Skip to main content

holosdb

An RDF 1.2 triplestore with SPARQL 1.2, where access policy is enforced at the index scan rather than by rewriting queries.

pip install holosdb
from holosdb import Store, Principal, Policy

store = Store()                    # in memory
store = Store("./var/db")          # persistent
store.load("data.trig")
store.load("dump.nq.gz")           # gzip: streamed, multi-member safe

for row in store.query("SELECT ?s ?name WHERE { ?s <http://example.com/name> ?name }"):
    print(row["s"], row["name"])

Asking a question as somebody

This is the part no other binding in this ecosystem has. A query can carry a principal and a policy, and the answer comes back filtered to what that principal may see:

policy = (Policy()
          .deny_predicate("http://example.com/salary", except_role="hr")
          .label_graph("http://example.com/reviews", 3))

anyone = Principal.anonymous()
hr     = Principal("urn:user:alice", roles=["hr"], clearance=3)

store.query(q, principal=anyone, policy=policy)   # no salaries, no reviews
store.query(q, principal=hr,     policy=policy)   # both

Because the filtering happens at the scan and not above it:

the answer to Q equals the answer Q would have over the sub-dataset the principal may see.

That holds for every query shape without anyone enumerating them. A COUNT cannot leak the existence of hidden rows, and a FILTER NOT EXISTS cannot probe for them.

Use Policy().fail_closed() when a partial answer would be misread as a complete one — a compliance report, a reconciliation total — and an error is better than a quiet omission.

What else is here

store.validate("shapes.ttl")            # SHACL, {'conforms': False, 'violations': 12, ...}
store.named_graphs()
store.dictionary_size                   # smaller than you expect: see below
holosdb.geosparql_functions()             # 45 of them
holosdb.has_rocksdb()                     # what this wheel actually contains

GeoSPARQL works through the ordinary query path, so it composes with policy — denying geo:asWKT makes a spatial join find nothing:

store.query("""
  PREFIX geof: <http://www.opengis.net/def/function/geosparql/>
  PREFIX uom:  <http://www.opengis.net/def/uom/OGC/1.0/>
  SELECT ?site WHERE {
    ?site <http://www.opengis.net/ont/geosparql#asWKT> ?g .
    FILTER(geof:sfWithin(?g, geof:buffer(?depot, 5, uom:kilometre)))
  }
""")

dictionary_size is reliably smaller than the number of terms — every integer, float, dateTime and short string is packed into its own 64-bit id and never reaches the dictionary. A million triples produced 489,479 dictionary entries.

Threading

A Store is safe to share across threads, and the GIL is released around every query and every load. Concurrent readers genuinely run concurrently rather than taking turns.

What is not here

store.update(...) raises NotImplementedError. There is no SPARQL Update evaluator in this build — raising is deliberate, because silently accepting an update that did nothing would be much worse than an error. Writes go through add() and load().

Persistence is compiled into the wheel rather than installed beside it, so pip install holosdb[rocksdb] is accepted but installs nothing; the published wheels already have it. PACKAGING.md explains why a Python extra cannot do otherwise, and has_rocksdb() reports what you actually got.

Licence

MIT or Apache-2.0, at your option.

Release files for holosdb 0.3.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for holosdb 0.3.0
File Size Uploaded
holosdb-0.3.0.tar.gz 442.5 kB Details

Built distributions (wheels)

Table of built distributions (wheels) for holosdb 0.3.0
File
holosdb-0.3.0-cp39-abi3-win_amd64.whl CPython 3.9 abi3 Windows x86-64 Details
holosdb-0.3.0-cp39-abi3-manylinux_2_28_x86_64.whl CPython 3.9 abi3 Linux glibc 2.28+ x86-64 Details
holosdb-0.3.0-cp39-abi3-manylinux_2_28_aarch64.whl CPython 3.9 abi3 Linux glibc 2.28+ ARM64 Details
holosdb-0.3.0-cp39-abi3-macosx_11_0_arm64.whl CPython 3.9 abi3 macOS 11.0+ ARM64 Details
holosdb-0.3.0-cp39-abi3-macosx_10_13_x86_64.whl CPython 3.9 abi3 macOS 10.13+ x86-64 Details

Total release size: 29.0 MB

Release files / holosdb-0.3.0.tar.gz

Download URL holosdb-0.3.0.tar.gz
Size 442.5 kB
Tags Source
SHA-256 checksum
How to use checksums
de0dac0cf9e7f8a0c305cc947cc5415f0d31f455abe8750e9647dbee95e52496
BLAKE2b-256 checksum
How to use checksums
09d27156eb40ff2875c387e040d2c8cd49d15e801acbfd6aa19150053123fee8
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 3, 2026.

