blob: 69c80417f3e8f4cc7a7d11e6276e077eb854108f [file] [log] [blame]
Harald Welte9b455bf2010-03-14 15:45:01 +08001/* GPRS LLC protocol implementation as per 3GPP TS 04.64 */
2
Harald Weltea2665542010-05-02 09:28:11 +02003/* (C) 2009-2010 by Harald Welte <laforge@gnumonks.org>
Harald Welte9b455bf2010-03-14 15:45:01 +08004 *
5 * All Rights Reserved
6 *
7 * This program is free software; you can redistribute it and/or modify
8 * it under the terms of the GNU General Public License as published by
9 * the Free Software Foundation; either version 2 of the License, or
10 * (at your option) any later version.
11 *
12 * This program is distributed in the hope that it will be useful,
13 * but WITHOUT ANY WARRANTY; without even the implied warranty of
14 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
15 * GNU General Public License for more details.
16 *
17 * You should have received a copy of the GNU General Public License along
18 * with this program; if not, write to the Free Software Foundation, Inc.,
19 * 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
20 *
21 */
22
23#include <errno.h>
Harald Welteeaa614c2010-05-02 11:26:34 +020024#include <stdint.h>
Harald Welte9b455bf2010-03-14 15:45:01 +080025
Harald Welte9b455bf2010-03-14 15:45:01 +080026#include <osmocore/msgb.h>
Harald Welte9b455bf2010-03-14 15:45:01 +080027#include <osmocore/linuxlist.h>
28#include <osmocore/timer.h>
Harald Weltea2665542010-05-02 09:28:11 +020029#include <osmocore/talloc.h>
30
31#include <openbsc/gsm_data.h>
32#include <openbsc/debug.h>
Harald Welte807a5d82010-06-01 11:53:01 +020033#include <openbsc/gprs_sgsn.h>
34#include <openbsc/gprs_gmm.h>
Harald Welte9b455bf2010-03-14 15:45:01 +080035#include <openbsc/gprs_bssgp.h>
36#include <openbsc/gprs_llc.h>
37#include <openbsc/crc24.h>
38
Harald Welte1d9d9442010-06-03 07:11:04 +020039/* Section 8.9.9 LLC layer parameter default values */
40static const struct gprs_llc_params llc_default_params[] = {
41 [1] = {
42 .t200_201 = 5,
43 .n200 = 3,
44 .n201_u = 400,
45 },
46 [2] = {
47 .t200_201 = 5,
48 .n200 = 3,
49 .n201_u = 270,
50 },
51 [3] = {
52 .iov_i_exp = 27,
53 .t200_201 = 5,
54 .n200 = 3,
55 .n201_u = 500,
56 .n201_i = 1503,
57 .mD = 1520,
58 .mU = 1520,
59 .kD = 16,
60 .kU = 16,
61 },
62 [5] = {
63 .iov_i_exp = 27,
64 .t200_201 = 10,
65 .n200 = 3,
66 .n201_u = 500,
67 .n201_i = 1503,
68 .mD = 760,
69 .mU = 760,
70 .kD = 8,
71 .kU = 8,
72 },
73 [7] = {
74 .t200_201 = 20,
75 .n200 = 3,
76 .n201_u = 270,
77 },
78 [8] = {
79 .t200_201 = 20,
80 .n200 = 3,
81 .n201_u = 270,
82 },
83 [9] = {
84 .iov_i_exp = 27,
85 .t200_201 = 20,
86 .n200 = 3,
87 .n201_u = 500,
88 .n201_i = 1503,
89 .mD = 380,
90 .mU = 380,
91 .kD = 4,
92 .kU = 4,
93 },
94 [11] = {
95 .iov_i_exp = 27,
96 .t200_201 = 40,
97 .n200 = 3,
98 .n201_u = 500,
99 .n201_i = 1503,
100 .mD = 190,
101 .mU = 190,
102 .kD = 2,
103 .kU = 2,
104 },
105};
106
Harald Welte807a5d82010-06-01 11:53:01 +0200107LLIST_HEAD(gprs_llc_llmes);
Harald Weltea2665542010-05-02 09:28:11 +0200108void *llc_tall_ctx;
109
110/* lookup LLC Entity based on DLCI (TLLI+SAPI tuple) */
Harald Welte1d9d9442010-06-03 07:11:04 +0200111static struct gprs_llc_lle *lle_by_tlli_sapi(uint32_t tlli, uint8_t sapi)
Harald Weltea2665542010-05-02 09:28:11 +0200112{
Harald Welte807a5d82010-06-01 11:53:01 +0200113 struct gprs_llc_llme *llme;
Harald Weltea2665542010-05-02 09:28:11 +0200114
Harald Welte807a5d82010-06-01 11:53:01 +0200115 llist_for_each_entry(llme, &gprs_llc_llmes, list) {
116 if (llme->tlli == tlli || llme->old_tlli == tlli)
117 return &llme->lle[sapi];
Harald Weltea2665542010-05-02 09:28:11 +0200118 }
119 return NULL;
120}
121
Harald Welte1d9d9442010-06-03 07:11:04 +0200122static void lle_init(struct gprs_llc_llme *llme, uint8_t sapi)
Harald Weltea2665542010-05-02 09:28:11 +0200123{
Harald Welte807a5d82010-06-01 11:53:01 +0200124 struct gprs_llc_lle *lle = &llme->lle[sapi];
Harald Weltea2665542010-05-02 09:28:11 +0200125
Harald Welte807a5d82010-06-01 11:53:01 +0200126 lle->llme = llme;
