blob: 2a9b23a4324736ab50ddda44902d2f98a4e19ef4 [file] [log] [blame]
Harald Weltef6dd64d2017-11-19 12:09:51 +01001module MSC_Tests {
2
Harald Welte34b5a952019-05-27 11:54:11 +02003/* Osmocom MSC test suite in in TTCN-3
4 * (C) 2017-2019 Harald Welte <laforge@gnumonks.org>
5 * (C) 2018-2019 sysmocom - s.f.m.c. GmbH
6 * (C) 2018-2019 Vadim Yanitskiy <axilirator@gmail.com>
7 * All rights reserved.
8 *
9 * Released under the terms of GNU General Public License, Version 2 or
10 * (at your option) any later version.
11 *
12 * SPDX-License-Identifier: GPL-2.0-or-later
13 */
14
Harald Weltee13cfb22019-04-23 16:52:02 +020015friend module MSC_Tests_Iu;
16
Harald Weltef6dd64d2017-11-19 12:09:51 +010017import from General_Types all;
18import from Osmocom_Types all;
19
20import from M3UA_Types all;
21import from M3UA_Emulation all;
22
23import from MTP3asp_Types all;
24import from MTP3asp_PortType all;
25
26import from SCCPasp_Types all;
27import from SCCP_Types all;
28import from SCCP_Emulation all;
29
30import from SCTPasp_Types all;
31import from SCTPasp_PortType all;
32
Harald Weltea49e36e2018-01-21 19:29:33 +010033import from Osmocom_CTRL_Functions all;
34import from Osmocom_CTRL_Types all;
35import from Osmocom_CTRL_Adapter all;
36
Harald Welte3ca1c902018-01-24 18:51:27 +010037import from TELNETasp_PortType all;
38import from Osmocom_VTY_Functions all;
39
Harald Weltea49e36e2018-01-21 19:29:33 +010040import from MNCC_Emulation all;
Harald Welte2bb825f2018-01-22 11:31:18 +010041import from MNCC_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010042
Harald Welte4aa970c2018-01-26 10:38:09 +010043import from MGCP_Emulation all;
44import from MGCP_Types all;
45import from MGCP_Templates all;
46import from SDP_Types all;
47
Harald Weltea49e36e2018-01-21 19:29:33 +010048import from GSUP_Emulation all;
49import from GSUP_Types all;
50import from IPA_Emulation all;
51
Harald Weltef6dd64d2017-11-19 12:09:51 +010052import from BSSAP_Types all;
Harald Welte6811d102019-04-14 22:23:14 +020053import from RAN_Adapter all;
Harald Weltea49e36e2018-01-21 19:29:33 +010054import from BSSAP_CodecPort all;
55import from BSSMAP_Templates all;
Harald Welte6811d102019-04-14 22:23:14 +020056import from RAN_Emulation all;
Harald Weltea49e36e2018-01-21 19:29:33 +010057import from BSC_ConnectionHandler all;
Harald Weltee13cfb22019-04-23 16:52:02 +020058import from RANAP_Templates all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010059
Harald Welte4263c522018-12-06 11:56:27 +010060import from SGsAP_Templates all;
61import from SGsAP_Types all;
62import from SGsAP_Emulation all;
63
Harald Weltea49e36e2018-01-21 19:29:33 +010064import from MobileL3_Types all;
65import from MobileL3_CommonIE_Types all;
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +070066import from MobileL3_SMS_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010067import from L3_Templates all;
Harald Welte158a7ca2018-02-16 18:11:31 +010068import from L3_Common all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010069
Harald Weltef640a012018-04-14 17:49:21 +020070import from SMPP_Types all;
71import from SMPP_Templates all;
72import from SMPP_Emulation all;
73
Stefan Sperlingc307e682018-06-14 15:15:46 +020074import from SCCP_Templates all;
75
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070076import from SS_Types all;
77import from SS_Templates all;
78import from USSD_Helpers all;
Harald Welte4263c522018-12-06 11:56:27 +010079import from DNS_Helpers all;
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070080
Philipp Maier948747b2019-04-02 15:22:33 +020081import from TCCConversion_Functions all;
82
Harald Welte9b751a62019-04-14 17:39:29 +020083const integer NUM_BSC := 3;
Harald Weltef6dd64d2017-11-19 12:09:51 +010084
Harald Welte4263c522018-12-06 11:56:27 +010085/* Needed for SGsAP SMS */
86import from MobileL3_SMS_Types all;
87
Harald Weltea4ca4462018-02-09 00:17:14 +010088type component MTC_CT extends CTRL_Adapter_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +010089 var boolean g_initialized := false;
Harald Weltea49e36e2018-01-21 19:29:33 +010090
Harald Welte6811d102019-04-14 22:23:14 +020091 var RAN_Adapter g_bssap[NUM_BSC];
Harald Weltea4ca4462018-02-09 00:17:14 +010092
Harald Weltea49e36e2018-01-21 19:29:33 +010093 /* no 'adapter_CT' for MNCC or GSUP */
94 var MNCC_Emulation_CT vc_MNCC;
Harald Welte4aa970c2018-01-26 10:38:09 +010095 var MGCP_Emulation_CT vc_MGCP;
Harald Weltea49e36e2018-01-21 19:29:33 +010096 var GSUP_Emulation_CT vc_GSUP;
97 var IPA_Emulation_CT vc_GSUP_IPA;
Harald Weltef640a012018-04-14 17:49:21 +020098 var SMPP_Emulation_CT vc_SMPP;
Harald Welte4263c522018-12-06 11:56:27 +010099 var SGsAP_Emulation_CT vc_SGsAP;
Harald Weltea49e36e2018-01-21 19:29:33 +0100100
101 /* only to get events from IPA underneath GSUP */
102 port IPA_CTRL_PT GSUP_IPA_EVENT;
Harald Welte3ca1c902018-01-24 18:51:27 +0100103 /* VTY to MSC */
104 port TELNETasp_PT MSCVTY;
Philipp Maier328d1662018-03-07 10:40:27 +0100105
106 /* A port to directly send BSSAP messages. This port is used for
107 * tests that require low level access to sen arbitrary BSSAP
108 * messages. Run f_init_bssap_direct() to connect and initialize */
109 port BSSAP_CODEC_PT BSSAP_DIRECT;
110
111 /* When BSSAP messages are directly sent, then the connection
112 * handler is not active, which means that also no guard timer is
113 * set up. The following timer will serve as a replacement */
114 timer Tguard_direct := 60.0;
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100115
116 /* Configure T(tias) over VTY, seconds */
117 var integer g_msc_sccp_timer_ias := 7 * 60;
118 /* Configure T(tiar) over VTY, seconds */
119 var integer g_msc_sccp_timer_iar := 15 * 60;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100120}
121
122modulepar {
Harald Weltea49e36e2018-01-21 19:29:33 +0100123 /* remote parameters of IUT */
124 charstring mp_msc_ip := "127.0.0.1";
125 integer mp_msc_ctrl_port := 4255;
126 integer mp_msc_vty_port := 4254;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100127
Harald Weltea49e36e2018-01-21 19:29:33 +0100128 /* local parameters of emulated HLR */
Philipp Maier9b690e42018-12-21 11:50:03 +0100129 boolean mp_mm_info := false;
Harald Weltea49e36e2018-01-21 19:29:33 +0100130 charstring mp_hlr_ip := "127.0.0.1";
131 integer mp_hlr_port := 4222;
Harald Welte6126fb02018-01-27 20:08:24 +0100132 charstring mp_mgw_ip := "127.0.0.1";
133 integer mp_mgw_port := 2427;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100134
Harald Weltea49e36e2018-01-21 19:29:33 +0100135 charstring mp_msc_mncc := "/tmp/mncc";
Harald Weltea4ca4462018-02-09 00:17:14 +0100136
Harald Weltef640a012018-04-14 17:49:21 +0200137 integer mp_msc_smpp_port := 2775;
138 charstring mp_smpp_system_id := "msc_tester";
139 charstring mp_smpp_password := "osmocom1";
Harald Welte4263c522018-12-06 11:56:27 +0100140 charstring mp_mme_name := "mmec01.mmegi0001.mme.epc.mnc070.mcc901.3gppnetwork.org";
141 charstring mp_vlr_name := "vlr.example.net";
Harald Weltef640a012018-04-14 17:49:21 +0200142
Pau Espin Pedrol690d6592019-05-31 17:56:32 +0200143 /* Whether to enable osmux tests. Can be dropped completely and enable
144 unconditionally once new version of osmo-msc is released (current
145 version: 1.3.1) */
146 boolean mp_enable_osmux_test := true;
147
Harald Welte6811d102019-04-14 22:23:14 +0200148 RAN_Configurations mp_bssap_cfg := {
Philipp Maier75932982018-03-27 14:52:35 +0200149 {
150 sccp_service_type := "mtp3_itu",
151 sctp_addr := { 23905, "127.0.0.1", 2905, "127.0.0.1" },
152 own_pc := 185,
153 own_ssn := 254,
154 peer_pc := 187,
155 peer_ssn := 254,
156 sio := '83'O,
157 rctx := 0
158 },
159 {
160 sccp_service_type := "mtp3_itu",
161 sctp_addr := { 23906, "127.0.0.1", 2905, "127.0.0.1" },
162 own_pc := 186,
163 own_ssn := 254,
164 peer_pc := 187,
165 peer_ssn := 254,
166 sio := '83'O,
167 rctx := 1
168 }
Harald Weltea4ca4462018-02-09 00:17:14 +0100169 };
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200170
171 boolean mp_enable_cell_id_test := true;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100172}
173
Philipp Maier328d1662018-03-07 10:40:27 +0100174/* altstep for the global guard timer (only used when BSSAP_DIRECT
175 * is used for communication */
176private altstep as_Tguard_direct() runs on MTC_CT {
177 [] Tguard_direct.timeout {
178 setverdict(fail, "Tguard timeout");
Daniel Willmannafce8662018-07-06 23:11:32 +0200179 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +0100180 }
181}
Harald Weltef6dd64d2017-11-19 12:09:51 +0100182
Neels Hofmeyr2ca1ab42019-03-08 03:45:43 +0100183private altstep as_optional_cc_rel(CallParameters cpars, boolean respond := false) runs on BSC_ConnHdlr {
184 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id))) {
185 if (respond) {
186 var BIT1 tid_remote := '1'B;
187 if (cpars.mo_call) {
188 tid_remote := '0'B;
189 }
190 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id, tid_remote)));
191 }
192 }
Neels Hofmeyrde76f052019-02-26 05:02:46 +0100193}
194
Harald Weltef640a012018-04-14 17:49:21 +0200195function f_init_smpp(charstring id) runs on MTC_CT {
196 id := id & "-SMPP";
197 var EsmePars pars := {
198 mode := MODE_TRANSCEIVER,
199 bind := {
200 system_id := mp_smpp_system_id,
201 password := mp_smpp_password,
202 system_type := "MSC_Tests",
203 interface_version := hex2int('34'H),
204 addr_ton := unknown,
205 addr_npi := unknown,
206 address_range := ""
207 },
208 esme_role := true
209 }
210
211 vc_SMPP := SMPP_Emulation_CT.create(id);
212 map(vc_SMPP:SMPP_PORT, system:SMPP_PORT);
Harald Welte4698a4c2020-08-18 22:57:52 +0200213 vc_SMPP.start(SMPP_Emulation.main_client(pars, mp_msc_ip, mp_msc_smpp_port, "", 0));
Harald Weltef640a012018-04-14 17:49:21 +0200214}
215
216
Harald Weltea49e36e2018-01-21 19:29:33 +0100217function f_init_mncc(charstring id) runs on MTC_CT {
218 id := id & "-MNCC";
219 var MnccOps ops := {
220 create_cb := refers(MNCC_Emulation.ExpectedCreateCallback),
221 unitdata_cb := refers(MNCC_Emulation.DummyUnitdataCallback)
222 }
223
224 vc_MNCC := MNCC_Emulation_CT.create(id);
225 map(vc_MNCC:MNCC, system:MNCC_CODEC_PT);
226 vc_MNCC.start(MNCC_Emulation.main(ops, id, mp_msc_mncc));
Harald Weltef6dd64d2017-11-19 12:09:51 +0100227}
228
Harald Welte4aa970c2018-01-26 10:38:09 +0100229function f_init_mgcp(charstring id) runs on MTC_CT {
230 id := id & "-MGCP";
231 var MGCPOps ops := {
232 create_cb := refers(MGCP_Emulation.ExpectedCreateCallback),
233 unitdata_cb := refers(MGCP_Emulation.DummyUnitdataCallback)
234 }
235 var MGCP_conn_parameters pars := {
Harald Welte6126fb02018-01-27 20:08:24 +0100236 callagent_ip := mp_msc_ip,
Harald Welte4aa970c2018-01-26 10:38:09 +0100237 callagent_udp_port := -1,
Harald Welte6126fb02018-01-27 20:08:24 +0100238 mgw_ip := mp_mgw_ip,
Pau Espin Pedrol1a026a52019-06-18 17:21:52 +0200239 mgw_udp_port := mp_mgw_port,
240 multi_conn_mode := false
Harald Welte4aa970c2018-01-26 10:38:09 +0100241 }
242
243 vc_MGCP := MGCP_Emulation_CT.create(id);
244 map(vc_MGCP:MGCP, system:MGCP_CODEC_PT);
245 vc_MGCP.start(MGCP_Emulation.main(ops, pars, id));
246}
247
Philipp Maierc09a1312019-04-09 16:05:26 +0200248function ForwardUnitdataCallback(PDU_SGsAP msg)
249runs on SGsAP_Emulation_CT return template PDU_SGsAP {
250 SGsAP_CLIENT.send(msg);
251 return omit;
252}
253
Harald Welte4263c522018-12-06 11:56:27 +0100254function f_init_sgsap(charstring id) runs on MTC_CT {
255 id := id & "-SGsAP";
256 var SGsAPOps ops := {
257 create_cb := refers(SGsAP_Emulation.ExpectedCreateCallback),
Philipp Maierc09a1312019-04-09 16:05:26 +0200258 unitdata_cb := refers(ForwardUnitdataCallback)
Harald Welte4263c522018-12-06 11:56:27 +0100259 }
260 var SGsAP_conn_parameters pars := {
261 remote_ip := mp_msc_ip,
262 remote_sctp_port := 29118,
263 local_ip := "",
264 local_sctp_port := -1
265 }
266
267 vc_SGsAP := SGsAP_Emulation_CT.create(id);
268 map(vc_SGsAP:SGsAP, system:SGsAP_CODEC_PT);
269 vc_SGsAP.start(SGsAP_Emulation.main(ops, pars, id));
270}
271
272
Harald Weltea49e36e2018-01-21 19:29:33 +0100273function f_init_gsup(charstring id) runs on MTC_CT {
274 id := id & "-GSUP";
275 var GsupOps ops := {
276 create_cb := refers(GSUP_Emulation.ExpectedCreateCallback)
277 }
278
279 vc_GSUP_IPA := IPA_Emulation_CT.create(id & "-IPA");
280 vc_GSUP := GSUP_Emulation_CT.create(id);
281
282 map(vc_GSUP_IPA:IPA_PORT, system:IPA_CODEC_PT);
283 connect(vc_GSUP:GSUP, vc_GSUP_IPA:IPA_GSUP_PORT);
284 /* we use this hack to get events like ASP_IPA_EVENT_UP */
285 connect(vc_GSUP_IPA:IPA_CTRL_PORT, self:GSUP_IPA_EVENT);
286
287 vc_GSUP.start(GSUP_Emulation.main(ops, id));
288 vc_GSUP_IPA.start(IPA_Emulation.main_server(mp_hlr_ip, mp_hlr_port));
289
290 /* wait for incoming connection to GSUP port before proceeding */
291 timer T := 10.0;
292 T.start;
293 alt {
Vadim Yanitskiy61564be2020-05-18 20:44:14 +0700294 [] GSUP_IPA_EVENT.receive(tr_ASP_IPA_EV(ASP_IPA_EVENT_UP)) { }
Harald Weltea49e36e2018-01-21 19:29:33 +0100295 [] T.timeout {
Harald Welte458fd372018-03-21 11:26:23 +0100296 setverdict(fail, "No connection to GSUP Port");
Daniel Willmannafce8662018-07-06 23:11:32 +0200297 mtc.stop
Harald Weltea49e36e2018-01-21 19:29:33 +0100298 }
299 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100300}
301
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200302function f_init(integer num_bsc := 1, boolean sgsap := false, boolean gsup := true, boolean osmux := false) runs on MTC_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +0100303
304 if (g_initialized == true) {
305 return;
306 }
307 g_initialized := true;
308
Philipp Maier75932982018-03-27 14:52:35 +0200309 if (num_bsc > NUM_BSC) {
Daniel Willmannafce8662018-07-06 23:11:32 +0200310 testcase.stop("excess number of BSC instances requested");
Philipp Maier75932982018-03-27 14:52:35 +0200311 }
312
313 for (var integer i := 0; i < num_bsc; i := i + 1) {
314 if (isbound(mp_bssap_cfg[i])) {
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200315 var RanOps ranops := BSC_RanOps;
316 ranops.use_osmux := osmux;
317 f_ran_adapter_init(g_bssap[i], mp_bssap_cfg[i], "MSC_Test_" & int2str(i), ranops);
Harald Welte3ca0ce12019-04-23 17:18:48 +0200318 f_ran_adapter_start(g_bssap[i]);
Philipp Maier75932982018-03-27 14:52:35 +0200319 } else {
Daniel Willmannafce8662018-07-06 23:11:32 +0200320 testcase.stop("missing BSSAP configuration");
Philipp Maier75932982018-03-27 14:52:35 +0200321 }
322 }
323
Harald Weltea49e36e2018-01-21 19:29:33 +0100324 f_ipa_ctrl_start(mp_msc_ip, mp_msc_ctrl_port);
325 f_init_mncc("MSC_Test");
Harald Welte4aa970c2018-01-26 10:38:09 +0100326 f_init_mgcp("MSC_Test");
Philipp Maierc09a1312019-04-09 16:05:26 +0200327
328 if (gsup == true) {
329 f_init_gsup("MSC_Test");
330 }
Harald Weltef640a012018-04-14 17:49:21 +0200331 f_init_smpp("MSC_Test");
Philipp Maier57865482019-01-07 18:33:13 +0100332
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100333 if (sgsap == true) {
Philipp Maier57865482019-01-07 18:33:13 +0100334 f_init_sgsap("MSC_Test");
335 }
Harald Welte3ca1c902018-01-24 18:51:27 +0100336
337 map(self:MSCVTY, system:MSCVTY);
338 f_vty_set_prompts(MSCVTY);
339 f_vty_transceive(MSCVTY, "enable");
Harald Welteb14c77a2018-01-25 17:25:44 +0100340
341 /* set some defaults */
342 f_vty_config(MSCVTY, "network", "authentication optional");
343 f_vty_config(MSCVTY, "msc", "assign-tmsi");
Oliver Smith1d118ff2019-07-03 10:57:35 +0200344 f_vty_config(MSCVTY, "msc", "check-imei-rqd 0");
Harald Welteb14c77a2018-01-25 17:25:44 +0100345 f_vty_config(MSCVTY, "network", "encryption a5 0");
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100346 f_vty_config(MSCVTY, "cs7 instance 0", "sccp-timer ias " & int2str(g_msc_sccp_timer_ias));
347 f_vty_config(MSCVTY, "cs7 instance 0", "sccp-timer iar " & int2str(g_msc_sccp_timer_iar));
Pau Espin Pedrol690d6592019-05-31 17:56:32 +0200348 if (mp_enable_osmux_test) {
349 if (osmux) {
350 f_vty_config(MSCVTY, "msc", "osmux on");
351 } else {
352 f_vty_config(MSCVTY, "msc", "osmux off");
353 }
Pau Espin Pedrol3dd33bc2019-05-31 17:51:20 +0200354 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100355}
356
Philipp Maier328d1662018-03-07 10:40:27 +0100357/* Initialize for a direct connection to BSSAP. This function is an alternative
358 * to f_init() when the high level functions of the BSC_ConnectionHandler are
359 * not needed. */
360function f_init_bssap_direct() runs on MTC_CT {
Harald Welte3ca0ce12019-04-23 17:18:48 +0200361 f_ran_adapter_init(g_bssap[0], mp_bssap_cfg[0], "MSC_Test", omit);
Philipp Maier75932982018-03-27 14:52:35 +0200362 connect(g_bssap[0].vc_SCCP:SCCP_SP_PORT, self:BSSAP_DIRECT);
Philipp Maier328d1662018-03-07 10:40:27 +0100363
364 /* Start guard timer and activate it as default */
365 Tguard_direct.start
366 activate(as_Tguard_direct());
367}
368
Harald Weltea49e36e2018-01-21 19:29:33 +0100369type function void_fn(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100370
Harald Weltea49e36e2018-01-21 19:29:33 +0100371/* FIXME: move into BSC_ConnectionHandler? */
Harald Welte9b751a62019-04-14 17:39:29 +0200372function f_init_pars(integer imsi_suffix, boolean sgsap := false, boolean gsup := true, integer ran_idx := 0,
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200373 boolean ran_is_geran := true, boolean use_osmux := false, OCT4 gsup_sid := '20000101'O,
374 boolean verify_cell_id := true)
Harald Weltef9abf8d2019-04-21 13:07:17 +0200375runs on MTC_CT return BSC_ConnHdlrPars {
Harald Weltede371492018-01-27 23:44:41 +0100376 var BSC_ConnHdlrNetworkPars net_pars := {
377 kc_support := '0A'O, /* A5/1 and A5/3 enabled */
378 expect_tmsi := true,
379 expect_auth := false,
Oliver Smith1d118ff2019-07-03 10:57:35 +0200380 expect_ciph := false,
381 expect_imei := false,
382 expect_imei_early := false,
383 check_imei_result := OSMO_GSUP_IMEI_RESULT_ACK,
384 check_imei_error := false
Harald Weltede371492018-01-27 23:44:41 +0100385 };
Harald Weltea49e36e2018-01-21 19:29:33 +0100386 var BSC_ConnHdlrPars pars := {
Harald Weltef9abf8d2019-04-21 13:07:17 +0200387 sccp_addr_own := g_bssap[ran_idx].sccp_addr_own,
388 sccp_addr_peer := g_bssap[ran_idx].sccp_addr_peer,
Harald Welteedbab812018-03-18 16:02:25 +0100389 cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42)),
Harald Welte81b7f9d2018-01-24 19:06:24 +0100390 imei := f_gen_imei(imsi_suffix),
391 imsi := f_gen_imsi(imsi_suffix),
392 msisdn := f_gen_msisdn(imsi_suffix),
Harald Welte256571e2018-01-24 18:47:19 +0100393 tmsi := omit,
Harald Welte9de84792018-01-28 01:06:35 +0100394 cm1 := valueof(ts_CM1),
Harald Welte82600572018-01-21 20:54:08 +0100395 cm2 := valueof(ts_CM2_default),
Harald Welte16114282018-01-24 22:41:21 +0100396 cm3 := omit,
Harald Weltede371492018-01-27 23:44:41 +0100397 vec := omit,
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100398 net := net_pars,
Philipp Maieraeb29a82018-11-08 17:40:53 +0100399 send_early_cm := true,
400 ipa_ctrl_ip := mp_msc_ip,
401 ipa_ctrl_port := mp_msc_ctrl_port,
Philipp Maier9b690e42018-12-21 11:50:03 +0100402 ipa_ctrl_enable := true,
Philipp Maier57865482019-01-07 18:33:13 +0100403 mm_info := mp_mm_info,
Philipp Maierc09a1312019-04-09 16:05:26 +0200404 sgsap_enable := sgsap,
Harald Weltef9abf8d2019-04-21 13:07:17 +0200405 gsup_enable := gsup,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +0100406 gsup_sid := gsup_sid,
Harald Weltec1f937a2019-04-21 21:19:23 +0200407 ran_idx := ran_idx,
Harald Welte9b751a62019-04-14 17:39:29 +0200408 use_umts_aka := false,
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200409 ran_is_geran := ran_is_geran,
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200410 use_osmux := use_osmux,
411 verify_cell_id := mp_enable_cell_id_test and verify_cell_id
Harald Weltea49e36e2018-01-21 19:29:33 +0100412 };
Harald Weltee13cfb22019-04-23 16:52:02 +0200413 if (not ran_is_geran) {
414 pars.use_umts_aka := true;
415 pars.net.expect_auth := true;
416 }
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100417 return pars;
418}
419
Neels Hofmeyr0ac63152019-05-07 01:20:17 +0200420function f_start_handler_with_pars(void_fn fn, BSC_ConnHdlrPars pars, integer bssap_idx := 0) runs on MTC_CT return BSC_ConnHdlr {
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100421 var BSC_ConnHdlr vc_conn;
Neels Hofmeyr0ac63152019-05-07 01:20:17 +0200422 var charstring id := testcasename() & int2str(bssap_idx);
Harald Weltea49e36e2018-01-21 19:29:33 +0100423
424 vc_conn := BSC_ConnHdlr.create(id);
425 /* BSSMAP part / A interface */
Neels Hofmeyr0ac63152019-05-07 01:20:17 +0200426 connect(vc_conn:BSSAP, g_bssap[pars.ran_idx + bssap_idx].vc_RAN:CLIENT);
427 connect(vc_conn:BSSAP_PROC, g_bssap[pars.ran_idx + bssap_idx].vc_RAN:PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100428 /* MNCC part */
429 connect(vc_conn:MNCC, vc_MNCC:MNCC_CLIENT);
430 connect(vc_conn:MNCC_PROC, vc_MNCC:MNCC_PROC);
Harald Welte4aa970c2018-01-26 10:38:09 +0100431 /* MGCP part */
432 connect(vc_conn:MGCP, vc_MGCP:MGCP_CLIENT);
433 connect(vc_conn:MGCP_PROC, vc_MGCP:MGCP_PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100434 /* GSUP part */
Philipp Maierc09a1312019-04-09 16:05:26 +0200435 if (pars.gsup_enable == true) {
436 connect(vc_conn:GSUP, vc_GSUP:GSUP_CLIENT);
437 connect(vc_conn:GSUP_PROC, vc_GSUP:GSUP_PROC);
438 }
Harald Weltef640a012018-04-14 17:49:21 +0200439 /* SMPP part */
440 connect(vc_conn:SMPP, vc_SMPP:SMPP_CLIENT);
441 connect(vc_conn:SMPP_PROC, vc_SMPP:SMPP_PROC);
Harald Welte4263c522018-12-06 11:56:27 +0100442 /* SGs part */
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100443 if (pars.sgsap_enable == true) {
Philipp Maier57865482019-01-07 18:33:13 +0100444 connect(vc_conn:SGsAP, vc_SGsAP:SGsAP_CLIENT);
445 connect(vc_conn:SGsAP_PROC, vc_SGsAP:SGsAP_PROC);
446 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100447
Harald Weltea10db902018-01-27 12:44:49 +0100448 /* We cannot use vc_conn.start(f_init_handler(fn, id, pars)); as we cannot have
449 * a stand-alone 'derefers()' call, see https://www.eclipse.org/forums/index.php/t/1091364/ */
Harald Weltea49e36e2018-01-21 19:29:33 +0100450 vc_conn.start(derefers(fn)(id, pars));
451 return vc_conn;
452}
453
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200454function f_start_handler(void_fn fn, integer imsi_suffix, integer ran_idx := 0, boolean ran_is_geran := true, boolean use_osmux := false,
455 boolean verify_cell_id := true)
Harald Welte9b751a62019-04-14 17:39:29 +0200456runs on MTC_CT return BSC_ConnHdlr {
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200457 return f_start_handler_with_pars(fn, f_init_pars(imsi_suffix, ran_idx := ran_idx, ran_is_geran := ran_is_geran, use_osmux := use_osmux, verify_cell_id := verify_cell_id));
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100458}
459
Harald Weltea49e36e2018-01-21 19:29:33 +0100460private function f_tc_lu_imsi_noauth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100461 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100462 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100463}
Harald Weltea49e36e2018-01-21 19:29:33 +0100464testcase TC_lu_imsi_noauth_tmsi() runs on MTC_CT {
465 var BSC_ConnHdlr vc_conn;
466 f_init();
467
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100468 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi), 1);
Harald Weltea49e36e2018-01-21 19:29:33 +0100469 vc_conn.done;
470}
471
472private function f_tc_lu_imsi_noauth_notmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100473 pars.net.expect_tmsi := false;
Harald Weltea10db902018-01-27 12:44:49 +0100474 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100475 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100476}
Harald Weltea49e36e2018-01-21 19:29:33 +0100477testcase TC_lu_imsi_noauth_notmsi() runs on MTC_CT {
478 var BSC_ConnHdlr vc_conn;
479 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100480 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
Harald Weltea49e36e2018-01-21 19:29:33 +0100481
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100482 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi), 2);
Harald Weltea49e36e2018-01-21 19:29:33 +0100483 vc_conn.done;
484}
485
486/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
Harald Weltee13cfb22019-04-23 16:52:02 +0200487friend function f_tc_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100488 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100489 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
490
491 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +0200492 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyrd076c522019-11-28 01:00:52 +0100493 f_mm_common();
Harald Weltea49e36e2018-01-21 19:29:33 +0100494 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
495 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
496 alt {
Harald Welte5946b332018-03-18 23:32:21 +0100497 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej(int2oct(23,1)))) {
498 f_expect_clear();
499 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100500 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
501 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200502 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100503 }
504 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100505}
506testcase TC_lu_imsi_reject() runs on MTC_CT {
507 var BSC_ConnHdlr vc_conn;
508 f_init();
509
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200510 vc_conn := f_start_handler(refers(f_tc_lu_imsi_reject), 3, verify_cell_id := false);
Harald Weltea49e36e2018-01-21 19:29:33 +0100511 vc_conn.done;
512}
513
Harald Weltee13cfb22019-04-23 16:52:02 +0200514
515
Harald Weltea49e36e2018-01-21 19:29:33 +0100516/* Do LU by IMSI, timeout on GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +0200517friend function f_tc_lu_imsi_timeout_gsup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100518 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100519 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
520
521 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +0200522 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyrd076c522019-11-28 01:00:52 +0100523 f_mm_common();
Harald Weltea49e36e2018-01-21 19:29:33 +0100524 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
525 /* Normally the HLR would need to respond here, but we decide to force a timeout here */
526 alt {
527 /* FIXME: Expect specific reject cause */
Harald Welte5946b332018-03-18 23:32:21 +0100528 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
529 f_expect_clear();
530 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100531 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
532 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200533 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100534 }
535 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100536}
537testcase TC_lu_imsi_timeout_gsup() runs on MTC_CT {
538 var BSC_ConnHdlr vc_conn;
539 f_init();
540
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200541 vc_conn := f_start_handler(refers(f_tc_lu_imsi_timeout_gsup), 4, verify_cell_id := false);
Harald Weltea49e36e2018-01-21 19:29:33 +0100542 vc_conn.done;
543}
544
Harald Weltee13cfb22019-04-23 16:52:02 +0200545
Harald Welte7b1b2812018-01-22 21:23:06 +0100546private function f_tc_lu_imsi_auth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100547 pars.net.expect_auth := true;
Harald Weltea10db902018-01-27 12:44:49 +0100548 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100549 f_perform_lu();
Harald Welte7b1b2812018-01-22 21:23:06 +0100550}
551testcase TC_lu_imsi_auth_tmsi() runs on MTC_CT {
552 var BSC_ConnHdlr vc_conn;
553 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100554 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte7b1b2812018-01-22 21:23:06 +0100555
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100556 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi), 5);
Harald Welte7b1b2812018-01-22 21:23:06 +0100557 vc_conn.done;
558}
559
Harald Weltee13cfb22019-04-23 16:52:02 +0200560
561friend function f_tc_lu_imsi_auth3g_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte8a397ae2019-04-21 22:03:37 +0200562 pars.net.expect_auth := true;
563 pars.use_umts_aka := true;
564 f_init_handler(pars);
565 f_perform_lu();
566}
567testcase TC_lu_imsi_auth3g_tmsi() runs on MTC_CT {
568 var BSC_ConnHdlr vc_conn;
569 f_init();
570 f_vty_config(MSCVTY, "network", "authentication required");
571
572 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi), 1005);
573 vc_conn.done;
574}
Harald Weltea49e36e2018-01-21 19:29:33 +0100575
Pau Espin Pedrold3d54a92019-12-17 17:02:54 +0100576/* Proceed with LU but never receive an TMSI Realloc from MS after LU Accept (OS#4337).
577 * TS 24.008 sec 4.3.1.5 states MSC should simply release all MM connections.
