pespin has uploaded this change for review. ( 
https://gerrit.osmocom.org/c/libosmocore/+/32014 )


Change subject: Fix parsing of TLV_TYPE_SINGLE_TV
......................................................................

Fix parsing of TLV_TYPE_SINGLE_TV

The decoding path of TLV_TYPE_SINGLE_TV is wrong, since it is not
shifting right the tag before using it. On the other hand, the encoding
path (tlv_encode_one) is doing that, so it is clear there's a bug.

It seems that in order to workaround the bug some IEs in gsm_04_08.h (TS
24.008 and TS 44.018) were defined incorrectly (eg 0x80) while the spec
clearly assigns eg. "8" to it, and makes sure no full byte IEI collides.
Some other IEIs like GSM48_IE_GMM_CIPH_CKSN which are also of the same
type were already correctly defined as 0x08.

Change-Id: I799e35dc8d4d153fa63bf50563a5482cdf4de2d7
---
M include/osmocom/gsm/protocol/gsm_04_08.h
M src/gsm/tlv_parser.c
2 files changed, 25 insertions(+), 6 deletions(-)



  git pull ssh://gerrit.osmocom.org:29418/libosmocore refs/changes/14/32014/1

diff --git a/include/osmocom/gsm/protocol/gsm_04_08.h 
b/include/osmocom/gsm/protocol/gsm_04_08.h
index 66aa135..07ce09a 100644
--- a/include/osmocom/gsm/protocol/gsm_04_08.h
+++ b/include/osmocom/gsm/protocol/gsm_04_08.h
@@ -1734,6 +1734,10 @@
 #define GSM48_IE_FRQSHORT_AFTER        0x02
 #define GSM48_IE_MUL_RATE_CFG  0x03    /* 10.5.2.21aa */
 #define GSM48_IE_FREQ_L_AFTER  0x05
+#define GSM48_IE_GROUP_CIP_SEQ 0x08
+#define GSM48_IE_CIP_MODE_SET  0x09
+#define GSM48_IE_GPRS_RESUMPT  0xc0
+#define GSM48_IE_SYNC_IND      0x0d
 #define GSM48_IE_MSLOT_DESC    0x10
 #define GSM48_IE_CHANMODE_2    0x11
 #define GSM48_IE_FRQSHORT_BEFORE 0x12
@@ -1775,20 +1779,16 @@
 #define GSM48_IE_START_TIME    0x7c
 #define GSM48_IE_INDIVIDUAL_PRIORITIES 0x7c /* 44.018 Section 9.1.7 */
 #define GSM48_IE_TIMING_ADVANCE        0x7d
-#define GSM48_IE_GROUP_CIP_SEQ 0x80
-#define GSM48_IE_CIP_MODE_SET  0x90
-#define GSM48_IE_GPRS_RESUMPT  0xc0
-#define GSM48_IE_SYNC_IND      0xd0
 /* System Information 4 (types are equal IEs above) */
 #define GSM48_IE_CBCH_CHAN_DESC        0x64
 #define GSM48_IE_CBCH_MOB_AL   0x72

 /* Additional MM elements */
+#define GSM48_IE_PRIORITY_LEV  0x08
 #define GSM48_IE_LOCATION_AREA 0x13
 #define GSM48_IE_AUTN          0x20
 #define GSM48_IE_AUTH_RES_EXT  0x21
 #define GSM48_IE_AUTS          0x22
-#define GSM48_IE_PRIORITY_LEV  0x80
 #define GSM48_IE_FOLLOW_ON_PROC        0xa1
 #define GSM48_IE_CTS_PERMISSION        0xa2

diff --git a/src/gsm/tlv_parser.c b/src/gsm/tlv_parser.c
index de76688..f60da8c 100644
--- a/src/gsm/tlv_parser.c
+++ b/src/gsm/tlv_parser.c
@@ -241,7 +241,7 @@
        *o_tag = tag;

        /* single octet TV IE */
-       if (def->def[tag & 0xf0].type == TLV_TYPE_SINGLE_TV) {
+       if (def->def[(tag & 0xf0) >> 4].type == TLV_TYPE_SINGLE_TV) {
                *o_tag = tag & 0xf0;
                *o_val = buf;
                *o_len = 1;

--
To view, visit https://gerrit.osmocom.org/c/libosmocore/+/32014
To unsubscribe, or for help writing mail filters, visit 
https://gerrit.osmocom.org/settings

Gerrit-Project: libosmocore
Gerrit-Branch: master
Gerrit-Change-Id: I799e35dc8d4d153fa63bf50563a5482cdf4de2d7
Gerrit-Change-Number: 32014
Gerrit-PatchSet: 1
Gerrit-Owner: pespin <pes...@sysmocom.de>
Gerrit-MessageType: newchange

Reply via email to