multiproxy maintains a SOCKS5 proxy on 127.0.0.1:1080. It discovers routes
from an OpenSSH config, selects the fastest reachable one, tests actual Google
traffic through the SOCKS tunnel, and reconnects or fails over when traffic
stalls. SSH keepalives also make dead connections terminate promptly instead of
hanging forever.
./install.sh
multiproxy routes
multiproxy start
multiproxy status
multiproxy testStop it with multiproxy stop. Logs are in
~/.local/state/multiproxy/multiproxy.log.
To use the proxy in a shell:
export ALL_PROXY=socks5h://127.0.0.1:1080
export HTTPS_PROXY=$ALL_PROXY
export HTTP_PROXY=$ALL_PROXYThe h in socks5h matters: DNS is resolved outside China by the SSH exit.
The first run records ~/.ssh/config as the authoritative source. OpenSSH
Include files are followed recursively. cam and srcf are exit hosts;
every other concrete Host alias is considered a possible jump. The tool tries
direct, one-jump, and two-jump permutations automatically. ProxyJump
directives already attached to aliases continue to apply. The repository's
sshconfig file is an example and is not used automatically.
cam
cam via scm1
cam via lxt-node3 -> scm1
srcf
srcf via scm2
...
Successful paths and their measured latency are stored in
~/.local/state/multiproxy/routes.json. Startup only rechecks those remembered
paths. If all fail, discovery runs again and replaces the cache. Run
multiproxy routes to force rediscovery after editing SSH config. Change
max_jump_hops in ~/.config/multiproxy/config.json to bound the search.
Discovery runs up to 8 SSH probes concurrently by default. New handshakes are
paced 350 ms apart, and only one probe at a time may use the same first-hop
host. multiproxy routes -j N changes global concurrency but deliberately does
not bypass these anti-burst safeguards. Advanced users can tune
per_host_workers and probe_launch_interval in the config, but increasing
them can trigger SSH rate limits or automated source-IP blocks.
Discovery is progressive: direct exits are probed together first, followed by
all one-hop routes, then all two-hop routes. It stops after remembering two
working paths (min_working_routes), avoiding needless combinatorial probes.
Authentication must work non-interactively (SSH agent or key), because the
watchdog deliberately uses BatchMode=yes.
Discovery is not in the data path. Once selected, the proxy is one ordinary
ssh -D process. A multi-hop route can naturally be slower than a direct route;
measured latency determines preference, and direct routes remain candidates.
The health URL defaults to Google's generate_204 endpoint. Change test_url
if Google blocks that endpoint on a particular exit route.