Skip to content
ocx
install

SignatureFormat to ensure

SignatureFormatattribute#

Re-exported from ocx_sdk._typesView source
SignatureFormat

ocx --signature-format values. A Literal because nothing but argv consumes it.

TESTED_OCX_VERSIONattributemodule attribute#

Re-exported from ocx_sdk._typesView source
TESTED_OCX_VERSION: Final = '0.6.2'

The ocx version this SDK’s contract tests run against.

Transportattribute#

Re-exported from ocx_sdk._clientView source
Transport

ocx --transport values — how a forge write is made. git is GitLab-only.

UNSETattributemodule attribute#

Re-exported from ocx_sdk._clientView source
UNSET: Final = _Unset.TOKEN

The default for every per-call retry=/timeout=, meaning “not given”.

Public so that a wrapper around this SDK can pass a caller’s override straight through without having to invent its own three-state sentinel: def deploy(*, retry: MaybeRetry = UNSET): ocx.package.push(..., retry=retry).

ensurefunction#

Re-exported from ocx_sdk._bootstrapView source
def ensure(version: str | None = None, *, channel: Channel = Channel.STABLE, dist: _dist.DistSource | None = None, mirror_url: str | None = None, ca_bundle: str | None = None, min_version: str | None = None, cache_dir: Path | None = None, env: HostEnv | None = None, trust_cache: bool = False, retry: RetryPolicy | None = None, timeout: float | None = None) -> Path

Provision a verified ocx binary and return its path.

Idempotent and offline-friendly: a cache hit that still hashes correctly needs no network at all. Every knob resolves explicit argument first, then the matching OCX_INSTALL_* variable from env, then the default.

Parameters

NameTypeDefaultDescription
versionstr | NoneNoneExact version to install. None takes the channel’s latest, then OCX_INSTALL_VERSION.
channelChannelChannel.STABLEChannel consulted when version is None. No variable — the setup script has none either.
dist_dist.DistSource | NoneNoneWhere the manifest comes from. None builds the default source, which honors OCX_INSTALL_DIST_URL; an explicitly constructed source does not.
mirror_urlstr | NoneNoneBase URL that replaces the artifact host, as <mirror_url>/<tag>/<filename>, falling back to OCX_INSTALL_MIRROR_URL. The manifest digest is still enforced — a mirror relocates bytes, it never revalidates them.
ca_bundlestr | NoneNonePEM file trusted for every download, replacing the system trust store, falling back to OCX_INSTALL_CA_BUNDLE. For a TLS-intercepting proxy; the digest checks are unaffected.
min_versionstr | NoneNoneOperator floor. A resolved version below it fails loudly instead of installing something older than the caller allows.
cache_dirPath | NoneNoneCache root. None uses the per-user cache directory.
envHostEnv | NoneNoneEnvironment snapshot. None reads the ambient one.
trust_cacheboolFalseSkip the digest re-check on a cache hit. Orthogonal to OCX_INSTALL_FORCE, which reinstalls even on a cache hit and has no argument of its own.
retryRetryPolicy | NoneNonePolicy for transient transport failures; None tries once.
timeoutfloat | NoneNonePer-attempt network budget in seconds.

Returns

Path
Path to the installed binary, mode 0o700.

Raises

BootstrapError
The cache root is untrusted, or the resolved version is below min_version.
DistManifestError
The manifest is unusable, or its archive is.
UnsupportedPlatformError
No release matches this platform.
ChecksumMismatchError
Downloaded bytes do not match the manifest. Never retried — the bytes are wrong, not late.
DownloadError
The manifest or artifact could not be fetched, or the CA bundle could not be loaded.