blob: 3a6711b00eb0f5d204d6429d2b8d635ed09a1ef1 [file] [log] [blame]
Harald Weltef6dd64d2017-11-19 12:09:51 +01001module MSC_Tests {
2
Harald Weltee13cfb22019-04-23 16:52:02 +02003friend module MSC_Tests_Iu;
4
Harald Weltef6dd64d2017-11-19 12:09:51 +01005import from General_Types all;
6import from Osmocom_Types all;
7
8import from M3UA_Types all;
9import from M3UA_Emulation all;
10
11import from MTP3asp_Types all;
12import from MTP3asp_PortType all;
13
14import from SCCPasp_Types all;
15import from SCCP_Types all;
16import from SCCP_Emulation all;
17
18import from SCTPasp_Types all;
19import from SCTPasp_PortType all;
20
Harald Weltea49e36e2018-01-21 19:29:33 +010021import from Osmocom_CTRL_Functions all;
22import from Osmocom_CTRL_Types all;
23import from Osmocom_CTRL_Adapter all;
24
Harald Welte3ca1c902018-01-24 18:51:27 +010025import from TELNETasp_PortType all;
26import from Osmocom_VTY_Functions all;
27
Harald Weltea49e36e2018-01-21 19:29:33 +010028import from MNCC_Emulation all;
Harald Welte2bb825f2018-01-22 11:31:18 +010029import from MNCC_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010030
Harald Welte4aa970c2018-01-26 10:38:09 +010031import from MGCP_Emulation all;
32import from MGCP_Types all;
33import from MGCP_Templates all;
34import from SDP_Types all;
35
Harald Weltea49e36e2018-01-21 19:29:33 +010036import from GSUP_Emulation all;
37import from GSUP_Types all;
38import from IPA_Emulation all;
39
Harald Weltef6dd64d2017-11-19 12:09:51 +010040import from BSSAP_Types all;
Harald Welte6811d102019-04-14 22:23:14 +020041import from RAN_Adapter all;
Harald Weltea49e36e2018-01-21 19:29:33 +010042import from BSSAP_CodecPort all;
43import from BSSMAP_Templates all;
Harald Welte6811d102019-04-14 22:23:14 +020044import from RAN_Emulation all;
Harald Weltea49e36e2018-01-21 19:29:33 +010045import from BSC_ConnectionHandler all;
Harald Weltee13cfb22019-04-23 16:52:02 +020046import from RANAP_Templates all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010047
Harald Welte4263c522018-12-06 11:56:27 +010048import from SGsAP_Templates all;
49import from SGsAP_Types all;
50import from SGsAP_Emulation all;
51
Harald Weltea49e36e2018-01-21 19:29:33 +010052import from MobileL3_Types all;
53import from MobileL3_CommonIE_Types all;
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +070054import from MobileL3_SMS_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010055import from L3_Templates all;
Harald Welte158a7ca2018-02-16 18:11:31 +010056import from L3_Common all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010057
Harald Weltef640a012018-04-14 17:49:21 +020058import from SMPP_Types all;
59import from SMPP_Templates all;
60import from SMPP_Emulation all;
61
Stefan Sperlingc307e682018-06-14 15:15:46 +020062import from SCCP_Templates all;
63
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070064import from SS_Types all;
65import from SS_Templates all;
66import from USSD_Helpers all;
Harald Welte4263c522018-12-06 11:56:27 +010067import from DNS_Helpers all;
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070068
Philipp Maier948747b2019-04-02 15:22:33 +020069import from TCCConversion_Functions all;
70
Harald Welte9b751a62019-04-14 17:39:29 +020071const integer NUM_BSC := 3;
Harald Welte6811d102019-04-14 22:23:14 +020072type record of RAN_Configuration RAN_Configurations;
Harald Weltef6dd64d2017-11-19 12:09:51 +010073
Harald Welte4263c522018-12-06 11:56:27 +010074/* Needed for SGsAP SMS */
75import from MobileL3_SMS_Types all;
76
Harald Weltea4ca4462018-02-09 00:17:14 +010077type component MTC_CT extends CTRL_Adapter_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +010078 var boolean g_initialized := false;
Harald Weltea49e36e2018-01-21 19:29:33 +010079
Harald Welte6811d102019-04-14 22:23:14 +020080 var RAN_Adapter g_bssap[NUM_BSC];
Harald Weltea4ca4462018-02-09 00:17:14 +010081
Harald Weltea49e36e2018-01-21 19:29:33 +010082 /* no 'adapter_CT' for MNCC or GSUP */
83 var MNCC_Emulation_CT vc_MNCC;
Harald Welte4aa970c2018-01-26 10:38:09 +010084 var MGCP_Emulation_CT vc_MGCP;
Harald Weltea49e36e2018-01-21 19:29:33 +010085 var GSUP_Emulation_CT vc_GSUP;
86 var IPA_Emulation_CT vc_GSUP_IPA;
Harald Weltef640a012018-04-14 17:49:21 +020087 var SMPP_Emulation_CT vc_SMPP;
Harald Welte4263c522018-12-06 11:56:27 +010088 var SGsAP_Emulation_CT vc_SGsAP;
Harald Weltea49e36e2018-01-21 19:29:33 +010089
90 /* only to get events from IPA underneath GSUP */
91 port IPA_CTRL_PT GSUP_IPA_EVENT;
Harald Welte3ca1c902018-01-24 18:51:27 +010092 /* VTY to MSC */
93 port TELNETasp_PT MSCVTY;
Philipp Maier328d1662018-03-07 10:40:27 +010094
95 /* A port to directly send BSSAP messages. This port is used for
96 * tests that require low level access to sen arbitrary BSSAP
97 * messages. Run f_init_bssap_direct() to connect and initialize */
98 port BSSAP_CODEC_PT BSSAP_DIRECT;
99
100 /* When BSSAP messages are directly sent, then the connection
101 * handler is not active, which means that also no guard timer is
102 * set up. The following timer will serve as a replacement */
103 timer Tguard_direct := 60.0;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100104}
105
106modulepar {
Harald Weltea49e36e2018-01-21 19:29:33 +0100107 /* remote parameters of IUT */
108 charstring mp_msc_ip := "127.0.0.1";
109 integer mp_msc_ctrl_port := 4255;
110 integer mp_msc_vty_port := 4254;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100111
Harald Weltea49e36e2018-01-21 19:29:33 +0100112 /* local parameters of emulated HLR */
Philipp Maier9b690e42018-12-21 11:50:03 +0100113 boolean mp_mm_info := false;
Harald Weltea49e36e2018-01-21 19:29:33 +0100114 charstring mp_hlr_ip := "127.0.0.1";
115 integer mp_hlr_port := 4222;
Harald Welte6126fb02018-01-27 20:08:24 +0100116 charstring mp_mgw_ip := "127.0.0.1";
117 integer mp_mgw_port := 2427;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100118
Harald Weltea49e36e2018-01-21 19:29:33 +0100119 charstring mp_msc_mncc := "/tmp/mncc";
Harald Weltea4ca4462018-02-09 00:17:14 +0100120
Harald Weltef640a012018-04-14 17:49:21 +0200121 integer mp_msc_smpp_port := 2775;
122 charstring mp_smpp_system_id := "msc_tester";
123 charstring mp_smpp_password := "osmocom1";
Harald Welte4263c522018-12-06 11:56:27 +0100124 charstring mp_mme_name := "mmec01.mmegi0001.mme.epc.mnc070.mcc901.3gppnetwork.org";
125 charstring mp_vlr_name := "vlr.example.net";
Harald Weltef640a012018-04-14 17:49:21 +0200126
Harald Welte6811d102019-04-14 22:23:14 +0200127 RAN_Configurations mp_bssap_cfg := {
Philipp Maier75932982018-03-27 14:52:35 +0200128 {
129 sccp_service_type := "mtp3_itu",
130 sctp_addr := { 23905, "127.0.0.1", 2905, "127.0.0.1" },
131 own_pc := 185,
132 own_ssn := 254,
133 peer_pc := 187,
134 peer_ssn := 254,
135 sio := '83'O,
136 rctx := 0
137 },
138 {
139 sccp_service_type := "mtp3_itu",
140 sctp_addr := { 23906, "127.0.0.1", 2905, "127.0.0.1" },
141 own_pc := 186,
142 own_ssn := 254,
143 peer_pc := 187,
144 peer_ssn := 254,
145 sio := '83'O,
146 rctx := 1
147 }
Harald Weltea4ca4462018-02-09 00:17:14 +0100148 };
Harald Weltef6dd64d2017-11-19 12:09:51 +0100149}
150
Philipp Maier328d1662018-03-07 10:40:27 +0100151/* altstep for the global guard timer (only used when BSSAP_DIRECT
152 * is used for communication */
153private altstep as_Tguard_direct() runs on MTC_CT {
154 [] Tguard_direct.timeout {
155 setverdict(fail, "Tguard timeout");
Daniel Willmannafce8662018-07-06 23:11:32 +0200156 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +0100157 }
158}
Harald Weltef6dd64d2017-11-19 12:09:51 +0100159
Neels Hofmeyr2ca1ab42019-03-08 03:45:43 +0100160private altstep as_optional_cc_rel(CallParameters cpars, boolean respond := false) runs on BSC_ConnHdlr {
161 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id))) {
162 if (respond) {
163 var BIT1 tid_remote := '1'B;
164 if (cpars.mo_call) {
165 tid_remote := '0'B;
166 }
167 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id, tid_remote)));
168 }
169 }
Neels Hofmeyrde76f052019-02-26 05:02:46 +0100170}
171
Harald Weltef640a012018-04-14 17:49:21 +0200172function f_init_smpp(charstring id) runs on MTC_CT {
173 id := id & "-SMPP";
174 var EsmePars pars := {
175 mode := MODE_TRANSCEIVER,
176 bind := {
177 system_id := mp_smpp_system_id,
178 password := mp_smpp_password,
179 system_type := "MSC_Tests",
180 interface_version := hex2int('34'H),
181 addr_ton := unknown,
182 addr_npi := unknown,
183 address_range := ""
184 },
185 esme_role := true
186 }
187
188 vc_SMPP := SMPP_Emulation_CT.create(id);
189 map(vc_SMPP:SMPP_PORT, system:SMPP_PORT);
190 vc_SMPP.start(SMPP_Emulation.main_client(pars, mp_msc_ip, mp_msc_smpp_port, "", -1));
191}
192
193
Harald Weltea49e36e2018-01-21 19:29:33 +0100194function f_init_mncc(charstring id) runs on MTC_CT {
195 id := id & "-MNCC";
196 var MnccOps ops := {
197 create_cb := refers(MNCC_Emulation.ExpectedCreateCallback),
198 unitdata_cb := refers(MNCC_Emulation.DummyUnitdataCallback)
199 }
200
201 vc_MNCC := MNCC_Emulation_CT.create(id);
202 map(vc_MNCC:MNCC, system:MNCC_CODEC_PT);
203 vc_MNCC.start(MNCC_Emulation.main(ops, id, mp_msc_mncc));
Harald Weltef6dd64d2017-11-19 12:09:51 +0100204}
205
Harald Welte4aa970c2018-01-26 10:38:09 +0100206function f_init_mgcp(charstring id) runs on MTC_CT {
207 id := id & "-MGCP";
208 var MGCPOps ops := {
209 create_cb := refers(MGCP_Emulation.ExpectedCreateCallback),
210 unitdata_cb := refers(MGCP_Emulation.DummyUnitdataCallback)
211 }
212 var MGCP_conn_parameters pars := {
Harald Welte6126fb02018-01-27 20:08:24 +0100213 callagent_ip := mp_msc_ip,
Harald Welte4aa970c2018-01-26 10:38:09 +0100214 callagent_udp_port := -1,
Harald Welte6126fb02018-01-27 20:08:24 +0100215 mgw_ip := mp_mgw_ip,
216 mgw_udp_port := mp_mgw_port
Harald Welte4aa970c2018-01-26 10:38:09 +0100217 }
218
219 vc_MGCP := MGCP_Emulation_CT.create(id);
220 map(vc_MGCP:MGCP, system:MGCP_CODEC_PT);
221 vc_MGCP.start(MGCP_Emulation.main(ops, pars, id));
222}
223
Philipp Maierc09a1312019-04-09 16:05:26 +0200224function ForwardUnitdataCallback(PDU_SGsAP msg)
225runs on SGsAP_Emulation_CT return template PDU_SGsAP {
226 SGsAP_CLIENT.send(msg);
227 return omit;
228}
229
Harald Welte4263c522018-12-06 11:56:27 +0100230function f_init_sgsap(charstring id) runs on MTC_CT {
231 id := id & "-SGsAP";
232 var SGsAPOps ops := {
233 create_cb := refers(SGsAP_Emulation.ExpectedCreateCallback),
Philipp Maierc09a1312019-04-09 16:05:26 +0200234 unitdata_cb := refers(ForwardUnitdataCallback)
Harald Welte4263c522018-12-06 11:56:27 +0100235 }
236 var SGsAP_conn_parameters pars := {
237 remote_ip := mp_msc_ip,
238 remote_sctp_port := 29118,
239 local_ip := "",
240 local_sctp_port := -1
241 }
242
243 vc_SGsAP := SGsAP_Emulation_CT.create(id);
244 map(vc_SGsAP:SGsAP, system:SGsAP_CODEC_PT);
245 vc_SGsAP.start(SGsAP_Emulation.main(ops, pars, id));
246}
247
248
Harald Weltea49e36e2018-01-21 19:29:33 +0100249function f_init_gsup(charstring id) runs on MTC_CT {
250 id := id & "-GSUP";
251 var GsupOps ops := {
252 create_cb := refers(GSUP_Emulation.ExpectedCreateCallback)
253 }
254
255 vc_GSUP_IPA := IPA_Emulation_CT.create(id & "-IPA");
256 vc_GSUP := GSUP_Emulation_CT.create(id);
257
258 map(vc_GSUP_IPA:IPA_PORT, system:IPA_CODEC_PT);
259 connect(vc_GSUP:GSUP, vc_GSUP_IPA:IPA_GSUP_PORT);
260 /* we use this hack to get events like ASP_IPA_EVENT_UP */
261 connect(vc_GSUP_IPA:IPA_CTRL_PORT, self:GSUP_IPA_EVENT);
262
263 vc_GSUP.start(GSUP_Emulation.main(ops, id));
264 vc_GSUP_IPA.start(IPA_Emulation.main_server(mp_hlr_ip, mp_hlr_port));
265
266 /* wait for incoming connection to GSUP port before proceeding */
267 timer T := 10.0;
268 T.start;
269 alt {
270 [] GSUP_IPA_EVENT.receive(t_ASP_IPA_EVT_UD(ASP_IPA_EVENT_UP)) { }
271 [] T.timeout {
Harald Welte458fd372018-03-21 11:26:23 +0100272 setverdict(fail, "No connection to GSUP Port");
Daniel Willmannafce8662018-07-06 23:11:32 +0200273 mtc.stop
Harald Weltea49e36e2018-01-21 19:29:33 +0100274 }
275 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100276}
277
Philipp Maierc09a1312019-04-09 16:05:26 +0200278function f_init(integer num_bsc := 1, boolean sgsap := false, boolean gsup := true) runs on MTC_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +0100279
280 if (g_initialized == true) {
281 return;
282 }
283 g_initialized := true;
284
Philipp Maier75932982018-03-27 14:52:35 +0200285 if (num_bsc > NUM_BSC) {
Daniel Willmannafce8662018-07-06 23:11:32 +0200286 testcase.stop("excess number of BSC instances requested");
Philipp Maier75932982018-03-27 14:52:35 +0200287 }
288
289 for (var integer i := 0; i < num_bsc; i := i + 1) {
290 if (isbound(mp_bssap_cfg[i])) {
Harald Welte3ca0ce12019-04-23 17:18:48 +0200291 f_ran_adapter_init(g_bssap[i], mp_bssap_cfg[i], "MSC_Test_" & int2str(i), BSC_RanOps);
292 f_ran_adapter_start(g_bssap[i]);
Philipp Maier75932982018-03-27 14:52:35 +0200293 } else {
Daniel Willmannafce8662018-07-06 23:11:32 +0200294 testcase.stop("missing BSSAP configuration");
Philipp Maier75932982018-03-27 14:52:35 +0200295 }
296 }
297
Harald Weltea49e36e2018-01-21 19:29:33 +0100298 f_ipa_ctrl_start(mp_msc_ip, mp_msc_ctrl_port);
299 f_init_mncc("MSC_Test");
Harald Welte4aa970c2018-01-26 10:38:09 +0100300 f_init_mgcp("MSC_Test");
Philipp Maierc09a1312019-04-09 16:05:26 +0200301
302 if (gsup == true) {
303 f_init_gsup("MSC_Test");
304 }
Harald Weltef640a012018-04-14 17:49:21 +0200305 f_init_smpp("MSC_Test");
Philipp Maier57865482019-01-07 18:33:13 +0100306
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100307 if (sgsap == true) {
Philipp Maier57865482019-01-07 18:33:13 +0100308 f_init_sgsap("MSC_Test");
309 }
Harald Welte3ca1c902018-01-24 18:51:27 +0100310
311 map(self:MSCVTY, system:MSCVTY);
312 f_vty_set_prompts(MSCVTY);
313 f_vty_transceive(MSCVTY, "enable");
Harald Welteb14c77a2018-01-25 17:25:44 +0100314
315 /* set some defaults */
316 f_vty_config(MSCVTY, "network", "authentication optional");
317 f_vty_config(MSCVTY, "msc", "assign-tmsi");
318 f_vty_config(MSCVTY, "network", "encryption a5 0");
Harald Weltef6dd64d2017-11-19 12:09:51 +0100319}
320
Philipp Maier328d1662018-03-07 10:40:27 +0100321/* Initialize for a direct connection to BSSAP. This function is an alternative
322 * to f_init() when the high level functions of the BSC_ConnectionHandler are
323 * not needed. */
324function f_init_bssap_direct() runs on MTC_CT {
Harald Welte3ca0ce12019-04-23 17:18:48 +0200325 f_ran_adapter_init(g_bssap[0], mp_bssap_cfg[0], "MSC_Test", omit);
Philipp Maier75932982018-03-27 14:52:35 +0200326 connect(g_bssap[0].vc_SCCP:SCCP_SP_PORT, self:BSSAP_DIRECT);
Philipp Maier328d1662018-03-07 10:40:27 +0100327
328 /* Start guard timer and activate it as default */
329 Tguard_direct.start
330 activate(as_Tguard_direct());
331}
332
Harald Weltef6dd64d2017-11-19 12:09:51 +0100333template PDU_BSSAP ts_BSSAP_BSSMAP := {
334 discriminator := '0'B,
335 spare := '0000000'B,
336 dlci := omit,
337 lengthIndicator := 0, /* overwritten by codec */
338 pdu := ?
339}
340
341template PDU_BSSAP tr_BSSAP_BSSMAP := {
342 discriminator := '0'B,
343 spare := '0000000'B,
344 dlci := omit,
345 lengthIndicator := ?,
346 pdu := {
347 bssmap := ?
348 }
349}
350
351
352type integer BssmapCause;
353
354template (value) BSSMAP_IE_Cause ts_BSSMAP_IE_Cause(BssmapCause val) := {
355 elementIdentifier := '04'O,
356 lengthIndicator := 0,
357 causeValue := int2bit(val, 7),
358 extensionCauseValue := '0'B,
359 spare1 := omit
360}
361
362template (value) PDU_BSSAP ts_BSSMAP_Reset(BssmapCause cause) modifies ts_BSSAP_BSSMAP := {
363 pdu := {
364 bssmap := {
365 reset := {
366 messageType := '30'O,
367 cause := ts_BSSMAP_IE_Cause(cause),
368 a_InterfaceSelectorForReset := omit
369 }
370 }
371 }
372}
373
374template (value) PDU_BSSAP ts_BSSMAP_ResetAck modifies ts_BSSAP_BSSMAP := {
375 pdu := {
376 bssmap := {
377 resetAck := {
378 messageType := '31'O,
379 a_InterfaceSelectorForReset := omit
380 }
381 }
382 }
383}
384
385template PDU_BSSAP tr_BSSMAP_ResetAck modifies tr_BSSAP_BSSMAP := {
386 pdu := {
387 bssmap := {
388 resetAck := {
389 messageType := '31'O,
390 a_InterfaceSelectorForReset := *
391 }
392 }
393 }
394}
395
396template BSSMAP_IE_CellIdentifier ts_BSSMAP_IE_CellID := {
397 elementIdentifier := '05'O,
398 lengthIndicator := 0,
399 cellIdentifierDiscriminator := '0000'B,
400 spare1_4 := '0000'B,
401 cellIdentification := ?