127 lle->sapi = sapi;
128 lle->state = GPRS_LLES_UNASSIGNED;
129
Harald Welte1d9d9442010-06-03 07:11:04 +0200130 /* Initialize according to parameters */
131 memcpy(&lle->params, &llc_default_params[sapi], sizeof(lle->params));
Harald Welte807a5d82010-06-01 11:53:01 +0200132}
133
134static struct gprs_llc_llme *llme_alloc(uint32_t tlli)
135{
136 struct gprs_llc_llme *llme;
137 uint32_t i;
138
139 llme = talloc_zero(llc_tall_ctx, struct gprs_llc_llme);
140 if (!llme)
Harald Weltea2665542010-05-02 09:28:11 +0200141 return NULL;
142
Harald Welte807a5d82010-06-01 11:53:01 +0200143 llme->tlli = tlli;
Harald Welte875840c2010-07-01 11:54:31 +0200144 llme->old_tlli = 0xffffffff;
Harald Welte807a5d82010-06-01 11:53:01 +0200145 llme->state = GPRS_LLMS_UNASSIGNED;
Harald Weltea2665542010-05-02 09:28:11 +0200146
Harald Welte807a5d82010-06-01 11:53:01 +0200147 for (i = 0; i < ARRAY_SIZE(llme->lle); i++)
148 lle_init(llme, i);
149
150 llist_add(&llme->list, &gprs_llc_llmes);
151
152 return llme;
Harald Weltea2665542010-05-02 09:28:11 +0200153}
154
Harald Weltef7fef482010-06-28 22:18:26 +0200155static void llme_free(struct gprs_llc_llme *llme)
156{
157 llist_del(&llme->list);
158 talloc_free(llme);
159}
160
Harald Welte9b455bf2010-03-14 15:45:01 +0800161enum gprs_llc_cmd {
162 GPRS_LLC_NULL,
163 GPRS_LLC_RR,
164 GPRS_LLC_ACK,
165 GPRS_LLC_RNR,
166 GPRS_LLC_SACK,
167 GPRS_LLC_DM,
168 GPRS_LLC_DISC,
169 GPRS_LLC_UA,
170 GPRS_LLC_SABM,
171 GPRS_LLC_FRMR,
172 GPRS_LLC_XID,
Harald Welte1ae09c72010-05-13 19:22:55 +0200173 GPRS_LLC_UI,
Harald Welte9b455bf2010-03-14 15:45:01 +0800174};
175
Harald Welteb61f4032010-05-18 12:31:50 +0200176static const struct value_string llc_cmd_strs[] = {
177 { GPRS_LLC_NULL, "NULL" },
178 { GPRS_LLC_RR, "RR" },
179 { GPRS_LLC_ACK, "ACK" },
180 { GPRS_LLC_RNR, "RNR" },
181 { GPRS_LLC_SACK, "SACK" },
182 { GPRS_LLC_DM, "DM" },
183 { GPRS_LLC_DISC, "DISC" },
184 { GPRS_LLC_UA, "UA" },
185 { GPRS_LLC_SABM, "SABM" },
186 { GPRS_LLC_FRMR, "FRMR" },
187 { GPRS_LLC_XID, "XID" },
188 { GPRS_LLC_UI, "UI" },
189 { 0, NULL }
190};
191
Harald Welte9b455bf2010-03-14 15:45:01 +0800192struct gprs_llc_hdr_parsed {
Harald Welteeaa614c2010-05-02 11:26:34 +0200193 uint8_t sapi;
194 uint8_t is_cmd:1,
Harald Welte9b455bf2010-03-14 15:45:01 +0800195 ack_req:1,
196 is_encrypted:1;
Harald Welteeaa614c2010-05-02 11:26:34 +0200197 uint32_t seq_rx;
198 uint32_t seq_tx;
199 uint32_t fcs;
200 uint32_t fcs_calc;
201 uint8_t *data;
Harald Welte5658a1a2010-05-03 13:25:07 +0200202 uint16_t data_len;
Harald Welte1b8827a2010-06-30 23:15:57 +0200203 uint16_t crc_length;
Harald Welte9b455bf2010-03-14 15:45:01 +0800204 enum gprs_llc_cmd cmd;
205};
206
207#define LLC_ALLOC_SIZE 16384
208#define UI_HDR_LEN 3
209#define N202 4
210#define CRC24_LENGTH 3
211
Harald Welteeaa614c2010-05-02 11:26:34 +0200212static int gprs_llc_fcs(uint8_t *data, unsigned int len)
Harald Welte9b455bf2010-03-14 15:45:01 +0800213{
Harald Welteeaa614c2010-05-02 11:26:34 +0200214 uint32_t fcs_calc;
Harald Welte9b455bf2010-03-14 15:45:01 +0800215
216 fcs_calc = crc24_calc(INIT_CRC24, data, len);
217 fcs_calc = ~fcs_calc;
218 fcs_calc &= 0xffffff;
219
220 return fcs_calc;
221}
222
Harald Welte9b455bf2010-03-14 15:45:01 +0800223static void t200_expired(void *data)
224{
225 struct gprs_llc_lle *lle = data;
226
227 /* 8.5.1.3: Expiry of T200 */
228
Harald Welte1d9d9442010-06-03 07:11:04 +0200229 if (lle->retrans_ctr >= lle->params.n200) {
Harald Welte9b455bf2010-03-14 15:45:01 +0800230 /* FIXME: LLGM-STATUS-IND, LL-RELEASE-IND/CNF */
Harald Welte807a5d82010-06-01 11:53:01 +0200231 lle->state = GPRS_LLES_ASSIGNED_ADM;
Harald Welte9b455bf2010-03-14 15:45:01 +0800232 }
233
234 switch (lle->state) {
Harald Welte807a5d82010-06-01 11:53:01 +0200235 case GPRS_LLES_LOCAL_EST:
Harald Welte1ae09c72010-05-13 19:22:55 +0200236 /* FIXME: retransmit SABM */
237 /* FIXME: re-start T200 */
Harald Welte9b455bf2010-03-14 15:45:01 +0800238 lle->retrans_ctr++;
239 break;
Harald Welte807a5d82010-06-01 11:53:01 +0200240 case GPRS_LLES_LOCAL_REL:
Harald Welte1ae09c72010-05-13 19:22:55 +0200241 /* FIXME: retransmit DISC */
242 /* FIXME: re-start T200 */
Harald Welte9b455bf2010-03-14 15:45:01 +0800243 lle->retrans_ctr++;
244 break;
245 }
246
247}
248
249static void t201_expired(void *data)
250{
251 struct gprs_llc_lle *lle = data;
252
Harald Welte1d9d9442010-06-03 07:11:04 +0200253 if (lle->retrans_ctr < lle->params.n200) {
Harald Welte1ae09c72010-05-13 19:22:55 +0200254 /* FIXME: transmit apropriate supervisory frame (8.6.4.1) */
255 /* FIXME: set timer T201 */
Harald Welte9b455bf2010-03-14 15:45:01 +0800256 lle->retrans_ctr++;
257 }
258}
259
Harald Welte10997d02010-05-03 12:28:12 +0200260int gprs_llc_tx_u(struct msgb *msg, uint8_t sapi, int command,
261 enum gprs_llc_u_cmd u_cmd, int pf_bit)
262{
263 uint8_t *fcs, *llch;
264 uint8_t addr, ctrl;
265 uint32_t fcs_calc;
266
267 /* Identifiers from UP: (TLLI, SAPI) + (BVCI, NSEI) */
268
269 /* Address Field */
270 addr = sapi & 0xf;
271 if (command)
272 addr |= 0x40;
273
274 /* 6.3 Figure 8 */
275 ctrl = 0xe0 | u_cmd;
276 if (pf_bit)
277 ctrl |= 0x10;
278
279 /* prepend LLC UI header */
280 llch = msgb_push(msg, 2);
281 llch[0] = addr;
282 llch[1] = ctrl;
283
284 /* append FCS to end of frame */
285 fcs = msgb_put(msg, 3);
286 fcs_calc = gprs_llc_fcs(llch, fcs - llch);
287 fcs[0] = fcs_calc & 0xff;
288 fcs[1] = (fcs_calc >> 8) & 0xff;
289 fcs[2] = (fcs_calc >> 16) & 0xff;
290
291 /* Identifiers passed down: (BVCI, NSEI) */
292
Harald Welte1ae09c72010-05-13 19:22:55 +0200293 /* Send BSSGP-DL-UNITDATA.req */
Harald Welte56a01452010-05-31 22:12:30 +0200294 return gprs_bssgp_tx_dl_ud(msg, NULL);
Harald Welte10997d02010-05-03 12:28:12 +0200295}
296
297/* Send XID response to LLE */
298static int gprs_llc_tx_xid(struct gprs_llc_lle *lle, struct msgb *msg)
299{
300 /* copy identifiers from LLE to ensure lower layers can route */
Harald Welte807a5d82010-06-01 11:53:01 +0200301 msgb_tlli(msg) = lle->llme->tlli;
302 msgb_bvci(msg) = lle->llme->bvci;
303 msgb_nsei(msg) = lle->llme->nsei;
Harald Welte10997d02010-05-03 12:28:12 +0200304
305 return gprs_llc_tx_u(msg, lle->sapi, 0, GPRS_LLC_U_XID, 1);
306}
307
Harald Welte9b455bf2010-03-14 15:45:01 +0800308/* Transmit a UI frame over the given SAPI */
Harald Welte56a01452010-05-31 22:12:30 +0200309int gprs_llc_tx_ui(struct msgb *msg, uint8_t sapi, int command,
310 void *mmctx)
Harald Welte9b455bf2010-03-14 15:45:01 +0800311{
Harald Weltee6afd602010-05-02 11:19:37 +0200312 struct gprs_llc_lle *lle;
Harald Welteeaa614c2010-05-02 11:26:34 +0200313 uint8_t *fcs, *llch;
314 uint8_t addr, ctrl[2];
315 uint32_t fcs_calc;
316 uint16_t nu = 0;
Harald Welted07b4f92010-06-30 23:07:59 +0200317 uint32_t oc;
Harald Welte9b455bf2010-03-14 15:45:01 +0800318
Harald Weltee6afd602010-05-02 11:19:37 +0200319 /* Identifiers from UP: (TLLI, SAPI) + (BVCI, NSEI) */
320
321 /* look-up or create the LL Entity for this (TLLI, SAPI) tuple */
322 lle = lle_by_tlli_sapi(msgb_tlli(msg), sapi);
Harald Welte807a5d82010-06-01 11:53:01 +0200323 if (!lle) {
324 struct gprs_llc_llme *llme;
325 llme = llme_alloc(msgb_tlli(msg));
326 lle = &llme->lle[sapi];
327 }
Harald Welte1d9d9442010-06-03 07:11:04 +0200328
329 if (msg->len > lle->params.n201_u) {
330 LOGP(DLLC, LOGL_ERROR, "Cannot Tx %u bytes (N201-U=%u)\n",
331 msg->len, lle->params.n201_u);
332 return -EFBIG;
333 }
334
Harald Weltee6afd602010-05-02 11:19:37 +0200335 /* Update LLE's (BVCI, NSEI) tuple */
Harald Welte807a5d82010-06-01 11:53:01 +0200336 lle->llme->bvci = msgb_bvci(msg);
337 lle->llme->nsei = msgb_nsei(msg);
Harald Weltee6afd602010-05-02 11:19:37 +0200338
Harald Welted07b4f92010-06-30 23:07:59 +0200339 /* Obtain current values for N(u) and OC */
Harald Welte6bdee6a2010-05-30 21:51:58 +0200340 nu = lle->vu_send;
Harald Welted07b4f92010-06-30 23:07:59 +0200341 oc = lle->oc_ui_send;
342 /* Increment V(U) */
Harald Welte6bdee6a2010-05-30 21:51:58 +0200343 lle->vu_send = (lle->vu_send + 1) % 512;
Harald Welted07b4f92010-06-30 23:07:59 +0200344 /* Increment Overflow Counter, if needed */
