# Void-Rules

![Validate rules](https://github.com/VoidInTheShell/void-rules/actions/workflows/validate.yml/badge.svg)
![Python >=3.11](https://img.shields.io/badge/Python-%3E%3D3.11-3776AB?logo=python&logoColor=white)

支持多格式的场景化分流规则集，提供Clash、V2Ray、ADGuardHome和通用txt集合

## 规则说明


| 规则集                    | 包含内容                                                                    | 主要来源                                                                                                                                                                                                                                                                                                                                                                                                           |
| ---------------------- | ----------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `fake-ip-bypass`       | 直连、局域网、时间同步、连接检测、游戏和其他兼容性敏感域名。                                          | [DustinWin/domain-list-custom](https://github.com/DustinWin/domain-list-custom)、[xixu-me/RFM](https://github.com/xixu-me/RFM)、[QuixoticHeart/rule-set](https://github.com/QuixoticHeart/rule-set)、[ShellCrash](https://github.com/juewuy/ShellCrash)、[MetaCubeX/meta-rules-dat](https://github.com/MetaCubeX/meta-rules-dat)、[blackmatrix7/ios\_rule\_script](https://github.com/blackmatrix7/ios_rule_script) |
| `stun`                 | STUN 及相关 TURN 端点、域名通配规则，合并去重后独立输出，使用策略由客户端指定。                           | [MetaCubeX（Mihomo）category-stun](https://github.com/MetaCubeX/meta-rules-dat/blob/meta/geo/geosite/category-stun.list)、[DustinWin 分离出的 STUN 规则](https://github.com/DustinWin/domain-list-custom)，另保留本地匹配模式                                                                                                                                                                                                     |
| `fake-ip-force`        | eBay、Amazon、Microsoft、Google、Gemini、GFW、非中国地区域名，以及 AI、跨境金融和 IP 代理池服务域名。 | [blackmatrix7/ios\_rule\_script](https://github.com/blackmatrix7/ios_rule_script)、[Loyalsoldier/clash-rules](https://github.com/Loyalsoldier/clash-rules)、[MetaCubeX/meta-rules-dat](https://github.com/MetaCubeX/meta-rules-dat)，并包含本仓库的 `ai`、`void-claude-rules`、`cross-border-finance` 和 `ip-proxy-pools` 规则                                                                                                |
| `ads`                  | 广告和跟踪域名                                                                 | [Loyalsoldier/clash-rules](https://github.com/Loyalsoldier/clash-rules)、[snapei/clash-pro-rules](https://github.com/snapei/clash-pro-rules)、[TG-Twilight/AWAvenue-Ads-Rule](https://github.com/TG-Twilight/AWAvenue-Ads-Rule)、[MetaCubeX/meta-rules-dat](https://github.com/MetaCubeX/meta-rules-dat)                                                                                                          |
| `global-legal`         | Nvidia、Samsung、Intel、AMD、Lenovo、Dell 等全球厂商的域名。                          | [blackmatrix7/ios\_rule\_script](https://github.com/blackmatrix7/ios_rule_script)                                                                                                                                                                                                                                                                                                                              |
| `ai`                   | MetaCubeX 的非中国 AI 服务域名，以及 OpenAI、Twitter、Claude 规则。                     | [MetaCubeX/meta-rules-dat](https://github.com/MetaCubeX/meta-rules-dat)、[blackmatrix7/ios\_rule\_script](https://github.com/blackmatrix7/ios_rule_script)                                                                                                                                                                                                                                                      |
| `void-claude-rules`    | Claude 网页、API、Code、MCP、更新下载及上游收录的共享依赖；保留进程名、IP 和 ASN 规则。                | [VPSDance/ai-proxy-rules](https://github.com/VPSDance/ai-proxy-rules)、[MetaCubeX/meta-rules-dat](https://github.com/MetaCubeX/meta-rules-dat)、[xiaolai/anthropic-claude-surge-rules-set](https://github.com/xiaolai/anthropic-claude-surge-rules-set)、[blackmatrix7/ios\_rule\_script](https://github.com/blackmatrix7/ios_rule_script)                                                                        |
| `cross-border-finance` | 全球银行、支付、券商、交易所、加密货币平台、运营商和地区探测域名。                                       | [cross-border-finance-rules](https://github.com/VoidInTheShell/cross-border-finance-rules)、[MetaCubeX/meta-rules-dat](https://github.com/MetaCubeX/meta-rules-dat)                                                                                                                                                                                                                                             |
| `ip-proxy-pools`       | 常见商业 IP 代理池服务商的官网、管理面板、API 和代理网关域名，并保留官方旧品牌和端点。                         | 自托管                                                                                                                                                                                                                                                                                                                                                                                                            |
| `pcdn`                 | PCDN、P2P-CDN 及相关域名阻断规则。                                                 | [pcdn-block-list](https://github.com/VoidInTheShell/pcdn-block-list)、[uselibrary/PCDN](https://github.com/uselibrary/PCDN)、[privacy-protection-tools/anti-AD](https://github.com/privacy-protection-tools/anti-AD)、[Block-pcdn-domains](https://github.com/thhbdd/Block-pcdn-domains)、[PCDNFilter-CHN](https://github.com/susetao/PCDNFilter-CHN-)、[MyAdBlockRules](https://github.com/Womsxd/MyAdBlockRules)  |


