DNS-dependent rule placed before string rules
low
Rules execute in source order and the first match returns. When a DNS-dependent rule precedes string rules, every request pays the lookup even if a later cheap rule would have decided it.
Why it matters
isPlainHostName, literal comparisons, shExpMatch and dnsDomainIs cost microseconds;
dnsResolve, isResolvable and isInNet on a name cost a resolver round trip. Putting
the cheap, frequently matching rules first means most requests never reach the expensive
ones. This is the ordering rule; PAC-P001 is the stronger statement that the expensive rules
should ideally not exist.
How to fix
Move isPlainHostName, host == and suffix/glob rules above any DNS-dependent rule.
Examples
Bad
function FindProxyForURL(url, host) {
var ip = dnsResolve(host);
if (ip && isInNet(ip, "10.0.0.0", "255.0.0.0")) {
return "DIRECT";
}
if (isPlainHostName(host)) {
return "DIRECT";
}
return "PROXY proxy.corp.example:8080";
}
Open bad example in checkerGood
function FindProxyForURL(url, host) {
if (isPlainHostName(host)) {
return "DIRECT";
}
var ip = dnsResolve(host);
if (ip && isInNet(ip, "10.0.0.0", "255.0.0.0")) {
return "DIRECT";
}
return "PROXY proxy.corp.example:8080";
}
Open good example in checker