blob: 4162944fce92986c9b122626c4c9b0e2985440c9 [file] [log] [blame]
Harald Welte27989d42018-06-21 20:39:20 +02001/* GSM Mobile Radio Interface Layer 3 Call Control */
2
3/* (C) 2008-2016 by Harald Welte <laforge@gnumonks.org>
4 * (C) 2008-2012 by Holger Hans Peter Freyther <zecke@selfish.org>
5 *
6 * All Rights Reserved
7 *
8 * This program is free software; you can redistribute it and/or modify
9 * it under the terms of the GNU Affero General Public License as published by
10 * the Free Software Foundation; either version 3 of the License, or
11 * (at your option) any later version.
12 *
13 * This program is distributed in the hope that it will be useful,
14 * but WITHOUT ANY WARRANTY; without even the implied warranty of
15 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
16 * GNU Affero General Public License for more details.
17 *
18 * You should have received a copy of the GNU Affero General Public License
19 * along with this program. If not, see <http://www.gnu.org/licenses/>.
20 *
21 */
22
23#include <stdio.h>
24#include <stdlib.h>
25#include <string.h>
26#include <stdbool.h>
27#include <errno.h>
28#include <time.h>
29#include <netinet/in.h>
30#include <regex.h>
31#include <sys/types.h>
32
Neels Hofmeyr5e19b9a2019-04-27 19:09:14 +020033#include <osmocom/mgcp_client/mgcp_client_endpoint_fsm.h>
34
Harald Welte27989d42018-06-21 20:39:20 +020035#include <osmocom/msc/db.h>
36#include <osmocom/msc/debug.h>
37#include <osmocom/msc/gsm_data.h>
38#include <osmocom/msc/gsm_subscriber.h>
39#include <osmocom/msc/gsm_04_11.h>
40#include <osmocom/msc/gsm_04_08.h>
41#include <osmocom/msc/gsm_04_80.h>
42#include <osmocom/msc/gsm_04_14.h>
43#include <osmocom/msc/gsm_09_11.h>
44#include <osmocom/msc/signal.h>
45#include <osmocom/msc/transaction.h>
Oliver Smith5375f782023-05-23 13:38:33 +020046#include <osmocom/msc/transaction_cc.h>
Harald Welte27989d42018-06-21 20:39:20 +020047#include <osmocom/msc/silent_call.h>
Harald Welte27989d42018-06-21 20:39:20 +020048#include <osmocom/msc/mncc_int.h>
49#include <osmocom/abis/e1_input.h>
50#include <osmocom/core/bitvec.h>
51#include <osmocom/msc/vlr.h>
Neels Hofmeyrc4628a32018-12-07 14:47:34 +010052#include <osmocom/msc/msub.h>
53#include <osmocom/msc/msc_a.h>
54#include <osmocom/msc/paging.h>
55#include <osmocom/msc/call_leg.h>
56#include <osmocom/msc/rtp_stream.h>
57#include <osmocom/msc/mncc_call.h>
58#include <osmocom/msc/msc_t.h>
Neels Hofmeyr58f40882023-03-08 04:04:27 +010059#include <osmocom/msc/sdp_msg.h>
Neels Hofmeyra001a702022-10-31 17:57:30 +010060#include <osmocom/msc/codec_mapping.h>
Harald Welte27989d42018-06-21 20:39:20 +020061
62#include <osmocom/gsm/gsm48.h>
63#include <osmocom/gsm/gsm0480.h>
64#include <osmocom/gsm/gsm_utils.h>
65#include <osmocom/gsm/protocol/gsm_04_08.h>
66#include <osmocom/core/msgb.h>
67#include <osmocom/core/talloc.h>
68#include <osmocom/core/utils.h>
69#include <osmocom/core/byteswap.h>
70#include <osmocom/gsm/tlv.h>
71#include <osmocom/crypt/auth.h>
Harald Welte27989d42018-06-21 20:39:20 +020072
73#include <assert.h>
74
Neels Hofmeyrc4628a32018-12-07 14:47:34 +010075static int gsm48_cc_tx_setup(struct gsm_trans *trans, void *arg);
76static int gsm48_cc_tx_release(struct gsm_trans *trans, void *arg);
77static int gsm48_cc_tx_disconnect(struct gsm_trans *trans, void *arg);
78
79static int trans_tx_gsm48(struct gsm_trans *trans, struct msgb *msg)
80{
81 struct gsm48_hdr *gh = (struct gsm48_hdr *) msg->data;
82 gh->proto_discr = GSM48_PDISC_CC | (trans->transaction_id << 4);
83 OMSC_LINKID_CB(msg) = trans->dlci;
84
85 return msc_a_tx_dtap_to_i(trans->msc_a, msg);
86}
87
88uint32_t msc_cc_next_outgoing_callref() {
89 static uint32_t last_callref = 0x80000000;
90 last_callref++;
91 if (last_callref < 0x80000001)
92 last_callref = 0x80000001;
93 return last_callref;
94}
Harald Welte27989d42018-06-21 20:39:20 +020095
Philipp Maier9ca7b312018-10-10 17:00:49 +020096static void gsm48_cc_guard_timeout(void *arg)
97{
98 struct gsm_trans *trans = arg;
Neels Hofmeyrff7074a2019-02-28 05:50:06 +010099 LOG_TRANS(trans, LOGL_DEBUG, "guard timeout expired\n");
Philipp Maier9ca7b312018-10-10 17:00:49 +0200100 trans_free(trans);
101 return;
102}
103
104static void gsm48_stop_guard_timer(struct gsm_trans *trans)
105{
106 if (osmo_timer_pending(&trans->cc.timer_guard)) {
Neels Hofmeyrff7074a2019-02-28 05:50:06 +0100107 LOG_TRANS(trans, LOGL_DEBUG, "stopping pending guard timer\n");
Philipp Maier9ca7b312018-10-10 17:00:49 +0200108 osmo_timer_del(&trans->cc.timer_guard);
109 }
110}
111
112static void gsm48_start_guard_timer(struct gsm_trans *trans)
113{
114 /* NOTE: The purpose of this timer is to prevent the cc state machine
115 * from hanging in cases where mncc, gsm48 or both become unresponsive
116 * for some reason. The timer is started initially with the setup from
117 * the gsm48 side and then re-started with every incoming mncc message.
118 * Once the mncc state reaches its active state the timer is stopped.
119 * So if the cc state machine does not show any activity for an
120 * extended amount of time during call setup or teardown the guard
121 * timer will time out and hard-clear the connection. */
122 if (osmo_timer_pending(&trans->cc.timer_guard))
123 gsm48_stop_guard_timer(trans);
Neels Hofmeyrff7074a2019-02-28 05:50:06 +0100124 LOG_TRANS(trans, LOGL_DEBUG, "starting guard timer with %d seconds\n", trans->net->mncc_guard_timeout);
Philipp Maier9ca7b312018-10-10 17:00:49 +0200125 osmo_timer_setup(&trans->cc.timer_guard, gsm48_cc_guard_timeout, trans);
126 osmo_timer_schedule(&trans->cc.timer_guard,
127 trans->net->mncc_guard_timeout, 0);
128}
Harald Welte27989d42018-06-21 20:39:20 +0200129
130/* Call Control */
131
132void cc_tx_to_mncc(struct gsm_network *net, struct msgb *msg)
133{
134 net->mncc_recv(net, msg);
135}
136
137int gsm48_cc_tx_notify_ss(struct gsm_trans *trans, const char *message)
138{
139 struct gsm48_hdr *gh;
140 struct msgb *ss_notify;
141
142 ss_notify = gsm0480_create_notifySS(message);
143 if (!ss_notify)
144 return -1;
145
146 gsm0480_wrap_invoke(ss_notify, GSM0480_OP_CODE_NOTIFY_SS, 0);
147 uint8_t *data = msgb_push(ss_notify, 1);
148 data[0] = ss_notify->len - 1;
149 gh = (struct gsm48_hdr *) msgb_push(ss_notify, sizeof(*gh));
150 gh->msg_type = GSM48_MT_CC_FACILITY;
Neels Hofmeyrc4628a32018-12-07 14:47:34 +0100151 return trans_tx_gsm48(trans, ss_notify);
Harald Welte27989d42018-06-21 20:39:20 +0200152}
153
154/* FIXME: this count_statistics is a state machine behaviour. we should convert
155 * the complete call control into a state machine. Afterwards we can move this
156 * code into state transitions.
157 */
158static void count_statistics(struct gsm_trans *trans, int new_state)
159{
160 int old_state = trans->cc.state;
161 struct rate_ctr_group *msc = trans->net->msc_ctrs;
162
163 if (old_state == new_state)
164 return;
165
166 /* state incoming */
167 switch (new_state) {
168 case GSM_CSTATE_ACTIVE:
Pau Espin Pedrol2e21a682021-06-04 16:45:44 +0200169 osmo_stat_item_inc(osmo_stat_item_group_get_item(trans->net->statg, MSC_STAT_ACTIVE_CALLS),
170 1);
171 rate_ctr_inc(rate_ctr_group_get_ctr(msc, MSC_CTR_CALL_ACTIVE));
Harald Welte27989d42018-06-21 20:39:20 +0200172 break;
173 }
174
175 /* state outgoing */
176 switch (old_state) {
177 case GSM_CSTATE_ACTIVE:
Pau Espin Pedrol2e21a682021-06-04 16:45:44 +0200178 osmo_stat_item_dec(osmo_stat_item_group_get_item(trans->net->statg, MSC_STAT_ACTIVE_CALLS),
179 1);
Harald Welte27989d42018-06-21 20:39:20 +0200180 if (new_state == GSM_CSTATE_DISCONNECT_REQ ||
181 new_state == GSM_CSTATE_DISCONNECT_IND)
Pau Espin Pedrol2e21a682021-06-04 16:45:44 +0200182 rate_ctr_inc(rate_ctr_group_get_ctr(msc, MSC_CTR_CALL_COMPLETE));
Harald Welte27989d42018-06-21 20:39:20 +0200183 else
Pau Espin Pedrol2e21a682021-06-04 16:45:44 +0200184 rate_ctr_inc(rate_ctr_group_get_ctr(msc, MSC_CTR_CALL_INCOMPLETE));
Harald Welte27989d42018-06-21 20:39:20 +0200185 break;
186 }
187}
188
Harald Welte27989d42018-06-21 20:39:20 +0200189static void new_cc_state(struct gsm_trans *trans, int state)
190{
191 if (state > 31 || state < 0)
192 return;
193
Neels Hofmeyrff7074a2019-02-28 05:50:06 +0100194 LOG_TRANS(trans, LOGL_DEBUG, "new state %s -> %s\n",
195 gsm48_cc_state_name(trans->cc.state),
196 gsm48_cc_state_name(state));
Harald Welte27989d42018-06-21 20:39:20 +0200197
198 count_statistics(trans, state);
199 trans->cc.state = state;
Philipp Maier9ca7b312018-10-10 17:00:49 +0200200
201 /* Stop the guard timer when a call reaches the active state */
202 if (state == GSM_CSTATE_ACTIVE)
203 gsm48_stop_guard_timer(trans);
Harald Welte27989d42018-06-21 20:39:20 +0200204}
205
206static int gsm48_cc_tx_status(struct gsm_trans *trans, void *arg)
207{
208 struct msgb *msg = gsm48_msgb_alloc_name("GSM 04.08 CC STATUS");
209 struct gsm48_hdr *gh = (struct gsm48_hdr *) msgb_put(msg, sizeof(*gh));
210 uint8_t *cause, *call_state;
211
212 gh->msg_type = GSM48_MT_CC_STATUS;
213
214 cause = msgb_put(msg, 3);
215 cause[0] = 2;
216 cause[1] = GSM48_CAUSE_CS_GSM | GSM48_CAUSE_LOC_USER;
217 cause[2] = 0x80 | 30; /* response to status inquiry */
218
219 call_state = msgb_put(msg, 1);
220 call_state[0] = 0xc0 | 0x00;
221
Neels Hofmeyrc4628a32018-12-07 14:47:34 +0100222 return trans_tx_gsm48(trans, msg);
Harald Welte27989d42018-06-21 20:39:20 +0200223}
224
225static void gsm48_stop_cc_timer(struct gsm_trans *trans)
226{
227 if (osmo_timer_pending(&trans->cc.timer)) {
Neels Hofmeyrff7074a2019-02-28 05:50:06 +0100228 LOG_TRANS(trans, LOGL_DEBUG, "stopping pending timer T%x\n", trans->cc.Tcurrent);
Harald Welte27989d42018-06-21 20:39:20 +0200229 osmo_timer_del(&trans->cc.timer);
230 trans->cc.Tcurrent = 0;
231 }
232}
233
Neels Hofmeyr58f40882023-03-08 04:04:27 +0100234/* Log the MNCC tx and rx events.
235 * Depending on msg_type, also log whether RTP information is passed on.
236 * (This is particularly interesting for the doc/sequence_charts/msc_log_to_ladder.py)
237 */
Neels Hofmeyr1c065072022-08-07 02:43:15 +0200238#define log_mncc_rx_tx(ARGS...) _log_mncc_rx_tx(__FILE__, __LINE__, ##ARGS)
239static void _log_mncc_rx_tx(const char *file, int line,
240 struct gsm_trans *trans, const char *rx_tx, const union mncc_msg *mncc)
Neels Hofmeyr58f40882023-03-08 04:04:27 +0100241{
242 const char *sdp = NULL;
243 struct sdp_msg sdp_msg = {};
244 struct osmo_sockaddr addr = {};
245
246 if (!log_check_level(DMNCC, LOGL_DEBUG))
247 return;
248
249 switch (mncc->msg_type) {
250 case MNCC_RTP_CREATE:
251 case MNCC_RTP_CONNECT:
252 addr = (struct osmo_sockaddr){ .u.sas = mncc->rtp.addr };
253 sdp = mncc->rtp.sdp;
254 break;
255
256 case MNCC_SETUP_IND:
257 case MNCC_SETUP_REQ:
258 case MNCC_SETUP_COMPL_IND:
259 case MNCC_SETUP_COMPL_REQ:
260 case MNCC_SETUP_RSP:
261 case MNCC_SETUP_CNF:
262 case MNCC_CALL_CONF_IND:
263 case MNCC_CALL_PROC_REQ:
264 case MNCC_ALERT_IND:
265 case MNCC_ALERT_REQ:
266 sdp = mncc->signal.sdp;
267 break;
268
269 default:
270 break;
271 }
272
273 if (sdp && sdp[0] && (sdp_msg_from_sdp_str(&sdp_msg, sdp) == 0)) {
Neels Hofmeyr1c065072022-08-07 02:43:15 +0200274 LOG_TRANS_CAT_SRC(trans, DMNCC, LOGL_DEBUG, file, line, "%s %s (RTP=%s)\n",
275 rx_tx,
276 get_mncc_name(mncc->msg_type),
277 sdp_msg_to_str(&sdp_msg));
Neels Hofmeyr58f40882023-03-08 04:04:27 +0100278 return;
279 }
280
281 if (osmo_sockaddr_is_any(&addr) == 0) {
Neels Hofmeyr1c065072022-08-07 02:43:15 +0200282 LOG_TRANS_CAT_SRC(trans, DMNCC, LOGL_DEBUG, file, line, "%s %s (RTP=%s)\n",
283 rx_tx,
284 get_mncc_name(mncc->msg_type),
285 osmo_sockaddr_to_str_c(OTC_SELECT, &addr));
Neels Hofmeyr58f40882023-03-08 04:04:27 +0100286 return;
287 }
288
Neels Hofmeyr1c065072022-08-07 02:43:15 +0200289 LOG_TRANS_CAT_SRC(trans, DMNCC, LOGL_DEBUG, file, line, "%s %s\n", rx_tx, get_mncc_name(mncc->msg_type));
Neels Hofmeyr58f40882023-03-08 04:04:27 +0100290}
291
Neels Hofmeyr1c065072022-08-07 02:43:15 +0200292#define mncc_recvmsg(ARGS...) _mncc_recvmsg(__FILE__, __LINE__, ##ARGS)
293static int _mncc_recvmsg(const char *file, int line,
294 struct gsm_network *net, struct gsm_trans *trans, int msg_type, struct gsm_mncc *mncc)
Harald Welte27989d42018-06-21 20:39:20 +0200295{
296 struct msgb *msg;
297 unsigned char *data;
298
Harald Welte27989d42018-06-21 20:39:20 +0200299 mncc->msg_type = msg_type;
Neels Hofmeyr58f40882023-03-08 04:04:27 +0100300 log_mncc_rx_tx(trans, "tx", (union mncc_msg *)mncc);
Harald Welte27989d42018-06-21 20:39:20 +0200301
302 msg = msgb_alloc(sizeof(struct gsm_mncc), "MNCC");
303 if (!msg)
304 return -ENOMEM;
305
306 data = msgb_put(msg, sizeof(struct gsm_mncc));
307 memcpy(data, mncc, sizeof(struct gsm_mncc));
308
309 cc_tx_to_mncc(net, msg);
Neels Hofmeyrcf90bdb2019-10-01 19:47:26 +0200310 /* trans may be NULL when sending an MNCC error reply upon an invalid MNCC request */
311 if (trans)
312 trans->cc.mncc_initiated = true;
Harald Welte27989d42018-06-21 20:39:20 +0200313
314 return 0;
315}
316
317int mncc_release_ind(struct gsm_network *net, struct gsm_trans *trans,
318 uint32_t callref, int location, int value)
319{
320 struct gsm_mncc rel;
321
322 memset(&rel, 0, sizeof(rel));
323 rel.callref = callref;
324 mncc_set_cause(&rel, location, value);
325 if (trans && trans->cc.state == GSM_CSTATE_RELEASE_REQ)
326 return mncc_recvmsg(net, trans, MNCC_REL_CNF, &rel);
327 return mncc_recvmsg(net, trans, MNCC_REL_IND, &rel);
328}
329
330/* Call Control Specific transaction release.
331 * gets called by trans_free, DO NOT CALL YOURSELF! */
332void _gsm48_cc_trans_free(struct gsm_trans *trans)
333{
334 gsm48_stop_cc_timer(trans);
335
Harald Welte27989d42018-06-21 20:39:20 +0200336 /* send release to L4, if callref still exists */
337 if (trans->callref) {
Vadim Yanitskiydd466cf2021-02-05 19:17:31 +0100338 /* Send MNCC REL.ind (cause='Resource unavailable') */
339 if (trans->cc.mncc_initiated) {
340 mncc_release_ind(trans->net, trans, trans->callref,
341 GSM48_CAUSE_LOC_PRN_S_LU,
Keith Whyteba4d6822022-07-03 04:12:58 +0100342 (trans->cc.state == GSM_CSTATE_CALL_RECEIVED) ?
