Rule Set
You may use a bundle of rules from an URL, a configured rule provider, or an inline section in the configuration itself. Chute also provides two internal rule sets.
Internal Rule Set
SYSTEM
RULE-SET,SYSTEM,DIRECT
Includes rules for most requests sent by macOS and iOS itself. The requests sent by App Store, iTunes and other content services are not included.
USER-AGENT,*com.apple.mobileme.fmip1
USER-AGENT,*WeatherFoundation*
USER-AGENT,%E5%9C%B0%E5%9B%BE*
USER-AGENT,%E8%AE%BE%E7%BD%AE*
USER-AGENT,com.apple.geod*
USER-AGENT,com.apple.Maps
USER-AGENT,FindMyFriends*
USER-AGENT,FindMyiPhone*
USER-AGENT,FMDClient*
USER-AGENT,FMFD*
USER-AGENT,fmflocatord*
USER-AGENT,geod*
USER-AGENT,locationd*
USER-AGENT,Maps*
DOMAIN,api.smoot.apple.com
DOMAIN,captive.apple.com
DOMAIN,configuration.apple.com
DOMAIN,guzzoni.apple.com
DOMAIN,smp-device-content.apple.com
DOMAIN,xp.apple.com
DOMAIN-SUFFIX,ess.apple.com
DOMAIN-SUFFIX,push-apple.com.akadns.net
DOMAIN-SUFFIX,push.apple.com
DOMAIN,aod.itunes.apple.com
DOMAIN,mesu.apple.com
DOMAIN,api.smoot.apple.cn
DOMAIN,gs-loc.apple.com
DOMAIN,mvod.itunes.apple.com
DOMAIN,streamingaudio.itunes.apple.com
DOMAIN-SUFFIX,lcdn-locator.apple.com
DOMAIN-SUFFIX,lcdn-registration.apple.com
DOMAIN-SUFFIX,ls.apple.com
PROCESS-NAME,trustd
These rules may be updated with Chute updates. Please refer the description in the software to get the latest sub-rules.
LAN
RULE-SET,LAN,DIRECT
Includes rules for LAN IP addresses and .local suffix. Please notice this rule set will trigger a DNS lookup.
DOMAIN-SUFFIX,local
IP-CIDR,192.168.0.0/16
IP-CIDR,10.0.0.0/8
IP-CIDR,172.16.0.0/12
IP-CIDR,127.0.0.0/8
IP-CIDR,100.64.0.0/10
IP-CIDR,255.0.0.0/8
IP-CIDR,fc00::/7
IP-CIDR,::1/128
IP-CIDR,fe80::/10
External Rule Set
Rule set from an http(s) URL. The rule set file should be a text file. Each line contains a rule declaration without the policy.
Notice: Rule set files support only leaf rule types. Logical rules (AND/OR/NOT), SCRIPT and DOMAIN-SET lines are dropped. A RULE-SET line in a file fetched by
RULE-SET,<url>is inert: the parser keeps only the built-in SYSTEM and LAN values, and even those are never expanded, so the line never matches. Nested references do work in a[Rule Provider]payload and in an inline[Ruleset]section. A bare CIDR line (e.g.1.2.4.0/24) is accepted as an IP-CIDR rule.
RULE-SET,https://example.com/my-rules.txt,Proxy
RULE-SET,https://example.com/my-rules.txt,Proxy,update-interval=86400
The optional update-interval parameter is how old, in seconds, the downloaded copy may get. There is no timer: the first match after the copy has grown older than that downloads it again in the background. When the configuration loads, a cached copy younger than that is used as it is, without a download; one older than that is not used, so the set has to download before it matches. Without update-interval, a cached copy is kept and the set is downloaded only when there is none. Written on the RULE-SET line, no-resolve applies to every IP-based rule in the set.
Example rule set file:
DOMAIN,exampleA.com
DOMAIN,exampleB.com
To use a local file, define an entry in the [Rule Provider] section with a path= parameter and reference it by name:
[Rule Provider]
my-rules = type=file, path=/path/to/my-rules.txt, format=native
[Rule]
RULE-SET,my-rules,Proxy
Rule provider parameters: type (http or file; http requires url=), behavior (classical for rule declarations, domain for a domain set, ipcidr for a list of bare CIDRs — also usable for Clash/mihomo providers, whose bare-CIDR payloads are accepted; default classical), format (native — or surge — for Chute rule lines, mihomo-yaml for a Clash/mihomo rule-provider YAML payload, sing-box-source — or sing-box, source — for a sing-box rule set in source (JSON) format; default mihomo-yaml), and interval (seconds, default 86400). A positive interval downloads the payload again each time the configuration loads, and a cached copy older than that is not used; 0 downloads only when there is no cached copy; a negative value never downloads — not even for the update-interval of a RULE-SET line — so the provider stays inactive unless a cached copy exists. While Chute runs, a provider is refreshed only through a RULE-SET line that names it and carries update-interval: the first match after the cached copy has grown older than that fetches it again from the provider's own source. A [Rule Provider] line has no key that carries rules, so type=inline there gives an empty provider; write an inline set as a [Ruleset <name>] section.
