blob: 2a6c0341939bd97cfe31608ad2c3fc931c0a6aea [file] [log] [blame]
Harald Weltef6dd64d2017-11-19 12:09:51 +01001module MSC_Tests {
2
3import from General_Types all;
4import from Osmocom_Types all;
5
6import from M3UA_Types all;
7import from M3UA_Emulation all;
8
9import from MTP3asp_Types all;
10import from MTP3asp_PortType all;
11
12import from SCCPasp_Types all;
13import from SCCP_Types all;
14import from SCCP_Emulation all;
15
16import from SCTPasp_Types all;
17import from SCTPasp_PortType all;
18
Harald Weltea49e36e2018-01-21 19:29:33 +010019import from Osmocom_CTRL_Functions all;
20import from Osmocom_CTRL_Types all;
21import from Osmocom_CTRL_Adapter all;
22
Harald Welte3ca1c902018-01-24 18:51:27 +010023import from TELNETasp_PortType all;
24import from Osmocom_VTY_Functions all;
25
Harald Weltea49e36e2018-01-21 19:29:33 +010026import from MNCC_Emulation all;
Harald Welte2bb825f2018-01-22 11:31:18 +010027import from MNCC_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010028
Harald Welte4aa970c2018-01-26 10:38:09 +010029import from MGCP_Emulation all;
30import from MGCP_Types all;
31import from MGCP_Templates all;
32import from SDP_Types all;
33
Harald Weltea49e36e2018-01-21 19:29:33 +010034import from GSUP_Emulation all;
35import from GSUP_Types all;
36import from IPA_Emulation all;
37
Harald Weltef6dd64d2017-11-19 12:09:51 +010038import from BSSAP_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010039import from BSSAP_Adapter all;
40import from BSSAP_CodecPort all;
41import from BSSMAP_Templates all;
42import from BSSMAP_Emulation all;
43import from BSC_ConnectionHandler all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010044
Harald Weltea49e36e2018-01-21 19:29:33 +010045import from MobileL3_Types all;
46import from MobileL3_CommonIE_Types all;
47import from L3_Templates all;
Harald Welte158a7ca2018-02-16 18:11:31 +010048import from L3_Common all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010049
Harald Weltef640a012018-04-14 17:49:21 +020050import from SMPP_Types all;
51import from SMPP_Templates all;
52import from SMPP_Emulation all;
53
Stefan Sperlingc307e682018-06-14 15:15:46 +020054import from SCCP_Templates all;
55
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070056import from SS_Types all;
57import from SS_Templates all;
58import from USSD_Helpers all;
59
Philipp Maier75932982018-03-27 14:52:35 +020060const integer NUM_BSC := 2;
61type record of BSSAP_Configuration BSSAP_Configurations;
Harald Weltef6dd64d2017-11-19 12:09:51 +010062
Harald Weltea4ca4462018-02-09 00:17:14 +010063type component MTC_CT extends CTRL_Adapter_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +010064 var boolean g_initialized := false;
Harald Weltea49e36e2018-01-21 19:29:33 +010065
Philipp Maier75932982018-03-27 14:52:35 +020066 var BSSAP_Adapter g_bssap[NUM_BSC];
Harald Weltea4ca4462018-02-09 00:17:14 +010067
Harald Weltea49e36e2018-01-21 19:29:33 +010068 /* no 'adapter_CT' for MNCC or GSUP */
69 var MNCC_Emulation_CT vc_MNCC;
Harald Welte4aa970c2018-01-26 10:38:09 +010070 var MGCP_Emulation_CT vc_MGCP;
Harald Weltea49e36e2018-01-21 19:29:33 +010071 var GSUP_Emulation_CT vc_GSUP;
72 var IPA_Emulation_CT vc_GSUP_IPA;
Harald Weltef640a012018-04-14 17:49:21 +020073 var SMPP_Emulation_CT vc_SMPP;
Harald Weltea49e36e2018-01-21 19:29:33 +010074
75 /* only to get events from IPA underneath GSUP */
76 port IPA_CTRL_PT GSUP_IPA_EVENT;
Harald Welte3ca1c902018-01-24 18:51:27 +010077 /* VTY to MSC */
78 port TELNETasp_PT MSCVTY;
Philipp Maier328d1662018-03-07 10:40:27 +010079
80 /* A port to directly send BSSAP messages. This port is used for
81 * tests that require low level access to sen arbitrary BSSAP
82 * messages. Run f_init_bssap_direct() to connect and initialize */
83 port BSSAP_CODEC_PT BSSAP_DIRECT;
84
85 /* When BSSAP messages are directly sent, then the connection
86 * handler is not active, which means that also no guard timer is
87 * set up. The following timer will serve as a replacement */
88 timer Tguard_direct := 60.0;
Harald Weltef6dd64d2017-11-19 12:09:51 +010089}
90
91modulepar {
Harald Weltea49e36e2018-01-21 19:29:33 +010092 /* remote parameters of IUT */
93 charstring mp_msc_ip := "127.0.0.1";
94 integer mp_msc_ctrl_port := 4255;
95 integer mp_msc_vty_port := 4254;
Harald Weltef6dd64d2017-11-19 12:09:51 +010096
Harald Weltea49e36e2018-01-21 19:29:33 +010097 /* local parameters of emulated HLR */
98 charstring mp_hlr_ip := "127.0.0.1";
99 integer mp_hlr_port := 4222;
Harald Welte6126fb02018-01-27 20:08:24 +0100100 charstring mp_mgw_ip := "127.0.0.1";
101 integer mp_mgw_port := 2427;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100102
Harald Weltea49e36e2018-01-21 19:29:33 +0100103 charstring mp_msc_mncc := "/tmp/mncc";
Harald Weltea4ca4462018-02-09 00:17:14 +0100104
Harald Weltef640a012018-04-14 17:49:21 +0200105 integer mp_msc_smpp_port := 2775;
106 charstring mp_smpp_system_id := "msc_tester";
107 charstring mp_smpp_password := "osmocom1";
108
Philipp Maier75932982018-03-27 14:52:35 +0200109 BSSAP_Configurations mp_bssap_cfg := {
110 {
111 sccp_service_type := "mtp3_itu",
112 sctp_addr := { 23905, "127.0.0.1", 2905, "127.0.0.1" },
113 own_pc := 185,
114 own_ssn := 254,
115 peer_pc := 187,
116 peer_ssn := 254,
117 sio := '83'O,
118 rctx := 0
119 },
120 {
121 sccp_service_type := "mtp3_itu",
122 sctp_addr := { 23906, "127.0.0.1", 2905, "127.0.0.1" },
123 own_pc := 186,
124 own_ssn := 254,
125 peer_pc := 187,
126 peer_ssn := 254,
127 sio := '83'O,
128 rctx := 1
129 }
Harald Weltea4ca4462018-02-09 00:17:14 +0100130 };
Harald Weltef6dd64d2017-11-19 12:09:51 +0100131}
132
Philipp Maier328d1662018-03-07 10:40:27 +0100133/* altstep for the global guard timer (only used when BSSAP_DIRECT
134 * is used for communication */
135private altstep as_Tguard_direct() runs on MTC_CT {
136 [] Tguard_direct.timeout {
137 setverdict(fail, "Tguard timeout");
Daniel Willmannafce8662018-07-06 23:11:32 +0200138 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +0100139 }
140}
Harald Weltef6dd64d2017-11-19 12:09:51 +0100141
Harald Weltef640a012018-04-14 17:49:21 +0200142function f_init_smpp(charstring id) runs on MTC_CT {
143 id := id & "-SMPP";
144 var EsmePars pars := {
145 mode := MODE_TRANSCEIVER,
146 bind := {
147 system_id := mp_smpp_system_id,
148 password := mp_smpp_password,
149 system_type := "MSC_Tests",
150 interface_version := hex2int('34'H),
151 addr_ton := unknown,
152 addr_npi := unknown,
153 address_range := ""
154 },
155 esme_role := true
156 }
157
158 vc_SMPP := SMPP_Emulation_CT.create(id);
159 map(vc_SMPP:SMPP_PORT, system:SMPP_PORT);
160 vc_SMPP.start(SMPP_Emulation.main_client(pars, mp_msc_ip, mp_msc_smpp_port, "", -1));
161}
162
163
Harald Weltea49e36e2018-01-21 19:29:33 +0100164function f_init_mncc(charstring id) runs on MTC_CT {
165 id := id & "-MNCC";
166 var MnccOps ops := {
167 create_cb := refers(MNCC_Emulation.ExpectedCreateCallback),
168 unitdata_cb := refers(MNCC_Emulation.DummyUnitdataCallback)
169 }
170
171 vc_MNCC := MNCC_Emulation_CT.create(id);
172 map(vc_MNCC:MNCC, system:MNCC_CODEC_PT);
173 vc_MNCC.start(MNCC_Emulation.main(ops, id, mp_msc_mncc));
Harald Weltef6dd64d2017-11-19 12:09:51 +0100174}
175
Harald Welte4aa970c2018-01-26 10:38:09 +0100176function f_init_mgcp(charstring id) runs on MTC_CT {
177 id := id & "-MGCP";
178 var MGCPOps ops := {
179 create_cb := refers(MGCP_Emulation.ExpectedCreateCallback),
180 unitdata_cb := refers(MGCP_Emulation.DummyUnitdataCallback)
181 }
182 var MGCP_conn_parameters pars := {
Harald Welte6126fb02018-01-27 20:08:24 +0100183 callagent_ip := mp_msc_ip,
Harald Welte4aa970c2018-01-26 10:38:09 +0100184 callagent_udp_port := -1,
Harald Welte6126fb02018-01-27 20:08:24 +0100185 mgw_ip := mp_mgw_ip,
186 mgw_udp_port := mp_mgw_port
Harald Welte4aa970c2018-01-26 10:38:09 +0100187 }
188
189 vc_MGCP := MGCP_Emulation_CT.create(id);
190 map(vc_MGCP:MGCP, system:MGCP_CODEC_PT);
191 vc_MGCP.start(MGCP_Emulation.main(ops, pars, id));
192}
193
Harald Weltea49e36e2018-01-21 19:29:33 +0100194function f_init_gsup(charstring id) runs on MTC_CT {
195 id := id & "-GSUP";
196 var GsupOps ops := {
197 create_cb := refers(GSUP_Emulation.ExpectedCreateCallback)
198 }
199
200 vc_GSUP_IPA := IPA_Emulation_CT.create(id & "-IPA");
201 vc_GSUP := GSUP_Emulation_CT.create(id);
202
203 map(vc_GSUP_IPA:IPA_PORT, system:IPA_CODEC_PT);
204 connect(vc_GSUP:GSUP, vc_GSUP_IPA:IPA_GSUP_PORT);
205 /* we use this hack to get events like ASP_IPA_EVENT_UP */
206 connect(vc_GSUP_IPA:IPA_CTRL_PORT, self:GSUP_IPA_EVENT);
207
208 vc_GSUP.start(GSUP_Emulation.main(ops, id));
209 vc_GSUP_IPA.start(IPA_Emulation.main_server(mp_hlr_ip, mp_hlr_port));
210
211 /* wait for incoming connection to GSUP port before proceeding */
212 timer T := 10.0;
213 T.start;
214 alt {
215 [] GSUP_IPA_EVENT.receive(t_ASP_IPA_EVT_UD(ASP_IPA_EVENT_UP)) { }
216 [] T.timeout {
Harald Welte458fd372018-03-21 11:26:23 +0100217 setverdict(fail, "No connection to GSUP Port");
Daniel Willmannafce8662018-07-06 23:11:32 +0200218 mtc.stop
Harald Weltea49e36e2018-01-21 19:29:33 +0100219 }
220 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100221}
222
Philipp Maier75932982018-03-27 14:52:35 +0200223function f_init(integer num_bsc := 1) runs on MTC_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +0100224
225 if (g_initialized == true) {
226 return;
227 }
228 g_initialized := true;
229
Philipp Maier75932982018-03-27 14:52:35 +0200230 if (num_bsc > NUM_BSC) {
Daniel Willmannafce8662018-07-06 23:11:32 +0200231 testcase.stop("excess number of BSC instances requested");
Philipp Maier75932982018-03-27 14:52:35 +0200232 }
233
234 for (var integer i := 0; i < num_bsc; i := i + 1) {
235 if (isbound(mp_bssap_cfg[i])) {
Philipp Maierdefd9482018-05-16 16:44:37 +0200236 f_bssap_init(g_bssap[i], mp_bssap_cfg[i], "MSC_Test_" & int2str(i), BSC_BssmapOps);
Harald Welted5833a82018-05-27 16:52:56 +0200237 f_bssap_start(g_bssap[i]);
Philipp Maier75932982018-03-27 14:52:35 +0200238 } else {
Daniel Willmannafce8662018-07-06 23:11:32 +0200239 testcase.stop("missing BSSAP configuration");
Philipp Maier75932982018-03-27 14:52:35 +0200240 }
241 }
242
Harald Weltea49e36e2018-01-21 19:29:33 +0100243 f_ipa_ctrl_start(mp_msc_ip, mp_msc_ctrl_port);
244 f_init_mncc("MSC_Test");
Harald Welte4aa970c2018-01-26 10:38:09 +0100245 f_init_mgcp("MSC_Test");
Harald Weltea49e36e2018-01-21 19:29:33 +0100246 f_init_gsup("MSC_Test");
Harald Weltef640a012018-04-14 17:49:21 +0200247 f_init_smpp("MSC_Test");
Harald Welte3ca1c902018-01-24 18:51:27 +0100248
249 map(self:MSCVTY, system:MSCVTY);
250 f_vty_set_prompts(MSCVTY);
251 f_vty_transceive(MSCVTY, "enable");
Harald Welteb14c77a2018-01-25 17:25:44 +0100252
253 /* set some defaults */
254 f_vty_config(MSCVTY, "network", "authentication optional");
255 f_vty_config(MSCVTY, "msc", "assign-tmsi");
256 f_vty_config(MSCVTY, "network", "encryption a5 0");
Harald Weltef6dd64d2017-11-19 12:09:51 +0100257}
258
Philipp Maier328d1662018-03-07 10:40:27 +0100259/* Initialize for a direct connection to BSSAP. This function is an alternative
260 * to f_init() when the high level functions of the BSC_ConnectionHandler are
261 * not needed. */
262function f_init_bssap_direct() runs on MTC_CT {
Philipp Maier75932982018-03-27 14:52:35 +0200263 f_bssap_init(g_bssap[0], mp_bssap_cfg[0], "MSC_Test", omit);
264 connect(g_bssap[0].vc_SCCP:SCCP_SP_PORT, self:BSSAP_DIRECT);
Philipp Maier328d1662018-03-07 10:40:27 +0100265
266 /* Start guard timer and activate it as default */
267 Tguard_direct.start
268 activate(as_Tguard_direct());
269}
270
Harald Weltef6dd64d2017-11-19 12:09:51 +0100271template PDU_BSSAP ts_BSSAP_BSSMAP := {
272 discriminator := '0'B,
273 spare := '0000000'B,
274 dlci := omit,
275 lengthIndicator := 0, /* overwritten by codec */
276 pdu := ?
