blob: 300c0ede1121d2058c05445b7b380c7afb3c641c [file] [log] [blame]
Neels Hofmeyr17518fe2017-06-20 04:35:06 +02001/*! \file gsm0480.c
2 * Format functions for GSM 04.80. */
Holger Hans Peter Freyther55aea502010-09-30 18:30:41 +08003/*
4 * (C) 2010 by Holger Hans Peter Freyther <zecke@selfish.org>
5 * (C) 2009 by Mike Haben <michael.haben@btinternet.com>
6 *
7 * All Rights Reserved
8 *
Harald Weltee08da972017-11-13 01:00:26 +09009 * SPDX-License-Identifier: GPL-2.0+
10 *
Holger Hans Peter Freyther55aea502010-09-30 18:30:41 +080011 * This program is free software; you can redistribute it and/or modify
12 * it under the terms of the GNU General Public License as published by
13 * the Free Software Foundation; either version 2 of the License, or
14 * (at your option) any later version.
15 *
16 * This program is distributed in the hope that it will be useful,
17 * but WITHOUT ANY WARRANTY; without even the implied warranty of
18 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
19 * GNU General Public License for more details.
20 *
21 * You should have received a copy of the GNU General Public License along
22 * with this program; if not, write to the Free Software Foundation, Inc.,
23 * 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
24 *
25 */
26
Pablo Neira Ayuso83419342011-03-22 16:36:13 +010027#include <osmocom/gsm/gsm0480.h>
28#include <osmocom/gsm/gsm_utils.h>
Holger Hans Peter Freyther55aea502010-09-30 18:30:41 +080029
Pablo Neira Ayuso83419342011-03-22 16:36:13 +010030#include <osmocom/core/logging.h>
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +080031
Pablo Neira Ayuso83419342011-03-22 16:36:13 +010032#include <osmocom/gsm/protocol/gsm_04_08.h>
33#include <osmocom/gsm/protocol/gsm_04_80.h>
Holger Hans Peter Freyther55aea502010-09-30 18:30:41 +080034
35#include <string.h>
Vadim Yanitskiy52e44122018-06-11 03:51:11 +070036#include <errno.h>
Holger Hans Peter Freyther55aea502010-09-30 18:30:41 +080037
38static inline unsigned char *msgb_wrap_with_TL(struct msgb *msgb, uint8_t tag)
39{
40 uint8_t *data = msgb_push(msgb, 2);
41
42 data[0] = tag;
43 data[1] = msgb->len - 2;
44 return data;
45}
46
47static inline unsigned char *msgb_push_TLV1(struct msgb *msgb, uint8_t tag,
48 uint8_t value)
49{
50 uint8_t *data = msgb_push(msgb, 3);
51
52 data[0] = tag;
53 data[1] = 1;
54 data[2] = value;
55 return data;
56}
57
58/* wrap an invoke around it... the other way around
59 *
60 * 1.) Invoke Component tag
61 * 2.) Invoke ID Tag
62 * 3.) Operation
63 * 4.) Data
64 */
65int gsm0480_wrap_invoke(struct msgb *msg, int op, int link_id)
66{
67 /* 3. operation */
68 msgb_push_TLV1(msg, GSM0480_OPERATION_CODE, op);
69
70 /* 2. invoke id tag */
71 msgb_push_TLV1(msg, GSM0480_COMPIDTAG_INVOKE_ID, link_id);
72
73 /* 1. component tag */
74 msgb_wrap_with_TL(msg, GSM0480_CTYPE_INVOKE);
75
76 return 0;
77}
78
79/* wrap the GSM 04.08 Facility IE around it */
80int gsm0480_wrap_facility(struct msgb *msg)
81{
82 msgb_wrap_with_TL(msg, GSM0480_IE_FACILITY);
83
84 return 0;
85}
86
87struct msgb *gsm0480_create_unstructuredSS_Notify(int alertPattern, const char *text)
88{
89 struct msgb *msg;
90 uint8_t *seq_len_ptr, *ussd_len_ptr, *data;
Holger Hans Peter Freyther47aa4822013-07-07 13:54:53 +020091 int len;
Holger Hans Peter Freyther55aea502010-09-30 18:30:41 +080092
93 msg = msgb_alloc_headroom(1024, 128, "GSM 04.80");
94 if (!msg)
95 return NULL;
96
97 /* SEQUENCE { */
98 msgb_put_u8(msg, GSM_0480_SEQUENCE_TAG);
99 seq_len_ptr = msgb_put(msg, 1);
100
101 /* DCS { */
102 msgb_put_u8(msg, ASN1_OCTET_STRING_TAG);
103 msgb_put_u8(msg, 1);
104 msgb_put_u8(msg, 0x0F);
105 /* } DCS */
106
107 /* USSD-String { */
108 msgb_put_u8(msg, ASN1_OCTET_STRING_TAG);
109 ussd_len_ptr = msgb_put(msg, 1);
110 data = msgb_put(msg, 0);
Jacob Erlbeck1d7f3b52013-08-12 17:07:53 +0200111 gsm_7bit_encode_n_ussd(data, msgb_tailroom(msg), text, &len);
Holger Hans Peter Freyther47aa4822013-07-07 13:54:53 +0200112 msgb_put(msg, len);
113 ussd_len_ptr[0] = len;
Holger Hans Peter Freyther55aea502010-09-30 18:30:41 +0800114 /* USSD-String } */
115
116 /* alertingPattern { */
117 msgb_put_u8(msg, ASN1_OCTET_STRING_TAG);
118 msgb_put_u8(msg, 1);
119 msgb_put_u8(msg, alertPattern);
120 /* } alertingPattern */
121
122 seq_len_ptr[0] = 3 + 2 + ussd_len_ptr[0] + 3;
