2 * Routines for UMTS Node B Application Part(RANAP) packet dissection
3 * Copyright 2005 - 2010, Anders Broman <anders.broman[AT]ericsson.com>
7 * Wireshark - Network traffic analyzer
8 * By Gerald Combs <gerald@wireshark.org>
9 * Copyright 1998 Gerald Combs
11 * This program is free software; you can redistribute it and/or
12 * modify it under the terms of the GNU General Public License
13 * as published by the Free Software Foundation; either version 2
14 * of the License, or (at your option) any later version.
16 * This program is distributed in the hope that it will be useful,
17 * but WITHOUT ANY WARRANTY; without even the implied warranty of
18 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
19 * GNU General Public License for more details.
21 * You should have received a copy of the GNU General Public License
22 * along with this program; if not, write to the Free Software
23 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
25 * References: 3GPP TS 25.413 version 10.4.0 Release 10
31 #include <epan/packet.h>
33 #include <epan/wmem/wmem.h>
34 #include <epan/strutil.h>
35 #include <epan/asn1.h>
36 #include <epan/prefs.h>
38 #include "packet-ber.h"
39 #include "packet-per.h"
40 #include "packet-gsm_map.h"
41 #include "packet-ranap.h"
42 #include "packet-e212.h"
43 #include "packet-sccp.h"
44 #include "packet-gsm_a_common.h"
45 #include "packet-isup.h"
48 /* disable: "warning C4146: unary minus operator applied to unsigned type, result still unsigned" */
49 #pragma warning(disable:4146)
52 #define SCCP_SSN_RANAP 142
54 #define PNAME "Radio Access Network Application Part"
55 #define PSNAME "RANAP"
56 #define PFNAME "ranap"
58 /* Higest Ranap_ProcedureCode_value, use in heuristics */
59 #define RANAP_MAX_PC 45 /* id_RANAPenhancedRelocation = 45 */
61 #include "packet-ranap-val.h"
63 /* Initialize the protocol and registered fields */
64 static int proto_ranap
= -1;
66 /* initialise sub-dissector handles */
67 static dissector_handle_t rrc_s_to_trnc_handle
= NULL
;
68 static dissector_handle_t rrc_t_to_srnc_handle
= NULL
;
69 static dissector_handle_t rrc_ho_to_utran_cmd
= NULL
;
71 static int hf_ranap_imsi_digits
= -1;
72 static int hf_ranap_transportLayerAddress_ipv4
= -1;
73 static int hf_ranap_transportLayerAddress_ipv6
= -1;
74 static int hf_ranap_transportLayerAddress_nsap
= -1;
76 #include "packet-ranap-hf.c"
78 /* Initialize the subtree pointers */
79 static int ett_ranap
= -1;
80 static int ett_ranap_TransportLayerAddress
= -1;
81 static int ett_ranap_TransportLayerAddress_nsap
= -1;
83 #include "packet-ranap-ett.c"
85 /* Global variables */
86 static guint32 ProcedureCode
;
87 static guint32 ProtocolIE_ID
;
88 static guint32 ProtocolExtensionID
;
89 static gboolean glbl_dissect_container
= FALSE
;
90 /* Some IE:s identities uses the same value for different IE:s
91 * depending on PDU type:
96 * As a workarond a value is added to the IE:id in the .cnf file.
98 * ResetResourceList N rnsap.ies IMSG||id-IuSigConIdList # no spaces are allowed in value as a space is delimiter
99 * PDU type is stored in a global variable and can is used in the IE decoding section.
