pacparser
Used by: pactester, python pacparser, old findproxyforurl.net backend.
Helper library
The checker runs this engine's own PAC helper library, copied verbatim at v1.5.3 (LGPL-3.0-or-later).
Upstream source.
Version ranges and quirks
pacparser ≤ 1.4
| Behaviour | Value | Source |
|---|---|---|
| alert() output | error | doc, unverified |
| Non-ASCII result rejected | false | code, verified 2026-10-04 |
| DNS lookups | sync | code, verified 2026-10-04 |
| dnsResolve is IPv4 only | true | code, verified 2026-10-04 |
| JavaScript level accepted | 3 | doc, verified 2026-10-04 |
| Calls FindProxyForURLEx if defined | true | code, verified 2026-10-04 |
| Microsoft *Ex functions | true | doc, verified 2026-10-04 |
| Global variables persist between calls | true | code, verified 2026-10-04 |
| Host lower-cased by the engine | false | code, verified 2026-10-04 |
| myIpAddress() source | user_supplied | code, verified 2026-10-04 |
| Native (C++) bindings | dnsResolve, myIpAddress, dnsResolveEx, myIpAddressEx | doc, verified 2026-10-04 |
| On exception | error | code, verified 2026-10-04 |
| On non-string / undefined result | stringify | code, verified 2026-10-04 |
| URL passed to FindProxyForURL | none | code, verified 2026-10-04 |
pacparser 1.5.0
| Behaviour | Value | Source |
|---|---|---|
| JavaScript level accepted | latest | doc, verified 2026-10-04 |
pacparser ≥ 1.5.1
| Behaviour | Value | Source |
|---|---|---|
| alert() output | console | code, verified 2026-10-04 |
| Native (C++) bindings | dnsResolve, myIpAddress, dnsResolveEx, myIpAddressEx, alert | code, verified 2026-10-04 |
Function availability
| Function | chromium | chromium | firefox | pacparser | pacparser | pacparser | reference |
|---|---|---|---|---|---|---|---|
isPlainHostName | yes | yes | yes | yes | yes | yes | yes |
dnsDomainIs | yes | yes | yes | yes | yes | yes | yes |
localHostOrDomainIs | yes | yes | yes | yes | yes | yes | yes |
isResolvable | yes | yes | yes | yes | yes | yes | yes |
isInNet | yes | yes | yes | yes | yes | yes | yes |
dnsResolve | yes | yes | yes | yes | yes | yes | yes |
myIpAddress | yes | yes | yes | yes | yes | yes | yes |
dnsDomainLevels | yes | yes | yes | yes | yes | yes | yes |
shExpMatch | yes | yes | yes | yes | yes | yes | yes |
weekdayRange | yes | yes | yes | yes | yes | yes | yes |
dateRange | yes | yes | yes | yes | yes | yes | yes |
timeRange | yes | yes | yes | yes | yes | yes | yes |
alert | yes | yes | yes | no | no | yes | yes |
dnsResolveEx | yes | yes | no | yes | yes | yes | no |
myIpAddressEx | yes | yes | no | yes | yes | yes | no |
isResolvableEx | yes | yes | no | yes | yes | yes | no |
isInNetEx | yes | yes | no | yes | yes | yes | no |
sortIpAddressList | yes | yes | no | no | no | no | no |
Rules with notes for pacparser
- PAC-C001Hostname pattern applied to url instead of host
shExpMatch(url, "example.com") does not match http://example.com/x; the same pattern on host does. lab, verified 2026-05-20
- PAC-C018Upper-case letters in a hostname pattern
Passes host as given; dnsDomainIs(host, ".example.com") does not match "Example.com". lab, verified 2026-05-20
- PAC-E012Proxy port out of range or not numeric
Returns the malformed string unchanged; no validation. lab, verified 2026-05-20
- PAC-K001ES2015+ syntax (let, const, arrow functions, template literals)
Depends on the bundled SpiderMonkey version; older builds reject ES2015 syntax. expert, unverified
- PAC-K002alert() used in the PAC
Message is passed to the host application's alert handler (pactester prints it). expert, unverified
- PAC-K003IPv6 extension functions (isInNetEx, dnsResolveEx, myIpAddressEx)
Ex functions are not implemented. expert, unverified
- PAC-K009Case-sensitive host comparisons without lower-casing host
Passes host as given to pactester; case-sensitive comparison. lab, verified 2026-05-20
- PAC-K013Routing decided by myIpAddress()
Resolves the local hostname via getaddrinfo; a fixed value can be injected for tests. expert, unverified
- PAC-X001No unconditional return at the end of FindProxyForURL
Returns undefined to the caller (pactester prints "undefined"). lab, verified 2026-05-20
- PAC-X002Trailing * in a host pattern matches attacker-controlled suffixes
"example.com*" matches example.com.evil.test lab, verified 2026-05-20
- PAC-X003dnsDomainIs pattern without a leading dot matches look-alike domains
dnsDomainIs(host, "example.com") is true for a look-alike ending in "example.com", for example.com itself and for www.example.com. lab, verified 2026-05-20
- PAC-X004Leading * without a dot matches look-alike domains
"*example.com" matches a look-alike domain ending in "example.com"; "*.example.com" does not. lab, verified 2026-05-20
- PAC-X006IP range matched as a text prefix
"127.*" matches the hostname 127.foo.evil.test; "127example.test" does not (the dot is required). lab, verified 2026-05-20
- PAC-X012Wildcard inside a domain label
A pattern of the form "name*.tld" matches look-alike names with extra characters before the TLD. lab, verified 2026-05-20
- PAC-X013PROXY entry without a port
Returns the unported string unchanged; no validation. lab, verified 2026-05-20