123 /* } SEQUENCE */
124
125 return msg;
126}
127
128struct msgb *gsm0480_create_notifySS(const char *text)
129{
130 struct msgb *msg;
131 uint8_t *data, *tmp_len;
132 uint8_t *seq_len_ptr, *cal_len_ptr, *opt_len_ptr, *nam_len_ptr;
Holger Hans Peter Freyther47aa4822013-07-07 13:54:53 +0200133 int len;
Holger Hans Peter Freyther55aea502010-09-30 18:30:41 +0800134
135 len = strlen(text);
136 if (len < 1 || len > 160)
137 return NULL;
138
139 msg = msgb_alloc_headroom(1024, 128, "GSM 04.80");
140 if (!msg)
141 return NULL;
142
143 msgb_put_u8(msg, GSM_0480_SEQUENCE_TAG);
144 seq_len_ptr = msgb_put(msg, 1);
145
146 /* ss_code for CNAP { */
147 msgb_put_u8(msg, 0x81);
148 msgb_put_u8(msg, 1);
149 msgb_put_u8(msg, 0x19);
150 /* } ss_code */
151
152
153 /* nameIndicator { */
154 msgb_put_u8(msg, 0xB4);
155 nam_len_ptr = msgb_put(msg, 1);
156
157 /* callingName { */
158 msgb_put_u8(msg, 0xA0);
159 opt_len_ptr = msgb_put(msg, 1);
160 msgb_put_u8(msg, 0xA0);
161 cal_len_ptr = msgb_put(msg, 1);
162
163 /* namePresentationAllowed { */
164 /* add the DCS value */
165 msgb_put_u8(msg, 0x80);
166 msgb_put_u8(msg, 1);
167 msgb_put_u8(msg, 0x0F);
168
169 /* add the lengthInCharacters */
170 msgb_put_u8(msg, 0x81);
171 msgb_put_u8(msg, 1);
172 msgb_put_u8(msg, strlen(text));
173
174 /* add the actual string */
175 msgb_put_u8(msg, 0x82);
176 tmp_len = msgb_put(msg, 1);
177 data = msgb_put(msg, 0);
Jacob Erlbeck1d7f3b52013-08-12 17:07:53 +0200178 gsm_7bit_encode_n_ussd(data, msgb_tailroom(msg), text, &len);
Holger Hans Peter Freyther47aa4822013-07-07 13:54:53 +0200179 tmp_len[0] = len;
180 msgb_put(msg, len);
Holger Hans Peter Freyther55aea502010-09-30 18:30:41 +0800181
182 /* }; namePresentationAllowed */
183
Holger Hans Peter Freyther47aa4822013-07-07 13:54:53 +0200184 cal_len_ptr[0] = 3 + 3 + 2 + len;
Holger Hans Peter Freyther55aea502010-09-30 18:30:41 +0800185 opt_len_ptr[0] = cal_len_ptr[0] + 2;
186 /* }; callingName */
187
188 nam_len_ptr[0] = opt_len_ptr[0] + 2;
189 /* ); nameIndicator */
190
191 /* write the lengths... */
192 seq_len_ptr[0] = 3 + nam_len_ptr[0] + 2;
193
194 return msg;
195}
196
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800197/* Forward declarations */
Tobias Engel419684e2012-03-08 13:31:52 +0100198static int parse_ss(const struct gsm48_hdr *hdr,
199 uint16_t len, struct ss_request *req);
Vadim Yanitskiyc30431f2017-07-29 04:47:42 +0600200static int parse_ss_facility(const uint8_t *ss_facility, uint16_t len,
201 struct ss_request *req);
Vadim Yanitskiyb41c70f2018-01-17 12:10:07 +0600202static int parse_ss_info_elements(const uint8_t *ss_ie, uint16_t len,
Tobias Engel419684e2012-03-08 13:31:52 +0100203 struct ss_request *req);
Holger Hans Peter Freyther49ad5002010-10-11 09:06:47 +0200204static int parse_ss_invoke(const uint8_t *invoke_data, uint16_t length,
Tobias Engel419684e2012-03-08 13:31:52 +0100205 struct ss_request *req);
Vadim Yanitskiy7f16c442017-07-29 05:05:54 +0600206static int parse_ss_return_result(const uint8_t *rr_data, uint16_t length,
207 struct ss_request *req);
208static int parse_process_uss_data(const uint8_t *uss_req_data, uint16_t length,
209 struct ss_request *req);
Holger Hans Peter Freyther49ad5002010-10-11 09:06:47 +0200210static int parse_process_uss_req(const uint8_t *uss_req_data, uint16_t length,
Tobias Engel419684e2012-03-08 13:31:52 +0100211 struct ss_request *req);
212static int parse_ss_for_bs_req(const uint8_t *ss_req_data,
213 uint16_t length,
214 struct ss_request *req);
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800215
Vadim Yanitskiy52e44122018-06-11 03:51:11 +0700216/*! Get pointer to the IE of a given type
217 * \param[in] hdr Pointer to the message starting from header
218 * \param[in] msg_len Length of the whole message + header
219 * \param[out] ie External pointer to be set
220 * \param[out] ie_len External IE length variable
221 * \param[in] ie_tag Tag value of the required IE
222 * \returns 0 in case of success, otherwise -ERRNO
223 *
224 * This function iterates over existing IEs within a given
225 * message (depending on its type), and looks for the one with
226 * given \ref ie_tag value. If the IE is found, the external
227 * pointer pointed by \ref ie will be set to its value part
228 * (omitting TL), and \ref ie_len will be set to the length.
