Skip to main content

holosdb

An RDF 1.2 triplestore with SPARQL 1.2, where access policy is enforced at the index scan rather than by rewriting queries.

pip install holosdb
from holosdb import Store, Principal, Policy

store = Store()                    # in memory
store = Store("./var/db")          # persistent
store.load("data.trig")
store.load("dump.nq.gz")           # gzip: streamed, multi-member safe

for row in store.query("SELECT ?s ?name WHERE { ?s <http://example.com/name> ?name }"):
    print(row["s"], row["name"])

Asking a question as somebody

This is the part no other binding in this ecosystem has. A query can carry a principal and a policy, and the answer comes back filtered to what that principal may see:

policy = (Policy()
          .deny_predicate("http://example.com/salary", except_role="hr")
          .label_graph("http://example.com/reviews", 3))

anyone = Principal.anonymous()
hr     = Principal("urn:user:alice", roles=["hr"], clearance=3)

store.query(q, principal=anyone, policy=policy)   # no salaries, no reviews
store.query(q, principal=hr,     policy=policy)   # both

Because the filtering happens at the scan and not above it:

the answer to Q equals the answer Q would have over the sub-dataset the principal may see.

That holds for every query shape without anyone enumerating them. A COUNT cannot leak the existence of hidden rows, and a FILTER NOT EXISTS cannot probe for them.

Use Policy().fail_closed() when a partial answer would be misread as a complete one — a compliance report, a reconciliation total — and an error is better than a quiet omission.

What else is here

store.validate("shapes.ttl")            # SHACL, {'conforms': False, 'violations': 12, ...}
store.named_graphs()
store.dictionary_size                   # smaller than you expect: see below
holosdb.geosparql_functions()             # 45 of them
holosdb.has_rocksdb()                     # what this wheel actually contains

GeoSPARQL works through the ordinary query path, so it composes with policy — denying geo:asWKT makes a spatial join find nothing:

store.query("""
  PREFIX geof: <http://www.opengis.net/def/function/geosparql/>
  PREFIX uom:  <http://www.opengis.net/def/uom/OGC/1.0/>
  SELECT ?site WHERE {
    ?site <http://www.opengis.net/ont/geosparql#asWKT> ?g .
    FILTER(geof:sfWithin(?g, geof:buffer(?depot, 5, uom:kilometre)))
  }
""")

dictionary_size is reliably smaller than the number of terms — every integer, float, dateTime and short string is packed into its own 64-bit id and never reaches the dictionary. A million triples produced 489,479 dictionary entries.

Threading

A Store is safe to share across threads, and the GIL is released around every query and every load. Concurrent readers genuinely run concurrently rather than taking turns.

What is not here

store.update(...) raises NotImplementedError. There is no SPARQL Update evaluator in this build — raising is deliberate, because silently accepting an update that did nothing would be much worse than an error. Writes go through add() and load().

Persistence is compiled into the wheel rather than installed beside it, so pip install holosdb[rocksdb] is accepted but installs nothing; the published wheels already have it. PACKAGING.md explains why a Python extra cannot do otherwise, and has_rocksdb() reports what you actually got.

Licence

MIT or Apache-2.0, at your option.

Release files for holosdb 0.14.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for holosdb 0.14.0
File Size Uploaded
holosdb-0.14.0.tar.gz 602.5 kB Details

Built distributions (wheels)

Table of built distributions (wheels) for holosdb 0.14.0
File
holosdb-0.14.0-cp39-abi3-win_amd64.whl CPython 3.9 abi3 Windows x86-64 Details
holosdb-0.14.0-cp39-abi3-manylinux_2_28_x86_64.whl CPython 3.9 abi3 Linux glibc 2.28+ x86-64 Details
holosdb-0.14.0-cp39-abi3-manylinux_2_28_aarch64.whl CPython 3.9 abi3 Linux glibc 2.28+ ARM64 Details
holosdb-0.14.0-cp39-abi3-macosx_11_0_arm64.whl CPython 3.9 abi3 macOS 11.0+ ARM64 Details
holosdb-0.14.0-cp39-abi3-macosx_10_13_x86_64.whl CPython 3.9 abi3 macOS 10.13+ x86-64 Details

Total release size: 29.8 MB

Release files / holosdb-0.14.0.tar.gz

Download URL holosdb-0.14.0.tar.gz
Size 602.5 kB
Tags Source
SHA-256 checksum
How to use checksums
b432bca26afbafe8029076af2374be5e9c05f066622c82be32f7796e2183a765
BLAKE2b-256 checksum
How to use checksums
ca8600462b2ea82d181ba2b73ee6de5c223c62d3c01af29d662a81634a922356
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 24, 2026.

