blob: db28f0dc6d405de885b8733ba1f04030ee9a2640 [file] [log] [blame]
Neels Hofmeyr17518fe2017-06-20 04:35:06 +02001/*! \file gsm0480.c
2 * Format functions for GSM 04.80. */
Holger Hans Peter Freyther55aea502010-09-30 18:30:41 +08003/*
4 * (C) 2010 by Holger Hans Peter Freyther <zecke@selfish.org>
5 * (C) 2009 by Mike Haben <michael.haben@btinternet.com>
Harald Welteb1a35d62018-06-16 18:34:52 +02006 * (C) 2018 by Harald Welte <laforge@gnumonks.org>
Holger Hans Peter Freyther55aea502010-09-30 18:30:41 +08007 *
8 * All Rights Reserved
9 *
Harald Weltee08da972017-11-13 01:00:26 +090010 * SPDX-License-Identifier: GPL-2.0+
11 *
Holger Hans Peter Freyther55aea502010-09-30 18:30:41 +080012 * This program is free software; you can redistribute it and/or modify
13 * it under the terms of the GNU General Public License as published by
14 * the Free Software Foundation; either version 2 of the License, or
15 * (at your option) any later version.
16 *
17 * This program is distributed in the hope that it will be useful,
18 * but WITHOUT ANY WARRANTY; without even the implied warranty of
19 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
20 * GNU General Public License for more details.
21 *
22 * You should have received a copy of the GNU General Public License along
23 * with this program; if not, write to the Free Software Foundation, Inc.,
24 * 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
25 *
26 */
27
Pablo Neira Ayuso83419342011-03-22 16:36:13 +010028#include <osmocom/gsm/gsm0480.h>
29#include <osmocom/gsm/gsm_utils.h>
Holger Hans Peter Freyther55aea502010-09-30 18:30:41 +080030
Pablo Neira Ayuso83419342011-03-22 16:36:13 +010031#include <osmocom/core/logging.h>
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +080032
Pablo Neira Ayuso83419342011-03-22 16:36:13 +010033#include <osmocom/gsm/protocol/gsm_04_08.h>
34#include <osmocom/gsm/protocol/gsm_04_80.h>
Holger Hans Peter Freyther55aea502010-09-30 18:30:41 +080035
36#include <string.h>
Vadim Yanitskiy52e44122018-06-11 03:51:11 +070037#include <errno.h>
Holger Hans Peter Freyther55aea502010-09-30 18:30:41 +080038
Harald Welteb1a35d62018-06-16 18:34:52 +020039const struct value_string gsm0480_comp_type_names[] = {
40 { GSM0480_CTYPE_INVOKE, "Invoke" },
41 { GSM0480_CTYPE_RETURN_RESULT, "ReturnResult" },
42 { GSM0480_CTYPE_RETURN_ERROR, "ReturnError" },
43 { GSM0480_CTYPE_REJECT, "Reject" },
44 { 0, NULL }
45};
46
47const struct value_string gsm0480_op_code_names[] = {
48 { GSM0480_OP_CODE_REGISTER_SS, "RegisterSS" },
49 { GSM0480_OP_CODE_ERASE_SS, "EraseSS" },
50 { GSM0480_OP_CODE_ACTIVATE_SS, "ActivateSS" },
51 { GSM0480_OP_CODE_DEACTIVATE_SS, "DeactivateSS" },
52 { GSM0480_OP_CODE_INTERROGATE_SS, "IngerrogateSS" },
53 { GSM0480_OP_CODE_NOTIFY_SS, "NotifySS" },
54 { GSM0480_OP_CODE_REGISTER_PASSWORD, "RegisterPassword" },
55 { GSM0480_OP_CODE_GET_PASSWORD, "GetPassword" },
56 { GSM0480_OP_CODE_PROCESS_USS_DATA, "ProcessUSSD" },
57 { GSM0480_OP_CODE_FORWARD_CHECK_SS_IND, "ForwardChecckSSind" },
58 { GSM0480_OP_CODE_PROCESS_USS_REQ, "ProcessUssReq" },
59 { GSM0480_OP_CODE_USS_REQUEST, "UssRequest" },
60 { GSM0480_OP_CODE_USS_NOTIFY, "UssNotify" },
61 { GSM0480_OP_CODE_FORWARD_CUG_INFO, "ForwardCugInfo" },
62 { GSM0480_OP_CODE_SPLIT_MPTY, "SplitMPTY" },
63 { GSM0480_OP_CODE_RETRIEVE_MPTY, "RetrieveMPTY" },
64 { GSM0480_OP_CODE_HOLD_MPTY, "HoldMPTY" },
65 { GSM0480_OP_CODE_BUILD_MPTY, "BuildMPTY" },
66 { GSM0480_OP_CODE_FORWARD_CHARGE_ADVICE, "ForwardChargeAdvice" },
67 { 0, NULL }
68};
69
Holger Hans Peter Freyther55aea502010-09-30 18:30:41 +080070static inline unsigned char *msgb_wrap_with_TL(struct msgb *msgb, uint8_t tag)
71{
72 uint8_t *data = msgb_push(msgb, 2);
73
74 data[0] = tag;
75 data[1] = msgb->len - 2;
76 return data;
77}
78
79static inline unsigned char *msgb_push_TLV1(struct msgb *msgb, uint8_t tag,
80 uint8_t value)
81{
82 uint8_t *data = msgb_push(msgb, 3);
83
84 data[0] = tag;
85 data[1] = 1;
86 data[2] = value;
87 return data;
88}
89
90/* wrap an invoke around it... the other way around
