blob: 709a73cb1f3ffebad04b8d1ed9146d5134714496 [file] [log] [blame]
Harald Weltef6dd64d2017-11-19 12:09:51 +01001module MSC_Tests {
2
Harald Weltee13cfb22019-04-23 16:52:02 +02003friend module MSC_Tests_Iu;
4
Harald Weltef6dd64d2017-11-19 12:09:51 +01005import from General_Types all;
6import from Osmocom_Types all;
7
8import from M3UA_Types all;
9import from M3UA_Emulation all;
10
11import from MTP3asp_Types all;
12import from MTP3asp_PortType all;
13
14import from SCCPasp_Types all;
15import from SCCP_Types all;
16import from SCCP_Emulation all;
17
18import from SCTPasp_Types all;
19import from SCTPasp_PortType all;
20
Harald Weltea49e36e2018-01-21 19:29:33 +010021import from Osmocom_CTRL_Functions all;
22import from Osmocom_CTRL_Types all;
23import from Osmocom_CTRL_Adapter all;
24
Harald Welte3ca1c902018-01-24 18:51:27 +010025import from TELNETasp_PortType all;
26import from Osmocom_VTY_Functions all;
27
Harald Weltea49e36e2018-01-21 19:29:33 +010028import from MNCC_Emulation all;
Harald Welte2bb825f2018-01-22 11:31:18 +010029import from MNCC_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010030
Harald Welte4aa970c2018-01-26 10:38:09 +010031import from MGCP_Emulation all;
32import from MGCP_Types all;
33import from MGCP_Templates all;
34import from SDP_Types all;
35
Harald Weltea49e36e2018-01-21 19:29:33 +010036import from GSUP_Emulation all;
37import from GSUP_Types all;
38import from IPA_Emulation all;
39
Harald Weltef6dd64d2017-11-19 12:09:51 +010040import from BSSAP_Types all;
Harald Welte6811d102019-04-14 22:23:14 +020041import from RAN_Adapter all;
Harald Weltea49e36e2018-01-21 19:29:33 +010042import from BSSAP_CodecPort all;
43import from BSSMAP_Templates all;
Harald Welte6811d102019-04-14 22:23:14 +020044import from RAN_Emulation all;
Harald Weltea49e36e2018-01-21 19:29:33 +010045import from BSC_ConnectionHandler all;
Harald Weltee13cfb22019-04-23 16:52:02 +020046import from RANAP_Templates all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010047
Harald Welte4263c522018-12-06 11:56:27 +010048import from SGsAP_Templates all;
49import from SGsAP_Types all;
50import from SGsAP_Emulation all;
51
Harald Weltea49e36e2018-01-21 19:29:33 +010052import from MobileL3_Types all;
53import from MobileL3_CommonIE_Types all;
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +070054import from MobileL3_SMS_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010055import from L3_Templates all;
Harald Welte158a7ca2018-02-16 18:11:31 +010056import from L3_Common all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010057
Harald Weltef640a012018-04-14 17:49:21 +020058import from SMPP_Types all;
59import from SMPP_Templates all;
60import from SMPP_Emulation all;
61
Stefan Sperlingc307e682018-06-14 15:15:46 +020062import from SCCP_Templates all;
63
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070064import from SS_Types all;
65import from SS_Templates all;
66import from USSD_Helpers all;
Harald Welte4263c522018-12-06 11:56:27 +010067import from DNS_Helpers all;
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070068
Philipp Maier948747b2019-04-02 15:22:33 +020069import from TCCConversion_Functions all;
70
Harald Welte9b751a62019-04-14 17:39:29 +020071const integer NUM_BSC := 3;
Harald Welte6811d102019-04-14 22:23:14 +020072type record of RAN_Configuration RAN_Configurations;
Harald Weltef6dd64d2017-11-19 12:09:51 +010073
Harald Welte4263c522018-12-06 11:56:27 +010074/* Needed for SGsAP SMS */
75import from MobileL3_SMS_Types all;
76
Harald Weltea4ca4462018-02-09 00:17:14 +010077type component MTC_CT extends CTRL_Adapter_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +010078 var boolean g_initialized := false;
Harald Weltea49e36e2018-01-21 19:29:33 +010079
Harald Welte6811d102019-04-14 22:23:14 +020080 var RAN_Adapter g_bssap[NUM_BSC];
Harald Weltea4ca4462018-02-09 00:17:14 +010081
Harald Weltea49e36e2018-01-21 19:29:33 +010082 /* no 'adapter_CT' for MNCC or GSUP */
83 var MNCC_Emulation_CT vc_MNCC;
Harald Welte4aa970c2018-01-26 10:38:09 +010084 var MGCP_Emulation_CT vc_MGCP;
Harald Weltea49e36e2018-01-21 19:29:33 +010085 var GSUP_Emulation_CT vc_GSUP;
86 var IPA_Emulation_CT vc_GSUP_IPA;
Harald Weltef640a012018-04-14 17:49:21 +020087 var SMPP_Emulation_CT vc_SMPP;
Harald Welte4263c522018-12-06 11:56:27 +010088 var SGsAP_Emulation_CT vc_SGsAP;
Harald Weltea49e36e2018-01-21 19:29:33 +010089
90 /* only to get events from IPA underneath GSUP */
91 port IPA_CTRL_PT GSUP_IPA_EVENT;
Harald Welte3ca1c902018-01-24 18:51:27 +010092 /* VTY to MSC */
93 port TELNETasp_PT MSCVTY;
Philipp Maier328d1662018-03-07 10:40:27 +010094
95 /* A port to directly send BSSAP messages. This port is used for
96 * tests that require low level access to sen arbitrary BSSAP
97 * messages. Run f_init_bssap_direct() to connect and initialize */
98 port BSSAP_CODEC_PT BSSAP_DIRECT;
99
100 /* When BSSAP messages are directly sent, then the connection
101 * handler is not active, which means that also no guard timer is
102 * set up. The following timer will serve as a replacement */
103 timer Tguard_direct := 60.0;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100104}
105
106modulepar {
Harald Weltea49e36e2018-01-21 19:29:33 +0100107 /* remote parameters of IUT */
108 charstring mp_msc_ip := "127.0.0.1";
109 integer mp_msc_ctrl_port := 4255;
110 integer mp_msc_vty_port := 4254;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100111
