finds.dev← search

// the find

breakwa11/gfw_whitelist

★ 3,145 · JavaScript · MIT · updated Feb 2021

gfw_whitelist

A GFW (China's firewall) circumvention tool that flips the usual approach: instead of a blacklist PAC that needs constant updates as new sites get blocked, it generates a whitelist PAC where only known-good domains/IPs bypass the proxy and everything else routes through it. Aimed at users in China setting up SS/SSH/goagent proxies who want a config that doesn't rot every few weeks.

The whitelist-over-blacklist inversion is the actual insight here — it costs a bit more bandwidth but the PAC file stays useful without updates, unlike gfwlist-based blacklists that go stale the moment a new site gets blocked. It ships three PAC variants (domain-only, domain+IP, combined black/white) so users can trade off accuracy against DNS-pollution resistance depending on their network. It also includes real PAC evaluation benchmarks across Firefox, Chrome, IE9, and Safari (100k iterations each) — more rigor than most PAC generators bother with.

Dead since February 2021, and the domain-blocking data (custom.py, tld.py, IP ranges) hasn't been touched since — GFW behavior and CDN IP ranges have moved on enough that the shipped whitelist.pac/proxy.pac are almost certainly stale, which undercuts the project's whole low-maintenance pitch. The repo is tagged JavaScript on GitHub but the actual generator logic is Python (main.py, list_black.py); the JS tag only shows up because the output .pac files get counted, which is confusing if you're browsing by language. There's no CI and only a single pactest.py for validation, so a bad change to the generator could silently produce a broken PAC with nothing to catch it. The dynamic PAC endpoint depends on the maintainer's personal domain (proxy.breakwa11.ga), which the README itself flags as still 'in testing' — a single point of failure with no fallback.

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →