blob: e6d270d0af52fb3e935dc2b8e0bb7f676479a374 [file] [log] [blame]
Harald Weltef6dd64d2017-11-19 12:09:51 +01001module MSC_Tests {
2
Harald Welte34b5a952019-05-27 11:54:11 +02003/* Osmocom MSC test suite in in TTCN-3
4 * (C) 2017-2019 Harald Welte <laforge@gnumonks.org>
5 * (C) 2018-2019 sysmocom - s.f.m.c. GmbH
6 * (C) 2018-2019 Vadim Yanitskiy <axilirator@gmail.com>
7 * All rights reserved.
8 *
9 * Released under the terms of GNU General Public License, Version 2 or
10 * (at your option) any later version.
11 *
12 * SPDX-License-Identifier: GPL-2.0-or-later
13 */
14
Harald Weltee13cfb22019-04-23 16:52:02 +020015friend module MSC_Tests_Iu;
16
Harald Weltef6dd64d2017-11-19 12:09:51 +010017import from General_Types all;
18import from Osmocom_Types all;
Pau Espin Pedrole979c402021-04-28 17:29:54 +020019import from GSM_Types all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010020
21import from M3UA_Types all;
22import from M3UA_Emulation all;
23
24import from MTP3asp_Types all;
25import from MTP3asp_PortType all;
26
27import from SCCPasp_Types all;
28import from SCCP_Types all;
29import from SCCP_Emulation all;
30
31import from SCTPasp_Types all;
32import from SCTPasp_PortType all;
33
Harald Weltea49e36e2018-01-21 19:29:33 +010034import from Osmocom_CTRL_Functions all;
35import from Osmocom_CTRL_Types all;
36import from Osmocom_CTRL_Adapter all;
37
Harald Welte3ca1c902018-01-24 18:51:27 +010038import from TELNETasp_PortType all;
39import from Osmocom_VTY_Functions all;
40
Harald Weltea49e36e2018-01-21 19:29:33 +010041import from MNCC_Emulation all;
Harald Welte2bb825f2018-01-22 11:31:18 +010042import from MNCC_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010043
Harald Welte4aa970c2018-01-26 10:38:09 +010044import from MGCP_Emulation all;
45import from MGCP_Types all;
46import from MGCP_Templates all;
47import from SDP_Types all;
48
Harald Weltea49e36e2018-01-21 19:29:33 +010049import from GSUP_Emulation all;
50import from GSUP_Types all;
51import from IPA_Emulation all;
52
Harald Weltef6dd64d2017-11-19 12:09:51 +010053import from BSSAP_Types all;
Harald Welte6811d102019-04-14 22:23:14 +020054import from RAN_Adapter all;
Harald Weltea49e36e2018-01-21 19:29:33 +010055import from BSSAP_CodecPort all;
56import from BSSMAP_Templates all;
Harald Welte6811d102019-04-14 22:23:14 +020057import from RAN_Emulation all;
Harald Weltea49e36e2018-01-21 19:29:33 +010058import from BSC_ConnectionHandler all;
Harald Weltee13cfb22019-04-23 16:52:02 +020059import from RANAP_Templates all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010060
Harald Welte4263c522018-12-06 11:56:27 +010061import from SGsAP_Templates all;
62import from SGsAP_Types all;
63import from SGsAP_Emulation all;
64
Harald Weltea49e36e2018-01-21 19:29:33 +010065import from MobileL3_Types all;
66import from MobileL3_CommonIE_Types all;
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +070067import from MobileL3_SMS_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010068import from L3_Templates all;
Harald Welte158a7ca2018-02-16 18:11:31 +010069import from L3_Common all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010070
Harald Weltef640a012018-04-14 17:49:21 +020071import from SMPP_Types all;
72import from SMPP_Templates all;
73import from SMPP_Emulation all;
74
Stefan Sperlingc307e682018-06-14 15:15:46 +020075import from SCCP_Templates all;
76
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070077import from SS_Types all;
78import from SS_Templates all;
79import from USSD_Helpers all;
Harald Welte4263c522018-12-06 11:56:27 +010080import from DNS_Helpers all;
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070081
Philipp Maier948747b2019-04-02 15:22:33 +020082import from TCCConversion_Functions all;
83
Harald Welte9b751a62019-04-14 17:39:29 +020084const integer NUM_BSC := 3;
Harald Weltef6dd64d2017-11-19 12:09:51 +010085
Harald Welte4263c522018-12-06 11:56:27 +010086/* Needed for SGsAP SMS */
87import from MobileL3_SMS_Types all;
88
Harald Weltea4ca4462018-02-09 00:17:14 +010089type component MTC_CT extends CTRL_Adapter_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +010090 var boolean g_initialized := false;
Harald Weltea49e36e2018-01-21 19:29:33 +010091
Harald Welte6811d102019-04-14 22:23:14 +020092 var RAN_Adapter g_bssap[NUM_BSC];
Harald Weltea4ca4462018-02-09 00:17:14 +010093
Harald Weltea49e36e2018-01-21 19:29:33 +010094 /* no 'adapter_CT' for MNCC or GSUP */
95 var MNCC_Emulation_CT vc_MNCC;
Harald Welte4aa970c2018-01-26 10:38:09 +010096 var MGCP_Emulation_CT vc_MGCP;
Harald Weltea49e36e2018-01-21 19:29:33 +010097 var GSUP_Emulation_CT vc_GSUP;
98 var IPA_Emulation_CT vc_GSUP_IPA;
Harald Weltef640a012018-04-14 17:49:21 +020099 var SMPP_Emulation_CT vc_SMPP;
Harald Welte4263c522018-12-06 11:56:27 +0100100 var SGsAP_Emulation_CT vc_SGsAP;
Harald Weltea49e36e2018-01-21 19:29:33 +0100101
102 /* only to get events from IPA underneath GSUP */
103 port IPA_CTRL_PT GSUP_IPA_EVENT;
Harald Welte3ca1c902018-01-24 18:51:27 +0100104 /* VTY to MSC */
105 port TELNETasp_PT MSCVTY;
Philipp Maier328d1662018-03-07 10:40:27 +0100106
107 /* A port to directly send BSSAP messages. This port is used for
108 * tests that require low level access to sen arbitrary BSSAP
109 * messages. Run f_init_bssap_direct() to connect and initialize */
110 port BSSAP_CODEC_PT BSSAP_DIRECT;
111
112 /* When BSSAP messages are directly sent, then the connection
113 * handler is not active, which means that also no guard timer is
114 * set up. The following timer will serve as a replacement */
115 timer Tguard_direct := 60.0;
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100116
117 /* Configure T(tias) over VTY, seconds */
118 var integer g_msc_sccp_timer_ias := 7 * 60;
119 /* Configure T(tiar) over VTY, seconds */
120 var integer g_msc_sccp_timer_iar := 15 * 60;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100121}
122
123modulepar {
Harald Weltea49e36e2018-01-21 19:29:33 +0100124 /* remote parameters of IUT */
125 charstring mp_msc_ip := "127.0.0.1";
126 integer mp_msc_ctrl_port := 4255;
127 integer mp_msc_vty_port := 4254;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100128
Harald Weltea49e36e2018-01-21 19:29:33 +0100129 /* local parameters of emulated HLR */
Philipp Maier9b690e42018-12-21 11:50:03 +0100130 boolean mp_mm_info := false;
Harald Weltea49e36e2018-01-21 19:29:33 +0100131 charstring mp_hlr_ip := "127.0.0.1";
132 integer mp_hlr_port := 4222;
Harald Welte6126fb02018-01-27 20:08:24 +0100133 charstring mp_mgw_ip := "127.0.0.1";
134 integer mp_mgw_port := 2427;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100135
Harald Weltea49e36e2018-01-21 19:29:33 +0100136 charstring mp_msc_mncc := "/tmp/mncc";
Harald Weltea4ca4462018-02-09 00:17:14 +0100137
Harald Weltef640a012018-04-14 17:49:21 +0200138 integer mp_msc_smpp_port := 2775;
139 charstring mp_smpp_system_id := "msc_tester";
140 charstring mp_smpp_password := "osmocom1";
Harald Welte4263c522018-12-06 11:56:27 +0100141 charstring mp_mme_name := "mmec01.mmegi0001.mme.epc.mnc070.mcc901.3gppnetwork.org";
142 charstring mp_vlr_name := "vlr.example.net";
Eric Wild49888a62022-03-30 03:16:11 +0200143 integer mp_bssap_reset_retries := 1;
Harald Weltef640a012018-04-14 17:49:21 +0200144
Harald Welte6811d102019-04-14 22:23:14 +0200145 RAN_Configurations mp_bssap_cfg := {
Philipp Maier75932982018-03-27 14:52:35 +0200146 {
147 sccp_service_type := "mtp3_itu",
148 sctp_addr := { 23905, "127.0.0.1", 2905, "127.0.0.1" },
149 own_pc := 185,
150 own_ssn := 254,
151 peer_pc := 187,
152 peer_ssn := 254,
153 sio := '83'O,
154 rctx := 0
155 },
156 {
157 sccp_service_type := "mtp3_itu",
158 sctp_addr := { 23906, "127.0.0.1", 2905, "127.0.0.1" },
159 own_pc := 186,
160 own_ssn := 254,
161 peer_pc := 187,
162 peer_ssn := 254,
163 sio := '83'O,
164 rctx := 1
165 }
Harald Weltea4ca4462018-02-09 00:17:14 +0100166 };
Harald Weltef6dd64d2017-11-19 12:09:51 +0100167}
168
Philipp Maier328d1662018-03-07 10:40:27 +0100169/* altstep for the global guard timer (only used when BSSAP_DIRECT
170 * is used for communication */
171private altstep as_Tguard_direct() runs on MTC_CT {
172 [] Tguard_direct.timeout {
173 setverdict(fail, "Tguard timeout");
Daniel Willmannafce8662018-07-06 23:11:32 +0200174 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +0100175 }
176}
Harald Weltef6dd64d2017-11-19 12:09:51 +0100177
Neels Hofmeyr2ca1ab42019-03-08 03:45:43 +0100178private altstep as_optional_cc_rel(CallParameters cpars, boolean respond := false) runs on BSC_ConnHdlr {
179 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id))) {
180 if (respond) {
181 var BIT1 tid_remote := '1'B;
182 if (cpars.mo_call) {
183 tid_remote := '0'B;
184 }
185 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id, tid_remote)));
186 }
187 }
Neels Hofmeyrde76f052019-02-26 05:02:46 +0100188}
189
Harald Weltef640a012018-04-14 17:49:21 +0200190function f_init_smpp(charstring id) runs on MTC_CT {
191 id := id & "-SMPP";
192 var EsmePars pars := {
193 mode := MODE_TRANSCEIVER,
194 bind := {
195 system_id := mp_smpp_system_id,
196 password := mp_smpp_password,
197 system_type := "MSC_Tests",
198 interface_version := hex2int('34'H),
199 addr_ton := unknown,
200 addr_npi := unknown,
201 address_range := ""
202 },
203 esme_role := true
204 }
205
206 vc_SMPP := SMPP_Emulation_CT.create(id);
207 map(vc_SMPP:SMPP_PORT, system:SMPP_PORT);
Harald Welte4698a4c2020-08-18 22:57:52 +0200208 vc_SMPP.start(SMPP_Emulation.main_client(pars, mp_msc_ip, mp_msc_smpp_port, "", 0));
Harald Weltef640a012018-04-14 17:49:21 +0200209}
210
211
Harald Weltea49e36e2018-01-21 19:29:33 +0100212function f_init_mncc(charstring id) runs on MTC_CT {
213 id := id & "-MNCC";
214 var MnccOps ops := {
215 create_cb := refers(MNCC_Emulation.ExpectedCreateCallback),
216 unitdata_cb := refers(MNCC_Emulation.DummyUnitdataCallback)
217 }
218
219 vc_MNCC := MNCC_Emulation_CT.create(id);
220 map(vc_MNCC:MNCC, system:MNCC_CODEC_PT);
221 vc_MNCC.start(MNCC_Emulation.main(ops, id, mp_msc_mncc));
Harald Weltef6dd64d2017-11-19 12:09:51 +0100222}
223
Harald Welte4aa970c2018-01-26 10:38:09 +0100224function f_init_mgcp(charstring id) runs on MTC_CT {
225 id := id & "-MGCP";
226 var MGCPOps ops := {
227 create_cb := refers(MGCP_Emulation.ExpectedCreateCallback),
228 unitdata_cb := refers(MGCP_Emulation.DummyUnitdataCallback)
229 }
230 var MGCP_conn_parameters pars := {
Harald Welte6126fb02018-01-27 20:08:24 +0100231 callagent_ip := mp_msc_ip,
Harald Welte4aa970c2018-01-26 10:38:09 +0100232 callagent_udp_port := -1,
Harald Welte6126fb02018-01-27 20:08:24 +0100233 mgw_ip := mp_mgw_ip,
Pau Espin Pedrol1a026a52019-06-18 17:21:52 +0200234 mgw_udp_port := mp_mgw_port,
235 multi_conn_mode := false
Harald Welte4aa970c2018-01-26 10:38:09 +0100236 }
237
238 vc_MGCP := MGCP_Emulation_CT.create(id);
239 map(vc_MGCP:MGCP, system:MGCP_CODEC_PT);
240 vc_MGCP.start(MGCP_Emulation.main(ops, pars, id));
241}
242
Philipp Maierc09a1312019-04-09 16:05:26 +0200243function ForwardUnitdataCallback(PDU_SGsAP msg)
244runs on SGsAP_Emulation_CT return template PDU_SGsAP {
245 SGsAP_CLIENT.send(msg);
246 return omit;
247}
248
Harald Welte4263c522018-12-06 11:56:27 +0100249function f_init_sgsap(charstring id) runs on MTC_CT {
250 id := id & "-SGsAP";
251 var SGsAPOps ops := {
252 create_cb := refers(SGsAP_Emulation.ExpectedCreateCallback),
Philipp Maierc09a1312019-04-09 16:05:26 +0200253 unitdata_cb := refers(ForwardUnitdataCallback)
Harald Welte4263c522018-12-06 11:56:27 +0100254 }
255 var SGsAP_conn_parameters pars := {
256 remote_ip := mp_msc_ip,
257 remote_sctp_port := 29118,
258 local_ip := "",
259 local_sctp_port := -1
260 }
261
262 vc_SGsAP := SGsAP_Emulation_CT.create(id);
263 map(vc_SGsAP:SGsAP, system:SGsAP_CODEC_PT);
264 vc_SGsAP.start(SGsAP_Emulation.main(ops, pars, id));
265}
266
267
Harald Weltea49e36e2018-01-21 19:29:33 +0100268function f_init_gsup(charstring id) runs on MTC_CT {
269 id := id & "-GSUP";
270 var GsupOps ops := {
271 create_cb := refers(GSUP_Emulation.ExpectedCreateCallback)
272 }
273
274 vc_GSUP_IPA := IPA_Emulation_CT.create(id & "-IPA");
275 vc_GSUP := GSUP_Emulation_CT.create(id);
276
277 map(vc_GSUP_IPA:IPA_PORT, system:IPA_CODEC_PT);
278 connect(vc_GSUP:GSUP, vc_GSUP_IPA:IPA_GSUP_PORT);
279 /* we use this hack to get events like ASP_IPA_EVENT_UP */
280 connect(vc_GSUP_IPA:IPA_CTRL_PORT, self:GSUP_IPA_EVENT);
281
282 vc_GSUP.start(GSUP_Emulation.main(ops, id));
283 vc_GSUP_IPA.start(IPA_Emulation.main_server(mp_hlr_ip, mp_hlr_port));
284
285 /* wait for incoming connection to GSUP port before proceeding */
286 timer T := 10.0;
287 T.start;
288 alt {
Vadim Yanitskiy61564be2020-05-18 20:44:14 +0700289 [] GSUP_IPA_EVENT.receive(tr_ASP_IPA_EV(ASP_IPA_EVENT_UP)) { }
Harald Weltea49e36e2018-01-21 19:29:33 +0100290 [] T.timeout {
Harald Welte458fd372018-03-21 11:26:23 +0100291 setverdict(fail, "No connection to GSUP Port");
Daniel Willmannafce8662018-07-06 23:11:32 +0200292 mtc.stop
Harald Weltea49e36e2018-01-21 19:29:33 +0100293 }
294 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100295}
296
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200297function f_init(integer num_bsc := 1, boolean sgsap := false, boolean gsup := true, boolean osmux := false) runs on MTC_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +0100298
299 if (g_initialized == true) {
300 return;
301 }
302 g_initialized := true;
303
Philipp Maier75932982018-03-27 14:52:35 +0200304 if (num_bsc > NUM_BSC) {
Daniel Willmannafce8662018-07-06 23:11:32 +0200305 testcase.stop("excess number of BSC instances requested");
Philipp Maier75932982018-03-27 14:52:35 +0200306 }
307
Pau Espin Pedrol9a5b8ff2021-01-04 19:01:31 +0100308 f_ipa_ctrl_start_client(mp_msc_ip, mp_msc_ctrl_port);
Harald Welte3ca1c902018-01-24 18:51:27 +0100309
310 map(self:MSCVTY, system:MSCVTY);
311 f_vty_set_prompts(MSCVTY);
312 f_vty_transceive(MSCVTY, "enable");
Harald Welteb14c77a2018-01-25 17:25:44 +0100313
314 /* set some defaults */
315 f_vty_config(MSCVTY, "network", "authentication optional");
316 f_vty_config(MSCVTY, "msc", "assign-tmsi");
Oliver Smith1d118ff2019-07-03 10:57:35 +0200317 f_vty_config(MSCVTY, "msc", "check-imei-rqd 0");
Harald Welteb14c77a2018-01-25 17:25:44 +0100318 f_vty_config(MSCVTY, "network", "encryption a5 0");
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100319 f_vty_config(MSCVTY, "cs7 instance 0", "sccp-timer ias " & int2str(g_msc_sccp_timer_ias));
320 f_vty_config(MSCVTY, "cs7 instance 0", "sccp-timer iar " & int2str(g_msc_sccp_timer_iar));
Pau Espin Pedrol9a732a42020-09-15 15:56:33 +0200321 if (osmux) {
322 f_vty_config(MSCVTY, "msc", "osmux on");
323 } else {
324 f_vty_config(MSCVTY, "msc", "osmux off");
Pau Espin Pedrol3dd33bc2019-05-31 17:51:20 +0200325 }
Daniel Willmann08862152022-02-22 13:21:49 +0100326
327 for (var integer i := 0; i < num_bsc; i := i + 1) {
328 if (isbound(mp_bssap_cfg[i])) {
329 var RanOps ranops := BSC_RanOps;
330 ranops.use_osmux := osmux;
Eric Wild49888a62022-03-30 03:16:11 +0200331 ranops.bssap_reset_retries := mp_bssap_reset_retries;
Daniel Willmann08862152022-02-22 13:21:49 +0100332 f_ran_adapter_init(g_bssap[i], mp_bssap_cfg[i], "MSC_Test_" & int2str(i), ranops);
333 f_ran_adapter_start(g_bssap[i]);
334 } else {
335 testcase.stop("missing BSSAP configuration");
336 }
337 }
338
339 f_init_mncc("MSC_Test");
340 f_init_mgcp("MSC_Test");
341
342 if (gsup == true) {
343 f_init_gsup("MSC_Test");
344 }
345 f_init_smpp("MSC_Test");
346
347 if (sgsap == true) {
348 f_init_sgsap("MSC_Test");
349 }
350
Harald Weltef6dd64d2017-11-19 12:09:51 +0100351}
352
Philipp Maier328d1662018-03-07 10:40:27 +0100353/* Initialize for a direct connection to BSSAP. This function is an alternative
354 * to f_init() when the high level functions of the BSC_ConnectionHandler are
355 * not needed. */
356function f_init_bssap_direct() runs on MTC_CT {
Harald Welte3ca0ce12019-04-23 17:18:48 +0200357 f_ran_adapter_init(g_bssap[0], mp_bssap_cfg[0], "MSC_Test", omit);
Philipp Maier75932982018-03-27 14:52:35 +0200358 connect(g_bssap[0].vc_SCCP:SCCP_SP_PORT, self:BSSAP_DIRECT);
Philipp Maier328d1662018-03-07 10:40:27 +0100359
360 /* Start guard timer and activate it as default */
361 Tguard_direct.start
362 activate(as_Tguard_direct());
363}
364
Harald Weltea49e36e2018-01-21 19:29:33 +0100365type function void_fn(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100366
Harald Weltea49e36e2018-01-21 19:29:33 +0100367/* FIXME: move into BSC_ConnectionHandler? */
Harald Welte9b751a62019-04-14 17:39:29 +0200368function f_init_pars(integer imsi_suffix, boolean sgsap := false, boolean gsup := true, integer ran_idx := 0,
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200369 boolean ran_is_geran := true, boolean use_osmux := false, OCT4 gsup_sid := '20000101'O,
370 boolean verify_cell_id := true)
Harald Weltef9abf8d2019-04-21 13:07:17 +0200371runs on MTC_CT return BSC_ConnHdlrPars {
Harald Weltede371492018-01-27 23:44:41 +0100372 var BSC_ConnHdlrNetworkPars net_pars := {
373 kc_support := '0A'O, /* A5/1 and A5/3 enabled */
374 expect_tmsi := true,
375 expect_auth := false,
Oliver Smith1d118ff2019-07-03 10:57:35 +0200376 expect_ciph := false,
377 expect_imei := false,
378 expect_imei_early := false,
379 check_imei_result := OSMO_GSUP_IMEI_RESULT_ACK,
380 check_imei_error := false
Harald Weltede371492018-01-27 23:44:41 +0100381 };
Harald Weltea49e36e2018-01-21 19:29:33 +0100382 var BSC_ConnHdlrPars pars := {
Harald Weltef9abf8d2019-04-21 13:07:17 +0200383 sccp_addr_own := g_bssap[ran_idx].sccp_addr_own,
384 sccp_addr_peer := g_bssap[ran_idx].sccp_addr_peer,
Harald Welteedbab812018-03-18 16:02:25 +0100385 cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42)),
Harald Welte81b7f9d2018-01-24 19:06:24 +0100386 imei := f_gen_imei(imsi_suffix),
387 imsi := f_gen_imsi(imsi_suffix),
388 msisdn := f_gen_msisdn(imsi_suffix),
Harald Welte256571e2018-01-24 18:47:19 +0100389 tmsi := omit,
Harald Welte9de84792018-01-28 01:06:35 +0100390 cm1 := valueof(ts_CM1),
Harald Welte82600572018-01-21 20:54:08 +0100391 cm2 := valueof(ts_CM2_default),
Harald Welte16114282018-01-24 22:41:21 +0100392 cm3 := omit,
Harald Weltede371492018-01-27 23:44:41 +0100393 vec := omit,
Neels Hofmeyrb00c5b02021-06-23 20:05:25 +0200394 vec_keep := false,
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100395 net := net_pars,
Philipp Maieraeb29a82018-11-08 17:40:53 +0100396 send_early_cm := true,
397 ipa_ctrl_ip := mp_msc_ip,
398 ipa_ctrl_port := mp_msc_ctrl_port,
Philipp Maier9b690e42018-12-21 11:50:03 +0100399 ipa_ctrl_enable := true,
Philipp Maier57865482019-01-07 18:33:13 +0100400 mm_info := mp_mm_info,
Philipp Maierc09a1312019-04-09 16:05:26 +0200401 sgsap_enable := sgsap,
Harald Weltef9abf8d2019-04-21 13:07:17 +0200402 gsup_enable := gsup,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +0100403 gsup_sid := gsup_sid,
Harald Weltec1f937a2019-04-21 21:19:23 +0200404 ran_idx := ran_idx,
Harald Welte9b751a62019-04-14 17:39:29 +0200405 use_umts_aka := false,
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200406 ran_is_geran := ran_is_geran,
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200407 use_osmux := use_osmux,
Pau Espin Pedrol833174e2020-09-03 16:46:02 +0200408 use_ipv6 := false,
Pau Espin Pedrole979c402021-04-28 17:29:54 +0200409 verify_cell_id := verify_cell_id,
410 common_id_last_eutran_plmn := omit
Harald Weltea49e36e2018-01-21 19:29:33 +0100411 };
Harald Weltee13cfb22019-04-23 16:52:02 +0200412 if (not ran_is_geran) {
413 pars.use_umts_aka := true;
414 pars.net.expect_auth := true;
415 }
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100416 return pars;
417}
418
Neels Hofmeyre1a1b632021-07-28 18:05:43 +0200419function f_start_handler_create(BSC_ConnHdlrPars pars) runs on MTC_CT return BSC_ConnHdlr {
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100420 var BSC_ConnHdlr vc_conn;
Neels Hofmeyr60122f82021-07-28 17:59:38 +0200421 var charstring id := testcasename() & int2str(pars.ran_idx);
Harald Weltea49e36e2018-01-21 19:29:33 +0100422
423 vc_conn := BSC_ConnHdlr.create(id);
Neels Hofmeyr60122f82021-07-28 17:59:38 +0200424
Harald Weltea49e36e2018-01-21 19:29:33 +0100425 /* BSSMAP part / A interface */
Neels Hofmeyr60122f82021-07-28 17:59:38 +0200426 connect(vc_conn:BSSAP, g_bssap[pars.ran_idx].vc_RAN:CLIENT);
427 connect(vc_conn:BSSAP_PROC, g_bssap[pars.ran_idx].vc_RAN:PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100428 /* MNCC part */
429 connect(vc_conn:MNCC, vc_MNCC:MNCC_CLIENT);
430 connect(vc_conn:MNCC_PROC, vc_MNCC:MNCC_PROC);
Harald Welte4aa970c2018-01-26 10:38:09 +0100431 /* MGCP part */
432 connect(vc_conn:MGCP, vc_MGCP:MGCP_CLIENT);
433 connect(vc_conn:MGCP_PROC, vc_MGCP:MGCP_PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100434 /* GSUP part */
Philipp Maierc09a1312019-04-09 16:05:26 +0200435 if (pars.gsup_enable == true) {
436 connect(vc_conn:GSUP, vc_GSUP:GSUP_CLIENT);
437 connect(vc_conn:GSUP_PROC, vc_GSUP:GSUP_PROC);
438 }
Harald Weltef640a012018-04-14 17:49:21 +0200439 /* SMPP part */
440 connect(vc_conn:SMPP, vc_SMPP:SMPP_CLIENT);
441 connect(vc_conn:SMPP_PROC, vc_SMPP:SMPP_PROC);
Harald Welte4263c522018-12-06 11:56:27 +0100442 /* SGs part */
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100443 if (pars.sgsap_enable == true) {
Philipp Maier57865482019-01-07 18:33:13 +0100444 connect(vc_conn:SGsAP, vc_SGsAP:SGsAP_CLIENT);
445 connect(vc_conn:SGsAP_PROC, vc_SGsAP:SGsAP_PROC);
446 }
Neels Hofmeyre1a1b632021-07-28 18:05:43 +0200447 return vc_conn;
448}
Harald Weltea49e36e2018-01-21 19:29:33 +0100449
Neels Hofmeyre1a1b632021-07-28 18:05:43 +0200450function f_start_handler_run(BSC_ConnHdlr vc_conn, void_fn fn, BSC_ConnHdlrPars pars) runs on MTC_CT {
451 var charstring id := testcasename() & int2str(pars.ran_idx);
Harald Weltea10db902018-01-27 12:44:49 +0100452 /* We cannot use vc_conn.start(f_init_handler(fn, id, pars)); as we cannot have
453 * a stand-alone 'derefers()' call, see https://www.eclipse.org/forums/index.php/t/1091364/ */
Harald Weltea49e36e2018-01-21 19:29:33 +0100454 vc_conn.start(derefers(fn)(id, pars));
Neels Hofmeyre1a1b632021-07-28 18:05:43 +0200455}
456
457function f_start_handler_with_pars(void_fn fn, BSC_ConnHdlrPars pars) runs on MTC_CT return BSC_ConnHdlr {
458 var BSC_ConnHdlr vc_conn;
459 vc_conn := f_start_handler_create(pars);
460 f_start_handler_run(vc_conn, fn, pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100461 return vc_conn;
462}
463
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200464function f_start_handler(void_fn fn, integer imsi_suffix, integer ran_idx := 0, boolean ran_is_geran := true, boolean use_osmux := false,
465 boolean verify_cell_id := true)
Harald Welte9b751a62019-04-14 17:39:29 +0200466runs on MTC_CT return BSC_ConnHdlr {
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200467 return f_start_handler_with_pars(fn, f_init_pars(imsi_suffix, ran_idx := ran_idx, ran_is_geran := ran_is_geran, use_osmux := use_osmux, verify_cell_id := verify_cell_id));
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100468}
469
Harald Weltea49e36e2018-01-21 19:29:33 +0100470private function f_tc_lu_imsi_noauth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100471 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100472 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100473}
Harald Weltea49e36e2018-01-21 19:29:33 +0100474testcase TC_lu_imsi_noauth_tmsi() runs on MTC_CT {
475 var BSC_ConnHdlr vc_conn;
476 f_init();
477
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100478 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi), 1);
Harald Weltea49e36e2018-01-21 19:29:33 +0100479 vc_conn.done;
480}
481
482private function f_tc_lu_imsi_noauth_notmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100483 pars.net.expect_tmsi := false;
Harald Weltea10db902018-01-27 12:44:49 +0100484 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100485 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100486}
Harald Weltea49e36e2018-01-21 19:29:33 +0100487testcase TC_lu_imsi_noauth_notmsi() runs on MTC_CT {
488 var BSC_ConnHdlr vc_conn;
489 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100490 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
Harald Weltea49e36e2018-01-21 19:29:33 +0100491
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100492 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi), 2);
Harald Weltea49e36e2018-01-21 19:29:33 +0100493 vc_conn.done;
494}
495
496/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
Harald Weltee13cfb22019-04-23 16:52:02 +0200497friend function f_tc_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100498 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100499 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
500
501 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +0200502 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyrd076c522019-11-28 01:00:52 +0100503 f_mm_common();
Harald Weltea49e36e2018-01-21 19:29:33 +0100504 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
505 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
506 alt {
Harald Welte5946b332018-03-18 23:32:21 +0100507 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej(int2oct(23,1)))) {
508 f_expect_clear();
509 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100510 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
511 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200512 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100513 }
514 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100515}
516testcase TC_lu_imsi_reject() runs on MTC_CT {
517 var BSC_ConnHdlr vc_conn;
518 f_init();
519
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200520 vc_conn := f_start_handler(refers(f_tc_lu_imsi_reject), 3, verify_cell_id := false);
Harald Weltea49e36e2018-01-21 19:29:33 +0100521 vc_conn.done;
522}
523
Harald Weltee13cfb22019-04-23 16:52:02 +0200524
525
Harald Weltea49e36e2018-01-21 19:29:33 +0100526/* Do LU by IMSI, timeout on GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +0200527friend function f_tc_lu_imsi_timeout_gsup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100528 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100529 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
530
531 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +0200532 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyrd076c522019-11-28 01:00:52 +0100533 f_mm_common();
Harald Weltea49e36e2018-01-21 19:29:33 +0100534 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
535 /* Normally the HLR would need to respond here, but we decide to force a timeout here */
536 alt {
537 /* FIXME: Expect specific reject cause */
Harald Welte5946b332018-03-18 23:32:21 +0100538 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
539 f_expect_clear();
540 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100541 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
542 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200543 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100544 }
545 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100546}
547testcase TC_lu_imsi_timeout_gsup() runs on MTC_CT {
548 var BSC_ConnHdlr vc_conn;
549 f_init();
550
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200551 vc_conn := f_start_handler(refers(f_tc_lu_imsi_timeout_gsup), 4, verify_cell_id := false);
Harald Weltea49e36e2018-01-21 19:29:33 +0100552 vc_conn.done;
553}
554
Harald Weltee13cfb22019-04-23 16:52:02 +0200555
Harald Welte7b1b2812018-01-22 21:23:06 +0100556private function f_tc_lu_imsi_auth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100557 pars.net.expect_auth := true;
Harald Weltea10db902018-01-27 12:44:49 +0100558 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100559 f_perform_lu();
Harald Welte7b1b2812018-01-22 21:23:06 +0100560}
561testcase TC_lu_imsi_auth_tmsi() runs on MTC_CT {
562 var BSC_ConnHdlr vc_conn;
563 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100564 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte7b1b2812018-01-22 21:23:06 +0100565
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100566 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi), 5);
Harald Welte7b1b2812018-01-22 21:23:06 +0100567 vc_conn.done;
568}
569
Harald Weltee13cfb22019-04-23 16:52:02 +0200570
571friend function f_tc_lu_imsi_auth3g_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte8a397ae2019-04-21 22:03:37 +0200572 pars.net.expect_auth := true;
573 pars.use_umts_aka := true;
574 f_init_handler(pars);
575 f_perform_lu();
576}
577testcase TC_lu_imsi_auth3g_tmsi() runs on MTC_CT {
578 var BSC_ConnHdlr vc_conn;
579 f_init();
580 f_vty_config(MSCVTY, "network", "authentication required");
581
582 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi), 1005);
583 vc_conn.done;
584}
Harald Weltea49e36e2018-01-21 19:29:33 +0100585
Pau Espin Pedrold3d54a92019-12-17 17:02:54 +0100586/* Proceed with LU but never receive an TMSI Realloc from MS after LU Accept (OS#4337).
587 * TS 24.008 sec 4.3.1.5 states MSC should simply release all MM connections.
