blob: a3c958dd756b5985a809e955f1f21738d20a9121 [file] [log] [blame]
Daniel Willmann97374c02015-12-03 09:37:58 +01001/* Test HNB */
2
3/* (C) 2015 by Daniel Willmann <dwillmann@sysmocom.de>
4 * (C) 2015 by Sysmocom s.f.m.c. GmbH
5 * All Rights Reserved
6 *
7 * This program is free software; you can redistribute it and/or modify
8 * it under the terms of the GNU Affero General Public License as published by
9 * the Free Software Foundation; either version 3 of the License, or
10 * (at your option) any later version.
11 *
12 * This program is distributed in the hope that it will be useful,
13 * but WITHOUT ANY WARRANTY; without even the implied warranty of
14 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
15 * GNU Affero General Public License for more details.
16 *
17 * You should have received a copy of the GNU Affero General Public License
18 * along with this program. If not, see <http://www.gnu.org/licenses/>.
19 *
20 */
21
22#include <unistd.h>
23#include <stdio.h>
24#include <stdlib.h>
25#include <string.h>
26#include <getopt.h>
27#include <errno.h>
28#include <signal.h>
29
30#include <sys/types.h>
31#include <sys/socket.h>
32#include <netinet/in.h>
33#include <netinet/sctp.h>
34#include <arpa/inet.h>
35
36#include <osmocom/core/application.h>
37#include <osmocom/core/talloc.h>
38#include <osmocom/core/select.h>
39#include <osmocom/core/logging.h>
40#include <osmocom/core/socket.h>
41#include <osmocom/core/msgb.h>
42#include <osmocom/core/write_queue.h>
Harald Weltec3851222015-12-24 15:41:21 +010043#include <osmocom/netif/stream.h>
Neels Hofmeyrae937122016-02-29 09:32:00 +010044#include <osmocom/gsm/tlv.h>
45#include <osmocom/gsm/gsm48.h>
Daniel Willmann97374c02015-12-03 09:37:58 +010046
47#include <osmocom/vty/telnet_interface.h>
48#include <osmocom/vty/logging.h>
Harald Weltec3851222015-12-24 15:41:21 +010049#include <osmocom/vty/command.h>
Daniel Willmann97374c02015-12-03 09:37:58 +010050
51#include "hnb-test.h"
Daniel Willmanna1e202e2015-12-07 17:21:07 +010052#include "hnbap_common.h"
53#include "hnbap_ies_defs.h"
Harald Welteb66c5d02016-01-03 18:04:28 +010054#include "rua_msg_factory.h"
Harald Weltec3851222015-12-24 15:41:21 +010055#include "asn1helpers.h"
Neels Hofmeyr96979af2016-01-05 15:19:44 +010056#include <osmocom/ranap/iu_helpers.h>
Harald Welte87ffeb92015-12-25 15:34:22 +010057#include "test_common.h"
Harald Weltec3851222015-12-24 15:41:21 +010058
Neels Hofmeyr96979af2016-01-05 15:19:44 +010059#include <osmocom/ranap/ranap_msg_factory.h>
Daniel Willmann97374c02015-12-03 09:37:58 +010060
Neels Hofmeyr0968a582016-01-11 15:19:38 +010061#include <osmocom/rua/RUA_RUA-PDU.h>
62
Neels Hofmeyr860a1292016-02-18 23:03:15 +010063#include <osmocom/gsm/protocol/gsm_04_08.h>
64
65#include <osmocom/ranap/RANAP_ProcedureCode.h>
66#include <osmocom/ranap/RANAP_Criticality.h>
67#include <osmocom/ranap/RANAP_DirectTransfer.h>
68
Daniel Willmann97374c02015-12-03 09:37:58 +010069static void *tall_hnb_ctx;
Daniel Willmann97374c02015-12-03 09:37:58 +010070
71struct hnb_test g_hnb_test = {
Neels Hofmeyr5f9be1e2016-02-29 13:33:44 +010072 .gw_addr = "127.0.0.1",
Daniel Willmann97374c02015-12-03 09:37:58 +010073 .gw_port = IUH_DEFAULT_SCTP_PORT,
74};
75
Harald Weltec3851222015-12-24 15:41:21 +010076struct msgb *rua_new_udt(struct msgb *inmsg);
77
Harald Weltec3851222015-12-24 15:41:21 +010078static int hnb_test_ue_de_register_tx(struct hnb_test *hnb_test)
Daniel Willmann19dedbb2015-12-17 11:57:41 +010079{
80 struct msgb *msg;
81 int rc, imsi_len;
82 uint32_t ctx_id;
83
84 UEDe_Register_t dereg;
85 UEDe_RegisterIEs_t dereg_ies;
86 memset(&dereg_ies, 0, sizeof(dereg_ies));
87
88 asn1_u24_to_bitstring(&dereg_ies.context_ID, &ctx_id, hnb_test->ctx_id);
89 dereg_ies.cause.present = Cause_PR_radioNetwork;
90 dereg_ies.cause.choice.radioNetwork = CauseRadioNetwork_connection_with_UE_lost;
91
92 memset(&dereg, 0, sizeof(dereg));
93 rc = hnbap_encode_uede_registeries(&dereg, &dereg_ies);
94
95 msg = hnbap_generate_initiating_message(ProcedureCode_id_UEDe_Register,
96 Criticality_ignore,
97 &asn_DEF_UEDe_Register,
98 &dereg);
99
Harald Weltec3851222015-12-24 15:41:21 +0100100 ASN_STRUCT_FREE_CONTENTS_ONLY(asn_DEF_UEDe_Register, &dereg);
Daniel Willmann19dedbb2015-12-17 11:57:41 +0100101
Harald Weltec3851222015-12-24 15:41:21 +0100102 msgb_sctp_ppid(msg) = IUH_PPI_HNBAP;
Daniel Willmann19dedbb2015-12-17 11:57:41 +0100103