578 */
579friend function f_tc_lu_imsi_timeout_tmsi_realloc(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
580
581 f_init_handler(pars);
582
583 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
584 var PDU_DTAP_MT dtap_mt;
585
586 /* tell GSUP dispatcher to send this IMSI to us */
587 f_create_gsup_expect(hex2str(g_pars.imsi));
588
589 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
590 if (g_pars.ran_is_geran) {
591 f_bssap_compl_l3(l3_lu);
592 if (g_pars.send_early_cm) {
593 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
594 }
595 } else {
596 f_ranap_initial_ue(l3_lu);
597 }
598
599 f_mm_imei_early();
600 f_mm_common();
601 f_msc_lu_hlr();
602 f_mm_imei();
603
604 alt {
605 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) -> value dtap_mt {}
606 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
607 setverdict(fail, "Expected LU ACK, but received LU REJ");
608 mtc.stop;
609 }
610 }
611
612 /* currently (due to bug OS#4337), an extra LU reject is received before
613 terminating the connection. Enabling following line makes the test
614 pass: */
615 //f_expect_lu_reject('16'O); /* Cause: congestion */
616
617 /* f_expect_lu_reject() already waits for T"-1" (X1, 5 seconds), but give some
618 extra time to avoid race conditons... */
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200619 f_expect_clear(7.0, verify_vlr_cell_id := false);
Pau Espin Pedrold3d54a92019-12-17 17:02:54 +0100620
621 setverdict(pass);
622}
623testcase TC_lu_imsi_timeout_tmsi_realloc() runs on MTC_CT {
624 var BSC_ConnHdlr vc_conn;
625 f_init();
626
627 vc_conn := f_start_handler(refers(f_tc_lu_imsi_timeout_tmsi_realloc), 5);
628 vc_conn.done;
629}
630
Harald Weltee13cfb22019-04-23 16:52:02 +0200631
Harald Weltea49e36e2018-01-21 19:29:33 +0100632/* Send CM SERVICE REQ for IMSI that has never performed LU before */
Harald Weltee13cfb22019-04-23 16:52:02 +0200633friend function f_tc_cmserv_imsi_unknown(charstring id, BSC_ConnHdlrPars pars)
Harald Weltea49e36e2018-01-21 19:29:33 +0100634runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100635 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100636
637 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welteedbab812018-03-18 16:02:25 +0100638 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
Harald Welte6ed6bf92018-01-24 21:09:15 +0100639 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
Harald Weltea49e36e2018-01-21 19:29:33 +0100640
641 f_create_gsup_expect(hex2str(g_pars.imsi));
642
643 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200644 f_cl3_or_initial_ue(l3_info);
Harald Welteb7817992019-05-09 13:15:39 +0200645 f_mm_auth();
Harald Weltea49e36e2018-01-21 19:29:33 +0100646
647 timer T := 10.0;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100648 T.start;
649 alt {
Harald Weltea49e36e2018-01-21 19:29:33 +0100650 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
651 //[] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_ACC)) { }
Daniel Willmannafce8662018-07-06 23:11:32 +0200652 [] BSSAP.receive {
653 setverdict(fail, "Received unexpected BSSAP");
654 mtc.stop;
655 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100656 [] GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi)) {
657 setverdict(fail, "Unexpected GSUP UL REQ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200658 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100659 }
Daniel Willmannafce8662018-07-06 23:11:32 +0200660 [] T.timeout {
Neels Hofmeyrf1c3c212020-08-19 13:15:32 +0000661 setverdict(fail, "Timeout waiting for CM SERV REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200662 mtc.stop;
663 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100664 }
665
Harald Welte1ddc7162018-01-27 14:25:46 +0100666 f_expect_clear();
Harald Weltef6dd64d2017-11-19 12:09:51 +0100667}
Harald Weltea49e36e2018-01-21 19:29:33 +0100668testcase TC_cmserv_imsi_unknown() runs on MTC_CT {
669 var BSC_ConnHdlr vc_conn;
670 f_init();
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200671 vc_conn := f_start_handler(refers(f_tc_cmserv_imsi_unknown), 6, verify_cell_id := false);
Harald Weltea49e36e2018-01-21 19:29:33 +0100672 vc_conn.done;
673}
674
Harald Weltee13cfb22019-04-23 16:52:02 +0200675
Neels Hofmeyr13737fb2020-08-19 13:16:14 +0000676/* Send CM SERVICE REQ for TMSI that has never performed LU before */
677friend function f_tc_cmserv_tmsi_unknown(charstring id, BSC_ConnHdlrPars pars)
678runs on BSC_ConnHdlr {
679 f_init_handler(pars);
680
681 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV('57111111'O));
682 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
683 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
684
685 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
686 f_cl3_or_initial_ue(l3_info);
687 f_mm_auth();
688
689 timer T := 10.0;
690 T.start;
691 alt {
692 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
693 [] BSSAP.receive {
694 setverdict(fail, "Received unexpected BSSAP");
695 mtc.stop;
696 }
697 [] T.timeout {
698 setverdict(fail, "Timeout waiting for CM SERV REJ");
699 mtc.stop;
700 }
701 }
702
703 f_expect_clear();
704}
705testcase TC_cmserv_tmsi_unknown() runs on MTC_CT {
706 var BSC_ConnHdlr vc_conn;
707 f_init();
708 vc_conn := f_start_handler(refers(f_tc_cmserv_tmsi_unknown), 57, verify_cell_id := false);
709 vc_conn.done;
710}
711
Neels Hofmeyr14d0b132020-08-19 13:49:05 +0000712/* Send Paging Response for IMSI that has never performed LU before */
713friend function f_tc_paging_response_imsi_unknown(charstring id, BSC_ConnHdlrPars pars)
714runs on BSC_ConnHdlr {
715 f_init_handler(pars);
716
717 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
718 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
719 var PDU_ML3_MS_NW l3_info := valueof(ts_PAG_RESP(mi));
720
721 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
722 f_cl3_or_initial_ue(l3_info);
723
724 /* The Paging Response gets rejected by a direct Clear Command */
725 f_expect_clear();
726}
727testcase TC_paging_response_imsi_unknown() runs on MTC_CT {
728 var BSC_ConnHdlr vc_conn;
729 f_init();
730 vc_conn := f_start_handler(refers(f_tc_paging_response_imsi_unknown), 58, verify_cell_id := false);
731 vc_conn.done;
732}
733
734/* Send Paging Response for TMSI that has never performed LU before */
735friend function f_tc_paging_response_tmsi_unknown(charstring id, BSC_ConnHdlrPars pars)
736runs on BSC_ConnHdlr {
737 f_init_handler(pars);
738
739 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV('59111111'O));
740 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
741 var PDU_ML3_MS_NW l3_info := valueof(ts_PAG_RESP(mi));
742
743 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
744 f_cl3_or_initial_ue(l3_info);
745
746 /* The Paging Response gets rejected by a direct Clear Command */
747 f_expect_clear();
748}
749testcase TC_paging_response_tmsi_unknown() runs on MTC_CT {
750 var BSC_ConnHdlr vc_conn;
751 f_init();
752 vc_conn := f_start_handler(refers(f_tc_paging_response_tmsi_unknown), 59, verify_cell_id := false);
753 vc_conn.done;
754}
755
Neels Hofmeyr13737fb2020-08-19 13:16:14 +0000756
Harald Weltee13cfb22019-04-23 16:52:02 +0200757friend function f_tc_lu_and_mo_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100758 f_init_handler(pars);
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +0200759 var CallParameters cpars := valueof(t_CallParams);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100760 f_perform_lu();
Harald Welteb71901a2018-01-26 19:16:05 +0100761 f_mo_call(cpars);
Harald Welte2bb825f2018-01-22 11:31:18 +0100762}
763testcase TC_lu_and_mo_call() runs on MTC_CT {
764 var BSC_ConnHdlr vc_conn;
765 f_init();
766
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100767 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_call), 7);
Harald Welte071ed732018-01-23 19:53:52 +0100768 vc_conn.done;
769}
770
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100771/* Verify T(iar) triggers and releases the channel */
772friend function f_lu_and_mo_call_sccp_tiar_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
773 timer T_wait_iar := int2float(5 + 1); /* g_msc_sccp_timer_iar + Give extra time (+1 sec) */
774 f_init_handler(pars);
775 var CallParameters cpars := valueof(t_CallParams);
776 f_perform_lu();
777 f_mo_call_establish(cpars);
778
779 /* Expect the channel cleared upon T(iar) triggered: */
780 T_wait_iar.start;
781 alt {
782 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {
783 T_wait_iar.stop
784 setverdict(pass);
785 }
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100786 [] T_wait_iar.timeout {
787 setverdict(fail, "Timeout waiting for T(iar) triggered SCCP RSLD");
788 mtc.stop;
789 }
790 }
Harald Welte4a3fa712020-08-19 08:57:33 +0200791 /* DLCX for both directions; if we don't do this, we might receive either of the two during
792 * shutdown causing race conditions */
793 MGCP.receive(tr_DLCX(?));
794 MGCP.receive(tr_DLCX(?));
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100795
796 setverdict(pass);
797}
798testcase TC_lu_and_mo_call_sccp_tiar_timeout() runs on MTC_CT {
799 var BSC_ConnHdlr vc_conn;
800
801 /* Set T(iar) in MSC low enough that it will trigger before other side
802 has time to keep alive with a T(ias). Keep recommended ratio of
803 T(iar) >= T(ias)*2 */
804 g_msc_sccp_timer_ias := 2;
805 g_msc_sccp_timer_iar := 5;
806
807 f_init();
808
809 vc_conn := f_start_handler(refers(f_lu_and_mo_call_sccp_tiar_timeout), 89);
810 vc_conn.done;
811}
812
Harald Weltee13cfb22019-04-23 16:52:02 +0200813
Harald Welte071ed732018-01-23 19:53:52 +0100814/* Test LU (with authentication enabled), where HLR times out sending SAI response */
Harald Weltee13cfb22019-04-23 16:52:02 +0200815friend function f_tc_lu_auth_sai_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100816 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100817
818 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
819 var PDU_DTAP_MT dtap_mt;
820
821 /* tell GSUP dispatcher to send this IMSI to us */
822 f_create_gsup_expect(hex2str(g_pars.imsi));
823
824 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200825 f_cl3_or_initial_ue(l3_lu);
Harald Welte071ed732018-01-23 19:53:52 +0100826
827 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200828 if (pars.ran_is_geran) {
829 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
830 }
Harald Welte071ed732018-01-23 19:53:52 +0100831
832 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
833 /* The HLR would normally return an auth vector here, but we fail to do so. */
834
835 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100836 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100837}
838testcase TC_lu_auth_sai_timeout() runs on MTC_CT {
839 var BSC_ConnHdlr vc_conn;
840 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100841 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100842
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200843 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_timeout), 8, verify_cell_id := false);
Harald Welte071ed732018-01-23 19:53:52 +0100844 vc_conn.done;
845}
846
Harald Weltee13cfb22019-04-23 16:52:02 +0200847
Harald Welte071ed732018-01-23 19:53:52 +0100848/* Test LU (with authentication enabled), where HLR rejects sending SAI error */
Harald Weltee13cfb22019-04-23 16:52:02 +0200849friend function f_tc_lu_auth_sai_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100850 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100851
852 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
853 var PDU_DTAP_MT dtap_mt;
854
855 /* tell GSUP dispatcher to send this IMSI to us */
856 f_create_gsup_expect(hex2str(g_pars.imsi));
857
858 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200859 f_cl3_or_initial_ue(l3_lu);
Harald Welte071ed732018-01-23 19:53:52 +0100860
861 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200862 if (pars.ran_is_geran) {
863 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
864 }
Harald Welte071ed732018-01-23 19:53:52 +0100865
866 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
867 GSUP.send(ts_GSUP_SAI_ERR(g_pars.imsi, 13));
868
869 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100870 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100871}
872testcase TC_lu_auth_sai_err() runs on MTC_CT {
873 var BSC_ConnHdlr vc_conn;
874 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100875 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100876
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200877 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_err), 9, verify_cell_id := false);
Harald Welte2bb825f2018-01-22 11:31:18 +0100878 vc_conn.done;
879}
Harald Weltea49e36e2018-01-21 19:29:33 +0100880
Harald Weltee13cfb22019-04-23 16:52:02 +0200881
Harald Weltebc881782018-01-23 20:09:15 +0100882/* Test LU but BSC will send a clear request in the middle */
883private function f_tc_lu_clear_request(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100884 f_init_handler(pars);
Harald Weltebc881782018-01-23 20:09:15 +0100885
886 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
887 var PDU_DTAP_MT dtap_mt;
888
889 /* tell GSUP dispatcher to send this IMSI to us */
890 f_create_gsup_expect(hex2str(g_pars.imsi));
891
892 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200893 f_cl3_or_initial_ue(l3_lu);
Harald Welte79f1e452020-08-18 22:55:02 +0200894 f_expect_common_id();
Harald Weltebc881782018-01-23 20:09:15 +0100895
896 /* Send Early Classmark, just for the fun of it */
897 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
898
899 f_sleep(1.0);
900 /* send clear request in the middle of the LU */
901 BSSAP.send(ts_BSSMAP_ClearRequest(0));
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200902 alt {
903 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { repeat; }
904 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {}
905 }
Harald Weltebc881782018-01-23 20:09:15 +0100906 BSSAP.send(ts_BSSMAP_ClearComplete);
Harald Welte89a32492018-01-27 19:07:28 +0100907 alt {
908 /* See https://osmocom.org/issues/2862 */
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200909 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {
910 setverdict(fail, "Got a second Clear Command, only one expected");
Daniel Willmannafce8662018-07-06 23:11:32 +0200911 mtc.stop;
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200912 repeat;
913 }
Harald Welte6811d102019-04-14 22:23:14 +0200914 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte89a32492018-01-27 19:07:28 +0100915 }
Harald Weltebc881782018-01-23 20:09:15 +0100916 setverdict(pass);
917}
918testcase TC_lu_clear_request() runs on MTC_CT {
919 var BSC_ConnHdlr vc_conn;
920 f_init();
921
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100922 vc_conn := f_start_handler(refers(f_tc_lu_clear_request), 10);
Harald Weltebc881782018-01-23 20:09:15 +0100923 vc_conn.done;
924}
925
Harald Welte66af9e62018-01-24 17:28:21 +0100926/* Test LU but BSC will send a clear request in the middle */
Harald Weltee13cfb22019-04-23 16:52:02 +0200927friend function f_tc_lu_disconnect(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100928 f_init_handler(pars);
Harald Welte66af9e62018-01-24 17:28:21 +0100929
930 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
931 var PDU_DTAP_MT dtap_mt;
932
933 /* tell GSUP dispatcher to send this IMSI to us */
934 f_create_gsup_expect(hex2str(g_pars.imsi));
935
936 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200937 f_cl3_or_initial_ue(l3_lu);
Harald Welte66af9e62018-01-24 17:28:21 +0100938
939 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200940 if (pars.ran_is_geran) {
941 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
942 }
Harald Welte66af9e62018-01-24 17:28:21 +0100943
944 f_sleep(1.0);
945 /* send clear request in the middle of the LU */
Harald Welte6811d102019-04-14 22:23:14 +0200946 BSSAP.send(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_REQ);
Harald Welte66af9e62018-01-24 17:28:21 +0100947 setverdict(pass);
Neels Hofmeyrbb825c92019-03-06 15:35:50 +0100948 f_sleep(1.0);
Harald Welte66af9e62018-01-24 17:28:21 +0100949}
950testcase TC_lu_disconnect() runs on MTC_CT {
951 var BSC_ConnHdlr vc_conn;
952 f_init();
953
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100954 vc_conn := f_start_handler(refers(f_tc_lu_disconnect), 11);
Harald Welte66af9e62018-01-24 17:28:21 +0100955 vc_conn.done;
956}
957
Harald Welteba7b6d92018-01-23 21:32:34 +0100958/* Test LU but with illegal mobile identity type = IMEI */
Harald Weltee13cfb22019-04-23 16:52:02 +0200959friend function f_tc_lu_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100960 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +0100961
Harald Welte256571e2018-01-24 18:47:19 +0100962 var PDU_ML3_MS_NW l3_lu := f_build_lu_imei(g_pars.imei)
Harald Welteba7b6d92018-01-23 21:32:34 +0100963 var PDU_DTAP_MT dtap_mt;
964
965 /* tell GSUP dispatcher to send this IMSI to us */
966 f_create_gsup_expect(hex2str(g_pars.imsi));
967
968 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200969 f_cl3_or_initial_ue(l3_lu);
Harald Welteba7b6d92018-01-23 21:32:34 +0100970
971 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200972 if (pars.ran_is_geran) {
973 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
974 }
Harald Welteba7b6d92018-01-23 21:32:34 +0100975 /* wait for LU reject, ignore any ID REQ */
976 alt {
977 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { }
978 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req)) { repeat; }
979 }
980 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100981 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +0100982}
983testcase TC_lu_by_imei() runs on MTC_CT {
984 var BSC_ConnHdlr vc_conn;
985 f_init();
986
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200987 vc_conn := f_start_handler(refers(f_tc_lu_by_imei), 12, verify_cell_id := false);
Harald Welteba7b6d92018-01-23 21:32:34 +0100988 vc_conn.done;
989}
990
Harald Weltee13cfb22019-04-23 16:52:02 +0200991
Harald Welteba7b6d92018-01-23 21:32:34 +0100992/* Test LU by TMSI with unknown TMSI, expect (and answer) ID REQ. */
993private function f_tc_lu_tmsi_noauth_unknown(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Stefan Sperling04fc4bc2018-06-25 17:44:57 +0200994 /* We piggyback a test for an MSC crash on overlong IMSI (OS#2864) onto this test. */
995 var hexstring overlong_imsi := '012345789ABCDEF0123456789ABCDEF'H;
Harald Weltea10db902018-01-27 12:44:49 +0100996 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +0100997
998 var PDU_ML3_MS_NW l3_lu := f_build_lu_tmsi('01020304'O); /* FIXME: Random */
999 var PDU_DTAP_MT dtap_mt;
1000
1001 /* tell GSUP dispatcher to send this IMSI to us */
1002 f_create_gsup_expect(hex2str(g_pars.imsi));
1003
1004 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001005 f_cl3_or_initial_ue(l3_lu);
Harald Welteba7b6d92018-01-23 21:32:34 +01001006
1007 /* Send Early Classmark, just for the fun of it */
1008 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1009
1010 /* Wait for + respond to ID REQ (IMSI) */
Oliver Smith32898452019-07-09 12:32:35 +02001011 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
Stefan Sperling04fc4bc2018-06-25 17:44:57 +02001012 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(overlong_imsi))); /* test for OS#2864 */
Harald Welteba7b6d92018-01-23 21:32:34 +01001013 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(g_pars.imsi)));
Harald Welte79f1e452020-08-18 22:55:02 +02001014 f_expect_common_id();
Harald Welteba7b6d92018-01-23 21:32:34 +01001015
1016 /* Expect MSC to do UpdateLocation to HLR; respond to it */
1017 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
1018 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
1019 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
1020 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
1021
1022 alt {
Harald Welte7ec4fa82018-01-27 10:57:40 +01001023 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
1024 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_TmsiRealloc_Cmpl));
1025 }
Harald Welteba7b6d92018-01-23 21:32:34 +01001026 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1027 setverdict(fail, "Expected LU ACK, but received REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +02001028 mtc.stop;
Harald Welteba7b6d92018-01-23 21:32:34 +01001029 }
1030 }
1031
Philipp Maier9b690e42018-12-21 11:50:03 +01001032 /* Wait for MM-Information (if enabled) */
1033 f_expect_mm_info();
1034
Harald Welteba7b6d92018-01-23 21:32:34 +01001035 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001036 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +01001037}
1038testcase TC_lu_by_tmsi_noauth_unknown() runs on MTC_CT {
1039 var BSC_ConnHdlr vc_conn;
1040 f_init();
1041
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001042 vc_conn := f_start_handler(refers(f_tc_lu_tmsi_noauth_unknown), 13);
Harald Welteba7b6d92018-01-23 21:32:34 +01001043 vc_conn.done;
1044}
1045
Neels Hofmeyrfc06c732020-08-19 12:52:28 +00001046/* Test LU by unknown TMSI, while the IMSI is already attached: osmo-msc should switch to the attached vlr_subscr. */
1047private function f_tc_attached_imsi_lu_unknown_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1048 f_init_handler(pars);
1049
1050 var PDU_ML3_MS_NW l3_lu := f_build_lu_tmsi('56111111'O);
1051 var PDU_DTAP_MT dtap_mt;
1052
1053 /* tell GSUP dispatcher to send this IMSI to us */
1054 f_create_gsup_expect(hex2str(g_pars.imsi));
1055
1056 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
1057 f_cl3_or_initial_ue(l3_lu);
1058
1059 /* Send Early Classmark, just for the fun of it */
1060 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1061
1062 /* Wait for + respond to ID REQ (IMSI) */
1063 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
1064 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(g_pars.imsi)));
1065 f_expect_common_id();
1066
1067 /* Expect MSC to do UpdateLocation to HLR; respond to it */
1068 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
1069 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
1070 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
1071 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
1072
1073 alt {
1074 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
1075 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_TmsiRealloc_Cmpl));
1076 }
1077 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1078 setverdict(fail, "Expected LU ACK, but received REJ");
1079 mtc.stop;
1080 }
1081 }
1082
1083 /* Wait for MM-Information (if enabled) */
1084 f_expect_mm_info();
1085
1086 /* wait for normal teardown */
1087 f_expect_clear();
1088
1089 /* Now the same IMSI is still attached in the VLR, and a LU with an unknown TMSI reveals the same IMSI only
1090 * later during ID Response. osmo-msc first creates a new vlr_subscr for the unknown TMSI, and as soon as the
1091 * IMSI becomes known, must notice that this IMSI is still regarded as attached, and must not create evil twins.
1092 */
1093
1094 /* (since the TMSI Reallocation happened, we could do this with exactly the same TMSI as above, but for test
1095 * readability just use a different one.) */
1096 l3_lu := f_build_lu_tmsi('56222222'O);
1097 f_cl3_or_initial_ue(l3_lu);
1098
1099 /* Wait for + respond to ID REQ (IMSI) */
1100 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
1101 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(g_pars.imsi)));
1102 f_expect_common_id();
1103
1104 /* Expect MSC to do UpdateLocation to HLR; respond to it */
1105 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
1106 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
1107 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
1108 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
1109
1110 alt {
1111 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
1112 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_TmsiRealloc_Cmpl));
1113 }
1114 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1115 setverdict(fail, "Expected LU ACK, but received REJ");
1116 mtc.stop;
1117 }
1118 }
1119
1120 /* Wait for MM-Information (if enabled) */
1121 f_expect_mm_info();
1122
1123 /* wait for normal teardown */
1124 f_expect_clear();
1125}
1126testcase TC_attached_imsi_lu_unknown_tmsi() runs on MTC_CT {
1127 var BSC_ConnHdlr vc_conn;
1128 f_init();
1129
1130 vc_conn := f_start_handler(refers(f_tc_attached_imsi_lu_unknown_tmsi), 56);
1131 vc_conn.done;
1132}
1133
Harald Welte4d15fa72020-08-19 08:58:28 +02001134friend function f_imsi_detach_by_imsi() runs on BSC_ConnHdlr {
Harald Welte45164da2018-01-24 12:51:27 +01001135 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1136
1137 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001138 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +01001139
1140 /* Send Early Classmark, just for the fun of it? */
Harald Welte4d15fa72020-08-19 08:58:28 +02001141 if (g_pars.ran_is_geran) {
Harald Weltee13cfb22019-04-23 16:52:02 +02001142 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1143 }
Harald Welte45164da2018-01-24 12:51:27 +01001144
1145 /* wait for normal teardown */
Harald Welte4d15fa72020-08-19 08:58:28 +02001146 f_expect_clear(verify_vlr_cell_id := false);
1147}
1148
1149
1150/* Test IMSI DETACH (MI=IMSI) */
1151friend function f_tc_imsi_detach_by_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1152 f_init_handler(pars);
1153
1154 f_imsi_detach_by_imsi();
Harald Welte45164da2018-01-24 12:51:27 +01001155}
1156testcase TC_imsi_detach_by_imsi() runs on MTC_CT {
1157 var BSC_ConnHdlr vc_conn;
1158 f_init();
1159
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001160 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imsi), 14, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001161 vc_conn.done;
1162}
1163
Harald Weltee13cfb22019-04-23 16:52:02 +02001164
Harald Welte45164da2018-01-24 12:51:27 +01001165/* Test IMSI DETACH (MI=TMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +02001166friend function f_tc_imsi_detach_by_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001167 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001168
1169 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV('01020304'O));
1170
1171 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001172 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +01001173
1174 /* Send Early Classmark, just for the fun of it? */
Harald Weltee13cfb22019-04-23 16:52:02 +02001175 if (pars.ran_is_geran) {
1176 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1177 }
Harald Welte45164da2018-01-24 12:51:27 +01001178
1179 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001180 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001181}
1182testcase TC_imsi_detach_by_tmsi() runs on MTC_CT {
1183 var BSC_ConnHdlr vc_conn;
1184 f_init();
1185
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001186 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_tmsi), 15, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001187 vc_conn.done;
1188}
1189
Harald Weltee13cfb22019-04-23 16:52:02 +02001190
Harald Welte45164da2018-01-24 12:51:27 +01001191/* Test IMSI DETACH (MI=IMEI), which is illegal */
Harald Weltee13cfb22019-04-23 16:52:02 +02001192friend function f_tc_imsi_detach_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001193 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001194
Harald Welte256571e2018-01-24 18:47:19 +01001195 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte45164da2018-01-24 12:51:27 +01001196
1197 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001198 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +01001199
1200 /* Send Early Classmark, just for the fun of it? */
Harald Weltee13cfb22019-04-23 16:52:02 +02001201 if (pars.ran_is_geran) {
1202 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1203 }
Harald Welte45164da2018-01-24 12:51:27 +01001204
1205 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001206 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001207}
1208testcase TC_imsi_detach_by_imei() runs on MTC_CT {
1209 var BSC_ConnHdlr vc_conn;
1210 f_init();
1211
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001212 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imei), 16, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001213 vc_conn.done;
1214}
1215
1216
1217/* helper function for an emergency call. caller passes in mobile identity to use */
1218private function f_emerg_call(MobileIdentityLV mi) runs on BSC_ConnHdlr {
Harald Welte0bef21e2018-02-10 09:48:23 +01001219 var CallParameters cpars := valueof(t_CallParams('112'H, 0));
1220 cpars.emergency := true;
Harald Welte45164da2018-01-24 12:51:27 +01001221
Harald Welte0bef21e2018-02-10 09:48:23 +01001222 f_mo_call(cpars);
Harald Welte45164da2018-01-24 12:51:27 +01001223}
1224
1225/* establish an emergency call by IMEI, no SIM inserted (and hence no IMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +02001226friend function f_tc_emerg_call_imei_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001227 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001228
Harald Welte256571e2018-01-24 18:47:19 +01001229 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001230 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_EMERG_CALL, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001231 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001232 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ('05'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +01001233 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001234}
1235testcase TC_emerg_call_imei_reject() runs on MTC_CT {
1236 var BSC_ConnHdlr vc_conn;
1237 f_init();
1238
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001239 vc_conn := f_start_handler(refers(f_tc_emerg_call_imei_reject), 17, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001240 vc_conn.done;
1241}
1242
Harald Weltee13cfb22019-04-23 16:52:02 +02001243
Harald Welted5b91402018-01-24 18:48:16 +01001244/* establish an emergency call by IMSI, SIM inserted (and hence IMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +02001245friend function f_tc_emerg_call_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001246 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001247 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001248 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001249 /* Then issue emergency call identified by IMSI */
1250 f_emerg_call(valueof(ts_MI_IMSI_LV(g_pars.imsi)));
1251}
1252testcase TC_emerg_call_imsi() runs on MTC_CT {
1253 var BSC_ConnHdlr vc_conn;
1254 f_init();
1255
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001256 vc_conn := f_start_handler(refers(f_tc_emerg_call_imsi), 18);
Harald Welte45164da2018-01-24 12:51:27 +01001257 vc_conn.done;
1258}
1259
Harald Weltee13cfb22019-04-23 16:52:02 +02001260
Harald Welte45164da2018-01-24 12:51:27 +01001261/* CM Service Request for VGCS -> reject */
1262private function f_tc_cm_serv_req_vgcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001263 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001264
1265 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001266 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001267
1268 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001269 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VGCS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001270 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001271 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001272 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001273}
1274testcase TC_cm_serv_req_vgcs_reject() runs on MTC_CT {
1275 var BSC_ConnHdlr vc_conn;
1276 f_init();
1277
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001278 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vgcs_reject), 19);
Harald Welte45164da2018-01-24 12:51:27 +01001279 vc_conn.done;
1280}
1281
1282/* CM Service Request for VBS -> reject */
1283private function f_tc_cm_serv_req_vbs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001284 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001285
1286 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001287 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001288
1289 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001290 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VBS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001291 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001292 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001293 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001294}
1295testcase TC_cm_serv_req_vbs_reject() runs on MTC_CT {
1296 var BSC_ConnHdlr vc_conn;
1297 f_init();
1298
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001299 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vbs_reject), 20);
Harald Welte45164da2018-01-24 12:51:27 +01001300 vc_conn.done;
1301}
1302
1303/* CM Service Request for LCS -> reject */
1304private function f_tc_cm_serv_req_lcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001305 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001306
1307 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001308 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001309
1310 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001311 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_LCS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001312 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001313 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001314 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001315}
1316testcase TC_cm_serv_req_lcs_reject() runs on MTC_CT {
1317 var BSC_ConnHdlr vc_conn;
1318 f_init();
1319
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001320 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_lcs_reject), 21);
Harald Welte45164da2018-01-24 12:51:27 +01001321 vc_conn.done;
1322}
1323
Harald Welte0195ab12018-01-24 21:50:20 +01001324/* CM Re-Establishment Request */
1325private function f_tc_cm_reest_req_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001326 f_init_handler(pars);
Harald Welte0195ab12018-01-24 21:50:20 +01001327
1328 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001329 f_perform_lu();
Harald Welte0195ab12018-01-24 21:50:20 +01001330
1331 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1332 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_REEST_REQ(0, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001333 f_cl3_or_initial_ue(l3_info);
Harald Welte0195ab12018-01-24 21:50:20 +01001334 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001335 f_expect_clear();
Harald Welte0195ab12018-01-24 21:50:20 +01001336}
1337testcase TC_cm_reest_req_reject() runs on MTC_CT {
1338 var BSC_ConnHdlr vc_conn;
1339 f_init();
Harald Welte0195ab12018-01-24 21:50:20 +01001340