345 if ((lle->vu_send + 1) / 512)
346 lle->oc_ui_send += 512;
Harald Welte6bdee6a2010-05-30 21:51:58 +0200347
Harald Welte9b455bf2010-03-14 15:45:01 +0800348 /* Address Field */
349 addr = sapi & 0xf;
350 if (command)
351 addr |= 0x40;
352
353 /* Control Field */
354 ctrl[0] = 0xc0;
355 ctrl[0] |= nu >> 6;
356 ctrl[1] = (nu << 2) & 0xfc;
357 ctrl[1] |= 0x01; /* Protected Mode */
358
359 /* prepend LLC UI header */
360 llch = msgb_push(msg, 3);
361 llch[0] = addr;
362 llch[1] = ctrl[0];
363 llch[2] = ctrl[1];
364
365 /* append FCS to end of frame */
366 fcs = msgb_put(msg, 3);
367 fcs_calc = gprs_llc_fcs(llch, fcs - llch);
368 fcs[0] = fcs_calc & 0xff;
369 fcs[1] = (fcs_calc >> 8) & 0xff;
370 fcs[2] = (fcs_calc >> 16) & 0xff;
371
Harald Welted07b4f92010-06-30 23:07:59 +0200372 /* encrypt information field + FCS, if needed! */
373 if (lle->llme->algo != GPRS_ALGO_GEA0) {
374 uint32_t iov_ui = 0; /* FIXME: randomly select for TLLI */
375 uint16_t crypt_len = (fcs + 3) - (llch + 3);
376 uint8_t cipher_out[GSM0464_CIPH_MAX_BLOCK];
377 uint32_t iv;
378 int rc, i;
379 uint64_t kc = *(uint64_t *)&lle->llme->kc;
380
381 /* Compute the 'Input' Paraemeter */
382 iv = gprs_cipher_gen_input_ui(iov_ui, sapi, nu, oc);
383
384 /* Compute the keystream that we need to XOR with the data */
385 rc = gprs_cipher_run(cipher_out, crypt_len, lle->llme->algo,
386 kc, iv, GPRS_CIPH_SGSN2MS);
387 if (rc < 0) {
388 LOGP(DLLC, LOGL_ERROR, "Error crypting UI frame: %d\n", rc);
389 return rc;
390 }
391
392 /* XOR the cipher output with the information field + FCS */
393 for (i = 0; i < crypt_len; i++)
394 *(llch + 3 + i) ^= cipher_out[i];
395
396 /* Mark frame as encrypted */
397 ctrl[1] |= 0x02;
398 }
399
Harald Weltee6afd602010-05-02 11:19:37 +0200400 /* Identifiers passed down: (BVCI, NSEI) */
401
Harald Welte1ae09c72010-05-13 19:22:55 +0200402 /* Send BSSGP-DL-UNITDATA.req */
Harald Welte56a01452010-05-31 22:12:30 +0200403 return gprs_bssgp_tx_dl_ud(msg, mmctx);
Harald Welte9b455bf2010-03-14 15:45:01 +0800404}
405
Holger Hans Peter Freyther3a6fdcd2010-05-23 21:35:25 +0800406static void gprs_llc_hdr_dump(struct gprs_llc_hdr_parsed *gph)
Harald Welte9b455bf2010-03-14 15:45:01 +0800407{
Sylvain Munaut6f3850f2010-07-03 22:03:02 +0200408 DEBUGP(DLLC, "LLC SAPI=%u %c %c FCS=0x%06x",
Harald Welte9b455bf2010-03-14 15:45:01 +0800409 gph->sapi, gph->is_cmd ? 'C' : 'R', gph->ack_req ? 'A' : ' ',
Sylvain Munaut6f3850f2010-07-03 22:03:02 +0200410 gph->fcs);
Harald Welte9b455bf2010-03-14 15:45:01 +0800411
412 if (gph->cmd)
Harald Welteb61f4032010-05-18 12:31:50 +0200413 DEBUGPC(DLLC, "CMD=%s ", get_value_string(llc_cmd_strs, gph->cmd));
Harald Welte9b455bf2010-03-14 15:45:01 +0800414
415 if (gph->data)
Harald Weltec6ecafe2010-05-13 19:47:50 +0200416 DEBUGPC(DLLC, "DATA ");
Harald Welte9b455bf2010-03-14 15:45:01 +0800417
Harald Weltec6ecafe2010-05-13 19:47:50 +0200418 DEBUGPC(DLLC, "\n");
Harald Welte9b455bf2010-03-14 15:45:01 +0800419}
420static int gprs_llc_hdr_rx(struct gprs_llc_hdr_parsed *gph,
421 struct gprs_llc_lle *lle)
422{
423 switch (gph->cmd) {
424 case GPRS_LLC_SABM: /* Section 6.4.1.1 */
425 lle->v_sent = lle->v_ack = lle->v_recv = 0;
Harald Welte807a5d82010-06-01 11:53:01 +0200426 if (lle->state == GPRS_LLES_ASSIGNED_ADM) {
Harald Welte9b455bf2010-03-14 15:45:01 +0800427 /* start re-establishment (8.7.1) */
428 }
Harald Welte807a5d82010-06-01 11:53:01 +0200429 lle->state = GPRS_LLES_REMOTE_EST;
Harald Welte9b455bf2010-03-14 15:45:01 +0800430 /* FIXME: Send UA */
Harald Welte807a5d82010-06-01 11:53:01 +0200431 lle->state = GPRS_LLES_ABM;
Harald Welte9b455bf2010-03-14 15:45:01 +0800432 /* FIXME: process data */
433 break;
434 case GPRS_LLC_DISC: /* Section 6.4.1.2 */
435 /* FIXME: Send UA */
436 /* terminate ABM */
Harald Welte807a5d82010-06-01 11:53:01 +0200437 lle->state = GPRS_LLES_ASSIGNED_ADM;
Harald Welte9b455bf2010-03-14 15:45:01 +0800438 break;
439 case GPRS_LLC_UA: /* Section 6.4.1.3 */