402}
403
404type uint16_t BssmapLAC;
405type uint16_t BssmapCI;
406
407/*
408template BSSMAP_IE_CellIdentifier ts_CellId_CGI(mcc, mnc, lac, ci)
409modifies ts_BSSMAP_IE_CellID := {
410 cellIdentification := {
411 cI_LAC_CGI := {
412 mnc_mcc := FIXME,
413 lac := int2oct(lac, 2),
414 ci := int2oct(ci, 2)
415 }
416 }
417}
418*/
419
420template BSSMAP_IE_CellIdentifier ts_CellID_LAC_CI(BssmapLAC lac, BssmapCI ci)
421modifies ts_BSSMAP_IE_CellID := {
422 cellIdentification := {
423 cI_LAC_CI := {
424 lac := int2oct(lac, 2),
425 ci := int2oct(ci, 2)
426 }
427 }
428}
429
430template BSSMAP_IE_CellIdentifier ts_CellId_CI(BssmapCI ci)
431modifies ts_BSSMAP_IE_CellID := {
432 cellIdentification := {
433 cI_CI := int2oct(ci, 2)
434 }
435}
436
437template BSSMAP_IE_CellIdentifier ts_CellId_none
438modifies ts_BSSMAP_IE_CellID := {
439 cellIdentification := {
440 cI_noCell := ''O
441 }
442}
443
444
445template BSSMAP_IE_Layer3Information ts_BSSMAP_IE_L3Info(octetstring l3info) := {
446 elementIdentifier := '17'O,
447 lengthIndicator := 0,
448 layer3info := l3info
449}
450
451template PDU_BSSAP ts_BSSMAP_ComplL3(BSSMAP_IE_CellIdentifier cell_id, octetstring l3_info)
452modifies ts_BSSAP_BSSMAP := {
453 pdu := {
454 bssmap := {
455 completeLayer3Information := {
456 messageType := '57'O,
457 cellIdentifier := cell_id,
458 layer3Information := ts_BSSMAP_IE_L3Info(l3_info),
459 chosenChannel := omit,
460 lSAIdentifier := omit,
461 aPDU := omit,
462 codecList := omit,
463 redirectAttemptFlag := omit,
464 sendSequenceNumber := omit,
465 iMSI := omit
466 }
467 }
468 }
469}
470
Harald Weltea49e36e2018-01-21 19:29:33 +0100471type function void_fn(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100472
Harald Weltea49e36e2018-01-21 19:29:33 +0100473/* FIXME: move into BSC_ConnectionHandler? */
Harald Welte9b751a62019-04-14 17:39:29 +0200474function f_init_pars(integer imsi_suffix, boolean sgsap := false, boolean gsup := true, integer ran_idx := 0,
475 boolean ran_is_geran := true)
Harald Weltef9abf8d2019-04-21 13:07:17 +0200476runs on MTC_CT return BSC_ConnHdlrPars {
Harald Weltede371492018-01-27 23:44:41 +0100477 var BSC_ConnHdlrNetworkPars net_pars := {
478 kc_support := '0A'O, /* A5/1 and A5/3 enabled */
479 expect_tmsi := true,
480 expect_auth := false,
481 expect_ciph := false
482 };
Harald Weltea49e36e2018-01-21 19:29:33 +0100483 var BSC_ConnHdlrPars pars := {
Harald Weltef9abf8d2019-04-21 13:07:17 +0200484 sccp_addr_own := g_bssap[ran_idx].sccp_addr_own,
485 sccp_addr_peer := g_bssap[ran_idx].sccp_addr_peer,
Harald Welteedbab812018-03-18 16:02:25 +0100486 cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42)),
Harald Welte81b7f9d2018-01-24 19:06:24 +0100487 imei := f_gen_imei(imsi_suffix),
488 imsi := f_gen_imsi(imsi_suffix),
489 msisdn := f_gen_msisdn(imsi_suffix),
Harald Welte256571e2018-01-24 18:47:19 +0100490 tmsi := omit,
Harald Welte9de84792018-01-28 01:06:35 +0100491 cm1 := valueof(ts_CM1),
Harald Welte82600572018-01-21 20:54:08 +0100492 cm2 := valueof(ts_CM2_default),
Harald Welte16114282018-01-24 22:41:21 +0100493 cm3 := omit,
Harald Weltede371492018-01-27 23:44:41 +0100494 vec := omit,
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100495 net := net_pars,
Philipp Maieraeb29a82018-11-08 17:40:53 +0100496 send_early_cm := true,
497 ipa_ctrl_ip := mp_msc_ip,
498 ipa_ctrl_port := mp_msc_ctrl_port,
Philipp Maier9b690e42018-12-21 11:50:03 +0100499 ipa_ctrl_enable := true,
Philipp Maier57865482019-01-07 18:33:13 +0100500 mm_info := mp_mm_info,
Philipp Maierc09a1312019-04-09 16:05:26 +0200501 sgsap_enable := sgsap,
Harald Weltef9abf8d2019-04-21 13:07:17 +0200502 gsup_enable := gsup,
Harald Weltec1f937a2019-04-21 21:19:23 +0200503 ran_idx := ran_idx,
Harald Welte9b751a62019-04-14 17:39:29 +0200504 use_umts_aka := false,
505 ran_is_geran := ran_is_geran
Harald Weltea49e36e2018-01-21 19:29:33 +0100506 };
Harald Weltee13cfb22019-04-23 16:52:02 +0200507 if (not ran_is_geran) {
508 pars.use_umts_aka := true;
509 pars.net.expect_auth := true;
510 }
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100511 return pars;
512}
513
Neels Hofmeyr0ac63152019-05-07 01:20:17 +0200514function f_start_handler_with_pars(void_fn fn, BSC_ConnHdlrPars pars, integer bssap_idx := 0) runs on MTC_CT return BSC_ConnHdlr {
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100515 var BSC_ConnHdlr vc_conn;
Neels Hofmeyr0ac63152019-05-07 01:20:17 +0200516 var charstring id := testcasename() & int2str(bssap_idx);
Harald Weltea49e36e2018-01-21 19:29:33 +0100517
518 vc_conn := BSC_ConnHdlr.create(id);
519 /* BSSMAP part / A interface */
Neels Hofmeyr0ac63152019-05-07 01:20:17 +0200520 connect(vc_conn:BSSAP, g_bssap[pars.ran_idx + bssap_idx].vc_RAN:CLIENT);
521 connect(vc_conn:BSSAP_PROC, g_bssap[pars.ran_idx + bssap_idx].vc_RAN:PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100522 /* MNCC part */
523 connect(vc_conn:MNCC, vc_MNCC:MNCC_CLIENT);
524 connect(vc_conn:MNCC_PROC, vc_MNCC:MNCC_PROC);
Harald Welte4aa970c2018-01-26 10:38:09 +0100525 /* MGCP part */
526 connect(vc_conn:MGCP, vc_MGCP:MGCP_CLIENT);
527 connect(vc_conn:MGCP_PROC, vc_MGCP:MGCP_PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100528 /* GSUP part */
Philipp Maierc09a1312019-04-09 16:05:26 +0200529 if (pars.gsup_enable == true) {
530 connect(vc_conn:GSUP, vc_GSUP:GSUP_CLIENT);
531 connect(vc_conn:GSUP_PROC, vc_GSUP:GSUP_PROC);
532 }
Harald Weltef640a012018-04-14 17:49:21 +0200533 /* SMPP part */
534 connect(vc_conn:SMPP, vc_SMPP:SMPP_CLIENT);
535 connect(vc_conn:SMPP_PROC, vc_SMPP:SMPP_PROC);
Harald Welte4263c522018-12-06 11:56:27 +0100536 /* SGs part */
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100537 if (pars.sgsap_enable == true) {
Philipp Maier57865482019-01-07 18:33:13 +0100538 connect(vc_conn:SGsAP, vc_SGsAP:SGsAP_CLIENT);
539 connect(vc_conn:SGsAP_PROC, vc_SGsAP:SGsAP_PROC);
540 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100541
Harald Weltea10db902018-01-27 12:44:49 +0100542 /* We cannot use vc_conn.start(f_init_handler(fn, id, pars)); as we cannot have
543 * a stand-alone 'derefers()' call, see https://www.eclipse.org/forums/index.php/t/1091364/ */
Harald Weltea49e36e2018-01-21 19:29:33 +0100544 vc_conn.start(derefers(fn)(id, pars));
545 return vc_conn;
546}
547
Harald Welte9b751a62019-04-14 17:39:29 +0200548function f_start_handler(void_fn fn, integer imsi_suffix, integer ran_idx := 0, boolean ran_is_geran := true)
549runs on MTC_CT return BSC_ConnHdlr {
550 return f_start_handler_with_pars(fn, f_init_pars(imsi_suffix, ran_idx := ran_idx, ran_is_geran := ran_is_geran));
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100551}
552
Harald Weltea49e36e2018-01-21 19:29:33 +0100553private function f_tc_lu_imsi_noauth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100554 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100555 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100556}
Harald Weltea49e36e2018-01-21 19:29:33 +0100557testcase TC_lu_imsi_noauth_tmsi() runs on MTC_CT {
558 var BSC_ConnHdlr vc_conn;
559 f_init();
560
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100561 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi), 1);
Harald Weltea49e36e2018-01-21 19:29:33 +0100562 vc_conn.done;
563}
564
565private function f_tc_lu_imsi_noauth_notmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100566 pars.net.expect_tmsi := false;
Harald Weltea10db902018-01-27 12:44:49 +0100567 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100568 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100569}
Harald Weltea49e36e2018-01-21 19:29:33 +0100570testcase TC_lu_imsi_noauth_notmsi() runs on MTC_CT {
571 var BSC_ConnHdlr vc_conn;
572 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100573 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
Harald Weltea49e36e2018-01-21 19:29:33 +0100574
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100575 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi), 2);
Harald Weltea49e36e2018-01-21 19:29:33 +0100576 vc_conn.done;
577}
578
579/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
Harald Weltee13cfb22019-04-23 16:52:02 +0200580friend function f_tc_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100581 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100582 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
583
584 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +0200585 f_cl3_or_initial_ue(l3_lu);
Harald Weltea49e36e2018-01-21 19:29:33 +0100586 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
587 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
588 alt {
Harald Welte5946b332018-03-18 23:32:21 +0100589 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej(int2oct(23,1)))) {
590 f_expect_clear();
591 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100592 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
593 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200594 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100595 }
596 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100597}
598testcase TC_lu_imsi_reject() runs on MTC_CT {
599 var BSC_ConnHdlr vc_conn;
600 f_init();
601
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100602 vc_conn := f_start_handler(refers(f_tc_lu_imsi_reject), 3);
Harald Weltea49e36e2018-01-21 19:29:33 +0100603 vc_conn.done;
604}
605
Harald Weltee13cfb22019-04-23 16:52:02 +0200606
607
Harald Weltea49e36e2018-01-21 19:29:33 +0100608/* Do LU by IMSI, timeout on GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +0200609friend function f_tc_lu_imsi_timeout_gsup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100610 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100611 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
612
613 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +0200614 f_cl3_or_initial_ue(l3_lu);
Harald Weltea49e36e2018-01-21 19:29:33 +0100615 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
616 /* Normally the HLR would need to respond here, but we decide to force a timeout here */
617 alt {
618 /* FIXME: Expect specific reject cause */
Harald Welte5946b332018-03-18 23:32:21 +0100619 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
620 f_expect_clear();
621 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100622 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
623 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200624 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100625 }
626 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100627}
628testcase TC_lu_imsi_timeout_gsup() runs on MTC_CT {
629 var BSC_ConnHdlr vc_conn;
630 f_init();
631
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100632 vc_conn := f_start_handler(refers(f_tc_lu_imsi_timeout_gsup), 4);
Harald Weltea49e36e2018-01-21 19:29:33 +0100633 vc_conn.done;
634}
635
Harald Weltee13cfb22019-04-23 16:52:02 +0200636
Harald Welte7b1b2812018-01-22 21:23:06 +0100637private function f_tc_lu_imsi_auth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100638 pars.net.expect_auth := true;
Harald Weltea10db902018-01-27 12:44:49 +0100639 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100640 f_perform_lu();
Harald Welte7b1b2812018-01-22 21:23:06 +0100641}
642testcase TC_lu_imsi_auth_tmsi() runs on MTC_CT {
643 var BSC_ConnHdlr vc_conn;
644 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100645 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte7b1b2812018-01-22 21:23:06 +0100646
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100647 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi), 5);
Harald Welte7b1b2812018-01-22 21:23:06 +0100648 vc_conn.done;
649}
650
Harald Weltee13cfb22019-04-23 16:52:02 +0200651
652friend function f_tc_lu_imsi_auth3g_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte8a397ae2019-04-21 22:03:37 +0200653 pars.net.expect_auth := true;
654 pars.use_umts_aka := true;
655 f_init_handler(pars);
656 f_perform_lu();
657}
658testcase TC_lu_imsi_auth3g_tmsi() runs on MTC_CT {
659 var BSC_ConnHdlr vc_conn;
660 f_init();
661 f_vty_config(MSCVTY, "network", "authentication required");
662
663 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi), 1005);
664 vc_conn.done;
665}
Harald Weltea49e36e2018-01-21 19:29:33 +0100666
Harald Weltee13cfb22019-04-23 16:52:02 +0200667
Harald Weltea49e36e2018-01-21 19:29:33 +0100668/* Send CM SERVICE REQ for IMSI that has never performed LU before */
Harald Weltee13cfb22019-04-23 16:52:02 +0200669friend function f_tc_cmserv_imsi_unknown(charstring id, BSC_ConnHdlrPars pars)
Harald Weltea49e36e2018-01-21 19:29:33 +0100670runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100671 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100672
673 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welteedbab812018-03-18 16:02:25 +0100674 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
Harald Welte6ed6bf92018-01-24 21:09:15 +0100675 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
Harald Weltea49e36e2018-01-21 19:29:33 +0100676
677 f_create_gsup_expect(hex2str(g_pars.imsi));
678
679 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200680 f_cl3_or_initial_ue(l3_info);
Harald Weltea49e36e2018-01-21 19:29:33 +0100681
682 timer T := 10.0;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100683 T.start;
684 alt {
Harald Weltea49e36e2018-01-21 19:29:33 +0100685 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
686 //[] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_ACC)) { }
Daniel Willmannafce8662018-07-06 23:11:32 +0200687 [] BSSAP.receive {
688 setverdict(fail, "Received unexpected BSSAP");
689 mtc.stop;
690 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100691 [] GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi)) {
692 setverdict(fail, "Unexpected GSUP UL REQ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200693 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100694 }
Daniel Willmannafce8662018-07-06 23:11:32 +0200695 [] T.timeout {
696 setverdict(fail, "Timeout waiting for CM SERV REQ");
697 mtc.stop;
698 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100699 }
700
Harald Welte1ddc7162018-01-27 14:25:46 +0100701 f_expect_clear();
Harald Weltef6dd64d2017-11-19 12:09:51 +0100702}
Harald Weltea49e36e2018-01-21 19:29:33 +0100703testcase TC_cmserv_imsi_unknown() runs on MTC_CT {
704 var BSC_ConnHdlr vc_conn;
705 f_init();
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100706 vc_conn := f_start_handler(refers(f_tc_cmserv_imsi_unknown), 6);
Harald Weltea49e36e2018-01-21 19:29:33 +0100707 vc_conn.done;
708}
709
Harald Weltee13cfb22019-04-23 16:52:02 +0200710
711friend function f_tc_lu_and_mo_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100712 f_init_handler(pars);
Harald Welteb71901a2018-01-26 19:16:05 +0100713 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
714 cpars.bss_rtp_port := 1110;
715 cpars.mgcp_connection_id_bss := '22222'H;
716 cpars.mgcp_connection_id_mss := '33333'H;
Philipp Maierf1e02bb2018-03-15 16:30:00 +0100717 cpars.mgcp_ep := "rtpbridge/1@mgw";
Harald Welte2bb825f2018-01-22 11:31:18 +0100718
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100719 f_perform_lu();
Harald Welteb71901a2018-01-26 19:16:05 +0100720 f_mo_call(cpars);
Harald Welte2bb825f2018-01-22 11:31:18 +0100721}
722testcase TC_lu_and_mo_call() runs on MTC_CT {
723 var BSC_ConnHdlr vc_conn;
724 f_init();
725
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100726 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_call), 7);
Harald Welte071ed732018-01-23 19:53:52 +0100727 vc_conn.done;
728}
729
Harald Weltee13cfb22019-04-23 16:52:02 +0200730
Harald Welte071ed732018-01-23 19:53:52 +0100731/* Test LU (with authentication enabled), where HLR times out sending SAI response */
Harald Weltee13cfb22019-04-23 16:52:02 +0200732friend function f_tc_lu_auth_sai_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100733 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100734
735 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
736 var PDU_DTAP_MT dtap_mt;
737
738 /* tell GSUP dispatcher to send this IMSI to us */
739 f_create_gsup_expect(hex2str(g_pars.imsi));
740
741 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200742 f_cl3_or_initial_ue(l3_lu);
Harald Welte071ed732018-01-23 19:53:52 +0100743
744 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200745 if (pars.ran_is_geran) {
746 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
747 }
Harald Welte071ed732018-01-23 19:53:52 +0100748
749 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
750 /* The HLR would normally return an auth vector here, but we fail to do so. */
751
752 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100753 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100754}
755testcase TC_lu_auth_sai_timeout() runs on MTC_CT {
756 var BSC_ConnHdlr vc_conn;
757 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100758 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100759
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100760 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_timeout), 8);
Harald Welte071ed732018-01-23 19:53:52 +0100761 vc_conn.done;
762}
763
Harald Weltee13cfb22019-04-23 16:52:02 +0200764
Harald Welte071ed732018-01-23 19:53:52 +0100765/* Test LU (with authentication enabled), where HLR rejects sending SAI error */
Harald Weltee13cfb22019-04-23 16:52:02 +0200766friend function f_tc_lu_auth_sai_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100767 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100768
769 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
770 var PDU_DTAP_MT dtap_mt;
771
772 /* tell GSUP dispatcher to send this IMSI to us */
773 f_create_gsup_expect(hex2str(g_pars.imsi));
774
775 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200776 f_cl3_or_initial_ue(l3_lu);
Harald Welte071ed732018-01-23 19:53:52 +0100777
778 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200779 if (pars.ran_is_geran) {
780 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
781 }
Harald Welte071ed732018-01-23 19:53:52 +0100782
783 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
784 GSUP.send(ts_GSUP_SAI_ERR(g_pars.imsi, 13));
785
786 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100787 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100788}
789testcase TC_lu_auth_sai_err() runs on MTC_CT {
790 var BSC_ConnHdlr vc_conn;
791 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100792 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100793
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100794 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_err), 9);
Harald Welte2bb825f2018-01-22 11:31:18 +0100795 vc_conn.done;
796}
Harald Weltea49e36e2018-01-21 19:29:33 +0100797
Harald Weltee13cfb22019-04-23 16:52:02 +0200798
Harald Weltebc881782018-01-23 20:09:15 +0100799/* Test LU but BSC will send a clear request in the middle */
800private function f_tc_lu_clear_request(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100801 f_init_handler(pars);
Harald Weltebc881782018-01-23 20:09:15 +0100802
803 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
804 var PDU_DTAP_MT dtap_mt;
805
806 /* tell GSUP dispatcher to send this IMSI to us */
807 f_create_gsup_expect(hex2str(g_pars.imsi));
808
809 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200810 f_cl3_or_initial_ue(l3_lu);
Harald Weltebc881782018-01-23 20:09:15 +0100811
812 /* Send Early Classmark, just for the fun of it */
813 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
814
815 f_sleep(1.0);
816 /* send clear request in the middle of the LU */
817 BSSAP.send(ts_BSSMAP_ClearRequest(0));
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200818 alt {
819 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { repeat; }
820 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {}
821 }
Harald Weltebc881782018-01-23 20:09:15 +0100822 BSSAP.send(ts_BSSMAP_ClearComplete);
Harald Welte89a32492018-01-27 19:07:28 +0100823 alt {
824 /* See https://osmocom.org/issues/2862 */
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200825 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {
826 setverdict(fail, "Got a second Clear Command, only one expected");
Daniel Willmannafce8662018-07-06 23:11:32 +0200827 mtc.stop;
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200828 repeat;
829 }
Harald Welte6811d102019-04-14 22:23:14 +0200830 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte89a32492018-01-27 19:07:28 +0100831 }
Harald Weltebc881782018-01-23 20:09:15 +0100832 setverdict(pass);
833}
834testcase TC_lu_clear_request() runs on MTC_CT {
835 var BSC_ConnHdlr vc_conn;
836 f_init();
837
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100838 vc_conn := f_start_handler(refers(f_tc_lu_clear_request), 10);
Harald Weltebc881782018-01-23 20:09:15 +0100839 vc_conn.done;
840}
841
Harald Welte66af9e62018-01-24 17:28:21 +0100842/* Test LU but BSC will send a clear request in the middle */
Harald Weltee13cfb22019-04-23 16:52:02 +0200843friend function f_tc_lu_disconnect(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100844 f_init_handler(pars);
Harald Welte66af9e62018-01-24 17:28:21 +0100845
846 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
847 var PDU_DTAP_MT dtap_mt;
848
849 /* tell GSUP dispatcher to send this IMSI to us */
850 f_create_gsup_expect(hex2str(g_pars.imsi));
851
852 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200853 f_cl3_or_initial_ue(l3_lu);
Harald Welte66af9e62018-01-24 17:28:21 +0100854
855 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200856 if (pars.ran_is_geran) {
857 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
858 }
Harald Welte66af9e62018-01-24 17:28:21 +0100859
860 f_sleep(1.0);
861 /* send clear request in the middle of the LU */
Harald Welte6811d102019-04-14 22:23:14 +0200862 BSSAP.send(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_REQ);
Harald Welte66af9e62018-01-24 17:28:21 +0100863 setverdict(pass);
Neels Hofmeyrbb825c92019-03-06 15:35:50 +0100864 f_sleep(1.0);
Harald Welte66af9e62018-01-24 17:28:21 +0100865}
866testcase TC_lu_disconnect() runs on MTC_CT {
867 var BSC_ConnHdlr vc_conn;
868 f_init();
869
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100870 vc_conn := f_start_handler(refers(f_tc_lu_disconnect), 11);
Harald Welte66af9e62018-01-24 17:28:21 +0100871 vc_conn.done;
872}
873
Harald Welteba7b6d92018-01-23 21:32:34 +0100874/* Test LU but with illegal mobile identity type = IMEI */
Harald Weltee13cfb22019-04-23 16:52:02 +0200875friend function f_tc_lu_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100876 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +0100877
Harald Welte256571e2018-01-24 18:47:19 +0100878 var PDU_ML3_MS_NW l3_lu := f_build_lu_imei(g_pars.imei)
Harald Welteba7b6d92018-01-23 21:32:34 +0100879 var PDU_DTAP_MT dtap_mt;
880
881 /* tell GSUP dispatcher to send this IMSI to us */
882 f_create_gsup_expect(hex2str(g_pars.imsi));
883
884 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200885 f_cl3_or_initial_ue(l3_lu);
Harald Welteba7b6d92018-01-23 21:32:34 +0100886
887 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200888 if (pars.ran_is_geran) {
889 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
890 }
Harald Welteba7b6d92018-01-23 21:32:34 +0100891 /* wait for LU reject, ignore any ID REQ */
892 alt {
893 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { }
894 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req)) { repeat; }
895 }
896 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100897 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +0100898}
899testcase TC_lu_by_imei() runs on MTC_CT {
900 var BSC_ConnHdlr vc_conn;
901 f_init();
902
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100903 vc_conn := f_start_handler(refers(f_tc_lu_by_imei), 12);
Harald Welteba7b6d92018-01-23 21:32:34 +0100904 vc_conn.done;
905}
906
Harald Weltee13cfb22019-04-23 16:52:02 +0200907
Harald Welteba7b6d92018-01-23 21:32:34 +0100908/* Test LU by TMSI with unknown TMSI, expect (and answer) ID REQ. */
909private function f_tc_lu_tmsi_noauth_unknown(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Stefan Sperling04fc4bc2018-06-25 17:44:57 +0200910 /* We piggyback a test for an MSC crash on overlong IMSI (OS#2864) onto this test. */
911 var hexstring overlong_imsi := '012345789ABCDEF0123456789ABCDEF'H;
Harald Weltea10db902018-01-27 12:44:49 +0100912 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +0100913
914 var PDU_ML3_MS_NW l3_lu := f_build_lu_tmsi('01020304'O); /* FIXME: Random */
915 var PDU_DTAP_MT dtap_mt;
916
917 /* tell GSUP dispatcher to send this IMSI to us */
918 f_create_gsup_expect(hex2str(g_pars.imsi));
919
920 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200921 f_cl3_or_initial_ue(l3_lu);
Harald Welteba7b6d92018-01-23 21:32:34 +0100922
923 /* Send Early Classmark, just for the fun of it */
924 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
925
926 /* Wait for + respond to ID REQ (IMSI) */
927 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req('001'B)));
Stefan Sperling04fc4bc2018-06-25 17:44:57 +0200928 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(overlong_imsi))); /* test for OS#2864 */
Harald Welteba7b6d92018-01-23 21:32:34 +0100929 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(g_pars.imsi)));
930
931 /* Expect MSC to do UpdateLocation to HLR; respond to it */
932 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
933 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
934 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
935 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
936
937 alt {
Harald Welte7ec4fa82018-01-27 10:57:40 +0100938 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
939 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_TmsiRealloc_Cmpl));
940 }
Harald Welteba7b6d92018-01-23 21:32:34 +0100941 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
942 setverdict(fail, "Expected LU ACK, but received REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200943 mtc.stop;
Harald Welteba7b6d92018-01-23 21:32:34 +0100944 }
945 }
946
Philipp Maier9b690e42018-12-21 11:50:03 +0100947 /* Wait for MM-Information (if enabled) */
948 f_expect_mm_info();
949
Harald Welteba7b6d92018-01-23 21:32:34 +0100950 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100951 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +0100952}
953testcase TC_lu_by_tmsi_noauth_unknown() runs on MTC_CT {
954 var BSC_ConnHdlr vc_conn;
955 f_init();
956
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100957 vc_conn := f_start_handler(refers(f_tc_lu_tmsi_noauth_unknown), 13);
Harald Welteba7b6d92018-01-23 21:32:34 +0100958 vc_conn.done;
959}
960
961
Harald Welte45164da2018-01-24 12:51:27 +0100962/* Test IMSI DETACH (MI=IMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +0200963friend function f_tc_imsi_detach_by_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100964 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +0100965
966 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
967
968 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200969 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +0100970
971 /* Send Early Classmark, just for the fun of it? */
Harald Weltee13cfb22019-04-23 16:52:02 +0200972 if (pars.ran_is_geran) {
973 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
974 }
Harald Welte45164da2018-01-24 12:51:27 +0100975
976 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100977 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +0100978}
979testcase TC_imsi_detach_by_imsi() runs on MTC_CT {
980 var BSC_ConnHdlr vc_conn;
981 f_init();
982
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100983 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imsi), 14);
Harald Welte45164da2018-01-24 12:51:27 +0100984 vc_conn.done;
985}
986
Harald Weltee13cfb22019-04-23 16:52:02 +0200987
Harald Welte45164da2018-01-24 12:51:27 +0100988/* Test IMSI DETACH (MI=TMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +0200989friend function f_tc_imsi_detach_by_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100990 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +0100991
992 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV('01020304'O));
993
994 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200995 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +0100996
997 /* Send Early Classmark, just for the fun of it? */
Harald Weltee13cfb22019-04-23 16:52:02 +0200998 if (pars.ran_is_geran) {
999 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1000 }
Harald Welte45164da2018-01-24 12:51:27 +01001001
1002 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001003 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001004}
1005testcase TC_imsi_detach_by_tmsi() runs on MTC_CT {
1006 var BSC_ConnHdlr vc_conn;
1007 f_init();
1008
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001009 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_tmsi), 15);
Harald Welte45164da2018-01-24 12:51:27 +01001010 vc_conn.done;
1011}
1012
Harald Weltee13cfb22019-04-23 16:52:02 +02001013
Harald Welte45164da2018-01-24 12:51:27 +01001014/* Test IMSI DETACH (MI=IMEI), which is illegal */
Harald Weltee13cfb22019-04-23 16:52:02 +02001015friend function f_tc_imsi_detach_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001016 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001017
Harald Welte256571e2018-01-24 18:47:19 +01001018 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte45164da2018-01-24 12:51:27 +01001019
1020 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001021 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +01001022
1023 /* Send Early Classmark, just for the fun of it? */
Harald Weltee13cfb22019-04-23 16:52:02 +02001024 if (pars.ran_is_geran) {
1025 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1026 }
Harald Welte45164da2018-01-24 12:51:27 +01001027
1028 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001029 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001030}
1031testcase TC_imsi_detach_by_imei() runs on MTC_CT {
1032 var BSC_ConnHdlr vc_conn;
1033 f_init();
1034
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001035 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imei), 16);
