Pau Espin Pedrol | fdd732b | 2017-10-13 14:32:24 +0200 | [diff] [blame] | 1 | /* |
Harald Welte | 632e843 | 2017-09-05 18:12:14 +0200 | [diff] [blame] | 2 | * OsmoGGSN - Gateway GPRS Support Node |
jjako | 0fe0df0 | 2004-09-17 11:30:40 +0000 | [diff] [blame] | 3 | * Copyright (C) 2002, 2003, 2004 Mondru AB. |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 4 | * Copyright (C) 2017 by Harald Welte <laforge@gnumonks.org> |
Pau Espin Pedrol | fdd732b | 2017-10-13 14:32:24 +0200 | [diff] [blame] | 5 | * |
jjako | a7cd249 | 2003-04-11 09:40:12 +0000 | [diff] [blame] | 6 | * The contents of this file may be used under the terms of the GNU |
| 7 | * General Public License Version 2, provided that the above copyright |
| 8 | * notice and this permission notice is included in all copies or |
| 9 | * substantial portions of the software. |
Pau Espin Pedrol | fdd732b | 2017-10-13 14:32:24 +0200 | [diff] [blame] | 10 | * |
jjako | 52c2414 | 2002-12-16 13:33:51 +0000 | [diff] [blame] | 11 | */ |
| 12 | |
| 13 | /* ggsn.c |
| 14 | * |
| 15 | */ |
| 16 | |
| 17 | #ifdef __linux__ |
| 18 | #define _GNU_SOURCE 1 /* strdup() prototype, broken arpa/inet.h */ |
| 19 | #endif |
| 20 | |
jjako | 0fe0df0 | 2004-09-17 11:30:40 +0000 | [diff] [blame] | 21 | #include "../config.h" |
| 22 | |
| 23 | #ifdef HAVE_STDINT_H |
| 24 | #include <stdint.h> |
| 25 | #endif |
jjako | 52c2414 | 2002-12-16 13:33:51 +0000 | [diff] [blame] | 26 | |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 27 | #include <getopt.h> |
jjako | 52c2414 | 2002-12-16 13:33:51 +0000 | [diff] [blame] | 28 | #include <ctype.h> |
jjako | 52c2414 | 2002-12-16 13:33:51 +0000 | [diff] [blame] | 29 | #include <signal.h> |
| 30 | #include <stdio.h> |
| 31 | #include <string.h> |
| 32 | #include <stdlib.h> |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 33 | #include <unistd.h> |
| 34 | #include <inttypes.h> |
| 35 | #include <errno.h> |
jjako | 52c2414 | 2002-12-16 13:33:51 +0000 | [diff] [blame] | 36 | #include <sys/types.h> |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 37 | #include <sys/ioctl.h> |
| 38 | |
| 39 | #include <net/if.h> |
| 40 | #include <arpa/inet.h> |
jjako | 52c2414 | 2002-12-16 13:33:51 +0000 | [diff] [blame] | 41 | #include <netinet/in.h> |
Harald Welte | 63ebccd | 2017-08-02 21:10:09 +0200 | [diff] [blame] | 42 | #include <netinet/ip.h> |
Harald Welte | a0d281d | 2017-08-02 21:48:16 +0200 | [diff] [blame] | 43 | #include <netinet/ip6.h> |
jjako | 52c2414 | 2002-12-16 13:33:51 +0000 | [diff] [blame] | 44 | |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 45 | #include <osmocom/core/application.h> |
Max | 727417d | 2016-08-02 17:10:38 +0200 | [diff] [blame] | 46 | #include <osmocom/core/select.h> |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 47 | #include <osmocom/core/stats.h> |
| 48 | #include <osmocom/core/rate_ctr.h> |
| 49 | #include <osmocom/core/timer.h> |
Max | 727417d | 2016-08-02 17:10:38 +0200 | [diff] [blame] | 50 | #include <osmocom/ctrl/control_if.h> |
| 51 | #include <osmocom/ctrl/control_cmd.h> |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 52 | #include <osmocom/ctrl/control_vty.h> |
Max | 727417d | 2016-08-02 17:10:38 +0200 | [diff] [blame] | 53 | #include <osmocom/ctrl/ports.h> |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 54 | #include <osmocom/vty/telnet_interface.h> |
| 55 | #include <osmocom/vty/logging.h> |
| 56 | #include <osmocom/vty/stats.h> |
| 57 | #include <osmocom/vty/ports.h> |
| 58 | #include <osmocom/vty/command.h> |
Harald Welte | 3e443ca | 2018-02-14 01:04:04 +0100 | [diff] [blame] | 59 | #include <osmocom/vty/misc.h> |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 60 | #include <osmocom/gsm/apn.h> |
Max | 727417d | 2016-08-02 17:10:38 +0200 | [diff] [blame] | 61 | |
Emmanuel Bretelle | 2a10368 | 2010-09-07 17:01:20 +0200 | [diff] [blame] | 62 | #include "../lib/tun.h" |
| 63 | #include "../lib/ippool.h" |
| 64 | #include "../lib/syserr.h" |
Harald Welte | d12eab9 | 2017-08-02 19:49:47 +0200 | [diff] [blame] | 65 | #include "../lib/in46_addr.h" |
Harald Welte | f228639 | 2018-04-25 19:02:31 +0200 | [diff] [blame] | 66 | #include "../lib/gtp-kernel.h" |
jjako | 52c2414 | 2002-12-16 13:33:51 +0000 | [diff] [blame] | 67 | #include "../gtp/pdp.h" |
| 68 | #include "../gtp/gtp.h" |
Harald Welte | d46bcd2 | 2017-08-08 23:27:22 +0200 | [diff] [blame] | 69 | #include "icmpv6.h" |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 70 | #include "ggsn.h" |
jjako | 52c2414 | 2002-12-16 13:33:51 +0000 | [diff] [blame] | 71 | |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 72 | void *tall_ggsn_ctx; |
jjako | a7cd249 | 2003-04-11 09:40:12 +0000 | [diff] [blame] | 73 | |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 74 | static int end = 0; |
| 75 | static int daemonize = 0; |
| 76 | static struct ctrl_handle *g_ctrlh; |
| 77 | |
jjako | a7cd249 | 2003-04-11 09:40:12 +0000 | [diff] [blame] | 78 | struct ul255_t qos; |
| 79 | struct ul255_t apn; |
| 80 | |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 81 | #define LOGPAPN(level, apn, fmt, args...) \ |
| 82 | LOGP(DGGSN, level, "APN(%s): " fmt, (apn)->cfg.name, ## args) |
jjako | 52c2414 | 2002-12-16 13:33:51 +0000 | [diff] [blame] | 83 | |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 84 | #define LOGPGGSN(level, ggsn, fmt, args...) \ |
| 85 | LOGP(DGGSN, level, "GGSN(%s): " fmt, (ggsn)->cfg.name, ## args) |
| 86 | |
Max | 6a21527 | 2017-09-25 10:35:34 +0200 | [diff] [blame] | 87 | #define LOGPPDP(level, pdp, fmt, args...) LOGPDPX(DGGSN, level, pdp, fmt, ## args) |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 88 | |
| 89 | static int ggsn_tun_fd_cb(struct osmo_fd *fd, unsigned int what); |
| 90 | static int cb_tun_ind(struct tun_t *tun, void *pack, unsigned len); |
| 91 | |
| 92 | |
| 93 | static void pool_close_all_pdp(struct ippool_t *pool) |
Harald Welte | bed35df | 2011-11-02 13:06:18 +0100 | [diff] [blame] | 94 | { |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 95 | unsigned int i; |
jjako | 52c2414 | 2002-12-16 13:33:51 +0000 | [diff] [blame] | 96 | |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 97 | if (!pool) |
Harald Welte | bed35df | 2011-11-02 13:06:18 +0100 | [diff] [blame] | 98 | return; |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 99 | |
| 100 | for (i = 0; i < pool->listsize; i++) { |
| 101 | struct ippoolm_t *member = &pool->member[i]; |
| 102 | struct pdp_t *pdp; |
| 103 | |
| 104 | if (!member->inuse) |
| 105 | continue; |
| 106 | pdp = member->peer; |
| 107 | if (!pdp) |
| 108 | continue; |
| 109 | LOGPPDP(LOGL_DEBUG, pdp, "Sending DELETE PDP CTX due to shutdown\n"); |
| 110 | gtp_delete_context_req(pdp->gsn, pdp, NULL, 1); |
Harald Welte | bed35df | 2011-11-02 13:06:18 +0100 | [diff] [blame] | 111 | } |
jjako | 52c2414 | 2002-12-16 13:33:51 +0000 | [diff] [blame] | 112 | } |
| 113 | |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 114 | int apn_stop(struct apn_ctx *apn, bool force) |
Harald Welte | bed35df | 2011-11-02 13:06:18 +0100 | [diff] [blame] | 115 | { |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 116 | LOGPAPN(LOGL_NOTICE, apn, "%sStopping\n", force ? "FORCED " : ""); |
| 117 | /* check if pools have any active PDP contexts and bail out */ |
| 118 | pool_close_all_pdp(apn->v4.pool); |
| 119 | pool_close_all_pdp(apn->v6.pool); |
| 120 | |
| 121 | /* shutdown whatever old state might be left */ |
| 122 | if (apn->tun.tun) { |
| 123 | /* run ip-down script */ |
| 124 | if (apn->tun.cfg.ipdown_script) { |
| 125 | LOGPAPN( LOGL_INFO, apn, "Running %s\n", apn->tun.cfg.ipdown_script); |
| 126 | tun_runscript(apn->tun.tun, apn->tun.cfg.ipdown_script); |
| 127 | } |
Harald Welte | f228639 | 2018-04-25 19:02:31 +0200 | [diff] [blame] | 128 | if (apn->cfg.gtpu_mode == APN_GTPU_MODE_TUN) { |
| 129 | /* release tun device */ |
| 130 | LOGPAPN(LOGL_INFO, apn, "Closing TUN device %s\n", apn->tun.tun->devname); |
| 131 | osmo_fd_unregister(&apn->tun.fd); |
| 132 | } |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 133 | tun_free(apn->tun.tun); |
| 134 | apn->tun.tun = NULL; |
| 135 | } |
| 136 | |
| 137 | if (apn->v4.pool) { |
| 138 | LOGPAPN(LOGL_INFO, apn, "Releasing IPv4 pool\n"); |
| 139 | ippool_free(apn->v4.pool); |
