SOCKS keywords mean different versions on different engines
low
The PAC format only defines "SOCKS host:port" and does not say which protocol version. Chromium treats plain SOCKS as SOCKS4 and also accepts SOCKS4 and SOCKS5; Firefox is reported to treat SOCKS as SOCKS5; WinHTTP support for the versioned keywords is unverified.
Why it matters
A SOCKS return is ambiguous by design: the original format predates the SOCKS4/SOCKS5
distinction. Chromium resolves the ambiguity towards SOCKS4 “for compatibility” (code,
2026-10-04) and understands the explicit SOCKS4 and SOCKS5 keywords. Firefox is
reported to speak SOCKS5 for plain SOCKS. An entry with a keyword an engine does not know
is dropped (PAC-E011). The result is that the same return string may use different protocol
versions on different browsers, or no proxy at all. SOCKS proxies are rare in enterprise
web routing; where one is needed, confirm the keyword and version on every target engine
and keep a PROXY fallback. Draft until the Firefox and WinHTTP behaviour is confirmed in
the lab.
How to fix
Prefer an HTTP proxy (PROXY host:port); if SOCKS is required, verify keyword and version per target engine and add a PROXY fallback.
Examples
Bad
function FindProxyForURL(url, host) {
return "SOCKS5 socks.corp.example:1080";
}
Open bad example in checkerGood
function FindProxyForURL(url, host) {
return "PROXY proxy.corp.example:8080; SOCKS socks.corp.example:1080";
}
Open good example in checkerEngine behaviour
| Engine | Behaviour | Source |
|---|---|---|
| chromium | Keywords SOCKS, SOCKS4 and SOCKS5 are accepted (case-insensitive); plain SOCKS is mapped to SOCKS4. | code, verified 2026-10-04 · ref |
| firefox | Reported to treat plain SOCKS as SOCKS5; versioned keywords unverified. | expert, unverified |
| winhttp | Unverified; needs lab run. | expert, unverified |
Related rules
- Return value is not a valid proxy string PAC-E011
- HTTPS proxy keyword without a PROXY fallback PAC-K006