277}
278
279template PDU_BSSAP tr_BSSAP_BSSMAP := {
280 discriminator := '0'B,
281 spare := '0000000'B,
282 dlci := omit,
283 lengthIndicator := ?,
284 pdu := {
285 bssmap := ?
286 }
287}
288
289
290type integer BssmapCause;
291
292template (value) BSSMAP_IE_Cause ts_BSSMAP_IE_Cause(BssmapCause val) := {
293 elementIdentifier := '04'O,
294 lengthIndicator := 0,
295 causeValue := int2bit(val, 7),
296 extensionCauseValue := '0'B,
297 spare1 := omit
298}
299
300template (value) PDU_BSSAP ts_BSSMAP_Reset(BssmapCause cause) modifies ts_BSSAP_BSSMAP := {
301 pdu := {
302 bssmap := {
303 reset := {
304 messageType := '30'O,
305 cause := ts_BSSMAP_IE_Cause(cause),
306 a_InterfaceSelectorForReset := omit
307 }
308 }
309 }
310}
311
312template (value) PDU_BSSAP ts_BSSMAP_ResetAck modifies ts_BSSAP_BSSMAP := {
313 pdu := {
314 bssmap := {
315 resetAck := {
316 messageType := '31'O,
317 a_InterfaceSelectorForReset := omit
318 }
319 }
320 }
321}
322
323template PDU_BSSAP tr_BSSMAP_ResetAck modifies tr_BSSAP_BSSMAP := {
324 pdu := {
325 bssmap := {
326 resetAck := {
327 messageType := '31'O,
328 a_InterfaceSelectorForReset := *
329 }
330 }
331 }
332}
333
334template BSSMAP_IE_CellIdentifier ts_BSSMAP_IE_CellID := {
335 elementIdentifier := '05'O,
336 lengthIndicator := 0,
337 cellIdentifierDiscriminator := '0000'B,
338 spare1_4 := '0000'B,
339 cellIdentification := ?
340}
341
342type uint16_t BssmapLAC;
343type uint16_t BssmapCI;
344
345/*
346template BSSMAP_IE_CellIdentifier ts_CellId_CGI(mcc, mnc, lac, ci)
347modifies ts_BSSMAP_IE_CellID := {
348 cellIdentification := {
349 cI_LAC_CGI := {
350 mnc_mcc := FIXME,
351 lac := int2oct(lac, 2),
352 ci := int2oct(ci, 2)
353 }
354 }
355}
356*/
357
358template BSSMAP_IE_CellIdentifier ts_CellID_LAC_CI(BssmapLAC lac, BssmapCI ci)
359modifies ts_BSSMAP_IE_CellID := {
360 cellIdentification := {
361 cI_LAC_CI := {
362 lac := int2oct(lac, 2),
363 ci := int2oct(ci, 2)
364 }
365 }
366}
367
368template BSSMAP_IE_CellIdentifier ts_CellId_CI(BssmapCI ci)
369modifies ts_BSSMAP_IE_CellID := {
370 cellIdentification := {
371 cI_CI := int2oct(ci, 2)
372 }
373}
374
375template BSSMAP_IE_CellIdentifier ts_CellId_none
376modifies ts_BSSMAP_IE_CellID := {
377 cellIdentification := {
378 cI_noCell := ''O
379 }
380}
381
382
383template BSSMAP_IE_Layer3Information ts_BSSMAP_IE_L3Info(octetstring l3info) := {
384 elementIdentifier := '17'O,
385 lengthIndicator := 0,
386 layer3info := l3info
387}
388
389template PDU_BSSAP ts_BSSMAP_ComplL3(BSSMAP_IE_CellIdentifier cell_id, octetstring l3_info)
390modifies ts_BSSAP_BSSMAP := {
391 pdu := {
392 bssmap := {
393 completeLayer3Information := {
394 messageType := '57'O,
395 cellIdentifier := cell_id,
396 layer3Information := ts_BSSMAP_IE_L3Info(l3_info),
397 chosenChannel := omit,
398 lSAIdentifier := omit,
399 aPDU := omit,
400 codecList := omit,
401 redirectAttemptFlag := omit,
402 sendSequenceNumber := omit,
403 iMSI := omit
404 }
405 }
406 }
407}
408
409template PDU_BSSAP ts_BSSMAP_HandoReq(BssmapCause cause, BSSMAP_IE_CellIdentifierList cid_list)
410modifies ts_BSSAP_BSSMAP := {
411 pdu := {
412 bssmap := {
413 handoverRequired := {
414 messageType := '11'O,
415 cause := ts_BSSMAP_IE_Cause(cause),
416 responseRequest := omit,
417 cellIdentifierList := cid_list,
418 circuitPoolList := omit,
419 currentChannelType1 := omit,
420 speechVersion := omit,
421 queueingIndicator := omit,
422 oldToNewBSSInfo := omit,
423 sourceToTargetRNCTransparentInfo := omit,
424 sourceToTargetRNCTransparentInfoCDMA := omit,
425 gERANClassmark := omit,
426 talkerPriority := omit,
427 speechCodec := omit,
428 cSG_Identifier := omit
429 }
430 }
431 }
432}
433
Harald Weltea49e36e2018-01-21 19:29:33 +0100434type function void_fn(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100435
Harald Weltea49e36e2018-01-21 19:29:33 +0100436/* FIXME: move into BSC_ConnectionHandler? */
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100437function f_init_pars(integer imsi_suffix) runs on MTC_CT return BSC_ConnHdlrPars {
Harald Weltede371492018-01-27 23:44:41 +0100438 var BSC_ConnHdlrNetworkPars net_pars := {
439 kc_support := '0A'O, /* A5/1 and A5/3 enabled */
440 expect_tmsi := true,
441 expect_auth := false,
442 expect_ciph := false
443 };
Harald Weltea49e36e2018-01-21 19:29:33 +0100444 var BSC_ConnHdlrPars pars := {
Philipp Maier75932982018-03-27 14:52:35 +0200445 sccp_addr_own := g_bssap[0].sccp_addr_own,
446 sccp_addr_peer := g_bssap[0].sccp_addr_peer,
Harald Welteedbab812018-03-18 16:02:25 +0100447 cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42)),
Harald Welte81b7f9d2018-01-24 19:06:24 +0100448 imei := f_gen_imei(imsi_suffix),
449 imsi := f_gen_imsi(imsi_suffix),
450 msisdn := f_gen_msisdn(imsi_suffix),
Harald Welte256571e2018-01-24 18:47:19 +0100451 tmsi := omit,
Harald Welte9de84792018-01-28 01:06:35 +0100452 cm1 := valueof(ts_CM1),
Harald Welte82600572018-01-21 20:54:08 +0100453 cm2 := valueof(ts_CM2_default),
Harald Welte16114282018-01-24 22:41:21 +0100454 cm3 := omit,
Harald Weltede371492018-01-27 23:44:41 +0100455 vec := omit,
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100456 net := net_pars,
457 send_early_cm := true
Harald Weltea49e36e2018-01-21 19:29:33 +0100458 };
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100459 return pars;
460}
461
462function f_start_handler_with_pars(void_fn fn, BSC_ConnHdlrPars pars) runs on MTC_CT return BSC_ConnHdlr {
463 var BSC_ConnHdlr vc_conn;
464 var charstring id := testcasename();
Harald Weltea49e36e2018-01-21 19:29:33 +0100465
466 vc_conn := BSC_ConnHdlr.create(id);
467 /* BSSMAP part / A interface */
Philipp Maier75932982018-03-27 14:52:35 +0200468 connect(vc_conn:BSSAP, g_bssap[0].vc_BSSMAP:CLIENT);
469 connect(vc_conn:BSSAP_PROC, g_bssap[0].vc_BSSMAP:PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100470 /* MNCC part */
471 connect(vc_conn:MNCC, vc_MNCC:MNCC_CLIENT);
472 connect(vc_conn:MNCC_PROC, vc_MNCC:MNCC_PROC);
Harald Welte4aa970c2018-01-26 10:38:09 +0100473 /* MGCP part */
474 connect(vc_conn:MGCP, vc_MGCP:MGCP_CLIENT);
475 connect(vc_conn:MGCP_PROC, vc_MGCP:MGCP_PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100476 /* GSUP part */
477 connect(vc_conn:GSUP, vc_GSUP:GSUP_CLIENT);
478 connect(vc_conn:GSUP_PROC, vc_GSUP:GSUP_PROC);
Harald Weltef640a012018-04-14 17:49:21 +0200479 /* SMPP part */
480 connect(vc_conn:SMPP, vc_SMPP:SMPP_CLIENT);
481 connect(vc_conn:SMPP_PROC, vc_SMPP:SMPP_PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100482
Harald Weltea10db902018-01-27 12:44:49 +0100483 /* We cannot use vc_conn.start(f_init_handler(fn, id, pars)); as we cannot have
484 * a stand-alone 'derefers()' call, see https://www.eclipse.org/forums/index.php/t/1091364/ */
Harald Weltea49e36e2018-01-21 19:29:33 +0100485 vc_conn.start(derefers(fn)(id, pars));
486 return vc_conn;
487}
488
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100489function f_start_handler(void_fn fn, integer imsi_suffix) runs on MTC_CT return BSC_ConnHdlr {
490 return f_start_handler_with_pars(fn, f_init_pars(imsi_suffix));
491}
492
Harald Weltea49e36e2018-01-21 19:29:33 +0100493private function f_tc_lu_imsi_noauth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100494 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100495 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100496}
Harald Weltea49e36e2018-01-21 19:29:33 +0100497testcase TC_lu_imsi_noauth_tmsi() runs on MTC_CT {
498 var BSC_ConnHdlr vc_conn;
499 f_init();
500
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100501 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi), 1);
Harald Weltea49e36e2018-01-21 19:29:33 +0100502 vc_conn.done;
503}
504
505private function f_tc_lu_imsi_noauth_notmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100506 pars.net.expect_tmsi := false;
Harald Weltea10db902018-01-27 12:44:49 +0100507 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100508 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100509}
Harald Weltea49e36e2018-01-21 19:29:33 +0100510testcase TC_lu_imsi_noauth_notmsi() runs on MTC_CT {
511 var BSC_ConnHdlr vc_conn;
512 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100513 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
Harald Weltea49e36e2018-01-21 19:29:33 +0100514
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100515 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi), 2);
Harald Weltea49e36e2018-01-21 19:29:33 +0100516 vc_conn.done;
517}
518
519/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
520private function f_tc_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100521 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100522 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
523
524 f_create_gsup_expect(hex2str(g_pars.imsi));
525 f_bssap_compl_l3(l3_lu);
526 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
527 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
528 alt {
Harald Welte5946b332018-03-18 23:32:21 +0100529 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej(int2oct(23,1)))) {
530 f_expect_clear();
531 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100532 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
533 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200534 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100535 }
536 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100537}
538testcase TC_lu_imsi_reject() runs on MTC_CT {
539 var BSC_ConnHdlr vc_conn;
540 f_init();
541
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100542 vc_conn := f_start_handler(refers(f_tc_lu_imsi_reject), 3);
Harald Weltea49e36e2018-01-21 19:29:33 +0100543 vc_conn.done;
544}
545
546/* Do LU by IMSI, timeout on GSUP */
547private function f_tc_lu_imsi_timeout_gsup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100548 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100549 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
550
551 f_create_gsup_expect(hex2str(g_pars.imsi));
552 f_bssap_compl_l3(l3_lu);
553 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
554 /* Normally the HLR would need to respond here, but we decide to force a timeout here */
555 alt {
556 /* FIXME: Expect specific reject cause */
Harald Welte5946b332018-03-18 23:32:21 +0100557 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
558 f_expect_clear();
559 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100560 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
561 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200562 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100563 }
564 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100565}
566testcase TC_lu_imsi_timeout_gsup() runs on MTC_CT {
567 var BSC_ConnHdlr vc_conn;
568 f_init();
569
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100570 vc_conn := f_start_handler(refers(f_tc_lu_imsi_timeout_gsup), 4);
Harald Weltea49e36e2018-01-21 19:29:33 +0100571 vc_conn.done;
572}
573
Harald Welte7b1b2812018-01-22 21:23:06 +0100574private function f_tc_lu_imsi_auth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100575 pars.net.expect_auth := true;
Harald Weltea10db902018-01-27 12:44:49 +0100576 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100577 f_perform_lu();
Harald Welte7b1b2812018-01-22 21:23:06 +0100578}
579testcase TC_lu_imsi_auth_tmsi() runs on MTC_CT {
580 var BSC_ConnHdlr vc_conn;
581 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100582 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte7b1b2812018-01-22 21:23:06 +0100583
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100584 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi), 5);
Harald Welte7b1b2812018-01-22 21:23:06 +0100585 vc_conn.done;
586}
587
Harald Weltea49e36e2018-01-21 19:29:33 +0100588
589/* Send CM SERVICE REQ for IMSI that has never performed LU before */
590private function f_tc_cmserv_imsi_unknown(charstring id, BSC_ConnHdlrPars pars)
591runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100592 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100593
594 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welteedbab812018-03-18 16:02:25 +0100595 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
Harald Welte6ed6bf92018-01-24 21:09:15 +0100596 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
Harald Weltea49e36e2018-01-21 19:29:33 +0100597
598 f_create_gsup_expect(hex2str(g_pars.imsi));
599
600 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
601 f_bssap_compl_l3(l3_info);
602
603 timer T := 10.0;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100604 T.start;
605 alt {
Harald Weltea49e36e2018-01-21 19:29:33 +0100606 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
607 //[] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_ACC)) { }
Daniel Willmannafce8662018-07-06 23:11:32 +0200608 [] BSSAP.receive {
609 setverdict(fail, "Received unexpected BSSAP");
610 mtc.stop;
611 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100612 [] GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi)) {
613 setverdict(fail, "Unexpected GSUP UL REQ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200614 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100615 }
Daniel Willmannafce8662018-07-06 23:11:32 +0200616 [] T.timeout {
617 setverdict(fail, "Timeout waiting for CM SERV REQ");
618 mtc.stop;
619 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100620 }
621
Harald Welte1ddc7162018-01-27 14:25:46 +0100622 f_expect_clear();
Harald Weltef6dd64d2017-11-19 12:09:51 +0100623}
Harald Weltea49e36e2018-01-21 19:29:33 +0100624testcase TC_cmserv_imsi_unknown() runs on MTC_CT {
625 var BSC_ConnHdlr vc_conn;
626 f_init();
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100627 vc_conn := f_start_handler(refers(f_tc_cmserv_imsi_unknown), 6);
Harald Weltea49e36e2018-01-21 19:29:33 +0100628 vc_conn.done;
629}
630
Harald Welte2bb825f2018-01-22 11:31:18 +0100631private function f_tc_lu_and_mo_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100632 f_init_handler(pars);
Harald Welteb71901a2018-01-26 19:16:05 +0100633 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
634 cpars.bss_rtp_port := 1110;
635 cpars.mgcp_connection_id_bss := '22222'H;
636 cpars.mgcp_connection_id_mss := '33333'H;
Philipp Maierf1e02bb2018-03-15 16:30:00 +0100637 cpars.mgcp_ep := "rtpbridge/1@mgw";
Harald Welte2bb825f2018-01-22 11:31:18 +0100638
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100639 f_perform_lu();
Harald Welteb71901a2018-01-26 19:16:05 +0100640 f_mo_call(cpars);
Harald Welte2bb825f2018-01-22 11:31:18 +0100641}
642testcase TC_lu_and_mo_call() runs on MTC_CT {
643 var BSC_ConnHdlr vc_conn;
644 f_init();
645
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100646 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_call), 7);
Harald Welte071ed732018-01-23 19:53:52 +0100647 vc_conn.done;
648}
649
650/* Test LU (with authentication enabled), where HLR times out sending SAI response */
651private function f_tc_lu_auth_sai_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100652 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100653
654 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
655 var PDU_DTAP_MT dtap_mt;
656
657 /* tell GSUP dispatcher to send this IMSI to us */
658 f_create_gsup_expect(hex2str(g_pars.imsi));
659
660 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
661 f_bssap_compl_l3(l3_lu);
662
663 /* Send Early Classmark, just for the fun of it */
664 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
665
666 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
667 /* The HLR would normally return an auth vector here, but we fail to do so. */
668
669 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100670 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100671}
672testcase TC_lu_auth_sai_timeout() runs on MTC_CT {
