Configuration
Most functions of Chute are controlled by the configuration file. You may edit it in your own text editor, or in the built-in editor of Chute iOS, Chute tvOS, Chute Mac (the main window's Config tab, or Preferences... in the older interface) or Chute Android. Chute Dashboard has no configuration editor — what it edits is the running engine's rules, never the file.
Chute iOS can sync configuration files through iCloud Drive, which is a licensed feature. Chute Mac has no iCloud sync of its own: there, sharing a file means picking one that happens to live in iCloud Drive from the import panel, and it is then referenced where it sits.
Configuration Sections
The configuration file is organized into named sections:
| Section | Purpose |
|---|---|
[General] |
Global settings (logging, IPv6, DNS, proxy ports, etc.) |
[Proxy] |
Outbound proxy server definitions |
[Proxy Group] |
Policy group definitions (select, url-test, fallback, load-balance, ssid, subnet) |
[Rule] |
Traffic matching and routing rules |
[Host] |
Local DNS host-to-IP mappings |
[DNS] |
DNS settings, accepting both [General] DNS keys and [Host]-style per-domain overrides |
[URL Rewrite] |
URL rewrite rules |
[Header Rewrite] |
HTTP header rewrite rules |
[Body Rewrite] |
HTTP body search-and-replace rules |
[Map Local] |
Mock response rules |
[MITM] |
HTTPS decryption settings |
[Script] |
JavaScript script definitions |
[SSID Setting] |
Per-network settings: suspend, and DNS overrides for a Wi-Fi network or a network type |
[Replica] |
Traffic recording filters |
[Module] |
External module files |
[WireGuard <name>] |
WireGuard tunnel configurations (an instance name is required, e.g. [WireGuard HomeServer]) |
[AmneziaWG <name>] |
AmneziaWG tunnel configurations, WireGuard-compatible with obfuscation parameters (an instance name is required, e.g. [AmneziaWG HomeServer]) |
[Tailscale] |
Global Tailscale configuration (globally unique; a [Tailscale <name>] header is read as this section) |
[Proxy Provider] |
External proxy list sources |
[Rule Provider] |
External rule set sources |
[Ruleset <name>] |
Inline rule set, used with RULE-SET,<name> — see Rule Set |
Notice: The sections
[Panel],[Ponte],[MTProto],[Keystore],[Port Forwarding],[Testing],[DHCP]and[Snell Server]are recognized so that a Surge configuration does not error (each logs one notice), and their lines are preserved verbatim when the configuration is saved, but they have no effect in Chute.
DNS Section
The DNS-related [General] keys may equivalently be written under a top-level [DNS] section. Lines in that section are handled per key:
| Line | Handling |
|---|---|
dns-server, direct-dns-server, proxy-dns-server, doh (aliases doh-server, doh-service), dot, doq, doh3, encrypted-dns-server, allow-dns-svcb, encrypted-dns-follow-outbound-mode, hijack-dns, always-real-ip |
Exactly as in [General]; the key is stored as if it had been written there |
| Any other line | Parsed with the [Host] per-domain syntax, e.g. *.example.com = server:1.1.1.1 |
| A key that is neither | Ignored with a notice in the log; the line itself is kept |
[DNS]
doh = https://dns.google/dns-query
hijack-dns = 8.8.8.8:53
*.example.com = server:1.1.1.1
Note: Because both line forms are accepted here, a
[DNS]section may mix DNS server settings with per-domain overrides. Do not repeat the same setting in[General]and[DNS]: a seconddohline, for example, is reported as a duplicate DoH configuration.Note:
fallback-dns-serverandencrypted-dns-skip-cert-verificationare read under[DNS]as well, even though they are not in the first row. A key that is not a DNS setting is not ignored here — it is read as a per-domain override, so a misplaced[General]key such asoptimistic-dns = falsesilently becomes the mappingoptimistic-dns→false. Only a line that the override parser also rejects gets a notice. See DNS.
Including Another File
A profile may pull in another file. Surge writes #!include <path>; Shadowrocket writes include = <other.conf> above the first section. Both are read, and the included file is spliced in where the directive stands, so a [Rule] fragment lands inside the section that names it.
#!include Rulesets/company.list
- The path is resolved against the directory of the file that names it, and may hold a
*—#!include Rulesets/*.listpulls in a directory of rule fragments, in name order. - Includes nest up to 8 levels deep, and a file already pulled in — the profile itself included — is not pulled in twice, so a cycle cannot run away; a profile that includes itself is simply ignored.
- An include is only expanded when the profile was loaded from a file. Handed to the engine as text — which is how a configuration usually crosses into the tunnel — there is no directory to resolve against, so the profile is reported as incomplete rather than treated as whole. The directive itself is preserved when the configuration is saved: it is written back exactly as it was read, and the included file's content is never written into the profile.
Comment
A line that starts with #, ; or // is a comment. The same three markers open an inline comment, but only right after a space or tab, and never inside quotes ("…" or '…', with \ escaping the next character). A URL's ://, a path such as a//b and an unquoted base64 value that happens to contain // or # therefore stay whole. Comments and blank lines are preserved when the configuration is saved.
Inline comments work differently in the rewrite sections and on the ssid / subnet lines of [Proxy Group]:
| Where | # |
; |
// |
Quotes |
|---|---|---|---|---|
[URL Rewrite] |
As above | As above | As above | None: the line is split at whitespace, and the first word that starts with a marker ends it |
[Header Rewrite] |
Never a comment, so header-add X-Color #ff0000 keeps its value |
Never a comment | As above | "…" |
[Body Rewrite], [Map Local] |
As above | Never a comment | As above | "…"; on a jq line also '…' |
ssid / subnet lines of [Proxy Group] |
As above | As above | As above | "…" only: an apostrophe is part of a network name such as Bob's iPhone |
Directive lines — #!include, #!MANAGED-CONFIG, #!IOS-ONLY and the like — are read as directives before any of this applies. The files a rule set, a domain set or a proxy provider downloads are not configuration sections: only a whole line can be a comment there.