1 /* GSM LAPDm (TS 04.06) implementation */
3 /* (C) 2010 by Harald Welte <laforge@gnumonks.org>
7 * This program is free software; you can redistribute it and/or modify
8 * it under the terms of the GNU General Public License as published by
9 * the Free Software Foundation; either version 2 of the License, or
10 * (at your option) any later version.
12 * This program is distributed in the hope that it will be useful,
13 * but WITHOUT ANY WARRANTY; without even the implied warranty of
14 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
15 * GNU General Public License for more details.
17 * You should have received a copy of the GNU General Public License along
18 * with this program; if not, write to the Free Software Foundation, Inc.,
19 * 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
27 #include <osmocore/timer.h>
28 #include <osmocore/msgb.h>
29 #include <osmocore/tlv.h>
30 #include <osmocore/utils.h>
31 #include <osmocore/rsl.h>
32 #include <osmocore/protocol/gsm_04_08.h>
33 #include <osmocore/protocol/gsm_08_58.h>
35 #include <osmocom/debug.h>
36 #include <osmocom/osmocom_data.h>
37 #include <osmocom/osmocom_layer2.h>
38 #include <osmocom/lapdm.h>
40 #include <l1a_l23_interface.h>
42 /* TS 04.06 Figure 4 / Section 3.2 */
43 #define LAPDm_LPD_NORMAL 0
44 #define LAPDm_LPD_SMSCB 1
45 #define LAPDm_SAPI_NORMAL 0
46 #define LAPDm_SAPI_SMS 3
47 #define LAPDm_ADDR(lpd, sapi, cr) (((lpd & 0x3) << 5) | ((sapi & 0x7) << 2) | ((cr & 0x1) << 1) | 0x1)
49 #define LAPDm_ADDR_SAPI(addr) ((addr >> 2) & 0x7)
51 /* TS 04.06 Table 3 / Section 3.4.3 */
52 #define LAPDm_CTRL_I(nr, ns, p) (((nr & 0x7) << 5) | ((p & 0x1) << 4) | ((ns & 0x7) << 1))
53 #define LAPDm_CTRL_S(nr, s, p) (((nr & 0x7) << 5) | ((p & 0x1) << 4) | ((s & 0x3) << 2) | 0x1)
54 #define LAPDm_CTRL_U(u, p) (((u & 0x1c) << 5) | ((p & 0x1) << 4) | ((u & 0x3) << 2) | 0x3)
56 #define LAPDm_CTRL_is_I(ctrl) ((ctrl & 0x1) == 0)
57 #define LAPDm_CTRL_is_S(ctrl) ((ctrl & 0x3) == 1)
58 #define LAPDm_CTRL_is_U(ctrl) ((ctrl & 0x3) == 3)
60 #define LAPDm_CTRL_U_BITS(ctrl) (((ctrl & 0xC) >> 2) | (ctrl & 0xE) >> 3)
61 #define LAPDm_CTRL_PF_BIT(ctrl) ((ctrl >> 4) & 0x1)
63 #define LAPDm_CTRL_S_BITS(ctrl) ((ctrl & 0xC) >> 2)
65 #define LAPDm_CTRL_I_Ns(ctrl) ((ctrl & 0xE) >> 1)
66 #define LAPDm_CTRL_I_Nr(ctrl) ((ctrl & 0xE0) >> 5)
68 /* TS 04.06 Table 4 / Section 3.8.1 */
69 #define LAPDm_U_SABM 0x7
70 #define LAPDm_U_DM 0x3
71 #define LAPDm_U_UI 0x0
72 #define LAPDm_U_DISC 0x8
73 #define LAPDm_U_UA 0xC
75 #define LAPDm_S_RR 0x0
76 #define LAPDm_S_RNR 0x1
77 #define LAPDm_S_REJ 0x2
79 #define LAPDm_LEN(len) ((len << 2) | 0x1)
81 /* TS 04.06 Section 5.8.3 */
82 #define N201_AB_SACCH 18
83 #define N201_AB_SDCCH 20
84 #define N201_AB_FACCH 20
86 #define N201_Bter_SACCH 21
87 #define N201_Bter_SDCCH 23
88 #define N201_Bter_FACCH 23
91 /* 5.8.2.1 N200 during establish and release */
92 #define N200_EST_REL 5
93 /* 5.8.2.1 N200 during timer recovery state */
