blob: 3f0c380e82dbc03ef9def0d308e815e2742b0123 [file] [log] [blame]
Pau Espin Pedrolac8a0542024-04-19 17:30:57 +02001/* Component implementing a IMS server towards Asterisk's IMS UE
2 * (C) 2024 by sysmocom - s.f.m.c. GmbH <info@sysmocom.de>
3 * Author: Pau Espin Pedrol <pespin@sysmocom.de>
4 * All rights reserved.
5 *
6 * Released under the terms of GNU General Public License, Version 2 or
7 * (at your option) any later version.
8 *
9 * SPDX-License-Identifier: GPL-2.0-or-later
10 */
11module IMS_ConnectionHandler {
12
Pau Espin Pedrol717379f2024-05-17 18:36:51 +020013import from TCCEncoding_Functions all;
Pau Espin Pedrolac8a0542024-04-19 17:30:57 +020014import from TCCOpenSecurity_Functions all;
15import from General_Types all;
16import from Osmocom_Types all;
17import from Native_Functions all;
18import from Misc_Helpers all;
19
Pau Espin Pedrola674d612024-05-14 19:56:33 +020020/* the PIPE asp port allows us to interact with ip xfrm via stdin/stdout */
21import from PIPEasp_PortType all;
22import from PIPEasp_Types all;
23import from PIPEasp_Templates all;
24
Pau Espin Pedrolac8a0542024-04-19 17:30:57 +020025import from SDP_Types all;
26import from SDP_Templates all;
27
28import from SIP_Emulation all;
29import from SIPmsg_Types all;
30import from SIP_Templates all;
31
Pau Espin Pedrola674d612024-05-14 19:56:33 +020032
33modulepar {
34 charstring mp_ipsec_setup_script_path := "./IMS_ipsec_setup.sh";
35}
36
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +020037const char c_sip_server_name := "osmo-ttcn3-hacks/0.23";
38
39
Pau Espin Pedrolac8a0542024-04-19 17:30:57 +020040type port IMSCoord_PT message
41{
42 inout charstring;
43} with { extension "internal" };
44
45const charstring IMS_COORD_CMD_REGISTERED := "COORD_CMD_REGISTERED";
46
47type component IMS_ConnHdlr extends SIP_ConnHdlr {
48 var charstring g_name;
49 var IMS_ConnHdlrPars g_pars;
50 timer g_Tguard;
51 var PDU_SIP_Request g_rx_sip_req;
52 var PDU_SIP_Response g_rx_sip_resp;
53
54 port IMSCoord_PT COORD;
Pau Espin Pedrola674d612024-05-14 19:56:33 +020055 port PIPEasp_PT PIPE;
Pau Espin Pedrolac8a0542024-04-19 17:30:57 +020056}
57type record of IMS_ConnHdlr IMS_ConnHdlrList;
58
Pau Espin Pedrol901cede2024-05-30 13:03:42 +020059type record IMS_ConnHdlrSubscrPars {
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +020060 charstring remote_sip_host optional,
61 uint16_t remote_sip_port optional,
Pau Espin Pedrol901cede2024-05-30 13:03:42 +020062 charstring imsi,
Pau Espin Pedrolac8a0542024-04-19 17:30:57 +020063 charstring display_name,
64 charstring password,
Pau Espin Pedrol4e6672c2024-05-22 17:03:53 +020065 charstring msisdn,
Pau Espin Pedrol0c5c6472024-05-21 13:13:49 +020066 /* Expected User-Location-Info in P-Access-Network-Info */
67 charstring uli_str,
Pau Espin Pedrol717379f2024-05-17 18:36:51 +020068 octetstring rand,
69 octetstring autn,
Pau Espin Pedrola674d612024-05-14 19:56:33 +020070 charstring ipsec_auth_key,
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +020071 integer ipsec_local_spi_c,
72 integer ipsec_local_spi_s,
73 integer ipsec_remote_spi_c optional,
74 integer ipsec_remote_spi_s optional,
Pau Espin Pedrola674d612024-05-14 19:56:33 +020075 uint16_t ipsec_remote_port_c optional,
76 uint16_t ipsec_remote_port_s optional,
Pau Espin Pedrolac8a0542024-04-19 17:30:57 +020077 SipAddr registrar_sip_record,
78 CallidString registrar_sip_call_id,
79 integer registrar_sip_seq_nr,
Pau Espin Pedrolac8a0542024-04-19 17:30:57 +020080 SipUrl local_sip_url_ext,
81 SipAddr local_sip_record,
82 Contact local_contact,
83 IMS_CallPars cp optional
84}
Pau Espin Pedrol901cede2024-05-30 13:03:42 +020085type record of IMS_ConnHdlrSubscrPars IMS_ConnHdlrSubscrParsList;
86
87
88type record IMS_ConnHdlrPars {
89 float t_guard,
90 charstring realm,
91 charstring local_sip_host,
92 uint16_t local_sip_port,
93 SipUrl registrar_sip_req_uri,
94 Via local_via,
95 IMS_ConnHdlrSubscrPars subscr optional
96}
Pau Espin Pedrolac8a0542024-04-19 17:30:57 +020097type record of IMS_ConnHdlrPars IMS_ConnHdlrParsList;
98
99type record IMS_CallParsMT {
100 /* Whether to wait for COORD.receive(COORD_CMD_PICKUP) before accepting the call. */
101 boolean wait_coord_cmd_pickup,
102 /* Whether to expect CANCEL instead of ACK as answer to our OK */
103 boolean exp_cancel
104}
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200105template (value) IMS_CallParsMT t_IMS_CallParsMT := {
106 wait_coord_cmd_pickup := false,
107 exp_cancel := false
108}
Pau Espin Pedrolac8a0542024-04-19 17:30:57 +0200109
110type record IMS_CallPars {
111 SipAddr calling optional,
112 SipAddr called optional,
113
