PAC-K011 · nondeterministic-result

Routing depends on Math.random or the clock

low · Compatibility across engines

Using Math.random() or the current time to pick a proxy produces different answers for identical requests. Load balancing done this way fragments connection pools and makes support cases impossible to reproduce.

Why it matters

Browsers call the PAC per request (connection), so random proxy selection scatters one page load over several proxies, defeats connection reuse and breaks proxies that keep per-client state (authentication sessions, sticky policies). Engines may also evaluate the PAC on different threads or contexts, so even “random once at load” is not what it looks like (PAC-K008). Failover and load distribution belong in the proxy list (PROXY a; PROXY b) or in a load balancer in front of the proxies.

How to fix

Return a fixed, ordered proxy list and let the browser's failover or a load balancer distribute load.

Examples

Bad

function FindProxyForURL(url, host) {
  if (Math.random() < 0.5) {
    return "PROXY proxy1.corp.example:8080";
  }
  return "PROXY proxy2.corp.example:8080";
}
Open bad example in checker

Good

function FindProxyForURL(url, host) {
  return "PROXY proxy1.corp.example:8080; PROXY proxy2.corp.example:8080";
}
Open good example in checker

Related rules

References