blob: 5bc9c12846b2e62dcbbea77ece2ca4fc9c81f349 [file] [log] [blame]
Pau Espin Pedrolc0a250d2021-01-21 18:46:13 +01001/* nacc_fsm.c
2 *
3 * Copyright (C) 2021 by sysmocom - s.f.m.c. GmbH <info@sysmocom.de>
4 * Author: Pau Espin Pedrol <pespin@sysmocom.de>
5 *
6 * This program is free software; you can redistribute it and/or
7 * modify it under the terms of the GNU General Public License
8 * as published by the Free Software Foundation; either version 2
9 * of the License, or (at your option) any later version.
10 *
11 * This program is distributed in the hope that it will be useful,
12 * but WITHOUT ANY WARRANTY; without even the implied warranty of
13 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
14 * GNU General Public License for more details.
15 *
16 * You should have received a copy of the GNU General Public License
17 * along with this program; if not, write to the Free Software
18 * Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA.
19 */
20
21#include <unistd.h>
22
23#include <talloc.h>
24
25#include <osmocom/core/rate_ctr.h>
26#include <osmocom/ctrl/control_cmd.h>
27#include <osmocom/ctrl/control_if.h>
28
29#include <osmocom/gsm/gsm48.h>
30#include <osmocom/gprs/gprs_bssgp.h>
31#include <osmocom/gprs/gprs_bssgp_rim.h>
32
33#include <nacc_fsm.h>
34#include <gprs_rlcmac.h>
35#include <gprs_debug.h>
36#include <gprs_ms.h>
37#include <encoding.h>
38#include <bts.h>
39#include <neigh_cache.h>
40
41#define X(s) (1 << (s))
42
Pau Espin Pedrol069a6372021-02-10 17:33:13 +010043/* Infer CTRL id (seqnum) for a given tgt arfcn+bsic (bsic range: 0-63) */
44#define arfcn_bsic_2_ctrl_id(arfcn, bsic) ((arfcn) * 100 + (bsic))
45
Pau Espin Pedrol41a22a72021-01-26 19:00:37 +010046static const struct osmo_tdef_state_timeout nacc_fsm_timeouts[32] = {
47 [NACC_ST_INITIAL] = {},
48 [NACC_ST_WAIT_RESOLVE_RAC_CI] = { .T = PCU_TDEF_NEIGH_RESOLVE_TO },
49 [NACC_ST_WAIT_REQUEST_SI] = { .T = PCU_TDEF_SI_RESOLVE_TO },
50 [NACC_ST_TX_NEIGHBOUR_DATA] = {},
51 [NACC_ST_TX_CELL_CHG_CONTINUE] = {},
Pau Espin Pedrol952cb3d2021-02-01 14:52:48 +010052 [NACC_ST_WAIT_CELL_CHG_CONTINUE_ACK] = {}, /* Timeout through event controlled by tbf::poll_timeout() */
Pau Espin Pedrol41a22a72021-01-26 19:00:37 +010053 [NACC_ST_DONE] = {},
54};
55
56/* Transition to a state, using the T timer defined in assignment_fsm_timeouts.
57 * The actual timeout value is in turn obtained from conn->T_defs.
58 * Assumes local variable fi exists. */
59
Pau Espin Pedrolc0a250d2021-01-21 18:46:13 +010060#define nacc_fsm_state_chg(fi, NEXT_STATE) \
Pau Espin Pedrol41a22a72021-01-26 19:00:37 +010061 osmo_tdef_fsm_inst_state_chg(fi, NEXT_STATE, \
62 nacc_fsm_timeouts, \
63 ((struct nacc_fsm_ctx*)(fi->priv))->ms->bts->pcu->T_defs, \
64 -1)
Pau Espin Pedrolc0a250d2021-01-21 18:46:13 +010065
66const struct value_string nacc_fsm_event_names[] = {
67 { NACC_EV_RX_CELL_CHG_NOTIFICATION, "RX_CELL_CHG_NOTIFICATION" },
68 { NACC_EV_RX_RAC_CI, "RX_RAC_CI" },
69 { NACC_EV_RX_SI, "RX_SI" },
70 { NACC_EV_CREATE_RLCMAC_MSG, "CREATE_RLCMAC_MSG" },
Pau Espin Pedrol952cb3d2021-02-01 14:52:48 +010071 { NACC_EV_RX_CELL_CHG_CONTINUE_ACK, "RX_CELL_CHG_CONTINUE_ACK"},
72 { NACC_EV_TIMEOUT_CELL_CHG_CONTINUE, "TIMEOUT_CELL_CHG_CONTINUE" },
Pau Espin Pedrolc0a250d2021-01-21 18:46:13 +010073 { 0, NULL }
74};
75
76/* TS 44 060 11.2.9e Packet Neighbour Cell Data */
77static struct msgb *create_packet_neighbour_cell_data(struct nacc_fsm_ctx *ctx,
78 const struct gprs_rlcmac_tbf *tbf,
79 bool *all_si_info_sent)
80{
81 struct msgb *msg;
82 int rc;
83 RlcMacDownlink_t *mac_control_block;
84 struct GprsMs *ms = tbf_ms(tbf);
85 OSMO_ASSERT(tbf_is_tfi_assigned(tbf));
86 uint8_t tfi_is_dl = tbf_direction(tbf) == GPRS_RLCMAC_DL_TBF;
87 uint8_t tfi = tbf_tfi(tbf);
88 uint8_t container_id = 0;
89 PNCDContainer_t container;
90 size_t max_len, len_to_write;
91 uint8_t *cont_buf;
92 uint8_t si_type = ctx->si_info.type_psi ? 0x01 : 0x0;
93
94 memset(&container, 0, sizeof(container));
95 if (ctx->container_idx == 0) {
96 container.UnionType = 1; /* with ID */
97 container.u.PNCD_Container_With_ID.ARFCN = ctx->neigh_key.tgt_arfcn;
98 container.u.PNCD_Container_With_ID.BSIC = ctx->neigh_key.tgt_bsic;