673 var BSC_ConnHdlr vc_conn;
674 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100675 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100676
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100677 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_timeout), 8);
Harald Welte071ed732018-01-23 19:53:52 +0100678 vc_conn.done;
679}
680
681/* Test LU (with authentication enabled), where HLR rejects sending SAI error */
682private function f_tc_lu_auth_sai_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100683 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100684
685 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
686 var PDU_DTAP_MT dtap_mt;
687
688 /* tell GSUP dispatcher to send this IMSI to us */
689 f_create_gsup_expect(hex2str(g_pars.imsi));
690
691 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
692 f_bssap_compl_l3(l3_lu);
693
694 /* Send Early Classmark, just for the fun of it */
695 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
696
697 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
698 GSUP.send(ts_GSUP_SAI_ERR(g_pars.imsi, 13));
699
700 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100701 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100702}
703testcase TC_lu_auth_sai_err() runs on MTC_CT {
704 var BSC_ConnHdlr vc_conn;
705 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100706 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100707
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100708 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_err), 9);
Harald Welte2bb825f2018-01-22 11:31:18 +0100709 vc_conn.done;
710}
Harald Weltea49e36e2018-01-21 19:29:33 +0100711
Harald Weltebc881782018-01-23 20:09:15 +0100712/* Test LU but BSC will send a clear request in the middle */
713private function f_tc_lu_clear_request(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100714 f_init_handler(pars);
Harald Weltebc881782018-01-23 20:09:15 +0100715
716 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
717 var PDU_DTAP_MT dtap_mt;
718
719 /* tell GSUP dispatcher to send this IMSI to us */
720 f_create_gsup_expect(hex2str(g_pars.imsi));
721
722 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
723 f_bssap_compl_l3(l3_lu);
724
725 /* Send Early Classmark, just for the fun of it */
726 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
727
728 f_sleep(1.0);
729 /* send clear request in the middle of the LU */
730 BSSAP.send(ts_BSSMAP_ClearRequest(0));
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200731 alt {
732 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { repeat; }
733 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {}
734 }
Harald Weltebc881782018-01-23 20:09:15 +0100735 BSSAP.send(ts_BSSMAP_ClearComplete);
Harald Welte89a32492018-01-27 19:07:28 +0100736 alt {
737 /* See https://osmocom.org/issues/2862 */
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200738 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {
739 setverdict(fail, "Got a second Clear Command, only one expected");
Daniel Willmannafce8662018-07-06 23:11:32 +0200740 mtc.stop;
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200741 repeat;
742 }
Harald Welte89a32492018-01-27 19:07:28 +0100743 [] BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
744 }
Harald Weltebc881782018-01-23 20:09:15 +0100745 setverdict(pass);
746}
747testcase TC_lu_clear_request() runs on MTC_CT {
748 var BSC_ConnHdlr vc_conn;
749 f_init();
750
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100751 vc_conn := f_start_handler(refers(f_tc_lu_clear_request), 10);
Harald Weltebc881782018-01-23 20:09:15 +0100752 vc_conn.done;
753}
754
Harald Welte66af9e62018-01-24 17:28:21 +0100755/* Test LU but BSC will send a clear request in the middle */
756private function f_tc_lu_disconnect(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100757 f_init_handler(pars);
Harald Welte66af9e62018-01-24 17:28:21 +0100758
759 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
760 var PDU_DTAP_MT dtap_mt;
761
762 /* tell GSUP dispatcher to send this IMSI to us */
763 f_create_gsup_expect(hex2str(g_pars.imsi));
764
765 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
766 f_bssap_compl_l3(l3_lu);
767
768 /* Send Early Classmark, just for the fun of it */
769 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
770
771 f_sleep(1.0);
772 /* send clear request in the middle of the LU */
773 BSSAP.send(BSSAP_Conn_Prim:MSC_CONN_PRIM_DISC_REQ);
774 setverdict(pass);
775}
776testcase TC_lu_disconnect() runs on MTC_CT {
777 var BSC_ConnHdlr vc_conn;
778 f_init();
779
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100780 vc_conn := f_start_handler(refers(f_tc_lu_disconnect), 11);
Harald Welte66af9e62018-01-24 17:28:21 +0100781 vc_conn.done;
782}
783
784
Harald Welteba7b6d92018-01-23 21:32:34 +0100785/* Test LU but with illegal mobile identity type = IMEI */
786private function f_tc_lu_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100787 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +0100788
Harald Welte256571e2018-01-24 18:47:19 +0100789 var PDU_ML3_MS_NW l3_lu := f_build_lu_imei(g_pars.imei)
Harald Welteba7b6d92018-01-23 21:32:34 +0100790 var PDU_DTAP_MT dtap_mt;
791
792 /* tell GSUP dispatcher to send this IMSI to us */
793 f_create_gsup_expect(hex2str(g_pars.imsi));
794
795 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
796 f_bssap_compl_l3(l3_lu);
797
798 /* Send Early Classmark, just for the fun of it */
799 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
800 /* wait for LU reject, ignore any ID REQ */
801 alt {
802 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { }
803 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req)) { repeat; }
804 }
805 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100806 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +0100807}
808testcase TC_lu_by_imei() runs on MTC_CT {
809 var BSC_ConnHdlr vc_conn;
810 f_init();
811
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100812 vc_conn := f_start_handler(refers(f_tc_lu_by_imei), 12);
Harald Welteba7b6d92018-01-23 21:32:34 +0100813 vc_conn.done;
814}
815
816/* Test LU by TMSI with unknown TMSI, expect (and answer) ID REQ. */
817private function f_tc_lu_tmsi_noauth_unknown(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Stefan Sperling04fc4bc2018-06-25 17:44:57 +0200818 /* We piggyback a test for an MSC crash on overlong IMSI (OS#2864) onto this test. */
819 var hexstring overlong_imsi := '012345789ABCDEF0123456789ABCDEF'H;
Harald Weltea10db902018-01-27 12:44:49 +0100820 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +0100821
822 var PDU_ML3_MS_NW l3_lu := f_build_lu_tmsi('01020304'O); /* FIXME: Random */
823 var PDU_DTAP_MT dtap_mt;
824
825 /* tell GSUP dispatcher to send this IMSI to us */
826 f_create_gsup_expect(hex2str(g_pars.imsi));
827
828 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
829 f_bssap_compl_l3(l3_lu);
830
831 /* Send Early Classmark, just for the fun of it */
832 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
833
834 /* Wait for + respond to ID REQ (IMSI) */
835 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req('001'B)));
Stefan Sperling04fc4bc2018-06-25 17:44:57 +0200836 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(overlong_imsi))); /* test for OS#2864 */
Harald Welteba7b6d92018-01-23 21:32:34 +0100837 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(g_pars.imsi)));
838
839 /* Expect MSC to do UpdateLocation to HLR; respond to it */
840 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
841 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
842 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
843 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
844
845 alt {
Harald Welte7ec4fa82018-01-27 10:57:40 +0100846 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
847 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_TmsiRealloc_Cmpl));
848 }
Harald Welteba7b6d92018-01-23 21:32:34 +0100849 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
850 setverdict(fail, "Expected LU ACK, but received REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200851 mtc.stop;
Harald Welteba7b6d92018-01-23 21:32:34 +0100852 }
853 }
854
855 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100856 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +0100857}
858testcase TC_lu_by_tmsi_noauth_unknown() runs on MTC_CT {
859 var BSC_ConnHdlr vc_conn;
860 f_init();
861
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100862 vc_conn := f_start_handler(refers(f_tc_lu_tmsi_noauth_unknown), 13);
Harald Welteba7b6d92018-01-23 21:32:34 +0100863 vc_conn.done;
864}
865
866
Harald Welte45164da2018-01-24 12:51:27 +0100867/* Test IMSI DETACH (MI=IMSI) */
868private function f_tc_imsi_detach_by_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100869 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +0100870
871 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
872
873 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
874 f_bssap_compl_l3(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
875
876 /* Send Early Classmark, just for the fun of it? */
877 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
878
879 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100880 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +0100881}
882testcase TC_imsi_detach_by_imsi() runs on MTC_CT {
883 var BSC_ConnHdlr vc_conn;
884 f_init();
885
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100886 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imsi), 14);
Harald Welte45164da2018-01-24 12:51:27 +0100887 vc_conn.done;
888}
889
890/* Test IMSI DETACH (MI=TMSI) */
891private function f_tc_imsi_detach_by_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100892 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +0100893
894 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV('01020304'O));
895
896 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
897 f_bssap_compl_l3(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
898
899 /* Send Early Classmark, just for the fun of it? */
900 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
901
902 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100903 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +0100904}
905testcase TC_imsi_detach_by_tmsi() runs on MTC_CT {
906 var BSC_ConnHdlr vc_conn;
907 f_init();
908
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100909 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_tmsi), 15);
Harald Welte45164da2018-01-24 12:51:27 +0100910 vc_conn.done;
911}
912
913/* Test IMSI DETACH (MI=IMEI), which is illegal */
914private function f_tc_imsi_detach_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100915 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +0100916
Harald Welte256571e2018-01-24 18:47:19 +0100917 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte45164da2018-01-24 12:51:27 +0100918
919 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
920 f_bssap_compl_l3(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
921
922 /* Send Early Classmark, just for the fun of it? */
923 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
924
925 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100926 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +0100927}
928testcase TC_imsi_detach_by_imei() runs on MTC_CT {
929 var BSC_ConnHdlr vc_conn;
930 f_init();
931
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100932 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imei), 16);
Harald Welte45164da2018-01-24 12:51:27 +0100933 vc_conn.done;
934}
935
936
937/* helper function for an emergency call. caller passes in mobile identity to use */
938private function f_emerg_call(MobileIdentityLV mi) runs on BSC_ConnHdlr {
Harald Welte0bef21e2018-02-10 09:48:23 +0100939 var CallParameters cpars := valueof(t_CallParams('112'H, 0));
940 cpars.emergency := true;
Philipp Maierf1e02bb2018-03-15 16:30:00 +0100941 cpars.mgcp_ep := "rtpbridge/1@mgw";
Harald Welte45164da2018-01-24 12:51:27 +0100942
Harald Welte0bef21e2018-02-10 09:48:23 +0100943 f_mo_call(cpars);
Harald Welte45164da2018-01-24 12:51:27 +0100944}
945
946/* establish an emergency call by IMEI, no SIM inserted (and hence no IMSI) */
947private function f_tc_emerg_call_imei_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100948 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +0100949
Harald Welte256571e2018-01-24 18:47:19 +0100950 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte6ed6bf92018-01-24 21:09:15 +0100951 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_EMERG_CALL, mi));
Harald Welte45164da2018-01-24 12:51:27 +0100952 f_bssap_compl_l3(l3_info);
953 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ('05'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +0100954 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +0100955}
956testcase TC_emerg_call_imei_reject() runs on MTC_CT {
957 var BSC_ConnHdlr vc_conn;
958 f_init();
959
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100960 vc_conn := f_start_handler(refers(f_tc_emerg_call_imei_reject), 17);
Harald Welte45164da2018-01-24 12:51:27 +0100961 vc_conn.done;
962}
963
Harald Welted5b91402018-01-24 18:48:16 +0100964/* establish an emergency call by IMSI, SIM inserted (and hence IMSI) */
Harald Welte45164da2018-01-24 12:51:27 +0100965private function f_tc_emerg_call_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100966 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +0100967 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100968 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +0100969 /* Then issue emergency call identified by IMSI */
970 f_emerg_call(valueof(ts_MI_IMSI_LV(g_pars.imsi)));
971}
972testcase TC_emerg_call_imsi() runs on MTC_CT {
973 var BSC_ConnHdlr vc_conn;
974 f_init();
975
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100976 vc_conn := f_start_handler(refers(f_tc_emerg_call_imsi), 18);
Harald Welte45164da2018-01-24 12:51:27 +0100977 vc_conn.done;
978}
979
980/* CM Service Request for VGCS -> reject */
981private function f_tc_cm_serv_req_vgcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100982 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +0100983
984 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100985 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +0100986
987 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +0100988 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VGCS, mi));
Harald Welte45164da2018-01-24 12:51:27 +0100989 f_bssap_compl_l3(l3_info);
990 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +0100991 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +0100992}
993testcase TC_cm_serv_req_vgcs_reject() runs on MTC_CT {
994 var BSC_ConnHdlr vc_conn;
995 f_init();
996
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100997 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vgcs_reject), 19);
Harald Welte45164da2018-01-24 12:51:27 +0100998 vc_conn.done;
999}
1000
1001/* CM Service Request for VBS -> reject */
1002private function f_tc_cm_serv_req_vbs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001003 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001004
1005 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001006 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001007
1008 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001009 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VBS, mi));
Harald Welte45164da2018-01-24 12:51:27 +01001010 f_bssap_compl_l3(l3_info);
1011 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001012 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001013}
1014testcase TC_cm_serv_req_vbs_reject() runs on MTC_CT {
1015 var BSC_ConnHdlr vc_conn;
1016 f_init();
1017