229 * Otherwise, e.g. in case of parsing error, both \ref ie
230 * and \ref ie_len are set to NULL and 0 respectively.
231 */
232int gsm0480_extract_ie_by_tag(const struct gsm48_hdr *hdr, uint16_t msg_len,
233 uint8_t **ie, uint16_t *ie_len, uint8_t ie_tag)
234{
235 uint8_t pdisc, msg_type;
236 uint8_t *tlv, len;
237
238 /* Init external variables */
239 *ie_len = 0;
240 *ie = NULL;
241
242 /* Drop incomplete / corrupted messages */
243 if (msg_len < sizeof(*hdr))
244 return -EINVAL;
245
246 pdisc = gsm48_hdr_pdisc(hdr);
247 msg_type = gsm48_hdr_msg_type(hdr);
248
249 /* Drop non-SS related messages */
250 if (pdisc != GSM48_PDISC_NC_SS)
251 return -EINVAL;
252
253 len = msg_len - sizeof(*hdr);
254 tlv = (uint8_t *) hdr->data;
255
256 /* Parse a message depending on its type */
257 switch (msg_type) {
258 /* See table 2.5: RELEASE COMPLETE message content */
259 case GSM0480_MTYPE_RELEASE_COMPLETE:
260 /* See tables 2.3 and 2.4: REGISTER message content */
261 case GSM0480_MTYPE_REGISTER:
262 /* Iterate over TLV-based IEs */
263 while (len > 2) {
264 if (tlv[0] == ie_tag) {
265 *ie_len = tlv[1];
266 *ie = tlv + 2;
267 return 0;
268 }
269
270 len -= tlv[1] + 2;
271 tlv += tlv[1] + 2;
272 continue;
273 }
274
275 /* The Facility IE is mandatory for REGISTER */
276 if (msg_type == GSM0480_MTYPE_REGISTER)
277 if (ie_tag == GSM0480_IE_FACILITY)
278 return -EINVAL;
279 break;
280
281 /* See table 2.2: FACILITY message content */
282 case GSM0480_MTYPE_FACILITY:
283 /* There is no other IEs */
284 if (ie_tag != GSM0480_IE_FACILITY)
285 break;
286
287 /* Mandatory LV-based Facility IE */
288 if (len < 2)
289 return -EINVAL;
290
291 *ie_len = tlv[0];
292 *ie = tlv + 1;
293 return 0;
294
295 default:
296 /* Wrong message type, out of specs */
297 return -EINVAL;
298 }
299
300 return 0;
301}
302
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800303/* Decode a mobile-originated USSD-request message */
Holger Hans Peter Freytherdaa653f2010-10-11 07:56:06 +0200304int gsm0480_decode_ussd_request(const struct gsm48_hdr *hdr, uint16_t len,
305 struct ussd_request *req)
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800306{
Tobias Engel419684e2012-03-08 13:31:52 +0100307 struct ss_request ss;
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800308 int rc = 0;
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800309
Tobias Engel419684e2012-03-08 13:31:52 +0100310 memset(&ss, 0, sizeof(ss));
311
Holger Hans Peter Freyther8ac04862010-10-11 08:08:58 +0200312 if (len < sizeof(*hdr) + 2) {
313 LOGP(0, LOGL_DEBUG, "USSD Request is too short.\n");
314 return 0;
315 }
316
Neels Hofmeyr282e9082016-03-14 16:06:46 +0100317 if (gsm48_hdr_pdisc(hdr) == GSM48_PDISC_NC_SS) {
Holger Hans Peter Freytherdaa653f2010-10-11 07:56:06 +0200318 req->transaction_id = hdr->proto_discr & 0x70;
Tobias Engel419684e2012-03-08 13:31:52 +0100319
320 ss.transaction_id = req->transaction_id;
Vadim Yanitskiy7689e0f2018-01-17 03:23:39 +0600321 rc = parse_ss(hdr, len - sizeof(*hdr), &ss);
Tobias Engel419684e2012-03-08 13:31:52 +0100322
323 /* convert from ss_request to legacy ussd_request */
324 req->transaction_id = ss.transaction_id;
325 req->invoke_id = ss.invoke_id;
326 if (ss.ussd_text[0] == 0xFF)
327 req->text[0] = '\0';
328 else {
329 memcpy(req->text, ss.ussd_text, sizeof(req->text));
330 req->text[sizeof(req->text)-1] = '\0';
331 }
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800332 }
333
334 if (!rc)
335 LOGP(0, LOGL_DEBUG, "Error occurred while parsing received USSD!\n");
336
337 return rc;
338}
339
Tobias Engel419684e2012-03-08 13:31:52 +0100340/* Decode a mobile-originated SS request message */
341int gsm0480_decode_ss_request(const struct gsm48_hdr *hdr, uint16_t len,
342 struct ss_request *req)
343{
Vadim Yanitskiyf07c58c2018-01-17 03:42:16 +0600344 uint8_t pdisc;
Tobias Engel419684e2012-03-08 13:31:52 +0100345
Vadim Yanitskiyf07c58c2018-01-17 03:42:16 +0600346 /**
347 * Check Protocol Discriminator
348 * see TS GSM 04.07 and GSM 04.80
