blob: cb228ef9b9c492493dd20e564f739fc90a2dc563 [file] [log] [blame]
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01001/* BSSAP/BSSMAP encoding and decoding for MSC */
2/*
3 * (C) 2019 by sysmocom - s.m.f.c. GmbH <info@sysmocom.de>
4 * All Rights Reserved
5 *
6 * Author: Neels Hofmeyr
7 *
8 * SPDX-License-Identifier: GPL-2.0+
9 *
10 * This program is free software; you can redistribute it and/or modify
11 * it under the terms of the GNU General Public License as published by
12 * the Free Software Foundation; either version 2 of the License, or
13 * (at your option) any later version.
14 *
15 * This program is distributed in the hope that it will be useful,
16 * but WITHOUT ANY WARRANTY; without even the implied warranty of
17 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
18 * GNU General Public License for more details.
19 *
20 * You should have received a copy of the GNU General Public License along
21 * with this program; if not, write to the Free Software Foundation, Inc.,
22 * 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
23 */
24
25#include <osmocom/core/byteswap.h>
26
27#include <osmocom/crypt/auth.h>
28
29#include <osmocom/gsm/tlv.h>
30#include <osmocom/gsm/gsm0808.h>
31#include <osmocom/gsm/mncc.h>
32#include <osmocom/gsm/gsm48.h>
33
34#include <osmocom/msc/debug.h>
35#include <osmocom/msc/ran_msg_a.h>
36#include <osmocom/msc/sccp_ran.h>
Pau Espin Pedrolc9ba7542019-05-07 12:23:49 +020037#include <osmocom/msc/gsm_data.h>
Neels Hofmeyrc4628a32018-12-07 14:47:34 +010038
39#define LOG_RAN_A_DEC(RAN_DEC, level, fmt, args...) \
40 LOG_RAN_DEC(RAN_DEC, DBSSAP, level, "BSSMAP: " fmt, ## args)
41
42/* Assumes presence of struct ran_dec *ran_dec and ran_dec_msg.msg_name (set) in the local scope. */
43#define LOG_RAN_A_DEC_MSG(level, fmt, args...) \
44 LOG_RAN_DEC(ran_dec, DBSSAP, level, "%s: " fmt, ran_dec_msg.msg_name, ## args)
45
46#define LOG_RAN_A_ENC(FI, level, fmt, args...) \
47 LOG_RAN_ENC(FI, DBSSAP, level, "BSSMAP: " fmt, ## args)
48
49static int ran_a_decode_l3_compl(struct ran_dec *ran_dec, struct msgb *msg, struct tlv_parsed *tp)
50{
51 struct gsm0808_cell_id_list2 cil;
52 struct gsm0808_cell_id cell_id;
53 struct tlv_p_entry *ie_cell_id = TLVP_GET(tp, GSM0808_IE_CELL_IDENTIFIER);
54 struct tlv_p_entry *ie_l3_info = TLVP_GET(tp, GSM0808_IE_LAYER_3_INFORMATION);
Neels Hofmeyr8a50cfb2019-10-21 03:01:00 +020055 struct tlv_p_entry *ie_codec_list_bss_supported = TLVP_GET(tp, GSM0808_IE_SPEECH_CODEC_LIST);
56 struct gsm0808_speech_codec_list codec_list_bss_supported;
Neels Hofmeyrc4628a32018-12-07 14:47:34 +010057 struct ran_msg ran_dec_msg = {
58 .msg_type = RAN_MSG_COMPL_L3,
Neels Hofmeyr0c1ed152019-10-21 03:12:58 +020059 .msg_name = "BSSMAP Complete Layer 3 Information",
Neels Hofmeyrc4628a32018-12-07 14:47:34 +010060 .compl_l3 = {
61 .cell_id = &cell_id,
62 .msg = msg,
63 },
64 };
65 int rc;
66
67 if (!ie_cell_id) {
68 LOG_RAN_A_DEC_MSG(LOGL_ERROR, "Mandatory CELL IDENTIFIER not present, discarding message\n");
69 return -EINVAL;
70 }
71 if (!ie_l3_info) {
72 LOG_RAN_A_DEC_MSG(LOGL_ERROR, "Mandatory LAYER 3 INFORMATION not present, discarding message\n");
73 return -EINVAL;
74 }
75
76 /* Parse Cell ID element -- this should yield a cell identifier "list" with 1 element. */
77
78 rc = gsm0808_dec_cell_id_list2(&cil, ie_cell_id->val, ie_cell_id->len);
79 if (rc < 0) {
80 LOG_RAN_A_DEC_MSG(LOGL_ERROR, "Decoding CELL IDENTIFIER gave rc=%d\n", rc);
81 return -EINVAL;
82 }
83 if (cil.id_list_len != 1) {
84 LOG_RAN_A_DEC_MSG(LOGL_ERROR, "Unable to parse element CELL IDENTIFIER, discarding message\n");
85 return -EINVAL;
86 }
87
88 /* Sanity check the Cell Identity */
89 switch (cil.id_discr) {
90 case CELL_IDENT_WHOLE_GLOBAL:
91 case CELL_IDENT_LAI_AND_LAC:
92 case CELL_IDENT_LAC_AND_CI:
93 case CELL_IDENT_LAC:
94 break;
95
96 case CELL_IDENT_CI:
97 case CELL_IDENT_NO_CELL:
98 case CELL_IDENT_BSS:
99 default:
100 LOG_RAN_A_DEC_MSG(LOGL_ERROR, "CELL IDENTIFIER does not specify a LAC, discarding message: %s\n",
101 gsm0808_cell_id_list_name(&cil));
102 return -EINVAL;
103 }
104
105 cell_id = (struct gsm0808_cell_id){
106 .id_discr = cil.id_discr,
107 .id = cil.id_list[0],
108 };
109
110 /* Parse Layer 3 Information element */
111 msg->l3h = (uint8_t*)ie_l3_info->val;
112 msgb_l3trim(msg, ie_l3_info->len);
113
114 if (msgb_l3len(msg) < sizeof(struct gsm48_hdr)) {
115 LOG_RAN_A_DEC_MSG(LOGL_ERROR, "too short L3 info (%d), discarding message\n", msgb_l3len(msg));
116 return -ENODATA;
117 }
118
Neels Hofmeyr8a50cfb2019-10-21 03:01:00 +0200119 /* Decode Codec List (BSS Supported) */
120 if (ie_codec_list_bss_supported) {
121 rc = gsm0808_dec_speech_codec_list(&codec_list_bss_supported,
122 ie_codec_list_bss_supported->val, ie_codec_list_bss_supported->len);
123 if (rc < 0) {
124 LOG_RAN_A_DEC_MSG(LOGL_ERROR,
125 "Complete Layer 3 Information: unable to decode IE Codec List (BSS Supported)"
126 " (rc=%d), continuing anyway\n", rc);
127 /* This IE is not critical, do not abort with error. */
128 } else
129 ran_dec_msg.compl_l3.codec_list_bss_supported = &codec_list_bss_supported;
130 }
131
Neels Hofmeyrc4628a32018-12-07 14:47:34 +0100132 return ran_decoded(ran_dec, &ran_dec_msg);
133}
134
135static int ran_a_decode_clear_request(struct ran_dec *ran_dec, struct msgb *msg, struct tlv_parsed *tp)
136{
137 struct tlv_p_entry *ie_cause = TLVP_GET(tp, GSM0808_IE_CAUSE);
138 struct ran_msg ran_dec_msg = {
139 .msg_type = RAN_MSG_CLEAR_REQUEST,
140 .msg_name = "BSSMAP Clear Request",
141 };
142
143 if (!ie_cause) {
144 LOG_RAN_A_DEC_MSG(LOGL_ERROR, "Cause code is missing, using GSM0808_CAUSE_EQUIPMENT_FAILURE\n");
145 ran_dec_msg.clear_request.bssap_cause = GSM0808_CAUSE_EQUIPMENT_FAILURE;
146 } else {
147 ran_dec_msg.clear_request.bssap_cause = ie_cause->val[0];
148 }
149
150 return ran_decoded(ran_dec, &ran_dec_msg);
151}
152
153static int ran_a_decode_clear_complete(struct ran_dec *ran_dec, struct msgb *msg, struct tlv_parsed *tp)
154{
155 struct ran_msg ran_dec_msg = {
156 .msg_type = RAN_MSG_CLEAR_COMPLETE,
157 .msg_name = "BSSMAP Clear Complete",
158 };
159 return ran_decoded(ran_dec, &ran_dec_msg);
160}
161
162static int ran_a_decode_classmark_update(struct ran_dec *ran_dec, struct msgb *msg, struct tlv_parsed *tp)
163{
164 struct tlv_p_entry *ie_cm2 = TLVP_GET(tp, GSM0808_IE_CLASSMARK_INFORMATION_T2);
165 struct tlv_p_entry *ie_cm3 = TLVP_GET(tp, GSM0808_IE_CLASSMARK_INFORMATION_T3);
166 struct osmo_gsm48_classmark cm = {};
167 struct ran_msg ran_dec_msg = {
168 .msg_type = RAN_MSG_CLASSMARK_UPDATE,
169 .msg_name = "BSSMAP Classmark Update",
170 .classmark_update = {
171 .classmark = &cm,
172 },
173 };
174
175 if (!ie_cm2) {
176 LOG_RAN_A_DEC_MSG(LOGL_ERROR, "mandatory Classmark Information Type 2 not present, discarding message\n");
177 return -EINVAL;
178 }
179
180 cm.classmark2_len = OSMO_MIN(sizeof(cm.classmark2), ie_cm2->len);
181 memcpy(&cm.classmark2, ie_cm2->val, cm.classmark2_len);
182
183 if (ie_cm3) {
184 cm.classmark3_len = OSMO_MIN(sizeof(cm.classmark3), ie_cm3->len);
185 memcpy(&cm.classmark3, ie_cm3->val, cm.classmark3_len);
186 }
187
188 return ran_decoded(ran_dec, &ran_dec_msg);
189}
190
191static int ran_a_decode_cipher_mode_complete(struct ran_dec *ran_dec, struct msgb *msg, struct tlv_parsed *tp)
192{
193 struct tlv_p_entry *ie_chosen_encr_alg = TLVP_GET(tp, GSM0808_IE_CHOSEN_ENCR_ALG);
194 struct tlv_p_entry *ie_l3_msg = TLVP_GET(tp, GSM0808_IE_LAYER_3_MESSAGE_CONTENTS);
195 int rc;
196 struct ran_msg ran_dec_msg = {
197 .msg_type = RAN_MSG_CIPHER_MODE_COMPLETE,
198 .msg_name = "BSSMAP Ciphering Mode Complete",
199 };
200
201 if (ie_chosen_encr_alg) {
202 uint8_t ie_val = ie_chosen_encr_alg->val[0];
203 /* 3GPP TS 48.008 3.2.2.44 Chosen Encryption Algorithm encodes as 1 = no encryption, 2 = A5/1, 4 = A5/3.