91 *
92 * 1.) Invoke Component tag
93 * 2.) Invoke ID Tag
94 * 3.) Operation
95 * 4.) Data
96 */
97int gsm0480_wrap_invoke(struct msgb *msg, int op, int link_id)
98{
99 /* 3. operation */
100 msgb_push_TLV1(msg, GSM0480_OPERATION_CODE, op);
101
102 /* 2. invoke id tag */
103 msgb_push_TLV1(msg, GSM0480_COMPIDTAG_INVOKE_ID, link_id);
104
105 /* 1. component tag */
106 msgb_wrap_with_TL(msg, GSM0480_CTYPE_INVOKE);
107
108 return 0;
109}
110
111/* wrap the GSM 04.08 Facility IE around it */
112int gsm0480_wrap_facility(struct msgb *msg)
113{
114 msgb_wrap_with_TL(msg, GSM0480_IE_FACILITY);
115
116 return 0;
117}
118
119struct msgb *gsm0480_create_unstructuredSS_Notify(int alertPattern, const char *text)
120{
121 struct msgb *msg;
122 uint8_t *seq_len_ptr, *ussd_len_ptr, *data;
Holger Hans Peter Freyther47aa4822013-07-07 13:54:53 +0200123 int len;
Holger Hans Peter Freyther55aea502010-09-30 18:30:41 +0800124
125 msg = msgb_alloc_headroom(1024, 128, "GSM 04.80");
126 if (!msg)
127 return NULL;
128
129 /* SEQUENCE { */
130 msgb_put_u8(msg, GSM_0480_SEQUENCE_TAG);
131 seq_len_ptr = msgb_put(msg, 1);
132
133 /* DCS { */
134 msgb_put_u8(msg, ASN1_OCTET_STRING_TAG);
135 msgb_put_u8(msg, 1);
136 msgb_put_u8(msg, 0x0F);
137 /* } DCS */
138
139 /* USSD-String { */
140 msgb_put_u8(msg, ASN1_OCTET_STRING_TAG);
141 ussd_len_ptr = msgb_put(msg, 1);
142 data = msgb_put(msg, 0);
Jacob Erlbeck1d7f3b52013-08-12 17:07:53 +0200143 gsm_7bit_encode_n_ussd(data, msgb_tailroom(msg), text, &len);
Holger Hans Peter Freyther47aa4822013-07-07 13:54:53 +0200144 msgb_put(msg, len);
145 ussd_len_ptr[0] = len;
Holger Hans Peter Freyther55aea502010-09-30 18:30:41 +0800146 /* USSD-String } */
147
148 /* alertingPattern { */
149 msgb_put_u8(msg, ASN1_OCTET_STRING_TAG);
150 msgb_put_u8(msg, 1);
151 msgb_put_u8(msg, alertPattern);
152 /* } alertingPattern */
153
154 seq_len_ptr[0] = 3 + 2 + ussd_len_ptr[0] + 3;
155 /* } SEQUENCE */
156
157 return msg;
158}
159
160struct msgb *gsm0480_create_notifySS(const char *text)
161{
162 struct msgb *msg;
163 uint8_t *data, *tmp_len;
164 uint8_t *seq_len_ptr, *cal_len_ptr, *opt_len_ptr, *nam_len_ptr;
Holger Hans Peter Freyther47aa4822013-07-07 13:54:53 +0200165 int len;
Holger Hans Peter Freyther55aea502010-09-30 18:30:41 +0800166
167 len = strlen(text);
168 if (len < 1 || len > 160)
169 return NULL;
170
171 msg = msgb_alloc_headroom(1024, 128, "GSM 04.80");
172 if (!msg)
173 return NULL;
174
175 msgb_put_u8(msg, GSM_0480_SEQUENCE_TAG);
176 seq_len_ptr = msgb_put(msg, 1);
177
178 /* ss_code for CNAP { */
179 msgb_put_u8(msg, 0x81);
180 msgb_put_u8(msg, 1);
181 msgb_put_u8(msg, 0x19);
182 /* } ss_code */
183
184
185 /* nameIndicator { */
186 msgb_put_u8(msg, 0xB4);
187 nam_len_ptr = msgb_put(msg, 1);
188
189 /* callingName { */
190 msgb_put_u8(msg, 0xA0);
191 opt_len_ptr = msgb_put(msg, 1);
192 msgb_put_u8(msg, 0xA0);
193 cal_len_ptr = msgb_put(msg, 1);
194
195 /* namePresentationAllowed { */
196 /* add the DCS value */
197 msgb_put_u8(msg, 0x80);
198 msgb_put_u8(msg, 1);
199 msgb_put_u8(msg, 0x0F);
200
201 /* add the lengthInCharacters */
202 msgb_put_u8(msg, 0x81);
203 msgb_put_u8(msg, 1);
204 msgb_put_u8(msg, strlen(text));
205
206 /* add the actual string */
207 msgb_put_u8(msg, 0x82);
208 tmp_len = msgb_put(msg, 1);
209 data = msgb_put(msg, 0);
Jacob Erlbeck1d7f3b52013-08-12 17:07:53 +0200210 gsm_7bit_encode_n_ussd(data, msgb_tailroom(msg), text, &len);
Holger Hans Peter Freyther47aa4822013-07-07 13:54:53 +0200211 tmp_len[0] = len;
212 msgb_put(msg, len);
Holger Hans Peter Freyther55aea502010-09-30 18:30:41 +0800213
214 /* }; namePresentationAllowed */
215
Holger Hans Peter Freyther47aa4822013-07-07 13:54:53 +0200216 cal_len_ptr[0] = 3 + 3 + 2 + len;
Holger Hans Peter Freyther55aea502010-09-30 18:30:41 +0800217 opt_len_ptr[0] = cal_len_ptr[0] + 2;
218 /* }; callingName */
219
220 nam_len_ptr[0] = opt_len_ptr[0] + 2;
221 /* ); nameIndicator */
222
223 /* write the lengths... */
224 seq_len_ptr[0] = 3 + nam_len_ptr[0] + 2;