343 GSM48_CC_CAUSE_USER_NOTRESPOND :
Vadim Yanitskiydd466cf2021-02-05 19:17:31 +0100344 GSM48_CC_CAUSE_RESOURCE_UNAVAIL);
345 }
346
Neels Hofmeyrc4628a32018-12-07 14:47:34 +0100347 /* FIXME: currently, a CC trans that would not yet be in state GSM_CSTATE_RELEASE_REQ fails to send a
348 * CC Release to the MS if it gets freed here. Hack it to do so. */
349 if (trans->cc.state != GSM_CSTATE_RELEASE_REQ) {
350 struct gsm_mncc rel = {};
351 rel.callref = trans->callref;
352 mncc_set_cause(&rel, GSM48_CAUSE_LOC_PRN_S_LU, GSM48_CC_CAUSE_RESOURCE_UNAVAIL);
353 gsm48_cc_tx_release(trans, &rel);
354 }
Harald Welte27989d42018-06-21 20:39:20 +0200355 /* This is a final freeing of the transaction. The MNCC release may have triggered the
356 * T308 release timer, but we don't have the luxury of graceful CC Release here. */
357 gsm48_stop_cc_timer(trans);
358 }
359 if (trans->cc.state != GSM_CSTATE_NULL)
360 new_cc_state(trans, GSM_CSTATE_NULL);
Philipp Maier9ca7b312018-10-10 17:00:49 +0200361
362 gsm48_stop_guard_timer(trans);
Neels Hofmeyrc4628a32018-12-07 14:47:34 +0100363
364 if (trans->msc_a && trans->msc_a->cc.active_trans == trans)
365 trans->msc_a->cc.active_trans = NULL;
Harald Welte27989d42018-06-21 20:39:20 +0200366}
367
Harald Welte27989d42018-06-21 20:39:20 +0200368/* call-back from paging the B-end of the connection */
Neels Hofmeyrc4628a32018-12-07 14:47:34 +0100369static void cc_paging_cb(struct msc_a *msc_a, struct gsm_trans *trans)
Harald Welte27989d42018-06-21 20:39:20 +0200370{
Neels Hofmeyrc4628a32018-12-07 14:47:34 +0100371 if (trans->msc_a) {
372 LOG_MSC_A_CAT(msc_a, DPAG, LOGL_ERROR,
373 "Handle paging error: transaction already associated with subscriber,"
374 " apparently it was already handled. Skip.\n");
375 return;
Harald Welte27989d42018-06-21 20:39:20 +0200376 }
377
Neels Hofmeyrc4628a32018-12-07 14:47:34 +0100378 if (msc_a) {
379 LOG_TRANS(trans, LOGL_DEBUG, "Paging succeeded\n");
380 /* Assign conn */
381 msc_a_get(msc_a, MSC_A_USE_CC);
382 trans->msc_a = msc_a;
383 trans->paging_request = NULL;
Keith Whytea1a70be2021-05-16 02:59:52 +0200384
385 /* Get the GCR from the MO call leg (if any). */
Vadim Yanitskiyc6921e52021-10-27 17:05:55 +0300386 if (!trans->cc.lcls)
Keith Whytea1a70be2021-05-16 02:59:52 +0200387 trans->cc.lcls = trans_lcls_compose(trans, true);
Vadim Yanitskiyc6921e52021-10-27 17:05:55 +0300388 if (trans->cc.lcls && trans->cc.msg.fields & MNCC_F_GCR) {
389 int rc = osmo_dec_gcr(&trans->cc.lcls->gcr,
390 &trans->cc.msg.gcr[0],
391 sizeof(trans->cc.msg.gcr));
392 if (rc < 0)
393 LOG_TRANS(trans, LOGL_ERROR, "Failed to parse GCR\n");
394 else
Keith Whytea1a70be2021-05-16 02:59:52 +0200395 trans->cc.lcls->gcr_available = true;
Keith Whytea1a70be2021-05-16 02:59:52 +0200396 }
397
Neels Hofmeyrc4628a32018-12-07 14:47:34 +0100398 osmo_fsm_inst_dispatch(msc_a->c.fi, MSC_A_EV_TRANSACTION_ACCEPTED, trans);
399 /* send SETUP request to called party */
400 gsm48_cc_tx_setup(trans, &trans->cc.msg);
401 } else {
402 LOG_TRANS(trans, LOGL_DEBUG, "Paging expired\n");
403 /* Temporarily out of order */
404 mncc_release_ind(trans->net, trans,
405 trans->callref,
406 GSM48_CAUSE_LOC_PRN_S_LU,
407 GSM48_CC_CAUSE_DEST_OOO);
408 trans->callref = 0;
409 trans->paging_request = NULL;
410 trans_free(trans);
411 }
Harald Welte27989d42018-06-21 20:39:20 +0200412}
413
414/* bridge channels of two transactions */
Neels Hofmeyrc4628a32018-12-07 14:47:34 +0100415static int tch_bridge(struct gsm_network *net, const struct gsm_mncc_bridge *bridge)
Harald Welte27989d42018-06-21 20:39:20 +0200416{
Andreas Eversberg7e4b0322023-04-23 11:43:13 +0200417 struct gsm_trans *trans1 = trans_find_by_callref(net, TRANS_CC, bridge->callref[0]);
418 struct gsm_trans *trans2 = trans_find_by_callref(net, TRANS_CC, bridge->callref[1]);
Neels Hofmeyrc4628a32018-12-07 14:47:34 +0100419 struct call_leg *cl1;
420 struct call_leg *cl2;
Harald Welte27989d42018-06-21 20:39:20 +0200421
Neels Hofmeyrff7074a2019-02-28 05:50:06 +0100422 if (!trans1 || !trans2) {
423 LOG_TRANS(trans1 ? : trans2, LOGL_ERROR, "Cannot MNCC_BRIDGE, one or both call legs are unset\n");
Harald Welte27989d42018-06-21 20:39:20 +0200424 return -EIO;
Neels Hofmeyrff7074a2019-02-28 05:50:06 +0100425 }
Harald Welte27989d42018-06-21 20:39:20 +0200426
Neels Hofmeyrc4628a32018-12-07 14:47:34 +0100427 if (!trans1->msc_a || !trans2->msc_a) {
Neels Hofmeyrff7074a2019-02-28 05:50:06 +0100428 LOG_TRANS(trans1, LOGL_ERROR, "Cannot MNCC_BRIDGE, one or both call legs lack an active connection\n");
429 LOG_TRANS(trans2, LOGL_ERROR, "Cannot MNCC_BRIDGE, one or both call legs lack an active connection\n");
Harald Welte27989d42018-06-21 20:39:20 +0200430 return -EIO;
Neels Hofmeyrff7074a2019-02-28 05:50:06 +0100431 }
432
433 LOG_TRANS(trans1, LOGL_DEBUG, "MNCC_BRIDGE: Local bridge to callref 0x%x\n", trans2->callref);
434 LOG_TRANS(trans2, LOGL_DEBUG, "MNCC_BRIDGE: Local bridge to callref 0x%x\n", trans1->callref);
Harald Welte27989d42018-06-21 20:39:20 +0200435
Neels Hofmeyrc4628a32018-12-07 14:47:34 +0100436 /* This call bridging mechanism is only used with the internal MNCC (with external MNCC briding would be done by
437 * the PBX). For inter-MSC Handover scenarios, an external MNCC is mandatory. The conclusion is that in this
438 * code path, there is only one MSC, and the MSC-I role is local, and hence we can directly access the ran_conn.
439 * If we can't, then we must give up. */
440 cl1 = trans1->msc_a->cc.call_leg;
441 cl2 = trans2->msc_a->cc.call_leg;
Harald Welte27989d42018-06-21 20:39:20 +0200442
Andreas Eversberg712b28e2023-06-21 11:17:26 +0200443 return call_leg_local_bridge(cl1, trans1->call_id, trans1, cl2, trans2->call_id, trans2);
Harald Welte27989d42018-06-21 20:39:20 +0200444}
445
446static int gsm48_cc_rx_status_enq(struct gsm_trans *trans, struct msgb *msg)
447{
Neels Hofmeyrff7074a2019-02-28 05:50:06 +0100448 LOG_TRANS(trans, LOGL_DEBUG, "-> STATUS ENQ\n");
Harald Welte27989d42018-06-21 20:39:20 +0200449 return gsm48_cc_tx_status(trans, msg);
450}
451
Harald Welte27989d42018-06-21 20:39:20 +0200452static void gsm48_cc_timeout(void *arg)
453{
454 struct gsm_trans *trans = arg;
455 int disconnect = 0, release = 0;
456 int mo_cause = GSM48_CC_CAUSE_RECOVERY_TIMER;
457 int mo_location = GSM48_CAUSE_LOC_USER;
458 int l4_cause = GSM48_CC_CAUSE_NORMAL_UNSPEC;
459 int l4_location = GSM48_CAUSE_LOC_PRN_S_LU;
460 struct gsm_mncc mo_rel, l4_rel;
461
Neels Hofmeyre29ee5a2022-08-06 14:16:55 +0200462 LOG_TRANS(trans, LOGL_INFO, "Timeout of T%x\n", trans->cc.Tcurrent);
463
Harald Welte27989d42018-06-21 20:39:20 +0200464 memset(&mo_rel, 0, sizeof(struct gsm_mncc));
465 mo_rel.callref = trans->callref;
466 memset(&l4_rel, 0, sizeof(struct gsm_mncc));
467 l4_rel.callref = trans->callref;
468
469 switch(trans->cc.Tcurrent) {
470 case 0x303:
471 release = 1;
472 l4_cause = GSM48_CC_CAUSE_USER_NOTRESPOND;
473 break;
474 case 0x310:
475 disconnect = 1;
476 l4_cause = GSM48_CC_CAUSE_USER_NOTRESPOND;
477 break;
478 case 0x313:
479 disconnect = 1;
480 /* unknown, did not find it in the specs */
481 break;
482 case 0x301:
483 disconnect = 1;
484 l4_cause = GSM48_CC_CAUSE_USER_NOTRESPOND;
485 break;
486 case 0x308:
487 if (!trans->cc.T308_second) {
488 /* restart T308 a second time */
489 gsm48_cc_tx_release(trans, &trans->cc.msg);
490 trans->cc.T308_second = 1;
491 break; /* stay in release state */
492 }
493 trans_free(trans);
494 return;
495 case 0x306:
496 release = 1;
497 mo_cause = trans->cc.msg.cause.value;
498 mo_location = trans->cc.msg.cause.location;
499 break;
500 case 0x323:
501 disconnect = 1;
502 break;
503 default:
504 release = 1;
505 }
506
507 if (release && trans->callref) {
508 /* process release towards layer 4 */
509 mncc_release_ind(trans->net, trans, trans->callref,
510 l4_location, l4_cause);
511 trans->callref = 0;
512 }
513
514 if (disconnect && trans->callref) {
515 /* process disconnect towards layer 4 */
516 mncc_set_cause(&l4_rel, l4_location, l4_cause);
517 mncc_recvmsg(trans->net, trans, MNCC_DISC_IND, &l4_rel);
518 }
519
520 /* process disconnect towards mobile station */
521 if (disconnect || release) {
522 mncc_set_cause(&mo_rel, mo_location, mo_cause);
523 mo_rel.cause.diag[0] = ((trans->cc.Tcurrent & 0xf00) >> 8) + '0';
524 mo_rel.cause.diag[1] = ((trans->cc.Tcurrent & 0x0f0) >> 4) + '0';
525 mo_rel.cause.diag[2] = (trans->cc.Tcurrent & 0x00f) + '0';
526 mo_rel.cause.diag_len = 3;
527
528 if (disconnect)
529 gsm48_cc_tx_disconnect(trans, &mo_rel);
530 if (release)
531 gsm48_cc_tx_release(trans, &mo_rel);
532 }
533
534}
535
536/* disconnect both calls from the bridge */
537static inline void disconnect_bridge(struct gsm_network *net,
Neels Hofmeyrc4628a32018-12-07 14:47:34 +0100538 const struct gsm_mncc_bridge *bridge, int err)
Harald Welte27989d42018-06-21 20:39:20 +0200539{
Andreas Eversberg7e4b0322023-04-23 11:43:13 +0200540 struct gsm_trans *trans0 = trans_find_by_callref(net, TRANS_CC, bridge->callref[0]);
541 struct gsm_trans *trans1 = trans_find_by_callref(net, TRANS_CC, bridge->callref[1]);
Harald Welte27989d42018-06-21 20:39:20 +0200542 struct gsm_mncc mx_rel;
543 if (!trans0 || !trans1)
544 return;
545
Neels Hofmeyrff7074a2019-02-28 05:50:06 +0100546 LOG_TRANS(trans0, LOGL_ERROR, "Failed to bridge TCH for calls %x <-> %x :: %s \n",
547 trans0->callref, trans1->callref, strerror(err));
548 LOG_TRANS(trans1, LOGL_ERROR, "Failed to bridge TCH for calls %x <-> %x :: %s \n",
Harald Welte27989d42018-06-21 20:39:20 +0200549 trans0->callref, trans1->callref, strerror(err));
550
551 memset(&mx_rel, 0, sizeof(struct gsm_mncc));
552 mncc_set_cause(&mx_rel, GSM48_CAUSE_LOC_INN_NET,
553 GSM48_CC_CAUSE_CHAN_UNACCEPT);
554
555 mx_rel.callref = trans0->callref;
556 gsm48_cc_tx_disconnect(trans0, &mx_rel);
557
558 mx_rel.callref = trans1->callref;
559 gsm48_cc_tx_disconnect(trans1, &mx_rel);
560}
561
562static void gsm48_start_cc_timer(struct gsm_trans *trans, int current,
563 int sec, int micro)
564{
Neels Hofmeyrff7074a2019-02-28 05:50:06 +0100565 LOG_TRANS(trans, LOGL_DEBUG, "starting timer T%x with %d seconds\n", current, sec);
Harald Welte27989d42018-06-21 20:39:20 +0200566 osmo_timer_setup(&trans->cc.timer, gsm48_cc_timeout, trans);
567 osmo_timer_schedule(&trans->cc.timer, sec, micro);
568 trans->cc.Tcurrent = current;
569}
570
571static int gsm48_cc_rx_setup(struct gsm_trans *trans, struct msgb *msg)
572{
573 struct gsm48_hdr *gh = msgb_l3(msg);
574 uint8_t msg_type = gsm48_hdr_msg_type(gh);
575 unsigned int payload_len = msgb_l3len(msg) - sizeof(*gh);
576 struct tlv_parsed tp;
577 struct gsm_mncc setup;
578
Philipp Maier9ca7b312018-10-10 17:00:49 +0200579 gsm48_start_guard_timer(trans);
580
Harald Welte27989d42018-06-21 20:39:20 +0200581 memset(&setup, 0, sizeof(struct gsm_mncc));
582 setup.callref = trans->callref;
583
Keith Whytea1a70be2021-05-16 02:59:52 +0200584 /* New Global Call Reference */
585 if (!trans->cc.lcls)
586 trans->cc.lcls = trans_lcls_compose(trans, true);
587
588 /* Pass the LCLS GCR on to the MT call leg via MNCC */
Vadim Yanitskiyc6921e52021-10-27 17:05:55 +0300589 if (trans->cc.lcls) {
590 struct msgb *gcr_msg = msgb_alloc(sizeof(setup.gcr), "MNCC GCR");
591 const struct osmo_gcr_parsed *gcr = &trans->cc.lcls->gcr;
592 int rc;
593
594 if (gcr_msg != NULL && (rc = osmo_enc_gcr(gcr_msg, gcr)) > 0) {
595 memcpy(&setup.gcr[0], gcr_msg->data, rc);
596 setup.fields |= MNCC_F_GCR;
597 } else
598 LOG_TRANS(trans, LOGL_ERROR, "Failed to encode GCR\n");
599 msgb_free(gcr_msg);
600 }
Keith Whytea1a70be2021-05-16 02:59:52 +0200601
Neels Hofmeyrbd5f8e92022-01-13 23:18:02 +0100602 OSMO_ASSERT(trans->msc_a);
603
Harald Welte27989d42018-06-21 20:39:20 +0200604 tlv_parse(&tp, &gsm48_att_tlvdef, gh->data, payload_len, 0, 0);
605 /* emergency setup is identified by msg_type */
606 if (msg_type == GSM48_MT_CC_EMERG_SETUP) {
607 setup.fields |= MNCC_F_EMERGENCY;
608 setup.emergency = 1;
609 /* use destination number as configured by user (if any) */
610 if (trans->net->emergency.route_to_msisdn) {
611 setup.fields |= MNCC_F_CALLED;
612 setup.called.type = 0; /* unknown */
613 setup.called.plan = 0; /* unknown */
614 OSMO_STRLCPY_ARRAY(setup.called.number,
615 trans->net->emergency.route_to_msisdn);
616 }
617 }
618
619 /* use subscriber as calling party number */
620 setup.fields |= MNCC_F_CALLING;
621 OSMO_STRLCPY_ARRAY(setup.calling.number, trans->vsub->msisdn);
622 OSMO_STRLCPY_ARRAY(setup.imsi, trans->vsub->imsi);
623
624 /* bearer capability */
625 if (TLVP_PRESENT(&tp, GSM48_IE_BEARER_CAP)) {
626 setup.fields |= MNCC_F_BEARER_CAP;
627 gsm48_decode_bearer_cap(&setup.bearer_cap,
628 TLVP_VAL(&tp, GSM48_IE_BEARER_CAP)-1);
629
630 /* Create a copy of the bearer capability
631 * in the transaction struct, so we can use
632 * this information later */
Neels Hofmeyrc4628a32018-12-07 14:47:34 +0100633 memcpy(&trans->bearer_cap, &setup.bearer_cap,
Harald Welte27989d42018-06-21 20:39:20 +0200634 sizeof(trans->bearer_cap));
635 }
636 /* facility */
637 if (TLVP_PRESENT(&tp, GSM48_IE_FACILITY)) {
638 setup.fields |= MNCC_F_FACILITY;
639 gsm48_decode_facility(&setup.facility,
640 TLVP_VAL(&tp, GSM48_IE_FACILITY)-1);
641 }
642 /* called party bcd number */
643 if (TLVP_PRESENT(&tp, GSM48_IE_CALLED_BCD)) {
644 setup.fields |= MNCC_F_CALLED;
645 gsm48_decode_called(&setup.called,
646 TLVP_VAL(&tp, GSM48_IE_CALLED_BCD)-1);
647 }
648 /* user-user */
649 if (TLVP_PRESENT(&tp, GSM48_IE_USER_USER)) {
650 setup.fields |= MNCC_F_USERUSER;
651 gsm48_decode_useruser(&setup.useruser,
652 TLVP_VAL(&tp, GSM48_IE_USER_USER)-1);
653 }
654 /* ss-version */
655 if (TLVP_PRESENT(&tp, GSM48_IE_SS_VERS)) {
656 setup.fields |= MNCC_F_SSVERSION;
657 gsm48_decode_ssversion(&setup.ssversion,
658 TLVP_VAL(&tp, GSM48_IE_SS_VERS)-1);
659 }
660 /* CLIR suppression */
661 if (TLVP_PRESENT(&tp, GSM48_IE_CLIR_SUPP))
662 setup.clir.sup = 1;
663 /* CLIR invocation */
664 if (TLVP_PRESENT(&tp, GSM48_IE_CLIR_INVOC))
665 setup.clir.inv = 1;
666 /* cc cap */
667 if (TLVP_PRESENT(&tp, GSM48_IE_CC_CAP)) {
668 setup.fields |= MNCC_F_CCCAP;
669 gsm48_decode_cccap(&setup.cccap,
670 TLVP_VAL(&tp, GSM48_IE_CC_CAP)-1);
671 }
672
Neels Hofmeyrf5559522022-01-13 21:39:11 +0100673 /* MO call leg starting, gather all codec information so far known: */