204 * Internally we handle without this weird off-by-one. */
205 if (ie_val < 1 || ie_val > 8)
206 LOG_RAN_A_DEC_MSG(LOGL_ERROR, "Unsupported value for 3.2.2.44 Chosen Encryption Algorithm: %u\n",
207 ie_val);
208 else
209 ran_dec_msg.cipher_mode_complete.alg_id = ie_chosen_encr_alg->val[0];
210 }
211
Neels Hofmeyre9a39112019-08-29 00:10:49 +0200212 if (ie_l3_msg)
213 ran_dec_msg.cipher_mode_complete.l3_msg = ie_l3_msg;
Neels Hofmeyrc4628a32018-12-07 14:47:34 +0100214
Neels Hofmeyre9a39112019-08-29 00:10:49 +0200215 rc = ran_decoded(ran_dec, &ran_dec_msg);
Neels Hofmeyrc4628a32018-12-07 14:47:34 +0100216
217 return rc;
218}
219
220static int ran_a_decode_cipher_mode_reject(struct ran_dec *ran_dec, struct msgb *msg, struct tlv_parsed *tp)
221{
222 int rc;
223 struct ran_msg ran_dec_msg = {
224 .msg_type = RAN_MSG_CIPHER_MODE_REJECT,
225 .msg_name = "BSSMAP Ciphering Mode Reject",
226 };
227
228 rc = gsm0808_get_cipher_reject_cause(tp);
229 if (rc < 0) {
230 LOG_RAN_A_DEC_MSG(LOGL_ERROR, "failed to extract Cause\n");
231 ran_dec_msg.cipher_mode_reject.bssap_cause = GSM0808_CAUSE_EQUIPMENT_FAILURE;
232 } else {
233 ran_dec_msg.cipher_mode_reject.bssap_cause = (enum gsm0808_cause)rc;
234 }
235
236 return ran_decoded(ran_dec, &ran_dec_msg);
237}
238
239enum mgcp_codecs ran_a_mgcp_codec_from_sc(const struct gsm0808_speech_codec *sc)
240{
241 switch (sc->type) {
242 case GSM0808_SCT_FR1:
243 return CODEC_GSM_8000_1;
244 break;
245 case GSM0808_SCT_FR2:
246 return CODEC_GSMEFR_8000_1;
247 break;
248 case GSM0808_SCT_FR3:
249 return CODEC_AMR_8000_1;
250 break;
251 case GSM0808_SCT_FR4:
252 return CODEC_AMRWB_16000_1;
253 break;
254 case GSM0808_SCT_FR5:
255 return CODEC_AMRWB_16000_1;
256 break;
257 case GSM0808_SCT_HR1:
258 return CODEC_GSMHR_8000_1;
259 break;
260 case GSM0808_SCT_HR3:
261 return CODEC_AMR_8000_1;
262 break;
263 case GSM0808_SCT_HR4:
264 return CODEC_AMRWB_16000_1;
265 break;
266 case GSM0808_SCT_HR6:
267 return CODEC_AMRWB_16000_1;
268 break;
269 default:
270 return CODEC_PCMU_8000_1;
271 break;
272 }
273}
274
275static int ran_a_decode_assignment_complete(struct ran_dec *ran_dec, struct msgb *msg, struct tlv_parsed *tp)
276{
277 struct tlv_p_entry *ie_aoip_transp_addr = TLVP_GET(tp, GSM0808_IE_AOIP_TRASP_ADDR);
278 struct tlv_p_entry *ie_speech_codec = TLVP_GET(tp, GSM0808_IE_SPEECH_CODEC);
Neels Hofmeyr8a50cfb2019-10-21 03:01:00 +0200279 struct tlv_p_entry *ie_codec_list_bss_supported = TLVP_GET(tp, GSM0808_IE_SPEECH_CODEC_LIST);
Pau Espin Pedrola3cdab42019-05-09 17:54:08 +0200280 struct tlv_p_entry *ie_osmux_cid = TLVP_GET(tp, GSM0808_IE_OSMO_OSMUX_CID);
Neels Hofmeyrc4628a32018-12-07 14:47:34 +0100281 struct sockaddr_storage rtp_addr;
282 struct sockaddr_in *rtp_addr_in;
283 struct gsm0808_speech_codec sc;
Neels Hofmeyr8a50cfb2019-10-21 03:01:00 +0200284 struct gsm0808_speech_codec_list codec_list_bss_supported;
Neels Hofmeyrc4628a32018-12-07 14:47:34 +0100285 int rc;
286 struct ran_msg ran_dec_msg = {
287 .msg_type = RAN_MSG_ASSIGNMENT_COMPLETE,
288 .msg_name = "BSSMAP Assignment Complete",
289 };
290
291 if (ie_aoip_transp_addr) {
292 /* Decode AoIP transport address element */
293 rc = gsm0808_dec_aoip_trasp_addr(&rtp_addr, ie_aoip_transp_addr->val, ie_aoip_transp_addr->len);
294 if (rc < 0) {
295 LOG_RAN_A_DEC_MSG(LOGL_ERROR, "Unable to decode AoIP Transport Layer Address\n");
296 return -EINVAL;
297 }
298
299 rtp_addr_in = (struct sockaddr_in*)&rtp_addr;
300
301 if (rtp_addr.ss_family != AF_INET) {
302 LOG_RAN_A_DEC_MSG(LOGL_ERROR, "Assignment Complete: IE AoIP Transport Address:"
303 " unsupported addressing scheme (only IPV4 supported)\n");
304 return -EINVAL;
305 }
306
307 if (osmo_sockaddr_str_from_sockaddr_in(&ran_dec_msg.assignment_complete.remote_rtp, rtp_addr_in)) {
308 LOG_RAN_A_DEC_MSG(LOGL_ERROR, "Assignment Complete: unable to decode remote RTP IP address\n");
309 return -EINVAL;
310 }
311 }
312
Pau Espin Pedrola3cdab42019-05-09 17:54:08 +0200313 if (ie_osmux_cid) {
314 rc = gsm0808_dec_osmux_cid(&ran_dec_msg.assignment_complete.osmux_cid, ie_osmux_cid->val, ie_osmux_cid->len);
315 if (rc < 0) {
316 LOG_RAN_A_DEC_MSG(LOGL_ERROR, "Unable to decode Osmux CID\n");
317 return -EINVAL;
318 }
319 ran_dec_msg.assignment_complete.osmux_present = true;
320 }
321
Neels Hofmeyrc4628a32018-12-07 14:47:34 +0100322 if (ie_speech_codec) {
323 /* Decode Speech Codec (Chosen) element */
324 rc = gsm0808_dec_speech_codec(&sc, ie_speech_codec->val, ie_speech_codec->len);
325 if (rc < 0) {
326 LOG_RAN_A_DEC_MSG(LOGL_ERROR, "Assignment Complete: unable to decode IE Speech Codec (Chosen)"
327 " (rc=%d).\n", rc);
328 return -EINVAL;
329 }
330 ran_dec_msg.assignment_complete.codec_present = true;
331 ran_dec_msg.assignment_complete.codec = ran_a_mgcp_codec_from_sc(&sc);
332 }
333
Neels Hofmeyr8a50cfb2019-10-21 03:01:00 +0200334 if (ie_codec_list_bss_supported) {
335 /* Decode Codec List (BSS Supported) */
336 rc = gsm0808_dec_speech_codec_list(&codec_list_bss_supported,
337 ie_codec_list_bss_supported->val, ie_codec_list_bss_supported->len);
338 if (rc < 0) {
339 LOG_RAN_A_DEC_MSG(LOGL_ERROR,
340 "Assignment Complete: unable to decode IE Codec List (BSS Supported)"
341 " (rc=%d), continuing anyway\n", rc);
342 /* This IE is not critical, do not abort with error. */
343 } else
344 ran_dec_msg.assignment_complete.codec_list_bss_supported = &codec_list_bss_supported;
345 }
346
Neels Hofmeyrc4628a32018-12-07 14:47:34 +0100347 return ran_decoded(ran_dec, &ran_dec_msg);
348}
349
350static int ran_a_decode_assignment_failure(struct ran_dec *ran_dec, struct msgb *msg, struct tlv_parsed *tp)
351{
352 struct tlv_p_entry *ie_cause = TLVP_GET(tp, GSM0808_IE_CAUSE);
353 struct tlv_p_entry *ie_rr_cause = TLVP_GET(tp, GSM0808_IE_RR_CAUSE);
354 struct tlv_p_entry *ie_speech_codec_list = TLVP_GET(tp, GSM0808_IE_SPEECH_CODEC_LIST);
355 struct gsm0808_speech_codec_list scl;