| 140 | apn->v4.pool = NULL; |
| 141 | } |
| 142 | if (apn->v6.pool) { |
| 143 | LOGPAPN(LOGL_INFO, apn, "Releasing IPv6 pool\n"); |
| 144 | ippool_free(apn->v6.pool); |
| 145 | apn->v6.pool = NULL; |
| 146 | } |
| 147 | |
| 148 | apn->started = false; |
| 149 | return 0; |
| 150 | } |
| 151 | |
Pau Espin Pedrol | 859f9b0 | 2017-10-16 14:52:25 +0200 | [diff] [blame] | 152 | |
Harald Welte | f55a039 | 2017-11-08 14:33:55 +0900 | [diff] [blame] | 153 | static int alloc_ippool_blacklist(struct apn_ctx *apn, struct in46_prefix **blacklist, bool ipv6) |
Pau Espin Pedrol | 859f9b0 | 2017-10-16 14:52:25 +0200 | [diff] [blame] | 154 | { |
| 155 | |
| 156 | int flags, len, len2, i; |
| 157 | |
Harald Welte | e2a1de5 | 2017-11-08 15:24:07 +0900 | [diff] [blame] | 158 | *blacklist = NULL; |
| 159 | |
Pau Espin Pedrol | 859f9b0 | 2017-10-16 14:52:25 +0200 | [diff] [blame] | 160 | if (ipv6) |
| 161 | flags = IP_TYPE_IPv6_NONLINK; |
| 162 | else |
| 163 | flags = IP_TYPE_IPv4; |
| 164 | |
| 165 | while (1) { |
Harald Welte | e2a1de5 | 2017-11-08 15:24:07 +0900 | [diff] [blame] | 166 | len = netdev_ip_local_get(apn->tun.cfg.dev_name, NULL, 0, flags); |
Pau Espin Pedrol | 859f9b0 | 2017-10-16 14:52:25 +0200 | [diff] [blame] | 167 | if (len < 1) |
| 168 | return len; |
| 169 | |
| 170 | *blacklist = talloc_zero_size(apn, len * sizeof(struct in46_prefix)); |
Harald Welte | e2a1de5 | 2017-11-08 15:24:07 +0900 | [diff] [blame] | 171 | len2 = netdev_ip_local_get(apn->tun.cfg.dev_name, *blacklist, len, flags); |
Pau Espin Pedrol | 859f9b0 | 2017-10-16 14:52:25 +0200 | [diff] [blame] | 172 | if (len2 < 1) { |
| 173 | talloc_free(*blacklist); |
Harald Welte | e2a1de5 | 2017-11-08 15:24:07 +0900 | [diff] [blame] | 174 | *blacklist = NULL; |
Pau Espin Pedrol | 859f9b0 | 2017-10-16 14:52:25 +0200 | [diff] [blame] | 175 | return len2; |
| 176 | } |
| 177 | |
Harald Welte | e2a1de5 | 2017-11-08 15:24:07 +0900 | [diff] [blame] | 178 | if (len2 > len) { /* iface was added between 2 calls, repeat operation */ |
Pau Espin Pedrol | 859f9b0 | 2017-10-16 14:52:25 +0200 | [diff] [blame] | 179 | talloc_free(*blacklist); |
Harald Welte | e2a1de5 | 2017-11-08 15:24:07 +0900 | [diff] [blame] | 180 | *blacklist = NULL; |
| 181 | } else |
Pau Espin Pedrol | 859f9b0 | 2017-10-16 14:52:25 +0200 | [diff] [blame] | 182 | break; |
| 183 | } |
| 184 | |
| 185 | for (i = 0; i < len2; i++) |
| 186 | LOGPAPN(LOGL_INFO, apn, "Blacklist tun IP %s\n", |
| 187 | in46p_ntoa(&(*blacklist)[i])); |
| 188 | |
| 189 | return len2; |
| 190 | } |
| 191 | |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 192 | /* actually start the APN with its current config */ |
| 193 | int apn_start(struct apn_ctx *apn) |
| 194 | { |
Pau Espin Pedrol | 859f9b0 | 2017-10-16 14:52:25 +0200 | [diff] [blame] | 195 | int ippool_flags = IPPOOL_NONETWORK | IPPOOL_NOBROADCAST; |
Pau Espin Pedrol | a037e59 | 2017-10-16 14:41:37 +0200 | [diff] [blame] | 196 | struct in46_prefix ipv6_tun_linklocal_ip; |
Pau Espin Pedrol | 859f9b0 | 2017-10-16 14:52:25 +0200 | [diff] [blame] | 197 | struct in46_prefix *blacklist; |
| 198 | int blacklist_size; |
Harald Welte | f228639 | 2018-04-25 19:02:31 +0200 | [diff] [blame] | 199 | struct gsn_t *gsn = apn->ggsn->gsn; |
Pau Espin Pedrol | bffc3f9 | 2017-12-14 11:19:10 +0100 | [diff] [blame] | 200 | int rc; |
Pau Espin Pedrol | 859f9b0 | 2017-10-16 14:52:25 +0200 | [diff] [blame] | 201 | |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 202 | if (apn->started) |
| 203 | return 0; |
| 204 | |
| 205 | LOGPAPN(LOGL_INFO, apn, "Starting\n"); |
| 206 | switch (apn->cfg.gtpu_mode) { |
| 207 | case APN_GTPU_MODE_TUN: |
| 208 | LOGPAPN(LOGL_INFO, apn, "Opening TUN device %s\n", apn->tun.cfg.dev_name); |
Harald Welte | f228639 | 2018-04-25 19:02:31 +0200 | [diff] [blame] | 209 | if (tun_new(&apn->tun.tun, apn->tun.cfg.dev_name, false, -1, -1)) { |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 210 | LOGPAPN(LOGL_ERROR, apn, "Failed to configure tun device\n"); |
| 211 | return -1; |
| 212 | } |
| 213 | LOGPAPN(LOGL_INFO, apn, "Opened TUN device %s\n", apn->tun.tun->devname); |
| 214 | |
| 215 | /* Register with libosmcoore */ |
| 216 | osmo_fd_setup(&apn->tun.fd, apn->tun.tun->fd, BSC_FD_READ, ggsn_tun_fd_cb, apn, 0); |
| 217 | osmo_fd_register(&apn->tun.fd); |
| 218 | |
| 219 | /* Set TUN library callback */ |
| 220 | tun_set_cb_ind(apn->tun.tun, cb_tun_ind); |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 221 | break; |
| 222 | case APN_GTPU_MODE_KERNEL_GTP: |
Harald Welte | 2fc2bc6 | 2017-11-08 15:50:53 +0900 | [diff] [blame] | 223 | LOGPAPN(LOGL_INFO, apn, "Opening Kernel GTP device %s\n", apn->tun.cfg.dev_name); |
Harald Welte | 490782d | 2017-11-08 14:09:51 +0900 | [diff] [blame] | 224 | if (apn->cfg.apn_type_mask & (APN_TYPE_IPv6|APN_TYPE_IPv4v6)) { |
| 225 | LOGPAPN(LOGL_ERROR, apn, "Kernel GTP currently supports only IPv4\n"); |
| 226 | apn_stop(apn, false); |
| 227 | return -1; |
| 228 | } |
Harald Welte | f228639 | 2018-04-25 19:02:31 +0200 | [diff] [blame] | 229 | if (gsn == NULL) { |
Harald Welte | 0757504 | 2018-02-14 01:04:04 +0100 | [diff] [blame] | 230 | /* skip bringing up the APN now if the GSN is not initialized yet. |
| 231 | * This happens during initial load of the config file, as the |
| 232 | * "no shutdown" in the ggsn node only happens after the "apn" nodes |
| 233 | * are brought up */ |
| 234 | LOGPAPN(LOGL_NOTICE, apn, "Skipping APN start\n"); |
| 235 | return 0; |
| 236 | } |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 237 | /* use GTP kernel module for data packet encapsulation */ |
Harald Welte | f228639 | 2018-04-25 19:02:31 +0200 | [diff] [blame] | 238 | if (tun_new(&apn->tun.tun, apn->tun.cfg.dev_name, true, gsn->fd0, gsn->fd1u)) { |
| 239 | LOGPAPN(LOGL_ERROR, apn, "Failed to configure Kernel GTP device\n"); |
Harald Welte | 490782d | 2017-11-08 14:09:51 +0900 | [diff] [blame] | 240 | return -1; |
| 241 | } |
Harald Welte | bed35df | 2011-11-02 13:06:18 +0100 | [diff] [blame] | 242 | break; |
| 243 | default: |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 244 | LOGPAPN(LOGL_ERROR, apn, "Unknown GTPU Mode %d\n", apn->cfg.gtpu_mode); |
| 245 | return -1; |
Harald Welte | bed35df | 2011-11-02 13:06:18 +0100 | [diff] [blame] | 246 | } |
jjako | 0141d20 | 2004-01-09 15:19:20 +0000 | [diff] [blame] | 247 | |
Harald Welte | f228639 | 2018-04-25 19:02:31 +0200 | [diff] [blame] | 248 | /* common initialization below */ |
| 249 | |
| 250 | /* set back-pointer from TUN device to APN */ |
| 251 | apn->tun.tun->priv = apn; |
| 252 | |
| 253 | if (apn->v4.cfg.ifconfig_prefix.addr.len) { |
| 254 | LOGPAPN(LOGL_INFO, apn, "Setting tun IP address %s\n", |
| 255 | in46p_ntoa(&apn->v4.cfg.ifconfig_prefix)); |
| 256 | if (tun_addaddr(apn->tun.tun, &apn->v4.cfg.ifconfig_prefix.addr, NULL, |
| 257 | apn->v4.cfg.ifconfig_prefix.prefixlen)) { |
| 258 | LOGPAPN(LOGL_ERROR, apn, "Failed to set tun IPv4 address %s: %s\n", |
| 259 | in46p_ntoa(&apn->v4.cfg.ifconfig_prefix), strerror(errno)); |
| 260 | apn_stop(apn, false); |
| 261 | return -1; |
| 262 | } |
| 263 | } |
| 264 | |
| 265 | if (apn->v6.cfg.ifconfig_prefix.addr.len) { |
| 266 | LOGPAPN(LOGL_INFO, apn, "Setting tun IPv6 address %s\n", |
| 267 | in46p_ntoa(&apn->v6.cfg.ifconfig_prefix)); |
| 268 | if (tun_addaddr(apn->tun.tun, &apn->v6.cfg.ifconfig_prefix.addr, NULL, |
| 269 | apn->v6.cfg.ifconfig_prefix.prefixlen)) { |
| 270 | LOGPAPN(LOGL_ERROR, apn, "Failed to set tun IPv6 address %s: %s. " |
| 271 | "Ensure you have ipv6 support and not used the disable_ipv6 sysctl?\n", |
| 272 | in46p_ntoa(&apn->v6.cfg.ifconfig_prefix), strerror(errno)); |
| 273 | apn_stop(apn, false); |
| 274 | return -1; |
| 275 | } |
| 276 | } |
| 277 | |
| 278 | if (apn->v6.cfg.ll_prefix.addr.len) { |
| 279 | LOGPAPN(LOGL_INFO, apn, "Setting tun IPv6 link-local address %s\n", |
| 280 | in46p_ntoa(&apn->v6.cfg.ll_prefix)); |
| 281 | if (tun_addaddr(apn->tun.tun, &apn->v6.cfg.ll_prefix.addr, NULL, |
| 282 | apn->v6.cfg.ll_prefix.prefixlen)) { |
| 283 | LOGPAPN(LOGL_ERROR, apn, "Failed to set tun IPv6 link-local address %s: %s. " |
| 284 | "Ensure you have ipv6 support and not used the disable_ipv6 sysctl?\n", |
| 285 | in46p_ntoa(&apn->v6.cfg.ll_prefix), strerror(errno)); |
