Coverage Report

Created: 2026-06-30 07:22

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/wireshark/epan/dissectors/packet-sgsap.c
Line
Count
Source
1
/* packet-sgsap.c
2
 * Routines for SGs Application Part (SGsAP) protocol dissection
3
 *
4
 * Copyright 2010 - 2017, Anders Broman <anders.broman@ericsson.com>
5
 *
6
 * Wireshark - Network traffic analyzer
7
 * By Gerald Combs <gerald@wireshark.org>
8
 * Copyright 1998 Gerald Combs
9
 *
10
 * SPDX-License-Identifier: GPL-2.0-or-later
11
 *
12
 * References: 3GPP TS 29.118 V10.2.0 (2010-12)
13
 */
14
15
#include "config.h"
16
17
#include <epan/packet.h>
18
#include <epan/tfs.h>
19
#include <epan/expert.h>
20
#include <epan/exceptions.h>
21
#include <epan/show_exception.h>
22
23
#include <wsutil/array.h>
24
#include "packet-gsm_a_common.h"
25
#include "packet-e212.h"
26
27
void proto_register_sgsap(void);
28
void proto_reg_handoff_sgsap(void);
29
30
/* Global variables */
31
static dissector_handle_t gsm_a_dtap_handle;
32
33
/* The registered SCTP port number for SGsAP is 29118.
34
 * The payload protocol identifier to be used for SGsAP is 0.
35
 */
36
14
#define SGSAP_SCTP_PORT_RANGE "29118"
37
38
/* Initialize the protocol and registered fields */
39
static int proto_sgsap;
40
41
static int hf_sgsap_msg_type;
42
int hf_sgsap_elem_id;
43
static int hf_sgsap_eps_location_update_type;
44
static int hf_sgsap_service_indicator_value;
45
static int hf_sgsap_sgs_cause;
46
static int hf_sgsap_ue_emm_mode;
47
static int hf_sgsap_eci;
48
static int hf_sgsap_cn_id;
49
static int hf_sgsap_imsi_det_eps;
50
static int hf_sgsap_imsi_det_non_eps;
51
static int hf_sgsap_lcs_indic;
52
static int hf_sgsap_mme_name;
53
static int hf_sgsap_vlr_name;
54
static int hf_sgsap_imeisv;
55
static int hf_sgsap_unknown_msg;
56
static int hf_sgsap_message_elements;
57
static int hf_sgsap_csri;
58
static int hf_sgsap_sel_cs_dmn_op;
59
60
static int ett_sgsap;
61
static int ett_sgsap_sel_cs_dmn_op;
62
63
static expert_field ei_sgsap_extraneous_data;
64
static expert_field ei_sgsap_missing_mandatory_element;
65
66
static dissector_handle_t sgsap_handle;
67
68
static void get_sgsap_msg_params(uint8_t oct, const char **msg_str, int *ett_tree, int *hf_idx, msg_fcn *msg_fcn_p);
69
70
/*
71
 * 9.4  Information elements
72
 */
73
/*
74
 * 9.4.1    CLI
75
 */
76
77
/*
78
 * Octets 3 to 14 contain the value part of the Calling party BCD number information element
79
 * defined in subclause 10.5.4.9 of 3GPP TS 24.008 [8] (octets 3 to 14, i.e. not including
80
 * 3GPP TS 24.008 IEI and 3GPP TS 24.008 length indicator)
81
 * ( packet-gsm_a_dtap.c )
82
 */
83
/*
84
 * 9.4.2    EPS location update type
85
 */
86
87
/* EPS location update type value (octet 3) */
88
static const value_string sgsap_eps_location_update_type_values[] = {
89
    { 0x00, "Shall not be sent in this version of the protocol" },
90
    { 0x01, "IMSI attach" },
91
    { 0x02, "Normal location update" },
92
    { 0, NULL }
93
};
94
95
static uint16_t
96
de_sgsap_eps_loc_upd_type(tvbuff_t *tvb, proto_tree *tree, packet_info *pinfo _U_, uint32_t offset, unsigned len _U_, char *add_string _U_, int string_len _U_)
97
0
{
98
0
    uint32_t curr_offset;
99
0
    uint8_t oct;
100
101
0
    curr_offset = offset;
102
103
    /* Octet 3  EPS location update type value */
104
0
    proto_tree_add_item(tree, hf_sgsap_eps_location_update_type, tvb, offset, 1, ENC_BIG_ENDIAN);
105
0
    if (add_string) {
106
0
        oct = tvb_get_uint8(tvb, curr_offset);
107
0
        snprintf(add_string, string_len, " - %s", val_to_str_const(oct, sgsap_eps_location_update_type_values, "Reserved"));
108
0
    }
109
110
0
    curr_offset++;
111
112
0
    return curr_offset - offset;
113
0
}
114
/*
115
 * 9.4.3    Erroneous message
116
 *
117
 * See subclause 18.4.5 in 3GPP TS 29.018 [16].
118
 */
119
static uint16_t
120
de_sgsap_err_msg(tvbuff_t *tvb, proto_tree *tree, packet_info *pinfo, uint32_t offset, unsigned len, char *add_string , int string_len)
121
0
{
122
0
    const char      *msg_str;
123
0
    int              ett_tree;
124
0
    int              hf_idx;
125
0
    void(*msg_fcn_p)(tvbuff_t *tvb, proto_tree *tree, packet_info *pinfo, uint32_t offset, unsigned len);
126
0
    uint8_t         oct;
127
128
    /* 18.4.5 Erroneous message
129
     * The Erroneous message IE is a TLV IE that encapsulates the message in error.
130
     * Octet 3 - Octet n
131
     * Erroneous message including the message type.
132
     */
133
     /* Message type IE*/
134
0
    oct = tvb_get_uint8(tvb, offset);
135
0
    msg_fcn_p = NULL;
136
0
    ett_tree = -1;
137
0
    hf_idx = -1;
138
0
    msg_str = NULL;
139
140
0
    proto_tree_add_item(tree, hf_sgsap_msg_type, tvb, offset, 1, ENC_BIG_ENDIAN);
141
142
0
    get_sgsap_msg_params(oct, &msg_str, &ett_tree, &hf_idx, &msg_fcn_p);
143
0
    if (msg_str) {
144
0
        if (add_string)
145
0
            snprintf(add_string, string_len, " - %s", msg_str);
146
147
0
    }
148
0
    if (msg_fcn_p){
149
0
        volatile uint32_t curr_offset = offset + 1;
150
0
        TRY {
151
            /*let's try to decode erroneous message and catch exceptions as it could be malformed */
152
0
            (*msg_fcn_p)(tvb, tree, pinfo, curr_offset, len - 1);
153
0
        } CATCH_BOUNDS_ERRORS {
154
0
            show_exception(tvb, pinfo, tree, EXCEPT_CODE, GET_MESSAGE);
155
0
        } ENDTRY
156
0
    }
157
158
159
0
    return len;
160
0
}
161
/*
162
 * 9.4.3a   E-UTRAN Cell Global Identity
163
 *
164
 * The coding of the E-UTRAN Cell Global Identity value is according to ECGI field information element
165
 * as specified in subclause 8.21.5 of 3GPP TS 29.274 [17A] (GTPv2-C)
166
 */
167
uint16_t
168
de_sgsap_ecgi(tvbuff_t *tvb, proto_tree *tree, packet_info *pinfo, uint32_t offset, unsigned len _U_, char *add_string _U_, int string_len _U_)
169
0
{
170
0
    uint32_t   curr_offset;
171
172
0
    curr_offset = offset;
173
174
0
    dissect_e212_mcc_mnc(tvb, pinfo, tree, offset, E212_ECGI, true);
175
0
    curr_offset += 3;
176
177
0
    proto_tree_add_item(tree, hf_sgsap_eci, tvb, curr_offset, 4, ENC_BIG_ENDIAN);
178
0
    curr_offset += 4;
179
180
0
    return curr_offset-offset;
181
0
}
182
/*
183
 * 9.4.4    Global CN-Id
184
 *
185
 * See subclause 18.4.27 in 3GPP TS 29.018 [16].
186
 * 18.4.27 Global CN-Id
187
 * The Global CN-Id consists of a PLMN-Id and a CN-Id, see 3GPP TS 23.003. The PLMN-Id consists of MCC and MNC
188
 * coded according to Location Area Identification in 3GPP TS 24.008. The CN-Id is an integer defined by O&M. The
189
 * least significant bit of the CN-Id field is bit 1 of octet 7 and the most significant bit is bit 8 of octet 6. If the CN-Id does
190
 * not fill the field reserved for it, the rest of the bits are set to '0'.
191
 */
192
static uint16_t
193
de_sgsap_g_cn_id(tvbuff_t *tvb, proto_tree *tree, packet_info *pinfo, uint32_t offset, unsigned len _U_, char *add_string _U_, int string_len _U_)
194
0
{
195
0
    uint32_t   curr_offset;
196
197
0
    curr_offset = offset;
198
199
0
    dissect_e212_mcc_mnc(tvb, pinfo, tree, offset, E212_NONE, true);
200
0
    curr_offset += 3;
201
202
0
    proto_tree_add_item(tree, hf_sgsap_cn_id, tvb, curr_offset, 2, ENC_BIG_ENDIAN);
203
0
    curr_offset += 2;
204
205
0
    return curr_offset-offset;
206
0
}
207
/*
208
 * 9.4.5    IMEISV
209
 * See subclause 18.4.9 in 3GPP TS 29.018 [16].
210
 * The IMEISV is coded as a sequence of BCD digits, compressed two into each octet.
211
 * The IMEISV consists of 16 digits
212
 * (see 3GPP TS 23.003).
213
 */
214
static uint16_t
215
de_sgsap_imeisv(tvbuff_t *tvb, proto_tree *tree, packet_info *pinfo _U_, uint32_t offset, unsigned len _U_, char *add_string _U_, int string_len _U_)
216
0
{
217
0
    char       *imeisv_str;
218
0
    uint32_t    curr_offset;
219
220
0
    curr_offset = offset;
221
222
0
    proto_tree_add_item_ret_display_string(tree, hf_sgsap_imeisv, tvb, curr_offset, len, ENC_BCD_DIGITS_0_9|ENC_LITTLE_ENDIAN, pinfo->pool, &imeisv_str);
223
0
    if (add_string) {
224
        /* (len<<2)+4 = the maximum number of bytes to produce (including the terminating nul character). */
225
0
        snprintf(add_string, (len<<2)+4, " - %s", imeisv_str);
226
0
    }
227
228
0
    return len;
229
0
}
230
231
/*
232
 * 9.4.6    IMSI
233
 * See subclause 18.4.10 in 3GPP TS 29.018 [16].
234
 */
235
/* The IMSI is coded as a sequence of BCD digits, compressed two into each octet.
236
 * This is a variable length element, and includes a length indicator.
237
 * The IMSI is defined in 3GPP TS 23.003. It shall not exceed 15 digits (see 3GPP TS 23.003).