356 struct ran_msg ran_dec_msg = {
357 .msg_type = RAN_MSG_ASSIGNMENT_FAILURE,
358 .msg_name = "BSSMAP Assignment Failure",
359 .assignment_failure = {
360 .bssap_cause = GSM0808_CAUSE_EQUIPMENT_FAILURE,
361 .rr_cause = GSM48_RR_CAUSE_ABNORMAL_UNSPEC,
362 },
363 };
364
365 if (ie_cause)
366 ran_dec_msg.assignment_failure.bssap_cause = ie_cause->val[0];
367 if (ie_rr_cause)
368 ran_dec_msg.assignment_failure.rr_cause = ie_rr_cause->val[0];
369
370 if (ie_speech_codec_list
371 && gsm0808_dec_speech_codec_list(&scl, ie_speech_codec_list->val, ie_speech_codec_list->len) == 0)
372 ran_dec_msg.assignment_failure.scl_bss_supported = &scl;
373
374 return ran_decoded(ran_dec, &ran_dec_msg);
375}
376
377static int ran_a_decode_sapi_n_reject(struct ran_dec *ran_dec, struct msgb *msg, struct tlv_parsed *tp)
378{
379 struct tlv_p_entry *ie_cause = TLVP_GET(tp, GSM0808_IE_CAUSE);
380 struct tlv_p_entry *ie_dlci = TLVP_GET(tp, GSM0808_IE_DLCI);
381 struct ran_msg ran_dec_msg = {
382 .msg_type = RAN_MSG_SAPI_N_REJECT,
383 .msg_name = "BSSMAP SAPI-N Reject",
384 };
385
386 /* Note: The MSC code seems not to care about the cause code, but by
387 * the specification it is mandatory, so we check its presence. See
388 * also 3GPP TS 48.008 3.2.1.34 SAPI "n" REJECT */
389 if (!ie_cause) {
390 LOG_RAN_A_DEC_MSG(LOGL_ERROR, "SAPI-N Reject: cause code IE is missing, discarding message\n");
391 return -EINVAL;
392 }
393 ran_dec_msg.sapi_n_reject.bssap_cause = ie_cause->val[0];
394
395 if (!ie_dlci) {
396 LOG_RAN_A_DEC_MSG(LOGL_ERROR, "SAPI-N Reject: DLCI IE is missing, discarding message\n");
397 return -EINVAL;
398 }
399 ran_dec_msg.sapi_n_reject.dlci = ie_dlci->val[0];
400
401 return ran_decoded(ran_dec, &ran_dec_msg);
402}
403
404static int ran_a_decode_lcls_notification(struct ran_dec *ran_dec, const struct msgb *msg, const struct tlv_parsed *tp)
405{
406 const struct tlv_p_entry *ie_lcls_bss_status = TLVP_GET(tp, GSM0808_IE_LCLS_BSS_STATUS);
407 const struct tlv_p_entry *ie_lcls_break_req = TLVP_GET(tp, GSM0808_IE_LCLS_BREAK_REQ);
408 struct ran_msg ran_dec_msg;
409
410 /* Either §3.2.2.119 LCLS-BSS-Status or §3.2.2.120 LCLS-Break-Request shall be present */
Vadim Yanitskiy18e8b392019-05-11 04:22:55 +0700411 if (ie_lcls_bss_status && !ie_lcls_break_req) {
Neels Hofmeyrc4628a32018-12-07 14:47:34 +0100412 ran_dec_msg = (struct ran_msg){
413 .msg_type = RAN_MSG_LCLS_STATUS,
414 .msg_name = "BSSMAP LCLS Notification (LCLS Status)",
415 .lcls_status = {
416 .status = ie_lcls_bss_status->len ?
417 ie_lcls_bss_status->val[0] : GSM0808_LCLS_STS_NA,
418 },
419 };
420 return ran_decoded(ran_dec, &ran_dec_msg);
Vadim Yanitskiy18e8b392019-05-11 04:22:55 +0700421 } else if (ie_lcls_break_req && !ie_lcls_bss_status) {
Neels Hofmeyrc4628a32018-12-07 14:47:34 +0100422 ran_dec_msg = (struct ran_msg){
423 .msg_type = RAN_MSG_LCLS_BREAK_REQ,
424 .msg_name = "BSSMAP LCLS Notification (LCLS Break Req)",
425 .lcls_break_req = {
426 .todo = 23,
427 },
428 };
429 return ran_decoded(ran_dec, &ran_dec_msg);
430 }
431
Vadim Yanitskiy18e8b392019-05-11 04:22:55 +0700432 LOG_RAN_A_DEC(ran_dec, LOGL_ERROR, "Ignoring broken LCLS Notification message\n");
Neels Hofmeyrc4628a32018-12-07 14:47:34 +0100433 return -EINVAL;
434}
435
436static int ran_a_decode_handover_required(struct ran_dec *ran_dec, const struct msgb *msg, const struct tlv_parsed *tp)
437{
438 const struct tlv_p_entry *ie_cause = TLVP_GET(tp, GSM0808_IE_CAUSE);
439 const struct tlv_p_entry *ie_cil = TLVP_GET(tp, GSM0808_IE_CELL_IDENTIFIER_LIST);
440 struct ran_msg ran_dec_msg = {
441 .msg_type = RAN_MSG_HANDOVER_REQUIRED,
442 .msg_name = "BSSMAP Handover Required",
443 };
444 /* On decoding failures, dispatch an invalid RAN_MSG_HANDOVER_REQUIRED so msc_a can pass down a
445 * BSS_MAP_MSG_HANDOVER_REQUIRED_REJECT message. */
446
447 if (ie_cause)
448 ran_dec_msg.handover_required.cause = ie_cause->val[0];
449 else
450 LOG_RAN_A_DEC_MSG(LOGL_ERROR, "Cause IE missing\n");
451
452 if (!ie_cil
453 || gsm0808_dec_cell_id_list2(&ran_dec_msg.handover_required.cil, ie_cil->val, ie_cil->len) <= 0) {
454 LOG_RAN_A_DEC_MSG(LOGL_ERROR, "No or invalid Cell Identifier List IE\n");
455 ran_dec_msg.handover_required.cil = (struct gsm0808_cell_id_list2){};
456 }
457
458 return ran_decoded(ran_dec, &ran_dec_msg);
459}
460
461static uint8_t a5_encryption_mask_from_gsm0808_chosen_enc_alg(enum gsm0808_chosen_enc_alg val)
462{
463 return 1 << val;
464}
465
466static int ran_a_decode_handover_request(struct ran_dec *ran_dec, const struct msgb *msg, const struct tlv_parsed *tp)
467{
468 struct osmo_gsm48_classmark classmark = {};
469 struct ran_msg ran_dec_msg = {
470 .msg_type = RAN_MSG_HANDOVER_REQUEST,
471 .msg_name = "BSSMAP Handover Request",
472 .handover_request = {
473 .classmark = &classmark,
474 },
475 };
476 struct ran_handover_request *r = &ran_dec_msg.handover_request;
477
478 const struct tlv_p_entry *ie_channel_type = TLVP_GET(tp, GSM0808_IE_CHANNEL_TYPE);
479 const struct tlv_p_entry *ie_encryption_information = TLVP_GET(tp, GSM0808_IE_ENCRYPTION_INFORMATION);
480 const struct tlv_p_entry *ie_classmark1 = TLVP_GET(tp, GSM0808_IE_CLASSMARK_INFORMATION_TYPE_1);
481 const struct tlv_p_entry *ie_classmark2 = TLVP_GET(tp, GSM0808_IE_CLASSMARK_INFORMATION_T2);
482 const struct tlv_p_entry *ie_cell_id_serving = TLVP_GET(&tp[0], GSM0808_IE_CELL_IDENTIFIER);
483 const struct tlv_p_entry *ie_cell_id_target = TLVP_GET(&tp[1], GSM0808_IE_CELL_IDENTIFIER);
484 const struct tlv_p_entry *ie_cause = TLVP_GET(tp, GSM0808_IE_CAUSE);
485 const struct tlv_p_entry *ie_classmark3 = TLVP_GET(tp, GSM0808_IE_CLASSMARK_INFORMATION_T3);
486 const struct tlv_p_entry *ie_current_channel_type_1 = TLVP_GET(tp, GSM0808_IE_CURRENT_CHANNEL_TYPE_1);
487 const struct tlv_p_entry *ie_speech_version_used = TLVP_GET(tp, GSM0808_IE_SPEECH_VERSION);