225
226 return msg;
227}
228
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800229/* Forward declarations */
Tobias Engel419684e2012-03-08 13:31:52 +0100230static int parse_ss(const struct gsm48_hdr *hdr,
231 uint16_t len, struct ss_request *req);
Vadim Yanitskiyc30431f2017-07-29 04:47:42 +0600232static int parse_ss_facility(const uint8_t *ss_facility, uint16_t len,
233 struct ss_request *req);
Vadim Yanitskiyb41c70f2018-01-17 12:10:07 +0600234static int parse_ss_info_elements(const uint8_t *ss_ie, uint16_t len,
Tobias Engel419684e2012-03-08 13:31:52 +0100235 struct ss_request *req);
Holger Hans Peter Freyther49ad5002010-10-11 09:06:47 +0200236static int parse_ss_invoke(const uint8_t *invoke_data, uint16_t length,
Tobias Engel419684e2012-03-08 13:31:52 +0100237 struct ss_request *req);
Vadim Yanitskiy7f16c442017-07-29 05:05:54 +0600238static int parse_ss_return_result(const uint8_t *rr_data, uint16_t length,
239 struct ss_request *req);
240static int parse_process_uss_data(const uint8_t *uss_req_data, uint16_t length,
241 struct ss_request *req);
Holger Hans Peter Freyther49ad5002010-10-11 09:06:47 +0200242static int parse_process_uss_req(const uint8_t *uss_req_data, uint16_t length,
Tobias Engel419684e2012-03-08 13:31:52 +0100243 struct ss_request *req);
244static int parse_ss_for_bs_req(const uint8_t *ss_req_data,
245 uint16_t length,
246 struct ss_request *req);
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800247
Vadim Yanitskiy52e44122018-06-11 03:51:11 +0700248/*! Get pointer to the IE of a given type
249 * \param[in] hdr Pointer to the message starting from header
250 * \param[in] msg_len Length of the whole message + header
251 * \param[out] ie External pointer to be set
252 * \param[out] ie_len External IE length variable
253 * \param[in] ie_tag Tag value of the required IE
254 * \returns 0 in case of success, otherwise -ERRNO
255 *
256 * This function iterates over existing IEs within a given
257 * message (depending on its type), and looks for the one with
258 * given \ref ie_tag value. If the IE is found, the external
259 * pointer pointed by \ref ie will be set to its value part
260 * (omitting TL), and \ref ie_len will be set to the length.
261 * Otherwise, e.g. in case of parsing error, both \ref ie
262 * and \ref ie_len are set to NULL and 0 respectively.
263 */
264int gsm0480_extract_ie_by_tag(const struct gsm48_hdr *hdr, uint16_t msg_len,
265 uint8_t **ie, uint16_t *ie_len, uint8_t ie_tag)
266{
267 uint8_t pdisc, msg_type;
268 uint8_t *tlv, len;
269
270 /* Init external variables */
271 *ie_len = 0;
272 *ie = NULL;
273
274 /* Drop incomplete / corrupted messages */
275 if (msg_len < sizeof(*hdr))
276 return -EINVAL;
277
278 pdisc = gsm48_hdr_pdisc(hdr);
279 msg_type = gsm48_hdr_msg_type(hdr);
280
281 /* Drop non-SS related messages */
282 if (pdisc != GSM48_PDISC_NC_SS)
283 return -EINVAL;
284
285 len = msg_len - sizeof(*hdr);
286 tlv = (uint8_t *) hdr->data;
287
288 /* Parse a message depending on its type */
289 switch (msg_type) {
290 /* See table 2.5: RELEASE COMPLETE message content */
291 case GSM0480_MTYPE_RELEASE_COMPLETE:
292 /* See tables 2.3 and 2.4: REGISTER message content */
293 case GSM0480_MTYPE_REGISTER:
294 /* Iterate over TLV-based IEs */
295 while (len > 2) {
296 if (tlv[0] == ie_tag) {
297 *ie_len = tlv[1];
298 *ie = tlv + 2;
299 return 0;
300 }
301
302 len -= tlv[1] + 2;
303 tlv += tlv[1] + 2;
304 continue;
305 }
306
307 /* The Facility IE is mandatory for REGISTER */
308 if (msg_type == GSM0480_MTYPE_REGISTER)
309 if (ie_tag == GSM0480_IE_FACILITY)
310 return -EINVAL;
311 break;
312
313 /* See table 2.2: FACILITY message content */
314 case GSM0480_MTYPE_FACILITY:
315 /* There is no other IEs */
316 if (ie_tag != GSM0480_IE_FACILITY)
317 break;
318
319 /* Mandatory LV-based Facility IE */
320 if (len < 2)
321 return -EINVAL;
322
323 *ie_len = tlv[0];
324 *ie = tlv + 1;
325 return 0;
326
327 default:
328 /* Wrong message type, out of specs */
329 return -EINVAL;
330 }
331
332 return 0;