238
 */
239
/*
240
 * 9.4.7    IMSI detach from EPS service type
241
 */
242
243
/* IMSI detach from EPS service type value (octet 3) */
244
static const value_string sgsap_imsi_det_from_eps_serv_type_values[] = {
245
    { 0x00, "Interpreted as reserved in this version of the protocol" },
246
    { 0x01, "Network initiated IMSI detach from EPS services" },
247
    { 0x02, "UE initiated IMSI detach from EPS services" },
248
    { 0x03, "EPS services not allowed" },
249
    { 0, NULL }
250
};
251
252
static uint16_t
253
de_sgsap_imsi_det_eps(tvbuff_t *tvb, proto_tree *tree, packet_info *pinfo _U_, uint32_t offset, unsigned len _U_, char *add_string _U_, int string_len _U_)
254
0
{
255
0
    uint32_t curr_offset;
256
257
0
    curr_offset = offset;
258
259
0
    proto_tree_add_item(tree, hf_sgsap_imsi_det_eps, tvb, curr_offset, 1, ENC_BIG_ENDIAN);
260
0
    curr_offset += 1;
261
262
0
    return curr_offset-offset;
263
0
}
264
/*
265
 * 9.4.8    IMSI detach from non-EPS service type
266
 */
267
/* IMSI detach from non-EPS service type value (octet 3)*/
268
static const value_string sgsap_imsi_det_from_non_eps_serv_type_values[] = {
269
    { 0x00, "Interpreted as reserved in this version of the protocol" },
270
    { 0x01, "Explicit UE initiated IMSI detach from non-EPS services" },
271
    { 0x02, "Combined UE initiated IMSI detach from EPS and non-EPS services" },
272
    { 0x03, "Implicit network initiated IMSI detach from non-EPS services" },
273
    { 0, NULL }
274
};
275
276
static uint16_t
277
de_sgsap_imsi_det_non_eps(tvbuff_t *tvb, proto_tree *tree, packet_info *pinfo _U_, uint32_t offset, unsigned len _U_, char *add_string _U_, int string_len _U_)
278
0
{
279
0
    uint32_t curr_offset;
280
281
0
    curr_offset = offset;
282
283
0
    proto_tree_add_item(tree, hf_sgsap_imsi_det_non_eps, tvb, curr_offset, 1, ENC_BIG_ENDIAN);
284
0
    curr_offset += 1;
285
286
0
    return curr_offset-offset;
287
0
}
288
/*
289
 * 9.4.9    LCS client identity
290
 * The coding of the LCS client identity value is according to LCS-ClientID
291
 * as specified in subclause 17.7.13 of 3GPP TS 29.002 [15]
292
 * (packet-nas_eps.c)
293
 */
294
/*
295
 * 9.4.10   LCS indicator
296
 */
297
static const value_string sgsap_lcs_indic_values[] = {
298
    { 0x00, "Normal, unspecified in this version of the protocol" },
299
    { 0x01, "MT-LR" },
300
    { 0, NULL }
301
};
302
303
static uint16_t
304
de_sgsap_lcs_indic(tvbuff_t *tvb, proto_tree *tree, packet_info *pinfo _U_, uint32_t offset, unsigned len _U_, char *add_string _U_, int string_len _U_)
305
0
{
306
0
    uint32_t curr_offset;
307
308
0
    curr_offset = offset;
309
310
0
    proto_tree_add_item(tree, hf_sgsap_lcs_indic, tvb, curr_offset, 1, ENC_BIG_ENDIAN);
311
0
    curr_offset += 1;
312
313
0
    return curr_offset-offset;
314
0
}
315
/*
316
 * 9.4.11   Location area identifier
317
 *
318
 * Octets 3 to 7 contain the value part of the Location area identification information element
319
 * defined in 3GPP TS 24.008 [8] (starting with octet 2, i.e. not including 3GPP TS 24.008 IEI)
320
 *(packet-gsm_a_common.c)
321
 */
322
/*
323
 * 9.4.12   MM information
324
 * For the coding see subclause 18.4.16 in 3GPP TS 29.018 [16].
325
 * User information: This field is composed of one or more of the
326
 * information elements of the MM information message as defined in
327
 * 3GPP TS 24.008, excluding the Protocol discriminator, Skip
328
 * indicator and Message type. This field includes the IEI and length
329
 * indicator of the other information elements.
330
 */
331
static uint16_t
332
de_sgsap_mm_info(tvbuff_t *tvb, proto_tree *tree, packet_info *pinfo _U_, uint32_t offset, unsigned len, char *add_string _U_, int string_len _U_)
333
0
{
334
0
    uint32_t curr_offset;
335
336
0
    curr_offset = offset;
337
338
0
    dtap_mm_mm_info(tvb, tree, pinfo, curr_offset, len);
339
340
0
    return len;
341
0
}
342
343
/*
344
 * 9.4.13   MME name
345
 */
346
static uint16_t
347
de_sgsap_mme_name(tvbuff_t *tvb, proto_tree *tree, packet_info *pinfo _U_, uint32_t offset, unsigned len _U_, char *add_string _U_, int string_len _U_)
348
0
{
349
0
    unsigned   name_len;
350
0
    char *fqdn = NULL;
351
352
    /* The MME name information element specifies the MME name and is coded as shown in figure 9.4.13.1. Octets 3
353
     * through n contain the name in the form of a fully qualified domain name (FQDN) as specified in 3GPP TS 23.003 [3].
354
     * The value part of the MME name information element (not including IEI and length indicator) shall have a length of 55
355
     * octets.
356
     */
357
0
    if (len > 0) {
358
0
        name_len = tvb_get_uint8(tvb, offset);
359
360
0
        if (name_len < 0x20) {
361
0
            fqdn = (char*)tvb_get_string_enc(pinfo->pool, tvb, offset, len, ENC_APN_STR);
362
0
        } else{
363
0
            fqdn = (char*)tvb_get_string_enc(pinfo->pool, tvb, offset, len, ENC_ASCII);
364
0
        }
365
0
        proto_tree_add_string(tree, hf_sgsap_mme_name, tvb, offset, len, fqdn);
366
0
        if (add_string)
367
0
            snprintf(add_string, string_len, " - %s", fqdn);
368
369
0
    }
370
371
0
    return len;
372
0
}
373
/*
374
 * 9.4.14   Mobile identity
375
 * See subclause 18.4.17 in 3GPP TS 29.018 [16].
376
 * (packet-gsm_a_common.c)
377
 */
378
/*
379
 * 9.4.14a  Mobile Station Classmark 2
380
 * With the exception of the IEI, the contents are specified in subclause 10.5.1.6 in 3GPP TS 24.008 [8].
381
 * (packet-gsm_a_common.c)
382
 */
383
/*
384
 * 9.4.15   NAS message container
385
 * Octets 3 to 253 contain the SMS message (i.e. CP DATA, CP ACK or CP ERROR)
386
 * as defined in subclause 7.2 of 3GPP TS 24.011 [10]
387
 */
388
static uint16_t
389
de_sgsap_nas_msg_container(tvbuff_t *tvb, proto_tree *tree, packet_info *pinfo, uint32_t offset, unsigned len, char *add_string _U_, int string_len _U_)
390
0
{
391
0
    tvbuff_t *new_tvb;
392
0
    uint32_t curr_offset;
393
394
0
    curr_offset = offset;
395
396
    /* Octets 3 to 253 contain the SMS message (i.e. CP DATA, CP ACK or CP ERROR)
397
     * as defined in subclause 7.2 of 3GPP TS 24.011 [10]
398
     */
399
0
    new_tvb = tvb_new_subset_length(tvb, curr_offset, len);
400
0
    if (gsm_a_dtap_handle) {
401
0
        call_dissector(gsm_a_dtap_handle, new_tvb, pinfo, tree);
402
0
    }
403
404
0
    return len;
405
0
}
406
/*
407
 * 9.4.16   Reject cause
408
 * See subclause 18.4.21 in 3GPP TS 29.018 [16].
409
 * The rest of the information element is coded as the value part of
410
 * the reject cause IE defined in 3GPP TS 24.008, not including
411
 * 3GPP TS 24.008 IEI.
412
 * (packet-gsm_a_dtap.c)
413
 */
414
/*
415
 * 9.4.17   Service indicator
416
 */
417
418
/* Octet 3  Service indicator value */
419
static const value_string sgsap_service_indicator_values[] = {
420
    { 0x00, "Shall not be sent in this version of the protocol" },
421
    { 0x01, "CS call indicator" },
422
    { 0x02, "SMS indicator" },
423
    { 0, NULL }
424
};
425
426
static uint16_t
427
de_sgsap_serv_indic(tvbuff_t *tvb, proto_tree *tree, packet_info *pinfo _U_, uint32_t offset, unsigned len _U_, char *add_string _U_, int string_len _U_)
428
0
{
429
0
    uint32_t curr_offset;
430
0
    uint8_t oct;
431
432
0
    curr_offset = offset;
433
434
    /* Octet 3  Service indicator value */
435
0
    proto_tree_add_item(tree, hf_sgsap_service_indicator_value, tvb, offset, 1, ENC_BIG_ENDIAN);
436
0
    if (add_string) {
437
0
        oct = tvb_get_uint8(tvb, curr_offset);
438
0
        snprintf(add_string, string_len, " - %s", val_to_str_const(oct, sgsap_service_indicator_values, "Reserved"));
439
0
    }
440
0
    curr_offset++;
441
442
0
    return curr_offset-offset;
443
0
}
444
/*
445
 * 9.4.18   SGs cause
446
 */
447
448
/* SGs cause value (octet 3) */
449
static const value_string sgsap_sgs_cause_values[] = {
450
    { 0x00, "Normal, unspecified in this version of the protocol" },
451
    { 0x01, "IMSI detached for EPS services" },
452
    { 0x02, "IMSI detached for EPS and non-EPS services" },
453
    { 0x03, "IMSI unknown" },
454
    { 0x04, "IMSI detached for non-EPS services" },
455
    { 0x05, "IMSI implicitly detached for non-EPS services" },
456
    { 0x06, "UE unreachable" },
457
    { 0x07, "Message not compatible with the protocol state" },
458
    { 0x08, "Missing mandatory information element" },
459
    { 0x09, "Invalid mandatory information" },
460
    { 0x0a, "Conditional information element error" },
461
    { 0x0b, "Semantically incorrect message" },
462
    { 0x0c, "Message unknown" },
463
    { 0x0d, "Mobile terminating CS fallback call rejected by the user" },
464
    { 0x0e, "UE temporarily unreachable" },
465
    { 0, NULL }
466
};
467
468
static value_string_ext sgsap_sgs_cause_values_ext = VALUE_STRING_EXT_INIT(sgsap_sgs_cause_values);
469
470
static uint16_t
471
de_sgsap_sgs_cause(tvbuff_t *tvb, proto_tree *tree, packet_info *pinfo _U_, uint32_t offset, unsigned len _U_, char *add_string _U_, int string_len _U_)
472
0
{
473
0
    uint32_t curr_offset;
474
0
    uint8_t oct;
475
476
0
    curr_offset = offset;
477
478
0
    proto_tree_add_item(tree, hf_sgsap_sgs_cause, tvb, offset, 1, ENC_BIG_ENDIAN);
479
0
    if (add_string) {
480
0
        oct = tvb_get_uint8(tvb, curr_offset);
481
0
        snprintf(add_string, string_len, " - %s", val_to_str_ext_const(oct, &sgsap_sgs_cause_values_ext, "Reserved"));
482
0
    }
483
0
    curr_offset++;
484
485
0
    return curr_offset-offset;
486
0
}
487
/*
488
 * 9.4.19   SS code
489
 * The coding of the SS code value is according to SS-Code as specified in
490
 * subclause 17.7.5 of 3GPP TS 29.002 [15]
491
 * ( packet-nas_eps.c)
492
 */
493
/*
494
 * 9.4.20   TMSI
495
 * See subclause 18.4.23 in 3GPP TS 29.018 [16].
496
 * (packet-gsm_a_bssmap.c)
497
 */
498
499
/*
500
 * 9.4.21   TMSI status
501
 *
502
 * See subclause 18.4.24 in 3GPP TS 29.018 [16].
503
 * (packet-gsm_a_gm.c)
504
 */
505
/*
506
 * 9.4.21a  Tracking Area Identity
507
 * Octets 3 to 7 contain the value part of the Tracking Area Identity information element defined in 3GPP TS 24.301 [14]
508
 * (starting with octet 2, i.e. not including 3GPP TS 24.301 IEI)
509
 * (packet-nas_eps.c)
510
 */
511
/*
512
 * 9.4.21b  UE Time Zone
513
 * The coding of the UE Time Zone value is according to value part of the Time Zone information element as specified
514
 * in subclause 10.5.3.8 of 3GPP TS 24.008 [8] (i.e. not including 3GPP TS 24.008 IEI)
515
 * (packet-gsm_a_dtap.c)
516
 */
517
/*
518
 * 9.4.21c  UE EMM mode
519
 */
520
static const value_string sgsap_ue_emm_mode_values[] = {
521
    { 0x00, "EMM-IDLE" },
522
    { 0x01, "EMM-CONNECTED" },
523
    { 0, NULL }
524
};
525
526
static uint16_t
527
de_sgsap_ue_emm_mode(tvbuff_t *tvb, proto_tree *tree, packet_info *pinfo _U_, uint32_t offset, unsigned len _U_, char *add_string _U_, int string_len _U_)
528
0
{
529
0
    uint32_t curr_offset;
530
531
0
    curr_offset = offset;
532
533
0
    proto_tree_add_item(tree, hf_sgsap_ue_emm_mode, tvb, offset, 1, ENC_BIG_ENDIAN);
534
0
    curr_offset += 1;
535
536
0
    return curr_offset-offset;
537
0
}
538
/*
539
 * 9.4.22   VLR name
540
 */
541
static uint16_t
542
de_sgsap_vlr_name(tvbuff_t *tvb, proto_tree *tree, packet_info *pinfo _U_, uint32_t offset, unsigned len _U_, char *add_string _U_, int string_len _U_)
543
0
{
544
0
    unsigned  name_len;
545
0
    char *fqdn = NULL;
546
547
    /* The VLR name information element specifies the VLR name and is coded as shown in figure 9.4.22.1.