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001341 vc_conn := f_start_handler(refers(f_tc_cm_reest_req_reject), 22);
Harald Welte0195ab12018-01-24 21:50:20 +01001342 vc_conn.done;
1343}
1344
Harald Weltec638f4d2018-01-24 22:00:36 +01001345/* Test LU (with authentication enabled), with wrong response from MS */
1346private function f_tc_lu_auth_2G_fail(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001347 f_init_handler(pars);
Harald Weltec638f4d2018-01-24 22:00:36 +01001348
1349 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
1350
1351 /* tell GSUP dispatcher to send this IMSI to us */
1352 f_create_gsup_expect(hex2str(g_pars.imsi));
1353
1354 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001355 f_cl3_or_initial_ue(l3_lu);
Harald Weltec638f4d2018-01-24 22:00:36 +01001356
1357 /* Send Early Classmark, just for the fun of it */
1358 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1359
1360 var AuthVector vec := f_gen_auth_vec_2g();
1361 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G(vec.rand, vec.sres, vec.kc));
1362 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
1363 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
1364
1365 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_AUTH_REQ(vec.rand)));
1366 /* Send back wrong auth response */
1367 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MT_MM_AUTH_RESP_2G('00000000'O)));
1368
1369 /* Expect GSUP AUTH FAIL REP to HLR */
1370 GSUP.receive(tr_GSUP_AUTH_FAIL_IND(g_pars.imsi));
1371
1372 /* Expect LU REJECT with Cause == Illegal MS */
1373 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej('03'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +01001374 f_expect_clear();
Harald Weltec638f4d2018-01-24 22:00:36 +01001375}
1376testcase TC_lu_auth_2G_fail() runs on MTC_CT {
1377 var BSC_ConnHdlr vc_conn;
1378 f_init();
1379 f_vty_config(MSCVTY, "network", "authentication required");
Harald Weltec638f4d2018-01-24 22:00:36 +01001380
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001381 vc_conn := f_start_handler(refers(f_tc_lu_auth_2G_fail), 23, verify_cell_id := false);
Harald Weltec638f4d2018-01-24 22:00:36 +01001382 vc_conn.done;
1383}
1384
Harald Weltede371492018-01-27 23:44:41 +01001385/* A5/1 + A5/3 permitted on network side, and MS capable to do it */
Harald Welte16114282018-01-24 22:41:21 +01001386private function f_tc_lu_imsi_auth_tmsi_encr_13_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +01001387 pars.net.expect_auth := true;
1388 pars.net.expect_ciph := true;
Harald Weltea10db902018-01-27 12:44:49 +01001389 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001390 f_perform_lu();
Harald Welte16114282018-01-24 22:41:21 +01001391}
1392testcase TC_lu_imsi_auth_tmsi_encr_13_13() runs on MTC_CT {
1393 var BSC_ConnHdlr vc_conn;
1394 f_init();
1395 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte16114282018-01-24 22:41:21 +01001396 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
1397
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001398 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_13), 24);
Harald Welte16114282018-01-24 22:41:21 +01001399 vc_conn.done;
1400}
1401
Harald Welte1af6ea82018-01-25 18:33:15 +01001402/* Test Complete L3 without payload */
1403private function f_tc_cl3_no_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001404 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001405
1406 /* Send Complete L3 Info with empty L3 frame */
1407 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1408 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, ''O))));
1409
Harald Weltef466eb42018-01-27 14:26:54 +01001410 timer T := 5.0;
1411 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001412 alt {
Harald Welte6811d102019-04-14 22:23:14 +02001413 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte1af6ea82018-01-25 18:33:15 +01001414 /* Expect LU REJECT with Cause == Illegal MS */
Harald Weltebdb3c452018-03-18 22:43:06 +01001415 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
Harald Welte6811d102019-04-14 22:23:14 +02001416 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001417 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001418 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001419 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001420 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001421 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001422 }
1423 setverdict(pass);
1424}
1425testcase TC_cl3_no_payload() runs on MTC_CT {
1426 var BSC_ConnHdlr vc_conn;
1427 f_init();
1428
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001429 vc_conn := f_start_handler(refers(f_tc_cl3_no_payload), 25);
Harald Welte1af6ea82018-01-25 18:33:15 +01001430 vc_conn.done;
1431}
1432
1433/* Test Complete L3 with random payload */
1434private function f_tc_cl3_rnd_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001435 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001436
Daniel Willmannaa14a382018-07-26 08:29:45 +02001437 /* length is limited by PDU_BSSAP length field which includes some
1438 * other fields beside l3info payload. So payl can only be 240 bytes
1439 * Since rnd() returns values < 1 multiply with 241
1440 */
1441 var integer len := float2int(rnd() * 241.0);
Harald Welte1af6ea82018-01-25 18:33:15 +01001442 var octetstring payl := f_rnd_octstring(len);
1443
1444 /* Send Complete L3 Info with empty L3 frame */
1445 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1446 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, payl))));
1447
Harald Weltef466eb42018-01-27 14:26:54 +01001448 timer T := 5.0;
1449 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001450 alt {
1451 /* Immediate disconnect */
Harald Welte6811d102019-04-14 22:23:14 +02001452 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte1af6ea82018-01-25 18:33:15 +01001453 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
Harald Welte6811d102019-04-14 22:23:14 +02001454 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001455 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001456 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001457 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001458 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001459 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001460 }
1461 setverdict(pass);
1462}
1463testcase TC_cl3_rnd_payload() runs on MTC_CT {
1464 var BSC_ConnHdlr vc_conn;
1465 f_init();
1466
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001467 vc_conn := f_start_handler(refers(f_tc_cl3_rnd_payload), 26);
Harald Welte1af6ea82018-01-25 18:33:15 +01001468 vc_conn.done;
1469}
1470
Harald Welte116e4332018-01-26 22:17:48 +01001471/* Test Complete L3 with random payload */
Harald Weltee13cfb22019-04-23 16:52:02 +02001472friend function f_tc_establish_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001473 f_init_handler(pars);
Harald Welte116e4332018-01-26 22:17:48 +01001474
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001475 f_perform_lu();
Harald Welte116e4332018-01-26 22:17:48 +01001476
Harald Welteb9e86fa2018-04-09 18:18:31 +02001477 f_establish_fully();
Daniel Willmann898a7e02018-05-17 12:16:16 +02001478 f_expect_clear(10.0);
Harald Welte116e4332018-01-26 22:17:48 +01001479}
1480testcase TC_establish_and_nothing() runs on MTC_CT {
1481 var BSC_ConnHdlr vc_conn;
1482 f_init();
1483
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001484 vc_conn := f_start_handler(refers(f_tc_establish_and_nothing), 27);
Harald Welte116e4332018-01-26 22:17:48 +01001485 vc_conn.done;
1486}
1487
Harald Weltee13cfb22019-04-23 16:52:02 +02001488
Harald Welte12510c52018-01-26 22:26:24 +01001489/* Test MO Call SETUP with no response from MNCC */
Harald Weltee13cfb22019-04-23 16:52:02 +02001490friend function f_tc_mo_setup_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier109e6aa2018-10-17 10:53:32 +02001491 f_init_handler(pars, 190.0);
Harald Weltea10db902018-01-27 12:44:49 +01001492
Harald Welte12510c52018-01-26 22:26:24 +01001493 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001494 cpars.mgw_conn_2.resp := 0;
1495 cpars.stop_after_cc_setup := true;
1496
1497 f_vty_config(MSCVTY, "msc", "mncc guard-timeout 20");
Harald Welte12510c52018-01-26 22:26:24 +01001498
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001499 f_perform_lu();
Harald Welte12510c52018-01-26 22:26:24 +01001500
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001501 f_mo_call_establish(cpars);
Harald Welte12510c52018-01-26 22:26:24 +01001502
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001503 var default ccrel := activate(as_optional_cc_rel(cpars));
1504
Philipp Maier109e6aa2018-10-17 10:53:32 +02001505 f_expect_clear(185.0);
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001506
1507 deactivate(ccrel);
1508
1509 f_sleep(1.0);
Harald Welte12510c52018-01-26 22:26:24 +01001510}
1511testcase TC_mo_setup_and_nothing() runs on MTC_CT {
1512 var BSC_ConnHdlr vc_conn;
1513 f_init();
1514
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001515 vc_conn := f_start_handler(refers(f_tc_mo_setup_and_nothing), 28);
Harald Welte12510c52018-01-26 22:26:24 +01001516 vc_conn.done;
1517}
1518
Harald Weltee13cfb22019-04-23 16:52:02 +02001519
Harald Welte3ab88002018-01-26 22:37:25 +01001520/* Test MO Call with no response to RAN-side CRCX */
Harald Weltee13cfb22019-04-23 16:52:02 +02001521friend function f_tc_mo_crcx_ran_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001522 f_init_handler(pars);
Harald Welte3ab88002018-01-26 22:37:25 +01001523 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1524 var MNCC_PDU mncc;
1525 var MgcpCommand mgcp_cmd;
1526
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001527 f_perform_lu();
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001528 /* Do not respond to the second CRCX */
1529 cpars.mgw_conn_2.resp := 0;
1530 f_mo_call_establish(cpars);
Harald Welte3ab88002018-01-26 22:37:25 +01001531
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001532 var default ccrel := activate(as_optional_cc_rel(cpars));
Harald Welte3ab88002018-01-26 22:37:25 +01001533
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001534 f_expect_clear(60.0);
Harald Welte3ab88002018-01-26 22:37:25 +01001535
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001536 deactivate(ccrel);
Harald Welte3ab88002018-01-26 22:37:25 +01001537}
1538testcase TC_mo_crcx_ran_timeout() runs on MTC_CT {
1539 var BSC_ConnHdlr vc_conn;
1540 f_init();
1541
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001542 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_timeout), 29);
Harald Welte3ab88002018-01-26 22:37:25 +01001543 vc_conn.done;
1544}
1545
Harald Weltee13cfb22019-04-23 16:52:02 +02001546
Harald Welte0cc82d92018-01-26 22:52:34 +01001547/* Test MO Call with reject to RAN-side CRCX */
Harald Weltee13cfb22019-04-23 16:52:02 +02001548friend function f_tc_mo_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001549 f_init_handler(pars);
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001550
Harald Welte0cc82d92018-01-26 22:52:34 +01001551 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001552
1553 /* Respond with error for the first CRCX */
1554 cpars.mgw_conn_1.resp := -1;
Harald Welte0cc82d92018-01-26 22:52:34 +01001555
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001556 f_perform_lu();
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001557 f_mo_call_establish(cpars);
Harald Welte0cc82d92018-01-26 22:52:34 +01001558
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001559 var default ccrel := activate(as_optional_cc_rel(cpars));
1560 f_expect_clear(60.0);
1561 deactivate(ccrel);
Harald Welte0cc82d92018-01-26 22:52:34 +01001562}
1563testcase TC_mo_crcx_ran_reject() runs on MTC_CT {
1564 var BSC_ConnHdlr vc_conn;
1565 f_init();
1566
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001567 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_reject), 30);
Harald Welte0cc82d92018-01-26 22:52:34 +01001568 vc_conn.done;
1569}
1570
Harald Welte3ab88002018-01-26 22:37:25 +01001571
Harald Welte812f7a42018-01-27 00:49:18 +01001572/* helper function to start a MT call: MNCC SETUP; Paging; DChan est.; DTAP SETUP */
1573private function f_mt_call_start(inout CallParameters cpars) runs on BSC_ConnHdlr {
1574 var MNCC_PDU mncc;
1575 var MgcpCommand mgcp_cmd;
Harald Welte812f7a42018-01-27 00:49:18 +01001576
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001577 f_perform_lu();
Vadim Yanitskiyae747742020-01-10 00:23:10 +01001578 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Welte812f7a42018-01-27 00:49:18 +01001579
1580 /* Allocate call reference and send SETUP via MNCC to MSC */
1581 cpars.mncc_callref := f_rnd_int(2147483648);
1582 MNCC.send(ts_MNCC_SETUP_req(cpars.mncc_callref, hex2str(g_pars.msisdn),
1583 hex2str(cpars.called_party), hex2str(g_pars.imsi)));
1584
1585 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02001586 f_expect_paging();
1587
Harald Welte812f7a42018-01-27 00:49:18 +01001588 /* MS -> MSC: PAGING RESPONSE */
Harald Welteb9e86fa2018-04-09 18:18:31 +02001589 f_establish_fully(EST_TYPE_PAG_RESP);
Harald Welte812f7a42018-01-27 00:49:18 +01001590
1591 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1592
1593 /* MSC->MS: SETUP */
1594 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_SETUP(cpars.transaction_id, *, cpars.called_party)));
1595}
1596
1597/* Test MT Call */
Harald Weltee13cfb22019-04-23 16:52:02 +02001598friend function f_tc_mt_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001599 f_init_handler(pars);
Harald Welte812f7a42018-01-27 00:49:18 +01001600 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1601 var MNCC_PDU mncc;
1602 var MgcpCommand mgcp_cmd;
1603
1604 f_mt_call_start(cpars);
1605
1606 /* MS->MSC: CALL CONFIRMED */
1607 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1608
1609 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1610
1611 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1612 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001613
1614 /* Detect if the received CRCX is a wildcarded CRCX request. If yes,
1615 * set an endpoint name that fits the pattern. If not, just use the
1616 * endpoint name from the request */
1617 if (match(mgcp_cmd.line.ep, t_MGCP_EP_wildcard)) {
1618 cpars.mgcp_ep := "rtpbridge/1@mgw";
1619 } else {
1620 cpars.mgcp_ep := mgcp_cmd.line.ep;
1621 }
1622
Harald Welte812f7a42018-01-27 00:49:18 +01001623 /* Respond to CRCX with error */
1624 var MgcpResponse mgcp_rsp := {
1625 line := {
1626 code := "542",
1627 trans_id := mgcp_cmd.line.trans_id,
1628 string := "FORCED_FAIL"
1629 },
Harald Welte812f7a42018-01-27 00:49:18 +01001630 sdp := omit
1631 }
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001632 var MgcpParameter mgcp_rsp_param := {
1633 code := "Z",
1634 val := cpars.mgcp_ep
1635 };
1636 mgcp_rsp.params[0] := mgcp_rsp_param;
Harald Welte812f7a42018-01-27 00:49:18 +01001637 MGCP.send(mgcp_rsp);
1638
1639 timer T := 30.0;
1640 T.start;
1641 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001642 [] T.timeout {
1643 setverdict(fail, "Timeout waiting for channel release");
1644 mtc.stop;
1645 }
Harald Welte812f7a42018-01-27 00:49:18 +01001646 [] MNCC.receive { repeat; }
1647 [] GSUP.receive { repeat; }
1648 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1649 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
1650 f_create_mgcp_delete_ep(cpars.mgcp_ep);
1651 repeat;
1652 }
1653 [] MGCP.receive { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001654 [] as_clear_cmd_compl_disc();
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001655 [] as_optional_cc_rel(cpars);
Harald Welte812f7a42018-01-27 00:49:18 +01001656 }
1657}
1658testcase TC_mt_crcx_ran_reject() runs on MTC_CT {
1659 var BSC_ConnHdlr vc_conn;
1660 f_init();
1661
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001662 vc_conn := f_start_handler(refers(f_tc_mt_crcx_ran_reject), 31);
Harald Welte812f7a42018-01-27 00:49:18 +01001663 vc_conn.done;
1664}
1665
1666
Harald Weltee13cfb22019-04-23 16:52:02 +02001667
Harald Welte812f7a42018-01-27 00:49:18 +01001668/* Test MT Call T310 timer */
Harald Weltee13cfb22019-04-23 16:52:02 +02001669friend function f_tc_mt_t310(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltead2952e2018-01-27 14:12:46 +01001670 f_init_handler(pars, 200.0);
Harald Welte812f7a42018-01-27 00:49:18 +01001671 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1672 var MNCC_PDU mncc;
1673 var MgcpCommand mgcp_cmd;
1674
1675 f_mt_call_start(cpars);
1676
1677 /* MS->MSC: CALL CONFIRMED */
1678 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1679 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1680
1681 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1682 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
1683 cpars.mgcp_ep := mgcp_cmd.line.ep;
1684 /* FIXME: Respond to CRCX */
1685
1686 /* old libosmocore T310 default timeout is 180s. so let's wait 190 */
1687 timer T := 190.0;
1688 T.start;
1689 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001690 [] T.timeout {
1691 setverdict(fail, "Timeout waiting for T310");
1692 mtc.stop;
1693 }
Harald Welte812f7a42018-01-27 00:49:18 +01001694 [] MNCC.receive(tr_MNCC_DISC_ind(cpars.mncc_callref)) {
1695 MNCC.send(ts_MNCC_REL_req(cpars.mncc_callref, valueof(ts_MNCC_cause(23))));
1696 }
1697 }
1698 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_DISC(cpars.transaction_id)));
1699 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id)));
1700 /* FIXME: We're sending this with TIflag 0: allocated by sender, which is wrong */
1701 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id)));
1702
1703 alt {
Harald Welte812f7a42018-01-27 00:49:18 +01001704 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1705 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
1706 f_create_mgcp_delete_ep(cpars.mgcp_ep);
1707 repeat;
1708 }
Harald Welte5946b332018-03-18 23:32:21 +01001709 [] as_clear_cmd_compl_disc();
Harald Welte812f7a42018-01-27 00:49:18 +01001710 }
1711}
1712testcase TC_mt_t310() runs on MTC_CT {
1713 var BSC_ConnHdlr vc_conn;
1714 f_init();
1715
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001716 vc_conn := f_start_handler(refers(f_tc_mt_t310), 32);
Harald Welte812f7a42018-01-27 00:49:18 +01001717 vc_conn.done;
1718}
1719
Harald Weltee13cfb22019-04-23 16:52:02 +02001720
Harald Welte167458a2018-01-27 15:58:16 +01001721/* Perform successful LU + MO call, then GSUP LocationCancel. Subscriber must be denied CM SERV */
Harald Weltee13cfb22019-04-23 16:52:02 +02001722friend function f_tc_gsup_cancel(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte167458a2018-01-27 15:58:16 +01001723 f_init_handler(pars);
1724 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Harald Welte167458a2018-01-27 15:58:16 +01001725
1726 /* Location Update to make subscriber known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001727 f_perform_lu();
Harald Welte167458a2018-01-27 15:58:16 +01001728
1729 /* First MO call should succeed */
1730 f_mo_call(cpars);
1731
1732 /* Cancel the subscriber in the VLR */
1733 GSUP.send(ts_GSUP_CL_REQ(g_pars.imsi, OSMO_GSUP_CANCEL_TYPE_WITHDRAW));
1734 alt {
1735 [] GSUP.receive(tr_GSUP_CL_RES(g_pars.imsi)) { }
1736 [] GSUP.receive(tr_GSUP_CL_ERR(g_pars.imsi)) {
1737 setverdict(fail, "Received GSUP Location Cancel Error");
Daniel Willmannafce8662018-07-06 23:11:32 +02001738 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001739 }
1740 }
1741
1742 /* Follow-up transactions should fail */
1743 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1744 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001745 f_cl3_or_initial_ue(l3_info);
Harald Welte167458a2018-01-27 15:58:16 +01001746 alt {
1747 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
1748 [] BSSAP.receive {
1749 setverdict(fail, "Received unexpected BSSAP instead of CM SERV REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +02001750 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001751 }
1752 }
Neels Hofmeyr0f7429a2019-03-07 22:28:41 +01001753
1754 f_expect_clear();
Harald Welte167458a2018-01-27 15:58:16 +01001755 setverdict(pass);
1756}
1757testcase TC_gsup_cancel() runs on MTC_CT {
1758 var BSC_ConnHdlr vc_conn;
1759 f_init();
1760
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001761 vc_conn := f_start_handler(refers(f_tc_gsup_cancel), 33, verify_cell_id := false);
Harald Welte167458a2018-01-27 15:58:16 +01001762 vc_conn.done;
1763}
1764
Harald Weltee13cfb22019-04-23 16:52:02 +02001765
Harald Welte9de84792018-01-28 01:06:35 +01001766/* A5/1 only permitted on network side, and MS capable to do it */
1767private function f_tc_lu_imsi_auth_tmsi_encr_1_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1768 pars.net.expect_auth := true;
1769 pars.net.expect_ciph := true;
1770 pars.net.kc_support := '02'O; /* A5/1 only */
1771 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001772 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001773}
1774testcase TC_lu_imsi_auth_tmsi_encr_1_13() runs on MTC_CT {
1775 var BSC_ConnHdlr vc_conn;
1776 f_init();
1777 f_vty_config(MSCVTY, "network", "authentication required");
1778 f_vty_config(MSCVTY, "network", "encryption a5 1");
1779
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001780 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_1_13), 34);
Harald Welte9de84792018-01-28 01:06:35 +01001781 vc_conn.done;
1782}
1783
1784/* A5/3 only permitted on network side, and MS capable to do it */
1785private function f_tc_lu_imsi_auth_tmsi_encr_3_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1786 pars.net.expect_auth := true;
1787 pars.net.expect_ciph := true;
1788 pars.net.kc_support := '08'O; /* A5/3 only */
1789 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001790 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001791}
1792testcase TC_lu_imsi_auth_tmsi_encr_3_13() runs on MTC_CT {
1793 var BSC_ConnHdlr vc_conn;
1794 f_init();
1795 f_vty_config(MSCVTY, "network", "authentication required");
1796 f_vty_config(MSCVTY, "network", "encryption a5 3");
1797
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001798 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_13), 35);
Harald Welte9de84792018-01-28 01:06:35 +01001799 vc_conn.done;
1800}
1801
1802/* A5/3 only permitted on network side, and MS with only A5/1 support */
1803private function f_tc_lu_imsi_auth_tmsi_encr_3_1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1804 pars.net.expect_auth := true;
1805 pars.net.expect_ciph := true;
1806 pars.net.kc_support := '08'O; /* A5/3 only */
1807 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1808 f_init_handler(pars, 15.0);
1809
1810 /* cannot use f_perform_lu() as we expect a reject */
1811 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
1812 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +02001813 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001814 if (pars.send_early_cm) {
1815 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1816 } else {
1817 pars.cm1.esind := '0'B;
1818 }
Harald Welte9de84792018-01-28 01:06:35 +01001819 f_mm_auth();
1820 alt {
Daniel Willmann52918e52018-09-20 14:39:09 +02001821 [] BSSAP.receive(tr_BSSMAP_ClassmarkReq) {
1822 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1823 repeat;
1824 }
Harald Welte5946b332018-03-18 23:32:21 +01001825 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1826 f_expect_clear();
1827 }
Harald Welte9de84792018-01-28 01:06:35 +01001828 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
1829 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02001830 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001831 }
1832 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01001833 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02001834 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001835 }
1836 }
1837 setverdict(pass);
1838}
1839testcase TC_lu_imsi_auth_tmsi_encr_3_1() runs on MTC_CT {
1840 var BSC_ConnHdlr vc_conn;
1841 f_init();
1842 f_vty_config(MSCVTY, "network", "authentication required");
1843 f_vty_config(MSCVTY, "network", "encryption a5 3");
1844
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001845 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 360, verify_cell_id := false);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001846 vc_conn.done;
1847}
1848testcase TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() runs on MTC_CT {
1849 var BSC_ConnHdlrPars pars;
1850 var BSC_ConnHdlr vc_conn;
1851 f_init();
1852 f_vty_config(MSCVTY, "network", "authentication required");
1853 f_vty_config(MSCVTY, "network", "encryption a5 3");
1854
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001855 pars := f_init_pars(361, verify_cell_id := false);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001856 pars.send_early_cm := false;
1857 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), pars);
Harald Welte9de84792018-01-28 01:06:35 +01001858 vc_conn.done;
1859}
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01001860testcase TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() runs on MTC_CT {
1861 var BSC_ConnHdlr vc_conn;
1862 f_init();
1863 f_vty_config(MSCVTY, "network", "authentication required");
1864 f_vty_config(MSCVTY, "network", "encryption a5 3");
1865
1866 /* Make sure the MSC category is on DEBUG level to trigger the log
1867 * message that is reported in OS#2947 to trigger the segfault */
1868 f_vty_config(MSCVTY, "log stderr", "logging level msc debug");
1869
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001870 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 362, verify_cell_id := false);
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01001871 vc_conn.done;
1872}
Harald Welte9de84792018-01-28 01:06:35 +01001873
1874/* A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
1875private function f_tc_lu_imsi_auth_tmsi_encr_13_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1876 pars.net.expect_auth := true;
1877 pars.net.expect_ciph := true;
1878 pars.net.kc_support := '0A'O; /* A5/1 + A5/3 */
1879 pars.cm1.a5_1 := '1'B;
1880 pars.cm2.a5_1 := '1'B;
1881 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1882 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
1883 f_init_handler(pars, 15.0);
1884
1885 /* cannot use f_perform_lu() as we expect a reject */
1886 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
1887 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +02001888 f_cl3_or_initial_ue(l3_lu);
Harald Welte9de84792018-01-28 01:06:35 +01001889 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1890 f_mm_auth();
1891 alt {
Harald Welte5946b332018-03-18 23:32:21 +01001892 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1893 f_expect_clear();
1894 }
Harald Welte9de84792018-01-28 01:06:35 +01001895 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
1896 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02001897 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001898 }
1899 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01001900 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02001901 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001902 }
1903 }
1904 setverdict(pass);
1905}
1906testcase TC_lu_imsi_auth_tmsi_encr_13_2() runs on MTC_CT {
1907 var BSC_ConnHdlr vc_conn;
1908 f_init();
1909 f_vty_config(MSCVTY, "network", "authentication required");
1910 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
1911
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001912 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_2), 37, verify_cell_id := false);
Harald Welte9de84792018-01-28 01:06:35 +01001913 vc_conn.done;
1914}
1915
1916/* A5/0 + A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
1917private function f_tc_lu_imsi_auth_tmsi_encr_013_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1918 pars.net.expect_auth := true;
1919 pars.net.expect_ciph := true;
1920 pars.net.kc_support := '0B'O; /* A5/1 + A5/3 */
1921 pars.cm1.a5_1 := '1'B;
1922 pars.cm2.a5_1 := '1'B;
1923 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1924 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
1925 f_init_handler(pars, 15.0);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001926 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001927}
1928testcase TC_lu_imsi_auth_tmsi_encr_013_2() runs on MTC_CT {
1929 var BSC_ConnHdlr vc_conn;
1930 f_init();
1931 f_vty_config(MSCVTY, "network", "authentication required");
1932 f_vty_config(MSCVTY, "network", "encryption a5 0 1 3");
1933
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001934 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_013_2), 38);
Harald Welte9de84792018-01-28 01:06:35 +01001935 vc_conn.done;
1936}
1937
Harald Welte33ec09b2018-02-10 15:34:46 +01001938/* LU followed by MT call (including paging) */
Neels Hofmeyr8fe8a902019-11-03 05:51:03 +01001939friend function f_tc_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte33ec09b2018-02-10 15:34:46 +01001940 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01001941 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02001942 cpars.use_osmux := pars.use_osmux;
Harald Welte33ec09b2018-02-10 15:34:46 +01001943
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001944 f_perform_lu();
Harald Welte33ec09b2018-02-10 15:34:46 +01001945 f_mt_call(cpars);
1946}
1947testcase TC_lu_and_mt_call() runs on MTC_CT {
1948 var BSC_ConnHdlr vc_conn;
1949 f_init();
1950
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001951 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call), 39);
Harald Welte33ec09b2018-02-10 15:34:46 +01001952 vc_conn.done;
1953}
1954
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02001955testcase TC_lu_and_mt_call_osmux() runs on MTC_CT {
1956 var BSC_ConnHdlr vc_conn;
1957 f_init(1, false, true, true);
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02001958
1959 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call), 39, 0, true, true);
1960 vc_conn.done;
1961}
1962
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01001963/* MT call while already Paging */
1964friend function f_tc_lu_and_mt_call_already_paging(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1965 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1966 var SmsParameters spars := valueof(t_SmsPars);
1967 var OCT4 tmsi;
1968
1969 f_init_handler(pars);
1970
1971 /* Perform location update */
1972 f_perform_lu();
1973
1974 /* register an 'expect' for given IMSI (+TMSI) */
1975 if (isvalue(g_pars.tmsi)) {
1976 tmsi := g_pars.tmsi;
1977 } else {
1978 tmsi := 'FFFFFFFF'O;
1979 }
1980 f_ran_register_imsi(g_pars.imsi, tmsi);
1981
1982 log("start Paging by an SMS");
1983 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
1984
1985 /* MSC->BSC: expect PAGING from MSC */
1986 f_expect_paging();
1987
1988 log("MNCC signals MT call, before Paging Response");
1989 f_mt_call_initate(cpars);
1990 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
1991
1992 f_sleep(0.5);
1993 log("phone answers Paging, expecting both SMS and MT call to be established");
1994 f_establish_fully(EST_TYPE_PAG_RESP);
1995 spars.tp.ud := 'C8329BFD064D9B53'O;
1996 interleave {
1997 [] BSSAP.receive(f_mt_sms_deliver_pdu(spars)) {
1998 log("Got SMS-DELIVER");
1999 };
2000 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_SETUP(cpars.transaction_id, *, cpars.called_party))) {
2001 log("Got CC Setup");
2002 };
2003 }
2004 setverdict(pass);
2005 log("success, tear down");
2006 var default ccrel := activate(as_optional_cc_rel(cpars));
2007 if (g_pars.ran_is_geran) {
2008 BSSAP.send(ts_BSSMAP_ClearRequest(0));
2009 } else {
2010 BSSAP.send(ts_RANAP_IuReleaseRequest(ts_RanapCause_om_intervention));
2011 }
2012 f_expect_clear();
2013 deactivate(ccrel);
2014 f_vty_sms_clear(hex2str(g_pars.imsi));
2015}
2016testcase TC_lu_and_mt_call_already_paging() runs on MTC_CT {
2017 var BSC_ConnHdlrPars pars;
2018 var BSC_ConnHdlr vc_conn;
2019 f_init();
2020 pars := f_init_pars(391);
2021 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_call_already_paging), pars);
2022 vc_conn.done;
2023}
2024
Daniel Willmann8b084372018-02-04 13:35:26 +01002025/* Test MO Call SETUP with DTMF */
2026private function f_tc_mo_setup_dtmf_dup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2027 f_init_handler(pars);
2028 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Daniel Willmann8b084372018-02-04 13:35:26 +01002029
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01002030 f_perform_lu();
Daniel Willmann8b084372018-02-04 13:35:26 +01002031 f_mo_seq_dtmf_dup(cpars);
2032}
2033testcase TC_mo_setup_and_dtmf_dup() runs on MTC_CT {
2034 var BSC_ConnHdlr vc_conn;
2035 f_init();
2036
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01002037 vc_conn := f_start_handler(refers(f_tc_mo_setup_dtmf_dup), 39);
Daniel Willmann8b084372018-02-04 13:35:26 +01002038 vc_conn.done;
2039}
Harald Welte9de84792018-01-28 01:06:35 +01002040
Philipp Maier328d1662018-03-07 10:40:27 +01002041testcase TC_cr_before_reset() runs on MTC_CT {
2042 timer T := 4.0;
2043 var boolean reset_ack_seen := false;
2044 f_init_bssap_direct();
2045
Harald Welte3ca0ce12019-04-23 17:18:48 +02002046 f_ran_adapter_start(g_bssap[0]);
Daniel Willmann42d1d5b2018-08-07 15:18:41 +02002047
Daniel Willmanne8018962018-08-21 14:18:00 +02002048 f_sleep(3.0);
2049
Philipp Maier328d1662018-03-07 10:40:27 +01002050 /* Make a blind connection attemt, to trigger the deadlock condition */
Philipp Maier75932982018-03-27 14:52:35 +02002051 BSSAP_DIRECT.send(ts_BSSAP_CONNECT_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, 1, omit));
Philipp Maier328d1662018-03-07 10:40:27 +01002052
2053 /* Send a BSSMAP reset */
Philipp Maier75932982018-03-27 14:52:35 +02002054 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_Reset(0)));
Philipp Maier328d1662018-03-07 10:40:27 +01002055 T.start
2056 alt {
2057 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_ResetAck)) {
2058 reset_ack_seen := true;
2059 repeat;
2060 }
2061
2062 /* Acknowledge MSC sided reset requests */
2063 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_Reset)) {
Philipp Maier75932982018-03-27 14:52:35 +02002064 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_ResetAck));
Philipp Maier328d1662018-03-07 10:40:27 +01002065 repeat;
2066 }
2067
2068 /* Ignore all other messages (e.g CR from the connection request) */
2069 [] BSSAP_DIRECT.receive { repeat }
2070
2071 /* If we got no BSSMAP RESET ACK back, then the MSC entered the
2072 * deadlock situation. The MSC is then unable to respond to any
2073 * further BSSMAP RESET or any other sort of traffic. */
2074 [reset_ack_seen == true] T.timeout { setverdict(pass) }
2075 [reset_ack_seen == false] T.timeout {
2076 setverdict(fail, "no BSSMAP RESET ACK seen!");
Daniel Willmannafce8662018-07-06 23:11:32 +02002077 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +01002078 }
