Skip to content
ocx
install

ocx_project_repo

load("@rules_ocx//ocx:defs.bzl", "ocx_project_repo")

ocx_project_repo(name, allow_unverified, allow_yanked, bins, config, groups, isolated_home,
                 no_config, ocx, ocx_lock, ocx_toml, patch_snapshot, platform, sigstore_trusted_root)

Provisions the toolchain declared in a workspace ocx.toml/ocx.lock.

Fails when the lockfile is stale or missing (fix with ocx lock). Every executable the toolchain’s packages declare as their public surface (ocx inspect --closure) becomes a runnable target //:<name>; a package shipping no complete binaries metadata falls back to scanning the composed PATH, which also exposes its private executables — //:env.bzl’s OCX_SCANNED_PACKAGES names the packages that forced it. The raw environment is loadable from the same file (OCX_ENV, OCX_HOME).

With bins, provisioning is lazy: nothing is pulled at fetch time, and each named executable becomes a launcher that re-enters ocx exec — content materializes on first execution and never becomes a Bazel action input, so fully remote-cached builds download no tool content at all.

groups scopes both the pull and the composed environment. Omitted, ocx’s defaults apply: every group is pulled, but only the default [tools] table is composed into launchers — name groups explicitly (or use the reserved all) to expose their executables.

platform composes a foreign platform’s environment from the same ocx.lock: that platform’s leaves are pulled into the store and env.bzl holds their absolute store paths (sysroots, target libraries, container image content). Foreign repos expose no runnable launchers — the binaries do not run on this host.

ATTRIBUTES

Name Description Type Mandatory Default
name A unique name for this repository. Name required
allow_unverified When true, sets OCX_NO_VERIFY=1 for every invocation — ocx’s own documented equivalent of --no-verify, so no verify flag is ever put on an argv. When false, OCX_NO_VERIFY=0 is written anyway, so an ambient value cannot switch verification off. It cannot switch verification on: ocx attaches that only under an operator-configured [[trust.policy]], so this attr can only decline to disable it — and no_config = True prunes the discovered tiers that policy lives in, so there is then nothing to decline and verification is off either way. Boolean optional False
allow_yanked Whether resolution may fall back to a yanked release — sets OCX_ALLOW_YANKED for every invocation. Boolean optional False
bins Lazy provisioning: names of the executables to expose (not validated at fetch time). When set, nothing is pulled during the fetch — each name becomes a launcher re-entering ocx exec, and actions key on the lockfile (a runfile) instead of tool content. Incompatible with isolated_home. List of strings optional []
config An ocx site config.toml (mirrors, registries, [patches]) layered over the host’s discovered config — not the project ocx.toml. Sets OCX_CONFIG for every invocation, overriding an ambient one, and the file is watched. Combine with no_config for a hermetic configuration. With bins it is copied into the repository and uploaded as an input with every action — keep credentials out of it. Label optional None
groups ocx.toml groups to provision (comma-joined into -g for ocx pull, ocx env, and lazy ocx exec). Reserved names: ‘default’ = the top-level [tools] table, ‘all’ = default + every declared group. List of strings optional []
isolated_home Keep the ocx store inside this repository instead of the shared user OCX_HOME. It also relocates OCX_HOME, so ocx’s ~/.ocx/sigstore/trusted-root.json rung is not found there — with a trust policy configured, trusted-root resolution falls through to the Rekor trust-root cache and then a live TUF fetch; offline it stops at the cache and fails outright, as ocx ships no embedded root. Boolean optional False
no_config Ignore the host’s discovered config tiers (/etc, the user config, $OCX_HOME/config.toml) and the managed-config snapshot — sets OCX_NO_CONFIG=1, and blanks an ambient OCX_CONFIG, OCX_PATCHES and OCX_PATCH_SNAPSHOT, which OCX_NO_CONFIG alone does not prune. The config and patch_snapshot attrs still apply. Use this when a corporate managed config must not reach the build; it also opts out of the exit-78 gate a required-but-unsynced managed config raises. Boolean optional False
ocx The pinned ocx CLI binary. Label optional "@ocx_tool//:ocx"
ocx_lock The ocx.lock next to ocx_toml; watched so lock changes refetch. Label required
ocx_toml The project ocx.toml declaring the toolchain. Label required
patch_snapshot A committed patches.snapshot.json (written by ocx patch freeze next to ocx.lock) freezing the digests of the patch companions composed onto this environment. Sets OCX_PATCH_SNAPSHOT. ocx lock --check does not cover companions — without a frozen snapshot they resolve at fetch time. With bins it is copied into the repository and uploaded as an input with every action — keep credentials out of it. Label optional None
platform ocx platform key (‘linux/arm64’, …) to compose for; empty = host. A foreign platform pulls that platform’s leaves from the same ocx.lock and exposes env.bzl only (no runnable launchers). Incompatible with bins — lazy launchers already resolve the executing host at run time. String optional ""
sigstore_trusted_root A sigstore trusted-root.json pinned in-tree. Sets OCX_SIGSTORE_TRUSTED_ROOT for every invocation, overriding the ambient <OCX_HOME>/sigstore/trusted-root.json rung, and the file is watched. Under lazy provisioning (bins on ocx.project/ocx.package) it is copied into the repository and uploaded as an input with every action. Label optional None