Harald Welte807a5d82010-06-01 11:53:01 +0200440 if (lle->state == GPRS_LLES_LOCAL_EST)
441 lle->state = GPRS_LLES_ABM;
Harald Welte9b455bf2010-03-14 15:45:01 +0800442 break;
443 case GPRS_LLC_DM: /* Section 6.4.1.4: ABM cannot be performed */
Harald Welte807a5d82010-06-01 11:53:01 +0200444 if (lle->state == GPRS_LLES_LOCAL_EST)
445 lle->state = GPRS_LLES_ASSIGNED_ADM;
Harald Welte9b455bf2010-03-14 15:45:01 +0800446 break;
447 case GPRS_LLC_FRMR: /* Section 6.4.1.5 */
448 break;
449 case GPRS_LLC_XID: /* Section 6.4.1.6 */
Harald Welte5658a1a2010-05-03 13:25:07 +0200450 /* FIXME: implement XID negotiation using SNDCP */
451 {
452 struct msgb *resp;
453 uint8_t *xid;
454 resp = msgb_alloc_headroom(4096, 1024, "LLC_XID");
455 xid = msgb_put(resp, gph->data_len);
456 memcpy(xid, gph->data, gph->data_len);
457 gprs_llc_tx_xid(lle, resp);
458 }
Harald Welte9b455bf2010-03-14 15:45:01 +0800459 break;
Harald Welteebabdea2010-06-01 18:28:10 +0200460 case GPRS_LLC_UI:
461 if (gph->seq_tx < lle->vu_recv) {
Holger Hans Peter Freyther2788b962010-06-23 09:48:25 +0800462 LOGP(DLLC, LOGL_NOTICE, "TLLI=%08x dropping UI, vurecv %u <= %u\n",
463 lle->llme ? lle->llme->tlli : -1,
Harald Welteebabdea2010-06-01 18:28:10 +0200464 gph->seq_tx, lle->vu_recv);
465 return -EIO;
466 }
467 /* Increment the sequence number that we expect in the next frame */
468 lle->vu_recv = (gph->seq_tx + 1) % 512;
Harald Welted07b4f92010-06-30 23:07:59 +0200469 /* Increment Overflow Counter */
470 if ((gph->seq_tx + 1) / 512)
471 lle->oc_ui_recv += 512;
Harald Welteebabdea2010-06-01 18:28:10 +0200472 break;
Harald Welte9b455bf2010-03-14 15:45:01 +0800473 }
474
475 return 0;
476}
477
478/* parse a GPRS LLC header, also check for invalid frames */
479static int gprs_llc_hdr_parse(struct gprs_llc_hdr_parsed *ghp,
Holger Hans Peter Freytherfa848d42010-05-23 21:43:57 +0800480 uint8_t *llc_hdr, int len)
Harald Welte9b455bf2010-03-14 15:45:01 +0800481{
Harald Welteeaa614c2010-05-02 11:26:34 +0200482 uint8_t *ctrl = llc_hdr+1;
Harald Welte9b455bf2010-03-14 15:45:01 +0800483 int is_sack = 0;
Harald Welte9b455bf2010-03-14 15:45:01 +0800484
485 if (len <= CRC24_LENGTH)
486 return -EIO;
487
Harald Welte1b8827a2010-06-30 23:15:57 +0200488 ghp->crc_length = len - CRC24_LENGTH;
Harald Welte9b455bf2010-03-14 15:45:01 +0800489
490 ghp->ack_req = 0;
491
492 /* Section 5.5: FCS */
493 ghp->fcs = *(llc_hdr + len - 3);
494 ghp->fcs |= *(llc_hdr + len - 2) << 8;
495 ghp->fcs |= *(llc_hdr + len - 1) << 16;
496
497 /* Section 6.2.1: invalid PD field */
498 if (llc_hdr[0] & 0x80)
499 return -EIO;
500
501 /* This only works for the MS->SGSN direction */
502 if (llc_hdr[0] & 0x40)
503 ghp->is_cmd = 0;
504 else
505 ghp->is_cmd = 1;
506
507 ghp->sapi = llc_hdr[0] & 0xf;
508
509 /* Section 6.2.3: check for reserved SAPI */
510 switch (ghp->sapi) {
511 case 0:
512 case 4:
513 case 6:
514 case 0xa:
515 case 0xc:
516 case 0xd:
517 case 0xf:
518 return -EINVAL;
519 }
520
521 if ((ctrl[0] & 0x80) == 0) {
522 /* I (Information transfer + Supervisory) format */
Harald Welteeaa614c2010-05-02 11:26:34 +0200523 uint8_t k;
Harald Welte9b455bf2010-03-14 15:45:01 +0800524
525 ghp->data = ctrl + 3;
526
527 if (ctrl[0] & 0x40)
528 ghp->ack_req = 1;
529
530 ghp->seq_tx = (ctrl[0] & 0x1f) << 4;
531 ghp->seq_tx |= (ctrl[1] >> 4);
532
533 ghp->seq_rx = (ctrl[1] & 0x7) << 6;
534 ghp->seq_rx |= (ctrl[2] >> 2);
535
536 switch (ctrl[2] & 0x03) {
537 case 0:
538 ghp->cmd = GPRS_LLC_RR;
539 break;
540 case 1:
541 ghp->cmd = GPRS_LLC_ACK;
542 break;
543 case 2:
544 ghp->cmd = GPRS_LLC_RNR;
545 break;
546 case 3:
547 ghp->cmd = GPRS_LLC_SACK;
548 k = ctrl[3] & 0x1f;
549 ghp->data += 1 + k;
550 break;
551 }
Harald Welte5658a1a2010-05-03 13:25:07 +0200552 ghp->data_len = (llc_hdr + len - 3) - ghp->data;
Harald Welte9b455bf2010-03-14 15:45:01 +0800553 } else if ((ctrl[0] & 0xc0) == 0x80) {
554 /* S (Supervisory) format */
555 ghp->data = NULL;
Harald Welte5658a1a2010-05-03 13:25:07 +0200556 ghp->data_len = 0;
Harald Welte9b455bf2010-03-14 15:45:01 +0800557
