PAC-X011 · fail-open-catch-direct

Exceptions are caught and turned into DIRECT

high · Security and fail-safety

A try/catch whose catch returns "DIRECT" converts every runtime problem (DNS failure, typo, engine quirk) into a proxy bypass. Errors should fail closed, towards the proxy.

Why it matters

Catching exceptions in a PAC is rarely useful; the engines already treat an uncaught exception as a script failure (which itself ends in DIRECT, PAC-E006). Catching and then returning DIRECT makes the fail-open explicit and permanent: a resolver outage, a renamed helper or any other bug now routes all affected traffic around the proxy without a trace in the engine’s error log. If a catch block exists, it should return the proxy, so that an error produces blocked or logged traffic instead of uninspected traffic.

How to fix

Remove the try/catch, or return the default proxy in the catch block.

Examples

Bad

function FindProxyForURL(url, host) {
  try {
    if (isInNet(dnsResolve(host), "10.0.0.0", "255.0.0.0")) {
      return "DIRECT";
    }
  } catch (e) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open bad example in checker

Good

function FindProxyForURL(url, host) {
  if (dnsDomainIs(host, ".corp.example")) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open good example in checker

Related rules