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001018 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vbs_reject), 20);
Harald Welte45164da2018-01-24 12:51:27 +01001019 vc_conn.done;
1020}
1021
1022/* CM Service Request for LCS -> reject */
1023private function f_tc_cm_serv_req_lcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001024 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001025
1026 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001027 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001028
1029 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001030 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_LCS, mi));
Harald Welte45164da2018-01-24 12:51:27 +01001031 f_bssap_compl_l3(l3_info);
1032 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001033 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001034}
1035testcase TC_cm_serv_req_lcs_reject() runs on MTC_CT {
1036 var BSC_ConnHdlr vc_conn;
1037 f_init();
1038
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001039 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_lcs_reject), 21);
Harald Welte45164da2018-01-24 12:51:27 +01001040 vc_conn.done;
1041}
1042
Harald Welte0195ab12018-01-24 21:50:20 +01001043/* CM Re-Establishment Request */
1044private function f_tc_cm_reest_req_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001045 f_init_handler(pars);
Harald Welte0195ab12018-01-24 21:50:20 +01001046
1047 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001048 f_perform_lu();
Harald Welte0195ab12018-01-24 21:50:20 +01001049
1050 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1051 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_REEST_REQ(0, mi));
1052 f_bssap_compl_l3(l3_info);
1053 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001054 f_expect_clear();
Harald Welte0195ab12018-01-24 21:50:20 +01001055}
1056testcase TC_cm_reest_req_reject() runs on MTC_CT {
1057 var BSC_ConnHdlr vc_conn;
1058 f_init();
Harald Welte0195ab12018-01-24 21:50:20 +01001059
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001060 vc_conn := f_start_handler(refers(f_tc_cm_reest_req_reject), 22);
Harald Welte0195ab12018-01-24 21:50:20 +01001061 vc_conn.done;
1062}
1063
Harald Weltec638f4d2018-01-24 22:00:36 +01001064/* Test LU (with authentication enabled), with wrong response from MS */
1065private function f_tc_lu_auth_2G_fail(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001066 f_init_handler(pars);
Harald Weltec638f4d2018-01-24 22:00:36 +01001067
1068 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
1069
1070 /* tell GSUP dispatcher to send this IMSI to us */
1071 f_create_gsup_expect(hex2str(g_pars.imsi));
1072
1073 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
1074 f_bssap_compl_l3(l3_lu);
1075
1076 /* Send Early Classmark, just for the fun of it */
1077 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1078
1079 var AuthVector vec := f_gen_auth_vec_2g();
1080 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G(vec.rand, vec.sres, vec.kc));
1081 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
1082 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
1083
1084 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_AUTH_REQ(vec.rand)));
1085 /* Send back wrong auth response */
1086 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MT_MM_AUTH_RESP_2G('00000000'O)));
1087
1088 /* Expect GSUP AUTH FAIL REP to HLR */
1089 GSUP.receive(tr_GSUP_AUTH_FAIL_IND(g_pars.imsi));
1090
1091 /* Expect LU REJECT with Cause == Illegal MS */
1092 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej('03'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +01001093 f_expect_clear();
Harald Weltec638f4d2018-01-24 22:00:36 +01001094}
1095testcase TC_lu_auth_2G_fail() runs on MTC_CT {
1096 var BSC_ConnHdlr vc_conn;
1097 f_init();
1098 f_vty_config(MSCVTY, "network", "authentication required");
Harald Weltec638f4d2018-01-24 22:00:36 +01001099
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001100 vc_conn := f_start_handler(refers(f_tc_lu_auth_2G_fail), 23);
Harald Weltec638f4d2018-01-24 22:00:36 +01001101 vc_conn.done;
1102}
1103
Harald Weltede371492018-01-27 23:44:41 +01001104/* A5/1 + A5/3 permitted on network side, and MS capable to do it */
Harald Welte16114282018-01-24 22:41:21 +01001105private function f_tc_lu_imsi_auth_tmsi_encr_13_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +01001106 pars.net.expect_auth := true;
1107 pars.net.expect_ciph := true;
Harald Weltea10db902018-01-27 12:44:49 +01001108 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001109 f_perform_lu();
Harald Welte16114282018-01-24 22:41:21 +01001110}
1111testcase TC_lu_imsi_auth_tmsi_encr_13_13() runs on MTC_CT {
1112 var BSC_ConnHdlr vc_conn;
1113 f_init();
1114 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte16114282018-01-24 22:41:21 +01001115 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
1116
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001117 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_13), 24);
Harald Welte16114282018-01-24 22:41:21 +01001118 vc_conn.done;
1119}
1120
Harald Welte1af6ea82018-01-25 18:33:15 +01001121/* Test Complete L3 without payload */
1122private function f_tc_cl3_no_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001123 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001124
1125 /* Send Complete L3 Info with empty L3 frame */
1126 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1127 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, ''O))));
1128
Harald Weltef466eb42018-01-27 14:26:54 +01001129 timer T := 5.0;
1130 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001131 alt {
1132 [] BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
1133 /* Expect LU REJECT with Cause == Illegal MS */
Harald Weltebdb3c452018-03-18 22:43:06 +01001134 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
1135 [] BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001136 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001137 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001138 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001139 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001140 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001141 }
1142 setverdict(pass);
1143}
1144testcase TC_cl3_no_payload() runs on MTC_CT {
1145 var BSC_ConnHdlr vc_conn;
1146 f_init();
1147
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001148 vc_conn := f_start_handler(refers(f_tc_cl3_no_payload), 25);
Harald Welte1af6ea82018-01-25 18:33:15 +01001149 vc_conn.done;
1150}
1151
1152/* Test Complete L3 with random payload */
1153private function f_tc_cl3_rnd_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001154 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001155
Daniel Willmannaa14a382018-07-26 08:29:45 +02001156 /* length is limited by PDU_BSSAP length field which includes some
1157 * other fields beside l3info payload. So payl can only be 240 bytes
1158 * Since rnd() returns values < 1 multiply with 241
1159 */
1160 var integer len := float2int(rnd() * 241.0);
Harald Welte1af6ea82018-01-25 18:33:15 +01001161 var octetstring payl := f_rnd_octstring(len);
1162
1163 /* Send Complete L3 Info with empty L3 frame */
1164 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1165 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, payl))));
1166
Harald Weltef466eb42018-01-27 14:26:54 +01001167 timer T := 5.0;
1168 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001169 alt {
1170 /* Immediate disconnect */
1171 [] BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte1af6ea82018-01-25 18:33:15 +01001172 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
Harald Weltebdb3c452018-03-18 22:43:06 +01001173 [] BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001174 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001175 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001176 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001177 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001178 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001179 }
1180 setverdict(pass);
1181}
1182testcase TC_cl3_rnd_payload() runs on MTC_CT {
1183 var BSC_ConnHdlr vc_conn;
1184 f_init();
1185
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001186 vc_conn := f_start_handler(refers(f_tc_cl3_rnd_payload), 26);
Harald Welte1af6ea82018-01-25 18:33:15 +01001187 vc_conn.done;
1188}
1189
Harald Welte116e4332018-01-26 22:17:48 +01001190/* Test Complete L3 with random payload */
1191private function f_tc_establish_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001192 f_init_handler(pars);
Harald Welte116e4332018-01-26 22:17:48 +01001193
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001194 f_perform_lu();
Harald Welte116e4332018-01-26 22:17:48 +01001195
Harald Welteb9e86fa2018-04-09 18:18:31 +02001196 f_establish_fully();
Daniel Willmann898a7e02018-05-17 12:16:16 +02001197 f_expect_clear(10.0);
Harald Welte116e4332018-01-26 22:17:48 +01001198}
1199testcase TC_establish_and_nothing() runs on MTC_CT {
1200 var BSC_ConnHdlr vc_conn;
1201 f_init();
1202
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001203 vc_conn := f_start_handler(refers(f_tc_establish_and_nothing), 27);
Harald Welte116e4332018-01-26 22:17:48 +01001204 vc_conn.done;
1205}
1206
Harald Welte12510c52018-01-26 22:26:24 +01001207/* Test MO Call SETUP with no response from MNCC */
1208private function f_tc_mo_setup_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier109e6aa2018-10-17 10:53:32 +02001209 f_init_handler(pars, 190.0);
Harald Weltea10db902018-01-27 12:44:49 +01001210
Harald Welte12510c52018-01-26 22:26:24 +01001211 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1212
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001213 f_perform_lu();
Harald Welte12510c52018-01-26 22:26:24 +01001214
Harald Welteb9e86fa2018-04-09 18:18:31 +02001215 f_establish_fully();
Harald Welte12510c52018-01-26 22:26:24 +01001216 f_create_mncc_expect(hex2str(cpars.called_party));
1217 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1218
1219 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
1220
Philipp Maier109e6aa2018-10-17 10:53:32 +02001221 f_expect_clear(185.0);
Harald Welte12510c52018-01-26 22:26:24 +01001222}
1223testcase TC_mo_setup_and_nothing() runs on MTC_CT {
1224 var BSC_ConnHdlr vc_conn;
1225 f_init();
1226
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001227 vc_conn := f_start_handler(refers(f_tc_mo_setup_and_nothing), 28);
Harald Welte12510c52018-01-26 22:26:24 +01001228 vc_conn.done;
1229}
1230
Harald Welte3ab88002018-01-26 22:37:25 +01001231/* Test MO Call with no response to RAN-side CRCX */
1232private function f_tc_mo_crcx_ran_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001233 f_init_handler(pars);
Harald Welte3ab88002018-01-26 22:37:25 +01001234 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1235 var MNCC_PDU mncc;
1236 var MgcpCommand mgcp_cmd;
1237
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001238 f_perform_lu();
Harald Welte3ab88002018-01-26 22:37:25 +01001239
Harald Welteb9e86fa2018-04-09 18:18:31 +02001240 f_establish_fully();
Harald Welte3ab88002018-01-26 22:37:25 +01001241 f_create_mncc_expect(hex2str(cpars.called_party));
1242 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1243
1244 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
1245 MNCC.receive(tr_MNCC_SETUP_ind(?, tr_MNCC_number(hex2str(cpars.called_party)))) -> value mncc;
1246 cpars.mncc_callref := mncc.u.signal.callref;
1247 MNCC.send(ts_MNCC_CALL_PROC_req(cpars.mncc_callref, cpars.mncc_bearer_cap));
1248 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_CALL_PROC(cpars.transaction_id)));
1249
1250 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
Harald Welte1852a842018-01-26 22:53:36 +01001251 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
1252 cpars.mgcp_ep := mgcp_cmd.line.ep;
Harald Welte3ab88002018-01-26 22:37:25 +01001253 /* never respond to this */
1254
Philipp Maier8e58f592018-03-14 11:10:56 +01001255 /* When the connection with the MGW fails, the MSC will first request
1256 * a release via call control. We will answer this request normally. */
1257 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id)));
1258 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id)));
1259
Harald Welte1ddc7162018-01-27 14:25:46 +01001260 f_expect_clear(30.0);
Harald Welte3ab88002018-01-26 22:37:25 +01001261}
1262testcase TC_mo_crcx_ran_timeout() runs on MTC_CT {
1263 var BSC_ConnHdlr vc_conn;
1264 f_init();
1265
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001266 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_timeout), 29);
Harald Welte3ab88002018-01-26 22:37:25 +01001267 vc_conn.done;
1268}
1269
Harald Welte0cc82d92018-01-26 22:52:34 +01001270/* Test MO Call with reject to RAN-side CRCX */
1271private function f_tc_mo_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001272 f_init_handler(pars);
Harald Welte0cc82d92018-01-26 22:52:34 +01001273 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1274 var MNCC_PDU mncc;
1275 var MgcpCommand mgcp_cmd;
1276
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001277 f_perform_lu();
Harald Welte0cc82d92018-01-26 22:52:34 +01001278
Harald Welteb9e86fa2018-04-09 18:18:31 +02001279 f_establish_fully();
Harald Welte0cc82d92018-01-26 22:52:34 +01001280 f_create_mncc_expect(hex2str(cpars.called_party));
1281 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1282
1283 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
1284 MNCC.receive(tr_MNCC_SETUP_ind(?, tr_MNCC_number(hex2str(cpars.called_party)))) -> value mncc;
1285 cpars.mncc_callref := mncc.u.signal.callref;
1286 MNCC.send(ts_MNCC_CALL_PROC_req(cpars.mncc_callref, cpars.mncc_bearer_cap));
1287 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_CALL_PROC(cpars.transaction_id)));
1288
1289 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001290
1291 /* Detect if the received CRCX is a wildcarded CRCX request. If yes,
1292 * set an endpoint name that fits the pattern. If not, just use the
1293 * endpoint name from the request */
1294 if (match(mgcp_cmd.line.ep, t_MGCP_EP_wildcard)) {
1295 cpars.mgcp_ep := "rtpbridge/1@mgw";
1296 } else {
1297 cpars.mgcp_ep := mgcp_cmd.line.ep;
1298 }
1299
Harald Welte0cc82d92018-01-26 22:52:34 +01001300 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001301
Harald Welte0cc82d92018-01-26 22:52:34 +01001302 /* Respond to CRCX with error */
1303 var MgcpResponse mgcp_rsp := {
1304 line := {
1305 code := "542",
1306 trans_id := mgcp_cmd.line.trans_id,
1307 string := "FORCED_FAIL"
1308 },
Harald Welte0cc82d92018-01-26 22:52:34 +01001309 sdp := omit
1310 }
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001311 var MgcpParameter mgcp_rsp_param := {
1312 code := "Z",
1313 val := cpars.mgcp_ep
1314 };
1315 mgcp_rsp.params[0] := mgcp_rsp_param;
Harald Welte0cc82d92018-01-26 22:52:34 +01001316 MGCP.send(mgcp_rsp);
1317
1318 timer T := 30.0;
1319 T.start;
1320 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001321 [] T.timeout {
1322 setverdict(fail, "Timeout waiting for channel release");
1323 mtc.stop;
1324 }
Daniel Willmann5868e622018-02-15 17:42:59 +01001325 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id))) {
1326 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id)));
1327 repeat;
1328 }
Harald Welte0cc82d92018-01-26 22:52:34 +01001329 [] MNCC.receive { repeat; }
1330 [] GSUP.receive { repeat; }
Philipp Maierc6e06f72018-04-11 18:12:23 +02001331 /* Note: As we did not respond properly to the CRCX from the MSC we
1332 * expect the MSC to omit any further MGCP operation (At least in the
1333 * the current implementation, there is no recovery mechanism implemented
1334 * and a DLCX can not be performed as the MSC does not know a specific
1335 * endpoint yet. */
