blob: fd2a48cebab5a1f5edef233e9ff6e794f7b728fa [file] [log] [blame]
Neels Hofmeyr17518fe2017-06-20 04:35:06 +02001/*! \file gprs_bssgp.c
2 * GPRS BSSGP protocol implementation as per 3GPP TS 08.18. */
3/*
4 * (C) 2009-2017 by Harald Welte <laforge@gnumonks.org>
Harald Welte9ba50052010-03-14 15:45:01 +08005 *
6 * All Rights Reserved
7 *
Harald Weltee08da972017-11-13 01:00:26 +09008 * SPDX-License-Identifier: GPL-2.0+
9 *
Harald Welte9ba50052010-03-14 15:45:01 +080010 * This program is free software; you can redistribute it and/or modify
Harald Welte7fa89c22014-10-26 20:33:09 +010011 * it under the terms of the GNU General Public License as published by
12 * the Free Software Foundation; either version 2 of the License, or
Harald Welte9ba50052010-03-14 15:45:01 +080013 * (at your option) any later version.
14 *
15 * This program is distributed in the hope that it will be useful,
16 * but WITHOUT ANY WARRANTY; without even the implied warranty of
17 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
Harald Welte7fa89c22014-10-26 20:33:09 +010018 * GNU General Public License for more details.
Harald Welte9ba50052010-03-14 15:45:01 +080019 *
Harald Welte7fa89c22014-10-26 20:33:09 +010020 * You should have received a copy of the GNU General Public License
Harald Weltee4cbb3f2011-01-01 15:25:50 +010021 * along with this program. If not, see <http://www.gnu.org/licenses/>.
Harald Welte9ba50052010-03-14 15:45:01 +080022 *
Harald Welte4e5721d2010-05-17 23:41:43 +020023 * TODO:
24 * o properly count incoming BVC-RESET packets in counter group
25 * o set log context as early as possible for outgoing packets
Harald Welte9ba50052010-03-14 15:45:01 +080026 */
27
28#include <errno.h>
Harald Welte8f9a3ee2010-05-02 11:26:34 +020029#include <stdint.h>
Harald Welte9ba50052010-03-14 15:45:01 +080030
Pablo Neira Ayusoff663232011-03-22 16:47:59 +010031#include <osmocom/core/msgb.h>
Harald Weltebfe62e52017-05-15 12:48:30 +020032#include <osmocom/core/byteswap.h>
33#include <osmocom/core/bit16gen.h>
Pablo Neira Ayusoff663232011-03-22 16:47:59 +010034#include <osmocom/gsm/tlv.h>
35#include <osmocom/core/talloc.h>
36#include <osmocom/core/rate_ctr.h>
Jacob Erlbeckbc9d9ac2015-11-02 14:49:35 +010037#include <osmocom/core/stats.h>
Harald Welte6752fa42010-05-02 09:23:16 +020038
Harald Welte73952e32012-06-16 14:59:56 +080039#include <osmocom/gprs/gprs_bssgp.h>
Max8b8938f2017-06-29 19:48:29 +020040#include <osmocom/gprs/gprs_bssgp_bss.h>
Harald Welte73952e32012-06-16 14:59:56 +080041#include <osmocom/gprs/gprs_ns.h>
42
Daniel Willmann2d42b902020-09-26 09:11:05 +020043#include "osmocom/gsm/gsm48.h"
Harald Weltecca49632012-06-16 17:45:59 +080044
Harald Welte6752fa42010-05-02 09:23:16 +020045void *bssgp_tall_ctx = NULL;
46
Alexander Couzens85a8fd32020-07-18 15:57:07 +020047static int _gprs_ns_sendmsg(void *ctx, struct msgb *msg);
48
49bssgp_bvc_send bssgp_ns_send = _gprs_ns_sendmsg;
50void *bssgp_ns_send_data = NULL;
51
Harald Welte25de8112010-05-13 21:26:28 +020052static const struct rate_ctr_desc bssgp_ctr_description[] = {
Harald Weltea7a50652017-10-03 17:49:21 +080053 { "packets:in", "Packets at BSSGP Level ( In)" },
54 { "packets:out","Packets at BSSGP Level (Out)" },
55 { "bytes:in", "Bytes at BSSGP Level ( In)" },
56 { "bytes:out", "Bytes at BSSGP Level (Out)" },
Harald Welte25de8112010-05-13 21:26:28 +020057 { "blocked", "BVC Blocking count" },
58 { "discarded", "BVC LLC Discarded count" },
Jacob Erlbeck36153dc2015-03-17 10:21:17 +010059 { "status", "BVC Status count" },
Harald Welte25de8112010-05-13 21:26:28 +020060};
61
62static const struct rate_ctr_group_desc bssgp_ctrg_desc = {
Harald Weltea7a50652017-10-03 17:49:21 +080063 .group_name_prefix = "bssgp:bss_ctx",
Harald Welte25de8112010-05-13 21:26:28 +020064 .group_description = "BSSGP Peer Statistics",
65 .num_ctr = ARRAY_SIZE(bssgp_ctr_description),
66 .ctr_desc = bssgp_ctr_description,
Jacob Erlbeckbc9d9ac2015-11-02 14:49:35 +010067 .class_id = OSMO_STATS_CLASS_PEER,
Harald Welte25de8112010-05-13 21:26:28 +020068};
69
Harald Weltea78b9c22010-05-17 23:02:42 +020070LLIST_HEAD(bssgp_bvc_ctxts);
Harald Welte6752fa42010-05-02 09:23:16 +020071
Harald Welted11c0592012-09-06 21:57:11 +020072static int _bssgp_tx_dl_ud(struct bssgp_flow_control *fc, struct msgb *msg,
73 uint32_t llc_pdu_len, void *priv);
74
Alexander Couzens85a8fd32020-07-18 15:57:07 +020075
Alexander Couzens83fb6862020-09-03 19:30:08 +020076/* callback to be backward compatible with old users which do not set the bssgp_ns_send function */
Alexander Couzens85a8fd32020-07-18 15:57:07 +020077static int _gprs_ns_sendmsg(void *ctx, struct msgb *msg)
78{
79 return gprs_ns_sendmsg(bssgp_nsi, msg);
80}
81
Harald Welte6752fa42010-05-02 09:23:16 +020082/* Find a BTS Context based on parsed RA ID and Cell ID */
Harald Welte8a521132010-05-17 22:59:29 +020083struct bssgp_bvc_ctx *btsctx_by_raid_cid(const struct gprs_ra_id *raid, uint16_t cid)
Harald Welte6752fa42010-05-02 09:23:16 +020084{
Harald Welte8a521132010-05-17 22:59:29 +020085 struct bssgp_bvc_ctx *bctx;
Harald Welte6752fa42010-05-02 09:23:16 +020086
Harald Weltea78b9c22010-05-17 23:02:42 +020087 llist_for_each_entry(bctx, &bssgp_bvc_ctxts, list) {
Harald Welte6752fa42010-05-02 09:23:16 +020088 if (!memcmp(&bctx->ra_id, raid, sizeof(bctx->ra_id)) &&
89 bctx->cell_id == cid)
90 return bctx;
91 }
92 return NULL;
93}
94
Daniel Willmann2d42b902020-09-26 09:11:05 +020095/*! Transmit a BVC-RESET message with a given nsei and bvci (Chapter 10.4.12)
96 * \param[in] nsei The NSEI to transmit over
97 * \param[in] bvci BVCI of the BVC to reset
98 * \param[in] cause The cause of the reset
99 * \param[in] ra_id Pointer to the ra_id to include. If NULL no cell information will be included
100 * \param[in] cell_id The cell_id to include (if ra_id is not NULL)
101 */
102int bssgp_tx_bvc_reset_nsei_bvci(uint16_t nsei, uint16_t bvci, enum gprs_bssgp_cause cause, const struct gprs_ra_id *ra_id, uint16_t cell_id)
103{
104 struct msgb *msg = bssgp_msgb_alloc();
105 struct bssgp_normal_hdr *bgph =
106 (struct bssgp_normal_hdr *) msgb_put(msg, sizeof(*bgph));
107 uint16_t _bvci = osmo_htons(bvci);
108
109 msgb_nsei(msg) = nsei;
110 msgb_bvci(msg) = 0; /* Signalling */
111 bgph->pdu_type = BSSGP_PDUT_BVC_RESET;
Harald Weltefde19ed2020-12-07 21:43:51 +0100112 LOGP(DLBSSGP, LOGL_NOTICE, "BSSGP (BVCI=%u) Tx BVC-RESET "
Daniel Willmann2d42b902020-09-26 09:11:05 +0200113 "CAUSE=%s\n", bvci, bssgp_cause_str(cause));
114
115 msgb_tvlv_put(msg, BSSGP_IE_BVCI, 2, (uint8_t *) &_bvci);
116 msgb_tvlv_put(msg, BSSGP_IE_CAUSE, 1, (uint8_t *) &cause);
117 if (ra_id) {
118 uint8_t bssgp_cid[8];
119 bssgp_create_cell_id(bssgp_cid, ra_id, cell_id);
120 msgb_tvlv_put(msg, BSSGP_IE_CELL_ID, sizeof(bssgp_cid), bssgp_cid);
121 }
122
123 /* Optional: Feature Bitmap */
124
125 return bssgp_ns_send(bssgp_ns_send_data, msg);
126}
127
Max8b8938f2017-06-29 19:48:29 +0200128/*! Initiate reset procedure for all PTP BVC on a given NSEI.
129 *
130 * This function initiates reset procedure for all PTP BVC with a given cause.
131 * \param[in] nsei NSEI to which PTP BVC should belong to
132 * \param[in] cause Cause of BVC RESET
133 * \returns 0 on success, negative error code otherwise
134 */
135int bssgp_tx_bvc_ptp_reset(uint16_t nsei, enum gprs_bssgp_cause cause)
136{
137 int rc;
138 struct bssgp_bvc_ctx *bctx;
139
140 llist_for_each_entry(bctx, &bssgp_bvc_ctxts, list) {
141 if (bctx->nsei == nsei && bctx->bvci != BVCI_SIGNALLING) {
Harald Weltefde19ed2020-12-07 21:43:51 +0100142 LOGP(DLBSSGP, LOGL_DEBUG, "NSEI=%u/BVCI=%u RESET due to %s\n",
Max8b8938f2017-06-29 19:48:29 +0200143 nsei, bctx->bvci, bssgp_cause_str(cause));
144 rc = bssgp_tx_bvc_reset(bctx, bctx->bvci, cause);
145 if (rc < 0)
146 return rc;
147 }
148 }
149
150 return 0;
151}
152
Harald Welte6752fa42010-05-02 09:23:16 +0200153/* Find a BTS context based on BVCI+NSEI tuple */
Harald Welte8a521132010-05-17 22:59:29 +0200154struct bssgp_bvc_ctx *btsctx_by_bvci_nsei(uint16_t bvci, uint16_t nsei)
Harald Welte6752fa42010-05-02 09:23:16 +0200155{
Harald Welte8a521132010-05-17 22:59:29 +0200156 struct bssgp_bvc_ctx *bctx;
Harald Welte6752fa42010-05-02 09:23:16 +0200157
Harald Weltea78b9c22010-05-17 23:02:42 +0200158 llist_for_each_entry(bctx, &bssgp_bvc_ctxts, list) {
Harald Welte6752fa42010-05-02 09:23:16 +0200159 if (bctx->nsei == nsei && bctx->bvci == bvci)
160 return bctx;
161 }
162 return NULL;
163}
164
Alexander Couzens85a8fd32020-07-18 15:57:07 +0200165void bssgp_set_bssgp_callback(bssgp_bvc_send ns_send, void *data)
166{
167 bssgp_ns_send = ns_send;
168 bssgp_ns_send_data = data;
169}
170
Harald Welte8a521132010-05-17 22:59:29 +0200171struct bssgp_bvc_ctx *btsctx_alloc(uint16_t bvci, uint16_t nsei)
Harald Welte6752fa42010-05-02 09:23:16 +0200172{
