// ==============================================================================
// Sing-box 官方客户端标准配置模板 (适用于 Sing-box 1.14.0+)
// 功能特色：防 DNS / WebRTC 泄露、Fake-IP 分流、SagerNet 二进制规则集、零报错启动
// 提示：Sing-box 官方内核原生支持 // 单行注释与 /* 多行注释 */
// ==============================================================================

{
  "$schema": "https://raw.githubusercontent.com/SagerNet/sing-box/main/schemas/config.json",
  "log": {
    "disabled": false,
    "level": "info",
    "timestamp": true
  },
  "dns": {
    "servers": [
      {
        "tag": "dns_proxy",
        "type": "https",
        "server": "1.1.1.1",
        "detour": "节点选择"
      },
      {
        "tag": "dns_direct",
        "type": "https",
        "server": "223.5.5.5"
      },
      {
        "tag": "dns_fakeip",
        "type": "fakeip",
        "inet4_range": "198.18.0.0/15"
      }
    ],
    "rules": [
      {
        "clash_mode": "Direct",
        "server": "dns_direct"
      },
      {
        "clash_mode": "Global",
        "server": "dns_fakeip"
      },
      {
        "rule_set": "reject",
        "action": "predefined",
        "rcode": "NOERROR"
      },
      {
        "rule_set": [
          "geosite-private",
          "geosite-cn"
        ],
        "server": "dns_direct"
      },
      {
        "domain_suffix": [
          ".lan",
          ".local",
          "msftconnecttest.com",
          "msftncsi.com"
        ],
        "domain": [
          "localhost.ptlogin2.qq.com",
          "localhost.sec.qq.com",
          "localhost.work.weixin.qq.com",
          "pool.ntp.org"
        ],
        "domain_keyword": [
          "time"
        ],
        "server": "dns_direct"
      },
      {
        "query_type": [
          "A",
          "AAAA"
        ],
        "server": "dns_fakeip"
      }
    ],
    "strategy": "ipv4_only",
    "reverse_mapping": true
  },
  "http_clients": [
    {
      "tag": "default_http"
    }
  ],
  "inbounds": [
    {
      "type": "mixed",
      "tag": "mixed-in",
      "listen": "0.0.0.0",
      "listen_port": 7890
    },
    {
      "type": "tun",
      "tag": "tun-in",
      "address": [
        "172.19.0.1/30"
      ],
      "auto_route": true,
      "strict_route": true,
      "stack": "mixed"
    }
  ],
  "outbounds": [
    // --------------------------------------------------------------------------
    // 策略组 1：主出口选择 (Selector)
    // 💡 说明：当你添加了新节点后，请把节点的 tag（名称）添加到下方的 outbounds 数组中
    // --------------------------------------------------------------------------
    {
      "tag": "节点选择",
      "type": "selector",
      "outbounds": [
        "自动选择",
        "全局直连",
        "自建-VLESS-Reality示例",
        "自建-Hysteria2示例",
        "自建-SS示例"
      ]
    },
    // --------------------------------------------------------------------------
    // 策略组 2：自动测速优选 (URLTest)
    // 💡 说明：会自动测试下方列表里的节点延迟，并自动选用延迟最低的节点
    // --------------------------------------------------------------------------
    {
      "tag": "自动选择",
      "type": "urltest",
      "outbounds": [
        "自建-VLESS-Reality示例",
        "自建-Hysteria2示例",
        "自建-SS示例"
      ],
      "url": "https://cp.cloudflare.com/generate_204",
      "interval": "5m",
      "tolerance": 50
    },
    {
      "tag": "谷歌服务",
      "type": "selector",
      "outbounds": [
        "节点选择",
        "全局直连"
      ]
    },
    {
      "tag": "YouTube",
      "type": "selector",
      "outbounds": [
        "节点选择",
        "全局直连"
      ]
    },
    {
      "tag": "Telegram",
      "type": "selector",
      "outbounds": [
        "节点选择",
        "全局直连"
      ]
    },
    {
      "tag": "Spotify",
      "type": "selector",
      "outbounds": [
        "节点选择",
        "全局直连"
      ]
    },
    {
      "tag": "AI",
      "type": "selector",
      "outbounds": [
        "节点选择",
        "全局直连"
      ]
    },
    {
      "tag": "TikTok",
      "type": "selector",
      "outbounds": [
        "节点选择",
        "全局直连"
      ]
    },
    {
      "tag": "Netflix",
      "type": "selector",
      "outbounds": [
        "节点选择",
        "全局直连"
      ]
    },
    {
      "tag": "微软服务",
      "type": "selector",
      "outbounds": [
        "节点选择",
        "全局直连"
      ]
    },
    {
      "tag": "苹果服务",
      "type": "selector",
      "outbounds": [
        "全局直连",
        "节点选择"
      ]
    },
    {
      "tag": "iCloud服务",
      "type": "selector",
      "outbounds": [
        "全局直连",
        "节点选择"
      ]
    },
    {
      "tag": "动画疯",
      "type": "selector",
      "outbounds": [
        "节点选择",
        "全局直连"
      ]
    },
    // 💡 提示：如需针对 B 站港澳台单独指定节点（实现主节点选美国、B站单独选台湾），
    // 可在下方 outbounds 列表中追加你的台湾/香港节点名称（例如 "台湾 01"）
    {
      "tag": "哔哩哔哩港澳台",
      "type": "selector",
      "outbounds": [
        "全局直连",
        "节点选择"
      ]
    },
    {
      "tag": "广告过滤",
      "type": "selector",
      "outbounds": [
        "block",
        "direct"
      ]
    },
    {
      "tag": "漏网之鱼",
      "type": "selector",
      "outbounds": [
        "节点选择",
        "全局直连"
      ]
    },
    {
      "tag": "WebRTC防护",
      "type": "selector",
      "outbounds": [
        "block",
        "节点选择"
      ]
    },
    {
      "tag": "全局直连",
      "type": "direct"
    },
    {
      "tag": "direct",
      "type": "direct"
    },
    {
      "tag": "全局拦截",
      "type": "block"
    },
    {
      "tag": "block",
      "type": "block"
    },