99 cont_buf = &container.u.PNCD_Container_With_ID.CONTAINER[0];
100 max_len = sizeof(container.u.PNCD_Container_With_ID.CONTAINER) - 1;
101 } else {
102 container.UnionType = 0; /* without ID */
103 cont_buf = &container.u.PNCD_Container_Without_ID.CONTAINER[0];
104 max_len = sizeof(container.u.PNCD_Container_Without_ID.CONTAINER) - 1;
105 }
106
107 len_to_write = ctx->si_info.si_len - ctx->si_info_bytes_sent;
108
109 if (len_to_write == 0) {
110 /* We sent all info on last message filing it exactly, we now send a zeroed one to finish */
111 *all_si_info_sent = true;
112 *cont_buf = (si_type << 5) | 0x00;
113 } else if (len_to_write >= max_len) {
114 /* We fill the rlcmac block, we'll need more messages */
115 *all_si_info_sent = false;
116 *cont_buf = (si_type << 5) | 0x1F;
117 memcpy(cont_buf + 1, &ctx->si_info.si_buf[ctx->si_info_bytes_sent], max_len);
118 ctx->si_info_bytes_sent += max_len;
119 } else {
120 /* Last block, we don't fill it exactly */
121 *all_si_info_sent = true;
122 *cont_buf = (si_type << 5) | (len_to_write & 0x1F);
123 memcpy(cont_buf + 1, &ctx->si_info.si_buf[ctx->si_info_bytes_sent], len_to_write);
124 ctx->si_info_bytes_sent += len_to_write;
125 }
126
127 msg = msgb_alloc(GSM_MACBLOCK_LEN, "neighbour_cell_data");
128 if (!msg)
129 return NULL;
130
131 /* Initialize a bit vector that uses allocated msgb as the data buffer. */
132 struct bitvec bv = {
133 .data = msgb_put(msg, GSM_MACBLOCK_LEN),
134 .data_len = GSM_MACBLOCK_LEN,
135 };
136 bitvec_unhex(&bv, DUMMY_VEC);
137
138 mac_control_block = (RlcMacDownlink_t *)talloc_zero(ctx->ms, RlcMacDownlink_t);
139
140 write_packet_neighbour_cell_data(mac_control_block,
141 tfi_is_dl, tfi, container_id,
142 ctx->container_idx, &container);
143 LOGP(DNACC, LOGL_DEBUG, "+++++++++++++++++++++++++ TX : Packet Neighbour Cell Data +++++++++++++++++++++++++\n");
144 rc = encode_gsm_rlcmac_downlink(&bv, mac_control_block);
145 if (rc < 0) {
146 LOGP(DTBF, LOGL_ERROR, "Encoding of Packet Neighbour Cell Data failed (%d)\n", rc);
147 goto free_ret;
148 }
149 LOGP(DNACC, LOGL_DEBUG, "------------------------- TX : Packet Neighbour Cell Data -------------------------\n");
150 rate_ctr_inc(&bts_rate_counters(ms->bts)->ctr[CTR_PKT_NEIGH_CELL_DATA]);
151 talloc_free(mac_control_block);
152
153 ctx->container_idx++;
154
155 return msg;
156
157free_ret:
158 talloc_free(mac_control_block);
159 msgb_free(msg);
160 return NULL;
161}
162
163/* TS 44 060 11.2.2a Packet Cell Change Continue */
164static struct msgb *create_packet_cell_chg_continue(const struct nacc_fsm_ctx *ctx,
Pau Espin Pedrol952cb3d2021-02-01 14:52:48 +0100165 const struct nacc_ev_create_rlcmac_msg_ctx *data,
166 uint32_t *new_poll_fn)
Pau Espin Pedrolc0a250d2021-01-21 18:46:13 +0100167{
168 struct msgb *msg;
169 int rc;
170 RlcMacDownlink_t *mac_control_block;
Pau Espin Pedrol952cb3d2021-02-01 14:52:48 +0100171 struct gprs_rlcmac_tbf *tbf = data->tbf;
Pau Espin Pedrolc0a250d2021-01-21 18:46:13 +0100172 struct GprsMs *ms = tbf_ms(tbf);
Pau Espin Pedrol952cb3d2021-02-01 14:52:48 +0100173 unsigned int rrbp;
174
175 rc = tbf_check_polling(tbf, data->fn, data->ts, new_poll_fn, &rrbp);
176 if (rc < 0) {
177 LOGP(DTBF, LOGL_ERROR, "Failed registering poll for Pkt Cell Chg Continue (%d)\n", rc);
178 return NULL;
179 }
Pau Espin Pedrolc0a250d2021-01-21 18:46:13 +0100180
181 msg = msgb_alloc(GSM_MACBLOCK_LEN, "pkt_cell_chg_continue");
182 if (!msg)
183 return NULL;
184
185 /* Initialize a bit vector that uses allocated msgb as the data buffer. */
186 struct bitvec bv = {
187 .data = msgb_put(msg, GSM_MACBLOCK_LEN),
188 .data_len = GSM_MACBLOCK_LEN,
189 };
190 bitvec_unhex(&bv, DUMMY_VEC);
191
192 mac_control_block = (RlcMacDownlink_t *)talloc_zero(ctx->ms, RlcMacDownlink_t);
193
194 OSMO_ASSERT(tbf_is_tfi_assigned(tbf));
195 uint8_t tfi_is_dl = tbf_direction(tbf) == GPRS_RLCMAC_DL_TBF;
196 uint8_t tfi = tbf_tfi(tbf);
197 uint8_t container_id = 0;
Pau Espin Pedrol952cb3d2021-02-01 14:52:48 +0100198 write_packet_cell_change_continue(mac_control_block, 1, rrbp, tfi_is_dl, tfi, true,
Pau Espin Pedrolc0a250d2021-01-21 18:46:13 +0100199 ctx->neigh_key.tgt_arfcn, ctx->neigh_key.tgt_bsic, container_id);