> [!IMPORTANT]
> `fake-ip-bypass` 中的域名使用真实 IP；`fake-ip-force` 中的域名在兼容性例外之外使用 Fake-IP。两套规则配合使用时，采用 Mihomo DNS `rule` 模式，先匹配 bypass 的 `real-ip`，再匹配 force 的 `fake-ip`，最后 `MATCH,real-ip`。单独使用 force 的 `whitelist` 模式无法排除父域下的时间同步等子域例外。配置见 [Mihomo 接入说明](docs/MIHOMO.md)。

NTP 保留在 `fake-ip-bypass`。`stun` 独立输出，不作为依赖合入 `fake-ip-force`；构建会从 DustinWin、RFM、ShellCrash 等所有 bypass 来源中排除已识别的 STUN 成员和明确的 STUN/TURN 通配规则。独立订阅不自动设置直连、代理或 Fake-IP：客户端已有的父域规则和默认 DNS 行为仍然有效，例如 `stun.qq.com` 仍可能匹配通用的 `qq.com` 规则。需要指定 STUN 行为时，应在客户端显式配置其优先级和动作。

## 规则来源和整理方式

来源清单位于 [`catalog/sources.yaml`](catalog/sources.yaml)，每个来源都记录了公开地址、输入格式、适用的规则类型、来源项目和下载限制。每个规则集的组合范围见 [`recipes/`](recipes/)，人工补充、排除项和兼容性断言位于 [`overlays/`](overlays/)。

仓库会严格检查来源内容：未知的非注释行、异常的规则数量、来源格式变化和无法表达的规则都会让构建失败或进入审阅，不会静默丢弃。每个生成目录还会保留来源清单、规则数量、哈希和无法转换项目的报告，便于追溯本次产物由哪些公开来源生成。

## 可用的规则格式

- Mihomo/Clash：`classical`、`domain`、`ipcidr` 的 YAML 和 text；纯 domain/ipcidr 规则另提供 MRS。
- AdGuard Home：分别提供 block 和 allow 列表。
- Xray/V2Ray：domain list、geosite DAT 和 geoip DAT。
- 普通域名/IP 列表，以及包含逐条来源记录的压缩 JSON Lines、来源清单和兼容性报告。

不同格式的表达能力不同。例如 `DOMAIN-KEYWORD` 可以保留在 Mihomo classical 或 Xray geosite 中，但不能伪装成精确域名；只包含 IP 的规则也不会被塞进 Fake-IP 的域名列表。生成结果会报告这类差异。

## 客户端订阅直链

下面的链接固定指向 `main` 分支。每个单元格都同时列出 GitHub Raw 和 jsDelivr 两个地址：前者直接读取仓库文件，后者适合需要 CDN 或备用入口的客户端。文件也可以在 [`dist/`](dist/) 中按路径查看。

- Raw 基础地址：[https://raw.githubusercontent.com/VoidInTheShell/void-rules/main/dist/](https://raw.githubusercontent.com/VoidInTheShell/void-rules/main/dist/)
- jsDelivr 基础地址：[https://cdn.jsdelivr.net/gh/VoidInTheShell/void-rules@main/dist/](https://cdn.jsdelivr.net/gh/VoidInTheShell/void-rules@main/dist/)


