blob: cd95c6bb236d7bb0beb71b24e7abc0ef34f00351 [file] [log] [blame]
Neels Hofmeyr17518fe2017-06-20 04:35:06 +02001/*! \file ipa.c
2 * OpenBSC Abis input driver for ip.access */
3/*
4 * (C) 2009-2017 by Harald Welte <laforge@gnumonks.org>
Harald Welte28aa9912014-08-20 22:06:04 +02005 * (C) 2010 by Holger Hans Peter Freyther
6 * (C) 2010 by On-Waves
7 *
8 * All Rights Reserved
9 *
Harald Weltee08da972017-11-13 01:00:26 +090010 * SPDX-License-Identifier: GPL-2.0+
11 *
Harald Welte28aa9912014-08-20 22:06:04 +020012 * This program is free software; you can redistribute it and/or modify
Harald Weltefd5ad172014-10-26 20:47:42 +010013 * it under the terms of the GNU General Public License as published by
14 * the Free Software Foundation; either version 2 of the License, or
Harald Welte28aa9912014-08-20 22:06:04 +020015 * (at your option) any later version.
16 *
17 * This program is distributed in the hope that it will be useful,
18 * but WITHOUT ANY WARRANTY; without even the implied warranty of
19 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
Harald Weltefd5ad172014-10-26 20:47:42 +010020 * GNU General Public License for more details.
Harald Welte28aa9912014-08-20 22:06:04 +020021 *
Harald Weltefd5ad172014-10-26 20:47:42 +010022 * You should have received a copy of the GNU General Public License
Harald Welte28aa9912014-08-20 22:06:04 +020023 * along with this program. If not, see <http://www.gnu.org/licenses/>.
24 *
25 */
26
Harald Welte20725b92017-05-15 12:50:04 +020027#include "config.h"
28
Harald Welte28aa9912014-08-20 22:06:04 +020029#include <unistd.h>
30#include <stdint.h>
31#include <errno.h>
32#include <stdlib.h>
33
Holger Hans Peter Freytheree6652b2015-11-09 16:21:19 +000034#include <sys/types.h>
Harald Welte28aa9912014-08-20 22:06:04 +020035
Harald Welte95871da2017-05-15 12:11:36 +020036#include <osmocom/core/byteswap.h>
Harald Welte28aa9912014-08-20 22:06:04 +020037#include <osmocom/core/msgb.h>
38#include <osmocom/core/talloc.h>
39#include <osmocom/core/logging.h>
40#include <osmocom/core/macaddr.h>
41#include <osmocom/core/select.h>
42
43#include <osmocom/gsm/tlv.h>
44#include <osmocom/gsm/protocol/ipaccess.h>
Harald Weltee3919962014-08-20 22:28:23 +020045#include <osmocom/gsm/ipa.h>
Harald Welte28aa9912014-08-20 22:06:04 +020046
Harald Welte96e2a002017-06-12 21:44:18 +020047/*! \addtogroup ipa
48 * @{
Neels Hofmeyr87e45502017-06-20 00:17:59 +020049 * IPA Multiplex utility routines
Harald Welte96e2a002017-06-12 21:44:18 +020050 */
51
Harald Welte28aa9912014-08-20 22:06:04 +020052#define IPA_ALLOC_SIZE 1200
53
54/*
55 * Common propietary IPA messages:
56 * - PONG: in reply to PING.
57 * - ID_REQUEST: first messages once OML has been established.
58 * - ID_ACK: in reply to ID_ACK.