| 286 | apn_stop(apn, false); |
| 287 | return -1; |
| 288 | } |
| 289 | apn->v6_lladdr = apn->v6.cfg.ll_prefix.addr.v6; |
| 290 | } |
| 291 | |
| 292 | if (apn->tun.cfg.ipup_script) { |
| 293 | LOGPAPN(LOGL_INFO, apn, "Running ip-up script %s\n", |
| 294 | apn->tun.cfg.ipup_script); |
| 295 | tun_runscript(apn->tun.tun, apn->tun.cfg.ipup_script); |
| 296 | } |
| 297 | |
| 298 | if (apn->cfg.apn_type_mask & (APN_TYPE_IPv6|APN_TYPE_IPv4v6) && |
| 299 | apn->v6.cfg.ll_prefix.addr.len == 0) { |
| 300 | rc = tun_ip_local_get(apn->tun.tun, &ipv6_tun_linklocal_ip, 1, IP_TYPE_IPv6_LINK); |
| 301 | if (rc < 1) { |
| 302 | LOGPAPN(LOGL_ERROR, apn, "Cannot obtain IPv6 link-local address of interface: %s\n", |
| 303 | rc ? strerror(errno) : "tun interface has no link-local IP assigned"); |
| 304 | apn_stop(apn, false); |
| 305 | return -1; |
| 306 | } |
| 307 | apn->v6_lladdr = ipv6_tun_linklocal_ip.addr.v6; |
| 308 | } |
| 309 | |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 310 | /* Create IPv4 pool */ |
| 311 | if (apn->v4.cfg.dynamic_prefix.addr.len) { |
| 312 | LOGPAPN(LOGL_INFO, apn, "Creating IPv4 pool %s\n", |
| 313 | in46p_ntoa(&apn->v4.cfg.dynamic_prefix)); |
Harald Welte | f55a039 | 2017-11-08 14:33:55 +0900 | [diff] [blame] | 314 | if ((blacklist_size = alloc_ippool_blacklist(apn, &blacklist, false)) < 0) |
Pau Espin Pedrol | 859f9b0 | 2017-10-16 14:52:25 +0200 | [diff] [blame] | 315 | LOGPAPN(LOGL_ERROR, apn, "Failed obtaining IPv4 tun IPs\n"); |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 316 | if (ippool_new(&apn->v4.pool, &apn->v4.cfg.dynamic_prefix, |
Pau Espin Pedrol | 859f9b0 | 2017-10-16 14:52:25 +0200 | [diff] [blame] | 317 | &apn->v4.cfg.static_prefix, ippool_flags, |
| 318 | blacklist, blacklist_size)) { |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 319 | LOGPAPN(LOGL_ERROR, apn, "Failed to create IPv4 pool\n"); |
Pau Espin Pedrol | 859f9b0 | 2017-10-16 14:52:25 +0200 | [diff] [blame] | 320 | talloc_free(blacklist); |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 321 | apn_stop(apn, false); |
| 322 | return -1; |
| 323 | } |
Pau Espin Pedrol | 859f9b0 | 2017-10-16 14:52:25 +0200 | [diff] [blame] | 324 | talloc_free(blacklist); |
Harald Welte | bed35df | 2011-11-02 13:06:18 +0100 | [diff] [blame] | 325 | } |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 326 | |
| 327 | /* Create IPv6 pool */ |
| 328 | if (apn->v6.cfg.dynamic_prefix.addr.len) { |
| 329 | LOGPAPN(LOGL_INFO, apn, "Creating IPv6 pool %s\n", |
| 330 | in46p_ntoa(&apn->v6.cfg.dynamic_prefix)); |
Harald Welte | f55a039 | 2017-11-08 14:33:55 +0900 | [diff] [blame] | 331 | if ((blacklist_size = alloc_ippool_blacklist(apn, &blacklist, true)) < 0) |
Pau Espin Pedrol | 859f9b0 | 2017-10-16 14:52:25 +0200 | [diff] [blame] | 332 | LOGPAPN(LOGL_ERROR, apn, "Failed obtaining IPv6 tun IPs\n"); |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 333 | if (ippool_new(&apn->v6.pool, &apn->v6.cfg.dynamic_prefix, |
Pau Espin Pedrol | 859f9b0 | 2017-10-16 14:52:25 +0200 | [diff] [blame] | 334 | &apn->v6.cfg.static_prefix, ippool_flags, |
| 335 | blacklist, blacklist_size)) { |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 336 | LOGPAPN(LOGL_ERROR, apn, "Failed to create IPv6 pool\n"); |
Pau Espin Pedrol | 859f9b0 | 2017-10-16 14:52:25 +0200 | [diff] [blame] | 337 | talloc_free(blacklist); |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 338 | apn_stop(apn, false); |
| 339 | return -1; |
| 340 | } |
Pau Espin Pedrol | 859f9b0 | 2017-10-16 14:52:25 +0200 | [diff] [blame] | 341 | talloc_free(blacklist); |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 342 | } |
| 343 | |
| 344 | LOGPAPN(LOGL_NOTICE, apn, "Successfully started\n"); |
| 345 | apn->started = true; |
| 346 | return 0; |
jjako | 0141d20 | 2004-01-09 15:19:20 +0000 | [diff] [blame] | 347 | } |
jjako | 0141d20 | 2004-01-09 15:19:20 +0000 | [diff] [blame] | 348 | |
Max | 3142d8d | 2017-05-04 17:45:10 +0200 | [diff] [blame] | 349 | static bool send_trap(const struct gsn_t *gsn, const struct pdp_t *pdp, const struct ippoolm_t *member, const char *var) |
| 350 | { |
Harald Welte | d12eab9 | 2017-08-02 19:49:47 +0200 | [diff] [blame] | 351 | char addrbuf[256]; |
Max | 3142d8d | 2017-05-04 17:45:10 +0200 | [diff] [blame] | 352 | char val[NAMESIZE]; |
| 353 | |
Harald Welte | d12eab9 | 2017-08-02 19:49:47 +0200 | [diff] [blame] | 354 | const char *addrstr = in46a_ntop(&member->addr, addrbuf, sizeof(addrbuf)); |
| 355 | |
Harald Welte | b10ee08 | 2017-08-12 19:29:16 +0200 | [diff] [blame] | 356 | snprintf(val, sizeof(val), "%s,%s", imsi_gtp2str(&pdp->imsi), addrstr); |
Max | 3142d8d | 2017-05-04 17:45:10 +0200 | [diff] [blame] | 357 | |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 358 | if (ctrl_cmd_send_trap(g_ctrlh, var, val) < 0) { |
| 359 | LOGPPDP(LOGL_ERROR, pdp, "Failed to create and send TRAP %s\n", var); |
Max | 3142d8d | 2017-05-04 17:45:10 +0200 | [diff] [blame] | 360 | return false; |
| 361 | } |
| 362 | return true; |
| 363 | } |
| 364 | |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 365 | static int delete_context(struct pdp_t *pdp) |
Harald Welte | bed35df | 2011-11-02 13:06:18 +0100 | [diff] [blame] | 366 | { |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 367 | struct gsn_t *gsn = pdp->gsn; |
Harald Welte | 698a233 | 2017-11-08 15:09:58 +0900 | [diff] [blame] | 368 | struct apn_ctx *apn = pdp->priv; |
Pau Espin Pedrol | 2d6a69e | 2017-12-06 19:26:25 +0100 | [diff] [blame] | 369 | struct ippoolm_t *member; |
| 370 | int i; |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 371 | |
| 372 | LOGPPDP(LOGL_INFO, pdp, "Deleting PDP context\n"); |
Max | dbd7024 | 2016-10-14 13:38:05 +0200 | [diff] [blame] | 373 | |
Pau Espin Pedrol | 2d6a69e | 2017-12-06 19:26:25 +0100 | [diff] [blame] | 374 | for (i = 0; i < 2; i++) { |
| 375 | if (pdp->peer[i]) { |
| 376 | member = pdp->peer[i]; |
| 377 | send_trap(gsn, pdp, member, "imsi-rem-ip"); /* TRAP with IP removal */ |
| 378 | ippool_freeip(member->pool, member); |
| 379 | } else if(i == 0) |
| 380 | LOGPPDP(LOGL_ERROR, pdp, "Cannot find/free IP Pool member\n"); |
| 381 | } |
Pablo Neira Ayuso | 4b075b6 | 2015-11-17 12:22:42 +0100 | [diff] [blame] | 382 | |
Harald Welte | 546884d | 2018-04-25 21:13:06 +0200 | [diff] [blame] | 383 | if (apn->cfg.gtpu_mode == APN_GTPU_MODE_KERNEL_GTP) { |
| 384 | if (gtp_kernel_tunnel_del(pdp, apn->tun.cfg.dev_name)) { |
| 385 | LOGPPDP(LOGL_ERROR, pdp, "Cannot delete tunnel from kernel:%s\n", |
| 386 | strerror(errno)); |
| 387 | } |
Pablo Neira Ayuso | 4b075b6 | 2015-11-17 12:22:42 +0100 | [diff] [blame] | 388 | } |
| 389 | |
Harald Welte | bed35df | 2011-11-02 13:06:18 +0100 | [diff] [blame] | 390 | return 0; |
jjako | 52c2414 | 2002-12-16 13:33:51 +0000 | [diff] [blame] | 391 | } |
| 392 | |
Harald Welte | 1ae9877 | 2017-08-09 20:28:52 +0200 | [diff] [blame] | 393 | #include <osmocom/gsm/tlv.h> |
| 394 | |
Pau Espin Pedrol | 0bdd8bf | 2018-01-26 17:46:37 +0100 | [diff] [blame] | 395 | /* RFC 1332 */ |
| 396 | enum ipcp_options { |
| 397 | IPCP_OPT_IPADDR = 3, |
| 398 | IPCP_OPT_PRIMARY_DNS = 129, |
| 399 | IPCP_OPT_SECONDARY_DNS = 131, |
| 400 | }; |
| 401 | |
| 402 | struct ipcp_option_hdr { |
| 403 | uint8_t type; |
| 404 | uint8_t len; |
| 405 | uint8_t data[0]; |
Philipp Maier | 6a2856b | 2018-05-28 17:50:09 +0200 | [diff] [blame] | 406 | } __attribute__ ((packed)); |
Pau Espin Pedrol | 0bdd8bf | 2018-01-26 17:46:37 +0100 | [diff] [blame] | 407 | |
| 408 | struct ipcp_hdr { |
| 409 | uint8_t code; |
| 410 | uint8_t id; |
| 411 | uint16_t len; |
| 412 | uint8_t options[0]; |
Philipp Maier | 6a2856b | 2018-05-28 17:50:09 +0200 | [diff] [blame] | 413 | } __attribute__ ((packed)); |
Pau Espin Pedrol | 0bdd8bf | 2018-01-26 17:46:37 +0100 | [diff] [blame] | 414 | |
| 415 | /* determine if IPCP contains given option */ |
Stefan Sperling | d70ab97 | 2018-07-19 15:25:47 +0200 | [diff] [blame^] | 416 | static uint8_t *ipcp_contains_option(uint8_t *ipcp, size_t ipcp_len, enum ipcp_options opt, size_t opt_minlen) |
Pau Espin Pedrol | 0bdd8bf | 2018-01-26 17:46:37 +0100 | [diff] [blame] | 417 | { |
Stefan Sperling | d70ab97 | 2018-07-19 15:25:47 +0200 | [diff] [blame^] | 418 | uint8_t *cur_opt = ipcp + sizeof(struct ipcp_hdr); |
