blob: 656fb4e32fd19aeadce7103890ccc08c4ab9e566 [file] [log] [blame]
Harald Weltea49e36e2018-01-21 19:29:33 +01001module BSC_ConnectionHandler {
2
3import from General_Types all;
4import from Osmocom_Types all;
5import from GSM_Types all;
6import from SCCPasp_Types all;
7import from BSSAP_Types all;
8import from BSSMAP_Emulation all;
9import from BSSMAP_Templates all;
10
11import from GSUP_Types all;
12import from GSUP_Emulation all;
13
14import from MNCC_Types all;
15import from MNCC_Emulation all;
16
17import from MobileL3_Types all;
18import from MobileL3_CommonIE_Types all;
19import from MobileL3_MM_Types all;
20import from L3_Templates all;
21
22/* this component represents a single subscriber connection */
23type component BSC_ConnHdlr extends BSSAP_ConnHdlr, MNCC_ConnHdlr, GSUP_ConnHdlr {
24 var BSC_ConnHdlrPars g_pars;
25}
26
27type record BSC_ConnHdlrPars {
28 SCCP_PAR_Address sccp_addr_own,
29 SCCP_PAR_Address sccp_addr_peer,
30 BSSMAP_IE_CellIdentifier cell_id,
Harald Welte256571e2018-01-24 18:47:19 +010031 hexstring imei,
Harald Weltea49e36e2018-01-21 19:29:33 +010032 hexstring imsi,
Harald Welte82600572018-01-21 20:54:08 +010033 hexstring msisdn,
Harald Welte256571e2018-01-24 18:47:19 +010034 OCT4 tmsi optional,
Harald Welte82600572018-01-21 20:54:08 +010035 BSSMAP_IE_ClassmarkInformationType2 cm2,
Harald Welte16114282018-01-24 22:41:21 +010036 BSSMAP_IE_ClassmarkInformationType3 cm3 optional,
37 octetstring kc optional
Harald Weltea49e36e2018-01-21 19:29:33 +010038};
39
40
41/* Callback function from general BSSMAP_Emulation whenever a connectionless
42 * BSSMAP message arrives. Canreturn a PDU_BSSAPthat should be sent in return */
43private function BscUnitdataCallback(PDU_BSSAP bssap)
44runs on BSSMAP_Emulation_CT return template PDU_BSSAP {
45 var template PDU_BSSAP resp := omit;
46
47 log("BSSMAP_BscUnitdataCallback");
48 /* answer all RESET with RESET ACK */
49 if (match(bssap, tr_BSSMAP_Reset)){
50 log("BSSMAP_BscUnitdataCallback: Responding to RESET with RESET-ACK");
51 resp := ts_BSSMAP_ResetAck;
52 }
53
54 /* FIXME: Handle paging, etc. */
55 return resp;
56}
57
58const BssmapOps BSC_BssmapOps := {
59 /* Create call-back for inbound connections from MSC (hand-over) */
60 create_cb := refers(BSSMAP_Emulation.ExpectedCreateCallback),
61 unitdata_cb := refers(BscUnitdataCallback),
62 decode_dtap := true,
63 role_ms := true
64}
65
66
67private function MnccUnitdataCallback(MNCC_PDU mncc)
68runs on MNCC_Emulation_CT return template MNCC_PDU {
69 log("Ignoring MNCC", mncc);
70 return omit;
71}
72
73const MnccOps BCC_MnccOps := {
74 create_cb := refers(MNCC_Emulation.ExpectedCreateCallback),
75 unitdata_cb := refers(MnccUnitdataCallback)
76}
77
78
79
80template BSSAP_Conn_Req ts_BSSAP_Conn_Req(SCCP_PAR_Address peer, SCCP_PAR_Address own, PDU_BSSAP bssap) := {
81 addr_peer := peer,
82 addr_own := own,
83 bssap := bssap
84};
85
Harald Weltea49e36e2018-01-21 19:29:33 +010086/* Encode 'l3' and ask BSSMAP_Emulation to create new connection with COMPL L3 INFO */
87function f_bssap_compl_l3(PDU_ML3_MS_NW l3)
88runs on BSC_ConnHdlr {
89 log("Sending COMPL L3: ", l3);
90 var octetstring l3_enc := enc_PDU_ML3_MS_NW(l3);
91 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
