blob: f3e9839d6724bf6090d8ecc2700c15d722e62744 [file] [log] [blame]
Pau Espin Pedrolac8a0542024-04-19 17:30:57 +02001/* Component implementing a IMS server towards Asterisk's IMS UE
2 * (C) 2024 by sysmocom - s.f.m.c. GmbH <info@sysmocom.de>
3 * Author: Pau Espin Pedrol <pespin@sysmocom.de>
4 * All rights reserved.
5 *
6 * Released under the terms of GNU General Public License, Version 2 or
7 * (at your option) any later version.
8 *
9 * SPDX-License-Identifier: GPL-2.0-or-later
10 */
11module IMS_ConnectionHandler {
12
Pau Espin Pedrol717379f2024-05-17 18:36:51 +020013import from TCCEncoding_Functions all;
Pau Espin Pedrolac8a0542024-04-19 17:30:57 +020014import from TCCOpenSecurity_Functions all;
15import from General_Types all;
16import from Osmocom_Types all;
17import from Native_Functions all;
18import from Misc_Helpers all;
19
Pau Espin Pedrola674d612024-05-14 19:56:33 +020020/* the PIPE asp port allows us to interact with ip xfrm via stdin/stdout */
21import from PIPEasp_PortType all;
22import from PIPEasp_Types all;
23import from PIPEasp_Templates all;
24
Pau Espin Pedrolac8a0542024-04-19 17:30:57 +020025import from SDP_Types all;
26import from SDP_Templates all;
27
28import from SIP_Emulation all;
29import from SIPmsg_Types all;
30import from SIP_Templates all;
31
Pau Espin Pedrola674d612024-05-14 19:56:33 +020032
33modulepar {
34 charstring mp_ipsec_setup_script_path := "./IMS_ipsec_setup.sh";
35}
36
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +020037const char c_sip_server_name := "osmo-ttcn3-hacks/0.23";
38
39
Pau Espin Pedrolac8a0542024-04-19 17:30:57 +020040type port IMSCoord_PT message
41{
42 inout charstring;
43} with { extension "internal" };
44
45const charstring IMS_COORD_CMD_REGISTERED := "COORD_CMD_REGISTERED";
46
47type component IMS_ConnHdlr extends SIP_ConnHdlr {
48 var charstring g_name;
49 var IMS_ConnHdlrPars g_pars;
50 timer g_Tguard;
51 var PDU_SIP_Request g_rx_sip_req;
52 var PDU_SIP_Response g_rx_sip_resp;
53
54 port IMSCoord_PT COORD;
Pau Espin Pedrola674d612024-05-14 19:56:33 +020055 port PIPEasp_PT PIPE;
Pau Espin Pedrolac8a0542024-04-19 17:30:57 +020056}
57type record of IMS_ConnHdlr IMS_ConnHdlrList;
58
Pau Espin Pedrol901cede2024-05-30 13:03:42 +020059type record IMS_ConnHdlrSubscrPars {
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +020060 charstring remote_sip_host optional,
61 uint16_t remote_sip_port optional,
Pau Espin Pedrol901cede2024-05-30 13:03:42 +020062 charstring imsi,
Pau Espin Pedrolac8a0542024-04-19 17:30:57 +020063 charstring display_name,
64 charstring password,
Pau Espin Pedrol4e6672c2024-05-22 17:03:53 +020065 charstring msisdn,
Pau Espin Pedrol0c5c6472024-05-21 13:13:49 +020066 /* Expected User-Location-Info in P-Access-Network-Info */
67 charstring uli_str,
Pau Espin Pedrol717379f2024-05-17 18:36:51 +020068 octetstring rand,
69 octetstring autn,
Pau Espin Pedrola674d612024-05-14 19:56:33 +020070 charstring ipsec_auth_key,
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +020071 integer ipsec_local_spi_c,
72 integer ipsec_local_spi_s,
73 integer ipsec_remote_spi_c optional,
74 integer ipsec_remote_spi_s optional,
Pau Espin Pedrola674d612024-05-14 19:56:33 +020075 uint16_t ipsec_remote_port_c optional,
76 uint16_t ipsec_remote_port_s optional,
Pau Espin Pedrolac8a0542024-04-19 17:30:57 +020077 SipAddr registrar_sip_record,
78 CallidString registrar_sip_call_id,
79 integer registrar_sip_seq_nr,
Pau Espin Pedrolac8a0542024-04-19 17:30:57 +020080 SipUrl local_sip_url_ext,
81 SipAddr local_sip_record,
82 Contact local_contact,
83 IMS_CallPars cp optional
84}
Pau Espin Pedrol901cede2024-05-30 13:03:42 +020085type record of IMS_ConnHdlrSubscrPars IMS_ConnHdlrSubscrParsList;
86
87
88type record IMS_ConnHdlrPars {
89 float t_guard,
90 charstring realm,
91 charstring local_sip_host,
92 uint16_t local_sip_port,
93 SipUrl registrar_sip_req_uri,
94 Via local_via,
95 IMS_ConnHdlrSubscrPars subscr optional
96}
Pau Espin Pedrolac8a0542024-04-19 17:30:57 +020097type record of IMS_ConnHdlrPars IMS_ConnHdlrParsList;
98
99type record IMS_CallParsMT {
100 /* Whether to wait for COORD.receive(COORD_CMD_PICKUP) before accepting the call. */
