blob: 2f25ca83611d5b1c926c48da89e8e246832f7e67 [file] [log] [blame]
Neels Hofmeyrc4628a32018-12-07 14:47:34 +01001/* MSC Handover implementation */
2/*
3 * (C) 2019 by sysmocom - s.m.f.c. GmbH <info@sysmocom.de>
4 * All Rights Reserved
5 *
6 * Author: Neels Hofmeyr
7 *
8 * SPDX-License-Identifier: GPL-2.0+
9 *
10 * This program is free software; you can redistribute it and/or modify
11 * it under the terms of the GNU General Public License as published by
12 * the Free Software Foundation; either version 2 of the License, or
13 * (at your option) any later version.
14 *
15 * This program is distributed in the hope that it will be useful,
16 * but WITHOUT ANY WARRANTY; without even the implied warranty of
17 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
18 * GNU General Public License for more details.
Neels Hofmeyrc4628a32018-12-07 14:47:34 +010019 */
20
21#include <osmocom/core/fsm.h>
22#include <osmocom/gsm/protocol/gsm_08_08.h>
23#include <osmocom/sigtran/sccp_helpers.h>
24
25#include <osmocom/msc/msc_ho.h>
26#include <osmocom/msc/ran_msg.h>
27#include <osmocom/msc/msc_a.h>
28#include <osmocom/msc/msc_i.h>
29#include <osmocom/msc/msc_t.h>
30#include <osmocom/msc/e_link.h>
31#include <osmocom/msc/msc_i_remote.h>
32#include <osmocom/msc/msc_t_remote.h>
33#include <osmocom/msc/neighbor_ident.h>
34#include <osmocom/msc/gsm_data.h>
35#include <osmocom/msc/ran_peer.h>
36#include <osmocom/msc/vlr.h>
37#include <osmocom/msc/transaction.h>
38#include <osmocom/msc/gsm_04_08.h>
39#include <osmocom/msc/call_leg.h>
40#include <osmocom/msc/rtp_stream.h>
41#include <osmocom/msc/mncc_call.h>
Neels Hofmeyr62bfa372022-10-31 18:51:07 +010042#include <osmocom/msc/codec_mapping.h>
Neels Hofmeyrc4628a32018-12-07 14:47:34 +010043
44struct osmo_fsm msc_ho_fsm;
45
46#define MSC_A_USE_HANDOVER "Handover"
47
48static const struct osmo_tdef_state_timeout msc_ho_fsm_timeouts[32] = {
49 [MSC_HO_ST_REQUIRED] = { .keep_timer = true, .T = -3 },
50 [MSC_HO_ST_WAIT_REQUEST_ACK] = { .keep_timer = true },
51 [MSC_HO_ST_WAIT_COMPLETE] = { .T = -3 },
52};
53
54/* Transition to a state, using the T timer defined in msc_a_fsm_timeouts.
55 * The actual timeout value is in turn obtained from network->T_defs.
56 * Assumes local variable fi exists. */
57#define msc_ho_fsm_state_chg(msc_a, state) \
58 osmo_tdef_fsm_inst_state_chg((msc_a)->ho.fi, state, msc_ho_fsm_timeouts, (msc_a)->c.ran->tdefs, 5)
59
60static __attribute__((constructor)) void msc_ho_fsm_init()
61{
Harald Welte34a8cc32019-12-01 15:32:09 +010062 OSMO_ASSERT(osmo_fsm_register(&msc_ho_fsm) == 0);
Neels Hofmeyrc4628a32018-12-07 14:47:34 +010063}
64
65void msc_ho_down_required_reject(struct msc_a *msc_a, enum gsm0808_cause cause)
66{
Vadim Yanitskiydb4839c2019-12-01 18:52:58 +070067 struct msc_i *msc_i;
Neels Hofmeyrc4628a32018-12-07 14:47:34 +010068 uint32_t event;
69
Vadim Yanitskiydb4839c2019-12-01 18:52:58 +070070 msc_i = msc_a_msc_i(msc_a);
71 OSMO_ASSERT(msc_i);
72
Neels Hofmeyrc4628a32018-12-07 14:47:34 +010073 struct ran_msg ran_enc_msg = {
74 .msg_type = RAN_MSG_HANDOVER_REQUIRED_REJECT,
75 .handover_required_reject = {
76 .cause = cause,
77 },
78 };
79
80 if (msc_i->c.remote_to)
81 event = MSC_I_EV_FROM_A_PREPARE_SUBSEQUENT_HANDOVER_ERROR;
82 else
83 event = MSC_I_EV_FROM_A_FORWARD_ACCESS_SIGNALLING_REQUEST;
84
85 msc_a_msg_down(msc_a, MSC_ROLE_I, event, &ran_enc_msg);
86}
87
88/* Even though this is using the 3GPP TS 48.008 definitions and naming, the intention is to be RAN implementation agnostic.
