tsdecrypt reads and decrypts CSA encrypted incoming mpeg transport stream over UDP/RTP using code words obtained from OSCAM or similar CAM server. tsdecrypt communicates with CAM server using cs378x (camd35 over tcp) protocol or newcamd protocol. https://georgi.unixsol.org/programs/tsdecrypt/
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

tables.c 15KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519
  1. /*
  2. * Process PSI tables
  3. * Copyright (C) 2011 Unix Solutions Ltd.
  4. *
  5. * This program is free software; you can redistribute it and/or modify
  6. * it under the terms of the GNU General Public License version 2
  7. * as published by the Free Software Foundation.
  8. *
  9. * This program is distributed in the hope that it will be useful,
  10. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  11. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  12. * GNU General Public License (COPYING file) for more details.
  13. *
  14. */
  15. #include <string.h>
  16. #include "data.h"
  17. #include "tables.h"
  18. #include "camd.h"
  19. #include "filter.h"
  20. #include "libtsfuncs/tsfuncs.h"
  21. #include "libfuncs/libfuncs.h"
  22. extern void show_ts_pack(struct ts *ts, uint16_t pid, char *wtf, char *extra, uint8_t *ts_packet);
  23. #define handle_table_changes(TABLE) \
  24. do { \
  25. show_ts_pack(ts, pid, #TABLE, NULL, ts_packet); \
  26. ts->cur##TABLE = ts_##TABLE##_push_packet(ts->cur##TABLE, ts_packet); \
  27. if (!ts->cur##TABLE->initialized) \
  28. return; \
  29. if (ts_##TABLE##_is_same(ts->TABLE, ts->cur##TABLE)) { \
  30. ts_##TABLE##_clear(ts->cur##TABLE); \
  31. return; \
  32. } \
  33. ts_##TABLE##_free(&ts->TABLE); \
  34. ts->TABLE = ts_##TABLE##_copy(ts->cur##TABLE); \
  35. ts_##TABLE##_clear(ts->cur##TABLE); \
  36. if (ts->debug_level >= 1) \
  37. ts_##TABLE##_dump(ts->TABLE); \
  38. } while(0)
  39. void process_pat(struct ts *ts, uint16_t pid, uint8_t *ts_packet) {
  40. int i;
  41. int num_services = 0;
  42. uint16_t f_service = 0, f_pid = 0;
  43. if (pid != 0x00)
  44. return;
  45. handle_table_changes(pat);
  46. for (i=0;i<ts->pat->programs_num;i++) {
  47. struct ts_pat_program *prg = ts->pat->programs[i];
  48. if (prg->pid && prg->program != 0) {
  49. num_services++;
  50. ts->pmt_pid = prg->pid;
  51. ts->service_id = prg->program;
  52. if (prg->program == ts->forced_service_id) {
  53. f_pid = prg->pid;
  54. f_service = prg->program;
  55. }
  56. }
  57. }
  58. if (f_service && f_pid) {
  59. ts->pmt_pid = f_pid;
  60. ts->service_id = f_service;
  61. }
  62. if (num_services > 1 && !f_service) {
  63. ts_LOGf("PAT | %d services exists. Consider using --input-service parameter.\n",
  64. num_services);
  65. for (i = 0; i < ts->pat->programs_num; i++) {
