blob: ae9891e04f4b6e0b5fa75f946dfe0be9bea070c6 [file] [log] [blame]
Holger Hans Peter Freytherdcf8a7d2010-06-15 18:48:01 +08001
2/* BSC Multiplexer/NAT Utilities */
3
4/*
Holger Hans Peter Freythere1880102011-04-23 23:31:31 +02005 * (C) 2010-2011 by Holger Hans Peter Freyther <zecke@selfish.org>
6 * (C) 2010-2011 by On-Waves
Holger Hans Peter Freytherdcf8a7d2010-06-15 18:48:01 +08007 * All Rights Reserved
8 *
9 * This program is free software; you can redistribute it and/or modify
Harald Welte9af6ddf2011-01-01 15:25:50 +010010 * it under the terms of the GNU Affero General Public License as published by
11 * the Free Software Foundation; either version 3 of the License, or
Holger Hans Peter Freytherdcf8a7d2010-06-15 18:48:01 +080012 * (at your option) any later version.
13 *
14 * This program is distributed in the hope that it will be useful,
15 * but WITHOUT ANY WARRANTY; without even the implied warranty of
16 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
Harald Welte9af6ddf2011-01-01 15:25:50 +010017 * GNU Affero General Public License for more details.
Holger Hans Peter Freytherdcf8a7d2010-06-15 18:48:01 +080018 *
Harald Welte9af6ddf2011-01-01 15:25:50 +010019 * You should have received a copy of the GNU Affero General Public License
20 * along with this program. If not, see <http://www.gnu.org/licenses/>.
Holger Hans Peter Freytherdcf8a7d2010-06-15 18:48:01 +080021 *
22 */
23
24#include <openbsc/bsc_nat.h>
Holger Hans Peter Freytherc2b31ed2010-07-31 05:17:17 +080025#include <openbsc/bsc_nat_sccp.h>
Holger Hans Peter Freyther20ee3122010-07-05 14:39:44 +080026#include <openbsc/bsc_msc.h>
Holger Hans Peter Freytherdcf8a7d2010-06-15 18:48:01 +080027#include <openbsc/gsm_data.h>
Holger Hans Peter Freytherbae9da42010-03-30 05:57:42 +020028#include <openbsc/debug.h>
Holger Hans Peter Freythera0df82d2010-04-01 08:21:33 +020029#include <openbsc/ipaccess.h>
Holger Hans Peter Freyther3e9a7f82010-10-12 23:21:54 +020030#include <openbsc/vty.h>
Holger Hans Peter Freytherdcf8a7d2010-06-15 18:48:01 +080031
Pablo Neira Ayuso136f4532011-03-22 16:47:59 +010032#include <osmocom/core/linuxlist.h>
33#include <osmocom/core/talloc.h>
Harald Welted36ff762011-03-23 18:26:56 +010034#include <osmocom/gsm/gsm0808.h>
Holger Hans Peter Freytherdcf8a7d2010-06-15 18:48:01 +080035
Harald Welted36ff762011-03-23 18:26:56 +010036#include <osmocom/gsm/protocol/gsm_08_08.h>
Holger Hans Peter Freyther9c205712011-05-27 17:14:15 +020037#include <osmocom/gsm/protocol/gsm_04_11.h>
Holger Hans Peter Freyther69d801e2010-06-15 20:13:33 +080038
Harald Welted5db12c2010-08-03 15:11:51 +020039#include <osmocom/sccp/sccp.h>
Holger Hans Peter Freyther23fe7be2010-03-30 10:45:48 +020040
Holger Hans Peter Freytherbae9da42010-03-30 05:57:42 +020041#include <netinet/in.h>
42#include <arpa/inet.h>
Holger Hans Peter Freyther69cfa172010-10-13 20:37:13 +020043#include <unistd.h>
Holger Hans Peter Freytherbae9da42010-03-30 05:57:42 +020044
Holger Hans Peter Freytherb2c38eb2010-06-17 18:16:00 +080045static const struct rate_ctr_desc bsc_cfg_ctr_description[] = {
Holger Hans Peter Freyther71d36b32010-06-17 18:31:18 +080046 [BCFG_CTR_SCCP_CONN] = { "sccp.conn", "SCCP Connections "},
47 [BCFG_CTR_SCCP_CALLS] = { "sccp.calls", "SCCP Assignment Commands "},
48 [BCFG_CTR_NET_RECONN] = { "net.reconnects", "Network reconnects "},
49 [BCFG_CTR_DROPPED_SCCP] = { "dropped.sccp", "Dropped SCCP connections."},
50 [BCFG_CTR_DROPPED_CALLS] = { "dropped.calls", "Dropped active calls. "},
Holger Hans Peter Freytheree884962010-09-25 17:58:22 +080051 [BCFG_CTR_REJECTED_CR] = { "rejected.cr", "Rejected CR due filter "},
52 [BCFG_CTR_REJECTED_MSG] = { "rejected.msg", "Rejected MSG due filter "},
53 [BCFG_CTR_ILL_PACKET] = { "rejected.ill", "Rejected due parse error "},
Holger Hans Peter Freyther463dc622010-10-03 19:41:42 +080054 [BCFG_CTR_CON_TYPE_LU] = { "conn.lu", "Conn Location Update "},
55 [BCFG_CTR_CON_CMSERV_RQ] = { "conn.rq", "Conn CM Service Req "},
56 [BCFG_CTR_CON_PAG_RESP] = { "conn.pag", "Conn Paging Response "},
Holger Hans Peter Freyther74dc3032010-09-29 02:47:29 +080057 [BCFG_CTR_CON_SSA] = { "conn.ssa", "Conn USSD "},
Holger Hans Peter Freyther463dc622010-10-03 19:41:42 +080058 [BCFG_CTR_CON_OTHER] = { "conn.other", "Conn Other "},
Holger Hans Peter Freytherb2c38eb2010-06-17 18:16:00 +080059};
60
61static const struct rate_ctr_group_desc bsc_cfg_ctrg_desc = {
62 .group_name_prefix = "nat.bsc",
63 .group_description = "NAT BSC Statistics",
64 .num_ctr = ARRAY_SIZE(bsc_cfg_ctr_description),
65 .ctr_desc = bsc_cfg_ctr_description,
66};
67
Holger Hans Peter Freyther2f1a9842010-09-25 06:14:52 +080068static const struct rate_ctr_desc acc_list_ctr_description[] = {
69 [ACC_LIST_BSC_FILTER] = { "access-list.bsc-filter", "Rejected by rule for BSC"},
70 [ACC_LIST_NAT_FILTER] = { "access-list.nat-filter", "Rejected by rule for NAT"},
71};
72
73static const struct rate_ctr_group_desc bsc_cfg_acc_list_desc = {
74 .group_name_prefix = "nat.filter",
75 .group_description = "NAT Access-List Statistics",
76 .num_ctr = ARRAY_SIZE(acc_list_ctr_description),
77 .ctr_desc = acc_list_ctr_description,
78};
79
Holger Hans Peter Freytherdcf8a7d2010-06-15 18:48:01 +080080struct bsc_nat *bsc_nat_alloc(void)
81{
82 struct bsc_nat *nat = talloc_zero(tall_bsc_ctx, struct bsc_nat);
83 if (!nat)
84 return NULL;
85
Holger Hans Peter Freythere1880102011-04-23 23:31:31 +020086 nat->main_dest = talloc_zero(nat, struct bsc_msc_dest);
87 if (!nat->main_dest) {
88 talloc_free(nat);
89 return NULL;
90 }
91
Holger Hans Peter Freytherdcf8a7d2010-06-15 18:48:01 +080092 INIT_LLIST_HEAD(&nat->sccp_connections);
93 INIT_LLIST_HEAD(&nat->bsc_connections);
Holger Hans Peter Freyther474698a2011-05-02 16:50:36 +020094 INIT_LLIST_HEAD(&nat->paging_groups);
Holger Hans Peter Freytherdcf8a7d2010-06-15 18:48:01 +080095 INIT_LLIST_HEAD(&nat->bsc_configs);
Holger Hans Peter Freyther8affef52010-06-01 01:03:13 +080096 INIT_LLIST_HEAD(&nat->access_lists);
Holger Hans Peter Freythere1880102011-04-23 23:31:31 +020097 INIT_LLIST_HEAD(&nat->dests);
Holger Hans Peter Freytherad75eab2011-05-27 12:38:58 +020098 INIT_LLIST_HEAD(&nat->num_rewr);
Holger Hans Peter Freyther9c205712011-05-27 17:14:15 +020099 INIT_LLIST_HEAD(&nat->smsc_rewr);
Holger Hans Peter Freyther8affef52010-06-01 01:03:13 +0800100
Pablo Neira Ayusodfb342c2011-05-06 12:13:10 +0200101 nat->stats.sccp.conn = osmo_counter_alloc("nat.sccp.conn");
102 nat->stats.sccp.calls = osmo_counter_alloc("nat.sccp.calls");
103 nat->stats.bsc.reconn = osmo_counter_alloc("nat.bsc.conn");