94 #define N200_TR_SACCH 5
95 #define N200_TR_SDCCH 23
96 #define N200_TR_FACCH_FR 34
97 #define N200_TR_EFACCH_FR 48
98 #define N200_TR_FACCH_HR 29
99 /* FIXME: this depends on chan type */
100 #define N200 N200_TR_SACCH
102 #define CR_MS2BS_CMD 0
103 #define CR_MS2BS_RESP 1
104 #define CR_BS2MS_CMD 1
105 #define CR_BS2MS_RESP 0
107 /* Set T200 to 1 Second (OpenBTS uses 900ms) */
118 struct lapdm_msg_ctx {
119 struct lapdm_datalink *dl;
120 enum lapdm_format lapdm_fmt;
127 static void lapdm_t200_cb(void *data);
129 /* UTILITY FUNCTIONS */
131 static inline uint8_t inc_mod8(uint8_t x)
136 static void lapdm_dl_init(struct lapdm_datalink *dl,
137 struct lapdm_entity *entity)
139 memset(dl, 0, sizeof(*dl));
141 dl->t200.cb = &lapdm_t200_cb;
145 void lapdm_init(struct lapdm_entity *le, struct osmocom_ms *ms)
149 for (i = 0; i < ARRAY_SIZE(le->datalink); i++)
150 lapdm_dl_init(&le->datalink[i], le);
155 static struct lapdm_datalink *datalink_for_sapi(struct lapdm_entity *le, uint8_t sapi)
158 case LAPDm_SAPI_NORMAL:
159 return &le->datalink[0];
161 return &le->datalink[1];
167 /* remove the L2 header from a MSGB */
168 static inline unsigned char *msgb_pull_l2h(struct msgb *msg)
170 unsigned char *ret = msgb_pull(msg, msg->l3h - msg->l2h);
175 /* Take a Bbis format message from L1 and create RSLms UNIT DATA IND */
176 static int send_rslms_rll_l3(uint8_t msg_type, struct lapdm_msg_ctx *mctx,
179 uint8_t l3_len = msg->tail - (uint8_t *)msgb_l3(msg);
180 struct abis_rsl_rll_hdr *rh;
182 /* construct a RSLms RLL message (DATA INDICATION, UNIT DATA
183 * INDICATION) and send it off via RSLms */
185 /* Push the L3 IE tag and lengh */
186 msgb_tv16_push(msg, RSL_IE_L3_INFO, l3_len);
188 /* Then push the RSL header */
189 rh = (struct abis_rsl_rll_hdr *) msgb_push(msg, sizeof(*rh));
190 rsl_init_rll_hdr(rh, msg_type);
191 rh->c.msg_discr |= ABIS_RSL_MDISC_TRANSP;
192 rh->chan_nr = mctx->chan_nr;
193 rh->link_id = mctx->link_id;
195 /* set the l2 header pointer */
196 msg->l2h = (uint8_t *)rh;
198 /* send off the RSLms message to L3 */
199 return rslms_sendmsg(msg, mctx->dl->entity->ms);
202 static int send_rslms_rll_simple(uint8_t msg_type, struct lapdm_msg_ctx *mctx)
204 struct abis_rsl_rll_hdr *rh;
205 struct msgb *msg = msgb_alloc(sizeof(*rh), "rslms_rll_simple");
207 /* put the RSL header */
208 rh = (struct abis_rsl_rll_hdr *) msgb_put(msg, sizeof(*rh));
209 rsl_init_rll_hdr(rh, msg_type);
210 rh->c.msg_discr |= ABIS_RSL_MDISC_TRANSP;
211 rh->chan_nr = mctx->chan_nr;
212 rh->link_id = mctx->link_id;
214 /* set the l2 header pointer */
215 msg->l2h = (uint8_t *)rh;
217 /* send off the RSLms message to L3 */
218 return rslms_sendmsg(msg, mctx->dl->entity->ms);
221 static int check_length_ind(uint8_t length_ind)
223 if (!(length_ind & 0x01)) {
224 /* G.4.1 If the EL bit is set to "0", an MDL-ERROR-INDICATION
225 * primitive with cause "frame not implemented" is sent to the