Pau Espin Pedrol | 0bdd8bf | 2018-01-26 17:46:37 +0100 | [diff] [blame] | 419 | |
| 420 | /* iterate over Options and check if protocol contained */ |
Stefan Sperling | d70ab97 | 2018-07-19 15:25:47 +0200 | [diff] [blame^] | 421 | while (cur_opt + 2 <= ipcp + ipcp_len) { |
| 422 | uint8_t type = cur_opt[0]; |
| 423 | uint8_t len = cur_opt[1]; /* length value includes 2 bytes type/length */ |
| 424 | if (len < 2) |
| 425 | return NULL; |
| 426 | if (type == opt && len >= 2 + opt_minlen) |
Pau Espin Pedrol | 0bdd8bf | 2018-01-26 17:46:37 +0100 | [diff] [blame] | 427 | return cur_opt; |
Stefan Sperling | d70ab97 | 2018-07-19 15:25:47 +0200 | [diff] [blame^] | 428 | cur_opt += len; |
Pau Espin Pedrol | 0bdd8bf | 2018-01-26 17:46:37 +0100 | [diff] [blame] | 429 | } |
| 430 | return NULL; |
| 431 | } |
| 432 | |
Harald Welte | 1ae9877 | 2017-08-09 20:28:52 +0200 | [diff] [blame] | 433 | /* 3GPP TS 24.008 10.6.5.3 */ |
| 434 | enum pco_protocols { |
| 435 | PCO_P_LCP = 0xC021, |
| 436 | PCO_P_PAP = 0xC023, |
| 437 | PCO_P_CHAP = 0xC223, |
| 438 | PCO_P_IPCP = 0x8021, |
| 439 | PCO_P_PCSCF_ADDR = 0x0001, |
| 440 | PCO_P_IM_CN_SS_F = 0x0002, |
| 441 | PCO_P_DNS_IPv6_ADDR = 0x0003, |
| 442 | PCO_P_POLICY_CTRL_REJ = 0x0004, /* only in Network->MS */ |
| 443 | PCO_P_MS_SUP_NETREQ_BCI = 0x0005, |
| 444 | /* reserved */ |
| 445 | PCO_P_DSMIPv6_HA_ADDR = 0x0007, |
| 446 | PCO_P_DSMIPv6_HN_PREF = 0x0008, |
| 447 | PCO_P_DSMIPv6_v4_HA_ADDR= 0x0009, |
| 448 | PCO_P_IP_ADDR_VIA_NAS = 0x000a, /* only MS->Network */ |
| 449 | PCO_P_IPv4_ADDR_VIA_DHCP= 0x000b, /* only MS->Netowrk */ |
| 450 | PCO_P_PCSCF_IPv4_ADDR = 0x000c, |
| 451 | PCO_P_DNS_IPv4_ADDR = 0x000d, |
| 452 | PCO_P_MSISDN = 0x000e, |
| 453 | PCO_P_IFOM_SUPPORT = 0x000f, |
| 454 | PCO_P_IPv4_LINK_MTU = 0x0010, |
| 455 | PCO_P_MS_SUPP_LOC_A_TFT = 0x0011, |
| 456 | PCO_P_PCSCF_RESEL_SUP = 0x0012, /* only MS->Network */ |
| 457 | PCO_P_NBIFOM_REQ = 0x0013, |
| 458 | PCO_P_NBIFOM_MODE = 0x0014, |
| 459 | PCO_P_NONIP_LINK_MTU = 0x0015, |
| 460 | PCO_P_APN_RATE_CTRL_SUP = 0x0016, |
| 461 | PCO_P_PS_DATA_OFF_UE = 0x0017, |
| 462 | PCO_P_REL_DATA_SVC = 0x0018, |
| 463 | }; |
| 464 | |
| 465 | /* determine if PCO contains given protocol */ |
Stefan Sperling | d70ab97 | 2018-07-19 15:25:47 +0200 | [diff] [blame^] | 466 | static uint8_t *pco_contains_proto(struct ul255_t *pco, uint16_t prot, size_t prot_minlen) |
Harald Welte | 1ae9877 | 2017-08-09 20:28:52 +0200 | [diff] [blame] | 467 | { |
| 468 | uint8_t *cur = pco->v + 1; |
| 469 | |
| 470 | /* iterate over PCO and check if protocol contained */ |
Pau Espin Pedrol | 0ab62fe | 2017-08-30 15:51:24 +0200 | [diff] [blame] | 471 | while (cur + 3 <= pco->v + pco->l) { |
Harald Welte | 1ae9877 | 2017-08-09 20:28:52 +0200 | [diff] [blame] | 472 | uint16_t cur_prot = osmo_load16be(cur); |
| 473 | uint8_t cur_len = cur[2]; |
Stefan Sperling | d70ab97 | 2018-07-19 15:25:47 +0200 | [diff] [blame^] | 474 | if (cur_prot == prot && cur_len >= prot_minlen) |
Pau Espin Pedrol | 0bdd8bf | 2018-01-26 17:46:37 +0100 | [diff] [blame] | 475 | return cur; |
Pau Espin Pedrol | 0ab62fe | 2017-08-30 15:51:24 +0200 | [diff] [blame] | 476 | cur += cur_len + 3; |
Harald Welte | 1ae9877 | 2017-08-09 20:28:52 +0200 | [diff] [blame] | 477 | } |
Pau Espin Pedrol | 0bdd8bf | 2018-01-26 17:46:37 +0100 | [diff] [blame] | 478 | return NULL; |
Harald Welte | 1ae9877 | 2017-08-09 20:28:52 +0200 | [diff] [blame] | 479 | } |
| 480 | |
Pau Espin Pedrol | 7d54ed4 | 2018-01-25 20:09:16 +0100 | [diff] [blame] | 481 | /*! Get the peer of pdp based on IP version used. |
| 482 | * \param[in] pdp PDP context to select the peer from. |
| 483 | * \param[in] v4v6 IP version to select. Valid values are 4 and 6. |
| 484 | * \returns The selected peer matching the given IP version. NULL if not present. |
| 485 | */ |
| 486 | static struct ippoolm_t *pdp_get_peer_ipv(struct pdp_t *pdp, bool is_ipv6) { |
| 487 | uint8_t len1, len2, i; |
| 488 | |
| 489 | if (is_ipv6) { |
| 490 | len1 = 8; |
| 491 | len2 = 16; |
| 492 | } else { |
| 493 | len1 = sizeof(struct in_addr); |
| 494 | len2 = len1; |
| 495 | } |
| 496 | |
| 497 | for (i = 0; i < 2; i++) { |
| 498 | struct ippoolm_t * ippool = pdp->peer[i]; |
| 499 | if (ippool && (ippool->addr.len == len1 || ippool->addr.len == len2)) |
| 500 | return ippool; |
| 501 | } |
| 502 | return NULL; |
| 503 | } |
| 504 | |
Pau Espin Pedrol | 0bdd8bf | 2018-01-26 17:46:37 +0100 | [diff] [blame] | 505 | /* construct an IPCP PCO response from request*/ |
Stefan Sperling | d70ab97 | 2018-07-19 15:25:47 +0200 | [diff] [blame^] | 506 | static void build_ipcp_pco(struct apn_ctx *apn, struct pdp_t *pdp, struct msgb *msg) |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 507 | { |
Pau Espin Pedrol | 0bdd8bf | 2018-01-26 17:46:37 +0100 | [diff] [blame] | 508 | const struct in46_addr *dns1 = &apn->v4.cfg.dns[0]; |
| 509 | const struct in46_addr *dns2 = &apn->v4.cfg.dns[1]; |
Stefan Sperling | d70ab97 | 2018-07-19 15:25:47 +0200 | [diff] [blame^] | 510 | uint8_t *ipcp; |
| 511 | uint16_t ipcp_len; |
Pau Espin Pedrol | 0bdd8bf | 2018-01-26 17:46:37 +0100 | [diff] [blame] | 512 | uint8_t *len1, *len2, *pco_ipcp; |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 513 | uint8_t *start = msg->tail; |
| 514 | unsigned int len_appended; |
Stefan Sperling | d70ab97 | 2018-07-19 15:25:47 +0200 | [diff] [blame^] | 515 | ptrdiff_t consumed; |
| 516 | size_t remain; |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 517 | |
Stefan Sperling | d70ab97 | 2018-07-19 15:25:47 +0200 | [diff] [blame^] | 518 | /* pco_contains_proto() returns a potentially unaligned pointer into pco_req->v (see OS#3194) */ |
| 519 | if (!(pco_ipcp = pco_contains_proto(&pdp->pco_req, PCO_P_IPCP, sizeof(struct ipcp_hdr)))) |
| 520 | return; |
| 521 | |
| 522 | ipcp = (pco_ipcp + 3); /* 2=type + 1=len */ |
| 523 | consumed = (ipcp - &pdp->pco_req.v[0]); |
| 524 | remain = sizeof(pdp->pco_req.v) - consumed; |
| 525 | ipcp_len = osmo_load16be(ipcp + 2); /* 1=code + 1=id */ |
| 526 | if (remain < 0 || remain < ipcp_len) |
| 527 | return; |
Pau Espin Pedrol | 0bdd8bf | 2018-01-26 17:46:37 +0100 | [diff] [blame] | 528 | |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 529 | /* Three byte T16L header */ |
| 530 | msgb_put_u16(msg, 0x8021); /* IPCP */ |
| 531 | len1 = msgb_put(msg, 1); /* Length of contents: delay */ |
| 532 | |
| 533 | msgb_put_u8(msg, 0x02); /* ACK */ |
Stefan Sperling | d70ab97 | 2018-07-19 15:25:47 +0200 | [diff] [blame^] | 534 | msgb_put_u8(msg, ipcp[1]); /* ID: Needs to match request */ |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 535 | msgb_put_u8(msg, 0x00); /* Length MSB */ |
| 536 | len2 = msgb_put(msg, 1); /* Length LSB: delay */ |
| 537 | |
Stefan Sperling | d70ab97 | 2018-07-19 15:25:47 +0200 | [diff] [blame^] | 538 | if (dns1->len == 4 && ipcp_contains_option(ipcp, ipcp_len, IPCP_OPT_PRIMARY_DNS, 4)) { |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 539 | msgb_put_u8(msg, 0x81); /* DNS1 Tag */ |
| 540 | msgb_put_u8(msg, 2 + dns1->len);/* DNS1 Length, incl. TL */ |
Harald Welte | bcab7fb | 2017-12-03 21:43:50 +0100 | [diff] [blame] | 541 | msgb_put_u32(msg, ntohl(dns1->v4.s_addr)); |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 542 | } |
| 543 | |
Stefan Sperling | d70ab97 | 2018-07-19 15:25:47 +0200 | [diff] [blame^] | 544 | if (dns2->len == 4 && ipcp_contains_option(ipcp, ipcp_len, IPCP_OPT_SECONDARY_DNS, 4)) { |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 545 | msgb_put_u8(msg, 0x83); /* DNS2 Tag */ |
| 546 | msgb_put_u8(msg, 2 + dns2->len);/* DNS2 Length, incl. TL */ |
Harald Welte | bcab7fb | 2017-12-03 21:43:50 +0100 | [diff] [blame] | 547 | msgb_put_u32(msg, ntohl(dns2->v4.s_addr)); |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 548 | } |
| 549 | |
| 550 | /* patch in length values */ |
| 551 | len_appended = msg->tail - start; |
| 552 | *len1 = len_appended - 3; |
| 553 | *len2 = len_appended - 3; |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 554 | } |
| 555 | |
Harald Welte | 1ae9877 | 2017-08-09 20:28:52 +0200 | [diff] [blame] | 556 | /* process one PCO request from a MS/UE, putting together the proper responses */ |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 557 | static void process_pco(struct apn_ctx *apn, struct pdp_t *pdp) |
