build-reject-domainset.ts 8.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192
  1. // @ts-check
  2. import path from 'node:path';
  3. import process from 'node:process';
  4. import { processHosts, processFilterRules, processDomainLists } from './lib/parse-filter';
  5. import { HOSTS, ADGUARD_FILTERS, PREDEFINED_WHITELIST, DOMAIN_LISTS, HOSTS_EXTRA, DOMAIN_LISTS_EXTRA, ADGUARD_FILTERS_EXTRA, PHISHING_DOMAIN_LISTS_EXTRA, ADGUARD_FILTERS_WHITELIST } from './constants/reject-data-source';
  6. import { compareAndWriteFile } from './lib/create-file';
  7. import { readFileIntoProcessedArray } from './lib/fetch-text-by-line';
  8. import { task } from './trace';
  9. // tldts-experimental is way faster than tldts, but very little bit inaccurate
  10. // (since it is hashes based). But the result is still deterministic, which is
  11. // enough when creating a simple stat of reject hosts.
  12. import { SHARED_DESCRIPTION } from './constants/description';
  13. import { getPhishingDomains } from './lib/get-phishing-domains';
  14. import { addArrayElementsToSet } from 'foxts/add-array-elements-to-set';
  15. import { appendArrayInPlace } from './lib/append-array-in-place';
  16. import { OUTPUT_INTERNAL_DIR, SOURCE_DIR } from './constants/dir';
  17. import { DomainsetOutput } from './lib/create-file';
  18. const readLocalRejectDomainsetPromise = readFileIntoProcessedArray(path.join(SOURCE_DIR, 'domainset/reject_sukka.conf'));
  19. const readLocalRejectExtraDomainsetPromise = readFileIntoProcessedArray(path.join(SOURCE_DIR, 'domainset/reject_sukka_extra.conf'));
  20. const readLocalRejectRulesetPromise = readFileIntoProcessedArray(path.join(SOURCE_DIR, 'non_ip/reject.conf'));
  21. const readLocalRejectDropRulesetPromise = readFileIntoProcessedArray(path.join(SOURCE_DIR, 'non_ip/reject-drop.conf'));
  22. const readLocalRejectNoDropRulesetPromise = readFileIntoProcessedArray(path.join(SOURCE_DIR, 'non_ip/reject-no-drop.conf'));
  23. const readLocalMyRejectRulesetPromise = readFileIntoProcessedArray(path.join(SOURCE_DIR, 'non_ip/my_reject.conf'));
  24. export const buildRejectDomainSet = task(require.main === module, __filename)(async (span) => {
  25. const rejectBaseDescription = [
  26. ...SHARED_DESCRIPTION,
  27. '',
  28. 'The domainset supports AD blocking, tracking protection, privacy protection, anti-phishing, anti-mining',
  29. '',
  30. 'Build from:',
  31. ...HOSTS.map(host => ` - ${host[0]}`),
  32. ...DOMAIN_LISTS.map(domainList => ` - ${domainList[0]}`),
  33. ...ADGUARD_FILTERS.map(filter => ` - ${Array.isArray(filter) ? filter[0] : filter}`)
  34. ];
  35. const rejectOutput = new DomainsetOutput(span, 'reject')
  36. .withTitle('Sukka\'s Ruleset - Reject Base')
  37. .withDescription(rejectBaseDescription);
  38. const rejectExtraOutput = new DomainsetOutput(span, 'reject_extra')
  39. .withTitle('Sukka\'s Ruleset - Reject Extra')
  40. .withDescription([
  41. ...SHARED_DESCRIPTION,
  42. '',
  43. 'The domainset supports AD blocking, tracking protection, privacy protection, anti-phishing, anti-mining',
  44. '',
  45. 'Build from:',
  46. ...HOSTS_EXTRA.map(host => ` - ${host[0]}`),
  47. ...DOMAIN_LISTS_EXTRA.map(domainList => ` - ${domainList[0]}`),
  48. ...ADGUARD_FILTERS_EXTRA.map(filter => ` - ${Array.isArray(filter) ? filter[0] : filter}`),
  49. ...PHISHING_DOMAIN_LISTS_EXTRA.map(domainList => ` - ${domainList[0]}`)
  50. ]);
  51. const appendArrayToRejectOutput = rejectOutput.addFromDomainset.bind(rejectOutput);
  52. const appendArrayToRejectExtraOutput = rejectExtraOutput.addFromDomainset.bind(rejectExtraOutput);
  53. /** Whitelists */
  54. const filterRuleWhitelistDomainSets = new Set(PREDEFINED_WHITELIST);
  55. // Parse from AdGuard Filters
  56. const shouldStop = await span
  57. .traceChild('download and process hosts / adblock filter rules')
  58. .traceAsyncFn(async (childSpan) => {
  59. // eslint-disable-next-line sukka/no-single-return -- not single return
  60. let shouldStop = false;
  61. await Promise.all([
  62. // Parse from remote hosts & domain lists
  63. HOSTS.map(entry => processHosts(childSpan, ...entry).then(appendArrayToRejectOutput)),
  64. HOSTS_EXTRA.map(entry => processHosts(childSpan, ...entry).then(appendArrayToRejectExtraOutput)),
  65. DOMAIN_LISTS.map(entry => processDomainLists(childSpan, ...entry).then(appendArrayToRejectOutput)),
