From b54f5b02f310a4705531d7bb1fe383afd6af98df Mon Sep 17 00:00:00 2001 From: Lilleman auf Larv Date: Tue, 22 Sep 2026 21:43:57 +0200 Subject: [PATCH] Leave alert_notification and outbind unanswered --- CHANGELOG.md | 3 +++ src/incoming-requests.ts | 7 +++++++ src/server.ts | 3 ++- test/session.test.ts | 42 ++++++++++++++++++++++++++++++++++++++++ todo.md | 6 ------ 5 files changed, 54 insertions(+), 7 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index e94672e..a3a9f5d 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -32,6 +32,9 @@ a caller that reads only `smsIds` meets a failure it has not met before. A whole number in an address or an id still spells its digits, so `message_id: 123` is unchanged. The integer fields name a refused `NaN` too, where the refusal used to read `null`. +- An `alert_notification` or an `outbind` from the peer is logged and left unanswered, as SMPP 3.4 + gives neither a response. Each one used to emit `sessionError`, `"alert_notification" has no + response command`, and a server did the same for an `outbind` before bind. ## 0.5.0 diff --git a/src/incoming-requests.ts b/src/incoming-requests.ts index 420dbf7..95d83c2 100644 --- a/src/incoming-requests.ts +++ b/src/incoming-requests.ts @@ -16,6 +16,7 @@ import { createSms } from './sms.ts'; import { dlrFromPdu } from './dlr.ts'; import { paramText } from './defs/types.ts'; import { respIdParams, segmentId } from './sms-id.ts'; +import { respNameFor } from './defs/commands.ts'; /** SMPP 3.4 lists ESME_RMSGQFUL under submit_sm_resp only; 4.6.2's retryable code is another. */ export function refusedSegmentStatus( @@ -171,6 +172,12 @@ export class IncomingRequests { return; } + if (!respNameFor(pduObj.cmdName)) { + this.log.info('session - ignoring a command SMPP gives no response', { cmdName: pduObj.cmdName }); + + return; + } + this.log.info('session - no handler for command', { cmdName: pduObj.cmdName }); await this.session.sendReturn(pduObj, 'ESME_RINVCMDID'); } diff --git a/src/server.ts b/src/server.ts index 51303bf..7cad123 100644 --- a/src/server.ts +++ b/src/server.ts @@ -13,6 +13,7 @@ import { defaultInterfaceVersion } from './defs/constants.ts'; import { errorFrom } from './error-from.ts'; import { paramText } from './defs/types.ts'; import { guardedLog } from './log.ts'; +import { respNameFor } from './defs/commands.ts'; export type AuthenticateResult = { userData?: unknown } | boolean; @@ -224,7 +225,7 @@ async function handleRequest( return true; } - if (pduObj.cmdName === 'unbind') return false; + if (pduObj.cmdName === 'unbind' || !respNameFor(pduObj.cmdName)) return false; session.log.debug('server - command before bind', { cmdName: pduObj.cmdName }); await session.sendReturn(pduObj, 'ESME_RINVBNDSTS'); diff --git a/test/session.test.ts b/test/session.test.ts index fa7d0a1..c0f6c39 100644 --- a/test/session.test.ts +++ b/test/session.test.ts @@ -316,6 +316,28 @@ describe('bind', () => { assert.equal(await responded, '00000010800000150000000400000001'); }); + test('leaves an outbind from an unbound peer unanswered', async t => { + const smpp = await startServer(t); + const errors: Error[] = []; + + smpp.on('session', session => { session.on('sessionError', err => { errors.push(err); }); }); + + const responded = once(resolve => { + const sock = net.connect({ port: smpp.port }, () => { + sock.write(pduBytes({ cmdName: 'outbind', params: { password: 'pass', system_id: 'smsc' }, seqNr: 1 })); + sock.write(Buffer.from('00000010000000150000000000000002', 'hex')); + }); + + sock.on('data', data => { + sock.destroy(); + resolve(data.toString('hex')); + }); + }); + + assert.equal(await responded, '00000010800000150000000400000002'); + assert.deepEqual(errors, []); + }); + test('answers the enquire_link a bound peer sends', async t => { const smpp = await startServer(t); const peer = rawPeer(t, smpp.port); @@ -1792,6 +1814,26 @@ describe('a PDU the codec cannot read', () => { assert.ok((await raceWithin(2000, failed)) instanceof Error, 'one sessionError per refused PDU'); }); + test('leaves an alert_notification and an outbind unanswered, since SMPP names no response', async t => { + const { peer, session } = await bound(t); + const errors: Error[] = []; + + session.on('sessionError', err => { errors.push(err); }); + peer.writeRaw(pduBytes({ + cmdName: 'alert_notification', + params: { esme_addr: '46709771337', source_addr: '46701113311' }, + seqNr: 10, + })); + peer.writeRaw(pduBytes({ cmdName: 'outbind', params: { password: 'pass', system_id: 'smsc' }, seqNr: 11 })); + peer.writeRaw(pduBytes({ cmdName: 'enquire_link', seqNr: 12 })); + + const answered = await answerTo(peer); + + assert.equal(answered.cmdName, 'enquire_link_resp'); + assert.equal(answered.seqNr, 12); + assert.deepEqual(errors, []); + }); + test('answers a deliver_sm with a truncated TLV stream with ESME_RINVTLVSTREAM', async t => { const { peer, session } = await bound(t); let reports = 0; diff --git a/todo.md b/todo.md index fe521dd..0ecb709 100644 --- a/todo.md +++ b/todo.md @@ -200,12 +200,6 @@ and is also what the panel ranked hardest — two methods, one answer. caller never wrote." A goal is the maintainer's, so nothing edits README until that is answered. From the prose pass of #18. -- [ ] **Answer `alert_notification` and `outbind` by not answering them.** Both are response-less in - SMPP 3.4, both fall through `route()`'s default into `unhandled()`, which calls - `sendReturn(pduObj, 'ESME_RINVCMDID')`; `pduReturn()` then finds no response command, and the - failure reaches the application as `sessionError` on every occurrence. `alert_notification` - appears nowhere in `src/` but `defs/commands.ts`. One case arm each: log and return. - - [ ] **Range-check `maxOctets` with its five siblings.** `limitsOf()` in `session-options.ts` covers `idleTimeout`, `maxOutstanding`, `maxReassembly`, `reassemblyTimeout`, `responseTimeout` and `shutdownTimeout`; `maxOctets` is documented, consumed by `Reassembler`, and absent from