349 */
350 pdisc = gsm48_hdr_pdisc(hdr);
351 if (pdisc != GSM48_PDISC_NC_SS) {
352 LOGP(0, LOGL_ERROR, "Dropping message with "
353 "unsupported pdisc=%02x\n", pdisc);
354 return 0;
Tobias Engel419684e2012-03-08 13:31:52 +0100355 }
356
Vadim Yanitskiyf07c58c2018-01-17 03:42:16 +0600357 /* GSM 04.80 3.3 Transaction Identifier */
358 req->transaction_id = hdr->proto_discr & 0x70;
Tobias Engel419684e2012-03-08 13:31:52 +0100359
Vadim Yanitskiyf07c58c2018-01-17 03:42:16 +0600360 /* Parse SS request */
361 return parse_ss(hdr, len - sizeof(*hdr), req);
Tobias Engel419684e2012-03-08 13:31:52 +0100362}
363
364static int parse_ss(const struct gsm48_hdr *hdr, uint16_t len, struct ss_request *req)
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800365{
366 int rc = 1;
Neels Hofmeyra95ee5e2016-10-10 22:46:20 +0200367 uint8_t msg_type = hdr->msg_type & 0x3F; /* message-type - section 3.4 */
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800368
Vadim Yanitskiyfd744ce2018-01-17 03:31:15 +0600369 /**
370 * GSM 04.80 Section 2.5 'Release complete' Table 2.5
371 * payload is optional for 'RELEASE COMPLETE' message
372 */
373 if (msg_type != GSM0480_MTYPE_RELEASE_COMPLETE) {
374 if (len < 2) {
375 LOGP(0, LOGL_DEBUG, "SS Request is too short.\n");
376 return 0;
377 }
378 }
379
Vadim Yanitskiy44ebb932018-01-17 02:59:46 +0600380 /* Table 2.1: Messages for call independent SS control */
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800381 switch (msg_type) {
382 case GSM0480_MTYPE_RELEASE_COMPLETE:
Tobias Engel419684e2012-03-08 13:31:52 +0100383 LOGP(0, LOGL_DEBUG, "SS Release Complete\n");
Vadim Yanitskiy3cafc062018-01-17 12:28:40 +0600384
Vadim Yanitskiyfb5da892018-04-04 19:25:38 +0700385 /**
386 * Indicates that there is no decoded message.
387 * To be overwriten by the message otherwise.
388 */
389 req->ussd_text[0] = 0xFF;
390
Vadim Yanitskiy3cafc062018-01-17 12:28:40 +0600391 /* Parse optional Cause and/or Facility data */
392 if (len >= 2)
393 rc &= parse_ss_info_elements(&hdr->data[0], len, req);
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800394 break;
395 case GSM0480_MTYPE_REGISTER:
Vadim Yanitskiy7689e0f2018-01-17 03:23:39 +0600396 rc &= parse_ss_info_elements(&hdr->data[0], len, req);
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800397 break;
Vadim Yanitskiyc30431f2017-07-29 04:47:42 +0600398 case GSM0480_MTYPE_FACILITY:
Vadim Yanitskiy7689e0f2018-01-17 03:23:39 +0600399 rc &= parse_ss_facility(&hdr->data[0], len, req);
Vadim Yanitskiyc30431f2017-07-29 04:47:42 +0600400 break;
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800401 default:
402 LOGP(0, LOGL_DEBUG, "Unknown GSM 04.80 message-type field 0x%02x\n",
Holger Hans Peter Freytherdaa653f2010-10-11 07:56:06 +0200403 hdr->msg_type);
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800404 rc = 0;
405 break;
406 }
407
408 return rc;
409}
410
Vadim Yanitskiyc30431f2017-07-29 04:47:42 +0600411static int parse_ss_facility(const uint8_t *ss_facility, uint16_t len,
412 struct ss_request *req)
413{
414 uint8_t facility_length;
415
416 facility_length = ss_facility[0];
417 if (len - 1 < facility_length)
418 return 0;
419
Vadim Yanitskiy5a09f752018-06-11 04:58:53 +0700420 return !gsm0480_parse_facility_ie(ss_facility + 1, facility_length, req);
Vadim Yanitskiyc30431f2017-07-29 04:47:42 +0600421}
422
Tobias Engel419684e2012-03-08 13:31:52 +0100423static int parse_ss_info_elements(const uint8_t *ss_ie, uint16_t len,
424 struct ss_request *req)
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800425{
426 int rc = -1;
427 /* Information Element Identifier - table 3.2 & GSM 04.08 section 10.5 */
Holger Hans Peter Freytherdaa653f2010-10-11 07:56:06 +0200428 uint8_t iei;
429 uint8_t iei_length;
430
Vadim Yanitskiyb92a27f2018-01-17 12:18:27 +0600431 /* We need at least two bytes */
432 if (len < 2)
433 return 0;
434
Tobias Engel419684e2012-03-08 13:31:52 +0100435 iei = ss_ie[0];
436 iei_length = ss_ie[1];
