Fix a race condition in res_pjsip_session with rapidly terminating the session.
[asterisk/asterisk.git] / res / res_pjsip_session.c
1 /*
2 * Asterisk -- An open source telephony toolkit.
3 *
4 * Copyright (C) 2013, Digium, Inc.
5 *
6 * Mark Michelson <mmichelson@digium.com>
7 *
8 * See http://www.asterisk.org for more information about
9 * the Asterisk project. Please do not directly contact
10 * any of the maintainers of this project for assistance;
11 * the project provides a web site, mailing lists and IRC
12 * channels for your use.
13 *
14 * This program is free software, distributed under the terms of
15 * the GNU General Public License Version 2. See the LICENSE file
16 * at the top of the source tree.
17 */
18
19 /*** MODULEINFO
20         <depend>pjproject</depend>
21         <depend>res_pjsip</depend>
22         <support_level>core</support_level>
23  ***/
24
25 #include "asterisk.h"
26
27 #include <pjsip.h>
28 #include <pjsip_ua.h>
29 #include <pjlib.h>
30
31 #include "asterisk/res_pjsip.h"
32 #include "asterisk/res_pjsip_session.h"
33 #include "asterisk/datastore.h"
34 #include "asterisk/module.h"
35 #include "asterisk/logger.h"
36 #include "asterisk/res_pjsip.h"
37 #include "asterisk/astobj2.h"
38 #include "asterisk/lock.h"
39 #include "asterisk/uuid.h"
40 #include "asterisk/pbx.h"
41 #include "asterisk/taskprocessor.h"
42 #include "asterisk/causes.h"
43 #include "asterisk/sdp_srtp.h"
44 #include "asterisk/dsp.h"
45 #include "asterisk/acl.h"
46
47 #define SDP_HANDLER_BUCKETS 11
48
49 #define MOD_DATA_ON_RESPONSE "on_response"
50 #define MOD_DATA_NAT_HOOK "nat_hook"
51
52 /* Hostname used for origin line within SDP */
53 static const pj_str_t *hostname;
54
55 /* Some forward declarations */
56 static void handle_incoming_request(struct ast_sip_session *session, pjsip_rx_data *rdata);
57 static void handle_incoming_response(struct ast_sip_session *session, pjsip_rx_data *rdata);
58 static int handle_incoming(struct ast_sip_session *session, pjsip_rx_data *rdata);
59 static void handle_outgoing_request(struct ast_sip_session *session, pjsip_tx_data *tdata);
60 static void handle_outgoing_response(struct ast_sip_session *session, pjsip_tx_data *tdata);
61 static void handle_outgoing(struct ast_sip_session *session, pjsip_tx_data *tdata);
62
63 /*! \brief NAT hook for modifying outgoing messages with SDP */
64 static struct ast_sip_nat_hook *nat_hook;
65
66 /*!
67  * \brief Registered SDP stream handlers
68  *
69  * This container is keyed on stream types. Each
70  * object in the container is a linked list of
71  * handlers for the stream type.
72  */
73 static struct ao2_container *sdp_handlers;
74
75 /*!
76  * These are the objects in the sdp_handlers container
77  */
78 struct sdp_handler_list {
79         /* The list of handlers to visit */
80         AST_LIST_HEAD_NOLOCK(, ast_sip_session_sdp_handler) list;
81         /* The handlers in this list handle streams of this type */
82         char stream_type[1];
83 };
84
85 static struct pjmedia_sdp_session *create_local_sdp(pjsip_inv_session *inv, struct ast_sip_session *session, const pjmedia_sdp_session *offer);
86
87 static int sdp_handler_list_hash(const void *obj, int flags)
88 {
89         const struct sdp_handler_list *handler_list = obj;
90         const char *stream_type = flags & OBJ_KEY ? obj : handler_list->stream_type;
91
92         return ast_str_hash(stream_type);
93 }
94
95 static int sdp_handler_list_cmp(void *obj, void *arg, int flags)
96 {
97         struct sdp_handler_list *handler_list1 = obj;
98         struct sdp_handler_list *handler_list2 = arg;
99         const char *stream_type2 = flags & OBJ_KEY ? arg : handler_list2->stream_type;
100
101         return strcmp(handler_list1->stream_type, stream_type2) ? 0 : CMP_MATCH | CMP_STOP;
102 }
103
104 static int session_media_hash(const void *obj, int flags)
105 {
106         const struct ast_sip_session_media *session_media = obj;
107         const char *stream_type = flags & OBJ_KEY ? obj : session_media->stream_type;
108
109         return ast_str_hash(stream_type);
110 }
111
112 static int session_media_cmp(void *obj, void *arg, int flags)
113 {
114         struct ast_sip_session_media *session_media1 = obj;
115         struct ast_sip_session_media *session_media2 = arg;
116         const char *stream_type2 = flags & OBJ_KEY ? arg : session_media2->stream_type;
117
118         return strcmp(session_media1->stream_type, stream_type2) ? 0 : CMP_MATCH | CMP_STOP;
119 }
120
121 int ast_sip_session_register_sdp_handler(struct ast_sip_session_sdp_handler *handler, const char *stream_type)
122 {
123         RAII_VAR(struct sdp_handler_list *, handler_list,
124                         ao2_find(sdp_handlers, stream_type, OBJ_KEY), ao2_cleanup);
125         SCOPED_AO2LOCK(lock, sdp_handlers);
126
127         if (handler_list) {
128                 struct ast_sip_session_sdp_handler *iter;
129                 /* Check if this handler is already registered for this stream type */
130                 AST_LIST_TRAVERSE(&handler_list->list, iter, next) {
131                         if (!strcmp(iter->id, handler->id)) {
132                                 ast_log(LOG_WARNING, "Handler '%s' already registered for stream type '%s'.\n", handler->id, stream_type);
133                                 return -1;
134                         }
135                 }
136                 AST_LIST_INSERT_TAIL(&handler_list->list, handler, next);
137                 ast_debug(1, "Registered SDP stream handler '%s' for stream type '%s'\n", handler->id, stream_type);
138                 ast_module_ref(ast_module_info->self);
139                 return 0;
140         }
141
142         /* No stream of this type has been registered yet, so we need to create a new list */
143         handler_list = ao2_alloc(sizeof(*handler_list) + strlen(stream_type), NULL);
144         if (!handler_list) {
145                 return -1;
146         }
147         /* Safe use of strcpy */
148         strcpy(handler_list->stream_type, stream_type);
149         AST_LIST_HEAD_INIT_NOLOCK(&handler_list->list);
150         AST_LIST_INSERT_TAIL(&handler_list->list, handler, next);
151         if (!ao2_link(sdp_handlers, handler_list)) {
152                 return -1;
153         }
154         ast_debug(1, "Registered SDP stream handler '%s' for stream type '%s'\n", handler->id, stream_type);
155         ast_module_ref(ast_module_info->self);
156         return 0;
157 }
158
159 static int remove_handler(void *obj, void *arg, void *data, int flags)
160 {
161         struct sdp_handler_list *handler_list = obj;
162         struct ast_sip_session_sdp_handler *handler = data;
163         struct ast_sip_session_sdp_handler *iter;
164         const char *stream_type = arg;
165
166         AST_LIST_TRAVERSE_SAFE_BEGIN(&handler_list->list, iter, next) {
167                 if (!strcmp(iter->id, handler->id)) {
168                         AST_LIST_REMOVE_CURRENT(next);
169                         ast_debug(1, "Unregistered SDP stream handler '%s' for stream type '%s'\n", handler->id, stream_type);
170                         ast_module_unref(ast_module_info->self);
171                 }
172         }
173         AST_LIST_TRAVERSE_SAFE_END;
174
175         if (AST_LIST_EMPTY(&handler_list->list)) {
176                 ast_debug(3, "No more handlers exist for stream type '%s'\n", stream_type);
177                 return CMP_MATCH;
178         } else {
179                 return CMP_STOP;
180         }
181 }
182
183 void ast_sip_session_unregister_sdp_handler(struct ast_sip_session_sdp_handler *handler, const char *stream_type)
184 {
185         ao2_callback_data(sdp_handlers, OBJ_KEY | OBJ_UNLINK | OBJ_NODATA, remove_handler, (void *)stream_type, handler);
186 }
187
188 static int validate_port_hash(const void *obj, int flags)
189 {
190         const int *port = obj;
191         return *port;
192 }
193
194 static int validate_port_cmp(void *obj, void *arg, int flags)
195 {
196         int *port1 = obj;
197         int *port2 = arg;
198
199         return *port1 == *port2 ? CMP_MATCH | CMP_STOP : 0;
200 }
201
202 struct bundle_assoc {
203         int port;
204         char tag[1];
205 };
206
207 static int bundle_assoc_hash(const void *obj, int flags)
208 {
209         const struct bundle_assoc *assoc = obj;
210         const char *tag = flags & OBJ_KEY ? obj : assoc->tag;
211
212         return ast_str_hash(tag);
213 }
214
215 static int bundle_assoc_cmp(void *obj, void *arg, int flags)
216 {
217         struct bundle_assoc *assoc1 = obj;
218         struct bundle_assoc *assoc2 = arg;
219         const char *tag2 = flags & OBJ_KEY ? arg : assoc2->tag;
220
221         return strcmp(assoc1->tag, tag2) ? 0 : CMP_MATCH | CMP_STOP;
222 }
223
224 /* return must be ast_freed */
225 static pjmedia_sdp_attr *media_get_mid(pjmedia_sdp_media *media)
226 {
227         pjmedia_sdp_attr *attr = pjmedia_sdp_media_find_attr2(media, "mid", NULL);
228         if (!attr) {
229                 return NULL;
230         }
231
232         return attr;
233 }
234
235 static int get_bundle_port(const pjmedia_sdp_session *sdp, const char *mid)
236 {
237         int i;
238         for (i = 0; i < sdp->media_count; ++i) {
239                 pjmedia_sdp_attr *mid_attr = media_get_mid(sdp->media[i]);
240                 if (mid_attr && !pj_strcmp2(&mid_attr->value, mid)) {
241                         return sdp->media[i]->desc.port;
242                 }
243         }
244
245         return -1;
246 }
247
248 static int validate_incoming_sdp(const pjmedia_sdp_session *sdp)
249 {
250         int i;
251         RAII_VAR(struct ao2_container *, portlist, ao2_container_alloc(5, validate_port_hash, validate_port_cmp), ao2_cleanup);
252         RAII_VAR(struct ao2_container *, bundle_assoc_list, ao2_container_alloc(5, bundle_assoc_hash, bundle_assoc_cmp), ao2_cleanup);
253
254         /* check for bundles (for websocket RTP multiplexing, there can be more than one) */
255         for (i = 0; i < sdp->attr_count; ++i) {
256                 char *bundle_list;
257                 int bundle_port = 0;
258                 if (pj_stricmp2(&sdp->attr[i]->name, "group")) {
259                         continue;
260                 }
261
262                 /* check to see if this group is a bundle */
263                 if (7 >= sdp->attr[i]->value.slen || pj_strnicmp2(&sdp->attr[i]->value, "bundle ", 7)) {
264                         continue;
265                 }
266
267                 bundle_list = ast_alloca(sdp->attr[i]->value.slen - 6);
268                 strncpy(bundle_list, sdp->attr[i]->value.ptr + 7, sdp->attr[i]->value.slen - 7);
269                 bundle_list[sdp->attr[i]->value.slen - 7] = '\0';
270                 while (bundle_list) {
271                         char *item;
272                         RAII_VAR(struct bundle_assoc *, assoc, NULL, ao2_cleanup);
273                         item = strsep(&bundle_list, " ,");
274                         if (!bundle_port) {
275                                 RAII_VAR(int *, port, ao2_alloc(sizeof(int), NULL), ao2_cleanup);
276                                 RAII_VAR(int *, port_match, NULL, ao2_cleanup);
277                                 bundle_port = get_bundle_port(sdp, item);
278                                 if (bundle_port < 0) {
279                                         return -1;
280                                 }
281                                 port_match = ao2_find(portlist, &bundle_port, OBJ_KEY);
282                                 if (port_match) {
283                                         /* bundle port aready consumed by a different bundle */
284                                         return -1;
285                                 }
286                                 *port = bundle_port;
287                                 ao2_link(portlist, port);
288                         }
289                         assoc = ao2_alloc(sizeof(*assoc) + strlen(item), NULL);
290                         if (!assoc) {
291                                 return -1;
292                         }
293
294                         /* safe use of strcpy */
295                         strcpy(assoc->tag, item);
296                         assoc->port = bundle_port;
297                         ao2_link(bundle_assoc_list, assoc);
298                 }
299         }
300
301         /* validate all streams */
302         for (i = 0; i < sdp->media_count; ++i) {
303                 RAII_VAR(int *, port, ao2_alloc(sizeof(int), NULL), ao2_cleanup);
304                 RAII_VAR(int *, port_match, NULL, ao2_cleanup);
305                 RAII_VAR(int *, bundle_match, NULL, ao2_cleanup);
306                 *port = sdp->media[i]->desc.port;
307                 port_match = ao2_find(portlist, port, OBJ_KEY);
308                 if (port_match) {
