blob: f7408ef97239d0304d7b035f396fae24a20f6f2b [file] [log] [blame]
Harald Welte9b455bf2010-03-14 15:45:01 +08001/* GPRS LLC protocol implementation as per 3GPP TS 04.64 */
2
Harald Weltea2665542010-05-02 09:28:11 +02003/* (C) 2009-2010 by Harald Welte <laforge@gnumonks.org>
Harald Welte9b455bf2010-03-14 15:45:01 +08004 *
5 * All Rights Reserved
6 *
7 * This program is free software; you can redistribute it and/or modify
Harald Welte9af6ddf2011-01-01 15:25:50 +01008 * it under the terms of the GNU Affero General Public License as published by
9 * the Free Software Foundation; either version 3 of the License, or
Harald Welte9b455bf2010-03-14 15:45:01 +080010 * (at your option) any later version.
11 *
12 * This program is distributed in the hope that it will be useful,
13 * but WITHOUT ANY WARRANTY; without even the implied warranty of
14 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
Harald Welte9af6ddf2011-01-01 15:25:50 +010015 * GNU Affero General Public License for more details.
Harald Welte9b455bf2010-03-14 15:45:01 +080016 *
Harald Welte9af6ddf2011-01-01 15:25:50 +010017 * You should have received a copy of the GNU Affero General Public License
18 * along with this program. If not, see <http://www.gnu.org/licenses/>.
Harald Welte9b455bf2010-03-14 15:45:01 +080019 *
20 */
21
22#include <errno.h>
Harald Welteeaa614c2010-05-02 11:26:34 +020023#include <stdint.h>
Harald Welte9b455bf2010-03-14 15:45:01 +080024
Pablo Neira Ayuso136f4532011-03-22 16:47:59 +010025#include <osmocom/core/msgb.h>
26#include <osmocom/core/linuxlist.h>
27#include <osmocom/core/timer.h>
28#include <osmocom/core/talloc.h>
Harald Weltea2665542010-05-02 09:28:11 +020029
30#include <openbsc/gsm_data.h>
31#include <openbsc/debug.h>
Harald Welte807a5d82010-06-01 11:53:01 +020032#include <openbsc/gprs_sgsn.h>
33#include <openbsc/gprs_gmm.h>
Harald Welte9b455bf2010-03-14 15:45:01 +080034#include <openbsc/gprs_bssgp.h>
35#include <openbsc/gprs_llc.h>
36#include <openbsc/crc24.h>
37
Harald Welte1d9d9442010-06-03 07:11:04 +020038/* Section 8.9.9 LLC layer parameter default values */
39static const struct gprs_llc_params llc_default_params[] = {
40 [1] = {
41 .t200_201 = 5,
42 .n200 = 3,
43 .n201_u = 400,
44 },
45 [2] = {
46 .t200_201 = 5,
47 .n200 = 3,
48 .n201_u = 270,
49 },
50 [3] = {
51 .iov_i_exp = 27,
52 .t200_201 = 5,
53 .n200 = 3,
54 .n201_u = 500,
55 .n201_i = 1503,
56 .mD = 1520,
57 .mU = 1520,
58 .kD = 16,
59 .kU = 16,
60 },
61 [5] = {
62 .iov_i_exp = 27,
63 .t200_201 = 10,
64 .n200 = 3,
65 .n201_u = 500,
66 .n201_i = 1503,
67 .mD = 760,
68 .mU = 760,
69 .kD = 8,
70 .kU = 8,
71 },
72 [7] = {
73 .t200_201 = 20,
74 .n200 = 3,
75 .n201_u = 270,
76 },
77 [8] = {
78 .t200_201 = 20,
79 .n200 = 3,
80 .n201_u = 270,
81 },
82 [9] = {
83 .iov_i_exp = 27,
84 .t200_201 = 20,
85 .n200 = 3,
86 .n201_u = 500,
87 .n201_i = 1503,
88 .mD = 380,
89 .mU = 380,
90 .kD = 4,
91 .kU = 4,
92 },
93 [11] = {
94 .iov_i_exp = 27,
95 .t200_201 = 40,
96 .n200 = 3,
97 .n201_u = 500,
98 .n201_i = 1503,
99 .mD = 190,
100 .mU = 190,
101 .kD = 2,
102 .kU = 2,
103 },
104};
105
Harald Welte807a5d82010-06-01 11:53:01 +0200106LLIST_HEAD(gprs_llc_llmes);
Harald Weltea2665542010-05-02 09:28:11 +0200107void *llc_tall_ctx;
108
Harald Weltef0901f02010-12-26 10:39:26 +0100109/* If the TLLI is foreign, return its local version */
110static inline uint32_t tlli_foreign2local(uint32_t tlli)
111{
112 uint32_t new_tlli;
113
114 if (gprs_tlli_type(tlli) == TLLI_FOREIGN) {
115 new_tlli = tlli | 0x40000000;
116 DEBUGP(DLLC, "TLLI 0x%08x is foreign, converting to "
117 "local TLLI 0x%08x\n", tlli, new_tlli);
118 } else
119 new_tlli = tlli;
120
121 return new_tlli;
122}
123
Harald Weltea2665542010-05-02 09:28:11 +0200124/* lookup LLC Entity based on DLCI (TLLI+SAPI tuple) */
Harald Welte1d9d9442010-06-03 07:11:04 +0200125static struct gprs_llc_lle *lle_by_tlli_sapi(uint32_t tlli, uint8_t sapi)
Harald Weltea2665542010-05-02 09:28:11 +0200126{
Harald Welte807a5d82010-06-01 11:53:01 +0200127 struct gprs_llc_llme *llme;
Harald Weltea2665542010-05-02 09:28:11 +0200128
Harald Weltef0901f02010-12-26 10:39:26 +0100129 tlli = tlli_foreign2local(tlli);
130