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200114 From from_addr optional,
115 To to_addr optional,
Pau Espin Pedrolac8a0542024-04-19 17:30:57 +0200116
117 CallidString sip_call_id,
118 integer sip_seq_nr,
119 charstring sip_body optional,
120
121 charstring local_rtp_addr,
122 uint16_t local_rtp_port,
123
124 SDP_Message peer_sdp optional,
125 IMS_CallParsMT mt
126}
127
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200128template (value) IMS_CallPars t_IMS_CallPars(charstring local_rtp_addr,
129 uint16_t local_rtp_port := 0,
130 template (omit) SipAddr calling := omit,
131 template (omit) SipAddr called := omit) := {
132 calling := calling,
133 called := called,
134 from_addr := omit,
135 to_addr := omit,
136 sip_call_id := hex2str(f_rnd_hexstring(15)),
137 sip_seq_nr := f_sip_rand_seq_nr(),
138 sip_body := omit,
139 local_rtp_addr := local_rtp_addr,
140 local_rtp_port := local_rtp_port,
141 peer_sdp := omit,
142 mt := t_IMS_CallParsMT
143}
144
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200145template (value) IMS_ConnHdlrSubscrPars t_IMS_SubscrPars(charstring local_sip_host,
146 uint16_t local_sip_port,
147 charstring imsi,
148 charstring msisdn := "90828",
149 charstring display_name := "Anonymous",
150 charstring password := "secret",
151 template (omit) IMS_CallPars cp := omit) := {
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200152 remote_sip_host := omit,
153 remote_sip_port := omit,
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200154 imsi := imsi,
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200155 display_name := f_sip_str_quote(display_name),
156 password := password,
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200157 msisdn := msisdn,
Pau Espin Pedrol0c5c6472024-05-21 13:13:49 +0200158 uli_str := "2380100010000101",
Pau Espin Pedrola674d612024-05-14 19:56:33 +0200159 /* The Nonce field is the Base64 encoded version of the RAND value and concatenated with the AUTN: */
Pau Espin Pedrol717379f2024-05-17 18:36:51 +0200160 rand := '14987631f65f8e3788a0798b6ebcd08e'O,
161 autn := 'f6e19a7ccb028000a06b19c9544516e5'O,
Pau Espin Pedrola674d612024-05-14 19:56:33 +0200162 ipsec_auth_key := "0x5238297dfcca759bd05d48ff49bc63fa00000000",
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200163 ipsec_local_spi_c := 4142,
164 ipsec_local_spi_s := 4143,
165 ipsec_remote_spi_c := omit,
166 ipsec_remote_spi_s := omit,
Pau Espin Pedrola674d612024-05-14 19:56:33 +0200167 ipsec_remote_port_c := omit,
168 ipsec_remote_port_s := omit,
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200169 registrar_sip_record := ts_SipAddr(ts_HostPort(local_sip_host),
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200170 ts_UserInfo(imsi),
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200171 f_sip_str_quote(display_name)),
172 registrar_sip_call_id := hex2str(f_rnd_hexstring(15)) & "@" & local_sip_host,
173 registrar_sip_seq_nr := f_sip_rand_seq_nr(),
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200174 local_sip_url_ext := ts_SipUrl(ts_HostPort(local_sip_host, local_sip_port),
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200175 ts_UserInfo(imsi)),
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200176 local_sip_record := ts_SipAddr(ts_HostPort(local_sip_host),
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200177 ts_UserInfo(imsi)),
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200178 local_contact := valueof(ts_Contact({
179 ts_ContactAddress(
180 ts_Addr_Union_SipUrl(ts_SipUrl(ts_HostPort(
181 local_sip_host,
182 local_sip_port),
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200183 ts_UserInfo(imsi))),
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200184 omit)
185 })),
186 cp := cp
187}
188
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200189template (value) IMS_ConnHdlrPars t_IMS_Pars(charstring local_sip_host,
190 uint16_t local_sip_port,
191 charstring imsi,
192 template (omit) IMS_CallPars cp := omit) := {
193 t_guard := 30.0,
194 realm := local_sip_host,
195 local_sip_host := local_sip_host,
196 local_sip_port := local_sip_port,
197 registrar_sip_req_uri := valueof(ts_SipUrlHost(local_sip_host)),
198 local_via := ts_Via_from(ts_HostPort(local_sip_host, local_sip_port)),
199 subscr := t_IMS_SubscrPars(local_sip_host, local_sip_port, imsi := imsi, cp := cp)
200}
201
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200202private altstep as_Tguard() runs on IMS_ConnHdlr {
203 [] g_Tguard.timeout {
204 setverdict(fail, "Tguard timeout");
205 mtc.stop;
206 }
207}
208
209type function ims_void_fn(charstring id) runs on IMS_ConnHdlr;
210function f_ims_handler_init(ims_void_fn fn, charstring id, IMS_ConnHdlrPars pars)