  66. struct ts_pat_program *prg = ts->pat->programs[i];
  67. if (prg->pid && prg->program != 0) {
  68. ts_LOGf("PAT | Service 0x%04x (%5d) with PMT PID %04x (%d)\n",
  69. prg->program, prg->program,
  70. prg->pid, prg->pid);
  71. }
  72. }
  73. }
  74. ts_LOGf("PAT | Using service 0x%04x (%d), PMT pid: %04x (%d)\n",
  75. ts->service_id, ts->service_id,
  76. ts->pmt_pid, ts->pmt_pid);
  77. if (num_services > 1) {
  78. ts_pat_clear(ts->genpat);
  79. ts->genpat = ts_pat_init(ts->genpat, ts->pat->section_header->ts_id_number);
  80. ts_pat_add_program(ts->genpat, ts->service_id, ts->pmt_pid);
  81. }
  82. }
  83. void process_cat(struct ts *ts, uint16_t pid, uint8_t *ts_packet) {
  84. if (pid != 0x01)
  85. return;
  86. handle_table_changes(cat);
  87. if (ts->camd.constant_codeword)
  88. return;
  89. if (ts->forced_caid) {
  90. ts->emm_caid = ts->forced_caid;
  91. ts_get_emm_info_by_caid(ts->cat, ts->emm_caid, &ts->emm_pid);
  92. } else {
  93. ts_get_emm_info(ts->cat, ts->req_CA_sys, &ts->emm_caid, &ts->emm_pid);
  94. }
  95. if (ts->forced_emm_pid)
  96. ts_get_emm_info_by_pid(ts->cat, &ts->emm_caid, ts->forced_emm_pid);
  97. if (ts->emm_caid) {
  98. char *CA_sys = ts_get_CA_sys_txt(ts_get_CA_sys(ts->emm_caid));
  99. ts_LOGf("--- | EMM CAID: 0x%04x (%s)\n", ts->emm_caid, CA_sys);
  100. if (!ts->forced_emm_pid) {
  101. ts_LOGf("--- | EMM pid : 0x%04x (%s)\n", ts->emm_pid, CA_sys);
  102. } else {
  103. ts_LOGf("--- | EMM pid : 0x%04x (%s) (forced: 0x%04x)\n",
  104. ts->emm_pid, CA_sys, ts->forced_emm_pid);
  105. ts->emm_pid = ts->forced_emm_pid;
  106. }
  107. } else {
  108. ts_LOGf("*** | ERROR: Can't detect EMM pid.\n");
  109. }
  110. }
  111. // Copied from libtsfuncs with added logic to return more than one PID and to handle both req_CA_type && forced_caid
  112. static int find_CA_descriptor(uint8_t *data, int data_len, enum CA_system req_CA_type, uint16_t forced_caid, uint16_t *CA_id, uint16_t *CA_pid, uint16_t *CA_pids, unsigned int *n_pids) {
  113. while (data_len >= 2) {
  114. uint8_t tag = data[0];
  115. uint8_t this_length = data[1];
  116. data += 2;
  117. data_len -= 2;
  118. if (tag == 9 && this_length >= 4) {
  119. uint16_t CA_ID = (data[0] << 8) | data[1];
  120. uint16_t CA_PID = ((data[2] & 0x1F) << 8) | data[3];
  121. bool ca_match = 0;
  122. if (forced_caid) {
  123. ca_match = forced_caid == CA_ID;
  124. } else {
  125. ca_match = ts_get_CA_sys(CA_ID) == req_CA_type;
  126. }
  127. if (ca_match) {
  128. *CA_id = CA_ID;
  129. *CA_pid = CA_PID;
  130. if (*n_pids < MAX_ECM_PIDS) {
  131. unsigned int i, exist = 0;
  132. for (i = 0; i < MAX_ECM_PIDS; i++) {
  133. if (CA_pids[i] == CA_PID) {
  134. exist = 1;
  135. break;
  136. }
  137. }
  138. if (!exist) {
  139. CA_pids[(*n_pids)++] = CA_PID;