Harald Welte | 1ae9877 | 2017-08-09 20:28:52 +0200 | [diff] [blame] | 558 | { |
| 559 | struct msgb *msg = msgb_alloc(256, "PCO"); |
Pau Espin Pedrol | 4ae8d82 | 2018-01-26 17:51:55 +0100 | [diff] [blame] | 560 | struct ippoolm_t *peer_v4 = pdp_get_peer_ipv(pdp, false); |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 561 | unsigned int i; |
| 562 | |
| 563 | OSMO_ASSERT(msg); |
Harald Welte | 1ae9877 | 2017-08-09 20:28:52 +0200 | [diff] [blame] | 564 | msgb_put_u8(msg, 0x80); /* ext-bit + configuration protocol byte */ |
| 565 | |
Pau Espin Pedrol | 4ae8d82 | 2018-01-26 17:51:55 +0100 | [diff] [blame] | 566 | if (peer_v4) |
Pau Espin Pedrol | 0bdd8bf | 2018-01-26 17:46:37 +0100 | [diff] [blame] | 567 | build_ipcp_pco(apn, pdp, msg); |
Harald Welte | 1ae9877 | 2017-08-09 20:28:52 +0200 | [diff] [blame] | 568 | |
Stefan Sperling | d70ab97 | 2018-07-19 15:25:47 +0200 | [diff] [blame^] | 569 | if (pco_contains_proto(&pdp->pco_req, PCO_P_DNS_IPv6_ADDR, 0)) { |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 570 | for (i = 0; i < ARRAY_SIZE(apn->v6.cfg.dns); i++) { |
| 571 | struct in46_addr *i46a = &apn->v6.cfg.dns[i]; |
| 572 | if (i46a->len != 16) |
| 573 | continue; |
| 574 | msgb_t16lv_put(msg, PCO_P_DNS_IPv6_ADDR, i46a->len, i46a->v6.s6_addr); |
| 575 | } |
Harald Welte | 1ae9877 | 2017-08-09 20:28:52 +0200 | [diff] [blame] | 576 | } |
| 577 | |
Stefan Sperling | d70ab97 | 2018-07-19 15:25:47 +0200 | [diff] [blame^] | 578 | if (pco_contains_proto(&pdp->pco_req, PCO_P_DNS_IPv4_ADDR, 0)) { |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 579 | for (i = 0; i < ARRAY_SIZE(apn->v4.cfg.dns); i++) { |
| 580 | struct in46_addr *i46a = &apn->v4.cfg.dns[i]; |
| 581 | if (i46a->len != 4) |
| 582 | continue; |
| 583 | msgb_t16lv_put(msg, PCO_P_DNS_IPv4_ADDR, i46a->len, (uint8_t *)&i46a->v4); |
| 584 | } |
Harald Welte | 1ae9877 | 2017-08-09 20:28:52 +0200 | [diff] [blame] | 585 | } |
| 586 | |
| 587 | if (msgb_length(msg) > 1) { |
| 588 | memcpy(pdp->pco_neg.v, msgb_data(msg), msgb_length(msg)); |
| 589 | pdp->pco_neg.l = msgb_length(msg); |
| 590 | } else |
| 591 | pdp->pco_neg.l = 0; |
| 592 | |
| 593 | msgb_free(msg); |
| 594 | } |
| 595 | |
Harald Welte | 9d9d91b | 2017-10-14 16:22:16 +0200 | [diff] [blame] | 596 | static bool apn_supports_ipv4(const struct apn_ctx *apn) |
| 597 | { |
| 598 | if (apn->v4.cfg.static_prefix.addr.len || apn->v4.cfg.dynamic_prefix.addr.len) |
| 599 | return true; |
| 600 | return false; |
| 601 | } |
| 602 | |
| 603 | static bool apn_supports_ipv6(const struct apn_ctx *apn) |
| 604 | { |
| 605 | if (apn->v6.cfg.static_prefix.addr.len || apn->v6.cfg.dynamic_prefix.addr.len) |
| 606 | return true; |
| 607 | return false; |
| 608 | } |
| 609 | |
Harald Welte | bed35df | 2011-11-02 13:06:18 +0100 | [diff] [blame] | 610 | int create_context_ind(struct pdp_t *pdp) |
| 611 | { |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 612 | static char name_buf[256]; |
| 613 | struct gsn_t *gsn = pdp->gsn; |
| 614 | struct ggsn_ctx *ggsn = gsn->priv; |
Pau Espin Pedrol | 2d6a69e | 2017-12-06 19:26:25 +0100 | [diff] [blame] | 615 | struct in46_addr addr[2]; |
Pau Espin Pedrol | 4e43ef5 | 2018-01-26 18:12:19 +0100 | [diff] [blame] | 616 | struct ippoolm_t *member = NULL, *addrv4 = NULL, *addrv6 = NULL; |
| 617 | char straddrv4[INET_ADDRSTRLEN], straddrv6[INET6_ADDRSTRLEN]; |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 618 | struct apn_ctx *apn; |
Pau Espin Pedrol | 2d6a69e | 2017-12-06 19:26:25 +0100 | [diff] [blame] | 619 | int rc, num_addr, i; |
jjako | 52c2414 | 2002-12-16 13:33:51 +0000 | [diff] [blame] | 620 | |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 621 | osmo_apn_to_str(name_buf, pdp->apn_req.v, pdp->apn_req.l); |
| 622 | |
| 623 | LOGPPDP(LOGL_DEBUG, pdp, "Processing create PDP context request for APN '%s'\n", name_buf); |
| 624 | |
| 625 | /* First find an exact APN name match */ |
| 626 | apn = ggsn_find_apn(ggsn, name_buf); |
Harald Welte | 2e84d2c | 2017-10-01 13:36:52 +0800 | [diff] [blame] | 627 | /* ignore if the APN has not been started */ |
Pau Espin Pedrol | 958256f | 2017-10-11 20:32:55 +0200 | [diff] [blame] | 628 | if (apn && !apn->started) |
Harald Welte | 2e84d2c | 2017-10-01 13:36:52 +0800 | [diff] [blame] | 629 | apn = NULL; |
Harald Welte | b16c46b | 2017-10-01 18:28:18 +0800 | [diff] [blame] | 630 | |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 631 | /* then try default (if any) */ |
| 632 | if (!apn) |
| 633 | apn = ggsn->cfg.default_apn; |
Harald Welte | b16c46b | 2017-10-01 18:28:18 +0800 | [diff] [blame] | 634 | /* ignore if the APN has not been started */ |
Pau Espin Pedrol | 958256f | 2017-10-11 20:32:55 +0200 | [diff] [blame] | 635 | if (apn && !apn->started) |
Harald Welte | b16c46b | 2017-10-01 18:28:18 +0800 | [diff] [blame] | 636 | apn = NULL; |
| 637 | |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 638 | if (!apn) { |
| 639 | /* no APN found for what user requested */ |
| 640 | LOGPPDP(LOGL_NOTICE, pdp, "Unknown APN '%s', rejecting\n", name_buf); |
| 641 | gtp_create_context_resp(gsn, pdp, GTPCAUSE_MISSING_APN); |
| 642 | return 0; |
| 643 | } |
jjako | 52c2414 | 2002-12-16 13:33:51 +0000 | [diff] [blame] | 644 | |
Harald Welte | d9d8862 | 2017-08-04 00:22:35 +0200 | [diff] [blame] | 645 | /* FIXME: we manually force all context requests to dynamic here! */ |
| 646 | if (pdp->eua.l > 2) |
| 647 | pdp->eua.l = 2; |
jjako | 52c2414 | 2002-12-16 13:33:51 +0000 | [diff] [blame] | 648 | |
Harald Welte | bed35df | 2011-11-02 13:06:18 +0100 | [diff] [blame] | 649 | memcpy(pdp->qos_neg0, pdp->qos_req0, sizeof(pdp->qos_req0)); |
jjako | 52c2414 | 2002-12-16 13:33:51 +0000 | [diff] [blame] | 650 | |
Harald Welte | bed35df | 2011-11-02 13:06:18 +0100 | [diff] [blame] | 651 | memcpy(pdp->qos_neg.v, pdp->qos_req.v, pdp->qos_req.l); /* TODO */ |
| 652 | pdp->qos_neg.l = pdp->qos_req.l; |
jjako | 52c2414 | 2002-12-16 13:33:51 +0000 | [diff] [blame] | 653 | |
Pau Espin Pedrol | 2d6a69e | 2017-12-06 19:26:25 +0100 | [diff] [blame] | 654 | memset(addr, 0, sizeof(addr)); |
| 655 | if ((num_addr = in46a_from_eua(&pdp->eua, addr)) < 0) { |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 656 | LOGPPDP(LOGL_ERROR, pdp, "Cannot decode EUA from MS/SGSN: %s\n", |
Harald Welte | d1bf1e1 | 2017-08-03 00:00:23 +0200 | [diff] [blame] | 657 | osmo_hexdump(pdp->eua.v, pdp->eua.l)); |
| 658 | gtp_create_context_resp(gsn, pdp, GTPCAUSE_UNKNOWN_PDP); |
| 659 | return 0; |
Harald Welte | bed35df | 2011-11-02 13:06:18 +0100 | [diff] [blame] | 660 | } |
jjako | a7cd249 | 2003-04-11 09:40:12 +0000 | [diff] [blame] | 661 | |
Pau Espin Pedrol | 2d6a69e | 2017-12-06 19:26:25 +0100 | [diff] [blame] | 662 | /* Allocate dynamic addresses from the pool */ |
| 663 | for (i = 0; i < num_addr; i++) { |
| 664 | if (addr[i].len == sizeof(struct in_addr)) { |
| 665 | /* does this APN actually have an IPv4 pool? */ |
| 666 | if (!apn_supports_ipv4(apn)) |
| 667 | goto err_wrong_af; |
Harald Welte | 9d9d91b | 2017-10-14 16:22:16 +0200 | [diff] [blame] | 668 | |
Pau Espin Pedrol | 2d6a69e | 2017-12-06 19:26:25 +0100 | [diff] [blame] | 669 | rc = ippool_newip(apn->v4.pool, &member, &addr[i], 0); |
| 670 | if (rc < 0) |
| 671 | goto err_pool_full; |
| 672 | /* copy back */ |
| 673 | memcpy(&addr[i].v4.s_addr, &member->addr.v4, 4); |
jjako | a7cd249 | 2003-04-11 09:40:12 +0000 | [diff] [blame] | 674 | |
Pau Espin Pedrol | 4e43ef5 | 2018-01-26 18:12:19 +0100 | [diff] [blame] | 675 | addrv4 = member; |
| 676 | |
Pau Espin Pedrol | 2d6a69e | 2017-12-06 19:26:25 +0100 | [diff] [blame] | 677 | } else if (addr[i].len == sizeof(struct in6_addr)) { |
| 678 | |
| 679 | /* does this APN actually have an IPv6 pool? */ |
| 680 | if (!apn_supports_ipv6(apn)) |
| 681 | goto err_wrong_af; |
| 682 | |
| 683 | rc = ippool_newip(apn->v6.pool, &member, &addr[i], 0); |
| 684 | if (rc < 0) |
| 685 | goto err_pool_full; |
| 686 | |
| 687 | /* IPv6 doesn't really send the real/allocated address at this point, but just |
| 688 | * the link-identifier which the MS shall use for router solicitation */ |
| 689 | /* initialize upper 64 bits to prefix, they are discarded by MS anyway */ |
| 690 | memcpy(addr[i].v6.s6_addr, &member->addr.v6, 8); |
