mirror of
https://github.com/MengMengCode/VoCat.git
synced 2026-08-22 07:43:43 +08:00
Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
63553eaf2b | ||
|
|
72e0af6eb9 | ||
|
|
c66fe06def | ||
|
|
489a6dc10c | ||
|
|
9c39e15bcf | ||
|
|
3b8f32f591 | ||
|
|
0318670f49 | ||
|
|
d06afdb076 | ||
|
|
b56acc0e3a | ||
|
|
60cc636969 | ||
|
|
73a72680ad | ||
|
|
60501d4831 | ||
|
|
2c843d82a4 | ||
|
|
ad66456d2f | ||
|
|
161aa667c9 | ||
|
|
8137fc875b | ||
|
|
1df338f9b3 | ||
|
|
20f91fac72 | ||
|
|
30880f6612 |
@@ -49,13 +49,13 @@ jobs:
|
||||
BUILD_TIME=${{ github.event.repository.updated_at }}
|
||||
cache-from: type=gha
|
||||
|
||||
- name: Verify ${{ matrix.platform }} runtime and smart-card stack
|
||||
- name: Verify ${{ matrix.platform }} runtime, QMI, and smart-card stack
|
||||
run: |
|
||||
docker run --rm --platform '${{ matrix.platform }}' \
|
||||
vocat-smoke:${{ matrix.arch }} version
|
||||
docker run --rm --platform '${{ matrix.platform }}' \
|
||||
--entrypoint /bin/sh vocat-smoke:${{ matrix.arch }} -c \
|
||||
'command -v pcscd && test -d /usr/lib/pcsc/drivers'
|
||||
'command -v qmicli && command -v qmi-network && command -v pcscd && test -d /usr/lib/pcsc/drivers'
|
||||
|
||||
build-and-push:
|
||||
needs: smoke
|
||||
|
||||
+1
-1
@@ -36,7 +36,7 @@ RUN CGO_ENABLED=0 GOOS=${TARGETOS:-linux} GOARCH=${TARGETARCH} go build \
|
||||
|
||||
# ---- Stage 3: minimal runtime ----
|
||||
FROM alpine:3.20
|
||||
RUN apk add --no-cache ca-certificates ccid iproute2 pcsc-lite tzdata && \
|
||||
RUN apk add --no-cache ca-certificates ccid iproute2 pcsc-lite qmi-utils tzdata && \
|
||||
addgroup -S -g 1000 vocat && \
|
||||
adduser -S -D -H -u 1000 -G vocat vocat
|
||||
|
||||
|
||||
@@ -96,6 +96,14 @@ to install matching `ip-full`, `kmod-ipsec`, `kmod-ipsec4/6`,
|
||||
If matching kernel modules are unavailable, use a firmware that includes them;
|
||||
never force-install kmods built for a different kernel.
|
||||
|
||||
If your kernel cannot provide XFRM/IPsec and you only need non-VoWiFi features
|
||||
such as cellular SMS or data, install with `--skip-vowifi-check`:
|
||||
|
||||
```bash
|
||||
curl -fsSL https://raw.githubusercontent.com/MengMengCode/VoCat/master/scripts/install.sh -o install.sh
|
||||
sudo bash install.sh --skip-vowifi-check
|
||||
```
|
||||
|
||||
The installer:
|
||||
|
||||
- detects `amd64`, `386`, `arm64`, `aarch64`, or `armv7`;
|
||||
@@ -188,6 +196,11 @@ those fixed nodes and does not provide complete multi-device or hot-plug discove
|
||||
|
||||
The GHCR image is published for `linux/amd64` and `linux/arm64`.
|
||||
|
||||
> [!TIP]
|
||||
> **NAS / QNAP Container Station Deployment Note**:
|
||||
> On NAS operating systems like QNAP QTS / QuTS hero (Container Station), custom non-root administrator accounts and volume isolation mechanisms may cause Docker named volumes (e.g. `-v vocat-data:/opt/vocat/data`) to resolve to different isolated paths between the one-off `bootstrap-admin` initialization and the daemon service container, leading to "Incorrect password" errors during Web login.
|
||||
> For NAS environments, it is strongly recommended to replace named volumes with a host absolute path bind mount (e.g. `-v /share/Container/vocat/data:/opt/vocat/data` on QNAP) for both initialization and runtime to guarantee consistent SQLite database persistence.
|
||||
|
||||
### USB SIM readers
|
||||
|
||||
USB SIM readers use the Linux PC/SC service. The one-click installer installs
|
||||
@@ -197,6 +210,18 @@ managers. On Debian/Ubuntu, the equivalent manual setup is
|
||||
VoCat keeps the reader visible in the add-device dialog and reports the missing
|
||||
service or driver instead of silently hiding it.
|
||||
|
||||
### QMI command-line utilities
|
||||
|
||||
VoCat uses `qmicli` to verify that a QMI control channel is ready and
|
||||
`qmi-network` to manage packet-data sessions. The one-click installer installs
|
||||
and verifies the corresponding utilities automatically. For manual deployment,
|
||||
Debian/Ubuntu uses `apt install libqmi-utils`; Arch Linux uses
|
||||
`pacman -S libqmi`, and Alpine uses `apk add qmi-utils`.
|
||||
|
||||
`vocat doctor --repair-dji-qmi` checks for `qmicli` before changing any USB
|
||||
driver binding or asserting DTR. If the utility is unavailable, the command
|
||||
stops with an installation hint and leaves the current device state untouched.
|
||||
|
||||
## Configuration
|
||||
|
||||
Vocat reads an optional JSON configuration file from `VOCAT_CONFIG`, then applies `VOCAT_*` environment variables. Environment variables take precedence.
|
||||
|
||||
+3
-2
@@ -22,8 +22,9 @@ Usage:
|
||||
vocat without arguments would enter the menu).
|
||||
vocat version Print the build version and exit.
|
||||
vocat doctor Diagnose USB modem, AT, QMI, PC/SC and proxy UDP paths.
|
||||
Use --repair-dji-qmi on Linux to safely wake a factory-ID
|
||||
DJI/Baiwang 2ca3:4006 QMI interface without changing NV.
|
||||
Use --repair-dji-qmi on Linux to restore the factory-ID
|
||||
DJI/Baiwang 2ca3:4006 AT/QMI interface bindings and wake
|
||||
QMI without changing NV.
|
||||
vocat carrier import-ipcc [flags] FILE.ipcc
|
||||
Convert an Apple carrier bundle into a reviewable VoCat
|
||||
profile. Preview is the default; --install writes it to
|
||||
|
||||
+13
-10
@@ -33,14 +33,17 @@ type doctorReport struct {
|
||||
}
|
||||
|
||||
type djiQMIRepairResult struct {
|
||||
USBName string `json:"usb_name"`
|
||||
Interface string `json:"interface"`
|
||||
USBDevice string `json:"usb_device"`
|
||||
OriginalDriver string `json:"original_driver,omitempty"`
|
||||
ControlDevice string `json:"control_device"`
|
||||
NetworkInterface string `json:"network_interface,omitempty"`
|
||||
QMIProbe string `json:"qmi_probe"`
|
||||
Attempts int `json:"attempts"`
|
||||
USBName string `json:"usb_name"`
|
||||
Interface string `json:"interface"`
|
||||
USBDevice string `json:"usb_device"`
|
||||
OriginalDriver string `json:"original_driver,omitempty"`
|
||||
SerialInterfaces []string `json:"serial_interfaces,omitempty"`
|
||||
SerialDevices []string `json:"serial_devices,omitempty"`
|
||||
ATDevice string `json:"at_device,omitempty"`
|
||||
ControlDevice string `json:"control_device"`
|
||||
NetworkInterface string `json:"network_interface,omitempty"`
|
||||
QMIProbe string `json:"qmi_probe"`
|
||||
Attempts int `json:"attempts"`
|
||||
}
|
||||
|
||||
func runDoctor(args []string) error {
|
||||
@@ -49,7 +52,7 @@ func runDoctor(args []string) error {
|
||||
proxyAddress := flags.String("proxy", "", "SOCKS5 host:port to test")
|
||||
proxyUsername := flags.String("proxy-username", "", "SOCKS5 username")
|
||||
passwordEnv := flags.String("proxy-password-env", "VOCAT_DOCTOR_PROXY_PASSWORD", "environment variable containing the proxy password")
|
||||
repairDJI := flags.Bool("repair-dji-qmi", false, "rebind DJI 2ca3:4006 interface 4 to qmi_wwan and assert DTR (Linux/root only; no NV write)")
|
||||
repairDJI := flags.Bool("repair-dji-qmi", false, "bind DJI 2ca3:4006 interfaces 0-3 to option and interface 4 to qmi_wwan, then assert DTR (Linux/root only; no NV write)")
|
||||
jsonOutput := flags.Bool("json", false, "write machine-readable JSON")
|
||||
timeout := flags.Duration("timeout", 12*time.Second, "per-probe timeout")
|
||||
if err := flags.Parse(args); err != nil {
|
||||
@@ -79,7 +82,7 @@ func runDoctor(args []string) error {
|
||||
if err != nil {
|
||||
return fmt.Errorf("repair DJI QMI binding: %w", err)
|
||||
}
|
||||
add("dji_qmi_repair", "passed", "dji_qmi_dtr_asserted", "DJI interface 4 was bound to qmi_wwan after a transient CDC DTR assertion; modem NV and USB identity were not changed", result)
|
||||
add("dji_qmi_repair", "passed", "dji_usb_interfaces_repaired", "DJI serial interfaces 0-3 were bound to option and interface 4 to qmi_wwan after a transient CDC DTR assertion; modem NV and USB identity were not changed", result)
|
||||
}
|
||||
|
||||
candidates, discoverErr := modem.NewSystemDiscoverer().Discover(ctx)
|
||||
|
||||
+194
-37
@@ -19,9 +19,12 @@ import (
|
||||
)
|
||||
|
||||
const (
|
||||
djiVendorID = "2ca3"
|
||||
djiProductID = "4006"
|
||||
djiQMIIndex = 4
|
||||
djiVendorID = "2ca3"
|
||||
djiProductID = "4006"
|
||||
djiFirstSerialIndex = 0
|
||||
djiLastSerialIndex = 3
|
||||
djiATIndex = 2
|
||||
djiQMIIndex = 4
|
||||
)
|
||||
|
||||
type usbControlTransfer struct {
|
||||
@@ -35,8 +38,12 @@ type usbControlTransfer struct {
|
||||
}
|
||||
|
||||
func repairDJIQMI(ctx context.Context) (djiQMIRepairResult, error) {
|
||||
qmicli, err := exec.LookPath("qmicli")
|
||||
if err != nil {
|
||||
return djiQMIRepairResult{}, errors.New("qmicli is required to verify DJI QMI readiness; install libqmi-utils on Debian/Ubuntu/Fedora, libqmi on Arch Linux, or qmi-utils on Alpine")
|
||||
}
|
||||
return retryDJIQMI(ctx, 3, 500*time.Millisecond, func(attemptContext context.Context) (djiQMIRepairResult, error) {
|
||||
return repairDJIQMIAt(attemptContext, "/sys", "/dev")
|
||||
return repairDJIQMIAt(attemptContext, "/sys", "/dev", qmicli)
|
||||
})
|
||||
}
|
||||
|
||||
@@ -68,7 +75,7 @@ func retryDJIQMI(
|
||||
return result, fmt.Errorf("failed after %d DTR repair attempt(s): %w", result.Attempts, err)
|
||||
}
|
||||
|
||||
func repairDJIQMIAt(ctx context.Context, sysRoot, devRoot string) (result djiQMIRepairResult, returnErr error) {
|
||||
func repairDJIQMIAt(ctx context.Context, sysRoot, devRoot, qmicli string) (result djiQMIRepairResult, returnErr error) {
|
||||
usbRoot := filepath.Join(sysRoot, "bus", "usb", "devices")
|
||||
entries, err := os.ReadDir(usbRoot)
|
||||
if err != nil {
|
||||
@@ -105,20 +112,36 @@ func repairDJIQMIAt(ctx context.Context, sysRoot, devRoot string) (result djiQMI
|
||||
}
|
||||
result.USBDevice = filepath.Join(devRoot, "bus", "usb", fmt.Sprintf("%03d", busNumber), fmt.Sprintf("%03d", deviceNumber))
|
||||
|
||||
driversRoot := filepath.Join(sysRoot, "bus", "usb", "drivers")
|
||||
if err := ensureUSBDriverLoaded(ctx, driversRoot, "qmi_wwan", "qmi_wwan"); err != nil {
|
||||
return result, err
|
||||
}
|
||||
if err := ensureUSBDriverLoaded(ctx, driversRoot, "option", "option"); err != nil {
|
||||
return result, err
|
||||
}
|
||||
|
||||
// qmi_wwan's USB dynamic ID is device-wide. Leaving it installed makes it
|
||||
// probe every vendor-specific interface after a USBIP reconnect; on this DJI
|
||||
// composition that can turn interfaces 1-3 into bogus cdc-wdm devices and
|
||||
// remove the AT port. Remove it before detaching anything, then add it only
|
||||
// briefly below while interface 4 is the sole unbound interface.
|
||||
qmiDriverRoot := filepath.Join(driversRoot, "qmi_wwan")
|
||||
if err := removeDynamicUSBID(qmiDriverRoot, djiVendorID+" "+djiProductID); err != nil {
|
||||
return result, fmt.Errorf("remove broad DJI qmi_wwan dynamic ID: %w", err)
|
||||
}
|
||||
|
||||
serialInterfaces, serialDevices, atDevice, err := bindDJISerialInterfaces(ctx, sysRoot, devRoot, usbRoot, driversRoot, result.USBName)
|
||||
if err != nil {
|
||||
return result, err
|
||||
}
|
||||
result.SerialInterfaces = serialInterfaces
|
||||
result.SerialDevices = serialDevices
|
||||
result.ATDevice = atDevice
|
||||
|
||||
result.OriginalDriver = usbInterfaceDriver(interfacePath)
|
||||
if result.OriginalDriver != "" && result.OriginalDriver != "option" && result.OriginalDriver != "qmi_wwan" {
|
||||
return result, fmt.Errorf("refusing to replace unexpected interface driver %q", result.OriginalDriver)
|
||||
}
|
||||
driversRoot := filepath.Join(sysRoot, "bus", "usb", "drivers")
|
||||
if _, err := os.Stat(filepath.Join(driversRoot, "qmi_wwan")); err != nil {
|
||||
modprobe, lookErr := exec.LookPath("modprobe")
|
||||
if lookErr != nil {
|
||||
return result, errors.New("qmi_wwan is not loaded and modprobe is unavailable")
|
||||
}
|
||||
if output, loadErr := exec.CommandContext(ctx, modprobe, "qmi_wwan").CombinedOutput(); loadErr != nil {
|
||||
return result, fmt.Errorf("load qmi_wwan: %w: %s", loadErr, strings.TrimSpace(string(output)))
|
||||
}
|
||||
}
|
||||
|
||||
interfaceDetached := false
|
||||
restoreOriginal := func() {
|
||||
@@ -128,7 +151,10 @@ func repairDJIQMIAt(ctx context.Context, sysRoot, devRoot string) (result djiQMI
|
||||
if currentDriver := usbInterfaceDriver(interfacePath); currentDriver != "" {
|
||||
_ = writeSysfs(filepath.Join(driversRoot, currentDriver, "unbind"), result.Interface)
|
||||
}
|
||||
if result.OriginalDriver != "" {
|
||||
switch result.OriginalDriver {
|
||||
case "qmi_wwan":
|
||||
_ = bindDJIQMIInterface(qmiDriverRoot, interfacePath, result.Interface)
|
||||
case "option":
|
||||
_ = writeSysfs(filepath.Join(driversRoot, result.OriginalDriver, "bind"), result.Interface)
|
||||
}
|
||||
}
|
||||
@@ -147,20 +173,8 @@ func repairDJIQMIAt(ctx context.Context, sysRoot, devRoot string) (result djiQMI
|
||||
return result, err
|
||||
}
|
||||
|
||||
bindPath := filepath.Join(driversRoot, "qmi_wwan", "bind")
|
||||
if err := writeSysfs(bindPath, result.Interface); err != nil {
|
||||
newIDErr := writeSysfs(filepath.Join(driversRoot, "qmi_wwan", "new_id"), djiVendorID+" "+djiProductID)
|
||||
if newIDErr != nil && !errors.Is(newIDErr, syscall.EEXIST) {
|
||||
return result, fmt.Errorf("register DJI qmi_wwan dynamic ID after bind failure %v: %w", err, newIDErr)
|
||||
}
|
||||
if usbInterfaceDriver(interfacePath) != "qmi_wwan" {
|
||||
if retryErr := writeSysfs(bindPath, result.Interface); retryErr != nil {
|
||||
return result, fmt.Errorf("bind qmi_wwan to %s: %w", result.Interface, retryErr)
|
||||
}
|
||||
}
|
||||
}
|
||||
if driver := usbInterfaceDriver(interfacePath); driver != "qmi_wwan" {
|
||||
return result, fmt.Errorf("interface %s driver is %q after qmi_wwan bind", result.Interface, driver)
|
||||
if err := bindDJIQMIInterface(qmiDriverRoot, interfacePath, result.Interface); err != nil {
|
||||
return result, err
|
||||
}
|
||||
|
||||
deadline := time.Now().Add(2 * time.Second)
|
||||
@@ -178,25 +192,168 @@ func repairDJIQMIAt(ctx context.Context, sysRoot, devRoot string) (result djiQMI
|
||||
}
|
||||
time.Sleep(25 * time.Millisecond)
|
||||
}
|
||||
// The requested driver topology is now established. A later DMS timeout is
|
||||
// a QMI/USBIP readiness problem, so do not roll interface 4 back to option.
|
||||
interfaceDetached = false
|
||||
time.Sleep(250 * time.Millisecond)
|
||||
qmicli, err := exec.LookPath("qmicli")
|
||||
if err != nil {
|
||||
return result, errors.New("qmicli is required to verify DJI QMI readiness after DTR repair")
|
||||
}
|
||||
probeContext, cancelProbe := context.WithTimeout(ctx, 8*time.Second)
|
||||
output, probeErr := exec.CommandContext(probeContext, qmicli, "-d", result.ControlDevice, "--dms-get-operating-mode").CombinedOutput()
|
||||
probeContextErr := probeContext.Err()
|
||||
cancelProbe()
|
||||
result.QMIProbe = strings.TrimSpace(string(output))
|
||||
if probeErr != nil {
|
||||
if probeContext.Err() != nil {
|
||||
probeErr = errors.Join(probeErr, probeContext.Err())
|
||||
if probeContextErr != nil {
|
||||
probeErr = errors.Join(probeErr, probeContextErr)
|
||||
}
|
||||
return result, fmt.Errorf("DMS readiness check after DTR repair: %w: %s", probeErr, result.QMIProbe)
|
||||
}
|
||||
interfaceDetached = false
|
||||
return result, nil
|
||||
}
|
||||
|
||||
func bindDJIQMIInterface(driverRoot, interfacePath, interfaceName string) (returnErr error) {
|
||||
bindPath := filepath.Join(driverRoot, "bind")
|
||||
dynamicIDAdded := false
|
||||
defer func() {
|
||||
if dynamicIDAdded {
|
||||
removeErr := removeDynamicUSBID(driverRoot, djiVendorID+" "+djiProductID)
|
||||
if returnErr == nil && removeErr != nil {
|
||||
returnErr = fmt.Errorf("remove temporary DJI qmi_wwan dynamic ID: %w", removeErr)
|
||||
}
|
||||
}
|
||||
}()
|
||||
if err := writeSysfs(bindPath, interfaceName); err != nil {
|
||||
newIDErr := writeSysfs(filepath.Join(driverRoot, "new_id"), djiVendorID+" "+djiProductID)
|
||||
if newIDErr != nil && !errors.Is(newIDErr, syscall.EEXIST) {
|
||||
return fmt.Errorf("register DJI qmi_wwan dynamic ID after bind failure %v: %w", err, newIDErr)
|
||||
}
|
||||
dynamicIDAdded = true
|
||||
if usbInterfaceDriver(interfacePath) != "qmi_wwan" {
|
||||
if retryErr := writeSysfs(bindPath, interfaceName); retryErr != nil {
|
||||
return fmt.Errorf("bind qmi_wwan to %s: %w", interfaceName, retryErr)
|
||||
}
|
||||
}
|
||||
}
|
||||
if driver := usbInterfaceDriver(interfacePath); driver != "qmi_wwan" {
|
||||
return fmt.Errorf("interface %s driver is %q after qmi_wwan bind", interfaceName, driver)
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
func ensureUSBDriverLoaded(ctx context.Context, driversRoot, driverName, moduleName string) error {
|
||||
if _, err := os.Stat(filepath.Join(driversRoot, driverName)); err == nil {
|
||||
return nil
|
||||
} else if !os.IsNotExist(err) {
|
||||
return fmt.Errorf("inspect %s driver: %w", driverName, err)
|
||||
}
|
||||
modprobe, err := exec.LookPath("modprobe")
|
||||
if err != nil {
|
||||
return fmt.Errorf("%s is not loaded and modprobe is unavailable", driverName)
|
||||
}
|
||||
if output, loadErr := exec.CommandContext(ctx, modprobe, moduleName).CombinedOutput(); loadErr != nil {
|
||||
return fmt.Errorf("load %s: %w: %s", moduleName, loadErr, strings.TrimSpace(string(output)))
|
||||
}
|
||||
if _, err := os.Stat(filepath.Join(driversRoot, driverName)); err != nil {
|
||||
return fmt.Errorf("%s driver is unavailable after loading module %s: %w", driverName, moduleName, err)
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
func bindDJISerialInterfaces(
|
||||
ctx context.Context,
|
||||
sysRoot, devRoot, usbRoot, driversRoot, usbName string,
|
||||
) ([]string, []string, string, error) {
|
||||
interfaceNames := make([]string, 0, djiLastSerialIndex-djiFirstSerialIndex+1)
|
||||
interfacePaths := make([]string, 0, cap(interfaceNames))
|
||||
needsDynamicID := false
|
||||
for index := djiFirstSerialIndex; index <= djiLastSerialIndex; index++ {
|
||||
name := fmt.Sprintf("%s:1.%d", usbName, index)
|
||||
path := filepath.Join(usbRoot, name)
|
||||
if _, err := os.Stat(path); err != nil {
|
||||
return nil, nil, "", fmt.Errorf("DJI serial interface %s unavailable: %w", name, err)
|
||||
}
|
||||
driver := usbInterfaceDriver(path)
|
||||
if driver != "" && driver != "option" && driver != "qmi_wwan" {
|
||||
return nil, nil, "", fmt.Errorf("refusing to replace unexpected driver %q on %s", driver, name)
|
||||
}
|
||||
interfaceNames = append(interfaceNames, name)
|
||||
interfacePaths = append(interfacePaths, path)
|
||||
needsDynamicID = needsDynamicID || driver != "option"
|
||||
}
|
||||
|
||||
if needsDynamicID {
|
||||
// Detach every false QMI claim before option's new_id triggers probing.
|
||||
for index, path := range interfacePaths {
|
||||
if usbInterfaceDriver(path) != "qmi_wwan" {
|
||||
continue
|
||||
}
|
||||
if err := writeSysfs(filepath.Join(driversRoot, "qmi_wwan", "unbind"), interfaceNames[index]); err != nil {
|
||||
return nil, nil, "", fmt.Errorf("unbind qmi_wwan from serial interface %s: %w", interfaceNames[index], err)
|
||||
}
|
||||
}
|
||||
|
||||
optionSerialRoot := filepath.Join(sysRoot, "bus", "usb-serial", "drivers", "option1")
|
||||
if _, err := os.Stat(optionSerialRoot); err != nil {
|
||||
return nil, nil, "", fmt.Errorf("option USB-serial driver is unavailable: %w", err)
|
||||
}
|
||||
if err := writeSysfs(filepath.Join(optionSerialRoot, "new_id"), djiVendorID+" "+djiProductID); err != nil && !errors.Is(err, syscall.EEXIST) {
|
||||
return nil, nil, "", fmt.Errorf("register DJI option dynamic ID: %w", err)
|
||||
}
|
||||
|
||||
for index, path := range interfacePaths {
|
||||
if usbInterfaceDriver(path) == "option" {
|
||||
continue
|
||||
}
|
||||
if err := writeSysfs(filepath.Join(driversRoot, "option", "bind"), interfaceNames[index]); err != nil {
|
||||
return nil, nil, "", fmt.Errorf("bind option to %s: %w", interfaceNames[index], err)
|
||||
}
|
||||
}
|
||||
}
|
||||
for index, path := range interfacePaths {
|
||||
if driver := usbInterfaceDriver(path); driver != "option" {
|
||||
return nil, nil, "", fmt.Errorf("serial interface %s driver is %q after option bind", interfaceNames[index], driver)
|
||||
}
|
||||
}
|
||||
|
||||
deadline := time.Now().Add(2 * time.Second)
|
||||
serialDevices := make([]string, len(interfacePaths))
|
||||
for {
|
||||
complete := true
|
||||
for index, path := range interfacePaths {
|
||||
name := firstEntryName(path, "ttyUSB")
|
||||
if name == "" {
|
||||
complete = false
|
||||
continue
|
||||
}
|
||||
serialDevices[index] = filepath.Join(devRoot, name)
|
||||
}
|
||||
if complete {
|
||||
break
|
||||
}
|
||||
if err := ctx.Err(); err != nil {
|
||||
return nil, nil, "", err
|
||||
}
|
||||
if time.Now().After(deadline) {
|
||||
return nil, nil, "", fmt.Errorf("option bound but not all ttyUSB nodes appeared for %s", usbName)
|
||||
}
|
||||
time.Sleep(25 * time.Millisecond)
|
||||
}
|
||||
return interfaceNames, serialDevices, serialDevices[djiATIndex-djiFirstSerialIndex], nil
|
||||
}
|
||||
|
||||
func removeDynamicUSBID(driverRoot, id string) error {
|
||||
path := filepath.Join(driverRoot, "remove_id")
|
||||
if _, err := os.Stat(path); err != nil {
|
||||
if os.IsNotExist(err) {
|
||||
return nil
|
||||
}
|
||||
return err
|
||||
}
|
||||
if err := writeSysfs(path, id); err != nil && !errors.Is(err, syscall.ENODEV) && !errors.Is(err, syscall.ENOENT) {
|
||||
return err
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
func assertUSBDTR(devicePath string, interfaceIndex int) error {
|
||||
fd, err := unix.Open(devicePath, unix.O_RDWR|unix.O_CLOEXEC, 0)
|
||||
if err != nil {
|
||||
|
||||
@@ -5,8 +5,10 @@ package main
|
||||
import (
|
||||
"context"
|
||||
"errors"
|
||||
"fmt"
|
||||
"os"
|
||||
"path/filepath"
|
||||
"strings"
|
||||
"testing"
|
||||
"time"
|
||||
"unsafe"
|
||||
@@ -49,6 +51,75 @@ func TestWriteSysfsDoesNotCreateMissingPath(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
func TestRepairDJIQMIRequiresQMICLIBeforeUSBAccess(t *testing.T) {
|
||||
t.Setenv("PATH", t.TempDir())
|
||||
|
||||
_, err := repairDJIQMI(context.Background())
|
||||
if err == nil {
|
||||
t.Fatal("repairDJIQMI() unexpectedly succeeded without qmicli")
|
||||
}
|
||||
if !strings.Contains(err.Error(), "qmicli is required") || !strings.Contains(err.Error(), "libqmi-utils") {
|
||||
t.Fatalf("repairDJIQMI() error = %q, want an actionable qmicli prerequisite error", err)
|
||||
}
|
||||
if strings.Contains(err.Error(), "DTR repair attempt") || strings.Contains(err.Error(), "USB topology") {
|
||||
t.Fatalf("repairDJIQMI() touched the repair path before checking qmicli: %v", err)
|
||||
}
|
||||
}
|
||||
|
||||
func TestDJISerialInterfaceLayout(t *testing.T) {
|
||||
if djiFirstSerialIndex != 0 || djiLastSerialIndex != 3 || djiATIndex != 2 || djiQMIIndex != 4 {
|
||||
t.Fatalf(
|
||||
"DJI interface layout = serial %d-%d, AT %d, QMI %d; want serial 0-3, AT 2, QMI 4",
|
||||
djiFirstSerialIndex,
|
||||
djiLastSerialIndex,
|
||||
djiATIndex,
|
||||
djiQMIIndex,
|
||||
)
|
||||
}
|
||||
}
|
||||
|
||||
func TestBindDJISerialInterfacesAlreadyCorrect(t *testing.T) {
|
||||
root := t.TempDir()
|
||||
sysRoot := filepath.Join(root, "sys")
|
||||
devRoot := filepath.Join(root, "dev")
|
||||
usbRoot := filepath.Join(sysRoot, "bus", "usb", "devices")
|
||||
driversRoot := filepath.Join(sysRoot, "bus", "usb", "drivers")
|
||||
optionRoot := filepath.Join(driversRoot, "option")
|
||||
if err := os.MkdirAll(optionRoot, 0o755); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
for index := djiFirstSerialIndex; index <= djiLastSerialIndex; index++ {
|
||||
interfacePath := filepath.Join(usbRoot, fmt.Sprintf("1-1:1.%d", index))
|
||||
if err := os.MkdirAll(filepath.Join(interfacePath, fmt.Sprintf("ttyUSB%d", index)), 0o755); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if err := os.Symlink(optionRoot, filepath.Join(interfacePath, "driver")); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
}
|
||||
|
||||
interfaces, devices, atDevice, err := bindDJISerialInterfaces(
|
||||
context.Background(),
|
||||
sysRoot,
|
||||
devRoot,
|
||||
usbRoot,
|
||||
driversRoot,
|
||||
"1-1",
|
||||
)
|
||||
if err != nil {
|
||||
t.Fatalf("bindDJISerialInterfaces() error = %v", err)
|
||||
}
|
||||
if len(interfaces) != 4 || interfaces[2] != "1-1:1.2" {
|
||||
t.Fatalf("interfaces = %#v, want four interfaces with AT at 1-1:1.2", interfaces)
|
||||
}
|
||||
if len(devices) != 4 || devices[2] != filepath.Join(devRoot, "ttyUSB2") {
|
||||
t.Fatalf("devices = %#v, want four devices with AT at ttyUSB2", devices)
|
||||
}
|
||||
if atDevice != filepath.Join(devRoot, "ttyUSB2") {
|
||||
t.Fatalf("AT device = %q, want %q", atDevice, filepath.Join(devRoot, "ttyUSB2"))
|
||||
}
|
||||
}
|
||||
|
||||
func TestRetryDJIQMISucceedsAfterTransientFailures(t *testing.T) {
|
||||
attempts := 0
|
||||
result, err := retryDJIQMI(context.Background(), 3, time.Millisecond, func(context.Context) (djiQMIRepairResult, error) {
|
||||
|
||||
@@ -29,3 +29,29 @@ func TestInstallerValidatesDatabaseBeforeReplacingBinary(t *testing.T) {
|
||||
t.Fatal("installer replaces the current binary before validating database compatibility")
|
||||
}
|
||||
}
|
||||
|
||||
func TestInstallerProvidesRequiredQMIUtilities(t *testing.T) {
|
||||
scriptBytes, err := os.ReadFile("../../scripts/install.sh")
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
script := string(scriptBytes)
|
||||
for _, required := range []string{
|
||||
"install_qmi_support()",
|
||||
"command -v qmicli",
|
||||
"command -v qmi-network",
|
||||
"apt-get install -y libqmi-utils",
|
||||
"dnf install -y libqmi-utils",
|
||||
"pacman -Sy --noconfirm libqmi",
|
||||
"apk add --no-cache qmi-utils",
|
||||
"Could not install or find qmicli/qmi-network",
|
||||
} {
|
||||
if !strings.Contains(script, required) {
|
||||
t.Errorf("installer is missing required QMI handling %q", required)
|
||||
}
|
||||
}
|
||||
mainStart := strings.LastIndex(script, "# --- Main ")
|
||||
if mainStart < 0 || !strings.Contains(script[mainStart:], "install_qmi_support") {
|
||||
t.Error("installer does not install QMI utilities from its main path")
|
||||
}
|
||||
}
|
||||
|
||||
@@ -759,6 +759,7 @@ func newVoWiFiOrchestrator(
|
||||
"service_center_timestamp": message.ServiceCenterTimestamp,
|
||||
"raw_rpdu": message.RawRPDU,
|
||||
"raw_tpdu": message.RawTPDU,
|
||||
"decode_error": message.DecodeError,
|
||||
})
|
||||
partsTotal := 1
|
||||
if message.Concat != nil && message.Concat.Total > 0 {
|
||||
@@ -823,6 +824,31 @@ func newVoWiFiOrchestrator(
|
||||
// acknowledged, otherwise the SMSC will keep retransmitting it.