211runs on IMS_ConnHdlr {
212 g_name := id;
213 g_pars := pars;
214 g_Tguard.start(pars.t_guard);
215 activate(as_Tguard());
216
217 /* call the user-supied test case function */
218 fn.apply(id);
219}
220
221private altstep as_SIP_fail_req(charstring exp_msg_str := "") runs on IMS_ConnHdlr
222{
223 var PDU_SIP_Request sip_req;
224 [] SIP.receive(PDU_SIP_Request:?) -> value sip_req {
225 Misc_Helpers.f_shutdown(__BFILE__, __LINE__, fail,
226 log2str(g_name & ": Received unexpected SIP Req message := ", sip_req, "\nvs exp := ", exp_msg_str));
227 }
228}
229
230private altstep as_SIP_fail_resp(charstring exp_msg_str := "") runs on IMS_ConnHdlr
231{
232 var PDU_SIP_Response sip_resp;
233 [] SIP.receive(PDU_SIP_Response:?) -> value sip_resp {
234 Misc_Helpers.f_shutdown(__BFILE__, __LINE__, fail,
235 log2str(g_name & ": Received unexpected SIP Resp message := ", sip_resp, "\nvs exp := ", exp_msg_str));
236 }
237}
238
Pau Espin Pedrol717379f2024-05-17 18:36:51 +0200239private function f_nonce_from_rand_autn(octetstring rand, octetstring autn) return charstring {
240 var octetstring concat := rand & autn;
241 var charstring nonce := enc_MIME_Base64(concat);
242 log("rand=", rand, " & autn=",autn, " => nonce=", nonce);
243 return nonce;
244}
245
Pau Espin Pedrola674d612024-05-14 19:56:33 +0200246/* HTTP Digest Authentication Using AKA (AKAv1-MD5): RFC 3310 */
247function f_tr_Authorization_AKAv1MD5(WwwAuthenticate www_authenticate,
248 charstring username,
249 charstring uri,
250 integer nc_int := 1)
251return template (present) Authorization {
252 var CommaParam_List digestCln;
253 var template (present) Authorization authorization;
254 var template (present) Credentials cred;
255 var template (omit) GenericParam rx_param;
256
257 digestCln := www_authenticate.challenge[0].digestCln;
258
259 var charstring algorithm := f_sip_param_get_value_present_or_fail(digestCln, "algorithm");
260 var charstring realm := f_sip_param_get_value_present_or_fail(digestCln, "realm");
261 var charstring nonce := f_sip_param_get_value_present_or_fail(digestCln, "nonce");
262
263 var template (present) CommaParam_List digestResponse := superset(
264 tr_Param("username", f_sip_str_quote(username)),
265 tr_Param("realm", f_sip_str_quote(realm)),
266 tr_Param("nonce", f_sip_str_quote(nonce)),
267 tr_Param("uri", f_sip_str_quote(uri)),
268 tr_Param("response", ?),
269 tr_Param("algorithm", algorithm),
270 tr_Param("qop", "auth"),
271 tr_Param("cnonce", ?),
272 tr_Param("nc", ?)
273 );
274 cred := tr_Credentials_DigestResponse(digestResponse);
275 authorization := tr_Authorization(cred);
276 return authorization;
277}
278
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200279private function f_ims_validate_register_contact(Contact rx_contact)
280{
281/* IMS contact shows up like this:
282 * Contact: <sip:8adf9f3d-9342-4060-aa4f-a909f37fd6f6@192.168.101.2:5060>;+g.3gpp.accesstype="cellular2";video;audio;+g.3gpp.smsip;+g.3gpp.nw-init-ussi;+g.3gpp.icsi-ref="urn%3Aurn-7%3A3gpp-service.ims.icsi.mmtel";+sip.instance="<urn:gsma:imei:35589811-338445-0>"
283 */
284 /* TODO: "that the UE must include the IMS Communication Service Identifier (ICSI)
285in the contact: header to indicate IMS Multimedia Telephony." */
286 /* TODO: "The UE must include an IMEI URN in the +sip.instance header field
287parameter of the contact: header." */
288 /* TODO: "If the UE supports SMS over IP, it must include the feature tag
289“+g.3gpp.smsip” in the contact: header." */
290 /* TODO: "If the UE supports conversational audio and video service, then this must
291be indicated by adding a “video” media feature tag to the contact: header." */
292}
293
Pau Espin Pedrol0c5c6472024-05-21 13:13:49 +0200294/* Validate P-Access-Network-Info: RFC7315 6.4 */
295private function f_ims_validate_register_P_Access_Network_info(PDU_SIP_Request req,
296 boolean exp_present := true) runs on IMS_ConnHdlr
297
298{
299 if (not exp_present) {
300 if (ispresent(g_rx_sip_req.msgHeader.p_access_network_info)) {
301 Misc_Helpers.f_shutdown(__BFILE__, __LINE__, fail,
302 log2str(g_name & ": Received unexpected [rfc7315 6.4] P-Access-Info := ",
303 g_rx_sip_req.msgHeader.p_access_network_info));
304 }
305 return;
306 }
307
308 /* exp_present: */
309 var template (present) P_Access_Network_Info expl_tmpl :=
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200310 tr_P_Access_Network_Info({ tr_Access_net_spec_EUTRAN(g_pars.subscr.uli_str) });
Pau Espin Pedrol0c5c6472024-05-21 13:13:49 +0200311
312 if (not ispresent(g_rx_sip_req.msgHeader.p_access_network_info)) {
313 Misc_Helpers.f_shutdown(__BFILE__, __LINE__, fail,
314 log2str(g_name & ": Received no P-Access-Info vs exp := ",