333}
334
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800335/* Decode a mobile-originated USSD-request message */
Holger Hans Peter Freytherdaa653f2010-10-11 07:56:06 +0200336int gsm0480_decode_ussd_request(const struct gsm48_hdr *hdr, uint16_t len,
337 struct ussd_request *req)
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800338{
Tobias Engel419684e2012-03-08 13:31:52 +0100339 struct ss_request ss;
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800340 int rc = 0;
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800341
Tobias Engel419684e2012-03-08 13:31:52 +0100342 memset(&ss, 0, sizeof(ss));
343
Holger Hans Peter Freyther8ac04862010-10-11 08:08:58 +0200344 if (len < sizeof(*hdr) + 2) {
345 LOGP(0, LOGL_DEBUG, "USSD Request is too short.\n");
346 return 0;
347 }
348
Neels Hofmeyr282e9082016-03-14 16:06:46 +0100349 if (gsm48_hdr_pdisc(hdr) == GSM48_PDISC_NC_SS) {
Holger Hans Peter Freytherdaa653f2010-10-11 07:56:06 +0200350 req->transaction_id = hdr->proto_discr & 0x70;
Tobias Engel419684e2012-03-08 13:31:52 +0100351
352 ss.transaction_id = req->transaction_id;
Vadim Yanitskiy7689e0f2018-01-17 03:23:39 +0600353 rc = parse_ss(hdr, len - sizeof(*hdr), &ss);
Tobias Engel419684e2012-03-08 13:31:52 +0100354
355 /* convert from ss_request to legacy ussd_request */
356 req->transaction_id = ss.transaction_id;
357 req->invoke_id = ss.invoke_id;
358 if (ss.ussd_text[0] == 0xFF)
359 req->text[0] = '\0';
360 else {
361 memcpy(req->text, ss.ussd_text, sizeof(req->text));
362 req->text[sizeof(req->text)-1] = '\0';
363 }
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800364 }
365
366 if (!rc)
367 LOGP(0, LOGL_DEBUG, "Error occurred while parsing received USSD!\n");
368
369 return rc;
370}
371
Tobias Engel419684e2012-03-08 13:31:52 +0100372/* Decode a mobile-originated SS request message */
373int gsm0480_decode_ss_request(const struct gsm48_hdr *hdr, uint16_t len,
374 struct ss_request *req)
375{
Vadim Yanitskiyf07c58c2018-01-17 03:42:16 +0600376 uint8_t pdisc;
Tobias Engel419684e2012-03-08 13:31:52 +0100377
Vadim Yanitskiyf07c58c2018-01-17 03:42:16 +0600378 /**
379 * Check Protocol Discriminator
380 * see TS GSM 04.07 and GSM 04.80
381 */
382 pdisc = gsm48_hdr_pdisc(hdr);
383 if (pdisc != GSM48_PDISC_NC_SS) {
384 LOGP(0, LOGL_ERROR, "Dropping message with "
385 "unsupported pdisc=%02x\n", pdisc);
386 return 0;
Tobias Engel419684e2012-03-08 13:31:52 +0100387 }
388
Vadim Yanitskiyf07c58c2018-01-17 03:42:16 +0600389 /* GSM 04.80 3.3 Transaction Identifier */
390 req->transaction_id = hdr->proto_discr & 0x70;
Tobias Engel419684e2012-03-08 13:31:52 +0100391
Vadim Yanitskiyf07c58c2018-01-17 03:42:16 +0600392 /* Parse SS request */
393 return parse_ss(hdr, len - sizeof(*hdr), req);
Tobias Engel419684e2012-03-08 13:31:52 +0100394}
395
396static int parse_ss(const struct gsm48_hdr *hdr, uint16_t len, struct ss_request *req)
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800397{
398 int rc = 1;
Neels Hofmeyra95ee5e2016-10-10 22:46:20 +0200399 uint8_t msg_type = hdr->msg_type & 0x3F; /* message-type - section 3.4 */
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800400
Vadim Yanitskiyfd744ce2018-01-17 03:31:15 +0600401 /**
402 * GSM 04.80 Section 2.5 'Release complete' Table 2.5
403 * payload is optional for 'RELEASE COMPLETE' message
404 */
405 if (msg_type != GSM0480_MTYPE_RELEASE_COMPLETE) {
406 if (len < 2) {
407 LOGP(0, LOGL_DEBUG, "SS Request is too short.\n");
408 return 0;
409 }
410 }
411
Vadim Yanitskiy44ebb932018-01-17 02:59:46 +0600412 /* Table 2.1: Messages for call independent SS control */
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800413 switch (msg_type) {
414 case GSM0480_MTYPE_RELEASE_COMPLETE:
Tobias Engel419684e2012-03-08 13:31:52 +0100415 LOGP(0, LOGL_DEBUG, "SS Release Complete\n");
Vadim Yanitskiy3cafc062018-01-17 12:28:40 +0600416
Vadim Yanitskiyfb5da892018-04-04 19:25:38 +0700417 /**
418 * Indicates that there is no decoded message.
419 * To be overwriten by the message otherwise.