548
     * Octets 3 through n contain the VLR name in the form of a fully qualified domain name (FQDN)
549
     * as specified in IETF RFC 1035 [21].
550
     */
551
0
    if (len > 0) {
552
0
        name_len = tvb_get_uint8(tvb, offset);
553
554
0
        if (name_len < 0x20) {
555
0
            fqdn = (char*)tvb_get_string_enc(pinfo->pool, tvb, offset, len, ENC_APN_STR);
556
0
        } else{
557
0
            fqdn = (char*)tvb_get_string_enc(pinfo->pool, tvb, offset, len, ENC_ASCII);
558
0
        }
559
0
        proto_tree_add_string(tree, hf_sgsap_vlr_name, tvb, offset, len, fqdn);
560
0
        if (add_string)
561
0
            snprintf(add_string, string_len, " - %s", fqdn);
562
0
    }
563
564
0
    return len;
565
0
}
566
567
/*
568
 * 9.4.23   Channel needed
569
 * See subclause 18.4.2 in 3GPP TS 29.018 [16].
570
 * The rest of the information element is coded as the IEI part and the
571
 * value part of the Channel Needed IE defined in 3GPP TS 44.018
572
 * (packet-gsm_a_bssmap.c)
573
 */
574
/*
575
 * 9.4.24   eMLPP priority
576
 * See subclause 18.4.4 in 3GPP TS 29.018 [16].
577
 * The rest of the information element is coded as the value part of
578
 * the eMLPP-Priority IE defined in 3GPP TS 48.008 (not including
579
 * 3GPP TS 48.008 IEI and 3GPP TS 48.008 length indicator).
580
 * (packet-gsm_a_bssmap.c)
581
 */
582
583
/*
584
 *
585
 */
586
static uint16_t
587
de_sgsap_add_paging_ind(tvbuff_t *tvb, proto_tree *tree, packet_info *pinfo _U_, uint32_t offset, unsigned len _U_, char *add_string _U_, int string_len _U_)
588
0
{
589
    /* Octet 3 0 0 0 0 0 0 0 CSRI */
590
0
    proto_tree_add_item(tree, hf_sgsap_csri, tvb, offset, 1, ENC_BIG_ENDIAN);
591
592
0
    return len;
593
0
}
594
595
#if 0
596
Reuse GSM_A_PDU_TYPE_GM, DE_NET_RES_ID_CONT
597
/*
598
 * 9.4.26 TMSI based NRI container
599
 */
600
static uint16_t
601
de_sgsap_tmsi_based_nri_cont(tvbuff_t *tvb, proto_tree *tree, packet_info *pinfo _U_, uint32_t offset, unsigned len _U_, char *add_string _U_, int string_len _U_)
602
{
603
604
    /* See subclause 18.4.28 in 3GPP TS 29.018 [16].
605
     * Which says The TMSI based NRI container value value consists of 10 bits which correspond to bits 23 to 14 of the valid TMSI
606
     * (3GPP TS 23.236 and
607
     * Octet 3 and Octet 4 The rest of the information element is coded as the value part of the Network resource identifier container IE
608
     * defined in 3GPP TS 24.008.
609
     */
610
    return len;
611
}
612
#endif
613
/*
614
* 9.4.27 Selected CS domain operator
615
*/
616
static uint16_t
617
de_sgsap_selected_cs_dmn_op(tvbuff_t *tvb, proto_tree *tree, packet_info *pinfo _U_, uint32_t offset, unsigned len _U_, char *add_string _U_, int string_len _U_)
618
0
{
619
0
    proto_item *item;
620
0
    proto_tree *sub_tree;
621
    /* Coded as octets 2 to 4 of the Location Area Identification IE,
622
     * defined in 3GPP TS 24.008 [8] (not including 3GPP TS 24.008 IEI
623
     * and LAC).(10.5.1.3 Location Area Identification)
624
     * MCC digit 2 MCC digit 1 octet 2
625
     * MNC digit 3 MCC digit 3 octet 3
626
     * MNC digit 2 MNC digit 1 octet 4
627
     */
628
0
    item = proto_tree_add_item(tree, hf_sgsap_sel_cs_dmn_op, tvb, offset, 1, ENC_NA);
629
0
    sub_tree = proto_item_add_subtree(item, ett_sgsap_sel_cs_dmn_op);
630
631
0
    dissect_e212_mcc_mnc_wmem_packet_str(tvb, pinfo, sub_tree, offset, E212_LAI, true);
632
633
0
    return len;
634
0
}
635
636
static const value_string sgsap_elem_strings[] = {
637
    { DE_SGSAP_IMSI, "IMSI" },                                              /* 9.4.6 */
638
    { DE_SGSAP_VLR_NAME, "VLR name" },                                      /* 9.4.22 */
639
    { DE_SGSAP_TMSI, "TMSI" },                                              /* 9.4.20 */
640
    { DE_SGSAP_LOC_AREA_ID, "Location area identifier" },                   /* 9.4.11 */
641
    { DE_SGSAP_CH_NEEDED, "Channel Needed" },                               /* 9.4.23 */
642
    { DE_SGSAP_EMLPP_PRIO, "eMLPP Priority" },                              /* 9.4.24 */
643
    { DE_SGSAP_TMSI_STATUS, "TMSI status" },                                /* 9.4.21 */
644
    { DE_SGSAP_SGS_CAUSE, "SGs cause" },                                    /* 9.4.18 */
645
    { DE_SGSAP_MME_NAME, "MME name" },                                      /* 9.4.13 */
646
    { DE_SGSAP_EPS_LOC_UPD_TYPE, "EPS location update type" },              /* 9.4.2 */
647
    { DE_SGSAP_GLOBAL_CN_ID, "Global CN-Id" },                              /* 9.4.4 */
648
649
    { DE_SGSAP_UDEF_11, "Undefined" },                                      /*  */
650
    { DE_SGSAP_UDEF_12, "Undefined" },                                      /*  */
651
652
    { DE_SGSAP_MID, "Mobile identity" },                                    /* 9.4.14 */
653
    { DE_SGSAP_REJ_CAUSE, "Reject cause" },                                 /* 9.4.16 */
654
    { DE_SGSAP_IMSI_DET_EPS, "IMSI detach from EPS service type" },         /* 9.4.7 */
655
    { DE_SGSAP_IMSI_DET_NON_EPS, "IMSI detach from non-EPS service type" }, /* 9.4.8 */
656
657
    { DE_SGSAP_IMEISV, "IMEISV" },                                          /* 9.4.5 */
658
    { DE_SGSAP_NAS_MSG_CONTAINER, "NAS message container" },                /* 9.4.15 */
659
    { DE_SGSAP_MM_INFO, "MM information" },                                 /* 9.4.12 */
660
661
    { DE_SGSAP_UDEF_20, "Undefined" },                                      /*  */
662
    { DE_SGSAP_UDEF_21, "Undefined" },                                      /*  */
663
    { DE_SGSAP_UDEF_22, "Undefined" },                                      /*  */
664
665
    { DE_SGSAP_ERR_MSG, "Erroneous message" },                              /* 9.4.3 */
666
    { DE_SGSAP_CLI, "CLI" },                                                /* 9.4.1 */
667
    { DE_SGSAP_LCS_CLIENT_ID, "LCS client identity" },                      /* 9.4.9 */
668
    { DE_SGSAP_LCS_INDIC, "LCS indicator" },                                /* 9.4.10 */
669
    { DE_SGSAP_SS_CODE, "SS code" },                                        /* 9.4.19 */
670
    { DE_SGSAP_SERV_INDIC, "Service indicator" },                           /* 9.4.17 */
671
    { DE_SGSAP_UE_TZ, "UE Time Zone" },                                     /* 9.4.21b */
672
    { DE_SGSAP_MSC_2, "Mobile Station Classmark 2" },                       /* 9.4.14a */
673
    { DE_SGSAP_TAID, "Tracking Area Identity" },                            /* 9.4.21a */
674
    { DE_SGSAP_ECGI, "E-UTRAN Cell Global Identity" },                      /* 9.4.3a */
675
    { DE_SGSAP_UE_EMM_MODE, "UE EMM mode" },                                /* 9.4.21c */
676
    { DE_SGSAP_ADD_PAGING_IND, "Additional paging indicators" },            /* 9.4.25 */
677
    { DE_SGSAP_TMSI_BASED_NRI_CONT, "TMSI based NRI container" },           /* 9.4.26 */
678
    { DE_SGSAP_SELECTED_CS_DMN_OP, "Selected CS domain operator" },         /* 9.4.27 */
679
    { 0, NULL }
680
};
681
value_string_ext sgsap_elem_strings_ext = VALUE_STRING_EXT_INIT(sgsap_elem_strings);
682
683
546
#define NUM_SGSAP_ELEM array_length(sgsap_elem_strings)
684
int ett_sgsap_elem[NUM_SGSAP_ELEM];
685
#if 0
686
This enum has been moved to packet-gsm_a_common to
687
make it possible to use element dissecton from this dissector
688
in other dissectors.
689
It is left here as a comment for easier reference.