Harald Welte8a521132010-05-17 22:59:29 +0200173 struct bssgp_bvc_ctx *ctx;
Harald Welte6752fa42010-05-02 09:23:16 +0200174
Harald Welte8a521132010-05-17 22:59:29 +0200175 ctx = talloc_zero(bssgp_tall_ctx, struct bssgp_bvc_ctx);
Harald Welte6752fa42010-05-02 09:23:16 +0200176 if (!ctx)
177 return NULL;
178 ctx->bvci = bvci;
179 ctx->nsei = nsei;
Harald Welte25de8112010-05-13 21:26:28 +0200180 /* FIXME: BVCI is not unique, only BVCI+NSEI ?!? */
181 ctx->ctrg = rate_ctr_group_alloc(ctx, &bssgp_ctrg_desc, bvci);
Alexander Couzens6a2c0742020-09-16 23:09:24 +0200182 if (!ctx->ctrg)
183 goto err_ctrg;
184
Harald Welted8b47692012-09-07 11:29:32 +0200185 ctx->fc = talloc_zero(ctx, struct bssgp_flow_control);
Alexander Couzens6a2c0742020-09-16 23:09:24 +0200186 if (!ctx->fc)
187 goto err_fc;
188
Harald Welted8b47692012-09-07 11:29:32 +0200189 /* cofigure for 2Mbit, 30 packets in queue */
190 bssgp_fc_init(ctx->fc, 100000, 2*1024*1024/8, 30, &_bssgp_tx_dl_ud);
Harald Welte25de8112010-05-13 21:26:28 +0200191
Harald Weltea78b9c22010-05-17 23:02:42 +0200192 llist_add(&ctx->list, &bssgp_bvc_ctxts);
Harald Welte6752fa42010-05-02 09:23:16 +0200193
194 return ctx;
Alexander Couzens6a2c0742020-09-16 23:09:24 +0200195
196err_fc:
197 rate_ctr_group_free(ctx->ctrg);
198err_ctrg:
199 talloc_free(ctx);
200 return NULL;
Harald Welte6752fa42010-05-02 09:23:16 +0200201}
202
Vadim Yanitskiy8eae2fc2019-11-09 01:45:11 +0700203void bssgp_bvc_ctx_free(struct bssgp_bvc_ctx *ctx)
204{
205 if (!ctx)
206 return;
Alexander Couzens495b4a72020-09-16 23:10:03 +0200207
208 osmo_timer_del(&ctx->fc->timer);
Vadim Yanitskiy8eae2fc2019-11-09 01:45:11 +0700209 rate_ctr_group_free(ctx->ctrg);
210 llist_del(&ctx->list);
211 talloc_free(ctx);
212}
213
Harald Welte9ba50052010-03-14 15:45:01 +0800214/* Chapter 10.4.5: Flow Control BVC ACK */
Harald Welte8f9a3ee2010-05-02 11:26:34 +0200215static int bssgp_tx_fc_bvc_ack(uint16_t nsei, uint8_t tag, uint16_t ns_bvci)
Harald Welte9ba50052010-03-14 15:45:01 +0800216{
217 struct msgb *msg = bssgp_msgb_alloc();
218 struct bssgp_normal_hdr *bgph =
219 (struct bssgp_normal_hdr *) msgb_put(msg, sizeof(*bgph));
220
Harald Welte24a655f2010-04-30 19:54:29 +0200221 msgb_nsei(msg) = nsei;
222 msgb_bvci(msg) = ns_bvci;
223
Harald Welte9ba50052010-03-14 15:45:01 +0800224 bgph->pdu_type = BSSGP_PDUT_FLOW_CONTROL_BVC_ACK;
225 msgb_tvlv_put(msg, BSSGP_IE_TAG, 1, &tag);
226
Alexander Couzens85a8fd32020-07-18 15:57:07 +0200227 return bssgp_ns_send(bssgp_ns_send_data, msg);
Harald Welte9ba50052010-03-14 15:45:01 +0800228}
229
Harald Weltea8aa4df2010-05-30 22:00:53 +0200230/* 10.3.7 SUSPEND-ACK PDU */
231int bssgp_tx_suspend_ack(uint16_t nsei, uint32_t tlli,
232 const struct gprs_ra_id *ra_id, uint8_t suspend_ref)
233{
234 struct msgb *msg = bssgp_msgb_alloc();
235 struct bssgp_normal_hdr *bgph =
236 (struct bssgp_normal_hdr *) msgb_put(msg, sizeof(*bgph));
Harald Weltea8aa4df2010-05-30 22:00:53 +0200237
238 msgb_nsei(msg) = nsei;
239 msgb_bvci(msg) = 0; /* Signalling */
240 bgph->pdu_type = BSSGP_PDUT_SUSPEND_ACK;
241
Maxe29ec852018-01-05 14:30:22 +0100242 bssgp_msgb_tlli_put(msg, tlli);
Maxf1ad60e2018-01-05 14:19:33 +0100243 bssgp_msgb_ra_put(msg, ra_id);
Harald Weltea8aa4df2010-05-30 22:00:53 +0200244 msgb_tvlv_put(msg, BSSGP_IE_SUSPEND_REF_NR, 1, &suspend_ref);
245
Alexander Couzens85a8fd32020-07-18 15:57:07 +0200246 return bssgp_ns_send(bssgp_ns_send_data, msg);
Harald Weltea8aa4df2010-05-30 22:00:53 +0200247}
248
249/* 10.3.8 SUSPEND-NACK PDU */
250int bssgp_tx_suspend_nack(uint16_t nsei, uint32_t tlli,
Dieter Spaard2b13fc2010-12-12 12:45:08 +0100251 const struct gprs_ra_id *ra_id,
Harald Weltea8aa4df2010-05-30 22:00:53 +0200252 uint8_t *cause)
253{
254 struct msgb *msg = bssgp_msgb_alloc();
255 struct bssgp_normal_hdr *bgph =
256 (struct bssgp_normal_hdr *) msgb_put(msg, sizeof(*bgph));
Harald Weltea8aa4df2010-05-30 22:00:53 +0200257
258 msgb_nsei(msg) = nsei;
259 msgb_bvci(msg) = 0; /* Signalling */
260 bgph->pdu_type = BSSGP_PDUT_SUSPEND_NACK;
261
Maxe29ec852018-01-05 14:30:22 +0100262 bssgp_msgb_tlli_put(msg, tlli);
Maxf1ad60e2018-01-05 14:19:33 +0100263 bssgp_msgb_ra_put(msg, ra_id);
264
Harald Weltea8aa4df2010-05-30 22:00:53 +0200265 if (cause)
266 msgb_tvlv_put(msg, BSSGP_IE_CAUSE, 1, cause);
267
Alexander Couzens85a8fd32020-07-18 15:57:07 +0200268 return bssgp_ns_send(bssgp_ns_send_data, msg);
Harald Weltea8aa4df2010-05-30 22:00:53 +0200269}
270
271/* 10.3.10 RESUME-ACK PDU */
272int bssgp_tx_resume_ack(uint16_t nsei, uint32_t tlli,
273 const struct gprs_ra_id *ra_id)
274{
275 struct msgb *msg = bssgp_msgb_alloc();
276 struct bssgp_normal_hdr *bgph =
277 (struct bssgp_normal_hdr *) msgb_put(msg, sizeof(*bgph));
Harald Weltea8aa4df2010-05-30 22:00:53 +0200278
279 msgb_nsei(msg) = nsei;
280 msgb_bvci(msg) = 0; /* Signalling */
281 bgph->pdu_type = BSSGP_PDUT_RESUME_ACK;
282
Maxe29ec852018-01-05 14:30:22 +0100283 bssgp_msgb_tlli_put(msg, tlli);
Maxf1ad60e2018-01-05 14:19:33 +0100284 bssgp_msgb_ra_put(msg, ra_id);
Harald Weltea8aa4df2010-05-30 22:00:53 +0200285
Alexander Couzens85a8fd32020-07-18 15:57:07 +0200286 return bssgp_ns_send(bssgp_ns_send_data, msg);
Harald Weltea8aa4df2010-05-30 22:00:53 +0200287}
288
289/* 10.3.11 RESUME-NACK PDU */
290int bssgp_tx_resume_nack(uint16_t nsei, uint32_t tlli,
291 const struct gprs_ra_id *ra_id, uint8_t *cause)
292{
293 struct msgb *msg = bssgp_msgb_alloc();
294 struct bssgp_normal_hdr *bgph =
295 (struct bssgp_normal_hdr *) msgb_put(msg, sizeof(*bgph));
Harald Weltea8aa4df2010-05-30 22:00:53 +0200296
297 msgb_nsei(msg) = nsei;
298 msgb_bvci(msg) = 0; /* Signalling */
299 bgph->pdu_type = BSSGP_PDUT_SUSPEND_NACK;
300
Maxe29ec852018-01-05 14:30:22 +0100301 bssgp_msgb_tlli_put(msg, tlli);
Maxf1ad60e2018-01-05 14:19:33 +0100302 bssgp_msgb_ra_put(msg, ra_id);
303
Harald Weltea8aa4df2010-05-30 22:00:53 +0200304 if (cause)
305 msgb_tvlv_put(msg, BSSGP_IE_CAUSE, 1, cause);
306
Alexander Couzens85a8fd32020-07-18 15:57:07 +0200307 return bssgp_ns_send(bssgp_ns_send_data, msg);
Harald Weltea8aa4df2010-05-30 22:00:53 +0200308}
309
Harald Weltea2ca4ed2010-05-02 11:54:55 +0200310uint16_t bssgp_parse_cell_id(struct gprs_ra_id *raid, const uint8_t *buf)
Harald Welte6752fa42010-05-02 09:23:16 +0200311{
312 /* 6 octets RAC */
313 gsm48_parse_ra(raid, buf);
314 /* 2 octets CID */
Harald Weltebfe62e52017-05-15 12:48:30 +0200315 return osmo_load16be(buf+6);
Harald Welte6752fa42010-05-02 09:23:16 +0200316}
317
Harald Welte28610072011-11-24 21:32:07 +0100318int bssgp_create_cell_id(uint8_t *buf, const struct gprs_ra_id *raid,
319 uint16_t cid)
320{
Harald Welte28610072011-11-24 21:32:07 +0100321 /* 6 octets RAC */
Maxf1ad60e2018-01-05 14:19:33 +0100322 gsm48_encode_ra((struct gsm48_ra_id *)buf, raid);
Harald Welte28610072011-11-24 21:32:07 +0100323 /* 2 octets CID */
Harald Weltebfe62e52017-05-15 12:48:30 +0200324 osmo_store16be(cid, buf+6);
Harald Welte28610072011-11-24 21:32:07 +0100325
326 return 8;
327}
328
Philipp Maierbd10c212020-12-14 22:28:19 +0100329/*! Parse a RIM Routing information IE (3GPP TS 48.018, chapter 11.3.70).
330 * \param[out] ri user provided memory to store the parsed results.
331 * \param[in] buf input buffer of the value part of the IE.
332 * \returns length of parsed octets, -EINVAL on error. */
333int bssgp_parse_rim_ri(struct bssgp_rim_routing_info *ri, const uint8_t *buf,
334 unsigned int len)
335{
336 struct gprs_ra_id raid_temp;
337
338 memset(ri, 0, sizeof(*ri));
339 if (len < 2)
340 return -EINVAL;
341
342 ri->discr = buf[0] & 0x0f;
343
344 switch (ri->discr) {
345 case BSSGP_RIM_ROUTING_INFO_GERAN:
346 if (len < 9)
347 return -EINVAL;
348 ri->geran.cid = bssgp_parse_cell_id(&ri->geran.raid, buf + 1);
349 return 9;
350 case BSSGP_RIM_ROUTING_INFO_UTRAN:
351 if (len < 9)
352 return -EINVAL;
353 gsm48_parse_ra(&ri->utran.raid, buf + 1);
354 ri->utran.rncid = osmo_load16be(buf + 7);
355 return 9;
356 case BSSGP_RIM_ROUTING_INFO_EUTRAN:
357 if (len < 7 || len > 14)
358 return -EINVAL;
359 /* Note: 3GPP TS 24.301 Figure 9.9.3.32.1 and 3GPP TS 24.008
360 * Figure 10.5.130 specify MCC/MNC encoding in the same way,
361 * so we can re-use gsm48_parse_ra() for that. */
362 gsm48_parse_ra(&raid_temp, buf + 1);
363 ri->eutran.tai.mcc = raid_temp.mcc;
364 ri->eutran.tai.mnc = raid_temp.mnc;
365 ri->eutran.tai.mnc_3_digits = raid_temp.mnc_3_digits;
366 ri->eutran.tai.tac = osmo_load16be(buf + 4);
367 memcpy(ri->eutran.global_enb_id, buf + 6, len - 6);
368 ri->eutran.global_enb_id_len = len - 6;
369 return len;
370 default:
371 return -EINVAL;
372 }
373}
374
375/*! Encode a RIM Routing information IE (3GPP TS 48.018, chapter 11.3.70).
376 * \param[out] buf user provided memory (at least 14 byte) for the generated value part of the IE.
377 * \param[in] ri user provided input data struct.