Harald Welte807a5d82010-06-01 11:53:01 +0200131 llist_for_each_entry(llme, &gprs_llc_llmes, list) {
132 if (llme->tlli == tlli || llme->old_tlli == tlli)
133 return &llme->lle[sapi];
Harald Weltea2665542010-05-02 09:28:11 +0200134 }
135 return NULL;
136}
137
Harald Welte1d9d9442010-06-03 07:11:04 +0200138static void lle_init(struct gprs_llc_llme *llme, uint8_t sapi)
Harald Weltea2665542010-05-02 09:28:11 +0200139{
Harald Welte807a5d82010-06-01 11:53:01 +0200140 struct gprs_llc_lle *lle = &llme->lle[sapi];
Harald Weltea2665542010-05-02 09:28:11 +0200141
Harald Welte807a5d82010-06-01 11:53:01 +0200142 lle->llme = llme;
143 lle->sapi = sapi;
144 lle->state = GPRS_LLES_UNASSIGNED;
145
Harald Welte1d9d9442010-06-03 07:11:04 +0200146 /* Initialize according to parameters */
147 memcpy(&lle->params, &llc_default_params[sapi], sizeof(lle->params));
Harald Welte807a5d82010-06-01 11:53:01 +0200148}
149
150static struct gprs_llc_llme *llme_alloc(uint32_t tlli)
151{
152 struct gprs_llc_llme *llme;
153 uint32_t i;
154
155 llme = talloc_zero(llc_tall_ctx, struct gprs_llc_llme);
156 if (!llme)
Harald Weltea2665542010-05-02 09:28:11 +0200157 return NULL;
158
Harald Welte807a5d82010-06-01 11:53:01 +0200159 llme->tlli = tlli;
Harald Welte875840c2010-07-01 11:54:31 +0200160 llme->old_tlli = 0xffffffff;
Harald Welte807a5d82010-06-01 11:53:01 +0200161 llme->state = GPRS_LLMS_UNASSIGNED;
Harald Weltea2665542010-05-02 09:28:11 +0200162
Harald Welte807a5d82010-06-01 11:53:01 +0200163 for (i = 0; i < ARRAY_SIZE(llme->lle); i++)
164 lle_init(llme, i);
165
166 llist_add(&llme->list, &gprs_llc_llmes);
167
168 return llme;
Harald Weltea2665542010-05-02 09:28:11 +0200169}
170
Harald Weltef7fef482010-06-28 22:18:26 +0200171static void llme_free(struct gprs_llc_llme *llme)
172{
173 llist_del(&llme->list);
174 talloc_free(llme);
175}
176
Harald Welte9b455bf2010-03-14 15:45:01 +0800177enum gprs_llc_cmd {
178 GPRS_LLC_NULL,
179 GPRS_LLC_RR,
180 GPRS_LLC_ACK,
181 GPRS_LLC_RNR,
182 GPRS_LLC_SACK,
183 GPRS_LLC_DM,
184 GPRS_LLC_DISC,
185 GPRS_LLC_UA,
186 GPRS_LLC_SABM,
187 GPRS_LLC_FRMR,
188 GPRS_LLC_XID,
Harald Welte1ae09c72010-05-13 19:22:55 +0200189 GPRS_LLC_UI,
Harald Welte9b455bf2010-03-14 15:45:01 +0800190};
191
Harald Welteb61f4032010-05-18 12:31:50 +0200192static const struct value_string llc_cmd_strs[] = {
193 { GPRS_LLC_NULL, "NULL" },
194 { GPRS_LLC_RR, "RR" },
195 { GPRS_LLC_ACK, "ACK" },
196 { GPRS_LLC_RNR, "RNR" },
197 { GPRS_LLC_SACK, "SACK" },
198 { GPRS_LLC_DM, "DM" },
199 { GPRS_LLC_DISC, "DISC" },
200 { GPRS_LLC_UA, "UA" },
201 { GPRS_LLC_SABM, "SABM" },
202 { GPRS_LLC_FRMR, "FRMR" },
203 { GPRS_LLC_XID, "XID" },
204 { GPRS_LLC_UI, "UI" },
205 { 0, NULL }
206};
207
Harald Welte9b455bf2010-03-14 15:45:01 +0800208struct gprs_llc_hdr_parsed {
Harald Welteeaa614c2010-05-02 11:26:34 +0200209 uint8_t sapi;
210 uint8_t is_cmd:1,
Harald Welte9b455bf2010-03-14 15:45:01 +0800211 ack_req:1,
212 is_encrypted:1;
Harald Welteeaa614c2010-05-02 11:26:34 +0200213 uint32_t seq_rx;
214 uint32_t seq_tx;
215 uint32_t fcs;
216 uint32_t fcs_calc;
217 uint8_t *data;
Harald Welte5658a1a2010-05-03 13:25:07 +0200218 uint16_t data_len;
Harald Welte1b8827a2010-06-30 23:15:57 +0200219 uint16_t crc_length;
Harald Welte9b455bf2010-03-14 15:45:01 +0800220 enum gprs_llc_cmd cmd;
221};
222
223#define LLC_ALLOC_SIZE 16384
224#define UI_HDR_LEN 3
225#define N202 4
226#define CRC24_LENGTH 3
227
Harald Welteeaa614c2010-05-02 11:26:34 +0200228static int gprs_llc_fcs(uint8_t *data, unsigned int len)
Harald Welte9b455bf2010-03-14 15:45:01 +0800229{
Harald Welteeaa614c2010-05-02 11:26:34 +0200230 uint32_t fcs_calc;
Harald Welte9b455bf2010-03-14 15:45:01 +0800231
232 fcs_calc = crc24_calc(INIT_CRC24, data, len);
233 fcs_calc = ~fcs_calc;
234 fcs_calc &= 0xffffff;
235
236 return fcs_calc;
237}
238
Harald Welte9b455bf2010-03-14 15:45:01 +0800239static void t200_expired(void *data)
240{
241 struct gprs_llc_lle *lle = data;
242
243 /* 8.5.1.3: Expiry of T200 */
244
Harald Welte1d9d9442010-06-03 07:11:04 +0200245 if (lle->retrans_ctr >= lle->params.n200) {
Harald Welte9b455bf2010-03-14 15:45:01 +0800246 /* FIXME: LLGM-STATUS-IND, LL-RELEASE-IND/CNF */
