blob: 6cb852a275140881801ec22ea76cb168ec0b737d [file] [log] [blame]
Harald Weltef6dd64d2017-11-19 12:09:51 +01001module MSC_Tests {
2
Harald Welte34b5a952019-05-27 11:54:11 +02003/* Osmocom MSC test suite in in TTCN-3
4 * (C) 2017-2019 Harald Welte <laforge@gnumonks.org>
5 * (C) 2018-2019 sysmocom - s.f.m.c. GmbH
6 * (C) 2018-2019 Vadim Yanitskiy <axilirator@gmail.com>
7 * All rights reserved.
8 *
9 * Released under the terms of GNU General Public License, Version 2 or
10 * (at your option) any later version.
11 *
12 * SPDX-License-Identifier: GPL-2.0-or-later
13 */
14
Harald Weltee13cfb22019-04-23 16:52:02 +020015friend module MSC_Tests_Iu;
16
Harald Weltef6dd64d2017-11-19 12:09:51 +010017import from General_Types all;
18import from Osmocom_Types all;
19
20import from M3UA_Types all;
21import from M3UA_Emulation all;
22
23import from MTP3asp_Types all;
24import from MTP3asp_PortType all;
25
26import from SCCPasp_Types all;
27import from SCCP_Types all;
28import from SCCP_Emulation all;
29
30import from SCTPasp_Types all;
31import from SCTPasp_PortType all;
32
Harald Weltea49e36e2018-01-21 19:29:33 +010033import from Osmocom_CTRL_Functions all;
34import from Osmocom_CTRL_Types all;
35import from Osmocom_CTRL_Adapter all;
36
Harald Welte3ca1c902018-01-24 18:51:27 +010037import from TELNETasp_PortType all;
38import from Osmocom_VTY_Functions all;
39
Harald Weltea49e36e2018-01-21 19:29:33 +010040import from MNCC_Emulation all;
Harald Welte2bb825f2018-01-22 11:31:18 +010041import from MNCC_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010042
Harald Welte4aa970c2018-01-26 10:38:09 +010043import from MGCP_Emulation all;
44import from MGCP_Types all;
45import from MGCP_Templates all;
46import from SDP_Types all;
47
Harald Weltea49e36e2018-01-21 19:29:33 +010048import from GSUP_Emulation all;
49import from GSUP_Types all;
50import from IPA_Emulation all;
51
Harald Weltef6dd64d2017-11-19 12:09:51 +010052import from BSSAP_Types all;
Harald Welte6811d102019-04-14 22:23:14 +020053import from RAN_Adapter all;
Harald Weltea49e36e2018-01-21 19:29:33 +010054import from BSSAP_CodecPort all;
55import from BSSMAP_Templates all;
Harald Welte6811d102019-04-14 22:23:14 +020056import from RAN_Emulation all;
Harald Weltea49e36e2018-01-21 19:29:33 +010057import from BSC_ConnectionHandler all;
Harald Weltee13cfb22019-04-23 16:52:02 +020058import from RANAP_Templates all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010059
Harald Welte4263c522018-12-06 11:56:27 +010060import from SGsAP_Templates all;
61import from SGsAP_Types all;
62import from SGsAP_Emulation all;
63
Harald Weltea49e36e2018-01-21 19:29:33 +010064import from MobileL3_Types all;
65import from MobileL3_CommonIE_Types all;
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +070066import from MobileL3_SMS_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010067import from L3_Templates all;
Harald Welte158a7ca2018-02-16 18:11:31 +010068import from L3_Common all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010069
Harald Weltef640a012018-04-14 17:49:21 +020070import from SMPP_Types all;
71import from SMPP_Templates all;
72import from SMPP_Emulation all;
73
Stefan Sperlingc307e682018-06-14 15:15:46 +020074import from SCCP_Templates all;
75
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070076import from SS_Types all;
77import from SS_Templates all;
78import from USSD_Helpers all;
Harald Welte4263c522018-12-06 11:56:27 +010079import from DNS_Helpers all;
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070080
Philipp Maier948747b2019-04-02 15:22:33 +020081import from TCCConversion_Functions all;
82
Harald Welte9b751a62019-04-14 17:39:29 +020083const integer NUM_BSC := 3;
Harald Weltef6dd64d2017-11-19 12:09:51 +010084
Harald Welte4263c522018-12-06 11:56:27 +010085/* Needed for SGsAP SMS */
86import from MobileL3_SMS_Types all;
87
Harald Weltea4ca4462018-02-09 00:17:14 +010088type component MTC_CT extends CTRL_Adapter_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +010089 var boolean g_initialized := false;
Harald Weltea49e36e2018-01-21 19:29:33 +010090
Harald Welte6811d102019-04-14 22:23:14 +020091 var RAN_Adapter g_bssap[NUM_BSC];
Harald Weltea4ca4462018-02-09 00:17:14 +010092
Harald Weltea49e36e2018-01-21 19:29:33 +010093 /* no 'adapter_CT' for MNCC or GSUP */
94 var MNCC_Emulation_CT vc_MNCC;
Harald Welte4aa970c2018-01-26 10:38:09 +010095 var MGCP_Emulation_CT vc_MGCP;
Harald Weltea49e36e2018-01-21 19:29:33 +010096 var GSUP_Emulation_CT vc_GSUP;
97 var IPA_Emulation_CT vc_GSUP_IPA;
Harald Weltef640a012018-04-14 17:49:21 +020098 var SMPP_Emulation_CT vc_SMPP;
Harald Welte4263c522018-12-06 11:56:27 +010099 var SGsAP_Emulation_CT vc_SGsAP;
Harald Weltea49e36e2018-01-21 19:29:33 +0100100
101 /* only to get events from IPA underneath GSUP */
102 port IPA_CTRL_PT GSUP_IPA_EVENT;
Harald Welte3ca1c902018-01-24 18:51:27 +0100103 /* VTY to MSC */
104 port TELNETasp_PT MSCVTY;
Philipp Maier328d1662018-03-07 10:40:27 +0100105
106 /* A port to directly send BSSAP messages. This port is used for
107 * tests that require low level access to sen arbitrary BSSAP
108 * messages. Run f_init_bssap_direct() to connect and initialize */
109 port BSSAP_CODEC_PT BSSAP_DIRECT;
110
111 /* When BSSAP messages are directly sent, then the connection
112 * handler is not active, which means that also no guard timer is
113 * set up. The following timer will serve as a replacement */
114 timer Tguard_direct := 60.0;
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100115
116 /* Configure T(tias) over VTY, seconds */
117 var integer g_msc_sccp_timer_ias := 7 * 60;
118 /* Configure T(tiar) over VTY, seconds */
119 var integer g_msc_sccp_timer_iar := 15 * 60;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100120}
121
122modulepar {
Harald Weltea49e36e2018-01-21 19:29:33 +0100123 /* remote parameters of IUT */
124 charstring mp_msc_ip := "127.0.0.1";
125 integer mp_msc_ctrl_port := 4255;
126 integer mp_msc_vty_port := 4254;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100127
Harald Weltea49e36e2018-01-21 19:29:33 +0100128 /* local parameters of emulated HLR */
Philipp Maier9b690e42018-12-21 11:50:03 +0100129 boolean mp_mm_info := false;
Harald Weltea49e36e2018-01-21 19:29:33 +0100130 charstring mp_hlr_ip := "127.0.0.1";
131 integer mp_hlr_port := 4222;
Harald Welte6126fb02018-01-27 20:08:24 +0100132 charstring mp_mgw_ip := "127.0.0.1";
133 integer mp_mgw_port := 2427;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100134
Harald Weltea49e36e2018-01-21 19:29:33 +0100135 charstring mp_msc_mncc := "/tmp/mncc";
Harald Weltea4ca4462018-02-09 00:17:14 +0100136
Harald Weltef640a012018-04-14 17:49:21 +0200137 integer mp_msc_smpp_port := 2775;
138 charstring mp_smpp_system_id := "msc_tester";
139 charstring mp_smpp_password := "osmocom1";
Harald Welte4263c522018-12-06 11:56:27 +0100140 charstring mp_mme_name := "mmec01.mmegi0001.mme.epc.mnc070.mcc901.3gppnetwork.org";
141 charstring mp_vlr_name := "vlr.example.net";
Harald Weltef640a012018-04-14 17:49:21 +0200142
Pau Espin Pedrol690d6592019-05-31 17:56:32 +0200143 /* Whether to enable osmux tests. Can be dropped completely and enable
144 unconditionally once new version of osmo-msc is released (current
145 version: 1.3.1) */
146 boolean mp_enable_osmux_test := true;
147
Harald Welte6811d102019-04-14 22:23:14 +0200148 RAN_Configurations mp_bssap_cfg := {
Philipp Maier75932982018-03-27 14:52:35 +0200149 {
150 sccp_service_type := "mtp3_itu",
151 sctp_addr := { 23905, "127.0.0.1", 2905, "127.0.0.1" },
152 own_pc := 185,
153 own_ssn := 254,
154 peer_pc := 187,
155 peer_ssn := 254,
156 sio := '83'O,
157 rctx := 0
158 },
159 {
160 sccp_service_type := "mtp3_itu",
161 sctp_addr := { 23906, "127.0.0.1", 2905, "127.0.0.1" },
162 own_pc := 186,
163 own_ssn := 254,
164 peer_pc := 187,
165 peer_ssn := 254,
166 sio := '83'O,
167 rctx := 1
168 }
Harald Weltea4ca4462018-02-09 00:17:14 +0100169 };
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200170
171 boolean mp_enable_cell_id_test := true;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100172}
173
Philipp Maier328d1662018-03-07 10:40:27 +0100174/* altstep for the global guard timer (only used when BSSAP_DIRECT
175 * is used for communication */
176private altstep as_Tguard_direct() runs on MTC_CT {
177 [] Tguard_direct.timeout {
178 setverdict(fail, "Tguard timeout");
Daniel Willmannafce8662018-07-06 23:11:32 +0200179 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +0100180 }
181}
Harald Weltef6dd64d2017-11-19 12:09:51 +0100182
Neels Hofmeyr2ca1ab42019-03-08 03:45:43 +0100183private altstep as_optional_cc_rel(CallParameters cpars, boolean respond := false) runs on BSC_ConnHdlr {
184 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id))) {
185 if (respond) {
186 var BIT1 tid_remote := '1'B;
187 if (cpars.mo_call) {
188 tid_remote := '0'B;
189 }
190 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id, tid_remote)));
191 }
192 }
Neels Hofmeyrde76f052019-02-26 05:02:46 +0100193}
194
Harald Weltef640a012018-04-14 17:49:21 +0200195function f_init_smpp(charstring id) runs on MTC_CT {
196 id := id & "-SMPP";
197 var EsmePars pars := {
198 mode := MODE_TRANSCEIVER,
199 bind := {
200 system_id := mp_smpp_system_id,
201 password := mp_smpp_password,
202 system_type := "MSC_Tests",
203 interface_version := hex2int('34'H),
204 addr_ton := unknown,
205 addr_npi := unknown,
206 address_range := ""
207 },
208 esme_role := true
209 }
210
211 vc_SMPP := SMPP_Emulation_CT.create(id);
212 map(vc_SMPP:SMPP_PORT, system:SMPP_PORT);
Harald Welte4698a4c2020-08-18 22:57:52 +0200213 vc_SMPP.start(SMPP_Emulation.main_client(pars, mp_msc_ip, mp_msc_smpp_port, "", 0));
Harald Weltef640a012018-04-14 17:49:21 +0200214}
215
216
Harald Weltea49e36e2018-01-21 19:29:33 +0100217function f_init_mncc(charstring id) runs on MTC_CT {
218 id := id & "-MNCC";
219 var MnccOps ops := {
220 create_cb := refers(MNCC_Emulation.ExpectedCreateCallback),
221 unitdata_cb := refers(MNCC_Emulation.DummyUnitdataCallback)
222 }
223
224 vc_MNCC := MNCC_Emulation_CT.create(id);
225 map(vc_MNCC:MNCC, system:MNCC_CODEC_PT);
226 vc_MNCC.start(MNCC_Emulation.main(ops, id, mp_msc_mncc));
Harald Weltef6dd64d2017-11-19 12:09:51 +0100227}
228
Harald Welte4aa970c2018-01-26 10:38:09 +0100229function f_init_mgcp(charstring id) runs on MTC_CT {
230 id := id & "-MGCP";
231 var MGCPOps ops := {
232 create_cb := refers(MGCP_Emulation.ExpectedCreateCallback),
233 unitdata_cb := refers(MGCP_Emulation.DummyUnitdataCallback)
234 }
235 var MGCP_conn_parameters pars := {
Harald Welte6126fb02018-01-27 20:08:24 +0100236 callagent_ip := mp_msc_ip,
Harald Welte4aa970c2018-01-26 10:38:09 +0100237 callagent_udp_port := -1,
Harald Welte6126fb02018-01-27 20:08:24 +0100238 mgw_ip := mp_mgw_ip,
Pau Espin Pedrol1a026a52019-06-18 17:21:52 +0200239 mgw_udp_port := mp_mgw_port,
240 multi_conn_mode := false
Harald Welte4aa970c2018-01-26 10:38:09 +0100241 }
242
243 vc_MGCP := MGCP_Emulation_CT.create(id);
244 map(vc_MGCP:MGCP, system:MGCP_CODEC_PT);
245 vc_MGCP.start(MGCP_Emulation.main(ops, pars, id));
246}
247
Philipp Maierc09a1312019-04-09 16:05:26 +0200248function ForwardUnitdataCallback(PDU_SGsAP msg)
249runs on SGsAP_Emulation_CT return template PDU_SGsAP {
250 SGsAP_CLIENT.send(msg);
251 return omit;
252}
253
Harald Welte4263c522018-12-06 11:56:27 +0100254function f_init_sgsap(charstring id) runs on MTC_CT {
255 id := id & "-SGsAP";
256 var SGsAPOps ops := {
257 create_cb := refers(SGsAP_Emulation.ExpectedCreateCallback),
Philipp Maierc09a1312019-04-09 16:05:26 +0200258 unitdata_cb := refers(ForwardUnitdataCallback)
Harald Welte4263c522018-12-06 11:56:27 +0100259 }
260 var SGsAP_conn_parameters pars := {
261 remote_ip := mp_msc_ip,
262 remote_sctp_port := 29118,
263 local_ip := "",
264 local_sctp_port := -1
265 }
266
267 vc_SGsAP := SGsAP_Emulation_CT.create(id);
268 map(vc_SGsAP:SGsAP, system:SGsAP_CODEC_PT);
269 vc_SGsAP.start(SGsAP_Emulation.main(ops, pars, id));
270}
271
272
Harald Weltea49e36e2018-01-21 19:29:33 +0100273function f_init_gsup(charstring id) runs on MTC_CT {
274 id := id & "-GSUP";
275 var GsupOps ops := {
276 create_cb := refers(GSUP_Emulation.ExpectedCreateCallback)
277 }
278
279 vc_GSUP_IPA := IPA_Emulation_CT.create(id & "-IPA");
280 vc_GSUP := GSUP_Emulation_CT.create(id);
281
282 map(vc_GSUP_IPA:IPA_PORT, system:IPA_CODEC_PT);
283 connect(vc_GSUP:GSUP, vc_GSUP_IPA:IPA_GSUP_PORT);
284 /* we use this hack to get events like ASP_IPA_EVENT_UP */
285 connect(vc_GSUP_IPA:IPA_CTRL_PORT, self:GSUP_IPA_EVENT);
286
287 vc_GSUP.start(GSUP_Emulation.main(ops, id));
288 vc_GSUP_IPA.start(IPA_Emulation.main_server(mp_hlr_ip, mp_hlr_port));
289
290 /* wait for incoming connection to GSUP port before proceeding */
291 timer T := 10.0;
292 T.start;
293 alt {
Vadim Yanitskiy61564be2020-05-18 20:44:14 +0700294 [] GSUP_IPA_EVENT.receive(tr_ASP_IPA_EV(ASP_IPA_EVENT_UP)) { }
Harald Weltea49e36e2018-01-21 19:29:33 +0100295 [] T.timeout {
Harald Welte458fd372018-03-21 11:26:23 +0100296 setverdict(fail, "No connection to GSUP Port");
Daniel Willmannafce8662018-07-06 23:11:32 +0200297 mtc.stop
Harald Weltea49e36e2018-01-21 19:29:33 +0100298 }
299 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100300}
301
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200302function f_init(integer num_bsc := 1, boolean sgsap := false, boolean gsup := true, boolean osmux := false) runs on MTC_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +0100303
304 if (g_initialized == true) {
305 return;
306 }
307 g_initialized := true;
308
Philipp Maier75932982018-03-27 14:52:35 +0200309 if (num_bsc > NUM_BSC) {
Daniel Willmannafce8662018-07-06 23:11:32 +0200310 testcase.stop("excess number of BSC instances requested");
Philipp Maier75932982018-03-27 14:52:35 +0200311 }
312
313 for (var integer i := 0; i < num_bsc; i := i + 1) {
314 if (isbound(mp_bssap_cfg[i])) {
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200315 var RanOps ranops := BSC_RanOps;
316 ranops.use_osmux := osmux;
317 f_ran_adapter_init(g_bssap[i], mp_bssap_cfg[i], "MSC_Test_" & int2str(i), ranops);
Harald Welte3ca0ce12019-04-23 17:18:48 +0200318 f_ran_adapter_start(g_bssap[i]);
Philipp Maier75932982018-03-27 14:52:35 +0200319 } else {
Daniel Willmannafce8662018-07-06 23:11:32 +0200320 testcase.stop("missing BSSAP configuration");
Philipp Maier75932982018-03-27 14:52:35 +0200321 }
322 }
323
Harald Weltea49e36e2018-01-21 19:29:33 +0100324 f_ipa_ctrl_start(mp_msc_ip, mp_msc_ctrl_port);
325 f_init_mncc("MSC_Test");
Harald Welte4aa970c2018-01-26 10:38:09 +0100326 f_init_mgcp("MSC_Test");
Philipp Maierc09a1312019-04-09 16:05:26 +0200327
328 if (gsup == true) {
329 f_init_gsup("MSC_Test");
330 }
Harald Weltef640a012018-04-14 17:49:21 +0200331 f_init_smpp("MSC_Test");
Philipp Maier57865482019-01-07 18:33:13 +0100332
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100333 if (sgsap == true) {
Philipp Maier57865482019-01-07 18:33:13 +0100334 f_init_sgsap("MSC_Test");
335 }
Harald Welte3ca1c902018-01-24 18:51:27 +0100336
337 map(self:MSCVTY, system:MSCVTY);
338 f_vty_set_prompts(MSCVTY);
339 f_vty_transceive(MSCVTY, "enable");
Harald Welteb14c77a2018-01-25 17:25:44 +0100340
341 /* set some defaults */
342 f_vty_config(MSCVTY, "network", "authentication optional");
343 f_vty_config(MSCVTY, "msc", "assign-tmsi");
Oliver Smith1d118ff2019-07-03 10:57:35 +0200344 f_vty_config(MSCVTY, "msc", "check-imei-rqd 0");
Harald Welteb14c77a2018-01-25 17:25:44 +0100345 f_vty_config(MSCVTY, "network", "encryption a5 0");
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100346 f_vty_config(MSCVTY, "cs7 instance 0", "sccp-timer ias " & int2str(g_msc_sccp_timer_ias));
347 f_vty_config(MSCVTY, "cs7 instance 0", "sccp-timer iar " & int2str(g_msc_sccp_timer_iar));
Pau Espin Pedrol690d6592019-05-31 17:56:32 +0200348 if (mp_enable_osmux_test) {
349 if (osmux) {
350 f_vty_config(MSCVTY, "msc", "osmux on");
351 } else {
352 f_vty_config(MSCVTY, "msc", "osmux off");
353 }
Pau Espin Pedrol3dd33bc2019-05-31 17:51:20 +0200354 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100355}
356
Philipp Maier328d1662018-03-07 10:40:27 +0100357/* Initialize for a direct connection to BSSAP. This function is an alternative
358 * to f_init() when the high level functions of the BSC_ConnectionHandler are
359 * not needed. */
360function f_init_bssap_direct() runs on MTC_CT {
Harald Welte3ca0ce12019-04-23 17:18:48 +0200361 f_ran_adapter_init(g_bssap[0], mp_bssap_cfg[0], "MSC_Test", omit);
Philipp Maier75932982018-03-27 14:52:35 +0200362 connect(g_bssap[0].vc_SCCP:SCCP_SP_PORT, self:BSSAP_DIRECT);
Philipp Maier328d1662018-03-07 10:40:27 +0100363
364 /* Start guard timer and activate it as default */
365 Tguard_direct.start
366 activate(as_Tguard_direct());
367}
368
Harald Weltea49e36e2018-01-21 19:29:33 +0100369type function void_fn(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100370
Harald Weltea49e36e2018-01-21 19:29:33 +0100371/* FIXME: move into BSC_ConnectionHandler? */
Harald Welte9b751a62019-04-14 17:39:29 +0200372function f_init_pars(integer imsi_suffix, boolean sgsap := false, boolean gsup := true, integer ran_idx := 0,
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200373 boolean ran_is_geran := true, boolean use_osmux := false, OCT4 gsup_sid := '20000101'O,
374 boolean verify_cell_id := true)
Harald Weltef9abf8d2019-04-21 13:07:17 +0200375runs on MTC_CT return BSC_ConnHdlrPars {
Harald Weltede371492018-01-27 23:44:41 +0100376 var BSC_ConnHdlrNetworkPars net_pars := {
377 kc_support := '0A'O, /* A5/1 and A5/3 enabled */
378 expect_tmsi := true,
379 expect_auth := false,
Oliver Smith1d118ff2019-07-03 10:57:35 +0200380 expect_ciph := false,
381 expect_imei := false,
382 expect_imei_early := false,
383 check_imei_result := OSMO_GSUP_IMEI_RESULT_ACK,
384 check_imei_error := false
Harald Weltede371492018-01-27 23:44:41 +0100385 };
Harald Weltea49e36e2018-01-21 19:29:33 +0100386 var BSC_ConnHdlrPars pars := {
Harald Weltef9abf8d2019-04-21 13:07:17 +0200387 sccp_addr_own := g_bssap[ran_idx].sccp_addr_own,
388 sccp_addr_peer := g_bssap[ran_idx].sccp_addr_peer,
Harald Welteedbab812018-03-18 16:02:25 +0100389 cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42)),
Harald Welte81b7f9d2018-01-24 19:06:24 +0100390 imei := f_gen_imei(imsi_suffix),
391 imsi := f_gen_imsi(imsi_suffix),
392 msisdn := f_gen_msisdn(imsi_suffix),
Harald Welte256571e2018-01-24 18:47:19 +0100393 tmsi := omit,
Harald Welte9de84792018-01-28 01:06:35 +0100394 cm1 := valueof(ts_CM1),
Harald Welte82600572018-01-21 20:54:08 +0100395 cm2 := valueof(ts_CM2_default),
Harald Welte16114282018-01-24 22:41:21 +0100396 cm3 := omit,
Harald Weltede371492018-01-27 23:44:41 +0100397 vec := omit,
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100398 net := net_pars,
Philipp Maieraeb29a82018-11-08 17:40:53 +0100399 send_early_cm := true,
400 ipa_ctrl_ip := mp_msc_ip,
401 ipa_ctrl_port := mp_msc_ctrl_port,
Philipp Maier9b690e42018-12-21 11:50:03 +0100402 ipa_ctrl_enable := true,
Philipp Maier57865482019-01-07 18:33:13 +0100403 mm_info := mp_mm_info,
Philipp Maierc09a1312019-04-09 16:05:26 +0200404 sgsap_enable := sgsap,
Harald Weltef9abf8d2019-04-21 13:07:17 +0200405 gsup_enable := gsup,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +0100406 gsup_sid := gsup_sid,
Harald Weltec1f937a2019-04-21 21:19:23 +0200407 ran_idx := ran_idx,
Harald Welte9b751a62019-04-14 17:39:29 +0200408 use_umts_aka := false,
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200409 ran_is_geran := ran_is_geran,
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200410 use_osmux := use_osmux,
Pau Espin Pedrol833174e2020-09-03 16:46:02 +0200411 use_ipv6 := false,
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200412 verify_cell_id := mp_enable_cell_id_test and verify_cell_id
Harald Weltea49e36e2018-01-21 19:29:33 +0100413 };
Harald Weltee13cfb22019-04-23 16:52:02 +0200414 if (not ran_is_geran) {
415 pars.use_umts_aka := true;
416 pars.net.expect_auth := true;
417 }
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100418 return pars;
419}
420
Neels Hofmeyr0ac63152019-05-07 01:20:17 +0200421function f_start_handler_with_pars(void_fn fn, BSC_ConnHdlrPars pars, integer bssap_idx := 0) runs on MTC_CT return BSC_ConnHdlr {
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100422 var BSC_ConnHdlr vc_conn;
Neels Hofmeyr0ac63152019-05-07 01:20:17 +0200423 var charstring id := testcasename() & int2str(bssap_idx);
Harald Weltea49e36e2018-01-21 19:29:33 +0100424
425 vc_conn := BSC_ConnHdlr.create(id);
426 /* BSSMAP part / A interface */
Neels Hofmeyr0ac63152019-05-07 01:20:17 +0200427 connect(vc_conn:BSSAP, g_bssap[pars.ran_idx + bssap_idx].vc_RAN:CLIENT);
428 connect(vc_conn:BSSAP_PROC, g_bssap[pars.ran_idx + bssap_idx].vc_RAN:PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100429 /* MNCC part */
430 connect(vc_conn:MNCC, vc_MNCC:MNCC_CLIENT);
431 connect(vc_conn:MNCC_PROC, vc_MNCC:MNCC_PROC);
Harald Welte4aa970c2018-01-26 10:38:09 +0100432 /* MGCP part */
433 connect(vc_conn:MGCP, vc_MGCP:MGCP_CLIENT);
434 connect(vc_conn:MGCP_PROC, vc_MGCP:MGCP_PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100435 /* GSUP part */
Philipp Maierc09a1312019-04-09 16:05:26 +0200436 if (pars.gsup_enable == true) {
437 connect(vc_conn:GSUP, vc_GSUP:GSUP_CLIENT);
438 connect(vc_conn:GSUP_PROC, vc_GSUP:GSUP_PROC);
439 }
Harald Weltef640a012018-04-14 17:49:21 +0200440 /* SMPP part */
441 connect(vc_conn:SMPP, vc_SMPP:SMPP_CLIENT);
442 connect(vc_conn:SMPP_PROC, vc_SMPP:SMPP_PROC);
Harald Welte4263c522018-12-06 11:56:27 +0100443 /* SGs part */
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100444 if (pars.sgsap_enable == true) {
Philipp Maier57865482019-01-07 18:33:13 +0100445 connect(vc_conn:SGsAP, vc_SGsAP:SGsAP_CLIENT);
446 connect(vc_conn:SGsAP_PROC, vc_SGsAP:SGsAP_PROC);
447 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100448
Harald Weltea10db902018-01-27 12:44:49 +0100449 /* We cannot use vc_conn.start(f_init_handler(fn, id, pars)); as we cannot have
450 * a stand-alone 'derefers()' call, see https://www.eclipse.org/forums/index.php/t/1091364/ */
Harald Weltea49e36e2018-01-21 19:29:33 +0100451 vc_conn.start(derefers(fn)(id, pars));
452 return vc_conn;
453}
454
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200455function f_start_handler(void_fn fn, integer imsi_suffix, integer ran_idx := 0, boolean ran_is_geran := true, boolean use_osmux := false,
456 boolean verify_cell_id := true)
Harald Welte9b751a62019-04-14 17:39:29 +0200457runs on MTC_CT return BSC_ConnHdlr {
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200458 return f_start_handler_with_pars(fn, f_init_pars(imsi_suffix, ran_idx := ran_idx, ran_is_geran := ran_is_geran, use_osmux := use_osmux, verify_cell_id := verify_cell_id));
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100459}
460
Harald Weltea49e36e2018-01-21 19:29:33 +0100461private function f_tc_lu_imsi_noauth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100462 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100463 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100464}
Harald Weltea49e36e2018-01-21 19:29:33 +0100465testcase TC_lu_imsi_noauth_tmsi() runs on MTC_CT {
466 var BSC_ConnHdlr vc_conn;
467 f_init();
468
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100469 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi), 1);
Harald Weltea49e36e2018-01-21 19:29:33 +0100470 vc_conn.done;
471}
472
473private function f_tc_lu_imsi_noauth_notmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100474 pars.net.expect_tmsi := false;
Harald Weltea10db902018-01-27 12:44:49 +0100475 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100476 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100477}
Harald Weltea49e36e2018-01-21 19:29:33 +0100478testcase TC_lu_imsi_noauth_notmsi() runs on MTC_CT {
479 var BSC_ConnHdlr vc_conn;
480 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100481 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
Harald Weltea49e36e2018-01-21 19:29:33 +0100482
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100483 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi), 2);
Harald Weltea49e36e2018-01-21 19:29:33 +0100484 vc_conn.done;
485}
486
487/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
Harald Weltee13cfb22019-04-23 16:52:02 +0200488friend function f_tc_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100489 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100490 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
491
492 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +0200493 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyrd076c522019-11-28 01:00:52 +0100494 f_mm_common();
Harald Weltea49e36e2018-01-21 19:29:33 +0100495 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
496 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
497 alt {
Harald Welte5946b332018-03-18 23:32:21 +0100498 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej(int2oct(23,1)))) {
499 f_expect_clear();
500 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100501 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
502 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200503 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100504 }
505 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100506}
507testcase TC_lu_imsi_reject() runs on MTC_CT {
508 var BSC_ConnHdlr vc_conn;
509 f_init();
510
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200511 vc_conn := f_start_handler(refers(f_tc_lu_imsi_reject), 3, verify_cell_id := false);
Harald Weltea49e36e2018-01-21 19:29:33 +0100512 vc_conn.done;
513}
514
Harald Weltee13cfb22019-04-23 16:52:02 +0200515
516
Harald Weltea49e36e2018-01-21 19:29:33 +0100517/* Do LU by IMSI, timeout on GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +0200518friend function f_tc_lu_imsi_timeout_gsup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100519 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100520 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
521
522 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +0200523 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyrd076c522019-11-28 01:00:52 +0100524 f_mm_common();
Harald Weltea49e36e2018-01-21 19:29:33 +0100525 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
526 /* Normally the HLR would need to respond here, but we decide to force a timeout here */
527 alt {
528 /* FIXME: Expect specific reject cause */
Harald Welte5946b332018-03-18 23:32:21 +0100529 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
530 f_expect_clear();
531 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100532 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
533 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200534 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100535 }
536 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100537}
538testcase TC_lu_imsi_timeout_gsup() runs on MTC_CT {
539 var BSC_ConnHdlr vc_conn;
540 f_init();
541
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200542 vc_conn := f_start_handler(refers(f_tc_lu_imsi_timeout_gsup), 4, verify_cell_id := false);
Harald Weltea49e36e2018-01-21 19:29:33 +0100543 vc_conn.done;
544}
545
Harald Weltee13cfb22019-04-23 16:52:02 +0200546
Harald Welte7b1b2812018-01-22 21:23:06 +0100547private function f_tc_lu_imsi_auth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100548 pars.net.expect_auth := true;
Harald Weltea10db902018-01-27 12:44:49 +0100549 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100550 f_perform_lu();
Harald Welte7b1b2812018-01-22 21:23:06 +0100551}
552testcase TC_lu_imsi_auth_tmsi() runs on MTC_CT {
553 var BSC_ConnHdlr vc_conn;
554 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100555 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte7b1b2812018-01-22 21:23:06 +0100556
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100557 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi), 5);
Harald Welte7b1b2812018-01-22 21:23:06 +0100558 vc_conn.done;
559}
560
Harald Weltee13cfb22019-04-23 16:52:02 +0200561
562friend function f_tc_lu_imsi_auth3g_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte8a397ae2019-04-21 22:03:37 +0200563 pars.net.expect_auth := true;
564 pars.use_umts_aka := true;
565 f_init_handler(pars);
566 f_perform_lu();
567}
568testcase TC_lu_imsi_auth3g_tmsi() runs on MTC_CT {
569 var BSC_ConnHdlr vc_conn;
570 f_init();
571 f_vty_config(MSCVTY, "network", "authentication required");
572
573 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi), 1005);
574 vc_conn.done;
575}
Harald Weltea49e36e2018-01-21 19:29:33 +0100576
Pau Espin Pedrold3d54a92019-12-17 17:02:54 +0100577/* Proceed with LU but never receive an TMSI Realloc from MS after LU Accept (OS#4337).
578 * TS 24.008 sec 4.3.1.5 states MSC should simply release all MM connections.