89 * For other RAN types, the 48.008 items shall be translated to their respective counterparts. */
90void msc_ho_start(struct msc_a *msc_a, const struct ran_handover_required *ho_req)
91{
92 if (msc_a->ho.fi) {
93 LOG_HO(msc_a, LOGL_ERROR, "Rx Handover Required, but Handover is still ongoing\n");
94 msc_ho_down_required_reject(msc_a, GSM0808_CAUSE_PROTOCOL_ERROR_BETWEEN_BSS_AND_MSC);
95 return;
96 }
97
98 if (!ho_req->cil.id_list_len) {
99 LOG_HO(msc_a, LOGL_ERROR, "Rx Handover Required without a Cell Identifier List\n");
100 msc_ho_down_required_reject(msc_a, GSM0808_CAUSE_INFORMATION_ELEMENT_OR_FIELD_MISSING);
101 return;
102 }
103
104 if (msc_a_msc_t(msc_a)) {
105 LOG_HO(msc_a, LOGL_ERROR,
106 "Rx Handover Required, but this subscriber still has an active MSC-T role: %s\n",
107 msc_a_msc_t(msc_a)->c.fi->id);
108 /* Protocol error because the BSS is not supposed to send another Handover Required before the previous
109 * attempt has concluded. */
110 msc_ho_down_required_reject(msc_a, GSM0808_CAUSE_PROTOCOL_ERROR_BETWEEN_BSS_AND_MSC);
111 return;
112 }
113
114 /* Paranoia: make sure we start with clean state */
115 msc_a->ho = (struct msc_ho_state){};
116
117 msc_a->ho.fi = osmo_fsm_inst_alloc_child(&msc_ho_fsm, msc_a->c.fi, MSC_A_EV_HANDOVER_END);
118 OSMO_ASSERT(msc_a->ho.fi);
119
120 msc_a->ho.fi->priv = msc_a;
121 msc_a->ho.info = *ho_req;
122 msc_a->ho.next_cil_idx = 0;
123
124 /* Start the timeout */
125 msc_ho_fsm_state_chg(msc_a, MSC_HO_ST_REQUIRED);
126}
127
128static void msc_ho_rtp_rollback_to_old_cell(struct msc_a *msc_a);
129
130static void msc_ho_end(struct msc_a *msc_a, bool success, enum gsm0808_cause cause)
131{
132 struct msc_i *msc_i;
133 struct msc_t *msc_t = msc_a_msc_t(msc_a);
134
135 if (!success) {
136 msc_ho_rtp_rollback_to_old_cell(msc_a);
137 msc_ho_down_required_reject(msc_a, cause);
138 }
139
140 if (success) {
141 /* Any previous call forwarding to a remote MSC becomes obsolete. */
142 if (msc_a->cc.mncc_forwarding_to_remote_ran) {
143 mncc_call_release(msc_a->cc.mncc_forwarding_to_remote_ran);
144 msc_a->cc.mncc_forwarding_to_remote_ran = NULL;
145 }
146
147 /* Replace MSC-I with new MSC-T */
148 if (msc_t->c.remote_to) {
149 /* Inter-MSC Handover. */
150
151 /* The MNCC forwarding set up for inter-MSC handover, so far transitional in msc_a->ho now
152 * becomes the "officially" active MNCC forwarding for this call. */
153 msc_a->cc.mncc_forwarding_to_remote_ran = msc_a->ho.new_cell.mncc_forwarding_to_remote_ran;
154 msc_a->ho.new_cell.mncc_forwarding_to_remote_ran = NULL;
155 mncc_call_reparent(msc_a->cc.mncc_forwarding_to_remote_ran,
156 msc_a->c.fi, -1, MSC_MNCC_EV_CALL_ENDED, NULL, NULL);
157
158 /* inter-MSC link. msc_i_remote_alloc() properly "steals" the e_link from msc_t. */
159 msc_i = msc_i_remote_alloc(msc_a->c.msub, msc_t->c.ran, msc_t->c.remote_to);
160 OSMO_ASSERT(msc_t->c.remote_to == NULL);
161 } else {
162 /* local BSS */
163 msc_i = msc_i_alloc(msc_a->c.msub, msc_t->c.ran);
164 /* msc_i_set_ran_conn() properly "steals" the ran_conn from msc_t */
165 msc_i_set_ran_conn(msc_i, msc_t->ran_conn);
166 }
167 }
168
169 osmo_fsm_inst_term(msc_a->ho.fi, OSMO_FSM_TERM_REGULAR, NULL);
170}
171
172#define msc_ho_failed(msc_a, cause, fmt, args...) do { \
173 LOG_HO(msc_a, LOGL_ERROR, fmt, ##args); \
174 msc_ho_end(msc_a, false, cause); \
175 } while(0)
176#define msc_ho_try_next_cell(msc_a, fmt, args...) do {\
177 LOG_HO(msc_a, LOGL_ERROR, fmt, ##args); \
178 msc_ho_fsm_state_chg(msc_a, MSC_HO_ST_REQUIRED); \
179 } while(0)
180#define msc_ho_success(msc_a) msc_ho_end(msc_a, true, 0)
181
182enum msc_neighbor_type msc_ho_find_target_cell(struct msc_a *msc_a, const struct gsm0808_cell_id *cid,
183 const struct neighbor_ident_entry **remote_msc,
184 struct ran_peer **ran_peer_from_neighbor_ident,
185 struct ran_peer **ran_peer_from_seen_cells)
186{
187 struct gsm_network *net = msc_a_net(msc_a);
188 const struct neighbor_ident_entry *e;
189 struct sccp_ran_inst *sri;
190 struct ran_peer *rp_from_neighbor_ident = NULL;
191 struct ran_peer *rp_from_cell_id = NULL;
192 struct ran_peer *rp;
193 int i;
194
195 OSMO_ASSERT(remote_msc);
196 OSMO_ASSERT(ran_peer_from_neighbor_ident);
197 OSMO_ASSERT(ran_peer_from_seen_cells);
198
199 e = neighbor_ident_find_by_cell(&net->neighbor_ident_list, msc_a->c.ran->type, cid);
200
201 if (e && e->addr.type == MSC_NEIGHBOR_TYPE_REMOTE_MSC) {
202 *remote_msc = e;
203 return MSC_NEIGHBOR_TYPE_REMOTE_MSC;
204 }
205
206 /* It is not a remote MSC target. Figure out local RAN peers. */
207
208 if (e && e->addr.type == MSC_NEIGHBOR_TYPE_LOCAL_RAN_PEER) {
209 /* Find local RAN peer in neighbor config. If anything is wrong with that, just keep
210 * rp_from_neighbor_ident == NULL. */
211
212 struct sccp_ran_inst *sri_from_neighbor_ident = NULL;
213 struct osmo_ss7_instance *ss7 = NULL;
214
215 /* Get the sccp_ran_inst with sanity checkin. If anything is fishy, just keep
216 * sri_from_neighbor_ident == NULL and below code will notice the error. */
217 if (e->addr.ran_type < msc_ran_infra_len) {
218 sri_from_neighbor_ident = msc_ran_infra[e->addr.ran_type].sri;
219 ss7 = osmo_sccp_get_ss7(sri_from_neighbor_ident->sccp);
220 if (!ss7)
221 sri_from_neighbor_ident = NULL;
222 }
223
224 if (!sri_from_neighbor_ident) {
225 LOG_HO(msc_a, LOGL_ERROR, "Cannot handover to RAN type %s\n", osmo_rat_type_name(e->addr.ran_type));
226 } else {
227 /* Interpret the point-code string placed in the neighbors config. */
228 int pc = osmo_ss7_pointcode_parse(ss7, e->addr.local_ran_peer_pc_str);
229
230 if (pc < 0) {
231 LOG_HO(msc_a, LOGL_ERROR, "Invalid point code string: %s\n",
232 osmo_quote_str(e->addr.local_ran_peer_pc_str, -1));
233 } else {
234 struct osmo_sccp_addr addr = {};
235 osmo_sccp_make_addr_pc_ssn(&addr, pc, sri_from_neighbor_ident->ran->ssn);
236 rp_from_neighbor_ident = ran_peer_find_by_addr(sri_from_neighbor_ident, &addr);
237 }
238 }
239
240 if (!rp_from_neighbor_ident) {
241 LOG_HO(msc_a, LOGL_ERROR, "Target RAN peer from neighbor config is not connected:"
242 " Cell ID %s resolves to target address %s\n",
243 gsm0808_cell_id_name(cid), e->addr.local_ran_peer_pc_str);
244 } else if (rp_from_neighbor_ident->fi->state != RAN_PEER_ST_READY) {
245 LOG_HO(msc_a, LOGL_ERROR, "Target RAN peer in invalid state: %s (%s)\n",
246 osmo_fsm_inst_state_name(rp_from_neighbor_ident->fi),
247 rp_from_neighbor_ident->fi->id);
248 rp_from_neighbor_ident = NULL;
249 }
250 }
251
252 /* Figure out actually connected RAN peers for this cell ID.