Oliver Smitha35abb72023-05-23 17:29:57 +0200674 trans_cc_filter_init(trans);
Oliver Smithc7c40c92023-05-23 17:43:40 +0200675 trans_cc_filter_set_ran(trans, trans->msc_a->c.ran->type);
Oliver Smith1c7f1782023-05-23 17:58:26 +0200676 trans_cc_filter_set_bss(trans, trans->msc_a);
Neels Hofmeyrf5559522022-01-13 21:39:11 +0100677 if (setup.fields & MNCC_F_BEARER_CAP)
Oliver Smith5375f782023-05-23 13:38:33 +0200678 trans_cc_filter_set_ms_from_bc(trans, &trans->bearer_cap);
Oliver Smithceca8e62023-05-24 11:15:52 +0200679 trans_cc_filter_run(trans);
Neels Hofmeyrf5559522022-01-13 21:39:11 +0100680
Neels Hofmeyrff7074a2019-02-28 05:50:06 +0100681 LOG_TRANS(trans, setup.emergency ? LOGL_NOTICE : LOGL_INFO, "%sSETUP to %s\n",
682 setup.emergency ? "EMERGENCY_" : "", setup.called.number);
Harald Welte27989d42018-06-21 20:39:20 +0200683
Pau Espin Pedrol2e21a682021-06-04 16:45:44 +0200684 rate_ctr_inc(rate_ctr_group_get_ctr(trans->net->msc_ctrs, MSC_CTR_CALL_MO_SETUP));
Harald Welte27989d42018-06-21 20:39:20 +0200685
Neels Hofmeyrbd5f8e92022-01-13 23:18:02 +0100686 new_cc_state(trans, GSM_CSTATE_INITIATED);
687
688 /* To complete the MNCC_SETUP_IND, we need to provide an RTP address and port. First instruct the MGW to create
689 * a CN-side RTP conn, and continue with MNCC_SETUP_IND once that is done. Leave trans.cc in GSM_CSTATE_NULL and
690 * note down the msg_type to indicate that we indeed composed an MNCC_SETUP_IND for later. */
691 setup.msg_type = MNCC_SETUP_IND;
692 trans->cc.msg = setup;
693 return msc_a_try_call_assignment(trans);
694 /* continue in gsm48_cc_rx_setup_cn_local_rtp_port_known() */
695}
696
697/* Callback for MNCC_SETUP_IND waiting for the core network RTP port to be established by the MGW (via msc_a) */
698void gsm48_cc_rx_setup_cn_local_rtp_port_known(struct gsm_trans *trans)
699{
700 struct msc_a *msc_a = trans->msc_a;
701 struct gsm_mncc setup = trans->cc.msg;
702 struct osmo_sockaddr_str *rtp_cn_local;
703 struct sdp_msg *sdp;
704 int rc;
705
706 if (trans->cc.state != GSM_CSTATE_INITIATED
707 || setup.msg_type != MNCC_SETUP_IND) {
708 LOG_TRANS(trans, LOGL_ERROR,
709 "Unexpected CC state. Expected GSM_CSTATE_INITIATED and a buffered MNCC_SETUP_IND message,"
710 " found CC state %d and msg_type %s\n",
711 trans->cc.state, get_mncc_name(setup.msg_type));
712 trans->callref = 0;
713 trans_free(trans);
714 return;
715 }
716
717 if (!msc_a) {
718 LOG_TRANS(trans, LOGL_ERROR, "No connection for CC trans\n");
719 trans->callref = 0;
720 trans_free(trans);
721 return;
722 }
723
724 /* 'setup' above has taken the value of trans->cc.msg, we can now clear that. */
725 trans->cc.msg = (struct gsm_mncc){};
726
727 /* Insert the CN side RTP port now available into SDP and compose SDP string */
728 rtp_cn_local = call_leg_local_ip(msc_a->cc.call_leg, RTP_TO_CN);
729 if (!osmo_sockaddr_str_is_nonzero(rtp_cn_local)) {
730 LOG_TRANS(trans, LOGL_ERROR, "Cannot compose SDP for MNCC_SETUP_IND: no RTP set up for the CN side\n");
731 trans_free(trans);
732 return;
733 }
Oliver Smithc63c3a02023-05-24 10:48:07 +0200734 trans->cc.local.rtp = *rtp_cn_local;
Neels Hofmeyr8dd16462022-01-13 20:06:53 +0100735
Oliver Smithc63c3a02023-05-24 10:48:07 +0200736 sdp = trans->cc.local.audio_codecs.count ? &trans->cc.local : NULL;
Neels Hofmeyr8dd16462022-01-13 20:06:53 +0100737 rc = sdp_msg_to_sdp_str_buf(setup.sdp, sizeof(setup.sdp), sdp);
738 if (rc >= sizeof(setup.sdp)) {
739 LOG_TRANS(trans, LOGL_ERROR, "MNCC_SETUP_IND: SDP too long (%d > %zu bytes)\n", rc, sizeof(setup.sdp));
740 trans_free(trans);
Neels Hofmeyrbd5f8e92022-01-13 23:18:02 +0100741 return;
Neels Hofmeyr8dd16462022-01-13 20:06:53 +0100742 }
743
Harald Welte27989d42018-06-21 20:39:20 +0200744 /* indicate setup to MNCC */
745 mncc_recvmsg(trans->net, trans, MNCC_SETUP_IND, &setup);
Harald Welte27989d42018-06-21 20:39:20 +0200746}
747
Neels Hofmeyr8dd16462022-01-13 20:06:53 +0100748static void rx_mncc_sdp(struct gsm_trans *trans, uint32_t mncc_msg_type, const char *sdp)
749{
750 int rc;
751 if (!sdp[0])
752 return;
Oliver Smith593cd882023-05-24 10:40:19 +0200753 rc = sdp_msg_from_sdp_str(&trans->cc.remote, sdp);
Neels Hofmeyr8dd16462022-01-13 20:06:53 +0100754 if (rc)
755 LOG_TRANS_CAT(trans, DMNCC, LOGL_ERROR, "rx %s: Failed to parse SDP: %d\n",
756 get_mncc_name(mncc_msg_type), rc);
757}
758
Harald Welte27989d42018-06-21 20:39:20 +0200759static int gsm48_cc_tx_setup(struct gsm_trans *trans, void *arg)
760{
Neels Hofmeyr3551d842022-01-13 19:35:12 +0100761 struct msgb *msg = gsm48_msgb_alloc_name("GSM 04.08 CC SETUP");
Harald Welte27989d42018-06-21 20:39:20 +0200762 struct gsm48_hdr *gh;
763 struct gsm_mncc *setup = arg;
764 int rc, trans_id;
Neels Hofmeyr909ea522022-01-13 21:40:58 +0100765 struct gsm_mncc_bearer_cap bearer_cap;
Harald Welte27989d42018-06-21 20:39:20 +0200766
767 gh = (struct gsm48_hdr *) msgb_put(msg, sizeof(*gh));
768
769 /* transaction id must not be assigned */
Maxd8daaae2019-02-14 16:54:10 +0700770 if (trans->transaction_id != TRANS_ID_UNASSIGNED) {
Neels Hofmeyrff7074a2019-02-28 05:50:06 +0100771 LOG_TRANS(trans, LOGL_DEBUG, "TX Setup with assigned transaction. "
Harald Welte27989d42018-06-21 20:39:20 +0200772 "This is not allowed!\n");
773 /* Temporarily out of order */
774 rc = mncc_release_ind(trans->net, trans, trans->callref,
775 GSM48_CAUSE_LOC_PRN_S_LU,
776 GSM48_CC_CAUSE_RESOURCE_UNAVAIL);
777 trans->callref = 0;
778 trans_free(trans);
Neels Hofmeyr61ae18c2019-08-28 03:41:05 +0200779 msgb_free(msg);
Harald Welte27989d42018-06-21 20:39:20 +0200780 return rc;
781 }
782
783 /* Get free transaction_id */
Neels Hofmeyrc4628a32018-12-07 14:47:34 +0100784 trans_id = trans_assign_trans_id(trans->net, trans->vsub, TRANS_CC);
Harald Welte27989d42018-06-21 20:39:20 +0200785 if (trans_id < 0) {
786 /* no free transaction ID */
787 rc = mncc_release_ind(trans->net, trans, trans->callref,
788 GSM48_CAUSE_LOC_PRN_S_LU,
789 GSM48_CC_CAUSE_RESOURCE_UNAVAIL);
790 trans->callref = 0;
791 trans_free(trans);
Neels Hofmeyr61ae18c2019-08-28 03:41:05 +0200792 msgb_free(msg);
Harald Welte27989d42018-06-21 20:39:20 +0200793 return rc;
794 }
795 trans->transaction_id = trans_id;
796
797 gh->msg_type = GSM48_MT_CC_SETUP;
798
799 gsm48_start_cc_timer(trans, 0x303, GSM48_T303);
800
Neels Hofmeyr7ddc48c2022-01-13 21:40:58 +0100801 /* MT call leg is starting. Gather all codecs information so far known.
802 * (Usually) paging has succeeded, and now we're processing the MNCC Setup from the remote MO call leg.
803 * Initialize the codecs filter with this side's BSS' codec list, received at Complete Layer 3.
Oliver Smithe545b9d2023-06-15 14:17:12 +0200804 * We haven't received the MT MS's Bearer Capabilities yet; the Bearer Capabilities handled here are
805 * actually the remote call leg's Bearer Capabilities. */
Oliver Smitha35abb72023-05-23 17:29:57 +0200806 trans_cc_filter_init(trans);
Oliver Smithc7c40c92023-05-23 17:43:40 +0200807 trans_cc_filter_set_ran(trans, trans->msc_a->c.ran->type);
Oliver Smith1c7f1782023-05-23 17:58:26 +0200808 trans_cc_filter_set_bss(trans, trans->msc_a);
Oliver Smith64f39302023-06-15 14:26:37 +0200809 if (setup->fields & MNCC_F_BEARER_CAP)
810 trans->bearer_cap.transfer = setup->bearer_cap.transfer;
Oliver Smith10632132023-05-12 12:14:22 +0200811
812 switch (trans->bearer_cap.transfer) {
813 case GSM48_BCAP_ITCAP_SPEECH:
814 /* sdp.remote: if SDP is included in the MNCC, take that as definitive list of remote audio codecs. */
815 rx_mncc_sdp(trans, setup->msg_type, setup->sdp);
816 /* sdp.remote: if there is no SDP information or we failed to parse it, try using the Bearer Capability from
817 * MNCC, if any. */
818 if (!trans->cc.remote.audio_codecs.count && (setup->fields & MNCC_F_BEARER_CAP)) {
819 trans->cc.remote = (struct sdp_msg){};
820 trans_cc_set_remote_from_bc(trans, &setup->bearer_cap);
821 LOG_TRANS_CAT(trans, DMNCC, LOGL_DEBUG, "rx %s Bearer Cap: remote=%s\n",
822 get_mncc_name(setup->msg_type), sdp_msg_to_str(&trans->cc.remote));
823 }
824 if (!trans->cc.remote.audio_codecs.count)
825 LOG_TRANS(trans, LOGL_INFO,
826 "Got no information of remote audio codecs: neither SDP nor Bearer Capability. Trying anyway.\n");
827 break;
828 case GSM48_BCAP_ITCAP_UNR_DIG_INF:
Oliver Smith412cf922023-07-05 15:47:04 +0200829 if (setup->fields & MNCC_F_BEARER_CAP) {
830 trans->cc.remote = (struct sdp_msg){};
831 trans_cc_set_remote_from_bc(trans, &setup->bearer_cap);
832 LOG_TRANS_CAT(trans, DMNCC, LOGL_DEBUG, "rx %s Bearer Cap: remote=%s\n",
833 get_mncc_name(setup->msg_type), sdp_msg_to_str(&trans->cc.remote));
834 } else {
835 LOG_TRANS(trans, LOGL_INFO,
836 "Got no information of remote Bearer Capability. Trying anyway.\n");
837 sdp_audio_codecs_set_csd(&trans->cc.codecs.ms);
838 }
Oliver Smith10632132023-05-12 12:14:22 +0200839 break;
840 default:
841 LOG_TRANS(trans, LOGL_ERROR, "Handling of information transfer capability %d not implemented\n",
842 trans->bearer_cap.transfer);
Neels Hofmeyraf9d30e2022-01-13 21:40:58 +0100843 }
Neels Hofmeyraf9d30e2022-01-13 21:40:58 +0100844
Oliver Smithceca8e62023-05-24 11:15:52 +0200845 trans_cc_filter_run(trans);
Neels Hofmeyr7ddc48c2022-01-13 21:40:58 +0100846
Oliver Smith10632132023-05-12 12:14:22 +0200847 /* Compose Bearer Capability information that reflects only the codecs (Speech Versions) / CSD bearer services
848 * remaining after intersecting MS, BSS and remote call leg restrictions. To store in trans for later use, and
849 * to include in the outgoing CC Setup message. */
850 switch (trans->bearer_cap.transfer) {
851 case GSM48_BCAP_ITCAP_SPEECH:
852 bearer_cap = (struct gsm_mncc_bearer_cap){
853 .speech_ver = { -1 },
854 };
855 sdp_audio_codecs_to_bearer_cap(&bearer_cap, &trans->cc.local.audio_codecs);
856 rc = bearer_cap_set_radio(&bearer_cap);
857 if (rc) {
858 LOG_TRANS(trans, LOGL_ERROR, "Error composing Bearer Capability for CC Setup\n");
859 trans_free(trans);
860 msgb_free(msg);
861 return rc;
862 }
863 /* If no resulting codecs remain, error out. We cannot find a codec that matches both call legs. If the MGW were
864 * able to transcode, we could use non-identical codecs on each conn of the MGW endpoint, but we are aiming for
865 * finding a matching codec. */
866 if (bearer_cap.speech_ver[0] == -1) {
867 LOG_TRANS(trans, LOGL_ERROR, "%s: no codec match possible: %s\n",
868 get_mncc_name(setup->msg_type),
869 codec_filter_to_str(&trans->cc.codecs, &trans->cc.local, &trans->cc.remote));
870
871 /* incompatible codecs */
872 rc = mncc_release_ind(trans->net, trans, trans->callref,
873 GSM48_CAUSE_LOC_PRN_S_LU,
874 GSM48_CC_CAUSE_INCOMPAT_DEST /* TODO: correct cause code? */);
875 trans->callref = 0;
876 trans_free(trans);
877 msgb_free(msg);
878 return rc;
879 }
880 break;
881 case GSM48_BCAP_ITCAP_UNR_DIG_INF:
882 if (csd_bs_list_to_bearer_cap(&bearer_cap, &trans->cc.local.bearer_services) == 0) {
883 LOG_TRANS(trans, LOGL_ERROR, "Error composing Bearer Capability for CC Setup\n");
884
885 /* incompatible codecs */
886 rc = mncc_release_ind(trans->net, trans, trans->callref,
887 GSM48_CAUSE_LOC_PRN_S_LU,
888 GSM48_CC_CAUSE_INCOMPAT_DEST /* TODO: correct cause code? */);
889 trans->callref = 0;
890 trans_free(trans);
891 msgb_free(msg);
892 return rc;
893 }
894 break;
Harald Welte27989d42018-06-21 20:39:20 +0200895 }
Oliver Smith10632132023-05-12 12:14:22 +0200896
Neels Hofmeyr909ea522022-01-13 21:40:58 +0100897 /* Create a copy of the bearer capability in the transaction struct, so we can use this information later */
Neels Hofmeyr909ea522022-01-13 21:40:58 +0100898 trans->bearer_cap = bearer_cap;
Neels Hofmeyr909ea522022-01-13 21:40:58 +0100899
Neels Hofmeyr909ea522022-01-13 21:40:58 +0100900 gsm48_encode_bearer_cap(msg, 0, &bearer_cap);
901
Harald Welte27989d42018-06-21 20:39:20 +0200902 /* facility */
903 if (setup->fields & MNCC_F_FACILITY)
904 gsm48_encode_facility(msg, 0, &setup->facility);
905 /* progress */
906 if (setup->fields & MNCC_F_PROGRESS)
907 gsm48_encode_progress(msg, 0, &setup->progress);
908 /* calling party BCD number */
909 if (setup->fields & MNCC_F_CALLING)
910 gsm48_encode_calling(msg, &setup->calling);
911 /* called party BCD number */
912 if (setup->fields & MNCC_F_CALLED)
913 gsm48_encode_called(msg, &setup->called);
914 /* user-user */
915 if (setup->fields & MNCC_F_USERUSER)
916 gsm48_encode_useruser(msg, 0, &setup->useruser);
917 /* redirecting party BCD number */
918 if (setup->fields & MNCC_F_REDIRECTING)
919 gsm48_encode_redirecting(msg, &setup->redirecting);
920 /* signal */
921 if (setup->fields & MNCC_F_SIGNAL)
922 gsm48_encode_signal(msg, setup->signal);
923
924 new_cc_state(trans, GSM_CSTATE_CALL_PRESENT);
925
Pau Espin Pedrol2e21a682021-06-04 16:45:44 +0200926 rate_ctr_inc(rate_ctr_group_get_ctr(trans->net->msc_ctrs, MSC_CTR_CALL_MT_SETUP));
Harald Welte27989d42018-06-21 20:39:20 +0200927
Neels Hofmeyrc4628a32018-12-07 14:47:34 +0100928 return trans_tx_gsm48(trans, msg);
Harald Welte27989d42018-06-21 20:39:20 +0200929}
930
931static int gsm48_cc_rx_call_conf(struct gsm_trans *trans, struct msgb *msg)
932{
933 struct gsm48_hdr *gh = msgb_l3(msg);
934 unsigned int payload_len = msgb_l3len(msg) - sizeof(*gh);
935 struct tlv_parsed tp;
936 struct gsm_mncc call_conf;
937 int rc;
938
939 gsm48_stop_cc_timer(trans);
940 gsm48_start_cc_timer(trans, 0x310, GSM48_T310);
941
942 memset(&call_conf, 0, sizeof(struct gsm_mncc));
943 call_conf.callref = trans->callref;
944
945 tlv_parse(&tp, &gsm48_att_tlvdef, gh->data, payload_len, 0, 0);
946#if 0
947 /* repeat */
948 if (TLVP_PRESENT(&tp, GSM48_IE_REPEAT_CIR))
949 call_conf.repeat = 1;
950 if (TLVP_PRESENT(&tp, GSM48_IE_REPEAT_SEQ))
951 call_conf.repeat = 2;
952#endif
953 /* bearer capability */
954 if (TLVP_PRESENT(&tp, GSM48_IE_BEARER_CAP)) {
955 call_conf.fields |= MNCC_F_BEARER_CAP;
956 gsm48_decode_bearer_cap(&call_conf.bearer_cap,
957 TLVP_VAL(&tp, GSM48_IE_BEARER_CAP)-1);
958
959 /* Create a copy of the bearer capability
960 * in the transaction struct, so we can use
961 * this information later */
Neels Hofmeyra9e383f2022-01-13 19:58:05 +0100962 memcpy(&trans->bearer_cap, &call_conf.bearer_cap,
Harald Welte27989d42018-06-21 20:39:20 +0200963 sizeof(trans->bearer_cap));
Neels Hofmeyr10357f82022-01-13 19:59:02 +0100964
965 /* This is the MT call leg's Call Conf, containing the MS Bearer Capabilities of the MT MS.