315 expl_tmpl));
316 }
317 if (not match(g_rx_sip_req.msgHeader.p_access_network_info, expl_tmpl)) {
318 Misc_Helpers.f_shutdown(__BFILE__, __LINE__, fail,
319 log2str(g_name & ": Received unexpected P-Access-Info := ",
320 g_rx_sip_req.msgHeader.p_access_network_info,
321 "\nvs exp := ", expl_tmpl));
322 }
323}
324
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200325private function f_ims_parse_security_client(Security_client security_client) runs on IMS_ConnHdlr
326{
327 var boolean found := false;
328 for (var integer i := 0; i < lengthof(security_client.sec_mechanism_list); i := i + 1) {
329 var Security_mechanism sec_mec := security_client.sec_mechanism_list[i];
330 if (sec_mec.mechanism_name != "ipsec-3gpp") {
331 log("Skipping Security Mechansim: ", sec_mec.mechanism_name);
332 continue;
333 }
334 var SemicolonParam_List sec_pars := sec_mec.mechanism_params;
335 var charstring par_val;
336 par_val := f_sip_param_get_value_present_or_fail(sec_pars, "alg");
337 if (par_val != "hmac-sha-1-96") {
338 log("Skipping Security Mechansim Algo: ", par_val);
339 continue;
340 }
341 par_val := f_sip_param_get_value_present_or_fail(sec_pars, "spi-c");
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200342 g_pars.subscr.ipsec_remote_spi_c := str2int(par_val);
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200343 par_val := f_sip_param_get_value_present_or_fail(sec_pars, "spi-s");
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200344 g_pars.subscr.ipsec_remote_spi_s := str2int(par_val);
Pau Espin Pedrola674d612024-05-14 19:56:33 +0200345 par_val := f_sip_param_get_value_present_or_fail(sec_pars, "port-c");
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200346 g_pars.subscr.ipsec_remote_port_c := str2int(par_val);
Pau Espin Pedrola674d612024-05-14 19:56:33 +0200347 par_val := f_sip_param_get_value_present_or_fail(sec_pars, "port-s");
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200348 g_pars.subscr.ipsec_remote_port_s := str2int(par_val);
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200349 found := true;
350 break;
351 }
352
353 if (not found) {
354 Misc_Helpers.f_shutdown(__BFILE__, __LINE__, fail,
355 log2str(g_name & "alg=hmac-sha-1-96 not found: ", security_client));
356 }
357
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200358 log("ipsec: remote_spi_c=", g_pars.subscr.ipsec_remote_spi_c, " remote_spi_s=", g_pars.subscr.ipsec_remote_spi_s,
359 "local_spi_c=", g_pars.subscr.ipsec_local_spi_c, " local_spi_s=", g_pars.subscr.ipsec_local_spi_s);
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200360}
361
Pau Espin Pedrola674d612024-05-14 19:56:33 +0200362private function f_IMS_exec_sync(charstring cmdline, template (present) integer rc := 0)
363 runs on IMS_ConnHdlr return ASP_PResult {
364 var ASP_PResult res;
365
366 map(self:PIPE, system:PIPE);
367 res := f_PIPEasp_exec_sync_PResult(PIPE, cmdline, tr_PResult(?, ?, rc));
368 unmap(self:PIPE, system:PIPE);
369
370 return res;
371}
372
373private function f_ims_setup_ipsec() runs on IMS_ConnHdlr
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200374{
Pau Espin Pedrola674d612024-05-14 19:56:33 +0200375 var ASP_PResult res;
376
377 var charstring cmd := mp_ipsec_setup_script_path & " " &
378 g_pars.local_sip_host & " " &
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200379 int2str(g_pars.local_sip_port) & " " & int2str(g_pars.subscr.ipsec_local_spi_c) & " " &
380 int2str(g_pars.local_sip_port) & " " & int2str(g_pars.subscr.ipsec_local_spi_s) & " " &
381 g_pars.subscr.remote_sip_host & " " &
382 int2str(g_pars.subscr.ipsec_remote_port_c) & " " & int2str(g_pars.subscr.ipsec_remote_spi_c) & " " &
383 int2str(g_pars.subscr.ipsec_remote_port_s) & " " & int2str(g_pars.subscr.ipsec_remote_spi_s) & " " &
384 g_pars.subscr.ipsec_auth_key;
Pau Espin Pedrola674d612024-05-14 19:56:33 +0200385
386 res := f_IMS_exec_sync(cmd);
387
388 /* Debug applied rules: */
389 /*
390 res := f_IMS_exec_sync("ip xfrm state");
391 log("ip-xfrm-state Result-Stdout: " & res.stdout);
392
393 res := f_IMS_exec_sync("ip xfrm policy");
394 log("ip-xfrm-policy Result-Stdout: " & res.stdout);
395 */
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200396}
397
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200398private function f_tr_Via_response(Via via_req) return template (present) Via {
399 template (present) SemicolonParam_List via_resp_params := ?;
400
401 /*via_resp_params := {
402 { id := "rport", paramValue := int2str(g_pars.subscr.remote_sip_port.subscr.remote_sip_port) },
403 { id := "received", paramValue := g_pars.subscr.remote_sip_host }
404 }; */