104 return osmo_wqueue_enqueue(&hnb_test->wqueue, msg);
105}
106
Harald Weltec3851222015-12-24 15:41:21 +0100107static int hnb_test_ue_register_tx(struct hnb_test *hnb_test, const char *imsi_str)
Daniel Willmann479cb302015-12-09 17:54:59 +0100108{
Daniel Willmann4e312502015-12-09 17:59:24 +0100109 struct msgb *msg;
110 int rc, imsi_len;
111
112 char imsi_buf[16];
Daniel Willmann141a0ba2015-12-17 18:03:52 +0100113
Daniel Willmann4e312502015-12-09 17:59:24 +0100114 UERegisterRequest_t request_out;
115 UERegisterRequestIEs_t request;
116 memset(&request, 0, sizeof(request));
117
118 request.uE_Identity.present = UE_Identity_PR_iMSI;
119
Harald Welte056984f2016-01-03 16:31:31 +0100120 imsi_len = ranap_imsi_encode(imsi_buf, sizeof(imsi_buf), imsi_str);
Harald Weltec3851222015-12-24 15:41:21 +0100121 OCTET_STRING_fromBuf(&request.uE_Identity.choice.iMSI, imsi_buf, imsi_len);
Daniel Willmann4e312502015-12-09 17:59:24 +0100122
123 request.registration_Cause = Registration_Cause_normal;
124 request.uE_Capabilities.access_stratum_release_indicator = Access_stratum_release_indicator_rel_6;
125 request.uE_Capabilities.csg_capability = CSG_Capability_not_csg_capable;
126
127 memset(&request_out, 0, sizeof(request_out));
128 rc = hnbap_encode_ueregisterrequesties(&request_out, &request);
129
130 msg = hnbap_generate_initiating_message(ProcedureCode_id_UERegister,
131 Criticality_reject,
132 &asn_DEF_UERegisterRequest,
133 &request_out);
134
Harald Weltec3851222015-12-24 15:41:21 +0100135 ASN_STRUCT_FREE_CONTENTS_ONLY(asn_DEF_UERegisterRequest, &request_out);
Daniel Willmann4e312502015-12-09 17:59:24 +0100136
Harald Weltec3851222015-12-24 15:41:21 +0100137 msgb_sctp_ppid(msg) = IUH_PPI_HNBAP;
Daniel Willmann4e312502015-12-09 17:59:24 +0100138
139 return osmo_wqueue_enqueue(&hnb_test->wqueue, msg);
Daniel Willmann479cb302015-12-09 17:54:59 +0100140}
141
Harald Weltec3851222015-12-24 15:41:21 +0100142static int hnb_test_rx_hnb_register_acc(struct hnb_test *hnb, ANY_t *in)
Daniel Willmann479cb302015-12-09 17:54:59 +0100143{
144 int rc;
145 HNBRegisterAcceptIEs_t accept;
146
147 rc = hnbap_decode_hnbregisteraccepties(&accept, in);
148 if (rc < 0) {
149 }
150
151 hnb->rnc_id = accept.rnc_id;
152 printf("HNB Register accept with RNC ID %u\n", hnb->rnc_id);
153
Daniel Willmann11e912a2016-01-07 13:19:30 +0100154 hnbap_free_hnbregisteraccepties(&accept);
Harald Weltec3851222015-12-24 15:41:21 +0100155 return 0;
Daniel Willmann479cb302015-12-09 17:54:59 +0100156}
157
Harald Weltec3851222015-12-24 15:41:21 +0100158static int hnb_test_rx_ue_register_acc(struct hnb_test *hnb, ANY_t *in)
Daniel Willmanna7b02402015-12-09 19:05:09 +0100159{
160 int rc;
161 uint32_t ctx_id;
162 UERegisterAcceptIEs_t accept;
163 char imsi[16];
164
165 rc = hnbap_decode_ueregisteraccepties(&accept, in);
166 if (rc < 0) {
167 return rc;
168 }
169
170 if (accept.uE_Identity.present != UE_Identity_PR_iMSI) {
171 printf("Wrong type in UE register accept\n");
172 return -1;
173 }
174
175 ctx_id = asn1bitstr_to_u24(&accept.context_ID);
176
Harald Welte056984f2016-01-03 16:31:31 +0100177 ranap_bcd_decode(imsi, sizeof(imsi), accept.uE_Identity.choice.iMSI.buf,
Daniel Willmanna7b02402015-12-09 19:05:09 +0100178 accept.uE_Identity.choice.iMSI.size);
179 printf("UE Register accept for IMSI %s, context %u\n", imsi, ctx_id);
180
Daniel Willmann19dedbb2015-12-17 11:57:41 +0100181 hnb->ctx_id = ctx_id;
Daniel Willmann11e912a2016-01-07 13:19:30 +0100182 hnbap_free_ueregisteraccepties(&accept);
Daniel Willmann19dedbb2015-12-17 11:57:41 +0100183
Daniel Willmanna7b02402015-12-09 19:05:09 +0100184 return 0;
185}
186
Neels Hofmeyr860a1292016-02-18 23:03:15 +0100187static struct msgb *gen_nas_id_resp()
188{
189 uint8_t id_resp[] = {
Neels Hofmeyr5c1cc8c2016-02-29 09:28:48 +0100190 GSM48_PDISC_MM,
191 GSM48_MT_MM_ID_RESP,
Neels Hofmeyr860a1292016-02-18 23:03:15 +0100192 /* IMEISV */
193 0x09, /* len */
194 0x03, /* first digit (0000) + even (0) + id IMEISV (011) */
195 0x31, 0x91, 0x06, 0x00, 0x28, 0x47, 0x11, /* digits */
196 0xf2, /* filler (1111) + last digit (0010) */
197 };
198
Neels Hofmeyre1f709f2016-02-28 00:50:45 +0100199 return ranap_new_msg_dt(0, id_resp, sizeof(id_resp));
Neels Hofmeyr860a1292016-02-18 23:03:15 +0100200}
201
Neels Hofmeyrae937122016-02-29 09:32:00 +0100202static struct msgb *gen_nas_tmsi_realloc_compl()
203{
204 uint8_t id_resp[] = {
205 GSM48_PDISC_MM,
206 GSM48_MT_MM_TMSI_REALL_COMPL,