|
||||
return nil
|
||||
},
|
||||
OnUSSD: func(ctx context.Context, message ims.ReceivedUSSD) error {
|
||||
extra, _ := json.Marshal(map[string]any{
|
||||
"transport": "ims-ussd",
|
||||
"dcs": message.DCS,
|
||||
"call_id": message.CallID,
|
||||
"received_at": message.Timestamp,
|
||||
"raw_body": message.RawBody,
|
||||
})
|
||||
_, saveErr := database.SaveSMSMessage(ctx, store.SMSMessage{
|
||||
MessageID: message.MessageID,
|
||||
DeviceID: message.DeviceID,
|
||||
ModemIMEI: deviceConfig.ModemIMEI,
|
||||
IMSI: message.IMSI,
|
||||
Peer: message.From,
|
||||
Direction: "inbound",
|
||||
Body: message.Text,
|
||||
Timestamp: message.Timestamp,
|
||||
Status: "received",
|
||||
Source: "ims-ussd",
|
||||
PartsTotal: 1,
|
||||
Read: false,
|
||||
Extra: extra,
|
||||
})
|
||||
return saveErr
|
||||
},
|
||||
})
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("device %q IMS provider: %w", deviceConfig.ID, err)
|
||||
|
||||
@@ -53,6 +53,9 @@ services:
|
||||
|
||||
volumes:
|
||||
# SQLite database + persistent state.
|
||||
# Note for NAS (e.g. QNAP Container Station / Synology): replace named volume
|
||||
# with a host absolute path (e.g. /share/Container/vocat/data:/opt/vocat/data)
|
||||
# to avoid volume isolation issues between bootstrap-admin and runtime.
|
||||
- vocat-data:/opt/vocat/data
|
||||
# Required for modem, MHI/WWAN and PC/SC USB-reader discovery, including
|
||||
# devices added after the container starts.
|
||||
|
||||
@@ -185,6 +185,11 @@ Quectel USB المدعومة (معرّف الشركة المصنعة USB `2c7c`)
|
||||
|
||||
تُنشر صورة GHCR لـ `linux/amd64` و`linux/arm64`.
|
||||
|
||||
> [!TIP]
|
||||
> **ملاحظة حول النشر على NAS / QNAP Container Station**:
|
||||
> في أنظمة NAS مثل QNAP QTS / QuTS hero (Container Station)، قد تؤدي حسابات المشرفين المخصصة وآليات عزل وحدات التخزين إلى توجيه وحدات تخزين Docker المسماة (مثل `-v vocat-data:/opt/vocat/data`) إلى مسارات معزولة مختلفة بين أمر التهيئة `bootstrap-admin` وحاوية الخدمة الرئيسية، مما يتسبب في ظهور خطأ في كلمة المرور عند تسجيل الدخول عبر الويب.
|
||||
> بالنسبة لبيئات NAS، يوصى بشدة باستبدال وحدات التخزين المسماة بربط مسار مطلق على المضيف (مثل `-v /share/Container/vocat/data:/opt/vocat/data` على QNAP) لكل من التهيئة والتشغيل لضمان استمرارية متسقة لقاعدة بيانات SQLite.
|
||||
|
||||
## الإعدادات
|
||||
|
||||
يقرأ Vocat ملف إعدادات JSON اختياريًا من `VOCAT_CONFIG`، ثم يطبق متغيرات البيئة `VOCAT_*`. متغيرات البيئة لها الأولوية.
|
||||
|
||||
@@ -187,6 +187,11 @@ dispositivos o de conexión en caliente.
|
||||
|
||||
La imagen GHCR se publica para `linux/amd64` y `linux/arm64`.
|
||||
|
||||
> [!TIP]
|
||||
> **Nota sobre el despliegue en NAS / QNAP Container Station**:
|
||||
> En sistemas NAS como QNAP QTS / QuTS hero (Container Station), las cuentas de administrador personalizadas y el aislamiento de volúmenes pueden hacer que los volúmenes con nombre de Docker (ej. `-v vocat-data:/opt/vocat/data`) se resuelvan en rutas aisladas distintas entre la inicialización `bootstrap-admin` y el contenedor del servicio principal, provocando errores de contraseña incorrecta al iniciar sesión en la interfaz web.
|
||||
> En entornos NAS, se recomienda encarecidamente sustituir los volúmenes con nombre por un montaje bind con ruta absoluta del host (ej. `-v /share/Container/vocat/data:/opt/vocat/data` en QNAP) tanto para la inicialización como para la ejecución, garantizando la persistencia coherente de la base de datos SQLite.
|
||||
|
||||
## Configuración
|
||||
|
||||
Vocat lee un archivo de configuración JSON opcional desde `VOCAT_CONFIG` y luego aplica las variables de entorno `VOCAT_*`. Las variables de entorno tienen prioridad.
|
||||
|
||||
@@ -187,6 +187,11 @@ pas une découverte multi-périphériques ou à chaud complète.
|
||||
|
||||
L'image GHCR est publiée pour `linux/amd64` et `linux/arm64`.
|
||||
|
||||
> [!TIP]
|
||||
> **Note de déploiement NAS / QNAP Container Station** :
|
||||
> Sur les systèmes NAS tels que QNAP QTS / QuTS hero (Container Station), les comptes administrateurs personnalisés et les mécanismes d'isolation de volumes peuvent faire en sorte que les volumes nommés Docker (ex. `-v vocat-data:/opt/vocat/data`) soient résolus vers des chemins isolés différents entre l'initialisation unique `bootstrap-admin` et le conteneur de service principal, entraînant des erreurs de mot de passe incorrect sur l'interface Web.
|
||||
> Pour les environnements NAS, il est fortement recommandé de remplacer les volumes nommés par un montage bind avec chemin absolu de l'hôte (ex. `-v /share/Container/vocat/data:/opt/vocat/data` sur QNAP) pour l'initialisation et l'exécution afin de garantir une persistance cohérente de la base de données SQLite.
|
||||
|
||||
## Configuration
|
||||
|
||||
Vocat lit un fichier de configuration JSON optionnel depuis `VOCAT_CONFIG`, puis applique les variables d'environnement `VOCAT_*`. Les variables d'environnement ont la priorité.
|
||||
|
||||
@@ -169,6 +169,11 @@ docker run -d \
|
||||
|
||||
GHCR イメージは `linux/amd64` と `linux/arm64` 向けに公開されています。
|
||||
|
||||
> [!TIP]
|
||||
> **NAS / QNAP Container Station デプロイ時の注意点**:
|
||||
> QNAP QTS / QuTS hero (Container Station) などの NAS 環境では、非 root カスタム管理者権限とボリューム分離メカニズムにより、Docker の名前付きボリューム(例: `-v vocat-data:/opt/vocat/data`)を使用すると、初回の `bootstrap-admin` 初期化時とデーモン起動時で異なる隔離パスに書き込まれ、Web ログイン時にパスワードエラーとなる場合があります。
|
||||
> NAS 環境では、初期化と常駐コンテナの両方で名前付きボリュームの代わりにホストの絶対パスバインドマウント(例: QNAP の `-v /share/Container/vocat/data:/opt/vocat/data`)を使用することを推奨します。
|
||||
|
||||
## 設定
|
||||
|
||||
Vocat は `VOCAT_CONFIG` からオプションの JSON 設定ファイルを読み込み、次に `VOCAT_*` 環境変数を適用します。環境変数が優先されます。
|
||||
|
||||
@@ -186,6 +186,11 @@ TUN, настройки сети и устройств, добавленных
|
||||
|
||||
Образ GHCR публикуется для `linux/amd64` и `linux/arm64`.
|
||||
|
||||
> [!TIP]
|
||||
> **Примечание по развертыванию на NAS / QNAP Container Station**:
|
||||
> В системах NAS, таких как QNAP QTS / QuTS hero (Container Station), из-за нестандартных прав администратора и механизмов изоляции томов именованные тома Docker (например, `-v vocat-data:/opt/vocat/data`) могут разрешаться в разные изолированные пути между выполнением команды `bootstrap-admin` и основным контейнером службы, что приводит к ошибкам неверного пароля при входе через веб-интерфейс.
|
||||
> Для сред NAS настоятельно рекомендуется использовать монтирование с абсолютным путем хоста (например, `-v /share/Container/vocat/data:/opt/vocat/data` на QNAP) как для инициализации, так и для запуска службы, чтобы гарантировать согласованность базы данных SQLite.
|
||||
|
||||
## Конфигурация
|
||||
|
||||
Vocat читает необязательный JSON-файл конфигурации из `VOCAT_CONFIG`, затем применяет переменные окружения `VOCAT_*`. Переменные окружения имеют приоритет.
|
||||
|
||||
@@ -92,6 +92,13 @@ sudo bash install.sh 0.0.2
|
||||
|
||||
VoWiFi IMS 必须使用 Linux XFRM/IPsec。OpenWrt/Kwrt 上安装脚本会从当前固件自己的软件源尝试安装严格匹配的 `ip-full`、`kmod-ipsec`、`kmod-ipsec4/6`、`kmod-crypto-authenc`、AES-CBC 和 SHA1 组件。若软件源没有与当前内核匹配的模块,必须更换包含这些组件的固件,禁止强装其他内核版本的 kmod。
|
||||
|
||||
如果你的内核确实无法提供 XFRM/IPsec,且仅需要非 VoWiFi 功能(蜂窝短信、数据等),可在安装时加上 `--skip-vowifi-check`:
|
||||
|
||||
```bash
|
||||
curl -fsSL https://raw.githubusercontent.com/MengMengCode/VoCat/master/scripts/install.sh -o install.sh
|
||||
sudo bash install.sh --skip-vowifi-check
|
||||
```
|
||||
|
||||
安装程序会:
|
||||
|
||||
- 检测 `amd64`、`386`、`arm64` 或 `armv7` 架构;
|
||||
@@ -168,6 +175,11 @@ docker run -d \
|
||||
|
||||
GHCR 镜像发布为 `linux/amd64` 与 `linux/arm64`。
|
||||
|
||||
> [!TIP]
|
||||
> **NAS / 威联通 (QNAP Container Station) 部署说明**:
|
||||
> 在威联通等 NAS 系统的 Container Station 下部署时,由于系统的非 Root 自定义管理员权限与卷隔离机制,使用 Docker 命名卷(如 `-v vocat-data:/opt/vocat/data`)在执行一次性初始化 `bootstrap-admin` 和启动常驻服务时,两者的卷极易被解析至不同的隔离路径,导致 Web 端登录时提示密码错误。
|
||||
> 建议在 NAS 环境下部署时,将 `-v vocat-data:/opt/vocat/data` 替换为宿主机的绝对路径挂载(例如威联通上的 `-v /share/Container/vocat/data:/opt/vocat/data`),以确保初始化与运行期读写同一个 SQLite 数据库文件。
|
||||
|
||||
### USB SIM 读卡器
|
||||
|
||||
USB SIM 读卡器通过 Linux PC/SC 服务访问。一键安装脚本会在支持的软件包管理器上
|
||||
@@ -175,6 +187,16 @@ USB SIM 读卡器通过 Linux PC/SC 服务访问。一键安装脚本会在支
|
||||
`apt install pcscd libccid`。如果 USB 已识别 CCID 读卡器但 PC/SC 尚未就绪,
|
||||
VoCat 会继续在添加设备窗口显示该硬件,并明确提示缺少服务或驱动,不再静默隐藏。
|
||||
|
||||
### QMI 命令行工具
|
||||
|
||||
VoCat 使用 `qmicli` 验证 QMI 控制通道是否就绪,并使用 `qmi-network` 管理
|
||||
分组数据会话。一键安装脚本会自动安装并验证对应工具。手动部署时,
|
||||
Debian/Ubuntu 使用 `apt install libqmi-utils`;Arch Linux 使用
|
||||
`pacman -S libqmi`,Alpine 使用 `apk add qmi-utils`。
|
||||
|
||||
`vocat doctor --repair-dji-qmi` 会在修改 USB 驱动绑定或触发 DTR 之前检查
|
||||
`qmicli`。如果工具不可用,命令会给出安装提示并停止,保持设备当前状态不变。
|
||||
|
||||
## 配置
|
||||
|
||||
Vocat 先从 `VOCAT_CONFIG` 读取可选的 JSON 配置文件,再应用 `VOCAT_*` 环境变量。环境变量优先级更高。
|
||||
|
||||
@@ -169,6 +169,11 @@ docker run -d \
|
||||
|
||||
GHCR 映像發佈為 `linux/amd64` 與 `linux/arm64`。
|
||||
|
||||
> [!TIP]
|
||||
> **NAS / 威聯通 (QNAP Container Station) 部署說明**:
|
||||
> 在威聯通等 NAS 系統的 Container Station 下部署時,由於系統的非 Root 自訂管理員權限與磁碟區隔離機制,使用 Docker 具名磁碟區(如 `-v vocat-data:/opt/vocat/data`)在執行一次性初始化 `bootstrap-admin` 與啟動常駐服務時,兩者的磁碟區極易被解析至不同的隔離路徑,導致 Web 端登入時提示密碼錯誤。
|
||||
> 建議在 NAS 環境下部署時,將 `-v vocat-data:/opt/vocat/data` 替換為宿主機的絕對路徑掛載(例如威聯通上的 `-v /share/Container/vocat/data:/opt/vocat/data`),以確保初始化與執行期讀寫同一個 SQLite 資料庫檔案。
|
||||
|
||||
## 配置
|
||||
|
||||
Vocat 先從 `VOCAT_CONFIG` 讀取可選的 JSON 配置檔,再套用 `VOCAT_*` 環境變數。環境變數優先級更高。
|
||||
|
||||
@@ -1,383 +0,0 @@
|
||||
# 企业微信消息推送实现计划
|
||||
|
||||
> **面向 AI 代理的工作者:** 必需子技能:使用 superpowers:subagent-driven-development(推荐)或 superpowers:executing-plans 逐任务实现此计划。步骤使用复选框(`- [ ]`)语法来跟踪进度。
|
||||
|
||||
**目标:** 增加可配置 JSON 请求模板的企业微信 Webhook 通知通道,向新短信和自动任务结果发送消息。
|
||||
|
||||
**架构:** 新建专注的企业微信通知模块,统一构建事件变量、JSON 安全替换、Webhook POST 和 `errcode` 响应判定。设置 API 将 `wecom` 纳入白名单、保密 URL 与连通性测试;短信和自动任务分发器只增加该通道分支。前端在现有通知设置表单中新增企业微信页签和请求体编辑器。
|
||||
|
||||
**技术栈:** Go 1.25、标准库 `net/http` 与 `encoding/json`、SQLite 通知设置、React、TypeScript、Vite。
|
||||
|
||||
---
|
||||
|
||||
## 文件结构
|
||||
|
||||
- 创建:`internal/server/wecom_notification.go`,渲染企业微信 JSON 模板、创建安全 HTTP 请求并判定企业微信响应。
|
||||
- 创建:`internal/server/wecom_notification_test.go`,覆盖 JSON 转义、模板拒绝和企业微信响应失败。
|
||||
- 修改:`internal/server/settings_api.go`,登记 `wecom` 配置字段、启用连通性测试并调用企业微信发送器。
|
||||
- 修改:`internal/server/settings_api_test.go`,验证企业微信配置 API、敏感 URL 与测试路径。
|
||||
- 修改:`internal/store/settings.go`,将 `wecom.urls` 注册为敏感字段。
|
||||
- 修改:`internal/server/sms_notifications.go`,将新短信事件接入企业微信通道。
|
||||
- 修改:`internal/server/sms_notifications_test.go`,覆盖企业微信短信配置要求和变量数据。
|
||||
- 修改:`internal/server/automatic_task_notifications.go`,将自动任务结果接入企业微信通道。
|
||||
- 修改:`web/src/types.ts`,扩展通知设置类型。
|
||||
- 修改:`web/src/components/settings/model.ts`,增加企业微信表单、默认模板、读取和提交映射。
|
||||
- 修改:`web/src/components/settings/PushTabs.tsx`,新增企业微信配置界面。
|
||||
- 修改:`web/src/pages/SettingsPage.tsx`,增加页签、测试状态与测试请求。
|
||||
|
||||
### 任务 1:企业微信模板与响应判定
|
||||
|
||||
**文件:**
|
||||
- 创建:`internal/server/wecom_notification_test.go`
|
||||
- 创建:`internal/server/wecom_notification.go`
|
||||
|
||||
- [ ] **步骤 1:编写失败的模板与响应测试**
|
||||
|
||||
```go
|
||||
func TestRenderWecomPayloadEscapesTemplateValues(t *testing.T) {
|
||||
payload, err := renderWecomPayload(
|
||||
`{"msgtype":"text","text":{"content":{{message}},"number":{{number}}}}`,
|
||||
wecomTemplateValues{"message": "quote: \\"\\nline", "number": "+447386"},
|
||||
)
|
||||
if err != nil { t.Fatal(err) }
|
||||
if got := string(payload); got != `{"msgtype":"text","text":{"content":"quote: \\"\\nline","number":"+447386"}}` {
|
||||
t.Fatalf("payload = %s", got)
|
||||
}
|
||||
}
|
||||
|
||||
func TestRenderWecomPayloadRejectsUnknownVariableAndNonObject(t *testing.T) {
|
||||
for _, template := range []string{`{"text":{{unknown}}}`, `[]`} {
|
||||
if _, err := renderWecomPayload(template, wecomTemplateValues{}); err == nil {
|
||||
t.Fatalf("template %q was accepted", template)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func TestValidateWecomResponseRejectsProviderError(t *testing.T) {
|
||||
if err := validateWecomResponse(http.StatusOK, []byte(`{"errcode":40058,"errmsg":"invalid"}`)); !errors.Is(err, errProviderRejected) {
|
||||
t.Fatalf("error = %v", err)
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
- [ ] **步骤 2:运行测试验证失败**
|
||||
|
||||
运行:`go test ./internal/server -run 'TestRenderWecomPayload|TestValidateWecomResponse' -count=1`
|
||||
|
||||
预期:FAIL,提示 `renderWecomPayload`、`wecomTemplateValues` 和 `validateWecomResponse` 未定义。
|
||||
|
||||
- [ ] **步骤 3:实现最少的模板与响应代码**
|
||||
|
||||
在 `internal/server/wecom_notification.go` 中定义受支持变量列表,先用 `json.Marshal` 编码每个字符串,再替换精确的 `{{name}}` 标记;若保留任何 `{{` 或 `}}`,或者 `json.Unmarshal` 后不是非空 `map[string]json.RawMessage`,返回错误。响应处理必须要求 HTTP 2xx、可解析 JSON,且 `errcode` 为零。
|
||||
|
||||
```go
|
||||
type wecomTemplateValues map[string]string
|
||||
|
||||
func renderWecomPayload(template string, values wecomTemplateValues) ([]byte, error) {
|
||||
for _, name := range wecomTemplateVariableNames {
|
||||
encoded, _ := json.Marshal(values[name])
|
||||
template = strings.ReplaceAll(template, "{{"+name+"}}", string(encoded))
|
||||
}
|
||||
if strings.Contains(template, "{{") || strings.Contains(template, "}}") {
|
||||
return nil, errors.New("wecom.payload_template contains an unsupported variable")
|
||||
}
|
||||
var payload map[string]json.RawMessage
|
||||
if err := json.Unmarshal([]byte(template), &payload); err != nil || len(payload) == 0 {
|
||||
return nil, errors.New("wecom.payload_template must render to a non-empty JSON object")
|
||||
}
|
||||
return []byte(template), nil
|
||||
}
|
||||
|
||||
func validateWecomResponse(status int, body []byte) error {
|
||||
var result struct { ErrCode int `json:"errcode"` }
|
||||
if status < http.StatusOK || status >= http.StatusMultipleChoices || json.Unmarshal(body, &result) != nil || result.ErrCode != 0 {
|
||||
return fmt.Errorf("%w: WeCom response was not successful", errProviderRejected)
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
func wecomTestValues(now time.Time) wecomTemplateValues {
|
||||
return wecomTemplateValues{
|
||||
"event": "test", "title": "vocat", "message": "vocat notification test",
|
||||
"timestamp": now.UTC().Format(time.RFC3339),
|
||||
}
|
||||
}
|
||||
|
||||
func sendWecomNotification(ctx context.Context, config map[string]any, values wecomTemplateValues) error {
|
||||
payload, err := renderWecomPayload(configString(config, "payload_template"), values)
|
||||
if err != nil { return err }
|
||||
client, err := restrictedHTTPClient(ctx, 8*time.Second, "")
|
||||
if err != nil { return err }
|
||||
for _, destination := range configStrings(config, "urls") {
|
||||
parsed, err := validateOutboundURL(ctx, destination, false)
|
||||
if err != nil { return err }
|
||||
request, err := http.NewRequestWithContext(ctx, http.MethodPost, parsed.String(), bytes.NewReader(payload))
|
||||
if err != nil { return fmt.Errorf("create WeCom notification request: %w", err) }
|
||||
request.Header.Set("Content-Type", "application/json; charset=utf-8")
|
||||
request.Header.Set("User-Agent", "vocat-wecom-notification/1")
|
||||
response, err := client.Do(request)
|
||||
if err != nil { return fmt.Errorf("send WeCom notification: %w", err) }
|
||||
body, readErr := io.ReadAll(io.LimitReader(response.Body, 64<<10)); response.Body.Close()
|
||||
if readErr != nil { return fmt.Errorf("read WeCom response: %w", readErr) }
|
||||
if err := validateWecomResponse(response.StatusCode, body); err != nil { return err }
|
||||
}
|
||||
return nil
|
||||
}
|
||||
```
|
||||
|
||||
- [ ] **步骤 4:运行测试验证通过**
|
||||
|
||||
运行:`go test ./internal/server -run 'TestRenderWecomPayload|TestValidateWecomResponse' -count=1`
|
||||
|
||||
预期:PASS。
|
||||
|
||||
- [ ] **步骤 5:提交本任务**
|
||||
|
||||
运行:`git add internal/server/wecom_notification.go internal/server/wecom_notification_test.go && git commit -m "feat: add WeCom payload renderer"`
|
||||
|
||||
预期:创建包含模板渲染和响应判定的提交。若 Git 作者身份仍未配置,停止提交但保留已验证的工作区改动,不自行设置身份。
|
||||
|
||||
### 任务 2:设置 API 与敏感 Webhook URL
|
||||
|
||||
**文件:**
|
||||
- 修改:`internal/server/settings_api_test.go`
|
||||
- 修改:`internal/store/settings.go`
|
||||
- 修改:`internal/server/settings_api.go`
|
||||
|
||||
- [ ] **步骤 1:编写失败的 API 测试**
|
||||
|
||||
```go
|
||||
func TestWecomNotificationSettingsPreserveWebhookURLs(t *testing.T) {
|
||||
test := newSettingsAPITest(t)
|
||||
body := `{"wecom":{"enabled":true,"urls":["https://qyapi.weixin.qq.com/cgi-bin/webhook/send?key=secret"],"payload_template":"{\\\"msgtype\\\":\\\"text\\\",\\\"text\\\":{\\\"content\\\":{{message}}}}"}}`
|
||||
recorder := test.request(t, http.MethodPut, "/api/settings/notifications", body)
|
||||
if recorder.Code != http.StatusOK { t.Fatalf("status = %d", recorder.Code) }
|
||||
if bytes.Contains(recorder.Body.Bytes(), []byte("key=secret")) { t.Fatal("response leaked webhook URL") }
|
||||
stored, err := test.database.NotificationSetting(context.Background(), "wecom")
|
||||
if err != nil || !bytes.Contains(stored.Config, []byte("key=secret")) { t.Fatalf("stored = %s, err = %v", stored.Config, err) }
|
||||
}
|
||||
|
||||
func TestWecomNotificationSettingsRejectMalformedTemplate(t *testing.T) {
|
||||
test := newSettingsAPITest(t)
|
||||
recorder := test.request(t, http.MethodPut, "/api/settings/notifications", `{"wecom":{"enabled":true,"urls":["https://qyapi.weixin.qq.com/cgi-bin/webhook/send?key=x"],"payload_template":"[]"}}`)
|
||||
if recorder.Code != http.StatusBadRequest { t.Fatalf("status = %d", recorder.Code) }
|
||||
}
|
||||
```
|
||||
|
||||
- [ ] **步骤 2:运行测试验证失败**
|
||||
|
||||
运行:`go test ./internal/server -run 'TestWecomNotificationSettings' -count=1`
|
||||
|
||||
预期:FAIL,设置 API 返回 `invalid_notification_channel`。
|
||||
|
||||
- [ ] **步骤 3:实现 API 契约、保存和测试端点**
|
||||
|
||||
在 `notificationChannels` 中加入 `wecom`,在 `notificationFields` 中登记 `urls: strings` 和 `payload_template: wecom_template`。将 `urls` 加入 `DefaultNotificationSensitiveFields("wecom")`。在字段验证中对 `wecom_template` 调用 `renderWecomPayload`,以默认测试变量确认模板会生成对象;在 `validateNotificationTestConfig`、`handleNotificationTest` 和发送分支中支持 `wecom`。
|
||||
|
||||
```go
|
||||
"wecom": {"urls": "strings", "payload_template": "wecom_template"},
|
||||
|
||||
case "wecom":
|
||||
return []string{"urls"}
|
||||
|
||||
case "wecom":
|
||||
err = sendWecomNotificationTest(r.Context(), resolved)
|
||||
```
|
||||
|
||||
将上段 `payload_template` 的字段类型实现为 `wecom_template`,避免只按普通字符串检查:
|
||||
|
||||
```go
|
||||
case "wecom_template":
|
||||
var template string
|
||||
if err := json.Unmarshal(raw, &template); err != nil || len(template) > 32768 {
|
||||
return fmt.Errorf("%s must be a template string", field)
|
||||
}
|
||||
_, err := renderWecomPayload(template, wecomTestValues(time.Unix(0, 0)))
|
||||
return err
|
||||
|
||||
case "wecom":
|
||||
if len(configStrings(config, "urls")) == 0 || configString(config, "payload_template") == "" {
|
||||
return errors.New("wecom.urls and wecom.payload_template are required")
|
||||
}
|
||||
```
|
||||
|
||||
测试消息的变量必须为 `event: "test"`、`title: "vocat"`、`message: "vocat notification test"` 和当前 UTC RFC3339 时间;它应经过与生产消息完全相同的渲染和发送路径。
|
||||
|
||||
- [ ] **步骤 4:运行测试验证通过**
|
||||
|
||||
运行:`go test ./internal/server -run 'TestWecomNotificationSettings|TestNotificationSettingsAlwaysReturns' -count=1`
|
||||
|
||||
预期:PASS,GET/PUT 响应不会泄露 `key`,但数据库保留原 URL。
|
||||
|
||||
- [ ] **步骤 5:提交本任务**
|
||||
|
||||
运行:`git add internal/server/settings_api.go internal/server/settings_api_test.go internal/store/settings.go && git commit -m "feat: configure WeCom notifications"`
|
||||
|
||||
预期:创建设置 API 与敏感配置提交;作者身份未配置时遵循任务 1 的处理方式。
|
||||
|
||||
### 任务 3:接入短信与自动任务分发
|
||||
|
||||
**文件:**
|
||||
- 修改:`internal/server/sms_notifications_test.go`
|
||||
- 修改:`internal/server/sms_notifications.go`
|
||||
- 修改:`internal/server/automatic_task_notifications.go`
|
||||
|
||||
- [ ] **步骤 1:编写失败的事件变量测试**
|
||||
|
||||
```go
|
||||
func TestWecomSMSValuesIncludeRenderedSMSFields(t *testing.T) {
|
||||
message := smsNotification{DeviceID: "device-1", DeviceName: "客厅", DeviceLabel: "EC20", Number: "+447386", Time: time.Unix(1700000000, 0), Content: "hello"}
|
||||
values := wecomSMSValues(message)
|
||||
if values["event"] != "sms.received" || values["content"] != "hello" || values["device_label"] != "EC20" {
|
||||
t.Fatalf("values = %#v", values)
|
||||
}
|
||||
}
|
||||
|
||||
func TestWecomAutomaticTaskValuesLeaveSMSFieldsEmpty(t *testing.T) {
|
||||
values := wecomAutomaticTaskValues(automaticTaskNotification{Title: "自动任务执行成功", Text: "任务已完成", Time: time.Unix(1700000000, 0)})
|
||||
if values["event"] != "automatic_task.completed" || values["message"] != "任务已完成" || values["number"] != "" {
|
||||
t.Fatalf("values = %#v", values)
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
- [ ] **步骤 2:运行测试验证失败**
|
||||
|
||||
运行:`go test ./internal/server -run 'TestWecomSMSValues|TestWecomAutomaticTaskValues' -count=1`
|
||||
|
||||
预期:FAIL,两个事件变量构建函数未定义。
|
||||
|
||||
- [ ] **步骤 3:实现分发接入**
|
||||
|
||||
在企业微信模块中实现 `wecomSMSValues` 和 `wecomAutomaticTaskValues`,填充全部已声明变量,短信专属字段在自动任务事件中设为空字符串。然后将 `wecom` 加入以下分发列表与 switch:
|
||||
|
||||
```go
|
||||
var smsOnlyNotificationChannels = []string{"bark", "email", "pushplus", "webhook", "wecom"}
|
||||
|
||||
case "wecom":
|
||||
return sendWecomNotification(ctx, config, wecomSMSValues(message))
|
||||
```
|
||||
|
||||
```go
|
||||
channels := []string{"telegram", "bark", "email", "pushplus", "webhook", "wecom"}
|
||||
for _, channel := range channels {
|
||||
setting, err := s.store.NotificationSetting(ctx, channel)
|
||||
if errors.Is(err, store.ErrNotFound) || (err == nil && !setting.Enabled) { continue }
|
||||
if err != nil { s.logger.Warn("read automatic task notification setting", "channel", channel, "error", err); continue }
|
||||
var config map[string]any
|
||||
if err := json.Unmarshal(setting.Config, &config); err != nil { s.logger.Warn("decode automatic task notification setting", "channel", channel, "error", err); continue }
|
||||
if err := sendAutomaticTaskNotification(ctx, channel, config, notification); err != nil { s.logger.Warn("send automatic task notification", "channel", channel, "task_id", task.ID, "error", err) }
|
||||
}
|
||||
|
||||
case "wecom":
|
||||
return sendWecomNotification(ctx, config, wecomAutomaticTaskValues(message))
|
||||
```
|
||||
|
||||
保持既有游标、错误限流日志和其他通道的行为不变。
|
||||
|
||||
- [ ] **步骤 4:运行测试验证通过**
|
||||
|
||||
运行:`go test ./internal/server -run 'TestWecomSMSValues|TestWecomAutomaticTaskValues|TestValidateSMSNotificationConfig' -count=1`
|
||||
|
||||
预期:PASS,`validateSMSNotificationConfig` 也接受包含有效 URL 和模板的 `wecom` 配置。
|
||||
|
||||
- [ ] **步骤 5:提交本任务**
|
||||
|
||||