59 */
60static const uint8_t ipa_pong_msg[] = {
61 0, 1, IPAC_PROTO_IPACCESS, IPAC_MSGT_PONG
62};
63
64static const uint8_t ipa_id_ack_msg[] = {
65 0, 1, IPAC_PROTO_IPACCESS, IPAC_MSGT_ID_ACK
66};
67
68static const uint8_t ipa_id_req_msg[] = {
69 0, 17, IPAC_PROTO_IPACCESS, IPAC_MSGT_ID_GET,
70 0x01, IPAC_IDTAG_UNIT,
71 0x01, IPAC_IDTAG_MACADDR,
72 0x01, IPAC_IDTAG_LOCATION1,
73 0x01, IPAC_IDTAG_LOCATION2,
74 0x01, IPAC_IDTAG_EQUIPVERS,
75 0x01, IPAC_IDTAG_SWVERSION,
76 0x01, IPAC_IDTAG_UNITNAME,
77 0x01, IPAC_IDTAG_SERNR,
78};
79
80
81static const char *idtag_names[] = {
82 [IPAC_IDTAG_SERNR] = "Serial_Number",
83 [IPAC_IDTAG_UNITNAME] = "Unit_Name",
84 [IPAC_IDTAG_LOCATION1] = "Location_1",
85 [IPAC_IDTAG_LOCATION2] = "Location_2",
86 [IPAC_IDTAG_EQUIPVERS] = "Equipment_Version",
87 [IPAC_IDTAG_SWVERSION] = "Software_Version",
88 [IPAC_IDTAG_IPADDR] = "IP_Address",
89 [IPAC_IDTAG_MACADDR] = "MAC_Address",
90 [IPAC_IDTAG_UNIT] = "Unit_ID",
91};
92
Harald Weltee3919962014-08-20 22:28:23 +020093const char *ipa_ccm_idtag_name(uint8_t tag)
Harald Welte28aa9912014-08-20 22:06:04 +020094{
95 if (tag >= ARRAY_SIZE(idtag_names))
96 return "unknown";
97
98 return idtag_names[tag];
99}
100
Pau Espin Pedroldeeab472019-03-27 17:33:17 +0100101/*! Parse the payload part of an IPA CCM ID GET, return \ref tlv_parsed format. */
Harald Weltee3919962014-08-20 22:28:23 +0200102int ipa_ccm_idtag_parse(struct tlv_parsed *dec, unsigned char *buf, int len)
Harald Welte28aa9912014-08-20 22:06:04 +0200103{
Pau Espin Pedroldeeab472019-03-27 17:33:17 +0100104 return ipa_ccm_idtag_parse_off(dec, buf, len, 1);
Harald Welte5a7740d2018-08-01 17:29:48 +0200105}
106
Pau Espin Pedroldeeab472019-03-27 17:33:17 +0100107/*! Parse the payload part of an IPA CCM ID GET, return \ref tlv_parsed format.
108 * WARNING: This function can only parse correctly IPA CCM ID GET/REQUEST
109 * messages, and only when len_offset is passed value of 1.
110 * \param[out] dec Caller-provided/allocated output structure for parsed payload
111 * \param[in] buf Buffer containing the payload (excluding 1 byte msg_type) of the message
112 * \param[in] len Length of \a buf in octets
113 * \param[in] len_offset Offset from end of len field to start of value (ommiting tag). Must be 1!
114 * \returns 0 on success; negative on error
115 */
Harald Welte5a7740d2018-08-01 17:29:48 +0200116int ipa_ccm_idtag_parse_off(struct tlv_parsed *dec, unsigned char *buf, int len, const int len_offset)
117{
Harald Welte28aa9912014-08-20 22:06:04 +0200118 uint8_t t_len;
119 uint8_t t_tag;
120 uint8_t *cur = buf;
121
122 memset(dec, 0, sizeof(*dec));
123
Pau Espin Pedrol9cc661b2020-08-26 13:29:47 +0200124 LOGP(DLMI, LOGL_DEBUG, "Rx IPA CCM ID_GET: ");
Harald Welte28aa9912014-08-20 22:06:04 +0200125 while (len >= 2) {
126 len -= 2;
127 t_len = *cur++;
128 t_tag = *cur++;
129
Harald Welte5a7740d2018-08-01 17:29:48 +0200130 if (t_len < len_offset) {
Pau Espin Pedrol9cc661b2020-08-26 13:29:47 +0200131 LOGPC(DLMI, LOGL_DEBUG, "\n");
Harald Welte5a7740d2018-08-01 17:29:48 +0200132 LOGP(DLMI, LOGL_ERROR, "minimal offset not included: %d < %d\n", t_len, len_offset);
133 return -EINVAL;
134 }
135
Harald Welte7869baf2018-07-31 20:25:48 +0200136 if (t_len > len + 1) {
Pau Espin Pedrol9cc661b2020-08-26 13:29:47 +0200137 LOGPC(DLMI, LOGL_DEBUG, "\n");
Harald Welte7869baf2018-07-31 20:25:48 +0200138 LOGP(DLMI, LOGL_ERROR, "The tag does not fit: %d > %d\n", t_len, len + 1);
Holger Hans Peter Freytherf558ed42015-06-02 15:52:06 +0200139 return -EINVAL;
140 }
141
Pau Espin Pedrol9cc661b2020-08-26 13:29:47 +0200142 LOGPC(DLMI, LOGL_DEBUG, "%s='%s' ", ipa_ccm_idtag_name(t_tag), cur);
Harald Welte7869baf2018-07-31 20:25:48 +0200143
Oliver Smith27f7b0d2019-03-25 13:45:57 +0100144 dec->lv[t_tag].len = t_len - len_offset;
Harald Welte7869baf2018-07-31 20:25:48 +0200145 dec->lv[t_tag].val = cur;
146
Harald Welte5a7740d2018-08-01 17:29:48 +0200147 cur += t_len - len_offset;
148 len -= t_len - len_offset;
Harald Welte7869baf2018-07-31 20:25:48 +0200149 }
Pau Espin Pedrol9cc661b2020-08-26 13:29:47 +0200150 LOGPC(DLMI, LOGL_DEBUG, "\n");
Harald Welte7869baf2018-07-31 20:25:48 +0200151 return 0;
152}
153
154/*! Parse the payload part of an IPA CCM ID GET, return \ref tlv_parsed format.