207 };
208
209 return ranap_new_msg_dt(0, id_resp, sizeof(id_resp));
210}
211
Neels Hofmeyr35888102016-03-09 01:39:56 +0100212static struct msgb *gen_nas_auth_resp()
213{
214 uint8_t id_resp[] = {
215 GSM48_PDISC_MM,
216 GSM48_MT_MM_AUTH_RESP,
217 0x61, 0xb5, 0x69, 0xf5 /* hardcoded SRES */
218 };
219
220 return ranap_new_msg_dt(0, id_resp, sizeof(id_resp));
221}
222
Neels Hofmeyrae937122016-02-29 09:32:00 +0100223static int hnb_test_nas_tx_dt(struct hnb_test *hnb, struct msgb *txm)
Neels Hofmeyr860a1292016-02-18 23:03:15 +0100224{
225 struct hnbtest_chan *chan;
Neels Hofmeyrae937122016-02-29 09:32:00 +0100226 struct msgb *rua;
Neels Hofmeyr860a1292016-02-18 23:03:15 +0100227
228 chan = hnb->cs.chan;
229 if (!chan) {
Neels Hofmeyrae937122016-02-29 09:32:00 +0100230 printf("hnb_test_nas_tx_tmsi_realloc_compl(): No CS channel established yet.\n");
Neels Hofmeyr860a1292016-02-18 23:03:15 +0100231 return -1;
232 }
233
Neels Hofmeyr860a1292016-02-18 23:03:15 +0100234 rua = rua_new_dt(chan->is_ps, chan->conn_id, txm);
Neels Hofmeyr860a1292016-02-18 23:03:15 +0100235 osmo_wqueue_enqueue(&g_hnb_test.wqueue, rua);
Neels Hofmeyr860a1292016-02-18 23:03:15 +0100236 return 0;
237}
238
Neels Hofmeyrd4598fa2016-03-09 01:37:40 +0100239static struct tlv_parsed *parse_mm(struct msgb *rxm)
240{
241 static struct tlv_parsed tp;
242 struct gsm48_hdr *gh;
243 int parse_res;
244 int length = msgb_l3len(rxm);
245
246 if (length < sizeof(*gh)) {
247 printf("GSM48 header does not fit.\n");
248 return NULL;
249 }
250
251 gh = (struct gsm48_hdr *) msgb_l3(rxm);
252 length -= (const char *)&gh->data[0] - (const char *)gh;
253
254 parse_res = tlv_parse(&tp, &gsm48_mm_att_tlvdef, &gh->data[0], length, 0, 0);
255 if (parse_res <= 0) {
256 uint8_t msg_type = gh->msg_type & 0xbf;
257 printf("Error parsing MM message 0x%hhx: %d\n", msg_type, parse_res);
258 return NULL;
259 }
260
261 return &tp;
262}
263
Neels Hofmeyrc04eb532016-03-04 12:38:43 +0100264int hnb_test_nas_rx_lu_accept(struct msgb *rxm, int *sent_tmsi)
Neels Hofmeyrae937122016-02-29 09:32:00 +0100265{
266 printf(" :D Location Update Accept :D\n");
267 struct gsm48_hdr *gh;
268 struct gsm48_loc_area_id *lai;
Neels Hofmeyrc04eb532016-03-04 12:38:43 +0100269 int length = msgb_l3len(rxm);
270
271 if (length < sizeof(*gh)) {
272 printf("GSM48 header does not fit.\n");
273 return -1;
274 }
275
Neels Hofmeyrae937122016-02-29 09:32:00 +0100276 gh = (struct gsm48_hdr *)msgb_l3(rxm);
277 lai = (struct gsm48_loc_area_id *)&gh->data[0];
278
279 uint16_t mcc, mnc, lac;
280 gsm48_decode_lai(lai, &mcc, &mnc, &lac);
281 printf("LU: mcc %hd mnc %hd lac %hd\n",
282 mcc, mnc, lac);
283
Neels Hofmeyrc04eb532016-03-04 12:38:43 +0100284 struct tlv_parsed tp;
285 int parse_res;
286
287 length -= (const char *)&gh->data[0] - (const char *)gh;
288 parse_res = tlv_parse(&tp, &gsm48_mm_att_tlvdef, &gh->data[0], length, 0, 0);
289 if (parse_res <= 0) {
290 printf("Error parsing Location Update Accept message: %d\n", parse_res);
291 return -1;
292 }
293
294 if (TLVP_PRESENT(&tp, GSM48_IE_MOBILE_ID)) {
295 uint8_t type = TLVP_VAL(&tp, GSM48_IE_NAME_SHORT)[0] & 0x0f;
296 if (type == GSM_MI_TYPE_TMSI)
297 *sent_tmsi = 1;
298 else *sent_tmsi = 0;
299 }
300 return 0;
Neels Hofmeyrae937122016-02-29 09:32:00 +0100301}
302
303void hnb_test_nas_rx_mm_info(struct msgb *rxm)
304{
305 printf(" :) MM Info :)\n");
Neels Hofmeyrd4598fa2016-03-09 01:37:40 +0100306 struct tlv_parsed *tp = parse_mm(rxm);
307 if (!tp)
Neels Hofmeyrae937122016-02-29 09:32:00 +0100308 return;
Neels Hofmeyrae937122016-02-29 09:32:00 +0100309
Neels Hofmeyrd4598fa2016-03-09 01:37:40 +0100310 if (TLVP_PRESENT(tp, GSM48_IE_NAME_SHORT)) {
Neels Hofmeyrae937122016-02-29 09:32:00 +0100311 char name[128] = {0};
312 gsm_7bit_decode_n(name, 127,
Neels Hofmeyrd4598fa2016-03-09 01:37:40 +0100313 TLVP_VAL(tp, GSM48_IE_NAME_SHORT)+1,
314 (TLVP_LEN(tp, GSM48_IE_NAME_SHORT)-1)*8/7);
Neels Hofmeyrae937122016-02-29 09:32:00 +0100315 printf("Info: Short Network Name: %s\n", name);
316 }
317
Neels Hofmeyrd4598fa2016-03-09 01:37:40 +0100318 if (TLVP_PRESENT(tp, GSM48_IE_NAME_LONG)) {
Neels Hofmeyrae937122016-02-29 09:32:00 +0100319 char name[128] = {0};
320 gsm_7bit_decode_n(name, 127,
Neels Hofmeyrd4598fa2016-03-09 01:37:40 +0100321 TLVP_VAL(tp, GSM48_IE_NAME_LONG)+1,
322 (TLVP_LEN(tp, GSM48_IE_NAME_LONG)-1)*8/7);
Neels Hofmeyrae937122016-02-29 09:32:00 +0100323 printf("Info: Long Network Name: %s\n", name);