| 691 | /* use allocated 64bit prefix as lower 64bit, used as link id by MS */ |
| 692 | memcpy(addr[i].v6.s6_addr+8, &member->addr.v6, 8); |
Pau Espin Pedrol | 4e43ef5 | 2018-01-26 18:12:19 +0100 | [diff] [blame] | 693 | |
| 694 | addrv6 = member; |
Pau Espin Pedrol | 2d6a69e | 2017-12-06 19:26:25 +0100 | [diff] [blame] | 695 | } else |
| 696 | OSMO_ASSERT(0); |
| 697 | |
| 698 | pdp->peer[i] = member; |
| 699 | member->peer = pdp; |
| 700 | } |
| 701 | |
| 702 | in46a_to_eua(addr, num_addr, &pdp->eua); |
| 703 | |
Harald Welte | 546884d | 2018-04-25 21:13:06 +0200 | [diff] [blame] | 704 | if (apn->cfg.gtpu_mode == APN_GTPU_MODE_KERNEL_GTP && apn_supports_ipv4(apn)) { |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 705 | /* TODO: In IPv6, EUA doesn't contain the actual IP addr/prefix! */ |
Harald Welte | 698a233 | 2017-11-08 15:09:58 +0900 | [diff] [blame] | 706 | if (gtp_kernel_tunnel_add(pdp, apn->tun.cfg.dev_name) < 0) { |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 707 | LOGPPDP(LOGL_ERROR, pdp, "Cannot add tunnel to kernel: %s\n", strerror(errno)); |
| 708 | gtp_create_context_resp(gsn, pdp, GTPCAUSE_SYS_FAIL); |
| 709 | return 0; |
| 710 | } |
Pau Espin Pedrol | 2d6a69e | 2017-12-06 19:26:25 +0100 | [diff] [blame] | 711 | } |
Harald Welte | 9d9d91b | 2017-10-14 16:22:16 +0200 | [diff] [blame] | 712 | |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 713 | pdp->ipif = apn->tun.tun; /* TODO */ |
Harald Welte | 698a233 | 2017-11-08 15:09:58 +0900 | [diff] [blame] | 714 | pdp->priv = apn; |
Max | 3142d8d | 2017-05-04 17:45:10 +0200 | [diff] [blame] | 715 | |
Pau Espin Pedrol | 4e43ef5 | 2018-01-26 18:12:19 +0100 | [diff] [blame] | 716 | /* TODO: change trap to send 2 IPs */ |
Max | 3142d8d | 2017-05-04 17:45:10 +0200 | [diff] [blame] | 717 | if (!send_trap(gsn, pdp, member, "imsi-ass-ip")) { /* TRAP with IP assignment */ |
Max | 727417d | 2016-08-02 17:10:38 +0200 | [diff] [blame] | 718 | gtp_create_context_resp(gsn, pdp, GTPCAUSE_NO_RESOURCES); |
| 719 | return 0; |
| 720 | } |
Pablo Neira Ayuso | 4b075b6 | 2015-11-17 12:22:42 +0100 | [diff] [blame] | 721 | |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 722 | process_pco(apn, pdp); |
Harald Welte | 1ae9877 | 2017-08-09 20:28:52 +0200 | [diff] [blame] | 723 | |
Harald Welte | 93fed3b | 2017-09-24 11:43:17 +0800 | [diff] [blame] | 724 | /* Transmit G-PDU sequence numbers (only) if configured in APN */ |
| 725 | pdp->tx_gpdu_seq = apn->cfg.tx_gpdu_seq; |
| 726 | |
Pau Espin Pedrol | 4e43ef5 | 2018-01-26 18:12:19 +0100 | [diff] [blame] | 727 | LOGPPDP(LOGL_INFO, pdp, "Successful PDP Context Creation: APN=%s(%s), TEIC=%u, IPv4=%s, IPv6=%s\n", |
| 728 | name_buf, apn->cfg.name, pdp->teic_own, |
| 729 | addrv4 ? inet_ntop(AF_INET, &addrv4->addr.v4, straddrv4, sizeof(straddrv4)) : "none", |
| 730 | addrv6 ? inet_ntop(AF_INET6, &addrv6->addr.v6, straddrv6, sizeof(straddrv6)) : "none"); |
Harald Welte | bed35df | 2011-11-02 13:06:18 +0100 | [diff] [blame] | 731 | gtp_create_context_resp(gsn, pdp, GTPCAUSE_ACC_REQ); |
| 732 | return 0; /* Success */ |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 733 | |
| 734 | err_pool_full: |
| 735 | LOGPPDP(LOGL_ERROR, pdp, "Cannot allocate IP address from pool (full!)\n"); |
| 736 | gtp_create_context_resp(gsn, pdp, -rc); |
| 737 | return 0; /* Already in use, or no more available */ |
Harald Welte | 9d9d91b | 2017-10-14 16:22:16 +0200 | [diff] [blame] | 738 | |
| 739 | err_wrong_af: |
| 740 | LOGPPDP(LOGL_ERROR, pdp, "APN doesn't support requested EUA / AF type\n"); |
| 741 | gtp_create_context_resp(gsn, pdp, GTPCAUSE_UNKNOWN_PDP); |
| 742 | return 0; |
jjako | 52c2414 | 2002-12-16 13:33:51 +0000 | [diff] [blame] | 743 | } |
| 744 | |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 745 | /* Internet-originated IP packet, needs to be sent via GTP towards MS */ |
| 746 | static int cb_tun_ind(struct tun_t *tun, void *pack, unsigned len) |
Harald Welte | bed35df | 2011-11-02 13:06:18 +0100 | [diff] [blame] | 747 | { |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 748 | struct apn_ctx *apn = tun->priv; |
Harald Welte | bed35df | 2011-11-02 13:06:18 +0100 | [diff] [blame] | 749 | struct ippoolm_t *ipm; |
Harald Welte | d12eab9 | 2017-08-02 19:49:47 +0200 | [diff] [blame] | 750 | struct in46_addr dst; |
Harald Welte | 63ebccd | 2017-08-02 21:10:09 +0200 | [diff] [blame] | 751 | struct iphdr *iph = (struct iphdr *)pack; |
Harald Welte | a0d281d | 2017-08-02 21:48:16 +0200 | [diff] [blame] | 752 | struct ip6_hdr *ip6h = (struct ip6_hdr *)pack; |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 753 | struct ippool_t *pool; |
Pau Espin Pedrol | 134855c | 2018-01-30 16:04:53 +0100 | [diff] [blame] | 754 | char straddr[INET6_ADDRSTRLEN]; |
Pau Espin Pedrol | dddbbaa | 2018-01-30 16:16:33 +0100 | [diff] [blame] | 755 | uint8_t pref_offset; |
jjako | c6762cf | 2004-04-28 14:52:58 +0000 | [diff] [blame] | 756 | |
Pau Espin Pedrol | a4942e6 | 2018-01-30 16:01:27 +0100 | [diff] [blame] | 757 | switch (iph->version) { |
| 758 | case 4: |
Harald Welte | d12eab9 | 2017-08-02 19:49:47 +0200 | [diff] [blame] | 759 | if (len < sizeof(*iph) || len < 4*iph->ihl) |
| 760 | return -1; |
| 761 | dst.len = 4; |
Harald Welte | 63ebccd | 2017-08-02 21:10:09 +0200 | [diff] [blame] | 762 | dst.v4.s_addr = iph->daddr; |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 763 | pool = apn->v4.pool; |
Pau Espin Pedrol | a4942e6 | 2018-01-30 16:01:27 +0100 | [diff] [blame] | 764 | break; |
| 765 | case 6: |
Harald Welte | d4d6e09 | 2017-08-08 18:10:43 +0200 | [diff] [blame] | 766 | /* Due to the fact that 3GPP requires an allocation of a |
| 767 | * /64 prefix to each MS, we must instruct |
| 768 | * ippool_getip() below to match only the leading /64 |
Pau Espin Pedrol | dddbbaa | 2018-01-30 16:16:33 +0100 | [diff] [blame] | 769 | * prefix, i.e. the first 8 bytes of the address. If the ll addr |
| 770 | * is used, then the match should be done on the trailing 64 |
| 771 | * bits. */ |
Harald Welte | d4d6e09 | 2017-08-08 18:10:43 +0200 | [diff] [blame] | 772 | dst.len = 8; |
Pau Espin Pedrol | dddbbaa | 2018-01-30 16:16:33 +0100 | [diff] [blame] | 773 | pref_offset = IN6_IS_ADDR_LINKLOCAL(&ip6h->ip6_dst) ? 8 : 0; |
| 774 | memcpy(&dst.v6, ((uint8_t*)&ip6h->ip6_dst) + pref_offset, 8); |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 775 | pool = apn->v6.pool; |
Pau Espin Pedrol | a4942e6 | 2018-01-30 16:01:27 +0100 | [diff] [blame] | 776 | break; |
| 777 | default: |
Pau Espin Pedrol | 55d639f | 2017-12-04 13:17:07 +0100 | [diff] [blame] | 778 | LOGP(DTUN, LOGL_NOTICE, "non-IPv%u packet received from tun\n", iph->version); |
Harald Welte | d12eab9 | 2017-08-02 19:49:47 +0200 | [diff] [blame] | 779 | return -1; |
| 780 | } |
jjako | c6762cf | 2004-04-28 14:52:58 +0000 | [diff] [blame] | 781 | |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 782 | /* IPv6 packet but no IPv6 pool, or IPv4 packet with no IPv4 pool */ |
| 783 | if (!pool) |
| 784 | return 0; |
Harald Welte | bed35df | 2011-11-02 13:06:18 +0100 | [diff] [blame] | 785 | |
Max | 427699e | 2017-12-05 16:30:37 +0100 | [diff] [blame] | 786 | DEBUGP(DTUN, "Received packet for APN(%s) from tun %s", apn->cfg.name, tun->devname); |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 787 | |
| 788 | if (ippool_getip(pool, &ipm, &dst)) { |
Pau Espin Pedrol | 134855c | 2018-01-30 16:04:53 +0100 | [diff] [blame] | 789 | DEBUGPC(DTUN, " with no PDP contex! (%s)\n", iph->version == 4 ? |
| 790 | inet_ntop(AF_INET, &iph->saddr, straddr, sizeof(straddr)) : |
| 791 | inet_ntop(AF_INET6, &ip6h->ip6_src, straddr, sizeof(straddr))); |
Harald Welte | bed35df | 2011-11-02 13:06:18 +0100 | [diff] [blame] | 792 | return 0; |
| 793 | } |
Max | 427699e | 2017-12-05 16:30:37 +0100 | [diff] [blame] | 794 | DEBUGPC(DTUN, "\n"); |
Harald Welte | bed35df | 2011-11-02 13:06:18 +0100 | [diff] [blame] | 795 | |
| 796 | if (ipm->peer) /* Check if a peer protocol is defined */ |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 797 | gtp_data_req(apn->ggsn->gsn, (struct pdp_t *)ipm->peer, pack, len); |
Harald Welte | bed35df | 2011-11-02 13:06:18 +0100 | [diff] [blame] | 798 | return 0; |
jjako | 52c2414 | 2002-12-16 13:33:51 +0000 | [diff] [blame] | 799 | } |
