Routing depends on Math.random or the clock
low
Using Math.random() or the current time to pick a proxy produces different answers for identical requests. Load balancing done this way fragments connection pools and makes support cases impossible to reproduce.
Why it matters
Browsers call the PAC per request (connection), so random proxy selection scatters one
page load over several proxies, defeats connection reuse and breaks proxies that keep
per-client state (authentication sessions, sticky policies). Engines may also evaluate the
PAC on different threads or contexts, so even “random once at load” is not what it looks
like (PAC-K008). Failover and load distribution belong in the proxy list
(PROXY a; PROXY b) or in a load balancer in front of the proxies.
How to fix
Return a fixed, ordered proxy list and let the browser's failover or a load balancer distribute load.
Examples
Bad
function FindProxyForURL(url, host) {
if (Math.random() < 0.5) {
return "PROXY proxy1.corp.example:8080";
}
return "PROXY proxy2.corp.example:8080";
}
Open bad example in checkerGood
function FindProxyForURL(url, host) {
return "PROXY proxy1.corp.example:8080; PROXY proxy2.corp.example:8080";
}
Open good example in checkerRelated rules
- Mutable state outside FindProxyForURL PAC-K008
- Time-based routing (weekdayRange, dateRange, timeRange) PAC-K007
- Single proxy without a fallback entry PAC-B011