324 }
Neels Hofmeyrae937122016-02-29 09:32:00 +0100325}
326
Neels Hofmeyr35888102016-03-09 01:39:56 +0100327static void hnb_test_nas_rx_auth_req(struct msgb *rxm)
328{
329 struct gsm48_hdr *gh;
330 struct gsm48_auth_req *ar;
331 int parse_res;
332 int length = msgb_l3len(rxm);
333
334 if (length < sizeof(*gh)) {
335 printf("GSM48 header does not fit.\n");
336 return;
337 }
338
339 gh = (struct gsm48_hdr *) msgb_l3(rxm);
340 length -= (const char *)&gh->data[0] - (const char *)gh;
341
342 if (length < sizeof(*ar)) {
343 printf("GSM48 Auth Req does not fit.\n");
344 return;
345 }
346
347 printf(" :) Authentication Request :)\n");
348
349 ar = (struct gsm48_auth_req*) &gh->data[0];
350 int seq = ar->key_seq;
351 printf("seq %d rand %s\n", seq, osmo_hexdump(ar->rand, sizeof(ar->rand)));
352}
353
Neels Hofmeyr860a1292016-02-18 23:03:15 +0100354static int hnb_test_nas_rx_mm(struct hnb_test *hnb, struct msgb *rxm)
355{
356 struct hnbtest_chan *chan;
357
358 chan = hnb->cs.chan;
359 if (!chan) {
360 printf("hnb_test_nas_rx_mm(): No CS channel established yet.\n");
361 return -1;
362 }
363
364 OSMO_ASSERT(!chan->is_ps);
365
366 struct gsm48_hdr *gh = msgb_l3(rxm);
367 uint8_t msg_type = gh->msg_type & 0xbf;
Neels Hofmeyrc04eb532016-03-04 12:38:43 +0100368 int sent_tmsi;
Neels Hofmeyr860a1292016-02-18 23:03:15 +0100369
370 switch (msg_type) {
371 case GSM48_MT_MM_ID_REQ:
Neels Hofmeyrae937122016-02-29 09:32:00 +0100372 return hnb_test_nas_tx_dt(hnb, gen_nas_id_resp());
Neels Hofmeyr860a1292016-02-18 23:03:15 +0100373
Neels Hofmeyrae937122016-02-29 09:32:00 +0100374 case GSM48_MT_MM_LOC_UPD_ACCEPT:
Neels Hofmeyrc04eb532016-03-04 12:38:43 +0100375 if (hnb_test_nas_rx_lu_accept(rxm, &sent_tmsi))
376 return -1;
377 if (sent_tmsi)
378 return hnb_test_nas_tx_dt(hnb, gen_nas_tmsi_realloc_compl());
379 else
380 return 0;
Neels Hofmeyrae937122016-02-29 09:32:00 +0100381
Neels Hofmeyr5dbb7b22016-03-09 01:38:13 +0100382 case GSM48_MT_MM_LOC_UPD_REJECT:
383 printf("Received Location Update Reject\n");
384 return 0;
385
Neels Hofmeyrae937122016-02-29 09:32:00 +0100386 case GSM48_MT_MM_INFO:
387 hnb_test_nas_rx_mm_info(rxm);
388 return 0;
389
Neels Hofmeyr35888102016-03-09 01:39:56 +0100390 case GSM48_MT_MM_AUTH_REQ:
391 hnb_test_nas_rx_auth_req(rxm);
392 return hnb_test_nas_tx_dt(hnb, gen_nas_auth_resp());
393
Neels Hofmeyr860a1292016-02-18 23:03:15 +0100394 default:
Neels Hofmeyrae937122016-02-29 09:32:00 +0100395 printf("04.08 message type not handled by hnb-test: 0x%x\n",
Neels Hofmeyr860a1292016-02-18 23:03:15 +0100396 msg_type);
397 return 0;
398 }
399
400}
401
402static int hnb_test_nas_rx_dtap(struct hnb_test *hnb, struct msgb *msg)
403{
404 printf("got %s\n", osmo_hexdump(msg->data, msg->len));
405
406 // nas_pdu == '05 08 12' ==> IMEI Identity request
407 // '05 04 0d' ==> LU reject
408
409 struct gsm48_hdr *gh = msgb_l3(msg);
410 uint8_t pdisc = gh->proto_discr & 0x0f;
411
412 switch (pdisc) {
413 case GSM48_PDISC_MM:
414 return hnb_test_nas_rx_mm(hnb, msg);
415 default:
416 printf("04.08 discriminator not handled by hnb-test: %d\n",
417 pdisc);
418 return 0;
419 }
420
421
422}
423
Daniel Willmann479cb302015-12-09 17:54:59 +0100424int hnb_test_hnbap_rx(struct hnb_test *hnb, struct msgb *msg)
425{
426 HNBAP_PDU_t _pdu, *pdu = &_pdu;
427 asn_dec_rval_t dec_ret;
428 int rc;
429
430 memset(pdu, 0, sizeof(*pdu));
431 dec_ret = aper_decode(NULL, &asn_DEF_HNBAP_PDU, (void **) &pdu,
432 msg->data, msgb_length(msg), 0, 0);
433 if (dec_ret.code != RC_OK) {
434 LOGP(DMAIN, LOGL_ERROR, "Error in ASN.1 decode\n");
435 return rc;
436 }
437
438 if (pdu->present != HNBAP_PDU_PR_successfulOutcome) {
439 printf("Unexpected HNBAP message received\n");
440 }
441
442 switch (pdu->choice.successfulOutcome.procedureCode) {
443 case ProcedureCode_id_HNBRegister:
444 /* Get HNB id and send UE Register request */
445 rc = hnb_test_rx_hnb_register_acc(hnb, &pdu->choice.successfulOutcome.value);
446 break;
447 case ProcedureCode_id_UERegister:
Daniel Willmanna7b02402015-12-09 19:05:09 +0100448 rc = hnb_test_rx_ue_register_acc(hnb, &pdu->choice.successfulOutcome.value);
Daniel Willmann479cb302015-12-09 17:54:59 +0100449 break;
450 default:
451 break;
452 }
453
454 return rc;
455}
456
Neels Hofmeyrb984f362016-02-18 01:18:20 +0100457extern void direct_transfer_nas_pdu_print(ANY_t *in);
458
