.dockerignore reinclusion retains unrelated files in a glob-excluded directory
メンテナーはふだん 4 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 3/5
- 見積もり時間
- 1〜2日
- 初心者へのやさしさ
- 74/100
- issue の種類
- バグ
- 明瞭さ
- 明確に書かれている
- 活発さ
- 活発
- 技術スタック
- docker, python
- 領域
- build-system
調査の方向性
Start from docker.utils.tar and the exclude/reinclusion pattern matching behind it (docker/utils/build.py) to see how **/cache combined with !cache/keep.txt is evaluated. Run the reproducer script from the issue (reproduce-ancestor.py) to confirm the current output keeps cache/drop.txt, then compare with the stated BuildKit expectation: only cache/keep.txt survives while src/cache/drop.txt is dropped. Done means the reproducer prints ['cache/keep.txt'] for the fixture files and the existing unit tests for build-context tar creation still pass.
索引モデルが issue の本文から書いたものです。
説明
🤖 this issue description was generated by an LLM. i reviewed it before submitting. 🤖
I used Codex for the investigation, reproduction scripts, and this draft.
When I generate a build context with docker.utils.tar, the rules **/cache and !cache/keep.txt retain both cache/keep.txt and cache/drop.txt. Docker's BuildKit keeps only cache/keep.txt with the same input. The SDK therefore includes an unrelated file that the ignore rule excludes.
Reproduction
Save this script as reproduce-ancestor.py:
import tarfile
from pathlib import Path
from tempfile import TemporaryDirectory
import docker
from docker.utils import tar
patterns = ['**/cache', '!cache/keep.txt']
files = ['cache/drop.txt', 'cache/keep.txt', 'src/cache/drop.txt']
with TemporaryDirectory() as directory:
root = Path(directory)
(root / 'Dockerfile').write_text('FROM scratch\nCOPY . /\n')
(root / '.dockerignore').write_text('\n'.join(patterns) + '\n')
for relative in files:
path = root / relative
path.parent.mkdir(parents=True, exist_ok=True)
path.write_text(relative)
with tar(str(root), exclude=patterns.copy()) as context:
with tarfile.open(fileobj=context) as archive:
actual = sorted(name for name in archive.getnames() if name in files)
print('docker:', docker.__version__)
print('patterns:', patterns)
print('SDK context files:', actual)
I ran it in an isolated uv environment, using commit 56343ddf8f0c44281e151c2dad016c16cdb8393d:
uv run --isolated --no-project --no-config --no-cache \
--python /home/jyn/.local/share/mise/installs/python/3.14.7/bin/python3 \
--with 'docker @ git+https://github.com/docker/docker-py@56343ddf8f0c44281e151c2dad016c16cdb8393d' \
python reproduce-ancestor.py
The --python path selects my tested Python installation; use the path to your Python executable on another machine. The pinned requirement selects the upstream SDK rather than an installed copy. I did not modify the SDK or replace its modules with mocks. This reproducer creates disposable files and examines the SDK's context tar without contacting a Docker daemon.
Expected behavior
The SDK should retain only cache/keep.txt from the fixture payload files. It should exclude cache/drop.txt and src/cache/drop.txt. I built the same files with FROM scratch and COPY . / using BuildKit, and its local output retained only cache/keep.txt.
Actual output
docker: 7.2.1.dev26+g56343ddf8
patterns: ['**/cache', '!cache/keep.txt']
SDK context files: ['cache/drop.txt', 'cache/keep.txt']
BuildKit control
I ran the following standalone control with Docker's active lima context and lima builder. It creates the same input files, runs docker buildx build with a local filesystem export, and enumerates every exported regular file before removing the temporary directories. The command uses the active Docker context and builder; another machine can use its own working configuration.
Buildx command and exported-file inspection
Save this script as buildkit-control-ancestor.py:
import subprocess
from pathlib import Path
from tempfile import TemporaryDirectory
patterns = ['**/cache', '!cache/keep.txt']
files = ['cache/drop.txt', 'cache/keep.txt', 'src/cache/drop.txt']
with TemporaryDirectory() as directory:
context = Path(directory) / 'input'
context.mkdir()
output = Path(directory) / 'output'
(context / 'Dockerfile').write_text('FROM scratch\nCOPY . /\n')
(context / '.dockerignore').write_text('\n'.join(patterns) + '\n')
for relative in files:
path = context / relative
path.parent.mkdir(parents=True, exist_ok=True)
path.write_text(relative)
subprocess.run([
'docker', 'buildx', 'build',
'--progress=plain', '--provenance=false',
'--output', f'type=local,dest={output}', str(context),
], check=True)
print('BuildKit output files:', sorted(
path.relative_to(output).as_posix()
for path in output.rglob('*') if path.is_file()
))
Run it with:
python3 buildkit-control-ancestor.py
I got this stdout; Buildx wrote its progress log to stderr and exited successfully:
BuildKit output files: ['.dockerignore', 'Dockerfile', 'cache/keep.txt']
Environment
- Docker SDK for Python:
7.2.1.dev26+g56343ddf8, using upstream commit56343ddf8f0c44281e151c2dad016c16cdb8393d. - Python:
3.14.7 (main, Sep 29 2026, 15:01:40) [Clang 22.1.3 ]. - OS/distribution: CachyOS Linux, rolling release (
BUILD_ID=rolling;/etc/os-releasedoes not defineVERSION_ID). - Kernel/platform:
Linux-7.2.9-1-cachyos-x86_64-with-glibc2.44. - Docker CLI:
29.8.2; Docker Engine:29.8.0(linux/amd64). - Buildx:
github.com/docker/buildx 0.37.2 2d379c0c3f22da0d2759d132a0ec81ca949098f0. - The SDK tar reproducer requires no engine connection; the separate BuildKit comparison used the versions above.
- 主要言語
- Python
- スター
- 7.2k
- フォーク
- 1.7k
- 平均マージ
- 3日 19時間
- マージ済み PR(30日)
- 1
環境構築
- Dockerfile または Docker Compose ファイルあり
- プルリクエストのテンプレートなし
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
docker/docker-py のほかの issue
-
.dockerignore matching ignores filename case on Linux対応中かも このイシューにリンクされたプルリクエストがオープン中、またはマージ済みです。 オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
メンテナーはふだん 4 日以内に返信
-
Add `pull` to the list of kwargs to pass to create and run対応中かも @zainnadeem786 が 130 日前に担当しました。 オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
docker/docker-py#3369 · コメント 2 件 ·
メンテナーはふだん 4 日以内に返信
-
難易度 1/5 1時間未満 初心者へのやさしさ 68/100
メンテナーはふだん 4 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 65/100
docker/docker-py#2457 · リアクション 4 件 ·
メンテナーはふだん 4 日以内に返信
-
難易度 3/5 1〜2日 初心者へのやさしさ 80/100
メンテナーはふだん 4 日以内に返信
docker/docker-py の issue をすべて見る
似ている issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
RedHatQE/mtv-api-tests#721 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
メンテナーはふだん 1 日以内に返信
-
難易度 1/5 1〜3時間 初心者へのやさしさ 85/100
pytest-dev/pluggy#757 ·
メンテナーはふだん 1 日以内に返信
-
難易度 1/5 1〜3時間 初心者へのやさしさ 85/100
NousResearch/hermes-agent#134960 ·
メンテナーはふだん 1 日以内に返信
-
HTML backend: `<br>` leaks the internal sentinel U+E000 into list items, headings and captions対応中かも @morten-lagabote が今日担当しました。 オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 67/100
docling-project/docling#4671 ·
メンテナーはふだん 1 日以内に返信