Pau Espin Pedrol7e9178d2019-12-17 17:52:17 +01002079 }
Philipp Maier328d1662018-03-07 10:40:27 +01002080}
Harald Welte9de84792018-01-28 01:06:35 +01002081
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002082/* Test MO Call with no response to RAN-side CRCX or DTAP Release */
Harald Weltee13cfb22019-04-23 16:52:02 +02002083friend function f_tc_mo_release_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002084 f_init_handler(pars);
2085 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
2086 var MNCC_PDU mncc;
2087 var MgcpCommand mgcp_cmd;
2088
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02002089 /* Do not respond to the second CRCX */
2090 cpars.mgw_conn_2.resp := 0;
2091
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002092 f_perform_lu();
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02002093 f_mo_call_establish(cpars);
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002094
Neels Hofmeyrde76f052019-02-26 05:02:46 +01002095 var default ccrel := activate(as_optional_cc_rel(cpars));
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002096
2097 f_expect_clear(60.0);
Neels Hofmeyrde76f052019-02-26 05:02:46 +01002098
2099 deactivate(ccrel);
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002100}
2101testcase TC_mo_release_timeout() runs on MTC_CT {
2102 var BSC_ConnHdlr vc_conn;
2103 f_init();
2104
2105 vc_conn := f_start_handler(refers(f_tc_mo_release_timeout), 40);
2106 vc_conn.done;
2107}
2108
Harald Welte12510c52018-01-26 22:26:24 +01002109
Philipp Maier2a98a732018-03-19 16:06:12 +01002110/* LU followed by MT call (including paging) */
2111private function f_tc_lu_and_mt_call_no_dlcx_resp(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2112 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01002113 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Philipp Maier2a98a732018-03-19 16:06:12 +01002114
2115 /* Intentionally disable the CRCX response */
2116 cpars.mgw_drop_dlcx := true;
2117
2118 /* Perform location update and call */
2119 f_perform_lu();
2120 f_mt_call(cpars);
2121}
2122testcase TC_lu_and_mt_call_no_dlcx_resp() runs on MTC_CT {
2123 var BSC_ConnHdlr vc_conn;
2124 f_init();
2125
2126 /* Perform an almost normal looking locationupdate + mt-call, but do
2127 * not respond to the DLCX at the end of the call */
2128 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call_no_dlcx_resp), 41);
2129 vc_conn.done;
2130
2131 /* Wait a guard period until the MGCP layer in the MSC times out,
2132 * if the MSC is vulnerable to the use-after-free situation that is
2133 * fixed by I78f1b6a9149488a4ad3f120c1e190a83c07d4b89 then it should
2134 * segfault now */
2135 f_sleep(6.0);
2136
2137 /* Run the init procedures once more. If the MSC has crashed, this
2138 * this will fail */
2139 f_init();
2140}
Harald Welte45164da2018-01-24 12:51:27 +01002141
Philipp Maier75932982018-03-27 14:52:35 +02002142/* Two BSSMAP resets from two different BSCs */
2143testcase TC_reset_two() runs on MTC_CT {
2144 var BSC_ConnHdlr vc_conn;
2145 f_init(2);
2146 f_sleep(2.0);
2147 setverdict(pass);
2148}
2149
Harald Weltee13cfb22019-04-23 16:52:02 +02002150/* Two BSSMAP resets from two different BSCs plus one IuCS RANAP Reset */
2151testcase TC_reset_two_1iu() runs on MTC_CT {
2152 var BSC_ConnHdlr vc_conn;
2153 f_init(3);
2154 f_sleep(2.0);
2155 setverdict(pass);
2156}
2157
Harald Weltef640a012018-04-14 17:49:21 +02002158/***********************************************************************
2159 * SMS Testing
2160 ***********************************************************************/
2161
Harald Weltef45efeb2018-04-09 18:19:24 +02002162/* LU followed by MO SMS */
Harald Weltee13cfb22019-04-23 16:52:02 +02002163friend function f_tc_lu_and_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02002164 var SmsParameters spars := valueof(t_SmsPars);
2165
2166 f_init_handler(pars);
2167
2168 /* Perform location update and call */
2169 f_perform_lu();
2170
2171 f_establish_fully(EST_TYPE_MO_SMS);
2172
2173 //spars.exp_rp_err := 96; /* invalid mandatory information */
2174 f_mo_sms(spars);
2175
2176 f_expect_clear();
2177}
2178testcase TC_lu_and_mo_sms() runs on MTC_CT {
2179 var BSC_ConnHdlr vc_conn;
2180 f_init();
2181 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_sms), 42);
2182 vc_conn.done;
2183}
2184
Harald Weltee13cfb22019-04-23 16:52:02 +02002185
Harald Weltef45efeb2018-04-09 18:19:24 +02002186private function f_vty_sms_send(charstring imsi, charstring msisdn, charstring text)
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002187runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02002188 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
2189}
2190
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01002191/* Remove still pending SMS */
2192private function f_vty_sms_clear(charstring imsi)
2193runs on BSC_ConnHdlr {
2194 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " sms delete-all");
2195 f_vty_transceive(MSCVTY, "sms-queue clear");
2196}
2197
Harald Weltef45efeb2018-04-09 18:19:24 +02002198/* LU followed by MT SMS */
Harald Weltee13cfb22019-04-23 16:52:02 +02002199friend function f_tc_lu_and_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02002200 var SmsParameters spars := valueof(t_SmsPars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002201
2202 f_init_handler(pars);
2203
2204 /* Perform location update and call */
2205 f_perform_lu();
2206
2207 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002208 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Weltef45efeb2018-04-09 18:19:24 +02002209
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002210 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
Harald Weltef45efeb2018-04-09 18:19:24 +02002211
2212 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02002213 f_expect_paging();
2214
Harald Weltef45efeb2018-04-09 18:19:24 +02002215 /* Establish DTAP / BSSAP / SCCP connection */
2216 f_establish_fully(EST_TYPE_PAG_RESP);
2217
2218 spars.tp.ud := 'C8329BFD064D9B53'O;
2219 f_mt_sms(spars);
2220
2221 f_expect_clear();
2222}
2223testcase TC_lu_and_mt_sms() runs on MTC_CT {
2224 var BSC_ConnHdlrPars pars;
2225 var BSC_ConnHdlr vc_conn;
2226 f_init();
2227 pars := f_init_pars(43);
2228 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms), pars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002229 vc_conn.done;
2230}
2231
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01002232/* SMS added while already Paging */
2233friend function f_tc_lu_and_mt_sms_already_paging(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2234 var SmsParameters spars := valueof(t_SmsPars);
2235 var OCT4 tmsi;
2236
2237 f_init_handler(pars);
2238
2239 f_perform_lu();
2240
2241 /* register an 'expect' for given IMSI (+TMSI) */
2242 if (isvalue(g_pars.tmsi)) {
2243 tmsi := g_pars.tmsi;
2244 } else {
2245 tmsi := 'FFFFFFFF'O;
2246 }
2247 f_ran_register_imsi(g_pars.imsi, tmsi);
2248
2249 log("first SMS");
2250 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2251
2252 /* MSC->BSC: expect PAGING from MSC */
2253 f_expect_paging();
2254
2255 log("second SMS");
2256 /* Now osmo-msc is in state "Paging pending", make sure that another SMS to be sent at this time just joins in
2257 * with the pending paging. Another SMS: */
2258 f_vty_sms_send(hex2str(pars.imsi), "2342", "Another SMS");
2259
2260 /* Establish DTAP / BSSAP / SCCP connection */
2261 f_establish_fully(EST_TYPE_PAG_RESP);
2262
2263 spars.tp.ud := 'C8329BFD064D9B53'O;
2264 f_mt_sms(spars);
2265
2266 spars.tp.ud := '41F79B8E2ECB41D3E614'O;
2267 f_mt_sms(spars);
2268
2269 f_expect_clear();
2270}
2271testcase TC_lu_and_mt_sms_already_paging() runs on MTC_CT {
2272 var BSC_ConnHdlrPars pars;
2273 var BSC_ConnHdlr vc_conn;
2274 f_init();
2275 pars := f_init_pars(44);
2276 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_already_paging), pars);
2277 vc_conn.done;
2278}
Harald Weltee13cfb22019-04-23 16:52:02 +02002279
Philipp Maier3983e702018-11-22 19:01:33 +01002280/* Paging for MT SMS but no response */
Harald Weltee13cfb22019-04-23 16:52:02 +02002281friend function f_tc_lu_and_mt_sms_paging_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier3983e702018-11-22 19:01:33 +01002282 var SmsParameters spars := valueof(t_SmsPars);
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002283
Philipp Maier3983e702018-11-22 19:01:33 +01002284 f_init_handler(pars, 150.0);
2285
2286 /* Perform location update */
2287 f_perform_lu();
2288
2289 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002290 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Philipp Maier3983e702018-11-22 19:01:33 +01002291
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002292 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2293
Neels Hofmeyr16237742019-03-06 15:34:01 +01002294 /* Expect the MSC to page exactly once */
Harald Weltee13cfb22019-04-23 16:52:02 +02002295 f_expect_paging();
Philipp Maier3983e702018-11-22 19:01:33 +01002296
2297 /* Wait some time to make sure the MSC is not delivering any further
2298 * paging messages or anything else that could be unexpected. */
2299 timer T := 20.0;
2300 T.start
2301 alt {
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002302 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
2303 setverdict(fail, "paging seems not to stop!");
2304 mtc.stop;
Philipp Maier3983e702018-11-22 19:01:33 +01002305 }
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002306 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
2307 setverdict(fail, "paging seems not to stop!");
2308 mtc.stop;
Harald Weltee13cfb22019-04-23 16:52:02 +02002309 }
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002310 [] BSSAP.receive {
2311 setverdict(fail, "unexpected BSSAP message received");
2312 self.stop;
Philipp Maier3983e702018-11-22 19:01:33 +01002313 }
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002314 [] T.timeout {
2315 setverdict(pass);
Philipp Maier3983e702018-11-22 19:01:33 +01002316 }
2317 }
2318
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01002319 f_vty_sms_clear(hex2str(g_pars.imsi));
2320
Philipp Maier3983e702018-11-22 19:01:33 +01002321 setverdict(pass);
2322}
2323testcase TC_lu_and_mt_sms_paging_and_nothing() runs on MTC_CT {
2324 var BSC_ConnHdlrPars pars;
2325 var BSC_ConnHdlr vc_conn;
2326 f_init();
Philipp Maiera99ad262019-01-22 15:35:42 +01002327 pars := f_init_pars(1843);
Philipp Maier3983e702018-11-22 19:01:33 +01002328 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_paging_and_nothing), pars);
Philipp Maier3983e702018-11-22 19:01:33 +01002329 vc_conn.done;
2330}
2331
Alexander Couzensfc02f242019-09-12 03:43:18 +02002332/* LU followed by MT SMS with repeated paging */
2333friend function f_tc_lu_and_mt_sms_paging_repeated(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2334 var SmsParameters spars := valueof(t_SmsPars);
Alexander Couzensfc02f242019-09-12 03:43:18 +02002335
2336 f_init_handler(pars);
2337
2338 /* Perform location update and call */
2339 f_perform_lu();
2340
2341 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002342 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Alexander Couzensfc02f242019-09-12 03:43:18 +02002343
2344 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2345
Neels Hofmeyrc3accec2019-11-28 01:09:47 +01002346 log("Expecting first Paging");
Alexander Couzensfc02f242019-09-12 03:43:18 +02002347 /* MSC->BSC: expect PAGING from MSC */
2348 f_expect_paging();
2349
Neels Hofmeyrc3accec2019-11-28 01:09:47 +01002350 if (g_pars.ran_is_geran) {
2351 log("GERAN: expect no further Paging");
2352 } else {
2353 log("UTRAN: expect more Paging");
2354 }
2355
2356 timer T := 5.0;
2357 T.start;
2358 alt {
2359 [g_pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
2360 setverdict(fail, "GERAN should not repeat Paging, but received a second Paging");
2361 mtc.stop;
2362 }
2363 [not g_pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
2364 log("UTRAN: second Paging received, as expected");
2365 setverdict(pass);
2366 }
2367 [] T.timeout {
2368 if (g_pars.ran_is_geran) {
2369 log("GERAN: No further Paging received, as expected");
2370 setverdict(pass);
2371 } else {
2372 setverdict(fail, "UTRAN: Expected a second Paging");
2373 mtc.stop;
2374 }
2375 }
2376 }
Alexander Couzensfc02f242019-09-12 03:43:18 +02002377
2378 /* Establish DTAP / BSSAP / SCCP connection */
2379 f_establish_fully(EST_TYPE_PAG_RESP);
2380
2381 spars.tp.ud := 'C8329BFD064D9B53'O;
2382 f_mt_sms(spars);
2383
2384 f_expect_clear();
2385}
2386testcase TC_lu_and_mt_sms_paging_repeated() runs on MTC_CT {
2387 var BSC_ConnHdlrPars pars;
2388 var BSC_ConnHdlr vc_conn;
2389 f_init();
2390 pars := f_init_pars(1844);
2391 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_paging_repeated), pars);
2392 vc_conn.done;
2393}
Harald Weltee13cfb22019-04-23 16:52:02 +02002394
Harald Weltef640a012018-04-14 17:49:21 +02002395/* mobile originated SMS from MS/BTS/BSC side to SMPP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002396friend function f_tc_smpp_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef640a012018-04-14 17:49:21 +02002397 var SmsParameters spars := valueof(t_SmsPars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002398
Harald Weltef640a012018-04-14 17:49:21 +02002399 f_init_handler(pars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002400
Harald Weltef640a012018-04-14 17:49:21 +02002401 /* Perform location update so IMSI is known + registered in MSC/VLR */
2402 f_perform_lu();
Harald Weltef640a012018-04-14 17:49:21 +02002403
Vadim Yanitskiy2d3f8462020-01-15 11:44:12 +07002404 /* MS/UE submits a MO SMS */
2405 f_establish_fully(EST_TYPE_MO_SMS);
2406 f_mo_sms_submit(spars);
Harald Weltef640a012018-04-14 17:49:21 +02002407
2408 var SMPP_PDU smpp;
2409 var template SMPP_PDU tr_smpp := tr_SMPP(c_SMPP_command_id_deliver_sm, ESME_ROK);
2410 tr_smpp.body.deliver_sm := {
2411 service_type := "CMT",
2412 source_addr_ton := network_specific,
2413 source_addr_npi := isdn,
2414 source_addr := hex2str(pars.msisdn),
2415 dest_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
2416 dest_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
2417 destination_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
2418 esm_class := '00000001'B,
2419 protocol_id := 0,
2420 priority_flag := 0,
2421 schedule_delivery_time := "",
2422 replace_if_present := 0,
2423 data_coding := '00000001'B,
2424 sm_default_msg_id := 0,
2425 sm_length := ?,
2426 short_message := spars.tp.ud,
2427 opt_pars := {
2428 {
2429 tag := user_message_reference,
2430 len := 2,
2431 opt_value := {
2432 int2_val := oct2int(spars.tp.msg_ref)
2433 }
2434 }
2435 }
2436 };
2437 alt {
2438 [] SMPP.receive(tr_smpp) -> value smpp {
2439 SMPP.send(ts_SMPP_DELIVER_SM_resp(ESME_ROK, smpp.header.seq_num));
2440 }
2441 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK)) { repeat; }
2442 }
2443
Vadim Yanitskiy2d3f8462020-01-15 11:44:12 +07002444 /* MSC terminates the SMS transaction with RP-ACK */
2445 f_mo_sms_wait_rp_ack(spars);
2446
Harald Weltef640a012018-04-14 17:49:21 +02002447 f_expect_clear();
2448}
2449testcase TC_smpp_mo_sms() runs on MTC_CT {
2450 var BSC_ConnHdlr vc_conn;
2451 f_init();
2452 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "default-route");
2453 vc_conn := f_start_handler(refers(f_tc_smpp_mo_sms), 44);
2454 vc_conn.done;
2455 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "no default-route");
2456}
2457
Vadim Yanitskiy33820762020-01-15 11:26:07 +07002458/* Test case for OS#4351: make sure that RP-ERROR from ESME is properly sent to the MS/UE */
2459friend function f_tc_smpp_mo_sms_rp_error(charstring id, BSC_ConnHdlrPars pars)
2460runs on BSC_ConnHdlr {
2461 var SmsParameters spars := valueof(t_SmsPars);
2462 var SMPP_PDU smpp_pdu;
2463 timer T := 3.0;
2464
2465 f_init_handler(pars);
2466
2467 /* Perform location update */
2468 f_perform_lu();
2469
2470 /* MS/UE submits a MO SMS */
2471 f_establish_fully(EST_TYPE_MO_SMS);
2472 f_mo_sms_submit(spars);
2473
2474 /* ESME responds with an error (Invalid Destination Address) */
2475 T.start;
2476 alt {
2477 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_deliver_sm, ESME_ROK, body := ?)) -> value smpp_pdu {
2478 SMPP.send(ts_SMPP_DELIVER_SM_resp(ESME_RINVDSTADR, smpp_pdu.header.seq_num));
2479 }
2480 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK)) { repeat; }
2481 [] T.timeout {
2482 setverdict(fail, "Timeout waiting for SMPP DELIVER-SM");
2483 mtc.stop;
2484 }
2485 }
2486
2487 /* Expect RP-ERROR on BSSAP interface */
2488 spars.exp_rp_err := 1; /* FIXME: GSM411_RP_CAUSE_MO_NUM_UNASSIGNED */
2489 f_mo_sms_wait_rp_ack(spars);
2490
2491 f_expect_clear();
2492}
2493testcase TC_smpp_mo_sms_rp_error() runs on MTC_CT {
2494 var BSC_ConnHdlr vc_conn;
2495 f_init();
2496 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "default-route");
2497 vc_conn := f_start_handler(refers(f_tc_smpp_mo_sms_rp_error), 45);
2498 vc_conn.done;
2499 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "no default-route");
2500}
2501
Harald Weltee13cfb22019-04-23 16:52:02 +02002502
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002503/* Test MO-SMS from MS/BTS/BSC towards HLR (via GSUP) */
Harald Weltee13cfb22019-04-23 16:52:02 +02002504friend function f_tc_gsup_mo_sms(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002505runs on BSC_ConnHdlr {
2506 var SmsParameters spars := valueof(t_SmsPars);
2507 var GSUP_PDU gsup_msg_rx;
2508 var octetstring sm_tpdu;
2509
2510 f_init_handler(pars);
2511
2512 /* We need to inspect GSUP activity */
2513 f_create_gsup_expect(hex2str(g_pars.imsi));
2514
2515 /* Perform location update */
2516 f_perform_lu();
2517
2518 /* Send CM Service Request for SMS */
2519 f_establish_fully(EST_TYPE_MO_SMS);
2520
2521 /* Prepare expected SM-RP-UI (SM TPDU) */
2522 enc_TPDU_RP_DATA_MS_SGSN_fast(
2523 valueof(ts_SMS_SUBMIT(spars.tp.msg_ref,
2524 spars.tp.da, spars.tp.pid, spars.tp.dcs,
2525 spars.tp.udl, spars.tp.ud)),
2526 sm_tpdu);
2527
2528 var template GSUP_PDU mo_forwardSM := tr_GSUP_MO_FORWARD_SM_REQ(
2529 imsi := g_pars.imsi,
2530 sm_rp_mr := spars.rp.msg_ref,
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09002531 /* SM-RP-DA: SMSC address */
2532 sm_rp_da := tr_GSUP_SM_RP_DA_SMSC_ADDR(t_GSUP_SM_RP_Addr(
2533 number := spars.rp.smsc_addr.rP_NumberDigits,
2534 npi := spars.rp.smsc_addr.rP_NumberingPlanIdentification,
2535 ton := spars.rp.smsc_addr.rP_TypeOfNumber,
2536 ext := spars.rp.smsc_addr.rP_Ext)),
2537 /* SM-RP-OA: subscriber's MSISDN (filled in by MSC) */
2538 sm_rp_oa := tr_GSUP_SM_RP_OA_MSISDN(t_GSUP_SM_RP_Addr(
2539 number := g_pars.msisdn,
2540 /* NOTE: MSISDN in g_pars lacks this info, assuming defaults */
2541 npi := '0001'B, ton := '001'B, ext := '1'B)),
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002542 /* TODO: can we use decmatch here? */
2543 sm_rp_ui := sm_tpdu
2544 );
2545
2546 /* Submit an SMS on DTAP and expect MO-forwardSM-Req on GSUP */
2547 f_mo_sms_submit(spars);
2548 alt {
2549 [] GSUP.receive(mo_forwardSM) -> value gsup_msg_rx {
Vadim Yanitskiya358dd42020-01-15 10:42:47 +07002550 log("RX MO-forwardSM-Req: ", gsup_msg_rx);
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002551 setverdict(pass);
2552 }
2553 [] GSUP.receive {
2554 log("RX unexpected GSUP message");
2555 setverdict(fail);
2556 mtc.stop;
2557 }
2558 }
2559
2560 /* Trigger RP-ACK by sending MO-forwardSM-Res */
2561 GSUP.send(valueof(ts_GSUP_MO_FORWARD_SM_RES(
2562 imsi := g_pars.imsi,
2563 sm_rp_mr := spars.rp.msg_ref)));
2564 /* Expect RP-ACK on DTAP */
2565 f_mo_sms_wait_rp_ack(spars);
2566
2567 f_expect_clear();
2568}
2569testcase TC_gsup_mo_sms() runs on MTC_CT {
2570 var BSC_ConnHdlr vc_conn;
2571 f_init();
2572 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2573 vc_conn := f_start_handler(refers(f_tc_gsup_mo_sms), 88);
2574 vc_conn.done;
2575 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2576}
2577
Harald Weltee13cfb22019-04-23 16:52:02 +02002578
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002579/* Test MO-SMMA from MS/BTS/BSC towards HLR (via GSUP) */
Harald Weltee13cfb22019-04-23 16:52:02 +02002580friend function f_tc_gsup_mo_smma(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002581runs on BSC_ConnHdlr {
2582 var SmsParameters spars := valueof(t_SmsPars);
2583 var GSUP_PDU gsup_msg_rx;
2584
2585 f_init_handler(pars);
2586
2587 /* We need to inspect GSUP activity */
2588 f_create_gsup_expect(hex2str(g_pars.imsi));
2589
2590 /* Perform location update */
2591 f_perform_lu();
2592
2593 /* Send CM Service Request for SMS */
2594 f_establish_fully(EST_TYPE_MO_SMS);
2595
2596 var template GSUP_PDU mo_ReadyForSM := tr_GSUP_MO_READY_FOR_SM_REQ(
2597 imsi := g_pars.imsi,
2598 sm_rp_mr := spars.rp.msg_ref,
2599 sm_alert_rsn := GSUP_SM_ALERT_RSN_TYPE_MEM_AVAIL
2600 );
2601
2602 /* Submit an SMS on DTAP and expect MO-forwardSM-Req on GSUP */
2603 f_mo_smma(spars);
2604 alt {
2605 [] GSUP.receive(mo_ReadyForSM) -> value gsup_msg_rx {
Vadim Yanitskiya358dd42020-01-15 10:42:47 +07002606 log("RX MO-ReadyForSM-Req: ", gsup_msg_rx);
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002607 setverdict(pass);
2608 }
2609 [] GSUP.receive {
2610 log("RX unexpected GSUP message");
2611 setverdict(fail);
2612 mtc.stop;
2613 }
2614 }
2615
2616 /* Trigger RP-ACK by sending MO-forwardSM-Res */
2617 GSUP.send(valueof(ts_GSUP_MO_READY_FOR_SM_RES(
2618 imsi := g_pars.imsi,
2619 sm_rp_mr := spars.rp.msg_ref)));
2620 /* Expect RP-ACK on DTAP */
2621 f_mo_sms_wait_rp_ack(spars);
2622
2623 f_expect_clear();
2624}
2625testcase TC_gsup_mo_smma() runs on MTC_CT {
2626 var BSC_ConnHdlr vc_conn;
2627 f_init();
2628 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2629 vc_conn := f_start_handler(refers(f_tc_gsup_mo_smma), 89);
2630 vc_conn.done;
2631 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2632}
2633
Harald Weltee13cfb22019-04-23 16:52:02 +02002634
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002635/* Helper for sending MT SMS over GSUP */
2636private function f_gsup_forwardSM_req(SmsParameters spars, OCT1 mms := '00'O)
2637runs on BSC_ConnHdlr {
Vadim Yanitskiya52347c2019-12-12 17:32:33 +09002638 var GSUP_SM_RP_Addr msisdn := valueof(t_GSUP_SM_RP_Addr(g_pars.msisdn));
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09002639 var GSUP_SM_RP_Addr smsc := valueof(t_GSUP_SM_RP_Addr(
2640 number := spars.rp.smsc_addr.rP_NumberDigits,
2641 npi := spars.rp.smsc_addr.rP_NumberingPlanIdentification,
2642 ton := spars.rp.smsc_addr.rP_TypeOfNumber,
2643 ext := spars.rp.smsc_addr.rP_Ext));
Vadim Yanitskiya52347c2019-12-12 17:32:33 +09002644
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002645 GSUP.send(ts_GSUP_MT_FORWARD_SM_REQ(
2646 imsi := g_pars.imsi,
2647 /* NOTE: MSC should assign RP-MR itself */
2648 sm_rp_mr := 'FF'O,
Vadim Yanitskiya52347c2019-12-12 17:32:33 +09002649 sm_rp_da := valueof(ts_GSUP_SM_RP_DA_MSISDN(msisdn)),
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09002650 sm_rp_oa := valueof(ts_GSUP_SM_RP_OA_SMSC_ADDR(smsc)),
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002651 /* Encoded SMS TPDU (taken from Wireshark)
2652 * FIXME: we should encode spars somehow */
2653 sm_rp_ui := '00068021436500008111328130858200'O,
2654 sm_rp_mms := mms
2655 ));
2656}
2657
2658/* Test successful MT-SMS (RP-ACK) over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002659friend function f_tc_gsup_mt_sms_ack(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002660runs on BSC_ConnHdlr {
2661 var SmsParameters spars := valueof(t_SmsPars);
2662
2663 f_init_handler(pars);
2664
2665 /* We need to inspect GSUP activity */
2666 f_create_gsup_expect(hex2str(g_pars.imsi));
2667
2668 /* Perform location update */
2669 f_perform_lu();
2670
2671 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002672 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002673
2674 var template GSUP_PDU mt_forwardSM_res := tr_GSUP_MT_FORWARD_SM_RES(
2675 imsi := g_pars.imsi,
2676 /* NOTE: MSC should assign RP-MR itself */
2677 sm_rp_mr := ?
2678 );
2679
2680 /* Submit a MT SMS on GSUP */
2681 f_gsup_forwardSM_req(spars);
2682
2683 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002684 f_expect_paging();
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002685 f_establish_fully(EST_TYPE_PAG_RESP);
2686
2687 /* Wait for MT SMS on DTAP */
2688 f_mt_sms_expect(spars);
2689
2690 /* Send RP-ACK and expect MT-forwardSM-Res on GSUP */
2691 f_mt_sms_send_rp_ack(spars);
2692 alt {
2693 [] GSUP.receive(mt_forwardSM_res) {
2694 log("RX MT-forwardSM-Res (RP-ACK)");
2695 setverdict(pass);
2696 }
2697 [] GSUP.receive {
2698 log("RX unexpected GSUP message");
2699 setverdict(fail);
2700 mtc.stop;
2701 }
2702 }
2703
2704 f_expect_clear();
2705}
2706testcase TC_gsup_mt_sms_ack() runs on MTC_CT {
2707 var BSC_ConnHdlrPars pars;
2708 var BSC_ConnHdlr vc_conn;
2709 f_init();
2710 pars := f_init_pars(90);
2711 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2712 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_ack), pars);
2713 vc_conn.done;
2714 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2715}
2716
Harald Weltee13cfb22019-04-23 16:52:02 +02002717
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002718/* Test rejected MT-SMS (RP-ERROR) over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002719friend function f_tc_gsup_mt_sms_err(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002720runs on BSC_ConnHdlr {
2721 var SmsParameters spars := valueof(t_SmsPars);
2722 var OCT1 sm_rp_cause := '78'O; /* dummy RP-Cause value */
2723
2724 f_init_handler(pars);
2725
2726 /* We need to inspect GSUP activity */
2727 f_create_gsup_expect(hex2str(g_pars.imsi));
2728
2729 /* Perform location update */
2730 f_perform_lu();
2731
2732 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002733 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002734
2735 var template GSUP_PDU mt_forwardSM_err := tr_GSUP_MT_FORWARD_SM_ERR(
2736 imsi := g_pars.imsi,
2737 /* NOTE: MSC should assign RP-MR itself */
2738 sm_rp_mr := ?,
2739 sm_rp_cause := sm_rp_cause
2740 );
2741
2742 /* Submit a MT SMS on GSUP */
2743 f_gsup_forwardSM_req(spars);
2744
2745 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002746 f_expect_paging();
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002747 f_establish_fully(EST_TYPE_PAG_RESP);
2748
2749 /* Wait for MT SMS on DTAP */
2750 f_mt_sms_expect(spars);
2751
2752 /* Send RP-ERROR and expect MT-forwardSM-Err on GSUP */
2753 f_mt_sms_send_rp_error(spars, oct2int(sm_rp_cause));
2754 alt {
2755 [] GSUP.receive(mt_forwardSM_err) {
2756 log("RX MT-forwardSM-Err (RP-ERROR)");
2757 setverdict(pass);
2758 mtc.stop;
2759 }
2760 [] GSUP.receive {
2761 log("RX unexpected GSUP message");
2762 setverdict(fail);
2763 mtc.stop;
2764 }
2765 }
2766
2767 f_expect_clear();
2768}
2769testcase TC_gsup_mt_sms_err() runs on MTC_CT {
2770 var BSC_ConnHdlrPars pars;
2771 var BSC_ConnHdlr vc_conn;
2772 f_init();
2773 pars := f_init_pars(91);
2774 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2775 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_err), pars);
2776 vc_conn.done;
2777 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2778}
2779
Harald Weltee13cfb22019-04-23 16:52:02 +02002780
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002781/* Test SM-RP-MR assignment for MT-SMS over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002782friend function f_tc_gsup_mt_sms_rp_mr(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002783runs on BSC_ConnHdlr {
2784 var SmsParameters spars1 := valueof(t_SmsPars); /* 1st SMS */
2785 var SmsParameters spars2 := valueof(t_SmsPars); /* 2nd SMS */
2786
2787 f_init_handler(pars);
2788
2789 /* We need to inspect GSUP activity */
2790 f_create_gsup_expect(hex2str(g_pars.imsi));
2791
2792 /* Perform location update */
2793 f_perform_lu();
2794
2795 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002796 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002797
2798 /* Submit the 1st MT SMS on GSUP */
2799 log("TX MT-forwardSM-Req for the 1st SMS");
2800 f_gsup_forwardSM_req(spars1);
2801
2802 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002803 f_expect_paging();
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002804 f_establish_fully(EST_TYPE_PAG_RESP);
2805
2806 /* Wait for 1st MT SMS on DTAP */
2807 f_mt_sms_expect(spars1);
2808 log("RX the 1st SMS on DTAP, DTAP TID is ", spars1.tid,
2809 ", SM-RP-MR is ", spars1.rp.msg_ref);
2810
2811 /* Submit the 2nd MT SMS on GSUP */
2812 log("TX MT-forwardSM-Req for the 2nd SMS");
2813 f_gsup_forwardSM_req(spars2);
2814
2815 /* Wait for 2nd MT SMS on DTAP */
2816 f_mt_sms_expect(spars2);
2817 log("RX the 2nd SMS on DTAP, DTAP TID is ", spars2.tid,
2818 ", SM-RP-MR is ", spars2.rp.msg_ref);
2819
2820 /* Both transaction IDs shall be different */
2821 if (spars1.tid == spars2.tid) {
2822 log("Both DTAP transaction IDs shall be different");
2823 setverdict(fail);
2824 }
2825
2826 /* Both SM-RP-MR values shall be different */
2827 if (spars1.rp.msg_ref == spars2.rp.msg_ref) {
2828 log("Both SM-RP-MR values shall be different");
2829 setverdict(fail);
2830 }
2831
2832 /* Both SM-RP-MR values shall be assigned */
2833 if (spars1.rp.msg_ref == 'FF'O) {
2834 log("Unassigned SM-RP-MR value for the 1st SMS");
2835 setverdict(fail);
2836 }
2837 if (spars2.rp.msg_ref == 'FF'O) {
2838 log("Unassigned SM-RP-MR value for the 2nd SMS");
2839 setverdict(fail);
2840 }
2841
2842 /* Send the 1st RP-ACK and expect MT-forwardSM-Res on GSUP */
2843 f_mt_sms_send_rp_ack(spars1);
2844 alt {
2845 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2846 imsi := g_pars.imsi,
2847 sm_rp_mr := spars1.rp.msg_ref
2848 )) {
2849 log("RX MT-forwardSM-Res (RP-ACK)");
2850 setverdict(pass);
2851 }
2852 [] GSUP.receive {
2853 log("RX unexpected GSUP message");
2854 setverdict(fail);
2855 mtc.stop;
2856 }
2857 }
2858
2859 /* Send the 2nd RP-ACK and expect MT-forwardSM-Res on GSUP */
2860 f_mt_sms_send_rp_ack(spars2);
2861 alt {
2862 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2863 imsi := g_pars.imsi,
2864 sm_rp_mr := spars2.rp.msg_ref
2865 )) {
2866 log("RX MT-forwardSM-Res (RP-ACK)");
2867 setverdict(pass);
2868 }
2869 [] GSUP.receive {
2870 log("RX unexpected GSUP message");
2871 setverdict(fail);
2872 mtc.stop;
2873 }
2874 }
2875
2876 f_expect_clear();
2877}
2878testcase TC_gsup_mt_sms_rp_mr() runs on MTC_CT {
2879 var BSC_ConnHdlrPars pars;
2880 var BSC_ConnHdlr vc_conn;
2881 f_init();
2882 pars := f_init_pars(92);
2883 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2884 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_rp_mr), pars);
2885 vc_conn.done;
2886 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2887}
2888
Harald Weltee13cfb22019-04-23 16:52:02 +02002889
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07002890/* Test SM-RP-MR assignment for MT-SMS over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002891friend function f_tc_gsup_mo_mt_sms_rp_mr(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07002892runs on BSC_ConnHdlr {
2893 var SmsParameters spars_mo := valueof(t_SmsPars); /* MO SMMA */
2894 var SmsParameters spars_mt := valueof(t_SmsPars); /* MT SMS */
2895
2896 f_init_handler(pars);
2897
2898 /* We need to inspect GSUP activity */
2899 f_create_gsup_expect(hex2str(g_pars.imsi));
2900
2901 /* Perform location update */
2902 f_perform_lu();
2903
2904 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002905 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07002906
2907 /* Send CM Service Request for MO SMMA */
2908 f_establish_fully(EST_TYPE_MO_SMS);
2909
2910 /* Submit MO SMMA on DTAP */
2911 log("Submit MO SMMA on DTAP, SM-RP-MR is '00'O");
2912 spars_mo.rp.msg_ref := '00'O;
2913 f_mo_smma(spars_mo);
2914
2915 /* Expect MO-forwardSM-Req for MO SMMA on GSUP */
2916 alt {
2917 [] GSUP.receive(tr_GSUP_MO_READY_FOR_SM_REQ(
2918 imsi := g_pars.imsi,
2919 sm_rp_mr := spars_mo.rp.msg_ref,
2920 sm_alert_rsn := GSUP_SM_ALERT_RSN_TYPE_MEM_AVAIL
2921 )) {
2922 log("RX MO-ReadyForSM-Req, SM-RP-MR is '00'O");
2923 setverdict(pass);
2924 }
2925 [] GSUP.receive {
2926 log("RX unexpected GSUP message");
2927 setverdict(fail);
2928 mtc.stop;
2929 }
2930 }
2931
2932 /* Submit MT SMS on GSUP */
2933 log("TX MT-forwardSM-Req for the MT SMS");
2934 f_gsup_forwardSM_req(spars_mt);
2935
2936 /* Wait for MT SMS on DTAP */
2937 f_mt_sms_expect(spars_mt);
2938 log("RX MT SMS on DTAP, DTAP TID is ", spars_mt.tid,
2939 ", SM-RP-MR is ", spars_mt.rp.msg_ref);
2940
2941 /* Both SM-RP-MR values shall be different */
2942 if (spars_mo.rp.msg_ref == spars_mt.rp.msg_ref) {
2943 log("Both SM-RP-MR values shall be different");
2944 setverdict(fail);
2945 }
2946
2947 /* SM-RP-MR value for MT SMS shall be assigned */
2948 if (spars_mt.rp.msg_ref == 'FF'O) {
2949 log("Unassigned SM-RP-MR value for the MT SMS");
2950 setverdict(fail);
2951 }
2952
2953 /* Trigger RP-ACK for MO SMMA by sending MO-forwardSM-Res */
2954 GSUP.send(valueof(ts_GSUP_MO_READY_FOR_SM_RES(
2955 imsi := g_pars.imsi,
2956 sm_rp_mr := spars_mo.rp.msg_ref)));
2957 /* Expect RP-ACK for MO SMMA on DTAP */
2958 f_mo_sms_wait_rp_ack(spars_mo);
2959
2960 /* Send RP-ACK for MT SMS and expect MT-forwardSM-Res on GSUP */
2961 f_mt_sms_send_rp_ack(spars_mt);
2962 alt {
2963 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2964 imsi := g_pars.imsi,
2965 sm_rp_mr := spars_mt.rp.msg_ref
2966 )) {
2967 log("RX MT-forwardSM-Res (RP-ACK)");
2968 setverdict(pass);
2969 }
2970 [] GSUP.receive {
2971 log("RX unexpected GSUP message");
2972 setverdict(fail);
2973 mtc.stop;
2974 }
2975 }
2976
2977 f_expect_clear();
2978}
2979testcase TC_gsup_mo_mt_sms_rp_mr() runs on MTC_CT {
2980 var BSC_ConnHdlrPars pars;
2981 var BSC_ConnHdlr vc_conn;
2982 f_init();
2983 pars := f_init_pars(93);
2984 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2985 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mo_mt_sms_rp_mr), pars);
2986 vc_conn.done;
2987 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2988}
2989
Harald Weltee13cfb22019-04-23 16:52:02 +02002990
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07002991/* Test multi-part MT-SMS over GSUP */
2992private function f_tc_gsup_mt_multi_part_sms(charstring id, BSC_ConnHdlrPars pars)
2993runs on BSC_ConnHdlr {
2994 var SmsParameters spars := valueof(t_SmsPars);
2995
2996 f_init_handler(pars);
2997
2998 /* We need to inspect GSUP activity */
2999 f_create_gsup_expect(hex2str(g_pars.imsi));
3000
3001 /* Perform location update */
3002 f_perform_lu();
3003
3004 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01003005 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07003006
3007 var template GSUP_PDU mt_forwardSM_res := tr_GSUP_MT_FORWARD_SM_RES(
3008 imsi := g_pars.imsi,
3009 /* NOTE: MSC should assign RP-MR itself */
3010 sm_rp_mr := ?