155 * The odd payload format of those messages is structured as follows:
156 * * 8bit length value (length of payload *and tag*)
157 * * 8bit tag value
158 * * optional, variable-length payload
159 * \param[out] dec Caller-provided/allocated output structure for parsed payload
160 * \param[in] buf Buffer containing the payload (excluding 1 byte msg_type) of the message
161 * \param[in] len Length of \a buf in octets
162 * \returns 0 on success; negative on error */
163int ipa_ccm_id_get_parse(struct tlv_parsed *dec, const uint8_t *buf, unsigned int len)
164{
165 uint8_t t_len;
166 uint8_t t_tag;
167 const uint8_t *cur = buf;
168
169 memset(dec, 0, sizeof(*dec));
170
Pau Espin Pedrol9cc661b2020-08-26 13:29:47 +0200171 LOGP(DLMI, LOGL_DEBUG, "Rx IPA CCM ID_GET: ");
Harald Welte7869baf2018-07-31 20:25:48 +0200172 while (len >= 2) {
173 len -= 2;
174 t_len = *cur++;
175 t_tag = *cur++;
176
Harald Welte28aa9912014-08-20 22:06:04 +0200177 if (t_len > len + 1) {
Pau Espin Pedrol9cc661b2020-08-26 13:29:47 +0200178 LOGPC(DLMI, LOGL_DEBUG, "\n");
Max9b4d0652016-11-15 19:21:23 +0100179 LOGP(DLMI, LOGL_ERROR, "The tag does not fit: %d > %d\n", t_len, len + 1);
Harald Welte28aa9912014-08-20 22:06:04 +0200180 return -EINVAL;
181 }
182
Pau Espin Pedrol9cc661b2020-08-26 13:29:47 +0200183 LOGPC(DLMI, LOGL_DEBUG, "%s='%s' ", ipa_ccm_idtag_name(t_tag), cur);
Harald Welte28aa9912014-08-20 22:06:04 +0200184
Harald Welte7869baf2018-07-31 20:25:48 +0200185 dec->lv[t_tag].len = t_len-1;
Harald Welte28aa9912014-08-20 22:06:04 +0200186 dec->lv[t_tag].val = cur;
187
Harald Welte7869baf2018-07-31 20:25:48 +0200188 cur += t_len-1;
189 len -= t_len-1;
190 }
Pau Espin Pedrol9cc661b2020-08-26 13:29:47 +0200191 LOGPC(DLMI, LOGL_DEBUG, "\n");
Harald Welte7869baf2018-07-31 20:25:48 +0200192 return 0;
193}
194
195/*! Parse the payload part of an IPA CCM ID RESP, return \ref tlv_parsed format.
196 * The odd payload format of those messages is structured as follows:
197 * * 16bit length value (length of payload *and tag*)
198 * * 8bit tag value
199 * * optional, variable-length payload
200 * \param[out] dec Caller-provided/allocated output structure for parsed payload
201 * \param[in] buf Buffer containing the payload (excluding 1 byte msg_type) of the message
202 * \param[in] len Length of \a buf in octets
203 * \returns 0 on success; negative on error */
204int ipa_ccm_id_resp_parse(struct tlv_parsed *dec, const uint8_t *buf, unsigned int len)
205{
206 uint8_t t_len;
207 uint8_t t_tag;
208 const uint8_t *cur = buf;
209
210 memset(dec, 0, sizeof(*dec));
211
Pau Espin Pedrol9cc661b2020-08-26 13:29:47 +0200212 LOGP(DLMI, LOGL_DEBUG, "Rx IPA CCM ID_RESP: ");
Harald Welte7869baf2018-07-31 20:25:48 +0200213 while (len >= 3) {
214 len -= 3;
Pau Espin Pedrol3cb68512019-03-27 17:45:00 +0100215 t_len = osmo_load16be(cur);
216 cur += 2;
Harald Welte7869baf2018-07-31 20:25:48 +0200217 t_tag = *cur++;
218
219 if (t_len > len + 1) {
Pau Espin Pedrol9cc661b2020-08-26 13:29:47 +0200220 LOGPC(DLMI, LOGL_DEBUG, "\n");
Harald Welte7869baf2018-07-31 20:25:48 +0200221 LOGP(DLMI, LOGL_ERROR, "The tag does not fit: %d > %d\n", t_len, len + 1);
222 return -EINVAL;
223 }
224
225 DEBUGPC(DLMI, "%s='%s' ", ipa_ccm_idtag_name(t_tag), cur);
226
227 dec->lv[t_tag].len = t_len-1;
228 dec->lv[t_tag].val = cur;
229
230 cur += t_len-1;
231 len -= t_len-1;