101 boolean wait_coord_cmd_pickup,
102 /* Whether to expect CANCEL instead of ACK as answer to our OK */
103 boolean exp_cancel
104}
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200105template (value) IMS_CallParsMT t_IMS_CallParsMT := {
106 wait_coord_cmd_pickup := false,
107 exp_cancel := false
108}
Pau Espin Pedrolac8a0542024-04-19 17:30:57 +0200109
110type record IMS_CallPars {
111 SipAddr calling optional,
112 SipAddr called optional,
113
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200114 From from_addr optional,
115 To to_addr optional,
Pau Espin Pedrolac8a0542024-04-19 17:30:57 +0200116
117 CallidString sip_call_id,
118 integer sip_seq_nr,
119 charstring sip_body optional,
120
121 charstring local_rtp_addr,
122 uint16_t local_rtp_port,
123
124 SDP_Message peer_sdp optional,
125 IMS_CallParsMT mt
126}
127
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200128template (value) IMS_CallPars t_IMS_CallPars(charstring local_rtp_addr,
129 uint16_t local_rtp_port := 0,
130 template (omit) SipAddr calling := omit,
131 template (omit) SipAddr called := omit) := {
132 calling := calling,
133 called := called,
134 from_addr := omit,
135 to_addr := omit,
136 sip_call_id := hex2str(f_rnd_hexstring(15)),
137 sip_seq_nr := f_sip_rand_seq_nr(),
138 sip_body := omit,
139 local_rtp_addr := local_rtp_addr,
140 local_rtp_port := local_rtp_port,
141 peer_sdp := omit,
142 mt := t_IMS_CallParsMT
143}
144
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200145template (value) IMS_ConnHdlrSubscrPars t_IMS_SubscrPars(charstring local_sip_host,
146 uint16_t local_sip_port,
Pau Espin Pedrolf46132e2024-06-04 17:11:59 +0200147 charstring domain,
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200148 charstring imsi,
149 charstring msisdn := "90828",
150 charstring display_name := "Anonymous",
151 charstring password := "secret",
152 template (omit) IMS_CallPars cp := omit) := {
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200153 remote_sip_host := omit,
154 remote_sip_port := omit,
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200155 imsi := imsi,
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200156 display_name := f_sip_str_quote(display_name),
157 password := password,
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200158 msisdn := msisdn,
Pau Espin Pedrol0c5c6472024-05-21 13:13:49 +0200159 uli_str := "2380100010000101",
Pau Espin Pedrola674d612024-05-14 19:56:33 +0200160 /* The Nonce field is the Base64 encoded version of the RAND value and concatenated with the AUTN: */
Pau Espin Pedrol717379f2024-05-17 18:36:51 +0200161 rand := '14987631f65f8e3788a0798b6ebcd08e'O,
162 autn := 'f6e19a7ccb028000a06b19c9544516e5'O,
Pau Espin Pedrola674d612024-05-14 19:56:33 +0200163 ipsec_auth_key := "0x5238297dfcca759bd05d48ff49bc63fa00000000",
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200164 ipsec_local_spi_c := 4142,
165 ipsec_local_spi_s := 4143,
166 ipsec_remote_spi_c := omit,
167 ipsec_remote_spi_s := omit,
Pau Espin Pedrola674d612024-05-14 19:56:33 +0200168 ipsec_remote_port_c := omit,
169 ipsec_remote_port_s := omit,
Pau Espin Pedrolf46132e2024-06-04 17:11:59 +0200170 registrar_sip_record := ts_SipAddr(ts_HostPort(domain),
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200171 ts_UserInfo(imsi),
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200172 f_sip_str_quote(display_name)),
Pau Espin Pedrolf46132e2024-06-04 17:11:59 +0200173 registrar_sip_call_id := hex2str(f_rnd_hexstring(15)) & "@" & domain,
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200174 registrar_sip_seq_nr := f_sip_rand_seq_nr(),
Pau Espin Pedrolf46132e2024-06-04 17:11:59 +0200175 local_sip_url_ext := ts_SipUrl(ts_HostPort(domain, local_sip_port),
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200176 ts_UserInfo(imsi)),
Pau Espin Pedrolf46132e2024-06-04 17:11:59 +0200177 local_sip_record := ts_SipAddr(ts_HostPort(domain),
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200178 ts_UserInfo(imsi)),
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200179 local_contact := valueof(ts_Contact({
180 ts_ContactAddress(
181 ts_Addr_Union_SipUrl(ts_SipUrl(ts_HostPort(