3011 );
3012
3013 /* Send 4 messages (NOTE: SM-RP-UI remains unchanged) */
3014 for (var integer i := 3; i >= 0; i := i-1) {
3015 /* Submit a MT SMS on GSUP (MMS is decremented) */
3016 f_gsup_forwardSM_req(spars, int2oct(i, 1));
3017
3018 /* Expect Paging Request and Establish connection */
3019 if (i == 3) { /* ... only once! */
Harald Weltee13cfb22019-04-23 16:52:02 +02003020 f_expect_paging();
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07003021 f_establish_fully(EST_TYPE_PAG_RESP);
3022 }
3023
3024 /* Wait for MT SMS on DTAP */
3025 f_mt_sms_expect(spars);
3026
3027 /* Send RP-ACK and expect MT-forwardSM-Res on GSUP */
3028 f_mt_sms_send_rp_ack(spars);
3029 alt {
3030 [] GSUP.receive(mt_forwardSM_res) {
3031 log("RX MT-forwardSM-Res (RP-ACK)");
3032 setverdict(pass);
3033 }
3034 [] GSUP.receive {
3035 log("RX unexpected GSUP message");
3036 setverdict(fail);
3037 mtc.stop;
3038 }
3039 }
3040
3041 /* Keep some 'distance' between transmissions */
3042 f_sleep(1.5);
3043 }
3044
3045 f_expect_clear();
3046}
3047testcase TC_gsup_mt_multi_part_sms() runs on MTC_CT {
3048 var BSC_ConnHdlrPars pars;
3049 var BSC_ConnHdlr vc_conn;
3050 f_init();
3051 pars := f_init_pars(91);
3052 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
3053 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_multi_part_sms), pars);
3054 vc_conn.done;
3055 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
3056}
3057
Harald Weltef640a012018-04-14 17:49:21 +02003058/* convert GSM L3 TON to SMPP_TON enum */
3059function f_sm_ton_from_gsm(BIT3 ton) return SMPP_TON {
3060 select (ton) {
3061 case ('000'B) { return unknown; }
3062 case ('001'B) { return international; }
3063 case ('010'B) { return national; }
3064 case ('011'B) { return network_specific; }
3065 case ('100'B) { return subscriber_number; }
3066 case ('101'B) { return alphanumeric; }
3067 case ('110'B) { return abbreviated; }
3068 }
3069 setverdict(fail, "Unknown TON ", ton);
Daniel Willmannafce8662018-07-06 23:11:32 +02003070 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02003071}
3072/* convert GSM L3 NPI to SMPP_NPI enum */
3073function f_sm_npi_from_gsm(BIT4 npi) return SMPP_NPI {
3074 select (npi) {
3075 case ('0000'B) { return unknown; }
3076 case ('0001'B) { return isdn; }
3077 case ('0011'B) { return data; }
3078 case ('0100'B) { return telex; }
3079 case ('0110'B) { return land_mobile; }
3080 case ('1000'B) { return national; }
3081 case ('1001'B) { return private_; }
3082 case ('1010'B) { return ermes; }
3083 }
3084 setverdict(fail, "Unknown NPI ", npi);
Daniel Willmannafce8662018-07-06 23:11:32 +02003085 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02003086}
3087
3088/* build a SMPP_SM from SmsParameters */
3089function f_mt_sm_from_spars(SmsParameters spars)
3090runs on BSC_ConnHdlr return SMPP_SM {
3091 var SMPP_SM sm := {
3092 service_type := "CMT",
3093 source_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
3094 source_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
3095 source_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
3096 dest_addr_ton := international,
3097 dest_addr_npi := isdn,
3098 destination_addr := hex2str(g_pars.msisdn),
3099 esm_class := '00000001'B,
3100 protocol_id := 0,
3101 priority_flag := 0,
3102 schedule_delivery_time := "",
3103 validity_period := "",
3104 registered_delivery := '00000000'B,
3105 replace_if_present := 0,
3106 data_coding := '00000001'B,
3107 sm_default_msg_id := 0,
3108 sm_length := spars.tp.udl,
3109 short_message := spars.tp.ud,
3110 opt_pars := {}
3111 };
3112 return sm;
3113}
3114
3115/* helper function to encode SMS from 'spars', send it via SMPP to MSC; receive it on MS side */
3116private function f_smpp_mt_sms(SmsParameters spars, boolean trans_mode) runs on BSC_ConnHdlr {
3117 var SMPP_SM sm := f_mt_sm_from_spars(spars);
3118 if (trans_mode) {
3119 sm.esm_class := '00000010'B;
3120 }
3121
3122 /* actually cause MSC to send a SMS via SUBMIT-SM from SMPP side */
3123 SMPP.send(ts_SMPP_SUBMIT_SM(sm));
3124 if (not match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
3125 /* if we're not in SMPP transaction mode, we expect the SMPP-level ACK
3126 * before we expect the SMS delivery on the BSC/radio side */
3127 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
3128 }
3129
3130 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02003131 f_expect_paging();
Harald Weltef640a012018-04-14 17:49:21 +02003132 /* Establish DTAP / BSSAP / SCCP connection */
3133 f_establish_fully(EST_TYPE_PAG_RESP);
3134 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
3135
3136 f_mt_sms(spars);
3137
3138 if (match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
3139 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
3140 }
3141 f_expect_clear();
3142}
3143
3144/* mobile terminated SMS, from SMPP to BSC/BTS/MS */
3145private function f_tc_smpp_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3146 f_init_handler(pars);
3147
3148 /* Perform location update so IMSI is known + registered in MSC/VLR */
3149 f_perform_lu();
3150 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
3151
3152 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01003153 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Weltef640a012018-04-14 17:49:21 +02003154
3155 var SmsParameters spars := valueof(t_SmsPars);
3156 /* TODO: test with more intelligent user data; test different coding schemes */
3157 spars.tp.ud := '00'O;
3158 spars.tp.udl := 1;
3159
3160 /* first test the non-transaction store+forward mode */
3161 f_smpp_mt_sms(spars, false);
3162
3163 /* then test the transaction mode */
3164 f_smpp_mt_sms(spars, true);
3165}
3166testcase TC_smpp_mt_sms() runs on MTC_CT {
3167 var BSC_ConnHdlr vc_conn;
3168 f_init();
3169 vc_conn := f_start_handler(refers(f_tc_smpp_mt_sms), 45);
3170 vc_conn.done;
3171}
3172
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003173/***********************************************************************
3174 * USSD Testing
3175 ***********************************************************************/
3176
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003177private altstep as_unexp_gsup_or_bssap_msg()
3178runs on BSC_ConnHdlr {
3179 [] GSUP.receive {
3180 setverdict(fail, "Unknown/unexpected GSUP received");
3181 self.stop;
3182 }
3183 [] BSSAP.receive {
3184 setverdict(fail, "Unknown/unexpected BSSAP message received");
3185 self.stop;
3186 }
3187}
3188
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003189private function f_expect_gsup_msg(template GSUP_PDU msg,
3190 float T_val := 2.0)
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003191runs on BSC_ConnHdlr return GSUP_PDU {
3192 var GSUP_PDU gsup_msg_complete;
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003193 timer T := T_val;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003194
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003195 T.start;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003196 alt {
3197 [] GSUP.receive(msg) -> value gsup_msg_complete {
3198 setverdict(pass);
3199 }
3200 /* We don't expect anything else */
3201 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003202 [] T.timeout {
3203 setverdict(fail, "Timeout waiting for GSUP message: ", msg);
3204 }
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003205 }
3206
3207 return gsup_msg_complete;
3208}
3209
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003210private function f_expect_mt_dtap_msg(template PDU_ML3_NW_MS msg,
3211 float T_val := 2.0)
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003212runs on BSC_ConnHdlr return PDU_ML3_NW_MS {
3213 var PDU_DTAP_MT bssap_msg_complete;
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003214 timer T := T_val;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003215
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003216 T.start;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003217 alt {
3218 [] BSSAP.receive(tr_PDU_DTAP_MT(msg)) -> value bssap_msg_complete {
3219 setverdict(pass);
3220 }
3221 /* We don't expect anything else */
3222 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003223 [] T.timeout {
3224 setverdict(fail, "Timeout waiting for BSSAP message: ", msg);
3225 }
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003226 }
3227
3228 return bssap_msg_complete.dtap;
3229}
3230
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003231/* LU followed by MO USSD request */
Harald Weltee13cfb22019-04-23 16:52:02 +02003232friend function f_tc_lu_and_mo_ussd_single_request(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003233runs on BSC_ConnHdlr {
3234 f_init_handler(pars);
3235
3236 /* Perform location update */
3237 f_perform_lu();
3238
3239 /* Send CM Service Request for SS/USSD */
3240 f_establish_fully(EST_TYPE_SS_ACT);
3241
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003242 /* We need to inspect GSUP activity */
3243 f_create_gsup_expect(hex2str(g_pars.imsi));
3244
3245 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3246 invoke_id := 5, /* Phone may not start from 0 or 1 */
3247 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3248 ussd_string := "*#100#"
3249 );
3250
3251 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3252 invoke_id := 5, /* InvokeID shall be the same for both REQ and RSP */
3253 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3254 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
3255 )
3256
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003257 /* Compose a new SS/REGISTER message with request */
3258 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
3259 tid := 1, /* We just need a single transaction */
3260 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003261 facility := valueof(facility_req)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003262 );
3263
3264 /* Compose SS/RELEASE_COMPLETE template with expected response */
3265 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
3266 tid := 1, /* Response should arrive within the same transaction */
3267 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003268 facility := valueof(facility_rsp)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003269 );
3270
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003271 /* Compose expected MSC -> HLR message */
3272 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
3273 imsi := g_pars.imsi,
3274 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3275 ss := valueof(facility_req)
3276 );
3277
3278 /* To be used for sending response with correct session ID */
3279 var GSUP_PDU gsup_req_complete;
3280
3281 /* Request own number */
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003282 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003283 /* Expect GSUP message containing the SS payload */
3284 gsup_req_complete := f_expect_gsup_msg(gsup_req);
3285
3286 /* Compose the response from HLR using received session ID */
3287 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
3288 imsi := g_pars.imsi,
3289 sid := gsup_req_complete.ies[1].val.session_id,
3290 state := OSMO_GSUP_SESSION_STATE_END,
3291 ss := valueof(facility_rsp)
3292 );
3293
3294 /* Finally, HLR terminates the session */
3295 GSUP.send(gsup_rsp);
3296 /* Expect RELEASE_COMPLETE message with the response */
3297 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003298
3299 f_expect_clear();
3300}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003301testcase TC_lu_and_mo_ussd_single_request() runs on MTC_CT {
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003302 var BSC_ConnHdlr vc_conn;
3303 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003304 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_single_request), 46);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003305 vc_conn.done;
3306}
3307
Harald Weltee13cfb22019-04-23 16:52:02 +02003308
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003309/* LU followed by MT USSD notification */
Harald Weltee13cfb22019-04-23 16:52:02 +02003310friend function f_tc_lu_and_mt_ussd_notification(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003311runs on BSC_ConnHdlr {
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003312 timer T := 5.0;
3313
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003314 f_init_handler(pars);
3315
3316 /* Perform location update */
3317 f_perform_lu();
3318
Harald Welte6811d102019-04-14 22:23:14 +02003319 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003320
3321 /* We need to inspect GSUP activity */
3322 f_create_gsup_expect(hex2str(g_pars.imsi));
3323
3324 /* Facility IE with network-originated USSD notification */
3325 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3326 op_code := SS_OP_CODE_USS_NOTIFY,
3327 ussd_string := "Mahlzeit!"
3328 );
3329
3330 /* Facility IE with acknowledgment to the USSD notification */
3331 var template OCTN facility_rsp := enc_SS_FacilityInformation(
3332 /* In case of USSD notification, Return Result is empty */
3333 valueof(ts_SS_USSD_FACILITY_RETURN_RESULT_EMPTY())
3334 );
3335
3336 /* Compose a new MT SS/REGISTER message with USSD notification */
3337 var template PDU_ML3_NW_MS ussd_ntf := tr_ML3_MT_SS_REGISTER(
3338 tid := 0, /* FIXME: most likely, it should be 0 */
3339 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3340 facility := valueof(facility_req)
3341 );
3342
3343 /* Compose HLR -> MSC GSUP message */
3344 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3345 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003346 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003347 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3348 ss := valueof(facility_req)
3349 );
3350
3351 /* Send it to MSC and expect Paging Request */
3352 GSUP.send(gsup_req);
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003353 T.start;
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003354 alt {
Harald Weltee13cfb22019-04-23 16:52:02 +02003355 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
3356 setverdict(pass);
3357 }
Harald Welte62113fc2019-05-09 13:04:02 +02003358 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003359 setverdict(pass);
3360 }
3361 /* We don't expect anything else */
3362 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003363 [] T.timeout {
3364 setverdict(fail, "Timeout waiting for Paging Request");
3365 }
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003366 }
3367
3368 /* Send Paging Response and expect USSD notification */
3369 f_establish_fully(EST_TYPE_PAG_RESP);
3370 /* Expect MT REGISTER message with USSD notification */
3371 f_expect_mt_dtap_msg(ussd_ntf);
3372
3373 /* Compose a new MO SS/FACILITY message with empty response */
3374 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
3375 tid := 0, /* FIXME: it shall match the request tid */
3376 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3377 facility := valueof(facility_rsp)
3378 );
3379
3380 /* Compose expected MSC -> HLR GSUP message */
3381 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
3382 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003383 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003384 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3385 ss := valueof(facility_rsp)
3386 );
3387
3388 /* MS sends response to the notification */
3389 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
3390 /* Expect GSUP message containing the SS payload */
3391 f_expect_gsup_msg(gsup_rsp);
3392
3393 /* Compose expected MT SS/RELEASE COMPLETE message */
3394 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
3395 tid := 0, /* FIXME: it shall match the request tid */
3396 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3397 facility := omit
3398 );
3399
3400 /* Compose MSC -> HLR GSUP message */
3401 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
3402 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003403 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003404 state := OSMO_GSUP_SESSION_STATE_END
3405 );
3406
3407 /* Finally, HLR terminates the session */
3408 GSUP.send(gsup_term)
3409 /* Expect MT RELEASE COMPLETE without Facility IE */
3410 f_expect_mt_dtap_msg(ussd_term);
3411
3412 f_expect_clear();
3413}
3414testcase TC_lu_and_mt_ussd_notification() runs on MTC_CT {
3415 var BSC_ConnHdlr vc_conn;
3416 f_init();
3417 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_notification), 47);
3418 vc_conn.done;
3419}
3420
Harald Weltee13cfb22019-04-23 16:52:02 +02003421
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003422/* LU followed by MT call and MO USSD request during this call */
Harald Weltee13cfb22019-04-23 16:52:02 +02003423friend function f_tc_lu_and_mo_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003424runs on BSC_ConnHdlr {
3425 f_init_handler(pars);
3426
3427 /* Call parameters taken from f_tc_lu_and_mt_call */
3428 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003429
3430 /* Perform location update */
3431 f_perform_lu();
3432
3433 /* Establish a MT call */
3434 f_mt_call_establish(cpars);
3435
3436 /* Hold the call for some time */
3437 f_sleep(1.0);
3438
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003439 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3440 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3441 ussd_string := "*#100#"
3442 );
3443
3444 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3445 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3446 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
3447 )
3448
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003449 /* Compose a new SS/REGISTER message with request */
3450 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
3451 tid := 1, /* We just need a single transaction */
3452 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003453 facility := valueof(facility_req)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003454 );
3455
3456 /* Compose SS/RELEASE_COMPLETE template with expected response */
3457 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
3458 tid := 1, /* Response should arrive within the same transaction */
3459 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003460 facility := valueof(facility_rsp)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003461 );
3462
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003463 /* Compose expected MSC -> HLR message */
3464 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
3465 imsi := g_pars.imsi,
3466 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3467 ss := valueof(facility_req)
3468 );
3469
3470 /* To be used for sending response with correct session ID */
3471 var GSUP_PDU gsup_req_complete;
3472
3473 /* Request own number */
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003474 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003475 /* Expect GSUP message containing the SS payload */
3476 gsup_req_complete := f_expect_gsup_msg(gsup_req);
3477
3478 /* Compose the response from HLR using received session ID */
3479 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
3480 imsi := g_pars.imsi,
3481 sid := gsup_req_complete.ies[1].val.session_id,
3482 state := OSMO_GSUP_SESSION_STATE_END,
3483 ss := valueof(facility_rsp)
3484 );
3485
3486 /* Finally, HLR terminates the session */
3487 GSUP.send(gsup_rsp);
3488 /* Expect RELEASE_COMPLETE message with the response */
3489 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003490
3491 /* Hold the call for some time */
3492 f_sleep(1.0);
3493
3494 /* Release the call (does Clear Complete itself) */
3495 f_call_hangup(cpars, true);
3496}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003497testcase TC_lu_and_mo_ussd_during_mt_call() runs on MTC_CT {
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003498 var BSC_ConnHdlr vc_conn;
3499 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003500 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_during_mt_call), 48);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003501 vc_conn.done;
3502}
3503
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003504/* BSSMAP Clear Request in the middle of a call, see OS#3062 */
Harald Weltee13cfb22019-04-23 16:52:02 +02003505friend function f_tc_mo_cc_bssmap_clear(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003506 f_init_handler(pars);
3507 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02003508 cpars.ran_clear_when_alerting := true;
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003509
3510 f_perform_lu();
3511
Neels Hofmeyrde76f052019-02-26 05:02:46 +01003512 var default ccrel := activate(as_optional_cc_rel(cpars));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02003513 f_mo_call_establish(cpars);
3514 f_expect_clear()
Neels Hofmeyrde76f052019-02-26 05:02:46 +01003515 deactivate(ccrel);
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003516
3517 f_sleep(1.0);
3518}
3519testcase TC_mo_cc_bssmap_clear() runs on MTC_CT {
3520 var BSC_ConnHdlr vc_conn;
3521 f_init();
3522
3523 vc_conn := f_start_handler(refers(f_tc_mo_cc_bssmap_clear), 43);
3524 vc_conn.done;
3525}
3526
Harald Weltee13cfb22019-04-23 16:52:02 +02003527
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003528/* LU followed by MT call and MT USSD request during this call */
Harald Weltee13cfb22019-04-23 16:52:02 +02003529friend function f_tc_lu_and_mt_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003530runs on BSC_ConnHdlr {
3531 f_init_handler(pars);
3532
3533 /* Call parameters taken from f_tc_lu_and_mt_call */
3534 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003535
3536 /* Perform location update */
3537 f_perform_lu();
3538
3539 /* Establish a MT call */
3540 f_mt_call_establish(cpars);
3541
3542 /* Hold the call for some time */
3543 f_sleep(1.0);
3544
3545 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3546 op_code := SS_OP_CODE_USS_REQUEST,
3547 ussd_string := "Please type anything..."
3548 );
3549
3550 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3551 op_code := SS_OP_CODE_USS_REQUEST,
3552 ussd_string := "Nope."
3553 )
3554
3555 /* Compose MT SS/REGISTER message with network-originated request */
3556 var template (value) PDU_ML3_NW_MS ussd_req := ts_ML3_MT_SS_REGISTER(
3557 tid := 0, /* FIXME: most likely, it should be 0 */
3558 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3559 facility := valueof(facility_req)
3560 );
3561
3562 /* Compose HLR -> MSC GSUP message */
3563 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3564 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003565 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003566 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3567 ss := valueof(facility_req)
3568 );
3569
3570 /* Send it to MSC */
3571 GSUP.send(gsup_req);
3572 /* Expect MT REGISTER message with USSD request */
3573 f_expect_mt_dtap_msg(ussd_req);
3574
3575 /* Compose a new MO SS/FACILITY message with response */
3576 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
3577 tid := 0, /* FIXME: it shall match the request tid */
3578 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3579 facility := valueof(facility_rsp)
3580 );
3581
3582 /* Compose expected MSC -> HLR GSUP message */
3583 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
3584 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003585 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003586 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3587 ss := valueof(facility_rsp)
3588 );
3589
3590 /* MS sends response */
3591 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
3592 f_expect_gsup_msg(gsup_rsp);
3593
3594 /* Compose expected MT SS/RELEASE COMPLETE message */
3595 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
3596 tid := 0, /* FIXME: it shall match the request tid */
3597 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3598 facility := omit
3599 );
3600
3601 /* Compose MSC -> HLR GSUP message */
3602 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
3603 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003604 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003605 state := OSMO_GSUP_SESSION_STATE_END
3606 );
3607
3608 /* Finally, HLR terminates the session */
3609 GSUP.send(gsup_term);
3610 /* Expect MT RELEASE COMPLETE without Facility IE */
3611 f_expect_mt_dtap_msg(ussd_term);
3612
3613 /* Hold the call for some time */
3614 f_sleep(1.0);
3615
3616 /* Release the call (does Clear Complete itself) */
3617 f_call_hangup(cpars, true);
3618}
3619testcase TC_lu_and_mt_ussd_during_mt_call() runs on MTC_CT {
3620 var BSC_ConnHdlr vc_conn;
3621 f_init();
3622 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_during_mt_call), 49);
3623 vc_conn.done;
3624}
3625
Harald Weltee13cfb22019-04-23 16:52:02 +02003626
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07003627/* LU followed by MO USSD request and MO Release during transaction */
Harald Weltee13cfb22019-04-23 16:52:02 +02003628friend function f_tc_lu_and_mo_ussd_mo_release(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07003629runs on BSC_ConnHdlr {
3630 f_init_handler(pars);
3631
3632 /* Perform location update */
3633 f_perform_lu();
3634
3635 /* Send CM Service Request for SS/USSD */
3636 f_establish_fully(EST_TYPE_SS_ACT);
3637
3638 /* We need to inspect GSUP activity */
3639 f_create_gsup_expect(hex2str(g_pars.imsi));
3640
3641 var template OCTN facility_ms_req := f_USSD_FACILITY_IE_INVOKE(
3642 invoke_id := 1, /* Initial request */
3643 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3644 ussd_string := "*6766*266#"
3645 );
3646
3647 var template OCTN facility_net_req := f_USSD_FACILITY_IE_INVOKE(
3648 invoke_id := 2, /* Counter request */
3649 op_code := SS_OP_CODE_USS_REQUEST,
3650 ussd_string := "Password?!?"
3651 )
3652
3653 /* Compose MO SS/REGISTER message with request */
3654 var template (value) PDU_ML3_MS_NW ussd_ms_req := ts_ML3_MO_SS_REGISTER(
3655 tid := 1, /* We just need a single transaction */
3656 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3657 facility := valueof(facility_ms_req)
3658 );
3659
3660 /* Compose expected MSC -> HLR message */
3661 var template GSUP_PDU gsup_ms_req := tr_GSUP_PROC_SS_REQ(
3662 imsi := g_pars.imsi,
3663 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3664 ss := valueof(facility_ms_req)
3665 );
3666
3667 /* To be used for sending response with correct session ID */
3668 var GSUP_PDU gsup_ms_req_complete;
3669
3670 /* Initiate a new transaction */
3671 BSSAP.send(ts_PDU_DTAP_MO(ussd_ms_req));
3672 /* Expect GSUP request with original Facility IE */
3673 gsup_ms_req_complete := f_expect_gsup_msg(gsup_ms_req);
3674
3675 /* Compose the response from HLR using received session ID */
3676 var template (value) GSUP_PDU gsup_net_req := ts_GSUP_PROC_SS_REQ(
3677 imsi := g_pars.imsi,
3678 sid := gsup_ms_req_complete.ies[1].val.session_id,
3679 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3680 ss := valueof(facility_net_req)
3681 );
3682
3683 /* Compose expected MT SS/FACILITY template with counter request */
3684 var template PDU_ML3_NW_MS ussd_net_req := tr_ML3_MT_SS_FACILITY(
3685 tid := 1, /* Response should arrive within the same transaction */
3686 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3687 facility := valueof(facility_net_req)
3688 );
3689
3690 /* Send response over GSUP */
3691 GSUP.send(gsup_net_req);
3692 /* Expect MT SS/FACILITY message with counter request */
3693 f_expect_mt_dtap_msg(ussd_net_req);
3694
3695 /* Compose MO SS/RELEASE COMPLETE */
3696 var template (value) PDU_ML3_MS_NW ussd_abort := ts_ML3_MO_SS_RELEASE_COMPLETE(
3697 tid := 1, /* Response should arrive within the same transaction */
3698 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3699 facility := omit
3700 /* TODO: cause? */
3701 );
3702
3703 /* Compose expected HLR -> MSC abort message */
3704 var template GSUP_PDU gsup_abort := tr_GSUP_PROC_SS_REQ(
3705 imsi := g_pars.imsi,
3706 sid := gsup_ms_req_complete.ies[1].val.session_id,
3707 state := OSMO_GSUP_SESSION_STATE_END
3708 );
3709
3710 /* Abort transaction */
3711 BSSAP.send(ts_PDU_DTAP_MO(ussd_abort));
3712 /* Expect GSUP message indicating abort */
3713 f_expect_gsup_msg(gsup_abort);
3714
3715 f_expect_clear();
3716}
3717testcase TC_lu_and_mo_ussd_mo_release() runs on MTC_CT {
3718 var BSC_ConnHdlr vc_conn;
3719 f_init();
3720 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_mo_release), 50);
3721 vc_conn.done;
3722}
3723
Harald Weltee13cfb22019-04-23 16:52:02 +02003724
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003725/* LU followed by MO USSD request and MT Release due to timeout */
Harald Weltee13cfb22019-04-23 16:52:02 +02003726friend function f_tc_lu_and_ss_session_timeout(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003727runs on BSC_ConnHdlr {
3728 f_init_handler(pars);
3729
3730 /* Perform location update */
3731 f_perform_lu();
3732
3733 /* Send CM Service Request for SS/USSD */
3734 f_establish_fully(EST_TYPE_SS_ACT);
3735
3736 /* We need to inspect GSUP activity */
3737 f_create_gsup_expect(hex2str(g_pars.imsi));
3738
3739 var template OCTN facility_ms_req := f_USSD_FACILITY_IE_INVOKE(
3740 invoke_id := 1,
3741 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3742 ussd_string := "#release_me");
3743
3744 /* Compose MO SS/REGISTER message with request */
3745 var template (value) PDU_ML3_MS_NW ussd_ms_req := ts_ML3_MO_SS_REGISTER(
3746 tid := 1, /* An arbitrary transaction identifier */
3747 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3748 facility := valueof(facility_ms_req));
3749
3750 /* Compose expected MSC -> HLR message */
3751 var template GSUP_PDU gsup_ms_req := tr_GSUP_PROC_SS_REQ(
3752 imsi := g_pars.imsi,
3753 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3754 ss := valueof(facility_ms_req));
3755
3756 /* To be used for sending response with correct session ID */
3757 var GSUP_PDU gsup_ms_req_complete;
3758
3759 /* Initiate a new SS transaction */
3760 BSSAP.send(ts_PDU_DTAP_MO(ussd_ms_req));
3761 /* Expect GSUP request with original Facility IE */
3762 gsup_ms_req_complete := f_expect_gsup_msg(gsup_ms_req);
3763
3764 /* Don't respond, wait for timeout */
3765 f_sleep(3.0);
3766
3767 var template PDU_ML3_NW_MS dtap_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
3768 tid := 1, /* Should match the request's tid */
3769 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3770 cause := *, /* TODO: expect some specific value */
3771 facility := omit);
3772
3773 var template GSUP_PDU gsup_rel := tr_GSUP_PROC_SS_ERR(
3774 imsi := g_pars.imsi,
3775 sid := gsup_ms_req_complete.ies[1].val.session_id,
3776 state := OSMO_GSUP_SESSION_STATE_END,
3777 cause := ?); /* TODO: expect some specific value */
3778
3779 /* Expect release on both interfaces */
3780 interleave {
3781 [] BSSAP.receive(tr_PDU_DTAP_MT(dtap_rel)) { };
3782 [] GSUP.receive(gsup_rel) { };
3783 }
3784
3785 f_expect_clear();
3786 setverdict(pass);
3787}
3788testcase TC_lu_and_ss_session_timeout() runs on MTC_CT {
3789 var BSC_ConnHdlr vc_conn;
3790 f_init();
Vadim Yanitskiy36d28dd2018-12-03 02:45:45 +07003791 f_vty_config(MSCVTY, "msc", "ncss guard-timeout 3");
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003792 vc_conn := f_start_handler(refers(f_tc_lu_and_ss_session_timeout), 51);
3793 vc_conn.done;
Vadim Yanitskiy36d28dd2018-12-03 02:45:45 +07003794 f_vty_config(MSCVTY, "msc", "ncss guard-timeout 0");
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003795}
3796
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07003797/* MT (network-originated) USSD for unknown subscriber */
3798friend function f_tc_mt_ussd_for_unknown_subscr(charstring id, BSC_ConnHdlrPars pars)
3799runs on BSC_ConnHdlr {
3800 var hexstring imsi := '000000000000000'H; /* Some unknown IMSI */
3801 var OCT4 sid := '20000222'O;
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07003802
3803 f_init_handler(pars);
3804 f_ran_register_imsi(imsi, 'FFFFFFFF'O);
3805 f_create_gsup_expect(hex2str(imsi));
3806
3807 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3808 imsi := imsi,
3809 sid := sid,
3810 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3811 ss := f_rnd_octstring(23)
3812 );
3813
3814 /* Error with cause GMM_CAUSE_IMSI_UNKNOWN */
3815 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
3816 imsi := imsi,
3817 sid := sid,
3818 state := OSMO_GSUP_SESSION_STATE_END,
3819 cause := 2 /* FIXME: introduce an enumerated type! */
3820 );
3821
3822 /* Initiate a MT USSD notification */
3823 GSUP.send(gsup_req);
3824
3825 /* Expect GSUP PROC_SS_ERROR message */
Vadim Yanitskiy851798c2019-06-15 14:22:28 +07003826 f_expect_gsup_msg(gsup_rsp);
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07003827}
3828testcase TC_mt_ussd_for_unknown_subscr() runs on MTC_CT {
3829 var BSC_ConnHdlr vc_conn;
3830 f_init();
3831 vc_conn := f_start_handler(refers(f_tc_mt_ussd_for_unknown_subscr), 0);
3832 vc_conn.done;
3833}
3834
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07003835/* MO (mobile-originated) SS/USSD for unknown transaction */
3836friend function f_tc_mo_ussd_for_unknown_trans(charstring id, BSC_ConnHdlrPars pars)
3837runs on BSC_ConnHdlr {
3838 f_init_handler(pars);
3839
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01003840 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07003841 f_create_gsup_expect(hex2str(g_pars.imsi));
3842
3843 /* Perform location update */
3844 f_perform_lu();
3845
3846 /* Send CM Service Request for SS/USSD */
3847 f_establish_fully(EST_TYPE_SS_ACT);
3848
3849 /* GSM 04.80 FACILITY message for a non-existing transaction */
3850 var template (value) PDU_ML3_MS_NW mo_ss_fac := ts_ML3_MO_SS_FACILITY(
3851 tid := 1, /* An arbitrary transaction identifier */
3852 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3853 facility := f_rnd_octstring(23) /* We don't care about the Facility IE */
3854 );
3855
3856 /* GSM 04.80 RELEASE COMPLETE message for a non-existing transaction */
3857 var template (value) PDU_ML3_MS_NW mo_ss_rel := ts_ML3_MO_SS_RELEASE_COMPLETE(
3858 tid := 1, /* An arbitrary transaction identifier */
3859 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3860 facility := f_rnd_octstring(23) /* We don't care about the Facility IE */
3861 );
3862
3863 /* Expected response from the network */
3864 var template PDU_ML3_NW_MS mt_ss_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
3865 tid := 1, /* Same as in the FACILITY message */
3866 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3867 facility := omit
3868 );
3869
3870 /* Send GSM 04.80 FACILITY for non-existing transaction */
3871 BSSAP.send(ts_PDU_DTAP_MO(mo_ss_fac));
3872
3873 /* Expect GSM 04.80 RELEASE COMPLETE message */
3874 f_expect_mt_dtap_msg(mt_ss_rel);
3875 f_expect_clear();
3876
3877 /* Send another CM Service Request for SS/USSD */
3878 f_establish_fully(EST_TYPE_SS_ACT);
3879
3880 /* Send GSM 04.80 RELEASE COMPLETE for non-existing transaction */
3881 BSSAP.send(ts_PDU_DTAP_MO(mo_ss_rel));
3882
3883 /* Expect GSM 04.80 RELEASE COMPLETE message */
3884 f_expect_mt_dtap_msg(mt_ss_rel);
3885 f_expect_clear();
3886}
3887testcase TC_mo_ussd_for_unknown_trans() runs on MTC_CT {
3888 var BSC_ConnHdlr vc_conn;
3889 f_init();
3890 vc_conn := f_start_handler(refers(f_tc_mo_ussd_for_unknown_trans), 111);
3891 vc_conn.done;
3892}
3893
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07003894/* MT (network-originated) USSD for unknown session */
3895friend function f_tc_proc_ss_for_unknown_session(charstring id, BSC_ConnHdlrPars pars)
3896runs on BSC_ConnHdlr {
3897 var OCT4 sid := '20000333'O;
3898
3899 f_init_handler(pars);
3900
3901 /* Perform location update */
3902 f_perform_lu();
3903
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01003904 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07003905 f_create_gsup_expect(hex2str(g_pars.imsi));
3906
3907 /* Request referencing a non-existing SS session */
3908 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3909 imsi := g_pars.imsi,
3910 sid := sid,
3911 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3912 ss := f_rnd_octstring(23)
3913 );
3914
3915 /* Error with some cause value */
3916 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
3917 imsi := g_pars.imsi,
3918 sid := sid,
3919 state := OSMO_GSUP_SESSION_STATE_END,
3920 cause := ? /* FIXME: introduce an enumerated type! */
3921 );
3922
3923 /* Initiate a MT USSD notification */
3924 GSUP.send(gsup_req);
3925
3926 /* Expect GSUP PROC_SS_ERROR message */
3927 f_expect_gsup_msg(gsup_rsp);
3928}
3929testcase TC_proc_ss_for_unknown_session() runs on MTC_CT {
3930 var BSC_ConnHdlr vc_conn;
3931 f_init();
3932 vc_conn := f_start_handler(refers(f_tc_proc_ss_for_unknown_session), 110);
3933 vc_conn.done;
3934}
3935
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003936/* MT (network-originated) USSD and no response to Paging Request */
3937friend function f_tc_proc_ss_paging_fail(charstring id, BSC_ConnHdlrPars pars)
3938runs on BSC_ConnHdlr {
3939 timer TP := 2.0; /* Paging timer */
3940
3941 f_init_handler(pars);
3942
3943 /* Perform location update */
3944 f_perform_lu();
3945
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01003946 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003947 f_create_gsup_expect(hex2str(g_pars.imsi));
3948
3949 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3950 imsi := g_pars.imsi,
3951 sid := '20000444'O,
3952 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3953 ss := f_rnd_octstring(23)
3954 );
3955
3956 /* Error with some cause value */
3957 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
3958 imsi := g_pars.imsi,
3959 sid := '20000444'O,
3960 state := OSMO_GSUP_SESSION_STATE_END,
3961 cause := ? /* FIXME: introduce an enumerated type! */
3962 );
3963
3964 /* Initiate a MT USSD notification */
3965 GSUP.send(gsup_req);
3966
3967 /* Send it to MSC and expect Paging Request */
3968 TP.start;
3969 alt {
3970 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
3971 setverdict(pass);
3972 }
3973 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
3974 setverdict(pass);
3975 }
3976 /* We don't expect anything else */
3977 [] as_unexp_gsup_or_bssap_msg();
3978 [] TP.timeout {
3979 setverdict(fail, "Timeout waiting for Paging Request");
3980 }
3981 }
3982
Vadim Yanitskiyd24b5252019-10-02 00:04:51 +07003983 /* Wait up to 20 seconds for GSUP PROC_SS_ERROR message.