Harald Welte45164da2018-01-24 12:51:27 +01001036 vc_conn.done;
1037}
1038
1039
1040/* helper function for an emergency call. caller passes in mobile identity to use */
1041private function f_emerg_call(MobileIdentityLV mi) runs on BSC_ConnHdlr {
Harald Welte0bef21e2018-02-10 09:48:23 +01001042 var CallParameters cpars := valueof(t_CallParams('112'H, 0));
1043 cpars.emergency := true;
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001044 cpars.mgcp_ep := "rtpbridge/1@mgw";
Harald Welte45164da2018-01-24 12:51:27 +01001045
Harald Welte0bef21e2018-02-10 09:48:23 +01001046 f_mo_call(cpars);
Harald Welte45164da2018-01-24 12:51:27 +01001047}
1048
1049/* establish an emergency call by IMEI, no SIM inserted (and hence no IMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +02001050friend function f_tc_emerg_call_imei_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001051 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001052
Harald Welte256571e2018-01-24 18:47:19 +01001053 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001054 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_EMERG_CALL, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001055 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001056 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ('05'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +01001057 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001058}
1059testcase TC_emerg_call_imei_reject() runs on MTC_CT {
1060 var BSC_ConnHdlr vc_conn;
1061 f_init();
1062
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001063 vc_conn := f_start_handler(refers(f_tc_emerg_call_imei_reject), 17);
Harald Welte45164da2018-01-24 12:51:27 +01001064 vc_conn.done;
1065}
1066
Harald Weltee13cfb22019-04-23 16:52:02 +02001067
Harald Welted5b91402018-01-24 18:48:16 +01001068/* establish an emergency call by IMSI, SIM inserted (and hence IMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +02001069friend function f_tc_emerg_call_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001070 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001071 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001072 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001073 /* Then issue emergency call identified by IMSI */
1074 f_emerg_call(valueof(ts_MI_IMSI_LV(g_pars.imsi)));
1075}
1076testcase TC_emerg_call_imsi() runs on MTC_CT {
1077 var BSC_ConnHdlr vc_conn;
1078 f_init();
1079
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001080 vc_conn := f_start_handler(refers(f_tc_emerg_call_imsi), 18);
Harald Welte45164da2018-01-24 12:51:27 +01001081 vc_conn.done;
1082}
1083
Harald Weltee13cfb22019-04-23 16:52:02 +02001084
Harald Welte45164da2018-01-24 12:51:27 +01001085/* CM Service Request for VGCS -> reject */
1086private function f_tc_cm_serv_req_vgcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001087 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001088
1089 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001090 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001091
1092 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001093 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VGCS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001094 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001095 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001096 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001097}
1098testcase TC_cm_serv_req_vgcs_reject() runs on MTC_CT {
1099 var BSC_ConnHdlr vc_conn;
1100 f_init();
1101
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001102 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vgcs_reject), 19);
Harald Welte45164da2018-01-24 12:51:27 +01001103 vc_conn.done;
1104}
1105
1106/* CM Service Request for VBS -> reject */
1107private function f_tc_cm_serv_req_vbs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001108 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001109
1110 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001111 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001112
1113 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001114 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VBS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001115 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001116 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001117 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001118}
1119testcase TC_cm_serv_req_vbs_reject() runs on MTC_CT {
1120 var BSC_ConnHdlr vc_conn;
1121 f_init();
1122
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001123 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vbs_reject), 20);
Harald Welte45164da2018-01-24 12:51:27 +01001124 vc_conn.done;
1125}
1126
1127/* CM Service Request for LCS -> reject */
1128private function f_tc_cm_serv_req_lcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001129 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001130
1131 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001132 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001133
1134 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001135 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_LCS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001136 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001137 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001138 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001139}
1140testcase TC_cm_serv_req_lcs_reject() runs on MTC_CT {
1141 var BSC_ConnHdlr vc_conn;
1142 f_init();
1143
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001144 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_lcs_reject), 21);
Harald Welte45164da2018-01-24 12:51:27 +01001145 vc_conn.done;
1146}
1147
Harald Welte0195ab12018-01-24 21:50:20 +01001148/* CM Re-Establishment Request */
1149private function f_tc_cm_reest_req_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001150 f_init_handler(pars);
Harald Welte0195ab12018-01-24 21:50:20 +01001151
1152 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001153 f_perform_lu();
Harald Welte0195ab12018-01-24 21:50:20 +01001154
1155 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1156 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_REEST_REQ(0, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001157 f_cl3_or_initial_ue(l3_info);
Harald Welte0195ab12018-01-24 21:50:20 +01001158 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001159 f_expect_clear();
Harald Welte0195ab12018-01-24 21:50:20 +01001160}
1161testcase TC_cm_reest_req_reject() runs on MTC_CT {
1162 var BSC_ConnHdlr vc_conn;
1163 f_init();
Harald Welte0195ab12018-01-24 21:50:20 +01001164
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001165 vc_conn := f_start_handler(refers(f_tc_cm_reest_req_reject), 22);
Harald Welte0195ab12018-01-24 21:50:20 +01001166 vc_conn.done;
1167}
1168
Harald Weltec638f4d2018-01-24 22:00:36 +01001169/* Test LU (with authentication enabled), with wrong response from MS */
1170private function f_tc_lu_auth_2G_fail(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001171 f_init_handler(pars);
Harald Weltec638f4d2018-01-24 22:00:36 +01001172
1173 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
1174
1175 /* tell GSUP dispatcher to send this IMSI to us */
1176 f_create_gsup_expect(hex2str(g_pars.imsi));
1177
1178 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001179 f_cl3_or_initial_ue(l3_lu);
Harald Weltec638f4d2018-01-24 22:00:36 +01001180
1181 /* Send Early Classmark, just for the fun of it */
1182 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1183
1184 var AuthVector vec := f_gen_auth_vec_2g();
1185 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G(vec.rand, vec.sres, vec.kc));
1186 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
1187 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
1188
1189 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_AUTH_REQ(vec.rand)));
1190 /* Send back wrong auth response */
1191 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MT_MM_AUTH_RESP_2G('00000000'O)));
1192
1193 /* Expect GSUP AUTH FAIL REP to HLR */
1194 GSUP.receive(tr_GSUP_AUTH_FAIL_IND(g_pars.imsi));
1195
1196 /* Expect LU REJECT with Cause == Illegal MS */
1197 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej('03'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +01001198 f_expect_clear();
Harald Weltec638f4d2018-01-24 22:00:36 +01001199}
1200testcase TC_lu_auth_2G_fail() runs on MTC_CT {
1201 var BSC_ConnHdlr vc_conn;
1202 f_init();
1203 f_vty_config(MSCVTY, "network", "authentication required");
Harald Weltec638f4d2018-01-24 22:00:36 +01001204
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001205 vc_conn := f_start_handler(refers(f_tc_lu_auth_2G_fail), 23);
Harald Weltec638f4d2018-01-24 22:00:36 +01001206 vc_conn.done;
1207}
1208
Harald Weltede371492018-01-27 23:44:41 +01001209/* A5/1 + A5/3 permitted on network side, and MS capable to do it */
Harald Welte16114282018-01-24 22:41:21 +01001210private function f_tc_lu_imsi_auth_tmsi_encr_13_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +01001211 pars.net.expect_auth := true;
1212 pars.net.expect_ciph := true;
Harald Weltea10db902018-01-27 12:44:49 +01001213 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001214 f_perform_lu();
Harald Welte16114282018-01-24 22:41:21 +01001215}
1216testcase TC_lu_imsi_auth_tmsi_encr_13_13() runs on MTC_CT {
1217 var BSC_ConnHdlr vc_conn;
1218 f_init();
1219 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte16114282018-01-24 22:41:21 +01001220 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
1221
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001222 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_13), 24);
Harald Welte16114282018-01-24 22:41:21 +01001223 vc_conn.done;
1224}
1225
Harald Welte1af6ea82018-01-25 18:33:15 +01001226/* Test Complete L3 without payload */
1227private function f_tc_cl3_no_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001228 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001229
1230 /* Send Complete L3 Info with empty L3 frame */
1231 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1232 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, ''O))));
1233
Harald Weltef466eb42018-01-27 14:26:54 +01001234 timer T := 5.0;
1235 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001236 alt {
Harald Welte6811d102019-04-14 22:23:14 +02001237 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte1af6ea82018-01-25 18:33:15 +01001238 /* Expect LU REJECT with Cause == Illegal MS */
Harald Weltebdb3c452018-03-18 22:43:06 +01001239 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
Harald Welte6811d102019-04-14 22:23:14 +02001240 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001241 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001242 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001243 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001244 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001245 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001246 }
1247 setverdict(pass);
1248}
1249testcase TC_cl3_no_payload() runs on MTC_CT {
1250 var BSC_ConnHdlr vc_conn;
1251 f_init();
1252
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001253 vc_conn := f_start_handler(refers(f_tc_cl3_no_payload), 25);
Harald Welte1af6ea82018-01-25 18:33:15 +01001254 vc_conn.done;
1255}
1256
1257/* Test Complete L3 with random payload */
1258private function f_tc_cl3_rnd_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001259 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001260
Daniel Willmannaa14a382018-07-26 08:29:45 +02001261 /* length is limited by PDU_BSSAP length field which includes some
1262 * other fields beside l3info payload. So payl can only be 240 bytes
1263 * Since rnd() returns values < 1 multiply with 241
1264 */
1265 var integer len := float2int(rnd() * 241.0);
Harald Welte1af6ea82018-01-25 18:33:15 +01001266 var octetstring payl := f_rnd_octstring(len);
1267
1268 /* Send Complete L3 Info with empty L3 frame */
1269 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1270 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, payl))));
1271
Harald Weltef466eb42018-01-27 14:26:54 +01001272 timer T := 5.0;
1273 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001274 alt {
1275 /* Immediate disconnect */
Harald Welte6811d102019-04-14 22:23:14 +02001276 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte1af6ea82018-01-25 18:33:15 +01001277 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
Harald Welte6811d102019-04-14 22:23:14 +02001278 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001279 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001280 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001281 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001282 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001283 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001284 }
1285 setverdict(pass);
1286}
1287testcase TC_cl3_rnd_payload() runs on MTC_CT {
1288 var BSC_ConnHdlr vc_conn;
1289 f_init();
1290
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001291 vc_conn := f_start_handler(refers(f_tc_cl3_rnd_payload), 26);
Harald Welte1af6ea82018-01-25 18:33:15 +01001292 vc_conn.done;
1293}
1294
Harald Welte116e4332018-01-26 22:17:48 +01001295/* Test Complete L3 with random payload */
Harald Weltee13cfb22019-04-23 16:52:02 +02001296friend function f_tc_establish_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001297 f_init_handler(pars);
Harald Welte116e4332018-01-26 22:17:48 +01001298
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001299 f_perform_lu();
Harald Welte116e4332018-01-26 22:17:48 +01001300
Harald Welteb9e86fa2018-04-09 18:18:31 +02001301 f_establish_fully();
Daniel Willmann898a7e02018-05-17 12:16:16 +02001302 f_expect_clear(10.0);
Harald Welte116e4332018-01-26 22:17:48 +01001303}
1304testcase TC_establish_and_nothing() runs on MTC_CT {
1305 var BSC_ConnHdlr vc_conn;
1306 f_init();
1307
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001308 vc_conn := f_start_handler(refers(f_tc_establish_and_nothing), 27);
Harald Welte116e4332018-01-26 22:17:48 +01001309 vc_conn.done;
1310}
1311
Harald Weltee13cfb22019-04-23 16:52:02 +02001312
Harald Welte12510c52018-01-26 22:26:24 +01001313/* Test MO Call SETUP with no response from MNCC */
Harald Weltee13cfb22019-04-23 16:52:02 +02001314friend function f_tc_mo_setup_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier109e6aa2018-10-17 10:53:32 +02001315 f_init_handler(pars, 190.0);
Harald Weltea10db902018-01-27 12:44:49 +01001316
Harald Welte12510c52018-01-26 22:26:24 +01001317 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1318
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001319 f_perform_lu();
Harald Welte12510c52018-01-26 22:26:24 +01001320
Harald Welteb9e86fa2018-04-09 18:18:31 +02001321 f_establish_fully();
Harald Welte12510c52018-01-26 22:26:24 +01001322 f_create_mncc_expect(hex2str(cpars.called_party));
1323 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1324
1325 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
1326
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001327 var default ccrel := activate(as_optional_cc_rel(cpars));
1328
Philipp Maier109e6aa2018-10-17 10:53:32 +02001329 f_expect_clear(185.0);
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001330
1331 deactivate(ccrel);
1332
1333 f_sleep(1.0);
Harald Welte12510c52018-01-26 22:26:24 +01001334}
1335testcase TC_mo_setup_and_nothing() runs on MTC_CT {
1336 var BSC_ConnHdlr vc_conn;
1337 f_init();
1338
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001339 vc_conn := f_start_handler(refers(f_tc_mo_setup_and_nothing), 28);
Harald Welte12510c52018-01-26 22:26:24 +01001340 vc_conn.done;
1341}
1342
Harald Weltee13cfb22019-04-23 16:52:02 +02001343
Harald Welte3ab88002018-01-26 22:37:25 +01001344/* Test MO Call with no response to RAN-side CRCX */
Harald Weltee13cfb22019-04-23 16:52:02 +02001345friend function f_tc_mo_crcx_ran_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001346 f_init_handler(pars);
Harald Welte3ab88002018-01-26 22:37:25 +01001347 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1348 var MNCC_PDU mncc;
1349 var MgcpCommand mgcp_cmd;
1350
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001351 f_perform_lu();
Harald Welte3ab88002018-01-26 22:37:25 +01001352
Harald Welteb9e86fa2018-04-09 18:18:31 +02001353 f_establish_fully();
Harald Welte3ab88002018-01-26 22:37:25 +01001354 f_create_mncc_expect(hex2str(cpars.called_party));
1355 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1356
1357 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
1358 MNCC.receive(tr_MNCC_SETUP_ind(?, tr_MNCC_number(hex2str(cpars.called_party)))) -> value mncc;
1359 cpars.mncc_callref := mncc.u.signal.callref;
1360 MNCC.send(ts_MNCC_CALL_PROC_req(cpars.mncc_callref, cpars.mncc_bearer_cap));
1361 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_CALL_PROC(cpars.transaction_id)));
1362
1363 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
Harald Welte1852a842018-01-26 22:53:36 +01001364 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
1365 cpars.mgcp_ep := mgcp_cmd.line.ep;
Harald Welte3ab88002018-01-26 22:37:25 +01001366 /* never respond to this */
1367
Philipp Maier8e58f592018-03-14 11:10:56 +01001368 /* When the connection with the MGW fails, the MSC will first request
1369 * a release via call control. We will answer this request normally. */
1370 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id)));
1371 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id)));
1372
Harald Welte1ddc7162018-01-27 14:25:46 +01001373 f_expect_clear(30.0);
Harald Welte3ab88002018-01-26 22:37:25 +01001374}
1375testcase TC_mo_crcx_ran_timeout() runs on MTC_CT {
1376 var BSC_ConnHdlr vc_conn;
1377 f_init();
1378
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001379 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_timeout), 29);
Harald Welte3ab88002018-01-26 22:37:25 +01001380 vc_conn.done;
1381}
1382
Harald Weltee13cfb22019-04-23 16:52:02 +02001383
Harald Welte0cc82d92018-01-26 22:52:34 +01001384/* Test MO Call with reject to RAN-side CRCX */
Harald Weltee13cfb22019-04-23 16:52:02 +02001385friend function f_tc_mo_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001386 f_init_handler(pars);
Harald Welte0cc82d92018-01-26 22:52:34 +01001387 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1388 var MNCC_PDU mncc;
1389 var MgcpCommand mgcp_cmd;
1390
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001391 f_perform_lu();
Harald Welte0cc82d92018-01-26 22:52:34 +01001392
Harald Welteb9e86fa2018-04-09 18:18:31 +02001393 f_establish_fully();
Harald Welte0cc82d92018-01-26 22:52:34 +01001394 f_create_mncc_expect(hex2str(cpars.called_party));
1395 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1396
1397 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
1398 MNCC.receive(tr_MNCC_SETUP_ind(?, tr_MNCC_number(hex2str(cpars.called_party)))) -> value mncc;
1399 cpars.mncc_callref := mncc.u.signal.callref;
1400 MNCC.send(ts_MNCC_CALL_PROC_req(cpars.mncc_callref, cpars.mncc_bearer_cap));
1401 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_CALL_PROC(cpars.transaction_id)));
1402
1403 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001404
1405 /* Detect if the received CRCX is a wildcarded CRCX request. If yes,
1406 * set an endpoint name that fits the pattern. If not, just use the
1407 * endpoint name from the request */
1408 if (match(mgcp_cmd.line.ep, t_MGCP_EP_wildcard)) {
1409 cpars.mgcp_ep := "rtpbridge/1@mgw";
1410 } else {
1411 cpars.mgcp_ep := mgcp_cmd.line.ep;
1412 }
1413
Harald Welte0cc82d92018-01-26 22:52:34 +01001414 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001415
Harald Welte0cc82d92018-01-26 22:52:34 +01001416 /* Respond to CRCX with error */
1417 var MgcpResponse mgcp_rsp := {
1418 line := {
1419 code := "542",
1420 trans_id := mgcp_cmd.line.trans_id,
1421 string := "FORCED_FAIL"
1422 },
Harald Welte0cc82d92018-01-26 22:52:34 +01001423 sdp := omit
1424 }
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001425 var MgcpParameter mgcp_rsp_param := {
1426 code := "Z",
1427 val := cpars.mgcp_ep
1428 };
1429 mgcp_rsp.params[0] := mgcp_rsp_param;
Harald Welte0cc82d92018-01-26 22:52:34 +01001430 MGCP.send(mgcp_rsp);
1431
1432 timer T := 30.0;
1433 T.start;
1434 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001435 [] T.timeout {
1436 setverdict(fail, "Timeout waiting for channel release");
1437 mtc.stop;
1438 }
Daniel Willmann5868e622018-02-15 17:42:59 +01001439 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id))) {
1440 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id)));
1441 repeat;
1442 }
Harald Welte0cc82d92018-01-26 22:52:34 +01001443 [] MNCC.receive { repeat; }
1444 [] GSUP.receive { repeat; }
Philipp Maierc6e06f72018-04-11 18:12:23 +02001445 /* Note: As we did not respond properly to the CRCX from the MSC we
1446 * expect the MSC to omit any further MGCP operation (At least in the
1447 * the current implementation, there is no recovery mechanism implemented
1448 * and a DLCX can not be performed as the MSC does not know a specific
1449 * endpoint yet. */
Daniel Willmannafce8662018-07-06 23:11:32 +02001450 [] MGCP.receive {
1451 setverdict(fail, "Unexpected MGCP message");
1452 mtc.stop;
1453 }
Harald Welte5946b332018-03-18 23:32:21 +01001454 [] as_clear_cmd_compl_disc();
Harald Welte0cc82d92018-01-26 22:52:34 +01001455 }
1456}
1457testcase TC_mo_crcx_ran_reject() runs on MTC_CT {
1458 var BSC_ConnHdlr vc_conn;
1459 f_init();
1460
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001461 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_reject), 30);
Harald Welte0cc82d92018-01-26 22:52:34 +01001462 vc_conn.done;
1463}
1464
Harald Welte3ab88002018-01-26 22:37:25 +01001465
Harald Welte812f7a42018-01-27 00:49:18 +01001466/* helper function to start a MT call: MNCC SETUP; Paging; DChan est.; DTAP SETUP */
1467private function f_mt_call_start(inout CallParameters cpars) runs on BSC_ConnHdlr {
1468 var MNCC_PDU mncc;
1469 var MgcpCommand mgcp_cmd;
1470 var OCT4 tmsi;
1471
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001472 f_perform_lu();
Harald Welte812f7a42018-01-27 00:49:18 +01001473 if (isvalue(g_pars.tmsi)) {
1474 tmsi := g_pars.tmsi;
1475 } else {
1476 tmsi := 'FFFFFFFF'O;
1477 }
Harald Welte6811d102019-04-14 22:23:14 +02001478 f_ran_register_imsi(g_pars.imsi, tmsi);
Harald Welte812f7a42018-01-27 00:49:18 +01001479
1480 /* Allocate call reference and send SETUP via MNCC to MSC */
1481 cpars.mncc_callref := f_rnd_int(2147483648);
1482 MNCC.send(ts_MNCC_SETUP_req(cpars.mncc_callref, hex2str(g_pars.msisdn),
1483 hex2str(cpars.called_party), hex2str(g_pars.imsi)));
1484
1485 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02001486 f_expect_paging();
1487
Harald Welte812f7a42018-01-27 00:49:18 +01001488 /* MS -> MSC: PAGING RESPONSE */
Harald Welteb9e86fa2018-04-09 18:18:31 +02001489 f_establish_fully(EST_TYPE_PAG_RESP);
Harald Welte812f7a42018-01-27 00:49:18 +01001490
1491 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1492
1493 /* MSC->MS: SETUP */
1494 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_SETUP(cpars.transaction_id, *, cpars.called_party)));
1495}
1496
1497/* Test MT Call */
Harald Weltee13cfb22019-04-23 16:52:02 +02001498friend function f_tc_mt_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001499 f_init_handler(pars);
Harald Welte812f7a42018-01-27 00:49:18 +01001500 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1501 var MNCC_PDU mncc;
1502 var MgcpCommand mgcp_cmd;
1503
1504 f_mt_call_start(cpars);
1505
1506 /* MS->MSC: CALL CONFIRMED */
1507 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1508
1509 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1510
1511 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1512 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001513
1514 /* Detect if the received CRCX is a wildcarded CRCX request. If yes,
1515 * set an endpoint name that fits the pattern. If not, just use the
1516 * endpoint name from the request */
1517 if (match(mgcp_cmd.line.ep, t_MGCP_EP_wildcard)) {
1518 cpars.mgcp_ep := "rtpbridge/1@mgw";
1519 } else {
1520 cpars.mgcp_ep := mgcp_cmd.line.ep;
1521 }
1522
Harald Welte812f7a42018-01-27 00:49:18 +01001523 /* Respond to CRCX with error */
1524 var MgcpResponse mgcp_rsp := {
1525 line := {
1526 code := "542",
1527 trans_id := mgcp_cmd.line.trans_id,
1528 string := "FORCED_FAIL"
1529 },
Harald Welte812f7a42018-01-27 00:49:18 +01001530 sdp := omit
1531 }
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001532 var MgcpParameter mgcp_rsp_param := {
1533 code := "Z",
1534 val := cpars.mgcp_ep
1535 };
1536 mgcp_rsp.params[0] := mgcp_rsp_param;
Harald Welte812f7a42018-01-27 00:49:18 +01001537 MGCP.send(mgcp_rsp);
1538
1539 timer T := 30.0;
1540 T.start;
1541 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001542 [] T.timeout {
1543 setverdict(fail, "Timeout waiting for channel release");
1544 mtc.stop;
1545 }
Harald Welte812f7a42018-01-27 00:49:18 +01001546 [] MNCC.receive { repeat; }
1547 [] GSUP.receive { repeat; }
1548 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1549 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
1550 f_create_mgcp_delete_ep(cpars.mgcp_ep);
1551 repeat;
1552 }
1553 [] MGCP.receive { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001554 [] as_clear_cmd_compl_disc();
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001555 [] as_optional_cc_rel(cpars);
Harald Welte812f7a42018-01-27 00:49:18 +01001556 }
1557}
1558testcase TC_mt_crcx_ran_reject() runs on MTC_CT {
1559 var BSC_ConnHdlr vc_conn;
1560 f_init();
1561
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001562 vc_conn := f_start_handler(refers(f_tc_mt_crcx_ran_reject), 31);
Harald Welte812f7a42018-01-27 00:49:18 +01001563 vc_conn.done;
1564}
1565
1566
Harald Weltee13cfb22019-04-23 16:52:02 +02001567
Harald Welte812f7a42018-01-27 00:49:18 +01001568/* Test MT Call T310 timer */
Harald Weltee13cfb22019-04-23 16:52:02 +02001569friend function f_tc_mt_t310(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltead2952e2018-01-27 14:12:46 +01001570 f_init_handler(pars, 200.0);
Harald Welte812f7a42018-01-27 00:49:18 +01001571 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1572 var MNCC_PDU mncc;
1573 var MgcpCommand mgcp_cmd;
1574
1575 f_mt_call_start(cpars);
1576
1577 /* MS->MSC: CALL CONFIRMED */
1578 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1579 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1580
1581 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1582 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
1583 cpars.mgcp_ep := mgcp_cmd.line.ep;
1584 /* FIXME: Respond to CRCX */
1585
1586 /* old libosmocore T310 default timeout is 180s. so let's wait 190 */
1587 timer T := 190.0;
1588 T.start;
1589 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001590 [] T.timeout {
1591 setverdict(fail, "Timeout waiting for T310");
1592 mtc.stop;
1593 }
Harald Welte812f7a42018-01-27 00:49:18 +01001594 [] MNCC.receive(tr_MNCC_DISC_ind(cpars.mncc_callref)) {
1595 MNCC.send(ts_MNCC_REL_req(cpars.mncc_callref, valueof(ts_MNCC_cause(23))));
1596 }
1597 }
1598 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_DISC(cpars.transaction_id)));
1599 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id)));
1600 /* FIXME: We're sending this with TIflag 0: allocated by sender, which is wrong */
1601 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id)));
1602
1603 alt {
Harald Welte812f7a42018-01-27 00:49:18 +01001604 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1605 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
1606 f_create_mgcp_delete_ep(cpars.mgcp_ep);
1607 repeat;
1608 }
Harald Welte5946b332018-03-18 23:32:21 +01001609 [] as_clear_cmd_compl_disc();
Harald Welte812f7a42018-01-27 00:49:18 +01001610 }
1611}
1612testcase TC_mt_t310() runs on MTC_CT {
1613 var BSC_ConnHdlr vc_conn;
1614 f_init();
1615
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001616 vc_conn := f_start_handler(refers(f_tc_mt_t310), 32);
Harald Welte812f7a42018-01-27 00:49:18 +01001617 vc_conn.done;
1618}
1619
Harald Weltee13cfb22019-04-23 16:52:02 +02001620
Harald Welte167458a2018-01-27 15:58:16 +01001621/* Perform successful LU + MO call, then GSUP LocationCancel. Subscriber must be denied CM SERV */
Harald Weltee13cfb22019-04-23 16:52:02 +02001622friend function f_tc_gsup_cancel(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte167458a2018-01-27 15:58:16 +01001623 f_init_handler(pars);
1624 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1625 cpars.bss_rtp_port := 1110;
1626 cpars.mgcp_connection_id_bss := '22222'H;
1627 cpars.mgcp_connection_id_mss := '33333'H;
Daniel Willmann9b0235b2018-07-24 12:13:34 +02001628 cpars.mgcp_ep := "rtpbridge/1@mgw";
Harald Welte167458a2018-01-27 15:58:16 +01001629
1630 /* Location Update to make subscriber known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001631 f_perform_lu();
Harald Welte167458a2018-01-27 15:58:16 +01001632
1633 /* First MO call should succeed */
1634 f_mo_call(cpars);
1635
1636 /* Cancel the subscriber in the VLR */
1637 GSUP.send(ts_GSUP_CL_REQ(g_pars.imsi, OSMO_GSUP_CANCEL_TYPE_WITHDRAW));
1638 alt {
1639 [] GSUP.receive(tr_GSUP_CL_RES(g_pars.imsi)) { }
1640 [] GSUP.receive(tr_GSUP_CL_ERR(g_pars.imsi)) {
1641 setverdict(fail, "Received GSUP Location Cancel Error");
Daniel Willmannafce8662018-07-06 23:11:32 +02001642 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001643 }
1644 }
1645
1646 /* Follow-up transactions should fail */
1647 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1648 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001649 f_cl3_or_initial_ue(l3_info);
Harald Welte167458a2018-01-27 15:58:16 +01001650 alt {
1651 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
1652 [] BSSAP.receive {
1653 setverdict(fail, "Received unexpected BSSAP instead of CM SERV REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +02001654 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001655 }
1656 }