405 return tr_Via_from(via_req.viaBody[0].sentBy,
406 via_req.viaBody[0].sentProtocol.transport,
407 via_resp_params);
408}
409
410private function f_tr_From(template (value) SipAddr from_req) return template (present) SipAddr {
411 return tr_SipAddr_from_val(from_req);
412}
413
414private altstep as_SIP_expect_req(template (present) PDU_SIP_Request sip_expect, boolean fail_others := true) runs on IMS_ConnHdlr
415{
416 var charstring sip_expect_str := log2str(sip_expect);
417 [] SIP.receive(sip_expect) -> value g_rx_sip_req;
418 [fail_others] as_SIP_fail_req(sip_expect_str);
419 [fail_others] as_SIP_fail_resp(sip_expect_str);
420}
421
422private function f_gen_sdp() runs on IMS_ConnHdlr return charstring {
423 var charstring sdp :=
424 "v=0\r\n" &
425 "o=0502 2390 1824 IN IP4 " & g_pars.subscr.cp.local_rtp_addr & "\r\n" &
426 "s=Talk\r\n" &
427 "c=IN IP4 " & g_pars.subscr.cp.local_rtp_addr & "\r\n" &
428 "t=0 0\r\n" &
429 "a=rtcp-xr:rcvr-rtt=all:10000 stat-summary=loss,dup,jitt,TTL voip-metrics\r\n" &
430 "a=record:off\r\n" &
431 "m=audio " & int2str(g_pars.subscr.cp.local_rtp_port) & " RTP/AVP 8 96 97 98 0 18 99 100 101\r\n" &
432 "a=rtpmap:8 PCMA/8000\r\n" &
433 "a=rtpmap:96 opus/48000/2\r\n" &
434 "a=fmtp:96 useinbandfec=1\r\n" &
435 "a=rtpmap:97 speex/16000\r\n" &
436 "a=fmtp:97 vbr=on\r\n" &
437 "a=rtpmap:98 speex/8000\r\n" &
438 "a=fmtp:98 vbr=on\r\n" &
439 "a=fmtp:18 annexb=yes\r\n" &
440 "a=rtpmap:99 telephone-event/48000\r\n" &
441 "a=rtpmap:100 telephone-event/16000\r\n" &
442 "a=rtpmap:101 telephone-event/8000\r\n" &
443 "a=rtcp:" & int2str(g_pars.subscr.cp.local_rtp_port + 1) & "\r\n" &
444 "a=rtcp-fb:* trr-int 1000\r\n" &
445 "a=rtcp-fb:* ccm tmmbr\r\n";
446 return sdp;
447}
448
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200449/* Peer is calling us, accept it: */
450altstep as_IMS_register(boolean exp_update_to_direct_rtp := true,
451 boolean fail_others := true) runs on IMS_ConnHdlr
452{
453 var template (present) PDU_SIP_Request exp_req :=
454 tr_SIP_REGISTER(g_pars.registrar_sip_req_uri,
455 ?,
Pau Espin Pedrol41b0e072024-05-29 18:25:51 +0200456 tr_From(),
457 tr_To(),
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200458 tr_Via_from(?),
459 require := tr_Require(superset("sec-agree")),
460 security_client := tr_Security_client(superset(tr_Security_mechanism("ipsec-3gpp",
461 superset(tr_Param("alg","hmac-sha-1-96"))))),
462 supported := tr_Supported(superset("path", "sec-agree")));
463 var charstring sip_expect_str := log2str(exp_req);
464
465 [] SIP.receive(exp_req) -> value g_rx_sip_req {
466 var template (value) PDU_SIP_Response tx_resp;
467 var Via via;
468 var CallidString sip_call_id;
469 var Contact contact;
Pau Espin Pedrol41b0e072024-05-29 18:25:51 +0200470 var template (value) From from_addr;
471 var template (value) To to_addr;
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200472 var template (value) CommaParam_List digestCln ;
473 var template (value) WwwAuthenticate wwwAuthenticate;
Pau Espin Pedrol4e6672c2024-05-22 17:03:53 +0200474 var template (value) P_Associated_Uri p_associated_uri := ts_P_Associated_Uri({});
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200475 var template (value) Security_server security_server;
476 var template (value) Server server_name := ts_Server({c_sip_server_name});
Pau Espin Pedrola674d612024-05-14 19:56:33 +0200477 var template (value) Require require := ts_Require({"sec-agree"});
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200478 var template (value) Supported supported := ts_Supported({"sec-agree"});
Pau Espin Pedrola674d612024-05-14 19:56:33 +0200479 var template (present) Authorization authorization;
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200480 var integer sip_seq_nr;
481 var charstring tx_sdp;
482
483 sip_call_id := g_rx_sip_req.msgHeader.callId.callid;
484 via := g_rx_sip_req.msgHeader.via;
485 via.viaBody[0].viaParams := f_sip_param_set(via.viaBody[0].viaParams, "rport", "1234"); /* TODO: set remote src port of the REGISTER */
Pau Espin Pedrol41b0e072024-05-29 18:25:51 +0200486 from_addr := g_rx_sip_req.msgHeader.fromField;
487 to_addr := g_rx_sip_req.msgHeader.toField;
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200488 sip_seq_nr := g_rx_sip_req.msgHeader.cSeq.seqNumber;
489
490 contact := g_rx_sip_req.msgHeader.contact;
491 f_ims_validate_register_contact(contact);
492
Pau Espin Pedrol0c5c6472024-05-21 13:13:49 +0200493 /* Validate P-Access-Network-Info: rfc7315 6.4:
494 * "3GPP will use the P-Access-Network-Info header field to
495 * carry relatively sensitive information like the cell ID. Therefore,
496 * the information MUST NOT be sent outside of the 3GPP domain.""