Harald Weltea49e36e2018-01-21 19:29:33 +0100112 /* local parameters of emulated HLR */
Philipp Maier9b690e42018-12-21 11:50:03 +0100113 boolean mp_mm_info := false;
Harald Weltea49e36e2018-01-21 19:29:33 +0100114 charstring mp_hlr_ip := "127.0.0.1";
115 integer mp_hlr_port := 4222;
Harald Welte6126fb02018-01-27 20:08:24 +0100116 charstring mp_mgw_ip := "127.0.0.1";
117 integer mp_mgw_port := 2427;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100118
Harald Weltea49e36e2018-01-21 19:29:33 +0100119 charstring mp_msc_mncc := "/tmp/mncc";
Harald Weltea4ca4462018-02-09 00:17:14 +0100120
Harald Weltef640a012018-04-14 17:49:21 +0200121 integer mp_msc_smpp_port := 2775;
122 charstring mp_smpp_system_id := "msc_tester";
123 charstring mp_smpp_password := "osmocom1";
Harald Welte4263c522018-12-06 11:56:27 +0100124 charstring mp_mme_name := "mmec01.mmegi0001.mme.epc.mnc070.mcc901.3gppnetwork.org";
125 charstring mp_vlr_name := "vlr.example.net";
Harald Weltef640a012018-04-14 17:49:21 +0200126
Harald Welte6811d102019-04-14 22:23:14 +0200127 RAN_Configurations mp_bssap_cfg := {
Philipp Maier75932982018-03-27 14:52:35 +0200128 {
129 sccp_service_type := "mtp3_itu",
130 sctp_addr := { 23905, "127.0.0.1", 2905, "127.0.0.1" },
131 own_pc := 185,
132 own_ssn := 254,
133 peer_pc := 187,
134 peer_ssn := 254,
135 sio := '83'O,
136 rctx := 0
137 },
138 {
139 sccp_service_type := "mtp3_itu",
140 sctp_addr := { 23906, "127.0.0.1", 2905, "127.0.0.1" },
141 own_pc := 186,
142 own_ssn := 254,
143 peer_pc := 187,
144 peer_ssn := 254,
145 sio := '83'O,
146 rctx := 1
147 }
Harald Weltea4ca4462018-02-09 00:17:14 +0100148 };
Harald Weltef6dd64d2017-11-19 12:09:51 +0100149}
150
Philipp Maier328d1662018-03-07 10:40:27 +0100151/* altstep for the global guard timer (only used when BSSAP_DIRECT
152 * is used for communication */
153private altstep as_Tguard_direct() runs on MTC_CT {
154 [] Tguard_direct.timeout {
155 setverdict(fail, "Tguard timeout");
Daniel Willmannafce8662018-07-06 23:11:32 +0200156 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +0100157 }
158}
Harald Weltef6dd64d2017-11-19 12:09:51 +0100159
Neels Hofmeyr2ca1ab42019-03-08 03:45:43 +0100160private altstep as_optional_cc_rel(CallParameters cpars, boolean respond := false) runs on BSC_ConnHdlr {
161 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id))) {
162 if (respond) {
163 var BIT1 tid_remote := '1'B;
164 if (cpars.mo_call) {
165 tid_remote := '0'B;
166 }
167 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id, tid_remote)));
168 }
169 }
Neels Hofmeyrde76f052019-02-26 05:02:46 +0100170}
171
Harald Weltef640a012018-04-14 17:49:21 +0200172function f_init_smpp(charstring id) runs on MTC_CT {
173 id := id & "-SMPP";
174 var EsmePars pars := {
175 mode := MODE_TRANSCEIVER,
176 bind := {
177 system_id := mp_smpp_system_id,
178 password := mp_smpp_password,
179 system_type := "MSC_Tests",
180 interface_version := hex2int('34'H),
181 addr_ton := unknown,
182 addr_npi := unknown,
183 address_range := ""
184 },
185 esme_role := true
186 }
187
188 vc_SMPP := SMPP_Emulation_CT.create(id);
189 map(vc_SMPP:SMPP_PORT, system:SMPP_PORT);
190 vc_SMPP.start(SMPP_Emulation.main_client(pars, mp_msc_ip, mp_msc_smpp_port, "", -1));
191}
192
193
Harald Weltea49e36e2018-01-21 19:29:33 +0100194function f_init_mncc(charstring id) runs on MTC_CT {
195 id := id & "-MNCC";
196 var MnccOps ops := {
197 create_cb := refers(MNCC_Emulation.ExpectedCreateCallback),
198 unitdata_cb := refers(MNCC_Emulation.DummyUnitdataCallback)
199 }
200
201 vc_MNCC := MNCC_Emulation_CT.create(id);
202 map(vc_MNCC:MNCC, system:MNCC_CODEC_PT);
203 vc_MNCC.start(MNCC_Emulation.main(ops, id, mp_msc_mncc));
Harald Weltef6dd64d2017-11-19 12:09:51 +0100204}
205
Harald Welte4aa970c2018-01-26 10:38:09 +0100206function f_init_mgcp(charstring id) runs on MTC_CT {
207 id := id & "-MGCP";
208 var MGCPOps ops := {
209 create_cb := refers(MGCP_Emulation.ExpectedCreateCallback),
210 unitdata_cb := refers(MGCP_Emulation.DummyUnitdataCallback)
211 }
212 var MGCP_conn_parameters pars := {
Harald Welte6126fb02018-01-27 20:08:24 +0100213 callagent_ip := mp_msc_ip,
Harald Welte4aa970c2018-01-26 10:38:09 +0100214 callagent_udp_port := -1,
Harald Welte6126fb02018-01-27 20:08:24 +0100215 mgw_ip := mp_mgw_ip,
216 mgw_udp_port := mp_mgw_port
Harald Welte4aa970c2018-01-26 10:38:09 +0100217 }
218
219 vc_MGCP := MGCP_Emulation_CT.create(id);
220 map(vc_MGCP:MGCP, system:MGCP_CODEC_PT);
221 vc_MGCP.start(MGCP_Emulation.main(ops, pars, id));
222}
223
Philipp Maierc09a1312019-04-09 16:05:26 +0200224function ForwardUnitdataCallback(PDU_SGsAP msg)
225runs on SGsAP_Emulation_CT return template PDU_SGsAP {
226 SGsAP_CLIENT.send(msg);
227 return omit;
228}
229
Harald Welte4263c522018-12-06 11:56:27 +0100230function f_init_sgsap(charstring id) runs on MTC_CT {
231 id := id & "-SGsAP";
232 var SGsAPOps ops := {
233 create_cb := refers(SGsAP_Emulation.ExpectedCreateCallback),
Philipp Maierc09a1312019-04-09 16:05:26 +0200234 unitdata_cb := refers(ForwardUnitdataCallback)
Harald Welte4263c522018-12-06 11:56:27 +0100235 }
236 var SGsAP_conn_parameters pars := {
237 remote_ip := mp_msc_ip,
238 remote_sctp_port := 29118,
239 local_ip := "",
240 local_sctp_port := -1
241 }
242
243 vc_SGsAP := SGsAP_Emulation_CT.create(id);
244 map(vc_SGsAP:SGsAP, system:SGsAP_CODEC_PT);
245 vc_SGsAP.start(SGsAP_Emulation.main(ops, pars, id));
246}
247
248
Harald Weltea49e36e2018-01-21 19:29:33 +0100249function f_init_gsup(charstring id) runs on MTC_CT {