Harald Welte807a5d82010-06-01 11:53:01 +0200247 lle->state = GPRS_LLES_ASSIGNED_ADM;
Harald Welte9b455bf2010-03-14 15:45:01 +0800248 }
249
250 switch (lle->state) {
Harald Welte807a5d82010-06-01 11:53:01 +0200251 case GPRS_LLES_LOCAL_EST:
Harald Welte1ae09c72010-05-13 19:22:55 +0200252 /* FIXME: retransmit SABM */
253 /* FIXME: re-start T200 */
Harald Welte9b455bf2010-03-14 15:45:01 +0800254 lle->retrans_ctr++;
255 break;
Harald Welte807a5d82010-06-01 11:53:01 +0200256 case GPRS_LLES_LOCAL_REL:
Harald Welte1ae09c72010-05-13 19:22:55 +0200257 /* FIXME: retransmit DISC */
258 /* FIXME: re-start T200 */
Harald Welte9b455bf2010-03-14 15:45:01 +0800259 lle->retrans_ctr++;
260 break;
261 }
262
263}
264
265static void t201_expired(void *data)
266{
267 struct gprs_llc_lle *lle = data;
268
Harald Welte1d9d9442010-06-03 07:11:04 +0200269 if (lle->retrans_ctr < lle->params.n200) {
Harald Welte1ae09c72010-05-13 19:22:55 +0200270 /* FIXME: transmit apropriate supervisory frame (8.6.4.1) */
271 /* FIXME: set timer T201 */
Harald Welte9b455bf2010-03-14 15:45:01 +0800272 lle->retrans_ctr++;
273 }
274}
275
Harald Welte10997d02010-05-03 12:28:12 +0200276int gprs_llc_tx_u(struct msgb *msg, uint8_t sapi, int command,
277 enum gprs_llc_u_cmd u_cmd, int pf_bit)
278{
279 uint8_t *fcs, *llch;
280 uint8_t addr, ctrl;
281 uint32_t fcs_calc;
282
283 /* Identifiers from UP: (TLLI, SAPI) + (BVCI, NSEI) */
284
285 /* Address Field */
286 addr = sapi & 0xf;
287 if (command)
288 addr |= 0x40;
289
290 /* 6.3 Figure 8 */
291 ctrl = 0xe0 | u_cmd;
292 if (pf_bit)
293 ctrl |= 0x10;
294
295 /* prepend LLC UI header */
296 llch = msgb_push(msg, 2);
297 llch[0] = addr;
298 llch[1] = ctrl;
299
300 /* append FCS to end of frame */
301 fcs = msgb_put(msg, 3);
302 fcs_calc = gprs_llc_fcs(llch, fcs - llch);
303 fcs[0] = fcs_calc & 0xff;
304 fcs[1] = (fcs_calc >> 8) & 0xff;
305 fcs[2] = (fcs_calc >> 16) & 0xff;
306
307 /* Identifiers passed down: (BVCI, NSEI) */
308
Harald Welte1ae09c72010-05-13 19:22:55 +0200309 /* Send BSSGP-DL-UNITDATA.req */
Harald Welte56a01452010-05-31 22:12:30 +0200310 return gprs_bssgp_tx_dl_ud(msg, NULL);
Harald Welte10997d02010-05-03 12:28:12 +0200311}
312
313/* Send XID response to LLE */
314static int gprs_llc_tx_xid(struct gprs_llc_lle *lle, struct msgb *msg)
315{
316 /* copy identifiers from LLE to ensure lower layers can route */
Harald Welte807a5d82010-06-01 11:53:01 +0200317 msgb_tlli(msg) = lle->llme->tlli;
318 msgb_bvci(msg) = lle->llme->bvci;
319 msgb_nsei(msg) = lle->llme->nsei;
Harald Welte10997d02010-05-03 12:28:12 +0200320
321 return gprs_llc_tx_u(msg, lle->sapi, 0, GPRS_LLC_U_XID, 1);
322}
323
Harald Welte9b455bf2010-03-14 15:45:01 +0800324/* Transmit a UI frame over the given SAPI */
Harald Welte56a01452010-05-31 22:12:30 +0200325int gprs_llc_tx_ui(struct msgb *msg, uint8_t sapi, int command,
326 void *mmctx)
Harald Welte9b455bf2010-03-14 15:45:01 +0800327{
Harald Weltee6afd602010-05-02 11:19:37 +0200328 struct gprs_llc_lle *lle;
Harald Welteeaa614c2010-05-02 11:26:34 +0200329 uint8_t *fcs, *llch;
330 uint8_t addr, ctrl[2];
331 uint32_t fcs_calc;
332 uint16_t nu = 0;
Harald Welted07b4f92010-06-30 23:07:59 +0200333 uint32_t oc;
Harald Welte9b455bf2010-03-14 15:45:01 +0800334
Harald Weltee6afd602010-05-02 11:19:37 +0200335 /* Identifiers from UP: (TLLI, SAPI) + (BVCI, NSEI) */
336
337 /* look-up or create the LL Entity for this (TLLI, SAPI) tuple */
338 lle = lle_by_tlli_sapi(msgb_tlli(msg), sapi);
Harald Welte807a5d82010-06-01 11:53:01 +0200339 if (!lle) {
340 struct gprs_llc_llme *llme;
Harald Weltef0901f02010-12-26 10:39:26 +0100341 LOGP(DLLC, LOGL_ERROR, "LLC TX: unknown TLLI 0x%08x, "
342 "creating LLME on the fly\n", msgb_tlli(msg));
Harald Welte807a5d82010-06-01 11:53:01 +0200343 llme = llme_alloc(msgb_tlli(msg));
344 lle = &llme->lle[sapi];
345 }
Harald Welte1d9d9442010-06-03 07:11:04 +0200346
347 if (msg->len > lle->params.n201_u) {
348 LOGP(DLLC, LOGL_ERROR, "Cannot Tx %u bytes (N201-U=%u)\n",
349 msg->len, lle->params.n201_u);
350 return -EFBIG;
351 }
352
Harald Weltee6afd602010-05-02 11:19:37 +0200353 /* Update LLE's (BVCI, NSEI) tuple */
