# ocx_sdk

*module*

Python SDK for [OCX](https://github.com/ocx-sh/ocx).

`ocx-sdk` drives the ocx binary rather than reimplementing it: ocx owns
resolution, verification, and the identifier grammar, and this package gives
you typed, CWD-independent handles over the commands it exposes.

```python
from ocx_sdk import Ocx, bootstrap

ocx = Ocx(exe=bootstrap.ensure())
project = ocx.project("/srv/build")
project.pull()
project.exec(["task", "verify"])
```

**This module is the API.** Everything listed in `__all__` is the stable
surface; every other module is underscored and package-private, and the one
public submodule is `ocx_sdk.bootstrap`. Reaching into an underscored path
means the next release may move it without notice — pre-1.0, breaking
changes ship without shims.

Start at `Ocx` for the runtime API and `bootstrap.ensure` for provisioning.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/__init__.py#L1-L1)

## ocx_sdk.PackageCommands

*class* · *dataclass*

```python
class PackageCommands
```

Re-exported from: `ocx_sdk._client`

The `ocx package` command group — machine tier.

Package operations act on the `$OCX_HOME` store and its candidate and
current symlinks. They take no project path and are CWD-independent by
construction; a path appears only where the CLI itself takes one.

Every method is multi-identifier native, mirroring the CLI's `PKG...`
with one shared resolution.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_client.py#L1470-L3367)

### ocx_sdk.PackageCommands.cascade_repair

*method*

```python
def cascade_repair(*refs: PackageLike, dry_run: bool = False, announce_tags: str | Path | None = None, timeout: MaybeTimeout = UNSET, retry: MaybeRetry = UNSET) -> CascadeRepairReport
```

Re-point packages' rolling tags at the content their versions imply.

Publishes nothing new — every index it writes references content the
registry already serves. `mutating=not dry_run` (D5), as `copy`:
the preview writes nothing and keeps the session retry policy.

**Report-then-fail** like `cascade_check`: exit 65 with the report
when a finding remains — on a `dry_run`, having planned anything is
the finding — so `report.clean` is the answer, not an exception.

Repairing the registry does not update the public index. Pass
`announce_tags` to record the tags this run moved, then hand that
file to `announce(..., tags_file=...)`.

**Parameters**

- `*refs` (`PackageLike`) (default: `()`) — Packages to repair.
- `dry_run` (`bool`) (default: `False`) — Compute and report the plan without writing.
- `announce_tags` (`str | Path | None`) (default: `None`) — Write the rolling tags this run moved or created to this file, one per line. Takes one package per run — ocx exits 64 when it is given more.
- `timeout` (`MaybeTimeout`) (default: `UNSET`) — Seconds per attempt. Omitted takes the config's.
- `retry` (`MaybeRetry`) (default: `UNSET`) — Retry policy. `None` opts out; omitted takes the config's — which D5 resolves to no retries unless `dry_run`.

**Returns**

- (`CascadeRepairReport`) — One entry per package, carrying the exit code.

**Raises**

- `UsageError` — A package names a digest or a non-version tag, or
`announce_tags` was given with more than one package (exit 64).
- `DataError` — Exit 65 *without* a report.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_client.py#L3277-L3327)

### ocx_sdk.PackageCommands.pull

*method*

```python
def pull(*refs: PackageLike, platform: str | None = None, verify: bool | None = None, timeout: MaybeTimeout = UNSET, retry: MaybeRetry = UNSET) -> Mapping[str, str]
```

Download packages into the store without creating symlinks.

**Parameters**

- `*refs` (`PackageLike`) (default: `()`) — Package identifiers.
- `platform` (`str | None`) (default: `None`) — The platform to resolve against.
- `verify` (`bool | None`) (default: `None`) — Verify each package's Sigstore signature before storing it. `None` leaves ocx's default, which is on. The gate fires only where a `[[trust.policy]]` covers the package, so `True` against an uncovered package is a documented no-op rather than enforcement. `False` also beats an ambient `OCX_NO_VERIFY`, which the SDK neutralizes on every spawn.
- `timeout` (`MaybeTimeout`) (default: `UNSET`) — Seconds per attempt. Omitted takes the config's.
- `retry` (`MaybeRetry`) (default: `UNSET`) — Retry policy. `None` opts out; omitted takes the config's.

**Returns**

- (`Mapping[str, str]`) — A store path per identifier — a bare string here, unlike the
- (`Mapping[str, str]`) — project tier's `pull` and unlike `which`.

**Raises**

- `OcxProcessError` — ocx 0.6 verifies a covered package's signature
before storing it, so this call can fail where the identical
call against a 0.5.x binary succeeded — no code change on the
caller's side, only a newer binary. The exit codes, and why
none of them retry, are in the guide's "Errors & credentials"
section on verification.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_client.py#L1988-L2023)
