# ocx_sdk

*module*

Python SDK for [OCX](https://github.com/ocx-sh/ocx).

`ocx-sdk` drives the ocx binary rather than reimplementing it: ocx owns
resolution, verification, and the identifier grammar, and this package gives
you typed, CWD-independent handles over the commands it exposes.

```python
from ocx_sdk import Ocx, bootstrap

ocx = Ocx(exe=bootstrap.ensure())
project = ocx.project("/srv/build")
project.pull()
project.exec(["task", "verify"])
```

**This module is the API.** Everything listed in `__all__` is the stable
surface; every other module is underscored and package-private, and the one
public submodule is `ocx_sdk.bootstrap`. Reaching into an underscored path
means the next release may move it without notice — pre-1.0, breaking
changes ship without shims.

Start at `Ocx` for the runtime API and `bootstrap.ensure` for provisioning.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/__init__.py#L1-L1)

## ocx_sdk.PackageCommands

*class* · *dataclass*

```python
class PackageCommands
```

Re-exported from: `ocx_sdk._client`

The `ocx package` command group — machine tier.

Package operations act on the `$OCX_HOME` store and its candidate and
current symlinks. They take no project path and are CWD-independent by
construction; a path appears only where the CLI itself takes one.

Every method is multi-identifier native, mirroring the CLI's `PKG...`
with one shared resolution.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_client.py#L1470-L3367)

### ocx_sdk.PackageCommands.cascade_check

*method*

```python
def cascade_check(*refs: PackageLike, timeout: MaybeTimeout = UNSET, retry: MaybeRetry = UNSET) -> CascadeCheckReport
```

Report where packages' rolling tags disagree with their versions.

Read-only: authenticates for pull only and writes nothing, so it
keeps the session retry policy. **Report-then-fail**: a finding makes
ocx exit 65 *with* the report on stdout, and that is a result here
— `report.clean` (the exit code's answer) says whether anything
disagreed, and the rows say what. The same code with no report is
still the failure it names.

**Parameters**

- `*refs` (`PackageLike`) (default: `()`) — Packages to audit. A tag (`cmake:3.28`) narrows the audit to that part of the graph.
- `timeout` (`MaybeTimeout`) (default: `UNSET`) — Seconds per attempt. Omitted takes the config's.
- `retry` (`MaybeRetry`) (default: `UNSET`) — Retry policy. `None` opts out; omitted takes the config's.

**Returns**

- (`CascadeCheckReport`) — One audit per package, carrying the exit code.

**Raises**

- `UsageError` — A package names a digest, or a tag that is not a
version (exit 64).
- `DataError` — Exit 65 *without* a report — a fault, not a finding.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_client.py#L3243-L3275)

### ocx_sdk.PackageCommands.install

*method*

```python
def install(*refs: PackageLike, platform: str | None = None, select: bool = False, verify: bool | None = None, timeout: MaybeTimeout = UNSET, retry: MaybeRetry = UNSET) -> InstallReport
```

Install packages into the store.

**Parameters**

- `*refs` (`PackageLike`) (default: `()`) — Package identifiers.
- `platform` (`str | None`) (default: `None`) — The platform to resolve against.
- `select` (`bool`) (default: `False`) — Also make each installed version current.
- `verify` (`bool | None`) (default: `None`) — Verify each package's Sigstore signature before installing. `None` leaves ocx's default, which is on. The gate fires only where a `[[trust.policy]]` covers the package, so `True` against an uncovered package is a documented no-op rather than enforcement — it does not make an unsigned package fail. `False` also beats an ambient `OCX_NO_VERIFY`, which the SDK neutralizes on every spawn.
- `timeout` (`MaybeTimeout`) (default: `UNSET`) — Seconds per attempt. Omitted takes the config's.
- `retry` (`MaybeRetry`) (default: `UNSET`) — Retry policy. `None` opts out; omitted takes the config's.

**Returns**

- (`InstallReport`) — The installed packages, keyed by the identifier as given.

**Raises**

- `OcxProcessError` — ocx 0.6 verifies a covered package's signature
before installing, so this call can fail where the identical
call against a 0.5.x binary succeeded — no code change on the
caller's side, only a newer binary. The exit codes, and why
none of them retry, are in the guide's "Errors & credentials"
section on verification.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_client.py#L1487-L1530)

### ocx_sdk.PackageCommands.which

*method*

```python
def which(*refs: PackageLike, platform: str | None = None, resolve: Resolve | None = None, lazy_mode: LazyMode | None = None, timeout: MaybeTimeout = UNSET, retry: MaybeRetry = UNSET) -> Mapping[str, WhichResult]
```

Resolve installed packages to their paths, downloading nothing.

**Parameters**

- `*refs` (`PackageLike`) (default: `()`) — Package identifiers.
- `platform` (`str | None`) (default: `None`) — The platform to resolve against.
- `resolve` (`Resolve | None`) (default: `None`) — Which store symlink to resolve through — `'candidate'` or `'current'`. `None` leaves the choice to ocx.
- `lazy_mode` (`LazyMode | None`) (default: `None`) — When content downloads — now, or on first use.
- `timeout` (`MaybeTimeout`) (default: `UNSET`) — Seconds per attempt. Omitted takes the config's.
- `retry` (`MaybeRetry`) (default: `UNSET`) — Retry policy. `None` opts out; omitted takes the config's.

**Returns**

- (`Mapping[str, WhichResult]`) — A path and kind per identifier. This payload is doc-flagged
- (`Mapping[str, WhichResult]`) — pre-1.0 upstream and may change shape.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_client.py#L1835-L1866)