Neels Hofmeyr0968a582016-01-11 15:19:38 +0100459int hnb_test_rua_rx(struct hnb_test *hnb, struct msgb *msg)
460{
461 RUA_RUA_PDU_t _pdu, *pdu = &_pdu;
462 asn_dec_rval_t dec_ret;
463 int rc;
464
465 memset(pdu, 0, sizeof(*pdu));
466 dec_ret = aper_decode(NULL, &asn_DEF_RUA_RUA_PDU, (void **) &pdu,
467 msg->data, msgb_length(msg), 0, 0);
468 if (dec_ret.code != RC_OK) {
469 LOGP(DMAIN, LOGL_ERROR, "Error in ASN.1 decode\n");
470 return rc;
471 }
472
473 switch (pdu->present) {
474 case RUA_RUA_PDU_PR_successfulOutcome:
475 printf("RUA_RUA_PDU_PR_successfulOutcome\n");
476 break;
477 case RUA_RUA_PDU_PR_initiatingMessage:
478 printf("RUA_RUA_PDU_PR_initiatingMessage\n");
479 break;
480 case RUA_RUA_PDU_PR_NOTHING:
481 printf("RUA_RUA_PDU_PR_NOTHING\n");
482 break;
483 case RUA_RUA_PDU_PR_unsuccessfulOutcome:
484 printf("RUA_RUA_PDU_PR_unsuccessfulOutcome\n");
485 break;
486 default:
487 printf("Unexpected RUA message received\n");
488 break;
489 }
490
491 switch (pdu->choice.successfulOutcome.procedureCode) {
492 case RUA_ProcedureCode_id_ConnectionlessTransfer:
493 printf("RUA rx Connectionless Transfer\n");
494 break;
495 case RUA_ProcedureCode_id_Connect:
496 printf("RUA rx Connect\n");
497 break;
498 case RUA_ProcedureCode_id_DirectTransfer:
499 printf("RUA rx DirectTransfer\n");
Neels Hofmeyrb984f362016-02-18 01:18:20 +0100500 {
501 struct msgb *m = msgb_alloc(1500, "direct_transfer_nas_pdu");
502 direct_transfer_nas_pdu_get(&pdu->choice.successfulOutcome.value, m);
503
Neels Hofmeyr860a1292016-02-18 23:03:15 +0100504 hnb_test_nas_rx_dtap(hnb, m);
Neels Hofmeyrb984f362016-02-18 01:18:20 +0100505
Neels Hofmeyrb984f362016-02-18 01:18:20 +0100506 msgb_free(m);
507 }
Neels Hofmeyr0968a582016-01-11 15:19:38 +0100508 break;
509 case RUA_ProcedureCode_id_Disconnect:
510 printf("RUA rx Disconnect\n");
511 break;
512 case RUA_ProcedureCode_id_ErrorIndication:
513 printf("RUA rx ErrorIndication\n");
514 break;
515 case RUA_ProcedureCode_id_privateMessage:
516 printf("RUA rx privateMessage\n");
517 break;
518 default:
519 printf("RUA rx unknown message\n");
520 break;
521 }
522
523 return rc;
524}
525
Daniel Willmann97374c02015-12-03 09:37:58 +0100526static int hnb_read_cb(struct osmo_fd *fd)
527{
528 struct hnb_test *hnb_test = fd->data;
529 struct sctp_sndrcvinfo sinfo;
530 struct msgb *msg = msgb_alloc(IUH_MSGB_SIZE, "Iuh rx");
531 int flags = 0;
532 int rc;
533
534 if (!msg)
535 return -ENOMEM;
536
537 rc = sctp_recvmsg(fd->fd, msgb_data(msg), msgb_tailroom(msg),
538 NULL, NULL, &sinfo, &flags);
539 if (rc < 0) {
540 LOGP(DMAIN, LOGL_ERROR, "Error during sctp_recvmsg()\n");
541 /* FIXME: clean up after disappeared HNB */
Daniel Willmann6637a282015-12-17 14:47:51 +0100542 close(fd->fd);
543 osmo_fd_unregister(fd);
Daniel Willmann97374c02015-12-03 09:37:58 +0100544 return rc;
Daniel Willmann6637a282015-12-17 14:47:51 +0100545 } else if (rc == 0) {
546 LOGP(DMAIN, LOGL_INFO, "Connection to HNB closed\n");
547 close(fd->fd);
548 osmo_fd_unregister(fd);
549 fd->fd = -1;
550
551 return -1;
552 } else {
Daniel Willmann97374c02015-12-03 09:37:58 +0100553 msgb_put(msg, rc);
Daniel Willmann6637a282015-12-17 14:47:51 +0100554 }
Daniel Willmann97374c02015-12-03 09:37:58 +0100555
556 if (flags & MSG_NOTIFICATION) {
Daniel Willmann32797802015-12-17 12:53:05 +0100557 LOGP(DMAIN, LOGL_DEBUG, "Ignoring SCTP notification\n");
Daniel Willmann97374c02015-12-03 09:37:58 +0100558 msgb_free(msg);
559 return 0;
560 }
561
562 sinfo.sinfo_ppid = ntohl(sinfo.sinfo_ppid);
563
564 switch (sinfo.sinfo_ppid) {
565 case IUH_PPI_HNBAP:
Neels Hofmeyr0968a582016-01-11 15:19:38 +0100566 printf("HNBAP message received\n");
Daniel Willmann479cb302015-12-09 17:54:59 +0100567 rc = hnb_test_hnbap_rx(hnb_test, msg);
Daniel Willmann97374c02015-12-03 09:37:58 +0100568 break;
569 case IUH_PPI_RUA:
Neels Hofmeyr0968a582016-01-11 15:19:38 +0100570 printf("RUA message received\n");
571 rc = hnb_test_rua_rx(hnb_test, msg);
Daniel Willmann97374c02015-12-03 09:37:58 +0100572 break;
573 case IUH_PPI_SABP:
574 case IUH_PPI_RNA:
575 case IUH_PPI_PUA:
576 LOGP(DMAIN, LOGL_ERROR, "Unimplemented SCTP PPID=%u received\n",
577 sinfo.sinfo_ppid);
578 rc = 0;
579 break;
580 default:
581 LOGP(DMAIN, LOGL_ERROR, "Unknown SCTP PPID=%u received\n",
582 sinfo.sinfo_ppid);
583 rc = 0;
584 break;
585 }
586
587 msgb_free(msg);
588 return rc;
589}
590
591static int hnb_write_cb(struct osmo_fd *fd, struct msgb *msg)
592{
