PAC-P006 · large-pac-file

PAC file is large

low · Performance

Above roughly 50 KB a PAC starts to cost measurable time per connection; above 1 MB engines refuse to load it. Long host lists usually belong on the proxy, not in the file every client downloads and executes.

Why it matters

The PAC is downloaded by every client and run for every connection. Thousands of if (shExpMatch(...)) lines are evaluated sequentially until one matches; for default-route traffic that is all of them. Very large files also hit hard limits: Chromium rejects PAC scripts above 1 MiB. Hostname allow-lists with hundreds of entries are a sign that proxy policy (categories, bypass lists) is being maintained in the PAC. Serve the file compressed (PAC-D006) as a stop-gap; move policy to the proxy as the fix.

How to fix

Move long bypass lists to the proxy; group remaining rules by domain suffix; enable gzip on the PAC server.

Examples

Bad

// imagine 3000 lines of the following
function FindProxyForURL(url, host) {
  if (host == "host0001.corp.example") { return "DIRECT"; }
  if (host == "host0002.corp.example") { return "DIRECT"; }
  if (host == "host0003.corp.example") { return "DIRECT"; }
  return "PROXY proxy.corp.example:8080";
}
Open bad example in checker

Good

function FindProxyForURL(url, host) {
  if (dnsDomainIs(host, ".corp.example")) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open good example in checker

Engine behaviour

EngineBehaviourSource
chromiumPAC scripts larger than 1 MiB are rejected by the fetcher.expert, unverified

Source: code = read in the engine's source, doc = vendor documentation, lab = observed in a lab run, expert = practitioner knowledge, not yet verified.

Related rules