966 * Store in codecs filter. */
Oliver Smith5375f782023-05-23 13:38:33 +0200967 trans_cc_filter_set_ms_from_bc(trans, &call_conf.bearer_cap);
Harald Welte27989d42018-06-21 20:39:20 +0200968 }
Neels Hofmeyra9e383f2022-01-13 19:58:05 +0100969
Harald Welte27989d42018-06-21 20:39:20 +0200970 /* cause */
971 if (TLVP_PRESENT(&tp, GSM48_IE_CAUSE)) {
972 call_conf.fields |= MNCC_F_CAUSE;
973 gsm48_decode_cause(&call_conf.cause,
974 TLVP_VAL(&tp, GSM48_IE_CAUSE)-1);
975 }
976 /* cc cap */
977 if (TLVP_PRESENT(&tp, GSM48_IE_CC_CAP)) {
978 call_conf.fields |= MNCC_F_CCCAP;
979 gsm48_decode_cccap(&call_conf.cccap,
980 TLVP_VAL(&tp, GSM48_IE_CC_CAP)-1);
981 }
982
983 /* IMSI of called subscriber */
984 OSMO_STRLCPY_ARRAY(call_conf.imsi, trans->vsub->imsi);
985
Harald Welte27989d42018-06-21 20:39:20 +0200986 /* Assign call (if not done yet) */
Neels Hofmeyrc4628a32018-12-07 14:47:34 +0100987 rc = msc_a_try_call_assignment(trans);
Harald Welte27989d42018-06-21 20:39:20 +0200988
989 /* don't continue, if there were problems with
990 * the call assignment. */
991 if (rc)
992 return rc;
993
Neels Hofmeyrbd5f8e92022-01-13 23:18:02 +0100994 /* Directly ack with MNCC_CALL_CONF_IND, not yet containing SDP or RTP IP:port information. */
995 new_cc_state(trans, GSM_CSTATE_MO_TERM_CALL_CONF);
996 return mncc_recvmsg(trans->net, trans, MNCC_CALL_CONF_IND, &call_conf);
997}
998
999static int mncc_recv_rtp(struct gsm_network *net, struct gsm_trans *trans, uint32_t callref,
1000 int cmd, struct osmo_sockaddr_str *rtp_addr, uint32_t payload_type,
1001 uint32_t payload_msg_type, const struct sdp_msg *sdp);
1002
1003static int gsm48_cc_mt_rtp_port_and_codec_known(struct gsm_trans *trans)
1004{
1005 struct msc_a *msc_a = trans->msc_a;
1006 struct osmo_sockaddr_str *rtp_cn_local;
1007 struct gsm_mncc_rtp;
1008
1009 if (!msc_a) {
1010 LOG_TRANS(trans, LOGL_ERROR, "No connection for CC trans\n");
1011 trans->callref = 0;
1012 trans_free(trans);
1013 return -EINVAL;
1014 }
1015
1016 /* Insert the CN side RTP port now available into SDP */
1017 rtp_cn_local = call_leg_local_ip(msc_a->cc.call_leg, RTP_TO_CN);
1018 if (!rtp_cn_local) {
1019 LOG_TRANS(trans, LOGL_ERROR, "Cannot compose SDP for MNCC_RTP_CREATE: no RTP set up for the CN side\n");
1020 trans_free(trans);
1021 return -EINVAL;
1022 }
Oliver Smithc63c3a02023-05-24 10:48:07 +02001023 trans->cc.local.rtp = *rtp_cn_local;
Neels Hofmeyrbd5f8e92022-01-13 23:18:02 +01001024
Oliver Smithceca8e62023-05-24 11:15:52 +02001025 trans_cc_filter_run(trans);
Neels Hofmeyrbd5f8e92022-01-13 23:18:02 +01001026
1027 /* If we haven't completed Assignment yet, don't sent MNCC_RTP_CREATE */
1028 if (!sdp_audio_codec_is_set(&trans->cc.codecs.assignment)) {
1029 LOG_TRANS(trans, LOGL_DEBUG, "no codec confirmed by Assignment yet\n");
1030 return 0;
1031 }
1032
1033 return mncc_recv_rtp(msc_a_net(msc_a), trans, trans->callref, MNCC_RTP_CREATE, rtp_cn_local, 0, 0,
Oliver Smithc63c3a02023-05-24 10:48:07 +02001034 &trans->cc.local);
Harald Welte27989d42018-06-21 20:39:20 +02001035}
1036
1037static int gsm48_cc_tx_call_proc_and_assign(struct gsm_trans *trans, void *arg)
1038{
1039 struct gsm_mncc *proceeding = arg;
1040 struct msgb *msg = gsm48_msgb_alloc_name("GSM 04.08 CC PROC");
1041 struct gsm48_hdr *gh = (struct gsm48_hdr *) msgb_put(msg, sizeof(*gh));
1042 int rc;
1043
1044 gh->msg_type = GSM48_MT_CC_CALL_PROC;
1045
1046 new_cc_state(trans, GSM_CSTATE_MO_CALL_PROC);
1047
1048 /* bearer capability */
1049 if (proceeding->fields & MNCC_F_BEARER_CAP) {
1050 gsm48_encode_bearer_cap(msg, 0, &proceeding->bearer_cap);
1051 memcpy(&trans->bearer_cap, &proceeding->bearer_cap, sizeof(trans->bearer_cap));
1052 }
1053 /* facility */
1054 if (proceeding->fields & MNCC_F_FACILITY)
1055 gsm48_encode_facility(msg, 0, &proceeding->facility);
1056 /* progress */
1057 if (proceeding->fields & MNCC_F_PROGRESS)
1058 gsm48_encode_progress(msg, 0, &proceeding->progress);
1059
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01001060 rc = trans_tx_gsm48(trans, msg);
Harald Welte27989d42018-06-21 20:39:20 +02001061 if (rc)
1062 return rc;
1063
1064 /* Assign call (if not done yet) */
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01001065 return msc_a_try_call_assignment(trans);
Harald Welte27989d42018-06-21 20:39:20 +02001066}
1067
1068static int gsm48_cc_rx_alerting(struct gsm_trans *trans, struct msgb *msg)
1069{
1070 struct gsm48_hdr *gh = msgb_l3(msg);
1071 unsigned int payload_len = msgb_l3len(msg) - sizeof(*gh);
1072 struct tlv_parsed tp;
1073 struct gsm_mncc alerting;
Neels Hofmeyr8dd16462022-01-13 20:06:53 +01001074 int rc;
Harald Welte27989d42018-06-21 20:39:20 +02001075
1076 gsm48_stop_cc_timer(trans);
1077 gsm48_start_cc_timer(trans, 0x301, GSM48_T301);
1078
1079 memset(&alerting, 0, sizeof(struct gsm_mncc));
1080 alerting.callref = trans->callref;
1081 tlv_parse(&tp, &gsm48_att_tlvdef, gh->data, payload_len, 0, 0);
1082 /* facility */
1083 if (TLVP_PRESENT(&tp, GSM48_IE_FACILITY)) {
1084 alerting.fields |= MNCC_F_FACILITY;
1085 gsm48_decode_facility(&alerting.facility,
1086 TLVP_VAL(&tp, GSM48_IE_FACILITY)-1);
1087 }
1088
1089 /* progress */
1090 if (TLVP_PRESENT(&tp, GSM48_IE_PROGR_IND)) {
1091 alerting.fields |= MNCC_F_PROGRESS;
1092 gsm48_decode_progress(&alerting.progress,
1093 TLVP_VAL(&tp, GSM48_IE_PROGR_IND)-1);
1094 }
1095 /* ss-version */
1096 if (TLVP_PRESENT(&tp, GSM48_IE_SS_VERS)) {
1097 alerting.fields |= MNCC_F_SSVERSION;
1098 gsm48_decode_ssversion(&alerting.ssversion,
1099 TLVP_VAL(&tp, GSM48_IE_SS_VERS)-1);
1100 }
1101
1102 new_cc_state(trans, GSM_CSTATE_CALL_RECEIVED);
1103
Oliver Smithceca8e62023-05-24 11:15:52 +02001104 trans_cc_filter_run(trans);
Oliver Smithc63c3a02023-05-24 10:48:07 +02001105 rc = sdp_msg_to_sdp_str_buf(alerting.sdp, sizeof(alerting.sdp), &trans->cc.local);
Neels Hofmeyr8dd16462022-01-13 20:06:53 +01001106 if (rc >= sizeof(alerting.sdp)) {
1107 LOG_TRANS(trans, LOGL_ERROR, "MNCC_ALERT_IND: SDP too long (%d > %zu bytes)\n",
1108 rc, sizeof(alerting.sdp));
1109 trans_free(trans);
1110 return -EINVAL;
1111 }
1112
Harald Welte27989d42018-06-21 20:39:20 +02001113 return mncc_recvmsg(trans->net, trans, MNCC_ALERT_IND,
1114 &alerting);
1115}
1116
1117static int gsm48_cc_tx_alerting(struct gsm_trans *trans, void *arg)
1118{
1119 struct gsm_mncc *alerting = arg;
1120 struct msgb *msg = gsm48_msgb_alloc_name("GSM 04.08 CC ALERT");
1121 struct gsm48_hdr *gh = (struct gsm48_hdr *) msgb_put(msg, sizeof(*gh));
Oliver Smith8e16e8b2023-06-22 11:27:24 +02001122 int rc;
Harald Welte27989d42018-06-21 20:39:20 +02001123
1124 gh->msg_type = GSM48_MT_CC_ALERTING;
1125
1126 /* facility */
1127 if (alerting->fields & MNCC_F_FACILITY)
1128 gsm48_encode_facility(msg, 0, &alerting->facility);
1129 /* progress */
1130 if (alerting->fields & MNCC_F_PROGRESS)
1131 gsm48_encode_progress(msg, 0, &alerting->progress);
1132 /* user-user */
1133 if (alerting->fields & MNCC_F_USERUSER)
1134 gsm48_encode_useruser(msg, 0, &alerting->useruser);
1135
1136 new_cc_state(trans, GSM_CSTATE_CALL_DELIVERED);
1137
Neels Hofmeyr8dd16462022-01-13 20:06:53 +01001138 if (alerting->sdp[0]) {
1139 struct call_leg *cl = trans->msc_a->cc.call_leg;
1140 struct rtp_stream *rtp_cn = cl ? cl->rtp[RTP_TO_CN] : NULL;
Oliver Smith8e16e8b2023-06-22 11:27:24 +02001141
1142 rc = sdp_msg_from_sdp_str(&trans->cc.remote, alerting->sdp);
1143 if (rc < 0)
1144 return rc;
1145
Oliver Smithceca8e62023-05-24 11:15:52 +02001146 trans_cc_filter_run(trans);
1147 LOG_TRANS(trans, LOGL_DEBUG, "msg_type=%s\n", get_mncc_name(alerting->msg_type));
Neels Hofmeyr8dd16462022-01-13 20:06:53 +01001148 if (rtp_cn) {
Oliver Smith593cd882023-05-24 10:40:19 +02001149 rtp_stream_set_remote_addr_and_codecs(rtp_cn, &trans->cc.remote);
Neels Hofmeyr8dd16462022-01-13 20:06:53 +01001150 rtp_stream_commit(rtp_cn);
1151 }
1152 }
1153
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01001154 return trans_tx_gsm48(trans, msg);
Harald Welte27989d42018-06-21 20:39:20 +02001155}
1156
1157static int gsm48_cc_tx_progress(struct gsm_trans *trans, void *arg)
1158{
1159 struct gsm_mncc *progress = arg;
1160 struct msgb *msg = gsm48_msgb_alloc_name("GSM 04.08 CC PROGRESS");
1161 struct gsm48_hdr *gh = (struct gsm48_hdr *) msgb_put(msg, sizeof(*gh));
1162
1163 gh->msg_type = GSM48_MT_CC_PROGRESS;
1164
1165 /* progress */
1166 gsm48_encode_progress(msg, 1, &progress->progress);
1167 /* user-user */
1168 if (progress->fields & MNCC_F_USERUSER)
1169 gsm48_encode_useruser(msg, 0, &progress->useruser);
1170
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01001171 return trans_tx_gsm48(trans, msg);
Harald Welte27989d42018-06-21 20:39:20 +02001172}
1173
1174static int gsm48_cc_tx_connect(struct gsm_trans *trans, void *arg)
1175{
1176 struct gsm_mncc *connect = arg;
1177 struct msgb *msg = gsm48_msgb_alloc_name("GSN 04.08 CC CON");
1178 struct gsm48_hdr *gh = (struct gsm48_hdr *) msgb_put(msg, sizeof(*gh));
1179
1180 gh->msg_type = GSM48_MT_CC_CONNECT;
1181
1182 gsm48_stop_cc_timer(trans);
1183 gsm48_start_cc_timer(trans, 0x313, GSM48_T313);
1184
1185 /* facility */
1186 if (connect->fields & MNCC_F_FACILITY)
1187 gsm48_encode_facility(msg, 0, &connect->facility);
1188 /* progress */
1189 if (connect->fields & MNCC_F_PROGRESS)
1190 gsm48_encode_progress(msg, 0, &connect->progress);
1191 /* connected number */
1192 if (connect->fields & MNCC_F_CONNECTED)
1193 gsm48_encode_connected(msg, &connect->connected);
1194 /* user-user */
1195 if (connect->fields & MNCC_F_USERUSER)
1196 gsm48_encode_useruser(msg, 0, &connect->useruser);
1197
1198 new_cc_state(trans, GSM_CSTATE_CONNECT_IND);
1199
Neels Hofmeyr8dd16462022-01-13 20:06:53 +01001200 /* Received an MNCC_SETUP_RSP with the remote leg's SDP information. Apply codec choice. */
1201 if (connect->sdp[0]) {
1202 struct call_leg *cl = trans->msc_a->cc.call_leg;
1203 struct rtp_stream *rtp_cn = cl ? cl->rtp[RTP_TO_CN] : NULL;
1204 rx_mncc_sdp(trans, connect->msg_type, connect->sdp);
Oliver Smithceca8e62023-05-24 11:15:52 +02001205 trans_cc_filter_run(trans);
1206 LOG_TRANS(trans, LOGL_DEBUG, "msg_type=%s\n", get_mncc_name(connect->msg_type));
Neels Hofmeyr8dd16462022-01-13 20:06:53 +01001207 if (rtp_cn) {
Oliver Smith593cd882023-05-24 10:40:19 +02001208 rtp_stream_set_remote_addr_and_codecs(rtp_cn, &trans->cc.remote);
Neels Hofmeyr8dd16462022-01-13 20:06:53 +01001209 rtp_stream_commit(rtp_cn);
1210 }
1211 }
1212
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01001213 return trans_tx_gsm48(trans, msg);
Harald Welte27989d42018-06-21 20:39:20 +02001214}
1215
1216static int gsm48_cc_rx_connect(struct gsm_trans *trans, struct msgb *msg)
1217{
1218 struct gsm48_hdr *gh = msgb_l3(msg);
1219 unsigned int payload_len = msgb_l3len(msg) - sizeof(*gh);
1220 struct tlv_parsed tp;
1221 struct gsm_mncc connect;
1222
1223 gsm48_stop_cc_timer(trans);
1224
1225 memset(&connect, 0, sizeof(struct gsm_mncc));
1226 connect.callref = trans->callref;
1227 tlv_parse(&tp, &gsm48_att_tlvdef, gh->data, payload_len, 0, 0);
1228 /* use subscriber as connected party number */
1229 connect.fields |= MNCC_F_CONNECTED;
1230 OSMO_STRLCPY_ARRAY(connect.connected.number, trans->vsub->msisdn);
1231 OSMO_STRLCPY_ARRAY(connect.imsi, trans->vsub->imsi);
1232
1233 /* facility */
1234 if (TLVP_PRESENT(&tp, GSM48_IE_FACILITY)) {
1235 connect.fields |= MNCC_F_FACILITY;
1236 gsm48_decode_facility(&connect.facility,
1237 TLVP_VAL(&tp, GSM48_IE_FACILITY)-1);
1238 }
1239 /* user-user */
1240 if (TLVP_PRESENT(&tp, GSM48_IE_USER_USER)) {
1241 connect.fields |= MNCC_F_USERUSER;
1242 gsm48_decode_useruser(&connect.useruser,
1243 TLVP_VAL(&tp, GSM48_IE_USER_USER)-1);
1244 }
1245 /* ss-version */
1246 if (TLVP_PRESENT(&tp, GSM48_IE_SS_VERS)) {
1247 connect.fields |= MNCC_F_SSVERSION;
1248 gsm48_decode_ssversion(&connect.ssversion,
1249 TLVP_VAL(&tp, GSM48_IE_SS_VERS)-1);
1250 }
1251
1252 new_cc_state(trans, GSM_CSTATE_CONNECT_REQUEST);
Pau Espin Pedrol2e21a682021-06-04 16:45:44 +02001253 rate_ctr_inc(rate_ctr_group_get_ctr(trans->net->msc_ctrs, MSC_CTR_CALL_MT_CONNECT));
Harald Welte27989d42018-06-21 20:39:20 +02001254
Oliver Smithceca8e62023-05-24 11:15:52 +02001255 trans_cc_filter_run(trans);
Oliver Smithc63c3a02023-05-24 10:48:07 +02001256 sdp_msg_to_sdp_str_buf(connect.sdp, sizeof(connect.sdp), &trans->cc.local);
Harald Welte27989d42018-06-21 20:39:20 +02001257 return mncc_recvmsg(trans->net, trans, MNCC_SETUP_CNF, &connect);
1258}
1259
1260
1261static int gsm48_cc_rx_connect_ack(struct gsm_trans *trans, struct msgb *msg)
1262{
1263 struct gsm_mncc connect_ack;
1264
1265 gsm48_stop_cc_timer(trans);
1266
1267 new_cc_state(trans, GSM_CSTATE_ACTIVE);
Pau Espin Pedrol2e21a682021-06-04 16:45:44 +02001268 rate_ctr_inc(rate_ctr_group_get_ctr(trans->net->msc_ctrs, MSC_CTR_CALL_MO_CONNECT_ACK));
Harald Welte27989d42018-06-21 20:39:20 +02001269
1270 memset(&connect_ack, 0, sizeof(struct gsm_mncc));
1271 connect_ack.callref = trans->callref;
1272
1273 return mncc_recvmsg(trans->net, trans, MNCC_SETUP_COMPL_IND,
1274 &connect_ack);
1275}
1276
1277static int gsm48_cc_tx_connect_ack(struct gsm_trans *trans, void *arg)
1278{
1279 struct msgb *msg = gsm48_msgb_alloc_name("GSM 04.08 CC CON ACK");
1280 struct gsm48_hdr *gh = (struct gsm48_hdr *) msgb_put(msg, sizeof(*gh));
1281
1282 gh->msg_type = GSM48_MT_CC_CONNECT_ACK;
1283
1284 new_cc_state(trans, GSM_CSTATE_ACTIVE);
1285
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01001286 return trans_tx_gsm48(trans, msg);
Harald Welte27989d42018-06-21 20:39:20 +02001287}
1288
1289static int gsm48_cc_rx_disconnect(struct gsm_trans *trans, struct msgb *msg)
1290{
1291 struct gsm48_hdr *gh = msgb_l3(msg);
1292 unsigned int payload_len = msgb_l3len(msg) - sizeof(*gh);
1293 struct tlv_parsed tp;
1294 struct gsm_mncc disc;
1295
1296 gsm48_stop_cc_timer(trans);
1297
1298 new_cc_state(trans, GSM_CSTATE_DISCONNECT_REQ);
1299
1300 memset(&disc, 0, sizeof(struct gsm_mncc));
1301 disc.callref = trans->callref;
1302 tlv_parse(&tp, &gsm48_att_tlvdef, gh->data, payload_len, GSM48_IE_CAUSE, 0);
1303 /* cause */