488 const struct tlv_p_entry *ie_chosen_encr_alg_serving = TLVP_GET(tp, GSM0808_IE_CHOSEN_ENCR_ALG);
489 const struct tlv_p_entry *ie_old_bss_to_new_bss_info = TLVP_GET(tp, GSM0808_IE_OLD_BSS_TO_NEW_BSS_INFORMATION);
490 const struct tlv_p_entry *ie_imsi = TLVP_GET(tp, GSM0808_IE_IMSI);
491 const struct tlv_p_entry *ie_aoip_transp_addr = TLVP_GET(tp, GSM0808_IE_AOIP_TRASP_ADDR);
492 const struct tlv_p_entry *ie_codec_list_msc_preferred = TLVP_GET(tp, GSM0808_IE_SPEECH_CODEC_LIST);
493 const struct tlv_p_entry *ie_call_id = TLVP_GET(tp, GSM0808_IE_CALL_ID);
494 const struct tlv_p_entry *ie_global_call_ref = TLVP_GET(tp, GSM0808_IE_GLOBAL_CALL_REF);
495
496 struct gsm0808_channel_type channel_type;
497 struct gsm0808_encrypt_info encr_info;
498 struct gsm0808_speech_codec_list scl;
499 struct geran_encr geran_encr = {};
500 char imsi[OSMO_IMSI_BUF_SIZE];
501 struct osmo_sockaddr_str rtp_ran_local;
502
503 if (!ie_channel_type) {
504 LOG_RAN_A_DEC_MSG(LOGL_ERROR, "Mandatory IE missing: Channel Type\n");
505 return -EINVAL;
506 }
507 if (gsm0808_dec_channel_type(&channel_type, ie_channel_type->val, ie_channel_type->len) <= 0) {
508 LOG_RAN_A_DEC_MSG(LOGL_ERROR, "Failed to decode Channel Type IE\n");
509 return -EINVAL;
510 }
511 r->geran.channel_type = &channel_type;
512
513 if (ie_encryption_information) {
514 int i;
515 if (gsm0808_dec_encrypt_info(&encr_info, ie_encryption_information->val, ie_encryption_information->len)
516 <= 0) {
Martin Hauke3f07dac2019-11-14 17:49:08 +0100517 LOG_RAN_A_DEC_MSG(LOGL_ERROR, "Failed to decode Encryption Information IE\n");
Neels Hofmeyrc4628a32018-12-07 14:47:34 +0100518 return -EINVAL;
519 }
520
521 for (i = 0; i < encr_info.perm_algo_len; i++) {
522 r->geran.a5_encryption_mask |=
523 a5_encryption_mask_from_gsm0808_chosen_enc_alg(encr_info.perm_algo[i]);
524 }
525
526 if (encr_info.key_len > sizeof(geran_encr.key)) {
Martin Hauke3f07dac2019-11-14 17:49:08 +0100527 LOG_RAN_A_DEC_MSG(LOGL_ERROR, "Failed to decode Encryption Information IE:"
Neels Hofmeyrc4628a32018-12-07 14:47:34 +0100528 " encryption key is too long: %u\n", geran_encr.key_len);
529 return -EINVAL;
530 }
531
532 if (encr_info.key_len) {
533 memcpy(geran_encr.key, encr_info.key, encr_info.key_len);
534 geran_encr.key_len = encr_info.key_len;
535 }
536
537 r->geran.chosen_encryption = &geran_encr;
538 }
539
540 if (!ie_classmark1 && !ie_classmark2) {
541 LOG_RAN_A_DEC_MSG(LOGL_ERROR, "Mandatory IE missing: either Classmark Information 1"
542 " or Classmark Information 2 must be included\n");
543 return -EINVAL;
544 }
545
546 if (ie_classmark1) {
547 if (ie_classmark1->len != sizeof(classmark.classmark1)) {
548 LOG_RAN_A_DEC_MSG(LOGL_ERROR, "Invalid size for Classmark 1: %u, expected %zu\n",
549 ie_classmark1->len, sizeof(classmark.classmark1));
550 return -EINVAL;
551 }
552 memcpy((uint8_t*)&classmark.classmark1, ie_classmark1->val, ie_classmark1->len);
553 classmark.classmark1_set = true;
554 }
555
556 if (ie_classmark2) {
557 uint8_t len = OSMO_MIN(ie_classmark2->len, sizeof(classmark.classmark2));
558 memcpy((uint8_t*)&classmark.classmark2, ie_classmark2->val, len);
559 classmark.classmark2_len = len;
560 }
561
562 if (!ie_cell_id_serving) {
563 LOG_RAN_A_DEC_MSG(LOGL_ERROR, "Mandatory IE missing: Cell Identifier (Serving)\n");
564 return -EINVAL;
565 }
566 if (gsm0808_dec_cell_id(&r->cell_id_serving, ie_cell_id_serving->val,
567 ie_cell_id_serving->len) <= 0) {
568 LOG_RAN_A_DEC_MSG(LOGL_ERROR, "Failed to decode Cell Identifier (Serving) IE\n");
569 return -EINVAL;
570 }
571
572 if (!ie_cell_id_target) {
573 LOG_RAN_A_DEC_MSG(LOGL_ERROR, "Mandatory IE missing: Cell Identifier (Target)\n");
574 return -EINVAL;
575 }
576 if (gsm0808_dec_cell_id(&r->cell_id_target, ie_cell_id_target->val,
577 ie_cell_id_target->len) <= 0) {
578 LOG_RAN_A_DEC_MSG(LOGL_ERROR, "Failed to decode Cell Identifier (Target) IE\n");
579 return -EINVAL;
580 }
581
582 if (ie_cause)
583 r->bssap_cause = ie_cause->val[0];
584
585 if (ie_classmark3) {
586 uint8_t len = OSMO_MIN(ie_classmark3->len, sizeof(classmark.classmark3));
587 memcpy(classmark.classmark3, ie_classmark3->val, len);
588 classmark.classmark3_len = len;
589 }
590
591 if (ie_current_channel_type_1) {
592 r->current_channel_type_1 = ie_current_channel_type_1->val[0];
593 r->current_channel_type_1_present = true;
594 }
595
596 if (ie_speech_version_used) {
597 r->speech_version_used = ie_speech_version_used->val[0];
598 }
599
600 if (ie_chosen_encr_alg_serving && ie_chosen_encr_alg_serving->len) {
601 geran_encr.alg_id = ie_chosen_encr_alg_serving->val[0];
602 r->geran.chosen_encryption = &geran_encr;
603 }
604
605 if (ie_old_bss_to_new_bss_info) {
606 r->old_bss_to_new_bss_info_raw = ie_old_bss_to_new_bss_info->val;
607 r->old_bss_to_new_bss_info_raw_len = ie_old_bss_to_new_bss_info->len;
608 }
609
610 if (ie_imsi) {
611 gsm48_mi_to_string(imsi, sizeof(imsi), ie_imsi->val, ie_imsi->len);
612 r->imsi = imsi;
613 }
614
615 if (ie_aoip_transp_addr) {
616 do {
617 struct sockaddr_storage rtp_addr;
618 if (gsm0808_dec_aoip_trasp_addr(&rtp_addr, ie_aoip_transp_addr->val, ie_aoip_transp_addr->len) < 0) {
619 LOG_RAN_A_DEC_MSG(LOGL_ERROR, "unable to decode AoIP transport address\n");
620 break;
621 }
622 if (rtp_addr.ss_family != AF_INET) {
623 LOG_RAN_A_DEC_MSG(LOGL_ERROR, "IE AoIP Transport Address:"
624 " unsupported addressing scheme (only IPV4 supported)\n");
625 break;
626 }
627 if (osmo_sockaddr_str_from_sockaddr_in(&rtp_ran_local, (struct sockaddr_in*)&rtp_addr)) {
628 LOG_RAN_A_DEC_MSG(LOGL_ERROR, "unable to decode remote RTP IP address\n");
629 break;
630 }
631 r->rtp_ran_local = &rtp_ran_local;
632 } while(0);
633 }
634
635 if (ie_codec_list_msc_preferred
636 && gsm0808_dec_speech_codec_list(&scl, ie_codec_list_msc_preferred->val,
637 ie_codec_list_msc_preferred->len) == 0)
638 r->codec_list_msc_preferred = &scl;
639
