blob: 6c92f8334555018663e9bb080ccc00f13335246c [file] [log] [blame]
Harald Welte9b455bf2010-03-14 15:45:01 +08001/* GPRS LLC protocol implementation as per 3GPP TS 04.64 */
2
Harald Weltea2665542010-05-02 09:28:11 +02003/* (C) 2009-2010 by Harald Welte <laforge@gnumonks.org>
Harald Welte9b455bf2010-03-14 15:45:01 +08004 *
5 * All Rights Reserved
6 *
7 * This program is free software; you can redistribute it and/or modify
Harald Welte9af6ddf2011-01-01 15:25:50 +01008 * it under the terms of the GNU Affero General Public License as published by
9 * the Free Software Foundation; either version 3 of the License, or
Harald Welte9b455bf2010-03-14 15:45:01 +080010 * (at your option) any later version.
11 *
12 * This program is distributed in the hope that it will be useful,
13 * but WITHOUT ANY WARRANTY; without even the implied warranty of
14 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
Harald Welte9af6ddf2011-01-01 15:25:50 +010015 * GNU Affero General Public License for more details.
Harald Welte9b455bf2010-03-14 15:45:01 +080016 *
Harald Welte9af6ddf2011-01-01 15:25:50 +010017 * You should have received a copy of the GNU Affero General Public License
18 * along with this program. If not, see <http://www.gnu.org/licenses/>.
Harald Welte9b455bf2010-03-14 15:45:01 +080019 *
20 */
21
22#include <errno.h>
Harald Welteeaa614c2010-05-02 11:26:34 +020023#include <stdint.h>
Max82040102016-07-06 11:59:18 +020024#include <stdbool.h>
Harald Welte9b455bf2010-03-14 15:45:01 +080025
Pablo Neira Ayuso136f4532011-03-22 16:47:59 +010026#include <osmocom/core/msgb.h>
27#include <osmocom/core/linuxlist.h>
28#include <osmocom/core/timer.h>
29#include <osmocom/core/talloc.h>
Alexander Couzens4e699a92016-07-05 11:04:27 +020030#include <osmocom/core/rate_ctr.h>
Harald Welteea34a4e2012-06-16 14:59:56 +080031#include <osmocom/gprs/gprs_bssgp.h>
Neels Hofmeyree6cfdc2017-07-13 02:03:50 +020032#include <osmocom/gsm/gsm_utils.h>
Harald Weltea2665542010-05-02 09:28:11 +020033
Neels Hofmeyr396f2e62017-09-04 15:13:25 +020034#include <osmocom/sgsn/debug.h>
35#include <osmocom/sgsn/gprs_sgsn.h>
36#include <osmocom/sgsn/gprs_gmm.h>
37#include <osmocom/sgsn/gprs_llc.h>
38#include <osmocom/sgsn/crc24.h>
39#include <osmocom/sgsn/sgsn.h>
40#include <osmocom/sgsn/gprs_llc_xid.h>
41#include <osmocom/sgsn/gprs_sndcp_comp.h>
42#include <osmocom/sgsn/gprs_sndcp.h>
Harald Welte9b455bf2010-03-14 15:45:01 +080043
Holger Hans Peter Freyther964a9b32013-07-30 09:29:27 +020044static struct gprs_llc_llme *llme_alloc(uint32_t tlli);
Philipp4ac3aee2016-08-10 12:24:09 +020045static int gprs_llc_tx_xid(struct gprs_llc_lle *lle, struct msgb *msg,
46 int command);
47static int gprs_llc_tx_u(struct msgb *msg, uint8_t sapi,
48 int command, enum gprs_llc_u_cmd u_cmd, int pf_bit);
49
50/* BEGIN XID RELATED */
51
52/* Generate XID message */
53static int gprs_llc_generate_xid(uint8_t *bytes, int bytes_len,
54 struct gprs_llc_xid_field *l3_xid_field,
55 struct gprs_llc_llme *llme)
56{
57 /* Note: Called by gprs_ll_xid_req() */
58
59 LLIST_HEAD(xid_fields);
60
61 struct gprs_llc_xid_field xid_version;
62 struct gprs_llc_xid_field xid_n201u;
63 struct gprs_llc_xid_field xid_n201i;
64
65 xid_version.type = GPRS_LLC_XID_T_VERSION;
66 xid_version.data = (uint8_t *) "\x00";
67 xid_version.data_len = 1;
68
69 xid_n201u.type = GPRS_LLC_XID_T_N201_U;
70 xid_n201u.data = (uint8_t *) "\x05\xf0";
71 xid_n201u.data_len = 2;
72
73 xid_n201i.type = GPRS_LLC_XID_T_N201_I;
74 xid_n201i.data = (uint8_t *) "\x05\xf0";
75 xid_n201i.data_len = 2;
76
77 /* Add locally managed XID Fields */
Philipp4ac3aee2016-08-10 12:24:09 +020078 llist_add(&xid_version.list, &xid_fields);
Philippf788d932016-12-05 12:44:19 +010079 llist_add(&xid_n201u.list, &xid_fields);
80 llist_add(&xid_n201i.list, &xid_fields);
Philipp4ac3aee2016-08-10 12:24:09 +020081
82 /* Append layer 3 XID field (if present) */
83 if (l3_xid_field) {
84 /* Enforce layer 3 XID type (just to be sure) */
85 l3_xid_field->type = GPRS_LLC_XID_T_L3_PAR;
86
87 /* Add Layer 3 XID field to the list */
88 llist_add(&l3_xid_field->list, &xid_fields);
89 }
90
91 /* Store generated XID for later reference */
92 talloc_free(llme->xid);
93 llme->xid = gprs_llc_copy_xid(llme, &xid_fields);
94
95 return gprs_llc_compile_xid(bytes, bytes_len, &xid_fields);
96}
97
98/* Generate XID message that will cause the GMM to reset */
99static int gprs_llc_generate_xid_for_gmm_reset(uint8_t *bytes,
100 int bytes_len, uint32_t iov_ui,
101 struct gprs_llc_llme *llme)
102{
103 /* Called by gprs_llgmm_reset() and
104 * gprs_llgmm_reset_oldmsg() */
105
106 LLIST_HEAD(xid_fields);
107
108 struct gprs_llc_xid_field xid_reset;
109 struct gprs_llc_xid_field xid_iovui;
110
111 /* First XID component must be RESET */
112 xid_reset.type = GPRS_LLC_XID_T_RESET;
113 xid_reset.data = NULL;
114 xid_reset.data_len = 0;
115
116 /* Add new IOV-UI */
117 xid_iovui.type = GPRS_LLC_XID_T_IOV_UI;
118 xid_iovui.data = (uint8_t *) & iov_ui;
119 xid_iovui.data_len = 4;
120
121 /* Add locally managed XID Fields */
122 llist_add(&xid_iovui.list, &xid_fields);
123 llist_add(&xid_reset.list, &xid_fields);
124
125 /* Store generated XID for later reference */
126 talloc_free(llme->xid);
127 llme->xid = gprs_llc_copy_xid(llme, &xid_fields);
128
129 return gprs_llc_compile_xid(bytes, bytes_len, &xid_fields);
130}
131
132/* Process an incoming XID confirmation */
133static int gprs_llc_process_xid_conf(uint8_t *bytes, int bytes_len,
134 struct gprs_llc_lle *lle)
135{
136 /* Note: This function handles the response of a network originated
Philipp532480a2016-12-23 11:05:11 +0100137 * XID-Request. There XID messages reflected by the MS are analyzed
Philipp4ac3aee2016-08-10 12:24:09 +0200138 * and processed here. The caller is called by rx_llc_xid(). */
139
140 struct llist_head *xid_fields;
141 struct gprs_llc_xid_field *xid_field;