579 */
580friend function f_tc_lu_imsi_timeout_tmsi_realloc(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
581
582 f_init_handler(pars);
583
584 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
585 var PDU_DTAP_MT dtap_mt;
586
587 /* tell GSUP dispatcher to send this IMSI to us */
588 f_create_gsup_expect(hex2str(g_pars.imsi));
589
590 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
591 if (g_pars.ran_is_geran) {
592 f_bssap_compl_l3(l3_lu);
593 if (g_pars.send_early_cm) {
594 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
595 }
596 } else {
597 f_ranap_initial_ue(l3_lu);
598 }
599
600 f_mm_imei_early();
601 f_mm_common();
602 f_msc_lu_hlr();
603 f_mm_imei();
604
605 alt {
606 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) -> value dtap_mt {}
607 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
608 setverdict(fail, "Expected LU ACK, but received LU REJ");
609 mtc.stop;
610 }
611 }
612
613 /* currently (due to bug OS#4337), an extra LU reject is received before
614 terminating the connection. Enabling following line makes the test
615 pass: */
616 //f_expect_lu_reject('16'O); /* Cause: congestion */
617
618 /* f_expect_lu_reject() already waits for T"-1" (X1, 5 seconds), but give some
619 extra time to avoid race conditons... */
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200620 f_expect_clear(7.0, verify_vlr_cell_id := false);
Pau Espin Pedrold3d54a92019-12-17 17:02:54 +0100621
622 setverdict(pass);
623}
624testcase TC_lu_imsi_timeout_tmsi_realloc() runs on MTC_CT {
625 var BSC_ConnHdlr vc_conn;
626 f_init();
627
628 vc_conn := f_start_handler(refers(f_tc_lu_imsi_timeout_tmsi_realloc), 5);
629 vc_conn.done;
630}
631
Harald Weltee13cfb22019-04-23 16:52:02 +0200632
Harald Weltea49e36e2018-01-21 19:29:33 +0100633/* Send CM SERVICE REQ for IMSI that has never performed LU before */
Harald Weltee13cfb22019-04-23 16:52:02 +0200634friend function f_tc_cmserv_imsi_unknown(charstring id, BSC_ConnHdlrPars pars)
Harald Weltea49e36e2018-01-21 19:29:33 +0100635runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100636 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100637
638 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welteedbab812018-03-18 16:02:25 +0100639 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
Harald Welte6ed6bf92018-01-24 21:09:15 +0100640 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
Harald Weltea49e36e2018-01-21 19:29:33 +0100641
642 f_create_gsup_expect(hex2str(g_pars.imsi));
643
644 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200645 f_cl3_or_initial_ue(l3_info);
Harald Welteb7817992019-05-09 13:15:39 +0200646 f_mm_auth();
Harald Weltea49e36e2018-01-21 19:29:33 +0100647
648 timer T := 10.0;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100649 T.start;
650 alt {
Harald Weltea49e36e2018-01-21 19:29:33 +0100651 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
652 //[] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_ACC)) { }
Daniel Willmannafce8662018-07-06 23:11:32 +0200653 [] BSSAP.receive {
654 setverdict(fail, "Received unexpected BSSAP");
655 mtc.stop;
656 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100657 [] GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi)) {
658 setverdict(fail, "Unexpected GSUP UL REQ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200659 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100660 }
Daniel Willmannafce8662018-07-06 23:11:32 +0200661 [] T.timeout {
Neels Hofmeyrf1c3c212020-08-19 13:15:32 +0000662 setverdict(fail, "Timeout waiting for CM SERV REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200663 mtc.stop;
664 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100665 }
666
Harald Welte1ddc7162018-01-27 14:25:46 +0100667 f_expect_clear();
Harald Weltef6dd64d2017-11-19 12:09:51 +0100668}
Harald Weltea49e36e2018-01-21 19:29:33 +0100669testcase TC_cmserv_imsi_unknown() runs on MTC_CT {
670 var BSC_ConnHdlr vc_conn;
671 f_init();
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200672 vc_conn := f_start_handler(refers(f_tc_cmserv_imsi_unknown), 6, verify_cell_id := false);
Harald Weltea49e36e2018-01-21 19:29:33 +0100673 vc_conn.done;
674}
675
Harald Weltee13cfb22019-04-23 16:52:02 +0200676
Neels Hofmeyr13737fb2020-08-19 13:16:14 +0000677/* Send CM SERVICE REQ for TMSI that has never performed LU before */
678friend function f_tc_cmserv_tmsi_unknown(charstring id, BSC_ConnHdlrPars pars)
679runs on BSC_ConnHdlr {
680 f_init_handler(pars);
681
682 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV('57111111'O));
683 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
684 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
685
686 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
687 f_cl3_or_initial_ue(l3_info);
688 f_mm_auth();
689
690 timer T := 10.0;
691 T.start;
692 alt {
693 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
694 [] BSSAP.receive {
695 setverdict(fail, "Received unexpected BSSAP");
696 mtc.stop;
697 }
698 [] T.timeout {
699 setverdict(fail, "Timeout waiting for CM SERV REJ");
700 mtc.stop;
701 }
702 }
703
704 f_expect_clear();
705}
706testcase TC_cmserv_tmsi_unknown() runs on MTC_CT {
707 var BSC_ConnHdlr vc_conn;
708 f_init();
709 vc_conn := f_start_handler(refers(f_tc_cmserv_tmsi_unknown), 57, verify_cell_id := false);
710 vc_conn.done;
711}
712
Neels Hofmeyr14d0b132020-08-19 13:49:05 +0000713/* Send Paging Response for IMSI that has never performed LU before */
714friend function f_tc_paging_response_imsi_unknown(charstring id, BSC_ConnHdlrPars pars)
715runs on BSC_ConnHdlr {
716 f_init_handler(pars);
717
718 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
719 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
720 var PDU_ML3_MS_NW l3_info := valueof(ts_PAG_RESP(mi));
721
722 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
723 f_cl3_or_initial_ue(l3_info);
724
725 /* The Paging Response gets rejected by a direct Clear Command */
726 f_expect_clear();
727}
728testcase TC_paging_response_imsi_unknown() runs on MTC_CT {
729 var BSC_ConnHdlr vc_conn;
730 f_init();
731 vc_conn := f_start_handler(refers(f_tc_paging_response_imsi_unknown), 58, verify_cell_id := false);
732 vc_conn.done;
733}
734
735/* Send Paging Response for TMSI that has never performed LU before */
736friend function f_tc_paging_response_tmsi_unknown(charstring id, BSC_ConnHdlrPars pars)
737runs on BSC_ConnHdlr {
738 f_init_handler(pars);
739
740 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV('59111111'O));
741 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
742 var PDU_ML3_MS_NW l3_info := valueof(ts_PAG_RESP(mi));
743
744 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
745 f_cl3_or_initial_ue(l3_info);
746
747 /* The Paging Response gets rejected by a direct Clear Command */
748 f_expect_clear();
749}
750testcase TC_paging_response_tmsi_unknown() runs on MTC_CT {
751 var BSC_ConnHdlr vc_conn;
752 f_init();
753 vc_conn := f_start_handler(refers(f_tc_paging_response_tmsi_unknown), 59, verify_cell_id := false);
754 vc_conn.done;
755}
756
Neels Hofmeyr13737fb2020-08-19 13:16:14 +0000757
Harald Weltee13cfb22019-04-23 16:52:02 +0200758friend function f_tc_lu_and_mo_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100759 f_init_handler(pars);
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +0200760 var CallParameters cpars := valueof(t_CallParams);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100761 f_perform_lu();
Harald Welteb71901a2018-01-26 19:16:05 +0100762 f_mo_call(cpars);
Harald Welte2bb825f2018-01-22 11:31:18 +0100763}
764testcase TC_lu_and_mo_call() runs on MTC_CT {
765 var BSC_ConnHdlr vc_conn;
766 f_init();
767
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100768 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_call), 7);
Harald Welte071ed732018-01-23 19:53:52 +0100769 vc_conn.done;
770}
Pau Espin Pedrol833174e2020-09-03 16:46:02 +0200771friend function f_tc_lu_and_mo_call_ipv6(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
772 f_init_handler(pars);
773 var CallParameters cpars := valueof(t_CallParams);
774 cpars.mgw_conn_1.mgw_rtp_ip := "::1";
775 cpars.mgw_conn_2.mgw_rtp_ip := "::2";
776 cpars.bss_rtp_ip := "::3";
777 f_perform_lu();
778 f_mo_call(cpars);
779}
780testcase TC_lu_and_mo_call_ipv6() runs on MTC_CT {
781 var BSC_ConnHdlr vc_conn;
782 f_init();
783
784 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_call_ipv6), 7);
785 vc_conn.done;
786}
Harald Welte071ed732018-01-23 19:53:52 +0100787
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100788/* Verify T(iar) triggers and releases the channel */
789friend function f_lu_and_mo_call_sccp_tiar_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
790 timer T_wait_iar := int2float(5 + 1); /* g_msc_sccp_timer_iar + Give extra time (+1 sec) */
791 f_init_handler(pars);
792 var CallParameters cpars := valueof(t_CallParams);
793 f_perform_lu();
794 f_mo_call_establish(cpars);
795
796 /* Expect the channel cleared upon T(iar) triggered: */
797 T_wait_iar.start;
798 alt {
799 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {
800 T_wait_iar.stop
801 setverdict(pass);
802 }
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100803 [] T_wait_iar.timeout {
804 setverdict(fail, "Timeout waiting for T(iar) triggered SCCP RSLD");
805 mtc.stop;
806 }
807 }
Harald Welte4a3fa712020-08-19 08:57:33 +0200808 /* DLCX for both directions; if we don't do this, we might receive either of the two during
809 * shutdown causing race conditions */
810 MGCP.receive(tr_DLCX(?));
811 MGCP.receive(tr_DLCX(?));
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100812
813 setverdict(pass);
814}
815testcase TC_lu_and_mo_call_sccp_tiar_timeout() runs on MTC_CT {
816 var BSC_ConnHdlr vc_conn;
817
818 /* Set T(iar) in MSC low enough that it will trigger before other side
819 has time to keep alive with a T(ias). Keep recommended ratio of
820 T(iar) >= T(ias)*2 */
821 g_msc_sccp_timer_ias := 2;
822 g_msc_sccp_timer_iar := 5;
823
824 f_init();
825
826 vc_conn := f_start_handler(refers(f_lu_and_mo_call_sccp_tiar_timeout), 89);
827 vc_conn.done;
828}
829
Harald Weltee13cfb22019-04-23 16:52:02 +0200830
Harald Welte071ed732018-01-23 19:53:52 +0100831/* Test LU (with authentication enabled), where HLR times out sending SAI response */
Harald Weltee13cfb22019-04-23 16:52:02 +0200832friend function f_tc_lu_auth_sai_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100833 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100834
835 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
836 var PDU_DTAP_MT dtap_mt;
837
838 /* tell GSUP dispatcher to send this IMSI to us */
839 f_create_gsup_expect(hex2str(g_pars.imsi));
840
841 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200842 f_cl3_or_initial_ue(l3_lu);
Harald Welte071ed732018-01-23 19:53:52 +0100843
844 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200845 if (pars.ran_is_geran) {
846 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
847 }
Harald Welte071ed732018-01-23 19:53:52 +0100848
849 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
850 /* The HLR would normally return an auth vector here, but we fail to do so. */
851
852 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100853 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100854}
855testcase TC_lu_auth_sai_timeout() runs on MTC_CT {
856 var BSC_ConnHdlr vc_conn;
857 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100858 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100859
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200860 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_timeout), 8, verify_cell_id := false);
Harald Welte071ed732018-01-23 19:53:52 +0100861 vc_conn.done;
862}
863
Harald Weltee13cfb22019-04-23 16:52:02 +0200864
Harald Welte071ed732018-01-23 19:53:52 +0100865/* Test LU (with authentication enabled), where HLR rejects sending SAI error */
Harald Weltee13cfb22019-04-23 16:52:02 +0200866friend function f_tc_lu_auth_sai_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100867 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100868
869 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
870 var PDU_DTAP_MT dtap_mt;
871
872 /* tell GSUP dispatcher to send this IMSI to us */
873 f_create_gsup_expect(hex2str(g_pars.imsi));
874
875 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200876 f_cl3_or_initial_ue(l3_lu);
Harald Welte071ed732018-01-23 19:53:52 +0100877
878 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200879 if (pars.ran_is_geran) {
880 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
881 }
Harald Welte071ed732018-01-23 19:53:52 +0100882
883 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
884 GSUP.send(ts_GSUP_SAI_ERR(g_pars.imsi, 13));
885
886 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100887 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100888}
889testcase TC_lu_auth_sai_err() runs on MTC_CT {
890 var BSC_ConnHdlr vc_conn;
891 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100892 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100893
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200894 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_err), 9, verify_cell_id := false);
Harald Welte2bb825f2018-01-22 11:31:18 +0100895 vc_conn.done;
896}
Harald Weltea49e36e2018-01-21 19:29:33 +0100897
Harald Weltee13cfb22019-04-23 16:52:02 +0200898
Harald Weltebc881782018-01-23 20:09:15 +0100899/* Test LU but BSC will send a clear request in the middle */
900private function f_tc_lu_clear_request(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100901 f_init_handler(pars);
Harald Weltebc881782018-01-23 20:09:15 +0100902
903 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
904 var PDU_DTAP_MT dtap_mt;
905
906 /* tell GSUP dispatcher to send this IMSI to us */
907 f_create_gsup_expect(hex2str(g_pars.imsi));
908
909 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200910 f_cl3_or_initial_ue(l3_lu);
Harald Welte79f1e452020-08-18 22:55:02 +0200911 f_expect_common_id();
Harald Weltebc881782018-01-23 20:09:15 +0100912
913 /* Send Early Classmark, just for the fun of it */
914 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
915
916 f_sleep(1.0);
917 /* send clear request in the middle of the LU */
918 BSSAP.send(ts_BSSMAP_ClearRequest(0));
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200919 alt {
920 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { repeat; }
921 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {}
922 }
Harald Weltebc881782018-01-23 20:09:15 +0100923 BSSAP.send(ts_BSSMAP_ClearComplete);
Harald Welte89a32492018-01-27 19:07:28 +0100924 alt {
925 /* See https://osmocom.org/issues/2862 */
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200926 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {
927 setverdict(fail, "Got a second Clear Command, only one expected");
Daniel Willmannafce8662018-07-06 23:11:32 +0200928 mtc.stop;
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200929 repeat;
930 }
Harald Welte6811d102019-04-14 22:23:14 +0200931 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte89a32492018-01-27 19:07:28 +0100932 }
Harald Weltebc881782018-01-23 20:09:15 +0100933 setverdict(pass);
934}
935testcase TC_lu_clear_request() runs on MTC_CT {
936 var BSC_ConnHdlr vc_conn;
937 f_init();
938
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100939 vc_conn := f_start_handler(refers(f_tc_lu_clear_request), 10);
Harald Weltebc881782018-01-23 20:09:15 +0100940 vc_conn.done;
941}
942
Harald Welte66af9e62018-01-24 17:28:21 +0100943/* Test LU but BSC will send a clear request in the middle */
Harald Weltee13cfb22019-04-23 16:52:02 +0200944friend function f_tc_lu_disconnect(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100945 f_init_handler(pars);
Harald Welte66af9e62018-01-24 17:28:21 +0100946
947 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
948 var PDU_DTAP_MT dtap_mt;
949
950 /* tell GSUP dispatcher to send this IMSI to us */
951 f_create_gsup_expect(hex2str(g_pars.imsi));
952
953 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200954 f_cl3_or_initial_ue(l3_lu);
Harald Welte66af9e62018-01-24 17:28:21 +0100955
956 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200957 if (pars.ran_is_geran) {
958 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
959 }
Harald Welte66af9e62018-01-24 17:28:21 +0100960
961 f_sleep(1.0);
962 /* send clear request in the middle of the LU */
Harald Welte6811d102019-04-14 22:23:14 +0200963 BSSAP.send(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_REQ);
Harald Welte66af9e62018-01-24 17:28:21 +0100964 setverdict(pass);
Neels Hofmeyrbb825c92019-03-06 15:35:50 +0100965 f_sleep(1.0);
Harald Welte66af9e62018-01-24 17:28:21 +0100966}
967testcase TC_lu_disconnect() runs on MTC_CT {
968 var BSC_ConnHdlr vc_conn;
969 f_init();
970
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100971 vc_conn := f_start_handler(refers(f_tc_lu_disconnect), 11);
Harald Welte66af9e62018-01-24 17:28:21 +0100972 vc_conn.done;
973}
974
Harald Welteba7b6d92018-01-23 21:32:34 +0100975/* Test LU but with illegal mobile identity type = IMEI */
Harald Weltee13cfb22019-04-23 16:52:02 +0200976friend function f_tc_lu_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100977 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +0100978
Harald Welte256571e2018-01-24 18:47:19 +0100979 var PDU_ML3_MS_NW l3_lu := f_build_lu_imei(g_pars.imei)
Harald Welteba7b6d92018-01-23 21:32:34 +0100980 var PDU_DTAP_MT dtap_mt;
981
982 /* tell GSUP dispatcher to send this IMSI to us */
983 f_create_gsup_expect(hex2str(g_pars.imsi));
984
985 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200986 f_cl3_or_initial_ue(l3_lu);
Harald Welteba7b6d92018-01-23 21:32:34 +0100987
988 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200989 if (pars.ran_is_geran) {
990 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
991 }
Harald Welteba7b6d92018-01-23 21:32:34 +0100992 /* wait for LU reject, ignore any ID REQ */
993 alt {
994 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { }
995 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req)) { repeat; }
996 }
997 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100998 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +0100999}
1000testcase TC_lu_by_imei() runs on MTC_CT {
1001 var BSC_ConnHdlr vc_conn;
1002 f_init();
1003
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001004 vc_conn := f_start_handler(refers(f_tc_lu_by_imei), 12, verify_cell_id := false);
Harald Welteba7b6d92018-01-23 21:32:34 +01001005 vc_conn.done;
1006}
1007
Harald Weltee13cfb22019-04-23 16:52:02 +02001008
Harald Welteba7b6d92018-01-23 21:32:34 +01001009/* Test LU by TMSI with unknown TMSI, expect (and answer) ID REQ. */
1010private function f_tc_lu_tmsi_noauth_unknown(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Stefan Sperling04fc4bc2018-06-25 17:44:57 +02001011 /* We piggyback a test for an MSC crash on overlong IMSI (OS#2864) onto this test. */
1012 var hexstring overlong_imsi := '012345789ABCDEF0123456789ABCDEF'H;
Harald Weltea10db902018-01-27 12:44:49 +01001013 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +01001014
1015 var PDU_ML3_MS_NW l3_lu := f_build_lu_tmsi('01020304'O); /* FIXME: Random */
1016 var PDU_DTAP_MT dtap_mt;
1017
1018 /* tell GSUP dispatcher to send this IMSI to us */
1019 f_create_gsup_expect(hex2str(g_pars.imsi));
1020
1021 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001022 f_cl3_or_initial_ue(l3_lu);
Harald Welteba7b6d92018-01-23 21:32:34 +01001023
1024 /* Send Early Classmark, just for the fun of it */
1025 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1026
1027 /* Wait for + respond to ID REQ (IMSI) */
Oliver Smith32898452019-07-09 12:32:35 +02001028 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
Stefan Sperling04fc4bc2018-06-25 17:44:57 +02001029 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(overlong_imsi))); /* test for OS#2864 */
Harald Welteba7b6d92018-01-23 21:32:34 +01001030 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(g_pars.imsi)));
Harald Welte79f1e452020-08-18 22:55:02 +02001031 f_expect_common_id();
Harald Welteba7b6d92018-01-23 21:32:34 +01001032
1033 /* Expect MSC to do UpdateLocation to HLR; respond to it */
1034 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
1035 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
1036 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
1037 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
1038
1039 alt {
Harald Welte7ec4fa82018-01-27 10:57:40 +01001040 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
1041 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_TmsiRealloc_Cmpl));
1042 }
Harald Welteba7b6d92018-01-23 21:32:34 +01001043 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1044 setverdict(fail, "Expected LU ACK, but received REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +02001045 mtc.stop;
Harald Welteba7b6d92018-01-23 21:32:34 +01001046 }
1047 }
1048
Philipp Maier9b690e42018-12-21 11:50:03 +01001049 /* Wait for MM-Information (if enabled) */
1050 f_expect_mm_info();
1051
Harald Welteba7b6d92018-01-23 21:32:34 +01001052 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001053 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +01001054}
1055testcase TC_lu_by_tmsi_noauth_unknown() runs on MTC_CT {
1056 var BSC_ConnHdlr vc_conn;
1057 f_init();
1058
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001059 vc_conn := f_start_handler(refers(f_tc_lu_tmsi_noauth_unknown), 13);
Harald Welteba7b6d92018-01-23 21:32:34 +01001060 vc_conn.done;
1061}
1062
Neels Hofmeyrfc06c732020-08-19 12:52:28 +00001063/* Test LU by unknown TMSI, while the IMSI is already attached: osmo-msc should switch to the attached vlr_subscr. */
1064private function f_tc_attached_imsi_lu_unknown_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1065 f_init_handler(pars);
1066
1067 var PDU_ML3_MS_NW l3_lu := f_build_lu_tmsi('56111111'O);
1068 var PDU_DTAP_MT dtap_mt;
1069
1070 /* tell GSUP dispatcher to send this IMSI to us */
1071 f_create_gsup_expect(hex2str(g_pars.imsi));
1072
1073 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
1074 f_cl3_or_initial_ue(l3_lu);
1075
1076 /* Send Early Classmark, just for the fun of it */
1077 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1078
1079 /* Wait for + respond to ID REQ (IMSI) */
1080 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
1081 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(g_pars.imsi)));
1082 f_expect_common_id();
1083
1084 /* Expect MSC to do UpdateLocation to HLR; respond to it */
1085 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
1086 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
1087 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
1088 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
1089
1090 alt {
1091 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
1092 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_TmsiRealloc_Cmpl));
1093 }
1094 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1095 setverdict(fail, "Expected LU ACK, but received REJ");
1096 mtc.stop;
1097 }
1098 }
1099
1100 /* Wait for MM-Information (if enabled) */
1101 f_expect_mm_info();
1102
1103 /* wait for normal teardown */
1104 f_expect_clear();
1105
1106 /* Now the same IMSI is still attached in the VLR, and a LU with an unknown TMSI reveals the same IMSI only
1107 * later during ID Response. osmo-msc first creates a new vlr_subscr for the unknown TMSI, and as soon as the
1108 * IMSI becomes known, must notice that this IMSI is still regarded as attached, and must not create evil twins.
1109 */
1110
1111 /* (since the TMSI Reallocation happened, we could do this with exactly the same TMSI as above, but for test
1112 * readability just use a different one.) */
1113 l3_lu := f_build_lu_tmsi('56222222'O);
1114 f_cl3_or_initial_ue(l3_lu);
1115
1116 /* Wait for + respond to ID REQ (IMSI) */
1117 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
1118 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(g_pars.imsi)));
1119 f_expect_common_id();
1120
1121 /* Expect MSC to do UpdateLocation to HLR; respond to it */
1122 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
1123 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
1124 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
1125 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
1126
1127 alt {
1128 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
1129 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_TmsiRealloc_Cmpl));
1130 }
1131 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1132 setverdict(fail, "Expected LU ACK, but received REJ");
1133 mtc.stop;
1134 }
1135 }
1136
1137 /* Wait for MM-Information (if enabled) */
1138 f_expect_mm_info();
1139
1140 /* wait for normal teardown */
1141 f_expect_clear();
1142}
1143testcase TC_attached_imsi_lu_unknown_tmsi() runs on MTC_CT {
1144 var BSC_ConnHdlr vc_conn;
1145 f_init();
1146
1147 vc_conn := f_start_handler(refers(f_tc_attached_imsi_lu_unknown_tmsi), 56);
1148 vc_conn.done;
1149}
1150
Harald Welte4d15fa72020-08-19 08:58:28 +02001151friend function f_imsi_detach_by_imsi() runs on BSC_ConnHdlr {
Harald Welte45164da2018-01-24 12:51:27 +01001152 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1153
1154 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001155 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +01001156
1157 /* Send Early Classmark, just for the fun of it? */
Harald Welte4d15fa72020-08-19 08:58:28 +02001158 if (g_pars.ran_is_geran) {
Harald Weltee13cfb22019-04-23 16:52:02 +02001159 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1160 }
Harald Welte45164da2018-01-24 12:51:27 +01001161
1162 /* wait for normal teardown */
Harald Welte4d15fa72020-08-19 08:58:28 +02001163 f_expect_clear(verify_vlr_cell_id := false);
1164}
1165
1166
1167/* Test IMSI DETACH (MI=IMSI) */
1168friend function f_tc_imsi_detach_by_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1169 f_init_handler(pars);
1170
1171 f_imsi_detach_by_imsi();
Harald Welte45164da2018-01-24 12:51:27 +01001172}
1173testcase TC_imsi_detach_by_imsi() runs on MTC_CT {
1174 var BSC_ConnHdlr vc_conn;
1175 f_init();
1176
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001177 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imsi), 14, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001178 vc_conn.done;
1179}
1180
Harald Weltee13cfb22019-04-23 16:52:02 +02001181
Harald Welte45164da2018-01-24 12:51:27 +01001182/* Test IMSI DETACH (MI=TMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +02001183friend function f_tc_imsi_detach_by_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001184 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001185
1186 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV('01020304'O));
1187
1188 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001189 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +01001190
1191 /* Send Early Classmark, just for the fun of it? */
Harald Weltee13cfb22019-04-23 16:52:02 +02001192 if (pars.ran_is_geran) {
1193 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1194 }
Harald Welte45164da2018-01-24 12:51:27 +01001195
1196 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001197 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001198}
1199testcase TC_imsi_detach_by_tmsi() runs on MTC_CT {
1200 var BSC_ConnHdlr vc_conn;
1201 f_init();
1202
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001203 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_tmsi), 15, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001204 vc_conn.done;
1205}
1206
Harald Weltee13cfb22019-04-23 16:52:02 +02001207
Harald Welte45164da2018-01-24 12:51:27 +01001208/* Test IMSI DETACH (MI=IMEI), which is illegal */
Harald Weltee13cfb22019-04-23 16:52:02 +02001209friend function f_tc_imsi_detach_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001210 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001211
Harald Welte256571e2018-01-24 18:47:19 +01001212 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte45164da2018-01-24 12:51:27 +01001213
1214 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001215 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +01001216
1217 /* Send Early Classmark, just for the fun of it? */
Harald Weltee13cfb22019-04-23 16:52:02 +02001218 if (pars.ran_is_geran) {
1219 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1220 }
Harald Welte45164da2018-01-24 12:51:27 +01001221
1222 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001223 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001224}
1225testcase TC_imsi_detach_by_imei() runs on MTC_CT {
1226 var BSC_ConnHdlr vc_conn;
1227 f_init();
1228
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001229 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imei), 16, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001230 vc_conn.done;
1231}
1232
1233
1234/* helper function for an emergency call. caller passes in mobile identity to use */
1235private function f_emerg_call(MobileIdentityLV mi) runs on BSC_ConnHdlr {
Harald Welte0bef21e2018-02-10 09:48:23 +01001236 var CallParameters cpars := valueof(t_CallParams('112'H, 0));
1237 cpars.emergency := true;
Harald Welte45164da2018-01-24 12:51:27 +01001238
Harald Welte0bef21e2018-02-10 09:48:23 +01001239 f_mo_call(cpars);
Harald Welte45164da2018-01-24 12:51:27 +01001240}
1241
1242/* establish an emergency call by IMEI, no SIM inserted (and hence no IMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +02001243friend function f_tc_emerg_call_imei_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001244 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001245
Harald Welte256571e2018-01-24 18:47:19 +01001246 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001247 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_EMERG_CALL, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001248 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001249 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ('05'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +01001250 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001251}
1252testcase TC_emerg_call_imei_reject() runs on MTC_CT {
1253 var BSC_ConnHdlr vc_conn;
1254 f_init();
1255
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001256 vc_conn := f_start_handler(refers(f_tc_emerg_call_imei_reject), 17, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001257 vc_conn.done;
1258}
1259
Harald Weltee13cfb22019-04-23 16:52:02 +02001260
Harald Welted5b91402018-01-24 18:48:16 +01001261/* establish an emergency call by IMSI, SIM inserted (and hence IMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +02001262friend function f_tc_emerg_call_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001263 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001264 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001265 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001266 /* Then issue emergency call identified by IMSI */
1267 f_emerg_call(valueof(ts_MI_IMSI_LV(g_pars.imsi)));
1268}
1269testcase TC_emerg_call_imsi() runs on MTC_CT {
1270 var BSC_ConnHdlr vc_conn;
1271 f_init();
1272
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001273 vc_conn := f_start_handler(refers(f_tc_emerg_call_imsi), 18);
Harald Welte45164da2018-01-24 12:51:27 +01001274 vc_conn.done;
1275}
1276
Harald Weltee13cfb22019-04-23 16:52:02 +02001277
Harald Welte45164da2018-01-24 12:51:27 +01001278/* CM Service Request for VGCS -> reject */
1279private function f_tc_cm_serv_req_vgcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001280 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001281
1282 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001283 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001284
1285 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001286 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VGCS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001287 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001288 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001289 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001290}
1291testcase TC_cm_serv_req_vgcs_reject() runs on MTC_CT {
1292 var BSC_ConnHdlr vc_conn;
1293 f_init();
1294
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001295 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vgcs_reject), 19);
Harald Welte45164da2018-01-24 12:51:27 +01001296 vc_conn.done;
1297}
1298
1299/* CM Service Request for VBS -> reject */
1300private function f_tc_cm_serv_req_vbs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001301 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001302
1303 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001304 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001305
1306 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001307 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VBS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001308 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001309 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001310 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001311}
1312testcase TC_cm_serv_req_vbs_reject() runs on MTC_CT {
1313 var BSC_ConnHdlr vc_conn;
1314 f_init();
1315
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001316 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vbs_reject), 20);
Harald Welte45164da2018-01-24 12:51:27 +01001317 vc_conn.done;
1318}
1319
1320/* CM Service Request for LCS -> reject */
1321private function f_tc_cm_serv_req_lcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001322 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001323
1324 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001325 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001326
1327 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001328 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_LCS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001329 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001330 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001331 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001332}
1333testcase TC_cm_serv_req_lcs_reject() runs on MTC_CT {
1334 var BSC_ConnHdlr vc_conn;
1335 f_init();
1336
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001337 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_lcs_reject), 21);
Harald Welte45164da2018-01-24 12:51:27 +01001338 vc_conn.done;
1339}
1340
Harald Welte0195ab12018-01-24 21:50:20 +01001341/* CM Re-Establishment Request */
1342private function f_tc_cm_reest_req_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001343 f_init_handler(pars);
Harald Welte0195ab12018-01-24 21:50:20 +01001344
1345 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001346 f_perform_lu();
Harald Welte0195ab12018-01-24 21:50:20 +01001347
1348 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1349 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_REEST_REQ(0, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001350 f_cl3_or_initial_ue(l3_info);
Harald Welte0195ab12018-01-24 21:50:20 +01001351 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001352 f_expect_clear();
