blob: 0490901b66a95c01a8873bac0697c6ee955bb1b6 [file] [log] [blame]
Harald Weltef6dd64d2017-11-19 12:09:51 +01001module MSC_Tests {
2
Harald Welte34b5a952019-05-27 11:54:11 +02003/* Osmocom MSC test suite in in TTCN-3
4 * (C) 2017-2019 Harald Welte <laforge@gnumonks.org>
5 * (C) 2018-2019 sysmocom - s.f.m.c. GmbH
6 * (C) 2018-2019 Vadim Yanitskiy <axilirator@gmail.com>
7 * All rights reserved.
8 *
9 * Released under the terms of GNU General Public License, Version 2 or
10 * (at your option) any later version.
11 *
12 * SPDX-License-Identifier: GPL-2.0-or-later
13 */
14
Harald Weltee13cfb22019-04-23 16:52:02 +020015friend module MSC_Tests_Iu;
16
Harald Weltef6dd64d2017-11-19 12:09:51 +010017import from General_Types all;
18import from Osmocom_Types all;
Pau Espin Pedrole979c402021-04-28 17:29:54 +020019import from GSM_Types all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010020
21import from M3UA_Types all;
22import from M3UA_Emulation all;
23
24import from MTP3asp_Types all;
25import from MTP3asp_PortType all;
26
27import from SCCPasp_Types all;
28import from SCCP_Types all;
29import from SCCP_Emulation all;
30
31import from SCTPasp_Types all;
32import from SCTPasp_PortType all;
33
Harald Weltea49e36e2018-01-21 19:29:33 +010034import from Osmocom_CTRL_Functions all;
35import from Osmocom_CTRL_Types all;
36import from Osmocom_CTRL_Adapter all;
37
Harald Welte3ca1c902018-01-24 18:51:27 +010038import from TELNETasp_PortType all;
39import from Osmocom_VTY_Functions all;
40
Harald Weltea49e36e2018-01-21 19:29:33 +010041import from MNCC_Emulation all;
Harald Welte2bb825f2018-01-22 11:31:18 +010042import from MNCC_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010043
Harald Welte4aa970c2018-01-26 10:38:09 +010044import from MGCP_Emulation all;
45import from MGCP_Types all;
46import from MGCP_Templates all;
47import from SDP_Types all;
48
Harald Weltea49e36e2018-01-21 19:29:33 +010049import from GSUP_Emulation all;
50import from GSUP_Types all;
51import from IPA_Emulation all;
52
Harald Weltef6dd64d2017-11-19 12:09:51 +010053import from BSSAP_Types all;
Harald Welte6811d102019-04-14 22:23:14 +020054import from RAN_Adapter all;
Harald Weltea49e36e2018-01-21 19:29:33 +010055import from BSSAP_CodecPort all;
56import from BSSMAP_Templates all;
Harald Welte6811d102019-04-14 22:23:14 +020057import from RAN_Emulation all;
Harald Weltea49e36e2018-01-21 19:29:33 +010058import from BSC_ConnectionHandler all;
Harald Weltee13cfb22019-04-23 16:52:02 +020059import from RANAP_Templates all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010060
Harald Welte4263c522018-12-06 11:56:27 +010061import from SGsAP_Templates all;
62import from SGsAP_Types all;
63import from SGsAP_Emulation all;
64
Harald Weltea49e36e2018-01-21 19:29:33 +010065import from MobileL3_Types all;
66import from MobileL3_CommonIE_Types all;
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +070067import from MobileL3_SMS_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010068import from L3_Templates all;
Harald Welte158a7ca2018-02-16 18:11:31 +010069import from L3_Common all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010070
Harald Weltef640a012018-04-14 17:49:21 +020071import from SMPP_Types all;
72import from SMPP_Templates all;
73import from SMPP_Emulation all;
74
Stefan Sperlingc307e682018-06-14 15:15:46 +020075import from SCCP_Templates all;
76
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070077import from SS_Types all;
78import from SS_Templates all;
79import from USSD_Helpers all;
Harald Welte4263c522018-12-06 11:56:27 +010080import from DNS_Helpers all;
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070081
Philipp Maier948747b2019-04-02 15:22:33 +020082import from TCCConversion_Functions all;
83
Harald Welte9b751a62019-04-14 17:39:29 +020084const integer NUM_BSC := 3;
Harald Weltef6dd64d2017-11-19 12:09:51 +010085
Harald Welte4263c522018-12-06 11:56:27 +010086/* Needed for SGsAP SMS */
87import from MobileL3_SMS_Types all;
88
Harald Weltea4ca4462018-02-09 00:17:14 +010089type component MTC_CT extends CTRL_Adapter_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +010090 var boolean g_initialized := false;
Harald Weltea49e36e2018-01-21 19:29:33 +010091
Harald Welte6811d102019-04-14 22:23:14 +020092 var RAN_Adapter g_bssap[NUM_BSC];
Harald Weltea4ca4462018-02-09 00:17:14 +010093
Harald Weltea49e36e2018-01-21 19:29:33 +010094 /* no 'adapter_CT' for MNCC or GSUP */
95 var MNCC_Emulation_CT vc_MNCC;
Harald Welte4aa970c2018-01-26 10:38:09 +010096 var MGCP_Emulation_CT vc_MGCP;
Harald Weltea49e36e2018-01-21 19:29:33 +010097 var GSUP_Emulation_CT vc_GSUP;
98 var IPA_Emulation_CT vc_GSUP_IPA;
Harald Weltef640a012018-04-14 17:49:21 +020099 var SMPP_Emulation_CT vc_SMPP;
Harald Welte4263c522018-12-06 11:56:27 +0100100 var SGsAP_Emulation_CT vc_SGsAP;
Harald Weltea49e36e2018-01-21 19:29:33 +0100101
102 /* only to get events from IPA underneath GSUP */
103 port IPA_CTRL_PT GSUP_IPA_EVENT;
Harald Welte3ca1c902018-01-24 18:51:27 +0100104 /* VTY to MSC */
105 port TELNETasp_PT MSCVTY;
Philipp Maier328d1662018-03-07 10:40:27 +0100106
107 /* A port to directly send BSSAP messages. This port is used for
108 * tests that require low level access to sen arbitrary BSSAP
109 * messages. Run f_init_bssap_direct() to connect and initialize */
110 port BSSAP_CODEC_PT BSSAP_DIRECT;
111
112 /* When BSSAP messages are directly sent, then the connection
113 * handler is not active, which means that also no guard timer is
114 * set up. The following timer will serve as a replacement */
115 timer Tguard_direct := 60.0;
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100116
117 /* Configure T(tias) over VTY, seconds */
118 var integer g_msc_sccp_timer_ias := 7 * 60;
119 /* Configure T(tiar) over VTY, seconds */
120 var integer g_msc_sccp_timer_iar := 15 * 60;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100121}
122
123modulepar {
Harald Weltea49e36e2018-01-21 19:29:33 +0100124 /* remote parameters of IUT */
125 charstring mp_msc_ip := "127.0.0.1";
126 integer mp_msc_ctrl_port := 4255;
127 integer mp_msc_vty_port := 4254;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100128
Harald Weltea49e36e2018-01-21 19:29:33 +0100129 /* local parameters of emulated HLR */
Philipp Maier9b690e42018-12-21 11:50:03 +0100130 boolean mp_mm_info := false;
Harald Weltea49e36e2018-01-21 19:29:33 +0100131 charstring mp_hlr_ip := "127.0.0.1";
132 integer mp_hlr_port := 4222;
Harald Welte6126fb02018-01-27 20:08:24 +0100133 charstring mp_mgw_ip := "127.0.0.1";
134 integer mp_mgw_port := 2427;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100135
Harald Weltea49e36e2018-01-21 19:29:33 +0100136 charstring mp_msc_mncc := "/tmp/mncc";
Harald Weltea4ca4462018-02-09 00:17:14 +0100137
Harald Weltef640a012018-04-14 17:49:21 +0200138 integer mp_msc_smpp_port := 2775;
139 charstring mp_smpp_system_id := "msc_tester";
140 charstring mp_smpp_password := "osmocom1";
Harald Welte4263c522018-12-06 11:56:27 +0100141 charstring mp_mme_name := "mmec01.mmegi0001.mme.epc.mnc070.mcc901.3gppnetwork.org";
142 charstring mp_vlr_name := "vlr.example.net";
Eric Wild49888a62022-03-30 03:16:11 +0200143 integer mp_bssap_reset_retries := 1;
Harald Weltef640a012018-04-14 17:49:21 +0200144
Harald Welte6811d102019-04-14 22:23:14 +0200145 RAN_Configurations mp_bssap_cfg := {
Philipp Maier75932982018-03-27 14:52:35 +0200146 {
147 sccp_service_type := "mtp3_itu",
148 sctp_addr := { 23905, "127.0.0.1", 2905, "127.0.0.1" },
149 own_pc := 185,
150 own_ssn := 254,
151 peer_pc := 187,
152 peer_ssn := 254,
153 sio := '83'O,
154 rctx := 0
155 },
156 {
157 sccp_service_type := "mtp3_itu",
158 sctp_addr := { 23906, "127.0.0.1", 2905, "127.0.0.1" },
159 own_pc := 186,
160 own_ssn := 254,
161 peer_pc := 187,
162 peer_ssn := 254,
163 sio := '83'O,
164 rctx := 1
165 }
Harald Weltea4ca4462018-02-09 00:17:14 +0100166 };
Harald Weltef6dd64d2017-11-19 12:09:51 +0100167}
168
Philipp Maier328d1662018-03-07 10:40:27 +0100169/* altstep for the global guard timer (only used when BSSAP_DIRECT
170 * is used for communication */
171private altstep as_Tguard_direct() runs on MTC_CT {
172 [] Tguard_direct.timeout {
173 setverdict(fail, "Tguard timeout");
Daniel Willmannafce8662018-07-06 23:11:32 +0200174 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +0100175 }
176}
Harald Weltef6dd64d2017-11-19 12:09:51 +0100177
Neels Hofmeyr2ca1ab42019-03-08 03:45:43 +0100178private altstep as_optional_cc_rel(CallParameters cpars, boolean respond := false) runs on BSC_ConnHdlr {
179 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id))) {
180 if (respond) {
181 var BIT1 tid_remote := '1'B;
182 if (cpars.mo_call) {
183 tid_remote := '0'B;
184 }
185 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id, tid_remote)));
186 }
187 }
Neels Hofmeyrde76f052019-02-26 05:02:46 +0100188}
189
Harald Weltef640a012018-04-14 17:49:21 +0200190function f_init_smpp(charstring id) runs on MTC_CT {
191 id := id & "-SMPP";
192 var EsmePars pars := {
193 mode := MODE_TRANSCEIVER,
194 bind := {
195 system_id := mp_smpp_system_id,
196 password := mp_smpp_password,
197 system_type := "MSC_Tests",
198 interface_version := hex2int('34'H),
199 addr_ton := unknown,
200 addr_npi := unknown,
201 address_range := ""
202 },
203 esme_role := true
204 }
205
206 vc_SMPP := SMPP_Emulation_CT.create(id);
207 map(vc_SMPP:SMPP_PORT, system:SMPP_PORT);
Harald Welte4698a4c2020-08-18 22:57:52 +0200208 vc_SMPP.start(SMPP_Emulation.main_client(pars, mp_msc_ip, mp_msc_smpp_port, "", 0));
Harald Weltef640a012018-04-14 17:49:21 +0200209}
210
211
Harald Weltea49e36e2018-01-21 19:29:33 +0100212function f_init_mncc(charstring id) runs on MTC_CT {
213 id := id & "-MNCC";
214 var MnccOps ops := {
215 create_cb := refers(MNCC_Emulation.ExpectedCreateCallback),
216 unitdata_cb := refers(MNCC_Emulation.DummyUnitdataCallback)
217 }
218
219 vc_MNCC := MNCC_Emulation_CT.create(id);
220 map(vc_MNCC:MNCC, system:MNCC_CODEC_PT);
221 vc_MNCC.start(MNCC_Emulation.main(ops, id, mp_msc_mncc));
Harald Weltef6dd64d2017-11-19 12:09:51 +0100222}
223
Harald Welte4aa970c2018-01-26 10:38:09 +0100224function f_init_mgcp(charstring id) runs on MTC_CT {
225 id := id & "-MGCP";
226 var MGCPOps ops := {
227 create_cb := refers(MGCP_Emulation.ExpectedCreateCallback),
228 unitdata_cb := refers(MGCP_Emulation.DummyUnitdataCallback)
229 }
230 var MGCP_conn_parameters pars := {
Harald Welte6126fb02018-01-27 20:08:24 +0100231 callagent_ip := mp_msc_ip,
Harald Welte4aa970c2018-01-26 10:38:09 +0100232 callagent_udp_port := -1,
Harald Welte6126fb02018-01-27 20:08:24 +0100233 mgw_ip := mp_mgw_ip,
Pau Espin Pedrol1a026a52019-06-18 17:21:52 +0200234 mgw_udp_port := mp_mgw_port,
235 multi_conn_mode := false
Harald Welte4aa970c2018-01-26 10:38:09 +0100236 }
237
238 vc_MGCP := MGCP_Emulation_CT.create(id);
239 map(vc_MGCP:MGCP, system:MGCP_CODEC_PT);
240 vc_MGCP.start(MGCP_Emulation.main(ops, pars, id));
241}
242
Philipp Maierc09a1312019-04-09 16:05:26 +0200243function ForwardUnitdataCallback(PDU_SGsAP msg)
244runs on SGsAP_Emulation_CT return template PDU_SGsAP {
245 SGsAP_CLIENT.send(msg);
246 return omit;
247}
248
Harald Welte4263c522018-12-06 11:56:27 +0100249function f_init_sgsap(charstring id) runs on MTC_CT {
250 id := id & "-SGsAP";
251 var SGsAPOps ops := {
252 create_cb := refers(SGsAP_Emulation.ExpectedCreateCallback),
Philipp Maierc09a1312019-04-09 16:05:26 +0200253 unitdata_cb := refers(ForwardUnitdataCallback)
Harald Welte4263c522018-12-06 11:56:27 +0100254 }
255 var SGsAP_conn_parameters pars := {
256 remote_ip := mp_msc_ip,
257 remote_sctp_port := 29118,
258 local_ip := "",
259 local_sctp_port := -1
260 }
261
262 vc_SGsAP := SGsAP_Emulation_CT.create(id);
263 map(vc_SGsAP:SGsAP, system:SGsAP_CODEC_PT);
264 vc_SGsAP.start(SGsAP_Emulation.main(ops, pars, id));
265}
266
267
Harald Weltea49e36e2018-01-21 19:29:33 +0100268function f_init_gsup(charstring id) runs on MTC_CT {
269 id := id & "-GSUP";
270 var GsupOps ops := {
271 create_cb := refers(GSUP_Emulation.ExpectedCreateCallback)
272 }
273
274 vc_GSUP_IPA := IPA_Emulation_CT.create(id & "-IPA");
275 vc_GSUP := GSUP_Emulation_CT.create(id);
276
277 map(vc_GSUP_IPA:IPA_PORT, system:IPA_CODEC_PT);
278 connect(vc_GSUP:GSUP, vc_GSUP_IPA:IPA_GSUP_PORT);
279 /* we use this hack to get events like ASP_IPA_EVENT_UP */
280 connect(vc_GSUP_IPA:IPA_CTRL_PORT, self:GSUP_IPA_EVENT);
281
282 vc_GSUP.start(GSUP_Emulation.main(ops, id));
283 vc_GSUP_IPA.start(IPA_Emulation.main_server(mp_hlr_ip, mp_hlr_port));
284
285 /* wait for incoming connection to GSUP port before proceeding */
286 timer T := 10.0;
287 T.start;
288 alt {
Vadim Yanitskiy61564be2020-05-18 20:44:14 +0700289 [] GSUP_IPA_EVENT.receive(tr_ASP_IPA_EV(ASP_IPA_EVENT_UP)) { }
Harald Weltea49e36e2018-01-21 19:29:33 +0100290 [] T.timeout {
Harald Welte458fd372018-03-21 11:26:23 +0100291 setverdict(fail, "No connection to GSUP Port");
Daniel Willmannafce8662018-07-06 23:11:32 +0200292 mtc.stop
Harald Weltea49e36e2018-01-21 19:29:33 +0100293 }
294 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100295}
296
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200297function f_init(integer num_bsc := 1, boolean sgsap := false, boolean gsup := true, boolean osmux := false) runs on MTC_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +0100298
299 if (g_initialized == true) {
300 return;
301 }
302 g_initialized := true;
303
Philipp Maier75932982018-03-27 14:52:35 +0200304 if (num_bsc > NUM_BSC) {
Daniel Willmannafce8662018-07-06 23:11:32 +0200305 testcase.stop("excess number of BSC instances requested");
Philipp Maier75932982018-03-27 14:52:35 +0200306 }
307
Pau Espin Pedrol9a5b8ff2021-01-04 19:01:31 +0100308 f_ipa_ctrl_start_client(mp_msc_ip, mp_msc_ctrl_port);
Harald Welte3ca1c902018-01-24 18:51:27 +0100309
310 map(self:MSCVTY, system:MSCVTY);
311 f_vty_set_prompts(MSCVTY);
312 f_vty_transceive(MSCVTY, "enable");
Harald Welteb14c77a2018-01-25 17:25:44 +0100313
314 /* set some defaults */
315 f_vty_config(MSCVTY, "network", "authentication optional");
316 f_vty_config(MSCVTY, "msc", "assign-tmsi");
Oliver Smith1d118ff2019-07-03 10:57:35 +0200317 f_vty_config(MSCVTY, "msc", "check-imei-rqd 0");
Harald Welteb14c77a2018-01-25 17:25:44 +0100318 f_vty_config(MSCVTY, "network", "encryption a5 0");
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100319 f_vty_config(MSCVTY, "cs7 instance 0", "sccp-timer ias " & int2str(g_msc_sccp_timer_ias));
320 f_vty_config(MSCVTY, "cs7 instance 0", "sccp-timer iar " & int2str(g_msc_sccp_timer_iar));
Pau Espin Pedrol9a732a42020-09-15 15:56:33 +0200321 if (osmux) {
322 f_vty_config(MSCVTY, "msc", "osmux on");
323 } else {
324 f_vty_config(MSCVTY, "msc", "osmux off");
Pau Espin Pedrol3dd33bc2019-05-31 17:51:20 +0200325 }
Daniel Willmann08862152022-02-22 13:21:49 +0100326
327 for (var integer i := 0; i < num_bsc; i := i + 1) {
328 if (isbound(mp_bssap_cfg[i])) {
329 var RanOps ranops := BSC_RanOps;
330 ranops.use_osmux := osmux;
Eric Wild49888a62022-03-30 03:16:11 +0200331 ranops.bssap_reset_retries := mp_bssap_reset_retries;
Daniel Willmann08862152022-02-22 13:21:49 +0100332 f_ran_adapter_init(g_bssap[i], mp_bssap_cfg[i], "MSC_Test_" & int2str(i), ranops);
333 f_ran_adapter_start(g_bssap[i]);
334 } else {
335 testcase.stop("missing BSSAP configuration");
336 }
337 }
338
339 f_init_mncc("MSC_Test");
340 f_init_mgcp("MSC_Test");
341
342 if (gsup == true) {
343 f_init_gsup("MSC_Test");
344 }
345 f_init_smpp("MSC_Test");
346
347 if (sgsap == true) {
348 f_init_sgsap("MSC_Test");
349 }
350
Harald Weltef6dd64d2017-11-19 12:09:51 +0100351}
352
Philipp Maier328d1662018-03-07 10:40:27 +0100353/* Initialize for a direct connection to BSSAP. This function is an alternative
354 * to f_init() when the high level functions of the BSC_ConnectionHandler are
355 * not needed. */
356function f_init_bssap_direct() runs on MTC_CT {
Harald Welte3ca0ce12019-04-23 17:18:48 +0200357 f_ran_adapter_init(g_bssap[0], mp_bssap_cfg[0], "MSC_Test", omit);
Philipp Maier75932982018-03-27 14:52:35 +0200358 connect(g_bssap[0].vc_SCCP:SCCP_SP_PORT, self:BSSAP_DIRECT);
Philipp Maier328d1662018-03-07 10:40:27 +0100359
360 /* Start guard timer and activate it as default */
361 Tguard_direct.start
362 activate(as_Tguard_direct());
363}
364
Harald Weltea49e36e2018-01-21 19:29:33 +0100365type function void_fn(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100366
Harald Weltea49e36e2018-01-21 19:29:33 +0100367/* FIXME: move into BSC_ConnectionHandler? */
Harald Welte9b751a62019-04-14 17:39:29 +0200368function f_init_pars(integer imsi_suffix, boolean sgsap := false, boolean gsup := true, integer ran_idx := 0,
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200369 boolean ran_is_geran := true, boolean use_osmux := false, OCT4 gsup_sid := '20000101'O,
370 boolean verify_cell_id := true)
Harald Weltef9abf8d2019-04-21 13:07:17 +0200371runs on MTC_CT return BSC_ConnHdlrPars {
Harald Weltede371492018-01-27 23:44:41 +0100372 var BSC_ConnHdlrNetworkPars net_pars := {
373 kc_support := '0A'O, /* A5/1 and A5/3 enabled */
Neels Hofmeyre860fc42022-10-05 01:15:54 +0200374 net_config := { "authentication optional", "encryption a5 0" },
375 expect_attach_success := true,
Harald Weltede371492018-01-27 23:44:41 +0100376 expect_tmsi := true,
Neels Hofmeyre860fc42022-10-05 01:15:54 +0200377 expect_auth_attempt := false,
378 hlr_has_auth_info := true,
Harald Weltede371492018-01-27 23:44:41 +0100379 expect_auth := false,
Oliver Smith1d118ff2019-07-03 10:57:35 +0200380 expect_ciph := false,
381 expect_imei := false,
382 expect_imei_early := false,
383 check_imei_result := OSMO_GSUP_IMEI_RESULT_ACK,
384 check_imei_error := false
Harald Weltede371492018-01-27 23:44:41 +0100385 };
Harald Weltea49e36e2018-01-21 19:29:33 +0100386 var BSC_ConnHdlrPars pars := {
Harald Weltef9abf8d2019-04-21 13:07:17 +0200387 sccp_addr_own := g_bssap[ran_idx].sccp_addr_own,
388 sccp_addr_peer := g_bssap[ran_idx].sccp_addr_peer,
Harald Welteedbab812018-03-18 16:02:25 +0100389 cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42)),
Harald Welte81b7f9d2018-01-24 19:06:24 +0100390 imei := f_gen_imei(imsi_suffix),
391 imsi := f_gen_imsi(imsi_suffix),
392 msisdn := f_gen_msisdn(imsi_suffix),
Harald Welte256571e2018-01-24 18:47:19 +0100393 tmsi := omit,
Harald Welte9de84792018-01-28 01:06:35 +0100394 cm1 := valueof(ts_CM1),
Harald Welte82600572018-01-21 20:54:08 +0100395 cm2 := valueof(ts_CM2_default),
Harald Welte16114282018-01-24 22:41:21 +0100396 cm3 := omit,
Harald Weltede371492018-01-27 23:44:41 +0100397 vec := omit,
Neels Hofmeyrb00c5b02021-06-23 20:05:25 +0200398 vec_keep := false,
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100399 net := net_pars,
Philipp Maieraeb29a82018-11-08 17:40:53 +0100400 send_early_cm := true,
401 ipa_ctrl_ip := mp_msc_ip,
402 ipa_ctrl_port := mp_msc_ctrl_port,
Philipp Maier9b690e42018-12-21 11:50:03 +0100403 ipa_ctrl_enable := true,
Philipp Maier57865482019-01-07 18:33:13 +0100404 mm_info := mp_mm_info,
Philipp Maierc09a1312019-04-09 16:05:26 +0200405 sgsap_enable := sgsap,
Harald Weltef9abf8d2019-04-21 13:07:17 +0200406 gsup_enable := gsup,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +0100407 gsup_sid := gsup_sid,
Harald Weltec1f937a2019-04-21 21:19:23 +0200408 ran_idx := ran_idx,
Harald Welte9b751a62019-04-14 17:39:29 +0200409 use_umts_aka := false,
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200410 ran_is_geran := ran_is_geran,
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200411 use_osmux := use_osmux,
Pau Espin Pedrol833174e2020-09-03 16:46:02 +0200412 use_ipv6 := false,
Pau Espin Pedrole979c402021-04-28 17:29:54 +0200413 verify_cell_id := verify_cell_id,
414 common_id_last_eutran_plmn := omit
Harald Weltea49e36e2018-01-21 19:29:33 +0100415 };
Harald Weltee13cfb22019-04-23 16:52:02 +0200416 if (not ran_is_geran) {
417 pars.use_umts_aka := true;
418 pars.net.expect_auth := true;
419 }
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100420 return pars;
421}
422
Neels Hofmeyre1a1b632021-07-28 18:05:43 +0200423function f_start_handler_create(BSC_ConnHdlrPars pars) runs on MTC_CT return BSC_ConnHdlr {
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100424 var BSC_ConnHdlr vc_conn;
Neels Hofmeyr60122f82021-07-28 17:59:38 +0200425 var charstring id := testcasename() & int2str(pars.ran_idx);
Harald Weltea49e36e2018-01-21 19:29:33 +0100426
427 vc_conn := BSC_ConnHdlr.create(id);
Neels Hofmeyr60122f82021-07-28 17:59:38 +0200428
Harald Weltea49e36e2018-01-21 19:29:33 +0100429 /* BSSMAP part / A interface */
Neels Hofmeyr60122f82021-07-28 17:59:38 +0200430 connect(vc_conn:BSSAP, g_bssap[pars.ran_idx].vc_RAN:CLIENT);
431 connect(vc_conn:BSSAP_PROC, g_bssap[pars.ran_idx].vc_RAN:PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100432 /* MNCC part */
433 connect(vc_conn:MNCC, vc_MNCC:MNCC_CLIENT);
434 connect(vc_conn:MNCC_PROC, vc_MNCC:MNCC_PROC);
Harald Welte4aa970c2018-01-26 10:38:09 +0100435 /* MGCP part */
436 connect(vc_conn:MGCP, vc_MGCP:MGCP_CLIENT);
437 connect(vc_conn:MGCP_PROC, vc_MGCP:MGCP_PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100438 /* GSUP part */
Philipp Maierc09a1312019-04-09 16:05:26 +0200439 if (pars.gsup_enable == true) {
440 connect(vc_conn:GSUP, vc_GSUP:GSUP_CLIENT);
441 connect(vc_conn:GSUP_PROC, vc_GSUP:GSUP_PROC);
442 }
Harald Weltef640a012018-04-14 17:49:21 +0200443 /* SMPP part */
444 connect(vc_conn:SMPP, vc_SMPP:SMPP_CLIENT);
445 connect(vc_conn:SMPP_PROC, vc_SMPP:SMPP_PROC);
Harald Welte4263c522018-12-06 11:56:27 +0100446 /* SGs part */
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100447 if (pars.sgsap_enable == true) {
Philipp Maier57865482019-01-07 18:33:13 +0100448 connect(vc_conn:SGsAP, vc_SGsAP:SGsAP_CLIENT);
449 connect(vc_conn:SGsAP_PROC, vc_SGsAP:SGsAP_PROC);
450 }
Neels Hofmeyre1a1b632021-07-28 18:05:43 +0200451 return vc_conn;
452}
Harald Weltea49e36e2018-01-21 19:29:33 +0100453
Neels Hofmeyre1a1b632021-07-28 18:05:43 +0200454function f_start_handler_run(BSC_ConnHdlr vc_conn, void_fn fn, BSC_ConnHdlrPars pars) runs on MTC_CT {
455 var charstring id := testcasename() & int2str(pars.ran_idx);
Harald Weltea10db902018-01-27 12:44:49 +0100456 /* We cannot use vc_conn.start(f_init_handler(fn, id, pars)); as we cannot have
457 * a stand-alone 'derefers()' call, see https://www.eclipse.org/forums/index.php/t/1091364/ */
Harald Weltea49e36e2018-01-21 19:29:33 +0100458 vc_conn.start(derefers(fn)(id, pars));
Neels Hofmeyre1a1b632021-07-28 18:05:43 +0200459}
460
461function f_start_handler_with_pars(void_fn fn, BSC_ConnHdlrPars pars) runs on MTC_CT return BSC_ConnHdlr {
462 var BSC_ConnHdlr vc_conn;
463 vc_conn := f_start_handler_create(pars);
464 f_start_handler_run(vc_conn, fn, pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100465 return vc_conn;
466}
467
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200468function f_start_handler(void_fn fn, integer imsi_suffix, integer ran_idx := 0, boolean ran_is_geran := true, boolean use_osmux := false,
469 boolean verify_cell_id := true)
Harald Welte9b751a62019-04-14 17:39:29 +0200470runs on MTC_CT return BSC_ConnHdlr {
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200471 return f_start_handler_with_pars(fn, f_init_pars(imsi_suffix, ran_idx := ran_idx, ran_is_geran := ran_is_geran, use_osmux := use_osmux, verify_cell_id := verify_cell_id));
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100472}
473
Harald Weltea49e36e2018-01-21 19:29:33 +0100474private function f_tc_lu_imsi_noauth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100475 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100476 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100477}
Harald Weltea49e36e2018-01-21 19:29:33 +0100478testcase TC_lu_imsi_noauth_tmsi() runs on MTC_CT {
479 var BSC_ConnHdlr vc_conn;
480 f_init();
481
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100482 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi), 1);
Harald Weltea49e36e2018-01-21 19:29:33 +0100483 vc_conn.done;
484}
485
486private function f_tc_lu_imsi_noauth_notmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100487 pars.net.expect_tmsi := false;
Harald Weltea10db902018-01-27 12:44:49 +0100488 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100489 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100490}
Harald Weltea49e36e2018-01-21 19:29:33 +0100491testcase TC_lu_imsi_noauth_notmsi() runs on MTC_CT {
492 var BSC_ConnHdlr vc_conn;
493 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100494 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
Harald Weltea49e36e2018-01-21 19:29:33 +0100495
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100496 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi), 2);
Harald Weltea49e36e2018-01-21 19:29:33 +0100497 vc_conn.done;
498}
499
500/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
Harald Weltee13cfb22019-04-23 16:52:02 +0200501friend function f_tc_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100502 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100503 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
504
505 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +0200506 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyrd076c522019-11-28 01:00:52 +0100507 f_mm_common();
Harald Weltea49e36e2018-01-21 19:29:33 +0100508 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
509 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
510 alt {
Harald Welte5946b332018-03-18 23:32:21 +0100511 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej(int2oct(23,1)))) {
512 f_expect_clear();
513 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100514 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
515 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200516 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100517 }
518 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100519}
520testcase TC_lu_imsi_reject() runs on MTC_CT {
521 var BSC_ConnHdlr vc_conn;
522 f_init();
523
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200524 vc_conn := f_start_handler(refers(f_tc_lu_imsi_reject), 3, verify_cell_id := false);
Harald Weltea49e36e2018-01-21 19:29:33 +0100525 vc_conn.done;
526}
527
Harald Weltee13cfb22019-04-23 16:52:02 +0200528
529
Harald Weltea49e36e2018-01-21 19:29:33 +0100530/* Do LU by IMSI, timeout on GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +0200531friend function f_tc_lu_imsi_timeout_gsup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100532 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100533 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
534
535 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +0200536 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyrd076c522019-11-28 01:00:52 +0100537 f_mm_common();
Harald Weltea49e36e2018-01-21 19:29:33 +0100538 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
539 /* Normally the HLR would need to respond here, but we decide to force a timeout here */
540 alt {
541 /* FIXME: Expect specific reject cause */
Harald Welte5946b332018-03-18 23:32:21 +0100542 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
543 f_expect_clear();
544 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100545 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
546 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200547 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100548 }
549 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100550}
551testcase TC_lu_imsi_timeout_gsup() runs on MTC_CT {
552 var BSC_ConnHdlr vc_conn;
553 f_init();
554
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200555 vc_conn := f_start_handler(refers(f_tc_lu_imsi_timeout_gsup), 4, verify_cell_id := false);
Harald Weltea49e36e2018-01-21 19:29:33 +0100556 vc_conn.done;
557}
558
Harald Weltee13cfb22019-04-23 16:52:02 +0200559
Harald Welte7b1b2812018-01-22 21:23:06 +0100560private function f_tc_lu_imsi_auth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100561 pars.net.expect_auth := true;
Harald Weltea10db902018-01-27 12:44:49 +0100562 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100563 f_perform_lu();
Harald Welte7b1b2812018-01-22 21:23:06 +0100564}
565testcase TC_lu_imsi_auth_tmsi() runs on MTC_CT {
566 var BSC_ConnHdlr vc_conn;
567 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100568 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte7b1b2812018-01-22 21:23:06 +0100569
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100570 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi), 5);
Harald Welte7b1b2812018-01-22 21:23:06 +0100571 vc_conn.done;
572}
573
Harald Weltee13cfb22019-04-23 16:52:02 +0200574
575friend function f_tc_lu_imsi_auth3g_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte8a397ae2019-04-21 22:03:37 +0200576 pars.net.expect_auth := true;
577 pars.use_umts_aka := true;
578 f_init_handler(pars);
579 f_perform_lu();
580}
581testcase TC_lu_imsi_auth3g_tmsi() runs on MTC_CT {
582 var BSC_ConnHdlr vc_conn;
583 f_init();
584 f_vty_config(MSCVTY, "network", "authentication required");
585
586 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi), 1005);
587 vc_conn.done;
588}
Harald Weltea49e36e2018-01-21 19:29:33 +0100589
Pau Espin Pedrold3d54a92019-12-17 17:02:54 +0100590/* Proceed with LU but never receive an TMSI Realloc from MS after LU Accept (OS#4337).
591 * TS 24.008 sec 4.3.1.5 states MSC should simply release all MM connections.
