Skip to content
ocx
install

PackageCommands (1 of 16)

PackageCommandsclassdataclass#

Re-exported from ocx_sdk._clientView source

cascade_checkmethod#

def cascade_check(*refs: PackageLike, timeout: MaybeTimeout = UNSET, retry: MaybeRetry = UNSET) -> CascadeCheckReport

Report where packages’ rolling tags disagree with their versions.

Read-only: authenticates for pull only and writes nothing, so it keeps the session retry policy. Report-then-fail: a finding makes ocx exit 65 with the report on stdout, and that is a result here — report.clean (the exit code’s answer) says whether anything disagreed, and the rows say what. The same code with no report is still the failure it names.

Parameters

NameTypeDefaultDescription
*refsPackageLike()Packages to audit. A tag (cmake:3.28) narrows the audit to that part of the graph.
timeoutMaybeTimeoutUNSETSeconds per attempt. Omitted takes the config’s.
retryMaybeRetryUNSETRetry policy. None opts out; omitted takes the config’s.

Returns

CascadeCheckReport
One audit per package, carrying the exit code.

Raises

UsageError
A package names a digest, or a tag that is not a version (exit 64).
DataError
Exit 65 without a report — a fault, not a finding.

installmethod#

def install(*refs: PackageLike, platform: str | None = None, select: bool = False, verify: bool | None = None, timeout: MaybeTimeout = UNSET, retry: MaybeRetry = UNSET) -> InstallReport

Install packages into the store.

Parameters

NameTypeDefaultDescription
*refsPackageLike()Package identifiers.
platformstr | NoneNoneThe platform to resolve against.
selectboolFalseAlso make each installed version current.
verifybool | NoneNoneVerify each package’s Sigstore signature before installing. None leaves ocx’s default, which is on. The gate fires only where a [[trust.policy]] covers the package, so True against an uncovered package is a documented no-op rather than enforcement — it does not make an unsigned package fail. False also beats an ambient OCX_NO_VERIFY, which the SDK neutralizes on every spawn.
timeoutMaybeTimeoutUNSETSeconds per attempt. Omitted takes the config’s.
retryMaybeRetryUNSETRetry policy. None opts out; omitted takes the config’s.

Returns

InstallReport
The installed packages, keyed by the identifier as given.

Raises

OcxProcessError
ocx 0.6 verifies a covered package’s signature before installing, so this call can fail where the identical call against a 0.5.x binary succeeded — no code change on the caller’s side, only a newer binary. The exit codes, and why none of them retry, are in the guide’s “Errors & credentials” section on verification.

whichmethod#

def which(*refs: PackageLike, platform: str | None = None, resolve: Resolve | None = None, lazy_mode: LazyMode | None = None, timeout: MaybeTimeout = UNSET, retry: MaybeRetry = UNSET) -> Mapping[str, WhichResult]

Resolve installed packages to their paths, downloading nothing.

Parameters

NameTypeDefaultDescription
*refsPackageLike()Package identifiers.
platformstr | NoneNoneThe platform to resolve against.
resolveResolve | NoneNoneWhich store symlink to resolve through — 'candidate' or 'current'. None leaves the choice to ocx.
lazy_modeLazyMode | NoneNoneWhen content downloads — now, or on first use.
timeoutMaybeTimeoutUNSETSeconds per attempt. Omitted takes the config’s.
retryMaybeRetryUNSETRetry policy. None opts out; omitted takes the config’s.

Returns

Mapping[str, WhichResult]
A path and kind per identifier. This payload is doc-flagged
Mapping[str, WhichResult]
pre-1.0 upstream and may change shape.