558 if (ctrl[0] & 0x20)
559 ghp->ack_req = 1;
560 ghp->seq_rx = (ctrl[0] & 0x7) << 6;
561 ghp->seq_rx |= (ctrl[1] >> 2);
562
563 switch (ctrl[1] & 0x03) {
564 case 0:
565 ghp->cmd = GPRS_LLC_RR;
566 break;
567 case 1:
568 ghp->cmd = GPRS_LLC_ACK;
569 break;
570 case 2:
571 ghp->cmd = GPRS_LLC_RNR;
572 break;
573 case 3:
574 ghp->cmd = GPRS_LLC_SACK;
575 break;
576 }
577 } else if ((ctrl[0] & 0xe0) == 0xc0) {
578 /* UI (Unconfirmed Inforamtion) format */
Harald Welte1ae09c72010-05-13 19:22:55 +0200579 ghp->cmd = GPRS_LLC_UI;
Harald Welte9b455bf2010-03-14 15:45:01 +0800580 ghp->data = ctrl + 2;
Harald Welte5658a1a2010-05-03 13:25:07 +0200581 ghp->data_len = (llc_hdr + len - 3) - ghp->data;
Harald Welte9b455bf2010-03-14 15:45:01 +0800582
583 ghp->seq_tx = (ctrl[0] & 0x7) << 6;
584 ghp->seq_tx |= (ctrl[1] >> 2);
585 if (ctrl[1] & 0x02) {
586 ghp->is_encrypted = 1;
587 /* FIXME: encryption */
588 }
589 if (ctrl[1] & 0x01) {
590 /* FCS over hdr + all inf fields */
591 } else {
592 /* FCS over hdr + N202 octets (4) */
Harald Welte1b8827a2010-06-30 23:15:57 +0200593 if (ghp->crc_length > UI_HDR_LEN + N202)
594 ghp->crc_length = UI_HDR_LEN + N202;
Harald Welte9b455bf2010-03-14 15:45:01 +0800595 }
596 } else {
597 /* U (Unnumbered) format: 1 1 1 P/F M4 M3 M2 M1 */
598 ghp->data = NULL;
Harald Welte5658a1a2010-05-03 13:25:07 +0200599 ghp->data_len = 0;
Harald Welte9b455bf2010-03-14 15:45:01 +0800600
601 switch (ctrl[0] & 0xf) {
Harald Welte5658a1a2010-05-03 13:25:07 +0200602 case GPRS_LLC_U_NULL_CMD:
Harald Welte9b455bf2010-03-14 15:45:01 +0800603 ghp->cmd = GPRS_LLC_NULL;
604 break;
Harald Welte5658a1a2010-05-03 13:25:07 +0200605 case GPRS_LLC_U_DM_RESP:
Harald Welte9b455bf2010-03-14 15:45:01 +0800606 ghp->cmd = GPRS_LLC_DM;
607 break;
Harald Welte5658a1a2010-05-03 13:25:07 +0200608 case GPRS_LLC_U_DISC_CMD:
Harald Welte9b455bf2010-03-14 15:45:01 +0800609 ghp->cmd = GPRS_LLC_DISC;
610 break;
Harald Welte5658a1a2010-05-03 13:25:07 +0200611 case GPRS_LLC_U_UA_RESP:
Harald Welte9b455bf2010-03-14 15:45:01 +0800612 ghp->cmd = GPRS_LLC_UA;
613 break;
Harald Welte5658a1a2010-05-03 13:25:07 +0200614 case GPRS_LLC_U_SABM_CMD:
Harald Welte9b455bf2010-03-14 15:45:01 +0800615 ghp->cmd = GPRS_LLC_SABM;
616 break;
Harald Welte5658a1a2010-05-03 13:25:07 +0200617 case GPRS_LLC_U_FRMR_RESP:
Harald Welte9b455bf2010-03-14 15:45:01 +0800618 ghp->cmd = GPRS_LLC_FRMR;
619 break;
Harald Welte5658a1a2010-05-03 13:25:07 +0200620 case GPRS_LLC_U_XID:
Harald Welte9b455bf2010-03-14 15:45:01 +0800621 ghp->cmd = GPRS_LLC_XID;
Harald Welte5658a1a2010-05-03 13:25:07 +0200622 ghp->data = ctrl + 1;
623 ghp->data_len = (llc_hdr + len - 3) - ghp->data;
Harald Welte9b455bf2010-03-14 15:45:01 +0800624 break;
625 default:
626 return -EIO;
627 }
628 }
629
Harald Welte9b455bf2010-03-14 15:45:01 +0800630 /* FIXME: parse sack frame */
Harald Welte1ae09c72010-05-13 19:22:55 +0200631 if (ghp->cmd == GPRS_LLC_SACK) {
Harald Welte1b170d12010-05-13 19:49:06 +0200632 LOGP(DLLC, LOGL_NOTICE, "Unsupported SACK frame\n");
Harald Welte1ae09c72010-05-13 19:22:55 +0200633 return -EIO;
634 }
635
636 return 0;
Harald Welte9b455bf2010-03-14 15:45:01 +0800637}
638
Harald Weltea2665542010-05-02 09:28:11 +0200639/* receive an incoming LLC PDU (BSSGP-UL-UNITDATA-IND, 7.2.4.2) */
Harald Welte9b455bf2010-03-14 15:45:01 +0800640int gprs_llc_rcvmsg(struct msgb *msg, struct tlv_parsed *tv)
641{
Harald Weltefd3fa1d2010-05-02 09:50:42 +0200642 struct bssgp_ud_hdr *udh = (struct bssgp_ud_hdr *) msgb_bssgph(msg);
Harald Welte943c5bc2010-04-30 16:33:12 +0200643 struct gprs_llc_hdr *lh = msgb_llch(msg);
Harald Welte9b455bf2010-03-14 15:45:01 +0800644 struct gprs_llc_hdr_parsed llhp;
Harald Welte10997d02010-05-03 12:28:12 +0200645 struct gprs_llc_lle *lle;
Harald Weltea2665542010-05-02 09:28:11 +0200646 int rc = 0;
Harald Welte9b455bf2010-03-14 15:45:01 +0800647
Harald Welte11d7c102010-05-02 11:54:55 +0200648 /* Identifiers from DOWN: NSEI, BVCI, TLLI */
649
Holger Hans Peter Freyther4752e0c2010-05-23 21:33:57 +0800650 memset(&llhp, 0, sizeof(llhp));