Daniel Willmannafce8662018-07-06 23:11:32 +02001336 [] MGCP.receive {
1337 setverdict(fail, "Unexpected MGCP message");
1338 mtc.stop;
1339 }
Harald Welte5946b332018-03-18 23:32:21 +01001340 [] as_clear_cmd_compl_disc();
Harald Welte0cc82d92018-01-26 22:52:34 +01001341 }
1342}
1343testcase TC_mo_crcx_ran_reject() runs on MTC_CT {
1344 var BSC_ConnHdlr vc_conn;
1345 f_init();
1346
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001347 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_reject), 30);
Harald Welte0cc82d92018-01-26 22:52:34 +01001348 vc_conn.done;
1349}
1350
Harald Welte3ab88002018-01-26 22:37:25 +01001351
Harald Welte812f7a42018-01-27 00:49:18 +01001352/* helper function to start a MT call: MNCC SETUP; Paging; DChan est.; DTAP SETUP */
1353private function f_mt_call_start(inout CallParameters cpars) runs on BSC_ConnHdlr {
1354 var MNCC_PDU mncc;
1355 var MgcpCommand mgcp_cmd;
1356 var OCT4 tmsi;
1357
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001358 f_perform_lu();
Harald Welte812f7a42018-01-27 00:49:18 +01001359 if (isvalue(g_pars.tmsi)) {
1360 tmsi := g_pars.tmsi;
1361 } else {
1362 tmsi := 'FFFFFFFF'O;
1363 }
1364 f_bssmap_register_imsi(g_pars.imsi, tmsi);
1365
1366 /* Allocate call reference and send SETUP via MNCC to MSC */
1367 cpars.mncc_callref := f_rnd_int(2147483648);
1368 MNCC.send(ts_MNCC_SETUP_req(cpars.mncc_callref, hex2str(g_pars.msisdn),
1369 hex2str(cpars.called_party), hex2str(g_pars.imsi)));
1370
1371 /* MSC->BSC: expect PAGING from MSC */
1372 BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi));
1373 /* MS -> MSC: PAGING RESPONSE */
Harald Welteb9e86fa2018-04-09 18:18:31 +02001374 f_establish_fully(EST_TYPE_PAG_RESP);
Harald Welte812f7a42018-01-27 00:49:18 +01001375
1376 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1377
1378 /* MSC->MS: SETUP */
1379 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_SETUP(cpars.transaction_id, *, cpars.called_party)));
1380}
1381
1382/* Test MT Call */
1383private function f_tc_mt_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001384 f_init_handler(pars);
Harald Welte812f7a42018-01-27 00:49:18 +01001385 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1386 var MNCC_PDU mncc;
1387 var MgcpCommand mgcp_cmd;
1388
1389 f_mt_call_start(cpars);
1390
1391 /* MS->MSC: CALL CONFIRMED */
1392 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1393
1394 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1395
1396 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1397 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001398
1399 /* Detect if the received CRCX is a wildcarded CRCX request. If yes,
1400 * set an endpoint name that fits the pattern. If not, just use the
1401 * endpoint name from the request */
1402 if (match(mgcp_cmd.line.ep, t_MGCP_EP_wildcard)) {
1403 cpars.mgcp_ep := "rtpbridge/1@mgw";
1404 } else {
1405 cpars.mgcp_ep := mgcp_cmd.line.ep;
1406 }
1407
Harald Welte812f7a42018-01-27 00:49:18 +01001408 /* Respond to CRCX with error */
1409 var MgcpResponse mgcp_rsp := {
1410 line := {
1411 code := "542",
1412 trans_id := mgcp_cmd.line.trans_id,
1413 string := "FORCED_FAIL"
1414 },
Harald Welte812f7a42018-01-27 00:49:18 +01001415 sdp := omit
1416 }
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001417 var MgcpParameter mgcp_rsp_param := {
1418 code := "Z",
1419 val := cpars.mgcp_ep
1420 };
1421 mgcp_rsp.params[0] := mgcp_rsp_param;
Harald Welte812f7a42018-01-27 00:49:18 +01001422 MGCP.send(mgcp_rsp);
1423
1424 timer T := 30.0;
1425 T.start;
1426 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001427 [] T.timeout {
1428 setverdict(fail, "Timeout waiting for channel release");
1429 mtc.stop;
1430 }
Harald Welte812f7a42018-01-27 00:49:18 +01001431 [] BSSAP.receive { repeat; }
1432 [] MNCC.receive { repeat; }
1433 [] GSUP.receive { repeat; }
1434 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1435 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
1436 f_create_mgcp_delete_ep(cpars.mgcp_ep);
1437 repeat;
1438 }
1439 [] MGCP.receive { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001440 [] as_clear_cmd_compl_disc();
Harald Welte812f7a42018-01-27 00:49:18 +01001441 }
1442}
1443testcase TC_mt_crcx_ran_reject() runs on MTC_CT {
1444 var BSC_ConnHdlr vc_conn;
1445 f_init();
1446
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001447 vc_conn := f_start_handler(refers(f_tc_mt_crcx_ran_reject), 31);
Harald Welte812f7a42018-01-27 00:49:18 +01001448 vc_conn.done;
1449}
1450
1451
1452/* Test MT Call T310 timer */
1453private function f_tc_mt_t310(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltead2952e2018-01-27 14:12:46 +01001454 f_init_handler(pars, 200.0);
Harald Welte812f7a42018-01-27 00:49:18 +01001455 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1456 var MNCC_PDU mncc;
1457 var MgcpCommand mgcp_cmd;
1458
1459 f_mt_call_start(cpars);
1460
1461 /* MS->MSC: CALL CONFIRMED */
1462 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1463 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1464
1465 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1466 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
1467 cpars.mgcp_ep := mgcp_cmd.line.ep;
1468 /* FIXME: Respond to CRCX */
1469
1470 /* old libosmocore T310 default timeout is 180s. so let's wait 190 */
1471 timer T := 190.0;
1472 T.start;
1473 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001474 [] T.timeout {
1475 setverdict(fail, "Timeout waiting for T310");
1476 mtc.stop;
1477 }
Harald Welte812f7a42018-01-27 00:49:18 +01001478 [] MNCC.receive(tr_MNCC_DISC_ind(cpars.mncc_callref)) {
1479 MNCC.send(ts_MNCC_REL_req(cpars.mncc_callref, valueof(ts_MNCC_cause(23))));
1480 }
1481 }
1482 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_DISC(cpars.transaction_id)));
1483 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id)));
1484 /* FIXME: We're sending this with TIflag 0: allocated by sender, which is wrong */
1485 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id)));
1486
1487 alt {
Harald Welte812f7a42018-01-27 00:49:18 +01001488 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1489 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
1490 f_create_mgcp_delete_ep(cpars.mgcp_ep);
1491 repeat;
1492 }
Harald Welte5946b332018-03-18 23:32:21 +01001493 [] as_clear_cmd_compl_disc();
Harald Welte812f7a42018-01-27 00:49:18 +01001494 }
1495}
1496testcase TC_mt_t310() runs on MTC_CT {
1497 var BSC_ConnHdlr vc_conn;
1498 f_init();
1499
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001500 vc_conn := f_start_handler(refers(f_tc_mt_t310), 32);
Harald Welte812f7a42018-01-27 00:49:18 +01001501 vc_conn.done;
1502}
1503
Harald Welte167458a2018-01-27 15:58:16 +01001504/* Perform successful LU + MO call, then GSUP LocationCancel. Subscriber must be denied CM SERV */
1505private function f_tc_gsup_cancel(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1506 f_init_handler(pars);
1507 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1508 cpars.bss_rtp_port := 1110;
1509 cpars.mgcp_connection_id_bss := '22222'H;
1510 cpars.mgcp_connection_id_mss := '33333'H;
Daniel Willmann9b0235b2018-07-24 12:13:34 +02001511 cpars.mgcp_ep := "rtpbridge/1@mgw";
Harald Welte167458a2018-01-27 15:58:16 +01001512
1513 /* Location Update to make subscriber known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001514 f_perform_lu();
Harald Welte167458a2018-01-27 15:58:16 +01001515
1516 /* First MO call should succeed */
1517 f_mo_call(cpars);
1518
1519 /* Cancel the subscriber in the VLR */
1520 GSUP.send(ts_GSUP_CL_REQ(g_pars.imsi, OSMO_GSUP_CANCEL_TYPE_WITHDRAW));
1521 alt {
1522 [] GSUP.receive(tr_GSUP_CL_RES(g_pars.imsi)) { }
1523 [] GSUP.receive(tr_GSUP_CL_ERR(g_pars.imsi)) {
1524 setverdict(fail, "Received GSUP Location Cancel Error");
Daniel Willmannafce8662018-07-06 23:11:32 +02001525 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001526 }
1527 }
1528
1529 /* Follow-up transactions should fail */
1530 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1531 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
1532 f_bssap_compl_l3(l3_info);
1533 alt {
1534 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
1535 [] BSSAP.receive {
1536 setverdict(fail, "Received unexpected BSSAP instead of CM SERV REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +02001537 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001538 }
1539 }
1540 setverdict(pass);
1541}
1542testcase TC_gsup_cancel() runs on MTC_CT {
1543 var BSC_ConnHdlr vc_conn;
1544 f_init();
1545
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001546 vc_conn := f_start_handler(refers(f_tc_gsup_cancel), 33);
Harald Welte167458a2018-01-27 15:58:16 +01001547 vc_conn.done;
1548}
1549
Harald Welte9de84792018-01-28 01:06:35 +01001550/* A5/1 only permitted on network side, and MS capable to do it */
1551private function f_tc_lu_imsi_auth_tmsi_encr_1_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1552 pars.net.expect_auth := true;
1553 pars.net.expect_ciph := true;
1554 pars.net.kc_support := '02'O; /* A5/1 only */
1555 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001556 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001557}
1558testcase TC_lu_imsi_auth_tmsi_encr_1_13() runs on MTC_CT {
1559 var BSC_ConnHdlr vc_conn;
1560 f_init();
1561 f_vty_config(MSCVTY, "network", "authentication required");
1562 f_vty_config(MSCVTY, "network", "encryption a5 1");
1563
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001564 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_1_13), 34);
Harald Welte9de84792018-01-28 01:06:35 +01001565 vc_conn.done;
1566}
1567
1568/* A5/3 only permitted on network side, and MS capable to do it */
1569private function f_tc_lu_imsi_auth_tmsi_encr_3_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1570 pars.net.expect_auth := true;
1571 pars.net.expect_ciph := true;
1572 pars.net.kc_support := '08'O; /* A5/3 only */
1573 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001574 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001575}
1576testcase TC_lu_imsi_auth_tmsi_encr_3_13() runs on MTC_CT {
1577 var BSC_ConnHdlr vc_conn;
1578 f_init();
1579 f_vty_config(MSCVTY, "network", "authentication required");
1580 f_vty_config(MSCVTY, "network", "encryption a5 3");
1581
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001582 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_13), 35);
Harald Welte9de84792018-01-28 01:06:35 +01001583 vc_conn.done;
1584}
1585
1586/* A5/3 only permitted on network side, and MS with only A5/1 support */
1587private function f_tc_lu_imsi_auth_tmsi_encr_3_1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1588 pars.net.expect_auth := true;
1589 pars.net.expect_ciph := true;
1590 pars.net.kc_support := '08'O; /* A5/3 only */
1591 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1592 f_init_handler(pars, 15.0);
1593
1594 /* cannot use f_perform_lu() as we expect a reject */
1595 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
1596 f_create_gsup_expect(hex2str(g_pars.imsi));
1597 f_bssap_compl_l3(l3_lu);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001598 if (pars.send_early_cm) {
1599 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1600 } else {
1601 pars.cm1.esind := '0'B;
1602 }
Harald Welte9de84792018-01-28 01:06:35 +01001603 f_mm_auth();
1604 alt {
Daniel Willmann52918e52018-09-20 14:39:09 +02001605 [] BSSAP.receive(tr_BSSMAP_ClassmarkReq) {
1606 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1607 repeat;
1608 }
Harald Welte5946b332018-03-18 23:32:21 +01001609 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1610 f_expect_clear();
1611 }
Harald Welte9de84792018-01-28 01:06:35 +01001612 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
1613 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02001614 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001615 }
1616 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01001617 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02001618 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001619 }
1620 }
1621 setverdict(pass);
1622}
1623testcase TC_lu_imsi_auth_tmsi_encr_3_1() runs on MTC_CT {
1624 var BSC_ConnHdlr vc_conn;
1625 f_init();
1626 f_vty_config(MSCVTY, "network", "authentication required");
1627 f_vty_config(MSCVTY, "network", "encryption a5 3");
1628
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001629 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 360);
1630 vc_conn.done;
1631}
1632testcase TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() runs on MTC_CT {
1633 var BSC_ConnHdlrPars pars;
1634 var BSC_ConnHdlr vc_conn;
1635 f_init();
1636 f_vty_config(MSCVTY, "network", "authentication required");
1637 f_vty_config(MSCVTY, "network", "encryption a5 3");
1638
1639 pars := f_init_pars(361);
1640 pars.send_early_cm := false;
1641 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), pars);
Harald Welte9de84792018-01-28 01:06:35 +01001642 vc_conn.done;
1643}
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01001644testcase TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() runs on MTC_CT {
1645 var BSC_ConnHdlr vc_conn;
1646 f_init();
1647 f_vty_config(MSCVTY, "network", "authentication required");
1648 f_vty_config(MSCVTY, "network", "encryption a5 3");
1649
1650 /* Make sure the MSC category is on DEBUG level to trigger the log
1651 * message that is reported in OS#2947 to trigger the segfault */
1652 f_vty_config(MSCVTY, "log stderr", "logging level msc debug");
1653
1654 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 362);
1655 vc_conn.done;
1656}
Harald Welte9de84792018-01-28 01:06:35 +01001657
1658/* A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
1659private function f_tc_lu_imsi_auth_tmsi_encr_13_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1660 pars.net.expect_auth := true;
1661 pars.net.expect_ciph := true;
1662 pars.net.kc_support := '0A'O; /* A5/1 + A5/3 */
1663 pars.cm1.a5_1 := '1'B;
1664 pars.cm2.a5_1 := '1'B;
1665 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1666 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
1667 f_init_handler(pars, 15.0);
1668
1669 /* cannot use f_perform_lu() as we expect a reject */
1670 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
1671 f_create_gsup_expect(hex2str(g_pars.imsi));
1672 f_bssap_compl_l3(l3_lu);
1673 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1674 f_mm_auth();
1675 alt {
Harald Welte5946b332018-03-18 23:32:21 +01001676 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1677 f_expect_clear();
1678 }
Harald Welte9de84792018-01-28 01:06:35 +01001679 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
1680 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02001681 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001682 }
1683 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01001684 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02001685 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001686 }
1687 }
1688 setverdict(pass);
1689}
1690testcase TC_lu_imsi_auth_tmsi_encr_13_2() runs on MTC_CT {
1691 var BSC_ConnHdlr vc_conn;
1692 f_init();
1693 f_vty_config(MSCVTY, "network", "authentication required");
1694 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
1695
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001696 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_2), 37);
Harald Welte9de84792018-01-28 01:06:35 +01001697 vc_conn.done;
1698}
1699
1700/* A5/0 + A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
1701private function f_tc_lu_imsi_auth_tmsi_encr_013_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1702 pars.net.expect_auth := true;
1703 pars.net.expect_ciph := true;
1704 pars.net.kc_support := '0B'O; /* A5/1 + A5/3 */
1705 pars.cm1.a5_1 := '1'B;
1706 pars.cm2.a5_1 := '1'B;
