# ocx_sdk

*module*

Python SDK for [OCX](https://github.com/ocx-sh/ocx).

`ocx-sdk` drives the ocx binary rather than reimplementing it: ocx owns
resolution, verification, and the identifier grammar, and this package gives
you typed, CWD-independent handles over the commands it exposes.

```python
from ocx_sdk import Ocx, bootstrap

ocx = Ocx(exe=bootstrap.ensure())
project = ocx.project("/srv/build")
project.pull()
project.exec(["task", "verify"])
```

**This module is the API.** Everything listed in `__all__` is the stable
surface; every other module is underscored and package-private, and the one
public submodule is `ocx_sdk.bootstrap`. Reaching into an underscored path
means the next release may move it without notice — pre-1.0, breaking
changes ship without shims.

Start at `Ocx` for the runtime API and `bootstrap.ensure` for provisioning.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/__init__.py#L1-L1)

## ocx_sdk.PackageCommands

*class* · *dataclass*

```python
class PackageCommands
```

Re-exported from: `ocx_sdk._client`

The `ocx package` command group — machine tier.

Package operations act on the `$OCX_HOME` store and its candidate and
current symlinks. They take no project path and are CWD-independent by
construction; a path appears only where the CLI itself takes one.

Every method is multi-identifier native, mirroring the CLI's `PKG...`
with one shared resolution.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_client.py#L1470-L3367)

### ocx_sdk.PackageCommands.create

*method*

```python
def create(path: str | Path, *, identifier: str | None = None, platform: str | None = None, output: str | Path | None = None, metadata: str | Path | None = None, force: bool = False, compression_level: Literal['fast', 'best', 'default'] | None = None, threads: int | None = None, bin_scan: bool | None = None, libc_lint: bool = True, timeout: MaybeTimeout = UNSET, retry: MaybeRetry = UNSET) -> None
```

Bundle a local directory into a package archive.

Writes the bundle, a compiled metadata sidecar when `metadata` is
given, and a build receipt that `push` and `test` read back. There is
nothing to return: ocx prints no payload for this command.

**Parameters**

- `path` (`str | Path`) — The package directory to bundle.
- `identifier` (`str | None`) (default: `None`) — The identifier the bundle will be published under. Recorded in the receipt, where `push` finds it.
- `platform` (`str | None`) (default: `None`) — The platform the content runs on. Required whenever `metadata` is given.
- `output` (`str | Path | None`) (default: `None`) — The output file or directory.
- `metadata` (`str | Path | None`) (default: `None`) — A `metadata.json` to validate, resolve, and write beside the bundle.
- `force` (`bool`) (default: `False`) — Overwrite an existing output file.
- `compression_level` (`Literal['fast', 'best', 'default'] | None`) (default: `None`) — How hard to compress the bundle. `None` leaves ocx's own default.
- `threads` (`int | None`) (default: `None`) — Compression threads. `0` auto-detects, `1` is single-threaded; `None` leaves ocx's own default.
- `bin_scan` (`bool | None`) (default: `None`) — Scan the content tree for the executables the package puts on `PATH`, verifying a declared `binaries` claim or filling an absent one. Needs `metadata`. `None` leaves ocx's own default, which fills an absent claim.
- `libc_lint` (`bool`) (default: `True`) — Check the packaged binaries against the platform's declared `os.features`. `False` is an escape hatch, not a convenience: it publishes a package that may not run on hosts the declaration claims.
- `timeout` (`MaybeTimeout`) (default: `UNSET`) — Seconds per attempt. Omitted takes the config's.
- `retry` (`MaybeRetry`) (default: `UNSET`) — Retry policy. `None` opts out; omitted takes the config's.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_client.py#L2025-L2085)

### ocx_sdk.PackageCommands.env

*method*

```python
def env(*refs: PackageLike, platform: str | None = None, env: Mapping[str, EnvValue] | None = None, resolve: Resolve | None = None, private: bool = False, lazy_mode: LazyMode | None = None, show_patches: bool = False, timeout: MaybeTimeout = UNSET, retry: MaybeRetry = UNSET) -> EnvReport
```

Report the environment a set of packages composes.

Returns the same envelope as the project-tier `env`, and carries the
same host snapshot for a hermetic `compose()`.

**Parameters**

- `*refs` (`PackageLike`) (default: `()`) — Package identifiers.
- `platform` (`str | None`) (default: `None`) — The platform to resolve against.
- `env` (`Mapping[str, EnvValue] | None`) (default: `None`) — Extra `[env]` entries for this call.
- `resolve` (`Resolve | None`) (default: `None`) — Which store symlink to resolve through — `'candidate'` or `'current'`. `None` leaves the choice to ocx. One value, not two booleans: ocx's `--candidate` and `--current` name one link each, so a pair of flags could ask for both.
- `private` (`bool`) (default: `False`) — Compose the private surface instead of the interface one — ocx's `--self`.
- `lazy_mode` (`LazyMode | None`) (default: `None`) — When content downloads — now, or on first use.
- `show_patches` (`bool`) (default: `False`) — Include patch-contributed entries.
- `timeout` (`MaybeTimeout`) (default: `UNSET`) — Seconds per attempt. Omitted takes the config's.
- `retry` (`MaybeRetry`) (default: `UNSET`) — Retry policy. `None` opts out; omitted takes the config's.

**Returns**

- (`EnvReport`) — The typed entries plus the full envelope.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_client.py#L1596-L1642)
