# ocx_sdk

*module*

Python SDK for [OCX](https://github.com/ocx-sh/ocx).

`ocx-sdk` drives the ocx binary rather than reimplementing it: ocx owns
resolution, verification, and the identifier grammar, and this package gives
you typed, CWD-independent handles over the commands it exposes.

```python
from ocx_sdk import Ocx, bootstrap

ocx = Ocx(exe=bootstrap.ensure())
project = ocx.project("/srv/build")
project.pull()
project.exec(["task", "verify"])
```

**This module is the API.** Everything listed in `__all__` is the stable
surface; every other module is underscored and package-private, and the one
public submodule is `ocx_sdk.bootstrap`. Reaching into an underscored path
means the next release may move it without notice — pre-1.0, breaking
changes ship without shims.

Start at `Ocx` for the runtime API and `bootstrap.ensure` for provisioning.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/__init__.py#L1-L1)

## ocx_sdk.Project

*class* · *dataclass*

```python
class Project
```

Re-exported from: `ocx_sdk._client`

A project-tier handle: every call carries `--project <file>`.

Obtained from `Ocx.project(path)`, never constructed directly. Because
the path travels explicitly on every call, no method depends on the
working directory, and an ambient `OCX_PROJECT` can never retarget one.
`init` is the exception, and only because ocx's is: it takes no flags and
writes into the working directory, so the handle sets that instead.

> **Example**
>
> ```python
> from ocx_sdk import Ocx
> 
> project = Ocx().project("/srv/build")
> project.add("ocx.sh/go-task/task:3", group="ci")
> project.lock()
> report = project.env()
> environment = report.compose().mapping
> ```

**Attributes**

- `path` (`Path`) — The absolute project file — the `ocx.toml` itself, which is what ocx's `--project` names.
- `session_config` (`OcxConfig`) — The `OcxConfig` every call spawns under.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_client.py#L860-L1467)

### ocx_sdk.Project.exec

*method*

```python
def exec(argv: Sequence[str], *, names: Iterable[str] = (), groups: Iterable[str] = (), clean: bool = False, env: Mapping[str, EnvValue] | None = None, lazy_mode: LazyMode | None = None, pinned: bool | None = None, records_dir: str | Path | None = None, records_name: str | None = None, capture: bool = True, check: bool = True, timeout: MaybeTimeout = UNSET) -> CommandResult
```

Run a command inside the project's composed environment.

The child's exit code comes back byte for byte, so `check=False` is
how you inspect a failing build instead of catching an exception.
Child processes are never retried.

**Parameters**

- `argv` (`Sequence[str]`) — The command and its arguments. Must not be empty.
- `names` (`Iterable[str]`) (default: `()`) — Bindings to compose. Omitted composes the default set.
- `groups` (`Iterable[str]`) (default: `()`) — Groups to compose.
- `clean` (`bool`) (default: `False`) — Strip the ambient parent environment before composing.
- `env` (`Mapping[str, EnvValue] | None`) (default: `None`) — Extra `[env]` entries for this call.
- `lazy_mode` (`LazyMode | None`) (default: `None`) — When content downloads — now, or on first use.
- `pinned` (`bool | None`) (default: `None`) — Resolve through the rendered toolchain's pinned digests rather than following its links — ocx's `--pinned` / `--no-pinned`. `None` leaves the choice to `ocx.toml`, then `OCX_TOOLCHAIN_PINNED`, then ocx's default.
- `records_dir` (`str | Path | None`) (default: `None`) — Write an execution record — the resolved closure and executable, captured just before the child starts — under this directory, which must already exist (ocx warns and skips the record otherwise). `None` leaves it to `[records] dir` and `OCX_RECORDS_DIR`; with none of the three, no record.
- `records_name` (`str | None`) (default: `None`) — The record's filename template, over `{time}`, `{host}`, `{pid}` and `{rand}`. `None` leaves it to `[records] name` and `OCX_RECORDS_NAME`.
- `capture` (`bool`) (default: `True`) — Pipe and capture both streams. `False` inherits stdio and forwards SIGINT to the child.
- `check` (`bool`) (default: `True`) — Raise on a non-zero child exit instead of returning it.
- `timeout` (`MaybeTimeout`) (default: `UNSET`) — Seconds for the whole run. Omitted takes the config's.

**Returns**

- (`CommandResult`) — The child's exit code and, under `capture`, its output.

**Raises**

- `ValueError` — `argv` is empty — ocx requires a command after `--`.
- `OcxProcessError` — The child exited non-zero under `check`.
- `OcxTimeoutError` — The timeout expired.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_client.py#L1251-L1308)

### ocx_sdk.Project.with_config

*method*

```python
def with_config(**overrides: Unpack[ConfigOverrides]) -> Project
```

Derive a project handle with some configuration fields replaced.

**Parameters**

- `**overrides` (`Unpack[ConfigOverrides]`) (default: `{}`) — `OcxConfig` field names and their new values, as `ConfigOverrides` spells them.

**Returns**

- (`Project`) — The same project, seen through a derived `Ocx`.

**Raises**

- `TypeError` — An override names no `OcxConfig` field.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_client.py#L918-L931)