592 */
593friend function f_tc_lu_imsi_timeout_tmsi_realloc(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
594
595 f_init_handler(pars);
596
597 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
598 var PDU_DTAP_MT dtap_mt;
599
600 /* tell GSUP dispatcher to send this IMSI to us */
601 f_create_gsup_expect(hex2str(g_pars.imsi));
602
603 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
604 if (g_pars.ran_is_geran) {
605 f_bssap_compl_l3(l3_lu);
606 if (g_pars.send_early_cm) {
607 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
608 }
609 } else {
610 f_ranap_initial_ue(l3_lu);
611 }
612
613 f_mm_imei_early();
614 f_mm_common();
615 f_msc_lu_hlr();
616 f_mm_imei();
617
618 alt {
619 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) -> value dtap_mt {}
620 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
621 setverdict(fail, "Expected LU ACK, but received LU REJ");
622 mtc.stop;
623 }
624 }
625
626 /* currently (due to bug OS#4337), an extra LU reject is received before
627 terminating the connection. Enabling following line makes the test
628 pass: */
629 //f_expect_lu_reject('16'O); /* Cause: congestion */
630
631 /* f_expect_lu_reject() already waits for T"-1" (X1, 5 seconds), but give some
632 extra time to avoid race conditons... */
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200633 f_expect_clear(7.0, verify_vlr_cell_id := false);
Pau Espin Pedrold3d54a92019-12-17 17:02:54 +0100634
635 setverdict(pass);
636}
637testcase TC_lu_imsi_timeout_tmsi_realloc() runs on MTC_CT {
638 var BSC_ConnHdlr vc_conn;
639 f_init();
640
641 vc_conn := f_start_handler(refers(f_tc_lu_imsi_timeout_tmsi_realloc), 5);
642 vc_conn.done;
643}
644
Harald Weltee13cfb22019-04-23 16:52:02 +0200645
Harald Weltea49e36e2018-01-21 19:29:33 +0100646/* Send CM SERVICE REQ for IMSI that has never performed LU before */
Harald Weltee13cfb22019-04-23 16:52:02 +0200647friend function f_tc_cmserv_imsi_unknown(charstring id, BSC_ConnHdlrPars pars)
Harald Weltea49e36e2018-01-21 19:29:33 +0100648runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100649 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100650
651 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welteedbab812018-03-18 16:02:25 +0100652 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
Harald Welte6ed6bf92018-01-24 21:09:15 +0100653 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
Harald Weltea49e36e2018-01-21 19:29:33 +0100654
655 f_create_gsup_expect(hex2str(g_pars.imsi));
656
657 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200658 f_cl3_or_initial_ue(l3_info);
Harald Welteb7817992019-05-09 13:15:39 +0200659 f_mm_auth();
Harald Weltea49e36e2018-01-21 19:29:33 +0100660
661 timer T := 10.0;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100662 T.start;
663 alt {
Harald Weltea49e36e2018-01-21 19:29:33 +0100664 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
665 //[] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_ACC)) { }
Daniel Willmannafce8662018-07-06 23:11:32 +0200666 [] BSSAP.receive {
667 setverdict(fail, "Received unexpected BSSAP");
668 mtc.stop;
669 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100670 [] GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi)) {
671 setverdict(fail, "Unexpected GSUP UL REQ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200672 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100673 }
Daniel Willmannafce8662018-07-06 23:11:32 +0200674 [] T.timeout {
Neels Hofmeyrf1c3c212020-08-19 13:15:32 +0000675 setverdict(fail, "Timeout waiting for CM SERV REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200676 mtc.stop;
677 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100678 }
679
Harald Welte1ddc7162018-01-27 14:25:46 +0100680 f_expect_clear();
Harald Weltef6dd64d2017-11-19 12:09:51 +0100681}
Harald Weltea49e36e2018-01-21 19:29:33 +0100682testcase TC_cmserv_imsi_unknown() runs on MTC_CT {
683 var BSC_ConnHdlr vc_conn;
684 f_init();
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200685 vc_conn := f_start_handler(refers(f_tc_cmserv_imsi_unknown), 6, verify_cell_id := false);
Harald Weltea49e36e2018-01-21 19:29:33 +0100686 vc_conn.done;
687}
688
Harald Weltee13cfb22019-04-23 16:52:02 +0200689
Neels Hofmeyr13737fb2020-08-19 13:16:14 +0000690/* Send CM SERVICE REQ for TMSI that has never performed LU before */
691friend function f_tc_cmserv_tmsi_unknown(charstring id, BSC_ConnHdlrPars pars)
692runs on BSC_ConnHdlr {
693 f_init_handler(pars);
694
695 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV('57111111'O));
696 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
697 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
698
699 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
700 f_cl3_or_initial_ue(l3_info);
701 f_mm_auth();
702
703 timer T := 10.0;
704 T.start;
705 alt {
706 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
707 [] BSSAP.receive {
708 setverdict(fail, "Received unexpected BSSAP");
709 mtc.stop;
710 }
711 [] T.timeout {
712 setverdict(fail, "Timeout waiting for CM SERV REJ");
713 mtc.stop;
714 }
715 }
716
717 f_expect_clear();
718}
719testcase TC_cmserv_tmsi_unknown() runs on MTC_CT {
720 var BSC_ConnHdlr vc_conn;
721 f_init();
722 vc_conn := f_start_handler(refers(f_tc_cmserv_tmsi_unknown), 57, verify_cell_id := false);
723 vc_conn.done;
724}
725
Neels Hofmeyr14d0b132020-08-19 13:49:05 +0000726/* Send Paging Response for IMSI that has never performed LU before */
727friend function f_tc_paging_response_imsi_unknown(charstring id, BSC_ConnHdlrPars pars)
728runs on BSC_ConnHdlr {
729 f_init_handler(pars);
730
731 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
732 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
733 var PDU_ML3_MS_NW l3_info := valueof(ts_PAG_RESP(mi));
734
735 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
736 f_cl3_or_initial_ue(l3_info);
737
738 /* The Paging Response gets rejected by a direct Clear Command */
739 f_expect_clear();
740}
741testcase TC_paging_response_imsi_unknown() runs on MTC_CT {
742 var BSC_ConnHdlr vc_conn;
743 f_init();
744 vc_conn := f_start_handler(refers(f_tc_paging_response_imsi_unknown), 58, verify_cell_id := false);
745 vc_conn.done;
746}
747
748/* Send Paging Response for TMSI that has never performed LU before */
749friend function f_tc_paging_response_tmsi_unknown(charstring id, BSC_ConnHdlrPars pars)
750runs on BSC_ConnHdlr {
751 f_init_handler(pars);
752
753 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV('59111111'O));
754 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
755 var PDU_ML3_MS_NW l3_info := valueof(ts_PAG_RESP(mi));
756
757 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
758 f_cl3_or_initial_ue(l3_info);
759
760 /* The Paging Response gets rejected by a direct Clear Command */
761 f_expect_clear();
762}
763testcase TC_paging_response_tmsi_unknown() runs on MTC_CT {
764 var BSC_ConnHdlr vc_conn;
765 f_init();
766 vc_conn := f_start_handler(refers(f_tc_paging_response_tmsi_unknown), 59, verify_cell_id := false);
767 vc_conn.done;
768}
769
Neels Hofmeyr13737fb2020-08-19 13:16:14 +0000770
Harald Weltee13cfb22019-04-23 16:52:02 +0200771friend function f_tc_lu_and_mo_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100772 f_init_handler(pars);
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +0200773 var CallParameters cpars := valueof(t_CallParams);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100774 f_perform_lu();
Harald Welteb71901a2018-01-26 19:16:05 +0100775 f_mo_call(cpars);
Harald Welte2bb825f2018-01-22 11:31:18 +0100776}
777testcase TC_lu_and_mo_call() runs on MTC_CT {
778 var BSC_ConnHdlr vc_conn;
779 f_init();
780
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100781 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_call), 7);
Harald Welte071ed732018-01-23 19:53:52 +0100782 vc_conn.done;
783}
Pau Espin Pedrol833174e2020-09-03 16:46:02 +0200784friend function f_tc_lu_and_mo_call_ipv6(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
785 f_init_handler(pars);
786 var CallParameters cpars := valueof(t_CallParams);
787 cpars.mgw_conn_1.mgw_rtp_ip := "::1";
788 cpars.mgw_conn_2.mgw_rtp_ip := "::2";
789 cpars.bss_rtp_ip := "::3";
790 f_perform_lu();
791 f_mo_call(cpars);
792}
793testcase TC_lu_and_mo_call_ipv6() runs on MTC_CT {
794 var BSC_ConnHdlr vc_conn;
795 f_init();
796
797 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_call_ipv6), 7);
798 vc_conn.done;
799}
Harald Welte071ed732018-01-23 19:53:52 +0100800
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100801/* Verify T(iar) triggers and releases the channel */
802friend function f_lu_and_mo_call_sccp_tiar_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
803 timer T_wait_iar := int2float(5 + 1); /* g_msc_sccp_timer_iar + Give extra time (+1 sec) */
804 f_init_handler(pars);
805 var CallParameters cpars := valueof(t_CallParams);
806 f_perform_lu();
807 f_mo_call_establish(cpars);
808
809 /* Expect the channel cleared upon T(iar) triggered: */
810 T_wait_iar.start;
811 alt {
812 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {
813 T_wait_iar.stop
814 setverdict(pass);
815 }
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100816 [] T_wait_iar.timeout {
817 setverdict(fail, "Timeout waiting for T(iar) triggered SCCP RSLD");
818 mtc.stop;
819 }
820 }
Harald Welte4a3fa712020-08-19 08:57:33 +0200821 /* DLCX for both directions; if we don't do this, we might receive either of the two during
822 * shutdown causing race conditions */
823 MGCP.receive(tr_DLCX(?));
824 MGCP.receive(tr_DLCX(?));
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100825
826 setverdict(pass);
827}
828testcase TC_lu_and_mo_call_sccp_tiar_timeout() runs on MTC_CT {
829 var BSC_ConnHdlr vc_conn;
830
831 /* Set T(iar) in MSC low enough that it will trigger before other side
832 has time to keep alive with a T(ias). Keep recommended ratio of
833 T(iar) >= T(ias)*2 */
834 g_msc_sccp_timer_ias := 2;
835 g_msc_sccp_timer_iar := 5;
836
837 f_init();
838
839 vc_conn := f_start_handler(refers(f_lu_and_mo_call_sccp_tiar_timeout), 89);
840 vc_conn.done;
841}
842
Harald Weltee13cfb22019-04-23 16:52:02 +0200843
Harald Welte071ed732018-01-23 19:53:52 +0100844/* Test LU (with authentication enabled), where HLR times out sending SAI response */
Harald Weltee13cfb22019-04-23 16:52:02 +0200845friend function f_tc_lu_auth_sai_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100846 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100847
848 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
849 var PDU_DTAP_MT dtap_mt;
850
851 /* tell GSUP dispatcher to send this IMSI to us */
852 f_create_gsup_expect(hex2str(g_pars.imsi));
853
854 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200855 f_cl3_or_initial_ue(l3_lu);
Harald Welte071ed732018-01-23 19:53:52 +0100856
857 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200858 if (pars.ran_is_geran) {
859 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
860 }
Harald Welte071ed732018-01-23 19:53:52 +0100861
862 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
863 /* The HLR would normally return an auth vector here, but we fail to do so. */
864
865 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100866 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100867}
868testcase TC_lu_auth_sai_timeout() runs on MTC_CT {
869 var BSC_ConnHdlr vc_conn;
870 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100871 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100872
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200873 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_timeout), 8, verify_cell_id := false);
Harald Welte071ed732018-01-23 19:53:52 +0100874 vc_conn.done;
875}
876
Harald Weltee13cfb22019-04-23 16:52:02 +0200877
Harald Welte071ed732018-01-23 19:53:52 +0100878/* Test LU (with authentication enabled), where HLR rejects sending SAI error */
Harald Weltee13cfb22019-04-23 16:52:02 +0200879friend function f_tc_lu_auth_sai_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100880 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100881
882 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
883 var PDU_DTAP_MT dtap_mt;
884
885 /* tell GSUP dispatcher to send this IMSI to us */
886 f_create_gsup_expect(hex2str(g_pars.imsi));
887
888 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200889 f_cl3_or_initial_ue(l3_lu);
Harald Welte071ed732018-01-23 19:53:52 +0100890
891 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200892 if (pars.ran_is_geran) {
893 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
894 }
Harald Welte071ed732018-01-23 19:53:52 +0100895
896 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
897 GSUP.send(ts_GSUP_SAI_ERR(g_pars.imsi, 13));
898
899 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100900 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100901}
902testcase TC_lu_auth_sai_err() runs on MTC_CT {
903 var BSC_ConnHdlr vc_conn;
904 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100905 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100906
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200907 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_err), 9, verify_cell_id := false);
Harald Welte2bb825f2018-01-22 11:31:18 +0100908 vc_conn.done;
909}
Harald Weltea49e36e2018-01-21 19:29:33 +0100910
Harald Weltee13cfb22019-04-23 16:52:02 +0200911
Harald Weltebc881782018-01-23 20:09:15 +0100912/* Test LU but BSC will send a clear request in the middle */
913private function f_tc_lu_clear_request(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100914 f_init_handler(pars);
Harald Weltebc881782018-01-23 20:09:15 +0100915
916 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
917 var PDU_DTAP_MT dtap_mt;
918
919 /* tell GSUP dispatcher to send this IMSI to us */
920 f_create_gsup_expect(hex2str(g_pars.imsi));
921
922 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200923 f_cl3_or_initial_ue(l3_lu);
Harald Welte79f1e452020-08-18 22:55:02 +0200924 f_expect_common_id();
Harald Weltebc881782018-01-23 20:09:15 +0100925
926 /* Send Early Classmark, just for the fun of it */
927 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
928
929 f_sleep(1.0);
930 /* send clear request in the middle of the LU */
931 BSSAP.send(ts_BSSMAP_ClearRequest(0));
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200932 alt {
933 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { repeat; }
934 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {}
935 }
Harald Weltebc881782018-01-23 20:09:15 +0100936 BSSAP.send(ts_BSSMAP_ClearComplete);
Harald Welte89a32492018-01-27 19:07:28 +0100937 alt {
938 /* See https://osmocom.org/issues/2862 */
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200939 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {
940 setverdict(fail, "Got a second Clear Command, only one expected");
Daniel Willmannafce8662018-07-06 23:11:32 +0200941 mtc.stop;
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200942 repeat;
943 }
Harald Welte6811d102019-04-14 22:23:14 +0200944 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte89a32492018-01-27 19:07:28 +0100945 }
Harald Weltebc881782018-01-23 20:09:15 +0100946 setverdict(pass);
947}
948testcase TC_lu_clear_request() runs on MTC_CT {
949 var BSC_ConnHdlr vc_conn;
950 f_init();
951
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100952 vc_conn := f_start_handler(refers(f_tc_lu_clear_request), 10);
Harald Weltebc881782018-01-23 20:09:15 +0100953 vc_conn.done;
954}
955
Vadim Yanitskiy109e7552021-02-05 05:36:02 +0100956/* Test reaction on Clear Request during a MO Call */
957friend function f_TC_mo_mt_call_clear_request(charstring id, BSC_ConnHdlrPars pars)
958runs on BSC_ConnHdlr {
959 var CallParameters cpars := valueof(t_CallParams);
960 var MNCC_PDU mncc_pdu;
961 timer T := 2.0;
962
963 f_init_handler(pars);
964
965 f_perform_lu();
966
967 /* HACK: reducing code duplication ('66'H - MO, '68'H - MT) */
968 if (pars.imsi == '262420002532766'H)
969 { f_mo_call_establish(cpars); }
970 else
971 { f_mt_call_establish(cpars); }
972
973 /* Hold the line for a while... */
974 f_sleep(2.0);
975
976 /* BSC sends BSSMAP Clear Request (e.g. due to RR failure) */
977 BSSAP.send(ts_BSSMAP_ClearRequest(1));
978
979 /* Expect (optional) CC RELEASE and Clear Command */
980 var default ccrel := activate(as_optional_cc_rel(cpars));
981 f_expect_clear();
982 deactivate(ccrel);
983
984 /* Expect RELease indication on the MNCC socket */
985 T.start;
986 alt {
987 [] MNCC.receive(tr_MNCC_REL_ind(cpars.mncc_callref)) -> value mncc_pdu {
988 log("Rx MNCC REL.ind, cause := ", mncc_pdu.u.signal.cause);
989 setverdict(pass);
990 }
991 [] MNCC.receive(MNCC_PDU:?) -> value mncc_pdu {
992 setverdict(fail, "Rx unexpected MNCC PDU: ", mncc_pdu);
993 }
994 [] T.timeout {
995 setverdict(fail, "Timeout waiting for MNCC REL.ind");
996 }
997 }
998}
999testcase TC_mo_call_clear_request() runs on MTC_CT {
1000 var BSC_ConnHdlr vc_conn;
1001
1002 f_init();
1003
1004 vc_conn := f_start_handler(refers(f_TC_mo_mt_call_clear_request), 2532766); // '66'H - MO
1005 vc_conn.done;
1006}
1007testcase TC_mt_call_clear_request() runs on MTC_CT {
1008 var BSC_ConnHdlr vc_conn;
1009
1010 f_init();
1011
1012 vc_conn := f_start_handler(refers(f_TC_mo_mt_call_clear_request), 2532768); // '68'H - MT
1013 vc_conn.done;
1014}
1015
Harald Welte66af9e62018-01-24 17:28:21 +01001016/* Test LU but BSC will send a clear request in the middle */
Harald Weltee13cfb22019-04-23 16:52:02 +02001017friend function f_tc_lu_disconnect(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001018 f_init_handler(pars);
Harald Welte66af9e62018-01-24 17:28:21 +01001019
1020 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
1021 var PDU_DTAP_MT dtap_mt;
1022
1023 /* tell GSUP dispatcher to send this IMSI to us */
1024 f_create_gsup_expect(hex2str(g_pars.imsi));
1025
1026 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001027 f_cl3_or_initial_ue(l3_lu);
Harald Welte66af9e62018-01-24 17:28:21 +01001028
1029 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +02001030 if (pars.ran_is_geran) {
1031 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1032 }
Harald Welte66af9e62018-01-24 17:28:21 +01001033
1034 f_sleep(1.0);
1035 /* send clear request in the middle of the LU */
Harald Welte6811d102019-04-14 22:23:14 +02001036 BSSAP.send(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_REQ);
Harald Welte66af9e62018-01-24 17:28:21 +01001037 setverdict(pass);
Neels Hofmeyrbb825c92019-03-06 15:35:50 +01001038 f_sleep(1.0);
Harald Welte66af9e62018-01-24 17:28:21 +01001039}
1040testcase TC_lu_disconnect() runs on MTC_CT {
1041 var BSC_ConnHdlr vc_conn;
1042 f_init();
1043
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001044 vc_conn := f_start_handler(refers(f_tc_lu_disconnect), 11);
Harald Welte66af9e62018-01-24 17:28:21 +01001045 vc_conn.done;
1046}
1047
Harald Welteba7b6d92018-01-23 21:32:34 +01001048/* Test LU but with illegal mobile identity type = IMEI */
Harald Weltee13cfb22019-04-23 16:52:02 +02001049friend function f_tc_lu_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001050 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +01001051
Harald Welte256571e2018-01-24 18:47:19 +01001052 var PDU_ML3_MS_NW l3_lu := f_build_lu_imei(g_pars.imei)
Harald Welteba7b6d92018-01-23 21:32:34 +01001053 var PDU_DTAP_MT dtap_mt;
1054
1055 /* tell GSUP dispatcher to send this IMSI to us */
1056 f_create_gsup_expect(hex2str(g_pars.imsi));
1057
1058 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001059 f_cl3_or_initial_ue(l3_lu);
Harald Welteba7b6d92018-01-23 21:32:34 +01001060
1061 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +02001062 if (pars.ran_is_geran) {
1063 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1064 }
Harald Welteba7b6d92018-01-23 21:32:34 +01001065 /* wait for LU reject, ignore any ID REQ */
1066 alt {
1067 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { }
1068 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req)) { repeat; }
1069 }
1070 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001071 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +01001072}
1073testcase TC_lu_by_imei() runs on MTC_CT {
1074 var BSC_ConnHdlr vc_conn;
1075 f_init();
1076
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001077 vc_conn := f_start_handler(refers(f_tc_lu_by_imei), 12, verify_cell_id := false);
Harald Welteba7b6d92018-01-23 21:32:34 +01001078 vc_conn.done;
1079}
1080
Harald Weltee13cfb22019-04-23 16:52:02 +02001081
Harald Welteba7b6d92018-01-23 21:32:34 +01001082/* Test LU by TMSI with unknown TMSI, expect (and answer) ID REQ. */
1083private function f_tc_lu_tmsi_noauth_unknown(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Stefan Sperling04fc4bc2018-06-25 17:44:57 +02001084 /* We piggyback a test for an MSC crash on overlong IMSI (OS#2864) onto this test. */
1085 var hexstring overlong_imsi := '012345789ABCDEF0123456789ABCDEF'H;
Harald Weltea10db902018-01-27 12:44:49 +01001086 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +01001087
1088 var PDU_ML3_MS_NW l3_lu := f_build_lu_tmsi('01020304'O); /* FIXME: Random */
1089 var PDU_DTAP_MT dtap_mt;
1090
1091 /* tell GSUP dispatcher to send this IMSI to us */
1092 f_create_gsup_expect(hex2str(g_pars.imsi));
1093
1094 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001095 f_cl3_or_initial_ue(l3_lu);
Harald Welteba7b6d92018-01-23 21:32:34 +01001096
1097 /* Send Early Classmark, just for the fun of it */
1098 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1099
1100 /* Wait for + respond to ID REQ (IMSI) */
Oliver Smith32898452019-07-09 12:32:35 +02001101 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
Stefan Sperling04fc4bc2018-06-25 17:44:57 +02001102 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(overlong_imsi))); /* test for OS#2864 */
Harald Welteba7b6d92018-01-23 21:32:34 +01001103 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(g_pars.imsi)));
Harald Welte79f1e452020-08-18 22:55:02 +02001104 f_expect_common_id();
Harald Welteba7b6d92018-01-23 21:32:34 +01001105
1106 /* Expect MSC to do UpdateLocation to HLR; respond to it */
1107 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
1108 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
1109 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
1110 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
1111
1112 alt {
Harald Welte7ec4fa82018-01-27 10:57:40 +01001113 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
1114 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_TmsiRealloc_Cmpl));
1115 }
Harald Welteba7b6d92018-01-23 21:32:34 +01001116 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1117 setverdict(fail, "Expected LU ACK, but received REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +02001118 mtc.stop;
Harald Welteba7b6d92018-01-23 21:32:34 +01001119 }
1120 }
1121
Philipp Maier9b690e42018-12-21 11:50:03 +01001122 /* Wait for MM-Information (if enabled) */
1123 f_expect_mm_info();
1124
Harald Welteba7b6d92018-01-23 21:32:34 +01001125 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001126 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +01001127}
1128testcase TC_lu_by_tmsi_noauth_unknown() runs on MTC_CT {
1129 var BSC_ConnHdlr vc_conn;
1130 f_init();
1131
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001132 vc_conn := f_start_handler(refers(f_tc_lu_tmsi_noauth_unknown), 13);
Harald Welteba7b6d92018-01-23 21:32:34 +01001133 vc_conn.done;
1134}
1135
Neels Hofmeyrfc06c732020-08-19 12:52:28 +00001136/* Test LU by unknown TMSI, while the IMSI is already attached: osmo-msc should switch to the attached vlr_subscr. */
1137private function f_tc_attached_imsi_lu_unknown_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1138 f_init_handler(pars);
1139
1140 var PDU_ML3_MS_NW l3_lu := f_build_lu_tmsi('56111111'O);
1141 var PDU_DTAP_MT dtap_mt;
1142
1143 /* tell GSUP dispatcher to send this IMSI to us */
1144 f_create_gsup_expect(hex2str(g_pars.imsi));
1145
1146 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
1147 f_cl3_or_initial_ue(l3_lu);
1148
1149 /* Send Early Classmark, just for the fun of it */
1150 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1151
1152 /* Wait for + respond to ID REQ (IMSI) */
1153 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
1154 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(g_pars.imsi)));
1155 f_expect_common_id();
1156
1157 /* Expect MSC to do UpdateLocation to HLR; respond to it */
1158 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
1159 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
1160 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
1161 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
1162
1163 alt {
1164 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
1165 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_TmsiRealloc_Cmpl));
1166 }
1167 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1168 setverdict(fail, "Expected LU ACK, but received REJ");
1169 mtc.stop;
1170 }
1171 }
1172
1173 /* Wait for MM-Information (if enabled) */
1174 f_expect_mm_info();
1175
1176 /* wait for normal teardown */
Eric Wild85cc1612022-03-30 01:44:29 +02001177 f_expect_clear(verify_vlr_cell_id := false);
Neels Hofmeyrfc06c732020-08-19 12:52:28 +00001178
1179 /* Now the same IMSI is still attached in the VLR, and a LU with an unknown TMSI reveals the same IMSI only
1180 * later during ID Response. osmo-msc first creates a new vlr_subscr for the unknown TMSI, and as soon as the
1181 * IMSI becomes known, must notice that this IMSI is still regarded as attached, and must not create evil twins.
1182 */
1183
1184 /* (since the TMSI Reallocation happened, we could do this with exactly the same TMSI as above, but for test
1185 * readability just use a different one.) */
1186 l3_lu := f_build_lu_tmsi('56222222'O);
1187 f_cl3_or_initial_ue(l3_lu);
1188
1189 /* Wait for + respond to ID REQ (IMSI) */
1190 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
1191 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(g_pars.imsi)));
1192 f_expect_common_id();
1193
1194 /* Expect MSC to do UpdateLocation to HLR; respond to it */
1195 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
1196 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
1197 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
1198 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
1199
1200 alt {
1201 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
1202 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_TmsiRealloc_Cmpl));
1203 }
1204 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1205 setverdict(fail, "Expected LU ACK, but received REJ");
1206 mtc.stop;
1207 }
1208 }
1209
1210 /* Wait for MM-Information (if enabled) */
1211 f_expect_mm_info();
1212
1213 /* wait for normal teardown */
Eric Wild85cc1612022-03-30 01:44:29 +02001214 f_expect_clear(verify_vlr_cell_id := false);
Neels Hofmeyrfc06c732020-08-19 12:52:28 +00001215}
1216testcase TC_attached_imsi_lu_unknown_tmsi() runs on MTC_CT {
1217 var BSC_ConnHdlr vc_conn;
1218 f_init();
1219
1220 vc_conn := f_start_handler(refers(f_tc_attached_imsi_lu_unknown_tmsi), 56);
1221 vc_conn.done;
1222}
1223
Harald Welte4d15fa72020-08-19 08:58:28 +02001224friend function f_imsi_detach_by_imsi() runs on BSC_ConnHdlr {
Harald Welte45164da2018-01-24 12:51:27 +01001225 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1226
1227 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001228 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +01001229
1230 /* Send Early Classmark, just for the fun of it? */
Harald Welte4d15fa72020-08-19 08:58:28 +02001231 if (g_pars.ran_is_geran) {
Harald Weltee13cfb22019-04-23 16:52:02 +02001232 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1233 }
Harald Welte45164da2018-01-24 12:51:27 +01001234
1235 /* wait for normal teardown */
Harald Welte4d15fa72020-08-19 08:58:28 +02001236 f_expect_clear(verify_vlr_cell_id := false);
1237}
1238
1239
1240/* Test IMSI DETACH (MI=IMSI) */
1241friend function f_tc_imsi_detach_by_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1242 f_init_handler(pars);
1243
1244 f_imsi_detach_by_imsi();
Harald Welte45164da2018-01-24 12:51:27 +01001245}
1246testcase TC_imsi_detach_by_imsi() runs on MTC_CT {
1247 var BSC_ConnHdlr vc_conn;
1248 f_init();
1249
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001250 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imsi), 14, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001251 vc_conn.done;
1252}
1253
Harald Weltee13cfb22019-04-23 16:52:02 +02001254
Harald Welte45164da2018-01-24 12:51:27 +01001255/* Test IMSI DETACH (MI=TMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +02001256friend function f_tc_imsi_detach_by_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001257 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001258
1259 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV('01020304'O));
1260
1261 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001262 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +01001263
1264 /* Send Early Classmark, just for the fun of it? */
Harald Weltee13cfb22019-04-23 16:52:02 +02001265 if (pars.ran_is_geran) {
1266 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1267 }
Harald Welte45164da2018-01-24 12:51:27 +01001268
1269 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001270 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001271}
1272testcase TC_imsi_detach_by_tmsi() runs on MTC_CT {
1273 var BSC_ConnHdlr vc_conn;
1274 f_init();
1275
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001276 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_tmsi), 15, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001277 vc_conn.done;
1278}
1279
Harald Weltee13cfb22019-04-23 16:52:02 +02001280
Harald Welte45164da2018-01-24 12:51:27 +01001281/* Test IMSI DETACH (MI=IMEI), which is illegal */
Harald Weltee13cfb22019-04-23 16:52:02 +02001282friend function f_tc_imsi_detach_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001283 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001284
Harald Welte256571e2018-01-24 18:47:19 +01001285 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte45164da2018-01-24 12:51:27 +01001286
1287 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001288 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +01001289
1290 /* Send Early Classmark, just for the fun of it? */
Harald Weltee13cfb22019-04-23 16:52:02 +02001291 if (pars.ran_is_geran) {
1292 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1293 }
Harald Welte45164da2018-01-24 12:51:27 +01001294
1295 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001296 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001297}
1298testcase TC_imsi_detach_by_imei() runs on MTC_CT {
1299 var BSC_ConnHdlr vc_conn;
1300 f_init();
1301
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001302 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imei), 16, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001303 vc_conn.done;
1304}
1305
1306
1307/* helper function for an emergency call. caller passes in mobile identity to use */
1308private function f_emerg_call(MobileIdentityLV mi) runs on BSC_ConnHdlr {
Harald Welte0bef21e2018-02-10 09:48:23 +01001309 var CallParameters cpars := valueof(t_CallParams('112'H, 0));
1310 cpars.emergency := true;
Harald Welte45164da2018-01-24 12:51:27 +01001311
Harald Welte0bef21e2018-02-10 09:48:23 +01001312 f_mo_call(cpars);
Harald Welte45164da2018-01-24 12:51:27 +01001313}
1314
1315/* establish an emergency call by IMEI, no SIM inserted (and hence no IMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +02001316friend function f_tc_emerg_call_imei_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001317 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001318
Harald Welte256571e2018-01-24 18:47:19 +01001319 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001320 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_EMERG_CALL, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001321 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001322 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ('05'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +01001323 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001324}
1325testcase TC_emerg_call_imei_reject() runs on MTC_CT {
1326 var BSC_ConnHdlr vc_conn;
1327 f_init();
1328
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001329 vc_conn := f_start_handler(refers(f_tc_emerg_call_imei_reject), 17, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001330 vc_conn.done;
1331}
1332
Harald Weltee13cfb22019-04-23 16:52:02 +02001333
Harald Welted5b91402018-01-24 18:48:16 +01001334/* establish an emergency call by IMSI, SIM inserted (and hence IMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +02001335friend function f_tc_emerg_call_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001336 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001337 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001338 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001339 /* Then issue emergency call identified by IMSI */
1340 f_emerg_call(valueof(ts_MI_IMSI_LV(g_pars.imsi)));
1341}
1342testcase TC_emerg_call_imsi() runs on MTC_CT {
1343 var BSC_ConnHdlr vc_conn;
1344 f_init();
1345
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001346 vc_conn := f_start_handler(refers(f_tc_emerg_call_imsi), 18);
Harald Welte45164da2018-01-24 12:51:27 +01001347 vc_conn.done;
1348}
1349
Harald Weltee13cfb22019-04-23 16:52:02 +02001350
Harald Welte45164da2018-01-24 12:51:27 +01001351/* CM Service Request for VGCS -> reject */
1352private function f_tc_cm_serv_req_vgcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001353 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001354
1355 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001356 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001357
1358 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001359 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VGCS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001360 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001361 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001362 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001363}
1364testcase TC_cm_serv_req_vgcs_reject() runs on MTC_CT {
1365 var BSC_ConnHdlr vc_conn;
1366 f_init();
1367
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001368 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vgcs_reject), 19);
Harald Welte45164da2018-01-24 12:51:27 +01001369 vc_conn.done;
1370}
1371
1372/* CM Service Request for VBS -> reject */
1373private function f_tc_cm_serv_req_vbs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001374 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001375
1376 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001377 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001378
1379 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001380 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VBS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001381 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001382 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001383 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001384}
1385testcase TC_cm_serv_req_vbs_reject() runs on MTC_CT {
1386 var BSC_ConnHdlr vc_conn;
1387 f_init();
1388
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001389 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vbs_reject), 20);
Harald Welte45164da2018-01-24 12:51:27 +01001390 vc_conn.done;
1391}
1392
1393/* CM Service Request for LCS -> reject */
1394private function f_tc_cm_serv_req_lcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001395 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001396
1397 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001398 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001399
1400 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001401 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_LCS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001402 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001403 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001404 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001405}
1406testcase TC_cm_serv_req_lcs_reject() runs on MTC_CT {
1407 var BSC_ConnHdlr vc_conn;
1408 f_init();
1409
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001410 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_lcs_reject), 21);
Harald Welte45164da2018-01-24 12:51:27 +01001411 vc_conn.done;
1412}
1413
Harald Welte0195ab12018-01-24 21:50:20 +01001414/* CM Re-Establishment Request */
1415private function f_tc_cm_reest_req_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001416 f_init_handler(pars);
Harald Welte0195ab12018-01-24 21:50:20 +01001417
1418 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001419 f_perform_lu();
Harald Welte0195ab12018-01-24 21:50:20 +01001420
1421 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1422 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_REEST_REQ(0, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001423 f_cl3_or_initial_ue(l3_info);
Neels Hofmeyr49bbb512021-07-29 22:51:08 +02001424 /* Older osmo-msc returns: GSM48_REJECT_SRV_OPT_NOT_SUPPORTED = 32,
1425 * newer osmo-msc with CM Re-Establish support returns: GSM48_REJECT_CALL_CAN_NOT_BE_IDENTIFIED = 38 */
1426 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ( (int2oct(32,1), int2oct(38,1)) )));
Harald Welte1ddc7162018-01-27 14:25:46 +01001427 f_expect_clear();
Harald Welte0195ab12018-01-24 21:50:20 +01001428}
1429testcase TC_cm_reest_req_reject() runs on MTC_CT {
1430 var BSC_ConnHdlr vc_conn;
1431 f_init();
Harald Welte0195ab12018-01-24 21:50:20 +01001432
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001433 vc_conn := f_start_handler(refers(f_tc_cm_reest_req_reject), 22);
Harald Welte0195ab12018-01-24 21:50:20 +01001434 vc_conn.done;
1435}
1436
Harald Weltec638f4d2018-01-24 22:00:36 +01001437/* Test LU (with authentication enabled), with wrong response from MS */
1438private function f_tc_lu_auth_2G_fail(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001439 f_init_handler(pars);
Harald Weltec638f4d2018-01-24 22:00:36 +01001440
1441 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
1442
1443 /* tell GSUP dispatcher to send this IMSI to us */
1444 f_create_gsup_expect(hex2str(g_pars.imsi));
1445
1446 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001447 f_cl3_or_initial_ue(l3_lu);
Harald Weltec638f4d2018-01-24 22:00:36 +01001448
1449 /* Send Early Classmark, just for the fun of it */
1450 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1451
1452 var AuthVector vec := f_gen_auth_vec_2g();
1453 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G(vec.rand, vec.sres, vec.kc));
1454 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
1455 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
1456
1457 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_AUTH_REQ(vec.rand)));
1458 /* Send back wrong auth response */
1459 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MT_MM_AUTH_RESP_2G('00000000'O)));
1460
1461 /* Expect GSUP AUTH FAIL REP to HLR */
1462 GSUP.receive(tr_GSUP_AUTH_FAIL_IND(g_pars.imsi));
1463
1464 /* Expect LU REJECT with Cause == Illegal MS */
1465 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej('03'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +01001466 f_expect_clear();
Harald Weltec638f4d2018-01-24 22:00:36 +01001467}
1468testcase TC_lu_auth_2G_fail() runs on MTC_CT {
1469 var BSC_ConnHdlr vc_conn;
1470 f_init();
1471 f_vty_config(MSCVTY, "network", "authentication required");
Harald Weltec638f4d2018-01-24 22:00:36 +01001472
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001473 vc_conn := f_start_handler(refers(f_tc_lu_auth_2G_fail), 23, verify_cell_id := false);
Harald Weltec638f4d2018-01-24 22:00:36 +01001474 vc_conn.done;
1475}
1476
Harald Weltede371492018-01-27 23:44:41 +01001477/* A5/1 + A5/3 permitted on network side, and MS capable to do it */
Harald Welte16114282018-01-24 22:41:21 +01001478private function f_tc_lu_imsi_auth_tmsi_encr_13_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +01001479 pars.net.expect_auth := true;
1480 pars.net.expect_ciph := true;
Harald Weltea10db902018-01-27 12:44:49 +01001481 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001482 f_perform_lu();
Harald Welte16114282018-01-24 22:41:21 +01001483}
1484testcase TC_lu_imsi_auth_tmsi_encr_13_13() runs on MTC_CT {
1485 var BSC_ConnHdlr vc_conn;
1486 f_init();
1487 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte16114282018-01-24 22:41:21 +01001488 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
1489
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001490 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_13), 24);
Harald Welte16114282018-01-24 22:41:21 +01001491 vc_conn.done;
1492}
1493
Harald Welte1af6ea82018-01-25 18:33:15 +01001494/* Test Complete L3 without payload */
1495private function f_tc_cl3_no_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001496 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001497
1498 /* Send Complete L3 Info with empty L3 frame */
1499 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1500 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, ''O))));
1501
Harald Weltef466eb42018-01-27 14:26:54 +01001502 timer T := 5.0;
1503 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001504 alt {
Harald Welte6811d102019-04-14 22:23:14 +02001505 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte1af6ea82018-01-25 18:33:15 +01001506 /* Expect LU REJECT with Cause == Illegal MS */
Harald Weltebdb3c452018-03-18 22:43:06 +01001507 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
Harald Welte6811d102019-04-14 22:23:14 +02001508 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001509 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001510 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001511 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001512 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001513 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001514 }
1515 setverdict(pass);
1516}
1517testcase TC_cl3_no_payload() runs on MTC_CT {
1518 var BSC_ConnHdlr vc_conn;
1519 f_init();
1520
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001521 vc_conn := f_start_handler(refers(f_tc_cl3_no_payload), 25);