497 * [...] "the sensitive information carried in the
498 * P-Access-Network-Info header field MUST NOT be sent in any initial
499 * unauthenticated and unprotected requests (e.g., REGISTER)."
500 */
501 f_ims_validate_register_P_Access_Network_info(g_rx_sip_req, exp_present := false);
502
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200503 /* TODO: Validate "Expires" is 600000 */
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200504
505 /* Tx 100 Tyring */
506 tx_resp := ts_SIP_Response_Trying(sip_call_id,
507 from_addr,
508 to_addr,
509 via,
510 sip_seq_nr,
511 "REGISTER",
512 allow := omit,
513 server := server_name,
514 userAgent := omit);
515 SIP.send(tx_resp);
516
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200517 var HostPort hp := valueof(contact.contactBody.contactAddresses[0].addressField.nameAddr.addrSpec.hostPort);
518 g_pars.subscr.remote_sip_host := hp.host;
519 if (ispresent(hp.portField)) {
520 g_pars.subscr.remote_sip_port := hp.portField;
521 } else {
522 g_pars.subscr.remote_sip_port := 5060;
523 }
Pau Espin Pedrola674d612024-05-14 19:56:33 +0200524 f_ims_parse_security_client(g_rx_sip_req.msgHeader.security_client);
525 f_ims_setup_ipsec();
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200526
Pau Espin Pedrol41b0e072024-05-29 18:25:51 +0200527 to_addr.toParams := f_sip_param_set(to_addr.toParams, "tag", f_sip_rand_tag());
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200528
529 digestCln := {
530 ts_Param("realm", f_sip_str_quote(g_pars.realm)),
531 ts_Param("qop", f_sip_str_quote("auth")),
532 ts_Param("algorithm", "AKAv1-MD5"),
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200533 ts_Param("nonce", f_sip_str_quote(f_nonce_from_rand_autn(g_pars.subscr.rand, g_pars.subscr.autn)))
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200534 /* "opaque not needed in IMS "*/
535 };
536 wwwAuthenticate := ts_WwwAuthenticate( { ts_Challenge_digestCln(digestCln) } )
537
538 /* Security-Server: ipsec-3gpp;q=0.1;prot=esp;mod=trans;spi-c=4096;spi-s=4097;port-c=5104;port-s=6104;alg=hmac-sha-1-96;ealg=null */
539 var template (value) SemicolonParam_List sec_params := {
540 ts_Param("q", "0.1"),
541 ts_Param("prot", "esp"),
542 ts_Param("mod", "trans"),
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200543 ts_Param("spi-c", int2str(g_pars.subscr.ipsec_local_spi_c)),
544 ts_Param("spi-s", int2str(g_pars.subscr.ipsec_local_spi_s)),
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200545 ts_Param("port-c", int2str(g_pars.local_sip_port)),
546 ts_Param("port-s", int2str(g_pars.local_sip_port)),
547 ts_Param("alg", "hmac-sha-1-96"),
548 ts_Param("ealg", "null")
549 };
550 security_server := ts_Security_server({
551 ts_Security_mechanism("ipsec-3gpp", sec_params)
552 });
Pau Espin Pedrola674d612024-05-14 19:56:33 +0200553
554 /* Tx 401 Unauthorized */
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200555 tx_resp := ts_SIP_Response_Unauthorized(sip_call_id,
556 from_addr,
557 to_addr,
558 via,
559 wwwAuthenticate,
560 sip_seq_nr,
561 "REGISTER",
Pau Espin Pedrol4e6672c2024-05-22 17:03:53 +0200562 p_associated_uri := p_associated_uri,
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200563 security_server := security_server,
564 server := server_name,
565 supported := supported,
566 userAgent := omit);
567 SIP.send(tx_resp);
568
Pau Espin Pedrola674d612024-05-14 19:56:33 +0200569 /* Now we should receive a new REGISTER over ipsec: */
570
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200571 /* TODO: Generate expected Authoritzation based on AKAv1-MD5: */
572 /*authorization := f_sip_digest_gen_Authorization(valueof(wwwAuthenticate),
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200573 g_pars.user, g_pars.subscr.password,
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200574 "REGISTER",