226 * mobile management entity. */
227 printf("we don't support multi-octet length\n");
230 if (length_ind & 0x02) {
231 printf("we don't support LAPDm fragmentation yet\n");
237 /* Timer callback on T200 expiry */
238 static void lapdm_t200_cb(void *data)
240 struct lapdm_datalink *dl = data;
243 case LAPDm_STATE_SABM_SENT:
245 if (dl->retrans_ctr >= N200_EST_REL + 1) {
246 /* FIXME: send RELEASE INDICATION to L3 */
248 dl->state = LAPDm_STATE_IDLE;
250 /* FIXME: retransmit SABM command */
252 /* increment re-transmission counter */
254 /* restart T200 (PH-READY-TO-SEND) */
255 bsc_schedule_timer(&dl->t200, T200);
257 case LAPDm_STATE_MF_EST:
260 dl->state = LAPDm_STATE_TIMER_RECOV;
261 case LAPDm_STATE_TIMER_RECOV:
263 if (dl->retrans_ctr < N200) {
264 /* FIXME: retransmit I frame (V_s-1) with P=1 */
265 /* FIXME: send appropriate supervision frame with P=1 */
266 /* restart T200 (PH-READY-TO-SEND) */
267 bsc_schedule_timer(&dl->t200, T200);
269 /* FIXME: send ERROR INDICATION to L3 */
273 printf("T200 expired in dl->state %u\n", dl->state);
277 static int lapdm_send_rr(struct lapdm_msg_ctx *mctx, uint8_t f_bit)
279 uint8_t sapi = mctx->link_id & 7;
280 struct msgb *msg = msgb_alloc(24, "LAPDm RR");
281 uint8_t *data = msgb_put(msg, 3);
283 data[0] = LAPDm_ADDR(LAPDm_LPD_NORMAL, sapi, CR_MS2BS_RESP);
284 data[1] = LAPDm_CTRL_S(mctx->dl->V_recv, LAPDm_S_RR, f_bit);
285 data[2] = LAPDm_LEN(0);
287 return tx_ph_data_req(mctx->dl->entity->ms, msg, mctx->chan_nr, mctx->link_id);
292 /* Receive a LAPDm S (Unnumbered) message from L1 */
293 static int lapdm_rx_u(struct msgb *msg, struct lapdm_msg_ctx *mctx)
295 struct lapdm_datalink *dl = mctx->dl;
299 switch (LAPDm_CTRL_U_BITS(mctx->ctrl)) {
302 /* Must be Format B */
303 rc = check_length_ind(msg->l2h[2]);
306 length = msg->l2h[2] >> 2;
307 /* FIXME: G.4.5 check */
308 if (dl->state == LAPDm_STATE_MF_EST) {
310 /* FIXME: re-establishment procedure 5.6 */
312 /* FIXME: check for contention resoultion */
313 printf("SABM command, multiple frame established state\n");
318 /* 5.4.1.2 Normal establishment procedures */
319 rc = send_rslms_rll_simple(RSL_MT_EST_IND, mctx);
321 /* 5.4.1.4 Contention resolution establishment */
322 msg->l3h = msg->l2h + 3;
324 rc = send_rslms_rll_l3(RSL_MT_EST_IND, mctx, msg);
327 dl->state = LAPDm_STATE_SABM_SENT;
331 if (!LAPDm_CTRL_PF_BIT(mctx->ctrl)) {
332 /* 5.4.1.2 DM responses with the F bit set to "0" shall be ignored. */
336 case LAPDm_STATE_IDLE:
337 /* 5.4.5 all other frame types shall be discarded */
338 printf("state=IDLE (discarding) ");
340 case LAPDm_STATE_MF_EST:
341 if (LAPDm_CTRL_PF_BIT(mctx->ctrl) == 1)
342 printf("unsolicited DM resposne ");
344 printf("unsolicited DM resposne, multiple frame established state ");
346 case LAPDm_STATE_TIMER_RECOV:
347 /* DM is normal in case PF = 1 */
348 if (LAPDm_CTRL_PF_BIT(mctx->ctrl) == 0) {
349 printf("unsolicited DM resposne, multiple frame established state ");