Harald Welte1af6ea82018-01-25 18:33:15 +01001522 vc_conn.done;
1523}
1524
1525/* Test Complete L3 with random payload */
1526private function f_tc_cl3_rnd_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001527 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001528
Daniel Willmannaa14a382018-07-26 08:29:45 +02001529 /* length is limited by PDU_BSSAP length field which includes some
1530 * other fields beside l3info payload. So payl can only be 240 bytes
1531 * Since rnd() returns values < 1 multiply with 241
1532 */
1533 var integer len := float2int(rnd() * 241.0);
Harald Welte1af6ea82018-01-25 18:33:15 +01001534 var octetstring payl := f_rnd_octstring(len);
1535
1536 /* Send Complete L3 Info with empty L3 frame */
1537 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1538 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, payl))));
1539
Harald Weltef466eb42018-01-27 14:26:54 +01001540 timer T := 5.0;
1541 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001542 alt {
1543 /* Immediate disconnect */
Harald Welte6811d102019-04-14 22:23:14 +02001544 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte1af6ea82018-01-25 18:33:15 +01001545 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
Harald Welte6811d102019-04-14 22:23:14 +02001546 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001547 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001548 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001549 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001550 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001551 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001552 }
1553 setverdict(pass);
1554}
1555testcase TC_cl3_rnd_payload() runs on MTC_CT {
1556 var BSC_ConnHdlr vc_conn;
1557 f_init();
1558
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001559 vc_conn := f_start_handler(refers(f_tc_cl3_rnd_payload), 26);
Harald Welte1af6ea82018-01-25 18:33:15 +01001560 vc_conn.done;
1561}
1562
Harald Welte116e4332018-01-26 22:17:48 +01001563/* Test Complete L3 with random payload */
Harald Weltee13cfb22019-04-23 16:52:02 +02001564friend function f_tc_establish_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001565 f_init_handler(pars);
Harald Welte116e4332018-01-26 22:17:48 +01001566
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001567 f_perform_lu();
Harald Welte116e4332018-01-26 22:17:48 +01001568
Harald Welteb9e86fa2018-04-09 18:18:31 +02001569 f_establish_fully();
Daniel Willmann898a7e02018-05-17 12:16:16 +02001570 f_expect_clear(10.0);
Harald Welte116e4332018-01-26 22:17:48 +01001571}
1572testcase TC_establish_and_nothing() runs on MTC_CT {
1573 var BSC_ConnHdlr vc_conn;
1574 f_init();
1575
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001576 vc_conn := f_start_handler(refers(f_tc_establish_and_nothing), 27);
Harald Welte116e4332018-01-26 22:17:48 +01001577 vc_conn.done;
1578}
1579
Harald Weltee13cfb22019-04-23 16:52:02 +02001580
Harald Welte12510c52018-01-26 22:26:24 +01001581/* Test MO Call SETUP with no response from MNCC */
Harald Weltee13cfb22019-04-23 16:52:02 +02001582friend function f_tc_mo_setup_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier109e6aa2018-10-17 10:53:32 +02001583 f_init_handler(pars, 190.0);
Harald Weltea10db902018-01-27 12:44:49 +01001584
Harald Welte12510c52018-01-26 22:26:24 +01001585 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001586 cpars.mgw_conn_2.resp := 0;
1587 cpars.stop_after_cc_setup := true;
1588
1589 f_vty_config(MSCVTY, "msc", "mncc guard-timeout 20");
Harald Welte12510c52018-01-26 22:26:24 +01001590
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001591 f_perform_lu();
Harald Welte12510c52018-01-26 22:26:24 +01001592
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001593 f_mo_call_establish(cpars);
Harald Welte12510c52018-01-26 22:26:24 +01001594
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001595 var default ccrel := activate(as_optional_cc_rel(cpars));
1596
Philipp Maier109e6aa2018-10-17 10:53:32 +02001597 f_expect_clear(185.0);
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001598
1599 deactivate(ccrel);
1600
1601 f_sleep(1.0);
Harald Welte12510c52018-01-26 22:26:24 +01001602}
1603testcase TC_mo_setup_and_nothing() runs on MTC_CT {
1604 var BSC_ConnHdlr vc_conn;
1605 f_init();
1606
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001607 vc_conn := f_start_handler(refers(f_tc_mo_setup_and_nothing), 28);
Harald Welte12510c52018-01-26 22:26:24 +01001608 vc_conn.done;
1609}
1610
Harald Weltee13cfb22019-04-23 16:52:02 +02001611
Harald Welte3ab88002018-01-26 22:37:25 +01001612/* Test MO Call with no response to RAN-side CRCX */
Harald Weltee13cfb22019-04-23 16:52:02 +02001613friend function f_tc_mo_crcx_ran_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001614 f_init_handler(pars);
Harald Welte3ab88002018-01-26 22:37:25 +01001615 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1616 var MNCC_PDU mncc;
1617 var MgcpCommand mgcp_cmd;
1618
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001619 f_perform_lu();
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001620 /* Do not respond to the second CRCX */
1621 cpars.mgw_conn_2.resp := 0;
1622 f_mo_call_establish(cpars);
Harald Welte3ab88002018-01-26 22:37:25 +01001623
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001624 var default ccrel := activate(as_optional_cc_rel(cpars));
Harald Welte3ab88002018-01-26 22:37:25 +01001625
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001626 f_expect_clear(60.0);
Harald Welte3ab88002018-01-26 22:37:25 +01001627
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001628 deactivate(ccrel);
Harald Welte3ab88002018-01-26 22:37:25 +01001629}
1630testcase TC_mo_crcx_ran_timeout() runs on MTC_CT {
1631 var BSC_ConnHdlr vc_conn;
1632 f_init();
1633
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001634 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_timeout), 29);
Harald Welte3ab88002018-01-26 22:37:25 +01001635 vc_conn.done;
1636}
1637
Harald Weltee13cfb22019-04-23 16:52:02 +02001638
Harald Welte0cc82d92018-01-26 22:52:34 +01001639/* Test MO Call with reject to RAN-side CRCX */
Harald Weltee13cfb22019-04-23 16:52:02 +02001640friend function f_tc_mo_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001641 f_init_handler(pars);
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001642
Harald Welte0cc82d92018-01-26 22:52:34 +01001643 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001644
1645 /* Respond with error for the first CRCX */
1646 cpars.mgw_conn_1.resp := -1;
Harald Welte0cc82d92018-01-26 22:52:34 +01001647
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001648 f_perform_lu();
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001649 f_mo_call_establish(cpars);
Harald Welte0cc82d92018-01-26 22:52:34 +01001650
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001651 var default ccrel := activate(as_optional_cc_rel(cpars));
1652 f_expect_clear(60.0);
1653 deactivate(ccrel);
Harald Welte0cc82d92018-01-26 22:52:34 +01001654}
1655testcase TC_mo_crcx_ran_reject() runs on MTC_CT {
1656 var BSC_ConnHdlr vc_conn;
1657 f_init();
1658
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001659 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_reject), 30);
Harald Welte0cc82d92018-01-26 22:52:34 +01001660 vc_conn.done;
1661}
1662
Harald Welte3ab88002018-01-26 22:37:25 +01001663
Harald Welte812f7a42018-01-27 00:49:18 +01001664/* helper function to start a MT call: MNCC SETUP; Paging; DChan est.; DTAP SETUP */
1665private function f_mt_call_start(inout CallParameters cpars) runs on BSC_ConnHdlr {
1666 var MNCC_PDU mncc;
1667 var MgcpCommand mgcp_cmd;
Harald Welte812f7a42018-01-27 00:49:18 +01001668
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001669 f_perform_lu();
Vadim Yanitskiyae747742020-01-10 00:23:10 +01001670 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Welte812f7a42018-01-27 00:49:18 +01001671
1672 /* Allocate call reference and send SETUP via MNCC to MSC */
1673 cpars.mncc_callref := f_rnd_int(2147483648);
1674 MNCC.send(ts_MNCC_SETUP_req(cpars.mncc_callref, hex2str(g_pars.msisdn),
1675 hex2str(cpars.called_party), hex2str(g_pars.imsi)));
1676
1677 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02001678 f_expect_paging();
1679
Harald Welte812f7a42018-01-27 00:49:18 +01001680 /* MS -> MSC: PAGING RESPONSE */
Harald Welteb9e86fa2018-04-09 18:18:31 +02001681 f_establish_fully(EST_TYPE_PAG_RESP);
Harald Welte812f7a42018-01-27 00:49:18 +01001682
1683 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1684
1685 /* MSC->MS: SETUP */
1686 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_SETUP(cpars.transaction_id, *, cpars.called_party)));
1687}
1688
1689/* Test MT Call */
Harald Weltee13cfb22019-04-23 16:52:02 +02001690friend function f_tc_mt_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001691 f_init_handler(pars);
Harald Welte812f7a42018-01-27 00:49:18 +01001692 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1693 var MNCC_PDU mncc;
1694 var MgcpCommand mgcp_cmd;
1695
1696 f_mt_call_start(cpars);
1697
1698 /* MS->MSC: CALL CONFIRMED */
1699 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1700
1701 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1702
1703 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1704 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001705
1706 /* Detect if the received CRCX is a wildcarded CRCX request. If yes,
1707 * set an endpoint name that fits the pattern. If not, just use the
1708 * endpoint name from the request */
1709 if (match(mgcp_cmd.line.ep, t_MGCP_EP_wildcard)) {
1710 cpars.mgcp_ep := "rtpbridge/1@mgw";
1711 } else {
1712 cpars.mgcp_ep := mgcp_cmd.line.ep;
1713 }
1714
Harald Welte812f7a42018-01-27 00:49:18 +01001715 /* Respond to CRCX with error */
1716 var MgcpResponse mgcp_rsp := {
1717 line := {
1718 code := "542",
1719 trans_id := mgcp_cmd.line.trans_id,
1720 string := "FORCED_FAIL"
1721 },
Harald Welte812f7a42018-01-27 00:49:18 +01001722 sdp := omit
1723 }
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001724 var MgcpParameter mgcp_rsp_param := {
1725 code := "Z",
1726 val := cpars.mgcp_ep
1727 };
1728 mgcp_rsp.params[0] := mgcp_rsp_param;
Harald Welte812f7a42018-01-27 00:49:18 +01001729 MGCP.send(mgcp_rsp);
1730
1731 timer T := 30.0;
1732 T.start;
1733 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001734 [] T.timeout {
1735 setverdict(fail, "Timeout waiting for channel release");
1736 mtc.stop;
1737 }
Harald Welte812f7a42018-01-27 00:49:18 +01001738 [] MNCC.receive { repeat; }
1739 [] GSUP.receive { repeat; }
1740 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1741 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
1742 f_create_mgcp_delete_ep(cpars.mgcp_ep);
1743 repeat;
1744 }
1745 [] MGCP.receive { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001746 [] as_clear_cmd_compl_disc();
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001747 [] as_optional_cc_rel(cpars);
Harald Welte812f7a42018-01-27 00:49:18 +01001748 }
1749}
1750testcase TC_mt_crcx_ran_reject() runs on MTC_CT {
1751 var BSC_ConnHdlr vc_conn;
1752 f_init();
1753
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001754 vc_conn := f_start_handler(refers(f_tc_mt_crcx_ran_reject), 31);
Harald Welte812f7a42018-01-27 00:49:18 +01001755 vc_conn.done;
1756}
1757
1758
Harald Weltee13cfb22019-04-23 16:52:02 +02001759
Harald Welte812f7a42018-01-27 00:49:18 +01001760/* Test MT Call T310 timer */
Harald Weltee13cfb22019-04-23 16:52:02 +02001761friend function f_tc_mt_t310(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte812f7a42018-01-27 00:49:18 +01001762 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
Harald Welte812f7a42018-01-27 00:49:18 +01001763 var MgcpCommand mgcp_cmd;
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001764 var PDU_BSSAP bssap;
1765 timer T310;
Harald Welte812f7a42018-01-27 00:49:18 +01001766
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001767 f_init_handler(pars);
1768
Neels Hofmeyr05606152023-03-06 22:42:27 +01001769 /* Make sure X2 does not fire in this test. This test does not send a CN RTP port to osmo-msc, which will
1770 * trigger X2 timeout. We want to test T310, so make X2 significantly longer than T310=30s. */
1771 f_vty_config(MSCVTY, "msc", "timer mgw X2 40");
1772
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001773 /* Initiate a MT call, establish connection */
Harald Welte812f7a42018-01-27 00:49:18 +01001774 f_mt_call_start(cpars);
1775
1776 /* MS->MSC: CALL CONFIRMED */
1777 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1778 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1779
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001780 /* NOTE: MSC is expected to start T310 here */
Harald Welte812f7a42018-01-27 00:49:18 +01001781
Neels Hofmeyrd8a4aee2022-07-25 22:07:24 +02001782 interleave {
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001783 /* MSC->MGW: CRCX (first) */
Neels Hofmeyrd8a4aee2022-07-25 22:07:24 +02001784 [] MGCP.receive(tr_CRCX) -> value mgcp_cmd {
1785 f_handle_crcx(cpars, mgcp_cmd); /* MSC<-MGW: OK */
1786 }
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001787
1788 /* BSC->BSC: BSSMAP ASSIGNMENT REQ */
Neels Hofmeyrd8a4aee2022-07-25 22:07:24 +02001789 [] BSSAP.receive(tr_BSSMAP_AssignmentReq(omit, ?)) -> value bssap {
1790 BSSAP.send(ts_BSSMAP_AssignmentComplete(omit,
1791 aoip := f_ts_BSSMAP_IE_AoIP_TLA(cpars.bss_rtp_ip, cpars.bss_rtp_port),
1792 speechCodec := ts_BSSMAP_IE_SpeechCodec({ ts_CodecFR })));
1793 }
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001794
1795 /* MSC->MGW: MDCX */
Neels Hofmeyrd8a4aee2022-07-25 22:07:24 +02001796 [] MGCP.receive(tr_MDCX) -> value mgcp_cmd {
1797 MGCP.send(ts_MDCX_ACK(mgcp_cmd.line.trans_id, cpars.mgw_conn_1.mgcp_connection_id,
1798 sdp := omit));
1799 }
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001800
1801 /* MSC->MGW: CRCX (second) */
Neels Hofmeyrd8a4aee2022-07-25 22:07:24 +02001802 [] MGCP.receive(tr_CRCX) -> value mgcp_cmd {
1803 f_handle_crcx(cpars, mgcp_cmd); /* MSC<-MGW: OK */
Neels Hofmeyrd8a4aee2022-07-25 22:07:24 +02001804 }
Neels Hofmeyrc29e6dc2022-08-09 02:38:10 +02001805
1806 [] MNCC.receive(tr_MNCC_RTP_CREATE(cpars.mncc_callref));
Neels Hofmeyrd8a4aee2022-07-25 22:07:24 +02001807 }
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001808
1809 /* Reschedule the guard timeout */
1810 g_Tguard.start(30.0 + 10.0);
1811
1812 /* NOTE: the BSC is expected to respond with CC ALERTING at this state, so
1813 * the MSC would stop T310. However, the idea is to verify T310 expiration
1814 * here, so grab some popcorn and wait for MNCC DISC.ind. */
1815 T310.start(30.0 + 2.0);
Neels Hofmeyre81ef422022-08-07 14:33:06 +02001816 var MNCC_PDU mncc_rx;
Harald Welte812f7a42018-01-27 00:49:18 +01001817 alt {
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001818 [] T310.timeout {
1819 setverdict(fail, "Timeout waiting for MNCC DISC.ind due to T310");
Daniel Willmannafce8662018-07-06 23:11:32 +02001820 mtc.stop;
1821 }
Harald Welte812f7a42018-01-27 00:49:18 +01001822 [] MNCC.receive(tr_MNCC_DISC_ind(cpars.mncc_callref)) {
1823 MNCC.send(ts_MNCC_REL_req(cpars.mncc_callref, valueof(ts_MNCC_cause(23))));
Neels Hofmeyr13eeb552022-08-07 14:33:37 +02001824 log("Rx MNCC DISC.ind, T310.read yields ", T310.read);
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001825 setverdict(pass);
Harald Welte812f7a42018-01-27 00:49:18 +01001826 }
Neels Hofmeyre81ef422022-08-07 14:33:06 +02001827 [] MNCC.receive(MNCC_PDU:?) -> value mncc_rx {
1828 log("Rx ", mncc_rx);
1829 setverdict(fail, "Expected MNCC DISC.ind, got some other MNCC message instead");
1830 mtc.stop;
1831 }
Harald Welte812f7a42018-01-27 00:49:18 +01001832 }
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001833
Harald Welte812f7a42018-01-27 00:49:18 +01001834 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_DISC(cpars.transaction_id)));
1835 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id)));
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001836 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id, '1'B)));
Harald Welte812f7a42018-01-27 00:49:18 +01001837
1838 alt {
Harald Welte812f7a42018-01-27 00:49:18 +01001839 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1840 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001841 // FIXME: f_create_mgcp_delete_ep(cpars.mgcp_ep);
Harald Welte812f7a42018-01-27 00:49:18 +01001842 repeat;
1843 }
Harald Welte5946b332018-03-18 23:32:21 +01001844 [] as_clear_cmd_compl_disc();
Harald Welte812f7a42018-01-27 00:49:18 +01001845 }
1846}
1847testcase TC_mt_t310() runs on MTC_CT {
1848 var BSC_ConnHdlr vc_conn;
1849 f_init();
1850
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001851 vc_conn := f_start_handler(refers(f_tc_mt_t310), 32);
Harald Welte812f7a42018-01-27 00:49:18 +01001852 vc_conn.done;
1853}
1854
Harald Weltee13cfb22019-04-23 16:52:02 +02001855
Harald Welte167458a2018-01-27 15:58:16 +01001856/* Perform successful LU + MO call, then GSUP LocationCancel. Subscriber must be denied CM SERV */
Harald Weltee13cfb22019-04-23 16:52:02 +02001857friend function f_tc_gsup_cancel(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte167458a2018-01-27 15:58:16 +01001858 f_init_handler(pars);
1859 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Harald Welte167458a2018-01-27 15:58:16 +01001860
1861 /* Location Update to make subscriber known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001862 f_perform_lu();
Harald Welte167458a2018-01-27 15:58:16 +01001863
1864 /* First MO call should succeed */
1865 f_mo_call(cpars);
1866
1867 /* Cancel the subscriber in the VLR */
1868 GSUP.send(ts_GSUP_CL_REQ(g_pars.imsi, OSMO_GSUP_CANCEL_TYPE_WITHDRAW));
1869 alt {
1870 [] GSUP.receive(tr_GSUP_CL_RES(g_pars.imsi)) { }
1871 [] GSUP.receive(tr_GSUP_CL_ERR(g_pars.imsi)) {
1872 setverdict(fail, "Received GSUP Location Cancel Error");
Daniel Willmannafce8662018-07-06 23:11:32 +02001873 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001874 }
1875 }
1876
1877 /* Follow-up transactions should fail */
1878 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1879 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001880 f_cl3_or_initial_ue(l3_info);
Harald Welte167458a2018-01-27 15:58:16 +01001881 alt {
1882 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
1883 [] BSSAP.receive {
1884 setverdict(fail, "Received unexpected BSSAP instead of CM SERV REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +02001885 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001886 }
1887 }
Neels Hofmeyr0f7429a2019-03-07 22:28:41 +01001888
1889 f_expect_clear();
Harald Welte167458a2018-01-27 15:58:16 +01001890 setverdict(pass);
1891}
1892testcase TC_gsup_cancel() runs on MTC_CT {
1893 var BSC_ConnHdlr vc_conn;
1894 f_init();
1895
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001896 vc_conn := f_start_handler(refers(f_tc_gsup_cancel), 33, verify_cell_id := false);
Harald Welte167458a2018-01-27 15:58:16 +01001897 vc_conn.done;
1898}
1899
Harald Weltee13cfb22019-04-23 16:52:02 +02001900
Harald Welte9de84792018-01-28 01:06:35 +01001901/* A5/1 only permitted on network side, and MS capable to do it */
1902private function f_tc_lu_imsi_auth_tmsi_encr_1_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1903 pars.net.expect_auth := true;
1904 pars.net.expect_ciph := true;
1905 pars.net.kc_support := '02'O; /* A5/1 only */
1906 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001907 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001908}
1909testcase TC_lu_imsi_auth_tmsi_encr_1_13() runs on MTC_CT {
1910 var BSC_ConnHdlr vc_conn;
1911 f_init();
1912 f_vty_config(MSCVTY, "network", "authentication required");
1913 f_vty_config(MSCVTY, "network", "encryption a5 1");
1914
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001915 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_1_13), 34);
Harald Welte9de84792018-01-28 01:06:35 +01001916 vc_conn.done;
1917}
1918
1919/* A5/3 only permitted on network side, and MS capable to do it */
1920private function f_tc_lu_imsi_auth_tmsi_encr_3_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1921 pars.net.expect_auth := true;
1922 pars.net.expect_ciph := true;
1923 pars.net.kc_support := '08'O; /* A5/3 only */
1924 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001925 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001926}
1927testcase TC_lu_imsi_auth_tmsi_encr_3_13() runs on MTC_CT {
1928 var BSC_ConnHdlr vc_conn;
1929 f_init();
1930 f_vty_config(MSCVTY, "network", "authentication required");
1931 f_vty_config(MSCVTY, "network", "encryption a5 3");
1932
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001933 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_13), 35);
Harald Welte9de84792018-01-28 01:06:35 +01001934 vc_conn.done;
1935}
1936
1937/* A5/3 only permitted on network side, and MS with only A5/1 support */
1938private function f_tc_lu_imsi_auth_tmsi_encr_3_1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1939 pars.net.expect_auth := true;
1940 pars.net.expect_ciph := true;
1941 pars.net.kc_support := '08'O; /* A5/3 only */
1942 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1943 f_init_handler(pars, 15.0);
1944
1945 /* cannot use f_perform_lu() as we expect a reject */
1946 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
1947 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +02001948 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001949 if (pars.send_early_cm) {
1950 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1951 } else {
1952 pars.cm1.esind := '0'B;
1953 }
Harald Welte9de84792018-01-28 01:06:35 +01001954 f_mm_auth();
1955 alt {
Daniel Willmann52918e52018-09-20 14:39:09 +02001956 [] BSSAP.receive(tr_BSSMAP_ClassmarkReq) {
1957 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1958 repeat;
1959 }
Harald Welte5946b332018-03-18 23:32:21 +01001960 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1961 f_expect_clear();
1962 }
Harald Welte9de84792018-01-28 01:06:35 +01001963 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
1964 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02001965 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001966 }
1967 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01001968 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02001969 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001970 }
1971 }
1972 setverdict(pass);
1973}
1974testcase TC_lu_imsi_auth_tmsi_encr_3_1() runs on MTC_CT {
1975 var BSC_ConnHdlr vc_conn;
1976 f_init();
1977 f_vty_config(MSCVTY, "network", "authentication required");
1978 f_vty_config(MSCVTY, "network", "encryption a5 3");
1979
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001980 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 360, verify_cell_id := false);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001981 vc_conn.done;
1982}
1983testcase TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() runs on MTC_CT {
1984 var BSC_ConnHdlrPars pars;
1985 var BSC_ConnHdlr vc_conn;
1986 f_init();
1987 f_vty_config(MSCVTY, "network", "authentication required");
1988 f_vty_config(MSCVTY, "network", "encryption a5 3");
1989
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001990 pars := f_init_pars(361, verify_cell_id := false);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001991 pars.send_early_cm := false;
1992 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), pars);
Harald Welte9de84792018-01-28 01:06:35 +01001993 vc_conn.done;
1994}
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01001995testcase TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() runs on MTC_CT {
1996 var BSC_ConnHdlr vc_conn;
1997 f_init();
1998 f_vty_config(MSCVTY, "network", "authentication required");
1999 f_vty_config(MSCVTY, "network", "encryption a5 3");
2000
2001 /* Make sure the MSC category is on DEBUG level to trigger the log
2002 * message that is reported in OS#2947 to trigger the segfault */
2003 f_vty_config(MSCVTY, "log stderr", "logging level msc debug");
2004
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02002005 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 362, verify_cell_id := false);
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01002006 vc_conn.done;
2007}
Harald Welte9de84792018-01-28 01:06:35 +01002008
2009/* A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
2010private function f_tc_lu_imsi_auth_tmsi_encr_13_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2011 pars.net.expect_auth := true;
2012 pars.net.expect_ciph := true;
2013 pars.net.kc_support := '0A'O; /* A5/1 + A5/3 */
2014 pars.cm1.a5_1 := '1'B;
2015 pars.cm2.a5_1 := '1'B;
2016 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
2017 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
2018 f_init_handler(pars, 15.0);
2019
2020 /* cannot use f_perform_lu() as we expect a reject */
2021 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
2022 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +02002023 f_cl3_or_initial_ue(l3_lu);
Harald Welte9de84792018-01-28 01:06:35 +01002024 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
2025 f_mm_auth();
2026 alt {
Harald Welte5946b332018-03-18 23:32:21 +01002027 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
2028 f_expect_clear();
2029 }
Harald Welte9de84792018-01-28 01:06:35 +01002030 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
2031 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02002032 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01002033 }
2034 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01002035 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02002036 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01002037 }
2038 }
2039 setverdict(pass);
2040}
2041testcase TC_lu_imsi_auth_tmsi_encr_13_2() runs on MTC_CT {
2042 var BSC_ConnHdlr vc_conn;
2043 f_init();
2044 f_vty_config(MSCVTY, "network", "authentication required");
2045 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
2046
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02002047 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_2), 37, verify_cell_id := false);
Harald Welte9de84792018-01-28 01:06:35 +01002048 vc_conn.done;
2049}
2050
Eric Wild26f4a622021-05-17 15:27:05 +02002051/* A5/0 + A5/1 + A5/3 + a5/4 only permitted on network side, and MS with only A5/1 support */
2052private function f_tc_lu_imsi_auth_tmsi_encr_0134_1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2053 pars.net.expect_auth := true;
2054 pars.net.expect_ciph := true;
2055 pars.net.kc_support := '03'O; /* A5/0 + A5/1 */
2056 pars.cm1.a5_1 := '0'B;
2057 pars.cm2.a5_1 := '0'B;
2058 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
2059 pars.cm2.classmarkInformationType2_oct5.a5_2 := '0'B;
2060 pars.cm2.classmarkInformationType2_oct5.cm3 := '0'B;
2061 pars.cm3 := omit;
2062 pars.use_umts_aka := true;
2063
2064 f_init_handler(pars, 15.0);
2065 f_perform_lu();
2066}
2067testcase TC_lu_imsi_auth_tmsi_encr_0134_1() runs on MTC_CT {
2068 var BSC_ConnHdlr vc_conn;
2069 f_init();
2070 f_vty_config(MSCVTY, "network", "authentication required");
2071 f_vty_config(MSCVTY, "network", "encryption a5 0 1 3 4");
2072
2073 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_0134_1), 39);
2074 vc_conn.done;
2075}
2076
2077/* A5/0 + A5/1 + A5/3 + a5/4 only permitted on network side, and MS with A5/3 + A5/4 support */
2078private function f_tc_lu_imsi_auth_tmsi_encr_0134_34(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2079 pars.net.expect_auth := true;
2080 pars.net.expect_ciph := true;
2081 pars.net.kc_support := '19'O; /* A5/3 + A5/4 */
2082 pars.cm1.a5_1 := '1'B;
2083 pars.cm2.a5_1 := '1'B;
2084 pars.cm2.classmarkInformationType2_oct5.a5_3 := '1'B;
2085 pars.cm2.classmarkInformationType2_oct5.a5_2 := '0'B;
2086 pars.cm2.classmarkInformationType2_oct5.cm3 := '1'B;
2087 pars.cm3 := valueof(ts_CM3_default);
2088 pars.use_umts_aka := true;
2089
2090 f_init_handler(pars, 15.0);
2091 f_perform_lu();
2092}
2093testcase TC_lu_imsi_auth_tmsi_encr_0134_34() runs on MTC_CT {
2094 var BSC_ConnHdlr vc_conn;
2095 f_init();
2096 f_vty_config(MSCVTY, "network", "authentication required");
2097 f_vty_config(MSCVTY, "network", "encryption a5 0 1 3 4");
2098
2099 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_0134_34), 40);
2100 vc_conn.done;
2101}
2102
2103/* A5/0 + A5/1 + A5/3 + a5/4 only permitted on network side, and MS with A5/3 support but no CM3 */
2104private function f_tc_lu_imsi_auth_tmsi_encr_0134_34_no_cm3(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2105 pars.net.expect_auth := true;
2106 pars.net.expect_ciph := true;
2107 pars.net.kc_support := '19'O; /* A5/3 + A5/4 */
2108 pars.cm1.a5_1 := '1'B;
2109 pars.cm2.a5_1 := '1'B;
2110 pars.cm2.classmarkInformationType2_oct5.a5_3 := '1'B;
2111 pars.cm2.classmarkInformationType2_oct5.a5_2 := '0'B;
2112 pars.cm2.classmarkInformationType2_oct5.cm3 := '0'B;
2113 pars.cm3 := omit;
2114 pars.use_umts_aka := true;
2115
2116 f_init_handler(pars, 15.0);
2117 f_perform_lu();
2118}
2119testcase TC_lu_imsi_auth_tmsi_encr_0134_34_no_cm3() runs on MTC_CT {
2120 var BSC_ConnHdlr vc_conn;
2121 f_init();
2122 f_vty_config(MSCVTY, "network", "authentication required");
2123 f_vty_config(MSCVTY, "network", "encryption a5 0 1 3 4");
2124
2125 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_0134_34_no_cm3), 41);
2126 vc_conn.done;
2127}
2128
Harald Welte9de84792018-01-28 01:06:35 +01002129/* A5/0 + A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
2130private function f_tc_lu_imsi_auth_tmsi_encr_013_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2131 pars.net.expect_auth := true;
2132 pars.net.expect_ciph := true;
2133 pars.net.kc_support := '0B'O; /* A5/1 + A5/3 */
2134 pars.cm1.a5_1 := '1'B;
2135 pars.cm2.a5_1 := '1'B;
2136 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
2137 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
2138 f_init_handler(pars, 15.0);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01002139 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01002140}
2141testcase TC_lu_imsi_auth_tmsi_encr_013_2() runs on MTC_CT {
2142 var BSC_ConnHdlr vc_conn;
2143 f_init();
2144 f_vty_config(MSCVTY, "network", "authentication required");
2145 f_vty_config(MSCVTY, "network", "encryption a5 0 1 3");
2146
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01002147 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_013_2), 38);
Harald Welte9de84792018-01-28 01:06:35 +01002148 vc_conn.done;
2149}
2150
Harald Welte33ec09b2018-02-10 15:34:46 +01002151/* LU followed by MT call (including paging) */
Neels Hofmeyr8fe8a902019-11-03 05:51:03 +01002152friend function f_tc_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte33ec09b2018-02-10 15:34:46 +01002153 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01002154 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02002155 cpars.use_osmux := pars.use_osmux;
Harald Welte33ec09b2018-02-10 15:34:46 +01002156
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01002157 f_perform_lu();
Harald Welte33ec09b2018-02-10 15:34:46 +01002158 f_mt_call(cpars);
2159}
2160testcase TC_lu_and_mt_call() runs on MTC_CT {
2161 var BSC_ConnHdlr vc_conn;
2162 f_init();
2163
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01002164 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call), 39);
Harald Welte33ec09b2018-02-10 15:34:46 +01002165 vc_conn.done;
2166}
2167
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02002168testcase TC_lu_and_mt_call_osmux() runs on MTC_CT {
2169 var BSC_ConnHdlr vc_conn;
2170 f_init(1, false, true, true);
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02002171
2172 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call), 39, 0, true, true);
2173 vc_conn.done;
2174}
2175
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02002176/* LU followed by MT call (including paging) */
2177friend function f_tc_lu_and_mt_call_ipv6(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2178 f_init_handler(pars);
2179 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
2180 cpars.mgw_conn_1.mgw_rtp_ip := "::1";
2181 cpars.mgw_conn_2.mgw_rtp_ip := "::2";
2182 cpars.bss_rtp_ip := "::3";
Pau Espin Pedrol563b3d02020-09-09 20:19:52 +02002183 cpars.mncc_rtp_ip := "::9";
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02002184 f_perform_lu();
2185 f_mt_call(cpars);
2186}
2187testcase TC_lu_and_mt_call_ipv6() runs on MTC_CT {
2188 var BSC_ConnHdlr vc_conn;
2189 f_init();
2190
2191 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call_ipv6), 39);
2192 vc_conn.done;
2193}
2194
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01002195/* MT call while already Paging */
2196friend function f_tc_lu_and_mt_call_already_paging(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2197 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
2198 var SmsParameters spars := valueof(t_SmsPars);
2199 var OCT4 tmsi;
2200
2201 f_init_handler(pars);
2202
2203 /* Perform location update */
2204 f_perform_lu();
2205
2206 /* register an 'expect' for given IMSI (+TMSI) */
2207 if (isvalue(g_pars.tmsi)) {
2208 tmsi := g_pars.tmsi;
2209 } else {
2210 tmsi := 'FFFFFFFF'O;
2211 }
2212 f_ran_register_imsi(g_pars.imsi, tmsi);
2213
2214 log("start Paging by an SMS");
2215 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2216
2217 /* MSC->BSC: expect PAGING from MSC */
2218 f_expect_paging();
2219
2220 log("MNCC signals MT call, before Paging Response");
2221 f_mt_call_initate(cpars);
2222 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
2223
2224 f_sleep(0.5);
2225 log("phone answers Paging, expecting both SMS and MT call to be established");
2226 f_establish_fully(EST_TYPE_PAG_RESP);
2227 spars.tp.ud := 'C8329BFD064D9B53'O;
2228 interleave {
2229 [] BSSAP.receive(f_mt_sms_deliver_pdu(spars)) {
2230 log("Got SMS-DELIVER");
2231 };
2232 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_SETUP(cpars.transaction_id, *, cpars.called_party))) {
2233 log("Got CC Setup");
2234 };
2235 }
2236 setverdict(pass);
2237 log("success, tear down");
2238 var default ccrel := activate(as_optional_cc_rel(cpars));
2239 if (g_pars.ran_is_geran) {
2240 BSSAP.send(ts_BSSMAP_ClearRequest(0));
2241 } else {
2242 BSSAP.send(ts_RANAP_IuReleaseRequest(ts_RanapCause_om_intervention));
2243 }
2244 f_expect_clear();
2245 deactivate(ccrel);
2246 f_vty_sms_clear(hex2str(g_pars.imsi));
2247}
2248testcase TC_lu_and_mt_call_already_paging() runs on MTC_CT {
2249 var BSC_ConnHdlrPars pars;
2250 var BSC_ConnHdlr vc_conn;
2251 f_init();
2252 pars := f_init_pars(391);
2253 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_call_already_paging), pars);
2254 vc_conn.done;
2255}
2256
Daniel Willmann8b084372018-02-04 13:35:26 +01002257/* Test MO Call SETUP with DTMF */
2258private function f_tc_mo_setup_dtmf_dup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2259 f_init_handler(pars);
2260 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Daniel Willmann8b084372018-02-04 13:35:26 +01002261
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01002262 f_perform_lu();
Daniel Willmann8b084372018-02-04 13:35:26 +01002263 f_mo_seq_dtmf_dup(cpars);
2264}
2265testcase TC_mo_setup_and_dtmf_dup() runs on MTC_CT {
2266 var BSC_ConnHdlr vc_conn;
2267 f_init();
2268
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01002269 vc_conn := f_start_handler(refers(f_tc_mo_setup_dtmf_dup), 39);
Daniel Willmann8b084372018-02-04 13:35:26 +01002270 vc_conn.done;
2271}
Harald Welte9de84792018-01-28 01:06:35 +01002272
Philipp Maier328d1662018-03-07 10:40:27 +01002273testcase TC_cr_before_reset() runs on MTC_CT {
2274 timer T := 4.0;
2275 var boolean reset_ack_seen := false;
2276 f_init_bssap_direct();
2277
Harald Welte3ca0ce12019-04-23 17:18:48 +02002278 f_ran_adapter_start(g_bssap[0]);
Daniel Willmann42d1d5b2018-08-07 15:18:41 +02002279
Daniel Willmanne8018962018-08-21 14:18:00 +02002280 f_sleep(3.0);
2281
Philipp Maier328d1662018-03-07 10:40:27 +01002282 /* Make a blind connection attemt, to trigger the deadlock condition */
Philipp Maier75932982018-03-27 14:52:35 +02002283 BSSAP_DIRECT.send(ts_BSSAP_CONNECT_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, 1, omit));
Philipp Maier328d1662018-03-07 10:40:27 +01002284
2285 /* Send a BSSMAP reset */
Philipp Maier75932982018-03-27 14:52:35 +02002286 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_Reset(0)));
Philipp Maier328d1662018-03-07 10:40:27 +01002287 T.start
2288 alt {
2289 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_ResetAck)) {
2290 reset_ack_seen := true;
2291 repeat;
2292 }
2293
2294 /* Acknowledge MSC sided reset requests */
2295 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_Reset)) {
Philipp Maier75932982018-03-27 14:52:35 +02002296 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_ResetAck));
Philipp Maier328d1662018-03-07 10:40:27 +01002297 repeat;
2298 }
2299
2300 /* Ignore all other messages (e.g CR from the connection request) */
2301 [] BSSAP_DIRECT.receive { repeat }
2302
2303 /* If we got no BSSMAP RESET ACK back, then the MSC entered the
2304 * deadlock situation. The MSC is then unable to respond to any
2305 * further BSSMAP RESET or any other sort of traffic. */
2306 [reset_ack_seen == true] T.timeout { setverdict(pass) }
2307 [reset_ack_seen == false] T.timeout {
2308 setverdict(fail, "no BSSMAP RESET ACK seen!");
Daniel Willmannafce8662018-07-06 23:11:32 +02002309 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +01002310 }
Pau Espin Pedrol7e9178d2019-12-17 17:52:17 +01002311 }
Philipp Maier328d1662018-03-07 10:40:27 +01002312}
Harald Welte9de84792018-01-28 01:06:35 +01002313
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002314/* Test MO Call with no response to RAN-side CRCX or DTAP Release */
Harald Weltee13cfb22019-04-23 16:52:02 +02002315friend function f_tc_mo_release_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002316 f_init_handler(pars);
2317 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
2318 var MNCC_PDU mncc;
2319 var MgcpCommand mgcp_cmd;
2320
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02002321 /* Do not respond to the second CRCX */
2322 cpars.mgw_conn_2.resp := 0;
2323
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002324 f_perform_lu();
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02002325 f_mo_call_establish(cpars);
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002326
Neels Hofmeyrde76f052019-02-26 05:02:46 +01002327 var default ccrel := activate(as_optional_cc_rel(cpars));
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002328
2329 f_expect_clear(60.0);
Neels Hofmeyrde76f052019-02-26 05:02:46 +01002330
2331 deactivate(ccrel);
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002332}
2333testcase TC_mo_release_timeout() runs on MTC_CT {
2334 var BSC_ConnHdlr vc_conn;
2335 f_init();
2336
2337 vc_conn := f_start_handler(refers(f_tc_mo_release_timeout), 40);
2338 vc_conn.done;
2339}
2340
Harald Welte12510c52018-01-26 22:26:24 +01002341
Philipp Maier2a98a732018-03-19 16:06:12 +01002342/* LU followed by MT call (including paging) */
2343private function f_tc_lu_and_mt_call_no_dlcx_resp(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2344 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01002345 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Philipp Maier2a98a732018-03-19 16:06:12 +01002346
2347 /* Intentionally disable the CRCX response */
2348 cpars.mgw_drop_dlcx := true;
2349
2350 /* Perform location update and call */
2351 f_perform_lu();
2352 f_mt_call(cpars);
2353}
2354testcase TC_lu_and_mt_call_no_dlcx_resp() runs on MTC_CT {
2355 var BSC_ConnHdlr vc_conn;
2356 f_init();
2357
2358 /* Perform an almost normal looking locationupdate + mt-call, but do
2359 * not respond to the DLCX at the end of the call */
2360 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call_no_dlcx_resp), 41);
2361 vc_conn.done;
2362
2363 /* Wait a guard period until the MGCP layer in the MSC times out,
2364 * if the MSC is vulnerable to the use-after-free situation that is
2365 * fixed by I78f1b6a9149488a4ad3f120c1e190a83c07d4b89 then it should
2366 * segfault now */
2367 f_sleep(6.0);
2368
2369 /* Run the init procedures once more. If the MSC has crashed, this
2370 * this will fail */
2371 f_init();
2372}
Harald Welte45164da2018-01-24 12:51:27 +01002373
Philipp Maier75932982018-03-27 14:52:35 +02002374/* Two BSSMAP resets from two different BSCs */
2375testcase TC_reset_two() runs on MTC_CT {
2376 var BSC_ConnHdlr vc_conn;
2377 f_init(2);
2378 f_sleep(2.0);
2379 setverdict(pass);
2380}
2381
Harald Weltee13cfb22019-04-23 16:52:02 +02002382/* Two BSSMAP resets from two different BSCs plus one IuCS RANAP Reset */
2383testcase TC_reset_two_1iu() runs on MTC_CT {
2384 var BSC_ConnHdlr vc_conn;
2385 f_init(3);
2386 f_sleep(2.0);
2387 setverdict(pass);
2388}
2389
Harald Weltef640a012018-04-14 17:49:21 +02002390/***********************************************************************
2391 * SMS Testing
2392 ***********************************************************************/
2393
Harald Weltef45efeb2018-04-09 18:19:24 +02002394/* LU followed by MO SMS */
Harald Weltee13cfb22019-04-23 16:52:02 +02002395friend function f_tc_lu_and_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02002396 var SmsParameters spars := valueof(t_SmsPars);
2397
2398 f_init_handler(pars);
2399
2400 /* Perform location update and call */
2401 f_perform_lu();
2402
2403 f_establish_fully(EST_TYPE_MO_SMS);
2404
2405 //spars.exp_rp_err := 96; /* invalid mandatory information */
2406 f_mo_sms(spars);
2407
2408 f_expect_clear();
2409}
2410testcase TC_lu_and_mo_sms() runs on MTC_CT {
2411 var BSC_ConnHdlr vc_conn;
2412 f_init();
2413 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_sms), 42);
2414 vc_conn.done;
2415}
2416
Harald Weltee13cfb22019-04-23 16:52:02 +02002417
Harald Weltef45efeb2018-04-09 18:19:24 +02002418private function f_vty_sms_send(charstring imsi, charstring msisdn, charstring text)
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002419runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02002420 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
2421}
2422
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01002423/* Remove still pending SMS */
2424private function f_vty_sms_clear(charstring imsi)
2425runs on BSC_ConnHdlr {
2426 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " sms delete-all");
2427 f_vty_transceive(MSCVTY, "sms-queue clear");
2428}
2429
Harald Weltef45efeb2018-04-09 18:19:24 +02002430/* LU followed by MT SMS */