104 nat->stats.bsc.auth_fail = osmo_counter_alloc("nat.bsc.auth_fail");
105 nat->stats.msc.reconn = osmo_counter_alloc("nat.msc.conn");
106 nat->stats.ussd.reconn = osmo_counter_alloc("nat.ussd.conn");
Holger Hans Peter Freytherda35a8d2010-05-05 16:57:38 +0800107 nat->auth_timeout = 2;
108 nat->ping_timeout = 20;
109 nat->pong_timeout = 5;
Holger Hans Peter Freythere1880102011-04-23 23:31:31 +0200110
111 llist_add(&nat->main_dest->list, &nat->dests);
112 nat->main_dest->ip = talloc_strdup(nat, "127.0.0.1");
113 nat->main_dest->port = 5000;
114
Holger Hans Peter Freytherdcf8a7d2010-06-15 18:48:01 +0800115 return nat;
116}
117
Holger Hans Peter Freythera88742c2010-06-15 18:51:04 +0800118void bsc_nat_set_msc_ip(struct bsc_nat *nat, const char *ip)
119{
Holger Hans Peter Freythere1880102011-04-23 23:31:31 +0200120 bsc_replace_string(nat, &nat->main_dest->ip, ip);
Holger Hans Peter Freythera88742c2010-06-15 18:51:04 +0800121}
122
Holger Hans Peter Freytherdcf8a7d2010-06-15 18:48:01 +0800123struct bsc_connection *bsc_connection_alloc(struct bsc_nat *nat)
124{
125 struct bsc_connection *con = talloc_zero(nat, struct bsc_connection);
126 if (!con)
127 return NULL;
128
Holger Hans Peter Freytherf8048d92010-03-29 15:14:15 +0200129 con->nat = nat;
Pablo Neira Ayusoe1273b12011-05-06 12:09:47 +0200130 osmo_wqueue_init(&con->write_queue, 100);
Holger Hans Peter Freytherdcf8a7d2010-06-15 18:48:01 +0800131 return con;
132}
133
Holger Hans Peter Freyther0bd60f32010-10-08 22:08:29 +0800134struct bsc_config *bsc_config_alloc(struct bsc_nat *nat, const char *token)
Holger Hans Peter Freytherdcf8a7d2010-06-15 18:48:01 +0800135{
136 struct bsc_config *conf = talloc_zero(nat, struct bsc_config);
137 if (!conf)
138 return NULL;
139
140 conf->token = talloc_strdup(conf, token);
Holger Hans Peter Freytherdcf8a7d2010-06-15 18:48:01 +0800141 conf->nr = nat->num_bsc;
142 conf->nat = nat;
Holger Hans Peter Freyther9ec030d2011-02-27 11:04:27 +0100143 conf->max_endpoints = 32;
Holger Hans Peter Freyther474698a2011-05-02 16:50:36 +0200144 conf->paging_group = PAGIN_GROUP_UNASSIGNED;
Holger Hans Peter Freytherdcf8a7d2010-06-15 18:48:01 +0800145
Holger Hans Peter Freyther0bd60f32010-10-08 22:08:29 +0800146 INIT_LLIST_HEAD(&conf->lac_list);
147
Holger Hans Peter Freytherd1278c12010-04-16 16:52:20 +0200148 llist_add_tail(&conf->entry, &nat->bsc_configs);
Holger Hans Peter Freytherdcf8a7d2010-06-15 18:48:01 +0800149 ++nat->num_bsc;
150
Holger Hans Peter Freyther0bd60f32010-10-08 22:08:29 +0800151 conf->stats.ctrg = rate_ctr_group_alloc(conf, &bsc_cfg_ctrg_desc, conf->nr);
Holger Hans Peter Freytherb2c38eb2010-06-17 18:16:00 +0800152 if (!conf->stats.ctrg) {
153 talloc_free(conf);
154 return NULL;
155 }
Holger Hans Peter Freytherd4702862010-04-12 12:17:09 +0200156
Holger Hans Peter Freytherdcf8a7d2010-06-15 18:48:01 +0800157 return conf;
158}
Holger Hans Peter Freytherbae9da42010-03-30 05:57:42 +0200159
Holger Hans Peter Freyther9212d9d2011-02-27 11:18:41 +0100160void bsc_config_free(struct bsc_config *cfg)
161{
162 rate_ctr_group_free(cfg->stats.ctrg);
163}
164
Holger Hans Peter Freyther6860c442011-05-02 19:16:13 +0200165static void _add_lac(void *ctx, struct llist_head *list, int _lac)
Holger Hans Peter Freyther0bd60f32010-10-08 22:08:29 +0800166{
167 struct bsc_lac_entry *lac;
168
Holger Hans Peter Freyther6860c442011-05-02 19:16:13 +0200169 llist_for_each_entry(lac, list, entry)
Holger Hans Peter Freyther0bd60f32010-10-08 22:08:29 +0800170 if (lac->lac == _lac)
171 return;
172
Holger Hans Peter Freyther6860c442011-05-02 19:16:13 +0200173 lac = talloc_zero(ctx, struct bsc_lac_entry);
Holger Hans Peter Freyther0bd60f32010-10-08 22:08:29 +0800174 if (!lac) {
175 LOGP(DNAT, LOGL_ERROR, "Failed to allocate.\n");
176 return;
177 }
178
179 lac->lac = _lac;
Holger Hans Peter Freyther6860c442011-05-02 19:16:13 +0200180 llist_add_tail(&lac->entry, list);
Holger Hans Peter Freyther0bd60f32010-10-08 22:08:29 +0800181}
182
Holger Hans Peter Freyther6860c442011-05-02 19:16:13 +0200183static void _del_lac(struct llist_head *list, int _lac)
Holger Hans Peter Freyther0bd60f32010-10-08 22:08:29 +0800184{
185 struct bsc_lac_entry *lac;
186
Holger Hans Peter Freyther6860c442011-05-02 19:16:13 +0200187 llist_for_each_entry(lac, list, entry)
Holger Hans Peter Freyther0bd60f32010-10-08 22:08:29 +0800188 if (lac->lac == _lac) {
189 llist_del(&lac->entry);
190 talloc_free(lac);
191 return;
192 }
193}
194
Holger Hans Peter Freyther6860c442011-05-02 19:16:13 +0200195void bsc_config_add_lac(struct bsc_config *cfg, int _lac)
196{
197 _add_lac(cfg, &cfg->lac_list, _lac);
198}
199
200void bsc_config_del_lac(struct bsc_config *cfg, int _lac)
201{
202 _del_lac(&cfg->lac_list, _lac);
203}
204
205struct bsc_nat_paging_group *bsc_nat_paging_group_create(struct bsc_nat *nat, int group)
206{
207 struct bsc_nat_paging_group *pgroup;
208
209 pgroup = talloc_zero(nat, struct bsc_nat_paging_group);
210 if (!pgroup) {
211 LOGP(DNAT, LOGL_ERROR, "Failed to allocate a paging group.\n");
212 return NULL;
213 }
214
215 pgroup->nr = group;
216 INIT_LLIST_HEAD(&pgroup->lists);
217 llist_add_tail(&pgroup->entry, &nat->paging_groups);
218 return pgroup;
219}
220
221void bsc_nat_paging_group_delete(struct bsc_nat_paging_group *pgroup)
222{
223 llist_del(&pgroup->entry);
224 talloc_free(pgroup);
225}
226
227struct bsc_nat_paging_group *bsc_nat_paging_group_num(struct bsc_nat *nat, int group)
Holger Hans Peter Freyther474698a2011-05-02 16:50:36 +0200228{
229 struct bsc_nat_paging_group *pgroup;
230
231 llist_for_each_entry(pgroup, &nat->paging_groups, entry)
232 if (pgroup->nr == group)
233 return pgroup;
234
235 return NULL;
236}
237
Holger Hans Peter Freyther6860c442011-05-02 19:16:13 +0200238void bsc_nat_paging_group_add_lac(struct bsc_nat_paging_group *pgroup, int lac)
239{
240 _add_lac(pgroup, &pgroup->lists, lac);
241}
242
243void bsc_nat_paging_group_del_lac(struct bsc_nat_paging_group *pgroup, int lac)
244{
245 _del_lac(&pgroup->lists, lac);
246}
247
Holger Hans Peter Freyther0bd60f32010-10-08 22:08:29 +0800248int bsc_config_handles_lac(struct bsc_config *cfg, int lac_nr)
249{
Holger Hans Peter Freyther474698a2011-05-02 16:50:36 +0200250 struct bsc_nat_paging_group *pgroup;
Holger Hans Peter Freyther0bd60f32010-10-08 22:08:29 +0800251 struct bsc_lac_entry *entry;
252
253 llist_for_each_entry(entry, &cfg->lac_list, entry)
254 if (entry->lac == lac_nr)
255 return 1;
256
Holger Hans Peter Freyther474698a2011-05-02 16:50:36 +0200257 /* now lookup the paging group */
