ruleset.ts 9.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283
  1. import { merge } from 'fast-cidr-tools';
  2. import type { Span } from '../../trace';
  3. import { createRetrieKeywordFilter as createKeywordFilter } from 'foxts/retrie';
  4. import { appendArrayInPlace } from '../append-array-in-place';
  5. import { appendSetElementsToArray } from 'foxts/append-set-elements-to-array';
  6. import type { SingboxSourceFormat } from '../singbox';
  7. import { RuleOutput } from './base';
  8. import picocolors from 'picocolors';
  9. import { normalizeDomain } from '../normalize-domain';
  10. import { isProbablyIpv4 } from 'foxts/is-probably-ip';
  11. import { fastIpVersion } from '../misc';
  12. type Preprocessed = [domain: string[], domainSuffix: string[], sortedDomainRules: string[]];
  13. export class RulesetOutput extends RuleOutput<Preprocessed> {
  14. constructor(span: Span, id: string, protected type: 'non_ip' | 'ip' | (string & {})) {
  15. super(span, id);
  16. }
  17. protected preprocess() {
  18. const kwfilter = createKeywordFilter(Array.from(this.domainKeywords));
  19. const domains: string[] = [];
  20. const domainSuffixes: string[] = [];
  21. const sortedDomainRules: string[] = [];
  22. this.domainTrie.dumpWithoutDot((domain, includeAllSubdomain) => {
  23. if (kwfilter(domain)) {
  24. return;
  25. }
  26. if (includeAllSubdomain) {
  27. domainSuffixes.push(domain);
  28. sortedDomainRules.push(`DOMAIN-SUFFIX,${domain}`);
  29. } else {
  30. domains.push(domain);
  31. sortedDomainRules.push(`DOMAIN,${domain}`);
  32. }
  33. }, true);
  34. return [domains, domainSuffixes, sortedDomainRules] satisfies Preprocessed;
  35. }
  36. surge(): string[] {
  37. const results: string[] = ['DOMAIN,this_ruleset_is_made_by_sukkaw.ruleset.skk.moe'];
  38. appendArrayInPlace(results, this.$preprocessed[2]);
  39. appendSetElementsToArray(results, this.domainKeywords, i => `DOMAIN-KEYWORD,${i}`);
  40. appendSetElementsToArray(results, this.domainWildcard, i => `DOMAIN-WILDCARD,${i}`);
  41. appendSetElementsToArray(results, this.userAgent, i => `USER-AGENT,${i}`);
  42. appendSetElementsToArray(results, this.processName, i => `PROCESS-NAME,${i}`);
  43. appendSetElementsToArray(results, this.processPath, i => `PROCESS-NAME,${i}`);
  44. appendSetElementsToArray(results, this.sourceIpOrCidr, i => `SRC-IP,${i}`);
  45. appendSetElementsToArray(results, this.sourcePort, i => `SRC-PORT,${i}`);
  46. appendSetElementsToArray(results, this.destPort, i => `DEST-PORT,${i}`);
  47. appendArrayInPlace(results, this.otherRules);
  48. appendSetElementsToArray(results, this.urlRegex, i => `URL-REGEX,${i}`);
  49. appendArrayInPlace(
  50. results,
  51. merge(Array.from(this.ipcidrNoResolve), true).map(i => `IP-CIDR,${i},no-resolve`)
  52. );
  53. appendSetElementsToArray(results, this.ipcidr6NoResolve, i => `IP-CIDR6,${i},no-resolve`);
  54. appendSetElementsToArray(results, this.ipasnNoResolve, i => `IP-ASN,${i},no-resolve`);
  55. appendSetElementsToArray(results, this.groipNoResolve, i => `GEOIP,${i},no-resolve`);
  56. appendArrayInPlace(
  57. results,
  58. merge(Array.from(this.ipcidr), true).map(i => `IP-CIDR,${i}`)
  59. );
  60. appendSetElementsToArray(results, this.ipcidr6, i => `IP-CIDR6,${i}`);
