blob: f773584f72da846a57f4ef1b9f5ad4474a5312bf [file] [log] [blame]
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001/* NS-over-IP proxy */
2
Harald Weltee5209642020-12-05 19:59:45 +01003/* (C) 2010-2020 by Harald Welte <laforge@gnumonks.org>
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02004 * (C) 2010-2013 by On-Waves
5 * (C) 2013 by Holger Hans Peter Freyther
6 * All Rights Reserved
7 *
8 * This program is free software; you can redistribute it and/or modify
9 * it under the terms of the GNU Affero General Public License as published by
10 * the Free Software Foundation; either version 3 of the License, or
11 * (at your option) any later version.
12 *
13 * This program is distributed in the hope that it will be useful,
14 * but WITHOUT ANY WARRANTY; without even the implied warranty of
15 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
16 * GNU Affero General Public License for more details.
17 *
18 * You should have received a copy of the GNU Affero General Public License
19 * along with this program. If not, see <http://www.gnu.org/licenses/>.
20 *
21 */
22
23#include <unistd.h>
24#include <stdio.h>
25#include <stdlib.h>
26#include <string.h>
27#include <getopt.h>
28#include <errno.h>
29#include <sys/fcntl.h>
30#include <sys/stat.h>
31#include <arpa/inet.h>
32#include <time.h>
33
Harald Welted2fef952020-12-05 00:31:07 +010034#include <osmocom/core/hashtable.h>
Daniel Willmann8f407b12020-12-02 19:33:50 +010035#include <osmocom/core/logging.h>
Daniel Willmannee834af2020-12-14 16:22:39 +010036#include <osmocom/core/linuxlist.h>
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +020037#include <osmocom/core/talloc.h>
38#include <osmocom/core/select.h>
39#include <osmocom/core/rate_ctr.h>
Oliver Smith29532c22021-01-29 11:13:00 +010040#include <osmocom/core/signal.h>
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +020041#include <osmocom/core/stats.h>
Daniel Willmannd4ab1f92020-12-21 18:53:55 +010042#include <osmocom/core/utils.h>
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +020043
Alexander Couzens951e1332020-09-22 13:21:46 +020044#include <osmocom/gprs/gprs_ns2.h>
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +020045#include <osmocom/gprs/gprs_bssgp.h>
Harald Welte209dc9f2020-12-12 19:02:16 +010046#include <osmocom/gprs/gprs_bssgp2.h>
Alexander Couzens951e1332020-09-22 13:21:46 +020047#include <osmocom/gprs/gprs_bssgp_bss.h>
Harald Weltee5209642020-12-05 19:59:45 +010048#include <osmocom/gprs/bssgp_bvc_fsm.h>
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +020049
Daniel Willmannd4ab1f92020-12-21 18:53:55 +010050#include <osmocom/gsm/gsm23236.h>
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +020051#include <osmocom/gsm/gsm_utils.h>
52
Oliver Smith29532c22021-01-29 11:13:00 +010053#include "debug.h"
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +020054#include <osmocom/sgsn/gb_proxy.h>
55
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +020056#include <osmocom/gsm/protocol/gsm_04_08_gprs.h>
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +020057
58extern void *tall_sgsn_ctx;
59
60static const struct rate_ctr_desc global_ctr_description[] = {
61 { "inv-bvci", "Invalid BVC Identifier " },
62 { "inv-lai", "Invalid Location Area Identifier" },
63 { "inv-rai", "Invalid Routing Area Identifier " },
64 { "inv-nsei", "No BVC established for NSEI " },
65 { "proto-err:bss", "BSSGP protocol error (BSS )" },
66 { "proto-err:sgsn", "BSSGP protocol error (SGSN)" },
67 { "not-supp:bss", "Feature not supported (BSS )" },
68 { "not-supp:sgsn", "Feature not supported (SGSN)" },
69 { "restart:sgsn", "Restarted RESET procedure (SGSN)" },
70 { "tx-err:sgsn", "NS Transmission error (SGSN)" },
71 { "error", "Other error " },
72 { "mod-peer-err", "Patch error: no peer " },
73};
74
75static const struct rate_ctr_group_desc global_ctrg_desc = {
76 .group_name_prefix = "gbproxy:global",
77 .group_description = "GBProxy Global Statistics",
78 .num_ctr = ARRAY_SIZE(global_ctr_description),
79 .ctr_desc = global_ctr_description,
80 .class_id = OSMO_STATS_CLASS_GLOBAL,
81};
82
Harald Welte560bdb32020-12-04 22:24:47 +010083static int gbprox_relay2peer(struct msgb *old_msg, struct gbproxy_bvc *bvc,
Daniel Willmann35f7d332020-11-03 21:11:45 +010084 uint16_t ns_bvci);
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +020085
Harald Weltea0f70732020-12-05 17:50:23 +010086
Harald Welteec0f8012020-12-06 16:32:01 +010087/* generate BVC-STATUS message with cause value derived from TLV-parser error */
88static int tx_status_from_tlvp(enum osmo_tlv_parser_error tlv_p_err, struct msgb *orig_msg)
89{
90 uint8_t bssgp_cause;
91 switch (tlv_p_err) {
92 case OSMO_TLVP_ERR_MAND_IE_MISSING:
93 bssgp_cause = BSSGP_CAUSE_MISSING_MAND_IE;
94 break;
95 default:
96 bssgp_cause = BSSGP_CAUSE_PROTO_ERR_UNSPEC;
97 }
98 return bssgp_tx_status(bssgp_cause, NULL, orig_msg);
99}
100
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +0200101/* strip off the NS header */
102static void strip_ns_hdr(struct msgb *msg)
103{
104 int strip_len = msgb_bssgph(msg) - msg->data;
105 msgb_pull(msg, strip_len);
106}
107
Harald Weltee5209642020-12-05 19:59:45 +0100108#if 0
Harald Welte560bdb32020-12-04 22:24:47 +0100109/* feed a message down the NS-VC associated with the specified bvc */
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +0200110static int gbprox_relay2sgsn(struct gbproxy_config *cfg, struct msgb *old_msg,
111 uint16_t ns_bvci, uint16_t sgsn_nsei)
112{
113 /* create a copy of the message so the old one can
114 * be free()d safely when we return from gbprox_rcvmsg() */
Alexander Couzens951e1332020-09-22 13:21:46 +0200115 struct gprs_ns2_inst *nsi = cfg->nsi;
116 struct osmo_gprs_ns2_prim nsp = {};
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +0200117 struct msgb *msg = bssgp_msgb_copy(old_msg, "msgb_relay2sgsn");
118 int rc;
119
Daniel Willmann3696dce2020-12-02 16:08:02 +0100120 DEBUGP(DGPRS, "NSE(%05u/BSS)-BVC(%05u) proxying BTS->SGSN NSE(%05u/SGSN)\n",
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +0200121 msgb_nsei(msg), ns_bvci, sgsn_nsei);
122
Alexander Couzens951e1332020-09-22 13:21:46 +0200123 nsp.bvci = ns_bvci;
124 nsp.nsei = sgsn_nsei;
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +0200125
126 strip_ns_hdr(msg);
Alexander Couzens951e1332020-09-22 13:21:46 +0200127 osmo_prim_init(&nsp.oph, SAP_NS, PRIM_NS_UNIT_DATA,
128 PRIM_OP_REQUEST, msg);
129 rc = gprs_ns2_recv_prim(nsi, &nsp.oph);
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +0200130 if (rc < 0)
131 rate_ctr_inc(&cfg->ctrg->ctr[GBPROX_GLOB_CTR_TX_ERR_SGSN]);
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +0200132 return rc;
133}
Harald Weltee5209642020-12-05 19:59:45 +0100134#endif
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +0200135
Harald Weltee30985e2021-01-28 19:13:19 +0100136/*! Determine the TLLI from the given BSSGP message.
137 * \param[in] bssgp pointer to start of BSSGP header
138 * \param[in] bssgp_len length of BSSGP message in octets
139 * \param[out] tlli TLLI (if any) in host byte order
140 * \returns 1 if TLLI found; 0 if none found; negative on parse error */
141int gprs_gb_parse_tlli(const uint8_t *bssgp, size_t bssgp_len, uint32_t *tlli)
142{
143 const struct bssgp_normal_hdr *bgph;
144 uint8_t pdu_type;
145
146 if (bssgp_len < sizeof(struct bssgp_normal_hdr))
147 return -EINVAL;
148
149 bgph = (struct bssgp_normal_hdr *)bssgp;
150 pdu_type = bgph->pdu_type;
151
152 if (pdu_type == BSSGP_PDUT_UL_UNITDATA ||
153 pdu_type == BSSGP_PDUT_DL_UNITDATA) {
154 const struct bssgp_ud_hdr *budh = (struct bssgp_ud_hdr *)bssgp;
155 if (bssgp_len < sizeof(struct bssgp_ud_hdr))
156 return -EINVAL;
157 *tlli = osmo_load32be((const uint8_t *)&budh->tlli);
158 return 1;
159 } else {
160 const uint8_t *data = bgph->data;
161 size_t data_len = bssgp_len - sizeof(*bgph);
162 struct tlv_parsed tp;
163
164 if (bssgp_tlv_parse(&tp, data, data_len) < 0)
165 return -EINVAL;
166
167 if (TLVP_PRESENT(&tp, BSSGP_IE_TLLI)) {
168 *tlli = osmo_load32be(TLVP_VAL(&tp, BSSGP_IE_TLLI));
169 return 1;
170 }
171 }
172
173 /* No TLLI present in message */
174 return 0;
175}
176
Daniel Willmann76205712020-11-30 17:08:58 +0100177/* feed a message down the NSE */
178static int gbprox_relay2nse(struct msgb *old_msg, struct gbproxy_nse *nse,
Daniel Willmann35f7d332020-11-03 21:11:45 +0100179 uint16_t ns_bvci)
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +0200180{
Daniel Willmanne50550e2020-11-26 18:19:21 +0100181 OSMO_ASSERT(nse);
182 OSMO_ASSERT(nse->cfg);
183
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +0200184 /* create a copy of the message so the old one can
185 * be free()d safely when we return from gbprox_rcvmsg() */
Daniel Willmanne50550e2020-11-26 18:19:21 +0100186 struct gprs_ns2_inst *nsi = nse->cfg->nsi;
Alexander Couzens951e1332020-09-22 13:21:46 +0200187 struct osmo_gprs_ns2_prim nsp = {};
Daniel Willmann76205712020-11-30 17:08:58 +0100188 struct msgb *msg = bssgp_msgb_copy(old_msg, "msgb_relay2nse");
Harald Weltefe059582020-11-18 12:01:46 +0100189 uint32_t tlli;
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +0200190 int rc;
191
Daniel Willmann98b1b452020-12-21 10:40:27 +0100192 DEBUGP(DGPRS, "NSE(%05u/%s)-BVC(%05u/??) proxying to NSE(%05u/%s)\n", msgb_nsei(msg),
193 !nse->sgsn_facing ? "SGSN" : "BSS", ns_bvci, nse->nsei, nse->sgsn_facing ? "SGSN" : "BSS");
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +0200194
Alexander Couzens951e1332020-09-22 13:21:46 +0200195 nsp.bvci = ns_bvci;
Daniel Willmanne50550e2020-11-26 18:19:21 +0100196 nsp.nsei = nse->nsei;
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +0200197
198 /* Strip the old NS header, it will be replaced with a new one */
199 strip_ns_hdr(msg);
200
Harald Weltefe059582020-11-18 12:01:46 +0100201 /* TS 48.018 Section 5.4.2: The link selector parameter is
202 * defined in 3GPP TS 48.016. At one side of the Gb interface,
203 * all BSSGP UNITDATA PDUs related to an MS shall be passed with
204 * the same LSP, e.g. the LSP contains the MS's TLLI, to the
205 * underlying network service. */
206 if (gprs_gb_parse_tlli(msgb_data(msg), msgb_length(msg), &tlli) == 1)
207 nsp.u.unitdata.link_selector = tlli;
208
Alexander Couzens55c36f92021-01-27 20:56:55 +0100209 osmo_prim_init(&nsp.oph, SAP_NS, GPRS_NS2_PRIM_UNIT_DATA,
Alexander Couzens951e1332020-09-22 13:21:46 +0200210 PRIM_OP_REQUEST, msg);
211 rc = gprs_ns2_recv_prim(nsi, &nsp.oph);
Daniel Willmann76205712020-11-30 17:08:58 +0100212 /* FIXME: We need a counter group for gbproxy_nse */
213 //if (rc < 0)
Harald Welte560bdb32020-12-04 22:24:47 +0100214 // rate_ctr_inc(&bvc->ctrg->ctr[GBPROX_PEER_CTR_TX_ERR]);
Daniel Willmann76205712020-11-30 17:08:58 +0100215
216 return rc;
217}
218
Harald Welte560bdb32020-12-04 22:24:47 +0100219/* feed a message down the NS-VC associated with the specified bvc */
220static int gbprox_relay2peer(struct msgb *old_msg, struct gbproxy_bvc *bvc,
Daniel Willmann76205712020-11-30 17:08:58 +0100221 uint16_t ns_bvci)
222{
223 int rc;
Harald Welte560bdb32020-12-04 22:24:47 +0100224 struct gbproxy_nse *nse = bvc->nse;
Daniel Willmann76205712020-11-30 17:08:58 +0100225 OSMO_ASSERT(nse);
226
227 rc = gbprox_relay2nse(old_msg, nse, ns_bvci);
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +0200228 if (rc < 0)
Harald Welte560bdb32020-12-04 22:24:47 +0100229 rate_ctr_inc(&bvc->ctrg->ctr[GBPROX_PEER_CTR_TX_ERR]);
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +0200230
231 return rc;
232}
233
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +0200234int bssgp_prim_cb(struct osmo_prim_hdr *oph, void *ctx)
235{
236 return 0;
237}
238
Harald Weltee5209642020-12-05 19:59:45 +0100239
240/***********************************************************************
241 * PTP BVC handling
242 ***********************************************************************/
243
Daniel Willmannd4ab1f92020-12-21 18:53:55 +0100244/* FIXME: Handle the tlli NULL case correctly,
245 * This function should take a generic selector
246 * and choose an sgsn based on that
247 */
248static struct gbproxy_sgsn *gbproxy_select_sgsn(struct gbproxy_config *cfg, const uint32_t *tlli)
249{
250 struct gbproxy_sgsn *sgsn = NULL;
251 struct gbproxy_sgsn *sgsn_avoid = NULL;
252
253 int tlli_type;
254 int16_t nri;
255 bool null_nri = false;
256
257 if (!tlli) {
258 sgsn = llist_first_entry(&cfg->sgsns, struct gbproxy_sgsn, list);
259 if (!sgsn) {
260 return NULL;
261 }
262 LOGPSGSN(sgsn, LOGL_INFO, "Could not get TLLI, using first SGSN\n");
263 return sgsn;
264 }
265
266 if (cfg->pool.nri_bitlen == 0) {
267 /* Pooling is disabled */
268 sgsn = llist_first_entry(&cfg->sgsns, struct gbproxy_sgsn, list);
269 if (!sgsn) {
270 return NULL;
271 }
272
273 LOGPSGSN(sgsn, LOGL_INFO, "Pooling disabled, using first configured SGSN\n");
274 } else {
275 /* Pooling is enabled, try to use the NRI for routing to an SGSN
276 * See 3GPP TS 23.236 Ch. 5.3.2 */
277 tlli_type = gprs_tlli_type(*tlli);
278 if (tlli_type == TLLI_LOCAL || tlli_type == TLLI_FOREIGN) {
279 /* Only get/use the NRI if tlli type is local */
280 osmo_tmsi_nri_v_get(&nri, *tlli, cfg->pool.nri_bitlen);
281 if (nri >= 0) {
282 /* Get the SGSN for the NRI */
283 sgsn = gbproxy_sgsn_by_nri(cfg, nri, &null_nri);
284 if (sgsn && !null_nri)
285 return sgsn;
286 /* If the NRI is the null NRI, we need to avoid the chosen SGSN */
287 if (null_nri && sgsn) {
288 sgsn_avoid = sgsn;
289 }
290 } else {
291 /* We couldn't get the NRI from the TLLI */
Daniel Willmanncd21afe2021-01-21 18:44:51 +0100292 LOGP(DGPRS, LOGL_ERROR, "Could not extract NRI from local TLLI %08x\n", *tlli);
Daniel Willmannd4ab1f92020-12-21 18:53:55 +0100293 }
Daniel Willmanncd21afe2021-01-21 18:44:51 +0100294 } else {
295 LOGP(DGPRS, LOGL_INFO, "TLLI %08x is neither local nor foreign, not routing by NRI\n", *tlli);
Daniel Willmannd4ab1f92020-12-21 18:53:55 +0100296 }
297 }
298
299 /* If we haven't found an SGSN yet we need to choose one, but avoid the one in sgsn_avoid
300 * NOTE: This function is not stable if the number of SGSNs or allow_attach changes
301 * We could implement TLLI tracking here, but 3GPP TS 23.236 Ch. 5.3.2 (see NOTE) argues that
302 * we can just wait for the MS to reattempt the procedure.
