Open-source project
GMOogway/shadowrocket-rules avatar
GMOogway/shadowrocket-rules

GMOogway/shadowrocket-rules: Modular DIRECT, PROXY and REJECT Rules for Shadowrocket

小火箭规则🚀,小火箭模块,小火箭配置,shadowrocket规则,shadowrocket rules,最全面的直连(DIRECT)、代理(PROXY)、屏蔽(REJECT)规则,自动构建,每日更新

5,532 stars278 forksUnknownGPL-3.0

At a glance

What is it?
A GPL-3.0 rule set that ships as three Shadowrocket modules instead of a full config, rebuilt daily from Chinese domain and ad-block lists. Useful if you already run Shadowrocket and want to keep your own config; the module priority model is the part to understand before you install it.
Who is it for?
Adopt it if you already run Shadowrocket on iOS, keep your own config, and want a broad split-routing and ad-block rule set you can add or remove as modules. Do not adopt it if you need a complete ready-made configuration, if you want the rules running on Android or Windows, or if you expect ad filtering to catch video ads.
Can I use it commercially?
Yes, with conditions. GPL-3.0 is a copyleft licence: if you distribute software that includes it, you must release that software's source code under the same licence. Running it internally without distributing it does not trigger that obligation.
Is it still maintained?
Yes. The repository last received commits 1 day ago.
What is it written in?
GitHub does not report a main language for this repository.

Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.

Editorial analysis

The problem: full configs make you inherit someone else's certificates and ciphers

Shadowrocket accepts both a configuration file and modules. A shared configuration bundles routing rules together with proxy settings, certificates and decryption options. Those last parts differ per user, so importing someone else's full config means either accepting their choices or editing a large file. This project takes the other route. It publishes rules only, packaged as Shadowrocket modules, and leaves the base settings to you. The README states the reasoning directly: the module form is more flexible because basic settings, certificates and decryption differ for each person, and it keeps your own config short and easy to edit. The intended audience is therefore narrow and specific: an iOS Shadowrocket user who already has a working config and wants better routing. If you do not have a config yet, the repository also links a minimal one in docs/03.shadowsocks_tiny.conf, described as under 20 lines, which you can copy into a new config or add as a remote file. The rule counts printed in the README on 2026-09-22 are 111180 DIRECT entries, 27333 PROXY entries and 190755 REJECT entries. Those numbers are the project's own reported totals, not an independent measurement.

Three modules, two matching modes, and a priority order that overrides your config

The data flow is simple. The repository holds three .module files at the top level: sr_direct_list.module, sr_proxy_list.module and sr_reject_list.module. Shadowrocket fetches them as remote modules, and each one contributes rules tagged DIRECT, PROXY or REJECT. The README describes two ways to combine them. In whitelist mode you load sr_direct_list.module, append GEOIP,cn,DIRECT to catch new Chinese domains that are missing from the list (the README points to issues #7 for that case), and finish with FINAL,PROXY so unknown traffic goes through the proxy. In blacklist mode you load sr_proxy_list.module and finish with FINAL,DIRECT, so unknown traffic goes direct. sr_reject_list.module is optional in both modes and adds ad blocking. The priority model is the part worth reading twice. Module rules outrank config rules, and among modules the one higher in the list wins. The README is explicit that this is why custom rules can stop working after you add the modules. The suggested fix is to put your special rules in a small module of your own and move it to the top, so it matches first. That is a real design trade-off, not a bug: you gain coverage and lose the automatic precedence of your own file.

Installing the modules and getting a first split-routing result

Everything happens inside the Shadowrocket app on iOS. The README's method is to copy the link for the minimal config, then add it under 小火箭 -> 配置 -> 远程文件 (Config -> Remote Files); the same file can also be pasted directly into a new config. The raw link is:

bash
https://raw.githubusercontent.com/GMOogway/shadowrocket-rules/master/docs/03.shadowsocks_tiny.conf

Next, open the modules screen and add the three rule modules from the top right corner. The README lists two URLs per rule type, one that needs a proxy to reach and one that does not; jsdelivr is the directly reachable one and the README notes it lags by 12 hours, which it treats as acceptable at these rule counts. The DIRECT module is:

bash
https://cdn.jsdelivr.net/gh/GMOogway/shadowrocket-rules@master/sr_direct_list.module

The PROXY and REJECT modules follow the same pattern with sr_proxy_list.module and sr_reject_list.module. After adding them, the README says the setup is complete and traffic is split by rule. If you want the rules to refresh on their own, docs/02.shadowrocket_update_modules.md covers manual and automatic updating; the README does not document what happens to your config if an update pulls a broken module. The README also repeats one troubleshooting note twice: some domestic apps, banking apps among them, refuse to run when they detect a proxy. The stated fix is to change the proxy type from http to none, which is tun mode, under Settings -> Proxy. That setting is in Shadowrocket, not in this repository.