  140. }
  141. }
  142. }
  143. }
  144. data_len -= this_length;
  145. data += this_length;
  146. }
  147. return 0;
  148. }
  149. // Copied from libtsfuncs with added logic to return more than one PID
  150. int __ts_get_ecm_info(struct ts_pmt *pmt, enum CA_system req_CA_type, uint16_t forced_caid, uint16_t *CA_id, uint16_t *CA_pid, uint16_t *CA_pids, unsigned int *n_pids) {
  151. int i, result = find_CA_descriptor(pmt->program_info, pmt->program_info_size, req_CA_type, forced_caid, CA_id, CA_pid, CA_pids, n_pids);
  152. if (!result) {
  153. for(i=0;i<pmt->streams_num;i++) {
  154. struct ts_pmt_stream *stream = pmt->streams[i];
  155. if (stream->ES_info) {
  156. result = find_CA_descriptor(stream->ES_info, stream->ES_info_size, req_CA_type, forced_caid, CA_id, CA_pid, CA_pids, n_pids);
  157. if (result)
  158. break;
  159. }
  160. }
  161. }
  162. return result;
  163. }
  164. void process_pmt(struct ts *ts, uint16_t pid, uint8_t *ts_packet) {
  165. int i;
  166. if (!pid || pid != ts->pmt_pid)
  167. return;
  168. // Mark PMT as valid and the received timestamp
  169. ts->last_pmt_ts = time(NULL);
  170. ts->have_valid_pmt = 1;
  171. handle_table_changes(pmt);
  172. pidmap_clear(&ts->pidmap);
  173. pidmap_set(&ts->pidmap, 0x0000); // PAT
  174. pidmap_set(&ts->pidmap, 0x0011); // SDT
  175. if (ts->nit_passthrough)
  176. pidmap_set(&ts->pidmap, 0x0010); // NIT
  177. if (ts->eit_passthrough)
  178. pidmap_set(&ts->pidmap, 0x0012); // EIT
  179. if (ts->tdt_passthrough)
  180. pidmap_set(&ts->pidmap, 0x0014); // TDT/TOT
  181. pidmap_set(&ts->pidmap, ts->pmt->ts_header.pid); // PMT PID
  182. pidmap_set(&ts->pidmap, ts->pmt->PCR_pid); // PCR
  183. for (i=0;i<ts->pmt->streams_num;i++) {
  184. struct ts_pmt_stream *stream = ts->pmt->streams[i];
  185. pidmap_set(&ts->pidmap, stream->pid); // Data
  186. }
  187. if (ts->camd.constant_codeword)
  188. return;
  189. ts->n_ecm_pids = 0;
  190. __ts_get_ecm_info(ts->pmt, ts->req_CA_sys, ts->forced_caid, &ts->ecm_caid, &ts->ecm_pid, &ts->ecm_pids[0], &ts->n_ecm_pids);
  191. if (ts->forced_ecm_pid)
  192. ts_get_ecm_info_by_pid(ts->pmt, &ts->ecm_caid, ts->forced_ecm_pid);
  193. if (ts->ecm_caid) {
  194. char *CA_sys = ts_get_CA_sys_txt(ts_get_CA_sys(ts->ecm_caid));
  195. ts_LOGf("--- | ECM CAID: 0x%04x (%s)\n", ts->ecm_caid, CA_sys);
  196. if (!ts->forced_ecm_pid) {
  197. ts_LOGf("--- | ECM pid : 0x%04x (%s)\n", ts->ecm_pid, CA_sys);
  198. } else {
  199. ts_LOGf("--- | ECM pid : 0x%04x (%s) (forced: 0x%04x)\n",
  200. ts->ecm_pid, CA_sys, ts->forced_ecm_pid);
  201. ts->ecm_pid = ts->forced_ecm_pid;
  202. }
  203. if (ts->n_ecm_pids > 1) {
  204. for (i = 0; i < (int)ts->n_ecm_pids; i++) {
  205. ts_LOGf("--- | ECM pid : 0x%04x (%s) idx:%d\n", ts->ecm_pids[i], CA_sys, i);