运行:`git add internal/server/wecom_notification.go internal/server/sms_notifications.go internal/server/sms_notifications_test.go internal/server/automatic_task_notifications.go && git commit -m "feat: dispatch WeCom notifications"`
|
||||
|
||||
预期:创建两类事件分发接入提交;作者身份未配置时遵循任务 1 的处理方式。
|
||||
|
||||
### 任务 4:企业微信配置界面
|
||||
|
||||
**文件:**
|
||||
- 修改:`web/src/types.ts`
|
||||
- 修改:`web/src/components/settings/model.ts`
|
||||
- 修改:`web/src/components/settings/PushTabs.tsx`
|
||||
- 修改:`web/src/pages/SettingsPage.tsx`
|
||||
|
||||
- [ ] **步骤 1:扩展前端类型和表单映射**
|
||||
|
||||
在 `NotificationSettings` 与 `NotifyForms` 中增加 `wecom`。新增以下表单类型和默认请求体;URL 数组保持一项一个输入行的既有 `UrlListEditor` 约定。
|
||||
|
||||
```ts
|
||||
export interface WecomForm {
|
||||
enabled: boolean;
|
||||
urls: string[];
|
||||
payloadTemplate: string;
|
||||
}
|
||||
|
||||
const DEFAULT_WECOM_PAYLOAD_TEMPLATE = `{
|
||||
"msgtype": "text",
|
||||
"text": { "content": {{message}} }
|
||||
}`;
|
||||
```
|
||||
|
||||
`formsFromNotifications` 读取 `payload_template`,`buildNotificationsPayload` 输出 `payload_template`,测试请求则修剪并移除空 URL。
|
||||
|
||||
- [ ] **步骤 2:实现企业微信页签与测试请求**
|
||||
|
||||
在 `PushTabs.tsx` 增加 `WecomTab`,显示启用开关、`UrlListEditor`、JSON `Textarea` 和变量说明。URL 列表文案必须明确“每个 Webhook URL 单独一行,点击添加 URL 增加”,不得提示使用分隔符。
|
||||
|
||||
```tsx
|
||||
<Field label={t("JSON 请求体模板")} hint={<span>变量必须作为 JSON 值使用,例如 <code>{'{{message}}'}</code>。</span>}>
|
||||
<Textarea value={value.payloadTemplate} onChange={(event) => onChange({ payloadTemplate: event.target.value })} disabled={off} rows={12} />
|
||||
</Field>
|
||||
```
|
||||
|
||||
在 `SettingsPage.tsx` 增加 `testingWecom`、`onTestWecom`、企业微信页签与组件渲染。测试请求使用 `POST /settings/notifications/wecom/test` 和企业微信表单 payload;成功与失败消息沿用现有通知测试模式。
|
||||
|
||||
- [ ] **步骤 3:运行前端构建验证**
|
||||
|
||||
运行:`npm run build`
|
||||
|
||||
工作目录:`web`
|
||||
|
||||
预期:Vite 类型检查与生产构建均以退出码 0 完成。
|
||||
|
||||
- [ ] **步骤 4:提交本任务**
|
||||
|
||||
运行:`git add web/src/types.ts web/src/components/settings/model.ts web/src/components/settings/PushTabs.tsx web/src/pages/SettingsPage.tsx && git commit -m "feat: add WeCom notification settings"`
|
||||
|
||||
预期:创建企业微信设置 UI 提交;作者身份未配置时遵循任务 1 的处理方式。
|
||||
|
||||
### 任务 5:完整验证
|
||||
|
||||
**文件:**
|
||||
- 修改:`internal/server/wecom_notification.go`
|
||||
- 修改:`internal/server/wecom_notification_test.go`
|
||||
- 修改:`internal/server/settings_api.go`
|
||||
- 修改:`internal/server/settings_api_test.go`
|
||||
- 修改:`internal/store/settings.go`
|
||||
- 修改:`internal/server/sms_notifications.go`
|
||||
- 修改:`internal/server/sms_notifications_test.go`
|
||||
- 修改:`internal/server/automatic_task_notifications.go`
|
||||
- 修改:`web/src/types.ts`
|
||||
- 修改:`web/src/components/settings/model.ts`
|
||||
- 修改:`web/src/components/settings/PushTabs.tsx`
|
||||
- 修改:`web/src/pages/SettingsPage.tsx`
|
||||
|
||||
- [ ] **步骤 1:格式化 Go 代码**
|
||||
|
||||
运行:`gofmt -w internal/server/wecom_notification.go internal/server/wecom_notification_test.go internal/server/settings_api.go internal/server/settings_api_test.go internal/server/sms_notifications.go internal/server/sms_notifications_test.go internal/server/automatic_task_notifications.go internal/store/settings.go`
|
||||
|
||||
预期:所有修改的 Go 文件采用项目标准格式。
|
||||
|
||||
- [ ] **步骤 2:运行前端生产构建**
|
||||
|
||||
运行:`npm run build`
|
||||
|
||||
工作目录:`web`
|
||||
|
||||
预期:退出码 0,并生成 `web/dist` 供 Go 的嵌入资源使用。
|
||||
|
||||
- [ ] **步骤 3:运行后端回归测试**
|
||||
|
||||
运行:`go test ./...`
|
||||
|
||||
预期:所有目标包通过,无失败测试;`cmd/vocat` 和 `web` 包从步骤 2 生成的 `web/dist` 读取嵌入资源。
|
||||
|
||||
- [ ] **步骤 4:检查最终变更**
|
||||
|
||||
运行:`git diff --check && git status --short`
|
||||
|
||||
预期:无空白错误;变更仅限企业微信通知、其测试与设计/计划文档。
|
||||
@@ -1,55 +0,0 @@
|
||||
# 企业微信消息推送设计
|
||||
|
||||
## 目标
|
||||
|
||||
新增独立的 `wecom` 通知通道,通过企业微信“消息推送(原群机器人)”Webhook 推送新收到的短信和自动任务执行结果。外部 API 契约与既有通知通道保持一致。
|
||||
|
||||
## 配置模型
|
||||
|
||||
`wecom` 配置包含:
|
||||
|
||||
- `enabled`:是否启用通道。
|
||||
- `urls`:一个或多个企业微信消息推送 Webhook URL。Web 设置页将每个 URL
|
||||
显示为独立输入行,通过“添加 URL”按钮新增输入行、通过删除按钮移除输入行;
|
||||
不使用逗号、空格或换行分隔多个 URL。
|
||||
- `payload_template`:完整 JSON 请求体模板。
|
||||
|
||||
Webhook URL 含有企业微信访问密钥,必须作为敏感配置存储、在读取接口中脱敏,并在日志和错误信息中避免泄露。URL 沿用现有出站 URL 校验与 SSRF 防护。
|
||||
|
||||
## 模板语义
|
||||
|
||||
用户在 Web 设置页编辑完整 JSON 请求体,以选择企业微信支持的任意消息格式,例如 `text`、`markdown`、`news` 或 `template_card`。
|
||||
|
||||
模板变量仅能作为 JSON 值出现,服务端使用 JSON 编码后的字符串替换,调用方不得在变量外添加引号。示例:
|
||||
|
||||
```json
|
||||
{
|
||||
"msgtype": "text",
|
||||
"text": {
|
||||
"content": {{message}}
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
可用变量:
|
||||
|
||||
- 通用:`{{event}}`、`{{title}}`、`{{message}}`、`{{timestamp}}`。
|
||||
- 短信事件:`{{content}}`、`{{number}}`、`{{device_id}}`、`{{device_name}}`、`{{device_label}}`、`{{time}}`。
|
||||
|
||||
自动任务使用通用变量;短信专属变量在自动任务中替换为空字符串。模板渲染后必须为非空 JSON 对象,不得保留模板变量;无效模板在保存和测试时拒绝。
|
||||
|
||||
## 发送流程
|
||||
|
||||
短信分发器为 `wecom` 维护独立游标,发送失败不会阻塞其他通知渠道。自动任务完成后,和 Telegram、Bark、邮件、PushPlus、通用 Webhook 一样,向已启用的 `wecom` 通道发送结果。
|
||||
|
||||
发送器逐一 POST 渲染后的 JSON 到所有配置 URL,使用现有受限 HTTP 客户端。除 HTTP 2xx 外,企业微信返回 JSON 的 `errcode` 非零也视为服务商拒绝。
|
||||
|
||||
## Web 与 API
|
||||
|
||||
设置 API 将 `wecom` 加入已知通道和配置字段白名单,并提供 `POST /api/settings/notifications/wecom/test`。Web 设置页新增“企业微信”页签、启用开关、逐行编辑的 Webhook URL 列表、JSON 模板编辑器和测试按钮。
|
||||
|
||||
默认模板使用 `text` 消息,发送一条可辨识的测试内容。
|
||||
|
||||
## 验证
|
||||
|
||||
后端测试覆盖:配置字段验证、模板的 JSON 转义和拒绝无效模板、企业微信请求载荷、非零 `errcode` 失败处理、通知设置 API 读写与敏感 Webhook URL 保留。前端构建用于验证新增表单与类型契约。
|
||||
@@ -0,0 +1,15 @@
|
||||
-----BEGIN CERTIFICATE-----
|
||||
MIICSTCCAe+gAwIBAgIQbmhWeneg7nyF7hg5Y9+qejAKBggqhkjOPQQDAjBEMRgw
|
||||
FgYDVQQKEw9HU00gQXNzb2NpYXRpb24xKDAmBgNVBAMTH0dTTSBBc3NvY2lhdGlv
|
||||
biAtIFJTUDIgUm9vdCBDSTEwIBcNMTcwMjIyMDAwMDAwWhgPMjA1MjAyMjEyMzU5
|
||||
NTlaMEQxGDAWBgNVBAoTD0dTTSBBc3NvY2lhdGlvbjEoMCYGA1UEAxMfR1NNIEFz
|
||||
c29jaWF0aW9uIC0gUlNQMiBSb290IENJMTBZMBMGByqGSM49AgEGCCqGSM49AwEH
|
||||
A0IABJ1qutL0HCMX52GJ6/jeibsAqZfULWj/X10p/Min6seZN+hf5llovbCNuB2n
|
||||
unLz+O8UD0SUCBUVo8e6n9X1TuajgcAwgb0wDgYDVR0PAQH/BAQDAgEGMA8GA1Ud
|
||||
EwEB/wQFMAMBAf8wEwYDVR0RBAwwCogIKwYBBAGC6WAwFwYDVR0gAQH/BA0wCzAJ
|
||||
BgdngRIBAgEAME0GA1UdHwRGMEQwQqBAoD6GPGh0dHA6Ly9nc21hLWNybC5zeW1h
|
||||
dXRoLmNvbS9vZmZsaW5lY2EvZ3NtYS1yc3AyLXJvb3QtY2kxLmNybDAdBgNVHQ4E
|
||||
FgQUgTcPUSXQsdQI1MOyMubSXnlb6/swCgYIKoZIzj0EAwIDSAAwRQIgIJdYsOMF
|
||||
WziPK7l8nh5mu0qiRiVf25oa9ullG/OIASwCIQDqCmDrYf+GziHXBOiwJwnBaeBO
|
||||
aFsiLzIEOaUuZwdNUw==
|
||||
-----END CERTIFICATE-----
|
||||
+32
-1
@@ -3,6 +3,7 @@ package device
|
||||
import (
|
||||
"bytes"
|
||||
"context"
|
||||
"crypto/x509"
|
||||
"encoding/base64"
|
||||
"encoding/json"
|
||||
"errors"
|
||||
@@ -14,9 +15,24 @@ import (
|
||||
"strings"
|
||||
"time"
|
||||
|
||||
_ "embed"
|
||||
|
||||
"vocat/internal/netguard"
|
||||
)
|
||||
|
||||
// GSM Association RSP2 Root CI1; SHA-256 fingerprint:
|
||||
// 5E:3E:91:FD:45:43:27:C3:AF:5D:32:A7:A7:3B:BC:59:FE:43:AA:7D:85:FD:32:D5:DB:44:42:3F:80:A5:6B:B3.
|
||||
//
|
||||
//go:embed certs/gsma-rsp2-root-ci1.pem
|
||||
var gsmaRSP2RootCI1PEM []byte
|
||||
|
||||
var gsmaRSP2RootCI1SHA256 = [32]byte{
|
||||
0x5e, 0x3e, 0x91, 0xfd, 0x45, 0x43, 0x27, 0xc3,
|
||||
0xaf, 0x5d, 0x32, 0xa7, 0xa7, 0x3b, 0xbc, 0x59,
|
||||
0xfe, 0x43, 0xaa, 0x7d, 0x85, 0xfd, 0x32, 0xd5,
|
||||
0xdb, 0x44, 0x42, 0x3f, 0x80, 0xa5, 0x6b, 0xb3,
|
||||
}
|
||||
|
||||
// es9pClient speaks SGP.22 ES9+ — JSON over HTTPS — to one SM-DP+. It is the
|
||||
// network half of the LPA download flow: the host authenticates nothing itself
|
||||
// (the eUICC does all certificate verification on-card); it only shuttles the
|
||||
@@ -50,13 +66,28 @@ func newES9PClient(ctx context.Context, smdp string) (*es9pClient, error) {
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("esim: unsafe SM-DP+ address: %w", err)
|
||||
}
|
||||
roots, err := es9pRootCAs()
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
return &es9pClient{
|
||||
smdp: validated.Host,
|
||||
endpoint: validated,
|
||||
http: netguard.NewPublicHTTPClient(90*time.Second, true),
|
||||
http: netguard.NewPublicHTTPClientWithRootCAs(90*time.Second, true, roots),
|
||||
}, nil
|
||||
}
|
||||
|
||||
func es9pRootCAs() (*x509.CertPool, error) {
|
||||
roots, err := x509.SystemCertPool()
|
||||
if err != nil || roots == nil {
|
||||
roots = x509.NewCertPool()
|
||||
}
|
||||
if !roots.AppendCertsFromPEM(gsmaRSP2RootCI1PEM) {
|
||||
return nil, errors.New("esim: load GSMA RSP2 Root CI1 certificate")
|
||||
}
|
||||
return roots, nil
|
||||
}
|
||||
|
||||
// es9pError is a failed ES9+ functionExecutionStatus. Message is the SM-DP+'s
|
||||
// own explanation (surfaced verbatim, as the reference implementation does).
|
||||
type es9pError struct {
|
||||
|
||||
@@ -3,8 +3,11 @@ package device
|
||||
import (
|
||||
"bytes"
|
||||
"context"
|
||||
"crypto/sha256"
|
||||
"crypto/x509"
|
||||
"encoding/base64"
|
||||
"encoding/json"
|
||||
"encoding/pem"
|
||||
"net/http"
|
||||
"net/http/httptest"
|
||||
"net/url"
|
||||
@@ -12,6 +15,30 @@ import (
|
||||
"testing"
|
||||
)
|
||||
|
||||
func TestES9PRootCAsIncludeGSMARSP2RootCI1(t *testing.T) {
|
||||
roots, err := es9pRootCAs()
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
block, _ := pem.Decode(gsmaRSP2RootCI1PEM)
|
||||
if block == nil {
|
||||
t.Fatal("GSMA Root CI1 PEM did not decode")
|
||||
}
|
||||
certificate, err := x509.ParseCertificate(block.Bytes)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if actual := sha256.Sum256(certificate.Raw); actual != gsmaRSP2RootCI1SHA256 {
|
||||
t.Fatalf("GSMA root SHA-256 = %X, want %X", actual, gsmaRSP2RootCI1SHA256)
|
||||
}
|
||||
if certificate.Subject.CommonName != "GSM Association - RSP2 Root CI1" || !certificate.IsCA {
|
||||
t.Fatalf("unexpected GSMA root certificate: subject=%q ca=%v", certificate.Subject.CommonName, certificate.IsCA)
|
||||
}
|
||||
if _, err := certificate.Verify(x509.VerifyOptions{Roots: roots}); err != nil {
|
||||
t.Fatalf("GSMA root is not trusted by the ES9+ pool: %v", err)
|
||||
}
|
||||
}
|
||||
|
||||
// newTestES9P routes an es9pClient at a throwaway TLS server.
|
||||
func newTestES9P(t *testing.T, handler http.HandlerFunc) *es9pClient {
|
||||
t.Helper()
|
||||
|
||||
@@ -548,6 +548,14 @@ func decodeGSM7(septets []byte) (string, error) {
|
||||
return result.String(), nil
|
||||
}
|
||||
|
||||
// DecodeGSM7Septets decodes a GSM 7-bit default-alphabet string whose septets
|
||||
// are stored one code per byte (the form USSI bodies use when DCS=0x0F). It
|
||||
// returns the decoded text and ok=false if a code is out of range.
|
||||
func DecodeGSM7Septets(data string) (string, bool) {
|
||||
decoded, err := decodeGSM7([]byte(data))
|
||||
return decoded, err == nil
|
||||
}
|
||||
|
||||
type pduCursor struct {
|
||||
data []byte
|
||||
index int
|
||||
@@ -758,13 +766,29 @@ func readTPAddress(cursor *pduCursor) (string, error) {
|
||||
if err != nil {
|
||||
return "", err
|
||||
}
|
||||
byteCount := (int(length) + 1) / 2
|
||||
var byteCount int
|
||||
var septetCount int
|
||||
if toa&0x70 == 0x50 {
|
||||
// 3GPP TS 23.040 §9.1.2.5: For alphanumeric addresses, the length field
|
||||
// indicates the number of useful semi-octets (i.e. characters * 7 / 4, rounded up).
|
||||
// The number of characters is (length * 4) / 7 and byte count is (length + 1) / 2.
|
||||
// However, some non-standard sources specify length as the direct count of septets
|
||||
// (e.g. length=4 for 4 chars, which needs 4 bytes instead of (4+1)/2=2 bytes).
|
||||
if length >= 7 {
|
||||
byteCount = (int(length) + 1) / 2
|
||||
septetCount = int(length) * 4 / 7
|
||||
} else {
|
||||
byteCount = (int(length)*7 + 7) / 8
|
||||
septetCount = int(length)
|
||||
}
|
||||
} else {
|
||||
byteCount = (int(length) + 1) / 2
|
||||
}
|
||||
value, err := cursor.bytes(byteCount)
|
||||
if err != nil {
|
||||
return "", err
|
||||
}
|
||||
if toa&0x70 == 0x50 {
|
||||
septetCount := int(length) * 4 / 7
|
||||
septets, unpackErr := unpackSeptets(value, septetCount, 0)
|
||||
if unpackErr != nil {
|
||||
return "", unpackErr
|
||||
@@ -852,7 +876,13 @@ func decodeUserData(
|
||||
message.Text = string(utf16.Decode(units))
|
||||
return nil
|
||||
default:
|
||||
// 8-bit (binary) user data has no portable text representation, so the
|
||||
// raw payload bytes are rendered as uppercase hexadecimal after the user
|
||||
// data header is stripped. This keeps the bubble non-empty and gives a
|
||||
// faithful rendering of the delivered content rather than a blank "".
|
||||
message.Encoding = SMSEncoding8BitPDU
|
||||
payload := data[headerBytes:]
|
||||
message.Text = strings.ToUpper(hex.EncodeToString(payload))
|
||||
return nil
|
||||
}
|
||||
}
|
||||
|
||||
@@ -263,3 +263,80 @@ func TestParseCMGLPreservesUndecodableRecord(t *testing.T) {
|
||||
t.Fatalf("messages = %#v", messages)
|
||||
}
|
||||
}
|
||||
|
||||
func TestDecodeAlphanumericTPAddress(t *testing.T) {
|
||||
// "TEST" encoded as 4 GSM-7 septets packed into 4 bytes (non-standard septet count format: length=4).
|
||||
cursor := &pduCursor{data: []byte{0x04, 0xd0, 0xd4, 0xe2, 0x94, 0x0a}}
|
||||
address, err := readTPAddress(cursor)
|
||||
if err != nil {
|
||||
t.Fatalf("readTPAddress error = %v", err)
|
||||
}
|
||||
if address != "TEST" {
|
||||
t.Fatalf("readTPAddress = %q, want TEST", address)
|
||||
}
|
||||
if cursor.index != len(cursor.data) {
|
||||
t.Fatalf("cursor did not consume all bytes: %d/%d", cursor.index, len(cursor.data))
|
||||
}
|
||||
}
|
||||
|
||||
func TestDecodeAlphanumericTPAddressStandard3GPP(t *testing.T) {
|
||||
// "Google" (6 chars) encoded per 3GPP TS 23.040 §9.1.2.5:
|
||||
// length = 0x0B (11 useful semi-octets), TOA = 0xD0 (Alphanumeric),
|
||||
// 6 bytes payload: C7 F7 FB CC 2E 03
|
||||
cursor := &pduCursor{data: []byte{0x0b, 0xd0, 0xc7, 0xf7, 0xfb, 0xcc, 0x2e, 0x03}}
|
||||
address, err := readTPAddress(cursor)
|
||||
if err != nil {
|
||||
t.Fatalf("readTPAddress standard 3GPP error = %v", err)
|
||||
}
|
||||
if address != "Google" {
|
||||
t.Fatalf("readTPAddress standard 3GPP = %q, want Google", address)
|
||||
}
|
||||
if cursor.index != len(cursor.data) {
|
||||
t.Fatalf("cursor did not consume all bytes: %d/%d", cursor.index, len(cursor.data))
|
||||
}
|
||||
|
||||
// "TEST" (4 chars) with standard 3GPP semi-octets (length = 0x08, 8 semi-octets -> 4 bytes)
|
||||
cursorTest := &pduCursor{data: []byte{0x08, 0xd0, 0xd4, 0xe2, 0x94, 0x0a}}
|
||||
addressTest, err := readTPAddress(cursorTest)
|
||||
if err != nil {
|
||||
t.Fatalf("readTPAddress standard 3GPP TEST error = %v", err)
|
||||
}
|
||||
if addressTest != "TEST" {
|
||||
t.Fatalf("readTPAddress standard 3GPP TEST = %q, want TEST", addressTest)
|
||||
}
|
||||
}
|
||||
|
||||
func TestDecodeDeliverPDUWithAlphanumericSender(t *testing.T) {
|
||||
// SMS-DELIVER with alphanumeric originator "VoCat" and empty user data.
|
||||
// SMSC length=0, first octet=0x04, OA length=0x05, OA TON=0xD0,
|
||||
// OA bytes pack "VoCat" (5 septets -> 5 bytes), PID=0x00, DCS=0x00,
|
||||
// SCTS=7 bytes, UDL=0x00.
|
||||
message, err := decodeSMSPDU("000405D0D6F7304C0700004210203040500000")
|
||||
if err != nil {
|
||||
t.Fatalf("decodeSMSPDU error = %v", err)
|
||||
}
|
||||
if message.From != "VoCat" {
|
||||
t.Fatalf("From = %q, want VoCat", message.From)
|
||||
}
|
||||
if message.Direction != SMSDirectionReceived {
|
||||
t.Fatalf("Direction = %q", message.Direction)
|
||||
}
|
||||
}
|
||||
|
||||
func TestDecode8BitPDUShowsHexPayload(t *testing.T) {
|
||||
// SMS-DELIVER with no SMSC, from +12345, DCS=0xF5 (8-bit data,
|
||||
// alphabet bits 0x0c), UDL=3. User data bytes are 0xAA 0xBB 0xCC.
|
||||
// Built from the GSM-7 deliver vector by swapping the DCS to 0xF5
|
||||
// and replacing the user data with three raw binary bytes.
|
||||
message, err := decodeSMSPDU(
|
||||
"000405912143F500F54210203040500003AABBCC",
|
||||
)
|
||||
if err != nil {
|
||||
t.Fatalf("decode 8-bit: %v", err)
|
||||
}
|
||||
if message.Encoding != SMSEncoding8BitPDU ||
|
||||
message.Text != "AABBCC" ||
|
||||
message.RawUserData != "AABBCC" {
|
||||
t.Fatalf("8-bit message = %#v", message)
|
||||
}
|
||||
}
|
||||
|
||||
@@ -14,7 +14,13 @@ import (
|
||||
const (
|
||||
djiVendorID = "2ca3"
|
||||
dji4GProductID = "4006"
|
||||
// quectelVendorID covers Quectel USB modems exposed purely as serial or
|
||||
// RNDIS/ECM devices (for example the EC200A at 2c7c:6005). Their control
|
||||
// interface is not bound to qmi_wwan, so the QMI-binding gate would skip
|
||||
// them even though they expose a usable AT serial port.
|
||||
quectelVendorID = "2c7c"
|
||||
)
|
||||
|
||||
type SysFSDiscoverer struct {
|
||||
SysRoot string
|
||||
DevRoot string
|
||||
@@ -83,7 +89,15 @@ func (d *SysFSDiscoverer) Discover(ctx context.Context) ([]Candidate, error) {
|
||||
vendorID := strings.ToLower(readTrimmed(filepath.Join(resolvedDevice, "idVendor")))
|
||||
productID := strings.ToLower(readTrimmed(filepath.Join(resolvedDevice, "idProduct")))
|
||||
if _, bound := qmiBound[deviceName]; !bound && !IsDJI4GUSB(vendorID, productID) {
|
||||
continue
|
||||
// A bound qmi_wwan interface is the strongest vendor-neutral "this is
|
||||
// a live QMI modem" signal, but it excludes Quectel modules running
|
||||
// in a serial or RNDIS/ECM USB composition (no qmi_wwan binding).
|
||||
// Re-admit them by vendor so their AT serial ports stay discoverable;
|
||||
// the candidate is only kept if a ttyUSB/ttyACM node is actually
|
||||
// found below, which is exactly the AT-bearing composition we want.
|
||||
if !isQuectelUSBModem(vendorID) {
|
||||
continue
|
||||
}
|
||||
}
|
||||
|
||||
state := devices[deviceName]
|
||||
@@ -142,11 +156,19 @@ func (d *SysFSDiscoverer) Discover(ctx context.Context) ([]Candidate, error) {
|
||||
assignQuectelPortRoles(state.candidate.Ports)
|
||||
state.candidate.ATPort = selectATPort(state.candidate.Ports)
|
||||
if !state.candidate.HasATPort() {
|
||||
// A bound QMI interface proves the modem is alive, but the snapshot,
|
||||
// SMS, USSD and eSIM (AT+CSIM) paths all require an AT port. A missing
|
||||
// ttyUSB/ttyACM node almost always means the option/qcserial driver
|
||||
// does not claim the serial interfaces (often a missing PID in its
|
||||
// device-ID table), not that the module lacks an AT interface.
|
||||
// A modem without a usable AT port cannot be driven by vocat, but it
|
||||
// is far more useful to surface it with a discovery issue than to
|
||||
// silently drop it: the operator sees the device is present and gets
|
||||
// told why it is unusable. Two shapes land here:
|
||||
// * qmi_wwan is bound but no ttyUSB/ttyACM exists — the option/qcserial
|
||||
// driver did not claim the serial interfaces (often a missing PID
|
||||
// in its device-ID table, common on Ubuntu for EG25-G carrier
|
||||
// builds). The modem is alive; it just lacks an AT node.
|
||||
// * no qmi_wwan binding (Quectel re-admitted by vendor) and no AT
|
||||
// port — typically an MBIM/RNDIS/ECM composition. The module is on
|
||||
// the bus but exposes no AT serial interface vocat can open.
|
||||
// Both resolve the same operator action: add the PID to the option
|
||||
// driver or switch the module to a QMI+AT composition.
|
||||
state.candidate.DiscoveryIssue = "at_port_missing"
|
||||
}
|
||||
result = append(result, state.candidate)
|
||||
@@ -168,6 +190,15 @@ func IsDJI4GUSB(vendorID, productID string) bool {
|
||||
strings.EqualFold(strings.TrimSpace(productID), dji4GProductID)
|
||||
}
|
||||
|
||||
// isQuectelUSBModem reports whether a USB identity belongs to a Quectel
|
||||
// module. Quectel's serial/RNDIS/ECM compositions (e.g. EC200A at 2c7c:6005)
|
||||
// do not bind qmi_wwan, so discovery must fall back to the vendor ID to keep
|
||||
// them visible. The candidate is only retained if it exposes an AT serial
|
||||
// port, which filters out unrelated Quectel-branded peripherals.
|
||||
func isQuectelUSBModem(vendorID string) bool {
|
||||
return strings.EqualFold(strings.TrimSpace(vendorID), quectelVendorID)
|
||||
}
|
||||
|
||||
type discoveredWWANDevice struct {
|
||||
index string
|
||||
ports []Port
|
||||
|
||||
@@ -444,6 +444,115 @@ func TestParseWWANPortName(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
func TestSysFSDiscoveryFindsQuectelSerialModemWithoutQMIWWANBinding(t *testing.T) {
|
||||
root := t.TempDir()
|
||||
sysRoot := filepath.Join(root, "sys")
|
||||
devRoot := filepath.Join(root, "dev")
|
||||
usbRoot := filepath.Join(sysRoot, "bus", "usb", "devices")
|
||||
// A Quectel EC200A in its USB-serial composition (2c7c:6005) exposes ttyUSB
|
||||
// control ports but no qmi_wwan-bound interface, so discovery must re-admit
|
||||
// it by vendor instead of skipping it.
|
||||
mustWrite(t, filepath.Join(usbRoot, "1-6", "idVendor"), "2c7c\n")
|
||||
mustWrite(t, filepath.Join(usbRoot, "1-6", "idProduct"), "6005\n")
|
||||
for number, tty := range []string{"ttyUSB0", "ttyUSB1", "ttyUSB2", "ttyUSB3"} {
|
||||
interfaceName := "1-6:1." + strconv.Itoa(number)
|
||||
mustWrite(t, filepath.Join(usbRoot, interfaceName, "bInterfaceNumber"), fmt.Sprintf("%02x\n", number))
|
||||
mustMkdir(t, filepath.Join(usbRoot, interfaceName, tty, "tty", tty))
|
||||
}
|
||||
|
||||
candidates, err := NewSysFSDiscoverer(sysRoot, devRoot).Discover(context.Background())
|
||||
if err != nil {
|
||||
t.Fatalf("Discover: %v", err)
|
||||
}
|
||||
if len(candidates) != 1 {
|
||||
t.Fatalf("got %d candidates, want 1", len(candidates))
|
||||
}
|
||||
candidate := candidates[0]
|
||||
if candidate.VendorID != "2c7c" || candidate.ProductID != "6005" {
|
||||
t.Fatalf("candidate = %#v", candidate)
|
||||
}
|
||||
if candidate.ID != "usb-2c7c-6005-1-6" {
|
||||
t.Fatalf("ID = %q", candidate.ID)
|
||||
}
|
||||
if candidate.ATPort.Name != "ttyUSB2" || candidate.ATPort.Role != PortRoleAT {
|
||||
t.Fatalf("AT port = %#v, want ttyUSB2 at role AT", candidate.ATPort)
|
||||
}
|
||||
if candidate.DiscoveryIssue != "" {
|
||||
t.Fatalf("discovery issue = %q, want none", candidate.DiscoveryIssue)
|
||||
}
|
||||
}
|
||||
|
||||
func TestSysFSDiscoveryMarksQuectelPeripheralWithoutATPort(t *testing.T) {
|
||||
root := t.TempDir()
|
||||
sysRoot := filepath.Join(root, "sys")
|
||||
devRoot := filepath.Join(root, "dev")
|
||||
usbRoot := filepath.Join(sysRoot, "bus", "usb", "devices")
|
||||
// A Quectel-branded peripheral exposing only a network interface (no
|
||||
// ttyUSB/ttyACM, no qmi_wwan binding) cannot be driven yet, but vocat
|
||||
// surfaces it with at_port_missing instead of silently dropping it so the
|
||||
// operator sees the device is present and learns what to fix.