Harald Weltee13cfb22019-04-23 16:52:02 +02002431friend function f_tc_lu_and_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02002432 var SmsParameters spars := valueof(t_SmsPars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002433
2434 f_init_handler(pars);
2435
2436 /* Perform location update and call */
2437 f_perform_lu();
2438
2439 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002440 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Weltef45efeb2018-04-09 18:19:24 +02002441
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002442 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
Harald Weltef45efeb2018-04-09 18:19:24 +02002443
2444 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02002445 f_expect_paging();
2446
Harald Weltef45efeb2018-04-09 18:19:24 +02002447 /* Establish DTAP / BSSAP / SCCP connection */
2448 f_establish_fully(EST_TYPE_PAG_RESP);
2449
2450 spars.tp.ud := 'C8329BFD064D9B53'O;
2451 f_mt_sms(spars);
2452
2453 f_expect_clear();
2454}
2455testcase TC_lu_and_mt_sms() runs on MTC_CT {
2456 var BSC_ConnHdlrPars pars;
2457 var BSC_ConnHdlr vc_conn;
2458 f_init();
2459 pars := f_init_pars(43);
2460 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms), pars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002461 vc_conn.done;
2462}
2463
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01002464/* SMS added while already Paging */
2465friend function f_tc_lu_and_mt_sms_already_paging(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2466 var SmsParameters spars := valueof(t_SmsPars);
2467 var OCT4 tmsi;
2468
2469 f_init_handler(pars);
2470
2471 f_perform_lu();
2472
2473 /* register an 'expect' for given IMSI (+TMSI) */
2474 if (isvalue(g_pars.tmsi)) {
2475 tmsi := g_pars.tmsi;
2476 } else {
2477 tmsi := 'FFFFFFFF'O;
2478 }
2479 f_ran_register_imsi(g_pars.imsi, tmsi);
2480
2481 log("first SMS");
2482 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2483
2484 /* MSC->BSC: expect PAGING from MSC */
2485 f_expect_paging();
2486
2487 log("second SMS");
2488 /* Now osmo-msc is in state "Paging pending", make sure that another SMS to be sent at this time just joins in
2489 * with the pending paging. Another SMS: */
2490 f_vty_sms_send(hex2str(pars.imsi), "2342", "Another SMS");
2491
2492 /* Establish DTAP / BSSAP / SCCP connection */
2493 f_establish_fully(EST_TYPE_PAG_RESP);
2494
2495 spars.tp.ud := 'C8329BFD064D9B53'O;
2496 f_mt_sms(spars);
2497
2498 spars.tp.ud := '41F79B8E2ECB41D3E614'O;
2499 f_mt_sms(spars);
2500
2501 f_expect_clear();
2502}
2503testcase TC_lu_and_mt_sms_already_paging() runs on MTC_CT {
2504 var BSC_ConnHdlrPars pars;
2505 var BSC_ConnHdlr vc_conn;
2506 f_init();
2507 pars := f_init_pars(44);
2508 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_already_paging), pars);
2509 vc_conn.done;
2510}
Harald Weltee13cfb22019-04-23 16:52:02 +02002511
Philipp Maier3983e702018-11-22 19:01:33 +01002512/* Paging for MT SMS but no response */
Harald Weltee13cfb22019-04-23 16:52:02 +02002513friend function f_tc_lu_and_mt_sms_paging_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier3983e702018-11-22 19:01:33 +01002514 var SmsParameters spars := valueof(t_SmsPars);
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002515
Philipp Maier3983e702018-11-22 19:01:33 +01002516 f_init_handler(pars, 150.0);
2517
2518 /* Perform location update */
2519 f_perform_lu();
2520
2521 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002522 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Philipp Maier3983e702018-11-22 19:01:33 +01002523
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002524 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2525
Neels Hofmeyr16237742019-03-06 15:34:01 +01002526 /* Expect the MSC to page exactly once */
Harald Weltee13cfb22019-04-23 16:52:02 +02002527 f_expect_paging();
Philipp Maier3983e702018-11-22 19:01:33 +01002528
2529 /* Wait some time to make sure the MSC is not delivering any further
2530 * paging messages or anything else that could be unexpected. */
2531 timer T := 20.0;
2532 T.start
2533 alt {
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002534 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
2535 setverdict(fail, "paging seems not to stop!");
2536 mtc.stop;
Philipp Maier3983e702018-11-22 19:01:33 +01002537 }
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002538 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
2539 setverdict(fail, "paging seems not to stop!");
2540 mtc.stop;
Harald Weltee13cfb22019-04-23 16:52:02 +02002541 }
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002542 [] BSSAP.receive {
2543 setverdict(fail, "unexpected BSSAP message received");
2544 self.stop;
Philipp Maier3983e702018-11-22 19:01:33 +01002545 }
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002546 [] T.timeout {
2547 setverdict(pass);
Philipp Maier3983e702018-11-22 19:01:33 +01002548 }
2549 }
2550
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01002551 f_vty_sms_clear(hex2str(g_pars.imsi));
2552
Philipp Maier3983e702018-11-22 19:01:33 +01002553 setverdict(pass);
2554}
2555testcase TC_lu_and_mt_sms_paging_and_nothing() runs on MTC_CT {
2556 var BSC_ConnHdlrPars pars;
2557 var BSC_ConnHdlr vc_conn;
2558 f_init();
Philipp Maiera99ad262019-01-22 15:35:42 +01002559 pars := f_init_pars(1843);
Philipp Maier3983e702018-11-22 19:01:33 +01002560 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_paging_and_nothing), pars);
Philipp Maier3983e702018-11-22 19:01:33 +01002561 vc_conn.done;
2562}
2563
Alexander Couzensfc02f242019-09-12 03:43:18 +02002564/* LU followed by MT SMS with repeated paging */
2565friend function f_tc_lu_and_mt_sms_paging_repeated(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2566 var SmsParameters spars := valueof(t_SmsPars);
Alexander Couzensfc02f242019-09-12 03:43:18 +02002567
2568 f_init_handler(pars);
2569
2570 /* Perform location update and call */
2571 f_perform_lu();
2572
2573 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002574 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Alexander Couzensfc02f242019-09-12 03:43:18 +02002575
2576 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2577
Neels Hofmeyrc3accec2019-11-28 01:09:47 +01002578 log("Expecting first Paging");
Alexander Couzensfc02f242019-09-12 03:43:18 +02002579 /* MSC->BSC: expect PAGING from MSC */
2580 f_expect_paging();
2581
Neels Hofmeyrc3accec2019-11-28 01:09:47 +01002582 if (g_pars.ran_is_geran) {
2583 log("GERAN: expect no further Paging");
2584 } else {
2585 log("UTRAN: expect more Paging");
2586 }
2587
2588 timer T := 5.0;
2589 T.start;
2590 alt {
2591 [g_pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
2592 setverdict(fail, "GERAN should not repeat Paging, but received a second Paging");
2593 mtc.stop;
2594 }
2595 [not g_pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
2596 log("UTRAN: second Paging received, as expected");
2597 setverdict(pass);
2598 }
2599 [] T.timeout {
2600 if (g_pars.ran_is_geran) {
2601 log("GERAN: No further Paging received, as expected");
2602 setverdict(pass);
2603 } else {
2604 setverdict(fail, "UTRAN: Expected a second Paging");
2605 mtc.stop;
2606 }
2607 }
2608 }
Alexander Couzensfc02f242019-09-12 03:43:18 +02002609
2610 /* Establish DTAP / BSSAP / SCCP connection */
2611 f_establish_fully(EST_TYPE_PAG_RESP);
2612
2613 spars.tp.ud := 'C8329BFD064D9B53'O;
2614 f_mt_sms(spars);
2615
2616 f_expect_clear();
2617}
2618testcase TC_lu_and_mt_sms_paging_repeated() runs on MTC_CT {
2619 var BSC_ConnHdlrPars pars;
2620 var BSC_ConnHdlr vc_conn;
2621 f_init();
2622 pars := f_init_pars(1844);
2623 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_paging_repeated), pars);
2624 vc_conn.done;
2625}
Harald Weltee13cfb22019-04-23 16:52:02 +02002626
Harald Weltef640a012018-04-14 17:49:21 +02002627/* mobile originated SMS from MS/BTS/BSC side to SMPP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002628friend function f_tc_smpp_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef640a012018-04-14 17:49:21 +02002629 var SmsParameters spars := valueof(t_SmsPars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002630
Harald Weltef640a012018-04-14 17:49:21 +02002631 f_init_handler(pars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002632
Harald Weltef640a012018-04-14 17:49:21 +02002633 /* Perform location update so IMSI is known + registered in MSC/VLR */
2634 f_perform_lu();
Harald Weltef640a012018-04-14 17:49:21 +02002635
Vadim Yanitskiy2d3f8462020-01-15 11:44:12 +07002636 /* MS/UE submits a MO SMS */
2637 f_establish_fully(EST_TYPE_MO_SMS);
2638 f_mo_sms_submit(spars);
Harald Weltef640a012018-04-14 17:49:21 +02002639
2640 var SMPP_PDU smpp;
2641 var template SMPP_PDU tr_smpp := tr_SMPP(c_SMPP_command_id_deliver_sm, ESME_ROK);
2642 tr_smpp.body.deliver_sm := {
2643 service_type := "CMT",
2644 source_addr_ton := network_specific,
2645 source_addr_npi := isdn,
2646 source_addr := hex2str(pars.msisdn),
2647 dest_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
2648 dest_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
2649 destination_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
2650 esm_class := '00000001'B,
2651 protocol_id := 0,
2652 priority_flag := 0,
2653 schedule_delivery_time := "",
2654 replace_if_present := 0,
2655 data_coding := '00000001'B,
2656 sm_default_msg_id := 0,
2657 sm_length := ?,
2658 short_message := spars.tp.ud,
2659 opt_pars := {
2660 {
2661 tag := user_message_reference,
2662 len := 2,
2663 opt_value := {
2664 int2_val := oct2int(spars.tp.msg_ref)
2665 }
2666 }
2667 }
2668 };
2669 alt {
2670 [] SMPP.receive(tr_smpp) -> value smpp {
2671 SMPP.send(ts_SMPP_DELIVER_SM_resp(ESME_ROK, smpp.header.seq_num));
2672 }
2673 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK)) { repeat; }
2674 }
2675
Vadim Yanitskiy2d3f8462020-01-15 11:44:12 +07002676 /* MSC terminates the SMS transaction with RP-ACK */
2677 f_mo_sms_wait_rp_ack(spars);
2678
Harald Weltef640a012018-04-14 17:49:21 +02002679 f_expect_clear();
2680}
2681testcase TC_smpp_mo_sms() runs on MTC_CT {
2682 var BSC_ConnHdlr vc_conn;
2683 f_init();
2684 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "default-route");
2685 vc_conn := f_start_handler(refers(f_tc_smpp_mo_sms), 44);
2686 vc_conn.done;
2687 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "no default-route");
2688}
2689
Vadim Yanitskiy33820762020-01-15 11:26:07 +07002690/* Test case for OS#4351: make sure that RP-ERROR from ESME is properly sent to the MS/UE */
2691friend function f_tc_smpp_mo_sms_rp_error(charstring id, BSC_ConnHdlrPars pars)
2692runs on BSC_ConnHdlr {
2693 var SmsParameters spars := valueof(t_SmsPars);
2694 var SMPP_PDU smpp_pdu;
2695 timer T := 3.0;
2696
2697 f_init_handler(pars);
2698
2699 /* Perform location update */
2700 f_perform_lu();
2701
2702 /* MS/UE submits a MO SMS */
2703 f_establish_fully(EST_TYPE_MO_SMS);
2704 f_mo_sms_submit(spars);
2705
2706 /* ESME responds with an error (Invalid Destination Address) */
2707 T.start;
2708 alt {
2709 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_deliver_sm, ESME_ROK, body := ?)) -> value smpp_pdu {
2710 SMPP.send(ts_SMPP_DELIVER_SM_resp(ESME_RINVDSTADR, smpp_pdu.header.seq_num));
2711 }
2712 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK)) { repeat; }
2713 [] T.timeout {
2714 setverdict(fail, "Timeout waiting for SMPP DELIVER-SM");
2715 mtc.stop;
2716 }
2717 }
2718
2719 /* Expect RP-ERROR on BSSAP interface */
2720 spars.exp_rp_err := 1; /* FIXME: GSM411_RP_CAUSE_MO_NUM_UNASSIGNED */
2721 f_mo_sms_wait_rp_ack(spars);
2722
2723 f_expect_clear();
2724}
2725testcase TC_smpp_mo_sms_rp_error() runs on MTC_CT {
2726 var BSC_ConnHdlr vc_conn;
2727 f_init();
2728 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "default-route");
2729 vc_conn := f_start_handler(refers(f_tc_smpp_mo_sms_rp_error), 45);
2730 vc_conn.done;
2731 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "no default-route");
2732}
2733
Harald Weltee13cfb22019-04-23 16:52:02 +02002734
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002735/* Test MO-SMS from MS/BTS/BSC towards HLR (via GSUP) */
Harald Weltee13cfb22019-04-23 16:52:02 +02002736friend function f_tc_gsup_mo_sms(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002737runs on BSC_ConnHdlr {
2738 var SmsParameters spars := valueof(t_SmsPars);
2739 var GSUP_PDU gsup_msg_rx;
2740 var octetstring sm_tpdu;
2741
2742 f_init_handler(pars);
2743
2744 /* We need to inspect GSUP activity */
2745 f_create_gsup_expect(hex2str(g_pars.imsi));
2746
2747 /* Perform location update */
2748 f_perform_lu();
2749
2750 /* Send CM Service Request for SMS */
2751 f_establish_fully(EST_TYPE_MO_SMS);
2752
2753 /* Prepare expected SM-RP-UI (SM TPDU) */
2754 enc_TPDU_RP_DATA_MS_SGSN_fast(
2755 valueof(ts_SMS_SUBMIT(spars.tp.msg_ref,
2756 spars.tp.da, spars.tp.pid, spars.tp.dcs,
2757 spars.tp.udl, spars.tp.ud)),
2758 sm_tpdu);
2759
2760 var template GSUP_PDU mo_forwardSM := tr_GSUP_MO_FORWARD_SM_REQ(
2761 imsi := g_pars.imsi,
2762 sm_rp_mr := spars.rp.msg_ref,
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09002763 /* SM-RP-DA: SMSC address */
2764 sm_rp_da := tr_GSUP_SM_RP_DA_SMSC_ADDR(t_GSUP_SM_RP_Addr(
2765 number := spars.rp.smsc_addr.rP_NumberDigits,
2766 npi := spars.rp.smsc_addr.rP_NumberingPlanIdentification,
2767 ton := spars.rp.smsc_addr.rP_TypeOfNumber,
2768 ext := spars.rp.smsc_addr.rP_Ext)),
2769 /* SM-RP-OA: subscriber's MSISDN (filled in by MSC) */
2770 sm_rp_oa := tr_GSUP_SM_RP_OA_MSISDN(t_GSUP_SM_RP_Addr(
2771 number := g_pars.msisdn,
2772 /* NOTE: MSISDN in g_pars lacks this info, assuming defaults */
2773 npi := '0001'B, ton := '001'B, ext := '1'B)),
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002774 /* TODO: can we use decmatch here? */
2775 sm_rp_ui := sm_tpdu
2776 );
2777
2778 /* Submit an SMS on DTAP and expect MO-forwardSM-Req on GSUP */
2779 f_mo_sms_submit(spars);
2780 alt {
2781 [] GSUP.receive(mo_forwardSM) -> value gsup_msg_rx {
Vadim Yanitskiya358dd42020-01-15 10:42:47 +07002782 log("RX MO-forwardSM-Req: ", gsup_msg_rx);
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002783 setverdict(pass);
2784 }
2785 [] GSUP.receive {
2786 log("RX unexpected GSUP message");
2787 setverdict(fail);
2788 mtc.stop;
2789 }
2790 }
2791
2792 /* Trigger RP-ACK by sending MO-forwardSM-Res */
2793 GSUP.send(valueof(ts_GSUP_MO_FORWARD_SM_RES(
2794 imsi := g_pars.imsi,
2795 sm_rp_mr := spars.rp.msg_ref)));
2796 /* Expect RP-ACK on DTAP */
2797 f_mo_sms_wait_rp_ack(spars);
2798
2799 f_expect_clear();
2800}
2801testcase TC_gsup_mo_sms() runs on MTC_CT {
2802 var BSC_ConnHdlr vc_conn;
2803 f_init();
2804 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2805 vc_conn := f_start_handler(refers(f_tc_gsup_mo_sms), 88);
2806 vc_conn.done;
2807 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2808}
2809
Harald Weltee13cfb22019-04-23 16:52:02 +02002810
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002811/* Test MO-SMMA from MS/BTS/BSC towards HLR (via GSUP) */
Harald Weltee13cfb22019-04-23 16:52:02 +02002812friend function f_tc_gsup_mo_smma(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002813runs on BSC_ConnHdlr {
2814 var SmsParameters spars := valueof(t_SmsPars);
2815 var GSUP_PDU gsup_msg_rx;
2816
2817 f_init_handler(pars);
2818
2819 /* We need to inspect GSUP activity */
2820 f_create_gsup_expect(hex2str(g_pars.imsi));
2821
2822 /* Perform location update */
2823 f_perform_lu();
2824
2825 /* Send CM Service Request for SMS */
2826 f_establish_fully(EST_TYPE_MO_SMS);
2827
2828 var template GSUP_PDU mo_ReadyForSM := tr_GSUP_MO_READY_FOR_SM_REQ(
2829 imsi := g_pars.imsi,
2830 sm_rp_mr := spars.rp.msg_ref,
2831 sm_alert_rsn := GSUP_SM_ALERT_RSN_TYPE_MEM_AVAIL
2832 );
2833
2834 /* Submit an SMS on DTAP and expect MO-forwardSM-Req on GSUP */
2835 f_mo_smma(spars);
2836 alt {
2837 [] GSUP.receive(mo_ReadyForSM) -> value gsup_msg_rx {
Vadim Yanitskiya358dd42020-01-15 10:42:47 +07002838 log("RX MO-ReadyForSM-Req: ", gsup_msg_rx);
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002839 setverdict(pass);
2840 }
2841 [] GSUP.receive {
2842 log("RX unexpected GSUP message");
2843 setverdict(fail);
2844 mtc.stop;
2845 }
2846 }
2847
2848 /* Trigger RP-ACK by sending MO-forwardSM-Res */
2849 GSUP.send(valueof(ts_GSUP_MO_READY_FOR_SM_RES(
2850 imsi := g_pars.imsi,
2851 sm_rp_mr := spars.rp.msg_ref)));
2852 /* Expect RP-ACK on DTAP */
2853 f_mo_sms_wait_rp_ack(spars);
2854
2855 f_expect_clear();
2856}
2857testcase TC_gsup_mo_smma() runs on MTC_CT {
2858 var BSC_ConnHdlr vc_conn;
2859 f_init();
2860 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2861 vc_conn := f_start_handler(refers(f_tc_gsup_mo_smma), 89);
2862 vc_conn.done;
2863 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2864}
2865
Harald Weltee13cfb22019-04-23 16:52:02 +02002866
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002867/* Helper for sending MT SMS over GSUP */
2868private function f_gsup_forwardSM_req(SmsParameters spars, OCT1 mms := '00'O)
2869runs on BSC_ConnHdlr {
Vadim Yanitskiya52347c2019-12-12 17:32:33 +09002870 var GSUP_SM_RP_Addr msisdn := valueof(t_GSUP_SM_RP_Addr(g_pars.msisdn));
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09002871 var GSUP_SM_RP_Addr smsc := valueof(t_GSUP_SM_RP_Addr(
2872 number := spars.rp.smsc_addr.rP_NumberDigits,
2873 npi := spars.rp.smsc_addr.rP_NumberingPlanIdentification,
2874 ton := spars.rp.smsc_addr.rP_TypeOfNumber,
2875 ext := spars.rp.smsc_addr.rP_Ext));
Vadim Yanitskiya52347c2019-12-12 17:32:33 +09002876
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002877 GSUP.send(ts_GSUP_MT_FORWARD_SM_REQ(
2878 imsi := g_pars.imsi,
2879 /* NOTE: MSC should assign RP-MR itself */
2880 sm_rp_mr := 'FF'O,
Vadim Yanitskiya52347c2019-12-12 17:32:33 +09002881 sm_rp_da := valueof(ts_GSUP_SM_RP_DA_MSISDN(msisdn)),
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09002882 sm_rp_oa := valueof(ts_GSUP_SM_RP_OA_SMSC_ADDR(smsc)),
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002883 /* Encoded SMS TPDU (taken from Wireshark)
2884 * FIXME: we should encode spars somehow */
2885 sm_rp_ui := '00068021436500008111328130858200'O,
2886 sm_rp_mms := mms
2887 ));
2888}
2889
2890/* Test successful MT-SMS (RP-ACK) over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002891friend function f_tc_gsup_mt_sms_ack(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002892runs on BSC_ConnHdlr {
2893 var SmsParameters spars := valueof(t_SmsPars);
2894
2895 f_init_handler(pars);
2896
2897 /* We need to inspect GSUP activity */
2898 f_create_gsup_expect(hex2str(g_pars.imsi));
2899
2900 /* Perform location update */
2901 f_perform_lu();
2902
2903 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002904 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002905
2906 var template GSUP_PDU mt_forwardSM_res := tr_GSUP_MT_FORWARD_SM_RES(
2907 imsi := g_pars.imsi,
2908 /* NOTE: MSC should assign RP-MR itself */
2909 sm_rp_mr := ?
2910 );
2911
2912 /* Submit a MT SMS on GSUP */
2913 f_gsup_forwardSM_req(spars);
2914
2915 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002916 f_expect_paging();
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002917 f_establish_fully(EST_TYPE_PAG_RESP);
2918
2919 /* Wait for MT SMS on DTAP */
2920 f_mt_sms_expect(spars);
2921
2922 /* Send RP-ACK and expect MT-forwardSM-Res on GSUP */
2923 f_mt_sms_send_rp_ack(spars);
2924 alt {
2925 [] GSUP.receive(mt_forwardSM_res) {
2926 log("RX MT-forwardSM-Res (RP-ACK)");
2927 setverdict(pass);
2928 }
2929 [] GSUP.receive {
2930 log("RX unexpected GSUP message");
2931 setverdict(fail);
2932 mtc.stop;
2933 }
2934 }
2935
2936 f_expect_clear();
2937}
2938testcase TC_gsup_mt_sms_ack() runs on MTC_CT {
2939 var BSC_ConnHdlrPars pars;
2940 var BSC_ConnHdlr vc_conn;
2941 f_init();
2942 pars := f_init_pars(90);
2943 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2944 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_ack), pars);
2945 vc_conn.done;
2946 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2947}
2948
Harald Weltee13cfb22019-04-23 16:52:02 +02002949
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002950/* Test rejected MT-SMS (RP-ERROR) over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002951friend function f_tc_gsup_mt_sms_err(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002952runs on BSC_ConnHdlr {
2953 var SmsParameters spars := valueof(t_SmsPars);
2954 var OCT1 sm_rp_cause := '78'O; /* dummy RP-Cause value */
2955
2956 f_init_handler(pars);
2957
2958 /* We need to inspect GSUP activity */
2959 f_create_gsup_expect(hex2str(g_pars.imsi));
2960
2961 /* Perform location update */
2962 f_perform_lu();
2963
2964 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002965 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002966
2967 var template GSUP_PDU mt_forwardSM_err := tr_GSUP_MT_FORWARD_SM_ERR(
2968 imsi := g_pars.imsi,
2969 /* NOTE: MSC should assign RP-MR itself */
2970 sm_rp_mr := ?,
2971 sm_rp_cause := sm_rp_cause
2972 );
2973
2974 /* Submit a MT SMS on GSUP */
2975 f_gsup_forwardSM_req(spars);
2976
2977 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002978 f_expect_paging();
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002979 f_establish_fully(EST_TYPE_PAG_RESP);
2980
2981 /* Wait for MT SMS on DTAP */
2982 f_mt_sms_expect(spars);
2983
2984 /* Send RP-ERROR and expect MT-forwardSM-Err on GSUP */
2985 f_mt_sms_send_rp_error(spars, oct2int(sm_rp_cause));
2986 alt {
2987 [] GSUP.receive(mt_forwardSM_err) {
2988 log("RX MT-forwardSM-Err (RP-ERROR)");
2989 setverdict(pass);
2990 mtc.stop;
2991 }
2992 [] GSUP.receive {
2993 log("RX unexpected GSUP message");
2994 setverdict(fail);
2995 mtc.stop;
2996 }
2997 }
2998
2999 f_expect_clear();
3000}
3001testcase TC_gsup_mt_sms_err() runs on MTC_CT {
3002 var BSC_ConnHdlrPars pars;
3003 var BSC_ConnHdlr vc_conn;
3004 f_init();
3005 pars := f_init_pars(91);
3006 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
3007 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_err), pars);
3008 vc_conn.done;
3009 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
3010}
3011
Harald Weltee13cfb22019-04-23 16:52:02 +02003012
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07003013/* Test SM-RP-MR assignment for MT-SMS over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02003014friend function f_tc_gsup_mt_sms_rp_mr(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07003015runs on BSC_ConnHdlr {
3016 var SmsParameters spars1 := valueof(t_SmsPars); /* 1st SMS */
3017 var SmsParameters spars2 := valueof(t_SmsPars); /* 2nd SMS */
3018
3019 f_init_handler(pars);
3020
3021 /* We need to inspect GSUP activity */
3022 f_create_gsup_expect(hex2str(g_pars.imsi));
3023
3024 /* Perform location update */
3025 f_perform_lu();
3026
3027 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01003028 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07003029
3030 /* Submit the 1st MT SMS on GSUP */
3031 log("TX MT-forwardSM-Req for the 1st SMS");
3032 f_gsup_forwardSM_req(spars1);
3033
3034 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02003035 f_expect_paging();
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07003036 f_establish_fully(EST_TYPE_PAG_RESP);
3037
3038 /* Wait for 1st MT SMS on DTAP */
3039 f_mt_sms_expect(spars1);
3040 log("RX the 1st SMS on DTAP, DTAP TID is ", spars1.tid,
3041 ", SM-RP-MR is ", spars1.rp.msg_ref);
3042
3043 /* Submit the 2nd MT SMS on GSUP */
3044 log("TX MT-forwardSM-Req for the 2nd SMS");
3045 f_gsup_forwardSM_req(spars2);
3046
3047 /* Wait for 2nd MT SMS on DTAP */
3048 f_mt_sms_expect(spars2);
3049 log("RX the 2nd SMS on DTAP, DTAP TID is ", spars2.tid,
3050 ", SM-RP-MR is ", spars2.rp.msg_ref);
3051
3052 /* Both transaction IDs shall be different */
3053 if (spars1.tid == spars2.tid) {
3054 log("Both DTAP transaction IDs shall be different");
3055 setverdict(fail);
3056 }
3057
3058 /* Both SM-RP-MR values shall be different */
3059 if (spars1.rp.msg_ref == spars2.rp.msg_ref) {
3060 log("Both SM-RP-MR values shall be different");
3061 setverdict(fail);
3062 }
3063
3064 /* Both SM-RP-MR values shall be assigned */
3065 if (spars1.rp.msg_ref == 'FF'O) {
3066 log("Unassigned SM-RP-MR value for the 1st SMS");
3067 setverdict(fail);
3068 }
3069 if (spars2.rp.msg_ref == 'FF'O) {
3070 log("Unassigned SM-RP-MR value for the 2nd SMS");
3071 setverdict(fail);
3072 }
3073
3074 /* Send the 1st RP-ACK and expect MT-forwardSM-Res on GSUP */
3075 f_mt_sms_send_rp_ack(spars1);
3076 alt {
3077 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
3078 imsi := g_pars.imsi,
3079 sm_rp_mr := spars1.rp.msg_ref
3080 )) {
3081 log("RX MT-forwardSM-Res (RP-ACK)");
3082 setverdict(pass);
3083 }
3084 [] GSUP.receive {
3085 log("RX unexpected GSUP message");
3086 setverdict(fail);
3087 mtc.stop;
3088 }
3089 }
3090
3091 /* Send the 2nd RP-ACK and expect MT-forwardSM-Res on GSUP */
3092 f_mt_sms_send_rp_ack(spars2);
3093 alt {
3094 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
3095 imsi := g_pars.imsi,
3096 sm_rp_mr := spars2.rp.msg_ref
3097 )) {
3098 log("RX MT-forwardSM-Res (RP-ACK)");
3099 setverdict(pass);
3100 }
3101 [] GSUP.receive {
3102 log("RX unexpected GSUP message");
3103 setverdict(fail);
3104 mtc.stop;
3105 }
3106 }
3107
3108 f_expect_clear();
3109}
3110testcase TC_gsup_mt_sms_rp_mr() runs on MTC_CT {
3111 var BSC_ConnHdlrPars pars;
3112 var BSC_ConnHdlr vc_conn;
3113 f_init();
3114 pars := f_init_pars(92);
3115 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
3116 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_rp_mr), pars);
3117 vc_conn.done;
3118 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
3119}
3120
Harald Weltee13cfb22019-04-23 16:52:02 +02003121
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07003122/* Test SM-RP-MR assignment for MT-SMS over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02003123friend function f_tc_gsup_mo_mt_sms_rp_mr(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07003124runs on BSC_ConnHdlr {
3125 var SmsParameters spars_mo := valueof(t_SmsPars); /* MO SMMA */
3126 var SmsParameters spars_mt := valueof(t_SmsPars); /* MT SMS */
3127
3128 f_init_handler(pars);
3129
3130 /* We need to inspect GSUP activity */
3131 f_create_gsup_expect(hex2str(g_pars.imsi));
3132
3133 /* Perform location update */
3134 f_perform_lu();
3135
3136 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01003137 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07003138
3139 /* Send CM Service Request for MO SMMA */
3140 f_establish_fully(EST_TYPE_MO_SMS);
3141
3142 /* Submit MO SMMA on DTAP */
3143 log("Submit MO SMMA on DTAP, SM-RP-MR is '00'O");
3144 spars_mo.rp.msg_ref := '00'O;
3145 f_mo_smma(spars_mo);
3146
3147 /* Expect MO-forwardSM-Req for MO SMMA on GSUP */
3148 alt {
3149 [] GSUP.receive(tr_GSUP_MO_READY_FOR_SM_REQ(
3150 imsi := g_pars.imsi,
3151 sm_rp_mr := spars_mo.rp.msg_ref,
3152 sm_alert_rsn := GSUP_SM_ALERT_RSN_TYPE_MEM_AVAIL
3153 )) {
3154 log("RX MO-ReadyForSM-Req, SM-RP-MR is '00'O");
3155 setverdict(pass);
3156 }
3157 [] GSUP.receive {
3158 log("RX unexpected GSUP message");
3159 setverdict(fail);
3160 mtc.stop;
3161 }
3162 }
3163
3164 /* Submit MT SMS on GSUP */
3165 log("TX MT-forwardSM-Req for the MT SMS");
3166 f_gsup_forwardSM_req(spars_mt);
3167
3168 /* Wait for MT SMS on DTAP */
3169 f_mt_sms_expect(spars_mt);
3170 log("RX MT SMS on DTAP, DTAP TID is ", spars_mt.tid,
3171 ", SM-RP-MR is ", spars_mt.rp.msg_ref);
3172
3173 /* Both SM-RP-MR values shall be different */
3174 if (spars_mo.rp.msg_ref == spars_mt.rp.msg_ref) {
3175 log("Both SM-RP-MR values shall be different");
3176 setverdict(fail);
3177 }
3178
3179 /* SM-RP-MR value for MT SMS shall be assigned */
3180 if (spars_mt.rp.msg_ref == 'FF'O) {
3181 log("Unassigned SM-RP-MR value for the MT SMS");
3182 setverdict(fail);
3183 }
3184
3185 /* Trigger RP-ACK for MO SMMA by sending MO-forwardSM-Res */
3186 GSUP.send(valueof(ts_GSUP_MO_READY_FOR_SM_RES(
3187 imsi := g_pars.imsi,
3188 sm_rp_mr := spars_mo.rp.msg_ref)));
3189 /* Expect RP-ACK for MO SMMA on DTAP */
3190 f_mo_sms_wait_rp_ack(spars_mo);
3191
3192 /* Send RP-ACK for MT SMS and expect MT-forwardSM-Res on GSUP */
3193 f_mt_sms_send_rp_ack(spars_mt);
3194 alt {
3195 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
3196 imsi := g_pars.imsi,
3197 sm_rp_mr := spars_mt.rp.msg_ref
3198 )) {
3199 log("RX MT-forwardSM-Res (RP-ACK)");
3200 setverdict(pass);
3201 }
3202 [] GSUP.receive {
3203 log("RX unexpected GSUP message");
3204 setverdict(fail);
3205 mtc.stop;
3206 }
3207 }
3208
3209 f_expect_clear();
3210}
3211testcase TC_gsup_mo_mt_sms_rp_mr() runs on MTC_CT {
3212 var BSC_ConnHdlrPars pars;
3213 var BSC_ConnHdlr vc_conn;
3214 f_init();
3215 pars := f_init_pars(93);
3216 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
3217 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mo_mt_sms_rp_mr), pars);
3218 vc_conn.done;
3219 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
3220}
3221
Harald Weltee13cfb22019-04-23 16:52:02 +02003222
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07003223/* Test multi-part MT-SMS over GSUP */
3224private function f_tc_gsup_mt_multi_part_sms(charstring id, BSC_ConnHdlrPars pars)
3225runs on BSC_ConnHdlr {
3226 var SmsParameters spars := valueof(t_SmsPars);
3227
3228 f_init_handler(pars);
3229
3230 /* We need to inspect GSUP activity */
3231 f_create_gsup_expect(hex2str(g_pars.imsi));
3232
3233 /* Perform location update */
3234 f_perform_lu();
3235
3236 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01003237 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07003238
3239 var template GSUP_PDU mt_forwardSM_res := tr_GSUP_MT_FORWARD_SM_RES(
3240 imsi := g_pars.imsi,
3241 /* NOTE: MSC should assign RP-MR itself */
3242 sm_rp_mr := ?
3243 );
3244
3245 /* Send 4 messages (NOTE: SM-RP-UI remains unchanged) */
3246 for (var integer i := 3; i >= 0; i := i-1) {
3247 /* Submit a MT SMS on GSUP (MMS is decremented) */
3248 f_gsup_forwardSM_req(spars, int2oct(i, 1));
3249
3250 /* Expect Paging Request and Establish connection */
3251 if (i == 3) { /* ... only once! */
Harald Weltee13cfb22019-04-23 16:52:02 +02003252 f_expect_paging();
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07003253 f_establish_fully(EST_TYPE_PAG_RESP);
3254 }
3255
3256 /* Wait for MT SMS on DTAP */
3257 f_mt_sms_expect(spars);
3258
3259 /* Send RP-ACK and expect MT-forwardSM-Res on GSUP */
3260 f_mt_sms_send_rp_ack(spars);
3261 alt {
3262 [] GSUP.receive(mt_forwardSM_res) {
3263 log("RX MT-forwardSM-Res (RP-ACK)");
3264 setverdict(pass);
3265 }
3266 [] GSUP.receive {
3267 log("RX unexpected GSUP message");
3268 setverdict(fail);
3269 mtc.stop;
3270 }
3271 }
3272
3273 /* Keep some 'distance' between transmissions */
3274 f_sleep(1.5);
3275 }
3276
3277 f_expect_clear();
3278}
3279testcase TC_gsup_mt_multi_part_sms() runs on MTC_CT {
3280 var BSC_ConnHdlrPars pars;
3281 var BSC_ConnHdlr vc_conn;
3282 f_init();
3283 pars := f_init_pars(91);
3284 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
3285 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_multi_part_sms), pars);
3286 vc_conn.done;
3287 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
3288}
3289
Harald Weltef640a012018-04-14 17:49:21 +02003290/* convert GSM L3 TON to SMPP_TON enum */
3291function f_sm_ton_from_gsm(BIT3 ton) return SMPP_TON {
3292 select (ton) {
3293 case ('000'B) { return unknown; }
3294 case ('001'B) { return international; }
3295 case ('010'B) { return national; }
3296 case ('011'B) { return network_specific; }
3297 case ('100'B) { return subscriber_number; }
3298 case ('101'B) { return alphanumeric; }
3299 case ('110'B) { return abbreviated; }
3300 }
3301 setverdict(fail, "Unknown TON ", ton);
Daniel Willmannafce8662018-07-06 23:11:32 +02003302 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02003303}
3304/* convert GSM L3 NPI to SMPP_NPI enum */
3305function f_sm_npi_from_gsm(BIT4 npi) return SMPP_NPI {
3306 select (npi) {
3307 case ('0000'B) { return unknown; }
3308 case ('0001'B) { return isdn; }
3309 case ('0011'B) { return data; }
3310 case ('0100'B) { return telex; }
3311 case ('0110'B) { return land_mobile; }
3312 case ('1000'B) { return national; }
3313 case ('1001'B) { return private_; }
3314 case ('1010'B) { return ermes; }
3315 }
3316 setverdict(fail, "Unknown NPI ", npi);
Daniel Willmannafce8662018-07-06 23:11:32 +02003317 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02003318}
3319
3320/* build a SMPP_SM from SmsParameters */
3321function f_mt_sm_from_spars(SmsParameters spars)
3322runs on BSC_ConnHdlr return SMPP_SM {
3323 var SMPP_SM sm := {
3324 service_type := "CMT",
3325 source_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
3326 source_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
3327 source_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
3328 dest_addr_ton := international,
3329 dest_addr_npi := isdn,
3330 destination_addr := hex2str(g_pars.msisdn),
3331 esm_class := '00000001'B,
3332 protocol_id := 0,
3333 priority_flag := 0,
3334 schedule_delivery_time := "",
3335 validity_period := "",
3336 registered_delivery := '00000000'B,
3337 replace_if_present := 0,
3338 data_coding := '00000001'B,
3339 sm_default_msg_id := 0,
3340 sm_length := spars.tp.udl,
3341 short_message := spars.tp.ud,
3342 opt_pars := {}
3343 };
3344 return sm;
3345}
3346
3347/* helper function to encode SMS from 'spars', send it via SMPP to MSC; receive it on MS side */
3348private function f_smpp_mt_sms(SmsParameters spars, boolean trans_mode) runs on BSC_ConnHdlr {
3349 var SMPP_SM sm := f_mt_sm_from_spars(spars);
3350 if (trans_mode) {
3351 sm.esm_class := '00000010'B;
3352 }
3353
3354 /* actually cause MSC to send a SMS via SUBMIT-SM from SMPP side */
3355 SMPP.send(ts_SMPP_SUBMIT_SM(sm));
3356 if (not match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
3357 /* if we're not in SMPP transaction mode, we expect the SMPP-level ACK
3358 * before we expect the SMS delivery on the BSC/radio side */
3359 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
3360 }
3361
3362 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02003363 f_expect_paging();
Harald Weltef640a012018-04-14 17:49:21 +02003364 /* Establish DTAP / BSSAP / SCCP connection */
3365 f_establish_fully(EST_TYPE_PAG_RESP);
3366 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
3367
3368 f_mt_sms(spars);
3369
3370 if (match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
3371 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
3372 }
3373 f_expect_clear();
3374}
3375
3376/* mobile terminated SMS, from SMPP to BSC/BTS/MS */
3377private function f_tc_smpp_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3378 f_init_handler(pars);
3379
3380 /* Perform location update so IMSI is known + registered in MSC/VLR */
3381 f_perform_lu();
3382 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
3383
3384 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01003385 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Weltef640a012018-04-14 17:49:21 +02003386
3387 var SmsParameters spars := valueof(t_SmsPars);
3388 /* TODO: test with more intelligent user data; test different coding schemes */
3389 spars.tp.ud := '00'O;
3390 spars.tp.udl := 1;
3391
3392 /* first test the non-transaction store+forward mode */
3393 f_smpp_mt_sms(spars, false);
3394
3395 /* then test the transaction mode */
3396 f_smpp_mt_sms(spars, true);
3397}
3398testcase TC_smpp_mt_sms() runs on MTC_CT {
3399 var BSC_ConnHdlr vc_conn;
3400 f_init();
3401 vc_conn := f_start_handler(refers(f_tc_smpp_mt_sms), 45);
3402 vc_conn.done;
3403}
3404
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003405/***********************************************************************
3406 * USSD Testing
3407 ***********************************************************************/
3408
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003409private altstep as_unexp_gsup_or_bssap_msg()
3410runs on BSC_ConnHdlr {
3411 [] GSUP.receive {
3412 setverdict(fail, "Unknown/unexpected GSUP received");
3413 self.stop;
3414 }
3415 [] BSSAP.receive {
3416 setverdict(fail, "Unknown/unexpected BSSAP message received");
3417 self.stop;
3418 }
3419}
3420
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003421private function f_expect_gsup_msg(template GSUP_PDU msg,
3422 float T_val := 2.0)
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003423runs on BSC_ConnHdlr return GSUP_PDU {
3424 var GSUP_PDU gsup_msg_complete;
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003425 timer T := T_val;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003426
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003427 T.start;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003428 alt {
3429 [] GSUP.receive(msg) -> value gsup_msg_complete {
3430 setverdict(pass);
3431 }
3432 /* We don't expect anything else */
3433 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003434 [] T.timeout {
3435 setverdict(fail, "Timeout waiting for GSUP message: ", msg);
3436 }
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003437 }
3438
3439 return gsup_msg_complete;
3440}
3441
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003442private function f_expect_mt_dtap_msg(template PDU_ML3_NW_MS msg,
3443 float T_val := 2.0)
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003444runs on BSC_ConnHdlr return PDU_ML3_NW_MS {
3445 var PDU_DTAP_MT bssap_msg_complete;
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003446 timer T := T_val;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003447
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003448 T.start;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003449 alt {
3450 [] BSSAP.receive(tr_PDU_DTAP_MT(msg)) -> value bssap_msg_complete {
3451 setverdict(pass);
3452 }
3453 /* We don't expect anything else */
3454 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003455 [] T.timeout {
3456 setverdict(fail, "Timeout waiting for BSSAP message: ", msg);
3457 }
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003458 }
3459
3460 return bssap_msg_complete.dtap;
3461}
3462
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003463/* LU followed by MO USSD request */
Harald Weltee13cfb22019-04-23 16:52:02 +02003464friend function f_tc_lu_and_mo_ussd_single_request(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003465runs on BSC_ConnHdlr {
3466 f_init_handler(pars);
3467
3468 /* Perform location update */
3469 f_perform_lu();
3470
3471 /* Send CM Service Request for SS/USSD */
3472 f_establish_fully(EST_TYPE_SS_ACT);
3473
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003474 /* We need to inspect GSUP activity */
3475 f_create_gsup_expect(hex2str(g_pars.imsi));
3476
3477 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3478 invoke_id := 5, /* Phone may not start from 0 or 1 */
3479 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3480 ussd_string := "*#100#"
3481 );
3482
3483 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3484 invoke_id := 5, /* InvokeID shall be the same for both REQ and RSP */
3485 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3486 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
3487 )
3488
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003489 /* Compose a new SS/REGISTER message with request */
3490 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
3491 tid := 1, /* We just need a single transaction */
3492 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003493 facility := valueof(facility_req)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003494 );
3495
3496 /* Compose SS/RELEASE_COMPLETE template with expected response */
3497 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
3498 tid := 1, /* Response should arrive within the same transaction */
3499 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003500 facility := valueof(facility_rsp)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003501 );
3502
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003503 /* Compose expected MSC -> HLR message */
3504 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
3505 imsi := g_pars.imsi,
3506 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3507 ss := valueof(facility_req)
3508 );
3509
3510 /* To be used for sending response with correct session ID */
3511 var GSUP_PDU gsup_req_complete;
3512
3513 /* Request own number */
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003514 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003515 /* Expect GSUP message containing the SS payload */
3516 gsup_req_complete := f_expect_gsup_msg(gsup_req);
3517
3518 /* Compose the response from HLR using received session ID */
3519 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
3520 imsi := g_pars.imsi,
3521 sid := gsup_req_complete.ies[1].val.session_id,
3522 state := OSMO_GSUP_SESSION_STATE_END,
3523 ss := valueof(facility_rsp)
3524 );
3525
3526 /* Finally, HLR terminates the session */
3527 GSUP.send(gsup_rsp);
3528 /* Expect RELEASE_COMPLETE message with the response */
3529 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003530
3531 f_expect_clear();
3532}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003533testcase TC_lu_and_mo_ussd_single_request() runs on MTC_CT {
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003534 var BSC_ConnHdlr vc_conn;
3535 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003536 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_single_request), 46);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003537 vc_conn.done;
3538}
3539
Harald Weltee13cfb22019-04-23 16:52:02 +02003540
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003541/* LU followed by MT USSD notification */
Harald Weltee13cfb22019-04-23 16:52:02 +02003542friend function f_tc_lu_and_mt_ussd_notification(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003543runs on BSC_ConnHdlr {
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003544 timer T := 5.0;
3545
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003546 f_init_handler(pars);
3547
3548 /* Perform location update */
3549 f_perform_lu();
3550
Harald Welte6811d102019-04-14 22:23:14 +02003551 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003552
3553 /* We need to inspect GSUP activity */
3554 f_create_gsup_expect(hex2str(g_pars.imsi));
3555
3556 /* Facility IE with network-originated USSD notification */
3557 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3558 op_code := SS_OP_CODE_USS_NOTIFY,
3559 ussd_string := "Mahlzeit!"