  206. }
  207. }
  208. } else {
  209. ts_LOGf("*** | ERROR: Can't detect ECM pid.\n");
  210. }
  211. if (ts->req_CA_sys == CA_IRDETO) {
  212. memset(ts->irdeto_chid, 0, sizeof(ts->irdeto_chid));
  213. ts->irdeto_max_chids = 0;
  214. }
  215. }
  216. static int sdt_parse_service_name_desc(
  217. int desc_len, uint8_t *desc,
  218. uint8_t *service_type,
  219. uint8_t *pname_len, uint8_t **pname,
  220. uint8_t *sname_len, uint8_t **sname)
  221. {
  222. int ofs = 0;
  223. *pname_len = 0;
  224. *sname_len = 0;
  225. *pname = NULL;
  226. *sname = NULL;
  227. while (ofs + 2 < desc_len) {
  228. uint8_t tag = desc[ofs++];
  229. uint8_t len = desc[ofs++];
  230. if (tag != 0x48) {
  231. ofs += len;
  232. continue;
  233. }
  234. // Parse descriptor 0x48 - service_descriptor
  235. // +3 == +1 for service type, +1 for provider len, +1 for service len
  236. if (ofs + 3 > desc_len)
  237. break;
  238. *service_type = desc[ofs++];
  239. *pname_len = desc[ofs++];
  240. if (*pname_len)
  241. *pname = desc + ofs;
  242. ofs += *pname_len;
  243. if (ofs > desc_len)
  244. break;
  245. *sname_len = desc[ofs++];
  246. if (*sname_len)
  247. *sname = desc + ofs;
  248. return 1;
  249. }
  250. return 0;
  251. }
  252. void process_sdt(struct ts *ts, uint16_t pid, uint8_t *ts_packet) {
  253. int i;
  254. if (pid != 0x11)
  255. return;
  256. handle_table_changes(sdt);
  257. for(i=0;i<ts->sdt->streams_num;i++) {
  258. struct ts_sdt_stream *stream = ts->sdt->streams[i];
  259. uint8_t service_type;
  260. uint8_t *pname, *sname;
  261. uint8_t pname_len, sname_len;
  262. if (sdt_parse_service_name_desc(
  263. stream->descriptor_size, stream->descriptor_data,
  264. &service_type,
  265. &pname_len, &pname, &sname_len, &sname))
  266. {
  267. int r;
  268. for (r = 0; r < pname_len; r++) {
  269. if (pname[r] < ' ')
  270. pname[r] = '*';
  271. }
  272. for (r = 0; r < sname_len; r++) {
  273. if (sname[r] < ' ')
  274. sname[r] = '*';
  275. }
  276. ts_LOGf("SDT | Service 0x%04x (%5d) Type: 0x%02x (%s) Provider: \"%.*s\" Service: \"%.*s\"\n",
  277. stream->service_id, stream->service_id,
  278. service_type,
  279. // The service types are described in Table 87 of
  280. // ETSI EN 300 468 v1.12.1 and also in annex I of the
  281. // same document.
  282. service_type == 0x01 ? "Tv" :
  283. service_type == 0x02 ? "Radio" :
  284. service_type == 0x11 ? "Tv/HD" :
  285. service_type == 0x16 ? "Tv/h264" :
  286. service_type == 0x19 ? "Tv/HD/h264" :
  287. service_type == 0x1c ? "Tv/3d" : "unknown",
  288. pname_len, (char *)pname,
  289. sname_len, (char *)sname);
  290. } else {
  291. ts_LOGf("SDT | Service 0x%04x (%5d)\n",
  292. stream->service_id, stream->service_id);
  293. }
  294. }
  295. }
  296. #define dump_sz (15)