92 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, l3_enc))));
Harald Welte71b69332018-01-21 20:43:53 +010093 alt {
94 [] BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_CONF_IND) {}
95 [] BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {
96 setverdict(fail, "DISC.ind from SCCP");
97 self.stop;
98 }
99 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100100}
101
102/* helper function to fully establish a dedicated channel */
103function f_establish_fully(MobileIdentityLV mi, boolean expect_auth)
104runs on BSC_ConnHdlr {
Harald Welte6ed6bf92018-01-24 21:09:15 +0100105 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
Harald Weltea49e36e2018-01-21 19:29:33 +0100106 var PDU_DTAP_MT dtap_mt;
107
108 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
109 f_bssap_compl_l3(l3_info);
110
111 if (expect_auth) {
112 /* FIXME */
113 }
114 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_ACC));
115}
116
117/* build a PDU_ML3_MS_NW containing a Location Update by IMSI */
118function f_build_lu_imsi(hexstring imsi) return PDU_ML3_MS_NW
119{
120 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(imsi));
121 return f_build_lu(mi);
122}
Harald Welteba7b6d92018-01-23 21:32:34 +0100123function f_build_lu_imei(hexstring imei) return PDU_ML3_MS_NW
124{
125 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(imei));
126 return f_build_lu(mi);
127}
128function f_build_lu_tmsi(OCT4 tmsi) return PDU_ML3_MS_NW
129{
130 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV(tmsi));
131 return f_build_lu(mi);
132}
Harald Weltea49e36e2018-01-21 19:29:33 +0100133private function f_build_lu(MobileIdentityLV mi) return PDU_ML3_MS_NW
134{
135 var LocationAreaIdentification_V old_lai := { '62F220'O, '9999'O };
136 var PDU_ML3_MS_NW l3_info := valueof(ts_ML3_MO_LU_Req(valueof(ts_ML3_IE_LuType_Attach),
137 old_lai, mi, valueof(ts_CM1)));
138 return l3_info;
139}
140
Harald Weltecf66d5a2018-01-23 19:24:28 +0100141type record AuthVector {
142 OCT16 rand,
143 OCT4 sres,
144 OCT8 kc
145 /* FIXME: 3G elements */
146}
147
148private function f_rnd_oct(integer len) return octetstring {
149 var integer i;
150 var octetstring res;
151 for (i := 0; i < len; i := i + 1) {
152 res[i] := int2oct(float2int(rnd()*256.0), 1);
153 }
154 return res;
155}
156
157function f_gen_auth_vec_2g() return AuthVector {
158 var AuthVector vec;
159 vec.rand := f_rnd_oct(16);
160 vec.sres := f_rnd_oct(4);
161 vec.kc := f_rnd_oct(8);
162 return vec;
163}
164
Harald Welte16114282018-01-24 22:41:21 +0100165function f_perform_lu(boolean expect_auth, boolean expect_tmsi, boolean send_early_cm,
166 boolean expect_ciph := false)
Harald Weltea49e36e2018-01-21 19:29:33 +0100167runs on BSC_ConnHdlr {
168 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
169 var PDU_DTAP_MT dtap_mt;
Harald Welte16114282018-01-24 22:41:21 +0100170 var AuthVector vec;
Harald Weltea49e36e2018-01-21 19:29:33 +0100171
172 /* tell GSUP dispatcher to send this IMSI to us */
173 f_create_gsup_expect(hex2str(g_pars.imsi));
174
175 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
176 f_bssap_compl_l3(l3_lu);
177
Harald Welte8a121b32018-01-22 03:00:41 +0100178 if (send_early_cm) {
179 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
180 }
Harald Welte5c2622c2018-01-21 20:45:20 +0100181