378 * \returns length of encoded octets, -EINVAL on error. */
379int bssgp_create_rim_ri(uint8_t *buf, const struct bssgp_rim_routing_info *ri)
380{
381 int rc;
382 struct gprs_ra_id raid_temp;
383
384 buf[0] = ri->discr & 0x0f;
385 buf++;
386
387 switch (ri->discr) {
388 case BSSGP_RIM_ROUTING_INFO_GERAN:
389 rc = bssgp_create_cell_id(buf, &ri->geran.raid, ri->geran.cid);
390 if (rc < 0)
391 return -EINVAL;
392 return rc + 1;
393 case BSSGP_RIM_ROUTING_INFO_UTRAN:
394 gsm48_encode_ra((struct gsm48_ra_id *)buf, &ri->utran.raid);
395 osmo_store16be(ri->utran.rncid, buf + 6);
396 return 9;
397 case BSSGP_RIM_ROUTING_INFO_EUTRAN:
398 /* Note: 3GPP TS 24.301 Figure 9.9.3.32.1 and 3GPP TS 24.008
399 * Figure 10.5.130 specify MCC/MNC encoding in the same way,
400 * so we can re-use gsm48_encode_ra() for that. */
401 raid_temp.mcc = ri->eutran.tai.mcc;
402 raid_temp.mnc = ri->eutran.tai.mnc;
403 raid_temp.mnc_3_digits = ri->eutran.tai.mnc_3_digits;
404 gsm48_encode_ra((struct gsm48_ra_id *)buf, &raid_temp);
405 osmo_store16be(ri->eutran.tai.tac, buf + 3);
406 OSMO_ASSERT(ri->eutran.global_enb_id_len <=
407 sizeof(ri->eutran.global_enb_id));
408 memcpy(buf + 5, ri->eutran.global_enb_id,
409 ri->eutran.global_enb_id_len);
410 return ri->eutran.global_enb_id_len + 6;
411 default:
412 return -EINVAL;
413 }
414}
415
Harald Welte3fddf3c2010-05-01 16:48:27 +0200416/* Chapter 8.4 BVC-Reset Procedure */
Alexander Couzens85a8fd32020-07-18 15:57:07 +0200417static int bssgp_rx_bvc_reset(struct msgb *msg, struct tlv_parsed *tp,
Harald Welte3fddf3c2010-05-01 16:48:27 +0200418 uint16_t ns_bvci)
419{
Harald Welte15a36432012-06-17 12:16:31 +0800420 struct osmo_bssgp_prim nmp;
Harald Welte8a521132010-05-17 22:59:29 +0200421 struct bssgp_bvc_ctx *bctx;
Harald Welte6752fa42010-05-02 09:23:16 +0200422 uint16_t nsei = msgb_nsei(msg);
423 uint16_t bvci;
Harald Welte3fddf3c2010-05-01 16:48:27 +0200424
Harald Weltebfe62e52017-05-15 12:48:30 +0200425 bvci = tlvp_val16be(tp, BSSGP_IE_BVCI);
Harald Weltefde19ed2020-12-07 21:43:51 +0100426 DEBUGP(DLBSSGP, "BSSGP BVCI=%u Rx RESET cause=%s\n", bvci,
Harald Welte3fddf3c2010-05-01 16:48:27 +0200427 bssgp_cause_str(*TLVP_VAL(tp, BSSGP_IE_CAUSE)));
428
Harald Welte6752fa42010-05-02 09:23:16 +0200429 /* look-up or create the BTS context for this BVC */
430 bctx = btsctx_by_bvci_nsei(bvci, nsei);
431 if (!bctx)
432 bctx = btsctx_alloc(bvci, nsei);
433
Harald Welte25de8112010-05-13 21:26:28 +0200434 /* As opposed to NS-VCs, BVCs are NOT blocked after RESET */
435 bctx->state &= ~BVC_S_BLOCKED;
436
Harald Welte3fddf3c2010-05-01 16:48:27 +0200437 /* When we receive a BVC-RESET PDU (at least of a PTP BVCI), the BSS
438 * informs us about its RAC + Cell ID, so we can create a mapping */
Harald Welte6752fa42010-05-02 09:23:16 +0200439 if (bvci != 0 && bvci != 1) {
Harald Welte2d9ce712020-12-03 15:53:59 +0100440 if (!TLVP_PRES_LEN(tp, BSSGP_IE_CELL_ID, 8)) {
Harald Weltefde19ed2020-12-07 21:43:51 +0100441 LOGP(DLBSSGP, LOGL_ERROR, "BSSGP BVCI=%u Rx RESET "
Harald Welte6752fa42010-05-02 09:23:16 +0200442 "missing mandatory IE\n", bvci);
443 return -EINVAL;
444 }
445 /* actually extract RAC / CID */
Harald Weltea2ca4ed2010-05-02 11:54:55 +0200446 bctx->cell_id = bssgp_parse_cell_id(&bctx->ra_id,
447 TLVP_VAL(tp, BSSGP_IE_CELL_ID));
Harald Weltefde19ed2020-12-07 21:43:51 +0100448 LOGP(DLBSSGP, LOGL_NOTICE, "Cell %s CI %u on BVCI %u\n",
Neels Hofmeyrc4fce142018-02-20 13:47:08 +0100449 osmo_rai_name(&bctx->ra_id), bctx->cell_id, bvci);
Harald Welte6752fa42010-05-02 09:23:16 +0200450 }
Harald Welte3fddf3c2010-05-01 16:48:27 +0200451
Harald Welte15a36432012-06-17 12:16:31 +0800452 /* Send NM_BVC_RESET.ind to NM */
453 memset(&nmp, 0, sizeof(nmp));
454 nmp.nsei = nsei;
455 nmp.bvci = bvci;
456 nmp.tp = tp;
457 nmp.ra_id = &bctx->ra_id;
458 osmo_prim_init(&nmp.oph, SAP_BSSGP_NM, PRIM_NM_BVC_RESET,
459 PRIM_OP_INDICATION, msg);
460 bssgp_prim_cb(&nmp.oph, NULL);
461
Harald Welte6752fa42010-05-02 09:23:16 +0200462 /* Acknowledge the RESET to the BTS */
Harald Welte5b3bffb2012-09-07 12:03:40 +0200463 bssgp_tx_simple_bvci(BSSGP_PDUT_BVC_RESET_ACK,
464 nsei, bvci, ns_bvci);
Harald Welte3fddf3c2010-05-01 16:48:27 +0200465 return 0;
466}
467
Harald Welte25de8112010-05-13 21:26:28 +0200468static int bssgp_rx_bvc_block(struct msgb *msg, struct tlv_parsed *tp)
469{
Harald Welte15a36432012-06-17 12:16:31 +0800470 struct osmo_bssgp_prim nmp;
Max548caef2019-03-07 13:49:34 +0100471 uint16_t bvci, nsei = msgb_nsei(msg);
Harald Welte8a521132010-05-17 22:59:29 +0200472 struct bssgp_bvc_ctx *ptp_ctx;
Harald Welte25de8112010-05-13 21:26:28 +0200473
Harald Weltebfe62e52017-05-15 12:48:30 +0200474 bvci = tlvp_val16be(tp, BSSGP_IE_BVCI);
Harald Welte61c07842010-05-18 11:57:08 +0200475 if (bvci == BVCI_SIGNALLING) {
Harald Welte58e65c92010-05-13 21:45:23 +0200476 /* 8.3.2: Signalling BVC shall never be blocked */
Harald Weltefde19ed2020-12-07 21:43:51 +0100477 LOGP(DLBSSGP, LOGL_ERROR, "NSEI=%u/BVCI=%u "
Harald Welte58e65c92010-05-13 21:45:23 +0200478 "received block for signalling BVC!?!\n",
Max548caef2019-03-07 13:49:34 +0100479 nsei, msgb_bvci(msg));
Harald Welte58e65c92010-05-13 21:45:23 +0200480 return 0;
481 }
Harald Welte25de8112010-05-13 21:26:28 +0200482
Harald Weltefde19ed2020-12-07 21:43:51 +0100483 LOGP(DLBSSGP, LOGL_INFO, "BSSGP Rx BVCI=%u BVC-BLOCK\n", bvci);
Harald Welte25de8112010-05-13 21:26:28 +0200484
Max548caef2019-03-07 13:49:34 +0100485 ptp_ctx = btsctx_by_bvci_nsei(bvci, nsei);
Harald Welte25de8112010-05-13 21:26:28 +0200486 if (!ptp_ctx)
487 return bssgp_tx_status(BSSGP_CAUSE_UNKNOWN_BVCI, &bvci, msg);
488
489 ptp_ctx->state |= BVC_S_BLOCKED;
490 rate_ctr_inc(&ptp_ctx->ctrg->ctr[BSSGP_CTR_BLOCKED]);
491
Harald Welte15a36432012-06-17 12:16:31 +0800492 /* Send NM_BVC_BLOCK.ind to NM */
493 memset(&nmp, 0, sizeof(nmp));
Max548caef2019-03-07 13:49:34 +0100494 nmp.nsei = nsei;
Harald Welte15a36432012-06-17 12:16:31 +0800495 nmp.bvci = bvci;
496 nmp.tp = tp;
497 osmo_prim_init(&nmp.oph, SAP_BSSGP_NM, PRIM_NM_BVC_BLOCK,
498 PRIM_OP_INDICATION, msg);
499 bssgp_prim_cb(&nmp.oph, NULL);
Harald Welte25de8112010-05-13 21:26:28 +0200500
501 /* We always acknowledge the BLOCKing */
Max548caef2019-03-07 13:49:34 +0100502 return bssgp_tx_simple_bvci(BSSGP_PDUT_BVC_BLOCK_ACK, nsei,
Harald Welte25de8112010-05-13 21:26:28 +0200503 bvci, msgb_bvci(msg));
504};
505
506static int bssgp_rx_bvc_unblock(struct msgb *msg, struct tlv_parsed *tp)
507{
Harald Welte15a36432012-06-17 12:16:31 +0800508 struct osmo_bssgp_prim nmp;
Max548caef2019-03-07 13:49:34 +0100509 uint16_t bvci, nsei = msgb_nsei(msg);
Harald Welte8a521132010-05-17 22:59:29 +0200510 struct bssgp_bvc_ctx *ptp_ctx;
Harald Welte25de8112010-05-13 21:26:28 +0200511
Harald Weltebfe62e52017-05-15 12:48:30 +0200512 bvci = tlvp_val16be(tp, BSSGP_IE_BVCI);
Harald Welte61c07842010-05-18 11:57:08 +0200513 if (bvci == BVCI_SIGNALLING) {
Harald Welte58e65c92010-05-13 21:45:23 +0200514 /* 8.3.2: Signalling BVC shall never be blocked */
Harald Weltefde19ed2020-12-07 21:43:51 +0100515 LOGP(DLBSSGP, LOGL_ERROR, "NSEI=%u/BVCI=%u "
Harald Welte58e65c92010-05-13 21:45:23 +0200516 "received unblock for signalling BVC!?!\n",
Max548caef2019-03-07 13:49:34 +0100517 nsei, msgb_bvci(msg));
Harald Welte58e65c92010-05-13 21:45:23 +0200518 return 0;
519 }
Harald Welte25de8112010-05-13 21:26:28 +0200520
Harald Weltefde19ed2020-12-07 21:43:51 +0100521 DEBUGP(DLBSSGP, "BSSGP BVCI=%u Rx BVC-UNBLOCK\n", bvci);
Harald Welte25de8112010-05-13 21:26:28 +0200522
Max548caef2019-03-07 13:49:34 +0100523 ptp_ctx = btsctx_by_bvci_nsei(bvci, nsei);
Harald Welte25de8112010-05-13 21:26:28 +0200524 if (!ptp_ctx)
525 return bssgp_tx_status(BSSGP_CAUSE_UNKNOWN_BVCI, &bvci, msg);
526
527 ptp_ctx->state &= ~BVC_S_BLOCKED;
528
Harald Welte15a36432012-06-17 12:16:31 +0800529 /* Send NM_BVC_UNBLOCK.ind to NM */
530 memset(&nmp, 0, sizeof(nmp));
Max548caef2019-03-07 13:49:34 +0100531 nmp.nsei = nsei;
Harald Welte15a36432012-06-17 12:16:31 +0800532 nmp.bvci = bvci;
533 nmp.tp = tp;
534 osmo_prim_init(&nmp.oph, SAP_BSSGP_NM, PRIM_NM_BVC_UNBLOCK,
535 PRIM_OP_INDICATION, msg);
536 bssgp_prim_cb(&nmp.oph, NULL);
Harald Welte25de8112010-05-13 21:26:28 +0200537
538 /* We always acknowledge the unBLOCKing */
Max548caef2019-03-07 13:49:34 +0100539 return bssgp_tx_simple_bvci(BSSGP_PDUT_BVC_UNBLOCK_ACK, nsei,
Harald Welte25de8112010-05-13 21:26:28 +0200540 bvci, msgb_bvci(msg));
541};
542
Harald Welte9ba50052010-03-14 15:45:01 +0800543/* Uplink unit-data */
Harald Welte25de8112010-05-13 21:26:28 +0200544static int bssgp_rx_ul_ud(struct msgb *msg, struct tlv_parsed *tp,
Harald Welte8a521132010-05-17 22:59:29 +0200545 struct bssgp_bvc_ctx *ctx)
Harald Welte9ba50052010-03-14 15:45:01 +0800546{
Harald Welte15a36432012-06-17 12:16:31 +0800547 struct osmo_bssgp_prim gbp;
Harald Welteec19c102010-05-02 09:50:42 +0200548 struct bssgp_ud_hdr *budh = (struct bssgp_ud_hdr *) msgb_bssgph(msg);
Harald Welte9ba50052010-03-14 15:45:01 +0800549
Harald Welte6752fa42010-05-02 09:23:16 +0200550 /* extract TLLI and parse TLV IEs */
Harald Weltebfe62e52017-05-15 12:48:30 +0200551 msgb_tlli(msg) = osmo_ntohl(budh->tlli);
Harald Welte9ba50052010-03-14 15:45:01 +0800552
Harald Weltefde19ed2020-12-07 21:43:51 +0100553 DEBUGP(DLBSSGP, "BSSGP TLLI=0x%08x Rx UPLINK-UNITDATA\n", msgb_tlli(msg));
Harald Weltee9686b62010-05-31 18:07:17 +0200554
Harald Welte9ba50052010-03-14 15:45:01 +0800555 /* Cell ID and LLC_PDU are the only mandatory IE */
Harald Welte2d9ce712020-12-03 15:53:59 +0100556 if (!TLVP_PRES_LEN(tp, BSSGP_IE_CELL_ID, 8) ||
Harald Weltee9686b62010-05-31 18:07:17 +0200557 !TLVP_PRESENT(tp, BSSGP_IE_LLC_PDU)) {
Harald Weltefde19ed2020-12-07 21:43:51 +0100558 LOGP(DLBSSGP, LOGL_ERROR, "BSSGP TLLI=0x%08x Rx UL-UD "
Harald Weltee9686b62010-05-31 18:07:17 +0200559 "missing mandatory IE\n", msgb_tlli(msg));
