Compare commits

...
17 Commits
Author SHA1 Message Date
Dave Horton fec25d5d15 0.9.9 2026-08-20 09:16:55 -04:00
Dave Horton 5c470b9630 0.9.8 2026-07-20 08:43:34 -04:00
Hoan Luu HuuandClaude Opus 4.8 606792825e feat: honor X-Jambonz-SRTP header for forwarded sip URI calls (#230)
The feature-server sets X-Jambonz-SRTP (from the dial verb's
srtpEncryption option) to request encrypted media on a per-call basis.
Previously SRTP on a forwarded sip URI could only be enabled globally
via JAMBONES_SIPS_FORWARD_SRTP + a sips: scheme; now an application can
opt in per call. The env var remains as a global fallback. The internal
header is stripped before the INVITE is sent to the target.

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-20 07:24:14 -04:00
Dave Horton ffec713d62 bump version 2026-07-09 07:31:05 -04:00
Hoan Luu Huu 6921c1cf31 update rtcp-mux to default for srtp (#229) 2026-07-09 07:10:13 -04:00
Sam Machin 37e4dea705 decrement count on abandoned call (#228)
fix typo so correct error message is logged
2026-07-03 11:11:46 -04:00
Hoan Luu Huu 4fb5acaf40 update realtimedb-helper (#227) 2026-06-15 20:43:07 -04:00
Sam MachinandDave Horton 865068f158 add new CODEC_TRANSCODE option (#225)
* add new CODEC_TRANSCODE option

allows RTP engine to add additional codecs to the outgoing offer that wern't in the invite from Freeswitch so RTP engine will transcode outbound calls.

* update README for new env var descriptions

---------

Co-authored-by: Dave Horton <daveh@beachdognet.com>
2026-05-01 08:43:13 -04:00
Hoan Luu Huu 4f65b4b585 support srtp for sips sipuri outbound call (#224)
* support srtp for sips sipuri outbound call

* wip

* wip

* add env variable for disable the srtp for sipURI
2026-04-22 08:00:50 -04:00
Hoan Luu Huu 8ccd02aa1f update drachtio srf 5.0.21 (#221) 2026-04-13 21:24:42 -04:00
Dave Horton 0911032146 bump version 2026-03-31 07:47:05 -04:00
Dave Horton 121ae75b39 update deps 2026-03-30 21:07:19 -04:00
Dave Horton 57bc073ea3 update to drachtio-srf latest (#218) 2026-03-13 09:02:05 -04:00
Dave Horton 84bce56766 update drachtio-srf 2026-02-09 10:25:47 -05:00
Sam Machin d053b94e71 remove ice and dtls off (#214)
* remove ice and dtls off if set in db