|
||||
mustWrite(t, filepath.Join(usbRoot, "1-8", "idVendor"), "2c7c\n")
|
||||
mustWrite(t, filepath.Join(usbRoot, "1-8", "idProduct"), "6005\n")
|
||||
mustMkdir(t, filepath.Join(usbRoot, "1-8:1.0", "net", "enx001122334455"))
|
||||
|
||||
candidates, err := NewSysFSDiscoverer(sysRoot, devRoot).Discover(context.Background())
|
||||
if err != nil {
|
||||
t.Fatalf("Discover: %v", err)
|
||||
}
|
||||
if len(candidates) != 1 {
|
||||
t.Fatalf("got %d candidates, want 1", len(candidates))
|
||||
}
|
||||
candidate := candidates[0]
|
||||
if candidate.DiscoveryIssue != "at_port_missing" {
|
||||
t.Fatalf("discovery issue = %q, want at_port_missing", candidate.DiscoveryIssue)
|
||||
}
|
||||
if candidate.HasATPort() {
|
||||
t.Fatalf("candidate unexpectedly has an AT port: %#v", candidate.ATPort)
|
||||
}
|
||||
if candidate.NetworkInterface != "enx001122334455" {
|
||||
t.Fatalf("network interface = %q", candidate.NetworkInterface)
|
||||
}
|
||||
}
|
||||
|
||||
func TestSysFSDiscoveryMarksQuectelMBIMCompositionWithoutATPort(t *testing.T) {
|
||||
root := t.TempDir()
|
||||
sysRoot := filepath.Join(root, "sys")
|
||||
devRoot := filepath.Join(root, "dev")
|
||||
usbRoot := filepath.Join(sysRoot, "bus", "usb", "devices")
|
||||
// An EG25-G in MBIM composition (2c7c:0900) exposes cdc-wdm + net but no
|
||||
// ttyUSB and has no qmi_wwan binding (cdc_mbim binds the control interface
|
||||
// instead). vocat has no MBIM backend, so it must surface the device with
|
||||
// at_port_missing rather than hiding it.
|
||||
mustWrite(t, filepath.Join(usbRoot, "1-6", "idVendor"), "2c7c\n")
|
||||
mustWrite(t, filepath.Join(usbRoot, "1-6", "idProduct"), "0900\n")
|
||||
mustWrite(t, filepath.Join(usbRoot, "1-6", "product"), "EG25-G\n")
|
||||
mustMkdir(t, filepath.Join(usbRoot, "1-6:1.0", "usbmisc", "cdc-wdm0"))
|
||||
mustMkdir(t, filepath.Join(usbRoot, "1-6:1.0", "net", "wwp0s20f0u6"))
|
||||
|
||||
candidates, err := NewSysFSDiscoverer(sysRoot, devRoot).Discover(context.Background())
|
||||
if err != nil {
|
||||
t.Fatalf("Discover: %v", err)
|
||||
}
|
||||
if len(candidates) != 1 {
|
||||
t.Fatalf("got %d candidates, want 1", len(candidates))
|
||||
}
|
||||
candidate := candidates[0]
|
||||
if candidate.DiscoveryIssue != "at_port_missing" {
|
||||
t.Fatalf("discovery issue = %q, want at_port_missing", candidate.DiscoveryIssue)
|
||||
}
|
||||
if candidate.HasATPort() {
|
||||
t.Fatalf("candidate unexpectedly has an AT port: %#v", candidate.ATPort)
|
||||
}
|
||||
if candidate.Product != "EG25-G" {
|
||||
t.Fatalf("product = %q", candidate.Product)
|
||||
}
|
||||
// cdc-wdm0 sits under usbmisc/, which scanUSBInterface reports as a QMI
|
||||
// control name; either way the device must appear present, not vanish.
|
||||
if candidate.QMIControl == "" && candidate.NetworkInterface == "" {
|
||||
t.Fatalf("candidate has neither QMI control nor net interface: %#v", candidate)
|
||||
}
|
||||
}
|
||||
|
||||
func mustWrite(t *testing.T, path, value string) {
|
||||
t.Helper()
|
||||
mustMkdir(t, filepath.Dir(path))
|
||||
|
||||
@@ -3,6 +3,7 @@ package netguard
|
||||
import (
|
||||
"context"
|
||||
"crypto/tls"
|
||||
"crypto/x509"
|
||||
"errors"
|
||||
"fmt"
|
||||
"net"
|
||||
@@ -48,6 +49,13 @@ func ValidatePublicURL(ctx context.Context, raw string, requireHTTPS bool) (*url
|
||||
// rejects private/special-use destinations at dial time, and validates every
|
||||
// redirect before following it.
|
||||
func NewPublicHTTPClient(timeout time.Duration, requireHTTPS bool) *http.Client {
|
||||
return NewPublicHTTPClientWithRootCAs(timeout, requireHTTPS, nil)
|
||||
}
|
||||
|
||||
// NewPublicHTTPClientWithRootCAs creates the same guarded client while using
|
||||
// the supplied trust pool for protocols whose standards define additional
|
||||
// public roots beyond the host operating system's CA bundle.
|
||||
func NewPublicHTTPClientWithRootCAs(timeout time.Duration, requireHTTPS bool, roots *x509.CertPool) *http.Client {
|
||||
if timeout <= 0 {
|
||||
timeout = 30 * time.Second
|
||||
}
|
||||
@@ -60,6 +68,7 @@ func NewPublicHTTPClient(timeout time.Duration, requireHTTPS bool) *http.Client
|
||||
ExpectContinueTimeout: time.Second,
|
||||
TLSClientConfig: &tls.Config{
|
||||
MinVersion: tls.VersionTLS12,
|
||||
RootCAs: roots,
|
||||
},
|
||||
}
|
||||
return &http.Client{
|
||||
|
||||
@@ -31,12 +31,42 @@ func TestValidateATCommandBlocksTrafficMessagingAndDialActions(t *testing.T) {
|
||||
"AT+CSQ;+CMSS=7",
|
||||
"AT+CSQ;D12345;",
|
||||
} {
|
||||
if err := validateATCommand(command); err == nil {
|
||||
if err := validateATCommand(command, false); err == nil {
|
||||
t.Errorf("validateATCommand(%q) permitted a guarded mutation", command)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func TestValidateATCommandForceBypassesGuard(t *testing.T) {
|
||||
t.Parallel()
|
||||
for _, command := range []string{
|
||||
"AT+CGATT=1",
|
||||
"AT+CFUN=1",
|
||||
"AT+CGACT=1,1",
|
||||
"AT+CUSD=1,\"*100#\"",
|
||||
"ATD12345;",
|
||||
} {
|
||||
if err := validateATCommand(command, true); err != nil {
|
||||
t.Errorf("validateATCommand(%q, true): %v", command, err)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func TestValidateATCommandForceKeepsSyntaxChecks(t *testing.T) {
|
||||
t.Parallel()
|
||||
for _, command := range []string{
|
||||
"A",
|
||||
"",
|
||||
"AT\r",
|
||||
"AT\n",
|
||||
string(make([]byte, 513)),
|
||||
} {
|
||||
if err := validateATCommand(command, true); err == nil {
|
||||
t.Errorf("validateATCommand(%q, true) skipped syntax check", command)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func TestValidateATCommandAllowsReadOnlyStatusQueries(t *testing.T) {
|
||||
t.Parallel()
|
||||
for _, command := range []string{
|
||||
@@ -48,7 +78,7 @@ func TestValidateATCommandAllowsReadOnlyStatusQueries(t *testing.T) {
|
||||
"AT+CIMI",
|
||||
"AT+CCID",
|
||||
} {
|
||||
if err := validateATCommand(command); err != nil {
|
||||
if err := validateATCommand(command, false); err != nil {
|
||||
t.Errorf("validateATCommand(%q): %v", command, err)
|
||||
}
|
||||
}
|
||||
|
||||
@@ -581,7 +581,7 @@ func (s *Server) handleDevicePath(
|
||||
if !s.requirePhysicalDevice(w, physicalPresent) {
|
||||
return true
|
||||
}
|
||||
return s.handleUSSD(w, r, physicalID)
|
||||
return s.handleUSSD(w, r, config, physicalID)
|
||||
case "actions/ussd/continue":
|
||||
return s.handleUSSDContinue(w, r)
|
||||
case "actions/ussd/cancel":
|
||||
@@ -1045,13 +1045,14 @@ func (s *Server) handleAT(w http.ResponseWriter, r *http.Request, id string) boo
|
||||
var request struct {
|
||||
Command string `json:"cmd"`
|
||||
TimeoutMs int `json:"timeout_ms"`
|
||||
Force bool `json:"force"`
|
||||
}
|
||||
if err := s.decodeJSON(w, r, &request); err != nil {
|
||||
writeError(w, http.StatusBadRequest, "invalid_request", err.Error())
|
||||
return true
|
||||
}
|
||||
command := strings.TrimSpace(request.Command)
|
||||
if err := validateATCommand(command); err != nil {
|
||||
if err := validateATCommand(command, request.Force); err != nil {
|
||||
writeError(w, http.StatusBadRequest, "unsafe_at_command", err.Error())
|
||||
return true
|
||||
}
|
||||
@@ -1100,7 +1101,7 @@ func (s *Server) handleAT(w http.ResponseWriter, r *http.Request, id string) boo
|
||||
return true
|
||||
}
|
||||
|
||||
func validateATCommand(command string) error {
|
||||
func validateATCommand(command string, force bool) error {
|
||||
upper := strings.ToUpper(command)
|
||||
if len(command) < 2 || len(command) > 512 || !strings.HasPrefix(upper, "AT") {
|
||||
return errors.New("AT command must start with AT and contain at most 512 characters")
|
||||
@@ -1108,6 +1109,9 @@ func validateATCommand(command string) error {
|
||||
if strings.ContainsAny(command, "\r\n\x00") {
|
||||
return errors.New("AT command must contain exactly one line")
|
||||
}
|
||||
if force {
|
||||
return nil
|
||||
}
|
||||
canonical := strings.NewReplacer(" ", "", "\t", "").Replace(upper)
|
||||
for _, blocked := range []string{
|
||||
`+QCFG="USBNET"`,
|
||||
@@ -1138,7 +1142,34 @@ func validateATCommand(command string) error {
|
||||
return nil
|
||||
}
|
||||
|
||||
func (s *Server) handleUSSD(w http.ResponseWriter, r *http.Request, id string) bool {
|
||||
// imsUSSIController is the optional VoWiFi runtime capability used to route a
|
||||
// USSD request over IMS (3GPP TS 24.390) when VoWiFi is enabled and the IMS
|
||||
// session is registered. device.Manager does not implement it; the VoWiFi
|
||||
// runtime manager does.
|
||||
type imsUSSIController interface {
|
||||
SendUSSI(context.Context, string, vowifi.USSISubmitRequest) (vowifi.USSISubmitResult, error)
|
||||
}
|
||||
|
||||
// openUSSDSession mirrors device.Manager.openUSSDSession but lives on the HTTP
|
||||
// server so a USSI awaiting-input reply can hand back a token the existing
|
||||
// continue/cancel endpoints understand. The token is only a device handle;
|
||||
// the IMS session owns the actual dialog.
|
||||
func (s *Server) openUSSDSession(deviceID string) string {
|
||||
return s.ussdSessions.open(deviceID)
|
||||
}
|
||||
|
||||
// ussdSessionDevice resolves a USSD session token created by openUSSDSession
|
||||
// back to its device id, matching device.ErrUSSDSessionNotFound semantics.
|
||||
func (s *Server) ussdSessionDevice(sessionID string) (string, error) {
|
||||
return s.ussdSessions.device(sessionID)
|
||||
}
|
||||
|
||||
// dropUSSDSession releases a USSD session token.
|
||||
func (s *Server) dropUSSDSession(sessionID string) {
|
||||
s.ussdSessions.drop(sessionID)
|
||||
}
|
||||
|
||||
func (s *Server) handleUSSD(w http.ResponseWriter, r *http.Request, config store.Device, id string) bool {
|
||||
if !requireMethod(w, r, http.MethodPost) {
|
||||
return true
|
||||
}
|
||||
@@ -1152,21 +1183,61 @@ func (s *Server) handleUSSD(w http.ResponseWriter, r *http.Request, id string) b
|
||||
}
|
||||
ctx, cancel := actionRequestContext(r.Context(), request.TimeoutMs)
|
||||
defer cancel()
|
||||
// VoWiFi-first: when VoWiFi owns the radio the cellular CUSD path has no
|
||||
// network to talk to (CFUN=4 returns +CME ERROR: 30). Route over IMS/USSI
|
||||
// when the IMS session is registered, and fall back to cellular CUSD only
|
||||
// when USSI is not ready or the runtime is unavailable.
|
||||
if config.VoWiFiEnabled && s.vowifi != nil {
|
||||
sender, canSendIMS := s.vowifi.(imsUSSIController)
|
||||
if canSendIMS {
|
||||
if state, stateErr := s.vowifi.State(id); stateErr == nil && state.IMSReady {
|
||||
result, sendErr := sender.SendUSSI(ctx, id, vowifi.USSISubmitRequest{Code: request.Command})
|
||||
if sendErr == nil {
|
||||
writeUSSDResult(w, ussdResultFromUSSI(result, id, s))
|
||||
return true
|
||||
}
|
||||
if !errors.Is(sendErr, vowifi.ErrUSSINotReady) {
|
||||
s.writeDeviceError(w, sendErr)
|
||||
return true
|
||||
}
|
||||
// ErrUSSINotReady: fall through to cellular CUSD.
|
||||
}
|
||||
}
|
||||
}
|
||||
result, err := s.devices.USSD(ctx, id, request.Command)
|
||||
if err != nil {
|
||||
s.writeDeviceError(w, err)
|
||||
return true
|
||||
}
|
||||
writeJSON(w, http.StatusOK, map[string]any{
|
||||
"data": map[string]any{
|
||||
"result": result.Text,
|
||||
"raw": result.Raw,
|
||||
"dcs": result.DCS,
|
||||
},
|
||||
})
|
||||
writeUSSDResult(w, result)
|
||||
return true
|
||||
}
|
||||
|
||||
// ussdResultFromUSSI maps a USSI result onto the device.USSDResult shape that
|
||||
// writeUSSDResult expects. A USSI awaiting-input reply opens a server-side
|
||||
// session token via the device manager so the existing continue/cancel
|
||||
// endpoints keep working; the token maps back to the device and the continue
|
||||
// handler re-enters the USSI path through the same imsUSSIController.
|
||||
func ussdResultFromUSSI(result vowifi.USSISubmitResult, deviceID string, server *Server) device.USSDResult {
|
||||
mapped := device.USSDResult{
|
||||
Text: result.Text,
|
||||
Raw: result.Raw,
|
||||
DCS: result.DCS,
|
||||
Status: result.Status,
|
||||
Continueable: result.Continueable,
|
||||
}
|
||||
// USSI has no inline continue/terminate flag in the 2xx response body, so
|
||||
// treat any non-empty successful reply as potentially multi-round. The cancel
|
||||
// endpoint drops the local token; the network will time the dialog out if it
|
||||
// was actually final.
|
||||
if mapped.Status != "failed" && mapped.Status != "terminated" && mapped.Text != "" {
|
||||
mapped.Status = "awaiting_input"
|
||||
mapped.Continueable = true
|
||||
mapped.SessionID = server.openUSSDSession(deviceID)
|
||||
}
|
||||
return mapped
|
||||
}
|
||||
|
||||
func (s *Server) handleFlightMode(w http.ResponseWriter, r *http.Request, config store.Device, physicalID string) bool {
|
||||
if !requireMethod(w, r, http.MethodPatch) {
|
||||
return true
|
||||
@@ -1636,7 +1707,14 @@ func (s *Server) configuredDeviceOverview(
|
||||
result["id"] = config.ID
|
||||
result["name"] = config.Name
|
||||
result["interface"] = config.Interface
|
||||
result["at_port"] = config.ATPort
|
||||
// ttyUSB allocation changes across USB reconnects and boot cycles. The AT
|
||||
// terminal must use only the currently discovered physical port; a stored
|
||||
// path may point at another modem after enumeration order changes.
|
||||
liveATPort := ""
|
||||
if present {
|
||||
liveATPort = entry.Candidate.ATPort.OpenPath()
|
||||
}
|
||||
result["at_port"] = liveATPort
|
||||
result["audio_device"] = config.AudioDevice
|
||||
result["backend_mode"] = config.DeviceBackend
|
||||
result["control_device"] = config.ControlDevice
|
||||
|
||||
@@ -9,6 +9,7 @@ import (
|
||||
|
||||
"vocat/internal/device"
|
||||
"vocat/internal/store"
|
||||
"vocat/internal/vowifi"
|
||||
)
|
||||
|
||||
// overviewStreamInterval is the cadence at which the overview SSE stream pushes
|
||||
@@ -192,6 +193,31 @@ func (s *Server) handleUSSDContinue(w http.ResponseWriter, r *http.Request) bool
|
||||
input := firstNonEmpty(request.Input, request.Command)
|
||||
ctx, cancel := actionRequestContext(r.Context(), request.TimeoutMs)
|
||||
defer cancel()
|
||||
// A session opened by the USSI path maps back to a device id that may still
|
||||
// be VoWiFi-active. Prefer USSI continue when IMS is ready; otherwise report
|
||||
// the session as unavailable rather than falling through to the cellular
|
||||
// CUSD path, because the IMS session owns the actual dialog.
|
||||
if deviceID, sessionErr := s.ussdSessionDevice(sessionID); sessionErr == nil {
|
||||
if config, configErr := s.store.Device(r.Context(), deviceID); configErr == nil &&
|
||||
config.VoWiFiEnabled && s.vowifi != nil {
|
||||
if sender, ok := s.vowifi.(imsUSSIController); ok {
|
||||
if state, stateErr := s.vowifi.State(deviceID); stateErr == nil && state.IMSReady {
|
||||
result, sendErr := sender.SendUSSI(ctx, deviceID, vowifi.USSISubmitRequest{Input: input})
|
||||
if sendErr == nil {
|
||||
writeUSSDResult(w, ussdResultFromUSSI(result, deviceID, s))
|
||||
return true
|
||||
}
|
||||
if !errors.Is(sendErr, vowifi.ErrUSSINotReady) {
|
||||
s.writeDeviceError(w, sendErr)
|
||||
return true
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
writeError(w, http.StatusServiceUnavailable, "ussi_session_unavailable",
|
||||
"USSI session is no longer available because the IMS registration has dropped")
|
||||
return true
|
||||
}
|
||||
result, err := s.devices.ContinueUSSD(ctx, sessionID, input)
|
||||
if err != nil {
|
||||
s.writeDeviceError(w, err)
|
||||
@@ -219,6 +245,16 @@ func (s *Server) handleUSSDCancel(w http.ResponseWriter, r *http.Request) bool {
|
||||
writeError(w, http.StatusBadRequest, "invalid_request", "session_id is required")
|
||||
return true
|
||||
}
|
||||
// Drop a USSI-originated session token locally. USSI has no network-side
|
||||
// release signalling in the minimal implementation, so dropping the handle
|
||||
// matches the cellular AT+CUSD=2 "best-effort abort" behavior.
|
||||
if _, sessionErr := s.ussdSessionDevice(sessionID); sessionErr == nil {
|
||||
s.dropUSSDSession(sessionID)
|
||||
writeJSON(w, http.StatusOK, map[string]any{
|
||||
"data": map[string]any{"cancelled": true, "session_id": sessionID},
|
||||
})
|
||||
return true
|
||||
}
|
||||
if err := s.devices.CancelUSSD(r.Context(), sessionID); err != nil {
|
||||
s.writeDeviceError(w, err)
|
||||
return true
|
||||
|
||||
@@ -18,6 +18,7 @@ import (
|
||||
"vocat/internal/modem"
|
||||
"vocat/internal/store"
|
||||
"vocat/internal/update"
|
||||
"vocat/internal/vowifi"
|
||||
)
|
||||
|
||||
func decodeData(t *testing.T, recorder *httptest.ResponseRecorder) map[string]any {
|
||||
@@ -266,6 +267,143 @@ func TestHandleUSSDContinueRequiresSession(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
// fakeUSSIController implements both VoWiFiController and the optional
|
||||
// imsUSSIController interface so the HTTP layer USSI path can be exercised
|
||||
// without a real runtime manager.
|
||||
type fakeUSSIController struct {
|
||||
fakeVoWiFiController
|
||||
sendErr error
|
||||
sendResult vowifi.USSISubmitResult
|
||||
sendCalled int
|
||||
lastInput string
|
||||
}
|
||||
|
||||
func (controller *fakeUSSIController) SendUSSI(
|
||||
_ context.Context,
|
||||
_ string,
|
||||
request vowifi.USSISubmitRequest,
|
||||
) (vowifi.USSISubmitResult, error) {
|
||||
controller.sendCalled++
|
||||
controller.lastInput = request.Input
|
||||
if request.Code != "" {
|
||||
controller.lastInput = request.Code
|
||||
}
|
||||
return controller.sendResult, controller.sendErr
|
||||
}
|
||||
|
||||
func TestHandleUSSDRoutesOverIMSWhenReady(t *testing.T) {
|
||||
controller := &fakeUSSIController{
|
||||
fakeVoWiFiController: fakeVoWiFiController{state: vowifi.State{IMSReady: true}},
|
||||
sendResult: vowifi.USSISubmitResult{Status: "final", Text: "IMS balance"},
|
||||
}
|
||||
devices := fakeDeviceController{ussdResult: device.USSDResult{Status: "final", Text: "cellular"}}
|
||||
server := &Server{
|
||||
logger: regionTestLogger(),
|
||||
maxRequestBodyBytes: 4096,
|
||||
devices: devices,
|
||||
vowifi: controller,
|
||||
}
|
||||
request := httptest.NewRequest(http.MethodPost, "/actions/ussd", strings.NewReader(`{"command":"*100#"}`))
|
||||
request.Header.Set("Content-Type", "application/json")
|
||||
recorder := httptest.NewRecorder()
|
||||
server.handleUSSD(recorder, request, store.Device{ID: "dev1", VoWiFiEnabled: true}, "dev1")
|
||||
if recorder.Code != http.StatusOK {
|
||||
t.Fatalf("status = %d, body=%s", recorder.Code, recorder.Body.String())
|
||||
}
|
||||
data := decodeData(t, recorder)
|
||||
result, _ := data["result"].(map[string]any)
|
||||
if result["text"] != "IMS balance" {
|
||||
t.Fatalf("result = %v, want IMS routed response", result)
|
||||
}
|
||||
if controller.sendCalled != 1 {
|
||||
t.Fatalf("SendUSSI called %d times, want 1", controller.sendCalled)
|
||||
}
|
||||
}
|
||||
|
||||
func TestHandleUSSDFallsBackToCellularWhenIMSNotReady(t *testing.T) {
|
||||
controller := &fakeUSSIController{
|
||||
fakeVoWiFiController: fakeVoWiFiController{state: vowifi.State{}},
|
||||
}
|
||||
devices := fakeDeviceController{ussdResult: device.USSDResult{Status: "final", Text: "cellular"}}
|
||||
server := &Server{
|
||||
logger: regionTestLogger(),
|
||||
maxRequestBodyBytes: 4096,
|
||||
devices: devices,
|
||||
vowifi: controller,
|
||||
}
|
||||
request := httptest.NewRequest(http.MethodPost, "/actions/ussd", strings.NewReader(`{"command":"*100#"}`))
|
||||
request.Header.Set("Content-Type", "application/json")
|
||||
recorder := httptest.NewRecorder()
|
||||
server.handleUSSD(recorder, request, store.Device{ID: "dev1", VoWiFiEnabled: true}, "dev1")
|
||||
if recorder.Code != http.StatusOK {
|
||||
t.Fatalf("status = %d, body=%s", recorder.Code, recorder.Body.String())
|
||||
}
|
||||
data := decodeData(t, recorder)
|
||||
result, _ := data["result"].(map[string]any)
|
||||
if result["text"] != "cellular" {
|
||||
t.Fatalf("result = %v, want cellular fallback", result)
|
||||
}
|
||||
if controller.sendCalled != 0 {
|
||||
t.Fatalf("SendUSSI called %d times, want 0", controller.sendCalled)
|
||||
}
|
||||
}
|
||||
|
||||
func TestHandleUSSDContinueUsesIMSForUSSIPersistedSession(t *testing.T) {
|
||||
database, err := store.Open(context.Background(), ":memory:")
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
t.Cleanup(func() { _ = database.Close() })
|
||||
if err := database.UpsertDevice(context.Background(), store.Device{ID: "dev1", Name: "test", DeviceType: store.DeviceTypePCIeEC20EC25, VoWiFiEnabled: true}); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
controller := &fakeUSSIController{
|
||||
fakeVoWiFiController: fakeVoWiFiController{state: vowifi.State{IMSReady: true}},
|
||||
sendResult: vowifi.USSISubmitResult{Status: "awaiting_input", Text: "Sub-menu"},
|
||||
}
|
||||
server := &Server{
|
||||
logger: regionTestLogger(),
|
||||
maxRequestBodyBytes: 4096,
|
||||
store: database,
|
||||
vowifi: controller,
|
||||
}
|
||||
sessionID := server.openUSSDSession("dev1")
|
||||
request := httptest.NewRequest(http.MethodPost, "/actions/ussd/continue", strings.NewReader(`{"session_id":"`+sessionID+`","input":"1"}`))
|
||||
request.Header.Set("Content-Type", "application/json")
|
||||
recorder := httptest.NewRecorder()
|
||||
server.handleUSSDContinue(recorder, request)
|
||||
if recorder.Code != http.StatusOK {
|
||||
t.Fatalf("status = %d, body=%s", recorder.Code, recorder.Body.String())
|
||||
}
|
||||
data := decodeData(t, recorder)
|
||||
result, _ := data["result"].(map[string]any)
|
||||
if result["text"] != "Sub-menu" {
|
||||
t.Fatalf("result = %v, want IMS continue response", result)
|
||||
}
|
||||
if controller.sendCalled != 1 || controller.lastInput != "1" {
|
||||
t.Fatalf("SendUSSI called %d times with input %q, want 1/1", controller.sendCalled, controller.lastInput)
|
||||
}
|
||||
}
|
||||
|
||||
func TestHandleUSSDCancelDropsUSSIPersistedSession(t *testing.T) {
|
||||
server := &Server{
|
||||
logger: regionTestLogger(),
|
||||
maxRequestBodyBytes: 4096,
|
||||
vowifi: &fakeUSSIController{},
|
||||
}
|
||||
sessionID := server.openUSSDSession("dev1")
|
||||
request := httptest.NewRequest(http.MethodPost, "/actions/ussd/cancel", strings.NewReader(`{"session_id":"`+sessionID+`"}`))
|
||||
request.Header.Set("Content-Type", "application/json")
|
||||
recorder := httptest.NewRecorder()
|
||||
server.handleUSSDCancel(recorder, request)
|
||||
if recorder.Code != http.StatusOK {
|
||||
t.Fatalf("status = %d, body=%s", recorder.Code, recorder.Body.String())
|
||||
}
|
||||
if _, err := server.ussdSessionDevice(sessionID); !errors.Is(err, device.ErrUSSDSessionNotFound) {
|
||||
t.Fatalf("session token was not dropped: %v", err)
|
||||
}
|
||||
}
|
||||
|
||||
func TestHandleCardPoliciesListsAll(t *testing.T) {
|
||||
database, err := store.Open(context.Background(), ":memory:")
|
||||
if err != nil {
|
||||
|
||||
@@ -134,6 +134,29 @@ func TestConfiguredDeviceSummaryMarksIdleRuntimeAsNotInUse(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
func TestConfiguredDeviceOverviewAlwaysUsesLiveDiscoveredATPort(t *testing.T) {
|
||||
database, err := store.Open(context.Background(), ":memory:")
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
t.Cleanup(func() { _ = database.Close() })
|
||||
s := &Server{store: database}
|
||||
config := store.Device{ID: "ec20_1", ATPort: "/dev/ttyUSB9"}
|
||||
entry := device.Device{Candidate: modem.Candidate{
|
||||
ATPort: modem.Port{Path: "/dev/ttyUSB2", Role: modem.PortRoleAT},
|
||||
}}
|
||||
|
||||
connected := s.configuredDeviceOverview(config, entry, true)
|
||||
if got := connected["at_port"]; got != "/dev/ttyUSB2" {
|
||||
t.Fatalf("connected AT port = %#v, want live /dev/ttyUSB2", got)
|
||||
}
|
||||
|
||||
offline := s.configuredDeviceOverview(config, entry, false)
|
||||
if got := offline["at_port"]; got != "" {
|
||||
t.Fatalf("offline AT port = %#v, want empty instead of stored port", got)
|
||||
}
|
||||
}
|
||||
|
||||
func TestSnapshotHasSIMDoesNotTreatUnknownStatusAsInserted(t *testing.T) {
|
||||
for _, snapshot := range []*device.Snapshot{
|
||||
{IMEI: "867123456789012"},
|
||||
|
||||
@@ -57,6 +57,7 @@ type Server struct {
|
||||
auth *auth.Service
|
||||
devices DeviceController
|
||||
vowifi VoWiFiController
|
||||
ussdSessions ussdSessionStore
|
||||
logs *loghub.Hub
|
||||
assets fs.FS
|
||||
indexHTML []byte
|
||||
@@ -117,6 +118,7 @@ func New(options Options) (*Server, error) {
|
||||
auth: options.Auth,
|
||||
devices: options.Devices,
|
||||
vowifi: options.VoWiFi,
|
||||
ussdSessions: newUSSDSessionStore(),
|
||||
logs: options.Logs,
|
||||
assets: options.Assets,
|
||||
indexHTML: indexHTML,
|
||||
|
||||
@@ -295,7 +295,7 @@ func validateNotificationField(
|
||||
}
|
||||
}
|
||||
if name == "proxy" && value != "" {
|
||||
if _, err := parseOutboundURL(value, false); err != nil {
|
||||
if _, err := parseProxyURL(value); err != nil {
|
||||
return fmt.Errorf("%s is not a valid HTTP URL", field)
|
||||
}
|
||||
}
|
||||
@@ -989,7 +989,7 @@ func validateOutboundURL(
|
||||
}
|
||||
|
||||
func validateNotificationProxyURL(ctx context.Context, raw string) (*url.URL, error) {
|
||||
parsed, err := parseOutboundURL(raw, false)
|
||||
parsed, err := parseProxyURL(raw)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
@@ -999,6 +999,26 @@ func validateNotificationProxyURL(ctx context.Context, raw string) (*url.URL, er
|
||||
return parsed, nil
|
||||
}
|
||||
|
||||
// parseProxyURL parses an HTTP(S) proxy URL. Unlike parseOutboundURL, it
|
||||
// permits embedded userinfo (http://user:pass@host:port) because HTTP proxies
|
||||
// commonly authenticate with Proxy-Authorization derived from the URL.