640 if (ie_call_id && ie_call_id->len == 4) {
641 r->call_id = osmo_load32le(ie_call_id->val);
642 r->call_id_present = true;
643 }
644
645 if (ie_global_call_ref) {
646 r->global_call_reference = ie_global_call_ref->val;
647 r->global_call_reference_len = ie_global_call_ref->len;
648 }
649
650 return ran_decoded(ran_dec, &ran_dec_msg);
651}
652
653static int ran_a_decode_handover_request_ack(struct ran_dec *ran_dec, const struct msgb *msg, const struct tlv_parsed *tp)
654{
655 struct ran_msg ran_dec_msg = {
656 .msg_type = RAN_MSG_HANDOVER_REQUEST_ACK,
657 .msg_name = "BSSMAP Handover Request Acknowledge",
658 };
659 const struct tlv_p_entry *ie_l3_info = TLVP_GET(tp, GSM0808_IE_LAYER_3_INFORMATION);
660 const struct tlv_p_entry *ie_aoip_transp_addr = TLVP_GET(tp, GSM0808_IE_AOIP_TRASP_ADDR);
661 const struct tlv_p_entry *ie_speech_codec = TLVP_GET(tp, GSM0808_IE_SPEECH_CODEC);
662 const struct tlv_p_entry *ie_chosen_channel = TLVP_GET(tp, GSM0808_IE_CHOSEN_CHANNEL);
663 const struct tlv_p_entry *ie_chosen_encr_alg = TLVP_GET(tp, GSM0808_IE_CHOSEN_ENCR_ALG);
664 const struct tlv_p_entry *ie_chosen_speech_version = TLVP_GET(tp, GSM0808_IE_SPEECH_VERSION);
665
666 /* On missing mandatory IEs, dispatch an invalid RAN_MSG_HANDOVER_REQUEST_ACK so msc_a can act on the failure. */
667
668 if (ie_l3_info) {
669 ran_dec_msg.handover_request_ack.rr_ho_command = ie_l3_info->val;
670 ran_dec_msg.handover_request_ack.rr_ho_command_len = ie_l3_info->len;
671 }
672
673 if (ie_chosen_channel) {
674 ran_dec_msg.handover_request_ack.chosen_channel_present = true;
675 ran_dec_msg.handover_request_ack.chosen_channel = *ie_chosen_channel->val;
676 }
677
678 if (ie_chosen_encr_alg) {
679 ran_dec_msg.handover_request_ack.chosen_encr_alg = *ie_chosen_encr_alg->val;
680 if (ran_dec_msg.handover_request_ack.chosen_encr_alg < 1
681 || ran_dec_msg.handover_request_ack.chosen_encr_alg > 8) {
682 LOG_RAN_A_DEC_MSG(LOGL_ERROR, "invalid Chosen Encryption Algorithm: %u\n",
683 ran_dec_msg.handover_request_ack.chosen_encr_alg);
684 }
685 }
686
687 if (ie_chosen_speech_version) {
688 struct gsm0808_speech_codec sc;
689 ran_dec_msg.handover_request_ack.chosen_speech_version = ie_chosen_speech_version->val[0];
690
691 /* the codec may be extrapolated from this Speech Version or below from Speech Codec */
692 gsm0808_speech_codec_from_chan_type(&sc, ran_dec_msg.handover_request_ack.chosen_speech_version);
693 ran_dec_msg.handover_request_ack.codec_present = true;
694 ran_dec_msg.handover_request_ack.codec = ran_a_mgcp_codec_from_sc(&sc);
695 }
696
697 if (ie_aoip_transp_addr) {
698 do {
699 struct sockaddr_storage rtp_addr;
700 if (gsm0808_dec_aoip_trasp_addr(&rtp_addr, ie_aoip_transp_addr->val, ie_aoip_transp_addr->len) < 0) {
701 LOG_RAN_A_DEC_MSG(LOGL_ERROR, "unable to decode AoIP transport address\n");
702 break;
703 }
704 if (rtp_addr.ss_family != AF_INET) {
705 LOG_RAN_A_DEC_MSG(LOGL_ERROR, "IE AoIP Transport Address:"
706 " unsupported addressing scheme (only IPV4 supported)\n");
707 break;
708 }
709 if (osmo_sockaddr_str_from_sockaddr_in(&ran_dec_msg.handover_request_ack.remote_rtp,
710 (struct sockaddr_in*)&rtp_addr)) {
711 LOG_RAN_A_DEC_MSG(LOGL_ERROR, "unable to decode remote RTP IP address\n");
712 ran_dec_msg.handover_request_ack.remote_rtp = (struct osmo_sockaddr_str){};
713 break;
714 }
715 } while(0);
716 }
717
718 if (ie_speech_codec) {
719 struct gsm0808_speech_codec sc;
720 if (gsm0808_dec_speech_codec(&sc, ie_speech_codec->val, ie_speech_codec->len) < 0)
721 LOG_RAN_A_DEC_MSG(LOGL_ERROR, "unable to decode IE Speech Codec (Chosen)\n");
722 else {
723 /* the codec may be extrapolated from above Speech Version or from this Speech Codec */
724 ran_dec_msg.handover_request_ack.codec_present = true;
725 ran_dec_msg.handover_request_ack.codec = ran_a_mgcp_codec_from_sc(&sc);
726 }
727 }
728
729 return ran_decoded(ran_dec, &ran_dec_msg);
730}
731
732static int ran_a_decode_handover_detect(struct ran_dec *ran_dec, const struct msgb *msg, const struct tlv_parsed *tp)
733{
734 struct ran_msg ran_dec_msg = {
735 .msg_type = RAN_MSG_HANDOVER_DETECT,
736 .msg_name = "BSSMAP Handover Detect",
737 };
738
739 return ran_decoded(ran_dec, &ran_dec_msg);
740}
741
742static int ran_a_decode_handover_succeeded(struct ran_dec *ran_dec, const struct msgb *msg, const struct tlv_parsed *tp)
743{
744 struct ran_msg ran_dec_msg = {
745 .msg_type = RAN_MSG_HANDOVER_SUCCEEDED,
746 .msg_name = "BSSMAP Handover Succeeded",
747 };
748
749 return ran_decoded(ran_dec, &ran_dec_msg);
750}
751
752static int ran_a_decode_handover_complete(struct ran_dec *ran_dec, const struct msgb *msg, const struct tlv_parsed *tp)
753{
754 struct ran_msg ran_dec_msg = {
755 .msg_type = RAN_MSG_HANDOVER_COMPLETE,
756 .msg_name = "BSSMAP Handover Complete",
757 };
758
759 return ran_decoded(ran_dec, &ran_dec_msg);
760}
761
762static int ran_a_decode_handover_failure(struct ran_dec *ran_dec, const struct msgb *msg, const struct tlv_parsed *tp)
763{
764 struct ran_msg ran_dec_msg = {
765 .msg_type = RAN_MSG_HANDOVER_FAILURE,
766 .msg_name = "BSSMAP Handover Failure",
767 };
768
769 return ran_decoded(ran_dec, &ran_dec_msg);
770}
771
772static int ran_a_decode_bssmap(struct ran_dec *ran_dec, struct msgb *bssmap)
773{
774 struct tlv_parsed tp[2];
775 int rc;
776 struct bssmap_header *h = msgb_l2(bssmap);
777 uint8_t msg_type;
778 bssmap->l3h = bssmap->l2h + sizeof(*h);
779
780 if (msgb_l3len(bssmap) < 1) {
781 LOG_RAN_A_DEC(ran_dec, LOGL_ERROR, "No data received, discarding message\n");
782 return -1;
783 }
784
785 if (msgb_l3len(bssmap) < h->length) {
Neels Hofmeyrf0923012019-08-22 17:19:49 +0200786 LOG_RAN_A_DEC(ran_dec, LOGL_ERROR, "BSSMAP data truncated, discarding message:"
787 " msgb_l3len(bssmap) == %u < bssmap_header->length == %u\n",
788 msgb_l3len(bssmap), h->length);
Neels Hofmeyrc4628a32018-12-07 14:47:34 +0100789 return -1;