    // ==========================================================================
    // 🚀【节点添加区域 / Node Configuration Area】
    // ==========================================================================
    // 💡 节点导入教程与常见方案：
    //
    // 【方案 A：使用 Sub-Store 转换机场订阅（最推荐、最简单）】
    //  1. 打开 Sub-Store 网页，在订阅输出格式中选择 "sing-box" 并复制生成的链接。
    //  2. 浏览器打开该链接，复制里面 "outbounds" 下的所有节点对象块。
    //  3. 粘贴到下方，并将节点的 "tag" 名称添加到顶部的 "节点选择" 与 "自动选择" 列表中。
    //
    // 【方案 B：手动填写自建 VPS 节点参数】
    //  下方提供了常用主流协议（VLESS Reality / Hysteria 2 / VMess / TUIC / SS）的示范模板。
    //  只需修改对应的 IP、端口、UUID、密码或公钥即可使用。
    // ==========================================================================

    // 示例 1：VLESS + XTLS + Reality 节点 (最推荐的抗封锁协议)
    {
      "tag": "自建-VLESS-Reality示例",
      "type": "vless",
      "server": "1.2.3.4", // 👈 修改为你 VPS 的 IP 地址或域名
      "server_port": 443,
      "uuid": "xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx", // 👈 修改为你的 UUID
      "flow": "xtls-rprx-vision",
      "packet_encoding": "xudp",
      "tls": {
        "enabled": true,
        "server_name": "apple.com", // 👈 修改为你的伪装域名 (SNI)
        "reality": {
          "enabled": true,
          "public_key": "你的Reality公钥填在此处", // 👈 服务端公钥
          "short_id": "02a1b631"               // 👈 服务端 ShortID
        },
        "utls": {
          "enabled": true,
          "fingerprint": "chrome"
        }
      }
    },

    // 示例 2：Hysteria 2 节点 (基于 UDP/QUIC 的超高速协议，适合大带宽)
    {
      "tag": "自建-Hysteria2示例",
      "type": "hysteria2",
      "server": "1.2.3.4", // 👈 修改为你 VPS 的 IP 地址或域名
      "server_port": 11410,
      "password": "your_password", // 👈 修改为你的密码
      "tls": {
        "enabled": true,
        "server_name": "www.bing.com", // 👈 修改为你的 SNI
        "insecure": false
      }
    },