258 pgroup = bsc_nat_paging_group_num(cfg->nat, cfg->paging_group);
259 if (!pgroup)
260 return 0;
261
262 llist_for_each_entry(entry, &pgroup->lists, entry)
263 if (entry->lac == lac_nr)
264 return 1;
265
Holger Hans Peter Freyther0bd60f32010-10-08 22:08:29 +0800266 return 0;
267}
268
Holger Hans Peter Freyther23fe7be2010-03-30 10:45:48 +0200269void sccp_connection_destroy(struct sccp_connections *conn)
270{
271 LOGP(DNAT, LOGL_DEBUG, "Destroy 0x%x <-> 0x%x mapping for con %p\n",
272 sccp_src_ref_to_int(&conn->real_ref),
273 sccp_src_ref_to_int(&conn->patched_ref), conn->bsc);
Holger Hans Peter Freyther7b7eef62010-04-22 12:08:17 +0800274 bsc_mgcp_dlcx(conn);
Holger Hans Peter Freyther23fe7be2010-03-30 10:45:48 +0200275 llist_del(&conn->list_entry);
276 talloc_free(conn);
277}
278
Holger Hans Peter Freyther1ffe98c2011-05-02 16:20:32 +0200279
280int bsc_nat_find_paging(struct msgb *msg,
281 const uint8_t **out_data, int *out_leng)
Holger Hans Peter Freytherbae9da42010-03-30 05:57:42 +0200282{
Holger Hans Peter Freytherbae9da42010-03-30 05:57:42 +0200283 int data_length;
Holger Hans Peter Freytherdbd16fe2010-07-23 19:08:55 +0800284 const uint8_t *data;
Holger Hans Peter Freytherbae9da42010-03-30 05:57:42 +0200285 struct tlv_parsed tp;
Holger Hans Peter Freyther7a773692010-04-18 02:41:20 +0800286
Holger Hans Peter Freythere9be5172010-03-30 06:51:23 +0200287 if (!msg->l3h || msgb_l3len(msg) < 3) {
288 LOGP(DNAT, LOGL_ERROR, "Paging message is too short.\n");
Holger Hans Peter Freyther1ffe98c2011-05-02 16:20:32 +0200289 return -1;
Holger Hans Peter Freythere9be5172010-03-30 06:51:23 +0200290 }
291
Holger Hans Peter Freytherbae9da42010-03-30 05:57:42 +0200292 tlv_parse(&tp, gsm0808_att_tlvdef(), msg->l3h + 3, msgb_l3len(msg) - 3, 0, 0);
293 if (!TLVP_PRESENT(&tp, GSM0808_IE_CELL_IDENTIFIER_LIST)) {
294 LOGP(DNAT, LOGL_ERROR, "No CellIdentifier List inside paging msg.\n");
Holger Hans Peter Freyther1ffe98c2011-05-02 16:20:32 +0200295 return -2;
Holger Hans Peter Freytherbae9da42010-03-30 05:57:42 +0200296 }
297
298 data_length = TLVP_LEN(&tp, GSM0808_IE_CELL_IDENTIFIER_LIST);
299 data = TLVP_VAL(&tp, GSM0808_IE_CELL_IDENTIFIER_LIST);
Holger Hans Peter Freythera4376ad2010-04-21 18:47:24 +0800300
301 /* No need to try a different BSS */
302 if (data[0] == CELL_IDENT_BSS) {
Holger Hans Peter Freyther1ffe98c2011-05-02 16:20:32 +0200303 return -3;
Holger Hans Peter Freythera4376ad2010-04-21 18:47:24 +0800304 } else if (data[0] != CELL_IDENT_LAC) {
Holger Hans Peter Freyther530c4b12010-04-06 10:25:40 +0200305 LOGP(DNAT, LOGL_ERROR, "Unhandled cell ident discrminator: %d\n", data[0]);
Holger Hans Peter Freyther1ffe98c2011-05-02 16:20:32 +0200306 return -4;
Holger Hans Peter Freytherbae9da42010-03-30 05:57:42 +0200307 }
308
Holger Hans Peter Freyther1ffe98c2011-05-02 16:20:32 +0200309 *out_data = &data[1];
310 *out_leng = data_length - 1;
311 return 0;
Holger Hans Peter Freythera0df82d2010-04-01 08:21:33 +0200312}
313
Holger Hans Peter Freytherdbd16fe2010-07-23 19:08:55 +0800314int bsc_write_mgcp(struct bsc_connection *bsc, const uint8_t *data, unsigned int length)
Holger Hans Peter Freythera0df82d2010-04-01 08:21:33 +0200315{
316 struct msgb *msg;
317
318 if (length > 4096 - 128) {
319 LOGP(DINP, LOGL_ERROR, "Can not send message of that size.\n");
320 return -1;
321 }
322
323 msg = msgb_alloc_headroom(4096, 128, "to-bsc");
324 if (!msg) {
325 LOGP(DINP, LOGL_ERROR, "Failed to allocate memory for BSC msg.\n");
326 return -1;
327 }
328
329 /* copy the data */
330 msg->l3h = msgb_put(msg, length);
331 memcpy(msg->l3h, data, length);
332
Holger Hans Peter Freyther368a0a72011-01-07 16:54:46 +0100333 return bsc_write(bsc, msg, IPAC_PROTO_MGCP_OLD);
Holger Hans Peter Freythera0df82d2010-04-01 08:21:33 +0200334}
335
Holger Hans Peter Freyther2896df72010-04-08 10:24:57 +0200336int bsc_write(struct bsc_connection *bsc, struct msgb *msg, int proto)
Holger Hans Peter Freythera0df82d2010-04-01 08:21:33 +0200337{
Holger Hans Peter Freyther4d44fc52010-10-13 17:56:22 +0200338 return bsc_do_write(&bsc->write_queue, msg, proto);
339}
340
Pablo Neira Ayusoe1273b12011-05-06 12:09:47 +0200341int bsc_do_write(struct osmo_wqueue *queue, struct msgb *msg, int proto)
Holger Hans Peter Freyther4d44fc52010-10-13 17:56:22 +0200342{
Holger Hans Peter Freythera0df82d2010-04-01 08:21:33 +0200343 /* prepend the header */
Holger Hans Peter Freyther2896df72010-04-08 10:24:57 +0200344 ipaccess_prepend_header(msg, proto);
Holger Hans Peter Freyther7e8da132010-10-16 17:33:46 +0200345 return bsc_write_msg(queue, msg);
346}
Holger Hans Peter Freythera0df82d2010-04-01 08:21:33 +0200347
Pablo Neira Ayusoe1273b12011-05-06 12:09:47 +0200348int bsc_write_msg(struct osmo_wqueue *queue, struct msgb *msg)
Holger Hans Peter Freyther7e8da132010-10-16 17:33:46 +0200349{
Pablo Neira Ayusoe1273b12011-05-06 12:09:47 +0200350 if (osmo_wqueue_enqueue(queue, msg) != 0) {
Holger Hans Peter Freythera0df82d2010-04-01 08:21:33 +0200351 LOGP(DINP, LOGL_ERROR, "Failed to enqueue the write.\n");
352 msgb_free(msg);
353 return -1;
354 }
355
356 return 0;
357}
Holger Hans Peter Freytherb4af5c92010-05-14 03:39:56 +0800358
Holger Hans Peter Freytherc1cac1e2010-10-11 09:50:31 +0200359int bsc_nat_lst_check_allow(struct bsc_nat_acc_lst *lst, const char *mi_string)
Holger Hans Peter Freytherd77c8172010-06-08 10:53:39 +0800360{
361 struct bsc_nat_acc_lst_entry *entry;
362
363 llist_for_each_entry(entry, &lst->fltr_list, list) {
364 if (!entry->imsi_allow)
365 continue;
366 if (regexec(&entry->imsi_allow_re, mi_string, 0, NULL, 0) == 0)
367 return 0;
368 }
369
370 return 1;
371}
372
373static int lst_check_deny(struct bsc_nat_acc_lst *lst, const char *mi_string)
374{
375 struct bsc_nat_acc_lst_entry *entry;
376
377 llist_for_each_entry(entry, &lst->fltr_list, list) {
378 if (!entry->imsi_deny)
379 continue;
380 if (regexec(&entry->imsi_deny_re, mi_string, 0, NULL, 0) == 0)
381 return 0;
382 }
383
384 return 1;
385}
386
Holger Hans Peter Freyther34a96ae2010-05-14 19:49:35 +0800387/* apply white/black list */
388static int auth_imsi(struct bsc_connection *bsc, const char *mi_string)
389{
Holger Hans Peter Freyther34a96ae2010-05-14 19:49:35 +0800390 /*
391 * Now apply blacklist/whitelist of the BSC and the NAT.
Holger Hans Peter Freyther1fd60632010-10-19 20:55:33 +0200392 * 1.) Allow directly if the IMSI is allowed at the BSC
393 * 2.) Reject if the IMSI is not allowed at the BSC
Holger Hans Peter Freyther34a96ae2010-05-14 19:49:35 +0800394 * 3.) Reject if the IMSI not allowed at the global level.