  297. #define dump_buf_sz (dump_sz * 6)
  298. static void __process_emm(struct ts *ts, uint16_t pid, uint8_t *ts_packet) {
  299. char dump[dump_buf_sz];
  300. show_ts_pack(ts, pid, "emm", NULL, ts_packet);
  301. ts->emm_input_count++;
  302. ts->emm = ts_privsec_push_packet(ts->emm, ts_packet);
  303. if (!ts->emm->initialized)
  304. return;
  305. struct ts_header *th = &ts->emm->ts_header;
  306. struct ts_section_header *sec = ts->emm->section_header;
  307. int emm_ok = 1;
  308. if (ts->emm_filters_num)
  309. emm_ok = filter_match_emm(ts, sec->section_data, sec->section_data_len);
  310. if (ts->debug_level >= 2) {
  311. ts_hex_dump_buf(dump, dump_buf_sz, sec->section_data, min(dump_sz, sec->section_data_len), 0);
  312. ts_LOGf("EMM | SID 0x%04x CAID: 0x%04x PID 0x%04x Table: 0x%02x Length: %4d %s %s..\n",
  313. ts->service_id,
  314. ts->emm_caid,
  315. th->pid,
  316. sec->table_id,
  317. sec->section_data_len,
  318. emm_ok == 1 ? "Data:" : "SKIP:",
  319. dump);
  320. }
  321. if (emm_ok && sec->section_data_len < CAMD35_DATA_SIZE)
  322. camd_process_packet(ts, camd_msg_alloc(EMM_MSG, ts->emm_caid, ts->service_id, sec->section_data, sec->section_data_len));
  323. else
  324. ts->emm_skipped_count++;
  325. ts_privsec_copy(ts->emm, ts->last_emm);
  326. ts_privsec_clear(ts->emm);
  327. }
  328. static void __process_ecm(struct ts *ts, uint16_t pid, uint8_t *ts_packet) {
  329. char dump[dump_buf_sz];
  330. ts->ecm = ts_privsec_push_packet(ts->ecm, ts_packet);
  331. if (!ts->ecm->initialized)
  332. return;
  333. if (ts->req_CA_sys == CA_IRDETO) {
  334. uint8_t idx = ts->ecm->section_header->section_data[4];
  335. uint8_t max_idx = ts->ecm->section_header->section_data[5];
  336. uint16_t chid = (ts->ecm->section_header->section_data[6] << 8) | ts->ecm->section_header->section_data[7];
  337. if (max_idx != ts->irdeto_max_chids) {
  338. memset(ts->irdeto_chid, 0, sizeof(ts->irdeto_chid));
  339. ts->irdeto_max_chids = max_idx;
  340. }
  341. bool ecm_ok = false;
  342. const char *filter_type;
  343. switch (ts->irdeto_ecm_filter_type) {
  344. case IRDETO_FILTER_IDX : ecm_ok = (idx == ts->irdeto_ecm_idx); filter_type = " BY IDX"; break;
  345. case IRDETO_FILTER_CHID: ecm_ok = (chid == ts->irdeto_ecm_chid); filter_type = " BY CHID"; break;
  346. }
  347. if (ts->irdeto_chid[idx].seen < 1) {
  348. ts_LOGf("CAS | Seen Irdeto CHID 0x%04x (idx %u/%u)%s%s\n", chid, idx, max_idx,
  349. ecm_ok ? " *SELECTED*" : "",
  350. ecm_ok ? filter_type : "");
  351. ts->irdeto_chid[idx].seen++;
  352. }
  353. if (!ecm_ok) {
  354. ts_privsec_clear(ts->ecm);
  355. return;
  356. }
  357. }
  358. struct ts_header *th = &ts->ecm->ts_header;
  359. struct ts_section_header *sec = ts->ecm->section_header;
  360. // ECMs should be in these tables.