250 id := id & "-GSUP";
251 var GsupOps ops := {
252 create_cb := refers(GSUP_Emulation.ExpectedCreateCallback)
253 }
254
255 vc_GSUP_IPA := IPA_Emulation_CT.create(id & "-IPA");
256 vc_GSUP := GSUP_Emulation_CT.create(id);
257
258 map(vc_GSUP_IPA:IPA_PORT, system:IPA_CODEC_PT);
259 connect(vc_GSUP:GSUP, vc_GSUP_IPA:IPA_GSUP_PORT);
260 /* we use this hack to get events like ASP_IPA_EVENT_UP */
261 connect(vc_GSUP_IPA:IPA_CTRL_PORT, self:GSUP_IPA_EVENT);
262
263 vc_GSUP.start(GSUP_Emulation.main(ops, id));
264 vc_GSUP_IPA.start(IPA_Emulation.main_server(mp_hlr_ip, mp_hlr_port));
265
266 /* wait for incoming connection to GSUP port before proceeding */
267 timer T := 10.0;
268 T.start;
269 alt {
270 [] GSUP_IPA_EVENT.receive(t_ASP_IPA_EVT_UD(ASP_IPA_EVENT_UP)) { }
271 [] T.timeout {
Harald Welte458fd372018-03-21 11:26:23 +0100272 setverdict(fail, "No connection to GSUP Port");
Daniel Willmannafce8662018-07-06 23:11:32 +0200273 mtc.stop
Harald Weltea49e36e2018-01-21 19:29:33 +0100274 }
275 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100276}
277
Philipp Maierc09a1312019-04-09 16:05:26 +0200278function f_init(integer num_bsc := 1, boolean sgsap := false, boolean gsup := true) runs on MTC_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +0100279
280 if (g_initialized == true) {
281 return;
282 }
283 g_initialized := true;
284
Philipp Maier75932982018-03-27 14:52:35 +0200285 if (num_bsc > NUM_BSC) {
Daniel Willmannafce8662018-07-06 23:11:32 +0200286 testcase.stop("excess number of BSC instances requested");
Philipp Maier75932982018-03-27 14:52:35 +0200287 }
288
289 for (var integer i := 0; i < num_bsc; i := i + 1) {
290 if (isbound(mp_bssap_cfg[i])) {
Harald Welte3ca0ce12019-04-23 17:18:48 +0200291 f_ran_adapter_init(g_bssap[i], mp_bssap_cfg[i], "MSC_Test_" & int2str(i), BSC_RanOps);
292 f_ran_adapter_start(g_bssap[i]);
Philipp Maier75932982018-03-27 14:52:35 +0200293 } else {
Daniel Willmannafce8662018-07-06 23:11:32 +0200294 testcase.stop("missing BSSAP configuration");
Philipp Maier75932982018-03-27 14:52:35 +0200295 }
296 }
297
Harald Weltea49e36e2018-01-21 19:29:33 +0100298 f_ipa_ctrl_start(mp_msc_ip, mp_msc_ctrl_port);
299 f_init_mncc("MSC_Test");
Harald Welte4aa970c2018-01-26 10:38:09 +0100300 f_init_mgcp("MSC_Test");
Philipp Maierc09a1312019-04-09 16:05:26 +0200301
302 if (gsup == true) {
303 f_init_gsup("MSC_Test");
304 }
Harald Weltef640a012018-04-14 17:49:21 +0200305 f_init_smpp("MSC_Test");
Philipp Maier57865482019-01-07 18:33:13 +0100306
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100307 if (sgsap == true) {
Philipp Maier57865482019-01-07 18:33:13 +0100308 f_init_sgsap("MSC_Test");
309 }
Harald Welte3ca1c902018-01-24 18:51:27 +0100310
311 map(self:MSCVTY, system:MSCVTY);
312 f_vty_set_prompts(MSCVTY);
313 f_vty_transceive(MSCVTY, "enable");
Harald Welteb14c77a2018-01-25 17:25:44 +0100314
315 /* set some defaults */
316 f_vty_config(MSCVTY, "network", "authentication optional");
317 f_vty_config(MSCVTY, "msc", "assign-tmsi");
318 f_vty_config(MSCVTY, "network", "encryption a5 0");
Harald Weltef6dd64d2017-11-19 12:09:51 +0100319}
320
Philipp Maier328d1662018-03-07 10:40:27 +0100321/* Initialize for a direct connection to BSSAP. This function is an alternative
322 * to f_init() when the high level functions of the BSC_ConnectionHandler are
323 * not needed. */
324function f_init_bssap_direct() runs on MTC_CT {
Harald Welte3ca0ce12019-04-23 17:18:48 +0200325 f_ran_adapter_init(g_bssap[0], mp_bssap_cfg[0], "MSC_Test", omit);
Philipp Maier75932982018-03-27 14:52:35 +0200326 connect(g_bssap[0].vc_SCCP:SCCP_SP_PORT, self:BSSAP_DIRECT);
Philipp Maier328d1662018-03-07 10:40:27 +0100327
328 /* Start guard timer and activate it as default */
329 Tguard_direct.start
330 activate(as_Tguard_direct());
331}
332
Harald Weltef6dd64d2017-11-19 12:09:51 +0100333template PDU_BSSAP ts_BSSAP_BSSMAP := {
334 discriminator := '0'B,
335 spare := '0000000'B,
336 dlci := omit,
337 lengthIndicator := 0, /* overwritten by codec */
338 pdu := ?
339}
340
341template PDU_BSSAP tr_BSSAP_BSSMAP := {
342 discriminator := '0'B,
343 spare := '0000000'B,
344 dlci := omit,
345 lengthIndicator := ?,
346 pdu := {
347 bssmap := ?
348 }
349}
350
351
352type integer BssmapCause;
353
354template (value) BSSMAP_IE_Cause ts_BSSMAP_IE_Cause(BssmapCause val) := {
355 elementIdentifier := '04'O,
356 lengthIndicator := 0,
357 causeValue := int2bit(val, 7),
358 extensionCauseValue := '0'B,
359 spare1 := omit
360}
361
362template (value) PDU_BSSAP ts_BSSMAP_Reset(BssmapCause cause) modifies ts_BSSAP_BSSMAP := {
363 pdu := {
364 bssmap := {
365 reset := {
366 messageType := '30'O,
367 cause := ts_BSSMAP_IE_Cause(cause),
368 a_InterfaceSelectorForReset := omit
369 }
370 }
371 }
372}
373
374template (value) PDU_BSSAP ts_BSSMAP_ResetAck modifies ts_BSSAP_BSSMAP := {
375 pdu := {
376 bssmap := {
377 resetAck := {
378 messageType := '31'O,
379 a_InterfaceSelectorForReset := omit
380 }
381 }
382 }
383}
384
385template PDU_BSSAP tr_BSSMAP_ResetAck modifies tr_BSSAP_BSSMAP := {
386 pdu := {
387 bssmap := {
388 resetAck := {
389 messageType := '31'O,
390 a_InterfaceSelectorForReset := *
391 }
392 }
393 }
394}
395
396template BSSMAP_IE_CellIdentifier ts_BSSMAP_IE_CellID := {
397 elementIdentifier := '05'O,
398 lengthIndicator := 0,
399 cellIdentifierDiscriminator := '0000'B,
400 spare1_4 := '0000'B,
401 cellIdentification := ?