3984 * OsmoMSC waits for Paging Response 10 seconds by default. */
3985 f_expect_gsup_msg(gsup_rsp, T_val := 20.0);
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003986}
3987testcase TC_proc_ss_paging_fail() runs on MTC_CT {
3988 var BSC_ConnHdlr vc_conn;
3989 f_init();
3990 vc_conn := f_start_handler(refers(f_tc_proc_ss_paging_fail), 101);
3991 vc_conn.done;
3992}
3993
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07003994/* MT (network-originated) USSD followed by immediate abort */
3995friend function f_tc_proc_ss_abort(charstring id, BSC_ConnHdlrPars pars)
3996runs on BSC_ConnHdlr {
3997 var octetstring facility := f_rnd_octstring(23);
3998 var OCT4 sid := '20000555'O;
3999 timer TP := 2.0;
4000
4001 f_init_handler(pars);
4002
4003 /* Perform location update */
4004 f_perform_lu();
4005
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01004006 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07004007 f_create_gsup_expect(hex2str(g_pars.imsi));
4008
4009 /* PROC_SS_REQ initiates a mobile-originated SS/USSD session */
4010 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
4011 imsi := g_pars.imsi, sid := sid,
4012 state := OSMO_GSUP_SESSION_STATE_BEGIN,
4013 ss := facility
4014 );
4015
4016 /* On the MS side, we expect GSM 04.80 REGISTER message */
4017 var template PDU_ML3_NW_MS dtap_reg := tr_ML3_MT_SS_REGISTER(
4018 tid := 0, /* Most likely, it should be 0 */
4019 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
4020 facility := facility
4021 );
4022
4023 /* PROC_SS_ERR with SESSION_STATE_END terminates the SS/USSD session */
4024 var template (value) GSUP_PDU gsup_abort := ts_GSUP_PROC_SS_ERR(
4025 imsi := g_pars.imsi, sid := sid,
4026 state := OSMO_GSUP_SESSION_STATE_END,
4027 cause := 0 /* FIXME: introduce an enumerated type! */
4028 );
4029
4030 /* On the MS side, we expect GSM 04.80 REGISTER message */
4031 var template PDU_ML3_NW_MS dtap_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
4032 tid := 0, /* Most likely, it should be 0 */
4033 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
4034 cause := *, /* FIXME: expect some specific cause value */
4035 facility := omit
4036 );
4037
4038 /* Initiate a MT USSD with random payload */
4039 GSUP.send(gsup_req);
4040
4041 /* Expect Paging Request */
4042 TP.start;
4043 alt {
4044 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
4045 setverdict(pass);
4046 }
4047 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
4048 setverdict(pass);
4049 }
4050 /* We don't expect anything else */
4051 [] as_unexp_gsup_or_bssap_msg();
4052 [] TP.timeout {
4053 setverdict(fail, "Timeout waiting for Paging Request");
4054 }
4055 }
4056
4057 /* Send Paging Response and establish connection */
4058 f_establish_fully(EST_TYPE_PAG_RESP);
4059 /* Expect MT REGISTER message with random facility */
4060 f_expect_mt_dtap_msg(dtap_reg);
4061
4062 /* HLR/EUSE decides to abort the session even
4063 * before getting any response from the MS */
4064 /* Initiate a MT USSD with random payload */
4065 GSUP.send(gsup_abort);
4066
4067 /* Expect RELEASE COMPLETE on ths MS side */
4068 f_expect_mt_dtap_msg(dtap_rel);
4069
4070 f_expect_clear();
4071}
4072testcase TC_proc_ss_abort() runs on MTC_CT {
4073 var BSC_ConnHdlr vc_conn;
4074 f_init();
4075 vc_conn := f_start_handler(refers(f_tc_proc_ss_abort), 102);
4076 vc_conn.done;
4077}
4078
Harald Weltee13cfb22019-04-23 16:52:02 +02004079
Vadim Yanitskiy1c9754d2020-01-07 21:56:55 +01004080/* Verify multiple concurrent MO SS/USSD transactions
4081 * (one subscriber - one transaction) */
4082testcase TC_multi_lu_and_mo_ussd() runs on MTC_CT {
4083 var BSC_ConnHdlr vc_conn[16];
4084 var integer i;
4085
4086 f_init();
4087
4088 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
4089 vc_conn[i] := f_start_handler(refers(f_tc_lu_and_mo_ussd_single_request), 210 + i);
4090 }
4091
4092 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
4093 vc_conn[i].done;
4094 }
4095}
4096
4097/* Verify multiple concurrent MT SS/USSD transactions
4098 * (one subscriber - one transaction) */
4099testcase TC_multi_lu_and_mt_ussd() runs on MTC_CT {
4100 var BSC_ConnHdlr vc_conn[16];
4101 var integer i;
4102 var OCT4 sid;
4103
4104 f_init();
4105
4106 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
4107 sid := '200001'O & int2oct(i, 1); /* All transactions must use different session ID */
4108 vc_conn[i] := f_start_handler_with_pars(refers(f_tc_lu_and_mt_ussd_notification),
4109 f_init_pars(226 + i, gsup_sid := sid));
4110 }
4111
4112 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
4113 vc_conn[i].done;
4114 }
4115}
4116
4117
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004118/* A5/1 only permitted on network side; attempt an invalid CIPHER MODE COMPLETE with A5/3 which MSC should reject. */
4119private function f_tc_cipher_complete_with_invalid_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4120 pars.net.expect_auth := true;
4121 pars.net.expect_ciph := true;
4122 pars.net.kc_support := '02'O; /* A5/1 only */
4123 f_init_handler(pars);
4124
4125 g_pars.vec := f_gen_auth_vec_2g();
4126
4127 /* Can't use f_perform_lu() directly. Code below is based on it. */
4128
4129 /* tell GSUP dispatcher to send this IMSI to us */
4130 f_create_gsup_expect(hex2str(g_pars.imsi));
4131
4132 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
4133 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
Harald Weltedceacc72019-04-21 20:58:35 +02004134 f_cl3_or_initial_ue(l3_lu);
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004135
4136 f_mm_auth();
4137
4138 var OCT1 a5_net := f_alg_mask_from_cm(g_pars.cm2);
4139 var OCT1 a5_intersect := g_pars.net.kc_support and4b a5_net;
4140 alt {
4141 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(a5_intersect, g_pars.vec.kc)) {
4142 BSSAP.send(ts_BSSMAP_CipherModeCompl(int2oct(4 /* "accept" A5/3 */, 1)));
4143 }
4144 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?, g_pars.vec.kc)) {
4145 setverdict(fail, "Wrong ciphering algorithm mask in CiphModCmd");
4146 mtc.stop;
4147 }
4148 [] BSSAP.receive {
4149 setverdict(fail, "Unknown/unexpected BSSAP received");
4150 mtc.stop;
4151 }
4152 }
Harald Welte79f1e452020-08-18 22:55:02 +02004153 f_expect_common_id();
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004154
4155 /* Expect LU reject from MSC. */
4156 alt {
4157 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
4158 setverdict(pass);
4159 }
4160 [] BSSAP.receive {
4161 setverdict(fail, "Unknown/unexpected BSSAP received");
4162 mtc.stop;
4163 }
4164 }
Stefan Sperlingc620b352018-12-18 17:23:36 +01004165 f_expect_clear();
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004166}
4167
4168testcase TC_cipher_complete_with_invalid_cipher() runs on MTC_CT {
4169 var BSC_ConnHdlr vc_conn;
4170 f_init();
4171 f_vty_config(MSCVTY, "network", "encryption a5 1");
4172
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02004173 vc_conn := f_start_handler(refers(f_tc_cipher_complete_with_invalid_cipher), 52, verify_cell_id := false);
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004174 vc_conn.done;
4175}
4176
Harald Welteb2284bd2019-05-10 11:30:43 +02004177/* Location Update with invalid (non-matching) MCC/MNC reported on BSSMAP level from BSC */
4178friend function f_tc_lu_with_invalid_mcc_mnc(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4179 f_init_handler(pars);
4180
4181 /* tell GSUP dispatcher to send this IMSI to us */
4182 f_create_gsup_expect(hex2str(g_pars.imsi));
4183
4184 /* modify the cell ID which will be used to construct the COMPLELTE L3 or InitialUE */
4185 g_pars.cell_id := valueof(ts_CellId_CGI('333'H, '22'H, 23, 42));
4186
4187 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
4188 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
4189 f_cl3_or_initial_ue(l3_lu);
Harald Welte79f1e452020-08-18 22:55:02 +02004190 f_expect_common_id();
Harald Welteb2284bd2019-05-10 11:30:43 +02004191
4192 /* Expect LU reject from MSC. */
4193 alt {
4194 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
4195 setverdict(pass);
4196 }
4197 [] BSSAP.receive {
4198 setverdict(fail, "Unknown/unexpected BSSAP received");
4199 mtc.stop;
4200 }
4201 }
4202 f_expect_clear();
4203}
4204testcase TC_lu_with_invalid_mcc_mnc() runs on MTC_CT {
4205 var BSC_ConnHdlr vc_conn;
4206 f_init();
4207 vc_conn := f_start_handler(refers(f_tc_lu_with_invalid_mcc_mnc), 54);
4208 vc_conn.done;
4209}
4210
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01004211private function f_tc_cipher_complete_without_alg(charstring id, BSC_ConnHdlrPars pars, octetstring kc_support) runs on BSC_ConnHdlr {
4212 pars.net.expect_auth := true;
4213 pars.net.expect_ciph := true;
4214 pars.net.kc_support := kc_support;
4215 f_init_handler(pars);
4216
4217 g_pars.vec := f_gen_auth_vec_2g();
4218
4219 /* Can't use f_perform_lu() directly. Code below is based on it. */
4220
4221 /* tell GSUP dispatcher to send this IMSI to us */
4222 f_create_gsup_expect(hex2str(g_pars.imsi));
4223
4224 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
4225 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
4226 f_cl3_or_initial_ue(l3_lu);
4227
4228 f_mm_auth();
4229
4230 var OCT1 a5_net := f_alg_mask_from_cm(g_pars.cm2);
4231 var OCT1 a5_intersect := g_pars.net.kc_support and4b a5_net;
4232 alt {
4233 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(a5_intersect, g_pars.vec.kc)) {
4234 BSSAP.send(ts_BSSMAP_CipherModeComplAlg(omit));
4235 }
4236 [] BSSAP.receive(tr_BSSMAP_ClassmarkReq) {
4237 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
4238 repeat;
4239 }
4240 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?, g_pars.vec.kc)) {
4241 setverdict(fail, "Wrong ciphering algorithm mask in CiphModCmd");
4242 mtc.stop;
4243 }
4244 [] BSSAP.receive {
4245 setverdict(fail, "Unknown/unexpected BSSAP received");
4246 mtc.stop;
4247 }
4248 }
Harald Welte79f1e452020-08-18 22:55:02 +02004249 f_expect_common_id();
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01004250
4251 /* TODO: Verify MSC is using the best cipher available! How? */
4252
4253 f_msc_lu_hlr();
4254 f_accept_reject_lu();
4255 f_expect_clear();
4256 setverdict(pass);
4257}
4258
4259/* A5/1 only permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
4260private function f_tc_cipher_complete_1_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4261 f_tc_cipher_complete_without_alg(id, pars, '02'O /* A5/1 only */);
4262}
4263
4264/* A5/3 only permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
4265private function f_tc_cipher_complete_3_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4266 f_tc_cipher_complete_without_alg(id, pars, '08'O /* A5/3 only */);
4267}
4268
4269/* A5/1 + A5/3 permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
4270private function f_tc_cipher_complete_13_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4271 f_tc_cipher_complete_without_alg(id, pars, '0A'O /* A5/1 and A5/3 enabled */);
4272}
4273
4274testcase TC_cipher_complete_1_without_cipher() runs on MTC_CT {
4275 var BSC_ConnHdlr vc_conn;
4276 f_init();
4277 f_vty_config(MSCVTY, "network", "encryption a5 1");
4278
4279 vc_conn := f_start_handler(refers(f_tc_cipher_complete_1_without_cipher), 53);
4280 vc_conn.done;
4281}
4282
4283testcase TC_cipher_complete_3_without_cipher() runs on MTC_CT {
4284 var BSC_ConnHdlr vc_conn;
4285 f_init();
4286 f_vty_config(MSCVTY, "network", "encryption a5 3");
4287
4288 vc_conn := f_start_handler(refers(f_tc_cipher_complete_3_without_cipher), 54);
4289 vc_conn.done;
4290}
4291
4292testcase TC_cipher_complete_13_without_cipher() runs on MTC_CT {
4293 var BSC_ConnHdlr vc_conn;
4294 f_init();
4295 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
4296
4297 vc_conn := f_start_handler(refers(f_tc_cipher_complete_13_without_cipher), 55);
4298 vc_conn.done;
4299}
Harald Welteb2284bd2019-05-10 11:30:43 +02004300
Harald Weltef640a012018-04-14 17:49:21 +02004301/* TODO (SMS):
4302 * different user data lengths
4303 * SMPP transaction mode with unsuccessful delivery
4304 * queued MT-SMS with no paging response + later delivery
4305 * different data coding schemes
4306 * multi-part SMS
4307 * user-data headers
4308 * TP-PID for SMS to SIM
4309 * behavior if SMS memory is full + RP-SMMA
4310 * delivery reports
4311 * SMPP osmocom extensions
4312 * more-messages-to-send
4313 * SMS during ongoing call (SACCH/SAPI3)
4314 */
4315
4316/* TODO (General):
Harald Welteba7b6d92018-01-23 21:32:34 +01004317 * continue to send repeated MO signalling messages to keep channel open: does MSC tmeout?
4318 * malformed messages (missing IE, invalid message type): properly rejected?
4319 * MT call while LU or is ongoing: Do we use existing lchan or page while lchan active?
4320 * 3G/2G auth permutations
4321 * encryption algorithms vs. classmark vs. vty config
Harald Welteba7b6d92018-01-23 21:32:34 +01004322 * send new transaction after/during clear (like SMS, ...)
Harald Welte45164da2018-01-24 12:51:27 +01004323 * too long L3 INFO in DTAP
4324 * too long / padded BSSAP
4325 * too long / short TLV values
Harald Welteba7b6d92018-01-23 21:32:34 +01004326 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01004327
Harald Weltee13cfb22019-04-23 16:52:02 +02004328/***********************************************************************
4329 * SGsAP Testing
4330 ***********************************************************************/
4331
Philipp Maier948747b2019-04-02 15:22:33 +02004332/* Check if a subscriber exists in the VLR */
4333private function f_ctrl_subscr_in_vlr(charstring imsi_or_msisdn) runs on BSC_ConnHdlr return boolean {
4334
4335 var CtrlValue active_subsribers;
4336 var integer rc;
4337 active_subsribers := f_ctrl_get(IPA_CTRL, "subscriber-list-active-v1");
4338
4339 rc := f_strstr(active_subsribers, imsi_or_msisdn);
4340 if (rc < 0) {
4341 return false;
4342 }
4343
4344 return true;
4345}
4346
Harald Welte4263c522018-12-06 11:56:27 +01004347/* Perform a location updatye at the A-Interface and run some checks to confirm
4348 * that everything is back to normal. */
4349private function f_sgsap_bssmap_screening() runs on BSC_ConnHdlr {
4350 var SmsParameters spars := valueof(t_SmsPars);
4351
4352 /* Perform a location update, the SGs association is expected to fall
4353 * back to NULL */
4354 f_perform_lu();
4355 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4356
4357 /* Trigger a paging request and expect the paging on BSSMAP, this is
4358 * to make sure that pagings are sent throught the A-Interface again
4359 * and not throught the SGs interface.*/
Harald Welte6811d102019-04-14 22:23:14 +02004360 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Welte4263c522018-12-06 11:56:27 +01004361 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4362
4363 alt {
Harald Weltee13cfb22019-04-23 16:52:02 +02004364 [g_pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)); {
4365 setverdict(pass);
4366 }
Harald Welte62113fc2019-05-09 13:04:02 +02004367 [not g_pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
Harald Welte4263c522018-12-06 11:56:27 +01004368 setverdict(pass);
4369 }
4370 [] SGsAP.receive {
4371 setverdict(fail, "Received unexpected message on SGs");
4372 }
4373 }
4374
4375 /* Send an SMS to make sure that also payload messages are routed
4376 * throught the A-Interface again */
4377 f_establish_fully(EST_TYPE_MO_SMS);
4378 f_mo_sms(spars);
4379 f_expect_clear();
4380}
4381
4382private function f_tc_sgsap_reset(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4383 var charstring vlr_name;
4384 f_init_handler(pars);
4385
4386 vlr_name := f_sgsap_reset_mme(mp_mme_name);
4387 log("VLR name: ", vlr_name);
4388 setverdict(pass);
Neels Hofmeyrc0b520d2019-03-06 15:35:50 +01004389 f_sleep(1.0);
Harald Welte4263c522018-12-06 11:56:27 +01004390}
4391
4392testcase TC_sgsap_reset() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004393 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004394 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004395 f_init(1, true);
4396 pars := f_init_pars(11810, true);
4397 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_reset), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004398 vc_conn.done;
4399}
4400
4401/* like f_mm_auth() but for SGs */
4402function f_mm_auth_sgs() runs on BSC_ConnHdlr {
4403 if (g_pars.net.expect_auth) {
4404 g_pars.vec := f_gen_auth_vec_3g();
4405 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G3G(g_pars.vec.rand,
4406 g_pars.vec.sres,
4407 g_pars.vec.kc,
4408 g_pars.vec.ik,
4409 g_pars.vec.ck,
4410 g_pars.vec.autn,
4411 g_pars.vec.res));
4412 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
4413 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
4414 SGsAP.receive(tr_ML3_MT_MM_AUTH_REQ_3G(g_pars.vec.rand, g_pars.vec.autn));
4415 SGsAP.send(ts_ML3_MT_MM_AUTH_RESP_3G(g_pars.vec.sres, g_pars.vec.res));
4416 }
4417}
4418
4419/* like f_perform_lu(), but on SGs rather than BSSAP */
4420function f_sgs_perform_lu() runs on BSC_ConnHdlr {
4421 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4422 var PDU_SGsAP lur;
4423 var PDU_SGsAP lua;
4424 var PDU_SGsAP mm_info;
4425 var octetstring mm_info_dtap;
4426
4427 /* tell GSUP dispatcher to send this IMSI to us */
4428 f_create_gsup_expect(hex2str(g_pars.imsi));
4429
4430 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
4431 ts_SGsAP_LAI('901'H, '70'H, 2342)));
4432 /* Old LAI, if MS sends it */
4433 /* TMSI status, if MS has no valid TMSI */
4434 /* IMEISV, if it supports "automatic device detection" */
4435 /* TAI, if available in MME */
4436 /* E-CGI, if available in MME */
4437 SGsAP.send(lur);
4438
4439 /* FIXME: is this really done over SGs? The Ue is already authenticated
4440 * via the MME ... */
4441 f_mm_auth_sgs();
4442
4443 /* Expect MSC to perform LU with HLR */
4444 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4445 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
4446 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
4447 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
4448
4449 alt {
4450 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) -> value lua {
4451 if (isvalue(lua.sGsAP_LOCATION_UPDATE_ACCEPT.newTMSIorIMSI.iD.iD.tmsi_ptmsi.octets)) {
4452 g_pars.tmsi :=lua.sGsAP_LOCATION_UPDATE_ACCEPT.newTMSIorIMSI.iD.iD.tmsi_ptmsi.octets
4453 SGsAP.send(ts_SGsAP_TMSI_REALL_CMPL(g_pars.imsi));
4454 }
4455 setverdict(pass);
4456 }
4457 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4458 setverdict(fail, "Received LU-REJECT instead of ACCEPT");
4459 }
4460 [] SGsAP.receive {
4461 setverdict(fail, "Received unexpected message on SGs");
4462 }
4463 }
4464
4465 /* Check MM information */
4466 if (mp_mm_info == true) {
4467 SGsAP.receive(tr_SGsAP_MM_INFO_REQ(g_pars.imsi, ?)) -> value mm_info;
4468 mm_info_dtap := '0532'O & mm_info.sGsAP_MM_INFORMATION_REQUEST.mM_Information.information;
4469 if (not match(dec_PDU_ML3_NW_MS(mm_info_dtap), tr_ML3_MT_MM_Info)) {
4470 setverdict(fail, "Unexpected MM Information");
4471 }
4472 }
4473
4474 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4475}
4476
4477private function f_tc_sgsap_lu(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4478 f_init_handler(pars);
4479 f_sgs_perform_lu();
4480 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4481
4482 f_sgsap_bssmap_screening();
4483
4484 setverdict(pass);
4485}
4486testcase TC_sgsap_lu() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004487 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004488 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004489 f_init(1, true);
4490 pars := f_init_pars(11811, true);
4491 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004492 vc_conn.done;
4493}
4494
4495/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
4496private function f_tc_sgsap_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4497 f_init_handler(pars);
4498 var PDU_SGsAP lur;
4499
4500 f_create_gsup_expect(hex2str(g_pars.imsi));
4501 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4502 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
4503 ts_SGsAP_LAI('901'H, '70'H, 2342)));
4504 SGsAP.send(lur);
4505
4506 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4507 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
4508 alt {
4509 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4510 setverdict(pass);
4511 }
4512 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) {
4513 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
4514 mtc.stop;
4515 }
4516 [] SGsAP.receive {
4517 setverdict(fail, "Received unexpected message on SGs");
4518 }
4519 }
4520
4521 f_sgsap_bssmap_screening();
4522
4523 setverdict(pass);
4524}
4525testcase TC_sgsap_lu_imsi_reject() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004526 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004527 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004528 f_init(1, true);
4529 pars := f_init_pars(11812, true);
Harald Welte4263c522018-12-06 11:56:27 +01004530
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004531 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_imsi_reject), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004532 vc_conn.done;
4533}
4534
4535/* Do LU by IMSI, but then remain silent so that Ts6-1 times out */
4536private function f_tc_sgsap_lu_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4537 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4538 var PDU_SGsAP lur;
4539
4540 f_init_handler(pars);
4541
4542 /* tell GSUP dispatcher to send this IMSI to us */
4543 f_create_gsup_expect(hex2str(g_pars.imsi));
4544
4545 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
4546 ts_SGsAP_LAI('901'H, '70'H, 2342)));
4547 /* Old LAI, if MS sends it */
4548 /* TMSI status, if MS has no valid TMSI */
4549 /* IMEISV, if it supports "automatic device detection" */
4550 /* TAI, if available in MME */
4551 /* E-CGI, if available in MME */
4552 SGsAP.send(lur);
4553
4554 /* FIXME: is this really done over SGs? The Ue is already authenticated
4555 * via the MME ... */
4556 f_mm_auth_sgs();
4557
4558 /* Expect MSC to perform LU with HLR */
4559 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4560 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
4561 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
4562 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
4563
4564 alt {
4565 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) {
4566 setverdict(pass);
4567 }
4568 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4569 setverdict(fail, "Received LU-REJECT instead of ACCEPT");
4570 }
4571 [] SGsAP.receive {
4572 setverdict(fail, "Received unexpected message on SGs");
4573 }
4574 }
4575
4576 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4577
4578 /* Wait until the VLR has abort the TMSI reallocation procedure */
4579 f_sleep(45.0);
4580
4581 /* The outcome does not change the SGs state, see also 5.2.3.4 */
4582 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4583
4584 f_sgsap_bssmap_screening();
4585
4586 setverdict(pass);
4587}
4588testcase TC_sgsap_lu_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004589 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004590 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004591 f_init(1, true);
4592 pars := f_init_pars(11813, true);
Harald Welte4263c522018-12-06 11:56:27 +01004593
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004594 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004595 vc_conn.done;
4596}
4597
4598private function f_tc_sgsap_expl_imsi_det_eps(charstring id, BSC_ConnHdlrPars pars)
4599runs on BSC_ConnHdlr {
4600 f_init_handler(pars);
4601 f_sgs_perform_lu();
4602 f_sleep(3.0);
4603
4604 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4605 SGsAP.send(ts_SGsAP_EPS_DETACH_IND(g_pars.imsi, mme_name, UE_initiated));
4606 SGsAP.receive(tr_SGsAP_EPS_DETACH_ACK(g_pars.imsi));
4607 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4608
4609 f_sgsap_bssmap_screening();
4610
4611 setverdict(pass);
4612}
4613testcase TC_sgsap_expl_imsi_det_eps() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004614 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004615 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004616 f_init(1, true);
4617 pars := f_init_pars(11814, true);
4618 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_expl_imsi_det_eps), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004619 vc_conn.done;
4620}
4621
Philipp Maierfc19f172019-03-21 11:17:54 +01004622private function f_tc_sgsap_impl_imsi_det_eps(charstring id, BSC_ConnHdlrPars pars)
4623runs on BSC_ConnHdlr {
4624 f_init_handler(pars);
4625 f_sgs_perform_lu();
4626 f_sleep(3.0);
4627
4628 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4629 SGsAP.send(ts_SGsAP_EPS_DETACH_IND(g_pars.imsi, mme_name, network_initiated));
4630 SGsAP.receive(tr_SGsAP_EPS_DETACH_ACK(g_pars.imsi));
4631 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4632
4633 f_sgsap_bssmap_screening();
4634
4635 setverdict(pass);
4636}
4637testcase TC_sgsap_impl_imsi_det_eps() runs on MTC_CT {
4638 var BSC_ConnHdlrPars pars;
4639 var BSC_ConnHdlr vc_conn;
4640 f_init(1, true);
4641 pars := f_init_pars(11814, true);
4642 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_impl_imsi_det_eps), pars);
4643 vc_conn.done;
4644}
4645
Harald Welte4263c522018-12-06 11:56:27 +01004646private function f_tc_sgsap_expl_imsi_det_noneps(charstring id, BSC_ConnHdlrPars pars)
4647runs on BSC_ConnHdlr {
4648 f_init_handler(pars);
4649 f_sgs_perform_lu();
4650 f_sleep(3.0);
4651
4652 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4653 SGsAP.send(ts_SGsAP_IMSI_DETACH_IND(g_pars.imsi, mme_name, combined_UE_initiated));
4654 SGsAP.receive(tr_SGsAP_IMSI_DETACH_ACK(g_pars.imsi));
Philipp Maierd08e7e72019-04-02 15:27:10 +02004655
4656 if (f_ctrl_subscr_in_vlr(hex2str(g_pars.imsi))) {
4657 setverdict(fail, "subscriber not removed from VLR");
4658 }
Harald Welte4263c522018-12-06 11:56:27 +01004659
4660 f_sgsap_bssmap_screening();
4661
4662 setverdict(pass);
4663}
4664testcase TC_sgsap_expl_imsi_det_noneps() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004665 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004666 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004667 f_init(1, true);
4668 pars := f_init_pars(11815, true);
4669 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_expl_imsi_det_noneps), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004670 vc_conn.done;
4671}
4672
Philipp Maier5d812702019-03-21 10:51:26 +01004673private function f_tc_sgsap_impl_imsi_det_noneps(charstring id, BSC_ConnHdlrPars pars)
4674runs on BSC_ConnHdlr {
4675 f_init_handler(pars);
4676 f_sgs_perform_lu();
4677 f_sleep(3.0);
4678
4679 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4680 SGsAP.send(ts_SGsAP_IMSI_DETACH_IND(g_pars.imsi, mme_name, implicit_network_initiated));
4681 SGsAP.receive(tr_SGsAP_IMSI_DETACH_ACK(g_pars.imsi));
4682
4683 if (f_ctrl_subscr_in_vlr(hex2str(g_pars.imsi))) {
4684 setverdict(fail, "subscriber not removed from VLR");
4685 }
4686
4687 f_sgsap_bssmap_screening();
4688
4689 setverdict(pass);
4690}
4691testcase TC_sgsap_impl_imsi_det_noneps() runs on MTC_CT {
4692 var BSC_ConnHdlrPars pars;
4693 var BSC_ConnHdlr vc_conn;
4694 f_init(1, true);
4695 pars := f_init_pars(11815, true);
4696 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_impl_imsi_det_noneps), pars);
4697 vc_conn.done;
4698}
4699
Harald Welte4263c522018-12-06 11:56:27 +01004700/* Trigger a paging request via VTY and send a paging reject in response */
4701private function f_tc_sgsap_paging_rej(charstring id, BSC_ConnHdlrPars pars)
4702runs on BSC_ConnHdlr {
4703 f_init_handler(pars);
4704 f_sgs_perform_lu();
4705 f_sleep(1.0);
4706
4707 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4708 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4709 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4710 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4711
4712 /* Initiate paging via VTY */
4713 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4714 alt {
4715 [] SGsAP.receive(exp_resp) {
4716 setverdict(pass);
4717 }
4718 [] SGsAP.receive {
4719 setverdict(fail, "Received unexpected message on SGs");
4720 }
4721 }
4722
4723 /* Now reject the paging */
4724 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, IMSI_unknown));
4725
4726 /* Wait for the states inside the MSC to settle and check the state
4727 * of the SGs Association */
4728 f_sleep(1.0);
4729 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4730
4731 /* FIXME: At the moment we send an IMSI_unknown as cause code, which is fine,
4732 * but we also need to cover tha case where the cause code indicates an
4733 * "IMSI detached for EPS services". In those cases the VLR is expected to
4734 * try paging on tha A/Iu interface. This will be another testcase similar to
4735 * this one, but extended with checks for the presence of the A/Iu paging
4736 * messages. */
4737
4738 f_sgsap_bssmap_screening();
4739
4740 setverdict(pass);
4741}
4742testcase TC_sgsap_paging_rej() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004743 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004744 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004745 f_init(1, true);
4746 pars := f_init_pars(11816, true);
4747 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_rej), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004748 vc_conn.done;
4749}
4750
4751/* Trigger a paging request via VTY and send a paging reject that indicates
4752 * that the subscriber intentionally rejected the call. */
4753private function f_tc_sgsap_paging_subscr_rej(charstring id, BSC_ConnHdlrPars pars)
4754runs on BSC_ConnHdlr {
4755 f_init_handler(pars);
4756 f_sgs_perform_lu();
4757 f_sleep(1.0);
4758
4759 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4760 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4761 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4762 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4763
4764 /* Initiate paging via VTY */
4765 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4766 alt {
4767 [] SGsAP.receive(exp_resp) {
4768 setverdict(pass);
4769 }
4770 [] SGsAP.receive {
4771 setverdict(fail, "Received unexpected message on SGs");
4772 }
4773 }
4774
4775 /* Now reject the paging */
4776 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, user_rejected_mobile_terminating_CS_fallback_call));
4777
4778 /* Wait for the states inside the MSC to settle and check the state
4779 * of the SGs Association */
4780 f_sleep(1.0);
4781 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4782
4783 /* FIXME: The VLR is supposed to trigger an User Determined User Busy (UDUB) as specified
4784 * in 3GPP TS 24.082, this is not yet implemented in the MSC or in this tests, we need
4785 * to check back how this works and how it can be tested */
4786
4787 f_sgsap_bssmap_screening();
4788
4789 setverdict(pass);
4790}
4791testcase TC_sgsap_paging_subscr_rej() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004792 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004793 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004794 f_init(1, true);
4795 pars := f_init_pars(11817, true);
4796 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_subscr_rej), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004797 vc_conn.done;
4798}
4799
4800/* Trigger a paging request via VTY and send an UE unreacable messge in response */
4801private function f_tc_sgsap_paging_ue_unr(charstring id, BSC_ConnHdlrPars pars)
4802runs on BSC_ConnHdlr {
4803 f_init_handler(pars);
4804 f_sgs_perform_lu();
4805 f_sleep(1.0);
4806
4807 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4808 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4809 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4810 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4811
4812 /* Initiate paging via VTY */
4813 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4814 alt {
4815 [] SGsAP.receive(exp_resp) {
4816 setverdict(pass);
4817 }
4818 [] SGsAP.receive {
4819 setverdict(fail, "Received unexpected message on SGs");
4820 }
4821 }
4822
4823 /* Now pretend that the UE is unreachable */
4824 SGsAP.send(ts_SGsAP_UE_UNREACHABLE(g_pars.imsi, UE_unreachable));
4825
4826 /* Wait for the states inside the MSC to settle and check the state
4827 * of the SGs Association. */
4828 f_sleep(1.0);
4829 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4830
4831 f_sgsap_bssmap_screening();
4832
4833 setverdict(pass);
4834}
4835testcase TC_sgsap_paging_ue_unr() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004836 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004837 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004838 f_init(1, true);
