#35292 test: Add coverage for Tor control `HASHEDPASSWORD` authentication

full analysis

https://github.com/bitcoin/bitcoin/pull/35292 · winterrdog · +69/-0 in 1 files, 1 commits · labels: Tests, Needs rebase

Goal

  • Add test coverage for Tor control hashed password authentication
  • Catch regressions in Tor daemon communication and onion service setup

This pull request adds functional test coverage for Tor control HASHEDPASSWORD authentication in test/functional/feature_torcontrol.py. It adds test cases verifying successful authentication with the right password, failure handling with the wrong password, behavior when -torpassword is omitted, and behavior when the Tor server does not advertise HASHEDPASSWORD support.

Problem: Bitcoin Core's functional test suite does not explicitly test the HASHEDPASSWORD authentication mechanism for Tor control, allowing potential regressions in Tor daemon communication and onion service setup to go undetected.

Category: P2P (#47 of 65)

P3 · test coverage

  • P3 because it adds regression coverage for Tor control hashed password authentication
  • Improves onion service test coverage without fixing an active vulnerability or bug

P3 because it introduces useful regression coverage for Tor control HASHEDPASSWORD authentication without fixing an active vulnerability or bug.

Membership: Directly covers Tor integration and Tor control daemon authentication.

Factors: security/stability 1, bug 0, performance 0, user value 1, leverage 0

Reviewability: Stale: Needs rebase

  • Needs rebase due to merge conflicts with master

The PR has merge conflicts with master and requires a rebase before it can be merged.

Author status: silent since force-push on 2026-08-04

Resolved concerns:

  • sedited requested rewriting the PR description to remove LLM-formulaic styling, which the author completed.
  • davidgumberg asked what the bad-password test validated separately from the good-password test; the author explained the log verification and early disconnect verification.

Agreement: Neutral

  • Neutral sentiment with questions answered but no ACKs posted
  • Clarified what bad-password assertions validate separately (davidgumberg)
  • Requested rewriting description to remove formulaic style (sedited)

Neutral; inline questions and description criticism were resolved, but no formal ACKs have been posted (sedited, davidgumberg)

Two contributors engaged to request description revisions and clarify test intent, but neither has explicitly endorsed or rejected the change.

  • sedited requested rewriting the PR description out of LLM format, which author did
  • davidgumberg asked for clarification on the incorrect password test assertion, which author answered

Review verdicts (DrahtBot): 0

Files

69 lines under test/bench/ci.

  • test/functional/feature_torcontrol.py +69/-0

Card

Adds functional tests in feature_torcontrol.py to cover Tor control HASHEDPASSWORD authentication scenarios. The PR tests successful auth, wrong password rejection, and missing password handling to protect against silent regressions in Tor onion service setup. No reviewers have given Concept ACKs yet, and minor review questions have been answered. The PR is currently in merge conflict and needs a rebase.

Data

dossier JSON · extract JSON · model openrouter/google/gemini-3.8-flash, generated 2026-09-17T15:52, confidence high, input hash 7b97a0da1d466e7e