| 规则集                    | Mihomo/Clash classical YAML                                                                                                                                                                                                                      | Mihomo domain MRS                                                                                                                                                                                                                        | Xray/V2Ray geosite DAT                                                                                                                                                                                                                 | AdGuard Home                                                                                                                                                                                                                                                                                                                                                                                                                     | 通用域名文本                                                                                                                                                                                                                                 |
| ---------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `fake-ip-bypass`       | [Raw](https://raw.githubusercontent.com/VoidInTheShell/void-rules/main/dist/fake-ip-bypass/mihomo-classical.yaml) / [jsDelivr](https://cdn.jsdelivr.net/gh/VoidInTheShell/void-rules@main/dist/fake-ip-bypass/mihomo-classical.yaml)             | [Raw](https://raw.githubusercontent.com/VoidInTheShell/void-rules/main/dist/fake-ip-bypass/mihomo-domain.mrs) / [jsDelivr](https://cdn.jsdelivr.net/gh/VoidInTheShell/void-rules@main/dist/fake-ip-bypass/mihomo-domain.mrs)             | [Raw](https://raw.githubusercontent.com/VoidInTheShell/void-rules/main/dist/fake-ip-bypass/xray-geosite.dat) / [jsDelivr](https://cdn.jsdelivr.net/gh/VoidInTheShell/void-rules@main/dist/fake-ip-bypass/xray-geosite.dat)             | —                                                                                                                                                                                                                                                                                                                                                                                                                                | [Raw](https://raw.githubusercontent.com/VoidInTheShell/void-rules/main/dist/fake-ip-bypass/plain-domain.txt) / [jsDelivr](https://cdn.jsdelivr.net/gh/VoidInTheShell/void-rules@main/dist/fake-ip-bypass/plain-domain.txt)             |
| `fake-ip-force`        | [Raw](https://raw.githubusercontent.com/VoidInTheShell/void-rules/main/dist/fake-ip-force/mihomo-classical.yaml) / [jsDelivr](https://cdn.jsdelivr.net/gh/VoidInTheShell/void-rules@main/dist/fake-ip-force/mihomo-classical.yaml)               | [Raw](https://raw.githubusercontent.com/VoidInTheShell/void-rules/main/dist/fake-ip-force/mihomo-domain.mrs) / [jsDelivr](https://cdn.jsdelivr.net/gh/VoidInTheShell/void-rules@main/dist/fake-ip-force/mihomo-domain.mrs)               | [Raw](https://raw.githubusercontent.com/VoidInTheShell/void-rules/main/dist/fake-ip-force/xray-geosite.dat) / [jsDelivr](https://cdn.jsdelivr.net/gh/VoidInTheShell/void-rules@main/dist/fake-ip-force/xray-geosite.dat)               | —                                                                                                                                                                                                                                                                                                                                                                                                                                | [Raw](https://raw.githubusercontent.com/VoidInTheShell/void-rules/main/dist/fake-ip-force/plain-domain.txt) / [jsDelivr](https://cdn.jsdelivr.net/gh/VoidInTheShell/void-rules@main/dist/fake-ip-force/plain-domain.txt)               |
