Chromium (Chrome, Edge, Brave, Opera, Electron)
Used by: Chrome, Edge, Brave, Opera, Vivaldi, Electron.
Helper library
The checker runs this engine's own PAC helper library, copied verbatim at cb6eb0e7cac0 (BSD-3-Clause (Chromium); JS body MPL-1.1/GPL-2.0/LGPL-2.1 (Mozilla-derived)).
Upstream source.
Version ranges and quirks
Chrome ≤ 51
| Behaviour | Value | Source |
|---|---|---|
| alert() output | netlog | code, verified 2026-10-04 |
| Non-ASCII result rejected | true | code, verified 2026-10-04 |
| DNS lookups | async | expert, unverified |
| dnsResolve is IPv4 only | true | code, verified 2026-10-04 |
| JavaScript level accepted | latest | code, verified 2026-10-04 |
| Calls FindProxyForURLEx if defined | false | code, verified 2026-10-04 |
| Microsoft *Ex functions | true | code, verified 2026-10-04 |
| Global variables persist between calls | true | code, verified 2026-10-04 |
| Host lower-cased by the engine | true | expert, unverified |
| myIpAddress() source | routing_ipv4 | expert, unverified |
| Native (C++) bindings | alert, myIpAddress, dnsResolve, isPlainHostName, dnsResolveEx, myIpAddressEx, sortIpAddressList, isInNetEx | code, verified 2026-10-04 |
| On exception | direct | code, verified 2026-10-04 |
| On non-string / undefined result | direct | code, verified 2026-10-04 |
| URL passed to FindProxyForURL | none | code, verified 2026-10-04 |
Chrome ≥ 52
| Behaviour | Value | Source |
|---|---|---|
| URL passed to FindProxyForURL | https_path_query | code, verified 2026-10-04 |
Function availability
| Function | chromium | chromium | firefox | pacparser | pacparser | pacparser | reference |
|---|---|---|---|---|---|---|---|
isPlainHostName | yes | yes | yes | yes | yes | yes | yes |
dnsDomainIs | yes | yes | yes | yes | yes | yes | yes |
localHostOrDomainIs | yes | yes | yes | yes | yes | yes | yes |
isResolvable | yes | yes | yes | yes | yes | yes | yes |
isInNet | yes | yes | yes | yes | yes | yes | yes |
dnsResolve | yes | yes | yes | yes | yes | yes | yes |
myIpAddress | yes | yes | yes | yes | yes | yes | yes |
dnsDomainLevels | yes | yes | yes | yes | yes | yes | yes |
shExpMatch | yes | yes | yes | yes | yes | yes | yes |
weekdayRange | yes | yes | yes | yes | yes | yes | yes |
dateRange | yes | yes | yes | yes | yes | yes | yes |
timeRange | yes | yes | yes | yes | yes | yes | yes |
alert | yes | yes | yes | no | no | yes | yes |
dnsResolveEx | yes | yes | no | yes | yes | yes | no |
myIpAddressEx | yes | yes | no | yes | yes | yes | no |
isResolvableEx | yes | yes | no | yes | yes | yes | no |
isInNetEx | yes | yes | no | yes | yes | yes | no |
sortIpAddressList | yes | yes | no | no | no | no | no |
Rules with notes for chromium
- PAC-C001Hostname pattern applied to url instead of host
For https:// URLs the path, query, fragment and userinfo are stripped before FindProxyForURL is called (since Chrome 52; the opt-out was removed in Chrome 75); url is reduced to scheme://host:port/. http:// URLs are passed with path and query. doc, verified 2026-10-04 · ref
- PAC-C004Wildcard characters in dnsDomainIs or localHostOrDomainIs
dnsDomainIs is a plain suffix comparison in the helper library. code, verified 2026-10-04 · ref
- PAC-C018Upper-case letters in a hostname pattern
host is passed lower-cased (URL canonicalisation). doc, unverified
- PAC-C027Cloudflare Gateway proxy endpoint with PROXY instead of HTTPS
"HTTPS host:port" opens TLS to the proxy; accepted PAC keyword. doc, verified 2026-10-04 · ref
- PAC-D002Content-Type is not application/x-ns-proxy-autoconfig
Content-Type is not enforced for PAC fetches (the body is used as script). expert, unverified
- PAC-D003No Cache-Control header on the PAC response
Without caching headers the PAC is re-fetched on an internal schedule and on network changes. expert, unverified
- PAC-D009PAC loaded from a file path or SMB share
file: PAC URLs are not supported. expert, unverified
- PAC-D010PAC URL does not return 200
Fetch failure falls back to DIRECT unless ProxyPacMandatory is set; the fetch is retried with back-off. doc, unverified
- PAC-E001PAC file does not parse
Script load fails; requests go DIRECT unless the ProxyPacMandatory policy is set. doc, verified 2026-10-04 · ref
- PAC-E002No FindProxyForURL function
FindProxyForURL is required; its absence is a script error and connections go DIRECT. code, verified 2026-10-04 · ref
- PAC-E005Call to a function that is not defined
An exception inside FindProxyForURL fails the evaluation (ERR_PAC_SCRIPT_FAILED); the request falls back to DIRECT unless ProxyPacMandatory is set. code, verified 2026-10-04 · ref