395 * 4.) Allow directly if the IMSI is allowed at the global level
396 */
Holger Hans Peter Freyther29c67032010-06-08 10:14:44 +0800397 struct bsc_nat_acc_lst *nat_lst = NULL;
398 struct bsc_nat_acc_lst *bsc_lst = NULL;
Holger Hans Peter Freyther8affef52010-06-01 01:03:13 +0800399
Holger Hans Peter Freyther29c67032010-06-08 10:14:44 +0800400 bsc_lst = bsc_nat_acc_lst_find(bsc->nat, bsc->cfg->acc_lst_name);
401 nat_lst = bsc_nat_acc_lst_find(bsc->nat, bsc->nat->acc_lst_name);
Holger Hans Peter Freyther8affef52010-06-01 01:03:13 +0800402
Holger Hans Peter Freyther34a96ae2010-05-14 19:49:35 +0800403
Holger Hans Peter Freytherd77c8172010-06-08 10:53:39 +0800404 if (bsc_lst) {
Holger Hans Peter Freyther1fd60632010-10-19 20:55:33 +0200405 /* 1. BSC allow */
Holger Hans Peter Freytherc1cac1e2010-10-11 09:50:31 +0200406 if (bsc_nat_lst_check_allow(bsc_lst, mi_string) == 0)
Holger Hans Peter Freyther1fd60632010-10-19 20:55:33 +0200407 return 1;
408
409 /* 2. BSC deny */
Holger Hans Peter Freytherd77c8172010-06-08 10:53:39 +0800410 if (lst_check_deny(bsc_lst, mi_string) == 0) {
Holger Hans Peter Freyther34a96ae2010-05-14 19:49:35 +0800411 LOGP(DNAT, LOGL_ERROR,
Holger Hans Peter Freyther48945b12010-05-16 00:45:07 +0800412 "Filtering %s by imsi_deny on bsc nr: %d.\n", mi_string, bsc->cfg->nr);
Holger Hans Peter Freyther2f1a9842010-09-25 06:14:52 +0800413 rate_ctr_inc(&bsc_lst->stats->ctr[ACC_LIST_BSC_FILTER]);
Holger Hans Peter Freyther34a96ae2010-05-14 19:49:35 +0800414 return -2;
415 }
Holger Hans Peter Freyther34a96ae2010-05-14 19:49:35 +0800416
Holger Hans Peter Freyther34a96ae2010-05-14 19:49:35 +0800417 }
418
419 /* 3. NAT deny */
Holger Hans Peter Freytherd77c8172010-06-08 10:53:39 +0800420 if (nat_lst) {
421 if (lst_check_deny(nat_lst, mi_string) == 0) {
Holger Hans Peter Freyther34a96ae2010-05-14 19:49:35 +0800422 LOGP(DNAT, LOGL_ERROR,
Holger Hans Peter Freyther48945b12010-05-16 00:45:07 +0800423 "Filtering %s by nat imsi_deny on bsc nr: %d.\n", mi_string, bsc->cfg->nr);
Holger Hans Peter Freyther0c35b5b2010-10-06 00:18:20 +0800424 rate_ctr_inc(&nat_lst->stats->ctr[ACC_LIST_NAT_FILTER]);
Holger Hans Peter Freyther34a96ae2010-05-14 19:49:35 +0800425 return -3;
426 }
427 }
428
Holger Hans Peter Freyther909e61f2010-09-15 00:41:19 +0800429 return 1;
Holger Hans Peter Freyther34a96ae2010-05-14 19:49:35 +0800430}
Holger Hans Peter Freyther290ed9a2010-05-14 08:14:09 +0800431
Holger Hans Peter Freyther749497e2010-09-29 01:19:42 +0800432static int _cr_check_loc_upd(struct bsc_connection *bsc,
433 uint8_t *data, unsigned int length,
434 char **imsi)
Holger Hans Peter Freyther290ed9a2010-05-14 08:14:09 +0800435{
Holger Hans Peter Freytherdbd16fe2010-07-23 19:08:55 +0800436 uint8_t mi_type;
Holger Hans Peter Freyther290ed9a2010-05-14 08:14:09 +0800437 struct gsm48_loc_upd_req *lu;
438 char mi_string[GSM48_MI_SIZE];
439
Holger Hans Peter Freytherf8303222010-05-14 19:24:06 +0800440 if (length < sizeof(*lu)) {
441 LOGP(DNAT, LOGL_ERROR,
442 "LU does not fit. Length is %d \n", length);
Holger Hans Peter Freyther290ed9a2010-05-14 08:14:09 +0800443 return -1;
444 }
445
446 lu = (struct gsm48_loc_upd_req *) data;
447 mi_type = lu->mi[0] & GSM_MI_TYPE_MASK;
448
449 /*
450 * We can only deal with the IMSI. This will fail for a phone that
451 * will send the TMSI of a previous network to us.
452 */
453 if (mi_type != GSM_MI_TYPE_IMSI)
454 return 0;
455
456 gsm48_mi_to_string(mi_string, sizeof(mi_string), lu->mi, lu->mi_len);
Holger Hans Peter Freyther749497e2010-09-29 01:19:42 +0800457 *imsi = talloc_strdup(bsc, mi_string);
Holger Hans Peter Freyther34a96ae2010-05-14 19:49:35 +0800458 return auth_imsi(bsc, mi_string);
Holger Hans Peter Freyther290ed9a2010-05-14 08:14:09 +0800459}
460
Holger Hans Peter Freyther749497e2010-09-29 01:19:42 +0800461static int _cr_check_cm_serv_req(struct bsc_connection *bsc,
462 uint8_t *data, unsigned int length,
Holger Hans Peter Freyther74dc3032010-09-29 02:47:29 +0800463 int *con_type, char **imsi)
Holger Hans Peter Freytherbcb32a42010-05-15 21:58:33 +0800464{
Holger Hans Peter Freyther66e1ef72010-05-16 01:13:28 +0800465 static const uint32_t classmark_offset =
466 offsetof(struct gsm48_service_request, classmark);
467
Holger Hans Peter Freytherbcb32a42010-05-15 21:58:33 +0800468 char mi_string[GSM48_MI_SIZE];
Holger Hans Peter Freyther66e1ef72010-05-16 01:13:28 +0800469 uint8_t mi_type;
470 int rc;
Holger Hans Peter Freytherbcb32a42010-05-15 21:58:33 +0800471 struct gsm48_service_request *req;
472
473 /* unfortunately in Phase1 the classmark2 length is variable */
Holger Hans Peter Freytherbcb32a42010-05-15 21:58:33 +0800474
475 if (length < sizeof(*req)) {
476 LOGP(DNAT, LOGL_ERROR,
477 "CM Serv Req does not fit. Length is %d\n", length);
478 return -1;
479 }
480
481 req = (struct gsm48_service_request *) data;
Holger Hans Peter Freyther74dc3032010-09-29 02:47:29 +0800482 if (req->cm_service_type == 0x8)
483 *con_type = NAT_CON_TYPE_SSA;
Holger Hans Peter Freyther66e1ef72010-05-16 01:13:28 +0800484 rc = gsm48_extract_mi((uint8_t *) &req->classmark,
485 length - classmark_offset, mi_string, &mi_type);
486 if (rc < 0) {
487 LOGP(DNAT, LOGL_ERROR, "Failed to parse the classmark2/mi. error: %d\n", rc);
Holger Hans Peter Freytherbcb32a42010-05-15 21:58:33 +0800488 return -1;
489 }
490
Holger Hans Peter Freytherbcb32a42010-05-15 21:58:33 +0800491 /* we have to let the TMSI or such pass */
492 if (mi_type != GSM_MI_TYPE_IMSI)
493 return 0;
494
Holger Hans Peter Freyther749497e2010-09-29 01:19:42 +0800495 *imsi = talloc_strdup(bsc, mi_string);
Holger Hans Peter Freytherbcb32a42010-05-15 21:58:33 +0800496 return auth_imsi(bsc, mi_string);
497}
498
Holger Hans Peter Freyther749497e2010-09-29 01:19:42 +0800499static int _cr_check_pag_resp(struct bsc_connection *bsc,
500 uint8_t *data, unsigned int length,
501 char **imsi)
Holger Hans Peter Freytherf1924982010-05-15 23:54:04 +0800502{
503 struct gsm48_pag_resp *resp;
504 char mi_string[GSM48_MI_SIZE];
Holger Hans Peter Freytherdbd16fe2010-07-23 19:08:55 +0800505 uint8_t mi_type;
Holger Hans Peter Freytherf1924982010-05-15 23:54:04 +0800506
507 if (length < sizeof(*resp)) {
508 LOGP(DNAT, LOGL_ERROR, "PAG RESP does not fit. Length was %d.\n", length);
509 return -1;
510 }
511
512 resp = (struct gsm48_pag_resp *) data;
513 if (gsm48_paging_extract_mi(resp, length, mi_string, &mi_type) < 0) {
514 LOGP(DNAT, LOGL_ERROR, "Failed to extract the MI.\n");
515 return -1;
516 }
517
518 /* we need to let it pass for now */
519 if (mi_type != GSM_MI_TYPE_IMSI)
520 return 0;
521
Holger Hans Peter Freyther749497e2010-09-29 01:19:42 +0800522 *imsi = talloc_strdup(bsc, mi_string);
Holger Hans Peter Freytherf1924982010-05-15 23:54:04 +0800523 return auth_imsi(bsc, mi_string);
524}
Holger Hans Peter Freyther290ed9a2010-05-14 08:14:09 +0800525
Holger Hans Peter Freyther32685402010-09-15 05:20:40 +0800526static int _dt_check_id_resp(struct bsc_connection *bsc,
527 uint8_t *data, unsigned int length,
528 struct sccp_connections *con)
529{
530 char mi_string[GSM48_MI_SIZE];
531 uint8_t mi_type;
532 int ret;
533
534 if (length < 2) {
535 LOGP(DNAT, LOGL_ERROR, "mi does not fit.\n");
536 return -1;