253 * If no cell has been found yet at all, this might determine a Handover target,
254 * otherwise this is for sanity checking. If none is found, just keep rp_from_cell_id == NULL. */
255
256 /* Iterate all connected RAN peers. Possibly, more than one RAN peer has advertised a match for this Cell ID.
257 * For example, if the handover target is identified as LAC=23 but there are multiple cells with distinct CIs
258 * serving in LAC=23, we have an ambiguity. It's up to the user to configure correctly, help with logging. */
259 for (i = 0; i < msc_ran_infra_len; i++) {
260 sri = msc_ran_infra[i].sri;
261 if (!sri)
262 continue;
263
264 rp = ran_peer_find_by_cell_id(sri, cid, true);
265 if (rp && rp->fi && rp->fi->state == RAN_PEER_ST_READY) {
266 if (rp_from_cell_id) {
267 LOG_HO(msc_a, LOGL_ERROR,
268 "Ambiguous match for cell ID %s: more than one RAN type is serving this cell"
269 " ID: %s and %s\n",
270 gsm0808_cell_id_name(cid),
271 rp_from_cell_id->fi->id,
272 rp->fi->id);
273 /* But logging is all we're going to do about it. */
274 }
275
276 /* Use the first found RAN peer, but if multiple matches are found, favor the one that matches
277 * the current RAN type. */
278 if (!rp_from_cell_id || rp->sri == msc_a->c.ran->sri)
279 rp_from_cell_id = rp;
280 }
281 }
282
283 /* Did we find mismatching targets from neighbor config and from connected cells? */
284 if (rp_from_neighbor_ident && rp_from_cell_id
285 && rp_from_neighbor_ident != rp_from_cell_id) {
286 LOG_HO(msc_a, LOGL_ERROR, "Ambiguous match for cell ID %s:"
287 " neighbor config points at %s; a matching cell is also served by connected RAN peer %s\n",
288 gsm0808_cell_id_name(cid), rp_from_neighbor_ident->fi->id, rp_from_cell_id->fi->id);
289 /* But logging is all we're going to do about it. */
290 }
291
292 if (rp_from_neighbor_ident && rp_from_neighbor_ident->sri != msc_a->c.ran->sri) {
293 LOG_HO(msc_a, LOGL_ERROR,
294 "Neighbor config indicates inter-RAT Handover, which is not implemented. Ignoring target %s\n",
295 rp_from_neighbor_ident->fi->id);
296 rp_from_neighbor_ident = NULL;
297 }
298
299 if (rp_from_cell_id && rp_from_cell_id->sri != msc_a->c.ran->sri) {
300 LOG_HO(msc_a, LOGL_ERROR,
301 "Target RAN peer indicates inter-RAT Handover, which is not implemented. Ignoring target %s\n",
302 rp_from_cell_id->fi->id);
303 rp_from_cell_id = NULL;
304 }
305
306 *ran_peer_from_neighbor_ident = rp_from_neighbor_ident;
307 *ran_peer_from_seen_cells = rp_from_cell_id;
308
309 return rp_from_neighbor_ident || rp_from_cell_id ? MSC_NEIGHBOR_TYPE_LOCAL_RAN_PEER : MSC_NEIGHBOR_TYPE_NONE;
310}
311
312static bool msc_ho_find_next_target_cell(struct msc_a *msc_a)
313{
314 struct vlr_subscr *vsub = msc_a_vsub(msc_a);
315 struct ran_handover_required *info = &msc_a->ho.info;
316 struct gsm0808_cell_id *cid = &msc_a->ho.new_cell.cid;
317 const struct neighbor_ident_entry *e;
318 struct ran_peer *rp_from_neighbor_ident = NULL;
319 struct ran_peer *rp_from_cell_id = NULL;
320 struct ran_peer *rp;
321
322 unsigned int cil_idx = msc_a->ho.next_cil_idx;
323 msc_a->ho.next_cil_idx++;
324
325 msc_a->ho.new_cell.type = MSC_NEIGHBOR_TYPE_NONE;
326
327 if (cil_idx >= info->cil.id_list_len)
328 return false;
329
330 *cid = (struct gsm0808_cell_id){
331 .id_discr = info->cil.id_discr,
332 .id = info->cil.id_list[cil_idx],
333 };
334
335 msc_a->ho.new_cell.cgi = (struct osmo_cell_global_id){
336 .lai = vsub->cgi.lai,
337 };
338 gsm0808_cell_id_to_cgi(&msc_a->ho.new_cell.cgi, cid);
339
340 switch (msc_ho_find_target_cell(msc_a, cid, &e, &rp_from_neighbor_ident, &rp_from_cell_id)) {
341 case MSC_NEIGHBOR_TYPE_REMOTE_MSC:
342 OSMO_ASSERT(e);
343 msc_a->ho.new_cell.ran_type = e->addr.ran_type;
344 msc_a->ho.new_cell.type = MSC_NEIGHBOR_TYPE_REMOTE_MSC;
345 msc_a->ho.new_cell.msc_ipa_name = e->addr.remote_msc_ipa_name.buf;
346 return true;
347
348 case MSC_NEIGHBOR_TYPE_LOCAL_RAN_PEER:
349 rp = rp_from_neighbor_ident ? : rp_from_cell_id;
350 OSMO_ASSERT(rp);
351 msc_a->ho.new_cell.type = MSC_NEIGHBOR_TYPE_LOCAL_RAN_PEER;
352 msc_a->ho.new_cell.ran_peer = rp;
353 return true;
354
355 default:
356 break;
357 }
358
359 LOG_HO(msc_a, LOGL_DEBUG, "Cannot find target peer for cell ID %s\n", gsm0808_cell_id_name(cid));
360 /* Try the next cell id, if any. */
361 return msc_ho_find_next_target_cell(msc_a);
362}
363