Holger Hans Peter Freytherfa848d42010-05-23 21:43:57 +0800651 rc = gprs_llc_hdr_parse(&llhp, (uint8_t *) lh, TLVP_LEN(tv, BSSGP_IE_LLC_PDU));
Harald Welte9b455bf2010-03-14 15:45:01 +0800652 gprs_llc_hdr_dump(&llhp);
Harald Welte1ae09c72010-05-13 19:22:55 +0200653 if (rc < 0) {
Harald Welte1b170d12010-05-13 19:49:06 +0200654 LOGP(DLLC, LOGL_NOTICE, "Error during LLC header parsing\n");
Harald Welte1ae09c72010-05-13 19:22:55 +0200655 return rc;
656 }
657
Harald Welte807a5d82010-06-01 11:53:01 +0200658 switch (gprs_tlli_type(msgb_tlli(msg))) {
659 case TLLI_LOCAL:
660 case TLLI_FOREIGN:
661 case TLLI_RANDOM:
662 case TLLI_AUXILIARY:
663 break;
664 default:
665 LOGP(DLLC, LOGL_ERROR,
666 "Discarding frame with strange TLLI type\n");
667 break;
668 }
669
Harald Weltea2665542010-05-02 09:28:11 +0200670 /* find the LLC Entity for this TLLI+SAPI tuple */
671 lle = lle_by_tlli_sapi(msgb_tlli(msg), llhp.sapi);
Harald Welte1ae09c72010-05-13 19:22:55 +0200672
673 /* 7.2.1.1 LLC belonging to unassigned TLLI+SAPI shall be discarded,
674 * except UID and XID frames with SAPI=1 */
Harald Welted764c062010-05-18 12:45:08 +0200675 if (!lle) {
676 if (llhp.sapi == GPRS_SAPI_GMM &&
677 (llhp.cmd == GPRS_LLC_XID || llhp.cmd == GPRS_LLC_UI)) {
Harald Welte807a5d82010-06-01 11:53:01 +0200678 struct gprs_llc_llme *llme;
Harald Welted764c062010-05-18 12:45:08 +0200679 /* FIXME: don't use the TLLI but the 0xFFFF unassigned? */
Harald Welte807a5d82010-06-01 11:53:01 +0200680 llme = llme_alloc(msgb_tlli(msg));
681 lle = &llme->lle[llhp.sapi];
Harald Welted764c062010-05-18 12:45:08 +0200682 } else {
683 LOGP(DLLC, LOGL_NOTICE,
684 "unknown TLLI/SAPI: Silently dropping\n");
685 return 0;
686 }
Harald Welte1ae09c72010-05-13 19:22:55 +0200687 }
Harald Weltea2665542010-05-02 09:28:11 +0200688
Harald Welted07b4f92010-06-30 23:07:59 +0200689 /* decrypt information field + FCS, if needed! */
690 if (llhp.is_encrypted) {
691 uint32_t iov_ui = 0; /* FIXME: randomly select for TLLI */
692 uint16_t crypt_len = llhp.data_len + 3;
693 uint8_t cipher_out[GSM0464_CIPH_MAX_BLOCK];
694 uint32_t iv;
695 uint64_t kc = *(uint64_t *)&lle->llme->kc;
696 int rc, i;
697
698 if (lle->llme->algo == GPRS_ALGO_GEA0) {
699 LOGP(DLLC, LOGL_NOTICE, "encrypted frame for LLC that "
700 "has no KC/Algo! Dropping.\n");
701 return 0;
702 }
703
704 iv = gprs_cipher_gen_input_ui(iov_ui, lle->sapi, llhp.seq_tx,
705 lle->oc_ui_recv);
706 rc = gprs_cipher_run(cipher_out, crypt_len, lle->llme->algo,
707 kc, iv, GPRS_CIPH_MS2SGSN);
708 if (rc < 0) {
709 LOGP(DLLC, LOGL_ERROR, "Error decrypting frame: %d\n",
710 rc);
711 return rc;
712 }
713
714 /* XOR the cipher output with the information field + FCS */
715 for (i = 0; i < crypt_len; i++)
716 *(llhp.data + i) ^= cipher_out[i];
717 } else {
718 if (lle->llme->algo != GPRS_ALGO_GEA0) {
719 LOGP(DLLC, LOGL_NOTICE, "unencrypted frame for LLC "
720 "that is supposed to be encrypted. Dropping.\n");
721 return 0;
722 }
723 }
724
725 /* We have to do the FCS check _after_ decryption */
Harald Welte1b8827a2010-06-30 23:15:57 +0200726 llhp.fcs_calc = gprs_llc_fcs((uint8_t *)lh, llhp.crc_length);
Harald Welted07b4f92010-06-30 23:07:59 +0200727 if (llhp.fcs != llhp.fcs_calc) {
728 LOGP(DLLC, LOGL_INFO, "Dropping frame with invalid FCS\n");
729 return -EIO;
730 }
731
Harald Welte10997d02010-05-03 12:28:12 +0200732 /* Update LLE's (BVCI, NSEI) tuple */
Harald Welte807a5d82010-06-01 11:53:01 +0200733 lle->llme->bvci = msgb_bvci(msg);
734 lle->llme->nsei = msgb_nsei(msg);
Harald Welte10997d02010-05-03 12:28:12 +0200735
Harald Welte1ae09c72010-05-13 19:22:55 +0200736 /* Receive and Process the actual LLC frame */
Harald Welte9b455bf2010-03-14 15:45:01 +0800737 rc = gprs_llc_hdr_rx(&llhp, lle);
Harald Welte1ae09c72010-05-13 19:22:55 +0200738 if (rc < 0)
739 return rc;
Harald Welte9b455bf2010-03-14 15:45:01 +0800740
Harald Welte1ae09c72010-05-13 19:22:55 +0200741 /* llhp.data is only set when we need to send LL_[UNIT]DATA_IND up */