200 LOGP(DNACC, LOGL_DEBUG, "+++++++++++++++++++++++++ TX : Packet Cell Change Continue +++++++++++++++++++++++++\n");
201 rc = encode_gsm_rlcmac_downlink(&bv, mac_control_block);
202 if (rc < 0) {
203 LOGP(DTBF, LOGL_ERROR, "Encoding of Packet Cell Change Continue failed (%d)\n", rc);
204 goto free_ret;
205 }
206 LOGP(DNACC, LOGL_DEBUG, "------------------------- TX : Packet Cell Change Continue -------------------------\n");
207 rate_ctr_inc(&bts_rate_counters(ms->bts)->ctr[CTR_PKT_CELL_CHG_CONTINUE]);
208 talloc_free(mac_control_block);
Pau Espin Pedrol952cb3d2021-02-01 14:52:48 +0100209 tbf_set_polling(tbf, *new_poll_fn, data->ts, GPRS_RLCMAC_POLL_CELL_CHG_CONTINUE);
Pau Espin Pedrolc0a250d2021-01-21 18:46:13 +0100210 return msg;
211
212free_ret:
213 talloc_free(mac_control_block);
214 msgb_free(msg);
215 return NULL;
216}
217
218static int fill_rim_ran_info_req(const struct nacc_fsm_ctx *ctx, struct bssgp_ran_information_pdu *pdu)
219{
220 struct gprs_rlcmac_bts *bts = ctx->ms->bts;
221
222 *pdu = (struct bssgp_ran_information_pdu){
223 .routing_info_dest = {
224 .discr = BSSGP_RIM_ROUTING_INFO_GERAN,
225 .geran = {
226 .raid = {
227 .mcc = ctx->cgi_ps.rai.lac.plmn.mcc,
228 .mnc = ctx->cgi_ps.rai.lac.plmn.mnc,
229 .mnc_3_digits = ctx->cgi_ps.rai.lac.plmn.mnc_3_digits,
230 .lac = ctx->cgi_ps.rai.lac.lac,
231 .rac = ctx->cgi_ps.rai.rac,
232 },
233 .cid = ctx->cgi_ps.cell_identity,
234 },
235 },
236 .routing_info_src = {
237 .discr = BSSGP_RIM_ROUTING_INFO_GERAN,
238 .geran = {
239 .raid = {
240 .mcc = bts->cgi_ps.rai.lac.plmn.mcc,
241 .mnc = bts->cgi_ps.rai.lac.plmn.mnc,
242 .mnc_3_digits = bts->cgi_ps.rai.lac.plmn.mnc_3_digits,
243 .lac = bts->cgi_ps.rai.lac.lac,
244 .rac = bts->cgi_ps.rai.rac,
245 },
246 .cid = bts->cgi_ps.cell_identity,
247 },
248 },
249 .rim_cont_iei = BSSGP_IE_RI_REQ_RIM_CONTAINER,
250 .decoded_present = true,
251 .decoded = {
252 .req_rim_cont = {
253 .app_id = BSSGP_RAN_INF_APP_ID_NACC,
254 .seq_num = 1,
255 .pdu_ind = {
256 .ack_requested = 0,
257 .pdu_type_ext = RIM_PDU_TYPE_SING_REP,
258 },
259 .prot_ver = 1,
260 .son_trans_app_id = NULL,
261 .son_trans_app_id_len = 0,
262 .u = {
263 .app_cont_nacc = {
264 .reprt_cell = ctx->cgi_ps,
265 },
266 },
267 },
268 },
269 };
270
271 return 0;
272}
273
Pau Espin Pedrol0c10b3c2021-02-10 17:12:02 +0100274static int fill_neigh_key_from_bts_pkt_cell_chg_not(struct neigh_cache_entry_key *neigh_key,
275 const struct gprs_rlcmac_bts *bts,
276 const Packet_Cell_Change_Notification_t *notif)
277{
278 switch (notif->Target_Cell.UnionType) {
279 case 0: /* GSM */
280 neigh_key->local_lac = bts->cgi_ps.rai.lac.lac;
281 neigh_key->local_ci = bts->cgi_ps.cell_identity;
282 neigh_key->tgt_arfcn = notif->Target_Cell.u.Target_Cell_GSM_Notif.ARFCN;
283 neigh_key->tgt_bsic = notif->Target_Cell.u.Target_Cell_GSM_Notif.BSIC;
284 return 0;
285 default:
286 return -ENOTSUP;
287 }
288}
289
Pau Espin Pedrol44768f22021-02-02 13:11:30 +0100290#define SI_HDR_LEN 2
291static void bts_fill_si_cache_value(const struct gprs_rlcmac_bts *bts, struct si_cache_value *val)
292{
293 val->type_psi = false;
294 val->si_len = 0;
295 if (bts->si1_is_set) {
296 osmo_static_assert(sizeof(bts->si1) - SI_HDR_LEN == BSSGP_RIM_SI_LEN, _si1_header_size);
297 memcpy(&val->si_buf[val->si_len], bts->si1 + SI_HDR_LEN, BSSGP_RIM_SI_LEN);
298 val->si_len += BSSGP_RIM_SI_LEN;
299 }
300 if (bts->si3_is_set) {
301 osmo_static_assert(sizeof(bts->si3) - SI_HDR_LEN == BSSGP_RIM_SI_LEN, _si3_header_size);
302 memcpy(&val->si_buf[val->si_len], bts->si3 + SI_HDR_LEN, BSSGP_RIM_SI_LEN);
303 val->si_len += BSSGP_RIM_SI_LEN;
304 }
305 if (bts->si13_is_set) {
306 osmo_static_assert(sizeof(bts->si13) - SI_HDR_LEN == BSSGP_RIM_SI_LEN, _si13_header_size);
307 memcpy(&val->si_buf[val->si_len], bts->si13 + SI_HDR_LEN, BSSGP_RIM_SI_LEN);
308 val->si_len += BSSGP_RIM_SI_LEN;
309 }
310}
Pau Espin Pedrolc0a250d2021-01-21 18:46:13 +0100311
Pau Espin Pedrol8e69fc02021-02-10 17:44:27 +0100312/* Called on event NACC_EV_RX_CELL_CHG_NOTIFICATION on states after
313 * WAIT_RESOLVE_RAC_CI. Ignore duplicate messages, transition back if target
314 * cell changed.