309                         RAII_VAR(struct bundle_assoc *, assoc, NULL, ao2_cleanup);
310                         pjmedia_sdp_attr *mid = media_get_mid(sdp->media[i]);
311                         char *mid_val;
312
313                         if (!mid) {
314                                 /* not part of a bundle */
315                                 return -1;
316                         }
317
318                         mid_val = ast_alloca(mid->value.slen + 1);
319                         strncpy(mid_val, mid->value.ptr, mid->value.slen);
320                         mid_val[mid->value.slen] = '\0';
321
322                         assoc = ao2_find(bundle_assoc_list, mid_val, OBJ_KEY);
323                         if (!assoc || assoc->port != *port) {
324                                 /* This port already exists elsewhere in the SDP
325                                  * and is not an appropriate bundle port, fail
326                                  * catastrophically */
327                                 return -1;
328                         }
329                 }
330                 ao2_link(portlist, port);
331         }
332         return 0;
333 }
334
335 static int handle_incoming_sdp(struct ast_sip_session *session, const pjmedia_sdp_session *sdp)
336 {
337         int i;
338         if (validate_incoming_sdp(sdp)) {
339                 return -1;
340         }
341
342         for (i = 0; i < sdp->media_count; ++i) {
343                 /* See if there are registered handlers for this media stream type */
344                 char media[20];
345                 struct ast_sip_session_sdp_handler *handler;
346                 RAII_VAR(struct sdp_handler_list *, handler_list, NULL, ao2_cleanup);
347                 RAII_VAR(struct ast_sip_session_media *, session_media, NULL, ao2_cleanup);
348
349                 /* We need a null-terminated version of the media string */
350                 ast_copy_pj_str(media, &sdp->media[i]->desc.media, sizeof(media));
351
352                 session_media = ao2_find(session->media, media, OBJ_KEY);
353                 if (!session_media) {
354                         /* if the session_media doesn't exist, there weren't
355                          * any handlers at the time of its creation */
356                         continue;
357                 }
358
359                 if (session_media->handler) {
360                         int res;
361                         handler = session_media->handler;
362                         res = handler->negotiate_incoming_sdp_stream(
363                                 session, session_media, sdp, sdp->media[i]);
364                         if (res <= 0) {
365                                 /* Catastrophic failure or ignored by assigned handler. Abort! */
366                                 return -1;
367                         }
368                         if (res > 0) {
369                                 /* Handled by this handler. Move to the next stream */
370                                 continue;
371                         }
372                 }
373
374                 handler_list = ao2_find(sdp_handlers, media, OBJ_KEY);
375                 if (!handler_list) {
376                         ast_debug(1, "No registered SDP handlers for media type '%s'\n", media);
377                         continue;
378                 }
379                 AST_LIST_TRAVERSE(&handler_list->list, handler, next) {
380                         int res;
381                         if (session_media->handler) {
382                                 /* There is only one slot for this stream type and it has already been claimed
383                                  * so it will go unhandled */
384                                 break;
385                         }
386                         res = handler->negotiate_incoming_sdp_stream(session, session_media, sdp, sdp->media[i]);
387                         if (res < 0) {
388                                 /* Catastrophic failure. Abort! */
389                                 return -1;
390                         }
391                         if (res > 0) {
392                                 /* Handled by this handler. Move to the next stream */
393                                 session_media->handler = handler;
394                                 break;
395                         }
396                 }
397         }
398         return 0;
399 }
400
401 struct handle_negotiated_sdp_cb {
402         struct ast_sip_session *session;
403         const pjmedia_sdp_session *local;
404         const pjmedia_sdp_session *remote;
405 };
406
407 static int handle_negotiated_sdp_session_media(void *obj, void *arg, int flags)
408 {
409         struct ast_sip_session_media *session_media = obj;
410         struct handle_negotiated_sdp_cb *callback_data = arg;
411         struct ast_sip_session *session = callback_data->session;
412         const pjmedia_sdp_session *local = callback_data->local;
413         const pjmedia_sdp_session *remote = callback_data->remote;
414         int i;
415
416         for (i = 0; i < local->media_count; ++i) {
417                 /* See if there are registered handlers for this media stream type */
418                 char media[20];
419                 struct ast_sip_session_sdp_handler *handler;
420                 RAII_VAR(struct sdp_handler_list *, handler_list, NULL, ao2_cleanup);
421
422                 if (!remote->media[i]) {
423                         continue;
424                 }
425
426                 /* We need a null-terminated version of the media string */
427                 ast_copy_pj_str(media, &local->media[i]->desc.media, sizeof(media));
428
429                 /* stream type doesn't match the one we're looking to fill */
430                 if (strcasecmp(session_media->stream_type, media)) {
431                         continue;
432                 }
433
434                 handler = session_media->handler;
435                 if (handler) {
436                         int res = handler->apply_negotiated_sdp_stream(session, session_media, local, local->media[i], remote, remote->media[i]);
437                         if (res >= 0) {
438                                 return CMP_MATCH;
439                         }
440                         return 0;
441                 }
442
443                 handler_list = ao2_find(sdp_handlers, media, OBJ_KEY);
444                 if (!handler_list) {
445                         ast_debug(1, "No registered SDP handlers for media type '%s'\n", media);
446                         continue;
447                 }
448                 AST_LIST_TRAVERSE(&handler_list->list, handler, next) {
449                         int res = handler->apply_negotiated_sdp_stream(session, session_media, local, local->media[i], remote, remote->media[i]);
450                         if (res < 0) {
451                                 /* Catastrophic failure. Abort! */
452                                 return 0;
453                         }
454                         if (res > 0) {
455                                 /* Handled by this handler. Move to the next stream */
456                                 session_media->handler = handler;
457                                 return CMP_MATCH;
458                         }
459                 }
460         }
461         return CMP_MATCH;
462 }
463
464 static int handle_negotiated_sdp(struct ast_sip_session *session, const pjmedia_sdp_session *local, const pjmedia_sdp_session *remote)
465 {
466         RAII_VAR(struct ao2_iterator *, successful, NULL, ao2_iterator_cleanup);
467         struct handle_negotiated_sdp_cb callback_data = {
468                 .session = session,
469                 .local = local,
470                 .remote = remote,
471         };
472
473         successful = ao2_callback(session->media, OBJ_MULTIPLE, handle_negotiated_sdp_session_media, &callback_data);
474         if (successful && ao2_container_count(successful->c) == ao2_container_count(session->media)) {
475                 /* Nothing experienced a catastrophic failure */
476                 ast_queue_frame(session->channel, &ast_null_frame);
477                 return 0;
478         }
479         return -1;
480 }
481
482 AST_RWLIST_HEAD_STATIC(session_supplements, ast_sip_session_supplement);
483
484 int ast_sip_session_register_supplement(struct ast_sip_session_supplement *supplement)
485 {
486         struct ast_sip_session_supplement *iter;
487         int inserted = 0;
488         SCOPED_LOCK(lock, &session_supplements, AST_RWLIST_WRLOCK, AST_RWLIST_UNLOCK);
489
490         AST_RWLIST_TRAVERSE_SAFE_BEGIN(&session_supplements, iter, next) {
491                 if (iter->priority > supplement->priority) {
492                         AST_RWLIST_INSERT_BEFORE_CURRENT(supplement, next);
493                         inserted = 1;
494                         break;
495                 }
496         }
497         AST_RWLIST_TRAVERSE_SAFE_END;
498
499         if (!inserted) {
500                 AST_RWLIST_INSERT_TAIL(&session_supplements, supplement, next);
501         }
502         ast_module_ref(ast_module_info->self);
503         return 0;
504 }
505
506 void ast_sip_session_unregister_supplement(struct ast_sip_session_supplement *supplement)
507 {
508         struct ast_sip_session_supplement *iter;
509         SCOPED_LOCK(lock, &session_supplements, AST_RWLIST_WRLOCK, AST_RWLIST_UNLOCK);
510         AST_RWLIST_TRAVERSE_SAFE_BEGIN(&session_supplements, iter, next) {
511                 if (supplement == iter) {
512                         AST_RWLIST_REMOVE_CURRENT(next);
513                         ast_module_unref(ast_module_info->self);
514                         break;
515                 }
516         }
517         AST_RWLIST_TRAVERSE_SAFE_END;
518 }
519
520 static struct ast_sip_session_supplement *supplement_dup(const struct ast_sip_session_supplement *src)
521 {
522         struct ast_sip_session_supplement *dst = ast_calloc(1, sizeof(*dst));
523         if (!dst) {
524                 return NULL;
525         }
526         /* Will need to revisit if shallow copy becomes an issue */
527         *dst = *src;
528         return dst;
529 }
530
531 #define DATASTORE_BUCKETS 53
532 #define MEDIA_BUCKETS 7
533
534 static void session_datastore_destroy(void *obj)
535 {
536         struct ast_datastore *datastore = obj;
537
538         /* Using the destroy function (if present) destroy the data */
539         if (datastore->info->destroy != NULL && datastore->data != NULL) {
540                 datastore->info->destroy(datastore->data);
541                 datastore->data = NULL;
542         }
543
544         ast_free((void *) datastore->uid);
545         datastore->uid = NULL;
546 }
547
548 struct ast_datastore *ast_sip_session_alloc_datastore(const struct ast_datastore_info *info, const char *uid)
549 {
550         RAII_VAR(struct ast_datastore *, datastore, NULL, ao2_cleanup);
551         const char *uid_ptr = uid;
552
553         if (!info) {
554                 return NULL;
555         }
556
557         datastore = ao2_alloc(sizeof(*datastore), session_datastore_destroy);
558         if (!datastore) {
559                 return NULL;
560         }
561
562         datastore->info = info;
563         if (ast_strlen_zero(uid)) {
564                 /* They didn't provide an ID so we'll provide one ourself */
565                 struct ast_uuid *uuid = ast_uuid_generate();
566                 char uuid_buf[AST_UUID_STR_LEN];
567                 if (!uuid) {
568                         return NULL;
569                 }
570                 uid_ptr = ast_uuid_to_str(uuid, uuid_buf, sizeof(uuid_buf));
571                 ast_free(uuid);
572         }
573
574         datastore->uid = ast_strdup(uid_ptr);
575         if (!datastore->uid) {
576                 return NULL;
577         }
578
579         ao2_ref(datastore, +1);
580         return datastore;
581 }
582
583 int ast_sip_session_add_datastore(struct ast_sip_session *session, struct ast_datastore *datastore)
584 {
585         ast_assert(datastore != NULL);
586         ast_assert(datastore->info != NULL);
587         ast_assert(ast_strlen_zero(datastore->uid) == 0);
588
589         if (!ao2_link(session->datastores, datastore)) {
590                 return -1;
591         }
592         return 0;
593 }
594
595 struct ast_datastore *ast_sip_session_get_datastore(struct ast_sip_session *session, const char *name)
596 {
597         return ao2_find(session->datastores, name, OBJ_KEY);
598 }
599
600 void ast_sip_session_remove_datastore(struct ast_sip_session *session, const char *name)
601 {
602         ao2_callback(session->datastores, OBJ_KEY | OBJ_UNLINK | OBJ_NODATA, NULL, (void *) name);
603 }
604
605 /*!
