Skip to main content

holosdb

An RDF 1.2 triplestore with SPARQL 1.2, where access policy is enforced at the index scan rather than by rewriting queries.

pip install holosdb
from holosdb import Store, Principal, Policy

store = Store()                    # in memory
store = Store("./var/db")          # persistent
store.load("data.trig")
store.load("dump.nq.gz")           # gzip: streamed, multi-member safe

for row in store.query("SELECT ?s ?name WHERE { ?s <http://example.com/name> ?name }"):
    print(row["s"], row["name"])

Asking a question as somebody

This is the part no other binding in this ecosystem has. A query can carry a principal and a policy, and the answer comes back filtered to what that principal may see:

policy = (Policy()
          .deny_predicate("http://example.com/salary", except_role="hr")
          .label_graph("http://example.com/reviews", 3))

anyone = Principal.anonymous()
hr     = Principal("urn:user:alice", roles=["hr"], clearance=3)

store.query(q, principal=anyone, policy=policy)   # no salaries, no reviews
store.query(q, principal=hr,     policy=policy)   # both

Because the filtering happens at the scan and not above it:

the answer to Q equals the answer Q would have over the sub-dataset the principal may see.

That holds for every query shape without anyone enumerating them. A COUNT cannot leak the existence of hidden rows, and a FILTER NOT EXISTS cannot probe for them.

Use Policy().fail_closed() when a partial answer would be misread as a complete one — a compliance report, a reconciliation total — and an error is better than a quiet omission.

What else is here

store.validate("shapes.ttl")            # SHACL, {'conforms': False, 'violations': 12, ...}
store.named_graphs()
store.dictionary_size                   # smaller than you expect: see below
holosdb.geosparql_functions()             # 45 of them
holosdb.has_rocksdb()                     # what this wheel actually contains

GeoSPARQL works through the ordinary query path, so it composes with policy — denying geo:asWKT makes a spatial join find nothing:

store.query("""
  PREFIX geof: <http://www.opengis.net/def/function/geosparql/>
  PREFIX uom:  <http://www.opengis.net/def/uom/OGC/1.0/>
  SELECT ?site WHERE {
    ?site <http://www.opengis.net/ont/geosparql#asWKT> ?g .
    FILTER(geof:sfWithin(?g, geof:buffer(?depot, 5, uom:kilometre)))
  }
""")

dictionary_size is reliably smaller than the number of terms — every integer, float, dateTime and short string is packed into its own 64-bit id and never reaches the dictionary. A million triples produced 489,479 dictionary entries.

Threading

A Store is safe to share across threads, and the GIL is released around every query and every load. Concurrent readers genuinely run concurrently rather than taking turns.

What is not here

store.update(...) raises NotImplementedError. There is no SPARQL Update evaluator in this build — raising is deliberate, because silently accepting an update that did nothing would be much worse than an error. Writes go through add() and load().

Persistence is compiled into the wheel rather than installed beside it, so pip install holosdb[rocksdb] is accepted but installs nothing; the published wheels already have it. PACKAGING.md explains why a Python extra cannot do otherwise, and has_rocksdb() reports what you actually got.

Licence

MIT or Apache-2.0, at your option.

Release files for holosdb 0.7.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for holosdb 0.7.0
File Size Uploaded
holosdb-0.7.0.tar.gz 513.9 kB Details

Built distributions (wheels)

Table of built distributions (wheels) for holosdb 0.7.0
File
holosdb-0.7.0-cp39-abi3-win_amd64.whl CPython 3.9 abi3 Windows x86-64 Details
holosdb-0.7.0-cp39-abi3-manylinux_2_28_x86_64.whl CPython 3.9 abi3 Linux glibc 2.28+ x86-64 Details
holosdb-0.7.0-cp39-abi3-manylinux_2_28_aarch64.whl CPython 3.9 abi3 Linux glibc 2.28+ ARM64 Details
holosdb-0.7.0-cp39-abi3-macosx_11_0_arm64.whl CPython 3.9 abi3 macOS 11.0+ ARM64 Details
holosdb-0.7.0-cp39-abi3-macosx_10_13_x86_64.whl CPython 3.9 abi3 macOS 10.13+ x86-64 Details

Total release size: 29.3 MB

Release files / holosdb-0.7.0.tar.gz

Download URL holosdb-0.7.0.tar.gz
Size 513.9 kB
Tags Source
SHA-256 checksum
How to use checksums
d57d31bcbb6ebac6ffdaabbe591a97ffef8726d77cffed3ac1864cd85427a232
BLAKE2b-256 checksum
How to use checksums
816f9ed86947588bc5c487b57a8fdbf2d85c1284ea2697e705d82f4f89815bca
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 9, 2026.