588 */
589friend function f_tc_lu_imsi_timeout_tmsi_realloc(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
590
591 f_init_handler(pars);
592
593 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
594 var PDU_DTAP_MT dtap_mt;
595
596 /* tell GSUP dispatcher to send this IMSI to us */
597 f_create_gsup_expect(hex2str(g_pars.imsi));
598
599 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
600 if (g_pars.ran_is_geran) {
601 f_bssap_compl_l3(l3_lu);
602 if (g_pars.send_early_cm) {
603 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
604 }
605 } else {
606 f_ranap_initial_ue(l3_lu);
607 }
608
609 f_mm_imei_early();
610 f_mm_common();
611 f_msc_lu_hlr();
612 f_mm_imei();
613
614 alt {
615 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) -> value dtap_mt {}
616 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
617 setverdict(fail, "Expected LU ACK, but received LU REJ");
618 mtc.stop;
619 }
620 }
621
622 /* currently (due to bug OS#4337), an extra LU reject is received before
623 terminating the connection. Enabling following line makes the test
624 pass: */
625 //f_expect_lu_reject('16'O); /* Cause: congestion */
626
627 /* f_expect_lu_reject() already waits for T"-1" (X1, 5 seconds), but give some
628 extra time to avoid race conditons... */
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200629 f_expect_clear(7.0, verify_vlr_cell_id := false);
Pau Espin Pedrold3d54a92019-12-17 17:02:54 +0100630
631 setverdict(pass);
632}
633testcase TC_lu_imsi_timeout_tmsi_realloc() runs on MTC_CT {
634 var BSC_ConnHdlr vc_conn;
635 f_init();
636
637 vc_conn := f_start_handler(refers(f_tc_lu_imsi_timeout_tmsi_realloc), 5);
638 vc_conn.done;
639}
640
Harald Weltee13cfb22019-04-23 16:52:02 +0200641
Harald Weltea49e36e2018-01-21 19:29:33 +0100642/* Send CM SERVICE REQ for IMSI that has never performed LU before */
Harald Weltee13cfb22019-04-23 16:52:02 +0200643friend function f_tc_cmserv_imsi_unknown(charstring id, BSC_ConnHdlrPars pars)
Harald Weltea49e36e2018-01-21 19:29:33 +0100644runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100645 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100646
647 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welteedbab812018-03-18 16:02:25 +0100648 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
Harald Welte6ed6bf92018-01-24 21:09:15 +0100649 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
Harald Weltea49e36e2018-01-21 19:29:33 +0100650
651 f_create_gsup_expect(hex2str(g_pars.imsi));
652
653 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200654 f_cl3_or_initial_ue(l3_info);
Harald Welteb7817992019-05-09 13:15:39 +0200655 f_mm_auth();
Harald Weltea49e36e2018-01-21 19:29:33 +0100656
657 timer T := 10.0;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100658 T.start;
659 alt {
Harald Weltea49e36e2018-01-21 19:29:33 +0100660 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
661 //[] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_ACC)) { }
Daniel Willmannafce8662018-07-06 23:11:32 +0200662 [] BSSAP.receive {
663 setverdict(fail, "Received unexpected BSSAP");
664 mtc.stop;
665 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100666 [] GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi)) {
667 setverdict(fail, "Unexpected GSUP UL REQ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200668 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100669 }
Daniel Willmannafce8662018-07-06 23:11:32 +0200670 [] T.timeout {
Neels Hofmeyrf1c3c212020-08-19 13:15:32 +0000671 setverdict(fail, "Timeout waiting for CM SERV REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200672 mtc.stop;
673 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100674 }
675
Harald Welte1ddc7162018-01-27 14:25:46 +0100676 f_expect_clear();
Harald Weltef6dd64d2017-11-19 12:09:51 +0100677}
Harald Weltea49e36e2018-01-21 19:29:33 +0100678testcase TC_cmserv_imsi_unknown() runs on MTC_CT {
679 var BSC_ConnHdlr vc_conn;
680 f_init();
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200681 vc_conn := f_start_handler(refers(f_tc_cmserv_imsi_unknown), 6, verify_cell_id := false);
Harald Weltea49e36e2018-01-21 19:29:33 +0100682 vc_conn.done;
683}
684
Harald Weltee13cfb22019-04-23 16:52:02 +0200685
Neels Hofmeyr13737fb2020-08-19 13:16:14 +0000686/* Send CM SERVICE REQ for TMSI that has never performed LU before */
687friend function f_tc_cmserv_tmsi_unknown(charstring id, BSC_ConnHdlrPars pars)
688runs on BSC_ConnHdlr {
689 f_init_handler(pars);
690
691 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV('57111111'O));
692 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
693 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
694
695 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
696 f_cl3_or_initial_ue(l3_info);
697 f_mm_auth();
698
699 timer T := 10.0;
700 T.start;
701 alt {
702 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
703 [] BSSAP.receive {
704 setverdict(fail, "Received unexpected BSSAP");
705 mtc.stop;
706 }
707 [] T.timeout {
708 setverdict(fail, "Timeout waiting for CM SERV REJ");
709 mtc.stop;
710 }
711 }
712
713 f_expect_clear();
714}
715testcase TC_cmserv_tmsi_unknown() runs on MTC_CT {
716 var BSC_ConnHdlr vc_conn;
717 f_init();
718 vc_conn := f_start_handler(refers(f_tc_cmserv_tmsi_unknown), 57, verify_cell_id := false);
719 vc_conn.done;
720}
721
Neels Hofmeyr14d0b132020-08-19 13:49:05 +0000722/* Send Paging Response for IMSI that has never performed LU before */
723friend function f_tc_paging_response_imsi_unknown(charstring id, BSC_ConnHdlrPars pars)
724runs on BSC_ConnHdlr {
725 f_init_handler(pars);
726
727 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
728 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
729 var PDU_ML3_MS_NW l3_info := valueof(ts_PAG_RESP(mi));
730
731 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
732 f_cl3_or_initial_ue(l3_info);
733
734 /* The Paging Response gets rejected by a direct Clear Command */
735 f_expect_clear();
736}
737testcase TC_paging_response_imsi_unknown() runs on MTC_CT {
738 var BSC_ConnHdlr vc_conn;
739 f_init();
740 vc_conn := f_start_handler(refers(f_tc_paging_response_imsi_unknown), 58, verify_cell_id := false);
741 vc_conn.done;
742}
743
744/* Send Paging Response for TMSI that has never performed LU before */
745friend function f_tc_paging_response_tmsi_unknown(charstring id, BSC_ConnHdlrPars pars)
746runs on BSC_ConnHdlr {
747 f_init_handler(pars);
748
749 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV('59111111'O));
750 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
751 var PDU_ML3_MS_NW l3_info := valueof(ts_PAG_RESP(mi));
752
753 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
754 f_cl3_or_initial_ue(l3_info);
755
756 /* The Paging Response gets rejected by a direct Clear Command */
757 f_expect_clear();
758}
759testcase TC_paging_response_tmsi_unknown() runs on MTC_CT {
760 var BSC_ConnHdlr vc_conn;
761 f_init();
762 vc_conn := f_start_handler(refers(f_tc_paging_response_tmsi_unknown), 59, verify_cell_id := false);
763 vc_conn.done;
764}
765
Neels Hofmeyr13737fb2020-08-19 13:16:14 +0000766
Harald Weltee13cfb22019-04-23 16:52:02 +0200767friend function f_tc_lu_and_mo_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100768 f_init_handler(pars);
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +0200769 var CallParameters cpars := valueof(t_CallParams);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100770 f_perform_lu();
Harald Welteb71901a2018-01-26 19:16:05 +0100771 f_mo_call(cpars);
Harald Welte2bb825f2018-01-22 11:31:18 +0100772}
773testcase TC_lu_and_mo_call() runs on MTC_CT {
774 var BSC_ConnHdlr vc_conn;
775 f_init();
776
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100777 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_call), 7);
Harald Welte071ed732018-01-23 19:53:52 +0100778 vc_conn.done;
779}
Pau Espin Pedrol833174e2020-09-03 16:46:02 +0200780friend function f_tc_lu_and_mo_call_ipv6(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
781 f_init_handler(pars);
782 var CallParameters cpars := valueof(t_CallParams);
783 cpars.mgw_conn_1.mgw_rtp_ip := "::1";
784 cpars.mgw_conn_2.mgw_rtp_ip := "::2";
785 cpars.bss_rtp_ip := "::3";
786 f_perform_lu();
787 f_mo_call(cpars);
788}
789testcase TC_lu_and_mo_call_ipv6() runs on MTC_CT {
790 var BSC_ConnHdlr vc_conn;
791 f_init();
792
793 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_call_ipv6), 7);
794 vc_conn.done;
795}
Harald Welte071ed732018-01-23 19:53:52 +0100796
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100797/* Verify T(iar) triggers and releases the channel */
798friend function f_lu_and_mo_call_sccp_tiar_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
799 timer T_wait_iar := int2float(5 + 1); /* g_msc_sccp_timer_iar + Give extra time (+1 sec) */
800 f_init_handler(pars);
801 var CallParameters cpars := valueof(t_CallParams);
802 f_perform_lu();
803 f_mo_call_establish(cpars);
804
805 /* Expect the channel cleared upon T(iar) triggered: */
806 T_wait_iar.start;
807 alt {
808 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {
809 T_wait_iar.stop
810 setverdict(pass);
811 }
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100812 [] T_wait_iar.timeout {
813 setverdict(fail, "Timeout waiting for T(iar) triggered SCCP RSLD");
814 mtc.stop;
815 }
816 }
Harald Welte4a3fa712020-08-19 08:57:33 +0200817 /* DLCX for both directions; if we don't do this, we might receive either of the two during
818 * shutdown causing race conditions */
819 MGCP.receive(tr_DLCX(?));
820 MGCP.receive(tr_DLCX(?));
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100821
822 setverdict(pass);
823}
824testcase TC_lu_and_mo_call_sccp_tiar_timeout() runs on MTC_CT {
825 var BSC_ConnHdlr vc_conn;
826
827 /* Set T(iar) in MSC low enough that it will trigger before other side
828 has time to keep alive with a T(ias). Keep recommended ratio of
829 T(iar) >= T(ias)*2 */
830 g_msc_sccp_timer_ias := 2;
831 g_msc_sccp_timer_iar := 5;
832
833 f_init();
834
835 vc_conn := f_start_handler(refers(f_lu_and_mo_call_sccp_tiar_timeout), 89);
836 vc_conn.done;
837}
838
Harald Weltee13cfb22019-04-23 16:52:02 +0200839
Harald Welte071ed732018-01-23 19:53:52 +0100840/* Test LU (with authentication enabled), where HLR times out sending SAI response */
Harald Weltee13cfb22019-04-23 16:52:02 +0200841friend function f_tc_lu_auth_sai_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100842 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100843
844 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
845 var PDU_DTAP_MT dtap_mt;
846
847 /* tell GSUP dispatcher to send this IMSI to us */
848 f_create_gsup_expect(hex2str(g_pars.imsi));
849
850 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200851 f_cl3_or_initial_ue(l3_lu);
Harald Welte071ed732018-01-23 19:53:52 +0100852
853 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200854 if (pars.ran_is_geran) {
855 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
856 }
Harald Welte071ed732018-01-23 19:53:52 +0100857
858 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
859 /* The HLR would normally return an auth vector here, but we fail to do so. */
860
861 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100862 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100863}
864testcase TC_lu_auth_sai_timeout() runs on MTC_CT {
865 var BSC_ConnHdlr vc_conn;
866 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100867 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100868
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200869 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_timeout), 8, verify_cell_id := false);
Harald Welte071ed732018-01-23 19:53:52 +0100870 vc_conn.done;
871}
872
Harald Weltee13cfb22019-04-23 16:52:02 +0200873
Harald Welte071ed732018-01-23 19:53:52 +0100874/* Test LU (with authentication enabled), where HLR rejects sending SAI error */
Harald Weltee13cfb22019-04-23 16:52:02 +0200875friend function f_tc_lu_auth_sai_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100876 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100877
878 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
879 var PDU_DTAP_MT dtap_mt;
880
881 /* tell GSUP dispatcher to send this IMSI to us */
882 f_create_gsup_expect(hex2str(g_pars.imsi));
883
884 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200885 f_cl3_or_initial_ue(l3_lu);
Harald Welte071ed732018-01-23 19:53:52 +0100886
887 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200888 if (pars.ran_is_geran) {
889 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
890 }
Harald Welte071ed732018-01-23 19:53:52 +0100891
892 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
893 GSUP.send(ts_GSUP_SAI_ERR(g_pars.imsi, 13));
894
895 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100896 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100897}
898testcase TC_lu_auth_sai_err() runs on MTC_CT {
899 var BSC_ConnHdlr vc_conn;
900 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100901 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100902
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200903 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_err), 9, verify_cell_id := false);
Harald Welte2bb825f2018-01-22 11:31:18 +0100904 vc_conn.done;
905}
Harald Weltea49e36e2018-01-21 19:29:33 +0100906
Harald Weltee13cfb22019-04-23 16:52:02 +0200907
Harald Weltebc881782018-01-23 20:09:15 +0100908/* Test LU but BSC will send a clear request in the middle */
909private function f_tc_lu_clear_request(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100910 f_init_handler(pars);
Harald Weltebc881782018-01-23 20:09:15 +0100911
912 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
913 var PDU_DTAP_MT dtap_mt;
914
915 /* tell GSUP dispatcher to send this IMSI to us */
916 f_create_gsup_expect(hex2str(g_pars.imsi));
917
918 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200919 f_cl3_or_initial_ue(l3_lu);
Harald Welte79f1e452020-08-18 22:55:02 +0200920 f_expect_common_id();
Harald Weltebc881782018-01-23 20:09:15 +0100921
922 /* Send Early Classmark, just for the fun of it */
923 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
924
925 f_sleep(1.0);
926 /* send clear request in the middle of the LU */
927 BSSAP.send(ts_BSSMAP_ClearRequest(0));
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200928 alt {
929 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { repeat; }
930 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {}
931 }
Harald Weltebc881782018-01-23 20:09:15 +0100932 BSSAP.send(ts_BSSMAP_ClearComplete);
Harald Welte89a32492018-01-27 19:07:28 +0100933 alt {
934 /* See https://osmocom.org/issues/2862 */
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200935 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {
936 setverdict(fail, "Got a second Clear Command, only one expected");
Daniel Willmannafce8662018-07-06 23:11:32 +0200937 mtc.stop;
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200938 repeat;
939 }
Harald Welte6811d102019-04-14 22:23:14 +0200940 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte89a32492018-01-27 19:07:28 +0100941 }
Harald Weltebc881782018-01-23 20:09:15 +0100942 setverdict(pass);
943}
944testcase TC_lu_clear_request() runs on MTC_CT {
945 var BSC_ConnHdlr vc_conn;
946 f_init();
947
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100948 vc_conn := f_start_handler(refers(f_tc_lu_clear_request), 10);
Harald Weltebc881782018-01-23 20:09:15 +0100949 vc_conn.done;
950}
951
Vadim Yanitskiy109e7552021-02-05 05:36:02 +0100952/* Test reaction on Clear Request during a MO Call */
953friend function f_TC_mo_mt_call_clear_request(charstring id, BSC_ConnHdlrPars pars)
954runs on BSC_ConnHdlr {
955 var CallParameters cpars := valueof(t_CallParams);
956 var MNCC_PDU mncc_pdu;
957 timer T := 2.0;
958
959 f_init_handler(pars);
960
961 f_perform_lu();
962
963 /* HACK: reducing code duplication ('66'H - MO, '68'H - MT) */
964 if (pars.imsi == '262420002532766'H)
965 { f_mo_call_establish(cpars); }
966 else
967 { f_mt_call_establish(cpars); }
968
969 /* Hold the line for a while... */
970 f_sleep(2.0);
971
972 /* BSC sends BSSMAP Clear Request (e.g. due to RR failure) */
973 BSSAP.send(ts_BSSMAP_ClearRequest(1));
974
975 /* Expect (optional) CC RELEASE and Clear Command */
976 var default ccrel := activate(as_optional_cc_rel(cpars));
977 f_expect_clear();
978 deactivate(ccrel);
979
980 /* Expect RELease indication on the MNCC socket */
981 T.start;
982 alt {
983 [] MNCC.receive(tr_MNCC_REL_ind(cpars.mncc_callref)) -> value mncc_pdu {
984 log("Rx MNCC REL.ind, cause := ", mncc_pdu.u.signal.cause);
985 setverdict(pass);
986 }
987 [] MNCC.receive(MNCC_PDU:?) -> value mncc_pdu {
988 setverdict(fail, "Rx unexpected MNCC PDU: ", mncc_pdu);
989 }
990 [] T.timeout {
991 setverdict(fail, "Timeout waiting for MNCC REL.ind");
992 }
993 }
994}
995testcase TC_mo_call_clear_request() runs on MTC_CT {
996 var BSC_ConnHdlr vc_conn;
997
998 f_init();
999
1000 vc_conn := f_start_handler(refers(f_TC_mo_mt_call_clear_request), 2532766); // '66'H - MO
1001 vc_conn.done;
1002}
1003testcase TC_mt_call_clear_request() runs on MTC_CT {
1004 var BSC_ConnHdlr vc_conn;
1005
1006 f_init();
1007
1008 vc_conn := f_start_handler(refers(f_TC_mo_mt_call_clear_request), 2532768); // '68'H - MT
1009 vc_conn.done;
1010}
1011
Harald Welte66af9e62018-01-24 17:28:21 +01001012/* Test LU but BSC will send a clear request in the middle */
Harald Weltee13cfb22019-04-23 16:52:02 +02001013friend function f_tc_lu_disconnect(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001014 f_init_handler(pars);
Harald Welte66af9e62018-01-24 17:28:21 +01001015
1016 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
1017 var PDU_DTAP_MT dtap_mt;
1018
1019 /* tell GSUP dispatcher to send this IMSI to us */
1020 f_create_gsup_expect(hex2str(g_pars.imsi));
1021
1022 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001023 f_cl3_or_initial_ue(l3_lu);
Harald Welte66af9e62018-01-24 17:28:21 +01001024
1025 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +02001026 if (pars.ran_is_geran) {
1027 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1028 }
Harald Welte66af9e62018-01-24 17:28:21 +01001029
1030 f_sleep(1.0);
1031 /* send clear request in the middle of the LU */
Harald Welte6811d102019-04-14 22:23:14 +02001032 BSSAP.send(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_REQ);
Harald Welte66af9e62018-01-24 17:28:21 +01001033 setverdict(pass);
Neels Hofmeyrbb825c92019-03-06 15:35:50 +01001034 f_sleep(1.0);
Harald Welte66af9e62018-01-24 17:28:21 +01001035}
1036testcase TC_lu_disconnect() runs on MTC_CT {
1037 var BSC_ConnHdlr vc_conn;
1038 f_init();
1039
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001040 vc_conn := f_start_handler(refers(f_tc_lu_disconnect), 11);
Harald Welte66af9e62018-01-24 17:28:21 +01001041 vc_conn.done;
1042}
1043
Harald Welteba7b6d92018-01-23 21:32:34 +01001044/* Test LU but with illegal mobile identity type = IMEI */
Harald Weltee13cfb22019-04-23 16:52:02 +02001045friend function f_tc_lu_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001046 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +01001047
Harald Welte256571e2018-01-24 18:47:19 +01001048 var PDU_ML3_MS_NW l3_lu := f_build_lu_imei(g_pars.imei)
Harald Welteba7b6d92018-01-23 21:32:34 +01001049 var PDU_DTAP_MT dtap_mt;
1050
1051 /* tell GSUP dispatcher to send this IMSI to us */
1052 f_create_gsup_expect(hex2str(g_pars.imsi));
1053
1054 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001055 f_cl3_or_initial_ue(l3_lu);
Harald Welteba7b6d92018-01-23 21:32:34 +01001056
1057 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +02001058 if (pars.ran_is_geran) {
1059 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1060 }
Harald Welteba7b6d92018-01-23 21:32:34 +01001061 /* wait for LU reject, ignore any ID REQ */
1062 alt {
1063 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { }
1064 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req)) { repeat; }
1065 }
1066 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001067 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +01001068}
1069testcase TC_lu_by_imei() runs on MTC_CT {
1070 var BSC_ConnHdlr vc_conn;
1071 f_init();
1072
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001073 vc_conn := f_start_handler(refers(f_tc_lu_by_imei), 12, verify_cell_id := false);
Harald Welteba7b6d92018-01-23 21:32:34 +01001074 vc_conn.done;
1075}
1076
Harald Weltee13cfb22019-04-23 16:52:02 +02001077
Harald Welteba7b6d92018-01-23 21:32:34 +01001078/* Test LU by TMSI with unknown TMSI, expect (and answer) ID REQ. */
1079private function f_tc_lu_tmsi_noauth_unknown(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Stefan Sperling04fc4bc2018-06-25 17:44:57 +02001080 /* We piggyback a test for an MSC crash on overlong IMSI (OS#2864) onto this test. */
1081 var hexstring overlong_imsi := '012345789ABCDEF0123456789ABCDEF'H;
Harald Weltea10db902018-01-27 12:44:49 +01001082 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +01001083
1084 var PDU_ML3_MS_NW l3_lu := f_build_lu_tmsi('01020304'O); /* FIXME: Random */
1085 var PDU_DTAP_MT dtap_mt;
1086
1087 /* tell GSUP dispatcher to send this IMSI to us */
1088 f_create_gsup_expect(hex2str(g_pars.imsi));
1089
1090 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001091 f_cl3_or_initial_ue(l3_lu);
Harald Welteba7b6d92018-01-23 21:32:34 +01001092
1093 /* Send Early Classmark, just for the fun of it */
1094 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1095
1096 /* Wait for + respond to ID REQ (IMSI) */
Oliver Smith32898452019-07-09 12:32:35 +02001097 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
Stefan Sperling04fc4bc2018-06-25 17:44:57 +02001098 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(overlong_imsi))); /* test for OS#2864 */
Harald Welteba7b6d92018-01-23 21:32:34 +01001099 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(g_pars.imsi)));
Harald Welte79f1e452020-08-18 22:55:02 +02001100 f_expect_common_id();
Harald Welteba7b6d92018-01-23 21:32:34 +01001101
1102 /* Expect MSC to do UpdateLocation to HLR; respond to it */
1103 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
1104 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
1105 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
1106 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
1107
1108 alt {
Harald Welte7ec4fa82018-01-27 10:57:40 +01001109 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
1110 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_TmsiRealloc_Cmpl));
1111 }
Harald Welteba7b6d92018-01-23 21:32:34 +01001112 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1113 setverdict(fail, "Expected LU ACK, but received REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +02001114 mtc.stop;
Harald Welteba7b6d92018-01-23 21:32:34 +01001115 }
1116 }
1117
Philipp Maier9b690e42018-12-21 11:50:03 +01001118 /* Wait for MM-Information (if enabled) */
1119 f_expect_mm_info();
1120
Harald Welteba7b6d92018-01-23 21:32:34 +01001121 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001122 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +01001123}
1124testcase TC_lu_by_tmsi_noauth_unknown() runs on MTC_CT {
1125 var BSC_ConnHdlr vc_conn;
1126 f_init();
1127
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001128 vc_conn := f_start_handler(refers(f_tc_lu_tmsi_noauth_unknown), 13);
Harald Welteba7b6d92018-01-23 21:32:34 +01001129 vc_conn.done;
1130}
1131
Neels Hofmeyrfc06c732020-08-19 12:52:28 +00001132/* Test LU by unknown TMSI, while the IMSI is already attached: osmo-msc should switch to the attached vlr_subscr. */
1133private function f_tc_attached_imsi_lu_unknown_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1134 f_init_handler(pars);
1135
1136 var PDU_ML3_MS_NW l3_lu := f_build_lu_tmsi('56111111'O);
1137 var PDU_DTAP_MT dtap_mt;
1138
1139 /* tell GSUP dispatcher to send this IMSI to us */
1140 f_create_gsup_expect(hex2str(g_pars.imsi));
1141
1142 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
1143 f_cl3_or_initial_ue(l3_lu);
1144
1145 /* Send Early Classmark, just for the fun of it */
1146 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1147
1148 /* Wait for + respond to ID REQ (IMSI) */
1149 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
1150 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(g_pars.imsi)));
1151 f_expect_common_id();
1152
1153 /* Expect MSC to do UpdateLocation to HLR; respond to it */
1154 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
1155 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
1156 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
1157 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
1158
1159 alt {
1160 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
1161 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_TmsiRealloc_Cmpl));
1162 }
1163 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1164 setverdict(fail, "Expected LU ACK, but received REJ");
1165 mtc.stop;
1166 }
1167 }
1168
1169 /* Wait for MM-Information (if enabled) */
1170 f_expect_mm_info();
1171
1172 /* wait for normal teardown */
Eric Wild85cc1612022-03-30 01:44:29 +02001173 f_expect_clear(verify_vlr_cell_id := false);
Neels Hofmeyrfc06c732020-08-19 12:52:28 +00001174
1175 /* Now the same IMSI is still attached in the VLR, and a LU with an unknown TMSI reveals the same IMSI only
1176 * later during ID Response. osmo-msc first creates a new vlr_subscr for the unknown TMSI, and as soon as the
1177 * IMSI becomes known, must notice that this IMSI is still regarded as attached, and must not create evil twins.
1178 */
1179
1180 /* (since the TMSI Reallocation happened, we could do this with exactly the same TMSI as above, but for test
1181 * readability just use a different one.) */
1182 l3_lu := f_build_lu_tmsi('56222222'O);
1183 f_cl3_or_initial_ue(l3_lu);
1184
1185 /* Wait for + respond to ID REQ (IMSI) */
1186 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
1187 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(g_pars.imsi)));
1188 f_expect_common_id();
1189
1190 /* Expect MSC to do UpdateLocation to HLR; respond to it */
1191 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
1192 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
1193 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
1194 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
1195
1196 alt {
1197 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
1198 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_TmsiRealloc_Cmpl));
1199 }
1200 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1201 setverdict(fail, "Expected LU ACK, but received REJ");
1202 mtc.stop;
1203 }
1204 }
1205
1206 /* Wait for MM-Information (if enabled) */
1207 f_expect_mm_info();
1208
1209 /* wait for normal teardown */
Eric Wild85cc1612022-03-30 01:44:29 +02001210 f_expect_clear(verify_vlr_cell_id := false);
Neels Hofmeyrfc06c732020-08-19 12:52:28 +00001211}
1212testcase TC_attached_imsi_lu_unknown_tmsi() runs on MTC_CT {
1213 var BSC_ConnHdlr vc_conn;
1214 f_init();
1215
1216 vc_conn := f_start_handler(refers(f_tc_attached_imsi_lu_unknown_tmsi), 56);
1217 vc_conn.done;
1218}
1219
Harald Welte4d15fa72020-08-19 08:58:28 +02001220friend function f_imsi_detach_by_imsi() runs on BSC_ConnHdlr {
Harald Welte45164da2018-01-24 12:51:27 +01001221 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1222
1223 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001224 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +01001225
1226 /* Send Early Classmark, just for the fun of it? */
Harald Welte4d15fa72020-08-19 08:58:28 +02001227 if (g_pars.ran_is_geran) {
Harald Weltee13cfb22019-04-23 16:52:02 +02001228 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1229 }
Harald Welte45164da2018-01-24 12:51:27 +01001230
1231 /* wait for normal teardown */
Harald Welte4d15fa72020-08-19 08:58:28 +02001232 f_expect_clear(verify_vlr_cell_id := false);
1233}
1234
1235
1236/* Test IMSI DETACH (MI=IMSI) */
1237friend function f_tc_imsi_detach_by_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1238 f_init_handler(pars);
1239
1240 f_imsi_detach_by_imsi();
Harald Welte45164da2018-01-24 12:51:27 +01001241}
1242testcase TC_imsi_detach_by_imsi() runs on MTC_CT {
1243 var BSC_ConnHdlr vc_conn;
1244 f_init();
1245
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001246 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imsi), 14, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001247 vc_conn.done;
1248}
1249
Harald Weltee13cfb22019-04-23 16:52:02 +02001250
Harald Welte45164da2018-01-24 12:51:27 +01001251/* Test IMSI DETACH (MI=TMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +02001252friend function f_tc_imsi_detach_by_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001253 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001254
1255 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV('01020304'O));
1256
1257 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001258 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +01001259
1260 /* Send Early Classmark, just for the fun of it? */
Harald Weltee13cfb22019-04-23 16:52:02 +02001261 if (pars.ran_is_geran) {
1262 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1263 }
Harald Welte45164da2018-01-24 12:51:27 +01001264
1265 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001266 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001267}
1268testcase TC_imsi_detach_by_tmsi() runs on MTC_CT {
1269 var BSC_ConnHdlr vc_conn;
1270 f_init();
1271
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001272 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_tmsi), 15, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001273 vc_conn.done;
1274}
1275
Harald Weltee13cfb22019-04-23 16:52:02 +02001276
Harald Welte45164da2018-01-24 12:51:27 +01001277/* Test IMSI DETACH (MI=IMEI), which is illegal */
Harald Weltee13cfb22019-04-23 16:52:02 +02001278friend function f_tc_imsi_detach_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001279 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001280
Harald Welte256571e2018-01-24 18:47:19 +01001281 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte45164da2018-01-24 12:51:27 +01001282
1283 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001284 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +01001285
1286 /* Send Early Classmark, just for the fun of it? */
Harald Weltee13cfb22019-04-23 16:52:02 +02001287 if (pars.ran_is_geran) {
1288 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1289 }
Harald Welte45164da2018-01-24 12:51:27 +01001290
1291 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001292 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001293}
1294testcase TC_imsi_detach_by_imei() runs on MTC_CT {
1295 var BSC_ConnHdlr vc_conn;
1296 f_init();
1297
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001298 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imei), 16, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001299 vc_conn.done;
1300}
1301
1302
1303/* helper function for an emergency call. caller passes in mobile identity to use */
1304private function f_emerg_call(MobileIdentityLV mi) runs on BSC_ConnHdlr {
Harald Welte0bef21e2018-02-10 09:48:23 +01001305 var CallParameters cpars := valueof(t_CallParams('112'H, 0));
1306 cpars.emergency := true;
Harald Welte45164da2018-01-24 12:51:27 +01001307
Harald Welte0bef21e2018-02-10 09:48:23 +01001308 f_mo_call(cpars);
Harald Welte45164da2018-01-24 12:51:27 +01001309}
1310
1311/* establish an emergency call by IMEI, no SIM inserted (and hence no IMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +02001312friend function f_tc_emerg_call_imei_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001313 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001314
Harald Welte256571e2018-01-24 18:47:19 +01001315 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001316 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_EMERG_CALL, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001317 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001318 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ('05'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +01001319 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001320}
1321testcase TC_emerg_call_imei_reject() runs on MTC_CT {
1322 var BSC_ConnHdlr vc_conn;
1323 f_init();
1324
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001325 vc_conn := f_start_handler(refers(f_tc_emerg_call_imei_reject), 17, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001326 vc_conn.done;
1327}
1328
Harald Weltee13cfb22019-04-23 16:52:02 +02001329
Harald Welted5b91402018-01-24 18:48:16 +01001330/* establish an emergency call by IMSI, SIM inserted (and hence IMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +02001331friend function f_tc_emerg_call_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001332 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001333 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001334 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001335 /* Then issue emergency call identified by IMSI */
1336 f_emerg_call(valueof(ts_MI_IMSI_LV(g_pars.imsi)));
1337}
1338testcase TC_emerg_call_imsi() runs on MTC_CT {
1339 var BSC_ConnHdlr vc_conn;
1340 f_init();
1341
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001342 vc_conn := f_start_handler(refers(f_tc_emerg_call_imsi), 18);
Harald Welte45164da2018-01-24 12:51:27 +01001343 vc_conn.done;
1344}
1345
Harald Weltee13cfb22019-04-23 16:52:02 +02001346
Harald Welte45164da2018-01-24 12:51:27 +01001347/* CM Service Request for VGCS -> reject */
1348private function f_tc_cm_serv_req_vgcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001349 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001350
1351 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001352 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001353
1354 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001355 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VGCS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001356 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001357 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001358 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001359}
1360testcase TC_cm_serv_req_vgcs_reject() runs on MTC_CT {
1361 var BSC_ConnHdlr vc_conn;
1362 f_init();
1363
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001364 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vgcs_reject), 19);
Harald Welte45164da2018-01-24 12:51:27 +01001365 vc_conn.done;
1366}
1367
1368/* CM Service Request for VBS -> reject */
1369private function f_tc_cm_serv_req_vbs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001370 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001371
1372 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001373 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001374
1375 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001376 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VBS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001377 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001378 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001379 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001380}
1381testcase TC_cm_serv_req_vbs_reject() runs on MTC_CT {
1382 var BSC_ConnHdlr vc_conn;
1383 f_init();
1384
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001385 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vbs_reject), 20);
Harald Welte45164da2018-01-24 12:51:27 +01001386 vc_conn.done;
1387}
1388
1389/* CM Service Request for LCS -> reject */
1390private function f_tc_cm_serv_req_lcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001391 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001392
1393 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001394 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001395
1396 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001397 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_LCS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001398 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001399 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001400 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001401}
1402testcase TC_cm_serv_req_lcs_reject() runs on MTC_CT {
1403 var BSC_ConnHdlr vc_conn;
1404 f_init();
1405
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001406 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_lcs_reject), 21);
Harald Welte45164da2018-01-24 12:51:27 +01001407 vc_conn.done;
1408}
1409
Harald Welte0195ab12018-01-24 21:50:20 +01001410/* CM Re-Establishment Request */
1411private function f_tc_cm_reest_req_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001412 f_init_handler(pars);
Harald Welte0195ab12018-01-24 21:50:20 +01001413
1414 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001415 f_perform_lu();
Harald Welte0195ab12018-01-24 21:50:20 +01001416
1417 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1418 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_REEST_REQ(0, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001419 f_cl3_or_initial_ue(l3_info);
Neels Hofmeyr49bbb512021-07-29 22:51:08 +02001420 /* Older osmo-msc returns: GSM48_REJECT_SRV_OPT_NOT_SUPPORTED = 32,
1421 * newer osmo-msc with CM Re-Establish support returns: GSM48_REJECT_CALL_CAN_NOT_BE_IDENTIFIED = 38 */
1422 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ( (int2oct(32,1), int2oct(38,1)) )));
Harald Welte1ddc7162018-01-27 14:25:46 +01001423 f_expect_clear();
Harald Welte0195ab12018-01-24 21:50:20 +01001424}
1425testcase TC_cm_reest_req_reject() runs on MTC_CT {
1426 var BSC_ConnHdlr vc_conn;
1427 f_init();
Harald Welte0195ab12018-01-24 21:50:20 +01001428
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001429 vc_conn := f_start_handler(refers(f_tc_cm_reest_req_reject), 22);
Harald Welte0195ab12018-01-24 21:50:20 +01001430 vc_conn.done;
1431}
1432
Harald Weltec638f4d2018-01-24 22:00:36 +01001433/* Test LU (with authentication enabled), with wrong response from MS */
1434private function f_tc_lu_auth_2G_fail(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001435 f_init_handler(pars);
Harald Weltec638f4d2018-01-24 22:00:36 +01001436
1437 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
1438
1439 /* tell GSUP dispatcher to send this IMSI to us */
1440 f_create_gsup_expect(hex2str(g_pars.imsi));
1441
1442 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001443 f_cl3_or_initial_ue(l3_lu);
Harald Weltec638f4d2018-01-24 22:00:36 +01001444
1445 /* Send Early Classmark, just for the fun of it */
1446 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1447
1448 var AuthVector vec := f_gen_auth_vec_2g();
1449 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G(vec.rand, vec.sres, vec.kc));
1450 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
1451 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
1452
1453 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_AUTH_REQ(vec.rand)));
1454 /* Send back wrong auth response */
1455 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MT_MM_AUTH_RESP_2G('00000000'O)));
1456
1457 /* Expect GSUP AUTH FAIL REP to HLR */
1458 GSUP.receive(tr_GSUP_AUTH_FAIL_IND(g_pars.imsi));
1459
1460 /* Expect LU REJECT with Cause == Illegal MS */
1461 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej('03'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +01001462 f_expect_clear();
Harald Weltec638f4d2018-01-24 22:00:36 +01001463}
1464testcase TC_lu_auth_2G_fail() runs on MTC_CT {
1465 var BSC_ConnHdlr vc_conn;
1466 f_init();
1467 f_vty_config(MSCVTY, "network", "authentication required");
Harald Weltec638f4d2018-01-24 22:00:36 +01001468
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001469 vc_conn := f_start_handler(refers(f_tc_lu_auth_2G_fail), 23, verify_cell_id := false);
Harald Weltec638f4d2018-01-24 22:00:36 +01001470 vc_conn.done;
1471}
1472
Harald Weltede371492018-01-27 23:44:41 +01001473/* A5/1 + A5/3 permitted on network side, and MS capable to do it */
Harald Welte16114282018-01-24 22:41:21 +01001474private function f_tc_lu_imsi_auth_tmsi_encr_13_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +01001475 pars.net.expect_auth := true;
1476 pars.net.expect_ciph := true;
Harald Weltea10db902018-01-27 12:44:49 +01001477 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001478 f_perform_lu();
Harald Welte16114282018-01-24 22:41:21 +01001479}
1480testcase TC_lu_imsi_auth_tmsi_encr_13_13() runs on MTC_CT {
1481 var BSC_ConnHdlr vc_conn;
1482 f_init();
1483 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte16114282018-01-24 22:41:21 +01001484 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
1485
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001486 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_13), 24);
Harald Welte16114282018-01-24 22:41:21 +01001487 vc_conn.done;
1488}
1489
Harald Welte1af6ea82018-01-25 18:33:15 +01001490/* Test Complete L3 without payload */
1491private function f_tc_cl3_no_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001492 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001493
1494 /* Send Complete L3 Info with empty L3 frame */
1495 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1496 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, ''O))));
1497
Harald Weltef466eb42018-01-27 14:26:54 +01001498 timer T := 5.0;
1499 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001500 alt {
Harald Welte6811d102019-04-14 22:23:14 +02001501 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte1af6ea82018-01-25 18:33:15 +01001502 /* Expect LU REJECT with Cause == Illegal MS */
Harald Weltebdb3c452018-03-18 22:43:06 +01001503 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
Harald Welte6811d102019-04-14 22:23:14 +02001504 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001505 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001506 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001507 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001508 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001509 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001510 }
1511 setverdict(pass);
1512}
1513testcase TC_cl3_no_payload() runs on MTC_CT {
