# ocx_sdk

*module*

Python SDK for [OCX](https://github.com/ocx-sh/ocx).

`ocx-sdk` drives the ocx binary rather than reimplementing it: ocx owns
resolution, verification, and the identifier grammar, and this package gives
you typed, CWD-independent handles over the commands it exposes.

```python
from ocx_sdk import Ocx, bootstrap

ocx = Ocx(exe=bootstrap.ensure())
project = ocx.project("/srv/build")
project.pull()
project.exec(["task", "verify"])
```

**This module is the API.** Everything listed in `__all__` is the stable
surface; every other module is underscored and package-private, and the one
public submodule is `ocx_sdk.bootstrap`. Reaching into an underscored path
means the next release may move it without notice — pre-1.0, breaking
changes ship without shims.

Start at `Ocx` for the runtime API and `bootstrap.ensure` for provisioning.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/__init__.py#L1-L1)

## ocx_sdk.PackageCommands

*class* · *dataclass*

```python
class PackageCommands
```

Re-exported from: `ocx_sdk._client`

The `ocx package` command group — machine tier.

Package operations act on the `$OCX_HOME` store and its candidate and
current symlinks. They take no project path and are CWD-independent by
construction; a path appears only where the CLI itself takes one.

Every method is multi-identifier native, mirroring the CLI's `PKG...`
with one shared resolution.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_client.py#L1470-L3367)

### ocx_sdk.PackageCommands.test

*method*

```python
def test(identifier: str, *, script: str | Path, layers: Iterable[str | Path] = (), platform: str | None = None, metadata: str | Path | None = None, output: str | Path | None = None, keep: bool = False, clean: bool = False, private: bool = False, env: Mapping[str, EnvValue] | None = None, timeout: MaybeTimeout = UNSET, retry: MaybeRetry = UNSET) -> TestResult
```

Materialize a package locally and run a Starlark test script.

Only the `--script` form is typed. ocx's trailing `-- CMD` form
prints the child's stdout verbatim even under `--format json`, so it
produces nothing parseable — reach for `invoke` if you need it.

**Parameters**

- `identifier` (`str`) — The identifier to materialize under. Tag form only.
- `script` (`str | Path`) — Path to the Starlark test script, or `-` to read the script source from stdin.
- `layers` (`Iterable[str | Path]`) (default: `()`) — Layer archives or digest references, base first.
- `platform` (`str | None`) (default: `None`) — The platform to resolve against. Omitted reads the build receipt beside the bundle.
- `metadata` (`str | Path | None`) (default: `None`) — The compiled metadata sidecar. Required when no file layers are given.
- `output` (`str | Path | None`) (default: `None`) — Where to materialize the package. `None` uses ocx's temp root under `$OCX_HOME`.
- `keep` (`bool`) (default: `False`) — Preserve the temporary build directory.
- `clean` (`bool`) (default: `False`) — Strip the ambient parent environment before composing.
- `private` (`bool`) (default: `False`) — Compose the private surface — ocx's `--self`.
- `env` (`Mapping[str, EnvValue] | None`) (default: `None`) — Extra `[env]` entries for this call.
- `timeout` (`MaybeTimeout`) (default: `UNSET`) — Seconds per attempt. Omitted takes the config's.
- `retry` (`MaybeRetry`) (default: `UNSET`) — Retry policy. `None` opts out; omitted takes the config's.

**Returns**

- (`TestResult`) — The outcome: `status` decides, and `assertion.kind` is the
- (`TestResult`) — stable machine-readable reason. A failing script is a RESULT
- (`TestResult`) — (exit 1 still carries the envelope), not an exception — only
- (`TestResult`) — resolution or usage failures raise.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_client.py#L2087-L2152)