|
||||
func parseProxyURL(raw string) (*url.URL, error) {
|
||||
parsed, err := url.Parse(strings.TrimSpace(raw))
|
||||
if err != nil || parsed.Hostname() == "" || parsed.IsAbs() == false {
|
||||
return nil, errors.New("proxy must be an absolute HTTP URL")
|
||||
}
|
||||
if parsed.Scheme != "http" && parsed.Scheme != "https" {
|
||||
return nil, errors.New("proxy URL must use HTTP or HTTPS")
|
||||
}
|
||||
if parsed.Port() != "" {
|
||||
port, err := strconv.Atoi(parsed.Port())
|
||||
if err != nil || port < 1 || port > 65535 {
|
||||
return nil, errors.New("proxy URL has an invalid port")
|
||||
}
|
||||
}
|
||||
return parsed, nil
|
||||
}
|
||||
|
||||
func parseOutboundURL(raw string, requireHTTPS bool) (*url.URL, error) {
|
||||
parsed, err := url.Parse(strings.TrimSpace(raw))
|
||||
if err != nil || parsed.Hostname() == "" || parsed.IsAbs() == false {
|
||||
|
||||
@@ -420,6 +420,11 @@ func TestNotificationSettingsRejectsUnknownAndMalformedInput(t *testing.T) {
|
||||
body: `{"lark":{"enabled":false,"url":"https://example.com/open-apis/bot/v2/hook/token"}}`,
|
||||
code: "invalid_notification_config",
|
||||
},
|
||||
{
|
||||
name: "webhook URL with embedded credentials",
|
||||
body: `{"webhook":{"enabled":true,"urls":["http://user:[email protected]"]}}`,
|
||||
code: "invalid_notification_config",
|
||||
},
|
||||
{
|
||||
name: "null body",
|
||||
body: `null`,
|
||||
@@ -994,6 +999,41 @@ func TestRestrictedNotificationClientCapsTimeoutAndRedirects(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
func TestNotificationProxyAcceptsAuthenticatedURL(t *testing.T) {
|
||||
test := newSettingsAPITest(t)
|
||||
body := `{"telegram":{"enabled":true,"bot_token":"123456:abc","chat_id":"1","proxy":"http://user:[email protected]:8080"}}`
|
||||
recorder := test.request(t, http.MethodPut, "/api/settings/notifications", body)
|
||||
if recorder.Code != http.StatusOK {
|
||||
t.Fatalf("status = %d, body = %s", recorder.Code, recorder.Body)
|
||||
}
|
||||
response := decodeSettingsResponse(t, recorder)
|
||||
data, ok := response["data"].(map[string]any)
|
||||
if !ok {
|
||||
t.Fatalf("data missing: %#v", response)
|
||||
}
|
||||
telegram, ok := data["telegram"].(map[string]any)
|
||||
if !ok {
|
||||
t.Fatalf("telegram response missing: %#v", data)
|
||||
}
|
||||
if telegram["proxy"] != "http://user:[email protected]:8080" {
|
||||
t.Fatalf("proxy not preserved: %#v", telegram["proxy"])
|
||||
}
|
||||
}
|
||||
|
||||
func TestNotificationProxyRejectsMalformedURL(t *testing.T) {
|
||||
test := newSettingsAPITest(t)
|
||||
body := `{"telegram":{"enabled":true,"bot_token":"123456:abc","chat_id":"1","proxy":"not-a-url"}}`
|
||||
recorder := test.request(t, http.MethodPut, "/api/settings/notifications", body)
|
||||
if recorder.Code != http.StatusBadRequest {
|
||||
t.Fatalf("status = %d, body = %s", recorder.Code, recorder.Body)
|
||||
}
|
||||
response := decodeSettingsResponse(t, recorder)
|
||||
detail, ok := response["error"].(map[string]any)
|
||||
if !ok || detail["code"] != "invalid_notification_config" {
|
||||
t.Fatalf("error = %#v", detail)
|
||||
}
|
||||
}
|
||||
|
||||
func TestRouteSettingsAPIReturnsFalseForUnknownPath(t *testing.T) {
|
||||
test := newSettingsAPITest(t)
|
||||
request := httptest.NewRequest(http.MethodGet, "/api/not-settings", nil)
|
||||
|
||||
@@ -1981,7 +1981,7 @@ func (bot *telegramBot) handleATCommand(ctx context.Context, config telegramRunt
|
||||
|
||||
func (bot *telegramBot) executeATCommand(ctx context.Context, deviceID, command string) (string, error) {
|
||||
command = strings.TrimSpace(command)
|
||||
if err := validateATCommand(command); err != nil {
|
||||
if err := validateATCommand(command, false); err != nil {
|
||||
return "", err
|
||||
}
|
||||
_, _, physicalID, err := bot.device(deviceID)
|
||||
|
||||
@@ -0,0 +1,58 @@
|
||||
package server
|
||||
|
||||
import (
|
||||
"crypto/rand"
|
||||
"encoding/hex"
|
||||
"strings"
|
||||
"sync"
|
||||
"time"
|
||||
|
||||
"vocat/internal/device"
|
||||
)
|
||||
|
||||
// ussdSessionStore is the HTTP-layer counterpart of device.Manager's USSD
|
||||
// session map. A USSI awaiting-input reply opens a token here so the existing
|
||||
// continue/cancel endpoints keep working; the token only records which device
|
||||
// the dialog belongs to — the IMS session owns the actual network dialog.
|
||||
type ussdSessionStore struct {
|
||||
mu sync.Mutex
|
||||
sessions map[string]ussdServerSession
|
||||
}
|
||||
|
||||
type ussdServerSession struct {
|
||||
deviceID string
|
||||
createdAt time.Time
|
||||
}
|
||||
|
||||
func newUSSDSessionStore() ussdSessionStore {
|
||||
return ussdSessionStore{sessions: make(map[string]ussdServerSession)}
|
||||
}
|
||||
|
||||
func (store *ussdSessionStore) open(deviceID string) string {
|
||||
var token [8]byte
|
||||
_, _ = rand.Read(token[:])
|
||||
id := hex.EncodeToString(token[:])
|
||||
store.mu.Lock()
|
||||
if store.sessions == nil {
|
||||
store.sessions = make(map[string]ussdServerSession)
|
||||
}
|
||||
store.sessions[id] = ussdServerSession{deviceID: deviceID, createdAt: time.Now().UTC()}
|
||||
store.mu.Unlock()
|
||||
return id
|
||||
}
|
||||
|
||||
func (store *ussdSessionStore) device(sessionID string) (string, error) {
|
||||
store.mu.Lock()
|
||||
defer store.mu.Unlock()
|
||||
session, ok := store.sessions[strings.TrimSpace(sessionID)]
|
||||
if !ok {
|
||||
return "", device.ErrUSSDSessionNotFound
|
||||
}
|
||||
return session.deviceID, nil
|
||||
}
|
||||
|
||||
func (store *ussdSessionStore) drop(sessionID string) {
|
||||
store.mu.Lock()
|
||||
delete(store.sessions, strings.TrimSpace(sessionID))
|
||||
store.mu.Unlock()
|
||||
}
|
||||
@@ -28,38 +28,61 @@ const (
|
||||
// protocol layers consume this common result so their carrier handling cannot
|
||||
// drift into separate MCC/MNC switch statements.
|
||||
type CarrierProfile struct {
|
||||
ID string
|
||||
MatchSource string
|
||||
RouteMCC string
|
||||
RouteMNC string
|
||||
EPDG string
|
||||
IKEProposal string
|
||||
AdvertiseEAPOnly bool
|
||||
IMSTransport string
|
||||
IMSIdentityProfile string
|
||||
IMSRegisterProfile string
|
||||
IMSIPSecEncryption string
|
||||
SMSCenter string
|
||||
PANICountry string
|
||||
PANINode string
|
||||
IMSDialURIScheme string
|
||||
IMSUserEqPhone bool
|
||||
IMSVoiceCodecs []string
|
||||
ID string
|
||||
MatchSource string
|
||||
RouteMCC string
|
||||
RouteMNC string
|
||||
EPDG string
|
||||
IKEProposal string
|
||||
AdvertiseEAPOnly bool
|
||||
AllowSMSWithoutContactConfirmation bool
|
||||
IMSRegisterOptions IMSRegisterOptions
|
||||
IMSTransport string
|
||||
IMSIdentityProfile string
|
||||
IMSRegisterProfile string
|
||||
IMSIPSecEncryption string
|
||||
SMSCenter string
|
||||
PANICountry string
|
||||
PANINode string
|
||||
IMSDialURIScheme string
|
||||
IMSUserEqPhone bool
|
||||
IMSVoiceCodecs []string
|
||||
}
|
||||
|
||||
// IMSRegisterOptions carries carrier-specific SIP REGISTER header values.
|
||||
// Pointer fields distinguish "use default" (nil) from "explicitly omit" ("").
|
||||
type IMSRegisterOptions struct {
|
||||
ContactFormat string
|
||||
ExpirySeconds int
|
||||
ContactExtraTags []string
|
||||
SupportedHeader *string
|
||||
AllowHeader *string
|
||||
UserAgent string
|
||||
PPreferredIdentity bool
|
||||
PVisitedNetworkID string
|
||||
PAccessNetworkInfo *string
|
||||
CellularNetworkInfo string
|
||||
AcceptContactTags []string
|
||||
}
|
||||
|
||||
const (
|
||||
IMSContactFormatStandard = "standard"
|
||||
IMSContactFormatATT = "att"
|
||||
)
|
||||
|
||||
type carrierProfileDocument struct {
|
||||
Version int `json:"version"`
|
||||
Profiles []carrierProfileRule `json:"profiles"`
|
||||
}
|
||||
|
||||
type carrierProfileRule struct {
|
||||
ID string `json:"id"`
|
||||
Match carrierProfileMatch `json:"match,omitzero"`
|
||||
MatchAny []carrierProfileMatch `json:"match_any,omitempty"`
|
||||
Route carrierProfileRoute `json:"route,omitzero"`
|
||||
EPDG carrierProfileEPDG `json:"epdg,omitzero"`
|
||||
IKE carrierProfileIKE `json:"ike,omitzero"`
|
||||
IMS carrierProfileIMS `json:"ims,omitzero"`
|
||||
ID string `json:"id"`
|
||||
Match carrierProfileMatch `json:"match,omitzero"`
|
||||
MatchAny []carrierProfileMatch `json:"match_any,omitempty"`
|
||||
Route carrierProfileRoute `json:"route,omitzero"`
|
||||
EPDG carrierProfileEPDG `json:"epdg,omitzero"`
|
||||
IKE carrierProfileIKE `json:"ike,omitzero"`
|
||||
IMS carrierProfileIMS `json:"ims,omitzero"`
|
||||
}
|
||||
|
||||
type carrierProfileMatch struct {
|
||||
@@ -88,16 +111,32 @@ type carrierProfileIKE struct {
|
||||
}
|
||||
|
||||
type carrierProfileIMS struct {
|
||||
Transport string `json:"transport,omitempty"`
|
||||
IdentityProfile string `json:"identity_profile,omitempty"`
|
||||
RegisterProfile string `json:"register_profile,omitempty"`
|
||||
IPSecEncryption string `json:"ipsec_encryption,omitempty"`
|
||||
SMSCenter string `json:"sms_center,omitempty"`
|
||||
PANICountry string `json:"pani_country,omitempty"`
|
||||
PANINode string `json:"pani_node,omitempty"`
|
||||
DialURIScheme string `json:"dial_uri_scheme,omitempty"`
|
||||
UserEqPhone *bool `json:"user_eq_phone,omitempty"`
|
||||
VoiceCodecs []string `json:"voice_codecs,omitempty"`
|
||||
Transport string `json:"transport,omitempty"`
|
||||
IdentityProfile string `json:"identity_profile,omitempty"`
|
||||
RegisterProfile string `json:"register_profile,omitempty"`
|
||||
IPSecEncryption string `json:"ipsec_encryption,omitempty"`
|
||||
SMSCenter string `json:"sms_center,omitempty"`
|
||||
PANICountry string `json:"pani_country,omitempty"`
|
||||
PANINode string `json:"pani_node,omitempty"`
|
||||
DialURIScheme string `json:"dial_uri_scheme,omitempty"`
|
||||
UserEqPhone *bool `json:"user_eq_phone,omitempty"`
|
||||
VoiceCodecs []string `json:"voice_codecs,omitempty"`
|
||||
RegisterOptions carrierProfileRegisterOptions `json:"register_options,omitzero"`
|
||||
AllowSMSWithoutContactConfirmation *bool `json:"allow_sms_without_contact_confirmation,omitempty"`
|
||||
}
|
||||
|
||||
type carrierProfileRegisterOptions struct {
|
||||
ContactFormat string `json:"contact_format,omitempty"`
|
||||
ExpirySeconds int `json:"expiry_seconds,omitempty"`
|
||||
ContactExtraTags []string `json:"contact_extra_tags,omitempty"`
|
||||
SupportedHeader *string `json:"supported_header,omitempty"`
|
||||
AllowHeader *string `json:"allow_header,omitempty"`
|
||||
UserAgent string `json:"user_agent,omitempty"`
|
||||
PPreferredIdentity bool `json:"p_preferred_identity,omitempty"`
|
||||
PVisitedNetworkID string `json:"p_visited_network_id,omitempty"`
|
||||
PAccessNetworkInfo *string `json:"p_access_network_info,omitempty"`
|
||||
CellularNetworkInfo string `json:"cellular_network_info,omitempty"`
|
||||
AcceptContactTags []string `json:"accept_contact_tags,omitempty"`
|
||||
}
|
||||
|
||||
//go:embed carrier_profiles.json
|
||||
@@ -292,6 +331,34 @@ func validCarrierProfileRule(rule carrierProfileRule) bool {
|
||||
return false
|
||||
}
|
||||
}
|
||||
if rule.IMS.RegisterOptions.ExpirySeconds != 0 &&
|
||||
(rule.IMS.RegisterOptions.ExpirySeconds < 60 || rule.IMS.RegisterOptions.ExpirySeconds > 86400) {
|
||||
return false
|
||||
}
|
||||
if format := strings.ToLower(strings.TrimSpace(rule.IMS.RegisterOptions.ContactFormat)); format != "" &&
|
||||
format != IMSContactFormatStandard && format != IMSContactFormatATT {
|
||||
return false
|
||||
}
|
||||
for _, value := range rule.IMS.RegisterOptions.ContactExtraTags {
|
||||
if strings.ContainsAny(value, "\r\n") {
|
||||
return false
|
||||
}
|
||||
}
|
||||
for _, value := range []*string{rule.IMS.RegisterOptions.SupportedHeader, rule.IMS.RegisterOptions.AllowHeader, rule.IMS.RegisterOptions.PAccessNetworkInfo} {
|
||||
if value != nil && strings.ContainsAny(*value, "\r\n") {
|
||||
return false
|
||||
}
|
||||
}
|
||||
for _, value := range []string{rule.IMS.RegisterOptions.UserAgent, rule.IMS.RegisterOptions.PVisitedNetworkID, rule.IMS.RegisterOptions.CellularNetworkInfo} {
|
||||
if strings.ContainsAny(value, "\r\n") {
|
||||
return false
|
||||
}
|
||||
}
|
||||
for _, value := range rule.IMS.RegisterOptions.AcceptContactTags {
|
||||
if strings.ContainsAny(value, "\r\n") {
|
||||
return false
|
||||
}
|
||||
}
|
||||
return true
|
||||
}
|
||||
|
||||
@@ -470,6 +537,50 @@ func applyCarrierProfileRule(base CarrierProfile, rule carrierProfileRule, sourc
|
||||
if len(rule.IMS.VoiceCodecs) > 0 {
|
||||
base.IMSVoiceCodecs = normalizeVoiceCodecs(rule.IMS.VoiceCodecs)
|
||||
}
|
||||
if rule.IMS.AllowSMSWithoutContactConfirmation != nil {
|
||||
base.AllowSMSWithoutContactConfirmation = *rule.IMS.AllowSMSWithoutContactConfirmation
|
||||
}
|
||||
base.IMSRegisterOptions = applyRegisterOptions(base.IMSRegisterOptions, rule.IMS.RegisterOptions)
|
||||
return base
|
||||
}
|
||||
|
||||
func applyRegisterOptions(base IMSRegisterOptions, rule carrierProfileRegisterOptions) IMSRegisterOptions {
|
||||
if value := strings.ToLower(strings.TrimSpace(rule.ContactFormat)); value != "" {
|
||||
base.ContactFormat = value
|
||||
}
|
||||
if rule.ExpirySeconds != 0 {
|
||||
base.ExpirySeconds = rule.ExpirySeconds
|
||||
}
|
||||
if len(rule.ContactExtraTags) > 0 {
|
||||
base.ContactExtraTags = append([]string(nil), rule.ContactExtraTags...)
|
||||
}
|
||||
if rule.SupportedHeader != nil {
|
||||
value := strings.TrimSpace(*rule.SupportedHeader)
|
||||
base.SupportedHeader = &value
|
||||
}
|
||||
if rule.AllowHeader != nil {
|
||||
value := strings.TrimSpace(*rule.AllowHeader)
|
||||
base.AllowHeader = &value
|
||||
}
|
||||
if value := strings.TrimSpace(rule.UserAgent); value != "" {
|
||||
base.UserAgent = value
|
||||
}
|
||||
if rule.PPreferredIdentity {
|
||||
base.PPreferredIdentity = true
|
||||
}
|
||||
if value := strings.TrimSpace(rule.PVisitedNetworkID); value != "" {
|
||||
base.PVisitedNetworkID = value
|
||||
}
|
||||
if rule.PAccessNetworkInfo != nil {
|
||||
value := strings.TrimSpace(*rule.PAccessNetworkInfo)
|
||||
base.PAccessNetworkInfo = &value
|
||||
}
|
||||
if value := strings.TrimSpace(rule.CellularNetworkInfo); value != "" {
|
||||
base.CellularNetworkInfo = value
|
||||
}
|
||||
if len(rule.AcceptContactTags) > 0 {
|
||||
base.AcceptContactTags = append([]string(nil), rule.AcceptContactTags...)
|
||||
}
|
||||
return base
|
||||
}
|
||||
|
||||
|
||||
@@ -1,6 +1,9 @@
|
||||
package vowifi
|
||||
|
||||
import "testing"
|
||||
import (
|
||||
"strings"
|
||||
"testing"
|
||||
)
|
||||
|
||||
func TestAssignedRoutePLMNUsesNarrowCardAndSubscriptionMatches(t *testing.T) {
|
||||
tests := []struct {
|
||||
@@ -145,3 +148,76 @@ func TestEPDGDNSClientSubnetComesFromCarrierProfileData(t *testing.T) {
|
||||
t.Fatalf("ordinary ePDG received geographic DNS fallback %q", got)
|
||||
}
|
||||
}
|
||||
|
||||
func TestResolveCarrierProfileDITOPhilippinesUsesLegacyIKE(t *testing.T) {
|
||||
profile := ResolveCarrierProfile(SIMIdentity{HomeMCC: "515", HomeMNC: "66"})
|
||||
if profile.ID != "dito-philippines" {
|
||||
t.Fatalf("DITO profile = %#v", profile)
|
||||
}
|
||||
if profile.IKEProposal != IKEProposalLegacy {
|
||||
t.Fatalf("DITO IKE proposal = %q, want %q", profile.IKEProposal, IKEProposalLegacy)
|
||||
}
|
||||
if !profile.AllowSMSWithoutContactConfirmation {
|
||||
t.Fatalf("DITO profile should allow SMS without contact confirmation")
|
||||
}
|
||||
}
|
||||
|
||||
func TestResolveCarrierProfileATTRegisterOptions(t *testing.T) {
|
||||
profile := ResolveCarrierProfile(SIMIdentity{IMSI: "310280000000001", HomeMCC: "310", HomeMNC: "280"})
|
||||
if profile.ID != "att-us" {
|
||||
t.Fatalf("AT&T profile = %#v", profile)
|
||||
}
|
||||
if profile.IMSRegisterOptions.ContactFormat != IMSContactFormatATT {
|
||||
t.Fatalf("AT&T contact format = %q, want %q", profile.IMSRegisterOptions.ContactFormat, IMSContactFormatATT)
|
||||
}
|
||||
if profile.IMSRegisterOptions.ExpirySeconds != 18400 {
|
||||
t.Fatalf("AT&T expiry = %d, want 18400", profile.IMSRegisterOptions.ExpirySeconds)
|
||||
}
|
||||
if profile.IMSRegisterOptions.UserAgent != "SimAdmin VoWiFi" {
|
||||
t.Fatalf("AT&T user agent = %q", profile.IMSRegisterOptions.UserAgent)
|
||||
}
|
||||
if profile.IMSRegisterOptions.PVisitedNetworkID != "one.att.net" {
|
||||
t.Fatalf("AT&T P-Visited-Network-ID = %q", profile.IMSRegisterOptions.PVisitedNetworkID)
|
||||
}
|
||||
if len(profile.IMSRegisterOptions.AcceptContactTags) != 2 {
|
||||
t.Fatalf("AT&T Accept-Contact tags = %v", profile.IMSRegisterOptions.AcceptContactTags)
|
||||
}
|
||||
}
|
||||
|
||||
func TestResolveCarrierProfileO2GermanyRegisterOptions(t *testing.T) {
|
||||
profile := ResolveCarrierProfile(SIMIdentity{HomeMCC: "262", HomeMNC: "03"})
|
||||
if profile.ID != "o2-germany" {
|
||||
t.Fatalf("O2 Germany profile = %#v", profile)
|
||||
}
|
||||
if profile.IMSRegisterOptions.ContactFormat != "" {
|
||||
t.Fatalf("O2 Germany contact format = %q, want empty", profile.IMSRegisterOptions.ContactFormat)
|
||||
}
|
||||
if profile.IMSRegisterOptions.SupportedHeader == nil || !strings.Contains(*profile.IMSRegisterOptions.SupportedHeader, "sec-agree") {
|
||||
t.Fatalf("O2 Germany Supported header = %v", profile.IMSRegisterOptions.SupportedHeader)
|
||||
}
|
||||
if profile.IMSRegisterOptions.AllowHeader == nil || !strings.Contains(*profile.IMSRegisterOptions.AllowHeader, "MESSAGE") {
|
||||
t.Fatalf("O2 Germany Allow header = %v", profile.IMSRegisterOptions.AllowHeader)
|
||||
}
|
||||
if !profile.IMSRegisterOptions.PPreferredIdentity {
|
||||
t.Fatal("O2 Germany should add P-Preferred-Identity")
|
||||
}
|
||||
}
|
||||
|
||||
func TestResolveCarrierProfileStandardHasNoRegisterOverrides(t *testing.T) {
|
||||
profile := ResolveCarrierProfile(SIMIdentity{HomeMCC: "001", HomeMNC: "01"})
|
||||
if profile.ID != CarrierProfileStandard {
|
||||
t.Fatalf("profile = %q", profile.ID)
|
||||
}
|
||||
if profile.IMSRegisterOptions.ExpirySeconds != 0 {
|
||||
t.Fatalf("standard expiry = %d", profile.IMSRegisterOptions.ExpirySeconds)
|
||||
}
|
||||
if profile.IMSRegisterOptions.ContactFormat != "" {
|
||||
t.Fatalf("standard contact format = %q", profile.IMSRegisterOptions.ContactFormat)
|
||||
}
|
||||
if profile.IMSRegisterOptions.SupportedHeader != nil {
|
||||
t.Fatalf("standard supported header = %v", *profile.IMSRegisterOptions.SupportedHeader)
|
||||
}
|
||||
if profile.AllowSMSWithoutContactConfirmation {
|
||||
t.Fatal("standard profile should require SMS contact confirmation")
|
||||
}
|
||||
}
|
||||
|
||||
@@ -36,7 +36,22 @@
|
||||
"ims": {
|
||||
"identity_profile": "att",
|
||||
"register_profile": "att",
|
||||
"ipsec_encryption": "aes-cbc"
|
||||
"ipsec_encryption": "aes-cbc",
|
||||
"register_options": {
|
||||
"contact_format": "att",
|
||||
"expiry_seconds": 18400,
|
||||
"contact_extra_tags": ["+g.3gpp.accesstype=\"wlan1\""],
|
||||
"supported_header": "path,sec-agree,gruu",
|
||||
"user_agent": "SimAdmin VoWiFi",
|
||||
"p_preferred_identity": true,
|
||||
"p_visited_network_id": "one.att.net",
|
||||
"p_access_network_info": "IEEE-802.11;i-wlan-node-id=000000000000;network-provided",
|
||||
"cellular_network_info": "3GPP-E-UTRAN-FDD;utran-cell-id-3gpp=3102800000000;cell-info-age=0",
|
||||
"accept_contact_tags": [
|
||||
"*;+g.3gpp.smsip",
|
||||
"*;+g.3gpp.icsi-ref=\"urn%3Aurn-7%3A3gpp-service.ims.icsi.mmtel\""
|
||||
]
|
||||
}
|
||||
}
|
||||
},
|
||||
{
|
||||
@@ -45,7 +60,12 @@
|
||||
"ike": { "advertise_eap_only": false },
|
||||
"ims": {
|
||||
"register_profile": "o2-germany",
|
||||
"ipsec_encryption": "null"
|
||||
"ipsec_encryption": "null",
|
||||
"register_options": {
|
||||
"supported_header": "path, gruu, outbound, sec-agree, 100rel, timer",
|
||||
"allow_header": "INVITE, ACK, CANCEL, BYE, PRACK, UPDATE, INFO, MESSAGE, OPTIONS",
|
||||
"p_preferred_identity": true
|
||||
}
|
||||
}
|
||||
},
|
||||
{
|
||||
@@ -93,6 +113,14 @@
|
||||
"dns_hosts": ["epdg.epc.mnc002.mcc262.pub.3gppnetwork.org"],
|
||||
"dns_client_subnet": "109.192.0.0/24"
|
||||
}
|
||||
},
|
||||
{
|
||||
"id": "dito-philippines",
|
||||
"match": { "home_plmns": ["51566"] },
|
||||
"ike": { "proposal": "legacy-sha1-modp1024" },
|
||||
"ims": {
|
||||
"allow_sms_without_contact_confirmation": true
|
||||
}
|
||||
}
|
||||
]
|
||||
}
|
||||
|
||||
@@ -188,34 +188,60 @@ func (provider *Provider) start(ctx context.Context, request vowifi.TunnelReques
|
||||
makeNotify(notifyNATSource, sourceHash),
|
||||
makeNotify(notifyNATDestination, destinationHash),
|
||||
}
|
||||
first, initBody, err := marshalPayloadChain(initPayloads)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
initRequest := ikeHeader{
|
||||
InitiatorSPI: initiatorSPI,
|
||||
NextPayload: first,
|
||||
Exchange: exchangeIKEInit,
|
||||
Flags: flagInitiator,
|
||||
MessageID: 0,
|
||||
}.marshal(initBody)
|
||||
initResponse, err := transport.RoundTrip(ctx, initRequest)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
responseHeader, responseBody, err := validateResponse(initResponse, initiatorSPI, [8]byte{}, exchangeIKEInit, 0)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
if responseHeader.ResponderSPI == [8]byte{} {
|
||||
return nil, errors.New("ike: responder returned a zero SPI")
|
||||
}
|
||||
initResponsePayloads, err := parsePayloadChain(responseHeader.NextPayload, responseBody)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
if err := rejectFatalNotifications(initResponsePayloads); err != nil {
|
||||
return nil, err
|
||||
var (
|
||||
initRequest []byte
|
||||
initResponse []byte
|
||||
responseHeader ikeHeader
|
||||
initResponsePayloads []payload
|
||||
cookie []byte
|
||||
)
|
||||
for attempt := 0; attempt < maxIKEInitCookieChallenges; attempt++ {
|
||||
requestPayloads := append([]payload(nil), initPayloads...)
|
||||
if len(cookie) > 0 {
|
||||
requestPayloads = append([]payload{makeNotify(notifyCookie, cookie)}, requestPayloads...)
|
||||
}
|
||||
first, initBody, err := marshalPayloadChain(requestPayloads)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
initRequest = ikeHeader{
|
||||
InitiatorSPI: initiatorSPI,
|
||||
NextPayload: first,
|
||||
Exchange: exchangeIKEInit,
|
||||
Flags: flagInitiator,
|
||||
MessageID: 0,
|
||||
}.marshal(initBody)
|
||||
initResponse, err = transport.RoundTrip(ctx, initRequest)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
var responseBody []byte
|
||||
responseHeader, responseBody, err = validateResponse(initResponse, initiatorSPI, [8]byte{}, exchangeIKEInit, 0)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
initResponsePayloads, err = parsePayloadChain(responseHeader.NextPayload, responseBody)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
if err := rejectFatalNotifications(initResponsePayloads); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
challenge, hasCookie, err := ikeInitCookie(initResponsePayloads)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
if hasCookie {
|
||||
if attempt+1 == maxIKEInitCookieChallenges {
|
||||
return nil, errors.New("ike: ePDG requested too many COOKIE challenges")
|
||||
}
|
||||
cookie = challenge
|
||||
continue
|
||||
}
|
||||
if responseHeader.ResponderSPI == [8]byte{} {
|
||||
return nil, errors.New("ike: responder returned a zero SPI")
|
||||
}
|
||||
break
|
||||
}
|
||||
saPayload, err := onePayload(initResponsePayloads, payloadSA)
|
||||
if err != nil {
|
||||
@@ -616,6 +642,29 @@ func (provider *Provider) start(ctx context.Context, request vowifi.TunnelReques
|
||||
return session, nil
|
||||
}
|
||||
|
||||
const maxIKEInitCookieChallenges = 2
|
||||
|
||||
func ikeInitCookie(payloads []payload) ([]byte, bool, error) {
|
||||
var cookie []byte
|
||||
for _, item := range payloadsOfType(payloads, payloadNotify) {
|
||||
kind, data, err := parseNotify(item)
|
||||
if err != nil {
|
||||
return nil, false, err
|
||||
}
|
||||
if kind != notifyCookie {
|
||||
continue
|
||||
}
|
||||
if len(data) == 0 {
|
||||
return nil, false, errors.New("ike: ePDG returned an empty COOKIE")
|
||||
}
|
||||
if cookie != nil {
|
||||
return nil, false, errors.New("ike: ePDG returned multiple COOKIE notifications")
|
||||
}
|
||||
cookie = append([]byte(nil), data...)