606  * \brief Structure used for sending delayed requests
607  *
608  * Requests are typically delayed because the current transaction
609  * state of an INVITE. Once the pending INVITE transaction terminates,
610  * the delayed request will be sent
611  */
612 struct ast_sip_session_delayed_request {
613         /*! Method of the request */
614         char method[15];
615         /*! Callback to call when the delayed request is created. */
616         ast_sip_session_request_creation_cb on_request_creation;
617         /*! Callback to call when the delayed request SDP is created */
618         ast_sip_session_sdp_creation_cb on_sdp_creation;
619         /*! Callback to call when the delayed request receives a response */
620         ast_sip_session_response_cb on_response;
621         /*! Request to send */
622         pjsip_tx_data *tdata;
623         AST_LIST_ENTRY(ast_sip_session_delayed_request) next;
624 };
625
626 static struct ast_sip_session_delayed_request *delayed_request_alloc(const char *method,
627                 ast_sip_session_request_creation_cb on_request_creation,
628                 ast_sip_session_sdp_creation_cb on_sdp_creation,
629                 ast_sip_session_response_cb on_response,
630                 pjsip_tx_data *tdata)
631 {
632         struct ast_sip_session_delayed_request *delay = ast_calloc(1, sizeof(*delay));
633         if (!delay) {
634                 return NULL;
635         }
636         ast_copy_string(delay->method, method, sizeof(delay->method));
637         delay->on_request_creation = on_request_creation;
638         delay->on_sdp_creation = on_sdp_creation;
639         delay->on_response = on_response;
640         delay->tdata = tdata;
641         return delay;
642 }
643
644 static int send_delayed_request(struct ast_sip_session *session, struct ast_sip_session_delayed_request *delay)
645 {
646         ast_debug(3, "Sending delayed %s request to %s\n", delay->method, ast_sorcery_object_get_id(session->endpoint));
647
648         if (delay->tdata) {
649                 ast_sip_session_send_request_with_cb(session, delay->tdata, delay->on_response);
650                 return 0;
651         }
652
653         if (!strcmp(delay->method, "INVITE")) {
654                 ast_sip_session_refresh(session, delay->on_request_creation,
655                                 delay->on_sdp_creation, delay->on_response, AST_SIP_SESSION_REFRESH_METHOD_INVITE, 1);
656         } else if (!strcmp(delay->method, "UPDATE")) {
657                 ast_sip_session_refresh(session, delay->on_request_creation,
658                                 delay->on_sdp_creation, delay->on_response, AST_SIP_SESSION_REFRESH_METHOD_UPDATE, 1);
659         } else {
660                 ast_log(LOG_WARNING, "Unexpected delayed %s request with no existing request structure\n", delay->method);
661                 return -1;
662         }
663         return 0;
664 }
665
666 static int queued_delayed_request_send(void *data)
667 {
668         RAII_VAR(struct ast_sip_session *, session, data, ao2_cleanup);
669         RAII_VAR(struct ast_sip_session_delayed_request *, delay, NULL, ast_free_ptr);
670
671         delay = AST_LIST_REMOVE_HEAD(&session->delayed_requests, next);
672         if (!delay) {
673                 return 0;
674         }
675
676         return send_delayed_request(session, delay);
677 }
678
679 static void queue_delayed_request(struct ast_sip_session *session)
680 {
681         if (AST_LIST_EMPTY(&session->delayed_requests)) {
682                 /* No delayed request to send, so just return */
683                 return;
684         }
685
686         ast_debug(3, "Queuing delayed request to run for %s\n",
687                         ast_sorcery_object_get_id(session->endpoint));
688
689         ao2_ref(session, +1);
690         ast_sip_push_task(session->serializer, queued_delayed_request_send, session);
691 }
692
693 static int delay_request(struct ast_sip_session *session, ast_sip_session_request_creation_cb on_request,
694                 ast_sip_session_sdp_creation_cb on_sdp_creation, ast_sip_session_response_cb on_response,
695                 const char *method, pjsip_tx_data *tdata)
696 {
697         struct ast_sip_session_delayed_request *delay = delayed_request_alloc(method,
698                         on_request, on_sdp_creation, on_response, tdata);
699
700         if (!delay) {
701                 return -1;
702         }
703
704         AST_LIST_INSERT_TAIL(&session->delayed_requests, delay, next);
705         return 0;
706 }
707
708 static pjmedia_sdp_session *generate_session_refresh_sdp(struct ast_sip_session *session)
709 {
710         pjsip_inv_session *inv_session = session->inv_session;
711         const pjmedia_sdp_session *previous_sdp;
712
713         if (pjmedia_sdp_neg_was_answer_remote(inv_session->neg)) {
714                 pjmedia_sdp_neg_get_active_remote(inv_session->neg, &previous_sdp);
715         } else {
716                 pjmedia_sdp_neg_get_active_local(inv_session->neg, &previous_sdp);
717         }
718         return create_local_sdp(inv_session, session, previous_sdp);
719 }
720
721 int ast_sip_session_refresh(struct ast_sip_session *session,
722                 ast_sip_session_request_creation_cb on_request_creation,
723                 ast_sip_session_sdp_creation_cb on_sdp_creation,
724                 ast_sip_session_response_cb on_response,
725                 enum ast_sip_session_refresh_method method, int generate_new_sdp)
726 {
727         pjsip_inv_session *inv_session = session->inv_session;
728         pjmedia_sdp_session *new_sdp = NULL;
729         pjsip_tx_data *tdata;
730
731         if (inv_session->state == PJSIP_INV_STATE_DISCONNECTED) {
732                 /* Don't try to do anything with a hung-up call */
733                 ast_debug(3, "Not sending reinvite to %s because of disconnected state...\n",
734                                 ast_sorcery_object_get_id(session->endpoint));
735                 return 0;
736         }
737
738         if (method == AST_SIP_SESSION_REFRESH_METHOD_INVITE) {
739                 if (inv_session->invite_tsx) {
740                         /* We can't send a reinvite yet, so delay it */
741                         ast_debug(3, "Delaying sending reinvite to %s because of outstanding transaction...\n",
742                                         ast_sorcery_object_get_id(session->endpoint));
743                         return delay_request(session, on_request_creation, on_sdp_creation, on_response, "INVITE", NULL);
744                 } else if (inv_session->state != PJSIP_INV_STATE_CONFIRMED) {
745                         /* Initial INVITE transaction failed to progress us to a confirmed state
746                          * which means re-invites are not possible
747                          */
748                         ast_debug(3, "Not sending reinvite to %s because not in confirmed state...\n",
749                                         ast_sorcery_object_get_id(session->endpoint));
750                         return 0;
751                 }
752         }
753
754         if (generate_new_sdp) {
755                 new_sdp = generate_session_refresh_sdp(session);
756                 if (!new_sdp) {
757                         ast_log(LOG_ERROR, "Failed to generate session refresh SDP. Not sending session refresh\n");
758                         return -1;
759                 }
760                 if (on_sdp_creation) {
761                         if (on_sdp_creation(session, new_sdp)) {
762                                 return -1;
763                         }
764                 }
765         }
766
767         if (method == AST_SIP_SESSION_REFRESH_METHOD_INVITE) {
768                 if (pjsip_inv_reinvite(inv_session, NULL, new_sdp, &tdata)) {
769                         ast_log(LOG_WARNING, "Failed to create reinvite properly.\n");
770                         return -1;
771                 }
772         } else if (pjsip_inv_update(inv_session, NULL, new_sdp, &tdata)) {
773                 ast_log(LOG_WARNING, "Failed to create UPDATE properly.\n");
774                 return -1;
775         }
776         if (on_request_creation) {
777                 if (on_request_creation(session, tdata)) {
778                         return -1;
779                 }
780         }
781         ast_sip_session_send_request_with_cb(session, tdata, on_response);
782         return 0;
783 }
784
785 void ast_sip_session_send_response(struct ast_sip_session *session, pjsip_tx_data *tdata)
786 {
787         handle_outgoing_response(session, tdata);
788         pjsip_inv_send_msg(session->inv_session, tdata);
789         return;
790 }
791
792 static pj_bool_t session_on_rx_request(pjsip_rx_data *rdata);
793
794 static pjsip_module session_module = {
795         .name = {"Session Module", 14},
796         .priority = PJSIP_MOD_PRIORITY_APPLICATION,
797         .on_rx_request = session_on_rx_request,
798 };
799
800 /*! \brief Determine whether the SDP provided requires deferral of negotiating or not
801  *
802  * \retval 1 re-invite should be deferred and resumed later
803  * \retval 0 re-invite should not be deferred
804  */
805 static int sdp_requires_deferral(struct ast_sip_session *session, const pjmedia_sdp_session *sdp)
806 {
807         int i;
808         if (validate_incoming_sdp(sdp)) {
809                 return 0;
810         }
811
812         for (i = 0; i < sdp->media_count; ++i) {
813                 /* See if there are registered handlers for this media stream type */
814                 char media[20];
815                 struct ast_sip_session_sdp_handler *handler;
816                 RAII_VAR(struct sdp_handler_list *, handler_list, NULL, ao2_cleanup);
817                 RAII_VAR(struct ast_sip_session_media *, session_media, NULL, ao2_cleanup);
818
819                 /* We need a null-terminated version of the media string */
820                 ast_copy_pj_str(media, &sdp->media[i]->desc.media, sizeof(media));
821
822                 session_media = ao2_find(session->media, media, OBJ_KEY);
823                 if (!session_media) {
824                         /* if the session_media doesn't exist, there weren't
825                          * any handlers at the time of its creation */
826                         continue;
827                 }
828
829                 if (session_media->handler && session_media->handler->defer_incoming_sdp_stream) {
830                         int res;
831                         handler = session_media->handler;
832                         res = handler->defer_incoming_sdp_stream(
833                                 session, session_media, sdp, sdp->media[i]);
834                         if (res) {
835                                 return 1;
836                         }
837                 }
838
839                 handler_list = ao2_find(sdp_handlers, media, OBJ_KEY);
840                 if (!handler_list) {
841                         ast_debug(1, "No registered SDP handlers for media type '%s'\n", media);
842                         continue;
843                 }
844                 AST_LIST_TRAVERSE(&handler_list->list, handler, next) {
845                         int res;
846                         if (session_media->handler) {
847                                 /* There is only one slot for this stream type and it has already been claimed
848                                  * so it will go unhandled */
849                                 break;
850                         }
851                         if (!handler->defer_incoming_sdp_stream) {
852                                 continue;
853                         }
854                         res = handler->defer_incoming_sdp_stream(session, session_media, sdp, sdp->media[i]);
855                         if (res) {
856                                 return 1;
857                         }
858                 }
859         }
860         return 0;
861 }
862
863 static pj_bool_t session_reinvite_on_rx_request(pjsip_rx_data *rdata)
864 {
865         pjsip_dialog *dlg;
866         RAII_VAR(struct ast_sip_session *, session, NULL, ao2_cleanup);
867         pjsip_rdata_sdp_info *sdp_info;
868
869         if (rdata->msg_info.msg->line.req.method.id != PJSIP_INVITE_METHOD ||
870                 !(dlg = pjsip_ua_find_dialog(&rdata->msg_info.cid->id, &rdata->msg_info.to->tag, &rdata->msg_info.from->tag, PJ_FALSE)) ||