Philippf1f34362016-08-26 17:00:21 +0200142 struct gprs_llc_xid_field *xid_field_request;
143 struct gprs_llc_xid_field *xid_field_request_l3 = NULL;
144
145 /* Pick layer3 XID from the XID request we have sent last */
146 if (lle->llme->xid) {
147 llist_for_each_entry(xid_field_request, lle->llme->xid, list) {
148 if (xid_field_request->type == GPRS_LLC_XID_T_L3_PAR)
149 xid_field_request_l3 = xid_field_request;
150 }
151 }
Philipp4ac3aee2016-08-10 12:24:09 +0200152
153 /* Parse and analyze XID-Response */
154 xid_fields = gprs_llc_parse_xid(NULL, bytes, bytes_len);
155
156 if (xid_fields) {
157
158 gprs_llc_dump_xid_fields(xid_fields, LOGL_DEBUG);
159 llist_for_each_entry(xid_field, xid_fields, list) {
160
161 /* Forward SNDCP-XID fields to Layer 3 (SNDCP) */
Philippf1f34362016-08-26 17:00:21 +0200162 if (xid_field->type == GPRS_LLC_XID_T_L3_PAR &&
163 xid_field_request_l3) {
164 sndcp_sn_xid_conf(xid_field,
165 xid_field_request_l3, lle);
Philipp4ac3aee2016-08-10 12:24:09 +0200166 }
167
168 /* Process LLC-XID fields: */
169 else {
170
171 /* FIXME: Do something more useful with the
172 * echoed XID-Information. Currently we
173 * just ignore the response completely and
174 * by doing so we blindly accept any changes
175 * the MS might have done to the our XID
176 * inquiry. There is a remainig risk of
177 * malfunction! */
178 LOGP(DLLC, LOGL_NOTICE,
Max549ebc72016-11-18 14:07:04 +0100179 "Ignoring XID-Field: XID: type %s, data_len=%d, data=%s\n",
180 get_value_string(gprs_llc_xid_type_names,
181 xid_field->type),
182 xid_field->data_len,
Philipp4ac3aee2016-08-10 12:24:09 +0200183 osmo_hexdump_nospc(xid_field->data,
184 xid_field->data_len));
185 }
186 }
187 talloc_free(xid_fields);
188 }
189
190 /* Flush pending XID fields */
191 talloc_free(lle->llme->xid);
192 lle->llme->xid = NULL;
193
194 return 0;
195}
196
197/* Process an incoming XID indication and generate an appropiate response */
198static int gprs_llc_process_xid_ind(uint8_t *bytes_request,
199 int bytes_request_len,
200 uint8_t *bytes_response,
201 int bytes_response_maxlen,
202 struct gprs_llc_lle *lle)
203{
204 /* Note: This function computes the response that is sent back to the
Philipp532480a2016-12-23 11:05:11 +0100205 * MS when a mobile originated XID is received. The function is
Philipp4ac3aee2016-08-10 12:24:09 +0200206 * called by rx_llc_xid() */
207
208 int rc = -EINVAL;
209
210 struct llist_head *xid_fields;
211 struct llist_head *xid_fields_response;
212
213 struct gprs_llc_xid_field *xid_field;
214 struct gprs_llc_xid_field *xid_field_response;
215
Philipp4ac3aee2016-08-10 12:24:09 +0200216 /* Parse and analyze XID-Request */
217 xid_fields =
218 gprs_llc_parse_xid(lle->llme, bytes_request, bytes_request_len);
219 if (xid_fields) {
220 xid_fields_response = talloc_zero(lle->llme, struct llist_head);
221 INIT_LLIST_HEAD(xid_fields_response);
222 gprs_llc_dump_xid_fields(xid_fields, LOGL_DEBUG);
223
224 /* Process LLC-XID fields: */
225 llist_for_each_entry(xid_field, xid_fields, list) {
226
227 if (xid_field->type != GPRS_LLC_XID_T_L3_PAR) {
228 /* FIXME: Check the incoming XID parameters for
229 * for validity. Currently we just blindly
230 * accept all XID fields by just echoing them.
231 * There is a remaining risk of malfunction
Philipp532480a2016-12-23 11:05:11 +0100232 * when a MS submits values which defer from
Philipp4ac3aee2016-08-10 12:24:09 +0200233 * the default! */
234 LOGP(DLLC, LOGL_NOTICE,
Max549ebc72016-11-18 14:07:04 +0100235 "Echoing XID-Field: XID: type %s, data_len=%d, data=%s\n",
236 get_value_string(gprs_llc_xid_type_names,
237 xid_field->type),
238 xid_field->data_len,
Philipp4ac3aee2016-08-10 12:24:09 +0200239 osmo_hexdump_nospc(xid_field->data,
240 xid_field->data_len));
241 xid_field_response =
242 gprs_llc_dup_xid_field
243 (lle->llme, xid_field);
244 llist_add(&xid_field_response->list,
245 xid_fields_response);
246 }
247 }
248
Philippf1f34362016-08-26 17:00:21 +0200249 /* Forward SNDCP-XID fields to Layer 3 (SNDCP) */
250 llist_for_each_entry(xid_field, xid_fields, list) {
251 if (xid_field->type == GPRS_LLC_XID_T_L3_PAR) {
252
253 xid_field_response =
254 talloc_zero(lle->llme,
255 struct gprs_llc_xid_field);
256 rc = sndcp_sn_xid_ind(xid_field,
257 xid_field_response, lle);
258 if (rc == 0)
259 llist_add(&xid_field_response->list,
260 xid_fields_response);
261 else
262 talloc_free(xid_field_response);
263 }
264 }
265
Philipp4ac3aee2016-08-10 12:24:09 +0200266 rc = gprs_llc_compile_xid(bytes_response,
267 bytes_response_maxlen,
268 xid_fields_response);
269 talloc_free(xid_fields_response);
270 talloc_free(xid_fields);
271 }
272
273 return rc;
274}
275
Philipp532480a2016-12-23 11:05:11 +0100276/* Dispatch XID indications and responses comming from the MS */
Philipp4ac3aee2016-08-10 12:24:09 +0200277static void rx_llc_xid(struct gprs_llc_lle *lle,
278 struct gprs_llc_hdr_parsed *gph)
279{
280 uint8_t response[1024];
281 int response_len;
282
283 /* FIXME: 8.5.3.3: check if XID is invalid */
284 if (gph->is_cmd) {
285 LOGP(DLLC, LOGL_NOTICE,
Philipp532480a2016-12-23 11:05:11 +0100286 "Received XID indication from MS.\n");
Philipp4ac3aee2016-08-10 12:24:09 +0200287
288 struct msgb *resp;
289 uint8_t *xid;
290 resp = msgb_alloc_headroom(4096, 1024, "LLC_XID");
291
292 response_len =
293 gprs_llc_process_xid_ind(gph->data, gph->data_len,
294 response, sizeof(response),
295 lle);
Philippf1f34362016-08-26 17:00:21 +0200296 if (response_len < 0) {
297 LOGP(DLLC, LOGL_ERROR,
298 "invalid XID indication received!\n");
299 } else {
300 xid = msgb_put(resp, response_len);
301 memcpy(xid, response, response_len);
302 }
Philipp4ac3aee2016-08-10 12:24:09 +0200303 gprs_llc_tx_xid(lle, resp, 0);
304 } else {
305 LOGP(DLLC, LOGL_NOTICE,
Philipp532480a2016-12-23 11:05:11 +0100306 "Received XID confirmation from MS.\n");
Philipp4ac3aee2016-08-10 12:24:09 +0200307 gprs_llc_process_xid_conf(gph->data, gph->data_len, lle);
