{"id":6176,"date":"2026-09-05T10:00:34","date_gmt":"2026-09-05T01:00:34","guid":{"rendered":"https:\/\/eternalsphere.net\/echoes\/?p=6176"},"modified":"2026-09-12T14:03:15","modified_gmt":"2026-09-12T05:03:15","slug":"5c0auwqj8v24d31","status":"publish","type":"post","link":"https:\/\/blog.eternalsphere.net\/index.php\/2026\/09\/05\/5c0auwqj8v24d31\/","title":{"rendered":"Understanding Tor Relay Flags: Running, Valid, Fast, Stable, HSDir, and Guard"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Tor relay flags describe what the network currently knows about a relay and which roles that relay is eligible to perform.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">They are not badges manually assigned by Tor Project staff. Most are calculated automatically by Directory Authorities according to protocol rules and network measurements.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Running<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><code>Running<\/code> means the Directory Authorities currently consider the relay reachable.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A relay that is publicly accessible and responding correctly on its ORPort can receive this flag relatively quickly.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Conceptually:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>ORPort reachable\n     \u2193\nAuthority confirms connectivity\n     \u2193\nRunning<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Losing Internet connectivity for long enough can cause the flag to disappear. It can return after reachability is restored.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Valid<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><code>Valid<\/code> means the relay is accepted as a valid participant in the Tor network.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It is not a performance rating.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A relay may be:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Valid<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">while still being:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>slow\nnew\nlightly used<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The flag primarily indicates that the relay has not been excluded from normal consideration.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">V2Dir<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><code>V2Dir<\/code> indicates that the relay can participate in Tor directory-cache functionality.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The name is historical and can be confusing.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Most importantly:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>V2Dir \u2260 Directory Authority<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">A V2Dir relay is still an ordinary relay.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Fast<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><code>Fast<\/code> indicates that the relay satisfies the Tor network&#8217;s current bandwidth criteria for fast-relay use.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This flag depends primarily on measured network capacity rather than age alone.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A newly deployed relay may therefore progress:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Running\nValid\nV2Dir\n   \u2193\nbandwidth measurement\n   \u2193\nFast<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">There is no universal rule such as:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>12 hours online = Fast<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The result depends on measurement timing and the current network-wide threshold.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For a capable new relay, obtaining <code>Fast<\/code> can occur within hours or days.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Stable<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><code>Stable<\/code> is much more dependent on historical behavior.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It reflects metrics related to long-term reliability, including weighted mean time between failures.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A relay that repeatedly disappears and reappears will have more difficulty becoming Stable than a continuously available relay.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is why:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>current uptime<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">and:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>historical stability<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">are not the same thing.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A relay can restart and later still be considered Stable because the decision incorporates longer-term history.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The realistic time scale is typically days rather than hours.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">HSDir<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><code>HSDir<\/code> means the relay is eligible to participate in the distributed directory system used by onion services.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">An HSDir does not host the onion service itself.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Its role is associated with onion-service descriptor storage and retrieval.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Eligibility generally depends on conditions including:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Fast\n+\nStable\n+\nsufficient continuous known time<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">A newly deployed relay therefore cannot immediately become an HSDir.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A minimum time scale of several days is expected.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Guard<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><code>Guard<\/code> is one of the most significant relay flags.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Guard relays can be selected as the first hop in a Tor circuit:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Client\n  \u2193\nGuard\n  \u2193\nMiddle\n  \u2193\nExit<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Tor deliberately applies stricter requirements to Guards because the first relay directly observes the client&#8217;s network address.