Harald Welte28aa9912014-08-20 22:06:04 +0200232 }
Pau Espin Pedrol9cc661b2020-08-26 13:29:47 +0200233 LOGPC(DLMI, LOGL_DEBUG, "\n");
Harald Welte28aa9912014-08-20 22:06:04 +0200234 return 0;
235}
236
Harald Weltee3919962014-08-20 22:28:23 +0200237int ipa_parse_unitid(const char *str, struct ipaccess_unit *unit_data)
Harald Welte28aa9912014-08-20 22:06:04 +0200238{
239 unsigned long ul;
240 char *endptr;
241 const char *nptr;
242
243 nptr = str;
244 ul = strtoul(nptr, &endptr, 10);
245 if (endptr <= nptr)
246 return -EINVAL;
247 unit_data->site_id = ul & 0xffff;
248
249 if (*endptr++ != '/')
250 return -EINVAL;
251
252 nptr = endptr;
253 ul = strtoul(nptr, &endptr, 10);
254 if (endptr <= nptr)
255 return -EINVAL;
256 unit_data->bts_id = ul & 0xffff;
257
258 if (*endptr++ != '/')
259 return -EINVAL;
260
261 nptr = endptr;
262 ul = strtoul(nptr, &endptr, 10);
263 if (endptr <= nptr)
264 return -EINVAL;
265 unit_data->trx_id = ul & 0xffff;
266
267 return 0;
268}
269
Harald Weltee3919962014-08-20 22:28:23 +0200270int ipa_ccm_tlv_to_unitdata(struct ipaccess_unit *ud,
Harald Welte28aa9912014-08-20 22:06:04 +0200271 const struct tlv_parsed *tp)
272{
273 int rc = 0;
274
275 if (TLVP_PRES_LEN(tp, IPAC_IDTAG_SERNR, 1))
276 ud->serno = talloc_strdup(ud, (char *)
277 TLVP_VAL(tp, IPAC_IDTAG_SERNR));
278
279 if (TLVP_PRES_LEN(tp, IPAC_IDTAG_UNITNAME, 1))
280 ud->unit_name = talloc_strdup(ud, (char *)
281 TLVP_VAL(tp, IPAC_IDTAG_UNITNAME));
282
283 if (TLVP_PRES_LEN(tp, IPAC_IDTAG_LOCATION1, 1))
284 ud->location1 = talloc_strdup(ud, (char *)
285 TLVP_VAL(tp, IPAC_IDTAG_LOCATION1));
286
287 if (TLVP_PRES_LEN(tp, IPAC_IDTAG_LOCATION2, 1))
288 ud->location2 = talloc_strdup(ud, (char *)
289 TLVP_VAL(tp, IPAC_IDTAG_LOCATION2));
290
291 if (TLVP_PRES_LEN(tp, IPAC_IDTAG_EQUIPVERS, 1))
292 ud->equipvers = talloc_strdup(ud, (char *)
293 TLVP_VAL(tp, IPAC_IDTAG_EQUIPVERS));
294
295 if (TLVP_PRES_LEN(tp, IPAC_IDTAG_SWVERSION, 1))
296 ud->swversion = talloc_strdup(ud, (char *)
297 TLVP_VAL(tp, IPAC_IDTAG_SWVERSION));
298
299 if (TLVP_PRES_LEN(tp, IPAC_IDTAG_MACADDR, 17)) {
300 rc = osmo_macaddr_parse(ud->mac_addr, (char *)
301 TLVP_VAL(tp, IPAC_IDTAG_MACADDR));
302 if (rc < 0)
303 goto out;
304 }
305
306 if (TLVP_PRES_LEN(tp, IPAC_IDTAG_UNIT, 1))
Harald Weltee3919962014-08-20 22:28:23 +0200307 rc = ipa_parse_unitid((char *)
Harald Welte28aa9912014-08-20 22:06:04 +0200308 TLVP_VAL(tp, IPAC_IDTAG_UNIT), ud);
309
310out:
311 return rc;
312}
313
Harald Welte7bc88bb2017-04-15 19:05:33 +0200314#define IPA_STRING_MAX 64
315
Neels Hofmeyr87e45502017-06-20 00:17:59 +0200316/*! Generate IPA CCM ID RESP based on list of IEs
Harald Welte7bc88bb2017-04-15 19:05:33 +0200317 * \param[in] dev Descriptor describing identity data for response
318 * \param[in] ies_req List of IEIs to include in response
319 * \param[in] num_ies_req Number of IEIs in \a ies_req
320 * \returns Message buffer with IPA CCM ID RESP */
321struct msgb *ipa_ccm_make_id_resp(const struct ipaccess_unit *dev,
322 const uint8_t *ies_req, unsigned int num_ies_req)
323{
324 struct msgb *msg = ipa_msg_alloc(16);
325 char str[IPA_STRING_MAX];
326 unsigned int i;
327
328 if (!msg)
329 return NULL;
330
331 *msgb_put(msg, 1) = IPAC_MSGT_ID_RESP;
332
333 for (i = 0; i < num_ies_req; i++) {
334 uint8_t *tag;
335
336 str[0] = '\0';
337 switch (ies_req[i]) {
338 case IPAC_IDTAG_UNIT:
339 snprintf(str, sizeof(str), "%u/%u/%u",
340 dev->site_id, dev->bts_id, dev->trx_id);
341 break;
342 case IPAC_IDTAG_MACADDR:
343 snprintf(str, sizeof(str),
344 "%02x:%02x:%02x:%02x:%02x:%02x",
345 dev->mac_addr[0], dev->mac_addr[1],
346 dev->mac_addr[2], dev->mac_addr[3],
347 dev->mac_addr[4], dev->mac_addr[5]);
348 break;
349 case IPAC_IDTAG_LOCATION1:
350 if (dev->location1)
Neels Hofmeyrebe4ef72018-07-26 17:12:07 +0200351 osmo_strlcpy(str, dev->location1, sizeof(str));
Harald Welte7bc88bb2017-04-15 19:05:33 +0200352 break;
353 case IPAC_IDTAG_LOCATION2:
354 if (dev->location2)
Neels Hofmeyrebe4ef72018-07-26 17:12:07 +0200355 osmo_strlcpy(str, dev->location2, sizeof(str));
Harald Welte7bc88bb2017-04-15 19:05:33 +0200356 break;
357 case IPAC_IDTAG_EQUIPVERS:
358 if (dev->equipvers)
Neels Hofmeyrebe4ef72018-07-26 17:12:07 +0200359 osmo_strlcpy(str, dev->equipvers, sizeof(str));
Harald Welte7bc88bb2017-04-15 19:05:33 +0200360 break;
361 case IPAC_IDTAG_SWVERSION:
362 if (dev->swversion)
Neels Hofmeyrebe4ef72018-07-26 17:12:07 +0200363 osmo_strlcpy(str, dev->swversion, sizeof(str));
Harald Welte7bc88bb2017-04-15 19:05:33 +0200364 break;
365 case IPAC_IDTAG_UNITNAME:
366 if (dev->unit_name) {
Neels Hofmeyrebe4ef72018-07-26 17:12:07 +0200367 snprintf(str, sizeof(str), "%s", dev->unit_name);
Harald Welte7bc88bb2017-04-15 19:05:33 +0200368 } else {
369 snprintf(str, sizeof(str),
370 "%02x-%02x-%02x-%02x-%02x-%02x",
371 dev->mac_addr[0], dev->mac_addr[1],
372 dev->mac_addr[2], dev->mac_addr[3],
373 dev->mac_addr[4], dev->mac_addr[5]);
374 }
375 break;
376 case IPAC_IDTAG_SERNR:
377 if (dev->serno)
Neels Hofmeyrebe4ef72018-07-26 17:12:07 +0200378 osmo_strlcpy(str, dev->serno, sizeof(str));
Harald Welte7bc88bb2017-04-15 19:05:33 +0200379 break;
380 default:
381 LOGP(DLINP, LOGL_NOTICE,
382 "Unknown ipaccess tag 0x%02x\n", ies_req[i]);
383 msgb_free(msg);
384 return NULL;
385 }
Harald Welte7bc88bb2017-04-15 19:05:33 +0200386
387 LOGP(DLINP, LOGL_INFO, " tag %d: %s\n", ies_req[i], str);
388 tag = msgb_put(msg, 3 + strlen(str) + 1);
389 tag[0] = 0x00;
390 tag[1] = 1 + strlen(str) + 1;
Harald Weltea5458422021-04-29 18:39:52 +0200391 tag[2] = ies_req[i];
Harald Welte7bc88bb2017-04-15 19:05:33 +0200392 memcpy(tag + 3, str, strlen(str) + 1);
393 }
394 ipa_prepend_header(msg, IPAC_PROTO_IPACCESS);
395 return msg;
396}
397
Neels Hofmeyr87e45502017-06-20 00:17:59 +0200398/*! Generate IPA CCM ID RESP based on requets payload
Harald Welte7bc88bb2017-04-15 19:05:33 +0200399 * \param[in] dev Descriptor describing identity data for response
400 * \param[in] data Payload of the IPA CCM ID GET request
401 * \param[in] len Length of \a data in octets
402 * \returns Message buffer with IPA CCM ID RESP */
403struct msgb *ipa_ccm_make_id_resp_from_req(const struct ipaccess_unit *dev,
404 const uint8_t *data, unsigned int len)
405{
406 uint8_t ies[len/2];
407 unsigned int num_ies = 0;
408 const uint8_t *cur = data;
409
Harald Welte8a4895c2017-04-27 10:25:10 +0200410 memset(ies, 0, sizeof(ies));
411
Harald Welte7bc88bb2017-04-15 19:05:33 +0200412 /* build a array of the IEIs */
413 while (len >= 2) {
414 uint8_t t_len, t_tag;
Harald Welteb189b5f2021-04-29 18:38:48 +0200415 len -= 2; /* subtract the length of the two bytes read below */
Harald Welte7bc88bb2017-04-15 19:05:33 +0200416 t_len = *cur++;