3560 );
3561
3562 /* Facility IE with acknowledgment to the USSD notification */
3563 var template OCTN facility_rsp := enc_SS_FacilityInformation(
3564 /* In case of USSD notification, Return Result is empty */
3565 valueof(ts_SS_USSD_FACILITY_RETURN_RESULT_EMPTY())
3566 );
3567
3568 /* Compose a new MT SS/REGISTER message with USSD notification */
3569 var template PDU_ML3_NW_MS ussd_ntf := tr_ML3_MT_SS_REGISTER(
3570 tid := 0, /* FIXME: most likely, it should be 0 */
3571 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3572 facility := valueof(facility_req)
3573 );
3574
3575 /* Compose HLR -> MSC GSUP message */
3576 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3577 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003578 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003579 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3580 ss := valueof(facility_req)
3581 );
3582
3583 /* Send it to MSC and expect Paging Request */
3584 GSUP.send(gsup_req);
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003585 T.start;
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003586 alt {
Harald Weltee13cfb22019-04-23 16:52:02 +02003587 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
3588 setverdict(pass);
3589 }
Harald Welte62113fc2019-05-09 13:04:02 +02003590 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003591 setverdict(pass);
3592 }
3593 /* We don't expect anything else */
3594 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003595 [] T.timeout {
3596 setverdict(fail, "Timeout waiting for Paging Request");
3597 }
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003598 }
3599
3600 /* Send Paging Response and expect USSD notification */
3601 f_establish_fully(EST_TYPE_PAG_RESP);
3602 /* Expect MT REGISTER message with USSD notification */
3603 f_expect_mt_dtap_msg(ussd_ntf);
3604
3605 /* Compose a new MO SS/FACILITY message with empty response */
3606 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
3607 tid := 0, /* FIXME: it shall match the request tid */
3608 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3609 facility := valueof(facility_rsp)
3610 );
3611
3612 /* Compose expected MSC -> HLR GSUP message */
3613 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
3614 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003615 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003616 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3617 ss := valueof(facility_rsp)
3618 );
3619
3620 /* MS sends response to the notification */
3621 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
3622 /* Expect GSUP message containing the SS payload */
3623 f_expect_gsup_msg(gsup_rsp);
3624
3625 /* Compose expected MT SS/RELEASE COMPLETE message */
3626 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
3627 tid := 0, /* FIXME: it shall match the request tid */
3628 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3629 facility := omit
3630 );
3631
3632 /* Compose MSC -> HLR GSUP message */
3633 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
3634 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003635 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003636 state := OSMO_GSUP_SESSION_STATE_END
3637 );
3638
3639 /* Finally, HLR terminates the session */
3640 GSUP.send(gsup_term)
3641 /* Expect MT RELEASE COMPLETE without Facility IE */
3642 f_expect_mt_dtap_msg(ussd_term);
3643
3644 f_expect_clear();
3645}
3646testcase TC_lu_and_mt_ussd_notification() runs on MTC_CT {
3647 var BSC_ConnHdlr vc_conn;
3648 f_init();
3649 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_notification), 47);
3650 vc_conn.done;
3651}
3652
Harald Weltee13cfb22019-04-23 16:52:02 +02003653
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003654/* LU followed by MT call and MO USSD request during this call */
Harald Weltee13cfb22019-04-23 16:52:02 +02003655friend function f_tc_lu_and_mo_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003656runs on BSC_ConnHdlr {
3657 f_init_handler(pars);
3658
3659 /* Call parameters taken from f_tc_lu_and_mt_call */
3660 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003661
3662 /* Perform location update */
3663 f_perform_lu();
3664
3665 /* Establish a MT call */
3666 f_mt_call_establish(cpars);
3667
3668 /* Hold the call for some time */
3669 f_sleep(1.0);
3670
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003671 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3672 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3673 ussd_string := "*#100#"
3674 );
3675
3676 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3677 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3678 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
3679 )
3680
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003681 /* Compose a new SS/REGISTER message with request */
3682 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
3683 tid := 1, /* We just need a single transaction */
3684 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003685 facility := valueof(facility_req)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003686 );
3687
3688 /* Compose SS/RELEASE_COMPLETE template with expected response */
3689 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
3690 tid := 1, /* Response should arrive within the same transaction */
3691 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003692 facility := valueof(facility_rsp)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003693 );
3694
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003695 /* Compose expected MSC -> HLR message */
3696 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
3697 imsi := g_pars.imsi,
3698 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3699 ss := valueof(facility_req)
3700 );
3701
3702 /* To be used for sending response with correct session ID */
3703 var GSUP_PDU gsup_req_complete;
3704
3705 /* Request own number */
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003706 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003707 /* Expect GSUP message containing the SS payload */
3708 gsup_req_complete := f_expect_gsup_msg(gsup_req);
3709
3710 /* Compose the response from HLR using received session ID */
3711 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
3712 imsi := g_pars.imsi,
3713 sid := gsup_req_complete.ies[1].val.session_id,
3714 state := OSMO_GSUP_SESSION_STATE_END,
3715 ss := valueof(facility_rsp)
3716 );
3717
3718 /* Finally, HLR terminates the session */
3719 GSUP.send(gsup_rsp);
3720 /* Expect RELEASE_COMPLETE message with the response */
3721 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003722
3723 /* Hold the call for some time */
3724 f_sleep(1.0);
3725
3726 /* Release the call (does Clear Complete itself) */
3727 f_call_hangup(cpars, true);
3728}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003729testcase TC_lu_and_mo_ussd_during_mt_call() runs on MTC_CT {
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003730 var BSC_ConnHdlr vc_conn;
3731 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003732 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_during_mt_call), 48);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003733 vc_conn.done;
3734}
3735
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003736/* BSSMAP Clear Request in the middle of a call, see OS#3062 */
Harald Weltee13cfb22019-04-23 16:52:02 +02003737friend function f_tc_mo_cc_bssmap_clear(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003738 f_init_handler(pars);
3739 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02003740 cpars.ran_clear_when_alerting := true;
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003741
3742 f_perform_lu();
3743
Neels Hofmeyrde76f052019-02-26 05:02:46 +01003744 var default ccrel := activate(as_optional_cc_rel(cpars));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02003745 f_mo_call_establish(cpars);
3746 f_expect_clear()
Neels Hofmeyrde76f052019-02-26 05:02:46 +01003747 deactivate(ccrel);
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003748
3749 f_sleep(1.0);
3750}
3751testcase TC_mo_cc_bssmap_clear() runs on MTC_CT {
3752 var BSC_ConnHdlr vc_conn;
3753 f_init();
3754
3755 vc_conn := f_start_handler(refers(f_tc_mo_cc_bssmap_clear), 43);
3756 vc_conn.done;
3757}
3758
Harald Weltee13cfb22019-04-23 16:52:02 +02003759
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003760/* LU followed by MT call and MT USSD request during this call */
Harald Weltee13cfb22019-04-23 16:52:02 +02003761friend function f_tc_lu_and_mt_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003762runs on BSC_ConnHdlr {
3763 f_init_handler(pars);
3764
3765 /* Call parameters taken from f_tc_lu_and_mt_call */
3766 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003767
3768 /* Perform location update */
3769 f_perform_lu();
3770
3771 /* Establish a MT call */
3772 f_mt_call_establish(cpars);
3773
3774 /* Hold the call for some time */
3775 f_sleep(1.0);
3776
3777 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3778 op_code := SS_OP_CODE_USS_REQUEST,
3779 ussd_string := "Please type anything..."
3780 );
3781
3782 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3783 op_code := SS_OP_CODE_USS_REQUEST,
3784 ussd_string := "Nope."
3785 )
3786
3787 /* Compose MT SS/REGISTER message with network-originated request */
3788 var template (value) PDU_ML3_NW_MS ussd_req := ts_ML3_MT_SS_REGISTER(
3789 tid := 0, /* FIXME: most likely, it should be 0 */
3790 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3791 facility := valueof(facility_req)
3792 );
3793
3794 /* Compose HLR -> MSC GSUP message */
3795 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3796 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003797 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003798 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3799 ss := valueof(facility_req)
3800 );
3801
3802 /* Send it to MSC */
3803 GSUP.send(gsup_req);
3804 /* Expect MT REGISTER message with USSD request */
3805 f_expect_mt_dtap_msg(ussd_req);
3806
3807 /* Compose a new MO SS/FACILITY message with response */
3808 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
3809 tid := 0, /* FIXME: it shall match the request tid */
3810 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3811 facility := valueof(facility_rsp)
3812 );
3813
3814 /* Compose expected MSC -> HLR GSUP message */
3815 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
3816 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003817 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003818 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3819 ss := valueof(facility_rsp)
3820 );
3821
3822 /* MS sends response */
3823 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
3824 f_expect_gsup_msg(gsup_rsp);
3825
3826 /* Compose expected MT SS/RELEASE COMPLETE message */
3827 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
3828 tid := 0, /* FIXME: it shall match the request tid */
3829 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3830 facility := omit
3831 );
3832
3833 /* Compose MSC -> HLR GSUP message */
3834 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
3835 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003836 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003837 state := OSMO_GSUP_SESSION_STATE_END
3838 );
3839
3840 /* Finally, HLR terminates the session */
3841 GSUP.send(gsup_term);
3842 /* Expect MT RELEASE COMPLETE without Facility IE */
3843 f_expect_mt_dtap_msg(ussd_term);
3844
3845 /* Hold the call for some time */
3846 f_sleep(1.0);
3847
3848 /* Release the call (does Clear Complete itself) */
3849 f_call_hangup(cpars, true);
3850}
3851testcase TC_lu_and_mt_ussd_during_mt_call() runs on MTC_CT {
3852 var BSC_ConnHdlr vc_conn;
3853 f_init();
3854 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_during_mt_call), 49);
3855 vc_conn.done;
3856}
3857
Harald Weltee13cfb22019-04-23 16:52:02 +02003858
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07003859/* LU followed by MO USSD request and MO Release during transaction */
Harald Weltee13cfb22019-04-23 16:52:02 +02003860friend function f_tc_lu_and_mo_ussd_mo_release(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07003861runs on BSC_ConnHdlr {
3862 f_init_handler(pars);
3863
3864 /* Perform location update */
3865 f_perform_lu();
3866
3867 /* Send CM Service Request for SS/USSD */
3868 f_establish_fully(EST_TYPE_SS_ACT);
3869
3870 /* We need to inspect GSUP activity */
3871 f_create_gsup_expect(hex2str(g_pars.imsi));
3872
3873 var template OCTN facility_ms_req := f_USSD_FACILITY_IE_INVOKE(
3874 invoke_id := 1, /* Initial request */
3875 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3876 ussd_string := "*6766*266#"
3877 );
3878
3879 var template OCTN facility_net_req := f_USSD_FACILITY_IE_INVOKE(
3880 invoke_id := 2, /* Counter request */
3881 op_code := SS_OP_CODE_USS_REQUEST,
3882 ussd_string := "Password?!?"
3883 )
3884
3885 /* Compose MO SS/REGISTER message with request */
3886 var template (value) PDU_ML3_MS_NW ussd_ms_req := ts_ML3_MO_SS_REGISTER(
3887 tid := 1, /* We just need a single transaction */
3888 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3889 facility := valueof(facility_ms_req)
3890 );
3891
3892 /* Compose expected MSC -> HLR message */
3893 var template GSUP_PDU gsup_ms_req := tr_GSUP_PROC_SS_REQ(
3894 imsi := g_pars.imsi,
3895 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3896 ss := valueof(facility_ms_req)
3897 );
3898
3899 /* To be used for sending response with correct session ID */
3900 var GSUP_PDU gsup_ms_req_complete;
3901
3902 /* Initiate a new transaction */
3903 BSSAP.send(ts_PDU_DTAP_MO(ussd_ms_req));
3904 /* Expect GSUP request with original Facility IE */
3905 gsup_ms_req_complete := f_expect_gsup_msg(gsup_ms_req);
3906
3907 /* Compose the response from HLR using received session ID */
3908 var template (value) GSUP_PDU gsup_net_req := ts_GSUP_PROC_SS_REQ(
3909 imsi := g_pars.imsi,
3910 sid := gsup_ms_req_complete.ies[1].val.session_id,
3911 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3912 ss := valueof(facility_net_req)
3913 );
3914
3915 /* Compose expected MT SS/FACILITY template with counter request */
3916 var template PDU_ML3_NW_MS ussd_net_req := tr_ML3_MT_SS_FACILITY(
3917 tid := 1, /* Response should arrive within the same transaction */
3918 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3919 facility := valueof(facility_net_req)
3920 );
3921
3922 /* Send response over GSUP */
3923 GSUP.send(gsup_net_req);
3924 /* Expect MT SS/FACILITY message with counter request */
3925 f_expect_mt_dtap_msg(ussd_net_req);
3926
3927 /* Compose MO SS/RELEASE COMPLETE */
3928 var template (value) PDU_ML3_MS_NW ussd_abort := ts_ML3_MO_SS_RELEASE_COMPLETE(
3929 tid := 1, /* Response should arrive within the same transaction */
3930 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3931 facility := omit
3932 /* TODO: cause? */
3933 );
3934
3935 /* Compose expected HLR -> MSC abort message */
3936 var template GSUP_PDU gsup_abort := tr_GSUP_PROC_SS_REQ(
3937 imsi := g_pars.imsi,
3938 sid := gsup_ms_req_complete.ies[1].val.session_id,
3939 state := OSMO_GSUP_SESSION_STATE_END
3940 );
3941
3942 /* Abort transaction */
3943 BSSAP.send(ts_PDU_DTAP_MO(ussd_abort));
3944 /* Expect GSUP message indicating abort */
3945 f_expect_gsup_msg(gsup_abort);
3946
3947 f_expect_clear();
3948}
3949testcase TC_lu_and_mo_ussd_mo_release() runs on MTC_CT {
3950 var BSC_ConnHdlr vc_conn;
3951 f_init();
3952 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_mo_release), 50);
3953 vc_conn.done;
3954}
3955
Harald Weltee13cfb22019-04-23 16:52:02 +02003956
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003957/* LU followed by MO USSD request and MT Release due to timeout */
Harald Weltee13cfb22019-04-23 16:52:02 +02003958friend function f_tc_lu_and_ss_session_timeout(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003959runs on BSC_ConnHdlr {
3960 f_init_handler(pars);
3961
3962 /* Perform location update */
3963 f_perform_lu();
3964
3965 /* Send CM Service Request for SS/USSD */
3966 f_establish_fully(EST_TYPE_SS_ACT);
3967
3968 /* We need to inspect GSUP activity */
3969 f_create_gsup_expect(hex2str(g_pars.imsi));
3970
3971 var template OCTN facility_ms_req := f_USSD_FACILITY_IE_INVOKE(
3972 invoke_id := 1,
3973 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3974 ussd_string := "#release_me");
3975
3976 /* Compose MO SS/REGISTER message with request */
3977 var template (value) PDU_ML3_MS_NW ussd_ms_req := ts_ML3_MO_SS_REGISTER(
3978 tid := 1, /* An arbitrary transaction identifier */
3979 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3980 facility := valueof(facility_ms_req));
3981
3982 /* Compose expected MSC -> HLR message */
3983 var template GSUP_PDU gsup_ms_req := tr_GSUP_PROC_SS_REQ(
3984 imsi := g_pars.imsi,
3985 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3986 ss := valueof(facility_ms_req));
3987
3988 /* To be used for sending response with correct session ID */
3989 var GSUP_PDU gsup_ms_req_complete;
3990
3991 /* Initiate a new SS transaction */
3992 BSSAP.send(ts_PDU_DTAP_MO(ussd_ms_req));
3993 /* Expect GSUP request with original Facility IE */
3994 gsup_ms_req_complete := f_expect_gsup_msg(gsup_ms_req);
3995
3996 /* Don't respond, wait for timeout */
3997 f_sleep(3.0);
3998
3999 var template PDU_ML3_NW_MS dtap_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
4000 tid := 1, /* Should match the request's tid */
4001 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
4002 cause := *, /* TODO: expect some specific value */
4003 facility := omit);
4004
4005 var template GSUP_PDU gsup_rel := tr_GSUP_PROC_SS_ERR(
4006 imsi := g_pars.imsi,
4007 sid := gsup_ms_req_complete.ies[1].val.session_id,
4008 state := OSMO_GSUP_SESSION_STATE_END,
4009 cause := ?); /* TODO: expect some specific value */
4010
4011 /* Expect release on both interfaces */
4012 interleave {
4013 [] BSSAP.receive(tr_PDU_DTAP_MT(dtap_rel)) { };
4014 [] GSUP.receive(gsup_rel) { };
4015 }
4016
4017 f_expect_clear();
4018 setverdict(pass);
4019}
4020testcase TC_lu_and_ss_session_timeout() runs on MTC_CT {
4021 var BSC_ConnHdlr vc_conn;
4022 f_init();
Vadim Yanitskiy36d28dd2018-12-03 02:45:45 +07004023 f_vty_config(MSCVTY, "msc", "ncss guard-timeout 3");
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07004024 vc_conn := f_start_handler(refers(f_tc_lu_and_ss_session_timeout), 51);
4025 vc_conn.done;
Vadim Yanitskiy36d28dd2018-12-03 02:45:45 +07004026 f_vty_config(MSCVTY, "msc", "ncss guard-timeout 0");
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07004027}
4028
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07004029/* MT (network-originated) USSD for unknown subscriber */
4030friend function f_tc_mt_ussd_for_unknown_subscr(charstring id, BSC_ConnHdlrPars pars)
4031runs on BSC_ConnHdlr {
4032 var hexstring imsi := '000000000000000'H; /* Some unknown IMSI */
4033 var OCT4 sid := '20000222'O;
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07004034
4035 f_init_handler(pars);
4036 f_ran_register_imsi(imsi, 'FFFFFFFF'O);
4037 f_create_gsup_expect(hex2str(imsi));
4038
4039 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
4040 imsi := imsi,
4041 sid := sid,
4042 state := OSMO_GSUP_SESSION_STATE_BEGIN,
4043 ss := f_rnd_octstring(23)
4044 );
4045
4046 /* Error with cause GMM_CAUSE_IMSI_UNKNOWN */
4047 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
4048 imsi := imsi,
4049 sid := sid,
4050 state := OSMO_GSUP_SESSION_STATE_END,
4051 cause := 2 /* FIXME: introduce an enumerated type! */
4052 );
4053
4054 /* Initiate a MT USSD notification */
4055 GSUP.send(gsup_req);
4056
4057 /* Expect GSUP PROC_SS_ERROR message */
Vadim Yanitskiy851798c2019-06-15 14:22:28 +07004058 f_expect_gsup_msg(gsup_rsp);
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07004059}
4060testcase TC_mt_ussd_for_unknown_subscr() runs on MTC_CT {
4061 var BSC_ConnHdlr vc_conn;
4062 f_init();
4063 vc_conn := f_start_handler(refers(f_tc_mt_ussd_for_unknown_subscr), 0);
4064 vc_conn.done;
4065}
4066
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07004067/* MO (mobile-originated) SS/USSD for unknown transaction */
4068friend function f_tc_mo_ussd_for_unknown_trans(charstring id, BSC_ConnHdlrPars pars)
4069runs on BSC_ConnHdlr {
4070 f_init_handler(pars);
4071
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01004072 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07004073 f_create_gsup_expect(hex2str(g_pars.imsi));
4074
4075 /* Perform location update */
4076 f_perform_lu();
4077
4078 /* Send CM Service Request for SS/USSD */
4079 f_establish_fully(EST_TYPE_SS_ACT);
4080
4081 /* GSM 04.80 FACILITY message for a non-existing transaction */
4082 var template (value) PDU_ML3_MS_NW mo_ss_fac := ts_ML3_MO_SS_FACILITY(
4083 tid := 1, /* An arbitrary transaction identifier */
4084 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
4085 facility := f_rnd_octstring(23) /* We don't care about the Facility IE */
4086 );
4087
4088 /* GSM 04.80 RELEASE COMPLETE message for a non-existing transaction */
4089 var template (value) PDU_ML3_MS_NW mo_ss_rel := ts_ML3_MO_SS_RELEASE_COMPLETE(
4090 tid := 1, /* An arbitrary transaction identifier */
4091 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
4092 facility := f_rnd_octstring(23) /* We don't care about the Facility IE */
4093 );
4094
4095 /* Expected response from the network */
4096 var template PDU_ML3_NW_MS mt_ss_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
4097 tid := 1, /* Same as in the FACILITY message */
4098 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
4099 facility := omit
4100 );
4101
4102 /* Send GSM 04.80 FACILITY for non-existing transaction */
4103 BSSAP.send(ts_PDU_DTAP_MO(mo_ss_fac));
4104
4105 /* Expect GSM 04.80 RELEASE COMPLETE message */
4106 f_expect_mt_dtap_msg(mt_ss_rel);
4107 f_expect_clear();
4108
4109 /* Send another CM Service Request for SS/USSD */
4110 f_establish_fully(EST_TYPE_SS_ACT);
4111
4112 /* Send GSM 04.80 RELEASE COMPLETE for non-existing transaction */
4113 BSSAP.send(ts_PDU_DTAP_MO(mo_ss_rel));
4114
4115 /* Expect GSM 04.80 RELEASE COMPLETE message */
4116 f_expect_mt_dtap_msg(mt_ss_rel);
4117 f_expect_clear();
4118}
4119testcase TC_mo_ussd_for_unknown_trans() runs on MTC_CT {
4120 var BSC_ConnHdlr vc_conn;
4121 f_init();
4122 vc_conn := f_start_handler(refers(f_tc_mo_ussd_for_unknown_trans), 111);
4123 vc_conn.done;
4124}
4125
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07004126/* MT (network-originated) USSD for unknown session */
4127friend function f_tc_proc_ss_for_unknown_session(charstring id, BSC_ConnHdlrPars pars)
4128runs on BSC_ConnHdlr {
4129 var OCT4 sid := '20000333'O;
4130
4131 f_init_handler(pars);
4132
4133 /* Perform location update */
4134 f_perform_lu();
4135
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01004136 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07004137 f_create_gsup_expect(hex2str(g_pars.imsi));
4138
4139 /* Request referencing a non-existing SS session */
4140 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
4141 imsi := g_pars.imsi,
4142 sid := sid,
4143 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
4144 ss := f_rnd_octstring(23)
4145 );
4146
4147 /* Error with some cause value */
4148 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
4149 imsi := g_pars.imsi,
4150 sid := sid,
4151 state := OSMO_GSUP_SESSION_STATE_END,
4152 cause := ? /* FIXME: introduce an enumerated type! */
4153 );
4154
4155 /* Initiate a MT USSD notification */
4156 GSUP.send(gsup_req);
4157
4158 /* Expect GSUP PROC_SS_ERROR message */
4159 f_expect_gsup_msg(gsup_rsp);
4160}
4161testcase TC_proc_ss_for_unknown_session() runs on MTC_CT {
4162 var BSC_ConnHdlr vc_conn;
4163 f_init();
4164 vc_conn := f_start_handler(refers(f_tc_proc_ss_for_unknown_session), 110);
4165 vc_conn.done;
4166}
4167
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07004168/* MT (network-originated) USSD and no response to Paging Request */
4169friend function f_tc_proc_ss_paging_fail(charstring id, BSC_ConnHdlrPars pars)
4170runs on BSC_ConnHdlr {
4171 timer TP := 2.0; /* Paging timer */
4172
4173 f_init_handler(pars);
4174
4175 /* Perform location update */
4176 f_perform_lu();
4177
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01004178 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07004179 f_create_gsup_expect(hex2str(g_pars.imsi));
4180
4181 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
4182 imsi := g_pars.imsi,
4183 sid := '20000444'O,
4184 state := OSMO_GSUP_SESSION_STATE_BEGIN,
4185 ss := f_rnd_octstring(23)
4186 );
4187
4188 /* Error with some cause value */
4189 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
4190 imsi := g_pars.imsi,
4191 sid := '20000444'O,
4192 state := OSMO_GSUP_SESSION_STATE_END,
4193 cause := ? /* FIXME: introduce an enumerated type! */
4194 );
4195
4196 /* Initiate a MT USSD notification */
4197 GSUP.send(gsup_req);
4198
4199 /* Send it to MSC and expect Paging Request */
4200 TP.start;
4201 alt {
4202 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
4203 setverdict(pass);
4204 }
4205 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
4206 setverdict(pass);
4207 }
4208 /* We don't expect anything else */
4209 [] as_unexp_gsup_or_bssap_msg();
4210 [] TP.timeout {
4211 setverdict(fail, "Timeout waiting for Paging Request");
4212 }
4213 }
4214
Vadim Yanitskiyd24b5252019-10-02 00:04:51 +07004215 /* Wait up to 20 seconds for GSUP PROC_SS_ERROR message.
4216 * OsmoMSC waits for Paging Response 10 seconds by default. */
4217 f_expect_gsup_msg(gsup_rsp, T_val := 20.0);
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07004218}
4219testcase TC_proc_ss_paging_fail() runs on MTC_CT {
4220 var BSC_ConnHdlr vc_conn;
4221 f_init();
4222 vc_conn := f_start_handler(refers(f_tc_proc_ss_paging_fail), 101);
4223 vc_conn.done;
4224}
4225
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07004226/* MT (network-originated) USSD followed by immediate abort */
4227friend function f_tc_proc_ss_abort(charstring id, BSC_ConnHdlrPars pars)
4228runs on BSC_ConnHdlr {
4229 var octetstring facility := f_rnd_octstring(23);
4230 var OCT4 sid := '20000555'O;
4231 timer TP := 2.0;
4232
4233 f_init_handler(pars);
4234
4235 /* Perform location update */
4236 f_perform_lu();
4237
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01004238 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07004239 f_create_gsup_expect(hex2str(g_pars.imsi));
4240
4241 /* PROC_SS_REQ initiates a mobile-originated SS/USSD session */
4242 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
4243 imsi := g_pars.imsi, sid := sid,
4244 state := OSMO_GSUP_SESSION_STATE_BEGIN,
4245 ss := facility
4246 );
4247
4248 /* On the MS side, we expect GSM 04.80 REGISTER message */
4249 var template PDU_ML3_NW_MS dtap_reg := tr_ML3_MT_SS_REGISTER(
4250 tid := 0, /* Most likely, it should be 0 */
4251 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
4252 facility := facility
4253 );
4254
4255 /* PROC_SS_ERR with SESSION_STATE_END terminates the SS/USSD session */
4256 var template (value) GSUP_PDU gsup_abort := ts_GSUP_PROC_SS_ERR(
4257 imsi := g_pars.imsi, sid := sid,
4258 state := OSMO_GSUP_SESSION_STATE_END,
4259 cause := 0 /* FIXME: introduce an enumerated type! */
4260 );
4261
4262 /* On the MS side, we expect GSM 04.80 REGISTER message */
4263 var template PDU_ML3_NW_MS dtap_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
4264 tid := 0, /* Most likely, it should be 0 */
4265 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
4266 cause := *, /* FIXME: expect some specific cause value */
4267 facility := omit
4268 );
4269
4270 /* Initiate a MT USSD with random payload */
4271 GSUP.send(gsup_req);
4272
4273 /* Expect Paging Request */
4274 TP.start;
4275 alt {
4276 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
4277 setverdict(pass);
4278 }
4279 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
4280 setverdict(pass);
4281 }
4282 /* We don't expect anything else */
4283 [] as_unexp_gsup_or_bssap_msg();
4284 [] TP.timeout {
4285 setverdict(fail, "Timeout waiting for Paging Request");
4286 }
4287 }
4288
4289 /* Send Paging Response and establish connection */
4290 f_establish_fully(EST_TYPE_PAG_RESP);
4291 /* Expect MT REGISTER message with random facility */
4292 f_expect_mt_dtap_msg(dtap_reg);
4293
4294 /* HLR/EUSE decides to abort the session even
4295 * before getting any response from the MS */
4296 /* Initiate a MT USSD with random payload */
4297 GSUP.send(gsup_abort);
4298
4299 /* Expect RELEASE COMPLETE on ths MS side */
4300 f_expect_mt_dtap_msg(dtap_rel);
4301
4302 f_expect_clear();
4303}
4304testcase TC_proc_ss_abort() runs on MTC_CT {
4305 var BSC_ConnHdlr vc_conn;
4306 f_init();
4307 vc_conn := f_start_handler(refers(f_tc_proc_ss_abort), 102);
4308 vc_conn.done;
4309}
4310
Harald Weltee13cfb22019-04-23 16:52:02 +02004311
Vadim Yanitskiy1c9754d2020-01-07 21:56:55 +01004312/* Verify multiple concurrent MO SS/USSD transactions
4313 * (one subscriber - one transaction) */
4314testcase TC_multi_lu_and_mo_ussd() runs on MTC_CT {
4315 var BSC_ConnHdlr vc_conn[16];
4316 var integer i;
4317
4318 f_init();
4319
4320 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
4321 vc_conn[i] := f_start_handler(refers(f_tc_lu_and_mo_ussd_single_request), 210 + i);
4322 }
4323
4324 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
4325 vc_conn[i].done;
4326 }
4327}
4328
4329/* Verify multiple concurrent MT SS/USSD transactions
4330 * (one subscriber - one transaction) */
4331testcase TC_multi_lu_and_mt_ussd() runs on MTC_CT {
4332 var BSC_ConnHdlr vc_conn[16];
4333 var integer i;
4334 var OCT4 sid;
4335
4336 f_init();
4337
4338 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
4339 sid := '200001'O & int2oct(i, 1); /* All transactions must use different session ID */
4340 vc_conn[i] := f_start_handler_with_pars(refers(f_tc_lu_and_mt_ussd_notification),
4341 f_init_pars(226 + i, gsup_sid := sid));
4342 }
4343
4344 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
4345 vc_conn[i].done;
4346 }
4347}
4348
4349
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004350/* A5/1 only permitted on network side; attempt an invalid CIPHER MODE COMPLETE with A5/3 which MSC should reject. */
4351private function f_tc_cipher_complete_with_invalid_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4352 pars.net.expect_auth := true;
4353 pars.net.expect_ciph := true;
4354 pars.net.kc_support := '02'O; /* A5/1 only */
4355 f_init_handler(pars);
4356
4357 g_pars.vec := f_gen_auth_vec_2g();
4358
4359 /* Can't use f_perform_lu() directly. Code below is based on it. */
4360
4361 /* tell GSUP dispatcher to send this IMSI to us */
4362 f_create_gsup_expect(hex2str(g_pars.imsi));
4363
4364 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
4365 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
Harald Weltedceacc72019-04-21 20:58:35 +02004366 f_cl3_or_initial_ue(l3_lu);
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004367
4368 f_mm_auth();
4369
4370 var OCT1 a5_net := f_alg_mask_from_cm(g_pars.cm2);
4371 var OCT1 a5_intersect := g_pars.net.kc_support and4b a5_net;
4372 alt {
4373 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(a5_intersect, g_pars.vec.kc)) {
4374 BSSAP.send(ts_BSSMAP_CipherModeCompl(int2oct(4 /* "accept" A5/3 */, 1)));
4375 }
4376 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?, g_pars.vec.kc)) {
4377 setverdict(fail, "Wrong ciphering algorithm mask in CiphModCmd");
4378 mtc.stop;
4379 }
4380 [] BSSAP.receive {
4381 setverdict(fail, "Unknown/unexpected BSSAP received");
4382 mtc.stop;
4383 }
4384 }
Harald Welte79f1e452020-08-18 22:55:02 +02004385 f_expect_common_id();
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004386
4387 /* Expect LU reject from MSC. */
4388 alt {
4389 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
4390 setverdict(pass);
4391 }
4392 [] BSSAP.receive {
4393 setverdict(fail, "Unknown/unexpected BSSAP received");
4394 mtc.stop;
4395 }
4396 }
Stefan Sperlingc620b352018-12-18 17:23:36 +01004397 f_expect_clear();
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004398}
4399
4400testcase TC_cipher_complete_with_invalid_cipher() runs on MTC_CT {
4401 var BSC_ConnHdlr vc_conn;
4402 f_init();
4403 f_vty_config(MSCVTY, "network", "encryption a5 1");
4404
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02004405 vc_conn := f_start_handler(refers(f_tc_cipher_complete_with_invalid_cipher), 52, verify_cell_id := false);
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004406 vc_conn.done;
4407}
4408
Harald Welteb2284bd2019-05-10 11:30:43 +02004409/* Location Update with invalid (non-matching) MCC/MNC reported on BSSMAP level from BSC */
4410friend function f_tc_lu_with_invalid_mcc_mnc(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4411 f_init_handler(pars);
4412
4413 /* tell GSUP dispatcher to send this IMSI to us */
4414 f_create_gsup_expect(hex2str(g_pars.imsi));
4415
4416 /* modify the cell ID which will be used to construct the COMPLELTE L3 or InitialUE */
4417 g_pars.cell_id := valueof(ts_CellId_CGI('333'H, '22'H, 23, 42));
4418
4419 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
4420 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
4421 f_cl3_or_initial_ue(l3_lu);
Harald Welte79f1e452020-08-18 22:55:02 +02004422 f_expect_common_id();
Harald Welteb2284bd2019-05-10 11:30:43 +02004423
4424 /* Expect LU reject from MSC. */
4425 alt {
4426 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
4427 setverdict(pass);
4428 }
4429 [] BSSAP.receive {
4430 setverdict(fail, "Unknown/unexpected BSSAP received");
4431 mtc.stop;
4432 }
4433 }
Eric Wild85cc1612022-03-30 01:44:29 +02004434 f_expect_clear(verify_vlr_cell_id:=false);
Harald Welteb2284bd2019-05-10 11:30:43 +02004435}
4436testcase TC_lu_with_invalid_mcc_mnc() runs on MTC_CT {
4437 var BSC_ConnHdlr vc_conn;
4438 f_init();
4439 vc_conn := f_start_handler(refers(f_tc_lu_with_invalid_mcc_mnc), 54);
4440 vc_conn.done;
4441}
4442
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01004443private function f_tc_cipher_complete_without_alg(charstring id, BSC_ConnHdlrPars pars, octetstring kc_support) runs on BSC_ConnHdlr {
4444 pars.net.expect_auth := true;
4445 pars.net.expect_ciph := true;
4446 pars.net.kc_support := kc_support;
4447 f_init_handler(pars);
4448
4449 g_pars.vec := f_gen_auth_vec_2g();
4450
4451 /* Can't use f_perform_lu() directly. Code below is based on it. */
4452
4453 /* tell GSUP dispatcher to send this IMSI to us */
4454 f_create_gsup_expect(hex2str(g_pars.imsi));
4455
4456 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
4457 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
4458 f_cl3_or_initial_ue(l3_lu);
4459
4460 f_mm_auth();
4461
4462 var OCT1 a5_net := f_alg_mask_from_cm(g_pars.cm2);
4463 var OCT1 a5_intersect := g_pars.net.kc_support and4b a5_net;
4464 alt {
4465 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(a5_intersect, g_pars.vec.kc)) {
4466 BSSAP.send(ts_BSSMAP_CipherModeComplAlg(omit));
4467 }
4468 [] BSSAP.receive(tr_BSSMAP_ClassmarkReq) {
4469 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
4470 repeat;
4471 }
4472 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?, g_pars.vec.kc)) {
4473 setverdict(fail, "Wrong ciphering algorithm mask in CiphModCmd");
4474 mtc.stop;
4475 }
4476 [] BSSAP.receive {
4477 setverdict(fail, "Unknown/unexpected BSSAP received");
4478 mtc.stop;
4479 }
4480 }
Harald Welte79f1e452020-08-18 22:55:02 +02004481 f_expect_common_id();
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01004482
4483 /* TODO: Verify MSC is using the best cipher available! How? */
4484
4485 f_msc_lu_hlr();
Neels Hofmeyre860fc42022-10-05 01:15:54 +02004486 as_accept_reject_lu();
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01004487 f_expect_clear();
4488 setverdict(pass);
4489}
4490
4491/* A5/1 only permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
4492private function f_tc_cipher_complete_1_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4493 f_tc_cipher_complete_without_alg(id, pars, '02'O /* A5/1 only */);
4494}
4495
4496/* A5/3 only permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
4497private function f_tc_cipher_complete_3_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4498 f_tc_cipher_complete_without_alg(id, pars, '08'O /* A5/3 only */);
4499}
4500
4501/* A5/1 + A5/3 permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
4502private function f_tc_cipher_complete_13_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4503 f_tc_cipher_complete_without_alg(id, pars, '0A'O /* A5/1 and A5/3 enabled */);
4504}
4505
4506testcase TC_cipher_complete_1_without_cipher() runs on MTC_CT {
4507 var BSC_ConnHdlr vc_conn;
4508 f_init();
4509 f_vty_config(MSCVTY, "network", "encryption a5 1");
4510
4511 vc_conn := f_start_handler(refers(f_tc_cipher_complete_1_without_cipher), 53);
4512 vc_conn.done;
4513}
4514
4515testcase TC_cipher_complete_3_without_cipher() runs on MTC_CT {
4516 var BSC_ConnHdlr vc_conn;
4517 f_init();
4518 f_vty_config(MSCVTY, "network", "encryption a5 3");
4519
4520 vc_conn := f_start_handler(refers(f_tc_cipher_complete_3_without_cipher), 54);
4521 vc_conn.done;
4522}
4523
4524testcase TC_cipher_complete_13_without_cipher() runs on MTC_CT {
4525 var BSC_ConnHdlr vc_conn;
4526 f_init();
4527 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
4528
4529 vc_conn := f_start_handler(refers(f_tc_cipher_complete_13_without_cipher), 55);
4530 vc_conn.done;
4531}
Harald Welteb2284bd2019-05-10 11:30:43 +02004532
Harald Weltef640a012018-04-14 17:49:21 +02004533/* TODO (SMS):
4534 * different user data lengths
4535 * SMPP transaction mode with unsuccessful delivery
4536 * queued MT-SMS with no paging response + later delivery
4537 * different data coding schemes
4538 * multi-part SMS
4539 * user-data headers
4540 * TP-PID for SMS to SIM
4541 * behavior if SMS memory is full + RP-SMMA
4542 * delivery reports
4543 * SMPP osmocom extensions
4544 * more-messages-to-send
4545 * SMS during ongoing call (SACCH/SAPI3)
4546 */
4547
4548/* TODO (General):
Harald Welteba7b6d92018-01-23 21:32:34 +01004549 * continue to send repeated MO signalling messages to keep channel open: does MSC tmeout?
4550 * malformed messages (missing IE, invalid message type): properly rejected?
4551 * MT call while LU or is ongoing: Do we use existing lchan or page while lchan active?
4552 * 3G/2G auth permutations
4553 * encryption algorithms vs. classmark vs. vty config
Harald Welteba7b6d92018-01-23 21:32:34 +01004554 * send new transaction after/during clear (like SMS, ...)