| 800 | |
Harald Welte | d46bcd2 | 2017-08-08 23:27:22 +0200 | [diff] [blame] | 801 | /* RFC3307 link-local scope multicast address */ |
| 802 | static const struct in6_addr all_router_mcast_addr = { |
| 803 | .s6_addr = { 0xff,0x02,0,0, 0,0,0,0, 0,0,0,0, 0,0,0,2 } |
| 804 | }; |
| 805 | |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 806 | /* MS-originated GTP1-U packet, needs to be sent via TUN device */ |
| 807 | static int encaps_tun(struct pdp_t *pdp, void *pack, unsigned len) |
Harald Welte | bed35df | 2011-11-02 13:06:18 +0100 | [diff] [blame] | 808 | { |
Harald Welte | d46bcd2 | 2017-08-08 23:27:22 +0200 | [diff] [blame] | 809 | struct iphdr *iph = (struct iphdr *)pack; |
| 810 | struct ip6_hdr *ip6h = (struct ip6_hdr *)pack; |
Harald Welte | f85fe97 | 2017-09-24 20:00:34 +0800 | [diff] [blame] | 811 | struct tun_t *tun = (struct tun_t *)pdp->ipif; |
| 812 | struct apn_ctx *apn = tun->priv; |
Pau Espin Pedrol | 5b1ef95 | 2018-01-25 20:50:59 +0100 | [diff] [blame] | 813 | char straddr[INET6_ADDRSTRLEN]; |
Pau Espin Pedrol | 7d54ed4 | 2018-01-25 20:09:16 +0100 | [diff] [blame] | 814 | struct ippoolm_t *peer; |
Pau Espin Pedrol | 5b1ef95 | 2018-01-25 20:50:59 +0100 | [diff] [blame] | 815 | uint8_t pref_offset; |
Harald Welte | f85fe97 | 2017-09-24 20:00:34 +0800 | [diff] [blame] | 816 | |
| 817 | OSMO_ASSERT(tun); |
| 818 | OSMO_ASSERT(apn); |
Harald Welte | d46bcd2 | 2017-08-08 23:27:22 +0200 | [diff] [blame] | 819 | |
Max | 427699e | 2017-12-05 16:30:37 +0100 | [diff] [blame] | 820 | LOGPPDP(LOGL_DEBUG, pdp, "Packet received on APN(%s): forwarding to tun %s\n", apn->cfg.name, tun->devname); |
Harald Welte | d46bcd2 | 2017-08-08 23:27:22 +0200 | [diff] [blame] | 821 | |
| 822 | switch (iph->version) { |
| 823 | case 6: |
Pau Espin Pedrol | 7d54ed4 | 2018-01-25 20:09:16 +0100 | [diff] [blame] | 824 | peer = pdp_get_peer_ipv(pdp, true); |
| 825 | if (!peer) { |
| 826 | LOGPPDP(LOGL_ERROR, pdp, "Packet from MS IPv6 with unassigned EUA: %s\n", |
| 827 | osmo_hexdump(pack, len)); |
| 828 | return -1; |
| 829 | } |
| 830 | |
Pau Espin Pedrol | 5b1ef95 | 2018-01-25 20:50:59 +0100 | [diff] [blame] | 831 | /* Validate packet comes from IPaddr assigned to the pdp ctx. |
| 832 | If packet is a LL addr, then EUA is in the lower 64 bits, |
| 833 | otherwise it's used as the 64 prefix */ |
| 834 | pref_offset = IN6_IS_ADDR_LINKLOCAL(&ip6h->ip6_src) ? 8 : 0; |
| 835 | if (memcmp(((uint8_t*)&ip6h->ip6_src) + pref_offset, &peer->addr.v6, 8)) { |
| 836 | LOGPPDP(LOGL_ERROR, pdp, "Packet from MS using unassigned src IPv6: %s\n", |
| 837 | inet_ntop(AF_INET6, &ip6h->ip6_src, straddr, sizeof(straddr))); |
| 838 | return -1; |
| 839 | } |
| 840 | |
Harald Welte | d46bcd2 | 2017-08-08 23:27:22 +0200 | [diff] [blame] | 841 | /* daddr: all-routers multicast addr */ |
| 842 | if (IN6_ARE_ADDR_EQUAL(&ip6h->ip6_dst, &all_router_mcast_addr)) |
Pau Espin Pedrol | 7d54ed4 | 2018-01-25 20:09:16 +0100 | [diff] [blame] | 843 | return handle_router_mcast(pdp->gsn, pdp, &peer->addr.v6, |
| 844 | &apn->v6_lladdr, pack, len); |
Harald Welte | d46bcd2 | 2017-08-08 23:27:22 +0200 | [diff] [blame] | 845 | break; |
| 846 | case 4: |
Pau Espin Pedrol | 7d54ed4 | 2018-01-25 20:09:16 +0100 | [diff] [blame] | 847 | peer = pdp_get_peer_ipv(pdp, false); |
| 848 | if (!peer) { |
| 849 | LOGPPDP(LOGL_ERROR, pdp, "Packet from MS IPv4 with unassigned EUA: %s\n", |
| 850 | osmo_hexdump(pack, len)); |
| 851 | return -1; |
| 852 | } |
Pau Espin Pedrol | 5b1ef95 | 2018-01-25 20:50:59 +0100 | [diff] [blame] | 853 | |
| 854 | /* Validate packet comes from IPaddr assigned to the pdp ctx */ |
| 855 | if (memcmp(&iph->saddr, &peer->addr.v4, sizeof(peer->addr.v4))) { |
| 856 | LOGPPDP(LOGL_ERROR, pdp, "Packet from MS using unassigned src IPv4: %s\n", |
| 857 | inet_ntop(AF_INET, &iph->saddr, straddr, sizeof(straddr))); |
| 858 | return -1; |
| 859 | } |
Harald Welte | d46bcd2 | 2017-08-08 23:27:22 +0200 | [diff] [blame] | 860 | break; |
| 861 | default: |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 862 | LOGPPDP(LOGL_ERROR, pdp, "Packet from MS is neither IPv4 nor IPv6: %s\n", |
| 863 | osmo_hexdump(pack, len)); |
Harald Welte | d46bcd2 | 2017-08-08 23:27:22 +0200 | [diff] [blame] | 864 | return -1; |
| 865 | } |
Harald Welte | bed35df | 2011-11-02 13:06:18 +0100 | [diff] [blame] | 866 | return tun_encaps((struct tun_t *)pdp->ipif, pack, len); |
jjako | 52c2414 | 2002-12-16 13:33:51 +0000 | [diff] [blame] | 867 | } |
| 868 | |
Harald Welte | 632e843 | 2017-09-05 18:12:14 +0200 | [diff] [blame] | 869 | static char *config_file = "osmo-ggsn.cfg"; |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 870 | |
| 871 | /* callback for tun device osmocom select loop integration */ |
| 872 | static int ggsn_tun_fd_cb(struct osmo_fd *fd, unsigned int what) |
| 873 | { |
| 874 | struct apn_ctx *apn = fd->data; |
| 875 | |
| 876 | OSMO_ASSERT(what & BSC_FD_READ); |
| 877 | |
| 878 | return tun_decaps(apn->tun.tun); |
| 879 | } |
| 880 | |
| 881 | /* callback for libgtp osmocom select loop integration */ |
| 882 | static int ggsn_gtp_fd_cb(struct osmo_fd *fd, unsigned int what) |
| 883 | { |
| 884 | struct ggsn_ctx *ggsn = fd->data; |
| 885 | int rc; |
| 886 | |
| 887 | OSMO_ASSERT(what & BSC_FD_READ); |
| 888 | |
| 889 | switch (fd->priv_nr) { |
| 890 | case 0: |
| 891 | rc = gtp_decaps0(ggsn->gsn); |
| 892 | break; |
| 893 | case 1: |
| 894 | rc = gtp_decaps1c(ggsn->gsn); |
| 895 | break; |
| 896 | case 2: |
| 897 | rc = gtp_decaps1u(ggsn->gsn); |
| 898 | break; |
| 899 | default: |
| 900 | OSMO_ASSERT(0); |
| 901 | break; |
| 902 | } |
| 903 | return rc; |
| 904 | } |
| 905 | |
| 906 | static void ggsn_gtp_tmr_start(struct ggsn_ctx *ggsn) |
| 907 | { |
| 908 | struct timeval next; |
| 909 | |
| 910 | /* Retrieve next retransmission as timeval */ |
| 911 | gtp_retranstimeout(ggsn->gsn, &next); |
| 912 | |
| 913 | /* re-schedule the timer */ |
| 914 | osmo_timer_schedule(&ggsn->gtp_timer, next.tv_sec, next.tv_usec/1000); |
| 915 | } |
| 916 | |
| 917 | /* timer callback for libgtp retransmission and ping */ |
| 918 | static void ggsn_gtp_tmr_cb(void *data) |
| 919 | { |
| 920 | struct ggsn_ctx *ggsn = data; |
| 921 | |
| 922 | /* do all the retransmissions as needed */ |
| 923 | gtp_retrans(ggsn->gsn); |
| 924 | |
| 925 | ggsn_gtp_tmr_start(ggsn); |
| 926 | } |
| 927 | |
| 928 | /* To exit gracefully. Used with GCC compilation flag -pg and gprof */ |
| 929 | static void signal_handler(int s) |
| 930 | { |
| 931 | LOGP(DGGSN, LOGL_NOTICE, "signal %d received\n", s); |
| 932 | switch (s) { |
| 933 | case SIGINT: |
Harald Welte | e804947 | 2017-08-20 12:44:21 +0200 | [diff] [blame] | 934 | case SIGTERM: |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 935 | LOGP(DGGSN, LOGL_NOTICE, "SIGINT received, shutting down\n"); |
| 936 | end = 1; |
| 937 | break; |
| 938 | case SIGABRT: |
| 939 | case SIGUSR1: |
| 940 | talloc_report(tall_vty_ctx, stderr); |
| 941 | talloc_report_full(tall_ggsn_ctx, stderr); |
| 942 | break; |
| 943 | case SIGUSR2: |
| 944 | talloc_report_full(tall_vty_ctx, stderr); |
| 945 | break; |
| 946 | default: |
| 947 | break; |
| 948 | } |
| 949 | } |
| 950 | |
| 951 | |
| 952 | /* Start a given GGSN */ |
| 953 | int ggsn_start(struct ggsn_ctx *ggsn) |
| 954 | { |
| 955 | struct apn_ctx *apn; |
| 956 | int rc; |
| 957 | |
| 958 | if (ggsn->started) |
| 959 | return 0; |
| 960 | |
| 961 | LOGPGGSN(LOGL_INFO, ggsn, "Starting GGSN\n"); |
| 962 | |
| 963 | /* Start libgtp listener */ |
| 964 | if (gtp_new(&ggsn->gsn, ggsn->cfg.state_dir, &ggsn->cfg.listen_addr.v4, GTP_MODE_GGSN)) { |
| 965 | LOGPGGSN(LOGL_ERROR, ggsn, "Failed to create GTP: %s\n", strerror(errno)); |
| 966 | return -1; |
| 967 | } |
| 968 | ggsn->gsn->priv = ggsn; |
| 969 | |
Harald Welte | 9814677 | 2017-09-05 17:41:20 +0200 | [diff] [blame] | 970 | /* patch in different addresses to use (in case we're behind NAT, the listen |
| 971 | * address is different from what we advertise externally) */ |
| 972 | if (ggsn->cfg.gtpc_addr.v4.s_addr) |
| 973 | ggsn->gsn->gsnc = ggsn->cfg.gtpc_addr.v4; |
| 974 | |
| 975 | if (ggsn->cfg.gtpu_addr.v4.s_addr) |
| 976 | ggsn->gsn->gsnu = ggsn->cfg.gtpu_addr.v4; |