Harald Welte807a5d82010-06-01 11:53:01 +0200354 lle->llme->bvci = msgb_bvci(msg);
355 lle->llme->nsei = msgb_nsei(msg);
Harald Weltee6afd602010-05-02 11:19:37 +0200356
Harald Welted07b4f92010-06-30 23:07:59 +0200357 /* Obtain current values for N(u) and OC */
Harald Welte6bdee6a2010-05-30 21:51:58 +0200358 nu = lle->vu_send;
Harald Welted07b4f92010-06-30 23:07:59 +0200359 oc = lle->oc_ui_send;
360 /* Increment V(U) */
Harald Welte6bdee6a2010-05-30 21:51:58 +0200361 lle->vu_send = (lle->vu_send + 1) % 512;
Harald Welted07b4f92010-06-30 23:07:59 +0200362 /* Increment Overflow Counter, if needed */
363 if ((lle->vu_send + 1) / 512)
364 lle->oc_ui_send += 512;
Harald Welte6bdee6a2010-05-30 21:51:58 +0200365
Harald Welte9b455bf2010-03-14 15:45:01 +0800366 /* Address Field */
367 addr = sapi & 0xf;
368 if (command)
369 addr |= 0x40;
370
371 /* Control Field */
372 ctrl[0] = 0xc0;
373 ctrl[0] |= nu >> 6;
374 ctrl[1] = (nu << 2) & 0xfc;
375 ctrl[1] |= 0x01; /* Protected Mode */
376
377 /* prepend LLC UI header */
378 llch = msgb_push(msg, 3);
379 llch[0] = addr;
380 llch[1] = ctrl[0];
381 llch[2] = ctrl[1];
382
383 /* append FCS to end of frame */
384 fcs = msgb_put(msg, 3);
385 fcs_calc = gprs_llc_fcs(llch, fcs - llch);
386 fcs[0] = fcs_calc & 0xff;
387 fcs[1] = (fcs_calc >> 8) & 0xff;
388 fcs[2] = (fcs_calc >> 16) & 0xff;
389
Harald Welted07b4f92010-06-30 23:07:59 +0200390 /* encrypt information field + FCS, if needed! */
391 if (lle->llme->algo != GPRS_ALGO_GEA0) {
392 uint32_t iov_ui = 0; /* FIXME: randomly select for TLLI */
393 uint16_t crypt_len = (fcs + 3) - (llch + 3);
394 uint8_t cipher_out[GSM0464_CIPH_MAX_BLOCK];
395 uint32_t iv;
396 int rc, i;
397 uint64_t kc = *(uint64_t *)&lle->llme->kc;
398
399 /* Compute the 'Input' Paraemeter */
400 iv = gprs_cipher_gen_input_ui(iov_ui, sapi, nu, oc);
401
402 /* Compute the keystream that we need to XOR with the data */
403 rc = gprs_cipher_run(cipher_out, crypt_len, lle->llme->algo,
404 kc, iv, GPRS_CIPH_SGSN2MS);
405 if (rc < 0) {
406 LOGP(DLLC, LOGL_ERROR, "Error crypting UI frame: %d\n", rc);
407 return rc;
408 }
409
410 /* XOR the cipher output with the information field + FCS */
411 for (i = 0; i < crypt_len; i++)
412 *(llch + 3 + i) ^= cipher_out[i];
413
414 /* Mark frame as encrypted */
415 ctrl[1] |= 0x02;
416 }
417
Harald Weltee6afd602010-05-02 11:19:37 +0200418 /* Identifiers passed down: (BVCI, NSEI) */
419
Harald Welte1ae09c72010-05-13 19:22:55 +0200420 /* Send BSSGP-DL-UNITDATA.req */
Harald Welte56a01452010-05-31 22:12:30 +0200421 return gprs_bssgp_tx_dl_ud(msg, mmctx);
Harald Welte9b455bf2010-03-14 15:45:01 +0800422}
423
Holger Hans Peter Freyther3a6fdcd2010-05-23 21:35:25 +0800424static void gprs_llc_hdr_dump(struct gprs_llc_hdr_parsed *gph)
Harald Welte9b455bf2010-03-14 15:45:01 +0800425{
Sylvain Munaut6f3850f2010-07-03 22:03:02 +0200426 DEBUGP(DLLC, "LLC SAPI=%u %c %c FCS=0x%06x",
Harald Welte9b455bf2010-03-14 15:45:01 +0800427 gph->sapi, gph->is_cmd ? 'C' : 'R', gph->ack_req ? 'A' : ' ',
Sylvain Munaut6f3850f2010-07-03 22:03:02 +0200428 gph->fcs);
Harald Welte9b455bf2010-03-14 15:45:01 +0800429
430 if (gph->cmd)
Harald Welteb61f4032010-05-18 12:31:50 +0200431 DEBUGPC(DLLC, "CMD=%s ", get_value_string(llc_cmd_strs, gph->cmd));
Harald Welte9b455bf2010-03-14 15:45:01 +0800432
433 if (gph->data)
Harald Weltec6ecafe2010-05-13 19:47:50 +0200434 DEBUGPC(DLLC, "DATA ");
Harald Welte9b455bf2010-03-14 15:45:01 +0800435
Harald Weltec6ecafe2010-05-13 19:47:50 +0200436 DEBUGPC(DLLC, "\n");
Harald Welte9b455bf2010-03-14 15:45:01 +0800437}
438static int gprs_llc_hdr_rx(struct gprs_llc_hdr_parsed *gph,
439 struct gprs_llc_lle *lle)
440{
441 switch (gph->cmd) {
442 case GPRS_LLC_SABM: /* Section 6.4.1.1 */
443 lle->v_sent = lle->v_ack = lle->v_recv = 0;
Harald Welte807a5d82010-06-01 11:53:01 +0200444 if (lle->state == GPRS_LLES_ASSIGNED_ADM) {
Harald Welte9b455bf2010-03-14 15:45:01 +0800445 /* start re-establishment (8.7.1) */
446 }
Harald Welte807a5d82010-06-01 11:53:01 +0200447 lle->state = GPRS_LLES_REMOTE_EST;
Harald Welte9b455bf2010-03-14 15:45:01 +0800448 /* FIXME: Send UA */
Harald Welte807a5d82010-06-01 11:53:01 +0200449 lle->state = GPRS_LLES_ABM;