|
||||
}
|
||||
return cookie, cookie != nil, nil
|
||||
}
|
||||
|
||||
func buildInitialEAPAuth(
|
||||
idi payload,
|
||||
requestedIDr payload,
|
||||
|
||||
@@ -4,8 +4,10 @@ import (
|
||||
"bytes"
|
||||
"context"
|
||||
"errors"
|
||||
"fmt"
|
||||
"io"
|
||||
"net"
|
||||
"strings"
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
@@ -64,17 +66,20 @@ func (reader constantReader) Read(destination []byte) (int, error) {
|
||||
}
|
||||
|
||||
type firstAuthCaptureTransport struct {
|
||||
t *testing.T
|
||||
wantEAPOnly bool
|
||||
wantGroup uint16
|
||||
calls int
|
||||
suite negotiatedSuite
|
||||
keys ikeKeys
|
||||
spii [8]byte
|
||||
spir [8]byte
|
||||
nonceI []byte
|
||||
nonceR []byte
|
||||
floated bool
|
||||
t *testing.T
|
||||
wantEAPOnly bool
|
||||
wantGroup uint16
|
||||
calls int
|
||||
suite negotiatedSuite
|
||||
keys ikeKeys
|
||||
spii [8]byte
|
||||
spir [8]byte
|
||||
nonceI []byte
|
||||
nonceR []byte
|
||||
floated bool
|
||||
cookieChallenge []byte
|
||||
cookieSeen bool
|
||||
cookieLoop bool
|
||||
}
|
||||
|
||||
func (transport *firstAuthCaptureTransport) LocalAddr() *net.UDPAddr {
|
||||
@@ -92,6 +97,24 @@ func (transport *firstAuthCaptureTransport) Float(context.Context) error {
|
||||
|
||||
func (transport *firstAuthCaptureTransport) RoundTrip(_ context.Context, packet []byte) ([]byte, error) {
|
||||
transport.calls++
|
||||
if len(transport.cookieChallenge) > 0 {
|
||||
switch transport.calls {
|
||||
case 1:
|
||||
return transport.answerIKECookie(packet)
|
||||
case 2:
|
||||
if err := transport.verifyIKECookie(packet); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
if transport.cookieLoop {
|
||||
return transport.answerIKECookie(packet)
|
||||
}
|
||||
return transport.answerIKEInit(packet)
|
||||
case 3:
|
||||
return nil, transport.observeFirstAuth(packet)
|
||||
default:
|
||||
return nil, errors.New("test: unexpected exchange")
|
||||
}
|
||||
}
|
||||
switch transport.calls {
|
||||
case 1:
|
||||
return transport.answerIKEInit(packet)
|
||||
@@ -102,6 +125,69 @@ func (transport *firstAuthCaptureTransport) RoundTrip(_ context.Context, packet
|
||||
}
|
||||
}
|
||||
|
||||
func (transport *firstAuthCaptureTransport) answerIKECookie(packet []byte) ([]byte, error) {
|
||||
header, _, err := parseIKEPacket(packet)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
first, body, err := marshalPayloadChain([]payload{
|
||||
makeNotify(notifyCookie, transport.cookieChallenge),
|
||||
})
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
return ikeHeader{
|
||||
InitiatorSPI: header.InitiatorSPI,
|
||||
NextPayload: first,
|
||||
Exchange: exchangeIKEInit,
|
||||
Flags: flagResponse,
|
||||
MessageID: 0,
|
||||
}.marshal(body), nil
|
||||
}
|
||||
|
||||
func (transport *firstAuthCaptureTransport) verifyIKECookie(packet []byte) error {
|
||||
header, body, err := parseIKEPacket(packet)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
if header.Exchange != exchangeIKEInit || header.MessageID != 0 || header.Flags != flagInitiator {
|
||||
return errors.New("test: invalid retried IKE_SA_INIT header")
|
||||
}
|
||||
payloads, err := parsePayloadChain(header.NextPayload, body)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
if len(payloads) == 0 || payloads[0].Type != payloadNotify {
|
||||
return errors.New("test: retried IKE_SA_INIT did not put COOKIE first")
|
||||
}
|
||||
firstKind, firstData, err := parseNotify(payloads[0])
|
||||
if err != nil || firstKind != notifyCookie || !bytes.Equal(firstData, transport.cookieChallenge) {
|
||||
return errors.New("test: first retried IKE_SA_INIT payload is not the expected COOKIE")
|
||||
}
|
||||
cookies := payloadsOfType(payloads, payloadNotify)
|
||||
if len(cookies) != 3 {
|
||||
return fmt.Errorf("test: retried IKE_SA_INIT has %d notify payloads, want 3", len(cookies))
|
||||
}
|
||||
found := false
|
||||
for _, item := range cookies {
|
||||
kind, data, err := parseNotify(item)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
if kind == notifyCookie {
|
||||
if !bytes.Equal(data, transport.cookieChallenge) {
|
||||
return fmt.Errorf("test: cookie = %x, want %x", data, transport.cookieChallenge)
|
||||
}
|
||||
found = true
|
||||
}
|
||||
}
|
||||
if !found {
|
||||
return errors.New("test: retried IKE_SA_INIT did not carry COOKIE")
|
||||
}
|
||||
transport.cookieSeen = true
|
||||
return nil
|
||||
}
|
||||
|
||||
func (transport *firstAuthCaptureTransport) answerIKEInit(packet []byte) ([]byte, error) {
|
||||
header, body, err := parseIKEPacket(packet)
|
||||
if err != nil {
|
||||
@@ -291,6 +377,93 @@ func TestProviderVodafoneFirstAuthIsEAPOnlyAndRequestsIMSAPN(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
func TestProviderRetriesIKEInitAfterCookie(t *testing.T) {
|
||||
capture := &firstAuthCaptureTransport{
|
||||
t: t,
|
||||
wantEAPOnly: true,
|
||||
cookieChallenge: []byte{0x10, 0x20, 0x30, 0x40},
|
||||
}
|
||||
provider, err := NewProvider(Config{
|
||||
Random: constantReader{value: 0x42},
|
||||
Timeout: time.Second,
|
||||
Installer: unusedInstaller{},
|
||||
APN: "ims",
|
||||
})
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
provider.transportFactory = func(
|
||||
context.Context,
|
||||
transportConfig,
|
||||
vowifi.ProxyRoute,
|
||||
string,
|
||||
) (datagramTransport, error) {
|
||||
return capture, nil
|
||||
}
|
||||
aka := &testAKAProvider{}
|
||||
_, err = provider.Start(context.Background(), vowifi.TunnelRequest{
|
||||
DeviceID: "ec20-cookie",
|
||||
Identity: vowifi.SIMIdentity{
|
||||
ICCID: "8944100000000000000",
|
||||
IMSI: "234150123456789",
|
||||
HomeMCC: "234",
|
||||
HomeMNC: "15",
|
||||
},
|
||||
EPDG: "epdg.epc.mnc015.mcc234.pub.3gppnetwork.org",
|
||||
AKA: aka,
|
||||
})
|
||||
if !errors.Is(err, errFirstAuthObserved) {
|
||||
t.Fatalf("Start() error = %v, want capture sentinel", err)
|
||||
}
|
||||
if capture.calls != 3 || !capture.cookieSeen || capture.floated || aka.calls != 0 {
|
||||
t.Fatalf("capture calls=%d cookie_seen=%v floated=%v AKA calls=%d", capture.calls, capture.cookieSeen, capture.floated, aka.calls)
|
||||
}
|
||||
}
|
||||
|
||||
func TestProviderBoundsRepeatedIKEInitCookieChallenges(t *testing.T) {
|
||||
capture := &firstAuthCaptureTransport{
|
||||
t: t,
|
||||
wantEAPOnly: true,
|
||||
cookieChallenge: []byte{0x10, 0x20, 0x30, 0x40},
|
||||
cookieLoop: true,
|
||||
}
|
||||
provider, err := NewProvider(Config{
|
||||
Random: constantReader{value: 0x42},
|
||||
Timeout: time.Second,
|
||||
Installer: unusedInstaller{},
|
||||
APN: "ims",
|
||||
})
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
provider.transportFactory = func(
|
||||
context.Context,
|
||||
transportConfig,
|
||||
vowifi.ProxyRoute,
|
||||
string,
|
||||
) (datagramTransport, error) {
|
||||
return capture, nil
|
||||
}
|
||||
aka := &testAKAProvider{}
|
||||
_, err = provider.Start(context.Background(), vowifi.TunnelRequest{
|
||||
DeviceID: "ec20-cookie-loop",
|
||||
Identity: vowifi.SIMIdentity{
|
||||
ICCID: "8944100000000000000",
|
||||
IMSI: "234150123456789",
|
||||
HomeMCC: "234",
|
||||
HomeMNC: "15",
|
||||
},
|
||||
EPDG: "epdg.epc.mnc015.mcc234.pub.3gppnetwork.org",
|
||||
AKA: aka,
|
||||
})
|
||||
if err == nil || !strings.Contains(err.Error(), "too many COOKIE challenges") {
|
||||
t.Fatalf("Start() error = %v, want bounded COOKIE error", err)
|
||||
}
|
||||
if capture.calls != maxIKEInitCookieChallenges || aka.calls != 0 {
|
||||
t.Fatalf("capture calls=%d AKA calls=%d", capture.calls, aka.calls)
|
||||
}
|
||||
}
|
||||
|
||||
func TestProviderO2GermanyFirstAuthUsesStandardEAPAndRequestsIMSAPN(t *testing.T) {
|
||||
capture := &firstAuthCaptureTransport{t: t, wantEAPOnly: false, wantGroup: dhMODP2048}
|
||||
provider, err := NewProvider(Config{
|
||||
|
||||
@@ -576,10 +576,17 @@ func (transport *socks5UDP) RoundTrip(ctx context.Context, packet []byte) ([]byt
|
||||
// Once a gateway answers, keep it pinned for the lifetime of the IKE SA.
|
||||
if !transport.floated && requestHeader.Exchange == exchangeIKEInit && requestHeader.MessageID == 0 && len(transport.remotes) > 1 {
|
||||
var lastErr error
|
||||
var cookieResponse []byte
|
||||
for _, candidate := range transport.remotes {
|
||||
transport.remote = cloneUDPAddr(candidate)
|
||||
response, attemptErr := transport.roundTripLocked(ctx, packet, requestHeader)
|
||||
if attemptErr == nil {
|
||||
if ikeInitResponseHasCookie(response) {
|
||||
if cookieResponse == nil {
|
||||
cookieResponse = append([]byte(nil), response...)
|
||||
}
|
||||
continue
|
||||
}
|
||||
return response, nil
|
||||
}
|
||||
lastErr = attemptErr
|
||||
@@ -587,6 +594,9 @@ func (transport *socks5UDP) RoundTrip(ctx context.Context, packet []byte) ([]byt
|
||||
return nil, attemptErr
|
||||
}
|
||||
}
|
||||
if cookieResponse != nil {
|
||||
return cookieResponse, nil
|
||||
}
|
||||
return nil, fmt.Errorf("ike: all %d resolved ePDG addresses timed out: %w", len(transport.remotes), lastErr)
|
||||
}
|
||||
return transport.roundTripLocked(ctx, packet, requestHeader)
|
||||
@@ -824,11 +834,34 @@ func ikeResponseMatchesRequest(
|
||||
}
|
||||
var zeroSPI [8]byte
|
||||
if request.ResponderSPI == zeroSPI {
|
||||
return response.ResponderSPI != zeroSPI
|
||||
if response.ResponderSPI != zeroSPI {
|
||||
return true
|
||||
}
|
||||
return response.Exchange == exchangeIKEInit &&
|
||||
response.MessageID == 0 &&
|
||||
ikeInitResponseHasCookie(packet)
|
||||
}
|
||||
return response.ResponderSPI == request.ResponderSPI
|
||||
}
|
||||
|
||||
func ikeInitResponseHasCookie(packet []byte) bool {
|
||||
header, body, err := parseIKEPacket(packet)
|
||||
if err != nil || header.Exchange != exchangeIKEInit || header.MessageID != 0 {
|
||||
return false
|
||||
}
|
||||
payloads, err := parsePayloadChain(header.NextPayload, body)
|
||||
if err != nil {
|
||||
return false
|
||||
}
|
||||
for _, item := range payloadsOfType(payloads, payloadNotify) {
|
||||
kind, data, err := parseNotify(item)
|
||||
if err == nil && kind == notifyCookie && len(data) > 0 {
|
||||
return true
|
||||
}
|
||||
}
|
||||
return false
|
||||
}
|
||||
|
||||
func marshalSOCKS5Datagram(remote *net.UDPAddr, payload []byte) ([]byte, error) {
|
||||
if remote == nil || remote.IP == nil || remote.Port < 1 || remote.Port > 65535 {
|
||||
return nil, errors.New("ike: invalid SOCKS5 UDP destination")
|
||||
|
||||
@@ -145,6 +145,18 @@ func TestSOCKS5InitialExchangeFallsBackAcrossResolvedEPDGAddresses(t *testing.T)
|
||||
Exchange: exchangeIKEInit,
|
||||
Flags: flagResponse,
|
||||
}.marshal([]byte("response"))
|
||||
cookieFirst, cookieBody, err := marshalPayloadChain([]payload{
|
||||
makeNotify(notifyCookie, []byte{0x10, 0x20, 0x30, 0x40}),
|
||||
})
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
cookieResponse := ikeHeader{
|
||||
InitiatorSPI: requestHeader.InitiatorSPI,
|
||||
NextPayload: cookieFirst,
|
||||
Exchange: exchangeIKEInit,
|
||||
Flags: flagResponse,
|
||||
}.marshal(cookieBody)
|
||||
serverDone := make(chan error, 1)
|
||||
go func() {
|
||||
buffer := make([]byte, 2048)
|
||||
@@ -160,6 +172,14 @@ func TestSOCKS5InitialExchangeFallsBackAcrossResolvedEPDGAddresses(t *testing.T)
|
||||
return
|
||||
}
|
||||
if !destination.IP.Equal(second.IP) {
|
||||
cookieWire, marshalErr := marshalSOCKS5Datagram(first, cookieResponse)
|
||||
if marshalErr == nil {
|
||||
_, marshalErr = relay.WriteToUDP(cookieWire, peer)
|
||||
}
|
||||
if marshalErr != nil {
|
||||
serverDone <- marshalErr
|
||||
return
|
||||
}
|
||||
continue
|
||||
}
|
||||
wire, marshalErr := marshalSOCKS5Datagram(second, response)
|
||||
@@ -186,6 +206,31 @@ func TestSOCKS5InitialExchangeFallsBackAcrossResolvedEPDGAddresses(t *testing.T)
|
||||
}
|
||||
}
|
||||
|
||||
func TestIKEResponseMatchesCookieChallengeWithZeroResponderSPI(t *testing.T) {
|
||||
request := ikeHeader{
|
||||
InitiatorSPI: [8]byte{1, 2, 3, 4, 5, 6, 7, 8},
|
||||
Exchange: exchangeIKEInit,
|
||||
Flags: flagInitiator,
|
||||
MessageID: 0,
|
||||
}
|
||||
first, body, err := marshalPayloadChain([]payload{
|
||||
makeNotify(notifyCookie, []byte{0x10, 0x20, 0x30, 0x40}),
|
||||
})
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
response := ikeHeader{
|
||||
InitiatorSPI: request.InitiatorSPI,
|
||||
Exchange: exchangeIKEInit,
|
||||
Flags: flagResponse,
|
||||
MessageID: 0,
|
||||
NextPayload: first,
|
||||
}.marshal(body)
|
||||
if !ikeResponseMatchesRequest(response, request) {
|
||||
t.Fatal("IKE COOKIE response with zero Responder SPI was rejected")
|
||||
}
|
||||
}
|
||||
|
||||
func TestSOCKS5RoundTripSkipsStaleAndESPDatagrams(t *testing.T) {
|
||||
relay, err := net.ListenUDP(
|
||||
"udp",
|
||||
|
||||
@@ -59,6 +59,7 @@ const (
|
||||
notifyMOBIKESupported = 16396
|
||||
notifyNATSource = 16388
|
||||
notifyNATDestination = 16389
|
||||
notifyCookie = 16390
|
||||
notifyEAPOnlyAuth = 16417
|
||||
notifyDeviceIdentity = 41101
|
||||
notifyInvalidKE = 17
|
||||
|
||||
+102
-60
@@ -66,6 +66,10 @@ type Config struct {
|
||||
// OnSMSStatus is invoked for an SMS-STATUS-REPORT received after a
|
||||
// submission that requested a delivery report.
|
||||
OnSMSStatus func(context.Context, ReceivedSMSStatus) error
|
||||
// OnUSSD is invoked for a network-originated USSD MESSAGE received over
|
||||
// IMS (3GPP TS 24.390). Returning an error is logged but does not affect
|
||||
// the 200 OK already sent, because USSI has no RP-ACK transport.
|
||||
OnUSSD func(context.Context, ReceivedUSSD) error
|
||||
// Logger receives structured IMS runtime diagnostics. Inbound SMS logs do
|
||||
// not include message text or raw protocol payloads.
|
||||
Logger *slog.Logger
|
||||
@@ -704,10 +708,6 @@ func securityEncryptionForIdentity(identity vowifi.SIMIdentity) string {
|
||||
return vowifi.ResolveCarrierProfile(identity).IMSIPSecEncryption
|
||||
}
|
||||
|
||||
func usesO2GermanyIMSProfile(identity vowifi.SIMIdentity) bool {
|
||||
return vowifi.ResolveCarrierProfile(identity).IMSRegisterProfile == vowifi.IMSProfileO2Germany
|
||||
}
|
||||
|
||||
func (session *Session) abort() {
|
||||
session.refreshCancel()
|
||||
_ = session.conn.Close()
|
||||
@@ -911,9 +911,10 @@ func (session *Session) buildRegister(
|
||||
authorizationHeader string,
|
||||
authorization string,
|
||||
) ([]byte, error) {
|
||||
att310280 := vowifi.IsATT310280(session.request.Identity)
|
||||
if att310280 {
|
||||
expires = 18400
|
||||
profile := vowifi.ResolveCarrierProfile(session.request.Identity)
|
||||
registerOptions := profile.IMSRegisterOptions
|
||||
if registerOptions.ExpirySeconds != 0 {
|
||||
expires = registerOptions.ExpirySeconds
|
||||
}
|
||||
branch, err := randomHex(12)
|
||||
if err != nil {
|
||||
@@ -924,43 +925,25 @@ func (session *Session) buildRegister(
|
||||
transportUpper := strings.ToUpper(session.transport)
|
||||
requestURI := "sip:" + session.identity.domain
|
||||
routeURI := "sip:" + session.endpoint.address() + ";transport=" + session.transport + ";lr"
|
||||
contact := fmt.Sprintf(
|
||||
"<sip:%s@%s;transport=%s>;+sip.instance=\"<%s>\";+g.3gpp.smsip;audio;"+
|
||||
`+g.3gpp.icsi-ref="%s"`,
|
||||
session.identity.user,
|
||||
contactAddress,
|
||||
session.transport,
|
||||
session.instanceID,
|
||||
"urn%3Aurn-7%3A3gpp-service.ims.icsi.mmtel",
|
||||
)
|
||||
if att310280 {
|
||||
contact = fmt.Sprintf(
|
||||
`<sip:%s@%s;transport=%s>;+g.3gpp.accesstype="wlan1";audio;+g.3gpp.smsip;`+
|
||||
`+g.3gpp.icsi-ref="%s";+sip.instance="<%s>"`,
|
||||
session.identity.user,
|
||||
contactAddress,
|
||||
session.transport,
|
||||
"urn%3Aurn-7%3A3gpp-service.ims.icsi.mmtel",
|
||||
session.instanceID,
|
||||
)
|
||||
contact := session.buildContact(contactAddress, registerOptions)
|
||||
|
||||
defaultSupported := "path, gruu"
|
||||
defaultAllow := "REGISTER, INVITE, ACK, CANCEL, BYE, OPTIONS, MESSAGE, SUBSCRIBE, NOTIFY"
|
||||
supported := defaultSupported
|
||||
if registerOptions.SupportedHeader != nil {
|
||||
supported = *registerOptions.SupportedHeader
|
||||
}
|
||||
o2Germany := usesO2GermanyIMSProfile(session.request.Identity)
|
||||
supported := "path, gruu"
|
||||
allow := "REGISTER, INVITE, ACK, CANCEL, BYE, OPTIONS, MESSAGE, SUBSCRIBE, NOTIFY"
|
||||
if o2Germany {
|
||||
// Match the complete IMS capability set used by the previously working
|
||||
// VoHive client. O2 validates more of the initial UE security profile
|
||||
// than the other tested carriers do.
|
||||
supported = "path, gruu, outbound, sec-agree, 100rel, timer"
|
||||
allow = "INVITE, ACK, CANCEL, BYE, PRACK, UPDATE, INFO, MESSAGE, OPTIONS"
|
||||
}
|
||||
if att310280 {
|
||||
supported = "path,sec-agree,gruu"
|
||||
allow := defaultAllow
|
||||
if registerOptions.AllowHeader != nil {
|
||||
allow = *registerOptions.AllowHeader
|
||||
}
|
||||
|
||||
userAgent := strings.TrimSpace(session.provider.config.UserAgent)
|
||||
if att310280 && (userAgent == "" || userAgent == "vocat/1") {
|
||||
userAgent = "SimAdmin VoWiFi"
|
||||
if override := strings.TrimSpace(registerOptions.UserAgent); override != "" &&
|
||||
(userAgent == "" || userAgent == "vocat/1") {
|
||||
userAgent = override
|
||||
}
|
||||
|
||||
lines := []string{
|
||||
"REGISTER " + requestURI + " SIP/2.0",
|
||||
fmt.Sprintf("Via: SIP/2.0/%s %s;branch=z9hG4bK%s;rport", transportUpper, local, branch),
|
||||
@@ -972,28 +955,45 @@ func (session *Session) buildRegister(
|
||||
fmt.Sprintf("CSeq: %d REGISTER", cseq),
|
||||
"Contact: " + contact,
|
||||
fmt.Sprintf("Expires: %d", expires),
|
||||
"Supported: " + supported,
|
||||
"Allow: " + allow,
|
||||
"User-Agent: " + userAgent,
|
||||
}
|
||||
if o2Germany {
|
||||
if supported != "" {
|
||||
lines = append(lines, "Supported: "+supported)
|
||||
}
|
||||
if allow != "" {
|
||||
lines = append(lines, "Allow: "+allow)
|
||||
}
|
||||
lines = append(lines, "User-Agent: "+userAgent)
|
||||
|
||||
defaultPANI := "IEEE-802.11;i-wlan-node-id=000000000000;network-provided"
|
||||
pani := defaultPANI
|
||||
if registerOptions.PAccessNetworkInfo != nil {
|
||||
pani = *registerOptions.PAccessNetworkInfo
|
||||
}
|
||||
|
||||
if registerOptions.PPreferredIdentity {
|
||||
lines = append(lines, "P-Preferred-Identity: <"+session.identity.public+">")
|
||||
} else if att310280 {
|
||||
lines = append(lines,
|
||||
"P-Preferred-Identity: <"+session.identity.public+">",
|
||||
`P-Visited-Network-ID: "one.att.net"`,
|
||||
"P-Access-Network-Info: IEEE-802.11;i-wlan-node-id=000000000000;network-provided",
|
||||
"Cellular-Network-Info: 3GPP-E-UTRAN-FDD;utran-cell-id-3gpp=3102800000000;cell-info-age=0",
|
||||
"Accept-Contact: *;+g.3gpp.smsip",
|
||||
`Accept-Contact: *;+g.3gpp.icsi-ref="urn%3Aurn-7%3A3gpp-service.ims.icsi.mmtel"`,
|
||||
)
|
||||
} else {
|
||||
lines = append(lines,
|
||||
"P-Access-Network-Info: IEEE-802.11;i-wlan-node-id=000000000000;network-provided",
|
||||
"Accept-Contact: *;+g.3gpp.smsip",
|
||||
`Accept-Contact: *;+g.3gpp.icsi-ref="urn%3Aurn-7%3A3gpp-service.ims.icsi.mmtel"`,
|
||||
)
|
||||
}
|
||||
if value := strings.TrimSpace(registerOptions.PVisitedNetworkID); value != "" {
|
||||
lines = append(lines, `P-Visited-Network-ID: "`+value+`"`)
|
||||
}
|
||||
if pani != "" {
|
||||
lines = append(lines, "P-Access-Network-Info: "+pani)
|
||||
}
|
||||
if value := strings.TrimSpace(registerOptions.CellularNetworkInfo); value != "" {
|
||||
lines = append(lines, "Cellular-Network-Info: "+value)
|
||||
}
|
||||
|
||||
acceptContactTags := []string{
|
||||
"*;+g.3gpp.smsip",
|
||||
`*;+g.3gpp.icsi-ref="urn%3Aurn-7%3A3gpp-service.ims.icsi.mmtel"`,
|
||||
}
|
||||
if registerOptions.AcceptContactTags != nil {
|
||||
acceptContactTags = registerOptions.AcceptContactTags
|
||||
}
|
||||
for _, tag := range acceptContactTags {
|
||||
lines = append(lines, "Accept-Contact: "+tag)
|
||||
}
|
||||
|
||||
if session.securityOffered() {
|
||||
lines = append(lines,
|
||||
"Security-Client: "+session.securityClientValue(),
|
||||
@@ -1020,6 +1020,33 @@ func (session *Session) buildRegister(
|
||||
return []byte(strings.Join(lines, "\r\n")), nil
|
||||
}
|
||||
|
||||
func (session *Session) buildContact(contactAddress string, registerOptions vowifi.IMSRegisterOptions) string {
|
||||
base := fmt.Sprintf("<sip:%s@%s;transport=%s>", session.identity.user, contactAddress, session.transport)
|
||||
instanceID := session.instanceID
|
||||
icsiRef := "urn%3Aurn-7%3A3gpp-service.ims.icsi.mmtel"
|
||||
|
||||
switch registerOptions.ContactFormat {
|
||||
case vowifi.IMSContactFormatATT:
|
||||
extra := ""
|
||||
for _, tag := range registerOptions.ContactExtraTags {
|
||||
extra += ";" + tag
|
||||
}
|
||||
return fmt.Sprintf(
|
||||
`%s%s;audio;+g.3gpp.smsip;+g.3gpp.icsi-ref="%s";+sip.instance="<%s>"`,
|
||||
base, extra, icsiRef, instanceID,
|
||||
)
|
||||
default:
|
||||
extra := ""
|
||||
for _, tag := range registerOptions.ContactExtraTags {
|
||||
extra += ";" + tag
|
||||
}
|
||||
return fmt.Sprintf(
|
||||
`%s;+sip.instance="<%s>";+g.3gpp.smsip;audio;+g.3gpp.icsi-ref="%s"%s`,
|
||||
base, instanceID, icsiRef, extra,
|
||||
)
|
||||
}
|
||||
}
|
||||
|
||||
func (session *Session) exchange(ctx context.Context, request []byte, cseq uint32) (*sipResponse, error) {
|
||||
if err := ctx.Err(); err != nil {
|
||||
return nil, err
|
||||
@@ -1372,13 +1399,28 @@ func (session *Session) EnableSMS(ctx context.Context) (vowifi.SMSEvidence, erro
|
||||
return vowifi.SMSEvidence{}, vowifi.ErrIMSNotRegistered
|
||||
case !session.expiresAt.IsZero() && !time.Now().Before(session.expiresAt):
|
||||
return vowifi.SMSEvidence{}, ErrRegistrationExpired
|
||||
case !session.smsContactConfirmed:
|
||||
case !session.smsCapabilityReady():
|
||||
return vowifi.SMSEvidence{Ready: false}, ErrSMSCapabilityNotConfirmed
|
||||
default:
|
||||
return vowifi.SMSEvidence{Ready: true}, nil
|
||||
}
|
||||
}
|
||||
|
||||
func (session *Session) smsCapabilityReady() bool {
|
||||
if session.smsContactConfirmed {
|
||||
return true
|
||||
}
|
||||
profile := vowifi.ResolveCarrierProfile(session.request.Identity)
|
||||
if profile.AllowSMSWithoutContactConfirmation {
|
||||
session.provider.config.Logger.Warn("IMS SMS capability was not confirmed by registrar; proceeding because carrier profile permits it",
|
||||
"device_id", session.request.DeviceID,
|
||||
"carrier_profile", profile.ID,
|
||||
"match_source", profile.MatchSource)
|
||||
return true
|
||||
}
|
||||
return false
|
||||
}
|
||||
|
||||
func (session *Session) Close(ctx context.Context) error {
|
||||
if ctx == nil {
|
||||
ctx = context.Background()
|
||||
|
||||
@@ -17,6 +17,7 @@ import (
|
||||
"strconv"
|
||||
"strings"
|
||||
"time"
|
||||
"unicode/utf16"
|
||||
|
||||
"vocat/internal/device"
|
||||
"vocat/internal/vowifi"
|
||||
@@ -24,6 +25,7 @@ import (
|
||||
|
||||
const (
|
||||
smsContentType = "application/vnd.3gpp.sms"
|
||||
ussiContentType = "application/vnd.3gpp.ussd"
|
||||
sipMessageRetransmitT1 = 500 * time.Millisecond
|
||||
sipMessageRetransmitMax = 4 * time.Second
|
||||
)
|
||||
@@ -52,6 +54,7 @@ type ReceivedSMS struct {
|
||||
CallID string
|
||||
RawRPDU string
|
||||
RawTPDU string
|
||||
DecodeError string
|
||||
}
|
||||
|
||||
// ReceivedSMSStatus is network delivery evidence for one submitted SMS part.
|
||||
@@ -69,6 +72,24 @@ type ReceivedSMSStatus struct {
|
||||
CallID string
|
||||
RawRPDU string
|
||||
RawTPDU string
|
||||
DecodeError string
|
||||
}
|
||||
|
||||
// ReceivedUSSD is a decoded network-originated USSD message delivered over IMS
|
||||
// (3GPP TS 24.390). Status carries the network's USSD operation code semantics
|
||||
// ("final", "awaiting_input", "terminated") when present in the body.
|
||||
type ReceivedUSSD struct {
|
||||
MessageID string
|
||||
DeviceID string
|
||||
IMSI string
|
||||
From string
|
||||
Text string
|
||||
DCS *int
|
||||
Status string
|
||||
Continueable bool
|
||||
Timestamp time.Time
|
||||
CallID string
|
||||
RawBody string
|
||||
}
|
||||
|
||||
type sipTransactionKey struct {
|
||||
@@ -343,10 +364,16 @@ func (session *Session) handleSIPRequest(request *sipRequest, respond func([]byt
|
||||
return
|
||||
}
|
||||
status := 200
|
||||
ussiMessage := false
|
||||
switch request.Method {
|
||||
case "OPTIONS":
|
||||
case "MESSAGE":
|
||||
if !supportsSMSContentType(request.value("Content-Type")) {
|
||||
switch {
|
||||
case supportsSMSContentType(request.value("Content-Type")):
|
||||
// SMS body handled below.