| 977 | |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 978 | /* Register File Descriptors */ |
| 979 | osmo_fd_setup(&ggsn->gtp_fd0, ggsn->gsn->fd0, BSC_FD_READ, ggsn_gtp_fd_cb, ggsn, 0); |
| 980 | rc = osmo_fd_register(&ggsn->gtp_fd0); |
| 981 | OSMO_ASSERT(rc == 0); |
| 982 | |
| 983 | osmo_fd_setup(&ggsn->gtp_fd1c, ggsn->gsn->fd1c, BSC_FD_READ, ggsn_gtp_fd_cb, ggsn, 1); |
| 984 | rc = osmo_fd_register(&ggsn->gtp_fd1c); |
| 985 | OSMO_ASSERT(rc == 0); |
| 986 | |
| 987 | osmo_fd_setup(&ggsn->gtp_fd1u, ggsn->gsn->fd1u, BSC_FD_READ, ggsn_gtp_fd_cb, ggsn, 2); |
| 988 | rc = osmo_fd_register(&ggsn->gtp_fd1u); |
| 989 | OSMO_ASSERT(rc == 0); |
| 990 | |
| 991 | /* Start GTP re-transmission timer */ |
| 992 | osmo_timer_setup(&ggsn->gtp_timer, ggsn_gtp_tmr_cb, ggsn); |
| 993 | |
| 994 | gtp_set_cb_data_ind(ggsn->gsn, encaps_tun); |
| 995 | gtp_set_cb_delete_context(ggsn->gsn, delete_context); |
| 996 | gtp_set_cb_create_context_ind(ggsn->gsn, create_context_ind); |
| 997 | |
| 998 | LOGPGGSN(LOGL_NOTICE, ggsn, "Successfully started\n"); |
| 999 | ggsn->started = true; |
| 1000 | |
| 1001 | llist_for_each_entry(apn, &ggsn->apn_list, list) |
| 1002 | apn_start(apn); |
| 1003 | |
| 1004 | return 0; |
| 1005 | } |
| 1006 | |
| 1007 | /* Stop a given GGSN */ |
| 1008 | int ggsn_stop(struct ggsn_ctx *ggsn) |
| 1009 | { |
| 1010 | struct apn_ctx *apn; |
| 1011 | |
| 1012 | if (!ggsn->started) |
| 1013 | return 0; |
| 1014 | |
| 1015 | /* iterate over all APNs and stop them */ |
| 1016 | llist_for_each_entry(apn, &ggsn->apn_list, list) |
| 1017 | apn_stop(apn, true); |
| 1018 | |
| 1019 | osmo_timer_del(&ggsn->gtp_timer); |
| 1020 | |
| 1021 | osmo_fd_unregister(&ggsn->gtp_fd1u); |
| 1022 | osmo_fd_unregister(&ggsn->gtp_fd1c); |
| 1023 | osmo_fd_unregister(&ggsn->gtp_fd0); |
| 1024 | |
| 1025 | if (ggsn->gsn) { |
| 1026 | gtp_free(ggsn->gsn); |
| 1027 | ggsn->gsn = NULL; |
| 1028 | } |
| 1029 | |
| 1030 | ggsn->started = false; |
| 1031 | return 0; |
| 1032 | } |
| 1033 | |
| 1034 | static void print_usage() |
| 1035 | { |
| 1036 | printf("Usage: osmo-ggsn [-h] [-D] [-c configfile] [-V]\n"); |
| 1037 | } |
| 1038 | |
| 1039 | static void print_help() |
| 1040 | { |
| 1041 | printf( " Some useful help...\n" |
| 1042 | " -h --help This help text\n" |
| 1043 | " -D --daemonize Fork the process into a background daemon\n" |
| 1044 | " -c --config-file filename The config file to use\n" |
| 1045 | " -V --version Print the version of OsmoGGSN\n" |
| 1046 | ); |
| 1047 | } |
| 1048 | |
| 1049 | static void handle_options(int argc, char **argv) |
| 1050 | { |
| 1051 | while (1) { |
| 1052 | int option_index = 0, c; |
| 1053 | static struct option long_options[] = { |
| 1054 | { "help", 0, 0, 'h' }, |
| 1055 | { "daemonize", 0, 0, 'D' }, |
| 1056 | { "config-file", 1, 0, 'c' }, |
| 1057 | { "version", 0, 0, 'V' }, |
| 1058 | { 0, 0, 0, 0 } |
| 1059 | }; |
| 1060 | |
| 1061 | c = getopt_long(argc, argv, "hdc:V", long_options, &option_index); |
| 1062 | if (c == -1) |
| 1063 | break; |
| 1064 | |
| 1065 | switch (c) { |
| 1066 | case 'h': |
| 1067 | print_usage(); |
| 1068 | print_help(); |
| 1069 | exit(0); |
| 1070 | case 'D': |
| 1071 | daemonize = 1; |
| 1072 | break; |
| 1073 | case 'c': |
| 1074 | config_file = optarg; |
| 1075 | break; |
| 1076 | case 'V': |
| 1077 | print_version(1); |
| 1078 | exit(0); |
| 1079 | break; |
| 1080 | } |
| 1081 | } |
| 1082 | } |
| 1083 | |
jjako | 52c2414 | 2002-12-16 13:33:51 +0000 | [diff] [blame] | 1084 | int main(int argc, char **argv) |
| 1085 | { |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 1086 | struct ggsn_ctx *ggsn; |
| 1087 | int rc; |
jjako | 52c2414 | 2002-12-16 13:33:51 +0000 | [diff] [blame] | 1088 | |
Harald Welte | 632e843 | 2017-09-05 18:12:14 +0200 | [diff] [blame] | 1089 | tall_ggsn_ctx = talloc_named_const(NULL, 0, "OsmoGGSN"); |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 1090 | msgb_talloc_ctx_init(tall_ggsn_ctx, 0); |
Harald Welte | 3e443ca | 2018-02-14 01:04:04 +0100 | [diff] [blame] | 1091 | g_vty_info.tall_ctx = tall_ggsn_ctx; |
jjako | 52c2414 | 2002-12-16 13:33:51 +0000 | [diff] [blame] | 1092 | |
Harald Welte | e804947 | 2017-08-20 12:44:21 +0200 | [diff] [blame] | 1093 | /* Handle keyboard interrupt SIGINT */ |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 1094 | signal(SIGINT, &signal_handler); |
Harald Welte | e804947 | 2017-08-20 12:44:21 +0200 | [diff] [blame] | 1095 | signal(SIGTERM, &signal_handler); |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 1096 | signal(SIGABRT, &signal_handler); |
| 1097 | signal(SIGUSR1, &signal_handler); |
| 1098 | signal(SIGUSR2, &signal_handler); |
jjako | 52c2414 | 2002-12-16 13:33:51 +0000 | [diff] [blame] | 1099 | |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 1100 | osmo_init_ignore_signals(); |
Pau Espin Pedrol | 042a445 | 2018-04-17 14:31:42 +0200 | [diff] [blame] | 1101 | osmo_init_logging2(tall_ggsn_ctx, &log_info); |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 1102 | osmo_stats_init(tall_ggsn_ctx); |
jjako | 0141d20 | 2004-01-09 15:19:20 +0000 | [diff] [blame] | 1103 | |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 1104 | vty_init(&g_vty_info); |
| 1105 | logging_vty_add_cmds(NULL); |
Harald Welte | 3e443ca | 2018-02-14 01:04:04 +0100 | [diff] [blame] | 1106 | osmo_talloc_vty_add_cmds(); |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 1107 | osmo_stats_vty_add_cmds(&log_info); |
| 1108 | ggsn_vty_init(); |
| 1109 | ctrl_vty_init(tall_ggsn_ctx); |
| 1110 | |
| 1111 | handle_options(argc, argv); |
| 1112 | |
| 1113 | rate_ctr_init(tall_ggsn_ctx); |
| 1114 | |
| 1115 | rc = vty_read_config_file(config_file, NULL); |
| 1116 | if (rc < 0) { |
| 1117 | fprintf(stderr, "Failed to open config file: '%s'\n", config_file); |
| 1118 | exit(2); |
Harald Welte | bed35df | 2011-11-02 13:06:18 +0100 | [diff] [blame] | 1119 | } |
jjako | 52c2414 | 2002-12-16 13:33:51 +0000 | [diff] [blame] | 1120 | |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 1121 | rc = telnet_init_dynif(tall_ggsn_ctx, NULL, vty_get_bind_addr(), OSMO_VTY_PORT_GGSN); |
| 1122 | if (rc < 0) |
Harald Welte | bed35df | 2011-11-02 13:06:18 +0100 | [diff] [blame] | 1123 | exit(1); |
Holger Hans Peter Freyther | 9c0ff4f | 2014-03-23 10:07:26 +0100 | [diff] [blame] | 1124 | |
Pau Espin Pedrol | 3e0baa6 | 2018-06-19 11:50:02 +0200 | [diff] [blame] | 1125 | g_ctrlh = ctrl_interface_setup_dynip(NULL, ctrl_vty_get_bind_addr(), |
| 1126 | OSMO_CTRL_PORT_GGSN, NULL); |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 1127 | if (!g_ctrlh) { |
| 1128 | LOGP(DGGSN, LOGL_ERROR, "Failed to create CTRL interface.\n"); |
Harald Welte | bed35df | 2011-11-02 13:06:18 +0100 | [diff] [blame] | 1129 | exit(1); |
| 1130 | } |
jjako | 88c2216 | 2003-07-06 19:33:18 +0000 | [diff] [blame] | 1131 | |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 1132 | if (daemonize) { |
| 1133 | rc = osmo_daemonize(); |
| 1134 | if (rc < 0) { |
| 1135 | perror("Error during daemonize"); |
Harald Welte | bed35df | 2011-11-02 13:06:18 +0100 | [diff] [blame] | 1136 | exit(1); |
| 1137 | } |
| 1138 | } |
jjako | 1d3db97 | 2004-01-16 09:56:56 +0000 | [diff] [blame] | 1139 | |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 1140 | #if 0 |
Harald Welte | bed35df | 2011-11-02 13:06:18 +0100 | [diff] [blame] | 1141 | /* qos */ |
| 1142 | qos.l = 3; |
| 1143 | qos.v[2] = (args_info.qos_arg) & 0xff; |
| 1144 | qos.v[1] = ((args_info.qos_arg) >> 8) & 0xff; |
| 1145 | qos.v[0] = ((args_info.qos_arg) >> 16) & 0xff; |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 1146 | #endif |
jjako | a7cd249 | 2003-04-11 09:40:12 +0000 | [diff] [blame] | 1147 | |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 1148 | /* Main select loop */ |
| 1149 | while (!end) { |
| 1150 | osmo_select_main(0); |
Harald Welte | bed35df | 2011-11-02 13:06:18 +0100 | [diff] [blame] | 1151 | } |
jjako | e014978 | 2003-07-06 17:07:04 +0000 | [diff] [blame] | 1152 | |
Harald Welte | dda21ed | 2017-08-12 15:07:02 +0200 | [diff] [blame] | 1153 | llist_for_each_entry(ggsn, &g_ggsn_list, list) |
| 1154 | ggsn_stop(ggsn); |
Harald Welte | bed35df | 2011-11-02 13:06:18 +0100 | [diff] [blame] | 1155 | |
| 1156 | return 1; |
jjako | 52c2414 | 2002-12-16 13:33:51 +0000 | [diff] [blame] | 1157 | } |