Neels Hofmeyr0f7429a2019-03-07 22:28:41 +01001657
1658 f_expect_clear();
Harald Welte167458a2018-01-27 15:58:16 +01001659 setverdict(pass);
1660}
1661testcase TC_gsup_cancel() runs on MTC_CT {
1662 var BSC_ConnHdlr vc_conn;
1663 f_init();
1664
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001665 vc_conn := f_start_handler(refers(f_tc_gsup_cancel), 33);
Harald Welte167458a2018-01-27 15:58:16 +01001666 vc_conn.done;
1667}
1668
Harald Weltee13cfb22019-04-23 16:52:02 +02001669
Harald Welte9de84792018-01-28 01:06:35 +01001670/* A5/1 only permitted on network side, and MS capable to do it */
1671private function f_tc_lu_imsi_auth_tmsi_encr_1_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1672 pars.net.expect_auth := true;
1673 pars.net.expect_ciph := true;
1674 pars.net.kc_support := '02'O; /* A5/1 only */
1675 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001676 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001677}
1678testcase TC_lu_imsi_auth_tmsi_encr_1_13() runs on MTC_CT {
1679 var BSC_ConnHdlr vc_conn;
1680 f_init();
1681 f_vty_config(MSCVTY, "network", "authentication required");
1682 f_vty_config(MSCVTY, "network", "encryption a5 1");
1683
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001684 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_1_13), 34);
Harald Welte9de84792018-01-28 01:06:35 +01001685 vc_conn.done;
1686}
1687
1688/* A5/3 only permitted on network side, and MS capable to do it */
1689private function f_tc_lu_imsi_auth_tmsi_encr_3_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1690 pars.net.expect_auth := true;
1691 pars.net.expect_ciph := true;
1692 pars.net.kc_support := '08'O; /* A5/3 only */
1693 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001694 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001695}
1696testcase TC_lu_imsi_auth_tmsi_encr_3_13() runs on MTC_CT {
1697 var BSC_ConnHdlr vc_conn;
1698 f_init();
1699 f_vty_config(MSCVTY, "network", "authentication required");
1700 f_vty_config(MSCVTY, "network", "encryption a5 3");
1701
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001702 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_13), 35);
Harald Welte9de84792018-01-28 01:06:35 +01001703 vc_conn.done;
1704}
1705
1706/* A5/3 only permitted on network side, and MS with only A5/1 support */
1707private function f_tc_lu_imsi_auth_tmsi_encr_3_1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1708 pars.net.expect_auth := true;
1709 pars.net.expect_ciph := true;
1710 pars.net.kc_support := '08'O; /* A5/3 only */
1711 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1712 f_init_handler(pars, 15.0);
1713
1714 /* cannot use f_perform_lu() as we expect a reject */
1715 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
1716 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +02001717 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001718 if (pars.send_early_cm) {
1719 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1720 } else {
1721 pars.cm1.esind := '0'B;
1722 }
Harald Welte9de84792018-01-28 01:06:35 +01001723 f_mm_auth();
1724 alt {
Daniel Willmann52918e52018-09-20 14:39:09 +02001725 [] BSSAP.receive(tr_BSSMAP_ClassmarkReq) {
1726 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1727 repeat;
1728 }
Harald Welte5946b332018-03-18 23:32:21 +01001729 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1730 f_expect_clear();
1731 }
Harald Welte9de84792018-01-28 01:06:35 +01001732 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
1733 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02001734 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001735 }
1736 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01001737 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02001738 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001739 }
1740 }
1741 setverdict(pass);
1742}
1743testcase TC_lu_imsi_auth_tmsi_encr_3_1() runs on MTC_CT {
1744 var BSC_ConnHdlr vc_conn;
1745 f_init();
1746 f_vty_config(MSCVTY, "network", "authentication required");
1747 f_vty_config(MSCVTY, "network", "encryption a5 3");
1748
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001749 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 360);
1750 vc_conn.done;
1751}
1752testcase TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() runs on MTC_CT {
1753 var BSC_ConnHdlrPars pars;
1754 var BSC_ConnHdlr vc_conn;
1755 f_init();
1756 f_vty_config(MSCVTY, "network", "authentication required");
1757 f_vty_config(MSCVTY, "network", "encryption a5 3");
1758
1759 pars := f_init_pars(361);
1760 pars.send_early_cm := false;
1761 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), pars);
Harald Welte9de84792018-01-28 01:06:35 +01001762 vc_conn.done;
1763}
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01001764testcase TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() runs on MTC_CT {
1765 var BSC_ConnHdlr vc_conn;
1766 f_init();
1767 f_vty_config(MSCVTY, "network", "authentication required");
1768 f_vty_config(MSCVTY, "network", "encryption a5 3");
1769
1770 /* Make sure the MSC category is on DEBUG level to trigger the log
1771 * message that is reported in OS#2947 to trigger the segfault */
1772 f_vty_config(MSCVTY, "log stderr", "logging level msc debug");
1773
1774 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 362);
1775 vc_conn.done;
1776}
Harald Welte9de84792018-01-28 01:06:35 +01001777
1778/* A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
1779private function f_tc_lu_imsi_auth_tmsi_encr_13_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1780 pars.net.expect_auth := true;
1781 pars.net.expect_ciph := true;
1782 pars.net.kc_support := '0A'O; /* A5/1 + A5/3 */
1783 pars.cm1.a5_1 := '1'B;
1784 pars.cm2.a5_1 := '1'B;
1785 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1786 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
1787 f_init_handler(pars, 15.0);
1788
1789 /* cannot use f_perform_lu() as we expect a reject */
1790 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
1791 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +02001792 f_cl3_or_initial_ue(l3_lu);
Harald Welte9de84792018-01-28 01:06:35 +01001793 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1794 f_mm_auth();
1795 alt {
Harald Welte5946b332018-03-18 23:32:21 +01001796 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1797 f_expect_clear();
1798 }
Harald Welte9de84792018-01-28 01:06:35 +01001799 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
1800 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02001801 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001802 }
1803 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01001804 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02001805 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001806 }
1807 }
1808 setverdict(pass);
1809}
1810testcase TC_lu_imsi_auth_tmsi_encr_13_2() runs on MTC_CT {
1811 var BSC_ConnHdlr vc_conn;
1812 f_init();
1813 f_vty_config(MSCVTY, "network", "authentication required");
1814 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
1815
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001816 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_2), 37);
Harald Welte9de84792018-01-28 01:06:35 +01001817 vc_conn.done;
1818}
1819
1820/* A5/0 + A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
1821private function f_tc_lu_imsi_auth_tmsi_encr_013_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1822 pars.net.expect_auth := true;
1823 pars.net.expect_ciph := true;
1824 pars.net.kc_support := '0B'O; /* A5/1 + A5/3 */
1825 pars.cm1.a5_1 := '1'B;
1826 pars.cm2.a5_1 := '1'B;
1827 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1828 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
1829 f_init_handler(pars, 15.0);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001830 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001831}
1832testcase TC_lu_imsi_auth_tmsi_encr_013_2() runs on MTC_CT {
1833 var BSC_ConnHdlr vc_conn;
1834 f_init();
1835 f_vty_config(MSCVTY, "network", "authentication required");
1836 f_vty_config(MSCVTY, "network", "encryption a5 0 1 3");
1837
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001838 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_013_2), 38);
Harald Welte9de84792018-01-28 01:06:35 +01001839 vc_conn.done;
1840}
1841
Harald Welte33ec09b2018-02-10 15:34:46 +01001842/* LU followed by MT call (including paging) */
1843private function f_tc_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1844 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01001845 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Harald Welte33ec09b2018-02-10 15:34:46 +01001846 cpars.bss_rtp_port := 1110;
1847 cpars.mgcp_connection_id_bss := '10004'H;
1848 cpars.mgcp_connection_id_mss := '10005'H;
1849
Philipp Maier4b2692d2018-03-14 16:37:48 +01001850 /* Note: This is an optional parameter. When the call-agent (MSC) does
1851 * supply a full endpoint name this setting will be overwritten. */
1852 cpars.mgcp_ep := "rtpbridge/1@mgw";
1853
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001854 f_perform_lu();
Harald Welte33ec09b2018-02-10 15:34:46 +01001855 f_mt_call(cpars);
1856}
1857testcase TC_lu_and_mt_call() runs on MTC_CT {
1858 var BSC_ConnHdlr vc_conn;
1859 f_init();
1860
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001861 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call), 39);
Harald Welte33ec09b2018-02-10 15:34:46 +01001862 vc_conn.done;
1863}
1864
Daniel Willmann8b084372018-02-04 13:35:26 +01001865/* Test MO Call SETUP with DTMF */
1866private function f_tc_mo_setup_dtmf_dup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1867 f_init_handler(pars);
1868 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1869 cpars.bss_rtp_port := 1110;
1870 cpars.mgcp_connection_id_bss := '22222'H;
1871 cpars.mgcp_connection_id_mss := '33333'H;
1872
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001873 f_perform_lu();
Daniel Willmann8b084372018-02-04 13:35:26 +01001874 f_mo_seq_dtmf_dup(cpars);
1875}
1876testcase TC_mo_setup_and_dtmf_dup() runs on MTC_CT {
1877 var BSC_ConnHdlr vc_conn;
1878 f_init();
1879
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001880 vc_conn := f_start_handler(refers(f_tc_mo_setup_dtmf_dup), 39);
Daniel Willmann8b084372018-02-04 13:35:26 +01001881 vc_conn.done;
1882}
Harald Welte9de84792018-01-28 01:06:35 +01001883
Philipp Maier328d1662018-03-07 10:40:27 +01001884testcase TC_cr_before_reset() runs on MTC_CT {
1885 timer T := 4.0;
1886 var boolean reset_ack_seen := false;
1887 f_init_bssap_direct();
1888
Harald Welte3ca0ce12019-04-23 17:18:48 +02001889 f_ran_adapter_start(g_bssap[0]);
Daniel Willmann42d1d5b2018-08-07 15:18:41 +02001890
Daniel Willmanne8018962018-08-21 14:18:00 +02001891 f_sleep(3.0);
1892
Philipp Maier328d1662018-03-07 10:40:27 +01001893 /* Make a blind connection attemt, to trigger the deadlock condition */
Philipp Maier75932982018-03-27 14:52:35 +02001894 BSSAP_DIRECT.send(ts_BSSAP_CONNECT_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, 1, omit));
Philipp Maier328d1662018-03-07 10:40:27 +01001895
1896 /* Send a BSSMAP reset */
Philipp Maier75932982018-03-27 14:52:35 +02001897 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_Reset(0)));
Philipp Maier328d1662018-03-07 10:40:27 +01001898 T.start
1899 alt {
1900 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_ResetAck)) {
1901 reset_ack_seen := true;
1902 repeat;
1903 }
1904
1905 /* Acknowledge MSC sided reset requests */
1906 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_Reset)) {
Philipp Maier75932982018-03-27 14:52:35 +02001907 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_ResetAck));
Philipp Maier328d1662018-03-07 10:40:27 +01001908 repeat;
1909 }
1910
1911 /* Ignore all other messages (e.g CR from the connection request) */
1912 [] BSSAP_DIRECT.receive { repeat }
1913
1914 /* If we got no BSSMAP RESET ACK back, then the MSC entered the
1915 * deadlock situation. The MSC is then unable to respond to any
1916 * further BSSMAP RESET or any other sort of traffic. */
1917 [reset_ack_seen == true] T.timeout { setverdict(pass) }
1918 [reset_ack_seen == false] T.timeout {
1919 setverdict(fail, "no BSSMAP RESET ACK seen!");
Daniel Willmannafce8662018-07-06 23:11:32 +02001920 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +01001921 }
1922 }
1923}
Harald Welte9de84792018-01-28 01:06:35 +01001924
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001925/* Test MO Call with no response to RAN-side CRCX or DTAP Release */
Harald Weltee13cfb22019-04-23 16:52:02 +02001926friend function f_tc_mo_release_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001927 f_init_handler(pars);
1928 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1929 var MNCC_PDU mncc;
1930 var MgcpCommand mgcp_cmd;
1931
1932 f_perform_lu();
1933
Harald Welteb9e86fa2018-04-09 18:18:31 +02001934 f_establish_fully();
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001935 f_create_mncc_expect(hex2str(cpars.called_party));
1936 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1937
1938 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
1939 MNCC.receive(tr_MNCC_SETUP_ind(?, tr_MNCC_number(hex2str(cpars.called_party)))) -> value mncc;
1940 cpars.mncc_callref := mncc.u.signal.callref;
1941 MNCC.send(ts_MNCC_CALL_PROC_req(cpars.mncc_callref, cpars.mncc_bearer_cap));
1942 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_CALL_PROC(cpars.transaction_id)));
1943
1944 /* Drop CRCX */
1945 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1946
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001947 var default ccrel := activate(as_optional_cc_rel(cpars));
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001948
1949 f_expect_clear(60.0);
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001950
1951 deactivate(ccrel);
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001952}
1953testcase TC_mo_release_timeout() runs on MTC_CT {
1954 var BSC_ConnHdlr vc_conn;
1955 f_init();
1956
1957 vc_conn := f_start_handler(refers(f_tc_mo_release_timeout), 40);
1958 vc_conn.done;
1959}
1960
Harald Welte12510c52018-01-26 22:26:24 +01001961
Philipp Maier2a98a732018-03-19 16:06:12 +01001962/* LU followed by MT call (including paging) */
1963private function f_tc_lu_and_mt_call_no_dlcx_resp(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1964 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01001965 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Philipp Maier2a98a732018-03-19 16:06:12 +01001966 cpars.bss_rtp_port := 1110;
1967 cpars.mgcp_connection_id_bss := '10004'H;
1968 cpars.mgcp_connection_id_mss := '10005'H;
1969
1970 /* Note: This is an optional parameter. When the call-agent (MSC) does
1971 * supply a full endpoint name this setting will be overwritten. */
1972 cpars.mgcp_ep := "rtpbridge/1@mgw";
1973
1974 /* Intentionally disable the CRCX response */
1975 cpars.mgw_drop_dlcx := true;
1976
1977 /* Perform location update and call */
1978 f_perform_lu();
1979 f_mt_call(cpars);
1980}
1981testcase TC_lu_and_mt_call_no_dlcx_resp() runs on MTC_CT {
1982 var BSC_ConnHdlr vc_conn;
1983 f_init();
1984
1985 /* Perform an almost normal looking locationupdate + mt-call, but do
1986 * not respond to the DLCX at the end of the call */
1987 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call_no_dlcx_resp), 41);
1988 vc_conn.done;
1989
1990 /* Wait a guard period until the MGCP layer in the MSC times out,
1991 * if the MSC is vulnerable to the use-after-free situation that is
1992 * fixed by I78f1b6a9149488a4ad3f120c1e190a83c07d4b89 then it should
1993 * segfault now */
1994 f_sleep(6.0);
1995
1996 /* Run the init procedures once more. If the MSC has crashed, this
1997 * this will fail */
1998 f_init();
1999}
Harald Welte45164da2018-01-24 12:51:27 +01002000
Philipp Maier75932982018-03-27 14:52:35 +02002001/* Two BSSMAP resets from two different BSCs */
2002testcase TC_reset_two() runs on MTC_CT {
2003 var BSC_ConnHdlr vc_conn;
2004 f_init(2);
2005 f_sleep(2.0);
2006 setverdict(pass);
2007}
2008
Harald Weltee13cfb22019-04-23 16:52:02 +02002009/* Two BSSMAP resets from two different BSCs plus one IuCS RANAP Reset */
2010testcase TC_reset_two_1iu() runs on MTC_CT {
2011 var BSC_ConnHdlr vc_conn;
2012 f_init(3);
2013 f_sleep(2.0);
2014 setverdict(pass);
2015}
2016
Harald Weltef640a012018-04-14 17:49:21 +02002017/***********************************************************************
2018 * SMS Testing
2019 ***********************************************************************/
2020
Harald Weltef45efeb2018-04-09 18:19:24 +02002021/* LU followed by MO SMS */
Harald Weltee13cfb22019-04-23 16:52:02 +02002022friend function f_tc_lu_and_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02002023 var SmsParameters spars := valueof(t_SmsPars);
2024
2025 f_init_handler(pars);
2026
2027 /* Perform location update and call */
2028 f_perform_lu();
2029
2030 f_establish_fully(EST_TYPE_MO_SMS);
2031
2032 //spars.exp_rp_err := 96; /* invalid mandatory information */
2033 f_mo_sms(spars);
2034
2035 f_expect_clear();
2036}
2037testcase TC_lu_and_mo_sms() runs on MTC_CT {
2038 var BSC_ConnHdlr vc_conn;
2039 f_init();
2040 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_sms), 42);
2041 vc_conn.done;
2042}
2043
Harald Weltee13cfb22019-04-23 16:52:02 +02002044
Harald Weltef45efeb2018-04-09 18:19:24 +02002045private function f_vty_sms_send(charstring imsi, charstring msisdn, charstring text)
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002046runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02002047 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
2048}
2049
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01002050/* Remove still pending SMS */
2051private function f_vty_sms_clear(charstring imsi)
2052runs on BSC_ConnHdlr {
2053 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " sms delete-all");
2054 f_vty_transceive(MSCVTY, "sms-queue clear");
2055}
2056
Harald Weltef45efeb2018-04-09 18:19:24 +02002057/* LU followed by MT SMS */
Harald Weltee13cfb22019-04-23 16:52:02 +02002058friend function f_tc_lu_and_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02002059 var SmsParameters spars := valueof(t_SmsPars);
2060 var OCT4 tmsi;
2061
2062 f_init_handler(pars);
2063
2064 /* Perform location update and call */
2065 f_perform_lu();
2066
2067 /* register an 'expect' for given IMSI (+TMSI) */
2068 if (isvalue(g_pars.tmsi)) {
2069 tmsi := g_pars.tmsi;
2070 } else {
2071 tmsi := 'FFFFFFFF'O;
2072 }
Harald Welte6811d102019-04-14 22:23:14 +02002073 f_ran_register_imsi(g_pars.imsi, tmsi);
Harald Weltef45efeb2018-04-09 18:19:24 +02002074
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002075 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
Harald Weltef45efeb2018-04-09 18:19:24 +02002076
2077 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02002078 f_expect_paging();
2079
Harald Weltef45efeb2018-04-09 18:19:24 +02002080 /* Establish DTAP / BSSAP / SCCP connection */
2081 f_establish_fully(EST_TYPE_PAG_RESP);
2082
2083 spars.tp.ud := 'C8329BFD064D9B53'O;
2084 f_mt_sms(spars);
2085
2086 f_expect_clear();
2087}
2088testcase TC_lu_and_mt_sms() runs on MTC_CT {
2089 var BSC_ConnHdlrPars pars;
2090 var BSC_ConnHdlr vc_conn;
2091 f_init();
2092 pars := f_init_pars(43);
2093 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms), pars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002094 vc_conn.done;
2095}
2096
Harald Weltee13cfb22019-04-23 16:52:02 +02002097
Philipp Maier3983e702018-11-22 19:01:33 +01002098/* Paging for MT SMS but no response */
Harald Weltee13cfb22019-04-23 16:52:02 +02002099friend function f_tc_lu_and_mt_sms_paging_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier3983e702018-11-22 19:01:33 +01002100 var SmsParameters spars := valueof(t_SmsPars);
2101 var OCT4 tmsi;
Philipp Maier3983e702018-11-22 19:01:33 +01002102 f_init_handler(pars, 150.0);
2103
2104 /* Perform location update */
2105 f_perform_lu();
2106
2107 /* register an 'expect' for given IMSI (+TMSI) */
2108 if (isvalue(g_pars.tmsi)) {
2109 tmsi := g_pars.tmsi;
2110 } else {
2111 tmsi := 'FFFFFFFF'O;
2112 }
Harald Welte6811d102019-04-14 22:23:14 +02002113 f_ran_register_imsi(g_pars.imsi, tmsi);
Philipp Maier3983e702018-11-22 19:01:33 +01002114
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002115 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2116
Neels Hofmeyr16237742019-03-06 15:34:01 +01002117 /* Expect the MSC to page exactly once */
Harald Weltee13cfb22019-04-23 16:52:02 +02002118 f_expect_paging();
Philipp Maier3983e702018-11-22 19:01:33 +01002119
2120 /* Wait some time to make sure the MSC is not delivering any further
2121 * paging messages or anything else that could be unexpected. */
2122 timer T := 20.0;
2123 T.start
2124 alt {
Harald Weltee13cfb22019-04-23 16:52:02 +02002125 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi))
Philipp Maier3983e702018-11-22 19:01:33 +01002126 {
2127 setverdict(fail, "paging seems not to stop!");
2128 mtc.stop;
2129 }
Harald Weltee13cfb22019-04-23 16:52:02 +02002130 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi), ?)) {
2131 setverdict(fail, "paging seems not to stop!");
2132 mtc.stop;
2133 }
Philipp Maier3983e702018-11-22 19:01:33 +01002134 [] BSSAP.receive {
2135 setverdict(fail, "unexpected BSSAP message received");
2136 self.stop;
2137 }
2138 [] T.timeout {
2139 setverdict(pass);
2140 }
2141 }
2142
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01002143 f_vty_sms_clear(hex2str(g_pars.imsi));
2144
Philipp Maier3983e702018-11-22 19:01:33 +01002145 setverdict(pass);
2146}
2147testcase TC_lu_and_mt_sms_paging_and_nothing() runs on MTC_CT {
2148 var BSC_ConnHdlrPars pars;
2149 var BSC_ConnHdlr vc_conn;
2150 f_init();
Philipp Maiera99ad262019-01-22 15:35:42 +01002151 pars := f_init_pars(1843);
Philipp Maier3983e702018-11-22 19:01:33 +01002152 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_paging_and_nothing), pars);
Philipp Maier3983e702018-11-22 19:01:33 +01002153 vc_conn.done;
2154}
2155
Harald Weltee13cfb22019-04-23 16:52:02 +02002156
Harald Weltef640a012018-04-14 17:49:21 +02002157/* mobile originated SMS from MS/BTS/BSC side to SMPP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002158friend function f_tc_smpp_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef640a012018-04-14 17:49:21 +02002159 var SmsParameters spars := valueof(t_SmsPars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002160
Harald Weltef640a012018-04-14 17:49:21 +02002161 f_init_handler(pars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002162
Harald Weltef640a012018-04-14 17:49:21 +02002163 /* Perform location update so IMSI is known + registered in MSC/VLR */
2164 f_perform_lu();
2165 f_establish_fully(EST_TYPE_MO_SMS);
2166
2167 f_mo_sms(spars);
2168
2169 var SMPP_PDU smpp;
2170 var template SMPP_PDU tr_smpp := tr_SMPP(c_SMPP_command_id_deliver_sm, ESME_ROK);
2171 tr_smpp.body.deliver_sm := {
2172 service_type := "CMT",
2173 source_addr_ton := network_specific,
2174 source_addr_npi := isdn,
2175 source_addr := hex2str(pars.msisdn),
2176 dest_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
2177 dest_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
2178 destination_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
2179 esm_class := '00000001'B,
2180 protocol_id := 0,
2181 priority_flag := 0,
2182 schedule_delivery_time := "",
2183 replace_if_present := 0,
2184 data_coding := '00000001'B,
2185 sm_default_msg_id := 0,
2186 sm_length := ?,
2187 short_message := spars.tp.ud,
2188 opt_pars := {
2189 {
2190 tag := user_message_reference,
2191 len := 2,
2192 opt_value := {
2193 int2_val := oct2int(spars.tp.msg_ref)
2194 }
2195 }
2196 }
2197 };
2198 alt {
2199 [] SMPP.receive(tr_smpp) -> value smpp {
2200 SMPP.send(ts_SMPP_DELIVER_SM_resp(ESME_ROK, smpp.header.seq_num));
2201 }
2202 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK)) { repeat; }
2203 }
2204
2205 f_expect_clear();
2206}
2207testcase TC_smpp_mo_sms() runs on MTC_CT {
2208 var BSC_ConnHdlr vc_conn;
2209 f_init();
2210 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "default-route");
2211 vc_conn := f_start_handler(refers(f_tc_smpp_mo_sms), 44);
2212 vc_conn.done;
2213 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "no default-route");
2214}
2215
Harald Weltee13cfb22019-04-23 16:52:02 +02002216
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002217/* Test MO-SMS from MS/BTS/BSC towards HLR (via GSUP) */
Harald Weltee13cfb22019-04-23 16:52:02 +02002218friend function f_tc_gsup_mo_sms(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002219runs on BSC_ConnHdlr {
2220 var SmsParameters spars := valueof(t_SmsPars);
2221 var GSUP_PDU gsup_msg_rx;
2222 var octetstring sm_tpdu;
2223
2224 f_init_handler(pars);
2225
2226 /* We need to inspect GSUP activity */
2227 f_create_gsup_expect(hex2str(g_pars.imsi));
2228
2229 /* Perform location update */
2230 f_perform_lu();
2231
2232 /* Send CM Service Request for SMS */
2233 f_establish_fully(EST_TYPE_MO_SMS);
2234
2235 /* Prepare expected SM-RP-UI (SM TPDU) */
2236 enc_TPDU_RP_DATA_MS_SGSN_fast(
2237 valueof(ts_SMS_SUBMIT(spars.tp.msg_ref,
2238 spars.tp.da, spars.tp.pid, spars.tp.dcs,
2239 spars.tp.udl, spars.tp.ud)),
2240 sm_tpdu);
2241
2242 var template GSUP_PDU mo_forwardSM := tr_GSUP_MO_FORWARD_SM_REQ(
2243 imsi := g_pars.imsi,
2244 sm_rp_mr := spars.rp.msg_ref,
2245 /* FIXME: extract SM-RP-DA from spars.rp.dest */
2246 sm_rp_da := tr_GSUP_SM_RP_DA_SMSC_ADDR(?),
2247 /* FIXME: MSISDN coding troubles */
2248 sm_rp_oa := tr_GSUP_SM_RP_OA_MSISDN(?),
2249 /* TODO: can we use decmatch here? */
2250 sm_rp_ui := sm_tpdu
2251 );
2252
2253 /* Submit an SMS on DTAP and expect MO-forwardSM-Req on GSUP */
2254 f_mo_sms_submit(spars);
2255 alt {
2256 [] GSUP.receive(mo_forwardSM) -> value gsup_msg_rx {
2257 log("RX MO-forwardSM-Req");
2258 log(gsup_msg_rx);
2259 setverdict(pass);
2260 }
2261 [] GSUP.receive {
2262 log("RX unexpected GSUP message");
2263 setverdict(fail);
2264 mtc.stop;
2265 }
2266 }
2267
2268 /* Trigger RP-ACK by sending MO-forwardSM-Res */
2269 GSUP.send(valueof(ts_GSUP_MO_FORWARD_SM_RES(
2270 imsi := g_pars.imsi,
2271 sm_rp_mr := spars.rp.msg_ref)));
2272 /* Expect RP-ACK on DTAP */
2273 f_mo_sms_wait_rp_ack(spars);
2274
2275 f_expect_clear();
2276}
2277testcase TC_gsup_mo_sms() runs on MTC_CT {
2278 var BSC_ConnHdlr vc_conn;
2279 f_init();
2280 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2281 vc_conn := f_start_handler(refers(f_tc_gsup_mo_sms), 88);
2282 vc_conn.done;
2283 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2284}
2285
Harald Weltee13cfb22019-04-23 16:52:02 +02002286
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002287/* Test MO-SMMA from MS/BTS/BSC towards HLR (via GSUP) */
Harald Weltee13cfb22019-04-23 16:52:02 +02002288friend function f_tc_gsup_mo_smma(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002289runs on BSC_ConnHdlr {
2290 var SmsParameters spars := valueof(t_SmsPars);
2291 var GSUP_PDU gsup_msg_rx;
2292
2293 f_init_handler(pars);
2294
2295 /* We need to inspect GSUP activity */
2296 f_create_gsup_expect(hex2str(g_pars.imsi));
2297
2298 /* Perform location update */
2299 f_perform_lu();
2300
2301 /* Send CM Service Request for SMS */
2302 f_establish_fully(EST_TYPE_MO_SMS);
2303
2304 var template GSUP_PDU mo_ReadyForSM := tr_GSUP_MO_READY_FOR_SM_REQ(
2305 imsi := g_pars.imsi,
2306 sm_rp_mr := spars.rp.msg_ref,
2307 sm_alert_rsn := GSUP_SM_ALERT_RSN_TYPE_MEM_AVAIL
2308 );
2309
2310 /* Submit an SMS on DTAP and expect MO-forwardSM-Req on GSUP */
2311 f_mo_smma(spars);
2312 alt {
2313 [] GSUP.receive(mo_ReadyForSM) -> value gsup_msg_rx {
2314 log("RX MO-ReadyForSM-Req");
2315 log(gsup_msg_rx);
2316 setverdict(pass);
2317 }
2318 [] GSUP.receive {
2319 log("RX unexpected GSUP message");
2320 setverdict(fail);
2321 mtc.stop;
2322 }
2323 }
2324
2325 /* Trigger RP-ACK by sending MO-forwardSM-Res */
2326 GSUP.send(valueof(ts_GSUP_MO_READY_FOR_SM_RES(
2327 imsi := g_pars.imsi,
2328 sm_rp_mr := spars.rp.msg_ref)));
2329 /* Expect RP-ACK on DTAP */
2330 f_mo_sms_wait_rp_ack(spars);
2331
2332 f_expect_clear();
2333}
2334testcase TC_gsup_mo_smma() runs on MTC_CT {
2335 var BSC_ConnHdlr vc_conn;
2336 f_init();
2337 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2338 vc_conn := f_start_handler(refers(f_tc_gsup_mo_smma), 89);
2339 vc_conn.done;
2340 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2341}
2342
Harald Weltee13cfb22019-04-23 16:52:02 +02002343
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002344/* Helper for sending MT SMS over GSUP */
2345private function f_gsup_forwardSM_req(SmsParameters spars, OCT1 mms := '00'O)
2346runs on BSC_ConnHdlr {
2347 GSUP.send(ts_GSUP_MT_FORWARD_SM_REQ(
2348 imsi := g_pars.imsi,
2349 /* NOTE: MSC should assign RP-MR itself */
2350 sm_rp_mr := 'FF'O,
2351 /* FIXME: extract SM-RP-DA from spars.rp.dest */
2352 /* TODO: fix encoding of ts_GSUP_SM_RP_DA_IMSI */
2353 sm_rp_da := valueof(ts_GSUP_SM_RP_DA_MSISDN(g_pars.msisdn)),
2354 sm_rp_oa := valueof(ts_GSUP_SM_RP_OA_SMSC_ADDR(g_pars.msisdn)),
2355 /* Encoded SMS TPDU (taken from Wireshark)
2356 * FIXME: we should encode spars somehow */
2357 sm_rp_ui := '00068021436500008111328130858200'O,
2358 sm_rp_mms := mms
2359 ));
2360}
2361
2362/* Test successful MT-SMS (RP-ACK) over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002363friend function f_tc_gsup_mt_sms_ack(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002364runs on BSC_ConnHdlr {
2365 var SmsParameters spars := valueof(t_SmsPars);
2366
2367 f_init_handler(pars);
2368
2369 /* We need to inspect GSUP activity */
2370 f_create_gsup_expect(hex2str(g_pars.imsi));
2371
2372 /* Perform location update */
2373 f_perform_lu();
2374
2375 /* Register an 'expect' for given IMSI (+TMSI) */
2376 if (isvalue(g_pars.tmsi)) {
Harald Welte6811d102019-04-14 22:23:14 +02002377 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002378 } else {
Harald Welte6811d102019-04-14 22:23:14 +02002379 f_ran_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002380 }
2381
2382 var template GSUP_PDU mt_forwardSM_res := tr_GSUP_MT_FORWARD_SM_RES(
2383 imsi := g_pars.imsi,
2384 /* NOTE: MSC should assign RP-MR itself */
2385 sm_rp_mr := ?
