Skip to main content

holosdb

An RDF 1.2 triplestore with SPARQL 1.2, where access policy is enforced at the index scan rather than by rewriting queries.

pip install holosdb
from holosdb import Store, Principal, Policy

store = Store()                    # in memory
store = Store("./var/db")          # persistent
store.load("data.trig")
store.load("dump.nq.gz")           # gzip: streamed, multi-member safe

for row in store.query("SELECT ?s ?name WHERE { ?s <http://example.com/name> ?name }"):
    print(row["s"], row["name"])

Asking a question as somebody

This is the part no other binding in this ecosystem has. A query can carry a principal and a policy, and the answer comes back filtered to what that principal may see:

policy = (Policy()
          .deny_predicate("http://example.com/salary", except_role="hr")
          .label_graph("http://example.com/reviews", 3))

anyone = Principal.anonymous()
hr     = Principal("urn:user:alice", roles=["hr"], clearance=3)

store.query(q, principal=anyone, policy=policy)   # no salaries, no reviews
store.query(q, principal=hr,     policy=policy)   # both

Because the filtering happens at the scan and not above it:

the answer to Q equals the answer Q would have over the sub-dataset the principal may see.

That holds for every query shape without anyone enumerating them. A COUNT cannot leak the existence of hidden rows, and a FILTER NOT EXISTS cannot probe for them.

Use Policy().fail_closed() when a partial answer would be misread as a complete one — a compliance report, a reconciliation total — and an error is better than a quiet omission.

What else is here

store.validate("shapes.ttl")            # SHACL, {'conforms': False, 'violations': 12, ...}
store.named_graphs()
store.dictionary_size                   # smaller than you expect: see below
holosdb.geosparql_functions()             # 45 of them
holosdb.has_rocksdb()                     # what this wheel actually contains

GeoSPARQL works through the ordinary query path, so it composes with policy — denying geo:asWKT makes a spatial join find nothing:

store.query("""
  PREFIX geof: <http://www.opengis.net/def/function/geosparql/>
  PREFIX uom:  <http://www.opengis.net/def/uom/OGC/1.0/>
  SELECT ?site WHERE {
    ?site <http://www.opengis.net/ont/geosparql#asWKT> ?g .
    FILTER(geof:sfWithin(?g, geof:buffer(?depot, 5, uom:kilometre)))
  }
""")

dictionary_size is reliably smaller than the number of terms — every integer, float, dateTime and short string is packed into its own 64-bit id and never reaches the dictionary. A million triples produced 489,479 dictionary entries.

Threading

A Store is safe to share across threads, and the GIL is released around every query and every load. Concurrent readers genuinely run concurrently rather than taking turns.

What is not here

store.update(...) raises NotImplementedError. There is no SPARQL Update evaluator in this build — raising is deliberate, because silently accepting an update that did nothing would be much worse than an error. Writes go through add() and load().

Persistence is compiled into the wheel rather than installed beside it, so pip install holosdb[rocksdb] is accepted but installs nothing; the published wheels already have it. PACKAGING.md explains why a Python extra cannot do otherwise, and has_rocksdb() reports what you actually got.

Licence

MIT or Apache-2.0, at your option.

Release files for holosdb 0.11.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for holosdb 0.11.0
File Size Uploaded
holosdb-0.11.0.tar.gz 568.0 kB Details

Built distributions (wheels)

Table of built distributions (wheels) for holosdb 0.11.0
File
holosdb-0.11.0-cp39-abi3-win_amd64.whl CPython 3.9 abi3 Windows x86-64 Details
holosdb-0.11.0-cp39-abi3-manylinux_2_28_x86_64.whl CPython 3.9 abi3 Linux glibc 2.28+ x86-64 Details
holosdb-0.11.0-cp39-abi3-manylinux_2_28_aarch64.whl CPython 3.9 abi3 Linux glibc 2.28+ ARM64 Details
holosdb-0.11.0-cp39-abi3-macosx_11_0_arm64.whl CPython 3.9 abi3 macOS 11.0+ ARM64 Details
holosdb-0.11.0-cp39-abi3-macosx_10_13_x86_64.whl CPython 3.9 abi3 macOS 10.13+ x86-64 Details

Total release size: 29.6 MB

Release files / holosdb-0.11.0.tar.gz

Download URL holosdb-0.11.0.tar.gz
Size 568.0 kB
Tags Source
SHA-256 checksum
How to use checksums
17760c62f81a8f1676e71f1762da0b7156e3987cf8cdf944a54dd4755414be64
BLAKE2b-256 checksum
How to use checksums
d892c999b840c193ca20710a22cc78ed4edc682b2b6271d7cd291528fd9eafa6
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 20, 2026.