537 }
538
539 if (data[0] < length - 1) {
540 LOGP(DNAT, LOGL_ERROR, "mi length too big.\n");
541 return -2;
542 }
543
544 mi_type = data[1] & GSM_MI_TYPE_MASK;
545 gsm48_mi_to_string(mi_string, sizeof(mi_string), &data[1], data[0]);
546
547 if (mi_type != GSM_MI_TYPE_IMSI)
548 return 0;
549
550 ret = auth_imsi(bsc, mi_string);
551 con->imsi_checked = 1;
Holger Hans Peter Freyther8c78b482010-09-29 01:00:46 +0800552 con->imsi = talloc_strdup(con, mi_string);
Holger Hans Peter Freyther32685402010-09-15 05:20:40 +0800553 return ret;
554}
555
Holger Hans Peter Freyther290ed9a2010-05-14 08:14:09 +0800556/* Filter out CR data... */
Holger Hans Peter Freyther749497e2010-09-29 01:19:42 +0800557int bsc_nat_filter_sccp_cr(struct bsc_connection *bsc, struct msgb *msg,
558 struct bsc_nat_parsed *parsed, int *con_type,
559 char **imsi)
Holger Hans Peter Freytherb4af5c92010-05-14 03:39:56 +0800560{
Holger Hans Peter Freyther290ed9a2010-05-14 08:14:09 +0800561 struct tlv_parsed tp;
562 struct gsm48_hdr *hdr48;
563 int hdr48_len;
564 int len;
Holger Hans Peter Freyther5cde92c2011-04-13 18:56:13 +0200565 uint8_t msg_type, proto;
Holger Hans Peter Freyther290ed9a2010-05-14 08:14:09 +0800566
Holger Hans Peter Freyther19c0a842010-05-16 02:00:40 +0800567 *con_type = NAT_CON_TYPE_NONE;
Holger Hans Peter Freyther749497e2010-09-29 01:19:42 +0800568 *imsi = NULL;
Holger Hans Peter Freyther19c0a842010-05-16 02:00:40 +0800569
Holger Hans Peter Freyther290ed9a2010-05-14 08:14:09 +0800570 if (parsed->gsm_type != BSS_MAP_MSG_COMPLETE_LAYER_3) {
571 LOGP(DNAT, LOGL_ERROR,
572 "Rejecting CR message due wrong GSM Type %d\n", parsed->gsm_type);
573 return -1;
574 }
575
576 /* the parsed has had some basic l3 length check */
577 len = msg->l3h[1];
578 if (msgb_l3len(msg) - 3 < len) {
579 LOGP(DNAT, LOGL_ERROR,
580 "The CR Data has not enough space...\n");
581 return -1;
582 }
583
584 msg->l4h = &msg->l3h[3];
585 len -= 1;
586
587 tlv_parse(&tp, gsm0808_att_tlvdef(), msg->l4h, len, 0, 0);
588
589 if (!TLVP_PRESENT(&tp, GSM0808_IE_LAYER_3_INFORMATION)) {
590 LOGP(DNAT, LOGL_ERROR, "CR Data does not contain layer3 information.\n");
591 return -1;
592 }
593
594 hdr48_len = TLVP_LEN(&tp, GSM0808_IE_LAYER_3_INFORMATION);
595
596 if (hdr48_len < sizeof(*hdr48)) {
597 LOGP(DNAT, LOGL_ERROR, "GSM48 header does not fit.\n");
598 return -1;
599 }
600
601 hdr48 = (struct gsm48_hdr *) TLVP_VAL(&tp, GSM0808_IE_LAYER_3_INFORMATION);
602
Holger Hans Peter Freyther5cde92c2011-04-13 18:56:13 +0200603 proto = hdr48->proto_discr & 0x0f;
Holger Hans Peter Freyther11ebe1b2010-09-15 05:24:25 +0800604 msg_type = hdr48->msg_type & 0xbf;
Holger Hans Peter Freyther5cde92c2011-04-13 18:56:13 +0200605 if (proto == GSM48_PDISC_MM &&
Holger Hans Peter Freyther11ebe1b2010-09-15 05:24:25 +0800606 msg_type == GSM48_MT_MM_LOC_UPD_REQUEST) {
Holger Hans Peter Freyther19c0a842010-05-16 02:00:40 +0800607 *con_type = NAT_CON_TYPE_LU;
Holger Hans Peter Freyther749497e2010-09-29 01:19:42 +0800608 return _cr_check_loc_upd(bsc, &hdr48->data[0], hdr48_len - sizeof(*hdr48), imsi);
Holger Hans Peter Freyther5cde92c2011-04-13 18:56:13 +0200609 } else if (proto == GSM48_PDISC_MM &&
Holger Hans Peter Freyther11ebe1b2010-09-15 05:24:25 +0800610 msg_type == GSM48_MT_MM_CM_SERV_REQ) {
Holger Hans Peter Freyther19c0a842010-05-16 02:00:40 +0800611 *con_type = NAT_CON_TYPE_CM_SERV_REQ;
Holger Hans Peter Freyther74dc3032010-09-29 02:47:29 +0800612 return _cr_check_cm_serv_req(bsc, &hdr48->data[0],
613 hdr48_len - sizeof(*hdr48),
614 con_type, imsi);
Holger Hans Peter Freyther5cde92c2011-04-13 18:56:13 +0200615 } else if (proto == GSM48_PDISC_RR &&
Holger Hans Peter Freyther11ebe1b2010-09-15 05:24:25 +0800616 msg_type == GSM48_MT_RR_PAG_RESP) {
Holger Hans Peter Freyther19c0a842010-05-16 02:00:40 +0800617 *con_type = NAT_CON_TYPE_PAG_RESP;
Holger Hans Peter Freyther749497e2010-09-29 01:19:42 +0800618 return _cr_check_pag_resp(bsc, &hdr48->data[0], hdr48_len - sizeof(*hdr48), imsi);
Holger Hans Peter Freyther290ed9a2010-05-14 08:14:09 +0800619 } else {
Holger Hans Peter Freyther1f387472010-05-16 01:05:47 +0800620 /* We only want to filter the above, let other things pass */
Holger Hans Peter Freyther19c0a842010-05-16 02:00:40 +0800621 *con_type = NAT_CON_TYPE_OTHER;
Holger Hans Peter Freyther1f387472010-05-16 01:05:47 +0800622 return 0;
Holger Hans Peter Freyther290ed9a2010-05-14 08:14:09 +0800623 }
Holger Hans Peter Freytherb4af5c92010-05-14 03:39:56 +0800624}
Holger Hans Peter Freyther12dc89a2010-05-14 18:38:29 +0800625
Holger Hans Peter Freythera3967572010-09-29 02:30:50 +0800626struct gsm48_hdr *bsc_unpack_dtap(struct bsc_nat_parsed *parsed,
627 struct msgb *msg, uint32_t *len)
628{
629 /* gsm_type is actually the size of the dtap */
630 *len = parsed->gsm_type;
631 if (*len < msgb_l3len(msg) - 3) {
632 LOGP(DNAT, LOGL_ERROR, "Not enough space for DTAP.\n");
633 return NULL;
634 }
635
636 if (*len < sizeof(struct gsm48_hdr)) {
637 LOGP(DNAT, LOGL_ERROR, "GSM48 header does not fit.\n");
638 return NULL;
639 }
640
641 msg->l4h = &msg->l3h[3];
642 return (struct gsm48_hdr *) msg->l4h;
643}
644
Holger Hans Peter Freyther74e0a1b2010-09-15 01:11:08 +0800645int bsc_nat_filter_dt(struct bsc_connection *bsc, struct msgb *msg,
646 struct sccp_connections *con, struct bsc_nat_parsed *parsed)
647{
Holger Hans Peter Freyther32685402010-09-15 05:20:40 +0800648 uint32_t len;
Holger Hans Peter Freyther5cde92c2011-04-13 18:56:13 +0200649 uint8_t msg_type, proto;
Holger Hans Peter Freyther32685402010-09-15 05:20:40 +0800650 struct gsm48_hdr *hdr48;
651
Holger Hans Peter Freyther74e0a1b2010-09-15 01:11:08 +0800652 if (con->imsi_checked)
653 return 0;
654
Holger Hans Peter Freyther32685402010-09-15 05:20:40 +0800655 /* only care about DTAP messages */
656 if (parsed->bssap != BSSAP_MSG_DTAP)
657 return 0;
658
Holger Hans Peter Freythera3967572010-09-29 02:30:50 +0800659 hdr48 = bsc_unpack_dtap(parsed, msg, &len);
660 if (!hdr48)
Holger Hans Peter Freyther32685402010-09-15 05:20:40 +0800661 return -1;
Holger Hans Peter Freyther32685402010-09-15 05:20:40 +0800662
Holger Hans Peter Freyther5cde92c2011-04-13 18:56:13 +0200663 proto = hdr48->proto_discr & 0x0f;
Holger Hans Peter Freyther11ebe1b2010-09-15 05:24:25 +0800664 msg_type = hdr48->msg_type & 0xbf;
Holger Hans Peter Freyther5cde92c2011-04-13 18:56:13 +0200665 if (proto == GSM48_PDISC_MM &&
Holger Hans Peter Freyther11ebe1b2010-09-15 05:24:25 +0800666 msg_type == GSM48_MT_MM_ID_RESP) {
Holger Hans Peter Freyther32685402010-09-15 05:20:40 +0800667 return _dt_check_id_resp(bsc, &hdr48->data[0], len - sizeof(*hdr48), con);
668 } else {
Holger Hans Peter Freyther32685402010-09-15 05:20:40 +0800669 return 0;
670 }
Holger Hans Peter Freyther74e0a1b2010-09-15 01:11:08 +0800671}
672
Holger Hans Peter Freyther4c9557e2011-04-04 19:19:26 +0200673int bsc_parse_reg(void *ctx, regex_t *reg, char **imsi, int argc, const char **argv)
Holger Hans Peter Freyther12dc89a2010-05-14 18:38:29 +0800674{
Holger Hans Peter Freyther4c9557e2011-04-04 19:19:26 +0200675 int ret;
676
677 ret = 0;
Holger Hans Peter Freyther12dc89a2010-05-14 18:38:29 +0800678 if (*imsi) {
679 talloc_free(*imsi);
680 *imsi = NULL;