402}
403
404type uint16_t BssmapLAC;
405type uint16_t BssmapCI;
406
407/*
408template BSSMAP_IE_CellIdentifier ts_CellId_CGI(mcc, mnc, lac, ci)
409modifies ts_BSSMAP_IE_CellID := {
410 cellIdentification := {
411 cI_LAC_CGI := {
412 mnc_mcc := FIXME,
413 lac := int2oct(lac, 2),
414 ci := int2oct(ci, 2)
415 }
416 }
417}
418*/
419
420template BSSMAP_IE_CellIdentifier ts_CellID_LAC_CI(BssmapLAC lac, BssmapCI ci)
421modifies ts_BSSMAP_IE_CellID := {
422 cellIdentification := {
423 cI_LAC_CI := {
424 lac := int2oct(lac, 2),
425 ci := int2oct(ci, 2)
426 }
427 }
428}
429
430template BSSMAP_IE_CellIdentifier ts_CellId_CI(BssmapCI ci)
431modifies ts_BSSMAP_IE_CellID := {
432 cellIdentification := {
433 cI_CI := int2oct(ci, 2)
434 }
435}
436
437template BSSMAP_IE_CellIdentifier ts_CellId_none
438modifies ts_BSSMAP_IE_CellID := {
439 cellIdentification := {
440 cI_noCell := ''O
441 }
442}
443
444
445template BSSMAP_IE_Layer3Information ts_BSSMAP_IE_L3Info(octetstring l3info) := {
446 elementIdentifier := '17'O,
447 lengthIndicator := 0,
448 layer3info := l3info
449}
450
451template PDU_BSSAP ts_BSSMAP_ComplL3(BSSMAP_IE_CellIdentifier cell_id, octetstring l3_info)
452modifies ts_BSSAP_BSSMAP := {
453 pdu := {
454 bssmap := {
455 completeLayer3Information := {
456 messageType := '57'O,
457 cellIdentifier := cell_id,
458 layer3Information := ts_BSSMAP_IE_L3Info(l3_info),
459 chosenChannel := omit,
460 lSAIdentifier := omit,
461 aPDU := omit,
462 codecList := omit,
463 redirectAttemptFlag := omit,
464 sendSequenceNumber := omit,
465 iMSI := omit
466 }
467 }
468 }
469}
470
471template PDU_BSSAP ts_BSSMAP_HandoReq(BssmapCause cause, BSSMAP_IE_CellIdentifierList cid_list)
472modifies ts_BSSAP_BSSMAP := {
473 pdu := {
474 bssmap := {
475 handoverRequired := {
476 messageType := '11'O,
477 cause := ts_BSSMAP_IE_Cause(cause),
478 responseRequest := omit,
479 cellIdentifierList := cid_list,
480 circuitPoolList := omit,
481 currentChannelType1 := omit,
482 speechVersion := omit,
483 queueingIndicator := omit,
484 oldToNewBSSInfo := omit,
485 sourceToTargetRNCTransparentInfo := omit,
486 sourceToTargetRNCTransparentInfoCDMA := omit,
487 gERANClassmark := omit,
488 talkerPriority := omit,
489 speechCodec := omit,
490 cSG_Identifier := omit
491 }
492 }
493 }
494}
495
Harald Weltea49e36e2018-01-21 19:29:33 +0100496type function void_fn(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100497
Harald Weltea49e36e2018-01-21 19:29:33 +0100498/* FIXME: move into BSC_ConnectionHandler? */
Harald Welte9b751a62019-04-14 17:39:29 +0200499function f_init_pars(integer imsi_suffix, boolean sgsap := false, boolean gsup := true, integer ran_idx := 0,
500 boolean ran_is_geran := true)
Harald Weltef9abf8d2019-04-21 13:07:17 +0200501runs on MTC_CT return BSC_ConnHdlrPars {
Harald Weltede371492018-01-27 23:44:41 +0100502 var BSC_ConnHdlrNetworkPars net_pars := {
503 kc_support := '0A'O, /* A5/1 and A5/3 enabled */
504 expect_tmsi := true,
505 expect_auth := false,
506 expect_ciph := false
507 };
Harald Weltea49e36e2018-01-21 19:29:33 +0100508 var BSC_ConnHdlrPars pars := {
Harald Weltef9abf8d2019-04-21 13:07:17 +0200509 sccp_addr_own := g_bssap[ran_idx].sccp_addr_own,
510 sccp_addr_peer := g_bssap[ran_idx].sccp_addr_peer,
Harald Welteedbab812018-03-18 16:02:25 +0100511 cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42)),
Harald Welte81b7f9d2018-01-24 19:06:24 +0100512 imei := f_gen_imei(imsi_suffix),
513 imsi := f_gen_imsi(imsi_suffix),
514 msisdn := f_gen_msisdn(imsi_suffix),
Harald Welte256571e2018-01-24 18:47:19 +0100515 tmsi := omit,
Harald Welte9de84792018-01-28 01:06:35 +0100516 cm1 := valueof(ts_CM1),
Harald Welte82600572018-01-21 20:54:08 +0100517 cm2 := valueof(ts_CM2_default),
Harald Welte16114282018-01-24 22:41:21 +0100518 cm3 := omit,
Harald Weltede371492018-01-27 23:44:41 +0100519 vec := omit,
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100520 net := net_pars,
Philipp Maieraeb29a82018-11-08 17:40:53 +0100521 send_early_cm := true,
522 ipa_ctrl_ip := mp_msc_ip,
523 ipa_ctrl_port := mp_msc_ctrl_port,
Philipp Maier9b690e42018-12-21 11:50:03 +0100524 ipa_ctrl_enable := true,
Philipp Maier57865482019-01-07 18:33:13 +0100525 mm_info := mp_mm_info,
Philipp Maierc09a1312019-04-09 16:05:26 +0200526 sgsap_enable := sgsap,
Harald Weltef9abf8d2019-04-21 13:07:17 +0200527 gsup_enable := gsup,
Harald Weltec1f937a2019-04-21 21:19:23 +0200528 ran_idx := ran_idx,
Harald Welte9b751a62019-04-14 17:39:29 +0200529 use_umts_aka := false,
530 ran_is_geran := ran_is_geran
Harald Weltea49e36e2018-01-21 19:29:33 +0100531 };
Harald Weltee13cfb22019-04-23 16:52:02 +0200532 if (not ran_is_geran) {
533 pars.use_umts_aka := true;
534 pars.net.expect_auth := true;
535 }
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100536 return pars;
537}
538
539function f_start_handler_with_pars(void_fn fn, BSC_ConnHdlrPars pars) runs on MTC_CT return BSC_ConnHdlr {
540 var BSC_ConnHdlr vc_conn;
541 var charstring id := testcasename();
Harald Weltea49e36e2018-01-21 19:29:33 +0100542
543 vc_conn := BSC_ConnHdlr.create(id);
544 /* BSSMAP part / A interface */
Harald Weltef9abf8d2019-04-21 13:07:17 +0200545 connect(vc_conn:BSSAP, g_bssap[pars.ran_idx].vc_RAN:CLIENT);
546 connect(vc_conn:BSSAP_PROC, g_bssap[pars.ran_idx].vc_RAN:PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100547 /* MNCC part */
548 connect(vc_conn:MNCC, vc_MNCC:MNCC_CLIENT);
549 connect(vc_conn:MNCC_PROC, vc_MNCC:MNCC_PROC);
Harald Welte4aa970c2018-01-26 10:38:09 +0100550 /* MGCP part */
551 connect(vc_conn:MGCP, vc_MGCP:MGCP_CLIENT);
552 connect(vc_conn:MGCP_PROC, vc_MGCP:MGCP_PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100553 /* GSUP part */
Philipp Maierc09a1312019-04-09 16:05:26 +0200554 if (pars.gsup_enable == true) {
555 connect(vc_conn:GSUP, vc_GSUP:GSUP_CLIENT);
556 connect(vc_conn:GSUP_PROC, vc_GSUP:GSUP_PROC);
557 }
Harald Weltef640a012018-04-14 17:49:21 +0200558 /* SMPP part */
559 connect(vc_conn:SMPP, vc_SMPP:SMPP_CLIENT);
560 connect(vc_conn:SMPP_PROC, vc_SMPP:SMPP_PROC);
Harald Welte4263c522018-12-06 11:56:27 +0100561 /* SGs part */
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100562 if (pars.sgsap_enable == true) {
Philipp Maier57865482019-01-07 18:33:13 +0100563 connect(vc_conn:SGsAP, vc_SGsAP:SGsAP_CLIENT);
564 connect(vc_conn:SGsAP_PROC, vc_SGsAP:SGsAP_PROC);
565 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100566
Harald Weltea10db902018-01-27 12:44:49 +0100567 /* We cannot use vc_conn.start(f_init_handler(fn, id, pars)); as we cannot have
568 * a stand-alone 'derefers()' call, see https://www.eclipse.org/forums/index.php/t/1091364/ */
Harald Weltea49e36e2018-01-21 19:29:33 +0100569 vc_conn.start(derefers(fn)(id, pars));
570 return vc_conn;
571}
572
Harald Welte9b751a62019-04-14 17:39:29 +0200573function f_start_handler(void_fn fn, integer imsi_suffix, integer ran_idx := 0, boolean ran_is_geran := true)
574runs on MTC_CT return BSC_ConnHdlr {
575 return f_start_handler_with_pars(fn, f_init_pars(imsi_suffix, ran_idx := ran_idx, ran_is_geran := ran_is_geran));
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100576}
577
Harald Weltea49e36e2018-01-21 19:29:33 +0100578private function f_tc_lu_imsi_noauth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100579 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100580 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100581}
Harald Weltea49e36e2018-01-21 19:29:33 +0100582testcase TC_lu_imsi_noauth_tmsi() runs on MTC_CT {
