isInNet called with a hostname
medium
isInNet resolves its first argument when it is not already an IP address. Passing host means a DNS lookup for every non-IP request, with all the latency and fail-open behaviour of dnsResolve, and only one of possibly several addresses is checked.
Why it matters
isInNet(host, "10.0.0.0", "255.0.0.0") looks like a cheap arithmetic test but is
isInNet(dnsResolve(host), ...) in disguise whenever host is a name. If the name has
several A records, only one is compared, and which one is engine-dependent. If resolution
fails, the test is false and the request falls through. The intended check (“is this an
address in our range”) is cheap and deterministic when applied only to IP literals; guard
it with an IP-literal test. If names must be resolved, do it once and explicitly
(PAC-P004) after all string rules.
How to fix
Guard with /^\d+\.\d+\.\d+\.\d+$/.test(host) so isInNet only sees IP literals, or resolve once explicitly and compare the result.
Examples
Bad
function FindProxyForURL(url, host) {
if (dnsDomainIs(host, ".corp.example")) {
return "DIRECT";
}
if (isInNet(host, "10.0.0.0", "255.0.0.0")) {
return "DIRECT";
}
return "PROXY proxy.corp.example:8080";
}
Open bad example in checkerGood
function FindProxyForURL(url, host) {
if (dnsDomainIs(host, ".corp.example")) {
return "DIRECT";
}
if (/^\d+\.\d+\.\d+\.\d+$/.test(host) && isInNet(host, "10.0.0.0", "255.0.0.0")) {
return "DIRECT";
}
return "PROXY proxy.corp.example:8080";
}
Open good example in checkerEngine behaviour
| Engine | Behaviour | Source |
|---|---|---|
| chromium | isInNet resolves a non-literal first argument via dnsResolve in the helper library. | code, verified 2026-10-04 · ref |
Related rules
- DNS lookup on every request PAC-P001
- dnsResolve called repeatedly for the same host PAC-P004
- IP range matched as a text prefix PAC-X006