315 */
316static void handle_retrans_pkt_cell_chg_notif(struct nacc_fsm_ctx *ctx, const Packet_Cell_Change_Notification_t *notif)
317{
318 struct gprs_rlcmac_bts *bts = ctx->ms->bts;
319 struct neigh_cache_entry_key neigh_key;
320
321 if (fill_neigh_key_from_bts_pkt_cell_chg_not(&neigh_key, bts, notif) < 0) {
322 LOGPFSML(ctx->fi, LOGL_NOTICE, "TargetCell type=0x%x not supported\n",
323 notif->Target_Cell.UnionType);
324 nacc_fsm_state_chg(ctx->fi, NACC_ST_TX_CELL_CHG_CONTINUE);
325 return;
326 }
327 /* If tgt cell changed, restart resolving it */
328 if (!neigh_cache_entry_key_eq(&ctx->neigh_key, &neigh_key)) {
329 ctx->neigh_key = neigh_key;
330 nacc_fsm_state_chg(ctx->fi, NACC_ST_WAIT_RESOLVE_RAC_CI);
331 }
332 /* else: ignore it, it's a dup, carry on what we were doing */
333}
334
Pau Espin Pedrolc0a250d2021-01-21 18:46:13 +0100335////////////////
336// FSM states //
337////////////////
338
339static void st_initial(struct osmo_fsm_inst *fi, uint32_t event, void *data)
340{
341 struct nacc_fsm_ctx *ctx = (struct nacc_fsm_ctx *)fi->priv;
342 struct gprs_rlcmac_bts *bts = ctx->ms->bts;
343 Packet_Cell_Change_Notification_t *notif;
344
345 switch (event) {
346 case NACC_EV_RX_CELL_CHG_NOTIFICATION:
347 notif = (Packet_Cell_Change_Notification_t *)data;
Pau Espin Pedrol0c10b3c2021-02-10 17:12:02 +0100348 if (fill_neigh_key_from_bts_pkt_cell_chg_not(&ctx->neigh_key, bts, notif) < 0) {
Pau Espin Pedrolc0a250d2021-01-21 18:46:13 +0100349 LOGPFSML(fi, LOGL_NOTICE, "TargetCell type=0x%x not supported\n",
350 notif->Target_Cell.UnionType);
351 osmo_fsm_inst_term(fi, OSMO_FSM_TERM_ERROR, NULL);
Pau Espin Pedrol0c10b3c2021-02-10 17:12:02 +0100352 } else {
353 nacc_fsm_state_chg(fi, NACC_ST_WAIT_RESOLVE_RAC_CI);
Pau Espin Pedrolc0a250d2021-01-21 18:46:13 +0100354 }
355 break;
356 default:
357 OSMO_ASSERT(0);
358 }
359}
360
361static void st_wait_resolve_rac_ci_on_enter(struct osmo_fsm_inst *fi, uint32_t prev_state)
362{
363 struct nacc_fsm_ctx *ctx = (struct nacc_fsm_ctx *)fi->priv;
364 struct gprs_rlcmac_bts *bts = ctx->ms->bts;
365 struct gprs_pcu *pcu = bts->pcu;
366 const struct osmo_cell_global_id_ps *cgi_ps;
Pau Espin Pedrolc0805e62021-01-27 17:16:59 +0100367 struct ctrl_cmd *cmd = NULL;
Pau Espin Pedrolc0a250d2021-01-21 18:46:13 +0100368 int rc;
369
370 /* First try to find the value in the cache */
371 cgi_ps = neigh_cache_lookup_value(pcu->neigh_cache, &ctx->neigh_key);
372 if (cgi_ps) {
373 ctx->cgi_ps = *cgi_ps;
374 nacc_fsm_state_chg(fi, NACC_ST_WAIT_REQUEST_SI);
375 return;
376 }
377
378 /* CGI-PS not in cache, resolve it using BSC Neighbor Resolution CTRL interface */
379
380 LOGPFSML(fi, LOGL_DEBUG, "No CGI-PS found in cache, resolving " NEIGH_CACHE_ENTRY_KEY_FMT "...\n",
381 NEIGH_CACHE_ENTRY_KEY_ARGS(&ctx->neigh_key));
382
Pau Espin Pedrol069a6372021-02-10 17:33:13 +0100383 /* We may have changed to this state previously (eg: we are handling
384 * another Pkt cell Change Notify with different target). Avoid
385 * re-creating the socket in that case. */
386 if (ctx->neigh_ctrl_conn->write_queue.bfd.fd == -1) {
387 rc = osmo_sock_init2_ofd(&ctx->neigh_ctrl_conn->write_queue.bfd,
388 AF_UNSPEC, SOCK_STREAM, IPPROTO_TCP,
389 NULL, 0, pcu->vty.neigh_ctrl_addr, pcu->vty.neigh_ctrl_port,
390 OSMO_SOCK_F_CONNECT);
391 if (rc < 0) {
392 LOGPFSML(fi, LOGL_ERROR,
393 "Failed to establish CTRL (neighbor resolution) connection to BSC r=%s:%u\n\n",
394 pcu->vty.neigh_ctrl_addr, pcu->vty.neigh_ctrl_port);
395 goto err_term;
396 }
Pau Espin Pedrolc0805e62021-01-27 17:16:59 +0100397 }
398
Pau Espin Pedrolc0a250d2021-01-21 18:46:13 +0100399 cmd = ctrl_cmd_create(ctx, CTRL_TYPE_GET);
400 if (!cmd) {
401 LOGPFSML(fi, LOGL_ERROR, "CTRL msg creation failed\n");
402 goto err_term;
403 }
404
Pau Espin Pedrol069a6372021-02-10 17:33:13 +0100405 cmd->id = talloc_asprintf(cmd, "%u", arfcn_bsic_2_ctrl_id(ctx->neigh_key.tgt_arfcn,
406 ctx->neigh_key.tgt_bsic));
Pau Espin Pedrolc0a250d2021-01-21 18:46:13 +0100407 cmd->variable = talloc_asprintf(cmd, "neighbor_resolve_cgi_ps_from_lac_ci.%d.%d.%d.%d",
408 ctx->neigh_key.local_lac, ctx->neigh_key.local_ci,
