PAC-C014 · shadowed-condition

Branch can never match because an earlier branch covers it

medium · Correctness

A later, more specific rule (www.corp.example -> proxy) is unreachable because an earlier, broader rule (*.corp.example -> DIRECT) returns for the same hosts. First match wins.

Why it matters

PAC functions are sequences of if (...) return; the first matching branch decides. When a broad pattern precedes a narrower one for the same hosts, the narrower rule is dead code. The typical story: an exception for one host was appended at the end of the file, below the wildcard that already catches it, and “does not work”. Detection compares literal patterns for subsumption (glob implies glob, suffix implies suffix, exact name under suffix).

Draft: the subsumption logic needs care with mixed function types and is still pending in the detector design.

How to fix

Order rules from specific to general, or remove the unreachable rule.

Examples

Bad

function FindProxyForURL(url, host) {
  if (shExpMatch(host, "*.corp.example")) {
    return "DIRECT";
  }
  if (host == "www.corp.example") {
    return "PROXY proxy.corp.example:8080";
  }
  return "PROXY proxy.corp.example:8080";
}
Open bad example in checker

Good

function FindProxyForURL(url, host) {
  if (host == "www.corp.example") {
    return "PROXY proxy.corp.example:8080";
  }
  if (shExpMatch(host, "*.corp.example")) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open good example in checker

Related rules