* lint

* more lint
2026-01-29 13:43:30 -05:00
Dave Horton a50ed56b36 update devDependencies (#215) 2026-01-22 11:47:02 -05:00
Hoan Luu Huu 8fdcc8cbc4 update drachtio srf version 5.0.17 (#213) 2026-01-22 08:12:50 -05:00
7 changed files with 666 additions and 515 deletions
+1
View File
@@ -34,6 +34,7 @@ build/Release
node_modules
.DS_Store
.vscode
examples/*
CLAUDE.md
+10
View File
@@ -29,9 +29,19 @@ Configuration is provided via environment variables:
|JAMBONES_RTPENGINES| commans-separated list of ip:ng-port for rtpengines (e.g. '172.31.32.10:22222')|yes|
|JAMBONES_TIME_SERIES_HOST| influxdb host |yes|
|JAMBONES_RECORD_ALL_CALLS| enable auto record calls |no|
|JAMBONES_CODEC_OFFER_WITH_ORDER| comma-separated codec list to use as the outbound offer toward the carrier; the original codecs from the feature server are stripped first (e.g. `'opus,PCMU,PCMA,telephone-event'`) |no|
|JAMBONES_CODEC_TRANSCODE| comma-separated codec list that rtpengine should add to the outbound offer and transcode on the fly when the carrier selects them — used to support codecs the feature server does not speak (e.g. `'AMR-WB/16000'`). Requires an rtpengine build that includes the corresponding codec module. |no|
|JAMBONES_ACCEPT_AND_TRANSCODE| comma-separated codec list to accept on the outbound leg and transcode to PCMU/PCMA toward the feature server |no|
|JAMBONES_ACCEPT_G729| if set, accept G.729 on the outbound leg and transcode to PCMU/PCMA (shorthand for `JAMBONES_ACCEPT_AND_TRANSCODE=g729`) |no|
|K8S| service running as kubernetes service |no|
|K8S_RTPENGINE_SERVICE_NAME| rtpengine service name(required for K8S) |no|
#### Codec transcoding notes
`JAMBONES_CODEC_OFFER_WITH_ORDER` and `JAMBONES_CODEC_TRANSCODE` can be combined. When both are set, rtpengine first strips the original codecs from the SDP, then adds the codecs listed in `JAMBONES_CODEC_OFFER_WITH_ORDER` to the offer, and finally adds the codecs from `JAMBONES_CODEC_TRANSCODE` with transcoding enabled. When only `JAMBONES_CODEC_TRANSCODE` is set, the original codecs from the feature server are kept in the offer and the transcode codecs are appended.
Codecs that require licensed or optional rtpengine modules (AMR, AMR-WB, G.729, etc.) only work if rtpengine was compiled with support for them. Carrier-specific fmtp parameters (for example, `octet-align=1` for AMR-WB) can be appended to the codec name as needed (e.g. `AMR-WB/16000;octet-align=1`).
### running under pm2
Typically, this application runs under [pm2](https://pm2.io) using an [ecosystem.config.js](https://pm2.keymetrics.io/docs/usage/application-declaration/) file similar to this:
```js
+1 -1
View File
@@ -4,7 +4,7 @@
"ICE": "force",
"SDES": "off",
"flags": ["generate mid", "SDES-no", "port latching"],
"rtcp-mux": ["require"]
"rtcp-mux": ["offer"]
},
"teams": {
"transport-protocol": "RTP/SAVP",
+44 -4
View File
@@ -237,6 +237,24 @@ class CallSession extends Emitter {
this.logger.info(`sending call to registered user ${destUri}`);
}
else if (this.req.locals.target === 'forward') {
/* the feature-server sets X-Jambonz-SRTP (from the dial verb's srtpEncryption
option) to request encrypted media on a per-call basis */
const srtpMode = this.req.get('X-Jambonz-SRTP');
if (srtpMode) {
/* SDES (RTP/SAVP): pass teams=true to select the SDES srtp profile, matching
the proven carrier tls/srtp path above. This offers a=crypto to the target
(what SIP endpoints such as LiveKit expect), not DTLS-SRTP. */
this.logger.info({uri: this.req.uri, srtpMode},
'using SRTP (SDES) for forwarded call per X-Jambonz-SRTP');
this.rtpEngineOpts = makeRtpEngineOpts(this.req, false, true, false, true);
encryptedMedia = true;
}
else if (process.env.JAMBONES_SIPS_FORWARD_SRTP && this.req.uri.startsWith('sips:')) {
/* legacy global opt-in for sips: forwards (uses the DTLS srtp profile) */
this.logger.info({uri: this.req.uri}, 'using SRTP/TLS for forwarded sips: call');
this.rtpEngineOpts = makeRtpEngineOpts(this.req, false, true, false, false);
encryptedMedia = true;
}
uris = [{
private_network: await isPrivateVoipNetwork(this.req.uri),
uri: this.req.uri
@@ -352,7 +370,8 @@ class CallSession extends Emitter {
* like a rare use case -- encryption is usually an all or nothing requirement.
*/
this.logger.info({u}, `using SRTP for outbound call, pad crypto: ${o.pad_crypto ? 'yes' : 'no'}`);
this.rtpEngineOpts = makeRtpEngineOpts(this.req, false, true, o.pad_crypto, true);
// eslint-disable-next-line max-len
this.rtpEngineOpts = makeRtpEngineOpts(this.req, false, true, o.pad_crypto, true, o.remove_ice, o.dtls_off);