2386 );
2387
2388 /* Submit a MT SMS on GSUP */
2389 f_gsup_forwardSM_req(spars);
2390
2391 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002392 f_expect_paging();
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002393 f_establish_fully(EST_TYPE_PAG_RESP);
2394
2395 /* Wait for MT SMS on DTAP */
2396 f_mt_sms_expect(spars);
2397
2398 /* Send RP-ACK and expect MT-forwardSM-Res on GSUP */
2399 f_mt_sms_send_rp_ack(spars);
2400 alt {
2401 [] GSUP.receive(mt_forwardSM_res) {
2402 log("RX MT-forwardSM-Res (RP-ACK)");
2403 setverdict(pass);
2404 }
2405 [] GSUP.receive {
2406 log("RX unexpected GSUP message");
2407 setverdict(fail);
2408 mtc.stop;
2409 }
2410 }
2411
2412 f_expect_clear();
2413}
2414testcase TC_gsup_mt_sms_ack() runs on MTC_CT {
2415 var BSC_ConnHdlrPars pars;
2416 var BSC_ConnHdlr vc_conn;
2417 f_init();
2418 pars := f_init_pars(90);
2419 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2420 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_ack), pars);
2421 vc_conn.done;
2422 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2423}
2424
Harald Weltee13cfb22019-04-23 16:52:02 +02002425
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002426/* Test rejected MT-SMS (RP-ERROR) over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002427friend function f_tc_gsup_mt_sms_err(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002428runs on BSC_ConnHdlr {
2429 var SmsParameters spars := valueof(t_SmsPars);
2430 var OCT1 sm_rp_cause := '78'O; /* dummy RP-Cause value */
2431
2432 f_init_handler(pars);
2433
2434 /* We need to inspect GSUP activity */
2435 f_create_gsup_expect(hex2str(g_pars.imsi));
2436
2437 /* Perform location update */
2438 f_perform_lu();
2439
2440 /* Register an 'expect' for given IMSI (+TMSI) */
2441 if (isvalue(g_pars.tmsi)) {
Harald Welte6811d102019-04-14 22:23:14 +02002442 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002443 } else {
Harald Welte6811d102019-04-14 22:23:14 +02002444 f_ran_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002445 }
2446
2447 var template GSUP_PDU mt_forwardSM_err := tr_GSUP_MT_FORWARD_SM_ERR(
2448 imsi := g_pars.imsi,
2449 /* NOTE: MSC should assign RP-MR itself */
2450 sm_rp_mr := ?,
2451 sm_rp_cause := sm_rp_cause
2452 );
2453
2454 /* Submit a MT SMS on GSUP */
2455 f_gsup_forwardSM_req(spars);
2456
2457 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002458 f_expect_paging();
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002459 f_establish_fully(EST_TYPE_PAG_RESP);
2460
2461 /* Wait for MT SMS on DTAP */
2462 f_mt_sms_expect(spars);
2463
2464 /* Send RP-ERROR and expect MT-forwardSM-Err on GSUP */
2465 f_mt_sms_send_rp_error(spars, oct2int(sm_rp_cause));
2466 alt {
2467 [] GSUP.receive(mt_forwardSM_err) {
2468 log("RX MT-forwardSM-Err (RP-ERROR)");
2469 setverdict(pass);
2470 mtc.stop;
2471 }
2472 [] GSUP.receive {
2473 log("RX unexpected GSUP message");
2474 setverdict(fail);
2475 mtc.stop;
2476 }
2477 }
2478
2479 f_expect_clear();
2480}
2481testcase TC_gsup_mt_sms_err() runs on MTC_CT {
2482 var BSC_ConnHdlrPars pars;
2483 var BSC_ConnHdlr vc_conn;
2484 f_init();
2485 pars := f_init_pars(91);
2486 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2487 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_err), pars);
2488 vc_conn.done;
2489 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2490}
2491
Harald Weltee13cfb22019-04-23 16:52:02 +02002492
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002493/* Test SM-RP-MR assignment for MT-SMS over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002494friend function f_tc_gsup_mt_sms_rp_mr(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002495runs on BSC_ConnHdlr {
2496 var SmsParameters spars1 := valueof(t_SmsPars); /* 1st SMS */
2497 var SmsParameters spars2 := valueof(t_SmsPars); /* 2nd SMS */
2498
2499 f_init_handler(pars);
2500
2501 /* We need to inspect GSUP activity */
2502 f_create_gsup_expect(hex2str(g_pars.imsi));
2503
2504 /* Perform location update */
2505 f_perform_lu();
2506
2507 /* Register an 'expect' for given IMSI (+TMSI) */
2508 if (isvalue(g_pars.tmsi)) {
Harald Welte6811d102019-04-14 22:23:14 +02002509 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002510 } else {
Harald Welte6811d102019-04-14 22:23:14 +02002511 f_ran_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002512 }
2513
2514 /* Submit the 1st MT SMS on GSUP */
2515 log("TX MT-forwardSM-Req for the 1st SMS");
2516 f_gsup_forwardSM_req(spars1);
2517
2518 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002519 f_expect_paging();
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002520 f_establish_fully(EST_TYPE_PAG_RESP);
2521
2522 /* Wait for 1st MT SMS on DTAP */
2523 f_mt_sms_expect(spars1);
2524 log("RX the 1st SMS on DTAP, DTAP TID is ", spars1.tid,
2525 ", SM-RP-MR is ", spars1.rp.msg_ref);
2526
2527 /* Submit the 2nd MT SMS on GSUP */
2528 log("TX MT-forwardSM-Req for the 2nd SMS");
2529 f_gsup_forwardSM_req(spars2);
2530
2531 /* Wait for 2nd MT SMS on DTAP */
2532 f_mt_sms_expect(spars2);
2533 log("RX the 2nd SMS on DTAP, DTAP TID is ", spars2.tid,
2534 ", SM-RP-MR is ", spars2.rp.msg_ref);
2535
2536 /* Both transaction IDs shall be different */
2537 if (spars1.tid == spars2.tid) {
2538 log("Both DTAP transaction IDs shall be different");
2539 setverdict(fail);
2540 }
2541
2542 /* Both SM-RP-MR values shall be different */
2543 if (spars1.rp.msg_ref == spars2.rp.msg_ref) {
2544 log("Both SM-RP-MR values shall be different");
2545 setverdict(fail);
2546 }
2547
2548 /* Both SM-RP-MR values shall be assigned */
2549 if (spars1.rp.msg_ref == 'FF'O) {
2550 log("Unassigned SM-RP-MR value for the 1st SMS");
2551 setverdict(fail);
2552 }
2553 if (spars2.rp.msg_ref == 'FF'O) {
2554 log("Unassigned SM-RP-MR value for the 2nd SMS");
2555 setverdict(fail);
2556 }
2557
2558 /* Send the 1st RP-ACK and expect MT-forwardSM-Res on GSUP */
2559 f_mt_sms_send_rp_ack(spars1);
2560 alt {
2561 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2562 imsi := g_pars.imsi,
2563 sm_rp_mr := spars1.rp.msg_ref
2564 )) {
2565 log("RX MT-forwardSM-Res (RP-ACK)");
2566 setverdict(pass);
2567 }
2568 [] GSUP.receive {
2569 log("RX unexpected GSUP message");
2570 setverdict(fail);
2571 mtc.stop;
2572 }
2573 }
2574
2575 /* Send the 2nd RP-ACK and expect MT-forwardSM-Res on GSUP */
2576 f_mt_sms_send_rp_ack(spars2);
2577 alt {
2578 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2579 imsi := g_pars.imsi,
2580 sm_rp_mr := spars2.rp.msg_ref
2581 )) {
2582 log("RX MT-forwardSM-Res (RP-ACK)");
2583 setverdict(pass);
2584 }
2585 [] GSUP.receive {
2586 log("RX unexpected GSUP message");
2587 setverdict(fail);
2588 mtc.stop;
2589 }
2590 }
2591
2592 f_expect_clear();
2593}
2594testcase TC_gsup_mt_sms_rp_mr() runs on MTC_CT {
2595 var BSC_ConnHdlrPars pars;
2596 var BSC_ConnHdlr vc_conn;
2597 f_init();
2598 pars := f_init_pars(92);
2599 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2600 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_rp_mr), pars);
2601 vc_conn.done;
2602 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2603}
2604
Harald Weltee13cfb22019-04-23 16:52:02 +02002605
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07002606/* Test SM-RP-MR assignment for MT-SMS over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002607friend function f_tc_gsup_mo_mt_sms_rp_mr(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07002608runs on BSC_ConnHdlr {
2609 var SmsParameters spars_mo := valueof(t_SmsPars); /* MO SMMA */
2610 var SmsParameters spars_mt := valueof(t_SmsPars); /* MT SMS */
2611
2612 f_init_handler(pars);
2613
2614 /* We need to inspect GSUP activity */
2615 f_create_gsup_expect(hex2str(g_pars.imsi));
2616
2617 /* Perform location update */
2618 f_perform_lu();
2619
2620 /* Register an 'expect' for given IMSI (+TMSI) */
2621 if (isvalue(g_pars.tmsi)) {
Harald Welte6811d102019-04-14 22:23:14 +02002622 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07002623 } else {
Harald Welte6811d102019-04-14 22:23:14 +02002624 f_ran_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07002625 }
2626
2627 /* Send CM Service Request for MO SMMA */
2628 f_establish_fully(EST_TYPE_MO_SMS);
2629
2630 /* Submit MO SMMA on DTAP */
2631 log("Submit MO SMMA on DTAP, SM-RP-MR is '00'O");
2632 spars_mo.rp.msg_ref := '00'O;
2633 f_mo_smma(spars_mo);
2634
2635 /* Expect MO-forwardSM-Req for MO SMMA on GSUP */
2636 alt {
2637 [] GSUP.receive(tr_GSUP_MO_READY_FOR_SM_REQ(
2638 imsi := g_pars.imsi,
2639 sm_rp_mr := spars_mo.rp.msg_ref,
2640 sm_alert_rsn := GSUP_SM_ALERT_RSN_TYPE_MEM_AVAIL
2641 )) {
2642 log("RX MO-ReadyForSM-Req, SM-RP-MR is '00'O");
2643 setverdict(pass);
2644 }
2645 [] GSUP.receive {
2646 log("RX unexpected GSUP message");
2647 setverdict(fail);
2648 mtc.stop;
2649 }
2650 }
2651
2652 /* Submit MT SMS on GSUP */
2653 log("TX MT-forwardSM-Req for the MT SMS");
2654 f_gsup_forwardSM_req(spars_mt);
2655
2656 /* Wait for MT SMS on DTAP */
2657 f_mt_sms_expect(spars_mt);
2658 log("RX MT SMS on DTAP, DTAP TID is ", spars_mt.tid,
2659 ", SM-RP-MR is ", spars_mt.rp.msg_ref);
2660
2661 /* Both SM-RP-MR values shall be different */
2662 if (spars_mo.rp.msg_ref == spars_mt.rp.msg_ref) {
2663 log("Both SM-RP-MR values shall be different");
2664 setverdict(fail);
2665 }
2666
2667 /* SM-RP-MR value for MT SMS shall be assigned */
2668 if (spars_mt.rp.msg_ref == 'FF'O) {
2669 log("Unassigned SM-RP-MR value for the MT SMS");
2670 setverdict(fail);
2671 }
2672
2673 /* Trigger RP-ACK for MO SMMA by sending MO-forwardSM-Res */
2674 GSUP.send(valueof(ts_GSUP_MO_READY_FOR_SM_RES(
2675 imsi := g_pars.imsi,
2676 sm_rp_mr := spars_mo.rp.msg_ref)));
2677 /* Expect RP-ACK for MO SMMA on DTAP */
2678 f_mo_sms_wait_rp_ack(spars_mo);
2679
2680 /* Send RP-ACK for MT SMS and expect MT-forwardSM-Res on GSUP */
2681 f_mt_sms_send_rp_ack(spars_mt);
2682 alt {
2683 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2684 imsi := g_pars.imsi,
2685 sm_rp_mr := spars_mt.rp.msg_ref
2686 )) {
2687 log("RX MT-forwardSM-Res (RP-ACK)");
2688 setverdict(pass);
2689 }
2690 [] GSUP.receive {
2691 log("RX unexpected GSUP message");
2692 setverdict(fail);
2693 mtc.stop;
2694 }
2695 }
2696
2697 f_expect_clear();
2698}
2699testcase TC_gsup_mo_mt_sms_rp_mr() runs on MTC_CT {
2700 var BSC_ConnHdlrPars pars;
2701 var BSC_ConnHdlr vc_conn;
2702 f_init();
2703 pars := f_init_pars(93);
2704 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2705 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mo_mt_sms_rp_mr), pars);
2706 vc_conn.done;
2707 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2708}
2709
Harald Weltee13cfb22019-04-23 16:52:02 +02002710
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07002711/* Test multi-part MT-SMS over GSUP */
2712private function f_tc_gsup_mt_multi_part_sms(charstring id, BSC_ConnHdlrPars pars)
2713runs on BSC_ConnHdlr {
2714 var SmsParameters spars := valueof(t_SmsPars);
2715
2716 f_init_handler(pars);
2717
2718 /* We need to inspect GSUP activity */
2719 f_create_gsup_expect(hex2str(g_pars.imsi));
2720
2721 /* Perform location update */
2722 f_perform_lu();
2723
2724 /* Register an 'expect' for given IMSI (+TMSI) */
2725 if (isvalue(g_pars.tmsi)) {
Harald Welte6811d102019-04-14 22:23:14 +02002726 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07002727 } else {
Harald Welte6811d102019-04-14 22:23:14 +02002728 f_ran_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07002729 }
2730
2731 var template GSUP_PDU mt_forwardSM_res := tr_GSUP_MT_FORWARD_SM_RES(
2732 imsi := g_pars.imsi,
2733 /* NOTE: MSC should assign RP-MR itself */
2734 sm_rp_mr := ?
2735 );
2736
2737 /* Send 4 messages (NOTE: SM-RP-UI remains unchanged) */
2738 for (var integer i := 3; i >= 0; i := i-1) {
2739 /* Submit a MT SMS on GSUP (MMS is decremented) */
2740 f_gsup_forwardSM_req(spars, int2oct(i, 1));
2741
2742 /* Expect Paging Request and Establish connection */
2743 if (i == 3) { /* ... only once! */
Harald Weltee13cfb22019-04-23 16:52:02 +02002744 f_expect_paging();
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07002745 f_establish_fully(EST_TYPE_PAG_RESP);
2746 }
2747
2748 /* Wait for MT SMS on DTAP */
2749 f_mt_sms_expect(spars);
2750
2751 /* Send RP-ACK and expect MT-forwardSM-Res on GSUP */
2752 f_mt_sms_send_rp_ack(spars);
2753 alt {
2754 [] GSUP.receive(mt_forwardSM_res) {
2755 log("RX MT-forwardSM-Res (RP-ACK)");
2756 setverdict(pass);
2757 }
2758 [] GSUP.receive {
2759 log("RX unexpected GSUP message");
2760 setverdict(fail);
2761 mtc.stop;
2762 }
2763 }
2764
2765 /* Keep some 'distance' between transmissions */
2766 f_sleep(1.5);
2767 }
2768
2769 f_expect_clear();
2770}
2771testcase TC_gsup_mt_multi_part_sms() runs on MTC_CT {
2772 var BSC_ConnHdlrPars pars;
2773 var BSC_ConnHdlr vc_conn;
2774 f_init();
2775 pars := f_init_pars(91);
2776 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2777 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_multi_part_sms), pars);
2778 vc_conn.done;
2779 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2780}
2781
Harald Weltef640a012018-04-14 17:49:21 +02002782/* convert GSM L3 TON to SMPP_TON enum */
2783function f_sm_ton_from_gsm(BIT3 ton) return SMPP_TON {
2784 select (ton) {
2785 case ('000'B) { return unknown; }
2786 case ('001'B) { return international; }
2787 case ('010'B) { return national; }
2788 case ('011'B) { return network_specific; }
2789 case ('100'B) { return subscriber_number; }
2790 case ('101'B) { return alphanumeric; }
2791 case ('110'B) { return abbreviated; }
2792 }
2793 setverdict(fail, "Unknown TON ", ton);
Daniel Willmannafce8662018-07-06 23:11:32 +02002794 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02002795}
2796/* convert GSM L3 NPI to SMPP_NPI enum */
2797function f_sm_npi_from_gsm(BIT4 npi) return SMPP_NPI {
2798 select (npi) {
2799 case ('0000'B) { return unknown; }
2800 case ('0001'B) { return isdn; }
2801 case ('0011'B) { return data; }
2802 case ('0100'B) { return telex; }
2803 case ('0110'B) { return land_mobile; }
2804 case ('1000'B) { return national; }
2805 case ('1001'B) { return private_; }
2806 case ('1010'B) { return ermes; }
2807 }
2808 setverdict(fail, "Unknown NPI ", npi);
Daniel Willmannafce8662018-07-06 23:11:32 +02002809 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02002810}
2811
2812/* build a SMPP_SM from SmsParameters */
2813function f_mt_sm_from_spars(SmsParameters spars)
2814runs on BSC_ConnHdlr return SMPP_SM {
2815 var SMPP_SM sm := {
2816 service_type := "CMT",
2817 source_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
2818 source_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
2819 source_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
2820 dest_addr_ton := international,
2821 dest_addr_npi := isdn,
2822 destination_addr := hex2str(g_pars.msisdn),
2823 esm_class := '00000001'B,
2824 protocol_id := 0,
2825 priority_flag := 0,
2826 schedule_delivery_time := "",
2827 validity_period := "",
2828 registered_delivery := '00000000'B,
2829 replace_if_present := 0,
2830 data_coding := '00000001'B,
2831 sm_default_msg_id := 0,
2832 sm_length := spars.tp.udl,
2833 short_message := spars.tp.ud,
2834 opt_pars := {}
2835 };
2836 return sm;
2837}
2838
2839/* helper function to encode SMS from 'spars', send it via SMPP to MSC; receive it on MS side */
2840private function f_smpp_mt_sms(SmsParameters spars, boolean trans_mode) runs on BSC_ConnHdlr {
2841 var SMPP_SM sm := f_mt_sm_from_spars(spars);
2842 if (trans_mode) {
2843 sm.esm_class := '00000010'B;
2844 }
2845
2846 /* actually cause MSC to send a SMS via SUBMIT-SM from SMPP side */
2847 SMPP.send(ts_SMPP_SUBMIT_SM(sm));
2848 if (not match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
2849 /* if we're not in SMPP transaction mode, we expect the SMPP-level ACK
2850 * before we expect the SMS delivery on the BSC/radio side */
2851 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
2852 }
2853
2854 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02002855 f_expect_paging();
Harald Weltef640a012018-04-14 17:49:21 +02002856 /* Establish DTAP / BSSAP / SCCP connection */
2857 f_establish_fully(EST_TYPE_PAG_RESP);
2858 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
2859
2860 f_mt_sms(spars);
2861
2862 if (match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
2863 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
2864 }
2865 f_expect_clear();
2866}
2867
2868/* mobile terminated SMS, from SMPP to BSC/BTS/MS */
2869private function f_tc_smpp_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2870 f_init_handler(pars);
2871
2872 /* Perform location update so IMSI is known + registered in MSC/VLR */
2873 f_perform_lu();
2874 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
2875
2876 /* register an 'expect' for given IMSI (+TMSI) */
2877 var OCT4 tmsi;
2878 if (isvalue(g_pars.tmsi)) {
2879 tmsi := g_pars.tmsi;
2880 } else {
2881 tmsi := 'FFFFFFFF'O;
2882 }
Harald Welte6811d102019-04-14 22:23:14 +02002883 f_ran_register_imsi(g_pars.imsi, tmsi);
Harald Weltef640a012018-04-14 17:49:21 +02002884
2885 var SmsParameters spars := valueof(t_SmsPars);
2886 /* TODO: test with more intelligent user data; test different coding schemes */
2887 spars.tp.ud := '00'O;
2888 spars.tp.udl := 1;
2889
2890 /* first test the non-transaction store+forward mode */
2891 f_smpp_mt_sms(spars, false);
2892
2893 /* then test the transaction mode */
2894 f_smpp_mt_sms(spars, true);
2895}
2896testcase TC_smpp_mt_sms() runs on MTC_CT {
2897 var BSC_ConnHdlr vc_conn;
2898 f_init();
2899 vc_conn := f_start_handler(refers(f_tc_smpp_mt_sms), 45);
2900 vc_conn.done;
2901}
2902
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002903/***********************************************************************
2904 * USSD Testing
2905 ***********************************************************************/
2906
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07002907private altstep as_unexp_gsup_or_bssap_msg()
2908runs on BSC_ConnHdlr {
2909 [] GSUP.receive {
2910 setverdict(fail, "Unknown/unexpected GSUP received");
2911 self.stop;
2912 }
2913 [] BSSAP.receive {
2914 setverdict(fail, "Unknown/unexpected BSSAP message received");
2915 self.stop;
2916 }
2917}
2918
2919private function f_expect_gsup_msg(template GSUP_PDU msg)
2920runs on BSC_ConnHdlr return GSUP_PDU {
2921 var GSUP_PDU gsup_msg_complete;
2922
2923 alt {
2924 [] GSUP.receive(msg) -> value gsup_msg_complete {
2925 setverdict(pass);
2926 }
2927 /* We don't expect anything else */
2928 [] as_unexp_gsup_or_bssap_msg();
2929 }
2930
2931 return gsup_msg_complete;
2932}
2933
2934private function f_expect_mt_dtap_msg(template PDU_ML3_NW_MS msg)
2935runs on BSC_ConnHdlr return PDU_ML3_NW_MS {
2936 var PDU_DTAP_MT bssap_msg_complete;
2937
2938 alt {
2939 [] BSSAP.receive(tr_PDU_DTAP_MT(msg)) -> value bssap_msg_complete {
2940 setverdict(pass);
2941 }
2942 /* We don't expect anything else */
2943 [] as_unexp_gsup_or_bssap_msg();
2944 }
2945
2946 return bssap_msg_complete.dtap;
2947}
2948
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07002949/* LU followed by MO USSD request */
Harald Weltee13cfb22019-04-23 16:52:02 +02002950friend function f_tc_lu_and_mo_ussd_single_request(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002951runs on BSC_ConnHdlr {
2952 f_init_handler(pars);
2953
2954 /* Perform location update */
2955 f_perform_lu();
2956
2957 /* Send CM Service Request for SS/USSD */
2958 f_establish_fully(EST_TYPE_SS_ACT);
2959
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002960 /* We need to inspect GSUP activity */
2961 f_create_gsup_expect(hex2str(g_pars.imsi));
2962
2963 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
2964 invoke_id := 5, /* Phone may not start from 0 or 1 */
2965 op_code := SS_OP_CODE_PROCESS_USS_REQ,
2966 ussd_string := "*#100#"
2967 );
2968
2969 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
2970 invoke_id := 5, /* InvokeID shall be the same for both REQ and RSP */
2971 op_code := SS_OP_CODE_PROCESS_USS_REQ,
2972 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
2973 )
2974
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002975 /* Compose a new SS/REGISTER message with request */
2976 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
2977 tid := 1, /* We just need a single transaction */
2978 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002979 facility := valueof(facility_req)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002980 );
2981
2982 /* Compose SS/RELEASE_COMPLETE template with expected response */
2983 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
2984 tid := 1, /* Response should arrive within the same transaction */
2985 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002986 facility := valueof(facility_rsp)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002987 );
2988
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002989 /* Compose expected MSC -> HLR message */
2990 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
2991 imsi := g_pars.imsi,
2992 state := OSMO_GSUP_SESSION_STATE_BEGIN,
2993 ss := valueof(facility_req)
2994 );
2995
2996 /* To be used for sending response with correct session ID */
2997 var GSUP_PDU gsup_req_complete;
2998
2999 /* Request own number */
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003000 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003001 /* Expect GSUP message containing the SS payload */
3002 gsup_req_complete := f_expect_gsup_msg(gsup_req);
3003
3004 /* Compose the response from HLR using received session ID */
3005 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
3006 imsi := g_pars.imsi,
3007 sid := gsup_req_complete.ies[1].val.session_id,
3008 state := OSMO_GSUP_SESSION_STATE_END,
3009 ss := valueof(facility_rsp)
3010 );
3011
3012 /* Finally, HLR terminates the session */
3013 GSUP.send(gsup_rsp);
3014 /* Expect RELEASE_COMPLETE message with the response */
3015 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003016
3017 f_expect_clear();
3018}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003019testcase TC_lu_and_mo_ussd_single_request() runs on MTC_CT {
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003020 var BSC_ConnHdlr vc_conn;
3021 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003022 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_single_request), 46);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003023 vc_conn.done;
3024}
3025
Harald Weltee13cfb22019-04-23 16:52:02 +02003026
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003027/* LU followed by MT USSD notification */
Harald Weltee13cfb22019-04-23 16:52:02 +02003028friend function f_tc_lu_and_mt_ussd_notification(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003029runs on BSC_ConnHdlr {
3030 f_init_handler(pars);
3031
3032 /* Perform location update */
3033 f_perform_lu();
3034
Harald Welte6811d102019-04-14 22:23:14 +02003035 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003036
3037 /* We need to inspect GSUP activity */
3038 f_create_gsup_expect(hex2str(g_pars.imsi));
3039
3040 /* Facility IE with network-originated USSD notification */
3041 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3042 op_code := SS_OP_CODE_USS_NOTIFY,
3043 ussd_string := "Mahlzeit!"
3044 );
3045
3046 /* Facility IE with acknowledgment to the USSD notification */
3047 var template OCTN facility_rsp := enc_SS_FacilityInformation(
3048 /* In case of USSD notification, Return Result is empty */
3049 valueof(ts_SS_USSD_FACILITY_RETURN_RESULT_EMPTY())
3050 );
3051
3052 /* Compose a new MT SS/REGISTER message with USSD notification */
3053 var template PDU_ML3_NW_MS ussd_ntf := tr_ML3_MT_SS_REGISTER(
3054 tid := 0, /* FIXME: most likely, it should be 0 */
3055 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3056 facility := valueof(facility_req)
3057 );
3058
3059 /* Compose HLR -> MSC GSUP message */
3060 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3061 imsi := g_pars.imsi,
3062 sid := '20000101'O,
3063 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3064 ss := valueof(facility_req)
3065 );
3066
3067 /* Send it to MSC and expect Paging Request */
3068 GSUP.send(gsup_req);
3069 alt {
Harald Weltee13cfb22019-04-23 16:52:02 +02003070 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
3071 setverdict(pass);
3072 }
3073 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi), ?)) {
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003074 setverdict(pass);
3075 }
3076 /* We don't expect anything else */
3077 [] as_unexp_gsup_or_bssap_msg();
3078 }
3079
3080 /* Send Paging Response and expect USSD notification */
3081 f_establish_fully(EST_TYPE_PAG_RESP);
3082 /* Expect MT REGISTER message with USSD notification */
3083 f_expect_mt_dtap_msg(ussd_ntf);
3084
3085 /* Compose a new MO SS/FACILITY message with empty response */
3086 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
3087 tid := 0, /* FIXME: it shall match the request tid */
3088 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3089 facility := valueof(facility_rsp)
3090 );
3091
3092 /* Compose expected MSC -> HLR GSUP message */
3093 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
3094 imsi := g_pars.imsi,
3095 sid := '20000101'O,
3096 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3097 ss := valueof(facility_rsp)
3098 );
3099
3100 /* MS sends response to the notification */
3101 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
3102 /* Expect GSUP message containing the SS payload */
3103 f_expect_gsup_msg(gsup_rsp);
3104
3105 /* Compose expected MT SS/RELEASE COMPLETE message */
3106 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
3107 tid := 0, /* FIXME: it shall match the request tid */
3108 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3109 facility := omit
3110 );
3111
3112 /* Compose MSC -> HLR GSUP message */
3113 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
3114 imsi := g_pars.imsi,
3115 sid := '20000101'O,
3116 state := OSMO_GSUP_SESSION_STATE_END
3117 );
3118
3119 /* Finally, HLR terminates the session */
3120 GSUP.send(gsup_term)
3121 /* Expect MT RELEASE COMPLETE without Facility IE */
3122 f_expect_mt_dtap_msg(ussd_term);
3123
3124 f_expect_clear();
3125}
3126testcase TC_lu_and_mt_ussd_notification() runs on MTC_CT {
3127 var BSC_ConnHdlr vc_conn;
3128 f_init();
3129 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_notification), 47);
3130 vc_conn.done;
3131}
3132
Harald Weltee13cfb22019-04-23 16:52:02 +02003133
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003134/* LU followed by MT call and MO USSD request during this call */
Harald Weltee13cfb22019-04-23 16:52:02 +02003135friend function f_tc_lu_and_mo_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003136runs on BSC_ConnHdlr {
3137 f_init_handler(pars);
3138
3139 /* Call parameters taken from f_tc_lu_and_mt_call */
3140 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
3141 cpars.mgcp_connection_id_bss := '10004'H;
3142 cpars.mgcp_connection_id_mss := '10005'H;
3143 cpars.mgcp_ep := "rtpbridge/1@mgw";
3144 cpars.bss_rtp_port := 1110;
3145
3146 /* Perform location update */
3147 f_perform_lu();
3148
3149 /* Establish a MT call */
3150 f_mt_call_establish(cpars);
3151
3152 /* Hold the call for some time */
3153 f_sleep(1.0);
3154
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003155 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3156 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3157 ussd_string := "*#100#"
3158 );
3159
3160 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3161 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3162 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
3163 )
3164
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003165 /* Compose a new SS/REGISTER message with request */
3166 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
3167 tid := 1, /* We just need a single transaction */
3168 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003169 facility := valueof(facility_req)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003170 );
3171
3172 /* Compose SS/RELEASE_COMPLETE template with expected response */
3173 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
3174 tid := 1, /* Response should arrive within the same transaction */
3175 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003176 facility := valueof(facility_rsp)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003177 );
3178
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003179 /* Compose expected MSC -> HLR message */
3180 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
3181 imsi := g_pars.imsi,
3182 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3183 ss := valueof(facility_req)
3184 );
3185
3186 /* To be used for sending response with correct session ID */
3187 var GSUP_PDU gsup_req_complete;
3188
3189 /* Request own number */
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003190 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003191 /* Expect GSUP message containing the SS payload */
3192 gsup_req_complete := f_expect_gsup_msg(gsup_req);
3193
3194 /* Compose the response from HLR using received session ID */
3195 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
3196 imsi := g_pars.imsi,
3197 sid := gsup_req_complete.ies[1].val.session_id,
3198 state := OSMO_GSUP_SESSION_STATE_END,
3199 ss := valueof(facility_rsp)
3200 );
3201
3202 /* Finally, HLR terminates the session */
3203 GSUP.send(gsup_rsp);
3204 /* Expect RELEASE_COMPLETE message with the response */
3205 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003206
3207 /* Hold the call for some time */
3208 f_sleep(1.0);
3209
3210 /* Release the call (does Clear Complete itself) */
3211 f_call_hangup(cpars, true);
3212}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003213testcase TC_lu_and_mo_ussd_during_mt_call() runs on MTC_CT {
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003214 var BSC_ConnHdlr vc_conn;
3215 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003216 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_during_mt_call), 48);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003217 vc_conn.done;
3218}
3219
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003220/* BSSMAP Clear Request in the middle of a call, see OS#3062 */
Harald Weltee13cfb22019-04-23 16:52:02 +02003221friend function f_tc_mo_cc_bssmap_clear(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003222 f_init_handler(pars);
3223 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
3224 var MNCC_PDU mncc;
3225 var MgcpCommand mgcp_cmd;
3226
3227 f_perform_lu();
3228
3229 f_establish_fully();
3230 f_create_mncc_expect(hex2str(cpars.called_party));
3231 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
3232
3233 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
3234 MNCC.receive(tr_MNCC_SETUP_ind(?, tr_MNCC_number(hex2str(cpars.called_party)))) -> value mncc;
3235 cpars.mncc_callref := mncc.u.signal.callref;
3236 log("mncc_callref=", cpars.mncc_callref);
3237 MNCC.send(ts_MNCC_CALL_PROC_req(cpars.mncc_callref, cpars.mncc_bearer_cap));
3238 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_CALL_PROC(cpars.transaction_id)));
3239
3240 MNCC.send(ts_MNCC_ALERT_req(cpars.mncc_callref));
3241 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_ALERTING(cpars.transaction_id)));
3242 MGCP.receive(tr_CRCX);
3243
3244 f_sleep(1.0);
Harald Weltee13cfb22019-04-23 16:52:02 +02003245 if (pars.ran_is_geran) {
3246 BSSAP.send(ts_BSSMAP_ClearRequest(0));
3247 } else {
3248 BSSAP.send(ts_RANAP_IuReleaseRequest(ts_RanapCause_om_intervention));
3249 }
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003250
Neels Hofmeyrde76f052019-02-26 05:02:46 +01003251 var default ccrel := activate(as_optional_cc_rel(cpars));
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003252
Harald Weltee13cfb22019-04-23 16:52:02 +02003253 if (pars.ran_is_geran) {
3254 interleave {
3255 [] MNCC.receive(tr_MNCC_REL_ind(?, ?)) { };
3256 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {
Neels Hofmeyrde76f052019-02-26 05:02:46 +01003257 BSSAP.send(ts_BSSMAP_ClearComplete);
Harald Weltee13cfb22019-04-23 16:52:02 +02003258 };
3259 }
3260 } else {
3261 interleave {
3262 [] MNCC.receive(tr_MNCC_REL_ind(?, ?)) { };
3263 [] BSSAP.receive(tr_RANAP_IuReleaseCommand(?)) {
3264 BSSAP.send(ts_RANAP_IuReleaseComplete);
3265 };
3266 }
Neels Hofmeyrde76f052019-02-26 05:02:46 +01003267 }
3268
3269 deactivate(ccrel);
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003270
3271 f_sleep(1.0);
3272}
3273testcase TC_mo_cc_bssmap_clear() runs on MTC_CT {
3274 var BSC_ConnHdlr vc_conn;
3275 f_init();
3276
3277 vc_conn := f_start_handler(refers(f_tc_mo_cc_bssmap_clear), 43);
3278 vc_conn.done;
3279}
3280
Harald Weltee13cfb22019-04-23 16:52:02 +02003281
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003282/* LU followed by MT call and MT USSD request during this call */
Harald Weltee13cfb22019-04-23 16:52:02 +02003283friend function f_tc_lu_and_mt_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003284runs on BSC_ConnHdlr {
3285 f_init_handler(pars);
3286
3287 /* Call parameters taken from f_tc_lu_and_mt_call */
3288 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
3289 cpars.mgcp_connection_id_bss := '10004'H;
3290 cpars.mgcp_connection_id_mss := '10005'H;
3291 cpars.mgcp_ep := "rtpbridge/1@mgw";
3292 cpars.bss_rtp_port := 1110;
3293
3294 /* Perform location update */
3295 f_perform_lu();
3296
3297 /* Establish a MT call */
3298 f_mt_call_establish(cpars);
3299
3300 /* Hold the call for some time */
3301 f_sleep(1.0);
3302
3303 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3304 op_code := SS_OP_CODE_USS_REQUEST,
3305 ussd_string := "Please type anything..."