1304 if (TLVP_PRESENT(&tp, GSM48_IE_CAUSE)) {
1305 disc.fields |= MNCC_F_CAUSE;
1306 gsm48_decode_cause(&disc.cause,
1307 TLVP_VAL(&tp, GSM48_IE_CAUSE)-1);
1308 }
1309 /* facility */
1310 if (TLVP_PRESENT(&tp, GSM48_IE_FACILITY)) {
1311 disc.fields |= MNCC_F_FACILITY;
1312 gsm48_decode_facility(&disc.facility,
1313 TLVP_VAL(&tp, GSM48_IE_FACILITY)-1);
1314 }
1315 /* user-user */
1316 if (TLVP_PRESENT(&tp, GSM48_IE_USER_USER)) {
1317 disc.fields |= MNCC_F_USERUSER;
1318 gsm48_decode_useruser(&disc.useruser,
1319 TLVP_VAL(&tp, GSM48_IE_USER_USER)-1);
1320 }
1321 /* ss-version */
1322 if (TLVP_PRESENT(&tp, GSM48_IE_SS_VERS)) {
1323 disc.fields |= MNCC_F_SSVERSION;
1324 gsm48_decode_ssversion(&disc.ssversion,
1325 TLVP_VAL(&tp, GSM48_IE_SS_VERS)-1);
1326 }
1327
1328 return mncc_recvmsg(trans->net, trans, MNCC_DISC_IND, &disc);
Harald Welte27989d42018-06-21 20:39:20 +02001329}
1330
1331static struct gsm_mncc_cause default_cause = {
1332 .location = GSM48_CAUSE_LOC_PRN_S_LU,
1333 .coding = 0,
1334 .rec = 0,
1335 .rec_val = 0,
1336 .value = GSM48_CC_CAUSE_NORMAL_UNSPEC,
1337 .diag_len = 0,
1338 .diag = { 0 },
1339};
1340
1341static int gsm48_cc_tx_disconnect(struct gsm_trans *trans, void *arg)
1342{
1343 struct gsm_mncc *disc = arg;
1344 struct msgb *msg = gsm48_msgb_alloc_name("GSM 04.08 CC DISC");
1345 struct gsm48_hdr *gh = (struct gsm48_hdr *) msgb_put(msg, sizeof(*gh));
1346
1347 gh->msg_type = GSM48_MT_CC_DISCONNECT;
1348
1349 gsm48_stop_cc_timer(trans);
1350 gsm48_start_cc_timer(trans, 0x306, GSM48_T306);
1351
1352 /* cause */
1353 if (disc->fields & MNCC_F_CAUSE)
1354 gsm48_encode_cause(msg, 1, &disc->cause);
1355 else
1356 gsm48_encode_cause(msg, 1, &default_cause);
1357
1358 /* facility */
1359 if (disc->fields & MNCC_F_FACILITY)
1360 gsm48_encode_facility(msg, 0, &disc->facility);
1361 /* progress */
1362 if (disc->fields & MNCC_F_PROGRESS)
1363 gsm48_encode_progress(msg, 0, &disc->progress);
1364 /* user-user */
1365 if (disc->fields & MNCC_F_USERUSER)
1366 gsm48_encode_useruser(msg, 0, &disc->useruser);
1367
1368 /* store disconnect cause for T306 expiry */
1369 memcpy(&trans->cc.msg, disc, sizeof(struct gsm_mncc));
1370
1371 new_cc_state(trans, GSM_CSTATE_DISCONNECT_IND);
1372
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01001373 return trans_tx_gsm48(trans, msg);
Harald Welte27989d42018-06-21 20:39:20 +02001374}
1375
1376static int gsm48_cc_rx_release(struct gsm_trans *trans, struct msgb *msg)
1377{
1378 struct gsm48_hdr *gh = msgb_l3(msg);
1379 unsigned int payload_len = msgb_l3len(msg) - sizeof(*gh);
1380 struct tlv_parsed tp;
1381 struct gsm_mncc rel;
1382 int rc;
1383
1384 gsm48_stop_cc_timer(trans);
1385
1386 memset(&rel, 0, sizeof(struct gsm_mncc));
1387 rel.callref = trans->callref;
1388 tlv_parse(&tp, &gsm48_att_tlvdef, gh->data, payload_len, 0, 0);
1389 /* cause */
1390 if (TLVP_PRESENT(&tp, GSM48_IE_CAUSE)) {
1391 rel.fields |= MNCC_F_CAUSE;
1392 gsm48_decode_cause(&rel.cause,
1393 TLVP_VAL(&tp, GSM48_IE_CAUSE)-1);
1394 }
1395 /* facility */
1396 if (TLVP_PRESENT(&tp, GSM48_IE_FACILITY)) {
1397 rel.fields |= MNCC_F_FACILITY;
1398 gsm48_decode_facility(&rel.facility,
1399 TLVP_VAL(&tp, GSM48_IE_FACILITY)-1);
1400 }
1401 /* user-user */
1402 if (TLVP_PRESENT(&tp, GSM48_IE_USER_USER)) {
1403 rel.fields |= MNCC_F_USERUSER;
1404 gsm48_decode_useruser(&rel.useruser,
1405 TLVP_VAL(&tp, GSM48_IE_USER_USER)-1);
1406 }
1407 /* ss-version */
1408 if (TLVP_PRESENT(&tp, GSM48_IE_SS_VERS)) {
1409 rel.fields |= MNCC_F_SSVERSION;
1410 gsm48_decode_ssversion(&rel.ssversion,
1411 TLVP_VAL(&tp, GSM48_IE_SS_VERS)-1);
1412 }
1413
1414 if (trans->cc.state == GSM_CSTATE_RELEASE_REQ) {
1415 /* release collision 5.4.5 */
1416 rc = mncc_recvmsg(trans->net, trans, MNCC_REL_CNF, &rel);
1417 } else {
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01001418 rc = gsm48_tx_simple(trans->msc_a,
Harald Welte27989d42018-06-21 20:39:20 +02001419 GSM48_PDISC_CC | (trans->transaction_id << 4),
1420 GSM48_MT_CC_RELEASE_COMPL);
1421 rc = mncc_recvmsg(trans->net, trans, MNCC_REL_IND, &rel);
1422 }
1423
1424 new_cc_state(trans, GSM_CSTATE_NULL);
1425
1426 trans->callref = 0;
1427 trans_free(trans);
1428
1429 return rc;
1430}
1431
1432static int gsm48_cc_tx_release(struct gsm_trans *trans, void *arg)
1433{
1434 struct gsm_mncc *rel = arg;
Neels Hofmeyr2e8f8812019-08-21 16:56:41 +02001435 struct msgb *msg;
1436 struct gsm48_hdr *gh;
1437
1438 if (!trans->msc_a) {
1439 LOG_TRANS(trans, LOGL_DEBUG, "Cannot send CC REL, there is no MSC-A connection\n");
1440 return -EINVAL;
1441 }
1442
1443 msg = gsm48_msgb_alloc_name("GSM 04.08 CC REL");
1444 gh = (struct gsm48_hdr *) msgb_put(msg, sizeof(*gh));
Harald Welte27989d42018-06-21 20:39:20 +02001445
1446 gh->msg_type = GSM48_MT_CC_RELEASE;
1447
1448 gsm48_stop_cc_timer(trans);
1449 gsm48_start_cc_timer(trans, 0x308, GSM48_T308);
1450
1451 /* cause */
1452 if (rel->fields & MNCC_F_CAUSE)
1453 gsm48_encode_cause(msg, 0, &rel->cause);
1454 /* facility */
1455 if (rel->fields & MNCC_F_FACILITY)
1456 gsm48_encode_facility(msg, 0, &rel->facility);
1457 /* user-user */
1458 if (rel->fields & MNCC_F_USERUSER)
1459 gsm48_encode_useruser(msg, 0, &rel->useruser);
1460
1461 trans->cc.T308_second = 0;
1462 memcpy(&trans->cc.msg, rel, sizeof(struct gsm_mncc));
1463
1464 if (trans->cc.state != GSM_CSTATE_RELEASE_REQ)
1465 new_cc_state(trans, GSM_CSTATE_RELEASE_REQ);
1466
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01001467 return trans_tx_gsm48(trans, msg);
Harald Welte27989d42018-06-21 20:39:20 +02001468}
1469
1470static int gsm48_cc_rx_release_compl(struct gsm_trans *trans, struct msgb *msg)
1471{
1472 struct gsm48_hdr *gh = msgb_l3(msg);
1473 unsigned int payload_len = msgb_l3len(msg) - sizeof(*gh);
1474 struct tlv_parsed tp;
1475 struct gsm_mncc rel;
1476 int rc = 0;
1477
1478 gsm48_stop_cc_timer(trans);
1479
1480 memset(&rel, 0, sizeof(struct gsm_mncc));
1481 rel.callref = trans->callref;
1482 tlv_parse(&tp, &gsm48_att_tlvdef, gh->data, payload_len, 0, 0);
1483 /* cause */
1484 if (TLVP_PRESENT(&tp, GSM48_IE_CAUSE)) {
1485 rel.fields |= MNCC_F_CAUSE;
1486 gsm48_decode_cause(&rel.cause,
1487 TLVP_VAL(&tp, GSM48_IE_CAUSE)-1);
1488 }
1489 /* facility */
1490 if (TLVP_PRESENT(&tp, GSM48_IE_FACILITY)) {
1491 rel.fields |= MNCC_F_FACILITY;
1492 gsm48_decode_facility(&rel.facility,
1493 TLVP_VAL(&tp, GSM48_IE_FACILITY)-1);
1494 }
1495 /* user-user */
1496 if (TLVP_PRESENT(&tp, GSM48_IE_USER_USER)) {
1497 rel.fields |= MNCC_F_USERUSER;
1498 gsm48_decode_useruser(&rel.useruser,
1499 TLVP_VAL(&tp, GSM48_IE_USER_USER)-1);
1500 }
1501 /* ss-version */
1502 if (TLVP_PRESENT(&tp, GSM48_IE_SS_VERS)) {
1503 rel.fields |= MNCC_F_SSVERSION;
1504 gsm48_decode_ssversion(&rel.ssversion,
1505 TLVP_VAL(&tp, GSM48_IE_SS_VERS)-1);
1506 }
1507
1508 if (trans->callref) {
1509 switch (trans->cc.state) {
1510 case GSM_CSTATE_CALL_PRESENT:
1511 rc = mncc_recvmsg(trans->net, trans,
1512 MNCC_REJ_IND, &rel);
1513 break;
1514 case GSM_CSTATE_RELEASE_REQ:
1515 rc = mncc_recvmsg(trans->net, trans,
1516 MNCC_REL_CNF, &rel);
1517 break;
1518 default:
1519 rc = mncc_recvmsg(trans->net, trans,
1520 MNCC_REL_IND, &rel);
1521 }
1522 }
1523
1524 trans->callref = 0;
1525 trans_free(trans);
1526
1527 return rc;
1528}
1529
1530static int gsm48_cc_tx_release_compl(struct gsm_trans *trans, void *arg)
1531{
1532 struct gsm_mncc *rel = arg;
1533 struct msgb *msg = gsm48_msgb_alloc_name("GSM 04.08 CC REL COMPL");
1534 struct gsm48_hdr *gh = (struct gsm48_hdr *) msgb_put(msg, sizeof(*gh));
1535 int ret;
1536
1537 gh->msg_type = GSM48_MT_CC_RELEASE_COMPL;
1538
1539 trans->callref = 0;
1540
1541 gsm48_stop_cc_timer(trans);
1542
1543 /* cause */
1544 if (rel->fields & MNCC_F_CAUSE)
1545 gsm48_encode_cause(msg, 0, &rel->cause);
1546 /* facility */
1547 if (rel->fields & MNCC_F_FACILITY)
1548 gsm48_encode_facility(msg, 0, &rel->facility);
1549 /* user-user */
1550 if (rel->fields & MNCC_F_USERUSER)
1551 gsm48_encode_useruser(msg, 0, &rel->useruser);
1552
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01001553 ret = trans_tx_gsm48(trans, msg);
Harald Welte27989d42018-06-21 20:39:20 +02001554
1555 trans_free(trans);
1556
1557 return ret;
1558}
1559
1560static int gsm48_cc_rx_facility(struct gsm_trans *trans, struct msgb *msg)
1561{
1562 struct gsm48_hdr *gh = msgb_l3(msg);
1563 unsigned int payload_len = msgb_l3len(msg) - sizeof(*gh);
1564 struct tlv_parsed tp;
1565 struct gsm_mncc fac;
1566
1567 memset(&fac, 0, sizeof(struct gsm_mncc));
1568 fac.callref = trans->callref;
1569 tlv_parse(&tp, &gsm48_att_tlvdef, gh->data, payload_len, GSM48_IE_FACILITY, 0);
1570 /* facility */
1571 if (TLVP_PRESENT(&tp, GSM48_IE_FACILITY)) {
1572 fac.fields |= MNCC_F_FACILITY;
1573 gsm48_decode_facility(&fac.facility,
1574 TLVP_VAL(&tp, GSM48_IE_FACILITY)-1);
1575 }
1576 /* ss-version */
1577 if (TLVP_PRESENT(&tp, GSM48_IE_SS_VERS)) {
1578 fac.fields |= MNCC_F_SSVERSION;
1579 gsm48_decode_ssversion(&fac.ssversion,
1580 TLVP_VAL(&tp, GSM48_IE_SS_VERS)-1);
1581 }
1582
1583 return mncc_recvmsg(trans->net, trans, MNCC_FACILITY_IND, &fac);
1584}
1585
1586static int gsm48_cc_tx_facility(struct gsm_trans *trans, void *arg)
1587{
1588 struct gsm_mncc *fac = arg;
1589 struct msgb *msg = gsm48_msgb_alloc_name("GSM 04.08 CC FAC");
1590 struct gsm48_hdr *gh = (struct gsm48_hdr *) msgb_put(msg, sizeof(*gh));
1591
1592 gh->msg_type = GSM48_MT_CC_FACILITY;
1593
1594 /* facility */
1595 gsm48_encode_facility(msg, 1, &fac->facility);
1596
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01001597 return trans_tx_gsm48(trans, msg);
Harald Welte27989d42018-06-21 20:39:20 +02001598}
1599
1600static int gsm48_cc_rx_hold(struct gsm_trans *trans, struct msgb *msg)
1601{
1602 struct gsm_mncc hold;
1603
1604 memset(&hold, 0, sizeof(struct gsm_mncc));
1605 hold.callref = trans->callref;
1606 return mncc_recvmsg(trans->net, trans, MNCC_HOLD_IND, &hold);
1607}
1608
1609static int gsm48_cc_tx_hold_ack(struct gsm_trans *trans, void *arg)
1610{
1611 struct msgb *msg = gsm48_msgb_alloc_name("GSM 04.08 CC HLD ACK");
1612 struct gsm48_hdr *gh = (struct gsm48_hdr *) msgb_put(msg, sizeof(*gh));
1613
1614 gh->msg_type = GSM48_MT_CC_HOLD_ACK;
1615
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01001616 return trans_tx_gsm48(trans, msg);
Harald Welte27989d42018-06-21 20:39:20 +02001617}
1618
1619static int gsm48_cc_tx_hold_rej(struct gsm_trans *trans, void *arg)
1620{
1621 struct gsm_mncc *hold_rej = arg;
1622 struct msgb *msg = gsm48_msgb_alloc_name("GSM 04.08 CC HLD REJ");
1623 struct gsm48_hdr *gh = (struct gsm48_hdr *) msgb_put(msg, sizeof(*gh));
1624
1625 gh->msg_type = GSM48_MT_CC_HOLD_REJ;
1626
1627 /* cause */
1628 if (hold_rej->fields & MNCC_F_CAUSE)
1629 gsm48_encode_cause(msg, 1, &hold_rej->cause);
1630 else
1631 gsm48_encode_cause(msg, 1, &default_cause);
1632
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01001633 return trans_tx_gsm48(trans, msg);
Harald Welte27989d42018-06-21 20:39:20 +02001634}
1635
1636static int gsm48_cc_rx_retrieve(struct gsm_trans *trans, struct msgb *msg)
1637{
1638 struct gsm_mncc retrieve;
1639
1640 memset(&retrieve, 0, sizeof(struct gsm_mncc));
1641 retrieve.callref = trans->callref;
1642 return mncc_recvmsg(trans->net, trans, MNCC_RETRIEVE_IND,
1643 &retrieve);
1644}
1645
1646static int gsm48_cc_tx_retrieve_ack(struct gsm_trans *trans, void *arg)
1647{
1648 struct msgb *msg = gsm48_msgb_alloc_name("GSM 04.08 CC RETR ACK");
1649 struct gsm48_hdr *gh = (struct gsm48_hdr *) msgb_put(msg, sizeof(*gh));
1650
1651 gh->msg_type = GSM48_MT_CC_RETR_ACK;
1652
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01001653 return trans_tx_gsm48(trans, msg);
Harald Welte27989d42018-06-21 20:39:20 +02001654}
1655
1656static int gsm48_cc_tx_retrieve_rej(struct gsm_trans *trans, void *arg)
1657{
1658 struct gsm_mncc *retrieve_rej = arg;
1659 struct msgb *msg = gsm48_msgb_alloc_name("GSM 04.08 CC RETR REJ");
1660 struct gsm48_hdr *gh = (struct gsm48_hdr *) msgb_put(msg, sizeof(*gh));
1661
1662 gh->msg_type = GSM48_MT_CC_RETR_REJ;
1663
1664 /* cause */
1665 if (retrieve_rej->fields & MNCC_F_CAUSE)
1666 gsm48_encode_cause(msg, 1, &retrieve_rej->cause);
1667 else
1668 gsm48_encode_cause(msg, 1, &default_cause);
1669
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01001670 return trans_tx_gsm48(trans, msg);
Harald Welte27989d42018-06-21 20:39:20 +02001671}
1672
1673static int gsm48_cc_rx_start_dtmf(struct gsm_trans *trans, struct msgb *msg)
1674{
1675 struct gsm48_hdr *gh = msgb_l3(msg);
1676 unsigned int payload_len = msgb_l3len(msg) - sizeof(*gh);
1677 struct tlv_parsed tp;
1678 struct gsm_mncc dtmf;
1679
1680 memset(&dtmf, 0, sizeof(struct gsm_mncc));
1681 dtmf.callref = trans->callref;
1682 tlv_parse(&tp, &gsm48_att_tlvdef, gh->data, payload_len, 0, 0);
1683 /* keypad facility */
1684 if (TLVP_PRESENT(&tp, GSM48_IE_KPD_FACILITY)) {
1685 dtmf.fields |= MNCC_F_KEYPAD;
1686 gsm48_decode_keypad(&dtmf.keypad,
1687 TLVP_VAL(&tp, GSM48_IE_KPD_FACILITY)-1);
1688 }
1689
1690 return mncc_recvmsg(trans->net, trans, MNCC_START_DTMF_IND, &dtmf);
1691}
1692
1693static int gsm48_cc_tx_start_dtmf_ack(struct gsm_trans *trans, void *arg)
1694{
1695 struct gsm_mncc *dtmf = arg;
1696 struct msgb *msg = gsm48_msgb_alloc_name("GSM 04.08 DTMF ACK");
1697 struct gsm48_hdr *gh = (struct gsm48_hdr *) msgb_put(msg, sizeof(*gh));
1698
1699 gh->msg_type = GSM48_MT_CC_START_DTMF_ACK;
1700
1701 /* keypad */
1702 if (dtmf->fields & MNCC_F_KEYPAD)
1703 gsm48_encode_keypad(msg, dtmf->keypad);
1704
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01001705 return trans_tx_gsm48(trans, msg);
Harald Welte27989d42018-06-21 20:39:20 +02001706}
1707
1708static int gsm48_cc_tx_start_dtmf_rej(struct gsm_trans *trans, void *arg)
1709{
1710 struct gsm_mncc *dtmf = arg;
1711 struct msgb *msg = gsm48_msgb_alloc_name("GSM 04.08 DTMF REJ");
1712 struct gsm48_hdr *gh = (struct gsm48_hdr *) msgb_put(msg, sizeof(*gh));
1713
1714 gh->msg_type = GSM48_MT_CC_START_DTMF_REJ;
1715
1716 /* cause */
1717 if (dtmf->fields & MNCC_F_CAUSE)
