Attention is currently required from: osmith, pespin.
laforge has posted comments on this change by pespin. ( https://gerrit.osmocom.org/c/libosmo-sigtran/+/43418?usp=email )
Change subject: xua_snm: Trim received Affected PC Mask to configured PC width
......................................................................
Patch Set 1: Code-Review+1
--
To view, visit https://gerrit.osmocom.org/c/libosmo-sigtran/+/43418?usp=email
To unsubscribe, or for help writing mail filters, visit https://gerrit.osmocom.org/settings?usp=email
Gerrit-MessageType: comment
Gerrit-Project: libosmo-sigtran
Gerrit-Branch: master
Gerrit-Change-Id: Ie178ff4b9fcbab16ca9d13b96fd689c4a57e8023
Gerrit-Change-Number: 43418
Gerrit-PatchSet: 1
Gerrit-Owner: pespin <pespin(a)sysmocom.de>
Gerrit-Reviewer: Jenkins Builder
Gerrit-Reviewer: laforge <laforge(a)osmocom.org>
Gerrit-Reviewer: osmith <osmith(a)sysmocom.de>
Gerrit-Attention: osmith <osmith(a)sysmocom.de>
Gerrit-Attention: pespin <pespin(a)sysmocom.de>
Gerrit-Comment-Date: Wed, 26 Aug 2026 21:22:37 +0000
Gerrit-HasComments: No
Gerrit-Has-Labels: Yes
lynxis lazus has submitted this change. ( https://gerrit.osmocom.org/c/osmo-remsim/+/43351?usp=email )
Change subject: client: simtrace2: Use the new API osmo_apdu_segment_in2()
......................................................................
client: simtrace2: Use the new API osmo_apdu_segment_in2()
The old osmo_apdu_segment_in() could not parse GP GET DATA correctly
and will fail when parsing a GP GET DATA case 2 with an Le != 0.
Related: SYS#8147
Change-Id: I432c96c8cdbcb78bc3e4f135ebd51c4077aa9007
---
M TODO-RELEASE
M src/client/user_simtrace2.c
2 files changed, 4 insertions(+), 3 deletions(-)
Approvals:
lynxis lazus: Looks good to me, approved
laforge: Looks good to me, but someone else must approve
fixeria: Looks good to me, but someone else must approve
Jenkins Builder: Verified
diff --git a/TODO-RELEASE b/TODO-RELEASE
index 0ed7189..1e46a1f 100644
--- a/TODO-RELEASE
+++ b/TODO-RELEASE
@@ -7,3 +7,4 @@
# If any interfaces have been added since the last public release: c:r:a + 1.
# If any interfaces have been removed or changed since the last public release: c:r:0.
#library what description / commit summary line
+libosmo-simtrace2 >0.9.1 osmo-remsim-client-st2 uses new api osmo_apdu_segment_in2()
diff --git a/src/client/user_simtrace2.c b/src/client/user_simtrace2.c
index 5d7d3c9..ad781ec 100644
--- a/src/client/user_simtrace2.c
+++ b/src/client/user_simtrace2.c
@@ -82,7 +82,7 @@
return 0;
}
-static struct osmo_apdu_context ac; // this will hold the complete APDU (across calls)
+static struct osmo_apdu_context ac, prev_ac; // this will hold the complete APDU and previous APDU (across calls)
/*! \brief Process a RX-DATA indication message from the SIMtrace2 */
static int process_do_rx_da(struct osmo_st2_cardem_inst *ci, uint8_t *buf, int len)
@@ -96,8 +96,8 @@
osmo_hexdump(data->data, data->data_len));
/* parse the APDU data in the USB message */
- rc = osmo_apdu_segment_in(&ac, data->data, data->data_len,
- data->flags & CEMU_DATA_F_TPDU_HDR);
+ rc = osmo_apdu_segment_in2(&ac, &prev_ac, data->data, data->data_len,
+ data->flags & CEMU_DATA_F_TPDU_HDR);
if (rc & APDU_ACT_TX_CAPDU_TO_CARD) {
/* there is no pending data coming from the modem */
--
To view, visit https://gerrit.osmocom.org/c/osmo-remsim/+/43351?usp=email
To unsubscribe, or for help writing mail filters, visit https://gerrit.osmocom.org/settings?usp=email
Gerrit-MessageType: merged
Gerrit-Project: osmo-remsim
Gerrit-Branch: master
Gerrit-Change-Id: I432c96c8cdbcb78bc3e4f135ebd51c4077aa9007
Gerrit-Change-Number: 43351
Gerrit-PatchSet: 3
Gerrit-Owner: lynxis lazus <lynxis(a)fe80.eu>
Gerrit-Reviewer: Jenkins Builder
Gerrit-Reviewer: dexter <pmaier(a)sysmocom.de>
Gerrit-Reviewer: fixeria <vyanitskiy(a)sysmocom.de>
Gerrit-Reviewer: laforge <laforge(a)osmocom.org>
Gerrit-Reviewer: lynxis lazus <lynxis(a)fe80.eu>
Attention is currently required from: dexter.
lynxis lazus has posted comments on this change by lynxis lazus. ( https://gerrit.osmocom.org/c/osmo-remsim/+/43351?usp=email )
Change subject: client: simtrace2: Use the new API osmo_apdu_segment_in2()
......................................................................