Harald Welte25de8112010-05-13 21:26:28 +0200560 return bssgp_tx_status(BSSGP_CAUSE_MISSING_MAND_IE, NULL, msg);
Harald Weltee9686b62010-05-31 18:07:17 +0200561 }
Harald Welte30bc19a2010-05-02 11:19:37 +0200562
Harald Weltea2ca4ed2010-05-02 11:54:55 +0200563 /* store pointer to LLC header and CELL ID in msgb->cb */
Holger Hans Peter Freytherb6eded82010-05-23 21:11:19 +0800564 msgb_llch(msg) = (uint8_t *) TLVP_VAL(tp, BSSGP_IE_LLC_PDU);
565 msgb_bcid(msg) = (uint8_t *) TLVP_VAL(tp, BSSGP_IE_CELL_ID);
Harald Welte9ba50052010-03-14 15:45:01 +0800566
Harald Welte15a36432012-06-17 12:16:31 +0800567 /* Send BSSGP_UL_UD.ind to NM */
568 memset(&gbp, 0, sizeof(gbp));
569 gbp.nsei = ctx->nsei;
570 gbp.bvci = ctx->bvci;
571 gbp.tlli = msgb_tlli(msg);
572 gbp.tp = tp;
573 osmo_prim_init(&gbp.oph, SAP_BSSGP_LL, PRIM_BSSGP_UL_UD,
574 PRIM_OP_INDICATION, msg);
575 return bssgp_prim_cb(&gbp.oph, NULL);
Harald Welte9ba50052010-03-14 15:45:01 +0800576}
577
Jacob Erlbeckb43baf22014-09-10 12:43:28 +0200578static int bssgp_rx_suspend(struct msgb *msg, struct tlv_parsed *tp)
Harald Welte9ba50052010-03-14 15:45:01 +0800579{
Harald Welte15a36432012-06-17 12:16:31 +0800580 struct osmo_bssgp_prim gbp;
Harald Weltea8aa4df2010-05-30 22:00:53 +0200581 struct gprs_ra_id raid;
582 uint32_t tlli;
Max548caef2019-03-07 13:49:34 +0100583 uint16_t ns_bvci = msgb_bvci(msg), nsei = msgb_nsei(msg);
Harald Welte313cccf2010-06-09 11:22:47 +0200584 int rc;
Harald Welte9ba50052010-03-14 15:45:01 +0800585
Harald Welte2d9ce712020-12-03 15:53:59 +0100586 if (!TLVP_PRES_LEN(tp, BSSGP_IE_TLLI, 4) ||
587 !TLVP_PRES_LEN(tp, BSSGP_IE_ROUTEING_AREA, 6)) {
Harald Weltefde19ed2020-12-07 21:43:51 +0100588 LOGP(DLBSSGP, LOGL_ERROR, "BSSGP BVCI=%u Rx SUSPEND "
Jacob Erlbeckb43baf22014-09-10 12:43:28 +0200589 "missing mandatory IE\n", ns_bvci);
Harald Welte25de8112010-05-13 21:26:28 +0200590 return bssgp_tx_status(BSSGP_CAUSE_MISSING_MAND_IE, NULL, msg);
Harald Weltee9686b62010-05-31 18:07:17 +0200591 }
Harald Welte9ba50052010-03-14 15:45:01 +0800592
Harald Weltebfe62e52017-05-15 12:48:30 +0200593 tlli = tlvp_val32be(tp, BSSGP_IE_TLLI);
Harald Weltee9686b62010-05-31 18:07:17 +0200594
Harald Weltefde19ed2020-12-07 21:43:51 +0100595 DEBUGP(DLBSSGP, "BSSGP BVCI=%u TLLI=0x%08x Rx SUSPEND\n",
Jacob Erlbeckb43baf22014-09-10 12:43:28 +0200596 ns_bvci, tlli);
Harald Weltee9686b62010-05-31 18:07:17 +0200597
Harald Weltea8aa4df2010-05-30 22:00:53 +0200598 gsm48_parse_ra(&raid, TLVP_VAL(tp, BSSGP_IE_ROUTEING_AREA));
599
Harald Welte313cccf2010-06-09 11:22:47 +0200600 /* Inform GMM about the SUSPEND request */
Harald Welte15a36432012-06-17 12:16:31 +0800601 memset(&gbp, 0, sizeof(gbp));
Max548caef2019-03-07 13:49:34 +0100602 gbp.nsei = nsei;
Jacob Erlbeckb43baf22014-09-10 12:43:28 +0200603 gbp.bvci = ns_bvci;
Harald Welte15a36432012-06-17 12:16:31 +0800604 gbp.tlli = tlli;
605 gbp.ra_id = &raid;
606 osmo_prim_init(&gbp.oph, SAP_BSSGP_GMM, PRIM_BSSGP_GMM_SUSPEND,
607 PRIM_OP_REQUEST, msg);
608
609 rc = bssgp_prim_cb(&gbp.oph, NULL);
Harald Welte313cccf2010-06-09 11:22:47 +0200610 if (rc < 0)
Max548caef2019-03-07 13:49:34 +0100611 return bssgp_tx_suspend_nack(nsei, tlli, &raid, NULL);
Harald Welte313cccf2010-06-09 11:22:47 +0200612
Max548caef2019-03-07 13:49:34 +0100613 bssgp_tx_suspend_ack(nsei, tlli, &raid, 0);
Harald Weltea8aa4df2010-05-30 22:00:53 +0200614
Holger Hans Peter Freytherd30cefa2010-05-23 21:12:15 +0800615 return 0;
Harald Welte9ba50052010-03-14 15:45:01 +0800616}
617
Jacob Erlbeckb43baf22014-09-10 12:43:28 +0200618static int bssgp_rx_resume(struct msgb *msg, struct tlv_parsed *tp)
Harald Welte9ba50052010-03-14 15:45:01 +0800619{
Harald Welte15a36432012-06-17 12:16:31 +0800620 struct osmo_bssgp_prim gbp;
Harald Weltea8aa4df2010-05-30 22:00:53 +0200621 struct gprs_ra_id raid;
622 uint32_t tlli;
Harald Welte313cccf2010-06-09 11:22:47 +0200623 uint8_t suspend_ref;
Max548caef2019-03-07 13:49:34 +0100624 uint16_t ns_bvci = msgb_bvci(msg), nsei = msgb_nsei(msg);
Harald Welte313cccf2010-06-09 11:22:47 +0200625 int rc;
Harald Welte9ba50052010-03-14 15:45:01 +0800626
Harald Welte2d9ce712020-12-03 15:53:59 +0100627 if (!TLVP_PRES_LEN(tp, BSSGP_IE_TLLI, 4 ) ||
628 !TLVP_PRES_LEN(tp, BSSGP_IE_ROUTEING_AREA, 6) ||
629 !TLVP_PRES_LEN(tp, BSSGP_IE_SUSPEND_REF_NR, 1)) {
Harald Weltefde19ed2020-12-07 21:43:51 +0100630 LOGP(DLBSSGP, LOGL_ERROR, "BSSGP BVCI=%u Rx RESUME "
Jacob Erlbeckb43baf22014-09-10 12:43:28 +0200631 "missing mandatory IE\n", ns_bvci);
Harald Welte25de8112010-05-13 21:26:28 +0200632 return bssgp_tx_status(BSSGP_CAUSE_MISSING_MAND_IE, NULL, msg);
Harald Weltee9686b62010-05-31 18:07:17 +0200633 }
Harald Welte9ba50052010-03-14 15:45:01 +0800634
Harald Weltebfe62e52017-05-15 12:48:30 +0200635 tlli = tlvp_val32be(tp, BSSGP_IE_TLLI);
Harald Welte313cccf2010-06-09 11:22:47 +0200636 suspend_ref = *TLVP_VAL(tp, BSSGP_IE_SUSPEND_REF_NR);
Harald Weltee9686b62010-05-31 18:07:17 +0200637
Harald Weltefde19ed2020-12-07 21:43:51 +0100638 DEBUGP(DLBSSGP, "BSSGP BVCI=%u TLLI=0x%08x Rx RESUME\n", ns_bvci, tlli);
Harald Weltee9686b62010-05-31 18:07:17 +0200639
Harald Weltea8aa4df2010-05-30 22:00:53 +0200640 gsm48_parse_ra(&raid, TLVP_VAL(tp, BSSGP_IE_ROUTEING_AREA));
641
Harald Welte313cccf2010-06-09 11:22:47 +0200642 /* Inform GMM about the RESUME request */
Harald Welte15a36432012-06-17 12:16:31 +0800643 memset(&gbp, 0, sizeof(gbp));
Max548caef2019-03-07 13:49:34 +0100644 gbp.nsei = nsei;
Jacob Erlbeckb43baf22014-09-10 12:43:28 +0200645 gbp.bvci = ns_bvci;
Harald Welte15a36432012-06-17 12:16:31 +0800646 gbp.tlli = tlli;
647 gbp.ra_id = &raid;
648 gbp.u.resume.suspend_ref = suspend_ref;
649 osmo_prim_init(&gbp.oph, SAP_BSSGP_GMM, PRIM_BSSGP_GMM_RESUME,
650 PRIM_OP_REQUEST, msg);
651
652 rc = bssgp_prim_cb(&gbp.oph, NULL);
Harald Welte313cccf2010-06-09 11:22:47 +0200653 if (rc < 0)
Max548caef2019-03-07 13:49:34 +0100654 return bssgp_tx_resume_nack(nsei, tlli, &raid,
Harald Welte313cccf2010-06-09 11:22:47 +0200655 NULL);
656
Max548caef2019-03-07 13:49:34 +0100657 bssgp_tx_resume_ack(nsei, tlli, &raid);
Holger Hans Peter Freytherd30cefa2010-05-23 21:12:15 +0800658 return 0;
Harald Welte9ba50052010-03-14 15:45:01 +0800659}
660
Harald Weltee9686b62010-05-31 18:07:17 +0200661
662static int bssgp_rx_llc_disc(struct msgb *msg, struct tlv_parsed *tp,
663 struct bssgp_bvc_ctx *ctx)
664{
Harald Welte15a36432012-06-17 12:16:31 +0800665 struct osmo_bssgp_prim nmp;
Harald Welteb7363142010-07-23 21:59:29 +0200666 uint32_t tlli = 0;
Max548caef2019-03-07 13:49:34 +0100667 uint16_t nsei = msgb_nsei(msg);
Harald Weltee9686b62010-05-31 18:07:17 +0200668
Harald Welte2d9ce712020-12-03 15:53:59 +0100669 if (!TLVP_PRES_LEN(tp, BSSGP_IE_TLLI, 4) ||
670 !TLVP_PRES_LEN(tp, BSSGP_IE_LLC_FRAMES_DISCARDED, 1) ||
671 !TLVP_PRES_LEN(tp, BSSGP_IE_BVCI, 2) ||
672 !TLVP_PRES_LEN(tp, BSSGP_IE_NUM_OCT_AFF, 3)) {
Harald Weltefde19ed2020-12-07 21:43:51 +0100673 LOGP(DLBSSGP, LOGL_ERROR, "BSSGP BVCI=%u Rx LLC DISCARDED "
Harald Weltee9686b62010-05-31 18:07:17 +0200674 "missing mandatory IE\n", ctx->bvci);
Harald Welte2d9ce712020-12-03 15:53:59 +0100675 return bssgp_tx_status(BSSGP_CAUSE_MISSING_MAND_IE, NULL, msg);
Harald Weltee9686b62010-05-31 18:07:17 +0200676 }
677
Harald Welte2d9ce712020-12-03 15:53:59 +0100678 tlli = tlvp_val32be(tp, BSSGP_IE_TLLI);
Harald Weltee9686b62010-05-31 18:07:17 +0200679
Harald Weltefde19ed2020-12-07 21:43:51 +0100680 DEBUGP(DLBSSGP, "BSSGP BVCI=%u TLLI=%08x Rx LLC DISCARDED\n",
Harald Weltee9686b62010-05-31 18:07:17 +0200681 ctx->bvci, tlli);
682
683 rate_ctr_inc(&ctx->ctrg->ctr[BSSGP_CTR_DISCARDED]);
684
Harald Welte15a36432012-06-17 12:16:31 +0800685 /* send NM_LLC_DISCARDED to NM */
686 memset(&nmp, 0, sizeof(nmp));
Max548caef2019-03-07 13:49:34 +0100687 nmp.nsei = nsei;
Harald Welte15a36432012-06-17 12:16:31 +0800688 nmp.bvci = ctx->bvci;
689 nmp.tlli = tlli;
690 nmp.tp = tp;
691 osmo_prim_init(&nmp.oph, SAP_BSSGP_NM, PRIM_NM_LLC_DISCARDED,
692 PRIM_OP_INDICATION, msg);
693
694 return bssgp_prim_cb(&nmp.oph, NULL);
Harald Weltee9686b62010-05-31 18:07:17 +0200695}
696
Jacob Erlbeck36153dc2015-03-17 10:21:17 +0100697int bssgp_rx_status(struct msgb *msg, struct tlv_parsed *tp,
698 uint16_t bvci, struct bssgp_bvc_ctx *bctx)
699{
Max548caef2019-03-07 13:49:34 +0100700 uint16_t nsei = msgb_nsei(msg);
Jacob Erlbeck36153dc2015-03-17 10:21:17 +0100701 struct osmo_bssgp_prim nmp;
702 enum gprs_bssgp_cause cause;
703
Harald Welte2d9ce712020-12-03 15:53:59 +0100704 if (!TLVP_PRES_LEN(tp, BSSGP_IE_CAUSE, 1)) {
Harald Weltefde19ed2020-12-07 21:43:51 +0100705 LOGP(DLBSSGP, LOGL_ERROR, "BSSGP BVCI=%u Rx STATUS "
Jacob Erlbeck36153dc2015-03-17 10:21:17 +0100706 "missing mandatory IE\n", bvci);
707 cause = BSSGP_CAUSE_PROTO_ERR_UNSPEC;
708 } else {
709 cause = *TLVP_VAL(tp, BSSGP_IE_CAUSE);
710 }
711
Harald Weltefde19ed2020-12-07 21:43:51 +0100712 LOGP(DLBSSGP, LOGL_NOTICE, "BSSGP BVCI=%u Rx BVC STATUS, cause=%s\n",
Jacob Erlbeck36153dc2015-03-17 10:21:17 +0100713 bvci, bssgp_cause_str(cause));
714
715 if (cause == BSSGP_CAUSE_BVCI_BLOCKED || cause == BSSGP_CAUSE_UNKNOWN_BVCI) {
Harald Welte2d9ce712020-12-03 15:53:59 +0100716 if (!TLVP_PRES_LEN(tp, BSSGP_IE_BVCI, 2))
Harald Weltefde19ed2020-12-07 21:43:51 +0100717 LOGP(DLBSSGP, LOGL_ERROR,
Jacob Erlbeck36153dc2015-03-17 10:21:17 +0100718 "BSSGP BVCI=%u Rx STATUS cause=%s "
719 "missing conditional BVCI IE\n",
720 bvci, bssgp_cause_str(cause));
721 }
722
723 if (bctx)
724 rate_ctr_inc(&bctx->ctrg->ctr[BSSGP_CTR_STATUS]);
725
726 /* send NM_STATUS to NM */
727 memset(&nmp, 0, sizeof(nmp));
Max548caef2019-03-07 13:49:34 +0100728 nmp.nsei = nsei;
Jacob Erlbeck36153dc2015-03-17 10:21:17 +0100729 nmp.bvci = bvci;
730 nmp.tp = tp;
731 osmo_prim_init(&nmp.oph, SAP_BSSGP_NM, PRIM_NM_STATUS,
732 PRIM_OP_INDICATION, msg);
733
734 return bssgp_prim_cb(&nmp.oph, NULL);
735}
736