303 */
304 if (!sgsn)
305 sgsn = gbproxy_sgsn_by_tlli(cfg, sgsn_avoid, *tlli);
306
307 if (!sgsn) {
308 LOGP(DGPRS, LOGL_ERROR, "No suitable SGSN found for TLLI %u\n", *tlli);
309 return NULL;
310 }
311
312 return sgsn;
313}
314
315/*! Find the correct gbproxy_bvc given a cell and an SGSN
316 * \param[in] cfg The gbproxy configuration
317 * \param[in] cell The cell the message belongs to
318 * \param[in] tlli An optional TLLI used for tracking
319 * \return Returns 0 on success, otherwise a negative value
320 */
321static struct gbproxy_bvc *gbproxy_select_sgsn_bvc(struct gbproxy_config *cfg, struct gbproxy_cell *cell, const uint32_t *tlli)
322{
323 struct gbproxy_sgsn *sgsn;
324 struct gbproxy_bvc *sgsn_bvc = NULL;
Harald Welte02d7c482020-12-30 12:13:36 +0100325 int i;
Daniel Willmannd4ab1f92020-12-21 18:53:55 +0100326
327 sgsn = gbproxy_select_sgsn(cfg, tlli);
328 if (!sgsn) {
329 LOGPCELL(cell, LOGL_ERROR, "Could not find any SGSN, dropping message!\n");
330 return NULL;
331 }
332
333 /* Get the BVC for this SGSN/NSE */
Harald Welte02d7c482020-12-30 12:13:36 +0100334 for (i = 0; i < ARRAY_SIZE(cell->sgsn_bvc); i++) {
Daniel Willmannd4ab1f92020-12-21 18:53:55 +0100335 sgsn_bvc = cell->sgsn_bvc[i];
336 if (!sgsn_bvc)
337 continue;
338 if (sgsn->nse != sgsn_bvc->nse)
339 continue;
340
341 return sgsn_bvc;
342 }
343
344 /* This shouldn't happen */
Daniel Willmanna648f3c2020-12-28 18:07:27 +0100345 LOGPCELL(cell, LOGL_ERROR, "Could not find matching BVC for SGSN %s, dropping message!\n", sgsn->name);
Daniel Willmannd4ab1f92020-12-21 18:53:55 +0100346 return NULL;
347}
348
349/*! Send a message to the next SGSN, possibly ignoring the null SGSN
350 * route an uplink message on a PTP-BVC to a SGSN using the TLLI
351 * \param[in] cell The cell the message belongs to
352 * \param[in] msg The BSSGP message
353 * \param[in] null_sgsn If not NULL then avoid this SGSN (because this message contains its null NRI)
354 * \param[in] tlli An optional TLLI used for tracking
355 * \return Returns 0 on success, otherwise a negative value
356 */
357static int gbprox_bss2sgsn_tlli(struct gbproxy_cell *cell, struct msgb *msg, const uint32_t *tlli,
Harald Weltee5209642020-12-05 19:59:45 +0100358 bool sig_bvci)
359{
Daniel Willmannd4ab1f92020-12-21 18:53:55 +0100360 struct gbproxy_config *cfg = cell->cfg;
Harald Weltee5209642020-12-05 19:59:45 +0100361 struct gbproxy_bvc *sgsn_bvc;
Harald Weltee5209642020-12-05 19:59:45 +0100362
Daniel Willmannd4ab1f92020-12-21 18:53:55 +0100363 sgsn_bvc = gbproxy_select_sgsn_bvc(cfg, cell, tlli);
364 if (!sgsn_bvc) {
365 LOGPCELL(cell, LOGL_NOTICE, "Could not find any SGSN for TLLI %u, dropping message!\n", *tlli);
366 return -EINVAL;
Harald Weltee5209642020-12-05 19:59:45 +0100367 }
Daniel Willmannd4ab1f92020-12-21 18:53:55 +0100368
369 return gbprox_relay2peer(msg, sgsn_bvc, sig_bvci ? 0 : sgsn_bvc->bvci);
Harald Weltee5209642020-12-05 19:59:45 +0100370}
371
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +0200372/* Receive an incoming PTP message from a BSS-side NS-VC */
Harald Weltee5209642020-12-05 19:59:45 +0100373static int gbprox_rx_ptp_from_bss(struct gbproxy_nse *nse, struct msgb *msg, uint16_t ns_bvci)
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +0200374{
Harald Welte278dd272020-12-06 13:35:24 +0100375 struct bssgp_normal_hdr *bgph = (struct bssgp_normal_hdr *) msgb_bssgph(msg);
Harald Weltee5209642020-12-05 19:59:45 +0100376 const char *pdut_name = osmo_tlv_prot_msg_name(&osmo_pdef_bssgp, bgph->pdu_type);
377 struct gbproxy_bvc *bss_bvc;
378 struct tlv_parsed tp;
379 char log_pfx[32];
380 uint32_t tlli;
381 int rc;
382
383 snprintf(log_pfx, sizeof(log_pfx), "NSE(%05u/BSS)-BVC(%05u/??)", nse->nsei, ns_bvci);
384
385 LOGP(DGPRS, LOGL_DEBUG, "%s Rx %s\n", log_pfx, pdut_name);
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +0200386
Daniel Willmann06331ac2020-12-10 17:59:46 +0100387 if (ns_bvci == 0 || ns_bvci == 1) {
Harald Weltee5209642020-12-05 19:59:45 +0100388 LOGP(DGPRS, LOGL_NOTICE, "%s BVCI=%05u is not PTP\n", log_pfx, ns_bvci);
Harald Welte278dd272020-12-06 13:35:24 +0100389 return bssgp_tx_status(BSSGP_CAUSE_PROTO_ERR_UNSPEC, NULL, msg);
390 }
391
392 if (!(bssgp_pdu_type_flags(bgph->pdu_type) & BSSGP_PDUF_PTP)) {
Harald Weltee5209642020-12-05 19:59:45 +0100393 LOGP(DGPRS, LOGL_NOTICE, "%s %s not allowed in PTP BVC\n", log_pfx, pdut_name);
Harald Welte278dd272020-12-06 13:35:24 +0100394 return bssgp_tx_status(BSSGP_CAUSE_PROTO_ERR_UNSPEC, NULL, msg);
395 }
396
397 if (!(bssgp_pdu_type_flags(bgph->pdu_type) & BSSGP_PDUF_UL)) {
Harald Weltee5209642020-12-05 19:59:45 +0100398 LOGP(DGPRS, LOGL_NOTICE, "%s %s not allowed in uplink direction\n", log_pfx, pdut_name);
Harald Welte278dd272020-12-06 13:35:24 +0100399 return bssgp_tx_status(BSSGP_CAUSE_PROTO_ERR_UNSPEC, NULL, msg);
400 }
401
Harald Weltee5209642020-12-05 19:59:45 +0100402 bss_bvc = gbproxy_bvc_by_bvci(nse, ns_bvci);
403 if (!bss_bvc) {
404 LOGP(DGPRS, LOGL_NOTICE, "%s %s - Didn't find BVC for PTP message, discarding\n",
405 log_pfx, pdut_name);
406 return bssgp_tx_status(BSSGP_CAUSE_UNKNOWN_BVCI, &ns_bvci, msg);
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +0200407 }
408
Harald Weltee5209642020-12-05 19:59:45 +0100409 /* UL_UNITDATA has a different header than all other uplink PDUs */
410 if (bgph->pdu_type == BSSGP_PDUT_UL_UNITDATA) {
411 const struct bssgp_ud_hdr *budh = (struct bssgp_ud_hdr *) msgb_bssgph(msg);
412 if (msgb_bssgp_len(msg) < sizeof(*budh))
413 return bssgp_tx_status(BSSGP_CAUSE_INV_MAND_INF, NULL, msg);
414 rc = osmo_tlv_prot_parse(&osmo_pdef_bssgp, &tp, 1, bgph->pdu_type, budh->data,
415 msgb_bssgp_len(msg) - sizeof(*budh), 0, 0, DGPRS, log_pfx);
416 /* populate TLLI from the fixed headser into the TLV-parsed array so later code
417 * doesn't have to worry where the TLLI came from */
418 tp.lv[BSSGP_IE_TLLI].len = 4;
419 tp.lv[BSSGP_IE_TLLI].val = (const uint8_t *) &budh->tlli;
420 } else {
421 rc = osmo_tlv_prot_parse(&osmo_pdef_bssgp, &tp, 1, bgph->pdu_type, bgph->data,
422 msgb_bssgp_len(msg) - sizeof(*bgph), 0, 0, DGPRS, log_pfx);
423 }
424 if (rc < 0) {
425 rate_ctr_inc(&nse->cfg->ctrg->ctr[GBPROX_GLOB_CTR_PROTO_ERR_BSS]);
426 return tx_status_from_tlvp(rc, msg);
427 }
Harald Welte85a40272020-12-08 21:43:22 +0100428 /* hack to get both msg + tlv_parsed passed via osmo_fsm_inst_dispatch */
429 msgb_bcid(msg) = (void *)&tp;
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +0200430
Harald Weltee5209642020-12-05 19:59:45 +0100431 switch (bgph->pdu_type) {
432 case BSSGP_PDUT_UL_UNITDATA:
433 case BSSGP_PDUT_RA_CAPA_UPDATE:
434 case BSSGP_PDUT_FLOW_CONTROL_MS:
435 case BSSGP_PDUT_DOWNLOAD_BSS_PFC:
436 case BSSGP_PDUT_CREATE_BSS_PFC_ACK:
437 case BSSGP_PDUT_CREATE_BSS_PFC_NACK:
438 case BSSGP_PDUT_MODIFY_BSS_PFC_ACK:
439 case BSSGP_PDUT_DELETE_BSS_PFC_ACK:
440 case BSSGP_PDUT_FLOW_CONTROL_PFC:
441 case BSSGP_PDUT_DELETE_BSS_PFC_REQ:
442 case BSSGP_PDUT_PS_HO_REQUIRED:
443 case BSSGP_PDUT_PS_HO_REQUEST_ACK:
444 case BSSGP_PDUT_PS_HO_REQUEST_NACK:
445 case BSSGP_PDUT_PS_HO_COMPLETE:
446 case BSSGP_PDUT_PS_HO_CANCEL:
447 /* We can route based on TLLI-NRI */
448 tlli = osmo_load32be(TLVP_VAL(&tp, BSSGP_IE_TLLI));
Daniel Willmannd4ab1f92020-12-21 18:53:55 +0100449 rc = gbprox_bss2sgsn_tlli(bss_bvc->cell, msg, &tlli, false);
Harald Weltee5209642020-12-05 19:59:45 +0100450 break;
451 case BSSGP_PDUT_RADIO_STATUS:
452 if (TLVP_PRESENT(&tp, BSSGP_IE_TLLI)) {
453 tlli = osmo_load32be(TLVP_VAL(&tp, BSSGP_IE_TLLI));
Daniel Willmannd4ab1f92020-12-21 18:53:55 +0100454 rc = gbprox_bss2sgsn_tlli(bss_bvc->cell, msg, &tlli, false);
Harald Weltee5209642020-12-05 19:59:45 +0100455 } else if (TLVP_PRESENT(&tp, BSSGP_IE_TMSI)) {
456 /* we treat the TMSI like a TLLI and extract the NRI from it */
457 tlli = osmo_load32be(TLVP_VAL(&tp, BSSGP_IE_TMSI));
Daniel Willmann8b3ed292021-01-21 18:46:51 +0100458 /* Convert the TMSI into a FOREIGN TLLI so it is routed appropriately */
459 tlli = gprs_tmsi2tlli(tlli, TLLI_FOREIGN);
Daniel Willmannd4ab1f92020-12-21 18:53:55 +0100460 rc = gbprox_bss2sgsn_tlli(bss_bvc->cell, msg, &tlli, false);
Harald Weltee5209642020-12-05 19:59:45 +0100461 } else if (TLVP_PRESENT(&tp, BSSGP_IE_IMSI)) {
Daniel Willmann5193f222021-01-11 05:00:46 +0100462 /* FIXME: Use the IMSI as selector? */
Daniel Willmannd4ab1f92020-12-21 18:53:55 +0100463 rc = gbprox_bss2sgsn_tlli(bss_bvc->cell, msg, NULL, false);
Daniel Willmann5193f222021-01-11 05:00:46 +0100464 /* rc = gbprox_bss2sgsn_hashed(bss_bvc->cell, msg, NULL); */
Harald Weltee5209642020-12-05 19:59:45 +0100465 } else
466 LOGPBVC(bss_bvc, LOGL_ERROR, "Rx RADIO-STATUS without any of the conditional IEs\n");
467 break;
468 case BSSGP_PDUT_DUMMY_PAGING_PS_RESP:
469 case BSSGP_PDUT_PAGING_PS_REJECT:
Daniel Willmann5614e572021-01-18 18:38:27 +0100470 {
471 /* Route according to IMSI<->NSE cache entry */
472 struct osmo_mobile_identity mi;
473 const uint8_t *mi_data = TLVP_VAL(&tp, BSSGP_IE_IMSI);
474 uint8_t mi_len = TLVP_LEN(&tp, BSSGP_IE_IMSI);
475 osmo_mobile_identity_decode(&mi, mi_data, mi_len, false);
476 nse = gbproxy_nse_by_imsi(nse->cfg, mi.imsi);
477 if (nse) {
478 OSMO_ASSERT(nse->sgsn_facing);
479 rc = gbprox_relay2nse(msg, nse, ns_bvci);
480 } else {
Daniel Willmann82669182021-01-19 11:37:55 +0100481 LOGPBVC(bss_bvc, LOGL_ERROR, "Rx unmatched %s with IMSI %s\n", pdut_name, mi.imsi);
Daniel Willmann5614e572021-01-18 18:38:27 +0100482 }
Harald Weltee5209642020-12-05 19:59:45 +0100483 break;
Daniel Willmann5614e572021-01-18 18:38:27 +0100484 }
Harald Weltee5209642020-12-05 19:59:45 +0100485 case BSSGP_PDUT_FLOW_CONTROL_BVC:
Harald Welte85a40272020-12-08 21:43:22 +0100486 osmo_fsm_inst_dispatch(bss_bvc->fi, BSSGP_BVCFSM_E_RX_FC_BVC, msg);
Harald Weltee5209642020-12-05 19:59:45 +0100487 break;
488 case BSSGP_PDUT_STATUS:
489 /* TODO: Implement by inspecting the contained PDU */
490 if (!TLVP_PRESENT(&tp, BSSGP_IE_PDU_IN_ERROR))