308 /* FIXME: if we had sent a XID reset, send
309 * LLGMM-RESET.conf to GMM */
310 }
311}
312
Philipp4ac3aee2016-08-10 12:24:09 +0200313/* Set of LL-XID negotiation (See also: TS 101 351, Section 7.2.2.4) */
314int gprs_ll_xid_req(struct gprs_llc_lle *lle,
315 struct gprs_llc_xid_field *l3_xid_field)
316{
317 /* Note: This functions is calle from gprs_sndcp.c */
318
319 uint8_t xid_bytes[1024];;
320 int xid_bytes_len;
321 uint8_t *xid;
322 struct msgb *msg;
Max549ebc72016-11-18 14:07:04 +0100323 const char *ftype;
Philipp4ac3aee2016-08-10 12:24:09 +0200324
325 /* Generate XID */
326 xid_bytes_len =
327 gprs_llc_generate_xid(xid_bytes, sizeof(xid_bytes),
328 l3_xid_field, lle->llme);
329
330 /* Only perform XID sending if the XID message contains something */
331 if (xid_bytes_len > 0) {
332 /* Transmit XID bytes */
333 msg = msgb_alloc_headroom(4096, 1024, "LLC_XID");
334 xid = msgb_put(msg, xid_bytes_len);
335 memcpy(xid, xid_bytes, xid_bytes_len);
Max549ebc72016-11-18 14:07:04 +0100336 if (l3_xid_field)
337 ftype = get_value_string(gprs_llc_xid_type_names,
338 l3_xid_field->type);
339 else
340 ftype = "NULL";
341 LOGP(DLLC, LOGL_NOTICE, "Sending XID type %s (%d bytes) request"
Philipp532480a2016-12-23 11:05:11 +0100342 " to MS...\n", ftype, xid_bytes_len);
Philipp4ac3aee2016-08-10 12:24:09 +0200343 gprs_llc_tx_xid(lle, msg, 1);
344 } else {
345 LOGP(DLLC, LOGL_ERROR,
346 "XID-Message generation failed, XID not sent!\n");
347 return -EINVAL;
348 }
349
350 return 0;
351}
352/* END XID RELATED */
353
354
355
Holger Hans Peter Freyther964a9b32013-07-30 09:29:27 +0200356
Harald Weltefaa70ff2012-06-17 09:31:16 +0800357/* Entry function from upper level (LLC), asking us to transmit a BSSGP PDU
358 * to a remote MS (identified by TLLI) at a BTS identified by its BVCI and NSEI */
359static int _bssgp_tx_dl_ud(struct msgb *msg, struct sgsn_mm_ctx *mmctx)
360{
361 struct bssgp_dl_ud_par dup;
362 const uint8_t qos_profile_default[3] = { 0x00, 0x00, 0x20 };
363
Harald Welte8c004962012-07-04 21:53:12 +0200364 memset(&dup, 0, sizeof(dup));
365 /* before we have received some identity from the MS, we might
366 * not yet have a MMC context (e.g. XID negotiation of primarly
Philipp4ac3aee2016-08-10 12:24:09 +0200367 * LLC connection from GMM sapi). */
Harald Welte8c004962012-07-04 21:53:12 +0200368 if (mmctx) {
369 dup.imsi = mmctx->imsi;
370 dup.drx_parms = mmctx->drx_parms;
371 dup.ms_ra_cap.len = mmctx->ms_radio_access_capa.len;
372 dup.ms_ra_cap.v = mmctx->ms_radio_access_capa.buf;
Holger Hans Peter Freyther7e0fec12013-07-29 10:09:12 +0200373
374 /* make sure we only send it to the right llme */
Neels Hofmeyr188a91c2017-12-27 17:29:04 +0100375 if (!(msgb_tlli(msg) == mmctx->gb.llme->tlli
376 || msgb_tlli(msg) == mmctx->gb.llme->old_tlli)) {
377 LOGP(DLLC, LOGL_ERROR,
378 "_bssgp_tx_dl_ud(): Attempt to send Downlink Unitdata to wrong LLME:"
379 " msgb_tlli=0x%x mmctx->gb.llme->tlli=0x%x ->old_tlli=0x%x\n",
380 msgb_tlli(msg), mmctx->gb.llme->tlli, mmctx->gb.llme->old_tlli);
381 msgb_free(msg);
382 return -EINVAL;
383 }
Harald Welte8c004962012-07-04 21:53:12 +0200384 }
Harald Weltefaa70ff2012-06-17 09:31:16 +0800385 memcpy(&dup.qos_profile, qos_profile_default,
386 sizeof(qos_profile_default));
387
Harald Weltece95b272012-06-17 13:04:02 +0800388 return bssgp_tx_dl_ud(msg, 1000, &dup);
Harald Weltefaa70ff2012-06-17 09:31:16 +0800389}
390
391
Harald Welte1d9d9442010-06-03 07:11:04 +0200392/* Section 8.9.9 LLC layer parameter default values */
Daniel Willmann46d13262014-06-27 17:05:48 +0200393static const struct gprs_llc_params llc_default_params[NUM_SAPIS] = {
Harald Welte1d9d9442010-06-03 07:11:04 +0200394 [1] = {
395 .t200_201 = 5,
396 .n200 = 3,
397 .n201_u = 400,
398 },
399 [2] = {
400 .t200_201 = 5,
401 .n200 = 3,
402 .n201_u = 270,
403 },
404 [3] = {
405 .iov_i_exp = 27,
406 .t200_201 = 5,
407 .n200 = 3,
408 .n201_u = 500,
409 .n201_i = 1503,
410 .mD = 1520,
411 .mU = 1520,
412 .kD = 16,
413 .kU = 16,
414 },
415 [5] = {
416 .iov_i_exp = 27,
417 .t200_201 = 10,
418 .n200 = 3,
419 .n201_u = 500,
420 .n201_i = 1503,
421 .mD = 760,
422 .mU = 760,
423 .kD = 8,
424 .kU = 8,
425 },
426 [7] = {
427 .t200_201 = 20,
428 .n200 = 3,
429 .n201_u = 270,
430 },
431 [8] = {
432 .t200_201 = 20,
433 .n200 = 3,
434 .n201_u = 270,
435 },
436 [9] = {
437 .iov_i_exp = 27,
438 .t200_201 = 20,
439 .n200 = 3,
440 .n201_u = 500,
441 .n201_i = 1503,
442 .mD = 380,
443 .mU = 380,
444 .kD = 4,
445 .kU = 4,
446 },
447 [11] = {
448 .iov_i_exp = 27,
449 .t200_201 = 40,
450 .n200 = 3,
451 .n201_u = 500,
452 .n201_i = 1503,
453 .mD = 190,
454 .mU = 190,
455 .kD = 2,
456 .kU = 2,
457 },
458};
459
Harald Welte807a5d82010-06-01 11:53:01 +0200460LLIST_HEAD(gprs_llc_llmes);
Harald Weltea2665542010-05-02 09:28:11 +0200461void *llc_tall_ctx;
462
463/* lookup LLC Entity based on DLCI (TLLI+SAPI tuple) */
Holger Hans Peter Freyther012a7ee2013-07-29 09:06:46 +0200464static struct gprs_llc_lle *lle_by_tlli_sapi(const uint32_t tlli, uint8_t sapi)
Harald Weltea2665542010-05-02 09:28:11 +0200465{
Harald Welte807a5d82010-06-01 11:53:01 +0200466 struct gprs_llc_llme *llme;
Harald Weltea2665542010-05-02 09:28:11 +0200467
Harald Welte807a5d82010-06-01 11:53:01 +0200468 llist_for_each_entry(llme, &gprs_llc_llmes, list) {
469 if (llme->tlli == tlli || llme->old_tlli == tlli)
470 return &llme->lle[sapi];
Harald Weltea2665542010-05-02 09:28:11 +0200471 }
472 return NULL;
473}
474
Holger Hans Peter Freyther4299c052014-10-02 21:27:24 +0200475struct gprs_llc_lle *gprs_lle_get_or_create(const uint32_t tlli, uint8_t sapi)
476{
477 struct gprs_llc_llme *llme;
478 struct gprs_llc_lle *lle;
479
480 lle = lle_by_tlli_sapi(tlli, sapi);
481 if (lle)
482 return lle;
483
Holger Hans Peter Freyther4299c052014-10-02 21:27:24 +0200484 LOGP(DLLC, LOGL_NOTICE, "LLC: unknown TLLI 0x%08x, "
485 "creating LLME on the fly\n", tlli);
486 llme = llme_alloc(tlli);