Philipp Maier1eaa7bc2020-12-16 21:07:04 +0100737static int bssgp_rx_rim(struct msgb *msg, struct tlv_parsed *tp, uint16_t bvci)
738{
739 struct osmo_bssgp_prim nmp;
740 uint16_t nsei = msgb_nsei(msg);
741 struct bssgp_normal_hdr *bgph = (struct bssgp_normal_hdr *)msgb_bssgph(msg);
742 enum bssgp_prim prim;
743
744 DEBUGP(DLBSSGP, "BSSGP BVCI=%u Rx RIM-PDU:%s\n", bvci, bssgp_pdu_str(bgph->pdu_type));
745
746 /* Specify PRIM type based on the RIM PDU */
747 switch (bgph->pdu_type) {
748 case BSSGP_PDUT_RAN_INFO:
749 case BSSGP_PDUT_RAN_INFO_REQ:
750 case BSSGP_PDUT_RAN_INFO_ACK:
751 case BSSGP_PDUT_RAN_INFO_ERROR:
752 case BSSGP_PDUT_RAN_INFO_APP_ERROR:
753 prim = PRIM_BSSGP_RIM_PDU_TRANSFER;
754 break;
755 default:
756 /* Caller already makes sure that this can't happen. */
757 OSMO_ASSERT(false);
758 }
759
760 /* Send BSSGP RIM indication to NM */
761 memset(&nmp, 0, sizeof(nmp));
762 nmp.nsei = nsei;
763 nmp.bvci = bvci;
764 nmp.tp = tp;
765 osmo_prim_init(&nmp.oph, SAP_BSSGP_RIM, prim, PRIM_OP_INDICATION, msg);
766 bssgp_prim_cb(&nmp.oph, NULL);
767
768 return 0;
769}
Jacob Erlbeck36153dc2015-03-17 10:21:17 +0100770
Harald Welted11c0592012-09-06 21:57:11 +0200771/* One element (msgb) in a BSSGP Flow Control queue */
772struct bssgp_fc_queue_element {
773 /* linked list of queue elements */
774 struct llist_head list;
775 /* The message that we have enqueued */
776 struct msgb *msg;
777 /* Length of the LLC PDU part of the contained message */
778 uint32_t llc_pdu_len;
779 /* private pointer passed to the flow control out_cb function */
780 void *priv;
781};
782
783static int fc_queue_timer_cfg(struct bssgp_flow_control *fc);
784static int bssgp_fc_needs_queueing(struct bssgp_flow_control *fc, uint32_t pdu_len);
785
786static void fc_timer_cb(void *data)
787{
788 struct bssgp_flow_control *fc = data;
789 struct bssgp_fc_queue_element *fcqe;
790 struct timeval time_now;
791
792 /* if the queue is empty, we return without sending something
793 * and without re-starting the timer */
794 if (llist_empty(&fc->queue))
795 return;
796
797 /* get the first entry from the queue */
798 fcqe = llist_entry(fc->queue.next, struct bssgp_fc_queue_element,
799 list);
800
801 if (bssgp_fc_needs_queueing(fc, fcqe->llc_pdu_len)) {
Harald Weltefde19ed2020-12-07 21:43:51 +0100802 LOGP(DLBSSGP, LOGL_NOTICE, "BSSGP-FC: fc_timer_cb() but still "
Harald Welted11c0592012-09-06 21:57:11 +0200803 "not able to send PDU of %u bytes\n", fcqe->llc_pdu_len);
804 /* make sure we re-start the timer */
805 fc_queue_timer_cfg(fc);
806 return;
807 }
808
809 /* remove from the queue */
810 llist_del(&fcqe->list);
811
812 fc->queue_depth--;
813
814 /* record the time we transmitted this PDU */
Neels Hofmeyr8e2f7e82016-09-22 03:58:13 +0200815 osmo_gettimeofday(&time_now, NULL);
Harald Welted11c0592012-09-06 21:57:11 +0200816 fc->time_last_pdu = time_now;
817
818 /* call the output callback for this FC instance */
819 fc->out_cb(fcqe->priv, fcqe->msg, fcqe->llc_pdu_len, NULL);
820
821 /* we expect that out_cb will in the end free the msgb once
822 * it is no longer needed */
823
824 /* but we have to free the queue element ourselves */
825 talloc_free(fcqe);
826
827 /* re-configure the timer for the next PDU */
828 fc_queue_timer_cfg(fc);
829}
830
831/* configure/schedule the flow control timer to expire once the bucket
832 * will have leaked a sufficient number of bytes to transmit the next
833 * PDU in the queue */
834static int fc_queue_timer_cfg(struct bssgp_flow_control *fc)
835{
836 struct bssgp_fc_queue_element *fcqe;
837 uint32_t msecs;
838
839 if (llist_empty(&fc->queue))
840 return 0;
841
Jacob Erlbeck97319352015-04-30 19:28:03 +0200842 fcqe = llist_entry(fc->queue.next, struct bssgp_fc_queue_element,
Harald Welted11c0592012-09-06 21:57:11 +0200843 list);
844
Harald Welte27b2bb72013-06-22 09:44:00 +0200845 if (fc->bucket_leak_rate != 0) {
846 /* Calculate the point in time at which we will have leaked
847 * a sufficient number of bytes from the bucket to transmit
848 * the first PDU in the queue */
849 msecs = (fcqe->llc_pdu_len * 1000) / fc->bucket_leak_rate;
850 /* FIXME: add that time to fc->time_last_pdu and subtract it from
851 * current time */
Pablo Neira Ayuso44f423f2017-05-08 18:00:28 +0200852 osmo_timer_setup(&fc->timer, fc_timer_cb, fc);
Harald Welte27b2bb72013-06-22 09:44:00 +0200853 osmo_timer_schedule(&fc->timer, msecs / 1000, (msecs % 1000) * 1000);
854 } else {
855 /* If the PCU is telling us to not send any more data at all,
856 * there's no point starting a timer. */
857 }
Harald Welted11c0592012-09-06 21:57:11 +0200858
859 return 0;
860}
861
862/* Enqueue a PDU in the flow control queue for delayed transmission */
863static int fc_enqueue(struct bssgp_flow_control *fc, struct msgb *msg,
864 uint32_t llc_pdu_len, void *priv)
865{
866 struct bssgp_fc_queue_element *fcqe;
867
868 if (fc->queue_depth >= fc->max_queue_depth)
869 return -ENOSPC;
870
871 fcqe = talloc_zero(fc, struct bssgp_fc_queue_element);
872 if (!fcqe)
873 return -ENOMEM;
874 fcqe->msg = msg;
875 fcqe->llc_pdu_len = llc_pdu_len;
876 fcqe->priv = priv;
877
878 llist_add_tail(&fcqe->list, &fc->queue);
879
880 fc->queue_depth++;
881
882 /* re-configure the timer for dequeueing the pdu */
883 fc_queue_timer_cfg(fc);
884
885 return 0;
886}
887
888/* According to Section 8.2 */
889static int bssgp_fc_needs_queueing(struct bssgp_flow_control *fc, uint32_t pdu_len)
890{
891 struct timeval time_now, time_diff;
892 int64_t bucket_predicted;
893 uint32_t csecs_elapsed, leaked;
894
895 /* B' = B + L(p) - (Tc - Tp)*R */
896
897 /* compute number of centi-seconds that have elapsed since transmitting
898 * the last PDU (Tc - Tp) */
Neels Hofmeyr8e2f7e82016-09-22 03:58:13 +0200899 osmo_gettimeofday(&time_now, NULL);
Harald Welted11c0592012-09-06 21:57:11 +0200900 timersub(&time_now, &fc->time_last_pdu, &time_diff);
901 csecs_elapsed = time_diff.tv_sec*100 + time_diff.tv_usec/10000;
902
903 /* compute number of bytes that have leaked in the elapsed number
904 * of centi-seconds */
905 leaked = csecs_elapsed * (fc->bucket_leak_rate / 100);
906 /* add the current PDU length to the last bucket level */
907 bucket_predicted = fc->bucket_counter + pdu_len;
908 /* ... and subtract the number of leaked bytes */
909 bucket_predicted -= leaked;
910
Vadim Yanitskiyf1786952017-06-12 03:41:35 +0700911 if (bucket_predicted < pdu_len)
912 return 0;
Harald Welted11c0592012-09-06 21:57:11 +0200913
914 if (bucket_predicted <= fc->bucket_size_max) {
915 /* the bucket is not full yet, we can pass the packet */
916 fc->bucket_counter = bucket_predicted;
Vadim Yanitskiyf1786952017-06-12 03:41:35 +0700917 return 0;
Harald Welted11c0592012-09-06 21:57:11 +0200918 }
919
920 /* bucket is full, PDU needs to be delayed */
921 return 1;
Harald Welted11c0592012-09-06 21:57:11 +0200922}
923
924/* output callback for BVC flow control */
925static int _bssgp_tx_dl_ud(struct bssgp_flow_control *fc, struct msgb *msg,
926 uint32_t llc_pdu_len, void *priv)
927{
Alexander Couzens85a8fd32020-07-18 15:57:07 +0200928 return bssgp_ns_send(bssgp_ns_send_data, msg);
Harald Welted11c0592012-09-06 21:57:11 +0200929}
930
931/* input function of the flow control implementation, called first
932 * for the MM flow control, and then as the MM flow control output
933 * callback in order to perform BVC flow control */
934int bssgp_fc_in(struct bssgp_flow_control *fc, struct msgb *msg,
935 uint32_t llc_pdu_len, void *priv)
936{
937 struct timeval time_now;
938
Harald Weltebb826222012-09-07 10:22:01 +0200939 if (llc_pdu_len > fc->bucket_size_max) {
Harald Weltefde19ed2020-12-07 21:43:51 +0100940 LOGP(DLBSSGP, LOGL_NOTICE, "Single PDU (size=%u) is larger "
Harald Weltebb826222012-09-07 10:22:01 +0200941 "than maximum bucket size (%u)!\n", llc_pdu_len,
942 fc->bucket_size_max);
Holger Hans Peter Freyther10dd73c2014-10-10 17:24:34 +0200943 msgb_free(msg);
Harald Weltebb826222012-09-07 10:22:01 +0200944 return -EIO;
945 }
946
Harald Welted11c0592012-09-06 21:57:11 +0200947 if (bssgp_fc_needs_queueing(fc, llc_pdu_len)) {
Neels Hofmeyrcd325ef2017-11-16 22:32:36 +0100948 int rc;
949 rc = fc_enqueue(fc, msg, llc_pdu_len, priv);
950 if (rc)
951 msgb_free(msg);
952 return rc;
Harald Welted11c0592012-09-06 21:57:11 +0200953 } else {
954 /* record the time we transmitted this PDU */
Neels Hofmeyr8e2f7e82016-09-22 03:58:13 +0200955 osmo_gettimeofday(&time_now, NULL);
Harald Welted11c0592012-09-06 21:57:11 +0200956 fc->time_last_pdu = time_now;
957 return fc->out_cb(priv, msg, llc_pdu_len, NULL);
958 }
959}
960
Harald Weltebb826222012-09-07 10:22:01 +0200961
962/* Initialize the Flow Control structure */
963void bssgp_fc_init(struct bssgp_flow_control *fc,
964 uint32_t bucket_size_max, uint32_t bucket_leak_rate,
965 uint32_t max_queue_depth,
966 int (*out_cb)(struct bssgp_flow_control *fc, struct msgb *msg,
967 uint32_t llc_pdu_len, void *priv))
968{
969 fc->out_cb = out_cb;
970 fc->bucket_size_max = bucket_size_max;
971 fc->bucket_leak_rate = bucket_leak_rate;
972 fc->max_queue_depth = max_queue_depth;
973 INIT_LLIST_HEAD(&fc->queue);
Neels Hofmeyr8e2f7e82016-09-22 03:58:13 +0200974 osmo_gettimeofday(&fc->time_last_pdu, NULL);
Harald Weltebb826222012-09-07 10:22:01 +0200975}
976
Harald Welted11c0592012-09-06 21:57:11 +0200977/* Initialize the Flow Control parameters for a new MS according to
978 * default values for the BVC specified by BVCI and NSEI */
979int bssgp_fc_ms_init(struct bssgp_flow_control *fc_ms, uint16_t bvci,
Harald Weltebb826222012-09-07 10:22:01 +0200980 uint16_t nsei, uint32_t max_queue_depth)
Harald Welted11c0592012-09-06 21:57:11 +0200981{
982 struct bssgp_bvc_ctx *ctx;
983
984 ctx = btsctx_by_bvci_nsei(bvci, nsei);
985 if (!ctx)
986 return -ENODEV;
Harald Weltebb826222012-09-07 10:22:01 +0200987
988 /* output call-back of per-MS FC is per-CTX FC */
989 bssgp_fc_init(fc_ms, ctx->bmax_default_ms, ctx->r_default_ms,