1707 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1708 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
1709 f_init_handler(pars, 15.0);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001710 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001711}
1712testcase TC_lu_imsi_auth_tmsi_encr_013_2() runs on MTC_CT {
1713 var BSC_ConnHdlr vc_conn;
1714 f_init();
1715 f_vty_config(MSCVTY, "network", "authentication required");
1716 f_vty_config(MSCVTY, "network", "encryption a5 0 1 3");
1717
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001718 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_013_2), 38);
Harald Welte9de84792018-01-28 01:06:35 +01001719 vc_conn.done;
1720}
1721
Harald Welte33ec09b2018-02-10 15:34:46 +01001722/* LU followed by MT call (including paging) */
1723private function f_tc_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1724 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01001725 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Harald Welte33ec09b2018-02-10 15:34:46 +01001726 cpars.bss_rtp_port := 1110;
1727 cpars.mgcp_connection_id_bss := '10004'H;
1728 cpars.mgcp_connection_id_mss := '10005'H;
1729
Philipp Maier4b2692d2018-03-14 16:37:48 +01001730 /* Note: This is an optional parameter. When the call-agent (MSC) does
1731 * supply a full endpoint name this setting will be overwritten. */
1732 cpars.mgcp_ep := "rtpbridge/1@mgw";
1733
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001734 f_perform_lu();
Harald Welte33ec09b2018-02-10 15:34:46 +01001735 f_mt_call(cpars);
1736}
1737testcase TC_lu_and_mt_call() runs on MTC_CT {
1738 var BSC_ConnHdlr vc_conn;
1739 f_init();
1740
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001741 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call), 39);
Harald Welte33ec09b2018-02-10 15:34:46 +01001742 vc_conn.done;
1743}
1744
Daniel Willmann8b084372018-02-04 13:35:26 +01001745/* Test MO Call SETUP with DTMF */
1746private function f_tc_mo_setup_dtmf_dup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1747 f_init_handler(pars);
1748 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1749 cpars.bss_rtp_port := 1110;
1750 cpars.mgcp_connection_id_bss := '22222'H;
1751 cpars.mgcp_connection_id_mss := '33333'H;
1752
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001753 f_perform_lu();
Daniel Willmann8b084372018-02-04 13:35:26 +01001754 f_mo_seq_dtmf_dup(cpars);
1755}
1756testcase TC_mo_setup_and_dtmf_dup() runs on MTC_CT {
1757 var BSC_ConnHdlr vc_conn;
1758 f_init();
1759
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001760 vc_conn := f_start_handler(refers(f_tc_mo_setup_dtmf_dup), 39);
Daniel Willmann8b084372018-02-04 13:35:26 +01001761 vc_conn.done;
1762}
Harald Welte9de84792018-01-28 01:06:35 +01001763
Philipp Maier328d1662018-03-07 10:40:27 +01001764testcase TC_cr_before_reset() runs on MTC_CT {
1765 timer T := 4.0;
1766 var boolean reset_ack_seen := false;
1767 f_init_bssap_direct();
1768
Daniel Willmann42d1d5b2018-08-07 15:18:41 +02001769 f_bssap_start(g_bssap[0]);
1770
Daniel Willmanne8018962018-08-21 14:18:00 +02001771 f_sleep(3.0);
1772
Philipp Maier328d1662018-03-07 10:40:27 +01001773 /* Make a blind connection attemt, to trigger the deadlock condition */
Philipp Maier75932982018-03-27 14:52:35 +02001774 BSSAP_DIRECT.send(ts_BSSAP_CONNECT_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, 1, omit));
Philipp Maier328d1662018-03-07 10:40:27 +01001775
1776 /* Send a BSSMAP reset */
Philipp Maier75932982018-03-27 14:52:35 +02001777 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_Reset(0)));
Philipp Maier328d1662018-03-07 10:40:27 +01001778 T.start
1779 alt {
1780 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_ResetAck)) {
1781 reset_ack_seen := true;
1782 repeat;
1783 }
1784
1785 /* Acknowledge MSC sided reset requests */
1786 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_Reset)) {
Philipp Maier75932982018-03-27 14:52:35 +02001787 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_ResetAck));
Philipp Maier328d1662018-03-07 10:40:27 +01001788 repeat;
1789 }
1790
1791 /* Ignore all other messages (e.g CR from the connection request) */
1792 [] BSSAP_DIRECT.receive { repeat }
1793
1794 /* If we got no BSSMAP RESET ACK back, then the MSC entered the
1795 * deadlock situation. The MSC is then unable to respond to any
1796 * further BSSMAP RESET or any other sort of traffic. */
1797 [reset_ack_seen == true] T.timeout { setverdict(pass) }
1798 [reset_ack_seen == false] T.timeout {
1799 setverdict(fail, "no BSSMAP RESET ACK seen!");
Daniel Willmannafce8662018-07-06 23:11:32 +02001800 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +01001801 }
1802 }
1803}
Harald Welte9de84792018-01-28 01:06:35 +01001804
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001805/* Test MO Call with no response to RAN-side CRCX or DTAP Release */
1806private function f_tc_mo_release_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1807 f_init_handler(pars);
1808 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1809 var MNCC_PDU mncc;
1810 var MgcpCommand mgcp_cmd;
1811
1812 f_perform_lu();
1813
Harald Welteb9e86fa2018-04-09 18:18:31 +02001814 f_establish_fully();
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001815 f_create_mncc_expect(hex2str(cpars.called_party));
1816 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1817
1818 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
1819 MNCC.receive(tr_MNCC_SETUP_ind(?, tr_MNCC_number(hex2str(cpars.called_party)))) -> value mncc;
1820 cpars.mncc_callref := mncc.u.signal.callref;
1821 MNCC.send(ts_MNCC_CALL_PROC_req(cpars.mncc_callref, cpars.mncc_bearer_cap));
1822 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_CALL_PROC(cpars.transaction_id)));
1823
1824 /* Drop CRCX */
1825 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1826
1827 /* Drop DTAP Release */
1828 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id)));
1829
1830 /* Drop resent DTAP Release */
1831 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id)));
1832
1833 f_expect_clear(60.0);
1834}
1835testcase TC_mo_release_timeout() runs on MTC_CT {
1836 var BSC_ConnHdlr vc_conn;
1837 f_init();
1838
1839 vc_conn := f_start_handler(refers(f_tc_mo_release_timeout), 40);
1840 vc_conn.done;
1841}
1842
Harald Welte12510c52018-01-26 22:26:24 +01001843
Philipp Maier2a98a732018-03-19 16:06:12 +01001844/* LU followed by MT call (including paging) */
1845private function f_tc_lu_and_mt_call_no_dlcx_resp(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1846 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01001847 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Philipp Maier2a98a732018-03-19 16:06:12 +01001848 cpars.bss_rtp_port := 1110;
1849 cpars.mgcp_connection_id_bss := '10004'H;
1850 cpars.mgcp_connection_id_mss := '10005'H;
1851
1852 /* Note: This is an optional parameter. When the call-agent (MSC) does
1853 * supply a full endpoint name this setting will be overwritten. */
1854 cpars.mgcp_ep := "rtpbridge/1@mgw";
1855
1856 /* Intentionally disable the CRCX response */
1857 cpars.mgw_drop_dlcx := true;
1858
1859 /* Perform location update and call */
1860 f_perform_lu();
1861 f_mt_call(cpars);
1862}
1863testcase TC_lu_and_mt_call_no_dlcx_resp() runs on MTC_CT {
1864 var BSC_ConnHdlr vc_conn;
1865 f_init();
1866
1867 /* Perform an almost normal looking locationupdate + mt-call, but do
1868 * not respond to the DLCX at the end of the call */
1869 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call_no_dlcx_resp), 41);
1870 vc_conn.done;
1871
1872 /* Wait a guard period until the MGCP layer in the MSC times out,
1873 * if the MSC is vulnerable to the use-after-free situation that is
1874 * fixed by I78f1b6a9149488a4ad3f120c1e190a83c07d4b89 then it should
1875 * segfault now */
1876 f_sleep(6.0);
1877
1878 /* Run the init procedures once more. If the MSC has crashed, this
1879 * this will fail */
1880 f_init();
1881}
Harald Welte45164da2018-01-24 12:51:27 +01001882
Philipp Maier75932982018-03-27 14:52:35 +02001883/* Two BSSMAP resets from two different BSCs */
1884testcase TC_reset_two() runs on MTC_CT {
1885 var BSC_ConnHdlr vc_conn;
1886 f_init(2);
1887 f_sleep(2.0);
1888 setverdict(pass);
1889}
1890
Harald Weltef640a012018-04-14 17:49:21 +02001891/***********************************************************************
1892 * SMS Testing
1893 ***********************************************************************/
1894
Harald Weltef45efeb2018-04-09 18:19:24 +02001895/* LU followed by MO SMS */
1896private function f_tc_lu_and_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1897 var SmsParameters spars := valueof(t_SmsPars);
1898
1899 f_init_handler(pars);
1900
1901 /* Perform location update and call */
1902 f_perform_lu();
1903
1904 f_establish_fully(EST_TYPE_MO_SMS);
1905
1906 //spars.exp_rp_err := 96; /* invalid mandatory information */
1907 f_mo_sms(spars);
1908
1909 f_expect_clear();
1910}
1911testcase TC_lu_and_mo_sms() runs on MTC_CT {
1912 var BSC_ConnHdlr vc_conn;
1913 f_init();
1914 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_sms), 42);
1915 vc_conn.done;
1916}
1917
1918private function f_vty_sms_send(charstring imsi, charstring msisdn, charstring text)
1919runs on MTC_CT {
1920 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
1921}
1922
1923/* LU followed by MT SMS */
1924private function f_tc_lu_and_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1925 var SmsParameters spars := valueof(t_SmsPars);
1926 var OCT4 tmsi;
1927
1928 f_init_handler(pars);
1929
1930 /* Perform location update and call */
1931 f_perform_lu();
1932
1933 /* register an 'expect' for given IMSI (+TMSI) */
1934 if (isvalue(g_pars.tmsi)) {
1935 tmsi := g_pars.tmsi;
1936 } else {
1937 tmsi := 'FFFFFFFF'O;
1938 }
1939 f_bssmap_register_imsi(g_pars.imsi, tmsi);
1940
1941 /* FIXME: actually cause MSC to send a SMS via VTY or SMPP */
1942
1943 /* MSC->BSC: expect PAGING from MSC */
1944 BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi));
1945 /* Establish DTAP / BSSAP / SCCP connection */
1946 f_establish_fully(EST_TYPE_PAG_RESP);
1947
1948 spars.tp.ud := 'C8329BFD064D9B53'O;
1949 f_mt_sms(spars);
1950
1951 f_expect_clear();
1952}
1953testcase TC_lu_and_mt_sms() runs on MTC_CT {
1954 var BSC_ConnHdlrPars pars;
1955 var BSC_ConnHdlr vc_conn;
1956 f_init();
1957 pars := f_init_pars(43);
1958 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms), pars);
1959 f_sleep(2.0);
1960 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
1961 vc_conn.done;
1962}
1963
Harald Weltef640a012018-04-14 17:49:21 +02001964/* mobile originated SMS from MS/BTS/BSC side to SMPP */
1965private function f_tc_smpp_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1966 var SmsParameters spars := valueof(t_SmsPars);
Harald Weltef45efeb2018-04-09 18:19:24 +02001967
Harald Weltef640a012018-04-14 17:49:21 +02001968 f_init_handler(pars);
Harald Weltef45efeb2018-04-09 18:19:24 +02001969
Harald Weltef640a012018-04-14 17:49:21 +02001970 /* Perform location update so IMSI is known + registered in MSC/VLR */
1971 f_perform_lu();
1972 f_establish_fully(EST_TYPE_MO_SMS);
1973
1974 f_mo_sms(spars);
1975
1976 var SMPP_PDU smpp;
1977 var template SMPP_PDU tr_smpp := tr_SMPP(c_SMPP_command_id_deliver_sm, ESME_ROK);
1978 tr_smpp.body.deliver_sm := {
1979 service_type := "CMT",
1980 source_addr_ton := network_specific,
1981 source_addr_npi := isdn,
1982 source_addr := hex2str(pars.msisdn),
1983 dest_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
1984 dest_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
1985 destination_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
1986 esm_class := '00000001'B,
1987 protocol_id := 0,
1988 priority_flag := 0,
1989 schedule_delivery_time := "",
1990 replace_if_present := 0,
1991 data_coding := '00000001'B,
1992 sm_default_msg_id := 0,
1993 sm_length := ?,
1994 short_message := spars.tp.ud,
1995 opt_pars := {
1996 {
1997 tag := user_message_reference,
1998 len := 2,
1999 opt_value := {
2000 int2_val := oct2int(spars.tp.msg_ref)
2001 }
2002 }
2003 }
2004 };
2005 alt {
2006 [] SMPP.receive(tr_smpp) -> value smpp {
2007 SMPP.send(ts_SMPP_DELIVER_SM_resp(ESME_ROK, smpp.header.seq_num));
2008 }
2009 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK)) { repeat; }
2010 }
2011
2012 f_expect_clear();
2013}
2014testcase TC_smpp_mo_sms() runs on MTC_CT {
2015 var BSC_ConnHdlr vc_conn;
2016 f_init();
2017 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "default-route");
2018 vc_conn := f_start_handler(refers(f_tc_smpp_mo_sms), 44);
2019 vc_conn.done;
2020 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "no default-route");
2021}
2022
2023/* convert GSM L3 TON to SMPP_TON enum */
2024function f_sm_ton_from_gsm(BIT3 ton) return SMPP_TON {
2025 select (ton) {
2026 case ('000'B) { return unknown; }
2027 case ('001'B) { return international; }
2028 case ('010'B) { return national; }
2029 case ('011'B) { return network_specific; }
2030 case ('100'B) { return subscriber_number; }
2031 case ('101'B) { return alphanumeric; }
2032 case ('110'B) { return abbreviated; }
2033 }
2034 setverdict(fail, "Unknown TON ", ton);
Daniel Willmannafce8662018-07-06 23:11:32 +02002035 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02002036}
2037/* convert GSM L3 NPI to SMPP_NPI enum */
2038function f_sm_npi_from_gsm(BIT4 npi) return SMPP_NPI {
2039 select (npi) {
2040 case ('0000'B) { return unknown; }
2041 case ('0001'B) { return isdn; }
2042 case ('0011'B) { return data; }
2043 case ('0100'B) { return telex; }
2044 case ('0110'B) { return land_mobile; }
2045 case ('1000'B) { return national; }
2046 case ('1001'B) { return private_; }
2047 case ('1010'B) { return ermes; }
2048 }
2049 setverdict(fail, "Unknown NPI ", npi);
Daniel Willmannafce8662018-07-06 23:11:32 +02002050 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02002051}
2052
2053/* build a SMPP_SM from SmsParameters */
2054function f_mt_sm_from_spars(SmsParameters spars)
2055runs on BSC_ConnHdlr return SMPP_SM {
2056 var SMPP_SM sm := {
2057 service_type := "CMT",
2058 source_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
2059 source_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
2060 source_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
2061 dest_addr_ton := international,
2062 dest_addr_npi := isdn,
2063 destination_addr := hex2str(g_pars.msisdn),
2064 esm_class := '00000001'B,
2065 protocol_id := 0,
2066 priority_flag := 0,
2067 schedule_delivery_time := "",
2068 validity_period := "",
2069 registered_delivery := '00000000'B,
2070 replace_if_present := 0,
2071 data_coding := '00000001'B,
2072 sm_default_msg_id := 0,
2073 sm_length := spars.tp.udl,
2074 short_message := spars.tp.ud,
2075 opt_pars := {}
2076 };
2077 return sm;
2078}
2079
2080/* helper function to encode SMS from 'spars', send it via SMPP to MSC; receive it on MS side */
2081private function f_smpp_mt_sms(SmsParameters spars, boolean trans_mode) runs on BSC_ConnHdlr {
2082 var SMPP_SM sm := f_mt_sm_from_spars(spars);
2083 if (trans_mode) {
2084 sm.esm_class := '00000010'B;
2085 }
2086
2087 /* actually cause MSC to send a SMS via SUBMIT-SM from SMPP side */
2088 SMPP.send(ts_SMPP_SUBMIT_SM(sm));
2089 if (not match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
2090 /* if we're not in SMPP transaction mode, we expect the SMPP-level ACK
2091 * before we expect the SMS delivery on the BSC/radio side */
2092 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
2093 }
2094
2095 /* MSC->BSC: expect PAGING from MSC */
2096 BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi));
2097 /* Establish DTAP / BSSAP / SCCP connection */
2098 f_establish_fully(EST_TYPE_PAG_RESP);
2099 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
2100
2101 f_mt_sms(spars);
2102
2103 if (match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