409 ctx->neigh_key.tgt_arfcn, ctx->neigh_key.tgt_bsic);
410 rc = ctrl_cmd_send(&ctx->neigh_ctrl_conn->write_queue, cmd);
411 if (rc) {
412 LOGPFSML(fi, LOGL_ERROR, "CTRL msg sent failed: %d\n", rc);
413 goto err_term;
414 }
415
416 talloc_free(cmd);
417 return;
418
419err_term:
420 talloc_free(cmd);
Pau Espin Pedrola06ac182021-01-26 19:13:43 +0100421 nacc_fsm_state_chg(fi, NACC_ST_TX_CELL_CHG_CONTINUE);
Pau Espin Pedrolc0a250d2021-01-21 18:46:13 +0100422}
423
Pau Espin Pedrolc0a250d2021-01-21 18:46:13 +0100424static void st_wait_resolve_rac_ci(struct osmo_fsm_inst *fi, uint32_t event, void *data)
425{
Pau Espin Pedrol069a6372021-02-10 17:33:13 +0100426 struct nacc_fsm_ctx *ctx = (struct nacc_fsm_ctx *)fi->priv;
Pau Espin Pedrol8e69fc02021-02-10 17:44:27 +0100427 const Packet_Cell_Change_Notification_t *notif;
Pau Espin Pedrol069a6372021-02-10 17:33:13 +0100428
Pau Espin Pedrolc0a250d2021-01-21 18:46:13 +0100429 switch (event) {
430 case NACC_EV_RX_CELL_CHG_NOTIFICATION:
Pau Espin Pedrol8e69fc02021-02-10 17:44:27 +0100431 notif = (const Packet_Cell_Change_Notification_t *)data;
432 handle_retrans_pkt_cell_chg_notif(ctx, notif);
Pau Espin Pedrolc0a250d2021-01-21 18:46:13 +0100433 break;
434 case NACC_EV_RX_RAC_CI:
435 /* Assumption: ctx->cgi_ps has been filled by caller of the event */
436 nacc_fsm_state_chg(fi, NACC_ST_WAIT_REQUEST_SI);
437 break;
438 default:
439 OSMO_ASSERT(0);
440 }
441}
442
443/* At this point, we expect correct tgt cell info to be already in ctx->cgi_ps */
444static void st_wait_request_si_on_enter(struct osmo_fsm_inst *fi, uint32_t prev_state)
445{
446 struct nacc_fsm_ctx *ctx = (struct nacc_fsm_ctx *)fi->priv;
447 struct gprs_rlcmac_bts *bts = ctx->ms->bts;
448 struct gprs_pcu *pcu = bts->pcu;
449 struct bssgp_ran_information_pdu pdu;
450 const struct si_cache_value *si;
Pau Espin Pedrol44768f22021-02-02 13:11:30 +0100451 struct gprs_rlcmac_bts *bts_i;
Pau Espin Pedrolc0a250d2021-01-21 18:46:13 +0100452 int rc;
453
Pau Espin Pedrol44768f22021-02-02 13:11:30 +0100454 /* First check if the CGI-PS addresses a cell managed by this PCU. If
455 * that's the case, we already have the info and there's no need to go
456 * the RIM way since we'd end up to this same PCU on the other end anyway.
457 */
458 llist_for_each_entry(bts_i, &the_pcu->bts_list, list) {
459 if (bts_i == bts) /* Makes no sense targeting the same cell */
460 continue;
461 if (osmo_cgi_ps_cmp(&ctx->cgi_ps, &bts_i->cgi_ps) != 0)
462 continue;
463
464 LOGPFSML(fi, LOGL_DEBUG, "neighbor CGI-PS %s addresses local BTS %d\n",
465 osmo_cgi_ps_name(&ctx->cgi_ps), bts_i->nr);
466 bts_fill_si_cache_value(bts, &ctx->si_info);
467 /* Tell the PCU scheduler we are ready to go, from here one we
468 * are polled/driven by the scheduler */
469 nacc_fsm_state_chg(fi, NACC_ST_TX_NEIGHBOUR_DATA);
470 return;
471 }
472
Pau Espin Pedrolc0a250d2021-01-21 18:46:13 +0100473 /* First check if we have SI info for the target cell in cache */
474 si = si_cache_lookup_value(pcu->si_cache, &ctx->cgi_ps);
475 if (si) {
476 /* Copy info since cache can be deleted at any point */
477 memcpy(&ctx->si_info, si, sizeof(ctx->si_info));
478 /* Tell the PCU scheduler we are ready to go, from here one we
479 * are polled/driven by the scheduler */
480 nacc_fsm_state_chg(fi, NACC_ST_TX_NEIGHBOUR_DATA);
481 return;
482 }
483
484 /* SI info not in cache, resolve it using RIM procedure against SGSN */
485 if (fill_rim_ran_info_req(ctx, &pdu) < 0) {
Pau Espin Pedrola06ac182021-01-26 19:13:43 +0100486 nacc_fsm_state_chg(fi, NACC_ST_TX_CELL_CHG_CONTINUE);
Pau Espin Pedrolc0a250d2021-01-21 18:46:13 +0100487 return;
488 }
489
490 rc = bssgp_tx_rim(&pdu, gprs_ns2_nse_nsei(ctx->ms->bts->nse));
491 if (rc < 0) {
492 LOGPFSML(fi, LOGL_ERROR, "Failed transmitting RIM PDU: %d\n", rc);
Pau Espin Pedrola06ac182021-01-26 19:13:43 +0100493 nacc_fsm_state_chg(fi, NACC_ST_TX_CELL_CHG_CONTINUE);
Pau Espin Pedrolc0a250d2021-01-21 18:46:13 +0100494 return;
495 }
496}
497
498
499static void st_wait_request_si(struct osmo_fsm_inst *fi, uint32_t event, void *data)
500{