|
||||
case supportsUSSIContentType(request.value("Content-Type")):
|
||||
ussiMessage = true
|
||||
default:
|
||||
status = 415
|
||||
}
|
||||
default:
|
||||
@@ -362,11 +389,17 @@ func (session *Session) handleSIPRequest(request *sipRequest, respond func([]byt
|
||||
}
|
||||
if status != 200 || request.Method != "MESSAGE" {
|
||||
if request.Method == "MESSAGE" {
|
||||
session.logInboundSMS(slog.LevelWarn, "IMS inbound SMS MESSAGE rejected", request,
|
||||
session.logInboundSMS(slog.LevelWarn, "IMS inbound MESSAGE rejected", request,
|
||||
"stage", "content_type", "sip_status", status)
|
||||
}
|
||||
return
|
||||
}
|
||||
if ussiMessage {
|
||||
session.logInboundSMS(slog.LevelInfo, "IMS inbound USSD MESSAGE received", request,
|
||||
"stage", "sip_accepted")
|
||||
go session.processUSSIMessage(request)
|
||||
return
|
||||
}
|
||||
session.logInboundSMS(slog.LevelInfo, "IMS inbound SMS MESSAGE received", request,
|
||||
"stage", "sip_accepted")
|
||||
go session.processSMSMessage(request)
|
||||
@@ -384,6 +417,14 @@ func supportsSMSContentType(value string) bool {
|
||||
strings.TrimSpace(parameters["boundary"]) != ""
|
||||
}
|
||||
|
||||
func supportsUSSIContentType(value string) bool {
|
||||
mediaType, _, err := mime.ParseMediaType(strings.TrimSpace(value))
|
||||
if err != nil {
|
||||
return false
|
||||
}
|
||||
return strings.EqualFold(mediaType, ussiContentType)
|
||||
}
|
||||
|
||||
func buildSIPResponse(request *sipRequest, status int, tag string) ([]byte, error) {
|
||||
reason := map[int]string{200: "OK", 405: "Method Not Allowed", 415: "Unsupported Media Type", 488: "Not Acceptable Here"}[status]
|
||||
if reason == "" {
|
||||
@@ -414,7 +455,7 @@ func buildSIPResponse(request *sipRequest, status int, tag string) ([]byte, erro
|
||||
lines = append(lines, "Allow: REGISTER, MESSAGE, OPTIONS")
|
||||
}
|
||||
if status == 415 {
|
||||
lines = append(lines, "Accept: "+smsContentType)
|
||||
lines = append(lines, "Accept: "+smsContentType+", "+ussiContentType)
|
||||
}
|
||||
lines = append(lines, "Content-Length: 0", "", "")
|
||||
return []byte(strings.Join(lines, "\r\n")), nil
|
||||
@@ -446,29 +487,28 @@ func (session *Session) processSMSMessage(request *sipRequest) {
|
||||
"rp_message_type", int(rpdu.messageType), "rp_reference", int(rpdu.reference))
|
||||
return
|
||||
}
|
||||
message, err := device.DecodeSMSDeliverTPDU(rpdu.tpdu)
|
||||
if err != nil {
|
||||
session.logInboundSMS(slog.LevelWarn, "IMS inbound SMS decode failed", request,
|
||||
"stage", "tpdu", "payload_source", payloadSource,
|
||||
"rp_reference", int(rpdu.reference), "tpdu_bytes", len(rpdu.tpdu), "error", err)
|
||||
session.sendLoggedDeliveryReport(request, buildRPError(rpdu.reference, 95), "rp_error")
|
||||
return
|
||||
}
|
||||
|
||||
message, decodeErr := device.DecodeSMSDeliverTPDU(rpdu.tpdu)
|
||||
receivedAt := time.Now().UTC()
|
||||
callID := strings.TrimSpace(request.value("Call-ID"))
|
||||
if message.Direction == device.SMSDirectionStatusReport {
|
||||
if message.MessageReference == nil || message.StatusCode == nil {
|
||||
session.logInboundSMS(slog.LevelWarn, "IMS inbound SMS status report is incomplete", request,
|
||||
"stage", "tpdu", "rp_reference", int(rpdu.reference))
|
||||
session.sendLoggedDeliveryReport(request, buildRPError(rpdu.reference, 95), "rp_error")
|
||||
return
|
||||
}
|
||||
carrierProfile := vowifi.ResolveCarrierProfile(session.request.Identity)
|
||||
|
||||
if decodeErr != nil {
|
||||
session.logInboundSMS(slog.LevelWarn, "IMS inbound SMS decode failed; persisting raw payload", request,
|
||||
"stage", "tpdu", "payload_source", payloadSource,
|
||||
"rp_reference", int(rpdu.reference), "tpdu_bytes", len(rpdu.tpdu),
|
||||
"carrier_profile", carrierProfile.ID,
|
||||
"direction", message.Direction, "error", decodeErr)
|
||||
}
|
||||
|
||||
switch {
|
||||
case message.Direction == device.SMSDirectionStatusReport:
|
||||
status := ReceivedSMSStatus{
|
||||
DeviceID: session.request.DeviceID,
|
||||
IMSI: session.request.Identity.IMSI,
|
||||
To: message.To,
|
||||
MessageReference: *message.MessageReference,
|
||||
StatusCode: *message.StatusCode,
|
||||
MessageReference: intPtrValue(message.MessageReference),
|
||||
StatusCode: intPtrValue(message.StatusCode),
|
||||
DeliveryStatus: message.DeliveryStatus,
|
||||
ServiceCenterTimestamp: message.ServiceCenterTimestamp,
|
||||
DischargeTimestamp: message.DischargeTimestamp,
|
||||
@@ -477,12 +517,15 @@ func (session *Session) processSMSMessage(request *sipRequest) {
|
||||
CallID: callID,
|
||||
RawRPDU: strings.ToUpper(hex.EncodeToString(payload)),
|
||||
RawTPDU: strings.ToUpper(hex.EncodeToString(rpdu.tpdu)),
|
||||
DecodeError: errorString(decodeErr),
|
||||
}
|
||||
if session.provider.config.OnSMSStatus != nil {
|
||||
ctx, cancel := context.WithTimeout(context.Background(), 5*time.Second)
|
||||
err = session.provider.config.OnSMSStatus(ctx, status)
|
||||
cancel()
|
||||
if (message.MessageReference == nil || message.StatusCode == nil) && decodeErr == nil {
|
||||
session.logInboundSMS(slog.LevelWarn, "IMS inbound SMS status report is incomplete", request,
|
||||
"stage", "tpdu", "rp_reference", int(rpdu.reference))
|
||||
session.sendLoggedDeliveryReport(request, buildRPError(rpdu.reference, 95), "rp_error")
|
||||
return
|
||||
}
|
||||
err := session.invokeSMSStatusCallback(status)
|
||||
if err != nil {
|
||||
session.logInboundSMS(slog.LevelWarn, "IMS inbound SMS status persistence failed", request,
|
||||
"stage", "status_callback", "rp_reference", int(rpdu.reference), "error", err)
|
||||
@@ -491,55 +534,84 @@ func (session *Session) processSMSMessage(request *sipRequest) {
|
||||
}
|
||||
session.logInboundSMS(slog.LevelInfo, "IMS inbound SMS status report processed", request,
|
||||
"stage", "status_callback", "rp_reference", int(rpdu.reference),
|
||||
"status_code", *message.StatusCode)
|
||||
"status_code", status.StatusCode)
|
||||
session.sendLoggedDeliveryReport(request, []byte{0x02, rpdu.reference}, "rp_ack")
|
||||
return
|
||||
}
|
||||
if message.Direction != device.SMSDirectionReceived {
|
||||
|
||||
case message.Direction == device.SMSDirectionReceived || decodeErr != nil:
|
||||
var serviceCenterTimestamp *time.Time
|
||||
if message.ServiceCenterTimestamp != nil {
|
||||
value := message.ServiceCenterTimestamp.UTC()
|
||||
serviceCenterTimestamp = &value
|
||||
}
|
||||
received := ReceivedSMS{
|
||||
// A retransmission inside the same SIP transaction is idempotent, but a
|
||||
// fresh Call-ID/RP reference is a distinct network delivery and must stay
|
||||
// visible even when its TPDU and text happen to be identical.
|
||||
MessageID: fmt.Sprintf("ims:%s:%d", callID, rpdu.reference),
|
||||
DeviceID: session.request.DeviceID,
|
||||
IMSI: session.request.Identity.IMSI,
|
||||
From: message.From,
|
||||
Text: message.Text,
|
||||
Timestamp: receivedAt,
|
||||
ServiceCenterTimestamp: serviceCenterTimestamp,
|
||||
Encoding: message.Encoding,
|
||||
Concat: message.Concat,
|
||||
RPReference: int(rpdu.reference),
|
||||
CallID: callID,
|
||||
RawRPDU: strings.ToUpper(hex.EncodeToString(payload)),
|
||||
RawTPDU: strings.ToUpper(hex.EncodeToString(rpdu.tpdu)),
|
||||
DecodeError: errorString(decodeErr),
|
||||
}
|
||||
err := session.invokeSMSCallback(received)
|
||||
if err != nil {
|
||||
session.logInboundSMS(slog.LevelWarn, "IMS inbound SMS persistence failed", request,
|
||||
"stage", "sms_callback", "rp_reference", int(rpdu.reference), "error", err)
|
||||
session.sendLoggedDeliveryReport(request, buildRPError(rpdu.reference, 22), "rp_error")
|
||||
return
|
||||
}
|
||||
session.logInboundSMS(slog.LevelInfo, "IMS inbound SMS processed", request,
|
||||
"stage", "sms_callback", "payload_source", payloadSource,
|
||||
"rp_reference", int(rpdu.reference), "encoding", message.Encoding,
|
||||
"concatenated", message.Concat != nil, "decode_error", decodeErr != nil)
|
||||
session.sendLoggedDeliveryReport(request, []byte{0x02, rpdu.reference}, "rp_ack")
|
||||
|
||||
default:
|
||||
session.logInboundSMS(slog.LevelWarn, "IMS inbound SMS has unexpected TPDU direction", request,
|
||||
"stage", "tpdu", "rp_reference", int(rpdu.reference), "direction", message.Direction)
|
||||
session.sendLoggedDeliveryReport(request, buildRPError(rpdu.reference, 95), "rp_error")
|
||||
return
|
||||
}
|
||||
var serviceCenterTimestamp *time.Time
|
||||
if message.ServiceCenterTimestamp != nil {
|
||||
value := message.ServiceCenterTimestamp.UTC()
|
||||
serviceCenterTimestamp = &value
|
||||
}
|
||||
|
||||
func (session *Session) invokeSMSCallback(received ReceivedSMS) error {
|
||||
if session.provider.config.OnSMS == nil {
|
||||
return nil
|
||||
}
|
||||
received := ReceivedSMS{
|
||||
// A retransmission inside the same SIP transaction is idempotent, but a
|
||||
// fresh Call-ID/RP reference is a distinct network delivery and must stay
|
||||
// visible even when its TPDU and text happen to be identical.
|
||||
MessageID: fmt.Sprintf("ims:%s:%d", callID, rpdu.reference),
|
||||
DeviceID: session.request.DeviceID,
|
||||
IMSI: session.request.Identity.IMSI,
|
||||
From: message.From,
|
||||
Text: message.Text,
|
||||
Timestamp: receivedAt,
|
||||
ServiceCenterTimestamp: serviceCenterTimestamp,
|
||||
Encoding: message.Encoding,
|
||||
Concat: message.Concat,
|
||||
RPReference: int(rpdu.reference),
|
||||
CallID: callID,
|
||||
RawRPDU: strings.ToUpper(hex.EncodeToString(payload)),
|
||||
RawTPDU: strings.ToUpper(hex.EncodeToString(rpdu.tpdu)),
|
||||
ctx, cancel := context.WithTimeout(context.Background(), 5*time.Second)
|
||||
defer cancel()
|
||||
return session.provider.config.OnSMS(ctx, received)
|
||||
}
|
||||
|
||||
func (session *Session) invokeSMSStatusCallback(status ReceivedSMSStatus) error {
|
||||
if session.provider.config.OnSMSStatus == nil {
|
||||
return nil
|
||||
}
|
||||
if session.provider.config.OnSMS != nil {
|
||||
ctx, cancel := context.WithTimeout(context.Background(), 5*time.Second)
|
||||
err = session.provider.config.OnSMS(ctx, received)
|
||||
cancel()
|
||||
ctx, cancel := context.WithTimeout(context.Background(), 5*time.Second)
|
||||
defer cancel()
|
||||
return session.provider.config.OnSMSStatus(ctx, status)
|
||||
}
|
||||
|
||||
func intPtrValue(value *int) int {
|
||||
if value == nil {
|
||||
return 0
|
||||
}
|
||||
if err != nil {
|
||||
session.logInboundSMS(slog.LevelWarn, "IMS inbound SMS persistence failed", request,
|
||||
"stage", "sms_callback", "rp_reference", int(rpdu.reference), "error", err)
|
||||
session.sendLoggedDeliveryReport(request, buildRPError(rpdu.reference, 22), "rp_error")
|
||||
return
|
||||
return *value
|
||||
}
|
||||
|
||||
func errorString(err error) string {
|
||||
if err == nil {
|
||||
return ""
|
||||
}
|
||||
session.logInboundSMS(slog.LevelInfo, "IMS inbound SMS processed", request,
|
||||
"stage", "sms_callback", "payload_source", payloadSource,
|
||||
"rp_reference", int(rpdu.reference), "encoding", message.Encoding,
|
||||
"concatenated", message.Concat != nil)
|
||||
session.sendLoggedDeliveryReport(request, []byte{0x02, rpdu.reference}, "rp_ack")
|
||||
return err.Error()
|
||||
}
|
||||
|
||||
func extractSMSPayload(request *sipRequest) ([]byte, string, error) {
|
||||
@@ -607,6 +679,235 @@ func decodeSMSTransfer(body []byte, encoding string) ([]byte, error) {
|
||||
}
|
||||
}
|
||||
|
||||
// encodeUSSDBody encodes a USSD string for a TS 24.390 application/vnd.3gpp.ussd
|
||||
// body. To avoid carrier-specific GSM-7 packing conventions the body is always
|
||||
// UTF-16 (big-endian) with DCS 0x48, which every USSI-capable P-CSCF accepts.
|
||||
func encodeUSSDBody(text string) ([]byte, *int, error) {
|
||||
dcs := 0x48
|
||||
if text == "" {
|
||||
return nil, &dcs, nil
|
||||
}
|
||||
encoded := utf16.Encode([]rune(text))
|
||||
body := make([]byte, 0, len(encoded)*2)
|
||||
for _, unit := range encoded {
|
||||
body = append(body, byte(unit>>8), byte(unit))
|
||||
}
|
||||
return body, &dcs, nil
|
||||
}
|
||||
|
||||
// decodeUSSDBody reverses encodeUSSDBody using the data coding scheme carried
|
||||
// alongside the USSD string. DCS 0x00/0x0F => GSM 7-bit default alphabet
|
||||
// (unpacked one code per byte, as some carriers send); 0x48 => UCS2/UTF-16.
|
||||
// Any other DCS is treated as raw bytes.
|
||||
func decodeUSSDBody(body []byte, dcs int) string {
|
||||
switch dcs {
|
||||
case 0x00, 0x0F:
|
||||
if decoded, ok := device.DecodeGSM7Septets(string(body)); ok {
|
||||
return decoded
|
||||
}
|
||||
}
|
||||
if dcs == 0x48 && len(body) > 0 && len(body)%2 == 0 {
|
||||
units := make([]uint16, 0, len(body)/2)
|
||||
for index := 0; index < len(body); index += 2 {
|
||||
units = append(units, uint16(body[index])<<8|uint16(body[index+1]))
|
||||
}
|
||||
return string(utf16.Decode(units))
|
||||
}
|
||||
return string(body)
|
||||
}
|
||||
|
||||
// processUSSIMessage decodes a network-originated USSD MESSAGE and hands it to
|
||||
// the OnUSSD callback. Unlike SMS there is no RP-ACK transport, so the 200 OK
|
||||
// has already been sent by handleSIPRequest and this routine only logs callback
|
||||
// failures.
|
||||
func (session *Session) processUSSIMessage(request *sipRequest) {
|
||||
body, dcs, text, err := extractUSSDBody(request)
|
||||
if err != nil {
|
||||
session.logInboundSMS(slog.LevelWarn, "IMS inbound USSD decode failed", request,
|
||||
"stage", "mime", "error", err)
|
||||
return
|
||||
}
|
||||
callID := strings.TrimSpace(request.value("Call-ID"))
|
||||
received := ReceivedUSSD{
|
||||
MessageID: fmt.Sprintf("ims-ussd:%s", callID),
|
||||
DeviceID: session.request.DeviceID,
|
||||
IMSI: session.request.Identity.IMSI,
|
||||
From: firstURI(request.value("P-Asserted-Identity")),
|
||||
Text: text,
|
||||
DCS: dcs,
|
||||
Status: "final",
|
||||
Timestamp: time.Now().UTC(),
|
||||
CallID: callID,
|
||||
RawBody: strings.ToUpper(hex.EncodeToString(body)),
|
||||
}
|
||||
if session.provider.config.OnUSSD != nil {
|
||||
ctx, cancel := context.WithTimeout(context.Background(), 5*time.Second)
|
||||
err = session.provider.config.OnUSSD(ctx, received)
|
||||
cancel()
|
||||
}
|
||||
if err != nil {
|
||||
session.logInboundSMS(slog.LevelWarn, "IMS inbound USSD callback failed", request,
|
||||
"stage", "ussd_callback", "error", err)
|
||||
return
|
||||
}
|
||||
session.logInboundSMS(slog.LevelInfo, "IMS inbound USSD processed", request,
|
||||
"stage", "ussd_callback", "dcs", dcsPointerToInt(dcs))
|
||||
}
|
||||
|
||||
func dcsPointerToInt(value *int) int {
|
||||
if value == nil {
|
||||
return -1
|
||||
}
|
||||
return *value
|
||||
}
|
||||
|
||||
// extractUSSDBody decodes a TS 24.390 USSD body. The body is a sequence of
|
||||
// information elements; the common form is an optional language/network
|
||||
// indicator followed by the USSD string with its DCS. We scan for a component
|
||||
// whose length leaves a trailing DCS+string pair, returning the string, its
|
||||
// DCS, and the raw bytes.
|
||||
func extractUSSDBody(request *sipRequest) (raw []byte, dcs *int, text string, err error) {
|
||||
if request == nil {
|
||||
return nil, nil, "", errors.New("ims: USSD MESSAGE is nil")
|
||||
}
|
||||
body, decodeErr := decodeSMSTransfer(request.Body, request.value("Content-Transfer-Encoding"))
|
||||
if decodeErr != nil {
|
||||
return nil, nil, "", fmt.Errorf("ims: decode USSD body: %w", decodeErr)
|
||||
}
|
||||
raw, dcs, text = extractUSSDString(body)
|
||||
return raw, dcs, text, nil
|
||||
}
|
||||
|
||||
// extractUSSDString walks the TS 24.390 information elements looking for the
|
||||
// USSD string component: [length][DCS][octets...]. A leading 0xAB language
|
||||
// indicator pair is skipped. If no structured component is found, the whole
|
||||
// body is treated as a DCS 0x0F string.
|
||||
func extractUSSDString(body []byte) (raw []byte, dcs *int, text string) {
|
||||
for offset := 0; offset+1 < len(body); {
|
||||
if body[offset] == 0xAB {
|
||||
// Language/network indicator: [0xAB][length of language].
|
||||
if offset+1 >= len(body) {
|
||||
break
|
||||
}
|
||||
skip := int(body[offset+1])
|
||||
offset += 2 + skip
|
||||
continue
|
||||
}
|
||||
// USSD string component: [length][DCS][octets...], length counts
|
||||
// everything after the length byte (DCS + string octets).
|
||||
length := int(body[offset])
|
||||
if length < 1 || offset+1+length > len(body) {
|
||||
break
|
||||
}
|
||||
dcsValue := int(body[offset+1])
|
||||
stringBytes := body[offset+2 : offset+1+length]
|
||||
dcs = &dcsValue
|
||||
return body, dcs, decodeUSSDBody(stringBytes, dcsValue)
|
||||
}
|
||||
zero := 0x0F
|
||||
return body, &zero, decodeUSSDBody(body, zero)
|
||||
}
|
||||
|
||||
// SendUSSI submits a USSD dialog turn over IMS. The first turn carries the
|
||||
// service code in request.Code; a follow-up turn on an open dialog carries the
|
||||
// menu reply in request.Input. USSI does not require the +g.3gpp.smsip contact
|
||||
// to be confirmed — only IMS registration.
|
||||
func (session *Session) SendUSSI(ctx context.Context, request vowifi.USSISubmitRequest) (vowifi.USSISubmitResult, error) {
|
||||
if ctx == nil {
|
||||
ctx = context.Background()
|
||||
}
|
||||
session.smsMu.Lock()
|
||||
defer session.smsMu.Unlock()
|
||||
|
||||
session.mu.Lock()
|
||||
if session.closed || !session.evidence.Registered {
|
||||
session.mu.Unlock()
|
||||
return vowifi.USSISubmitResult{}, vowifi.ErrUSSINotReady
|
||||
}
|
||||
target := session.ussiTarget()
|
||||
session.mu.Unlock()
|
||||
|
||||
payload := strings.TrimSpace(firstNonEmpty(request.Input, request.Code))
|
||||
if payload == "" {
|
||||
return vowifi.USSISubmitResult{}, errors.New("ims: USSI payload is empty")
|
||||
}
|
||||
body, dcs, err := encodeUSSDBody(payload)
|
||||
if err != nil {
|
||||
return vowifi.USSISubmitResult{}, err
|
||||
}
|
||||
// TS 24.390 §5.2.1: [language indicator]? [length][DCS][USSD string].
|
||||
// The length byte counts the DCS plus the string octets that follow it.
|
||||
stringOctets := body
|
||||
length := len(stringOctets) + 1
|
||||
if length > 255 {
|
||||
return vowifi.USSISubmitResult{}, errors.New("ims: USSD string exceeds 254 octets")
|
||||
}
|
||||
message := make([]byte, 0, 2+len(stringOctets))
|
||||
message = append(message, byte(length), byte(*dcs))
|
||||
message = append(message, stringOctets...)
|
||||
response, sendErr := session.sendSIPMessageWith(ctx, target, message, "", ussiContentType, "ussd")
|
||||
result := vowifi.USSISubmitResult{
|
||||
SubmissionStatus: "pending",
|
||||
}
|
||||
if response != nil {
|
||||
result.SIPCode = response.StatusCode
|
||||
}
|
||||
if sendErr != nil {
|
||||
result.SubmissionStatus = "failed"
|
||||
result.Raw = strings.ToUpper(hex.EncodeToString(message))
|
||||
return result, sendErr
|
||||
}
|
||||
if response.StatusCode < 200 || response.StatusCode >= 300 {
|
||||
result.SubmissionStatus = "rejected_by_ims"
|
||||
result.Status = "failed"
|
||||
result.Raw = strings.ToUpper(hex.EncodeToString(message))
|
||||
return result, fmt.Errorf("ims: USSI rejected with SIP %d", response.StatusCode)
|
||||
}
|
||||
// A 2xx response may carry the network's reply in the same MESSAGE body.
|
||||
text, replyDCS := session.parseUSSIReply(response)
|
||||
result.Text = text
|
||||
result.DCS = replyDCS
|
||||
result.Status = "final"
|
||||
result.Continueable = false
|
||||
result.Raw = strings.ToUpper(hex.EncodeToString(message))
|
||||
if result.Status == "" {
|
||||
result.Status = "final"
|
||||
}
|
||||
result.SubmissionStatus = "accepted_by_ims"
|
||||
return result, nil
|
||||
}
|
||||
|
||||
// parseUSSIReply decodes the USSD body of a 2xx response when the network
|
||||
// returned the dialog reply inline. A missing body is a final empty reply.
|
||||
func (session *Session) parseUSSIReply(response *sipResponse) (string, *int) {
|
||||
if response == nil || len(response.Body) == 0 {
|
||||
return "", nil
|
||||
}
|
||||
if !supportsUSSIContentType(response.value("Content-Type")) {
|
||||
return "", nil
|
||||
}
|
||||
_, dcs, text := extractUSSDString(response.Body)
|
||||
return text, dcs
|
||||
}
|
||||
|
||||
func (session *Session) ussiTarget() string {
|
||||
if number, _, ok := vowifi.ExtractAssociatedMSISDN(session.evidence); ok {
|
||||
if normalized := normalizeE164(number); normalized != "" {
|
||||
return "tel:" + normalized
|
||||
}
|
||||
}
|
||||
return session.identity.public
|
||||
}
|
||||
|
||||
func firstNonEmpty(values ...string) string {
|
||||
for _, value := range values {
|
||||
if strings.TrimSpace(value) != "" {
|
||||
return value
|
||||
}
|
||||
}
|
||||
return ""
|
||||
}
|
||||
|
||||
func (session *Session) logInboundSMS(level slog.Level, message string, request *sipRequest, attributes ...any) {
|
||||
logger := slog.Default()
|
||||
if session != nil && session.provider != nil && session.provider.config.Logger != nil {
|
||||
@@ -664,7 +965,7 @@ func (session *Session) SendSMS(ctx context.Context, request vowifi.SMSSubmitReq
|
||||
defer session.smsMu.Unlock()
|
||||
|
||||
session.mu.Lock()
|
||||
if session.closed || !session.evidence.Registered || !session.smsContactConfirmed {
|
||||
if session.closed || !session.evidence.Registered || !session.smsCapabilityReady() {
|
||||
session.mu.Unlock()
|
||||
return vowifi.SMSSubmitResult{}, vowifi.ErrSMSNotReady
|
||||
}
|
||||
@@ -810,6 +1111,20 @@ func (session *Session) sendSIPMessage(
|
||||
target string,
|
||||
body []byte,
|
||||
inReplyTo string,
|
||||
) (*sipResponse, error) {
|
||||
return session.sendSIPMessageWith(ctx, target, body, inReplyTo, smsContentType, "smsip")
|
||||
}
|
||||
|
||||
// sendSIPMessageWith is the parameterized MESSAGE transaction used by both SMS
|
||||
// and USSI. acceptContactTag is the 3gpp feature tag (e.g. "smsip" or "ussd")
|
||||
// advertised via Accept-Contact; pass an empty string to omit the header.
|
||||
func (session *Session) sendSIPMessageWith(
|
||||
ctx context.Context,
|
||||
target string,
|
||||
body []byte,
|
||||
inReplyTo string,
|
||||
contentType string,
|
||||
acceptContactTag string,
|
||||
) (*sipResponse, error) {
|
||||
callToken, err := randomHex(18)
|
||||
if err != nil {
|
||||
@@ -849,7 +1164,11 @@ func (session *Session) sendSIPMessage(
|
||||
"Call-ID: "+callID,
|
||||
fmt.Sprintf("CSeq: %d MESSAGE", cseq),
|
||||
"P-Preferred-Identity: <"+session.identity.public+">",
|
||||
"Accept-Contact: *;+g.3gpp.smsip",
|
||||
)
|
||||
if acceptContactTag != "" {
|
||||
lines = append(lines, "Accept-Contact: *;+g.3gpp."+acceptContactTag)
|
||||
}
|
||||
lines = append(lines,
|
||||
"Request-Disposition: no-fork",
|
||||
"Allow: MESSAGE",
|
||||
)
|
||||
@@ -857,7 +1176,7 @@ func (session *Session) sendSIPMessage(
|
||||
lines = append(lines, "In-Reply-To: "+inReplyTo)
|
||||
}
|
||||
lines = append(lines,
|
||||
"Content-Type: "+smsContentType,
|
||||
"Content-Type: "+contentType,
|
||||
"Content-Transfer-Encoding: binary",
|
||||
"Content-Length: "+strconv.Itoa(len(body)),
|
||||
"", "",
|
||||
@@ -1025,3 +1344,4 @@ func (session *Session) closeInboundConnections() {
|
||||
}
|
||||
|
||||
var _ vowifi.SMSSender = (*Session)(nil)
|
||||
var _ vowifi.USSISender = (*Session)(nil)
|
||||
|
||||
@@ -6,6 +6,7 @@ import (
|
||||
"encoding/base64"
|
||||
"errors"
|
||||
"fmt"
|
||||
"log/slog"
|
||||
"mime/multipart"
|
||||
"net"
|
||||
"net/textproto"
|
||||
@@ -158,6 +159,57 @@ func TestSupportsSMSContentType(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
func TestSupportsUSSIContentType(t *testing.T) {
|
||||
for _, test := range []struct {
|
||||
value string
|
||||
want bool
|
||||
}{
|
||||
{ussiContentType, true},
|
||||
{"Application/Vnd.3gpp.Ussd; charset=binary", true},
|
||||
{smsContentType, false},
|
||||
{"text/plain", false},
|
||||
} {
|
||||
if got := supportsUSSIContentType(test.value); got != test.want {
|
||||
t.Errorf("supportsUSSIContentType(%q) = %v, want %v", test.value, got, test.want)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func TestEncodeDecodeUSSDBody(t *testing.T) {
|
||||
for _, text := range []string{"*100#", "Main menu 中文"} {
|
||||
body, dcs, err := encodeUSSDBody(text)
|
||||
if err != nil {
|
||||
t.Fatalf("encodeUSSDBody(%q) error = %v", text, err)
|
||||
}
|
||||
if dcs == nil || *dcs != 0x48 {
|
||||
t.Fatalf("encodeUSSDBody(%q) dcs = %v, want 0x48", text, dcs)
|
||||
}
|
||||
decoded := decodeUSSDBody(body, *dcs)
|
||||
if decoded != text {
|
||||
t.Fatalf("decodeUSSDBody(%q) = %q, want %q", text, decoded, text)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func TestExtractUSSDString(t *testing.T) {
|
||||
text := "Main menu"
|
||||
encoded, dcs, err := encodeUSSDBody(text)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
body := append([]byte{byte(len(encoded) + 1), byte(*dcs)}, encoded...)
|
||||
raw, gotDCS, gotText := extractUSSDString(body)
|
||||
if gotText != text || gotDCS == nil || *gotDCS != *dcs || !bytes.Equal(raw, body) {
|
||||
t.Fatalf("extractUSSDString(%x) = (%q, %v, %q)", body, raw, gotDCS, gotText)
|
||||
}
|
||||
|
||||
// A plain raw body without a length/DCS prefix falls back to DCS 0x0F.
|
||||
raw, gotDCS, gotText = extractUSSDString([]byte("fallback"))
|
||||
if gotDCS == nil || *gotDCS != 0x0F || gotText != "fallback" || !bytes.Equal(raw, []byte("fallback")) {
|
||||
t.Fatalf("extractUSSDString fallback = (%q, %v, %q)", raw, gotDCS, gotText)
|
||||
}
|
||||
}
|
||||
|
||||
func TestSMSCenterForIdentityUsesExactPLMN(t *testing.T) {
|
||||
config := Config{SMSCenterByPLMN: map[string]string{
|
||||
"23410": "+447802000332",
|
||||
@@ -539,3 +591,368 @@ func serveOutboundSMS(listener *net.UDPConn, nonce string, readyForClose chan<-
|
||||
_, err = listener.WriteToUDP(testResponse(200, "OK", registerCallID, headers["cseq"], nil), remote)
|
||||
return err
|
||||
}
|
||||
|
||||
func TestSessionReceivesUSSIOverIMS(t *testing.T) {
|
||||
listener, err := net.ListenUDP("udp", &net.UDPAddr{IP: net.ParseIP("127.0.0.1")})
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
defer listener.Close()
|
||||
_ = listener.SetDeadline(time.Now().Add(10 * time.Second))
|
||||
|
||||
received := make(chan ReceivedUSSD, 1)
|
||||
serverDone := make(chan error, 1)
|
||||
readyForClose := make(chan struct{})
|
||||
nonce := base64.StdEncoding.EncodeToString(make([]byte, 32))
|
||||
go func() { serverDone <- serveInboundUSSI(listener, nonce, readyForClose) }()
|
||||
provider, err := NewProvider(
|
||||
smsTestAKA{&recordingAKA{result: vowifi.AKAResult{RES: []byte{1, 2, 3, 4}}}},
|
||||
Config{
|
||||
PCSCF: listener.LocalAddr().String(), LocalAddress: "127.0.0.1",
|
||||
Transport: "udp", TransactionTimeout: 3 * time.Second, SecurityMode: SecurityDisabled,
|
||||
OnUSSD: func(_ context.Context, message ReceivedUSSD) error {
|
||||
received <- message
|
||||
return nil
|
||||
},
|
||||
},
|
||||
)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
session, err := provider.Start(context.Background(), vowifi.IMSRequest{
|
||||
DeviceID: "ec20",
|
||||
Identity: vowifi.SIMIdentity{IMSI: "001010123456789", HomeMCC: "001", HomeMNC: "01"},
|
||||
Tunnel: evidenceTunnel{evidence: vowifi.TunnelEvidence{
|
||||
Established: true, LocalIPv4: "127.0.0.1", PCSCF: []string{listener.LocalAddr().String()},
|
||||
}},
|
||||
})
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
select {
|
||||
case message := <-received:
|
||||
if message.Text != "Main menu" || message.From != "sip:[email protected]" || message.CallID != "network-ussd-1" {
|
||||
t.Fatalf("received = %#v", message)
|
||||
}
|
||||
case <-time.After(5 * time.Second):
|
||||
t.Fatal("timed out waiting for inbound USSI")
|
||||
}
|
||||
select {
|
||||
case <-readyForClose:
|
||||
case <-time.After(5 * time.Second):
|
||||
t.Fatal("timed out waiting for USSI MESSAGE acceptance")
|
||||
}
|
||||
if err := session.Close(context.Background()); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if err := <-serverDone; err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
}
|
||||
|
||||
func serveInboundUSSI(listener *net.UDPConn, nonce string, readyForClose chan<- struct{}) error {
|
||||
packet := make([]byte, 65535)
|
||||
count, remote, err := listener.ReadFromUDP(packet)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
_, headers, err := parseTestRequest(packet[:count])
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
callID := headers["call-id"]
|
||||
if _, err = listener.WriteToUDP(testResponse(401, "Unauthorized", callID, headers["cseq"], []string{
|
||||
`WWW-Authenticate: Digest realm="ims.mnc001.mcc001.3gppnetwork.org", nonce="` + nonce + `", algorithm=AKAv1-MD5, qop="auth"`,
|
||||
}), remote); err != nil {
|
||||
return err
|
||||
}
|
||||
count, remote, err = listener.ReadFromUDP(packet)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
_, headers, err = parseTestRequest(packet[:count])
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
if _, err = listener.WriteToUDP(testResponse(200, "OK", callID, headers["cseq"], []string{
|
||||
"Contact: " + headers["contact"] + ";expires=600",
|
||||
}), remote); err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
body := buildUSSDBody("Main menu")
|
||||
request := []byte(strings.Join([]string{
|
||||
"MESSAGE sip:[email protected] SIP/2.0",
|
||||
"Via: SIP/2.0/UDP " + listener.LocalAddr().String() + ";branch=z9hG4bKussd",
|
||||
"From: <sip:[email protected]>;tag=gw",
|
||||
"To: <sip:[email protected]>",
|
||||
"P-Asserted-Identity: <sip:[email protected]>",
|
||||
"Call-ID: network-ussd-1",
|
||||
"CSeq: 1 MESSAGE",
|
||||
"Content-Type: application/vnd.3gpp.ussd",
|
||||
"Content-Transfer-Encoding: binary",
|
||||
fmt.Sprintf("Content-Length: %d", len(body)), "", "",
|
||||
}, "\r\n"))
|
||||
request = append(request, body...)
