# ocx_sdk

*module*

Python SDK for [OCX](https://github.com/ocx-sh/ocx).

`ocx-sdk` drives the ocx binary rather than reimplementing it: ocx owns
resolution, verification, and the identifier grammar, and this package gives
you typed, CWD-independent handles over the commands it exposes.

```python
from ocx_sdk import Ocx, bootstrap

ocx = Ocx(exe=bootstrap.ensure())
project = ocx.project("/srv/build")
project.pull()
project.exec(["task", "verify"])
```

**This module is the API.** Everything listed in `__all__` is the stable
surface; every other module is underscored and package-private, and the one
public submodule is `ocx_sdk.bootstrap`. Reaching into an underscored path
means the next release may move it without notice — pre-1.0, breaking
changes ship without shims.

Start at `Ocx` for the runtime API and `bootstrap.ensure` for provisioning.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/__init__.py#L1-L1)

## ocx_sdk.WhichResult

*class* · *dataclass*

```python
class WhichResult
```

Re-exported from: `ocx_sdk._results`

Where one identifier resolves on disk, per `package which`.

**Attributes**

- `path` (`str`) — The resolved location.
- `kind` (`str`) — `"package"` for a store directory, `"shim"` for a shim.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1096-L1111)

### ocx_sdk.WhichResult.kind

*attribute* · *instance attribute*

```python
kind: str
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1106-L1106)

### ocx_sdk.WhichResult.path

*attribute* · *instance attribute*

```python
path: str
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1105-L1105)

### ocx_sdk.WhichResult.from_dict

*method* · *classmethod*

```python
def from_dict(data: Mapping[str, Any]) -> WhichResult
```

Build from one decoded value of the keyed object.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1108-L1111)

## ocx_sdk.error_envelope

*function*

```python
def error_envelope(error: OcxProcessError) -> ErrorEnvelope | None
```

Re-exported from: `ocx_sdk._results`

Return the structured failure a non-zero exit carried, else `None`.

The dual of `partial_report`: where that recovers the *report* a
report-then-fail command wrote, this recovers the *envelope* a hard
failure wrote instead. A failure never carries both, so for any one
error at most one of the two answers.

```python
try:
    ocx.package.claim("acme/widget", repository="oci://ghcr.io/acme/widget")
except DataError as exc:
    envelope = error_envelope(exc)
    if envelope is None or "already claimed" not in envelope.message:
        raise
```

**Parameters**

- `error` (`OcxProcessError`) — The caught process failure.

**Returns**

- (`ErrorEnvelope | None`) — `None` when stdout is empty, is not JSON, or is a report rather than
- (`ErrorEnvelope | None`) — an envelope. Otherwise the parsed envelope.

**Raises**

- `ValueError` — stdout is an envelope missing one of its frozen keys —
a binary outside the tested window, not a recoverable state.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L380-L414)