1718 gsm48_encode_cause(msg, 1, &dtmf->cause);
1719 else
1720 gsm48_encode_cause(msg, 1, &default_cause);
1721
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01001722 return trans_tx_gsm48(trans, msg);
Harald Welte27989d42018-06-21 20:39:20 +02001723}
1724
1725static int gsm48_cc_tx_stop_dtmf_ack(struct gsm_trans *trans, void *arg)
1726{
1727 struct msgb *msg = gsm48_msgb_alloc_name("GSM 04.08 DTMF STP ACK");
1728 struct gsm48_hdr *gh = (struct gsm48_hdr *) msgb_put(msg, sizeof(*gh));
1729
1730 gh->msg_type = GSM48_MT_CC_STOP_DTMF_ACK;
1731
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01001732 return trans_tx_gsm48(trans, msg);
Harald Welte27989d42018-06-21 20:39:20 +02001733}
1734
1735static int gsm48_cc_rx_stop_dtmf(struct gsm_trans *trans, struct msgb *msg)
1736{
1737 struct gsm_mncc dtmf;
1738
1739 memset(&dtmf, 0, sizeof(struct gsm_mncc));
1740 dtmf.callref = trans->callref;
1741
1742 return mncc_recvmsg(trans->net, trans, MNCC_STOP_DTMF_IND, &dtmf);
1743}
1744
1745static int gsm48_cc_rx_modify(struct gsm_trans *trans, struct msgb *msg)
1746{
1747 struct gsm48_hdr *gh = msgb_l3(msg);
1748 unsigned int payload_len = msgb_l3len(msg) - sizeof(*gh);
1749 struct tlv_parsed tp;
1750 struct gsm_mncc modify;
1751
1752 memset(&modify, 0, sizeof(struct gsm_mncc));
1753 modify.callref = trans->callref;
1754 tlv_parse(&tp, &gsm48_att_tlvdef, gh->data, payload_len, GSM48_IE_BEARER_CAP, 0);
1755 /* bearer capability */
1756 if (TLVP_PRESENT(&tp, GSM48_IE_BEARER_CAP)) {
1757 modify.fields |= MNCC_F_BEARER_CAP;
1758 gsm48_decode_bearer_cap(&modify.bearer_cap,
1759 TLVP_VAL(&tp, GSM48_IE_BEARER_CAP)-1);
1760
1761 /* Create a copy of the bearer capability
1762 * in the transaction struct, so we can use
1763 * this information later */
1764 memcpy(&trans->bearer_cap,&modify.bearer_cap,
1765 sizeof(trans->bearer_cap));
1766 }
1767
1768 new_cc_state(trans, GSM_CSTATE_MO_ORIG_MODIFY);
1769
1770 return mncc_recvmsg(trans->net, trans, MNCC_MODIFY_IND, &modify);
1771}
1772
1773static int gsm48_cc_tx_modify(struct gsm_trans *trans, void *arg)
1774{
1775 struct gsm_mncc *modify = arg;
1776 struct msgb *msg = gsm48_msgb_alloc_name("GSM 04.08 CC MOD");
1777 struct gsm48_hdr *gh = (struct gsm48_hdr *) msgb_put(msg, sizeof(*gh));
1778
1779 gh->msg_type = GSM48_MT_CC_MODIFY;
1780
1781 gsm48_start_cc_timer(trans, 0x323, GSM48_T323);
1782
1783 /* bearer capability */
1784 gsm48_encode_bearer_cap(msg, 1, &modify->bearer_cap);
1785 memcpy(&trans->bearer_cap, &modify->bearer_cap, sizeof(trans->bearer_cap));
1786
1787 new_cc_state(trans, GSM_CSTATE_MO_TERM_MODIFY);
1788
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01001789 return trans_tx_gsm48(trans, msg);
Harald Welte27989d42018-06-21 20:39:20 +02001790}
1791
1792static int gsm48_cc_rx_modify_complete(struct gsm_trans *trans, struct msgb *msg)
1793{
1794 struct gsm48_hdr *gh = msgb_l3(msg);
1795 unsigned int payload_len = msgb_l3len(msg) - sizeof(*gh);
1796 struct tlv_parsed tp;
1797 struct gsm_mncc modify;
1798
1799 gsm48_stop_cc_timer(trans);
1800
1801 memset(&modify, 0, sizeof(struct gsm_mncc));
1802 modify.callref = trans->callref;
1803 tlv_parse(&tp, &gsm48_att_tlvdef, gh->data, payload_len, GSM48_IE_BEARER_CAP, 0);
1804 /* bearer capability */
1805 if (TLVP_PRESENT(&tp, GSM48_IE_BEARER_CAP)) {
1806 modify.fields |= MNCC_F_BEARER_CAP;
1807 gsm48_decode_bearer_cap(&modify.bearer_cap,
1808 TLVP_VAL(&tp, GSM48_IE_BEARER_CAP)-1);
1809
1810 /* Create a copy of the bearer capability
1811 * in the transaction struct, so we can use
1812 * this information later */
1813 memcpy(&trans->bearer_cap,&modify.bearer_cap,
1814 sizeof(trans->bearer_cap));
1815 }
1816
1817 new_cc_state(trans, GSM_CSTATE_ACTIVE);
1818
1819 return mncc_recvmsg(trans->net, trans, MNCC_MODIFY_CNF, &modify);
1820}
1821
1822static int gsm48_cc_tx_modify_complete(struct gsm_trans *trans, void *arg)
1823{
1824 struct gsm_mncc *modify = arg;
1825 struct msgb *msg = gsm48_msgb_alloc_name("GSM 04.08 CC MOD COMPL");
1826 struct gsm48_hdr *gh = (struct gsm48_hdr *) msgb_put(msg, sizeof(*gh));
1827
1828 gh->msg_type = GSM48_MT_CC_MODIFY_COMPL;
1829
1830 /* bearer capability */
1831 gsm48_encode_bearer_cap(msg, 1, &modify->bearer_cap);
1832 memcpy(&trans->bearer_cap, &modify->bearer_cap, sizeof(trans->bearer_cap));
1833
1834 new_cc_state(trans, GSM_CSTATE_ACTIVE);
1835
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01001836 return trans_tx_gsm48(trans, msg);
Harald Welte27989d42018-06-21 20:39:20 +02001837}
1838
1839static int gsm48_cc_rx_modify_reject(struct gsm_trans *trans, struct msgb *msg)
1840{
1841 struct gsm48_hdr *gh = msgb_l3(msg);
1842 unsigned int payload_len = msgb_l3len(msg) - sizeof(*gh);
1843 struct tlv_parsed tp;
1844 struct gsm_mncc modify;
1845
1846 gsm48_stop_cc_timer(trans);
1847
1848 memset(&modify, 0, sizeof(struct gsm_mncc));
1849 modify.callref = trans->callref;
1850 tlv_parse(&tp, &gsm48_att_tlvdef, gh->data, payload_len, GSM48_IE_BEARER_CAP, GSM48_IE_CAUSE);
1851 /* bearer capability */
1852 if (TLVP_PRESENT(&tp, GSM48_IE_BEARER_CAP)) {
1853 modify.fields |= GSM48_IE_BEARER_CAP;
1854 gsm48_decode_bearer_cap(&modify.bearer_cap,
1855 TLVP_VAL(&tp, GSM48_IE_BEARER_CAP)-1);
1856
1857 /* Create a copy of the bearer capability
1858 * in the transaction struct, so we can use
1859 * this information later */
1860 memcpy(&trans->bearer_cap,&modify.bearer_cap,
1861 sizeof(trans->bearer_cap));
1862 }
1863 /* cause */
1864 if (TLVP_PRESENT(&tp, GSM48_IE_CAUSE)) {
1865 modify.fields |= MNCC_F_CAUSE;
1866 gsm48_decode_cause(&modify.cause,
1867 TLVP_VAL(&tp, GSM48_IE_CAUSE)-1);
1868 }
1869
1870 new_cc_state(trans, GSM_CSTATE_ACTIVE);
1871
1872 return mncc_recvmsg(trans->net, trans, MNCC_MODIFY_REJ, &modify);
1873}
1874
1875static int gsm48_cc_tx_modify_reject(struct gsm_trans *trans, void *arg)
1876{
1877 struct gsm_mncc *modify = arg;
1878 struct msgb *msg = gsm48_msgb_alloc_name("GSM 04.08 CC MOD REJ");
1879 struct gsm48_hdr *gh = (struct gsm48_hdr *) msgb_put(msg, sizeof(*gh));
1880
1881 gh->msg_type = GSM48_MT_CC_MODIFY_REJECT;
1882
1883 /* bearer capability */
1884 gsm48_encode_bearer_cap(msg, 1, &modify->bearer_cap);
1885 memcpy(&trans->bearer_cap, &modify->bearer_cap, sizeof(trans->bearer_cap));
1886 /* cause */
1887 gsm48_encode_cause(msg, 1, &modify->cause);
1888
1889 new_cc_state(trans, GSM_CSTATE_ACTIVE);
1890
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01001891 return trans_tx_gsm48(trans, msg);
Harald Welte27989d42018-06-21 20:39:20 +02001892}
1893
1894static int gsm48_cc_tx_notify(struct gsm_trans *trans, void *arg)
1895{
1896 struct gsm_mncc *notify = arg;
1897 struct msgb *msg = gsm48_msgb_alloc_name("GSM 04.08 CC NOT");
1898 struct gsm48_hdr *gh = (struct gsm48_hdr *) msgb_put(msg, sizeof(*gh));
1899
1900 gh->msg_type = GSM48_MT_CC_NOTIFY;
1901
1902 /* notify */
1903 gsm48_encode_notify(msg, notify->notify);
1904
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01001905 return trans_tx_gsm48(trans, msg);
Harald Welte27989d42018-06-21 20:39:20 +02001906}
1907
1908static int gsm48_cc_rx_notify(struct gsm_trans *trans, struct msgb *msg)
1909{
1910 struct gsm48_hdr *gh = msgb_l3(msg);
1911 unsigned int payload_len = msgb_l3len(msg) - sizeof(*gh);
1912// struct tlv_parsed tp;
1913 struct gsm_mncc notify;
1914
1915 memset(&notify, 0, sizeof(struct gsm_mncc));
1916 notify.callref = trans->callref;
1917// tlv_parse(&tp, &gsm48_att_tlvdef, gh->data, payload_len);
1918 if (payload_len >= 1)
1919 gsm48_decode_notify(&notify.notify, gh->data);
1920
1921 return mncc_recvmsg(trans->net, trans, MNCC_NOTIFY_IND, &notify);
1922}
1923
1924static int gsm48_cc_tx_userinfo(struct gsm_trans *trans, void *arg)
1925{
1926 struct gsm_mncc *user = arg;
1927 struct msgb *msg = gsm48_msgb_alloc_name("GSM 04.08 USR INFO");
1928 struct gsm48_hdr *gh = (struct gsm48_hdr *) msgb_put(msg, sizeof(*gh));
1929
1930 gh->msg_type = GSM48_MT_CC_USER_INFO;
1931
1932 /* user-user */
1933 if (user->fields & MNCC_F_USERUSER)
1934 gsm48_encode_useruser(msg, 1, &user->useruser);
1935 /* more data */
1936 if (user->more)
1937 gsm48_encode_more(msg);
1938
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01001939 return trans_tx_gsm48(trans, msg);
Harald Welte27989d42018-06-21 20:39:20 +02001940}
1941
1942static int gsm48_cc_rx_userinfo(struct gsm_trans *trans, struct msgb *msg)
1943{
1944 struct gsm48_hdr *gh = msgb_l3(msg);
1945 unsigned int payload_len = msgb_l3len(msg) - sizeof(*gh);
1946 struct tlv_parsed tp;
1947 struct gsm_mncc user;
1948
1949 memset(&user, 0, sizeof(struct gsm_mncc));
1950 user.callref = trans->callref;
1951 tlv_parse(&tp, &gsm48_att_tlvdef, gh->data, payload_len, GSM48_IE_USER_USER, 0);
1952 /* user-user */
1953 if (TLVP_PRESENT(&tp, GSM48_IE_USER_USER)) {
1954 user.fields |= MNCC_F_USERUSER;
1955 gsm48_decode_useruser(&user.useruser,
1956 TLVP_VAL(&tp, GSM48_IE_USER_USER)-1);
1957 }
1958 /* more data */
1959 if (TLVP_PRESENT(&tp, GSM48_IE_MORE_DATA))
1960 user.more = 1;
1961
1962 return mncc_recvmsg(trans->net, trans, MNCC_USERINFO_IND, &user);
1963}
1964
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01001965static int mncc_recv_rtp(struct gsm_network *net, struct gsm_trans *trans, uint32_t callref,
1966 int cmd, struct osmo_sockaddr_str *rtp_addr, uint32_t payload_type,
Neels Hofmeyr8dd16462022-01-13 20:06:53 +01001967 uint32_t payload_msg_type, const struct sdp_msg *sdp)
Harald Welte27989d42018-06-21 20:39:20 +02001968{
1969 uint8_t data[sizeof(struct gsm_mncc)];
1970 struct gsm_mncc_rtp *rtp;
1971
1972 memset(&data, 0, sizeof(data));
1973 rtp = (struct gsm_mncc_rtp *) &data[0];
1974
1975 rtp->callref = callref;
1976 rtp->msg_type = cmd;
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01001977 if (rtp_addr) {
Pau Espin Pedroleeda9e12020-09-03 22:11:03 +02001978 if (osmo_sockaddr_str_to_sockaddr(rtp_addr, &rtp->addr) < 0)
1979 return -EINVAL;
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01001980 }
Harald Welte27989d42018-06-21 20:39:20 +02001981 rtp->payload_type = payload_type;
1982 rtp->payload_msg_type = payload_msg_type;
Neels Hofmeyr8dd16462022-01-13 20:06:53 +01001983 if (sdp)
1984 sdp_msg_to_sdp_str_buf(rtp->sdp, sizeof(rtp->sdp), sdp);
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01001985 return mncc_recvmsg(net, trans, cmd, (struct gsm_mncc *)data);
Harald Welte27989d42018-06-21 20:39:20 +02001986}
1987
Neels Hofmeyrc65cfe82019-04-08 03:48:56 +02001988static void mncc_recv_rtp_err(struct gsm_network *net, struct gsm_trans *trans, uint32_t callref, int cmd)
Harald Welte27989d42018-06-21 20:39:20 +02001989{
Neels Hofmeyr8dd16462022-01-13 20:06:53 +01001990 mncc_recv_rtp(net, trans, callref, cmd, NULL, 0, 0, NULL);
Harald Welte27989d42018-06-21 20:39:20 +02001991}
1992
Neels Hofmeyr58f40882023-03-08 04:04:27 +01001993static int tch_rtp_create(struct gsm_network *net, const struct gsm_mncc_rtp *rtp)
Harald Welte27989d42018-06-21 20:39:20 +02001994{
1995 struct gsm_trans *trans;
Harald Welte27989d42018-06-21 20:39:20 +02001996
1997 /* Find callref */
Andreas Eversberg7e4b0322023-04-23 11:43:13 +02001998 trans = trans_find_by_callref(net, TRANS_CC, rtp->callref);
Harald Welte27989d42018-06-21 20:39:20 +02001999 if (!trans) {
Neels Hofmeyrff7074a2019-02-28 05:50:06 +01002000 LOG_TRANS_CAT(trans, DMNCC, LOGL_ERROR, "RTP create for non-existing trans\n");
Neels Hofmeyr58f40882023-03-08 04:04:27 +01002001 mncc_recv_rtp_err(net, trans, rtp->callref, MNCC_RTP_CREATE);
Harald Welte27989d42018-06-21 20:39:20 +02002002 return -EIO;
2003 }
2004 log_set_context(LOG_CTX_VLR_SUBSCR, trans->vsub);
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01002005 if (!trans->msc_a) {
Neels Hofmeyrff7074a2019-02-28 05:50:06 +01002006 LOG_TRANS_CAT(trans, DMNCC, LOGL_NOTICE, "RTP create for trans without conn\n");
Neels Hofmeyr58f40882023-03-08 04:04:27 +01002007 mncc_recv_rtp_err(net, trans, rtp->callref, MNCC_RTP_CREATE);
Harald Welte27989d42018-06-21 20:39:20 +02002008 return 0;
2009 }
Neels Hofmeyr58f40882023-03-08 04:04:27 +01002010 log_mncc_rx_tx(trans, "rx", (const union mncc_msg *)rtp);
Harald Welte27989d42018-06-21 20:39:20 +02002011
Harald Welte27989d42018-06-21 20:39:20 +02002012 /* Assign call (if not done yet) */
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01002013 return msc_a_try_call_assignment(trans);
Harald Welte27989d42018-06-21 20:39:20 +02002014}
2015
Neels Hofmeyrbd5f8e92022-01-13 23:18:02 +01002016int cc_on_cn_local_rtp_port_known(struct gsm_trans *cc_trans)
2017{
2018 /* Depending on MO or MT call, dispatch the event differently */
2019 switch (cc_trans->cc.state) {
2020 case GSM_CSTATE_INITIATED:
2021 if (cc_trans->cc.msg.msg_type != MNCC_SETUP_IND) {
2022 LOG_TRANS(cc_trans, LOGL_ERROR, "Assuming MO call, expected MNCC_SETUP_IND to be prepared\n");
2023 return -EINVAL;
2024 }
2025 /* This is the MO call leg, waiting for a CN RTP be able to send initial MNCC_SETUP_IND. */
2026 gsm48_cc_rx_setup_cn_local_rtp_port_known(cc_trans);
2027 return 0;
2028
2029 case GSM_CSTATE_MO_TERM_CALL_CONF:
2030 /* This is the MT call leg, waiting for a CN RTP to be able to send MNCC_CALL_CONF_IND. */
2031 return gsm48_cc_mt_rtp_port_and_codec_known(cc_trans);
2032
2033 default:
2034 LOG_TRANS(cc_trans, LOGL_ERROR, "CN RTP address available, but in unexpected state %d\n",
2035 cc_trans->cc.state);
2036 return -EINVAL;
2037 }
2038}
2039
2040int cc_on_assignment_done(struct gsm_trans *trans)
2041{
2042 struct msc_a *msc_a = trans->msc_a;
2043
2044 switch (trans->cc.state) {
2045 case GSM_CSTATE_INITIATED:
2046 case GSM_CSTATE_MO_CALL_PROC:
2047 /* MO call */
2048 break;
2049
2050 case GSM_CSTATE_CALL_RECEIVED:
2051 case GSM_CSTATE_MO_TERM_CALL_CONF:
2052 /* MT call */
2053 break;
2054
2055 case GSM_CSTATE_ACTIVE:
2056 /* already active. MNCC finished before Abis completed the Assignment. */
2057 break;
2058
2059 default:
2060 LOG_TRANS(trans, LOGL_ERROR, "Assignment done in unexpected CC state: %d\n", trans->cc.state);
2061 return -EINVAL;
2062 }
2063
2064 if (!call_leg_local_ip(msc_a->cc.call_leg, RTP_TO_CN)) {
2065 LOG_TRANS(trans, LOGL_DEBUG,