Harald Welte0195ab12018-01-24 21:50:20 +01001353}
1354testcase TC_cm_reest_req_reject() runs on MTC_CT {
1355 var BSC_ConnHdlr vc_conn;
1356 f_init();
Harald Welte0195ab12018-01-24 21:50:20 +01001357
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001358 vc_conn := f_start_handler(refers(f_tc_cm_reest_req_reject), 22);
Harald Welte0195ab12018-01-24 21:50:20 +01001359 vc_conn.done;
1360}
1361
Harald Weltec638f4d2018-01-24 22:00:36 +01001362/* Test LU (with authentication enabled), with wrong response from MS */
1363private function f_tc_lu_auth_2G_fail(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001364 f_init_handler(pars);
Harald Weltec638f4d2018-01-24 22:00:36 +01001365
1366 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
1367
1368 /* tell GSUP dispatcher to send this IMSI to us */
1369 f_create_gsup_expect(hex2str(g_pars.imsi));
1370
1371 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001372 f_cl3_or_initial_ue(l3_lu);
Harald Weltec638f4d2018-01-24 22:00:36 +01001373
1374 /* Send Early Classmark, just for the fun of it */
1375 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1376
1377 var AuthVector vec := f_gen_auth_vec_2g();
1378 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G(vec.rand, vec.sres, vec.kc));
1379 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
1380 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
1381
1382 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_AUTH_REQ(vec.rand)));
1383 /* Send back wrong auth response */
1384 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MT_MM_AUTH_RESP_2G('00000000'O)));
1385
1386 /* Expect GSUP AUTH FAIL REP to HLR */
1387 GSUP.receive(tr_GSUP_AUTH_FAIL_IND(g_pars.imsi));
1388
1389 /* Expect LU REJECT with Cause == Illegal MS */
1390 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej('03'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +01001391 f_expect_clear();
Harald Weltec638f4d2018-01-24 22:00:36 +01001392}
1393testcase TC_lu_auth_2G_fail() runs on MTC_CT {
1394 var BSC_ConnHdlr vc_conn;
1395 f_init();
1396 f_vty_config(MSCVTY, "network", "authentication required");
Harald Weltec638f4d2018-01-24 22:00:36 +01001397
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001398 vc_conn := f_start_handler(refers(f_tc_lu_auth_2G_fail), 23, verify_cell_id := false);
Harald Weltec638f4d2018-01-24 22:00:36 +01001399 vc_conn.done;
1400}
1401
Harald Weltede371492018-01-27 23:44:41 +01001402/* A5/1 + A5/3 permitted on network side, and MS capable to do it */
Harald Welte16114282018-01-24 22:41:21 +01001403private function f_tc_lu_imsi_auth_tmsi_encr_13_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +01001404 pars.net.expect_auth := true;
1405 pars.net.expect_ciph := true;
Harald Weltea10db902018-01-27 12:44:49 +01001406 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001407 f_perform_lu();
Harald Welte16114282018-01-24 22:41:21 +01001408}
1409testcase TC_lu_imsi_auth_tmsi_encr_13_13() runs on MTC_CT {
1410 var BSC_ConnHdlr vc_conn;
1411 f_init();
1412 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte16114282018-01-24 22:41:21 +01001413 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
1414
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001415 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_13), 24);
Harald Welte16114282018-01-24 22:41:21 +01001416 vc_conn.done;
1417}
1418
Harald Welte1af6ea82018-01-25 18:33:15 +01001419/* Test Complete L3 without payload */
1420private function f_tc_cl3_no_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001421 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001422
1423 /* Send Complete L3 Info with empty L3 frame */
1424 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1425 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, ''O))));
1426
Harald Weltef466eb42018-01-27 14:26:54 +01001427 timer T := 5.0;
1428 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001429 alt {
Harald Welte6811d102019-04-14 22:23:14 +02001430 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte1af6ea82018-01-25 18:33:15 +01001431 /* Expect LU REJECT with Cause == Illegal MS */
Harald Weltebdb3c452018-03-18 22:43:06 +01001432 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
Harald Welte6811d102019-04-14 22:23:14 +02001433 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001434 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001435 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001436 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001437 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001438 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001439 }
1440 setverdict(pass);
1441}
1442testcase TC_cl3_no_payload() runs on MTC_CT {
1443 var BSC_ConnHdlr vc_conn;
1444 f_init();
1445
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001446 vc_conn := f_start_handler(refers(f_tc_cl3_no_payload), 25);
Harald Welte1af6ea82018-01-25 18:33:15 +01001447 vc_conn.done;
1448}
1449
1450/* Test Complete L3 with random payload */
1451private function f_tc_cl3_rnd_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001452 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001453
Daniel Willmannaa14a382018-07-26 08:29:45 +02001454 /* length is limited by PDU_BSSAP length field which includes some
1455 * other fields beside l3info payload. So payl can only be 240 bytes
1456 * Since rnd() returns values < 1 multiply with 241
1457 */
1458 var integer len := float2int(rnd() * 241.0);
Harald Welte1af6ea82018-01-25 18:33:15 +01001459 var octetstring payl := f_rnd_octstring(len);
1460
1461 /* Send Complete L3 Info with empty L3 frame */
1462 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1463 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, payl))));
1464
Harald Weltef466eb42018-01-27 14:26:54 +01001465 timer T := 5.0;
1466 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001467 alt {
1468 /* Immediate disconnect */
Harald Welte6811d102019-04-14 22:23:14 +02001469 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte1af6ea82018-01-25 18:33:15 +01001470 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
Harald Welte6811d102019-04-14 22:23:14 +02001471 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001472 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001473 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001474 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001475 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001476 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001477 }
1478 setverdict(pass);
1479}
1480testcase TC_cl3_rnd_payload() runs on MTC_CT {
1481 var BSC_ConnHdlr vc_conn;
1482 f_init();
1483
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001484 vc_conn := f_start_handler(refers(f_tc_cl3_rnd_payload), 26);
Harald Welte1af6ea82018-01-25 18:33:15 +01001485 vc_conn.done;
1486}
1487
Harald Welte116e4332018-01-26 22:17:48 +01001488/* Test Complete L3 with random payload */
Harald Weltee13cfb22019-04-23 16:52:02 +02001489friend function f_tc_establish_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001490 f_init_handler(pars);
Harald Welte116e4332018-01-26 22:17:48 +01001491
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001492 f_perform_lu();
Harald Welte116e4332018-01-26 22:17:48 +01001493
Harald Welteb9e86fa2018-04-09 18:18:31 +02001494 f_establish_fully();
Daniel Willmann898a7e02018-05-17 12:16:16 +02001495 f_expect_clear(10.0);
Harald Welte116e4332018-01-26 22:17:48 +01001496}
1497testcase TC_establish_and_nothing() runs on MTC_CT {
1498 var BSC_ConnHdlr vc_conn;
1499 f_init();
1500
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001501 vc_conn := f_start_handler(refers(f_tc_establish_and_nothing), 27);
Harald Welte116e4332018-01-26 22:17:48 +01001502 vc_conn.done;
1503}
1504
Harald Weltee13cfb22019-04-23 16:52:02 +02001505
Harald Welte12510c52018-01-26 22:26:24 +01001506/* Test MO Call SETUP with no response from MNCC */
Harald Weltee13cfb22019-04-23 16:52:02 +02001507friend function f_tc_mo_setup_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier109e6aa2018-10-17 10:53:32 +02001508 f_init_handler(pars, 190.0);
Harald Weltea10db902018-01-27 12:44:49 +01001509
Harald Welte12510c52018-01-26 22:26:24 +01001510 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001511 cpars.mgw_conn_2.resp := 0;
1512 cpars.stop_after_cc_setup := true;
1513
1514 f_vty_config(MSCVTY, "msc", "mncc guard-timeout 20");
Harald Welte12510c52018-01-26 22:26:24 +01001515
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001516 f_perform_lu();
Harald Welte12510c52018-01-26 22:26:24 +01001517
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001518 f_mo_call_establish(cpars);
Harald Welte12510c52018-01-26 22:26:24 +01001519
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001520 var default ccrel := activate(as_optional_cc_rel(cpars));
1521
Philipp Maier109e6aa2018-10-17 10:53:32 +02001522 f_expect_clear(185.0);
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001523
1524 deactivate(ccrel);
1525
1526 f_sleep(1.0);
Harald Welte12510c52018-01-26 22:26:24 +01001527}
1528testcase TC_mo_setup_and_nothing() runs on MTC_CT {
1529 var BSC_ConnHdlr vc_conn;
1530 f_init();
1531
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001532 vc_conn := f_start_handler(refers(f_tc_mo_setup_and_nothing), 28);
Harald Welte12510c52018-01-26 22:26:24 +01001533 vc_conn.done;
1534}
1535
Harald Weltee13cfb22019-04-23 16:52:02 +02001536
Harald Welte3ab88002018-01-26 22:37:25 +01001537/* Test MO Call with no response to RAN-side CRCX */
Harald Weltee13cfb22019-04-23 16:52:02 +02001538friend function f_tc_mo_crcx_ran_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001539 f_init_handler(pars);
Harald Welte3ab88002018-01-26 22:37:25 +01001540 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1541 var MNCC_PDU mncc;
1542 var MgcpCommand mgcp_cmd;
1543
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001544 f_perform_lu();
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001545 /* Do not respond to the second CRCX */
1546 cpars.mgw_conn_2.resp := 0;
1547 f_mo_call_establish(cpars);
Harald Welte3ab88002018-01-26 22:37:25 +01001548
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001549 var default ccrel := activate(as_optional_cc_rel(cpars));
Harald Welte3ab88002018-01-26 22:37:25 +01001550
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001551 f_expect_clear(60.0);
Harald Welte3ab88002018-01-26 22:37:25 +01001552
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001553 deactivate(ccrel);
Harald Welte3ab88002018-01-26 22:37:25 +01001554}
1555testcase TC_mo_crcx_ran_timeout() runs on MTC_CT {
1556 var BSC_ConnHdlr vc_conn;
1557 f_init();
1558
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001559 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_timeout), 29);
Harald Welte3ab88002018-01-26 22:37:25 +01001560 vc_conn.done;
1561}
1562
Harald Weltee13cfb22019-04-23 16:52:02 +02001563
Harald Welte0cc82d92018-01-26 22:52:34 +01001564/* Test MO Call with reject to RAN-side CRCX */
Harald Weltee13cfb22019-04-23 16:52:02 +02001565friend function f_tc_mo_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001566 f_init_handler(pars);
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001567
Harald Welte0cc82d92018-01-26 22:52:34 +01001568 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001569
1570 /* Respond with error for the first CRCX */
1571 cpars.mgw_conn_1.resp := -1;
Harald Welte0cc82d92018-01-26 22:52:34 +01001572
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001573 f_perform_lu();
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001574 f_mo_call_establish(cpars);
Harald Welte0cc82d92018-01-26 22:52:34 +01001575
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001576 var default ccrel := activate(as_optional_cc_rel(cpars));
1577 f_expect_clear(60.0);
1578 deactivate(ccrel);
Harald Welte0cc82d92018-01-26 22:52:34 +01001579}
1580testcase TC_mo_crcx_ran_reject() runs on MTC_CT {
1581 var BSC_ConnHdlr vc_conn;
1582 f_init();
1583
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001584 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_reject), 30);
Harald Welte0cc82d92018-01-26 22:52:34 +01001585 vc_conn.done;
1586}
1587
Harald Welte3ab88002018-01-26 22:37:25 +01001588
Harald Welte812f7a42018-01-27 00:49:18 +01001589/* helper function to start a MT call: MNCC SETUP; Paging; DChan est.; DTAP SETUP */
1590private function f_mt_call_start(inout CallParameters cpars) runs on BSC_ConnHdlr {
1591 var MNCC_PDU mncc;
1592 var MgcpCommand mgcp_cmd;
Harald Welte812f7a42018-01-27 00:49:18 +01001593
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001594 f_perform_lu();
Vadim Yanitskiyae747742020-01-10 00:23:10 +01001595 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Welte812f7a42018-01-27 00:49:18 +01001596
1597 /* Allocate call reference and send SETUP via MNCC to MSC */
1598 cpars.mncc_callref := f_rnd_int(2147483648);
1599 MNCC.send(ts_MNCC_SETUP_req(cpars.mncc_callref, hex2str(g_pars.msisdn),
1600 hex2str(cpars.called_party), hex2str(g_pars.imsi)));
1601
1602 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02001603 f_expect_paging();
1604
Harald Welte812f7a42018-01-27 00:49:18 +01001605 /* MS -> MSC: PAGING RESPONSE */
Harald Welteb9e86fa2018-04-09 18:18:31 +02001606 f_establish_fully(EST_TYPE_PAG_RESP);
Harald Welte812f7a42018-01-27 00:49:18 +01001607
1608 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1609
1610 /* MSC->MS: SETUP */
1611 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_SETUP(cpars.transaction_id, *, cpars.called_party)));
1612}
1613
1614/* Test MT Call */
Harald Weltee13cfb22019-04-23 16:52:02 +02001615friend function f_tc_mt_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001616 f_init_handler(pars);
Harald Welte812f7a42018-01-27 00:49:18 +01001617 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1618 var MNCC_PDU mncc;
1619 var MgcpCommand mgcp_cmd;
1620
1621 f_mt_call_start(cpars);
1622
1623 /* MS->MSC: CALL CONFIRMED */
1624 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1625
1626 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1627
1628 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1629 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001630
1631 /* Detect if the received CRCX is a wildcarded CRCX request. If yes,
1632 * set an endpoint name that fits the pattern. If not, just use the
1633 * endpoint name from the request */
1634 if (match(mgcp_cmd.line.ep, t_MGCP_EP_wildcard)) {
1635 cpars.mgcp_ep := "rtpbridge/1@mgw";
1636 } else {
1637 cpars.mgcp_ep := mgcp_cmd.line.ep;
1638 }
1639
Harald Welte812f7a42018-01-27 00:49:18 +01001640 /* Respond to CRCX with error */
1641 var MgcpResponse mgcp_rsp := {
1642 line := {
1643 code := "542",
1644 trans_id := mgcp_cmd.line.trans_id,
1645 string := "FORCED_FAIL"
1646 },
Harald Welte812f7a42018-01-27 00:49:18 +01001647 sdp := omit
1648 }
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001649 var MgcpParameter mgcp_rsp_param := {
1650 code := "Z",
1651 val := cpars.mgcp_ep
1652 };
1653 mgcp_rsp.params[0] := mgcp_rsp_param;
Harald Welte812f7a42018-01-27 00:49:18 +01001654 MGCP.send(mgcp_rsp);
1655
1656 timer T := 30.0;
1657 T.start;
1658 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001659 [] T.timeout {
1660 setverdict(fail, "Timeout waiting for channel release");
1661 mtc.stop;
1662 }
Harald Welte812f7a42018-01-27 00:49:18 +01001663 [] MNCC.receive { repeat; }
1664 [] GSUP.receive { repeat; }
1665 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1666 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
1667 f_create_mgcp_delete_ep(cpars.mgcp_ep);
1668 repeat;
1669 }
1670 [] MGCP.receive { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001671 [] as_clear_cmd_compl_disc();
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001672 [] as_optional_cc_rel(cpars);
Harald Welte812f7a42018-01-27 00:49:18 +01001673 }
1674}
1675testcase TC_mt_crcx_ran_reject() runs on MTC_CT {
1676 var BSC_ConnHdlr vc_conn;
1677 f_init();
1678
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001679 vc_conn := f_start_handler(refers(f_tc_mt_crcx_ran_reject), 31);
Harald Welte812f7a42018-01-27 00:49:18 +01001680 vc_conn.done;
1681}
1682
1683
Harald Weltee13cfb22019-04-23 16:52:02 +02001684
Harald Welte812f7a42018-01-27 00:49:18 +01001685/* Test MT Call T310 timer */
Harald Weltee13cfb22019-04-23 16:52:02 +02001686friend function f_tc_mt_t310(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltead2952e2018-01-27 14:12:46 +01001687 f_init_handler(pars, 200.0);
Harald Welte812f7a42018-01-27 00:49:18 +01001688 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1689 var MNCC_PDU mncc;
1690 var MgcpCommand mgcp_cmd;
1691
1692 f_mt_call_start(cpars);
1693
1694 /* MS->MSC: CALL CONFIRMED */
1695 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1696 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1697
1698 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1699 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
1700 cpars.mgcp_ep := mgcp_cmd.line.ep;
1701 /* FIXME: Respond to CRCX */
1702
1703 /* old libosmocore T310 default timeout is 180s. so let's wait 190 */
1704 timer T := 190.0;
1705 T.start;
1706 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001707 [] T.timeout {
1708 setverdict(fail, "Timeout waiting for T310");
1709 mtc.stop;
1710 }
Harald Welte812f7a42018-01-27 00:49:18 +01001711 [] MNCC.receive(tr_MNCC_DISC_ind(cpars.mncc_callref)) {
1712 MNCC.send(ts_MNCC_REL_req(cpars.mncc_callref, valueof(ts_MNCC_cause(23))));
1713 }
1714 }
1715 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_DISC(cpars.transaction_id)));
1716 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id)));
1717 /* FIXME: We're sending this with TIflag 0: allocated by sender, which is wrong */
1718 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id)));
1719
1720 alt {
Harald Welte812f7a42018-01-27 00:49:18 +01001721 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1722 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
1723 f_create_mgcp_delete_ep(cpars.mgcp_ep);
1724 repeat;
1725 }
Harald Welte5946b332018-03-18 23:32:21 +01001726 [] as_clear_cmd_compl_disc();
Harald Welte812f7a42018-01-27 00:49:18 +01001727 }
1728}
1729testcase TC_mt_t310() runs on MTC_CT {
1730 var BSC_ConnHdlr vc_conn;
1731 f_init();
1732
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001733 vc_conn := f_start_handler(refers(f_tc_mt_t310), 32);
Harald Welte812f7a42018-01-27 00:49:18 +01001734 vc_conn.done;
1735}
1736
Harald Weltee13cfb22019-04-23 16:52:02 +02001737
Harald Welte167458a2018-01-27 15:58:16 +01001738/* Perform successful LU + MO call, then GSUP LocationCancel. Subscriber must be denied CM SERV */
Harald Weltee13cfb22019-04-23 16:52:02 +02001739friend function f_tc_gsup_cancel(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte167458a2018-01-27 15:58:16 +01001740 f_init_handler(pars);
1741 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Harald Welte167458a2018-01-27 15:58:16 +01001742
1743 /* Location Update to make subscriber known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001744 f_perform_lu();
Harald Welte167458a2018-01-27 15:58:16 +01001745
1746 /* First MO call should succeed */
1747 f_mo_call(cpars);
1748
1749 /* Cancel the subscriber in the VLR */
1750 GSUP.send(ts_GSUP_CL_REQ(g_pars.imsi, OSMO_GSUP_CANCEL_TYPE_WITHDRAW));
1751 alt {
1752 [] GSUP.receive(tr_GSUP_CL_RES(g_pars.imsi)) { }
1753 [] GSUP.receive(tr_GSUP_CL_ERR(g_pars.imsi)) {
1754 setverdict(fail, "Received GSUP Location Cancel Error");
Daniel Willmannafce8662018-07-06 23:11:32 +02001755 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001756 }
1757 }
1758
1759 /* Follow-up transactions should fail */
1760 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1761 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001762 f_cl3_or_initial_ue(l3_info);
Harald Welte167458a2018-01-27 15:58:16 +01001763 alt {
1764 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
1765 [] BSSAP.receive {
1766 setverdict(fail, "Received unexpected BSSAP instead of CM SERV REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +02001767 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001768 }
1769 }
Neels Hofmeyr0f7429a2019-03-07 22:28:41 +01001770
1771 f_expect_clear();
Harald Welte167458a2018-01-27 15:58:16 +01001772 setverdict(pass);
1773}
1774testcase TC_gsup_cancel() runs on MTC_CT {
1775 var BSC_ConnHdlr vc_conn;
1776 f_init();
1777
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001778 vc_conn := f_start_handler(refers(f_tc_gsup_cancel), 33, verify_cell_id := false);
Harald Welte167458a2018-01-27 15:58:16 +01001779 vc_conn.done;
1780}
1781
Harald Weltee13cfb22019-04-23 16:52:02 +02001782
Harald Welte9de84792018-01-28 01:06:35 +01001783/* A5/1 only permitted on network side, and MS capable to do it */
1784private function f_tc_lu_imsi_auth_tmsi_encr_1_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1785 pars.net.expect_auth := true;
1786 pars.net.expect_ciph := true;
1787 pars.net.kc_support := '02'O; /* A5/1 only */
1788 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001789 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001790}
1791testcase TC_lu_imsi_auth_tmsi_encr_1_13() runs on MTC_CT {
1792 var BSC_ConnHdlr vc_conn;
1793 f_init();
1794 f_vty_config(MSCVTY, "network", "authentication required");
1795 f_vty_config(MSCVTY, "network", "encryption a5 1");
1796
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001797 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_1_13), 34);
Harald Welte9de84792018-01-28 01:06:35 +01001798 vc_conn.done;
1799}
1800
1801/* A5/3 only permitted on network side, and MS capable to do it */
1802private function f_tc_lu_imsi_auth_tmsi_encr_3_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1803 pars.net.expect_auth := true;
1804 pars.net.expect_ciph := true;
1805 pars.net.kc_support := '08'O; /* A5/3 only */
1806 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001807 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001808}
1809testcase TC_lu_imsi_auth_tmsi_encr_3_13() runs on MTC_CT {
1810 var BSC_ConnHdlr vc_conn;
1811 f_init();
1812 f_vty_config(MSCVTY, "network", "authentication required");
1813 f_vty_config(MSCVTY, "network", "encryption a5 3");
1814
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001815 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_13), 35);
Harald Welte9de84792018-01-28 01:06:35 +01001816 vc_conn.done;
1817}
1818
1819/* A5/3 only permitted on network side, and MS with only A5/1 support */
1820private function f_tc_lu_imsi_auth_tmsi_encr_3_1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1821 pars.net.expect_auth := true;
1822 pars.net.expect_ciph := true;
1823 pars.net.kc_support := '08'O; /* A5/3 only */
1824 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1825 f_init_handler(pars, 15.0);
1826
1827 /* cannot use f_perform_lu() as we expect a reject */
1828 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
1829 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +02001830 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001831 if (pars.send_early_cm) {
1832 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1833 } else {
1834 pars.cm1.esind := '0'B;
1835 }
Harald Welte9de84792018-01-28 01:06:35 +01001836 f_mm_auth();
1837 alt {
Daniel Willmann52918e52018-09-20 14:39:09 +02001838 [] BSSAP.receive(tr_BSSMAP_ClassmarkReq) {
1839 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1840 repeat;
1841 }
Harald Welte5946b332018-03-18 23:32:21 +01001842 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1843 f_expect_clear();
1844 }
Harald Welte9de84792018-01-28 01:06:35 +01001845 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
1846 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02001847 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001848 }
1849 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01001850 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02001851 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001852 }
1853 }
1854 setverdict(pass);
1855}
1856testcase TC_lu_imsi_auth_tmsi_encr_3_1() runs on MTC_CT {
1857 var BSC_ConnHdlr vc_conn;
1858 f_init();
1859 f_vty_config(MSCVTY, "network", "authentication required");
1860 f_vty_config(MSCVTY, "network", "encryption a5 3");
1861
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001862 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 360, verify_cell_id := false);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001863 vc_conn.done;
1864}
1865testcase TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() runs on MTC_CT {
1866 var BSC_ConnHdlrPars pars;
1867 var BSC_ConnHdlr vc_conn;
1868 f_init();
1869 f_vty_config(MSCVTY, "network", "authentication required");
1870 f_vty_config(MSCVTY, "network", "encryption a5 3");
1871
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001872 pars := f_init_pars(361, verify_cell_id := false);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001873 pars.send_early_cm := false;
1874 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), pars);
Harald Welte9de84792018-01-28 01:06:35 +01001875 vc_conn.done;
1876}
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01001877testcase TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() runs on MTC_CT {
1878 var BSC_ConnHdlr vc_conn;
1879 f_init();
1880 f_vty_config(MSCVTY, "network", "authentication required");
1881 f_vty_config(MSCVTY, "network", "encryption a5 3");
1882
1883 /* Make sure the MSC category is on DEBUG level to trigger the log
1884 * message that is reported in OS#2947 to trigger the segfault */
1885 f_vty_config(MSCVTY, "log stderr", "logging level msc debug");
1886
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001887 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 362, verify_cell_id := false);
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01001888 vc_conn.done;
1889}
Harald Welte9de84792018-01-28 01:06:35 +01001890
1891/* A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
1892private function f_tc_lu_imsi_auth_tmsi_encr_13_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1893 pars.net.expect_auth := true;
1894 pars.net.expect_ciph := true;
1895 pars.net.kc_support := '0A'O; /* A5/1 + A5/3 */
1896 pars.cm1.a5_1 := '1'B;
1897 pars.cm2.a5_1 := '1'B;
1898 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1899 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
1900 f_init_handler(pars, 15.0);
1901
1902 /* cannot use f_perform_lu() as we expect a reject */
1903 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
1904 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +02001905 f_cl3_or_initial_ue(l3_lu);
Harald Welte9de84792018-01-28 01:06:35 +01001906 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1907 f_mm_auth();
1908 alt {
Harald Welte5946b332018-03-18 23:32:21 +01001909 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1910 f_expect_clear();
1911 }
Harald Welte9de84792018-01-28 01:06:35 +01001912 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
1913 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02001914 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001915 }
1916 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01001917 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02001918 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001919 }
1920 }
1921 setverdict(pass);
1922}
1923testcase TC_lu_imsi_auth_tmsi_encr_13_2() runs on MTC_CT {
1924 var BSC_ConnHdlr vc_conn;
1925 f_init();
1926 f_vty_config(MSCVTY, "network", "authentication required");
1927 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
1928
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001929 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_2), 37, verify_cell_id := false);
Harald Welte9de84792018-01-28 01:06:35 +01001930 vc_conn.done;
1931}
1932
1933/* A5/0 + A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
1934private function f_tc_lu_imsi_auth_tmsi_encr_013_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1935 pars.net.expect_auth := true;
1936 pars.net.expect_ciph := true;
1937 pars.net.kc_support := '0B'O; /* A5/1 + A5/3 */
1938 pars.cm1.a5_1 := '1'B;
1939 pars.cm2.a5_1 := '1'B;
1940 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1941 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
1942 f_init_handler(pars, 15.0);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001943 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001944}
1945testcase TC_lu_imsi_auth_tmsi_encr_013_2() runs on MTC_CT {
1946 var BSC_ConnHdlr vc_conn;
1947 f_init();
1948 f_vty_config(MSCVTY, "network", "authentication required");
1949 f_vty_config(MSCVTY, "network", "encryption a5 0 1 3");
1950
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001951 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_013_2), 38);
Harald Welte9de84792018-01-28 01:06:35 +01001952 vc_conn.done;
1953}
1954
Harald Welte33ec09b2018-02-10 15:34:46 +01001955/* LU followed by MT call (including paging) */
Neels Hofmeyr8fe8a902019-11-03 05:51:03 +01001956friend function f_tc_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte33ec09b2018-02-10 15:34:46 +01001957 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01001958 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02001959 cpars.use_osmux := pars.use_osmux;
Harald Welte33ec09b2018-02-10 15:34:46 +01001960
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001961 f_perform_lu();
Harald Welte33ec09b2018-02-10 15:34:46 +01001962 f_mt_call(cpars);
1963}
1964testcase TC_lu_and_mt_call() runs on MTC_CT {
1965 var BSC_ConnHdlr vc_conn;
1966 f_init();
1967
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001968 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call), 39);
Harald Welte33ec09b2018-02-10 15:34:46 +01001969 vc_conn.done;
1970}
1971
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02001972testcase TC_lu_and_mt_call_osmux() runs on MTC_CT {
1973 var BSC_ConnHdlr vc_conn;
1974 f_init(1, false, true, true);
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02001975
1976 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call), 39, 0, true, true);
1977 vc_conn.done;
1978}
1979
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02001980/* LU followed by MT call (including paging) */
1981friend function f_tc_lu_and_mt_call_ipv6(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1982 f_init_handler(pars);
1983 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1984 cpars.mgw_conn_1.mgw_rtp_ip := "::1";
1985 cpars.mgw_conn_2.mgw_rtp_ip := "::2";
1986 cpars.bss_rtp_ip := "::3";
1987 f_perform_lu();
1988 f_mt_call(cpars);
1989}
1990testcase TC_lu_and_mt_call_ipv6() runs on MTC_CT {
1991 var BSC_ConnHdlr vc_conn;
1992 f_init();
1993
1994 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call_ipv6), 39);
1995 vc_conn.done;
1996}
1997
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01001998/* MT call while already Paging */
1999friend function f_tc_lu_and_mt_call_already_paging(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2000 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
2001 var SmsParameters spars := valueof(t_SmsPars);
2002 var OCT4 tmsi;
2003
2004 f_init_handler(pars);
2005
2006 /* Perform location update */
2007 f_perform_lu();
2008
2009 /* register an 'expect' for given IMSI (+TMSI) */
2010 if (isvalue(g_pars.tmsi)) {
2011 tmsi := g_pars.tmsi;
2012 } else {
2013 tmsi := 'FFFFFFFF'O;
2014 }
2015 f_ran_register_imsi(g_pars.imsi, tmsi);
2016
2017 log("start Paging by an SMS");
2018 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2019
2020 /* MSC->BSC: expect PAGING from MSC */
2021 f_expect_paging();
2022
2023 log("MNCC signals MT call, before Paging Response");
2024 f_mt_call_initate(cpars);
2025 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
2026
2027 f_sleep(0.5);
2028 log("phone answers Paging, expecting both SMS and MT call to be established");
2029 f_establish_fully(EST_TYPE_PAG_RESP);
2030 spars.tp.ud := 'C8329BFD064D9B53'O;
2031 interleave {
2032 [] BSSAP.receive(f_mt_sms_deliver_pdu(spars)) {
2033 log("Got SMS-DELIVER");
2034 };
2035 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_SETUP(cpars.transaction_id, *, cpars.called_party))) {
2036 log("Got CC Setup");
2037 };
2038 }
2039 setverdict(pass);
2040 log("success, tear down");
2041 var default ccrel := activate(as_optional_cc_rel(cpars));
2042 if (g_pars.ran_is_geran) {
2043 BSSAP.send(ts_BSSMAP_ClearRequest(0));
2044 } else {
2045 BSSAP.send(ts_RANAP_IuReleaseRequest(ts_RanapCause_om_intervention));
2046 }
2047 f_expect_clear();
2048 deactivate(ccrel);
2049 f_vty_sms_clear(hex2str(g_pars.imsi));
2050}
2051testcase TC_lu_and_mt_call_already_paging() runs on MTC_CT {
2052 var BSC_ConnHdlrPars pars;
2053 var BSC_ConnHdlr vc_conn;
2054 f_init();
2055 pars := f_init_pars(391);
2056 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_call_already_paging), pars);
2057 vc_conn.done;
2058}
2059
Daniel Willmann8b084372018-02-04 13:35:26 +01002060/* Test MO Call SETUP with DTMF */
2061private function f_tc_mo_setup_dtmf_dup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2062 f_init_handler(pars);
2063 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Daniel Willmann8b084372018-02-04 13:35:26 +01002064
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01002065 f_perform_lu();
Daniel Willmann8b084372018-02-04 13:35:26 +01002066 f_mo_seq_dtmf_dup(cpars);
2067}
2068testcase TC_mo_setup_and_dtmf_dup() runs on MTC_CT {
2069 var BSC_ConnHdlr vc_conn;
2070 f_init();
2071
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01002072 vc_conn := f_start_handler(refers(f_tc_mo_setup_dtmf_dup), 39);
Daniel Willmann8b084372018-02-04 13:35:26 +01002073 vc_conn.done;
2074}
Harald Welte9de84792018-01-28 01:06:35 +01002075
Philipp Maier328d1662018-03-07 10:40:27 +01002076testcase TC_cr_before_reset() runs on MTC_CT {
2077 timer T := 4.0;
2078 var boolean reset_ack_seen := false;
2079 f_init_bssap_direct();
2080
Harald Welte3ca0ce12019-04-23 17:18:48 +02002081 f_ran_adapter_start(g_bssap[0]);
Daniel Willmann42d1d5b2018-08-07 15:18:41 +02002082
Daniel Willmanne8018962018-08-21 14:18:00 +02002083 f_sleep(3.0);
2084
Philipp Maier328d1662018-03-07 10:40:27 +01002085 /* Make a blind connection attemt, to trigger the deadlock condition */
Philipp Maier75932982018-03-27 14:52:35 +02002086 BSSAP_DIRECT.send(ts_BSSAP_CONNECT_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, 1, omit));
Philipp Maier328d1662018-03-07 10:40:27 +01002087
2088 /* Send a BSSMAP reset */
Philipp Maier75932982018-03-27 14:52:35 +02002089 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_Reset(0)));
Philipp Maier328d1662018-03-07 10:40:27 +01002090 T.start
2091 alt {
2092 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_ResetAck)) {
2093 reset_ack_seen := true;
2094 repeat;
2095 }
2096
2097 /* Acknowledge MSC sided reset requests */
2098 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_Reset)) {
Philipp Maier75932982018-03-27 14:52:35 +02002099 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_ResetAck));
Philipp Maier328d1662018-03-07 10:40:27 +01002100 repeat;
2101 }
2102
2103 /* Ignore all other messages (e.g CR from the connection request) */
2104 [] BSSAP_DIRECT.receive { repeat }