487 lle = &llme->lle[sapi];
488 return lle;
489}
490
491struct llist_head *gprs_llme_list(void)
492{
493 return &gprs_llc_llmes;
494}
495
Holger Hans Peter Freyther964a9b32013-07-30 09:29:27 +0200496/* lookup LLC Entity for RX based on DLCI (TLLI+SAPI tuple) */
497static struct gprs_llc_lle *lle_for_rx_by_tlli_sapi(const uint32_t tlli,
498 uint8_t sapi, enum gprs_llc_cmd cmd)
499{
500 struct gprs_llc_lle *lle;
501
502 /* We already know about this TLLI */
503 lle = lle_by_tlli_sapi(tlli, sapi);
504 if (lle)
505 return lle;
506
507 /* Maybe it is a routing area update but we already know this sapi? */
508 if (gprs_tlli_type(tlli) == TLLI_FOREIGN) {
Jacob Erlbeck3fbf0a32016-01-04 18:43:32 +0100509 lle = lle_by_tlli_sapi(tlli, sapi);
Holger Hans Peter Freyther964a9b32013-07-30 09:29:27 +0200510 if (lle) {
511 LOGP(DLLC, LOGL_NOTICE,
512 "LLC RX: Found a local entry for TLLI 0x%08x\n",
513 tlli);
514 return lle;
515 }
516 }
517
518 /* 7.2.1.1 LLC belonging to unassigned TLLI+SAPI shall be discarded,
519 * except UID and XID frames with SAPI=1 */
520 if (sapi == GPRS_SAPI_GMM &&
521 (cmd == GPRS_LLC_XID || cmd == GPRS_LLC_UI)) {
522 struct gprs_llc_llme *llme;
523 /* FIXME: don't use the TLLI but the 0xFFFF unassigned? */
524 llme = llme_alloc(tlli);
Daniel Willmann46553142014-09-03 17:46:44 +0200525 LOGP(DLLC, LOGL_NOTICE, "LLC RX: unknown TLLI 0x%08x, "
Holger Hans Peter Freyther964a9b32013-07-30 09:29:27 +0200526 "creating LLME on the fly\n", tlli);
527 lle = &llme->lle[sapi];
528 return lle;
529 }
530
531 LOGP(DLLC, LOGL_NOTICE,
532 "unknown TLLI(0x%08x)/SAPI(%d): Silently dropping\n",
533 tlli, sapi);
534 return NULL;
535}
536
Harald Welte1d9d9442010-06-03 07:11:04 +0200537static void lle_init(struct gprs_llc_llme *llme, uint8_t sapi)
Harald Weltea2665542010-05-02 09:28:11 +0200538{
Harald Welte807a5d82010-06-01 11:53:01 +0200539 struct gprs_llc_lle *lle = &llme->lle[sapi];
Harald Weltea2665542010-05-02 09:28:11 +0200540
Harald Welte807a5d82010-06-01 11:53:01 +0200541 lle->llme = llme;
542 lle->sapi = sapi;
543 lle->state = GPRS_LLES_UNASSIGNED;
544
Harald Welte1d9d9442010-06-03 07:11:04 +0200545 /* Initialize according to parameters */
546 memcpy(&lle->params, &llc_default_params[sapi], sizeof(lle->params));
Harald Welte807a5d82010-06-01 11:53:01 +0200547}
548
549static struct gprs_llc_llme *llme_alloc(uint32_t tlli)
550{
551 struct gprs_llc_llme *llme;
552 uint32_t i;
553
554 llme = talloc_zero(llc_tall_ctx, struct gprs_llc_llme);
555 if (!llme)
Harald Weltea2665542010-05-02 09:28:11 +0200556 return NULL;
557
Harald Welte807a5d82010-06-01 11:53:01 +0200558 llme->tlli = tlli;
Harald Welte875840c2010-07-01 11:54:31 +0200559 llme->old_tlli = 0xffffffff;
Harald Welte807a5d82010-06-01 11:53:01 +0200560 llme->state = GPRS_LLMS_UNASSIGNED;
Jacob Erlbeck81ffb742015-01-23 11:33:51 +0100561 llme->age_timestamp = GPRS_LLME_RESET_AGE;
Max5aa51962016-07-06 11:33:04 +0200562 llme->cksn = GSM_KEY_SEQ_INVAL;
Harald Weltea2665542010-05-02 09:28:11 +0200563
Harald Welte807a5d82010-06-01 11:53:01 +0200564 for (i = 0; i < ARRAY_SIZE(llme->lle); i++)
565 lle_init(llme, i);
566
567 llist_add(&llme->list, &gprs_llc_llmes);
568
Philippf1f34362016-08-26 17:00:21 +0200569 llme->comp.proto = gprs_sndcp_comp_alloc(llme);
570 llme->comp.data = gprs_sndcp_comp_alloc(llme);
571
Harald Welte807a5d82010-06-01 11:53:01 +0200572 return llme;
Harald Weltea2665542010-05-02 09:28:11 +0200573}
574
Harald Weltef7fef482010-06-28 22:18:26 +0200575static void llme_free(struct gprs_llc_llme *llme)
576{
Philippf1f34362016-08-26 17:00:21 +0200577 gprs_sndcp_comp_free(llme->comp.proto);
578 gprs_sndcp_comp_free(llme->comp.data);
Philipp4ac3aee2016-08-10 12:24:09 +0200579 talloc_free(llme->xid);
Harald Weltef7fef482010-06-28 22:18:26 +0200580 llist_del(&llme->list);
581 talloc_free(llme);
582}
583
Holger Hans Peter Freyther744568b2014-04-04 12:47:32 +0200584#if 0
585/* FIXME: Unused code... */
Harald Welte9b455bf2010-03-14 15:45:01 +0800586static void t200_expired(void *data)
587{
588 struct gprs_llc_lle *lle = data;
589
590 /* 8.5.1.3: Expiry of T200 */
591
Harald Welte1d9d9442010-06-03 07:11:04 +0200592 if (lle->retrans_ctr >= lle->params.n200) {
Harald Welte9b455bf2010-03-14 15:45:01 +0800593 /* FIXME: LLGM-STATUS-IND, LL-RELEASE-IND/CNF */
Harald Welte807a5d82010-06-01 11:53:01 +0200594 lle->state = GPRS_LLES_ASSIGNED_ADM;
Harald Welte9b455bf2010-03-14 15:45:01 +0800595 }
596
597 switch (lle->state) {
Harald Welte807a5d82010-06-01 11:53:01 +0200598 case GPRS_LLES_LOCAL_EST:
Harald Welte1ae09c72010-05-13 19:22:55 +0200599 /* FIXME: retransmit SABM */
600 /* FIXME: re-start T200 */
Harald Welte9b455bf2010-03-14 15:45:01 +0800601 lle->retrans_ctr++;
602 break;
Harald Welte807a5d82010-06-01 11:53:01 +0200603 case GPRS_LLES_LOCAL_REL:
Harald Welte1ae09c72010-05-13 19:22:55 +0200604 /* FIXME: retransmit DISC */
605 /* FIXME: re-start T200 */
Harald Welte9b455bf2010-03-14 15:45:01 +0800606 lle->retrans_ctr++;
607 break;
Holger Hans Peter Freyther744568b2014-04-04 12:47:32 +0200608 default:
609 LOGP(DLLC, LOGL_ERROR, "LLC unhandled state: %d\n", lle->state);
610 break;
Harald Welte9b455bf2010-03-14 15:45:01 +0800611 }
612
613}
614
615static void t201_expired(void *data)
616{
617 struct gprs_llc_lle *lle = data;
618
Harald Welte1d9d9442010-06-03 07:11:04 +0200619 if (lle->retrans_ctr < lle->params.n200) {
Harald Welte1ae09c72010-05-13 19:22:55 +0200620 /* FIXME: transmit apropriate supervisory frame (8.6.4.1) */
621 /* FIXME: set timer T201 */
Harald Welte9b455bf2010-03-14 15:45:01 +0800622 lle->retrans_ctr++;
623 }
624}
Holger Hans Peter Freyther744568b2014-04-04 12:47:32 +0200625#endif
Harald Welte9b455bf2010-03-14 15:45:01 +0800626
Harald Welte10997d02010-05-03 12:28:12 +0200627int gprs_llc_tx_u(struct msgb *msg, uint8_t sapi, int command,
628 enum gprs_llc_u_cmd u_cmd, int pf_bit)
629{
630 uint8_t *fcs, *llch;