690
691
Note this enum must be of the same size as the element decoding list
692
693
typedef enum
694
{
695
696
    DE_SGSAP_IMSI,                                  /. 9.4.6 IMSI./
697
    DE_SGSAP_VLR_NAME,                              /. 9.4.22 VLR name./
698
    DE_SGSAP_TMSI,                                  /. 9.4.20 TMSI ./
699
    DE_SGSAP_LOC_AREA_ID,                           /. 9.4.11 Location area identifier ./
700
    DE_SGSAP_CH_NEEDED,                             /. 9.4.23 Channel Needed ./
701
    DE_SGSAP_EMLPP_PRIO,                            /. 9.4.24 eMLPP Priority./
702
    DE_SGSAP_TMSI_STATUS,                           /. 9.4.21 TMSI status ./
703
    DE_SGSAP_SGS_CAUSE,                             /. 9.4.18 SGs cause./
704
    DE_SGSAP_MME_NAME,                              /. 9.4.13 MME name./
705
    DE_SGSAP_EPS_LOC_UPD_TYPE,                      /. 9.4.2 EPS location update type./
706
    DE_SGSAP_GLOBAL_CN_ID,                          /. 9.4.4 Global CN-Id./
707
708
    DE_SGSAP_UDEF_11,                               /. Undefined ./
709
    DE_SGSAP_UDEF_12,                               /. Undefined ./
710
711
    DE_SGSAP_MID,                                   /. 9.4.14 Mobile identity./
712
    DE_SGSAP_REJ_CAUSE,                             /. 9.4.16 Reject cause ./
713
    DE_SGSAP_IMSI_DET_EPS,                          /. 9.4.7 IMSI detach from EPS service type ./
714
    DE_SGSAP_IMSI_DET_NON_EPS,                      /. 9.4.8 IMSI detach from non-EPS service type ./
715
716
    DE_SGSAP_IMEISV,                                /. 9.4.5 IMEISV ./
717
    DE_SGSAP_NAS_MSG_CONTAINER,                     /. 9.4.15 NAS message container./
718
    DE_SGSAP_MM_INFO,                               /. 9.4.12 MM information./
719
720
    DE_SGSAP_UDEF_20,                               /. Undefined ./
721
    DE_SGSAP_UDEF_21,                               /. Undefined ./
722
    DE_SGSAP_UDEF_22,                               /. Undefined ./
723
724
    DE_SGSAP_ERR_MSG,                               /. 9.4.3 Erroneous message./
725
    DE_SGSAP_CLI,                                   /. 9.4.1 CLI ./
726
    DE_SGSAP_LCS_CLIENT_ID,                         /. 9.4.9 LCS client identity ./
727
    DE_SGSAP_LCS_INDIC,                             /. 9.4.10 LCS indicator ./
728
    DE_SGSAP_SS_CODE,                               /. 9.4.19 SS code ./
729
    DE_SGSAP_SERV_INDIC,                            /. 9.4.17 Service indicator ./
730
    DE_SGSAP_UE_TZ,                                 /. 9.4.21b UE Time Zone ./
731
    DE_SGSAP_MSC_2,                                 /. 9.4.14a Mobile Station Classmark 2 ./
732
    DE_SGSAP_TAID,                                  /. 9.4.21a Tracking Area Identity ./
733
    DE_SGSAP_ECGI,                                  /. 9.4.3a E-UTRAN Cell Global Identity ./
734
    DE_SGSAP_UE_EMM_MODE,                           /. 9.4.21c UE EMM mode./
735
    DE_SGSAP_ADD_PAGING_IND,                        /. 9.4.25 Additional paging indicators ./
736
    DE_SGSAP_TMSI_BASED_NRI_CONT,                   /. 9.4.26 TMSI based NRI container ./
737
    DE_SGSAP_SELECTED_CS_DMN_OP,                    /. 9.4.27 Selected CS domain operator ./
738
739
    DE_SGAP_NONE                            /. NONE ./
740
}
741
sgsap_elem_idx_t;
742
#endif /* 0 */
743
744
uint16_t (* const sgsap_elem_fcn[])(tvbuff_t *tvb, proto_tree *tree, packet_info *pinfo _U_, uint32_t offset, unsigned len, char *add_string, int string_len) = {
745
    NULL/*DE_SGSAP_IMSI*/,                                  /* 9.4.6 IMSI*/
746
    de_sgsap_vlr_name,                                      /* 9.4.22 VLR name*/
747
    NULL/*DE_SGSAP_TMSI*/,                                  /* 9.4.20 TMSI */
748
    NULL/*DE_SGSAP_LOC_AREA_ID*/,                           /* 9.4.11 Location area identifier */
749
    NULL/*DE_SGSAP_CH_NEEDED*/,                             /* 9.4.23 Channel Needed */
750
    NULL/*DE_SGSAP_EMLPP_PRIO*/,                            /* 9.4.24 eMLPP Priority*/
751
    NULL/*DE_SGSAP_TMSI_STATUS*/,                           /* 9.4.21 TMSI status */
752
    de_sgsap_sgs_cause,                                     /* 9.4.18 SGs cause*/
753
    de_sgsap_mme_name,                                      /* 9.4.13 MME name*/
754
    de_sgsap_eps_loc_upd_type,                              /* 9.4.2 EPS location update type*/
755
    de_sgsap_g_cn_id,                                       /* 9.4.4 Global CN-Id*/
756
757
    NULL/*DE_SGSAP_UDEF_11*/,                               /* Undefined */
758
    NULL/*DE_SGSAP_UDEF_12*/,                               /* Undefined */
759
760
    NULL/*DE_SGSAP_MID*/,                                   /* 9.4.14 Mobile identity*/
761
    NULL/*DE_SGSAP_REJ_CAUSE*/,                             /* 9.4.16 Reject cause */
762
    de_sgsap_imsi_det_eps,                                  /* 9.4.7 IMSI detach from EPS service type */
763
    de_sgsap_imsi_det_non_eps,                              /* 9.4.8 IMSI detach from non-EPS service type */
764
765
    de_sgsap_imeisv,                                        /* 9.4.5 IMEISV */
766
    de_sgsap_nas_msg_container,                             /* 9.4.15 NAS message container*/
767
    de_sgsap_mm_info,                                       /* 9.4.12 MM information*/
768
769
    NULL/*DE_SGSAP_UDEF_20*/,                               /* Undefined */
770
    NULL/*DE_SGSAP_UDEF_21*/,                               /* Undefined */
771
    NULL/*DE_SGSAP_UDEF_22*/,                               /* Undefined */
772
773
    de_sgsap_err_msg,                                       /* 9.4.3 Erroneous message*/
774
    NULL/*DE_SGSAP_CLI*/,                                   /* 9.4.1 CLI */
775
    NULL/*DE_SGSAP_LCS_CLIENT_ID*/,                         /* 9.4.9 LCS client identity */
776
    de_sgsap_lcs_indic,                                     /* 9.4.10 LCS indicator */
777
    NULL/*DE_SGSAP_SS_CODE*/,                               /* 9.4.19 SS code */
778
    de_sgsap_serv_indic,                                    /* 9.4.17 Service indicator */
779
    NULL/*DE_SGSAP_UE_TZ*/,                                 /* 9.4.21b UE Time Zone */
780
    NULL/*DE_SGSAP_MSC_2*/,                                 /* 9.4.14a Mobile Station Classmark 2 */
781
    NULL/*DE_SGSAP_TAID*/,                                  /* 9.4.21a Tracking Area Identity */
782
    de_sgsap_ecgi,                                          /* 9.4.3a E-UTRAN Cell Global Identity */
783
    de_sgsap_ue_emm_mode,                                   /* 9.4.21c UE EMM mode*/
784
    de_sgsap_add_paging_ind,                                /* 9.4.25 Additional paging indicators */
785
    NULL/*DE_SGSAP_TMSI_BASED_NRI_CONT */,                  /* 9.4.26 TMSI based NRI container (Reuse GSM_A_PDU_TYPE_GM, DE_NET_RES_ID_CONT */
786
    de_sgsap_selected_cs_dmn_op,                            /* 9.4.27 Selected CS domain operator */
787
    NULL,   /* NONE */
788
};
789
790
/* MESSAGE FUNCTIONS */
791
792
/*
793
 * 8.1  SGsAP-ALERT-ACK message
794
 */
795
static void
796
sgsap_alert_ack(tvbuff_t *tvb, proto_tree *tree, packet_info *pinfo _U_, uint32_t offset, unsigned len)
797
0
{
798
0
    uint32_t curr_offset;
799
0
    uint32_t consumed;
800
0
    unsigned   curr_len;
801
802
0
    curr_offset = offset;
803
0
    curr_len    = len;
804
805
    /* IMSI IMSI 9.4.6  M   TLV 6-10 */
806
0
    ELEM_MAND_TLV(0x01, GSM_A_PDU_TYPE_BSSMAP, BE_IMSI, NULL, ei_sgsap_missing_mandatory_element);
807
808
0
    EXTRANEOUS_DATA_CHECK(curr_len, 0, pinfo, &ei_sgsap_extraneous_data);
809
0
}
810
811
/*
812
 * 8.2  SGsAP-ALERT-REJECT message
813
 */
814
static void
815
sgsap_alert_rej(tvbuff_t *tvb, proto_tree *tree, packet_info *pinfo _U_, uint32_t offset, unsigned len)
816
0
{
817
0
    uint32_t curr_offset;
818
0
    uint32_t consumed;
819
0
    unsigned   curr_len;
820
821
0
    curr_offset = offset;
822
0
    curr_len    = len;
823
824
    /* IMSI IMSI 9.4.6  M   TLV 6-10 */
825
0
    ELEM_MAND_TLV(0x01, GSM_A_PDU_TYPE_BSSMAP, BE_IMSI, NULL, ei_sgsap_missing_mandatory_element);
826
    /* SGs Cause    SGs cause  9.4.18   M   TLV 3 */
827
0
    ELEM_MAND_TLV(0x08, SGSAP_PDU_TYPE, DE_SGSAP_SGS_CAUSE, NULL, ei_sgsap_missing_mandatory_element);
828
829
0
    EXTRANEOUS_DATA_CHECK(curr_len, 0, pinfo, &ei_sgsap_extraneous_data);
830
0
}
831
832
/*
833
 * 8.3  SGsAP-ALERT-REQUEST message
834
 */
835
static void
836
sgsap_alert_req(tvbuff_t *tvb, proto_tree *tree, packet_info *pinfo _U_, uint32_t offset, unsigned len)
837
0
{
838
0
    uint32_t curr_offset;
839
0
    uint32_t consumed;
840
0
    unsigned   curr_len;
841
842
0
    curr_offset = offset;
843
0
    curr_len    = len;
844
845
    /* IMSI IMSI 9.4.6  M   TLV 6-10 */
846
0
    ELEM_MAND_TLV(0x01, GSM_A_PDU_TYPE_BSSMAP, BE_IMSI, NULL, ei_sgsap_missing_mandatory_element);
847
848
0
    EXTRANEOUS_DATA_CHECK(curr_len, 0, pinfo, &ei_sgsap_extraneous_data);
849
0
}
850
851
/*
852
 * 8.4  SGsAP-DOWNLINK-UNITDATA message
853
 */
854
static void
855