990 max_queue_depth, bssgp_fc_in);
Harald Welted11c0592012-09-06 21:57:11 +0200991
992 return 0;
993}
994
Harald Welte25de8112010-05-13 21:26:28 +0200995static int bssgp_rx_fc_bvc(struct msgb *msg, struct tlv_parsed *tp,
Harald Welte8a521132010-05-17 22:59:29 +0200996 struct bssgp_bvc_ctx *bctx)
Harald Welte9ba50052010-03-14 15:45:01 +0800997{
Harald Welte27b2bb72013-06-22 09:44:00 +0200998 uint32_t old_leak_rate = bctx->fc->bucket_leak_rate;
999 uint32_t old_r_def_ms = bctx->r_default_ms;
Harald Welte9ba50052010-03-14 15:45:01 +08001000
Harald Weltefde19ed2020-12-07 21:43:51 +01001001 DEBUGP(DLBSSGP, "BSSGP BVCI=%u Rx Flow Control BVC\n",
Harald Weltee9686b62010-05-31 18:07:17 +02001002 bctx->bvci);
Harald Welte9ba50052010-03-14 15:45:01 +08001003
Harald Welte2d9ce712020-12-03 15:53:59 +01001004 if (!TLVP_PRES_LEN(tp, BSSGP_IE_TAG, 1) ||
1005 !TLVP_PRES_LEN(tp, BSSGP_IE_BVC_BUCKET_SIZE, 2) ||
1006 !TLVP_PRES_LEN(tp, BSSGP_IE_BUCKET_LEAK_RATE, 2) ||
1007 !TLVP_PRES_LEN(tp, BSSGP_IE_BMAX_DEFAULT_MS, 2) ||
1008 !TLVP_PRES_LEN(tp, BSSGP_IE_R_DEFAULT_MS,2)) {
Harald Weltefde19ed2020-12-07 21:43:51 +01001009 LOGP(DLBSSGP, LOGL_ERROR, "BSSGP BVCI=%u Rx FC BVC "
Harald Weltee9686b62010-05-31 18:07:17 +02001010 "missing mandatory IE\n", bctx->bvci);
Harald Welte9ba50052010-03-14 15:45:01 +08001011 return bssgp_tx_status(BSSGP_CAUSE_MISSING_MAND_IE, NULL, msg);
Harald Weltee9686b62010-05-31 18:07:17 +02001012 }
Harald Welte9ba50052010-03-14 15:45:01 +08001013
Harald Weltebb826222012-09-07 10:22:01 +02001014 /* 11.3.5 Bucket Size in 100 octets unit */
Harald Weltebfe62e52017-05-15 12:48:30 +02001015 bctx->fc->bucket_size_max = 100 * tlvp_val16be(tp, BSSGP_IE_BVC_BUCKET_SIZE);
Harald Weltebb826222012-09-07 10:22:01 +02001016 /* 11.3.4 Bucket Leak Rate in 100 bits/sec unit */
Harald Weltebfe62e52017-05-15 12:48:30 +02001017 bctx->fc->bucket_leak_rate = 100 * tlvp_val16be(tp, BSSGP_IE_BUCKET_LEAK_RATE) / 8;
Harald Weltebb826222012-09-07 10:22:01 +02001018 /* 11.3.2 in octets */
Harald Weltebfe62e52017-05-15 12:48:30 +02001019 bctx->bmax_default_ms = tlvp_val16be(tp, BSSGP_IE_BMAX_DEFAULT_MS);
Harald Weltebb826222012-09-07 10:22:01 +02001020 /* 11.3.32 Bucket Leak rate in 100bits/sec unit */
Harald Weltebfe62e52017-05-15 12:48:30 +02001021 bctx->r_default_ms = 100 * tlvp_val16be(tp, BSSGP_IE_R_DEFAULT_MS) / 8;
Harald Welte30bc19a2010-05-02 11:19:37 +02001022
Harald Welte27b2bb72013-06-22 09:44:00 +02001023 if (old_leak_rate != 0 && bctx->fc->bucket_leak_rate == 0)
Harald Weltefde19ed2020-12-07 21:43:51 +01001024 LOGP(DLBSSGP, LOGL_NOTICE, "BSS instructs us to bucket leak "
Harald Welte27b2bb72013-06-22 09:44:00 +02001025 "rate of 0, stopping all DL GPRS!\n");
1026 else if (old_leak_rate == 0 && bctx->fc->bucket_leak_rate != 0)
Harald Weltefde19ed2020-12-07 21:43:51 +01001027 LOGP(DLBSSGP, LOGL_NOTICE, "BSS instructs us to bucket leak "
Harald Welte27b2bb72013-06-22 09:44:00 +02001028 "rate of != 0, restarting all DL GPRS!\n");
1029
1030 if (old_r_def_ms != 0 && bctx->r_default_ms == 0)
Harald Weltefde19ed2020-12-07 21:43:51 +01001031 LOGP(DLBSSGP, LOGL_NOTICE, "BSS instructs us to MS default "
Harald Welte27b2bb72013-06-22 09:44:00 +02001032 "bucket leak rate of 0, stopping DL GPRS!\n");
1033 else if (old_r_def_ms == 0 && bctx->r_default_ms != 0)
Harald Weltefde19ed2020-12-07 21:43:51 +01001034 LOGP(DLBSSGP, LOGL_NOTICE, "BSS instructs us to MS default "
Harald Welte27b2bb72013-06-22 09:44:00 +02001035 "bucket leak rate != 0, restarting DL GPRS!\n");
1036
1037 /* reconfigure the timer for flow control based on new values */
1038 fc_queue_timer_cfg(bctx->fc);
1039
Harald Welte9ba50052010-03-14 15:45:01 +08001040 /* Send FLOW_CONTROL_BVC_ACK */
Harald Welte24a655f2010-04-30 19:54:29 +02001041 return bssgp_tx_fc_bvc_ack(msgb_nsei(msg), *TLVP_VAL(tp, BSSGP_IE_TAG),
Harald Welte30bc19a2010-05-02 11:19:37 +02001042 msgb_bvci(msg));
Harald Welte9ba50052010-03-14 15:45:01 +08001043}
Harald Welte3fddf3c2010-05-01 16:48:27 +02001044
Harald Welte25de8112010-05-13 21:26:28 +02001045/* Receive a BSSGP PDU from a BSS on a PTP BVCI */
Harald Weltede4599c2012-06-17 13:04:02 +08001046static int bssgp_rx_ptp(struct msgb *msg, struct tlv_parsed *tp,
1047 struct bssgp_bvc_ctx *bctx)
Harald Welte9ba50052010-03-14 15:45:01 +08001048{
Harald Welteec19c102010-05-02 09:50:42 +02001049 struct bssgp_normal_hdr *bgph =
1050 (struct bssgp_normal_hdr *) msgb_bssgph(msg);
Harald Welte30bc19a2010-05-02 11:19:37 +02001051 uint8_t pdu_type = bgph->pdu_type;
Harald Welte9ba50052010-03-14 15:45:01 +08001052 int rc = 0;
1053
Jacob Erlbeck36153dc2015-03-17 10:21:17 +01001054 OSMO_ASSERT(pdu_type != BSSGP_PDUT_STATUS);
1055
Harald Welte58e65c92010-05-13 21:45:23 +02001056 /* If traffic is received on a BVC that is marked as blocked, the
1057 * received PDU shall not be accepted and a STATUS PDU (Cause value:
1058 * BVC Blocked) shall be sent to the peer entity on the signalling BVC */
Jacob Erlbeck36153dc2015-03-17 10:21:17 +01001059 if (bctx->state & BVC_S_BLOCKED) {
Harald Welte58e65c92010-05-13 21:45:23 +02001060 uint16_t bvci = msgb_bvci(msg);
1061 return bssgp_tx_status(BSSGP_CAUSE_BVCI_BLOCKED, &bvci, msg);
1062 }
1063
Harald Welte9ba50052010-03-14 15:45:01 +08001064 switch (pdu_type) {
1065 case BSSGP_PDUT_UL_UNITDATA:
1066 /* some LLC data from the MS */
Harald Welte25de8112010-05-13 21:26:28 +02001067 rc = bssgp_rx_ul_ud(msg, tp, bctx);
Harald Welte9ba50052010-03-14 15:45:01 +08001068 break;
1069 case BSSGP_PDUT_RA_CAPABILITY:
1070 /* BSS requests RA capability or IMSI */
Harald Weltefde19ed2020-12-07 21:43:51 +01001071 DEBUGP(DLBSSGP, "BSSGP BVCI=%u Rx RA CAPABILITY UPDATE\n",
Harald Weltee9686b62010-05-31 18:07:17 +02001072 bctx->bvci);
Harald Welte6b7cf252010-05-13 19:41:31 +02001073 /* FIXME: send GMM_RA_CAPABILITY_UPDATE.ind to GMM */
Harald Welte9ba50052010-03-14 15:45:01 +08001074 /* FIXME: send RA_CAPA_UPDATE_ACK */
1075 break;
1076 case BSSGP_PDUT_RADIO_STATUS:
Harald Weltefde19ed2020-12-07 21:43:51 +01001077 DEBUGP(DLBSSGP, "BSSGP BVCI=%u Rx RADIO STATUS\n", bctx->bvci);
Harald Welte9ba50052010-03-14 15:45:01 +08001078 /* BSS informs us of some exception */
Harald Welte6b7cf252010-05-13 19:41:31 +02001079 /* FIXME: send GMM_RADIO_STATUS.ind to GMM */
Harald Welte9ba50052010-03-14 15:45:01 +08001080 break;
Harald Welte9ba50052010-03-14 15:45:01 +08001081 case BSSGP_PDUT_FLOW_CONTROL_BVC:
1082 /* BSS informs us of available bandwidth in Gb interface */
Harald Welte25de8112010-05-13 21:26:28 +02001083 rc = bssgp_rx_fc_bvc(msg, tp, bctx);
Harald Welte9ba50052010-03-14 15:45:01 +08001084 break;
1085 case BSSGP_PDUT_FLOW_CONTROL_MS:
1086 /* BSS informs us of available bandwidth to one MS */
Harald Weltefde19ed2020-12-07 21:43:51 +01001087 DEBUGP(DLBSSGP, "BSSGP BVCI=%u Rx Flow Control MS\n",
Harald Weltee9686b62010-05-31 18:07:17 +02001088 bctx->bvci);
Harald Welte30bc19a2010-05-02 11:19:37 +02001089 /* FIXME: actually implement flow control */
1090 /* FIXME: Send FLOW_CONTROL_MS_ACK */
Harald Welte9ba50052010-03-14 15:45:01 +08001091 break;
Harald Welte9ba50052010-03-14 15:45:01 +08001092 case BSSGP_PDUT_STATUS:
Jacob Erlbeck36153dc2015-03-17 10:21:17 +01001093 /* This is already handled in bssgp_rcvmsg() */
Jacob Erlbeck49ed9be2015-03-17 10:21:16 +01001094 break;
Harald Welte9ba50052010-03-14 15:45:01 +08001095 case BSSGP_PDUT_DOWNLOAD_BSS_PFC:
1096 case BSSGP_PDUT_CREATE_BSS_PFC_ACK:
1097 case BSSGP_PDUT_CREATE_BSS_PFC_NACK:
1098 case BSSGP_PDUT_MODIFY_BSS_PFC:
1099 case BSSGP_PDUT_DELETE_BSS_PFC_ACK:
Harald Weltefde19ed2020-12-07 21:43:51 +01001100 DEBUGP(DLBSSGP, "BSSGP BVCI=%u Rx PDU type %s not [yet] "
Max2c34ab42016-03-17 15:42:26 +01001101 "implemented\n", bctx->bvci, bssgp_pdu_str(pdu_type));
Harald Welte25de8112010-05-13 21:26:28 +02001102 rc = bssgp_tx_status(BSSGP_CAUSE_PDU_INCOMP_FEAT, NULL, msg);
Harald Welte9ba50052010-03-14 15:45:01 +08001103 break;
1104 /* those only exist in the SGSN -> BSS direction */
1105 case BSSGP_PDUT_DL_UNITDATA:
1106 case BSSGP_PDUT_PAGING_PS:
1107 case BSSGP_PDUT_PAGING_CS:
1108 case BSSGP_PDUT_RA_CAPA_UPDATE_ACK:
Harald Welte25de8112010-05-13 21:26:28 +02001109 case BSSGP_PDUT_FLOW_CONTROL_BVC_ACK:
1110 case BSSGP_PDUT_FLOW_CONTROL_MS_ACK:
Harald Weltefde19ed2020-12-07 21:43:51 +01001111 DEBUGP(DLBSSGP, "BSSGP BVCI=%u PDU type %s only exists in DL\n",
Max2c34ab42016-03-17 15:42:26 +01001112 bctx->bvci, bssgp_pdu_str(pdu_type));
Harald Welte25de8112010-05-13 21:26:28 +02001113 bssgp_tx_status(BSSGP_CAUSE_PROTO_ERR_UNSPEC, NULL, msg);
1114 rc = -EINVAL;
1115 break;
1116 default:
Harald Weltefde19ed2020-12-07 21:43:51 +01001117 DEBUGP(DLBSSGP, "BSSGP BVCI=%u PDU type %s unknown\n",
Max2c34ab42016-03-17 15:42:26 +01001118 bctx->bvci, bssgp_pdu_str(pdu_type));
Harald Welte25de8112010-05-13 21:26:28 +02001119 rc = bssgp_tx_status(BSSGP_CAUSE_PROTO_ERR_UNSPEC, NULL, msg);
1120 break;
1121 }
1122
Holger Hans Peter Freytherd30cefa2010-05-23 21:12:15 +08001123 return rc;
Harald Welte25de8112010-05-13 21:26:28 +02001124}
1125
1126/* Receive a BSSGP PDU from a BSS on a SIGNALLING BVCI */
Harald Weltede4599c2012-06-17 13:04:02 +08001127static int bssgp_rx_sign(struct msgb *msg, struct tlv_parsed *tp,
1128 struct bssgp_bvc_ctx *bctx)
Harald Welte25de8112010-05-13 21:26:28 +02001129{
1130 struct bssgp_normal_hdr *bgph =
1131 (struct bssgp_normal_hdr *) msgb_bssgph(msg);
1132 uint8_t pdu_type = bgph->pdu_type;
1133 int rc = 0;
1134 uint16_t ns_bvci = msgb_bvci(msg);
Jacob Erlbeckb43baf22014-09-10 12:43:28 +02001135 uint16_t bvci = bctx ? bctx->bvci : ns_bvci;
Harald Welte25de8112010-05-13 21:26:28 +02001136
1137 switch (bgph->pdu_type) {
1138 case BSSGP_PDUT_SUSPEND:
1139 /* MS wants to suspend */
Jacob Erlbeckb43baf22014-09-10 12:43:28 +02001140 rc = bssgp_rx_suspend(msg, tp);
Harald Welte25de8112010-05-13 21:26:28 +02001141 break;
1142 case BSSGP_PDUT_RESUME:
1143 /* MS wants to resume */
Jacob Erlbeckb43baf22014-09-10 12:43:28 +02001144 rc = bssgp_rx_resume(msg, tp);
Harald Welte25de8112010-05-13 21:26:28 +02001145 break;
1146 case BSSGP_PDUT_FLUSH_LL_ACK:
1147 /* BSS informs us it has performed LL FLUSH */
Harald Weltefde19ed2020-12-07 21:43:51 +01001148 DEBUGP(DLBSSGP, "BSSGP Rx BVCI=%u FLUSH LL ACK\n", bvci);
Harald Welte25de8112010-05-13 21:26:28 +02001149 /* FIXME: send NM_FLUSH_LL.res to NM */
1150 break;
1151 case BSSGP_PDUT_LLC_DISCARD:
1152 /* BSS informs that some LLC PDU's have been discarded */
Jacob Erlbeckb43baf22014-09-10 12:43:28 +02001153 if (!bctx) {
Harald Weltefde19ed2020-12-07 21:43:51 +01001154 LOGP(DLBSSGP, LOGL_ERROR,
Jacob Erlbeckb43baf22014-09-10 12:43:28 +02001155 "BSSGP Rx LLC-DISCARD missing mandatory BVCI\n");
1156 goto err_mand_ie;
1157 }
Harald Weltee9686b62010-05-31 18:07:17 +02001158 rc = bssgp_rx_llc_disc(msg, tp, bctx);
Harald Welte25de8112010-05-13 21:26:28 +02001159 break;
1160 case BSSGP_PDUT_BVC_BLOCK:
1161 /* BSS tells us that BVC shall be blocked */
Harald Welte2d9ce712020-12-03 15:53:59 +01001162 if (!TLVP_PRES_LEN(tp, BSSGP_IE_BVCI, 2) ||
1163 !TLVP_PRES_LEN(tp, BSSGP_IE_CAUSE, 1)) {
Harald Weltefde19ed2020-12-07 21:43:51 +01001164 LOGP(DLBSSGP, LOGL_ERROR, "BSSGP Rx BVC-BLOCK "
Harald Weltee9686b62010-05-31 18:07:17 +02001165 "missing mandatory IE\n");
Harald Welte25de8112010-05-13 21:26:28 +02001166 goto err_mand_ie;
Harald Weltee9686b62010-05-31 18:07:17 +02001167 }
Harald Welte2677ea52010-05-31 17:16:36 +02001168 rc = bssgp_rx_bvc_block(msg, tp);
Harald Welte25de8112010-05-13 21:26:28 +02001169 break;
1170 case BSSGP_PDUT_BVC_UNBLOCK:
1171 /* BSS tells us that BVC shall be unblocked */
Harald Welte2d9ce712020-12-03 15:53:59 +01001172 if (!TLVP_PRES_LEN(tp, BSSGP_IE_BVCI, 2)) {
Harald Weltefde19ed2020-12-07 21:43:51 +01001173 LOGP(DLBSSGP, LOGL_ERROR, "BSSGP Rx BVC-UNBLOCK "
Harald Weltee9686b62010-05-31 18:07:17 +02001174 "missing mandatory IE\n");
Harald Welte25de8112010-05-13 21:26:28 +02001175 goto err_mand_ie;
Harald Weltee9686b62010-05-31 18:07:17 +02001176 }
Harald Welte25de8112010-05-13 21:26:28 +02001177 rc = bssgp_rx_bvc_unblock(msg, tp);
1178 break;
Max590c4022017-06-28 14:29:24 +02001179 case BSSGP_PDUT_BVC_RESET_ACK:
Harald Weltefde19ed2020-12-07 21:43:51 +01001180 LOGP(DLBSSGP, LOGL_ERROR, "BSSGP BVCI=%u Rx BVC-RESET-ACK\n", bvci);
Max590c4022017-06-28 14:29:24 +02001181 break;
Harald Welte25de8112010-05-13 21:26:28 +02001182 case BSSGP_PDUT_BVC_RESET:
1183 /* BSS tells us that BVC init is required */
Harald Welte2d9ce712020-12-03 15:53:59 +01001184 if (!TLVP_PRES_LEN(tp, BSSGP_IE_BVCI, 2) ||
1185 !TLVP_PRES_LEN(tp, BSSGP_IE_CAUSE, 1)) {
Harald Weltefde19ed2020-12-07 21:43:51 +01001186 LOGP(DLBSSGP, LOGL_ERROR, "BSSGP Rx BVC-RESET "
Harald Weltee9686b62010-05-31 18:07:17 +02001187 "missing mandatory IE\n");
Harald Welte25de8112010-05-13 21:26:28 +02001188 goto err_mand_ie;
Harald Weltee9686b62010-05-31 18:07:17 +02001189 }
Harald Welte25de8112010-05-13 21:26:28 +02001190 rc = bssgp_rx_bvc_reset(msg, tp, ns_bvci);
1191 break;
1192 case BSSGP_PDUT_STATUS:
Jacob Erlbeck36153dc2015-03-17 10:21:17 +01001193 /* This is already handled in bssgp_rcvmsg() */
Harald Welte25de8112010-05-13 21:26:28 +02001194 break;
Philipp Maier1eaa7bc2020-12-16 21:07:04 +01001195
1196 case BSSGP_PDUT_RAN_INFO:
1197 case BSSGP_PDUT_RAN_INFO_REQ:
1198 case BSSGP_PDUT_RAN_INFO_ACK:
1199 case BSSGP_PDUT_RAN_INFO_ERROR:
1200 case BSSGP_PDUT_RAN_INFO_APP_ERROR:
1201 bssgp_rx_rim(msg, tp, bvci);
1202 break;
1203
Harald Welte25de8112010-05-13 21:26:28 +02001204 /* those only exist in the SGSN -> BSS direction */
1205 case BSSGP_PDUT_PAGING_PS:
1206 case BSSGP_PDUT_PAGING_CS:
Harald Welte9ba50052010-03-14 15:45:01 +08001207 case BSSGP_PDUT_SUSPEND_ACK:
1208 case BSSGP_PDUT_SUSPEND_NACK:
1209 case BSSGP_PDUT_RESUME_ACK:
1210 case BSSGP_PDUT_RESUME_NACK:
Harald Welte6b7cf252010-05-13 19:41:31 +02001211 case BSSGP_PDUT_FLUSH_LL:
Harald Welte9ba50052010-03-14 15:45:01 +08001212 case BSSGP_PDUT_BVC_BLOCK_ACK:
1213 case BSSGP_PDUT_BVC_UNBLOCK_ACK:
1214 case BSSGP_PDUT_SGSN_INVOKE_TRACE:
Harald Weltefde19ed2020-12-07 21:43:51 +01001215 DEBUGP(DLBSSGP, "BSSGP BVCI=%u Rx PDU type %s only exists in DL\n",
Max2c34ab42016-03-17 15:42:26 +01001216 bvci, bssgp_pdu_str(pdu_type));
Harald Welte25de8112010-05-13 21:26:28 +02001217 bssgp_tx_status(BSSGP_CAUSE_PROTO_ERR_UNSPEC, NULL, msg);
Harald Welte9ba50052010-03-14 15:45:01 +08001218 rc = -EINVAL;
1219 break;
1220 default:
Harald Weltefde19ed2020-12-07 21:43:51 +01001221 DEBUGP(DLBSSGP, "BSSGP BVCI=%u Rx PDU type %s unknown\n",
Max2c34ab42016-03-17 15:42:26 +01001222 bvci, bssgp_pdu_str(pdu_type));
Harald Welte25de8112010-05-13 21:26:28 +02001223 rc = bssgp_tx_status(BSSGP_CAUSE_PROTO_ERR_UNSPEC, NULL, msg);
Harald Welte9ba50052010-03-14 15:45:01 +08001224 break;
1225 }
1226
1227 return rc;
1228err_mand_ie:
1229 return bssgp_tx_status(BSSGP_CAUSE_MISSING_MAND_IE, NULL, msg);
1230}
1231
Harald Welte25de8112010-05-13 21:26:28 +02001232/* We expect msgb_bssgph() to point to the BSSGP header */
Harald Weltede4599c2012-06-17 13:04:02 +08001233int bssgp_rcvmsg(struct msgb *msg)
Harald Welte25de8112010-05-13 21:26:28 +02001234{
1235 struct bssgp_normal_hdr *bgph =
1236 (struct bssgp_normal_hdr *) msgb_bssgph(msg);
1237 struct bssgp_ud_hdr *budh = (struct bssgp_ud_hdr *) msgb_bssgph(msg);
1238 struct tlv_parsed tp;
Harald Welte8a521132010-05-17 22:59:29 +02001239 struct bssgp_bvc_ctx *bctx;
Harald Welte25de8112010-05-13 21:26:28 +02001240 uint8_t pdu_type = bgph->pdu_type;
1241 uint16_t ns_bvci = msgb_bvci(msg);
Max548caef2019-03-07 13:49:34 +01001242 uint16_t nsei = msgb_nsei(msg);
Jacob Erlbeckb83b8382014-09-23 13:28:22 +02001243 uint16_t bvci = ns_bvci;
Harald Welte25de8112010-05-13 21:26:28 +02001244 int data_len;
1245 int rc = 0;
1246
1247 /* Identifiers from DOWN: NSEI, BVCI (both in msg->cb) */
1248
1249 /* UNITDATA BSSGP headers have TLLI in front */
1250 if (pdu_type != BSSGP_PDUT_UL_UNITDATA &&
1251 pdu_type != BSSGP_PDUT_DL_UNITDATA) {
1252 data_len = msgb_bssgp_len(msg) - sizeof(*bgph);
1253 rc = bssgp_tlv_parse(&tp, bgph->data, data_len);
1254 } else {
1255 data_len = msgb_bssgp_len(msg) - sizeof(*budh);
1256 rc = bssgp_tlv_parse(&tp, budh->data, data_len);
1257 }
Stefan Sperling2b544b22018-06-25 12:20:43 +02001258 if (rc < 0) {
Harald Weltefde19ed2020-12-07 21:43:51 +01001259 LOGP(DLBSSGP, LOGL_ERROR, "Failed to parse BSSGP %s message. Invalid message was: %s\n",
Stefan Sperling2b544b22018-06-25 12:20:43 +02001260 bssgp_pdu_str(pdu_type), msgb_hexdump(msg));
Stefan Sperlingf1e13d62018-06-25 12:20:43 +02001261 if (pdu_type != BSSGP_PDUT_STATUS)
1262 return bssgp_tx_status(BSSGP_CAUSE_INV_MAND_INF, NULL, msg);
Stefan Sperling2b544b22018-06-25 12:20:43 +02001263 return rc;
1264 }
Harald Welte25de8112010-05-13 21:26:28 +02001265
Harald Welte2d9ce712020-12-03 15:53:59 +01001266 if (bvci == BVCI_SIGNALLING && TLVP_PRES_LEN(&tp, BSSGP_IE_BVCI, 2))
Harald Weltebfe62e52017-05-15 12:48:30 +02001267 bvci = tlvp_val16be(&tp, BSSGP_IE_BVCI);
Jacob Erlbeckb83b8382014-09-23 13:28:22 +02001268
Harald Welte25de8112010-05-13 21:26:28 +02001269 /* look-up or create the BTS context for this BVC */
Max548caef2019-03-07 13:49:34 +01001270 bctx = btsctx_by_bvci_nsei(bvci, nsei);
Harald Welte25de8112010-05-13 21:26:28 +02001271
Harald Welte16c8dbb2010-05-17 23:30:01 +02001272 if (bctx) {
Neels Hofmeyr8b86cd72017-02-23 18:03:28 +01001273 log_set_context(LOG_CTX_GB_BVC, bctx);
Harald Welte16c8dbb2010-05-17 23:30:01 +02001274 rate_ctr_inc(&bctx->ctrg->ctr[BSSGP_CTR_PKTS_IN]);
1275 rate_ctr_add(&bctx->ctrg->ctr[BSSGP_CTR_BYTES_IN],
1276 msgb_bssgp_len(msg));
1277 }
1278
Jacob Erlbeck36153dc2015-03-17 10:21:17 +01001279 /* Always handle STATUS PDUs, even if they contain an invalid BVCI or
1280 * are otherwise unexpected */
1281 if (pdu_type == BSSGP_PDUT_STATUS)
1282 /* Some exception has occurred */
1283 return bssgp_rx_status(msg, &tp, bvci, bctx);
1284
1285 /* Only a RESET PDU can create a new BVC context, otherwise it must be
1286 * registered if a BVCI is given. */
1287 if (!bctx && bvci != BVCI_SIGNALLING &&
1288 pdu_type != BSSGP_PDUT_BVC_RESET) {
Harald Weltefde19ed2020-12-07 21:43:51 +01001289 LOGP(DLBSSGP, LOGL_NOTICE, "NSEI=%u/BVCI=%u Rejecting PDU type %s for unknown BVCI\n", nsei, bvci,
Max2c34ab42016-03-17 15:42:26 +01001290 bssgp_pdu_str(pdu_type));
Jacob Erlbeck36153dc2015-03-17 10:21:17 +01001291 return bssgp_tx_status(BSSGP_CAUSE_UNKNOWN_BVCI, &bvci, msg);
1292 }
1293
Harald Welte61c07842010-05-18 11:57:08 +02001294 if (ns_bvci == BVCI_SIGNALLING)
Harald Weltede4599c2012-06-17 13:04:02 +08001295 rc = bssgp_rx_sign(msg, &tp, bctx);
Harald Welte61c07842010-05-18 11:57:08 +02001296 else if (ns_bvci == BVCI_PTM)
Harald Welte25de8112010-05-13 21:26:28 +02001297 rc = bssgp_tx_status(BSSGP_CAUSE_PDU_INCOMP_FEAT, NULL, msg);
Jacob Erlbeckb535e392015-04-07 17:52:44 +02001298 else if (bctx)
Harald Weltede4599c2012-06-17 13:04:02 +08001299 rc = bssgp_rx_ptp(msg, &tp, bctx);
Jacob Erlbeckb535e392015-04-07 17:52:44 +02001300 else
Harald Weltefde19ed2020-12-07 21:43:51 +01001301 LOGP(DLBSSGP, LOGL_NOTICE,
Max548caef2019-03-07 13:49:34 +01001302 "NSEI=%u/BVCI=%u Cannot handle PDU type %s for unknown BVCI, NS BVCI %u\n", nsei, bvci,
1303 bssgp_pdu_str(pdu_type), ns_bvci);
Harald Welte25de8112010-05-13 21:26:28 +02001304
1305 return rc;
1306}
1307
Harald Weltede4599c2012-06-17 13:04:02 +08001308int bssgp_tx_dl_ud(struct msgb *msg, uint16_t pdu_lifetime,
1309 struct bssgp_dl_ud_par *dup)
Harald Welte9ba50052010-03-14 15:45:01 +08001310{
Harald Welte8a521132010-05-17 22:59:29 +02001311 struct bssgp_bvc_ctx *bctx;
Harald Welte9ba50052010-03-14 15:45:01 +08001312 struct bssgp_ud_hdr *budh;
Harald Welte8f9a3ee2010-05-02 11:26:34 +02001313 uint8_t llc_pdu_tlv_hdr_len = 2;