871                 !(session = ast_sip_dialog_get_session(dlg))) {
872                 return PJ_FALSE;
873         }
874
875         if (session->deferred_reinvite) {
876                 pj_str_t key, deferred_key;
877                 pjsip_tx_data *tdata;
878
879                 /* We use memory from the new request on purpose so the deferred reinvite pool does not grow uncontrollably */
880                 pjsip_tsx_create_key(rdata->tp_info.pool, &key, PJSIP_ROLE_UAS, &rdata->msg_info.cseq->method, rdata);
881                 pjsip_tsx_create_key(rdata->tp_info.pool, &deferred_key, PJSIP_ROLE_UAS, &session->deferred_reinvite->msg_info.cseq->method,
882                         session->deferred_reinvite);
883
884                 /* If this is a retransmission ignore it */
885                 if (!pj_strcmp(&key, &deferred_key)) {
886                         return PJ_TRUE;
887                 }
888
889                 /* Otherwise this is a new re-invite, so reject it */
890                 if (pjsip_dlg_create_response(dlg, rdata, 491, NULL, &tdata) == PJ_SUCCESS) {
891                         pjsip_endpt_send_response2(ast_sip_get_pjsip_endpoint(), rdata, tdata, NULL, NULL);
892                 }
893
894                 return PJ_TRUE;
895         }
896
897         if (!(sdp_info = pjsip_rdata_get_sdp_info(rdata)) ||
898                 (sdp_info->sdp_err != PJ_SUCCESS) ||
899                 !sdp_info->sdp ||
900                 !sdp_requires_deferral(session, sdp_info->sdp)) {
901                 return PJ_FALSE;
902         }
903
904         pjsip_rx_data_clone(rdata, 0, &session->deferred_reinvite);
905
906         return PJ_TRUE;
907 }
908
909 void ast_sip_session_resume_reinvite(struct ast_sip_session *session)
910 {
911         if (!session->deferred_reinvite) {
912                 return;
913         }
914
915         pjsip_endpt_process_rx_data(ast_sip_get_pjsip_endpoint(), session->deferred_reinvite, NULL, NULL);
916         pjsip_rx_data_free_cloned(session->deferred_reinvite);
917         session->deferred_reinvite = NULL;
918 }
919
920 static pjsip_module session_reinvite_module = {
921         .name = { "Session Re-Invite Module", 24 },
922         .priority = PJSIP_MOD_PRIORITY_UA_PROXY_LAYER - 1,
923         .on_rx_request = session_reinvite_on_rx_request,
924 };
925
926 void ast_sip_session_send_request_with_cb(struct ast_sip_session *session, pjsip_tx_data *tdata,
927                 ast_sip_session_response_cb on_response)
928 {
929         pjsip_inv_session *inv_session = session->inv_session;
930
931         if (inv_session->state == PJSIP_INV_STATE_DISCONNECTED) {
932                 /* Don't try to do anything with a hung-up call */
933                 return;
934         }
935
936         ast_sip_mod_data_set(tdata->pool, tdata->mod_data, session_module.id,
937                              MOD_DATA_ON_RESPONSE, on_response);
938
939         handle_outgoing_request(session, tdata);
940         pjsip_inv_send_msg(session->inv_session, tdata);
941         return;
942 }
943
944 void ast_sip_session_send_request(struct ast_sip_session *session, pjsip_tx_data *tdata)
945 {
946         ast_sip_session_send_request_with_cb(session, tdata, NULL);
947 }
948
949 int ast_sip_session_create_invite(struct ast_sip_session *session, pjsip_tx_data **tdata)
950 {
951         pjmedia_sdp_session *offer;
952
953         if (!(offer = create_local_sdp(session->inv_session, session, NULL))) {
954                 pjsip_inv_terminate(session->inv_session, 500, PJ_FALSE);
955                 return -1;
956         }
957
958         pjsip_inv_set_local_sdp(session->inv_session, offer);
959         pjmedia_sdp_neg_set_prefer_remote_codec_order(session->inv_session->neg, PJ_FALSE);
960 #ifdef PJMEDIA_SDP_NEG_ANSWER_MULTIPLE_CODECS
961         pjmedia_sdp_neg_set_answer_multiple_codecs(session->inv_session->neg, PJ_TRUE);
962 #endif
963         if (pjsip_inv_invite(session->inv_session, tdata) != PJ_SUCCESS) {
964                 return -1;
965         }
966         return 0;
967 }
968
969 static int datastore_hash(const void *obj, int flags)
970 {
971         const struct ast_datastore *datastore = obj;
972         const char *uid = flags & OBJ_KEY ? obj : datastore->uid;
973
974         ast_assert(uid != NULL);
975
976         return ast_str_hash(uid);
977 }
978
979 static int datastore_cmp(void *obj, void *arg, int flags)
980 {
981         const struct ast_datastore *datastore1 = obj;
982         const struct ast_datastore *datastore2 = arg;
983         const char *uid2 = flags & OBJ_KEY ? arg : datastore2->uid;
984
985         ast_assert(datastore1->uid != NULL);
986         ast_assert(uid2 != NULL);
987
988         return strcmp(datastore1->uid, uid2) ? 0 : CMP_MATCH | CMP_STOP;
989 }
990
991 static void session_media_dtor(void *obj)
992 {
993         struct ast_sip_session_media *session_media = obj;
994         if (session_media->handler) {
995                 session_media->handler->stream_destroy(session_media);
996         }
997         if (session_media->srtp) {
998                 ast_sdp_srtp_destroy(session_media->srtp);
999         }
1000 }
1001
1002 static void session_destructor(void *obj)
1003 {
1004         struct ast_sip_session *session = obj;
1005         struct ast_sip_session_supplement *supplement;
1006         struct ast_sip_session_delayed_request *delay;
1007
1008         ast_debug(3, "Destroying SIP session with endpoint %s\n",
1009                         ast_sorcery_object_get_id(session->endpoint));
1010
1011         while ((supplement = AST_LIST_REMOVE_HEAD(&session->supplements, next))) {
1012                 if (supplement->session_destroy) {
1013                         supplement->session_destroy(session);
1014                 }
1015                 ast_free(supplement);
1016         }
1017
1018         ast_taskprocessor_unreference(session->serializer);
1019         ao2_cleanup(session->datastores);
1020         ao2_cleanup(session->media);
1021
1022         AST_LIST_HEAD_DESTROY(&session->supplements);
1023         while ((delay = AST_LIST_REMOVE_HEAD(&session->delayed_requests, next))) {
1024                 ast_free(delay);
1025         }
1026         ast_party_id_free(&session->id);
1027         ao2_cleanup(session->endpoint);
1028         ast_format_cap_destroy(session->req_caps);
1029
1030         if (session->dsp) {
1031                 ast_dsp_free(session->dsp);
1032         }
1033
1034         if (session->inv_session) {
1035                 pjsip_dlg_dec_session(session->inv_session->dlg, &session_module);
1036         }
1037 }
1038
1039 static int add_supplements(struct ast_sip_session *session)
1040 {
1041         struct ast_sip_session_supplement *iter;
1042         SCOPED_LOCK(lock, &session_supplements, AST_RWLIST_RDLOCK, AST_RWLIST_UNLOCK);
1043
1044         AST_RWLIST_TRAVERSE(&session_supplements, iter, next) {
1045                 struct ast_sip_session_supplement *copy = supplement_dup(iter);
1046                 if (!copy) {
1047                         return -1;
1048                 }
1049                 AST_LIST_INSERT_TAIL(&session->supplements, copy, next);
1050         }
1051         return 0;
1052 }
1053
1054 static int add_session_media(void *obj, void *arg, int flags)
1055 {
1056         struct sdp_handler_list *handler_list = obj;
1057         struct ast_sip_session * session = arg;
1058         RAII_VAR(struct ast_sip_session_media *, session_media, NULL, ao2_cleanup);
1059         session_media = ao2_alloc(sizeof(*session_media) + strlen(handler_list->stream_type), session_media_dtor);
1060         if (!session_media) {
1061                 return CMP_STOP;
1062         }
1063         /* Safe use of strcpy */
1064         strcpy(session_media->stream_type, handler_list->stream_type);
1065         ao2_link(session->media, session_media);
1066         return 0;
1067 }
1068
1069 /*! \brief Destructor for SIP channel */
1070 static void sip_channel_destroy(void *obj)
1071 {
1072         struct ast_sip_channel_pvt *channel = obj;
1073
1074         ao2_cleanup(channel->pvt);
1075         ao2_cleanup(channel->session);
1076 }
1077
1078 struct ast_sip_channel_pvt *ast_sip_channel_pvt_alloc(void *pvt, struct ast_sip_session *session)
1079 {
1080         struct ast_sip_channel_pvt *channel = ao2_alloc(sizeof(*channel), sip_channel_destroy);
1081
1082         if (!channel) {
1083                 return NULL;
1084         }
1085
1086         ao2_ref(pvt, +1);
1087         channel->pvt = pvt;
1088         ao2_ref(session, +1);
1089         channel->session = session;
1090
1091         return channel;
1092 }
1093
1094 struct ast_sip_session *ast_sip_session_alloc(struct ast_sip_endpoint *endpoint, pjsip_inv_session *inv_session)
1095 {
1096         RAII_VAR(struct ast_sip_session *, session, ao2_alloc(sizeof(*session), session_destructor), ao2_cleanup);
1097         struct ast_sip_session_supplement *iter;
1098         int dsp_features = 0;
1099         if (!session) {
1100                 return NULL;
1101         }
1102         AST_LIST_HEAD_INIT(&session->supplements);
1103         session->datastores = ao2_container_alloc(DATASTORE_BUCKETS, datastore_hash, datastore_cmp);
1104         if (!session->datastores) {
1105                 return NULL;
1106         }
1107
1108         session->media = ao2_container_alloc(MEDIA_BUCKETS, session_media_hash, session_media_cmp);
1109         if (!session->media) {
1110                 return NULL;
1111         }
1112         /* fill session->media with available types */
1113         ao2_callback(sdp_handlers, OBJ_NODATA, add_session_media, session);
1114
1115         session->serializer = ast_sip_create_serializer();
1116         if (!session->serializer) {
1117                 return NULL;
1118         }
1119         ast_sip_dialog_set_serializer(inv_session->dlg, session->serializer);
1120         ast_sip_dialog_set_endpoint(inv_session->dlg, endpoint);
1121         pjsip_dlg_inc_session(inv_session->dlg, &session_module);
1122         ao2_ref(session, +1);
1123         inv_session->mod_data[session_module.id] = session;
1124         ao2_ref(endpoint, +1);
1125         session->endpoint = endpoint;
1126         session->inv_session = inv_session;
1127         session->req_caps = ast_format_cap_alloc(AST_FORMAT_CAP_FLAG_NOLOCK);
1128
1129         if (endpoint->dtmf == AST_SIP_DTMF_INBAND) {
1130                 dsp_features |= DSP_FEATURE_DIGIT_DETECT;
1131         }
1132
1133         if (endpoint->faxdetect) {
1134                 dsp_features |= DSP_FEATURE_FAX_DETECT;
1135         }
1136
1137         if (dsp_features) {
1138                 if (!(session->dsp = ast_dsp_new())) {
1139                         ao2_ref(session, -1);
1140                         return NULL;
1141                 }
1142
1143                 ast_dsp_set_features(session->dsp, dsp_features);
1144         }
1145
1146         if (add_supplements(session)) {
1147                 ao2_ref(session, -1);
1148                 return NULL;
1149         }
1150         AST_LIST_TRAVERSE(&session->supplements, iter, next) {
1151                 if (iter->session_begin) {
1152                         iter->session_begin(session);
1153                 }
1154         }
1155         session->direct_media_cap = ast_format_cap_alloc(AST_FORMAT_CAP_FLAG_NOLOCK);
1156         AST_LIST_HEAD_INIT_NOLOCK(&session->delayed_requests);
1157         ast_party_id_init(&session->id);
1158         ao2_ref(session, +1);
1159         return session;
1160 }
1161
1162 static int session_outbound_auth(pjsip_dialog *dlg, pjsip_tx_data *tdata, void *user_data)
1163 {
1164         pjsip_inv_session *inv = pjsip_dlg_get_inv_session(dlg);
1165         struct ast_sip_session *session = inv->mod_data[session_module.id];
1166
1167         if (inv->state < PJSIP_INV_STATE_CONFIRMED && tdata->msg->line.req.method.id == PJSIP_INVITE_METHOD) {
1168                 pjsip_inv_uac_restart(inv, PJ_TRUE);
1169         }
1170         ast_sip_session_send_request(session, tdata);
1171         return 0;
1172 }
1173
1174 struct ast_sip_session *ast_sip_session_create_outgoing(struct ast_sip_endpoint *endpoint, const char *location, const char *request_user, struct ast_format_cap *req_caps)
1175 {
1176         const char *uri = NULL;
1177         RAII_VAR(struct ast_sip_contact *, contact, NULL, ao2_cleanup);
1178         pjsip_timer_setting timer;