491 break;
492 LOGPBVC(bss_bvc, LOGL_ERROR, "Rx %s: Implementation missing\n", pdut_name);
493 break;
494 }
495
496 return 0;
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +0200497}
498
499/* Receive an incoming PTP message from a SGSN-side NS-VC */
Harald Weltee5209642020-12-05 19:59:45 +0100500static int gbprox_rx_ptp_from_sgsn(struct gbproxy_nse *nse, struct msgb *msg, uint16_t ns_bvci)
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +0200501{
Harald Welte278dd272020-12-06 13:35:24 +0100502 struct bssgp_normal_hdr *bgph = (struct bssgp_normal_hdr *) msgb_bssgph(msg);
Harald Weltee5209642020-12-05 19:59:45 +0100503 const char *pdut_name = osmo_tlv_prot_msg_name(&osmo_pdef_bssgp, bgph->pdu_type);
504 struct gbproxy_bvc *sgsn_bvc, *bss_bvc;
Harald Welte85a40272020-12-08 21:43:22 +0100505 struct tlv_parsed tp;
Harald Weltee5209642020-12-05 19:59:45 +0100506 char log_pfx[32];
Harald Welte85a40272020-12-08 21:43:22 +0100507 int rc;
Harald Weltee5209642020-12-05 19:59:45 +0100508
509 snprintf(log_pfx, sizeof(log_pfx), "NSE(%05u/SGSN)-BVC(%05u/??)", nse->nsei, ns_bvci);
510
511 LOGP(DGPRS, LOGL_DEBUG, "%s Rx %s\n", log_pfx, pdut_name);
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +0200512
Daniel Willmann06331ac2020-12-10 17:59:46 +0100513 if (ns_bvci == 0 || ns_bvci == 1) {
Harald Weltee5209642020-12-05 19:59:45 +0100514 LOGP(DGPRS, LOGL_NOTICE, "%s BVCI is not PTP\n", log_pfx);
Harald Welte278dd272020-12-06 13:35:24 +0100515 return bssgp_tx_status(BSSGP_CAUSE_PROTO_ERR_UNSPEC, NULL, msg);
516 }
517
518 if (!(bssgp_pdu_type_flags(bgph->pdu_type) & BSSGP_PDUF_PTP)) {
Harald Weltee5209642020-12-05 19:59:45 +0100519 LOGP(DGPRS, LOGL_NOTICE, "%s %s not allowed in PTP BVC\n", log_pfx, pdut_name);
Harald Welte278dd272020-12-06 13:35:24 +0100520 return bssgp_tx_status(BSSGP_CAUSE_PROTO_ERR_UNSPEC, NULL, msg);
521 }
522
523 if (!(bssgp_pdu_type_flags(bgph->pdu_type) & BSSGP_PDUF_DL)) {
Harald Weltee5209642020-12-05 19:59:45 +0100524 LOGP(DGPRS, LOGL_NOTICE, "%s %s not allowed in downlink direction\n", log_pfx, pdut_name);
Harald Welte278dd272020-12-06 13:35:24 +0100525 return bssgp_tx_status(BSSGP_CAUSE_PROTO_ERR_UNSPEC, NULL, msg);
526 }
527
Harald Weltee5209642020-12-05 19:59:45 +0100528 sgsn_bvc = gbproxy_bvc_by_bvci(nse, ns_bvci);
529 if (!sgsn_bvc) {
530 LOGP(DGPRS, LOGL_NOTICE, "%s %s - Didn't find BVC for for PTP message, discarding\n",
531 log_pfx, pdut_name);
532 rate_ctr_inc(&nse->cfg->ctrg-> ctr[GBPROX_GLOB_CTR_INV_BVCI]);
533 return bssgp_tx_status(BSSGP_CAUSE_UNKNOWN_BVCI, &ns_bvci, msg);
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +0200534 }
535
Harald Weltee5209642020-12-05 19:59:45 +0100536 if (!bssgp_bvc_fsm_is_unblocked(sgsn_bvc->fi)) {
537 LOGPBVC(sgsn_bvc, LOGL_NOTICE, "Rx %s: Dropping on blocked BVC\n", pdut_name);
538 rate_ctr_inc(&sgsn_bvc->ctrg->ctr[GBPROX_PEER_CTR_DROPPED]);
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +0200539 return bssgp_tx_status(BSSGP_CAUSE_BVCI_BLOCKED, &ns_bvci, msg);
540 }
Harald Welte85a40272020-12-08 21:43:22 +0100541
542 /* DL_UNITDATA has a different header than all other uplink PDUs */
543 if (bgph->pdu_type == BSSGP_PDUT_DL_UNITDATA) {
544 const struct bssgp_ud_hdr *budh = (struct bssgp_ud_hdr *) msgb_bssgph(msg);
545 if (msgb_bssgp_len(msg) < sizeof(*budh))
546 return bssgp_tx_status(BSSGP_CAUSE_INV_MAND_INF, NULL, msg);
547 rc = osmo_tlv_prot_parse(&osmo_pdef_bssgp, &tp, 1, bgph->pdu_type, budh->data,
548 msgb_bssgp_len(msg) - sizeof(*budh), 0, 0, DGPRS, log_pfx);
549 /* populate TLLI from the fixed headser into the TLV-parsed array so later code
550 * doesn't have to worry where the TLLI came from */
551 tp.lv[BSSGP_IE_TLLI].len = 4;
552 tp.lv[BSSGP_IE_TLLI].val = (const uint8_t *) &budh->tlli;
553 } else {
554 rc = osmo_tlv_prot_parse(&osmo_pdef_bssgp, &tp, 1, bgph->pdu_type, bgph->data,
555 msgb_bssgp_len(msg) - sizeof(*bgph), 0, 0, DGPRS, log_pfx);
556 }
557 if (rc < 0) {
558 rate_ctr_inc(&nse->cfg->ctrg->ctr[GBPROX_GLOB_CTR_PROTO_ERR_BSS]);
559 return tx_status_from_tlvp(rc, msg);
560 }
561 /* hack to get both msg + tlv_parsed passed via osmo_fsm_inst_dispatch */
562 msgb_bcid(msg) = (void *)&tp;
563
Harald Weltee5209642020-12-05 19:59:45 +0100564 OSMO_ASSERT(sgsn_bvc->cell);
565 bss_bvc = sgsn_bvc->cell->bss_bvc;
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +0200566
Harald Welte85a40272020-12-08 21:43:22 +0100567 switch (bgph->pdu_type) {
568 case BSSGP_PDUT_FLOW_CONTROL_BVC_ACK:
569 return osmo_fsm_inst_dispatch(sgsn_bvc->fi, BSSGP_BVCFSM_E_RX_FC_BVC_ACK, msg);
Daniel Willmann5614e572021-01-18 18:38:27 +0100570 case BSSGP_PDUT_DUMMY_PAGING_PS:
571 case BSSGP_PDUT_PAGING_PS:
572 {
573 /* Cache the IMSI<->NSE to route PAGING REJECT */
574 struct osmo_mobile_identity mi;
575 const uint8_t *mi_data = TLVP_VAL(&tp, BSSGP_IE_IMSI);
576 uint8_t mi_len = TLVP_LEN(&tp, BSSGP_IE_IMSI);
577 osmo_mobile_identity_decode(&mi, mi_data, mi_len, false);
578 gbproxy_imsi_cache_update(nse, mi.imsi);
579 break;
Harald Welte85a40272020-12-08 21:43:22 +0100580 }
Daniel Willmann5614e572021-01-18 18:38:27 +0100581 default:
582 break;
583 }
584 return gbprox_relay2peer(msg, bss_bvc, bss_bvc->bvci);
Harald Welte85a40272020-12-08 21:43:22 +0100585
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +0200586}
587
Harald Weltee5209642020-12-05 19:59:45 +0100588/***********************************************************************
589 * BVC FSM call-backs
590 ***********************************************************************/
Harald Welte7df1e5a2020-12-02 22:53:26 +0100591
Harald Weltee5209642020-12-05 19:59:45 +0100592/* helper function to dispatch a FSM event to all SGSN-side BVC FSMs of a cell */
593static void dispatch_to_all_sgsn_bvc(struct gbproxy_cell *cell, uint32_t event, void *priv)
594{
595 unsigned int i;
596
597 for (i = 0; i < ARRAY_SIZE(cell->sgsn_bvc); i++) {
598 struct gbproxy_bvc *sgsn_bvc = cell->sgsn_bvc[i];
599 if (!sgsn_bvc)
600 continue;
601 osmo_fsm_inst_dispatch(sgsn_bvc->fi, event, priv);
602 }
603}
604
605/* BVC FSM informs us about a BSS-side reset of the signaling BVC */
606static void bss_sig_bvc_reset_notif(uint16_t nsei, uint16_t bvci, const struct gprs_ra_id *ra_id,
607 uint16_t cell_id, uint8_t cause, void *priv)
608{
609 struct gbproxy_bvc *sig_bvc = priv;
610 struct gbproxy_nse *nse = sig_bvc->nse;
611 struct gbproxy_bvc *ptp_bvc;
612 unsigned int i;
613
614 /* BLOCK all SGSN-side PTP BVC within this NSE */
615 hash_for_each(nse->bvcs, i, ptp_bvc, list) {
616 if (ptp_bvc == sig_bvc)
617 continue;
618 OSMO_ASSERT(ptp_bvc->cell);
619
620 dispatch_to_all_sgsn_bvc(ptp_bvc->cell, BSSGP_BVCFSM_E_REQ_BLOCK, &cause);
Harald Weltef9e149b2020-12-02 23:29:38 +0100621 }
Harald Welte7df1e5a2020-12-02 22:53:26 +0100622
Harald Weltee5209642020-12-05 19:59:45 +0100623 /* Delete all BSS-side PTP BVC within this NSE */
624 gbproxy_cleanup_bvcs(nse, 0);
625
626 /* TODO: we keep the "CELL" around for now, re-connecting it to
627 * any (later) new PTP-BVC for that BVCI. Not sure if that's the
628 * best idea ? */
629}
630
631/* forward declaration */
632static const struct bssgp_bvc_fsm_ops sgsn_ptp_bvc_fsm_ops;
633
634static const struct bssgp_bvc_fsm_ops bss_sig_bvc_fsm_ops = {
635 .reset_notification = bss_sig_bvc_reset_notif,
636};
637
638/* BVC FSM informs us about a BSS-side reset of a PTP BVC */
639static void bss_ptp_bvc_reset_notif(uint16_t nsei, uint16_t bvci, const struct gprs_ra_id *ra_id,
640 uint16_t cell_id, uint8_t cause, void *priv)
641{
642 struct gbproxy_bvc *bvc = priv;
643 struct gbproxy_config *cfg = bvc->nse->cfg;
Harald Welte664c24e2020-12-12 15:01:17 +0100644 struct gbproxy_nse *sgsn_nse;
Harald Weltee5209642020-12-05 19:59:45 +0100645 unsigned int i;
646
647 OSMO_ASSERT(bvci != 0);
648
649 if (!bvc->cell) {
650 /* see if we have a CELL dangling around */
651 bvc->cell = gbproxy_cell_by_bvci(cfg, bvci);
652 if (bvc->cell) {
653 /* the CELL already exists. This means either it * was created before at an
654 * earlier PTP BVC-RESET, or that there are non-unique BVCIs and hence a
655 * malconfiguration */
656 if (bvc->cell->bss_bvc) {
657 LOGPBVC(bvc, LOGL_NOTICE, "Rx BVC-RESET via this NSE, but CELL already "
658 "has BVC on NSEI=%05u\n", bvc->cell->bss_bvc->nse->nsei);
659 LOGPBVC(bvc->cell->bss_bvc, LOGL_NOTICE, "Destroying due to conflicting "
660 "BVCI configuration (new NSEI=%05u)!\n", bvc->nse->nsei);
661 gbproxy_bvc_free(bvc->cell->bss_bvc);
662 }
663 bvc->cell->bss_bvc = bvc;
664 }
665 }
666
667 if (!bvc->cell) {
Harald Weltee5209642020-12-05 19:59:45 +0100668 /* if we end up here, it means this is the first time we received a BVC-RESET
669 * for this BVC. We need to create the 'cell' data structure and the SGSN-side
670 * BVC counterparts */
671
Philipp Maiere4597ec2021-02-09 16:02:00 +0100672 bvc->cell = gbproxy_cell_alloc(cfg, bvci, ra_id, cell_id);
Harald Weltee5209642020-12-05 19:59:45 +0100673 OSMO_ASSERT(bvc->cell);
674
675 /* link us to the cell and vice-versa */
676 bvc->cell->bss_bvc = bvc;
Harald Welte664c24e2020-12-12 15:01:17 +0100677 }
Harald Weltee5209642020-12-05 19:59:45 +0100678
Harald Welte664c24e2020-12-12 15:01:17 +0100679 /* allocate (any missing) SGSN-side BVCs within the cell, and reset them */
680 hash_for_each(cfg->sgsn_nses, i, sgsn_nse, list) {
681 struct gbproxy_bvc *sgsn_bvc = gbproxy_bvc_by_bvci(sgsn_nse, bvci);
682 if (sgsn_bvc)
683 OSMO_ASSERT(sgsn_bvc->cell == bvc->cell || !sgsn_bvc->cell);
Harald Weltee5209642020-12-05 19:59:45 +0100684
Harald Welte664c24e2020-12-12 15:01:17 +0100685 if (!sgsn_bvc) {
686 sgsn_bvc = gbproxy_bvc_alloc(sgsn_nse, bvci);
687 OSMO_ASSERT(sgsn_bvc);
Harald Weltee5209642020-12-05 19:59:45 +0100688
Harald Welte664c24e2020-12-12 15:01:17 +0100689 sgsn_bvc->cell = bvc->cell;
Philipp Maierda3af942021-02-04 21:54:09 +0100690 memcpy(&sgsn_bvc->raid, &bvc->cell->id.raid, sizeof(sgsn_bvc->raid));