  66. DOMAIN_LISTS_EXTRA.map(entry => processDomainLists(childSpan, ...entry).then(appendArrayToRejectExtraOutput)),
  67. ADGUARD_FILTERS.map(
  68. entry => processFilterRules(childSpan, ...entry)
  69. .then(({ white, black, foundDebugDomain }) => {
  70. if (foundDebugDomain) {
  71. // eslint-disable-next-line sukka/no-single-return -- not single return
  72. shouldStop = true;
  73. // we should not break here, as we want to see full matches from all data source
  74. }
  75. addArrayElementsToSet(filterRuleWhitelistDomainSets, white);
  76. appendArrayToRejectOutput(black);
  77. })
  78. ),
  79. ADGUARD_FILTERS_EXTRA.map(
  80. entry => processFilterRules(childSpan, ...entry)
  81. .then(({ white, black, foundDebugDomain }) => {
  82. if (foundDebugDomain) {
  83. // eslint-disable-next-line sukka/no-single-return -- not single return
  84. shouldStop = true;
  85. // we should not break here, as we want to see full matches from all data source
  86. }
  87. addArrayElementsToSet(filterRuleWhitelistDomainSets, white);
  88. appendArrayToRejectExtraOutput(black);
  89. })
  90. ),
  91. ADGUARD_FILTERS_WHITELIST.map(entry => processFilterRules(childSpan, ...entry).then(({ white, black }) => {
  92. addArrayElementsToSet(filterRuleWhitelistDomainSets, white);
  93. addArrayElementsToSet(filterRuleWhitelistDomainSets, black);
  94. })),
  95. getPhishingDomains(childSpan).then(appendArrayToRejectExtraOutput),
  96. readLocalRejectDomainsetPromise.then(appendArrayToRejectOutput),
  97. readLocalRejectDomainsetPromise.then(appendArrayToRejectExtraOutput),
  98. readLocalRejectExtraDomainsetPromise.then(appendArrayToRejectExtraOutput),
  99. // Dedupe domainSets
  100. // span.traceChildAsync('collect black keywords/suffixes', async () =>
  101. /**
  102. * Collect DOMAIN, DOMAIN-SUFFIX, and DOMAIN-KEYWORD from non_ip/reject.conf for deduplication
  103. * DOMAIN-WILDCARD is not really useful for deduplication, it is only included in AdGuardHome output
  104. */
  105. rejectOutput.addFromRuleset(readLocalRejectRulesetPromise),
  106. rejectExtraOutput.addFromRuleset(readLocalRejectRulesetPromise)
  107. ].flat());
  108. // eslint-disable-next-line sukka/no-single-return -- not single return
  109. return shouldStop;
  110. });
  111. if (shouldStop) {
  112. process.exit(1);
  113. }
  114. await Promise.all([
  115. rejectOutput.done(),
  116. rejectExtraOutput.done()
  117. ]);
  118. // whitelist
  119. span.traceChildSync('whitelist', () => {
  120. for (const domain of filterRuleWhitelistDomainSets) {
  121. rejectOutput.whitelistDomain(domain);
  122. rejectExtraOutput.whitelistDomain(domain);
  123. }
  124. for (let i = 0, len = rejectOutput.$preprocessed.length; i < len; i++) {
  125. rejectExtraOutput.whitelistDomain(rejectOutput.$preprocessed[i]);
  126. }
  127. });
  128. // Create reject stats
  129. const rejectDomainsStats: string[] = span
  130. .traceChild('create reject stats')
  131. .traceSyncFn(() => {
  132. const results = [];
  133. results.push('=== base ===');
  134. appendArrayInPlace(results, rejectOutput.getStatMap());
  135. results.push('=== extra ===');
  136. appendArrayInPlace(results, rejectExtraOutput.getStatMap());
  137. return results;
  138. });
  139. return Promise.all([
  140. rejectOutput.write(),
  141. rejectExtraOutput.write(),
  142. compareAndWriteFile(
  143. span,
  144. rejectDomainsStats,
  145. path.join(OUTPUT_INTERNAL_DIR, 'reject-stats.txt')
  146. ),
  147. compareAndWriteFile(
  148. span,
  149. appendArrayInPlace(
  150. [
  151. '! Title: Sukka\'s Ruleset - Blocklist for AdGuardHome',
  152. '! Last modified: ' + new Date().toUTCString(),
  153. '! Expires: 6 hours',
  154. '! License: https://github.com/SukkaW/Surge/blob/master/LICENSE',
  155. '! Homepage: https://github.com/SukkaW/Surge',
  156. '! Description: The domainset supports AD blocking, tracking protection, privacy protection, anti-phishing, anti-mining',
  157. '!'
  158. ],
  159. appendArrayInPlace(
  160. rejectOutput.adguardhome(),
  161. (
  162. await new DomainsetOutput(span, 'my_reject')
  163. .addFromRuleset(readLocalMyRejectRulesetPromise)
  164. .addFromRuleset(readLocalRejectRulesetPromise)
  165. .addFromRuleset(readLocalRejectDropRulesetPromise)
  166. .addFromRuleset(readLocalRejectNoDropRulesetPromise)
  167. .done()
  168. ).adguardhome()
  169. )
  170. ),
  171. path.join(OUTPUT_INTERNAL_DIR, 'reject-adguardhome.txt')
  172. )
  173. ]);
  174. });