631 uint8_t addr, ctrl;
632 uint32_t fcs_calc;
633
634 /* Identifiers from UP: (TLLI, SAPI) + (BVCI, NSEI) */
635
636 /* Address Field */
637 addr = sapi & 0xf;
638 if (command)
639 addr |= 0x40;
640
641 /* 6.3 Figure 8 */
642 ctrl = 0xe0 | u_cmd;
643 if (pf_bit)
644 ctrl |= 0x10;
645
646 /* prepend LLC UI header */
647 llch = msgb_push(msg, 2);
648 llch[0] = addr;
649 llch[1] = ctrl;
650
651 /* append FCS to end of frame */
652 fcs = msgb_put(msg, 3);
653 fcs_calc = gprs_llc_fcs(llch, fcs - llch);
654 fcs[0] = fcs_calc & 0xff;
655 fcs[1] = (fcs_calc >> 8) & 0xff;
656 fcs[2] = (fcs_calc >> 16) & 0xff;
657
658 /* Identifiers passed down: (BVCI, NSEI) */
659
Alexander Couzens4e699a92016-07-05 11:04:27 +0200660 rate_ctr_inc(&sgsn->rate_ctrs->ctr[CTR_LLC_DL_PACKETS]);
661 rate_ctr_add(&sgsn->rate_ctrs->ctr[CTR_LLC_DL_BYTES], msg->len);
662
Harald Welte1ae09c72010-05-13 19:22:55 +0200663 /* Send BSSGP-DL-UNITDATA.req */
Harald Welteb1fd9022012-06-17 12:16:31 +0800664 return _bssgp_tx_dl_ud(msg, NULL);
Harald Welte10997d02010-05-03 12:28:12 +0200665}
666
667/* Send XID response to LLE */
Harald Welte0c1a3032011-10-16 18:49:05 +0200668static int gprs_llc_tx_xid(struct gprs_llc_lle *lle, struct msgb *msg,
669 int command)
Harald Welte10997d02010-05-03 12:28:12 +0200670{
671 /* copy identifiers from LLE to ensure lower layers can route */
Harald Welte807a5d82010-06-01 11:53:01 +0200672 msgb_tlli(msg) = lle->llme->tlli;
673 msgb_bvci(msg) = lle->llme->bvci;
674 msgb_nsei(msg) = lle->llme->nsei;
Harald Welte10997d02010-05-03 12:28:12 +0200675
Harald Welte0c1a3032011-10-16 18:49:05 +0200676 return gprs_llc_tx_u(msg, lle->sapi, command, GPRS_LLC_U_XID, 1);
Harald Welte10997d02010-05-03 12:28:12 +0200677}
678
Max1de15912016-07-11 12:42:12 +0200679/* encrypt information field + FCS, if needed! */
680static int apply_gea(struct gprs_llc_lle *lle, uint16_t crypt_len, uint16_t nu,
681 uint32_t oc, uint8_t sapi, uint8_t *fcs, uint8_t *data)
682{
683 uint8_t cipher_out[GSM0464_CIPH_MAX_BLOCK];
684
685 if (lle->llme->algo == GPRS_ALGO_GEA0)
686 return -EINVAL;
687
688 /* Compute the 'Input' Paraemeter */
Dieter Spaarb572d7c2016-07-11 12:48:07 +0200689 uint32_t fcs_calc, iv = gprs_cipher_gen_input_ui(lle->llme->iov_ui, sapi,
Max1de15912016-07-11 12:42:12 +0200690 nu, oc);
691 /* Compute gamma that we need to XOR with the data */
692 int r = gprs_cipher_run(cipher_out, crypt_len, lle->llme->algo,
693 lle->llme->kc, iv,
694 fcs ? GPRS_CIPH_SGSN2MS : GPRS_CIPH_MS2SGSN);
695 if (r < 0) {
696 LOGP(DLLC, LOGL_ERROR, "Error producing %s gamma for UI "
697 "frame: %d\n", get_value_string(gprs_cipher_names,
698 lle->llme->algo), r);
699 return -ENOMSG;
700 }
701
702 if (fcs) {
Dieter Spaarb572d7c2016-07-11 12:48:07 +0200703 /* Mark frame as encrypted and update FCS */
704 data[2] |= 0x02;
705 fcs_calc = gprs_llc_fcs(data, fcs - data);
706 fcs[0] = fcs_calc & 0xff;
707 fcs[1] = (fcs_calc >> 8) & 0xff;
708 fcs[2] = (fcs_calc >> 16) & 0xff;
Max1de15912016-07-11 12:42:12 +0200709 data += 3;
710 }
711
712 /* XOR the cipher output with the data */
713 for (r = 0; r < crypt_len; r++)
714 *(data + r) ^= cipher_out[r];
715
716 return 0;
717}
718
Max82040102016-07-06 11:59:18 +0200719/* Transmit a UI frame over the given SAPI:
720 'encryptable' indicates whether particular message can be encrypted according
721 to 3GPP TS 24.008 § 4.7.1.2
722 */
Harald Welte56a01452010-05-31 22:12:30 +0200723int gprs_llc_tx_ui(struct msgb *msg, uint8_t sapi, int command,
Max82040102016-07-06 11:59:18 +0200724 struct sgsn_mm_ctx *mmctx, bool encryptable)
Harald Welte9b455bf2010-03-14 15:45:01 +0800725{
Harald Weltee6afd602010-05-02 11:19:37 +0200726 struct gprs_llc_lle *lle;
Harald Welteeaa614c2010-05-02 11:26:34 +0200727 uint8_t *fcs, *llch;
728 uint8_t addr, ctrl[2];
729 uint32_t fcs_calc;
730 uint16_t nu = 0;
Harald Welted07b4f92010-06-30 23:07:59 +0200731 uint32_t oc;
Harald Welte9b455bf2010-03-14 15:45:01 +0800732
Harald Weltee6afd602010-05-02 11:19:37 +0200733 /* Identifiers from UP: (TLLI, SAPI) + (BVCI, NSEI) */
734
735 /* look-up or create the LL Entity for this (TLLI, SAPI) tuple */
Holger Hans Peter Freyther4299c052014-10-02 21:27:24 +0200736 lle = gprs_lle_get_or_create(msgb_tlli(msg), sapi);
Harald Welte1d9d9442010-06-03 07:11:04 +0200737
738 if (msg->len > lle->params.n201_u) {
739 LOGP(DLLC, LOGL_ERROR, "Cannot Tx %u bytes (N201-U=%u)\n",
740 msg->len, lle->params.n201_u);
Holger Hans Peter Freytherf9ffd1f2014-10-10 17:35:54 +0200741 msgb_free(msg);
Harald Welte1d9d9442010-06-03 07:11:04 +0200742 return -EFBIG;
743 }
744
Max5aa51962016-07-06 11:33:04 +0200745 gprs_llme_copy_key(mmctx, lle->llme);
746
Harald Weltee6afd602010-05-02 11:19:37 +0200747 /* Update LLE's (BVCI, NSEI) tuple */
Harald Welte807a5d82010-06-01 11:53:01 +0200748 lle->llme->bvci = msgb_bvci(msg);
749 lle->llme->nsei = msgb_nsei(msg);
Harald Weltee6afd602010-05-02 11:19:37 +0200750
Harald Welted07b4f92010-06-30 23:07:59 +0200751 /* Obtain current values for N(u) and OC */
Harald Welte6bdee6a2010-05-30 21:51:58 +0200752 nu = lle->vu_send;
Harald Welted07b4f92010-06-30 23:07:59 +0200753 oc = lle->oc_ui_send;
754 /* Increment V(U) */
Harald Welte6bdee6a2010-05-30 21:51:58 +0200755 lle->vu_send = (lle->vu_send + 1) % 512;
Harald Welted07b4f92010-06-30 23:07:59 +0200756 /* Increment Overflow Counter, if needed */
757 if ((lle->vu_send + 1) / 512)
758 lle->oc_ui_send += 512;
Harald Welte6bdee6a2010-05-30 21:51:58 +0200759
Harald Welte9b455bf2010-03-14 15:45:01 +0800760 /* Address Field */
761 addr = sapi & 0xf;
762 if (command)
763 addr |= 0x40;
764
765 /* Control Field */
766 ctrl[0] = 0xc0;
767 ctrl[0] |= nu >> 6;
768 ctrl[1] = (nu << 2) & 0xfc;
769 ctrl[1] |= 0x01; /* Protected Mode */
770
771 /* prepend LLC UI header */
772 llch = msgb_push(msg, 3);
773 llch[0] = addr;
774 llch[1] = ctrl[0];
775 llch[2] = ctrl[1];
776
777 /* append FCS to end of frame */