790 }
791
792 if (msgb_l3len(bssmap) > h->length) {
Neels Hofmeyrf0923012019-08-22 17:19:49 +0200793 LOG_RAN_A_DEC(ran_dec, LOGL_NOTICE, "There are %u extra bytes after the BSSMAP data, truncating:"
794 " msgb_l3len(bssmap) == %u > bssmap_header->length == %u\n",
795 msgb_l3len(bssmap) - h->length,
796 msgb_l3len(bssmap), h->length);
Neels Hofmeyrc4628a32018-12-07 14:47:34 +0100797 msgb_l3trim(bssmap, h->length);
798 }
799
800 /* h->type == BSSAP_MSG_BSS_MANAGEMENT; h->length is the data length,
801 * which starts with the MAP msg_type, followed by IEs. */
802 msg_type = bssmap->l3h[0];
803 rc = osmo_bssap_tlv_parse2(tp, ARRAY_SIZE(tp), bssmap->l3h + 1, h->length - 1);
804 if (rc < 0) {
805 LOG_RAN_A_DEC(ran_dec, LOGL_ERROR, "Failed parsing TLV, discarding message\n");
806 return -EINVAL;
807 }
808
Neels Hofmeyr72fc7062019-10-08 06:24:17 +0200809 LOG_RAN_A_DEC(ran_dec, LOGL_DEBUG, "%s\n", gsm0808_bssmap_name(msg_type));
Neels Hofmeyrc4628a32018-12-07 14:47:34 +0100810
811 switch (msg_type) {
812 case BSS_MAP_MSG_COMPLETE_LAYER_3:
813 return ran_a_decode_l3_compl(ran_dec, bssmap, tp);
814 case BSS_MAP_MSG_CLEAR_RQST:
815 return ran_a_decode_clear_request(ran_dec, bssmap, tp);
816 case BSS_MAP_MSG_CLEAR_COMPLETE:
817 return ran_a_decode_clear_complete(ran_dec, bssmap, tp);
818 case BSS_MAP_MSG_CLASSMARK_UPDATE:
819 return ran_a_decode_classmark_update(ran_dec, bssmap, tp);
820 case BSS_MAP_MSG_CIPHER_MODE_COMPLETE:
821 return ran_a_decode_cipher_mode_complete(ran_dec, bssmap, tp);
822 case BSS_MAP_MSG_CIPHER_MODE_REJECT:
823 return ran_a_decode_cipher_mode_reject(ran_dec, bssmap, tp);
824 case BSS_MAP_MSG_ASSIGMENT_COMPLETE:
825 rc = ran_a_decode_assignment_complete(ran_dec, bssmap, tp);
826 if (rc < 0) {
827 struct ran_msg ran_dec_msg = {
828 .msg_type = RAN_MSG_ASSIGNMENT_FAILURE,
829 .msg_name = "BSSMAP Assignment Complete but failed to decode",
830 .clear_request = {
831 .bssap_cause = GSM0808_CAUSE_EQUIPMENT_FAILURE,
832 },
833 };
834 ran_decoded(ran_dec, &ran_dec_msg);
835 }
836 return rc;
837 case BSS_MAP_MSG_ASSIGMENT_FAILURE:
838 return ran_a_decode_assignment_failure(ran_dec, bssmap, tp);
839 case BSS_MAP_MSG_SAPI_N_REJECT:
840 return ran_a_decode_sapi_n_reject(ran_dec, bssmap, tp);
841 case BSS_MAP_MSG_LCLS_NOTIFICATION:
842 return ran_a_decode_lcls_notification(ran_dec, bssmap, tp);
843
844 /* From current RAN peer, the Handover origin: */
845 case BSS_MAP_MSG_HANDOVER_REQUIRED:
846 return ran_a_decode_handover_required(ran_dec, bssmap, tp);
847
848 /* From current MSC to remote handover target MSC */
849 case BSS_MAP_MSG_HANDOVER_RQST:
850 return ran_a_decode_handover_request(ran_dec, bssmap, tp);
851
852 /* From potential new RAN peer, the Handover target: */
853 case BSS_MAP_MSG_HANDOVER_RQST_ACKNOWLEDGE:
854 return ran_a_decode_handover_request_ack(ran_dec, bssmap, tp);
855 case BSS_MAP_MSG_HANDOVER_DETECT:
856 return ran_a_decode_handover_detect(ran_dec, bssmap, tp);
857 case BSS_MAP_MSG_HANDOVER_SUCCEEDED:
858 return ran_a_decode_handover_succeeded(ran_dec, bssmap, tp);
859 case BSS_MAP_MSG_HANDOVER_COMPLETE:
860 return ran_a_decode_handover_complete(ran_dec, bssmap, tp);
861
862 /* From any Handover peer: */
863 case BSS_MAP_MSG_HANDOVER_FAILURE:
864 return ran_a_decode_handover_failure(ran_dec, bssmap, tp);
865
866 default:
867 LOG_RAN_A_DEC(ran_dec, LOGL_ERROR, "Unimplemented msg type: %s\n", gsm0808_bssmap_name(msg_type));
868 return -EINVAL;
869 }
870
871 return -EINVAL;
872}
873
874static int ran_a_decode_l3(struct ran_dec *ran_dec, struct msgb *l3)
875{
876 struct dtap_header *dtap = msgb_l2(l3);
877 struct ran_msg ran_dec_msg = {
878 .msg_type = RAN_MSG_DTAP,
879 .msg_name = "BSSAP DTAP",
880 .dtap = l3,
881 };
882 l3->l3h = l3->l2h + sizeof(struct dtap_header);
883 OMSC_LINKID_CB(l3) = dtap->link_id;
884 return ran_decoded(ran_dec, &ran_dec_msg);
885}
886
887int ran_a_decode_l2(struct ran_dec *ran_dec, struct msgb *bssap)
888{
889 uint8_t bssap_type;
890 OSMO_ASSERT(bssap);
891
892 if (!msgb_l2(bssap) || !msgb_l2len(bssap)) {
893 LOG_RAN_A_DEC(ran_dec, LOGL_ERROR, "Cannot decode L2, msg->l2h is unset / empty: %s\n",
894 msgb_hexdump(bssap));
895 return -EINVAL;
896 }
897
898 if (msgb_l2len(bssap) < sizeof(struct bssmap_header)) {
899 LOG_RAN_A_DEC(ran_dec, LOGL_ERROR, "The header is too short -- discarding message\n");
900 return -EINVAL;
901 }
902
903 bssap_type = bssap->l2h[0];
904 switch (bssap_type) {
905 case BSSAP_MSG_BSS_MANAGEMENT:
906 return ran_a_decode_bssmap(ran_dec, bssap);
907 case BSSAP_MSG_DTAP:
908 return ran_a_decode_l3(ran_dec, bssap);
909 default:
910 LOG_RAN_A_DEC(ran_dec, LOGL_ERROR, "Unimplemented BSSAP msg type: %s\n", gsm0808_bssap_name(bssap_type));
911 return -EINVAL;
912 }
913}
914
915static struct msgb *ran_a_wrap_dtap(struct msgb *dtap)
916{
917 struct msgb *an_apdu;
918 dtap->l3h = dtap->data;
919 an_apdu = gsm0808_create_dtap(dtap, OMSC_LINKID_CB(dtap));
920 an_apdu->l2h = an_apdu->data;
921 msgb_free(dtap);
922 return an_apdu;
923}
924
925static int ran_a_channel_type_to_speech_codec_list(struct gsm0808_speech_codec_list *scl, const struct gsm0808_channel_type *ct)
926{
927 unsigned int i;
928 int rc;
929
930 memset(scl, 0, sizeof(*scl));
931 for (i = 0; i < ct->perm_spch_len; i++) {
932 rc = gsm0808_speech_codec_from_chan_type(&scl->codec[i], ct->perm_spch[i]);
933 if (rc != 0)
934 return -EINVAL;
935 }
936 scl->len = i;
937
938 return 0;
939}
940
Pau Espin Pedrola3cdab42019-05-09 17:54:08 +0200941static void _gsm0808_assignment_extend_osmux(struct msgb *msg, uint8_t cid)
942{
943 OSMO_ASSERT(msg->l3h[1] == msgb_l3len(msg) - 2); /*TL not in len */
944 msgb_tv_put(msg, GSM0808_IE_OSMO_OSMUX_CID, cid);
945 msg->l3h[1] = msgb_l3len(msg) - 2;
946}
947
Neels Hofmeyrc4628a32018-12-07 14:47:34 +0100948/* Compose a BSSAP Assignment Command.
949 * Passing an RTP address is optional.