2105
2106 /* If we got no BSSMAP RESET ACK back, then the MSC entered the
2107 * deadlock situation. The MSC is then unable to respond to any
2108 * further BSSMAP RESET or any other sort of traffic. */
2109 [reset_ack_seen == true] T.timeout { setverdict(pass) }
2110 [reset_ack_seen == false] T.timeout {
2111 setverdict(fail, "no BSSMAP RESET ACK seen!");
Daniel Willmannafce8662018-07-06 23:11:32 +02002112 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +01002113 }
Pau Espin Pedrol7e9178d2019-12-17 17:52:17 +01002114 }
Philipp Maier328d1662018-03-07 10:40:27 +01002115}
Harald Welte9de84792018-01-28 01:06:35 +01002116
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002117/* Test MO Call with no response to RAN-side CRCX or DTAP Release */
Harald Weltee13cfb22019-04-23 16:52:02 +02002118friend function f_tc_mo_release_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002119 f_init_handler(pars);
2120 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
2121 var MNCC_PDU mncc;
2122 var MgcpCommand mgcp_cmd;
2123
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02002124 /* Do not respond to the second CRCX */
2125 cpars.mgw_conn_2.resp := 0;
2126
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002127 f_perform_lu();
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02002128 f_mo_call_establish(cpars);
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002129
Neels Hofmeyrde76f052019-02-26 05:02:46 +01002130 var default ccrel := activate(as_optional_cc_rel(cpars));
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002131
2132 f_expect_clear(60.0);
Neels Hofmeyrde76f052019-02-26 05:02:46 +01002133
2134 deactivate(ccrel);
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002135}
2136testcase TC_mo_release_timeout() runs on MTC_CT {
2137 var BSC_ConnHdlr vc_conn;
2138 f_init();
2139
2140 vc_conn := f_start_handler(refers(f_tc_mo_release_timeout), 40);
2141 vc_conn.done;
2142}
2143
Harald Welte12510c52018-01-26 22:26:24 +01002144
Philipp Maier2a98a732018-03-19 16:06:12 +01002145/* LU followed by MT call (including paging) */
2146private function f_tc_lu_and_mt_call_no_dlcx_resp(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2147 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01002148 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Philipp Maier2a98a732018-03-19 16:06:12 +01002149
2150 /* Intentionally disable the CRCX response */
2151 cpars.mgw_drop_dlcx := true;
2152
2153 /* Perform location update and call */
2154 f_perform_lu();
2155 f_mt_call(cpars);
2156}
2157testcase TC_lu_and_mt_call_no_dlcx_resp() runs on MTC_CT {
2158 var BSC_ConnHdlr vc_conn;
2159 f_init();
2160
2161 /* Perform an almost normal looking locationupdate + mt-call, but do
2162 * not respond to the DLCX at the end of the call */
2163 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call_no_dlcx_resp), 41);
2164 vc_conn.done;
2165
2166 /* Wait a guard period until the MGCP layer in the MSC times out,
2167 * if the MSC is vulnerable to the use-after-free situation that is
2168 * fixed by I78f1b6a9149488a4ad3f120c1e190a83c07d4b89 then it should
2169 * segfault now */
2170 f_sleep(6.0);
2171
2172 /* Run the init procedures once more. If the MSC has crashed, this
2173 * this will fail */
2174 f_init();
2175}
Harald Welte45164da2018-01-24 12:51:27 +01002176
Philipp Maier75932982018-03-27 14:52:35 +02002177/* Two BSSMAP resets from two different BSCs */
2178testcase TC_reset_two() runs on MTC_CT {
2179 var BSC_ConnHdlr vc_conn;
2180 f_init(2);
2181 f_sleep(2.0);
2182 setverdict(pass);
2183}
2184
Harald Weltee13cfb22019-04-23 16:52:02 +02002185/* Two BSSMAP resets from two different BSCs plus one IuCS RANAP Reset */
2186testcase TC_reset_two_1iu() runs on MTC_CT {
2187 var BSC_ConnHdlr vc_conn;
2188 f_init(3);
2189 f_sleep(2.0);
2190 setverdict(pass);
2191}
2192
Harald Weltef640a012018-04-14 17:49:21 +02002193/***********************************************************************
2194 * SMS Testing
2195 ***********************************************************************/
2196
Harald Weltef45efeb2018-04-09 18:19:24 +02002197/* LU followed by MO SMS */
Harald Weltee13cfb22019-04-23 16:52:02 +02002198friend function f_tc_lu_and_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02002199 var SmsParameters spars := valueof(t_SmsPars);
2200
2201 f_init_handler(pars);
2202
2203 /* Perform location update and call */
2204 f_perform_lu();
2205
2206 f_establish_fully(EST_TYPE_MO_SMS);
2207
2208 //spars.exp_rp_err := 96; /* invalid mandatory information */
2209 f_mo_sms(spars);
2210
2211 f_expect_clear();
2212}
2213testcase TC_lu_and_mo_sms() runs on MTC_CT {
2214 var BSC_ConnHdlr vc_conn;
2215 f_init();
2216 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_sms), 42);
2217 vc_conn.done;
2218}
2219
Harald Weltee13cfb22019-04-23 16:52:02 +02002220
Harald Weltef45efeb2018-04-09 18:19:24 +02002221private function f_vty_sms_send(charstring imsi, charstring msisdn, charstring text)
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002222runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02002223 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
2224}
2225
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01002226/* Remove still pending SMS */
2227private function f_vty_sms_clear(charstring imsi)
2228runs on BSC_ConnHdlr {
2229 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " sms delete-all");
2230 f_vty_transceive(MSCVTY, "sms-queue clear");
2231}
2232
Harald Weltef45efeb2018-04-09 18:19:24 +02002233/* LU followed by MT SMS */
Harald Weltee13cfb22019-04-23 16:52:02 +02002234friend function f_tc_lu_and_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02002235 var SmsParameters spars := valueof(t_SmsPars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002236
2237 f_init_handler(pars);
2238
2239 /* Perform location update and call */
2240 f_perform_lu();
2241
2242 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002243 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Weltef45efeb2018-04-09 18:19:24 +02002244
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002245 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
Harald Weltef45efeb2018-04-09 18:19:24 +02002246
2247 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02002248 f_expect_paging();
2249
Harald Weltef45efeb2018-04-09 18:19:24 +02002250 /* Establish DTAP / BSSAP / SCCP connection */
2251 f_establish_fully(EST_TYPE_PAG_RESP);
2252
2253 spars.tp.ud := 'C8329BFD064D9B53'O;
2254 f_mt_sms(spars);
2255
2256 f_expect_clear();
2257}
2258testcase TC_lu_and_mt_sms() runs on MTC_CT {
2259 var BSC_ConnHdlrPars pars;
2260 var BSC_ConnHdlr vc_conn;
2261 f_init();
2262 pars := f_init_pars(43);
2263 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms), pars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002264 vc_conn.done;
2265}
2266
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01002267/* SMS added while already Paging */
2268friend function f_tc_lu_and_mt_sms_already_paging(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2269 var SmsParameters spars := valueof(t_SmsPars);
2270 var OCT4 tmsi;
2271
2272 f_init_handler(pars);
2273
2274 f_perform_lu();
2275
2276 /* register an 'expect' for given IMSI (+TMSI) */
2277 if (isvalue(g_pars.tmsi)) {
2278 tmsi := g_pars.tmsi;
2279 } else {
2280 tmsi := 'FFFFFFFF'O;
2281 }
2282 f_ran_register_imsi(g_pars.imsi, tmsi);
2283
2284 log("first SMS");
2285 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2286
2287 /* MSC->BSC: expect PAGING from MSC */
2288 f_expect_paging();
2289
2290 log("second SMS");
2291 /* Now osmo-msc is in state "Paging pending", make sure that another SMS to be sent at this time just joins in
2292 * with the pending paging. Another SMS: */
2293 f_vty_sms_send(hex2str(pars.imsi), "2342", "Another SMS");
2294
2295 /* Establish DTAP / BSSAP / SCCP connection */
2296 f_establish_fully(EST_TYPE_PAG_RESP);
2297
2298 spars.tp.ud := 'C8329BFD064D9B53'O;
2299 f_mt_sms(spars);
2300
2301 spars.tp.ud := '41F79B8E2ECB41D3E614'O;
2302 f_mt_sms(spars);
2303
2304 f_expect_clear();
2305}
2306testcase TC_lu_and_mt_sms_already_paging() runs on MTC_CT {
2307 var BSC_ConnHdlrPars pars;
2308 var BSC_ConnHdlr vc_conn;
2309 f_init();
2310 pars := f_init_pars(44);
2311 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_already_paging), pars);
2312 vc_conn.done;
2313}
Harald Weltee13cfb22019-04-23 16:52:02 +02002314
Philipp Maier3983e702018-11-22 19:01:33 +01002315/* Paging for MT SMS but no response */
Harald Weltee13cfb22019-04-23 16:52:02 +02002316friend function f_tc_lu_and_mt_sms_paging_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier3983e702018-11-22 19:01:33 +01002317 var SmsParameters spars := valueof(t_SmsPars);
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002318
Philipp Maier3983e702018-11-22 19:01:33 +01002319 f_init_handler(pars, 150.0);
2320
2321 /* Perform location update */
2322 f_perform_lu();
2323
2324 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002325 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Philipp Maier3983e702018-11-22 19:01:33 +01002326
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002327 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2328
Neels Hofmeyr16237742019-03-06 15:34:01 +01002329 /* Expect the MSC to page exactly once */
Harald Weltee13cfb22019-04-23 16:52:02 +02002330 f_expect_paging();
Philipp Maier3983e702018-11-22 19:01:33 +01002331
2332 /* Wait some time to make sure the MSC is not delivering any further
2333 * paging messages or anything else that could be unexpected. */
2334 timer T := 20.0;
2335 T.start
2336 alt {
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002337 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
2338 setverdict(fail, "paging seems not to stop!");
2339 mtc.stop;
Philipp Maier3983e702018-11-22 19:01:33 +01002340 }
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002341 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
2342 setverdict(fail, "paging seems not to stop!");
2343 mtc.stop;
Harald Weltee13cfb22019-04-23 16:52:02 +02002344 }
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002345 [] BSSAP.receive {
2346 setverdict(fail, "unexpected BSSAP message received");
2347 self.stop;
Philipp Maier3983e702018-11-22 19:01:33 +01002348 }
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002349 [] T.timeout {
2350 setverdict(pass);
Philipp Maier3983e702018-11-22 19:01:33 +01002351 }
2352 }
2353
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01002354 f_vty_sms_clear(hex2str(g_pars.imsi));
2355
Philipp Maier3983e702018-11-22 19:01:33 +01002356 setverdict(pass);
2357}
2358testcase TC_lu_and_mt_sms_paging_and_nothing() runs on MTC_CT {
2359 var BSC_ConnHdlrPars pars;
2360 var BSC_ConnHdlr vc_conn;
2361 f_init();
Philipp Maiera99ad262019-01-22 15:35:42 +01002362 pars := f_init_pars(1843);
Philipp Maier3983e702018-11-22 19:01:33 +01002363 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_paging_and_nothing), pars);
Philipp Maier3983e702018-11-22 19:01:33 +01002364 vc_conn.done;
2365}
2366
Alexander Couzensfc02f242019-09-12 03:43:18 +02002367/* LU followed by MT SMS with repeated paging */
2368friend function f_tc_lu_and_mt_sms_paging_repeated(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2369 var SmsParameters spars := valueof(t_SmsPars);
Alexander Couzensfc02f242019-09-12 03:43:18 +02002370
2371 f_init_handler(pars);
2372
2373 /* Perform location update and call */
2374 f_perform_lu();
2375
2376 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002377 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Alexander Couzensfc02f242019-09-12 03:43:18 +02002378
2379 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2380
Neels Hofmeyrc3accec2019-11-28 01:09:47 +01002381 log("Expecting first Paging");
Alexander Couzensfc02f242019-09-12 03:43:18 +02002382 /* MSC->BSC: expect PAGING from MSC */
2383 f_expect_paging();
2384
Neels Hofmeyrc3accec2019-11-28 01:09:47 +01002385 if (g_pars.ran_is_geran) {
2386 log("GERAN: expect no further Paging");
2387 } else {
2388 log("UTRAN: expect more Paging");
2389 }
2390
2391 timer T := 5.0;
2392 T.start;
2393 alt {
2394 [g_pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
2395 setverdict(fail, "GERAN should not repeat Paging, but received a second Paging");
2396 mtc.stop;
2397 }
2398 [not g_pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
2399 log("UTRAN: second Paging received, as expected");
2400 setverdict(pass);
2401 }
2402 [] T.timeout {
2403 if (g_pars.ran_is_geran) {
2404 log("GERAN: No further Paging received, as expected");
2405 setverdict(pass);
2406 } else {
2407 setverdict(fail, "UTRAN: Expected a second Paging");
2408 mtc.stop;
2409 }
2410 }
2411 }
Alexander Couzensfc02f242019-09-12 03:43:18 +02002412
2413 /* Establish DTAP / BSSAP / SCCP connection */
2414 f_establish_fully(EST_TYPE_PAG_RESP);
2415
2416 spars.tp.ud := 'C8329BFD064D9B53'O;
2417 f_mt_sms(spars);
2418
2419 f_expect_clear();
2420}
2421testcase TC_lu_and_mt_sms_paging_repeated() runs on MTC_CT {
2422 var BSC_ConnHdlrPars pars;
2423 var BSC_ConnHdlr vc_conn;
2424 f_init();
2425 pars := f_init_pars(1844);
2426 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_paging_repeated), pars);
2427 vc_conn.done;
2428}
Harald Weltee13cfb22019-04-23 16:52:02 +02002429
Harald Weltef640a012018-04-14 17:49:21 +02002430/* mobile originated SMS from MS/BTS/BSC side to SMPP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002431friend function f_tc_smpp_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef640a012018-04-14 17:49:21 +02002432 var SmsParameters spars := valueof(t_SmsPars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002433
Harald Weltef640a012018-04-14 17:49:21 +02002434 f_init_handler(pars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002435
Harald Weltef640a012018-04-14 17:49:21 +02002436 /* Perform location update so IMSI is known + registered in MSC/VLR */
2437 f_perform_lu();
Harald Weltef640a012018-04-14 17:49:21 +02002438
Vadim Yanitskiy2d3f8462020-01-15 11:44:12 +07002439 /* MS/UE submits a MO SMS */
2440 f_establish_fully(EST_TYPE_MO_SMS);
2441 f_mo_sms_submit(spars);
Harald Weltef640a012018-04-14 17:49:21 +02002442
2443 var SMPP_PDU smpp;
2444 var template SMPP_PDU tr_smpp := tr_SMPP(c_SMPP_command_id_deliver_sm, ESME_ROK);
2445 tr_smpp.body.deliver_sm := {
2446 service_type := "CMT",
2447 source_addr_ton := network_specific,
2448 source_addr_npi := isdn,
2449 source_addr := hex2str(pars.msisdn),
2450 dest_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
2451 dest_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
2452 destination_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
2453 esm_class := '00000001'B,
2454 protocol_id := 0,
2455 priority_flag := 0,
2456 schedule_delivery_time := "",
2457 replace_if_present := 0,
2458 data_coding := '00000001'B,
2459 sm_default_msg_id := 0,
2460 sm_length := ?,
2461 short_message := spars.tp.ud,
2462 opt_pars := {
2463 {
2464 tag := user_message_reference,
2465 len := 2,
2466 opt_value := {
2467 int2_val := oct2int(spars.tp.msg_ref)
2468 }
2469 }
2470 }
2471 };
2472 alt {
2473 [] SMPP.receive(tr_smpp) -> value smpp {
2474 SMPP.send(ts_SMPP_DELIVER_SM_resp(ESME_ROK, smpp.header.seq_num));
2475 }
2476 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK)) { repeat; }
2477 }
2478
Vadim Yanitskiy2d3f8462020-01-15 11:44:12 +07002479 /* MSC terminates the SMS transaction with RP-ACK */
2480 f_mo_sms_wait_rp_ack(spars);
2481
Harald Weltef640a012018-04-14 17:49:21 +02002482 f_expect_clear();
2483}
2484testcase TC_smpp_mo_sms() runs on MTC_CT {
2485 var BSC_ConnHdlr vc_conn;
2486 f_init();
2487 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "default-route");
2488 vc_conn := f_start_handler(refers(f_tc_smpp_mo_sms), 44);
2489 vc_conn.done;
2490 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "no default-route");
2491}
2492
Vadim Yanitskiy33820762020-01-15 11:26:07 +07002493/* Test case for OS#4351: make sure that RP-ERROR from ESME is properly sent to the MS/UE */
2494friend function f_tc_smpp_mo_sms_rp_error(charstring id, BSC_ConnHdlrPars pars)
2495runs on BSC_ConnHdlr {
2496 var SmsParameters spars := valueof(t_SmsPars);
2497 var SMPP_PDU smpp_pdu;
2498 timer T := 3.0;
2499
2500 f_init_handler(pars);
2501
2502 /* Perform location update */
2503 f_perform_lu();
2504
2505 /* MS/UE submits a MO SMS */
2506 f_establish_fully(EST_TYPE_MO_SMS);
2507 f_mo_sms_submit(spars);
2508
2509 /* ESME responds with an error (Invalid Destination Address) */
2510 T.start;
2511 alt {
2512 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_deliver_sm, ESME_ROK, body := ?)) -> value smpp_pdu {
2513 SMPP.send(ts_SMPP_DELIVER_SM_resp(ESME_RINVDSTADR, smpp_pdu.header.seq_num));
2514 }
2515 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK)) { repeat; }
2516 [] T.timeout {
2517 setverdict(fail, "Timeout waiting for SMPP DELIVER-SM");
2518 mtc.stop;
2519 }
2520 }
2521
2522 /* Expect RP-ERROR on BSSAP interface */
2523 spars.exp_rp_err := 1; /* FIXME: GSM411_RP_CAUSE_MO_NUM_UNASSIGNED */
2524 f_mo_sms_wait_rp_ack(spars);
2525
2526 f_expect_clear();
2527}
2528testcase TC_smpp_mo_sms_rp_error() runs on MTC_CT {
2529 var BSC_ConnHdlr vc_conn;
2530 f_init();
2531 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "default-route");
2532 vc_conn := f_start_handler(refers(f_tc_smpp_mo_sms_rp_error), 45);
2533 vc_conn.done;
2534 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "no default-route");
2535}
2536
Harald Weltee13cfb22019-04-23 16:52:02 +02002537
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002538/* Test MO-SMS from MS/BTS/BSC towards HLR (via GSUP) */
Harald Weltee13cfb22019-04-23 16:52:02 +02002539friend function f_tc_gsup_mo_sms(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002540runs on BSC_ConnHdlr {
2541 var SmsParameters spars := valueof(t_SmsPars);
2542 var GSUP_PDU gsup_msg_rx;
2543 var octetstring sm_tpdu;
2544
2545 f_init_handler(pars);
2546
2547 /* We need to inspect GSUP activity */
2548 f_create_gsup_expect(hex2str(g_pars.imsi));
2549
2550 /* Perform location update */
2551 f_perform_lu();
2552
2553 /* Send CM Service Request for SMS */
2554 f_establish_fully(EST_TYPE_MO_SMS);
2555
2556 /* Prepare expected SM-RP-UI (SM TPDU) */
2557 enc_TPDU_RP_DATA_MS_SGSN_fast(
2558 valueof(ts_SMS_SUBMIT(spars.tp.msg_ref,
2559 spars.tp.da, spars.tp.pid, spars.tp.dcs,
2560 spars.tp.udl, spars.tp.ud)),
2561 sm_tpdu);
2562
2563 var template GSUP_PDU mo_forwardSM := tr_GSUP_MO_FORWARD_SM_REQ(
2564 imsi := g_pars.imsi,
2565 sm_rp_mr := spars.rp.msg_ref,
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09002566 /* SM-RP-DA: SMSC address */
2567 sm_rp_da := tr_GSUP_SM_RP_DA_SMSC_ADDR(t_GSUP_SM_RP_Addr(
2568 number := spars.rp.smsc_addr.rP_NumberDigits,
2569 npi := spars.rp.smsc_addr.rP_NumberingPlanIdentification,
2570 ton := spars.rp.smsc_addr.rP_TypeOfNumber,
2571 ext := spars.rp.smsc_addr.rP_Ext)),
2572 /* SM-RP-OA: subscriber's MSISDN (filled in by MSC) */
2573 sm_rp_oa := tr_GSUP_SM_RP_OA_MSISDN(t_GSUP_SM_RP_Addr(
2574 number := g_pars.msisdn,
2575 /* NOTE: MSISDN in g_pars lacks this info, assuming defaults */
2576 npi := '0001'B, ton := '001'B, ext := '1'B)),
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002577 /* TODO: can we use decmatch here? */
2578 sm_rp_ui := sm_tpdu
2579 );
2580
2581 /* Submit an SMS on DTAP and expect MO-forwardSM-Req on GSUP */
2582 f_mo_sms_submit(spars);
2583 alt {
2584 [] GSUP.receive(mo_forwardSM) -> value gsup_msg_rx {
Vadim Yanitskiya358dd42020-01-15 10:42:47 +07002585 log("RX MO-forwardSM-Req: ", gsup_msg_rx);
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002586 setverdict(pass);
2587 }
2588 [] GSUP.receive {
2589 log("RX unexpected GSUP message");
2590 setverdict(fail);
2591 mtc.stop;
2592 }
2593 }
2594
2595 /* Trigger RP-ACK by sending MO-forwardSM-Res */
2596 GSUP.send(valueof(ts_GSUP_MO_FORWARD_SM_RES(
2597 imsi := g_pars.imsi,
2598 sm_rp_mr := spars.rp.msg_ref)));
2599 /* Expect RP-ACK on DTAP */
2600 f_mo_sms_wait_rp_ack(spars);
2601
2602 f_expect_clear();
2603}
2604testcase TC_gsup_mo_sms() runs on MTC_CT {
2605 var BSC_ConnHdlr vc_conn;
2606 f_init();
2607 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2608 vc_conn := f_start_handler(refers(f_tc_gsup_mo_sms), 88);
2609 vc_conn.done;
2610 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2611}
2612
Harald Weltee13cfb22019-04-23 16:52:02 +02002613
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002614/* Test MO-SMMA from MS/BTS/BSC towards HLR (via GSUP) */
Harald Weltee13cfb22019-04-23 16:52:02 +02002615friend function f_tc_gsup_mo_smma(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002616runs on BSC_ConnHdlr {
2617 var SmsParameters spars := valueof(t_SmsPars);
2618 var GSUP_PDU gsup_msg_rx;
2619
2620 f_init_handler(pars);
2621
2622 /* We need to inspect GSUP activity */
2623 f_create_gsup_expect(hex2str(g_pars.imsi));
2624
2625 /* Perform location update */
2626 f_perform_lu();
2627
2628 /* Send CM Service Request for SMS */
2629 f_establish_fully(EST_TYPE_MO_SMS);
2630
2631 var template GSUP_PDU mo_ReadyForSM := tr_GSUP_MO_READY_FOR_SM_REQ(
2632 imsi := g_pars.imsi,
2633 sm_rp_mr := spars.rp.msg_ref,
2634 sm_alert_rsn := GSUP_SM_ALERT_RSN_TYPE_MEM_AVAIL
2635 );
2636
2637 /* Submit an SMS on DTAP and expect MO-forwardSM-Req on GSUP */
2638 f_mo_smma(spars);
2639 alt {
2640 [] GSUP.receive(mo_ReadyForSM) -> value gsup_msg_rx {
Vadim Yanitskiya358dd42020-01-15 10:42:47 +07002641 log("RX MO-ReadyForSM-Req: ", gsup_msg_rx);
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002642 setverdict(pass);
2643 }
2644 [] GSUP.receive {
2645 log("RX unexpected GSUP message");
2646 setverdict(fail);
2647 mtc.stop;
2648 }
2649 }
2650
2651 /* Trigger RP-ACK by sending MO-forwardSM-Res */
2652 GSUP.send(valueof(ts_GSUP_MO_READY_FOR_SM_RES(
2653 imsi := g_pars.imsi,
2654 sm_rp_mr := spars.rp.msg_ref)));
2655 /* Expect RP-ACK on DTAP */
2656 f_mo_sms_wait_rp_ack(spars);
2657
2658 f_expect_clear();
2659}
2660testcase TC_gsup_mo_smma() runs on MTC_CT {
2661 var BSC_ConnHdlr vc_conn;
2662 f_init();
2663 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2664 vc_conn := f_start_handler(refers(f_tc_gsup_mo_smma), 89);
2665 vc_conn.done;
2666 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2667}
2668
Harald Weltee13cfb22019-04-23 16:52:02 +02002669
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002670/* Helper for sending MT SMS over GSUP */
2671private function f_gsup_forwardSM_req(SmsParameters spars, OCT1 mms := '00'O)
2672runs on BSC_ConnHdlr {
Vadim Yanitskiya52347c2019-12-12 17:32:33 +09002673 var GSUP_SM_RP_Addr msisdn := valueof(t_GSUP_SM_RP_Addr(g_pars.msisdn));
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09002674 var GSUP_SM_RP_Addr smsc := valueof(t_GSUP_SM_RP_Addr(
2675 number := spars.rp.smsc_addr.rP_NumberDigits,
2676 npi := spars.rp.smsc_addr.rP_NumberingPlanIdentification,
2677 ton := spars.rp.smsc_addr.rP_TypeOfNumber,
2678 ext := spars.rp.smsc_addr.rP_Ext));
Vadim Yanitskiya52347c2019-12-12 17:32:33 +09002679
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002680 GSUP.send(ts_GSUP_MT_FORWARD_SM_REQ(
2681 imsi := g_pars.imsi,
2682 /* NOTE: MSC should assign RP-MR itself */
2683 sm_rp_mr := 'FF'O,
Vadim Yanitskiya52347c2019-12-12 17:32:33 +09002684 sm_rp_da := valueof(ts_GSUP_SM_RP_DA_MSISDN(msisdn)),
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09002685 sm_rp_oa := valueof(ts_GSUP_SM_RP_OA_SMSC_ADDR(smsc)),
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002686 /* Encoded SMS TPDU (taken from Wireshark)
2687 * FIXME: we should encode spars somehow */
2688 sm_rp_ui := '00068021436500008111328130858200'O,
2689 sm_rp_mms := mms
2690 ));
2691}
2692
2693/* Test successful MT-SMS (RP-ACK) over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002694friend function f_tc_gsup_mt_sms_ack(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002695runs on BSC_ConnHdlr {
2696 var SmsParameters spars := valueof(t_SmsPars);
2697
2698 f_init_handler(pars);
2699
2700 /* We need to inspect GSUP activity */
2701 f_create_gsup_expect(hex2str(g_pars.imsi));
2702
2703 /* Perform location update */
2704 f_perform_lu();
2705
2706 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002707 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002708
2709 var template GSUP_PDU mt_forwardSM_res := tr_GSUP_MT_FORWARD_SM_RES(
2710 imsi := g_pars.imsi,
2711 /* NOTE: MSC should assign RP-MR itself */
2712 sm_rp_mr := ?
2713 );
2714
2715 /* Submit a MT SMS on GSUP */
2716 f_gsup_forwardSM_req(spars);
2717
2718 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002719 f_expect_paging();
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002720 f_establish_fully(EST_TYPE_PAG_RESP);
2721
2722 /* Wait for MT SMS on DTAP */
2723 f_mt_sms_expect(spars);
2724
2725 /* Send RP-ACK and expect MT-forwardSM-Res on GSUP */
2726 f_mt_sms_send_rp_ack(spars);
2727 alt {
2728 [] GSUP.receive(mt_forwardSM_res) {
2729 log("RX MT-forwardSM-Res (RP-ACK)");
2730 setverdict(pass);
2731 }
2732 [] GSUP.receive {
2733 log("RX unexpected GSUP message");
2734 setverdict(fail);
2735 mtc.stop;
2736 }
2737 }
2738
2739 f_expect_clear();
2740}
2741testcase TC_gsup_mt_sms_ack() runs on MTC_CT {
2742 var BSC_ConnHdlrPars pars;
2743 var BSC_ConnHdlr vc_conn;
2744 f_init();
2745 pars := f_init_pars(90);
2746 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2747 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_ack), pars);
2748 vc_conn.done;
2749 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2750}
2751
Harald Weltee13cfb22019-04-23 16:52:02 +02002752
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002753/* Test rejected MT-SMS (RP-ERROR) over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002754friend function f_tc_gsup_mt_sms_err(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002755runs on BSC_ConnHdlr {
2756 var SmsParameters spars := valueof(t_SmsPars);
2757 var OCT1 sm_rp_cause := '78'O; /* dummy RP-Cause value */
2758
2759 f_init_handler(pars);
2760
2761 /* We need to inspect GSUP activity */
2762 f_create_gsup_expect(hex2str(g_pars.imsi));
2763
2764 /* Perform location update */
2765 f_perform_lu();
2766
2767 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002768 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002769
2770 var template GSUP_PDU mt_forwardSM_err := tr_GSUP_MT_FORWARD_SM_ERR(
2771 imsi := g_pars.imsi,
2772 /* NOTE: MSC should assign RP-MR itself */
2773 sm_rp_mr := ?,
2774 sm_rp_cause := sm_rp_cause
2775 );
2776
2777 /* Submit a MT SMS on GSUP */
2778 f_gsup_forwardSM_req(spars);
2779
2780 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002781 f_expect_paging();
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002782 f_establish_fully(EST_TYPE_PAG_RESP);
2783
2784 /* Wait for MT SMS on DTAP */
2785 f_mt_sms_expect(spars);
2786
2787 /* Send RP-ERROR and expect MT-forwardSM-Err on GSUP */
2788 f_mt_sms_send_rp_error(spars, oct2int(sm_rp_cause));
2789 alt {
2790 [] GSUP.receive(mt_forwardSM_err) {
2791 log("RX MT-forwardSM-Err (RP-ERROR)");
2792 setverdict(pass);
2793 mtc.stop;
2794 }
2795 [] GSUP.receive {
2796 log("RX unexpected GSUP message");
2797 setverdict(fail);
2798 mtc.stop;
2799 }
2800 }
2801
2802 f_expect_clear();
2803}
2804testcase TC_gsup_mt_sms_err() runs on MTC_CT {
2805 var BSC_ConnHdlrPars pars;
2806 var BSC_ConnHdlr vc_conn;
2807 f_init();
2808 pars := f_init_pars(91);
2809 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2810 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_err), pars);
2811 vc_conn.done;
2812 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2813}
2814
Harald Weltee13cfb22019-04-23 16:52:02 +02002815
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002816/* Test SM-RP-MR assignment for MT-SMS over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002817friend function f_tc_gsup_mt_sms_rp_mr(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002818runs on BSC_ConnHdlr {
2819 var SmsParameters spars1 := valueof(t_SmsPars); /* 1st SMS */
2820 var SmsParameters spars2 := valueof(t_SmsPars); /* 2nd SMS */
2821
2822 f_init_handler(pars);
2823
2824 /* We need to inspect GSUP activity */
2825 f_create_gsup_expect(hex2str(g_pars.imsi));
2826
2827 /* Perform location update */
2828 f_perform_lu();
2829
2830 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002831 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002832
2833 /* Submit the 1st MT SMS on GSUP */
2834 log("TX MT-forwardSM-Req for the 1st SMS");
2835 f_gsup_forwardSM_req(spars1);
2836
2837 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002838 f_expect_paging();
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002839 f_establish_fully(EST_TYPE_PAG_RESP);
2840
2841 /* Wait for 1st MT SMS on DTAP */
2842 f_mt_sms_expect(spars1);
2843 log("RX the 1st SMS on DTAP, DTAP TID is ", spars1.tid,
2844 ", SM-RP-MR is ", spars1.rp.msg_ref);
2845
2846 /* Submit the 2nd MT SMS on GSUP */
2847 log("TX MT-forwardSM-Req for the 2nd SMS");
2848 f_gsup_forwardSM_req(spars2);
2849
2850 /* Wait for 2nd MT SMS on DTAP */
2851 f_mt_sms_expect(spars2);
2852 log("RX the 2nd SMS on DTAP, DTAP TID is ", spars2.tid,
2853 ", SM-RP-MR is ", spars2.rp.msg_ref);
2854
2855 /* Both transaction IDs shall be different */
2856 if (spars1.tid == spars2.tid) {
2857 log("Both DTAP transaction IDs shall be different");
2858 setverdict(fail);
2859 }
2860
2861 /* Both SM-RP-MR values shall be different */
2862 if (spars1.rp.msg_ref == spars2.rp.msg_ref) {
2863 log("Both SM-RP-MR values shall be different");
2864 setverdict(fail);
2865 }
2866
2867 /* Both SM-RP-MR values shall be assigned */
2868 if (spars1.rp.msg_ref == 'FF'O) {
2869 log("Unassigned SM-RP-MR value for the 1st SMS");
2870 setverdict(fail);
2871 }
2872 if (spars2.rp.msg_ref == 'FF'O) {
2873 log("Unassigned SM-RP-MR value for the 2nd SMS");
2874 setverdict(fail);
2875 }
2876
2877 /* Send the 1st RP-ACK and expect MT-forwardSM-Res on GSUP */
2878 f_mt_sms_send_rp_ack(spars1);
2879 alt {
2880 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2881 imsi := g_pars.imsi,
2882 sm_rp_mr := spars1.rp.msg_ref
2883 )) {
2884 log("RX MT-forwardSM-Res (RP-ACK)");
2885 setverdict(pass);
2886 }
2887 [] GSUP.receive {
2888 log("RX unexpected GSUP message");
2889 setverdict(fail);
2890 mtc.stop;
2891 }
2892 }
2893
2894 /* Send the 2nd RP-ACK and expect MT-forwardSM-Res on GSUP */
2895 f_mt_sms_send_rp_ack(spars2);
2896 alt {
2897 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2898 imsi := g_pars.imsi,
2899 sm_rp_mr := spars2.rp.msg_ref
2900 )) {
2901 log("RX MT-forwardSM-Res (RP-ACK)");
2902 setverdict(pass);
2903 }
2904 [] GSUP.receive {
2905 log("RX unexpected GSUP message");
2906 setverdict(fail);
2907 mtc.stop;
2908 }
2909 }
2910
2911 f_expect_clear();
2912}
2913testcase TC_gsup_mt_sms_rp_mr() runs on MTC_CT {
2914 var BSC_ConnHdlrPars pars;
2915 var BSC_ConnHdlr vc_conn;
2916 f_init();
2917 pars := f_init_pars(92);
2918 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2919 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_rp_mr), pars);
2920 vc_conn.done;
2921 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2922}
2923
Harald Weltee13cfb22019-04-23 16:52:02 +02002924
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07002925/* Test SM-RP-MR assignment for MT-SMS over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002926friend function f_tc_gsup_mo_mt_sms_rp_mr(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07002927runs on BSC_ConnHdlr {
2928 var SmsParameters spars_mo := valueof(t_SmsPars); /* MO SMMA */
2929 var SmsParameters spars_mt := valueof(t_SmsPars); /* MT SMS */
2930
2931 f_init_handler(pars);
2932
2933 /* We need to inspect GSUP activity */
2934 f_create_gsup_expect(hex2str(g_pars.imsi));
2935
2936 /* Perform location update */
2937 f_perform_lu();
2938
2939 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002940 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07002941
2942 /* Send CM Service Request for MO SMMA */
2943 f_establish_fully(EST_TYPE_MO_SMS);
2944
2945 /* Submit MO SMMA on DTAP */
2946 log("Submit MO SMMA on DTAP, SM-RP-MR is '00'O");
2947 spars_mo.rp.msg_ref := '00'O;
2948 f_mo_smma(spars_mo);
2949
2950 /* Expect MO-forwardSM-Req for MO SMMA on GSUP */
2951 alt {
2952 [] GSUP.receive(tr_GSUP_MO_READY_FOR_SM_REQ(
2953 imsi := g_pars.imsi,
2954 sm_rp_mr := spars_mo.rp.msg_ref,
2955 sm_alert_rsn := GSUP_SM_ALERT_RSN_TYPE_MEM_AVAIL
2956 )) {
2957 log("RX MO-ReadyForSM-Req, SM-RP-MR is '00'O");
2958 setverdict(pass);
2959 }
2960 [] GSUP.receive {
2961 log("RX unexpected GSUP message");
2962 setverdict(fail);
2963 mtc.stop;
2964 }
2965 }
2966
2967 /* Submit MT SMS on GSUP */
2968 log("TX MT-forwardSM-Req for the MT SMS");
2969 f_gsup_forwardSM_req(spars_mt);
2970
2971 /* Wait for MT SMS on DTAP */
2972 f_mt_sms_expect(spars_mt);
2973 log("RX MT SMS on DTAP, DTAP TID is ", spars_mt.tid,
2974 ", SM-RP-MR is ", spars_mt.rp.msg_ref);
2975
2976 /* Both SM-RP-MR values shall be different */
2977 if (spars_mo.rp.msg_ref == spars_mt.rp.msg_ref) {
2978 log("Both SM-RP-MR values shall be different");
2979 setverdict(fail);
2980 }
2981
2982 /* SM-RP-MR value for MT SMS shall be assigned */
2983 if (spars_mt.rp.msg_ref == 'FF'O) {
2984 log("Unassigned SM-RP-MR value for the MT SMS");
2985 setverdict(fail);
2986 }
2987
2988 /* Trigger RP-ACK for MO SMMA by sending MO-forwardSM-Res */
2989 GSUP.send(valueof(ts_GSUP_MO_READY_FOR_SM_RES(
2990 imsi := g_pars.imsi,
2991 sm_rp_mr := spars_mo.rp.msg_ref)));
2992 /* Expect RP-ACK for MO SMMA on DTAP */
2993 f_mo_sms_wait_rp_ack(spars_mo);
2994
2995 /* Send RP-ACK for MT SMS and expect MT-forwardSM-Res on GSUP */
2996 f_mt_sms_send_rp_ack(spars_mt);
2997 alt {
2998 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2999 imsi := g_pars.imsi,
3000 sm_rp_mr := spars_mt.rp.msg_ref
3001 )) {
3002 log("RX MT-forwardSM-Res (RP-ACK)");
3003 setverdict(pass);
3004 }
3005 [] GSUP.receive {
3006 log("RX unexpected GSUP message");
3007 setverdict(fail);
3008 mtc.stop;
3009 }
3010 }
3011
3012 f_expect_clear();
3013}
3014testcase TC_gsup_mo_mt_sms_rp_mr() runs on MTC_CT {
3015 var BSC_ConnHdlrPars pars;
3016 var BSC_ConnHdlr vc_conn;
3017 f_init();
3018 pars := f_init_pars(93);
3019 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
3020 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mo_mt_sms_rp_mr), pars);
3021 vc_conn.done;
3022 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
3023}
3024
Harald Weltee13cfb22019-04-23 16:52:02 +02003025
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07003026/* Test multi-part MT-SMS over GSUP */
3027private function f_tc_gsup_mt_multi_part_sms(charstring id, BSC_ConnHdlrPars pars)
3028runs on BSC_ConnHdlr {
3029 var SmsParameters spars := valueof(t_SmsPars);
3030
3031 f_init_handler(pars);
3032
3033 /* We need to inspect GSUP activity */
3034 f_create_gsup_expect(hex2str(g_pars.imsi));
3035
3036 /* Perform location update */
3037 f_perform_lu();
3038
3039 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01003040 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07003041
3042 var template GSUP_PDU mt_forwardSM_res := tr_GSUP_MT_FORWARD_SM_RES(
3043 imsi := g_pars.imsi,
3044 /* NOTE: MSC should assign RP-MR itself */
3045 sm_rp_mr := ?