778 fcs = msgb_put(msg, 3);
779 fcs_calc = gprs_llc_fcs(llch, fcs - llch);
780 fcs[0] = fcs_calc & 0xff;
781 fcs[1] = (fcs_calc >> 8) & 0xff;
782 fcs[2] = (fcs_calc >> 16) & 0xff;
783
Max82040102016-07-06 11:59:18 +0200784 if (lle->llme->algo != GPRS_ALGO_GEA0 && encryptable) {
Max1de15912016-07-11 12:42:12 +0200785 int rc = apply_gea(lle, fcs - llch, nu, oc, sapi, fcs, llch);
Harald Welted07b4f92010-06-30 23:07:59 +0200786 if (rc < 0) {
Holger Hans Peter Freytherf9ffd1f2014-10-10 17:35:54 +0200787 msgb_free(msg);
Harald Welted07b4f92010-06-30 23:07:59 +0200788 return rc;
789 }
Harald Welted07b4f92010-06-30 23:07:59 +0200790 }
791
Alexander Couzens33163972016-10-04 17:53:21 +0200792 rate_ctr_inc(&sgsn->rate_ctrs->ctr[CTR_LLC_DL_PACKETS]);
793 rate_ctr_add(&sgsn->rate_ctrs->ctr[CTR_LLC_DL_BYTES], msg->len);
794
Harald Weltee6afd602010-05-02 11:19:37 +0200795 /* Identifiers passed down: (BVCI, NSEI) */
796
Harald Welte1ae09c72010-05-13 19:22:55 +0200797 /* Send BSSGP-DL-UNITDATA.req */
Harald Weltefaa70ff2012-06-17 09:31:16 +0800798 return _bssgp_tx_dl_ud(msg, mmctx);
Harald Welte9b455bf2010-03-14 15:45:01 +0800799}
800
Harald Welte9b455bf2010-03-14 15:45:01 +0800801static int gprs_llc_hdr_rx(struct gprs_llc_hdr_parsed *gph,
802 struct gprs_llc_lle *lle)
803{
804 switch (gph->cmd) {
805 case GPRS_LLC_SABM: /* Section 6.4.1.1 */
806 lle->v_sent = lle->v_ack = lle->v_recv = 0;
Harald Welte807a5d82010-06-01 11:53:01 +0200807 if (lle->state == GPRS_LLES_ASSIGNED_ADM) {
Harald Welte9b455bf2010-03-14 15:45:01 +0800808 /* start re-establishment (8.7.1) */
809 }
Harald Welte807a5d82010-06-01 11:53:01 +0200810 lle->state = GPRS_LLES_REMOTE_EST;
Harald Welte9b455bf2010-03-14 15:45:01 +0800811 /* FIXME: Send UA */
Harald Welte807a5d82010-06-01 11:53:01 +0200812 lle->state = GPRS_LLES_ABM;
Harald Welte9b455bf2010-03-14 15:45:01 +0800813 /* FIXME: process data */
814 break;
815 case GPRS_LLC_DISC: /* Section 6.4.1.2 */
816 /* FIXME: Send UA */
817 /* terminate ABM */
Harald Welte807a5d82010-06-01 11:53:01 +0200818 lle->state = GPRS_LLES_ASSIGNED_ADM;
Harald Welte9b455bf2010-03-14 15:45:01 +0800819 break;
820 case GPRS_LLC_UA: /* Section 6.4.1.3 */
Harald Welte807a5d82010-06-01 11:53:01 +0200821 if (lle->state == GPRS_LLES_LOCAL_EST)
822 lle->state = GPRS_LLES_ABM;
Harald Welte9b455bf2010-03-14 15:45:01 +0800823 break;
824 case GPRS_LLC_DM: /* Section 6.4.1.4: ABM cannot be performed */
Harald Welte807a5d82010-06-01 11:53:01 +0200825 if (lle->state == GPRS_LLES_LOCAL_EST)
826 lle->state = GPRS_LLES_ASSIGNED_ADM;
Harald Welte9b455bf2010-03-14 15:45:01 +0800827 break;
828 case GPRS_LLC_FRMR: /* Section 6.4.1.5 */
829 break;
830 case GPRS_LLC_XID: /* Section 6.4.1.6 */
Harald Welte0c1a3032011-10-16 18:49:05 +0200831 rx_llc_xid(lle, gph);
Harald Welte9b455bf2010-03-14 15:45:01 +0800832 break;
Harald Welteebabdea2010-06-01 18:28:10 +0200833 case GPRS_LLC_UI:
Holger Hans Peter Freytherfaf1f642011-06-23 17:53:27 -0400834 if (gprs_llc_is_retransmit(gph->seq_tx, lle->vu_recv)) {
835 LOGP(DLLC, LOGL_NOTICE,
836 "TLLI=%08x dropping UI, N(U=%d) not in window V(URV(UR:%d).\n",
Holger Hans Peter Freyther2788b962010-06-23 09:48:25 +0800837 lle->llme ? lle->llme->tlli : -1,
Harald Welteebabdea2010-06-01 18:28:10 +0200838 gph->seq_tx, lle->vu_recv);
Harald Welteabadd542013-06-21 14:06:18 +0200839
840 /* HACK: non-standard recovery handling. If remote LLE
841 * is re-transmitting the same sequence number for
Harald Welte649e1ff2013-07-21 17:41:46 +0800842 * three times, don't discard the frame but pass it on
Harald Welteabadd542013-06-21 14:06:18 +0200843 * and 'learn' the new sequence number */
844 if (gph->seq_tx != lle->vu_recv_last) {
845 lle->vu_recv_last = gph->seq_tx;
846 lle->vu_recv_duplicates = 0;
847 } else {
848 lle->vu_recv_duplicates++;
849 if (lle->vu_recv_duplicates < 3)
850 return -EIO;
851 LOGP(DLLC, LOGL_NOTICE, "TLLI=%08x recovering "
852 "N(U=%d) after receiving %u duplicates\n",
853 lle->llme ? lle->llme->tlli : -1,
854 gph->seq_tx, lle->vu_recv_duplicates);
855 }
Harald Welteebabdea2010-06-01 18:28:10 +0200856 }
857 /* Increment the sequence number that we expect in the next frame */
858 lle->vu_recv = (gph->seq_tx + 1) % 512;
Harald Welted07b4f92010-06-30 23:07:59 +0200859 /* Increment Overflow Counter */
860 if ((gph->seq_tx + 1) / 512)
861 lle->oc_ui_recv += 512;
Harald Welteebabdea2010-06-01 18:28:10 +0200862 break;
Holger Hans Peter Freyther744568b2014-04-04 12:47:32 +0200863 default:
864 LOGP(DLLC, LOGL_NOTICE, "Unhandled command: %d\n", gph->cmd);
865 break;
Harald Welte9b455bf2010-03-14 15:45:01 +0800866 }
867
868 return 0;
869}
870
Harald Weltea2665542010-05-02 09:28:11 +0200871/* receive an incoming LLC PDU (BSSGP-UL-UNITDATA-IND, 7.2.4.2) */
Harald Welte9b455bf2010-03-14 15:45:01 +0800872int gprs_llc_rcvmsg(struct msgb *msg, struct tlv_parsed *tv)
873{
Holger Hans Peter Freyther3dccda52011-10-14 23:42:13 +0200874 struct gprs_llc_hdr *lh = (struct gprs_llc_hdr *) msgb_llch(msg);
Harald Welte9b455bf2010-03-14 15:45:01 +0800875 struct gprs_llc_hdr_parsed llhp;
Max549ebc72016-11-18 14:07:04 +0100876 struct gprs_llc_lle *lle = NULL;
Max82040102016-07-06 11:59:18 +0200877 bool drop_cipherable = false;
Harald Weltea2665542010-05-02 09:28:11 +0200878 int rc = 0;
Harald Welte9b455bf2010-03-14 15:45:01 +0800879
Harald Welte11d7c102010-05-02 11:54:55 +0200880 /* Identifiers from DOWN: NSEI, BVCI, TLLI */
881
Holger Hans Peter Freyther4752e0c2010-05-23 21:33:57 +0800882 memset(&llhp, 0, sizeof(llhp));
Holger Hans Peter Freytherfa848d42010-05-23 21:43:57 +0800883 rc = gprs_llc_hdr_parse(&llhp, (uint8_t *) lh, TLVP_LEN(tv, BSSGP_IE_LLC_PDU));
Harald Welte1ae09c72010-05-13 19:22:55 +0200884 if (rc < 0) {
Harald Welte1b170d12010-05-13 19:49:06 +0200885 LOGP(DLLC, LOGL_NOTICE, "Error during LLC header parsing\n");
Harald Welte1ae09c72010-05-13 19:22:55 +0200886 return rc;
887 }
888