950 * The msub is passed merely for error logging. */
951static struct msgb *ran_a_make_assignment_command(struct osmo_fsm_inst *log_fi,
952 const struct ran_assignment_command *ac)
953{
954 struct gsm0808_speech_codec_list scl;
955 struct gsm0808_speech_codec_list *use_scl = NULL;
956 struct sockaddr_storage rtp_addr;
957 struct sockaddr_storage *use_rtp_addr = NULL;
Pau Espin Pedrola3cdab42019-05-09 17:54:08 +0200958 struct msgb *msg;
Neels Hofmeyrc4628a32018-12-07 14:47:34 +0100959 int rc;
960
961 if (!ac->channel_type) {
962 LOG_RAN_A_ENC(log_fi, LOGL_ERROR, "Assignment Command: missing Channel Type\n");
963 return NULL;
964 }
965
966 if (ac->channel_type->ch_indctr == GSM0808_CHAN_SPEECH) {
967 rc = ran_a_channel_type_to_speech_codec_list(&scl, ac->channel_type);
968 if (rc < 0) {
969 LOG_RAN_A_ENC(log_fi, LOGL_ERROR, "Assignment Command: Cannot translate Channel Type to Speech Codec List\n");
970 return NULL;
971 }
972 use_scl = &scl;
973
974 /* Package RTP-Address data */
Neels Hofmeyr84ce2062019-10-05 05:15:25 +0200975 if (osmo_sockaddr_str_is_nonzero(ac->cn_rtp)) {
Neels Hofmeyrc4628a32018-12-07 14:47:34 +0100976 struct sockaddr_in rtp_addr_in;
977
978 memset(&rtp_addr_in, 0, sizeof(rtp_addr_in));
979 rtp_addr_in.sin_family = AF_INET;
980 rtp_addr_in.sin_port = osmo_htons(ac->cn_rtp->port),
981 rtp_addr_in.sin_addr.s_addr = inet_addr(ac->cn_rtp->ip);
982
983 if (rtp_addr_in.sin_addr.s_addr == INADDR_NONE) {
984 LOG_RAN_A_ENC(log_fi, LOGL_ERROR, "Assignment Command: Invalid RTP-Address\n");
985 return NULL;
986 }
987 if (rtp_addr_in.sin_port == 0) {
988 LOG_RAN_A_ENC(log_fi, LOGL_ERROR, "Assignment Command: Invalid RTP-Port\n");
989 return NULL;
990 }
991
992 memset(&rtp_addr, 0, sizeof(rtp_addr));
993 memcpy(&rtp_addr, &rtp_addr_in, sizeof(rtp_addr_in));
994
995 use_rtp_addr = &rtp_addr;
996 }
997 }
998
Pau Espin Pedrola3cdab42019-05-09 17:54:08 +0200999 msg = gsm0808_create_ass(ac->channel_type, NULL, use_rtp_addr, use_scl, NULL);
1000 if (ac->osmux_present)
1001 _gsm0808_assignment_extend_osmux(msg, ac->osmux_cid);
1002 return msg;
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01001003}
1004
1005/* For an A5/N number a5_n set dst to the matching GSM0808_ALG_ID_A5_<n>. */
1006static int a5_n_to_gsm0808_chosen_enc_alg(uint8_t *dst, int a5_n)
1007{
1008 switch (a5_n) {
1009 case 0:
1010 *dst = GSM0808_ALG_ID_A5_0;
1011 return 0;
1012 case 1:
1013 *dst = GSM0808_ALG_ID_A5_1;
1014 return 0;
1015 case 2:
1016 *dst = GSM0808_ALG_ID_A5_2;
1017 return 0;
1018 case 3:
1019 *dst = GSM0808_ALG_ID_A5_3;
1020 return 0;
1021 default:
1022 return -ENOTSUP;
1023 }
1024}
1025
1026static int make_encrypt_info_perm_algo(struct osmo_fsm_inst *fi, struct gsm0808_encrypt_info *ei,
1027 uint8_t a5_encryption_mask, const struct osmo_gsm48_classmark *cm)
1028{
1029 int i;
1030 int j = 0;
1031 for (i = 0; i < 8; i++) {
1032 int supported;
1033
1034 /* A5/n permitted by osmo-msc.cfg? */
1035 if (!(a5_encryption_mask & (1 << i)))
1036 continue;
1037
1038 /* A5/n supported by MS? */
1039 supported = osmo_gsm48_classmark_supports_a5(cm, i);
1040 if (supported != 1)
1041 continue;
1042
1043 if (a5_n_to_gsm0808_chosen_enc_alg(&ei->perm_algo[j], i)) {
1044 LOG_RAN_A_ENC(fi, LOGL_ERROR, "Not supported: A5/%d algorithm\n", i);
1045 return -1;
1046 }
1047 j++;
1048 ei->perm_algo_len = j;
1049 }
1050 return 0;
1051}
1052
1053/* For ran_a_make_cipher_mode_command(), for
1054 * memcpy(ei.key, cm->vec->kc, sizeof(cm->vec->kc));
1055 */
1056osmo_static_assert(sizeof(((struct gsm0808_encrypt_info*)0)->key) >= sizeof(((struct osmo_auth_vector*)0)->kc),
1057 gsm0808_encrypt_info_key_fits_osmo_auth_vec_kc);
1058static struct msgb *ran_a_make_cipher_mode_command(struct osmo_fsm_inst *fi, const struct ran_cipher_mode_command *cm)
1059{
1060 struct gsm0808_encrypt_info ei = {};
1061 char buf[16 * 2 + 1];
1062 const uint8_t cipher_response_mode = 1;
1063
1064 if (make_encrypt_info_perm_algo(fi, &ei, cm->geran.a5_encryption_mask, cm->classmark))
1065 return NULL;
1066
1067 if (ei.perm_algo_len == 0) {
1068 LOG_RAN_A_ENC(fi, LOGL_ERROR, "cannot start ciphering, no intersection between MSC-configured"
1069 " and MS-supported A5 algorithms. MSC: 0x%02x MS: %s\n",
1070 cm->geran.a5_encryption_mask, osmo_gsm48_classmark_a5_name(cm->classmark));
1071 return NULL;
1072 }
1073
1074 /* In case of UMTS AKA, the Kc for ciphering must be derived from the 3G auth
1075 * tokens. vec->kc was calculated from the GSM algorithm and is not
1076 * necessarily a match for the UMTS AKA tokens. */
1077 if (cm->geran.umts_aka)
1078 osmo_auth_c3(ei.key, cm->vec->ck, cm->vec->ik);
1079 else
1080 memcpy(ei.key, cm->vec->kc, sizeof(cm->vec->kc));
1081 ei.key_len = sizeof(cm->vec->kc);
1082
1083 /* Store chosen GERAN key where the caller asked it to be stored.
1084 * alg_id remains unknown until we receive a Cipher Mode Complete from the BSC */
1085 if (cm->geran.chosen_key) {
1086 if (ei.key_len > sizeof(cm->geran.chosen_key->key)) {
1087 LOG_RAN_A_ENC(fi, LOGL_ERROR, "Chosen key is larger than I can store\n");
1088 return NULL;
1089 }
1090 memcpy(cm->geran.chosen_key->key, ei.key, ei.key_len);
1091 cm->geran.chosen_key->key_len = ei.key_len;
1092 }
1093
1094 LOG_RAN_A_ENC(fi, LOGL_DEBUG, "Tx BSSMAP CIPHER MODE COMMAND to BSC, %u ciphers (%s) key %s\n",
1095 ei.perm_algo_len, osmo_hexdump_nospc(ei.perm_algo, ei.perm_algo_len),
1096 osmo_hexdump_buf(buf, sizeof(buf), ei.key, ei.key_len, NULL, false));
1097 return gsm0808_create_cipher(&ei, cm->geran.retrieve_imeisv ? &cipher_response_mode : NULL);
1098}
1099
1100struct msgb *ran_a_make_handover_request(struct osmo_fsm_inst *log_fi, const struct ran_handover_request *n)
1101{
1102 struct sockaddr_storage ss;
1103 struct gsm0808_handover_request r = {
1104 .cell_identifier_serving = n->cell_id_serving,
1105 .cell_identifier_target = n->cell_id_target,
1106 .cause = n->bssap_cause,
1107 .current_channel_type_1_present = n->current_channel_type_1_present,
1108 .current_channel_type_1 = n->current_channel_type_1,
1109
1110 .speech_version_used = n->speech_version_used,
1111
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01001112 .old_bss_to_new_bss_info_raw = n->old_bss_to_new_bss_info_raw,
1113 .old_bss_to_new_bss_info_raw_len = n->old_bss_to_new_bss_info_raw_len,
1114
1115 .imsi = n->imsi,
1116 .codec_list_msc_preferred = n->codec_list_msc_preferred,
1117 .call_id = n->call_id,
1118 .global_call_reference = n->global_call_reference,
1119 .global_call_reference_len = n->global_call_reference_len,
1120 };
1121
1122 if (!n->geran.channel_type) {
1123 LOG_RAN_A_ENC(log_fi, LOGL_ERROR, "Channel Type required for encoding Handover Request in BSSAP\n");
1124 return NULL;
1125 }
1126 r.channel_type = *n->geran.channel_type;
1127
1128 /* Encryption Information */
1129 make_encrypt_info_perm_algo(log_fi, &r.encryption_information, n->geran.a5_encryption_mask, n->classmark);
1130 if (n->geran.chosen_encryption && n->geran.chosen_encryption->key_len) {
Vadim Yanitskiy444771d2019-05-11 04:46:24 +07001131 /* Prevent both source / destination buffer overrun / overflow */
1132 if (n->geran.chosen_encryption->key_len > sizeof(r.encryption_information.key)
1133 || n->geran.chosen_encryption->key_len > sizeof(n->geran.chosen_encryption->key)) {
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01001134 LOG_RAN_A_ENC(log_fi, LOGL_ERROR, "Handover Request: invalid chosen encryption key size %u\n",
1135 n->geran.chosen_encryption->key_len);
1136 return NULL;
1137 }
1138 memcpy(r.encryption_information.key,
1139 n->geran.chosen_encryption->key, n->geran.chosen_encryption->key_len);