102 * &InitiatingMessage ,
103 * &SuccessfulOutcome OPTIONAL,
104 * &UnsuccessfulOutcome OPTIONAL,
107 * Only these two needed currently
111 #define SPECIAL (4<<16)
113 int pdu_type
= 0; /* 0 means wildcard */
115 /* Initialise the Preferences */
116 static gint global_ranap_sccp_ssn
= SCCP_SSN_RANAP
;
118 /* Dissector tables */
119 static dissector_table_t ranap_ies_dissector_table
;
120 static dissector_table_t ranap_ies_p1_dissector_table
;
121 static dissector_table_t ranap_ies_p2_dissector_table
;
122 static dissector_table_t ranap_extension_dissector_table
;
123 static dissector_table_t ranap_proc_imsg_dissector_table
;
124 static dissector_table_t ranap_proc_sout_dissector_table
;
125 static dissector_table_t ranap_proc_uout_dissector_table
;
126 static dissector_table_t ranap_proc_out_dissector_table
;
127 static dissector_table_t nas_pdu_dissector_table
;
129 static int dissect_ProtocolIEFieldValue(tvbuff_t
*tvb
, packet_info
*pinfo
, proto_tree
*tree
, void *);
130 static int dissect_ProtocolIEFieldPairFirstValue(tvbuff_t
*tvb
, packet_info
*pinfo
, proto_tree
*tree
, void *);
131 static int dissect_ProtocolIEFieldPairSecondValue(tvbuff_t
*tvb
, packet_info
*pinfo
, proto_tree
*tree
, void *);
132 static int dissect_ProtocolExtensionFieldExtensionValue(tvbuff_t
*tvb
, packet_info
*pinfo
, proto_tree
*tree
, void *);
133 static int dissect_InitiatingMessageValue(tvbuff_t
*tvb
, packet_info
*pinfo
, proto_tree
*tree
, void *);
134 static int dissect_SuccessfulOutcomeValue(tvbuff_t
*tvb
, packet_info
*pinfo
, proto_tree
*tree
, void *);
135 static int dissect_UnsuccessfulOutcomeValue(tvbuff_t
*tvb
, packet_info
*pinfo
, proto_tree
*tree
, void *);
136 static int dissect_OutcomeValue(tvbuff_t
*tvb
, packet_info
*pinfo
, proto_tree
*tree
, void *);
138 static int dissect_ranap_SourceRNC_ToTargetRNC_TransparentContainer(tvbuff_t
*tvb
, int offset
, asn1_ctx_t
*actx
, proto_tree
*tree
, int hf_index
);
139 static int dissect_ranap_TargetRNC_ToSourceRNC_TransparentContainer(tvbuff_t
*tvb
, int offset
, asn1_ctx_t
*actx
, proto_tree
*tree
, int hf_index
);
141 void proto_reg_handoff_ranap(void);
143 #include "packet-ranap-fn.c"
146 dissect_ProtocolIEFieldValue(tvbuff_t
*tvb
, packet_info
*pinfo
, proto_tree
*tree
, void *data _U_
)
152 /* Special handling, same ID used for different IE's depending on signal */
153 switch(ProcedureCode
){
154 case id_RelocationPreparation
:
155 if((ProtocolIE_ID
== id_Source_ToTarget_TransparentContainer
)||(ProtocolIE_ID
== id_Target_ToSource_TransparentContainer
)){
156 key
= SPECIAL
| ProtocolIE_ID
;
157 ret
= (dissector_try_uint_new(ranap_ies_dissector_table
, key
, tvb
, pinfo
, tree
, FALSE
, NULL
)) ? tvb_length(tvb
) : 0;
162 /* no special handling */
163 ret
= (dissector_try_uint_new(ranap_ies_dissector_table
, ProtocolIE_ID
, tvb
, pinfo
, tree
, FALSE
, NULL
)) ? tvb_length(tvb
) : 0;
165 key
= pdu_type
| ProtocolIE_ID
;
166 ret
= (dissector_try_uint_new(ranap_ies_dissector_table
, key
, tvb
, pinfo
, tree
, FALSE
, NULL
)) ? tvb_length(tvb
) : 0;
174 dissect_ProtocolIEFieldPairFirstValue(tvbuff_t
*tvb
, packet_info
*pinfo
, proto_tree
*tree
, void *data _U_
)
176 return (dissector_try_uint_new(ranap_ies_p1_dissector_table
, ProtocolIE_ID
, tvb
, pinfo
, tree
, FALSE
, NULL
)) ? tvb_length(tvb
) : 0;
180 dissect_ProtocolIEFieldPairSecondValue(tvbuff_t
*tvb
, packet_info
*pinfo
, proto_tree
*tree
, void *data _U_
)
182 return (dissector_try_uint_new(ranap_ies_p2_dissector_table
, ProtocolIE_ID
, tvb
, pinfo
, tree
, FALSE
, NULL
)) ? tvb_length(tvb
) : 0;
186 dissect_ProtocolExtensionFieldExtensionValue(tvbuff_t