364static void msc_ho_fsm_required_onenter(struct osmo_fsm_inst *fi, uint32_t prev_state)
365{
366 struct msc_a *msc_a = fi->priv;
367
368 if (!msc_ho_find_next_target_cell(msc_a)) {
369 int tried = msc_a->ho.next_cil_idx - 1;
370 msc_ho_failed(msc_a, GSM0808_CAUSE_NO_RADIO_RESOURCE_AVAILABLE,
371 "Attempted Handover to %u cells without success\n", tried);
372 return;
373 }
374
375 msc_ho_fsm_state_chg(msc_a, MSC_HO_ST_WAIT_REQUEST_ACK);
376}
377
378static void msc_ho_send_handover_request(struct msc_a *msc_a)
379{
380 struct vlr_subscr *vsub = msc_a_vsub(msc_a);
381 struct gsm_network *net = msc_a_net(msc_a);
382 struct gsm0808_channel_type channel_type;
Philipp Maier7da956e2020-06-09 14:34:40 +0200383 struct gsm_trans *cc_trans = msc_a->cc.active_trans;
Neels Hofmeyrc4628a32018-12-07 14:47:34 +0100384 struct ran_msg ran_enc_msg = {
385 .msg_type = RAN_MSG_HANDOVER_REQUEST,
386 .handover_request = {
387 .imsi = vsub->imsi,
388 .classmark = &vsub->classmark,
389 .geran = {
390 .chosen_encryption = &msc_a->geran_encr,
391 .a5_encryption_mask = net->a5_encryption_mask,
392 },
393 .bssap_cause = GSM0808_CAUSE_BETTER_CELL,
394 .current_channel_type_1_present = msc_a->ho.info.current_channel_type_1_present,
395 .current_channel_type_1 = msc_a->ho.info.current_channel_type_1,
396 .speech_version_used = msc_a->ho.info.speech_version_used,
397 .old_bss_to_new_bss_info_raw = msc_a->ho.info.old_bss_to_new_bss_info_raw,
398 .old_bss_to_new_bss_info_raw_len = msc_a->ho.info.old_bss_to_new_bss_info_raw_len,
399
400 /* Don't send AoIP Transport Layer Address for inter-MSC Handover */
401 .rtp_ran_local = (msc_a->ho.new_cell.type == MSC_NEIGHBOR_TYPE_LOCAL_RAN_PEER)
402 ? call_leg_local_ip(msc_a->cc.call_leg, RTP_TO_RAN) : NULL,
Philipp Maier7da956e2020-06-09 14:34:40 +0200403 .call_id_present = true,
404 .call_id = cc_trans->callref,
Neels Hofmeyrc4628a32018-12-07 14:47:34 +0100405 },
406 };
407
Neels Hofmeyr73d093a2021-06-23 23:54:43 +0200408 if (msc_a->geran_encr.key_len)
409 LOG_MSC_A(msc_a, LOGL_DEBUG, "HO Request with ciphering: A5/%d kc %s kc128 %s\n",
410 msc_a->geran_encr.alg_id - 1,
411 osmo_hexdump_nospc_c(OTC_SELECT, msc_a->geran_encr.key, msc_a->geran_encr.key_len),
412 msc_a->geran_encr.kc128_present ?
413 osmo_hexdump_nospc_c(OTC_SELECT, msc_a->geran_encr.kc128, sizeof(msc_a->geran_encr.kc128))
414 : "-");
415
Neels Hofmeyrb6c11c42022-08-08 18:15:32 +0200416 if (cc_trans) {
417 if (sdp_audio_codecs_to_gsm0808_channel_type(&channel_type,
418 &cc_trans->cc.codecs.result.audio_codecs)) {
Neels Hofmeyrc4628a32018-12-07 14:47:34 +0100419 msc_ho_failed(msc_a, GSM0808_CAUSE_EQUIPMENT_FAILURE,
Neels Hofmeyrb6c11c42022-08-08 18:15:32 +0200420 "Failed to determine Channel Type for Handover Request message\n");
Neels Hofmeyrc4628a32018-12-07 14:47:34 +0100421 return;
422 }
423 ran_enc_msg.handover_request.geran.channel_type = &channel_type;
424 }
425
426 gsm0808_cell_id_from_cgi(&ran_enc_msg.handover_request.cell_id_serving, CELL_IDENT_WHOLE_GLOBAL, &vsub->cgi);
427 ran_enc_msg.handover_request.cell_id_target = msc_a->ho.new_cell.cid;
428
429 if (msc_a_msg_down(msc_a, MSC_ROLE_T, MSC_T_EV_FROM_A_PREPARE_HANDOVER_REQUEST, &ran_enc_msg))
430 msc_ho_try_next_cell(msc_a, "Failed to send Handover Request message\n");
431}
432
433static void msc_ho_fsm_wait_request_ack_onenter(struct osmo_fsm_inst *fi, uint32_t prev_state)
434{
435 struct msc_a *msc_a = fi->priv;
436 struct msc_i *msc_i = msc_a_msc_i(msc_a);
437 struct msc_t *msc_t;
438 struct ran_peer *rp;
439 const char *ipa_name;
440
441 msc_t = msc_a_msc_t(msc_a);
442 if (msc_t) {
443 /* All the other code should prevent this from happening, ever. */
444 msc_ho_failed(msc_a, GSM0808_CAUSE_EQUIPMENT_FAILURE,
445 "Cannot initiate Handover Request, there still is an active MSC-T role: %s\n",
446 msc_t->c.fi->id);
447 return;
448 }
449
450 if (!msc_i) {
451 msc_ho_failed(msc_a, GSM0808_CAUSE_EQUIPMENT_FAILURE,
452 "Cannot initiate Handover Request, there is no MSC-I role\n");
453 return;
454 }
455
456 if (!msc_i->c.remote_to
457 && !(msc_i->ran_conn && msc_i->ran_conn->ran_peer)) {
458 msc_ho_failed(msc_a, GSM0808_CAUSE_EQUIPMENT_FAILURE,
459 "Cannot initiate Handover Request, MSC-I role has no connection\n");
460 return;
461 }
462
463 switch (msc_a->ho.new_cell.type) {
464 case MSC_NEIGHBOR_TYPE_LOCAL_RAN_PEER:
465 rp = msc_a->ho.new_cell.ran_peer;
466 OSMO_ASSERT(rp && rp->fi);