501 struct nacc_fsm_ctx *ctx = (struct nacc_fsm_ctx *)fi->priv;
Pau Espin Pedrol8e69fc02021-02-10 17:44:27 +0100502 const Packet_Cell_Change_Notification_t *notif;
Pau Espin Pedrolc0a250d2021-01-21 18:46:13 +0100503 struct si_cache_entry *entry;
504
505 switch (event) {
Pau Espin Pedrol8e69fc02021-02-10 17:44:27 +0100506 case NACC_EV_RX_CELL_CHG_NOTIFICATION:
507 notif = (const Packet_Cell_Change_Notification_t *)data;
508 handle_retrans_pkt_cell_chg_notif(ctx, notif);
509 break;
Pau Espin Pedrolc0a250d2021-01-21 18:46:13 +0100510 case NACC_EV_RX_SI:
511 entry = (struct si_cache_entry *)data;
512 /* Copy info since cache can be deleted at any point */
513 memcpy(&ctx->si_info, &entry->value, sizeof(ctx->si_info));
514 /* Tell the PCU scheduler we are ready to go, from here one we
515 * are polled/driven by the scheduler */
516 nacc_fsm_state_chg(fi, NACC_ST_TX_NEIGHBOUR_DATA);
517 break;
518 default:
519 OSMO_ASSERT(0);
520 }
521}
522
523/* st_tx_neighbour_data_on_enter:
524 * At this point, we already received all required SI information to send stored
525 * in struct nacc_fsm_ctx. We now wait for scheduler to ask us to construct
526 * RLCMAC DL CTRL messages to move FSM states forward
527 */
528
529static void st_tx_neighbour_data(struct osmo_fsm_inst *fi, uint32_t event, void *data)
530{
531 struct nacc_fsm_ctx *ctx = (struct nacc_fsm_ctx *)fi->priv;
532 struct nacc_ev_create_rlcmac_msg_ctx *data_ctx;
533 bool all_si_info_sent;
534
535 switch (event) {
536 case NACC_EV_CREATE_RLCMAC_MSG:
537 data_ctx = (struct nacc_ev_create_rlcmac_msg_ctx *)data;
538 data_ctx->msg = create_packet_neighbour_cell_data(ctx, data_ctx->tbf, &all_si_info_sent);
539 if (!data_ctx->msg) {
540 osmo_fsm_inst_term(fi, OSMO_FSM_TERM_ERROR, NULL);
541 return;
542 }
543 if (all_si_info_sent) /* DONE */
544 nacc_fsm_state_chg(fi, NACC_ST_TX_CELL_CHG_CONTINUE);
545 break;
546 default:
547 OSMO_ASSERT(0);
548 }
549}
550
Pau Espin Pedrol1aef1132021-02-01 19:33:59 +0100551/* st_cell_chg_continue_on_enter:
Pau Espin Pedrolc0a250d2021-01-21 18:46:13 +0100552 * At this point, we already sent all Pkt Cell Neighbour Change rlcmac
553 * blocks, and we only need to wait to be scheduled again to send PKT
554 * CELL CHANGE NOTIFICATION and then we are done
555 */
556
Pau Espin Pedrol1aef1132021-02-01 19:33:59 +0100557static void st_cell_chg_continue(struct osmo_fsm_inst *fi, uint32_t event, void *data)
Pau Espin Pedrolc0a250d2021-01-21 18:46:13 +0100558{
559 struct nacc_fsm_ctx *ctx = (struct nacc_fsm_ctx *)fi->priv;
560 struct nacc_ev_create_rlcmac_msg_ctx *data_ctx;
561
562 switch (event) {
563 case NACC_EV_CREATE_RLCMAC_MSG:
564 data_ctx = (struct nacc_ev_create_rlcmac_msg_ctx *)data;
Pau Espin Pedrol952cb3d2021-02-01 14:52:48 +0100565 data_ctx->msg = create_packet_cell_chg_continue(ctx, data_ctx, &ctx->continue_poll_fn);
566 if (data_ctx->msg) {
567 ctx->continue_poll_ts = data_ctx->ts;
568 nacc_fsm_state_chg(fi, NACC_ST_WAIT_CELL_CHG_CONTINUE_ACK);
569 }
570 break;
571 default:
572 OSMO_ASSERT(0);
573 }
574}
575
576static void st_wait_cell_chg_continue_ack(struct osmo_fsm_inst *fi, uint32_t event, void *data)
577{
578 switch (event) {
579 case NACC_EV_TIMEOUT_CELL_CHG_CONTINUE:
580 nacc_fsm_state_chg(fi, NACC_ST_TX_CELL_CHG_CONTINUE);
581 break;
582 case NACC_EV_RX_CELL_CHG_CONTINUE_ACK:
Pau Espin Pedrolc0a250d2021-01-21 18:46:13 +0100583 nacc_fsm_state_chg(fi, NACC_ST_DONE);
584 break;
585 default:
586 OSMO_ASSERT(0);
587 }
588}
589
590
591static void st_done_on_enter(struct osmo_fsm_inst *fi, uint32_t prev_state)
592{
593 osmo_fsm_inst_term(fi, OSMO_FSM_TERM_REGULAR, NULL);
594}
595
596static void nacc_fsm_cleanup(struct osmo_fsm_inst *fi, enum osmo_fsm_term_cause cause)
597{
598 struct nacc_fsm_ctx *ctx = (struct nacc_fsm_ctx *)fi->priv;
599 /* after cleanup() finishes, FSM termination calls osmo_fsm_inst_free,
600 so we need to avoid double-freeing it during ctx talloc free
601 destructor */
602 talloc_reparent(ctx, ctx->ms, ctx->fi);
603 ctx->fi = NULL;
604
605 /* remove references from owning MS and free entire ctx */
606 ctx->ms->nacc = NULL;
607 talloc_free(ctx);