*tvb
, packet_info
*pinfo
, proto_tree
*tree
, void *data _U_
)
188 return (dissector_try_uint_new(ranap_extension_dissector_table
, ProtocolExtensionID
, tvb
, pinfo
, tree
, FALSE
, NULL
)) ? tvb_length(tvb
) : 0;
192 dissect_InitiatingMessageValue(tvbuff_t
*tvb
, packet_info
*pinfo
, proto_tree
*tree
, void *data _U_
)
197 ret
= dissector_try_uint_new(ranap_proc_imsg_dissector_table
, ProcedureCode
, tvb
, pinfo
, tree
, FALSE
, NULL
);
199 return ret
? tvb_length(tvb
) : 0;
203 dissect_SuccessfulOutcomeValue(tvbuff_t
*tvb
, packet_info
*pinfo
, proto_tree
*tree
, void *data _U_
)
208 ret
= dissector_try_uint_new(ranap_proc_sout_dissector_table
, ProcedureCode
, tvb
, pinfo
, tree
, FALSE
, NULL
);
210 return ret
? tvb_length(tvb
) : 0;
214 dissect_UnsuccessfulOutcomeValue(tvbuff_t
*tvb
, packet_info
*pinfo
, proto_tree
*tree
, void *data _U_
)
216 return (dissector_try_uint_new(ranap_proc_uout_dissector_table
, ProcedureCode
, tvb
, pinfo
, tree
, FALSE
, NULL
)) ? tvb_length(tvb
) : 0;
220 dissect_OutcomeValue(tvbuff_t
*tvb
, packet_info
*pinfo
, proto_tree
*tree
, void *data _U_
)
222 return (dissector_try_uint_new(ranap_proc_out_dissector_table
, ProcedureCode
, tvb
, pinfo
, tree
, FALSE
, NULL
)) ? tvb_length(tvb
) : 0;
226 dissect_ranap(tvbuff_t
*tvb
, packet_info
*pinfo
, proto_tree
*tree
)
228 proto_item
*ranap_item
= NULL
;
229 proto_tree
*ranap_tree
= NULL
;
234 /* make entry in the Protocol column on summary display */
235 col_set_str(pinfo
->cinfo
, COL_PROTOCOL
, "RANAP");
237 /* create the ranap protocol tree */
238 ranap_item
= proto_tree_add_item(tree
, proto_ranap
, tvb
, 0, -1, ENC_NA
);
239 ranap_tree
= proto_item_add_subtree(ranap_item
, ett_ranap
);
241 dissect_RANAP_PDU_PDU(tvb
, pinfo
, ranap_tree
, NULL
);
242 if (pinfo
->sccp_info
) {
243 sccp_msg_info_t
* sccp_msg_lcl
= pinfo
->sccp_info
;
245 if (sccp_msg_lcl
->data
.co
.assoc
)
246 sccp_msg_lcl
->data
.co
.assoc
->payload
= SCCP_PLOAD_RANAP
;
248 if (! sccp_msg_lcl
->data
.co
.label
&& ProcedureCode
!= 0xFFFFFFFF) {
249 const gchar
* str
= val_to_str(ProcedureCode
, ranap_ProcedureCode_vals
,"Unknown RANAP");
250 sccp_msg_lcl
->data
.co
.label
= wmem_strdup(wmem_file_scope(), str
);
256 dissect_sccp_ranap_heur(tvbuff_t
*tvb
, packet_info
*pinfo
, proto_tree
*tree
, void *data _U_
)
263 asn1_ctx_init(&asn1_ctx
, ASN1_ENC_PER
, TRUE
, pinfo
);
265 /* Is it a ranap packet?
267 * 4th octet should be the length of the rest of the message.
268 * 2nd octet is the message-type e Z[0, 28]
269 * (obviously there must be at least four octets)
271 * If both hold true we'll assume its RANAP
274 #define LENGTH_OFFSET 3
275 #define MSG_TYPE_OFFSET 1
276 if (tvb_length(tvb
) < 4) { return FALSE
; }
277 /*if (tvb_get_guint8(tvb, LENGTH_OFFSET) != (tvb_length(tvb) - 4)) { return FALSE; }*/
278 /* Read the length NOTE offset in bits */
279 offset
= dissect_per_length_determinant(tvb
, LENGTH_OFFSET
<<3, &asn1_ctx
, tree
, -1, &length
);
281 if (length
!= (tvb_length(tvb
) - offset
)){
285 temp
= tvb_get_guint8(tvb
, MSG_TYPE_OFFSET
);
286 if (temp
> RANAP_MAX_PC
) { return FALSE
; }
288 dissect_ranap(tvb
, pinfo
, tree
);
293 /*--- proto_register_ranap -------------------------------------------*/
294 void proto_register_ranap(void) {
295 module_t
*ranap_module
;
299 static hf_register_info hf
[] = {
300 { &hf_ranap_imsi_digits
,
301 { "IMSI digits", "ranap.imsi_digits",
302 FT_STRING
, BASE_NONE
, NULL
, 0,
304 { &hf_ranap_transportLayerAddress_ipv4
,
305 { "transportLayerAddress IPv4", "ranap.transportLayerAddress_ipv4",
306 FT_IPv4
, BASE_NONE
, NULL
, 0,