420 */
421 req->ussd_text[0] = 0xFF;
422
Vadim Yanitskiy3cafc062018-01-17 12:28:40 +0600423 /* Parse optional Cause and/or Facility data */
424 if (len >= 2)
425 rc &= parse_ss_info_elements(&hdr->data[0], len, req);
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800426 break;
427 case GSM0480_MTYPE_REGISTER:
Vadim Yanitskiy7689e0f2018-01-17 03:23:39 +0600428 rc &= parse_ss_info_elements(&hdr->data[0], len, req);
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800429 break;
Vadim Yanitskiyc30431f2017-07-29 04:47:42 +0600430 case GSM0480_MTYPE_FACILITY:
Vadim Yanitskiy7689e0f2018-01-17 03:23:39 +0600431 rc &= parse_ss_facility(&hdr->data[0], len, req);
Vadim Yanitskiyc30431f2017-07-29 04:47:42 +0600432 break;
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800433 default:
434 LOGP(0, LOGL_DEBUG, "Unknown GSM 04.80 message-type field 0x%02x\n",
Holger Hans Peter Freytherdaa653f2010-10-11 07:56:06 +0200435 hdr->msg_type);
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800436 rc = 0;
437 break;
438 }
439
440 return rc;
441}
442
Vadim Yanitskiyc30431f2017-07-29 04:47:42 +0600443static int parse_ss_facility(const uint8_t *ss_facility, uint16_t len,
444 struct ss_request *req)
445{
446 uint8_t facility_length;
447
448 facility_length = ss_facility[0];
449 if (len - 1 < facility_length)
450 return 0;
451
Vadim Yanitskiy5a09f752018-06-11 04:58:53 +0700452 return !gsm0480_parse_facility_ie(ss_facility + 1, facility_length, req);
Vadim Yanitskiyc30431f2017-07-29 04:47:42 +0600453}
454
Tobias Engel419684e2012-03-08 13:31:52 +0100455static int parse_ss_info_elements(const uint8_t *ss_ie, uint16_t len,
456 struct ss_request *req)
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800457{
458 int rc = -1;
459 /* Information Element Identifier - table 3.2 & GSM 04.08 section 10.5 */
Holger Hans Peter Freytherdaa653f2010-10-11 07:56:06 +0200460 uint8_t iei;
461 uint8_t iei_length;
462
Vadim Yanitskiyb92a27f2018-01-17 12:18:27 +0600463 /* We need at least two bytes */
464 if (len < 2)
465 return 0;
466
Tobias Engel419684e2012-03-08 13:31:52 +0100467 iei = ss_ie[0];
468 iei_length = ss_ie[1];
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800469
Holger Hans Peter Freyther8ac04862010-10-11 08:08:58 +0200470 /* If the data does not fit, report an error */
Vadim Yanitskiyb92a27f2018-01-17 12:18:27 +0600471 if (iei_length + 2 > len)
Holger Hans Peter Freyther8ac04862010-10-11 08:08:58 +0200472 return 0;
473
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800474 switch (iei) {
475 case GSM48_IE_CAUSE:
476 break;
477 case GSM0480_IE_FACILITY:
Vadim Yanitskiy5a09f752018-06-11 04:58:53 +0700478 rc = !gsm0480_parse_facility_ie(ss_ie + 2, iei_length, req);
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800479 break;
480 case GSM0480_IE_SS_VERSION:
481 break;
482 default:
483 LOGP(0, LOGL_DEBUG, "Unhandled GSM 04.08 or 04.80 IEI 0x%02x\n",
484 iei);
485 rc = 0;
486 break;
487 }
488
Vadim Yanitskiyb92a27f2018-01-17 12:18:27 +0600489 /* A message may contain multiple IEs */
490 if (iei_length + 2 + 2 < len)
491 rc &= parse_ss_info_elements(ss_ie + iei_length + 2,
492 len - iei_length - 2, req);
493
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800494 return rc;
495}
496
Vadim Yanitskiy5a09f752018-06-11 04:58:53 +0700497/*! Parse the components of a given Facility IE
498 * \param[in] facility_ie The Facility IE
499 * \param[in] length The length of Facility IE
500 * \param[out] req Abstract representation of SS message
501 * \return 0 in case of success, otherwise -ERRNO
502 */
503int gsm0480_parse_facility_ie(const uint8_t *facility_ie, uint16_t length,
504 struct ss_request *req)
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800505{
Vadim Yanitskiy5a09f752018-06-11 04:58:53 +0700506 uint8_t component_length;
507 uint8_t component_type;
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800508 uint8_t offset = 0;
Vadim Yanitskiy5a09f752018-06-11 04:58:53 +0700509 int rc = 1;
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800510
Vadim Yanitskiy5a09f752018-06-11 04:58:53 +0700511 /* Iterate over components within IE */
Holger Hans Peter Freyther4156ec62010-10-11 09:07:50 +0200512 while (offset + 2 <= length) {
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800513 /* Component Type tag - table 3.7 */
Vadim Yanitskiy5a09f752018-06-11 04:58:53 +0700514 component_type = facility_ie[offset];
515 component_length = facility_ie[offset + 1];
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800516
Vadim Yanitskiy5a09f752018-06-11 04:58:53 +0700517 /* Make sure that there is no overflow */
Holger Hans Peter Freyther4156ec62010-10-11 09:07:50 +0200518 if (offset + 2 + component_length > length) {
519 LOGP(0, LOGL_ERROR, "Component does not fit.\n");
Vadim Yanitskiy5a09f752018-06-11 04:58:53 +0700520 return -EINVAL;
Holger Hans Peter Freyther4156ec62010-10-11 09:07:50 +0200521 }
522
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800523 switch (component_type) {
524 case GSM0480_CTYPE_INVOKE:
Vadim Yanitskiy5a09f752018-06-11 04:58:53 +0700525 rc &= parse_ss_invoke(facility_ie + 2,
Tobias Engel419684e2012-03-08 13:31:52 +0100526 component_length,
527 req);
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800528 break;
529 case GSM0480_CTYPE_RETURN_RESULT:
Vadim Yanitskiy5a09f752018-06-11 04:58:53 +0700530 rc &= parse_ss_return_result(facility_ie + 2,
Vadim Yanitskiy7f16c442017-07-29 05:05:54 +0600531 component_length,
532 req);
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800533 break;
534 case GSM0480_CTYPE_RETURN_ERROR:
535 break;
536 case GSM0480_CTYPE_REJECT:
537 break;
538 default:
539 LOGP(0, LOGL_DEBUG, "Unknown GSM 04.80 Facility "
540 "Component Type 0x%02x\n", component_type);
541 rc = 0;
542 break;
543 }
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800544
Vadim Yanitskiy5a09f752018-06-11 04:58:53 +0700545 offset += (component_length + 2);
546 }
547
548 /**
549 * The internal functions are using inverted return
550 * codes, where '0' means error/failure. While a
551 * common approach is to return negative errno in
552 * case of any failure, and '0' if all is ok.