1514 var BSC_ConnHdlr vc_conn;
1515 f_init();
1516
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001517 vc_conn := f_start_handler(refers(f_tc_cl3_no_payload), 25);
Harald Welte1af6ea82018-01-25 18:33:15 +01001518 vc_conn.done;
1519}
1520
1521/* Test Complete L3 with random payload */
1522private function f_tc_cl3_rnd_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001523 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001524
Daniel Willmannaa14a382018-07-26 08:29:45 +02001525 /* length is limited by PDU_BSSAP length field which includes some
1526 * other fields beside l3info payload. So payl can only be 240 bytes
1527 * Since rnd() returns values < 1 multiply with 241
1528 */
1529 var integer len := float2int(rnd() * 241.0);
Harald Welte1af6ea82018-01-25 18:33:15 +01001530 var octetstring payl := f_rnd_octstring(len);
1531
1532 /* Send Complete L3 Info with empty L3 frame */
1533 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1534 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, payl))));
1535
Harald Weltef466eb42018-01-27 14:26:54 +01001536 timer T := 5.0;
1537 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001538 alt {
1539 /* Immediate disconnect */
Harald Welte6811d102019-04-14 22:23:14 +02001540 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte1af6ea82018-01-25 18:33:15 +01001541 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
Harald Welte6811d102019-04-14 22:23:14 +02001542 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001543 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001544 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001545 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001546 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001547 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001548 }
1549 setverdict(pass);
1550}
1551testcase TC_cl3_rnd_payload() runs on MTC_CT {
1552 var BSC_ConnHdlr vc_conn;
1553 f_init();
1554
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001555 vc_conn := f_start_handler(refers(f_tc_cl3_rnd_payload), 26);
Harald Welte1af6ea82018-01-25 18:33:15 +01001556 vc_conn.done;
1557}
1558
Harald Welte116e4332018-01-26 22:17:48 +01001559/* Test Complete L3 with random payload */
Harald Weltee13cfb22019-04-23 16:52:02 +02001560friend function f_tc_establish_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001561 f_init_handler(pars);
Harald Welte116e4332018-01-26 22:17:48 +01001562
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001563 f_perform_lu();
Harald Welte116e4332018-01-26 22:17:48 +01001564
Harald Welteb9e86fa2018-04-09 18:18:31 +02001565 f_establish_fully();
Daniel Willmann898a7e02018-05-17 12:16:16 +02001566 f_expect_clear(10.0);
Harald Welte116e4332018-01-26 22:17:48 +01001567}
1568testcase TC_establish_and_nothing() runs on MTC_CT {
1569 var BSC_ConnHdlr vc_conn;
1570 f_init();
1571
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001572 vc_conn := f_start_handler(refers(f_tc_establish_and_nothing), 27);
Harald Welte116e4332018-01-26 22:17:48 +01001573 vc_conn.done;
1574}
1575
Harald Weltee13cfb22019-04-23 16:52:02 +02001576
Harald Welte12510c52018-01-26 22:26:24 +01001577/* Test MO Call SETUP with no response from MNCC */
Harald Weltee13cfb22019-04-23 16:52:02 +02001578friend function f_tc_mo_setup_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier109e6aa2018-10-17 10:53:32 +02001579 f_init_handler(pars, 190.0);
Harald Weltea10db902018-01-27 12:44:49 +01001580
Harald Welte12510c52018-01-26 22:26:24 +01001581 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001582 cpars.mgw_conn_2.resp := 0;
1583 cpars.stop_after_cc_setup := true;
1584
1585 f_vty_config(MSCVTY, "msc", "mncc guard-timeout 20");
Harald Welte12510c52018-01-26 22:26:24 +01001586
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001587 f_perform_lu();
Harald Welte12510c52018-01-26 22:26:24 +01001588
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001589 f_mo_call_establish(cpars);
Harald Welte12510c52018-01-26 22:26:24 +01001590
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001591 var default ccrel := activate(as_optional_cc_rel(cpars));
1592
Philipp Maier109e6aa2018-10-17 10:53:32 +02001593 f_expect_clear(185.0);
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001594
1595 deactivate(ccrel);
1596
1597 f_sleep(1.0);
Harald Welte12510c52018-01-26 22:26:24 +01001598}
1599testcase TC_mo_setup_and_nothing() runs on MTC_CT {
1600 var BSC_ConnHdlr vc_conn;
1601 f_init();
1602
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001603 vc_conn := f_start_handler(refers(f_tc_mo_setup_and_nothing), 28);
Harald Welte12510c52018-01-26 22:26:24 +01001604 vc_conn.done;
1605}
1606
Harald Weltee13cfb22019-04-23 16:52:02 +02001607
Harald Welte3ab88002018-01-26 22:37:25 +01001608/* Test MO Call with no response to RAN-side CRCX */
Harald Weltee13cfb22019-04-23 16:52:02 +02001609friend function f_tc_mo_crcx_ran_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001610 f_init_handler(pars);
Harald Welte3ab88002018-01-26 22:37:25 +01001611 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1612 var MNCC_PDU mncc;
1613 var MgcpCommand mgcp_cmd;
1614
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001615 f_perform_lu();
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001616 /* Do not respond to the second CRCX */
1617 cpars.mgw_conn_2.resp := 0;
1618 f_mo_call_establish(cpars);
Harald Welte3ab88002018-01-26 22:37:25 +01001619
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001620 var default ccrel := activate(as_optional_cc_rel(cpars));
Harald Welte3ab88002018-01-26 22:37:25 +01001621
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001622 f_expect_clear(60.0);
Harald Welte3ab88002018-01-26 22:37:25 +01001623
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001624 deactivate(ccrel);
Harald Welte3ab88002018-01-26 22:37:25 +01001625}
1626testcase TC_mo_crcx_ran_timeout() runs on MTC_CT {
1627 var BSC_ConnHdlr vc_conn;
1628 f_init();
1629
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001630 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_timeout), 29);
Harald Welte3ab88002018-01-26 22:37:25 +01001631 vc_conn.done;
1632}
1633
Harald Weltee13cfb22019-04-23 16:52:02 +02001634
Harald Welte0cc82d92018-01-26 22:52:34 +01001635/* Test MO Call with reject to RAN-side CRCX */
Harald Weltee13cfb22019-04-23 16:52:02 +02001636friend function f_tc_mo_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001637 f_init_handler(pars);
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001638
Harald Welte0cc82d92018-01-26 22:52:34 +01001639 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001640
1641 /* Respond with error for the first CRCX */
1642 cpars.mgw_conn_1.resp := -1;
Harald Welte0cc82d92018-01-26 22:52:34 +01001643
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001644 f_perform_lu();
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001645 f_mo_call_establish(cpars);
Harald Welte0cc82d92018-01-26 22:52:34 +01001646
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001647 var default ccrel := activate(as_optional_cc_rel(cpars));
1648 f_expect_clear(60.0);
1649 deactivate(ccrel);
Harald Welte0cc82d92018-01-26 22:52:34 +01001650}
1651testcase TC_mo_crcx_ran_reject() runs on MTC_CT {
1652 var BSC_ConnHdlr vc_conn;
1653 f_init();
1654
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001655 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_reject), 30);
Harald Welte0cc82d92018-01-26 22:52:34 +01001656 vc_conn.done;
1657}
1658
Harald Welte3ab88002018-01-26 22:37:25 +01001659
Harald Welte812f7a42018-01-27 00:49:18 +01001660/* helper function to start a MT call: MNCC SETUP; Paging; DChan est.; DTAP SETUP */
1661private function f_mt_call_start(inout CallParameters cpars) runs on BSC_ConnHdlr {
1662 var MNCC_PDU mncc;
1663 var MgcpCommand mgcp_cmd;
Harald Welte812f7a42018-01-27 00:49:18 +01001664
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001665 f_perform_lu();
Vadim Yanitskiyae747742020-01-10 00:23:10 +01001666 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Welte812f7a42018-01-27 00:49:18 +01001667
1668 /* Allocate call reference and send SETUP via MNCC to MSC */
1669 cpars.mncc_callref := f_rnd_int(2147483648);
1670 MNCC.send(ts_MNCC_SETUP_req(cpars.mncc_callref, hex2str(g_pars.msisdn),
1671 hex2str(cpars.called_party), hex2str(g_pars.imsi)));
1672
1673 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02001674 f_expect_paging();
1675
Harald Welte812f7a42018-01-27 00:49:18 +01001676 /* MS -> MSC: PAGING RESPONSE */
Harald Welteb9e86fa2018-04-09 18:18:31 +02001677 f_establish_fully(EST_TYPE_PAG_RESP);
Harald Welte812f7a42018-01-27 00:49:18 +01001678
1679 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1680
1681 /* MSC->MS: SETUP */
1682 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_SETUP(cpars.transaction_id, *, cpars.called_party)));
1683}
1684
1685/* Test MT Call */
Harald Weltee13cfb22019-04-23 16:52:02 +02001686friend function f_tc_mt_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001687 f_init_handler(pars);
Harald Welte812f7a42018-01-27 00:49:18 +01001688 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1689 var MNCC_PDU mncc;
1690 var MgcpCommand mgcp_cmd;
1691
1692 f_mt_call_start(cpars);
1693
1694 /* MS->MSC: CALL CONFIRMED */
1695 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1696
1697 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1698
1699 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1700 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001701
1702 /* Detect if the received CRCX is a wildcarded CRCX request. If yes,
1703 * set an endpoint name that fits the pattern. If not, just use the
1704 * endpoint name from the request */
1705 if (match(mgcp_cmd.line.ep, t_MGCP_EP_wildcard)) {
1706 cpars.mgcp_ep := "rtpbridge/1@mgw";
1707 } else {
1708 cpars.mgcp_ep := mgcp_cmd.line.ep;
1709 }
1710
Harald Welte812f7a42018-01-27 00:49:18 +01001711 /* Respond to CRCX with error */
1712 var MgcpResponse mgcp_rsp := {
1713 line := {
1714 code := "542",
1715 trans_id := mgcp_cmd.line.trans_id,
1716 string := "FORCED_FAIL"
1717 },
Harald Welte812f7a42018-01-27 00:49:18 +01001718 sdp := omit
1719 }
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001720 var MgcpParameter mgcp_rsp_param := {
1721 code := "Z",
1722 val := cpars.mgcp_ep
1723 };
1724 mgcp_rsp.params[0] := mgcp_rsp_param;
Harald Welte812f7a42018-01-27 00:49:18 +01001725 MGCP.send(mgcp_rsp);
1726
1727 timer T := 30.0;
1728 T.start;
1729 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001730 [] T.timeout {
1731 setverdict(fail, "Timeout waiting for channel release");
1732 mtc.stop;
1733 }
Harald Welte812f7a42018-01-27 00:49:18 +01001734 [] MNCC.receive { repeat; }
1735 [] GSUP.receive { repeat; }
1736 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1737 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
1738 f_create_mgcp_delete_ep(cpars.mgcp_ep);
1739 repeat;
1740 }
1741 [] MGCP.receive { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001742 [] as_clear_cmd_compl_disc();
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001743 [] as_optional_cc_rel(cpars);
Harald Welte812f7a42018-01-27 00:49:18 +01001744 }
1745}
1746testcase TC_mt_crcx_ran_reject() runs on MTC_CT {
1747 var BSC_ConnHdlr vc_conn;
1748 f_init();
1749
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001750 vc_conn := f_start_handler(refers(f_tc_mt_crcx_ran_reject), 31);
Harald Welte812f7a42018-01-27 00:49:18 +01001751 vc_conn.done;
1752}
1753
1754
Harald Weltee13cfb22019-04-23 16:52:02 +02001755
Harald Welte812f7a42018-01-27 00:49:18 +01001756/* Test MT Call T310 timer */
Harald Weltee13cfb22019-04-23 16:52:02 +02001757friend function f_tc_mt_t310(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte812f7a42018-01-27 00:49:18 +01001758 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
Harald Welte812f7a42018-01-27 00:49:18 +01001759 var MgcpCommand mgcp_cmd;
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001760 var PDU_BSSAP bssap;
1761 timer T310;
Harald Welte812f7a42018-01-27 00:49:18 +01001762
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001763 f_init_handler(pars);
1764
1765 /* Initiate a MT call, establish connection */
Harald Welte812f7a42018-01-27 00:49:18 +01001766 f_mt_call_start(cpars);
1767
1768 /* MS->MSC: CALL CONFIRMED */
1769 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1770 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1771
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001772 /* NOTE: MSC is expected to start T310 here */
Harald Welte812f7a42018-01-27 00:49:18 +01001773
Neels Hofmeyrd8a4aee2022-07-25 22:07:24 +02001774 interleave {
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001775 /* MSC->MGW: CRCX (first) */
Neels Hofmeyrd8a4aee2022-07-25 22:07:24 +02001776 [] MGCP.receive(tr_CRCX) -> value mgcp_cmd {
1777 f_handle_crcx(cpars, mgcp_cmd); /* MSC<-MGW: OK */
1778 }
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001779
1780 /* BSC->BSC: BSSMAP ASSIGNMENT REQ */
Neels Hofmeyrd8a4aee2022-07-25 22:07:24 +02001781 [] BSSAP.receive(tr_BSSMAP_AssignmentReq(omit, ?)) -> value bssap {
1782 BSSAP.send(ts_BSSMAP_AssignmentComplete(omit,
1783 aoip := f_ts_BSSMAP_IE_AoIP_TLA(cpars.bss_rtp_ip, cpars.bss_rtp_port),
1784 speechCodec := ts_BSSMAP_IE_SpeechCodec({ ts_CodecFR })));
1785 }
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001786
1787 /* MSC->MGW: MDCX */
Neels Hofmeyrd8a4aee2022-07-25 22:07:24 +02001788 [] MGCP.receive(tr_MDCX) -> value mgcp_cmd {
1789 MGCP.send(ts_MDCX_ACK(mgcp_cmd.line.trans_id, cpars.mgw_conn_1.mgcp_connection_id,
1790 sdp := omit));
1791 }
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001792
1793 /* MSC->MGW: CRCX (second) */
Neels Hofmeyrd8a4aee2022-07-25 22:07:24 +02001794 [] MGCP.receive(tr_CRCX) -> value mgcp_cmd {
1795 f_handle_crcx(cpars, mgcp_cmd); /* MSC<-MGW: OK */
1796 MNCC.receive(tr_MNCC_RTP_CREATE(cpars.mncc_callref));
1797 }
1798 }
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001799
1800 /* Reschedule the guard timeout */
1801 g_Tguard.start(30.0 + 10.0);
1802
1803 /* NOTE: the BSC is expected to respond with CC ALERTING at this state, so
1804 * the MSC would stop T310. However, the idea is to verify T310 expiration
1805 * here, so grab some popcorn and wait for MNCC DISC.ind. */
1806 T310.start(30.0 + 2.0);
Neels Hofmeyre81ef422022-08-07 14:33:06 +02001807 var MNCC_PDU mncc_rx;
Harald Welte812f7a42018-01-27 00:49:18 +01001808 alt {
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001809 [] T310.timeout {
1810 setverdict(fail, "Timeout waiting for MNCC DISC.ind due to T310");
Daniel Willmannafce8662018-07-06 23:11:32 +02001811 mtc.stop;
1812 }
Harald Welte812f7a42018-01-27 00:49:18 +01001813 [] MNCC.receive(tr_MNCC_DISC_ind(cpars.mncc_callref)) {
1814 MNCC.send(ts_MNCC_REL_req(cpars.mncc_callref, valueof(ts_MNCC_cause(23))));
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001815 log("Rx MNCC DISC.ind, T310.read yelds ", T310.read);
1816 setverdict(pass);
Harald Welte812f7a42018-01-27 00:49:18 +01001817 }
Neels Hofmeyre81ef422022-08-07 14:33:06 +02001818 [] MNCC.receive(MNCC_PDU:?) -> value mncc_rx {
1819 log("Rx ", mncc_rx);
1820 setverdict(fail, "Expected MNCC DISC.ind, got some other MNCC message instead");
1821 mtc.stop;
1822 }
Harald Welte812f7a42018-01-27 00:49:18 +01001823 }
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001824
Harald Welte812f7a42018-01-27 00:49:18 +01001825 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_DISC(cpars.transaction_id)));
1826 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id)));
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001827 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id, '1'B)));
Harald Welte812f7a42018-01-27 00:49:18 +01001828
1829 alt {
Harald Welte812f7a42018-01-27 00:49:18 +01001830 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1831 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001832 // FIXME: f_create_mgcp_delete_ep(cpars.mgcp_ep);
Harald Welte812f7a42018-01-27 00:49:18 +01001833 repeat;
1834 }
Harald Welte5946b332018-03-18 23:32:21 +01001835 [] as_clear_cmd_compl_disc();
Harald Welte812f7a42018-01-27 00:49:18 +01001836 }
1837}
1838testcase TC_mt_t310() runs on MTC_CT {
1839 var BSC_ConnHdlr vc_conn;
1840 f_init();
1841
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001842 vc_conn := f_start_handler(refers(f_tc_mt_t310), 32);
Harald Welte812f7a42018-01-27 00:49:18 +01001843 vc_conn.done;
1844}
1845
Harald Weltee13cfb22019-04-23 16:52:02 +02001846
Harald Welte167458a2018-01-27 15:58:16 +01001847/* Perform successful LU + MO call, then GSUP LocationCancel. Subscriber must be denied CM SERV */
Harald Weltee13cfb22019-04-23 16:52:02 +02001848friend function f_tc_gsup_cancel(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte167458a2018-01-27 15:58:16 +01001849 f_init_handler(pars);
1850 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Harald Welte167458a2018-01-27 15:58:16 +01001851
1852 /* Location Update to make subscriber known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001853 f_perform_lu();
Harald Welte167458a2018-01-27 15:58:16 +01001854
1855 /* First MO call should succeed */
1856 f_mo_call(cpars);
1857
1858 /* Cancel the subscriber in the VLR */
1859 GSUP.send(ts_GSUP_CL_REQ(g_pars.imsi, OSMO_GSUP_CANCEL_TYPE_WITHDRAW));
1860 alt {
1861 [] GSUP.receive(tr_GSUP_CL_RES(g_pars.imsi)) { }
1862 [] GSUP.receive(tr_GSUP_CL_ERR(g_pars.imsi)) {
1863 setverdict(fail, "Received GSUP Location Cancel Error");
Daniel Willmannafce8662018-07-06 23:11:32 +02001864 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001865 }
1866 }
1867
1868 /* Follow-up transactions should fail */
1869 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1870 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001871 f_cl3_or_initial_ue(l3_info);
Harald Welte167458a2018-01-27 15:58:16 +01001872 alt {
1873 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
1874 [] BSSAP.receive {
1875 setverdict(fail, "Received unexpected BSSAP instead of CM SERV REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +02001876 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001877 }
1878 }
Neels Hofmeyr0f7429a2019-03-07 22:28:41 +01001879
1880 f_expect_clear();
Harald Welte167458a2018-01-27 15:58:16 +01001881 setverdict(pass);
1882}
1883testcase TC_gsup_cancel() runs on MTC_CT {
1884 var BSC_ConnHdlr vc_conn;
1885 f_init();
1886
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001887 vc_conn := f_start_handler(refers(f_tc_gsup_cancel), 33, verify_cell_id := false);
Harald Welte167458a2018-01-27 15:58:16 +01001888 vc_conn.done;
1889}
1890
Harald Weltee13cfb22019-04-23 16:52:02 +02001891
Harald Welte9de84792018-01-28 01:06:35 +01001892/* A5/1 only permitted on network side, and MS capable to do it */
1893private function f_tc_lu_imsi_auth_tmsi_encr_1_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1894 pars.net.expect_auth := true;
1895 pars.net.expect_ciph := true;
1896 pars.net.kc_support := '02'O; /* A5/1 only */
1897 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001898 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001899}
1900testcase TC_lu_imsi_auth_tmsi_encr_1_13() runs on MTC_CT {
1901 var BSC_ConnHdlr vc_conn;
1902 f_init();
1903 f_vty_config(MSCVTY, "network", "authentication required");
1904 f_vty_config(MSCVTY, "network", "encryption a5 1");
1905
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001906 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_1_13), 34);
Harald Welte9de84792018-01-28 01:06:35 +01001907 vc_conn.done;
1908}
1909
1910/* A5/3 only permitted on network side, and MS capable to do it */
1911private function f_tc_lu_imsi_auth_tmsi_encr_3_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1912 pars.net.expect_auth := true;
1913 pars.net.expect_ciph := true;
1914 pars.net.kc_support := '08'O; /* A5/3 only */
1915 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001916 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001917}
1918testcase TC_lu_imsi_auth_tmsi_encr_3_13() runs on MTC_CT {
1919 var BSC_ConnHdlr vc_conn;
1920 f_init();
1921 f_vty_config(MSCVTY, "network", "authentication required");
1922 f_vty_config(MSCVTY, "network", "encryption a5 3");
1923
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001924 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_13), 35);
Harald Welte9de84792018-01-28 01:06:35 +01001925 vc_conn.done;
1926}
1927
1928/* A5/3 only permitted on network side, and MS with only A5/1 support */
1929private function f_tc_lu_imsi_auth_tmsi_encr_3_1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1930 pars.net.expect_auth := true;
1931 pars.net.expect_ciph := true;
1932 pars.net.kc_support := '08'O; /* A5/3 only */
1933 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1934 f_init_handler(pars, 15.0);
1935
1936 /* cannot use f_perform_lu() as we expect a reject */
1937 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
1938 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +02001939 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001940 if (pars.send_early_cm) {
1941 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1942 } else {
1943 pars.cm1.esind := '0'B;
1944 }
Harald Welte9de84792018-01-28 01:06:35 +01001945 f_mm_auth();
1946 alt {
Daniel Willmann52918e52018-09-20 14:39:09 +02001947 [] BSSAP.receive(tr_BSSMAP_ClassmarkReq) {
1948 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1949 repeat;
1950 }
Harald Welte5946b332018-03-18 23:32:21 +01001951 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1952 f_expect_clear();
1953 }
Harald Welte9de84792018-01-28 01:06:35 +01001954 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
1955 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02001956 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001957 }
1958 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01001959 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02001960 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001961 }
1962 }
1963 setverdict(pass);
1964}
1965testcase TC_lu_imsi_auth_tmsi_encr_3_1() runs on MTC_CT {
1966 var BSC_ConnHdlr vc_conn;
1967 f_init();
1968 f_vty_config(MSCVTY, "network", "authentication required");
1969 f_vty_config(MSCVTY, "network", "encryption a5 3");
1970
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001971 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 360, verify_cell_id := false);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001972 vc_conn.done;
1973}
1974testcase TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() runs on MTC_CT {
1975 var BSC_ConnHdlrPars pars;
1976 var BSC_ConnHdlr vc_conn;
1977 f_init();
1978 f_vty_config(MSCVTY, "network", "authentication required");
1979 f_vty_config(MSCVTY, "network", "encryption a5 3");
1980
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001981 pars := f_init_pars(361, verify_cell_id := false);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001982 pars.send_early_cm := false;
1983 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), pars);
Harald Welte9de84792018-01-28 01:06:35 +01001984 vc_conn.done;
1985}
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01001986testcase TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() runs on MTC_CT {
1987 var BSC_ConnHdlr vc_conn;
1988 f_init();
1989 f_vty_config(MSCVTY, "network", "authentication required");
1990 f_vty_config(MSCVTY, "network", "encryption a5 3");
1991
1992 /* Make sure the MSC category is on DEBUG level to trigger the log
1993 * message that is reported in OS#2947 to trigger the segfault */
1994 f_vty_config(MSCVTY, "log stderr", "logging level msc debug");
1995
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001996 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 362, verify_cell_id := false);
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01001997 vc_conn.done;
1998}
Harald Welte9de84792018-01-28 01:06:35 +01001999
2000/* A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
2001private function f_tc_lu_imsi_auth_tmsi_encr_13_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2002 pars.net.expect_auth := true;
2003 pars.net.expect_ciph := true;
2004 pars.net.kc_support := '0A'O; /* A5/1 + A5/3 */
2005 pars.cm1.a5_1 := '1'B;
2006 pars.cm2.a5_1 := '1'B;
2007 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
2008 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
2009 f_init_handler(pars, 15.0);
2010
2011 /* cannot use f_perform_lu() as we expect a reject */
2012 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
2013 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +02002014 f_cl3_or_initial_ue(l3_lu);
Harald Welte9de84792018-01-28 01:06:35 +01002015 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
2016 f_mm_auth();
2017 alt {
Harald Welte5946b332018-03-18 23:32:21 +01002018 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
2019 f_expect_clear();
2020 }
Harald Welte9de84792018-01-28 01:06:35 +01002021 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
2022 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02002023 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01002024 }
2025 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01002026 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02002027 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01002028 }
2029 }
2030 setverdict(pass);
2031}
2032testcase TC_lu_imsi_auth_tmsi_encr_13_2() runs on MTC_CT {
2033 var BSC_ConnHdlr vc_conn;
2034 f_init();
2035 f_vty_config(MSCVTY, "network", "authentication required");
2036 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
2037
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02002038 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_2), 37, verify_cell_id := false);
Harald Welte9de84792018-01-28 01:06:35 +01002039 vc_conn.done;
2040}
2041
Eric Wild26f4a622021-05-17 15:27:05 +02002042/* A5/0 + A5/1 + A5/3 + a5/4 only permitted on network side, and MS with only A5/1 support */
2043private function f_tc_lu_imsi_auth_tmsi_encr_0134_1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2044 pars.net.expect_auth := true;
2045 pars.net.expect_ciph := true;
2046 pars.net.kc_support := '03'O; /* A5/0 + A5/1 */
2047 pars.cm1.a5_1 := '0'B;
2048 pars.cm2.a5_1 := '0'B;
2049 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
2050 pars.cm2.classmarkInformationType2_oct5.a5_2 := '0'B;
2051 pars.cm2.classmarkInformationType2_oct5.cm3 := '0'B;
2052 pars.cm3 := omit;
2053 pars.use_umts_aka := true;
2054
2055 f_init_handler(pars, 15.0);
2056 f_perform_lu();
2057}
2058testcase TC_lu_imsi_auth_tmsi_encr_0134_1() runs on MTC_CT {
2059 var BSC_ConnHdlr vc_conn;
2060 f_init();
2061 f_vty_config(MSCVTY, "network", "authentication required");
2062 f_vty_config(MSCVTY, "network", "encryption a5 0 1 3 4");
2063
2064 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_0134_1), 39);
2065 vc_conn.done;
2066}
2067
2068/* A5/0 + A5/1 + A5/3 + a5/4 only permitted on network side, and MS with A5/3 + A5/4 support */
2069private function f_tc_lu_imsi_auth_tmsi_encr_0134_34(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2070 pars.net.expect_auth := true;
2071 pars.net.expect_ciph := true;
2072 pars.net.kc_support := '19'O; /* A5/3 + A5/4 */
2073 pars.cm1.a5_1 := '1'B;
2074 pars.cm2.a5_1 := '1'B;
2075 pars.cm2.classmarkInformationType2_oct5.a5_3 := '1'B;
2076 pars.cm2.classmarkInformationType2_oct5.a5_2 := '0'B;
2077 pars.cm2.classmarkInformationType2_oct5.cm3 := '1'B;
2078 pars.cm3 := valueof(ts_CM3_default);
2079 pars.use_umts_aka := true;
2080
2081 f_init_handler(pars, 15.0);
2082 f_perform_lu();
2083}
2084testcase TC_lu_imsi_auth_tmsi_encr_0134_34() runs on MTC_CT {
2085 var BSC_ConnHdlr vc_conn;
2086 f_init();
2087 f_vty_config(MSCVTY, "network", "authentication required");
2088 f_vty_config(MSCVTY, "network", "encryption a5 0 1 3 4");
2089
2090 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_0134_34), 40);
2091 vc_conn.done;
2092}
2093
2094/* A5/0 + A5/1 + A5/3 + a5/4 only permitted on network side, and MS with A5/3 support but no CM3 */
2095private function f_tc_lu_imsi_auth_tmsi_encr_0134_34_no_cm3(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2096 pars.net.expect_auth := true;
2097 pars.net.expect_ciph := true;
2098 pars.net.kc_support := '19'O; /* A5/3 + A5/4 */
2099 pars.cm1.a5_1 := '1'B;
2100 pars.cm2.a5_1 := '1'B;
2101 pars.cm2.classmarkInformationType2_oct5.a5_3 := '1'B;
2102 pars.cm2.classmarkInformationType2_oct5.a5_2 := '0'B;
2103 pars.cm2.classmarkInformationType2_oct5.cm3 := '0'B;
2104 pars.cm3 := omit;
2105 pars.use_umts_aka := true;
2106
2107 f_init_handler(pars, 15.0);
2108 f_perform_lu();
2109}
2110testcase TC_lu_imsi_auth_tmsi_encr_0134_34_no_cm3() runs on MTC_CT {
2111 var BSC_ConnHdlr vc_conn;
2112 f_init();
2113 f_vty_config(MSCVTY, "network", "authentication required");
2114 f_vty_config(MSCVTY, "network", "encryption a5 0 1 3 4");
2115
2116 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_0134_34_no_cm3), 41);
2117 vc_conn.done;
2118}
2119
Harald Welte9de84792018-01-28 01:06:35 +01002120/* A5/0 + A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
2121private function f_tc_lu_imsi_auth_tmsi_encr_013_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2122 pars.net.expect_auth := true;
2123 pars.net.expect_ciph := true;
2124 pars.net.kc_support := '0B'O; /* A5/1 + A5/3 */
2125 pars.cm1.a5_1 := '1'B;
2126 pars.cm2.a5_1 := '1'B;
2127 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
2128 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
2129 f_init_handler(pars, 15.0);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01002130 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01002131}
2132testcase TC_lu_imsi_auth_tmsi_encr_013_2() runs on MTC_CT {
2133 var BSC_ConnHdlr vc_conn;
2134 f_init();
2135 f_vty_config(MSCVTY, "network", "authentication required");
2136 f_vty_config(MSCVTY, "network", "encryption a5 0 1 3");
2137
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01002138 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_013_2), 38);
Harald Welte9de84792018-01-28 01:06:35 +01002139 vc_conn.done;
2140}
2141
Harald Welte33ec09b2018-02-10 15:34:46 +01002142/* LU followed by MT call (including paging) */
Neels Hofmeyr8fe8a902019-11-03 05:51:03 +01002143friend function f_tc_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte33ec09b2018-02-10 15:34:46 +01002144 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01002145 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02002146 cpars.use_osmux := pars.use_osmux;
Harald Welte33ec09b2018-02-10 15:34:46 +01002147
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01002148 f_perform_lu();
Harald Welte33ec09b2018-02-10 15:34:46 +01002149 f_mt_call(cpars);
2150}
2151testcase TC_lu_and_mt_call() runs on MTC_CT {
2152 var BSC_ConnHdlr vc_conn;
2153 f_init();
2154
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01002155 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call), 39);
Harald Welte33ec09b2018-02-10 15:34:46 +01002156 vc_conn.done;
2157}
2158
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02002159testcase TC_lu_and_mt_call_osmux() runs on MTC_CT {
2160 var BSC_ConnHdlr vc_conn;
2161 f_init(1, false, true, true);
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02002162
2163 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call), 39, 0, true, true);
2164 vc_conn.done;
2165}
2166
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02002167/* LU followed by MT call (including paging) */
2168friend function f_tc_lu_and_mt_call_ipv6(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2169 f_init_handler(pars);
2170 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
2171 cpars.mgw_conn_1.mgw_rtp_ip := "::1";
2172 cpars.mgw_conn_2.mgw_rtp_ip := "::2";
2173 cpars.bss_rtp_ip := "::3";
Pau Espin Pedrol563b3d02020-09-09 20:19:52 +02002174 cpars.mncc_rtp_ip := "::9";
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02002175 f_perform_lu();
2176 f_mt_call(cpars);
2177}
2178testcase TC_lu_and_mt_call_ipv6() runs on MTC_CT {
2179 var BSC_ConnHdlr vc_conn;
2180 f_init();
2181
2182 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call_ipv6), 39);
2183 vc_conn.done;
2184}
2185
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01002186/* MT call while already Paging */
2187friend function f_tc_lu_and_mt_call_already_paging(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2188 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
2189 var SmsParameters spars := valueof(t_SmsPars);
2190 var OCT4 tmsi;
2191
2192 f_init_handler(pars);
2193
2194 /* Perform location update */
2195 f_perform_lu();
2196
2197 /* register an 'expect' for given IMSI (+TMSI) */
2198 if (isvalue(g_pars.tmsi)) {
2199 tmsi := g_pars.tmsi;
2200 } else {
2201 tmsi := 'FFFFFFFF'O;
2202 }
2203 f_ran_register_imsi(g_pars.imsi, tmsi);
2204
2205 log("start Paging by an SMS");
2206 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2207
2208 /* MSC->BSC: expect PAGING from MSC */
2209 f_expect_paging();
2210
2211 log("MNCC signals MT call, before Paging Response");
2212 f_mt_call_initate(cpars);
2213 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
2214
2215 f_sleep(0.5);
2216 log("phone answers Paging, expecting both SMS and MT call to be established");
2217 f_establish_fully(EST_TYPE_PAG_RESP);
2218 spars.tp.ud := 'C8329BFD064D9B53'O;
2219 interleave {
2220 [] BSSAP.receive(f_mt_sms_deliver_pdu(spars)) {
2221 log("Got SMS-DELIVER");
2222 };
2223 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_SETUP(cpars.transaction_id, *, cpars.called_party))) {
2224 log("Got CC Setup");
2225 };
2226 }
2227 setverdict(pass);
2228 log("success, tear down");
2229 var default ccrel := activate(as_optional_cc_rel(cpars));
2230 if (g_pars.ran_is_geran) {
2231 BSSAP.send(ts_BSSMAP_ClearRequest(0));
2232 } else {
2233 BSSAP.send(ts_RANAP_IuReleaseRequest(ts_RanapCause_om_intervention));
2234 }
2235 f_expect_clear();
2236 deactivate(ccrel);
2237 f_vty_sms_clear(hex2str(g_pars.imsi));
2238}
2239testcase TC_lu_and_mt_call_already_paging() runs on MTC_CT {
2240 var BSC_ConnHdlrPars pars;
2241 var BSC_ConnHdlr vc_conn;
2242 f_init();
2243 pars := f_init_pars(391);
2244 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_call_already_paging), pars);
2245 vc_conn.done;
2246}
2247
Daniel Willmann8b084372018-02-04 13:35:26 +01002248/* Test MO Call SETUP with DTMF */
2249private function f_tc_mo_setup_dtmf_dup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2250 f_init_handler(pars);
2251 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Daniel Willmann8b084372018-02-04 13:35:26 +01002252
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01002253 f_perform_lu();
Daniel Willmann8b084372018-02-04 13:35:26 +01002254 f_mo_seq_dtmf_dup(cpars);
2255}
2256testcase TC_mo_setup_and_dtmf_dup() runs on MTC_CT {
2257 var BSC_ConnHdlr vc_conn;
2258 f_init();
2259
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01002260 vc_conn := f_start_handler(refers(f_tc_mo_setup_dtmf_dup), 39);
Daniel Willmann8b084372018-02-04 13:35:26 +01002261 vc_conn.done;
2262}
Harald Welte9de84792018-01-28 01:06:35 +01002263
Philipp Maier328d1662018-03-07 10:40:27 +01002264testcase TC_cr_before_reset() runs on MTC_CT {
2265 timer T := 4.0;
2266 var boolean reset_ack_seen := false;
2267 f_init_bssap_direct();
2268
Harald Welte3ca0ce12019-04-23 17:18:48 +02002269 f_ran_adapter_start(g_bssap[0]);
Daniel Willmann42d1d5b2018-08-07 15:18:41 +02002270
Daniel Willmanne8018962018-08-21 14:18:00 +02002271 f_sleep(3.0);
2272
Philipp Maier328d1662018-03-07 10:40:27 +01002273 /* Make a blind connection attemt, to trigger the deadlock condition */
Philipp Maier75932982018-03-27 14:52:35 +02002274 BSSAP_DIRECT.send(ts_BSSAP_CONNECT_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, 1, omit));
Philipp Maier328d1662018-03-07 10:40:27 +01002275
2276 /* Send a BSSMAP reset */
Philipp Maier75932982018-03-27 14:52:35 +02002277 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_Reset(0)));
Philipp Maier328d1662018-03-07 10:40:27 +01002278 T.start
2279 alt {
2280 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_ResetAck)) {
2281 reset_ack_seen := true;
2282 repeat;
2283 }
2284
2285 /* Acknowledge MSC sided reset requests */
2286 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_Reset)) {
Philipp Maier75932982018-03-27 14:52:35 +02002287 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_ResetAck));
Philipp Maier328d1662018-03-07 10:40:27 +01002288 repeat;
2289 }
2290
2291 /* Ignore all other messages (e.g CR from the connection request) */
2292 [] BSSAP_DIRECT.receive { repeat }
2293
2294 /* If we got no BSSMAP RESET ACK back, then the MSC entered the
2295 * deadlock situation. The MSC is then unable to respond to any
2296 * further BSSMAP RESET or any other sort of traffic. */
2297 [reset_ack_seen == true] T.timeout { setverdict(pass) }
2298 [reset_ack_seen == false] T.timeout {
2299 setverdict(fail, "no BSSMAP RESET ACK seen!");
Daniel Willmannafce8662018-07-06 23:11:32 +02002300 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +01002301 }
Pau Espin Pedrol7e9178d2019-12-17 17:52:17 +01002302 }
Philipp Maier328d1662018-03-07 10:40:27 +01002303}
Harald Welte9de84792018-01-28 01:06:35 +01002304
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002305/* Test MO Call with no response to RAN-side CRCX or DTAP Release */
Harald Weltee13cfb22019-04-23 16:52:02 +02002306friend function f_tc_mo_release_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002307 f_init_handler(pars);
2308 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
2309 var MNCC_PDU mncc;
2310 var MgcpCommand mgcp_cmd;
2311
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02002312 /* Do not respond to the second CRCX */
2313 cpars.mgw_conn_2.resp := 0;
2314
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002315 f_perform_lu();
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02002316 f_mo_call_establish(cpars);
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002317
Neels Hofmeyrde76f052019-02-26 05:02:46 +01002318 var default ccrel := activate(as_optional_cc_rel(cpars));
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002319
2320 f_expect_clear(60.0);
Neels Hofmeyrde76f052019-02-26 05:02:46 +01002321
2322 deactivate(ccrel);
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002323}
2324testcase TC_mo_release_timeout() runs on MTC_CT {
2325 var BSC_ConnHdlr vc_conn;
2326 f_init();
2327
2328 vc_conn := f_start_handler(refers(f_tc_mo_release_timeout), 40);
2329 vc_conn.done;
2330}
2331
Harald Welte12510c52018-01-26 22:26:24 +01002332
Philipp Maier2a98a732018-03-19 16:06:12 +01002333/* LU followed by MT call (including paging) */
2334private function f_tc_lu_and_mt_call_no_dlcx_resp(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2335 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01002336 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Philipp Maier2a98a732018-03-19 16:06:12 +01002337
2338 /* Intentionally disable the CRCX response */
2339 cpars.mgw_drop_dlcx := true;
2340
2341 /* Perform location update and call */
2342 f_perform_lu();
2343 f_mt_call(cpars);
2344}
2345testcase TC_lu_and_mt_call_no_dlcx_resp() runs on MTC_CT {
2346 var BSC_ConnHdlr vc_conn;
2347 f_init();
2348
2349 /* Perform an almost normal looking locationupdate + mt-call, but do
2350 * not respond to the DLCX at the end of the call */
2351 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call_no_dlcx_resp), 41);
2352 vc_conn.done;
2353
2354 /* Wait a guard period until the MGCP layer in the MSC times out,
2355 * if the MSC is vulnerable to the use-after-free situation that is
2356 * fixed by I78f1b6a9149488a4ad3f120c1e190a83c07d4b89 then it should
2357 * segfault now */
2358 f_sleep(6.0);
2359
2360 /* Run the init procedures once more. If the MSC has crashed, this
2361 * this will fail */
2362 f_init();
2363}
Harald Welte45164da2018-01-24 12:51:27 +01002364
Philipp Maier75932982018-03-27 14:52:35 +02002365/* Two BSSMAP resets from two different BSCs */
2366testcase TC_reset_two() runs on MTC_CT {
2367 var BSC_ConnHdlr vc_conn;
2368 f_init(2);
2369 f_sleep(2.0);
2370 setverdict(pass);
2371}
2372
Harald Weltee13cfb22019-04-23 16:52:02 +02002373/* Two BSSMAP resets from two different BSCs plus one IuCS RANAP Reset */
2374testcase TC_reset_two_1iu() runs on MTC_CT {
2375 var BSC_ConnHdlr vc_conn;
2376 f_init(3);
2377 f_sleep(2.0);
2378 setverdict(pass);
2379}
2380
Harald Weltef640a012018-04-14 17:49:21 +02002381/***********************************************************************
2382 * SMS Testing
2383 ***********************************************************************/
2384
Harald Weltef45efeb2018-04-09 18:19:24 +02002385/* LU followed by MO SMS */
Harald Weltee13cfb22019-04-23 16:52:02 +02002386friend function f_tc_lu_and_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02002387 var SmsParameters spars := valueof(t_SmsPars);
2388
2389 f_init_handler(pars);
2390
2391 /* Perform location update and call */
2392 f_perform_lu();
2393
2394 f_establish_fully(EST_TYPE_MO_SMS);
2395
2396 //spars.exp_rp_err := 96; /* invalid mandatory information */
2397 f_mo_sms(spars);
2398
2399 f_expect_clear();
2400}
2401testcase TC_lu_and_mo_sms() runs on MTC_CT {
2402 var BSC_ConnHdlr vc_conn;
2403 f_init();
2404 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_sms), 42);
2405 vc_conn.done;
2406}
2407
Harald Weltee13cfb22019-04-23 16:52:02 +02002408
Harald Weltef45efeb2018-04-09 18:19:24 +02002409private function f_vty_sms_send(charstring imsi, charstring msisdn, charstring text)
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002410runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02002411 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
2412}
2413
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01002414/* Remove still pending SMS */
2415private function f_vty_sms_clear(charstring imsi)
2416runs on BSC_ConnHdlr {
2417 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " sms delete-all");
2418 f_vty_transceive(MSCVTY, "sms-queue clear");
2419}
2420
Harald Weltef45efeb2018-04-09 18:19:24 +02002421/* LU followed by MT SMS */
Harald Weltee13cfb22019-04-23 16:52:02 +02002422friend function f_tc_lu_and_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02002423 var SmsParameters spars := valueof(t_SmsPars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002424