467
468 if (msc_i->c.remote_to) {
469 LOG_HO(msc_a, LOGL_INFO,
470 "Starting inter-MSC Subsequent Handover from remote MSC %s to local %s\n",
471 msc_i->c.remote_to->remote_name, rp->fi->id);
472 msc_a->ho.subsequent_ho = true;
473 } else {
474 LOG_HO(msc_a, LOGL_INFO, "Starting inter-BSC Handover from %s to %s\n",
475 msc_i->ran_conn->ran_peer->fi->id, rp->fi->id);
476 }
477
Vadim Yanitskiya870faf2019-05-11 02:45:46 +0700478 msc_t = msc_t_alloc(msc_a->c.msub, rp);
479 break;
Neels Hofmeyrc4628a32018-12-07 14:47:34 +0100480
481 case MSC_NEIGHBOR_TYPE_REMOTE_MSC:
482 ipa_name = msc_a->ho.new_cell.msc_ipa_name;
483 OSMO_ASSERT(ipa_name);
484
485 if (msc_i->c.remote_to) {
486 LOG_HO(msc_a, LOGL_INFO,
487 "Starting inter-MSC Subsequent Handover from remote MSC %s to remote MSC at %s\n",
488 msc_i->c.remote_to->remote_name, osmo_quote_str(ipa_name, -1));
489 msc_a->ho.subsequent_ho = true;
490 } else {
491 LOG_HO(msc_a, LOGL_INFO, "Starting inter-MSC Handover from local %s to remote MSC at %s\n",
492 msc_i->ran_conn->ran_peer->fi->id,
493 osmo_quote_str(ipa_name, -1));
494 }
495
Vadim Yanitskiya870faf2019-05-11 02:45:46 +0700496 msc_t = msc_t_remote_alloc(msc_a->c.msub, msc_a->c.ran,
497 (const uint8_t *) ipa_name,
498 strlen(ipa_name));
499 break;
Neels Hofmeyrc4628a32018-12-07 14:47:34 +0100500
501 default:
502 msc_ho_try_next_cell(msc_a, "unknown Handover target type %d\n", msc_a->ho.new_cell.type);
503 return;
504 }
505
Neels Hofmeyrc4628a32018-12-07 14:47:34 +0100506 if (!msc_t) {
507 /* There should definitely be one now. */
508 msc_ho_failed(msc_a, GSM0808_CAUSE_EQUIPMENT_FAILURE,
509 "Cannot initiate Handover Request, failed to set up a target MSC-T\n");
510 return;
511 }
Vadim Yanitskiya870faf2019-05-11 02:45:46 +0700512
513 msc_ho_send_handover_request(msc_a);
Neels Hofmeyrc4628a32018-12-07 14:47:34 +0100514}
515
516static void msc_ho_rx_request_ack(struct msc_a *msc_a, struct msc_a_ran_dec_data *hra);
517
518static void msc_ho_fsm_wait_request_ack(struct osmo_fsm_inst *fi, uint32_t event, void *data)
519{
520 struct msc_a *msc_a = fi->priv;
521
522 switch (event) {
523
524 case MSC_HO_EV_RX_REQUEST_ACK:
525 msc_ho_rx_request_ack(msc_a, (struct msc_a_ran_dec_data*)data);
526 return;
527
528 case MSC_HO_EV_RX_FAILURE:
529 msc_ho_failed(msc_a, GSM0808_CAUSE_NO_RADIO_RESOURCE_AVAILABLE,
530 "Received Handover Failure message\n");
531 return;
532
533 default:
534 OSMO_ASSERT(false);
535 }
536}
537
538static void msc_ho_rtp_switch_to_new_cell(struct msc_a *msc_a);
539
540void msc_ho_mncc_forward_cb(struct mncc_call *mncc_call, const union mncc_msg *mncc_msg, void *data)
541{
542 struct msc_a *msc_a = data;
543 switch (mncc_msg->msg_type) {
544 case MNCC_RTP_CONNECT:
545 msc_a->ho.rtp_switched_to_new_cell = true;
546 return;
547 default:
548 return;
549 }
550}
551
552/* Initiate call forwarding via MNCC: call the Handover Number that the other MSC assigned. */
553static int msc_ho_start_inter_msc_call_forwarding(struct msc_a *msc_a, struct msc_t *msc_t,
554 const struct msc_a_ran_dec_data *hra)
555{
556 const struct osmo_gsup_message *e_info = hra->an_apdu->e_info;
557 struct gsm_mncc outgoing_call_req = {};
558 struct call_leg *cl = msc_a->cc.call_leg;
559 struct rtp_stream *rtp_to_ran = cl ? cl->rtp[RTP_TO_RAN] : NULL;
560 struct mncc_call *mncc_call;
561
562 if (!e_info || !e_info->msisdn_enc || !e_info->msisdn_enc_len) {
563 msc_ho_try_next_cell(msc_a,
564 "No Handover Number in Handover Request Acknowledge from remote MSC\n");
565 return -EINVAL;
566 }
567
Neels Hofmeyrda3ce712019-05-09 14:16:26 +0200568 if (!rtp_to_ran) {
569 msc_ho_failed(msc_a, GSM0808_CAUSE_EQUIPMENT_FAILURE, "Unexpected: no RTP stream is set up\n");
570 return -EINVAL;
571 }
572
Neels Hofmeyrc4628a32018-12-07 14:47:34 +0100573 /* Backup old cell's RTP IP:port and codec data */
574 msc_a->ho.old_cell.ran_remote_rtp = rtp_to_ran->remote;
Neels Hofmeyr62bfa372022-10-31 18:51:07 +0100575 msc_a->ho.old_cell.codecs = rtp_to_ran->codecs;
Neels Hofmeyrc4628a32018-12-07 14:47:34 +0100576
577 /* Blindly taken over from an MNCC trace of existing code: send an all-zero CCCAP: */
578 outgoing_call_req.fields |= MNCC_F_CCCAP;
579
580 /* Called number */
581 outgoing_call_req.fields |= MNCC_F_CALLED;
582 outgoing_call_req.called.plan = 1; /* Empirical magic number. There seem to be no enum or defines for this.