553 */
554 return (rc == 0) ? -EINVAL : 0;
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800555}
556
557/* Parse an Invoke component - see table 3.3 */
Holger Hans Peter Freyther49ad5002010-10-11 09:06:47 +0200558static int parse_ss_invoke(const uint8_t *invoke_data, uint16_t length,
Tobias Engel419684e2012-03-08 13:31:52 +0100559 struct ss_request *req)
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800560{
561 int rc = 1;
562 uint8_t offset;
563
Holger Hans Peter Freyther7d0bce32010-10-11 09:12:33 +0200564 if (length < 3)
565 return 0;
566
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800567 /* mandatory part */
568 if (invoke_data[0] != GSM0480_COMPIDTAG_INVOKE_ID) {
569 LOGP(0, LOGL_DEBUG, "Unexpected GSM 04.80 Component-ID tag "
Tobias Engel419684e2012-03-08 13:31:52 +0100570 "0x%02x (expecting Invoke ID tag)\n", invoke_data[0]);
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800571 }
572
573 offset = invoke_data[1] + 2;
574 req->invoke_id = invoke_data[2];
575
Holger Hans Peter Freyther7d0bce32010-10-11 09:12:33 +0200576 /* look ahead once */
577 if (offset + 1 > length)
578 return 0;
579
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800580 /* optional part */
581 if (invoke_data[offset] == GSM0480_COMPIDTAG_LINKED_ID)
582 offset += invoke_data[offset+1] + 2; /* skip over it */
583
584 /* mandatory part */
585 if (invoke_data[offset] == GSM0480_OPERATION_CODE) {
Holger Hans Peter Freyther7d0bce32010-10-11 09:12:33 +0200586 if (offset + 2 > length)
587 return 0;
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800588 uint8_t operation_code = invoke_data[offset+2];
Tobias Engel419684e2012-03-08 13:31:52 +0100589 req->opcode = operation_code;
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800590 switch (operation_code) {
Vadim Yanitskiy511426d2017-07-29 05:11:39 +0600591 case GSM0480_OP_CODE_USS_NOTIFY:
592 case GSM0480_OP_CODE_USS_REQUEST:
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800593 case GSM0480_OP_CODE_PROCESS_USS_REQ:
594 rc = parse_process_uss_req(invoke_data + offset + 3,
595 length - offset - 3,
596 req);
597 break;
Vadim Yanitskiy394447b2017-07-29 05:14:15 +0600598 case GSM0480_OP_CODE_PROCESS_USS_DATA:
599 rc = parse_process_uss_data(invoke_data + offset + 3,
600 length - offset - 3,
601 req);
602 break;
Tobias Engel419684e2012-03-08 13:31:52 +0100603 case GSM0480_OP_CODE_ACTIVATE_SS:
604 case GSM0480_OP_CODE_DEACTIVATE_SS:
605 case GSM0480_OP_CODE_INTERROGATE_SS:
606 rc = parse_ss_for_bs_req(invoke_data + offset + 3,
607 length - offset - 3,
608 req);
609 break;
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800610 default:
611 LOGP(0, LOGL_DEBUG, "GSM 04.80 operation code 0x%02x "
612 "is not yet handled\n", operation_code);
613 rc = 0;
614 break;
615 }
616 } else {
617 LOGP(0, LOGL_DEBUG, "Unexpected GSM 04.80 Component-ID tag 0x%02x "
618 "(expecting Operation Code tag)\n",
619 invoke_data[0]);
620 rc = 0;
621 }
622
623 return rc;
624}
625
Vadim Yanitskiy7f16c442017-07-29 05:05:54 +0600626/* Parse a Return Result component - see table 3.4 */
627static int parse_ss_return_result(const uint8_t *rr_data, uint16_t length,
628 struct ss_request *req)
629{
630 uint8_t operation_code;
631 uint8_t offset;
632
633 if (length < 3)
634 return 0;
635
636 /* Mandatory part */
637 if (rr_data[0] != GSM0480_COMPIDTAG_INVOKE_ID) {
638 LOGP(0, LOGL_DEBUG, "Unexpected GSM 04.80 Component-ID tag "
639 "0x%02x (expecting Invoke ID tag)\n", rr_data[0]);
640 return 0;
641 }
642
643 offset = rr_data[1] + 2;
644 req->invoke_id = rr_data[2];
645
646 if (offset >= length)
647 return 0;
648
649 if (rr_data[offset] != GSM_0480_SEQUENCE_TAG)
650 return 0;
651
652 if (offset + 2 > length)
653 return 0;
654
655 offset += 2;
656 operation_code = rr_data[offset + 2];
657 req->opcode = operation_code;
658
659 switch (operation_code) {
660 case GSM0480_OP_CODE_USS_NOTIFY:
661 case GSM0480_OP_CODE_USS_REQUEST:
662 case GSM0480_OP_CODE_PROCESS_USS_REQ:
663 return parse_process_uss_req(rr_data + offset + 3,
664 length - offset - 3, req);
665 case GSM0480_OP_CODE_PROCESS_USS_DATA:
666 return parse_process_uss_data(rr_data + offset + 3,
667 length - offset - 3, req);
668 default:
669 LOGP(0, LOGL_DEBUG, "GSM 04.80 operation code 0x%02x "
670 "is not yet handled\n", operation_code);
671 return 0;
672 }
673
674 return 1;
675}
676
677static int parse_process_uss_data(const uint8_t *uss_req_data, uint16_t length,
678 struct ss_request *req)
679{
680 uint8_t num_chars;
681
682 /* we need at least that much */
683 if (length < 3)
684 return 0;
685
686 if (uss_req_data[0] != ASN1_IA5_STRING_TAG)