3046 );
3047
3048 /* Send 4 messages (NOTE: SM-RP-UI remains unchanged) */
3049 for (var integer i := 3; i >= 0; i := i-1) {
3050 /* Submit a MT SMS on GSUP (MMS is decremented) */
3051 f_gsup_forwardSM_req(spars, int2oct(i, 1));
3052
3053 /* Expect Paging Request and Establish connection */
3054 if (i == 3) { /* ... only once! */
Harald Weltee13cfb22019-04-23 16:52:02 +02003055 f_expect_paging();
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07003056 f_establish_fully(EST_TYPE_PAG_RESP);
3057 }
3058
3059 /* Wait for MT SMS on DTAP */
3060 f_mt_sms_expect(spars);
3061
3062 /* Send RP-ACK and expect MT-forwardSM-Res on GSUP */
3063 f_mt_sms_send_rp_ack(spars);
3064 alt {
3065 [] GSUP.receive(mt_forwardSM_res) {
3066 log("RX MT-forwardSM-Res (RP-ACK)");
3067 setverdict(pass);
3068 }
3069 [] GSUP.receive {
3070 log("RX unexpected GSUP message");
3071 setverdict(fail);
3072 mtc.stop;
3073 }
3074 }
3075
3076 /* Keep some 'distance' between transmissions */
3077 f_sleep(1.5);
3078 }
3079
3080 f_expect_clear();
3081}
3082testcase TC_gsup_mt_multi_part_sms() runs on MTC_CT {
3083 var BSC_ConnHdlrPars pars;
3084 var BSC_ConnHdlr vc_conn;
3085 f_init();
3086 pars := f_init_pars(91);
3087 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
3088 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_multi_part_sms), pars);
3089 vc_conn.done;
3090 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
3091}
3092
Harald Weltef640a012018-04-14 17:49:21 +02003093/* convert GSM L3 TON to SMPP_TON enum */
3094function f_sm_ton_from_gsm(BIT3 ton) return SMPP_TON {
3095 select (ton) {
3096 case ('000'B) { return unknown; }
3097 case ('001'B) { return international; }
3098 case ('010'B) { return national; }
3099 case ('011'B) { return network_specific; }
3100 case ('100'B) { return subscriber_number; }
3101 case ('101'B) { return alphanumeric; }
3102 case ('110'B) { return abbreviated; }
3103 }
3104 setverdict(fail, "Unknown TON ", ton);
Daniel Willmannafce8662018-07-06 23:11:32 +02003105 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02003106}
3107/* convert GSM L3 NPI to SMPP_NPI enum */
3108function f_sm_npi_from_gsm(BIT4 npi) return SMPP_NPI {
3109 select (npi) {
3110 case ('0000'B) { return unknown; }
3111 case ('0001'B) { return isdn; }
3112 case ('0011'B) { return data; }
3113 case ('0100'B) { return telex; }
3114 case ('0110'B) { return land_mobile; }
3115 case ('1000'B) { return national; }
3116 case ('1001'B) { return private_; }
3117 case ('1010'B) { return ermes; }
3118 }
3119 setverdict(fail, "Unknown NPI ", npi);
Daniel Willmannafce8662018-07-06 23:11:32 +02003120 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02003121}
3122
3123/* build a SMPP_SM from SmsParameters */
3124function f_mt_sm_from_spars(SmsParameters spars)
3125runs on BSC_ConnHdlr return SMPP_SM {
3126 var SMPP_SM sm := {
3127 service_type := "CMT",
3128 source_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
3129 source_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
3130 source_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
3131 dest_addr_ton := international,
3132 dest_addr_npi := isdn,
3133 destination_addr := hex2str(g_pars.msisdn),
3134 esm_class := '00000001'B,
3135 protocol_id := 0,
3136 priority_flag := 0,
3137 schedule_delivery_time := "",
3138 validity_period := "",
3139 registered_delivery := '00000000'B,
3140 replace_if_present := 0,
3141 data_coding := '00000001'B,
3142 sm_default_msg_id := 0,
3143 sm_length := spars.tp.udl,
3144 short_message := spars.tp.ud,
3145 opt_pars := {}
3146 };
3147 return sm;
3148}
3149
3150/* helper function to encode SMS from 'spars', send it via SMPP to MSC; receive it on MS side */
3151private function f_smpp_mt_sms(SmsParameters spars, boolean trans_mode) runs on BSC_ConnHdlr {
3152 var SMPP_SM sm := f_mt_sm_from_spars(spars);
3153 if (trans_mode) {
3154 sm.esm_class := '00000010'B;
3155 }
3156
3157 /* actually cause MSC to send a SMS via SUBMIT-SM from SMPP side */
3158 SMPP.send(ts_SMPP_SUBMIT_SM(sm));
3159 if (not match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
3160 /* if we're not in SMPP transaction mode, we expect the SMPP-level ACK
3161 * before we expect the SMS delivery on the BSC/radio side */
3162 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
3163 }
3164
3165 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02003166 f_expect_paging();
Harald Weltef640a012018-04-14 17:49:21 +02003167 /* Establish DTAP / BSSAP / SCCP connection */
3168 f_establish_fully(EST_TYPE_PAG_RESP);
3169 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
3170
3171 f_mt_sms(spars);
3172
3173 if (match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
3174 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
3175 }
3176 f_expect_clear();
3177}
3178
3179/* mobile terminated SMS, from SMPP to BSC/BTS/MS */
3180private function f_tc_smpp_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3181 f_init_handler(pars);
3182
3183 /* Perform location update so IMSI is known + registered in MSC/VLR */
3184 f_perform_lu();
3185 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
3186
3187 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01003188 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Weltef640a012018-04-14 17:49:21 +02003189
3190 var SmsParameters spars := valueof(t_SmsPars);
3191 /* TODO: test with more intelligent user data; test different coding schemes */
3192 spars.tp.ud := '00'O;
3193 spars.tp.udl := 1;
3194
3195 /* first test the non-transaction store+forward mode */
3196 f_smpp_mt_sms(spars, false);
3197
3198 /* then test the transaction mode */
3199 f_smpp_mt_sms(spars, true);
3200}
3201testcase TC_smpp_mt_sms() runs on MTC_CT {
3202 var BSC_ConnHdlr vc_conn;
3203 f_init();
3204 vc_conn := f_start_handler(refers(f_tc_smpp_mt_sms), 45);
3205 vc_conn.done;
3206}
3207
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003208/***********************************************************************
3209 * USSD Testing
3210 ***********************************************************************/
3211
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003212private altstep as_unexp_gsup_or_bssap_msg()
3213runs on BSC_ConnHdlr {
3214 [] GSUP.receive {
3215 setverdict(fail, "Unknown/unexpected GSUP received");
3216 self.stop;
3217 }
3218 [] BSSAP.receive {
3219 setverdict(fail, "Unknown/unexpected BSSAP message received");
3220 self.stop;
3221 }
3222}
3223
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003224private function f_expect_gsup_msg(template GSUP_PDU msg,
3225 float T_val := 2.0)
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003226runs on BSC_ConnHdlr return GSUP_PDU {
3227 var GSUP_PDU gsup_msg_complete;
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003228 timer T := T_val;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003229
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003230 T.start;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003231 alt {
3232 [] GSUP.receive(msg) -> value gsup_msg_complete {
3233 setverdict(pass);
3234 }
3235 /* We don't expect anything else */
3236 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003237 [] T.timeout {
3238 setverdict(fail, "Timeout waiting for GSUP message: ", msg);
3239 }
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003240 }
3241
3242 return gsup_msg_complete;
3243}
3244
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003245private function f_expect_mt_dtap_msg(template PDU_ML3_NW_MS msg,
3246 float T_val := 2.0)
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003247runs on BSC_ConnHdlr return PDU_ML3_NW_MS {
3248 var PDU_DTAP_MT bssap_msg_complete;
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003249 timer T := T_val;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003250
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003251 T.start;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003252 alt {
3253 [] BSSAP.receive(tr_PDU_DTAP_MT(msg)) -> value bssap_msg_complete {
3254 setverdict(pass);
3255 }
3256 /* We don't expect anything else */
3257 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003258 [] T.timeout {
3259 setverdict(fail, "Timeout waiting for BSSAP message: ", msg);
3260 }
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003261 }
3262
3263 return bssap_msg_complete.dtap;
3264}
3265
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003266/* LU followed by MO USSD request */
Harald Weltee13cfb22019-04-23 16:52:02 +02003267friend function f_tc_lu_and_mo_ussd_single_request(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003268runs on BSC_ConnHdlr {
3269 f_init_handler(pars);
3270
3271 /* Perform location update */
3272 f_perform_lu();
3273
3274 /* Send CM Service Request for SS/USSD */
3275 f_establish_fully(EST_TYPE_SS_ACT);
3276
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003277 /* We need to inspect GSUP activity */
3278 f_create_gsup_expect(hex2str(g_pars.imsi));
3279
3280 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3281 invoke_id := 5, /* Phone may not start from 0 or 1 */
3282 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3283 ussd_string := "*#100#"
3284 );
3285
3286 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3287 invoke_id := 5, /* InvokeID shall be the same for both REQ and RSP */
3288 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3289 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
3290 )
3291
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003292 /* Compose a new SS/REGISTER message with request */
3293 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
3294 tid := 1, /* We just need a single transaction */
3295 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003296 facility := valueof(facility_req)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003297 );
3298
3299 /* Compose SS/RELEASE_COMPLETE template with expected response */
3300 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
3301 tid := 1, /* Response should arrive within the same transaction */
3302 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003303 facility := valueof(facility_rsp)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003304 );
3305
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003306 /* Compose expected MSC -> HLR message */
3307 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
3308 imsi := g_pars.imsi,
3309 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3310 ss := valueof(facility_req)
3311 );
3312
3313 /* To be used for sending response with correct session ID */
3314 var GSUP_PDU gsup_req_complete;
3315
3316 /* Request own number */
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003317 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003318 /* Expect GSUP message containing the SS payload */
3319 gsup_req_complete := f_expect_gsup_msg(gsup_req);
3320
3321 /* Compose the response from HLR using received session ID */
3322 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
3323 imsi := g_pars.imsi,
3324 sid := gsup_req_complete.ies[1].val.session_id,
3325 state := OSMO_GSUP_SESSION_STATE_END,
3326 ss := valueof(facility_rsp)
3327 );
3328
3329 /* Finally, HLR terminates the session */
3330 GSUP.send(gsup_rsp);
3331 /* Expect RELEASE_COMPLETE message with the response */
3332 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003333
3334 f_expect_clear();
3335}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003336testcase TC_lu_and_mo_ussd_single_request() runs on MTC_CT {
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003337 var BSC_ConnHdlr vc_conn;
3338 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003339 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_single_request), 46);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003340 vc_conn.done;
3341}
3342
Harald Weltee13cfb22019-04-23 16:52:02 +02003343
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003344/* LU followed by MT USSD notification */
Harald Weltee13cfb22019-04-23 16:52:02 +02003345friend function f_tc_lu_and_mt_ussd_notification(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003346runs on BSC_ConnHdlr {
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003347 timer T := 5.0;
3348
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003349 f_init_handler(pars);
3350
3351 /* Perform location update */
3352 f_perform_lu();
3353
Harald Welte6811d102019-04-14 22:23:14 +02003354 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003355
3356 /* We need to inspect GSUP activity */
3357 f_create_gsup_expect(hex2str(g_pars.imsi));
3358
3359 /* Facility IE with network-originated USSD notification */
3360 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3361 op_code := SS_OP_CODE_USS_NOTIFY,
3362 ussd_string := "Mahlzeit!"
3363 );
3364
3365 /* Facility IE with acknowledgment to the USSD notification */
3366 var template OCTN facility_rsp := enc_SS_FacilityInformation(
3367 /* In case of USSD notification, Return Result is empty */
3368 valueof(ts_SS_USSD_FACILITY_RETURN_RESULT_EMPTY())
3369 );
3370
3371 /* Compose a new MT SS/REGISTER message with USSD notification */
3372 var template PDU_ML3_NW_MS ussd_ntf := tr_ML3_MT_SS_REGISTER(
3373 tid := 0, /* FIXME: most likely, it should be 0 */
3374 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3375 facility := valueof(facility_req)
3376 );
3377
3378 /* Compose HLR -> MSC GSUP message */
3379 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3380 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003381 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003382 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3383 ss := valueof(facility_req)
3384 );
3385
3386 /* Send it to MSC and expect Paging Request */
3387 GSUP.send(gsup_req);
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003388 T.start;
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003389 alt {
Harald Weltee13cfb22019-04-23 16:52:02 +02003390 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
3391 setverdict(pass);
3392 }
Harald Welte62113fc2019-05-09 13:04:02 +02003393 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003394 setverdict(pass);
3395 }
3396 /* We don't expect anything else */
3397 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003398 [] T.timeout {
3399 setverdict(fail, "Timeout waiting for Paging Request");
3400 }
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003401 }
3402
3403 /* Send Paging Response and expect USSD notification */
3404 f_establish_fully(EST_TYPE_PAG_RESP);
3405 /* Expect MT REGISTER message with USSD notification */
3406 f_expect_mt_dtap_msg(ussd_ntf);
3407
3408 /* Compose a new MO SS/FACILITY message with empty response */
3409 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
3410 tid := 0, /* FIXME: it shall match the request tid */
3411 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3412 facility := valueof(facility_rsp)
3413 );
3414
3415 /* Compose expected MSC -> HLR GSUP message */
3416 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
3417 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003418 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003419 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3420 ss := valueof(facility_rsp)
3421 );
3422
3423 /* MS sends response to the notification */
3424 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
3425 /* Expect GSUP message containing the SS payload */
3426 f_expect_gsup_msg(gsup_rsp);
3427
3428 /* Compose expected MT SS/RELEASE COMPLETE message */
3429 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
3430 tid := 0, /* FIXME: it shall match the request tid */
3431 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3432 facility := omit
3433 );
3434
3435 /* Compose MSC -> HLR GSUP message */
3436 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
3437 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003438 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003439 state := OSMO_GSUP_SESSION_STATE_END
3440 );
3441
3442 /* Finally, HLR terminates the session */
3443 GSUP.send(gsup_term)
3444 /* Expect MT RELEASE COMPLETE without Facility IE */
3445 f_expect_mt_dtap_msg(ussd_term);
3446
3447 f_expect_clear();
3448}
3449testcase TC_lu_and_mt_ussd_notification() runs on MTC_CT {
3450 var BSC_ConnHdlr vc_conn;
3451 f_init();
3452 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_notification), 47);
3453 vc_conn.done;
3454}
3455
Harald Weltee13cfb22019-04-23 16:52:02 +02003456
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003457/* LU followed by MT call and MO USSD request during this call */
Harald Weltee13cfb22019-04-23 16:52:02 +02003458friend function f_tc_lu_and_mo_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003459runs on BSC_ConnHdlr {
3460 f_init_handler(pars);
3461
3462 /* Call parameters taken from f_tc_lu_and_mt_call */
3463 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003464
3465 /* Perform location update */
3466 f_perform_lu();
3467
3468 /* Establish a MT call */
3469 f_mt_call_establish(cpars);
3470
3471 /* Hold the call for some time */
3472 f_sleep(1.0);
3473
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003474 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3475 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3476 ussd_string := "*#100#"
3477 );
3478
3479 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3480 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3481 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
3482 )
3483
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003484 /* Compose a new SS/REGISTER message with request */
3485 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
3486 tid := 1, /* We just need a single transaction */
3487 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003488 facility := valueof(facility_req)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003489 );
3490
3491 /* Compose SS/RELEASE_COMPLETE template with expected response */
3492 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
3493 tid := 1, /* Response should arrive within the same transaction */
3494 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003495 facility := valueof(facility_rsp)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003496 );
3497
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003498 /* Compose expected MSC -> HLR message */
3499 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
3500 imsi := g_pars.imsi,
3501 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3502 ss := valueof(facility_req)
3503 );
3504
3505 /* To be used for sending response with correct session ID */
3506 var GSUP_PDU gsup_req_complete;
3507
3508 /* Request own number */
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003509 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003510 /* Expect GSUP message containing the SS payload */
3511 gsup_req_complete := f_expect_gsup_msg(gsup_req);
3512
3513 /* Compose the response from HLR using received session ID */
3514 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
3515 imsi := g_pars.imsi,
3516 sid := gsup_req_complete.ies[1].val.session_id,
3517 state := OSMO_GSUP_SESSION_STATE_END,
3518 ss := valueof(facility_rsp)
3519 );
3520
3521 /* Finally, HLR terminates the session */
3522 GSUP.send(gsup_rsp);
3523 /* Expect RELEASE_COMPLETE message with the response */
3524 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003525
3526 /* Hold the call for some time */
3527 f_sleep(1.0);
3528
3529 /* Release the call (does Clear Complete itself) */
3530 f_call_hangup(cpars, true);
3531}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003532testcase TC_lu_and_mo_ussd_during_mt_call() runs on MTC_CT {
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003533 var BSC_ConnHdlr vc_conn;
3534 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003535 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_during_mt_call), 48);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003536 vc_conn.done;
3537}
3538
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003539/* BSSMAP Clear Request in the middle of a call, see OS#3062 */
Harald Weltee13cfb22019-04-23 16:52:02 +02003540friend function f_tc_mo_cc_bssmap_clear(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003541 f_init_handler(pars);
3542 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02003543 cpars.ran_clear_when_alerting := true;
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003544
3545 f_perform_lu();
3546
Neels Hofmeyrde76f052019-02-26 05:02:46 +01003547 var default ccrel := activate(as_optional_cc_rel(cpars));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02003548 f_mo_call_establish(cpars);
3549 f_expect_clear()
Neels Hofmeyrde76f052019-02-26 05:02:46 +01003550 deactivate(ccrel);
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003551
3552 f_sleep(1.0);
3553}
3554testcase TC_mo_cc_bssmap_clear() runs on MTC_CT {
3555 var BSC_ConnHdlr vc_conn;
3556 f_init();
3557
3558 vc_conn := f_start_handler(refers(f_tc_mo_cc_bssmap_clear), 43);
3559 vc_conn.done;
3560}
3561
Harald Weltee13cfb22019-04-23 16:52:02 +02003562
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003563/* LU followed by MT call and MT USSD request during this call */
Harald Weltee13cfb22019-04-23 16:52:02 +02003564friend function f_tc_lu_and_mt_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003565runs on BSC_ConnHdlr {
3566 f_init_handler(pars);
3567
3568 /* Call parameters taken from f_tc_lu_and_mt_call */
3569 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003570
3571 /* Perform location update */
3572 f_perform_lu();
3573
3574 /* Establish a MT call */
3575 f_mt_call_establish(cpars);
3576
3577 /* Hold the call for some time */
3578 f_sleep(1.0);
3579
3580 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3581 op_code := SS_OP_CODE_USS_REQUEST,
3582 ussd_string := "Please type anything..."
3583 );
3584
3585 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3586 op_code := SS_OP_CODE_USS_REQUEST,
3587 ussd_string := "Nope."
3588 )
3589
3590 /* Compose MT SS/REGISTER message with network-originated request */
3591 var template (value) PDU_ML3_NW_MS ussd_req := ts_ML3_MT_SS_REGISTER(
3592 tid := 0, /* FIXME: most likely, it should be 0 */
3593 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3594 facility := valueof(facility_req)
3595 );
3596
3597 /* Compose HLR -> MSC GSUP message */
3598 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3599 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003600 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003601 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3602 ss := valueof(facility_req)
3603 );
3604
3605 /* Send it to MSC */
3606 GSUP.send(gsup_req);
3607 /* Expect MT REGISTER message with USSD request */
3608 f_expect_mt_dtap_msg(ussd_req);
3609
3610 /* Compose a new MO SS/FACILITY message with response */
3611 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
3612 tid := 0, /* FIXME: it shall match the request tid */
3613 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3614 facility := valueof(facility_rsp)
3615 );
3616
3617 /* Compose expected MSC -> HLR GSUP message */
3618 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
3619 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003620 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003621 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3622 ss := valueof(facility_rsp)
3623 );
3624
3625 /* MS sends response */
3626 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
3627 f_expect_gsup_msg(gsup_rsp);
3628
3629 /* Compose expected MT SS/RELEASE COMPLETE message */
3630 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
3631 tid := 0, /* FIXME: it shall match the request tid */
3632 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3633 facility := omit
3634 );
3635
3636 /* Compose MSC -> HLR GSUP message */
3637 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
3638 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003639 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003640 state := OSMO_GSUP_SESSION_STATE_END
3641 );
3642
3643 /* Finally, HLR terminates the session */
3644 GSUP.send(gsup_term);
3645 /* Expect MT RELEASE COMPLETE without Facility IE */
3646 f_expect_mt_dtap_msg(ussd_term);
3647
3648 /* Hold the call for some time */
3649 f_sleep(1.0);
3650
3651 /* Release the call (does Clear Complete itself) */
3652 f_call_hangup(cpars, true);
3653}
3654testcase TC_lu_and_mt_ussd_during_mt_call() runs on MTC_CT {
3655 var BSC_ConnHdlr vc_conn;
3656 f_init();
3657 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_during_mt_call), 49);
3658 vc_conn.done;
3659}
3660
Harald Weltee13cfb22019-04-23 16:52:02 +02003661
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07003662/* LU followed by MO USSD request and MO Release during transaction */
Harald Weltee13cfb22019-04-23 16:52:02 +02003663friend function f_tc_lu_and_mo_ussd_mo_release(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07003664runs on BSC_ConnHdlr {
3665 f_init_handler(pars);
3666
3667 /* Perform location update */
3668 f_perform_lu();
3669
3670 /* Send CM Service Request for SS/USSD */
3671 f_establish_fully(EST_TYPE_SS_ACT);
3672
3673 /* We need to inspect GSUP activity */
3674 f_create_gsup_expect(hex2str(g_pars.imsi));
3675
3676 var template OCTN facility_ms_req := f_USSD_FACILITY_IE_INVOKE(
3677 invoke_id := 1, /* Initial request */
3678 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3679 ussd_string := "*6766*266#"
3680 );
3681
3682 var template OCTN facility_net_req := f_USSD_FACILITY_IE_INVOKE(
3683 invoke_id := 2, /* Counter request */
3684 op_code := SS_OP_CODE_USS_REQUEST,
3685 ussd_string := "Password?!?"
3686 )
3687
3688 /* Compose MO SS/REGISTER message with request */
3689 var template (value) PDU_ML3_MS_NW ussd_ms_req := ts_ML3_MO_SS_REGISTER(
3690 tid := 1, /* We just need a single transaction */
3691 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3692 facility := valueof(facility_ms_req)
3693 );
3694
3695 /* Compose expected MSC -> HLR message */
3696 var template GSUP_PDU gsup_ms_req := tr_GSUP_PROC_SS_REQ(
3697 imsi := g_pars.imsi,
3698 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3699 ss := valueof(facility_ms_req)
3700 );
3701
3702 /* To be used for sending response with correct session ID */
3703 var GSUP_PDU gsup_ms_req_complete;
3704
3705 /* Initiate a new transaction */
3706 BSSAP.send(ts_PDU_DTAP_MO(ussd_ms_req));
3707 /* Expect GSUP request with original Facility IE */
3708 gsup_ms_req_complete := f_expect_gsup_msg(gsup_ms_req);
3709
3710 /* Compose the response from HLR using received session ID */
3711 var template (value) GSUP_PDU gsup_net_req := ts_GSUP_PROC_SS_REQ(
3712 imsi := g_pars.imsi,
3713 sid := gsup_ms_req_complete.ies[1].val.session_id,
3714 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3715 ss := valueof(facility_net_req)
3716 );
3717
3718 /* Compose expected MT SS/FACILITY template with counter request */
3719 var template PDU_ML3_NW_MS ussd_net_req := tr_ML3_MT_SS_FACILITY(
3720 tid := 1, /* Response should arrive within the same transaction */
3721 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3722 facility := valueof(facility_net_req)
3723 );
3724
3725 /* Send response over GSUP */
3726 GSUP.send(gsup_net_req);
3727 /* Expect MT SS/FACILITY message with counter request */
3728 f_expect_mt_dtap_msg(ussd_net_req);
3729
3730 /* Compose MO SS/RELEASE COMPLETE */
3731 var template (value) PDU_ML3_MS_NW ussd_abort := ts_ML3_MO_SS_RELEASE_COMPLETE(
3732 tid := 1, /* Response should arrive within the same transaction */
3733 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3734 facility := omit
3735 /* TODO: cause? */
3736 );
3737
3738 /* Compose expected HLR -> MSC abort message */
3739 var template GSUP_PDU gsup_abort := tr_GSUP_PROC_SS_REQ(
3740 imsi := g_pars.imsi,
3741 sid := gsup_ms_req_complete.ies[1].val.session_id,
3742 state := OSMO_GSUP_SESSION_STATE_END
3743 );
3744
3745 /* Abort transaction */
3746 BSSAP.send(ts_PDU_DTAP_MO(ussd_abort));
3747 /* Expect GSUP message indicating abort */
3748 f_expect_gsup_msg(gsup_abort);
3749
3750 f_expect_clear();
3751}
3752testcase TC_lu_and_mo_ussd_mo_release() runs on MTC_CT {
3753 var BSC_ConnHdlr vc_conn;
3754 f_init();
3755 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_mo_release), 50);
3756 vc_conn.done;
3757}
3758
Harald Weltee13cfb22019-04-23 16:52:02 +02003759
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003760/* LU followed by MO USSD request and MT Release due to timeout */
Harald Weltee13cfb22019-04-23 16:52:02 +02003761friend function f_tc_lu_and_ss_session_timeout(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003762runs on BSC_ConnHdlr {
3763 f_init_handler(pars);
3764
3765 /* Perform location update */
3766 f_perform_lu();
3767
3768 /* Send CM Service Request for SS/USSD */
3769 f_establish_fully(EST_TYPE_SS_ACT);
3770
3771 /* We need to inspect GSUP activity */
3772 f_create_gsup_expect(hex2str(g_pars.imsi));
3773
3774 var template OCTN facility_ms_req := f_USSD_FACILITY_IE_INVOKE(
3775 invoke_id := 1,
3776 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3777 ussd_string := "#release_me");
3778
3779 /* Compose MO SS/REGISTER message with request */
3780 var template (value) PDU_ML3_MS_NW ussd_ms_req := ts_ML3_MO_SS_REGISTER(
3781 tid := 1, /* An arbitrary transaction identifier */
3782 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3783 facility := valueof(facility_ms_req));
3784
3785 /* Compose expected MSC -> HLR message */
3786 var template GSUP_PDU gsup_ms_req := tr_GSUP_PROC_SS_REQ(
3787 imsi := g_pars.imsi,
3788 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3789 ss := valueof(facility_ms_req));
3790
3791 /* To be used for sending response with correct session ID */
3792 var GSUP_PDU gsup_ms_req_complete;
3793
3794 /* Initiate a new SS transaction */
3795 BSSAP.send(ts_PDU_DTAP_MO(ussd_ms_req));
3796 /* Expect GSUP request with original Facility IE */
3797 gsup_ms_req_complete := f_expect_gsup_msg(gsup_ms_req);
3798
3799 /* Don't respond, wait for timeout */
3800 f_sleep(3.0);
3801
3802 var template PDU_ML3_NW_MS dtap_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
3803 tid := 1, /* Should match the request's tid */
3804 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3805 cause := *, /* TODO: expect some specific value */
3806 facility := omit);
3807
3808 var template GSUP_PDU gsup_rel := tr_GSUP_PROC_SS_ERR(
3809 imsi := g_pars.imsi,
3810 sid := gsup_ms_req_complete.ies[1].val.session_id,
3811 state := OSMO_GSUP_SESSION_STATE_END,
3812 cause := ?); /* TODO: expect some specific value */
3813
3814 /* Expect release on both interfaces */
3815 interleave {
3816 [] BSSAP.receive(tr_PDU_DTAP_MT(dtap_rel)) { };
3817 [] GSUP.receive(gsup_rel) { };
3818 }
3819
3820 f_expect_clear();
3821 setverdict(pass);
3822}
3823testcase TC_lu_and_ss_session_timeout() runs on MTC_CT {
3824 var BSC_ConnHdlr vc_conn;
3825 f_init();
Vadim Yanitskiy36d28dd2018-12-03 02:45:45 +07003826 f_vty_config(MSCVTY, "msc", "ncss guard-timeout 3");
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003827 vc_conn := f_start_handler(refers(f_tc_lu_and_ss_session_timeout), 51);
3828 vc_conn.done;
Vadim Yanitskiy36d28dd2018-12-03 02:45:45 +07003829 f_vty_config(MSCVTY, "msc", "ncss guard-timeout 0");
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003830}
3831
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07003832/* MT (network-originated) USSD for unknown subscriber */
3833friend function f_tc_mt_ussd_for_unknown_subscr(charstring id, BSC_ConnHdlrPars pars)
3834runs on BSC_ConnHdlr {
3835 var hexstring imsi := '000000000000000'H; /* Some unknown IMSI */
3836 var OCT4 sid := '20000222'O;
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07003837
3838 f_init_handler(pars);
3839 f_ran_register_imsi(imsi, 'FFFFFFFF'O);
3840 f_create_gsup_expect(hex2str(imsi));
3841
3842 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3843 imsi := imsi,
3844 sid := sid,
3845 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3846 ss := f_rnd_octstring(23)
3847 );
3848
3849 /* Error with cause GMM_CAUSE_IMSI_UNKNOWN */
3850 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
3851 imsi := imsi,
3852 sid := sid,
3853 state := OSMO_GSUP_SESSION_STATE_END,
3854 cause := 2 /* FIXME: introduce an enumerated type! */
3855 );
3856
3857 /* Initiate a MT USSD notification */
3858 GSUP.send(gsup_req);
3859
3860 /* Expect GSUP PROC_SS_ERROR message */
Vadim Yanitskiy851798c2019-06-15 14:22:28 +07003861 f_expect_gsup_msg(gsup_rsp);
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07003862}
3863testcase TC_mt_ussd_for_unknown_subscr() runs on MTC_CT {
3864 var BSC_ConnHdlr vc_conn;
3865 f_init();
3866 vc_conn := f_start_handler(refers(f_tc_mt_ussd_for_unknown_subscr), 0);
3867 vc_conn.done;
3868}
3869
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07003870/* MO (mobile-originated) SS/USSD for unknown transaction */
3871friend function f_tc_mo_ussd_for_unknown_trans(charstring id, BSC_ConnHdlrPars pars)
3872runs on BSC_ConnHdlr {
3873 f_init_handler(pars);
3874
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01003875 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07003876 f_create_gsup_expect(hex2str(g_pars.imsi));
3877
3878 /* Perform location update */
3879 f_perform_lu();
3880
3881 /* Send CM Service Request for SS/USSD */
3882 f_establish_fully(EST_TYPE_SS_ACT);
3883
3884 /* GSM 04.80 FACILITY message for a non-existing transaction */
3885 var template (value) PDU_ML3_MS_NW mo_ss_fac := ts_ML3_MO_SS_FACILITY(
3886 tid := 1, /* An arbitrary transaction identifier */
3887 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3888 facility := f_rnd_octstring(23) /* We don't care about the Facility IE */
3889 );
3890
3891 /* GSM 04.80 RELEASE COMPLETE message for a non-existing transaction */
3892 var template (value) PDU_ML3_MS_NW mo_ss_rel := ts_ML3_MO_SS_RELEASE_COMPLETE(
3893 tid := 1, /* An arbitrary transaction identifier */
3894 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3895 facility := f_rnd_octstring(23) /* We don't care about the Facility IE */
3896 );
3897
3898 /* Expected response from the network */
3899 var template PDU_ML3_NW_MS mt_ss_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
3900 tid := 1, /* Same as in the FACILITY message */
3901 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3902 facility := omit
3903 );
3904
3905 /* Send GSM 04.80 FACILITY for non-existing transaction */
3906 BSSAP.send(ts_PDU_DTAP_MO(mo_ss_fac));
3907
3908 /* Expect GSM 04.80 RELEASE COMPLETE message */
3909 f_expect_mt_dtap_msg(mt_ss_rel);
3910 f_expect_clear();
3911
3912 /* Send another CM Service Request for SS/USSD */
3913 f_establish_fully(EST_TYPE_SS_ACT);
3914
3915 /* Send GSM 04.80 RELEASE COMPLETE for non-existing transaction */
3916 BSSAP.send(ts_PDU_DTAP_MO(mo_ss_rel));
3917
3918 /* Expect GSM 04.80 RELEASE COMPLETE message */
3919 f_expect_mt_dtap_msg(mt_ss_rel);
3920 f_expect_clear();
3921}
3922testcase TC_mo_ussd_for_unknown_trans() runs on MTC_CT {
3923 var BSC_ConnHdlr vc_conn;
3924 f_init();
3925 vc_conn := f_start_handler(refers(f_tc_mo_ussd_for_unknown_trans), 111);
3926 vc_conn.done;
3927}
3928
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07003929/* MT (network-originated) USSD for unknown session */
3930friend function f_tc_proc_ss_for_unknown_session(charstring id, BSC_ConnHdlrPars pars)
3931runs on BSC_ConnHdlr {
3932 var OCT4 sid := '20000333'O;
3933
3934 f_init_handler(pars);
3935
3936 /* Perform location update */
3937 f_perform_lu();
3938
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01003939 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07003940 f_create_gsup_expect(hex2str(g_pars.imsi));
3941
3942 /* Request referencing a non-existing SS session */
3943 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3944 imsi := g_pars.imsi,
3945 sid := sid,
3946 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3947 ss := f_rnd_octstring(23)
3948 );
3949
3950 /* Error with some cause value */
3951 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
3952 imsi := g_pars.imsi,
3953 sid := sid,
3954 state := OSMO_GSUP_SESSION_STATE_END,
3955 cause := ? /* FIXME: introduce an enumerated type! */
3956 );
3957
3958 /* Initiate a MT USSD notification */
3959 GSUP.send(gsup_req);
3960
3961 /* Expect GSUP PROC_SS_ERROR message */
3962 f_expect_gsup_msg(gsup_rsp);
3963}
3964testcase TC_proc_ss_for_unknown_session() runs on MTC_CT {
3965 var BSC_ConnHdlr vc_conn;
3966 f_init();
3967 vc_conn := f_start_handler(refers(f_tc_proc_ss_for_unknown_session), 110);
3968 vc_conn.done;
3969}
3970
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003971/* MT (network-originated) USSD and no response to Paging Request */
3972friend function f_tc_proc_ss_paging_fail(charstring id, BSC_ConnHdlrPars pars)
3973runs on BSC_ConnHdlr {
3974 timer TP := 2.0; /* Paging timer */
3975
3976 f_init_handler(pars);
3977
3978 /* Perform location update */
3979 f_perform_lu();
3980
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01003981 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003982 f_create_gsup_expect(hex2str(g_pars.imsi));
3983
3984 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3985 imsi := g_pars.imsi,
3986 sid := '20000444'O,
3987 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3988 ss := f_rnd_octstring(23)
3989 );
3990
3991 /* Error with some cause value */
3992 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
3993 imsi := g_pars.imsi,
3994 sid := '20000444'O,
3995 state := OSMO_GSUP_SESSION_STATE_END,
3996 cause := ? /* FIXME: introduce an enumerated type! */
3997 );
3998
3999 /* Initiate a MT USSD notification */
4000 GSUP.send(gsup_req);
4001
4002 /* Send it to MSC and expect Paging Request */
4003 TP.start;
4004 alt {
4005 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
4006 setverdict(pass);
4007 }
4008 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
4009 setverdict(pass);
4010 }
4011 /* We don't expect anything else */
4012 [] as_unexp_gsup_or_bssap_msg();
4013 [] TP.timeout {
4014 setverdict(fail, "Timeout waiting for Paging Request");
4015 }
4016 }
4017
Vadim Yanitskiyd24b5252019-10-02 00:04:51 +07004018 /* Wait up to 20 seconds for GSUP PROC_SS_ERROR message.