encryptedMedia = true;
}
});
@@ -525,6 +544,7 @@ class CallSession extends Emitter {
'-X-Preferred-From-Host',
'-X-Jambonz-FS-UUID',
'-X-Voip-Carrier-Sid',
'-X-Jambonz-SRTP',
'-X-SIP-Proxy'
],
proxyResponseHeaders: [
@@ -659,7 +679,21 @@ class CallSession extends Emitter {
}
}
} catch (err) {
if ('abandonded' !== err.message) this.logger.error({err}, `Error setting up outbound call to: ${uris}`);
if ('abandoned' !== err.message) this.logger.error({err}, `Error setting up outbound call to: ${uris}`);
/* the call count was incremented on 'init' but we bailed out before connecting (e.g. caller
hung up before the B leg answered), so we must decrement it here - no failure response is
sent on this path, so the res.once('end') safety net in middleware would not fire.
nudgeCallCounts is a no-op if the count was already decremented elsewhere. */
const {writeCallCount, writeCallCountSP, writeCallCountApp} = this.req.srf.locals;
nudgeCallCounts(this.req, 'failure', {
service_provider_sid: this.service_provider_sid,
account_sid: this.account_sid,
application_sid: this.application_sid,
callId: this.req.locals.callId
}, this.decrKey, {writeCallCountSP, writeCallCount, writeCallCountApp})
.catch((err) => this.logger.error(err, 'Error decrementing call counts'));
this.emit('failed');
this.srf.endSession(this.req);
this.rtpEngineResource.destroy();
@@ -886,8 +920,14 @@ Duration=${payload.duration} `
process.env.JAMBONES_ACCEPT_G729 ? 'g729' : '';
offerMedia = { ...offerMedia, ...(acceptCodecs && dlg.type === 'uac' &&
{ codec: { mask: acceptCodecs, transcode: 'pcmu,pcma' } })};
answerMedia = { ...answerMedia, ...(process.env.JAMBONES_CODEC_OFFER_WITH_ORDER && dlg.type === 'uac' &&
{ codec: {offer: process.env.JAMBONES_CODEC_OFFER_WITH_ORDER.split(','), strip: 'all' }})};
answerMedia = { ...answerMedia, ...((process.env.JAMBONES_CODEC_OFFER_WITH_ORDER ||
process.env.JAMBONES_CODEC_TRANSCODE) && dlg.type === 'uac' &&
{ codec: {
...(process.env.JAMBONES_CODEC_OFFER_WITH_ORDER &&
{ offer: process.env.JAMBONES_CODEC_OFFER_WITH_ORDER.split(','), strip: 'all' }),
...(process.env.JAMBONES_CODEC_TRANSCODE &&
{ transcode: process.env.JAMBONES_CODEC_TRANSCODE.split(',') })
}})};
let opts = {
...this.rtpEngineOpts.common,
...offerMedia,
+14 -1
View File
@@ -5,7 +5,8 @@ const CIDRMatcher = require('cidr-matcher');
const dns = require('dns');
const sdpTransform = require('sdp-transform');
function makeRtpEngineOpts(req, srcIsUsingSrtp, dstIsUsingSrtp, padCrypto, teams) {
// eslint-disable-next-line max-len
function makeRtpEngineOpts(req, srcIsUsingSrtp, dstIsUsingSrtp, padCrypto, teams, remove_ice = false, dtls_off = false) {
const from = req.getParsedHeader('from');
const rtpCopy = JSON.parse(JSON.stringify(rtpCharacteristics));
const srtpCopy = JSON.parse(JSON.stringify(srtpCharacteristics));
@@ -16,6 +17,14 @@ function makeRtpEngineOpts(req, srcIsUsingSrtp, dstIsUsingSrtp, padCrypto, teams
}
const srtpOpts = teams ? srtpCopy['teams'] : srtpCopy['default'];
if (remove_ice) {
srtpOpts.ICE = 'remove';
}
if (dtls_off) {
srtpOpts.DTLS = 'off';
}
const dstOpts = JSON.parse(JSON.stringify(dstIsUsingSrtp ? srtpOpts : rtpCopy));
const srcOpts = JSON.parse(JSON.stringify(srcIsUsingSrtp ? srtpOpts : rtpCopy));
@@ -49,6 +58,10 @@ function makeRtpEngineOpts(req, srcIsUsingSrtp, dstIsUsingSrtp, padCrypto, teams
offer: process.env.JAMBONES_CODEC_OFFER_WITH_ORDER.split(','),
strip: 'all'
}),
...(process.env.JAMBONES_CODEC_TRANSCODE &&
{
transcode: process.env.JAMBONES_CODEC_TRANSCODE.split(',')
}),
};
return {
+590 -503
View File
File diff suppressed because it is too large Load Diff
+6 -6
View File
@@ -1,9 +1,9 @@
{
"name": "sbc-outbound",
"version": "0.9.5",
"version": "0.9.9",
"main": "app.js",
"engines": {
"node": ">= 18.0.0"
"node": ">= 20.0.0"
},
"keywords": [
"sip",
@@ -31,7 +31,7 @@
"@jambonz/db-helpers": "^0.9.18",
"@jambonz/http-health-check": "^0.0.1",
"@jambonz/mw-registrar": "0.2.7",
"@jambonz/realtimedb-helpers": "^0.8.13",
"@jambonz/realtimedb-helpers": "^0.8.21",
"@jambonz/rtpengine-utils": "^0.4.4",
"@jambonz/siprec-client-utils": "^0.2.10",
"@jambonz/stats-collector": "^0.1.10",
@@ -39,7 +39,7 @@
"cidr-matcher": "^2.1.1",
"debug": "^4.4.3",
"drachtio-fn-b2b-sugar": "^0.2.1",
"drachtio-srf": "^5.0.12",
"drachtio-srf": "^5.0.21",
"express": "^4.21.2",
"pino": "^10.1.0",
"sdp-transform": "^2.15.0"
@@ -48,7 +48,7 @@
"bent": "^7.3.12",
"eslint": "^9.17.0",
"eslint-plugin-promise": "^7.2.1",
"nyc": "^15.1.0",
"tape": "^5.7.5"
"nyc": "^17.1.0",
"tape": "^5.9.0"
}
}