687 return 0;
688
689 num_chars = uss_req_data[1];
690 if (num_chars > length - 2)
691 return 0;
692
Vadim Yanitskiy2ecfb302018-04-04 19:19:07 +0700693 /* Drop messages with incorrect length */
694 if (num_chars > GSM0480_USSD_OCTET_STRING_LEN) {
695 LOGP(DLGLOBAL, LOGL_ERROR, "Incorrect USS_DATA data length=%u, "
696 "dropping message", num_chars);
697 return 0;
698 }
Vadim Yanitskiy7f16c442017-07-29 05:05:54 +0600699
700 memcpy(req->ussd_text, uss_req_data + 2, num_chars);
701
Vadim Yanitskiya24ead02018-04-04 10:34:41 +0700702 /* Copy the data 'as is' */
703 memcpy(req->ussd_data, uss_req_data + 2, num_chars);
704 req->ussd_data_len = num_chars;
705 req->ussd_data_dcs = 0x00;
706
Vadim Yanitskiy7f16c442017-07-29 05:05:54 +0600707 return 1;
708}
709
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800710/* Parse the parameters of a Process UnstructuredSS Request */
Holger Hans Peter Freyther49ad5002010-10-11 09:06:47 +0200711static int parse_process_uss_req(const uint8_t *uss_req_data, uint16_t length,
Tobias Engel419684e2012-03-08 13:31:52 +0100712 struct ss_request *req)
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800713{
Vadim Yanitskiy5b0790d2017-07-29 04:26:21 +0600714 uint8_t num_chars;
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800715 uint8_t dcs;
716
Holger Hans Peter Freytherd65a6982010-10-11 09:23:50 +0200717 /* we need at least that much */
718 if (length < 8)
719 return 0;
720
Vadim Yanitskiy5b0790d2017-07-29 04:26:21 +0600721 if (uss_req_data[0] != GSM_0480_SEQUENCE_TAG)
722 return 0;
Holger Hans Peter Freytherd65a6982010-10-11 09:23:50 +0200723
Vadim Yanitskiy5b0790d2017-07-29 04:26:21 +0600724 /* Both 2th and 5th should be equal to ASN1_OCTET_STRING_TAG */
725 if ((uss_req_data[2] & uss_req_data[5]) != ASN1_OCTET_STRING_TAG)
726 return 0;
727
Vadim Yanitskiy01b85722017-07-29 04:43:48 +0600728 /* Get DCS (Data Coding Scheme) */
Vadim Yanitskiy5b0790d2017-07-29 04:26:21 +0600729 dcs = uss_req_data[4];
Vadim Yanitskiya24ead02018-04-04 10:34:41 +0700730 /* Get the amount of bytes */
731 num_chars = uss_req_data[6];
732
Vadim Yanitskiy2ecfb302018-04-04 19:19:07 +0700733 /* Drop messages with incorrect length */
734 if (num_chars > GSM0480_USSD_OCTET_STRING_LEN) {
735 LOGP(DLGLOBAL, LOGL_ERROR, "Incorrect USS_REQ data length=%u, "
736 "dropping message", num_chars);
737 return 0;
738 }
Vadim Yanitskiya24ead02018-04-04 10:34:41 +0700739
740 /* Copy the data 'as is' */
741 memcpy(req->ussd_data, uss_req_data + 7, num_chars);
742 req->ussd_data_len = num_chars;
743 req->ussd_data_dcs = dcs;
Vadim Yanitskiy01b85722017-07-29 04:43:48 +0600744
745 /**
746 * According to GSM 04.08, 4.4.2 "ASN.1 data types":
747 * the USSD-DataCodingScheme shall indicate use of
748 * the default alphabet using the 0x0F value.
749 */
Vadim Yanitskiy5b0790d2017-07-29 04:26:21 +0600750 if (dcs == 0x0F) {
Vadim Yanitskiy01b85722017-07-29 04:43:48 +0600751 /* Calculate the amount of 7-bit characters */
Vadim Yanitskiya24ead02018-04-04 10:34:41 +0700752 num_chars = (num_chars * 8) / 7;
Vadim Yanitskiy01b85722017-07-29 04:43:48 +0600753
Vadim Yanitskiy5b0790d2017-07-29 04:26:21 +0600754 gsm_7bit_decode_n_ussd((char *)req->ussd_text,
755 sizeof(req->ussd_text), &(uss_req_data[7]), num_chars);
756
757 return 1;
Vadim Yanitskiy01b85722017-07-29 04:43:48 +0600758 } else {
Vadim Yanitskiy01b85722017-07-29 04:43:48 +0600759 memcpy(req->ussd_text, &(uss_req_data[7]), num_chars);
Vadim Yanitskiy01b85722017-07-29 04:43:48 +0600760 return 1;
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800761 }
Vadim Yanitskiy5b0790d2017-07-29 04:26:21 +0600762
763 return 0;
Holger Hans Peter Freyther00cb5702010-10-09 01:47:15 +0800764}
Holger Hans Peter Freytherc64970e2010-10-18 16:56:43 +0200765
Tobias Engel419684e2012-03-08 13:31:52 +0100766/* Parse the parameters of a Interrogate/Activate/DeactivateSS Request */
767static int parse_ss_for_bs_req(const uint8_t *ss_req_data,
768 uint16_t length,
769 struct ss_request *req)
770{
771 int rc = 0;
772
773
774 /* we need at least that much */
775 if (length < 5)
776 return 0;
777
778
779 if (ss_req_data[0] == GSM_0480_SEQUENCE_TAG) {
780 if ((ss_req_data[2] == ASN1_OCTET_STRING_TAG) &&
781 ss_req_data[3] == 1) {
782 req->ss_code = ss_req_data[4];
783
784 rc = 1;
785 }
786 }
787 return rc;
788}
789
Harald Welte88fa5a32018-07-28 22:55:43 +0200790struct msgb *gsm0480_msgb_alloc_name(const char *name)
791{
792 return msgb_alloc_headroom(1024, 128, name);
793}
794
Harald Welteb0d95942018-07-28 23:02:48 +0200795/*! Generate a USSD ReturnResult component containing a string in default GSM alphabet.