4019 * OsmoMSC waits for Paging Response 10 seconds by default. */
4020 f_expect_gsup_msg(gsup_rsp, T_val := 20.0);
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07004021}
4022testcase TC_proc_ss_paging_fail() runs on MTC_CT {
4023 var BSC_ConnHdlr vc_conn;
4024 f_init();
4025 vc_conn := f_start_handler(refers(f_tc_proc_ss_paging_fail), 101);
4026 vc_conn.done;
4027}
4028
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07004029/* MT (network-originated) USSD followed by immediate abort */
4030friend function f_tc_proc_ss_abort(charstring id, BSC_ConnHdlrPars pars)
4031runs on BSC_ConnHdlr {
4032 var octetstring facility := f_rnd_octstring(23);
4033 var OCT4 sid := '20000555'O;
4034 timer TP := 2.0;
4035
4036 f_init_handler(pars);
4037
4038 /* Perform location update */
4039 f_perform_lu();
4040
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01004041 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07004042 f_create_gsup_expect(hex2str(g_pars.imsi));
4043
4044 /* PROC_SS_REQ initiates a mobile-originated SS/USSD session */
4045 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
4046 imsi := g_pars.imsi, sid := sid,
4047 state := OSMO_GSUP_SESSION_STATE_BEGIN,
4048 ss := facility
4049 );
4050
4051 /* On the MS side, we expect GSM 04.80 REGISTER message */
4052 var template PDU_ML3_NW_MS dtap_reg := tr_ML3_MT_SS_REGISTER(
4053 tid := 0, /* Most likely, it should be 0 */
4054 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
4055 facility := facility
4056 );
4057
4058 /* PROC_SS_ERR with SESSION_STATE_END terminates the SS/USSD session */
4059 var template (value) GSUP_PDU gsup_abort := ts_GSUP_PROC_SS_ERR(
4060 imsi := g_pars.imsi, sid := sid,
4061 state := OSMO_GSUP_SESSION_STATE_END,
4062 cause := 0 /* FIXME: introduce an enumerated type! */
4063 );
4064
4065 /* On the MS side, we expect GSM 04.80 REGISTER message */
4066 var template PDU_ML3_NW_MS dtap_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
4067 tid := 0, /* Most likely, it should be 0 */
4068 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
4069 cause := *, /* FIXME: expect some specific cause value */
4070 facility := omit
4071 );
4072
4073 /* Initiate a MT USSD with random payload */
4074 GSUP.send(gsup_req);
4075
4076 /* Expect Paging Request */
4077 TP.start;
4078 alt {
4079 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
4080 setverdict(pass);
4081 }
4082 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
4083 setverdict(pass);
4084 }
4085 /* We don't expect anything else */
4086 [] as_unexp_gsup_or_bssap_msg();
4087 [] TP.timeout {
4088 setverdict(fail, "Timeout waiting for Paging Request");
4089 }
4090 }
4091
4092 /* Send Paging Response and establish connection */
4093 f_establish_fully(EST_TYPE_PAG_RESP);
4094 /* Expect MT REGISTER message with random facility */
4095 f_expect_mt_dtap_msg(dtap_reg);
4096
4097 /* HLR/EUSE decides to abort the session even
4098 * before getting any response from the MS */
4099 /* Initiate a MT USSD with random payload */
4100 GSUP.send(gsup_abort);
4101
4102 /* Expect RELEASE COMPLETE on ths MS side */
4103 f_expect_mt_dtap_msg(dtap_rel);
4104
4105 f_expect_clear();
4106}
4107testcase TC_proc_ss_abort() runs on MTC_CT {
4108 var BSC_ConnHdlr vc_conn;
4109 f_init();
4110 vc_conn := f_start_handler(refers(f_tc_proc_ss_abort), 102);
4111 vc_conn.done;
4112}
4113
Harald Weltee13cfb22019-04-23 16:52:02 +02004114
Vadim Yanitskiy1c9754d2020-01-07 21:56:55 +01004115/* Verify multiple concurrent MO SS/USSD transactions
4116 * (one subscriber - one transaction) */
4117testcase TC_multi_lu_and_mo_ussd() runs on MTC_CT {
4118 var BSC_ConnHdlr vc_conn[16];
4119 var integer i;
4120
4121 f_init();
4122
4123 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
4124 vc_conn[i] := f_start_handler(refers(f_tc_lu_and_mo_ussd_single_request), 210 + i);
4125 }
4126
4127 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
4128 vc_conn[i].done;
4129 }
4130}
4131
4132/* Verify multiple concurrent MT SS/USSD transactions
4133 * (one subscriber - one transaction) */
4134testcase TC_multi_lu_and_mt_ussd() runs on MTC_CT {
4135 var BSC_ConnHdlr vc_conn[16];
4136 var integer i;
4137 var OCT4 sid;
4138
4139 f_init();
4140
4141 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
4142 sid := '200001'O & int2oct(i, 1); /* All transactions must use different session ID */
4143 vc_conn[i] := f_start_handler_with_pars(refers(f_tc_lu_and_mt_ussd_notification),
4144 f_init_pars(226 + i, gsup_sid := sid));
4145 }
4146
4147 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
4148 vc_conn[i].done;
4149 }
4150}
4151
4152
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004153/* A5/1 only permitted on network side; attempt an invalid CIPHER MODE COMPLETE with A5/3 which MSC should reject. */
4154private function f_tc_cipher_complete_with_invalid_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4155 pars.net.expect_auth := true;
4156 pars.net.expect_ciph := true;
4157 pars.net.kc_support := '02'O; /* A5/1 only */
4158 f_init_handler(pars);
4159
4160 g_pars.vec := f_gen_auth_vec_2g();
4161
4162 /* Can't use f_perform_lu() directly. Code below is based on it. */
4163
4164 /* tell GSUP dispatcher to send this IMSI to us */
4165 f_create_gsup_expect(hex2str(g_pars.imsi));
4166
4167 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
4168 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
Harald Weltedceacc72019-04-21 20:58:35 +02004169 f_cl3_or_initial_ue(l3_lu);
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004170
4171 f_mm_auth();
4172
4173 var OCT1 a5_net := f_alg_mask_from_cm(g_pars.cm2);
4174 var OCT1 a5_intersect := g_pars.net.kc_support and4b a5_net;
4175 alt {
4176 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(a5_intersect, g_pars.vec.kc)) {
4177 BSSAP.send(ts_BSSMAP_CipherModeCompl(int2oct(4 /* "accept" A5/3 */, 1)));
4178 }
4179 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?, g_pars.vec.kc)) {
4180 setverdict(fail, "Wrong ciphering algorithm mask in CiphModCmd");
4181 mtc.stop;
4182 }
4183 [] BSSAP.receive {
4184 setverdict(fail, "Unknown/unexpected BSSAP received");
4185 mtc.stop;
4186 }
4187 }
Harald Welte79f1e452020-08-18 22:55:02 +02004188 f_expect_common_id();
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004189
4190 /* Expect LU reject from MSC. */
4191 alt {
4192 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
4193 setverdict(pass);
4194 }
4195 [] BSSAP.receive {
4196 setverdict(fail, "Unknown/unexpected BSSAP received");
4197 mtc.stop;
4198 }
4199 }
Stefan Sperlingc620b352018-12-18 17:23:36 +01004200 f_expect_clear();
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004201}
4202
4203testcase TC_cipher_complete_with_invalid_cipher() runs on MTC_CT {
4204 var BSC_ConnHdlr vc_conn;
4205 f_init();
4206 f_vty_config(MSCVTY, "network", "encryption a5 1");
4207
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02004208 vc_conn := f_start_handler(refers(f_tc_cipher_complete_with_invalid_cipher), 52, verify_cell_id := false);
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004209 vc_conn.done;
4210}
4211
Harald Welteb2284bd2019-05-10 11:30:43 +02004212/* Location Update with invalid (non-matching) MCC/MNC reported on BSSMAP level from BSC */
4213friend function f_tc_lu_with_invalid_mcc_mnc(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4214 f_init_handler(pars);
4215
4216 /* tell GSUP dispatcher to send this IMSI to us */
4217 f_create_gsup_expect(hex2str(g_pars.imsi));
4218
4219 /* modify the cell ID which will be used to construct the COMPLELTE L3 or InitialUE */
4220 g_pars.cell_id := valueof(ts_CellId_CGI('333'H, '22'H, 23, 42));
4221
4222 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
4223 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
4224 f_cl3_or_initial_ue(l3_lu);
Harald Welte79f1e452020-08-18 22:55:02 +02004225 f_expect_common_id();
Harald Welteb2284bd2019-05-10 11:30:43 +02004226
4227 /* Expect LU reject from MSC. */
4228 alt {
4229 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
4230 setverdict(pass);
4231 }
4232 [] BSSAP.receive {
4233 setverdict(fail, "Unknown/unexpected BSSAP received");
4234 mtc.stop;
4235 }
4236 }
4237 f_expect_clear();
4238}
4239testcase TC_lu_with_invalid_mcc_mnc() runs on MTC_CT {
4240 var BSC_ConnHdlr vc_conn;
4241 f_init();
4242 vc_conn := f_start_handler(refers(f_tc_lu_with_invalid_mcc_mnc), 54);
4243 vc_conn.done;
4244}
4245
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01004246private function f_tc_cipher_complete_without_alg(charstring id, BSC_ConnHdlrPars pars, octetstring kc_support) runs on BSC_ConnHdlr {
4247 pars.net.expect_auth := true;
4248 pars.net.expect_ciph := true;
4249 pars.net.kc_support := kc_support;
4250 f_init_handler(pars);
4251
4252 g_pars.vec := f_gen_auth_vec_2g();
4253
4254 /* Can't use f_perform_lu() directly. Code below is based on it. */
4255
4256 /* tell GSUP dispatcher to send this IMSI to us */
4257 f_create_gsup_expect(hex2str(g_pars.imsi));
4258
4259 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
4260 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
4261 f_cl3_or_initial_ue(l3_lu);
4262
4263 f_mm_auth();
4264
4265 var OCT1 a5_net := f_alg_mask_from_cm(g_pars.cm2);
4266 var OCT1 a5_intersect := g_pars.net.kc_support and4b a5_net;
4267 alt {
4268 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(a5_intersect, g_pars.vec.kc)) {
4269 BSSAP.send(ts_BSSMAP_CipherModeComplAlg(omit));
4270 }
4271 [] BSSAP.receive(tr_BSSMAP_ClassmarkReq) {
4272 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
4273 repeat;
4274 }
4275 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?, g_pars.vec.kc)) {
4276 setverdict(fail, "Wrong ciphering algorithm mask in CiphModCmd");
4277 mtc.stop;
4278 }
4279 [] BSSAP.receive {
4280 setverdict(fail, "Unknown/unexpected BSSAP received");
4281 mtc.stop;
4282 }
4283 }
Harald Welte79f1e452020-08-18 22:55:02 +02004284 f_expect_common_id();
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01004285
4286 /* TODO: Verify MSC is using the best cipher available! How? */
4287
4288 f_msc_lu_hlr();
4289 f_accept_reject_lu();
4290 f_expect_clear();
4291 setverdict(pass);
4292}
4293
4294/* A5/1 only permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
4295private function f_tc_cipher_complete_1_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4296 f_tc_cipher_complete_without_alg(id, pars, '02'O /* A5/1 only */);
4297}
4298
4299/* A5/3 only permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
4300private function f_tc_cipher_complete_3_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4301 f_tc_cipher_complete_without_alg(id, pars, '08'O /* A5/3 only */);
4302}
4303
4304/* A5/1 + A5/3 permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
4305private function f_tc_cipher_complete_13_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4306 f_tc_cipher_complete_without_alg(id, pars, '0A'O /* A5/1 and A5/3 enabled */);
4307}
4308
4309testcase TC_cipher_complete_1_without_cipher() runs on MTC_CT {
4310 var BSC_ConnHdlr vc_conn;
4311 f_init();
4312 f_vty_config(MSCVTY, "network", "encryption a5 1");
4313
4314 vc_conn := f_start_handler(refers(f_tc_cipher_complete_1_without_cipher), 53);
4315 vc_conn.done;
4316}
4317
4318testcase TC_cipher_complete_3_without_cipher() runs on MTC_CT {
4319 var BSC_ConnHdlr vc_conn;
4320 f_init();
4321 f_vty_config(MSCVTY, "network", "encryption a5 3");
4322
4323 vc_conn := f_start_handler(refers(f_tc_cipher_complete_3_without_cipher), 54);
4324 vc_conn.done;
4325}
4326
4327testcase TC_cipher_complete_13_without_cipher() runs on MTC_CT {
4328 var BSC_ConnHdlr vc_conn;
4329 f_init();
4330 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
4331
4332 vc_conn := f_start_handler(refers(f_tc_cipher_complete_13_without_cipher), 55);
4333 vc_conn.done;
4334}
Harald Welteb2284bd2019-05-10 11:30:43 +02004335
Harald Weltef640a012018-04-14 17:49:21 +02004336/* TODO (SMS):
4337 * different user data lengths
4338 * SMPP transaction mode with unsuccessful delivery
4339 * queued MT-SMS with no paging response + later delivery
4340 * different data coding schemes
4341 * multi-part SMS
4342 * user-data headers
4343 * TP-PID for SMS to SIM
4344 * behavior if SMS memory is full + RP-SMMA
4345 * delivery reports
4346 * SMPP osmocom extensions
4347 * more-messages-to-send
4348 * SMS during ongoing call (SACCH/SAPI3)
4349 */
4350
4351/* TODO (General):
Harald Welteba7b6d92018-01-23 21:32:34 +01004352 * continue to send repeated MO signalling messages to keep channel open: does MSC tmeout?
4353 * malformed messages (missing IE, invalid message type): properly rejected?
4354 * MT call while LU or is ongoing: Do we use existing lchan or page while lchan active?
4355 * 3G/2G auth permutations
4356 * encryption algorithms vs. classmark vs. vty config
Harald Welteba7b6d92018-01-23 21:32:34 +01004357 * send new transaction after/during clear (like SMS, ...)
Harald Welte45164da2018-01-24 12:51:27 +01004358 * too long L3 INFO in DTAP
4359 * too long / padded BSSAP
4360 * too long / short TLV values
Harald Welteba7b6d92018-01-23 21:32:34 +01004361 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01004362
Harald Weltee13cfb22019-04-23 16:52:02 +02004363/***********************************************************************
4364 * SGsAP Testing
4365 ***********************************************************************/
4366
Philipp Maier948747b2019-04-02 15:22:33 +02004367/* Check if a subscriber exists in the VLR */
4368private function f_ctrl_subscr_in_vlr(charstring imsi_or_msisdn) runs on BSC_ConnHdlr return boolean {
4369
4370 var CtrlValue active_subsribers;
4371 var integer rc;
4372 active_subsribers := f_ctrl_get(IPA_CTRL, "subscriber-list-active-v1");
4373
4374 rc := f_strstr(active_subsribers, imsi_or_msisdn);
4375 if (rc < 0) {
4376 return false;
4377 }
4378
4379 return true;
4380}
4381
Harald Welte4263c522018-12-06 11:56:27 +01004382/* Perform a location updatye at the A-Interface and run some checks to confirm
4383 * that everything is back to normal. */
4384private function f_sgsap_bssmap_screening() runs on BSC_ConnHdlr {
4385 var SmsParameters spars := valueof(t_SmsPars);
4386
4387 /* Perform a location update, the SGs association is expected to fall
4388 * back to NULL */
4389 f_perform_lu();
4390 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4391
4392 /* Trigger a paging request and expect the paging on BSSMAP, this is
4393 * to make sure that pagings are sent throught the A-Interface again
4394 * and not throught the SGs interface.*/
Harald Welte6811d102019-04-14 22:23:14 +02004395 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Welte4263c522018-12-06 11:56:27 +01004396 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4397
4398 alt {
Harald Weltee13cfb22019-04-23 16:52:02 +02004399 [g_pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)); {
4400 setverdict(pass);
4401 }
Harald Welte62113fc2019-05-09 13:04:02 +02004402 [not g_pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
Harald Welte4263c522018-12-06 11:56:27 +01004403 setverdict(pass);
4404 }
4405 [] SGsAP.receive {
4406 setverdict(fail, "Received unexpected message on SGs");
4407 }
4408 }
4409
4410 /* Send an SMS to make sure that also payload messages are routed
4411 * throught the A-Interface again */
4412 f_establish_fully(EST_TYPE_MO_SMS);
4413 f_mo_sms(spars);
4414 f_expect_clear();
4415}
4416
4417private function f_tc_sgsap_reset(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4418 var charstring vlr_name;
4419 f_init_handler(pars);
4420
4421 vlr_name := f_sgsap_reset_mme(mp_mme_name);
4422 log("VLR name: ", vlr_name);
4423 setverdict(pass);
Neels Hofmeyrc0b520d2019-03-06 15:35:50 +01004424 f_sleep(1.0);
Harald Welte4263c522018-12-06 11:56:27 +01004425}
4426
4427testcase TC_sgsap_reset() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004428 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004429 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004430 f_init(1, true);
4431 pars := f_init_pars(11810, true);
4432 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_reset), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004433 vc_conn.done;
4434}
4435
4436/* like f_mm_auth() but for SGs */
4437function f_mm_auth_sgs() runs on BSC_ConnHdlr {
4438 if (g_pars.net.expect_auth) {
4439 g_pars.vec := f_gen_auth_vec_3g();
4440 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G3G(g_pars.vec.rand,
4441 g_pars.vec.sres,
4442 g_pars.vec.kc,
4443 g_pars.vec.ik,
4444 g_pars.vec.ck,
4445 g_pars.vec.autn,
4446 g_pars.vec.res));
4447 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
4448 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
4449 SGsAP.receive(tr_ML3_MT_MM_AUTH_REQ_3G(g_pars.vec.rand, g_pars.vec.autn));
4450 SGsAP.send(ts_ML3_MT_MM_AUTH_RESP_3G(g_pars.vec.sres, g_pars.vec.res));
4451 }
4452}
4453
4454/* like f_perform_lu(), but on SGs rather than BSSAP */
4455function f_sgs_perform_lu() runs on BSC_ConnHdlr {
4456 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4457 var PDU_SGsAP lur;
4458 var PDU_SGsAP lua;
4459 var PDU_SGsAP mm_info;
4460 var octetstring mm_info_dtap;
4461
4462 /* tell GSUP dispatcher to send this IMSI to us */
4463 f_create_gsup_expect(hex2str(g_pars.imsi));
4464
4465 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
4466 ts_SGsAP_LAI('901'H, '70'H, 2342)));
4467 /* Old LAI, if MS sends it */
4468 /* TMSI status, if MS has no valid TMSI */
4469 /* IMEISV, if it supports "automatic device detection" */
4470 /* TAI, if available in MME */
4471 /* E-CGI, if available in MME */
4472 SGsAP.send(lur);
4473
4474 /* FIXME: is this really done over SGs? The Ue is already authenticated
4475 * via the MME ... */
4476 f_mm_auth_sgs();
4477
4478 /* Expect MSC to perform LU with HLR */
4479 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4480 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
4481 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
4482 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
4483
4484 alt {
4485 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) -> value lua {
4486 if (isvalue(lua.sGsAP_LOCATION_UPDATE_ACCEPT.newTMSIorIMSI.iD.iD.tmsi_ptmsi.octets)) {
4487 g_pars.tmsi :=lua.sGsAP_LOCATION_UPDATE_ACCEPT.newTMSIorIMSI.iD.iD.tmsi_ptmsi.octets
4488 SGsAP.send(ts_SGsAP_TMSI_REALL_CMPL(g_pars.imsi));
4489 }
4490 setverdict(pass);
4491 }
4492 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4493 setverdict(fail, "Received LU-REJECT instead of ACCEPT");
4494 }
4495 [] SGsAP.receive {
4496 setverdict(fail, "Received unexpected message on SGs");
4497 }
4498 }
4499
4500 /* Check MM information */
4501 if (mp_mm_info == true) {
4502 SGsAP.receive(tr_SGsAP_MM_INFO_REQ(g_pars.imsi, ?)) -> value mm_info;
4503 mm_info_dtap := '0532'O & mm_info.sGsAP_MM_INFORMATION_REQUEST.mM_Information.information;
4504 if (not match(dec_PDU_ML3_NW_MS(mm_info_dtap), tr_ML3_MT_MM_Info)) {
4505 setverdict(fail, "Unexpected MM Information");
4506 }
4507 }
4508
4509 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4510}
4511
4512private function f_tc_sgsap_lu(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4513 f_init_handler(pars);
4514 f_sgs_perform_lu();
4515 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4516
4517 f_sgsap_bssmap_screening();
4518
4519 setverdict(pass);
4520}
4521testcase TC_sgsap_lu() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004522 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004523 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004524 f_init(1, true);
4525 pars := f_init_pars(11811, true);
4526 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004527 vc_conn.done;
4528}
4529
4530/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
4531private function f_tc_sgsap_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4532 f_init_handler(pars);
4533 var PDU_SGsAP lur;
4534
4535 f_create_gsup_expect(hex2str(g_pars.imsi));
4536 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4537 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
4538 ts_SGsAP_LAI('901'H, '70'H, 2342)));
4539 SGsAP.send(lur);
4540
4541 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4542 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
4543 alt {
4544 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4545 setverdict(pass);
4546 }
4547 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) {
4548 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
4549 mtc.stop;
4550 }
4551 [] SGsAP.receive {
4552 setverdict(fail, "Received unexpected message on SGs");
4553 }
4554 }
4555
4556 f_sgsap_bssmap_screening();
4557
4558 setverdict(pass);
4559}
4560testcase TC_sgsap_lu_imsi_reject() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004561 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004562 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004563 f_init(1, true);
4564 pars := f_init_pars(11812, true);
Harald Welte4263c522018-12-06 11:56:27 +01004565
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004566 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_imsi_reject), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004567 vc_conn.done;
4568}
4569
4570/* Do LU by IMSI, but then remain silent so that Ts6-1 times out */
4571private function f_tc_sgsap_lu_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4572 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4573 var PDU_SGsAP lur;
4574
4575 f_init_handler(pars);
4576
4577 /* tell GSUP dispatcher to send this IMSI to us */
4578 f_create_gsup_expect(hex2str(g_pars.imsi));
4579
4580 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
4581 ts_SGsAP_LAI('901'H, '70'H, 2342)));
4582 /* Old LAI, if MS sends it */
4583 /* TMSI status, if MS has no valid TMSI */
4584 /* IMEISV, if it supports "automatic device detection" */
4585 /* TAI, if available in MME */
4586 /* E-CGI, if available in MME */
4587 SGsAP.send(lur);
4588
4589 /* FIXME: is this really done over SGs? The Ue is already authenticated
4590 * via the MME ... */
4591 f_mm_auth_sgs();
4592
4593 /* Expect MSC to perform LU with HLR */
4594 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4595 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
4596 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
4597 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
4598
4599 alt {
4600 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) {
4601 setverdict(pass);
4602 }
4603 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4604 setverdict(fail, "Received LU-REJECT instead of ACCEPT");
4605 }
4606 [] SGsAP.receive {
4607 setverdict(fail, "Received unexpected message on SGs");
4608 }
4609 }
4610
4611 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4612
4613 /* Wait until the VLR has abort the TMSI reallocation procedure */
4614 f_sleep(45.0);
4615
4616 /* The outcome does not change the SGs state, see also 5.2.3.4 */
4617 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4618
4619 f_sgsap_bssmap_screening();
4620
4621 setverdict(pass);
4622}
4623testcase TC_sgsap_lu_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004624 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004625 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004626 f_init(1, true);
4627 pars := f_init_pars(11813, true);
Harald Welte4263c522018-12-06 11:56:27 +01004628
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004629 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004630 vc_conn.done;
4631}
4632
4633private function f_tc_sgsap_expl_imsi_det_eps(charstring id, BSC_ConnHdlrPars pars)
4634runs on BSC_ConnHdlr {
4635 f_init_handler(pars);
4636 f_sgs_perform_lu();
4637 f_sleep(3.0);
4638
4639 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4640 SGsAP.send(ts_SGsAP_EPS_DETACH_IND(g_pars.imsi, mme_name, UE_initiated));
4641 SGsAP.receive(tr_SGsAP_EPS_DETACH_ACK(g_pars.imsi));
4642 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4643
4644 f_sgsap_bssmap_screening();
4645
4646 setverdict(pass);
4647}
4648testcase TC_sgsap_expl_imsi_det_eps() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004649 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004650 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004651 f_init(1, true);
4652 pars := f_init_pars(11814, true);
4653 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_expl_imsi_det_eps), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004654 vc_conn.done;
4655}
4656
Philipp Maierfc19f172019-03-21 11:17:54 +01004657private function f_tc_sgsap_impl_imsi_det_eps(charstring id, BSC_ConnHdlrPars pars)
4658runs on BSC_ConnHdlr {
4659 f_init_handler(pars);
4660 f_sgs_perform_lu();
4661 f_sleep(3.0);
4662
4663 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4664 SGsAP.send(ts_SGsAP_EPS_DETACH_IND(g_pars.imsi, mme_name, network_initiated));
4665 SGsAP.receive(tr_SGsAP_EPS_DETACH_ACK(g_pars.imsi));
4666 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4667
4668 f_sgsap_bssmap_screening();
4669
4670 setverdict(pass);
4671}
4672testcase TC_sgsap_impl_imsi_det_eps() runs on MTC_CT {
4673 var BSC_ConnHdlrPars pars;
4674 var BSC_ConnHdlr vc_conn;
4675 f_init(1, true);
4676 pars := f_init_pars(11814, true);
4677 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_impl_imsi_det_eps), pars);
4678 vc_conn.done;
4679}
4680
Harald Welte4263c522018-12-06 11:56:27 +01004681private function f_tc_sgsap_expl_imsi_det_noneps(charstring id, BSC_ConnHdlrPars pars)
4682runs on BSC_ConnHdlr {
4683 f_init_handler(pars);
4684 f_sgs_perform_lu();
4685 f_sleep(3.0);
4686
4687 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4688 SGsAP.send(ts_SGsAP_IMSI_DETACH_IND(g_pars.imsi, mme_name, combined_UE_initiated));
4689 SGsAP.receive(tr_SGsAP_IMSI_DETACH_ACK(g_pars.imsi));
Philipp Maierd08e7e72019-04-02 15:27:10 +02004690
4691 if (f_ctrl_subscr_in_vlr(hex2str(g_pars.imsi))) {
4692 setverdict(fail, "subscriber not removed from VLR");
4693 }
Harald Welte4263c522018-12-06 11:56:27 +01004694
4695 f_sgsap_bssmap_screening();
4696
4697 setverdict(pass);
4698}
4699testcase TC_sgsap_expl_imsi_det_noneps() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004700 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004701 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004702 f_init(1, true);
4703 pars := f_init_pars(11815, true);
4704 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_expl_imsi_det_noneps), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004705 vc_conn.done;
4706}
4707
Philipp Maier5d812702019-03-21 10:51:26 +01004708private function f_tc_sgsap_impl_imsi_det_noneps(charstring id, BSC_ConnHdlrPars pars)
4709runs on BSC_ConnHdlr {
4710 f_init_handler(pars);
4711 f_sgs_perform_lu();
4712 f_sleep(3.0);
4713
4714 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4715 SGsAP.send(ts_SGsAP_IMSI_DETACH_IND(g_pars.imsi, mme_name, implicit_network_initiated));
4716 SGsAP.receive(tr_SGsAP_IMSI_DETACH_ACK(g_pars.imsi));
4717
4718 if (f_ctrl_subscr_in_vlr(hex2str(g_pars.imsi))) {
4719 setverdict(fail, "subscriber not removed from VLR");
4720 }
4721
4722 f_sgsap_bssmap_screening();
4723
4724 setverdict(pass);
4725}
4726testcase TC_sgsap_impl_imsi_det_noneps() runs on MTC_CT {
4727 var BSC_ConnHdlrPars pars;
4728 var BSC_ConnHdlr vc_conn;
4729 f_init(1, true);
4730 pars := f_init_pars(11815, true);
4731 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_impl_imsi_det_noneps), pars);
4732 vc_conn.done;
4733}
4734
Harald Welte4263c522018-12-06 11:56:27 +01004735/* Trigger a paging request via VTY and send a paging reject in response */
4736private function f_tc_sgsap_paging_rej(charstring id, BSC_ConnHdlrPars pars)
4737runs on BSC_ConnHdlr {
4738 f_init_handler(pars);
4739 f_sgs_perform_lu();
4740 f_sleep(1.0);
4741
4742 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4743 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4744 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4745 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4746
4747 /* Initiate paging via VTY */
4748 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4749 alt {
4750 [] SGsAP.receive(exp_resp) {
4751 setverdict(pass);
4752 }
4753 [] SGsAP.receive {
4754 setverdict(fail, "Received unexpected message on SGs");
4755 }
4756 }
4757
4758 /* Now reject the paging */
4759 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, IMSI_unknown));
4760
4761 /* Wait for the states inside the MSC to settle and check the state
4762 * of the SGs Association */
4763 f_sleep(1.0);
4764 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4765
4766 /* FIXME: At the moment we send an IMSI_unknown as cause code, which is fine,
4767 * but we also need to cover tha case where the cause code indicates an
4768 * "IMSI detached for EPS services". In those cases the VLR is expected to
4769 * try paging on tha A/Iu interface. This will be another testcase similar to
4770 * this one, but extended with checks for the presence of the A/Iu paging
4771 * messages. */
4772
4773 f_sgsap_bssmap_screening();
4774
4775 setverdict(pass);
4776}
4777testcase TC_sgsap_paging_rej() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004778 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004779 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004780 f_init(1, true);
4781 pars := f_init_pars(11816, true);
4782 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_rej), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004783 vc_conn.done;
4784}
4785
4786/* Trigger a paging request via VTY and send a paging reject that indicates
4787 * that the subscriber intentionally rejected the call. */
4788private function f_tc_sgsap_paging_subscr_rej(charstring id, BSC_ConnHdlrPars pars)
4789runs on BSC_ConnHdlr {
4790 f_init_handler(pars);
4791 f_sgs_perform_lu();
4792 f_sleep(1.0);
4793
4794 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4795 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4796 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4797 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4798
4799 /* Initiate paging via VTY */
4800 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4801 alt {
4802 [] SGsAP.receive(exp_resp) {
4803 setverdict(pass);
4804 }
4805 [] SGsAP.receive {
4806 setverdict(fail, "Received unexpected message on SGs");
4807 }
4808 }
4809
4810 /* Now reject the paging */
4811 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, user_rejected_mobile_terminating_CS_fallback_call));
4812
4813 /* Wait for the states inside the MSC to settle and check the state
4814 * of the SGs Association */
4815 f_sleep(1.0);
4816 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4817
4818 /* FIXME: The VLR is supposed to trigger an User Determined User Busy (UDUB) as specified
4819 * in 3GPP TS 24.082, this is not yet implemented in the MSC or in this tests, we need
4820 * to check back how this works and how it can be tested */
4821
4822 f_sgsap_bssmap_screening();
4823
4824 setverdict(pass);
4825}
4826testcase TC_sgsap_paging_subscr_rej() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004827 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004828 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004829 f_init(1, true);
4830 pars := f_init_pars(11817, true);
4831 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_subscr_rej), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004832 vc_conn.done;
4833}
4834
4835/* Trigger a paging request via VTY and send an UE unreacable messge in response */
4836private function f_tc_sgsap_paging_ue_unr(charstring id, BSC_ConnHdlrPars pars)
4837runs on BSC_ConnHdlr {
4838 f_init_handler(pars);
4839 f_sgs_perform_lu();
4840 f_sleep(1.0);
4841
4842 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4843 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4844 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4845 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4846
4847 /* Initiate paging via VTY */
4848 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4849 alt {
4850 [] SGsAP.receive(exp_resp) {
4851 setverdict(pass);
4852 }
4853 [] SGsAP.receive {
4854 setverdict(fail, "Received unexpected message on SGs");
4855 }
4856 }
4857
4858 /* Now pretend that the UE is unreachable */
4859 SGsAP.send(ts_SGsAP_UE_UNREACHABLE(g_pars.imsi, UE_unreachable));
4860
4861 /* Wait for the states inside the MSC to settle and check the state
4862 * of the SGs Association. */
4863 f_sleep(1.0);
4864 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4865
4866 f_sgsap_bssmap_screening();
4867
4868 setverdict(pass);
4869}
4870testcase TC_sgsap_paging_ue_unr() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004871 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004872 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004873 f_init(1, true);
4874 pars := f_init_pars(11818, true);
4875 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_ue_unr), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004876 vc_conn.done;
4877}
4878
4879/* Trigger a paging request via VTY but don't respond to it */
4880private function f_tc_sgsap_paging_and_nothing(charstring id, BSC_ConnHdlrPars pars)
4881runs on BSC_ConnHdlr {
4882 f_init_handler(pars);
4883 f_sgs_perform_lu();
4884 f_sleep(1.0);
4885
4886 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4887 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
Philipp Maier34218102019-09-24 09:15:49 +02004888 var template PDU_SGsAP exp_serv_abrt := ts_SGsAP_SERVICE_ABORT_REQ(g_pars.imsi);