4839 pars := f_init_pars(11818, true);
4840 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_ue_unr), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004841 vc_conn.done;
4842}
4843
4844/* Trigger a paging request via VTY but don't respond to it */
4845private function f_tc_sgsap_paging_and_nothing(charstring id, BSC_ConnHdlrPars pars)
4846runs on BSC_ConnHdlr {
4847 f_init_handler(pars);
4848 f_sgs_perform_lu();
4849 f_sleep(1.0);
4850
4851 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4852 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
Philipp Maier34218102019-09-24 09:15:49 +02004853 var template PDU_SGsAP exp_serv_abrt := ts_SGsAP_SERVICE_ABORT_REQ(g_pars.imsi);
Harald Welte4263c522018-12-06 11:56:27 +01004854 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4855 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4856
4857 /* Initiate paging via VTY */
4858 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4859 alt {
4860 [] SGsAP.receive(exp_resp) {
4861 setverdict(pass);
4862 }
4863 [] SGsAP.receive {
4864 setverdict(fail, "Received unexpected message on SGs");
4865 }
4866 }
4867
Philipp Maier34218102019-09-24 09:15:49 +02004868 /* While we are doing nothing, expect an SGsAP-SERVICE-ABORT-REQUEST
4869 * after some time */
4870 timer T := 10.0;
4871 T.start
4872 alt {
4873 [] SGsAP.receive(exp_serv_abrt)
4874 {
4875 setverdict(pass);
4876 }
4877 [] SGsAP.receive {
4878 setverdict(fail, "unexpected SGsAP message received");
4879 self.stop;
4880 }
4881 [] T.timeout {
4882 setverdict(fail, "MSC did not send SGsAP-SERVICE-ABORT-REQUEST");
4883 self.stop;
4884 }
4885 }
4886
4887 /* The SGs association must remain unchanged. */
Harald Welte4263c522018-12-06 11:56:27 +01004888 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4889
4890 f_sgsap_bssmap_screening();
4891
4892 setverdict(pass);
4893}
4894testcase TC_sgsap_paging_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004895 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004896 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004897 f_init(1, true);
4898 pars := f_init_pars(11819, true);
4899 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004900 vc_conn.done;
4901}
4902
4903/* Trigger a paging request via VTY and slip in an LU */
4904private function f_tc_sgsap_paging_and_lu(charstring id, BSC_ConnHdlrPars pars)
4905runs on BSC_ConnHdlr {
4906 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4907 f_init_handler(pars);
4908
4909 /* First we prepar the situation, where the SGs association is in state
4910 * NULL and the confirmed by radio contact indicator is set to false
4911 * as well. This can be archived by performing an SGs LU and then
4912 * resetting the VLR */
4913 f_sgs_perform_lu();
4914 f_sgsap_reset_mme(mp_mme_name);
4915 f_sleep(1.0);
4916 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4917
4918 /* Perform a paging, expect the paging messages on the SGs interface */
4919 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4920 alt {
4921 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
4922 setverdict(pass);
4923 }
4924 [] SGsAP.receive {
4925 setverdict(fail, "Received unexpected message on SGs");
4926 }
4927 }
4928
4929 /* Perform the LU as normal */
4930 f_sgs_perform_lu();
4931 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4932
4933 /* Expect a new paging request right after the LU */
4934 alt {
4935 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
4936 setverdict(pass);
4937 }
4938 [] SGsAP.receive {
4939 setverdict(fail, "Received unexpected message on SGs");
4940 }
4941 }
4942
4943 /* Test is done now, lets round everything up by rejecting the paging
4944 * cleanly. */
4945 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, user_rejected_mobile_terminating_CS_fallback_call));
4946 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4947
4948 f_sgsap_bssmap_screening();
4949
4950 setverdict(pass);
4951}
4952testcase TC_sgsap_paging_and_lu() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004953 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004954 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004955 f_init(1, true);
4956 pars := f_init_pars(11820, true);
4957 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_and_lu), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004958 vc_conn.done;
4959}
4960
4961/* Send unexpected unit-data through the SGs interface */
4962private function f_tc_sgsap_unexp_ud(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4963 f_init_handler(pars);
4964 f_sleep(1.0);
4965
4966 /* This simulates what happens when a subscriber without SGs
4967 * association gets unitdata via the SGs interface. */
4968
4969 /* Make sure the subscriber exists and the SGs association
4970 * is in NULL state */
4971 f_perform_lu();
4972 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4973
4974 /* Send some random unit data, the MSC/VLR should send a release
4975 * immediately. */
4976 SGsAP.send(ts_SGsAP_UL_UD(pars.imsi,'1234'O));
4977 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, IMSI_detached_for_EPS_nonEPS_services));
4978
4979 f_sgsap_bssmap_screening();
4980
4981 setverdict(pass);
4982}
4983testcase TC_sgsap_unexp_ud() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004984 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004985 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004986 f_init(1, true);
4987 pars := f_init_pars(11821, true);
4988 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_unexp_ud), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004989 vc_conn.done;
4990}
4991
4992/* Send unsolicited unit-data through the SGs interface */
4993private function f_tc_sgsap_unsol_ud(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4994 f_init_handler(pars);
4995 f_sleep(1.0);
4996
4997 /* This simulates what happens when the MME attempts to send unitdata
4998 * to a subscriber that is completely unknown to the VLR */
4999
5000 /* Send some random unit data, the MSC/VLR should send a release
5001 * immediately. */
5002 SGsAP.send(ts_SGsAP_UL_UD(pars.imsi,'1234'O));
5003 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, IMSI_unknown));
5004
5005 f_sgsap_bssmap_screening();
5006
Harald Welte4d15fa72020-08-19 08:58:28 +02005007 /* clean-up VLR state about this subscriber */
5008 f_imsi_detach_by_imsi();
5009
Harald Welte4263c522018-12-06 11:56:27 +01005010 setverdict(pass);
5011}
5012testcase TC_sgsap_unsol_ud() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005013 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005014 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005015 f_init(1, true);
5016 pars := f_init_pars(11822, true);
5017 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_unsol_ud), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005018 vc_conn.done;
5019}
5020
5021private altstep as_other_sms_sgs() runs on BSC_ConnHdlr {
5022 /* FIXME: Match an actual payload (second questionmark), the type is
5023 * octetstring, how do we use a tr_PDU_DTAP_MT here? */
5024 [] SGsAP.receive(tr_SGsAP_DL_UD(?,?)) {
5025 setverdict(fail, "Unexpected SMS related PDU from MSC");
5026 mtc.stop;
5027 }
5028}
5029
5030/* receive a MT-SMS delivered from the MSC/SMSC over an already existing SGsAP connection */
5031function f_mt_sms_sgs(inout SmsParameters spars)
5032runs on BSC_ConnHdlr {
5033 var template (value) TPDU_RP_DATA_MS_SGSN tp_mo;
5034 var template (value) RPDU_MS_SGSN rp_mo;
5035 var template (value) PDU_ML3_MS_NW l3_mo;
5036
5037 var template TPDU_RP_DATA_SGSN_MS tp_mt;
5038 var template RPDU_SGSN_MS rp_mt;
5039 var template PDU_ML3_NW_MS l3_mt;
5040
5041 var PDU_ML3_NW_MS sgsap_l3_mt;
5042
5043 var default d := activate(as_other_sms_sgs());
5044
5045 /* Expect CP-DATA(RP-DATA(SMS-DELIVER)) */
5046 tp_mt := tr_SMS_DELIVER(?, spars.tp.ud, spars.tp.pid, spars.tp.dcs, ?);
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09005047 rp_mt := tr_RP_DATA_MT(?, spars.rp.smsc_addr, omit, tp_mt);
Harald Welte4263c522018-12-06 11:56:27 +01005048 l3_mt := tr_ML3_MT_SMS(?, c_TIF_ORIG, tr_CP_DATA_MT(rp_mt));
5049
5050 SGsAP.receive(l3_mt) -> value sgsap_l3_mt;
5051
5052 /* Extract relevant identifiers */
5053 spars.tid := bit2int(sgsap_l3_mt.tiOrSkip.transactionId.tio);
5054 spars.rp.msg_ref := sgsap_l3_mt.msgs.sms.cP_DATA.cP_User_Data.cP_RPDU.rP_DATA_SGSN_MS.rP_MessageReference;
5055
5056 /* send CP-ACK for CP-DATA just received */
5057 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_REPL, ts_CP_ACK_MO);
5058
5059 SGsAP.send(l3_mo);
5060
5061 /* send RP-ACK for RP-DATA */
5062 rp_mo := ts_RP_ACK_MO(spars.rp.msg_ref);
5063 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_REPL, ts_CP_DATA_MO(rp_mo));
5064
5065 SGsAP.send(l3_mo);
5066
5067 /* expect CP-ACK for CP-DATA(RP-ACK) just sent */
5068 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_ORIG, tr_CP_ACK_MT);
5069
5070 SGsAP.receive(l3_mt);
5071
5072 deactivate(d);
5073
5074 setverdict(pass);
5075}
5076
5077/* submit a MO-SMS to MSC/SMSC over an already existing SGsAP connection */
5078function f_mo_sms_sgs(inout SmsParameters spars)
5079runs on BSC_ConnHdlr {
5080 var template (value) TPDU_RP_DATA_MS_SGSN tp_mo;
5081 var template (value) RPDU_MS_SGSN rp_mo;
5082 var template (value) PDU_ML3_MS_NW l3_mo;
5083
5084 var template TPDU_RP_DATA_SGSN_MS tp_mt;
5085 var template RPDU_SGSN_MS rp_mt;
5086 var template PDU_ML3_NW_MS l3_mt;
5087
5088 var default d := activate(as_other_sms_sgs());
5089
5090 /* just in case this is routed to SMPP.. */
5091 f_create_smpp_expect(hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue));
5092
5093 tp_mo := ts_SMS_SUBMIT(spars.tp.msg_ref, spars.tp.da, spars.tp.pid, spars.tp.dcs,
5094 spars.tp.udl, spars.tp.ud);
Vadim Yanitskiy437b5a62019-12-15 14:13:39 +09005095 rp_mo := ts_RP_DATA_MO(spars.rp.msg_ref, omit, spars.rp.smsc_addr, tp_mo);
Harald Welte4263c522018-12-06 11:56:27 +01005096 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_DATA_MO(rp_mo));
5097
5098 SGsAP.send(l3_mo);
5099
5100 /* receive CP-ACK for CP-DATA above */
5101 SGsAP.receive(tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_ACK_MT));
5102
5103 if (ispresent(spars.exp_rp_err)) {
5104 /* expect an RP-ERROR message from MSC with given cause */
5105 rp_mt := tr_RP_ERROR_MT(spars.rp.msg_ref, spars.exp_rp_err);
5106 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_DATA_MT(rp_mt));
5107 SGsAP.receive(l3_mt);
5108 /* send CP-ACK for CP-DATA just received */
5109 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_ACK_MO);
5110 SGsAP.send(l3_mo);
5111 } else {
5112 /* expect RP-ACK for RP-DATA */
5113 rp_mt := tr_RP_ACK_MT(spars.rp.msg_ref);
5114 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_DATA_MT(rp_mt));
5115 SGsAP.receive(l3_mt);
5116 /* send CP-ACO for CP-DATA just received */
5117 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_ACK_MO);
5118 SGsAP.send(l3_mo);
5119 }
5120
5121 deactivate(d);
5122
5123 setverdict(pass);
5124}
5125
5126private function f_vty_sms_send_conn_hdlr(charstring imsi, charstring msisdn, charstring text)
5127runs on BSC_ConnHdlr {
5128 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
5129}
5130
5131/* Send a MT SMS via SGs interface */
5132private function f_tc_sgsap_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5133 f_init_handler(pars);
5134 f_sgs_perform_lu();
5135 f_sleep(1.0);
5136 var SmsParameters spars := valueof(t_SmsPars);
5137 spars.tp.ud := 'C8329BFD064D9B53'O;
5138
5139 /* Trigger SMS via VTY */
5140 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
5141 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5142
5143 /* Expect a paging request and respond accordingly with a service request */
5144 SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, SMS_indicator, omit));
5145 SGsAP.send(ts_SGsAP_SERVICE_REQ(pars.imsi, SMS_indicator, EMM_CONNECTED));
5146
5147 /* Connection is now live, receive the MT-SMS */
5148 f_mt_sms_sgs(spars);
5149
5150 /* Expect a concluding release from the MSC */
5151 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, omit));
5152
5153 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
5154 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5155
5156 f_sgsap_bssmap_screening();
5157
5158 setverdict(pass);
5159}
5160testcase TC_sgsap_mt_sms() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005161 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005162 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005163 f_init(1, true);
5164 pars := f_init_pars(11823, true);
5165 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005166 vc_conn.done;
5167}
5168
5169/* Send a MO SMS via SGs interface */
5170private function f_tc_sgsap_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5171 f_init_handler(pars);
5172 f_sgs_perform_lu();
5173 f_sleep(1.0);
5174 var SmsParameters spars := valueof(t_SmsPars);
5175 spars.tp.ud := 'C8329BFD064D9B53'O;
5176
5177 /* Send the MO-SMS */
5178 f_mo_sms_sgs(spars);
5179
5180 /* Expect a concluding release from the MSC/VLR */
5181 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, omit));
5182
5183 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
5184 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5185
5186 setverdict(pass);
5187
5188 f_sgsap_bssmap_screening()
5189}
5190testcase TC_sgsap_mo_sms() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005191 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005192 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005193 f_init(1, true);
5194 pars := f_init_pars(11824, true);
5195 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mo_sms), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005196 vc_conn.done;
5197}
5198
5199/* Trigger sending of an MT sms via VTY but never respond to anything */
5200private function f_tc_sgsap_mt_sms_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5201 f_init_handler(pars, 170.0);
5202 f_sgs_perform_lu();
5203 f_sleep(1.0);
5204
5205 var SmsParameters spars := valueof(t_SmsPars);
5206 spars.tp.ud := 'C8329BFD064D9B53'O;
5207 var integer page_count := 0;
5208 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5209 var template PDU_SGsAP exp_pag_req := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, SMS_indicator, omit);
5210 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
5211 exp_pag_req.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
5212
5213 /* Trigger SMS via VTY */
5214 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
5215
Neels Hofmeyr16237742019-03-06 15:34:01 +01005216 /* Expect the MSC/VLR to page exactly once */
5217 SGsAP.receive(exp_pag_req);
Harald Welte4263c522018-12-06 11:56:27 +01005218
5219 /* Wait some time to make sure the MSC is not delivering any further
5220 * paging messages or anything else that could be unexpected. */
5221 timer T := 20.0;
5222 T.start
5223 alt {
5224 [] SGsAP.receive(exp_pag_req)
5225 {
5226 setverdict(fail, "paging seems not to stop!");
5227 mtc.stop;
5228 }
5229 [] SGsAP.receive {
5230 setverdict(fail, "unexpected SGsAP message received");
5231 self.stop;
5232 }
5233 [] T.timeout {
5234 setverdict(pass);
5235 }
5236 }
5237
5238 /* Even on a failed paging the SGs Association should stay intact */
5239 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5240
Philipp Maier26bdb8c2019-09-24 09:21:12 +02005241 /* Make sure that the SMS we just inserted is cleared and the
5242 * subscriber is expired. This is necessary because otherwise the MSC
5243 * might re-try the SMS delivery and disturb the following tests. */
Harald Welte4263c522018-12-06 11:56:27 +01005244
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01005245 f_vty_sms_clear(hex2str(g_pars.imsi));
5246
Harald Welte4263c522018-12-06 11:56:27 +01005247 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " expire");
5248
5249 setverdict(pass);
Neels Hofmeyrb0f82342019-03-06 15:36:51 +01005250
5251 f_sgsap_bssmap_screening();
Harald Welte4263c522018-12-06 11:56:27 +01005252}
5253testcase TC_sgsap_mt_sms_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005254 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005255 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005256 f_init(1, true);
5257 pars := f_init_pars(11825, true);
5258 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005259 vc_conn.done;
5260}
5261
5262/* Trigger sending of an MT sms via VTY but reject the paging immediately */
5263private function f_tc_sgsap_mt_sms_and_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5264 f_init_handler(pars, 150.0);
5265 f_sgs_perform_lu();
5266 f_sleep(1.0);
5267
5268 var SmsParameters spars := valueof(t_SmsPars);
5269 spars.tp.ud := 'C8329BFD064D9B53'O;
5270 var integer page_count := 0;
5271 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5272 var template PDU_SGsAP exp_pag_req := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, SMS_indicator, omit);
5273 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
5274 exp_pag_req.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
5275
5276 /* Trigger SMS via VTY */
5277 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
5278
5279 /* Expect a paging request and reject it immediately */
5280 SGsAP.receive(exp_pag_req);
5281 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, IMSI_unknown));
5282
5283 /* The MSC/VLR should no longer try to page once the paging has been
5284 * rejected. Wait some time and check if there are no unexpected
5285 * messages on the SGs interface. */
5286 timer T := 20.0;
5287 T.start
5288 alt {
5289 [] SGsAP.receive(exp_pag_req)
5290 {
5291 setverdict(fail, "paging seems not to stop!");
5292 mtc.stop;
5293 }
5294 [] SGsAP.receive {
5295 setverdict(fail, "unexpected SGsAP message received");
5296 self.stop;
5297 }
5298 [] T.timeout {
5299 setverdict(pass);
5300 }
5301 }
5302
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01005303 f_vty_sms_clear(hex2str(g_pars.imsi));
5304
Harald Welte4263c522018-12-06 11:56:27 +01005305 /* A rejected paging with IMSI_unknown (see above) should always send
5306 * the SGs association to NULL. */
5307 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
5308
5309 f_sgsap_bssmap_screening();
5310
Harald Welte4263c522018-12-06 11:56:27 +01005311 setverdict(pass);
5312}
5313testcase TC_sgsap_mt_sms_and_reject() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005314 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005315 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005316 f_init(1, true);
5317 pars := f_init_pars(11826, true);
5318 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms_and_reject), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005319 vc_conn.done;
5320}
5321
5322/* Perform an MT CSDB call including LU */
5323private function f_mt_lu_and_csfb_call(charstring id, BSC_ConnHdlrPars pars, boolean bssmap_lu) runs on BSC_ConnHdlr {
5324 f_init_handler(pars);
5325
5326 /* Be sure that the BSSMAP reset is done before we begin. */
5327 f_sleep(2.0);
5328
5329 /* Testcase variation: See what happens when we do a regular BSSMAP
5330 * LU first (this should not hurt in any way!) */
5331 if (bssmap_lu) {
5332 f_perform_lu();
5333 }
5334
5335 f_sgs_perform_lu();
5336 f_sleep(1.0);
5337
5338 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5339 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Harald Welte4263c522018-12-06 11:56:27 +01005340
5341 /* Initiate a call via MNCC interface */
5342 f_mt_call_initate(cpars);
5343
5344 /* Expect a paging request and respond accordingly with a service request */
5345 SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit));
5346 SGsAP.send(ts_SGsAP_SERVICE_REQ(pars.imsi, CS_call_indicator, EMM_CONNECTED));
5347
5348 /* Complete the call, hold it for some time and then tear it down */
5349 f_mt_call_complete(cpars);
5350 f_sleep(3.0);
Harald Welte4c422b72019-02-17 16:27:10 +01005351 f_call_hangup(cpars, true, is_csfb := true);
Harald Welte4263c522018-12-06 11:56:27 +01005352
5353 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
5354 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5355
Harald Welte4263c522018-12-06 11:56:27 +01005356 /* Test for successful return by triggering a paging, when the paging
5357 * request is received via SGs, we can be sure that the MSC/VLR has
5358 * recognized that the UE is now back on 4G */
5359 f_sleep(1.0);
5360 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
5361 alt {
5362 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
5363 setverdict(pass);
5364 }
5365 [] SGsAP.receive {
5366 setverdict(fail, "Received unexpected message on SGs");
5367 }
5368 }
5369
5370 f_sgsap_bssmap_screening();
5371
5372 setverdict(pass);
5373}
5374
5375/* Perform a regular BSSAP LU first, do a SGSAP LU and then make a CSFB call */
5376private function f_tc_bssap_lu_sgsap_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5377 f_mt_lu_and_csfb_call(id, pars, true);
5378}
5379testcase TC_bssap_lu_sgsap_lu_and_mt_call() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005380 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005381 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005382 f_init(1, true);
5383 pars := f_init_pars(118139, true);
Harald Welte4263c522018-12-06 11:56:27 +01005384
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005385 vc_conn := f_start_handler_with_pars(refers(f_tc_bssap_lu_sgsap_lu_and_mt_call), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005386 vc_conn.done;
5387}
5388
Harald Welte4263c522018-12-06 11:56:27 +01005389/* Perform a SGSAP LU and then make a CSFB call */
5390private function f_tc_sgsap_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5391 f_mt_lu_and_csfb_call(id, pars, false);
5392}
5393testcase TC_sgsap_lu_and_mt_call() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005394 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005395 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005396 f_init(1, true);
5397 pars := f_init_pars(11827, true);
Harald Welte4263c522018-12-06 11:56:27 +01005398
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005399 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_and_mt_call), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005400 vc_conn.done;
5401}
5402
Philipp Maier628c0052019-04-09 17:36:57 +02005403/* Simulate an HLR/VLR failure */
5404private function f_tc_sgsap_vlr_failure(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5405 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
5406 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5407
5408 var PDU_SGsAP lur;
5409
5410 f_init_handler(pars);
5411
5412 /* Attempt location update (which is expected to fail) */
5413 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
5414 ts_SGsAP_LAI('901'H, '70'H, 2342)));
5415 SGsAP.send(lur);
5416
5417 /* Respond to SGsAP-RESET-INDICATION from VLR */
5418 alt {
5419 [] SGsAP.receive(tr_SGsAP_RESET_IND_VLR(vlr_name)); {
5420 SGsAP.send(valueof(ts_SGsAP_RESET_ACK_MME(mme_name)));
5421 setverdict(pass);
5422 }
5423 [] SGsAP.receive {
5424 setverdict(fail, "Received unexpected message on SGs");
5425 }
5426 }
5427
5428 f_sleep(1.0);
5429 setverdict(pass);
5430}
5431testcase TC_sgsap_vlr_failure() runs on MTC_CT {
5432 var BSC_ConnHdlrPars pars;
5433 var BSC_ConnHdlr vc_conn;
5434 f_init(1, true, false);
5435 pars := f_init_pars(11811, true, false);
5436 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_vlr_failure), pars);
5437 vc_conn.done;
5438}
5439
Harald Welte4263c522018-12-06 11:56:27 +01005440/* SGs TODO:
5441 * LU attempt for IMSI without NAM_PS in HLR
5442 * LU attempt with AUTH FAIL due to invalid RES/SRES
5443 * LU attempt with no response from HLR (VLR should timeout + LU REJ)
5444 * LU attempt with new TMSI but without TMSI REALL CMPL baco to VLR
5445 * implicit IMSI detach from EPS
5446 * implicit IMSI detach from non-EPS
5447 * MM INFO
5448 *
5449 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01005450
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005451private function f_tc_ho_inter_bsc_unknown_cell(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5452 f_init_handler(pars);
5453 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005454
5455 f_perform_lu();
5456 f_mo_call_establish(cpars);
5457
5458 f_sleep(1.0);
5459
5460 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5461 var BssmapCause cause := enum2int(cause_val);
5462
5463 var template BSSMAP_FIELD_CellIdentificationList cil;
5464 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('023'H, '42'H, 999) } };
5465
5466 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5467 BSSAP.receive(tr_BSSMAP_HandoverRequiredReject);
5468
5469 f_call_hangup(cpars, true);
5470}
5471testcase TC_ho_inter_bsc_unknown_cell() runs on MTC_CT {
5472 var BSC_ConnHdlr vc_conn;
5473 f_init();
5474
5475 vc_conn := f_start_handler(refers(f_tc_ho_inter_bsc_unknown_cell), 53);
5476 vc_conn.done;
5477}
5478
5479private altstep as_mgcp_ack_all_mdcx(CallParameters cpars) runs on BSC_ConnHdlr {
5480 var MgcpCommand mgcp_cmd;
5481 [] MGCP.receive(tr_MDCX) -> value mgcp_cmd {
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02005482 var SDP_Message sdp := valueof(ts_SDP(cpars.mgw_conn_2.mgw_rtp_ip, cpars.mgw_conn_2.mgw_rtp_ip,
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005483 hex2str(cpars.mgcp_call_id), "42",
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02005484 cpars.mgw_conn_2.mgw_rtp_port,
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005485 { int2str(cpars.rtp_payload_type) },
5486 { valueof(ts_SDP_rtpmap(cpars.rtp_payload_type,
5487 cpars.rtp_sdp_format)),
5488 valueof(ts_SDP_ptime(20)) }));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02005489 MGCP.send(ts_MDCX_ACK(mgcp_cmd.line.trans_id, cpars.mgw_conn_2.mgcp_connection_id, sdp));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005490 repeat;
5491 }
5492}
5493
5494private function f_tc_ho_inter_bsc0(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5495 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005496
5497 f_init_handler(pars);
5498
5499 f_vty_transceive(MSCVTY, "configure terminal");
5500 f_vty_transceive(MSCVTY, "msc");
5501 f_vty_transceive(MSCVTY, "neighbor a cgi 262 42 23 42 ran-pc 0.24.1");
5502 f_vty_transceive(MSCVTY, "neighbor a lac 5 ran-pc 0.24.2");
5503 f_vty_transceive(MSCVTY, "exit");
5504 f_vty_transceive(MSCVTY, "exit");
5505
5506 f_perform_lu();
5507 f_mo_call_establish(cpars);
5508
5509 f_sleep(1.0);
5510
5511 var default ack_mdcx := activate(as_mgcp_ack_all_mdcx(cpars));
5512
5513 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5514 var BssmapCause cause := enum2int(cause_val);
5515
5516 var template BSSMAP_FIELD_CellIdentificationList cil;
5517 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('023'H, '42'H, 5) } };
5518
5519 /* old BSS sends Handover Required */
5520 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5521
5522 /* Now the action goes on in f_tc_ho_inter_bsc1() */
5523
5524 /* MSC forwards the RR Handover Command to old BSS */
5525 var PDU_BSSAP ho_command;
5526 BSSAP.receive(tr_BSSMAP_HandoverCommand) -> value ho_command;
5527
5528 log("GOT HandoverCommand", ho_command);
5529
5530 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
5531
5532 /* f_tc_ho_inter_bsc1() completes Handover, then expecting a Clear here. */
5533 f_expect_clear();
5534
5535 log("FIRST inter-BSC Handover done");
5536
5537
5538 /* ------------------------ */
5539
5540 /* Ok, that went well, now the other BSC is handovering back here --
5541 * from now on this here is the new BSS. */
5542 f_create_bssmap_exp_handoverRequest(193);
5543
5544 var PDU_BSSAP ho_request;
5545 BSSAP.receive(tr_BSSMAP_HandoverRequest) -> value ho_request;
5546
5547 /* new BSS composes a RR Handover Command */
5548 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5549 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
5550 var BSSMAP_IE_AoIP_TransportLayerAddress tla := valueof(ts_BSSMAP_IE_AoIP_TLA4('01020304'O, 2342));
5551 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5552 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5553
5554 /* Now f_tc_ho_inter_bsc1() expects HandoverCommand */
5555
5556 f_sleep(0.5);
5557
5558 /* Notify that the MS is now over here */
5559
5560 BSSAP.send(ts_BSSMAP_HandoverDetect);
5561 f_sleep(0.1);
5562 BSSAP.send(ts_BSSMAP_HandoverComplete);
5563
5564 f_sleep(3.0);
5565
5566 deactivate(ack_mdcx);
5567
5568 var default ccrel := activate(as_optional_cc_rel(cpars, true));
5569
5570 /* blatant cheating */
5571 var N_Sd_Array last_n_sd := f_bssmap_last_n_sd();
5572 last_n_sd[0] := 3;
5573 f_bssmap_continue_after_n_sd(last_n_sd);
5574
5575 f_call_hangup(cpars, true);
5576 f_sleep(1.0);
5577 deactivate(ccrel);
5578
5579 setverdict(pass);
5580}
5581private function f_tc_ho_inter_bsc1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5582 f_init_handler(pars);
5583 f_create_bssmap_exp_handoverRequest(194);
5584
5585 var PDU_BSSAP ho_request;
5586 BSSAP.receive(tr_BSSMAP_HandoverRequest) -> value ho_request;
5587
5588 /* new BSS composes a RR Handover Command */
5589 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5590 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
5591 var BSSMAP_IE_AoIP_TransportLayerAddress tla := valueof(ts_BSSMAP_IE_AoIP_TLA4('01020304'O, 2342));
5592 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5593 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5594
5595 /* Now f_tc_ho_inter_bsc0() expects HandoverCommand */
5596
5597 f_sleep(0.5);
5598
5599 /* Notify that the MS is now over here */
5600
5601 BSSAP.send(ts_BSSMAP_HandoverDetect);
5602 f_sleep(0.1);
5603 BSSAP.send(ts_BSSMAP_HandoverComplete);
5604
5605 f_sleep(3.0);
5606
5607 /* Now I'd like to f_call_hangup() but we don't know any cpars here. So
5608 * ... handover back to the first BSC :P */
5609
5610 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5611 var BssmapCause cause := enum2int(cause_val);
5612
5613 var template BSSMAP_FIELD_CellIdentificationList cil;
5614 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('262'H, '42'H, 23) } };
5615
5616 /* old BSS sends Handover Required */
5617 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5618
5619 /* Now the action goes on in f_tc_ho_inter_bsc0() */
5620
5621 /* MSC forwards the RR Handover Command to old BSS */
5622 var PDU_BSSAP ho_command;
5623 BSSAP.receive(tr_BSSMAP_HandoverCommand) -> value ho_command;
5624
5625 log("GOT HandoverCommand", ho_command);
5626
5627 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
5628
5629 /* f_tc_ho_inter_bsc1() completes Handover, then expecting a Clear here. */
5630 f_expect_clear();
5631 setverdict(pass);
5632}
5633testcase TC_ho_inter_bsc() runs on MTC_CT {
5634 var BSC_ConnHdlr vc_conn0;
5635 var BSC_ConnHdlr vc_conn1;
5636 f_init(2);
5637
5638 var BSC_ConnHdlrPars pars0 := f_init_pars(53);
5639 var BSC_ConnHdlrPars pars1 := f_init_pars(53);
5640
5641 vc_conn0 := f_start_handler_with_pars(refers(f_tc_ho_inter_bsc0), pars0, 0);
5642 vc_conn1 := f_start_handler_with_pars(refers(f_tc_ho_inter_bsc1), pars1, 1);
5643 vc_conn0.done;
5644 vc_conn1.done;
5645}
5646
5647function f_ML3_patch_seq_nr_MS_NW(in uint2_t seq_nr, inout octetstring enc_l3) {
5648 log("MS_NW patching N(SD)=", seq_nr, " into dtap ", enc_l3);
5649 enc_l3[2] := (enc_l3[2] and4b '3f'O) or4b bit2oct(int2bit(seq_nr, 8) << 6);
5650 log("MS_NW patched enc_l3: ", enc_l3);
5651}
5652
5653private function f_tc_ho_inter_msc_out(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5654 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005655 var hexstring ho_number := f_gen_msisdn(99999);
5656
5657 f_init_handler(pars);
5658
5659 f_create_mncc_expect(hex2str(ho_number));
5660
5661 f_vty_transceive(MSCVTY, "configure terminal");
5662 f_vty_transceive(MSCVTY, "msc");
5663 f_vty_transceive(MSCVTY, "neighbor a cgi 017 017 1 1 msc-ipa-name msc-017-017-1");
5664 f_vty_transceive(MSCVTY, "exit");
5665 f_vty_transceive(MSCVTY, "exit");
5666
5667 f_perform_lu();
5668 f_mo_call_establish(cpars);
5669
5670 f_sleep(1.0);
5671
5672 var default ack_mdcx := activate(as_mgcp_ack_all_mdcx(cpars));
5673
5674 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5675 var BssmapCause cause := enum2int(cause_val);
5676
5677 var template BSSMAP_FIELD_CellIdentificationList cil;
5678 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('017'H, '017'H, 1) } };
5679
5680 /* old BSS sends Handover Required */
5681 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5682
5683 /* The target cell 017-017 LAC 1 is configured to be a remote MSC of name "msc-017-017-1".
