torcontrol: escape backslashes in -torpassword #36374

pull 0xShadowX wants to merge 1 commits into bitcoin:master from 0xShadowX:fix-torpassword-backslash changing 2 files +32 −0
  1. 0xShadowX commented at 5:47 PM on September 28, 2026: none

    With HASHEDPASSWORD authentication, TorController::protocolinfo_cb sends the password as a quoted string, AUTHENTICATE "<password>" (torcontrol.cpp:667). It escapes " but not \.

    Tor parses that argument as a control-spec QuotedString, where a backslash escapes the next character. So:

    • -torpassword=pa\ss reaches Tor as pass, authentication fails and no onion service is created
    • -torpassword=pass\ escapes the closing quote, so the command is malformed

    This escapes backslashes before quotes.

    The new test_password_escaping in feature_torcontrol.py uses the mock control server with HASHEDPASSWORD and -torpassword=pa\ss"word\, and checks the exact AUTHENTICATE line. On master it gets AUTHENTICATE "pa\ss\"word\", with the fix AUTHENTICATE "pa\\ss\"word\\".

    Tested against Tor 0.4.9.12 with HashedControlPassword set for pa\ss"word\: on master bitcoind logs "tor: Authentication failed", with this change authentication succeeds and ADD_ONION creates the onion service.

    AI tools were used to help find this issue and to prepare the patch and test.

  2. torcontrol: escape backslashes in -torpassword
    With HASHEDPASSWORD authentication the password is sent as a quoted
    string: AUTHENTICATE "<password>". Quotes in the password are escaped,
    but backslashes aren't. Tor reads a backslash in a quoted string as an
    escape for the next character, so a password like pa\ss reaches Tor as
    "pass" and authentication fails, and a password ending in a backslash
    escapes the closing quote.
    
    Escape backslashes before quotes.
    898346346b
  3. DrahtBot commented at 5:47 PM on September 28, 2026: contributor

    <!--e57a25ab6845829454e8d69fc972939a-->

    The following sections might be updated with supplementary metadata relevant to reviewers and maintainers.

    <!--006a51241073e994b41acfe9ec718e94-->

    Code Coverage & Benchmarks

    For details see: https://corecheck.dev/bitcoin/bitcoin/pulls/36374.

    <!--021abf342d371248e50ceaed478a90ca-->

    Reviews

    See the guideline and AI policy for information on the review process. A summary of reviews will appear here.

    <!--174a7506f384e20aa4161008e828411d-->

    Conflicts

    Reviewers, this pull request conflicts with the following ones:

    • #36142 (net: validate Tor onion service replies and cached keys by l0rinc)
    • #35292 (test: Add coverage for Tor control HASHEDPASSWORD authentication by winterrdog)
    • #34486 (net: Reduce local network activity when networkactive=0 by willcl-ark)

    If you consider this pull request important, please also help to review the conflicting pull requests. Ideally, start with the one that should be merged first.

    <!--5faf32d7da4f0f540f40219e4f7537a3-->

  4. fjahr commented at 7:24 PM on September 28, 2026: contributor

    There is already test coverage suggested for this in #35292, please coordinate with the author there how to proceed.

    I don't have Tor installed here, so this checks the escaping against the control-spec rules rather than a live Tor.

    You should install it and then test it.

  5. 0xShadowX commented at 8:16 PM on September 28, 2026: none

    Installed Tor 0.4.9.12 and tested against it with HashedControlPassword for pa\ss"word\: on master bitcoind gets "tor: Authentication failed", with this change authentication succeeds and ADD_ONION creates the service. I'll ask in #35292 how to combine the test coverage.


github-metadata-mirror

This is a metadata mirror of the GitHub repository bitcoin/bitcoin. This site is not affiliated with GitHub. Content is generated from a GitHub metadata backup.
generated: 2026-10-05 05:51 UTC

This site is hosted by @0xB10C
More mirrored repositories can be found on mirror.b10c.me