1140 r.encryption_information.key_len = n->geran.chosen_encryption->key_len;
Vadim Yanitskiybfe8eb72019-05-11 03:52:28 +07001141 r.chosen_encryption_algorithm_serving = n->geran.chosen_encryption->alg_id;
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01001142 }
1143
1144 if (n->classmark)
1145 r.classmark_information = *n->classmark;
1146
Neels Hofmeyr84ce2062019-10-05 05:15:25 +02001147 if (osmo_sockaddr_str_is_nonzero(n->rtp_ran_local)) {
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01001148 if (osmo_sockaddr_str_to_sockaddr(n->rtp_ran_local, &ss)) {
1149 LOG_RAN_A_ENC(log_fi, LOGL_ERROR,
1150 "Handover Request: invalid AoIP Transport Layer address/port: "
1151 OSMO_SOCKADDR_STR_FMT "\n", OSMO_SOCKADDR_STR_FMT_ARGS(n->rtp_ran_local));
1152 return NULL;
1153 }
1154 r.aoip_transport_layer = &ss;
1155 }
1156
1157 return gsm0808_create_handover_request(&r);
1158}
1159
1160static struct msgb *ran_a_make_handover_request_ack(struct osmo_fsm_inst *caller_fi, const struct ran_handover_request_ack *r)
1161{
1162 struct sockaddr_storage ss;
1163 struct gsm0808_handover_request_ack params = {
1164 .l3_info = r->rr_ho_command,
1165 .l3_info_len = r->rr_ho_command_len,
1166 .chosen_channel_present = r->chosen_channel_present,
1167 .chosen_channel = r->chosen_channel,
1168 .chosen_encr_alg = r->chosen_encr_alg,
1169 .chosen_speech_version = r->chosen_speech_version,
1170 };
1171
Neels Hofmeyr84ce2062019-10-05 05:15:25 +02001172 if (osmo_sockaddr_str_is_nonzero(&r->remote_rtp)) {
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01001173 osmo_sockaddr_str_to_sockaddr(&r->remote_rtp, &ss);
1174 params.aoip_transport_layer = &ss;
1175 }
1176
1177 return gsm0808_create_handover_request_ack2(&params);
1178}
1179
1180struct msgb *ran_a_make_handover_command(struct osmo_fsm_inst *log_fi, const struct ran_handover_command *n)
1181{
1182 struct gsm0808_handover_command c = {
1183 .l3_info = n->rr_ho_command,
1184 .l3_info_len = n->rr_ho_command_len,
1185 };
1186
1187 return gsm0808_create_handover_command(&c);
1188}
1189
1190struct msgb *ran_a_make_handover_failure(struct osmo_fsm_inst *log_fi, const struct ran_msg *msg)
1191{
1192 struct gsm0808_handover_failure params = {
1193 .cause = msg->handover_failure.cause,
1194 };
1195 return gsm0808_create_handover_failure(&params);
1196}
1197
1198static struct msgb *_ran_a_encode(struct osmo_fsm_inst *caller_fi, const struct ran_msg *ran_enc_msg)
1199{
1200
1201 LOG_RAN_A_ENC(caller_fi, LOGL_DEBUG, "%s\n", ran_msg_type_name(ran_enc_msg->msg_type));
1202
1203 switch (ran_enc_msg->msg_type) {
1204
1205 case RAN_MSG_DTAP:
1206 return ran_a_wrap_dtap(ran_enc_msg->dtap);
1207
1208 case RAN_MSG_CLASSMARK_REQUEST:
1209 return gsm0808_create_classmark_request();
1210
1211 case RAN_MSG_CLEAR_COMMAND:
1212 return gsm0808_create_clear_command2(ran_enc_msg->clear_command.gsm0808_cause,
1213 ran_enc_msg->clear_command.csfb_ind);
1214
1215 case RAN_MSG_ASSIGNMENT_COMMAND:
1216 return ran_a_make_assignment_command(caller_fi, &ran_enc_msg->assignment_command);
1217
1218 case RAN_MSG_CIPHER_MODE_COMMAND:
1219 return ran_a_make_cipher_mode_command(caller_fi, &ran_enc_msg->cipher_mode_command);
1220
1221 case RAN_MSG_HANDOVER_REQUIRED_REJECT:
1222 return gsm0808_create_handover_required_reject(&ran_enc_msg->handover_required_reject);
1223
1224 case RAN_MSG_HANDOVER_REQUEST:
1225 return ran_a_make_handover_request(caller_fi, &ran_enc_msg->handover_request);
1226
1227 case RAN_MSG_HANDOVER_REQUEST_ACK:
1228 return ran_a_make_handover_request_ack(caller_fi, &ran_enc_msg->handover_request_ack);
1229
1230 case RAN_MSG_HANDOVER_COMMAND:
1231 return ran_a_make_handover_command(caller_fi, &ran_enc_msg->handover_command);
1232
1233 case RAN_MSG_HANDOVER_SUCCEEDED:
1234 return gsm0808_create_handover_succeeded();
1235
1236 case RAN_MSG_HANDOVER_FAILURE:
1237 return ran_a_make_handover_failure(caller_fi, ran_enc_msg);
1238
1239 default:
1240 LOG_RAN_A_ENC(caller_fi, LOGL_ERROR, "Unimplemented RAN-encode message type: %s\n",
1241 ran_msg_type_name(ran_enc_msg->msg_type));
1242 return NULL;
1243 }
1244}
1245
1246struct msgb *ran_a_encode(struct osmo_fsm_inst *caller_fi, const struct ran_msg *ran_enc_msg)
1247{
1248 struct msgb *msg = _ran_a_encode(caller_fi, ran_enc_msg);
1249
1250 if (!msg)
1251 return NULL;
1252
1253 msg->l2h = msg->data;
1254
1255 /* some consistency checks to ensure we don't send invalid length */
1256 switch (msg->l2h[0]) {
1257 case BSSAP_MSG_DTAP:
1258 OSMO_ASSERT(msgb_l2len(msg) == msg->l2h[2] + 3);
1259 break;
1260 case BSSAP_MSG_BSS_MANAGEMENT:
1261 OSMO_ASSERT(msgb_l2len(msg) == msg->l2h[1] + 2);
1262 break;
1263 default:
1264 break;
1265 }
1266
1267 return msg;
1268}
1269
1270/* Return 1 for a RESET, 2 for a RESET ACK message, 0 otherwise */
1271enum reset_msg_type bssmap_is_reset_msg(const struct sccp_ran_inst *sri, const struct msgb *l2)
1272{
1273 struct bssmap_header *bs = (struct bssmap_header *)msgb_l2(l2);
1274
1275 if (!bs
1276 || msgb_l2len(l2) < (sizeof(*bs) + 1)
1277 || bs->type != BSSAP_MSG_BSS_MANAGEMENT)
1278 return SCCP_RAN_MSG_NON_RESET;
1279
1280 switch (l2->l2h[sizeof(*bs)]) {
1281 case BSS_MAP_MSG_RESET:
1282 return SCCP_RAN_MSG_RESET;
1283 case BSS_MAP_MSG_RESET_ACKNOWLEDGE:
1284 return SCCP_RAN_MSG_RESET_ACK;
1285 default:
1286 return SCCP_RAN_MSG_NON_RESET;
1287 }
1288}
1289
Pau Espin Pedrolc9ba7542019-05-07 12:23:49 +02001290/* Patch regular BSSMAP RESET to add extra T to announce Osmux support (osmocom extension) */
1291static void _gsm0808_extend_announce_osmux(struct msgb *msg)
1292{
1293 OSMO_ASSERT(msg->l3h[1] == msgb_l3len(msg) - 2); /*TL not in len */
1294 msgb_put_u8(msg, GSM0808_IE_OSMO_OSMUX_SUPPORT);
1295 msg->l3h[1] = msgb_l3len(msg) - 2;
1296}
1297
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01001298struct msgb *bssmap_make_reset_msg(const struct sccp_ran_inst *sri, enum reset_msg_type type)
1299{
Pau Espin Pedrolc9ba7542019-05-07 12:23:49 +02001300 struct gsm_network *net = sri->user_data;
1301 struct msgb *msg;
1302
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01001303 switch (type) {
1304 case SCCP_RAN_MSG_RESET:
Pau Espin Pedrolc9ba7542019-05-07 12:23:49 +02001305 msg = gsm0808_create_reset();
1306 break;
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01001307 case SCCP_RAN_MSG_RESET_ACK:
Pau Espin Pedrolc9ba7542019-05-07 12:23:49 +02001308 msg = gsm0808_create_reset_ack();
1309 break;
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01001310 default:
1311 return NULL;
1312 }
Pau Espin Pedrolc9ba7542019-05-07 12:23:49 +02001313
1314 if (!msg)
1315 return NULL;
1316
1317 if (net->use_osmux != OSMUX_USAGE_OFF)
1318 _gsm0808_extend_announce_osmux(msg);
1319
1320 return msg;
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01001321}
1322
1323struct msgb *bssmap_make_paging_msg(const struct sccp_ran_inst *sri, const struct gsm0808_cell_id *page_cell_id,
1324 const char *imsi, uint32_t tmsi, enum paging_cause cause)
1325{
1326 struct gsm0808_cell_id_list2 cil;
1327 gsm0808_cell_id_to_list(&cil, page_cell_id);
1328 return gsm0808_create_paging2(imsi, tmsi == GSM_RESERVED_TMSI ? NULL : &tmsi, &cil, NULL);
1329}
1330
1331const char *bssmap_msg_name(const struct sccp_ran_inst *sri, const struct msgb *l2)
1332{
1333 struct bssmap_header *bs;
1334
1335 if (!l2->l2h)
1336 return "?";
1337
1338 bs = (struct bssmap_header *)msgb_l2(l2);
1339 switch (bs->type) {
1340 case BSSAP_MSG_BSS_MANAGEMENT:
1341 return gsm0808_bssmap_name(l2->l2h[0]);
1342 case BSSAP_MSG_DTAP:
1343 return "DTAP";
1344 default:
1345 return "?";
1346 }
1347}