Harald Welte8ef54d12012-06-17 09:31:16 +08001314 uint8_t *llc_pdu_tlv;
Harald Welte8f9a3ee2010-05-02 11:26:34 +02001315 uint16_t msg_len = msg->len;
Harald Welte30bc19a2010-05-02 11:19:37 +02001316 uint16_t bvci = msgb_bvci(msg);
1317 uint16_t nsei = msgb_nsei(msg);
Harald Weltebfe62e52017-05-15 12:48:30 +02001318 uint16_t _pdu_lifetime = osmo_htons(pdu_lifetime); /* centi-seconds */
Harald Welte2f946832010-05-31 22:12:30 +02001319 uint16_t drx_params;
Harald Welte9ba50052010-03-14 15:45:01 +08001320
Jacob Erlbeckc6415912015-04-07 17:52:43 +02001321 OSMO_ASSERT(dup != NULL);
1322
Harald Welte30bc19a2010-05-02 11:19:37 +02001323 /* Identifiers from UP: TLLI, BVCI, NSEI (all in msgb->cb) */
Harald Welte61c07842010-05-18 11:57:08 +02001324 if (bvci <= BVCI_PTM ) {
Harald Weltefde19ed2020-12-07 21:43:51 +01001325 LOGP(DLBSSGP, LOGL_ERROR, "Cannot send DL-UD to BVCI %u\n",
Harald Welte30bc19a2010-05-02 11:19:37 +02001326 bvci);
Holger Hans Peter Freyther10dd73c2014-10-10 17:24:34 +02001327 msgb_free(msg);
Harald Welte30bc19a2010-05-02 11:19:37 +02001328 return -EINVAL;
1329 }
1330
1331 bctx = btsctx_by_bvci_nsei(bvci, nsei);
Harald Welte25de8112010-05-13 21:26:28 +02001332 if (!bctx) {
Harald Weltefde19ed2020-12-07 21:43:51 +01001333 LOGP(DLBSSGP, LOGL_ERROR, "Cannot send DL-UD to unknown BVCI %u\n",
Harald Welted11c0592012-09-06 21:57:11 +02001334 bvci);
Holger Hans Peter Freyther10dd73c2014-10-10 17:24:34 +02001335 msgb_free(msg);
Harald Welted11c0592012-09-06 21:57:11 +02001336 return -ENODEV;
Harald Welte25de8112010-05-13 21:26:28 +02001337 }
Harald Welte9ba50052010-03-14 15:45:01 +08001338
1339 if (msg->len > TVLV_MAX_ONEBYTE)
1340 llc_pdu_tlv_hdr_len += 1;
1341
1342 /* prepend the tag and length of the LLC-PDU TLV */
1343 llc_pdu_tlv = msgb_push(msg, llc_pdu_tlv_hdr_len);
1344 llc_pdu_tlv[0] = BSSGP_IE_LLC_PDU;
1345 if (llc_pdu_tlv_hdr_len > 2) {
1346 llc_pdu_tlv[1] = msg_len >> 8;
1347 llc_pdu_tlv[2] = msg_len & 0xff;
1348 } else {
Sylvain Munautb00d1ad2010-06-09 21:13:13 +02001349 llc_pdu_tlv[1] = msg_len & 0x7f;
Harald Welte9ba50052010-03-14 15:45:01 +08001350 llc_pdu_tlv[1] |= 0x80;
1351 }
1352
Harald Welte2f946832010-05-31 22:12:30 +02001353 /* FIXME: optional elements: Alignment, UTRAN CCO, LSA, PFI */
1354
Jacob Erlbeckc6415912015-04-07 17:52:43 +02001355 /* Old TLLI to help BSS map from old->new */
1356 if (dup->tlli) {
Harald Weltebfe62e52017-05-15 12:48:30 +02001357 uint32_t tlli = osmo_htonl(*dup->tlli);
Jacob Erlbeckc6415912015-04-07 17:52:43 +02001358 msgb_tvlv_push(msg, BSSGP_IE_TLLI, 4, (uint8_t *) &tlli);
Harald Welte2f946832010-05-31 22:12:30 +02001359 }
Harald Welte9ba50052010-03-14 15:45:01 +08001360
Jacob Erlbeckc6415912015-04-07 17:52:43 +02001361 /* IMSI */
1362 if (dup->imsi && strlen(dup->imsi)) {
Harald Weltea13fb752020-06-16 08:44:42 +02001363 uint8_t mi[GSM48_MID_MAX_SIZE];
1364/* gsm48_generate_mid_from_imsi() is guaranteed to never return more than 11,
1365 * but somehow gcc (8.2) is not smart enough to figure this out and claims that
1366 * the memcpy in msgb_tvlv_put() below will cause and out-of-bounds access up to
1367 * mi[131], which is wrong */
1368#pragma GCC diagnostic push
1369#pragma GCC diagnostic ignored "-Warray-bounds"
1370 int imsi_len = gsm48_generate_mid_from_imsi(mi, dup->imsi);
1371 OSMO_ASSERT(imsi_len <= GSM48_MID_MAX_SIZE);
1372 if (imsi_len > 2)
1373 msgb_tvlv_push(msg, BSSGP_IE_IMSI,
1374 imsi_len-2, mi+2);
1375#pragma GCC diagnostic pop
Jacob Erlbeckc6415912015-04-07 17:52:43 +02001376 }
1377
1378 /* DRX parameters */
Harald Weltebfe62e52017-05-15 12:48:30 +02001379 drx_params = osmo_htons(dup->drx_parms);
Jacob Erlbeckc6415912015-04-07 17:52:43 +02001380 msgb_tvlv_push(msg, BSSGP_IE_DRX_PARAMS, 2,
1381 (uint8_t *) &drx_params);
1382
1383 /* FIXME: Priority */
1384
1385 /* MS Radio Access Capability */
1386 if (dup->ms_ra_cap.len)
1387 msgb_tvlv_push(msg, BSSGP_IE_MS_RADIO_ACCESS_CAP,
1388 dup->ms_ra_cap.len, dup->ms_ra_cap.v);
1389
Harald Welte9ba50052010-03-14 15:45:01 +08001390 /* prepend the pdu lifetime */
Harald Welte8ef54d12012-06-17 09:31:16 +08001391 msgb_tvlv_push(msg, BSSGP_IE_PDU_LIFETIME, 2, (uint8_t *)&_pdu_lifetime);
Harald Welte9ba50052010-03-14 15:45:01 +08001392
1393 /* prepend the QoS profile, TLLI and pdu type */
1394 budh = (struct bssgp_ud_hdr *) msgb_push(msg, sizeof(*budh));
Harald Welte8ef54d12012-06-17 09:31:16 +08001395 memcpy(budh->qos_profile, dup->qos_profile, sizeof(budh->qos_profile));
Harald Weltebfe62e52017-05-15 12:48:30 +02001396 budh->tlli = osmo_htonl(msgb_tlli(msg));
Harald Welte9ba50052010-03-14 15:45:01 +08001397 budh->pdu_type = BSSGP_PDUT_DL_UNITDATA;
1398
Harald Welte16c8dbb2010-05-17 23:30:01 +02001399 rate_ctr_inc(&bctx->ctrg->ctr[BSSGP_CTR_PKTS_OUT]);
1400 rate_ctr_add(&bctx->ctrg->ctr[BSSGP_CTR_BYTES_OUT], msg->len);
1401
Harald Welte30bc19a2010-05-02 11:19:37 +02001402 /* Identifiers down: BVCI, NSEI (in msgb->cb) */
Harald Welte24a655f2010-04-30 19:54:29 +02001403
Harald Welted11c0592012-09-06 21:57:11 +02001404 /* check if we have to go through per-ms flow control or can go
1405 * directly to the per-BSS flow control */
1406 if (dup->fc)
Harald Welted8b47692012-09-07 11:29:32 +02001407 return bssgp_fc_in(dup->fc, msg, msg_len, bctx->fc);
Harald Welted11c0592012-09-06 21:57:11 +02001408 else
Harald Welted8b47692012-09-07 11:29:32 +02001409 return bssgp_fc_in(bctx->fc, msg, msg_len, NULL);
Harald Welte9ba50052010-03-14 15:45:01 +08001410}
Harald Welte68b4f032010-06-09 16:22:28 +02001411
1412/* Send a single GMM-PAGING.req to a given NSEI/NS-BVCI */
Harald Weltede4599c2012-06-17 13:04:02 +08001413int bssgp_tx_paging(uint16_t nsei, uint16_t ns_bvci,
1414 struct bssgp_paging_info *pinfo)
Harald Welte68b4f032010-06-09 16:22:28 +02001415{
1416 struct msgb *msg = bssgp_msgb_alloc();
1417 struct bssgp_normal_hdr *bgph =
1418 (struct bssgp_normal_hdr *) msgb_put(msg, sizeof(*bgph));
Harald Weltebfe62e52017-05-15 12:48:30 +02001419 uint16_t drx_params = osmo_htons(pinfo->drx_params);
Harald Weltea13fb752020-06-16 08:44:42 +02001420 uint8_t mi[GSM48_MID_MAX_SIZE];
1421 int imsi_len = gsm48_generate_mid_from_imsi(mi, pinfo->imsi);
Maxf1ad60e2018-01-05 14:19:33 +01001422 struct gsm48_ra_id ra;
Harald Weltea13fb752020-06-16 08:44:42 +02001423
1424 if (imsi_len < 2)
1425 return -EINVAL;
Harald Welte68b4f032010-06-09 16:22:28 +02001426
1427 msgb_nsei(msg) = nsei;
1428 msgb_bvci(msg) = ns_bvci;
1429
1430 if (pinfo->mode == BSSGP_PAGING_PS)
1431 bgph->pdu_type = BSSGP_PDUT_PAGING_PS;
1432 else
1433 bgph->pdu_type = BSSGP_PDUT_PAGING_CS;
1434 /* IMSI */
Harald Weltea13fb752020-06-16 08:44:42 +02001435/* gsm48_generate_mid_from_imsi() is guaranteed to never return more than 11,
1436 * but somehow gcc (8.2) is not smart enough to figure this out and claims that
1437 * the memcpy in msgb_tvlv_put() below will cause and out-of-bounds access up to
1438 * mi[131], which is wrong */
1439#pragma GCC diagnostic push
1440#pragma GCC diagnostic ignored "-Warray-bounds"
1441 OSMO_ASSERT(imsi_len <= GSM48_MID_MAX_SIZE);
1442 msgb_tvlv_put(msg, BSSGP_IE_IMSI, imsi_len-2, mi+2);
1443#pragma GCC diagnostic pop
Harald Welte68b4f032010-06-09 16:22:28 +02001444 /* DRX Parameters */
1445 msgb_tvlv_put(msg, BSSGP_IE_DRX_PARAMS, 2,
1446 (uint8_t *) &drx_params);
1447 /* Scope */
1448 switch (pinfo->scope) {
1449 case BSSGP_PAGING_BSS_AREA:
1450 {
1451 uint8_t null = 0;
1452 msgb_tvlv_put(msg, BSSGP_IE_BSS_AREA_ID, 1, &null);
1453 }
1454 break;
1455 case BSSGP_PAGING_LOCATION_AREA:
Maxf1ad60e2018-01-05 14:19:33 +01001456 gsm48_encode_ra(&ra, &pinfo->raid);
1457 msgb_tvlv_put(msg, BSSGP_IE_LOCATION_AREA, 4, (const uint8_t *)&ra);
Harald Welte68b4f032010-06-09 16:22:28 +02001458 break;
1459 case BSSGP_PAGING_ROUTEING_AREA:
Maxf1ad60e2018-01-05 14:19:33 +01001460 bssgp_msgb_ra_put(msg, &pinfo->raid);
Harald Welte68b4f032010-06-09 16:22:28 +02001461 break;
1462 case BSSGP_PAGING_BVCI:
1463 {
Harald Weltebfe62e52017-05-15 12:48:30 +02001464 uint16_t bvci = osmo_htons(pinfo->bvci);
Harald Welte68b4f032010-06-09 16:22:28 +02001465 msgb_tvlv_put(msg, BSSGP_IE_BVCI, 2, (uint8_t *)&bvci);
1466 }
1467 break;
1468 }
1469 /* QoS profile mandatory for PS */
1470 if (pinfo->mode == BSSGP_PAGING_PS)
1471 msgb_tvlv_put(msg, BSSGP_IE_QOS_PROFILE, 3, pinfo->qos);
1472
1473 /* Optional (P-)TMSI */
1474 if (pinfo->ptmsi) {
Harald Weltebfe62e52017-05-15 12:48:30 +02001475 uint32_t ptmsi = osmo_htonl(*pinfo->ptmsi);
Harald Welte68b4f032010-06-09 16:22:28 +02001476 msgb_tvlv_put(msg, BSSGP_IE_TMSI, 4, (uint8_t *) &ptmsi);
1477 }
1478
Alexander Couzens85a8fd32020-07-18 15:57:07 +02001479 return bssgp_ns_send(bssgp_ns_send_data, msg);
Harald Welte68b4f032010-06-09 16:22:28 +02001480}
Harald Weltecca49632012-06-16 17:45:59 +08001481
Harald Weltede4599c2012-06-17 13:04:02 +08001482void bssgp_set_log_ss(int ss)
Harald Weltecca49632012-06-16 17:45:59 +08001483{
Pau Espin Pedrol0e617162020-12-10 13:38:42 +01001484 /* BSSGP has moved from DGPRS to DLGPRS, please update your code if it's
1485 * still calling this function
1486 */
Harald Weltecca49632012-06-16 17:45:59 +08001487}
Alexander Couzensacc0a072018-08-07 11:22:28 +02001488
1489/*!
1490 * \brief Flush the queue of the bssgp_flow_control
1491 * \param[in] The flow control object which holds the queue.
1492 */
1493void bssgp_fc_flush_queue(struct bssgp_flow_control *fc)
1494{
1495 struct bssgp_fc_queue_element *element, *tmp;
1496
1497 llist_for_each_entry_safe(element, tmp, &fc->queue, list) {
1498 msgb_free(element->msg);
1499 llist_del(&element->list);
1500 talloc_free(element);
1501 }
1502}
1503
1504/*!
1505 * \brief Flush the queues of all BSSGP contexts.
1506 */
1507void bssgp_flush_all_queues()
1508{
1509 struct bssgp_bvc_ctx *bctx;
1510
1511 llist_for_each_entry(bctx, &bssgp_bvc_ctxts, list) {
1512 if (bctx->fc)
1513 bssgp_fc_flush_queue(bctx->fc);
1514 }
1515}