PAC-P002 · isinnet-on-hostname

isInNet called with a hostname

medium · Performance · Top 20 #16

isInNet resolves its first argument when it is not already an IP address. Passing host means a DNS lookup for every non-IP request, with all the latency and fail-open behaviour of dnsResolve, and only one of possibly several addresses is checked.

Why it matters

isInNet(host, "10.0.0.0", "255.0.0.0") looks like a cheap arithmetic test but is isInNet(dnsResolve(host), ...) in disguise whenever host is a name. If the name has several A records, only one is compared, and which one is engine-dependent. If resolution fails, the test is false and the request falls through. The intended check (“is this an address in our range”) is cheap and deterministic when applied only to IP literals; guard it with an IP-literal test. If names must be resolved, do it once and explicitly (PAC-P004) after all string rules.

How to fix

Guard with /^\d+\.\d+\.\d+\.\d+$/.test(host) so isInNet only sees IP literals, or resolve once explicitly and compare the result.

Examples

Bad

function FindProxyForURL(url, host) {
  if (dnsDomainIs(host, ".corp.example")) {
    return "DIRECT";
  }
  if (isInNet(host, "10.0.0.0", "255.0.0.0")) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open bad example in checker

Good

function FindProxyForURL(url, host) {
  if (dnsDomainIs(host, ".corp.example")) {
    return "DIRECT";
  }
  if (/^\d+\.\d+\.\d+\.\d+$/.test(host) && isInNet(host, "10.0.0.0", "255.0.0.0")) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open good example in checker

Engine behaviour

EngineBehaviourSource
chromiumisInNet resolves a non-literal first argument via dnsResolve in the helper library.code, verified 2026-10-04 · ref

Source: code = read in the engine's source, doc = vendor documentation, lab = observed in a lab run, expert = practitioner knowledge, not yet verified.

Related rules

References