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800437
Holger Hans Peter Freyther8ac04862010-10-11 08:08:58 +0200438 /* If the data does not fit, report an error */
Vadim Yanitskiyb92a27f2018-01-17 12:18:27 +0600439 if (iei_length + 2 > len)
Holger Hans Peter Freyther8ac04862010-10-11 08:08:58 +0200440 return 0;
441
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800442 switch (iei) {
443 case GSM48_IE_CAUSE:
444 break;
445 case GSM0480_IE_FACILITY:
Vadim Yanitskiy5a09f752018-06-11 04:58:53 +0700446 rc = !gsm0480_parse_facility_ie(ss_ie + 2, iei_length, req);
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800447 break;
448 case GSM0480_IE_SS_VERSION:
449 break;
450 default:
451 LOGP(0, LOGL_DEBUG, "Unhandled GSM 04.08 or 04.80 IEI 0x%02x\n",
452 iei);
453 rc = 0;
454 break;
455 }
456
Vadim Yanitskiyb92a27f2018-01-17 12:18:27 +0600457 /* A message may contain multiple IEs */
458 if (iei_length + 2 + 2 < len)
459 rc &= parse_ss_info_elements(ss_ie + iei_length + 2,
460 len - iei_length - 2, req);
461
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800462 return rc;
463}
464
Vadim Yanitskiy5a09f752018-06-11 04:58:53 +0700465/*! Parse the components of a given Facility IE
466 * \param[in] facility_ie The Facility IE
467 * \param[in] length The length of Facility IE
468 * \param[out] req Abstract representation of SS message
469 * \return 0 in case of success, otherwise -ERRNO
470 */
471int gsm0480_parse_facility_ie(const uint8_t *facility_ie, uint16_t length,
472 struct ss_request *req)
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800473{
Vadim Yanitskiy5a09f752018-06-11 04:58:53 +0700474 uint8_t component_length;
475 uint8_t component_type;
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800476 uint8_t offset = 0;
Vadim Yanitskiy5a09f752018-06-11 04:58:53 +0700477 int rc = 1;
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800478
Vadim Yanitskiy5a09f752018-06-11 04:58:53 +0700479 /* Iterate over components within IE */
Holger Hans Peter Freyther4156ec62010-10-11 09:07:50 +0200480 while (offset + 2 <= length) {
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800481 /* Component Type tag - table 3.7 */
Vadim Yanitskiy5a09f752018-06-11 04:58:53 +0700482 component_type = facility_ie[offset];
483 component_length = facility_ie[offset + 1];
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800484
Vadim Yanitskiy5a09f752018-06-11 04:58:53 +0700485 /* Make sure that there is no overflow */
Holger Hans Peter Freyther4156ec62010-10-11 09:07:50 +0200486 if (offset + 2 + component_length > length) {
487 LOGP(0, LOGL_ERROR, "Component does not fit.\n");
Vadim Yanitskiy5a09f752018-06-11 04:58:53 +0700488 return -EINVAL;
Holger Hans Peter Freyther4156ec62010-10-11 09:07:50 +0200489 }
490
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800491 switch (component_type) {
492 case GSM0480_CTYPE_INVOKE:
Vadim Yanitskiy5a09f752018-06-11 04:58:53 +0700493 rc &= parse_ss_invoke(facility_ie + 2,
Tobias Engel419684e2012-03-08 13:31:52 +0100494 component_length,
495 req);
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800496 break;
497 case GSM0480_CTYPE_RETURN_RESULT:
Vadim Yanitskiy5a09f752018-06-11 04:58:53 +0700498 rc &= parse_ss_return_result(facility_ie + 2,
Vadim Yanitskiy7f16c442017-07-29 05:05:54 +0600499 component_length,
500 req);
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800501 break;
502 case GSM0480_CTYPE_RETURN_ERROR:
503 break;
504 case GSM0480_CTYPE_REJECT:
505 break;
506 default:
507 LOGP(0, LOGL_DEBUG, "Unknown GSM 04.80 Facility "
508 "Component Type 0x%02x\n", component_type);
509 rc = 0;
510 break;
511 }
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800512
Vadim Yanitskiy5a09f752018-06-11 04:58:53 +0700513 offset += (component_length + 2);
514 }
515
516 /**
517 * The internal functions are using inverted return
518 * codes, where '0' means error/failure. While a
519 * common approach is to return negative errno in
520 * case of any failure, and '0' if all is ok.