sgsap_dl_unitdata(tvbuff_t *tvb, proto_tree *tree, packet_info *pinfo _U_, uint32_t offset, unsigned len)
856
0
{
857
0
    uint32_t curr_offset;
858
0
    uint32_t consumed;
859
0
    unsigned   curr_len;
860
861
0
    curr_offset = offset;
862
0
    curr_len    = len;
863
864
865
    /* IMSI IMSI 9.4.6  M   TLV 6-10 */
866
0
    ELEM_MAND_TLV(0x01, GSM_A_PDU_TYPE_BSSMAP, BE_IMSI, NULL, ei_sgsap_missing_mandatory_element);
867
    /* NAS message container    NAS message container 9.4.15    M   TLV 4-253 */
868
0
    ELEM_MAND_TLV(0x16, SGSAP_PDU_TYPE, DE_SGSAP_NAS_MSG_CONTAINER, NULL, ei_sgsap_missing_mandatory_element);
869
870
0
    EXTRANEOUS_DATA_CHECK(curr_len, 0, pinfo, &ei_sgsap_extraneous_data);
871
0
}
872
873
/*
874
 * 8.5  SGsAP-EPS-DETACH-ACK message
875
 */
876
877
static void
878
sgsap_eps_det_ack(tvbuff_t *tvb, proto_tree *tree, packet_info *pinfo _U_, uint32_t offset, unsigned len)
879
0
{
880
0
    uint32_t curr_offset;
881
0
    uint32_t consumed;
882
0
    unsigned   curr_len;
883
884
0
    curr_offset = offset;
885
0
    curr_len    = len;
886
887
    /* IMSI IMSI 9.4.6  M   TLV 6-10 */
888
0
    ELEM_MAND_TLV(0x01, GSM_A_PDU_TYPE_BSSMAP, BE_IMSI, NULL, ei_sgsap_missing_mandatory_element);
889
890
0
    EXTRANEOUS_DATA_CHECK(curr_len, 0, pinfo, &ei_sgsap_extraneous_data);
891
0
}
892
/*
893
 * 8.6  SGsAP-EPS-DETACH-INDICATION message
894
 */
895
896
static void
897
sgsap_eps_det_ind(tvbuff_t *tvb, proto_tree *tree, packet_info *pinfo _U_, uint32_t offset, unsigned len)
898
0
{
899
0
    uint32_t curr_offset;
900
0
    uint32_t consumed;
901
0
    unsigned   curr_len;
902
903
0
    curr_offset = offset;
904
0
    curr_len    = len;
905
906
    /* IMSI IMSI 9.4.6  M   TLV 6-10 */
907
0
    ELEM_MAND_TLV(0x01, GSM_A_PDU_TYPE_BSSMAP, BE_IMSI, NULL, ei_sgsap_missing_mandatory_element);
908
    /* MME name MME name 9.4.13 M   TLV 57 */
909
0
    ELEM_MAND_TLV(0x09, SGSAP_PDU_TYPE, DE_SGSAP_MME_NAME, NULL, ei_sgsap_missing_mandatory_element);
910
    /* IMSI detach from EPS service type    IMSI detach from EPS service type 9.4.7 M   TLV 3 */
911
0
    ELEM_MAND_TLV(0x10, SGSAP_PDU_TYPE, DE_SGSAP_IMSI_DET_EPS, NULL, ei_sgsap_missing_mandatory_element);
912
913
0
    EXTRANEOUS_DATA_CHECK(curr_len, 0, pinfo, &ei_sgsap_extraneous_data);
914
0
}
915
916
/*
917
 * 8.7  SGsAP-IMSI-DETACH-ACK message
918
 */
919
static void
920
sgsap_imsi_det_ack(tvbuff_t *tvb, proto_tree *tree, packet_info *pinfo _U_, uint32_t offset, unsigned len)
921
0
{
922
0
    uint32_t curr_offset;
923
0
    uint32_t consumed;
924
0
    unsigned   curr_len;
925
926
0
    curr_offset = offset;
927
0
    curr_len    = len;
928
929
    /* IMSI IMSI 9.4.6  M   TLV 6-10 */
930
0
    ELEM_MAND_TLV(0x01, GSM_A_PDU_TYPE_BSSMAP, BE_IMSI, NULL, ei_sgsap_missing_mandatory_element);
931
932
0
    EXTRANEOUS_DATA_CHECK(curr_len, 0, pinfo, &ei_sgsap_extraneous_data);
933
0
}
934
/*
935
 * 8.8  SGsAP-IMSI-DETACH-INDICATION message
936
 */
937
static void
938
sgsap_imsi_det_ind(tvbuff_t *tvb, proto_tree *tree, packet_info *pinfo _U_, uint32_t offset, unsigned len)
939
0
{
940
0
    uint32_t curr_offset;
941
0
    uint32_t consumed;
942
0
    unsigned   curr_len;
943
944
0
    curr_offset = offset;
945
0
    curr_len    = len;
946
947
    /* IMSI IMSI 9.4.6  M   TLV 6-10 */
948
0
    ELEM_MAND_TLV(0x01, GSM_A_PDU_TYPE_BSSMAP, BE_IMSI, NULL, ei_sgsap_missing_mandatory_element);
949
    /* MME name MME name 9.4.13 M   TLV 57 */
950
0
    ELEM_MAND_TLV(0x09, SGSAP_PDU_TYPE, DE_SGSAP_MME_NAME, NULL, ei_sgsap_missing_mandatory_element);
951
    /* IMSI Detach from non-EPS service type    IMSI detach from non-EPS service type 9.4.8 M   TLV 3 */
952
0
    ELEM_MAND_TLV(0x11, SGSAP_PDU_TYPE, DE_SGSAP_IMSI_DET_NON_EPS, NULL, ei_sgsap_missing_mandatory_element);
953
954
0
    EXTRANEOUS_DATA_CHECK(curr_len, 0, pinfo, &ei_sgsap_extraneous_data);
955
0
}
956
957
/*
958
 * 8.9  SGsAP-LOCATION-UPDATE-ACCEPT message
959
 */
960
static void
961
sgsap_imsi_loc_update_acc(tvbuff_t *tvb, proto_tree *tree, packet_info *pinfo _U_, uint32_t offset, unsigned len)
962
0
{
963
0
    uint32_t curr_offset;
964
0
    uint32_t consumed;
965
0
    unsigned   curr_len;
966
967
0
    curr_offset = offset;
968
0
    curr_len    = len;
969
970
    /* IMSI IMSI 9.4.6  M   TLV 6-10 */
971
0
    ELEM_MAND_TLV(0x01, GSM_A_PDU_TYPE_BSSMAP, BE_IMSI, NULL, ei_sgsap_missing_mandatory_element);
972
    /* Location area identifier Location area identifier 9.4.11 M   TLV 7 */
973
0
    ELEM_MAND_TLV(0x04, GSM_A_PDU_TYPE_COMMON, DE_LAI, NULL, ei_sgsap_missing_mandatory_element);
974
    /* New TMSI, or IMSI    Mobile identity 9.4.14  O   TLV 6-10 */
975
0
    ELEM_OPT_TLV(0x0e, GSM_A_PDU_TYPE_COMMON, DE_MID, " - New TMSI, or IMSI");
976
977
0
    EXTRANEOUS_DATA_CHECK(curr_len, 0, pinfo, &ei_sgsap_extraneous_data);
978
0
}
979
980
/*
981
 * 8.10 SGsAP-LOCATION-UPDATE-REJECT message
982
 */
983
static void
984
sgsap_imsi_loc_update_rej(tvbuff_t *tvb, proto_tree *tree, packet_info *pinfo _U_, uint32_t offset, unsigned len)
985
0
{
986
0
    uint32_t curr_offset;
987
0
    uint32_t consumed;
988
0
    unsigned   curr_len;
989
990
0
    curr_offset = offset;
991
0
    curr_len    = len;
992
993
    /* IMSI IMSI 9.4.6  M   TLV 6-10 */
994
0
    ELEM_MAND_TLV(0x01, GSM_A_PDU_TYPE_BSSMAP, BE_IMSI, NULL, ei_sgsap_missing_mandatory_element);
995
    /* Reject cause Reject cause 9.4.16 M   TLV 3 */
996
0
    ELEM_MAND_TLV(0x0f, GSM_A_PDU_TYPE_DTAP, DE_REJ_CAUSE, NULL, ei_sgsap_missing_mandatory_element);
997
    /* Location area identifier Location area identifier 9.4.11 O   TLV 7 */
998
0
    ELEM_OPT_TLV(0x04, GSM_A_PDU_TYPE_COMMON, DE_LAI, NULL);
999
1000
0
    EXTRANEOUS_DATA_CHECK(curr_len, 0, pinfo, &ei_sgsap_extraneous_data);
1001
0
}
1002
1003
/*
1004
 * 8.11 SGsAP-LOCATION-UPDATE-REQUEST message
1005
 */
1006
1007
static void
1008
sgsap_imsi_loc_update_req(tvbuff_t *tvb, proto_tree *tree, packet_info *pinfo _U_, uint32_t offset, unsigned len)
1009
0
{
1010
0
    uint32_t curr_offset;
1011
0
    uint32_t consumed;
1012
0
    unsigned   curr_len;
1013
1014
0
    curr_offset = offset;
1015
0
    curr_len    = len;
1016
1017
    /* IMSI IMSI 9.4.6  M   TLV 6-10 */
1018
0
    ELEM_MAND_TLV(0x01, GSM_A_PDU_TYPE_BSSMAP, BE_IMSI, NULL, ei_sgsap_missing_mandatory_element);
1019
    /* MME name MME name 9.4.13 M   TLV 57 */
1020
0
    ELEM_MAND_TLV(0x09, SGSAP_PDU_TYPE, DE_SGSAP_MME_NAME, NULL, ei_sgsap_missing_mandatory_element);
1021
    /* EPS location update type EPS location update type 9.4.2  M   TLV 3 */
1022
0
    ELEM_MAND_TLV(0x0a, SGSAP_PDU_TYPE, DE_SGSAP_EPS_LOC_UPD_TYPE, NULL, ei_sgsap_missing_mandatory_element);
1023
    /* New location area identifier Location area identifier 9.4.11 M   TLV 7 */
1024
0
    ELEM_MAND_TLV(0x04, GSM_A_PDU_TYPE_COMMON, DE_LAI, NULL, ei_sgsap_missing_mandatory_element);
1025
    /* Old location area identifier Location area identifier 9.4.11 O   TLV 7 */
1026
0
    ELEM_OPT_TLV(0x04, GSM_A_PDU_TYPE_COMMON, DE_LAI, " - Old location area identifier");
1027
    /* TMSI status  TMSI status 9.4.21  O   TLV 3 */
1028
0
    ELEM_OPT_TLV( 0x07 , GSM_A_PDU_TYPE_GM, DE_TMSI_STAT , NULL );
1029
    /* IMEISV   IMEISV 9.4.5    O   TLV 10 */
1030
0
    ELEM_OPT_TLV(0x15, SGSAP_PDU_TYPE, DE_SGSAP_IMEISV, NULL);
1031
    /* TAI Tracking Area Identity 9.4.21a O TLV 7 */
1032
0
    ELEM_OPT_TLV(0x23, NAS_PDU_TYPE_EMM, DE_EMM_TRAC_AREA_ID, NULL);
1033
    /* E-CGI E-UTRAN Cell Global Identity 9.4.3a O TLV 9 */
1034
0
    ELEM_OPT_TLV(0x24, SGSAP_PDU_TYPE, DE_SGSAP_ECGI, NULL);
1035
    /* TMSI based NRI container TMSI based NRI container 9.4.26 O TLV 4 */
1036
0
    ELEM_OPT_TLV(0x27, GSM_A_PDU_TYPE_GM, DE_NET_RES_ID_CONT, " - TMSI based NRI container");
1037
    /* Selected CS domain operator Selected CS domain operator 9.4.27 O TLV 5 */
1038
0
    ELEM_OPT_TLV(0x28, SGSAP_PDU_TYPE, DE_SGSAP_SELECTED_CS_DMN_OP, NULL);
1039
1040
0
    EXTRANEOUS_DATA_CHECK(curr_len, 0, pinfo, &ei_sgsap_extraneous_data);
1041
0
}
1042
1043
/*
1044
 * 8.12 SGsAP-MM-INFORMATION-REQUEST
1045
 */
1046
static void
1047
sgsap_mm_info_req(tvbuff_t *tvb, proto_tree *tree, packet_info *pinfo _U_, uint32_t offset, unsigned len)
1048
0
{
1049
0
    uint32_t curr_offset;
1050
0
    uint32_t consumed;
1051
0
    unsigned   curr_len;
1052
1053
0
    curr_offset = offset;
1054
0
    curr_len    = len;
1055
1056
    /* IMSI IMSI 9.4.6  M   TLV 6-10 */
1057
0
    ELEM_MAND_TLV(0x01, GSM_A_PDU_TYPE_BSSMAP, BE_IMSI, NULL, ei_sgsap_missing_mandatory_element);
1058
    /* MM information   MM information 9.4.12   M   TLV 3-n */
1059
0
    ELEM_MAND_TLV(0x17, SGSAP_PDU_TYPE, DE_SGSAP_MM_INFO, NULL, ei_sgsap_missing_mandatory_element);
1060
1061
0
    EXTRANEOUS_DATA_CHECK(curr_len, 0, pinfo, &ei_sgsap_extraneous_data);
1062
0
}
1063
1064
/*
1065
 * 8.13 SGsAP-PAGING-REJECT message
1066
 */
1067
static void
1068
sgsap_paging_rej(tvbuff_t *tvb, proto_tree *tree, packet_info *pinfo _U_, uint32_t offset, unsigned len)
1069
0
{
1070
0
    uint32_t curr_offset;
1071
0
    uint32_t consumed;
1072
0
    unsigned   curr_len;
1073
1074
0
    curr_offset = offset;
1075
0
    curr_len    = len;
1076
1077