593 struct hnb_test *ctx = fd->data;
594 struct sctp_sndrcvinfo sinfo = {
Harald Weltec3851222015-12-24 15:41:21 +0100595 .sinfo_ppid = htonl(msgb_sctp_ppid(msg)),
Daniel Willmann97374c02015-12-03 09:37:58 +0100596 .sinfo_stream = 0,
597 };
598 int rc;
599
600 rc = sctp_send(fd->fd, msgb_data(msg), msgb_length(msg),
601 &sinfo, 0);
602 /* we don't need to msgb_free(), write_queue does this for us */
603 return rc;
604}
605
Daniel Willmann4aeef6c2015-12-03 17:02:13 +0100606static void hnb_send_register_req(struct hnb_test *hnb_test)
607{
Daniel Willmanna1e202e2015-12-07 17:21:07 +0100608 HNBRegisterRequest_t request_out;
Daniel Willmann4aeef6c2015-12-03 17:02:13 +0100609 struct msgb *msg;
610 int rc;
Daniel Willmanna1e202e2015-12-07 17:21:07 +0100611 uint16_t lac, sac;
612 uint8_t rac;
613 uint32_t cid;
614 uint8_t plmn[] = {0x09, 0xf1, 0x99};
615 char identity[50] = "ATestHNB@";
Daniel Willmann4aeef6c2015-12-03 17:02:13 +0100616
Daniel Willmanna1e202e2015-12-07 17:21:07 +0100617 HNBRegisterRequestIEs_t request;
618 memset(&request, 0, sizeof(request));
Daniel Willmann4aeef6c2015-12-03 17:02:13 +0100619
Daniel Willmanna1e202e2015-12-07 17:21:07 +0100620 lac = 0xc0fe;
621 sac = 0xabab;
622 rac = 0x42;
Daniel Willmannd6a45b42015-12-08 13:55:17 +0100623 cid = 0xadceaab;
Daniel Willmann4aeef6c2015-12-03 17:02:13 +0100624
Daniel Willmanna1e202e2015-12-07 17:21:07 +0100625 asn1_u16_to_str(&request.lac, &lac, lac);
626 asn1_u16_to_str(&request.sac, &sac, sac);
627 asn1_u8_to_str(&request.rac, &rac, rac);
Daniel Willmannd6a45b42015-12-08 13:55:17 +0100628 asn1_u28_to_bitstring(&request.cellIdentity, &cid, cid);
Daniel Willmanna1e202e2015-12-07 17:21:07 +0100629
630 request.hnB_Identity.hNB_Identity_Info.buf = identity;
631 request.hnB_Identity.hNB_Identity_Info.size = strlen(identity);
632
633 request.plmNidentity.buf = plmn;
634 request.plmNidentity.size = 3;
635
636
637
638 memset(&request_out, 0, sizeof(request_out));
639 rc = hnbap_encode_hnbregisterrequesties(&request_out, &request);
640 if (rc < 0) {
641 printf("Could not encode HNB register request IEs\n");
642 }
643
644 msg = hnbap_generate_initiating_message(ProcedureCode_id_HNBRegister,
645 Criticality_reject,
646 &asn_DEF_HNBRegisterRequest,
647 &request_out);
648
Daniel Willmann4aeef6c2015-12-03 17:02:13 +0100649
Harald Weltec3851222015-12-24 15:41:21 +0100650 msgb_sctp_ppid(msg) = IUH_PPI_HNBAP;
651
652 osmo_wqueue_enqueue(&hnb_test->wqueue, msg);
653}
654
655static void hnb_send_deregister_req(struct hnb_test *hnb_test)
656{
657 struct msgb *msg;
658 int rc;
659
660 HNBDe_RegisterIEs_t request;
661 memset(&request, 0, sizeof(request));
662
663 request.cause.present = Cause_PR_misc;
664 request.cause.choice.misc = CauseMisc_o_and_m_intervention;
665
666 HNBDe_Register_t request_out;
667 memset(&request_out, 0, sizeof(request_out));
668 rc = hnbap_encode_hnbde_registeries(&request_out, &request);
669 if (rc < 0) {
670 printf("Could not encode HNB deregister request IEs\n");
671 }
672
673 msg = hnbap_generate_initiating_message(ProcedureCode_id_HNBDe_Register,
674 Criticality_reject,
675 &asn_DEF_HNBDe_Register,
676 &request_out);
677
678 msgb_sctp_ppid(msg) = IUH_PPI_HNBAP;
Daniel Willmann4aeef6c2015-12-03 17:02:13 +0100679
680 osmo_wqueue_enqueue(&hnb_test->wqueue, msg);
681}
682
683
Daniel Willmann97374c02015-12-03 09:37:58 +0100684static const struct log_info_cat log_cat[] = {
685 [DMAIN] = {
Daniel Willmann32797802015-12-17 12:53:05 +0100686 .name = "DMAIN", .loglevel = LOGL_INFO, .enabled = 1,
Daniel Willmann97374c02015-12-03 09:37:58 +0100687 .color = "",
688 .description = "Main program",
689 },
Daniel Willmann32797802015-12-17 12:53:05 +0100690 [DHNBAP] = {
691 .name = "DHNBAP", .loglevel = LOGL_DEBUG, .enabled = 1,
692 .color = "",
693 .description = "Home Node B Application Part",
694 },
Daniel Willmann97374c02015-12-03 09:37:58 +0100695};
696
697static const struct log_info hnb_test_log_info = {
698 .cat = log_cat,
699 .num_cat = ARRAY_SIZE(log_cat),
700};
701
702static struct vty_app_info vty_info = {
703 .name = "OsmoHNB-Test",
704 .version = "0",
705};
706
Daniel Willmann4abdee02015-12-09 17:57:32 +0100707static int sctp_sock_init(int fd)
708{
709 struct sctp_event_subscribe event;
710 int rc;
711
712 /* subscribe for all events */
713 memset((uint8_t *)&event, 1, sizeof(event));
714 rc = setsockopt(fd, IPPROTO_SCTP, SCTP_EVENTS,
715 &event, sizeof(event));
716
717 return rc;
