Blob endpoint returns 406 for an empty Accept header
Maintainers usually reply within 1 day
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 72/100
Research direction
Search the codebase for the error string "Could not satisfy the request Accept header" to find where content negotiation runs for blob requests (pulp_container's registry views/handlers). Start from the blob endpoint's Accept parsing and confirm how an empty header value differs from an absent one. Done means an empty Accept is treated like a missing header so the blob redirect is served, verified with a regression test that sends an explicitly empty Accept header.
Written by the indexing model from the issue text.
Description
406 Not Acceptable
{"errors":[{"code":"UNSUPPORTED","message":"Could not satisfy the request Accept header.","detail":{}}]}
The failure can be reproduced by requesting a valid configuration blob with an explicitly empty Accept header:
Requesting a token:
TOKEN=$(curl -fsS \
'https://pulp.example.com/token/?service=pulp.breuni.io&scope=repository:docker/library/eclipse-temurin:pull' \
| jq -r '.token')
Fetching the blob
curl -i -H "Authorization: Bearer $TOKEN" -H 'Accept;' \
'https://pulp.example.com/v2/docker/library/eclipse-temurin/blobs/sha256:6779cc3e4a680ad633e699feadcffe9ee38f7c7e9812a9a1187efb64ac77c8c5'
Response:
HTTP/1.1 406 Not Acceptable
server: gunicorn
date: Wed, 07 Oct 2026 14:37:27 GMT
content-type: application/json
allow: GET, DELETE, HEAD, OPTIONS
docker-distribution-api-version: registry/2.0
x-registry-supports-signatures: 1
x-frame-options: DENY
content-length: 104
x-content-type-options: nosniff
referrer-policy: same-origin
cross-origin-opener-policy: same-origin
correlation-id: 15d5ce5a21834f6db87af17a671d456d
access-control-expose-headers: Correlation-ID
{"errors":[{"code":"UNSUPPORTED","message":"Could not satisfy the request Accept header.","detail":{}}]}
Actual: Pulp returns 406.
Expected: Pulp serves the blob, treating the empty header like a missing header.
Omitting Accept or setting it to */* returns a redirect, and the blob downloads successfully. Docker Hub serves the same blob successfully. We have not yet confirmed the exact header sent by Jib
- Dominant language
- Python
- Stars
- 31
- Forks
- 57
- Avg merge
- 1d 3h
- Merged PRs (30d)
- 42
Getting set up
- No Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from pulp/pulp_container
-
docker pull unauthenticatedPossibly taken @am9zZWY claimed this 2 days ago. OpenIssue
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
pulp/pulp_container#1976 · 2 comments · 8 reactions ·
Maintainers usually reply within 1 day
-
Feature
Difficulty 3/5 1-2 days Newbie friendliness 65/100
pulp/pulp_container#2519 ·
Maintainers usually reply within 1 day
-
base_path uniqueness constraint prevents syncing the same image from multiple remote registriesOpenQuestion
Difficulty 5/5 Over a week Newbie friendliness 35/100
pulp/pulp_container#2495 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 4/5 3-5 days Newbie friendliness 55/100
pulp/pulp_container#2474 ·
Maintainers usually reply within 1 day
-
Difficulty 5/5 Over a week Newbie friendliness 35/100
pulp/pulp_container#2473 ·
Maintainers usually reply within 1 day
All issues in pulp/pulp_container
Similar issues
-
changelog investigate
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
ramnes/notion-sdk-py#409 ·
-
good first issue help wanted
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
lindicaphxag-tech/kaggle#28 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
BSData/horus-heresy-3rd-edition#3211 ·
Maintainers usually reply within 1 day
-
bug needs-triage
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
Maintainers usually reply within 1 day
-
Unreachable-proxy mount test depends on fixed port 9999Possibly taken A pull request linked to this issue is open or already merged. Openbug tests
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
Maintainers usually reply within 1 day