608}
609
Pau Espin Pedrol41a22a72021-01-26 19:00:37 +0100610static int nacc_fsm_timer_cb(struct osmo_fsm_inst *fi)
611{
612 switch (fi->T) {
613 case PCU_TDEF_NEIGH_RESOLVE_TO:
614 case PCU_TDEF_SI_RESOLVE_TO:
615 nacc_fsm_state_chg(fi, NACC_ST_TX_CELL_CHG_CONTINUE);
616 break;
617 }
618 return 0;
619}
620
Pau Espin Pedrolc0a250d2021-01-21 18:46:13 +0100621static struct osmo_fsm_state nacc_fsm_states[] = {
622 [NACC_ST_INITIAL] = {
623 .in_event_mask =
624 X(NACC_EV_RX_CELL_CHG_NOTIFICATION),
625 .out_state_mask =
626 X(NACC_ST_WAIT_RESOLVE_RAC_CI),
627 .name = "INITIAL",
628 .action = st_initial,
629 },
630 [NACC_ST_WAIT_RESOLVE_RAC_CI] = {
631 .in_event_mask =
Pau Espin Pedrol069a6372021-02-10 17:33:13 +0100632 X(NACC_EV_RX_CELL_CHG_NOTIFICATION) |
Pau Espin Pedrolc0a250d2021-01-21 18:46:13 +0100633 X(NACC_EV_RX_RAC_CI),
634 .out_state_mask =
Pau Espin Pedrol069a6372021-02-10 17:33:13 +0100635 X(NACC_ST_WAIT_RESOLVE_RAC_CI) |
Pau Espin Pedrol41a22a72021-01-26 19:00:37 +0100636 X(NACC_ST_WAIT_REQUEST_SI) |
637 X(NACC_ST_TX_CELL_CHG_CONTINUE),
Pau Espin Pedrolc0a250d2021-01-21 18:46:13 +0100638 .name = "WAIT_RESOLVE_RAC_CI",
639 .onenter = st_wait_resolve_rac_ci_on_enter,
640 .action = st_wait_resolve_rac_ci,
641 },
642 [NACC_ST_WAIT_REQUEST_SI] = {
643 .in_event_mask =
644 X(NACC_EV_RX_CELL_CHG_NOTIFICATION) |
645 X(NACC_EV_RX_SI),
646 .out_state_mask =
Pau Espin Pedrol8e69fc02021-02-10 17:44:27 +0100647 X(NACC_ST_WAIT_RESOLVE_RAC_CI) |
Pau Espin Pedrol41a22a72021-01-26 19:00:37 +0100648 X(NACC_ST_TX_NEIGHBOUR_DATA) |
649 X(NACC_ST_TX_CELL_CHG_CONTINUE),
Pau Espin Pedrolc0a250d2021-01-21 18:46:13 +0100650 .name = "WAIT_REQUEST_SI",
651 .onenter = st_wait_request_si_on_enter,
652 .action = st_wait_request_si,
653 },
654 [NACC_ST_TX_NEIGHBOUR_DATA] = {
655 .in_event_mask =
656 X(NACC_EV_RX_CELL_CHG_NOTIFICATION) |
Pau Espin Pedrolc0a250d2021-01-21 18:46:13 +0100657 X(NACC_EV_CREATE_RLCMAC_MSG),
658 .out_state_mask =
659 X(NACC_ST_TX_CELL_CHG_CONTINUE),
660 .name = "TX_NEIGHBOUR_DATA",
661 .action = st_tx_neighbour_data,
662 },
663 [NACC_ST_TX_CELL_CHG_CONTINUE] = {
664 .in_event_mask =
665 X(NACC_EV_RX_CELL_CHG_NOTIFICATION) |
Pau Espin Pedrolc0a250d2021-01-21 18:46:13 +0100666 X(NACC_EV_CREATE_RLCMAC_MSG),
667 .out_state_mask =
Pau Espin Pedrol952cb3d2021-02-01 14:52:48 +0100668 X(NACC_ST_WAIT_CELL_CHG_CONTINUE_ACK),
Pau Espin Pedrolc0a250d2021-01-21 18:46:13 +0100669 .name = "TX_CELL_CHG_CONTINUE",
Pau Espin Pedrol1aef1132021-02-01 19:33:59 +0100670 .action = st_cell_chg_continue,
Pau Espin Pedrolc0a250d2021-01-21 18:46:13 +0100671 },
Pau Espin Pedrol952cb3d2021-02-01 14:52:48 +0100672 [NACC_ST_WAIT_CELL_CHG_CONTINUE_ACK] = {
673 .in_event_mask =
674 X(NACC_EV_RX_CELL_CHG_CONTINUE_ACK) |
675 X(NACC_EV_TIMEOUT_CELL_CHG_CONTINUE),
676 .out_state_mask =
677 X(NACC_ST_TX_CELL_CHG_CONTINUE) |
678 X(NACC_ST_DONE),
679 .name = "WAIT_CELL_CHG_CONTINUE_ACK",
680 .action = st_wait_cell_chg_continue_ack,
681 },
Pau Espin Pedrolc0a250d2021-01-21 18:46:13 +0100682 [NACC_ST_DONE] = {
683 .in_event_mask = 0,
684 .out_state_mask = 0,
685 .name = "DONE",
686 .onenter = st_done_on_enter,
687 },
688};
689
690static struct osmo_fsm nacc_fsm = {
691 .name = "NACC",
692 .states = nacc_fsm_states,
693 .num_states = ARRAY_SIZE(nacc_fsm_states),
Pau Espin Pedrol41a22a72021-01-26 19:00:37 +0100694 .timer_cb = nacc_fsm_timer_cb,
Pau Espin Pedrolc0a250d2021-01-21 18:46:13 +0100695 .cleanup = nacc_fsm_cleanup,
696 .log_subsys = DNACC,
697 .event_names = nacc_fsm_event_names,
698};
699
700static __attribute__((constructor)) void nacc_fsm_init(void)
701{
702 OSMO_ASSERT(osmo_fsm_register(&nacc_fsm) == 0);
703}
704
705void nacc_fsm_ctrl_reply_cb(struct ctrl_handle *ctrl, struct ctrl_cmd *cmd, void *data)
706{
707 struct nacc_fsm_ctx *ctx = (struct nacc_fsm_ctx *)data;
708 char *tmp = NULL, *tok, *saveptr;
Pau Espin Pedrol069a6372021-02-10 17:33:13 +0100709 unsigned int exp_id;
Pau Espin Pedrolc0a250d2021-01-21 18:46:13 +0100710
Pau Espin Pedrol069a6372021-02-10 17:33:13 +0100711 LOGPFSML(ctx->fi, LOGL_NOTICE, "Received CTRL message: type=%d %s %s: %s\n",