308 { &hf_ranap_transportLayerAddress_ipv6
,
309 { "transportLayerAddress IPv6", "ranap.transportLayerAddress_ipv6",
310 FT_IPv6
, BASE_NONE
, NULL
, 0,
312 { &hf_ranap_transportLayerAddress_nsap
,
313 { "transportLayerAddress NSAP", "ranap.transportLayerAddress_NSAP",
314 FT_BYTES
, BASE_NONE
, NULL
, 0,
318 #include "packet-ranap-hfarr.c"
321 /* List of subtrees */
322 static gint
*ett
[] = {
324 &ett_ranap_TransportLayerAddress
,
325 &ett_ranap_TransportLayerAddress_nsap
,
326 #include "packet-ranap-ettarr.c"
330 /* Register protocol */
331 proto_ranap
= proto_register_protocol(PNAME
, PSNAME
, PFNAME
);
332 /* Register fields and subtrees */
333 proto_register_field_array(proto_ranap
, hf
, array_length(hf
));
334 proto_register_subtree_array(ett
, array_length(ett
));
336 /* Register dissector */
337 register_dissector("ranap", dissect_ranap
, proto_ranap
);
339 /* Register dissector tables */
340 ranap_ies_dissector_table
= register_dissector_table("ranap.ies", "RANAP-PROTOCOL-IES", FT_UINT32
, BASE_DEC
);
341 ranap_ies_p1_dissector_table
= register_dissector_table("ranap.ies.pair.first", "RANAP-PROTOCOL-IES-PAIR FirstValue", FT_UINT32
, BASE_DEC
);
342 ranap_ies_p2_dissector_table
= register_dissector_table("ranap.ies.pair.second", "RANAP-PROTOCOL-IES-PAIR SecondValue", FT_UINT32
, BASE_DEC
);
343 ranap_extension_dissector_table
= register_dissector_table("ranap.extension", "RANAP-PROTOCOL-EXTENSION", FT_UINT32
, BASE_DEC
);
344 ranap_proc_imsg_dissector_table
= register_dissector_table("ranap.proc.imsg", "RANAP-ELEMENTARY-PROCEDURE InitiatingMessage", FT_UINT32
, BASE_DEC
);
345 ranap_proc_sout_dissector_table
= register_dissector_table("ranap.proc.sout", "RANAP-ELEMENTARY-PROCEDURE SuccessfulOutcome", FT_UINT32
, BASE_DEC
);
346 ranap_proc_uout_dissector_table
= register_dissector_table("ranap.proc.uout", "RANAP-ELEMENTARY-PROCEDURE UnsuccessfulOutcome", FT_UINT32
, BASE_DEC
);
347 ranap_proc_out_dissector_table
= register_dissector_table("ranap.proc.out", "RANAP-ELEMENTARY-PROCEDURE Outcome", FT_UINT32
, BASE_DEC
);
349 nas_pdu_dissector_table
= register_dissector_table("ranap.nas_pdu", "RANAP NAS PDU", FT_UINT8
, BASE_DEC
);
351 ranap_module
= prefs_register_protocol(proto_ranap
, proto_reg_handoff_ranap
);
352 prefs_register_uint_preference(ranap_module
, "sccp_ssn", "SCCP SSN for RANAP",
353 "The SCCP SubSystem Number for RANAP (default 142)", 10,
354 &global_ranap_sccp_ssn
);
355 prefs_register_bool_preference(ranap_module
, "dissect_rrc_container",
356 "Attempt to dissect RRC-Container",
357 "Attempt to dissect RRC message embedded in RRC-Container IE",
358 &glbl_dissect_container
);
362 /*--- proto_reg_handoff_ranap ---------------------------------------*/
364 proto_reg_handoff_ranap(void)
366 static gboolean initialized
= FALSE
;
367 static dissector_handle_t ranap_handle
;
368 static gint local_ranap_sccp_ssn
;
371 ranap_handle
= find_dissector("ranap");
372 rrc_s_to_trnc_handle
= find_dissector("rrc.s_to_trnc_cont");
373 rrc_t_to_srnc_handle
= find_dissector("rrc.t_to_srnc_cont");
374 rrc_ho_to_utran_cmd
= find_dissector("rrc.irat.ho_to_utran_cmd");
376 #include "packet-ranap-dis-tab.c"
378 dissector_delete_uint("sccp.ssn", local_ranap_sccp_ssn
, ranap_handle
);
381 dissector_add_uint("sccp.ssn", global_ranap_sccp_ssn
, ranap_handle
);
382 local_ranap_sccp_ssn
= global_ranap_sccp_ssn
;
383 /* Add heuristic dissector
384 * Perhaps we want a preference whether the heuristic dissector
385 * is or isn't enabled
387 heur_dissector_add("sccp", dissect_sccp_ranap_heur
, proto_ranap
);
388 heur_dissector_add("sua", dissect_sccp_ranap_heur
, proto_ranap
);