355 bsc_del_timer(&dl->t200);
356 rc = send_rslms_rll_simple(RSL_MT_REL_IND, mctx);
360 if (mctx->lapdm_fmt == LAPDm_FMT_B4) {
362 msg->l3h = msg->l2h + 2;
364 rc = check_length_ind(msg->l2h[2]);
367 length = msg->l2h[2] >> 2;
368 msg->l3h = msg->l2h + 3;
370 /* do some length checks */
372 /* 5.3.3 UI frames received with the length indicator set to "0" shall be ignored */
373 printf("length=0 (discarding) ");
376 /* FIXME: G.4.5 check */
377 switch (LAPDm_ADDR_SAPI(mctx->ctrl)) {
378 case LAPDm_SAPI_NORMAL:
382 /* 5.3.3 UI frames with invalid SAPI values shall be discarded */
383 printf("sapi=%u (discarding) ", LAPDm_ADDR_SAPI(mctx->ctrl));
387 rc = send_rslms_rll_l3(RSL_MT_UNIT_DATA_IND, mctx, msg);
391 length = msg->l2h[2] >> 2;
392 if (length > 0 || msg->l2h[2] & 0x02) {
393 /* G.4.4 If a DISC or DM frame is received with L>0 or
394 * with the M bit set to "1", an MDL-ERROR-INDICATION
395 * primitive with cause "U frame with incorrect
396 * parameters" is sent to the mobile management entity. */
397 printf("U frame iwth incorrect parameters ");
401 case LAPDm_STATE_IDLE:
402 /* FIXME: send DM with F=P */
411 /* FIXME: G.4.5 check */
412 if (!LAPDm_CTRL_PF_BIT(mctx->ctrl)) {
413 /* 5.4.1.2 A UA response with the F bit set to "0" shall be ignored. */
414 printf("F=0 (discarding) ");
418 case LAPDm_STATE_SABM_SENT:
420 case LAPDm_STATE_IDLE:
421 /* 5.4.5 all other frame types shall be discarded */
423 printf("unsolicited UA response! (discarding) ");
426 /* reset Timer T200 */
427 bsc_del_timer(&dl->t200);
428 /* set Vs, Vr and Va to 0 */
429 dl->V_send = dl->V_recv = dl->V_ack = 0;
430 /* enter multiple-frame-established state */
431 dl->state = LAPDm_STATE_MF_EST;
432 /* send notification to L3 */
433 rc = send_rslms_rll_simple(RSL_MT_EST_CONF, mctx);
439 /* Receive a LAPDm S (Supervisory) message from L1 */
440 static int lapdm_rx_s(struct msgb *msg, struct lapdm_msg_ctx *mctx)
442 struct lapdm_datalink *dl = mctx->dl;
445 length = msg->l2h[2] >> 2;
446 if (length > 0 || msg->l2h[2] & 0x02) {
447 /* G.4.3 If a supervisory frame is received with L>0 or
448 * with the M bit set to "1", an MDL-ERROR-INDICATION
449 * primitive with cause "S frame with incorrect
450 * parameters" is sent to the mobile management entity. */
454 case LAPDm_STATE_IDLE:
455 /* FIXME: if P=1, respond DM with F=1 (5.2.2) */
456 /* 5.4.5 all other frame types shall be discarded */
459 switch (LAPDm_CTRL_S_BITS(mctx->ctrl)) {
473 /* Receive a LAPDm I (Information) message from L1 */
474 static int lapdm_rx_i(struct msgb *msg, struct lapdm_msg_ctx *mctx)
476 struct lapdm_datalink *dl = mctx->dl;
477 uint8_t nr = LAPDm_CTRL_I_Nr(mctx->ctrl);
478 uint8_t ns = LAPDm_CTRL_I_Ns(mctx->ctrl);
482 length = msg->l2h[2] >> 2;
483 /* FIXME: check for length > N201 */
485 /* G.4.2 If the length indicator of an I frame is set
486 * to a numerical value L>N201 or L=0, an MDL-ERROR-INDICATION