1179         pjsip_dialog *dlg;
1180         struct pjsip_inv_session *inv_session;
1181         RAII_VAR(struct ast_sip_session *, session, NULL, ao2_cleanup);
1182
1183         /* If no location has been provided use the AOR list from the endpoint itself */
1184         location = S_OR(location, endpoint->aors);
1185
1186         contact = ast_sip_location_retrieve_contact_from_aor_list(location);
1187         if (!contact || ast_strlen_zero(contact->uri)) {
1188                 uri = location;
1189         } else {
1190                 uri = contact->uri;
1191         }
1192
1193         /* If we still have no URI to dial fail to create the session */
1194         if (ast_strlen_zero(uri)) {
1195                 return NULL;
1196         }
1197
1198         if (!(dlg = ast_sip_create_dialog_uac(endpoint, uri, request_user))) {
1199                 return NULL;
1200         }
1201
1202         if (ast_sip_dialog_setup_outbound_authentication(dlg, endpoint, session_outbound_auth, NULL)) {
1203                 pjsip_dlg_terminate(dlg);
1204                 return NULL;
1205         }
1206
1207         if (pjsip_inv_create_uac(dlg, NULL, endpoint->extensions.flags, &inv_session) != PJ_SUCCESS) {
1208                 pjsip_dlg_terminate(dlg);
1209                 return NULL;
1210         }
1211 #ifdef PJMEDIA_SDP_NEG_ALLOW_MEDIA_CHANGE
1212         inv_session->sdp_neg_flags = PJMEDIA_SDP_NEG_ALLOW_MEDIA_CHANGE;
1213 #endif
1214
1215         pjsip_timer_setting_default(&timer);
1216         timer.min_se = endpoint->extensions.timer.min_se;
1217         timer.sess_expires = endpoint->extensions.timer.sess_expires;
1218         pjsip_timer_init_session(inv_session, &timer);
1219
1220         if (!(session = ast_sip_session_alloc(endpoint, inv_session))) {
1221                 pjsip_inv_terminate(inv_session, 500, PJ_FALSE);
1222                 return NULL;
1223         }
1224
1225         ast_format_cap_copy(session->req_caps, req_caps);
1226         if ((pjsip_dlg_add_usage(dlg, &session_module, NULL) != PJ_SUCCESS)) {
1227                 pjsip_inv_terminate(inv_session, 500, PJ_FALSE);
1228                 /* Since we are not notifying ourselves that the INVITE session is being terminated
1229                  * we need to manually drop its reference to session
1230                  */
1231                 ao2_ref(session, -1);
1232                 return NULL;
1233         }
1234
1235         ao2_ref(session, +1);
1236         return session;
1237 }
1238
1239 static int session_termination_task(void *data)
1240 {
1241         RAII_VAR(struct ast_sip_session *, session, data, ao2_cleanup);
1242         pjsip_tx_data *packet = NULL;
1243
1244         if (!session->inv_session) {
1245                 return 0;
1246         }
1247
1248         if (pjsip_inv_end_session(session->inv_session, 603, NULL, &packet) == PJ_SUCCESS) {
1249                 ast_sip_session_send_request(session, packet);
1250         }
1251
1252         return 0;
1253 }
1254
1255 static void session_termination_cb(pj_timer_heap_t *timer_heap, struct pj_timer_entry *entry)
1256 {
1257         struct ast_sip_session *session = entry->user_data;
1258
1259         if (ast_sip_push_task(session->serializer, session_termination_task, session)) {
1260                 ao2_cleanup(session);
1261         }
1262 }
1263
1264 void ast_sip_session_defer_termination(struct ast_sip_session *session)
1265 {
1266         pj_time_val delay = { .sec = 60, };
1267
1268         session->defer_terminate = 1;
1269
1270         session->scheduled_termination.id = 0;
1271         ao2_ref(session, +1);
1272         session->scheduled_termination.user_data = session;
1273         session->scheduled_termination.cb = session_termination_cb;
1274
1275         if (pjsip_endpt_schedule_timer(ast_sip_get_pjsip_endpoint(), &session->scheduled_termination, &delay) != PJ_SUCCESS) {
1276                 ao2_ref(session, -1);
1277         }
1278 }
1279
1280 struct ast_sip_session *ast_sip_dialog_get_session(pjsip_dialog *dlg)
1281 {
1282         pjsip_inv_session *inv_session = pjsip_dlg_get_inv_session(dlg);
1283         struct ast_sip_session *session;
1284
1285         if (!inv_session ||
1286                 !(session = inv_session->mod_data[session_module.id])) {
1287                 return NULL;
1288         }
1289
1290         ao2_ref(session, +1);
1291
1292         return session;
1293 }
1294
1295 enum sip_get_destination_result {
1296         /*! The extension was successfully found */
1297         SIP_GET_DEST_EXTEN_FOUND,
1298         /*! The extension specified in the RURI was not found */
1299         SIP_GET_DEST_EXTEN_NOT_FOUND,
1300         /*! The extension specified in the RURI was a partial match */
1301         SIP_GET_DEST_EXTEN_PARTIAL,
1302         /*! The RURI is of an unsupported scheme */
1303         SIP_GET_DEST_UNSUPPORTED_URI,
1304 };
1305
1306 /*!
1307  * \brief Determine where in the dialplan a call should go
1308  *
1309  * This uses the username in the request URI to try to match
1310  * an extension in the endpoint's configured context in order
1311  * to route the call.
1312  *
1313  * \param session The inbound SIP session
1314  * \param rdata The SIP INVITE
1315  */
1316 static enum sip_get_destination_result get_destination(struct ast_sip_session *session, pjsip_rx_data *rdata)
1317 {
1318         pjsip_uri *ruri = rdata->msg_info.msg->line.req.uri;
1319         pjsip_sip_uri *sip_ruri;
1320         if (!PJSIP_URI_SCHEME_IS_SIP(ruri) && !PJSIP_URI_SCHEME_IS_SIPS(ruri)) {
1321                 return SIP_GET_DEST_UNSUPPORTED_URI;
1322         }
1323         sip_ruri = pjsip_uri_get_uri(ruri);
1324         ast_copy_pj_str(session->exten, &sip_ruri->user, sizeof(session->exten));
1325         if (ast_exists_extension(NULL, session->endpoint->context, session->exten, 1, NULL)) {
1326                 return SIP_GET_DEST_EXTEN_FOUND;
1327         }
1328         /* XXX In reality, we'll likely have further options so that partial matches
1329          * can be indicated here, but for getting something up and running, we're going
1330          * to return a "not exists" error here.
1331          */
1332         return SIP_GET_DEST_EXTEN_NOT_FOUND;
1333 }
1334
1335 static pjsip_inv_session *pre_session_setup(pjsip_rx_data *rdata, const struct ast_sip_endpoint *endpoint)
1336 {
1337         pjsip_tx_data *tdata;
1338         pjsip_dialog *dlg;
1339         pjsip_inv_session *inv_session;
1340         unsigned int options = endpoint->extensions.flags;
1341
1342         if (pjsip_inv_verify_request(rdata, &options, NULL, NULL, ast_sip_get_pjsip_endpoint(), &tdata) != PJ_SUCCESS) {
1343                 if (tdata) {
1344                         pjsip_endpt_send_response2(ast_sip_get_pjsip_endpoint(), rdata, tdata, NULL, NULL);
1345                 } else {
1346                         pjsip_endpt_respond_stateless(ast_sip_get_pjsip_endpoint(), rdata, 500, NULL, NULL, NULL);
1347                 }
1348                 return NULL;
1349         }
1350         dlg = ast_sip_create_dialog_uas(endpoint, rdata);
1351         if (!dlg) {
1352                 pjsip_endpt_respond_stateless(ast_sip_get_pjsip_endpoint(), rdata, 500, NULL, NULL, NULL);
1353                 return NULL;
1354         }
1355         if (pjsip_inv_create_uas(dlg, rdata, NULL, 0, &inv_session) != PJ_SUCCESS) {
1356                 pjsip_endpt_respond_stateless(ast_sip_get_pjsip_endpoint(), rdata, 500, NULL, NULL, NULL);
1357                 pjsip_dlg_terminate(dlg);
1358                 return NULL;
1359         }
1360 #ifdef PJMEDIA_SDP_NEG_ALLOW_MEDIA_CHANGE
1361         inv_session->sdp_neg_flags = PJMEDIA_SDP_NEG_ALLOW_MEDIA_CHANGE;
1362 #endif
1363         if (pjsip_dlg_add_usage(dlg, &session_module, NULL) != PJ_SUCCESS) {
1364                 if (pjsip_inv_initial_answer(inv_session, rdata, 500, NULL, NULL, &tdata) != PJ_SUCCESS) {
1365                         pjsip_inv_terminate(inv_session, 500, PJ_FALSE);
1366                 }
1367                 pjsip_inv_send_msg(inv_session, tdata);
1368                 return NULL;
1369         }
1370         return inv_session;
1371 }
1372
1373 struct new_invite {
1374         /*! \brief Session created for the new INVITE */
1375         struct ast_sip_session *session;
1376
1377         /*! \brief INVITE request itself */
1378         pjsip_rx_data *rdata;
1379 };
1380
1381 static void new_invite_destroy(void *obj)
1382 {
1383         struct new_invite *invite = obj;
1384
1385         ao2_cleanup(invite->session);
1386
1387         if (invite->rdata) {
1388                 pjsip_rx_data_free_cloned(invite->rdata);
1389         }
1390 }
1391
1392 static struct new_invite *new_invite_alloc(struct ast_sip_session *session, pjsip_rx_data *rdata)
1393 {
1394         struct new_invite *invite = ao2_alloc(sizeof(*invite), new_invite_destroy);
1395
1396         if (!invite) {
1397                 return NULL;
1398         }
1399
1400         ao2_ref(session, +1);
1401         invite->session = session;
1402
1403         if (pjsip_rx_data_clone(rdata, 0, &invite->rdata) != PJ_SUCCESS) {
1404                 ao2_ref(invite, -1);
1405                 return NULL;
1406         }
1407
1408         return invite;
1409 }
1410
1411 static int new_invite(void *data)
1412 {
1413         RAII_VAR(struct new_invite *, invite, data, ao2_cleanup);
1414         pjsip_tx_data *tdata = NULL;
1415         pjsip_timer_setting timer;
1416         pjsip_rdata_sdp_info *sdp_info;
1417         pjmedia_sdp_session *local = NULL;
1418
1419         /* From this point on, any calls to pjsip_inv_terminate have the last argument as PJ_TRUE
1420          * so that we will be notified so we can destroy the session properly
1421          */
1422
1423         switch (get_destination(invite->session, invite->rdata)) {
1424         case SIP_GET_DEST_EXTEN_FOUND:
1425                 /* Things worked. Keep going */
1426                 break;
1427         case SIP_GET_DEST_UNSUPPORTED_URI:
1428                 if (pjsip_inv_initial_answer(invite->session->inv_session, invite->rdata, 416, NULL, NULL, &tdata) == PJ_SUCCESS) {
1429                         ast_sip_session_send_response(invite->session, tdata);
1430                 } else  {
1431                         pjsip_inv_terminate(invite->session->inv_session, 416, PJ_TRUE);
1432                 }
1433                 return 0;
1434         case SIP_GET_DEST_EXTEN_NOT_FOUND:
1435         case SIP_GET_DEST_EXTEN_PARTIAL:
1436         default:
1437                 ast_log(LOG_NOTICE, "Call from '%s' (%s:%s:%d) to extension '%s' rejected because extension not found in context '%s'.\n",
1438                         ast_sorcery_object_get_id(invite->session->endpoint), invite->rdata->tp_info.transport->type_name, invite->rdata->pkt_info.src_name,
1439                         invite->rdata->pkt_info.src_port, invite->session->exten, invite->session->endpoint->context);
1440
1441                 if (pjsip_inv_initial_answer(invite->session->inv_session, invite->rdata, 404, NULL, NULL, &tdata) == PJ_SUCCESS) {
1442                         ast_sip_session_send_response(invite->session, tdata);
1443                 } else  {
1444                         pjsip_inv_terminate(invite->session->inv_session, 404, PJ_TRUE);
1445                 }
1446                 return 0;
1447         };
1448
1449         if ((sdp_info = pjsip_rdata_get_sdp_info(invite->rdata)) && (sdp_info->sdp_err == PJ_SUCCESS) && sdp_info->sdp) {
1450                 if (handle_incoming_sdp(invite->session, sdp_info->sdp)) {
1451                         if (pjsip_inv_initial_answer(invite->session->inv_session, invite->rdata, 488, NULL, NULL, &tdata) == PJ_SUCCESS) {
1452                                 ast_sip_session_send_response(invite->session, tdata);
1453                         } else  {
1454                                 pjsip_inv_terminate(invite->session->inv_session, 488, PJ_TRUE);
1455                         }
1456                         return 0;
1457                 }
1458                 /* We are creating a local SDP which is an answer to their offer */
1459                 local = create_local_sdp(invite->session->inv_session, invite->session, sdp_info->sdp);
1460         } else {
1461                 /* We are creating a local SDP which is an offer */
1462                 local = create_local_sdp(invite->session->inv_session, invite->session, NULL);