521 */
522 return (rc == 0) ? -EINVAL : 0;
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800523}
524
525/* Parse an Invoke component - see table 3.3 */
Holger Hans Peter Freyther49ad5002010-10-11 09:06:47 +0200526static int parse_ss_invoke(const uint8_t *invoke_data, uint16_t length,
Tobias Engel419684e2012-03-08 13:31:52 +0100527 struct ss_request *req)
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800528{
529 int rc = 1;
530 uint8_t offset;
531
Holger Hans Peter Freyther7d0bce32010-10-11 09:12:33 +0200532 if (length < 3)
533 return 0;
534
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800535 /* mandatory part */
536 if (invoke_data[0] != GSM0480_COMPIDTAG_INVOKE_ID) {
537 LOGP(0, LOGL_DEBUG, "Unexpected GSM 04.80 Component-ID tag "
Tobias Engel419684e2012-03-08 13:31:52 +0100538 "0x%02x (expecting Invoke ID tag)\n", invoke_data[0]);
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800539 }
540
541 offset = invoke_data[1] + 2;
542 req->invoke_id = invoke_data[2];
543
Holger Hans Peter Freyther7d0bce32010-10-11 09:12:33 +0200544 /* look ahead once */
545 if (offset + 1 > length)
546 return 0;
547
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800548 /* optional part */
549 if (invoke_data[offset] == GSM0480_COMPIDTAG_LINKED_ID)
550 offset += invoke_data[offset+1] + 2; /* skip over it */
551
552 /* mandatory part */
553 if (invoke_data[offset] == GSM0480_OPERATION_CODE) {
Holger Hans Peter Freyther7d0bce32010-10-11 09:12:33 +0200554 if (offset + 2 > length)
555 return 0;
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800556 uint8_t operation_code = invoke_data[offset+2];
Tobias Engel419684e2012-03-08 13:31:52 +0100557 req->opcode = operation_code;
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800558 switch (operation_code) {
Vadim Yanitskiy511426d2017-07-29 05:11:39 +0600559 case GSM0480_OP_CODE_USS_NOTIFY:
560 case GSM0480_OP_CODE_USS_REQUEST:
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800561 case GSM0480_OP_CODE_PROCESS_USS_REQ:
562 rc = parse_process_uss_req(invoke_data + offset + 3,
563 length - offset - 3,
564 req);
565 break;
Vadim Yanitskiy394447b2017-07-29 05:14:15 +0600566 case GSM0480_OP_CODE_PROCESS_USS_DATA:
567 rc = parse_process_uss_data(invoke_data + offset + 3,
568 length - offset - 3,
569 req);
570 break;
Tobias Engel419684e2012-03-08 13:31:52 +0100571 case GSM0480_OP_CODE_ACTIVATE_SS:
572 case GSM0480_OP_CODE_DEACTIVATE_SS:
573 case GSM0480_OP_CODE_INTERROGATE_SS:
574 rc = parse_ss_for_bs_req(invoke_data + offset + 3,
575 length - offset - 3,
576 req);
577 break;
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800578 default:
579 LOGP(0, LOGL_DEBUG, "GSM 04.80 operation code 0x%02x "
580 "is not yet handled\n", operation_code);
581 rc = 0;
582 break;
583 }
584 } else {
585 LOGP(0, LOGL_DEBUG, "Unexpected GSM 04.80 Component-ID tag 0x%02x "
586 "(expecting Operation Code tag)\n",
587 invoke_data[0]);
588 rc = 0;
589 }
590
591 return rc;
592}
593
Vadim Yanitskiy7f16c442017-07-29 05:05:54 +0600594/* Parse a Return Result component - see table 3.4 */
595static int parse_ss_return_result(const uint8_t *rr_data, uint16_t length,
596 struct ss_request *req)
597{
598 uint8_t operation_code;
599 uint8_t offset;
600
601 if (length < 3)
602 return 0;
603
604 /* Mandatory part */
605 if (rr_data[0] != GSM0480_COMPIDTAG_INVOKE_ID) {
606 LOGP(0, LOGL_DEBUG, "Unexpected GSM 04.80 Component-ID tag "
607 "0x%02x (expecting Invoke ID tag)\n", rr_data[0]);
608 return 0;
609 }
610
611 offset = rr_data[1] + 2;
612 req->invoke_id = rr_data[2];
613
614 if (offset >= length)
615 return 0;
616
617 if (rr_data[offset] != GSM_0480_SEQUENCE_TAG)
618 return 0;
619
620 if (offset + 2 > length)