417 t_tag = *cur++;
418
Harald Welteb189b5f2021-04-29 18:38:48 +0200419 /* as the 'tag' is included in the length of t_len, this cannot happen */
420 if (t_len == 0)
421 break;
422
Harald Welte7bc88bb2017-04-15 19:05:33 +0200423 if (t_len > len + 1) {
Thorsten Alteholz5a9dbf82018-04-08 19:13:25 +0200424 LOGP(DLINP, LOGL_ERROR, "IPA CCM tag 0x%02x does not fit\n", t_tag);
Harald Welte7bc88bb2017-04-15 19:05:33 +0200425 break;
426 }
427
428 ies[num_ies++] = t_tag;
429
Harald Welteb189b5f2021-04-29 18:38:48 +0200430 /* we need to subtract one from t_len to account for the tag */
431 cur += t_len - 1;
Harald Welte0b2c0ec2018-04-16 22:53:48 +0200432 /* prevent any unsigned integer underflow due to somebody sending us
433 * messages with wrong length values */
434 if (len <= t_len)
Harald Welte0b2c0ec2018-04-16 22:53:48 +0200435 len = 0;
Harald Welte539272d2021-04-29 15:52:38 +0200436 else
Harald Welteb189b5f2021-04-29 18:38:48 +0200437 len -= t_len - 1;
Harald Welte7bc88bb2017-04-15 19:05:33 +0200438 }
439 return ipa_ccm_make_id_resp(dev, ies, num_ies);
440}
441
Harald Weltee3919962014-08-20 22:28:23 +0200442int ipa_send(int fd, const void *msg, size_t msglen)
Harald Welte28aa9912014-08-20 22:06:04 +0200443{
444 int ret;
445
446 ret = write(fd, msg, msglen);
447 if (ret < 0)
Jacob Erlbecka6be2242014-12-22 10:58:46 +0100448 return -errno;
Harald Welte28aa9912014-08-20 22:06:04 +0200449 if (ret < msglen) {
Harald Weltee3919962014-08-20 22:28:23 +0200450 LOGP(DLINP, LOGL_ERROR, "ipa_send: short write\n");
Harald Welte28aa9912014-08-20 22:06:04 +0200451 return -EIO;
452 }
453 return ret;
454}
455
Harald Weltee3919962014-08-20 22:28:23 +0200456int ipa_ccm_send_pong(int fd)
Harald Welte28aa9912014-08-20 22:06:04 +0200457{
Harald Weltee3919962014-08-20 22:28:23 +0200458 return ipa_send(fd, ipa_pong_msg, sizeof(ipa_pong_msg));
Harald Welte28aa9912014-08-20 22:06:04 +0200459}
460
Harald Weltee3919962014-08-20 22:28:23 +0200461int ipa_ccm_send_id_ack(int fd)
Harald Welte28aa9912014-08-20 22:06:04 +0200462{
Harald Weltee3919962014-08-20 22:28:23 +0200463 return ipa_send(fd, ipa_id_ack_msg, sizeof(ipa_id_ack_msg));
Harald Welte28aa9912014-08-20 22:06:04 +0200464}
465
Harald Weltee3919962014-08-20 22:28:23 +0200466int ipa_ccm_send_id_req(int fd)
Harald Welte28aa9912014-08-20 22:06:04 +0200467{
Harald Weltee3919962014-08-20 22:28:23 +0200468 return ipa_send(fd, ipa_id_req_msg, sizeof(ipa_id_req_msg));
Harald Welte28aa9912014-08-20 22:06:04 +0200469}
470
471/* base handling of the ip.access protocol */
Harald Weltee3919962014-08-20 22:28:23 +0200472int ipa_ccm_rcvmsg_base(struct msgb *msg, struct osmo_fd *bfd)
Harald Welte28aa9912014-08-20 22:06:04 +0200473{
474 uint8_t msg_type = *(msg->l2h);
475 int ret;
476
477 switch (msg_type) {
478 case IPAC_MSGT_PING:
Harald Weltee3919962014-08-20 22:28:23 +0200479 ret = ipa_ccm_send_pong(bfd->fd);
Harald Welte28aa9912014-08-20 22:06:04 +0200480 if (ret < 0) {
Vadim Yanitskiy403dfbc2023-07-05 00:54:06 +0700481 LOGP(DLINP, LOGL_ERROR, "Cannot send PONG "
Harald Welte28aa9912014-08-20 22:06:04 +0200482 "message. Reason: %s\n", strerror(errno));
483 break;
484 }
485 ret = 1;
486 break;
487 case IPAC_MSGT_PONG:
488 DEBUGP(DLMI, "PONG!\n");
489 ret = 1;
490 break;
491 case IPAC_MSGT_ID_ACK:
492 DEBUGP(DLMI, "ID_ACK? -> ACK!\n");
Harald Weltee3919962014-08-20 22:28:23 +0200493 ret = ipa_ccm_send_id_ack(bfd->fd);