Harald Welte9b455bf2010-03-14 15:45:01 +0800450 /* FIXME: process data */
451 break;
452 case GPRS_LLC_DISC: /* Section 6.4.1.2 */
453 /* FIXME: Send UA */
454 /* terminate ABM */
Harald Welte807a5d82010-06-01 11:53:01 +0200455 lle->state = GPRS_LLES_ASSIGNED_ADM;
Harald Welte9b455bf2010-03-14 15:45:01 +0800456 break;
457 case GPRS_LLC_UA: /* Section 6.4.1.3 */
Harald Welte807a5d82010-06-01 11:53:01 +0200458 if (lle->state == GPRS_LLES_LOCAL_EST)
459 lle->state = GPRS_LLES_ABM;
Harald Welte9b455bf2010-03-14 15:45:01 +0800460 break;
461 case GPRS_LLC_DM: /* Section 6.4.1.4: ABM cannot be performed */
Harald Welte807a5d82010-06-01 11:53:01 +0200462 if (lle->state == GPRS_LLES_LOCAL_EST)
463 lle->state = GPRS_LLES_ASSIGNED_ADM;
Harald Welte9b455bf2010-03-14 15:45:01 +0800464 break;
465 case GPRS_LLC_FRMR: /* Section 6.4.1.5 */
466 break;
467 case GPRS_LLC_XID: /* Section 6.4.1.6 */
Harald Welte5658a1a2010-05-03 13:25:07 +0200468 /* FIXME: implement XID negotiation using SNDCP */
469 {
470 struct msgb *resp;
471 uint8_t *xid;
472 resp = msgb_alloc_headroom(4096, 1024, "LLC_XID");
473 xid = msgb_put(resp, gph->data_len);
474 memcpy(xid, gph->data, gph->data_len);
475 gprs_llc_tx_xid(lle, resp);
476 }
Harald Welte9b455bf2010-03-14 15:45:01 +0800477 break;
Harald Welteebabdea2010-06-01 18:28:10 +0200478 case GPRS_LLC_UI:
479 if (gph->seq_tx < lle->vu_recv) {
Holger Hans Peter Freyther2788b962010-06-23 09:48:25 +0800480 LOGP(DLLC, LOGL_NOTICE, "TLLI=%08x dropping UI, vurecv %u <= %u\n",
481 lle->llme ? lle->llme->tlli : -1,
Harald Welteebabdea2010-06-01 18:28:10 +0200482 gph->seq_tx, lle->vu_recv);
483 return -EIO;
484 }
485 /* Increment the sequence number that we expect in the next frame */
486 lle->vu_recv = (gph->seq_tx + 1) % 512;
Harald Welted07b4f92010-06-30 23:07:59 +0200487 /* Increment Overflow Counter */
488 if ((gph->seq_tx + 1) / 512)
489 lle->oc_ui_recv += 512;
Harald Welteebabdea2010-06-01 18:28:10 +0200490 break;
Harald Welte9b455bf2010-03-14 15:45:01 +0800491 }
492
493 return 0;
494}
495
496/* parse a GPRS LLC header, also check for invalid frames */
497static int gprs_llc_hdr_parse(struct gprs_llc_hdr_parsed *ghp,
Holger Hans Peter Freytherfa848d42010-05-23 21:43:57 +0800498 uint8_t *llc_hdr, int len)
Harald Welte9b455bf2010-03-14 15:45:01 +0800499{
Harald Welteeaa614c2010-05-02 11:26:34 +0200500 uint8_t *ctrl = llc_hdr+1;
Harald Welte9b455bf2010-03-14 15:45:01 +0800501 int is_sack = 0;
Harald Welte9b455bf2010-03-14 15:45:01 +0800502
503 if (len <= CRC24_LENGTH)
504 return -EIO;
505
Harald Welte1b8827a2010-06-30 23:15:57 +0200506 ghp->crc_length = len - CRC24_LENGTH;
Harald Welte9b455bf2010-03-14 15:45:01 +0800507
508 ghp->ack_req = 0;
509
510 /* Section 5.5: FCS */
511 ghp->fcs = *(llc_hdr + len - 3);
512 ghp->fcs |= *(llc_hdr + len - 2) << 8;
513 ghp->fcs |= *(llc_hdr + len - 1) << 16;
514
515 /* Section 6.2.1: invalid PD field */
516 if (llc_hdr[0] & 0x80)
517 return -EIO;
518
519 /* This only works for the MS->SGSN direction */
520 if (llc_hdr[0] & 0x40)
521 ghp->is_cmd = 0;
522 else
523 ghp->is_cmd = 1;
524
525 ghp->sapi = llc_hdr[0] & 0xf;
526
527 /* Section 6.2.3: check for reserved SAPI */
528 switch (ghp->sapi) {
529 case 0:
530 case 4:
531 case 6:
532 case 0xa:
533 case 0xc:
534 case 0xd:
535 case 0xf:
536 return -EINVAL;
537 }
538
539 if ((ctrl[0] & 0x80) == 0) {
540 /* I (Information transfer + Supervisory) format */
Harald Welteeaa614c2010-05-02 11:26:34 +0200541 uint8_t k;
Harald Welte9b455bf2010-03-14 15:45:01 +0800542
543 ghp->data = ctrl + 3;
544
545 if (ctrl[0] & 0x40)
546 ghp->ack_req = 1;
547
548 ghp->seq_tx = (ctrl[0] & 0x1f) << 4;
549 ghp->seq_tx |= (ctrl[1] >> 4);
550
551 ghp->seq_rx = (ctrl[1] & 0x7) << 6;
552 ghp->seq_rx |= (ctrl[2] >> 2);
553
554 switch (ctrl[2] & 0x03) {
555 case 0:
556 ghp->cmd = GPRS_LLC_RR;
557 break;
558 case 1:
559 ghp->cmd = GPRS_LLC_ACK;
560 break;
561 case 2:
562 ghp->cmd = GPRS_LLC_RNR;
563 break;
564 case 3:
565 ghp->cmd = GPRS_LLC_SACK;
566 k = ctrl[3] & 0x1f;
567 ghp->data += 1 + k;
568 break;
569 }
Harald Welte5658a1a2010-05-03 13:25:07 +0200570 ghp->data_len = (llc_hdr + len - 3) - ghp->data;