583 * The only other place setting this apparently is gsm48_decode_called(). */
584 if (gsm48_decode_bcd_number2(outgoing_call_req.called.number, sizeof(outgoing_call_req.called.number),
585 e_info->msisdn_enc, e_info->msisdn_enc_len, 0)) {
586 msc_ho_try_next_cell(msc_a,
587 "Failed to decode Handover Number in Handover Request Acknowledge"
588 " from remote MSC\n");
589 return -EINVAL;
590 }
591
592 if (msc_a->cc.active_trans) {
593 outgoing_call_req.fields |= MNCC_F_BEARER_CAP;
594 outgoing_call_req.bearer_cap = msc_a->cc.active_trans->bearer_cap;
595 }
596
597 mncc_call = mncc_call_alloc(msc_a_vsub(msc_a),
598 msc_a->ho.fi,
599 MSC_HO_EV_MNCC_FORWARDING_COMPLETE,
600 MSC_HO_EV_MNCC_FORWARDING_FAILED,
601 msc_ho_mncc_forward_cb, msc_a);
602
603 mncc_call_set_rtp_stream(mncc_call, rtp_to_ran);
604 msc_a->ho.new_cell.mncc_forwarding_to_remote_ran = mncc_call;
605 return mncc_call_outgoing_start(mncc_call, &outgoing_call_req);
606}
607
608static void msc_ho_rx_request_ack(struct msc_a *msc_a, struct msc_a_ran_dec_data *hra)
609{
610 struct msc_t *msc_t = msc_a_msc_t(msc_a);
611 struct ran_msg ran_enc_msg;
612
613 OSMO_ASSERT(hra->ran_dec);
614 OSMO_ASSERT(hra->an_apdu);
615
616 if (!msc_t) {
617 msc_ho_failed(msc_a, GSM0808_CAUSE_EQUIPMENT_FAILURE, "MSC-T role missing\n");
618 return;
619 }
620
621 if (!hra->ran_dec->handover_request_ack.rr_ho_command
622 || !hra->ran_dec->handover_request_ack.rr_ho_command_len) {
623 msc_ho_try_next_cell(msc_a, "Missing mandatory IE in Handover Request Acknowledge:"
624 " L3 Info (RR Handover Command)\n");
625 return;
626 }
627
628 if (!hra->ran_dec->handover_request_ack.chosen_channel_present) {
629 LOG_HO(msc_a, LOGL_DEBUG, "No 'Chosen Channel' IE in Handover Request Ack\n");
630 msc_t->geran.chosen_channel = 0;
631 } else
632 msc_t->geran.chosen_channel = hra->ran_dec->handover_request_ack.chosen_channel;
633
634 if (!hra->ran_dec->handover_request_ack.chosen_encr_alg) {
635 LOG_HO(msc_a, LOGL_DEBUG, "No 'Chosen Encryption Algorithm' IE in Handover Request Ack\n");
636 msc_t->geran.chosen_encr_alg = 0;
637 } else {
638 msc_t->geran.chosen_encr_alg = hra->ran_dec->handover_request_ack.chosen_encr_alg;
639 if (msc_t->geran.chosen_encr_alg < 1 || msc_t->geran.chosen_encr_alg > 8) {
640 msc_ho_try_next_cell(msc_a, "Handover Request Ack: Invalid 'Chosen Encryption Algorithm': %u\n",
641 msc_t->geran.chosen_encr_alg);
642 return;
643 }
644 }
645
646 msc_t->geran.chosen_speech_version = hra->ran_dec->handover_request_ack.chosen_speech_version;
647 if (!msc_t->geran.chosen_speech_version)
648 LOG_HO(msc_a, LOGL_DEBUG, "No 'Chosen Speech Version' IE in Handover Request Ack\n");
649
650 /* Inter-MSC call forwarding? */
651 if (msc_a->ho.new_cell.type == MSC_NEIGHBOR_TYPE_REMOTE_MSC) {
652 if (msc_ho_start_inter_msc_call_forwarding(msc_a, msc_t, hra))
653 return;
654 }
655
656 msc_ho_fsm_state_chg(msc_a, MSC_HO_ST_WAIT_COMPLETE);
657
658 /* Forward the RR Handover Command composed by the new RAN peer down to the old RAN peer */
659 ran_enc_msg = (struct ran_msg){
660 .msg_type = RAN_MSG_HANDOVER_COMMAND,
661 .handover_command = {
662 .rr_ho_command = hra->ran_dec->handover_request_ack.rr_ho_command,
663 .rr_ho_command_len = hra->ran_dec->handover_request_ack.rr_ho_command_len,
664 },
665 };
666
667 if (msc_a_msg_down(msc_a, MSC_ROLE_I,
668 msc_a->ho.subsequent_ho ? MSC_I_EV_FROM_A_PREPARE_SUBSEQUENT_HANDOVER_RESULT
669 : MSC_I_EV_FROM_A_FORWARD_ACCESS_SIGNALLING_REQUEST,
670 &ran_enc_msg)) {
671 msc_ho_failed(msc_a, GSM0808_CAUSE_EQUIPMENT_FAILURE, "Failed to send Handover Command\n");
672 return;
673 }
674
675 msc_a->ho.new_cell.ran_remote_rtp = hra->ran_dec->handover_request_ack.remote_rtp;
Neels Hofmeyr84ce2062019-10-05 05:15:25 +0200676 if (osmo_sockaddr_str_is_nonzero(&msc_a->ho.new_cell.ran_remote_rtp)) {
Neels Hofmeyrc4628a32018-12-07 14:47:34 +0100677 LOG_HO(msc_a, LOGL_DEBUG, "Request Ack contains cell's RTP address " OSMO_SOCKADDR_STR_FMT "\n",
678 OSMO_SOCKADDR_STR_FMT_ARGS(&msc_a->ho.new_cell.ran_remote_rtp));
679 }
680
681 msc_a->ho.new_cell.codec_present = hra->ran_dec->handover_request_ack.codec_present;
682 msc_a->ho.new_cell.codec = hra->ran_dec->handover_request_ack.codec;
683 if (hra->ran_dec->handover_request_ack.codec_present) {
684 LOG_HO(msc_a, LOGL_DEBUG, "Request Ack contains codec %s\n",
Neels Hofmeyr7934e0d2022-10-31 18:13:47 +0100685 gsm0808_speech_codec_type_name(msc_a->ho.new_cell.codec.type));
Neels Hofmeyrc4628a32018-12-07 14:47:34 +0100686 }
687}
688
689static void msc_ho_rtp_switch_to_new_cell(struct msc_a *msc_a)
690{
691 struct call_leg *cl = msc_a->cc.call_leg;
692 struct rtp_stream *rtp_to_ran = cl ? cl->rtp[RTP_TO_RAN] : NULL;
693
694 if (!rtp_to_ran) {
695 LOG_HO(msc_a, LOGL_DEBUG, "No RTP stream, nothing to switch\n");
696 return;
697 }
698