Transparency log

Release files / holosdb-0.3.0-cp39-abi3-win_amd64.whl

Download URL holosdb-0.3.0-cp39-abi3-win_amd64.whl
Size 5.3 MB
Tags CPython 3.9 Windows x86-64 abi3
SHA-256 checksum
How to use checksums
f61a24d0558ab335e939039c5a5a49a00b3f06d52703928713170e3e943de34d
BLAKE2b-256 checksum
How to use checksums
d98d49ed4ea2b562c9b58e26ac137447886199116ca3b85226aeb2e1893e44c3
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 3, 2026.

Transparency log

Release files / holosdb-0.3.0-cp39-abi3-manylinux_2_28_x86_64.whl

Download URL holosdb-0.3.0-cp39-abi3-manylinux_2_28_x86_64.whl
Size 6.6 MB
Tags CPython 3.9 Linux glibc 2.28+ x86-64 abi3
SHA-256 checksum
How to use checksums
9c7f71e478d0db3cf04fd52877c365c0eca39f406aea4cd820acad31e506862b
BLAKE2b-256 checksum
How to use checksums
38c23a5640498d78774dcc1a156f667fe3542b1348e56212eb69e92aaf98dc56
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 3, 2026.

Transparency log

Release files / holosdb-0.3.0-cp39-abi3-manylinux_2_28_aarch64.whl

Download URL holosdb-0.3.0-cp39-abi3-manylinux_2_28_aarch64.whl
Size 6.0 MB
Tags CPython 3.9 Linux glibc 2.28+ ARM64 abi3
SHA-256 checksum
How to use checksums
b45515bff815a2ce225eb6cf4ad44ae04d9d5231cad9145c8555089167c94759
BLAKE2b-256 checksum
How to use checksums
04f7667d30b154b5df5d5a217af4c1ce34691bce17e1a15faba72529b13b92d3
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 3, 2026.

Transparency log

Release files / holosdb-0.3.0-cp39-abi3-macosx_11_0_arm64.whl

Download URL holosdb-0.3.0-cp39-abi3-macosx_11_0_arm64.whl
Size 5.1 MB
Tags CPython 3.9 abi3 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
16ad9bb8814b9d6b28d6db0ab41bd5d42645139f629854ad70b031e157d1e072
BLAKE2b-256 checksum
How to use checksums
f901208fbb47b24ebef6de2d6d40df614d86ad3fdfd76203d088d16ca3c475cd
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 3, 2026.

Transparency log

Release files / holosdb-0.3.0-cp39-abi3-macosx_10_13_x86_64.whl

Download URL holosdb-0.3.0-cp39-abi3-macosx_10_13_x86_64.whl
Size 5.6 MB
Tags CPython 3.9 abi3 macOS 10.13+ x86-64
SHA-256 checksum
How to use checksums
fbe9f0bdd1d8003ceb4a2695e742f138f7899cbaaf8544a0d8bfb88dbbf205c9
BLAKE2b-256 checksum
How to use checksums
673abc216ec936fb03ae329d2fb1dba561579b2e104cc08877b09c0842b4162b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 3, 2026.

Transparency log

Release history Release notifications | RSS feed

0.14.0

6 release files

0.13.0

6 release files

0.12.0

6 release files

0.11.0

6 release files

0.10.0

6 release files

0.9.0

6 release files

0.7.0

6 release files

0.6.0

6 release files

0.5.0

6 release files

0.4.0

6 release files

This release

0.3.0 This release

6 release files

0.2.0

6 release files

0.1.1

6 release files

0.1.0

6 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page