Harald Welte664c24e2020-12-12 15:01:17 +0100691 sgsn_bvc->fi = bssgp_bvc_fsm_alloc_ptp_bss(sgsn_bvc, cfg->nsi, sgsn_nse->nsei,
692 bvci, ra_id, cell_id);
693 OSMO_ASSERT(sgsn_bvc->fi);
694 bssgp_bvc_fsm_set_ops(sgsn_bvc->fi, &sgsn_ptp_bvc_fsm_ops, sgsn_bvc);
Harald Weltee5209642020-12-05 19:59:45 +0100695
Harald Welte664c24e2020-12-12 15:01:17 +0100696 gbproxy_cell_add_sgsn_bvc(bvc->cell, sgsn_bvc);
Harald Weltee5209642020-12-05 19:59:45 +0100697 }
698 }
699
700 /* Trigger outbound BVC-RESET procedure toward each SGSN */
701 dispatch_to_all_sgsn_bvc(bvc->cell, BSSGP_BVCFSM_E_REQ_RESET, &cause);
702}
703
704/* BVC FSM informs us about a BSS-side FSM state change */
705static void bss_ptp_bvc_state_chg_notif(uint16_t nsei, uint16_t bvci, int old_state, int state, void *priv)
706{
707 struct gbproxy_bvc *bvc = priv;
708 struct gbproxy_cell *cell = bvc->cell;
709 uint8_t cause = bssgp_bvc_fsm_get_block_cause(bvc->fi);
710
711 /* we have just been created but due to callback ordering the cell is not associated */
712 if (!cell)
713 return;
714
715 switch (state) {
716 case BSSGP_BVCFSM_S_BLOCKED:
717 /* block the corresponding SGSN-side PTP BVCs */
718 dispatch_to_all_sgsn_bvc(cell, BSSGP_BVCFSM_E_REQ_BLOCK, &cause);
719 break;
720 case BSSGP_BVCFSM_S_UNBLOCKED:
721 /* unblock the corresponding SGSN-side PTP BVCs */
722 dispatch_to_all_sgsn_bvc(cell, BSSGP_BVCFSM_E_REQ_UNBLOCK, NULL);
723 break;
724 }
725}
726
Harald Welte85a40272020-12-08 21:43:22 +0100727/* BVC FSM informs us about BVC-FC PDU receive */
728static void bss_ptp_bvc_fc_bvc(uint16_t nsei, uint16_t bvci, const struct bssgp2_flow_ctrl *fc, void *priv)
729{
Harald Welte209dc9f2020-12-12 19:02:16 +0100730 struct bssgp2_flow_ctrl fc_reduced;
Harald Welte85a40272020-12-08 21:43:22 +0100731 struct gbproxy_bvc *bss_bvc = priv;
Harald Welte209dc9f2020-12-12 19:02:16 +0100732 struct gbproxy_cell *cell;
733 struct gbproxy_config *cfg;
Harald Welte85a40272020-12-08 21:43:22 +0100734
Harald Welte209dc9f2020-12-12 19:02:16 +0100735 OSMO_ASSERT(bss_bvc);
736 OSMO_ASSERT(fc);
737
738 cell = bss_bvc->cell;
Harald Welte85a40272020-12-08 21:43:22 +0100739 if (!cell)
740 return;
741
Harald Welte209dc9f2020-12-12 19:02:16 +0100742 cfg = cell->cfg;
Harald Welte85a40272020-12-08 21:43:22 +0100743
Harald Welte209dc9f2020-12-12 19:02:16 +0100744 /* reduce / scale according to configuration to make sure we only advertise a fraction
745 * of the capacity to each of the SGSNs in the pool */
746 fc_reduced = *fc;
747 fc_reduced.bucket_size_max = (fc->bucket_size_max * cfg->pool.bvc_fc_ratio) / 100;
748 fc_reduced.bucket_leak_rate = (fc->bucket_leak_rate * cfg->pool.bvc_fc_ratio) / 100;
749 /* we don't modify the per-MS related values as any single MS is only served by one SGSN */
750
751 dispatch_to_all_sgsn_bvc(cell, BSSGP_BVCFSM_E_REQ_FC_BVC, (void *) &fc_reduced);
Harald Welte85a40272020-12-08 21:43:22 +0100752}
753
Harald Weltee5209642020-12-05 19:59:45 +0100754static const struct bssgp_bvc_fsm_ops bss_ptp_bvc_fsm_ops = {
755 .reset_notification = bss_ptp_bvc_reset_notif,
756 .state_chg_notification = bss_ptp_bvc_state_chg_notif,
Harald Welte85a40272020-12-08 21:43:22 +0100757 .rx_fc_bvc = bss_ptp_bvc_fc_bvc,
Harald Weltee5209642020-12-05 19:59:45 +0100758};
759
760/* BVC FSM informs us about a SGSN-side reset of a PTP BVC */
761static void sgsn_ptp_bvc_reset_notif(uint16_t nsei, uint16_t bvci, const struct gprs_ra_id *ra_id,
762 uint16_t cell_id, uint8_t cause, void *priv)
763{
764 struct gbproxy_bvc *bvc = priv;
765
766 if (!bvc->cell) {
767 LOGPBVC(bvc, LOGL_ERROR, "RESET of PTP BVC on SGSN side for which we have no BSS?\n");
768 return;
769 }
770
771 OSMO_ASSERT(bvc->cell->bss_bvc);
772
773 /* request reset of BSS-facing PTP-BVC */
774 osmo_fsm_inst_dispatch(bvc->cell->bss_bvc->fi, BSSGP_BVCFSM_E_REQ_RESET, &cause);
775}
776
777static const struct bssgp_bvc_fsm_ops sgsn_ptp_bvc_fsm_ops = {
778 .reset_notification = sgsn_ptp_bvc_reset_notif,
779};
780
781/* BVC FSM informs us about a SGSN-side reset of the signaling BVC */
782static void sgsn_sig_bvc_reset_notif(uint16_t nsei, uint16_t bvci, const struct gprs_ra_id *ra_id,
783 uint16_t cell_id, uint8_t cause, void *priv)
784{
785 struct gbproxy_bvc *bvc = priv;
786 struct gbproxy_config *cfg = bvc->nse->cfg;
787 struct gbproxy_nse *bss_nse;
788 unsigned int i;
789
790 /* delete all SGSN-side PTP BVC for this SGSN */
791 gbproxy_cleanup_bvcs(bvc->nse, 0);
792 /* FIXME: what to do about the cells? */
793 /* FIXME: do we really want to RESET all signaling BVC on the BSS and affect all other SGSN? */
794
795 /* we need to trigger generating a reset procedure towards each BSS side signaling BVC */
796 hash_for_each(cfg->bss_nses, i, bss_nse, list) {
797 struct gbproxy_bvc *bss_bvc = gbproxy_bvc_by_bvci(bss_nse, 0);
798 if (!bss_bvc) {
799 LOGPNSE(bss_nse, LOGL_ERROR, "Doesn't have BVC with BVCI=0 ?!?\n");
800 continue;
801 }
802 osmo_fsm_inst_dispatch(bss_bvc->fi, BSSGP_BVCFSM_E_REQ_RESET, &cause);
803 }
804}
805
806const struct bssgp_bvc_fsm_ops sgsn_sig_bvc_fsm_ops = {
807 .reset_notification = sgsn_sig_bvc_reset_notif,
808};
809
810/***********************************************************************
811 * Signaling BVC handling
812 ***********************************************************************/
813
814/* process a BVC-RESET message from the BSS side */
815static int rx_bvc_reset_from_bss(struct gbproxy_nse *nse, struct msgb *msg, struct tlv_parsed *tp)
816{
817 struct gbproxy_bvc *from_bvc = NULL;
818 uint16_t bvci = ntohs(tlvp_val16_unal(tp, BSSGP_IE_BVCI));
819 uint32_t features = 0; // FIXME: make configurable
820
821 LOGPNSE(nse, LOGL_INFO, "Rx BVC-RESET (BVCI=%05u)\n", bvci);
822
Harald Welte314647b2020-12-02 23:03:22 +0100823 if (bvci == 0) {
824 /* If we receive a BVC reset on the signalling endpoint, we
825 * don't want the SGSN to reset, as the signalling endpoint
826 * is common for all point-to-point BVCs (and thus all BTS) */
Harald Welte324f0652020-12-02 23:06:37 +0100827
Harald Weltee5209642020-12-05 19:59:45 +0100828 from_bvc = gbproxy_bvc_by_bvci(nse, 0);
Harald Welte560bdb32020-12-04 22:24:47 +0100829 if (!from_bvc) {
Harald Weltee5209642020-12-05 19:59:45 +0100830 from_bvc = gbproxy_bvc_alloc(nse, 0);
831 OSMO_ASSERT(from_bvc);
832 from_bvc->fi = bssgp_bvc_fsm_alloc_sig_sgsn(from_bvc, nse->cfg->nsi, nse->nsei, features);
833 if (!from_bvc->fi) {
834 LOGPNSE(nse, LOGL_ERROR, "Cannot allocate SIG-BVC FSM\n");
835 gbproxy_bvc_free(from_bvc);
836 return -ENOMEM;
Harald Welte7df1e5a2020-12-02 22:53:26 +0100837 }
Harald Weltee5209642020-12-05 19:59:45 +0100838 bssgp_bvc_fsm_set_ops(from_bvc->fi, &bss_sig_bvc_fsm_ops, from_bvc);
839 }
840 } else {
841 from_bvc = gbproxy_bvc_by_bvci(nse, bvci);
842 if (!from_bvc) {
Harald Welte7df1e5a2020-12-02 22:53:26 +0100843 /* if a PTP-BVC is reset, and we don't know that
Harald Welte560bdb32020-12-04 22:24:47 +0100844 * PTP-BVCI yet, we should allocate a new bvc */
845 from_bvc = gbproxy_bvc_alloc(nse, bvci);
846 OSMO_ASSERT(from_bvc);
Harald Weltee5209642020-12-05 19:59:45 +0100847 from_bvc->fi = bssgp_bvc_fsm_alloc_ptp_sgsn(from_bvc, nse->cfg->nsi,
848 nse->nsei, bvci);
849 if (!from_bvc->fi) {
850 LOGPNSE(nse, LOGL_ERROR, "Cannot allocate SIG-BVC FSM\n");
851 gbproxy_bvc_free(from_bvc);
852 return -ENOMEM;
853 }
854 bssgp_bvc_fsm_set_ops(from_bvc->fi, &bss_ptp_bvc_fsm_ops, from_bvc);
Harald Welte7df1e5a2020-12-02 22:53:26 +0100855 }
Harald Weltee5209642020-12-05 19:59:45 +0100856#if 0
Harald Welte7df1e5a2020-12-02 22:53:26 +0100857 /* Could have moved to a different NSE */
Harald Welte560bdb32020-12-04 22:24:47 +0100858 if (!check_bvc_nsei(from_bvc, nsei)) {
859 LOGPBVC(from_bvc, LOGL_NOTICE, "moving bvc to NSE(%05u)\n", nsei);
Harald Welte7df1e5a2020-12-02 22:53:26 +0100860
Harald Weltee5209642020-12-05 19:59:45 +0100861 struct gbproxy_nse *nse_new = gbproxy_nse_by_nsei(cfg, nsei, false);
Harald Welte7df1e5a2020-12-02 22:53:26 +0100862 if (!nse_new) {
863 LOGP(DGPRS, LOGL_NOTICE, "NSE(%05u) Got PtP BVC reset before signalling reset for "
864 "BVCI=%05u\n", bvci, nsei);
865 bssgp_tx_status(BSSGP_CAUSE_PDU_INCOMP_STATE, NULL, msg);
866 return 0;
867 }
868
Harald Welte560bdb32020-12-04 22:24:47 +0100869 /* Move bvc to different NSE */
870 gbproxy_bvc_move(from_bvc, nse_new);
Harald Welte7df1e5a2020-12-02 22:53:26 +0100871 }
Harald Weltee5209642020-12-05 19:59:45 +0100872#endif
873 /* FIXME: do we need this, if it happens within FSM? */
Harald Welte173a1822020-12-03 15:36:59 +0100874 if (TLVP_PRES_LEN(tp, BSSGP_IE_CELL_ID, 8)) {
Harald Welte7df1e5a2020-12-02 22:53:26 +0100875 struct gprs_ra_id raid;
876 /* We have a Cell Identifier present in this
877 * PDU, this means we can extend our local
878 * state information about this particular cell
879 * */
Philipp Maierda3af942021-02-04 21:54:09 +0100880 gsm48_parse_ra(&raid, TLVP_VAL(tp, BSSGP_IE_CELL_ID));
881 memcpy(&from_bvc->raid, &raid, sizeof(from_bvc->raid));
Harald Welte560bdb32020-12-04 22:24:47 +0100882 LOGPBVC(from_bvc, LOGL_INFO, "Cell ID %s\n", osmo_rai_name(&raid));
Harald Welte7df1e5a2020-12-02 22:53:26 +0100883 }
Harald Welte7df1e5a2020-12-02 22:53:26 +0100884 }
Harald Weltee5209642020-12-05 19:59:45 +0100885 /* hand into FSM for further processing */
886 osmo_fsm_inst_dispatch(from_bvc->fi, BSSGP_BVCFSM_E_RX_RESET, msg);
887 return 0;
Harald Welte7df1e5a2020-12-02 22:53:26 +0100888}
889
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +0200890/* Receive an incoming signalling message from a BSS-side NS-VC */
Harald Weltee5209642020-12-05 19:59:45 +0100891static int gbprox_rx_sig_from_bss(struct gbproxy_nse *nse, struct msgb *msg, uint16_t ns_bvci)
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +0200892{
893 struct bssgp_normal_hdr *bgph = (struct bssgp_normal_hdr *) msgb_bssgph(msg);
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +0200894 uint8_t pdu_type = bgph->pdu_type;