2104 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
2105 }
2106 f_expect_clear();
2107}
2108
2109/* mobile terminated SMS, from SMPP to BSC/BTS/MS */
2110private function f_tc_smpp_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2111 f_init_handler(pars);
2112
2113 /* Perform location update so IMSI is known + registered in MSC/VLR */
2114 f_perform_lu();
2115 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
2116
2117 /* register an 'expect' for given IMSI (+TMSI) */
2118 var OCT4 tmsi;
2119 if (isvalue(g_pars.tmsi)) {
2120 tmsi := g_pars.tmsi;
2121 } else {
2122 tmsi := 'FFFFFFFF'O;
2123 }
2124 f_bssmap_register_imsi(g_pars.imsi, tmsi);
2125
2126 var SmsParameters spars := valueof(t_SmsPars);
2127 /* TODO: test with more intelligent user data; test different coding schemes */
2128 spars.tp.ud := '00'O;
2129 spars.tp.udl := 1;
2130
2131 /* first test the non-transaction store+forward mode */
2132 f_smpp_mt_sms(spars, false);
2133
2134 /* then test the transaction mode */
2135 f_smpp_mt_sms(spars, true);
2136}
2137testcase TC_smpp_mt_sms() runs on MTC_CT {
2138 var BSC_ConnHdlr vc_conn;
2139 f_init();
2140 vc_conn := f_start_handler(refers(f_tc_smpp_mt_sms), 45);
2141 vc_conn.done;
2142}
2143
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002144/***********************************************************************
2145 * USSD Testing
2146 ***********************************************************************/
2147
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07002148private altstep as_unexp_gsup_or_bssap_msg()
2149runs on BSC_ConnHdlr {
2150 [] GSUP.receive {
2151 setverdict(fail, "Unknown/unexpected GSUP received");
2152 self.stop;
2153 }
2154 [] BSSAP.receive {
2155 setverdict(fail, "Unknown/unexpected BSSAP message received");
2156 self.stop;
2157 }
2158}
2159
2160private function f_expect_gsup_msg(template GSUP_PDU msg)
2161runs on BSC_ConnHdlr return GSUP_PDU {
2162 var GSUP_PDU gsup_msg_complete;
2163
2164 alt {
2165 [] GSUP.receive(msg) -> value gsup_msg_complete {
2166 setverdict(pass);
2167 }
2168 /* We don't expect anything else */
2169 [] as_unexp_gsup_or_bssap_msg();
2170 }
2171
2172 return gsup_msg_complete;
2173}
2174
2175private function f_expect_mt_dtap_msg(template PDU_ML3_NW_MS msg)
2176runs on BSC_ConnHdlr return PDU_ML3_NW_MS {
2177 var PDU_DTAP_MT bssap_msg_complete;
2178
2179 alt {
2180 [] BSSAP.receive(tr_PDU_DTAP_MT(msg)) -> value bssap_msg_complete {
2181 setverdict(pass);
2182 }
2183 /* We don't expect anything else */
2184 [] as_unexp_gsup_or_bssap_msg();
2185 }
2186
2187 return bssap_msg_complete.dtap;
2188}
2189
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07002190/* LU followed by MO USSD request */
2191private function f_tc_lu_and_mo_ussd_single_request(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002192runs on BSC_ConnHdlr {
2193 f_init_handler(pars);
2194
2195 /* Perform location update */
2196 f_perform_lu();
2197
2198 /* Send CM Service Request for SS/USSD */
2199 f_establish_fully(EST_TYPE_SS_ACT);
2200
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002201 /* We need to inspect GSUP activity */
2202 f_create_gsup_expect(hex2str(g_pars.imsi));
2203
2204 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
2205 invoke_id := 5, /* Phone may not start from 0 or 1 */
2206 op_code := SS_OP_CODE_PROCESS_USS_REQ,
2207 ussd_string := "*#100#"
2208 );
2209
2210 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
2211 invoke_id := 5, /* InvokeID shall be the same for both REQ and RSP */
2212 op_code := SS_OP_CODE_PROCESS_USS_REQ,
2213 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
2214 )
2215
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002216 /* Compose a new SS/REGISTER message with request */
2217 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
2218 tid := 1, /* We just need a single transaction */
2219 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002220 facility := valueof(facility_req)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002221 );
2222
2223 /* Compose SS/RELEASE_COMPLETE template with expected response */
2224 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
2225 tid := 1, /* Response should arrive within the same transaction */
2226 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002227 facility := valueof(facility_rsp)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002228 );
2229
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002230 /* Compose expected MSC -> HLR message */
2231 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
2232 imsi := g_pars.imsi,
2233 state := OSMO_GSUP_SESSION_STATE_BEGIN,
2234 ss := valueof(facility_req)
2235 );
2236
2237 /* To be used for sending response with correct session ID */
2238 var GSUP_PDU gsup_req_complete;
2239
2240 /* Request own number */
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002241 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002242 /* Expect GSUP message containing the SS payload */
2243 gsup_req_complete := f_expect_gsup_msg(gsup_req);
2244
2245 /* Compose the response from HLR using received session ID */
2246 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
2247 imsi := g_pars.imsi,
2248 sid := gsup_req_complete.ies[1].val.session_id,
2249 state := OSMO_GSUP_SESSION_STATE_END,
2250 ss := valueof(facility_rsp)
2251 );
2252
2253 /* Finally, HLR terminates the session */
2254 GSUP.send(gsup_rsp);
2255 /* Expect RELEASE_COMPLETE message with the response */
2256 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002257
2258 f_expect_clear();
2259}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07002260testcase TC_lu_and_mo_ussd_single_request() runs on MTC_CT {
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002261 var BSC_ConnHdlr vc_conn;
2262 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07002263 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_single_request), 46);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002264 vc_conn.done;
2265}
2266
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07002267/* LU followed by MT USSD notification */
2268private function f_tc_lu_and_mt_ussd_notification(charstring id, BSC_ConnHdlrPars pars)
2269runs on BSC_ConnHdlr {
2270 f_init_handler(pars);
2271
2272 /* Perform location update */
2273 f_perform_lu();
2274
2275 f_bssmap_register_imsi(g_pars.imsi, g_pars.tmsi);
2276
2277 /* We need to inspect GSUP activity */
2278 f_create_gsup_expect(hex2str(g_pars.imsi));
2279
2280 /* Facility IE with network-originated USSD notification */
2281 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
2282 op_code := SS_OP_CODE_USS_NOTIFY,
2283 ussd_string := "Mahlzeit!"
2284 );
2285
2286 /* Facility IE with acknowledgment to the USSD notification */
2287 var template OCTN facility_rsp := enc_SS_FacilityInformation(
2288 /* In case of USSD notification, Return Result is empty */
2289 valueof(ts_SS_USSD_FACILITY_RETURN_RESULT_EMPTY())
2290 );
2291
2292 /* Compose a new MT SS/REGISTER message with USSD notification */
2293 var template PDU_ML3_NW_MS ussd_ntf := tr_ML3_MT_SS_REGISTER(
2294 tid := 0, /* FIXME: most likely, it should be 0 */
2295 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
2296 facility := valueof(facility_req)
2297 );
2298
2299 /* Compose HLR -> MSC GSUP message */
2300 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
2301 imsi := g_pars.imsi,
2302 sid := '20000101'O,
2303 state := OSMO_GSUP_SESSION_STATE_BEGIN,
2304 ss := valueof(facility_req)
2305 );
2306
2307 /* Send it to MSC and expect Paging Request */
2308 GSUP.send(gsup_req);
2309 alt {
2310 [] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
2311 setverdict(pass);
2312 }
2313 /* We don't expect anything else */
2314 [] as_unexp_gsup_or_bssap_msg();
2315 }
2316
2317 /* Send Paging Response and expect USSD notification */
2318 f_establish_fully(EST_TYPE_PAG_RESP);
2319 /* Expect MT REGISTER message with USSD notification */
2320 f_expect_mt_dtap_msg(ussd_ntf);
2321
2322 /* Compose a new MO SS/FACILITY message with empty response */
2323 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
2324 tid := 0, /* FIXME: it shall match the request tid */
2325 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
2326 facility := valueof(facility_rsp)
2327 );
2328
2329 /* Compose expected MSC -> HLR GSUP message */
2330 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
2331 imsi := g_pars.imsi,
2332 sid := '20000101'O,
2333 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
2334 ss := valueof(facility_rsp)
2335 );
2336
2337 /* MS sends response to the notification */
2338 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
2339 /* Expect GSUP message containing the SS payload */
2340 f_expect_gsup_msg(gsup_rsp);
2341
2342 /* Compose expected MT SS/RELEASE COMPLETE message */
2343 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
2344 tid := 0, /* FIXME: it shall match the request tid */
2345 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
2346 facility := omit
2347 );
2348
2349 /* Compose MSC -> HLR GSUP message */
2350 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
2351 imsi := g_pars.imsi,
2352 sid := '20000101'O,
2353 state := OSMO_GSUP_SESSION_STATE_END
2354 );
2355
2356 /* Finally, HLR terminates the session */
2357 GSUP.send(gsup_term)
2358 /* Expect MT RELEASE COMPLETE without Facility IE */
2359 f_expect_mt_dtap_msg(ussd_term);
2360
2361 f_expect_clear();
2362}
2363testcase TC_lu_and_mt_ussd_notification() runs on MTC_CT {
2364 var BSC_ConnHdlr vc_conn;
2365 f_init();
2366 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_notification), 47);
2367 vc_conn.done;
2368}
2369
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07002370/* LU followed by MT call and MO USSD request during this call */
2371private function f_tc_lu_and_mo_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07002372runs on BSC_ConnHdlr {
2373 f_init_handler(pars);
2374
2375 /* Call parameters taken from f_tc_lu_and_mt_call */
2376 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
2377 cpars.mgcp_connection_id_bss := '10004'H;
2378 cpars.mgcp_connection_id_mss := '10005'H;
2379 cpars.mgcp_ep := "rtpbridge/1@mgw";
2380 cpars.bss_rtp_port := 1110;
2381
2382 /* Perform location update */
2383 f_perform_lu();
2384
2385 /* Establish a MT call */
2386 f_mt_call_establish(cpars);
2387
2388 /* Hold the call for some time */
2389 f_sleep(1.0);
2390
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002391 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
2392 op_code := SS_OP_CODE_PROCESS_USS_REQ,
2393 ussd_string := "*#100#"
2394 );
2395
2396 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
2397 op_code := SS_OP_CODE_PROCESS_USS_REQ,
2398 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
2399 )
2400
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07002401 /* Compose a new SS/REGISTER message with request */
2402 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
2403 tid := 1, /* We just need a single transaction */
2404 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002405 facility := valueof(facility_req)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07002406 );
2407
2408 /* Compose SS/RELEASE_COMPLETE template with expected response */
2409 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
2410 tid := 1, /* Response should arrive within the same transaction */
2411 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002412 facility := valueof(facility_rsp)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07002413 );
2414
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002415 /* Compose expected MSC -> HLR message */
2416 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
2417 imsi := g_pars.imsi,
2418 state := OSMO_GSUP_SESSION_STATE_BEGIN,
2419 ss := valueof(facility_req)
2420 );
2421
2422 /* To be used for sending response with correct session ID */
2423 var GSUP_PDU gsup_req_complete;
2424
2425 /* Request own number */
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07002426 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002427 /* Expect GSUP message containing the SS payload */
2428 gsup_req_complete := f_expect_gsup_msg(gsup_req);
2429
2430 /* Compose the response from HLR using received session ID */
2431 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
2432 imsi := g_pars.imsi,
2433 sid := gsup_req_complete.ies[1].val.session_id,
2434 state := OSMO_GSUP_SESSION_STATE_END,
2435 ss := valueof(facility_rsp)
2436 );
2437
2438 /* Finally, HLR terminates the session */
2439 GSUP.send(gsup_rsp);
2440 /* Expect RELEASE_COMPLETE message with the response */
2441 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07002442
2443 /* Hold the call for some time */
2444 f_sleep(1.0);
2445
2446 /* Release the call (does Clear Complete itself) */
2447 f_call_hangup(cpars, true);
2448}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07002449testcase TC_lu_and_mo_ussd_during_mt_call() runs on MTC_CT {
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07002450 var BSC_ConnHdlr vc_conn;
2451 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07002452 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_during_mt_call), 48);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07002453 vc_conn.done;
2454}
2455
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02002456/* BSSMAP Clear Request in the middle of a call, see OS#3062 */
2457private function f_tc_mo_cc_bssmap_clear(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2458 f_init_handler(pars);
2459 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
2460 var MNCC_PDU mncc;
2461 var MgcpCommand mgcp_cmd;
2462
2463 f_perform_lu();
2464
2465 f_establish_fully();
2466 f_create_mncc_expect(hex2str(cpars.called_party));
2467 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
2468
2469 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
2470 MNCC.receive(tr_MNCC_SETUP_ind(?, tr_MNCC_number(hex2str(cpars.called_party)))) -> value mncc;
2471 cpars.mncc_callref := mncc.u.signal.callref;
2472 log("mncc_callref=", cpars.mncc_callref);
2473 MNCC.send(ts_MNCC_CALL_PROC_req(cpars.mncc_callref, cpars.mncc_bearer_cap));
2474 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_CALL_PROC(cpars.transaction_id)));
2475
2476 MNCC.send(ts_MNCC_ALERT_req(cpars.mncc_callref));
2477 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_ALERTING(cpars.transaction_id)));
2478 MGCP.receive(tr_CRCX);
2479
2480 f_sleep(1.0);
2481 BSSAP.send(ts_BSSMAP_ClearRequest(0));
2482
2483 MNCC.receive(tr_MNCC_REL_ind(?, ?)) -> value mncc;
2484
2485 BSSAP.receive(tr_BSSMAP_ClearCommand);
2486 BSSAP.send(ts_BSSMAP_ClearComplete);
2487
2488 f_sleep(1.0);
2489}
2490testcase TC_mo_cc_bssmap_clear() runs on MTC_CT {
2491 var BSC_ConnHdlr vc_conn;
2492 f_init();
2493
2494 vc_conn := f_start_handler(refers(f_tc_mo_cc_bssmap_clear), 43);
2495 vc_conn.done;
2496}
2497
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07002498/* LU followed by MT call and MT USSD request during this call */
2499private function f_tc_lu_and_mt_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
2500runs on BSC_ConnHdlr {
2501 f_init_handler(pars);
2502
2503 /* Call parameters taken from f_tc_lu_and_mt_call */
2504 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
2505 cpars.mgcp_connection_id_bss := '10004'H;
2506 cpars.mgcp_connection_id_mss := '10005'H;
2507 cpars.mgcp_ep := "rtpbridge/1@mgw";
2508 cpars.bss_rtp_port := 1110;
2509
2510 /* Perform location update */
2511 f_perform_lu();
2512
2513 /* Establish a MT call */
2514 f_mt_call_establish(cpars);
2515
2516 /* Hold the call for some time */
2517 f_sleep(1.0);
2518
2519 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
2520 op_code := SS_OP_CODE_USS_REQUEST,
2521 ussd_string := "Please type anything..."