Harald Welte45164da2018-01-24 12:51:27 +01004555 * too long L3 INFO in DTAP
4556 * too long / padded BSSAP
4557 * too long / short TLV values
Harald Welteba7b6d92018-01-23 21:32:34 +01004558 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01004559
Harald Weltee13cfb22019-04-23 16:52:02 +02004560/***********************************************************************
4561 * SGsAP Testing
4562 ***********************************************************************/
4563
Philipp Maier948747b2019-04-02 15:22:33 +02004564/* Check if a subscriber exists in the VLR */
4565private function f_ctrl_subscr_in_vlr(charstring imsi_or_msisdn) runs on BSC_ConnHdlr return boolean {
4566
4567 var CtrlValue active_subsribers;
4568 var integer rc;
4569 active_subsribers := f_ctrl_get(IPA_CTRL, "subscriber-list-active-v1");
4570
4571 rc := f_strstr(active_subsribers, imsi_or_msisdn);
4572 if (rc < 0) {
4573 return false;
4574 }
4575
4576 return true;
4577}
4578
Pau Espin Pedrolcefe9da2021-07-02 18:38:27 +02004579/* Perform a Location Update at the A-Interface and run some checks to confirm
Harald Welte4263c522018-12-06 11:56:27 +01004580 * that everything is back to normal. */
4581private function f_sgsap_bssmap_screening() runs on BSC_ConnHdlr {
4582 var SmsParameters spars := valueof(t_SmsPars);
4583
Pau Espin Pedrol7593a8a2021-07-02 18:55:16 +02004584 /* From now on, since we initiated LU from A-Interface, we expect no
4585 * LastEutranPLMNId on Common Id, since the SGs interface should be gone
4586 */
4587 g_pars.common_id_last_eutran_plmn := omit;
4588
Harald Welte4263c522018-12-06 11:56:27 +01004589 /* Perform a location update, the SGs association is expected to fall
4590 * back to NULL */
4591 f_perform_lu();
4592 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4593
4594 /* Trigger a paging request and expect the paging on BSSMAP, this is
4595 * to make sure that pagings are sent throught the A-Interface again
4596 * and not throught the SGs interface.*/
Harald Welte6811d102019-04-14 22:23:14 +02004597 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Welte4263c522018-12-06 11:56:27 +01004598 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4599
4600 alt {
Harald Weltee13cfb22019-04-23 16:52:02 +02004601 [g_pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)); {
4602 setverdict(pass);
4603 }
Harald Welte62113fc2019-05-09 13:04:02 +02004604 [not g_pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
Harald Welte4263c522018-12-06 11:56:27 +01004605 setverdict(pass);
4606 }
4607 [] SGsAP.receive {
4608 setverdict(fail, "Received unexpected message on SGs");
4609 }
4610 }
4611
4612 /* Send an SMS to make sure that also payload messages are routed
4613 * throught the A-Interface again */
4614 f_establish_fully(EST_TYPE_MO_SMS);
4615 f_mo_sms(spars);
4616 f_expect_clear();
4617}
4618
4619private function f_tc_sgsap_reset(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4620 var charstring vlr_name;
4621 f_init_handler(pars);
4622
4623 vlr_name := f_sgsap_reset_mme(mp_mme_name);
4624 log("VLR name: ", vlr_name);
4625 setverdict(pass);
Neels Hofmeyrc0b520d2019-03-06 15:35:50 +01004626 f_sleep(1.0);
Harald Welte4263c522018-12-06 11:56:27 +01004627}
4628
4629testcase TC_sgsap_reset() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004630 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004631 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004632 f_init(1, true);
4633 pars := f_init_pars(11810, true);
4634 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_reset), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004635 vc_conn.done;
4636}
4637
4638/* like f_mm_auth() but for SGs */
4639function f_mm_auth_sgs() runs on BSC_ConnHdlr {
4640 if (g_pars.net.expect_auth) {
4641 g_pars.vec := f_gen_auth_vec_3g();
4642 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G3G(g_pars.vec.rand,
4643 g_pars.vec.sres,
4644 g_pars.vec.kc,
4645 g_pars.vec.ik,
4646 g_pars.vec.ck,
4647 g_pars.vec.autn,
4648 g_pars.vec.res));
4649 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
4650 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
4651 SGsAP.receive(tr_ML3_MT_MM_AUTH_REQ_3G(g_pars.vec.rand, g_pars.vec.autn));
4652 SGsAP.send(ts_ML3_MT_MM_AUTH_RESP_3G(g_pars.vec.sres, g_pars.vec.res));
4653 }
4654}
4655
4656/* like f_perform_lu(), but on SGs rather than BSSAP */
4657function f_sgs_perform_lu() runs on BSC_ConnHdlr {
4658 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4659 var PDU_SGsAP lur;
4660 var PDU_SGsAP lua;
4661 var PDU_SGsAP mm_info;
4662 var octetstring mm_info_dtap;
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004663 var GsmMcc mcc;
4664 var GsmMnc mnc;
4665 var template (omit) TrackingAreaIdentityValue tai := omit;
Harald Welte4263c522018-12-06 11:56:27 +01004666
4667 /* tell GSUP dispatcher to send this IMSI to us */
4668 f_create_gsup_expect(hex2str(g_pars.imsi));
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004669 if (g_pars.common_id_last_eutran_plmn != omit) {
4670 f_dec_mcc_mnc(g_pars.common_id_last_eutran_plmn, mcc, mnc);
4671 tai := ts_SGsAP_TAI(mcc, mnc, 555);
4672 }
Harald Welte4263c522018-12-06 11:56:27 +01004673 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
Pau Espin Pedrol3768a6f2021-04-28 14:24:23 +02004674 ts_SGsAP_LAI('901'H, '70'H, 2342),
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004675 tai));
Harald Welte4263c522018-12-06 11:56:27 +01004676 /* Old LAI, if MS sends it */
4677 /* TMSI status, if MS has no valid TMSI */
4678 /* IMEISV, if it supports "automatic device detection" */
4679 /* TAI, if available in MME */
4680 /* E-CGI, if available in MME */
4681 SGsAP.send(lur);
4682
4683 /* FIXME: is this really done over SGs? The Ue is already authenticated
4684 * via the MME ... */
4685 f_mm_auth_sgs();
4686
4687 /* Expect MSC to perform LU with HLR */
4688 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4689 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
4690 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
4691 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
4692
4693 alt {
4694 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) -> value lua {
4695 if (isvalue(lua.sGsAP_LOCATION_UPDATE_ACCEPT.newTMSIorIMSI.iD.iD.tmsi_ptmsi.octets)) {
4696 g_pars.tmsi :=lua.sGsAP_LOCATION_UPDATE_ACCEPT.newTMSIorIMSI.iD.iD.tmsi_ptmsi.octets
4697 SGsAP.send(ts_SGsAP_TMSI_REALL_CMPL(g_pars.imsi));
4698 }
4699 setverdict(pass);
4700 }
4701 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4702 setverdict(fail, "Received LU-REJECT instead of ACCEPT");
4703 }
4704 [] SGsAP.receive {
4705 setverdict(fail, "Received unexpected message on SGs");
4706 }
4707 }
4708
4709 /* Check MM information */
4710 if (mp_mm_info == true) {
4711 SGsAP.receive(tr_SGsAP_MM_INFO_REQ(g_pars.imsi, ?)) -> value mm_info;
4712 mm_info_dtap := '0532'O & mm_info.sGsAP_MM_INFORMATION_REQUEST.mM_Information.information;
4713 if (not match(dec_PDU_ML3_NW_MS(mm_info_dtap), tr_ML3_MT_MM_Info)) {
4714 setverdict(fail, "Unexpected MM Information");
4715 }
4716 }
4717
4718 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4719}
4720
4721private function f_tc_sgsap_lu(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4722 f_init_handler(pars);
4723 f_sgs_perform_lu();
4724 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4725
4726 f_sgsap_bssmap_screening();
4727
4728 setverdict(pass);
4729}
4730testcase TC_sgsap_lu() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004731 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004732 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004733 f_init(1, true);
4734 pars := f_init_pars(11811, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004735 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004736 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004737 vc_conn.done;
4738}
4739
4740/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
4741private function f_tc_sgsap_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4742 f_init_handler(pars);
4743 var PDU_SGsAP lur;
4744
4745 f_create_gsup_expect(hex2str(g_pars.imsi));
4746 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4747 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
4748 ts_SGsAP_LAI('901'H, '70'H, 2342)));
4749 SGsAP.send(lur);
4750
4751 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4752 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
4753 alt {
4754 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4755 setverdict(pass);
4756 }
4757 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) {
4758 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
4759 mtc.stop;
4760 }
4761 [] SGsAP.receive {
4762 setverdict(fail, "Received unexpected message on SGs");
4763 }
4764 }
4765
4766 f_sgsap_bssmap_screening();
4767
4768 setverdict(pass);
4769}
4770testcase TC_sgsap_lu_imsi_reject() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004771 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004772 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004773 f_init(1, true);
4774 pars := f_init_pars(11812, true);
Harald Welte4263c522018-12-06 11:56:27 +01004775
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004776 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_imsi_reject), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004777 vc_conn.done;
4778}
4779
4780/* Do LU by IMSI, but then remain silent so that Ts6-1 times out */
4781private function f_tc_sgsap_lu_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4782 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4783 var PDU_SGsAP lur;
4784
4785 f_init_handler(pars);
4786
4787 /* tell GSUP dispatcher to send this IMSI to us */
4788 f_create_gsup_expect(hex2str(g_pars.imsi));
4789
4790 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
4791 ts_SGsAP_LAI('901'H, '70'H, 2342)));
4792 /* Old LAI, if MS sends it */
4793 /* TMSI status, if MS has no valid TMSI */
4794 /* IMEISV, if it supports "automatic device detection" */
4795 /* TAI, if available in MME */
4796 /* E-CGI, if available in MME */
4797 SGsAP.send(lur);
4798
4799 /* FIXME: is this really done over SGs? The Ue is already authenticated
4800 * via the MME ... */
4801 f_mm_auth_sgs();
4802
4803 /* Expect MSC to perform LU with HLR */
4804 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4805 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
4806 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
4807 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
4808
4809 alt {
4810 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) {
4811 setverdict(pass);
4812 }
4813 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4814 setverdict(fail, "Received LU-REJECT instead of ACCEPT");
4815 }
4816 [] SGsAP.receive {
4817 setverdict(fail, "Received unexpected message on SGs");
4818 }
4819 }
4820
4821 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4822
4823 /* Wait until the VLR has abort the TMSI reallocation procedure */
4824 f_sleep(45.0);
4825
4826 /* The outcome does not change the SGs state, see also 5.2.3.4 */
4827 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4828
4829 f_sgsap_bssmap_screening();
4830
4831 setverdict(pass);
4832}
4833testcase TC_sgsap_lu_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004834 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004835 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004836 f_init(1, true);
4837 pars := f_init_pars(11813, true);
Harald Welte4263c522018-12-06 11:56:27 +01004838
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004839 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004840 vc_conn.done;
4841}
4842
4843private function f_tc_sgsap_expl_imsi_det_eps(charstring id, BSC_ConnHdlrPars pars)
4844runs on BSC_ConnHdlr {
4845 f_init_handler(pars);
4846 f_sgs_perform_lu();
4847 f_sleep(3.0);
4848
4849 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4850 SGsAP.send(ts_SGsAP_EPS_DETACH_IND(g_pars.imsi, mme_name, UE_initiated));
4851 SGsAP.receive(tr_SGsAP_EPS_DETACH_ACK(g_pars.imsi));
4852 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4853
4854 f_sgsap_bssmap_screening();
4855
4856 setverdict(pass);
4857}
4858testcase TC_sgsap_expl_imsi_det_eps() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004859 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004860 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004861 f_init(1, true);
4862 pars := f_init_pars(11814, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004863 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004864 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_expl_imsi_det_eps), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004865 vc_conn.done;
4866}
4867
Philipp Maierfc19f172019-03-21 11:17:54 +01004868private function f_tc_sgsap_impl_imsi_det_eps(charstring id, BSC_ConnHdlrPars pars)
4869runs on BSC_ConnHdlr {
4870 f_init_handler(pars);
4871 f_sgs_perform_lu();
4872 f_sleep(3.0);
4873
4874 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4875 SGsAP.send(ts_SGsAP_EPS_DETACH_IND(g_pars.imsi, mme_name, network_initiated));
4876 SGsAP.receive(tr_SGsAP_EPS_DETACH_ACK(g_pars.imsi));
4877 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4878
4879 f_sgsap_bssmap_screening();
4880
4881 setverdict(pass);
4882}
4883testcase TC_sgsap_impl_imsi_det_eps() runs on MTC_CT {
4884 var BSC_ConnHdlrPars pars;
4885 var BSC_ConnHdlr vc_conn;
4886 f_init(1, true);
4887 pars := f_init_pars(11814, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004888 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maierfc19f172019-03-21 11:17:54 +01004889 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_impl_imsi_det_eps), pars);
4890 vc_conn.done;
4891}
4892
Harald Welte4263c522018-12-06 11:56:27 +01004893private function f_tc_sgsap_expl_imsi_det_noneps(charstring id, BSC_ConnHdlrPars pars)
4894runs on BSC_ConnHdlr {
4895 f_init_handler(pars);
4896 f_sgs_perform_lu();
4897 f_sleep(3.0);
4898
4899 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4900 SGsAP.send(ts_SGsAP_IMSI_DETACH_IND(g_pars.imsi, mme_name, combined_UE_initiated));
4901 SGsAP.receive(tr_SGsAP_IMSI_DETACH_ACK(g_pars.imsi));
Philipp Maierd08e7e72019-04-02 15:27:10 +02004902
4903 if (f_ctrl_subscr_in_vlr(hex2str(g_pars.imsi))) {
4904 setverdict(fail, "subscriber not removed from VLR");
4905 }
Harald Welte4263c522018-12-06 11:56:27 +01004906
4907 f_sgsap_bssmap_screening();
4908
4909 setverdict(pass);
4910}
4911testcase TC_sgsap_expl_imsi_det_noneps() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004912 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004913 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004914 f_init(1, true);
4915 pars := f_init_pars(11815, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004916 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004917 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_expl_imsi_det_noneps), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004918 vc_conn.done;
4919}
4920
Philipp Maier5d812702019-03-21 10:51:26 +01004921private function f_tc_sgsap_impl_imsi_det_noneps(charstring id, BSC_ConnHdlrPars pars)
4922runs on BSC_ConnHdlr {
4923 f_init_handler(pars);
4924 f_sgs_perform_lu();
4925 f_sleep(3.0);
4926
4927 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4928 SGsAP.send(ts_SGsAP_IMSI_DETACH_IND(g_pars.imsi, mme_name, implicit_network_initiated));
4929 SGsAP.receive(tr_SGsAP_IMSI_DETACH_ACK(g_pars.imsi));
4930
4931 if (f_ctrl_subscr_in_vlr(hex2str(g_pars.imsi))) {
4932 setverdict(fail, "subscriber not removed from VLR");
4933 }
4934
4935 f_sgsap_bssmap_screening();
4936
4937 setverdict(pass);
4938}
4939testcase TC_sgsap_impl_imsi_det_noneps() runs on MTC_CT {
4940 var BSC_ConnHdlrPars pars;
4941 var BSC_ConnHdlr vc_conn;
4942 f_init(1, true);
4943 pars := f_init_pars(11815, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004944 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier5d812702019-03-21 10:51:26 +01004945 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_impl_imsi_det_noneps), pars);
4946 vc_conn.done;
4947}
4948
Harald Welte4263c522018-12-06 11:56:27 +01004949/* Trigger a paging request via VTY and send a paging reject in response */
4950private function f_tc_sgsap_paging_rej(charstring id, BSC_ConnHdlrPars pars)
4951runs on BSC_ConnHdlr {
4952 f_init_handler(pars);
4953 f_sgs_perform_lu();
4954 f_sleep(1.0);
4955
4956 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4957 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4958 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4959 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4960
4961 /* Initiate paging via VTY */
4962 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4963 alt {
4964 [] SGsAP.receive(exp_resp) {
4965 setverdict(pass);
4966 }
4967 [] SGsAP.receive {
4968 setverdict(fail, "Received unexpected message on SGs");
4969 }
4970 }
4971
4972 /* Now reject the paging */
4973 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, IMSI_unknown));
4974
4975 /* Wait for the states inside the MSC to settle and check the state
4976 * of the SGs Association */
4977 f_sleep(1.0);
4978 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4979
4980 /* FIXME: At the moment we send an IMSI_unknown as cause code, which is fine,
4981 * but we also need to cover tha case where the cause code indicates an
4982 * "IMSI detached for EPS services". In those cases the VLR is expected to
4983 * try paging on tha A/Iu interface. This will be another testcase similar to
4984 * this one, but extended with checks for the presence of the A/Iu paging
4985 * messages. */
4986
4987 f_sgsap_bssmap_screening();
4988
4989 setverdict(pass);
4990}
4991testcase TC_sgsap_paging_rej() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004992 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004993 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004994 f_init(1, true);
4995 pars := f_init_pars(11816, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004996 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004997 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_rej), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004998 vc_conn.done;
4999}
5000
5001/* Trigger a paging request via VTY and send a paging reject that indicates
5002 * that the subscriber intentionally rejected the call. */
5003private function f_tc_sgsap_paging_subscr_rej(charstring id, BSC_ConnHdlrPars pars)
5004runs on BSC_ConnHdlr {
5005 f_init_handler(pars);
5006 f_sgs_perform_lu();
5007 f_sleep(1.0);
5008
5009 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5010 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
5011 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
5012 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
5013
5014 /* Initiate paging via VTY */
5015 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
5016 alt {
5017 [] SGsAP.receive(exp_resp) {
5018 setverdict(pass);
5019 }
5020 [] SGsAP.receive {
5021 setverdict(fail, "Received unexpected message on SGs");
5022 }
5023 }
5024
5025 /* Now reject the paging */
5026 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, user_rejected_mobile_terminating_CS_fallback_call));
5027
5028 /* Wait for the states inside the MSC to settle and check the state
5029 * of the SGs Association */
5030 f_sleep(1.0);
5031 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5032
5033 /* FIXME: The VLR is supposed to trigger an User Determined User Busy (UDUB) as specified
5034 * in 3GPP TS 24.082, this is not yet implemented in the MSC or in this tests, we need
5035 * to check back how this works and how it can be tested */
5036
5037 f_sgsap_bssmap_screening();
5038
5039 setverdict(pass);
5040}
5041testcase TC_sgsap_paging_subscr_rej() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005042 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005043 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005044 f_init(1, true);
5045 pars := f_init_pars(11817, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005046 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005047 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_subscr_rej), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005048 vc_conn.done;
5049}
5050
5051/* Trigger a paging request via VTY and send an UE unreacable messge in response */
5052private function f_tc_sgsap_paging_ue_unr(charstring id, BSC_ConnHdlrPars pars)
5053runs on BSC_ConnHdlr {
5054 f_init_handler(pars);
5055 f_sgs_perform_lu();
5056 f_sleep(1.0);
5057
5058 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5059 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
5060 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
5061 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
5062
5063 /* Initiate paging via VTY */
5064 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
5065 alt {
5066 [] SGsAP.receive(exp_resp) {
5067 setverdict(pass);
5068 }
5069 [] SGsAP.receive {
5070 setverdict(fail, "Received unexpected message on SGs");
5071 }
5072 }
5073
5074 /* Now pretend that the UE is unreachable */
5075 SGsAP.send(ts_SGsAP_UE_UNREACHABLE(g_pars.imsi, UE_unreachable));
5076
5077 /* Wait for the states inside the MSC to settle and check the state
5078 * of the SGs Association. */
5079 f_sleep(1.0);
5080 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5081
5082 f_sgsap_bssmap_screening();
5083
5084 setverdict(pass);
5085}
5086testcase TC_sgsap_paging_ue_unr() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005087 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005088 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005089 f_init(1, true);
5090 pars := f_init_pars(11818, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005091 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005092 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_ue_unr), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005093 vc_conn.done;
5094}
5095
5096/* Trigger a paging request via VTY but don't respond to it */
5097private function f_tc_sgsap_paging_and_nothing(charstring id, BSC_ConnHdlrPars pars)
5098runs on BSC_ConnHdlr {
5099 f_init_handler(pars);
5100 f_sgs_perform_lu();
5101 f_sleep(1.0);
5102
5103 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5104 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
Philipp Maier34218102019-09-24 09:15:49 +02005105 var template PDU_SGsAP exp_serv_abrt := ts_SGsAP_SERVICE_ABORT_REQ(g_pars.imsi);
Harald Welte4263c522018-12-06 11:56:27 +01005106 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
5107 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
5108
5109 /* Initiate paging via VTY */
5110 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
5111 alt {
5112 [] SGsAP.receive(exp_resp) {
5113 setverdict(pass);
5114 }
5115 [] SGsAP.receive {
5116 setverdict(fail, "Received unexpected message on SGs");
5117 }
5118 }
5119
Philipp Maier34218102019-09-24 09:15:49 +02005120 /* While we are doing nothing, expect an SGsAP-SERVICE-ABORT-REQUEST
5121 * after some time */
5122 timer T := 10.0;
5123 T.start
5124 alt {
5125 [] SGsAP.receive(exp_serv_abrt)
5126 {
5127 setverdict(pass);
5128 }
5129 [] SGsAP.receive {
5130 setverdict(fail, "unexpected SGsAP message received");
5131 self.stop;
5132 }
5133 [] T.timeout {
5134 setverdict(fail, "MSC did not send SGsAP-SERVICE-ABORT-REQUEST");
5135 self.stop;
5136 }
5137 }
5138
5139 /* The SGs association must remain unchanged. */
Harald Welte4263c522018-12-06 11:56:27 +01005140 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5141
5142 f_sgsap_bssmap_screening();
5143
5144 setverdict(pass);
5145}
5146testcase TC_sgsap_paging_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005147 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005148 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005149 f_init(1, true);
5150 pars := f_init_pars(11819, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005151 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005152 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005153 vc_conn.done;
5154}
5155
5156/* Trigger a paging request via VTY and slip in an LU */
5157private function f_tc_sgsap_paging_and_lu(charstring id, BSC_ConnHdlrPars pars)
5158runs on BSC_ConnHdlr {
5159 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5160 f_init_handler(pars);
5161
5162 /* First we prepar the situation, where the SGs association is in state
5163 * NULL and the confirmed by radio contact indicator is set to false
5164 * as well. This can be archived by performing an SGs LU and then
5165 * resetting the VLR */
5166 f_sgs_perform_lu();
5167 f_sgsap_reset_mme(mp_mme_name);
5168 f_sleep(1.0);
5169 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
5170
5171 /* Perform a paging, expect the paging messages on the SGs interface */
5172 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
5173 alt {
5174 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
5175 setverdict(pass);
5176 }
5177 [] SGsAP.receive {
5178 setverdict(fail, "Received unexpected message on SGs");
5179 }
5180 }
5181
5182 /* Perform the LU as normal */
5183 f_sgs_perform_lu();
5184 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5185
5186 /* Expect a new paging request right after the LU */
5187 alt {
5188 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
5189 setverdict(pass);
5190 }
5191 [] SGsAP.receive {
5192 setverdict(fail, "Received unexpected message on SGs");
5193 }
5194 }
5195
5196 /* Test is done now, lets round everything up by rejecting the paging
5197 * cleanly. */
5198 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, user_rejected_mobile_terminating_CS_fallback_call));
5199 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5200
5201 f_sgsap_bssmap_screening();
5202
5203 setverdict(pass);
5204}
5205testcase TC_sgsap_paging_and_lu() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005206 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005207 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005208 f_init(1, true);
5209 pars := f_init_pars(11820, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005210 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005211 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_and_lu), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005212 vc_conn.done;
5213}
5214
5215/* Send unexpected unit-data through the SGs interface */
5216private function f_tc_sgsap_unexp_ud(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5217 f_init_handler(pars);
5218 f_sleep(1.0);
5219
5220 /* This simulates what happens when a subscriber without SGs
5221 * association gets unitdata via the SGs interface. */
5222
5223 /* Make sure the subscriber exists and the SGs association
5224 * is in NULL state */
5225 f_perform_lu();
5226 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
5227
5228 /* Send some random unit data, the MSC/VLR should send a release
5229 * immediately. */
5230 SGsAP.send(ts_SGsAP_UL_UD(pars.imsi,'1234'O));
5231 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, IMSI_detached_for_EPS_nonEPS_services));
5232
5233 f_sgsap_bssmap_screening();
5234
5235 setverdict(pass);
5236}
5237testcase TC_sgsap_unexp_ud() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005238 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005239 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005240 f_init(1, true);
5241 pars := f_init_pars(11821, true);
5242 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_unexp_ud), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005243 vc_conn.done;
5244}
5245
5246/* Send unsolicited unit-data through the SGs interface */
5247private function f_tc_sgsap_unsol_ud(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5248 f_init_handler(pars);
5249 f_sleep(1.0);
5250
5251 /* This simulates what happens when the MME attempts to send unitdata
5252 * to a subscriber that is completely unknown to the VLR */
5253
5254 /* Send some random unit data, the MSC/VLR should send a release
5255 * immediately. */
5256 SGsAP.send(ts_SGsAP_UL_UD(pars.imsi,'1234'O));
5257 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, IMSI_unknown));
5258
5259 f_sgsap_bssmap_screening();
5260
Harald Welte4d15fa72020-08-19 08:58:28 +02005261 /* clean-up VLR state about this subscriber */
5262 f_imsi_detach_by_imsi();
5263
Harald Welte4263c522018-12-06 11:56:27 +01005264 setverdict(pass);
5265}
5266testcase TC_sgsap_unsol_ud() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005267 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005268 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005269 f_init(1, true);
5270 pars := f_init_pars(11822, true);
5271 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_unsol_ud), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005272 vc_conn.done;
5273}
5274
5275private altstep as_other_sms_sgs() runs on BSC_ConnHdlr {
5276 /* FIXME: Match an actual payload (second questionmark), the type is
5277 * octetstring, how do we use a tr_PDU_DTAP_MT here? */
5278 [] SGsAP.receive(tr_SGsAP_DL_UD(?,?)) {
5279 setverdict(fail, "Unexpected SMS related PDU from MSC");
5280 mtc.stop;
5281 }
5282}
5283
5284/* receive a MT-SMS delivered from the MSC/SMSC over an already existing SGsAP connection */
5285function f_mt_sms_sgs(inout SmsParameters spars)
5286runs on BSC_ConnHdlr {
5287 var template (value) TPDU_RP_DATA_MS_SGSN tp_mo;
5288 var template (value) RPDU_MS_SGSN rp_mo;
5289 var template (value) PDU_ML3_MS_NW l3_mo;
5290
5291 var template TPDU_RP_DATA_SGSN_MS tp_mt;
5292 var template RPDU_SGSN_MS rp_mt;
5293 var template PDU_ML3_NW_MS l3_mt;
5294
5295 var PDU_ML3_NW_MS sgsap_l3_mt;
5296
5297 var default d := activate(as_other_sms_sgs());
5298
5299 /* Expect CP-DATA(RP-DATA(SMS-DELIVER)) */
5300 tp_mt := tr_SMS_DELIVER(?, spars.tp.ud, spars.tp.pid, spars.tp.dcs, ?);
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09005301 rp_mt := tr_RP_DATA_MT(?, spars.rp.smsc_addr, omit, tp_mt);
Harald Welte4263c522018-12-06 11:56:27 +01005302 l3_mt := tr_ML3_MT_SMS(?, c_TIF_ORIG, tr_CP_DATA_MT(rp_mt));
5303
5304 SGsAP.receive(l3_mt) -> value sgsap_l3_mt;
5305
5306 /* Extract relevant identifiers */
5307 spars.tid := bit2int(sgsap_l3_mt.tiOrSkip.transactionId.tio);
5308 spars.rp.msg_ref := sgsap_l3_mt.msgs.sms.cP_DATA.cP_User_Data.cP_RPDU.rP_DATA_SGSN_MS.rP_MessageReference;
5309
5310 /* send CP-ACK for CP-DATA just received */
5311 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_REPL, ts_CP_ACK_MO);
5312
5313 SGsAP.send(l3_mo);
5314
5315 /* send RP-ACK for RP-DATA */
5316 rp_mo := ts_RP_ACK_MO(spars.rp.msg_ref);
5317 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_REPL, ts_CP_DATA_MO(rp_mo));
5318
5319 SGsAP.send(l3_mo);
5320
5321 /* expect CP-ACK for CP-DATA(RP-ACK) just sent */
5322 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_ORIG, tr_CP_ACK_MT);
5323
5324 SGsAP.receive(l3_mt);
5325
5326 deactivate(d);
5327
5328 setverdict(pass);
5329}
5330
5331/* submit a MO-SMS to MSC/SMSC over an already existing SGsAP connection */
5332function f_mo_sms_sgs(inout SmsParameters spars)
5333runs on BSC_ConnHdlr {
5334 var template (value) TPDU_RP_DATA_MS_SGSN tp_mo;
5335 var template (value) RPDU_MS_SGSN rp_mo;
5336 var template (value) PDU_ML3_MS_NW l3_mo;
5337
5338 var template TPDU_RP_DATA_SGSN_MS tp_mt;
5339 var template RPDU_SGSN_MS rp_mt;
5340 var template PDU_ML3_NW_MS l3_mt;
5341
5342 var default d := activate(as_other_sms_sgs());
5343
5344 /* just in case this is routed to SMPP.. */
5345 f_create_smpp_expect(hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue));
5346
5347 tp_mo := ts_SMS_SUBMIT(spars.tp.msg_ref, spars.tp.da, spars.tp.pid, spars.tp.dcs,
5348 spars.tp.udl, spars.tp.ud);
Vadim Yanitskiy437b5a62019-12-15 14:13:39 +09005349 rp_mo := ts_RP_DATA_MO(spars.rp.msg_ref, omit, spars.rp.smsc_addr, tp_mo);
Harald Welte4263c522018-12-06 11:56:27 +01005350 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_DATA_MO(rp_mo));
5351
5352 SGsAP.send(l3_mo);
5353
5354 /* receive CP-ACK for CP-DATA above */
5355 SGsAP.receive(tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_ACK_MT));
5356
5357 if (ispresent(spars.exp_rp_err)) {
5358 /* expect an RP-ERROR message from MSC with given cause */
5359 rp_mt := tr_RP_ERROR_MT(spars.rp.msg_ref, spars.exp_rp_err);
5360 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_DATA_MT(rp_mt));
5361 SGsAP.receive(l3_mt);
5362 /* send CP-ACK for CP-DATA just received */
5363 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_ACK_MO);
5364 SGsAP.send(l3_mo);
5365 } else {
5366 /* expect RP-ACK for RP-DATA */
5367 rp_mt := tr_RP_ACK_MT(spars.rp.msg_ref);
5368 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_DATA_MT(rp_mt));
5369 SGsAP.receive(l3_mt);
5370 /* send CP-ACO for CP-DATA just received */
5371 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_ACK_MO);
5372 SGsAP.send(l3_mo);
5373 }
5374
5375 deactivate(d);
5376
5377 setverdict(pass);
5378}
5379
5380private function f_vty_sms_send_conn_hdlr(charstring imsi, charstring msisdn, charstring text)
5381runs on BSC_ConnHdlr {
5382 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
5383}
5384
5385/* Send a MT SMS via SGs interface */
5386private function f_tc_sgsap_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5387 f_init_handler(pars);
5388 f_sgs_perform_lu();
5389 f_sleep(1.0);
5390 var SmsParameters spars := valueof(t_SmsPars);
5391 spars.tp.ud := 'C8329BFD064D9B53'O;
5392
5393 /* Trigger SMS via VTY */
5394 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
5395 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5396
5397 /* Expect a paging request and respond accordingly with a service request */
5398 SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, SMS_indicator, omit));
5399 SGsAP.send(ts_SGsAP_SERVICE_REQ(pars.imsi, SMS_indicator, EMM_CONNECTED));
5400
5401 /* Connection is now live, receive the MT-SMS */
5402 f_mt_sms_sgs(spars);
5403
5404 /* Expect a concluding release from the MSC */
5405 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, omit));
5406
5407 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
5408 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5409
5410 f_sgsap_bssmap_screening();
5411
5412 setverdict(pass);
5413}
5414testcase TC_sgsap_mt_sms() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005415 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005416 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005417 f_init(1, true);
5418 pars := f_init_pars(11823, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005419 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005420 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005421 vc_conn.done;
5422}
5423
5424/* Send a MO SMS via SGs interface */
5425private function f_tc_sgsap_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5426 f_init_handler(pars);
5427 f_sgs_perform_lu();
5428 f_sleep(1.0);
5429 var SmsParameters spars := valueof(t_SmsPars);
5430 spars.tp.ud := 'C8329BFD064D9B53'O;
5431
5432 /* Send the MO-SMS */
5433 f_mo_sms_sgs(spars);
5434
5435 /* Expect a concluding release from the MSC/VLR */
5436 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, omit));
5437
5438 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
5439 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5440
5441 setverdict(pass);
5442
5443 f_sgsap_bssmap_screening()
5444}
5445testcase TC_sgsap_mo_sms() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005446 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005447 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005448 f_init(1, true);
5449 pars := f_init_pars(11824, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005450 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005451 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mo_sms), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005452 vc_conn.done;
5453}
5454
5455/* Trigger sending of an MT sms via VTY but never respond to anything */
5456private function f_tc_sgsap_mt_sms_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5457 f_init_handler(pars, 170.0);
5458 f_sgs_perform_lu();
5459 f_sleep(1.0);
5460
5461 var SmsParameters spars := valueof(t_SmsPars);
5462 spars.tp.ud := 'C8329BFD064D9B53'O;
5463 var integer page_count := 0;
5464 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5465 var template PDU_SGsAP exp_pag_req := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, SMS_indicator, omit);
5466 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
5467 exp_pag_req.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
5468
5469 /* Trigger SMS via VTY */
5470 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
5471
Neels Hofmeyr16237742019-03-06 15:34:01 +01005472 /* Expect the MSC/VLR to page exactly once */
5473 SGsAP.receive(exp_pag_req);
Harald Welte4263c522018-12-06 11:56:27 +01005474
5475 /* Wait some time to make sure the MSC is not delivering any further
5476 * paging messages or anything else that could be unexpected. */
5477 timer T := 20.0;
5478 T.start
5479 alt {
5480 [] SGsAP.receive(exp_pag_req)
5481 {
5482 setverdict(fail, "paging seems not to stop!");
5483 mtc.stop;
5484 }
5485 [] SGsAP.receive {
5486 setverdict(fail, "unexpected SGsAP message received");
5487 self.stop;
5488 }
5489 [] T.timeout {
5490 setverdict(pass);
5491 }
5492 }
5493
5494 /* Even on a failed paging the SGs Association should stay intact */
5495 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5496
Philipp Maier26bdb8c2019-09-24 09:21:12 +02005497 /* Make sure that the SMS we just inserted is cleared and the
5498 * subscriber is expired. This is necessary because otherwise the MSC
5499 * might re-try the SMS delivery and disturb the following tests. */
Harald Welte4263c522018-12-06 11:56:27 +01005500
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01005501 f_vty_sms_clear(hex2str(g_pars.imsi));
5502
Harald Welte4263c522018-12-06 11:56:27 +01005503 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " expire");
5504
5505 setverdict(pass);
Neels Hofmeyrb0f82342019-03-06 15:36:51 +01005506
5507 f_sgsap_bssmap_screening();
Harald Welte4263c522018-12-06 11:56:27 +01005508}
5509testcase TC_sgsap_mt_sms_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005510 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005511 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005512 f_init(1, true);
5513 pars := f_init_pars(11825, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005514 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005515 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005516 vc_conn.done;
5517}
5518
5519/* Trigger sending of an MT sms via VTY but reject the paging immediately */
5520private function f_tc_sgsap_mt_sms_and_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5521 f_init_handler(pars, 150.0);
5522 f_sgs_perform_lu();
5523 f_sleep(1.0);
5524
5525 var SmsParameters spars := valueof(t_SmsPars);
5526 spars.tp.ud := 'C8329BFD064D9B53'O;
5527 var integer page_count := 0;
5528 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5529 var template PDU_SGsAP exp_pag_req := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, SMS_indicator, omit);
5530 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
5531 exp_pag_req.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
5532
5533 /* Trigger SMS via VTY */
5534 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
5535
5536 /* Expect a paging request and reject it immediately */
5537 SGsAP.receive(exp_pag_req);
5538 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, IMSI_unknown));
5539
5540 /* The MSC/VLR should no longer try to page once the paging has been
5541 * rejected. Wait some time and check if there are no unexpected
5542 * messages on the SGs interface. */
5543 timer T := 20.0;
5544 T.start
5545 alt {
5546 [] SGsAP.receive(exp_pag_req)
5547 {
5548 setverdict(fail, "paging seems not to stop!");
5549 mtc.stop;
5550 }
5551 [] SGsAP.receive {
5552 setverdict(fail, "unexpected SGsAP message received");
5553 self.stop;
5554 }
5555 [] T.timeout {
5556 setverdict(pass);
5557 }
5558 }
5559
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01005560 f_vty_sms_clear(hex2str(g_pars.imsi));
5561
Harald Welte4263c522018-12-06 11:56:27 +01005562 /* A rejected paging with IMSI_unknown (see above) should always send
5563 * the SGs association to NULL. */
5564 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
5565
5566 f_sgsap_bssmap_screening();
5567
Harald Welte4263c522018-12-06 11:56:27 +01005568 setverdict(pass);
5569}
5570testcase TC_sgsap_mt_sms_and_reject() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005571 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005572 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005573 f_init(1, true);
5574 pars := f_init_pars(11826, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005575 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005576 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms_and_reject), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005577 vc_conn.done;
5578}
5579
Pau Espin Pedrol3acd19e2021-04-28 12:59:52 +02005580/* Perform an MT CSFB call including LU */
Harald Welte4263c522018-12-06 11:56:27 +01005581private function f_mt_lu_and_csfb_call(charstring id, BSC_ConnHdlrPars pars, boolean bssmap_lu) runs on BSC_ConnHdlr {
5582 f_init_handler(pars);
5583
5584 /* Be sure that the BSSMAP reset is done before we begin. */
5585 f_sleep(2.0);
5586
5587 /* Testcase variation: See what happens when we do a regular BSSMAP
5588 * LU first (this should not hurt in any way!) */
5589 if (bssmap_lu) {
5590 f_perform_lu();
5591 }
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005592 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Harald Welte4263c522018-12-06 11:56:27 +01005593
5594 f_sgs_perform_lu();
5595 f_sleep(1.0);
5596
5597 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5598 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Harald Welte4263c522018-12-06 11:56:27 +01005599
5600 /* Initiate a call via MNCC interface */
5601 f_mt_call_initate(cpars);
5602
5603 /* Expect a paging request and respond accordingly with a service request */
5604 SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit));
5605 SGsAP.send(ts_SGsAP_SERVICE_REQ(pars.imsi, CS_call_indicator, EMM_CONNECTED));
5606
5607 /* Complete the call, hold it for some time and then tear it down */
5608 f_mt_call_complete(cpars);
5609 f_sleep(3.0);
Harald Welte4c422b72019-02-17 16:27:10 +01005610 f_call_hangup(cpars, true, is_csfb := true);
Harald Welte4263c522018-12-06 11:56:27 +01005611
5612 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
5613 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5614
Harald Welte4263c522018-12-06 11:56:27 +01005615 /* Test for successful return by triggering a paging, when the paging
5616 * request is received via SGs, we can be sure that the MSC/VLR has
5617 * recognized that the UE is now back on 4G */
5618 f_sleep(1.0);
5619 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
5620 alt {
5621 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
5622 setverdict(pass);
5623 }
5624 [] SGsAP.receive {
5625 setverdict(fail, "Received unexpected message on SGs");
5626 }
5627 }
5628
5629 f_sgsap_bssmap_screening();
5630
5631 setverdict(pass);
5632}
5633
5634/* Perform a regular BSSAP LU first, do a SGSAP LU and then make a CSFB call */
5635private function f_tc_bssap_lu_sgsap_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5636 f_mt_lu_and_csfb_call(id, pars, true);
5637}
5638testcase TC_bssap_lu_sgsap_lu_and_mt_call() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005639 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005640 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005641 f_init(1, true);
5642 pars := f_init_pars(118139, true);
Harald Welte4263c522018-12-06 11:56:27 +01005643
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005644 vc_conn := f_start_handler_with_pars(refers(f_tc_bssap_lu_sgsap_lu_and_mt_call), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005645 vc_conn.done;
5646}
5647
Harald Welte4263c522018-12-06 11:56:27 +01005648/* Perform a SGSAP LU and then make a CSFB call */
5649private function f_tc_sgsap_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5650 f_mt_lu_and_csfb_call(id, pars, false);