| `ads`                  | [Raw](https://raw.githubusercontent.com/VoidInTheShell/void-rules/main/dist/ads/mihomo-classical.yaml) / [jsDelivr](https://cdn.jsdelivr.net/gh/VoidInTheShell/void-rules@main/dist/ads/mihomo-classical.yaml)                                   | [Raw](https://raw.githubusercontent.com/VoidInTheShell/void-rules/main/dist/ads/mihomo-domain.mrs) / [jsDelivr](https://cdn.jsdelivr.net/gh/VoidInTheShell/void-rules@main/dist/ads/mihomo-domain.mrs)                                   | [Raw](https://raw.githubusercontent.com/VoidInTheShell/void-rules/main/dist/ads/xray-geosite.dat) / [jsDelivr](https://cdn.jsdelivr.net/gh/VoidInTheShell/void-rules@main/dist/ads/xray-geosite.dat)                                   | block：[Raw](https://raw.githubusercontent.com/VoidInTheShell/void-rules/main/dist/ads/adguard-block.txt) / [jsDelivr](https://cdn.jsdelivr.net/gh/VoidInTheShell/void-rules@main/dist/ads/adguard-block.txt)<br>allow：[Raw](https://raw.githubusercontent.com/VoidInTheShell/void-rules/main/dist/ads/adguard-allow.txt) / [jsDelivr](https://cdn.jsdelivr.net/gh/VoidInTheShell/void-rules@main/dist/ads/adguard-allow.txt)     | [Raw](https://raw.githubusercontent.com/VoidInTheShell/void-rules/main/dist/ads/plain-domain.txt) / [jsDelivr](https://cdn.jsdelivr.net/gh/VoidInTheShell/void-rules@main/dist/ads/plain-domain.txt)                                   |
| `global-legal`         | [Raw](https://raw.githubusercontent.com/VoidInTheShell/void-rules/main/dist/global-legal/mihomo-classical.yaml) / [jsDelivr](https://cdn.jsdelivr.net/gh/VoidInTheShell/void-rules@main/dist/global-legal/mihomo-classical.yaml)                 | [Raw](https://raw.githubusercontent.com/VoidInTheShell/void-rules/main/dist/global-legal/mihomo-domain.mrs) / [jsDelivr](https://cdn.jsdelivr.net/gh/VoidInTheShell/void-rules@main/dist/global-legal/mihomo-domain.mrs)                 | [Raw](https://raw.githubusercontent.com/VoidInTheShell/void-rules/main/dist/global-legal/xray-geosite.dat) / [jsDelivr](https://cdn.jsdelivr.net/gh/VoidInTheShell/void-rules@main/dist/global-legal/xray-geosite.dat)                 | —                                                                                                                                                                                                                                                                                                                                                                                                                                | [Raw](https://raw.githubusercontent.com/VoidInTheShell/void-rules/main/dist/global-legal/plain-domain.txt) / [jsDelivr](https://cdn.jsdelivr.net/gh/VoidInTheShell/void-rules@main/dist/global-legal/plain-domain.txt)                 |
| `ai`                   | [Raw](https://raw.githubusercontent.com/VoidInTheShell/void-rules/main/dist/ai/mihomo-classical.yaml) / [jsDelivr](https://cdn.jsdelivr.net/gh/VoidInTheShell/void-rules@main/dist/ai/mihomo-classical.yaml)                                     | [Raw](https://raw.githubusercontent.com/VoidInTheShell/void-rules/main/dist/ai/mihomo-domain.mrs) / [jsDelivr](https://cdn.jsdelivr.net/gh/VoidInTheShell/void-rules@main/dist/ai/mihomo-domain.mrs)                                     | [Raw](https://raw.githubusercontent.com/VoidInTheShell/void-rules/main/dist/ai/xray-geosite.dat) / [jsDelivr](https://cdn.jsdelivr.net/gh/VoidInTheShell/void-rules@main/dist/ai/xray-geosite.dat)                                     | —                                                                                                                                                                                                                                                                                                                                                                                                                                | [Raw](https://raw.githubusercontent.com/VoidInTheShell/void-rules/main/dist/ai/plain-domain.txt) / [jsDelivr](https://cdn.jsdelivr.net/gh/VoidInTheShell/void-rules@main/dist/ai/plain-domain.txt)                                     |
| `void-claude-rules`    | [Raw](https://raw.githubusercontent.com/VoidInTheShell/void-rules/main/dist/void-claude-rules/mihomo-classical.yaml) / [jsDelivr](https://cdn.jsdelivr.net/gh/VoidInTheShell/void-rules@main/dist/void-claude-rules/mihomo-classical.yaml)       | [Raw](https://raw.githubusercontent.com/VoidInTheShell/void-rules/main/dist/void-claude-rules/mihomo-domain.mrs) / [jsDelivr](https://cdn.jsdelivr.net/gh/VoidInTheShell/void-rules@main/dist/void-claude-rules/mihomo-domain.mrs)       | [Raw](https://raw.githubusercontent.com/VoidInTheShell/void-rules/main/dist/void-claude-rules/xray-geosite.dat) / [jsDelivr](https://cdn.jsdelivr.net/gh/VoidInTheShell/void-rules@main/dist/void-claude-rules/xray-geosite.dat)       | —                                                                                                                                                                                                                                                                                                                                                                                                                                | [Raw](https://raw.githubusercontent.com/VoidInTheShell/void-rules/main/dist/void-claude-rules/plain-domain.txt) / [jsDelivr](https://cdn.jsdelivr.net/gh/VoidInTheShell/void-rules@main/dist/void-claude-rules/plain-domain.txt)       |