681 }
682 regfree(reg);
683
684 if (argc > 0) {
685 *imsi = talloc_strdup(ctx, argv[0]);
Holger Hans Peter Freyther4c9557e2011-04-04 19:19:26 +0200686 ret = regcomp(reg, argv[0], 0);
687
688 /* handle compilation failures */
689 if (ret != 0) {
690 talloc_free(*imsi);
691 *imsi = NULL;
692 }
Holger Hans Peter Freyther12dc89a2010-05-14 18:38:29 +0800693 }
Holger Hans Peter Freyther4c9557e2011-04-04 19:19:26 +0200694
695 return ret;
Holger Hans Peter Freyther12dc89a2010-05-14 18:38:29 +0800696}
Holger Hans Peter Freyther234d3122010-05-16 02:06:11 +0800697
698static const char *con_types [] = {
699 [NAT_CON_TYPE_NONE] = "n/a",
700 [NAT_CON_TYPE_LU] = "Location Update",
701 [NAT_CON_TYPE_CM_SERV_REQ] = "CM Serv Req",
702 [NAT_CON_TYPE_PAG_RESP] = "Paging Response",
Holger Hans Peter Freyther74dc3032010-09-29 02:47:29 +0800703 [NAT_CON_TYPE_SSA] = "Supplementar Service Activation",
Holger Hans Peter Freytherb71c23b2010-05-16 20:43:52 +0800704 [NAT_CON_TYPE_LOCAL_REJECT] = "Local Reject",
Holger Hans Peter Freyther234d3122010-05-16 02:06:11 +0800705 [NAT_CON_TYPE_OTHER] = "Other",
706};
707
708const char *bsc_con_type_to_string(int type)
709{
710 return con_types[type];
Holger Hans Peter Freyther8affef52010-06-01 01:03:13 +0800711}
712
Holger Hans Peter Freyther29c67032010-06-08 10:14:44 +0800713struct bsc_nat_acc_lst *bsc_nat_acc_lst_find(struct bsc_nat *nat, const char *name)
Holger Hans Peter Freyther8affef52010-06-01 01:03:13 +0800714{
Holger Hans Peter Freyther29c67032010-06-08 10:14:44 +0800715 struct bsc_nat_acc_lst *lst;
Holger Hans Peter Freyther8affef52010-06-01 01:03:13 +0800716
717 if (!name)
718 return NULL;
719
720 llist_for_each_entry(lst, &nat->access_lists, list)
721 if (strcmp(lst->name, name) == 0)
722 return lst;
723
724 return NULL;
725}
726
Holger Hans Peter Freyther29c67032010-06-08 10:14:44 +0800727struct bsc_nat_acc_lst *bsc_nat_acc_lst_get(struct bsc_nat *nat, const char *name)
Holger Hans Peter Freyther8affef52010-06-01 01:03:13 +0800728{
Holger Hans Peter Freyther29c67032010-06-08 10:14:44 +0800729 struct bsc_nat_acc_lst *lst;
Holger Hans Peter Freyther8affef52010-06-01 01:03:13 +0800730
Holger Hans Peter Freyther29c67032010-06-08 10:14:44 +0800731 lst = bsc_nat_acc_lst_find(nat, name);
Holger Hans Peter Freyther8affef52010-06-01 01:03:13 +0800732 if (lst)
733 return lst;
734
Holger Hans Peter Freyther29c67032010-06-08 10:14:44 +0800735 lst = talloc_zero(nat, struct bsc_nat_acc_lst);
Holger Hans Peter Freyther8affef52010-06-01 01:03:13 +0800736 if (!lst) {
737 LOGP(DNAT, LOGL_ERROR, "Failed to allocate access list");
738 return NULL;
739 }
740
Holger Hans Peter Freyther2f1a9842010-09-25 06:14:52 +0800741 /* TODO: get the index right */
742 lst->stats = rate_ctr_group_alloc(lst, &bsc_cfg_acc_list_desc, 0);
743 if (!lst->stats) {
744 talloc_free(lst);
745 return NULL;
746 }
747
Holger Hans Peter Freytherd77c8172010-06-08 10:53:39 +0800748 INIT_LLIST_HEAD(&lst->fltr_list);
Holger Hans Peter Freyther8affef52010-06-01 01:03:13 +0800749 lst->name = talloc_strdup(lst, name);
Holger Hans Peter Freyther26c3a352010-06-08 11:00:09 +0800750 llist_add_tail(&lst->list, &nat->access_lists);
Holger Hans Peter Freyther8affef52010-06-01 01:03:13 +0800751 return lst;
Holger Hans Peter Freythere4900a02010-06-03 01:44:05 +0800752}
753
Holger Hans Peter Freyther29c67032010-06-08 10:14:44 +0800754void bsc_nat_acc_lst_delete(struct bsc_nat_acc_lst *lst)
Holger Hans Peter Freythere4900a02010-06-03 01:44:05 +0800755{
756 llist_del(&lst->list);
Holger Hans Peter Freyther2f1a9842010-09-25 06:14:52 +0800757 rate_ctr_group_free(lst->stats);
Holger Hans Peter Freythere4900a02010-06-03 01:44:05 +0800758 talloc_free(lst);
Holger Hans Peter Freytherd77c8172010-06-08 10:53:39 +0800759}
760
761struct bsc_nat_acc_lst_entry *bsc_nat_acc_lst_entry_create(struct bsc_nat_acc_lst *lst)
762{
763 struct bsc_nat_acc_lst_entry *entry;
764
765 entry = talloc_zero(lst, struct bsc_nat_acc_lst_entry);
766 if (!entry)
767 return NULL;
768
Holger Hans Peter Freyther26c3a352010-06-08 11:00:09 +0800769 llist_add_tail(&entry->list, &lst->fltr_list);
Holger Hans Peter Freytherd77c8172010-06-08 10:53:39 +0800770 return entry;
Holger Hans Peter Freytherb2c38eb2010-06-17 18:16:00 +0800771}
Holger Hans Peter Freyther20ee3122010-07-05 14:39:44 +0800772
773int bsc_nat_msc_is_connected(struct bsc_nat *nat)
774{
775 return nat->msc_con->is_connected;
776}
Holger Hans Peter Freyther463dc622010-10-03 19:41:42 +0800777
778static const int con_to_ctr[] = {
779 [NAT_CON_TYPE_NONE] = -1,
780 [NAT_CON_TYPE_LU] = BCFG_CTR_CON_TYPE_LU,
781 [NAT_CON_TYPE_CM_SERV_REQ] = BCFG_CTR_CON_CMSERV_RQ,
782 [NAT_CON_TYPE_PAG_RESP] = BCFG_CTR_CON_PAG_RESP,
Holger Hans Peter Freyther74dc3032010-09-29 02:47:29 +0800783 [NAT_CON_TYPE_SSA] = BCFG_CTR_CON_SSA,
Holger Hans Peter Freyther463dc622010-10-03 19:41:42 +0800784 [NAT_CON_TYPE_LOCAL_REJECT] = -1,
785 [NAT_CON_TYPE_OTHER] = BCFG_CTR_CON_OTHER,
786};
787
788int bsc_conn_type_to_ctr(struct sccp_connections *conn)
789{
790 return con_to_ctr[conn->con_type];
791}
Holger Hans Peter Freyther69cfa172010-10-13 20:37:13 +0200792
Pablo Neira Ayuso4db92992011-05-06 12:11:23 +0200793int bsc_write_cb(struct osmo_fd *bfd, struct msgb *msg)
Holger Hans Peter Freyther69cfa172010-10-13 20:37:13 +0200794{
795 int rc;
796
797 rc = write(bfd->fd, msg->data, msg->len);
798 if (rc != msg->len)
799 LOGP(DNAT, LOGL_ERROR, "Failed to write message to the BSC.\n");
800
801 return rc;
802}
803
Holger Hans Peter Freyther20102b02011-05-18 18:41:14 +0200804static char *rewrite_non_international(struct bsc_nat *nat, void *ctx, const char *imsi,
805 struct gsm_mncc_number *called)
806{
Holger Hans Peter Freytherad75eab2011-05-27 12:38:58 +0200807 struct bsc_nat_num_rewr_entry *entry;
Holger Hans Peter Freyther20102b02011-05-18 18:41:14 +0200808 char *new_number = NULL;
809
Holger Hans Peter Freytherad75eab2011-05-27 12:38:58 +0200810 if (llist_empty(&nat->num_rewr))
Holger Hans Peter Freyther20102b02011-05-18 18:41:14 +0200811 return NULL;
812
813 if (called->plan != 1)
814 return NULL;
815 if (called->type == 1)
816 return NULL;
Holger Hans Peter Freyther20102b02011-05-18 18:41:14 +0200817
818 /* need to find a replacement and then fix it */
Holger Hans Peter Freytherad75eab2011-05-27 12:38:58 +0200819 llist_for_each_entry(entry, &nat->num_rewr, list) {
Holger Hans Peter Freyther20102b02011-05-18 18:41:14 +0200820 regmatch_t matches[2];
821
Holger Hans Peter Freytherad75eab2011-05-27 12:38:58 +0200822 /* check the IMSI match */
823 if (regexec(&entry->msisdn_reg, imsi, 0, NULL, 0) != 0)
Holger Hans Peter Freyther20102b02011-05-18 18:41:14 +0200824 continue;
Holger Hans Peter Freyther20102b02011-05-18 18:41:14 +0200825
826 /* this regexp matches... */
Holger Hans Peter Freytherad75eab2011-05-27 12:38:58 +0200827 if (regexec(&entry->num_reg, called->number, 2, matches, 0) == 0 &&
Holger Hans Peter Freyther20102b02011-05-18 18:41:14 +0200828 matches[1].rm_eo != -1)
829 new_number = talloc_asprintf(ctx, "%s%s",
Holger Hans Peter Freytherad75eab2011-05-27 12:38:58 +0200830 entry->replace,
Holger Hans Peter Freyther20102b02011-05-18 18:41:14 +0200831 &called->number[matches[1].rm_so]);