5651}
5652testcase TC_sgsap_lu_and_mt_call() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005653 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005654 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005655 f_init(1, true);
5656 pars := f_init_pars(11827, true);
Harald Welte4263c522018-12-06 11:56:27 +01005657
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005658 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_and_mt_call), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005659 vc_conn.done;
5660}
5661
Philipp Maier628c0052019-04-09 17:36:57 +02005662/* Simulate an HLR/VLR failure */
5663private function f_tc_sgsap_vlr_failure(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5664 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
5665 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5666
5667 var PDU_SGsAP lur;
5668
5669 f_init_handler(pars);
5670
5671 /* Attempt location update (which is expected to fail) */
5672 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
5673 ts_SGsAP_LAI('901'H, '70'H, 2342)));
5674 SGsAP.send(lur);
5675
5676 /* Respond to SGsAP-RESET-INDICATION from VLR */
5677 alt {
5678 [] SGsAP.receive(tr_SGsAP_RESET_IND_VLR(vlr_name)); {
5679 SGsAP.send(valueof(ts_SGsAP_RESET_ACK_MME(mme_name)));
5680 setverdict(pass);
5681 }
5682 [] SGsAP.receive {
5683 setverdict(fail, "Received unexpected message on SGs");
5684 }
5685 }
5686
5687 f_sleep(1.0);
5688 setverdict(pass);
5689}
5690testcase TC_sgsap_vlr_failure() runs on MTC_CT {
5691 var BSC_ConnHdlrPars pars;
5692 var BSC_ConnHdlr vc_conn;
5693 f_init(1, true, false);
5694 pars := f_init_pars(11811, true, false);
5695 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_vlr_failure), pars);
5696 vc_conn.done;
5697}
5698
Harald Welte4263c522018-12-06 11:56:27 +01005699/* SGs TODO:
5700 * LU attempt for IMSI without NAM_PS in HLR
5701 * LU attempt with AUTH FAIL due to invalid RES/SRES
5702 * LU attempt with no response from HLR (VLR should timeout + LU REJ)
5703 * LU attempt with new TMSI but without TMSI REALL CMPL baco to VLR
5704 * implicit IMSI detach from EPS
5705 * implicit IMSI detach from non-EPS
5706 * MM INFO
5707 *
5708 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01005709
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005710private function f_tc_ho_inter_bsc_unknown_cell(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5711 f_init_handler(pars);
5712 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005713
5714 f_perform_lu();
5715 f_mo_call_establish(cpars);
5716
5717 f_sleep(1.0);
5718
5719 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5720 var BssmapCause cause := enum2int(cause_val);
5721
5722 var template BSSMAP_FIELD_CellIdentificationList cil;
5723 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('023'H, '42'H, 999) } };
5724
5725 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5726 BSSAP.receive(tr_BSSMAP_HandoverRequiredReject);
5727
5728 f_call_hangup(cpars, true);
5729}
5730testcase TC_ho_inter_bsc_unknown_cell() runs on MTC_CT {
5731 var BSC_ConnHdlr vc_conn;
5732 f_init();
5733
5734 vc_conn := f_start_handler(refers(f_tc_ho_inter_bsc_unknown_cell), 53);
5735 vc_conn.done;
5736}
5737
5738private altstep as_mgcp_ack_all_mdcx(CallParameters cpars) runs on BSC_ConnHdlr {
5739 var MgcpCommand mgcp_cmd;
5740 [] MGCP.receive(tr_MDCX) -> value mgcp_cmd {
Neels Hofmeyr8913b9e2021-07-27 22:33:45 +02005741 var charstring conn_id;
5742 f_mgcp_find_param_entry(mgcp_cmd.params, "I", conn_id);
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02005743 var SDP_Message sdp := valueof(ts_SDP(cpars.mgw_conn_2.mgw_rtp_ip, cpars.mgw_conn_2.mgw_rtp_ip,
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005744 hex2str(cpars.mgcp_call_id), "42",
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02005745 cpars.mgw_conn_2.mgw_rtp_port,
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005746 { int2str(cpars.rtp_payload_type) },
5747 { valueof(ts_SDP_rtpmap(cpars.rtp_payload_type,
5748 cpars.rtp_sdp_format)),
5749 valueof(ts_SDP_ptime(20)) }));
Neels Hofmeyr8913b9e2021-07-27 22:33:45 +02005750 MGCP.send(ts_MDCX_ACK(mgcp_cmd.line.trans_id, str2hex(conn_id), sdp));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005751 repeat;
5752 }
5753}
5754
Neels Hofmeyr8853afb2021-07-27 22:34:15 +02005755private altstep as_mgcp_ack_all_dlcx(CallParameters cpars) runs on BSC_ConnHdlr {
5756 var MgcpCommand mgcp_cmd;
5757 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
5758 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
5759 repeat;
5760 }
5761}
5762
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005763private function f_tc_ho_inter_bsc0(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005764 var CallParameters cpars;
5765
5766 cpars := valueof(t_CallParams('12345'H, 0));
5767 if (pars.use_ipv6) {
5768 cpars.mgw_conn_1.mgw_rtp_ip := "::1";
5769 cpars.mgw_conn_2.mgw_rtp_ip := "::2";
5770 cpars.bss_rtp_ip := "::3";
5771 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005772
5773 f_init_handler(pars);
5774
5775 f_vty_transceive(MSCVTY, "configure terminal");
5776 f_vty_transceive(MSCVTY, "msc");
5777 f_vty_transceive(MSCVTY, "neighbor a cgi 262 42 23 42 ran-pc 0.24.1");
Neels Hofmeyr2822d072021-06-23 03:20:32 +02005778 f_vty_transceive(MSCVTY, "neighbor a cgi 023 42 5 6 ran-pc 0.24.2");
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005779 f_vty_transceive(MSCVTY, "exit");
5780 f_vty_transceive(MSCVTY, "exit");
5781
5782 f_perform_lu();
5783 f_mo_call_establish(cpars);
5784
5785 f_sleep(1.0);
5786
5787 var default ack_mdcx := activate(as_mgcp_ack_all_mdcx(cpars));
5788
5789 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5790 var BssmapCause cause := enum2int(cause_val);
5791
5792 var template BSSMAP_FIELD_CellIdentificationList cil;
Neels Hofmeyr2822d072021-06-23 03:20:32 +02005793 cil := { cIl_CGI := { ts_BSSMAP_CI_CGI('023'H, '42'H, 5, 6) } };
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005794
5795 /* old BSS sends Handover Required */
5796 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5797
5798 /* Now the action goes on in f_tc_ho_inter_bsc1() */
5799
5800 /* MSC forwards the RR Handover Command to old BSS */
5801 var PDU_BSSAP ho_command;
5802 BSSAP.receive(tr_BSSMAP_HandoverCommand) -> value ho_command;
5803
5804 log("GOT HandoverCommand", ho_command);
5805
5806 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
5807
5808 /* f_tc_ho_inter_bsc1() completes Handover, then expecting a Clear here. */
5809 f_expect_clear();
5810
5811 log("FIRST inter-BSC Handover done");
5812
5813
5814 /* ------------------------ */
5815
5816 /* Ok, that went well, now the other BSC is handovering back here --
5817 * from now on this here is the new BSS. */
5818 f_create_bssmap_exp_handoverRequest(193);
5819
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005820 var template BSSMAP_IE_EncryptionInformation encryptionInformation;
5821 var template BSSMAP_IE_ChosenEncryptionAlgorithm chosenEncryptionAlgorithm;
5822 var template BSSMAP_IE_KC128 kC128;
5823 var OCT1 a5_perm_alg;
5824 f_get_expected_encryption(encryptionInformation, chosenEncryptionAlgorithm, kC128, a5_perm_alg);
Vadim Yanitskiyc5fcb892022-08-04 04:06:07 +07005825 var template PDU_BSSAP expect_ho_request := tr_BSSMAP_HandoverRequest(encryptionInformation,
5826 chosenEncryptionAlgorithm,
5827 kC128, codecList := ?);
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005828 var PDU_BSSAP ho_request;
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005829 alt {
5830 [] BSSAP.receive(expect_ho_request);
5831 [] BSSAP.receive(tr_BSSMAP_HandoverRequest) -> value ho_request {
5832 log("Error: Wrong handoverRequest received. Expected: ", expect_ho_request,
5833 " got ", ho_request);
5834 setverdict(fail, "Wrong handoverRequest received");
5835 mtc.stop;
5836 }
5837 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005838
5839 /* new BSS composes a RR Handover Command */
5840 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5841 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005842 var BSSMAP_IE_AoIP_TransportLayerAddress tla tla :=
5843 valueof(f_ts_BSSMAP_IE_AoIP_TLA(cpars.bss_rtp_ip, cpars.bss_rtp_port));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005844 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5845 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5846
5847 /* Now f_tc_ho_inter_bsc1() expects HandoverCommand */
5848
5849 f_sleep(0.5);
5850
5851 /* Notify that the MS is now over here */
5852
5853 BSSAP.send(ts_BSSMAP_HandoverDetect);
5854 f_sleep(0.1);
5855 BSSAP.send(ts_BSSMAP_HandoverComplete);
5856
5857 f_sleep(3.0);
5858
5859 deactivate(ack_mdcx);
5860
5861 var default ccrel := activate(as_optional_cc_rel(cpars, true));
5862
5863 /* blatant cheating */
5864 var N_Sd_Array last_n_sd := f_bssmap_last_n_sd();
5865 last_n_sd[0] := 3;
5866 f_bssmap_continue_after_n_sd(last_n_sd);
5867
5868 f_call_hangup(cpars, true);
5869 f_sleep(1.0);
5870 deactivate(ccrel);
5871
5872 setverdict(pass);
5873}
5874private function f_tc_ho_inter_bsc1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005875 var charstring bss_rtp_ip;
5876 if (pars.use_ipv6) {
5877 bss_rtp_ip := "::8";
5878 } else {
5879 bss_rtp_ip := "1.2.3.4";
5880 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005881 f_init_handler(pars);
5882 f_create_bssmap_exp_handoverRequest(194);
5883
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005884 var template BSSMAP_IE_EncryptionInformation encryptionInformation;
5885 var template BSSMAP_IE_ChosenEncryptionAlgorithm chosenEncryptionAlgorithm;
5886 var template BSSMAP_IE_KC128 kC128;
5887 var OCT1 a5_perm_alg;
5888 f_get_expected_encryption(encryptionInformation, chosenEncryptionAlgorithm, kC128, a5_perm_alg);
Vadim Yanitskiyc5fcb892022-08-04 04:06:07 +07005889 var template PDU_BSSAP expect_ho_request := tr_BSSMAP_HandoverRequest(encryptionInformation,
5890 chosenEncryptionAlgorithm,
5891 kC128, codecList := ?);
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005892 var PDU_BSSAP ho_request;
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005893 alt {
5894 [] BSSAP.receive(expect_ho_request);
5895 [] BSSAP.receive(tr_BSSMAP_HandoverRequest) -> value ho_request {
5896 log("Error: Wrong handoverRequest received. Expected: ", expect_ho_request,
5897 " got ", ho_request);
5898 setverdict(fail, "Wrong handoverRequest received");
5899 mtc.stop;
5900 }
5901 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005902 /* new BSS composes a RR Handover Command */
5903 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5904 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005905 var BSSMAP_IE_AoIP_TransportLayerAddress tla :=
5906 valueof(f_ts_BSSMAP_IE_AoIP_TLA(bss_rtp_ip, 2342));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005907 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5908 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5909
5910 /* Now f_tc_ho_inter_bsc0() expects HandoverCommand */
5911
5912 f_sleep(0.5);
5913
5914 /* Notify that the MS is now over here */
5915
5916 BSSAP.send(ts_BSSMAP_HandoverDetect);
5917 f_sleep(0.1);
5918 BSSAP.send(ts_BSSMAP_HandoverComplete);
5919
5920 f_sleep(3.0);
5921
5922 /* Now I'd like to f_call_hangup() but we don't know any cpars here. So
5923 * ... handover back to the first BSC :P */
5924
5925 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5926 var BssmapCause cause := enum2int(cause_val);
5927
5928 var template BSSMAP_FIELD_CellIdentificationList cil;
Neels Hofmeyr2822d072021-06-23 03:20:32 +02005929 cil := { cIl_CGI := { ts_BSSMAP_CI_CGI('262'H, '42'H, 23, 42) } };
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005930
5931 /* old BSS sends Handover Required */
5932 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5933
5934 /* Now the action goes on in f_tc_ho_inter_bsc0() */
5935
5936 /* MSC forwards the RR Handover Command to old BSS */
5937 var PDU_BSSAP ho_command;
5938 BSSAP.receive(tr_BSSMAP_HandoverCommand) -> value ho_command;
5939
5940 log("GOT HandoverCommand", ho_command);
5941
5942 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
5943
5944 /* f_tc_ho_inter_bsc1() completes Handover, then expecting a Clear here. */
5945 f_expect_clear();
5946 setverdict(pass);
5947}
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005948function f_tc_ho_inter_bsc_main(boolean use_ipv6 := false, integer a5_n := 0) runs on MTC_CT {
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005949 var BSC_ConnHdlr vc_conn0;
5950 var BSC_ConnHdlr vc_conn1;
5951 f_init(2);
5952
5953 var BSC_ConnHdlrPars pars0 := f_init_pars(53);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005954 pars0.use_ipv6 := use_ipv6;
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005955 pars0.net.expect_ciph := a5_n > 0;
5956 pars0.net.expect_auth := pars0.net.expect_ciph;
5957 pars0.net.kc_support := bit2oct('00000001'B << a5_n);
5958 pars0.cm2.classmarkInformationType2_oct5.a5_3 := '1'B;
5959 pars0.cm2.classmarkInformationType2_oct5.a5_2 := '0'B;
5960 pars0.cm2.classmarkInformationType2_oct5.cm3 := '1'B;
5961 pars0.cm3 := valueof(ts_CM3_default);
5962 pars0.use_umts_aka := true;
5963 pars0.vec := f_gen_auth_vec_3g();
5964 pars0.vec_keep := true;
Neels Hofmeyr60122f82021-07-28 17:59:38 +02005965 pars0.ran_idx := 0;
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005966
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005967 var BSC_ConnHdlrPars pars1 := f_init_pars(53);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005968 pars1.use_ipv6 := use_ipv6;
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005969 pars1.net.expect_ciph := pars0.net.expect_ciph;
5970 pars1.net.expect_auth := pars0.net.expect_ciph;
5971 pars1.net.kc_support := bit2oct('00000001'B << a5_n);
5972 pars1.cm2 := pars0.cm2;
5973 pars1.cm3 := pars0.cm3;
5974 pars1.use_umts_aka := true;
5975 /* Both components need the same auth vector info because we expect f_tc_ho_inter_bsc0's ciphering key to be
5976 * identical to the one that shows up in f_tc_ho_inter_bsc1. Can only do that by feeding in a vector to both
5977 * components and then not overwriting it in BSC_ConnectionHandler. */
5978 pars1.vec := pars0.vec;
5979 pars1.vec_keep := true;
Neels Hofmeyr60122f82021-07-28 17:59:38 +02005980 pars1.ran_idx := 1;
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005981
5982 if (a5_n > 0) {
5983 f_vty_config(MSCVTY, "network", "authentication required");
5984 }
5985 f_vty_config(MSCVTY, "network", "encryption a5 " & int2str(a5_n));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005986
Neels Hofmeyr60122f82021-07-28 17:59:38 +02005987 vc_conn0 := f_start_handler_with_pars(refers(f_tc_ho_inter_bsc0), pars0);
5988 vc_conn1 := f_start_handler_with_pars(refers(f_tc_ho_inter_bsc1), pars1);
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005989 vc_conn0.done;
5990 vc_conn1.done;
5991}
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005992testcase TC_ho_inter_bsc() runs on MTC_CT {
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005993 f_tc_ho_inter_bsc_main(false, a5_n := 0);
5994}
5995testcase TC_ho_inter_bsc_a5_1() runs on MTC_CT {
5996 f_tc_ho_inter_bsc_main(false, a5_n := 1);
5997}
5998testcase TC_ho_inter_bsc_a5_3() runs on MTC_CT {
5999 f_tc_ho_inter_bsc_main(false, a5_n := 3);
6000}
6001testcase TC_ho_inter_bsc_a5_4() runs on MTC_CT {
6002 f_tc_ho_inter_bsc_main(false, a5_n := 4);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006003}
6004testcase TC_ho_inter_bsc_ipv6() runs on MTC_CT {
6005 f_tc_ho_inter_bsc_main(true);
6006}
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006007
6008function f_ML3_patch_seq_nr_MS_NW(in uint2_t seq_nr, inout octetstring enc_l3) {
6009 log("MS_NW patching N(SD)=", seq_nr, " into dtap ", enc_l3);
6010 enc_l3[2] := (enc_l3[2] and4b '3f'O) or4b bit2oct(int2bit(seq_nr, 8) << 6);
6011 log("MS_NW patched enc_l3: ", enc_l3);
6012}
6013
6014private function f_tc_ho_inter_msc_out(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006015 var CallParameters cpars;
Neels Hofmeyr906af102021-07-01 12:08:35 +02006016 var PDU_BSSAP ho_request;
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006017
6018 cpars := valueof(t_CallParams('12345'H, 0));
6019 if (pars.use_ipv6) {
6020 cpars.mgw_conn_1.mgw_rtp_ip := "::1";
6021 cpars.mgw_conn_2.mgw_rtp_ip := "::2";
6022 cpars.bss_rtp_ip := "::3";
6023 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006024 var hexstring ho_number := f_gen_msisdn(99999);
6025
6026 f_init_handler(pars);
6027
6028 f_create_mncc_expect(hex2str(ho_number));
6029
6030 f_vty_transceive(MSCVTY, "configure terminal");
6031 f_vty_transceive(MSCVTY, "msc");
6032 f_vty_transceive(MSCVTY, "neighbor a cgi 017 017 1 1 msc-ipa-name msc-017-017-1");
6033 f_vty_transceive(MSCVTY, "exit");
6034 f_vty_transceive(MSCVTY, "exit");
6035
6036 f_perform_lu();
6037 f_mo_call_establish(cpars);
6038
6039 f_sleep(1.0);
6040
6041 var default ack_mdcx := activate(as_mgcp_ack_all_mdcx(cpars));
6042
6043 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
6044 var BssmapCause cause := enum2int(cause_val);
6045
6046 var template BSSMAP_FIELD_CellIdentificationList cil;
Neels Hofmeyr36ebc332021-06-23 03:20:32 +02006047 cil := { cIl_CGI := { ts_BSSMAP_CI_CGI('017'H, '017'H, 1, 1) } };
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006048
6049 /* old BSS sends Handover Required */
6050 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
6051
6052 /* The target cell 017-017 LAC 1 is configured to be a remote MSC of name "msc-017-017-1".
6053 * This MSC tries to reach the other MSC via GSUP. */
6054
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006055 var template BSSMAP_IE_EncryptionInformation encryptionInformation;
6056 var template BSSMAP_IE_ChosenEncryptionAlgorithm chosenEncryptionAlgorithm;
6057 var template BSSMAP_IE_KC128 kC128;
6058 var OCT1 a5_perm_alg;
6059 f_get_expected_encryption(encryptionInformation, chosenEncryptionAlgorithm, kC128, a5_perm_alg);
Vadim Yanitskiyc5fcb892022-08-04 04:06:07 +07006060 var template PDU_BSSAP expect_ho_request := tr_BSSMAP_HandoverRequest(encryptionInformation,
6061 chosenEncryptionAlgorithm,
6062 kC128, codecList := ?);
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006063
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006064 var octetstring remote_msc_name := '6D73632D3031372D3031372D3100'O; /* "msc-017-017-1\0" as octetstring */
6065 var GSUP_PDU prep_ho_req;
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006066 alt {
6067 [] GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_HANDOVER_REQUEST,
6068 pars.imsi, destination_name := remote_msc_name,
Neels Hofmeyrec2e1f72021-07-02 02:08:32 +02006069 an_apdu := t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006, pdu := ?))) -> value prep_ho_req;
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006070 [] GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_HANDOVER_REQUEST)) {
6071 setverdict(fail, "Wrong OSMO_GSUP_MSGT_E_PREPARE_HANDOVER_REQUEST message received");
6072 mtc.stop;
6073 }
6074 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006075
6076 var GSUP_IeValue source_name_ie;
6077 f_gsup_find_ie(prep_ho_req, OSMO_GSUP_SOURCE_NAME_IE, source_name_ie);
6078 var octetstring local_msc_name := source_name_ie.source_name;
6079
Neels Hofmeyrec2e1f72021-07-02 02:08:32 +02006080 /* Decode PDU to 1) match with expect_ho_request and 2) to forward the actual chosen encryption algorithm. */
Neels Hofmeyr906af102021-07-01 12:08:35 +02006081 var GSUP_IeValue an_apdu_ie;
6082 f_gsup_find_ie(prep_ho_req, OSMO_GSUP_AN_APDU_IE, an_apdu_ie);
6083 ho_request := dec_PDU_BSSAP(an_apdu_ie.an_apdu.pdu);
Neels Hofmeyrec2e1f72021-07-02 02:08:32 +02006084 if (not match(ho_request, expect_ho_request)) {
6085 setverdict(fail, "Wrong PDU in OSMO_GSUP_MSGT_E_PREPARE_HANDOVER_REQUEST message received");
6086 mtc.stop;
6087 }
Neels Hofmeyr906af102021-07-01 12:08:35 +02006088
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006089 /* Remote MSC has figured out its BSC and signals success */
6090 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
6091 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
6092 var PDU_BSSAP ho_req_ack := valueof(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
Neels Hofmeyr906af102021-07-01 12:08:35 +02006093 aoIPTransportLayer := omit,
6094 speechCodec := ts_BSSMAP_IE_SpeechCodec({ts_CodecFR}),
6095 chosenEncryptionAlgorithm := ho_request.pdu.bssmap.handoverRequest.chosenEncryptionAlgorithm));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006096 GSUP.send(ts_GSUP_E_PrepareHandoverResult(
6097 pars.imsi,
6098 ho_number,
6099 remote_msc_name, local_msc_name,
6100 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006, enc_PDU_BSSAP(ho_req_ack)))));
6101
6102 /* MSC forwards the RR Handover Command to old BSS */
6103 BSSAP.receive(tr_BSSMAP_HandoverCommand);
6104
6105 /* The MS shows up at remote new BSS */
6106
6107 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PROCESS_ACCESS_SIGNALLING_REQUEST,
6108 pars.imsi, remote_msc_name, local_msc_name,
6109 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
6110 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverDetect))))));
6111 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
6112 f_sleep(0.1);
6113
6114 /* Save the MS sequence counters for use on the other connection */
6115 var N_Sd_Array last_n_sd := f_bssmap_last_n_sd();
6116
6117 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_SEND_END_SIGNAL_REQUEST,
6118 pars.imsi, remote_msc_name, local_msc_name,
6119 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
6120 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverComplete))))));
6121
6122 /* The local BSS conn clears, all communication goes via remote MSC now */
6123 f_expect_clear();
6124
6125 /**********************************/
6126 /* Play through some signalling across the inter-MSC link.
6127 * This is a copy of f_tc_lu_and_mo_ussd_single_request() translated into GSUP AN-APDUs. */
6128
6129 if (false) {
6130 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
6131 invoke_id := 5, /* Phone may not start from 0 or 1 */
6132 op_code := SS_OP_CODE_PROCESS_USS_REQ,
6133 ussd_string := "*#100#"
6134 );
6135
6136 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
6137 invoke_id := 5, /* InvokeID shall be the same for both REQ and RSP */
6138 op_code := SS_OP_CODE_PROCESS_USS_REQ,
6139 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
6140 )
6141
6142 /* Compose a new SS/REGISTER message with request */
6143 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
6144 tid := 1, /* We just need a single transaction */
6145 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
6146 facility := valueof(facility_req)
6147 );
6148 var PDU_ML3_MS_NW ussd_req_v := valueof(ussd_req);
6149
6150 /* Compose SS/RELEASE_COMPLETE template with expected response */
6151 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
6152 tid := 1, /* Response should arrive within the same transaction */
6153 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
6154 facility := valueof(facility_rsp)
6155 );
6156
6157 /* Compose expected MSC -> HLR message */
6158 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
6159 imsi := g_pars.imsi,
6160 state := OSMO_GSUP_SESSION_STATE_BEGIN,
6161 ss := valueof(facility_req)
6162 );
6163
6164 /* To be used for sending response with correct session ID */
6165 var GSUP_PDU gsup_req_complete;
6166
6167 /* Request own number */
6168 /* From remote MSC instead of BSSAP directly */
6169 /* Patch the correct N_SD value into the message. */
6170 var octetstring l3_enc := enc_PDU_ML3_MS_NW(ussd_req_v);
6171 var RAN_Emulation.ConnectionData cd;
6172 f_ML3_patch_seq_nr_MS_NW(f_next_n_sd(last_n_sd, f_ML3_n_sd_idx(ussd_req_v)), l3_enc);
6173 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PROCESS_ACCESS_SIGNALLING_REQUEST,
6174 pars.imsi, remote_msc_name, local_msc_name,
6175 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
6176 enc_PDU_BSSAP(valueof(ts_BSSAP_DTAP(l3_enc)))
6177 ))
6178 ));
6179
6180 /* Expect GSUP message containing the SS payload */
6181 gsup_req_complete := f_expect_gsup_msg(gsup_req);
6182
6183 /* Compose the response from HLR using received session ID */
6184 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
6185 imsi := g_pars.imsi,
6186 sid := gsup_req_complete.ies[1].val.session_id,
6187 state := OSMO_GSUP_SESSION_STATE_END,
6188 ss := valueof(facility_rsp)
6189 );
6190
6191 /* Finally, HLR terminates the session */
6192 GSUP.send(gsup_rsp);
6193
6194 /* The USSD response goes out to remote MSC, on GSUP E instead of BSSAP */
6195 var GSUP_PDU gsup_ussd_rsp;
6196 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_FORWARD_ACCESS_SIGNALLING_REQUEST,
6197 pars.imsi, destination_name := remote_msc_name)) -> value gsup_ussd_rsp;
6198
6199 var GSUP_IeValue an_apdu;
6200 if (not f_gsup_find_ie(gsup_ussd_rsp, OSMO_GSUP_AN_APDU_IE, an_apdu)) {
6201 setverdict(fail, "No AN-APDU in received GSUP message. Expected USSD response in DTAP, got", gsup_ussd_rsp);
6202 mtc.stop;
6203 }
6204 var PDU_BSSAP bssap_dtap_mt := dec_PDU_BSSAP(an_apdu.an_apdu.pdu);
6205 var PDU_ML3_NW_MS dtap_mt := dec_PDU_ML3_NW_MS(bssap_dtap_mt.pdu.dtap);
6206 log("Expecting", ussd_rsp);
6207 log("Got", dtap_mt);
6208 if (not match(dtap_mt, ussd_rsp)) {
6209 setverdict(fail, "Unexpected GSUP message. Expected USSD response in DTAP, got", gsup_ussd_rsp);
6210 mtc.stop;
6211 }
6212 }
6213 /**********************************/
6214
6215
6216 /* inter-MSC handover back to the first MSC */
6217 f_create_bssmap_exp_handoverRequest(193);
6218 cil := { cIl_CGI := { ts_BSSMAP_CI_CGI('262'H, '42'H, 23, 42) } };
6219
6220 /* old BSS sends Handover Required, via inter-MSC E link: like
6221 * BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
6222 * but via GSUP */
6223 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_SUBSEQUENT_HANDOVER_REQUEST,
6224 pars.imsi, remote_msc_name, local_msc_name,
6225 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
6226 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverRequired(cause, cil)))
6227 ))
6228 ));
6229
6230 /* MSC asks local BSS to prepare Handover to it */
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006231 f_get_expected_encryption(encryptionInformation, chosenEncryptionAlgorithm, kC128, a5_perm_alg);
Vadim Yanitskiyc5fcb892022-08-04 04:06:07 +07006232 expect_ho_request := tr_BSSMAP_HandoverRequest(encryptionInformation,
6233 chosenEncryptionAlgorithm,
6234 kC128, codecList := ?);
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006235 alt {
Neels Hofmeyr906af102021-07-01 12:08:35 +02006236 [] BSSAP.receive(expect_ho_request) -> value ho_request;
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006237 [] BSSAP.receive(tr_BSSMAP_HandoverRequest) -> value ho_request {
6238 log("Error: Wrong handoverRequest received. Expected: ", expect_ho_request,
6239 " got ", ho_request);
6240 setverdict(fail, "Wrong handoverRequest received");
6241 mtc.stop;
6242 }
6243 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006244
6245 /* Make sure the new BSSAP conn continues with the correct N_SD sequence numbers */
6246 f_bssmap_continue_after_n_sd(last_n_sd);
6247
6248 /* new BSS composes a RR Handover Command */
6249 rr_ho_cmd := valueof(ts_RR_HandoverCommand);
6250 rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006251 var BSSMAP_IE_AoIP_TransportLayerAddress tla :=
6252 valueof(f_ts_BSSMAP_IE_AoIP_TLA(cpars.bss_rtp_ip, cpars.bss_rtp_port));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006253 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
Neels Hofmeyr906af102021-07-01 12:08:35 +02006254 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR}),
6255 chosenEncryptionAlgorithm := ho_request.pdu.bssmap.handoverRequest.chosenEncryptionAlgorithm));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006256
6257 /* HandoverCommand goes out via remote MSC-I */
6258 var GSUP_PDU prep_subsq_ho_res;
6259 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_SUBSEQUENT_HANDOVER_RESULT,
6260 pars.imsi, destination_name := remote_msc_name)) -> value prep_subsq_ho_res;
6261
6262 /* MS shows up at the local BSS */
6263 BSSAP.send(ts_BSSMAP_HandoverDetect);
6264 f_sleep(0.1);
6265 BSSAP.send(ts_BSSMAP_HandoverComplete);
6266
6267 /* Handover Succeeded message */
6268 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_FORWARD_ACCESS_SIGNALLING_REQUEST,
6269 pars.imsi, destination_name := remote_msc_name));
6270
6271 /* MS has handovered to here, Clear Command goes out via remote MSC-I -- in form of a GSUP Close. */
6272 GSUP.receive(tr_GSUP_E_NO_PDU(OSMO_GSUP_MSGT_E_CLOSE,
6273 pars.imsi, destination_name := remote_msc_name));
6274
6275 /* Handover ends successfully. Call goes on for a little longer and then we hang up. */
6276
6277 f_sleep(1.0);
6278 deactivate(ack_mdcx);
6279
6280 /* FIXME: the inter-MSC call has put a number of MNCC messages in the queue, which above code should expect and
6281 * clear out. The f_call_hangup() expects an MNCC_REL_IND, so, for the time being, just clear the MNCC messages
6282 * before starting the call hangup. Instead of this, the individual messages should be tested for above. */
6283 MNCC.clear;
6284
6285 var default ccrel := activate(as_optional_cc_rel(cpars, true));
6286 f_call_hangup(cpars, true);
6287 f_sleep(1.0);
6288 deactivate(ccrel);
6289
6290 setverdict(pass);
6291}
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006292function f_tc_ho_inter_msc_out_a5(integer a5_n) runs on MTC_CT {
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006293 var BSC_ConnHdlr vc_conn;
6294 f_init(1);
6295
6296 var BSC_ConnHdlrPars pars := f_init_pars(54);
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006297 pars.net.expect_ciph := a5_n > 0;
6298 pars.net.expect_auth := pars.net.expect_ciph;
6299 pars.net.kc_support := bit2oct('00000001'B << a5_n);
6300 pars.cm2.classmarkInformationType2_oct5.a5_3 := '1'B;
6301 pars.cm2.classmarkInformationType2_oct5.a5_2 := '0'B;
6302 pars.cm2.classmarkInformationType2_oct5.cm3 := '1'B;
6303 pars.cm3 := valueof(ts_CM3_default);
6304 pars.use_umts_aka := true;
6305
6306 if (a5_n > 0) {
6307 f_vty_config(MSCVTY, "network", "authentication required");
6308 }
6309 f_vty_config(MSCVTY, "network", "encryption a5 " & int2str(a5_n));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006310
Neels Hofmeyr60122f82021-07-28 17:59:38 +02006311 vc_conn := f_start_handler_with_pars(refers(f_tc_ho_inter_msc_out), pars);
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006312 vc_conn.done;
6313}
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006314testcase TC_ho_inter_msc_out() runs on MTC_CT {
6315 f_tc_ho_inter_msc_out_a5(0);
6316}
6317testcase TC_ho_inter_msc_out_a5_1() runs on MTC_CT {
6318 f_tc_ho_inter_msc_out_a5(1);
6319}
6320testcase TC_ho_inter_msc_out_a5_3() runs on MTC_CT {
6321 f_tc_ho_inter_msc_out_a5(3);
6322}
6323testcase TC_ho_inter_msc_out_a5_4() runs on MTC_CT {
6324 f_tc_ho_inter_msc_out_a5(4);
6325}
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006326testcase TC_ho_inter_msc_out_ipv6() runs on MTC_CT {
6327 var BSC_ConnHdlr vc_conn;
6328 f_init(1);
6329
6330 var BSC_ConnHdlrPars pars := f_init_pars(54);
6331 pars.use_ipv6 := true;
6332
Neels Hofmeyr60122f82021-07-28 17:59:38 +02006333 vc_conn := f_start_handler_with_pars(refers(f_tc_ho_inter_msc_out), pars);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006334 vc_conn.done;
6335}
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006336
Oliver Smith1d118ff2019-07-03 10:57:35 +02006337private function f_tc_lu_imsi_auth_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6338 pars.net.expect_auth := true;
6339 pars.net.expect_imei := true;
6340 f_init_handler(pars);
6341 f_perform_lu();
6342}
6343testcase TC_lu_imsi_auth_tmsi_check_imei() runs on MTC_CT {
6344 var BSC_ConnHdlr vc_conn;
6345 f_init();
6346 f_vty_config(MSCVTY, "network", "authentication required");
6347 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6348
6349 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei), 5);
6350 vc_conn.done;
6351}
6352
6353private function f_tc_lu_imsi_auth3g_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6354 pars.net.expect_auth := true;
6355 pars.use_umts_aka := true;
6356 pars.net.expect_imei := true;
6357 f_init_handler(pars);
6358 f_perform_lu();
6359}
6360testcase TC_lu_imsi_auth3g_tmsi_check_imei() runs on MTC_CT {
6361 var BSC_ConnHdlr vc_conn;
6362 f_init();
6363 f_vty_config(MSCVTY, "network", "authentication required");
6364 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6365
6366 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi_check_imei), 5);
6367 vc_conn.done;
6368}
6369
6370private function f_tc_lu_imsi_noauth_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6371 pars.net.expect_imei := true;
6372 f_init_handler(pars);
6373 f_perform_lu();
6374}
6375testcase TC_lu_imsi_noauth_tmsi_check_imei() runs on MTC_CT {
6376 var BSC_ConnHdlr vc_conn;
6377 f_init();
6378 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6379
6380 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi_check_imei), 5);
6381 vc_conn.done;
6382}
6383
6384private function f_tc_lu_imsi_noauth_notmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6385 pars.net.expect_tmsi := false;
6386 pars.net.expect_imei := true;
6387 f_init_handler(pars);
6388 f_perform_lu();
6389}
6390testcase TC_lu_imsi_noauth_notmsi_check_imei() runs on MTC_CT {
6391 var BSC_ConnHdlr vc_conn;
6392 f_init();
6393 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
6394 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6395
6396 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi_check_imei), 5);
6397 vc_conn.done;
6398}
6399
6400private function f_tc_lu_imsi_auth_tmsi_check_imei_nack(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6401 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02006402
6403 pars.net.expect_auth := true;
6404 pars.net.expect_imei := true;
6405 pars.net.check_imei_result := OSMO_GSUP_IMEI_RESULT_NACK;
6406 f_init_handler(pars);
6407
6408 /* Cannot use f_perform_lu() as we expect a reject */
6409 l3_lu := f_build_lu_imsi(g_pars.imsi)
6410 f_create_gsup_expect(hex2str(g_pars.imsi));
6411 f_bssap_compl_l3(l3_lu);
6412 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
6413
6414 f_mm_common();
6415 f_msc_lu_hlr();
6416 f_mm_imei();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02006417 f_expect_lu_reject();
Eric Wild85cc1612022-03-30 01:44:29 +02006418 f_expect_clear(verify_vlr_cell_id:=false);
Oliver Smith1d118ff2019-07-03 10:57:35 +02006419}
6420testcase TC_lu_imsi_auth_tmsi_check_imei_nack() runs on MTC_CT {
6421 var BSC_ConnHdlr vc_conn;
6422 f_init();
6423 f_vty_config(MSCVTY, "network", "authentication required");
6424 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6425
6426 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_nack), 5);
6427 vc_conn.done;
6428}
6429
6430private function f_tc_lu_imsi_auth_tmsi_check_imei_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6431 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02006432
6433 pars.net.expect_auth := true;
6434 pars.net.expect_imei := true;
6435 pars.net.check_imei_error := true;
6436 f_init_handler(pars);
6437
6438 /* Cannot use f_perform_lu() as we expect a reject */
6439 l3_lu := f_build_lu_imsi(g_pars.imsi)
6440 f_create_gsup_expect(hex2str(g_pars.imsi));
6441 f_bssap_compl_l3(l3_lu);
6442 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
6443
6444 f_mm_common();
6445 f_msc_lu_hlr();
6446 f_mm_imei();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02006447 f_expect_lu_reject();
Eric Wild85cc1612022-03-30 01:44:29 +02006448 f_expect_clear(verify_vlr_cell_id:=false);
Oliver Smith1d118ff2019-07-03 10:57:35 +02006449}
6450testcase TC_lu_imsi_auth_tmsi_check_imei_err() runs on MTC_CT {
6451 var BSC_ConnHdlr vc_conn;
6452 f_init();
6453 f_vty_config(MSCVTY, "network", "authentication required");
6454 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6455
6456 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_err), 5);
6457 vc_conn.done;
6458}
6459
6460private function f_tc_lu_imsi_auth_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6461 pars.net.expect_auth := true;
6462 pars.net.expect_imei_early := true;
6463 f_init_handler(pars);
6464 f_perform_lu();
6465}
6466testcase TC_lu_imsi_auth_tmsi_check_imei_early() runs on MTC_CT {
6467 var BSC_ConnHdlr vc_conn;
6468 f_init();
6469 f_vty_config(MSCVTY, "network", "authentication required");
6470 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6471
6472 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early), 5);
6473 vc_conn.done;
6474}
6475
6476private function f_tc_lu_imsi_auth3g_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6477 pars.net.expect_auth := true;
6478 pars.use_umts_aka := true;
6479 pars.net.expect_imei_early := true;
6480 f_init_handler(pars);
6481 f_perform_lu();
6482}
6483testcase TC_lu_imsi_auth3g_tmsi_check_imei_early() runs on MTC_CT {
6484 var BSC_ConnHdlr vc_conn;
6485 f_init();
6486 f_vty_config(MSCVTY, "network", "authentication required");
6487 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6488
6489 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi_check_imei_early), 5);
6490 vc_conn.done;
6491}
6492
6493private function f_tc_lu_imsi_noauth_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6494 pars.net.expect_imei_early := true;
6495 f_init_handler(pars);
6496 f_perform_lu();
6497}
6498testcase TC_lu_imsi_noauth_tmsi_check_imei_early() runs on MTC_CT {
6499 var BSC_ConnHdlr vc_conn;
6500 f_init();
6501 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6502
6503 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi_check_imei_early), 5);
6504 vc_conn.done;
6505}
6506
6507private function f_tc_lu_imsi_noauth_notmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6508 pars.net.expect_tmsi := false;
6509 pars.net.expect_imei_early := true;
6510 f_init_handler(pars);
6511 f_perform_lu();
6512}
6513testcase TC_lu_imsi_noauth_notmsi_check_imei_early() runs on MTC_CT {
6514 var BSC_ConnHdlr vc_conn;
6515 f_init();
6516 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
6517 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6518
6519 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi_check_imei_early), 5);
6520 vc_conn.done;
6521}
6522
6523private function f_tc_lu_imsi_auth_tmsi_check_imei_early_nack(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6524 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02006525
6526 pars.net.expect_auth := true;
6527 pars.net.expect_imei_early := true;
6528 pars.net.check_imei_result := OSMO_GSUP_IMEI_RESULT_NACK;
6529 f_init_handler(pars);
6530
6531 /* Cannot use f_perform_lu() as we expect a reject */
6532 l3_lu := f_build_lu_imsi(g_pars.imsi)
6533 f_create_gsup_expect(hex2str(g_pars.imsi));
6534 f_bssap_compl_l3(l3_lu);
6535 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
6536
6537 f_mm_imei_early();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02006538 f_expect_lu_reject();
Eric Wild85cc1612022-03-30 01:44:29 +02006539 f_expect_clear(verify_vlr_cell_id:=false);
Oliver Smith1d118ff2019-07-03 10:57:35 +02006540}
6541testcase TC_lu_imsi_auth_tmsi_check_imei_early_nack() runs on MTC_CT {
6542 var BSC_ConnHdlr vc_conn;
6543 f_init();
6544 f_vty_config(MSCVTY, "network", "authentication required");
6545 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6546
6547 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early_nack), 5);
6548 vc_conn.done;
6549}
6550
6551private function f_tc_lu_imsi_auth_tmsi_check_imei_early_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6552 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02006553
6554 pars.net.expect_auth := true;
6555 pars.net.expect_imei_early := true;
6556 pars.net.check_imei_error := true;
6557 f_init_handler(pars);
6558
6559 /* Cannot use f_perform_lu() as we expect a reject */
6560 l3_lu := f_build_lu_imsi(g_pars.imsi)
6561 f_create_gsup_expect(hex2str(g_pars.imsi));
6562 f_bssap_compl_l3(l3_lu);
6563 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
6564
6565 f_mm_imei_early();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02006566 f_expect_lu_reject();
Eric Wild85cc1612022-03-30 01:44:29 +02006567 f_expect_clear(verify_vlr_cell_id:=false);
Oliver Smith1d118ff2019-07-03 10:57:35 +02006568}
6569testcase TC_lu_imsi_auth_tmsi_check_imei_early_err() runs on MTC_CT {
6570 var BSC_ConnHdlr vc_conn;
6571 f_init();
6572 f_vty_config(MSCVTY, "network", "authentication required");
6573 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6574
6575 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early_err), 5);
6576 vc_conn.done;
6577}
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006578
Neels Hofmeyr8df69622019-11-02 19:16:03 +01006579friend function f_tc_invalid_mgcp_crash(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6580 f_init_handler(pars);
6581 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
6582
6583 /* Set invalid IP address so that osmo-msc discards the rtp_stream and MGCP endpoint FSM instances in the middle
6584 * of successful MGCP response dispatch. If things aren't safeguarded, the on_success() in osmo_mgcpc_ep_fsm
6585 * will cause a use-after-free after that event dispatch. */
6586 cpars.mgw_conn_1.mgw_rtp_ip := "0.0.0.0";
6587 cpars.mgw_conn_2.mgw_rtp_ip := "0.0.0.0";
6588 cpars.rtp_sdp_format := "FOO/8000";
6589 cpars.expect_release := true;
6590
6591 f_perform_lu();
6592 f_mo_call_establish(cpars);
6593}
6594testcase TC_invalid_mgcp_crash() runs on MTC_CT {
6595 var BSC_ConnHdlr vc_conn;
6596 f_init();
6597
6598 vc_conn := f_start_handler(refers(f_tc_invalid_mgcp_crash), 7);
6599 vc_conn.done;
6600}
6601
Vadim Yanitskiyeddebaa2019-12-28 17:45:34 +01006602friend function f_tc_mm_id_resp_no_identity(charstring id, BSC_ConnHdlrPars pars)
6603runs on BSC_ConnHdlr {
6604 pars.tmsi := 'FFFFFFFF'O;
6605 f_init_handler(pars);
6606
6607 f_create_gsup_expect(hex2str(g_pars.imsi));
6608
6609 /* Initiate Location Updating using an unknown TMSI */
6610 f_bssap_compl_l3(f_build_lu_tmsi(pars.tmsi));
6611
6612 /* Expect an Identity Request, send response with no identity */
6613 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
6614 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp({
6615 lengthIndicator := 1,
6616 mobileIdentityV := {
6617 typeOfIdentity := '000'B,
6618 oddEvenInd_identity := {
6619 no_identity := {
6620 oddevenIndicator := '0'B,
6621 fillerDigits := '00000'H
6622 }
6623 }
6624 }
6625 })));
6626
6627 f_expect_lu_reject();
6628 f_expect_clear();
6629}
6630testcase TC_mm_id_resp_no_identity() runs on MTC_CT {
6631 var BSC_ConnHdlr vc_conn;
6632
6633 f_init();
6634
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02006635 vc_conn := f_start_handler(refers(f_tc_mm_id_resp_no_identity), 7, verify_cell_id := false);
Vadim Yanitskiyeddebaa2019-12-28 17:45:34 +01006636 vc_conn.done;
6637}
6638
Vadim Yanitskiy25219062020-01-21 01:41:33 +07006639/* Verify the case when T3212 expires during Paging procedure, just before the receipt
6640 * of Paging Response. This used to provoke a NULL-pointer dereference in old versions
6641 * of OsmoMSC, but apparently the bug has been fixed, and we're safe now. */
6642friend function f_tc_lu_and_expire_while_paging(charstring id, BSC_ConnHdlrPars pars)
6643runs on BSC_ConnHdlr {
6644 var charstring imsi := hex2str(pars.imsi);
6645
6646 f_init_handler(pars);
6647
6648 /* Perform location update */
6649 f_perform_lu();
6650
6651 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
6652 f_create_gsup_expect(hex2str(g_pars.imsi));
6653
6654 /* Initiate paging procedure from the VTY */
6655 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " paging");
6656 f_expect_paging();
6657
6658 /* Emulate T3212 expiration during paging (we don't want to wait, right?) */
6659 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " expire");
6660
6661 /* MS sends PAGING RESPONSE, *old* OsmoMSC crashes here... */
6662 f_establish_fully(EST_TYPE_PAG_RESP);
6663
6664 /* The recent OsmoMSC keeps subscriber in its VLR unless the Paging is completed.