712 cmd->type, cmd->variable, cmd->id, osmo_escape_str(cmd->reply, -1));
Pau Espin Pedrolc0a250d2021-01-21 18:46:13 +0100713
714 if (cmd->type != CTRL_TYPE_GET_REPLY || !cmd->reply) {
Pau Espin Pedrola06ac182021-01-26 19:13:43 +0100715 nacc_fsm_state_chg(ctx->fi, NACC_ST_TX_CELL_CHG_CONTINUE);
Pau Espin Pedrolc0a250d2021-01-21 18:46:13 +0100716 return;
717 }
718
Pau Espin Pedrol069a6372021-02-10 17:33:13 +0100719 /* Validate it's the seqnum from our last GET cmd, and not from older
720 * one we may have requested in case MS decided to resend Pkt Cell
721 * Change Notify with a different tgt cell:
722 */
723 exp_id = arfcn_bsic_2_ctrl_id(ctx->neigh_key.tgt_arfcn, ctx->neigh_key.tgt_bsic);
724 if ((unsigned int)atoi(cmd->id) != exp_id) {
725 LOGPFSML(ctx->fi, LOGL_INFO,
726 "Received CTRL message with id=%s doesn't match our expected last id=%d, ignoring\n",
727 cmd->id, exp_id);
728 return;
729 }
730
Pau Espin Pedrolc0a250d2021-01-21 18:46:13 +0100731 /* TODO: Potentially validate cmd->variable contains same params as we
732 sent, and that cmd->id matches the original set. We may want to keep
733 the original cmd around by setting cmd->defer=1 when sending it. */
734
735 tmp = talloc_strdup(cmd, cmd->reply);
736 if (!tmp)
737 goto free_ret;
738
739 if (!(tok = strtok_r(tmp, "-", &saveptr)))
740 goto free_ret;
741 ctx->cgi_ps.rai.lac.plmn.mcc = atoi(tok);
742
743 if (!(tok = strtok_r(NULL, "-", &saveptr)))
744 goto free_ret;
745 ctx->cgi_ps.rai.lac.plmn.mnc = atoi(tok);
746
747 if (!(tok = strtok_r(NULL, "-", &saveptr)))
748 goto free_ret;
749 ctx->cgi_ps.rai.lac.lac = atoi(tok);
750
751 if (!(tok = strtok_r(NULL, "-", &saveptr)))
752 goto free_ret;
753 ctx->cgi_ps.rai.rac = atoi(tok);
754
755 if (!(tok = strtok_r(NULL, "\0", &saveptr)))
756 goto free_ret;
757 ctx->cgi_ps.cell_identity = atoi(tok);
758
759 /* Cache the cgi_ps so we can avoid requesting again same resolution for a while */
760 neigh_cache_add(ctx->ms->bts->pcu->neigh_cache, &ctx->neigh_key, &ctx->cgi_ps);
761
762 osmo_fsm_inst_dispatch(ctx->fi, NACC_EV_RX_RAC_CI, NULL);
763 return;
764
765free_ret:
766 talloc_free(tmp);
Pau Espin Pedrola06ac182021-01-26 19:13:43 +0100767 nacc_fsm_state_chg(ctx->fi, NACC_ST_TX_CELL_CHG_CONTINUE);
Pau Espin Pedrolc0a250d2021-01-21 18:46:13 +0100768 return;
769}
770
771static int nacc_fsm_ctx_talloc_destructor(struct nacc_fsm_ctx *ctx)
772{
773 if (ctx->fi) {
774 osmo_fsm_inst_free(ctx->fi);
775 ctx->fi = NULL;
776 }
777
778 if (ctx->neigh_ctrl_conn) {
779 if (ctx->neigh_ctrl_conn->write_queue.bfd.fd != -1) {
780 osmo_wqueue_clear(&ctx->neigh_ctrl_conn->write_queue);
781 osmo_fd_unregister(&ctx->neigh_ctrl_conn->write_queue.bfd);
782 close(ctx->neigh_ctrl_conn->write_queue.bfd.fd);
783 ctx->neigh_ctrl_conn->write_queue.bfd.fd = -1;
784 }
785 }
786
787 return 0;
788}
789
790struct nacc_fsm_ctx *nacc_fsm_alloc(struct GprsMs* ms)
791{
Pau Espin Pedrolc0a250d2021-01-21 18:46:13 +0100792 struct nacc_fsm_ctx *ctx = talloc_zero(ms, struct nacc_fsm_ctx);
793 char buf[64];
Pau Espin Pedrolc0a250d2021-01-21 18:46:13 +0100794
795 talloc_set_destructor(ctx, nacc_fsm_ctx_talloc_destructor);
796
797 ctx->ms = ms;
798
799 snprintf(buf, sizeof(buf), "TLLI-0x%08x", ms_tlli(ms));
800 ctx->fi = osmo_fsm_inst_alloc(&nacc_fsm, ctx, ctx, LOGL_INFO, buf);
801 if (!ctx->fi)
802 goto free_ret;
803
804 ctx->neigh_ctrl = ctrl_handle_alloc(ctx, ctx, NULL);
805 ctx->neigh_ctrl->reply_cb = nacc_fsm_ctrl_reply_cb;
806 ctx->neigh_ctrl_conn = osmo_ctrl_conn_alloc(ctx, ctx->neigh_ctrl);
807 if (!ctx->neigh_ctrl_conn)
808 goto free_ret;
Pau Espin Pedrol202a4782021-01-27 17:05:12 +0100809 /* Older versions of osmo_ctrl_conn_alloc didn't properly initialize fd to -1,
810 * so make sure to do it here otherwise fd may be valid fd 0 and cause trouble */
811 ctx->neigh_ctrl_conn->write_queue.bfd.fd = -1;
Pau Espin Pedrolc0a250d2021-01-21 18:46:13 +0100812 llist_add(&ctx->neigh_ctrl_conn->list_entry, &ctx->neigh_ctrl->ccon_list);
813
Pau Espin Pedrolc0a250d2021-01-21 18:46:13 +0100814 return ctx;
815free_ret:
816 talloc_free(ctx);
817 return NULL;
818}