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200575 f_sip_SipUrl_to_str(g_pars.subscr.registrar_sip_record.addr.nameAddr.addrSpec))
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200576 */
Pau Espin Pedrola674d612024-05-14 19:56:33 +0200577 authorization := f_tr_Authorization_AKAv1MD5(valueof(wwwAuthenticate),
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200578 g_pars.subscr.imsi & "@" & g_pars.realm,
Pau Espin Pedrolb0dbf7a2024-05-22 18:12:15 +0200579 f_sip_SipUrl_to_str(g_pars.registrar_sip_req_uri));
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200580 /* TODO: match Authorization from above: */
581 exp_req :=
582 tr_SIP_REGISTER(g_pars.registrar_sip_req_uri,
583 ?,
Pau Espin Pedrol41b0e072024-05-29 18:25:51 +0200584 tr_From(),
585 tr_To(),
Pau Espin Pedrola674d612024-05-14 19:56:33 +0200586 tr_Via_from(?),
587 authorization := authorization);
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200588 SIP.receive(exp_req) -> value g_rx_sip_req;
589
590 sip_call_id := g_rx_sip_req.msgHeader.callId.callid;
591 via := g_rx_sip_req.msgHeader.via;
Pau Espin Pedrol41b0e072024-05-29 18:25:51 +0200592 from_addr := g_rx_sip_req.msgHeader.fromField;
593 to_addr := g_rx_sip_req.msgHeader.toField;
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200594 sip_seq_nr := g_rx_sip_req.msgHeader.cSeq.seqNumber;
595
Pau Espin Pedrola674d612024-05-14 19:56:33 +0200596 /* Tx 100 Trying */
597 tx_resp := ts_SIP_Response_Trying(sip_call_id,
598 from_addr,
599 to_addr,
600 via,
601 sip_seq_nr,
602 "REGISTER",
603 allow := omit,
604 server := server_name,
605 userAgent := omit);
606 SIP.send(tx_resp);
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200607
Pau Espin Pedrol0c5c6472024-05-21 13:13:49 +0200608 /* Validate P-Access-Network-Info: */
609 f_ims_validate_register_P_Access_Network_info(g_rx_sip_req, exp_present := true);
610
Pau Espin Pedrol4e6672c2024-05-22 17:03:53 +0200611 p_associated_uri := ts_P_Associated_Uri({
612 ts_P_Assoc_uri_spec(ts_NameAddr(ts_SipUrl(ts_HostPort(g_pars.realm),
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200613 ts_UserInfo(g_pars.subscr.msisdn),
Pau Espin Pedrol4e6672c2024-05-22 17:03:53 +0200614 scheme := "sip"))),
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200615 ts_P_Assoc_uri_spec(ts_NameAddr(ts_SipUrl(ts_HostPort(g_pars.subscr.msisdn),
Pau Espin Pedrol4e6672c2024-05-22 17:03:53 +0200616 omit,
617 scheme := "tel"))),
618 ts_P_Assoc_uri_spec(g_rx_sip_req.msgHeader.toField.addressField.nameAddr)
619 });
620
Pau Espin Pedrola674d612024-05-14 19:56:33 +0200621 /* Tx 200 OK */
Pau Espin Pedrol41b0e072024-05-29 18:25:51 +0200622 to_addr.toParams := f_sip_param_set(to_addr.toParams, "tag", f_sip_rand_tag());
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200623 tx_resp := ts_SIP_Response(sip_call_id,
624 from_addr,
625 to_addr,
626 "REGISTER", 200,
627 sip_seq_nr,
628 "OK",
Pau Espin Pedrola674d612024-05-14 19:56:33 +0200629 via,
Pau Espin Pedrol4e6672c2024-05-22 17:03:53 +0200630 p_associated_uri := p_associated_uri,
Pau Espin Pedrola674d612024-05-14 19:56:33 +0200631 require := require,
632 server := server_name,
633 supported := supported,
634 userAgent := omit);
Pau Espin Pedrola2812ec2024-05-10 20:30:44 +0200635 SIP.send(tx_resp);
636 }
637 [fail_others] as_SIP_fail_resp(sip_expect_str);
638 [fail_others] as_SIP_fail_req(sip_expect_str);
639
640}
641
Pau Espin Pedrol901cede2024-05-30 13:03:42 +0200642private function f_ConnHdlr_parse_initial_SIP_INVITE(PDU_SIP_Request rx_sip_req) runs on IMS_ConnHdlr
643{
644 f_SDP_decodeMessage(rx_sip_req.messageBody, g_pars.subscr.cp.peer_sdp);
645 log("Rx Initial MO INVITE decoded SDP: ", g_pars.subscr.cp.peer_sdp);
646
647 /* Obtain params: */
648 g_pars.subscr.cp.sip_call_id := rx_sip_req.msgHeader.callId.callid;