2066 "Assignment complete, but still waiting for the CRCX OK on the CN side RTP\n");
2067 return 0;
2068 }
2069 return gsm48_tch_rtp_create(trans);
2070}
2071
Harald Welte27989d42018-06-21 20:39:20 +02002072/* Trigger TCH_RTP_CREATE acknowledgement */
2073int gsm48_tch_rtp_create(struct gsm_trans *trans)
2074{
2075 /* This function is called as soon as the port, on which the
2076 * mgcp-gw expects the incoming RTP stream from the remote
2077 * end (e.g. Asterisk) is known. */
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01002078 struct msc_a *msc_a = trans->msc_a;
2079 struct gsm_network *net = msc_a_net(msc_a);
2080 struct call_leg *cl = msc_a->cc.call_leg;
2081 struct osmo_sockaddr_str *rtp_cn_local;
Neels Hofmeyr5e19b9a2019-04-27 19:09:14 +02002082 struct rtp_stream *rtp_cn = cl ? cl->rtp[RTP_TO_CN] : NULL;
Neels Hofmeyr006b0ee2022-11-07 16:59:09 +01002083 int mncc_payload_msg_type;
2084 struct sdp_audio_codec *codec;
Neels Hofmeyra001a702022-10-31 17:57:30 +01002085 const struct codec_mapping *m;
Neels Hofmeyr006b0ee2022-11-07 16:59:09 +01002086 struct sdp_audio_codecs *codecs;
Harald Welte27989d42018-06-21 20:39:20 +02002087
Neels Hofmeyr5e19b9a2019-04-27 19:09:14 +02002088 if (!rtp_cn) {
2089 LOG_TRANS_CAT(trans, DMNCC, LOGL_ERROR, "Cannot RTP CREATE to MNCC, no RTP set up for the CN side\n");
2090 return -EINVAL;
2091 }
2092
Oliver Smithceca8e62023-05-24 11:15:52 +02002093 trans_cc_filter_run(trans);
Oliver Smithc63c3a02023-05-24 10:48:07 +02002094 codecs = &trans->cc.local.audio_codecs;
Neels Hofmeyr006b0ee2022-11-07 16:59:09 +01002095 if (!codecs->count) {
Neels Hofmeyr5e19b9a2019-04-27 19:09:14 +02002096 LOG_TRANS_CAT(trans, DMNCC, LOGL_ERROR,
Neels Hofmeyr006b0ee2022-11-07 16:59:09 +01002097 "Cannot RTP CREATE to MNCC, there is no codec available\n");
Neels Hofmeyr5e19b9a2019-04-27 19:09:14 +02002098 return -EINVAL;
2099 }
2100
Neels Hofmeyr006b0ee2022-11-07 16:59:09 +01002101 /* Populate the legacy MNCC codec elements: payload_type and payload_msg_type */
2102 codec = &codecs->codec[0];
2103 m = codec_mapping_by_subtype_name(codec->subtype_name);
2104 mncc_payload_msg_type = m ? m->mncc_payload_msg_type : 0;
Harald Welte27989d42018-06-21 20:39:20 +02002105
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01002106 rtp_cn_local = call_leg_local_ip(cl, RTP_TO_CN);
2107 if (!rtp_cn_local) {
Neels Hofmeyr006b0ee2022-11-07 16:59:09 +01002108 LOG_TRANS_CAT(trans, DMNCC, LOGL_ERROR, "Cannot RTP CREATE to MNCC, no local RTP IP:port to CN set up\n");
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01002109 return -EINVAL;
2110 }
2111
Neels Hofmeyr006b0ee2022-11-07 16:59:09 +01002112 return mncc_recv_rtp(net, trans, trans->callref, MNCC_RTP_CREATE, rtp_cn_local,
Oliver Smithc63c3a02023-05-24 10:48:07 +02002113 codec->payload_type, mncc_payload_msg_type, &trans->cc.local);
Harald Welte27989d42018-06-21 20:39:20 +02002114}
2115
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01002116static int tch_rtp_connect(struct gsm_network *net, const struct gsm_mncc_rtp *rtp)
Harald Welte27989d42018-06-21 20:39:20 +02002117{
2118 struct gsm_trans *trans;
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01002119 struct call_leg *cl;
2120 struct rtp_stream *rtps;
Philipp Maier8ad3dac2018-08-07 13:00:14 +02002121
Harald Welte27989d42018-06-21 20:39:20 +02002122 /* Find callref */
Andreas Eversberg7e4b0322023-04-23 11:43:13 +02002123 trans = trans_find_by_callref(net, TRANS_CC, rtp->callref);
Harald Welte27989d42018-06-21 20:39:20 +02002124 if (!trans) {
Neels Hofmeyrff7074a2019-02-28 05:50:06 +01002125 LOG_TRANS_CAT(trans, DMNCC, LOGL_ERROR, "RTP connect for non-existing trans\n");
Neels Hofmeyrc65cfe82019-04-08 03:48:56 +02002126 mncc_recv_rtp_err(net, trans, rtp->callref, MNCC_RTP_CONNECT);
Harald Welte27989d42018-06-21 20:39:20 +02002127 return -EIO;
2128 }
2129 log_set_context(LOG_CTX_VLR_SUBSCR, trans->vsub);
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01002130 if (!trans->msc_a) {
Neels Hofmeyrff7074a2019-02-28 05:50:06 +01002131 LOG_TRANS_CAT(trans, DMNCC, LOGL_ERROR, "RTP connect for trans without conn\n");
Neels Hofmeyrc65cfe82019-04-08 03:48:56 +02002132 mncc_recv_rtp_err(net, trans, rtp->callref, MNCC_RTP_CONNECT);
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01002133 return -EIO;
Harald Welte27989d42018-06-21 20:39:20 +02002134 }
2135
Neels Hofmeyr58f40882023-03-08 04:04:27 +01002136 log_mncc_rx_tx(trans, "rx", (const union mncc_msg *)rtp);
Neels Hofmeyrc65cfe82019-04-08 03:48:56 +02002137
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01002138 cl = trans->msc_a->cc.call_leg;
2139 rtps = cl ? cl->rtp[RTP_TO_CN] : NULL;
2140
2141 if (!rtps) {
2142 LOG_TRANS_CAT(trans, DMNCC, LOGL_ERROR, "RTP connect for trans without ongoing call\n");
2143 mncc_recv_rtp_err(net, trans, rtp->callref, MNCC_RTP_CONNECT);
2144 return -EINVAL;
2145 }
2146
Neels Hofmeyr8dd16462022-01-13 20:06:53 +01002147 rx_mncc_sdp(trans, rtp->msg_type, rtp->sdp);
Oliver Smith593cd882023-05-24 10:40:19 +02002148 rtp_stream_set_remote_addr_and_codecs(rtps, &trans->cc.remote);
Neels Hofmeyr8dd16462022-01-13 20:06:53 +01002149
2150 if (!osmo_sockaddr_str_is_nonzero(&rtps->remote)) {
2151 /* Didn't get an IP address from SDP. Try legacy MNCC IP address */
2152 struct osmo_sockaddr_str rtp_addr;
2153 if (osmo_sockaddr_str_from_sockaddr(&rtp_addr, &rtp->addr) < 0) {
2154 LOG_TRANS_CAT(trans, DMNCC, LOGL_ERROR, "RTP connect with invalid IP addr\n");
2155 mncc_recv_rtp_err(net, trans, rtp->callref, MNCC_RTP_CONNECT);
2156 return -EINVAL;
2157 }
2158 rtp_stream_set_remote_addr(rtps, &rtp_addr);
Pau Espin Pedroleeda9e12020-09-03 22:11:03 +02002159 }
Neels Hofmeyr8dd16462022-01-13 20:06:53 +01002160
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01002161 rtp_stream_commit(rtps);
2162 return 0;
Harald Welte27989d42018-06-21 20:39:20 +02002163}
2164
2165static struct downstate {
2166 uint32_t states;
2167 int type;
2168 int (*rout) (struct gsm_trans *trans, void *arg);
2169} downstatelist[] = {
2170 /* mobile originating call establishment */
2171 {SBIT(GSM_CSTATE_INITIATED), /* 5.2.1.2 */
2172 MNCC_CALL_PROC_REQ, gsm48_cc_tx_call_proc_and_assign},
2173 {SBIT(GSM_CSTATE_INITIATED) | SBIT(GSM_CSTATE_MO_CALL_PROC), /* 5.2.1.2 | 5.2.1.5 */
2174 MNCC_ALERT_REQ, gsm48_cc_tx_alerting},
2175 {SBIT(GSM_CSTATE_INITIATED) | SBIT(GSM_CSTATE_MO_CALL_PROC) | SBIT(GSM_CSTATE_CALL_DELIVERED), /* 5.2.1.2 | 5.2.1.6 | 5.2.1.6 */
2176 MNCC_SETUP_RSP, gsm48_cc_tx_connect},
2177 {SBIT(GSM_CSTATE_MO_CALL_PROC), /* 5.2.1.4.2 */
2178 MNCC_PROGRESS_REQ, gsm48_cc_tx_progress},
2179 /* mobile terminating call establishment */
2180 {SBIT(GSM_CSTATE_NULL), /* 5.2.2.1 */
2181 MNCC_SETUP_REQ, gsm48_cc_tx_setup},
2182 {SBIT(GSM_CSTATE_CONNECT_REQUEST),
2183 MNCC_SETUP_COMPL_REQ, gsm48_cc_tx_connect_ack},
2184 /* signalling during call */
2185 {SBIT(GSM_CSTATE_ACTIVE),
2186 MNCC_NOTIFY_REQ, gsm48_cc_tx_notify},
2187 {ALL_STATES - SBIT(GSM_CSTATE_NULL) - SBIT(GSM_CSTATE_RELEASE_REQ),
2188 MNCC_FACILITY_REQ, gsm48_cc_tx_facility},
2189 {ALL_STATES,
2190 MNCC_START_DTMF_RSP, gsm48_cc_tx_start_dtmf_ack},
2191 {ALL_STATES,
2192 MNCC_START_DTMF_REJ, gsm48_cc_tx_start_dtmf_rej},
2193 {ALL_STATES,
2194 MNCC_STOP_DTMF_RSP, gsm48_cc_tx_stop_dtmf_ack},
2195 {SBIT(GSM_CSTATE_ACTIVE),
2196 MNCC_HOLD_CNF, gsm48_cc_tx_hold_ack},
2197 {SBIT(GSM_CSTATE_ACTIVE),
2198 MNCC_HOLD_REJ, gsm48_cc_tx_hold_rej},
2199 {SBIT(GSM_CSTATE_ACTIVE),
2200 MNCC_RETRIEVE_CNF, gsm48_cc_tx_retrieve_ack},
2201 {SBIT(GSM_CSTATE_ACTIVE),
2202 MNCC_RETRIEVE_REJ, gsm48_cc_tx_retrieve_rej},
2203 {SBIT(GSM_CSTATE_ACTIVE),
2204 MNCC_MODIFY_REQ, gsm48_cc_tx_modify},
2205 {SBIT(GSM_CSTATE_MO_ORIG_MODIFY),
2206 MNCC_MODIFY_RSP, gsm48_cc_tx_modify_complete},
2207 {SBIT(GSM_CSTATE_MO_ORIG_MODIFY),
2208 MNCC_MODIFY_REJ, gsm48_cc_tx_modify_reject},
2209 {SBIT(GSM_CSTATE_ACTIVE),
2210 MNCC_USERINFO_REQ, gsm48_cc_tx_userinfo},
2211 /* clearing */
2212 {SBIT(GSM_CSTATE_INITIATED),
2213 MNCC_REJ_REQ, gsm48_cc_tx_release_compl},
2214 {ALL_STATES - SBIT(GSM_CSTATE_NULL) - SBIT(GSM_CSTATE_DISCONNECT_IND) - SBIT(GSM_CSTATE_RELEASE_REQ) - SBIT(GSM_CSTATE_DISCONNECT_REQ), /* 5.4.4 */
2215 MNCC_DISC_REQ, gsm48_cc_tx_disconnect},
2216 {ALL_STATES - SBIT(GSM_CSTATE_NULL) - SBIT(GSM_CSTATE_RELEASE_REQ), /* 5.4.3.2 */
2217 MNCC_REL_REQ, gsm48_cc_tx_release},
2218};
2219
2220#define DOWNSLLEN \
2221 (sizeof(downstatelist) / sizeof(struct downstate))
2222
2223
Philipp Maiercd64af72019-08-01 09:46:40 +02002224static int mncc_tx_to_gsm_cc(struct gsm_network *net, const union mncc_msg *msg)
Harald Welte27989d42018-06-21 20:39:20 +02002225{
2226 int i, rc = 0;
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01002227 struct msc_a *msc_a = NULL;
2228 struct gsm_trans *trans = NULL;
2229 const struct gsm_mncc *data;
Harald Welte27989d42018-06-21 20:39:20 +02002230
Harald Welte27989d42018-06-21 20:39:20 +02002231 /* handle special messages */
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01002232 switch(msg->msg_type) {
Harald Welte27989d42018-06-21 20:39:20 +02002233 case MNCC_BRIDGE:
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01002234 rc = tch_bridge(net, &msg->bridge);
Harald Welte27989d42018-06-21 20:39:20 +02002235 if (rc < 0)
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01002236 disconnect_bridge(net, &msg->bridge, -rc);
Harald Welte27989d42018-06-21 20:39:20 +02002237 return rc;
2238 case MNCC_RTP_CREATE:
Neels Hofmeyr58f40882023-03-08 04:04:27 +01002239 return tch_rtp_create(net, &msg->rtp);
Harald Welte27989d42018-06-21 20:39:20 +02002240 case MNCC_RTP_CONNECT:
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01002241 return tch_rtp_connect(net, &msg->rtp);
Harald Welte27989d42018-06-21 20:39:20 +02002242 case MNCC_RTP_FREE:
2243 /* unused right now */
2244 return -EIO;
2245
2246 case MNCC_FRAME_DROP:
2247 case MNCC_FRAME_RECV:
2248 case GSM_TCHF_FRAME:
2249 case GSM_TCHF_FRAME_EFR:
2250 case GSM_TCHH_FRAME:
2251 case GSM_TCH_FRAME_AMR:
Neels Hofmeyrff7074a2019-02-28 05:50:06 +01002252 LOG_TRANS_CAT(trans, DMNCC, LOGL_ERROR, "RTP streams must be handled externally; %s not supported.\n",
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01002253 get_mncc_name(msg->msg_type));
Harald Welte27989d42018-06-21 20:39:20 +02002254 return -ENOTSUP;
2255 }
2256
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01002257 data = &msg->signal;
Harald Welte27989d42018-06-21 20:39:20 +02002258
2259 /* Find callref */
Andreas Eversberg7e4b0322023-04-23 11:43:13 +02002260 trans = trans_find_by_callref(net, TRANS_CC, data->callref);
Harald Welte27989d42018-06-21 20:39:20 +02002261
2262 /* Callref unknown */
2263 if (!trans) {
2264 struct vlr_subscr *vsub;
2265
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01002266 if (msg->msg_type != MNCC_SETUP_REQ) {
Neels Hofmeyrff7074a2019-02-28 05:50:06 +01002267 LOG_TRANS_CAT(trans, DCC, LOGL_ERROR, "Unknown call reference for %s\n",
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01002268 get_mncc_name(msg->msg_type));
Harald Welte27989d42018-06-21 20:39:20 +02002269 /* Invalid call reference */
2270 return mncc_release_ind(net, NULL, data->callref,
2271 GSM48_CAUSE_LOC_PRN_S_LU,
2272 GSM48_CC_CAUSE_INVAL_TRANS_ID);
2273 }
2274 if (!data->called.number[0] && !data->imsi[0]) {
Neels Hofmeyrff7074a2019-02-28 05:50:06 +01002275 LOG_TRANS_CAT(trans, DCC, LOGL_ERROR, "Neither number nor IMSI in %s\n",
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01002276 get_mncc_name(msg->msg_type));
Harald Welte27989d42018-06-21 20:39:20 +02002277 /* Invalid number */
2278 return mncc_release_ind(net, NULL, data->callref,
2279 GSM48_CAUSE_LOC_PRN_S_LU,
2280 GSM48_CC_CAUSE_INV_NR_FORMAT);
2281 }
2282 /* New transaction due to setup, find subscriber */
Neels Hofmeyrff7074a2019-02-28 05:50:06 +01002283 if (data->called.number[0]) {
2284 vsub = vlr_subscr_find_by_msisdn(net->vlr, data->called.number, __func__);
2285 if (!vsub)
2286 LOG_TRANS_CAT(trans, DCC, LOGL_ERROR, "rx %s for unknown subscriber number '%s'\n",
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01002287 get_mncc_name(msg->msg_type), data->called.number);
Neels Hofmeyrff7074a2019-02-28 05:50:06 +01002288 } else {
Neels Hofmeyr7c5346c2019-02-19 02:36:35 +01002289 vsub = vlr_subscr_find_by_imsi(net->vlr, data->imsi, __func__);
Neels Hofmeyrff7074a2019-02-28 05:50:06 +01002290 if (!vsub)
2291 LOG_TRANS_CAT(trans, DCC, LOGL_ERROR, "rx %s for unknown subscriber IMSI '%s'\n",
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01002292 get_mncc_name(msg->msg_type), data->imsi);
Neels Hofmeyrff7074a2019-02-28 05:50:06 +01002293 }
2294 if (!vsub)
2295 return mncc_release_ind(net, NULL, data->callref, GSM48_CAUSE_LOC_PRN_S_LU,
Neels Hofmeyr43a349f2019-08-22 22:30:20 +02002296 GSM48_CC_CAUSE_USER_NOTRESPOND);
Harald Welte27989d42018-06-21 20:39:20 +02002297 /* update the subscriber we deal with */
2298 log_set_context(LOG_CTX_VLR_SUBSCR, vsub);
2299
Harald Welte27989d42018-06-21 20:39:20 +02002300 /* If subscriber is not "attached" */
Neels Hofmeyrff7074a2019-02-28 05:50:06 +01002301 if (!vsub->lu_complete) {
2302 LOG_TRANS_CAT(trans, DCC, LOGL_ERROR, "rx %s for subscriber that is not attached: %s\n",
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01002303 get_mncc_name(msg->msg_type), vlr_subscr_name(vsub));
Neels Hofmeyr7c5346c2019-02-19 02:36:35 +01002304 vlr_subscr_put(vsub, __func__);
Harald Welte27989d42018-06-21 20:39:20 +02002305 /* Temporarily out of order */
2306 return mncc_release_ind(net, NULL, data->callref,
2307 GSM48_CAUSE_LOC_PRN_S_LU,
2308 GSM48_CC_CAUSE_DEST_OOO);
2309 }
Keith Whyte991bb422019-08-08 15:43:40 +02002310
2311 /* Find valid conn */
2312 msc_a = msc_a_for_vsub(vsub, true);
2313
2314 /* If subscriber is BUSY and we do not DO call in call aka "call-waiting" */
2315 if (!net->call_waiting && msc_a) {
2316 struct gsm_trans *existing_cc_trans = trans_find_by_type(msc_a, TRANS_CC);
2317 if (existing_cc_trans && existing_cc_trans->cc.state != GSM_CSTATE_NULL) {
2318 LOG_TRANS_CAT(existing_cc_trans, DCC, LOGL_NOTICE,