Transparency log

Release files / holosdb-0.11.0-cp39-abi3-win_amd64.whl

Download URL holosdb-0.11.0-cp39-abi3-win_amd64.whl
Size 5.4 MB
Tags CPython 3.9 Windows x86-64 abi3
SHA-256 checksum
How to use checksums
fe2af4795eca4b13734be9375e964e7b703916d17706308d49796d5c6e5fc9f4
BLAKE2b-256 checksum
How to use checksums
b8bb6e8076961c3d3001d2190795218bed75994c7d889178a6569bce24460439
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 20, 2026.

Transparency log

Release files / holosdb-0.11.0-cp39-abi3-manylinux_2_28_x86_64.whl

Download URL holosdb-0.11.0-cp39-abi3-manylinux_2_28_x86_64.whl
Size 6.7 MB
Tags CPython 3.9 Linux glibc 2.28+ x86-64 abi3
SHA-256 checksum
How to use checksums
0d8e982fe8d8d5a144d5b865f87f91ca1399b56a37d5c169a8755f5897ba28e3
BLAKE2b-256 checksum
How to use checksums
1b852e54779f82ad70e76d0f4baa1d0b1afc571a8435c3288b531931e22479ff
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 20, 2026.

Transparency log

Release files / holosdb-0.11.0-cp39-abi3-manylinux_2_28_aarch64.whl

Download URL holosdb-0.11.0-cp39-abi3-manylinux_2_28_aarch64.whl
Size 6.1 MB
Tags CPython 3.9 Linux glibc 2.28+ ARM64 abi3
SHA-256 checksum
How to use checksums
92d87e5ec9e8e1abcfb3799605e6e4e7db5fc8d2321b5a2c09d4890f2495a36b
BLAKE2b-256 checksum
How to use checksums
8e8745a9c24537258d2a6d4779601556c7d4f953b49d761b7b3abb35cd61f75c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 20, 2026.

Transparency log

Release files / holosdb-0.11.0-cp39-abi3-macosx_11_0_arm64.whl

Download URL holosdb-0.11.0-cp39-abi3-macosx_11_0_arm64.whl
Size 5.2 MB
Tags CPython 3.9 abi3 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
43a5923eb80aada3cf064f5ac3c0fe8fe95e002b6a8ddab32ec39aae3e4371df
BLAKE2b-256 checksum
How to use checksums
52d51878047781be14de90b502eb307d992a56b4ac0d4bfe5977c06f3919dc81
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 20, 2026.

Transparency log

Release files / holosdb-0.11.0-cp39-abi3-macosx_10_13_x86_64.whl

Download URL holosdb-0.11.0-cp39-abi3-macosx_10_13_x86_64.whl
Size 5.7 MB
Tags CPython 3.9 abi3 macOS 10.13+ x86-64
SHA-256 checksum
How to use checksums
930595bd0bb692b4894a019079df9a8a38d0a38618be3070402d01354936be7b
BLAKE2b-256 checksum
How to use checksums
5c1f148a29a0baa2b73fb580f9630848c71be80b9ad20f26435d1ddc48689b71
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 20, 2026.

Transparency log

Release history Release notifications | RSS feed

0.14.0

6 release files

0.13.0

6 release files

0.12.0

6 release files

This release

0.11.0 This release

6 release files

0.10.0

6 release files

0.9.0

6 release files

0.7.0

6 release files

0.6.0

6 release files

0.5.0

6 release files

0.4.0

6 release files

0.3.0

6 release files

0.2.0

6 release files

0.1.1

6 release files

0.1.0

6 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page