Pau Espin Pedrolf46132e2024-06-04 17:11:59 +0200182 domain,
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200183 local_sip_port),
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200184 ts_UserInfo(imsi))),
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200185 omit)
186 })),
187 cp := cp
188}
189
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200190template (value) IMS_ConnHdlrPars t_IMS_Pars(charstring local_sip_host,
191 uint16_t local_sip_port,
Pau Espin Pedrolf46132e2024-06-04 17:11:59 +0200192 charstring domain,
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200193 charstring imsi,
194 template (omit) IMS_CallPars cp := omit) := {
195 t_guard := 30.0,
Pau Espin Pedrolf46132e2024-06-04 17:11:59 +0200196 realm := domain,
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200197 local_sip_host := local_sip_host,
198 local_sip_port := local_sip_port,
Pau Espin Pedrolf46132e2024-06-04 17:11:59 +0200199 registrar_sip_req_uri := valueof(ts_SipUrlHost(domain)),
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200200 local_via := ts_Via_from(ts_HostPort(local_sip_host, local_sip_port)),
Pau Espin Pedrolf46132e2024-06-04 17:11:59 +0200201 subscr := t_IMS_SubscrPars(local_sip_host, local_sip_port, domain := domain, imsi := imsi, cp := cp)
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200202}
203
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200204private altstep as_Tguard() runs on IMS_ConnHdlr {
205 [] g_Tguard.timeout {
206 setverdict(fail, "Tguard timeout");
207 mtc.stop;
208 }
209}
210
211type function ims_void_fn(charstring id) runs on IMS_ConnHdlr;
212function f_ims_handler_init(ims_void_fn fn, charstring id, IMS_ConnHdlrPars pars)
213runs on IMS_ConnHdlr {
214 g_name := id;
215 g_pars := pars;
216 g_Tguard.start(pars.t_guard);
217 activate(as_Tguard());
218
219 /* call the user-supied test case function */
220 fn.apply(id);
221}
222
223private altstep as_SIP_fail_req(charstring exp_msg_str := "") runs on IMS_ConnHdlr
224{
225 var PDU_SIP_Request sip_req;
226 [] SIP.receive(PDU_SIP_Request:?) -> value sip_req {
227 Misc_Helpers.f_shutdown(__BFILE__, __LINE__, fail,
228 log2str(g_name & ": Received unexpected SIP Req message := ", sip_req, "\nvs exp := ", exp_msg_str));
229 }
230}
231
232private altstep as_SIP_fail_resp(charstring exp_msg_str := "") runs on IMS_ConnHdlr
233{
234 var PDU_SIP_Response sip_resp;
235 [] SIP.receive(PDU_SIP_Response:?) -> value sip_resp {
236 Misc_Helpers.f_shutdown(__BFILE__, __LINE__, fail,
237 log2str(g_name & ": Received unexpected SIP Resp message := ", sip_resp, "\nvs exp := ", exp_msg_str));
238 }
239}
240
Pau Espin Pedrol717379f2024-05-17 18:36:51 +0200241private function f_nonce_from_rand_autn(octetstring rand, octetstring autn) return charstring {
242 var octetstring concat := rand & autn;
243 var charstring nonce := enc_MIME_Base64(concat);
244 log("rand=", rand, " & autn=",autn, " => nonce=", nonce);
245 return nonce;
246}
247
Pau Espin Pedrola674d612024-05-14 19:56:33 +0200248/* HTTP Digest Authentication Using AKA (AKAv1-MD5): RFC 3310 */
249function f_tr_Authorization_AKAv1MD5(WwwAuthenticate www_authenticate,
250 charstring username,
251 charstring uri,
252 integer nc_int := 1)
253return template (present) Authorization {
254 var CommaParam_List digestCln;
255 var template (present) Authorization authorization;
256 var template (present) Credentials cred;
257 var template (omit) GenericParam rx_param;
258
259 digestCln := www_authenticate.challenge[0].digestCln;
260
261 var charstring algorithm := f_sip_param_get_value_present_or_fail(digestCln, "algorithm");
262 var charstring realm := f_sip_param_get_value_present_or_fail(digestCln, "realm");
263 var charstring nonce := f_sip_param_get_value_present_or_fail(digestCln, "nonce");
264
265 var template (present) CommaParam_List digestResponse := superset(
266 tr_Param("username", f_sip_str_quote(username)),
267 tr_Param("realm", f_sip_str_quote(realm)),
268 tr_Param("nonce", f_sip_str_quote(nonce)),
269 tr_Param("uri", f_sip_str_quote(uri)),
270 tr_Param("response", ?),
271 tr_Param("algorithm", algorithm),
272 tr_Param("qop", "auth"),
273 tr_Param("cnonce", ?),
274 tr_Param("nc", ?)