Patch Set 2: Code-Review+2
--
To view, visit https://gerrit.osmocom.org/c/osmo-remsim/+/43351?usp=email
To unsubscribe, or for help writing mail filters, visit https://gerrit.osmocom.org/settings?usp=email
Gerrit-MessageType: comment
Gerrit-Project: osmo-remsim
Gerrit-Branch: master
Gerrit-Change-Id: I432c96c8cdbcb78bc3e4f135ebd51c4077aa9007
Gerrit-Change-Number: 43351
Gerrit-PatchSet: 2
Gerrit-Owner: lynxis lazus <lynxis(a)fe80.eu>
Gerrit-Reviewer: Jenkins Builder
Gerrit-Reviewer: dexter <pmaier(a)sysmocom.de>
Gerrit-Reviewer: fixeria <vyanitskiy(a)sysmocom.de>
Gerrit-Reviewer: laforge <laforge(a)osmocom.org>
Gerrit-Reviewer: lynxis lazus <lynxis(a)fe80.eu>
Gerrit-Attention: dexter <pmaier(a)sysmocom.de>
Gerrit-Comment-Date: Wed, 26 Aug 2026 19:31:59 +0000
Gerrit-HasComments: No
Gerrit-Has-Labels: Yes
Attention is currently required from: fixeria, osmith, pespin.
lynxis lazus has posted comments on this change by fixeria. ( https://gerrit.osmocom.org/c/osmo-sgsn/+/42594?usp=email )
Change subject: gprs_gmm: gsm48_rx_gmm_att_req(): drop stale PDP contexts on re-Attach
......................................................................
Patch Set 4:
(1 comment)
Patchset:
PS4:
> Actually, we cannot merge this patch as-is. […]
That is a known issue and fixing it is quite complex.
--
To view, visit https://gerrit.osmocom.org/c/osmo-sgsn/+/42594?usp=email
To unsubscribe, or for help writing mail filters, visit https://gerrit.osmocom.org/settings?usp=email
Gerrit-MessageType: comment
Gerrit-Project: osmo-sgsn
Gerrit-Branch: master
Gerrit-Change-Id: I20c1f5f741275115635188b2f4b1c5fe7c6e40f1
Gerrit-Change-Number: 42594
Gerrit-PatchSet: 4
Gerrit-Owner: fixeria <vyanitskiy(a)sysmocom.de>
Gerrit-Reviewer: Jenkins Builder
Gerrit-Reviewer: fixeria <vyanitskiy(a)sysmocom.de>
Gerrit-Reviewer: osmith <osmith(a)sysmocom.de>
Gerrit-Reviewer: pespin <pespin(a)sysmocom.de>
Gerrit-CC: lynxis lazus <lynxis(a)fe80.eu>
Gerrit-Attention: osmith <osmith(a)sysmocom.de>
Gerrit-Attention: fixeria <vyanitskiy(a)sysmocom.de>
Gerrit-Attention: pespin <pespin(a)sysmocom.de>
Gerrit-Comment-Date: Wed, 26 Aug 2026 18:08:12 +0000
Gerrit-HasComments: Yes
Gerrit-Has-Labels: No
Comment-In-Reply-To: fixeria <vyanitskiy(a)sysmocom.de>
pespin has uploaded this change for review. ( https://gerrit.osmocom.org/c/libosmo-sigtran/+/43418?usp=email )
Change subject: xua_snm: Trim received Affected PC Mask to configured PC width
......................................................................
xua_snm: Trim received Affected PC Mask to configured PC width
The mask byte in the Affected PCs IE was so far directly controlled
by the peer sending the message to us.
As a result, values much bigger than expected (>14 in ITU and >24 in
ANSI) were being used as is, ending up in incorrect bitmasks being
generated and in turn resulting in potential endless loops and memory
allocation to fullfill up to ~2^30 combinations.
