Skip to content
ocx
install

ocx_download

load("@rules_ocx//ocx:defs.bzl", "ocx_download")

ocx_download(name, dist_manifest, triple, version)

Downloads a pinned ocx CLI release for the host platform.

The release row (URL + sha256) comes from the vendored dist.json snapshot of https://setup.ocx.sh/dist.json. Corporate mirrors: set OCX_INSTALL_DIST_URL to fetch a mirrored manifest instead, and/or OCX_INSTALL_MIRROR_URL to rewrite the artifact download to <mirror>/<tag>/<filename>. The artifact sha256 is enforced either way.

A mirrored manifest is itself verified when it is named <sha256>.json (the form the official setup.ocx.sh installers write, as dist/<sha256>.json) — the name carries the manifest’s own digest, which is then enforced on the fetch. Any other manifest name is fetched unverified: the transport to the mirror is then all that stands behind the rows it serves, sha256 included.

version must be 0.6.1 or newer: rules_ocx passes --pinned to ocx env and ocx exec and pins OCX_NO_CONSENT, none of which exists on older releases.

ATTRIBUTES

Name Description Type Mandatory Default
name A unique name for this repository. Name required
dist_manifest Release manifest snapshot (dist.json schema 1). Label optional "@rules_ocx//dist:dist.json"
triple Escape hatch: exact release target triple, e.g. ‘x86_64-unknown-linux-gnu’ to prefer the glibc build. Defaults to host detection (Linux maps to musl). String optional ""
version Exact ocx version to download, e.g. ‘0.6.2’. Must be 0.6.1 or newer. String required