policy=<name> downloads the payload through that policy or group — mihomo's proxy: — as in my-rules = type=http, url=https://example.com/rules.yaml, policy=Proxy; for a group, its pick when the download starts is used. Without it, or with policy=DIRECT, the payload is fetched directly. A name that is not defined refuses the download rather than fetching it directly.
GET /api/rules/providers on the HTTP Control API reports every [Rule Provider] entry and [Ruleset] section: whether it loaded, the reason it did not, and any conversion warnings. Its rule_count counts the lines of a [Ruleset] section and stays 0 for a downloaded or file provider. RULE-SET,<url> and DOMAIN-SET,<url> are not in the list; a failed download of one shows only in the log.
On iPhone, Apple TV and Android a rule provider's payload — downloaded or read from a file — has a size ceiling, because the tunnel has little memory to spare there: 400 KB for sing-box-source, 1 MB for every other format. A payload over the ceiling is not loaded, and the provider's status says why. RULE-SET,<url> and DOMAIN-SET,<url> are read without being converted in memory and have no ceiling. Desktop has no ceiling, so a large published set (geosite/cn and friends) loads as a provider only there. The rule-set index keeps at most 24 database connections open at once on those platforms (128 on desktop).
When a mihomo-yaml payload does not parse but looks like a plain list of rule lines, it is read as native instead, and a notice is logged. A line of a classical mihomo payload names no policy, so what follows its value is read as parameters: no-resolve is kept, and any other parameter — mihomo's src, say — is dropped. A logical rule and a …-REGEX rule keep the rest of the line as their value.
A payload that is a JSON object is tried as a sing-box rule set first, so a sing-box rule set declared with the default format loads too. In a sing-box rule set, a rule whose matchers are all of one kind becomes one line per value. The kinds are: destination (domain, domain_suffix, domain_keyword, domain_regex, ip_cidr, geoip, and ip_is_private, which becomes the private address ranges with no-resolve), destination port (port, port_range), source address (source_ip_cidr, source_ip_is_private), source port (source_port, source_port_range), and protocol, network, process_name and process_path, a kind each. clash_mode: rule is ignored, since rule mode is the only one Chute runs; any other clash_mode drops the rule. A rule that combines kinds (a domain and a port, say), an invert rule and a logical rule cannot be a single line; they are skipped and listed in the rule set's warnings. The compiled binary formats cannot be read. A sing-box .srs provider is detected as one — from format=srs or format=binary, or from a location ending in .srs — and stays inactive with a status that says to point it at the sing-box source (.json) form. mihomo's .mrs is not detected: its payload simply fails to decode as text, so the rule set stays inactive under the generic download-failure status. On macOS the importer rewrites a binary rule set to the source payload beside it where the publisher offers one; on iOS, Apple TV and Android it does not.
RULE-SET and DOMAIN-SET may be used as sub-rules inside AND/OR/NOT logical rules —
NOT,((RULE-SET,cn_ip)),Proxyworks, and the nested set is matched with the same payload filter as one written on its own.
Inline Rule Set
A [Ruleset <name>] section keeps a rule set inside the configuration file itself (Surge's syntax). Each line in it is a rule declaration without the policy, as in a rule set file, and a rule refers to the section by its name:
[Ruleset Streaming]
DOMAIN-SUFFIX,netflix.com
IP-CIDR,198.51.100.0/24,no-resolve
[Rule]
RULE-SET,Streaming,Proxy
The section works like a [Rule Provider] entry with type=inline and format=native, and it is saved back as a section. Two rule sets with the same name are a configuration error.
An inline section — like the payload of a rule provider — may include RULE-SET,SYSTEM, RULE-SET,LAN or RULE-SET,<another inline section>. These are expanded when the rules load, up to 8 levels deep. A reference that would form a loop, or one to a file or http rule set, a domain set or a DOMAIN-SET, is dropped with a warning.
Domain Set
A domain set is similar to an external rule set but specifically for domain names, and uses a more compact file format.
DOMAIN-SET,https://example.com/domains.txt,DIRECT
DOMAIN-SET,https://example.com/domains.txt,DIRECT,update-interval=86400
The first field after the type must be an http(s) URL. The domain set file contains bare domains, one per line (NOT rule declarations):
# exact domain
example.com
# the domain and all of its subdomains
.example.org
+.example.net
Lines starting with # or // are comments.