Harald Weltee5209642020-12-05 19:59:45 +0100895 const char *pdut_name = osmo_tlv_prot_msg_name(&osmo_pdef_bssgp, bgph->pdu_type);
Philipp Maier74882dc2021-02-04 16:31:46 +0100896 struct tlv_parsed tp[2];
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +0200897 int data_len = msgb_bssgp_len(msg) - sizeof(*bgph);
Harald Welte560bdb32020-12-04 22:24:47 +0100898 struct gbproxy_bvc *from_bvc = NULL;
Harald Welteec0f8012020-12-06 16:32:01 +0100899 char log_pfx[32];
Harald Weltee5209642020-12-05 19:59:45 +0100900 uint16_t ptp_bvci;
901 uint32_t tlli;
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +0200902 int rc;
903
Harald Weltee5209642020-12-05 19:59:45 +0100904 snprintf(log_pfx, sizeof(log_pfx), "NSE(%05u/BSS)-BVC(%05u/??)", nse->nsei, ns_bvci);
905
906 LOGP(DGPRS, LOGL_DEBUG, "%s Rx %s\n", log_pfx, pdut_name);
Harald Welteec0f8012020-12-06 16:32:01 +0100907
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +0200908 if (ns_bvci != 0 && ns_bvci != 1) {
Harald Weltee5209642020-12-05 19:59:45 +0100909 LOGP(DGPRS, LOGL_NOTICE, "%s %s BVCI=%05u is not signalling\n", log_pfx, pdut_name, ns_bvci);
Harald Welte278dd272020-12-06 13:35:24 +0100910 return bssgp_tx_status(BSSGP_CAUSE_PROTO_ERR_UNSPEC, NULL, msg);
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +0200911 }
912
Harald Welte278dd272020-12-06 13:35:24 +0100913 if (!(bssgp_pdu_type_flags(pdu_type) & BSSGP_PDUF_SIG)) {
Harald Weltee5209642020-12-05 19:59:45 +0100914 LOGP(DGPRS, LOGL_NOTICE, "%s %s not allowed in signalling BVC\n", log_pfx, pdut_name);
Harald Welte278dd272020-12-06 13:35:24 +0100915 return bssgp_tx_status(BSSGP_CAUSE_PROTO_ERR_UNSPEC, NULL, msg);
916 }
917
918 if (!(bssgp_pdu_type_flags(pdu_type) & BSSGP_PDUF_UL)) {
Harald Weltee5209642020-12-05 19:59:45 +0100919 LOGP(DGPRS, LOGL_NOTICE, "%s %s not allowed in uplink direction\n", log_pfx, pdut_name);
Harald Welte278dd272020-12-06 13:35:24 +0100920 return bssgp_tx_status(BSSGP_CAUSE_PROTO_ERR_UNSPEC, NULL, msg);
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +0200921 }
922
Philipp Maier74882dc2021-02-04 16:31:46 +0100923 rc = osmo_tlv_prot_parse(&osmo_pdef_bssgp, tp, ARRAY_SIZE(tp), pdu_type, bgph->data, data_len, 0, 0,
Harald Welteec0f8012020-12-06 16:32:01 +0100924 DGPRS, log_pfx);
925 if (rc < 0) {
Harald Weltee5209642020-12-05 19:59:45 +0100926 rate_ctr_inc(&nse->cfg->ctrg->ctr[GBPROX_GLOB_CTR_PROTO_ERR_BSS]);
Harald Welteec0f8012020-12-06 16:32:01 +0100927 return tx_status_from_tlvp(rc, msg);
928 }
Harald Weltee5209642020-12-05 19:59:45 +0100929 /* hack to get both msg + tlv_parsed passed via osmo_fsm_inst_dispatch */
Philipp Maier74882dc2021-02-04 16:31:46 +0100930 msgb_bcid(msg) = (void *)tp;
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +0200931
Harald Weltee5209642020-12-05 19:59:45 +0100932 /* special case handling for some PDU types */
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +0200933 switch (pdu_type) {
Harald Weltee5209642020-12-05 19:59:45 +0100934 case BSSGP_PDUT_BVC_RESET:
935 /* resolve or create gbproxy_bvc + handlei n BVC-FSM */
Philipp Maier74882dc2021-02-04 16:31:46 +0100936 return rx_bvc_reset_from_bss(nse, msg, &tp[0]);
Harald Weltee5209642020-12-05 19:59:45 +0100937 case BSSGP_PDUT_BVC_RESET_ACK:
Philipp Maier74882dc2021-02-04 16:31:46 +0100938 ptp_bvci = ntohs(tlvp_val16_unal(&tp[0], BSSGP_IE_BVCI));
Harald Weltee5209642020-12-05 19:59:45 +0100939 from_bvc = gbproxy_bvc_by_bvci(nse, ptp_bvci);
Harald Welte560bdb32020-12-04 22:24:47 +0100940 if (!from_bvc)
941 goto err_no_bvc;
Harald Weltee5209642020-12-05 19:59:45 +0100942 return osmo_fsm_inst_dispatch(from_bvc->fi, BSSGP_BVCFSM_E_RX_RESET_ACK, msg);
943 case BSSGP_PDUT_BVC_BLOCK:
Philipp Maier74882dc2021-02-04 16:31:46 +0100944 ptp_bvci = ntohs(tlvp_val16_unal(&tp[0], BSSGP_IE_BVCI));
Harald Weltee5209642020-12-05 19:59:45 +0100945 from_bvc = gbproxy_bvc_by_bvci(nse, ptp_bvci);
946 if (!from_bvc)
947 goto err_no_bvc;
948 return osmo_fsm_inst_dispatch(from_bvc->fi, BSSGP_BVCFSM_E_RX_BLOCK, msg);
949 case BSSGP_PDUT_BVC_UNBLOCK:
Philipp Maier74882dc2021-02-04 16:31:46 +0100950 ptp_bvci = ntohs(tlvp_val16_unal(&tp[0], BSSGP_IE_BVCI));
Harald Weltee5209642020-12-05 19:59:45 +0100951 from_bvc = gbproxy_bvc_by_bvci(nse, ptp_bvci);
952 if (!from_bvc)
953 goto err_no_bvc;
954 return osmo_fsm_inst_dispatch(from_bvc->fi, BSSGP_BVCFSM_E_RX_UNBLOCK, msg);
955 case BSSGP_PDUT_SUSPEND:
956 case BSSGP_PDUT_RESUME:
Daniel Willmann77493b12020-12-29 21:13:31 +0100957 {
958 struct gbproxy_sgsn *sgsn;
959
Philipp Maier74882dc2021-02-04 16:31:46 +0100960 tlli = osmo_load32be(TLVP_VAL(&tp[0], BSSGP_IE_TLLI));
Daniel Willmann77493b12020-12-29 21:13:31 +0100961 sgsn = gbproxy_select_sgsn(nse->cfg, &tlli);
962 if (!sgsn) {
963 LOGP(DGPRS, LOGL_ERROR, "Could not find any SGSN for TLLI, dropping message!\n");
964 rc = -EINVAL;
965 break;
966 }
967
968 gbproxy_tlli_cache_update(nse, tlli);
969
970 rc = gbprox_relay2nse(msg, sgsn->nse, 0);
Harald Weltee5209642020-12-05 19:59:45 +0100971#if 0
972 /* TODO: Validate the RAI for consistency with the RAI
973 * we expect for any of the BVC within this BSS side NSE */
Philipp Maier74882dc2021-02-04 16:31:46 +0100974 memcpy(ra, TLVP_VAL(&tp[0], BSSGP_IE_ROUTEING_AREA), sizeof(from_bvc->ra));
Harald Welte560bdb32020-12-04 22:24:47 +0100975 gsm48_parse_ra(&raid, from_bvc->ra);
Harald Weltee5209642020-12-05 19:59:45 +0100976#endif
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +0200977 break;
Daniel Willmann77493b12020-12-29 21:13:31 +0100978 }
Harald Weltee5209642020-12-05 19:59:45 +0100979 case BSSGP_PDUT_STATUS:
980 /* FIXME: inspect the erroneous PDU IE (if any) and check
981 * if we can extract a TLLI/RNI to route it to the correct SGSN */
982 break;
983 case BSSGP_PDUT_RAN_INFO:
984 case BSSGP_PDUT_RAN_INFO_REQ:
985 case BSSGP_PDUT_RAN_INFO_ACK:
986 case BSSGP_PDUT_RAN_INFO_ERROR:
987 case BSSGP_PDUT_RAN_INFO_APP_ERROR:
988 /* FIXME: route based in RIM Routing IE */
989 rc = bssgp_tx_status(BSSGP_CAUSE_PDU_INCOMP_FEAT, NULL, msg);
990 break;
991 case BSSGP_PDUT_LLC_DISCARD:
992 case BSSGP_PDUT_FLUSH_LL_ACK:
993 /* route based on BVCI + TLLI */
Philipp Maier74882dc2021-02-04 16:31:46 +0100994 ptp_bvci = ntohs(tlvp_val16_unal(&tp[0], BSSGP_IE_BVCI));
995 tlli = osmo_load32be(TLVP_VAL(&tp[0], BSSGP_IE_TLLI));
Harald Weltee5209642020-12-05 19:59:45 +0100996 from_bvc = gbproxy_bvc_by_bvci(nse, ptp_bvci);
997 if (!from_bvc)
998 goto err_no_bvc;
Daniel Willmannd4ab1f92020-12-21 18:53:55 +0100999 gbprox_bss2sgsn_tlli(from_bvc->cell, msg, &tlli, true);
Harald Weltee5209642020-12-05 19:59:45 +01001000 break;
Daniel Willmann8613c9d2021-01-17 13:40:38 +01001001 case BSSGP_PDUT_PAGING_PS_REJECT:
Daniel Willmann5614e572021-01-18 18:38:27 +01001002 case BSSGP_PDUT_DUMMY_PAGING_PS_RESP:
Daniel Willmann8613c9d2021-01-17 13:40:38 +01001003 {
1004 /* Route according to IMSI<->NSE cache entry */
1005 struct osmo_mobile_identity mi;
Philipp Maier74882dc2021-02-04 16:31:46 +01001006 const uint8_t *mi_data = TLVP_VAL(&tp[0], BSSGP_IE_IMSI);
1007 uint8_t mi_len = TLVP_LEN(&tp[0], BSSGP_IE_IMSI);
Daniel Willmann8613c9d2021-01-17 13:40:38 +01001008 osmo_mobile_identity_decode(&mi, mi_data, mi_len, false);
1009 nse = gbproxy_nse_by_imsi(nse->cfg, mi.imsi);
1010 if (!nse) {
1011 return bssgp_tx_status(BSSGP_CAUSE_INV_MAND_INF, NULL, msg);
1012 }
Daniel Willmann5614e572021-01-18 18:38:27 +01001013 OSMO_ASSERT(nse->sgsn_facing);
Daniel Willmann8613c9d2021-01-17 13:40:38 +01001014 rc = gbprox_relay2nse(msg, nse, 0);
1015 break;
1016 }
Harald Weltee5209642020-12-05 19:59:45 +01001017 default:
1018 LOGPNSE(nse, LOGL_ERROR, "Rx %s: Implementation missing\n", pdut_name);
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001019 break;
1020 }
1021
Harald Weltee5209642020-12-05 19:59:45 +01001022 return rc;
Harald Welte560bdb32020-12-04 22:24:47 +01001023err_no_bvc:
Harald Weltee5209642020-12-05 19:59:45 +01001024 LOGPNSE(nse, LOGL_ERROR, "Rx %s: cannot find BVC for BVCI=%05u\n", pdut_name, ptp_bvci);
1025 rate_ctr_inc(&nse->cfg->ctrg->ctr[GBPROX_GLOB_CTR_INV_NSEI]);
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001026 return bssgp_tx_status(BSSGP_CAUSE_INV_MAND_INF, NULL, msg);
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001027}
1028
1029/* Receive paging request from SGSN, we need to relay to proper BSS */
Harald Weltedf690e82020-12-12 15:58:28 +01001030static int gbprox_rx_paging(struct gbproxy_nse *sgsn_nse, struct msgb *msg, const char *pdut_name,
Daniel Willmann5614e572021-01-18 18:38:27 +01001031 struct tlv_parsed *tp, uint16_t ns_bvci, bool broadcast)
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001032{
Harald Weltedf690e82020-12-12 15:58:28 +01001033 struct gbproxy_config *cfg = sgsn_nse->cfg;
Harald Weltee5209642020-12-05 19:59:45 +01001034 struct gbproxy_bvc *sgsn_bvc, *bss_bvc;
Harald Weltedf690e82020-12-12 15:58:28 +01001035 struct gbproxy_nse *nse;
Daniel Willmann76205712020-11-30 17:08:58 +01001036 unsigned int n_nses = 0;
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001037 int errctr = GBPROX_GLOB_CTR_PROTO_ERR_SGSN;
Harald Welte8b4c7942020-12-05 10:14:49 +01001038 int i, j;
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001039
Daniel Willmanne50550e2020-11-26 18:19:21 +01001040 /* FIXME: Handle paging logic to only page each matching NSE */
1041
Harald Welte173a1822020-12-03 15:36:59 +01001042 if (TLVP_PRES_LEN(tp, BSSGP_IE_BVCI, 2)) {
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001043 uint16_t bvci = ntohs(tlvp_val16_unal(tp, BSSGP_IE_BVCI));
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001044 errctr = GBPROX_GLOB_CTR_OTHER_ERR;
Harald Weltedf690e82020-12-12 15:58:28 +01001045 sgsn_bvc = gbproxy_bvc_by_bvci(sgsn_nse, bvci);
Harald Weltee5209642020-12-05 19:59:45 +01001046 if (!sgsn_bvc) {
Harald Weltedf690e82020-12-12 15:58:28 +01001047 LOGPNSE(sgsn_nse, LOGL_NOTICE, "Rx %s: unable to route: BVCI=%05u unknown\n",