Where the rule set stops being the right tool

The README answers the ad-blocking question honestly: the rules do not guarantee 100 percent filtering, and video ads are the weak spot. Youku and similar apps can change their ad strategy with each release, so URL matching cannot stay current, and YouTube ads cannot be removed by simple URL matching at all. Treat REJECT as a web-ad and tracker filter, not as an ad-free guarantee. The second limit is platform. This is a Shadowrocket module set, and Shadowrocket is an iOS app; nothing in the repository or README describes an Android, Windows or macOS client, so the search interest in those platforms has no answer here. Third, the priority rule cuts both ways. If your config carries hand-tuned exceptions, adding the modules can silently override them, and the only documented remedy is building your own module and placing it above. Fourth, the project is a generated artifact. The factory directory holds six .txt files, and the README tells contributors to edit those; the .module files are build output. Editing a .module file by hand is not the documented path. Finally, the README's claim that 50000 rules and 50 rules are both O(1) in Shadowrocket is the project's own assertion about the app's matching, and it is not something this article can verify.

How it differs from importing a finished Shadowrocket config

The obvious alternative is a complete shared configuration, the kind distributed as a single .conf that you import and use as-is. The difference is what travels with the file. A full config carries proxy groups, certificates and decryption settings alongside the rules, so adopting it means adopting someone else's choices about your connection. This project ships rules only and expects you to supply the rest, which is why docs/03.shadowsocks_tiny.conf is deliberately tiny. The second alternative is a plain GFW list, such as the gfwlist project that this repository lists among its data sources. A GFW list answers one question, whether a domain is blocked, and leaves ad blocking and domestic direct routing to you. Here the three rule categories are separate modules, so you can take direct routing without ad blocking, or the reverse. The cost of that granularity is the priority model: a single config gives you one ordered rule list, while three modules give you three lists whose relative order you must manage yourself. The README's own comparison is the cleanest summary, that the module form keeps your configuration very concise and easy to edit.

Maintenance, build cadence and the GPL-3.0 question

The last push to the repository was on 2026-09-22, and the README's header block reports a build time of 2026-09-22 09:00:43 with per-category change counts: DIRECT update +0, PROXY update +2, REJECT update +364. That is a daily rebuild, and the REJECT delta shows most of the churn sits in the ad and tracker lists. The practical upgrade cost is close to zero because Shadowrocket fetches remote modules, but there is a trade-off in that same line: you get upstream list changes whether or not you reviewed them, and the README does not describe a pinned or versioned module URL. If you need a frozen rule set, the repository does not document one. On licensing, the repository carries GPL-3.0. The rules are aggregated from sources the README lists, including dnsmasq-china-list, v2fly/domain-list-community, gfwlist, Loyalsoldier/cn-blocked-domain, easylistchina plus easylist, AdGuard DNS filters, pgl.yoyo.org, someonewhocares.org and WindowsSpyBlocker. Those upstream projects have their own licences, and the README does not map each source to a licence or state how the aggregation handles them. If you plan to redistribute the .module files, that mapping is the thing to check; this article is not legal advice.

Editorial conclusion

Adopt it if you already run Shadowrocket on iOS, keep your own config, and want a broad split-routing and ad-block rule set you can add or remove as modules. Do not adopt it if you need a complete ready-made configuration, if you want the rules running on Android or Windows, or if you expect ad filtering to catch video ads. Verify two things first: that the module links resolve from your network, since one of the two published links requires a proxy to reach, and that your existing custom rules still match after the modules load, because module rules take priority over config rules.

Frequently asked questions

How do I use GMOogway/shadowrocket-rules with my existing Shadowrocket config?

Add the three .module links under the modules screen in Shadowrocket and keep your own config for base settings and proxies. Be aware that module rules take priority over config rules, so custom rules you already have may stop matching; the README suggests moving your own rules into a small module placed above the others.

Is GMOogway/shadowrocket-rules safe to use?

The repository is public, carries GPL-3.0, and its README lists the upstream data sources the rules are built from. What the README does not do is map each source to its own licence or describe a review step before the daily build is published, so that is what you would have to check yourself.

Does GMOogway/shadowrocket-rules work on Android, Windows or Mac?

The repository publishes Shadowrocket modules, and Shadowrocket is an iOS app. Neither the README nor the repository layout mentions an Android, Windows or macOS client, so there is nothing here for those platforms.

Will GMOogway/shadowrocket-rules block all ads?

No. The README states the rules do not guarantee 100 percent filtering, that app video ads such as Youku's change with each app release, and that YouTube ads cannot be removed by simple URL matching.

Why does GMOogway/shadowrocket-rules ship modules instead of a full config?

The README says the module form is more flexible because basic settings, certificates and decryption differ for each user, and it keeps your own configuration concise and easy to edit. A minimal config is still provided in docs/03.shadowsocks_tiny.conf for people who need a starting point.

Official sources

  1. GMOogway/shadowrocket-rules on GitHub
  2. Issues
  3. License: GPL-3.0
  4. Project website
  5. README
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/gmoogway-shadowrocket-rules.svg)](https://hysenlabs.com/projects/gmoogway-shadowrocket-rules)