Harald Welte9b455bf2010-03-14 15:45:01 +0800571 } else if ((ctrl[0] & 0xc0) == 0x80) {
572 /* S (Supervisory) format */
573 ghp->data = NULL;
Harald Welte5658a1a2010-05-03 13:25:07 +0200574 ghp->data_len = 0;
Harald Welte9b455bf2010-03-14 15:45:01 +0800575
576 if (ctrl[0] & 0x20)
577 ghp->ack_req = 1;
578 ghp->seq_rx = (ctrl[0] & 0x7) << 6;
579 ghp->seq_rx |= (ctrl[1] >> 2);
580
581 switch (ctrl[1] & 0x03) {
582 case 0:
583 ghp->cmd = GPRS_LLC_RR;
584 break;
585 case 1:
586 ghp->cmd = GPRS_LLC_ACK;
587 break;
588 case 2:
589 ghp->cmd = GPRS_LLC_RNR;
590 break;
591 case 3:
592 ghp->cmd = GPRS_LLC_SACK;
593 break;
594 }
595 } else if ((ctrl[0] & 0xe0) == 0xc0) {
596 /* UI (Unconfirmed Inforamtion) format */
Harald Welte1ae09c72010-05-13 19:22:55 +0200597 ghp->cmd = GPRS_LLC_UI;
Harald Welte9b455bf2010-03-14 15:45:01 +0800598 ghp->data = ctrl + 2;
Harald Welte5658a1a2010-05-03 13:25:07 +0200599 ghp->data_len = (llc_hdr + len - 3) - ghp->data;
Harald Welte9b455bf2010-03-14 15:45:01 +0800600
601 ghp->seq_tx = (ctrl[0] & 0x7) << 6;
602 ghp->seq_tx |= (ctrl[1] >> 2);
603 if (ctrl[1] & 0x02) {
604 ghp->is_encrypted = 1;
605 /* FIXME: encryption */
606 }
607 if (ctrl[1] & 0x01) {
608 /* FCS over hdr + all inf fields */
609 } else {
610 /* FCS over hdr + N202 octets (4) */
Harald Welte1b8827a2010-06-30 23:15:57 +0200611 if (ghp->crc_length > UI_HDR_LEN + N202)
612 ghp->crc_length = UI_HDR_LEN + N202;
Harald Welte9b455bf2010-03-14 15:45:01 +0800613 }
614 } else {
615 /* U (Unnumbered) format: 1 1 1 P/F M4 M3 M2 M1 */
616 ghp->data = NULL;
Harald Welte5658a1a2010-05-03 13:25:07 +0200617 ghp->data_len = 0;
Harald Welte9b455bf2010-03-14 15:45:01 +0800618
619 switch (ctrl[0] & 0xf) {
Harald Welte5658a1a2010-05-03 13:25:07 +0200620 case GPRS_LLC_U_NULL_CMD:
Harald Welte9b455bf2010-03-14 15:45:01 +0800621 ghp->cmd = GPRS_LLC_NULL;
622 break;
Harald Welte5658a1a2010-05-03 13:25:07 +0200623 case GPRS_LLC_U_DM_RESP:
Harald Welte9b455bf2010-03-14 15:45:01 +0800624 ghp->cmd = GPRS_LLC_DM;
625 break;
Harald Welte5658a1a2010-05-03 13:25:07 +0200626 case GPRS_LLC_U_DISC_CMD:
Harald Welte9b455bf2010-03-14 15:45:01 +0800627 ghp->cmd = GPRS_LLC_DISC;
628 break;
Harald Welte5658a1a2010-05-03 13:25:07 +0200629 case GPRS_LLC_U_UA_RESP:
Harald Welte9b455bf2010-03-14 15:45:01 +0800630 ghp->cmd = GPRS_LLC_UA;
631 break;
Harald Welte5658a1a2010-05-03 13:25:07 +0200632 case GPRS_LLC_U_SABM_CMD:
Harald Welte9b455bf2010-03-14 15:45:01 +0800633 ghp->cmd = GPRS_LLC_SABM;
634 break;
Harald Welte5658a1a2010-05-03 13:25:07 +0200635 case GPRS_LLC_U_FRMR_RESP:
Harald Welte9b455bf2010-03-14 15:45:01 +0800636 ghp->cmd = GPRS_LLC_FRMR;
637 break;
Harald Welte5658a1a2010-05-03 13:25:07 +0200638 case GPRS_LLC_U_XID:
Harald Welte9b455bf2010-03-14 15:45:01 +0800639 ghp->cmd = GPRS_LLC_XID;
Harald Welte5658a1a2010-05-03 13:25:07 +0200640 ghp->data = ctrl + 1;
641 ghp->data_len = (llc_hdr + len - 3) - ghp->data;
Harald Welte9b455bf2010-03-14 15:45:01 +0800642 break;
643 default:
644 return -EIO;
645 }
646 }
647
Harald Welte9b455bf2010-03-14 15:45:01 +0800648 /* FIXME: parse sack frame */
Harald Welte1ae09c72010-05-13 19:22:55 +0200649 if (ghp->cmd == GPRS_LLC_SACK) {
Harald Welte1b170d12010-05-13 19:49:06 +0200650 LOGP(DLLC, LOGL_NOTICE, "Unsupported SACK frame\n");
Harald Welte1ae09c72010-05-13 19:22:55 +0200651 return -EIO;
652 }
653
654 return 0;
Harald Welte9b455bf2010-03-14 15:45:01 +0800655}
656
Harald Weltea2665542010-05-02 09:28:11 +0200657/* receive an incoming LLC PDU (BSSGP-UL-UNITDATA-IND, 7.2.4.2) */
Harald Welte9b455bf2010-03-14 15:45:01 +0800658int gprs_llc_rcvmsg(struct msgb *msg, struct tlv_parsed *tv)
659{
Harald Weltefd3fa1d2010-05-02 09:50:42 +0200660 struct bssgp_ud_hdr *udh = (struct bssgp_ud_hdr *) msgb_bssgph(msg);
Harald Welte943c5bc2010-04-30 16:33:12 +0200661 struct gprs_llc_hdr *lh = msgb_llch(msg);
Harald Welte9b455bf2010-03-14 15:45:01 +0800662 struct gprs_llc_hdr_parsed llhp;
Harald Welte10997d02010-05-03 12:28:12 +0200663 struct gprs_llc_lle *lle;
Harald Weltea2665542010-05-02 09:28:11 +0200664 int rc = 0;
Harald Welte9b455bf2010-03-14 15:45:01 +0800665
Harald Welte11d7c102010-05-02 11:54:55 +0200666 /* Identifiers from DOWN: NSEI, BVCI, TLLI */