583 var BSC_ConnHdlr vc_conn;
584 f_init();
585
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100586 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi), 1);
Harald Weltea49e36e2018-01-21 19:29:33 +0100587 vc_conn.done;
588}
589
590private function f_tc_lu_imsi_noauth_notmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100591 pars.net.expect_tmsi := false;
Harald Weltea10db902018-01-27 12:44:49 +0100592 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100593 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100594}
Harald Weltea49e36e2018-01-21 19:29:33 +0100595testcase TC_lu_imsi_noauth_notmsi() runs on MTC_CT {
596 var BSC_ConnHdlr vc_conn;
597 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100598 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
Harald Weltea49e36e2018-01-21 19:29:33 +0100599
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100600 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi), 2);
Harald Weltea49e36e2018-01-21 19:29:33 +0100601 vc_conn.done;
602}
603
604/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
Harald Weltee13cfb22019-04-23 16:52:02 +0200605friend function f_tc_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100606 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100607 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
608
609 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +0200610 f_cl3_or_initial_ue(l3_lu);
Harald Weltea49e36e2018-01-21 19:29:33 +0100611 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
612 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
613 alt {
Harald Welte5946b332018-03-18 23:32:21 +0100614 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej(int2oct(23,1)))) {
615 f_expect_clear();
616 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100617 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
618 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200619 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100620 }
621 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100622}
623testcase TC_lu_imsi_reject() runs on MTC_CT {
624 var BSC_ConnHdlr vc_conn;
625 f_init();
626
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100627 vc_conn := f_start_handler(refers(f_tc_lu_imsi_reject), 3);
Harald Weltea49e36e2018-01-21 19:29:33 +0100628 vc_conn.done;
629}
630
Harald Weltee13cfb22019-04-23 16:52:02 +0200631
632
Harald Weltea49e36e2018-01-21 19:29:33 +0100633/* Do LU by IMSI, timeout on GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +0200634friend function f_tc_lu_imsi_timeout_gsup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100635 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100636 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
637
638 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +0200639 f_cl3_or_initial_ue(l3_lu);
Harald Weltea49e36e2018-01-21 19:29:33 +0100640 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
641 /* Normally the HLR would need to respond here, but we decide to force a timeout here */
642 alt {
643 /* FIXME: Expect specific reject cause */
Harald Welte5946b332018-03-18 23:32:21 +0100644 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
645 f_expect_clear();
646 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100647 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
648 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200649 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100650 }
651 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100652}
653testcase TC_lu_imsi_timeout_gsup() runs on MTC_CT {
654 var BSC_ConnHdlr vc_conn;
655 f_init();
656
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100657 vc_conn := f_start_handler(refers(f_tc_lu_imsi_timeout_gsup), 4);
Harald Weltea49e36e2018-01-21 19:29:33 +0100658 vc_conn.done;
659}
660
Harald Weltee13cfb22019-04-23 16:52:02 +0200661
Harald Welte7b1b2812018-01-22 21:23:06 +0100662private function f_tc_lu_imsi_auth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100663 pars.net.expect_auth := true;
Harald Weltea10db902018-01-27 12:44:49 +0100664 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100665 f_perform_lu();
Harald Welte7b1b2812018-01-22 21:23:06 +0100666}
667testcase TC_lu_imsi_auth_tmsi() runs on MTC_CT {
668 var BSC_ConnHdlr vc_conn;
669 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100670 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte7b1b2812018-01-22 21:23:06 +0100671
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100672 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi), 5);
Harald Welte7b1b2812018-01-22 21:23:06 +0100673 vc_conn.done;
674}
675
Harald Weltee13cfb22019-04-23 16:52:02 +0200676
677friend function f_tc_lu_imsi_auth3g_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte8a397ae2019-04-21 22:03:37 +0200678 pars.net.expect_auth := true;
679 pars.use_umts_aka := true;
680 f_init_handler(pars);
681 f_perform_lu();
682}
683testcase TC_lu_imsi_auth3g_tmsi() runs on MTC_CT {
684 var BSC_ConnHdlr vc_conn;
685 f_init();
686 f_vty_config(MSCVTY, "network", "authentication required");
687
688 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi), 1005);
689 vc_conn.done;
690}
Harald Weltea49e36e2018-01-21 19:29:33 +0100691
Harald Weltee13cfb22019-04-23 16:52:02 +0200692
Harald Weltea49e36e2018-01-21 19:29:33 +0100693/* Send CM SERVICE REQ for IMSI that has never performed LU before */
Harald Weltee13cfb22019-04-23 16:52:02 +0200694friend function f_tc_cmserv_imsi_unknown(charstring id, BSC_ConnHdlrPars pars)
Harald Weltea49e36e2018-01-21 19:29:33 +0100695runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100696 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100697
698 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welteedbab812018-03-18 16:02:25 +0100699 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
Harald Welte6ed6bf92018-01-24 21:09:15 +0100700 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
Harald Weltea49e36e2018-01-21 19:29:33 +0100701
702 f_create_gsup_expect(hex2str(g_pars.imsi));
703
704 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200705 f_cl3_or_initial_ue(l3_info);
Harald Weltea49e36e2018-01-21 19:29:33 +0100706
707 timer T := 10.0;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100708 T.start;
709 alt {
Harald Weltea49e36e2018-01-21 19:29:33 +0100710 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
711 //[] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_ACC)) { }
Daniel Willmannafce8662018-07-06 23:11:32 +0200712 [] BSSAP.receive {
713 setverdict(fail, "Received unexpected BSSAP");
714 mtc.stop;
715 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100716 [] GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi)) {
717 setverdict(fail, "Unexpected GSUP UL REQ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200718 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100719 }
Daniel Willmannafce8662018-07-06 23:11:32 +0200720 [] T.timeout {
721 setverdict(fail, "Timeout waiting for CM SERV REQ");
722 mtc.stop;
723 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100724 }
725
Harald Welte1ddc7162018-01-27 14:25:46 +0100726 f_expect_clear();
Harald Weltef6dd64d2017-11-19 12:09:51 +0100727}
Harald Weltea49e36e2018-01-21 19:29:33 +0100728testcase TC_cmserv_imsi_unknown() runs on MTC_CT {
729 var BSC_ConnHdlr vc_conn;
730 f_init();