275 );
276 cred := tr_Credentials_DigestResponse(digestResponse);
277 authorization := tr_Authorization(cred);
278 return authorization;
279}
280
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200281private function f_ims_validate_register_contact(Contact rx_contact)
282{
283/* IMS contact shows up like this:
284 * Contact: <sip:8adf9f3d-9342-4060-aa4f-a909f37fd6f6@192.168.101.2:5060>;+g.3gpp.accesstype="cellular2";video;audio;+g.3gpp.smsip;+g.3gpp.nw-init-ussi;+g.3gpp.icsi-ref="urn%3Aurn-7%3A3gpp-service.ims.icsi.mmtel";+sip.instance="<urn:gsma:imei:35589811-338445-0>"
285 */
286 /* TODO: "that the UE must include the IMS Communication Service Identifier (ICSI)
287in the contact: header to indicate IMS Multimedia Telephony." */
288 /* TODO: "The UE must include an IMEI URN in the +sip.instance header field
289parameter of the contact: header." */
290 /* TODO: "If the UE supports SMS over IP, it must include the feature tag
291“+g.3gpp.smsip” in the contact: header." */
292 /* TODO: "If the UE supports conversational audio and video service, then this must
293be indicated by adding a “video” media feature tag to the contact: header." */
294}
295
Pau Espin Pedrol0c5c6472024-05-21 13:13:49 +0200296/* Validate P-Access-Network-Info: RFC7315 6.4 */
297private function f_ims_validate_register_P_Access_Network_info(PDU_SIP_Request req,
298 boolean exp_present := true) runs on IMS_ConnHdlr
299
300{
301 if (not exp_present) {
302 if (ispresent(g_rx_sip_req.msgHeader.p_access_network_info)) {
303 Misc_Helpers.f_shutdown(__BFILE__, __LINE__, fail,
304 log2str(g_name & ": Received unexpected [rfc7315 6.4] P-Access-Info := ",
305 g_rx_sip_req.msgHeader.p_access_network_info));
306 }
307 return;
308 }
309
310 /* exp_present: */
311 var template (present) P_Access_Network_Info expl_tmpl :=
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200312 tr_P_Access_Network_Info({ tr_Access_net_spec_EUTRAN(g_pars.subscr.uli_str) });
Pau Espin Pedrol0c5c6472024-05-21 13:13:49 +0200313
314 if (not ispresent(g_rx_sip_req.msgHeader.p_access_network_info)) {
315 Misc_Helpers.f_shutdown(__BFILE__, __LINE__, fail,
316 log2str(g_name & ": Received no P-Access-Info vs exp := ",
317 expl_tmpl));
318 }
319 if (not match(g_rx_sip_req.msgHeader.p_access_network_info, expl_tmpl)) {
320 Misc_Helpers.f_shutdown(__BFILE__, __LINE__, fail,
321 log2str(g_name & ": Received unexpected P-Access-Info := ",
322 g_rx_sip_req.msgHeader.p_access_network_info,
323 "\nvs exp := ", expl_tmpl));
324 }
325}
326
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200327private function f_ims_parse_security_client(Security_client security_client) runs on IMS_ConnHdlr
328{
329 var boolean found := false;
330 for (var integer i := 0; i < lengthof(security_client.sec_mechanism_list); i := i + 1) {
331 var Security_mechanism sec_mec := security_client.sec_mechanism_list[i];
332 if (sec_mec.mechanism_name != "ipsec-3gpp") {
333 log("Skipping Security Mechansim: ", sec_mec.mechanism_name);
334 continue;
335 }
336 var SemicolonParam_List sec_pars := sec_mec.mechanism_params;
337 var charstring par_val;
338 par_val := f_sip_param_get_value_present_or_fail(sec_pars, "alg");
339 if (par_val != "hmac-sha-1-96") {
340 log("Skipping Security Mechansim Algo: ", par_val);
341 continue;
342 }
343 par_val := f_sip_param_get_value_present_or_fail(sec_pars, "spi-c");
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200344 g_pars.subscr.ipsec_remote_spi_c := str2int(par_val);
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200345 par_val := f_sip_param_get_value_present_or_fail(sec_pars, "spi-s");
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200346 g_pars.subscr.ipsec_remote_spi_s := str2int(par_val);
Pau Espin Pedrola674d612024-05-14 19:56:33 +0200347 par_val := f_sip_param_get_value_present_or_fail(sec_pars, "port-c");
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200348 g_pars.subscr.ipsec_remote_port_c := str2int(par_val);
Pau Espin Pedrola674d612024-05-14 19:56:33 +0200349 par_val := f_sip_param_get_value_present_or_fail(sec_pars, "port-s");
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200350 g_pars.subscr.ipsec_remote_port_s := str2int(par_val);
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200351 found := true;
352 break;
353 }
354
355 if (not found) {
356 Misc_Helpers.f_shutdown(__BFILE__, __LINE__, fail,
357 log2str(g_name & "alg=hmac-sha-1-96 not found: ", security_client));
358 }
359
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200360 log("ipsec: remote_spi_c=", g_pars.subscr.ipsec_remote_spi_c, " remote_spi_s=", g_pars.subscr.ipsec_remote_spi_s,