Harald Welte807a5d82010-06-01 11:53:01 +0200889 switch (gprs_tlli_type(msgb_tlli(msg))) {
890 case TLLI_LOCAL:
891 case TLLI_FOREIGN:
892 case TLLI_RANDOM:
893 case TLLI_AUXILIARY:
894 break;
895 default:
896 LOGP(DLLC, LOGL_ERROR,
897 "Discarding frame with strange TLLI type\n");
898 break;
899 }
900
Harald Weltea2665542010-05-02 09:28:11 +0200901 /* find the LLC Entity for this TLLI+SAPI tuple */
Holger Hans Peter Freyther964a9b32013-07-30 09:29:27 +0200902 lle = lle_for_rx_by_tlli_sapi(msgb_tlli(msg), llhp.sapi, llhp.cmd);
Jacob Erlbeck78ecaf02014-09-05 14:32:36 +0200903 if (!lle) {
904 switch (llhp.sapi) {
905 case GPRS_SAPI_SNDCP3:
906 case GPRS_SAPI_SNDCP5:
907 case GPRS_SAPI_SNDCP9:
908 case GPRS_SAPI_SNDCP11:
909 /* Ask an upper layer for help. */
Alexander Couzens58f446c2016-08-30 18:51:50 +0200910 return gsm0408_gprs_force_reattach_oldmsg(msg, NULL);
Jacob Erlbeck78ecaf02014-09-05 14:32:36 +0200911 default:
912 break;
913 }
Holger Hans Peter Freyther964a9b32013-07-30 09:29:27 +0200914 return 0;
Jacob Erlbeck78ecaf02014-09-05 14:32:36 +0200915 }
Max549ebc72016-11-18 14:07:04 +0100916 gprs_llc_hdr_dump(&llhp, lle);
Jacob Erlbeck81ffb742015-01-23 11:33:51 +0100917 /* reset age computation */
918 lle->llme->age_timestamp = GPRS_LLME_RESET_AGE;
919
Harald Welted07b4f92010-06-30 23:07:59 +0200920 /* decrypt information field + FCS, if needed! */
921 if (llhp.is_encrypted) {
Max1de15912016-07-11 12:42:12 +0200922 if (lle->llme->algo != GPRS_ALGO_GEA0) {
923 rc = apply_gea(lle, llhp.data_len + 3, llhp.seq_tx,
924 lle->oc_ui_recv, lle->sapi, NULL,
925 llhp.data);
926 if (rc < 0)
927 return rc;
Dieter Spaarb572d7c2016-07-11 12:48:07 +0200928 llhp.fcs = *(llhp.data + llhp.data_len);
929 llhp.fcs |= *(llhp.data + llhp.data_len + 1) << 8;
930 llhp.fcs |= *(llhp.data + llhp.data_len + 2) << 16;
Max1de15912016-07-11 12:42:12 +0200931 } else {
Harald Welted07b4f92010-06-30 23:07:59 +0200932 LOGP(DLLC, LOGL_NOTICE, "encrypted frame for LLC that "
933 "has no KC/Algo! Dropping.\n");
934 return 0;
935 }
Harald Welted07b4f92010-06-30 23:07:59 +0200936 } else {
Max82040102016-07-06 11:59:18 +0200937 if (lle->llme->algo != GPRS_ALGO_GEA0 &&
938 lle->llme->cksn != GSM_KEY_SEQ_INVAL)
939 drop_cipherable = true;
Harald Welted07b4f92010-06-30 23:07:59 +0200940 }
941
942 /* We have to do the FCS check _after_ decryption */
Harald Welte1b8827a2010-06-30 23:15:57 +0200943 llhp.fcs_calc = gprs_llc_fcs((uint8_t *)lh, llhp.crc_length);
Harald Welted07b4f92010-06-30 23:07:59 +0200944 if (llhp.fcs != llhp.fcs_calc) {
945 LOGP(DLLC, LOGL_INFO, "Dropping frame with invalid FCS\n");
946 return -EIO;
947 }
948
Harald Welte10997d02010-05-03 12:28:12 +0200949 /* Update LLE's (BVCI, NSEI) tuple */
Harald Welte807a5d82010-06-01 11:53:01 +0200950 lle->llme->bvci = msgb_bvci(msg);
951 lle->llme->nsei = msgb_nsei(msg);
Harald Welte10997d02010-05-03 12:28:12 +0200952
Harald Welte1ae09c72010-05-13 19:22:55 +0200953 /* Receive and Process the actual LLC frame */
Harald Welte9b455bf2010-03-14 15:45:01 +0800954 rc = gprs_llc_hdr_rx(&llhp, lle);
Harald Welte1ae09c72010-05-13 19:22:55 +0200955 if (rc < 0)
956 return rc;
Harald Welte9b455bf2010-03-14 15:45:01 +0800957
Alexander Couzens4e699a92016-07-05 11:04:27 +0200958 rate_ctr_inc(&sgsn->rate_ctrs->ctr[CTR_LLC_UL_PACKETS]);
959 rate_ctr_add(&sgsn->rate_ctrs->ctr[CTR_LLC_UL_BYTES], msg->len);
960
Harald Welte1ae09c72010-05-13 19:22:55 +0200961 /* llhp.data is only set when we need to send LL_[UNIT]DATA_IND up */
Harald Welte22df4ac2015-08-16 15:23:32 +0200962 if (llhp.cmd == GPRS_LLC_UI && llhp.data && llhp.data_len) {
Harald Welte943c5bc2010-04-30 16:33:12 +0200963 msgb_gmmh(msg) = llhp.data;
Harald Welte9b455bf2010-03-14 15:45:01 +0800964 switch (llhp.sapi) {
965 case GPRS_SAPI_GMM:
Harald Welte1ae09c72010-05-13 19:22:55 +0200966 /* send LL_UNITDATA_IND to GMM */
Max82040102016-07-06 11:59:18 +0200967 rc = gsm0408_gprs_rcvmsg_gb(msg, lle->llme,
968 drop_cipherable);
Harald Weltea2665542010-05-02 09:28:11 +0200969 break;
Harald Weltea2665542010-05-02 09:28:11 +0200970 case GPRS_SAPI_SNDCP3:
971 case GPRS_SAPI_SNDCP5:
972 case GPRS_SAPI_SNDCP9:
973 case GPRS_SAPI_SNDCP11:
Harald Welteebabdea2010-06-01 18:28:10 +0200974 /* send LL_DATA_IND/LL_UNITDATA_IND to SNDCP */
975 rc = sndcp_llunitdata_ind(msg, lle, llhp.data, llhp.data_len);
976 break;
Harald Weltea2665542010-05-02 09:28:11 +0200977 case GPRS_SAPI_SMS:
978 /* FIXME */
Harald Welteebabdea2010-06-01 18:28:10 +0200979 case GPRS_SAPI_TOM2:
980 case GPRS_SAPI_TOM8:
981 /* FIXME: send LL_DATA_IND/LL_UNITDATA_IND to TOM */
Harald Weltea2665542010-05-02 09:28:11 +0200982 default:
Harald Weltec6ecafe2010-05-13 19:47:50 +0200983 LOGP(DLLC, LOGL_NOTICE, "Unsupported SAPI %u\n", llhp.sapi);
Harald Weltea2665542010-05-02 09:28:11 +0200984 rc = -EINVAL;
985 break;
Harald Welte9b455bf2010-03-14 15:45:01 +0800986 }
987 }
988
Harald Weltea2665542010-05-02 09:28:11 +0200989 return rc;
Harald Welte9b455bf2010-03-14 15:45:01 +0800990}
Harald Welte807a5d82010-06-01 11:53:01 +0200991
Max5aa51962016-07-06 11:33:04 +0200992/* Propagate crypto parameters MM -> LLME */
993void gprs_llme_copy_key(struct sgsn_mm_ctx *mm, struct gprs_llc_llme *llme)
994{
995 if (!mm)
996 return;
997 if (mm->ciph_algo != GPRS_ALGO_GEA0) {
998 llme->algo = mm->ciph_algo;
999 if (llme->cksn != mm->auth_triplet.key_seq &&
1000 mm->auth_triplet.key_seq != GSM_KEY_SEQ_INVAL) {
1001 memcpy(llme->kc, mm->auth_triplet.vec.kc,
1002 gprs_cipher_key_length(mm->ciph_algo));
1003 llme->cksn = mm->auth_triplet.key_seq;
1004 }
1005 } else
1006 llme->cksn = GSM_KEY_SEQ_INVAL;
1007}
1008
Harald Welte807a5d82010-06-01 11:53:01 +02001009/* 04.64 Chapter 7.2.1.1 LLGMM-ASSIGN */
1010int gprs_llgmm_assign(struct gprs_llc_llme *llme,
Max5aa51962016-07-06 11:33:04 +02001011 uint32_t old_tlli, uint32_t new_tlli)
Harald Welte807a5d82010-06-01 11:53:01 +02001012{
1013 unsigned int i;
1014