5684 * This MSC tries to reach the other MSC via GSUP. */
5685
5686 var octetstring remote_msc_name := '6D73632D3031372D3031372D3100'O; /* "msc-017-017-1\0" as octetstring */
5687 var GSUP_PDU prep_ho_req;
5688 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_HANDOVER_REQUEST,
5689 pars.imsi, destination_name := remote_msc_name)) -> value prep_ho_req;
5690
5691 var GSUP_IeValue source_name_ie;
5692 f_gsup_find_ie(prep_ho_req, OSMO_GSUP_SOURCE_NAME_IE, source_name_ie);
5693 var octetstring local_msc_name := source_name_ie.source_name;
5694
5695 /* Remote MSC has figured out its BSC and signals success */
5696 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5697 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
5698 var PDU_BSSAP ho_req_ack := valueof(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5699 aoIPTransportLayer := omit,
5700 speechCodec := ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5701 GSUP.send(ts_GSUP_E_PrepareHandoverResult(
5702 pars.imsi,
5703 ho_number,
5704 remote_msc_name, local_msc_name,
5705 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006, enc_PDU_BSSAP(ho_req_ack)))));
5706
5707 /* MSC forwards the RR Handover Command to old BSS */
5708 BSSAP.receive(tr_BSSMAP_HandoverCommand);
5709
5710 /* The MS shows up at remote new BSS */
5711
5712 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PROCESS_ACCESS_SIGNALLING_REQUEST,
5713 pars.imsi, remote_msc_name, local_msc_name,
5714 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5715 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverDetect))))));
5716 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
5717 f_sleep(0.1);
5718
5719 /* Save the MS sequence counters for use on the other connection */
5720 var N_Sd_Array last_n_sd := f_bssmap_last_n_sd();
5721
5722 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_SEND_END_SIGNAL_REQUEST,
5723 pars.imsi, remote_msc_name, local_msc_name,
5724 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5725 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverComplete))))));
5726
5727 /* The local BSS conn clears, all communication goes via remote MSC now */
5728 f_expect_clear();
5729
5730 /**********************************/
5731 /* Play through some signalling across the inter-MSC link.
5732 * This is a copy of f_tc_lu_and_mo_ussd_single_request() translated into GSUP AN-APDUs. */
5733
5734 if (false) {
5735 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
5736 invoke_id := 5, /* Phone may not start from 0 or 1 */
5737 op_code := SS_OP_CODE_PROCESS_USS_REQ,
5738 ussd_string := "*#100#"
5739 );
5740
5741 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
5742 invoke_id := 5, /* InvokeID shall be the same for both REQ and RSP */
5743 op_code := SS_OP_CODE_PROCESS_USS_REQ,
5744 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
5745 )
5746
5747 /* Compose a new SS/REGISTER message with request */
5748 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
5749 tid := 1, /* We just need a single transaction */
5750 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
5751 facility := valueof(facility_req)
5752 );
5753 var PDU_ML3_MS_NW ussd_req_v := valueof(ussd_req);
5754
5755 /* Compose SS/RELEASE_COMPLETE template with expected response */
5756 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
5757 tid := 1, /* Response should arrive within the same transaction */
5758 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
5759 facility := valueof(facility_rsp)
5760 );
5761
5762 /* Compose expected MSC -> HLR message */
5763 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
5764 imsi := g_pars.imsi,
5765 state := OSMO_GSUP_SESSION_STATE_BEGIN,
5766 ss := valueof(facility_req)
5767 );
5768
5769 /* To be used for sending response with correct session ID */
5770 var GSUP_PDU gsup_req_complete;
5771
5772 /* Request own number */
5773 /* From remote MSC instead of BSSAP directly */
5774 /* Patch the correct N_SD value into the message. */
5775 var octetstring l3_enc := enc_PDU_ML3_MS_NW(ussd_req_v);
5776 var RAN_Emulation.ConnectionData cd;
5777 f_ML3_patch_seq_nr_MS_NW(f_next_n_sd(last_n_sd, f_ML3_n_sd_idx(ussd_req_v)), l3_enc);
5778 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PROCESS_ACCESS_SIGNALLING_REQUEST,
5779 pars.imsi, remote_msc_name, local_msc_name,
5780 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5781 enc_PDU_BSSAP(valueof(ts_BSSAP_DTAP(l3_enc)))
5782 ))
5783 ));
5784
5785 /* Expect GSUP message containing the SS payload */
5786 gsup_req_complete := f_expect_gsup_msg(gsup_req);
5787
5788 /* Compose the response from HLR using received session ID */
5789 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
5790 imsi := g_pars.imsi,
5791 sid := gsup_req_complete.ies[1].val.session_id,
5792 state := OSMO_GSUP_SESSION_STATE_END,
5793 ss := valueof(facility_rsp)
5794 );
5795
5796 /* Finally, HLR terminates the session */
5797 GSUP.send(gsup_rsp);
5798
5799 /* The USSD response goes out to remote MSC, on GSUP E instead of BSSAP */
5800 var GSUP_PDU gsup_ussd_rsp;
5801 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_FORWARD_ACCESS_SIGNALLING_REQUEST,
5802 pars.imsi, destination_name := remote_msc_name)) -> value gsup_ussd_rsp;
5803
5804 var GSUP_IeValue an_apdu;
5805 if (not f_gsup_find_ie(gsup_ussd_rsp, OSMO_GSUP_AN_APDU_IE, an_apdu)) {
5806 setverdict(fail, "No AN-APDU in received GSUP message. Expected USSD response in DTAP, got", gsup_ussd_rsp);
5807 mtc.stop;
5808 }
5809 var PDU_BSSAP bssap_dtap_mt := dec_PDU_BSSAP(an_apdu.an_apdu.pdu);
5810 var PDU_ML3_NW_MS dtap_mt := dec_PDU_ML3_NW_MS(bssap_dtap_mt.pdu.dtap);
5811 log("Expecting", ussd_rsp);
5812 log("Got", dtap_mt);
5813 if (not match(dtap_mt, ussd_rsp)) {
5814 setverdict(fail, "Unexpected GSUP message. Expected USSD response in DTAP, got", gsup_ussd_rsp);
5815 mtc.stop;
5816 }
5817 }
5818 /**********************************/
5819
5820
5821 /* inter-MSC handover back to the first MSC */
5822 f_create_bssmap_exp_handoverRequest(193);
5823 cil := { cIl_CGI := { ts_BSSMAP_CI_CGI('262'H, '42'H, 23, 42) } };
5824
5825 /* old BSS sends Handover Required, via inter-MSC E link: like
5826 * BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5827 * but via GSUP */
5828 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_SUBSEQUENT_HANDOVER_REQUEST,
5829 pars.imsi, remote_msc_name, local_msc_name,
5830 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5831 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverRequired(cause, cil)))
5832 ))
5833 ));
5834
5835 /* MSC asks local BSS to prepare Handover to it */
5836 BSSAP.receive(tr_BSSMAP_HandoverRequest);
5837
5838 /* Make sure the new BSSAP conn continues with the correct N_SD sequence numbers */
5839 f_bssmap_continue_after_n_sd(last_n_sd);
5840
5841 /* new BSS composes a RR Handover Command */
5842 rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5843 rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
5844 var BSSMAP_IE_AoIP_TransportLayerAddress tla := valueof(ts_BSSMAP_IE_AoIP_TLA4('01020304'O, 2342));
5845 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5846 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5847
5848 /* HandoverCommand goes out via remote MSC-I */
5849 var GSUP_PDU prep_subsq_ho_res;
5850 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_SUBSEQUENT_HANDOVER_RESULT,
5851 pars.imsi, destination_name := remote_msc_name)) -> value prep_subsq_ho_res;
5852
5853 /* MS shows up at the local BSS */
5854 BSSAP.send(ts_BSSMAP_HandoverDetect);
5855 f_sleep(0.1);
5856 BSSAP.send(ts_BSSMAP_HandoverComplete);
5857
5858 /* Handover Succeeded message */
5859 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_FORWARD_ACCESS_SIGNALLING_REQUEST,
5860 pars.imsi, destination_name := remote_msc_name));
5861
5862 /* MS has handovered to here, Clear Command goes out via remote MSC-I -- in form of a GSUP Close. */
5863 GSUP.receive(tr_GSUP_E_NO_PDU(OSMO_GSUP_MSGT_E_CLOSE,
5864 pars.imsi, destination_name := remote_msc_name));
5865
5866 /* Handover ends successfully. Call goes on for a little longer and then we hang up. */
5867
5868 f_sleep(1.0);
5869 deactivate(ack_mdcx);
5870
5871 /* FIXME: the inter-MSC call has put a number of MNCC messages in the queue, which above code should expect and
5872 * clear out. The f_call_hangup() expects an MNCC_REL_IND, so, for the time being, just clear the MNCC messages
5873 * before starting the call hangup. Instead of this, the individual messages should be tested for above. */
5874 MNCC.clear;
5875
5876 var default ccrel := activate(as_optional_cc_rel(cpars, true));
5877 f_call_hangup(cpars, true);
5878 f_sleep(1.0);
5879 deactivate(ccrel);
5880
5881 setverdict(pass);
5882}
5883testcase TC_ho_inter_msc_out() runs on MTC_CT {
5884 var BSC_ConnHdlr vc_conn;
5885 f_init(1);
5886
5887 var BSC_ConnHdlrPars pars := f_init_pars(54);
5888
5889 vc_conn := f_start_handler_with_pars(refers(f_tc_ho_inter_msc_out), pars, 0);
5890 vc_conn.done;
5891}
5892
Oliver Smith1d118ff2019-07-03 10:57:35 +02005893private function f_tc_lu_imsi_auth_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5894 pars.net.expect_auth := true;
5895 pars.net.expect_imei := true;
5896 f_init_handler(pars);
5897 f_perform_lu();
5898}
5899testcase TC_lu_imsi_auth_tmsi_check_imei() runs on MTC_CT {
5900 var BSC_ConnHdlr vc_conn;
5901 f_init();
5902 f_vty_config(MSCVTY, "network", "authentication required");
5903 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
5904
5905 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei), 5);
5906 vc_conn.done;
5907}
5908
5909private function f_tc_lu_imsi_auth3g_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5910 pars.net.expect_auth := true;
5911 pars.use_umts_aka := true;
5912 pars.net.expect_imei := true;
5913 f_init_handler(pars);
5914 f_perform_lu();
5915}
5916testcase TC_lu_imsi_auth3g_tmsi_check_imei() runs on MTC_CT {
5917 var BSC_ConnHdlr vc_conn;
5918 f_init();
5919 f_vty_config(MSCVTY, "network", "authentication required");
5920 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
5921
5922 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi_check_imei), 5);
5923 vc_conn.done;
5924}
5925
5926private function f_tc_lu_imsi_noauth_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5927 pars.net.expect_imei := true;
5928 f_init_handler(pars);
5929 f_perform_lu();
5930}
5931testcase TC_lu_imsi_noauth_tmsi_check_imei() runs on MTC_CT {
5932 var BSC_ConnHdlr vc_conn;
5933 f_init();
5934 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
5935
5936 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi_check_imei), 5);
5937 vc_conn.done;
5938}
5939
5940private function f_tc_lu_imsi_noauth_notmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5941 pars.net.expect_tmsi := false;
5942 pars.net.expect_imei := true;
5943 f_init_handler(pars);
5944 f_perform_lu();
5945}
5946testcase TC_lu_imsi_noauth_notmsi_check_imei() runs on MTC_CT {
5947 var BSC_ConnHdlr vc_conn;
5948 f_init();
5949 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
5950 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
5951
5952 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi_check_imei), 5);
5953 vc_conn.done;
5954}
5955
5956private function f_tc_lu_imsi_auth_tmsi_check_imei_nack(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5957 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02005958
5959 pars.net.expect_auth := true;
5960 pars.net.expect_imei := true;
5961 pars.net.check_imei_result := OSMO_GSUP_IMEI_RESULT_NACK;
5962 f_init_handler(pars);
5963
5964 /* Cannot use f_perform_lu() as we expect a reject */
5965 l3_lu := f_build_lu_imsi(g_pars.imsi)
5966 f_create_gsup_expect(hex2str(g_pars.imsi));
5967 f_bssap_compl_l3(l3_lu);
5968 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
5969
5970 f_mm_common();
5971 f_msc_lu_hlr();
5972 f_mm_imei();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02005973 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02005974 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02005975}
5976testcase TC_lu_imsi_auth_tmsi_check_imei_nack() runs on MTC_CT {
5977 var BSC_ConnHdlr vc_conn;
5978 f_init();
5979 f_vty_config(MSCVTY, "network", "authentication required");
5980 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
5981
5982 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_nack), 5);
5983 vc_conn.done;
5984}
5985
5986private function f_tc_lu_imsi_auth_tmsi_check_imei_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5987 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02005988
5989 pars.net.expect_auth := true;
5990 pars.net.expect_imei := true;
5991 pars.net.check_imei_error := true;
5992 f_init_handler(pars);
5993
5994 /* Cannot use f_perform_lu() as we expect a reject */
5995 l3_lu := f_build_lu_imsi(g_pars.imsi)
5996 f_create_gsup_expect(hex2str(g_pars.imsi));
5997 f_bssap_compl_l3(l3_lu);
5998 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
5999
6000 f_mm_common();
6001 f_msc_lu_hlr();
6002 f_mm_imei();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02006003 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02006004 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02006005}
6006testcase TC_lu_imsi_auth_tmsi_check_imei_err() runs on MTC_CT {
6007 var BSC_ConnHdlr vc_conn;
6008 f_init();
6009 f_vty_config(MSCVTY, "network", "authentication required");
6010 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6011
6012 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_err), 5);
6013 vc_conn.done;
6014}
6015
6016private function f_tc_lu_imsi_auth_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6017 pars.net.expect_auth := true;
6018 pars.net.expect_imei_early := true;
6019 f_init_handler(pars);
6020 f_perform_lu();
6021}
6022testcase TC_lu_imsi_auth_tmsi_check_imei_early() runs on MTC_CT {
6023 var BSC_ConnHdlr vc_conn;
6024 f_init();
6025 f_vty_config(MSCVTY, "network", "authentication required");
6026 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6027
6028 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early), 5);
6029 vc_conn.done;
6030}
6031
6032private function f_tc_lu_imsi_auth3g_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6033 pars.net.expect_auth := true;
6034 pars.use_umts_aka := true;
6035 pars.net.expect_imei_early := true;
6036 f_init_handler(pars);
6037 f_perform_lu();
6038}
6039testcase TC_lu_imsi_auth3g_tmsi_check_imei_early() runs on MTC_CT {
6040 var BSC_ConnHdlr vc_conn;
6041 f_init();
6042 f_vty_config(MSCVTY, "network", "authentication required");
6043 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6044
6045 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi_check_imei_early), 5);
6046 vc_conn.done;
6047}
6048
6049private function f_tc_lu_imsi_noauth_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6050 pars.net.expect_imei_early := true;
6051 f_init_handler(pars);
6052 f_perform_lu();
6053}
6054testcase TC_lu_imsi_noauth_tmsi_check_imei_early() runs on MTC_CT {
6055 var BSC_ConnHdlr vc_conn;
6056 f_init();
6057 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6058
6059 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi_check_imei_early), 5);
6060 vc_conn.done;
6061}
6062
6063private function f_tc_lu_imsi_noauth_notmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6064 pars.net.expect_tmsi := false;
6065 pars.net.expect_imei_early := true;
6066 f_init_handler(pars);
6067 f_perform_lu();
6068}
6069testcase TC_lu_imsi_noauth_notmsi_check_imei_early() runs on MTC_CT {
6070 var BSC_ConnHdlr vc_conn;
6071 f_init();
6072 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
6073 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6074
6075 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi_check_imei_early), 5);
6076 vc_conn.done;
6077}
6078
6079private function f_tc_lu_imsi_auth_tmsi_check_imei_early_nack(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6080 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02006081
6082 pars.net.expect_auth := true;
6083 pars.net.expect_imei_early := true;
6084 pars.net.check_imei_result := OSMO_GSUP_IMEI_RESULT_NACK;
6085 f_init_handler(pars);
6086
6087 /* Cannot use f_perform_lu() as we expect a reject */
6088 l3_lu := f_build_lu_imsi(g_pars.imsi)
6089 f_create_gsup_expect(hex2str(g_pars.imsi));
6090 f_bssap_compl_l3(l3_lu);
6091 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
6092
6093 f_mm_imei_early();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02006094 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02006095 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02006096}
6097testcase TC_lu_imsi_auth_tmsi_check_imei_early_nack() runs on MTC_CT {
6098 var BSC_ConnHdlr vc_conn;
6099 f_init();
6100 f_vty_config(MSCVTY, "network", "authentication required");
6101 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6102
6103 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early_nack), 5);
6104 vc_conn.done;
6105}
6106
6107private function f_tc_lu_imsi_auth_tmsi_check_imei_early_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6108 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02006109
6110 pars.net.expect_auth := true;
6111 pars.net.expect_imei_early := true;
6112 pars.net.check_imei_error := true;
6113 f_init_handler(pars);
6114
6115 /* Cannot use f_perform_lu() as we expect a reject */
6116 l3_lu := f_build_lu_imsi(g_pars.imsi)
6117 f_create_gsup_expect(hex2str(g_pars.imsi));
6118 f_bssap_compl_l3(l3_lu);
6119 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
6120
6121 f_mm_imei_early();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02006122 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02006123 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02006124}
6125testcase TC_lu_imsi_auth_tmsi_check_imei_early_err() runs on MTC_CT {
6126 var BSC_ConnHdlr vc_conn;
6127 f_init();
6128 f_vty_config(MSCVTY, "network", "authentication required");
6129 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6130
6131 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early_err), 5);
6132 vc_conn.done;
6133}
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006134
Neels Hofmeyr8df69622019-11-02 19:16:03 +01006135friend function f_tc_invalid_mgcp_crash(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6136 f_init_handler(pars);
6137 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
6138
6139 /* Set invalid IP address so that osmo-msc discards the rtp_stream and MGCP endpoint FSM instances in the middle
6140 * of successful MGCP response dispatch. If things aren't safeguarded, the on_success() in osmo_mgcpc_ep_fsm
6141 * will cause a use-after-free after that event dispatch. */
6142 cpars.mgw_conn_1.mgw_rtp_ip := "0.0.0.0";
6143 cpars.mgw_conn_2.mgw_rtp_ip := "0.0.0.0";
6144 cpars.rtp_sdp_format := "FOO/8000";
6145 cpars.expect_release := true;
6146
6147 f_perform_lu();
6148 f_mo_call_establish(cpars);
6149}
6150testcase TC_invalid_mgcp_crash() runs on MTC_CT {
6151 var BSC_ConnHdlr vc_conn;
6152 f_init();
6153
6154 vc_conn := f_start_handler(refers(f_tc_invalid_mgcp_crash), 7);
6155 vc_conn.done;
6156}
6157
Vadim Yanitskiyeddebaa2019-12-28 17:45:34 +01006158friend function f_tc_mm_id_resp_no_identity(charstring id, BSC_ConnHdlrPars pars)
6159runs on BSC_ConnHdlr {
6160 pars.tmsi := 'FFFFFFFF'O;
6161 f_init_handler(pars);
6162
6163 f_create_gsup_expect(hex2str(g_pars.imsi));
6164
6165 /* Initiate Location Updating using an unknown TMSI */
6166 f_bssap_compl_l3(f_build_lu_tmsi(pars.tmsi));
6167
6168 /* Expect an Identity Request, send response with no identity */
6169 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
6170 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp({
6171 lengthIndicator := 1,
6172 mobileIdentityV := {
6173 typeOfIdentity := '000'B,
6174 oddEvenInd_identity := {
6175 no_identity := {
6176 oddevenIndicator := '0'B,
6177 fillerDigits := '00000'H
6178 }
6179 }
6180 }
6181 })));
6182
6183 f_expect_lu_reject();
6184 f_expect_clear();
6185}
6186testcase TC_mm_id_resp_no_identity() runs on MTC_CT {
6187 var BSC_ConnHdlr vc_conn;
6188
6189 f_init();
6190
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02006191 vc_conn := f_start_handler(refers(f_tc_mm_id_resp_no_identity), 7, verify_cell_id := false);
Vadim Yanitskiyeddebaa2019-12-28 17:45:34 +01006192 vc_conn.done;
6193}
6194
Vadim Yanitskiy25219062020-01-21 01:41:33 +07006195/* Verify the case when T3212 expires during Paging procedure, just before the receipt
6196 * of Paging Response. This used to provoke a NULL-pointer dereference in old versions
6197 * of OsmoMSC, but apparently the bug has been fixed, and we're safe now. */
6198friend function f_tc_lu_and_expire_while_paging(charstring id, BSC_ConnHdlrPars pars)
6199runs on BSC_ConnHdlr {
6200 var charstring imsi := hex2str(pars.imsi);
6201
6202 f_init_handler(pars);
6203
6204 /* Perform location update */
6205 f_perform_lu();
6206
6207 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
6208 f_create_gsup_expect(hex2str(g_pars.imsi));
6209
6210 /* Initiate paging procedure from the VTY */
6211 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " paging");
6212 f_expect_paging();
6213
6214 /* Emulate T3212 expiration during paging (we don't want to wait, right?) */
6215 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " expire");
6216
6217 /* MS sends PAGING RESPONSE, *old* OsmoMSC crashes here... */
6218 f_establish_fully(EST_TYPE_PAG_RESP);
6219
6220 /* The recent OsmoMSC keeps subscriber in its VLR unless the Paging is completed.
6221 * In this case we do not send anything and just wait for a Clear Command. */
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02006222 f_expect_clear(verify_vlr_cell_id := false);
Vadim Yanitskiy25219062020-01-21 01:41:33 +07006223}
6224testcase TC_lu_and_expire_while_paging() runs on MTC_CT {
6225 var BSC_ConnHdlr vc_conn;
6226
6227 f_init();
6228
6229 vc_conn := f_start_handler(refers(f_tc_lu_and_expire_while_paging), 7);
6230 vc_conn.done;
6231}
6232
Harald Weltef6dd64d2017-11-19 12:09:51 +01006233control {
Philipp Maier328d1662018-03-07 10:40:27 +01006234 execute( TC_cr_before_reset() );
Harald Weltea49e36e2018-01-21 19:29:33 +01006235 execute( TC_lu_imsi_noauth_tmsi() );
Harald Welted2328a22018-01-27 14:27:16 +01006236 execute( TC_lu_imsi_noauth_notmsi() );
Harald Weltea49e36e2018-01-21 19:29:33 +01006237 execute( TC_lu_imsi_reject() );
6238 execute( TC_lu_imsi_timeout_gsup() );
Harald Welted2328a22018-01-27 14:27:16 +01006239 execute( TC_lu_imsi_auth_tmsi() );
Harald Welte8a397ae2019-04-21 22:03:37 +02006240 execute( TC_lu_imsi_auth3g_tmsi() );
Pau Espin Pedrold3d54a92019-12-17 17:02:54 +01006241 execute( TC_lu_imsi_timeout_tmsi_realloc() );
Harald Welted2328a22018-01-27 14:27:16 +01006242 execute( TC_cmserv_imsi_unknown() );
Neels Hofmeyr13737fb2020-08-19 13:16:14 +00006243 execute( TC_cmserv_tmsi_unknown() );
Harald Welte2bb825f2018-01-22 11:31:18 +01006244 execute( TC_lu_and_mo_call() );
Pau Espin Pedrola42745c2020-01-10 18:03:28 +01006245 execute( TC_lu_and_mo_call_sccp_tiar_timeout() );
Harald Welte071ed732018-01-23 19:53:52 +01006246 execute( TC_lu_auth_sai_timeout() );
6247 execute( TC_lu_auth_sai_err() );
Harald Weltee1a2f3c2018-01-24 17:28:48 +01006248 execute( TC_lu_clear_request() );
6249 execute( TC_lu_disconnect() );
6250 execute( TC_lu_by_imei() );
6251 execute( TC_lu_by_tmsi_noauth_unknown() );
Neels Hofmeyrfc06c732020-08-19 12:52:28 +00006252 execute( TC_attached_imsi_lu_unknown_tmsi() );
Harald Weltee1a2f3c2018-01-24 17:28:48 +01006253 execute( TC_imsi_detach_by_imsi() );
6254 execute( TC_imsi_detach_by_tmsi() );
6255 execute( TC_imsi_detach_by_imei() );
6256 execute( TC_emerg_call_imei_reject() );
6257 execute( TC_emerg_call_imsi() );
6258 execute( TC_cm_serv_req_vgcs_reject() );
6259 execute( TC_cm_serv_req_vbs_reject() );
6260 execute( TC_cm_serv_req_lcs_reject() );
Harald Welte0195ab12018-01-24 21:50:20 +01006261 execute( TC_cm_reest_req_reject() );
Harald Welte1af6ea82018-01-25 18:33:15 +01006262 execute( TC_lu_auth_2G_fail() );
6263 execute( TC_lu_imsi_auth_tmsi_encr_13_13() );
6264 execute( TC_cl3_no_payload() );
6265 execute( TC_cl3_rnd_payload() );
Harald Welte1852a842018-01-26 22:53:36 +01006266 execute( TC_establish_and_nothing() );
6267 execute( TC_mo_setup_and_nothing() );
6268 execute( TC_mo_crcx_ran_timeout() );
6269 execute( TC_mo_crcx_ran_reject() );
Harald Welted2328a22018-01-27 14:27:16 +01006270 execute( TC_mt_crcx_ran_reject() );
Daniel Willmann8b084372018-02-04 13:35:26 +01006271 execute( TC_mo_setup_and_dtmf_dup() );
Harald Welteaa54cf82018-01-30 08:15:32 +01006272 //execute( TC_mt_t310() );
Harald Welte167458a2018-01-27 15:58:16 +01006273 execute( TC_gsup_cancel() );
Harald Welte9de84792018-01-28 01:06:35 +01006274 execute( TC_lu_imsi_auth_tmsi_encr_1_13() );
6275 execute( TC_lu_imsi_auth_tmsi_encr_3_13() );
6276 execute( TC_lu_imsi_auth_tmsi_encr_3_1() );
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01006277 execute( TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() );
Harald Welte9de84792018-01-28 01:06:35 +01006278 execute( TC_lu_imsi_auth_tmsi_encr_13_2() );
6279 execute( TC_lu_imsi_auth_tmsi_encr_013_2() );
Philipp Maier94f3f1b2018-03-15 18:54:13 +01006280 execute( TC_mo_release_timeout() );
Philipp Maier2a98a732018-03-19 16:06:12 +01006281 execute( TC_lu_and_mt_call_no_dlcx_resp() );
Philipp Maier75932982018-03-27 14:52:35 +02006282 execute( TC_reset_two() );
Harald Welte33ec09b2018-02-10 15:34:46 +01006283
6284 execute( TC_lu_and_mt_call() );
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01006285 execute( TC_lu_and_mt_call_already_paging() );
Harald Welte33ec09b2018-02-10 15:34:46 +01006286
Harald Weltef45efeb2018-04-09 18:19:24 +02006287 execute( TC_lu_and_mo_sms() );
6288 execute( TC_lu_and_mt_sms() );
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01006289 execute( TC_lu_and_mt_sms_already_paging() );
Philipp Maier3983e702018-11-22 19:01:33 +01006290 execute( TC_lu_and_mt_sms_paging_and_nothing() );
Alexander Couzensfc02f242019-09-12 03:43:18 +02006291 execute( TC_lu_and_mt_sms_paging_repeated() );
Harald Weltef640a012018-04-14 17:49:21 +02006292 execute( TC_smpp_mo_sms() );
Vadim Yanitskiy33820762020-01-15 11:26:07 +07006293 execute( TC_smpp_mo_sms_rp_error() );
Harald Weltef640a012018-04-14 17:49:21 +02006294 execute( TC_smpp_mt_sms() );
Harald Weltef45efeb2018-04-09 18:19:24 +02006295
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07006296 execute( TC_gsup_mo_sms() );
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07006297 execute( TC_gsup_mo_smma() );
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07006298 execute( TC_gsup_mt_sms_ack() );
6299 execute( TC_gsup_mt_sms_err() );
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07006300 execute( TC_gsup_mt_sms_rp_mr() );
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07006301 execute( TC_gsup_mo_mt_sms_rp_mr() );
Vadim Yanitskiya2a8a112019-07-08 20:04:32 +07006302 execute( TC_gsup_mt_multi_part_sms() );
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07006303
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07006304 execute( TC_lu_and_mo_ussd_single_request() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07006305 execute( TC_lu_and_mt_ussd_notification() );
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07006306 execute( TC_lu_and_mo_ussd_during_mt_call() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07006307 execute( TC_lu_and_mt_ussd_during_mt_call() );
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07006308 execute( TC_lu_and_mo_ussd_mo_release() );
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07006309 execute( TC_lu_and_ss_session_timeout() );
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07006310
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07006311 execute( TC_mt_ussd_for_unknown_subscr() );
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07006312 execute( TC_mo_ussd_for_unknown_trans() );
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07006313 execute( TC_proc_ss_for_unknown_session() );
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07006314 execute( TC_proc_ss_paging_fail() );
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07006315 execute( TC_proc_ss_abort() );
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07006316
Vadim Yanitskiy1c9754d2020-01-07 21:56:55 +01006317 execute( TC_multi_lu_and_mo_ussd() );
6318 execute( TC_multi_lu_and_mt_ussd() );
6319
Stefan Sperling89eb1f32018-12-17 15:06:20 +01006320 execute( TC_cipher_complete_with_invalid_cipher() );
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01006321 execute( TC_cipher_complete_1_without_cipher() );
6322 execute( TC_cipher_complete_3_without_cipher() );
6323 execute( TC_cipher_complete_13_without_cipher() );
Harald Welteb2284bd2019-05-10 11:30:43 +02006324 execute( TC_lu_with_invalid_mcc_mnc() );
Stefan Sperling89eb1f32018-12-17 15:06:20 +01006325
Harald Welte4263c522018-12-06 11:56:27 +01006326 execute( TC_sgsap_reset() );
6327 execute( TC_sgsap_lu() );
6328 execute( TC_sgsap_lu_imsi_reject() );
6329 execute( TC_sgsap_lu_and_nothing() );
6330 execute( TC_sgsap_expl_imsi_det_eps() );
Philipp Maierfc19f172019-03-21 11:17:54 +01006331 execute( TC_sgsap_impl_imsi_det_eps() );
Harald Welte4263c522018-12-06 11:56:27 +01006332 execute( TC_sgsap_expl_imsi_det_noneps() );
Philipp Maier5d812702019-03-21 10:51:26 +01006333 execute( TC_sgsap_impl_imsi_det_noneps() );
Harald Welte4263c522018-12-06 11:56:27 +01006334 execute( TC_sgsap_paging_rej() );
6335 execute( TC_sgsap_paging_subscr_rej() );
6336 execute( TC_sgsap_paging_ue_unr() );
6337 execute( TC_sgsap_paging_and_nothing() );
6338 execute( TC_sgsap_paging_and_lu() );
6339 execute( TC_sgsap_mt_sms() );
6340 execute( TC_sgsap_mo_sms() );
6341 execute( TC_sgsap_mt_sms_and_nothing() );
6342 execute( TC_sgsap_mt_sms_and_reject() );
6343 execute( TC_sgsap_unexp_ud() );
6344 execute( TC_sgsap_unsol_ud() );
6345 execute( TC_bssap_lu_sgsap_lu_and_mt_call() );
6346 execute( TC_sgsap_lu_and_mt_call() );
Philipp Maier628c0052019-04-09 17:36:57 +02006347 execute( TC_sgsap_vlr_failure() );
Harald Welte4263c522018-12-06 11:56:27 +01006348
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006349 execute( TC_ho_inter_bsc_unknown_cell() );
6350 execute( TC_ho_inter_bsc() );
6351
6352 execute( TC_ho_inter_msc_out() );
6353
Oliver Smith1d118ff2019-07-03 10:57:35 +02006354 execute( TC_lu_imsi_auth_tmsi_check_imei() );
6355 execute( TC_lu_imsi_auth3g_tmsi_check_imei() );
6356 execute( TC_lu_imsi_noauth_tmsi_check_imei() );
6357 execute( TC_lu_imsi_noauth_notmsi_check_imei() );
6358 execute( TC_lu_imsi_auth_tmsi_check_imei_nack() );
6359 execute( TC_lu_imsi_auth_tmsi_check_imei_err() );
6360 execute( TC_lu_imsi_auth_tmsi_check_imei_early() );
6361 execute( TC_lu_imsi_auth3g_tmsi_check_imei_early() );
6362 execute( TC_lu_imsi_noauth_tmsi_check_imei_early() );
6363 execute( TC_lu_imsi_noauth_notmsi_check_imei_early() );
6364 execute( TC_lu_imsi_auth_tmsi_check_imei_early_nack() );
6365 execute( TC_lu_imsi_auth_tmsi_check_imei_early_err() );
6366
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01006367 /* Run this last: at the time of writing this test crashes the MSC */
6368 execute( TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() );
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02006369 execute( TC_mo_cc_bssmap_clear() );
Pau Espin Pedrol690d6592019-05-31 17:56:32 +02006370 if (mp_enable_osmux_test) {
6371 execute( TC_lu_and_mt_call_osmux() );
6372 }
Neels Hofmeyr8df69622019-11-02 19:16:03 +01006373 execute( TC_invalid_mgcp_crash() );
Vadim Yanitskiyeddebaa2019-12-28 17:45:34 +01006374 execute( TC_mm_id_resp_no_identity() );
Vadim Yanitskiy25219062020-01-21 01:41:33 +07006375 execute( TC_lu_and_expire_while_paging() );
Neels Hofmeyr14d0b132020-08-19 13:49:05 +00006376 execute( TC_paging_response_imsi_unknown() );
6377 execute( TC_paging_response_tmsi_unknown() );
Harald Weltef6dd64d2017-11-19 12:09:51 +01006378}
6379
6380
6381}