| `cross-border-finance` | [Raw](https://raw.githubusercontent.com/VoidInTheShell/void-rules/main/dist/cross-border-finance/mihomo-classical.yaml) / [jsDelivr](https://cdn.jsdelivr.net/gh/VoidInTheShell/void-rules@main/dist/cross-border-finance/mihomo-classical.yaml) | [Raw](https://raw.githubusercontent.com/VoidInTheShell/void-rules/main/dist/cross-border-finance/mihomo-domain.mrs) / [jsDelivr](https://cdn.jsdelivr.net/gh/VoidInTheShell/void-rules@main/dist/cross-border-finance/mihomo-domain.mrs) | [Raw](https://raw.githubusercontent.com/VoidInTheShell/void-rules/main/dist/cross-border-finance/xray-geosite.dat) / [jsDelivr](https://cdn.jsdelivr.net/gh/VoidInTheShell/void-rules@main/dist/cross-border-finance/xray-geosite.dat) | —                                                                                                                                                                                                                                                                                                                                                                                                                                | [Raw](https://raw.githubusercontent.com/VoidInTheShell/void-rules/main/dist/cross-border-finance/plain-domain.txt) / [jsDelivr](https://cdn.jsdelivr.net/gh/VoidInTheShell/void-rules@main/dist/cross-border-finance/plain-domain.txt) |
| `ip-proxy-pools`       | [Raw](https://raw.githubusercontent.com/VoidInTheShell/void-rules/main/dist/ip-proxy-pools/mihomo-classical.yaml) / [jsDelivr](https://cdn.jsdelivr.net/gh/VoidInTheShell/void-rules@main/dist/ip-proxy-pools/mihomo-classical.yaml)             | [Raw](https://raw.githubusercontent.com/VoidInTheShell/void-rules/main/dist/ip-proxy-pools/mihomo-domain.mrs) / [jsDelivr](https://cdn.jsdelivr.net/gh/VoidInTheShell/void-rules@main/dist/ip-proxy-pools/mihomo-domain.mrs)             | [Raw](https://raw.githubusercontent.com/VoidInTheShell/void-rules/main/dist/ip-proxy-pools/xray-geosite.dat) / [jsDelivr](https://cdn.jsdelivr.net/gh/VoidInTheShell/void-rules@main/dist/ip-proxy-pools/xray-geosite.dat)             | —                                                                                                                                                                                                                                                                                                                                                                                                                                | [Raw](https://raw.githubusercontent.com/VoidInTheShell/void-rules/main/dist/ip-proxy-pools/plain-domain.txt) / [jsDelivr](https://cdn.jsdelivr.net/gh/VoidInTheShell/void-rules@main/dist/ip-proxy-pools/plain-domain.txt)             |
| `pcdn`                 | [Raw](https://raw.githubusercontent.com/VoidInTheShell/void-rules/main/dist/pcdn/mihomo-classical.yaml) / [jsDelivr](https://cdn.jsdelivr.net/gh/VoidInTheShell/void-rules@main/dist/pcdn/mihomo-classical.yaml)                                 | [Raw](https://raw.githubusercontent.com/VoidInTheShell/void-rules/main/dist/pcdn/mihomo-domain.mrs) / [jsDelivr](https://cdn.jsdelivr.net/gh/VoidInTheShell/void-rules@main/dist/pcdn/mihomo-domain.mrs)                                 | [Raw](https://raw.githubusercontent.com/VoidInTheShell/void-rules/main/dist/pcdn/xray-geosite.dat) / [jsDelivr](https://cdn.jsdelivr.net/gh/VoidInTheShell/void-rules@main/dist/pcdn/xray-geosite.dat)                                 | block：[Raw](https://raw.githubusercontent.com/VoidInTheShell/void-rules/main/dist/pcdn/adguard-block.txt) / [jsDelivr](https://cdn.jsdelivr.net/gh/VoidInTheShell/void-rules@main/dist/pcdn/adguard-block.txt)<br>allow：[Raw](https://raw.githubusercontent.com/VoidInTheShell/void-rules@main/dist/pcdn/adguard-allow.txt) / [jsDelivr](https://cdn.jsdelivr.net/gh/VoidInTheShell/void-rules@main/dist/pcdn/adguard-allow.txt) | [Raw](https://raw.githubusercontent.com/VoidInTheShell/void-rules/main/dist/pcdn/plain-domain.txt) / [jsDelivr](https://cdn.jsdelivr.net/gh/VoidInTheShell/void-rules@main/dist/pcdn/plain-domain.txt)                                 |