621 return 0;
622
623 offset += 2;
624 operation_code = rr_data[offset + 2];
625 req->opcode = operation_code;
626
627 switch (operation_code) {
628 case GSM0480_OP_CODE_USS_NOTIFY:
629 case GSM0480_OP_CODE_USS_REQUEST:
630 case GSM0480_OP_CODE_PROCESS_USS_REQ:
631 return parse_process_uss_req(rr_data + offset + 3,
632 length - offset - 3, req);
633 case GSM0480_OP_CODE_PROCESS_USS_DATA:
634 return parse_process_uss_data(rr_data + offset + 3,
635 length - offset - 3, req);
636 default:
637 LOGP(0, LOGL_DEBUG, "GSM 04.80 operation code 0x%02x "
638 "is not yet handled\n", operation_code);
639 return 0;
640 }
641
642 return 1;
643}
644
645static int parse_process_uss_data(const uint8_t *uss_req_data, uint16_t length,
646 struct ss_request *req)
647{
648 uint8_t num_chars;
649
650 /* we need at least that much */
651 if (length < 3)
652 return 0;
653
654 if (uss_req_data[0] != ASN1_IA5_STRING_TAG)
655 return 0;
656
657 num_chars = uss_req_data[1];
658 if (num_chars > length - 2)
659 return 0;
660
Vadim Yanitskiy2ecfb302018-04-04 19:19:07 +0700661 /* Drop messages with incorrect length */
662 if (num_chars > GSM0480_USSD_OCTET_STRING_LEN) {
663 LOGP(DLGLOBAL, LOGL_ERROR, "Incorrect USS_DATA data length=%u, "
664 "dropping message", num_chars);
665 return 0;
666 }
Vadim Yanitskiy7f16c442017-07-29 05:05:54 +0600667
668 memcpy(req->ussd_text, uss_req_data + 2, num_chars);
669
Vadim Yanitskiya24ead02018-04-04 10:34:41 +0700670 /* Copy the data 'as is' */
671 memcpy(req->ussd_data, uss_req_data + 2, num_chars);
672 req->ussd_data_len = num_chars;
673 req->ussd_data_dcs = 0x00;
674
Vadim Yanitskiy7f16c442017-07-29 05:05:54 +0600675 return 1;
676}
677
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800678/* Parse the parameters of a Process UnstructuredSS Request */
Holger Hans Peter Freyther49ad5002010-10-11 09:06:47 +0200679static int parse_process_uss_req(const uint8_t *uss_req_data, uint16_t length,
Tobias Engel419684e2012-03-08 13:31:52 +0100680 struct ss_request *req)
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800681{
Vadim Yanitskiy5b0790d2017-07-29 04:26:21 +0600682 uint8_t num_chars;
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800683 uint8_t dcs;
684
Holger Hans Peter Freytherd65a6982010-10-11 09:23:50 +0200685 /* we need at least that much */
686 if (length < 8)
687 return 0;
688
Vadim Yanitskiy5b0790d2017-07-29 04:26:21 +0600689 if (uss_req_data[0] != GSM_0480_SEQUENCE_TAG)
690 return 0;
Holger Hans Peter Freytherd65a6982010-10-11 09:23:50 +0200691
Vadim Yanitskiy5b0790d2017-07-29 04:26:21 +0600692 /* Both 2th and 5th should be equal to ASN1_OCTET_STRING_TAG */
693 if ((uss_req_data[2] & uss_req_data[5]) != ASN1_OCTET_STRING_TAG)
694 return 0;
695
Vadim Yanitskiy01b85722017-07-29 04:43:48 +0600696 /* Get DCS (Data Coding Scheme) */
Vadim Yanitskiy5b0790d2017-07-29 04:26:21 +0600697 dcs = uss_req_data[4];
Vadim Yanitskiya24ead02018-04-04 10:34:41 +0700698 /* Get the amount of bytes */
699 num_chars = uss_req_data[6];
700
Vadim Yanitskiy2ecfb302018-04-04 19:19:07 +0700701 /* Drop messages with incorrect length */
702 if (num_chars > GSM0480_USSD_OCTET_STRING_LEN) {
703 LOGP(DLGLOBAL, LOGL_ERROR, "Incorrect USS_REQ data length=%u, "
704 "dropping message", num_chars);
705 return 0;
706 }
Vadim Yanitskiya24ead02018-04-04 10:34:41 +0700707
708 /* Copy the data 'as is' */
709 memcpy(req->ussd_data, uss_req_data + 7, num_chars);
710 req->ussd_data_len = num_chars;
711 req->ussd_data_dcs = dcs;
Vadim Yanitskiy01b85722017-07-29 04:43:48 +0600712
713 /**
714 * According to GSM 04.08, 4.4.2 "ASN.1 data types":
715 * the USSD-DataCodingScheme shall indicate use of
716 * the default alphabet using the 0x0F value.
