Reef store rules
DRAFT. Requires legal review before publication. These rules become part of the developer terms (terms version draft-2026-09, which sign-up must accept). The technical rules are enforced by the automated review; review-checklist.md lists every check.
Accounts
No registration fee. Opening a developer account, keeping it, uploading builds and having them reviewed and published cost nothing, for free and paid apps alike. Reef takes no share of sales: for now, developers of paid apps sell them through their own checkout, and Reef lists them free of charge. A revenue-share programme may follow; pricing-and-revenue-share.md keeps its draft. Decided; still subject to the legal review above.
- One account per developer or organisation. The e-mail address must be verified before an API key is issued.
- API keys are secrets. Keep them in CI secret stores, revoke them (
DELETE /v1/me/api-keys/{id}) when a machine or person leaves, and never put them in an app or a public repository. Keys start withswdp_so secret scanners can find them. - You sign every package with your own OpenPGP key, registered with
POST /v1/me/signing-keys. Reef re-signs published packages with the Reef repository key; your signature proves to us that the upload is yours.
App ids and names
- The app id is the RPM package name, the binary name, the desktop file name and the licence
appclaim. It is 3 to 64 characters of lowercase letters, digits and single hyphens, starts with a letter and does not end with a hyphen. - Reserved and refused:
harbour-(Jolla's store namespace: a Reef package must never shadow a Harbour package);- Shipwright and platform prefixes:
shipwright,shoal-,reef-,keel-,sailfish,jolla,nemo-,lipstick,mapplauncherd,sailjail,ssu,qt5,qt6,chum,patchmanager,store-client; - the names
shoal,reef,keel,harbour,store,system, and the names of OS packages; - subpackage-like suffixes:
-devel,-debuginfo,-debugsource,-tests.
- App ids are first come, first served, but we may reassign one that impersonates another product or trademark. The display title must not imply endorsement by Jolla, Shipwright or anyone else.
Packages
- One binary RPM per upload, built for the release and architecture you upload it for (or
noarch). No source RPMs. - Every version you publish for a release and architecture is newer, by rpm's version comparison, than the last one we accepted there.
- Files stay inside your app's paths. No setuid or setgid files, no world-writable files, no file capabilities, all files owned by
root:root. - Scriptlets run as root outside any sandbox, so only the cache refreshes on the allow-list are accepted. No
%pretrans, no triggers, no file triggers. - You may not
Provideanything but your own package, its desktop and metainfo, or MIME handlers, and you may notObsoleteanything. - Upload limit: 100 MiB per RPM (installed size 512 MiB), unless we agree otherwise.
Sandbox and permissions
- Every app declares Sailjail permissions in
[X-Sailjail]. The store shows them to users before installing. Sandboxing=Disabledis refused unless a reviewer approves it after you explain why the app cannot work sandboxed (file managers, system tools). The listing marks the app as unsandboxed.PrivilegedandApplicationInstallationneed a reviewer's approval and a justification.- Apps do not download and execute code that was not reviewed (plugins, scripts, updaters). Updates come through Reef.
Content and behaviour
- The app does what its listing says. No malware, spyware, cryptocurrency mining, ad fraud or hidden functionality. Every upload passes the malware scan.
- Collecting personal data needs a privacy policy linked from the listing and the user's informed consent where the law requires it. Health, location and contact data are sensitive.
- No content that is illegal in the EU, and no content in the categories the final terms exclude (to be set by legal review).
- Third-party code is used under its licence. The RPM
Licensetag is accurate, and GPL apps provide their source (sourceURL on the app).
Enforcement
- We may reject a build with reasons, withdraw a published build (for security, legal or policy reasons), suspend an account, or remove an app. Withdrawn builds leave the repository at the next publish run; users who installed them keep them unless we push a security update.
- You can ask a different reviewer to look at a rejection again. The appeal process is to be defined in the final terms.
Source: docs/developers/store-rules.md in the Shipwright repository; paths and ADR numbers in the text refer to it.