2425 f_init_handler(pars);
2426
2427 /* Perform location update and call */
2428 f_perform_lu();
2429
2430 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002431 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Weltef45efeb2018-04-09 18:19:24 +02002432
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002433 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
Harald Weltef45efeb2018-04-09 18:19:24 +02002434
2435 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02002436 f_expect_paging();
2437
Harald Weltef45efeb2018-04-09 18:19:24 +02002438 /* Establish DTAP / BSSAP / SCCP connection */
2439 f_establish_fully(EST_TYPE_PAG_RESP);
2440
2441 spars.tp.ud := 'C8329BFD064D9B53'O;
2442 f_mt_sms(spars);
2443
2444 f_expect_clear();
2445}
2446testcase TC_lu_and_mt_sms() runs on MTC_CT {
2447 var BSC_ConnHdlrPars pars;
2448 var BSC_ConnHdlr vc_conn;
2449 f_init();
2450 pars := f_init_pars(43);
2451 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms), pars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002452 vc_conn.done;
2453}
2454
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01002455/* SMS added while already Paging */
2456friend function f_tc_lu_and_mt_sms_already_paging(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2457 var SmsParameters spars := valueof(t_SmsPars);
2458 var OCT4 tmsi;
2459
2460 f_init_handler(pars);
2461
2462 f_perform_lu();
2463
2464 /* register an 'expect' for given IMSI (+TMSI) */
2465 if (isvalue(g_pars.tmsi)) {
2466 tmsi := g_pars.tmsi;
2467 } else {
2468 tmsi := 'FFFFFFFF'O;
2469 }
2470 f_ran_register_imsi(g_pars.imsi, tmsi);
2471
2472 log("first SMS");
2473 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2474
2475 /* MSC->BSC: expect PAGING from MSC */
2476 f_expect_paging();
2477
2478 log("second SMS");
2479 /* Now osmo-msc is in state "Paging pending", make sure that another SMS to be sent at this time just joins in
2480 * with the pending paging. Another SMS: */
2481 f_vty_sms_send(hex2str(pars.imsi), "2342", "Another SMS");
2482
2483 /* Establish DTAP / BSSAP / SCCP connection */
2484 f_establish_fully(EST_TYPE_PAG_RESP);
2485
2486 spars.tp.ud := 'C8329BFD064D9B53'O;
2487 f_mt_sms(spars);
2488
2489 spars.tp.ud := '41F79B8E2ECB41D3E614'O;
2490 f_mt_sms(spars);
2491
2492 f_expect_clear();
2493}
2494testcase TC_lu_and_mt_sms_already_paging() runs on MTC_CT {
2495 var BSC_ConnHdlrPars pars;
2496 var BSC_ConnHdlr vc_conn;
2497 f_init();
2498 pars := f_init_pars(44);
2499 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_already_paging), pars);
2500 vc_conn.done;
2501}
Harald Weltee13cfb22019-04-23 16:52:02 +02002502
Philipp Maier3983e702018-11-22 19:01:33 +01002503/* Paging for MT SMS but no response */
Harald Weltee13cfb22019-04-23 16:52:02 +02002504friend function f_tc_lu_and_mt_sms_paging_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier3983e702018-11-22 19:01:33 +01002505 var SmsParameters spars := valueof(t_SmsPars);
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002506
Philipp Maier3983e702018-11-22 19:01:33 +01002507 f_init_handler(pars, 150.0);
2508
2509 /* Perform location update */
2510 f_perform_lu();
2511
2512 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002513 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Philipp Maier3983e702018-11-22 19:01:33 +01002514
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002515 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2516
Neels Hofmeyr16237742019-03-06 15:34:01 +01002517 /* Expect the MSC to page exactly once */
Harald Weltee13cfb22019-04-23 16:52:02 +02002518 f_expect_paging();
Philipp Maier3983e702018-11-22 19:01:33 +01002519
2520 /* Wait some time to make sure the MSC is not delivering any further
2521 * paging messages or anything else that could be unexpected. */
2522 timer T := 20.0;
2523 T.start
2524 alt {
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002525 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
2526 setverdict(fail, "paging seems not to stop!");
2527 mtc.stop;
Philipp Maier3983e702018-11-22 19:01:33 +01002528 }
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002529 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
2530 setverdict(fail, "paging seems not to stop!");
2531 mtc.stop;
Harald Weltee13cfb22019-04-23 16:52:02 +02002532 }
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002533 [] BSSAP.receive {
2534 setverdict(fail, "unexpected BSSAP message received");
2535 self.stop;
Philipp Maier3983e702018-11-22 19:01:33 +01002536 }
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002537 [] T.timeout {
2538 setverdict(pass);
Philipp Maier3983e702018-11-22 19:01:33 +01002539 }
2540 }
2541
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01002542 f_vty_sms_clear(hex2str(g_pars.imsi));
2543
Philipp Maier3983e702018-11-22 19:01:33 +01002544 setverdict(pass);
2545}
2546testcase TC_lu_and_mt_sms_paging_and_nothing() runs on MTC_CT {
2547 var BSC_ConnHdlrPars pars;
2548 var BSC_ConnHdlr vc_conn;
2549 f_init();
Philipp Maiera99ad262019-01-22 15:35:42 +01002550 pars := f_init_pars(1843);
Philipp Maier3983e702018-11-22 19:01:33 +01002551 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_paging_and_nothing), pars);
Philipp Maier3983e702018-11-22 19:01:33 +01002552 vc_conn.done;
2553}
2554
Alexander Couzensfc02f242019-09-12 03:43:18 +02002555/* LU followed by MT SMS with repeated paging */
2556friend function f_tc_lu_and_mt_sms_paging_repeated(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2557 var SmsParameters spars := valueof(t_SmsPars);
Alexander Couzensfc02f242019-09-12 03:43:18 +02002558
2559 f_init_handler(pars);
2560
2561 /* Perform location update and call */
2562 f_perform_lu();
2563
2564 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002565 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Alexander Couzensfc02f242019-09-12 03:43:18 +02002566
2567 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2568
Neels Hofmeyrc3accec2019-11-28 01:09:47 +01002569 log("Expecting first Paging");
Alexander Couzensfc02f242019-09-12 03:43:18 +02002570 /* MSC->BSC: expect PAGING from MSC */
2571 f_expect_paging();
2572
Neels Hofmeyrc3accec2019-11-28 01:09:47 +01002573 if (g_pars.ran_is_geran) {
2574 log("GERAN: expect no further Paging");
2575 } else {
2576 log("UTRAN: expect more Paging");
2577 }
2578
2579 timer T := 5.0;
2580 T.start;
2581 alt {
2582 [g_pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
2583 setverdict(fail, "GERAN should not repeat Paging, but received a second Paging");
2584 mtc.stop;
2585 }
2586 [not g_pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
2587 log("UTRAN: second Paging received, as expected");
2588 setverdict(pass);
2589 }
2590 [] T.timeout {
2591 if (g_pars.ran_is_geran) {
2592 log("GERAN: No further Paging received, as expected");
2593 setverdict(pass);
2594 } else {
2595 setverdict(fail, "UTRAN: Expected a second Paging");
2596 mtc.stop;
2597 }
2598 }
2599 }
Alexander Couzensfc02f242019-09-12 03:43:18 +02002600
2601 /* Establish DTAP / BSSAP / SCCP connection */
2602 f_establish_fully(EST_TYPE_PAG_RESP);
2603
2604 spars.tp.ud := 'C8329BFD064D9B53'O;
2605 f_mt_sms(spars);
2606
2607 f_expect_clear();
2608}
2609testcase TC_lu_and_mt_sms_paging_repeated() runs on MTC_CT {
2610 var BSC_ConnHdlrPars pars;
2611 var BSC_ConnHdlr vc_conn;
2612 f_init();
2613 pars := f_init_pars(1844);
2614 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_paging_repeated), pars);
2615 vc_conn.done;
2616}
Harald Weltee13cfb22019-04-23 16:52:02 +02002617
Harald Weltef640a012018-04-14 17:49:21 +02002618/* mobile originated SMS from MS/BTS/BSC side to SMPP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002619friend function f_tc_smpp_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef640a012018-04-14 17:49:21 +02002620 var SmsParameters spars := valueof(t_SmsPars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002621
Harald Weltef640a012018-04-14 17:49:21 +02002622 f_init_handler(pars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002623
Harald Weltef640a012018-04-14 17:49:21 +02002624 /* Perform location update so IMSI is known + registered in MSC/VLR */
2625 f_perform_lu();
Harald Weltef640a012018-04-14 17:49:21 +02002626
Vadim Yanitskiy2d3f8462020-01-15 11:44:12 +07002627 /* MS/UE submits a MO SMS */
2628 f_establish_fully(EST_TYPE_MO_SMS);
2629 f_mo_sms_submit(spars);
Harald Weltef640a012018-04-14 17:49:21 +02002630
2631 var SMPP_PDU smpp;
2632 var template SMPP_PDU tr_smpp := tr_SMPP(c_SMPP_command_id_deliver_sm, ESME_ROK);
2633 tr_smpp.body.deliver_sm := {
2634 service_type := "CMT",
2635 source_addr_ton := network_specific,
2636 source_addr_npi := isdn,
2637 source_addr := hex2str(pars.msisdn),
2638 dest_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
2639 dest_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
2640 destination_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
2641 esm_class := '00000001'B,
2642 protocol_id := 0,
2643 priority_flag := 0,
2644 schedule_delivery_time := "",
2645 replace_if_present := 0,
2646 data_coding := '00000001'B,
2647 sm_default_msg_id := 0,
2648 sm_length := ?,
2649 short_message := spars.tp.ud,
2650 opt_pars := {
2651 {
2652 tag := user_message_reference,
2653 len := 2,
2654 opt_value := {
2655 int2_val := oct2int(spars.tp.msg_ref)
2656 }
2657 }
2658 }
2659 };
2660 alt {
2661 [] SMPP.receive(tr_smpp) -> value smpp {
2662 SMPP.send(ts_SMPP_DELIVER_SM_resp(ESME_ROK, smpp.header.seq_num));
2663 }
2664 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK)) { repeat; }
2665 }
2666
Vadim Yanitskiy2d3f8462020-01-15 11:44:12 +07002667 /* MSC terminates the SMS transaction with RP-ACK */
2668 f_mo_sms_wait_rp_ack(spars);
2669
Harald Weltef640a012018-04-14 17:49:21 +02002670 f_expect_clear();
2671}
2672testcase TC_smpp_mo_sms() runs on MTC_CT {
2673 var BSC_ConnHdlr vc_conn;
2674 f_init();
2675 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "default-route");
2676 vc_conn := f_start_handler(refers(f_tc_smpp_mo_sms), 44);
2677 vc_conn.done;
2678 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "no default-route");
2679}
2680
Vadim Yanitskiy33820762020-01-15 11:26:07 +07002681/* Test case for OS#4351: make sure that RP-ERROR from ESME is properly sent to the MS/UE */
2682friend function f_tc_smpp_mo_sms_rp_error(charstring id, BSC_ConnHdlrPars pars)
2683runs on BSC_ConnHdlr {
2684 var SmsParameters spars := valueof(t_SmsPars);
2685 var SMPP_PDU smpp_pdu;
2686 timer T := 3.0;
2687
2688 f_init_handler(pars);
2689
2690 /* Perform location update */
2691 f_perform_lu();
2692
2693 /* MS/UE submits a MO SMS */
2694 f_establish_fully(EST_TYPE_MO_SMS);
2695 f_mo_sms_submit(spars);
2696
2697 /* ESME responds with an error (Invalid Destination Address) */
2698 T.start;
2699 alt {
2700 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_deliver_sm, ESME_ROK, body := ?)) -> value smpp_pdu {
2701 SMPP.send(ts_SMPP_DELIVER_SM_resp(ESME_RINVDSTADR, smpp_pdu.header.seq_num));
2702 }
2703 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK)) { repeat; }
2704 [] T.timeout {
2705 setverdict(fail, "Timeout waiting for SMPP DELIVER-SM");
2706 mtc.stop;
2707 }
2708 }
2709
2710 /* Expect RP-ERROR on BSSAP interface */
2711 spars.exp_rp_err := 1; /* FIXME: GSM411_RP_CAUSE_MO_NUM_UNASSIGNED */
2712 f_mo_sms_wait_rp_ack(spars);
2713
2714 f_expect_clear();
2715}
2716testcase TC_smpp_mo_sms_rp_error() runs on MTC_CT {
2717 var BSC_ConnHdlr vc_conn;
2718 f_init();
2719 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "default-route");
2720 vc_conn := f_start_handler(refers(f_tc_smpp_mo_sms_rp_error), 45);
2721 vc_conn.done;
2722 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "no default-route");
2723}
2724
Harald Weltee13cfb22019-04-23 16:52:02 +02002725
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002726/* Test MO-SMS from MS/BTS/BSC towards HLR (via GSUP) */
Harald Weltee13cfb22019-04-23 16:52:02 +02002727friend function f_tc_gsup_mo_sms(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002728runs on BSC_ConnHdlr {
2729 var SmsParameters spars := valueof(t_SmsPars);
2730 var GSUP_PDU gsup_msg_rx;
2731 var octetstring sm_tpdu;
2732
2733 f_init_handler(pars);
2734
2735 /* We need to inspect GSUP activity */
2736 f_create_gsup_expect(hex2str(g_pars.imsi));
2737
2738 /* Perform location update */
2739 f_perform_lu();
2740
2741 /* Send CM Service Request for SMS */
2742 f_establish_fully(EST_TYPE_MO_SMS);
2743
2744 /* Prepare expected SM-RP-UI (SM TPDU) */
2745 enc_TPDU_RP_DATA_MS_SGSN_fast(
2746 valueof(ts_SMS_SUBMIT(spars.tp.msg_ref,
2747 spars.tp.da, spars.tp.pid, spars.tp.dcs,
2748 spars.tp.udl, spars.tp.ud)),
2749 sm_tpdu);
2750
2751 var template GSUP_PDU mo_forwardSM := tr_GSUP_MO_FORWARD_SM_REQ(
2752 imsi := g_pars.imsi,
2753 sm_rp_mr := spars.rp.msg_ref,
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09002754 /* SM-RP-DA: SMSC address */
2755 sm_rp_da := tr_GSUP_SM_RP_DA_SMSC_ADDR(t_GSUP_SM_RP_Addr(
2756 number := spars.rp.smsc_addr.rP_NumberDigits,
2757 npi := spars.rp.smsc_addr.rP_NumberingPlanIdentification,
2758 ton := spars.rp.smsc_addr.rP_TypeOfNumber,
2759 ext := spars.rp.smsc_addr.rP_Ext)),
2760 /* SM-RP-OA: subscriber's MSISDN (filled in by MSC) */
2761 sm_rp_oa := tr_GSUP_SM_RP_OA_MSISDN(t_GSUP_SM_RP_Addr(
2762 number := g_pars.msisdn,
2763 /* NOTE: MSISDN in g_pars lacks this info, assuming defaults */
2764 npi := '0001'B, ton := '001'B, ext := '1'B)),
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002765 /* TODO: can we use decmatch here? */
2766 sm_rp_ui := sm_tpdu
2767 );
2768
2769 /* Submit an SMS on DTAP and expect MO-forwardSM-Req on GSUP */
2770 f_mo_sms_submit(spars);
2771 alt {
2772 [] GSUP.receive(mo_forwardSM) -> value gsup_msg_rx {
Vadim Yanitskiya358dd42020-01-15 10:42:47 +07002773 log("RX MO-forwardSM-Req: ", gsup_msg_rx);
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002774 setverdict(pass);
2775 }
2776 [] GSUP.receive {
2777 log("RX unexpected GSUP message");
2778 setverdict(fail);
2779 mtc.stop;
2780 }
2781 }
2782
2783 /* Trigger RP-ACK by sending MO-forwardSM-Res */
2784 GSUP.send(valueof(ts_GSUP_MO_FORWARD_SM_RES(
2785 imsi := g_pars.imsi,
2786 sm_rp_mr := spars.rp.msg_ref)));
2787 /* Expect RP-ACK on DTAP */
2788 f_mo_sms_wait_rp_ack(spars);
2789
2790 f_expect_clear();
2791}
2792testcase TC_gsup_mo_sms() runs on MTC_CT {
2793 var BSC_ConnHdlr vc_conn;
2794 f_init();
2795 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2796 vc_conn := f_start_handler(refers(f_tc_gsup_mo_sms), 88);
2797 vc_conn.done;
2798 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2799}
2800
Harald Weltee13cfb22019-04-23 16:52:02 +02002801
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002802/* Test MO-SMMA from MS/BTS/BSC towards HLR (via GSUP) */
Harald Weltee13cfb22019-04-23 16:52:02 +02002803friend function f_tc_gsup_mo_smma(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002804runs on BSC_ConnHdlr {
2805 var SmsParameters spars := valueof(t_SmsPars);
2806 var GSUP_PDU gsup_msg_rx;
2807
2808 f_init_handler(pars);
2809
2810 /* We need to inspect GSUP activity */
2811 f_create_gsup_expect(hex2str(g_pars.imsi));
2812
2813 /* Perform location update */
2814 f_perform_lu();
2815
2816 /* Send CM Service Request for SMS */
2817 f_establish_fully(EST_TYPE_MO_SMS);
2818
2819 var template GSUP_PDU mo_ReadyForSM := tr_GSUP_MO_READY_FOR_SM_REQ(
2820 imsi := g_pars.imsi,
2821 sm_rp_mr := spars.rp.msg_ref,
2822 sm_alert_rsn := GSUP_SM_ALERT_RSN_TYPE_MEM_AVAIL
2823 );
2824
2825 /* Submit an SMS on DTAP and expect MO-forwardSM-Req on GSUP */
2826 f_mo_smma(spars);
2827 alt {
2828 [] GSUP.receive(mo_ReadyForSM) -> value gsup_msg_rx {
Vadim Yanitskiya358dd42020-01-15 10:42:47 +07002829 log("RX MO-ReadyForSM-Req: ", gsup_msg_rx);
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002830 setverdict(pass);
2831 }
2832 [] GSUP.receive {
2833 log("RX unexpected GSUP message");
2834 setverdict(fail);
2835 mtc.stop;
2836 }
2837 }
2838
2839 /* Trigger RP-ACK by sending MO-forwardSM-Res */
2840 GSUP.send(valueof(ts_GSUP_MO_READY_FOR_SM_RES(
2841 imsi := g_pars.imsi,
2842 sm_rp_mr := spars.rp.msg_ref)));
2843 /* Expect RP-ACK on DTAP */
2844 f_mo_sms_wait_rp_ack(spars);
2845
2846 f_expect_clear();
2847}
2848testcase TC_gsup_mo_smma() runs on MTC_CT {
2849 var BSC_ConnHdlr vc_conn;
2850 f_init();
2851 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2852 vc_conn := f_start_handler(refers(f_tc_gsup_mo_smma), 89);
2853 vc_conn.done;
2854 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2855}
2856
Harald Weltee13cfb22019-04-23 16:52:02 +02002857
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002858/* Helper for sending MT SMS over GSUP */
2859private function f_gsup_forwardSM_req(SmsParameters spars, OCT1 mms := '00'O)
2860runs on BSC_ConnHdlr {
Vadim Yanitskiya52347c2019-12-12 17:32:33 +09002861 var GSUP_SM_RP_Addr msisdn := valueof(t_GSUP_SM_RP_Addr(g_pars.msisdn));
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09002862 var GSUP_SM_RP_Addr smsc := valueof(t_GSUP_SM_RP_Addr(
2863 number := spars.rp.smsc_addr.rP_NumberDigits,
2864 npi := spars.rp.smsc_addr.rP_NumberingPlanIdentification,
2865 ton := spars.rp.smsc_addr.rP_TypeOfNumber,
2866 ext := spars.rp.smsc_addr.rP_Ext));
Vadim Yanitskiya52347c2019-12-12 17:32:33 +09002867
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002868 GSUP.send(ts_GSUP_MT_FORWARD_SM_REQ(
2869 imsi := g_pars.imsi,
2870 /* NOTE: MSC should assign RP-MR itself */
2871 sm_rp_mr := 'FF'O,
Vadim Yanitskiya52347c2019-12-12 17:32:33 +09002872 sm_rp_da := valueof(ts_GSUP_SM_RP_DA_MSISDN(msisdn)),
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09002873 sm_rp_oa := valueof(ts_GSUP_SM_RP_OA_SMSC_ADDR(smsc)),
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002874 /* Encoded SMS TPDU (taken from Wireshark)
2875 * FIXME: we should encode spars somehow */
2876 sm_rp_ui := '00068021436500008111328130858200'O,
2877 sm_rp_mms := mms
2878 ));
2879}
2880
2881/* Test successful MT-SMS (RP-ACK) over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002882friend function f_tc_gsup_mt_sms_ack(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002883runs on BSC_ConnHdlr {
2884 var SmsParameters spars := valueof(t_SmsPars);
2885
2886 f_init_handler(pars);
2887
2888 /* We need to inspect GSUP activity */
2889 f_create_gsup_expect(hex2str(g_pars.imsi));
2890
2891 /* Perform location update */
2892 f_perform_lu();
2893
2894 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002895 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002896
2897 var template GSUP_PDU mt_forwardSM_res := tr_GSUP_MT_FORWARD_SM_RES(
2898 imsi := g_pars.imsi,
2899 /* NOTE: MSC should assign RP-MR itself */
2900 sm_rp_mr := ?
2901 );
2902
2903 /* Submit a MT SMS on GSUP */
2904 f_gsup_forwardSM_req(spars);
2905
2906 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002907 f_expect_paging();
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002908 f_establish_fully(EST_TYPE_PAG_RESP);
2909
2910 /* Wait for MT SMS on DTAP */
2911 f_mt_sms_expect(spars);
2912
2913 /* Send RP-ACK and expect MT-forwardSM-Res on GSUP */
2914 f_mt_sms_send_rp_ack(spars);
2915 alt {
2916 [] GSUP.receive(mt_forwardSM_res) {
2917 log("RX MT-forwardSM-Res (RP-ACK)");
2918 setverdict(pass);
2919 }
2920 [] GSUP.receive {
2921 log("RX unexpected GSUP message");
2922 setverdict(fail);
2923 mtc.stop;
2924 }
2925 }
2926
2927 f_expect_clear();
2928}
2929testcase TC_gsup_mt_sms_ack() runs on MTC_CT {
2930 var BSC_ConnHdlrPars pars;
2931 var BSC_ConnHdlr vc_conn;
2932 f_init();
2933 pars := f_init_pars(90);
2934 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2935 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_ack), pars);
2936 vc_conn.done;
2937 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2938}
2939
Harald Weltee13cfb22019-04-23 16:52:02 +02002940
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002941/* Test rejected MT-SMS (RP-ERROR) over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002942friend function f_tc_gsup_mt_sms_err(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002943runs on BSC_ConnHdlr {
2944 var SmsParameters spars := valueof(t_SmsPars);
2945 var OCT1 sm_rp_cause := '78'O; /* dummy RP-Cause value */
2946
2947 f_init_handler(pars);
2948
2949 /* We need to inspect GSUP activity */
2950 f_create_gsup_expect(hex2str(g_pars.imsi));
2951
2952 /* Perform location update */
2953 f_perform_lu();
2954
2955 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002956 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002957
2958 var template GSUP_PDU mt_forwardSM_err := tr_GSUP_MT_FORWARD_SM_ERR(
2959 imsi := g_pars.imsi,
2960 /* NOTE: MSC should assign RP-MR itself */
2961 sm_rp_mr := ?,
2962 sm_rp_cause := sm_rp_cause
2963 );
2964
2965 /* Submit a MT SMS on GSUP */
2966 f_gsup_forwardSM_req(spars);
2967
2968 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002969 f_expect_paging();
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002970 f_establish_fully(EST_TYPE_PAG_RESP);
2971
2972 /* Wait for MT SMS on DTAP */
2973 f_mt_sms_expect(spars);
2974
2975 /* Send RP-ERROR and expect MT-forwardSM-Err on GSUP */
2976 f_mt_sms_send_rp_error(spars, oct2int(sm_rp_cause));
2977 alt {
2978 [] GSUP.receive(mt_forwardSM_err) {
2979 log("RX MT-forwardSM-Err (RP-ERROR)");
2980 setverdict(pass);
2981 mtc.stop;
2982 }
2983 [] GSUP.receive {
2984 log("RX unexpected GSUP message");
2985 setverdict(fail);
2986 mtc.stop;
2987 }
2988 }
2989
2990 f_expect_clear();
2991}
2992testcase TC_gsup_mt_sms_err() runs on MTC_CT {
2993 var BSC_ConnHdlrPars pars;
2994 var BSC_ConnHdlr vc_conn;
2995 f_init();
2996 pars := f_init_pars(91);
2997 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2998 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_err), pars);
2999 vc_conn.done;
3000 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
3001}
3002
Harald Weltee13cfb22019-04-23 16:52:02 +02003003
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07003004/* Test SM-RP-MR assignment for MT-SMS over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02003005friend function f_tc_gsup_mt_sms_rp_mr(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07003006runs on BSC_ConnHdlr {
3007 var SmsParameters spars1 := valueof(t_SmsPars); /* 1st SMS */
3008 var SmsParameters spars2 := valueof(t_SmsPars); /* 2nd SMS */
3009
3010 f_init_handler(pars);
3011
3012 /* We need to inspect GSUP activity */
3013 f_create_gsup_expect(hex2str(g_pars.imsi));
3014
3015 /* Perform location update */
3016 f_perform_lu();
3017
3018 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01003019 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07003020
3021 /* Submit the 1st MT SMS on GSUP */
3022 log("TX MT-forwardSM-Req for the 1st SMS");
3023 f_gsup_forwardSM_req(spars1);
3024
3025 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02003026 f_expect_paging();
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07003027 f_establish_fully(EST_TYPE_PAG_RESP);
3028
3029 /* Wait for 1st MT SMS on DTAP */
3030 f_mt_sms_expect(spars1);
3031 log("RX the 1st SMS on DTAP, DTAP TID is ", spars1.tid,
3032 ", SM-RP-MR is ", spars1.rp.msg_ref);
3033
3034 /* Submit the 2nd MT SMS on GSUP */
3035 log("TX MT-forwardSM-Req for the 2nd SMS");
3036 f_gsup_forwardSM_req(spars2);
3037
3038 /* Wait for 2nd MT SMS on DTAP */
3039 f_mt_sms_expect(spars2);
3040 log("RX the 2nd SMS on DTAP, DTAP TID is ", spars2.tid,
3041 ", SM-RP-MR is ", spars2.rp.msg_ref);
3042
3043 /* Both transaction IDs shall be different */
3044 if (spars1.tid == spars2.tid) {
3045 log("Both DTAP transaction IDs shall be different");
3046 setverdict(fail);
3047 }
3048
3049 /* Both SM-RP-MR values shall be different */
3050 if (spars1.rp.msg_ref == spars2.rp.msg_ref) {
3051 log("Both SM-RP-MR values shall be different");
3052 setverdict(fail);
3053 }
3054
3055 /* Both SM-RP-MR values shall be assigned */
3056 if (spars1.rp.msg_ref == 'FF'O) {
3057 log("Unassigned SM-RP-MR value for the 1st SMS");
3058 setverdict(fail);
3059 }
3060 if (spars2.rp.msg_ref == 'FF'O) {
3061 log("Unassigned SM-RP-MR value for the 2nd SMS");
3062 setverdict(fail);
3063 }
3064
3065 /* Send the 1st RP-ACK and expect MT-forwardSM-Res on GSUP */
3066 f_mt_sms_send_rp_ack(spars1);
3067 alt {
3068 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
3069 imsi := g_pars.imsi,
3070 sm_rp_mr := spars1.rp.msg_ref
3071 )) {
3072 log("RX MT-forwardSM-Res (RP-ACK)");
3073 setverdict(pass);
3074 }
3075 [] GSUP.receive {
3076 log("RX unexpected GSUP message");
3077 setverdict(fail);
3078 mtc.stop;
3079 }
3080 }
3081
3082 /* Send the 2nd RP-ACK and expect MT-forwardSM-Res on GSUP */
3083 f_mt_sms_send_rp_ack(spars2);
3084 alt {
3085 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
3086 imsi := g_pars.imsi,
3087 sm_rp_mr := spars2.rp.msg_ref
3088 )) {
3089 log("RX MT-forwardSM-Res (RP-ACK)");
3090 setverdict(pass);
3091 }
3092 [] GSUP.receive {
3093 log("RX unexpected GSUP message");
3094 setverdict(fail);
3095 mtc.stop;
3096 }
3097 }
3098
3099 f_expect_clear();
3100}
3101testcase TC_gsup_mt_sms_rp_mr() runs on MTC_CT {
3102 var BSC_ConnHdlrPars pars;
3103 var BSC_ConnHdlr vc_conn;
3104 f_init();
3105 pars := f_init_pars(92);
3106 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
3107 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_rp_mr), pars);
3108 vc_conn.done;
3109 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
3110}
3111
Harald Weltee13cfb22019-04-23 16:52:02 +02003112
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07003113/* Test SM-RP-MR assignment for MT-SMS over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02003114friend function f_tc_gsup_mo_mt_sms_rp_mr(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07003115runs on BSC_ConnHdlr {
3116 var SmsParameters spars_mo := valueof(t_SmsPars); /* MO SMMA */
3117 var SmsParameters spars_mt := valueof(t_SmsPars); /* MT SMS */
3118
3119 f_init_handler(pars);
3120
3121 /* We need to inspect GSUP activity */
3122 f_create_gsup_expect(hex2str(g_pars.imsi));
3123
3124 /* Perform location update */
3125 f_perform_lu();
3126
3127 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01003128 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07003129
3130 /* Send CM Service Request for MO SMMA */
3131 f_establish_fully(EST_TYPE_MO_SMS);
3132
3133 /* Submit MO SMMA on DTAP */
3134 log("Submit MO SMMA on DTAP, SM-RP-MR is '00'O");
3135 spars_mo.rp.msg_ref := '00'O;
3136 f_mo_smma(spars_mo);
3137
3138 /* Expect MO-forwardSM-Req for MO SMMA on GSUP */
3139 alt {
3140 [] GSUP.receive(tr_GSUP_MO_READY_FOR_SM_REQ(
3141 imsi := g_pars.imsi,
3142 sm_rp_mr := spars_mo.rp.msg_ref,
3143 sm_alert_rsn := GSUP_SM_ALERT_RSN_TYPE_MEM_AVAIL
3144 )) {
3145 log("RX MO-ReadyForSM-Req, SM-RP-MR is '00'O");
3146 setverdict(pass);
3147 }
3148 [] GSUP.receive {
3149 log("RX unexpected GSUP message");
3150 setverdict(fail);
3151 mtc.stop;
3152 }
3153 }
3154
3155 /* Submit MT SMS on GSUP */
3156 log("TX MT-forwardSM-Req for the MT SMS");
3157 f_gsup_forwardSM_req(spars_mt);
3158
3159 /* Wait for MT SMS on DTAP */
3160 f_mt_sms_expect(spars_mt);
3161 log("RX MT SMS on DTAP, DTAP TID is ", spars_mt.tid,
3162 ", SM-RP-MR is ", spars_mt.rp.msg_ref);
3163
3164 /* Both SM-RP-MR values shall be different */
3165 if (spars_mo.rp.msg_ref == spars_mt.rp.msg_ref) {
3166 log("Both SM-RP-MR values shall be different");
3167 setverdict(fail);
3168 }
3169
3170 /* SM-RP-MR value for MT SMS shall be assigned */
3171 if (spars_mt.rp.msg_ref == 'FF'O) {
3172 log("Unassigned SM-RP-MR value for the MT SMS");
3173 setverdict(fail);
3174 }
3175
3176 /* Trigger RP-ACK for MO SMMA by sending MO-forwardSM-Res */
3177 GSUP.send(valueof(ts_GSUP_MO_READY_FOR_SM_RES(
3178 imsi := g_pars.imsi,
3179 sm_rp_mr := spars_mo.rp.msg_ref)));
3180 /* Expect RP-ACK for MO SMMA on DTAP */
3181 f_mo_sms_wait_rp_ack(spars_mo);
3182
3183 /* Send RP-ACK for MT SMS and expect MT-forwardSM-Res on GSUP */
3184 f_mt_sms_send_rp_ack(spars_mt);
3185 alt {
3186 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
3187 imsi := g_pars.imsi,
3188 sm_rp_mr := spars_mt.rp.msg_ref
3189 )) {
3190 log("RX MT-forwardSM-Res (RP-ACK)");
3191 setverdict(pass);
3192 }
3193 [] GSUP.receive {
3194 log("RX unexpected GSUP message");
3195 setverdict(fail);
3196 mtc.stop;
3197 }
3198 }
3199
3200 f_expect_clear();
3201}
3202testcase TC_gsup_mo_mt_sms_rp_mr() runs on MTC_CT {
3203 var BSC_ConnHdlrPars pars;
3204 var BSC_ConnHdlr vc_conn;
3205 f_init();
3206 pars := f_init_pars(93);
3207 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
3208 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mo_mt_sms_rp_mr), pars);
3209 vc_conn.done;
3210 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
3211}
3212
Harald Weltee13cfb22019-04-23 16:52:02 +02003213
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07003214/* Test multi-part MT-SMS over GSUP */
3215private function f_tc_gsup_mt_multi_part_sms(charstring id, BSC_ConnHdlrPars pars)
3216runs on BSC_ConnHdlr {
3217 var SmsParameters spars := valueof(t_SmsPars);
3218
3219 f_init_handler(pars);
3220
3221 /* We need to inspect GSUP activity */
3222 f_create_gsup_expect(hex2str(g_pars.imsi));
3223
3224 /* Perform location update */
3225 f_perform_lu();
3226
3227 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01003228 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07003229
3230 var template GSUP_PDU mt_forwardSM_res := tr_GSUP_MT_FORWARD_SM_RES(
3231 imsi := g_pars.imsi,
3232 /* NOTE: MSC should assign RP-MR itself */
3233 sm_rp_mr := ?
3234 );
3235
3236 /* Send 4 messages (NOTE: SM-RP-UI remains unchanged) */
3237 for (var integer i := 3; i >= 0; i := i-1) {
3238 /* Submit a MT SMS on GSUP (MMS is decremented) */
3239 f_gsup_forwardSM_req(spars, int2oct(i, 1));
3240
3241 /* Expect Paging Request and Establish connection */
3242 if (i == 3) { /* ... only once! */
Harald Weltee13cfb22019-04-23 16:52:02 +02003243 f_expect_paging();
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07003244 f_establish_fully(EST_TYPE_PAG_RESP);
3245 }
3246
3247 /* Wait for MT SMS on DTAP */
3248 f_mt_sms_expect(spars);
3249
3250 /* Send RP-ACK and expect MT-forwardSM-Res on GSUP */
3251 f_mt_sms_send_rp_ack(spars);
3252 alt {
3253 [] GSUP.receive(mt_forwardSM_res) {
3254 log("RX MT-forwardSM-Res (RP-ACK)");
3255 setverdict(pass);
3256 }
3257 [] GSUP.receive {
3258 log("RX unexpected GSUP message");
3259 setverdict(fail);
3260 mtc.stop;
3261 }
3262 }
3263
3264 /* Keep some 'distance' between transmissions */
3265 f_sleep(1.5);
3266 }
3267
3268 f_expect_clear();
3269}
3270testcase TC_gsup_mt_multi_part_sms() runs on MTC_CT {
3271 var BSC_ConnHdlrPars pars;
3272 var BSC_ConnHdlr vc_conn;
3273 f_init();
3274 pars := f_init_pars(91);
3275 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
3276 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_multi_part_sms), pars);
3277 vc_conn.done;
3278 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
3279}
3280
Harald Weltef640a012018-04-14 17:49:21 +02003281/* convert GSM L3 TON to SMPP_TON enum */
3282function f_sm_ton_from_gsm(BIT3 ton) return SMPP_TON {
3283 select (ton) {
3284 case ('000'B) { return unknown; }
3285 case ('001'B) { return international; }
3286 case ('010'B) { return national; }
3287 case ('011'B) { return network_specific; }
3288 case ('100'B) { return subscriber_number; }
3289 case ('101'B) { return alphanumeric; }
3290 case ('110'B) { return abbreviated; }
3291 }
3292 setverdict(fail, "Unknown TON ", ton);
Daniel Willmannafce8662018-07-06 23:11:32 +02003293 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02003294}
3295/* convert GSM L3 NPI to SMPP_NPI enum */
3296function f_sm_npi_from_gsm(BIT4 npi) return SMPP_NPI {
3297 select (npi) {
3298 case ('0000'B) { return unknown; }
3299 case ('0001'B) { return isdn; }
3300 case ('0011'B) { return data; }
3301 case ('0100'B) { return telex; }
3302 case ('0110'B) { return land_mobile; }
3303 case ('1000'B) { return national; }
3304 case ('1001'B) { return private_; }
3305 case ('1010'B) { return ermes; }
3306 }
3307 setverdict(fail, "Unknown NPI ", npi);
Daniel Willmannafce8662018-07-06 23:11:32 +02003308 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02003309}
3310
3311/* build a SMPP_SM from SmsParameters */
3312function f_mt_sm_from_spars(SmsParameters spars)
3313runs on BSC_ConnHdlr return SMPP_SM {
3314 var SMPP_SM sm := {
3315 service_type := "CMT",
3316 source_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
3317 source_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
3318 source_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
3319 dest_addr_ton := international,
3320 dest_addr_npi := isdn,
3321 destination_addr := hex2str(g_pars.msisdn),
3322 esm_class := '00000001'B,
3323 protocol_id := 0,
3324 priority_flag := 0,
3325 schedule_delivery_time := "",
3326 validity_period := "",
3327 registered_delivery := '00000000'B,
3328 replace_if_present := 0,
3329 data_coding := '00000001'B,
3330 sm_default_msg_id := 0,
3331 sm_length := spars.tp.udl,
3332 short_message := spars.tp.ud,
3333 opt_pars := {}
3334 };
3335 return sm;
3336}
3337
3338/* helper function to encode SMS from 'spars', send it via SMPP to MSC; receive it on MS side */
3339private function f_smpp_mt_sms(SmsParameters spars, boolean trans_mode) runs on BSC_ConnHdlr {
3340 var SMPP_SM sm := f_mt_sm_from_spars(spars);
3341 if (trans_mode) {
3342 sm.esm_class := '00000010'B;
3343 }
3344
3345 /* actually cause MSC to send a SMS via SUBMIT-SM from SMPP side */
3346 SMPP.send(ts_SMPP_SUBMIT_SM(sm));
3347 if (not match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
3348 /* if we're not in SMPP transaction mode, we expect the SMPP-level ACK
3349 * before we expect the SMS delivery on the BSC/radio side */
3350 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
3351 }
3352
3353 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02003354 f_expect_paging();
Harald Weltef640a012018-04-14 17:49:21 +02003355 /* Establish DTAP / BSSAP / SCCP connection */
3356 f_establish_fully(EST_TYPE_PAG_RESP);
3357 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
3358
3359 f_mt_sms(spars);
3360
3361 if (match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
3362 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
3363 }
3364 f_expect_clear();
3365}
3366
3367/* mobile terminated SMS, from SMPP to BSC/BTS/MS */
3368private function f_tc_smpp_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3369 f_init_handler(pars);
3370
3371 /* Perform location update so IMSI is known + registered in MSC/VLR */
3372 f_perform_lu();
3373 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
3374
3375 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01003376 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Weltef640a012018-04-14 17:49:21 +02003377
3378 var SmsParameters spars := valueof(t_SmsPars);
3379 /* TODO: test with more intelligent user data; test different coding schemes */
3380 spars.tp.ud := '00'O;
3381 spars.tp.udl := 1;
3382
3383 /* first test the non-transaction store+forward mode */
3384 f_smpp_mt_sms(spars, false);
3385
3386 /* then test the transaction mode */
3387 f_smpp_mt_sms(spars, true);
3388}
3389testcase TC_smpp_mt_sms() runs on MTC_CT {
3390 var BSC_ConnHdlr vc_conn;
3391 f_init();
3392 vc_conn := f_start_handler(refers(f_tc_smpp_mt_sms), 45);
3393 vc_conn.done;
3394}
3395
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003396/***********************************************************************
3397 * USSD Testing
3398 ***********************************************************************/
3399
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003400private altstep as_unexp_gsup_or_bssap_msg()
3401runs on BSC_ConnHdlr {
3402 [] GSUP.receive {
3403 setverdict(fail, "Unknown/unexpected GSUP received");
3404 self.stop;
3405 }
3406 [] BSSAP.receive {
3407 setverdict(fail, "Unknown/unexpected BSSAP message received");
3408 self.stop;
3409 }
3410}
3411
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003412private function f_expect_gsup_msg(template GSUP_PDU msg,
3413 float T_val := 2.0)
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003414runs on BSC_ConnHdlr return GSUP_PDU {
3415 var GSUP_PDU gsup_msg_complete;
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003416 timer T := T_val;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003417
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003418 T.start;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003419 alt {
3420 [] GSUP.receive(msg) -> value gsup_msg_complete {
3421 setverdict(pass);
3422 }
3423 /* We don't expect anything else */
3424 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003425 [] T.timeout {
3426 setverdict(fail, "Timeout waiting for GSUP message: ", msg);
3427 }
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003428 }
3429
3430 return gsup_msg_complete;
3431}
3432
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003433private function f_expect_mt_dtap_msg(template PDU_ML3_NW_MS msg,
3434 float T_val := 2.0)
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003435runs on BSC_ConnHdlr return PDU_ML3_NW_MS {
3436 var PDU_DTAP_MT bssap_msg_complete;
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003437 timer T := T_val;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003438
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003439 T.start;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003440 alt {
3441 [] BSSAP.receive(tr_PDU_DTAP_MT(msg)) -> value bssap_msg_complete {
3442 setverdict(pass);
3443 }
3444 /* We don't expect anything else */
3445 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003446 [] T.timeout {
3447 setverdict(fail, "Timeout waiting for BSSAP message: ", msg);
3448 }
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003449 }
3450
3451 return bssap_msg_complete.dtap;
3452}
3453
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003454/* LU followed by MO USSD request */
Harald Weltee13cfb22019-04-23 16:52:02 +02003455friend function f_tc_lu_and_mo_ussd_single_request(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003456runs on BSC_ConnHdlr {
3457 f_init_handler(pars);
3458
3459 /* Perform location update */
3460 f_perform_lu();
3461
3462 /* Send CM Service Request for SS/USSD */
3463 f_establish_fully(EST_TYPE_SS_ACT);
3464
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003465 /* We need to inspect GSUP activity */
3466 f_create_gsup_expect(hex2str(g_pars.imsi));
3467
3468 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3469 invoke_id := 5, /* Phone may not start from 0 or 1 */
3470 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3471 ussd_string := "*#100#"
3472 );
3473
3474 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3475 invoke_id := 5, /* InvokeID shall be the same for both REQ and RSP */
3476 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3477 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
3478 )
3479
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003480 /* Compose a new SS/REGISTER message with request */
3481 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
3482 tid := 1, /* We just need a single transaction */
3483 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003484 facility := valueof(facility_req)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003485 );
3486
3487 /* Compose SS/RELEASE_COMPLETE template with expected response */
3488 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
3489 tid := 1, /* Response should arrive within the same transaction */
3490 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003491 facility := valueof(facility_rsp)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003492 );
3493
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003494 /* Compose expected MSC -> HLR message */
3495 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
3496 imsi := g_pars.imsi,
3497 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3498 ss := valueof(facility_req)
3499 );
3500
3501 /* To be used for sending response with correct session ID */
3502 var GSUP_PDU gsup_req_complete;
3503
3504 /* Request own number */
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003505 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003506 /* Expect GSUP message containing the SS payload */
3507 gsup_req_complete := f_expect_gsup_msg(gsup_req);
3508
3509 /* Compose the response from HLR using received session ID */
3510 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
3511 imsi := g_pars.imsi,
3512 sid := gsup_req_complete.ies[1].val.session_id,
3513 state := OSMO_GSUP_SESSION_STATE_END,
3514 ss := valueof(facility_rsp)
3515 );
3516
3517 /* Finally, HLR terminates the session */
3518 GSUP.send(gsup_rsp);
3519 /* Expect RELEASE_COMPLETE message with the response */
3520 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003521
3522 f_expect_clear();
3523}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003524testcase TC_lu_and_mo_ussd_single_request() runs on MTC_CT {
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003525 var BSC_ConnHdlr vc_conn;
3526 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003527 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_single_request), 46);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003528 vc_conn.done;
3529}
3530
Harald Weltee13cfb22019-04-23 16:52:02 +02003531
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003532/* LU followed by MT USSD notification */
Harald Weltee13cfb22019-04-23 16:52:02 +02003533friend function f_tc_lu_and_mt_ussd_notification(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003534runs on BSC_ConnHdlr {
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003535 timer T := 5.0;
3536
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003537 f_init_handler(pars);
3538
3539 /* Perform location update */
3540 f_perform_lu();
3541
Harald Welte6811d102019-04-14 22:23:14 +02003542 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003543
3544 /* We need to inspect GSUP activity */
3545 f_create_gsup_expect(hex2str(g_pars.imsi));
3546
3547 /* Facility IE with network-originated USSD notification */
3548 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3549 op_code := SS_OP_CODE_USS_NOTIFY,
3550 ussd_string := "Mahlzeit!"