Transparency log

Release files / holosdb-0.7.0-cp39-abi3-win_amd64.whl

Download URL holosdb-0.7.0-cp39-abi3-win_amd64.whl
Size 5.3 MB
Tags CPython 3.9 Windows x86-64 abi3
SHA-256 checksum
How to use checksums
d4f537f2a48bc111181e5187cda4fbd673db3763ee0c3cf1c3f05e3c19909fa0
BLAKE2b-256 checksum
How to use checksums
801824dadd7ad2b338b0b668a8b67b02e30ff04bc0bb3fbadb4fe3e2082f0b35
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 9, 2026.

Transparency log

Release files / holosdb-0.7.0-cp39-abi3-manylinux_2_28_x86_64.whl

Download URL holosdb-0.7.0-cp39-abi3-manylinux_2_28_x86_64.whl
Size 6.6 MB
Tags CPython 3.9 Linux glibc 2.28+ x86-64 abi3
SHA-256 checksum
How to use checksums
fb269b5cd44aa11f140f75bfe5460bda0da502a11e2805843d12824e9b03d4d3
BLAKE2b-256 checksum
How to use checksums
ecdcfa4e34a604d9211c3497acb2d8d38436ba274fc5ccd8f236fbee8cb16682
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 9, 2026.

Transparency log

Release files / holosdb-0.7.0-cp39-abi3-manylinux_2_28_aarch64.whl

Download URL holosdb-0.7.0-cp39-abi3-manylinux_2_28_aarch64.whl
Size 6.1 MB
Tags CPython 3.9 Linux glibc 2.28+ ARM64 abi3
SHA-256 checksum
How to use checksums
bdc3240f8b44e3c80f9a13e2b3cf2cae818365a6a5eccee5aed56509bf1114a6
BLAKE2b-256 checksum
How to use checksums
83d8634b66ef77e8258b4d55c6f351d019f2a5635f916a1ae81ef59fb57ef85d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 9, 2026.

Transparency log

Release files / holosdb-0.7.0-cp39-abi3-macosx_11_0_arm64.whl

Download URL holosdb-0.7.0-cp39-abi3-macosx_11_0_arm64.whl
Size 5.1 MB
Tags CPython 3.9 abi3 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
7085eedd87145c083e0800c97fccd5426f30da690bf7e74e5af998e5302faee3
BLAKE2b-256 checksum
How to use checksums
0830784ad9860b1c1ed5355261468a101e3be3d099d50e84b6c1d686c55850eb
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 9, 2026.

Transparency log

Release files / holosdb-0.7.0-cp39-abi3-macosx_10_13_x86_64.whl

Download URL holosdb-0.7.0-cp39-abi3-macosx_10_13_x86_64.whl
Size 5.7 MB
Tags CPython 3.9 abi3 macOS 10.13+ x86-64
SHA-256 checksum
How to use checksums
181ffa4d1282e7c1fe11f84ac6296b8b9f79e7fbe236a13fc3eb405c38b3e8be
BLAKE2b-256 checksum
How to use checksums
3ba3fd9d05624506219621725d6977d0ac647bc337e5cef240122f45800e1991
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 9, 2026.

Transparency log

Release history Release notifications | RSS feed

0.14.0

6 release files

0.13.0

6 release files

0.12.0

6 release files

0.11.0

6 release files

0.10.0

6 release files

0.9.0

6 release files

This release

0.7.0 This release

6 release files

0.6.0

6 release files

0.5.0

6 release files

0.4.0

6 release files

0.3.0

6 release files

0.2.0

6 release files

0.1.1

6 release files

0.1.0

6 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page