Harald Weltee5209642020-12-05 19:59:45 +01001048 pdut_name, bvci);
Harald Welte3d1bd4d2020-11-23 15:14:20 +01001049 rate_ctr_inc(&cfg->ctrg->ctr[errctr]);
1050 return -EINVAL;
1051 }
Harald Weltee5209642020-12-05 19:59:45 +01001052 LOGPBVC(sgsn_bvc, LOGL_INFO, "Rx %s: routing by BVCI\n", pdut_name);
1053 return gbprox_relay2peer(msg, sgsn_bvc->cell->bss_bvc, ns_bvci);
Harald Welte173a1822020-12-03 15:36:59 +01001054 } else if (TLVP_PRES_LEN(tp, BSSGP_IE_ROUTEING_AREA, 6)) {
Philipp Maierda3af942021-02-04 21:54:09 +01001055 struct gprs_ra_id raid;
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001056 errctr = GBPROX_GLOB_CTR_INV_RAI;
Philipp Maierda3af942021-02-04 21:54:09 +01001057 gsm48_parse_ra(&raid, TLVP_VAL(tp, BSSGP_IE_ROUTEING_AREA));
Harald Welte560bdb32020-12-04 22:24:47 +01001058 /* iterate over all bvcs and dispatch the paging to each matching one */
Harald Welted2fef952020-12-05 00:31:07 +01001059 hash_for_each(cfg->bss_nses, i, nse, list) {
Harald Weltee5209642020-12-05 19:59:45 +01001060 hash_for_each(nse->bvcs, j, bss_bvc, list) {
Philipp Maierda3af942021-02-04 21:54:09 +01001061 if (gsm48_ra_equal(&bss_bvc->raid, &raid)) {
Harald Weltee5209642020-12-05 19:59:45 +01001062 LOGPNSE(nse, LOGL_INFO, "Rx %s: routing to NSE (RAI match)\n",
1063 pdut_name);
1064 gbprox_relay2peer(msg, bss_bvc, ns_bvci);
Daniel Willmann76205712020-11-30 17:08:58 +01001065 n_nses++;
1066 /* Only send it once to each NSE */
1067 break;
Daniel Willmanne50550e2020-11-26 18:19:21 +01001068 }
Harald Welte3d1bd4d2020-11-23 15:14:20 +01001069 }
1070 }
Harald Welte173a1822020-12-03 15:36:59 +01001071 } else if (TLVP_PRES_LEN(tp, BSSGP_IE_LOCATION_AREA, 5)) {
Philipp Maierda3af942021-02-04 21:54:09 +01001072 struct gsm48_ra_id lac;
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001073 errctr = GBPROX_GLOB_CTR_INV_LAI;
Harald Welte560bdb32020-12-04 22:24:47 +01001074 /* iterate over all bvcs and dispatch the paging to each matching one */
Harald Welted2fef952020-12-05 00:31:07 +01001075 hash_for_each(cfg->bss_nses, i, nse, list) {
Harald Weltee5209642020-12-05 19:59:45 +01001076 hash_for_each(nse->bvcs, j, bss_bvc, list) {
Philipp Maierda3af942021-02-04 21:54:09 +01001077 gsm48_encode_ra(&lac, &bss_bvc->raid);
1078 if (!memcmp(&lac, TLVP_VAL(tp, BSSGP_IE_LOCATION_AREA), 5)) {
Harald Weltee5209642020-12-05 19:59:45 +01001079 LOGPNSE(nse, LOGL_INFO, "Rx %s: routing to NSE (LAI match)\n",
1080 pdut_name);
1081 gbprox_relay2peer(msg, bss_bvc, ns_bvci);
Daniel Willmann76205712020-11-30 17:08:58 +01001082 n_nses++;
1083 /* Only send it once to each NSE */
1084 break;
Daniel Willmanne50550e2020-11-26 18:19:21 +01001085 }
Harald Welte3d1bd4d2020-11-23 15:14:20 +01001086 }
1087 }
Daniel Willmann5614e572021-01-18 18:38:27 +01001088 } else if (TLVP_PRES_LEN(tp, BSSGP_IE_BSS_AREA_ID, 1) || broadcast) {
Harald Welte560bdb32020-12-04 22:24:47 +01001089 /* iterate over all bvcs and dispatch the paging to each matching one */
Harald Welted2fef952020-12-05 00:31:07 +01001090 hash_for_each(cfg->bss_nses, i, nse, list) {
Harald Weltee5209642020-12-05 19:59:45 +01001091 hash_for_each(nse->bvcs, j, bss_bvc, list) {
1092 LOGPNSE(nse, LOGL_INFO, "Rx %s:routing to NSE (broadcast)\n", pdut_name);
1093 gbprox_relay2peer(msg, bss_bvc, ns_bvci);
Daniel Willmann76205712020-11-30 17:08:58 +01001094 n_nses++;
1095 /* Only send it once to each NSE */
1096 break;
Daniel Willmanne50550e2020-11-26 18:19:21 +01001097 }
Harald Welte53ee2062020-11-24 11:31:13 +01001098 }
1099 } else {
Harald Weltedf690e82020-12-12 15:58:28 +01001100 LOGPNSE(sgsn_nse, LOGL_ERROR, "BSSGP PAGING: unable to route, missing IE\n");
Harald Welte53ee2062020-11-24 11:31:13 +01001101 rate_ctr_inc(&cfg->ctrg->ctr[errctr]);
1102 }
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001103
Daniel Willmann76205712020-11-30 17:08:58 +01001104 if (n_nses == 0) {
Harald Weltedf690e82020-12-12 15:58:28 +01001105 LOGPNSE(sgsn_nse, LOGL_ERROR, "BSSGP PAGING: unable to route, no destination found\n");
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001106 rate_ctr_inc(&cfg->ctrg->ctr[errctr]);
1107 return -EINVAL;
1108 }
Harald Welte3d1bd4d2020-11-23 15:14:20 +01001109 return 0;
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001110}
1111
1112/* Receive an incoming BVC-RESET message from the SGSN */
Harald Weltee5209642020-12-05 19:59:45 +01001113static int rx_bvc_reset_from_sgsn(struct gbproxy_nse *nse, struct msgb *msg, struct tlv_parsed *tp,
1114 uint16_t ns_bvci)
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001115{
Harald Weltee5209642020-12-05 19:59:45 +01001116 uint16_t ptp_bvci = ntohs(tlvp_val16_unal(tp, BSSGP_IE_BVCI));
1117 struct gbproxy_bvc *from_bvc;
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001118
Harald Weltee5209642020-12-05 19:59:45 +01001119 LOGPNSE(nse, LOGL_INFO, "Rx BVC-RESET (BVCI=%05u)\n", ptp_bvci);
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001120
Harald Weltee5209642020-12-05 19:59:45 +01001121 if (ptp_bvci == 0) {
1122 from_bvc = gbproxy_bvc_by_bvci(nse, 0);
1123 OSMO_ASSERT(from_bvc);
1124 osmo_fsm_inst_dispatch(from_bvc->fi, BSSGP_BVCFSM_E_RX_RESET, msg);
1125 } else {
1126 from_bvc = gbproxy_bvc_by_bvci(nse, ptp_bvci);
1127 if (!from_bvc) {
1128 LOGPNSE(nse, LOGL_ERROR, "Rx BVC-RESET BVCI=%05u: Cannot find BVC\n", ptp_bvci);
1129 rate_ctr_inc(&nse->cfg->ctrg->ctr[GBPROX_GLOB_CTR_INV_BVCI]);
1130 return bssgp_tx_status(BSSGP_CAUSE_UNKNOWN_BVCI, &ptp_bvci, msg);
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001131 }
Harald Weltee5209642020-12-05 19:59:45 +01001132 osmo_fsm_inst_dispatch(from_bvc->fi, BSSGP_BVCFSM_E_RX_RESET, msg);
Daniel Willmanne50550e2020-11-26 18:19:21 +01001133 }
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001134
1135 return 0;
1136}
1137
1138/* Receive an incoming signalling message from the SGSN-side NS-VC */
Harald Weltedbef0aa2020-12-07 17:48:11 +01001139static int gbprox_rx_sig_from_sgsn(struct gbproxy_nse *nse, struct msgb *msg, uint16_t ns_bvci)
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001140{
Harald Weltedbef0aa2020-12-07 17:48:11 +01001141 struct bssgp_normal_hdr *bgph = (struct bssgp_normal_hdr *) msgb_bssgph(msg);
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001142 uint8_t pdu_type = bgph->pdu_type;
Harald Weltee5209642020-12-05 19:59:45 +01001143 const char *pdut_name = osmo_tlv_prot_msg_name(&osmo_pdef_bssgp, bgph->pdu_type);
1144 struct gbproxy_config *cfg = nse->cfg;
1145 struct gbproxy_bvc *sgsn_bvc;
Philipp Maier74882dc2021-02-04 16:31:46 +01001146 struct tlv_parsed tp[2];
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001147 int data_len;
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001148 uint16_t bvci;
Harald Welteec0f8012020-12-06 16:32:01 +01001149 char log_pfx[32];
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001150 int rc = 0;
1151 int cause;
Harald Welted2fef952020-12-05 00:31:07 +01001152 int i;
Daniel Willmann5614e572021-01-18 18:38:27 +01001153 bool paging_bc = false;
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001154
Harald Weltee5209642020-12-05 19:59:45 +01001155 snprintf(log_pfx, sizeof(log_pfx), "NSE(%05u/SGSN)-BVC(%05u/??)", nse->nsei, ns_bvci);
1156
1157 LOGP(DGPRS, LOGL_DEBUG, "%s Rx %s\n", log_pfx, pdut_name);
Harald Welteec0f8012020-12-06 16:32:01 +01001158
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001159 if (ns_bvci != 0 && ns_bvci != 1) {
Harald Welteec0f8012020-12-06 16:32:01 +01001160 LOGP(DGPRS, LOGL_NOTICE, "%s BVCI=%05u is not signalling\n", log_pfx, ns_bvci);
Harald Weltedbef0aa2020-12-07 17:48:11 +01001161 return bssgp_tx_status(BSSGP_CAUSE_PROTO_ERR_UNSPEC, NULL, msg);
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001162 }
1163
Harald Welte278dd272020-12-06 13:35:24 +01001164 if (!(bssgp_pdu_type_flags(pdu_type) & BSSGP_PDUF_SIG)) {
Harald Weltee5209642020-12-05 19:59:45 +01001165 LOGP(DGPRS, LOGL_NOTICE, "%s %s not allowed in signalling BVC\n", log_pfx, pdut_name);
Harald Weltedbef0aa2020-12-07 17:48:11 +01001166 return bssgp_tx_status(BSSGP_CAUSE_PROTO_ERR_UNSPEC, NULL, msg);
Harald Welte278dd272020-12-06 13:35:24 +01001167 }
1168
1169 if (!(bssgp_pdu_type_flags(pdu_type) & BSSGP_PDUF_DL)) {
Harald Weltee5209642020-12-05 19:59:45 +01001170 LOGP(DGPRS, LOGL_NOTICE, "%s %s not allowed in downlink direction\n", log_pfx, pdut_name);
Harald Weltedbef0aa2020-12-07 17:48:11 +01001171 return bssgp_tx_status(BSSGP_CAUSE_PROTO_ERR_UNSPEC, NULL, msg);
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001172 }
1173
Harald Weltedbef0aa2020-12-07 17:48:11 +01001174 data_len = msgb_bssgp_len(msg) - sizeof(*bgph);
Harald Welteec0f8012020-12-06 16:32:01 +01001175
Philipp Maier74882dc2021-02-04 16:31:46 +01001176 rc = osmo_tlv_prot_parse(&osmo_pdef_bssgp, tp, ARRAY_SIZE(tp), pdu_type, bgph->data, data_len, 0, 0,
Harald Welteec0f8012020-12-06 16:32:01 +01001177 DGPRS, log_pfx);
1178 if (rc < 0) {
1179 rc = tx_status_from_tlvp(rc, msg);
Harald Welteec0f8012020-12-06 16:32:01 +01001180 rate_ctr_inc(&cfg->ctrg->ctr[GBPROX_GLOB_CTR_PROTO_ERR_SGSN]);
1181 return rc;
1182 }
Harald Weltee5209642020-12-05 19:59:45 +01001183 /* hack to get both msg + tlv_parsed passed via osmo_fsm_inst_dispatch */
Philipp Maier74882dc2021-02-04 16:31:46 +01001184 msgb_bcid(msg) = (void *)tp;
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001185
1186 switch (pdu_type) {
1187 case BSSGP_PDUT_BVC_RESET:
Harald Weltee5209642020-12-05 19:59:45 +01001188 /* resolve or create ggbproxy_bvc + handle in BVC-FSM */
Philipp Maier74882dc2021-02-04 16:31:46 +01001189 bvci = ntohs(tlvp_val16_unal(&tp[0], BSSGP_IE_BVCI));
1190 rc = rx_bvc_reset_from_sgsn(nse, msg, &tp[0], ns_bvci);
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001191 break;
1192 case BSSGP_PDUT_BVC_RESET_ACK:
Philipp Maier74882dc2021-02-04 16:31:46 +01001193 bvci = ntohs(tlvp_val16_unal(&tp[0], BSSGP_IE_BVCI));