3551 );
3552
3553 /* Facility IE with acknowledgment to the USSD notification */
3554 var template OCTN facility_rsp := enc_SS_FacilityInformation(
3555 /* In case of USSD notification, Return Result is empty */
3556 valueof(ts_SS_USSD_FACILITY_RETURN_RESULT_EMPTY())
3557 );
3558
3559 /* Compose a new MT SS/REGISTER message with USSD notification */
3560 var template PDU_ML3_NW_MS ussd_ntf := tr_ML3_MT_SS_REGISTER(
3561 tid := 0, /* FIXME: most likely, it should be 0 */
3562 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3563 facility := valueof(facility_req)
3564 );
3565
3566 /* Compose HLR -> MSC GSUP message */
3567 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3568 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003569 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003570 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3571 ss := valueof(facility_req)
3572 );
3573
3574 /* Send it to MSC and expect Paging Request */
3575 GSUP.send(gsup_req);
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003576 T.start;
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003577 alt {
Harald Weltee13cfb22019-04-23 16:52:02 +02003578 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
3579 setverdict(pass);
3580 }
Harald Welte62113fc2019-05-09 13:04:02 +02003581 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003582 setverdict(pass);
3583 }
3584 /* We don't expect anything else */
3585 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003586 [] T.timeout {
3587 setverdict(fail, "Timeout waiting for Paging Request");
3588 }
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003589 }
3590
3591 /* Send Paging Response and expect USSD notification */
3592 f_establish_fully(EST_TYPE_PAG_RESP);
3593 /* Expect MT REGISTER message with USSD notification */
3594 f_expect_mt_dtap_msg(ussd_ntf);
3595
3596 /* Compose a new MO SS/FACILITY message with empty response */
3597 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
3598 tid := 0, /* FIXME: it shall match the request tid */
3599 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3600 facility := valueof(facility_rsp)
3601 );
3602
3603 /* Compose expected MSC -> HLR GSUP message */
3604 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
3605 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003606 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003607 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3608 ss := valueof(facility_rsp)
3609 );
3610
3611 /* MS sends response to the notification */
3612 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
3613 /* Expect GSUP message containing the SS payload */
3614 f_expect_gsup_msg(gsup_rsp);
3615
3616 /* Compose expected MT SS/RELEASE COMPLETE message */
3617 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
3618 tid := 0, /* FIXME: it shall match the request tid */
3619 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3620 facility := omit
3621 );
3622
3623 /* Compose MSC -> HLR GSUP message */
3624 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
3625 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003626 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003627 state := OSMO_GSUP_SESSION_STATE_END
3628 );
3629
3630 /* Finally, HLR terminates the session */
3631 GSUP.send(gsup_term)
3632 /* Expect MT RELEASE COMPLETE without Facility IE */
3633 f_expect_mt_dtap_msg(ussd_term);
3634
3635 f_expect_clear();
3636}
3637testcase TC_lu_and_mt_ussd_notification() runs on MTC_CT {
3638 var BSC_ConnHdlr vc_conn;
3639 f_init();
3640 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_notification), 47);
3641 vc_conn.done;
3642}
3643
Harald Weltee13cfb22019-04-23 16:52:02 +02003644
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003645/* LU followed by MT call and MO USSD request during this call */
Harald Weltee13cfb22019-04-23 16:52:02 +02003646friend function f_tc_lu_and_mo_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003647runs on BSC_ConnHdlr {
3648 f_init_handler(pars);
3649
3650 /* Call parameters taken from f_tc_lu_and_mt_call */
3651 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003652
3653 /* Perform location update */
3654 f_perform_lu();
3655
3656 /* Establish a MT call */
3657 f_mt_call_establish(cpars);
3658
3659 /* Hold the call for some time */
3660 f_sleep(1.0);
3661
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003662 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3663 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3664 ussd_string := "*#100#"
3665 );
3666
3667 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3668 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3669 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
3670 )
3671
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003672 /* Compose a new SS/REGISTER message with request */
3673 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
3674 tid := 1, /* We just need a single transaction */
3675 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003676 facility := valueof(facility_req)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003677 );
3678
3679 /* Compose SS/RELEASE_COMPLETE template with expected response */
3680 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
3681 tid := 1, /* Response should arrive within the same transaction */
3682 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003683 facility := valueof(facility_rsp)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003684 );
3685
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003686 /* Compose expected MSC -> HLR message */
3687 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
3688 imsi := g_pars.imsi,
3689 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3690 ss := valueof(facility_req)
3691 );
3692
3693 /* To be used for sending response with correct session ID */
3694 var GSUP_PDU gsup_req_complete;
3695
3696 /* Request own number */
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003697 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003698 /* Expect GSUP message containing the SS payload */
3699 gsup_req_complete := f_expect_gsup_msg(gsup_req);
3700
3701 /* Compose the response from HLR using received session ID */
3702 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
3703 imsi := g_pars.imsi,
3704 sid := gsup_req_complete.ies[1].val.session_id,
3705 state := OSMO_GSUP_SESSION_STATE_END,
3706 ss := valueof(facility_rsp)
3707 );
3708
3709 /* Finally, HLR terminates the session */
3710 GSUP.send(gsup_rsp);
3711 /* Expect RELEASE_COMPLETE message with the response */
3712 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003713
3714 /* Hold the call for some time */
3715 f_sleep(1.0);
3716
3717 /* Release the call (does Clear Complete itself) */
3718 f_call_hangup(cpars, true);
3719}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003720testcase TC_lu_and_mo_ussd_during_mt_call() runs on MTC_CT {
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003721 var BSC_ConnHdlr vc_conn;
3722 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003723 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_during_mt_call), 48);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003724 vc_conn.done;
3725}
3726
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003727/* BSSMAP Clear Request in the middle of a call, see OS#3062 */
Harald Weltee13cfb22019-04-23 16:52:02 +02003728friend function f_tc_mo_cc_bssmap_clear(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003729 f_init_handler(pars);
3730 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02003731 cpars.ran_clear_when_alerting := true;
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003732
3733 f_perform_lu();
3734
Neels Hofmeyrde76f052019-02-26 05:02:46 +01003735 var default ccrel := activate(as_optional_cc_rel(cpars));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02003736 f_mo_call_establish(cpars);
3737 f_expect_clear()
Neels Hofmeyrde76f052019-02-26 05:02:46 +01003738 deactivate(ccrel);
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003739
3740 f_sleep(1.0);
3741}
3742testcase TC_mo_cc_bssmap_clear() runs on MTC_CT {
3743 var BSC_ConnHdlr vc_conn;
3744 f_init();
3745
3746 vc_conn := f_start_handler(refers(f_tc_mo_cc_bssmap_clear), 43);
3747 vc_conn.done;
3748}
3749
Harald Weltee13cfb22019-04-23 16:52:02 +02003750
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003751/* LU followed by MT call and MT USSD request during this call */
Harald Weltee13cfb22019-04-23 16:52:02 +02003752friend function f_tc_lu_and_mt_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003753runs on BSC_ConnHdlr {
3754 f_init_handler(pars);
3755
3756 /* Call parameters taken from f_tc_lu_and_mt_call */
3757 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003758
3759 /* Perform location update */
3760 f_perform_lu();
3761
3762 /* Establish a MT call */
3763 f_mt_call_establish(cpars);
3764
3765 /* Hold the call for some time */
3766 f_sleep(1.0);
3767
3768 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3769 op_code := SS_OP_CODE_USS_REQUEST,
3770 ussd_string := "Please type anything..."
3771 );
3772
3773 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3774 op_code := SS_OP_CODE_USS_REQUEST,
3775 ussd_string := "Nope."
3776 )
3777
3778 /* Compose MT SS/REGISTER message with network-originated request */
3779 var template (value) PDU_ML3_NW_MS ussd_req := ts_ML3_MT_SS_REGISTER(
3780 tid := 0, /* FIXME: most likely, it should be 0 */
3781 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3782 facility := valueof(facility_req)
3783 );
3784
3785 /* Compose HLR -> MSC GSUP message */
3786 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3787 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003788 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003789 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3790 ss := valueof(facility_req)
3791 );
3792
3793 /* Send it to MSC */
3794 GSUP.send(gsup_req);
3795 /* Expect MT REGISTER message with USSD request */
3796 f_expect_mt_dtap_msg(ussd_req);
3797
3798 /* Compose a new MO SS/FACILITY message with response */
3799 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
3800 tid := 0, /* FIXME: it shall match the request tid */
3801 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3802 facility := valueof(facility_rsp)
3803 );
3804
3805 /* Compose expected MSC -> HLR GSUP message */
3806 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
3807 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003808 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003809 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3810 ss := valueof(facility_rsp)
3811 );
3812
3813 /* MS sends response */
3814 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
3815 f_expect_gsup_msg(gsup_rsp);
3816
3817 /* Compose expected MT SS/RELEASE COMPLETE message */
3818 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
3819 tid := 0, /* FIXME: it shall match the request tid */
3820 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3821 facility := omit
3822 );
3823
3824 /* Compose MSC -> HLR GSUP message */
3825 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
3826 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003827 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003828 state := OSMO_GSUP_SESSION_STATE_END
3829 );
3830
3831 /* Finally, HLR terminates the session */
3832 GSUP.send(gsup_term);
3833 /* Expect MT RELEASE COMPLETE without Facility IE */
3834 f_expect_mt_dtap_msg(ussd_term);
3835
3836 /* Hold the call for some time */
3837 f_sleep(1.0);
3838
3839 /* Release the call (does Clear Complete itself) */
3840 f_call_hangup(cpars, true);
3841}
3842testcase TC_lu_and_mt_ussd_during_mt_call() runs on MTC_CT {
3843 var BSC_ConnHdlr vc_conn;
3844 f_init();
3845 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_during_mt_call), 49);
3846 vc_conn.done;
3847}
3848
Harald Weltee13cfb22019-04-23 16:52:02 +02003849
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07003850/* LU followed by MO USSD request and MO Release during transaction */
Harald Weltee13cfb22019-04-23 16:52:02 +02003851friend function f_tc_lu_and_mo_ussd_mo_release(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07003852runs on BSC_ConnHdlr {
3853 f_init_handler(pars);
3854
3855 /* Perform location update */
3856 f_perform_lu();
3857
3858 /* Send CM Service Request for SS/USSD */
3859 f_establish_fully(EST_TYPE_SS_ACT);
3860
3861 /* We need to inspect GSUP activity */
3862 f_create_gsup_expect(hex2str(g_pars.imsi));
3863
3864 var template OCTN facility_ms_req := f_USSD_FACILITY_IE_INVOKE(
3865 invoke_id := 1, /* Initial request */
3866 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3867 ussd_string := "*6766*266#"
3868 );
3869
3870 var template OCTN facility_net_req := f_USSD_FACILITY_IE_INVOKE(
3871 invoke_id := 2, /* Counter request */
3872 op_code := SS_OP_CODE_USS_REQUEST,
3873 ussd_string := "Password?!?"
3874 )
3875
3876 /* Compose MO SS/REGISTER message with request */
3877 var template (value) PDU_ML3_MS_NW ussd_ms_req := ts_ML3_MO_SS_REGISTER(
3878 tid := 1, /* We just need a single transaction */
3879 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3880 facility := valueof(facility_ms_req)
3881 );
3882
3883 /* Compose expected MSC -> HLR message */
3884 var template GSUP_PDU gsup_ms_req := tr_GSUP_PROC_SS_REQ(
3885 imsi := g_pars.imsi,
3886 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3887 ss := valueof(facility_ms_req)
3888 );
3889
3890 /* To be used for sending response with correct session ID */
3891 var GSUP_PDU gsup_ms_req_complete;
3892
3893 /* Initiate a new transaction */
3894 BSSAP.send(ts_PDU_DTAP_MO(ussd_ms_req));
3895 /* Expect GSUP request with original Facility IE */
3896 gsup_ms_req_complete := f_expect_gsup_msg(gsup_ms_req);
3897
3898 /* Compose the response from HLR using received session ID */
3899 var template (value) GSUP_PDU gsup_net_req := ts_GSUP_PROC_SS_REQ(
3900 imsi := g_pars.imsi,
3901 sid := gsup_ms_req_complete.ies[1].val.session_id,
3902 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3903 ss := valueof(facility_net_req)
3904 );
3905
3906 /* Compose expected MT SS/FACILITY template with counter request */
3907 var template PDU_ML3_NW_MS ussd_net_req := tr_ML3_MT_SS_FACILITY(
3908 tid := 1, /* Response should arrive within the same transaction */
3909 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3910 facility := valueof(facility_net_req)
3911 );
3912
3913 /* Send response over GSUP */
3914 GSUP.send(gsup_net_req);
3915 /* Expect MT SS/FACILITY message with counter request */
3916 f_expect_mt_dtap_msg(ussd_net_req);
3917
3918 /* Compose MO SS/RELEASE COMPLETE */
3919 var template (value) PDU_ML3_MS_NW ussd_abort := ts_ML3_MO_SS_RELEASE_COMPLETE(
3920 tid := 1, /* Response should arrive within the same transaction */
3921 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3922 facility := omit
3923 /* TODO: cause? */
3924 );
3925
3926 /* Compose expected HLR -> MSC abort message */
3927 var template GSUP_PDU gsup_abort := tr_GSUP_PROC_SS_REQ(
3928 imsi := g_pars.imsi,
3929 sid := gsup_ms_req_complete.ies[1].val.session_id,
3930 state := OSMO_GSUP_SESSION_STATE_END
3931 );
3932
3933 /* Abort transaction */
3934 BSSAP.send(ts_PDU_DTAP_MO(ussd_abort));
3935 /* Expect GSUP message indicating abort */
3936 f_expect_gsup_msg(gsup_abort);
3937
3938 f_expect_clear();
3939}
3940testcase TC_lu_and_mo_ussd_mo_release() runs on MTC_CT {
3941 var BSC_ConnHdlr vc_conn;
3942 f_init();
3943 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_mo_release), 50);
3944 vc_conn.done;
3945}
3946
Harald Weltee13cfb22019-04-23 16:52:02 +02003947
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003948/* LU followed by MO USSD request and MT Release due to timeout */
Harald Weltee13cfb22019-04-23 16:52:02 +02003949friend function f_tc_lu_and_ss_session_timeout(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003950runs on BSC_ConnHdlr {
3951 f_init_handler(pars);
3952
3953 /* Perform location update */
3954 f_perform_lu();
3955
3956 /* Send CM Service Request for SS/USSD */
3957 f_establish_fully(EST_TYPE_SS_ACT);
3958
3959 /* We need to inspect GSUP activity */
3960 f_create_gsup_expect(hex2str(g_pars.imsi));
3961
3962 var template OCTN facility_ms_req := f_USSD_FACILITY_IE_INVOKE(
3963 invoke_id := 1,
3964 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3965 ussd_string := "#release_me");
3966
3967 /* Compose MO SS/REGISTER message with request */
3968 var template (value) PDU_ML3_MS_NW ussd_ms_req := ts_ML3_MO_SS_REGISTER(
3969 tid := 1, /* An arbitrary transaction identifier */
3970 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3971 facility := valueof(facility_ms_req));
3972
3973 /* Compose expected MSC -> HLR message */
3974 var template GSUP_PDU gsup_ms_req := tr_GSUP_PROC_SS_REQ(
3975 imsi := g_pars.imsi,
3976 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3977 ss := valueof(facility_ms_req));
3978
3979 /* To be used for sending response with correct session ID */
3980 var GSUP_PDU gsup_ms_req_complete;
3981
3982 /* Initiate a new SS transaction */
3983 BSSAP.send(ts_PDU_DTAP_MO(ussd_ms_req));
3984 /* Expect GSUP request with original Facility IE */
3985 gsup_ms_req_complete := f_expect_gsup_msg(gsup_ms_req);
3986
3987 /* Don't respond, wait for timeout */
3988 f_sleep(3.0);
3989
3990 var template PDU_ML3_NW_MS dtap_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
3991 tid := 1, /* Should match the request's tid */
3992 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3993 cause := *, /* TODO: expect some specific value */
3994 facility := omit);
3995
3996 var template GSUP_PDU gsup_rel := tr_GSUP_PROC_SS_ERR(
3997 imsi := g_pars.imsi,
3998 sid := gsup_ms_req_complete.ies[1].val.session_id,
3999 state := OSMO_GSUP_SESSION_STATE_END,
4000 cause := ?); /* TODO: expect some specific value */
4001
4002 /* Expect release on both interfaces */
4003 interleave {
4004 [] BSSAP.receive(tr_PDU_DTAP_MT(dtap_rel)) { };
4005 [] GSUP.receive(gsup_rel) { };
4006 }
4007
4008 f_expect_clear();
4009 setverdict(pass);
4010}
4011testcase TC_lu_and_ss_session_timeout() runs on MTC_CT {
4012 var BSC_ConnHdlr vc_conn;
4013 f_init();
Vadim Yanitskiy36d28dd2018-12-03 02:45:45 +07004014 f_vty_config(MSCVTY, "msc", "ncss guard-timeout 3");
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07004015 vc_conn := f_start_handler(refers(f_tc_lu_and_ss_session_timeout), 51);
4016 vc_conn.done;
Vadim Yanitskiy36d28dd2018-12-03 02:45:45 +07004017 f_vty_config(MSCVTY, "msc", "ncss guard-timeout 0");
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07004018}
4019
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07004020/* MT (network-originated) USSD for unknown subscriber */
4021friend function f_tc_mt_ussd_for_unknown_subscr(charstring id, BSC_ConnHdlrPars pars)
4022runs on BSC_ConnHdlr {
4023 var hexstring imsi := '000000000000000'H; /* Some unknown IMSI */
4024 var OCT4 sid := '20000222'O;
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07004025
4026 f_init_handler(pars);
4027 f_ran_register_imsi(imsi, 'FFFFFFFF'O);
4028 f_create_gsup_expect(hex2str(imsi));
4029
4030 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
4031 imsi := imsi,
4032 sid := sid,
4033 state := OSMO_GSUP_SESSION_STATE_BEGIN,
4034 ss := f_rnd_octstring(23)
4035 );
4036
4037 /* Error with cause GMM_CAUSE_IMSI_UNKNOWN */
4038 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
4039 imsi := imsi,
4040 sid := sid,
4041 state := OSMO_GSUP_SESSION_STATE_END,
4042 cause := 2 /* FIXME: introduce an enumerated type! */
4043 );
4044
4045 /* Initiate a MT USSD notification */
4046 GSUP.send(gsup_req);
4047
4048 /* Expect GSUP PROC_SS_ERROR message */
Vadim Yanitskiy851798c2019-06-15 14:22:28 +07004049 f_expect_gsup_msg(gsup_rsp);
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07004050}
4051testcase TC_mt_ussd_for_unknown_subscr() runs on MTC_CT {
4052 var BSC_ConnHdlr vc_conn;
4053 f_init();
4054 vc_conn := f_start_handler(refers(f_tc_mt_ussd_for_unknown_subscr), 0);
4055 vc_conn.done;
4056}
4057
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07004058/* MO (mobile-originated) SS/USSD for unknown transaction */
4059friend function f_tc_mo_ussd_for_unknown_trans(charstring id, BSC_ConnHdlrPars pars)
4060runs on BSC_ConnHdlr {
4061 f_init_handler(pars);
4062
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01004063 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07004064 f_create_gsup_expect(hex2str(g_pars.imsi));
4065
4066 /* Perform location update */
4067 f_perform_lu();
4068
4069 /* Send CM Service Request for SS/USSD */
4070 f_establish_fully(EST_TYPE_SS_ACT);
4071
4072 /* GSM 04.80 FACILITY message for a non-existing transaction */
4073 var template (value) PDU_ML3_MS_NW mo_ss_fac := ts_ML3_MO_SS_FACILITY(
4074 tid := 1, /* An arbitrary transaction identifier */
4075 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
4076 facility := f_rnd_octstring(23) /* We don't care about the Facility IE */
4077 );
4078
4079 /* GSM 04.80 RELEASE COMPLETE message for a non-existing transaction */
4080 var template (value) PDU_ML3_MS_NW mo_ss_rel := ts_ML3_MO_SS_RELEASE_COMPLETE(
4081 tid := 1, /* An arbitrary transaction identifier */
4082 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
4083 facility := f_rnd_octstring(23) /* We don't care about the Facility IE */
4084 );
4085
4086 /* Expected response from the network */
4087 var template PDU_ML3_NW_MS mt_ss_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
4088 tid := 1, /* Same as in the FACILITY message */
4089 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
4090 facility := omit
4091 );
4092
4093 /* Send GSM 04.80 FACILITY for non-existing transaction */
4094 BSSAP.send(ts_PDU_DTAP_MO(mo_ss_fac));
4095
4096 /* Expect GSM 04.80 RELEASE COMPLETE message */
4097 f_expect_mt_dtap_msg(mt_ss_rel);
4098 f_expect_clear();
4099
4100 /* Send another CM Service Request for SS/USSD */
4101 f_establish_fully(EST_TYPE_SS_ACT);
4102
4103 /* Send GSM 04.80 RELEASE COMPLETE for non-existing transaction */
4104 BSSAP.send(ts_PDU_DTAP_MO(mo_ss_rel));
4105
4106 /* Expect GSM 04.80 RELEASE COMPLETE message */
4107 f_expect_mt_dtap_msg(mt_ss_rel);
4108 f_expect_clear();
4109}
4110testcase TC_mo_ussd_for_unknown_trans() runs on MTC_CT {
4111 var BSC_ConnHdlr vc_conn;
4112 f_init();
4113 vc_conn := f_start_handler(refers(f_tc_mo_ussd_for_unknown_trans), 111);
4114 vc_conn.done;
4115}
4116
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07004117/* MT (network-originated) USSD for unknown session */
4118friend function f_tc_proc_ss_for_unknown_session(charstring id, BSC_ConnHdlrPars pars)
4119runs on BSC_ConnHdlr {
4120 var OCT4 sid := '20000333'O;
4121
4122 f_init_handler(pars);
4123
4124 /* Perform location update */
4125 f_perform_lu();
4126
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01004127 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07004128 f_create_gsup_expect(hex2str(g_pars.imsi));
4129
4130 /* Request referencing a non-existing SS session */
4131 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
4132 imsi := g_pars.imsi,
4133 sid := sid,
4134 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
4135 ss := f_rnd_octstring(23)
4136 );
4137
4138 /* Error with some cause value */
4139 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
4140 imsi := g_pars.imsi,
4141 sid := sid,
4142 state := OSMO_GSUP_SESSION_STATE_END,
4143 cause := ? /* FIXME: introduce an enumerated type! */
4144 );
4145
4146 /* Initiate a MT USSD notification */
4147 GSUP.send(gsup_req);
4148
4149 /* Expect GSUP PROC_SS_ERROR message */
4150 f_expect_gsup_msg(gsup_rsp);
4151}
4152testcase TC_proc_ss_for_unknown_session() runs on MTC_CT {
4153 var BSC_ConnHdlr vc_conn;
4154 f_init();
4155 vc_conn := f_start_handler(refers(f_tc_proc_ss_for_unknown_session), 110);
4156 vc_conn.done;
4157}
4158
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07004159/* MT (network-originated) USSD and no response to Paging Request */
4160friend function f_tc_proc_ss_paging_fail(charstring id, BSC_ConnHdlrPars pars)
4161runs on BSC_ConnHdlr {
4162 timer TP := 2.0; /* Paging timer */
4163
4164 f_init_handler(pars);
4165
4166 /* Perform location update */
4167 f_perform_lu();
4168
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01004169 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07004170 f_create_gsup_expect(hex2str(g_pars.imsi));
4171
4172 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
4173 imsi := g_pars.imsi,
4174 sid := '20000444'O,
4175 state := OSMO_GSUP_SESSION_STATE_BEGIN,
4176 ss := f_rnd_octstring(23)
4177 );
4178
4179 /* Error with some cause value */
4180 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
4181 imsi := g_pars.imsi,
4182 sid := '20000444'O,
4183 state := OSMO_GSUP_SESSION_STATE_END,
4184 cause := ? /* FIXME: introduce an enumerated type! */
4185 );
4186
4187 /* Initiate a MT USSD notification */
4188 GSUP.send(gsup_req);
4189
4190 /* Send it to MSC and expect Paging Request */
4191 TP.start;
4192 alt {
4193 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
4194 setverdict(pass);
4195 }
4196 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
4197 setverdict(pass);
4198 }
4199 /* We don't expect anything else */
4200 [] as_unexp_gsup_or_bssap_msg();
4201 [] TP.timeout {
4202 setverdict(fail, "Timeout waiting for Paging Request");
4203 }
4204 }
4205
Vadim Yanitskiyd24b5252019-10-02 00:04:51 +07004206 /* Wait up to 20 seconds for GSUP PROC_SS_ERROR message.
4207 * OsmoMSC waits for Paging Response 10 seconds by default. */
4208 f_expect_gsup_msg(gsup_rsp, T_val := 20.0);
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07004209}
4210testcase TC_proc_ss_paging_fail() runs on MTC_CT {
4211 var BSC_ConnHdlr vc_conn;
4212 f_init();
4213 vc_conn := f_start_handler(refers(f_tc_proc_ss_paging_fail), 101);
4214 vc_conn.done;
4215}
4216
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07004217/* MT (network-originated) USSD followed by immediate abort */
4218friend function f_tc_proc_ss_abort(charstring id, BSC_ConnHdlrPars pars)
4219runs on BSC_ConnHdlr {
4220 var octetstring facility := f_rnd_octstring(23);
4221 var OCT4 sid := '20000555'O;
4222 timer TP := 2.0;
4223
4224 f_init_handler(pars);
4225
4226 /* Perform location update */
4227 f_perform_lu();
4228
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01004229 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07004230 f_create_gsup_expect(hex2str(g_pars.imsi));
4231
4232 /* PROC_SS_REQ initiates a mobile-originated SS/USSD session */
4233 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
4234 imsi := g_pars.imsi, sid := sid,
4235 state := OSMO_GSUP_SESSION_STATE_BEGIN,
4236 ss := facility
4237 );
4238
4239 /* On the MS side, we expect GSM 04.80 REGISTER message */
4240 var template PDU_ML3_NW_MS dtap_reg := tr_ML3_MT_SS_REGISTER(
4241 tid := 0, /* Most likely, it should be 0 */
4242 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
4243 facility := facility
4244 );
4245
4246 /* PROC_SS_ERR with SESSION_STATE_END terminates the SS/USSD session */
4247 var template (value) GSUP_PDU gsup_abort := ts_GSUP_PROC_SS_ERR(
4248 imsi := g_pars.imsi, sid := sid,
4249 state := OSMO_GSUP_SESSION_STATE_END,
4250 cause := 0 /* FIXME: introduce an enumerated type! */
4251 );
4252
4253 /* On the MS side, we expect GSM 04.80 REGISTER message */
4254 var template PDU_ML3_NW_MS dtap_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
4255 tid := 0, /* Most likely, it should be 0 */
4256 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
4257 cause := *, /* FIXME: expect some specific cause value */
4258 facility := omit
4259 );
4260
4261 /* Initiate a MT USSD with random payload */
4262 GSUP.send(gsup_req);
4263
4264 /* Expect Paging Request */
4265 TP.start;
4266 alt {
4267 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
4268 setverdict(pass);
4269 }
4270 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
4271 setverdict(pass);
4272 }
4273 /* We don't expect anything else */
4274 [] as_unexp_gsup_or_bssap_msg();
4275 [] TP.timeout {
4276 setverdict(fail, "Timeout waiting for Paging Request");
4277 }
4278 }
4279
4280 /* Send Paging Response and establish connection */
4281 f_establish_fully(EST_TYPE_PAG_RESP);
4282 /* Expect MT REGISTER message with random facility */
4283 f_expect_mt_dtap_msg(dtap_reg);
4284
4285 /* HLR/EUSE decides to abort the session even
4286 * before getting any response from the MS */
4287 /* Initiate a MT USSD with random payload */
4288 GSUP.send(gsup_abort);
4289
4290 /* Expect RELEASE COMPLETE on ths MS side */
4291 f_expect_mt_dtap_msg(dtap_rel);
4292
4293 f_expect_clear();
4294}
4295testcase TC_proc_ss_abort() runs on MTC_CT {
4296 var BSC_ConnHdlr vc_conn;
4297 f_init();
4298 vc_conn := f_start_handler(refers(f_tc_proc_ss_abort), 102);
4299 vc_conn.done;
4300}
4301
Harald Weltee13cfb22019-04-23 16:52:02 +02004302
Vadim Yanitskiy1c9754d2020-01-07 21:56:55 +01004303/* Verify multiple concurrent MO SS/USSD transactions
4304 * (one subscriber - one transaction) */
4305testcase TC_multi_lu_and_mo_ussd() runs on MTC_CT {
4306 var BSC_ConnHdlr vc_conn[16];
4307 var integer i;
4308
4309 f_init();
4310
4311 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
4312 vc_conn[i] := f_start_handler(refers(f_tc_lu_and_mo_ussd_single_request), 210 + i);
4313 }
4314
4315 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
4316 vc_conn[i].done;
4317 }
4318}
4319
4320/* Verify multiple concurrent MT SS/USSD transactions
4321 * (one subscriber - one transaction) */
4322testcase TC_multi_lu_and_mt_ussd() runs on MTC_CT {
4323 var BSC_ConnHdlr vc_conn[16];
4324 var integer i;
4325 var OCT4 sid;
4326
4327 f_init();
4328
4329 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
4330 sid := '200001'O & int2oct(i, 1); /* All transactions must use different session ID */
4331 vc_conn[i] := f_start_handler_with_pars(refers(f_tc_lu_and_mt_ussd_notification),
4332 f_init_pars(226 + i, gsup_sid := sid));
4333 }
4334
4335 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
4336 vc_conn[i].done;
4337 }
4338}
4339
4340
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004341/* A5/1 only permitted on network side; attempt an invalid CIPHER MODE COMPLETE with A5/3 which MSC should reject. */
4342private function f_tc_cipher_complete_with_invalid_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4343 pars.net.expect_auth := true;
4344 pars.net.expect_ciph := true;
4345 pars.net.kc_support := '02'O; /* A5/1 only */
4346 f_init_handler(pars);
4347
4348 g_pars.vec := f_gen_auth_vec_2g();
4349
4350 /* Can't use f_perform_lu() directly. Code below is based on it. */
4351
4352 /* tell GSUP dispatcher to send this IMSI to us */
4353 f_create_gsup_expect(hex2str(g_pars.imsi));
4354
4355 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
4356 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
Harald Weltedceacc72019-04-21 20:58:35 +02004357 f_cl3_or_initial_ue(l3_lu);
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004358
4359 f_mm_auth();
4360
4361 var OCT1 a5_net := f_alg_mask_from_cm(g_pars.cm2);
4362 var OCT1 a5_intersect := g_pars.net.kc_support and4b a5_net;
4363 alt {
4364 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(a5_intersect, g_pars.vec.kc)) {
4365 BSSAP.send(ts_BSSMAP_CipherModeCompl(int2oct(4 /* "accept" A5/3 */, 1)));
4366 }
4367 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?, g_pars.vec.kc)) {
4368 setverdict(fail, "Wrong ciphering algorithm mask in CiphModCmd");
4369 mtc.stop;
4370 }
4371 [] BSSAP.receive {
4372 setverdict(fail, "Unknown/unexpected BSSAP received");
4373 mtc.stop;
4374 }
4375 }
Harald Welte79f1e452020-08-18 22:55:02 +02004376 f_expect_common_id();
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004377
4378 /* Expect LU reject from MSC. */
4379 alt {
4380 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
4381 setverdict(pass);
4382 }
4383 [] BSSAP.receive {
4384 setverdict(fail, "Unknown/unexpected BSSAP received");
4385 mtc.stop;
4386 }
4387 }
Stefan Sperlingc620b352018-12-18 17:23:36 +01004388 f_expect_clear();
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004389}
4390
4391testcase TC_cipher_complete_with_invalid_cipher() runs on MTC_CT {
4392 var BSC_ConnHdlr vc_conn;
4393 f_init();
4394 f_vty_config(MSCVTY, "network", "encryption a5 1");
4395
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02004396 vc_conn := f_start_handler(refers(f_tc_cipher_complete_with_invalid_cipher), 52, verify_cell_id := false);
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004397 vc_conn.done;
4398}
4399
Harald Welteb2284bd2019-05-10 11:30:43 +02004400/* Location Update with invalid (non-matching) MCC/MNC reported on BSSMAP level from BSC */
4401friend function f_tc_lu_with_invalid_mcc_mnc(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4402 f_init_handler(pars);
4403
4404 /* tell GSUP dispatcher to send this IMSI to us */
4405 f_create_gsup_expect(hex2str(g_pars.imsi));
4406
4407 /* modify the cell ID which will be used to construct the COMPLELTE L3 or InitialUE */
4408 g_pars.cell_id := valueof(ts_CellId_CGI('333'H, '22'H, 23, 42));
4409
4410 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
4411 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
4412 f_cl3_or_initial_ue(l3_lu);
Harald Welte79f1e452020-08-18 22:55:02 +02004413 f_expect_common_id();
Harald Welteb2284bd2019-05-10 11:30:43 +02004414
4415 /* Expect LU reject from MSC. */
4416 alt {
4417 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
4418 setverdict(pass);
4419 }
4420 [] BSSAP.receive {
4421 setverdict(fail, "Unknown/unexpected BSSAP received");
4422 mtc.stop;
4423 }
4424 }
Eric Wild85cc1612022-03-30 01:44:29 +02004425 f_expect_clear(verify_vlr_cell_id:=false);
Harald Welteb2284bd2019-05-10 11:30:43 +02004426}
4427testcase TC_lu_with_invalid_mcc_mnc() runs on MTC_CT {
4428 var BSC_ConnHdlr vc_conn;
4429 f_init();
4430 vc_conn := f_start_handler(refers(f_tc_lu_with_invalid_mcc_mnc), 54);
4431 vc_conn.done;
4432}
4433
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01004434private function f_tc_cipher_complete_without_alg(charstring id, BSC_ConnHdlrPars pars, octetstring kc_support) runs on BSC_ConnHdlr {
4435 pars.net.expect_auth := true;
4436 pars.net.expect_ciph := true;
4437 pars.net.kc_support := kc_support;
4438 f_init_handler(pars);
4439
4440 g_pars.vec := f_gen_auth_vec_2g();
4441
4442 /* Can't use f_perform_lu() directly. Code below is based on it. */
4443
4444 /* tell GSUP dispatcher to send this IMSI to us */
4445 f_create_gsup_expect(hex2str(g_pars.imsi));
4446
4447 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
4448 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
4449 f_cl3_or_initial_ue(l3_lu);
4450
4451 f_mm_auth();
4452
4453 var OCT1 a5_net := f_alg_mask_from_cm(g_pars.cm2);
4454 var OCT1 a5_intersect := g_pars.net.kc_support and4b a5_net;
4455 alt {
4456 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(a5_intersect, g_pars.vec.kc)) {
4457 BSSAP.send(ts_BSSMAP_CipherModeComplAlg(omit));
4458 }
4459 [] BSSAP.receive(tr_BSSMAP_ClassmarkReq) {
4460 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
4461 repeat;
4462 }
4463 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?, g_pars.vec.kc)) {
4464 setverdict(fail, "Wrong ciphering algorithm mask in CiphModCmd");
4465 mtc.stop;
4466 }
4467 [] BSSAP.receive {
4468 setverdict(fail, "Unknown/unexpected BSSAP received");
4469 mtc.stop;
4470 }
4471 }
Harald Welte79f1e452020-08-18 22:55:02 +02004472 f_expect_common_id();
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01004473
4474 /* TODO: Verify MSC is using the best cipher available! How? */
4475
4476 f_msc_lu_hlr();
4477 f_accept_reject_lu();
4478 f_expect_clear();
4479 setverdict(pass);
4480}
4481
4482/* A5/1 only permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
4483private function f_tc_cipher_complete_1_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4484 f_tc_cipher_complete_without_alg(id, pars, '02'O /* A5/1 only */);
4485}
4486
4487/* A5/3 only permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
4488private function f_tc_cipher_complete_3_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4489 f_tc_cipher_complete_without_alg(id, pars, '08'O /* A5/3 only */);
4490}
4491
4492/* A5/1 + A5/3 permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
4493private function f_tc_cipher_complete_13_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4494 f_tc_cipher_complete_without_alg(id, pars, '0A'O /* A5/1 and A5/3 enabled */);
4495}
4496
4497testcase TC_cipher_complete_1_without_cipher() runs on MTC_CT {
4498 var BSC_ConnHdlr vc_conn;
4499 f_init();
4500 f_vty_config(MSCVTY, "network", "encryption a5 1");
4501
4502 vc_conn := f_start_handler(refers(f_tc_cipher_complete_1_without_cipher), 53);
4503 vc_conn.done;
4504}
4505
4506testcase TC_cipher_complete_3_without_cipher() runs on MTC_CT {
4507 var BSC_ConnHdlr vc_conn;
4508 f_init();
4509 f_vty_config(MSCVTY, "network", "encryption a5 3");
4510
4511 vc_conn := f_start_handler(refers(f_tc_cipher_complete_3_without_cipher), 54);
4512 vc_conn.done;
4513}
4514
4515testcase TC_cipher_complete_13_without_cipher() runs on MTC_CT {
4516 var BSC_ConnHdlr vc_conn;
4517 f_init();
4518 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
4519
4520 vc_conn := f_start_handler(refers(f_tc_cipher_complete_13_without_cipher), 55);
4521 vc_conn.done;
4522}
Harald Welteb2284bd2019-05-10 11:30:43 +02004523
Harald Weltef640a012018-04-14 17:49:21 +02004524/* TODO (SMS):
4525 * different user data lengths
4526 * SMPP transaction mode with unsuccessful delivery
4527 * queued MT-SMS with no paging response + later delivery
4528 * different data coding schemes
4529 * multi-part SMS
4530 * user-data headers
4531 * TP-PID for SMS to SIM
4532 * behavior if SMS memory is full + RP-SMMA
4533 * delivery reports
4534 * SMPP osmocom extensions
4535 * more-messages-to-send
4536 * SMS during ongoing call (SACCH/SAPI3)
4537 */
4538
4539/* TODO (General):
Harald Welteba7b6d92018-01-23 21:32:34 +01004540 * continue to send repeated MO signalling messages to keep channel open: does MSC tmeout?