361 "local_spi_c=", g_pars.subscr.ipsec_local_spi_c, " local_spi_s=", g_pars.subscr.ipsec_local_spi_s);
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200362}
363
Pau Espin Pedrola674d612024-05-14 19:56:33 +0200364private function f_IMS_exec_sync(charstring cmdline, template (present) integer rc := 0)
365 runs on IMS_ConnHdlr return ASP_PResult {
366 var ASP_PResult res;
367
368 map(self:PIPE, system:PIPE);
369 res := f_PIPEasp_exec_sync_PResult(PIPE, cmdline, tr_PResult(?, ?, rc));
370 unmap(self:PIPE, system:PIPE);
371
372 return res;
373}
374
375private function f_ims_setup_ipsec() runs on IMS_ConnHdlr
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200376{
Pau Espin Pedrola674d612024-05-14 19:56:33 +0200377 var ASP_PResult res;
378
379 var charstring cmd := mp_ipsec_setup_script_path & " " &
380 g_pars.local_sip_host & " " &
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200381 int2str(g_pars.local_sip_port) & " " & int2str(g_pars.subscr.ipsec_local_spi_c) & " " &
382 int2str(g_pars.local_sip_port) & " " & int2str(g_pars.subscr.ipsec_local_spi_s) & " " &
383 g_pars.subscr.remote_sip_host & " " &
384 int2str(g_pars.subscr.ipsec_remote_port_c) & " " & int2str(g_pars.subscr.ipsec_remote_spi_c) & " " &
385 int2str(g_pars.subscr.ipsec_remote_port_s) & " " & int2str(g_pars.subscr.ipsec_remote_spi_s) & " " &
386 g_pars.subscr.ipsec_auth_key;
Pau Espin Pedrola674d612024-05-14 19:56:33 +0200387
388 res := f_IMS_exec_sync(cmd);
389
390 /* Debug applied rules: */
391 /*
392 res := f_IMS_exec_sync("ip xfrm state");
393 log("ip-xfrm-state Result-Stdout: " & res.stdout);
394
395 res := f_IMS_exec_sync("ip xfrm policy");
396 log("ip-xfrm-policy Result-Stdout: " & res.stdout);
397 */
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200398}
399
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200400private function f_tr_Via_response(Via via_req) return template (present) Via {
401 template (present) SemicolonParam_List via_resp_params := ?;
402
403 /*via_resp_params := {
404 { id := "rport", paramValue := int2str(g_pars.subscr.remote_sip_port.subscr.remote_sip_port) },
405 { id := "received", paramValue := g_pars.subscr.remote_sip_host }
406 }; */
407 return tr_Via_from(via_req.viaBody[0].sentBy,
408 via_req.viaBody[0].sentProtocol.transport,
409 via_resp_params);
410}
411
412private function f_tr_From(template (value) SipAddr from_req) return template (present) SipAddr {
413 return tr_SipAddr_from_val(from_req);
414}
415
416private altstep as_SIP_expect_req(template (present) PDU_SIP_Request sip_expect, boolean fail_others := true) runs on IMS_ConnHdlr
417{
418 var charstring sip_expect_str := log2str(sip_expect);
419 [] SIP.receive(sip_expect) -> value g_rx_sip_req;
420 [fail_others] as_SIP_fail_req(sip_expect_str);
421 [fail_others] as_SIP_fail_resp(sip_expect_str);
422}
423
424private function f_gen_sdp() runs on IMS_ConnHdlr return charstring {
425 var charstring sdp :=
426 "v=0\r\n" &
427 "o=0502 2390 1824 IN IP4 " & g_pars.subscr.cp.local_rtp_addr & "\r\n" &
428 "s=Talk\r\n" &
429 "c=IN IP4 " & g_pars.subscr.cp.local_rtp_addr & "\r\n" &
430 "t=0 0\r\n" &
431 "a=rtcp-xr:rcvr-rtt=all:10000 stat-summary=loss,dup,jitt,TTL voip-metrics\r\n" &
432 "a=record:off\r\n" &
433 "m=audio " & int2str(g_pars.subscr.cp.local_rtp_port) & " RTP/AVP 8 96 97 98 0 18 99 100 101\r\n" &
434 "a=rtpmap:8 PCMA/8000\r\n" &
435 "a=rtpmap:96 opus/48000/2\r\n" &
436 "a=fmtp:96 useinbandfec=1\r\n" &
437 "a=rtpmap:97 speex/16000\r\n" &
438 "a=fmtp:97 vbr=on\r\n" &
439 "a=rtpmap:98 speex/8000\r\n" &
440 "a=fmtp:98 vbr=on\r\n" &
441 "a=fmtp:18 annexb=yes\r\n" &
442 "a=rtpmap:99 telephone-event/48000\r\n" &
443 "a=rtpmap:100 telephone-event/16000\r\n" &
444 "a=rtpmap:101 telephone-event/8000\r\n" &
445 "a=rtcp:" & int2str(g_pars.subscr.cp.local_rtp_port + 1) & "\r\n" &
446 "a=rtcp-fb:* trr-int 1000\r\n" &
447 "a=rtcp-fb:* ccm tmmbr\r\n";
448 return sdp;
449}
450
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200451/* Peer is calling us, accept it: */
452altstep as_IMS_register(boolean exp_update_to_direct_rtp := true,
453 boolean fail_others := true) runs on IMS_ConnHdlr
454{
455 var template (present) PDU_SIP_Request exp_req :=
456 tr_SIP_REGISTER(g_pars.registrar_sip_req_uri,
457 ?,
Pau Espin Pedrol41b0e072024-05-29 18:25:51 +0200458 tr_From(),
459 tr_To(),
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200460 tr_Via_from(?),
461 require := tr_Require(superset("sec-agree")),
462 security_client := tr_Security_client(superset(tr_Security_mechanism("ipsec-3gpp",