Related: OS#7078
Reported-By: Tristan Madani <tristan(a)talencesecurity.com>
Change-Id: Ie178ff4b9fcbab16ca9d13b96fd689c4a57e8023
---
M src/xua_snm.c
1 file changed, 21 insertions(+), 4 deletions(-)
git pull ssh://gerrit.osmocom.org:29418/libosmo-sigtran refs/changes/18/43418/1
diff --git a/src/xua_snm.c b/src/xua_snm.c
index 2abc42e..6befecc 100644
--- a/src/xua_snm.c
+++ b/src/xua_snm.c
@@ -48,6 +48,20 @@
osmo_static_assert(M3UA_IEI_ROUTE_CTX == SUA_IEI_ROUTE_CTX, _sa_rctx);
osmo_static_assert(M3UA_IEI_INFO_STRING == SUA_IEI_INFO_STRING, _sa_inf_str);
+/* Get "Mask" field from M3UA/SUA "Affected Point Code" IE and trim it to subset of
+ * Point Codes available in this instance.
+ * This prevents creating incorrect bitmasks and ending up in long loops based on peer
+ * inputting unexpected big values (ie. >14 on ITU and >24 on ANSI).
+ */
+static uint8_t mask_from_affected_pc(const struct osmo_ss7_instance *s7i, uint8_t aff_pc)
+{
+ const uint8_t pc_width = osmo_ss7_pc_width(&s7i->cfg.pc_fmt);
+ uint8_t mask = aff_pc >> 24;
+ if (mask > pc_width)
+ return pc_width;
+ return mask;
+}
+
static const char *format_affected_pcs_c(void *ctx, const struct osmo_ss7_instance *s7i,
const struct xua_msg_part *ie_aff_pc)
{
@@ -60,6 +74,7 @@
uint32_t _aff_pc = ntohl(aff_pc[i]);
uint32_t pc = _aff_pc & 0xffffff;
uint8_t mask = _aff_pc >> 24;
+ /* No need to call mask_from_affected_pc() here, we want to print what we actually received. */
/* append point code + mask */
out = talloc_asprintf_append(out, "%s%s/%u", i == 0 ? "" : ", ",
@@ -144,7 +159,7 @@
* see RFC 4666 3.4.1 */
uint32_t _aff_pc = ntohl(aff_pc[i]);
uint32_t pc = _aff_pc & 0xffffff;
- uint8_t mask = _aff_pc >> 24;
+ uint8_t mask = mask_from_affected_pc(s7i, _aff_pc);
if (!mask) {
if (available)
@@ -200,12 +215,14 @@
const uint32_t *aff_pc, unsigned int num_aff_pc,
bool available)
{
+ const struct osmo_ss7_instance *s7i = as->inst;
+
for (unsigned int i = 0; i < num_aff_pc; i++) {
/* 32bit "Affected Point Code" consists of a 7-bit mask followed by 14/16/24-bit SS7 PC,
* see RFC 4666 3.4.1 */
uint32_t _aff_pc = ntohl(aff_pc[i]);
uint32_t pc = _aff_pc & 0xffffff;
- uint8_t mask = _aff_pc >> 24;
+ uint8_t mask = mask_from_affected_pc(s7i, _aff_pc);
if (!mask) {
xua_snm_srm_pc_available_single(as, pc, available);
@@ -349,7 +366,7 @@
* see RFC 4666 3.4.1 */
uint32_t _aff_pc = ntohl(aff_pc[i]);
uint32_t pc = _aff_pc & 0xffffff;
- uint8_t mask = _aff_pc >> 24;
+ uint8_t mask = mask_from_affected_pc(s7i, _aff_pc);
if (!mask) {
mtp_status_ind_up_to_all_users(s7i, pc, MTP_UNAVAIL_C_CONGESTED,
@@ -430,7 +447,7 @@
for (i = 0; i < num_aff_pc; i++) {
uint32_t _aff_pc = ntohl(aff_pc[i]);
uint32_t pc = _aff_pc & 0xffffff;
- uint8_t mask = _aff_pc >> 24;
+ uint8_t mask = mask_from_affected_pc(s7i, _aff_pc);
bool is_available;
if (mask == 0) {
--
To view, visit https://gerrit.osmocom.org/c/libosmo-sigtran/+/43418?usp=email
To unsubscribe, or for help writing mail filters, visit https://gerrit.osmocom.org/settings?usp=email
Gerrit-MessageType: newchange
Gerrit-Project: libosmo-sigtran
Gerrit-Branch: master
Gerrit-Change-Id: Ie178ff4b9fcbab16ca9d13b96fd689c4a57e8023
Gerrit-Change-Number: 43418
Gerrit-PatchSet: 1
Gerrit-Owner: pespin <pespin(a)sysmocom.de>