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100731 vc_conn := f_start_handler(refers(f_tc_cmserv_imsi_unknown), 6);
Harald Weltea49e36e2018-01-21 19:29:33 +0100732 vc_conn.done;
733}
734
Harald Weltee13cfb22019-04-23 16:52:02 +0200735
736friend function f_tc_lu_and_mo_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100737 f_init_handler(pars);
Harald Welteb71901a2018-01-26 19:16:05 +0100738 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
739 cpars.bss_rtp_port := 1110;
740 cpars.mgcp_connection_id_bss := '22222'H;
741 cpars.mgcp_connection_id_mss := '33333'H;
Philipp Maierf1e02bb2018-03-15 16:30:00 +0100742 cpars.mgcp_ep := "rtpbridge/1@mgw";
Harald Welte2bb825f2018-01-22 11:31:18 +0100743
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100744 f_perform_lu();
Harald Welteb71901a2018-01-26 19:16:05 +0100745 f_mo_call(cpars);
Harald Welte2bb825f2018-01-22 11:31:18 +0100746}
747testcase TC_lu_and_mo_call() runs on MTC_CT {
748 var BSC_ConnHdlr vc_conn;
749 f_init();
750
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100751 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_call), 7);
Harald Welte071ed732018-01-23 19:53:52 +0100752 vc_conn.done;
753}
754
Harald Weltee13cfb22019-04-23 16:52:02 +0200755
Harald Welte071ed732018-01-23 19:53:52 +0100756/* Test LU (with authentication enabled), where HLR times out sending SAI response */
Harald Weltee13cfb22019-04-23 16:52:02 +0200757friend function f_tc_lu_auth_sai_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100758 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100759
760 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
761 var PDU_DTAP_MT dtap_mt;
762
763 /* tell GSUP dispatcher to send this IMSI to us */
764 f_create_gsup_expect(hex2str(g_pars.imsi));
765
766 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200767 f_cl3_or_initial_ue(l3_lu);
Harald Welte071ed732018-01-23 19:53:52 +0100768
769 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200770 if (pars.ran_is_geran) {
771 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
772 }
Harald Welte071ed732018-01-23 19:53:52 +0100773
774 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
775 /* The HLR would normally return an auth vector here, but we fail to do so. */
776
777 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100778 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100779}
780testcase TC_lu_auth_sai_timeout() runs on MTC_CT {
781 var BSC_ConnHdlr vc_conn;
782 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100783 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100784
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100785 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_timeout), 8);
Harald Welte071ed732018-01-23 19:53:52 +0100786 vc_conn.done;
787}
788
Harald Weltee13cfb22019-04-23 16:52:02 +0200789
Harald Welte071ed732018-01-23 19:53:52 +0100790/* Test LU (with authentication enabled), where HLR rejects sending SAI error */
Harald Weltee13cfb22019-04-23 16:52:02 +0200791friend function f_tc_lu_auth_sai_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100792 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100793
794 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
795 var PDU_DTAP_MT dtap_mt;
796
797 /* tell GSUP dispatcher to send this IMSI to us */
798 f_create_gsup_expect(hex2str(g_pars.imsi));
799
800 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200801 f_cl3_or_initial_ue(l3_lu);
Harald Welte071ed732018-01-23 19:53:52 +0100802
803 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200804 if (pars.ran_is_geran) {
805 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
806 }
Harald Welte071ed732018-01-23 19:53:52 +0100807
808 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
809 GSUP.send(ts_GSUP_SAI_ERR(g_pars.imsi, 13));
810
811 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100812 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100813}
814testcase TC_lu_auth_sai_err() runs on MTC_CT {
815 var BSC_ConnHdlr vc_conn;
816 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100817 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100818
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100819 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_err), 9);
Harald Welte2bb825f2018-01-22 11:31:18 +0100820 vc_conn.done;
821}
Harald Weltea49e36e2018-01-21 19:29:33 +0100822
Harald Weltee13cfb22019-04-23 16:52:02 +0200823
Harald Weltebc881782018-01-23 20:09:15 +0100824/* Test LU but BSC will send a clear request in the middle */
825private function f_tc_lu_clear_request(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100826 f_init_handler(pars);
Harald Weltebc881782018-01-23 20:09:15 +0100827
828 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
829 var PDU_DTAP_MT dtap_mt;
830
831 /* tell GSUP dispatcher to send this IMSI to us */
832 f_create_gsup_expect(hex2str(g_pars.imsi));
833
834 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200835 f_cl3_or_initial_ue(l3_lu);
Harald Weltebc881782018-01-23 20:09:15 +0100836
837 /* Send Early Classmark, just for the fun of it */
838 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
839
840 f_sleep(1.0);
841 /* send clear request in the middle of the LU */
842 BSSAP.send(ts_BSSMAP_ClearRequest(0));
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200843 alt {
844 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { repeat; }
845 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {}
846 }
Harald Weltebc881782018-01-23 20:09:15 +0100847 BSSAP.send(ts_BSSMAP_ClearComplete);
Harald Welte89a32492018-01-27 19:07:28 +0100848 alt {
849 /* See https://osmocom.org/issues/2862 */
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200850 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {
851 setverdict(fail, "Got a second Clear Command, only one expected");
Daniel Willmannafce8662018-07-06 23:11:32 +0200852 mtc.stop;
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200853 repeat;
854 }
Harald Welte6811d102019-04-14 22:23:14 +0200855 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte89a32492018-01-27 19:07:28 +0100856 }
Harald Weltebc881782018-01-23 20:09:15 +0100857 setverdict(pass);
858}
859testcase TC_lu_clear_request() runs on MTC_CT {
860 var BSC_ConnHdlr vc_conn;
861 f_init();
862
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100863 vc_conn := f_start_handler(refers(f_tc_lu_clear_request), 10);
Harald Weltebc881782018-01-23 20:09:15 +0100864 vc_conn.done;
865}
866
Harald Welte66af9e62018-01-24 17:28:21 +0100867/* Test LU but BSC will send a clear request in the middle */
Harald Weltee13cfb22019-04-23 16:52:02 +0200868friend function f_tc_lu_disconnect(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100869 f_init_handler(pars);
Harald Welte66af9e62018-01-24 17:28:21 +0100870
871 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
872 var PDU_DTAP_MT dtap_mt;
873
874 /* tell GSUP dispatcher to send this IMSI to us */
875 f_create_gsup_expect(hex2str(g_pars.imsi));
876
877 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200878 f_cl3_or_initial_ue(l3_lu);
Harald Welte66af9e62018-01-24 17:28:21 +0100879
880 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200881 if (pars.ran_is_geran) {
882 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
883 }
Harald Welte66af9e62018-01-24 17:28:21 +0100884
885 f_sleep(1.0);
886 /* send clear request in the middle of the LU */