Harald Welte4263c522018-12-06 11:56:27 +01004889 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4890 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4891
4892 /* Initiate paging via VTY */
4893 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4894 alt {
4895 [] SGsAP.receive(exp_resp) {
4896 setverdict(pass);
4897 }
4898 [] SGsAP.receive {
4899 setverdict(fail, "Received unexpected message on SGs");
4900 }
4901 }
4902
Philipp Maier34218102019-09-24 09:15:49 +02004903 /* While we are doing nothing, expect an SGsAP-SERVICE-ABORT-REQUEST
4904 * after some time */
4905 timer T := 10.0;
4906 T.start
4907 alt {
4908 [] SGsAP.receive(exp_serv_abrt)
4909 {
4910 setverdict(pass);
4911 }
4912 [] SGsAP.receive {
4913 setverdict(fail, "unexpected SGsAP message received");
4914 self.stop;
4915 }
4916 [] T.timeout {
4917 setverdict(fail, "MSC did not send SGsAP-SERVICE-ABORT-REQUEST");
4918 self.stop;
4919 }
4920 }
4921
4922 /* The SGs association must remain unchanged. */
Harald Welte4263c522018-12-06 11:56:27 +01004923 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4924
4925 f_sgsap_bssmap_screening();
4926
4927 setverdict(pass);
4928}
4929testcase TC_sgsap_paging_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004930 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004931 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004932 f_init(1, true);
4933 pars := f_init_pars(11819, true);
4934 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004935 vc_conn.done;
4936}
4937
4938/* Trigger a paging request via VTY and slip in an LU */
4939private function f_tc_sgsap_paging_and_lu(charstring id, BSC_ConnHdlrPars pars)
4940runs on BSC_ConnHdlr {
4941 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4942 f_init_handler(pars);
4943
4944 /* First we prepar the situation, where the SGs association is in state
4945 * NULL and the confirmed by radio contact indicator is set to false
4946 * as well. This can be archived by performing an SGs LU and then
4947 * resetting the VLR */
4948 f_sgs_perform_lu();
4949 f_sgsap_reset_mme(mp_mme_name);
4950 f_sleep(1.0);
4951 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4952
4953 /* Perform a paging, expect the paging messages on the SGs interface */
4954 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4955 alt {
4956 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
4957 setverdict(pass);
4958 }
4959 [] SGsAP.receive {
4960 setverdict(fail, "Received unexpected message on SGs");
4961 }
4962 }
4963
4964 /* Perform the LU as normal */
4965 f_sgs_perform_lu();
4966 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4967
4968 /* Expect a new paging request right after the LU */
4969 alt {
4970 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
4971 setverdict(pass);
4972 }
4973 [] SGsAP.receive {
4974 setverdict(fail, "Received unexpected message on SGs");
4975 }
4976 }
4977
4978 /* Test is done now, lets round everything up by rejecting the paging
4979 * cleanly. */
4980 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, user_rejected_mobile_terminating_CS_fallback_call));
4981 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4982
4983 f_sgsap_bssmap_screening();
4984
4985 setverdict(pass);
4986}
4987testcase TC_sgsap_paging_and_lu() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004988 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004989 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004990 f_init(1, true);
4991 pars := f_init_pars(11820, true);
4992 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_and_lu), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004993 vc_conn.done;
4994}
4995
4996/* Send unexpected unit-data through the SGs interface */
4997private function f_tc_sgsap_unexp_ud(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4998 f_init_handler(pars);
4999 f_sleep(1.0);
5000
5001 /* This simulates what happens when a subscriber without SGs
5002 * association gets unitdata via the SGs interface. */
5003
5004 /* Make sure the subscriber exists and the SGs association
5005 * is in NULL state */
5006 f_perform_lu();
5007 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
5008
5009 /* Send some random unit data, the MSC/VLR should send a release
5010 * immediately. */
5011 SGsAP.send(ts_SGsAP_UL_UD(pars.imsi,'1234'O));
5012 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, IMSI_detached_for_EPS_nonEPS_services));
5013
5014 f_sgsap_bssmap_screening();
5015
5016 setverdict(pass);
5017}
5018testcase TC_sgsap_unexp_ud() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005019 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005020 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005021 f_init(1, true);
5022 pars := f_init_pars(11821, true);
5023 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_unexp_ud), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005024 vc_conn.done;
5025}
5026
5027/* Send unsolicited unit-data through the SGs interface */
5028private function f_tc_sgsap_unsol_ud(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5029 f_init_handler(pars);
5030 f_sleep(1.0);
5031
5032 /* This simulates what happens when the MME attempts to send unitdata
5033 * to a subscriber that is completely unknown to the VLR */
5034
5035 /* Send some random unit data, the MSC/VLR should send a release
5036 * immediately. */
5037 SGsAP.send(ts_SGsAP_UL_UD(pars.imsi,'1234'O));
5038 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, IMSI_unknown));
5039
5040 f_sgsap_bssmap_screening();
5041
Harald Welte4d15fa72020-08-19 08:58:28 +02005042 /* clean-up VLR state about this subscriber */
5043 f_imsi_detach_by_imsi();
5044
Harald Welte4263c522018-12-06 11:56:27 +01005045 setverdict(pass);
5046}
5047testcase TC_sgsap_unsol_ud() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005048 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005049 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005050 f_init(1, true);
5051 pars := f_init_pars(11822, true);
5052 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_unsol_ud), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005053 vc_conn.done;
5054}
5055
5056private altstep as_other_sms_sgs() runs on BSC_ConnHdlr {
5057 /* FIXME: Match an actual payload (second questionmark), the type is
5058 * octetstring, how do we use a tr_PDU_DTAP_MT here? */
5059 [] SGsAP.receive(tr_SGsAP_DL_UD(?,?)) {
5060 setverdict(fail, "Unexpected SMS related PDU from MSC");
5061 mtc.stop;
5062 }
5063}
5064
5065/* receive a MT-SMS delivered from the MSC/SMSC over an already existing SGsAP connection */
5066function f_mt_sms_sgs(inout SmsParameters spars)
5067runs on BSC_ConnHdlr {
5068 var template (value) TPDU_RP_DATA_MS_SGSN tp_mo;
5069 var template (value) RPDU_MS_SGSN rp_mo;
5070 var template (value) PDU_ML3_MS_NW l3_mo;
5071
5072 var template TPDU_RP_DATA_SGSN_MS tp_mt;
5073 var template RPDU_SGSN_MS rp_mt;
5074 var template PDU_ML3_NW_MS l3_mt;
5075
5076 var PDU_ML3_NW_MS sgsap_l3_mt;
5077
5078 var default d := activate(as_other_sms_sgs());
5079
5080 /* Expect CP-DATA(RP-DATA(SMS-DELIVER)) */
5081 tp_mt := tr_SMS_DELIVER(?, spars.tp.ud, spars.tp.pid, spars.tp.dcs, ?);
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09005082 rp_mt := tr_RP_DATA_MT(?, spars.rp.smsc_addr, omit, tp_mt);
Harald Welte4263c522018-12-06 11:56:27 +01005083 l3_mt := tr_ML3_MT_SMS(?, c_TIF_ORIG, tr_CP_DATA_MT(rp_mt));
5084
5085 SGsAP.receive(l3_mt) -> value sgsap_l3_mt;
5086
5087 /* Extract relevant identifiers */
5088 spars.tid := bit2int(sgsap_l3_mt.tiOrSkip.transactionId.tio);
5089 spars.rp.msg_ref := sgsap_l3_mt.msgs.sms.cP_DATA.cP_User_Data.cP_RPDU.rP_DATA_SGSN_MS.rP_MessageReference;
5090
5091 /* send CP-ACK for CP-DATA just received */
5092 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_REPL, ts_CP_ACK_MO);
5093
5094 SGsAP.send(l3_mo);
5095
5096 /* send RP-ACK for RP-DATA */
5097 rp_mo := ts_RP_ACK_MO(spars.rp.msg_ref);
5098 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_REPL, ts_CP_DATA_MO(rp_mo));
5099
5100 SGsAP.send(l3_mo);
5101
5102 /* expect CP-ACK for CP-DATA(RP-ACK) just sent */
5103 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_ORIG, tr_CP_ACK_MT);
5104
5105 SGsAP.receive(l3_mt);
5106
5107 deactivate(d);
5108
5109 setverdict(pass);
5110}
5111
5112/* submit a MO-SMS to MSC/SMSC over an already existing SGsAP connection */
5113function f_mo_sms_sgs(inout SmsParameters spars)
5114runs on BSC_ConnHdlr {
5115 var template (value) TPDU_RP_DATA_MS_SGSN tp_mo;
5116 var template (value) RPDU_MS_SGSN rp_mo;
5117 var template (value) PDU_ML3_MS_NW l3_mo;
5118
5119 var template TPDU_RP_DATA_SGSN_MS tp_mt;
5120 var template RPDU_SGSN_MS rp_mt;
5121 var template PDU_ML3_NW_MS l3_mt;
5122
5123 var default d := activate(as_other_sms_sgs());
5124
5125 /* just in case this is routed to SMPP.. */
5126 f_create_smpp_expect(hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue));
5127
5128 tp_mo := ts_SMS_SUBMIT(spars.tp.msg_ref, spars.tp.da, spars.tp.pid, spars.tp.dcs,
5129 spars.tp.udl, spars.tp.ud);
Vadim Yanitskiy437b5a62019-12-15 14:13:39 +09005130 rp_mo := ts_RP_DATA_MO(spars.rp.msg_ref, omit, spars.rp.smsc_addr, tp_mo);
Harald Welte4263c522018-12-06 11:56:27 +01005131 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_DATA_MO(rp_mo));
5132
5133 SGsAP.send(l3_mo);
5134
5135 /* receive CP-ACK for CP-DATA above */
5136 SGsAP.receive(tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_ACK_MT));
5137
5138 if (ispresent(spars.exp_rp_err)) {
5139 /* expect an RP-ERROR message from MSC with given cause */
5140 rp_mt := tr_RP_ERROR_MT(spars.rp.msg_ref, spars.exp_rp_err);
5141 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_DATA_MT(rp_mt));
5142 SGsAP.receive(l3_mt);
5143 /* send CP-ACK for CP-DATA just received */
5144 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_ACK_MO);
5145 SGsAP.send(l3_mo);
5146 } else {
5147 /* expect RP-ACK for RP-DATA */
5148 rp_mt := tr_RP_ACK_MT(spars.rp.msg_ref);
5149 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_DATA_MT(rp_mt));
5150 SGsAP.receive(l3_mt);
5151 /* send CP-ACO for CP-DATA just received */
5152 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_ACK_MO);
5153 SGsAP.send(l3_mo);
5154 }
5155
5156 deactivate(d);
5157
5158 setverdict(pass);
5159}
5160
5161private function f_vty_sms_send_conn_hdlr(charstring imsi, charstring msisdn, charstring text)
5162runs on BSC_ConnHdlr {
5163 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
5164}
5165
5166/* Send a MT SMS via SGs interface */
5167private function f_tc_sgsap_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5168 f_init_handler(pars);
5169 f_sgs_perform_lu();
5170 f_sleep(1.0);
5171 var SmsParameters spars := valueof(t_SmsPars);
5172 spars.tp.ud := 'C8329BFD064D9B53'O;
5173
5174 /* Trigger SMS via VTY */
5175 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
5176 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5177
5178 /* Expect a paging request and respond accordingly with a service request */
5179 SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, SMS_indicator, omit));
5180 SGsAP.send(ts_SGsAP_SERVICE_REQ(pars.imsi, SMS_indicator, EMM_CONNECTED));
5181
5182 /* Connection is now live, receive the MT-SMS */
5183 f_mt_sms_sgs(spars);
5184
5185 /* Expect a concluding release from the MSC */
5186 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, omit));
5187
5188 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
5189 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5190
5191 f_sgsap_bssmap_screening();
5192
5193 setverdict(pass);
5194}
5195testcase TC_sgsap_mt_sms() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005196 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005197 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005198 f_init(1, true);
5199 pars := f_init_pars(11823, true);
5200 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005201 vc_conn.done;
5202}
5203
5204/* Send a MO SMS via SGs interface */
5205private function f_tc_sgsap_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5206 f_init_handler(pars);
5207 f_sgs_perform_lu();
5208 f_sleep(1.0);
5209 var SmsParameters spars := valueof(t_SmsPars);
5210 spars.tp.ud := 'C8329BFD064D9B53'O;
5211
5212 /* Send the MO-SMS */
5213 f_mo_sms_sgs(spars);
5214
5215 /* Expect a concluding release from the MSC/VLR */
5216 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, omit));
5217
5218 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
5219 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5220
5221 setverdict(pass);
5222
5223 f_sgsap_bssmap_screening()
5224}
5225testcase TC_sgsap_mo_sms() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005226 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005227 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005228 f_init(1, true);
5229 pars := f_init_pars(11824, true);
5230 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mo_sms), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005231 vc_conn.done;
5232}
5233
5234/* Trigger sending of an MT sms via VTY but never respond to anything */
5235private function f_tc_sgsap_mt_sms_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5236 f_init_handler(pars, 170.0);
5237 f_sgs_perform_lu();
5238 f_sleep(1.0);
5239
5240 var SmsParameters spars := valueof(t_SmsPars);
5241 spars.tp.ud := 'C8329BFD064D9B53'O;
5242 var integer page_count := 0;
5243 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5244 var template PDU_SGsAP exp_pag_req := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, SMS_indicator, omit);
5245 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
5246 exp_pag_req.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
5247
5248 /* Trigger SMS via VTY */
5249 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
5250
Neels Hofmeyr16237742019-03-06 15:34:01 +01005251 /* Expect the MSC/VLR to page exactly once */
5252 SGsAP.receive(exp_pag_req);
Harald Welte4263c522018-12-06 11:56:27 +01005253
5254 /* Wait some time to make sure the MSC is not delivering any further
5255 * paging messages or anything else that could be unexpected. */
5256 timer T := 20.0;
5257 T.start
5258 alt {
5259 [] SGsAP.receive(exp_pag_req)
5260 {
5261 setverdict(fail, "paging seems not to stop!");
5262 mtc.stop;
5263 }
5264 [] SGsAP.receive {
5265 setverdict(fail, "unexpected SGsAP message received");
5266 self.stop;
5267 }
5268 [] T.timeout {
5269 setverdict(pass);
5270 }
5271 }
5272
5273 /* Even on a failed paging the SGs Association should stay intact */
5274 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5275
Philipp Maier26bdb8c2019-09-24 09:21:12 +02005276 /* Make sure that the SMS we just inserted is cleared and the
5277 * subscriber is expired. This is necessary because otherwise the MSC
5278 * might re-try the SMS delivery and disturb the following tests. */
Harald Welte4263c522018-12-06 11:56:27 +01005279
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01005280 f_vty_sms_clear(hex2str(g_pars.imsi));
5281
Harald Welte4263c522018-12-06 11:56:27 +01005282 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " expire");
5283
5284 setverdict(pass);
Neels Hofmeyrb0f82342019-03-06 15:36:51 +01005285
5286 f_sgsap_bssmap_screening();
Harald Welte4263c522018-12-06 11:56:27 +01005287}
5288testcase TC_sgsap_mt_sms_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005289 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005290 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005291 f_init(1, true);
5292 pars := f_init_pars(11825, true);
5293 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005294 vc_conn.done;
5295}
5296
5297/* Trigger sending of an MT sms via VTY but reject the paging immediately */
5298private function f_tc_sgsap_mt_sms_and_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5299 f_init_handler(pars, 150.0);
5300 f_sgs_perform_lu();
5301 f_sleep(1.0);
5302
5303 var SmsParameters spars := valueof(t_SmsPars);
5304 spars.tp.ud := 'C8329BFD064D9B53'O;
5305 var integer page_count := 0;
5306 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5307 var template PDU_SGsAP exp_pag_req := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, SMS_indicator, omit);
5308 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
5309 exp_pag_req.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
5310
5311 /* Trigger SMS via VTY */
5312 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
5313
5314 /* Expect a paging request and reject it immediately */
5315 SGsAP.receive(exp_pag_req);
5316 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, IMSI_unknown));
5317
5318 /* The MSC/VLR should no longer try to page once the paging has been
5319 * rejected. Wait some time and check if there are no unexpected
5320 * messages on the SGs interface. */
5321 timer T := 20.0;
5322 T.start
5323 alt {
5324 [] SGsAP.receive(exp_pag_req)
5325 {
5326 setverdict(fail, "paging seems not to stop!");
5327 mtc.stop;
5328 }
5329 [] SGsAP.receive {
5330 setverdict(fail, "unexpected SGsAP message received");
5331 self.stop;
5332 }
5333 [] T.timeout {
5334 setverdict(pass);
5335 }
5336 }
5337
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01005338 f_vty_sms_clear(hex2str(g_pars.imsi));
5339
Harald Welte4263c522018-12-06 11:56:27 +01005340 /* A rejected paging with IMSI_unknown (see above) should always send
5341 * the SGs association to NULL. */
5342 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
5343
5344 f_sgsap_bssmap_screening();
5345
Harald Welte4263c522018-12-06 11:56:27 +01005346 setverdict(pass);
5347}
5348testcase TC_sgsap_mt_sms_and_reject() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005349 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005350 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005351 f_init(1, true);
5352 pars := f_init_pars(11826, true);
5353 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms_and_reject), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005354 vc_conn.done;
5355}
5356
5357/* Perform an MT CSDB call including LU */
5358private function f_mt_lu_and_csfb_call(charstring id, BSC_ConnHdlrPars pars, boolean bssmap_lu) runs on BSC_ConnHdlr {
5359 f_init_handler(pars);
5360
5361 /* Be sure that the BSSMAP reset is done before we begin. */
5362 f_sleep(2.0);
5363
5364 /* Testcase variation: See what happens when we do a regular BSSMAP
5365 * LU first (this should not hurt in any way!) */
5366 if (bssmap_lu) {
5367 f_perform_lu();
5368 }
5369
5370 f_sgs_perform_lu();
5371 f_sleep(1.0);
5372
5373 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5374 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Harald Welte4263c522018-12-06 11:56:27 +01005375
5376 /* Initiate a call via MNCC interface */
5377 f_mt_call_initate(cpars);
5378
5379 /* Expect a paging request and respond accordingly with a service request */
5380 SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit));
5381 SGsAP.send(ts_SGsAP_SERVICE_REQ(pars.imsi, CS_call_indicator, EMM_CONNECTED));
5382
5383 /* Complete the call, hold it for some time and then tear it down */
5384 f_mt_call_complete(cpars);
5385 f_sleep(3.0);
Harald Welte4c422b72019-02-17 16:27:10 +01005386 f_call_hangup(cpars, true, is_csfb := true);
Harald Welte4263c522018-12-06 11:56:27 +01005387
5388 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
5389 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5390
Harald Welte4263c522018-12-06 11:56:27 +01005391 /* Test for successful return by triggering a paging, when the paging
5392 * request is received via SGs, we can be sure that the MSC/VLR has
5393 * recognized that the UE is now back on 4G */
5394 f_sleep(1.0);
5395 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
5396 alt {
5397 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
5398 setverdict(pass);
5399 }
5400 [] SGsAP.receive {
5401 setverdict(fail, "Received unexpected message on SGs");
5402 }
5403 }
5404
5405 f_sgsap_bssmap_screening();
5406
5407 setverdict(pass);
5408}
5409
5410/* Perform a regular BSSAP LU first, do a SGSAP LU and then make a CSFB call */
5411private function f_tc_bssap_lu_sgsap_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5412 f_mt_lu_and_csfb_call(id, pars, true);
5413}
5414testcase TC_bssap_lu_sgsap_lu_and_mt_call() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005415 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005416 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005417 f_init(1, true);
5418 pars := f_init_pars(118139, true);
Harald Welte4263c522018-12-06 11:56:27 +01005419
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005420 vc_conn := f_start_handler_with_pars(refers(f_tc_bssap_lu_sgsap_lu_and_mt_call), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005421 vc_conn.done;
5422}
5423
Harald Welte4263c522018-12-06 11:56:27 +01005424/* Perform a SGSAP LU and then make a CSFB call */
5425private function f_tc_sgsap_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5426 f_mt_lu_and_csfb_call(id, pars, false);
5427}
5428testcase TC_sgsap_lu_and_mt_call() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005429 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005430 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005431 f_init(1, true);
5432 pars := f_init_pars(11827, true);
Harald Welte4263c522018-12-06 11:56:27 +01005433
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005434 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_and_mt_call), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005435 vc_conn.done;
5436}
5437
Philipp Maier628c0052019-04-09 17:36:57 +02005438/* Simulate an HLR/VLR failure */
5439private function f_tc_sgsap_vlr_failure(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5440 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
5441 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5442
5443 var PDU_SGsAP lur;
5444
5445 f_init_handler(pars);
5446
5447 /* Attempt location update (which is expected to fail) */
5448 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
5449 ts_SGsAP_LAI('901'H, '70'H, 2342)));
5450 SGsAP.send(lur);
5451
5452 /* Respond to SGsAP-RESET-INDICATION from VLR */
5453 alt {
5454 [] SGsAP.receive(tr_SGsAP_RESET_IND_VLR(vlr_name)); {
5455 SGsAP.send(valueof(ts_SGsAP_RESET_ACK_MME(mme_name)));
5456 setverdict(pass);
5457 }
5458 [] SGsAP.receive {
5459 setverdict(fail, "Received unexpected message on SGs");
5460 }
5461 }
5462
5463 f_sleep(1.0);
5464 setverdict(pass);
5465}
5466testcase TC_sgsap_vlr_failure() runs on MTC_CT {
5467 var BSC_ConnHdlrPars pars;
5468 var BSC_ConnHdlr vc_conn;
5469 f_init(1, true, false);
5470 pars := f_init_pars(11811, true, false);
5471 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_vlr_failure), pars);
5472 vc_conn.done;
5473}
5474
Harald Welte4263c522018-12-06 11:56:27 +01005475/* SGs TODO:
5476 * LU attempt for IMSI without NAM_PS in HLR
5477 * LU attempt with AUTH FAIL due to invalid RES/SRES
5478 * LU attempt with no response from HLR (VLR should timeout + LU REJ)
5479 * LU attempt with new TMSI but without TMSI REALL CMPL baco to VLR
5480 * implicit IMSI detach from EPS
5481 * implicit IMSI detach from non-EPS
5482 * MM INFO
5483 *
5484 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01005485
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005486private function f_tc_ho_inter_bsc_unknown_cell(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5487 f_init_handler(pars);
5488 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005489
5490 f_perform_lu();
5491 f_mo_call_establish(cpars);
5492
5493 f_sleep(1.0);
5494
5495 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5496 var BssmapCause cause := enum2int(cause_val);
5497
5498 var template BSSMAP_FIELD_CellIdentificationList cil;
5499 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('023'H, '42'H, 999) } };
5500
5501 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5502 BSSAP.receive(tr_BSSMAP_HandoverRequiredReject);
5503
5504 f_call_hangup(cpars, true);
5505}
5506testcase TC_ho_inter_bsc_unknown_cell() runs on MTC_CT {
5507 var BSC_ConnHdlr vc_conn;
5508 f_init();
5509
5510 vc_conn := f_start_handler(refers(f_tc_ho_inter_bsc_unknown_cell), 53);
5511 vc_conn.done;
5512}
5513
5514private altstep as_mgcp_ack_all_mdcx(CallParameters cpars) runs on BSC_ConnHdlr {
5515 var MgcpCommand mgcp_cmd;
5516 [] MGCP.receive(tr_MDCX) -> value mgcp_cmd {
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02005517 var SDP_Message sdp := valueof(ts_SDP(cpars.mgw_conn_2.mgw_rtp_ip, cpars.mgw_conn_2.mgw_rtp_ip,
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005518 hex2str(cpars.mgcp_call_id), "42",
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02005519 cpars.mgw_conn_2.mgw_rtp_port,
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005520 { int2str(cpars.rtp_payload_type) },
5521 { valueof(ts_SDP_rtpmap(cpars.rtp_payload_type,
5522 cpars.rtp_sdp_format)),
5523 valueof(ts_SDP_ptime(20)) }));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02005524 MGCP.send(ts_MDCX_ACK(mgcp_cmd.line.trans_id, cpars.mgw_conn_2.mgcp_connection_id, sdp));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005525 repeat;
5526 }
5527}
5528
5529private function f_tc_ho_inter_bsc0(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005530 var CallParameters cpars;
5531
5532 cpars := valueof(t_CallParams('12345'H, 0));
5533 if (pars.use_ipv6) {
5534 cpars.mgw_conn_1.mgw_rtp_ip := "::1";
5535 cpars.mgw_conn_2.mgw_rtp_ip := "::2";
5536 cpars.bss_rtp_ip := "::3";
5537 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005538
5539 f_init_handler(pars);
5540
5541 f_vty_transceive(MSCVTY, "configure terminal");
5542 f_vty_transceive(MSCVTY, "msc");
5543 f_vty_transceive(MSCVTY, "neighbor a cgi 262 42 23 42 ran-pc 0.24.1");
5544 f_vty_transceive(MSCVTY, "neighbor a lac 5 ran-pc 0.24.2");
5545 f_vty_transceive(MSCVTY, "exit");
5546 f_vty_transceive(MSCVTY, "exit");
5547
5548 f_perform_lu();
5549 f_mo_call_establish(cpars);
5550
5551 f_sleep(1.0);
5552
5553 var default ack_mdcx := activate(as_mgcp_ack_all_mdcx(cpars));
5554
5555 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5556 var BssmapCause cause := enum2int(cause_val);
5557
5558 var template BSSMAP_FIELD_CellIdentificationList cil;
5559 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('023'H, '42'H, 5) } };
5560
5561 /* old BSS sends Handover Required */
5562 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5563
5564 /* Now the action goes on in f_tc_ho_inter_bsc1() */
5565
5566 /* MSC forwards the RR Handover Command to old BSS */
5567 var PDU_BSSAP ho_command;
5568 BSSAP.receive(tr_BSSMAP_HandoverCommand) -> value ho_command;
5569
5570 log("GOT HandoverCommand", ho_command);
5571
5572 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
5573
5574 /* f_tc_ho_inter_bsc1() completes Handover, then expecting a Clear here. */
5575 f_expect_clear();
5576
5577 log("FIRST inter-BSC Handover done");
5578
5579
5580 /* ------------------------ */
5581
5582 /* Ok, that went well, now the other BSC is handovering back here --
5583 * from now on this here is the new BSS. */
5584 f_create_bssmap_exp_handoverRequest(193);
5585
5586 var PDU_BSSAP ho_request;
5587 BSSAP.receive(tr_BSSMAP_HandoverRequest) -> value ho_request;
5588
5589 /* new BSS composes a RR Handover Command */
5590 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5591 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005592 var BSSMAP_IE_AoIP_TransportLayerAddress tla tla :=
5593 valueof(f_ts_BSSMAP_IE_AoIP_TLA(cpars.bss_rtp_ip, cpars.bss_rtp_port));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005594 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5595 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5596
5597 /* Now f_tc_ho_inter_bsc1() expects HandoverCommand */
5598
5599 f_sleep(0.5);
5600
5601 /* Notify that the MS is now over here */
5602
5603 BSSAP.send(ts_BSSMAP_HandoverDetect);
5604 f_sleep(0.1);
5605 BSSAP.send(ts_BSSMAP_HandoverComplete);
5606
5607 f_sleep(3.0);
5608
5609 deactivate(ack_mdcx);
5610
5611 var default ccrel := activate(as_optional_cc_rel(cpars, true));
5612
5613 /* blatant cheating */
5614 var N_Sd_Array last_n_sd := f_bssmap_last_n_sd();
5615 last_n_sd[0] := 3;
5616 f_bssmap_continue_after_n_sd(last_n_sd);
5617
5618 f_call_hangup(cpars, true);
5619 f_sleep(1.0);
5620 deactivate(ccrel);
5621
5622 setverdict(pass);
5623}
5624private function f_tc_ho_inter_bsc1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005625 var charstring bss_rtp_ip;
5626 if (pars.use_ipv6) {
5627 bss_rtp_ip := "::8";
5628 } else {
5629 bss_rtp_ip := "1.2.3.4";
5630 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005631 f_init_handler(pars);
5632 f_create_bssmap_exp_handoverRequest(194);
5633
5634 var PDU_BSSAP ho_request;
5635 BSSAP.receive(tr_BSSMAP_HandoverRequest) -> value ho_request;
5636
5637 /* new BSS composes a RR Handover Command */
5638 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5639 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005640 var BSSMAP_IE_AoIP_TransportLayerAddress tla :=
5641 valueof(f_ts_BSSMAP_IE_AoIP_TLA(bss_rtp_ip, 2342));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005642 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5643 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5644
5645 /* Now f_tc_ho_inter_bsc0() expects HandoverCommand */
5646
5647 f_sleep(0.5);
5648
5649 /* Notify that the MS is now over here */
5650
5651 BSSAP.send(ts_BSSMAP_HandoverDetect);
5652 f_sleep(0.1);
5653 BSSAP.send(ts_BSSMAP_HandoverComplete);
5654
5655 f_sleep(3.0);
5656
5657 /* Now I'd like to f_call_hangup() but we don't know any cpars here. So
5658 * ... handover back to the first BSC :P */
5659
5660 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5661 var BssmapCause cause := enum2int(cause_val);
5662
5663 var template BSSMAP_FIELD_CellIdentificationList cil;
5664 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('262'H, '42'H, 23) } };
5665
5666 /* old BSS sends Handover Required */
5667 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5668
5669 /* Now the action goes on in f_tc_ho_inter_bsc0() */
5670
5671 /* MSC forwards the RR Handover Command to old BSS */
5672 var PDU_BSSAP ho_command;
5673 BSSAP.receive(tr_BSSMAP_HandoverCommand) -> value ho_command;
5674
5675 log("GOT HandoverCommand", ho_command);
5676
5677 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
5678
5679 /* f_tc_ho_inter_bsc1() completes Handover, then expecting a Clear here. */
5680 f_expect_clear();
5681 setverdict(pass);
5682}
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005683function f_tc_ho_inter_bsc_main(boolean use_ipv6 := false) runs on MTC_CT {
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005684 var BSC_ConnHdlr vc_conn0;
5685 var BSC_ConnHdlr vc_conn1;
5686 f_init(2);
5687
5688 var BSC_ConnHdlrPars pars0 := f_init_pars(53);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005689 pars0.use_ipv6 := use_ipv6;
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005690 var BSC_ConnHdlrPars pars1 := f_init_pars(53);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005691 pars1.use_ipv6 := use_ipv6;
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005692
5693 vc_conn0 := f_start_handler_with_pars(refers(f_tc_ho_inter_bsc0), pars0, 0);
5694 vc_conn1 := f_start_handler_with_pars(refers(f_tc_ho_inter_bsc1), pars1, 1);
5695 vc_conn0.done;
5696 vc_conn1.done;
5697}
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005698testcase TC_ho_inter_bsc() runs on MTC_CT {
5699 f_tc_ho_inter_bsc_main(false);
5700}
5701testcase TC_ho_inter_bsc_ipv6() runs on MTC_CT {
5702 f_tc_ho_inter_bsc_main(true);
5703}
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005704
5705function f_ML3_patch_seq_nr_MS_NW(in uint2_t seq_nr, inout octetstring enc_l3) {
5706 log("MS_NW patching N(SD)=", seq_nr, " into dtap ", enc_l3);
5707 enc_l3[2] := (enc_l3[2] and4b '3f'O) or4b bit2oct(int2bit(seq_nr, 8) << 6);
5708 log("MS_NW patched enc_l3: ", enc_l3);
5709}
5710
5711private function f_tc_ho_inter_msc_out(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005712 var CallParameters cpars;
5713
5714 cpars := valueof(t_CallParams('12345'H, 0));
5715 if (pars.use_ipv6) {
5716 cpars.mgw_conn_1.mgw_rtp_ip := "::1";
5717 cpars.mgw_conn_2.mgw_rtp_ip := "::2";
5718 cpars.bss_rtp_ip := "::3";
5719 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005720 var hexstring ho_number := f_gen_msisdn(99999);
5721
5722 f_init_handler(pars);
5723
5724 f_create_mncc_expect(hex2str(ho_number));
5725
5726 f_vty_transceive(MSCVTY, "configure terminal");
5727 f_vty_transceive(MSCVTY, "msc");
5728 f_vty_transceive(MSCVTY, "neighbor a cgi 017 017 1 1 msc-ipa-name msc-017-017-1");
5729 f_vty_transceive(MSCVTY, "exit");
5730 f_vty_transceive(MSCVTY, "exit");
5731
5732 f_perform_lu();
5733 f_mo_call_establish(cpars);
5734
5735 f_sleep(1.0);
5736
5737 var default ack_mdcx := activate(as_mgcp_ack_all_mdcx(cpars));
5738
5739 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5740 var BssmapCause cause := enum2int(cause_val);
5741
5742 var template BSSMAP_FIELD_CellIdentificationList cil;
5743 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('017'H, '017'H, 1) } };
5744
5745 /* old BSS sends Handover Required */
5746 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5747
5748 /* The target cell 017-017 LAC 1 is configured to be a remote MSC of name "msc-017-017-1".