2319 "rx '%s' for subscriber %s with trans state (%s)"
2320 " rejecting with USER_BUSY\n",
2321 get_mncc_name(msg->msg_type), data->called.number,
2322 gsm48_cc_state_name(existing_cc_trans->cc.state));
2323 return mncc_release_ind(net, NULL, data->callref,
2324 GSM48_CAUSE_LOC_PRN_S_LU,
2325 GSM48_CC_CAUSE_USER_BUSY);
2326 }
2327 }
2328
Harald Welte27989d42018-06-21 20:39:20 +02002329 /* Create transaction */
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01002330 trans = trans_alloc(net, vsub, TRANS_CC,
Maxd8daaae2019-02-14 16:54:10 +07002331 TRANS_ID_UNASSIGNED, data->callref);
Harald Welte27989d42018-06-21 20:39:20 +02002332 if (!trans) {
Neels Hofmeyrff7074a2019-02-28 05:50:06 +01002333 LOG_TRANS(trans, LOGL_ERROR, "No memory for trans.\n");
Neels Hofmeyr7c5346c2019-02-19 02:36:35 +01002334 vlr_subscr_put(vsub, __func__);
Martin Hauke3f07dac2019-11-14 17:49:08 +01002335 /* Resource unavailable */
Harald Welte27989d42018-06-21 20:39:20 +02002336 mncc_release_ind(net, NULL, data->callref,
2337 GSM48_CAUSE_LOC_PRN_S_LU,
2338 GSM48_CC_CAUSE_RESOURCE_UNAVAIL);
2339 return -ENOMEM;
2340 }
2341
Neels Hofmeyr8dd16462022-01-13 20:06:53 +01002342 /* Remember remote SDP, if any */
2343 rx_mncc_sdp(trans, data->msg_type, data->sdp);
2344
Harald Welte27989d42018-06-21 20:39:20 +02002345 /* If subscriber has no conn */
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01002346 if (!msc_a) {
Neels Hofmeyrc67b4832019-10-21 02:34:54 +02002347 /* This condition will return before the common logging of the received MNCC message below, so
2348 * log it now. */
Neels Hofmeyr58f40882023-03-08 04:04:27 +01002349 log_mncc_rx_tx(trans, "rx", msg);
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01002350
Harald Welte27989d42018-06-21 20:39:20 +02002351 /* store setup information until paging succeeds */
2352 memcpy(&trans->cc.msg, data, sizeof(struct gsm_mncc));
2353
Neels Hofmeyrbde605d2019-10-21 03:07:25 +02002354 /* Request a channel. If Paging already started, paging_request_start() will append the new
2355 * trans to the already ongoing Paging. */
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01002356 trans->paging_request = paging_request_start(vsub, PAGING_CAUSE_CALL_CONVERSATIONAL,
2357 cc_paging_cb, trans, "MNCC: establish call");
Harald Welte27989d42018-06-21 20:39:20 +02002358 if (!trans->paging_request) {
Neels Hofmeyrff7074a2019-02-28 05:50:06 +01002359 LOG_TRANS(trans, LOGL_ERROR, "Failed to allocate paging token.\n");
Harald Welte27989d42018-06-21 20:39:20 +02002360 trans_free(trans);
Harald Welte27989d42018-06-21 20:39:20 +02002361 }
Neels Hofmeyr7c5346c2019-02-19 02:36:35 +01002362 vlr_subscr_put(vsub, __func__);
Harald Welte27989d42018-06-21 20:39:20 +02002363 return 0;
2364 }
2365
2366 /* Assign conn */
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01002367 trans->msc_a = msc_a;
2368 msc_a_get(msc_a, MSC_A_USE_CC);
Harald Welte27989d42018-06-21 20:39:20 +02002369 trans->dlci = 0x00; /* SAPI=0, not SACCH */
Neels Hofmeyr7c5346c2019-02-19 02:36:35 +01002370 vlr_subscr_put(vsub, __func__);
Harald Welte27989d42018-06-21 20:39:20 +02002371 } else {
2372 /* update the subscriber we deal with */
2373 log_set_context(LOG_CTX_VLR_SUBSCR, trans->vsub);
2374 }
2375
Neels Hofmeyr58f40882023-03-08 04:04:27 +01002376 log_mncc_rx_tx(trans, "rx", msg);
Neels Hofmeyrff7074a2019-02-28 05:50:06 +01002377
Philipp Maier9ca7b312018-10-10 17:00:49 +02002378 gsm48_start_guard_timer(trans);
Neels Hofmeyrcf90bdb2019-10-01 19:47:26 +02002379 trans->cc.mncc_initiated = true;
Philipp Maier9ca7b312018-10-10 17:00:49 +02002380
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01002381 if (trans->msc_a)
2382 msc_a = trans->msc_a;
Harald Welte27989d42018-06-21 20:39:20 +02002383
2384 /* if paging did not respond yet */
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01002385 if (!msc_a) {
2386 struct gsm_mncc rel = {
2387 .callref = data->callref,
2388 };
Neels Hofmeyr58f40882023-03-08 04:04:27 +01002389 LOG_TRANS(trans, LOGL_DEBUG, "still paging\n");
Harald Welte27989d42018-06-21 20:39:20 +02002390 mncc_set_cause(&rel, GSM48_CAUSE_LOC_PRN_S_LU,
2391 GSM48_CC_CAUSE_NORM_CALL_CLEAR);
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01002392 if (msg->msg_type == MNCC_REL_REQ)
Harald Welte27989d42018-06-21 20:39:20 +02002393 rc = mncc_recvmsg(net, trans, MNCC_REL_CNF, &rel);
2394 else
2395 rc = mncc_recvmsg(net, trans, MNCC_REL_IND, &rel);
2396 trans->callref = 0;
2397 trans_free(trans);
2398 return rc;
Harald Welte27989d42018-06-21 20:39:20 +02002399 }
2400
2401 /* Find function for current state and message */
2402 for (i = 0; i < DOWNSLLEN; i++)
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01002403 if ((msg->msg_type == downstatelist[i].type)
Harald Welte27989d42018-06-21 20:39:20 +02002404 && ((1 << trans->cc.state) & downstatelist[i].states))
2405 break;
2406 if (i == DOWNSLLEN) {
Neels Hofmeyrff7074a2019-02-28 05:50:06 +01002407 LOG_TRANS(trans, LOGL_DEBUG, "Message '%s' unhandled at state '%s'\n",
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01002408 get_mncc_name(msg->msg_type), gsm48_cc_state_name(trans->cc.state));
Harald Welte27989d42018-06-21 20:39:20 +02002409 return 0;
2410 }
2411
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01002412 rc = downstatelist[i].rout(trans, (void*)msg);
Harald Welte27989d42018-06-21 20:39:20 +02002413
2414 return rc;
2415}
2416
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01002417struct mncc_call *mncc_find_by_callref_from_msg(const union mncc_msg *msg)
2418{
2419 uint32_t callref;
2420
2421 switch (msg->msg_type) {
2422 case MNCC_BRIDGE:
2423 callref = msg->bridge.callref[0];
2424 break;
2425 case MNCC_RTP_CREATE:
2426 case MNCC_RTP_CONNECT:
2427 callref = msg->rtp.callref;
2428 break;
2429
2430 case MNCC_RTP_FREE:
2431 case MNCC_FRAME_DROP:
2432 case MNCC_FRAME_RECV:
2433 case GSM_TCHF_FRAME:
2434 case GSM_TCHF_FRAME_EFR:
2435 case GSM_TCHH_FRAME:
2436 case GSM_TCH_FRAME_AMR:
2437 return NULL;
2438
2439 default:
2440 callref = msg->signal.callref;
2441 break;
2442 }
2443
2444 return mncc_call_find_by_callref(callref);
2445}
2446
2447/* Demux incoming genuine calls to GSM CC from MNCC forwarding for inter-MSC handover */
Neels Hofmeyr52558742019-05-09 01:23:09 +02002448int mncc_tx_to_cc(struct gsm_network *net, void *arg)
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01002449{
2450 const union mncc_msg *msg = arg;
2451 struct mncc_call *mncc_call = NULL;
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01002452
2453 if (msg->msg_type == MNCC_SETUP_REQ) {
2454 /* Incoming call to forward for inter-MSC Handover? */
2455 mncc_call = msc_t_check_call_to_handover_number(&msg->signal);
2456 if (mncc_call)
2457 LOG_MNCC_CALL(mncc_call, LOGL_DEBUG,
2458 "Incoming call matches pending inter-MSC Handover Number\n");
2459 }
2460 if (!mncc_call) {
2461 /* Find already active MNCC FSM for this callref.
2462 * Currently only for inter-MSC call forwarding, but mncc_fsm could at some point also be used for direct
2463 * MNCC<->GSM-CC call handling. */
2464 mncc_call = mncc_find_by_callref_from_msg(msg);
2465 }
2466 if (mncc_call) {
2467 mncc_call_rx(mncc_call, msg);
2468 return 0;
2469 }
2470
2471 /* None of the above? Then it must be a normal GSM CC call related message. */
2472 return mncc_tx_to_gsm_cc(net, msg);
2473}
Harald Welte27989d42018-06-21 20:39:20 +02002474
2475static struct datastate {
2476 uint32_t states;
2477 int type;
2478 int (*rout) (struct gsm_trans *trans, struct msgb *msg);
2479} datastatelist[] = {
2480 /* mobile originating call establishment */
2481 {SBIT(GSM_CSTATE_NULL), /* 5.2.1.2 */
2482 GSM48_MT_CC_SETUP, gsm48_cc_rx_setup},
2483 {SBIT(GSM_CSTATE_NULL), /* 5.2.1.2 */
2484 GSM48_MT_CC_EMERG_SETUP, gsm48_cc_rx_setup},
2485 {SBIT(GSM_CSTATE_CONNECT_IND), /* 5.2.1.2 */
2486 GSM48_MT_CC_CONNECT_ACK, gsm48_cc_rx_connect_ack},
2487 /* mobile terminating call establishment */
2488 {SBIT(GSM_CSTATE_CALL_PRESENT), /* 5.2.2.3.2 */
2489 GSM48_MT_CC_CALL_CONF, gsm48_cc_rx_call_conf},
2490 {SBIT(GSM_CSTATE_CALL_PRESENT) | SBIT(GSM_CSTATE_MO_TERM_CALL_CONF), /* ???? | 5.2.2.3.2 */
2491 GSM48_MT_CC_ALERTING, gsm48_cc_rx_alerting},
2492 {SBIT(GSM_CSTATE_CALL_PRESENT) | SBIT(GSM_CSTATE_MO_TERM_CALL_CONF) | SBIT(GSM_CSTATE_CALL_RECEIVED), /* (5.2.2.6) | 5.2.2.6 | 5.2.2.6 */
2493 GSM48_MT_CC_CONNECT, gsm48_cc_rx_connect},
2494 /* signalling during call */
2495 {ALL_STATES - SBIT(GSM_CSTATE_NULL),
2496 GSM48_MT_CC_FACILITY, gsm48_cc_rx_facility},
2497 {SBIT(GSM_CSTATE_ACTIVE),
2498 GSM48_MT_CC_NOTIFY, gsm48_cc_rx_notify},
2499 {ALL_STATES,
2500 GSM48_MT_CC_START_DTMF, gsm48_cc_rx_start_dtmf},
2501 {ALL_STATES,
2502 GSM48_MT_CC_STOP_DTMF, gsm48_cc_rx_stop_dtmf},
2503 {ALL_STATES,
2504 GSM48_MT_CC_STATUS_ENQ, gsm48_cc_rx_status_enq},
2505 {SBIT(GSM_CSTATE_ACTIVE),
2506 GSM48_MT_CC_HOLD, gsm48_cc_rx_hold},
2507 {SBIT(GSM_CSTATE_ACTIVE),
2508 GSM48_MT_CC_RETR, gsm48_cc_rx_retrieve},
2509 {SBIT(GSM_CSTATE_ACTIVE),
2510 GSM48_MT_CC_MODIFY, gsm48_cc_rx_modify},
2511 {SBIT(GSM_CSTATE_MO_TERM_MODIFY),
2512 GSM48_MT_CC_MODIFY_COMPL, gsm48_cc_rx_modify_complete},
2513 {SBIT(GSM_CSTATE_MO_TERM_MODIFY),
2514 GSM48_MT_CC_MODIFY_REJECT, gsm48_cc_rx_modify_reject},
2515 {SBIT(GSM_CSTATE_ACTIVE),
2516 GSM48_MT_CC_USER_INFO, gsm48_cc_rx_userinfo},
2517 /* clearing */
2518 {ALL_STATES - SBIT(GSM_CSTATE_NULL) - SBIT(GSM_CSTATE_RELEASE_REQ), /* 5.4.3.2 */
2519 GSM48_MT_CC_DISCONNECT, gsm48_cc_rx_disconnect},
2520 {ALL_STATES - SBIT(GSM_CSTATE_NULL), /* 5.4.4.1.2.2 */
2521 GSM48_MT_CC_RELEASE, gsm48_cc_rx_release},
2522 {ALL_STATES, /* 5.4.3.4 */
2523 GSM48_MT_CC_RELEASE_COMPL, gsm48_cc_rx_release_compl},
2524};
2525
2526#define DATASLLEN \
2527 (sizeof(datastatelist) / sizeof(struct datastate))
2528
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01002529int gsm0408_rcv_cc(struct msc_a *msc_a, struct msgb *msg)
Harald Welte27989d42018-06-21 20:39:20 +02002530{
2531 struct gsm48_hdr *gh = msgb_l3(msg);
2532 uint8_t msg_type = gsm48_hdr_msg_type(gh);
2533 uint8_t transaction_id = gsm48_hdr_trans_id_flip_ti(gh);
2534 struct gsm_trans *trans = NULL;
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01002535 struct vlr_subscr *vsub = msc_a_vsub(msc_a);
2536 struct gsm_network *net = msc_a_net(msc_a);
Harald Welte27989d42018-06-21 20:39:20 +02002537 int i, rc = 0;
2538
2539 if (msg_type & 0x80) {
Neels Hofmeyrff7074a2019-02-28 05:50:06 +01002540 LOG_TRANS(trans, LOGL_DEBUG, "MSG 0x%2x not defined for PD error\n", msg_type);
Harald Welte27989d42018-06-21 20:39:20 +02002541 return -EINVAL;
2542 }
2543
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01002544 if (!vsub) {
Neels Hofmeyrff7074a2019-02-28 05:50:06 +01002545 LOG_TRANS(trans, LOGL_ERROR, "Invalid conn: no subscriber\n");
Harald Welte27989d42018-06-21 20:39:20 +02002546 return -EINVAL;
2547 }
2548
2549 /* Find transaction */
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01002550 trans = trans_find_by_id(msc_a, TRANS_CC, transaction_id);
Harald Welte27989d42018-06-21 20:39:20 +02002551
Harald Welte27989d42018-06-21 20:39:20 +02002552 /* Create transaction */
2553 if (!trans) {
Harald Welte27989d42018-06-21 20:39:20 +02002554 /* Create transaction */
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01002555 trans = trans_alloc(net, vsub,
2556 TRANS_CC,
2557 transaction_id, msc_cc_next_outgoing_callref());
Harald Welte27989d42018-06-21 20:39:20 +02002558 if (!trans) {
Neels Hofmeyrff7074a2019-02-28 05:50:06 +01002559 LOG_TRANS(trans, LOGL_ERROR, "No memory for trans.\n");
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01002560 rc = gsm48_tx_simple(msc_a,
Harald Welte27989d42018-06-21 20:39:20 +02002561 GSM48_PDISC_CC | (transaction_id << 4),
2562 GSM48_MT_CC_RELEASE_COMPL);
2563 return -ENOMEM;
2564 }
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01002565 if (osmo_fsm_inst_dispatch(msc_a->c.fi, MSC_A_EV_TRANSACTION_ACCEPTED, trans)) {
2566 LOG_MSC_A(msc_a, LOGL_ERROR, "Not allowed to accept CC transaction\n");
2567 trans_free(trans);
2568 return -EINVAL;
2569 }
2570
Harald Welte27989d42018-06-21 20:39:20 +02002571 /* Assign transaction */
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01002572 msc_a_get(msc_a, MSC_A_USE_CC);
2573 trans->msc_a = msc_a;
Harald Welte27989d42018-06-21 20:39:20 +02002574 trans->dlci = OMSC_LINKID_CB(msg); /* DLCI as received from BSC */
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01002575
2576 /* An earlier CM Service Request for this CC message now has concluded */
2577 if (!osmo_use_count_by(&msc_a->use_count, MSC_A_USE_CM_SERVICE_CC))
2578 LOG_MSC_A(msc_a, LOGL_ERROR,
2579 "Creating new CC transaction without prior CM Service Request\n");
2580 else
2581 msc_a_put(msc_a, MSC_A_USE_CM_SERVICE_CC);
Harald Welte27989d42018-06-21 20:39:20 +02002582 }
2583
Neels Hofmeyrff7074a2019-02-28 05:50:06 +01002584 LOG_TRANS(trans, LOGL_DEBUG, "rx %s in state %s\n", gsm48_cc_msg_name(msg_type),
2585 gsm48_cc_state_name(trans->cc.state));
2586
Harald Welte27989d42018-06-21 20:39:20 +02002587 /* find function for current state and message */
2588 for (i = 0; i < DATASLLEN; i++)
2589 if ((msg_type == datastatelist[i].type)
2590 && ((1 << trans->cc.state) & datastatelist[i].states))
2591 break;
2592 if (i == DATASLLEN) {
Neels Hofmeyrff7074a2019-02-28 05:50:06 +01002593 LOG_TRANS(trans, LOGL_ERROR, "Message unhandled at this state.\n");
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01002594
2595 /* If a transaction was just now created, it was a bogus transaction ID, and we need to clean up the
2596 * transaction right away. */
2597 if (trans->cc.state == GSM_CSTATE_NULL) {
2598 LOG_TRANS(trans, LOGL_ERROR, "Unknown transaction ID for non-SETUP message is not allowed"
2599 " -- disarding new CC transaction right away\n");
2600 trans_free(trans);
2601 }
Harald Welte27989d42018-06-21 20:39:20 +02002602 return 0;
2603 }
2604
2605 assert(trans->vsub);
2606
2607 rc = datastatelist[i].rout(trans, msg);
2608
Harald Welte27989d42018-06-21 20:39:20 +02002609 return rc;
2610}