    /* IMSI IMSI 9.4.6  M   TLV 6-10 */
1078
0
    ELEM_MAND_TLV(0x01, GSM_A_PDU_TYPE_BSSMAP, BE_IMSI, NULL, ei_sgsap_missing_mandatory_element);
1079
    /* SGs Cause    SGs Cause 9.4.18    M   TLV 3 */
1080
0
    ELEM_MAND_TLV(0x08, SGSAP_PDU_TYPE, DE_SGSAP_SGS_CAUSE, NULL, ei_sgsap_missing_mandatory_element);
1081
1082
0
    EXTRANEOUS_DATA_CHECK(curr_len, 0, pinfo, &ei_sgsap_extraneous_data);
1083
0
}
1084
/*
1085
 * 8.14 SGsAP-PAGING-REQUEST message
1086
 */
1087
static void
1088
sgsap_paging_req(tvbuff_t *tvb, proto_tree *tree, packet_info *pinfo _U_, uint32_t offset, unsigned len)
1089
0
{
1090
0
    uint32_t curr_offset;
1091
0
    uint32_t consumed;
1092
0
    unsigned   curr_len;
1093
1094
0
    curr_offset = offset;
1095
0
    curr_len    = len;
1096
1097
    /* IMSI IMSI 9.4.6  M   TLV 6-10 */
1098
0
    ELEM_MAND_TLV(0x01, GSM_A_PDU_TYPE_BSSMAP, BE_IMSI, NULL, ei_sgsap_missing_mandatory_element);
1099
    /* VLR name VLR name 9.4.22 M   TLV 3-n */
1100
0
    ELEM_MAND_TLV(0x02, SGSAP_PDU_TYPE, DE_SGSAP_VLR_NAME, NULL, ei_sgsap_missing_mandatory_element);
1101
    /* Service indicator    Service indicator 9.4.17    M   TLV 3 */
1102
0
    ELEM_MAND_TLV(0x20, SGSAP_PDU_TYPE, DE_SGSAP_SERV_INDIC, NULL, ei_sgsap_missing_mandatory_element);
1103
    /* TMSI TMSI 9.4.20 O   TLV 6 */
1104
0
    ELEM_OPT_TLV(0x03, GSM_A_PDU_TYPE_BSSMAP, BE_TMSI, NULL);
1105
    /* CLI  CLI 9.4.1   O   TLV 3-14 */
1106
0
    ELEM_OPT_TLV(0x1c, GSM_A_PDU_TYPE_DTAP, DE_CLG_PARTY_BCD_NUM, " - CLI");
1107
    /* Location area identifier Location area identifier 9.4.11 O   TLV 7 */
1108
0
    ELEM_OPT_TLV(0x04, GSM_A_PDU_TYPE_COMMON, DE_LAI, NULL);
1109
    /* Global CN-Id Global CN-Id 9.4.4  O   TLV 7 */
1110
0
    ELEM_OPT_TLV(0x0b, SGSAP_PDU_TYPE, DE_SGSAP_GLOBAL_CN_ID, NULL);
1111
    /* SS code  SS code 9.4.19  O   TLV 3 */
1112
0
    ELEM_OPT_TLV(0x1f, NAS_PDU_TYPE_EMM, DE_EMM_SS_CODE, NULL);
1113
    /* LCS indicator    LCS indicator 9.4.10    O   TLV 3 */
1114
0
    ELEM_OPT_TLV(0x1e, SGSAP_PDU_TYPE, DE_SGSAP_LCS_INDIC, NULL);
1115
    /* LCS client identity  LCS client identity 9.4.9   O   TLV 3-n */
1116
0
    ELEM_OPT_TLV(0x1d, NAS_PDU_TYPE_EMM, DE_EMM_LCS_CLIENT_ID, NULL);
1117
    /* Channel needed   Channel needed 9.4.23   O   TLV 3 */
1118
0
    ELEM_OPT_TLV(0x05, GSM_A_PDU_TYPE_BSSMAP, BE_CHAN_NEEDED, NULL);
1119
    /* eMLPP Priority   eMLPP Priority 9.4.24   O   TLV 3 */
1120
0
    ELEM_OPT_TLV(0x06, GSM_A_PDU_TYPE_BSSMAP, BE_EMLPP_PRIO, NULL);
1121
    /* Additional paging indicators Additional paging indicators 9.4.25 O TLV 3 */
1122
0
    ELEM_OPT_TLV(0x26, SGSAP_PDU_TYPE, DE_SGSAP_ADD_PAGING_IND, NULL);
1123
1124
0
    EXTRANEOUS_DATA_CHECK(curr_len, 0, pinfo, &ei_sgsap_extraneous_data);
1125
0
}
1126
/*
1127
 * 8.15 SGsAP-RESET-ACK message
1128
 */
1129
static void
1130
sgsap_reset_ack(tvbuff_t *tvb, proto_tree *tree, packet_info *pinfo _U_, uint32_t offset, unsigned len)
1131
0
{
1132
0
    uint32_t curr_offset;
1133
0
    uint32_t consumed;
1134
0
    unsigned   curr_len;
1135
1136
0
    curr_offset = offset;
1137
0
    curr_len    = len;
1138
1139
    /* MME name MME name 9.4.13 C   TLV 57 */
1140
0
    ELEM_OPT_TLV(0x09, SGSAP_PDU_TYPE, DE_SGSAP_MME_NAME, NULL);
1141
    /* VLR name VLR name 9.4.22 C   TLV 3-n */
1142
0
    ELEM_OPT_TLV(0x02, SGSAP_PDU_TYPE, DE_SGSAP_VLR_NAME, NULL);
1143
1144
0
    EXTRANEOUS_DATA_CHECK(curr_len, 0, pinfo, &ei_sgsap_extraneous_data);
1145
0
}
1146
1147
/*
1148
 * 8.16 SGsAP-RESET-INDICATION message
1149
 */
1150
static void
1151
sgsap_reset_ind(tvbuff_t *tvb, proto_tree *tree, packet_info *pinfo _U_, uint32_t offset, unsigned len)
1152
0
{
1153
0
    uint32_t curr_offset;
1154
0
    uint32_t consumed;
1155
0
    unsigned   curr_len;
1156
1157
0
    curr_offset = offset;
1158
0
    curr_len    = len;
1159
1160
    /* MME name MME name 9.4.13 C   TLV 57 */
1161
0
    ELEM_OPT_TLV(0x09, SGSAP_PDU_TYPE, DE_SGSAP_MME_NAME, NULL);
1162
    /* VLR name VLR name 9.4.22 C   TLV 3-n */
1163
0
    ELEM_OPT_TLV(0x02, SGSAP_PDU_TYPE, DE_SGSAP_VLR_NAME, NULL);
1164
1165
0
    EXTRANEOUS_DATA_CHECK(curr_len, 0, pinfo, &ei_sgsap_extraneous_data);
1166
0
}
1167
/*
1168
 * 8.17 SGsAP-SERVICE-REQUEST message
1169
 */
1170
static void
1171
sgsap_service_req(tvbuff_t *tvb, proto_tree *tree, packet_info *pinfo _U_, uint32_t offset, unsigned len)
1172
0
{
1173
0
    uint32_t curr_offset;
1174
0
    uint32_t consumed;
1175
0
    unsigned   curr_len;
1176
1177
0
    curr_offset = offset;
1178
0
    curr_len    = len;
1179
1180
    /*IMSI  IMSI 9.4.6  M   TLV 6-10 */
1181
0
    ELEM_MAND_TLV(0x01, GSM_A_PDU_TYPE_BSSMAP, BE_IMSI, NULL, ei_sgsap_missing_mandatory_element);
1182
    /* Service indicator    Service indicator 9.4.17    M   TLV 3 */
1183
0
    ELEM_MAND_TLV(0x20, SGSAP_PDU_TYPE, DE_SGSAP_SERV_INDIC, NULL, ei_sgsap_missing_mandatory_element);
1184
    /* IMEISV   IMEISV 9.4.5    O   TLV 10 */
1185
0
    ELEM_OPT_TLV(0x15, SGSAP_PDU_TYPE, DE_SGSAP_IMEISV, NULL);
1186
    /* UE Time Zone UE Time Zone 9.4.21b    O   TLV 3 */
1187
0
    ELEM_OPT_TLV(0x21, GSM_A_PDU_TYPE_DTAP, DE_TIME_ZONE, " - UE Time Zone");
1188
    /* Mobile Station Classmark 2   Mobile Station Classmark 2 9.4.14a  O   TLV 5 */
1189
0
    ELEM_OPT_TLV(0x22 , GSM_A_PDU_TYPE_COMMON, DE_MS_CM_2, NULL);
1190
    /* TAI  Tracking Area Identity 9.4.21a  O   TLV 7 */
1191
0
    ELEM_OPT_TLV(0x23, NAS_PDU_TYPE_EMM, DE_EMM_TRAC_AREA_ID, NULL);
1192
    /* E-CGI    E-UTRAN Cell Global Identity 9.4.3a O   TLV 9 */
1193
0
    ELEM_OPT_TLV(0x24, SGSAP_PDU_TYPE, DE_SGSAP_ECGI, NULL);
1194
    /* UE EMM Mode  UE EMM mode 9.4.21c O   TLV 3 */
1195
0
    ELEM_OPT_TLV(0x25, SGSAP_PDU_TYPE, DE_SGSAP_UE_EMM_MODE, NULL);
1196
1197
0
    EXTRANEOUS_DATA_CHECK(curr_len, 0, pinfo, &ei_sgsap_extraneous_data);
1198
0
}
1199
1200
/*
1201
 * 8.18 SGsAP-STATUS message
1202
 */
1203
static void
1204
sgsap_status(tvbuff_t *tvb, proto_tree *tree, packet_info *pinfo _U_, uint32_t offset, unsigned len)
1205
0
{
1206
0
    uint32_t curr_offset;
1207
0
    uint32_t consumed;
1208
0
    unsigned   curr_len;
1209
1210
0
    curr_offset = offset;
1211
0
    curr_len    = len;
1212
1213
    /* IMSI IMSI 9.4.6  O   TLV 6-10 */
1214
0
    ELEM_OPT_TLV(0x01, GSM_A_PDU_TYPE_BSSMAP, BE_IMSI, NULL);
1215
    /* SGs cause    SGs cause 9.4.18    M   TLV 3 */
1216
0
    ELEM_MAND_TLV(0x08, SGSAP_PDU_TYPE, DE_SGSAP_SGS_CAUSE, NULL, ei_sgsap_missing_mandatory_element);
1217
    /* Erroneous message    Erroneous message 9.4.3 M   TLV 3-n */
1218
0
    ELEM_OPT_TLV(0x1b, SGSAP_PDU_TYPE, DE_SGSAP_ERR_MSG, NULL);
1219
1220
0
    EXTRANEOUS_DATA_CHECK(curr_len, 0, pinfo, &ei_sgsap_extraneous_data);
1221
0
}
1222
1223
/*
1224
 * 8.19 SGsAP-TMSI-REALLOCATION-COMPLETE message
1225
 */
1226
static void
1227
sgsap_tmsi_realloc_comp(tvbuff_t *tvb, proto_tree *tree, packet_info *pinfo _U_, uint32_t offset, unsigned len)
1228
0
{
1229
0
    uint32_t curr_offset;
1230
0
    uint32_t consumed;
1231
0
    unsigned   curr_len;
1232
1233
0
    curr_offset = offset;
1234
0
    curr_len    = len;
1235
1236
    /*IMSI  IMSI 9.4.6  M   TLV 6-10  */
1237
0
    ELEM_MAND_TLV(0x01, GSM_A_PDU_TYPE_BSSMAP, BE_IMSI, NULL, ei_sgsap_missing_mandatory_element);
1238
1239
0
    EXTRANEOUS_DATA_CHECK(curr_len, 0, pinfo, &ei_sgsap_extraneous_data);
1240
0
}
1241
1242
/*
1243
 * 8.20 SGsAP-UE-ACTIVITY-INDICATION message
1244
 */
1245
static void
1246
sgsap_ue_act_ind(tvbuff_t *tvb, proto_tree *tree, packet_info *pinfo _U_, uint32_t offset, unsigned len)
1247
0
{
1248
0
    uint32_t curr_offset;
1249
0
    uint32_t consumed;
1250
0
    unsigned   curr_len;
1251
1252
0
    curr_offset = offset;
1253
0
    curr_len    = len;
1254
1255
    /* IMSI IMSI 9.4.6  M   TLV 6-10 */
1256
0
    ELEM_MAND_TLV(0x01, GSM_A_PDU_TYPE_BSSMAP, BE_IMSI, NULL, ei_sgsap_missing_mandatory_element);
1257
1258
0
    EXTRANEOUS_DATA_CHECK(curr_len, 0, pinfo, &ei_sgsap_extraneous_data);
1259
0
}
1260
1261
/*
1262
 * 8.21 SGsAP-UE-UNREACHABLE message
1263
 */
1264
static void
1265
sgsap_ue_unreachable(tvbuff_t *tvb, proto_tree *tree, packet_info *pinfo _U_, uint32_t offset, unsigned len)
1266
0
{
1267
0
    uint32_t curr_offset;
1268
0
    uint32_t consumed;
1269
0
    unsigned   curr_len;
1270
1271
0
    curr_offset = offset;
1272
0
    curr_len    = len;
1273
1274
1275
    /* IMSI IMSI 9.4.6  M   TLV 6-10 */
1276
0
    ELEM_MAND_TLV(0x01, GSM_A_PDU_TYPE_BSSMAP, BE_IMSI, NULL, ei_sgsap_missing_mandatory_element);
1277
    /* SGs cause    SGs cause 9.4.18    M   TLV 3 */
1278
0
    ELEM_MAND_TLV(0x08, SGSAP_PDU_TYPE, DE_SGSAP_SGS_CAUSE, NULL, ei_sgsap_missing_mandatory_element);
1279
1280
0
    EXTRANEOUS_DATA_CHECK(curr_len, 0, pinfo, &ei_sgsap_extraneous_data);
1281
0
}
1282
/*
1283
 * 8.22 SGsAP-UPLINK-UNITDATA message
1284
 */
1285
static void
1286
sgsap_ue_ul_unitdata(tvbuff_t *tvb, proto_tree *tree, packet_info *pinfo _U_, uint32_t offset, unsigned len)
1287
0
{
1288
0
    uint32_t curr_offset;
1289
0
    uint32_t consumed;
1290
0
    unsigned   curr_len;
1291
1292
0
    curr_offset = offset;
1293
0
    curr_len    = len;
1294
1295
    /* IMSI IMSI 9.4.6  M   TLV 6-10 */