3306 );
3307
3308 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3309 op_code := SS_OP_CODE_USS_REQUEST,
3310 ussd_string := "Nope."
3311 )
3312
3313 /* Compose MT SS/REGISTER message with network-originated request */
3314 var template (value) PDU_ML3_NW_MS ussd_req := ts_ML3_MT_SS_REGISTER(
3315 tid := 0, /* FIXME: most likely, it should be 0 */
3316 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3317 facility := valueof(facility_req)
3318 );
3319
3320 /* Compose HLR -> MSC GSUP message */
3321 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3322 imsi := g_pars.imsi,
3323 sid := '20000101'O,
3324 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3325 ss := valueof(facility_req)
3326 );
3327
3328 /* Send it to MSC */
3329 GSUP.send(gsup_req);
3330 /* Expect MT REGISTER message with USSD request */
3331 f_expect_mt_dtap_msg(ussd_req);
3332
3333 /* Compose a new MO SS/FACILITY message with response */
3334 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
3335 tid := 0, /* FIXME: it shall match the request tid */
3336 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3337 facility := valueof(facility_rsp)
3338 );
3339
3340 /* Compose expected MSC -> HLR GSUP message */
3341 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
3342 imsi := g_pars.imsi,
3343 sid := '20000101'O,
3344 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3345 ss := valueof(facility_rsp)
3346 );
3347
3348 /* MS sends response */
3349 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
3350 f_expect_gsup_msg(gsup_rsp);
3351
3352 /* Compose expected MT SS/RELEASE COMPLETE message */
3353 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
3354 tid := 0, /* FIXME: it shall match the request tid */
3355 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3356 facility := omit
3357 );
3358
3359 /* Compose MSC -> HLR GSUP message */
3360 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
3361 imsi := g_pars.imsi,
3362 sid := '20000101'O,
3363 state := OSMO_GSUP_SESSION_STATE_END
3364 );
3365
3366 /* Finally, HLR terminates the session */
3367 GSUP.send(gsup_term);
3368 /* Expect MT RELEASE COMPLETE without Facility IE */
3369 f_expect_mt_dtap_msg(ussd_term);
3370
3371 /* Hold the call for some time */
3372 f_sleep(1.0);
3373
3374 /* Release the call (does Clear Complete itself) */
3375 f_call_hangup(cpars, true);
3376}
3377testcase TC_lu_and_mt_ussd_during_mt_call() runs on MTC_CT {
3378 var BSC_ConnHdlr vc_conn;
3379 f_init();
3380 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_during_mt_call), 49);
3381 vc_conn.done;
3382}
3383
Harald Weltee13cfb22019-04-23 16:52:02 +02003384
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07003385/* LU followed by MO USSD request and MO Release during transaction */
Harald Weltee13cfb22019-04-23 16:52:02 +02003386friend function f_tc_lu_and_mo_ussd_mo_release(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07003387runs on BSC_ConnHdlr {
3388 f_init_handler(pars);
3389
3390 /* Perform location update */
3391 f_perform_lu();
3392
3393 /* Send CM Service Request for SS/USSD */
3394 f_establish_fully(EST_TYPE_SS_ACT);
3395
3396 /* We need to inspect GSUP activity */
3397 f_create_gsup_expect(hex2str(g_pars.imsi));
3398
3399 var template OCTN facility_ms_req := f_USSD_FACILITY_IE_INVOKE(
3400 invoke_id := 1, /* Initial request */
3401 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3402 ussd_string := "*6766*266#"
3403 );
3404
3405 var template OCTN facility_net_req := f_USSD_FACILITY_IE_INVOKE(
3406 invoke_id := 2, /* Counter request */
3407 op_code := SS_OP_CODE_USS_REQUEST,
3408 ussd_string := "Password?!?"
3409 )
3410
3411 /* Compose MO SS/REGISTER message with request */
3412 var template (value) PDU_ML3_MS_NW ussd_ms_req := ts_ML3_MO_SS_REGISTER(
3413 tid := 1, /* We just need a single transaction */
3414 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3415 facility := valueof(facility_ms_req)
3416 );
3417
3418 /* Compose expected MSC -> HLR message */
3419 var template GSUP_PDU gsup_ms_req := tr_GSUP_PROC_SS_REQ(
3420 imsi := g_pars.imsi,
3421 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3422 ss := valueof(facility_ms_req)
3423 );
3424
3425 /* To be used for sending response with correct session ID */
3426 var GSUP_PDU gsup_ms_req_complete;
3427
3428 /* Initiate a new transaction */
3429 BSSAP.send(ts_PDU_DTAP_MO(ussd_ms_req));
3430 /* Expect GSUP request with original Facility IE */
3431 gsup_ms_req_complete := f_expect_gsup_msg(gsup_ms_req);
3432
3433 /* Compose the response from HLR using received session ID */
3434 var template (value) GSUP_PDU gsup_net_req := ts_GSUP_PROC_SS_REQ(
3435 imsi := g_pars.imsi,
3436 sid := gsup_ms_req_complete.ies[1].val.session_id,
3437 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3438 ss := valueof(facility_net_req)
3439 );
3440
3441 /* Compose expected MT SS/FACILITY template with counter request */
3442 var template PDU_ML3_NW_MS ussd_net_req := tr_ML3_MT_SS_FACILITY(
3443 tid := 1, /* Response should arrive within the same transaction */
3444 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3445 facility := valueof(facility_net_req)
3446 );
3447
3448 /* Send response over GSUP */
3449 GSUP.send(gsup_net_req);
3450 /* Expect MT SS/FACILITY message with counter request */
3451 f_expect_mt_dtap_msg(ussd_net_req);
3452
3453 /* Compose MO SS/RELEASE COMPLETE */
3454 var template (value) PDU_ML3_MS_NW ussd_abort := ts_ML3_MO_SS_RELEASE_COMPLETE(
3455 tid := 1, /* Response should arrive within the same transaction */
3456 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3457 facility := omit
3458 /* TODO: cause? */
3459 );
3460
3461 /* Compose expected HLR -> MSC abort message */
3462 var template GSUP_PDU gsup_abort := tr_GSUP_PROC_SS_REQ(
3463 imsi := g_pars.imsi,
3464 sid := gsup_ms_req_complete.ies[1].val.session_id,
3465 state := OSMO_GSUP_SESSION_STATE_END
3466 );
3467
3468 /* Abort transaction */
3469 BSSAP.send(ts_PDU_DTAP_MO(ussd_abort));
3470 /* Expect GSUP message indicating abort */
3471 f_expect_gsup_msg(gsup_abort);
3472
3473 f_expect_clear();
3474}
3475testcase TC_lu_and_mo_ussd_mo_release() runs on MTC_CT {
3476 var BSC_ConnHdlr vc_conn;
3477 f_init();
3478 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_mo_release), 50);
3479 vc_conn.done;
3480}
3481
Harald Weltee13cfb22019-04-23 16:52:02 +02003482
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003483/* LU followed by MO USSD request and MT Release due to timeout */
Harald Weltee13cfb22019-04-23 16:52:02 +02003484friend function f_tc_lu_and_ss_session_timeout(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003485runs on BSC_ConnHdlr {
3486 f_init_handler(pars);
3487
3488 /* Perform location update */
3489 f_perform_lu();
3490
3491 /* Send CM Service Request for SS/USSD */
3492 f_establish_fully(EST_TYPE_SS_ACT);
3493
3494 /* We need to inspect GSUP activity */
3495 f_create_gsup_expect(hex2str(g_pars.imsi));
3496
3497 var template OCTN facility_ms_req := f_USSD_FACILITY_IE_INVOKE(
3498 invoke_id := 1,
3499 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3500 ussd_string := "#release_me");
3501
3502 /* Compose MO SS/REGISTER message with request */
3503 var template (value) PDU_ML3_MS_NW ussd_ms_req := ts_ML3_MO_SS_REGISTER(
3504 tid := 1, /* An arbitrary transaction identifier */
3505 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3506 facility := valueof(facility_ms_req));
3507
3508 /* Compose expected MSC -> HLR message */
3509 var template GSUP_PDU gsup_ms_req := tr_GSUP_PROC_SS_REQ(
3510 imsi := g_pars.imsi,
3511 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3512 ss := valueof(facility_ms_req));
3513
3514 /* To be used for sending response with correct session ID */
3515 var GSUP_PDU gsup_ms_req_complete;
3516
3517 /* Initiate a new SS transaction */
3518 BSSAP.send(ts_PDU_DTAP_MO(ussd_ms_req));
3519 /* Expect GSUP request with original Facility IE */
3520 gsup_ms_req_complete := f_expect_gsup_msg(gsup_ms_req);
3521
3522 /* Don't respond, wait for timeout */
3523 f_sleep(3.0);
3524
3525 var template PDU_ML3_NW_MS dtap_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
3526 tid := 1, /* Should match the request's tid */
3527 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3528 cause := *, /* TODO: expect some specific value */
3529 facility := omit);
3530
3531 var template GSUP_PDU gsup_rel := tr_GSUP_PROC_SS_ERR(
3532 imsi := g_pars.imsi,
3533 sid := gsup_ms_req_complete.ies[1].val.session_id,
3534 state := OSMO_GSUP_SESSION_STATE_END,
3535 cause := ?); /* TODO: expect some specific value */
3536
3537 /* Expect release on both interfaces */
3538 interleave {
3539 [] BSSAP.receive(tr_PDU_DTAP_MT(dtap_rel)) { };
3540 [] GSUP.receive(gsup_rel) { };
3541 }
3542
3543 f_expect_clear();
3544 setverdict(pass);
3545}
3546testcase TC_lu_and_ss_session_timeout() runs on MTC_CT {
3547 var BSC_ConnHdlr vc_conn;
3548 f_init();
Vadim Yanitskiy36d28dd2018-12-03 02:45:45 +07003549 f_vty_config(MSCVTY, "msc", "ncss guard-timeout 3");
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003550 vc_conn := f_start_handler(refers(f_tc_lu_and_ss_session_timeout), 51);
3551 vc_conn.done;
Vadim Yanitskiy36d28dd2018-12-03 02:45:45 +07003552 f_vty_config(MSCVTY, "msc", "ncss guard-timeout 0");
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003553}
3554
Harald Weltee13cfb22019-04-23 16:52:02 +02003555
Stefan Sperling89eb1f32018-12-17 15:06:20 +01003556/* A5/1 only permitted on network side; attempt an invalid CIPHER MODE COMPLETE with A5/3 which MSC should reject. */
3557private function f_tc_cipher_complete_with_invalid_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3558 pars.net.expect_auth := true;
3559 pars.net.expect_ciph := true;
3560 pars.net.kc_support := '02'O; /* A5/1 only */
3561 f_init_handler(pars);
3562
3563 g_pars.vec := f_gen_auth_vec_2g();
3564
3565 /* Can't use f_perform_lu() directly. Code below is based on it. */
3566
3567 /* tell GSUP dispatcher to send this IMSI to us */
3568 f_create_gsup_expect(hex2str(g_pars.imsi));
3569
3570 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
3571 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
Harald Weltedceacc72019-04-21 20:58:35 +02003572 f_cl3_or_initial_ue(l3_lu);
Stefan Sperling89eb1f32018-12-17 15:06:20 +01003573
3574 f_mm_auth();
3575
3576 var OCT1 a5_net := f_alg_mask_from_cm(g_pars.cm2);
3577 var OCT1 a5_intersect := g_pars.net.kc_support and4b a5_net;
3578 alt {
3579 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(a5_intersect, g_pars.vec.kc)) {
3580 BSSAP.send(ts_BSSMAP_CipherModeCompl(int2oct(4 /* "accept" A5/3 */, 1)));
3581 }
3582 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?, g_pars.vec.kc)) {
3583 setverdict(fail, "Wrong ciphering algorithm mask in CiphModCmd");
3584 mtc.stop;
3585 }
3586 [] BSSAP.receive {
3587 setverdict(fail, "Unknown/unexpected BSSAP received");
3588 mtc.stop;
3589 }
3590 }
3591
3592 /* Expect LU reject from MSC. */
3593 alt {
3594 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
3595 setverdict(pass);
3596 }
3597 [] BSSAP.receive {
3598 setverdict(fail, "Unknown/unexpected BSSAP received");
3599 mtc.stop;
3600 }
3601 }
Stefan Sperlingc620b352018-12-18 17:23:36 +01003602 f_expect_clear();
Stefan Sperling89eb1f32018-12-17 15:06:20 +01003603}
3604
3605testcase TC_cipher_complete_with_invalid_cipher() runs on MTC_CT {
3606 var BSC_ConnHdlr vc_conn;
3607 f_init();
3608 f_vty_config(MSCVTY, "network", "encryption a5 1");
3609
3610 vc_conn := f_start_handler(refers(f_tc_cipher_complete_with_invalid_cipher), 52);
3611 vc_conn.done;
3612}
3613
Harald Weltef640a012018-04-14 17:49:21 +02003614/* TODO (SMS):
3615 * different user data lengths
3616 * SMPP transaction mode with unsuccessful delivery
3617 * queued MT-SMS with no paging response + later delivery
3618 * different data coding schemes
3619 * multi-part SMS
3620 * user-data headers
3621 * TP-PID for SMS to SIM
3622 * behavior if SMS memory is full + RP-SMMA
3623 * delivery reports
3624 * SMPP osmocom extensions
3625 * more-messages-to-send
3626 * SMS during ongoing call (SACCH/SAPI3)
3627 */
3628
3629/* TODO (General):
Harald Welteba7b6d92018-01-23 21:32:34 +01003630 * continue to send repeated MO signalling messages to keep channel open: does MSC tmeout?
3631 * malformed messages (missing IE, invalid message type): properly rejected?
3632 * MT call while LU or is ongoing: Do we use existing lchan or page while lchan active?
3633 * 3G/2G auth permutations
3634 * encryption algorithms vs. classmark vs. vty config
Harald Welteba7b6d92018-01-23 21:32:34 +01003635 * send new transaction after/during clear (like SMS, ...)
Harald Welte45164da2018-01-24 12:51:27 +01003636 * too long L3 INFO in DTAP
3637 * too long / padded BSSAP
3638 * too long / short TLV values
Harald Welteba7b6d92018-01-23 21:32:34 +01003639 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01003640
Harald Weltee13cfb22019-04-23 16:52:02 +02003641/***********************************************************************
3642 * SGsAP Testing
3643 ***********************************************************************/
3644
Philipp Maier948747b2019-04-02 15:22:33 +02003645/* Check if a subscriber exists in the VLR */
3646private function f_ctrl_subscr_in_vlr(charstring imsi_or_msisdn) runs on BSC_ConnHdlr return boolean {
3647
3648 var CtrlValue active_subsribers;
3649 var integer rc;
3650 active_subsribers := f_ctrl_get(IPA_CTRL, "subscriber-list-active-v1");
3651
3652 rc := f_strstr(active_subsribers, imsi_or_msisdn);
3653 if (rc < 0) {
3654 return false;
3655 }
3656
3657 return true;
3658}
3659
Harald Welte4263c522018-12-06 11:56:27 +01003660/* Perform a location updatye at the A-Interface and run some checks to confirm
3661 * that everything is back to normal. */
3662private function f_sgsap_bssmap_screening() runs on BSC_ConnHdlr {
3663 var SmsParameters spars := valueof(t_SmsPars);
3664
3665 /* Perform a location update, the SGs association is expected to fall
3666 * back to NULL */
3667 f_perform_lu();
3668 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
3669
3670 /* Trigger a paging request and expect the paging on BSSMAP, this is
3671 * to make sure that pagings are sent throught the A-Interface again
3672 * and not throught the SGs interface.*/
Harald Welte6811d102019-04-14 22:23:14 +02003673 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Welte4263c522018-12-06 11:56:27 +01003674 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
3675
3676 alt {
Harald Weltee13cfb22019-04-23 16:52:02 +02003677 [g_pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)); {
3678 setverdict(pass);
3679 }
3680 [not g_pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi), ?)) {
Harald Welte4263c522018-12-06 11:56:27 +01003681 setverdict(pass);
3682 }
3683 [] SGsAP.receive {
3684 setverdict(fail, "Received unexpected message on SGs");
3685 }
3686 }
3687
3688 /* Send an SMS to make sure that also payload messages are routed
3689 * throught the A-Interface again */
3690 f_establish_fully(EST_TYPE_MO_SMS);
3691 f_mo_sms(spars);
3692 f_expect_clear();
3693}
3694
3695private function f_tc_sgsap_reset(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3696 var charstring vlr_name;
3697 f_init_handler(pars);
3698
3699 vlr_name := f_sgsap_reset_mme(mp_mme_name);
3700 log("VLR name: ", vlr_name);
3701 setverdict(pass);
Neels Hofmeyrc0b520d2019-03-06 15:35:50 +01003702 f_sleep(1.0);
Harald Welte4263c522018-12-06 11:56:27 +01003703}
3704
3705testcase TC_sgsap_reset() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003706 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01003707 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003708 f_init(1, true);
3709 pars := f_init_pars(11810, true);
3710 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_reset), pars);
Harald Welte4263c522018-12-06 11:56:27 +01003711 vc_conn.done;
3712}
3713
3714/* like f_mm_auth() but for SGs */
3715function f_mm_auth_sgs() runs on BSC_ConnHdlr {
3716 if (g_pars.net.expect_auth) {
3717 g_pars.vec := f_gen_auth_vec_3g();
3718 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G3G(g_pars.vec.rand,
3719 g_pars.vec.sres,
3720 g_pars.vec.kc,
3721 g_pars.vec.ik,
3722 g_pars.vec.ck,
3723 g_pars.vec.autn,
3724 g_pars.vec.res));
3725 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
3726 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
3727 SGsAP.receive(tr_ML3_MT_MM_AUTH_REQ_3G(g_pars.vec.rand, g_pars.vec.autn));
3728 SGsAP.send(ts_ML3_MT_MM_AUTH_RESP_3G(g_pars.vec.sres, g_pars.vec.res));
3729 }
3730}
3731
3732/* like f_perform_lu(), but on SGs rather than BSSAP */
3733function f_sgs_perform_lu() runs on BSC_ConnHdlr {
3734 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
3735 var PDU_SGsAP lur;
3736 var PDU_SGsAP lua;
3737 var PDU_SGsAP mm_info;
3738 var octetstring mm_info_dtap;
3739
3740 /* tell GSUP dispatcher to send this IMSI to us */
3741 f_create_gsup_expect(hex2str(g_pars.imsi));
3742
3743 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
3744 ts_SGsAP_LAI('901'H, '70'H, 2342)));
3745 /* Old LAI, if MS sends it */
3746 /* TMSI status, if MS has no valid TMSI */
3747 /* IMEISV, if it supports "automatic device detection" */
3748 /* TAI, if available in MME */
3749 /* E-CGI, if available in MME */
3750 SGsAP.send(lur);
3751
3752 /* FIXME: is this really done over SGs? The Ue is already authenticated
3753 * via the MME ... */
3754 f_mm_auth_sgs();
3755
3756 /* Expect MSC to perform LU with HLR */
3757 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
3758 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
3759 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
3760 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
3761
3762 alt {
3763 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) -> value lua {
3764 if (isvalue(lua.sGsAP_LOCATION_UPDATE_ACCEPT.newTMSIorIMSI.iD.iD.tmsi_ptmsi.octets)) {
3765 g_pars.tmsi :=lua.sGsAP_LOCATION_UPDATE_ACCEPT.newTMSIorIMSI.iD.iD.tmsi_ptmsi.octets
3766 SGsAP.send(ts_SGsAP_TMSI_REALL_CMPL(g_pars.imsi));
3767 }
3768 setverdict(pass);
3769 }
3770 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
3771 setverdict(fail, "Received LU-REJECT instead of ACCEPT");
3772 }
3773 [] SGsAP.receive {
3774 setverdict(fail, "Received unexpected message on SGs");
3775 }
3776 }
3777
3778 /* Check MM information */
3779 if (mp_mm_info == true) {
3780 SGsAP.receive(tr_SGsAP_MM_INFO_REQ(g_pars.imsi, ?)) -> value mm_info;
3781 mm_info_dtap := '0532'O & mm_info.sGsAP_MM_INFORMATION_REQUEST.mM_Information.information;
3782 if (not match(dec_PDU_ML3_NW_MS(mm_info_dtap), tr_ML3_MT_MM_Info)) {
3783 setverdict(fail, "Unexpected MM Information");
3784 }
3785 }
3786
3787 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
3788}
3789
3790private function f_tc_sgsap_lu(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3791 f_init_handler(pars);
3792 f_sgs_perform_lu();
3793 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
3794
3795 f_sgsap_bssmap_screening();
3796
3797 setverdict(pass);
3798}
3799testcase TC_sgsap_lu() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003800 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01003801 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003802 f_init(1, true);
3803 pars := f_init_pars(11811, true);
3804 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu), pars);
Harald Welte4263c522018-12-06 11:56:27 +01003805 vc_conn.done;
3806}
3807
3808/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
3809private function f_tc_sgsap_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3810 f_init_handler(pars);
3811 var PDU_SGsAP lur;
3812
3813 f_create_gsup_expect(hex2str(g_pars.imsi));
3814 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
3815 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
3816 ts_SGsAP_LAI('901'H, '70'H, 2342)));
3817 SGsAP.send(lur);
3818
3819 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
3820 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
3821 alt {
3822 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
3823 setverdict(pass);
3824 }
3825 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) {
3826 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
3827 mtc.stop;
3828 }
3829 [] SGsAP.receive {
3830 setverdict(fail, "Received unexpected message on SGs");
3831 }
3832 }
3833
3834 f_sgsap_bssmap_screening();
3835
3836 setverdict(pass);
3837}
3838testcase TC_sgsap_lu_imsi_reject() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003839 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01003840 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003841 f_init(1, true);
3842 pars := f_init_pars(11812, true);
Harald Welte4263c522018-12-06 11:56:27 +01003843
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003844 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_imsi_reject), pars);
Harald Welte4263c522018-12-06 11:56:27 +01003845 vc_conn.done;
3846}
3847
3848/* Do LU by IMSI, but then remain silent so that Ts6-1 times out */
3849private function f_tc_sgsap_lu_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3850 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
3851 var PDU_SGsAP lur;
3852
3853 f_init_handler(pars);
3854
3855 /* tell GSUP dispatcher to send this IMSI to us */
3856 f_create_gsup_expect(hex2str(g_pars.imsi));
3857
3858 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
3859 ts_SGsAP_LAI('901'H, '70'H, 2342)));
3860 /* Old LAI, if MS sends it */
3861 /* TMSI status, if MS has no valid TMSI */
3862 /* IMEISV, if it supports "automatic device detection" */
3863 /* TAI, if available in MME */
3864 /* E-CGI, if available in MME */
3865 SGsAP.send(lur);
3866
3867 /* FIXME: is this really done over SGs? The Ue is already authenticated
3868 * via the MME ... */
3869 f_mm_auth_sgs();
3870
3871 /* Expect MSC to perform LU with HLR */
3872 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
3873 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
3874 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
3875 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
3876
3877 alt {
3878 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) {
3879 setverdict(pass);
3880 }
3881 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
3882 setverdict(fail, "Received LU-REJECT instead of ACCEPT");
3883 }
3884 [] SGsAP.receive {
3885 setverdict(fail, "Received unexpected message on SGs");
3886 }
3887 }
3888
3889 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
3890
3891 /* Wait until the VLR has abort the TMSI reallocation procedure */
3892 f_sleep(45.0);
3893
3894 /* The outcome does not change the SGs state, see also 5.2.3.4 */
3895 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
3896
3897 f_sgsap_bssmap_screening();
3898
3899 setverdict(pass);
3900}
3901testcase TC_sgsap_lu_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003902 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01003903 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003904 f_init(1, true);
3905 pars := f_init_pars(11813, true);
Harald Welte4263c522018-12-06 11:56:27 +01003906
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003907 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01003908 vc_conn.done;
3909}
3910
3911private function f_tc_sgsap_expl_imsi_det_eps(charstring id, BSC_ConnHdlrPars pars)
3912runs on BSC_ConnHdlr {
3913 f_init_handler(pars);
3914 f_sgs_perform_lu();
3915 f_sleep(3.0);
3916
3917 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
3918 SGsAP.send(ts_SGsAP_EPS_DETACH_IND(g_pars.imsi, mme_name, UE_initiated));
3919 SGsAP.receive(tr_SGsAP_EPS_DETACH_ACK(g_pars.imsi));
3920 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
3921
3922 f_sgsap_bssmap_screening();
3923
3924 setverdict(pass);
3925}
3926testcase TC_sgsap_expl_imsi_det_eps() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003927 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01003928 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003929 f_init(1, true);
3930 pars := f_init_pars(11814, true);
3931 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_expl_imsi_det_eps), pars);
Harald Welte4263c522018-12-06 11:56:27 +01003932 vc_conn.done;
3933}
3934
Philipp Maierfc19f172019-03-21 11:17:54 +01003935private function f_tc_sgsap_impl_imsi_det_eps(charstring id, BSC_ConnHdlrPars pars)
3936runs on BSC_ConnHdlr {
3937 f_init_handler(pars);
3938 f_sgs_perform_lu();
3939 f_sleep(3.0);
3940
3941 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
3942 SGsAP.send(ts_SGsAP_EPS_DETACH_IND(g_pars.imsi, mme_name, network_initiated));
3943 SGsAP.receive(tr_SGsAP_EPS_DETACH_ACK(g_pars.imsi));
3944 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
3945
3946 f_sgsap_bssmap_screening();
3947
3948 setverdict(pass);
3949}
3950testcase TC_sgsap_impl_imsi_det_eps() runs on MTC_CT {
3951 var BSC_ConnHdlrPars pars;
3952 var BSC_ConnHdlr vc_conn;
3953 f_init(1, true);
3954 pars := f_init_pars(11814, true);
3955 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_impl_imsi_det_eps), pars);
3956 vc_conn.done;
3957}
3958
Harald Welte4263c522018-12-06 11:56:27 +01003959private function f_tc_sgsap_expl_imsi_det_noneps(charstring id, BSC_ConnHdlrPars pars)
3960runs on BSC_ConnHdlr {
3961 f_init_handler(pars);
3962 f_sgs_perform_lu();
3963 f_sleep(3.0);
3964
3965 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
3966 SGsAP.send(ts_SGsAP_IMSI_DETACH_IND(g_pars.imsi, mme_name, combined_UE_initiated));
3967 SGsAP.receive(tr_SGsAP_IMSI_DETACH_ACK(g_pars.imsi));
Philipp Maierd08e7e72019-04-02 15:27:10 +02003968
3969 if (f_ctrl_subscr_in_vlr(hex2str(g_pars.imsi))) {
3970 setverdict(fail, "subscriber not removed from VLR");
3971 }
Harald Welte4263c522018-12-06 11:56:27 +01003972
3973 f_sgsap_bssmap_screening();
3974
3975 setverdict(pass);
3976}
3977testcase TC_sgsap_expl_imsi_det_noneps() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003978 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01003979 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003980 f_init(1, true);
3981 pars := f_init_pars(11815, true);
3982 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_expl_imsi_det_noneps), pars);
Harald Welte4263c522018-12-06 11:56:27 +01003983 vc_conn.done;
3984}
3985
Philipp Maier5d812702019-03-21 10:51:26 +01003986private function f_tc_sgsap_impl_imsi_det_noneps(charstring id, BSC_ConnHdlrPars pars)
3987runs on BSC_ConnHdlr {
3988 f_init_handler(pars);
3989 f_sgs_perform_lu();
3990 f_sleep(3.0);
3991
3992 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
3993 SGsAP.send(ts_SGsAP_IMSI_DETACH_IND(g_pars.imsi, mme_name, implicit_network_initiated));
3994 SGsAP.receive(tr_SGsAP_IMSI_DETACH_ACK(g_pars.imsi));
3995
3996 if (f_ctrl_subscr_in_vlr(hex2str(g_pars.imsi))) {