  361. if (sec->section_data[0] != 0x80 && sec->section_data[0] != 0x81) {
  362. ts_privsec_clear(ts->ecm);
  363. return;
  364. }
  365. int duplicate = ts_privsec_is_same(ts->ecm, ts->last_ecm);
  366. if (duplicate && !ts->is_cw_error)
  367. ts->ecm_duplicate_count++;
  368. if (!ts->ecm_change_time.tv_sec && !ts->ecm_change_time.tv_usec) // The first time
  369. gettimeofday(&ts->ecm_change_time, NULL);
  370. if (!duplicate || ts->is_cw_error) {
  371. if (ts->ecm_cw_log) {
  372. struct timeval tv;
  373. gettimeofday(&tv, NULL);
  374. ts_LOGf("ECC | SID 0x%04x ------------ EcmChng: %5llu ms\n",
  375. ts->service_id,
  376. timeval_diff_msec(&ts->ecm_change_time, &tv));
  377. ts_hex_dump_buf(dump, dump_buf_sz, sec->section_data, min(dump_sz, sec->section_data_len), 0);
  378. ts_LOGf("ECM | SID 0x%04x CAID: 0x%04x PID 0x%04x Table: 0x%02x Length: %4d Data: %s..\n",
  379. ts->service_id,
  380. ts->ecm_caid,
  381. th->pid,
  382. sec->table_id,
  383. sec->section_data_len,
  384. dump);
  385. }
  386. gettimeofday(&ts->ecm_change_time, NULL);
  387. ts->is_cw_error = 0;
  388. camd_process_packet(ts, camd_msg_alloc(ECM_MSG, ts->ecm_caid, ts->service_id, sec->section_data, sec->section_data_len));
  389. } else if (ts->debug_level >= 3) {
  390. ts_LOGf("ECM | SID 0x%04x CAID: 0x%04x PID 0x%04x Table: 0x%02x Length: %4d Data: -dup-\n",
  391. ts->service_id,
  392. ts->ecm_caid,
  393. th->pid,
  394. sec->table_id,
  395. sec->section_data_len);
  396. }
  397. ts_privsec_copy(ts->ecm, ts->last_ecm);
  398. ts_privsec_clear(ts->ecm);
  399. show_ts_pack(ts, pid, !duplicate ? "ecm" : "ec+", NULL, ts_packet);
  400. }
  401. // There are cryptosystems that are puting more than one PSI table
  402. // in TS packet. IRDETO is such example. Because libtsfuncs assumes
  403. // that one ts packet can produce maximum 1 PSI table, the following
  404. // workaround is used for EMM/ECM private sections. Basically we detect
  405. // if after the section there is something else than 0xff (filler) and
  406. // if there is something change ts_packet pointer field to point to
  407. // start of the potential section and reparse section.
  408. void process_ecm(struct ts *ts, uint16_t pid, uint8_t *ts_packet) {
  409. int section_end;
  410. if (!ts->process_ecm)
  411. return;
  412. if (!ts->ecm_pid || ts->ecm_pid != pid)
  413. return;
  414. process_psi:
  415. ts->tmp_ecm = ts_privsec_push_packet(ts->tmp_ecm, ts_packet);
  416. if (!ts->tmp_ecm->initialized) {
  417. __process_ecm(ts, pid, ts_packet);
  418. return;
  419. }
  420. section_end = ts->tmp_ecm->section_header->pointer_field + ts->tmp_ecm->section_header->section_length + 3 + 4 + 1;
  421. if (section_end < 188 && ts_packet[section_end] != 0xff) {
  422. __process_ecm(ts, pid, ts_packet);
  423. ts_packet[4] = ts_packet[4] + ts->tmp_ecm->section_header->section_length + 3;
  424. ts_privsec_clear(ts->tmp_ecm);
  425. goto process_psi;
  426. } else {
  427. __process_ecm(ts, pid, ts_packet);
  428. }
  429. ts_privsec_clear(ts->tmp_ecm);
  430. }
  431. void process_emm(struct ts *ts, uint16_t pid, uint8_t *ts_packet) {
  432. int section_end;
  433. if (!ts->process_emm)
  434. return;
  435. process_psi:
  436. ts->tmp_emm = ts_privsec_push_packet(ts->tmp_emm, ts_packet);
  437. if (!ts->tmp_emm->initialized) {
  438. __process_emm(ts, pid, ts_packet);
  439. return;
  440. }
  441. section_end = ts->tmp_emm->section_header->pointer_field + ts->tmp_emm->section_header->section_length + 3 + 4 + 1;
  442. if (section_end < 188 && ts_packet[section_end] != 0xff) {
  443. __process_emm(ts, pid, ts_packet);
  444. ts_packet[4] = ts_packet[4] + ts->tmp_emm->section_header->section_length + 3;
  445. ts_privsec_clear(ts->tmp_emm);
  446. goto process_psi;
  447. } else {
  448. __process_emm(ts, pid, ts_packet);
  449. }
  450. ts_privsec_clear(ts->tmp_emm);
  451. }