487 * primitive with cause "I frame with incorrect length"
488 * is sent to the mobile management entity. */
491 /* FIXME: G.4.2 If the numerical value of L is L<N201 and the M
492 * bit is set to "1", then an MDL-ERROR-INDICATION primitive with
493 * cause "I frame with incorrect use of M bit" is sent to the
494 * mobile management entity. */
496 case LAPDm_STATE_IDLE:
497 /* FIXME: if P=1, respond DM with F=1 (5.2.2) */
498 /* 5.4.5 all other frame types shall be discarded */
502 /* processing of Nr, Ns and P fields */
503 if (ns == dl->V_recv) {
504 /* FIXME: check for M bit! */
505 dl->V_recv = inc_mod8(dl->V_recv);
507 /* send a DATA INDICATION to L3 */
508 msg->l3h = msg->l2h + 2;
510 rc = send_rslms_rll_l3(RSL_MT_DATA_IND, mctx, msg);
512 printf("N(s) sequence error: Ns=%u, V_recv=%u ", ns, dl->V_recv);
513 /* FIXME: 5.7.1: N(s) sequence error */
518 /* Check for P bit */
519 if (LAPDm_CTRL_PF_BIT(mctx->ctrl)) {
521 /* FIXME: check ifwe are in own receiver busy */
522 /* FIXME: Send RR with F=1 */
523 rc = lapdm_send_rr(mctx, 1);
526 /* FIXME: check ifwe are in own receiver busy */
527 //if (we_have_I_frame_pending) {
529 /* FIXME: send that I frame with Nr=Vr */
531 /* Send RR with F=0 */
532 rc = lapdm_send_rr(mctx, 0);
536 if (dl->state != LAPDm_STATE_TIMER_RECOV) {
537 /* When not in the timer recovery condition, the data
538 * link layer entity shall reset the timer T200 on
539 * receipt of a valid I frame with N(R) higher than V(A) */
540 if (nr > dl->V_ack) {
541 /* FIXME: 5.5.3.1 Note 1 + 2 */
542 bsc_del_timer(&dl->t200);
543 /* FIXME: if there are outstanding I frames
544 * still unacknowledged, the data link layer
545 * entity shall set timer T200 */
548 /* FIXME: 5.7.4: N(R) sequence error */
549 /* N(R) is called valid, if and only if (N(R)-V(A)) mod 8 <= (V(S)-V(A)) mod 8. */
552 /* V(A) shall be set to the value of N(R) */
553 dl->V_ack = LAPDm_CTRL_I_Nr(mctx->ctrl);
558 /* Receive a LAPDm message from L1 */
559 static int lapdm_ph_data_ind(struct msgb *msg, struct lapdm_msg_ctx *mctx)
563 if (LAPDm_CTRL_is_U(mctx->ctrl))
564 rc = lapdm_rx_u(msg, mctx);
565 else if (LAPDm_CTRL_is_S(mctx->ctrl))
566 rc = lapdm_rx_s(msg, mctx);
567 else if (LAPDm_CTRL_is_I(mctx->ctrl))
568 rc = lapdm_rx_i(msg, mctx);
570 printf("unknown LAPDm format ");
576 /* input into layer2 (from layer 1) */
577 int l2_ph_data_ind(struct msgb *msg, struct lapdm_entity *le, struct l1ctl_info_dl *l1i)
579 uint8_t cbits = l1i->chan_nr >> 3;
580 uint8_t sapi = l1i->link_id & 7;
581 struct lapdm_msg_ctx mctx;
584 printf("l2_ph_data_ind() ");
585 /* when we reach here, we have a msgb with l2h pointing to the raw
586 * 23byte mac block. The l1h has already been purged. */
588 mctx.dl = datalink_for_sapi(le, sapi);
589 mctx.chan_nr = l1i->chan_nr;
590 mctx.link_id = l1i->link_id;
591 mctx.addr = mctx.ctrl = 0;
593 /* check for L1 chan_nr/link_id and determine LAPDm hdr format */
