With HASHEDPASSWORD authentication, TorController::protocolinfo_cb sends the password as a quoted string, AUTHENTICATE "<password>" (torcontrol.cpp:667). It escapes " but not \.
Tor parses that argument as a control-spec QuotedString, where a backslash escapes the next character. So:
-torpassword=pa\ssreaches Tor aspass, authentication fails and no onion service is created-torpassword=pass\escapes the closing quote, so the command is malformed
This escapes backslashes before quotes.
The new test_password_escaping in feature_torcontrol.py uses the mock control server with HASHEDPASSWORD and -torpassword=pa\ss"word\, and checks the exact AUTHENTICATE line. On master it gets AUTHENTICATE "pa\ss\"word\", with the fix AUTHENTICATE "pa\\ss\"word\\".
Tested against Tor 0.4.9.12 with HashedControlPassword set for pa\ss"word\: on master bitcoind logs "tor: Authentication failed", with this change authentication succeeds and ADD_ONION creates the onion service.
AI tools were used to help find this issue and to prepare the patch and test.