Transparency log

Release files / holosdb-0.14.0-cp39-abi3-win_amd64.whl

Download URL holosdb-0.14.0-cp39-abi3-win_amd64.whl
Size 5.4 MB
Tags CPython 3.9 Windows x86-64 abi3
SHA-256 checksum
How to use checksums
7a1f1d44c288bf15a170b3919c097a416be329afb475c7e7f5547a572630b1a8
BLAKE2b-256 checksum
How to use checksums
1de45d7a3db4ee28edf528ad62c7183e00e0b261e5650b1ef123d3a6803a4d76
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 24, 2026.

Transparency log

Release files / holosdb-0.14.0-cp39-abi3-manylinux_2_28_x86_64.whl

Download URL holosdb-0.14.0-cp39-abi3-manylinux_2_28_x86_64.whl
Size 6.7 MB
Tags CPython 3.9 Linux glibc 2.28+ x86-64 abi3
SHA-256 checksum
How to use checksums
ddc95ff833b58ab5108f0795ea6b1ff03c259db4f8de691515ed15d4aae3d3e0
BLAKE2b-256 checksum
How to use checksums
ca0e8c3d4b57747afff884759e7848711484af1e357e0d85cf26ee654ea9cfe2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 24, 2026.

Transparency log

Release files / holosdb-0.14.0-cp39-abi3-manylinux_2_28_aarch64.whl

Download URL holosdb-0.14.0-cp39-abi3-manylinux_2_28_aarch64.whl
Size 6.1 MB
Tags CPython 3.9 Linux glibc 2.28+ ARM64 abi3
SHA-256 checksum
How to use checksums
10631de6a9f5f8b209352debdad7a94f19f5703215b021fb0212d34a62595618
BLAKE2b-256 checksum
How to use checksums
9734fbb53ac061973311774dedf215ce214cb774ff720d2fd98309b0e546e507
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 24, 2026.

Transparency log

Release files / holosdb-0.14.0-cp39-abi3-macosx_11_0_arm64.whl

Download URL holosdb-0.14.0-cp39-abi3-macosx_11_0_arm64.whl
Size 5.2 MB
Tags CPython 3.9 abi3 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
b0d050afe9caea9371c6b8b9f6a875f52c1d1cf3fb93cf9f3e81ca9690cd395d
BLAKE2b-256 checksum
How to use checksums
5d590129c2b3df59f407ec645478af5f248e714c45f9a81e885e7b921860199d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 24, 2026.

Transparency log

Release files / holosdb-0.14.0-cp39-abi3-macosx_10_13_x86_64.whl

Download URL holosdb-0.14.0-cp39-abi3-macosx_10_13_x86_64.whl
Size 5.7 MB
Tags CPython 3.9 abi3 macOS 10.13+ x86-64
SHA-256 checksum
How to use checksums
50fbe6720b7662c12cd1e34eaa643b830f8a1e63a3a2e168e503eaabb9fbff94
BLAKE2b-256 checksum
How to use checksums
18eec63cdc8df9e57f264ffc06ea5ce258b18b6f2d69649be9e7be804d23c634
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 24, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.14.0 This release

6 release files

0.13.0

6 release files

0.12.0

6 release files

0.11.0

6 release files

0.10.0

6 release files

0.9.0

6 release files

0.7.0

6 release files

0.6.0

6 release files

0.5.0

6 release files

0.4.0

6 release files

0.3.0

6 release files

0.2.0

6 release files

0.1.1

6 release files

0.1.0

6 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page