Holger Hans Peter Freyther20102b02011-05-18 18:41:14 +0200832 if (new_number)
833 break;
834 }
835
836 return new_number;
837}
838
839
Holger Hans Peter Freythera914daf2010-10-21 12:12:57 +0200840/**
841 * Rewrite non global numbers... according to rules based on the IMSI
842 */
Holger Hans Peter Freytherdf8e6e92011-05-27 14:09:55 +0200843static struct msgb *rewrite_setup(struct bsc_nat *nat, struct msgb *msg,
844 struct bsc_nat_parsed *parsed, const char *imsi,
845 struct gsm48_hdr *hdr48, const uint32_t len)
Holger Hans Peter Freythera914daf2010-10-21 12:12:57 +0200846{
Holger Hans Peter Freyther73bbf892010-10-21 14:46:57 +0200847 struct tlv_parsed tp;
Holger Hans Peter Freyther73bbf892010-10-21 14:46:57 +0200848 unsigned int payload_len;
849 struct gsm_mncc_number called;
Holger Hans Peter Freyther2e2ff342011-05-27 14:22:58 +0200850 struct msgb *out;
Holger Hans Peter Freytherdf8e6e92011-05-27 14:09:55 +0200851 char *new_number = NULL;
Holger Hans Peter Freyther73bbf892010-10-21 14:46:57 +0200852 uint8_t *outptr;
853 const uint8_t *msgptr;
854 int sec_len;
855
Holger Hans Peter Freyther73bbf892010-10-21 14:46:57 +0200856 /* decode and rewrite the message */
857 payload_len = len - sizeof(*hdr48);
858 tlv_parse(&tp, &gsm48_att_tlvdef, hdr48->data, payload_len, 0, 0);
859
860 /* no number, well let us ignore it */
861 if (!TLVP_PRESENT(&tp, GSM48_IE_CALLED_BCD))
Holger Hans Peter Freyther2e2ff342011-05-27 14:22:58 +0200862 return NULL;
Holger Hans Peter Freyther73bbf892010-10-21 14:46:57 +0200863
864 memset(&called, 0, sizeof(called));
865 gsm48_decode_called(&called,
866 TLVP_VAL(&tp, GSM48_IE_CALLED_BCD) - 1);
867
868 /* check if it looks international and stop */
Holger Hans Peter Freyther20102b02011-05-18 18:41:14 +0200869 new_number = rewrite_non_international(nat, msg, imsi, &called);
Holger Hans Peter Freyther73bbf892010-10-21 14:46:57 +0200870
871 if (!new_number) {
872 LOGP(DNAT, LOGL_DEBUG, "No IMSI match found, returning message.\n");
Holger Hans Peter Freyther2e2ff342011-05-27 14:22:58 +0200873 return NULL;
Holger Hans Peter Freyther73bbf892010-10-21 14:46:57 +0200874 }
875
Holger Hans Peter Freyther4446b3b2011-02-10 11:41:49 +0100876 if (strlen(new_number) > sizeof(called.number)) {
877 LOGP(DNAT, LOGL_ERROR, "Number is too long for structure.\n");
878 talloc_free(new_number);
Holger Hans Peter Freyther2e2ff342011-05-27 14:22:58 +0200879 return NULL;
Holger Hans Peter Freyther4446b3b2011-02-10 11:41:49 +0100880 }
881
Holger Hans Peter Freyther73bbf892010-10-21 14:46:57 +0200882 /*
883 * Need to create a new message now based on the old onew
884 * with a new number. We can sadly not patch this in place
885 * so we will need to regenerate it.
886 */
887
888 out = msgb_alloc_headroom(4096, 128, "changed-setup");
889 if (!out) {
890 LOGP(DNAT, LOGL_ERROR, "Failed to allocate.\n");
891 talloc_free(new_number);
Holger Hans Peter Freyther2e2ff342011-05-27 14:22:58 +0200892 return NULL;
Holger Hans Peter Freyther73bbf892010-10-21 14:46:57 +0200893 }
894
895 /* copy the header */
896 outptr = msgb_put(out, sizeof(*hdr48));
897 memcpy(outptr, hdr48, sizeof(*hdr48));
898
899 /* copy everything up to the number */
900 sec_len = TLVP_VAL(&tp, GSM48_IE_CALLED_BCD) - 2 - &hdr48->data[0];
901 outptr = msgb_put(out, sec_len);
902 memcpy(outptr, &hdr48->data[0], sec_len);
903
904 /* create the new number */
Holger Hans Peter Freyther91fa8502011-02-10 11:46:51 +0100905 if (strncmp(new_number, "00", 2) == 0) {
906 called.type = 1;
907 strncpy(called.number, new_number + 2, sizeof(called.number));
908 } else {
909 strncpy(called.number, new_number, sizeof(called.number));
910 }
Holger Hans Peter Freyther73bbf892010-10-21 14:46:57 +0200911 gsm48_encode_called(out, &called);
912
913 /* copy thre rest */
914 msgptr = TLVP_VAL(&tp, GSM48_IE_CALLED_BCD) +
915 TLVP_LEN(&tp, GSM48_IE_CALLED_BCD);
916 sec_len = payload_len - (msgptr - &hdr48->data[0]);
917 outptr = msgb_put(out, sec_len);
918 memcpy(outptr, msgptr, sec_len);
919
Holger Hans Peter Freyther73bbf892010-10-21 14:46:57 +0200920 talloc_free(new_number);
Holger Hans Peter Freyther2e2ff342011-05-27 14:22:58 +0200921 return out;
Holger Hans Peter Freythera914daf2010-10-21 12:12:57 +0200922}
Holger Hans Peter Freyther73bbf892010-10-21 14:46:57 +0200923
Holger Hans Peter Freyther9c205712011-05-27 17:14:15 +0200924static struct msgb *rewrite_smsc(struct bsc_nat *nat, struct msgb *msg,
925 struct bsc_nat_parsed *parsed, const char *imsi,
926 struct gsm48_hdr *hdr48, const uint32_t len)
927{
928 unsigned int payload_len;
929 unsigned int cp_len;
930
931 uint8_t ref;
932 uint8_t orig_addr_len, *orig_addr_ptr;
933 uint8_t dest_addr_len, *dest_addr_ptr;
934 uint8_t data_len, *data_ptr;
935 char smsc_addr[30];
936 uint8_t new_addr[12];
937
938 struct bsc_nat_num_rewr_entry *entry;
939 char *new_number = NULL;
940 uint8_t new_addr_len;
941 struct gsm48_hdr *new_hdr48;
942 struct msgb *out;
943
944 payload_len = len - sizeof(*hdr48);
945 if (payload_len < 1) {
946 LOGP(DNAT, LOGL_ERROR, "SMS too short for things. %d\n", payload_len);
947 return NULL;
948 }
949
950 cp_len = hdr48->data[0];
951 if (payload_len + 1 < cp_len) {
952 LOGP(DNAT, LOGL_ERROR, "SMS RPDU can not fit in: %d %d\n", cp_len, payload_len);
953 return NULL;
954 }
955
956 if (hdr48->data[1] != GSM411_MT_RP_DATA_MO)
957 return NULL;
958
959 if (cp_len < 5) {
960 LOGP(DNAT, LOGL_ERROR, "RD-DATA can not fit in the CP len: %d\n", cp_len);
961 return NULL;
962 }
963
964 ref = hdr48->data[2];
965 orig_addr_len = hdr48->data[3];
966 orig_addr_ptr = &hdr48->data[4];
967
968 /* the +1 is for checking if the following element has some space */
969 if (cp_len < 3 + orig_addr_len + 1) {
970 LOGP(DNAT, LOGL_ERROR, "RP-Originator addr does not fit: %d\n", orig_addr_len);
971 return NULL;
972 }
973
974 dest_addr_len = hdr48->data[3 + orig_addr_len + 1];
975 dest_addr_ptr = &hdr48->data[3 + orig_addr_len + 2];
976
977 if (cp_len < 3 + orig_addr_len + 1 + dest_addr_len + 1) {
978 LOGP(DNAT, LOGL_ERROR, "RP-Destination addr does not fit: %d\n", dest_addr_len);
979 return NULL;
980 }
981 gsm48_decode_bcd_number(smsc_addr, ARRAY_SIZE(smsc_addr), dest_addr_ptr - 1, 1);
982
983 data_len = hdr48->data[3 + orig_addr_len + 1 + dest_addr_len + 1];
984 data_ptr = &hdr48->data[3 + orig_addr_len + 1 + dest_addr_len + 2];
985
986 if (cp_len < 3 + orig_addr_len + 1 + dest_addr_len + 1 + data_len) {
987 LOGP(DNAT, LOGL_ERROR, "RP-Data does not fit: %d\n", data_len);
988 return NULL;
989 }
990
991 /* We will find a new number now */
992 llist_for_each_entry(entry, &nat->smsc_rewr, list) {
993 regmatch_t matches[2];
994
995 /* check the IMSI match */
996 if (regexec(&entry->msisdn_reg, imsi, 0, NULL, 0) != 0)
997 continue;
998
999 /* this regexp matches... */
1000 if (regexec(&entry->num_reg, smsc_addr, 2, matches, 0) == 0 &&
1001 matches[1].rm_eo != -1)
1002 new_number = talloc_asprintf(msg, "%s%s",
1003 entry->replace,
1004 &smsc_addr[matches[1].rm_so]);
1005 if (new_number)
1006 break;
1007 }
1008
1009 if (!new_number)
1010 return NULL;
1011
1012 /*
1013 * We need to re-create the patched structure. This is why we have
1014 * saved the above pointers.