Neels Hofmeyr84ce2062019-10-05 05:15:25 +0200699 if (!osmo_sockaddr_str_is_nonzero(&msc_a->ho.new_cell.ran_remote_rtp)) {
Neels Hofmeyrc4628a32018-12-07 14:47:34 +0100700 LOG_HO(msc_a, LOGL_DEBUG, "New cell's RTP IP:port not yet known, not switching RTP stream\n");
701 return;
702 }
703
704 if (msc_a->ho.rtp_switched_to_new_cell) {
705 LOG_HO(msc_a, LOGL_DEBUG, "Already switched RTP to new cell\n");
706 return;
707 }
708 msc_a->ho.rtp_switched_to_new_cell = true;
709
710 /* Backup old cell's RTP IP:port and codec data */
711 msc_a->ho.old_cell.ran_remote_rtp = rtp_to_ran->remote;
Neels Hofmeyr62bfa372022-10-31 18:51:07 +0100712 msc_a->ho.old_cell.codecs = rtp_to_ran->codecs;
Neels Hofmeyrc4628a32018-12-07 14:47:34 +0100713
714 LOG_HO(msc_a, LOGL_DEBUG, "Switching RTP stream to new cell: from " OSMO_SOCKADDR_STR_FMT " to " OSMO_SOCKADDR_STR_FMT "\n",
715 OSMO_SOCKADDR_STR_FMT_ARGS(&msc_a->ho.old_cell.ran_remote_rtp),
716 OSMO_SOCKADDR_STR_FMT_ARGS(&msc_a->ho.new_cell.ran_remote_rtp));
717
718 /* If a previous forwarding to a remote MSC is still active, this now becomes no longer responsible for the RTP
719 * stream. */
720 if (msc_a->cc.mncc_forwarding_to_remote_ran) {
721 if (msc_a->cc.mncc_forwarding_to_remote_ran->rtps != rtp_to_ran) {
722 LOG_HO(msc_a, LOGL_ERROR,
723 "Unexpected state: previous MNCC forwarding not using RTP-to-RAN stream\n");
724 /* That would be weird, but carry on anyway... */
725 }
726 mncc_call_detach_rtp_stream(msc_a->cc.mncc_forwarding_to_remote_ran);
727 }
728
729 /* Switch over to the new peer */
730 rtp_stream_set_remote_addr(rtp_to_ran, &msc_a->ho.new_cell.ran_remote_rtp);
Neels Hofmeyr62bfa372022-10-31 18:51:07 +0100731 if (msc_a->ho.new_cell.codec_present) {
Neels Hofmeyr7934e0d2022-10-31 18:13:47 +0100732 const struct codec_mapping *m;
733 m = codec_mapping_by_gsm0808_speech_codec_type(msc_a->ho.new_cell.codec.type);
734 /* TODO: use codec_mapping_by_gsm0808_speech_codec() to also match on codec.cfg */
735 if (!m)
736 LOG_HO(msc_a, LOGL_ERROR, "Cannot resolve codec: %s\n",
737 gsm0808_speech_codec_type_name(msc_a->ho.new_cell.codec.type));
738 else
739 rtp_stream_set_one_codec(rtp_to_ran, &m->sdp);
Neels Hofmeyr62bfa372022-10-31 18:51:07 +0100740 } else {
Neels Hofmeyrc4628a32018-12-07 14:47:34 +0100741 LOG_HO(msc_a, LOGL_ERROR, "No codec is set\n");
Neels Hofmeyr62bfa372022-10-31 18:51:07 +0100742 }
Neels Hofmeyrc4628a32018-12-07 14:47:34 +0100743 rtp_stream_commit(rtp_to_ran);
744}
745
746static void msc_ho_rtp_rollback_to_old_cell(struct msc_a *msc_a)
747{
748 struct call_leg *cl = msc_a->cc.call_leg;
749 struct rtp_stream *rtp_to_ran = cl ? cl->rtp[RTP_TO_RAN] : NULL;
750
751 if (!msc_a->ho.rtp_switched_to_new_cell) {
752 LOG_HO(msc_a, LOGL_DEBUG, "Not switched RTP to new cell yet, no need to roll back\n");
753 return;
754 }
755
756 if (!rtp_to_ran) {
757 LOG_HO(msc_a, LOGL_DEBUG, "No RTP stream, nothing to switch\n");
758 return;
759 }
760
Neels Hofmeyr84ce2062019-10-05 05:15:25 +0200761 if (!osmo_sockaddr_str_is_nonzero(&msc_a->ho.old_cell.ran_remote_rtp)) {
Neels Hofmeyrc4628a32018-12-07 14:47:34 +0100762 LOG_HO(msc_a, LOGL_DEBUG, "Have no RTP IP:port for the old cell, not switching back to\n");
763 return;
764 }
765
766 /* The new call forwarding to a remote MSC is no longer needed because the handover failed */
767 if (msc_a->ho.new_cell.mncc_forwarding_to_remote_ran)
768 mncc_call_detach_rtp_stream(msc_a->ho.new_cell.mncc_forwarding_to_remote_ran);
769
770 /* If before this handover, there was a call forwarding to a remote MSC in place, this now goes back into
771 * responsibility. */
772 if (msc_a->cc.mncc_forwarding_to_remote_ran)
773 mncc_call_set_rtp_stream(msc_a->cc.mncc_forwarding_to_remote_ran, rtp_to_ran);
774
775 msc_a->ho.rtp_switched_to_new_cell = false;
776 msc_a->ho.ready_to_switch_rtp = false;
777 LOG_HO(msc_a, LOGL_NOTICE, "Switching RTP back to old cell\n");
778
779 /* Switch back to the old cell */
780 rtp_stream_set_remote_addr(rtp_to_ran, &msc_a->ho.old_cell.ran_remote_rtp);
Neels Hofmeyr62bfa372022-10-31 18:51:07 +0100781 rtp_stream_set_codecs(rtp_to_ran, &msc_a->ho.old_cell.codecs);
Neels Hofmeyrc4628a32018-12-07 14:47:34 +0100782 rtp_stream_commit(rtp_to_ran);
783}
784
785static void msc_ho_send_handover_succeeded(struct msc_a *msc_a)
786{
787 struct ran_msg ran_enc_msg = {
788 .msg_type = RAN_MSG_HANDOVER_SUCCEEDED,
789 };
790
791 if (msc_a_msg_down(msc_a, MSC_ROLE_I, MSC_I_EV_FROM_A_FORWARD_ACCESS_SIGNALLING_REQUEST, &ran_enc_msg))
792 msc_ho_failed(msc_a, GSM0808_CAUSE_EQUIPMENT_FAILURE, "Failed to send Handover Succeeded message\n");
793}
794
795static void msc_ho_fsm_wait_complete(struct osmo_fsm_inst *fi, uint32_t event, void *data)
796{
797 struct msc_a *msc_a = fi->priv;
798
799 switch (event) {
800
801 case MSC_HO_EV_RX_DETECT:
802 msc_a->ho.ready_to_switch_rtp = true;
803 /* For inter-MSC, the mncc_fsm switches the rtp_stream upon MNCC_RTP_CONNECT.