463 superset(tr_Param("alg","hmac-sha-1-96"))))),
464 supported := tr_Supported(superset("path", "sec-agree")));
465 var charstring sip_expect_str := log2str(exp_req);
466
467 [] SIP.receive(exp_req) -> value g_rx_sip_req {
468 var template (value) PDU_SIP_Response tx_resp;
469 var Via via;
470 var CallidString sip_call_id;
471 var Contact contact;
Pau Espin Pedrol41b0e072024-05-29 18:25:51 +0200472 var template (value) From from_addr;
473 var template (value) To to_addr;
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200474 var template (value) CommaParam_List digestCln ;
475 var template (value) WwwAuthenticate wwwAuthenticate;
Pau Espin Pedrol4e6672c2024-05-22 17:03:53 +0200476 var template (value) P_Associated_Uri p_associated_uri := ts_P_Associated_Uri({});
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200477 var template (value) Security_server security_server;
478 var template (value) Server server_name := ts_Server({c_sip_server_name});
Pau Espin Pedrola674d612024-05-14 19:56:33 +0200479 var template (value) Require require := ts_Require({"sec-agree"});
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200480 var template (value) Supported supported := ts_Supported({"sec-agree"});
Pau Espin Pedrola674d612024-05-14 19:56:33 +0200481 var template (present) Authorization authorization;
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200482 var integer sip_seq_nr;
483 var charstring tx_sdp;
484
485 sip_call_id := g_rx_sip_req.msgHeader.callId.callid;
486 via := g_rx_sip_req.msgHeader.via;
487 via.viaBody[0].viaParams := f_sip_param_set(via.viaBody[0].viaParams, "rport", "1234"); /* TODO: set remote src port of the REGISTER */
Pau Espin Pedrol41b0e072024-05-29 18:25:51 +0200488 from_addr := g_rx_sip_req.msgHeader.fromField;
489 to_addr := g_rx_sip_req.msgHeader.toField;
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200490 sip_seq_nr := g_rx_sip_req.msgHeader.cSeq.seqNumber;
491
492 contact := g_rx_sip_req.msgHeader.contact;
493 f_ims_validate_register_contact(contact);
494
Pau Espin Pedrol0c5c6472024-05-21 13:13:49 +0200495 /* Validate P-Access-Network-Info: rfc7315 6.4:
496 * "3GPP will use the P-Access-Network-Info header field to
497 * carry relatively sensitive information like the cell ID. Therefore,
498 * the information MUST NOT be sent outside of the 3GPP domain.""
499 * [...] "the sensitive information carried in the
500 * P-Access-Network-Info header field MUST NOT be sent in any initial
501 * unauthenticated and unprotected requests (e.g., REGISTER)."
502 */
503 f_ims_validate_register_P_Access_Network_info(g_rx_sip_req, exp_present := false);
504
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200505 /* TODO: Validate "Expires" is 600000 */
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200506
507 /* Tx 100 Tyring */
508 tx_resp := ts_SIP_Response_Trying(sip_call_id,
509 from_addr,
510 to_addr,
511 via,
512 sip_seq_nr,
513 "REGISTER",
514 allow := omit,
515 server := server_name,
516 userAgent := omit);
517 SIP.send(tx_resp);
518
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200519 var HostPort hp := valueof(contact.contactBody.contactAddresses[0].addressField.nameAddr.addrSpec.hostPort);
520 g_pars.subscr.remote_sip_host := hp.host;
521 if (ispresent(hp.portField)) {
522 g_pars.subscr.remote_sip_port := hp.portField;
523 } else {
524 g_pars.subscr.remote_sip_port := 5060;
525 }
Pau Espin Pedrola674d612024-05-14 19:56:33 +0200526 f_ims_parse_security_client(g_rx_sip_req.msgHeader.security_client);
527 f_ims_setup_ipsec();
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200528
Pau Espin Pedrol41b0e072024-05-29 18:25:51 +0200529 to_addr.toParams := f_sip_param_set(to_addr.toParams, "tag", f_sip_rand_tag());
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200530
531 digestCln := {
532 ts_Param("realm", f_sip_str_quote(g_pars.realm)),
533 ts_Param("qop", f_sip_str_quote("auth")),
534 ts_Param("algorithm", "AKAv1-MD5"),
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200535 ts_Param("nonce", f_sip_str_quote(f_nonce_from_rand_autn(g_pars.subscr.rand, g_pars.subscr.autn)))
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200536 /* "opaque not needed in IMS "*/
537 };
538 wwwAuthenticate := ts_WwwAuthenticate( { ts_Challenge_digestCln(digestCln) } )
539
540 /* Security-Server: ipsec-3gpp;q=0.1;prot=esp;mod=trans;spi-c=4096;spi-s=4097;port-c=5104;port-s=6104;alg=hmac-sha-1-96;ealg=null */
541 var template (value) SemicolonParam_List sec_params := {
542 ts_Param("q", "0.1"),