4541 * malformed messages (missing IE, invalid message type): properly rejected?
4542 * MT call while LU or is ongoing: Do we use existing lchan or page while lchan active?
4543 * 3G/2G auth permutations
4544 * encryption algorithms vs. classmark vs. vty config
Harald Welteba7b6d92018-01-23 21:32:34 +01004545 * send new transaction after/during clear (like SMS, ...)
Harald Welte45164da2018-01-24 12:51:27 +01004546 * too long L3 INFO in DTAP
4547 * too long / padded BSSAP
4548 * too long / short TLV values
Harald Welteba7b6d92018-01-23 21:32:34 +01004549 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01004550
Harald Weltee13cfb22019-04-23 16:52:02 +02004551/***********************************************************************
4552 * SGsAP Testing
4553 ***********************************************************************/
4554
Philipp Maier948747b2019-04-02 15:22:33 +02004555/* Check if a subscriber exists in the VLR */
4556private function f_ctrl_subscr_in_vlr(charstring imsi_or_msisdn) runs on BSC_ConnHdlr return boolean {
4557
4558 var CtrlValue active_subsribers;
4559 var integer rc;
4560 active_subsribers := f_ctrl_get(IPA_CTRL, "subscriber-list-active-v1");
4561
4562 rc := f_strstr(active_subsribers, imsi_or_msisdn);
4563 if (rc < 0) {
4564 return false;
4565 }
4566
4567 return true;
4568}
4569
Pau Espin Pedrolcefe9da2021-07-02 18:38:27 +02004570/* Perform a Location Update at the A-Interface and run some checks to confirm
Harald Welte4263c522018-12-06 11:56:27 +01004571 * that everything is back to normal. */
4572private function f_sgsap_bssmap_screening() runs on BSC_ConnHdlr {
4573 var SmsParameters spars := valueof(t_SmsPars);
4574
Pau Espin Pedrol7593a8a2021-07-02 18:55:16 +02004575 /* From now on, since we initiated LU from A-Interface, we expect no
4576 * LastEutranPLMNId on Common Id, since the SGs interface should be gone
4577 */
4578 g_pars.common_id_last_eutran_plmn := omit;
4579
Harald Welte4263c522018-12-06 11:56:27 +01004580 /* Perform a location update, the SGs association is expected to fall
4581 * back to NULL */
4582 f_perform_lu();
4583 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4584
4585 /* Trigger a paging request and expect the paging on BSSMAP, this is
4586 * to make sure that pagings are sent throught the A-Interface again
4587 * and not throught the SGs interface.*/
Harald Welte6811d102019-04-14 22:23:14 +02004588 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Welte4263c522018-12-06 11:56:27 +01004589 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4590
4591 alt {
Harald Weltee13cfb22019-04-23 16:52:02 +02004592 [g_pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)); {
4593 setverdict(pass);
4594 }
Harald Welte62113fc2019-05-09 13:04:02 +02004595 [not g_pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
Harald Welte4263c522018-12-06 11:56:27 +01004596 setverdict(pass);
4597 }
4598 [] SGsAP.receive {
4599 setverdict(fail, "Received unexpected message on SGs");
4600 }
4601 }
4602
4603 /* Send an SMS to make sure that also payload messages are routed
4604 * throught the A-Interface again */
4605 f_establish_fully(EST_TYPE_MO_SMS);
4606 f_mo_sms(spars);
4607 f_expect_clear();
4608}
4609
4610private function f_tc_sgsap_reset(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4611 var charstring vlr_name;
4612 f_init_handler(pars);
4613
4614 vlr_name := f_sgsap_reset_mme(mp_mme_name);
4615 log("VLR name: ", vlr_name);
4616 setverdict(pass);
Neels Hofmeyrc0b520d2019-03-06 15:35:50 +01004617 f_sleep(1.0);
Harald Welte4263c522018-12-06 11:56:27 +01004618}
4619
4620testcase TC_sgsap_reset() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004621 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004622 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004623 f_init(1, true);
4624 pars := f_init_pars(11810, true);
4625 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_reset), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004626 vc_conn.done;
4627}
4628
4629/* like f_mm_auth() but for SGs */
4630function f_mm_auth_sgs() runs on BSC_ConnHdlr {
4631 if (g_pars.net.expect_auth) {
4632 g_pars.vec := f_gen_auth_vec_3g();
4633 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G3G(g_pars.vec.rand,
4634 g_pars.vec.sres,
4635 g_pars.vec.kc,
4636 g_pars.vec.ik,
4637 g_pars.vec.ck,
4638 g_pars.vec.autn,
4639 g_pars.vec.res));
4640 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
4641 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
4642 SGsAP.receive(tr_ML3_MT_MM_AUTH_REQ_3G(g_pars.vec.rand, g_pars.vec.autn));
4643 SGsAP.send(ts_ML3_MT_MM_AUTH_RESP_3G(g_pars.vec.sres, g_pars.vec.res));
4644 }
4645}
4646
4647/* like f_perform_lu(), but on SGs rather than BSSAP */
4648function f_sgs_perform_lu() runs on BSC_ConnHdlr {
4649 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4650 var PDU_SGsAP lur;
4651 var PDU_SGsAP lua;
4652 var PDU_SGsAP mm_info;
4653 var octetstring mm_info_dtap;
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004654 var GsmMcc mcc;
4655 var GsmMnc mnc;
4656 var template (omit) TrackingAreaIdentityValue tai := omit;
Harald Welte4263c522018-12-06 11:56:27 +01004657
4658 /* tell GSUP dispatcher to send this IMSI to us */
4659 f_create_gsup_expect(hex2str(g_pars.imsi));
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004660 if (g_pars.common_id_last_eutran_plmn != omit) {
4661 f_dec_mcc_mnc(g_pars.common_id_last_eutran_plmn, mcc, mnc);
4662 tai := ts_SGsAP_TAI(mcc, mnc, 555);
4663 }
Harald Welte4263c522018-12-06 11:56:27 +01004664 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
Pau Espin Pedrol3768a6f2021-04-28 14:24:23 +02004665 ts_SGsAP_LAI('901'H, '70'H, 2342),
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004666 tai));
Harald Welte4263c522018-12-06 11:56:27 +01004667 /* Old LAI, if MS sends it */
4668 /* TMSI status, if MS has no valid TMSI */
4669 /* IMEISV, if it supports "automatic device detection" */
4670 /* TAI, if available in MME */
4671 /* E-CGI, if available in MME */
4672 SGsAP.send(lur);
4673
4674 /* FIXME: is this really done over SGs? The Ue is already authenticated
4675 * via the MME ... */
4676 f_mm_auth_sgs();
4677
4678 /* Expect MSC to perform LU with HLR */
4679 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4680 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
4681 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
4682 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
4683
4684 alt {
4685 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) -> value lua {
4686 if (isvalue(lua.sGsAP_LOCATION_UPDATE_ACCEPT.newTMSIorIMSI.iD.iD.tmsi_ptmsi.octets)) {
4687 g_pars.tmsi :=lua.sGsAP_LOCATION_UPDATE_ACCEPT.newTMSIorIMSI.iD.iD.tmsi_ptmsi.octets
4688 SGsAP.send(ts_SGsAP_TMSI_REALL_CMPL(g_pars.imsi));
4689 }
4690 setverdict(pass);
4691 }
4692 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4693 setverdict(fail, "Received LU-REJECT instead of ACCEPT");
4694 }
4695 [] SGsAP.receive {
4696 setverdict(fail, "Received unexpected message on SGs");
4697 }
4698 }
4699
4700 /* Check MM information */
4701 if (mp_mm_info == true) {
4702 SGsAP.receive(tr_SGsAP_MM_INFO_REQ(g_pars.imsi, ?)) -> value mm_info;
4703 mm_info_dtap := '0532'O & mm_info.sGsAP_MM_INFORMATION_REQUEST.mM_Information.information;
4704 if (not match(dec_PDU_ML3_NW_MS(mm_info_dtap), tr_ML3_MT_MM_Info)) {
4705 setverdict(fail, "Unexpected MM Information");
4706 }
4707 }
4708
4709 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4710}
4711
4712private function f_tc_sgsap_lu(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4713 f_init_handler(pars);
4714 f_sgs_perform_lu();
4715 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4716
4717 f_sgsap_bssmap_screening();
4718
4719 setverdict(pass);
4720}
4721testcase TC_sgsap_lu() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004722 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004723 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004724 f_init(1, true);
4725 pars := f_init_pars(11811, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004726 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004727 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004728 vc_conn.done;
4729}
4730
4731/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
4732private function f_tc_sgsap_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4733 f_init_handler(pars);
4734 var PDU_SGsAP lur;
4735
4736 f_create_gsup_expect(hex2str(g_pars.imsi));
4737 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4738 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
4739 ts_SGsAP_LAI('901'H, '70'H, 2342)));
4740 SGsAP.send(lur);
4741
4742 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4743 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
4744 alt {
4745 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4746 setverdict(pass);
4747 }
4748 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) {
4749 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
4750 mtc.stop;
4751 }
4752 [] SGsAP.receive {
4753 setverdict(fail, "Received unexpected message on SGs");
4754 }
4755 }
4756
4757 f_sgsap_bssmap_screening();
4758
4759 setverdict(pass);
4760}
4761testcase TC_sgsap_lu_imsi_reject() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004762 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004763 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004764 f_init(1, true);
4765 pars := f_init_pars(11812, true);
Harald Welte4263c522018-12-06 11:56:27 +01004766
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004767 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_imsi_reject), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004768 vc_conn.done;
4769}
4770
4771/* Do LU by IMSI, but then remain silent so that Ts6-1 times out */
4772private function f_tc_sgsap_lu_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4773 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4774 var PDU_SGsAP lur;
4775
4776 f_init_handler(pars);
4777
4778 /* tell GSUP dispatcher to send this IMSI to us */
4779 f_create_gsup_expect(hex2str(g_pars.imsi));
4780
4781 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
4782 ts_SGsAP_LAI('901'H, '70'H, 2342)));
4783 /* Old LAI, if MS sends it */
4784 /* TMSI status, if MS has no valid TMSI */
4785 /* IMEISV, if it supports "automatic device detection" */
4786 /* TAI, if available in MME */
4787 /* E-CGI, if available in MME */
4788 SGsAP.send(lur);
4789
4790 /* FIXME: is this really done over SGs? The Ue is already authenticated
4791 * via the MME ... */
4792 f_mm_auth_sgs();
4793
4794 /* Expect MSC to perform LU with HLR */
4795 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4796 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
4797 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
4798 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
4799
4800 alt {
4801 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) {
4802 setverdict(pass);
4803 }
4804 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4805 setverdict(fail, "Received LU-REJECT instead of ACCEPT");
4806 }
4807 [] SGsAP.receive {
4808 setverdict(fail, "Received unexpected message on SGs");
4809 }
4810 }
4811
4812 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4813
4814 /* Wait until the VLR has abort the TMSI reallocation procedure */
4815 f_sleep(45.0);
4816
4817 /* The outcome does not change the SGs state, see also 5.2.3.4 */
4818 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4819
4820 f_sgsap_bssmap_screening();
4821
4822 setverdict(pass);
4823}
4824testcase TC_sgsap_lu_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004825 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004826 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004827 f_init(1, true);
4828 pars := f_init_pars(11813, true);
Harald Welte4263c522018-12-06 11:56:27 +01004829
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004830 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004831 vc_conn.done;
4832}
4833
4834private function f_tc_sgsap_expl_imsi_det_eps(charstring id, BSC_ConnHdlrPars pars)
4835runs on BSC_ConnHdlr {
4836 f_init_handler(pars);
4837 f_sgs_perform_lu();
4838 f_sleep(3.0);
4839
4840 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4841 SGsAP.send(ts_SGsAP_EPS_DETACH_IND(g_pars.imsi, mme_name, UE_initiated));
4842 SGsAP.receive(tr_SGsAP_EPS_DETACH_ACK(g_pars.imsi));
4843 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4844
4845 f_sgsap_bssmap_screening();
4846
4847 setverdict(pass);
4848}
4849testcase TC_sgsap_expl_imsi_det_eps() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004850 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004851 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004852 f_init(1, true);
4853 pars := f_init_pars(11814, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004854 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004855 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_expl_imsi_det_eps), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004856 vc_conn.done;
4857}
4858
Philipp Maierfc19f172019-03-21 11:17:54 +01004859private function f_tc_sgsap_impl_imsi_det_eps(charstring id, BSC_ConnHdlrPars pars)
4860runs on BSC_ConnHdlr {
4861 f_init_handler(pars);
4862 f_sgs_perform_lu();
4863 f_sleep(3.0);
4864
4865 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4866 SGsAP.send(ts_SGsAP_EPS_DETACH_IND(g_pars.imsi, mme_name, network_initiated));
4867 SGsAP.receive(tr_SGsAP_EPS_DETACH_ACK(g_pars.imsi));
4868 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4869
4870 f_sgsap_bssmap_screening();
4871
4872 setverdict(pass);
4873}
4874testcase TC_sgsap_impl_imsi_det_eps() runs on MTC_CT {
4875 var BSC_ConnHdlrPars pars;
4876 var BSC_ConnHdlr vc_conn;
4877 f_init(1, true);
4878 pars := f_init_pars(11814, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004879 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maierfc19f172019-03-21 11:17:54 +01004880 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_impl_imsi_det_eps), pars);
4881 vc_conn.done;
4882}
4883
Harald Welte4263c522018-12-06 11:56:27 +01004884private function f_tc_sgsap_expl_imsi_det_noneps(charstring id, BSC_ConnHdlrPars pars)
4885runs on BSC_ConnHdlr {
4886 f_init_handler(pars);
4887 f_sgs_perform_lu();
4888 f_sleep(3.0);
4889
4890 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4891 SGsAP.send(ts_SGsAP_IMSI_DETACH_IND(g_pars.imsi, mme_name, combined_UE_initiated));
4892 SGsAP.receive(tr_SGsAP_IMSI_DETACH_ACK(g_pars.imsi));
Philipp Maierd08e7e72019-04-02 15:27:10 +02004893
4894 if (f_ctrl_subscr_in_vlr(hex2str(g_pars.imsi))) {
4895 setverdict(fail, "subscriber not removed from VLR");
4896 }
Harald Welte4263c522018-12-06 11:56:27 +01004897
4898 f_sgsap_bssmap_screening();
4899
4900 setverdict(pass);
4901}
4902testcase TC_sgsap_expl_imsi_det_noneps() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004903 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004904 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004905 f_init(1, true);
4906 pars := f_init_pars(11815, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004907 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004908 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_expl_imsi_det_noneps), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004909 vc_conn.done;
4910}
4911
Philipp Maier5d812702019-03-21 10:51:26 +01004912private function f_tc_sgsap_impl_imsi_det_noneps(charstring id, BSC_ConnHdlrPars pars)
4913runs on BSC_ConnHdlr {
4914 f_init_handler(pars);
4915 f_sgs_perform_lu();
4916 f_sleep(3.0);
4917
4918 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4919 SGsAP.send(ts_SGsAP_IMSI_DETACH_IND(g_pars.imsi, mme_name, implicit_network_initiated));
4920 SGsAP.receive(tr_SGsAP_IMSI_DETACH_ACK(g_pars.imsi));
4921
4922 if (f_ctrl_subscr_in_vlr(hex2str(g_pars.imsi))) {
4923 setverdict(fail, "subscriber not removed from VLR");
4924 }
4925
4926 f_sgsap_bssmap_screening();
4927
4928 setverdict(pass);
4929}
4930testcase TC_sgsap_impl_imsi_det_noneps() runs on MTC_CT {
4931 var BSC_ConnHdlrPars pars;
4932 var BSC_ConnHdlr vc_conn;
4933 f_init(1, true);
4934 pars := f_init_pars(11815, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004935 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier5d812702019-03-21 10:51:26 +01004936 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_impl_imsi_det_noneps), pars);
4937 vc_conn.done;
4938}
4939
Harald Welte4263c522018-12-06 11:56:27 +01004940/* Trigger a paging request via VTY and send a paging reject in response */
4941private function f_tc_sgsap_paging_rej(charstring id, BSC_ConnHdlrPars pars)
4942runs on BSC_ConnHdlr {
4943 f_init_handler(pars);
4944 f_sgs_perform_lu();
4945 f_sleep(1.0);
4946
4947 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4948 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4949 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4950 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4951
4952 /* Initiate paging via VTY */
4953 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4954 alt {
4955 [] SGsAP.receive(exp_resp) {
4956 setverdict(pass);
4957 }
4958 [] SGsAP.receive {
4959 setverdict(fail, "Received unexpected message on SGs");
4960 }
4961 }
4962
4963 /* Now reject the paging */
4964 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, IMSI_unknown));
4965
4966 /* Wait for the states inside the MSC to settle and check the state
4967 * of the SGs Association */
4968 f_sleep(1.0);
4969 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4970
4971 /* FIXME: At the moment we send an IMSI_unknown as cause code, which is fine,
4972 * but we also need to cover tha case where the cause code indicates an
4973 * "IMSI detached for EPS services". In those cases the VLR is expected to
4974 * try paging on tha A/Iu interface. This will be another testcase similar to
4975 * this one, but extended with checks for the presence of the A/Iu paging
4976 * messages. */
4977
4978 f_sgsap_bssmap_screening();
4979
4980 setverdict(pass);
4981}
4982testcase TC_sgsap_paging_rej() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004983 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004984 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004985 f_init(1, true);
4986 pars := f_init_pars(11816, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004987 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004988 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_rej), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004989 vc_conn.done;
4990}
4991
4992/* Trigger a paging request via VTY and send a paging reject that indicates
4993 * that the subscriber intentionally rejected the call. */
4994private function f_tc_sgsap_paging_subscr_rej(charstring id, BSC_ConnHdlrPars pars)
4995runs on BSC_ConnHdlr {
4996 f_init_handler(pars);
4997 f_sgs_perform_lu();
4998 f_sleep(1.0);
4999
5000 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5001 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
5002 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
5003 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
5004
5005 /* Initiate paging via VTY */
5006 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
5007 alt {
5008 [] SGsAP.receive(exp_resp) {
5009 setverdict(pass);
5010 }
5011 [] SGsAP.receive {
5012 setverdict(fail, "Received unexpected message on SGs");
5013 }
5014 }
5015
5016 /* Now reject the paging */
5017 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, user_rejected_mobile_terminating_CS_fallback_call));
5018
5019 /* Wait for the states inside the MSC to settle and check the state
5020 * of the SGs Association */
5021 f_sleep(1.0);
5022 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5023
5024 /* FIXME: The VLR is supposed to trigger an User Determined User Busy (UDUB) as specified
5025 * in 3GPP TS 24.082, this is not yet implemented in the MSC or in this tests, we need
5026 * to check back how this works and how it can be tested */
5027
5028 f_sgsap_bssmap_screening();
5029
5030 setverdict(pass);
5031}
5032testcase TC_sgsap_paging_subscr_rej() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005033 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005034 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005035 f_init(1, true);
5036 pars := f_init_pars(11817, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005037 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005038 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_subscr_rej), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005039 vc_conn.done;
5040}
5041
5042/* Trigger a paging request via VTY and send an UE unreacable messge in response */
5043private function f_tc_sgsap_paging_ue_unr(charstring id, BSC_ConnHdlrPars pars)
5044runs on BSC_ConnHdlr {
5045 f_init_handler(pars);
5046 f_sgs_perform_lu();
5047 f_sleep(1.0);
5048
5049 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5050 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
5051 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
5052 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
5053
5054 /* Initiate paging via VTY */
5055 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
5056 alt {
5057 [] SGsAP.receive(exp_resp) {
5058 setverdict(pass);
5059 }
5060 [] SGsAP.receive {
5061 setverdict(fail, "Received unexpected message on SGs");
5062 }
5063 }
5064
5065 /* Now pretend that the UE is unreachable */
5066 SGsAP.send(ts_SGsAP_UE_UNREACHABLE(g_pars.imsi, UE_unreachable));
5067
5068 /* Wait for the states inside the MSC to settle and check the state
5069 * of the SGs Association. */
5070 f_sleep(1.0);
5071 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5072
5073 f_sgsap_bssmap_screening();
5074
5075 setverdict(pass);
5076}
5077testcase TC_sgsap_paging_ue_unr() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005078 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005079 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005080 f_init(1, true);
5081 pars := f_init_pars(11818, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005082 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005083 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_ue_unr), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005084 vc_conn.done;
5085}
5086
5087/* Trigger a paging request via VTY but don't respond to it */
5088private function f_tc_sgsap_paging_and_nothing(charstring id, BSC_ConnHdlrPars pars)
5089runs on BSC_ConnHdlr {
5090 f_init_handler(pars);
5091 f_sgs_perform_lu();
5092 f_sleep(1.0);
5093
5094 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5095 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
Philipp Maier34218102019-09-24 09:15:49 +02005096 var template PDU_SGsAP exp_serv_abrt := ts_SGsAP_SERVICE_ABORT_REQ(g_pars.imsi);
Harald Welte4263c522018-12-06 11:56:27 +01005097 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
5098 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
5099
5100 /* Initiate paging via VTY */
5101 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
5102 alt {
5103 [] SGsAP.receive(exp_resp) {
5104 setverdict(pass);
5105 }
5106 [] SGsAP.receive {
5107 setverdict(fail, "Received unexpected message on SGs");
5108 }
5109 }
5110
Philipp Maier34218102019-09-24 09:15:49 +02005111 /* While we are doing nothing, expect an SGsAP-SERVICE-ABORT-REQUEST
5112 * after some time */
5113 timer T := 10.0;
5114 T.start
5115 alt {
5116 [] SGsAP.receive(exp_serv_abrt)
5117 {
5118 setverdict(pass);
5119 }
5120 [] SGsAP.receive {
5121 setverdict(fail, "unexpected SGsAP message received");
5122 self.stop;
5123 }
5124 [] T.timeout {
5125 setverdict(fail, "MSC did not send SGsAP-SERVICE-ABORT-REQUEST");
5126 self.stop;
5127 }
5128 }
5129
5130 /* The SGs association must remain unchanged. */
Harald Welte4263c522018-12-06 11:56:27 +01005131 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5132
5133 f_sgsap_bssmap_screening();
5134
5135 setverdict(pass);
5136}
5137testcase TC_sgsap_paging_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005138 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005139 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005140 f_init(1, true);
5141 pars := f_init_pars(11819, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005142 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005143 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005144 vc_conn.done;
5145}
5146
5147/* Trigger a paging request via VTY and slip in an LU */
5148private function f_tc_sgsap_paging_and_lu(charstring id, BSC_ConnHdlrPars pars)
5149runs on BSC_ConnHdlr {
5150 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5151 f_init_handler(pars);
5152
5153 /* First we prepar the situation, where the SGs association is in state
5154 * NULL and the confirmed by radio contact indicator is set to false
5155 * as well. This can be archived by performing an SGs LU and then
5156 * resetting the VLR */
5157 f_sgs_perform_lu();
5158 f_sgsap_reset_mme(mp_mme_name);
5159 f_sleep(1.0);
5160 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
5161
5162 /* Perform a paging, expect the paging messages on the SGs interface */
5163 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
5164 alt {
5165 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
5166 setverdict(pass);
5167 }
5168 [] SGsAP.receive {
5169 setverdict(fail, "Received unexpected message on SGs");
5170 }
5171 }
5172
5173 /* Perform the LU as normal */
5174 f_sgs_perform_lu();
5175 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5176
5177 /* Expect a new paging request right after the LU */
5178 alt {
5179 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
5180 setverdict(pass);
5181 }
5182 [] SGsAP.receive {
5183 setverdict(fail, "Received unexpected message on SGs");
5184 }
5185 }
5186
5187 /* Test is done now, lets round everything up by rejecting the paging
5188 * cleanly. */
5189 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, user_rejected_mobile_terminating_CS_fallback_call));
5190 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5191
5192 f_sgsap_bssmap_screening();
5193
5194 setverdict(pass);
5195}
5196testcase TC_sgsap_paging_and_lu() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005197 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005198 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005199 f_init(1, true);
5200 pars := f_init_pars(11820, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005201 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005202 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_and_lu), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005203 vc_conn.done;
5204}
5205
5206/* Send unexpected unit-data through the SGs interface */
5207private function f_tc_sgsap_unexp_ud(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5208 f_init_handler(pars);
5209 f_sleep(1.0);
5210
5211 /* This simulates what happens when a subscriber without SGs
5212 * association gets unitdata via the SGs interface. */
5213
5214 /* Make sure the subscriber exists and the SGs association
5215 * is in NULL state */
5216 f_perform_lu();
5217 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
5218
5219 /* Send some random unit data, the MSC/VLR should send a release
5220 * immediately. */
5221 SGsAP.send(ts_SGsAP_UL_UD(pars.imsi,'1234'O));
5222 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, IMSI_detached_for_EPS_nonEPS_services));
5223
5224 f_sgsap_bssmap_screening();
5225
5226 setverdict(pass);
5227}
5228testcase TC_sgsap_unexp_ud() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005229 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005230 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005231 f_init(1, true);
5232 pars := f_init_pars(11821, true);
5233 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_unexp_ud), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005234 vc_conn.done;
5235}
5236
5237/* Send unsolicited unit-data through the SGs interface */
5238private function f_tc_sgsap_unsol_ud(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5239 f_init_handler(pars);
5240 f_sleep(1.0);
5241
5242 /* This simulates what happens when the MME attempts to send unitdata
5243 * to a subscriber that is completely unknown to the VLR */
5244
5245 /* Send some random unit data, the MSC/VLR should send a release
5246 * immediately. */
5247 SGsAP.send(ts_SGsAP_UL_UD(pars.imsi,'1234'O));
5248 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, IMSI_unknown));
5249
5250 f_sgsap_bssmap_screening();
5251
Harald Welte4d15fa72020-08-19 08:58:28 +02005252 /* clean-up VLR state about this subscriber */
5253 f_imsi_detach_by_imsi();
5254
Harald Welte4263c522018-12-06 11:56:27 +01005255 setverdict(pass);
5256}
5257testcase TC_sgsap_unsol_ud() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005258 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005259 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005260 f_init(1, true);
5261 pars := f_init_pars(11822, true);
5262 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_unsol_ud), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005263 vc_conn.done;
5264}
5265
5266private altstep as_other_sms_sgs() runs on BSC_ConnHdlr {
5267 /* FIXME: Match an actual payload (second questionmark), the type is
5268 * octetstring, how do we use a tr_PDU_DTAP_MT here? */
5269 [] SGsAP.receive(tr_SGsAP_DL_UD(?,?)) {
5270 setverdict(fail, "Unexpected SMS related PDU from MSC");
5271 mtc.stop;
5272 }
5273}
5274
5275/* receive a MT-SMS delivered from the MSC/SMSC over an already existing SGsAP connection */
5276function f_mt_sms_sgs(inout SmsParameters spars)
5277runs on BSC_ConnHdlr {
5278 var template (value) TPDU_RP_DATA_MS_SGSN tp_mo;
5279 var template (value) RPDU_MS_SGSN rp_mo;
5280 var template (value) PDU_ML3_MS_NW l3_mo;
5281
5282 var template TPDU_RP_DATA_SGSN_MS tp_mt;
5283 var template RPDU_SGSN_MS rp_mt;
5284 var template PDU_ML3_NW_MS l3_mt;
5285
5286 var PDU_ML3_NW_MS sgsap_l3_mt;
5287
5288 var default d := activate(as_other_sms_sgs());
5289
5290 /* Expect CP-DATA(RP-DATA(SMS-DELIVER)) */
5291 tp_mt := tr_SMS_DELIVER(?, spars.tp.ud, spars.tp.pid, spars.tp.dcs, ?);
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09005292 rp_mt := tr_RP_DATA_MT(?, spars.rp.smsc_addr, omit, tp_mt);
Harald Welte4263c522018-12-06 11:56:27 +01005293 l3_mt := tr_ML3_MT_SMS(?, c_TIF_ORIG, tr_CP_DATA_MT(rp_mt));
5294
5295 SGsAP.receive(l3_mt) -> value sgsap_l3_mt;
5296
5297 /* Extract relevant identifiers */
5298 spars.tid := bit2int(sgsap_l3_mt.tiOrSkip.transactionId.tio);
5299 spars.rp.msg_ref := sgsap_l3_mt.msgs.sms.cP_DATA.cP_User_Data.cP_RPDU.rP_DATA_SGSN_MS.rP_MessageReference;
5300
5301 /* send CP-ACK for CP-DATA just received */
5302 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_REPL, ts_CP_ACK_MO);
5303
5304 SGsAP.send(l3_mo);
5305
5306 /* send RP-ACK for RP-DATA */
5307 rp_mo := ts_RP_ACK_MO(spars.rp.msg_ref);
5308 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_REPL, ts_CP_DATA_MO(rp_mo));
5309
5310 SGsAP.send(l3_mo);
5311
5312 /* expect CP-ACK for CP-DATA(RP-ACK) just sent */
5313 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_ORIG, tr_CP_ACK_MT);
5314
5315 SGsAP.receive(l3_mt);
5316
5317 deactivate(d);
5318
5319 setverdict(pass);
5320}
5321
5322/* submit a MO-SMS to MSC/SMSC over an already existing SGsAP connection */
5323function f_mo_sms_sgs(inout SmsParameters spars)
5324runs on BSC_ConnHdlr {
5325 var template (value) TPDU_RP_DATA_MS_SGSN tp_mo;
5326 var template (value) RPDU_MS_SGSN rp_mo;
5327 var template (value) PDU_ML3_MS_NW l3_mo;
5328
5329 var template TPDU_RP_DATA_SGSN_MS tp_mt;
5330 var template RPDU_SGSN_MS rp_mt;
5331 var template PDU_ML3_NW_MS l3_mt;
5332
5333 var default d := activate(as_other_sms_sgs());
5334
5335 /* just in case this is routed to SMPP.. */
5336 f_create_smpp_expect(hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue));
5337
5338 tp_mo := ts_SMS_SUBMIT(spars.tp.msg_ref, spars.tp.da, spars.tp.pid, spars.tp.dcs,
5339 spars.tp.udl, spars.tp.ud);
Vadim Yanitskiy437b5a62019-12-15 14:13:39 +09005340 rp_mo := ts_RP_DATA_MO(spars.rp.msg_ref, omit, spars.rp.smsc_addr, tp_mo);
Harald Welte4263c522018-12-06 11:56:27 +01005341 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_DATA_MO(rp_mo));
5342
5343 SGsAP.send(l3_mo);
5344
5345 /* receive CP-ACK for CP-DATA above */
5346 SGsAP.receive(tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_ACK_MT));
5347
5348 if (ispresent(spars.exp_rp_err)) {
5349 /* expect an RP-ERROR message from MSC with given cause */
5350 rp_mt := tr_RP_ERROR_MT(spars.rp.msg_ref, spars.exp_rp_err);
5351 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_DATA_MT(rp_mt));
5352 SGsAP.receive(l3_mt);
5353 /* send CP-ACK for CP-DATA just received */
5354 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_ACK_MO);
5355 SGsAP.send(l3_mo);
5356 } else {
5357 /* expect RP-ACK for RP-DATA */
5358 rp_mt := tr_RP_ACK_MT(spars.rp.msg_ref);
5359 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_DATA_MT(rp_mt));
5360 SGsAP.receive(l3_mt);
5361 /* send CP-ACO for CP-DATA just received */
5362 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_ACK_MO);
5363 SGsAP.send(l3_mo);
5364 }
5365
5366 deactivate(d);
5367
5368 setverdict(pass);
5369}