Harald Welte9b455bf2010-03-14 15:45:01 +0800742 if (llhp.data) {
Harald Welte943c5bc2010-04-30 16:33:12 +0200743 msgb_gmmh(msg) = llhp.data;
Harald Welte9b455bf2010-03-14 15:45:01 +0800744 switch (llhp.sapi) {
745 case GPRS_SAPI_GMM:
Harald Welte1ae09c72010-05-13 19:22:55 +0200746 /* send LL_UNITDATA_IND to GMM */
Harald Welte807a5d82010-06-01 11:53:01 +0200747 rc = gsm0408_gprs_rcvmsg(msg, lle->llme);
Harald Weltea2665542010-05-02 09:28:11 +0200748 break;
Harald Weltea2665542010-05-02 09:28:11 +0200749 case GPRS_SAPI_SNDCP3:
750 case GPRS_SAPI_SNDCP5:
751 case GPRS_SAPI_SNDCP9:
752 case GPRS_SAPI_SNDCP11:
Harald Welteebabdea2010-06-01 18:28:10 +0200753 /* send LL_DATA_IND/LL_UNITDATA_IND to SNDCP */
754 rc = sndcp_llunitdata_ind(msg, lle, llhp.data, llhp.data_len);
755 break;
Harald Weltea2665542010-05-02 09:28:11 +0200756 case GPRS_SAPI_SMS:
757 /* FIXME */
Harald Welteebabdea2010-06-01 18:28:10 +0200758 case GPRS_SAPI_TOM2:
759 case GPRS_SAPI_TOM8:
760 /* FIXME: send LL_DATA_IND/LL_UNITDATA_IND to TOM */
Harald Weltea2665542010-05-02 09:28:11 +0200761 default:
Harald Weltec6ecafe2010-05-13 19:47:50 +0200762 LOGP(DLLC, LOGL_NOTICE, "Unsupported SAPI %u\n", llhp.sapi);
Harald Weltea2665542010-05-02 09:28:11 +0200763 rc = -EINVAL;
764 break;
Harald Welte9b455bf2010-03-14 15:45:01 +0800765 }
766 }
767
Harald Weltea2665542010-05-02 09:28:11 +0200768 return rc;
Harald Welte9b455bf2010-03-14 15:45:01 +0800769}
Harald Welte807a5d82010-06-01 11:53:01 +0200770
771/* 04.64 Chapter 7.2.1.1 LLGMM-ASSIGN */
772int gprs_llgmm_assign(struct gprs_llc_llme *llme,
773 uint32_t old_tlli, uint32_t new_tlli,
774 enum gprs_ciph_algo alg, const uint8_t *kc)
775{
776 unsigned int i;
777
Harald Welted07b4f92010-06-30 23:07:59 +0200778 /* Update the crypto parameters */
Harald Welted07b4f92010-06-30 23:07:59 +0200779 llme->algo = alg;
Harald Welte3e2e1592010-06-30 23:19:23 +0200780 if (alg != GPRS_ALGO_GEA0)
781 memcpy(llme->kc, kc, sizeof(llme->kc));
Harald Welted07b4f92010-06-30 23:07:59 +0200782
Harald Welte807a5d82010-06-01 11:53:01 +0200783 if (old_tlli == 0xffffffff && new_tlli != 0xffffffff) {
784 /* TLLI Assignment 8.3.1 */
785 /* New TLLI shall be assigned and used when (re)transmitting LLC frames */
786 /* If old TLLI != 0xffffffff was assigned to LLME, then TLLI
787 * old is unassigned. Only TLLI new shall be accepted when
788 * received from peer. */
Harald Welte875840c2010-07-01 11:54:31 +0200789 if (llme->old_tlli != 0xffffffff) {
790 llme->old_tlli = 0xffffffff;
791 llme->tlli = new_tlli;
792 } else {
793 /* If TLLI old == 0xffffffff was assigned to LLME, then this is
794 * TLLI assignmemt according to 8.3.1 */
795 llme->old_tlli = 0xffffffff;
796 llme->tlli = new_tlli;
797 llme->state = GPRS_LLMS_ASSIGNED;
798 /* 8.5.3.1 For all LLE's */
799 for (i = 0; i < ARRAY_SIZE(llme->lle); i++) {
800 struct gprs_llc_lle *l = &llme->lle[i];
801 l->vu_send = l->vu_recv = 0;
802 l->retrans_ctr = 0;
803 l->state = GPRS_LLES_ASSIGNED_ADM;
804 /* FIXME Set parameters according to table 9 */
805 }
Harald Welte807a5d82010-06-01 11:53:01 +0200806 }
807 } else if (old_tlli != 0xffffffff && new_tlli != 0xffffffff) {
808 /* TLLI Change 8.3.2 */
809 /* Both TLLI Old and TLLI New are assigned; use New when
810 * (re)transmitting. Accept toth Old and New on Rx */
811 llme->old_tlli = llme->tlli;
812 llme->tlli = new_tlli;
813 llme->state = GPRS_LLMS_ASSIGNED;
814 } else if (old_tlli != 0xffffffff && new_tlli == 0xffffffff) {
815 /* TLLI Unassignment 8.3.3) */
816 llme->tlli = llme->old_tlli = 0;
817 llme->state = GPRS_LLMS_UNASSIGNED;
818 for (i = 0; i < ARRAY_SIZE(llme->lle); i++) {
819 struct gprs_llc_lle *l = &llme->lle[i];
820 l->state = GPRS_LLES_UNASSIGNED;
821 }
Harald Weltef7fef482010-06-28 22:18:26 +0200822 llme_free(llme);
Harald Welte807a5d82010-06-01 11:53:01 +0200823 } else
824 return -EINVAL;
825
826 return 0;
827}
Harald Welte496aee42010-06-30 19:59:55 +0200828
829int gprs_llc_init(const char *cipher_plugin_path)
830{
831 return gprs_cipher_load(cipher_plugin_path);
832}