543 ts_Param("prot", "esp"),
544 ts_Param("mod", "trans"),
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200545 ts_Param("spi-c", int2str(g_pars.subscr.ipsec_local_spi_c)),
546 ts_Param("spi-s", int2str(g_pars.subscr.ipsec_local_spi_s)),
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200547 ts_Param("port-c", int2str(g_pars.local_sip_port)),
548 ts_Param("port-s", int2str(g_pars.local_sip_port)),
549 ts_Param("alg", "hmac-sha-1-96"),
550 ts_Param("ealg", "null")
551 };
552 security_server := ts_Security_server({
553 ts_Security_mechanism("ipsec-3gpp", sec_params)
554 });
Pau Espin Pedrola674d612024-05-14 19:56:33 +0200555
556 /* Tx 401 Unauthorized */
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200557 tx_resp := ts_SIP_Response_Unauthorized(sip_call_id,
558 from_addr,
559 to_addr,
560 via,
561 wwwAuthenticate,
562 sip_seq_nr,
563 "REGISTER",
Pau Espin Pedrol4e6672c2024-05-22 17:03:53 +0200564 p_associated_uri := p_associated_uri,
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200565 security_server := security_server,
566 server := server_name,
567 supported := supported,
568 userAgent := omit);
569 SIP.send(tx_resp);
570
Pau Espin Pedrola674d612024-05-14 19:56:33 +0200571 /* Now we should receive a new REGISTER over ipsec: */
572
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200573 /* TODO: Generate expected Authoritzation based on AKAv1-MD5: */
574 /*authorization := f_sip_digest_gen_Authorization(valueof(wwwAuthenticate),
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200575 g_pars.user, g_pars.subscr.password,
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200576 "REGISTER",
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200577 f_sip_SipUrl_to_str(g_pars.subscr.registrar_sip_record.addr.nameAddr.addrSpec))
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200578 */
Pau Espin Pedrola674d612024-05-14 19:56:33 +0200579 authorization := f_tr_Authorization_AKAv1MD5(valueof(wwwAuthenticate),
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200580 g_pars.subscr.imsi & "@" & g_pars.realm,
Pau Espin Pedrolb0dbf7a2024-05-22 18:12:15 +0200581 f_sip_SipUrl_to_str(g_pars.registrar_sip_req_uri));
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200582 /* TODO: match Authorization from above: */
583 exp_req :=
584 tr_SIP_REGISTER(g_pars.registrar_sip_req_uri,
585 ?,
Pau Espin Pedrol41b0e072024-05-29 18:25:51 +0200586 tr_From(),
587 tr_To(),
Pau Espin Pedrola674d612024-05-14 19:56:33 +0200588 tr_Via_from(?),
589 authorization := authorization);
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200590 SIP.receive(exp_req) -> value g_rx_sip_req;
591
592 sip_call_id := g_rx_sip_req.msgHeader.callId.callid;
593 via := g_rx_sip_req.msgHeader.via;
Pau Espin Pedrol41b0e072024-05-29 18:25:51 +0200594 from_addr := g_rx_sip_req.msgHeader.fromField;
595 to_addr := g_rx_sip_req.msgHeader.toField;
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200596 sip_seq_nr := g_rx_sip_req.msgHeader.cSeq.seqNumber;
597
Pau Espin Pedrola674d612024-05-14 19:56:33 +0200598 /* Tx 100 Trying */
599 tx_resp := ts_SIP_Response_Trying(sip_call_id,
600 from_addr,
601 to_addr,
602 via,
603 sip_seq_nr,
604 "REGISTER",
605 allow := omit,
606 server := server_name,
607 userAgent := omit);
608 SIP.send(tx_resp);
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200609
Pau Espin Pedrol0c5c6472024-05-21 13:13:49 +0200610 /* Validate P-Access-Network-Info: */
611 f_ims_validate_register_P_Access_Network_info(g_rx_sip_req, exp_present := true);
612
Pau Espin Pedrol4e6672c2024-05-22 17:03:53 +0200613 p_associated_uri := ts_P_Associated_Uri({
614 ts_P_Assoc_uri_spec(ts_NameAddr(ts_SipUrl(ts_HostPort(g_pars.realm),
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200615 ts_UserInfo(g_pars.subscr.msisdn),
Pau Espin Pedrol4e6672c2024-05-22 17:03:53 +0200616 scheme := "sip"))),
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200617 ts_P_Assoc_uri_spec(ts_NameAddr(ts_SipUrl(ts_HostPort(g_pars.subscr.msisdn),
Pau Espin Pedrol4e6672c2024-05-22 17:03:53 +0200618 omit,
619 scheme := "tel"))),
620 ts_P_Assoc_uri_spec(g_rx_sip_req.msgHeader.toField.addressField.nameAddr)
621 });
622
Pau Espin Pedrola674d612024-05-14 19:56:33 +0200623 /* Tx 200 OK */
Pau Espin Pedrol41b0e072024-05-29 18:25:51 +0200624 to_addr.toParams := f_sip_param_set(to_addr.toParams, "tag", f_sip_rand_tag());
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200625 tx_resp := ts_SIP_Response(sip_call_id,
626 from_addr,
627 to_addr,
628 "REGISTER", 200,
629 sip_seq_nr,
630 "OK",