667
Holger Hans Peter Freyther4752e0c2010-05-23 21:33:57 +0800668 memset(&llhp, 0, sizeof(llhp));
Holger Hans Peter Freytherfa848d42010-05-23 21:43:57 +0800669 rc = gprs_llc_hdr_parse(&llhp, (uint8_t *) lh, TLVP_LEN(tv, BSSGP_IE_LLC_PDU));
Harald Welte9b455bf2010-03-14 15:45:01 +0800670 gprs_llc_hdr_dump(&llhp);
Harald Welte1ae09c72010-05-13 19:22:55 +0200671 if (rc < 0) {
Harald Welte1b170d12010-05-13 19:49:06 +0200672 LOGP(DLLC, LOGL_NOTICE, "Error during LLC header parsing\n");
Harald Welte1ae09c72010-05-13 19:22:55 +0200673 return rc;
674 }
675
Harald Welte807a5d82010-06-01 11:53:01 +0200676 switch (gprs_tlli_type(msgb_tlli(msg))) {
677 case TLLI_LOCAL:
678 case TLLI_FOREIGN:
679 case TLLI_RANDOM:
680 case TLLI_AUXILIARY:
681 break;
682 default:
683 LOGP(DLLC, LOGL_ERROR,
684 "Discarding frame with strange TLLI type\n");
685 break;
686 }
687
Harald Weltea2665542010-05-02 09:28:11 +0200688 /* find the LLC Entity for this TLLI+SAPI tuple */
689 lle = lle_by_tlli_sapi(msgb_tlli(msg), llhp.sapi);
Harald Welte1ae09c72010-05-13 19:22:55 +0200690
691 /* 7.2.1.1 LLC belonging to unassigned TLLI+SAPI shall be discarded,
692 * except UID and XID frames with SAPI=1 */
Harald Welted764c062010-05-18 12:45:08 +0200693 if (!lle) {
694 if (llhp.sapi == GPRS_SAPI_GMM &&
695 (llhp.cmd == GPRS_LLC_XID || llhp.cmd == GPRS_LLC_UI)) {
Harald Welte807a5d82010-06-01 11:53:01 +0200696 struct gprs_llc_llme *llme;
Harald Welted764c062010-05-18 12:45:08 +0200697 /* FIXME: don't use the TLLI but the 0xFFFF unassigned? */
Harald Welte807a5d82010-06-01 11:53:01 +0200698 llme = llme_alloc(msgb_tlli(msg));
Harald Weltef0901f02010-12-26 10:39:26 +0100699 LOGP(DLLC, LOGL_DEBUG, "LLC RX: unknown TLLI 0x08x, "
700 "creating LLME on the fly\n", msgb_tlli(msg));
Harald Welte807a5d82010-06-01 11:53:01 +0200701 lle = &llme->lle[llhp.sapi];
Harald Welted764c062010-05-18 12:45:08 +0200702 } else {
703 LOGP(DLLC, LOGL_NOTICE,
704 "unknown TLLI/SAPI: Silently dropping\n");
705 return 0;
706 }
Harald Welte1ae09c72010-05-13 19:22:55 +0200707 }
Harald Weltea2665542010-05-02 09:28:11 +0200708
Harald Welted07b4f92010-06-30 23:07:59 +0200709 /* decrypt information field + FCS, if needed! */
710 if (llhp.is_encrypted) {
711 uint32_t iov_ui = 0; /* FIXME: randomly select for TLLI */
712 uint16_t crypt_len = llhp.data_len + 3;
713 uint8_t cipher_out[GSM0464_CIPH_MAX_BLOCK];
714 uint32_t iv;
715 uint64_t kc = *(uint64_t *)&lle->llme->kc;
716 int rc, i;
717
718 if (lle->llme->algo == GPRS_ALGO_GEA0) {
719 LOGP(DLLC, LOGL_NOTICE, "encrypted frame for LLC that "
720 "has no KC/Algo! Dropping.\n");
721 return 0;
722 }
723
724 iv = gprs_cipher_gen_input_ui(iov_ui, lle->sapi, llhp.seq_tx,
725 lle->oc_ui_recv);
726 rc = gprs_cipher_run(cipher_out, crypt_len, lle->llme->algo,
727 kc, iv, GPRS_CIPH_MS2SGSN);
728 if (rc < 0) {
729 LOGP(DLLC, LOGL_ERROR, "Error decrypting frame: %d\n",
730 rc);
731 return rc;
732 }
733
734 /* XOR the cipher output with the information field + FCS */
735 for (i = 0; i < crypt_len; i++)
736 *(llhp.data + i) ^= cipher_out[i];
737 } else {
738 if (lle->llme->algo != GPRS_ALGO_GEA0) {
739 LOGP(DLLC, LOGL_NOTICE, "unencrypted frame for LLC "
740 "that is supposed to be encrypted. Dropping.\n");
741 return 0;
742 }
743 }
744
745 /* We have to do the FCS check _after_ decryption */
Harald Welte1b8827a2010-06-30 23:15:57 +0200746 llhp.fcs_calc = gprs_llc_fcs((uint8_t *)lh, llhp.crc_length);
Harald Welted07b4f92010-06-30 23:07:59 +0200747 if (llhp.fcs != llhp.fcs_calc) {
748 LOGP(DLLC, LOGL_INFO, "Dropping frame with invalid FCS\n");
749 return -EIO;
750 }
751
Harald Welte10997d02010-05-03 12:28:12 +0200752 /* Update LLE's (BVCI, NSEI) tuple */
Harald Welte807a5d82010-06-01 11:53:01 +0200753 lle->llme->bvci = msgb_bvci(msg);
754 lle->llme->nsei = msgb_nsei(msg);
Harald Welte10997d02010-05-03 12:28:12 +0200755
Harald Welte1ae09c72010-05-13 19:22:55 +0200756 /* Receive and Process the actual LLC frame */
Harald Welte9b455bf2010-03-14 15:45:01 +0800757 rc = gprs_llc_hdr_rx(&llhp, lle);
Harald Welte1ae09c72010-05-13 19:22:55 +0200758 if (rc < 0)
759 return rc;
Harald Welte9b455bf2010-03-14 15:45:01 +0800760
