Skip to content
ocx
install

PackageCommands (2 of 16)

PackageCommandsclassdataclass#

Re-exported from ocx_sdk._clientView source

cascade_repairmethod#

def cascade_repair(*refs: PackageLike, dry_run: bool = False, announce_tags: str | Path | None = None, timeout: MaybeTimeout = UNSET, retry: MaybeRetry = UNSET) -> CascadeRepairReport

Re-point packages’ rolling tags at the content their versions imply.

Publishes nothing new — every index it writes references content the registry already serves. mutating=not dry_run (D5), as copy: the preview writes nothing and keeps the session retry policy.

Report-then-fail like cascade_check: exit 65 with the report when a finding remains — on a dry_run, having planned anything is the finding — so report.clean is the answer, not an exception.

Repairing the registry does not update the public index. Pass announce_tags to record the tags this run moved, then hand that file to announce(..., tags_file=...).

Parameters

NameTypeDefaultDescription
*refsPackageLike()Packages to repair.
dry_runboolFalseCompute and report the plan without writing.
announce_tagsstr | Path | NoneNoneWrite the rolling tags this run moved or created to this file, one per line. Takes one package per run — ocx exits 64 when it is given more.
timeoutMaybeTimeoutUNSETSeconds per attempt. Omitted takes the config’s.
retryMaybeRetryUNSETRetry policy. None opts out; omitted takes the config’s — which D5 resolves to no retries unless dry_run.

Returns

CascadeRepairReport
One entry per package, carrying the exit code.

Raises

UsageError
A package names a digest or a non-version tag, or announce_tags was given with more than one package (exit 64).
DataError
Exit 65 without a report.

pullmethod#

def pull(*refs: PackageLike, platform: str | None = None, verify: bool | None = None, timeout: MaybeTimeout = UNSET, retry: MaybeRetry = UNSET) -> Mapping[str, str]

Download packages into the store without creating symlinks.

Parameters

NameTypeDefaultDescription
*refsPackageLike()Package identifiers.
platformstr | NoneNoneThe platform to resolve against.
verifybool | NoneNoneVerify each package’s Sigstore signature before storing it. None leaves ocx’s default, which is on. The gate fires only where a [[trust.policy]] covers the package, so True against an uncovered package is a documented no-op rather than enforcement. False also beats an ambient OCX_NO_VERIFY, which the SDK neutralizes on every spawn.
timeoutMaybeTimeoutUNSETSeconds per attempt. Omitted takes the config’s.
retryMaybeRetryUNSETRetry policy. None opts out; omitted takes the config’s.

Returns

Mapping[str, str]
A store path per identifier — a bare string here, unlike the
Mapping[str, str]
project tier’s pull and unlike which.

Raises

OcxProcessError
ocx 0.6 verifies a covered package’s signature before storing it, so this call can fail where the identical call against a 0.5.x binary succeeded — no code change on the caller’s side, only a newer binary. The exit codes, and why none of them retry, are in the guide’s “Errors & credentials” section on verification.