PAC-E011 · invalid-return-value

Return value is not a valid proxy string

high · Errors and robustness

The function returns something that is not a string of semicolon-separated 'DIRECT' / 'PROXY host:port' / 'SOCKS host:port' entries (or an engine-specific extension). Engines drop what they cannot parse and typically end up DIRECT.

Why it matters

The return grammar is a list of entries separated by ;, each DIRECT, PROXY host:port or SOCKS host:port. Chromium additionally understands HTTPS, SOCKS4 and SOCKS5 (see PAC-K005, PAC-K006); it does not accept HTTP or QUIC as PAC keywords. A return of a number, null, an object, an empty string, a non-ASCII string, a keyword without a space before the host, host: with an empty port, or an unknown keyword is a malformed directive. Keyword matching itself is case-insensitive in Chromium, but other engines are not guaranteed to be as lenient. Entries that fail to parse are skipped; when nothing is left the client connects directly. This is mechanism (c) of the “silent DIRECT” family: the PAC appears to work, the proxy is simply not used.

How to fix

Return a string such as "PROXY proxy.corp.example:8080; DIRECT" with upper-case keywords and one space before host:port.

Examples

Bad

function FindProxyForURL(url, host) {
  if (isPlainHostName(host)) {
    return "direct";
  }
  return "Proxy:proxy.corp.example:8080";
}
Open bad example in checker

Good

function FindProxyForURL(url, host) {
  if (isPlainHostName(host)) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open good example in checker

Engine behaviour

EngineBehaviourSource
chromiumEntries that do not parse are skipped; if no valid entry remains the list is treated as DIRECT (ProxyList::SetFromPacString). Accepted keywords (case-insensitive) are PROXY, HTTPS, SOCKS, SOCKS4, SOCKS5, DIRECT. A non-ASCII return string fails the evaluation.code, verified 2026-10-04 · ref

Source: code = read in the engine's source, doc = vendor documentation, lab = observed in a lab run, expert = practitioner knowledge, not yet verified.

Related rules

References