1463         }
1464
1465         /* If we were unable to create a local SDP terminate the session early, it won't go anywhere */
1466         if (!local) {
1467                 if (pjsip_inv_initial_answer(invite->session->inv_session, invite->rdata, 500, NULL, NULL, &tdata) == PJ_SUCCESS) {
1468                         ast_sip_session_send_response(invite->session, tdata);
1469                 } else  {
1470                         pjsip_inv_terminate(invite->session->inv_session, 500, PJ_TRUE);
1471                 }
1472                 return 0;
1473         } else {
1474                 pjsip_inv_set_local_sdp(invite->session->inv_session, local);
1475                 pjmedia_sdp_neg_set_prefer_remote_codec_order(invite->session->inv_session->neg, PJ_FALSE);
1476 #ifdef PJMEDIA_SDP_NEG_ANSWER_MULTIPLE_CODECS
1477                 pjmedia_sdp_neg_set_answer_multiple_codecs(invite->session->inv_session->neg, PJ_TRUE);
1478 #endif
1479         }
1480
1481         pjsip_timer_setting_default(&timer);
1482         timer.min_se = invite->session->endpoint->extensions.timer.min_se;
1483         timer.sess_expires = invite->session->endpoint->extensions.timer.sess_expires;
1484         pjsip_timer_init_session(invite->session->inv_session, &timer);
1485
1486         /* At this point, we've verified what we can, so let's go ahead and send a 100 Trying out */
1487         if (pjsip_inv_initial_answer(invite->session->inv_session, invite->rdata, 100, NULL, NULL, &tdata) != PJ_SUCCESS) {
1488                 pjsip_inv_terminate(invite->session->inv_session, 500, PJ_TRUE);
1489                 return 0;
1490         }
1491         ast_sip_session_send_response(invite->session, tdata);
1492
1493         handle_incoming_request(invite->session, invite->rdata);
1494
1495         return 0;
1496 }
1497
1498 static void handle_new_invite_request(pjsip_rx_data *rdata)
1499 {
1500         RAII_VAR(struct ast_sip_endpoint *, endpoint,
1501                         ast_pjsip_rdata_get_endpoint(rdata), ao2_cleanup);
1502         pjsip_tx_data *tdata = NULL;
1503         pjsip_inv_session *inv_session = NULL;
1504         RAII_VAR(struct ast_sip_session *, session, NULL, ao2_cleanup);
1505         struct new_invite *invite;
1506
1507         ast_assert(endpoint != NULL);
1508
1509         inv_session = pre_session_setup(rdata, endpoint);
1510         if (!inv_session) {
1511                 /* pre_session_setup() returns a response on failure */
1512                 return;
1513         }
1514
1515         session = ast_sip_session_alloc(endpoint, inv_session);
1516         if (!session) {
1517                 if (pjsip_inv_initial_answer(inv_session, rdata, 500, NULL, NULL, &tdata) == PJ_SUCCESS) {
1518                         pjsip_inv_terminate(inv_session, 500, PJ_FALSE);
1519                 } else {
1520                         pjsip_inv_send_msg(inv_session, tdata);
1521                 }
1522                 return;
1523         }
1524
1525         invite = new_invite_alloc(session, rdata);
1526         if (!invite || ast_sip_push_task(session->serializer, new_invite, invite)) {
1527                 if (pjsip_inv_initial_answer(inv_session, rdata, 500, NULL, NULL, &tdata) == PJ_SUCCESS) {
1528                         pjsip_inv_terminate(inv_session, 500, PJ_FALSE);
1529                 } else {
1530                         pjsip_inv_send_msg(inv_session, tdata);
1531                 }
1532                 ao2_ref(session, -1);
1533                 ao2_cleanup(invite);
1534                 return;
1535         }
1536 }
1537
1538 static pj_bool_t does_method_match(const pj_str_t *message_method, const char *supplement_method)
1539 {
1540         pj_str_t method;
1541
1542         if (ast_strlen_zero(supplement_method)) {
1543                 return PJ_TRUE;
1544         }
1545
1546         pj_cstr(&method, supplement_method);
1547
1548         return pj_stristr(&method, message_method) ? PJ_TRUE : PJ_FALSE;
1549 }
1550
1551 static pj_bool_t has_supplement(const struct ast_sip_session *session, const pjsip_rx_data *rdata)
1552 {
1553         struct ast_sip_session_supplement *supplement;
1554         struct pjsip_method *method = &rdata->msg_info.msg->line.req.method;
1555
1556         if (!session) {
1557                 return PJ_FALSE;
1558         }
1559
1560         AST_LIST_TRAVERSE(&session->supplements, supplement, next) {
1561                 if (does_method_match(&method->name, supplement->method)) {
1562                         return PJ_TRUE;
1563                 }
1564         }
1565         return PJ_FALSE;
1566 }
1567 /*!
1568  * \brief Called when a new SIP request comes into PJSIP
1569  *
1570  * This function is called under two circumstances
1571  * 1) An out-of-dialog request is received by PJSIP
1572  * 2) An in-dialog request that the inv_session layer does not
1573  *    handle is received (such as an in-dialog INFO)
1574  *
1575  * In all cases, there is very little we actually do in this function
1576  * 1) For requests we don't handle, we return PJ_FALSE
1577  * 2) For new INVITEs, throw the work into the SIP threadpool to be done
1578  *    there to free up the thread(s) handling incoming requests
1579  * 3) For in-dialog requests we handle, we defer handling them until the
1580  *    on_inv_state_change() callback instead (where we will end up putting
1581  *    them into the threadpool).
1582  */
1583 static pj_bool_t session_on_rx_request(pjsip_rx_data *rdata)
1584 {
1585         pj_status_t handled = PJ_FALSE;
1586         pjsip_dialog *dlg = pjsip_rdata_get_dlg(rdata);
1587         pjsip_inv_session *inv_session;
1588
1589         switch (rdata->msg_info.msg->line.req.method.id) {
1590         case PJSIP_INVITE_METHOD:
1591                 if (dlg) {
1592                         ast_log(LOG_WARNING, "on_rx_request called for INVITE in mid-dialog?\n");
1593                         break;
1594                 }
1595                 handled = PJ_TRUE;
1596                 handle_new_invite_request(rdata);
1597                 break;
1598         default:
1599                 /* Handle other in-dialog methods if their supplements have been registered */
1600                 handled = dlg && (inv_session = pjsip_dlg_get_inv_session(dlg)) &&
1601                         has_supplement(inv_session->mod_data[session_module.id], rdata);
1602                 break;
1603         }
1604
1605         return handled;
1606 }
1607
1608 struct reschedule_reinvite_data {
1609         struct ast_sip_session *session;
1610         struct ast_sip_session_delayed_request *delay;
1611 };
1612
1613 static struct reschedule_reinvite_data *reschedule_reinvite_data_alloc(
1614                 struct ast_sip_session *session, struct ast_sip_session_delayed_request *delay)
1615 {
1616         struct reschedule_reinvite_data *rrd = ast_malloc(sizeof(*rrd));
1617         if (!rrd) {
1618                 return NULL;
1619         }
1620         ao2_ref(session, +1);
1621         rrd->session = session;
1622         rrd->delay = delay;
1623         return rrd;
1624 }
1625
1626 static void reschedule_reinvite_data_destroy(struct reschedule_reinvite_data *rrd)
1627 {
1628         ao2_cleanup(rrd->session);
1629         ast_free(rrd->delay);
1630         ast_free(rrd);
1631 }
1632
1633 static int really_resend_reinvite(void *data)
1634 {
1635         RAII_VAR(struct reschedule_reinvite_data *, rrd, data, reschedule_reinvite_data_destroy);
1636
1637         return send_delayed_request(rrd->session, rrd->delay);
1638 }
1639
1640 static void resend_reinvite(pj_timer_heap_t *timer, pj_timer_entry *entry)
1641 {
1642         struct reschedule_reinvite_data *rrd = entry->user_data;
1643
1644         ast_sip_push_task(rrd->session->serializer, really_resend_reinvite, entry->user_data);
1645 }
1646
1647 static void reschedule_reinvite(struct ast_sip_session *session, ast_sip_session_response_cb on_response, pjsip_tx_data *tdata)
1648 {
1649         struct ast_sip_session_delayed_request *delay = delayed_request_alloc("INVITE",
1650                         NULL, NULL, on_response, tdata);
1651         pjsip_inv_session *inv = session->inv_session;
1652         struct reschedule_reinvite_data *rrd = reschedule_reinvite_data_alloc(session, delay);
1653         pj_time_val tv;
1654
1655         if (!rrd || !delay) {
1656                 return;
1657         }
1658
1659         tv.sec = 0;
1660         if (inv->role == PJSIP_ROLE_UAC) {
1661                 tv.msec = 2100 + ast_random() % 2000;
1662         } else {
1663                 tv.msec = ast_random() % 2000;
1664         }
1665
1666         pj_timer_entry_init(&session->rescheduled_reinvite, 0, rrd, resend_reinvite);
1667
1668         pjsip_endpt_schedule_timer(ast_sip_get_pjsip_endpoint(), &session->rescheduled_reinvite, &tv);
1669 }
1670
1671 static void __print_debug_details(const char *function, pjsip_inv_session *inv, pjsip_transaction *tsx, pjsip_event *e)
1672 {
1673         struct ast_sip_session *session;
1674         ast_debug(5, "Function %s called on event %s\n", function, pjsip_event_str(e->type));
1675         if (!inv) {
1676                 ast_debug(5, "Transaction %p does not belong to an inv_session?\n", tsx);
1677                 ast_debug(5, "The transaction state is %s\n", pjsip_tsx_state_str(tsx->state));
1678                 return;
1679         }
1680         session = inv->mod_data[session_module.id];
1681         if (!session) {
1682                 ast_debug(5, "inv_session %p has no ast session\n", inv);
1683         } else {
1684                 ast_debug(5, "The state change pertains to the session with %s\n",
1685                                 ast_sorcery_object_get_id(session->endpoint));
1686         }
1687         if (inv->invite_tsx) {
1688                 ast_debug(5, "The inv session still has an invite_tsx (%p)\n", inv->invite_tsx);
1689         } else {
1690                 ast_debug(5, "The inv session does NOT have an invite_tsx\n");
1691         }
1692         if (tsx) {
1693                 ast_debug(5, "The transaction involved in this state change is %p\n", tsx);
1694                 ast_debug(5, "The current transaction state is %s\n", pjsip_tsx_state_str(tsx->state));
1695                 ast_debug(5, "The transaction state change event is %s\n", pjsip_event_str(e->body.tsx_state.type));
1696         } else {
1697                 ast_debug(5, "There is no transaction involved in this state change\n");
1698         }
1699         ast_debug(5, "The current inv state is %s\n", pjsip_inv_state_name(inv->state));
1700 }
1701
1702 #define print_debug_details(inv, tsx, e) __print_debug_details(__PRETTY_FUNCTION__, (inv), (tsx), (e))
1703
1704 static void handle_incoming_request(struct ast_sip_session *session, pjsip_rx_data *rdata)
1705 {
1706         struct ast_sip_session_supplement *supplement;
1707         struct pjsip_request_line req = rdata->msg_info.msg->line.req;
1708
1709         ast_debug(3, "Method is %.*s\n", (int) pj_strlen(&req.method.name), pj_strbuf(&req.method.name));
1710         AST_LIST_TRAVERSE(&session->supplements, supplement, next) {
1711                 if (supplement->incoming_request && does_method_match(&req.method.name, supplement->method)) {
1712                         if (supplement->incoming_request(session, rdata)) {
1713                                 break;
1714                         }
1715                 }
1716         }
1717 }
1718
1719 static void handle_incoming_response(struct ast_sip_session *session, pjsip_rx_data *rdata)
1720 {
1721         struct ast_sip_session_supplement *supplement;
1722         struct pjsip_status_line status = rdata->msg_info.msg->line.status;
1723
1724         ast_debug(3, "Response is %d %.*s\n", status.code, (int) pj_strlen(&status.reason),
1725                         pj_strbuf(&status.reason));
1726
1727         AST_LIST_TRAVERSE(&session->supplements, supplement, next) {
1728                 if (supplement->incoming_response && does_method_match(&rdata->msg_info.cseq->method.name, supplement->method)) {
1729                         supplement->incoming_response(session, rdata);
1730                 }
1731         }
1732 }
1733
1734 static int handle_incoming(struct ast_sip_session *session, pjsip_rx_data *rdata)
1735 {
1736         ast_debug(3, "Received %s\n", rdata->msg_info.msg->type == PJSIP_REQUEST_MSG ?