804 * For inter-BSC, need to switch here to the address obtained from Handover Request Ack. */
805 if (msc_a->ho.new_cell.type == MSC_NEIGHBOR_TYPE_LOCAL_RAN_PEER)
806 msc_ho_rtp_switch_to_new_cell(msc_a);
807 msc_ho_send_handover_succeeded(msc_a);
808 return;
809
810 case MSC_HO_EV_RX_COMPLETE:
811 msc_ho_success(msc_a);
812 return;
813
814 case MSC_HO_EV_RX_FAILURE:
815 msc_ho_failed(msc_a, GSM0808_CAUSE_NO_RADIO_RESOURCE_AVAILABLE,
816 "Received Handover Failure message\n");
817 return;
818
819 case MSC_HO_EV_MNCC_FORWARDING_FAILED:
820 msc_ho_failed(msc_a, GSM0808_CAUSE_EQUIPMENT_FAILURE, "MNCC Forwarding failed\n");
821 return;
822
823 case MSC_HO_EV_MNCC_FORWARDING_COMPLETE:
824 return;
825
826 default:
827 OSMO_ASSERT(false);
828 }
829}
830
831static void msc_ho_fsm_cleanup(struct osmo_fsm_inst *fi, enum osmo_fsm_term_cause cause)
832{
833 struct msc_a *msc_a = fi->priv;
834 struct msc_t *msc_t = msc_a_msc_t(msc_a);
835
836 /* paranoia */
837 if (msc_a->ho.fi != fi)
838 return;
839
840 /* Completely clear all handover state */
841 msc_a->ho = (struct msc_ho_state){};
842
843 if (msc_t)
844 msc_t_clear(msc_t);
845}
846
847static int msc_ho_fsm_timer_cb(struct osmo_fsm_inst *fi)
848{
849 return 1;
850}
851
852#define S(x) (1 << (x))
853
854static const struct osmo_fsm_state msc_ho_fsm_states[] = {
855 [MSC_HO_ST_REQUIRED] = {
856 .name = OSMO_STRINGIFY(MSC_HO_ST_REQUIRED),
857 .out_state_mask = 0
858 | S(MSC_HO_ST_REQUIRED)
859 | S(MSC_HO_ST_WAIT_REQUEST_ACK)
860 ,
861 .onenter = msc_ho_fsm_required_onenter,
862 },
863 [MSC_HO_ST_WAIT_REQUEST_ACK] = {
864 .name = OSMO_STRINGIFY(MSC_HO_ST_WAIT_REQUEST_ACK),
865 .in_event_mask = 0
866 | S(MSC_HO_EV_RX_REQUEST_ACK)
867 | S(MSC_HO_EV_RX_FAILURE)
868 ,
869 .out_state_mask = 0
870 | S(MSC_HO_ST_REQUIRED)
871 | S(MSC_HO_ST_WAIT_COMPLETE)
872 ,
873 .onenter = msc_ho_fsm_wait_request_ack_onenter,
874 .action = msc_ho_fsm_wait_request_ack,
875 },
876 [MSC_HO_ST_WAIT_COMPLETE] = {
877 .name = OSMO_STRINGIFY(MSC_HO_ST_WAIT_COMPLETE),
878 .in_event_mask = 0
879 | S(MSC_HO_EV_RX_DETECT)
880 | S(MSC_HO_EV_RX_COMPLETE)
881 | S(MSC_HO_EV_RX_FAILURE)
882 | S(MSC_HO_EV_MNCC_FORWARDING_COMPLETE)
883 | S(MSC_HO_EV_MNCC_FORWARDING_FAILED)
884 ,
885 .action = msc_ho_fsm_wait_complete,
886 },
887};
888
889static const struct value_string msc_ho_fsm_event_names[] = {
890 OSMO_VALUE_STRING(MSC_HO_EV_RX_REQUEST_ACK),
891 OSMO_VALUE_STRING(MSC_HO_EV_RX_DETECT),
892 OSMO_VALUE_STRING(MSC_HO_EV_RX_COMPLETE),
893 OSMO_VALUE_STRING(MSC_HO_EV_RX_FAILURE),
894 {}
895};
896
897struct osmo_fsm msc_ho_fsm = {
898 .name = "handover",
899 .states = msc_ho_fsm_states,
900 .num_states = ARRAY_SIZE(msc_ho_fsm_states),
901 .log_subsys = DHO,
902 .event_names = msc_ho_fsm_event_names,
903 .timer_cb = msc_ho_fsm_timer_cb,
904 .cleanup = msc_ho_fsm_cleanup,
905};