    // 示例 3：VMess + WebSocket + TLS 节点 (经典稳定 CDN 节点)
    {
      "tag": "自建-VMess-WS示例",
      "type": "vmess",
      "server": "your-domain.com",
      "server_port": 443,
      "uuid": "xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx",
      "security": "auto",
      "alter_id": 0,
      "tls": {
        "enabled": true,
        "server_name": "your-domain.com"
      },
      "transport": {
        "type": "ws",
        "path": "/your-path",
        "headers": {
          "Host": "your-domain.com"
        }
      }
    },

    // 示例 4：TUIC v5 节点 (新一代高性能 UDP 协议)
    {
      "tag": "自建-TUIC-v5示例",
      "type": "tuic",
      "server": "1.2.3.4",
      "server_port": 11588,
      "uuid": "xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx",
      "password": "your_password",
      "tls": {
        "enabled": true,
        "server_name": "www.bing.com",
        "insecure": true,
        "alpn": [
          "h3"
        ]
      },
      "congestion_control": "bbr"
    },

    // 示例 5：Shadowsocks 经典节点
    {
      "tag": "自建-SS示例",
      "type": "shadowsocks",
      "server": "1.2.3.4",
      "server_port": 8388,
      "method": "chacha20-ietf-poly1305",
      "password": "your_password"
    }
  ],
  "route": {
    "default_domain_resolver": "dns_direct",
    "default_http_client": "default_http",
    "rules": [
      {
        "action": "sniff"
      },
      {
        "protocol": "dns",
        "action": "hijack-dns"
      },
      {
        "process_name": [
          "Zoom.exe"
        ],
        "outbound": "全局直连"
      },
      {
        "process_name": [
          "Discord.exe"
        ],
        "outbound": "节点选择"
      },
      {
        "domain_suffix": [
          "zoom.us",
          "zoom.com"
        ],
        "outbound": "全局直连"
      },
      {
        "domain_suffix": [
          "discord.com",
          "discord.gg"
        ],
        "outbound": "节点选择"
      },
      {
        "port": [
          3478,
          5349,
          19302,
          19303,
          19304,
          19305,
          19306,
          19307,
          19308,
          19309
        ],
        "outbound": "WebRTC防护"
      },
      {
        "domain_keyword": [
          "stun"
        ],
        "outbound": "WebRTC防护"
      },
      {
        "clash_mode": "Direct",
        "outbound": "direct"
      },
      {
        "clash_mode": "Global",
        "outbound": "节点选择"
      },
      {
        "domain_suffix": [
          "googleapis.cn",
          "gstatic.com",
          "xn--ngstr-lra8j.com"
        ],
        "outbound": "谷歌服务"
      },
      {
        "domain_suffix": [
          "github.io"
        ],
        "outbound": "节点选择"
      },
      {
        "domain": [
          "v2rayse.com"
        ],
        "outbound": "节点选择"
      },
      {
        "rule_set": "reject",
        "outbound": "广告过滤"
      },
      {
        "rule_set": "geosite-private",
        "outbound": "全局直连"
      },
      {
        "rule_set": "icloud",
        "outbound": "iCloud服务"
      },
      {
        "rule_set": "apple",
        "outbound": "苹果服务"
      },
      {
        "rule_set": "youtube",
        "outbound": "YouTube"
      },
      {
        "rule_set": "netflix",
        "outbound": "Netflix"
      },
      {
        "rule_set": [
          "telegram",
          "geoip-telegram"
        ],
        "outbound": "Telegram"
      },
      {
        "rule_set": "spotify",
        "outbound": "Spotify"
      },
      {
        "rule_set": "bahamut",
        "outbound": "动画疯"
      },
      {
        "domain_suffix": [
          "bsbsb.top"
        ],
        "outbound": "哔哩哔哩港澳台"
      },
      {
        "rule_set": "bilibili",
        "outbound": "哔哩哔哩港澳台"
      },
      {
        "rule_set": "ai",
        "outbound": "AI"
      },
      {
        "rule_set": "tiktok",
        "outbound": "TikTok"
      },
      {
        "rule_set": "microsoft",
        "outbound": "微软服务"
      },
      {
        "rule_set": "google",
        "outbound": "谷歌服务"
      },
      {
        "rule_set": "gfw",
        "outbound": "节点选择"
      },
      {
        "rule_set": "geolocation-!cn",