Harald Welte6811d102019-04-14 22:23:14 +0200887 BSSAP.send(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_REQ);
Harald Welte66af9e62018-01-24 17:28:21 +0100888 setverdict(pass);
Neels Hofmeyrbb825c92019-03-06 15:35:50 +0100889 f_sleep(1.0);
Harald Welte66af9e62018-01-24 17:28:21 +0100890}
891testcase TC_lu_disconnect() runs on MTC_CT {
892 var BSC_ConnHdlr vc_conn;
893 f_init();
894
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100895 vc_conn := f_start_handler(refers(f_tc_lu_disconnect), 11);
Harald Welte66af9e62018-01-24 17:28:21 +0100896 vc_conn.done;
897}
898
Harald Welteba7b6d92018-01-23 21:32:34 +0100899/* Test LU but with illegal mobile identity type = IMEI */
Harald Weltee13cfb22019-04-23 16:52:02 +0200900friend function f_tc_lu_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100901 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +0100902
Harald Welte256571e2018-01-24 18:47:19 +0100903 var PDU_ML3_MS_NW l3_lu := f_build_lu_imei(g_pars.imei)
Harald Welteba7b6d92018-01-23 21:32:34 +0100904 var PDU_DTAP_MT dtap_mt;
905
906 /* tell GSUP dispatcher to send this IMSI to us */
907 f_create_gsup_expect(hex2str(g_pars.imsi));
908
909 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200910 f_cl3_or_initial_ue(l3_lu);
Harald Welteba7b6d92018-01-23 21:32:34 +0100911
912 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200913 if (pars.ran_is_geran) {
914 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
915 }
Harald Welteba7b6d92018-01-23 21:32:34 +0100916 /* wait for LU reject, ignore any ID REQ */
917 alt {
918 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { }
919 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req)) { repeat; }
920 }
921 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100922 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +0100923}
924testcase TC_lu_by_imei() runs on MTC_CT {
925 var BSC_ConnHdlr vc_conn;
926 f_init();
927
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100928 vc_conn := f_start_handler(refers(f_tc_lu_by_imei), 12);
Harald Welteba7b6d92018-01-23 21:32:34 +0100929 vc_conn.done;
930}
931
Harald Weltee13cfb22019-04-23 16:52:02 +0200932
Harald Welteba7b6d92018-01-23 21:32:34 +0100933/* Test LU by TMSI with unknown TMSI, expect (and answer) ID REQ. */
934private function f_tc_lu_tmsi_noauth_unknown(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Stefan Sperling04fc4bc2018-06-25 17:44:57 +0200935 /* We piggyback a test for an MSC crash on overlong IMSI (OS#2864) onto this test. */
936 var hexstring overlong_imsi := '012345789ABCDEF0123456789ABCDEF'H;
Harald Weltea10db902018-01-27 12:44:49 +0100937 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +0100938
939 var PDU_ML3_MS_NW l3_lu := f_build_lu_tmsi('01020304'O); /* FIXME: Random */
940 var PDU_DTAP_MT dtap_mt;
941
942 /* tell GSUP dispatcher to send this IMSI to us */
943 f_create_gsup_expect(hex2str(g_pars.imsi));
944
945 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200946 f_cl3_or_initial_ue(l3_lu);
Harald Welteba7b6d92018-01-23 21:32:34 +0100947
948 /* Send Early Classmark, just for the fun of it */
949 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
950
951 /* Wait for + respond to ID REQ (IMSI) */
952 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req('001'B)));
Stefan Sperling04fc4bc2018-06-25 17:44:57 +0200953 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(overlong_imsi))); /* test for OS#2864 */
Harald Welteba7b6d92018-01-23 21:32:34 +0100954 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(g_pars.imsi)));
955
956 /* Expect MSC to do UpdateLocation to HLR; respond to it */
957 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
958 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
959 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
960 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
961
962 alt {
Harald Welte7ec4fa82018-01-27 10:57:40 +0100963 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
964 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_TmsiRealloc_Cmpl));
965 }
Harald Welteba7b6d92018-01-23 21:32:34 +0100966 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
967 setverdict(fail, "Expected LU ACK, but received REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200968 mtc.stop;
Harald Welteba7b6d92018-01-23 21:32:34 +0100969 }
970 }
971
Philipp Maier9b690e42018-12-21 11:50:03 +0100972 /* Wait for MM-Information (if enabled) */
973 f_expect_mm_info();
974
Harald Welteba7b6d92018-01-23 21:32:34 +0100975 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100976 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +0100977}
978testcase TC_lu_by_tmsi_noauth_unknown() runs on MTC_CT {
979 var BSC_ConnHdlr vc_conn;
980 f_init();
981
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100982 vc_conn := f_start_handler(refers(f_tc_lu_tmsi_noauth_unknown), 13);
Harald Welteba7b6d92018-01-23 21:32:34 +0100983 vc_conn.done;
984}
985
986
Harald Welte45164da2018-01-24 12:51:27 +0100987/* Test IMSI DETACH (MI=IMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +0200988friend function f_tc_imsi_detach_by_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100989 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +0100990
991 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
992
993 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200994 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +0100995
996 /* Send Early Classmark, just for the fun of it? */
Harald Weltee13cfb22019-04-23 16:52:02 +0200997 if (pars.ran_is_geran) {
998 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
999 }
Harald Welte45164da2018-01-24 12:51:27 +01001000
1001 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001002 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001003}
1004testcase TC_imsi_detach_by_imsi() runs on MTC_CT {
1005 var BSC_ConnHdlr vc_conn;
1006 f_init();
1007
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001008 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imsi), 14);
Harald Welte45164da2018-01-24 12:51:27 +01001009 vc_conn.done;
1010}
1011
Harald Weltee13cfb22019-04-23 16:52:02 +02001012
Harald Welte45164da2018-01-24 12:51:27 +01001013/* Test IMSI DETACH (MI=TMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +02001014friend function f_tc_imsi_detach_by_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001015 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001016
1017 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV('01020304'O));
1018
1019 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001020 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +01001021
1022 /* Send Early Classmark, just for the fun of it? */
Harald Weltee13cfb22019-04-23 16:52:02 +02001023 if (pars.ran_is_geran) {
1024 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1025 }
Harald Welte45164da2018-01-24 12:51:27 +01001026
1027 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001028 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001029}
1030testcase TC_imsi_detach_by_tmsi() runs on MTC_CT {
1031 var BSC_ConnHdlr vc_conn;
1032 f_init();
1033
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001034 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_tmsi), 15);
Harald Welte45164da2018-01-24 12:51:27 +01001035 vc_conn.done;
1036}
1037
Harald Weltee13cfb22019-04-23 16:52:02 +02001038
Harald Welte45164da2018-01-24 12:51:27 +01001039/* Test IMSI DETACH (MI=IMEI), which is illegal */