- PAC-E010isInNet called with an invalid address, mask or argument count
isInNet returns false when the network or mask literal is not a valid dotted quad (isValidIpAddress check); non-contiguous masks are accepted and applied bitwise. code, verified 2026-10-04 · ref
- PAC-E011Return value is not a valid proxy string
Entries that do not parse are skipped; if no valid entry remains the list is treated as DIRECT (ProxyList::SetFromPacString). Accepted keywords (case-insensitive) are PROXY, HTTPS, SOCKS, SOCKS4, SOCKS5, DIRECT. A non-ASCII return string fails the evaluation. code, verified 2026-10-04 · ref
- PAC-E012Proxy port out of range or not numeric
host:port that does not canonicalise to a valid port yields an invalid ProxyServer; the entry is dropped and the remaining list (empty = DIRECT) is used. code, verified 2026-10-04 · ref
- PAC-E013File starts with a UTF-8 byte order mark
BOM is skipped by the parser. expert, unverified
- PAC-E014Non-ASCII characters in code
A non-ASCII string returned by FindProxyForURL is rejected as a script error ("returned a non-ASCII string"); non-ASCII inside string literals that are not returned is not an error. code, verified 2026-10-04 · ref
- PAC-E018console.log or other browser APIs used in the PAC
Resolver context provides only the PAC helpers and ECMAScript built-ins; console is not defined. expert, unverified
- PAC-K001ES2015+ syntax (let, const, arrow functions, template literals)
V8; current ECMAScript syntax parses. code, verified 2026-10-04 · ref
- PAC-K002alert() used in the PAC
alert is bound (AlertCallback) and the message is forwarded to the resolver bindings, which record it in the network log; no dialog, no exception. code, verified 2026-10-04 · ref
- PAC-K003IPv6 extension functions (isInNetEx, dnsResolveEx, myIpAddressEx)
The Ex functions are implemented (isResolvableEx in the JS helper library, dnsResolveEx/myIpAddressEx/sortIpAddressList as native bindings in proxy_resolver_v8.cc). code, verified 2026-10-04 · ref
- PAC-K004FindProxyForURLEx entry point
Only FindProxyForURL is called. code, verified 2026-10-04 · ref
- PAC-K005SOCKS keywords mean different versions on different engines
Keywords SOCKS, SOCKS4 and SOCKS5 are accepted (case-insensitive); plain SOCKS is mapped to SOCKS4. code, verified 2026-10-04 · ref
- PAC-K006HTTPS proxy keyword without a PROXY fallback
"HTTPS host:port" is an accepted PAC return keyword (TLS to the proxy; HTTP/2 to the proxy is possible, QUIC is not selectable from PAC). doc, verified 2026-10-04 · ref
- PAC-K009Case-sensitive host comparisons without lower-casing host
host is passed lower-cased (URL canonicalisation). doc, unverified
- PAC-K012Engines return different results for the same URL
Path and query of https URLs are not visible to the PAC (since Chrome 52). doc, verified 2026-10-04 · ref
- PAC-K013Routing decided by myIpAddress()
Ordered heuristic: (1) source address of a route to 8.8.8.8 / 2001:4860:4860::8888, (2) first address from resolving the machine's hostname (IPv4 preferred), (3) route to 10.0.0.0 / 172.16.0.0 / 192.168.0.0 / fc00::; link-local and loopback only as last resort; returns 127.0.0.1 on failure. Before M72 it was just getaddrinfo(gethostname). doc, verified 2026-10-04 · ref
- PAC-K015Regular-expression syntax inside a shExpMatch pattern
shExpMatch converts the glob to a RegExp without escaping ( ) | ; regex alternation works. code, verified 2026-10-04 · ref
- PAC-P001DNS lookup on every request
Resolution goes through the network service; the PAC evaluation waits for the answer. expert, unverified
- PAC-P002isInNet called with a hostname
isInNet resolves a non-literal first argument via dnsResolve in the helper library. code, verified 2026-10-04 · ref
- PAC-P006PAC file is large
PAC scripts larger than 1 MiB are rejected by the fetcher. expert, unverified
- PAC-X001No unconditional return at the end of FindProxyForURL
A non-string result is reported as "FindProxyForURL() did not return a string." and the evaluation fails (ERR_PAC_SCRIPT_FAILED); the request then falls back to DIRECT unless ProxyPacMandatory is set. code, verified 2026-10-04 · ref
- PAC-X003dnsDomainIs pattern without a leading dot matches look-alike domains
Suffix comparison without boundary check (helper library implementation). code, verified 2026-10-04 · ref
- PAC-X013PROXY entry without a port
Missing port is replaced by the scheme default (PROXY 80, HTTPS 443, SOCKS/SOCKS4/SOCKS5 1080; ProxyServer::GetDefaultPortForScheme). "host:" with an empty port is rejected as an invalid entry. code, verified 2026-10-04 · ref