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Guard eligibility depends on a combination of:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>bandwidth<\/li>\n\n\n\n<li>Fast status<\/li>\n\n\n\n<li>Stable status<\/li>\n\n\n\n<li>uptime history<\/li>\n\n\n\n<li>time known to the authorities<\/li>\n\n\n\n<li>other network thresholds<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">For this reason, <code>Guard<\/code> is generally a <strong>weeks-scale<\/strong> milestone rather than an hours-scale milestone.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Exit<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><code>Exit<\/code> means the relay is eligible to send Tor traffic to destinations on the ordinary Internet.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A relay configured with a policy equivalent to:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>reject *:*<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">cannot operate as a normal Exit and therefore does not receive the Exit role.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This distinction is operationally important because Exit relays have significantly different abuse and legal exposure from non-exit relays.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">BadExit<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><code>BadExit<\/code> is an administrative safety flag used when a relay should not be trusted for normal Exit operation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It does not necessarily mean:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>server compromised<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">It means the network has determined that the relay should not be selected as a normal exit.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Authority<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><code>Authority<\/code> identifies one of the small number of Tor Directory Authorities.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Ordinary relay operators cannot simply enable this flag.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Directory Authorities form part of Tor&#8217;s network-governance infrastructure and participate in producing the consensus.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">MiddleOnly<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><code>MiddleOnly<\/code> indicates a relay that should be used only in middle positions rather than as Guard or Exit.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It is relatively uncommon compared with flags such as Running, Valid, Fast, or Stable.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Flags Can Be Combined<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Flags are not mutually exclusive.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A mature non-exit Guard relay might show:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Fast\nGuard\nRunning\nStable\nV2Dir\nValid<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">while a brand-new relay might initially show only:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Running\nValid\nV2Dir<\/code><\/pre>\n\n\n\n<h2 class=\"wp-block-heading\">Approximate Time Scales<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A practical way to think about relay development is:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>First hours:\nRunning \/ Valid \/ V2Dir\n\nHours to days:\nFast\n\nDays to a week or longer:\nStable\n\nSeveral days or more:\nHSDir\n\nWeeks:\nGuard<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">These are observation ranges, not guaranteed deadlines.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Conclusion<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Tor flags answer a different question from bandwidth or connection count.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">They describe <strong>eligibility and network status<\/strong>:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Running \u2192 Is it reachable?\nValid   \u2192 Is it accepted?\nFast    \u2192 Is it sufficiently fast?\nStable  \u2192 Has it proven reliable?\nHSDir   \u2192 Can it participate in onion-service directory functions?\nGuard   \u2192 Can it protect the first hop of client circuits?\nExit    \u2192 Can it send traffic to the public Internet?<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">For relay operators, the best way to earn the later flags is remarkably simple: maintain a reachable, well-performing, continuously available relay and allow the directory system to accumulate history.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Tor relay flags describe what the network currently knows about a relay and which roles that relay is eligible to perform. They are not badges manually assigned by Tor Project staff. Most are calculated automatically by Directory Authorities according to protocol rules and network measurements. Running Running means the Directory &hellip;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[120],"tags":[245],"class_list":["post-6176","post","type-post","status-publish","format-standard","hentry","category-1s3b6h7r2zay02x","tag-tor"],"_links":{"self":[{"href":"https:\/\/blog.eternalsphere.net\/index.php\/wp-json\/wp\/v2\/posts\/6176","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.eternalsphere.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.eternalsphere.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.eternalsphere.net\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.eternalsphere.net\/index.php\/wp-json\/wp\/v2\/comments?post=6176"}],"version-history":[{"count":1,"href":"https:\/\/blog.eternalsphere.net\/index.php\/wp-json\/wp\/v2\/posts\/6176\/revisions"}],"predecessor-version":[{"id":6177,"href":"https:\/\/blog.eternalsphere.net\/index.php\/wp-json\/wp\/v2\/posts\/6176\/revisions\/6177"}],"wp:attachment":[{"href":"https:\/\/blog.eternalsphere.net\/index.php\/wp-json\/wp\/v2\/media?parent=6176"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.eternalsphere.net\/index.php\/wp-json\/wp\/v2\/categories?post=6176"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.eternalsphere.net\/index.php\/wp-json\/wp\/v2\/tags?post=6176"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}