2522 );
2523
2524 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
2525 op_code := SS_OP_CODE_USS_REQUEST,
2526 ussd_string := "Nope."
2527 )
2528
2529 /* Compose MT SS/REGISTER message with network-originated request */
2530 var template (value) PDU_ML3_NW_MS ussd_req := ts_ML3_MT_SS_REGISTER(
2531 tid := 0, /* FIXME: most likely, it should be 0 */
2532 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
2533 facility := valueof(facility_req)
2534 );
2535
2536 /* Compose HLR -> MSC GSUP message */
2537 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
2538 imsi := g_pars.imsi,
2539 sid := '20000101'O,
2540 state := OSMO_GSUP_SESSION_STATE_BEGIN,
2541 ss := valueof(facility_req)
2542 );
2543
2544 /* Send it to MSC */
2545 GSUP.send(gsup_req);
2546 /* Expect MT REGISTER message with USSD request */
2547 f_expect_mt_dtap_msg(ussd_req);
2548
2549 /* Compose a new MO SS/FACILITY message with response */
2550 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
2551 tid := 0, /* FIXME: it shall match the request tid */
2552 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
2553 facility := valueof(facility_rsp)
2554 );
2555
2556 /* Compose expected MSC -> HLR GSUP message */
2557 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
2558 imsi := g_pars.imsi,
2559 sid := '20000101'O,
2560 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
2561 ss := valueof(facility_rsp)
2562 );
2563
2564 /* MS sends response */
2565 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
2566 f_expect_gsup_msg(gsup_rsp);
2567
2568 /* Compose expected MT SS/RELEASE COMPLETE message */
2569 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
2570 tid := 0, /* FIXME: it shall match the request tid */
2571 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
2572 facility := omit
2573 );
2574
2575 /* Compose MSC -> HLR GSUP message */
2576 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
2577 imsi := g_pars.imsi,
2578 sid := '20000101'O,
2579 state := OSMO_GSUP_SESSION_STATE_END
2580 );
2581
2582 /* Finally, HLR terminates the session */
2583 GSUP.send(gsup_term);
2584 /* Expect MT RELEASE COMPLETE without Facility IE */
2585 f_expect_mt_dtap_msg(ussd_term);
2586
2587 /* Hold the call for some time */
2588 f_sleep(1.0);
2589
2590 /* Release the call (does Clear Complete itself) */
2591 f_call_hangup(cpars, true);
2592}
2593testcase TC_lu_and_mt_ussd_during_mt_call() runs on MTC_CT {
2594 var BSC_ConnHdlr vc_conn;
2595 f_init();
2596 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_during_mt_call), 49);
2597 vc_conn.done;
2598}
2599
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07002600/* LU followed by MO USSD request and MO Release during transaction */
2601private function f_tc_lu_and_mo_ussd_mo_release(charstring id, BSC_ConnHdlrPars pars)
2602runs on BSC_ConnHdlr {
2603 f_init_handler(pars);
2604
2605 /* Perform location update */
2606 f_perform_lu();
2607
2608 /* Send CM Service Request for SS/USSD */
2609 f_establish_fully(EST_TYPE_SS_ACT);
2610
2611 /* We need to inspect GSUP activity */
2612 f_create_gsup_expect(hex2str(g_pars.imsi));
2613
2614 var template OCTN facility_ms_req := f_USSD_FACILITY_IE_INVOKE(
2615 invoke_id := 1, /* Initial request */
2616 op_code := SS_OP_CODE_PROCESS_USS_REQ,
2617 ussd_string := "*6766*266#"
2618 );
2619
2620 var template OCTN facility_net_req := f_USSD_FACILITY_IE_INVOKE(
2621 invoke_id := 2, /* Counter request */
2622 op_code := SS_OP_CODE_USS_REQUEST,
2623 ussd_string := "Password?!?"
2624 )
2625
2626 /* Compose MO SS/REGISTER message with request */
2627 var template (value) PDU_ML3_MS_NW ussd_ms_req := ts_ML3_MO_SS_REGISTER(
2628 tid := 1, /* We just need a single transaction */
2629 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
2630 facility := valueof(facility_ms_req)
2631 );
2632
2633 /* Compose expected MSC -> HLR message */
2634 var template GSUP_PDU gsup_ms_req := tr_GSUP_PROC_SS_REQ(
2635 imsi := g_pars.imsi,
2636 state := OSMO_GSUP_SESSION_STATE_BEGIN,
2637 ss := valueof(facility_ms_req)
2638 );
2639
2640 /* To be used for sending response with correct session ID */
2641 var GSUP_PDU gsup_ms_req_complete;
2642
2643 /* Initiate a new transaction */
2644 BSSAP.send(ts_PDU_DTAP_MO(ussd_ms_req));
2645 /* Expect GSUP request with original Facility IE */
2646 gsup_ms_req_complete := f_expect_gsup_msg(gsup_ms_req);
2647
2648 /* Compose the response from HLR using received session ID */
2649 var template (value) GSUP_PDU gsup_net_req := ts_GSUP_PROC_SS_REQ(
2650 imsi := g_pars.imsi,
2651 sid := gsup_ms_req_complete.ies[1].val.session_id,
2652 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
2653 ss := valueof(facility_net_req)
2654 );
2655
2656 /* Compose expected MT SS/FACILITY template with counter request */
2657 var template PDU_ML3_NW_MS ussd_net_req := tr_ML3_MT_SS_FACILITY(
2658 tid := 1, /* Response should arrive within the same transaction */
2659 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
2660 facility := valueof(facility_net_req)
2661 );
2662
2663 /* Send response over GSUP */
2664 GSUP.send(gsup_net_req);
2665 /* Expect MT SS/FACILITY message with counter request */
2666 f_expect_mt_dtap_msg(ussd_net_req);
2667
2668 /* Compose MO SS/RELEASE COMPLETE */
2669 var template (value) PDU_ML3_MS_NW ussd_abort := ts_ML3_MO_SS_RELEASE_COMPLETE(
2670 tid := 1, /* Response should arrive within the same transaction */
2671 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
2672 facility := omit
2673 /* TODO: cause? */
2674 );
2675
2676 /* Compose expected HLR -> MSC abort message */
2677 var template GSUP_PDU gsup_abort := tr_GSUP_PROC_SS_REQ(
2678 imsi := g_pars.imsi,
2679 sid := gsup_ms_req_complete.ies[1].val.session_id,
2680 state := OSMO_GSUP_SESSION_STATE_END
2681 );
2682
2683 /* Abort transaction */
2684 BSSAP.send(ts_PDU_DTAP_MO(ussd_abort));
2685 /* Expect GSUP message indicating abort */
2686 f_expect_gsup_msg(gsup_abort);
2687
2688 f_expect_clear();
2689}
2690testcase TC_lu_and_mo_ussd_mo_release() runs on MTC_CT {
2691 var BSC_ConnHdlr vc_conn;
2692 f_init();
2693 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_mo_release), 50);
2694 vc_conn.done;
2695}
2696
Harald Weltef640a012018-04-14 17:49:21 +02002697/* TODO (SMS):
2698 * different user data lengths
2699 * SMPP transaction mode with unsuccessful delivery
2700 * queued MT-SMS with no paging response + later delivery
2701 * different data coding schemes
2702 * multi-part SMS
2703 * user-data headers
2704 * TP-PID for SMS to SIM
2705 * behavior if SMS memory is full + RP-SMMA
2706 * delivery reports
2707 * SMPP osmocom extensions
2708 * more-messages-to-send
2709 * SMS during ongoing call (SACCH/SAPI3)
2710 */
2711
2712/* TODO (General):
Harald Welteba7b6d92018-01-23 21:32:34 +01002713 * continue to send repeated MO signalling messages to keep channel open: does MSC tmeout?
2714 * malformed messages (missing IE, invalid message type): properly rejected?
2715 * MT call while LU or is ongoing: Do we use existing lchan or page while lchan active?
2716 * 3G/2G auth permutations
2717 * encryption algorithms vs. classmark vs. vty config
Harald Welteba7b6d92018-01-23 21:32:34 +01002718 * send new transaction after/during clear (like SMS, ...)
Harald Welte45164da2018-01-24 12:51:27 +01002719 * too long L3 INFO in DTAP
2720 * too long / padded BSSAP
2721 * too long / short TLV values
Harald Welteba7b6d92018-01-23 21:32:34 +01002722 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01002723
2724
2725control {
Philipp Maier328d1662018-03-07 10:40:27 +01002726 execute( TC_cr_before_reset() );
Harald Weltea49e36e2018-01-21 19:29:33 +01002727 execute( TC_lu_imsi_noauth_tmsi() );
Harald Welted2328a22018-01-27 14:27:16 +01002728 execute( TC_lu_imsi_noauth_notmsi() );
Harald Weltea49e36e2018-01-21 19:29:33 +01002729 execute( TC_lu_imsi_reject() );
2730 execute( TC_lu_imsi_timeout_gsup() );
Harald Welted2328a22018-01-27 14:27:16 +01002731 execute( TC_lu_imsi_auth_tmsi() );
2732 execute( TC_cmserv_imsi_unknown() );
Harald Welte2bb825f2018-01-22 11:31:18 +01002733 execute( TC_lu_and_mo_call() );
Harald Welte071ed732018-01-23 19:53:52 +01002734 execute( TC_lu_auth_sai_timeout() );
2735 execute( TC_lu_auth_sai_err() );
Harald Weltee1a2f3c2018-01-24 17:28:48 +01002736 execute( TC_lu_clear_request() );
2737 execute( TC_lu_disconnect() );
2738 execute( TC_lu_by_imei() );
2739 execute( TC_lu_by_tmsi_noauth_unknown() );
2740 execute( TC_imsi_detach_by_imsi() );
2741 execute( TC_imsi_detach_by_tmsi() );
2742 execute( TC_imsi_detach_by_imei() );
2743 execute( TC_emerg_call_imei_reject() );
2744 execute( TC_emerg_call_imsi() );
2745 execute( TC_cm_serv_req_vgcs_reject() );
2746 execute( TC_cm_serv_req_vbs_reject() );
2747 execute( TC_cm_serv_req_lcs_reject() );
Harald Welte0195ab12018-01-24 21:50:20 +01002748 execute( TC_cm_reest_req_reject() );
Harald Welte1af6ea82018-01-25 18:33:15 +01002749 execute( TC_lu_auth_2G_fail() );
2750 execute( TC_lu_imsi_auth_tmsi_encr_13_13() );
2751 execute( TC_cl3_no_payload() );
2752 execute( TC_cl3_rnd_payload() );
Harald Welte1852a842018-01-26 22:53:36 +01002753 execute( TC_establish_and_nothing() );
2754 execute( TC_mo_setup_and_nothing() );
2755 execute( TC_mo_crcx_ran_timeout() );
2756 execute( TC_mo_crcx_ran_reject() );
Harald Welted2328a22018-01-27 14:27:16 +01002757 execute( TC_mt_crcx_ran_reject() );
Daniel Willmann8b084372018-02-04 13:35:26 +01002758 execute( TC_mo_setup_and_dtmf_dup() );
Harald Welteaa54cf82018-01-30 08:15:32 +01002759 //execute( TC_mt_t310() );
Harald Welte167458a2018-01-27 15:58:16 +01002760 execute( TC_gsup_cancel() );
Harald Welte9de84792018-01-28 01:06:35 +01002761 execute( TC_lu_imsi_auth_tmsi_encr_1_13() );
2762 execute( TC_lu_imsi_auth_tmsi_encr_3_13() );
2763 execute( TC_lu_imsi_auth_tmsi_encr_3_1() );
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01002764 execute( TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() );
Harald Welte9de84792018-01-28 01:06:35 +01002765 execute( TC_lu_imsi_auth_tmsi_encr_13_2() );
2766 execute( TC_lu_imsi_auth_tmsi_encr_013_2() );
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002767 execute( TC_mo_release_timeout() );
Philipp Maier2a98a732018-03-19 16:06:12 +01002768 execute( TC_lu_and_mt_call_no_dlcx_resp() );
Philipp Maier75932982018-03-27 14:52:35 +02002769 execute( TC_reset_two() );
Harald Welte33ec09b2018-02-10 15:34:46 +01002770
2771 execute( TC_lu_and_mt_call() );
2772
Harald Weltef45efeb2018-04-09 18:19:24 +02002773 execute( TC_lu_and_mo_sms() );
2774 execute( TC_lu_and_mt_sms() );
Harald Weltef640a012018-04-14 17:49:21 +02002775 execute( TC_smpp_mo_sms() );
2776 execute( TC_smpp_mt_sms() );
Harald Weltef45efeb2018-04-09 18:19:24 +02002777
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07002778 execute( TC_lu_and_mo_ussd_single_request() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07002779 execute( TC_lu_and_mt_ussd_notification() );
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07002780 execute( TC_lu_and_mo_ussd_during_mt_call() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07002781 execute( TC_lu_and_mt_ussd_during_mt_call() );
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07002782 execute( TC_lu_and_mo_ussd_mo_release() );
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002783
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01002784 /* Run this last: at the time of writing this test crashes the MSC */
2785 execute( TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() );
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02002786 execute( TC_mo_cc_bssmap_clear() );
Harald Weltef6dd64d2017-11-19 12:09:51 +01002787}
2788
2789
2790}