1015 */
1016 out = msgb_alloc_headroom(4096, 128, "changed-smsc");
1017 if (!out) {
1018 LOGP(DNAT, LOGL_ERROR, "Failed to allocate.\n");
1019 return NULL;
1020 }
1021
1022 out->l3h = out->data;
1023 msgb_v_put(out, GSM411_MT_RP_DATA_MO);
1024 msgb_v_put(out, ref);
1025 msgb_lv_put(out, orig_addr_len, orig_addr_ptr);
1026
1027 /*
1028 * Copy the new number. We let libosmocore encode it, then set
1029 * the extension followed after the length. For our convenience
1030 * we let the TLV code re-add the length so we start copying
1031 * from &new_addr[1].
1032 */
1033 new_addr_len = gsm48_encode_bcd_number(new_addr, ARRAY_SIZE(new_addr),
1034 1, new_number);
1035 new_addr[1] = 0x91;
1036 msgb_lv_put(out, new_addr_len - 1, new_addr + 1);
1037
1038 msgb_lv_put(out, data_len, data_ptr);
1039
1040 new_hdr48 = (struct gsm48_hdr *) msgb_push(out, sizeof(*hdr48) + 1);
1041 memcpy(new_hdr48, hdr48, sizeof(*hdr48));
1042 new_hdr48->data[0] = msgb_l3len(out);
1043
1044 talloc_free(new_number);
1045 return out;
1046}
1047
Holger Hans Peter Freytherdf8e6e92011-05-27 14:09:55 +02001048struct msgb *bsc_nat_rewrite_msg(struct bsc_nat *nat, struct msgb *msg, struct bsc_nat_parsed *parsed, const char *imsi)
1049{
1050 struct gsm48_hdr *hdr48;
1051 uint32_t len;
1052 uint8_t msg_type, proto;
Holger Hans Peter Freyther2e2ff342011-05-27 14:22:58 +02001053 struct msgb *new_msg = NULL, *sccp;
Holger Hans Peter Freytherdf8e6e92011-05-27 14:09:55 +02001054
1055 if (!imsi || strlen(imsi) < 5)
1056 return msg;
1057
1058 /* only care about DTAP messages */
1059 if (parsed->bssap != BSSAP_MSG_DTAP)
1060 return msg;
1061 if (!parsed->dest_local_ref)
1062 return msg;
1063
1064 hdr48 = bsc_unpack_dtap(parsed, msg, &len);
1065 if (!hdr48)
1066 return msg;
1067
1068 proto = hdr48->proto_discr & 0x0f;
1069 msg_type = hdr48->msg_type & 0xbf;
1070
1071 if (proto == GSM48_PDISC_CC && msg_type == GSM48_MT_CC_SETUP)
Holger Hans Peter Freyther2e2ff342011-05-27 14:22:58 +02001072 new_msg = rewrite_setup(nat, msg, parsed, imsi, hdr48, len);
Holger Hans Peter Freyther9c205712011-05-27 17:14:15 +02001073 else if (proto == GSM48_PDISC_SMS && msg_type == GSM411_MT_CP_DATA)
1074 new_msg = rewrite_smsc(nat, msg, parsed, imsi, hdr48, len);
Holger Hans Peter Freytherdf8e6e92011-05-27 14:09:55 +02001075
Holger Hans Peter Freyther2e2ff342011-05-27 14:22:58 +02001076 if (!new_msg)
1077 return msg;
1078
1079 /* wrap with DTAP, SCCP, then IPA. TODO: Stop copying */
1080 gsm0808_prepend_dtap_header(new_msg, 0);
1081 sccp = sccp_create_dt1(parsed->dest_local_ref, new_msg->data, new_msg->len);
1082 talloc_free(new_msg);
1083
1084 if (!sccp) {
1085 LOGP(DNAT, LOGL_ERROR, "Failed to allocate.\n");
1086 return msg;
1087 }
1088
1089 ipaccess_prepend_header(sccp, IPAC_PROTO_SCCP);
1090
1091 /* the parsed hangs off from msg but it needs to survive */
1092 talloc_steal(sccp, parsed);
1093 msgb_free(msg);
1094 return sccp;
Holger Hans Peter Freytherdf8e6e92011-05-27 14:09:55 +02001095}
Holger Hans Peter Freyther2e2ff342011-05-27 14:22:58 +02001096
Holger Hans Peter Freytherad75eab2011-05-27 12:38:58 +02001097static void num_rewr_free_data(struct bsc_nat_num_rewr_entry *entry)
1098{
1099 regfree(&entry->msisdn_reg);
1100 regfree(&entry->num_reg);
1101 talloc_free(entry->replace);
1102}
1103
Holger Hans Peter Freyther9c205712011-05-27 17:14:15 +02001104void bsc_nat_num_rewr_entry_adapt(void *ctx, struct llist_head *head,
1105 const struct osmo_config_list *list)
Holger Hans Peter Freytherad75eab2011-05-27 12:38:58 +02001106{
1107 struct bsc_nat_num_rewr_entry *entry, *tmp;
1108 struct osmo_config_entry *cfg_entry;
1109
1110 /* free the old data */
Holger Hans Peter Freyther9c205712011-05-27 17:14:15 +02001111 llist_for_each_entry_safe(entry, tmp, head, list) {
Holger Hans Peter Freytherad75eab2011-05-27 12:38:58 +02001112 num_rewr_free_data(entry);
1113 llist_del(&entry->list);
1114 talloc_free(entry);
1115 }
1116
1117
1118 if (!list)
1119 return;
1120
1121 llist_for_each_entry(cfg_entry, &list->entry, list) {
1122 char *regexp;
1123 if (cfg_entry->text[0] == '+') {
1124 LOGP(DNAT, LOGL_ERROR,
1125 "Plus is not allowed in the number\n");
1126 continue;
1127 }
1128
Holger Hans Peter Freyther9c205712011-05-27 17:14:15 +02001129 entry = talloc_zero(ctx, struct bsc_nat_num_rewr_entry);
Holger Hans Peter Freytherad75eab2011-05-27 12:38:58 +02001130 if (!entry) {
1131 LOGP(DNAT, LOGL_ERROR,
1132 "Allication of the num_rewr entry failed.\n");
1133 continue;
1134 }
1135
1136 entry->replace = talloc_strdup(entry, cfg_entry->text);
1137 if (!entry->replace) {
1138 LOGP(DNAT, LOGL_ERROR,
1139 "Failed to copy the replacement text.\n");
1140 talloc_free(entry);
1141 continue;
1142 }
1143
1144 /* we will now build a regexp string */
1145 if (cfg_entry->mcc[0] == '^') {
1146 regexp = talloc_strdup(entry, cfg_entry->mcc);
1147 } else {
1148 regexp = talloc_asprintf(entry, "^%s%s",
1149 cfg_entry->mcc[0] == '*' ?
1150 "[0-9][0-9][0-9]" : cfg_entry->mcc,
1151 cfg_entry->mnc[0] == '*' ?
1152 "[0-9][0-9]" : cfg_entry->mnc);
1153 }
1154
1155 if (!regexp) {
1156 LOGP(DNAT, LOGL_ERROR, "Failed to create a regexp string.\n");
1157 talloc_free(entry);
1158 continue;
1159 }
1160
1161 if (regcomp(&entry->msisdn_reg, regexp, 0) != 0) {
1162 LOGP(DNAT, LOGL_ERROR,
1163 "Failed to compile regexp '%s'\n", regexp);
1164 talloc_free(regexp);
1165 talloc_free(entry);
1166 continue;
1167 }
1168
1169 talloc_free(regexp);
1170 if (regcomp(&entry->num_reg, cfg_entry->option, REG_EXTENDED) != 0) {
1171 LOGP(DNAT, LOGL_ERROR,
1172 "Failed to compile regexp '%s\n'", cfg_entry->option);
1173 regfree(&entry->msisdn_reg);
1174 talloc_free(entry);
1175 continue;
1176 }
1177
1178 /* we have copied the number */
Holger Hans Peter Freyther9c205712011-05-27 17:14:15 +02001179 llist_add_tail(&entry->list, head);
Holger Hans Peter Freytherad75eab2011-05-27 12:38:58 +02001180 }
1181}