718}
719
Harald Weltec3851222015-12-24 15:41:21 +0100720#define HNBAP_STR "HNBAP related commands\n"
721#define HNB_STR "HomeNodeB commands\n"
722#define UE_STR "User Equipment commands\n"
723#define RANAP_STR "RANAP related commands\n"
724#define CSPS_STR "Circuit Switched\n" "Packet Switched\n"
725
726DEFUN(hnb_register, hnb_register_cmd,
727 "hnbap hnb register", HNBAP_STR HNB_STR "Send HNB-REGISTER REQUEST")
728{
729 hnb_send_register_req(&g_hnb_test);
730
731 return CMD_SUCCESS;
732}
733
734DEFUN(hnb_deregister, hnb_deregister_cmd,
735 "hnbap hnb deregister", HNBAP_STR HNB_STR "Send HNB-DEREGISTER REQUEST")
736{
737 hnb_send_deregister_req(&g_hnb_test);
738
739 return CMD_SUCCESS;
740}
741
742DEFUN(ue_register, ue_register_cmd,
743 "hnbap ue register IMSI", HNBAP_STR UE_STR "Send UE-REGISTER REQUEST")
744{
745 hnb_test_ue_register_tx(&g_hnb_test, argv[0]);
746
747 return CMD_SUCCESS;
748}
749
750DEFUN(asn_dbg, asn_dbg_cmd,
751 "asn-debug (1|0)", "Enable or disabel libasn1c debugging")
752{
753 asn_debug = atoi(argv[0]);
754
755 return CMD_SUCCESS;
756}
757
758DEFUN(ranap_reset, ranap_reset_cmd,
759 "ranap reset (cs|ps)", RANAP_STR "Send RANAP RESET\n" CSPS_STR)
760{
761 int is_ps = 0;
762 struct msgb *msg, *rua;
763
764 RANAP_Cause_t cause = {
765 .present = RANAP_Cause_PR_transmissionNetwork,
766 .choice.transmissionNetwork = RANAP_CauseTransmissionNetwork_signalling_transport_resource_failure,
767 };
768
769 if (!strcmp(argv[0], "ps"))
770 is_ps = 1;
771
772 msg = ranap_new_msg_reset(is_ps, &cause);
773 rua = rua_new_udt(msg);
774 //msgb_free(msg);
775 osmo_wqueue_enqueue(&g_hnb_test.wqueue, rua);
776
777 return CMD_SUCCESS;
778}
779
780
781enum my_vty_nodes {
782 CHAN_NODE = _LAST_OSMOVTY_NODE,
783};
784
785static struct cmd_node chan_node = {
786 CHAN_NODE,
787 "%s(chan)> ",
788 1,
789};
790
791
Harald Weltec3851222015-12-24 15:41:21 +0100792static struct msgb *gen_initue_lu(int is_ps, uint32_t conn_id, const char *imsi)
793{
Neels Hofmeyr5c1cc8c2016-02-29 09:28:48 +0100794 uint8_t lu[] = { GSM48_PDISC_MM, GSM48_MT_MM_LOC_UPD_REQUEST,
795 0x70, 0x62, 0xf2, 0x30, 0xff, 0xf3, 0x57,
Neels Hofmeyr32828702016-01-14 13:06:47 +0100796 /* len, IMSI/type, IMSI-------------------------------- */
Harald Weltec3851222015-12-24 15:41:21 +0100797 0x08, 0x29, 0x26, 0x24, 0x10, 0x32, 0x54, 0x76, 0x98,
798 0x33, 0x03, 0x57, 0x18 , 0xb2 };
799 uint8_t plmn_id[] = { 0x09, 0x01, 0x99 };
800 RANAP_GlobalRNC_ID_t rnc_id = {
801 .rNC_ID = 23,
802 .pLMNidentity.buf = plmn_id,
803 .pLMNidentity.size = sizeof(plmn_id),
804 };
Harald Weltec3851222015-12-24 15:41:21 +0100805
806 /* FIXME: patch imsi */
Neels Hofmeyr7b811282016-01-14 13:05:24 +0100807 /* Note: the Mobile Identitiy IE's IMSI data has the identity type and
808 * an even/odd indicator bit encoded in the first octet. So the first
809 * octet looks like this:
810 *
811 * 8 7 6 5 | 4 | 3 2 1
812 * IMSI-digit | even/odd | type
813 *
814 * followed by the remaining IMSI digits.
815 * If digit count is even (bit 4 == 0), that first high-nibble is 0xf.
816 * (derived from Iu pcap Location Update Request msg and TS 25.413)
817 *
818 * TODO I'm only 90% sure about this
819 */
Harald Weltec3851222015-12-24 15:41:21 +0100820
Neels Hofmeyr6a62e542016-01-15 03:07:45 +0100821 return ranap_new_msg_initial_ue(conn_id, is_ps, &rnc_id, lu, sizeof(lu));
Harald Weltec3851222015-12-24 15:41:21 +0100822}
823
824DEFUN(chan, chan_cmd,
825 "channel (cs|ps) lu imsi IMSI",
826 "Open a new Signalling Connection\n"
827 "To Circuit-Switched CN\n"
828 "To Packet-Switched CN\n"
829 "Performing a Location Update\n"
830 )
831{
832 struct hnbtest_chan *chan;
833 struct msgb *msg, *rua;
Daniel Willmann85927162016-01-14 15:36:49 +0100834 static uint16_t conn_id = 42;
Harald Weltec3851222015-12-24 15:41:21 +0100835
836 chan = talloc_zero(tall_hnb_ctx, struct hnbtest_chan);
837 if (!strcmp(argv[0], "ps"))
838 chan->is_ps = 1;
839 chan->imsi = talloc_strdup(chan, argv[1]);
Daniel Willmann85927162016-01-14 15:36:49 +0100840 chan->conn_id = conn_id;
841 conn_id++;
Harald Weltec3851222015-12-24 15:41:21 +0100842
843 msg = gen_initue_lu(chan->is_ps, chan->conn_id, chan->imsi);
844 rua = rua_new_conn(chan->is_ps, chan->conn_id, msg);
845
846 osmo_wqueue_enqueue(&g_hnb_test.wqueue, rua);
847
848 vty->index = chan;
849 vty->node = CHAN_NODE;
850
Neels Hofmeyr860a1292016-02-18 23:03:15 +0100851 if (!chan->is_ps)