6665 * In this case we do not send anything and just wait for a Clear Command. */
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02006666 f_expect_clear(verify_vlr_cell_id := false);
Vadim Yanitskiy25219062020-01-21 01:41:33 +07006667}
6668testcase TC_lu_and_expire_while_paging() runs on MTC_CT {
6669 var BSC_ConnHdlr vc_conn;
6670
6671 f_init();
6672
6673 vc_conn := f_start_handler(refers(f_tc_lu_and_expire_while_paging), 7);
6674 vc_conn.done;
6675}
6676
Neels Hofmeyr3ad76a42022-08-09 02:57:49 +02006677private altstep as_mncc_rx_rtp_create(CallParameters cpars) runs on BSC_ConnHdlr {
6678 [] MNCC.receive(tr_MNCC_RTP_CREATE(cpars.mncc_callref));
6679}
6680
Neels Hofmeyr4f099b42021-07-27 03:45:26 +02006681const charstring REEST_LOST_CONNECTION := "REEST_LOST_CONNECTION";
6682const charstring REEST_CLEARED := "REEST_CLEARED";
6683
6684friend function f_tc_call_re_establishment_1(charstring id, BSC_ConnHdlrPars pars)
6685 runs on BSC_ConnHdlr {
6686 f_init_handler(pars, t_guard := 30.0);
6687
6688 f_perform_lu();
6689
6690 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
6691 f_mo_call_establish(cpars);
6692 f_sleep(3.0);
6693 COORD.send(REEST_LOST_CONNECTION);
6694 COORD.send(cpars);
6695 f_expect_clear(verify_vlr_cell_id := false);
6696 COORD.send(REEST_CLEARED);
6697}
6698
6699friend function f_tc_call_re_establishment_2(charstring id, BSC_ConnHdlrPars pars)
6700 runs on BSC_ConnHdlr {
6701 f_init_handler(pars, t_guard := 30.0);
6702 var CallParameters cpars;
6703
6704 COORD.receive(REEST_LOST_CONNECTION);
6705 COORD.receive(tr_CallParams) -> value cpars;
6706
6707 f_gsup_change_connhdlr(hex2str(g_pars.imsi));
6708 f_create_smpp_expect(hex2str(pars.msisdn));
6709
6710 /* The MS has lost the first channel and decides to show up on a new conn (on a nearby neighbor cell) to ask for
6711 * CM Re-Establishment. Send a Complete Layer 3 to osmo-msc with a CM Re-Establishment Request. */
6712 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
6713 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_REESTABL_REQ(mi));
6714 f_cl3_or_initial_ue(l3_info);
6715
6716 /* At this point the other test component should receive the Clear Command for the first A connection. */
6717
6718 /* This new connection continues with Authentication... */
6719 f_mm_common();
6720
6721 /* ...and with Assignment of a voice channel. */
6722 var template BSSMAP_IE_AoIP_TransportLayerAddress tla_ass :=
Neels Hofmeyr02d513e2022-07-25 22:07:24 +02006723 (f_tr_BSSMAP_IE_AoIP_TLA(cpars.mgw_conn_1.mgw_rtp_ip, ?),
6724 f_tr_BSSMAP_IE_AoIP_TLA(cpars.mgw_conn_2.mgw_rtp_ip, ?));
Neels Hofmeyr4f099b42021-07-27 03:45:26 +02006725 BSSAP.receive(tr_BSSMAP_AssignmentReq(omit, tla_ass));
6726 /* By this Assignment Request, the CM Re-Establishment Request is implicitly accepted. */
6727
6728 /* Send Assignment Complete from BSC */
6729 var template BSSMAP_IE_AoIP_TransportLayerAddress tla;
6730 tla := f_ts_BSSMAP_IE_AoIP_TLA(cpars.bss_rtp_ip, cpars.bss_rtp_port);
6731 var BSSMAP_IE_SpeechCodec codec;
6732 codec := valueof(ts_BSSMAP_IE_SpeechCodec({ts_CodecFR}));
6733
6734 /* Make really sure the other component is done with its MGCP */
6735 COORD.receive(REEST_CLEARED);
6736
6737 /* Transfer state for this call over to this test component so we can resolve MNCC and MGCP in this function. */
6738 f_mncc_change_connhdlr(cpars.mncc_callref);
6739 f_mgcp_change_connhdlr(cpars.mgcp_ep);
6740
6741 /* osmo-msc may redirect the MGW endpoint to the newly allocated channel.
6742 * Apparently osmo-msc currently also sends an MDCX to the CN side, just repeating the same configuration that
6743 * is already in use. This test accepts any number of or even lack of MDCX. */
6744 var default ack_mdcx := activate(as_mgcp_ack_all_mdcx(cpars));
Neels Hofmeyr3ad76a42022-08-09 02:57:49 +02006745 var default optional_rtp_create := activate(as_mncc_rx_rtp_create(cpars));
Neels Hofmeyr4f099b42021-07-27 03:45:26 +02006746
6747 BSSAP.send(ts_BSSMAP_AssignmentComplete(omit, tla, codec));
Neels Hofmeyr3ad76a42022-08-09 02:57:49 +02006748
Neels Hofmeyr4f099b42021-07-27 03:45:26 +02006749 /* The call has been fully re-established.
6750 * Let a bit of time pass before hanging up, for everything to settle. */
6751 f_sleep(3.0);
6752
Neels Hofmeyr3ad76a42022-08-09 02:57:49 +02006753 deactivate(optional_rtp_create);
Neels Hofmeyr4f099b42021-07-27 03:45:26 +02006754 deactivate(ack_mdcx);
6755
6756 /* Hang up the call and clear the new, second A connection */
6757 var default ack_dlcx := activate(as_mgcp_ack_all_dlcx(cpars));
6758
6759 /* CC release. This is the proper MS initiated release sequence as shown by
6760 * https://git.osmocom.org/osmo-msc/tree/doc/sequence_charts/voice_call_full.msc?id=e53ecde83e4fb2470209e818e9ad76a2d6a19190
6761 * f_call_hangup() seems a bit mixed up, so here a "proper" sequence. Fix of f_call_hangup() pending. */
6762 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_DISC(cpars.transaction_id, '0'B, '0000000'B)));
6763 MNCC.receive(tr_MNCC_DISC_ind(cpars.mncc_callref));
6764 MNCC.send(ts_MNCC_REL_req(cpars.mncc_callref, valueof(ts_MNCC_cause(23))));
6765 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id)));
6766 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id, '0'B)));
6767 MNCC.receive(tr_MNCC_REL_cnf(cpars.mncc_callref, cause := *));
6768
6769 /* BSSAP clear */
6770 interleave {
6771 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {
6772 BSSAP.send(ts_BSSMAP_ClearComplete);
6773 }
6774 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND);
6775 }
6776
6777 f_sleep(1.0);
6778 deactivate(ack_dlcx);
6779}
6780
6781testcase TC_call_re_establishment() runs on MTC_CT {
6782 var BSC_ConnHdlr vc_conn1;
6783 var BSC_ConnHdlr vc_conn2;
6784 f_init();
6785
6786 var BSC_ConnHdlrPars pars1 := f_init_pars(91);
6787 var BSC_ConnHdlrPars pars2 := pars1;
6788
6789 vc_conn1 := f_start_handler_create(pars1);
6790 vc_conn2 := f_start_handler_create(pars2);
6791 connect(vc_conn1:COORD, vc_conn2:COORD);
6792 f_start_handler_run(vc_conn1, refers(f_tc_call_re_establishment_1), pars1);
6793 f_start_handler_run(vc_conn2, refers(f_tc_call_re_establishment_2), pars2);
6794 vc_conn1.done;
6795 vc_conn2.done;
6796}
6797
Neels Hofmeyra9b2dcf2021-07-28 00:57:58 +02006798testcase TC_call_re_establishment_auth() runs on MTC_CT {
6799 var BSC_ConnHdlr vc_conn1;
6800 var BSC_ConnHdlr vc_conn2;
6801 f_init();
6802
6803 f_vty_config(MSCVTY, "network", "authentication required");
6804
6805 var BSC_ConnHdlrPars pars1 := f_init_pars(92);
6806 pars1.net.expect_auth := true;
6807 var BSC_ConnHdlrPars pars2 := pars1;
6808
6809 vc_conn1 := f_start_handler_create(pars1);
6810 vc_conn2 := f_start_handler_create(pars2);
6811 connect(vc_conn1:COORD, vc_conn2:COORD);
6812 f_start_handler_run(vc_conn1, refers(f_tc_call_re_establishment_1), pars1);
6813 f_start_handler_run(vc_conn2, refers(f_tc_call_re_establishment_2), pars2);
6814 vc_conn1.done;
6815 vc_conn2.done;
6816}
6817
Neels Hofmeyr48e4d7d2021-07-28 00:57:58 +02006818testcase TC_call_re_establishment_ciph() runs on MTC_CT {
6819 var BSC_ConnHdlr vc_conn1;
6820 var BSC_ConnHdlr vc_conn2;
6821 f_init();
6822
6823 f_vty_config(MSCVTY, "network", "authentication required");
6824 f_vty_config(MSCVTY, "network", "encryption a5 3");
6825
6826 var BSC_ConnHdlrPars pars1 := f_init_pars(92);
6827 pars1.net.expect_auth := true;
6828 pars1.net.expect_ciph := true;
6829 pars1.net.kc_support := '08'O; /* A5/3 only */
6830 var BSC_ConnHdlrPars pars2 := pars1;
6831
6832 vc_conn1 := f_start_handler_create(pars1);
6833 vc_conn2 := f_start_handler_create(pars2);
6834 connect(vc_conn1:COORD, vc_conn2:COORD);
6835 f_start_handler_run(vc_conn1, refers(f_tc_call_re_establishment_1), pars1);
6836 f_start_handler_run(vc_conn2, refers(f_tc_call_re_establishment_2), pars2);
6837 vc_conn1.done;
6838 vc_conn2.done;
6839}
6840
Neels Hofmeyr07ea7f22022-05-05 01:39:26 +02006841/* Establish a conn with a valid Mobile Identity. Then send a CM Service Request containing a mismatching Mobile
6842 * Identity on the same conn. Caused a crash, see OS#5532. */
6843friend function f_tc_cm_serv_wrong_mi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6844 f_init_handler(pars);
6845
6846 /* Set up a fully identified conn */
6847 f_perform_lu();
6848 f_establish_fully();
6849
6850 /* CM Serv Req with mismatching Mobile Identity */
6851 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(f_gen_imsi(99999))); /* ensure it is different from below*/
6852 BSSAP.send(ts_PDU_DTAP_MO(ts_CM_SERV_REQ(CM_TYPE_MO_SMS, mi)));
6853 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ));
6854
6855 /* Cancel the first CM Service from f_establish_fully() */
6856 BSSAP.send(ts_BSSMAP_ClearRequest(0));
6857
6858 f_expect_clear();
6859}
6860testcase TC_cm_serv_wrong_mi() runs on MTC_CT {
6861 var BSC_ConnHdlr vc_conn;
6862 f_init();
6863 vc_conn := f_start_handler(refers(f_tc_cm_serv_wrong_mi), 94);
6864 vc_conn.done;
6865}
6866
Neels Hofmeyre860fc42022-10-05 01:15:54 +02006867/* a5 0 a5 0 a5 0 3 a5 0 3 a5 3 a5 3
6868 * HLR has auth info no yes no yes no yes
6869 *
6870 * test case index [0] [1] [2] [3] [4] [5]
6871 * authentication optional No auth No auth attempt auth, auth reject auth
6872 * (%) fall back to +ciph +ciph
6873 * no-auth
6874 *
6875 * [6] [7] [8] [9] [10] [11]
6876 * authentication mandatory reject auth reject auth reject auth
6877 * only +ciph +ciph
6878 *
6879 * (%): Arguably, when HLR has auth info, the MSC should use it. Current behavior of osmo-msc is to not attempt auth at
6880 * all. Related: OS#4830.
6881 */
6882type record of BSC_ConnHdlrNetworkPars rof_netpars;
6883
6884const rof_netpars auth_options_testcases := {
6885 {
6886 /* [0] auth optional, encr a5 0: no-auth" */
6887 kc_support := '01'O,
6888 net_config := { "authentication optional",
6889 "encryption a5 0" },
6890 expect_attach_success := true,
6891 expect_tmsi := true,
6892 expect_auth_attempt := false,
6893 hlr_has_auth_info := false,
6894 expect_auth := false,
6895 expect_ciph := false,
6896 expect_imei := false,
6897 expect_imei_early := false,
6898 check_imei_result := OSMO_GSUP_IMEI_RESULT_ACK,
6899 check_imei_error := false
6900 },
6901 {
6902 /* [1] auth optional, encr a5 0, HLR HAS auth info: no-auth */
6903 kc_support := '01'O,
6904 net_config := { "authentication optional",
6905 "encryption a5 0" },
6906 expect_attach_success := true,
6907 expect_tmsi := true,
6908 expect_auth_attempt := false,
6909 hlr_has_auth_info := true,
6910 expect_auth := false,
6911 expect_ciph := false,
6912 expect_imei := false,
6913 expect_imei_early := false,
6914 check_imei_result := OSMO_GSUP_IMEI_RESULT_ACK,
6915 check_imei_error := false
6916 },
6917 {
6918 /* [2] auth optional, encr a5 0 3, HLR has NO Auth Info: Fall back to no-auth" */
6919 kc_support := '09'O,
6920 net_config := { "authentication optional",
6921 "encryption a5 0 3" },
6922 expect_attach_success := true,
6923 expect_tmsi := true,
6924 expect_auth_attempt := true,
6925 hlr_has_auth_info := false,
6926 expect_auth := false,
6927 expect_ciph := false,
6928 expect_imei := false,
6929 expect_imei_early := false,
6930 check_imei_result := OSMO_GSUP_IMEI_RESULT_ACK,
6931 check_imei_error := false
6932 },
6933 {
6934 /* [3] auth optional, encr a5 0 3, HLR HAS Auth Info: Use A5/3 */
6935 kc_support := '09'O,
6936 net_config := { "authentication optional",
6937 "encryption a5 0 3" },
6938 expect_attach_success := true,
6939 expect_tmsi := true,
6940 expect_auth_attempt := true,
6941 hlr_has_auth_info := true,
6942 expect_auth := true,
6943 expect_ciph := true,
6944 expect_imei := false,
6945 expect_imei_early := false,
6946 check_imei_result := OSMO_GSUP_IMEI_RESULT_ACK,
6947 check_imei_error := false
6948 },
6949 {
6950 /* [4] auth optional, encr a5 3, HLR has NO Auth Info: reject.
6951 * Auth is required implicitly because ciph is required. */
6952 kc_support := '08'O,
6953 net_config := { "authentication optional",
6954 "encryption a5 3" },
6955 expect_attach_success := false,
6956 expect_tmsi := true,
6957 expect_auth_attempt := true,
6958 hlr_has_auth_info := false,
6959 expect_auth := false,
6960 expect_ciph := false,
6961 expect_imei := false,
6962 expect_imei_early := false,
6963 check_imei_result := OSMO_GSUP_IMEI_RESULT_ACK,
6964 check_imei_error := false
6965 },
6966 {
6967 /* [5] auth optional, encr a5 3, HLR HAS Auth Info: auth + ciph.
6968 * Auth is required implicitly because ciph is required. */
6969 kc_support := '08'O,
6970 net_config := { "authentication optional",
6971 "encryption a5 3" },
6972 expect_attach_success := true,
6973 expect_tmsi := true,
6974 expect_auth_attempt := true,
6975 hlr_has_auth_info := true,
6976 expect_auth := true,
6977 expect_ciph := true,
6978 expect_imei := false,
6979 expect_imei_early := false,
6980 check_imei_result := OSMO_GSUP_IMEI_RESULT_ACK,
6981 check_imei_error := false
6982 },
6983
6984 /* Same as above, but with 'authentication required' */
6985
6986 {
6987 /* [6] auth required, encr a5 0, HLR has NO auth info: reject */
6988 kc_support := '01'O,
6989 net_config := { "authentication required",
6990 "encryption a5 0" },
6991 expect_attach_success := false,
6992 expect_tmsi := true,
6993 expect_auth_attempt := true,
6994 hlr_has_auth_info := false,
6995 expect_auth := false,
6996 expect_ciph := false,
6997 expect_imei := false,
6998 expect_imei_early := false,
6999 check_imei_result := OSMO_GSUP_IMEI_RESULT_ACK,
7000 check_imei_error := false
7001 },
7002 {
7003 /* [7] auth required, encr a5 0, HLR HAS auth info: do auth, no ciph" */
7004 kc_support := '01'O,
7005 net_config := { "authentication required",
7006 "encryption a5 0" },
7007 expect_attach_success := true,
7008 expect_tmsi := true,
7009 expect_auth_attempt := true,
7010 hlr_has_auth_info := true,
7011 expect_auth := true,
7012 expect_ciph := false,
7013 expect_imei := false,
7014 expect_imei_early := false,
7015 check_imei_result := OSMO_GSUP_IMEI_RESULT_ACK,
7016 check_imei_error := false
7017 },
7018 {
7019 /* [8] auth required, encr a5 0 3, HLR has NO Auth Info: reject */
7020 kc_support := '09'O,
7021 net_config := { "authentication required",
7022 "encryption a5 0 3" },
7023 expect_attach_success := false,
7024 expect_tmsi := true,
7025 expect_auth_attempt := true,
7026 hlr_has_auth_info := false,
7027 expect_auth := false,
7028 expect_ciph := false,
7029 expect_imei := false,
7030 expect_imei_early := false,
7031 check_imei_result := OSMO_GSUP_IMEI_RESULT_ACK,
7032 check_imei_error := false
7033 },
7034 {
7035 /* [9] auth required, encr a5 0 3, HLR HAS Auth Info: Use A5/3 */
7036 kc_support := '09'O,
7037 net_config := { "authentication required",
7038 "encryption a5 0 3" },
7039 expect_attach_success := true,
7040 expect_tmsi := true,
7041 expect_auth_attempt := true,
7042 hlr_has_auth_info := true,
7043 expect_auth := true,
7044 expect_ciph := true,
7045 expect_imei := false,
7046 expect_imei_early := false,
7047 check_imei_result := OSMO_GSUP_IMEI_RESULT_ACK,
7048 check_imei_error := false
7049 },
7050 {
7051 /* [10] auth required, encr a5 3, HLR has NO Auth Info: reject. */
7052 kc_support := '08'O,
7053 net_config := { "authentication required",
7054 "encryption a5 3" },
7055 expect_attach_success := false,
7056 expect_tmsi := true,
7057 expect_auth_attempt := true,
7058 hlr_has_auth_info := false,
7059 expect_auth := false,
7060 expect_ciph := false,
7061 expect_imei := false,
7062 expect_imei_early := false,
7063 check_imei_result := OSMO_GSUP_IMEI_RESULT_ACK,
7064 check_imei_error := false
7065 },
7066 {
7067 /* [11] auth required, encr a5 3, HLR HAS Auth Info: auth + ciph. */
7068 kc_support := '08'O,
7069 net_config := { "authentication required",
7070 "encryption a5 3" },
7071 expect_attach_success := true,
7072 expect_tmsi := true,
7073 expect_auth_attempt := true,
7074 hlr_has_auth_info := true,
7075 expect_auth := true,
7076 expect_ciph := true,
7077 expect_imei := false,
7078 expect_imei_early := false,
7079 check_imei_result := OSMO_GSUP_IMEI_RESULT_ACK,
7080 check_imei_error := false
7081 }
7082};
7083
7084private function f_tc_auth_options(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
7085 f_init_handler(pars);
7086
7087 /* Location Updating */
7088 log(MSCVTY, "f_perform_lu() starting");
7089 f_perform_lu();
7090 log(MSCVTY, "f_perform_lu() done");
7091
7092 f_sleep(1.0);
7093
7094 if (not pars.net.expect_attach_success) {
7095 /* Expected above LU to fail. In order to test CM Service Request below, a LU has to succeed first. So
7096 * run another LU that will be successful. Careful not to load auth tokens into the VLR that may taint
7097 * the test for CM Service Request below. */
7098
7099 log(MSCVTY, "Running a successful LU so that CM Service Request can be tested");
7100 var BSC_ConnHdlrNetworkPars saved_net := g_pars.net;
7101 g_pars.net.kc_support := '01'O;
7102 g_pars.net.expect_attach_success := true;
7103 g_pars.net.expect_auth_attempt := false;
7104 g_pars.net.expect_auth := false;
7105 g_pars.net.expect_ciph := false;
7106 f_vty_config3(MSCVTY, {"network"}, {"authentication optional", "encryption a5 0"});
7107 f_perform_lu();
7108
7109 /* Reconfigure like it was before */
7110 g_pars.net := saved_net;
7111 f_vty_config3(MSCVTY, {"network"}, g_pars.net.net_config);
7112 log(MSCVTY, "Running a successful LU done");
7113 }
7114
7115 /* CM Service Request */
7116 log(MSCVTY, "f_establish_fully() starting");
7117 f_establish_fully();
7118 log(MSCVTY, "f_establish_fully() done");
7119 BSSAP.send(ts_BSSMAP_ClearRequest(0));
7120 f_expect_clear();
7121}
7122
7123function f_TC_auth_options(integer tc_i) runs on MTC_CT {
7124 f_init();
7125
7126 var BSC_ConnHdlrNetworkPars tc := auth_options_testcases[tc_i];
7127
7128 f_vty_config3(MSCVTY, {"network"}, tc.net_config);
7129
7130 var BSC_ConnHdlrPars pars := f_init_pars(42300 + tc_i);
7131 pars.net := tc;
7132
7133 var BSC_ConnHdlr vc_conn;
7134 vc_conn := f_start_handler_with_pars(refers(f_tc_auth_options), pars);
7135 vc_conn.done;
7136}
7137
7138testcase TC_auth_options_0() runs on MTC_CT {
7139 f_TC_auth_options(0);
7140}
7141
7142testcase TC_auth_options_1() runs on MTC_CT {
7143 f_TC_auth_options(1);
7144}
7145
7146testcase TC_auth_options_2() runs on MTC_CT {
7147 f_TC_auth_options(2);
7148}
7149
7150testcase TC_auth_options_3() runs on MTC_CT {
7151 f_TC_auth_options(3);
7152}
7153
7154testcase TC_auth_options_4() runs on MTC_CT {
7155 f_TC_auth_options(4);
7156}
7157
7158testcase TC_auth_options_5() runs on MTC_CT {
7159 f_TC_auth_options(5);
7160}
7161
7162testcase TC_auth_options_6() runs on MTC_CT {
7163 f_TC_auth_options(6);
7164}
7165
7166testcase TC_auth_options_7() runs on MTC_CT {
7167 f_TC_auth_options(7);
7168}
7169
7170testcase TC_auth_options_8() runs on MTC_CT {
7171 f_TC_auth_options(8);
7172}
7173
7174testcase TC_auth_options_9() runs on MTC_CT {
7175 f_TC_auth_options(9);
7176}
7177
7178testcase TC_auth_options_10() runs on MTC_CT {
7179 f_TC_auth_options(10);
7180}
7181
7182testcase TC_auth_options_11() runs on MTC_CT {
7183 f_TC_auth_options(11);
7184}
7185
Harald Weltef6dd64d2017-11-19 12:09:51 +01007186control {
Philipp Maier328d1662018-03-07 10:40:27 +01007187 execute( TC_cr_before_reset() );
Harald Weltea49e36e2018-01-21 19:29:33 +01007188 execute( TC_lu_imsi_noauth_tmsi() );
Harald Welted2328a22018-01-27 14:27:16 +01007189 execute( TC_lu_imsi_noauth_notmsi() );
Harald Weltea49e36e2018-01-21 19:29:33 +01007190 execute( TC_lu_imsi_reject() );
7191 execute( TC_lu_imsi_timeout_gsup() );
Harald Welted2328a22018-01-27 14:27:16 +01007192 execute( TC_lu_imsi_auth_tmsi() );
Harald Welte8a397ae2019-04-21 22:03:37 +02007193 execute( TC_lu_imsi_auth3g_tmsi() );
Pau Espin Pedrold3d54a92019-12-17 17:02:54 +01007194 execute( TC_lu_imsi_timeout_tmsi_realloc() );
Harald Welted2328a22018-01-27 14:27:16 +01007195 execute( TC_cmserv_imsi_unknown() );
Neels Hofmeyr13737fb2020-08-19 13:16:14 +00007196 execute( TC_cmserv_tmsi_unknown() );
Harald Welte2bb825f2018-01-22 11:31:18 +01007197 execute( TC_lu_and_mo_call() );
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02007198 execute( TC_lu_and_mo_call_ipv6() );
Pau Espin Pedrola42745c2020-01-10 18:03:28 +01007199 execute( TC_lu_and_mo_call_sccp_tiar_timeout() );
Harald Welte071ed732018-01-23 19:53:52 +01007200 execute( TC_lu_auth_sai_timeout() );
7201 execute( TC_lu_auth_sai_err() );
Harald Weltee1a2f3c2018-01-24 17:28:48 +01007202 execute( TC_lu_clear_request() );
Vadim Yanitskiy109e7552021-02-05 05:36:02 +01007203 execute( TC_mo_call_clear_request() );
7204 execute( TC_mt_call_clear_request() );
Harald Weltee1a2f3c2018-01-24 17:28:48 +01007205 execute( TC_lu_disconnect() );
7206 execute( TC_lu_by_imei() );
7207 execute( TC_lu_by_tmsi_noauth_unknown() );
Neels Hofmeyrfc06c732020-08-19 12:52:28 +00007208 execute( TC_attached_imsi_lu_unknown_tmsi() );
Harald Weltee1a2f3c2018-01-24 17:28:48 +01007209 execute( TC_imsi_detach_by_imsi() );
7210 execute( TC_imsi_detach_by_tmsi() );
7211 execute( TC_imsi_detach_by_imei() );
7212 execute( TC_emerg_call_imei_reject() );
7213 execute( TC_emerg_call_imsi() );
7214 execute( TC_cm_serv_req_vgcs_reject() );
7215 execute( TC_cm_serv_req_vbs_reject() );
7216 execute( TC_cm_serv_req_lcs_reject() );
Harald Welte0195ab12018-01-24 21:50:20 +01007217 execute( TC_cm_reest_req_reject() );
Harald Welte1af6ea82018-01-25 18:33:15 +01007218 execute( TC_lu_auth_2G_fail() );
7219 execute( TC_lu_imsi_auth_tmsi_encr_13_13() );
7220 execute( TC_cl3_no_payload() );
7221 execute( TC_cl3_rnd_payload() );
Harald Welte1852a842018-01-26 22:53:36 +01007222 execute( TC_establish_and_nothing() );
7223 execute( TC_mo_setup_and_nothing() );
7224 execute( TC_mo_crcx_ran_timeout() );
7225 execute( TC_mo_crcx_ran_reject() );
Harald Welted2328a22018-01-27 14:27:16 +01007226 execute( TC_mt_crcx_ran_reject() );
Daniel Willmann8b084372018-02-04 13:35:26 +01007227 execute( TC_mo_setup_and_dtmf_dup() );
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01007228 execute( TC_mt_t310() );
Harald Welte167458a2018-01-27 15:58:16 +01007229 execute( TC_gsup_cancel() );
Harald Welte9de84792018-01-28 01:06:35 +01007230 execute( TC_lu_imsi_auth_tmsi_encr_1_13() );
7231 execute( TC_lu_imsi_auth_tmsi_encr_3_13() );
7232 execute( TC_lu_imsi_auth_tmsi_encr_3_1() );
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01007233 execute( TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() );
Harald Welte9de84792018-01-28 01:06:35 +01007234 execute( TC_lu_imsi_auth_tmsi_encr_13_2() );
7235 execute( TC_lu_imsi_auth_tmsi_encr_013_2() );
Eric Wild26f4a622021-05-17 15:27:05 +02007236 execute( TC_lu_imsi_auth_tmsi_encr_0134_1() );
7237 execute( TC_lu_imsi_auth_tmsi_encr_0134_34() );
7238 execute( TC_lu_imsi_auth_tmsi_encr_0134_34_no_cm3() );
7239
Philipp Maier94f3f1b2018-03-15 18:54:13 +01007240 execute( TC_mo_release_timeout() );
Philipp Maier2a98a732018-03-19 16:06:12 +01007241 execute( TC_lu_and_mt_call_no_dlcx_resp() );
Philipp Maier75932982018-03-27 14:52:35 +02007242 execute( TC_reset_two() );
Harald Welte33ec09b2018-02-10 15:34:46 +01007243
7244 execute( TC_lu_and_mt_call() );
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02007245 execute( TC_lu_and_mt_call_ipv6() );
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01007246 execute( TC_lu_and_mt_call_already_paging() );
Pau Espin Pedrol9a732a42020-09-15 15:56:33 +02007247 execute( TC_lu_and_mt_call_osmux() );
Harald Welte33ec09b2018-02-10 15:34:46 +01007248
Harald Weltef45efeb2018-04-09 18:19:24 +02007249 execute( TC_lu_and_mo_sms() );
7250 execute( TC_lu_and_mt_sms() );
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01007251 execute( TC_lu_and_mt_sms_already_paging() );
Philipp Maier3983e702018-11-22 19:01:33 +01007252 execute( TC_lu_and_mt_sms_paging_and_nothing() );
Alexander Couzensfc02f242019-09-12 03:43:18 +02007253 execute( TC_lu_and_mt_sms_paging_repeated() );
Harald Weltef640a012018-04-14 17:49:21 +02007254 execute( TC_smpp_mo_sms() );
Vadim Yanitskiy33820762020-01-15 11:26:07 +07007255 execute( TC_smpp_mo_sms_rp_error() );
Harald Weltef640a012018-04-14 17:49:21 +02007256 execute( TC_smpp_mt_sms() );
Harald Weltef45efeb2018-04-09 18:19:24 +02007257
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07007258 execute( TC_gsup_mo_sms() );
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07007259 execute( TC_gsup_mo_smma() );
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07007260 execute( TC_gsup_mt_sms_ack() );
7261 execute( TC_gsup_mt_sms_err() );
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07007262 execute( TC_gsup_mt_sms_rp_mr() );
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07007263 execute( TC_gsup_mo_mt_sms_rp_mr() );
Vadim Yanitskiya2a8a112019-07-08 20:04:32 +07007264 execute( TC_gsup_mt_multi_part_sms() );
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07007265
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07007266 execute( TC_lu_and_mo_ussd_single_request() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07007267 execute( TC_lu_and_mt_ussd_notification() );
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07007268 execute( TC_lu_and_mo_ussd_during_mt_call() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07007269 execute( TC_lu_and_mt_ussd_during_mt_call() );
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07007270 execute( TC_lu_and_mo_ussd_mo_release() );
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07007271 execute( TC_lu_and_ss_session_timeout() );
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07007272
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07007273 execute( TC_mt_ussd_for_unknown_subscr() );
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07007274 execute( TC_mo_ussd_for_unknown_trans() );
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07007275 execute( TC_proc_ss_for_unknown_session() );
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07007276 execute( TC_proc_ss_paging_fail() );
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07007277 execute( TC_proc_ss_abort() );
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07007278
Vadim Yanitskiy1c9754d2020-01-07 21:56:55 +01007279 execute( TC_multi_lu_and_mo_ussd() );
7280 execute( TC_multi_lu_and_mt_ussd() );
7281
Stefan Sperling89eb1f32018-12-17 15:06:20 +01007282 execute( TC_cipher_complete_with_invalid_cipher() );
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01007283 execute( TC_cipher_complete_1_without_cipher() );
7284 execute( TC_cipher_complete_3_without_cipher() );
7285 execute( TC_cipher_complete_13_without_cipher() );
Harald Welteb2284bd2019-05-10 11:30:43 +02007286 execute( TC_lu_with_invalid_mcc_mnc() );
Stefan Sperling89eb1f32018-12-17 15:06:20 +01007287
Harald Welte4263c522018-12-06 11:56:27 +01007288 execute( TC_sgsap_reset() );
7289 execute( TC_sgsap_lu() );
7290 execute( TC_sgsap_lu_imsi_reject() );
7291 execute( TC_sgsap_lu_and_nothing() );
7292 execute( TC_sgsap_expl_imsi_det_eps() );
Philipp Maierfc19f172019-03-21 11:17:54 +01007293 execute( TC_sgsap_impl_imsi_det_eps() );
Harald Welte4263c522018-12-06 11:56:27 +01007294 execute( TC_sgsap_expl_imsi_det_noneps() );
Philipp Maier5d812702019-03-21 10:51:26 +01007295 execute( TC_sgsap_impl_imsi_det_noneps() );
Harald Welte4263c522018-12-06 11:56:27 +01007296 execute( TC_sgsap_paging_rej() );
7297 execute( TC_sgsap_paging_subscr_rej() );
7298 execute( TC_sgsap_paging_ue_unr() );
7299 execute( TC_sgsap_paging_and_nothing() );
7300 execute( TC_sgsap_paging_and_lu() );
7301 execute( TC_sgsap_mt_sms() );
7302 execute( TC_sgsap_mo_sms() );
7303 execute( TC_sgsap_mt_sms_and_nothing() );
7304 execute( TC_sgsap_mt_sms_and_reject() );
7305 execute( TC_sgsap_unexp_ud() );
7306 execute( TC_sgsap_unsol_ud() );
7307 execute( TC_bssap_lu_sgsap_lu_and_mt_call() );
7308 execute( TC_sgsap_lu_and_mt_call() );
Philipp Maier628c0052019-04-09 17:36:57 +02007309 execute( TC_sgsap_vlr_failure() );
Harald Welte4263c522018-12-06 11:56:27 +01007310
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02007311 execute( TC_ho_inter_bsc_unknown_cell() );
7312 execute( TC_ho_inter_bsc() );
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02007313 execute( TC_ho_inter_bsc_a5_1() );
7314 execute( TC_ho_inter_bsc_a5_3() );
7315 execute( TC_ho_inter_bsc_a5_4() );
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02007316 execute( TC_ho_inter_bsc_ipv6() );
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02007317
7318 execute( TC_ho_inter_msc_out() );
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02007319 execute( TC_ho_inter_msc_out_a5_1() );
7320 execute( TC_ho_inter_msc_out_a5_3() );
7321 execute( TC_ho_inter_msc_out_a5_4() );
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02007322 execute( TC_ho_inter_msc_out_ipv6() );
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02007323
Oliver Smith1d118ff2019-07-03 10:57:35 +02007324 execute( TC_lu_imsi_auth_tmsi_check_imei() );
7325 execute( TC_lu_imsi_auth3g_tmsi_check_imei() );
7326 execute( TC_lu_imsi_noauth_tmsi_check_imei() );
7327 execute( TC_lu_imsi_noauth_notmsi_check_imei() );
7328 execute( TC_lu_imsi_auth_tmsi_check_imei_nack() );
7329 execute( TC_lu_imsi_auth_tmsi_check_imei_err() );
7330 execute( TC_lu_imsi_auth_tmsi_check_imei_early() );
7331 execute( TC_lu_imsi_auth3g_tmsi_check_imei_early() );
7332 execute( TC_lu_imsi_noauth_tmsi_check_imei_early() );
7333 execute( TC_lu_imsi_noauth_notmsi_check_imei_early() );
7334 execute( TC_lu_imsi_auth_tmsi_check_imei_early_nack() );
7335 execute( TC_lu_imsi_auth_tmsi_check_imei_early_err() );
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01007336 execute( TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() );
Pau Espin Pedrol609f1d62020-09-15 16:01:55 +02007337
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02007338 execute( TC_mo_cc_bssmap_clear() );
Neels Hofmeyr8df69622019-11-02 19:16:03 +01007339 execute( TC_invalid_mgcp_crash() );
Vadim Yanitskiyeddebaa2019-12-28 17:45:34 +01007340 execute( TC_mm_id_resp_no_identity() );
Vadim Yanitskiy25219062020-01-21 01:41:33 +07007341 execute( TC_lu_and_expire_while_paging() );
Pau Espin Pedrol174fac22021-02-26 13:20:10 +01007342 execute( TC_paging_response_imsi_unknown() );
7343 execute( TC_paging_response_tmsi_unknown() );
Neels Hofmeyr4f099b42021-07-27 03:45:26 +02007344
7345 execute( TC_call_re_establishment() );
Neels Hofmeyra9b2dcf2021-07-28 00:57:58 +02007346 execute( TC_call_re_establishment_auth() );
Neels Hofmeyr48e4d7d2021-07-28 00:57:58 +02007347 execute( TC_call_re_establishment_ciph() );
Neels Hofmeyr07ea7f22022-05-05 01:39:26 +02007348
7349 execute( TC_cm_serv_wrong_mi() );
Neels Hofmeyre860fc42022-10-05 01:15:54 +02007350
7351 execute( TC_auth_options_0() );
7352 execute( TC_auth_options_1() );
7353 execute( TC_auth_options_2() );
7354 execute( TC_auth_options_3() );
7355 execute( TC_auth_options_4() );
7356 execute( TC_auth_options_5() );
7357 execute( TC_auth_options_6() );
7358 execute( TC_auth_options_7() );
7359 execute( TC_auth_options_8() );
7360 execute( TC_auth_options_9() );
7361 execute( TC_auth_options_10() );
7362 execute( TC_auth_options_11() );
Harald Weltef6dd64d2017-11-19 12:09:51 +01007363}
7364
7365
7366}