  61. appendSetElementsToArray(results, this.ipasn, i => `IP-ASN,${i}`);
  62. appendSetElementsToArray(results, this.geoip, i => `GEOIP,${i}`);
  63. return results;
  64. }
  65. clash(): string[] {
  66. const results: string[] = ['DOMAIN,this_ruleset_is_made_by_sukkaw.ruleset.skk.moe'];
  67. appendArrayInPlace(results, this.$preprocessed[2]);
  68. appendSetElementsToArray(results, this.domainKeywords, i => `DOMAIN-KEYWORD,${i}`);
  69. appendSetElementsToArray(results, this.domainWildcard, i => `DOMAIN-REGEX,${RuleOutput.domainWildCardToRegex(i)}`);
  70. appendSetElementsToArray(results, this.processName, i => `PROCESS-NAME,${i}`);
  71. appendSetElementsToArray(results, this.processPath, i => `PROCESS-PATH,${i}`);
  72. appendSetElementsToArray(results, this.sourceIpOrCidr, value => {
  73. if (value.includes('/')) {
  74. return `SRC-IP-CIDR,${value}`;
  75. }
  76. const v = fastIpVersion(value);
  77. if (v === 4) {
  78. return `SRC-IP-CIDR,${value}/32`;
  79. }
  80. if (v === 6) {
  81. return `SRC-IP-CIDR6,${value}/128`;
  82. }
  83. return '';
  84. });
  85. appendSetElementsToArray(results, this.sourcePort, i => `SRC-PORT,${i}`);
  86. appendSetElementsToArray(results, this.destPort, i => `DST-PORT,${i}`);
  87. // appendArrayInPlace(results, this.otherRules);
  88. appendArrayInPlace(
  89. results,
  90. merge(Array.from(this.ipcidrNoResolve), true).map(i => `IP-CIDR,${i},no-resolve`)
  91. );
  92. appendSetElementsToArray(results, this.ipcidr6NoResolve, i => `IP-CIDR6,${i},no-resolve`);
  93. appendSetElementsToArray(results, this.ipasnNoResolve, i => `IP-ASN,${i},no-resolve`);
  94. appendSetElementsToArray(results, this.groipNoResolve, i => `GEOIP,${i},no-resolve`);
  95. appendArrayInPlace(
  96. results,
  97. merge(Array.from(this.ipcidr), true).map(i => `IP-CIDR,${i}`)
  98. );
  99. appendSetElementsToArray(results, this.ipcidr6, i => `IP-CIDR6,${i}`);
  100. appendSetElementsToArray(results, this.ipasn, i => `IP-ASN,${i}`);
  101. appendSetElementsToArray(results, this.geoip, i => `GEOIP,${i}`);
  102. return results;
  103. }
  104. singbox(): string[] {
  105. const ip_cidr: string[] = [];
  106. appendArrayInPlace(
  107. ip_cidr,
  108. merge(
  109. appendSetElementsToArray(Array.from(this.ipcidrNoResolve), this.ipcidr),
  110. true
  111. )
  112. );
  113. appendSetElementsToArray(ip_cidr, this.ipcidr6NoResolve);
  114. appendSetElementsToArray(ip_cidr, this.ipcidr6);
  115. const singbox: SingboxSourceFormat = {
  116. version: 2,
  117. rules: [{
  118. domain: appendArrayInPlace(['this_ruleset_is_made_by_sukkaw.ruleset.skk.moe'], this.$preprocessed[0]),
  119. domain_suffix: this.$preprocessed[1],
  120. domain_keyword: Array.from(this.domainKeywords),
  121. domain_regex: Array.from(this.domainWildcard, RuleOutput.domainWildCardToRegex),
  122. ip_cidr,
  123. source_ip_cidr: [...this.sourceIpOrCidr].reduce<string[]>((acc, cur) => {
  124. if (cur.includes('/')) {
  125. acc.push(cur);
  126. } else {
  127. const v = fastIpVersion(cur);
  128. if (v === 4) {
  129. acc.push(cur + '/32');
  130. } else if (v === 6) {
  131. acc.push(cur + '/128');
  132. }
  133. }
  134. return acc;
  135. }, []),
  136. source_port: [...this.sourcePort].reduce<number[]>((acc, cur) => {
