Skip to content
ocx
install

partial_report, tolerated_report

partial_reportfunction#

Re-exported from ocx_sdk._resultsView source
def partial_report(error: OcxProcessError) -> str | None

Return the report a non-zero-exit stdout carried, else None (D10).

Several ocx failures still print a full JSON report before exiting non-zero: a --signature-format both sign or attest losing one leg, a partially-failed tag sweep, a copy refused on a sidecar conflict, and a push whose inline signing failed. OcxProcessError never parses its own stdout, so a caller recovers the report explicitly:

try:
result = ocx.package.sign(ref, key="file://k.pem", rekor_upload=False)
except OcxProcessError as exc:
raw = partial_report(exc)
if raw is not None:
result = SignatureReport.from_json(raw)
else:
raise

Parameters

NameTypeDescription
errorOcxProcessErrorThe caught process failure.

Returns

str | None
None for a hard failure (an error envelope carrying an error key
str | None
and no data, or stdout that is empty or unparseable as JSON) —
str | None
there is nothing to recover. Otherwise error.stdout verbatim, ready
str | None
for the matching from_json.

tolerated_reportfunction#

Re-exported from ocx_sdk._resultsView source
def tolerated_report(result: CommandResult) -> str

Return the report a report-then-fail command wrote, or raise its failure.

package test, cascade check and cascade repair exit non-zero with their report on stdout when the outcome is a finding rather than a fault — the client tolerates that code (ok_codes) so the report comes back as a result. The same code with an error envelope, or with no JSON at all, is a fault the tolerance must not swallow: this raises it as the exception the exit code maps to, stdout preserved for error_envelope(err).

Parameters

NameTypeDescription
resultCommandResultThe finished call, exit code and both streams.

Returns

str
result.stdout, for the matching from_json.

Raises

OcxProcessError
The exit was non-zero and stdout carried no report — the subclass _errors maps the code to, or the base class for a code ocx never assigns.