Harald Weltee5209642020-12-05 19:59:45 +01001194 sgsn_bvc = gbproxy_bvc_by_bvci(nse, bvci);
1195 if (!sgsn_bvc)
1196 goto err_no_bvc;
1197 rc = osmo_fsm_inst_dispatch(sgsn_bvc->fi, BSSGP_BVCFSM_E_RX_RESET_ACK, msg);
1198 break;
1199 case BSSGP_PDUT_BVC_BLOCK_ACK:
Philipp Maier74882dc2021-02-04 16:31:46 +01001200 bvci = ntohs(tlvp_val16_unal(&tp[0], BSSGP_IE_BVCI));
Harald Weltee5209642020-12-05 19:59:45 +01001201 sgsn_bvc = gbproxy_bvc_by_bvci(nse, bvci);
1202 if (!sgsn_bvc)
1203 goto err_no_bvc;
1204 rc = osmo_fsm_inst_dispatch(sgsn_bvc->fi, BSSGP_BVCFSM_E_RX_BLOCK_ACK, msg);
1205 break;
1206 case BSSGP_PDUT_BVC_UNBLOCK_ACK:
Philipp Maier74882dc2021-02-04 16:31:46 +01001207 bvci = ntohs(tlvp_val16_unal(&tp[0], BSSGP_IE_BVCI));
Harald Weltee5209642020-12-05 19:59:45 +01001208 sgsn_bvc = gbproxy_bvc_by_bvci(nse, bvci);
1209 if (!sgsn_bvc)
1210 goto err_no_bvc;
1211 rc = osmo_fsm_inst_dispatch(sgsn_bvc->fi, BSSGP_BVCFSM_E_RX_UNBLOCK_ACK, msg);
Daniel Willmann8489e7a2020-11-03 21:12:42 +01001212 break;
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001213 case BSSGP_PDUT_FLUSH_LL:
1214 /* simple case: BVCI IE is mandatory */
Philipp Maier74882dc2021-02-04 16:31:46 +01001215 bvci = ntohs(tlvp_val16_unal(&tp[0], BSSGP_IE_BVCI));
Harald Weltee5209642020-12-05 19:59:45 +01001216 sgsn_bvc = gbproxy_bvc_by_bvci(nse, bvci);
1217 if (!sgsn_bvc)
1218 goto err_no_bvc;
1219 if (sgsn_bvc->cell && sgsn_bvc->cell->bss_bvc)
1220 rc = gbprox_relay2peer(msg, sgsn_bvc->cell->bss_bvc, ns_bvci);
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001221 break;
Daniel Willmann5614e572021-01-18 18:38:27 +01001222 case BSSGP_PDUT_DUMMY_PAGING_PS:
1223 /* Routing area is optional in dummy paging and we have nothing else to go by
1224 * so in case it is missing we need to broadcast the paging */
1225 paging_bc = true;
1226 /* fall through */
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001227 case BSSGP_PDUT_PAGING_PS:
Daniel Willmann8613c9d2021-01-17 13:40:38 +01001228 {
1229 /* Cache the IMSI<->NSE to route PAGING REJECT */
1230 struct osmo_mobile_identity mi;
Philipp Maier74882dc2021-02-04 16:31:46 +01001231 const uint8_t *mi_data = TLVP_VAL(&tp[0], BSSGP_IE_IMSI);
1232 uint8_t mi_len = TLVP_LEN(&tp[0], BSSGP_IE_IMSI);
Daniel Willmann8613c9d2021-01-17 13:40:38 +01001233 osmo_mobile_identity_decode(&mi, mi_data, mi_len, false);
1234 gbproxy_imsi_cache_update(nse, mi.imsi);
1235 /* fall through */
1236 }
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001237 case BSSGP_PDUT_PAGING_CS:
1238 /* process the paging request (LAI/RAI lookup) */
Philipp Maier74882dc2021-02-04 16:31:46 +01001239 rc = gbprox_rx_paging(nse, msg, pdut_name, &tp[0], ns_bvci, paging_bc);
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001240 break;
1241 case BSSGP_PDUT_STATUS:
1242 /* Some exception has occurred */
Philipp Maier74882dc2021-02-04 16:31:46 +01001243 cause = *TLVP_VAL(&tp[0], BSSGP_IE_CAUSE);
Harald Weltee5209642020-12-05 19:59:45 +01001244 LOGPNSE(nse, LOGL_NOTICE, "Rx STATUS cause=0x%02x(%s) ", cause,
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001245 bssgp_cause_str(cause));
Philipp Maier74882dc2021-02-04 16:31:46 +01001246 if (TLVP_PRES_LEN(&tp[0], BSSGP_IE_BVCI, 2)) {
1247 bvci = ntohs(tlvp_val16_unal(&tp[0], BSSGP_IE_BVCI));
Daniel Willmann3696dce2020-12-02 16:08:02 +01001248 LOGPC(DGPRS, LOGL_NOTICE, "BVCI=%05u\n", bvci);
Harald Weltee5209642020-12-05 19:59:45 +01001249 sgsn_bvc = gbproxy_bvc_by_bvci(nse, bvci);
1250 /* don't send STATUS in response to STATUS if !bvc */
1251 if (sgsn_bvc && sgsn_bvc->cell && sgsn_bvc->cell->bss_bvc)
1252 rc = gbprox_relay2peer(msg, sgsn_bvc->cell->bss_bvc, ns_bvci);
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001253 } else
1254 LOGPC(DGPRS, LOGL_NOTICE, "\n");
1255 break;
1256 /* those only exist in the SGSN -> BSS direction */
1257 case BSSGP_PDUT_SUSPEND_ACK:
1258 case BSSGP_PDUT_SUSPEND_NACK:
1259 case BSSGP_PDUT_RESUME_ACK:
1260 case BSSGP_PDUT_RESUME_NACK:
Daniel Willmann77493b12020-12-29 21:13:31 +01001261 {
1262 struct gbproxy_nse *nse_peer;
Philipp Maier74882dc2021-02-04 16:31:46 +01001263 uint32_t tlli = osmo_load32be(TLVP_VAL(&tp[0], BSSGP_IE_TLLI));
Daniel Willmann77493b12020-12-29 21:13:31 +01001264
1265 nse_peer = gbproxy_nse_by_tlli(cfg, tlli);
1266 if (!nse_peer) {
1267 LOGPNSE(nse, LOGL_ERROR, "Rx %s: Cannot find NSE\n", pdut_name);
1268 /* TODO: Counter */
1269 return bssgp_tx_status(BSSGP_CAUSE_INV_MAND_INF, NULL, msg);
1270 }
1271 /* Delete the entry after we're done */
1272 gbproxy_tlli_cache_remove(cfg, tlli);
1273 LOGPNSE(nse_peer, LOGL_DEBUG, "Rx %s: forwarding\n", pdut_name);
1274 gbprox_relay2nse(msg, nse_peer, ns_bvci);
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001275 break;
Daniel Willmann77493b12020-12-29 21:13:31 +01001276 }
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001277 case BSSGP_PDUT_SGSN_INVOKE_TRACE:
Harald Welte7479c4d2020-12-02 20:06:04 +01001278 case BSSGP_PDUT_OVERLOAD:
Harald Weltee5209642020-12-05 19:59:45 +01001279 LOGPNSE(nse, LOGL_DEBUG, "Rx %s: broadcasting\n", pdut_name);
Harald Welte560bdb32020-12-04 22:24:47 +01001280 /* broadcast to all BSS-side bvcs */
Harald Welted2fef952020-12-05 00:31:07 +01001281 hash_for_each(cfg->bss_nses, i, nse, list) {
Harald Welte7479c4d2020-12-02 20:06:04 +01001282 gbprox_relay2nse(msg, nse, 0);
1283 }
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001284 break;
Harald Weltee5209642020-12-05 19:59:45 +01001285 case BSSGP_PDUT_RAN_INFO:
1286 case BSSGP_PDUT_RAN_INFO_REQ:
1287 case BSSGP_PDUT_RAN_INFO_ACK:
1288 case BSSGP_PDUT_RAN_INFO_ERROR:
1289 case BSSGP_PDUT_RAN_INFO_APP_ERROR:
1290 /* FIXME: route based in RIM Routing IE */
Harald Weltedbef0aa2020-12-07 17:48:11 +01001291 rc = bssgp_tx_status(BSSGP_CAUSE_PDU_INCOMP_FEAT, NULL, msg);
Harald Weltee5209642020-12-05 19:59:45 +01001292 break;
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001293 default:
Harald Weltee5209642020-12-05 19:59:45 +01001294 LOGPNSE(nse, LOGL_NOTICE, "Rx %s: Not supported\n", pdut_name);
1295 rate_ctr_inc(&cfg->ctrg->ctr[GBPROX_GLOB_CTR_PROTO_ERR_SGSN]);
Harald Weltedbef0aa2020-12-07 17:48:11 +01001296 rc = bssgp_tx_status(BSSGP_CAUSE_PROTO_ERR_UNSPEC, NULL, msg);
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001297 break;
1298 }
1299
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001300 return rc;
Harald Weltee5209642020-12-05 19:59:45 +01001301
Harald Welte560bdb32020-12-04 22:24:47 +01001302err_no_bvc:
Harald Weltee5209642020-12-05 19:59:45 +01001303 LOGPNSE(nse, LOGL_ERROR, "Rx %s: Cannot find BVC\n", pdut_name);
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001304 rate_ctr_inc(&cfg->ctrg-> ctr[GBPROX_GLOB_CTR_INV_RAI]);
Harald Weltedbef0aa2020-12-07 17:48:11 +01001305 return bssgp_tx_status(BSSGP_CAUSE_INV_MAND_INF, NULL, msg);
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001306}
1307
Harald Weltee5209642020-12-05 19:59:45 +01001308
1309/***********************************************************************
1310 * libosmogb NS/BSSGP integration
1311 ***********************************************************************/
1312
Alexander Couzens951e1332020-09-22 13:21:46 +02001313int gbprox_bssgp_send_cb(void *ctx, struct msgb *msg)
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001314{
1315 int rc;
Alexander Couzens951e1332020-09-22 13:21:46 +02001316 struct gbproxy_config *cfg = (struct gbproxy_config *) ctx;
1317 struct gprs_ns2_inst *nsi = cfg->nsi;
1318 struct osmo_gprs_ns2_prim nsp = {};
1319
1320 nsp.bvci = msgb_bvci(msg);
1321 nsp.nsei = msgb_nsei(msg);
1322
Alexander Couzens55c36f92021-01-27 20:56:55 +01001323 osmo_prim_init(&nsp.oph, SAP_NS, GPRS_NS2_PRIM_UNIT_DATA, PRIM_OP_REQUEST, msg);
Alexander Couzens951e1332020-09-22 13:21:46 +02001324 rc = gprs_ns2_recv_prim(nsi, &nsp.oph);
1325
1326 return rc;
1327}
1328
1329/* Main input function for Gb proxy */
1330int gbprox_rcvmsg(void *ctx, struct msgb *msg)
1331{
Alexander Couzens951e1332020-09-22 13:21:46 +02001332 struct gbproxy_config *cfg = (struct gbproxy_config *) ctx;
Harald Weltee5209642020-12-05 19:59:45 +01001333 uint16_t ns_bvci = msgb_bvci(msg);
1334 uint16_t nsei = msgb_nsei(msg);
1335 struct gbproxy_nse *nse;
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001336
Harald Welte278dd272020-12-06 13:35:24 +01001337 /* ensure minimum length to decode PCU type */
1338 if (msgb_bssgp_len(msg) < sizeof(struct bssgp_normal_hdr))
1339 return bssgp_tx_status(BSSGP_CAUSE_SEM_INCORR_PDU, NULL, msg);
1340
Harald Weltee5209642020-12-05 19:59:45 +01001341 nse = gbproxy_nse_by_nsei(cfg, nsei, NSE_F_SGSN);
1342 if (nse) {
1343 if (ns_bvci == 0 || ns_bvci == 1)
1344 return gbprox_rx_sig_from_sgsn(nse, msg, ns_bvci);
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001345 else
Harald Weltee5209642020-12-05 19:59:45 +01001346 return gbprox_rx_ptp_from_sgsn(nse, msg, ns_bvci);
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001347 }
1348
Harald Weltee5209642020-12-05 19:59:45 +01001349 nse = gbproxy_nse_by_nsei(cfg, nsei, NSE_F_BSS);
1350 if (!nse) {
1351 LOGP(DGPRS, LOGL_NOTICE, "NSE(%05u/BSS) not known -> allocating\n", nsei);
1352 nse = gbproxy_nse_alloc(cfg, nsei, false);
1353 }
1354 if (nse) {
1355 if (ns_bvci == 0 || ns_bvci == 1)
1356 return gbprox_rx_sig_from_bss(nse, msg, ns_bvci);
1357 else
1358 return gbprox_rx_ptp_from_bss(nse, msg, ns_bvci);
1359 }
1360
1361 return 0;
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001362}
1363
Alexander Couzens951e1332020-09-22 13:21:46 +02001364/* TODO: What about handling:
Alexander Couzens55c36f92021-01-27 20:56:55 +01001365 * GPRS_NS2_AFF_CAUSE_VC_FAILURE,
1366 GPRS_NS2_AFF_CAUSE_VC_RECOVERY,
1367 GPRS_NS2_AFF_CAUSE_FAILURE,
1368 GPRS_NS2_AFF_CAUSE_RECOVERY,
Alexander Couzens951e1332020-09-22 13:21:46 +02001369 osmocom own causes
Alexander Couzens55c36f92021-01-27 20:56:55 +01001370 GPRS_NS2_AFF_CAUSE_SNS_CONFIGURED,