Harald Welte1ae09c72010-05-13 19:22:55 +0200761 /* llhp.data is only set when we need to send LL_[UNIT]DATA_IND up */
Harald Welte9b455bf2010-03-14 15:45:01 +0800762 if (llhp.data) {
Harald Welte943c5bc2010-04-30 16:33:12 +0200763 msgb_gmmh(msg) = llhp.data;
Harald Welte9b455bf2010-03-14 15:45:01 +0800764 switch (llhp.sapi) {
765 case GPRS_SAPI_GMM:
Harald Welte1ae09c72010-05-13 19:22:55 +0200766 /* send LL_UNITDATA_IND to GMM */
Harald Welte807a5d82010-06-01 11:53:01 +0200767 rc = gsm0408_gprs_rcvmsg(msg, lle->llme);
Harald Weltea2665542010-05-02 09:28:11 +0200768 break;
Harald Weltea2665542010-05-02 09:28:11 +0200769 case GPRS_SAPI_SNDCP3:
770 case GPRS_SAPI_SNDCP5:
771 case GPRS_SAPI_SNDCP9:
772 case GPRS_SAPI_SNDCP11:
Harald Welteebabdea2010-06-01 18:28:10 +0200773 /* send LL_DATA_IND/LL_UNITDATA_IND to SNDCP */
774 rc = sndcp_llunitdata_ind(msg, lle, llhp.data, llhp.data_len);
775 break;
Harald Weltea2665542010-05-02 09:28:11 +0200776 case GPRS_SAPI_SMS:
777 /* FIXME */
Harald Welteebabdea2010-06-01 18:28:10 +0200778 case GPRS_SAPI_TOM2:
779 case GPRS_SAPI_TOM8:
780 /* FIXME: send LL_DATA_IND/LL_UNITDATA_IND to TOM */
Harald Weltea2665542010-05-02 09:28:11 +0200781 default:
Harald Weltec6ecafe2010-05-13 19:47:50 +0200782 LOGP(DLLC, LOGL_NOTICE, "Unsupported SAPI %u\n", llhp.sapi);
Harald Weltea2665542010-05-02 09:28:11 +0200783 rc = -EINVAL;
784 break;
Harald Welte9b455bf2010-03-14 15:45:01 +0800785 }
786 }
787
Harald Weltea2665542010-05-02 09:28:11 +0200788 return rc;
Harald Welte9b455bf2010-03-14 15:45:01 +0800789}
Harald Welte807a5d82010-06-01 11:53:01 +0200790
791/* 04.64 Chapter 7.2.1.1 LLGMM-ASSIGN */
792int gprs_llgmm_assign(struct gprs_llc_llme *llme,
793 uint32_t old_tlli, uint32_t new_tlli,
794 enum gprs_ciph_algo alg, const uint8_t *kc)
795{
796 unsigned int i;
797
Harald Welted07b4f92010-06-30 23:07:59 +0200798 /* Update the crypto parameters */
Harald Welted07b4f92010-06-30 23:07:59 +0200799 llme->algo = alg;
Harald Welte3e2e1592010-06-30 23:19:23 +0200800 if (alg != GPRS_ALGO_GEA0)
801 memcpy(llme->kc, kc, sizeof(llme->kc));
Harald Welted07b4f92010-06-30 23:07:59 +0200802
Harald Welte807a5d82010-06-01 11:53:01 +0200803 if (old_tlli == 0xffffffff && new_tlli != 0xffffffff) {
804 /* TLLI Assignment 8.3.1 */
805 /* New TLLI shall be assigned and used when (re)transmitting LLC frames */
806 /* If old TLLI != 0xffffffff was assigned to LLME, then TLLI
807 * old is unassigned. Only TLLI new shall be accepted when
808 * received from peer. */
Harald Welte875840c2010-07-01 11:54:31 +0200809 if (llme->old_tlli != 0xffffffff) {
810 llme->old_tlli = 0xffffffff;
811 llme->tlli = new_tlli;
812 } else {
813 /* If TLLI old == 0xffffffff was assigned to LLME, then this is
814 * TLLI assignmemt according to 8.3.1 */
815 llme->old_tlli = 0xffffffff;
816 llme->tlli = new_tlli;
817 llme->state = GPRS_LLMS_ASSIGNED;
818 /* 8.5.3.1 For all LLE's */
819 for (i = 0; i < ARRAY_SIZE(llme->lle); i++) {
820 struct gprs_llc_lle *l = &llme->lle[i];
821 l->vu_send = l->vu_recv = 0;
822 l->retrans_ctr = 0;
823 l->state = GPRS_LLES_ASSIGNED_ADM;
824 /* FIXME Set parameters according to table 9 */
825 }
Harald Welte807a5d82010-06-01 11:53:01 +0200826 }
827 } else if (old_tlli != 0xffffffff && new_tlli != 0xffffffff) {
828 /* TLLI Change 8.3.2 */
829 /* Both TLLI Old and TLLI New are assigned; use New when
830 * (re)transmitting. Accept toth Old and New on Rx */
831 llme->old_tlli = llme->tlli;
832 llme->tlli = new_tlli;
833 llme->state = GPRS_LLMS_ASSIGNED;
834 } else if (old_tlli != 0xffffffff && new_tlli == 0xffffffff) {
835 /* TLLI Unassignment 8.3.3) */
836 llme->tlli = llme->old_tlli = 0;
837 llme->state = GPRS_LLMS_UNASSIGNED;
838 for (i = 0; i < ARRAY_SIZE(llme->lle); i++) {
839 struct gprs_llc_lle *l = &llme->lle[i];
840 l->state = GPRS_LLES_UNASSIGNED;
841 }
Harald Weltef7fef482010-06-28 22:18:26 +0200842 llme_free(llme);
Harald Welte807a5d82010-06-01 11:53:01 +0200843 } else
844 return -EINVAL;
845
846 return 0;
847}
Harald Welte496aee42010-06-30 19:59:55 +0200848
849int gprs_llc_init(const char *cipher_plugin_path)
850{
851 return gprs_cipher_load(cipher_plugin_path);
852}