Harald Weltea49e36e2018-01-21 19:29:33 +0100182 if (expect_auth) {
Harald Welte16114282018-01-24 22:41:21 +0100183 vec := f_gen_auth_vec_2g();
Harald Weltecf66d5a2018-01-23 19:24:28 +0100184 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G(vec.rand, vec.sres, vec.kc));
Harald Welteef9fa872018-01-22 03:00:17 +0100185 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
Harald Welte7b1b2812018-01-22 21:23:06 +0100186 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
187
Harald Weltecf66d5a2018-01-23 19:24:28 +0100188 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_AUTH_REQ(vec.rand)));
189 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MT_MM_AUTH_RESP_2G(vec.sres)));
Harald Weltea49e36e2018-01-21 19:29:33 +0100190 }
191
Harald Welte16114282018-01-24 22:41:21 +0100192 if (expect_ciph) {
193 BSSAP.receive(tr_BSSMAP_CipherModeCmd(?, vec.kc));
194 g_pars.kc := vec.kc;
195 BSSAP.send(ts_BSSMAP_CipherModeCompl('02'O));
196 }
197
Harald Weltea49e36e2018-01-21 19:29:33 +0100198 /* Expect MSC to perform LU with HLR */
199 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
200 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
201 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
202 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
203
204 alt {
205 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) -> value dtap_mt {
206 var PDU_ML3_LocationUpdateAccept lu_acc := dtap_mt.dtap.msgs.mm.locationUpdateAccept;
207 if (expect_tmsi) {
208 if (not ispresent(lu_acc.mobileIdentityTLV) or
209 not ischosen(lu_acc.mobileIdentityTLV.mobileIdentityLV.mobileIdentityV.oddEvenInd_identity.tmsi_ptmsi)) {
210 setverdict(fail, "Expected TMSI but no TMSI was allocated");
211 self.stop;
212 } else {
Harald Welte256571e2018-01-24 18:47:19 +0100213 g_pars.tmsi := lu_acc.mobileIdentityTLV.mobileIdentityLV.mobileIdentityV.oddEvenInd_identity.tmsi_ptmsi.octets;
Harald Weltea49e36e2018-01-21 19:29:33 +0100214 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_TmsiRealloc_Cmpl));
215 }
216 } else {
217 if (ispresent(lu_acc.mobileIdentityTLV) and
218 ischosen(lu_acc.mobileIdentityTLV.mobileIdentityLV.mobileIdentityV.oddEvenInd_identity.tmsi_ptmsi)) {
219 setverdict(fail, "Expected no TMSI but TMSI was allocated");
220 self.stop;
221 }
222 }
223 }
224 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
225 setverdict(fail, "Expected LU ACK, but received LU REJ");
226 self.stop;
227 }
228 }
229 /* FIXME: there could be pending SMS or other common procedures by the MSC, let's ignore them */
230 BSSAP.receive(tr_BSSMAP_ClearCommand);
231 BSSAP.send(ts_BSSMAP_ClearComplete);
232 BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_DISC_IND);
233 setverdict(pass);
234}
235
236function f_foo() runs on BSC_ConnHdlr{
237 /* SCCP CC handled by BSSMAP_Emulation_CT.main() */
238 /* Expect auth, if enabled */
239
240 /* TODO: ISD */
241 /* Expect encr, if enabled */
242 /* Expect encr, if enabled */
243 /* Expect ASS CMD, if chan_type != requested */
244 /* Send ASS CMPL in successful case */
245
246 /* Expect AoIP port/ip information for RTP stream */
247 /* Expect MSC-originated MGCP to our simulated MGW */
248 /* Verify Counters via CTRL */
249 /* re-configure MSC behaviour via VTY */
250}
251
252
253
254
255
256}
257
258