1371 GPRS_NS2_AFF_CAUSE_SNS_FAILURE,
Alexander Couzens951e1332020-09-22 13:21:46 +02001372 */
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001373
Alexander Couzens951e1332020-09-22 13:21:46 +02001374void gprs_ns_prim_status_cb(struct gbproxy_config *cfg, struct osmo_gprs_ns2_prim *nsp)
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001375{
Harald Welte560bdb32020-12-04 22:24:47 +01001376 /* TODO: bss nsei available/unavailable bssgp_tx_simple_bvci(BSSGP_PDUT_BVC_BLOCK, nsvc->nsei, bvc->bvci, 0);
Alexander Couzens951e1332020-09-22 13:21:46 +02001377 * TODO: sgsn nsei available/unavailable
1378 */
Harald Weltee5209642020-12-05 19:59:45 +01001379
Harald Welte560bdb32020-12-04 22:24:47 +01001380 struct gbproxy_bvc *bvc;
Harald Weltee5209642020-12-05 19:59:45 +01001381 struct gbproxy_nse *sgsn_nse;
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001382
Alexander Couzens951e1332020-09-22 13:21:46 +02001383 switch (nsp->u.status.cause) {
Alexander Couzens55c36f92021-01-27 20:56:55 +01001384 case GPRS_NS2_AFF_CAUSE_SNS_FAILURE:
1385 case GPRS_NS2_AFF_CAUSE_SNS_CONFIGURED:
Alexander Couzens951e1332020-09-22 13:21:46 +02001386 break;
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001387
Alexander Couzens55c36f92021-01-27 20:56:55 +01001388 case GPRS_NS2_AFF_CAUSE_RECOVERY:
Harald Welte9b367d22021-01-18 13:55:51 +01001389 LOGP(DGPRS, LOGL_NOTICE, "NS-NSE %d became available\n", nsp->nsei);
Harald Weltee5209642020-12-05 19:59:45 +01001390 sgsn_nse = gbproxy_nse_by_nsei(cfg, nsp->nsei, NSE_F_SGSN);
1391 if (sgsn_nse) {
1392 uint8_t cause = BSSGP_CAUSE_OML_INTERV;
1393 bvc = gbproxy_bvc_by_bvci(sgsn_nse, 0);
1394 if (bvc)
1395 osmo_fsm_inst_dispatch(bvc->fi, BSSGP_BVCFSM_E_REQ_RESET, &cause);
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001396 }
Alexander Couzens951e1332020-09-22 13:21:46 +02001397 break;
Alexander Couzens55c36f92021-01-27 20:56:55 +01001398 case GPRS_NS2_AFF_CAUSE_FAILURE:
Harald Weltee5209642020-12-05 19:59:45 +01001399#if 0
Harald Weltea0f70732020-12-05 17:50:23 +01001400 if (gbproxy_is_sgsn_nsei(cfg, nsp->nsei)) {
Alexander Couzens951e1332020-09-22 13:21:46 +02001401 /* sgsn */
1402 /* TODO: BSVC: block all PtP towards bss */
1403 rate_ctr_inc(&cfg->ctrg->
1404 ctr[GBPROX_GLOB_CTR_RESTART_RESET_SGSN]);
1405 } else {
Daniel Willmanne50550e2020-11-26 18:19:21 +01001406 /* bss became unavailable
1407 * TODO: Block all BVC belonging to that NSE */
Harald Welte560bdb32020-12-04 22:24:47 +01001408 bvc = gbproxy_bvc_by_nsei(cfg, nsp->nsei);
1409 if (!bvc) {
Alexander Couzens951e1332020-09-22 13:21:46 +02001410 /* TODO: use primitive name + status cause name */
Harald Welte560bdb32020-12-04 22:24:47 +01001411 LOGP(DGPRS, LOGL_NOTICE, "Received ns2 primitive %d for unknown bvc NSEI=%u\n",
Alexander Couzens951e1332020-09-22 13:21:46 +02001412 nsp->u.status.cause, nsp->nsei);
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001413 break;
1414 }
Alexander Couzens951e1332020-09-22 13:21:46 +02001415
Harald Welte560bdb32020-12-04 22:24:47 +01001416 if (!bvc->blocked)
Alexander Couzens951e1332020-09-22 13:21:46 +02001417 break;
Harald Weltee5209642020-12-05 19:59:45 +01001418 hash_for_each(cfg->sgsn_nses, _sgsn, sgsn_nse, list) {
1419 bssgp_tx_simple_bvci(BSSGP_PDUT_BVC_BLOCK, sgsn_nse->nsei, bvc->bvci, 0);
1420 }
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001421 }
Harald Weltee5209642020-12-05 19:59:45 +01001422#endif
Harald Welte9b367d22021-01-18 13:55:51 +01001423 LOGP(DGPRS, LOGL_NOTICE, "NS-NSE %d became unavailable\n", nsp->nsei);
Alexander Couzens951e1332020-09-22 13:21:46 +02001424 break;
1425 default:
Harald Welte9b367d22021-01-18 13:55:51 +01001426 LOGP(DGPRS, LOGL_NOTICE, "NS: Unknown NS-STATUS.ind cause=%s from NS\n",
Harald Welte95cf9fb2020-11-30 10:55:22 +01001427 gprs_ns2_aff_cause_prim_str(nsp->u.status.cause));
Alexander Couzens951e1332020-09-22 13:21:46 +02001428 break;
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001429 }
Alexander Couzens951e1332020-09-22 13:21:46 +02001430}
1431
Alexander Couzens951e1332020-09-22 13:21:46 +02001432/* called by the ns layer */
1433int gprs_ns2_prim_cb(struct osmo_prim_hdr *oph, void *ctx)
1434{
1435 struct osmo_gprs_ns2_prim *nsp;
1436 struct gbproxy_config *cfg = (struct gbproxy_config *) ctx;
Daniel Willmann8f407b12020-12-02 19:33:50 +01001437 uintptr_t bvci;
Alexander Couzens951e1332020-09-22 13:21:46 +02001438 int rc = 0;
1439
1440 if (oph->sap != SAP_NS)
1441 return 0;
1442
1443 nsp = container_of(oph, struct osmo_gprs_ns2_prim, oph);
1444
1445 if (oph->operation != PRIM_OP_INDICATION) {
Harald Welte9b367d22021-01-18 13:55:51 +01001446 LOGP(DGPRS, LOGL_NOTICE, "NS: Unexpected primitive operation %s from NS\n",
Harald Welte95cf9fb2020-11-30 10:55:22 +01001447 get_value_string(osmo_prim_op_names, oph->operation));
Alexander Couzens951e1332020-09-22 13:21:46 +02001448 return 0;
1449 }
1450
1451 switch (oph->primitive) {
Alexander Couzens55c36f92021-01-27 20:56:55 +01001452 case GPRS_NS2_PRIM_UNIT_DATA:
Daniel Willmann8f407b12020-12-02 19:33:50 +01001453
Alexander Couzens951e1332020-09-22 13:21:46 +02001454 /* hand the message into the BSSGP implementation */
1455 msgb_bssgph(oph->msg) = oph->msg->l3h;
1456 msgb_bvci(oph->msg) = nsp->bvci;
1457 msgb_nsei(oph->msg) = nsp->nsei;
Daniel Willmann8f407b12020-12-02 19:33:50 +01001458 bvci = nsp->bvci | BVC_LOG_CTX_FLAG;
Alexander Couzens951e1332020-09-22 13:21:46 +02001459
Daniel Willmann8f407b12020-12-02 19:33:50 +01001460 log_set_context(LOG_CTX_GB_BVC, (void *)bvci);
Alexander Couzens951e1332020-09-22 13:21:46 +02001461 rc = gbprox_rcvmsg(cfg, oph->msg);
Daniel Willmannb6550102020-11-04 17:32:56 +01001462 msgb_free(oph->msg);
Alexander Couzens951e1332020-09-22 13:21:46 +02001463 break;
Alexander Couzens55c36f92021-01-27 20:56:55 +01001464 case GPRS_NS2_PRIM_STATUS:
Alexander Couzens951e1332020-09-22 13:21:46 +02001465 gprs_ns_prim_status_cb(cfg, nsp);
1466 break;
1467 default:
Harald Welte9b367d22021-01-18 13:55:51 +01001468 LOGP(DGPRS, LOGL_NOTICE, "NS: Unknown prim %s %s from NS\n",
Harald Welte95cf9fb2020-11-30 10:55:22 +01001469 gprs_ns2_prim_str(oph->primitive),
1470 get_value_string(osmo_prim_op_names, oph->operation));
Alexander Couzens951e1332020-09-22 13:21:46 +02001471 break;
1472 }
1473
1474 return rc;
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001475}
1476
1477void gbprox_reset(struct gbproxy_config *cfg)
1478{
Harald Welted2fef952020-12-05 00:31:07 +01001479 struct gbproxy_nse *nse;
1480 struct hlist_node *ntmp;
Harald Welte8b4c7942020-12-05 10:14:49 +01001481 int i, j;
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001482
Harald Welted2fef952020-12-05 00:31:07 +01001483 hash_for_each_safe(cfg->bss_nses, i, ntmp, nse, list) {
Harald Welte8b4c7942020-12-05 10:14:49 +01001484 struct gbproxy_bvc *bvc;
1485 struct hlist_node *tmp;
1486 hash_for_each_safe(nse->bvcs, j, tmp, bvc, list)
Harald Welte560bdb32020-12-04 22:24:47 +01001487 gbproxy_bvc_free(bvc);
Daniel Willmanne50550e2020-11-26 18:19:21 +01001488
1489 gbproxy_nse_free(nse);
1490 }
Harald Weltee5209642020-12-05 19:59:45 +01001491 /* FIXME: cells */
1492 /* FIXME: SGSN side BVCs (except signaling) */
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001493
1494 rate_ctr_group_free(cfg->ctrg);
1495 gbproxy_init_config(cfg);
1496}
1497
Daniel Willmann77493b12020-12-29 21:13:31 +01001498static void tlli_cache_cleanup(void *data)
1499{
1500 struct gbproxy_config *cfg = data;
1501 gbproxy_tlli_cache_cleanup(cfg);
1502
1503 /* TODO: Disable timer when cache is empty */
1504 osmo_timer_schedule(&cfg->tlli_cache.timer, 2, 0);
1505}
1506
Daniel Willmannc8a50092021-01-17 13:11:41 +01001507static void imsi_cache_cleanup(void *data)
1508{
1509 struct gbproxy_config *cfg = data;
1510 gbproxy_imsi_cache_cleanup(cfg);
1511
1512 /* TODO: Disable timer when cache is empty */
1513 osmo_timer_schedule(&cfg->imsi_cache.timer, 2, 0);
1514}
1515
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001516int gbproxy_init_config(struct gbproxy_config *cfg)
1517{
1518 struct timespec tp;
1519
Harald Welte209dc9f2020-12-12 19:02:16 +01001520 /* by default we advertise 100% of the BSS-side capacity to _each_ SGSN */
1521 cfg->pool.bvc_fc_ratio = 100;
Daniel Willmannee834af2020-12-14 16:22:39 +01001522 cfg->pool.null_nri_ranges = osmo_nri_ranges_alloc(cfg);
Daniel Willmann77493b12020-12-29 21:13:31 +01001523 /* TODO: Make configurable */
Daniel Willmannbd12f3f2021-01-13 18:16:04 +01001524 cfg->tlli_cache.timeout = 10;
Daniel Willmannc8a50092021-01-17 13:11:41 +01001525 cfg->imsi_cache.timeout = 10;
Daniel Willmannee834af2020-12-14 16:22:39 +01001526
Harald Welted2fef952020-12-05 00:31:07 +01001527 hash_init(cfg->bss_nses);
Daniel Willmann1e7be5d2020-12-21 18:08:21 +01001528 hash_init(cfg->sgsn_nses);
1529 hash_init(cfg->cells);
Daniel Willmann77493b12020-12-29 21:13:31 +01001530 hash_init(cfg->tlli_cache.entries);
Daniel Willmannee834af2020-12-14 16:22:39 +01001531 INIT_LLIST_HEAD(&cfg->sgsns);
1532
Daniel Willmann77493b12020-12-29 21:13:31 +01001533 osmo_timer_setup(&cfg->tlli_cache.timer, tlli_cache_cleanup, cfg);
1534 osmo_timer_schedule(&cfg->tlli_cache.timer, 2, 0);
1535
Daniel Willmannc8a50092021-01-17 13:11:41 +01001536 /* We could also combine both timers */
1537 osmo_timer_setup(&cfg->imsi_cache.timer, imsi_cache_cleanup, cfg);
1538 osmo_timer_schedule(&cfg->imsi_cache.timer, 2, 0);
1539
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001540 cfg->ctrg = rate_ctr_group_alloc(tall_sgsn_ctx, &global_ctrg_desc, 0);
1541 if (!cfg->ctrg) {
1542 LOGP(DGPRS, LOGL_ERROR, "Cannot allocate global counter group!\n");
1543 return -1;
1544 }
1545 osmo_clock_gettime(CLOCK_REALTIME, &tp);
Harald Weltec169de42020-12-07 13:12:13 +01001546 osmo_fsm_log_timeouts(true);
Pau Espin Pedrol1ddefb12019-08-30 19:48:34 +02001547
1548 return 0;
Oliver Smith29532c22021-01-29 11:13:00 +01001549}