594 if (cbits == 0x10 || cbits == 0x12) {
595 /* Format Bbis is used on BCCH and CCCH(PCH, NCH and AGCH) */
596 mctx.lapdm_fmt = LAPDm_FMT_Bbis;
599 if (mctx.link_id & 0x40) {
600 /* It was received from network on SACCH, thus
601 * lapdm_fmt must be B4 */
602 mctx.lapdm_fmt = LAPDm_FMT_B4;
604 /* SACCH frames have a two-byte L1 header that OsmocomBB L1 doesn't
608 mctx.lapdm_fmt = LAPDm_FMT_B;
613 switch (mctx.lapdm_fmt) {
617 mctx.addr = msg->l2h[0];
618 if (!(mctx.addr & 0x01)) {
619 printf("we don't support multibyte addresses (discarding)\n");
622 mctx.ctrl = msg->l2h[1];
623 /* obtain SAPI from address field */
624 mctx.link_id |= LAPDm_ADDR_SAPI(mctx.addr);
625 rc = lapdm_ph_data_ind(msg, &mctx);
631 /* directly pass up to layer3 */
635 rc = send_rslms_rll_l3(RSL_MT_UNIT_DATA_IND, &mctx, msg);
643 /* L3 -> L2 / RSLMS -> LAPDm */
645 /* L3 requests establishment of data link */
646 static int rslms_rx_rll_est_req(struct msgb *msg, struct lapdm_datalink *dl)
648 struct abis_rsl_rll_hdr *rllh = msgb_l2(msg);
649 uint8_t chan_nr = rllh->chan_nr;
650 uint8_t link_id = rllh->link_id;
651 uint8_t sapi = rllh->link_id & 7;
652 struct tlv_parsed tv;
656 rsl_tlv_parse(&tv, rllh->data, msgb_l2len(msg)-sizeof(*rllh));
657 if (TLVP_PRESENT(&tv, RSL_IE_L3_INFO)) {
658 /* contention resolution establishment procedure */
659 if (dl->state != LAPDm_STATE_IDLE) {
660 /* 5.4.1.4: The data link layer shall, however, ignore any such
661 * service request if it is not in the idle state when the
662 * request is received. */
667 /* According to clause 6, the contention resolution
668 * procedure is only permitted with SAPI value 0 */
672 /* transmit a SABM command with the P bit set to "1". The SABM
673 * command shall contain the layer 3 message unit */
674 len = LAPDm_LEN(TLVP_LEN(&tv, RSL_IE_L3_INFO));
676 /* FIXME: store information field in dl entity */
678 /* normal establishment procedure */
682 /* Remove RLL header from msgb */
685 /* Push LAPDm header on msgb */
686 lapdh = msgb_push(msg, 3);
687 lapdh[0] = LAPDm_ADDR(LAPDm_LPD_NORMAL, sapi, CR_MS2BS_CMD);
688 lapdh[1] = LAPDm_CTRL_U(LAPDm_U_SABM, 1);
691 /* Tramsmit and start T200 */
692 bsc_schedule_timer(&dl->t200, T200);
693 return tx_ph_data_req(dl->entity->ms, msg, chan_nr, link_id);
696 /* L3 requests transfer of unnumbered information */
697 static int rslms_rx_rll_udata_req(struct msgb *msg, struct lapdm_datalink *dl)
699 struct abis_rsl_rll_hdr *rllh = msgb_l2(msg);
700 uint8_t chan_nr = rllh->chan_nr;
701 uint8_t link_id = rllh->link_id;
702 uint8_t sapi = link_id & 7;
703 struct tlv_parsed tv;
706 rsl_tlv_parse(&tv, rllh->data, msgb_l2len(msg)-sizeof(*rllh));
708 /* Remove RLL header from msgb */
711 /* Push LAPDm header on msgb */
712 lapdh = msgb_push(msg, 3);
713 lapdh[0] = LAPDm_ADDR(LAPDm_LPD_NORMAL, sapi, CR_MS2BS_CMD);
714 lapdh[1] = LAPDm_CTRL_U(LAPDm_U_SABM, 1);
715 lapdh[2] = LAPDm_LEN(TLVP_LEN(&tv, RSL_IE_L3_INFO));