717 */
Vadim Yanitskiy5b0790d2017-07-29 04:26:21 +0600718 if (dcs == 0x0F) {
Vadim Yanitskiy01b85722017-07-29 04:43:48 +0600719 /* Calculate the amount of 7-bit characters */
Vadim Yanitskiya24ead02018-04-04 10:34:41 +0700720 num_chars = (num_chars * 8) / 7;
Vadim Yanitskiy01b85722017-07-29 04:43:48 +0600721
Vadim Yanitskiy5b0790d2017-07-29 04:26:21 +0600722 gsm_7bit_decode_n_ussd((char *)req->ussd_text,
723 sizeof(req->ussd_text), &(uss_req_data[7]), num_chars);
724
725 return 1;
Vadim Yanitskiy01b85722017-07-29 04:43:48 +0600726 } else {
Vadim Yanitskiy01b85722017-07-29 04:43:48 +0600727 memcpy(req->ussd_text, &(uss_req_data[7]), num_chars);
Vadim Yanitskiy01b85722017-07-29 04:43:48 +0600728 return 1;
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800729 }
Vadim Yanitskiy5b0790d2017-07-29 04:26:21 +0600730
731 return 0;
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800732}
Holger Hans Peter Freytherc64970e2010-10-18 16:56:43 +0200733
Tobias Engel419684e2012-03-08 13:31:52 +0100734/* Parse the parameters of a Interrogate/Activate/DeactivateSS Request */
735static int parse_ss_for_bs_req(const uint8_t *ss_req_data,
736 uint16_t length,
737 struct ss_request *req)
738{
739 int rc = 0;
740
741
742 /* we need at least that much */
743 if (length < 5)
744 return 0;
745
746
747 if (ss_req_data[0] == GSM_0480_SEQUENCE_TAG) {
748 if ((ss_req_data[2] == ASN1_OCTET_STRING_TAG) &&
749 ss_req_data[3] == 1) {
750 req->ss_code = ss_req_data[4];
751
752 rc = 1;
753 }
754 }
755 return rc;
756}
757
Holger Hans Peter Freytherc64970e2010-10-18 16:56:43 +0200758struct msgb *gsm0480_create_ussd_resp(uint8_t invoke_id, uint8_t trans_id, const char *text)
759{
760 struct msgb *msg;
Holger Hans Peter Freytherc64970e2010-10-18 16:56:43 +0200761 uint8_t *ptr8;
Holger Hans Peter Freyther47aa4822013-07-07 13:54:53 +0200762 int response_len;
Holger Hans Peter Freytherc64970e2010-10-18 16:56:43 +0200763
764 msg = msgb_alloc_headroom(1024, 128, "GSM 04.80");
765 if (!msg)
766 return NULL;
767
768 /* First put the payload text into the message */
769 ptr8 = msgb_put(msg, 0);
Jacob Erlbeck1d7f3b52013-08-12 17:07:53 +0200770 gsm_7bit_encode_n_ussd(ptr8, msgb_tailroom(msg), text, &response_len);
Holger Hans Peter Freyther47aa4822013-07-07 13:54:53 +0200771 msgb_put(msg, response_len);
Holger Hans Peter Freytherc64970e2010-10-18 16:56:43 +0200772
773 /* Then wrap it as an Octet String */
774 msgb_wrap_with_TL(msg, ASN1_OCTET_STRING_TAG);
775
776 /* Pre-pend the DCS octet string */
777 msgb_push_TLV1(msg, ASN1_OCTET_STRING_TAG, 0x0F);
778
779 /* Then wrap these as a Sequence */
780 msgb_wrap_with_TL(msg, GSM_0480_SEQUENCE_TAG);
781
782 /* Pre-pend the operation code */
783 msgb_push_TLV1(msg, GSM0480_OPERATION_CODE,
784 GSM0480_OP_CODE_PROCESS_USS_REQ);
785
786 /* Wrap the operation code and IA5 string as a sequence */
787 msgb_wrap_with_TL(msg, GSM_0480_SEQUENCE_TAG);
788
789 /* Pre-pend the invoke ID */
790 msgb_push_TLV1(msg, GSM0480_COMPIDTAG_INVOKE_ID, invoke_id);
791
792 /* Wrap this up as a Return Result component */
793 msgb_wrap_with_TL(msg, GSM0480_CTYPE_RETURN_RESULT);
794
795 /* Wrap the component in a Facility message */
796 msgb_wrap_with_TL(msg, GSM0480_IE_FACILITY);
797
798 /* And finally pre-pend the L3 header */
Neels Hofmeyr25774b92016-11-26 15:21:05 +0100799 gsm0480_l3hdr_push(msg,
800 GSM48_PDISC_NC_SS | trans_id
801 | (1<<7) /* TI direction = 1 */,
802 GSM0480_MTYPE_RELEASE_COMPLETE);
Holger Hans Peter Freytherc64970e2010-10-18 16:56:43 +0200803 return msg;
804}
Neels Hofmeyr25774b92016-11-26 15:21:05 +0100805
806struct gsm48_hdr *gsm0480_l3hdr_push(struct msgb *msg, uint8_t proto_discr,
807 uint8_t msg_type)
808{
809 struct gsm48_hdr *gh;
810 gh = (struct gsm48_hdr *) msgb_push(msg, sizeof(*gh));
811 gh->proto_discr = proto_discr;
812 gh->msg_type = msg_type;
813 return gh;
814}
Neels Hofmeyrbc1d7582016-11-26 15:21:15 +0100815
816struct msgb *gsm0480_create_ussd_notify(int level, const char *text)
817{
818 struct msgb *msg;
819
820 msg = gsm0480_create_unstructuredSS_Notify(level, text);
821 if (!msg)
822 return NULL;
823
824 gsm0480_wrap_invoke(msg, GSM0480_OP_CODE_USS_NOTIFY, 0);
825 gsm0480_wrap_facility(msg);
826
827 gsm0480_l3hdr_push(msg, GSM48_PDISC_NC_SS, GSM0480_MTYPE_REGISTER);
828 return msg;
829}
830
831struct msgb *gsm0480_create_ussd_release_complete(void)
832{
833 struct msgb *msg;
834
835 msg = msgb_alloc_headroom(1024, 128, "GSM 04.80 USSD REL COMPL");
836 if (!msg)
837 return NULL;
838
839 /* FIXME: should this set trans_id and TI direction flag? */
840 gsm0480_l3hdr_push(msg, GSM48_PDISC_NC_SS,
841 GSM0480_MTYPE_RELEASE_COMPLETE);
842 return msg;
843}