Harald Welte28aa9912014-08-20 22:06:04 +0200494 if (ret < 0) {
495 LOGP(DLINP, LOGL_ERROR, "Cannot send ID_ACK "
496 "message. Reason: %s\n", strerror(errno));
497 break;
498 }
499 ret = 1;
500 break;
501 default:
502 /* This is not an IPA PING, PONG or ID_ACK message */
503 ret = 0;
504 break;
505 }
506 return ret;
507}
508
509/* base handling of the ip.access protocol */
Harald Weltee3919962014-08-20 22:28:23 +0200510int ipa_ccm_rcvmsg_bts_base(struct msgb *msg, struct osmo_fd *bfd)
Harald Welte28aa9912014-08-20 22:06:04 +0200511{
512 uint8_t msg_type = *(msg->l2h);
513 int ret = 0;
514
515 switch (msg_type) {
516 case IPAC_MSGT_PING:
Harald Weltee3919962014-08-20 22:28:23 +0200517 ret = ipa_ccm_send_pong(bfd->fd);
Harald Welte28aa9912014-08-20 22:06:04 +0200518 if (ret < 0) {
519 LOGP(DLINP, LOGL_ERROR, "Cannot send PONG "
520 "message. Reason: %s\n", strerror(errno));
521 }
522 break;
523 case IPAC_MSGT_PONG:
524 DEBUGP(DLMI, "PONG!\n");
525 break;
526 case IPAC_MSGT_ID_ACK:
527 DEBUGP(DLMI, "ID_ACK\n");
528 break;
529 }
530 return ret;
531}
532
533
Harald Weltee3919962014-08-20 22:28:23 +0200534void ipa_prepend_header_ext(struct msgb *msg, int proto)
Harald Welte28aa9912014-08-20 22:06:04 +0200535{
536 struct ipaccess_head_ext *hh_ext;
537
538 /* prepend the osmo ip.access header extension */
539 hh_ext = (struct ipaccess_head_ext *) msgb_push(msg, sizeof(*hh_ext));
540 hh_ext->proto = proto;
541}
542
Harald Weltee3919962014-08-20 22:28:23 +0200543void ipa_prepend_header(struct msgb *msg, int proto)
Harald Welte28aa9912014-08-20 22:06:04 +0200544{
545 struct ipaccess_head *hh;
546
547 /* prepend the ip.access header */
548 hh = (struct ipaccess_head *) msgb_push(msg, sizeof(*hh));
Harald Welte95871da2017-05-15 12:11:36 +0200549 hh->len = osmo_htons(msg->len - sizeof(*hh));
Harald Welte28aa9912014-08-20 22:06:04 +0200550 hh->proto = proto;
551}
552
Harald Welte20725b92017-05-15 12:50:04 +0200553#ifdef HAVE_SYS_SOCKET_H
554#include <sys/socket.h>
555
Pau Espin Pedrol8a757d22018-08-22 14:12:01 +0200556/*! Read one ipa message from socket fd without caching not fully received
557 * messages. See \ref ipa_msg_recv_buffered for further information.
558 */
Harald Welte28aa9912014-08-20 22:06:04 +0200559int ipa_msg_recv(int fd, struct msgb **rmsg)
560{
561 int rc = ipa_msg_recv_buffered(fd, rmsg, NULL);
562 if (rc < 0) {
563 errno = -rc;
564 rc = -1;
565 }
566 return rc;
567}
568
Pau Espin Pedrol8a757d22018-08-22 14:12:01 +0200569/*! Read one ipa message from socket fd or store part if still not fully received.
570 * \param[in] fd The fd for the socket to read from.
571 * \param[out] rmsg internally allocated msgb containing a fully received ipa message.
572 * \param[inout] tmp_msg internally allocated msgb caching data for not yet fully received message.
573 *
574 * As ipa can run on top of stream based protocols such as TCP, there's the
575 * possibility that such lower layers split ipa messages in several low level
576 * packets. If a low layer packet is received containing several ipa frames,
577 * this function will pull from the socket and return only the first one
578 * available in the stream. As the socket will remain with data, it will
579 * trigger again during next select() and then this function will fetch the
580 * next ipa message, and so on.