852 g_hnb_test.cs.chan = chan;
853
854
Harald Weltec3851222015-12-24 15:41:21 +0100855 return CMD_SUCCESS;
856}
857
858static void hnbtest_vty_init(void)
859{
860 install_element_ve(&asn_dbg_cmd);
861 install_element_ve(&hnb_register_cmd);
862 install_element_ve(&hnb_deregister_cmd);
863 install_element_ve(&ue_register_cmd);
864 install_element_ve(&ranap_reset_cmd);
865 install_element_ve(&chan_cmd);
866
867 install_node(&chan_node, NULL);
868 vty_install_default(CHAN_NODE);
869}
870
Daniel Willmann141a0ba2015-12-17 18:03:52 +0100871static void handle_options(int argc, char **argv)
872{
873 while (1) {
874 int idx = 0, c;
875 static const struct option long_options[] = {
876 { "ues", 1, 0, 'u' },
Neels Hofmeyr5f9be1e2016-02-29 13:33:44 +0100877 { "gw-addr", 1, 0, 'g' },
Daniel Willmann141a0ba2015-12-17 18:03:52 +0100878 { 0, 0, 0, 0 },
879 };
880
Neels Hofmeyr5f9be1e2016-02-29 13:33:44 +0100881 c = getopt_long(argc, argv, "u:g:", long_options, &idx);
Daniel Willmann141a0ba2015-12-17 18:03:52 +0100882
883 if (c == -1)
884 break;
885
886 switch (c) {
887 case 'u':
888 g_hnb_test.ues = atoi(optarg);
889 break;
Neels Hofmeyr5f9be1e2016-02-29 13:33:44 +0100890 case 'g':
891 g_hnb_test.gw_addr = optarg;
892 break;
Daniel Willmann141a0ba2015-12-17 18:03:52 +0100893 }
894 }
895}
896
Harald Weltec3851222015-12-24 15:41:21 +0100897int main(int argc, char **argv)
Daniel Willmann97374c02015-12-03 09:37:58 +0100898{
899 int rc;
900
Harald Welte87ffeb92015-12-25 15:34:22 +0100901 test_common_init();
Daniel Willmann97374c02015-12-03 09:37:58 +0100902
Harald Welte87ffeb92015-12-25 15:34:22 +0100903 tall_hnb_ctx = talloc_named_const(NULL, 0, "hnb_context");
Daniel Willmann97374c02015-12-03 09:37:58 +0100904
905 vty_init(&vty_info);
Harald Weltec3851222015-12-24 15:41:21 +0100906 hnbtest_vty_init();
907
Neels Hofmeyra0d21472016-02-24 20:50:31 +0100908 printf("VTY at %s %d\n", vty_get_bind_addr(), 2324);
909 rc = telnet_init_dynif(NULL, NULL, vty_get_bind_addr(), 2324);
Harald Weltec3851222015-12-24 15:41:21 +0100910 if (rc < 0) {
911 perror("Error binding VTY port");
912 exit(1);
913 }
Daniel Willmann97374c02015-12-03 09:37:58 +0100914
Daniel Willmann141a0ba2015-12-17 18:03:52 +0100915 handle_options(argc, argv);
916
Daniel Willmann97374c02015-12-03 09:37:58 +0100917 osmo_wqueue_init(&g_hnb_test.wqueue, 16);
918 g_hnb_test.wqueue.bfd.data = &g_hnb_test;
919 g_hnb_test.wqueue.read_cb = hnb_read_cb;
920 g_hnb_test.wqueue.write_cb = hnb_write_cb;
921
922 rc = osmo_sock_init_ofd(&g_hnb_test.wqueue.bfd, AF_INET, SOCK_STREAM,
Neels Hofmeyr5f9be1e2016-02-29 13:33:44 +0100923 IPPROTO_SCTP, g_hnb_test.gw_addr,
Daniel Willmann97374c02015-12-03 09:37:58 +0100924 g_hnb_test.gw_port, OSMO_SOCK_F_CONNECT);
925 if (rc < 0) {
926 perror("Error connecting to Iuh port");
927 exit(1);
928 }
Daniel Willmann4abdee02015-12-09 17:57:32 +0100929 sctp_sock_init(g_hnb_test.wqueue.bfd.fd);
Daniel Willmann97374c02015-12-03 09:37:58 +0100930
Harald Weltec3851222015-12-24 15:41:21 +0100931#if 0
932 /* some hard-coded message generation. Doesn't make sense from
933 * a protocol point of view but enables to look at the encoded
934 * results in wireshark for manual verification */
935 {
936 struct msgb *msg, *rua;
937 const uint8_t nas[] = { 0, 1, 2, 3 };
938 const uint8_t ik[] = { 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15 };
939
940 msg = ranap_new_msg_dt(0, nas, sizeof(nas));
941 rua = rua_new_udt(msg);
942 osmo_wqueue_enqueue(&g_hnb_test.wqueue, rua);
943
944 msg = ranap_new_msg_sec_mod_cmd(ik, ik);
945 rua = rua_new_udt(msg);
946 osmo_wqueue_enqueue(&g_hnb_test.wqueue, rua);
947
948 msg = ranap_new_msg_iu_rel_cmd()
949 rua = rua_new_udt(msg);
950 osmo_wqueue_enqueue(&g_hnb_test.wqueue, rua);
951
952 msg = ranap_new_msg_paging_cmd("901990123456789", NULL, 0, 0);
953 rua = rua_new_udt(msg);
954 osmo_wqueue_enqueue(&g_hnb_test.wqueue, rua);
955
956 msg = ranap_new_msg_rab_assign_voice(1, 0x01020304, 0x1020);
957 rua = rua_new_udt(msg);
958 osmo_wqueue_enqueue(&g_hnb_test.wqueue, rua);
959
960 msg = ranap_new_msg_rab_assign_data(2, 0x01020304, 0x11223344);
961 rua = rua_new_udt(msg);
962 osmo_wqueue_enqueue(&g_hnb_test.wqueue, rua);
963 }
964#endif
Daniel Willmann4aeef6c2015-12-03 17:02:13 +0100965
Daniel Willmann97374c02015-12-03 09:37:58 +0100966 while (1) {
967 rc = osmo_select_main(0);
968 if (rc < 0)
969 exit(3);
970 }
971
972 /* not reached */
973 exit(0);
974}