649 g_pars.subscr.cp.from_addr := rx_sip_req.msgHeader.fromField;
650 g_pars.subscr.cp.to_addr := rx_sip_req.msgHeader.toField;
651 g_pars.subscr.cp.to_addr.toParams := f_sip_param_set(g_pars.subscr.cp.to_addr.toParams, "tag", f_sip_rand_tag());
652 g_pars.subscr.cp.sip_seq_nr := rx_sip_req.msgHeader.cSeq.seqNumber;
653}
654
655/* Peer is calling us, accept it: */
656altstep as_IMS_mo_call_accept(boolean exp_update_to_direct_rtp := false,
657 boolean fail_others := true) runs on IMS_ConnHdlr
658{
659 var template (present) PDU_SIP_Request exp_req :=
660 tr_SIP_INVITE(f_tr_SipUrl_opt_defport(ts_SipUrl_from_Addr_Union(g_pars.subscr.cp.called.addr)),
661 ?,
662 ( /* FIXME: We should be sending with MSISDN here, aka 2nd option below, but we receive IMSI (first opt): */
663 tr_From(tr_Addr_Union_from_val(g_pars.subscr.local_sip_record.addr), *),
664 tr_From(tr_Addr_Union_from_val(g_pars.subscr.cp.calling.addr), *)
665 ),
666 tr_To(tr_Addr_Union_from_val(g_pars.subscr.cp.called.addr), *),
667 tr_Via_from(f_tr_HostPort(g_pars.subscr.remote_sip_host, g_pars.subscr.remote_sip_port)),
668 ?, ?);
669 var charstring sip_expect_str := log2str(exp_req);
670
671 [] SIP.receive(exp_req) -> value g_rx_sip_req {
672 var template (value) PDU_SIP_Response tx_resp;
673 var Via via;
674 var charstring tx_sdp;
675
676 /* Obtain params: */
677 f_ConnHdlr_parse_initial_SIP_INVITE(g_rx_sip_req);
678 via := g_rx_sip_req.msgHeader.via;
679
680
681 /* Tx 180 Ringing */
682 tx_resp := ts_SIP_Response_Ringing(g_pars.subscr.cp.sip_call_id,
683 g_pars.subscr.cp.from_addr,
684 g_pars.subscr.cp.to_addr,
685 via,
686 g_pars.subscr.cp.sip_seq_nr);
687 SIP.send(tx_resp);
688
689 /* Tx 200 OK */
690 tx_sdp := f_gen_sdp();
691 tx_resp := ts_SIP_Response(g_pars.subscr.cp.sip_call_id,
692 g_pars.subscr.cp.from_addr,
693 g_pars.subscr.cp.to_addr,
694 "INVITE", 200,
695 g_pars.subscr.cp.sip_seq_nr,
696 "OK",
697 via,
698 body := tx_sdp);
699 SIP.send(tx_resp);
700
701 /* Wait for ACK */
702 exp_req := tr_SIP_ACK(f_tr_SipUrl_opt_defport(ts_SipUrl_from_Addr_Union(g_pars.subscr.cp.called.addr)),
703 g_pars.subscr.cp.sip_call_id,
704 g_pars.subscr.cp.from_addr,
705 g_pars.subscr.cp.to_addr,
706 f_tr_Via_response(via),
707 g_pars.subscr.cp.sip_seq_nr, *);
708 as_SIP_expect_req(exp_req);
709 }
710 [fail_others] as_SIP_fail_resp(sip_expect_str);
711 [fail_others] as_SIP_fail_req(sip_expect_str);
712
713}
714
715/* Call is terminated by peer: */
716altstep as_IMS_exp_call_hangup(template (present) integer exp_seq_nr := ?, boolean fail_others := true) runs on IMS_ConnHdlr
717{
718 var template (present) PDU_SIP_Request exp_req :=
719 tr_SIP_BYE(f_tr_SipUrl_opt_defport(ts_SipUrl_from_Addr_Union(g_pars.subscr.cp.called.addr)),
720 g_pars.subscr.cp.sip_call_id,
721 g_pars.subscr.cp.from_addr,
722 g_pars.subscr.cp.to_addr,
723 tr_Via_from(f_tr_HostPort(g_pars.subscr.remote_sip_host, g_pars.subscr.remote_sip_port)),
724 exp_seq_nr);
725 var charstring sip_expect_str := log2str(exp_req);
726
727 [] SIP.receive(exp_req) -> value g_rx_sip_req {
728 var template (value) PDU_SIP_Response tx_resp;
729 var charstring tx_sdp;
730 var Via via;
731
732 /* Update parameters: */
733 g_pars.subscr.cp.sip_seq_nr := g_rx_sip_req.msgHeader.cSeq.seqNumber;
734 /* "branch" has changed: */
735 via := g_rx_sip_req.msgHeader.via;
736
737 /* Tx 200 OK */
738 tx_sdp := f_gen_sdp();
739 tx_resp := ts_SIP_Response(g_pars.subscr.cp.sip_call_id,
740 g_pars.subscr.cp.from_addr,
741 g_pars.subscr.cp.to_addr,
742 "BYE", 200,
743 g_pars.subscr.cp.sip_seq_nr,
744 "OK",
745 via,
746 body := tx_sdp);
747 SIP.send(tx_resp);
748 }
749 [fail_others] as_SIP_fail_resp(sip_expect_str);
750 [fail_others] as_SIP_fail_req(sip_expect_str);
751}
752
Pau Espin Pedrolac8a0542024-04-19 17:30:57 +0200753}