|
||||
if _, err = listener.WriteToUDP(request, remote); err != nil {
|
||||
return err
|
||||
}
|
||||
count, remote, err = listener.ReadFromUDP(packet)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
response, err := parseSIPResponse(packet[:count])
|
||||
if err != nil || response.StatusCode != 200 {
|
||||
return fmt.Errorf("USSI MESSAGE response = (%#v, %v)", response, err)
|
||||
}
|
||||
close(readyForClose)
|
||||
|
||||
count, remote, err = listener.ReadFromUDP(packet)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
_, headers, err = parseTestRequest(packet[:count])
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
if headers["expires"] != "0" {
|
||||
return errors.New("expected deregistration")
|
||||
}
|
||||
_, err = listener.WriteToUDP(testResponse(200, "OK", callID, headers["cseq"], nil), remote)
|
||||
return err
|
||||
}
|
||||
|
||||
func TestSessionReceivesMalformedSMSBestEffort(t *testing.T) {
|
||||
request := &sipRequest{
|
||||
Headers: map[string][]string{
|
||||
"content-type": {smsContentType},
|
||||
"content-transfer-encoding": {"binary"},
|
||||
"call-id": {"malformed-test"},
|
||||
"p-asserted-identity": {"<sip:[email protected]>"},
|
||||
},
|
||||
Body: []byte{0x01, 0x2a, 0x00, 0x00, 0x03, 0xff, 0xff, 0xff},
|
||||
}
|
||||
|
||||
received := make(chan ReceivedSMS, 1)
|
||||
session := &Session{
|
||||
provider: &Provider{config: Config{
|
||||
Logger: slog.Default(),
|
||||
OnSMS: func(_ context.Context, message ReceivedSMS) error {
|
||||
received <- message
|
||||
return nil
|
||||
},
|
||||
}},
|
||||
request: vowifi.IMSRequest{DeviceID: "ec20", Identity: vowifi.SIMIdentity{IMSI: "001010123456789", HomeMCC: "001", HomeMNC: "01"}},
|
||||
conn: &fakeConn{},
|
||||
transactions: make(map[sipTransactionKey]chan *sipResponse),
|
||||
fromTag: "tag",
|
||||
nextRPReference: 1,
|
||||
}
|
||||
|
||||
session.processSMSMessage(request)
|
||||
|
||||
select {
|
||||
case message := <-received:
|
||||
if message.DecodeError == "" {
|
||||
t.Fatal("expected DecodeError to be set")
|
||||
}
|
||||
if message.RawRPDU == "" || message.RawTPDU == "" {
|
||||
t.Fatalf("expected raw payloads to be preserved, got %#v", message)
|
||||
}
|
||||
case <-time.After(time.Second):
|
||||
t.Fatal("timed out waiting for best-effort SMS callback")
|
||||
}
|
||||
}
|
||||
|
||||
func TestSessionAllowsSMSWithoutContactConfirmationWhenProfilePermits(t *testing.T) {
|
||||
session := &Session{
|
||||
provider: &Provider{config: Config{Logger: slog.Default()}},
|
||||
request: vowifi.IMSRequest{
|
||||
Identity: vowifi.SIMIdentity{HomeMCC: "515", HomeMNC: "66"},
|
||||
},
|
||||
evidence: vowifi.IMSEvidence{
|
||||
Registered: true,
|
||||
RegistrationState: "registered",
|
||||
},
|
||||
expiresAt: time.Now().Add(time.Hour),
|
||||
}
|
||||
|
||||
evidence, err := session.EnableSMS(context.Background())
|
||||
if err != nil || !evidence.Ready {
|
||||
t.Fatalf("EnableSMS() = (%#v, %v), want ready for DITO profile", evidence, err)
|
||||
}
|
||||
}
|
||||
|
||||
func TestSessionRequiresSMSContactConfirmationByDefault(t *testing.T) {
|
||||
session := &Session{
|
||||
provider: &Provider{config: Config{Logger: slog.Default()}},
|
||||
request: vowifi.IMSRequest{
|
||||
Identity: vowifi.SIMIdentity{HomeMCC: "001", HomeMNC: "01"},
|
||||
},
|
||||
evidence: vowifi.IMSEvidence{
|
||||
Registered: true,
|
||||
RegistrationState: "registered",
|
||||
},
|
||||
expiresAt: time.Now().Add(time.Hour),
|
||||
}
|
||||
|
||||
evidence, err := session.EnableSMS(context.Background())
|
||||
if !errors.Is(err, ErrSMSCapabilityNotConfirmed) || evidence.Ready {
|
||||
t.Fatalf("EnableSMS() = (%#v, %v), want not-ready", evidence, err)
|
||||
}
|
||||
}
|
||||
|
||||
func buildUSSDBody(text string) []byte {
|
||||
encoded, dcs, err := encodeUSSDBody(text)
|
||||
if err != nil {
|
||||
panic(err)
|
||||
}
|
||||
return append([]byte{byte(len(encoded) + 1), byte(*dcs)}, encoded...)
|
||||
}
|
||||
|
||||
func TestSessionSendsUSSIOverIMS(t *testing.T) {
|
||||
listener, err := net.ListenUDP("udp", &net.UDPAddr{IP: net.ParseIP("127.0.0.1")})
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
defer listener.Close()
|
||||
_ = listener.SetDeadline(time.Now().Add(10 * time.Second))
|
||||
serverDone := make(chan error, 1)
|
||||
readyForClose := make(chan struct{})
|
||||
nonce := base64.StdEncoding.EncodeToString(make([]byte, 32))
|
||||
go func() { serverDone <- serveOutboundUSSI(listener, nonce, readyForClose) }()
|
||||
provider, err := NewProvider(
|
||||
smsTestAKA{&recordingAKA{result: vowifi.AKAResult{RES: []byte{1, 2, 3, 4}}}},
|
||||
Config{
|
||||
PCSCF: listener.LocalAddr().String(), LocalAddress: "127.0.0.1",
|
||||
Transport: "udp", TransactionTimeout: 3 * time.Second, SecurityMode: SecurityDisabled,
|
||||
},
|
||||
)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
session, err := provider.Start(context.Background(), vowifi.IMSRequest{
|
||||
DeviceID: "ec20",
|
||||
Identity: vowifi.SIMIdentity{IMSI: "001010123456789", HomeMCC: "001", HomeMNC: "01"},
|
||||
Tunnel: evidenceTunnel{evidence: vowifi.TunnelEvidence{
|
||||
Established: true, LocalIPv4: "127.0.0.1", PCSCF: []string{listener.LocalAddr().String()},
|
||||
}},
|
||||
})
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
result, err := session.(vowifi.USSISender).SendUSSI(context.Background(), vowifi.USSISubmitRequest{Code: "*100#"})
|
||||
if err != nil {
|
||||
t.Fatalf("SendUSSI error = %v", err)
|
||||
}
|
||||
if result.Status != "final" || result.Text != "Reply" || result.SIPCode != 200 {
|
||||
t.Fatalf("SendUSSI result = %#v", result)
|
||||
}
|
||||
select {
|
||||
case <-readyForClose:
|
||||
case <-time.After(5 * time.Second):
|
||||
t.Fatal("timed out waiting for USSI transaction to complete")
|
||||
}
|
||||
if err := session.Close(context.Background()); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if err := <-serverDone; err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
}
|
||||
|
||||
func serveOutboundUSSI(listener *net.UDPConn, nonce string, readyForClose chan<- struct{}) error {
|
||||
packet := make([]byte, 65535)
|
||||
count, remote, err := listener.ReadFromUDP(packet)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
_, headers, err := parseTestRequest(packet[:count])
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
registerCallID := headers["call-id"]
|
||||
if _, err = listener.WriteToUDP(testResponse(401, "Unauthorized", registerCallID, headers["cseq"], []string{
|
||||
`WWW-Authenticate: Digest realm="ims.mnc001.mcc001.3gppnetwork.org", nonce="` + nonce + `", algorithm=AKAv1-MD5, qop="auth"`,
|
||||
}), remote); err != nil {
|
||||
return err
|
||||
}
|
||||
count, remote, err = listener.ReadFromUDP(packet)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
_, headers, err = parseTestRequest(packet[:count])
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
if _, err = listener.WriteToUDP(testResponse(200, "OK", registerCallID, headers["cseq"], []string{
|
||||
"Contact: " + headers["contact"] + ";expires=600",
|
||||
}), remote); err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
count, remote, err = listener.ReadFromUDP(packet)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
message, err := parseSIPPacket(packet[:count])
|
||||
if err != nil || message.Request == nil {
|
||||
return fmt.Errorf("outbound MESSAGE parse: %v", err)
|
||||
}
|
||||
if message.Request.Method != "MESSAGE" ||
|
||||
!strings.HasPrefix(message.Request.URI, "sip:") ||
|
||||
strings.ToLower(message.Request.value("Content-Type")) != ussiContentType ||
|
||||
message.Request.value("Request-Disposition") != "no-fork" ||
|
||||
message.Request.value("Allow") != "MESSAGE" {
|
||||
return fmt.Errorf("unexpected outbound MESSAGE %#v", message.Request)
|
||||
}
|
||||
_, _, text := extractUSSDString(message.Request.Body)
|
||||
if text != "*100#" {
|
||||
return fmt.Errorf("USSI text = %q, want *100#", text)
|
||||
}
|
||||
replyBody := buildUSSDBody("Reply")
|
||||
reply := []byte(strings.Join([]string{
|
||||
"SIP/2.0 200 OK",
|
||||
"Call-ID: " + message.Request.value("Call-ID"),
|
||||
"CSeq: " + message.Request.value("CSeq"),
|
||||
"Content-Type: application/vnd.3gpp.ussd",
|
||||
"Content-Transfer-Encoding: binary",
|
||||
fmt.Sprintf("Content-Length: %d", len(replyBody)), "", "",
|
||||
}, "\r\n"))
|
||||
reply = append(reply, replyBody...)
|
||||
if _, err = listener.WriteToUDP(reply, remote); err != nil {
|
||||
return err
|
||||
}
|
||||
close(readyForClose)
|
||||
|
||||
count, remote, err = listener.ReadFromUDP(packet)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
_, headers, err = parseTestRequest(packet[:count])
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
if headers["expires"] != "0" {
|
||||
return errors.New("expected deregistration")
|
||||
}
|
||||
_, err = listener.WriteToUDP(testResponse(200, "OK", registerCallID, headers["cseq"], nil), remote)
|
||||
return err
|
||||
}
|
||||
|
||||
// fakeConn is a minimal net.Conn useful for tests that only need LocalAddr
|
||||
// to succeed and do not care about the actual SIP MESSAGE delivery report.
|
||||
type fakeConn struct{}
|
||||
|
||||
func (*fakeConn) Read([]byte) (int, error) { return 0, errors.New("fakeConn: closed") }
|
||||
func (*fakeConn) Write(source []byte) (int, error) { return len(source), nil }
|
||||
func (*fakeConn) Close() error { return nil }
|
||||
func (*fakeConn) LocalAddr() net.Addr {
|
||||
return &net.UDPAddr{IP: net.IPv4(192, 0, 2, 10), Port: 5060}
|
||||
}
|
||||
func (*fakeConn) RemoteAddr() net.Addr {
|
||||
return &net.UDPAddr{IP: net.IPv4(192, 0, 2, 20), Port: 5060}
|
||||
}
|
||||
func (*fakeConn) SetDeadline(time.Time) error { return nil }
|
||||
func (*fakeConn) SetReadDeadline(time.Time) error { return nil }
|
||||
func (*fakeConn) SetWriteDeadline(time.Time) error { return nil }
|
||||
|
||||
@@ -560,6 +560,35 @@ func (orchestrator *Orchestrator) SendSMS(
|
||||
return sender.SendSMS(ctx, request)
|
||||
}
|
||||
|
||||
// SendUSSI submits a USSD dialog turn through the currently registered IMS
|
||||
// session. USSI only requires IMS registration — it does not depend on the
|
||||
// +g.3gpp.smsip contact being confirmed, so the readiness gate is IMSReady
|
||||
// alone (unlike SendSMS which also requires SMSReady).
|
||||
func (orchestrator *Orchestrator) SendUSSI(
|
||||
ctx context.Context,
|
||||
request USSISubmitRequest,
|
||||
) (USSISubmitResult, error) {
|
||||
if ctx == nil {
|
||||
ctx = context.Background()
|
||||
}
|
||||
if err := orchestrator.lockOperation(ctx); err != nil {
|
||||
return USSISubmitResult{}, err
|
||||
}
|
||||
defer orchestrator.unlockOperation()
|
||||
orchestrator.mu.Lock()
|
||||
resources := orchestrator.resources
|
||||
ready := orchestrator.state.IMSReady
|
||||
orchestrator.mu.Unlock()
|
||||
if resources == nil || resources.ims == nil || !ready {
|
||||
return USSISubmitResult{}, ErrUSSINotReady
|
||||
}
|
||||
sender, ok := resources.ims.(USSISender)
|
||||
if !ok {
|
||||
return USSISubmitResult{}, ErrUSSINotReady
|
||||
}
|
||||
return sender.SendUSSI(ctx, request)
|
||||
}
|
||||
|
||||
func (orchestrator *Orchestrator) Calls() ([]Call, error) {
|
||||
orchestrator.mu.Lock()
|
||||
resources := orchestrator.resources
|
||||
|
||||
@@ -318,6 +318,27 @@ func (manager *Manager) SendSMS(
|
||||
return item.orchestrator.SendSMS(ctx, request)
|
||||
}
|
||||
|
||||
func (manager *Manager) SendUSSI(
|
||||
ctx context.Context,
|
||||
deviceID string,
|
||||
request vowifi.USSISubmitRequest,
|
||||
) (vowifi.USSISubmitResult, error) {
|
||||
if err := manager.Ensure(ctx, deviceID); err != nil {
|
||||
return vowifi.USSISubmitResult{}, err
|
||||
}
|
||||
manager.mu.Lock()
|
||||
if manager.closed {
|
||||
manager.mu.Unlock()
|
||||
return vowifi.USSISubmitResult{}, ErrClosed
|
||||
}
|
||||
item := manager.entries[deviceID]
|
||||
manager.mu.Unlock()
|
||||
if item == nil {
|
||||
return vowifi.USSISubmitResult{}, ErrNotRegistered
|
||||
}
|
||||
return item.orchestrator.SendUSSI(ctx, request)
|
||||
}
|
||||
|
||||
func (manager *Manager) Calls(deviceID string) ([]vowifi.Call, error) {
|
||||
if err := manager.Ensure(manager.ctx, deviceID); err != nil {
|
||||
return nil, err
|
||||
|
||||
@@ -53,6 +53,7 @@ var (
|
||||
ErrTunnelNotEstablished = errors.New("vowifi: tunnel is not established")
|
||||
ErrIMSNotRegistered = errors.New("vowifi: IMS is not registered")
|
||||
ErrSMSNotReady = errors.New("vowifi: SMS over IMS is not ready")
|
||||
ErrUSSINotReady = errors.New("vowifi: USSI over IMS is not ready")
|
||||
ErrEAPAuthenticationRejected = errors.New("vowifi: EAP-AKA authentication rejected")
|
||||
ErrResponderAUTHRequired = errors.New("vowifi: verified IKE responder AUTH is required")
|
||||
// ErrCleanupIncomplete marks a teardown that released its local IMS, tunnel,
|
||||
@@ -297,6 +298,27 @@ type SMSSubmitResult struct {
|
||||
PartResults []SMSSubmitPart `json:"partResults"`
|
||||
}
|
||||
|
||||
// USSISubmitRequest is one USSD dialog turn over IMS (3GPP TS 24.390). The
|
||||
// first turn carries the service code in Code; a follow-up turn on an open
|
||||
// dialog carries the menu reply in Input and leaves Code empty.
|
||||
type USSISubmitRequest struct {
|
||||
Code string
|
||||
Input string
|
||||
}
|
||||
|
||||
// USSISubmitResult mirrors the device.USSDResult shape so the HTTP layer can
|
||||
// present USSI and cellular CUSD results uniformly.
|
||||
type USSISubmitResult struct {
|
||||
Status string `json:"status,omitempty"`
|
||||
Text string `json:"text"`
|
||||
Raw string `json:"raw,omitempty"`
|
||||
DCS *int `json:"dcs,omitempty"`
|
||||
Continueable bool `json:"continueable,omitempty"`
|
||||
SessionID string `json:"sessionId,omitempty"`
|
||||
SIPCode int `json:"sipCode,omitempty"`
|
||||
SubmissionStatus string `json:"submissionStatus,omitempty"`
|
||||
}
|
||||
|
||||
type PhoneRecord struct {
|
||||
ICCID string
|
||||
Number string
|
||||
@@ -397,6 +419,13 @@ type SMSSender interface {
|
||||
SendSMS(context.Context, SMSSubmitRequest) (SMSSubmitResult, error)
|
||||
}
|
||||
|
||||
// USSISender is an optional capability of a registered IMS session. Unlike SMS
|
||||
// it does not require the +g.3gpp.smsip contact to be confirmed — USSI rides
|
||||
// directly on a SIP MESSAGE with application/vnd.3gpp.ussd (TS 24.390).
|
||||
type USSISender interface {
|
||||
SendUSSI(context.Context, USSISubmitRequest) (USSISubmitResult, error)
|
||||
}
|
||||
|
||||
// Call describes one IMS call and reports whether an RTP media stream is
|
||||
// available to an authenticated extension.
|
||||
type Call struct {
|
||||
|
||||
+39
-5
@@ -3,9 +3,9 @@
|
||||
# vocat install / update script for systemd and OpenWrt/procd deployments.
|
||||
#
|
||||
# Usage:
|
||||
# bash install.sh [version] # run directly when already root
|
||||
# sudo bash install.sh [version] # run through sudo as a normal user
|
||||
# bash install.sh --check-env # check VoWiFi host prerequisites
|
||||
# bash install.sh [--check-env] [--skip-vowifi-check] [version] # run directly when already root
|
||||
# sudo bash install.sh [--check-env] [--skip-vowifi-check] [version] # run through sudo as a normal user
|
||||
# bash install.sh --check-env # check VoWiFi host prerequisites
|
||||
#
|
||||
# Behavior:
|
||||
# - Prompts for script language (中文 / English) as soon as it runs.
|
||||
@@ -195,6 +195,39 @@ install_linux_ip_tool() {
|
||||
fi
|
||||
}
|
||||
|
||||
install_qmi_support() {
|
||||
msg "正在检查 QMI 命令行工具..." "Checking QMI command-line utilities..."
|
||||
if command -v qmicli >/dev/null 2>&1 && command -v qmi-network >/dev/null 2>&1; then
|
||||
return 0
|
||||
fi
|
||||
|
||||
if is_openwrt && command -v opkg >/dev/null 2>&1; then
|
||||
opkg update >/dev/null 2>&1 || true
|
||||
if opkg_has_package libqmi; then
|
||||
opkg install libqmi >/dev/null 2>&1 || true
|
||||
fi
|
||||
elif command -v apt-get >/dev/null 2>&1; then
|
||||
apt-get update -qq || true
|
||||
DEBIAN_FRONTEND=noninteractive apt-get install -y libqmi-utils || true
|
||||
elif command -v dnf >/dev/null 2>&1; then
|
||||
dnf install -y libqmi-utils || true
|
||||
elif command -v yum >/dev/null 2>&1; then
|
||||
yum install -y libqmi-utils || true
|
||||
elif command -v pacman >/dev/null 2>&1; then
|
||||
pacman -Sy --noconfirm libqmi || true
|
||||
elif command -v apk >/dev/null 2>&1; then
|
||||
apk add --no-cache qmi-utils || true
|
||||
fi
|
||||
|
||||
if command -v qmicli >/dev/null 2>&1 && command -v qmi-network >/dev/null 2>&1; then
|
||||
msg "QMI 命令行工具已就绪。" "QMI command-line utilities are ready."
|
||||
return 0
|
||||
fi
|
||||
die \
|
||||
"无法安装或找到 qmicli/qmi-network。请安装系统提供的 libqmi/qmi-utils 软件包后重试。" \
|
||||
"Could not install or find qmicli/qmi-network. Install your distribution's libqmi/qmi-utils package and retry."
|
||||
}
|
||||
|
||||
install_pcsc_support() {
|
||||
msg "正在检查 USB SIM 读卡器的 PC/SC 运行环境..." "Checking the PC/SC environment for USB SIM readers..."
|
||||
local installed=0
|
||||
@@ -263,8 +296,8 @@ check_vowifi_environment() {
|
||||
"The OpenWrt/Kwrt kernel $(uname -r) lacks NETLINK_XFRM and its feed has no matching kmod-ipsec. Use a firmware built with matching kmod-ipsec, kmod-ipsec4/6, crypto-authenc, CBC, AES and SHA1 modules. Never force kmods from another kernel. Use --skip-vowifi-check only for non-VoWiFi operation."
|
||||
fi
|
||||
die \
|
||||
"当前 Linux 内核不支持 XFRM/IPsec,VoWiFi IMS 无法工作。请启用 CONFIG_XFRM、CONFIG_XFRM_USER、CONFIG_INET_ESP、CONFIG_INET6_ESP、AES-CBC 和 HMAC-SHA1。" \
|
||||
"This Linux kernel lacks XFRM/IPsec required by VoWiFi IMS. Enable CONFIG_XFRM, CONFIG_XFRM_USER, CONFIG_INET_ESP, CONFIG_INET6_ESP, AES-CBC and HMAC-SHA1."
|
||||
"当前 Linux 内核不支持 XFRM/IPsec,VoWiFi IMS 无法工作。请启用 CONFIG_XFRM、CONFIG_XFRM_USER、CONFIG_INET_ESP、CONFIG_INET6_ESP、AES-CBC 和 HMAC-SHA1;若仅使用非 VoWiFi 功能(蜂窝短信/数据等),可重新运行安装脚本并加 --skip-vowifi-check。" \
|
||||
"This Linux kernel lacks XFRM/IPsec required by VoWiFi IMS. Enable CONFIG_XFRM, CONFIG_XFRM_USER, CONFIG_INET_ESP, CONFIG_INET6_ESP, AES-CBC and HMAC-SHA1; or re-run with --skip-vowifi-check if you only need non-VoWiFi features (cellular SMS/data)."
|
||||
}
|
||||
|
||||
# --- Skip if already installed at the same version ---------------------------
|
||||
@@ -538,6 +571,7 @@ enable_and_start() {
|
||||
|
||||
# --- Main --------------------------------------------------------------------
|
||||
detect_arch
|
||||
install_qmi_support
|
||||
install_pcsc_support
|
||||
check_vowifi_environment
|
||||
if [ "$CHECK_ENV" -eq 1 ]; then
|
||||
|
||||
Generated
+1896
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,2 @@
|
||||
allowBuilds:
|
||||
esbuild: set this to true or false
|
||||
@@ -1,7 +1,7 @@
|
||||
import { useState } from "react";
|
||||
import { WindowConsoleRegular, WarningRegular } from "@fluentui/react-icons";
|
||||
import { api } from "../../api";
|
||||
import { Button, Input, Select } from "../ui";
|
||||
import { Button, Input, Select, Switch } from "../ui";
|
||||
import { AT_COMMAND_GROUPS } from "./atCommands";
|
||||
import { AtLogEntry, AtTypingBubble, type AtLogItem } from "./AtLogEntry";
|
||||
import { useI18n } from "../../lib/i18n";
|
||||
@@ -19,6 +19,7 @@ export function DeviceAtTab({ deviceId, backendMode, atPort, running }: DeviceAt
|
||||
const [template, setTemplate] = useState("");
|
||||
const [timeoutMs, setTimeoutMs] = useState<number>(10000);
|
||||
const [sending, setSending] = useState(false);
|
||||
const [force, setForce] = useState(false);
|
||||
const [log, setLog] = useState<AtLogItem[]>([]);
|
||||
|
||||
const hasAtPort = String(atPort || "").trim().length > 0;
|
||||
@@ -40,7 +41,7 @@ export function DeviceAtTab({ deviceId, backendMode, atPort, running }: DeviceAt
|
||||
try {
|
||||
const res = await api<{ ok?: boolean; response?: string; result?: string }>(`/devices/${deviceId}/actions/at`, {
|
||||
method: "POST",
|
||||
body: { cmd: command, timeoutMs: timeoutMs || 10000 },
|
||||
body: { cmd: command, timeoutMs: timeoutMs || 10000, force },
|
||||
});
|
||||
setLog((prev) => [
|
||||
...prev,
|
||||
@@ -120,6 +121,13 @@ export function DeviceAtTab({ deviceId, backendMode, atPort, running }: DeviceAt
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
<div className="mt-3 flex items-center justify-end gap-3">
|
||||
<div className="flex items-center gap-2 text-sm text-orange-600 dark:text-orange-400">
|
||||
<WarningRegular className="text-base" />
|
||||
<span>{t("强制模式允许发送默认被拦截的 AT 指令(如切网、拨号、短信、USSD),误操作可能导致断网或费用扣除。")}</span>
|
||||
</div>
|
||||
<Switch checked={force} onChange={setForce} ariaLabel={t("强制发送 AT 指令")} />
|
||||
</div>
|
||||
</>
|
||||
) : (
|
||||
<div className="mt-4 flex flex-col items-center justify-center rounded-xl border border-orange-100 bg-orange-50 p-8 dark:border-orange-900/50 dark:bg-orange-900/20">
|
||||
|
||||
@@ -7,7 +7,7 @@ import { AtTypingBubble } from "./AtLogEntry";
|
||||
import { tf, useI18n } from "../../lib/i18n";
|
||||
|
||||
interface UssdResult {
|
||||
status?: number;
|
||||
status?: string;
|
||||
text?: string;
|
||||
rawText?: string;
|
||||
dcs?: number;
|
||||
@@ -40,7 +40,7 @@ export function DeviceUssdTab({ deviceId }: { deviceId: string }) {
|
||||
const res = await api<{ result?: Record<string, unknown>; channel?: string }>(path, { method: "POST", body });
|
||||
const r = (res?.result || {}) as Record<string, unknown>;
|
||||
return {
|
||||
status: r.status as number | undefined,
|
||||
status: r.status as string | undefined,
|
||||
text: (r.text as string) || "",
|
||||
rawText: ((r.rawText as string) || (r.rawXml as string) || "") as string,
|
||||
dcs: r.dcs as number | undefined,
|
||||
@@ -59,15 +59,15 @@ export function DeviceUssdTab({ deviceId }: { deviceId: string }) {
|
||||
const v = await callUssd(command);
|
||||
if (v.channel) setChannel(v.channel);
|
||||
const text = v.text || v.rawText || t("[空响应]");
|
||||
if (v.status === 5) {
|
||||
if (v.status === "failed") {
|
||||
setLog((prev) => [...prev, { ts: Date.now(), type: "err", content: tf("[网络不支持/无响应]\n{text}", { text }), dcs: v.dcs, channel: v.channel }]);
|
||||
clearSession();
|
||||
} else if (v.status === 2) {
|
||||
} else if (v.status === "terminated") {
|
||||
setLog((prev) => [...prev, { ts: Date.now(), type: "err", content: tf("[被网络终止]\n{text}", { text }), dcs: v.dcs, channel: v.channel }]);
|
||||
clearSession();
|
||||
} else {
|
||||
setLog((prev) => [...prev, { ts: Date.now(), type: "res", content: text, dcs: v.dcs, channel: v.channel }]);
|
||||
if (v.status === 1 && v.sessionId) setSessionId(v.sessionId);
|
||||
if (v.status === "awaiting_input" && v.sessionId) setSessionId(v.sessionId);
|
||||
else clearSession();
|
||||
}
|
||||
} catch (e) {
|
||||
|
||||
@@ -23,7 +23,9 @@ export function DiscoveredDeviceRow({
|
||||
? t("系统已发现 USB 读卡器,但 PC/SC 服务未运行;请安装并启动 pcscd 后重新扫描。")
|
||||
: device.discoveryIssue === "pcsc_driver_missing"
|
||||
? t("系统已发现 USB 读卡器,但 PC/SC 驱动未加载;请安装 libccid 或厂商驱动后重新扫描。")
|
||||
: "";
|
||||
: device.discoveryIssue === "at_port_missing"
|
||||
? t("已发现该模组,但未找到 AT 串口:通常是 option 驱动未认该 PID 或模组处于 MBIM/RNDIS 组态。可 `echo 2c7c <pid> | sudo tee /sys/bus/usb-serial/drivers/option1/new_id` 后重扫,或用 AT+QCFG 切到 QMI+AT 组态。")
|
||||
: "";
|
||||
return (
|
||||
<button
|
||||
type="button"
|
||||
|
||||
@@ -685,6 +685,8 @@ export const EN_DICT: Record<string, string> = {
|
||||
"AT 终端暂不可用": "AT terminal unavailable",
|
||||
"AT=串口 / QMI=纯 QMI": "AT=serial / QMI=pure QMI",
|
||||
"AT=传统串口 / QMI=纯 QMI": "AT=legacy serial / QMI=pure QMI",
|
||||
"强制发送 AT 指令": "Force-send AT command",
|
||||
"强制模式允许发送默认被拦截的 AT 指令(如切网、拨号、短信、USSD),误操作可能导致断网或费用扣除。": "Force mode allows sending AT commands that are normally blocked (e.g. mode switching, dialing, SMS, USSD). Mistakes may disconnect the network or incur charges.",
|
||||
"E911地址": "E911 Address",
|
||||
"E911地址设置页面打开失败": "Failed to open the E911 address setup page",
|
||||
"IMEI 绑定": "IMEI Binding",
|
||||
@@ -820,6 +822,8 @@ export const EN_DICT: Record<string, string> = {
|
||||
"匹配依据": "Profile Match",
|
||||
"方向": "Direction",
|
||||
"无法读取 IMEI(控制口可能挂死),暂不可添加。": "Cannot read the IMEI (the control port may be stuck); cannot add for now.",
|
||||
"已发现该模组,但未找到 AT 串口:通常是 option 驱动未认该 PID 或模组处于 MBIM/RNDIS 组态。可 `echo 2c7c <pid> | sudo tee /sys/bus/usb-serial/drivers/option1/new_id` 后重扫,或用 AT+QCFG 切到 QMI+AT 组态。":
|
||||
"The modem was discovered, but no AT serial port was found. This usually means the `option` driver does not recognize this PID, or the module is in an MBIM/RNDIS composition. Run `echo 2c7c <pid> | sudo tee /sys/bus/usb-serial/drivers/option1/new_id` then rescan, or use AT+QCFG to switch to a QMI+AT composition.",
|
||||
"未找到可用的 AT 端口(串口可能仍在枚举),系统会自动重试;也可点击重新扫描。":
|
||||
"No usable AT port was found (serial interfaces may still be enumerating). The system retries automatically; you can also rescan now.",
|
||||
"无法读取该设备 IMEI(可能控制口挂死),请执行 AT!RESET 或切换组态后重试": "Cannot read the device IMEI (the control port may be stuck); run AT!RESET or switch the USB composition and retry",
|
||||
|
||||
@@ -381,6 +381,10 @@ export default function DevicesPage() {
|
||||
message.warning(t("系统已发现 USB 读卡器,但 PC/SC 驱动未加载;请安装 libccid 或厂商驱动后重新扫描。"));
|
||||
return;
|
||||
}
|
||||
if (d.discoveryIssue === "at_port_missing") {
|
||||
message.warning(t("已发现该模组,但未找到 AT 串口:通常是 option 驱动未认该 PID 或模组处于 MBIM/RNDIS 组态。可 `echo 2c7c <pid> | sudo tee /sys/bus/usb-serial/drivers/option1/new_id` 后重扫,或用 AT+QCFG 切到 QMI+AT 组态。"));
|
||||
return;
|
||||
}
|
||||
if (d.degraded) {
|
||||
message.warning(t("无法读取该设备 IMEI(可能控制口挂死),请执行 AT!RESET 或切换组态后重试"));
|
||||
return;
|
||||
|
||||
Reference in New Issue
Block a user