1015 if (old_tlli == 0xffffffff && new_tlli != 0xffffffff) {
1016 /* TLLI Assignment 8.3.1 */
1017 /* New TLLI shall be assigned and used when (re)transmitting LLC frames */
1018 /* If old TLLI != 0xffffffff was assigned to LLME, then TLLI
1019 * old is unassigned. Only TLLI new shall be accepted when
1020 * received from peer. */
Harald Welte875840c2010-07-01 11:54:31 +02001021 if (llme->old_tlli != 0xffffffff) {
1022 llme->old_tlli = 0xffffffff;
1023 llme->tlli = new_tlli;
1024 } else {
1025 /* If TLLI old == 0xffffffff was assigned to LLME, then this is
1026 * TLLI assignmemt according to 8.3.1 */
1027 llme->old_tlli = 0xffffffff;
1028 llme->tlli = new_tlli;
1029 llme->state = GPRS_LLMS_ASSIGNED;
1030 /* 8.5.3.1 For all LLE's */
1031 for (i = 0; i < ARRAY_SIZE(llme->lle); i++) {
1032 struct gprs_llc_lle *l = &llme->lle[i];
1033 l->vu_send = l->vu_recv = 0;
1034 l->retrans_ctr = 0;
1035 l->state = GPRS_LLES_ASSIGNED_ADM;
1036 /* FIXME Set parameters according to table 9 */
1037 }
Harald Welte807a5d82010-06-01 11:53:01 +02001038 }
1039 } else if (old_tlli != 0xffffffff && new_tlli != 0xffffffff) {
1040 /* TLLI Change 8.3.2 */
1041 /* Both TLLI Old and TLLI New are assigned; use New when
Holger Hans Peter Freyther92aa6bb2013-07-28 20:13:01 +02001042 * (re)transmitting. Accept both Old and New on Rx */
Holger Hans Peter Freytheraa93bac2013-07-31 11:20:37 +02001043 llme->old_tlli = old_tlli;
Harald Welte807a5d82010-06-01 11:53:01 +02001044 llme->tlli = new_tlli;
1045 llme->state = GPRS_LLMS_ASSIGNED;
1046 } else if (old_tlli != 0xffffffff && new_tlli == 0xffffffff) {
1047 /* TLLI Unassignment 8.3.3) */
1048 llme->tlli = llme->old_tlli = 0;
1049 llme->state = GPRS_LLMS_UNASSIGNED;
1050 for (i = 0; i < ARRAY_SIZE(llme->lle); i++) {
1051 struct gprs_llc_lle *l = &llme->lle[i];
1052 l->state = GPRS_LLES_UNASSIGNED;
1053 }
Harald Weltef7fef482010-06-28 22:18:26 +02001054 llme_free(llme);
Harald Welte807a5d82010-06-01 11:53:01 +02001055 } else
1056 return -EINVAL;
1057
1058 return 0;
1059}
Harald Welte496aee42010-06-30 19:59:55 +02001060
Max39550252016-06-28 17:39:20 +02001061/* TLLI unassignment */
1062int gprs_llgmm_unassign(struct gprs_llc_llme *llme)
1063{
Max5aa51962016-07-06 11:33:04 +02001064 return gprs_llgmm_assign(llme, llme->tlli, 0xffffffff);
Max39550252016-06-28 17:39:20 +02001065}
1066
Harald Welte0c1a3032011-10-16 18:49:05 +02001067/* Chapter 7.2.1.2 LLGMM-RESET.req */
1068int gprs_llgmm_reset(struct gprs_llc_llme *llme)
1069{
1070 struct msgb *msg = msgb_alloc_headroom(4096, 1024, "LLC_XID");
Jacob Erlbeck25ad52c2014-09-11 14:20:53 +02001071 struct gprs_llc_lle *lle = &llme->lle[1];
Philipp4ac3aee2016-08-10 12:24:09 +02001072 uint8_t xid_bytes[1024];
Max3b6332f2017-11-01 13:28:38 +01001073 int xid_bytes_len, rc;
Philipp4ac3aee2016-08-10 12:24:09 +02001074 uint8_t *xid;
Harald Welte0c1a3032011-10-16 18:49:05 +02001075
Philipp4ac3aee2016-08-10 12:24:09 +02001076 LOGP(DLLC, LOGL_NOTICE, "LLGM Reset\n");
Max3b6332f2017-11-01 13:28:38 +01001077
1078 rc = osmo_get_rand_id((uint8_t *) &llme->iov_ui, 4);
1079 if (rc < 0) {
1080 LOGP(DLLC, LOGL_ERROR, "osmo_get_rand_id() failed for LLC XID reset: %s\n", strerror(-rc));
1081 return rc;
Maxb997f842016-07-06 15:57:01 +02001082 }
1083
Philipp4ac3aee2016-08-10 12:24:09 +02001084 /* Generate XID message */
1085 xid_bytes_len = gprs_llc_generate_xid_for_gmm_reset(xid_bytes,
1086 sizeof(xid_bytes),llme->iov_ui,llme);
Harald Welte7e5bb622016-09-28 08:20:58 +08001087 if (xid_bytes_len < 0)
Philipp4ac3aee2016-08-10 12:24:09 +02001088 return -EINVAL;
1089 xid = msgb_put(msg, xid_bytes_len);
1090 memcpy(xid, xid_bytes, xid_bytes_len);
Harald Welte0c1a3032011-10-16 18:49:05 +02001091
Jacob Erlbeck25ad52c2014-09-11 14:20:53 +02001092 /* Reset some of the LLC parameters. See GSM 04.64, 8.5.3.1 */
1093 lle->vu_recv = 0;
1094 lle->vu_send = 0;
1095 lle->oc_ui_send = 0;
1096 lle->oc_ui_recv = 0;
1097
Harald Welte0c1a3032011-10-16 18:49:05 +02001098 /* FIXME: Start T200, wait for XID response */
Jacob Erlbeck25ad52c2014-09-11 14:20:53 +02001099 return gprs_llc_tx_xid(lle, msg, 1);
Harald Welte0c1a3032011-10-16 18:49:05 +02001100}
1101
Maxb997f842016-07-06 15:57:01 +02001102int gprs_llgmm_reset_oldmsg(struct msgb* oldmsg, uint8_t sapi,
1103 struct gprs_llc_llme *llme)
Jacob Erlbeck78ecaf02014-09-05 14:32:36 +02001104{
1105 struct msgb *msg = msgb_alloc_headroom(4096, 1024, "LLC_XID");
Philipp4ac3aee2016-08-10 12:24:09 +02001106 uint8_t xid_bytes[1024];
Max3b6332f2017-11-01 13:28:38 +01001107 int xid_bytes_len, rc;
Philipp4ac3aee2016-08-10 12:24:09 +02001108 uint8_t *xid;
Maxb997f842016-07-06 15:57:01 +02001109
Philipp4ac3aee2016-08-10 12:24:09 +02001110 LOGP(DLLC, LOGL_NOTICE, "LLGM Reset\n");
Max3b6332f2017-11-01 13:28:38 +01001111
1112 rc = osmo_get_rand_id((uint8_t *) &llme->iov_ui, 4);
1113 if (rc < 0) {
1114 LOGP(DLLC, LOGL_ERROR, "osmo_get_rand_id() failed for LLC XID reset: %s\n", strerror(-rc));
1115 return rc;
Maxb997f842016-07-06 15:57:01 +02001116 }
Jacob Erlbeck78ecaf02014-09-05 14:32:36 +02001117
Philipp4ac3aee2016-08-10 12:24:09 +02001118 /* Generate XID message */
1119 xid_bytes_len = gprs_llc_generate_xid_for_gmm_reset(xid_bytes,
1120 sizeof(xid_bytes),llme->iov_ui,llme);
Harald Welte7e5bb622016-09-28 08:20:58 +08001121 if (xid_bytes_len < 0)
Philipp4ac3aee2016-08-10 12:24:09 +02001122 return -EINVAL;
1123 xid = msgb_put(msg, xid_bytes_len);
1124 memcpy(xid, xid_bytes, xid_bytes_len);
Jacob Erlbeck78ecaf02014-09-05 14:32:36 +02001125
1126 /* FIXME: Start T200, wait for XID response */
1127
1128 msgb_tlli(msg) = msgb_tlli(oldmsg);
1129 msgb_bvci(msg) = msgb_bvci(oldmsg);
1130 msgb_nsei(msg) = msgb_nsei(oldmsg);
1131
1132 return gprs_llc_tx_u(msg, sapi, 1, GPRS_LLC_U_XID, 1);
1133}
1134
Harald Welte496aee42010-06-30 19:59:55 +02001135int gprs_llc_init(const char *cipher_plugin_path)
1136{
1137 return gprs_cipher_load(cipher_plugin_path);
1138}