717 /* Tramsmit and start T200 */
718 bsc_schedule_timer(&dl->t200, T200);
719 return tx_ph_data_req(dl->entity->ms, msg, chan_nr, link_id);
722 /* L3 requests transfer of acknowledged information */
723 static int rslms_rx_rll_data_req(struct msgb *msg, struct lapdm_datalink *dl)
725 struct abis_rsl_rll_hdr *rllh = msgb_l2(msg);
726 uint8_t chan_nr = rllh->chan_nr;
727 uint8_t link_id = rllh->link_id;
728 uint8_t sapi = rllh->link_id & 7;
729 struct tlv_parsed tv;
733 case LAPDm_STATE_MF_EST:
736 printf("refusing RLL DATA REQ during DL state %u\n", dl->state);
741 /* FIXME: check if the layer3 message length exceeds N201 */
743 rsl_tlv_parse(&tv, rllh->data, msgb_l2len(msg)-sizeof(*rllh));
745 /* Remove the RSL/RLL header */
748 /* Push the LAPDm header */
749 lapdh = msgb_put(msg, 3);
750 lapdh[0] = LAPDm_ADDR(LAPDm_LPD_NORMAL, sapi, CR_MS2BS_CMD);
751 lapdh[1] = LAPDm_CTRL_I(dl->V_recv, dl->V_send, 0);
752 lapdh[2] = LAPDm_LEN(TLVP_LEN(&tv, RSL_IE_L3_INFO));
754 /* The value of the send state variable V(S) shall be incremented by 1
755 * at the end of the transmission of the I frame */
756 dl->V_send = inc_mod8(dl->V_send);
758 /* If timer T200 is not running at the time right before transmitting a
759 * frame, when the PH-READY-TO-SEND primitive is received from the
760 * physical layer., it shall be set. */
761 if (!bsc_timer_pending(&dl->t200))
762 bsc_schedule_timer(&dl->t200, T200);
764 /* FIXME: If the send state variable V(S) is equal to V(A) plus k
765 * (where k is the maximum number of outstanding I frames - see
766 * subclause 5.8.4), the data link layer entity shall not transmit any
767 * new I frames, but shall retransmit an I frame as a result
768 * of the error recovery procedures as described in subclauses 5.5.4 and
771 return tx_ph_data_req(dl->entity->ms, msg, chan_nr, link_id);
774 /* incoming RSLms RLL message from L3 */
775 static int rslms_rx_rll(struct msgb *msg, struct osmocom_ms *ms)
777 struct abis_rsl_rll_hdr *rllh = msgb_l2(msg);
779 uint8_t sapi = rllh->link_id & 7;
780 struct lapdm_entity *le;
781 struct lapdm_datalink *dl;
783 if (rllh->link_id & 0x40)
784 le = &ms->lapdm_acch;
786 le = &ms->lapdm_dcch;
787 dl = datalink_for_sapi(le, sapi);
789 switch (rllh->c.msg_type) {
790 case RSL_MT_UNIT_DATA_REQ:
791 /* create and send UI command */
792 rc = rslms_rx_rll_udata_req(msg, dl);
795 /* create and send SABM command */
796 rc = rslms_rx_rll_est_req(msg, dl);
798 case RSL_MT_DATA_REQ:
799 /* create and send I command */
800 rc = rslms_rx_rll_data_req(msg, dl);
803 /* FIXME: create and send DISC command */
805 printf("unknown RLL message type 0x%02x\n",
813 /* input into layer2 (from layer 3) */
814 int rslms_recvmsg(struct msgb *msg, struct osmocom_ms *ms)
816 struct abis_rsl_common_hdr *rslh = msgb_l2(msg);
819 switch (rslh->msg_discr & 0xfe) {
820 case ABIS_RSL_MDISC_RLL:
821 rc = rslms_rx_rll(msg, ms);
824 printf("unknown RSLms message discriminator 0x%02x",