1296
0
    ELEM_MAND_TLV(0x01, GSM_A_PDU_TYPE_BSSMAP, BE_IMSI, NULL, ei_sgsap_missing_mandatory_element);
1297
    /* NAS message container    NAS message container 9.4.15    M   TLV 4-253 */
1298
0
    ELEM_MAND_TLV(0x16, SGSAP_PDU_TYPE, DE_SGSAP_NAS_MSG_CONTAINER, NULL, ei_sgsap_missing_mandatory_element);
1299
    /* IMEISV   IMEISV 9.4.5    O   TLV 10 */
1300
0
    ELEM_OPT_TLV(0x15, SGSAP_PDU_TYPE, DE_SGSAP_IMEISV, NULL);
1301
    /* UE Time Zone UE Time Zone 9.4.21b    O   TLV 3 */
1302
0
    ELEM_OPT_TLV(0x21, GSM_A_PDU_TYPE_DTAP, DE_TIME_ZONE, " - UE Time Zone");
1303
    /* Mobile Station Classmark 2   Mobile Station Classmark 2 9.4.14a  O   TLV 5 */
1304
0
    ELEM_OPT_TLV(0x22 , GSM_A_PDU_TYPE_COMMON, DE_MS_CM_2, NULL);
1305
    /* TAI  Tracking Area Identity 9.4.21a  O   TLV 7 */
1306
0
    ELEM_OPT_TLV(0x23, NAS_PDU_TYPE_EMM, DE_EMM_TRAC_AREA_ID, NULL);
1307
    /* E-CGI    E-UTRAN Cell Global Identity 9.4.3a O   TLV 9 */
1308
0
    ELEM_OPT_TLV(0x24, SGSAP_PDU_TYPE, DE_SGSAP_ECGI, NULL);
1309
1310
0
    EXTRANEOUS_DATA_CHECK(curr_len, 0, pinfo, &ei_sgsap_extraneous_data);
1311
0
}
1312
/*
1313
 * 8.23 SGsAP-RELEASE-REQUEST message
1314
 */
1315
static void
1316
sgsap_release_req(tvbuff_t *tvb, proto_tree *tree, packet_info *pinfo _U_, uint32_t offset, unsigned len)
1317
0
{
1318
0
    uint32_t curr_offset;
1319
0
    uint32_t consumed;
1320
0
    unsigned   curr_len;
1321
1322
0
    curr_offset = offset;
1323
0
    curr_len    = len;
1324
1325
    /* IMSI IMSI 9.4.6  M   TLV 6-10 */
1326
0
    ELEM_MAND_TLV(0x01, GSM_A_PDU_TYPE_BSSMAP, BE_IMSI, NULL, ei_sgsap_missing_mandatory_element);
1327
    /* SGs cause    SGs cause 9.4.18    O   TLV 3 */
1328
0
    ELEM_OPT_TLV(0x08, SGSAP_PDU_TYPE, DE_SGSAP_SGS_CAUSE, NULL);
1329
1330
0
    EXTRANEOUS_DATA_CHECK(curr_len, 0, pinfo, &ei_sgsap_extraneous_data);
1331
0
}
1332
1333
/*
1334
 * 8.24 SGsAP-SERVICE-ABORT-REQUEST message
1335
 */
1336
static void
1337
sgsap_service_abort_req(tvbuff_t *tvb, proto_tree *tree, packet_info *pinfo _U_, uint32_t offset, unsigned len)
1338
0
{
1339
0
    uint32_t curr_offset;
1340
0
    uint32_t consumed;
1341
0
    unsigned   curr_len;
1342
1343
0
    curr_offset = offset;
1344
0
    curr_len    = len;
1345
1346
    /* IMSI IMSI 9.4.6  M   TLV 6-10 */
1347
0
    ELEM_MAND_TLV(0x01, GSM_A_PDU_TYPE_BSSMAP, BE_IMSI, NULL, ei_sgsap_missing_mandatory_element);
1348
1349
0
    EXTRANEOUS_DATA_CHECK(curr_len, 0, pinfo, &ei_sgsap_extraneous_data);
1350
0
}
1351
1352
/*
1353
 * 8.25 SGsAP-MO-CSFB-INDICATION message
1354
 */
1355
static void
1356
sgsap_mo_csfb_ind(tvbuff_t *tvb, proto_tree *tree, packet_info *pinfo _U_, uint32_t offset, unsigned len)
1357
0
{
1358
0
    uint32_t curr_offset;
1359
0
    uint32_t consumed;
1360
0
    unsigned   curr_len;
1361
1362
0
    curr_offset = offset;
1363
0
    curr_len    = len;
1364
1365
    /* IMSI IMSI 9.4.6 M TLV 6-10 */
1366
0
    ELEM_MAND_TLV(0x01, GSM_A_PDU_TYPE_BSSMAP, BE_IMSI, NULL, ei_sgsap_missing_mandatory_element);
1367
    /* TAI Tracking Area Identity 9.4.21a O TLV 7 */
1368
0
    ELEM_OPT_TLV(0x23, NAS_PDU_TYPE_EMM, DE_EMM_TRAC_AREA_ID, NULL);
1369
    /* E-CGI E-UTRAN Cell Global Identity 9.4.3a O TLV 9 */
1370
0
    ELEM_OPT_TLV(0x24, SGSAP_PDU_TYPE, DE_SGSAP_ECGI, NULL);
1371
1372
0
    EXTRANEOUS_DATA_CHECK(curr_len, 0, pinfo, &ei_sgsap_extraneous_data);
1373
0
}
1374
/*
1375
 * 9.2  Message type
1376
 */
1377
static const value_string sgsap_msg_strings[] = {
1378
    { 0x01, "SGsAP-PAGING-REQUEST"},                /*  8.14 */
1379
    { 0x02, "SGsAP-PAGING-REJECT"},                 /*  8.13 */
1380
/*
1381
 * 0 0 0 0 0 0 1 1
1382
 * to
1383
 * 0 0 0 0 0 1 0 1
1384
 * Unassigned: treated as an unknown Message type
1385
 */
1386
    { 0x03, "Unassigned"},                          /* 7 */
1387
    { 0x04, "Unassigned"},                          /* 7 */
1388
    { 0x05, "Unassigned"},                          /* 7 */
1389
1390
    { 0x06, "SGsAP-SERVICE-REQUEST"},               /* 8.17 */
1391
    { 0x07, "SGsAP-DOWNLINK-UNITDATA"},             /* 8.4 */
1392
    { 0x08, "SGsAP-UPLINK-UNITDATA"},               /* 8.22 */
1393
    { 0x09, "SGsAP-LOCATION-UPDATE-REQUEST"},       /* 8.11 */
1394
    { 0x0a, "SGsAP-LOCATION-UPDATE-ACCEPT"},        /* 8.9 */
1395
    { 0x0b, "SGsAP-LOCATION-UPDATE-REJECT"},        /* 8.10 */
1396
    { 0x0c, "SGsAP-TMSI-REALLOCATION-COMPLETE"},    /* 8.19 */
1397
    { 0x0d, "SGsAP-ALERT-REQUEST"},                 /* 8.3 */
1398
    { 0x0e, "SGsAP-ALERT-ACK"},                     /* 8.1 */
1399
    { 0x0f, "SGsAP-ALERT-REJECT"},                  /* 8.2 */
1400
    { 0x10, "SGsAP-UE-ACTIVITY-INDICATION"},        /* 8.20 */
1401
    { 0x11, "SGsAP-EPS-DETACH-INDICATION"},         /* 8.6 */
1402
    { 0x12, "SGsAP-EPS-DETACH-ACK"},                /* 8.5 */
1403
    { 0x13, "SGsAP-IMSI-DETACH-INDICATION"},        /* 8.8 */
1404
    { 0x14, "SGsAP-IMSI-DETACH-ACK"},               /* 8.7 */
1405
    { 0x15, "SGsAP-RESET-INDICATION"},              /* 8.16 */
1406
    { 0x16, "SGsAP-RESET-ACK"},                     /* 8.15 */
1407
    { 0x17, "SGsAP-SERVICE-ABORT-REQUEST"},         /* 8.24 */
1408
    { 0x18, "SGsAP-MO-CSFB-INDICATION"},            /* 8.25 */
1409
/*
1410
 * 0 0 0 1 1 0 0 0
1411
 * to
1412
 * 0 0 0 1 1 0 0 1
1413
 * Unassigned: treated as an unknown Message type
1414
 */
1415
    { 0x19, "Unassigned"},
1416
1417
    { 0x1a, "SGsAP-MM-INFORMATION-REQUEST"},        /* 8.12 */
1418
    { 0x1b, "SGsAP-RELEASE-REQUEST"},               /* 8.23 */
1419
/*
1420
 * 0 0 0 1 1 1 0 0  Unassigned: treated as an unknown Message type  7
1421
 */
1422
    { 0x1c, "Unassigned"},                          /* 7 */
1423
1424
    { 0x1d, "SGsAP-STATUS"},                        /* 8.18 */
1425
    { 0x1e, "Unassigned"},                          /* 7 */
1426
    { 0x1f, "SGsAP-UE-UNREACHABLE"},                /* 8.21 */
1427
    { 0,    NULL }
1428
};
1429
static value_string_ext sgsap_msg_strings_ext = VALUE_STRING_EXT_INIT(sgsap_msg_strings);
1430
1431
462
#define NUM_SGSAP_MSG array_length(sgsap_msg_strings)
1432
static int ett_sgsap_msg[NUM_SGSAP_MSG];
1433
static void (* const sgsap_msg_fcn[])(tvbuff_t *tvb, proto_tree *tree, packet_info *pinfo _U_, uint32_t offset, unsigned len) = {
1434
    sgsap_paging_req,           /* 0x01,    "SGsAP-PAGING-REQUEST"  8.14 */
1435
    sgsap_paging_rej,           /* 0x02,    "SGsAP-PAGING-REJECT"   8.13 */
1436
/*
1437
 * 0 0 0 0 0 0 1 1
1438
 * to
1439
 * 0 0 0 0 0 1 0 1
1440
 * Unassigned: treated as an unknown Message type
1441
 */
1442
    NULL,                           /* 0x03,    "Unassigned" 7 */
1443
    NULL,                           /* 0x04,    "Unassigned" 7 */
1444
    NULL,                           /* 0x05,    "Unassigned" 7 */
1445
1446
    sgsap_service_req,              /* 0x06,    "SGsAP-SERVICE-REQUEST" 8.17 */
1447
    sgsap_dl_unitdata,              /* 0x07,    "SGsAP-DOWNLINK-UNITDATA" 8.4 */
1448
    sgsap_ue_ul_unitdata,           /* 0x08,    "SGsAP-UPLINK-UNITDATA" 8.22 */
1449
    sgsap_imsi_loc_update_req,      /* 0x09,    "SGsAP-LOCATION-UPDATE-REQUEST" 8.11 */
1450
    sgsap_imsi_loc_update_acc,      /* 0x0a,    "SGsAP-LOCATION-UPDATE-ACCEPT" 8.9 */
1451
    sgsap_imsi_loc_update_rej,      /* 0x0b,    "SGsAP-LOCATION-UPDATE-REJECT" 8.10 */
1452
    sgsap_tmsi_realloc_comp,        /* 0x0c,    "SGsAP-TMSI-REALLOCATION-COMPLETE"  8.19 */
1453
    sgsap_alert_req,                /* 0x0d,    "SGsAP-ALERT-REQUEST" 8.3 */
1454
    sgsap_alert_ack,                /* 0x0e,    "SGsAP-ALERT-ACK" 8.1 */
1455
    sgsap_alert_rej,                /* 0x0f,    "SGsAP-ALERT-REJECT" 8.2 */
1456
    sgsap_ue_act_ind,               /* 0x10,    "SGsAP-UE-ACTIVITY-INDICATION" 8.20 */
1457
    sgsap_eps_det_ind,              /* 0x11,    "SGsAP-EPS-DETACH-INDICATION" 8.6 */
1458
    sgsap_eps_det_ack,              /* 0x12,    "SGsAP-EPS-DETACH-ACK" 8.5 */
1459
    sgsap_imsi_det_ind,             /* 0x13,    "SGsAP-IMSI-DETACH-INDICATION" 8.8 */
1460
    sgsap_imsi_det_ack,             /* 0x14,    "SGsAP-IMSI-DETACH-ACK" 8.7 */
1461
    sgsap_reset_ind,                /* 0x15,    "SGsAP-RESET-INDICATION" 8.16 */
1462
    sgsap_reset_ack,                /* 0x16,    "SGsAP-RESET-ACK" 8.15 */
1463
    sgsap_service_abort_req,        /* 0x17,    "SGsAP-SERVICE-ABORT-REQUEST" 8.24 */
1464
    sgsap_mo_csfb_ind,              /* 0x18,    "SGsAP-MO-CSFB-INDICATION" 8.25 */
1465
/*
1466
 * 0 0 0 1 1 0 0 1
1467
 * to
1468
 * 0 0 0 1 1 0 0 1
1469
 * Unassigned: treated as an unknown Message type
1470
 */
1471
    NULL,                           /* 0x19,    "Unassigned" */
1472
1473
    sgsap_mm_info_req,              /* 0x1a,    "SGsAP-MM-INFORMATION-REQUEST" 8.12 */
1474
    sgsap_release_req,              /* 0x1b,    "SGsAP-RELEASE-REQUEST" 8.23 */
1475
/*
1476
 * 0 0 0 1 1 1 0 0  Unassigned: treated as an unknown Message type  7
1477
 */
1478
    NULL,                           /* 0x1c,    "Unassigned" */
1479
1480
    sgsap_status,                   /* 0x1d,    "SGsAP-STATUS" 8.18 */
1481
    NULL,                           /* 0x1e,    "Unassigned" */