Pau Espin Pedrola674d612024-05-14 19:56:33 +0200631 via,
Pau Espin Pedrol4e6672c2024-05-22 17:03:53 +0200632 p_associated_uri := p_associated_uri,
Pau Espin Pedrola674d612024-05-14 19:56:33 +0200633 require := require,
634 server := server_name,
635 supported := supported,
636 userAgent := omit);
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200637 SIP.send(tx_resp);
638 }
639 [fail_others] as_SIP_fail_resp(sip_expect_str);
640 [fail_others] as_SIP_fail_req(sip_expect_str);
641
642}
643
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200644private function f_ConnHdlr_parse_initial_SIP_INVITE(PDU_SIP_Request rx_sip_req) runs on IMS_ConnHdlr
645{
646 f_SDP_decodeMessage(rx_sip_req.messageBody, g_pars.subscr.cp.peer_sdp);
647 log("Rx Initial MO INVITE decoded SDP: ", g_pars.subscr.cp.peer_sdp);
648
649 /* Obtain params: */
650 g_pars.subscr.cp.sip_call_id := rx_sip_req.msgHeader.callId.callid;
651 g_pars.subscr.cp.from_addr := rx_sip_req.msgHeader.fromField;
652 g_pars.subscr.cp.to_addr := rx_sip_req.msgHeader.toField;
653 g_pars.subscr.cp.to_addr.toParams := f_sip_param_set(g_pars.subscr.cp.to_addr.toParams, "tag", f_sip_rand_tag());
654 g_pars.subscr.cp.sip_seq_nr := rx_sip_req.msgHeader.cSeq.seqNumber;
655}
656
657/* Peer is calling us, accept it: */
658altstep as_IMS_mo_call_accept(boolean exp_update_to_direct_rtp := false,
659 boolean fail_others := true) runs on IMS_ConnHdlr
660{
661 var template (present) PDU_SIP_Request exp_req :=
662 tr_SIP_INVITE(f_tr_SipUrl_opt_defport(ts_SipUrl_from_Addr_Union(g_pars.subscr.cp.called.addr)),
663 ?,
Pau Espin Pedrol09087012024-06-04 18:07:48 +0200664 tr_From(tr_Addr_Union_from_val(g_pars.subscr.cp.calling.addr), *),
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200665 tr_To(tr_Addr_Union_from_val(g_pars.subscr.cp.called.addr), *),
666 tr_Via_from(f_tr_HostPort(g_pars.subscr.remote_sip_host, g_pars.subscr.remote_sip_port)),
667 ?, ?);
668 var charstring sip_expect_str := log2str(exp_req);
669
670 [] SIP.receive(exp_req) -> value g_rx_sip_req {
671 var template (value) PDU_SIP_Response tx_resp;
672 var Via via;
673 var charstring tx_sdp;
674
675 /* Obtain params: */
676 f_ConnHdlr_parse_initial_SIP_INVITE(g_rx_sip_req);
677 via := g_rx_sip_req.msgHeader.via;
678
679
680 /* Tx 180 Ringing */
681 tx_resp := ts_SIP_Response_Ringing(g_pars.subscr.cp.sip_call_id,
682 g_pars.subscr.cp.from_addr,
683 g_pars.subscr.cp.to_addr,
684 via,
685 g_pars.subscr.cp.sip_seq_nr);
686 SIP.send(tx_resp);
687
688 /* Tx 200 OK */
689 tx_sdp := f_gen_sdp();
690 tx_resp := ts_SIP_Response(g_pars.subscr.cp.sip_call_id,
691 g_pars.subscr.cp.from_addr,
692 g_pars.subscr.cp.to_addr,
693 "INVITE", 200,
694 g_pars.subscr.cp.sip_seq_nr,
695 "OK",
696 via,
697 body := tx_sdp);
698 SIP.send(tx_resp);
699
700 /* Wait for ACK */
701 exp_req := tr_SIP_ACK(f_tr_SipUrl_opt_defport(ts_SipUrl_from_Addr_Union(g_pars.subscr.cp.called.addr)),
702 g_pars.subscr.cp.sip_call_id,
703 g_pars.subscr.cp.from_addr,
704 g_pars.subscr.cp.to_addr,
705 f_tr_Via_response(via),
706 g_pars.subscr.cp.sip_seq_nr, *);
707 as_SIP_expect_req(exp_req);
708 }
709 [fail_others] as_SIP_fail_resp(sip_expect_str);
710 [fail_others] as_SIP_fail_req(sip_expect_str);
711
712}
713
714/* Call is terminated by peer: */
715altstep as_IMS_exp_call_hangup(template (present) integer exp_seq_nr := ?, boolean fail_others := true) runs on IMS_ConnHdlr
716{
717 var template (present) PDU_SIP_Request exp_req :=
718 tr_SIP_BYE(f_tr_SipUrl_opt_defport(ts_SipUrl_from_Addr_Union(g_pars.subscr.cp.called.addr)),
719 g_pars.subscr.cp.sip_call_id,
720 g_pars.subscr.cp.from_addr,
721 g_pars.subscr.cp.to_addr,
722 tr_Via_from(f_tr_HostPort(g_pars.subscr.remote_sip_host, g_pars.subscr.remote_sip_port)),
723 exp_seq_nr);
724 var charstring sip_expect_str := log2str(exp_req);
725
726 [] SIP.receive(exp_req) -> value g_rx_sip_req {
727 var template (value) PDU_SIP_Response tx_resp;
728 var charstring tx_sdp;
729 var Via via;
730
731 /* Update parameters: */
732 g_pars.subscr.cp.sip_seq_nr := g_rx_sip_req.msgHeader.cSeq.seqNumber;
733 /* "branch" has changed: */
734 via := g_rx_sip_req.msgHeader.via;
735
736 /* Tx 200 OK */
737 tx_sdp := f_gen_sdp();
738 tx_resp := ts_SIP_Response(g_pars.subscr.cp.sip_call_id,
739 g_pars.subscr.cp.from_addr,
740 g_pars.subscr.cp.to_addr,
741 "BYE", 200,
742 g_pars.subscr.cp.sip_seq_nr,
743 "OK",
744 via,
745 body := tx_sdp);
746 SIP.send(tx_resp);
747 }
748 [fail_others] as_SIP_fail_resp(sip_expect_str);
749 [fail_others] as_SIP_fail_req(sip_expect_str);
750}
751
Pau Espin Pedrolac8a0542024-04-19 17:30:57 +0200752}