the padding after the last file is missing too.
docker context import still reads these files, because Go's archive/tar stops quietly at EOF. Other readers are stricter: with TLS files in the context, Python's tarfile rejects the export, and so does the macOS tar when reading it from a pipe (output below).
The cause is the order of these deferred calls in Export() in cli/context/store/store.go:
tw := tar.NewWriter(writer)
defer tw.Close()
defer writer.Close()
Deferred calls run last-in, first-out. So the pipe is closed first, and when tw.Close() then tries to write the padding and the trailer, it gets io.ErrClosedPipe. That error is ignored. The code hasn't changed since the context store was added in b34f340346f (2018).
Reproduce
$ openssl req -x509 -newkey rsa:2048 -nodes -keyout /dev/null -out ca.pem -days 1 -subj "/CN=example"
$ docker context create example --docker "host=tcp://127.0.0.1:2376,ca=$PWD/ca.pem"
example
Successfully created context "example"
$ docker context export example example.tar
Written file "example.tar"
$ wc -c < example.tar
3667
A tar file is always a multiple of 512 bytes, and 3667 isn't (the exact size depends on the certificate). The file stops 83 bytes into a block, right after the contents of tls/docker/ca.pem:
$ python3 -m tarfile -l example.tar
Traceback (most recent call last):
...
ReadError: unexpected end of data
$ docker context export example - | tar -tf - > /dev/null
tar: Truncated input file (needed 1536 bytes, only 1107 available)
tar: Error exit delayed from previous errors.
Expected behavior
A complete tar file: each file padded to a 512-byte boundary, then the end-of-archive marker. Other tar tools should be able to read the export too.
docker version
Client:
Version: 29.8.0
API version: 1.56
Go version: go1.26.8
Git commit: 88096ef
Built: Thu Sep 3 21:49:43 2026
OS/Arch: darwin/amd64
Context: default
Server: Docker Desktop 4.91.0 (239619)
Engine:
Version: 29.8.0
API version: 1.56 (minimum version 1.40)
Go version: go1.26.8
Git commit: 3ce5872
Built: Thu Sep 3 21:51:20 2026
OS/Arch: linux/amd64
Experimental: false
containerd:
Version: v2.3.4
GitCommit: db8809540e1a7a9da5d518876894933ff55692ab
runc:
Version: 1.4.3
GitCommit: v1.4.3-0-gbb14dabe
docker-init:
Version: 0.19.0
GitCommit: de40ad0
docker info
N/A, the daemon isn't involved. This happens in the CLI's context store (cli/context/store).
Additional Info
Same result with the CLI built from master (7fc2dff9bc).
Without TLS files the archive happens to end on a block boundary, and the readers above accept it. The end-of-archive marker is still missing, though.
Closing the tar writer before the pipe fixes it. With this change, the export from the steps above is a complete archive that both readers accept, and the existing tests in cli/context/store still pass:
tw := tar.NewWriter(writer)
defer func() {
// Close the tar writer first, so that the padding and the
// end-of-archive marker are written before the pipe is closed.
writer.CloseWithError(tw.Close())
}()
Happy to open a PR for this.
- Langage dominant
- Go
- Étoiles
- 6.1k
- Forks
- 2.2k
- Merge moyen
- 1 j 11 h
- PR mergées (30 j)
- 45
Préparer son environnement
- Fournit un Dockerfile ou un fichier Docker Compose
- Propose un modèle de pull request
- Lire le guide de contribution
Par où commencer
- Lisez l'issue en entier, puis le guide de contribution du projet.
- Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
- Forkez le dépôt et travaillez sur une branche.
- Ouvrez une pull request qui référence le numéro de l'issue.
Autres issues de docker/cli
-
kind/bug status/0-triage
Difficulté 2/5 1-3 heures Accessibilité débutants 75/100
Les mainteneurs répondent en général sous 1 jour
-
kind/bug status/0-triage
Difficulté 2/5 1-3 heures Accessibilité débutants 72/100
docker/cli#7176 · 1 commentaire ·
Les mainteneurs répondent en général sous 1 jour
-
Difficulté 2/5 1-3 heures Accessibilité débutants 74/100
docker/cli#7005 · 2 commentaires ·
Les mainteneurs répondent en général sous 1 jour
-
kind/feature status/0-triage
Difficulté 2/5 1-3 heures Accessibilité débutants 70/100
docker/cli#6919 · 3 commentaires ·
Les mainteneurs répondent en général sous 1 jour
-
kind/bug status/0-triage
Difficulté 2/5 1-3 heures Accessibilité débutants 76/100
docker/cli#6917 · 2 commentaires ·
Les mainteneurs répondent en général sous 1 jour
Toutes les issues de docker/cli
Issues similaires
-
priority: low 🌱 type: enhancement 💅🏼
Difficulté 2/5 Une demi-journée Accessibilité débutants 84/100
nebari-dev/llm-serving-pack#199 ·
Les mainteneurs répondent en général sous 3 jours
-
bug
Difficulté 2/5 1-3 heures Accessibilité débutants 78/100
-
area/helm kind/bug priority/backlog triage/accepted
Difficulté 2/5 1-3 heures Accessibilité débutants 84/100
lexfrei/cloudflare-tunnel-gateway-controller#889 ·
Les mainteneurs répondent en général sous 1 jour
-
bug difficulty: beginner documentation good first issue help wanted localization
Difficulté 1/5 Moins d'une heure Accessibilité débutants 90/100
wavefnd/wave-platform#140 ·
-
compiler/runtime
Difficulté 2/5 1-3 heures Accessibilité débutants 78/100
golang/go#81797 · 1 commentaire ·
Les mainteneurs répondent en général sous 1 jour