3997 setverdict(fail, "subscriber not removed from VLR");
3998 }
3999
4000 f_sgsap_bssmap_screening();
4001
4002 setverdict(pass);
4003}
4004testcase TC_sgsap_impl_imsi_det_noneps() runs on MTC_CT {
4005 var BSC_ConnHdlrPars pars;
4006 var BSC_ConnHdlr vc_conn;
4007 f_init(1, true);
4008 pars := f_init_pars(11815, true);
4009 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_impl_imsi_det_noneps), pars);
4010 vc_conn.done;
4011}
4012
Harald Welte4263c522018-12-06 11:56:27 +01004013/* Trigger a paging request via VTY and send a paging reject in response */
4014private function f_tc_sgsap_paging_rej(charstring id, BSC_ConnHdlrPars pars)
4015runs on BSC_ConnHdlr {
4016 f_init_handler(pars);
4017 f_sgs_perform_lu();
4018 f_sleep(1.0);
4019
4020 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4021 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4022 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4023 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4024
4025 /* Initiate paging via VTY */
4026 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4027 alt {
4028 [] SGsAP.receive(exp_resp) {
4029 setverdict(pass);
4030 }
4031 [] SGsAP.receive {
4032 setverdict(fail, "Received unexpected message on SGs");
4033 }
4034 }
4035
4036 /* Now reject the paging */
4037 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, IMSI_unknown));
4038
4039 /* Wait for the states inside the MSC to settle and check the state
4040 * of the SGs Association */
4041 f_sleep(1.0);
4042 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4043
4044 /* FIXME: At the moment we send an IMSI_unknown as cause code, which is fine,
4045 * but we also need to cover tha case where the cause code indicates an
4046 * "IMSI detached for EPS services". In those cases the VLR is expected to
4047 * try paging on tha A/Iu interface. This will be another testcase similar to
4048 * this one, but extended with checks for the presence of the A/Iu paging
4049 * messages. */
4050
4051 f_sgsap_bssmap_screening();
4052
4053 setverdict(pass);
4054}
4055testcase TC_sgsap_paging_rej() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004056 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004057 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004058 f_init(1, true);
4059 pars := f_init_pars(11816, true);
4060 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_rej), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004061 vc_conn.done;
4062}
4063
4064/* Trigger a paging request via VTY and send a paging reject that indicates
4065 * that the subscriber intentionally rejected the call. */
4066private function f_tc_sgsap_paging_subscr_rej(charstring id, BSC_ConnHdlrPars pars)
4067runs on BSC_ConnHdlr {
4068 f_init_handler(pars);
4069 f_sgs_perform_lu();
4070 f_sleep(1.0);
4071
4072 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4073 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4074 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4075 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4076
4077 /* Initiate paging via VTY */
4078 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4079 alt {
4080 [] SGsAP.receive(exp_resp) {
4081 setverdict(pass);
4082 }
4083 [] SGsAP.receive {
4084 setverdict(fail, "Received unexpected message on SGs");
4085 }
4086 }
4087
4088 /* Now reject the paging */
4089 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, user_rejected_mobile_terminating_CS_fallback_call));
4090
4091 /* Wait for the states inside the MSC to settle and check the state
4092 * of the SGs Association */
4093 f_sleep(1.0);
4094 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4095
4096 /* FIXME: The VLR is supposed to trigger an User Determined User Busy (UDUB) as specified
4097 * in 3GPP TS 24.082, this is not yet implemented in the MSC or in this tests, we need
4098 * to check back how this works and how it can be tested */
4099
4100 f_sgsap_bssmap_screening();
4101
4102 setverdict(pass);
4103}
4104testcase TC_sgsap_paging_subscr_rej() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004105 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004106 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004107 f_init(1, true);
4108 pars := f_init_pars(11817, true);
4109 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_subscr_rej), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004110 vc_conn.done;
4111}
4112
4113/* Trigger a paging request via VTY and send an UE unreacable messge in response */
4114private function f_tc_sgsap_paging_ue_unr(charstring id, BSC_ConnHdlrPars pars)
4115runs on BSC_ConnHdlr {
4116 f_init_handler(pars);
4117 f_sgs_perform_lu();
4118 f_sleep(1.0);
4119
4120 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4121 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4122 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4123 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4124
4125 /* Initiate paging via VTY */
4126 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4127 alt {
4128 [] SGsAP.receive(exp_resp) {
4129 setverdict(pass);
4130 }
4131 [] SGsAP.receive {
4132 setverdict(fail, "Received unexpected message on SGs");
4133 }
4134 }
4135
4136 /* Now pretend that the UE is unreachable */
4137 SGsAP.send(ts_SGsAP_UE_UNREACHABLE(g_pars.imsi, UE_unreachable));
4138
4139 /* Wait for the states inside the MSC to settle and check the state
4140 * of the SGs Association. */
4141 f_sleep(1.0);
4142 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4143
4144 f_sgsap_bssmap_screening();
4145
4146 setverdict(pass);
4147}
4148testcase TC_sgsap_paging_ue_unr() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004149 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004150 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004151 f_init(1, true);
4152 pars := f_init_pars(11818, true);
4153 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_ue_unr), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004154 vc_conn.done;
4155}
4156
4157/* Trigger a paging request via VTY but don't respond to it */
4158private function f_tc_sgsap_paging_and_nothing(charstring id, BSC_ConnHdlrPars pars)
4159runs on BSC_ConnHdlr {
4160 f_init_handler(pars);
4161 f_sgs_perform_lu();
4162 f_sleep(1.0);
4163
4164 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4165 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4166 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4167 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4168
4169 /* Initiate paging via VTY */
4170 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4171 alt {
4172 [] SGsAP.receive(exp_resp) {
4173 setverdict(pass);
4174 }
4175 [] SGsAP.receive {
4176 setverdict(fail, "Received unexpected message on SGs");
4177 }
4178 }
4179
4180 /* Now do nothing, the MSC/VLR should fail silently to page after a
4181 * few seconds, The SGs association must remain unchanged. */
4182 f_sleep(15.0);
4183 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4184
4185 f_sgsap_bssmap_screening();
4186
4187 setverdict(pass);
4188}
4189testcase TC_sgsap_paging_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004190 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004191 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004192 f_init(1, true);
4193 pars := f_init_pars(11819, true);
4194 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004195 vc_conn.done;
4196}
4197
4198/* Trigger a paging request via VTY and slip in an LU */
4199private function f_tc_sgsap_paging_and_lu(charstring id, BSC_ConnHdlrPars pars)
4200runs on BSC_ConnHdlr {
4201 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4202 f_init_handler(pars);
4203
4204 /* First we prepar the situation, where the SGs association is in state
4205 * NULL and the confirmed by radio contact indicator is set to false
4206 * as well. This can be archived by performing an SGs LU and then
4207 * resetting the VLR */
4208 f_sgs_perform_lu();
4209 f_sgsap_reset_mme(mp_mme_name);
4210 f_sleep(1.0);
4211 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4212
4213 /* Perform a paging, expect the paging messages on the SGs interface */
4214 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4215 alt {
4216 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
4217 setverdict(pass);
4218 }
4219 [] SGsAP.receive {
4220 setverdict(fail, "Received unexpected message on SGs");
4221 }
4222 }
4223
4224 /* Perform the LU as normal */
4225 f_sgs_perform_lu();
4226 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4227
4228 /* Expect a new paging request right after the LU */
4229 alt {
4230 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
4231 setverdict(pass);
4232 }
4233 [] SGsAP.receive {
4234 setverdict(fail, "Received unexpected message on SGs");
4235 }
4236 }
4237
4238 /* Test is done now, lets round everything up by rejecting the paging
4239 * cleanly. */
4240 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, user_rejected_mobile_terminating_CS_fallback_call));
4241 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4242
4243 f_sgsap_bssmap_screening();
4244
4245 setverdict(pass);
4246}
4247testcase TC_sgsap_paging_and_lu() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004248 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004249 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004250 f_init(1, true);
4251 pars := f_init_pars(11820, true);
4252 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_and_lu), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004253 vc_conn.done;
4254}
4255
4256/* Send unexpected unit-data through the SGs interface */
4257private function f_tc_sgsap_unexp_ud(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4258 f_init_handler(pars);
4259 f_sleep(1.0);
4260
4261 /* This simulates what happens when a subscriber without SGs
4262 * association gets unitdata via the SGs interface. */
4263
4264 /* Make sure the subscriber exists and the SGs association
4265 * is in NULL state */
4266 f_perform_lu();
4267 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4268
4269 /* Send some random unit data, the MSC/VLR should send a release
4270 * immediately. */
4271 SGsAP.send(ts_SGsAP_UL_UD(pars.imsi,'1234'O));
4272 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, IMSI_detached_for_EPS_nonEPS_services));
4273
4274 f_sgsap_bssmap_screening();
4275
4276 setverdict(pass);
4277}
4278testcase TC_sgsap_unexp_ud() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004279 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004280 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004281 f_init(1, true);
4282 pars := f_init_pars(11821, true);
4283 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_unexp_ud), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004284 vc_conn.done;
4285}
4286
4287/* Send unsolicited unit-data through the SGs interface */
4288private function f_tc_sgsap_unsol_ud(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4289 f_init_handler(pars);
4290 f_sleep(1.0);
4291
4292 /* This simulates what happens when the MME attempts to send unitdata
4293 * to a subscriber that is completely unknown to the VLR */
4294
4295 /* Send some random unit data, the MSC/VLR should send a release
4296 * immediately. */
4297 SGsAP.send(ts_SGsAP_UL_UD(pars.imsi,'1234'O));
4298 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, IMSI_unknown));
4299
4300 f_sgsap_bssmap_screening();
4301
4302 setverdict(pass);
4303}
4304testcase TC_sgsap_unsol_ud() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004305 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004306 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004307 f_init(1, true);
4308 pars := f_init_pars(11822, true);
4309 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_unsol_ud), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004310 vc_conn.done;
4311}
4312
4313private altstep as_other_sms_sgs() runs on BSC_ConnHdlr {
4314 /* FIXME: Match an actual payload (second questionmark), the type is
4315 * octetstring, how do we use a tr_PDU_DTAP_MT here? */
4316 [] SGsAP.receive(tr_SGsAP_DL_UD(?,?)) {
4317 setverdict(fail, "Unexpected SMS related PDU from MSC");
4318 mtc.stop;
4319 }
4320}
4321
4322/* receive a MT-SMS delivered from the MSC/SMSC over an already existing SGsAP connection */
4323function f_mt_sms_sgs(inout SmsParameters spars)
4324runs on BSC_ConnHdlr {
4325 var template (value) TPDU_RP_DATA_MS_SGSN tp_mo;
4326 var template (value) RPDU_MS_SGSN rp_mo;
4327 var template (value) PDU_ML3_MS_NW l3_mo;
4328
4329 var template TPDU_RP_DATA_SGSN_MS tp_mt;
4330 var template RPDU_SGSN_MS rp_mt;
4331 var template PDU_ML3_NW_MS l3_mt;
4332
4333 var PDU_ML3_NW_MS sgsap_l3_mt;
4334
4335 var default d := activate(as_other_sms_sgs());
4336
4337 /* Expect CP-DATA(RP-DATA(SMS-DELIVER)) */
4338 tp_mt := tr_SMS_DELIVER(?, spars.tp.ud, spars.tp.pid, spars.tp.dcs, ?);
4339 rp_mt := tr_RP_DATA_MT(?, ?, omit, tp_mt);
4340 l3_mt := tr_ML3_MT_SMS(?, c_TIF_ORIG, tr_CP_DATA_MT(rp_mt));
4341
4342 SGsAP.receive(l3_mt) -> value sgsap_l3_mt;
4343
4344 /* Extract relevant identifiers */
4345 spars.tid := bit2int(sgsap_l3_mt.tiOrSkip.transactionId.tio);
4346 spars.rp.msg_ref := sgsap_l3_mt.msgs.sms.cP_DATA.cP_User_Data.cP_RPDU.rP_DATA_SGSN_MS.rP_MessageReference;
4347
4348 /* send CP-ACK for CP-DATA just received */
4349 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_REPL, ts_CP_ACK_MO);
4350
4351 SGsAP.send(l3_mo);
4352
4353 /* send RP-ACK for RP-DATA */
4354 rp_mo := ts_RP_ACK_MO(spars.rp.msg_ref);
4355 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_REPL, ts_CP_DATA_MO(rp_mo));
4356
4357 SGsAP.send(l3_mo);
4358
4359 /* expect CP-ACK for CP-DATA(RP-ACK) just sent */
4360 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_ORIG, tr_CP_ACK_MT);
4361
4362 SGsAP.receive(l3_mt);
4363
4364 deactivate(d);
4365
4366 setverdict(pass);
4367}
4368
4369/* submit a MO-SMS to MSC/SMSC over an already existing SGsAP connection */
4370function f_mo_sms_sgs(inout SmsParameters spars)
4371runs on BSC_ConnHdlr {
4372 var template (value) TPDU_RP_DATA_MS_SGSN tp_mo;
4373 var template (value) RPDU_MS_SGSN rp_mo;
4374 var template (value) PDU_ML3_MS_NW l3_mo;
4375
4376 var template TPDU_RP_DATA_SGSN_MS tp_mt;
4377 var template RPDU_SGSN_MS rp_mt;
4378 var template PDU_ML3_NW_MS l3_mt;
4379
4380 var default d := activate(as_other_sms_sgs());
4381
4382 /* just in case this is routed to SMPP.. */
4383 f_create_smpp_expect(hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue));
4384
4385 tp_mo := ts_SMS_SUBMIT(spars.tp.msg_ref, spars.tp.da, spars.tp.pid, spars.tp.dcs,
4386 spars.tp.udl, spars.tp.ud);
4387 rp_mo := ts_RP_DATA_MO(spars.rp.msg_ref, spars.rp.orig, spars.rp.dest, tp_mo);
4388 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_DATA_MO(rp_mo));
4389
4390 SGsAP.send(l3_mo);
4391
4392 /* receive CP-ACK for CP-DATA above */
4393 SGsAP.receive(tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_ACK_MT));
4394
4395 if (ispresent(spars.exp_rp_err)) {
4396 /* expect an RP-ERROR message from MSC with given cause */
4397 rp_mt := tr_RP_ERROR_MT(spars.rp.msg_ref, spars.exp_rp_err);
4398 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_DATA_MT(rp_mt));
4399 SGsAP.receive(l3_mt);
4400 /* send CP-ACK for CP-DATA just received */
4401 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_ACK_MO);
4402 SGsAP.send(l3_mo);
4403 } else {
4404 /* expect RP-ACK for RP-DATA */
4405 rp_mt := tr_RP_ACK_MT(spars.rp.msg_ref);
4406 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_DATA_MT(rp_mt));
4407 SGsAP.receive(l3_mt);
4408 /* send CP-ACO for CP-DATA just received */
4409 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_ACK_MO);
4410 SGsAP.send(l3_mo);
4411 }
4412
4413 deactivate(d);
4414
4415 setverdict(pass);
4416}
4417
4418private function f_vty_sms_send_conn_hdlr(charstring imsi, charstring msisdn, charstring text)
4419runs on BSC_ConnHdlr {
4420 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
4421}
4422
4423/* Send a MT SMS via SGs interface */
4424private function f_tc_sgsap_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4425 f_init_handler(pars);
4426 f_sgs_perform_lu();
4427 f_sleep(1.0);
4428 var SmsParameters spars := valueof(t_SmsPars);
4429 spars.tp.ud := 'C8329BFD064D9B53'O;
4430
4431 /* Trigger SMS via VTY */
4432 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
4433 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4434
4435 /* Expect a paging request and respond accordingly with a service request */
4436 SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, SMS_indicator, omit));
4437 SGsAP.send(ts_SGsAP_SERVICE_REQ(pars.imsi, SMS_indicator, EMM_CONNECTED));
4438
4439 /* Connection is now live, receive the MT-SMS */
4440 f_mt_sms_sgs(spars);
4441
4442 /* Expect a concluding release from the MSC */
4443 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, omit));
4444
4445 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
4446 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4447
4448 f_sgsap_bssmap_screening();
4449
4450 setverdict(pass);
4451}
4452testcase TC_sgsap_mt_sms() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004453 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004454 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004455 f_init(1, true);
4456 pars := f_init_pars(11823, true);
4457 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004458 vc_conn.done;
4459}
4460
4461/* Send a MO SMS via SGs interface */
4462private function f_tc_sgsap_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4463 f_init_handler(pars);
4464 f_sgs_perform_lu();
4465 f_sleep(1.0);
4466 var SmsParameters spars := valueof(t_SmsPars);
4467 spars.tp.ud := 'C8329BFD064D9B53'O;
4468
4469 /* Send the MO-SMS */
4470 f_mo_sms_sgs(spars);
4471
4472 /* Expect a concluding release from the MSC/VLR */
4473 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, omit));
4474
4475 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
4476 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4477
4478 setverdict(pass);
4479
4480 f_sgsap_bssmap_screening()
4481}
4482testcase TC_sgsap_mo_sms() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004483 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004484 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004485 f_init(1, true);
4486 pars := f_init_pars(11824, true);
4487 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mo_sms), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004488 vc_conn.done;
4489}
4490
4491/* Trigger sending of an MT sms via VTY but never respond to anything */
4492private function f_tc_sgsap_mt_sms_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4493 f_init_handler(pars, 170.0);
4494 f_sgs_perform_lu();
4495 f_sleep(1.0);
4496
4497 var SmsParameters spars := valueof(t_SmsPars);
4498 spars.tp.ud := 'C8329BFD064D9B53'O;
4499 var integer page_count := 0;
4500 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4501 var template PDU_SGsAP exp_pag_req := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, SMS_indicator, omit);
4502 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4503 exp_pag_req.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4504
4505 /* Trigger SMS via VTY */
4506 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
4507
Neels Hofmeyr16237742019-03-06 15:34:01 +01004508 /* Expect the MSC/VLR to page exactly once */
4509 SGsAP.receive(exp_pag_req);
Harald Welte4263c522018-12-06 11:56:27 +01004510
4511 /* Wait some time to make sure the MSC is not delivering any further
4512 * paging messages or anything else that could be unexpected. */
4513 timer T := 20.0;
4514 T.start
4515 alt {
4516 [] SGsAP.receive(exp_pag_req)
4517 {
4518 setverdict(fail, "paging seems not to stop!");
4519 mtc.stop;
4520 }
4521 [] SGsAP.receive {
4522 setverdict(fail, "unexpected SGsAP message received");
4523 self.stop;
4524 }
4525 [] T.timeout {
4526 setverdict(pass);
4527 }
4528 }
4529
4530 /* Even on a failed paging the SGs Association should stay intact */
4531 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4532
4533 /* Note: We do not execute f_sgsap_bssmap_screening() here since the
4534 * MSC/VLR would re-try to deliver the test SMS trigered above and
4535 * so the screening would fail. */
4536
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01004537 f_vty_sms_clear(hex2str(g_pars.imsi));
4538
Harald Welte4263c522018-12-06 11:56:27 +01004539 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " expire");
4540
4541 setverdict(pass);
Neels Hofmeyrb0f82342019-03-06 15:36:51 +01004542
4543 f_sgsap_bssmap_screening();
Harald Welte4263c522018-12-06 11:56:27 +01004544}
4545testcase TC_sgsap_mt_sms_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004546 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004547 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004548 f_init(1, true);
4549 pars := f_init_pars(11825, true);
4550 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004551 vc_conn.done;
4552}
4553
4554/* Trigger sending of an MT sms via VTY but reject the paging immediately */
4555private function f_tc_sgsap_mt_sms_and_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4556 f_init_handler(pars, 150.0);
4557 f_sgs_perform_lu();
4558 f_sleep(1.0);
4559
4560 var SmsParameters spars := valueof(t_SmsPars);
4561 spars.tp.ud := 'C8329BFD064D9B53'O;
4562 var integer page_count := 0;
4563 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4564 var template PDU_SGsAP exp_pag_req := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, SMS_indicator, omit);
4565 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4566 exp_pag_req.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4567
4568 /* Trigger SMS via VTY */
4569 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
4570
4571 /* Expect a paging request and reject it immediately */
4572 SGsAP.receive(exp_pag_req);
4573 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, IMSI_unknown));
4574
4575 /* The MSC/VLR should no longer try to page once the paging has been
4576 * rejected. Wait some time and check if there are no unexpected
4577 * messages on the SGs interface. */
4578 timer T := 20.0;
4579 T.start
4580 alt {
4581 [] SGsAP.receive(exp_pag_req)
4582 {
4583 setverdict(fail, "paging seems not to stop!");
4584 mtc.stop;
4585 }
4586 [] SGsAP.receive {
4587 setverdict(fail, "unexpected SGsAP message received");
4588 self.stop;
4589 }
4590 [] T.timeout {
4591 setverdict(pass);
4592 }
4593 }
4594
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01004595 f_vty_sms_clear(hex2str(g_pars.imsi));
4596
Harald Welte4263c522018-12-06 11:56:27 +01004597 /* A rejected paging with IMSI_unknown (see above) should always send
4598 * the SGs association to NULL. */
4599 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4600
4601 f_sgsap_bssmap_screening();
4602
Harald Welte4263c522018-12-06 11:56:27 +01004603 setverdict(pass);
4604}
4605testcase TC_sgsap_mt_sms_and_reject() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004606 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004607 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004608 f_init(1, true);
4609 pars := f_init_pars(11826, true);
4610 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms_and_reject), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004611 vc_conn.done;
4612}
4613
4614/* Perform an MT CSDB call including LU */
4615private function f_mt_lu_and_csfb_call(charstring id, BSC_ConnHdlrPars pars, boolean bssmap_lu) runs on BSC_ConnHdlr {
4616 f_init_handler(pars);
4617
4618 /* Be sure that the BSSMAP reset is done before we begin. */
4619 f_sleep(2.0);
4620
4621 /* Testcase variation: See what happens when we do a regular BSSMAP
4622 * LU first (this should not hurt in any way!) */
4623 if (bssmap_lu) {
4624 f_perform_lu();
4625 }
4626
4627 f_sgs_perform_lu();
4628 f_sleep(1.0);
4629
4630 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4631 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
4632 cpars.bss_rtp_port := 1110;
4633 cpars.mgcp_connection_id_bss := '10004'H;
4634 cpars.mgcp_connection_id_mss := '10005'H;
4635
4636 /* Note: This is an optional parameter. When the call-agent (MSC) does
4637 * supply a full endpoint name this setting will be overwritten. */
4638 cpars.mgcp_ep := "rtpbridge/1@mgw";
4639
4640 /* Initiate a call via MNCC interface */
4641 f_mt_call_initate(cpars);
4642
4643 /* Expect a paging request and respond accordingly with a service request */
4644 SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit));
4645 SGsAP.send(ts_SGsAP_SERVICE_REQ(pars.imsi, CS_call_indicator, EMM_CONNECTED));
4646
4647 /* Complete the call, hold it for some time and then tear it down */
4648 f_mt_call_complete(cpars);
4649 f_sleep(3.0);
Harald Welte4c422b72019-02-17 16:27:10 +01004650 f_call_hangup(cpars, true, is_csfb := true);
Harald Welte4263c522018-12-06 11:56:27 +01004651
4652 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
4653 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4654
4655 /* Finally simulate the return of the UE to the 4G network */
4656 SGsAP.send(ts_SGsAP_MO_CSFB_IND(pars.imsi));
4657
4658 /* Test for successful return by triggering a paging, when the paging
4659 * request is received via SGs, we can be sure that the MSC/VLR has
4660 * recognized that the UE is now back on 4G */
4661 f_sleep(1.0);
4662 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4663 alt {
4664 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
4665 setverdict(pass);
4666 }
4667 [] SGsAP.receive {
4668 setverdict(fail, "Received unexpected message on SGs");
4669 }
4670 }
4671
4672 f_sgsap_bssmap_screening();
4673
4674 setverdict(pass);
4675}
4676
4677/* Perform a regular BSSAP LU first, do a SGSAP LU and then make a CSFB call */
4678private function f_tc_bssap_lu_sgsap_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4679 f_mt_lu_and_csfb_call(id, pars, true);
4680}
4681testcase TC_bssap_lu_sgsap_lu_and_mt_call() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004682 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004683 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004684 f_init(1, true);
4685 pars := f_init_pars(118139, true);
Harald Welte4263c522018-12-06 11:56:27 +01004686
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004687 vc_conn := f_start_handler_with_pars(refers(f_tc_bssap_lu_sgsap_lu_and_mt_call), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004688 vc_conn.done;
4689}
4690
4691
4692/* Perform a SGSAP LU and then make a CSFB call */
4693private function f_tc_sgsap_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4694 f_mt_lu_and_csfb_call(id, pars, false);
4695}