1737                         "request" : "response");
1738
1739         if (rdata->msg_info.msg->type == PJSIP_REQUEST_MSG) {
1740                 handle_incoming_request(session, rdata);
1741         } else {
1742                 handle_incoming_response(session, rdata);
1743         }
1744
1745         return 0;
1746 }
1747
1748 static void handle_outgoing_request(struct ast_sip_session *session, pjsip_tx_data *tdata)
1749 {
1750         struct ast_sip_session_supplement *supplement;
1751         struct pjsip_request_line req = tdata->msg->line.req;
1752
1753         ast_debug(3, "Method is %.*s\n", (int) pj_strlen(&req.method.name), pj_strbuf(&req.method.name));
1754         AST_LIST_TRAVERSE(&session->supplements, supplement, next) {
1755                 if (supplement->outgoing_request && does_method_match(&req.method.name, supplement->method)) {
1756                         supplement->outgoing_request(session, tdata);
1757                 }
1758         }
1759 }
1760
1761 static void handle_outgoing_response(struct ast_sip_session *session, pjsip_tx_data *tdata)
1762 {
1763         struct ast_sip_session_supplement *supplement;
1764         struct pjsip_status_line status = tdata->msg->line.status;
1765         pjsip_cseq_hdr *cseq = pjsip_msg_find_hdr(tdata->msg, PJSIP_H_CSEQ, NULL);
1766         ast_debug(3, "Method is %.*s, Response is %d %.*s\n", (int) pj_strlen(&cseq->method.name),
1767                 pj_strbuf(&cseq->method.name), status.code, (int) pj_strlen(&status.reason),
1768                 pj_strbuf(&status.reason));
1769
1770         AST_LIST_TRAVERSE(&session->supplements, supplement, next) {
1771                 if (supplement->outgoing_response && does_method_match(&cseq->method.name, supplement->method)) {
1772                         supplement->outgoing_response(session, tdata);
1773                 }
1774         }
1775 }
1776
1777 static void handle_outgoing(struct ast_sip_session *session, pjsip_tx_data *tdata)
1778 {
1779         ast_debug(3, "Sending %s\n", tdata->msg->type == PJSIP_REQUEST_MSG ?
1780                         "request" : "response");
1781         if (tdata->msg->type == PJSIP_REQUEST_MSG) {
1782                 handle_outgoing_request(session, tdata);
1783         } else {
1784                 handle_outgoing_response(session, tdata);
1785         }
1786 }
1787
1788 static int session_end(struct ast_sip_session *session)
1789 {
1790         struct ast_sip_session_supplement *iter;
1791
1792         /* Stop the scheduled termination */
1793         if (pj_timer_heap_cancel(pjsip_endpt_get_timer_heap(ast_sip_get_pjsip_endpoint()), &session->scheduled_termination)) {
1794                 ao2_ref(session, -1);
1795         }
1796
1797         /* Session is dead. Let's get rid of the reference to the session */
1798         AST_LIST_TRAVERSE(&session->supplements, iter, next) {
1799                 if (iter->session_end) {
1800                         iter->session_end(session);
1801                 }
1802         }
1803
1804         session->inv_session->mod_data[session_module.id] = NULL;
1805         ast_sip_dialog_set_serializer(session->inv_session->dlg, NULL);
1806         ast_sip_dialog_set_endpoint(session->inv_session->dlg, NULL);
1807         ao2_cleanup(session);
1808         return 0;
1809 }
1810
1811 static void session_inv_on_state_changed(pjsip_inv_session *inv, pjsip_event *e)
1812 {
1813         struct ast_sip_session *session = inv->mod_data[session_module.id];
1814
1815         print_debug_details(inv, NULL, e);
1816
1817         if (!session) {
1818                 return;
1819         }
1820
1821         switch(e->type) {
1822         case PJSIP_EVENT_TX_MSG:
1823                 handle_outgoing(session, e->body.tx_msg.tdata);
1824                 break;
1825         case PJSIP_EVENT_RX_MSG:
1826                 handle_incoming(session, e->body.rx_msg.rdata);
1827                 break;
1828         case PJSIP_EVENT_TSX_STATE:
1829                 ast_debug(3, "Source of transaction state change is %s\n", pjsip_event_str(e->body.tsx_state.type));
1830                 /* Transaction state changes are prompted by some other underlying event. */
1831                 switch(e->body.tsx_state.type) {
1832                 case PJSIP_EVENT_TX_MSG:
1833                         handle_outgoing(session, e->body.tsx_state.src.tdata);
1834                         break;
1835                 case PJSIP_EVENT_RX_MSG:
1836                         handle_incoming(session, e->body.tsx_state.src.rdata);
1837                         break;
1838                 case PJSIP_EVENT_TRANSPORT_ERROR:
1839                 case PJSIP_EVENT_TIMER:
1840                 case PJSIP_EVENT_USER:
1841                 case PJSIP_EVENT_UNKNOWN:
1842                 case PJSIP_EVENT_TSX_STATE:
1843                         /* Inception? */
1844                         break;
1845                 }
1846                 break;
1847         case PJSIP_EVENT_TRANSPORT_ERROR:
1848         case PJSIP_EVENT_TIMER:
1849         case PJSIP_EVENT_UNKNOWN:
1850         case PJSIP_EVENT_USER:
1851         default:
1852                 break;
1853         }
1854
1855         if (inv->state == PJSIP_INV_STATE_DISCONNECTED) {
1856                 session_end(session);
1857         }
1858 }
1859
1860 static void session_inv_on_new_session(pjsip_inv_session *inv, pjsip_event *e)
1861 {
1862         /* XXX STUB */
1863 }
1864
1865 static void session_inv_on_tsx_state_changed(pjsip_inv_session *inv, pjsip_transaction *tsx, pjsip_event *e)
1866 {
1867         ast_sip_session_response_cb cb;
1868         struct ast_sip_session *session = inv->mod_data[session_module.id];
1869         print_debug_details(inv, tsx, e);
1870         if (!session) {
1871                 /* Transaction likely timed out after the call was hung up. Just
1872                  * ignore such transaction changes
1873                  */
1874                 return;
1875         }
1876         switch (e->body.tsx_state.type) {
1877         case PJSIP_EVENT_TX_MSG:
1878                 /* When we create an outgoing request, we do not have access to the transaction that
1879                  * is created. Instead, We have to place transaction-specific data in the tdata. Here,
1880                  * we transfer the data into the transaction. This way, when we receive a response, we
1881                  * can dig this data out again
1882                  */
1883                 tsx->mod_data[session_module.id] = e->body.tsx_state.src.tdata->mod_data[session_module.id];
1884                 break;
1885         case PJSIP_EVENT_RX_MSG:
1886                 if (tsx->method.id == PJSIP_INVITE_METHOD) {
1887                         if (tsx->role == PJSIP_ROLE_UAC) {
1888                                 if (tsx->state == PJSIP_TSX_STATE_COMPLETED) {
1889                                         /* This means we got a non 2XX final response to our outgoing INVITE */
1890                                         if (tsx->status_code == PJSIP_SC_REQUEST_PENDING) {
1891                                                 reschedule_reinvite(session, tsx->mod_data[session_module.id], tsx->last_tx);
1892                                                 return;
1893                                         } else if (inv->state == PJSIP_INV_STATE_CONFIRMED &&
1894                                                    tsx->status_code != 488) {
1895                                                 /* Other reinvite failures (except 488) result in destroying the session. */
1896                                                 pjsip_tx_data *tdata;
1897                                                 if (pjsip_inv_end_session(inv, 500, NULL, &tdata) == PJ_SUCCESS) {
1898                                                         ast_sip_session_send_request(session, tdata);
1899                                                 }
1900                                         }
1901                                 } else if (tsx->state == PJSIP_TSX_STATE_TERMINATED) {
1902                                         if (inv->cancelling && tsx->status_code == PJSIP_SC_OK) {
1903                                                 /* This is a race condition detailed in RFC 5407 section 3.1.2.
1904                                                  * We sent a CANCEL at the same time that the UAS sent us a 200 OK for
1905                                                  * the original INVITE. As a result, we have now received a 200 OK for
1906                                                  * a cancelled call. Our role is to immediately send a BYE to end the
1907                                                  * dialog.