581 *
582 * \returns -EAGAIN and allocated tmp_msg if message was not yet fully
583 * received. Other negative values indicate an error and cached msgb will be
584 * freed. 0 if socket is found dead. Positive value indicating l2 msgb len and
585 * rmsg pointing to internally allocated msgb containing the ipa frame on
586 * scucess.
587 */
Harald Welte28aa9912014-08-20 22:06:04 +0200588int ipa_msg_recv_buffered(int fd, struct msgb **rmsg, struct msgb **tmp_msg)
589{
590 struct msgb *msg = tmp_msg ? *tmp_msg : NULL;
591 struct ipaccess_head *hh;
592 int len, ret;
593 int needed;
594
595 if (msg == NULL) {
596 msg = ipa_msg_alloc(0);
597 if (msg == NULL) {
598 ret = -ENOMEM;
599 goto discard_msg;
600 }
601 msg->l1h = msg->tail;
602 }
603
604 if (msg->l2h == NULL) {
605 /* first read our 3-byte header */
606 needed = sizeof(*hh) - msg->len;
607 ret = recv(fd, msg->tail, needed, 0);
608 if (ret == 0)
609 goto discard_msg;
610
611 if (ret < 0) {
612 if (errno == EAGAIN || errno == EINTR)
613 ret = 0;
614 else {
615 ret = -errno;
616 goto discard_msg;
617 }
618 }
619
620 msgb_put(msg, ret);
621
622 if (ret < needed) {
623 if (msg->len == 0) {
624 ret = -EAGAIN;
625 goto discard_msg;
626 }
627
628 LOGP(DLINP, LOGL_INFO,
Harald Weltef196a022014-08-21 09:42:03 +0200629 "Received part of IPA message header (%d/%zu)\n",
Harald Welte28aa9912014-08-20 22:06:04 +0200630 msg->len, sizeof(*hh));
631 if (!tmp_msg) {
632 ret = -EIO;
633 goto discard_msg;
634 }
635 *tmp_msg = msg;
636 return -EAGAIN;
637 }
638
639 msg->l2h = msg->tail;
640 }
641
642 hh = (struct ipaccess_head *) msg->data;
643
644 /* then read the length as specified in header */
Harald Welte95871da2017-05-15 12:11:36 +0200645 len = osmo_ntohs(hh->len);
Harald Welte28aa9912014-08-20 22:06:04 +0200646
647 if (len < 0 || IPA_ALLOC_SIZE < len + sizeof(*hh)) {
648 LOGP(DLINP, LOGL_ERROR, "bad message length of %d bytes, "
649 "received %d bytes\n", len, msg->len);
650 ret = -EIO;
651 goto discard_msg;
652 }
653
654 needed = len - msgb_l2len(msg);
655
656 if (needed > 0) {
657 ret = recv(fd, msg->tail, needed, 0);
658
659 if (ret == 0)
660 goto discard_msg;
661
662 if (ret < 0) {
663 if (errno == EAGAIN || errno == EINTR)
664 ret = 0;
665 else {
666 ret = -errno;
667 goto discard_msg;
668 }
669 }
670
671 msgb_put(msg, ret);
672
673 if (ret < needed) {
674 LOGP(DLINP, LOGL_INFO,
675 "Received part of IPA message L2 data (%d/%d)\n",
676 msgb_l2len(msg), len);
677 if (!tmp_msg) {
678 ret = -EIO;
679 goto discard_msg;
680 }
681 *tmp_msg = msg;
682 return -EAGAIN;
683 }
684 }
685
686 ret = msgb_l2len(msg);
687
688 if (ret == 0) {
689 LOGP(DLINP, LOGL_INFO,
690 "Discarding IPA message without payload\n");
691 ret = -EAGAIN;
692 goto discard_msg;
693 }
694
695 if (tmp_msg)
696 *tmp_msg = NULL;
697 *rmsg = msg;
698 return ret;
699
700discard_msg:
701 if (tmp_msg)
702 *tmp_msg = NULL;
703 msgb_free(msg);
704 return ret;
705}
706
Harald Welte20725b92017-05-15 12:50:04 +0200707#endif /* SYS_SOCKET_H */
708
Harald Welte28aa9912014-08-20 22:06:04 +0200709struct msgb *ipa_msg_alloc(int headroom)
710{
711 struct msgb *nmsg;
712
713 headroom += sizeof(struct ipaccess_head);
714
Neels Hofmeyr889ab162017-09-07 20:41:12 +0200715 nmsg = msgb_alloc_headroom(1200 + headroom, headroom, "IPA Multiplex");
Harald Welte28aa9912014-08-20 22:06:04 +0200716 if (!nmsg)
717 return NULL;
718 return nmsg;
719}
Harald Welte96e2a002017-06-12 21:44:18 +0200720
721/*! @} */