4696testcase TC_sgsap_lu_and_mt_call() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004697 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004698 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004699 f_init(1, true);
4700 pars := f_init_pars(11827, true);
Harald Welte4263c522018-12-06 11:56:27 +01004701
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004702 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_and_mt_call), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004703 vc_conn.done;
4704}
4705
Philipp Maier628c0052019-04-09 17:36:57 +02004706/* Simulate an HLR/VLR failure */
4707private function f_tc_sgsap_vlr_failure(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4708 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4709 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4710
4711 var PDU_SGsAP lur;
4712
4713 f_init_handler(pars);
4714
4715 /* Attempt location update (which is expected to fail) */
4716 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
4717 ts_SGsAP_LAI('901'H, '70'H, 2342)));
4718 SGsAP.send(lur);
4719
4720 /* Respond to SGsAP-RESET-INDICATION from VLR */
4721 alt {
4722 [] SGsAP.receive(tr_SGsAP_RESET_IND_VLR(vlr_name)); {
4723 SGsAP.send(valueof(ts_SGsAP_RESET_ACK_MME(mme_name)));
4724 setverdict(pass);
4725 }
4726 [] SGsAP.receive {
4727 setverdict(fail, "Received unexpected message on SGs");
4728 }
4729 }
4730
4731 f_sleep(1.0);
4732 setverdict(pass);
4733}
4734testcase TC_sgsap_vlr_failure() runs on MTC_CT {
4735 var BSC_ConnHdlrPars pars;
4736 var BSC_ConnHdlr vc_conn;
4737 f_init(1, true, false);
4738 pars := f_init_pars(11811, true, false);
4739 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_vlr_failure), pars);
4740 vc_conn.done;
4741}
4742
Harald Welte4263c522018-12-06 11:56:27 +01004743/* SGs TODO:
4744 * LU attempt for IMSI without NAM_PS in HLR
4745 * LU attempt with AUTH FAIL due to invalid RES/SRES
4746 * LU attempt with no response from HLR (VLR should timeout + LU REJ)
4747 * LU attempt with new TMSI but without TMSI REALL CMPL baco to VLR
4748 * implicit IMSI detach from EPS
4749 * implicit IMSI detach from non-EPS
4750 * MM INFO
4751 *
4752 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01004753
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02004754private function f_tc_ho_inter_bsc_unknown_cell(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4755 f_init_handler(pars);
4756 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
4757 cpars.bss_rtp_port := 1110;
4758 cpars.mgcp_connection_id_bss := '22222'H;
4759 cpars.mgcp_connection_id_mss := '33333'H;
4760 cpars.mgcp_ep := "rtpbridge/1@mgw";
4761 cpars.mo_call := true;
4762
4763 f_perform_lu();
4764 f_mo_call_establish(cpars);
4765
4766 f_sleep(1.0);
4767
4768 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
4769 var BssmapCause cause := enum2int(cause_val);
4770
4771 var template BSSMAP_FIELD_CellIdentificationList cil;
4772 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('023'H, '42'H, 999) } };
4773
4774 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
4775 BSSAP.receive(tr_BSSMAP_HandoverRequiredReject);
4776
4777 f_call_hangup(cpars, true);
4778}
4779testcase TC_ho_inter_bsc_unknown_cell() runs on MTC_CT {
4780 var BSC_ConnHdlr vc_conn;
4781 f_init();
4782
4783 vc_conn := f_start_handler(refers(f_tc_ho_inter_bsc_unknown_cell), 53);
4784 vc_conn.done;
4785}
4786
4787private altstep as_mgcp_ack_all_mdcx(CallParameters cpars) runs on BSC_ConnHdlr {
4788 var MgcpCommand mgcp_cmd;
4789 [] MGCP.receive(tr_MDCX) -> value mgcp_cmd {
4790 var SDP_Message sdp := valueof(ts_SDP(cpars.mgw_rtp_ip_mss, cpars.mgw_rtp_ip_mss,
4791 hex2str(cpars.mgcp_call_id), "42",
4792 cpars.mgw_rtp_port_mss,
4793 { int2str(cpars.rtp_payload_type) },
4794 { valueof(ts_SDP_rtpmap(cpars.rtp_payload_type,
4795 cpars.rtp_sdp_format)),
4796 valueof(ts_SDP_ptime(20)) }));
4797 MGCP.send(ts_MDCX_ACK(mgcp_cmd.line.trans_id, cpars.mgcp_connection_id_mss, sdp));
4798 repeat;
4799 }
4800}
4801
4802private function f_tc_ho_inter_bsc0(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4803 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
4804 cpars.bss_rtp_port := 1110;
4805 cpars.mgcp_connection_id_bss := '22222'H;
4806 cpars.mgcp_connection_id_mss := '33333'H;
4807 cpars.mgcp_ep := "rtpbridge/1@mgw";
4808 cpars.mo_call := true;
4809
4810 f_init_handler(pars);
4811
4812 f_vty_transceive(MSCVTY, "configure terminal");
4813 f_vty_transceive(MSCVTY, "msc");
4814 f_vty_transceive(MSCVTY, "neighbor a cgi 262 42 23 42 ran-pc 0.24.1");
4815 f_vty_transceive(MSCVTY, "neighbor a lac 5 ran-pc 0.24.2");
4816 f_vty_transceive(MSCVTY, "exit");
4817 f_vty_transceive(MSCVTY, "exit");
4818
4819 f_perform_lu();
4820 f_mo_call_establish(cpars);
4821
4822 f_sleep(1.0);
4823
4824 var default ack_mdcx := activate(as_mgcp_ack_all_mdcx(cpars));
4825
4826 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
4827 var BssmapCause cause := enum2int(cause_val);
4828
4829 var template BSSMAP_FIELD_CellIdentificationList cil;
4830 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('023'H, '42'H, 5) } };
4831
4832 /* old BSS sends Handover Required */
4833 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
4834
4835 /* Now the action goes on in f_tc_ho_inter_bsc1() */
4836
4837 /* MSC forwards the RR Handover Command to old BSS */
4838 var PDU_BSSAP ho_command;
4839 BSSAP.receive(tr_BSSMAP_HandoverCommand) -> value ho_command;
4840
4841 log("GOT HandoverCommand", ho_command);
4842
4843 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
4844
4845 /* f_tc_ho_inter_bsc1() completes Handover, then expecting a Clear here. */
4846 f_expect_clear();
4847
4848 log("FIRST inter-BSC Handover done");
4849
4850
4851 /* ------------------------ */
4852
4853 /* Ok, that went well, now the other BSC is handovering back here --
4854 * from now on this here is the new BSS. */
4855 f_create_bssmap_exp_handoverRequest(193);
4856
4857 var PDU_BSSAP ho_request;
4858 BSSAP.receive(tr_BSSMAP_HandoverRequest) -> value ho_request;
4859
4860 /* new BSS composes a RR Handover Command */
4861 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
4862 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
4863 var BSSMAP_IE_AoIP_TransportLayerAddress tla := valueof(ts_BSSMAP_IE_AoIP_TLA4('01020304'O, 2342));
4864 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
4865 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
4866
4867 /* Now f_tc_ho_inter_bsc1() expects HandoverCommand */
4868
4869 f_sleep(0.5);
4870
4871 /* Notify that the MS is now over here */
4872
4873 BSSAP.send(ts_BSSMAP_HandoverDetect);
4874 f_sleep(0.1);
4875 BSSAP.send(ts_BSSMAP_HandoverComplete);
4876
4877 f_sleep(3.0);
4878
4879 deactivate(ack_mdcx);
4880
4881 var default ccrel := activate(as_optional_cc_rel(cpars, true));
4882
4883 /* blatant cheating */
4884 var N_Sd_Array last_n_sd := f_bssmap_last_n_sd();
4885 last_n_sd[0] := 3;
4886 f_bssmap_continue_after_n_sd(last_n_sd);
4887
4888 f_call_hangup(cpars, true);
4889 f_sleep(1.0);
4890 deactivate(ccrel);
4891
4892 setverdict(pass);
4893}
4894private function f_tc_ho_inter_bsc1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4895 f_init_handler(pars);
4896 f_create_bssmap_exp_handoverRequest(194);
4897
4898 var PDU_BSSAP ho_request;
4899 BSSAP.receive(tr_BSSMAP_HandoverRequest) -> value ho_request;
4900
4901 /* new BSS composes a RR Handover Command */
4902 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
4903 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
4904 var BSSMAP_IE_AoIP_TransportLayerAddress tla := valueof(ts_BSSMAP_IE_AoIP_TLA4('01020304'O, 2342));
4905 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
4906 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
4907
4908 /* Now f_tc_ho_inter_bsc0() expects HandoverCommand */
4909
4910 f_sleep(0.5);
4911
4912 /* Notify that the MS is now over here */
4913
4914 BSSAP.send(ts_BSSMAP_HandoverDetect);
4915 f_sleep(0.1);
4916 BSSAP.send(ts_BSSMAP_HandoverComplete);
4917
4918 f_sleep(3.0);
4919
4920 /* Now I'd like to f_call_hangup() but we don't know any cpars here. So
4921 * ... handover back to the first BSC :P */
4922
4923 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
4924 var BssmapCause cause := enum2int(cause_val);
4925
4926 var template BSSMAP_FIELD_CellIdentificationList cil;
4927 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('262'H, '42'H, 23) } };
4928
4929 /* old BSS sends Handover Required */
4930 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
4931
4932 /* Now the action goes on in f_tc_ho_inter_bsc0() */
4933
4934 /* MSC forwards the RR Handover Command to old BSS */
4935 var PDU_BSSAP ho_command;
4936 BSSAP.receive(tr_BSSMAP_HandoverCommand) -> value ho_command;
4937
4938 log("GOT HandoverCommand", ho_command);
4939
4940 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
4941
4942 /* f_tc_ho_inter_bsc1() completes Handover, then expecting a Clear here. */
4943 f_expect_clear();
4944 setverdict(pass);
4945}
4946testcase TC_ho_inter_bsc() runs on MTC_CT {
4947 var BSC_ConnHdlr vc_conn0;
4948 var BSC_ConnHdlr vc_conn1;
4949 f_init(2);
4950
4951 var BSC_ConnHdlrPars pars0 := f_init_pars(53);
4952 var BSC_ConnHdlrPars pars1 := f_init_pars(53);
4953
4954 vc_conn0 := f_start_handler_with_pars(refers(f_tc_ho_inter_bsc0), pars0, 0);
4955 vc_conn1 := f_start_handler_with_pars(refers(f_tc_ho_inter_bsc1), pars1, 1);
4956 vc_conn0.done;
4957 vc_conn1.done;
4958}
4959
4960function f_ML3_patch_seq_nr_MS_NW(in uint2_t seq_nr, inout octetstring enc_l3) {
4961 log("MS_NW patching N(SD)=", seq_nr, " into dtap ", enc_l3);
4962 enc_l3[2] := (enc_l3[2] and4b '3f'O) or4b bit2oct(int2bit(seq_nr, 8) << 6);
4963 log("MS_NW patched enc_l3: ", enc_l3);
4964}
4965
4966private function f_tc_ho_inter_msc_out(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4967 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
4968 cpars.bss_rtp_port := 1110;
4969 cpars.mgcp_connection_id_bss := '22222'H;
4970 cpars.mgcp_connection_id_mss := '33333'H;
4971 cpars.mgcp_ep := "rtpbridge/1@mgw";
4972 cpars.mo_call := true;
4973 var hexstring ho_number := f_gen_msisdn(99999);
4974
4975 f_init_handler(pars);
4976
4977 f_create_mncc_expect(hex2str(ho_number));
4978
4979 f_vty_transceive(MSCVTY, "configure terminal");
4980 f_vty_transceive(MSCVTY, "msc");
4981 f_vty_transceive(MSCVTY, "neighbor a cgi 017 017 1 1 msc-ipa-name msc-017-017-1");
4982 f_vty_transceive(MSCVTY, "exit");
4983 f_vty_transceive(MSCVTY, "exit");
4984
4985 f_perform_lu();
4986 f_mo_call_establish(cpars);
4987
4988 f_sleep(1.0);
4989
4990 var default ack_mdcx := activate(as_mgcp_ack_all_mdcx(cpars));
4991
4992 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
4993 var BssmapCause cause := enum2int(cause_val);
4994
4995 var template BSSMAP_FIELD_CellIdentificationList cil;
4996 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('017'H, '017'H, 1) } };
4997
4998 /* old BSS sends Handover Required */
4999 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5000
5001 /* The target cell 017-017 LAC 1 is configured to be a remote MSC of name "msc-017-017-1".
5002 * This MSC tries to reach the other MSC via GSUP. */
5003
5004 var octetstring remote_msc_name := '6D73632D3031372D3031372D3100'O; /* "msc-017-017-1\0" as octetstring */
5005 var GSUP_PDU prep_ho_req;
5006 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_HANDOVER_REQUEST,
5007 pars.imsi, destination_name := remote_msc_name)) -> value prep_ho_req;
5008
5009 var GSUP_IeValue source_name_ie;
5010 f_gsup_find_ie(prep_ho_req, OSMO_GSUP_SOURCE_NAME_IE, source_name_ie);
5011 var octetstring local_msc_name := source_name_ie.source_name;
5012
5013 /* Remote MSC has figured out its BSC and signals success */
5014 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5015 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
5016 var PDU_BSSAP ho_req_ack := valueof(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5017 aoIPTransportLayer := omit,
5018 speechCodec := ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5019 GSUP.send(ts_GSUP_E_PrepareHandoverResult(
5020 pars.imsi,
5021 ho_number,
5022 remote_msc_name, local_msc_name,
5023 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006, enc_PDU_BSSAP(ho_req_ack)))));
5024
5025 /* MSC forwards the RR Handover Command to old BSS */
5026 BSSAP.receive(tr_BSSMAP_HandoverCommand);
5027
5028 /* The MS shows up at remote new BSS */
5029
5030 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PROCESS_ACCESS_SIGNALLING_REQUEST,
5031 pars.imsi, remote_msc_name, local_msc_name,
5032 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5033 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverDetect))))));
5034 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
5035 f_sleep(0.1);
5036
5037 /* Save the MS sequence counters for use on the other connection */
5038 var N_Sd_Array last_n_sd := f_bssmap_last_n_sd();
5039
5040 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_SEND_END_SIGNAL_REQUEST,
5041 pars.imsi, remote_msc_name, local_msc_name,
5042 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5043 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverComplete))))));
5044
5045 /* The local BSS conn clears, all communication goes via remote MSC now */
5046 f_expect_clear();
5047
5048 /**********************************/
5049 /* Play through some signalling across the inter-MSC link.
5050 * This is a copy of f_tc_lu_and_mo_ussd_single_request() translated into GSUP AN-APDUs. */
5051
5052 if (false) {
5053 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
5054 invoke_id := 5, /* Phone may not start from 0 or 1 */
5055 op_code := SS_OP_CODE_PROCESS_USS_REQ,
5056 ussd_string := "*#100#"
5057 );
5058
5059 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
5060 invoke_id := 5, /* InvokeID shall be the same for both REQ and RSP */
5061 op_code := SS_OP_CODE_PROCESS_USS_REQ,
5062 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
5063 )
5064
5065 /* Compose a new SS/REGISTER message with request */
5066 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
5067 tid := 1, /* We just need a single transaction */
5068 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
5069 facility := valueof(facility_req)
5070 );
5071 var PDU_ML3_MS_NW ussd_req_v := valueof(ussd_req);
5072
5073 /* Compose SS/RELEASE_COMPLETE template with expected response */
5074 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
5075 tid := 1, /* Response should arrive within the same transaction */
5076 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
5077 facility := valueof(facility_rsp)
5078 );
5079
5080 /* Compose expected MSC -> HLR message */
5081 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
5082 imsi := g_pars.imsi,
5083 state := OSMO_GSUP_SESSION_STATE_BEGIN,
5084 ss := valueof(facility_req)
5085 );
5086
5087 /* To be used for sending response with correct session ID */
5088 var GSUP_PDU gsup_req_complete;
5089
5090 /* Request own number */
5091 /* From remote MSC instead of BSSAP directly */
5092 /* Patch the correct N_SD value into the message. */
5093 var octetstring l3_enc := enc_PDU_ML3_MS_NW(ussd_req_v);
5094 var RAN_Emulation.ConnectionData cd;
5095 f_ML3_patch_seq_nr_MS_NW(f_next_n_sd(last_n_sd, f_ML3_n_sd_idx(ussd_req_v)), l3_enc);
5096 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PROCESS_ACCESS_SIGNALLING_REQUEST,
5097 pars.imsi, remote_msc_name, local_msc_name,
5098 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5099 enc_PDU_BSSAP(valueof(ts_BSSAP_DTAP(l3_enc)))
5100 ))
5101 ));
5102
5103 /* Expect GSUP message containing the SS payload */
5104 gsup_req_complete := f_expect_gsup_msg(gsup_req);
5105
5106 /* Compose the response from HLR using received session ID */
5107 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
5108 imsi := g_pars.imsi,
5109 sid := gsup_req_complete.ies[1].val.session_id,
5110 state := OSMO_GSUP_SESSION_STATE_END,
5111 ss := valueof(facility_rsp)
5112 );
5113
5114 /* Finally, HLR terminates the session */
5115 GSUP.send(gsup_rsp);
5116
5117 /* The USSD response goes out to remote MSC, on GSUP E instead of BSSAP */
5118 var GSUP_PDU gsup_ussd_rsp;
5119 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_FORWARD_ACCESS_SIGNALLING_REQUEST,
5120 pars.imsi, destination_name := remote_msc_name)) -> value gsup_ussd_rsp;
5121
5122 var GSUP_IeValue an_apdu;
5123 if (not f_gsup_find_ie(gsup_ussd_rsp, OSMO_GSUP_AN_APDU_IE, an_apdu)) {
5124 setverdict(fail, "No AN-APDU in received GSUP message. Expected USSD response in DTAP, got", gsup_ussd_rsp);
5125 mtc.stop;
5126 }
5127 var PDU_BSSAP bssap_dtap_mt := dec_PDU_BSSAP(an_apdu.an_apdu.pdu);
5128 var PDU_ML3_NW_MS dtap_mt := dec_PDU_ML3_NW_MS(bssap_dtap_mt.pdu.dtap);
5129 log("Expecting", ussd_rsp);
5130 log("Got", dtap_mt);
5131 if (not match(dtap_mt, ussd_rsp)) {
5132 setverdict(fail, "Unexpected GSUP message. Expected USSD response in DTAP, got", gsup_ussd_rsp);
5133 mtc.stop;
5134 }
5135 }
5136 /**********************************/
5137
5138
5139 /* inter-MSC handover back to the first MSC */
5140 f_create_bssmap_exp_handoverRequest(193);
5141 cil := { cIl_CGI := { ts_BSSMAP_CI_CGI('262'H, '42'H, 23, 42) } };
5142
5143 /* old BSS sends Handover Required, via inter-MSC E link: like
5144 * BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5145 * but via GSUP */
5146 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_SUBSEQUENT_HANDOVER_REQUEST,
5147 pars.imsi, remote_msc_name, local_msc_name,
5148 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5149 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverRequired(cause, cil)))
5150 ))
5151 ));
5152
5153 /* MSC asks local BSS to prepare Handover to it */
5154 BSSAP.receive(tr_BSSMAP_HandoverRequest);
5155
5156 /* Make sure the new BSSAP conn continues with the correct N_SD sequence numbers */
5157 f_bssmap_continue_after_n_sd(last_n_sd);
5158
5159 /* new BSS composes a RR Handover Command */
5160 rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5161 rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
5162 var BSSMAP_IE_AoIP_TransportLayerAddress tla := valueof(ts_BSSMAP_IE_AoIP_TLA4('01020304'O, 2342));
5163 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5164 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5165
5166 /* HandoverCommand goes out via remote MSC-I */
5167 var GSUP_PDU prep_subsq_ho_res;
5168 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_SUBSEQUENT_HANDOVER_RESULT,
5169 pars.imsi, destination_name := remote_msc_name)) -> value prep_subsq_ho_res;
5170
5171 /* MS shows up at the local BSS */
5172 BSSAP.send(ts_BSSMAP_HandoverDetect);
5173 f_sleep(0.1);
5174 BSSAP.send(ts_BSSMAP_HandoverComplete);
5175
5176 /* Handover Succeeded message */
5177 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_FORWARD_ACCESS_SIGNALLING_REQUEST,
5178 pars.imsi, destination_name := remote_msc_name));
5179
5180 /* MS has handovered to here, Clear Command goes out via remote MSC-I -- in form of a GSUP Close. */
5181 GSUP.receive(tr_GSUP_E_NO_PDU(OSMO_GSUP_MSGT_E_CLOSE,
5182 pars.imsi, destination_name := remote_msc_name));
5183
5184 /* Handover ends successfully. Call goes on for a little longer and then we hang up. */
5185
5186 f_sleep(1.0);
5187 deactivate(ack_mdcx);
5188
5189 /* FIXME: the inter-MSC call has put a number of MNCC messages in the queue, which above code should expect and
5190 * clear out. The f_call_hangup() expects an MNCC_REL_IND, so, for the time being, just clear the MNCC messages
5191 * before starting the call hangup. Instead of this, the individual messages should be tested for above. */
5192 MNCC.clear;
5193
5194 var default ccrel := activate(as_optional_cc_rel(cpars, true));
5195 f_call_hangup(cpars, true);
5196 f_sleep(1.0);
5197 deactivate(ccrel);
5198
5199 setverdict(pass);
5200}
5201testcase TC_ho_inter_msc_out() runs on MTC_CT {
5202 var BSC_ConnHdlr vc_conn;
5203 f_init(1);
5204
5205 var BSC_ConnHdlrPars pars := f_init_pars(54);
5206
5207 vc_conn := f_start_handler_with_pars(refers(f_tc_ho_inter_msc_out), pars, 0);
5208 vc_conn.done;
5209}
5210
5211
Harald Weltef6dd64d2017-11-19 12:09:51 +01005212control {
Philipp Maier328d1662018-03-07 10:40:27 +01005213 execute( TC_cr_before_reset() );
Harald Weltea49e36e2018-01-21 19:29:33 +01005214 execute( TC_lu_imsi_noauth_tmsi() );
Harald Welted2328a22018-01-27 14:27:16 +01005215 execute( TC_lu_imsi_noauth_notmsi() );
Harald Weltea49e36e2018-01-21 19:29:33 +01005216 execute( TC_lu_imsi_reject() );
5217 execute( TC_lu_imsi_timeout_gsup() );
Harald Welted2328a22018-01-27 14:27:16 +01005218 execute( TC_lu_imsi_auth_tmsi() );
Harald Welte8a397ae2019-04-21 22:03:37 +02005219 execute( TC_lu_imsi_auth3g_tmsi() );
Harald Welted2328a22018-01-27 14:27:16 +01005220 execute( TC_cmserv_imsi_unknown() );
Harald Welte2bb825f2018-01-22 11:31:18 +01005221 execute( TC_lu_and_mo_call() );
Harald Welte071ed732018-01-23 19:53:52 +01005222 execute( TC_lu_auth_sai_timeout() );
5223 execute( TC_lu_auth_sai_err() );
Harald Weltee1a2f3c2018-01-24 17:28:48 +01005224 execute( TC_lu_clear_request() );
5225 execute( TC_lu_disconnect() );
5226 execute( TC_lu_by_imei() );
5227 execute( TC_lu_by_tmsi_noauth_unknown() );
5228 execute( TC_imsi_detach_by_imsi() );
5229 execute( TC_imsi_detach_by_tmsi() );
5230 execute( TC_imsi_detach_by_imei() );
5231 execute( TC_emerg_call_imei_reject() );
5232 execute( TC_emerg_call_imsi() );
5233 execute( TC_cm_serv_req_vgcs_reject() );
5234 execute( TC_cm_serv_req_vbs_reject() );
5235 execute( TC_cm_serv_req_lcs_reject() );
Harald Welte0195ab12018-01-24 21:50:20 +01005236 execute( TC_cm_reest_req_reject() );
Harald Welte1af6ea82018-01-25 18:33:15 +01005237 execute( TC_lu_auth_2G_fail() );
5238 execute( TC_lu_imsi_auth_tmsi_encr_13_13() );
5239 execute( TC_cl3_no_payload() );
5240 execute( TC_cl3_rnd_payload() );
Harald Welte1852a842018-01-26 22:53:36 +01005241 execute( TC_establish_and_nothing() );
5242 execute( TC_mo_setup_and_nothing() );
5243 execute( TC_mo_crcx_ran_timeout() );
5244 execute( TC_mo_crcx_ran_reject() );
Harald Welted2328a22018-01-27 14:27:16 +01005245 execute( TC_mt_crcx_ran_reject() );
Daniel Willmann8b084372018-02-04 13:35:26 +01005246 execute( TC_mo_setup_and_dtmf_dup() );
Harald Welteaa54cf82018-01-30 08:15:32 +01005247 //execute( TC_mt_t310() );
Harald Welte167458a2018-01-27 15:58:16 +01005248 execute( TC_gsup_cancel() );
Harald Welte9de84792018-01-28 01:06:35 +01005249 execute( TC_lu_imsi_auth_tmsi_encr_1_13() );
5250 execute( TC_lu_imsi_auth_tmsi_encr_3_13() );
5251 execute( TC_lu_imsi_auth_tmsi_encr_3_1() );
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01005252 execute( TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() );
Harald Welte9de84792018-01-28 01:06:35 +01005253 execute( TC_lu_imsi_auth_tmsi_encr_13_2() );
5254 execute( TC_lu_imsi_auth_tmsi_encr_013_2() );
Philipp Maier94f3f1b2018-03-15 18:54:13 +01005255 execute( TC_mo_release_timeout() );
Philipp Maier2a98a732018-03-19 16:06:12 +01005256 execute( TC_lu_and_mt_call_no_dlcx_resp() );
Philipp Maier75932982018-03-27 14:52:35 +02005257 execute( TC_reset_two() );
Harald Welte33ec09b2018-02-10 15:34:46 +01005258
5259 execute( TC_lu_and_mt_call() );
5260
Harald Weltef45efeb2018-04-09 18:19:24 +02005261 execute( TC_lu_and_mo_sms() );
5262 execute( TC_lu_and_mt_sms() );
Philipp Maier3983e702018-11-22 19:01:33 +01005263 execute( TC_lu_and_mt_sms_paging_and_nothing() );
Harald Weltef640a012018-04-14 17:49:21 +02005264 execute( TC_smpp_mo_sms() );
5265 execute( TC_smpp_mt_sms() );
Harald Weltef45efeb2018-04-09 18:19:24 +02005266
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07005267 execute( TC_gsup_mo_sms() );
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07005268 execute( TC_gsup_mo_smma() );
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07005269 execute( TC_gsup_mt_sms_ack() );
5270 execute( TC_gsup_mt_sms_err() );
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07005271 execute( TC_gsup_mt_sms_rp_mr() );
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07005272 execute( TC_gsup_mo_mt_sms_rp_mr() );
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07005273
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07005274 execute( TC_lu_and_mo_ussd_single_request() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07005275 execute( TC_lu_and_mt_ussd_notification() );
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07005276 execute( TC_lu_and_mo_ussd_during_mt_call() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07005277 execute( TC_lu_and_mt_ussd_during_mt_call() );
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07005278 execute( TC_lu_and_mo_ussd_mo_release() );
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07005279 execute( TC_lu_and_ss_session_timeout() );
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07005280
Stefan Sperling89eb1f32018-12-17 15:06:20 +01005281 execute( TC_cipher_complete_with_invalid_cipher() );
5282
Harald Welte4263c522018-12-06 11:56:27 +01005283 execute( TC_sgsap_reset() );
5284 execute( TC_sgsap_lu() );
5285 execute( TC_sgsap_lu_imsi_reject() );
5286 execute( TC_sgsap_lu_and_nothing() );
5287 execute( TC_sgsap_expl_imsi_det_eps() );
Philipp Maierfc19f172019-03-21 11:17:54 +01005288 execute( TC_sgsap_impl_imsi_det_eps() );
Harald Welte4263c522018-12-06 11:56:27 +01005289 execute( TC_sgsap_expl_imsi_det_noneps() );
Philipp Maier5d812702019-03-21 10:51:26 +01005290 execute( TC_sgsap_impl_imsi_det_noneps() );
Harald Welte4263c522018-12-06 11:56:27 +01005291 execute( TC_sgsap_paging_rej() );
5292 execute( TC_sgsap_paging_subscr_rej() );
5293 execute( TC_sgsap_paging_ue_unr() );
5294 execute( TC_sgsap_paging_and_nothing() );
5295 execute( TC_sgsap_paging_and_lu() );
5296 execute( TC_sgsap_mt_sms() );
5297 execute( TC_sgsap_mo_sms() );
5298 execute( TC_sgsap_mt_sms_and_nothing() );
5299 execute( TC_sgsap_mt_sms_and_reject() );
5300 execute( TC_sgsap_unexp_ud() );
5301 execute( TC_sgsap_unsol_ud() );
5302 execute( TC_bssap_lu_sgsap_lu_and_mt_call() );
5303 execute( TC_sgsap_lu_and_mt_call() );
Philipp Maier628c0052019-04-09 17:36:57 +02005304 execute( TC_sgsap_vlr_failure() );
Harald Welte4263c522018-12-06 11:56:27 +01005305
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005306 execute( TC_ho_inter_bsc_unknown_cell() );
5307 execute( TC_ho_inter_bsc() );
5308
5309 execute( TC_ho_inter_msc_out() );
5310
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01005311 /* Run this last: at the time of writing this test crashes the MSC */
5312 execute( TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() );
Philipp Maierdb7fb8d2019-02-11 10:50:13 +01005313 execute( TC_gsup_mt_multi_part_sms() );
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02005314 execute( TC_mo_cc_bssmap_clear() );
Harald Weltef6dd64d2017-11-19 12:09:51 +01005315}
5316
5317
5318}