- integrations
- Python
- ocx_sdk
partial_report, tolerated_report
partial_reportfunction#
ocx_sdk._resultsView sourcedef partial_report(error: OcxProcessError) -> str | NoneReturn the report a non-zero-exit stdout carried, else None (D10).
Several ocx failures still print a full JSON report before exiting
non-zero: a --signature-format both sign or attest losing one leg, a
partially-failed tag sweep, a copy refused on a sidecar conflict, and a
push whose inline signing failed. OcxProcessError never parses its own
stdout, so a caller recovers the report explicitly:
try: result = ocx.package.sign(ref, key="file://k.pem", rekor_upload=False)except OcxProcessError as exc: raw = partial_report(exc) if raw is not None: result = SignatureReport.from_json(raw) else: raiseParameters
| Name | Type | Description |
|---|---|---|
error | OcxProcessError | The caught process failure. |
Returns
str | NoneNonefor a hard failure (an error envelope carrying anerrorkeystr | None- and no
data, or stdout that is empty or unparseable as JSON) — str | None- there is nothing to recover. Otherwise
error.stdoutverbatim, ready str | None- for the matching
from_json.
tolerated_reportfunction#
ocx_sdk._resultsView sourcedef tolerated_report(result: CommandResult) -> strReturn the report a report-then-fail command wrote, or raise its failure.
package test, cascade check and cascade repair exit non-zero with
their report on stdout when the outcome is a finding rather than a fault —
the client tolerates that code (ok_codes) so the report comes back as a
result. The same code with an error envelope, or with no JSON at all, is a
fault the tolerance must not swallow: this raises it as the exception the
exit code maps to, stdout preserved for error_envelope(err).
Parameters
| Name | Type | Description |
|---|---|---|
result | CommandResult | The finished call, exit code and both streams. |
Returns
strresult.stdout, for the matchingfrom_json.
Raises
OcxProcessError- The exit was non-zero and stdout carried no report —
the subclass
_errorsmaps the code to, or the base class for a code ocx never assigns.