        "outbound": "节点选择"
      },
      {
        "rule_set": [
          "geosite-cn",
          "geoip-cn"
        ],
        "outbound": "全局直连"
      }
    ],
    "rule_set": [
      {
        "tag": "reject",
        "type": "remote",
        "format": "binary",
        "url": "https://fastly.jsdelivr.net/gh/SagerNet/sing-geosite@rule-set/geosite-category-ads-all.srs"
      },
      {
        "tag": "icloud",
        "type": "remote",
        "format": "binary",
        "url": "https://fastly.jsdelivr.net/gh/SagerNet/sing-geosite@rule-set/geosite-icloud.srs"
      },
      {
        "tag": "apple",
        "type": "remote",
        "format": "binary",
        "url": "https://fastly.jsdelivr.net/gh/SagerNet/sing-geosite@rule-set/geosite-apple.srs"
      },
      {
        "tag": "google",
        "type": "remote",
        "format": "binary",
        "url": "https://fastly.jsdelivr.net/gh/SagerNet/sing-geosite@rule-set/geosite-google.srs"
      },
      {
        "tag": "youtube",
        "type": "remote",
        "format": "binary",
        "url": "https://fastly.jsdelivr.net/gh/SagerNet/sing-geosite@rule-set/geosite-youtube.srs"
      },
      {
        "tag": "telegram",
        "type": "remote",
        "format": "binary",
        "url": "https://fastly.jsdelivr.net/gh/SagerNet/sing-geosite@rule-set/geosite-telegram.srs"
      },
      {
        "tag": "netflix",
        "type": "remote",
        "format": "binary",
        "url": "https://fastly.jsdelivr.net/gh/SagerNet/sing-geosite@rule-set/geosite-netflix.srs"
      },
      {
        "tag": "spotify",
        "type": "remote",
        "format": "binary",
        "url": "https://fastly.jsdelivr.net/gh/SagerNet/sing-geosite@rule-set/geosite-spotify.srs"
      },
      {
        "tag": "bahamut",
        "type": "remote",
        "format": "binary",
        "url": "https://fastly.jsdelivr.net/gh/SagerNet/sing-geosite@rule-set/geosite-bahamut.srs"
      },
      {
        "tag": "bilibili",
        "type": "remote",
        "format": "binary",
        "url": "https://fastly.jsdelivr.net/gh/SagerNet/sing-geosite@rule-set/geosite-bilibili.srs"
      },
      {
        "tag": "ai",
        "type": "remote",
        "format": "binary",
        "url": "https://fastly.jsdelivr.net/gh/SagerNet/sing-geosite@rule-set/geosite-openai.srs"
      },
      {
        "tag": "tiktok",
        "type": "remote",
        "format": "binary",
        "url": "https://fastly.jsdelivr.net/gh/SagerNet/sing-geosite@rule-set/geosite-tiktok.srs"
      },
      {
        "tag": "microsoft",
        "type": "remote",
        "format": "binary",
        "url": "https://fastly.jsdelivr.net/gh/SagerNet/sing-geosite@rule-set/geosite-microsoft.srs"
      },
      {
        "tag": "gfw",
        "type": "remote",
        "format": "binary",
        "url": "https://fastly.jsdelivr.net/gh/lyc8503/sing-box-rules@rule-set-geosite/geosite-gfw.srs"
      },
      {
        "tag": "geolocation-!cn",
        "type": "remote",
        "format": "binary",
        "url": "https://fastly.jsdelivr.net/gh/SagerNet/sing-geosite@rule-set/geosite-geolocation-!cn.srs"
      },
      {
        "tag": "geosite-cn",
        "type": "remote",
        "format": "binary",
        "url": "https://fastly.jsdelivr.net/gh/SagerNet/sing-geosite@rule-set/geosite-cn.srs"
      },
      {
        "tag": "geosite-private",
        "type": "remote",
        "format": "binary",
        "url": "https://fastly.jsdelivr.net/gh/SagerNet/sing-geosite@rule-set/geosite-private.srs"
      },
      {
        "tag": "geoip-cn",
        "type": "remote",
        "format": "binary",
        "url": "https://fastly.jsdelivr.net/gh/SagerNet/sing-geoip@rule-set/geoip-cn.srs"
      },
      {
        "tag": "geoip-telegram",
        "type": "remote",
        "format": "binary",
        "url": "https://fastly.jsdelivr.net/gh/lyc8503/sing-box-rules@rule-set-geoip/geoip-telegram.srs"
      }
    ],
    "final": "漏网之鱼",
    "auto_detect_interface": true
  },
  "experimental": {
    "cache_file": {
      "enabled": true,
      "store_fakeip": true
    }
  }
}