796 * \param[in] invoke_id InvokeID of the request to which we respond
797 * \param[in] text USSD text in ASCII; to be encoded as GSM 7-but alphabet
798 */
799struct msgb *gsm0480_gen_ussd_resp_7bit(uint8_t invoke_id, const char *text)
Holger Hans Peter Freytherc64970e2010-10-18 16:56:43 +0200800{
801 struct msgb *msg;
Holger Hans Peter Freytherc64970e2010-10-18 16:56:43 +0200802 uint8_t *ptr8;
Holger Hans Peter Freyther47aa4822013-07-07 13:54:53 +0200803 int response_len;
Holger Hans Peter Freytherc64970e2010-10-18 16:56:43 +0200804
Harald Welte88fa5a32018-07-28 22:55:43 +0200805 msg = gsm0480_msgb_alloc_name("TS 04.80 USSD Resp");
Holger Hans Peter Freytherc64970e2010-10-18 16:56:43 +0200806 if (!msg)
807 return NULL;
808
809 /* First put the payload text into the message */
810 ptr8 = msgb_put(msg, 0);
Jacob Erlbeck1d7f3b52013-08-12 17:07:53 +0200811 gsm_7bit_encode_n_ussd(ptr8, msgb_tailroom(msg), text, &response_len);
Holger Hans Peter Freyther47aa4822013-07-07 13:54:53 +0200812 msgb_put(msg, response_len);
Holger Hans Peter Freytherc64970e2010-10-18 16:56:43 +0200813
814 /* Then wrap it as an Octet String */
815 msgb_wrap_with_TL(msg, ASN1_OCTET_STRING_TAG);
816
817 /* Pre-pend the DCS octet string */
818 msgb_push_TLV1(msg, ASN1_OCTET_STRING_TAG, 0x0F);
819
820 /* Then wrap these as a Sequence */
821 msgb_wrap_with_TL(msg, GSM_0480_SEQUENCE_TAG);
822
823 /* Pre-pend the operation code */
824 msgb_push_TLV1(msg, GSM0480_OPERATION_CODE,
825 GSM0480_OP_CODE_PROCESS_USS_REQ);
826
827 /* Wrap the operation code and IA5 string as a sequence */
828 msgb_wrap_with_TL(msg, GSM_0480_SEQUENCE_TAG);
829
830 /* Pre-pend the invoke ID */
831 msgb_push_TLV1(msg, GSM0480_COMPIDTAG_INVOKE_ID, invoke_id);
832
833 /* Wrap this up as a Return Result component */
834 msgb_wrap_with_TL(msg, GSM0480_CTYPE_RETURN_RESULT);
835
Harald Welteb0d95942018-07-28 23:02:48 +0200836 return msg;
837}
838
839/*! Legacy helper: Generate USSD response including FACILITY IE + L3 header.
840 *
841 * This function is just like \ref gsm0480_gen_ussd_resp_7bit, but it generates
842 * not only the FACILITY value, but the full L3 message including message header
843 * and FACILITY IE Tag+Length.
844 */
845struct msgb *gsm0480_create_ussd_resp(uint8_t invoke_id, uint8_t trans_id, const char *text)
846{
847 struct msgb *msg;
848
849 msg = gsm0480_gen_ussd_resp_7bit(invoke_id, text);
850 if (!msg)
851 return NULL;
852
Holger Hans Peter Freytherc64970e2010-10-18 16:56:43 +0200853 /* Wrap the component in a Facility message */
854 msgb_wrap_with_TL(msg, GSM0480_IE_FACILITY);
855
856 /* And finally pre-pend the L3 header */
Neels Hofmeyr25774b92016-11-26 15:21:05 +0100857 gsm0480_l3hdr_push(msg,
858 GSM48_PDISC_NC_SS | trans_id
859 | (1<<7) /* TI direction = 1 */,
860 GSM0480_MTYPE_RELEASE_COMPLETE);
Holger Hans Peter Freytherc64970e2010-10-18 16:56:43 +0200861 return msg;
862}
Neels Hofmeyr25774b92016-11-26 15:21:05 +0100863
864struct gsm48_hdr *gsm0480_l3hdr_push(struct msgb *msg, uint8_t proto_discr,
865 uint8_t msg_type)
866{
867 struct gsm48_hdr *gh;
868 gh = (struct gsm48_hdr *) msgb_push(msg, sizeof(*gh));
869 gh->proto_discr = proto_discr;
870 gh->msg_type = msg_type;
871 return gh;
872}
Neels Hofmeyrbc1d7582016-11-26 15:21:15 +0100873
874struct msgb *gsm0480_create_ussd_notify(int level, const char *text)
875{
876 struct msgb *msg;
877
878 msg = gsm0480_create_unstructuredSS_Notify(level, text);
879 if (!msg)
880 return NULL;
881
882 gsm0480_wrap_invoke(msg, GSM0480_OP_CODE_USS_NOTIFY, 0);
883 gsm0480_wrap_facility(msg);
884
885 gsm0480_l3hdr_push(msg, GSM48_PDISC_NC_SS, GSM0480_MTYPE_REGISTER);
886 return msg;
887}
888
889struct msgb *gsm0480_create_ussd_release_complete(void)
890{
891 struct msgb *msg;
892
893 msg = msgb_alloc_headroom(1024, 128, "GSM 04.80 USSD REL COMPL");
894 if (!msg)
895 return NULL;
896
897 /* FIXME: should this set trans_id and TI direction flag? */
898 gsm0480_l3hdr_push(msg, GSM48_PDISC_NC_SS,
899 GSM0480_MTYPE_RELEASE_COMPLETE);
900 return msg;
901}