  137. const tmp = Number(cur);
  138. if (!Number.isNaN(tmp)) {
  139. acc.push(tmp);
  140. }
  141. return acc;
  142. }, []),
  143. port: [...this.destPort].reduce<number[]>((acc, cur) => {
  144. const tmp = Number(cur);
  145. if (!Number.isNaN(tmp)) {
  146. acc.push(tmp);
  147. }
  148. return acc;
  149. }, []),
  150. process_name: Array.from(this.processName),
  151. process_path: Array.from(this.processPath)
  152. }]
  153. };
  154. return RuleOutput.jsonToLines(singbox);
  155. }
  156. mitmSgmodule(): string[] | null {
  157. if (this.urlRegex.size === 0 || this.mitmSgmodulePath === null) {
  158. return null;
  159. }
  160. const urlRegexResults: Array<{ origin: string, processed: string[] }> = [];
  161. const parsedFailures: Array<[original: string, processed: string]> = [];
  162. const parsed: Array<[original: string, domain: string]> = [];
  163. for (let urlRegex of this.urlRegex) {
  164. if (
  165. urlRegex.startsWith('http://')
  166. || urlRegex.startsWith('^http://')
  167. ) {
  168. continue;
  169. }
  170. if (urlRegex.startsWith('^https?://')) {
  171. urlRegex = urlRegex.slice(10);
  172. }
  173. if (urlRegex.startsWith('^https://')) {
  174. urlRegex = urlRegex.slice(9);
  175. }
  176. const potentialHostname = urlRegex.split('/')[0]
  177. // pre process regex
  178. .replaceAll(String.raw`\.`, '.')
  179. .replaceAll('.+', '*')
  180. .replaceAll(/([a-z])\?/g, '($1|)')
  181. // convert regex to surge hostlist syntax
  182. .replaceAll('([a-z])', '?')
  183. .replaceAll(String.raw`\d`, '?')
  184. .replaceAll(/\*+/g, '*');
  185. let processed: string[] = [potentialHostname];
  186. const matches = [...potentialHostname.matchAll(/\((?:([^()|]+)\|)+([^()|]*)\)/g)];
  187. if (matches.length > 0) {
  188. const replaceVariant = (combinations: string[], fullMatch: string, options: string[]): string[] => {
  189. const newCombinations: string[] = [];
  190. combinations.forEach(combination => {
  191. options.forEach(option => {
  192. newCombinations.push(combination.replace(fullMatch, option));
  193. });
  194. });
  195. return newCombinations;
  196. };
  197. for (let i = 0; i < matches.length; i++) {
  198. const match = matches[i];
  199. const [_, ...options] = match;
  200. processed = replaceVariant(processed, _, options);
  201. }
  202. }
  203. urlRegexResults.push({
  204. origin: potentialHostname,
  205. processed
  206. });
  207. }
  208. for (const i of urlRegexResults) {
  209. for (const processed of i.processed) {
  210. if (
  211. normalizeDomain(
  212. processed
  213. .replaceAll('*', 'a')
  214. .replaceAll('?', 'b')
  215. )
  216. ) {
  217. parsed.push([i.origin, processed]);
  218. } else if (!isProbablyIpv4(processed)) {
  219. parsedFailures.push([i.origin, processed]);
  220. }
  221. }
  222. }
  223. if (parsedFailures.length > 0) {
  224. console.error(picocolors.bold('Parsed Failed'));
  225. console.table(parsedFailures);
  226. }
  227. const hostnames = Array.from(new Set(parsed.map(i => i[1])));
  228. return [
  229. '#!name=[Sukka] Surge Reject MITM',
  230. `#!desc=为 URL Regex 规则组启用 MITM (size: ${hostnames.length})`,
  231. '',
  232. '[MITM]',
  233. 'hostname = %APPEND% ' + hostnames.join(', ')
  234. ];
  235. }
  236. }