1908                                                  */
1909                                                 pjsip_tx_data *tdata;
1910
1911                                                 if (pjsip_inv_end_session(inv, 500, NULL, &tdata) == PJ_SUCCESS) {
1912                                                         ast_sip_session_send_request(session, tdata);
1913                                                 }
1914                                         }
1915                                 }
1916                         }
1917                 } else {
1918                         if (tsx->role == PJSIP_ROLE_UAS && tsx->state == PJSIP_TSX_STATE_TRYING) {
1919                                 handle_incoming_request(session, e->body.tsx_state.src.rdata);
1920                         }
1921                 }
1922                 if ((cb = ast_sip_mod_data_get(tsx->mod_data, session_module.id,
1923                                                MOD_DATA_ON_RESPONSE))) {
1924                         cb(session, e->body.tsx_state.src.rdata);
1925                 }
1926         case PJSIP_EVENT_TRANSPORT_ERROR:
1927         case PJSIP_EVENT_TIMER:
1928         case PJSIP_EVENT_USER:
1929         case PJSIP_EVENT_UNKNOWN:
1930         case PJSIP_EVENT_TSX_STATE:
1931                 /* Inception? */
1932                 break;
1933         }
1934
1935         /* Terminated INVITE transactions always should result in queuing delayed requests,
1936          * no matter what event caused the transaction to terminate
1937          */
1938         if (tsx->method.id == PJSIP_INVITE_METHOD && tsx->state == PJSIP_TSX_STATE_TERMINATED) {
1939                 queue_delayed_request(session);
1940         }
1941 }
1942
1943 static int add_sdp_streams(void *obj, void *arg, void *data, int flags)
1944 {
1945         struct ast_sip_session_media *session_media = obj;
1946         pjmedia_sdp_session *answer = arg;
1947         struct ast_sip_session *session = data;
1948         struct ast_sip_session_sdp_handler *handler = session_media->handler;
1949         RAII_VAR(struct sdp_handler_list *, handler_list, NULL, ao2_cleanup);
1950
1951         if (handler) {
1952                 /* if an already assigned handler does not handle the session_media or reports a catastrophic error, fail */
1953                 if (handler->create_outgoing_sdp_stream(session, session_media, answer) <= 0) {
1954                         return 0;
1955                 }
1956                 return CMP_MATCH;
1957         }
1958
1959         handler_list = ao2_find(sdp_handlers, session_media->stream_type, OBJ_KEY);
1960         if (!handler_list) {
1961                 return CMP_MATCH;
1962         }
1963
1964         /* no handler for this stream type and we have a list to search */
1965         AST_LIST_TRAVERSE(&handler_list->list, handler, next) {
1966                 int res = handler->create_outgoing_sdp_stream(session, session_media, answer);
1967                 if (res < 0) {
1968                         /* catastrophic error */
1969                         return 0;
1970                 }
1971                 if (res > 0) {
1972                         /* handled */
1973                         return CMP_MATCH;
1974                 }
1975         }
1976
1977         /* streams that weren't handled won't be included in generated outbound SDP */
1978         return CMP_MATCH;
1979 }
1980
1981 static struct pjmedia_sdp_session *create_local_sdp(pjsip_inv_session *inv, struct ast_sip_session *session, const pjmedia_sdp_session *offer)
1982 {
1983         RAII_VAR(struct ao2_iterator *, successful, NULL, ao2_iterator_cleanup);
1984         static const pj_str_t STR_IN = { "IN", 2 };
1985         static const pj_str_t STR_IP4 = { "IP4", 3 };
1986         static const pj_str_t STR_IP6 = { "IP6", 3 };
1987         pjmedia_sdp_session *local;
1988
1989         if (!(local = PJ_POOL_ZALLOC_T(inv->pool_prov, pjmedia_sdp_session))) {
1990                 return NULL;
1991         }
1992
1993         if (!offer) {
1994                 local->origin.version = local->origin.id = (pj_uint32_t)(ast_random());
1995         } else {
1996                 local->origin.version = offer->origin.version + 1;
1997                 local->origin.id = offer->origin.id;
1998         }
1999
2000         pj_strdup2(inv->pool, &local->origin.user, session->endpoint->media.sdpowner);
2001         local->origin.net_type = STR_IN;
2002         local->origin.addr_type = session->endpoint->media.rtp.ipv6 ? STR_IP6 : STR_IP4;
2003         local->origin.addr = *hostname;
2004         pj_strdup2(inv->pool, &local->name, session->endpoint->media.sdpsession);
2005
2006         /* Now let the handlers add streams of various types, pjmedia will automatically reorder the media streams for us */
2007         successful = ao2_callback_data(session->media, OBJ_MULTIPLE, add_sdp_streams, local, session);
2008         if (!successful || ao2_container_count(successful->c) != ao2_container_count(session->media)) {
2009                 /* Something experienced a catastrophic failure */
2010                 return NULL;
2011         }
2012
2013         /* Use the connection details of the first media stream if possible for SDP level */
2014         if (local->media_count) {
2015                 local->conn = local->media[0]->conn;
2016         }
2017
2018         return local;
2019 }
2020
2021 static void session_inv_on_rx_offer(pjsip_inv_session *inv, const pjmedia_sdp_session *offer)
2022 {
2023         struct ast_sip_session *session = inv->mod_data[session_module.id];
2024         pjmedia_sdp_session *answer;
2025
2026         if (handle_incoming_sdp(session, offer)) {
2027                 return;
2028         }
2029
2030         if ((answer = create_local_sdp(inv, session, offer))) {
2031                 pjsip_inv_set_sdp_answer(inv, answer);
2032         }
2033 }
2034
2035 #if 0
2036 static void session_inv_on_create_offer(pjsip_inv_session *inv, pjmedia_sdp_session **p_offer)
2037 {
2038         /* XXX STUB */
2039 }
2040 #endif
2041
2042 static void session_inv_on_media_update(pjsip_inv_session *inv, pj_status_t status)
2043 {
2044         struct ast_sip_session *session = inv->mod_data[session_module.id];
2045         const pjmedia_sdp_session *local, *remote;
2046
2047         if (!session->channel) {
2048                 /* If we don't have a channel. We really don't care about media updates.
2049                  * Just ignore
2050                  */
2051                 return;
2052         }
2053
2054         if ((status != PJ_SUCCESS) || (pjmedia_sdp_neg_get_active_local(inv->neg, &local) != PJ_SUCCESS) ||
2055                 (pjmedia_sdp_neg_get_active_remote(inv->neg, &remote) != PJ_SUCCESS)) {
2056                 ast_channel_hangupcause_set(session->channel, AST_CAUSE_BEARERCAPABILITY_NOTAVAIL);
2057                 ast_queue_hangup(session->channel);
2058                 return;
2059         }
2060
2061         handle_negotiated_sdp(session, local, remote);
2062 }
2063
2064 static pjsip_redirect_op session_inv_on_redirected(pjsip_inv_session *inv, const pjsip_uri *target, const pjsip_event *e)
2065 {
2066         struct ast_sip_session *session = inv->mod_data[session_module.id];
2067
2068         if (PJSIP_URI_SCHEME_IS_SIP(target) || PJSIP_URI_SCHEME_IS_SIPS(target)) {
2069                 const pjsip_sip_uri *uri = pjsip_uri_get_uri(target);
2070                 char exten[AST_MAX_EXTENSION];
2071
2072                 ast_copy_pj_str(exten, &uri->user, sizeof(exten));
2073                 ast_channel_call_forward_set(session->channel, exten);
2074         }
2075
2076         return PJSIP_REDIRECT_STOP;
2077 }
2078
2079 static pjsip_inv_callback inv_callback = {
2080         .on_state_changed = session_inv_on_state_changed,
2081         .on_new_session = session_inv_on_new_session,
2082         .on_tsx_state_changed = session_inv_on_tsx_state_changed,
2083         .on_rx_offer = session_inv_on_rx_offer,
2084         .on_media_update = session_inv_on_media_update,
2085         .on_redirected = session_inv_on_redirected,
2086 };
2087
2088 /*! \brief Hook for modifying outgoing messages with SDP to contain the proper address information */
2089 static void session_outgoing_nat_hook(pjsip_tx_data *tdata, struct ast_sip_transport *transport)
2090 {
2091         struct ast_sip_nat_hook *hook = ast_sip_mod_data_get(
2092                 tdata->mod_data, session_module.id, MOD_DATA_NAT_HOOK);
2093         struct pjmedia_sdp_session *sdp;
2094         int stream;
2095
2096         /* SDP produced by us directly will never be multipart */
2097         if (hook || !tdata->msg->body || pj_stricmp2(&tdata->msg->body->content_type.type, "application") ||
2098                 pj_stricmp2(&tdata->msg->body->content_type.subtype, "sdp") || ast_strlen_zero(transport->external_media_address)) {
2099                 return;
2100         }
2101
2102         sdp = tdata->msg->body->data;
2103
2104         if (sdp->conn) {
2105                 char host[NI_MAXHOST];
2106                 struct ast_sockaddr addr = { { 0, } };
2107
2108                 ast_copy_pj_str(host, &sdp->conn->addr, sizeof(host));
2109                 ast_sockaddr_parse(&addr, host, PARSE_PORT_FORBID);
2110
2111                 if (ast_apply_ha(transport->localnet, &addr) != AST_SENSE_ALLOW) {
2112                         pj_strdup2(tdata->pool, &sdp->conn->addr, transport->external_media_address);
2113                 }
2114         }
2115
2116         for (stream = 0; stream < sdp->media_count; ++stream) {
2117                 /* See if there are registered handlers for this media stream type */
2118                 char media[20];
2119                 struct ast_sip_session_sdp_handler *handler;
2120                 RAII_VAR(struct sdp_handler_list *, handler_list, NULL, ao2_cleanup);
2121
2122                 /* We need a null-terminated version of the media string */
2123                 ast_copy_pj_str(media, &sdp->media[stream]->desc.media, sizeof(media));
2124
2125                 handler_list = ao2_find(sdp_handlers, media, OBJ_KEY);
2126                 if (!handler_list) {
2127                         ast_debug(1, "No registered SDP handlers for media type '%s'\n", media);
2128                         continue;
2129                 }
2130                 AST_LIST_TRAVERSE(&handler_list->list, handler, next) {
2131                         if (handler->change_outgoing_sdp_stream_media_address) {
2132                                 handler->change_outgoing_sdp_stream_media_address(tdata, sdp->media[stream], transport);
2133                         }
2134                 }
2135         }
2136
2137         /* We purposely do this so that the hook will not be invoked multiple times, ie: if a retransmit occurs */
2138         ast_sip_mod_data_set(tdata->pool, tdata->mod_data, session_module.id, MOD_DATA_NAT_HOOK, nat_hook);
2139 }
2140
2141 static int load_module(void)
2142 {
2143         pjsip_endpoint *endpt;
2144         if (!ast_sip_get_sorcery() || !ast_sip_get_pjsip_endpoint()) {
2145                 return AST_MODULE_LOAD_DECLINE;
2146         }
2147         if (!(nat_hook = ast_sorcery_alloc(ast_sip_get_sorcery(), "nat_hook", NULL))) {
2148                 return AST_MODULE_LOAD_DECLINE;
2149         }
2150         nat_hook->outgoing_external_message = session_outgoing_nat_hook;
2151         ast_sorcery_create(ast_sip_get_sorcery(), nat_hook);
2152         sdp_handlers = ao2_container_alloc(SDP_HANDLER_BUCKETS,
2153                         sdp_handler_list_hash, sdp_handler_list_cmp);
2154         if (!sdp_handlers) {
2155                 return AST_MODULE_LOAD_DECLINE;
2156         }
2157         endpt = ast_sip_get_pjsip_endpoint();
2158         pjsip_inv_usage_init(endpt, &inv_callback);
2159         pjsip_100rel_init_module(endpt);
2160         pjsip_timer_init_module(endpt);
2161         hostname = pj_gethostname();
2162         if (ast_sip_register_service(&session_module)) {
2163                 return AST_MODULE_LOAD_DECLINE;
2164         }
2165         ast_sip_register_service(&session_reinvite_module);
2166
2167         ast_module_ref(ast_module_info->self);
2168
2169         return AST_MODULE_LOAD_SUCCESS;
2170 }
2171
2172 static int unload_module(void)
2173 {
2174         /* This will never get called as this module can't be unloaded */
2175         return 0;
2176 }
2177
2178 AST_MODULE_INFO(ASTERISK_GPL_KEY, AST_MODFLAG_GLOBAL_SYMBOLS | AST_MODFLAG_LOAD_ORDER, "PJSIP Session resource",
2179                 .load = load_module,
2180                 .unload = unload_module,
2181                 .load_pri = AST_MODPRI_APP_DEPEND,
2182                );