`fake-ip-bypass` 可单独用于 Fake-IP blacklist，或在 `rule` 模式下优先于 `fake-ip-force` 返回真实 IP；其他规则集按客户端对应的格式选择即可。每个目录中还提供 classical text/YAML、domain/ipcidr、Xray/V2Ray 和 `rules.jsonl.gz` 等完整输出。

`void-claude-rules` 建议使用 Mihomo/Clash `classical` 版本（rule-provider 设置 `behavior: classical`）。domain/MRS 只含可表达的域名，geosite DAT 只含域名匹配，IP 列表/geoip DAT 只含 CIDR；这些格式无法单独保留进程名、ASN 等全部规则，具体差异见该目录的 `compatibility.json`。CIDR/domain MRS 可对等价覆盖进行压缩，原始语义和来源保留在 `rules.jsonl.gz`。

该集合保留四个上游的规则范围，包括 `storage.googleapis.com`、`intercom.io`、`sentry.io` 和 `datadog`/`sentry`/`sift` 关键词，其他应用访问这些共享服务时也可能命中。使用 Claude 专用策略时，应将它放在通用 `ai`、广告拦截或其他会覆盖相同域名的规则之前；仅添加订阅源不会改变客户端的规则顺序。

## 自动更新

GitHub Actions 每 24 小时运行一次（每天 00:17 UTC）检查来源并重建全部规则。目录和配置格式、来源数量变化、受保护文件、冲突处理、代码质量、测试以及固定输入重建检查全部通过后，生成结果会直接提交到 `main`。`void-claude-rules` 通过独立 recipe 纳入同一流程，四个上游会一起拉取、规范化去重并保留逐条来源，无需额外定时任务。`fake-ip-force` 同时引用该集合，后续上游更新会自动进入其对应格式的产物。 定时/手动同步和 PR 校验均设有 Claude 联动检查：验证规则继承、去重与来源记录，并模拟上游增删域名，确认两个集合同步重建且可离线复现；检查失败时不会发布。

`stun` 同样加入每日同步：读取 MetaCubeX STUN 清单，按该清单和明确的本地 STUN/TURN 匹配模式从 DustinWin 混合源中分离 STUN，合并去重并保留双方来源；DustinWin 的 NTP 等其他规则不会混入。随后通过 bypass 的 `exclude_rulesets: [stun]` 自动排除各来源中的对应规则。分离所需的上游数据不可用时停止构建，避免用过期分类放行新成员；来源增长/缩水门禁继续保留。定时/手动同步和 PR 校验均检查双源去重及来源记录、独立输出、上游增删传播、NTP 保留及不可用源阻断。分离数量见 STUN manifest 的 `composition.filtered_sources`；排除明细和保留的父域交集见 bypass manifest 的 `composition.excluded_rulesets.stun`，域名/后缀交集报告不穷举正则、关键词或通配规则之间的覆盖。

PR、push 和手动验证使用 `discover --locked --check` 与 `sync --locked --check`，只重放随提交保存的 `generated/inputs/` 原始输入，并校验 SHA-256。上游正常更新不会再让旧提交的一致性检查报红；快照缺失、损坏或产物与配置不一致仍会失败。`--offline` 仅使用本地可变下载缓存，用于开发或迁移，不能替代固定输入验证。

构建会先完成全部解析、渲染和门槛检查，再写入产物、来源锁和快照。需要审查或中途失败时保留原基线，重复运行不能消除待审查项；本次失败原因保存在 `.work/reports/` 并随 Actions 失败报告上传。`--ruleset` 会扩展到依赖、下游引用方、共享来源和 Fake-IP 冲突检查涉及的规则集，其余全局来源锁和报告会保留；自动发布仍要求完整规则集通过固定输入重放及二进制校验。

自动发现只生成候选项，不直接添加规则。卡片目录按接口的 `nextOffset` 遍历分页，并核对总数、重复 ID 和分页进度；发现失败会停止同步。发布前还会核对保护文件、暂存区及验证后的产物摘要；若远端 `main` 已前进，则停止并要求基于新版本重跑同步。

## 目录说明

```text
catalog/                 公开来源和自动发现范围
recipes/                 每个规则集包含哪些来源
overlays/                人工补充、排除项和兼容性断言
schemas/                 配置格式检查
src/void_rules/          Python 规则整理程序
cmd/void-rules-geodata/  Xray/V2Ray DAT 工具
generated/               固定输入快照、来源锁、发现候选和构建报告
dist/                    可供客户端引用的稳定文件
tests/                   解析、合并、格式转换和自动化测试
```

来源项目的原始条款和署名信息见 [`NOTICE.md`](NOTICE.md) 以及每个生成目录中的来源清单。