5749 * This MSC tries to reach the other MSC via GSUP. */
5750
5751 var octetstring remote_msc_name := '6D73632D3031372D3031372D3100'O; /* "msc-017-017-1\0" as octetstring */
5752 var GSUP_PDU prep_ho_req;
5753 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_HANDOVER_REQUEST,
5754 pars.imsi, destination_name := remote_msc_name)) -> value prep_ho_req;
5755
5756 var GSUP_IeValue source_name_ie;
5757 f_gsup_find_ie(prep_ho_req, OSMO_GSUP_SOURCE_NAME_IE, source_name_ie);
5758 var octetstring local_msc_name := source_name_ie.source_name;
5759
5760 /* Remote MSC has figured out its BSC and signals success */
5761 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5762 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
5763 var PDU_BSSAP ho_req_ack := valueof(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5764 aoIPTransportLayer := omit,
5765 speechCodec := ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5766 GSUP.send(ts_GSUP_E_PrepareHandoverResult(
5767 pars.imsi,
5768 ho_number,
5769 remote_msc_name, local_msc_name,
5770 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006, enc_PDU_BSSAP(ho_req_ack)))));
5771
5772 /* MSC forwards the RR Handover Command to old BSS */
5773 BSSAP.receive(tr_BSSMAP_HandoverCommand);
5774
5775 /* The MS shows up at remote new BSS */
5776
5777 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PROCESS_ACCESS_SIGNALLING_REQUEST,
5778 pars.imsi, remote_msc_name, local_msc_name,
5779 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5780 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverDetect))))));
5781 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
5782 f_sleep(0.1);
5783
5784 /* Save the MS sequence counters for use on the other connection */
5785 var N_Sd_Array last_n_sd := f_bssmap_last_n_sd();
5786
5787 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_SEND_END_SIGNAL_REQUEST,
5788 pars.imsi, remote_msc_name, local_msc_name,
5789 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5790 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverComplete))))));
5791
5792 /* The local BSS conn clears, all communication goes via remote MSC now */
5793 f_expect_clear();
5794
5795 /**********************************/
5796 /* Play through some signalling across the inter-MSC link.
5797 * This is a copy of f_tc_lu_and_mo_ussd_single_request() translated into GSUP AN-APDUs. */
5798
5799 if (false) {
5800 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
5801 invoke_id := 5, /* Phone may not start from 0 or 1 */
5802 op_code := SS_OP_CODE_PROCESS_USS_REQ,
5803 ussd_string := "*#100#"
5804 );
5805
5806 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
5807 invoke_id := 5, /* InvokeID shall be the same for both REQ and RSP */
5808 op_code := SS_OP_CODE_PROCESS_USS_REQ,
5809 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
5810 )
5811
5812 /* Compose a new SS/REGISTER message with request */
5813 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
5814 tid := 1, /* We just need a single transaction */
5815 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
5816 facility := valueof(facility_req)
5817 );
5818 var PDU_ML3_MS_NW ussd_req_v := valueof(ussd_req);
5819
5820 /* Compose SS/RELEASE_COMPLETE template with expected response */
5821 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
5822 tid := 1, /* Response should arrive within the same transaction */
5823 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
5824 facility := valueof(facility_rsp)
5825 );
5826
5827 /* Compose expected MSC -> HLR message */
5828 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
5829 imsi := g_pars.imsi,
5830 state := OSMO_GSUP_SESSION_STATE_BEGIN,
5831 ss := valueof(facility_req)
5832 );
5833
5834 /* To be used for sending response with correct session ID */
5835 var GSUP_PDU gsup_req_complete;
5836
5837 /* Request own number */
5838 /* From remote MSC instead of BSSAP directly */
5839 /* Patch the correct N_SD value into the message. */
5840 var octetstring l3_enc := enc_PDU_ML3_MS_NW(ussd_req_v);
5841 var RAN_Emulation.ConnectionData cd;
5842 f_ML3_patch_seq_nr_MS_NW(f_next_n_sd(last_n_sd, f_ML3_n_sd_idx(ussd_req_v)), l3_enc);
5843 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PROCESS_ACCESS_SIGNALLING_REQUEST,
5844 pars.imsi, remote_msc_name, local_msc_name,
5845 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5846 enc_PDU_BSSAP(valueof(ts_BSSAP_DTAP(l3_enc)))
5847 ))
5848 ));
5849
5850 /* Expect GSUP message containing the SS payload */
5851 gsup_req_complete := f_expect_gsup_msg(gsup_req);
5852
5853 /* Compose the response from HLR using received session ID */
5854 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
5855 imsi := g_pars.imsi,
5856 sid := gsup_req_complete.ies[1].val.session_id,
5857 state := OSMO_GSUP_SESSION_STATE_END,
5858 ss := valueof(facility_rsp)
5859 );
5860
5861 /* Finally, HLR terminates the session */
5862 GSUP.send(gsup_rsp);
5863
5864 /* The USSD response goes out to remote MSC, on GSUP E instead of BSSAP */
5865 var GSUP_PDU gsup_ussd_rsp;
5866 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_FORWARD_ACCESS_SIGNALLING_REQUEST,
5867 pars.imsi, destination_name := remote_msc_name)) -> value gsup_ussd_rsp;
5868
5869 var GSUP_IeValue an_apdu;
5870 if (not f_gsup_find_ie(gsup_ussd_rsp, OSMO_GSUP_AN_APDU_IE, an_apdu)) {
5871 setverdict(fail, "No AN-APDU in received GSUP message. Expected USSD response in DTAP, got", gsup_ussd_rsp);
5872 mtc.stop;
5873 }
5874 var PDU_BSSAP bssap_dtap_mt := dec_PDU_BSSAP(an_apdu.an_apdu.pdu);
5875 var PDU_ML3_NW_MS dtap_mt := dec_PDU_ML3_NW_MS(bssap_dtap_mt.pdu.dtap);
5876 log("Expecting", ussd_rsp);
5877 log("Got", dtap_mt);
5878 if (not match(dtap_mt, ussd_rsp)) {
5879 setverdict(fail, "Unexpected GSUP message. Expected USSD response in DTAP, got", gsup_ussd_rsp);
5880 mtc.stop;
5881 }
5882 }
5883 /**********************************/
5884
5885
5886 /* inter-MSC handover back to the first MSC */
5887 f_create_bssmap_exp_handoverRequest(193);
5888 cil := { cIl_CGI := { ts_BSSMAP_CI_CGI('262'H, '42'H, 23, 42) } };
5889
5890 /* old BSS sends Handover Required, via inter-MSC E link: like
5891 * BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5892 * but via GSUP */
5893 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_SUBSEQUENT_HANDOVER_REQUEST,
5894 pars.imsi, remote_msc_name, local_msc_name,
5895 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5896 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverRequired(cause, cil)))
5897 ))
5898 ));
5899
5900 /* MSC asks local BSS to prepare Handover to it */
5901 BSSAP.receive(tr_BSSMAP_HandoverRequest);
5902
5903 /* Make sure the new BSSAP conn continues with the correct N_SD sequence numbers */
5904 f_bssmap_continue_after_n_sd(last_n_sd);
5905
5906 /* new BSS composes a RR Handover Command */
5907 rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5908 rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005909 var BSSMAP_IE_AoIP_TransportLayerAddress tla :=
5910 valueof(f_ts_BSSMAP_IE_AoIP_TLA(cpars.bss_rtp_ip, cpars.bss_rtp_port));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005911 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5912 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5913
5914 /* HandoverCommand goes out via remote MSC-I */
5915 var GSUP_PDU prep_subsq_ho_res;
5916 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_SUBSEQUENT_HANDOVER_RESULT,
5917 pars.imsi, destination_name := remote_msc_name)) -> value prep_subsq_ho_res;
5918
5919 /* MS shows up at the local BSS */
5920 BSSAP.send(ts_BSSMAP_HandoverDetect);
5921 f_sleep(0.1);
5922 BSSAP.send(ts_BSSMAP_HandoverComplete);
5923
5924 /* Handover Succeeded message */
5925 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_FORWARD_ACCESS_SIGNALLING_REQUEST,
5926 pars.imsi, destination_name := remote_msc_name));
5927
5928 /* MS has handovered to here, Clear Command goes out via remote MSC-I -- in form of a GSUP Close. */
5929 GSUP.receive(tr_GSUP_E_NO_PDU(OSMO_GSUP_MSGT_E_CLOSE,
5930 pars.imsi, destination_name := remote_msc_name));
5931
5932 /* Handover ends successfully. Call goes on for a little longer and then we hang up. */
5933
5934 f_sleep(1.0);
5935 deactivate(ack_mdcx);
5936
5937 /* FIXME: the inter-MSC call has put a number of MNCC messages in the queue, which above code should expect and
5938 * clear out. The f_call_hangup() expects an MNCC_REL_IND, so, for the time being, just clear the MNCC messages
5939 * before starting the call hangup. Instead of this, the individual messages should be tested for above. */
5940 MNCC.clear;
5941
5942 var default ccrel := activate(as_optional_cc_rel(cpars, true));
5943 f_call_hangup(cpars, true);
5944 f_sleep(1.0);
5945 deactivate(ccrel);
5946
5947 setverdict(pass);
5948}
5949testcase TC_ho_inter_msc_out() runs on MTC_CT {
5950 var BSC_ConnHdlr vc_conn;
5951 f_init(1);
5952
5953 var BSC_ConnHdlrPars pars := f_init_pars(54);
5954
5955 vc_conn := f_start_handler_with_pars(refers(f_tc_ho_inter_msc_out), pars, 0);
5956 vc_conn.done;
5957}
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005958testcase TC_ho_inter_msc_out_ipv6() runs on MTC_CT {
5959 var BSC_ConnHdlr vc_conn;
5960 f_init(1);
5961
5962 var BSC_ConnHdlrPars pars := f_init_pars(54);
5963 pars.use_ipv6 := true;
5964
5965 vc_conn := f_start_handler_with_pars(refers(f_tc_ho_inter_msc_out), pars, 0);
5966 vc_conn.done;
5967}
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005968
Oliver Smith1d118ff2019-07-03 10:57:35 +02005969private function f_tc_lu_imsi_auth_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5970 pars.net.expect_auth := true;
5971 pars.net.expect_imei := true;
5972 f_init_handler(pars);
5973 f_perform_lu();
5974}
5975testcase TC_lu_imsi_auth_tmsi_check_imei() runs on MTC_CT {
5976 var BSC_ConnHdlr vc_conn;
5977 f_init();
5978 f_vty_config(MSCVTY, "network", "authentication required");
5979 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
5980
5981 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei), 5);
5982 vc_conn.done;
5983}
5984
5985private function f_tc_lu_imsi_auth3g_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5986 pars.net.expect_auth := true;
5987 pars.use_umts_aka := true;
5988 pars.net.expect_imei := true;
5989 f_init_handler(pars);
5990 f_perform_lu();
5991}
5992testcase TC_lu_imsi_auth3g_tmsi_check_imei() runs on MTC_CT {
5993 var BSC_ConnHdlr vc_conn;
5994 f_init();
5995 f_vty_config(MSCVTY, "network", "authentication required");
5996 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
5997
5998 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi_check_imei), 5);
5999 vc_conn.done;
6000}
6001
6002private function f_tc_lu_imsi_noauth_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6003 pars.net.expect_imei := true;
6004 f_init_handler(pars);
6005 f_perform_lu();
6006}
6007testcase TC_lu_imsi_noauth_tmsi_check_imei() runs on MTC_CT {
6008 var BSC_ConnHdlr vc_conn;
6009 f_init();
6010 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6011
6012 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi_check_imei), 5);
6013 vc_conn.done;
6014}
6015
6016private function f_tc_lu_imsi_noauth_notmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6017 pars.net.expect_tmsi := false;
6018 pars.net.expect_imei := true;
6019 f_init_handler(pars);
6020 f_perform_lu();
6021}
6022testcase TC_lu_imsi_noauth_notmsi_check_imei() runs on MTC_CT {
6023 var BSC_ConnHdlr vc_conn;
6024 f_init();
6025 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
6026 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6027
6028 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi_check_imei), 5);
6029 vc_conn.done;
6030}
6031
6032private function f_tc_lu_imsi_auth_tmsi_check_imei_nack(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6033 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02006034
6035 pars.net.expect_auth := true;
6036 pars.net.expect_imei := true;
6037 pars.net.check_imei_result := OSMO_GSUP_IMEI_RESULT_NACK;
6038 f_init_handler(pars);
6039
6040 /* Cannot use f_perform_lu() as we expect a reject */
6041 l3_lu := f_build_lu_imsi(g_pars.imsi)
6042 f_create_gsup_expect(hex2str(g_pars.imsi));
6043 f_bssap_compl_l3(l3_lu);
6044 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
6045
6046 f_mm_common();
6047 f_msc_lu_hlr();
6048 f_mm_imei();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02006049 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02006050 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02006051}
6052testcase TC_lu_imsi_auth_tmsi_check_imei_nack() runs on MTC_CT {
6053 var BSC_ConnHdlr vc_conn;
6054 f_init();
6055 f_vty_config(MSCVTY, "network", "authentication required");
6056 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6057
6058 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_nack), 5);
6059 vc_conn.done;
6060}
6061
6062private function f_tc_lu_imsi_auth_tmsi_check_imei_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6063 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02006064
6065 pars.net.expect_auth := true;
6066 pars.net.expect_imei := true;
6067 pars.net.check_imei_error := true;
6068 f_init_handler(pars);
6069
6070 /* Cannot use f_perform_lu() as we expect a reject */
6071 l3_lu := f_build_lu_imsi(g_pars.imsi)
6072 f_create_gsup_expect(hex2str(g_pars.imsi));
6073 f_bssap_compl_l3(l3_lu);
6074 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
6075
6076 f_mm_common();
6077 f_msc_lu_hlr();
6078 f_mm_imei();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02006079 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02006080 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02006081}
6082testcase TC_lu_imsi_auth_tmsi_check_imei_err() runs on MTC_CT {
6083 var BSC_ConnHdlr vc_conn;
6084 f_init();
6085 f_vty_config(MSCVTY, "network", "authentication required");
6086 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6087
6088 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_err), 5);
6089 vc_conn.done;
6090}
6091
6092private function f_tc_lu_imsi_auth_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6093 pars.net.expect_auth := true;
6094 pars.net.expect_imei_early := true;
6095 f_init_handler(pars);
6096 f_perform_lu();
6097}
6098testcase TC_lu_imsi_auth_tmsi_check_imei_early() runs on MTC_CT {
6099 var BSC_ConnHdlr vc_conn;
6100 f_init();
6101 f_vty_config(MSCVTY, "network", "authentication required");
6102 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6103
6104 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early), 5);
6105 vc_conn.done;
6106}
6107
6108private function f_tc_lu_imsi_auth3g_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6109 pars.net.expect_auth := true;
6110 pars.use_umts_aka := true;
6111 pars.net.expect_imei_early := true;
6112 f_init_handler(pars);
6113 f_perform_lu();
6114}
6115testcase TC_lu_imsi_auth3g_tmsi_check_imei_early() runs on MTC_CT {
6116 var BSC_ConnHdlr vc_conn;
6117 f_init();
6118 f_vty_config(MSCVTY, "network", "authentication required");
6119 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6120
6121 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi_check_imei_early), 5);
6122 vc_conn.done;
6123}
6124
6125private function f_tc_lu_imsi_noauth_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6126 pars.net.expect_imei_early := true;
6127 f_init_handler(pars);
6128 f_perform_lu();
6129}
6130testcase TC_lu_imsi_noauth_tmsi_check_imei_early() runs on MTC_CT {
6131 var BSC_ConnHdlr vc_conn;
6132 f_init();
6133 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6134
6135 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi_check_imei_early), 5);
6136 vc_conn.done;
6137}
6138
6139private function f_tc_lu_imsi_noauth_notmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6140 pars.net.expect_tmsi := false;
6141 pars.net.expect_imei_early := true;
6142 f_init_handler(pars);
6143 f_perform_lu();
6144}
6145testcase TC_lu_imsi_noauth_notmsi_check_imei_early() runs on MTC_CT {
6146 var BSC_ConnHdlr vc_conn;
6147 f_init();
6148 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
6149 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6150
6151 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi_check_imei_early), 5);
6152 vc_conn.done;
6153}
6154
6155private function f_tc_lu_imsi_auth_tmsi_check_imei_early_nack(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6156 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02006157
6158 pars.net.expect_auth := true;
6159 pars.net.expect_imei_early := true;
6160 pars.net.check_imei_result := OSMO_GSUP_IMEI_RESULT_NACK;
6161 f_init_handler(pars);
6162
6163 /* Cannot use f_perform_lu() as we expect a reject */
6164 l3_lu := f_build_lu_imsi(g_pars.imsi)
6165 f_create_gsup_expect(hex2str(g_pars.imsi));
6166 f_bssap_compl_l3(l3_lu);
6167 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
6168
6169 f_mm_imei_early();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02006170 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02006171 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02006172}
6173testcase TC_lu_imsi_auth_tmsi_check_imei_early_nack() runs on MTC_CT {
6174 var BSC_ConnHdlr vc_conn;
6175 f_init();
6176 f_vty_config(MSCVTY, "network", "authentication required");
6177 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6178
6179 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early_nack), 5);
6180 vc_conn.done;
6181}
6182
6183private function f_tc_lu_imsi_auth_tmsi_check_imei_early_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6184 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02006185
6186 pars.net.expect_auth := true;
6187 pars.net.expect_imei_early := true;
6188 pars.net.check_imei_error := true;
6189 f_init_handler(pars);
6190
6191 /* Cannot use f_perform_lu() as we expect a reject */
6192 l3_lu := f_build_lu_imsi(g_pars.imsi)
6193 f_create_gsup_expect(hex2str(g_pars.imsi));
6194 f_bssap_compl_l3(l3_lu);
6195 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
6196
6197 f_mm_imei_early();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02006198 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02006199 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02006200}
6201testcase TC_lu_imsi_auth_tmsi_check_imei_early_err() runs on MTC_CT {
6202 var BSC_ConnHdlr vc_conn;
6203 f_init();
6204 f_vty_config(MSCVTY, "network", "authentication required");
6205 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6206
6207 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early_err), 5);
6208 vc_conn.done;
6209}
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006210
Neels Hofmeyr8df69622019-11-02 19:16:03 +01006211friend function f_tc_invalid_mgcp_crash(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6212 f_init_handler(pars);
6213 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
6214
6215 /* Set invalid IP address so that osmo-msc discards the rtp_stream and MGCP endpoint FSM instances in the middle
6216 * of successful MGCP response dispatch. If things aren't safeguarded, the on_success() in osmo_mgcpc_ep_fsm
6217 * will cause a use-after-free after that event dispatch. */
6218 cpars.mgw_conn_1.mgw_rtp_ip := "0.0.0.0";
6219 cpars.mgw_conn_2.mgw_rtp_ip := "0.0.0.0";
6220 cpars.rtp_sdp_format := "FOO/8000";
6221 cpars.expect_release := true;
6222
6223 f_perform_lu();
6224 f_mo_call_establish(cpars);
6225}
6226testcase TC_invalid_mgcp_crash() runs on MTC_CT {
6227 var BSC_ConnHdlr vc_conn;
6228 f_init();
6229
6230 vc_conn := f_start_handler(refers(f_tc_invalid_mgcp_crash), 7);
6231 vc_conn.done;
6232}
6233
Vadim Yanitskiyeddebaa2019-12-28 17:45:34 +01006234friend function f_tc_mm_id_resp_no_identity(charstring id, BSC_ConnHdlrPars pars)
6235runs on BSC_ConnHdlr {
6236 pars.tmsi := 'FFFFFFFF'O;
6237 f_init_handler(pars);
6238
6239 f_create_gsup_expect(hex2str(g_pars.imsi));
6240
6241 /* Initiate Location Updating using an unknown TMSI */
6242 f_bssap_compl_l3(f_build_lu_tmsi(pars.tmsi));
6243
6244 /* Expect an Identity Request, send response with no identity */
6245 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
6246 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp({
6247 lengthIndicator := 1,
6248 mobileIdentityV := {
6249 typeOfIdentity := '000'B,
6250 oddEvenInd_identity := {
6251 no_identity := {
6252 oddevenIndicator := '0'B,
6253 fillerDigits := '00000'H
6254 }
6255 }
6256 }
6257 })));
6258
6259 f_expect_lu_reject();
6260 f_expect_clear();
6261}
6262testcase TC_mm_id_resp_no_identity() runs on MTC_CT {
6263 var BSC_ConnHdlr vc_conn;
6264
6265 f_init();
6266
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02006267 vc_conn := f_start_handler(refers(f_tc_mm_id_resp_no_identity), 7, verify_cell_id := false);
Vadim Yanitskiyeddebaa2019-12-28 17:45:34 +01006268 vc_conn.done;
6269}
6270
Vadim Yanitskiy25219062020-01-21 01:41:33 +07006271/* Verify the case when T3212 expires during Paging procedure, just before the receipt
6272 * of Paging Response. This used to provoke a NULL-pointer dereference in old versions
6273 * of OsmoMSC, but apparently the bug has been fixed, and we're safe now. */
6274friend function f_tc_lu_and_expire_while_paging(charstring id, BSC_ConnHdlrPars pars)
6275runs on BSC_ConnHdlr {
6276 var charstring imsi := hex2str(pars.imsi);
6277
6278 f_init_handler(pars);
6279
6280 /* Perform location update */
6281 f_perform_lu();
6282
6283 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
6284 f_create_gsup_expect(hex2str(g_pars.imsi));
6285
6286 /* Initiate paging procedure from the VTY */
6287 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " paging");
6288 f_expect_paging();
6289
6290 /* Emulate T3212 expiration during paging (we don't want to wait, right?) */
6291 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " expire");
6292
6293 /* MS sends PAGING RESPONSE, *old* OsmoMSC crashes here... */
6294 f_establish_fully(EST_TYPE_PAG_RESP);
6295
6296 /* The recent OsmoMSC keeps subscriber in its VLR unless the Paging is completed.
6297 * In this case we do not send anything and just wait for a Clear Command. */
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02006298 f_expect_clear(verify_vlr_cell_id := false);
Vadim Yanitskiy25219062020-01-21 01:41:33 +07006299}
6300testcase TC_lu_and_expire_while_paging() runs on MTC_CT {
6301 var BSC_ConnHdlr vc_conn;
6302
6303 f_init();
6304
6305 vc_conn := f_start_handler(refers(f_tc_lu_and_expire_while_paging), 7);
6306 vc_conn.done;
6307}
6308
Harald Weltef6dd64d2017-11-19 12:09:51 +01006309control {
Philipp Maier328d1662018-03-07 10:40:27 +01006310 execute( TC_cr_before_reset() );
Harald Weltea49e36e2018-01-21 19:29:33 +01006311 execute( TC_lu_imsi_noauth_tmsi() );
Harald Welted2328a22018-01-27 14:27:16 +01006312 execute( TC_lu_imsi_noauth_notmsi() );
Harald Weltea49e36e2018-01-21 19:29:33 +01006313 execute( TC_lu_imsi_reject() );
6314 execute( TC_lu_imsi_timeout_gsup() );
Harald Welted2328a22018-01-27 14:27:16 +01006315 execute( TC_lu_imsi_auth_tmsi() );
Harald Welte8a397ae2019-04-21 22:03:37 +02006316 execute( TC_lu_imsi_auth3g_tmsi() );
Pau Espin Pedrold3d54a92019-12-17 17:02:54 +01006317 execute( TC_lu_imsi_timeout_tmsi_realloc() );
Harald Welted2328a22018-01-27 14:27:16 +01006318 execute( TC_cmserv_imsi_unknown() );
Neels Hofmeyr13737fb2020-08-19 13:16:14 +00006319 execute( TC_cmserv_tmsi_unknown() );
Harald Welte2bb825f2018-01-22 11:31:18 +01006320 execute( TC_lu_and_mo_call() );
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006321 execute( TC_lu_and_mo_call_ipv6() );
Pau Espin Pedrola42745c2020-01-10 18:03:28 +01006322 execute( TC_lu_and_mo_call_sccp_tiar_timeout() );
Harald Welte071ed732018-01-23 19:53:52 +01006323 execute( TC_lu_auth_sai_timeout() );
6324 execute( TC_lu_auth_sai_err() );
Harald Weltee1a2f3c2018-01-24 17:28:48 +01006325 execute( TC_lu_clear_request() );
6326 execute( TC_lu_disconnect() );
6327 execute( TC_lu_by_imei() );
6328 execute( TC_lu_by_tmsi_noauth_unknown() );
Neels Hofmeyrfc06c732020-08-19 12:52:28 +00006329 execute( TC_attached_imsi_lu_unknown_tmsi() );
Harald Weltee1a2f3c2018-01-24 17:28:48 +01006330 execute( TC_imsi_detach_by_imsi() );
6331 execute( TC_imsi_detach_by_tmsi() );
6332 execute( TC_imsi_detach_by_imei() );
6333 execute( TC_emerg_call_imei_reject() );
6334 execute( TC_emerg_call_imsi() );
6335 execute( TC_cm_serv_req_vgcs_reject() );
6336 execute( TC_cm_serv_req_vbs_reject() );
6337 execute( TC_cm_serv_req_lcs_reject() );
Harald Welte0195ab12018-01-24 21:50:20 +01006338 execute( TC_cm_reest_req_reject() );
Harald Welte1af6ea82018-01-25 18:33:15 +01006339 execute( TC_lu_auth_2G_fail() );
6340 execute( TC_lu_imsi_auth_tmsi_encr_13_13() );
6341 execute( TC_cl3_no_payload() );
6342 execute( TC_cl3_rnd_payload() );
Harald Welte1852a842018-01-26 22:53:36 +01006343 execute( TC_establish_and_nothing() );
6344 execute( TC_mo_setup_and_nothing() );
6345 execute( TC_mo_crcx_ran_timeout() );
6346 execute( TC_mo_crcx_ran_reject() );
Harald Welted2328a22018-01-27 14:27:16 +01006347 execute( TC_mt_crcx_ran_reject() );
Daniel Willmann8b084372018-02-04 13:35:26 +01006348 execute( TC_mo_setup_and_dtmf_dup() );
Harald Welteaa54cf82018-01-30 08:15:32 +01006349 //execute( TC_mt_t310() );
Harald Welte167458a2018-01-27 15:58:16 +01006350 execute( TC_gsup_cancel() );
Harald Welte9de84792018-01-28 01:06:35 +01006351 execute( TC_lu_imsi_auth_tmsi_encr_1_13() );
6352 execute( TC_lu_imsi_auth_tmsi_encr_3_13() );
6353 execute( TC_lu_imsi_auth_tmsi_encr_3_1() );
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01006354 execute( TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() );
Harald Welte9de84792018-01-28 01:06:35 +01006355 execute( TC_lu_imsi_auth_tmsi_encr_13_2() );
6356 execute( TC_lu_imsi_auth_tmsi_encr_013_2() );
Philipp Maier94f3f1b2018-03-15 18:54:13 +01006357 execute( TC_mo_release_timeout() );
Philipp Maier2a98a732018-03-19 16:06:12 +01006358 execute( TC_lu_and_mt_call_no_dlcx_resp() );
Philipp Maier75932982018-03-27 14:52:35 +02006359 execute( TC_reset_two() );
Harald Welte33ec09b2018-02-10 15:34:46 +01006360
6361 execute( TC_lu_and_mt_call() );
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006362 execute( TC_lu_and_mt_call_ipv6() );
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01006363 execute( TC_lu_and_mt_call_already_paging() );
Harald Welte33ec09b2018-02-10 15:34:46 +01006364
Harald Weltef45efeb2018-04-09 18:19:24 +02006365 execute( TC_lu_and_mo_sms() );
6366 execute( TC_lu_and_mt_sms() );
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01006367 execute( TC_lu_and_mt_sms_already_paging() );
Philipp Maier3983e702018-11-22 19:01:33 +01006368 execute( TC_lu_and_mt_sms_paging_and_nothing() );
Alexander Couzensfc02f242019-09-12 03:43:18 +02006369 execute( TC_lu_and_mt_sms_paging_repeated() );
Harald Weltef640a012018-04-14 17:49:21 +02006370 execute( TC_smpp_mo_sms() );
Vadim Yanitskiy33820762020-01-15 11:26:07 +07006371 execute( TC_smpp_mo_sms_rp_error() );
Harald Weltef640a012018-04-14 17:49:21 +02006372 execute( TC_smpp_mt_sms() );
Harald Weltef45efeb2018-04-09 18:19:24 +02006373
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07006374 execute( TC_gsup_mo_sms() );
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07006375 execute( TC_gsup_mo_smma() );
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07006376 execute( TC_gsup_mt_sms_ack() );
6377 execute( TC_gsup_mt_sms_err() );
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07006378 execute( TC_gsup_mt_sms_rp_mr() );
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07006379 execute( TC_gsup_mo_mt_sms_rp_mr() );
Vadim Yanitskiya2a8a112019-07-08 20:04:32 +07006380 execute( TC_gsup_mt_multi_part_sms() );
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07006381
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07006382 execute( TC_lu_and_mo_ussd_single_request() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07006383 execute( TC_lu_and_mt_ussd_notification() );
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07006384 execute( TC_lu_and_mo_ussd_during_mt_call() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07006385 execute( TC_lu_and_mt_ussd_during_mt_call() );
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07006386 execute( TC_lu_and_mo_ussd_mo_release() );
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07006387 execute( TC_lu_and_ss_session_timeout() );
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07006388
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07006389 execute( TC_mt_ussd_for_unknown_subscr() );
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07006390 execute( TC_mo_ussd_for_unknown_trans() );
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07006391 execute( TC_proc_ss_for_unknown_session() );
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07006392 execute( TC_proc_ss_paging_fail() );
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07006393 execute( TC_proc_ss_abort() );
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07006394
Vadim Yanitskiy1c9754d2020-01-07 21:56:55 +01006395 execute( TC_multi_lu_and_mo_ussd() );
6396 execute( TC_multi_lu_and_mt_ussd() );
6397
Stefan Sperling89eb1f32018-12-17 15:06:20 +01006398 execute( TC_cipher_complete_with_invalid_cipher() );
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01006399 execute( TC_cipher_complete_1_without_cipher() );
6400 execute( TC_cipher_complete_3_without_cipher() );
6401 execute( TC_cipher_complete_13_without_cipher() );
Harald Welteb2284bd2019-05-10 11:30:43 +02006402 execute( TC_lu_with_invalid_mcc_mnc() );
Stefan Sperling89eb1f32018-12-17 15:06:20 +01006403
Harald Welte4263c522018-12-06 11:56:27 +01006404 execute( TC_sgsap_reset() );
6405 execute( TC_sgsap_lu() );
6406 execute( TC_sgsap_lu_imsi_reject() );
6407 execute( TC_sgsap_lu_and_nothing() );
6408 execute( TC_sgsap_expl_imsi_det_eps() );
Philipp Maierfc19f172019-03-21 11:17:54 +01006409 execute( TC_sgsap_impl_imsi_det_eps() );
Harald Welte4263c522018-12-06 11:56:27 +01006410 execute( TC_sgsap_expl_imsi_det_noneps() );
Philipp Maier5d812702019-03-21 10:51:26 +01006411 execute( TC_sgsap_impl_imsi_det_noneps() );
Harald Welte4263c522018-12-06 11:56:27 +01006412 execute( TC_sgsap_paging_rej() );
6413 execute( TC_sgsap_paging_subscr_rej() );
6414 execute( TC_sgsap_paging_ue_unr() );
6415 execute( TC_sgsap_paging_and_nothing() );
6416 execute( TC_sgsap_paging_and_lu() );
6417 execute( TC_sgsap_mt_sms() );
6418 execute( TC_sgsap_mo_sms() );
6419 execute( TC_sgsap_mt_sms_and_nothing() );
6420 execute( TC_sgsap_mt_sms_and_reject() );
6421 execute( TC_sgsap_unexp_ud() );
6422 execute( TC_sgsap_unsol_ud() );
6423 execute( TC_bssap_lu_sgsap_lu_and_mt_call() );
6424 execute( TC_sgsap_lu_and_mt_call() );
Philipp Maier628c0052019-04-09 17:36:57 +02006425 execute( TC_sgsap_vlr_failure() );
Harald Welte4263c522018-12-06 11:56:27 +01006426
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006427 execute( TC_ho_inter_bsc_unknown_cell() );
6428 execute( TC_ho_inter_bsc() );
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006429 execute( TC_ho_inter_bsc_ipv6() );
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006430
6431 execute( TC_ho_inter_msc_out() );
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006432 execute( TC_ho_inter_msc_out_ipv6() );
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006433
Oliver Smith1d118ff2019-07-03 10:57:35 +02006434 execute( TC_lu_imsi_auth_tmsi_check_imei() );
6435 execute( TC_lu_imsi_auth3g_tmsi_check_imei() );
6436 execute( TC_lu_imsi_noauth_tmsi_check_imei() );
6437 execute( TC_lu_imsi_noauth_notmsi_check_imei() );
6438 execute( TC_lu_imsi_auth_tmsi_check_imei_nack() );
6439 execute( TC_lu_imsi_auth_tmsi_check_imei_err() );
6440 execute( TC_lu_imsi_auth_tmsi_check_imei_early() );
6441 execute( TC_lu_imsi_auth3g_tmsi_check_imei_early() );
6442 execute( TC_lu_imsi_noauth_tmsi_check_imei_early() );
6443 execute( TC_lu_imsi_noauth_notmsi_check_imei_early() );
6444 execute( TC_lu_imsi_auth_tmsi_check_imei_early_nack() );
6445 execute( TC_lu_imsi_auth_tmsi_check_imei_early_err() );
6446
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01006447 /* Run this last: at the time of writing this test crashes the MSC */
6448 execute( TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() );
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02006449 execute( TC_mo_cc_bssmap_clear() );
Pau Espin Pedrol690d6592019-05-31 17:56:32 +02006450 if (mp_enable_osmux_test) {
6451 execute( TC_lu_and_mt_call_osmux() );
6452 }
Neels Hofmeyr8df69622019-11-02 19:16:03 +01006453 execute( TC_invalid_mgcp_crash() );
Vadim Yanitskiyeddebaa2019-12-28 17:45:34 +01006454 execute( TC_mm_id_resp_no_identity() );
Vadim Yanitskiy25219062020-01-21 01:41:33 +07006455 execute( TC_lu_and_expire_while_paging() );
Neels Hofmeyr14d0b132020-08-19 13:49:05 +00006456 execute( TC_paging_response_imsi_unknown() );
6457 execute( TC_paging_response_tmsi_unknown() );
Harald Weltef6dd64d2017-11-19 12:09:51 +01006458}
6459
6460
6461}