1482
    sgsap_ue_unreachable,           /* 0x1f,    "SGsAP-UE-UNREACHABLE" 8.21 */
1483
1484
    NULL,   /* NONE */
1485
};
1486
1487
static void get_sgsap_msg_params(uint8_t oct, const char **msg_str, int *ett_tree, int *hf_idx, msg_fcn *msg_fcn_p)
1488
0
{
1489
0
    int             idx;
1490
1491
0
    *msg_str   = try_val_to_str_idx_ext((uint32_t) (oct & 0xff), &sgsap_msg_strings_ext, &idx);
1492
0
    *hf_idx    = hf_sgsap_msg_type;
1493
0
    if (*msg_str != NULL) {
1494
0
        *ett_tree  = ett_sgsap_msg[idx];
1495
0
        *msg_fcn_p = sgsap_msg_fcn[idx];
1496
0
    }
1497
1498
0
    return;
1499
0
}
1500
1501
1502
static int
1503
dissect_sgsap(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void* data _U_)
1504
0
{
1505
0
    proto_item      *item;
1506
0
    proto_tree      *sgsap_tree;
1507
0
    int              offset = 0;
1508
0
    uint32_t         len;
1509
0
    const char      *msg_str;
1510
0
    int              ett_tree;
1511
0
    int              hf_idx;
1512
0
    void            (*msg_fcn_p)(tvbuff_t *tvb, proto_tree *tree, packet_info *pinfo, uint32_t offset, unsigned len);
1513
0
    uint8_t         oct;
1514
1515
0
    len = tvb_reported_length(tvb);
1516
1517
    /* Make entry in the Protocol column on summary display */
1518
0
    col_set_str(pinfo->cinfo, COL_PROTOCOL, "SGSAP");
1519
1520
0
    item = proto_tree_add_item(tree, proto_sgsap, tvb, 0, -1, ENC_NA);
1521
0
    sgsap_tree = proto_item_add_subtree(item, ett_sgsap);
1522
1523
    /* Message type IE*/
1524
0
    oct       = tvb_get_uint8(tvb, offset);
1525
0
    msg_fcn_p = NULL;
1526
0
    ett_tree  = -1;
1527
0
    hf_idx    = -1;
1528
0
    msg_str   = NULL;
1529
1530
0
    get_sgsap_msg_params(oct, &msg_str, &ett_tree, &hf_idx, &msg_fcn_p);
1531
1532
0
    if (msg_str) {
1533
0
        col_add_str(pinfo->cinfo, COL_INFO, msg_str);
1534
0
    }else{
1535
0
        proto_tree_add_item(tree, hf_sgsap_unknown_msg, tvb, offset, 1, ENC_BIG_ENDIAN);
1536
0
        return tvb_captured_length(tvb);
1537
0
    }
1538
1539
    /*
1540
     * Add SGSAP message name
1541
     */
1542
0
    proto_tree_add_item(sgsap_tree, hf_idx, tvb, offset, 1, ENC_BIG_ENDIAN);
1543
0
    offset++;
1544
1545
1546
    /*
1547
     * decode elements
1548
     */
1549
0
    if (msg_fcn_p == NULL)
1550
0
    {
1551
0
        proto_tree_add_item(sgsap_tree, hf_sgsap_message_elements, tvb, offset, len - offset, ENC_NA);
1552
0
    }
1553
0
    else
1554
0
    {
1555
0
        (*msg_fcn_p)(tvb, sgsap_tree, pinfo, offset, len - offset);
1556
0
    }
1557
1558
0
    return tvb_captured_length(tvb);
1559
0
}
1560
1561
1562
1563
14
void proto_register_sgsap(void) {
1564
14
    unsigned     i;
1565
14
    unsigned     last_offset;
1566
1567
    /* List of fields */
1568
1569
14
  static hf_register_info hf[] = {
1570
14
    { &hf_sgsap_msg_type,
1571
14
        { "SGSAP Message Type",    "sgsap.msg_type",
1572
14
        FT_UINT8, BASE_HEX|BASE_EXT_STRING, &sgsap_msg_strings_ext, 0x0,
1573
14
        NULL, HFILL }
1574
14
    },
1575
14
    { &hf_sgsap_elem_id,
1576
14
        { "Element ID",    "sgsap.elem_id",
1577
14
        FT_UINT8, BASE_HEX, NULL, 0x0,
1578
14
        NULL, HFILL }
1579
14
    },
1580
14
    { &hf_sgsap_eps_location_update_type,
1581
14
        { "EPS location update type",    "sgsap.eps_location_update_type",
1582
14
        FT_UINT8, BASE_DEC, VALS(sgsap_eps_location_update_type_values), 0x0,
1583
14
        NULL, HFILL }
1584
14
    },
1585
14
    { &hf_sgsap_service_indicator_value,
1586
14
        { "Service indicator",    "sgsap.service_indicator",
1587
14
        FT_UINT8, BASE_DEC, VALS(sgsap_service_indicator_values), 0x0,
1588
14
        NULL, HFILL }
1589
14
    },
1590
14
    { &hf_sgsap_sgs_cause,
1591
14
        { "SGs cause",    "sgsap.sgs_cause",
1592
14
        FT_UINT8, BASE_DEC|BASE_EXT_STRING, &sgsap_sgs_cause_values_ext, 0x0,
1593
14
        NULL, HFILL }
1594
14
    },
1595
14
    { &hf_sgsap_ue_emm_mode,
1596
14
        { "UE EMM mode",    "sgsap.ue_emm_mode",
1597
14
        FT_UINT8, BASE_DEC, VALS(sgsap_ue_emm_mode_values), 0x0,
1598
14
        NULL, HFILL }
1599
14
    },
1600
14
    { &hf_sgsap_eci,
1601
14
        {"ECI (E-UTRAN Cell Identifier)", "sgsap.eci",
1602
14
        FT_UINT32, BASE_DEC, NULL, 0x0fffffff,
1603
14
        NULL, HFILL}
1604
14
    },
1605
14
    { &hf_sgsap_cn_id,
1606
14
        {"CN_ID", "sgsap.cn_id",
1607
14
        FT_UINT16, BASE_DEC, NULL, 0x0,
1608
14
        NULL, HFILL}
1609
14
    },
1610
14
    { &hf_sgsap_imsi_det_eps,
1611
14
        { "IMSI detach from EPS service type",    "sgsap.imsi_det_eps",
1612
14
        FT_UINT8, BASE_DEC, VALS(sgsap_imsi_det_from_eps_serv_type_values), 0x0,
1613
14
        NULL, HFILL }
1614
14
    },
1615
14
    { &hf_sgsap_imsi_det_non_eps,
1616
14
        { "IMSI detach from non-EPS service type",    "sgsap.imsi_det_non_eps",
1617
14
        FT_UINT8, BASE_DEC, VALS(sgsap_imsi_det_from_non_eps_serv_type_values), 0x0,
1618
14
        NULL, HFILL }
1619
14
    },
1620
14
    { &hf_sgsap_lcs_indic,
1621
14
        { "LCS indicator",    "sgsap.lcs_indicator",
1622
14
        FT_UINT8, BASE_DEC, VALS(sgsap_lcs_indic_values), 0x0,
1623
14
        NULL, HFILL }
1624
14
    },
1625
14
    { &hf_sgsap_mme_name,
1626
14
        {"MME name", "sgsap.mme_name",
1627
14
        FT_STRING, BASE_NONE, NULL, 0x0,
1628
14
        NULL, HFILL}
1629
14
    },
1630
14
    { &hf_sgsap_vlr_name,
1631
14
        {"VLR name", "sgsap.vlr_name",
1632
14
        FT_STRING, BASE_NONE, NULL, 0x0,
1633
14
        NULL, HFILL}
1634
14
    },
1635
14
    { &hf_sgsap_imeisv,
1636
14
        {"IMEISV", "sgsap.imeisv",
1637
14
        FT_STRING, BASE_NONE, NULL, 0x0,
1638
14
        NULL, HFILL}
1639
14
    },
1640
14
    { &hf_sgsap_unknown_msg,
1641
14
        { "Unknown message",    "sgsap.unknown_msg",
1642
14
        FT_UINT8, BASE_HEX, NULL, 0x0,
1643
14
        NULL, HFILL }
1644
14
    },
1645
14
    { &hf_sgsap_message_elements,
1646
14
        {"Message Elements", "sgsap.message_elements",
1647
14
        FT_BYTES, BASE_NONE, NULL, 0x0,
1648
14
        NULL, HFILL}
1649
14
    },
1650
14
    { &hf_sgsap_csri,
1651
14
        {"CS restoration indicator (CSRI)", "sgsap.csri",
1652
14
        FT_BOOLEAN, 8, TFS(&tfs_set_notset), 0x01,
1653
14
        NULL, HFILL }
1654
14
    },
1655
14
    { &hf_sgsap_sel_cs_dmn_op,
1656
14
        { "Selected CS domain operator", "sgsap.sel_cs_dmn_op",
1657
14
        FT_BYTES, BASE_NONE, NULL, 0x0,
1658
14
        NULL, HFILL }
1659
14
    },
1660
14
  };
1661
1662
14
    static ei_register_info ei[] = {
1663
14
        { &ei_sgsap_extraneous_data, { "sgsap.extraneous_data", PI_PROTOCOL, PI_NOTE, "Extraneous Data, dissector bug or later version spec (report to wireshark.org)", EXPFILL }},
1664
14
        { &ei_sgsap_missing_mandatory_element, { "sgsap.missing_mandatory_element", PI_PROTOCOL, PI_WARN, "Missing Mandatory element, rest of dissection is suspect", EXPFILL }},
1665
14
    };
1666
1667
14
   expert_module_t* expert_sgsap;
1668
1669
    /* Setup protocol subtree array */
1670
14
#define NUM_INDIVIDUAL_ELEMS    2
1671
14
    int *ett[NUM_INDIVIDUAL_ELEMS +
1672
14
          NUM_SGSAP_ELEM +
1673
14
          NUM_SGSAP_MSG];
1674
1675
14
    ett[0] = &ett_sgsap;
1676
14
    ett[1] = &ett_sgsap_sel_cs_dmn_op;
1677
1678
14
    last_offset = NUM_INDIVIDUAL_ELEMS;
1679
1680
546
    for (i=0; i < NUM_SGSAP_ELEM; i++, last_offset++)
1681
532
    {
1682
532
        ett[last_offset] = &ett_sgsap_elem[i];
1683
532
    }
1684
1685
462
    for (i=0; i < NUM_SGSAP_MSG; i++, last_offset++)
1686
448
    {
1687
448
        ett[last_offset] = &ett_sgsap_msg[i];
1688
448
    }
1689
1690
    /* Register protocol */
1691
14
    proto_sgsap = proto_register_protocol("SGs Application Part (SGsAP)", "SGSAP", "sgsap");
1692
    /* Register fields and subtrees */
1693
14
    proto_register_field_array(proto_sgsap, hf, array_length(hf));
1694
14
    proto_register_subtree_array(ett, array_length(ett));
1695
14
    expert_sgsap = expert_register_protocol(proto_sgsap);
1696
14
    expert_register_field_array(expert_sgsap, ei, array_length(ei));
1697
1698
    /* Register dissector */
1699
14
    sgsap_handle = register_dissector("sgsap", dissect_sgsap, proto_sgsap);
1700
1701
    /* sgsap_module = prefs_register_protocol(proto_sgsap, NULL); */
1702
1703
14
}
1704
1705
void
1706
proto_reg_handoff_sgsap(void)
1707
14
{
1708
    /* The registered SCTP port number for SGsAP is 29118.
1709
     * The payload protocol identifier to be used for SGsAP is 0.
1710
     */
1711
14
    gsm_a_dtap_handle = find_dissector_add_dependency("gsm_a_dtap", proto_sgsap);
1712
14
    dissector_add_uint_range_with_preference("sctp.port", SGSAP_SCTP_PORT_RANGE, sgsap_handle);
1713
14
}
1714
1715
/*
1716
 * Editor modelines  -  https://www.wireshark.org/tools/modelines.html
1717
 *
1718
 * Local variables:
1719
 * c-basic-offset: 4
1720
 * tab-width: 8
1721
 * indent-tabs-mode: nil
1722
 * End:
1723
 *
1724
 * vi: set shiftwidth=4 tabstop=8 expandtab:
1725
 * :indentSize=4:tabSize=8:noTabs=true:
1726
 */