5370
5371private function f_vty_sms_send_conn_hdlr(charstring imsi, charstring msisdn, charstring text)
5372runs on BSC_ConnHdlr {
5373 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
5374}
5375
5376/* Send a MT SMS via SGs interface */
5377private function f_tc_sgsap_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5378 f_init_handler(pars);
5379 f_sgs_perform_lu();
5380 f_sleep(1.0);
5381 var SmsParameters spars := valueof(t_SmsPars);
5382 spars.tp.ud := 'C8329BFD064D9B53'O;
5383
5384 /* Trigger SMS via VTY */
5385 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
5386 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5387
5388 /* Expect a paging request and respond accordingly with a service request */
5389 SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, SMS_indicator, omit));
5390 SGsAP.send(ts_SGsAP_SERVICE_REQ(pars.imsi, SMS_indicator, EMM_CONNECTED));
5391
5392 /* Connection is now live, receive the MT-SMS */
5393 f_mt_sms_sgs(spars);
5394
5395 /* Expect a concluding release from the MSC */
5396 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, omit));
5397
5398 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
5399 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5400
5401 f_sgsap_bssmap_screening();
5402
5403 setverdict(pass);
5404}
5405testcase TC_sgsap_mt_sms() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005406 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005407 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005408 f_init(1, true);
5409 pars := f_init_pars(11823, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005410 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005411 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005412 vc_conn.done;
5413}
5414
5415/* Send a MO SMS via SGs interface */
5416private function f_tc_sgsap_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5417 f_init_handler(pars);
5418 f_sgs_perform_lu();
5419 f_sleep(1.0);
5420 var SmsParameters spars := valueof(t_SmsPars);
5421 spars.tp.ud := 'C8329BFD064D9B53'O;
5422
5423 /* Send the MO-SMS */
5424 f_mo_sms_sgs(spars);
5425
5426 /* Expect a concluding release from the MSC/VLR */
5427 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, omit));
5428
5429 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
5430 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5431
5432 setverdict(pass);
5433
5434 f_sgsap_bssmap_screening()
5435}
5436testcase TC_sgsap_mo_sms() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005437 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005438 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005439 f_init(1, true);
5440 pars := f_init_pars(11824, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005441 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005442 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mo_sms), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005443 vc_conn.done;
5444}
5445
5446/* Trigger sending of an MT sms via VTY but never respond to anything */
5447private function f_tc_sgsap_mt_sms_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5448 f_init_handler(pars, 170.0);
5449 f_sgs_perform_lu();
5450 f_sleep(1.0);
5451
5452 var SmsParameters spars := valueof(t_SmsPars);
5453 spars.tp.ud := 'C8329BFD064D9B53'O;
5454 var integer page_count := 0;
5455 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5456 var template PDU_SGsAP exp_pag_req := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, SMS_indicator, omit);
5457 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
5458 exp_pag_req.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
5459
5460 /* Trigger SMS via VTY */
5461 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
5462
Neels Hofmeyr16237742019-03-06 15:34:01 +01005463 /* Expect the MSC/VLR to page exactly once */
5464 SGsAP.receive(exp_pag_req);
Harald Welte4263c522018-12-06 11:56:27 +01005465
5466 /* Wait some time to make sure the MSC is not delivering any further
5467 * paging messages or anything else that could be unexpected. */
5468 timer T := 20.0;
5469 T.start
5470 alt {
5471 [] SGsAP.receive(exp_pag_req)
5472 {
5473 setverdict(fail, "paging seems not to stop!");
5474 mtc.stop;
5475 }
5476 [] SGsAP.receive {
5477 setverdict(fail, "unexpected SGsAP message received");
5478 self.stop;
5479 }
5480 [] T.timeout {
5481 setverdict(pass);
5482 }
5483 }
5484
5485 /* Even on a failed paging the SGs Association should stay intact */
5486 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5487
Philipp Maier26bdb8c2019-09-24 09:21:12 +02005488 /* Make sure that the SMS we just inserted is cleared and the
5489 * subscriber is expired. This is necessary because otherwise the MSC
5490 * might re-try the SMS delivery and disturb the following tests. */
Harald Welte4263c522018-12-06 11:56:27 +01005491
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01005492 f_vty_sms_clear(hex2str(g_pars.imsi));
5493
Harald Welte4263c522018-12-06 11:56:27 +01005494 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " expire");
5495
5496 setverdict(pass);
Neels Hofmeyrb0f82342019-03-06 15:36:51 +01005497
5498 f_sgsap_bssmap_screening();
Harald Welte4263c522018-12-06 11:56:27 +01005499}
5500testcase TC_sgsap_mt_sms_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005501 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005502 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005503 f_init(1, true);
5504 pars := f_init_pars(11825, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005505 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005506 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005507 vc_conn.done;
5508}
5509
5510/* Trigger sending of an MT sms via VTY but reject the paging immediately */
5511private function f_tc_sgsap_mt_sms_and_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5512 f_init_handler(pars, 150.0);
5513 f_sgs_perform_lu();
5514 f_sleep(1.0);
5515
5516 var SmsParameters spars := valueof(t_SmsPars);
5517 spars.tp.ud := 'C8329BFD064D9B53'O;
5518 var integer page_count := 0;
5519 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5520 var template PDU_SGsAP exp_pag_req := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, SMS_indicator, omit);
5521 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
5522 exp_pag_req.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
5523
5524 /* Trigger SMS via VTY */
5525 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
5526
5527 /* Expect a paging request and reject it immediately */
5528 SGsAP.receive(exp_pag_req);
5529 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, IMSI_unknown));
5530
5531 /* The MSC/VLR should no longer try to page once the paging has been
5532 * rejected. Wait some time and check if there are no unexpected
5533 * messages on the SGs interface. */
5534 timer T := 20.0;
5535 T.start
5536 alt {
5537 [] SGsAP.receive(exp_pag_req)
5538 {
5539 setverdict(fail, "paging seems not to stop!");
5540 mtc.stop;
5541 }
5542 [] SGsAP.receive {
5543 setverdict(fail, "unexpected SGsAP message received");
5544 self.stop;
5545 }
5546 [] T.timeout {
5547 setverdict(pass);
5548 }
5549 }
5550
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01005551 f_vty_sms_clear(hex2str(g_pars.imsi));
5552
Harald Welte4263c522018-12-06 11:56:27 +01005553 /* A rejected paging with IMSI_unknown (see above) should always send
5554 * the SGs association to NULL. */
5555 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
5556
5557 f_sgsap_bssmap_screening();
5558
Harald Welte4263c522018-12-06 11:56:27 +01005559 setverdict(pass);
5560}
5561testcase TC_sgsap_mt_sms_and_reject() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005562 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005563 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005564 f_init(1, true);
5565 pars := f_init_pars(11826, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005566 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005567 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms_and_reject), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005568 vc_conn.done;
5569}
5570
Pau Espin Pedrol3acd19e2021-04-28 12:59:52 +02005571/* Perform an MT CSFB call including LU */
Harald Welte4263c522018-12-06 11:56:27 +01005572private function f_mt_lu_and_csfb_call(charstring id, BSC_ConnHdlrPars pars, boolean bssmap_lu) runs on BSC_ConnHdlr {
5573 f_init_handler(pars);
5574
5575 /* Be sure that the BSSMAP reset is done before we begin. */
5576 f_sleep(2.0);
5577
5578 /* Testcase variation: See what happens when we do a regular BSSMAP
5579 * LU first (this should not hurt in any way!) */
5580 if (bssmap_lu) {
5581 f_perform_lu();
5582 }
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005583 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Harald Welte4263c522018-12-06 11:56:27 +01005584
5585 f_sgs_perform_lu();
5586 f_sleep(1.0);
5587
5588 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5589 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Harald Welte4263c522018-12-06 11:56:27 +01005590
5591 /* Initiate a call via MNCC interface */
5592 f_mt_call_initate(cpars);
5593
5594 /* Expect a paging request and respond accordingly with a service request */
5595 SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit));
5596 SGsAP.send(ts_SGsAP_SERVICE_REQ(pars.imsi, CS_call_indicator, EMM_CONNECTED));
5597
5598 /* Complete the call, hold it for some time and then tear it down */
5599 f_mt_call_complete(cpars);
5600 f_sleep(3.0);
Harald Welte4c422b72019-02-17 16:27:10 +01005601 f_call_hangup(cpars, true, is_csfb := true);
Harald Welte4263c522018-12-06 11:56:27 +01005602
5603 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
5604 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5605
Harald Welte4263c522018-12-06 11:56:27 +01005606 /* Test for successful return by triggering a paging, when the paging
5607 * request is received via SGs, we can be sure that the MSC/VLR has
5608 * recognized that the UE is now back on 4G */
5609 f_sleep(1.0);
5610 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
5611 alt {
5612 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
5613 setverdict(pass);
5614 }
5615 [] SGsAP.receive {
5616 setverdict(fail, "Received unexpected message on SGs");
5617 }
5618 }
5619
5620 f_sgsap_bssmap_screening();
5621
5622 setverdict(pass);
5623}
5624
5625/* Perform a regular BSSAP LU first, do a SGSAP LU and then make a CSFB call */
5626private function f_tc_bssap_lu_sgsap_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5627 f_mt_lu_and_csfb_call(id, pars, true);
5628}
5629testcase TC_bssap_lu_sgsap_lu_and_mt_call() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005630 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005631 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005632 f_init(1, true);
5633 pars := f_init_pars(118139, true);
Harald Welte4263c522018-12-06 11:56:27 +01005634
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005635 vc_conn := f_start_handler_with_pars(refers(f_tc_bssap_lu_sgsap_lu_and_mt_call), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005636 vc_conn.done;
5637}
5638
Harald Welte4263c522018-12-06 11:56:27 +01005639/* Perform a SGSAP LU and then make a CSFB call */
5640private function f_tc_sgsap_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5641 f_mt_lu_and_csfb_call(id, pars, false);
5642}
5643testcase TC_sgsap_lu_and_mt_call() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005644 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005645 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005646 f_init(1, true);
5647 pars := f_init_pars(11827, true);
Harald Welte4263c522018-12-06 11:56:27 +01005648
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005649 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_and_mt_call), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005650 vc_conn.done;
5651}
5652
Philipp Maier628c0052019-04-09 17:36:57 +02005653/* Simulate an HLR/VLR failure */
5654private function f_tc_sgsap_vlr_failure(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5655 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
5656 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5657
5658 var PDU_SGsAP lur;
5659
5660 f_init_handler(pars);
5661
5662 /* Attempt location update (which is expected to fail) */
5663 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
5664 ts_SGsAP_LAI('901'H, '70'H, 2342)));
5665 SGsAP.send(lur);
5666
5667 /* Respond to SGsAP-RESET-INDICATION from VLR */
5668 alt {
5669 [] SGsAP.receive(tr_SGsAP_RESET_IND_VLR(vlr_name)); {
5670 SGsAP.send(valueof(ts_SGsAP_RESET_ACK_MME(mme_name)));
5671 setverdict(pass);
5672 }
5673 [] SGsAP.receive {
5674 setverdict(fail, "Received unexpected message on SGs");
5675 }
5676 }
5677
5678 f_sleep(1.0);
5679 setverdict(pass);
5680}
5681testcase TC_sgsap_vlr_failure() runs on MTC_CT {
5682 var BSC_ConnHdlrPars pars;
5683 var BSC_ConnHdlr vc_conn;
5684 f_init(1, true, false);
5685 pars := f_init_pars(11811, true, false);
5686 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_vlr_failure), pars);
5687 vc_conn.done;
5688}
5689
Harald Welte4263c522018-12-06 11:56:27 +01005690/* SGs TODO:
5691 * LU attempt for IMSI without NAM_PS in HLR
5692 * LU attempt with AUTH FAIL due to invalid RES/SRES
5693 * LU attempt with no response from HLR (VLR should timeout + LU REJ)
5694 * LU attempt with new TMSI but without TMSI REALL CMPL baco to VLR
5695 * implicit IMSI detach from EPS
5696 * implicit IMSI detach from non-EPS
5697 * MM INFO
5698 *
5699 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01005700
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005701private function f_tc_ho_inter_bsc_unknown_cell(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5702 f_init_handler(pars);
5703 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005704
5705 f_perform_lu();
5706 f_mo_call_establish(cpars);
5707
5708 f_sleep(1.0);
5709
5710 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5711 var BssmapCause cause := enum2int(cause_val);
5712
5713 var template BSSMAP_FIELD_CellIdentificationList cil;
5714 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('023'H, '42'H, 999) } };
5715
5716 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5717 BSSAP.receive(tr_BSSMAP_HandoverRequiredReject);
5718
5719 f_call_hangup(cpars, true);
5720}
5721testcase TC_ho_inter_bsc_unknown_cell() runs on MTC_CT {
5722 var BSC_ConnHdlr vc_conn;
5723 f_init();
5724
5725 vc_conn := f_start_handler(refers(f_tc_ho_inter_bsc_unknown_cell), 53);
5726 vc_conn.done;
5727}
5728
5729private altstep as_mgcp_ack_all_mdcx(CallParameters cpars) runs on BSC_ConnHdlr {
5730 var MgcpCommand mgcp_cmd;
5731 [] MGCP.receive(tr_MDCX) -> value mgcp_cmd {
Neels Hofmeyr8913b9e2021-07-27 22:33:45 +02005732 var charstring conn_id;
5733 f_mgcp_find_param_entry(mgcp_cmd.params, "I", conn_id);
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02005734 var SDP_Message sdp := valueof(ts_SDP(cpars.mgw_conn_2.mgw_rtp_ip, cpars.mgw_conn_2.mgw_rtp_ip,
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005735 hex2str(cpars.mgcp_call_id), "42",
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02005736 cpars.mgw_conn_2.mgw_rtp_port,
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005737 { int2str(cpars.rtp_payload_type) },
5738 { valueof(ts_SDP_rtpmap(cpars.rtp_payload_type,
5739 cpars.rtp_sdp_format)),
5740 valueof(ts_SDP_ptime(20)) }));
Neels Hofmeyr8913b9e2021-07-27 22:33:45 +02005741 MGCP.send(ts_MDCX_ACK(mgcp_cmd.line.trans_id, str2hex(conn_id), sdp));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005742 repeat;
5743 }
5744}
5745
Neels Hofmeyr8853afb2021-07-27 22:34:15 +02005746private altstep as_mgcp_ack_all_dlcx(CallParameters cpars) runs on BSC_ConnHdlr {
5747 var MgcpCommand mgcp_cmd;
5748 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
5749 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
5750 repeat;
5751 }
5752}
5753
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005754private function f_tc_ho_inter_bsc0(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005755 var CallParameters cpars;
5756
5757 cpars := valueof(t_CallParams('12345'H, 0));
5758 if (pars.use_ipv6) {
5759 cpars.mgw_conn_1.mgw_rtp_ip := "::1";
5760 cpars.mgw_conn_2.mgw_rtp_ip := "::2";
5761 cpars.bss_rtp_ip := "::3";
5762 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005763
5764 f_init_handler(pars);
5765
5766 f_vty_transceive(MSCVTY, "configure terminal");
5767 f_vty_transceive(MSCVTY, "msc");
5768 f_vty_transceive(MSCVTY, "neighbor a cgi 262 42 23 42 ran-pc 0.24.1");
Neels Hofmeyr2822d072021-06-23 03:20:32 +02005769 f_vty_transceive(MSCVTY, "neighbor a cgi 023 42 5 6 ran-pc 0.24.2");
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005770 f_vty_transceive(MSCVTY, "exit");
5771 f_vty_transceive(MSCVTY, "exit");
5772
5773 f_perform_lu();
5774 f_mo_call_establish(cpars);
5775
5776 f_sleep(1.0);
5777
5778 var default ack_mdcx := activate(as_mgcp_ack_all_mdcx(cpars));
5779
5780 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5781 var BssmapCause cause := enum2int(cause_val);
5782
5783 var template BSSMAP_FIELD_CellIdentificationList cil;
Neels Hofmeyr2822d072021-06-23 03:20:32 +02005784 cil := { cIl_CGI := { ts_BSSMAP_CI_CGI('023'H, '42'H, 5, 6) } };
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005785
5786 /* old BSS sends Handover Required */
5787 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5788
5789 /* Now the action goes on in f_tc_ho_inter_bsc1() */
5790
5791 /* MSC forwards the RR Handover Command to old BSS */
5792 var PDU_BSSAP ho_command;
5793 BSSAP.receive(tr_BSSMAP_HandoverCommand) -> value ho_command;
5794
5795 log("GOT HandoverCommand", ho_command);
5796
5797 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
5798
5799 /* f_tc_ho_inter_bsc1() completes Handover, then expecting a Clear here. */
5800 f_expect_clear();
5801
5802 log("FIRST inter-BSC Handover done");
5803
5804
5805 /* ------------------------ */
5806
5807 /* Ok, that went well, now the other BSC is handovering back here --
5808 * from now on this here is the new BSS. */
5809 f_create_bssmap_exp_handoverRequest(193);
5810
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005811 var template BSSMAP_IE_EncryptionInformation encryptionInformation;
5812 var template BSSMAP_IE_ChosenEncryptionAlgorithm chosenEncryptionAlgorithm;
5813 var template BSSMAP_IE_KC128 kC128;
5814 var OCT1 a5_perm_alg;
5815 f_get_expected_encryption(encryptionInformation, chosenEncryptionAlgorithm, kC128, a5_perm_alg);
Vadim Yanitskiyc5fcb892022-08-04 04:06:07 +07005816 var template PDU_BSSAP expect_ho_request := tr_BSSMAP_HandoverRequest(encryptionInformation,
5817 chosenEncryptionAlgorithm,
5818 kC128, codecList := ?);
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005819 var PDU_BSSAP ho_request;
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005820 alt {
5821 [] BSSAP.receive(expect_ho_request);
5822 [] BSSAP.receive(tr_BSSMAP_HandoverRequest) -> value ho_request {
5823 log("Error: Wrong handoverRequest received. Expected: ", expect_ho_request,
5824 " got ", ho_request);
5825 setverdict(fail, "Wrong handoverRequest received");
5826 mtc.stop;
5827 }
5828 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005829
5830 /* new BSS composes a RR Handover Command */
5831 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5832 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005833 var BSSMAP_IE_AoIP_TransportLayerAddress tla tla :=
5834 valueof(f_ts_BSSMAP_IE_AoIP_TLA(cpars.bss_rtp_ip, cpars.bss_rtp_port));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005835 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5836 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5837
5838 /* Now f_tc_ho_inter_bsc1() expects HandoverCommand */
5839
5840 f_sleep(0.5);
5841
5842 /* Notify that the MS is now over here */
5843
5844 BSSAP.send(ts_BSSMAP_HandoverDetect);
5845 f_sleep(0.1);
5846 BSSAP.send(ts_BSSMAP_HandoverComplete);
5847
5848 f_sleep(3.0);
5849
5850 deactivate(ack_mdcx);
5851
5852 var default ccrel := activate(as_optional_cc_rel(cpars, true));
5853
5854 /* blatant cheating */
5855 var N_Sd_Array last_n_sd := f_bssmap_last_n_sd();
5856 last_n_sd[0] := 3;
5857 f_bssmap_continue_after_n_sd(last_n_sd);
5858
5859 f_call_hangup(cpars, true);
5860 f_sleep(1.0);
5861 deactivate(ccrel);
5862
5863 setverdict(pass);
5864}
5865private function f_tc_ho_inter_bsc1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005866 var charstring bss_rtp_ip;
5867 if (pars.use_ipv6) {
5868 bss_rtp_ip := "::8";
5869 } else {
5870 bss_rtp_ip := "1.2.3.4";
5871 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005872 f_init_handler(pars);
5873 f_create_bssmap_exp_handoverRequest(194);
5874
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005875 var template BSSMAP_IE_EncryptionInformation encryptionInformation;
5876 var template BSSMAP_IE_ChosenEncryptionAlgorithm chosenEncryptionAlgorithm;
5877 var template BSSMAP_IE_KC128 kC128;
5878 var OCT1 a5_perm_alg;
5879 f_get_expected_encryption(encryptionInformation, chosenEncryptionAlgorithm, kC128, a5_perm_alg);
Vadim Yanitskiyc5fcb892022-08-04 04:06:07 +07005880 var template PDU_BSSAP expect_ho_request := tr_BSSMAP_HandoverRequest(encryptionInformation,
5881 chosenEncryptionAlgorithm,
5882 kC128, codecList := ?);
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005883 var PDU_BSSAP ho_request;
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005884 alt {
5885 [] BSSAP.receive(expect_ho_request);
5886 [] BSSAP.receive(tr_BSSMAP_HandoverRequest) -> value ho_request {
5887 log("Error: Wrong handoverRequest received. Expected: ", expect_ho_request,
5888 " got ", ho_request);
5889 setverdict(fail, "Wrong handoverRequest received");
5890 mtc.stop;
5891 }
5892 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005893 /* new BSS composes a RR Handover Command */
5894 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5895 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005896 var BSSMAP_IE_AoIP_TransportLayerAddress tla :=
5897 valueof(f_ts_BSSMAP_IE_AoIP_TLA(bss_rtp_ip, 2342));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005898 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5899 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5900
5901 /* Now f_tc_ho_inter_bsc0() expects HandoverCommand */
5902
5903 f_sleep(0.5);
5904
5905 /* Notify that the MS is now over here */
5906
5907 BSSAP.send(ts_BSSMAP_HandoverDetect);
5908 f_sleep(0.1);
5909 BSSAP.send(ts_BSSMAP_HandoverComplete);
5910
5911 f_sleep(3.0);
5912
5913 /* Now I'd like to f_call_hangup() but we don't know any cpars here. So
5914 * ... handover back to the first BSC :P */
5915
5916 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5917 var BssmapCause cause := enum2int(cause_val);
5918
5919 var template BSSMAP_FIELD_CellIdentificationList cil;
Neels Hofmeyr2822d072021-06-23 03:20:32 +02005920 cil := { cIl_CGI := { ts_BSSMAP_CI_CGI('262'H, '42'H, 23, 42) } };
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005921
5922 /* old BSS sends Handover Required */
5923 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5924
5925 /* Now the action goes on in f_tc_ho_inter_bsc0() */
5926
5927 /* MSC forwards the RR Handover Command to old BSS */
5928 var PDU_BSSAP ho_command;
5929 BSSAP.receive(tr_BSSMAP_HandoverCommand) -> value ho_command;
5930
5931 log("GOT HandoverCommand", ho_command);
5932
5933 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
5934
5935 /* f_tc_ho_inter_bsc1() completes Handover, then expecting a Clear here. */
5936 f_expect_clear();
5937 setverdict(pass);
5938}
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005939function f_tc_ho_inter_bsc_main(boolean use_ipv6 := false, integer a5_n := 0) runs on MTC_CT {
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005940 var BSC_ConnHdlr vc_conn0;
5941 var BSC_ConnHdlr vc_conn1;
5942 f_init(2);
5943
5944 var BSC_ConnHdlrPars pars0 := f_init_pars(53);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005945 pars0.use_ipv6 := use_ipv6;
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005946 pars0.net.expect_ciph := a5_n > 0;
5947 pars0.net.expect_auth := pars0.net.expect_ciph;
5948 pars0.net.kc_support := bit2oct('00000001'B << a5_n);
5949 pars0.cm2.classmarkInformationType2_oct5.a5_3 := '1'B;
5950 pars0.cm2.classmarkInformationType2_oct5.a5_2 := '0'B;
5951 pars0.cm2.classmarkInformationType2_oct5.cm3 := '1'B;
5952 pars0.cm3 := valueof(ts_CM3_default);
5953 pars0.use_umts_aka := true;
5954 pars0.vec := f_gen_auth_vec_3g();
5955 pars0.vec_keep := true;
Neels Hofmeyr60122f82021-07-28 17:59:38 +02005956 pars0.ran_idx := 0;
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005957
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005958 var BSC_ConnHdlrPars pars1 := f_init_pars(53);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005959 pars1.use_ipv6 := use_ipv6;
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005960 pars1.net.expect_ciph := pars0.net.expect_ciph;
5961 pars1.net.expect_auth := pars0.net.expect_ciph;
5962 pars1.net.kc_support := bit2oct('00000001'B << a5_n);
5963 pars1.cm2 := pars0.cm2;
5964 pars1.cm3 := pars0.cm3;
5965 pars1.use_umts_aka := true;
5966 /* Both components need the same auth vector info because we expect f_tc_ho_inter_bsc0's ciphering key to be
5967 * identical to the one that shows up in f_tc_ho_inter_bsc1. Can only do that by feeding in a vector to both
5968 * components and then not overwriting it in BSC_ConnectionHandler. */
5969 pars1.vec := pars0.vec;
5970 pars1.vec_keep := true;
Neels Hofmeyr60122f82021-07-28 17:59:38 +02005971 pars1.ran_idx := 1;
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005972
5973 if (a5_n > 0) {
5974 f_vty_config(MSCVTY, "network", "authentication required");
5975 }
5976 f_vty_config(MSCVTY, "network", "encryption a5 " & int2str(a5_n));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005977
Neels Hofmeyr60122f82021-07-28 17:59:38 +02005978 vc_conn0 := f_start_handler_with_pars(refers(f_tc_ho_inter_bsc0), pars0);
5979 vc_conn1 := f_start_handler_with_pars(refers(f_tc_ho_inter_bsc1), pars1);
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005980 vc_conn0.done;
5981 vc_conn1.done;
5982}
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005983testcase TC_ho_inter_bsc() runs on MTC_CT {
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005984 f_tc_ho_inter_bsc_main(false, a5_n := 0);
5985}
5986testcase TC_ho_inter_bsc_a5_1() runs on MTC_CT {
5987 f_tc_ho_inter_bsc_main(false, a5_n := 1);
5988}
5989testcase TC_ho_inter_bsc_a5_3() runs on MTC_CT {
5990 f_tc_ho_inter_bsc_main(false, a5_n := 3);
5991}
5992testcase TC_ho_inter_bsc_a5_4() runs on MTC_CT {
5993 f_tc_ho_inter_bsc_main(false, a5_n := 4);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005994}
5995testcase TC_ho_inter_bsc_ipv6() runs on MTC_CT {
5996 f_tc_ho_inter_bsc_main(true);
5997}
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005998
5999function f_ML3_patch_seq_nr_MS_NW(in uint2_t seq_nr, inout octetstring enc_l3) {
6000 log("MS_NW patching N(SD)=", seq_nr, " into dtap ", enc_l3);
6001 enc_l3[2] := (enc_l3[2] and4b '3f'O) or4b bit2oct(int2bit(seq_nr, 8) << 6);
6002 log("MS_NW patched enc_l3: ", enc_l3);
6003}
6004
6005private function f_tc_ho_inter_msc_out(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006006 var CallParameters cpars;
Neels Hofmeyr906af102021-07-01 12:08:35 +02006007 var PDU_BSSAP ho_request;
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006008
6009 cpars := valueof(t_CallParams('12345'H, 0));
6010 if (pars.use_ipv6) {
6011 cpars.mgw_conn_1.mgw_rtp_ip := "::1";
6012 cpars.mgw_conn_2.mgw_rtp_ip := "::2";
6013 cpars.bss_rtp_ip := "::3";
6014 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006015 var hexstring ho_number := f_gen_msisdn(99999);
6016
6017 f_init_handler(pars);
6018
6019 f_create_mncc_expect(hex2str(ho_number));
6020
6021 f_vty_transceive(MSCVTY, "configure terminal");
6022 f_vty_transceive(MSCVTY, "msc");
6023 f_vty_transceive(MSCVTY, "neighbor a cgi 017 017 1 1 msc-ipa-name msc-017-017-1");
6024 f_vty_transceive(MSCVTY, "exit");
6025 f_vty_transceive(MSCVTY, "exit");
6026
6027 f_perform_lu();
6028 f_mo_call_establish(cpars);
6029
6030 f_sleep(1.0);
6031
6032 var default ack_mdcx := activate(as_mgcp_ack_all_mdcx(cpars));
6033
6034 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
6035 var BssmapCause cause := enum2int(cause_val);
6036
6037 var template BSSMAP_FIELD_CellIdentificationList cil;
Neels Hofmeyr36ebc332021-06-23 03:20:32 +02006038 cil := { cIl_CGI := { ts_BSSMAP_CI_CGI('017'H, '017'H, 1, 1) } };
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006039
6040 /* old BSS sends Handover Required */
6041 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
6042
6043 /* The target cell 017-017 LAC 1 is configured to be a remote MSC of name "msc-017-017-1".
6044 * This MSC tries to reach the other MSC via GSUP. */
6045
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006046 var template BSSMAP_IE_EncryptionInformation encryptionInformation;
6047 var template BSSMAP_IE_ChosenEncryptionAlgorithm chosenEncryptionAlgorithm;
6048 var template BSSMAP_IE_KC128 kC128;
6049 var OCT1 a5_perm_alg;
6050 f_get_expected_encryption(encryptionInformation, chosenEncryptionAlgorithm, kC128, a5_perm_alg);
Vadim Yanitskiyc5fcb892022-08-04 04:06:07 +07006051 var template PDU_BSSAP expect_ho_request := tr_BSSMAP_HandoverRequest(encryptionInformation,
6052 chosenEncryptionAlgorithm,
6053 kC128, codecList := ?);
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006054
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006055 var octetstring remote_msc_name := '6D73632D3031372D3031372D3100'O; /* "msc-017-017-1\0" as octetstring */
6056 var GSUP_PDU prep_ho_req;
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006057 alt {
6058 [] GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_HANDOVER_REQUEST,
6059 pars.imsi, destination_name := remote_msc_name,
Neels Hofmeyrec2e1f72021-07-02 02:08:32 +02006060 an_apdu := t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006, pdu := ?))) -> value prep_ho_req;
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006061 [] GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_HANDOVER_REQUEST)) {
6062 setverdict(fail, "Wrong OSMO_GSUP_MSGT_E_PREPARE_HANDOVER_REQUEST message received");
6063 mtc.stop;
6064 }
6065 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006066
6067 var GSUP_IeValue source_name_ie;
6068 f_gsup_find_ie(prep_ho_req, OSMO_GSUP_SOURCE_NAME_IE, source_name_ie);
6069 var octetstring local_msc_name := source_name_ie.source_name;
6070
Neels Hofmeyrec2e1f72021-07-02 02:08:32 +02006071 /* Decode PDU to 1) match with expect_ho_request and 2) to forward the actual chosen encryption algorithm. */
Neels Hofmeyr906af102021-07-01 12:08:35 +02006072 var GSUP_IeValue an_apdu_ie;
6073 f_gsup_find_ie(prep_ho_req, OSMO_GSUP_AN_APDU_IE, an_apdu_ie);
6074 ho_request := dec_PDU_BSSAP(an_apdu_ie.an_apdu.pdu);
Neels Hofmeyrec2e1f72021-07-02 02:08:32 +02006075 if (not match(ho_request, expect_ho_request)) {
6076 setverdict(fail, "Wrong PDU in OSMO_GSUP_MSGT_E_PREPARE_HANDOVER_REQUEST message received");
6077 mtc.stop;
6078 }
Neels Hofmeyr906af102021-07-01 12:08:35 +02006079
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006080 /* Remote MSC has figured out its BSC and signals success */
6081 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
6082 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
6083 var PDU_BSSAP ho_req_ack := valueof(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
Neels Hofmeyr906af102021-07-01 12:08:35 +02006084 aoIPTransportLayer := omit,
6085 speechCodec := ts_BSSMAP_IE_SpeechCodec({ts_CodecFR}),
6086 chosenEncryptionAlgorithm := ho_request.pdu.bssmap.handoverRequest.chosenEncryptionAlgorithm));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006087 GSUP.send(ts_GSUP_E_PrepareHandoverResult(
6088 pars.imsi,
6089 ho_number,
6090 remote_msc_name, local_msc_name,
6091 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006, enc_PDU_BSSAP(ho_req_ack)))));
6092
6093 /* MSC forwards the RR Handover Command to old BSS */
6094 BSSAP.receive(tr_BSSMAP_HandoverCommand);
6095
6096 /* The MS shows up at remote new BSS */
6097
6098 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PROCESS_ACCESS_SIGNALLING_REQUEST,
6099 pars.imsi, remote_msc_name, local_msc_name,
6100 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
6101 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverDetect))))));
6102 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
6103 f_sleep(0.1);
6104
6105 /* Save the MS sequence counters for use on the other connection */
6106 var N_Sd_Array last_n_sd := f_bssmap_last_n_sd();
6107
6108 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_SEND_END_SIGNAL_REQUEST,
6109 pars.imsi, remote_msc_name, local_msc_name,
6110 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
6111 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverComplete))))));
6112
6113 /* The local BSS conn clears, all communication goes via remote MSC now */
6114 f_expect_clear();
6115
6116 /**********************************/
6117 /* Play through some signalling across the inter-MSC link.
