isInNet called with an invalid address, mask or argument count
high
The network or mask literal is not a dotted-quad IPv4 address, the mask is not contiguous, or the call has fewer than three arguments. The comparison is then false for every host.
Why it matters
isInNet(host, pattern, mask) only works with two syntactically valid IPv4 literals.
Typos such as 295.255.255.240, 10.0.0 or 255:255.255.0 do not raise an error in
most engines; the function just returns false and the DIRECT branch for the internal
network silently stops matching. Non-contiguous masks (255.0.255.0) are accepted by some
implementations and produce surprising matches. With only two arguments the mask is
undefined and the result is engine-dependent. IPv6 literals are not valid arguments for
the v1 function (PAC-K014).
How to fix
Use four decimal octets 0-255 for both address and mask; the mask must be a run of 1-bits followed by 0-bits (e.g. 255.240.0.0).
Examples
Bad
function FindProxyForURL(url, host) {
if (isInNet(host, "10.20.30.40", "295.255.255.240")) {
return "DIRECT";
}
return "PROXY proxy.corp.example:8080";
}
Open bad example in checkerGood
function FindProxyForURL(url, host) {
if (isInNet(host, "10.20.30.32", "255.255.255.240")) {
return "DIRECT";
}
return "PROXY proxy.corp.example:8080";
}
Open good example in checkerEngine behaviour
| Engine | Behaviour | Source |
|---|---|---|
| chromium | isInNet returns false when the network or mask literal is not a valid dotted quad (isValidIpAddress check); non-contiguous masks are accepted and applied bitwise. | code, verified 2026-10-04 · ref |
Related rules
- RFC 1918 range with the wrong mask PAC-C007
- isInNet arguments in the wrong order PAC-C016
- isInNet called with an IPv6 address PAC-K014