6118 * This is a copy of f_tc_lu_and_mo_ussd_single_request() translated into GSUP AN-APDUs. */
6119
6120 if (false) {
6121 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
6122 invoke_id := 5, /* Phone may not start from 0 or 1 */
6123 op_code := SS_OP_CODE_PROCESS_USS_REQ,
6124 ussd_string := "*#100#"
6125 );
6126
6127 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
6128 invoke_id := 5, /* InvokeID shall be the same for both REQ and RSP */
6129 op_code := SS_OP_CODE_PROCESS_USS_REQ,
6130 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
6131 )
6132
6133 /* Compose a new SS/REGISTER message with request */
6134 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
6135 tid := 1, /* We just need a single transaction */
6136 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
6137 facility := valueof(facility_req)
6138 );
6139 var PDU_ML3_MS_NW ussd_req_v := valueof(ussd_req);
6140
6141 /* Compose SS/RELEASE_COMPLETE template with expected response */
6142 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
6143 tid := 1, /* Response should arrive within the same transaction */
6144 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
6145 facility := valueof(facility_rsp)
6146 );
6147
6148 /* Compose expected MSC -> HLR message */
6149 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
6150 imsi := g_pars.imsi,
6151 state := OSMO_GSUP_SESSION_STATE_BEGIN,
6152 ss := valueof(facility_req)
6153 );
6154
6155 /* To be used for sending response with correct session ID */
6156 var GSUP_PDU gsup_req_complete;
6157
6158 /* Request own number */
6159 /* From remote MSC instead of BSSAP directly */
6160 /* Patch the correct N_SD value into the message. */
6161 var octetstring l3_enc := enc_PDU_ML3_MS_NW(ussd_req_v);
6162 var RAN_Emulation.ConnectionData cd;
6163 f_ML3_patch_seq_nr_MS_NW(f_next_n_sd(last_n_sd, f_ML3_n_sd_idx(ussd_req_v)), l3_enc);
6164 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PROCESS_ACCESS_SIGNALLING_REQUEST,
6165 pars.imsi, remote_msc_name, local_msc_name,
6166 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
6167 enc_PDU_BSSAP(valueof(ts_BSSAP_DTAP(l3_enc)))
6168 ))
6169 ));
6170
6171 /* Expect GSUP message containing the SS payload */
6172 gsup_req_complete := f_expect_gsup_msg(gsup_req);
6173
6174 /* Compose the response from HLR using received session ID */
6175 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
6176 imsi := g_pars.imsi,
6177 sid := gsup_req_complete.ies[1].val.session_id,
6178 state := OSMO_GSUP_SESSION_STATE_END,
6179 ss := valueof(facility_rsp)
6180 );
6181
6182 /* Finally, HLR terminates the session */
6183 GSUP.send(gsup_rsp);
6184
6185 /* The USSD response goes out to remote MSC, on GSUP E instead of BSSAP */
6186 var GSUP_PDU gsup_ussd_rsp;
6187 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_FORWARD_ACCESS_SIGNALLING_REQUEST,
6188 pars.imsi, destination_name := remote_msc_name)) -> value gsup_ussd_rsp;
6189
6190 var GSUP_IeValue an_apdu;
6191 if (not f_gsup_find_ie(gsup_ussd_rsp, OSMO_GSUP_AN_APDU_IE, an_apdu)) {
6192 setverdict(fail, "No AN-APDU in received GSUP message. Expected USSD response in DTAP, got", gsup_ussd_rsp);
6193 mtc.stop;
6194 }
6195 var PDU_BSSAP bssap_dtap_mt := dec_PDU_BSSAP(an_apdu.an_apdu.pdu);
6196 var PDU_ML3_NW_MS dtap_mt := dec_PDU_ML3_NW_MS(bssap_dtap_mt.pdu.dtap);
6197 log("Expecting", ussd_rsp);
6198 log("Got", dtap_mt);
6199 if (not match(dtap_mt, ussd_rsp)) {
6200 setverdict(fail, "Unexpected GSUP message. Expected USSD response in DTAP, got", gsup_ussd_rsp);
6201 mtc.stop;
6202 }
6203 }
6204 /**********************************/
6205
6206
6207 /* inter-MSC handover back to the first MSC */
6208 f_create_bssmap_exp_handoverRequest(193);
6209 cil := { cIl_CGI := { ts_BSSMAP_CI_CGI('262'H, '42'H, 23, 42) } };
6210
6211 /* old BSS sends Handover Required, via inter-MSC E link: like
6212 * BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
6213 * but via GSUP */
6214 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_SUBSEQUENT_HANDOVER_REQUEST,
6215 pars.imsi, remote_msc_name, local_msc_name,
6216 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
6217 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverRequired(cause, cil)))
6218 ))
6219 ));
6220
6221 /* MSC asks local BSS to prepare Handover to it */
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006222 f_get_expected_encryption(encryptionInformation, chosenEncryptionAlgorithm, kC128, a5_perm_alg);
Vadim Yanitskiyc5fcb892022-08-04 04:06:07 +07006223 expect_ho_request := tr_BSSMAP_HandoverRequest(encryptionInformation,
6224 chosenEncryptionAlgorithm,
6225 kC128, codecList := ?);
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006226 alt {
Neels Hofmeyr906af102021-07-01 12:08:35 +02006227 [] BSSAP.receive(expect_ho_request) -> value ho_request;
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006228 [] BSSAP.receive(tr_BSSMAP_HandoverRequest) -> value ho_request {
6229 log("Error: Wrong handoverRequest received. Expected: ", expect_ho_request,
6230 " got ", ho_request);
6231 setverdict(fail, "Wrong handoverRequest received");
6232 mtc.stop;
6233 }
6234 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006235
6236 /* Make sure the new BSSAP conn continues with the correct N_SD sequence numbers */
6237 f_bssmap_continue_after_n_sd(last_n_sd);
6238
6239 /* new BSS composes a RR Handover Command */
6240 rr_ho_cmd := valueof(ts_RR_HandoverCommand);
6241 rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006242 var BSSMAP_IE_AoIP_TransportLayerAddress tla :=
6243 valueof(f_ts_BSSMAP_IE_AoIP_TLA(cpars.bss_rtp_ip, cpars.bss_rtp_port));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006244 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
Neels Hofmeyr906af102021-07-01 12:08:35 +02006245 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR}),
6246 chosenEncryptionAlgorithm := ho_request.pdu.bssmap.handoverRequest.chosenEncryptionAlgorithm));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006247
6248 /* HandoverCommand goes out via remote MSC-I */
6249 var GSUP_PDU prep_subsq_ho_res;
6250 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_SUBSEQUENT_HANDOVER_RESULT,
6251 pars.imsi, destination_name := remote_msc_name)) -> value prep_subsq_ho_res;
6252
6253 /* MS shows up at the local BSS */
6254 BSSAP.send(ts_BSSMAP_HandoverDetect);
6255 f_sleep(0.1);
6256 BSSAP.send(ts_BSSMAP_HandoverComplete);
6257
6258 /* Handover Succeeded message */
6259 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_FORWARD_ACCESS_SIGNALLING_REQUEST,
6260 pars.imsi, destination_name := remote_msc_name));
6261
6262 /* MS has handovered to here, Clear Command goes out via remote MSC-I -- in form of a GSUP Close. */
6263 GSUP.receive(tr_GSUP_E_NO_PDU(OSMO_GSUP_MSGT_E_CLOSE,
6264 pars.imsi, destination_name := remote_msc_name));
6265
6266 /* Handover ends successfully. Call goes on for a little longer and then we hang up. */
6267
6268 f_sleep(1.0);
6269 deactivate(ack_mdcx);
6270
6271 /* FIXME: the inter-MSC call has put a number of MNCC messages in the queue, which above code should expect and
6272 * clear out. The f_call_hangup() expects an MNCC_REL_IND, so, for the time being, just clear the MNCC messages
6273 * before starting the call hangup. Instead of this, the individual messages should be tested for above. */
6274 MNCC.clear;
6275
6276 var default ccrel := activate(as_optional_cc_rel(cpars, true));
6277 f_call_hangup(cpars, true);
6278 f_sleep(1.0);
6279 deactivate(ccrel);
6280
6281 setverdict(pass);
6282}
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006283function f_tc_ho_inter_msc_out_a5(integer a5_n) runs on MTC_CT {
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006284 var BSC_ConnHdlr vc_conn;
6285 f_init(1);
6286
6287 var BSC_ConnHdlrPars pars := f_init_pars(54);
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006288 pars.net.expect_ciph := a5_n > 0;
6289 pars.net.expect_auth := pars.net.expect_ciph;
6290 pars.net.kc_support := bit2oct('00000001'B << a5_n);
6291 pars.cm2.classmarkInformationType2_oct5.a5_3 := '1'B;
6292 pars.cm2.classmarkInformationType2_oct5.a5_2 := '0'B;
6293 pars.cm2.classmarkInformationType2_oct5.cm3 := '1'B;
6294 pars.cm3 := valueof(ts_CM3_default);
6295 pars.use_umts_aka := true;
6296
6297 if (a5_n > 0) {
6298 f_vty_config(MSCVTY, "network", "authentication required");
6299 }
6300 f_vty_config(MSCVTY, "network", "encryption a5 " & int2str(a5_n));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006301
Neels Hofmeyr60122f82021-07-28 17:59:38 +02006302 vc_conn := f_start_handler_with_pars(refers(f_tc_ho_inter_msc_out), pars);
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006303 vc_conn.done;
6304}
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006305testcase TC_ho_inter_msc_out() runs on MTC_CT {
6306 f_tc_ho_inter_msc_out_a5(0);
6307}
6308testcase TC_ho_inter_msc_out_a5_1() runs on MTC_CT {
6309 f_tc_ho_inter_msc_out_a5(1);
6310}
6311testcase TC_ho_inter_msc_out_a5_3() runs on MTC_CT {
6312 f_tc_ho_inter_msc_out_a5(3);
6313}
6314testcase TC_ho_inter_msc_out_a5_4() runs on MTC_CT {
6315 f_tc_ho_inter_msc_out_a5(4);
6316}
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006317testcase TC_ho_inter_msc_out_ipv6() runs on MTC_CT {
6318 var BSC_ConnHdlr vc_conn;
6319 f_init(1);
6320
6321 var BSC_ConnHdlrPars pars := f_init_pars(54);
6322 pars.use_ipv6 := true;
6323
Neels Hofmeyr60122f82021-07-28 17:59:38 +02006324 vc_conn := f_start_handler_with_pars(refers(f_tc_ho_inter_msc_out), pars);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006325 vc_conn.done;
6326}
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006327
Oliver Smith1d118ff2019-07-03 10:57:35 +02006328private function f_tc_lu_imsi_auth_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6329 pars.net.expect_auth := true;
6330 pars.net.expect_imei := true;
6331 f_init_handler(pars);
6332 f_perform_lu();
6333}
6334testcase TC_lu_imsi_auth_tmsi_check_imei() runs on MTC_CT {
6335 var BSC_ConnHdlr vc_conn;
6336 f_init();
6337 f_vty_config(MSCVTY, "network", "authentication required");
6338 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6339
6340 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei), 5);
6341 vc_conn.done;
6342}
6343
6344private function f_tc_lu_imsi_auth3g_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6345 pars.net.expect_auth := true;
6346 pars.use_umts_aka := true;
6347 pars.net.expect_imei := true;
6348 f_init_handler(pars);
6349 f_perform_lu();
6350}
6351testcase TC_lu_imsi_auth3g_tmsi_check_imei() runs on MTC_CT {
6352 var BSC_ConnHdlr vc_conn;
6353 f_init();
6354 f_vty_config(MSCVTY, "network", "authentication required");
6355 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6356
6357 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi_check_imei), 5);
6358 vc_conn.done;
6359}
6360
6361private function f_tc_lu_imsi_noauth_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6362 pars.net.expect_imei := true;
6363 f_init_handler(pars);
6364 f_perform_lu();
6365}
6366testcase TC_lu_imsi_noauth_tmsi_check_imei() runs on MTC_CT {
6367 var BSC_ConnHdlr vc_conn;
6368 f_init();
6369 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6370
6371 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi_check_imei), 5);
6372 vc_conn.done;
6373}
6374
6375private function f_tc_lu_imsi_noauth_notmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6376 pars.net.expect_tmsi := false;
6377 pars.net.expect_imei := true;
6378 f_init_handler(pars);
6379 f_perform_lu();
6380}
6381testcase TC_lu_imsi_noauth_notmsi_check_imei() runs on MTC_CT {
6382 var BSC_ConnHdlr vc_conn;
6383 f_init();
6384 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
6385 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6386
6387 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi_check_imei), 5);
6388 vc_conn.done;
6389}
6390
6391private function f_tc_lu_imsi_auth_tmsi_check_imei_nack(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6392 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02006393
6394 pars.net.expect_auth := true;
6395 pars.net.expect_imei := true;
6396 pars.net.check_imei_result := OSMO_GSUP_IMEI_RESULT_NACK;
6397 f_init_handler(pars);
6398
6399 /* Cannot use f_perform_lu() as we expect a reject */
6400 l3_lu := f_build_lu_imsi(g_pars.imsi)
6401 f_create_gsup_expect(hex2str(g_pars.imsi));
6402 f_bssap_compl_l3(l3_lu);
6403 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
6404
6405 f_mm_common();
6406 f_msc_lu_hlr();
6407 f_mm_imei();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02006408 f_expect_lu_reject();
Eric Wild85cc1612022-03-30 01:44:29 +02006409 f_expect_clear(verify_vlr_cell_id:=false);
Oliver Smith1d118ff2019-07-03 10:57:35 +02006410}
6411testcase TC_lu_imsi_auth_tmsi_check_imei_nack() runs on MTC_CT {
6412 var BSC_ConnHdlr vc_conn;
6413 f_init();
6414 f_vty_config(MSCVTY, "network", "authentication required");
6415 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6416
6417 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_nack), 5);
6418 vc_conn.done;
6419}
6420
6421private function f_tc_lu_imsi_auth_tmsi_check_imei_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6422 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02006423
6424 pars.net.expect_auth := true;
6425 pars.net.expect_imei := true;
6426 pars.net.check_imei_error := true;
6427 f_init_handler(pars);
6428
6429 /* Cannot use f_perform_lu() as we expect a reject */
6430 l3_lu := f_build_lu_imsi(g_pars.imsi)
6431 f_create_gsup_expect(hex2str(g_pars.imsi));
6432 f_bssap_compl_l3(l3_lu);
6433 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
6434
6435 f_mm_common();
6436 f_msc_lu_hlr();
6437 f_mm_imei();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02006438 f_expect_lu_reject();
Eric Wild85cc1612022-03-30 01:44:29 +02006439 f_expect_clear(verify_vlr_cell_id:=false);
Oliver Smith1d118ff2019-07-03 10:57:35 +02006440}
6441testcase TC_lu_imsi_auth_tmsi_check_imei_err() runs on MTC_CT {
6442 var BSC_ConnHdlr vc_conn;
6443 f_init();
6444 f_vty_config(MSCVTY, "network", "authentication required");
6445 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6446
6447 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_err), 5);
6448 vc_conn.done;
6449}
6450
6451private function f_tc_lu_imsi_auth_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6452 pars.net.expect_auth := true;
6453 pars.net.expect_imei_early := true;
6454 f_init_handler(pars);
6455 f_perform_lu();
6456}
6457testcase TC_lu_imsi_auth_tmsi_check_imei_early() runs on MTC_CT {
6458 var BSC_ConnHdlr vc_conn;
6459 f_init();
6460 f_vty_config(MSCVTY, "network", "authentication required");
6461 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6462
6463 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early), 5);
6464 vc_conn.done;
6465}
6466
6467private function f_tc_lu_imsi_auth3g_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6468 pars.net.expect_auth := true;
6469 pars.use_umts_aka := true;
6470 pars.net.expect_imei_early := true;
6471 f_init_handler(pars);
6472 f_perform_lu();
6473}
6474testcase TC_lu_imsi_auth3g_tmsi_check_imei_early() runs on MTC_CT {
6475 var BSC_ConnHdlr vc_conn;
6476 f_init();
6477 f_vty_config(MSCVTY, "network", "authentication required");
6478 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6479
6480 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi_check_imei_early), 5);
6481 vc_conn.done;
6482}
6483
6484private function f_tc_lu_imsi_noauth_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6485 pars.net.expect_imei_early := true;
6486 f_init_handler(pars);
6487 f_perform_lu();
6488}
6489testcase TC_lu_imsi_noauth_tmsi_check_imei_early() runs on MTC_CT {
6490 var BSC_ConnHdlr vc_conn;
6491 f_init();
6492 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6493
6494 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi_check_imei_early), 5);
6495 vc_conn.done;
6496}
6497
6498private function f_tc_lu_imsi_noauth_notmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6499 pars.net.expect_tmsi := false;
6500 pars.net.expect_imei_early := true;
6501 f_init_handler(pars);
6502 f_perform_lu();
6503}
6504testcase TC_lu_imsi_noauth_notmsi_check_imei_early() runs on MTC_CT {
6505 var BSC_ConnHdlr vc_conn;
6506 f_init();
6507 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
6508 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6509
6510 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi_check_imei_early), 5);
6511 vc_conn.done;
6512}
6513
6514private function f_tc_lu_imsi_auth_tmsi_check_imei_early_nack(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6515 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02006516
6517 pars.net.expect_auth := true;
6518 pars.net.expect_imei_early := true;
6519 pars.net.check_imei_result := OSMO_GSUP_IMEI_RESULT_NACK;
6520 f_init_handler(pars);
6521
6522 /* Cannot use f_perform_lu() as we expect a reject */
6523 l3_lu := f_build_lu_imsi(g_pars.imsi)
6524 f_create_gsup_expect(hex2str(g_pars.imsi));
6525 f_bssap_compl_l3(l3_lu);
6526 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
6527
6528 f_mm_imei_early();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02006529 f_expect_lu_reject();
Eric Wild85cc1612022-03-30 01:44:29 +02006530 f_expect_clear(verify_vlr_cell_id:=false);
Oliver Smith1d118ff2019-07-03 10:57:35 +02006531}
6532testcase TC_lu_imsi_auth_tmsi_check_imei_early_nack() runs on MTC_CT {
6533 var BSC_ConnHdlr vc_conn;
6534 f_init();
6535 f_vty_config(MSCVTY, "network", "authentication required");
6536 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6537
6538 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early_nack), 5);
6539 vc_conn.done;
6540}
6541
6542private function f_tc_lu_imsi_auth_tmsi_check_imei_early_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6543 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02006544
6545 pars.net.expect_auth := true;
6546 pars.net.expect_imei_early := true;
6547 pars.net.check_imei_error := true;
6548 f_init_handler(pars);
6549
6550 /* Cannot use f_perform_lu() as we expect a reject */
6551 l3_lu := f_build_lu_imsi(g_pars.imsi)
6552 f_create_gsup_expect(hex2str(g_pars.imsi));
6553 f_bssap_compl_l3(l3_lu);
6554 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
6555
6556 f_mm_imei_early();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02006557 f_expect_lu_reject();
Eric Wild85cc1612022-03-30 01:44:29 +02006558 f_expect_clear(verify_vlr_cell_id:=false);
Oliver Smith1d118ff2019-07-03 10:57:35 +02006559}
6560testcase TC_lu_imsi_auth_tmsi_check_imei_early_err() runs on MTC_CT {
6561 var BSC_ConnHdlr vc_conn;
6562 f_init();
6563 f_vty_config(MSCVTY, "network", "authentication required");
6564 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6565
6566 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early_err), 5);
6567 vc_conn.done;
6568}
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006569
Neels Hofmeyr8df69622019-11-02 19:16:03 +01006570friend function f_tc_invalid_mgcp_crash(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6571 f_init_handler(pars);
6572 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
6573
6574 /* Set invalid IP address so that osmo-msc discards the rtp_stream and MGCP endpoint FSM instances in the middle
6575 * of successful MGCP response dispatch. If things aren't safeguarded, the on_success() in osmo_mgcpc_ep_fsm
6576 * will cause a use-after-free after that event dispatch. */
6577 cpars.mgw_conn_1.mgw_rtp_ip := "0.0.0.0";
6578 cpars.mgw_conn_2.mgw_rtp_ip := "0.0.0.0";
6579 cpars.rtp_sdp_format := "FOO/8000";
6580 cpars.expect_release := true;
6581
6582 f_perform_lu();
6583 f_mo_call_establish(cpars);
6584}
6585testcase TC_invalid_mgcp_crash() runs on MTC_CT {
6586 var BSC_ConnHdlr vc_conn;
6587 f_init();
6588
6589 vc_conn := f_start_handler(refers(f_tc_invalid_mgcp_crash), 7);
6590 vc_conn.done;
6591}
6592
Vadim Yanitskiyeddebaa2019-12-28 17:45:34 +01006593friend function f_tc_mm_id_resp_no_identity(charstring id, BSC_ConnHdlrPars pars)
6594runs on BSC_ConnHdlr {
6595 pars.tmsi := 'FFFFFFFF'O;
6596 f_init_handler(pars);
6597
6598 f_create_gsup_expect(hex2str(g_pars.imsi));
6599
6600 /* Initiate Location Updating using an unknown TMSI */
6601 f_bssap_compl_l3(f_build_lu_tmsi(pars.tmsi));
6602
6603 /* Expect an Identity Request, send response with no identity */
6604 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
6605 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp({
6606 lengthIndicator := 1,
6607 mobileIdentityV := {
6608 typeOfIdentity := '000'B,
6609 oddEvenInd_identity := {
6610 no_identity := {
6611 oddevenIndicator := '0'B,
6612 fillerDigits := '00000'H
6613 }
6614 }
6615 }
6616 })));
6617
6618 f_expect_lu_reject();
6619 f_expect_clear();
6620}
6621testcase TC_mm_id_resp_no_identity() runs on MTC_CT {
6622 var BSC_ConnHdlr vc_conn;
6623
6624 f_init();
6625
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02006626 vc_conn := f_start_handler(refers(f_tc_mm_id_resp_no_identity), 7, verify_cell_id := false);
Vadim Yanitskiyeddebaa2019-12-28 17:45:34 +01006627 vc_conn.done;
6628}
6629
Vadim Yanitskiy25219062020-01-21 01:41:33 +07006630/* Verify the case when T3212 expires during Paging procedure, just before the receipt
6631 * of Paging Response. This used to provoke a NULL-pointer dereference in old versions
6632 * of OsmoMSC, but apparently the bug has been fixed, and we're safe now. */
6633friend function f_tc_lu_and_expire_while_paging(charstring id, BSC_ConnHdlrPars pars)
6634runs on BSC_ConnHdlr {
6635 var charstring imsi := hex2str(pars.imsi);
6636
6637 f_init_handler(pars);
6638
6639 /* Perform location update */
6640 f_perform_lu();
6641
6642 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
6643 f_create_gsup_expect(hex2str(g_pars.imsi));
6644
6645 /* Initiate paging procedure from the VTY */
6646 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " paging");
6647 f_expect_paging();
6648
6649 /* Emulate T3212 expiration during paging (we don't want to wait, right?) */
6650 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " expire");
6651
6652 /* MS sends PAGING RESPONSE, *old* OsmoMSC crashes here... */
6653 f_establish_fully(EST_TYPE_PAG_RESP);
6654
6655 /* The recent OsmoMSC keeps subscriber in its VLR unless the Paging is completed.
6656 * In this case we do not send anything and just wait for a Clear Command. */
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02006657 f_expect_clear(verify_vlr_cell_id := false);
Vadim Yanitskiy25219062020-01-21 01:41:33 +07006658}
6659testcase TC_lu_and_expire_while_paging() runs on MTC_CT {
6660 var BSC_ConnHdlr vc_conn;
6661
6662 f_init();
6663
6664 vc_conn := f_start_handler(refers(f_tc_lu_and_expire_while_paging), 7);
6665 vc_conn.done;
6666}
6667
Neels Hofmeyr4f099b42021-07-27 03:45:26 +02006668const charstring REEST_LOST_CONNECTION := "REEST_LOST_CONNECTION";
6669const charstring REEST_CLEARED := "REEST_CLEARED";
6670
6671friend function f_tc_call_re_establishment_1(charstring id, BSC_ConnHdlrPars pars)
6672 runs on BSC_ConnHdlr {
6673 f_init_handler(pars, t_guard := 30.0);
6674
6675 f_perform_lu();
6676
6677 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
6678 f_mo_call_establish(cpars);
6679 f_sleep(3.0);
6680 COORD.send(REEST_LOST_CONNECTION);
6681 COORD.send(cpars);
6682 f_expect_clear(verify_vlr_cell_id := false);
6683 COORD.send(REEST_CLEARED);
6684}
6685
6686friend function f_tc_call_re_establishment_2(charstring id, BSC_ConnHdlrPars pars)
6687 runs on BSC_ConnHdlr {
6688 f_init_handler(pars, t_guard := 30.0);
6689 var CallParameters cpars;
6690
6691 COORD.receive(REEST_LOST_CONNECTION);
6692 COORD.receive(tr_CallParams) -> value cpars;
6693
6694 f_gsup_change_connhdlr(hex2str(g_pars.imsi));
6695 f_create_smpp_expect(hex2str(pars.msisdn));
6696
6697 /* The MS has lost the first channel and decides to show up on a new conn (on a nearby neighbor cell) to ask for
6698 * CM Re-Establishment. Send a Complete Layer 3 to osmo-msc with a CM Re-Establishment Request. */
6699 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
6700 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_REESTABL_REQ(mi));
6701 f_cl3_or_initial_ue(l3_info);
6702
6703 /* At this point the other test component should receive the Clear Command for the first A connection. */
6704
6705 /* This new connection continues with Authentication... */
6706 f_mm_common();
6707
6708 /* ...and with Assignment of a voice channel. */
6709 var template BSSMAP_IE_AoIP_TransportLayerAddress tla_ass :=
Neels Hofmeyr02d513e2022-07-25 22:07:24 +02006710 (f_tr_BSSMAP_IE_AoIP_TLA(cpars.mgw_conn_1.mgw_rtp_ip, ?),
6711 f_tr_BSSMAP_IE_AoIP_TLA(cpars.mgw_conn_2.mgw_rtp_ip, ?));
Neels Hofmeyr4f099b42021-07-27 03:45:26 +02006712 BSSAP.receive(tr_BSSMAP_AssignmentReq(omit, tla_ass));
6713 /* By this Assignment Request, the CM Re-Establishment Request is implicitly accepted. */
6714
6715 /* Send Assignment Complete from BSC */
6716 var template BSSMAP_IE_AoIP_TransportLayerAddress tla;
6717 tla := f_ts_BSSMAP_IE_AoIP_TLA(cpars.bss_rtp_ip, cpars.bss_rtp_port);
6718 var BSSMAP_IE_SpeechCodec codec;
6719 codec := valueof(ts_BSSMAP_IE_SpeechCodec({ts_CodecFR}));
6720
6721 /* Make really sure the other component is done with its MGCP */
6722 COORD.receive(REEST_CLEARED);
6723
6724 /* Transfer state for this call over to this test component so we can resolve MNCC and MGCP in this function. */
6725 f_mncc_change_connhdlr(cpars.mncc_callref);
6726 f_mgcp_change_connhdlr(cpars.mgcp_ep);
6727
6728 /* osmo-msc may redirect the MGW endpoint to the newly allocated channel.
6729 * Apparently osmo-msc currently also sends an MDCX to the CN side, just repeating the same configuration that
6730 * is already in use. This test accepts any number of or even lack of MDCX. */
6731 var default ack_mdcx := activate(as_mgcp_ack_all_mdcx(cpars));
6732
6733 BSSAP.send(ts_BSSMAP_AssignmentComplete(omit, tla, codec));
6734 /* The call has been fully re-established.
6735 * Let a bit of time pass before hanging up, for everything to settle. */
6736 f_sleep(3.0);
6737
6738 deactivate(ack_mdcx);
6739
6740 /* Hang up the call and clear the new, second A connection */
6741 var default ack_dlcx := activate(as_mgcp_ack_all_dlcx(cpars));
6742
6743 /* CC release. This is the proper MS initiated release sequence as shown by
6744 * https://git.osmocom.org/osmo-msc/tree/doc/sequence_charts/voice_call_full.msc?id=e53ecde83e4fb2470209e818e9ad76a2d6a19190
6745 * f_call_hangup() seems a bit mixed up, so here a "proper" sequence. Fix of f_call_hangup() pending. */
6746 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_DISC(cpars.transaction_id, '0'B, '0000000'B)));
6747 MNCC.receive(tr_MNCC_DISC_ind(cpars.mncc_callref));
6748 MNCC.send(ts_MNCC_REL_req(cpars.mncc_callref, valueof(ts_MNCC_cause(23))));
6749 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id)));
6750 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id, '0'B)));
6751 MNCC.receive(tr_MNCC_REL_cnf(cpars.mncc_callref, cause := *));
6752
6753 /* BSSAP clear */
6754 interleave {
6755 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {
6756 BSSAP.send(ts_BSSMAP_ClearComplete);
6757 }
6758 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND);
6759 }
6760
6761 f_sleep(1.0);
6762 deactivate(ack_dlcx);
6763}
6764
6765testcase TC_call_re_establishment() runs on MTC_CT {
6766 var BSC_ConnHdlr vc_conn1;
6767 var BSC_ConnHdlr vc_conn2;
6768 f_init();
6769
6770 var BSC_ConnHdlrPars pars1 := f_init_pars(91);
6771 var BSC_ConnHdlrPars pars2 := pars1;
6772
6773 vc_conn1 := f_start_handler_create(pars1);
6774 vc_conn2 := f_start_handler_create(pars2);
6775 connect(vc_conn1:COORD, vc_conn2:COORD);
6776 f_start_handler_run(vc_conn1, refers(f_tc_call_re_establishment_1), pars1);
6777 f_start_handler_run(vc_conn2, refers(f_tc_call_re_establishment_2), pars2);
6778 vc_conn1.done;
6779 vc_conn2.done;
6780}
6781
Neels Hofmeyra9b2dcf2021-07-28 00:57:58 +02006782testcase TC_call_re_establishment_auth() runs on MTC_CT {
6783 var BSC_ConnHdlr vc_conn1;
6784 var BSC_ConnHdlr vc_conn2;
6785 f_init();
6786
6787 f_vty_config(MSCVTY, "network", "authentication required");
6788
6789 var BSC_ConnHdlrPars pars1 := f_init_pars(92);
6790 pars1.net.expect_auth := true;
6791 var BSC_ConnHdlrPars pars2 := pars1;
6792
6793 vc_conn1 := f_start_handler_create(pars1);
6794 vc_conn2 := f_start_handler_create(pars2);
6795 connect(vc_conn1:COORD, vc_conn2:COORD);
6796 f_start_handler_run(vc_conn1, refers(f_tc_call_re_establishment_1), pars1);
6797 f_start_handler_run(vc_conn2, refers(f_tc_call_re_establishment_2), pars2);
6798 vc_conn1.done;
6799 vc_conn2.done;
6800}
6801
Neels Hofmeyr48e4d7d2021-07-28 00:57:58 +02006802testcase TC_call_re_establishment_ciph() runs on MTC_CT {
6803 var BSC_ConnHdlr vc_conn1;
6804 var BSC_ConnHdlr vc_conn2;
6805 f_init();
6806
6807 f_vty_config(MSCVTY, "network", "authentication required");
6808 f_vty_config(MSCVTY, "network", "encryption a5 3");
6809
6810 var BSC_ConnHdlrPars pars1 := f_init_pars(92);
6811 pars1.net.expect_auth := true;
6812 pars1.net.expect_ciph := true;
6813 pars1.net.kc_support := '08'O; /* A5/3 only */
6814 var BSC_ConnHdlrPars pars2 := pars1;
6815
6816 vc_conn1 := f_start_handler_create(pars1);
6817 vc_conn2 := f_start_handler_create(pars2);
6818 connect(vc_conn1:COORD, vc_conn2:COORD);
6819 f_start_handler_run(vc_conn1, refers(f_tc_call_re_establishment_1), pars1);
6820 f_start_handler_run(vc_conn2, refers(f_tc_call_re_establishment_2), pars2);
6821 vc_conn1.done;
6822 vc_conn2.done;
6823}
6824
Neels Hofmeyr07ea7f22022-05-05 01:39:26 +02006825/* Establish a conn with a valid Mobile Identity. Then send a CM Service Request containing a mismatching Mobile
6826 * Identity on the same conn. Caused a crash, see OS#5532. */
6827friend function f_tc_cm_serv_wrong_mi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6828 f_init_handler(pars);
6829
6830 /* Set up a fully identified conn */
6831 f_perform_lu();
6832 f_establish_fully();
6833
6834 /* CM Serv Req with mismatching Mobile Identity */
6835 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(f_gen_imsi(99999))); /* ensure it is different from below*/
6836 BSSAP.send(ts_PDU_DTAP_MO(ts_CM_SERV_REQ(CM_TYPE_MO_SMS, mi)));
6837 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ));
6838
6839 /* Cancel the first CM Service from f_establish_fully() */
6840 BSSAP.send(ts_BSSMAP_ClearRequest(0));
6841
6842 f_expect_clear();
6843}
6844testcase TC_cm_serv_wrong_mi() runs on MTC_CT {
6845 var BSC_ConnHdlr vc_conn;
6846 f_init();
6847 vc_conn := f_start_handler(refers(f_tc_cm_serv_wrong_mi), 94);
6848 vc_conn.done;
6849}
6850
Harald Weltef6dd64d2017-11-19 12:09:51 +01006851control {
Philipp Maier328d1662018-03-07 10:40:27 +01006852 execute( TC_cr_before_reset() );
Harald Weltea49e36e2018-01-21 19:29:33 +01006853 execute( TC_lu_imsi_noauth_tmsi() );
Harald Welted2328a22018-01-27 14:27:16 +01006854 execute( TC_lu_imsi_noauth_notmsi() );
Harald Weltea49e36e2018-01-21 19:29:33 +01006855 execute( TC_lu_imsi_reject() );
6856 execute( TC_lu_imsi_timeout_gsup() );
Harald Welted2328a22018-01-27 14:27:16 +01006857 execute( TC_lu_imsi_auth_tmsi() );
Harald Welte8a397ae2019-04-21 22:03:37 +02006858 execute( TC_lu_imsi_auth3g_tmsi() );
Pau Espin Pedrold3d54a92019-12-17 17:02:54 +01006859 execute( TC_lu_imsi_timeout_tmsi_realloc() );
Harald Welted2328a22018-01-27 14:27:16 +01006860 execute( TC_cmserv_imsi_unknown() );
Neels Hofmeyr13737fb2020-08-19 13:16:14 +00006861 execute( TC_cmserv_tmsi_unknown() );
Harald Welte2bb825f2018-01-22 11:31:18 +01006862 execute( TC_lu_and_mo_call() );
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006863 execute( TC_lu_and_mo_call_ipv6() );
Pau Espin Pedrola42745c2020-01-10 18:03:28 +01006864 execute( TC_lu_and_mo_call_sccp_tiar_timeout() );
Harald Welte071ed732018-01-23 19:53:52 +01006865 execute( TC_lu_auth_sai_timeout() );
6866 execute( TC_lu_auth_sai_err() );
Harald Weltee1a2f3c2018-01-24 17:28:48 +01006867 execute( TC_lu_clear_request() );
Vadim Yanitskiy109e7552021-02-05 05:36:02 +01006868 execute( TC_mo_call_clear_request() );
6869 execute( TC_mt_call_clear_request() );
Harald Weltee1a2f3c2018-01-24 17:28:48 +01006870 execute( TC_lu_disconnect() );
6871 execute( TC_lu_by_imei() );
6872 execute( TC_lu_by_tmsi_noauth_unknown() );
Neels Hofmeyrfc06c732020-08-19 12:52:28 +00006873 execute( TC_attached_imsi_lu_unknown_tmsi() );
Harald Weltee1a2f3c2018-01-24 17:28:48 +01006874 execute( TC_imsi_detach_by_imsi() );
6875 execute( TC_imsi_detach_by_tmsi() );
6876 execute( TC_imsi_detach_by_imei() );
6877 execute( TC_emerg_call_imei_reject() );
6878 execute( TC_emerg_call_imsi() );
6879 execute( TC_cm_serv_req_vgcs_reject() );
6880 execute( TC_cm_serv_req_vbs_reject() );
6881 execute( TC_cm_serv_req_lcs_reject() );
Harald Welte0195ab12018-01-24 21:50:20 +01006882 execute( TC_cm_reest_req_reject() );
Harald Welte1af6ea82018-01-25 18:33:15 +01006883 execute( TC_lu_auth_2G_fail() );
6884 execute( TC_lu_imsi_auth_tmsi_encr_13_13() );
6885 execute( TC_cl3_no_payload() );
6886 execute( TC_cl3_rnd_payload() );
Harald Welte1852a842018-01-26 22:53:36 +01006887 execute( TC_establish_and_nothing() );
6888 execute( TC_mo_setup_and_nothing() );
6889 execute( TC_mo_crcx_ran_timeout() );
6890 execute( TC_mo_crcx_ran_reject() );
Harald Welted2328a22018-01-27 14:27:16 +01006891 execute( TC_mt_crcx_ran_reject() );
Daniel Willmann8b084372018-02-04 13:35:26 +01006892 execute( TC_mo_setup_and_dtmf_dup() );
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01006893 execute( TC_mt_t310() );
Harald Welte167458a2018-01-27 15:58:16 +01006894 execute( TC_gsup_cancel() );
Harald Welte9de84792018-01-28 01:06:35 +01006895 execute( TC_lu_imsi_auth_tmsi_encr_1_13() );
6896 execute( TC_lu_imsi_auth_tmsi_encr_3_13() );
6897 execute( TC_lu_imsi_auth_tmsi_encr_3_1() );
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01006898 execute( TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() );
Harald Welte9de84792018-01-28 01:06:35 +01006899 execute( TC_lu_imsi_auth_tmsi_encr_13_2() );
6900 execute( TC_lu_imsi_auth_tmsi_encr_013_2() );
Eric Wild26f4a622021-05-17 15:27:05 +02006901 execute( TC_lu_imsi_auth_tmsi_encr_0134_1() );
6902 execute( TC_lu_imsi_auth_tmsi_encr_0134_34() );
6903 execute( TC_lu_imsi_auth_tmsi_encr_0134_34_no_cm3() );
6904
Philipp Maier94f3f1b2018-03-15 18:54:13 +01006905 execute( TC_mo_release_timeout() );
Philipp Maier2a98a732018-03-19 16:06:12 +01006906 execute( TC_lu_and_mt_call_no_dlcx_resp() );
Philipp Maier75932982018-03-27 14:52:35 +02006907 execute( TC_reset_two() );
Harald Welte33ec09b2018-02-10 15:34:46 +01006908
6909 execute( TC_lu_and_mt_call() );
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006910 execute( TC_lu_and_mt_call_ipv6() );
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01006911 execute( TC_lu_and_mt_call_already_paging() );
Pau Espin Pedrol9a732a42020-09-15 15:56:33 +02006912 execute( TC_lu_and_mt_call_osmux() );
Harald Welte33ec09b2018-02-10 15:34:46 +01006913
Harald Weltef45efeb2018-04-09 18:19:24 +02006914 execute( TC_lu_and_mo_sms() );
6915 execute( TC_lu_and_mt_sms() );
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01006916 execute( TC_lu_and_mt_sms_already_paging() );
Philipp Maier3983e702018-11-22 19:01:33 +01006917 execute( TC_lu_and_mt_sms_paging_and_nothing() );
Alexander Couzensfc02f242019-09-12 03:43:18 +02006918 execute( TC_lu_and_mt_sms_paging_repeated() );
Harald Weltef640a012018-04-14 17:49:21 +02006919 execute( TC_smpp_mo_sms() );
Vadim Yanitskiy33820762020-01-15 11:26:07 +07006920 execute( TC_smpp_mo_sms_rp_error() );
Harald Weltef640a012018-04-14 17:49:21 +02006921 execute( TC_smpp_mt_sms() );
Harald Weltef45efeb2018-04-09 18:19:24 +02006922
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07006923 execute( TC_gsup_mo_sms() );
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07006924 execute( TC_gsup_mo_smma() );
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07006925 execute( TC_gsup_mt_sms_ack() );
6926 execute( TC_gsup_mt_sms_err() );
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07006927 execute( TC_gsup_mt_sms_rp_mr() );
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07006928 execute( TC_gsup_mo_mt_sms_rp_mr() );
Vadim Yanitskiya2a8a112019-07-08 20:04:32 +07006929 execute( TC_gsup_mt_multi_part_sms() );
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07006930
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07006931 execute( TC_lu_and_mo_ussd_single_request() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07006932 execute( TC_lu_and_mt_ussd_notification() );
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07006933 execute( TC_lu_and_mo_ussd_during_mt_call() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07006934 execute( TC_lu_and_mt_ussd_during_mt_call() );
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07006935 execute( TC_lu_and_mo_ussd_mo_release() );
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07006936 execute( TC_lu_and_ss_session_timeout() );
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07006937
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07006938 execute( TC_mt_ussd_for_unknown_subscr() );
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07006939 execute( TC_mo_ussd_for_unknown_trans() );
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07006940 execute( TC_proc_ss_for_unknown_session() );
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07006941 execute( TC_proc_ss_paging_fail() );
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07006942 execute( TC_proc_ss_abort() );
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07006943
Vadim Yanitskiy1c9754d2020-01-07 21:56:55 +01006944 execute( TC_multi_lu_and_mo_ussd() );
6945 execute( TC_multi_lu_and_mt_ussd() );
6946
Stefan Sperling89eb1f32018-12-17 15:06:20 +01006947 execute( TC_cipher_complete_with_invalid_cipher() );
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01006948 execute( TC_cipher_complete_1_without_cipher() );
6949 execute( TC_cipher_complete_3_without_cipher() );
6950 execute( TC_cipher_complete_13_without_cipher() );
Harald Welteb2284bd2019-05-10 11:30:43 +02006951 execute( TC_lu_with_invalid_mcc_mnc() );
Stefan Sperling89eb1f32018-12-17 15:06:20 +01006952
Harald Welte4263c522018-12-06 11:56:27 +01006953 execute( TC_sgsap_reset() );
6954 execute( TC_sgsap_lu() );
6955 execute( TC_sgsap_lu_imsi_reject() );
6956 execute( TC_sgsap_lu_and_nothing() );
6957 execute( TC_sgsap_expl_imsi_det_eps() );
Philipp Maierfc19f172019-03-21 11:17:54 +01006958 execute( TC_sgsap_impl_imsi_det_eps() );
Harald Welte4263c522018-12-06 11:56:27 +01006959 execute( TC_sgsap_expl_imsi_det_noneps() );
Philipp Maier5d812702019-03-21 10:51:26 +01006960 execute( TC_sgsap_impl_imsi_det_noneps() );
Harald Welte4263c522018-12-06 11:56:27 +01006961 execute( TC_sgsap_paging_rej() );
6962 execute( TC_sgsap_paging_subscr_rej() );
6963 execute( TC_sgsap_paging_ue_unr() );
6964 execute( TC_sgsap_paging_and_nothing() );
6965 execute( TC_sgsap_paging_and_lu() );
6966 execute( TC_sgsap_mt_sms() );
6967 execute( TC_sgsap_mo_sms() );
6968 execute( TC_sgsap_mt_sms_and_nothing() );
6969 execute( TC_sgsap_mt_sms_and_reject() );
6970 execute( TC_sgsap_unexp_ud() );
6971 execute( TC_sgsap_unsol_ud() );
6972 execute( TC_bssap_lu_sgsap_lu_and_mt_call() );
6973 execute( TC_sgsap_lu_and_mt_call() );
Philipp Maier628c0052019-04-09 17:36:57 +02006974 execute( TC_sgsap_vlr_failure() );
Harald Welte4263c522018-12-06 11:56:27 +01006975
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006976 execute( TC_ho_inter_bsc_unknown_cell() );
6977 execute( TC_ho_inter_bsc() );
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02006978 execute( TC_ho_inter_bsc_a5_1() );
6979 execute( TC_ho_inter_bsc_a5_3() );
6980 execute( TC_ho_inter_bsc_a5_4() );
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006981 execute( TC_ho_inter_bsc_ipv6() );
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006982
6983 execute( TC_ho_inter_msc_out() );
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006984 execute( TC_ho_inter_msc_out_a5_1() );
6985 execute( TC_ho_inter_msc_out_a5_3() );
6986 execute( TC_ho_inter_msc_out_a5_4() );
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006987 execute( TC_ho_inter_msc_out_ipv6() );
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006988
Oliver Smith1d118ff2019-07-03 10:57:35 +02006989 execute( TC_lu_imsi_auth_tmsi_check_imei() );
6990 execute( TC_lu_imsi_auth3g_tmsi_check_imei() );
6991 execute( TC_lu_imsi_noauth_tmsi_check_imei() );
6992 execute( TC_lu_imsi_noauth_notmsi_check_imei() );
6993 execute( TC_lu_imsi_auth_tmsi_check_imei_nack() );
6994 execute( TC_lu_imsi_auth_tmsi_check_imei_err() );
6995 execute( TC_lu_imsi_auth_tmsi_check_imei_early() );
6996 execute( TC_lu_imsi_auth3g_tmsi_check_imei_early() );
6997 execute( TC_lu_imsi_noauth_tmsi_check_imei_early() );
6998 execute( TC_lu_imsi_noauth_notmsi_check_imei_early() );
6999 execute( TC_lu_imsi_auth_tmsi_check_imei_early_nack() );
7000 execute( TC_lu_imsi_auth_tmsi_check_imei_early_err() );
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01007001 execute( TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() );
Pau Espin Pedrol609f1d62020-09-15 16:01:55 +02007002
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02007003 execute( TC_mo_cc_bssmap_clear() );
Neels Hofmeyr8df69622019-11-02 19:16:03 +01007004 execute( TC_invalid_mgcp_crash() );
Vadim Yanitskiyeddebaa2019-12-28 17:45:34 +01007005 execute( TC_mm_id_resp_no_identity() );
Vadim Yanitskiy25219062020-01-21 01:41:33 +07007006 execute( TC_lu_and_expire_while_paging() );
Pau Espin Pedrol174fac22021-02-26 13:20:10 +01007007 execute( TC_paging_response_imsi_unknown() );
7008 execute( TC_paging_response_tmsi_unknown() );
Neels Hofmeyr4f099b42021-07-27 03:45:26 +02007009
7010 execute( TC_call_re_establishment() );
Neels Hofmeyra9b2dcf2021-07-28 00:57:58 +02007011 execute( TC_call_re_establishment_auth() );
Neels Hofmeyr48e4d7d2021-07-28 00:57:58 +02007012 execute( TC_call_re_establishment_ciph() );
Neels Hofmeyr07ea7f22022-05-05 01:39:26 +02007013
7014 execute( TC_cm_serv_wrong_mi() );
Harald Weltef6dd64d2017-11-19 12:09:51 +01007015}
7016
7017
7018}