Harald Weltee13cfb22019-04-23 16:52:02 +02001040friend function f_tc_imsi_detach_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001041 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001042
Harald Welte256571e2018-01-24 18:47:19 +01001043 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte45164da2018-01-24 12:51:27 +01001044
1045 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001046 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +01001047
1048 /* Send Early Classmark, just for the fun of it? */
Harald Weltee13cfb22019-04-23 16:52:02 +02001049 if (pars.ran_is_geran) {
1050 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1051 }
Harald Welte45164da2018-01-24 12:51:27 +01001052
1053 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001054 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001055}
1056testcase TC_imsi_detach_by_imei() runs on MTC_CT {
1057 var BSC_ConnHdlr vc_conn;
1058 f_init();
1059
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001060 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imei), 16);
Harald Welte45164da2018-01-24 12:51:27 +01001061 vc_conn.done;
1062}
1063
1064
1065/* helper function for an emergency call. caller passes in mobile identity to use */
1066private function f_emerg_call(MobileIdentityLV mi) runs on BSC_ConnHdlr {
Harald Welte0bef21e2018-02-10 09:48:23 +01001067 var CallParameters cpars := valueof(t_CallParams('112'H, 0));
1068 cpars.emergency := true;
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001069 cpars.mgcp_ep := "rtpbridge/1@mgw";
Harald Welte45164da2018-01-24 12:51:27 +01001070
Harald Welte0bef21e2018-02-10 09:48:23 +01001071 f_mo_call(cpars);
Harald Welte45164da2018-01-24 12:51:27 +01001072}
1073
1074/* establish an emergency call by IMEI, no SIM inserted (and hence no IMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +02001075friend function f_tc_emerg_call_imei_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001076 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001077
Harald Welte256571e2018-01-24 18:47:19 +01001078 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001079 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_EMERG_CALL, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001080 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001081 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ('05'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +01001082 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001083}
1084testcase TC_emerg_call_imei_reject() runs on MTC_CT {
1085 var BSC_ConnHdlr vc_conn;
1086 f_init();
1087
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001088 vc_conn := f_start_handler(refers(f_tc_emerg_call_imei_reject), 17);
Harald Welte45164da2018-01-24 12:51:27 +01001089 vc_conn.done;
1090}
1091
Harald Weltee13cfb22019-04-23 16:52:02 +02001092
Harald Welted5b91402018-01-24 18:48:16 +01001093/* establish an emergency call by IMSI, SIM inserted (and hence IMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +02001094friend function f_tc_emerg_call_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001095 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001096 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001097 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001098 /* Then issue emergency call identified by IMSI */
1099 f_emerg_call(valueof(ts_MI_IMSI_LV(g_pars.imsi)));
1100}
1101testcase TC_emerg_call_imsi() runs on MTC_CT {
1102 var BSC_ConnHdlr vc_conn;
1103 f_init();
1104
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001105 vc_conn := f_start_handler(refers(f_tc_emerg_call_imsi), 18);
Harald Welte45164da2018-01-24 12:51:27 +01001106 vc_conn.done;
1107}
1108
Harald Weltee13cfb22019-04-23 16:52:02 +02001109
Harald Welte45164da2018-01-24 12:51:27 +01001110/* CM Service Request for VGCS -> reject */
1111private function f_tc_cm_serv_req_vgcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001112 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001113
1114 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001115 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001116
1117 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001118 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VGCS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001119 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001120 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001121 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001122}
1123testcase TC_cm_serv_req_vgcs_reject() runs on MTC_CT {
1124 var BSC_ConnHdlr vc_conn;
1125 f_init();
1126
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001127 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vgcs_reject), 19);
Harald Welte45164da2018-01-24 12:51:27 +01001128 vc_conn.done;
1129}
1130
1131/* CM Service Request for VBS -> reject */
1132private function f_tc_cm_serv_req_vbs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001133 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001134
1135 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001136 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001137
1138 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001139 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VBS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001140 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001141 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001142 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001143}
1144testcase TC_cm_serv_req_vbs_reject() runs on MTC_CT {
1145 var BSC_ConnHdlr vc_conn;
1146 f_init();
1147
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001148 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vbs_reject), 20);
Harald Welte45164da2018-01-24 12:51:27 +01001149 vc_conn.done;
1150}
1151
1152/* CM Service Request for LCS -> reject */
1153private function f_tc_cm_serv_req_lcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001154 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001155
1156 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001157 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001158
1159 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001160 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_LCS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001161 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001162 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001163 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001164}
1165testcase TC_cm_serv_req_lcs_reject() runs on MTC_CT {
1166 var BSC_ConnHdlr vc_conn;
1167 f_init();
1168
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001169 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_lcs_reject), 21);
Harald Welte45164da2018-01-24 12:51:27 +01001170 vc_conn.done;
1171}
1172
Harald Welte0195ab12018-01-24 21:50:20 +01001173/* CM Re-Establishment Request */
1174private function f_tc_cm_reest_req_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001175 f_init_handler(pars);
Harald Welte0195ab12018-01-24 21:50:20 +01001176
1177 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001178 f_perform_lu();
Harald Welte0195ab12018-01-24 21:50:20 +01001179
1180 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1181 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_REEST_REQ(0, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001182 f_cl3_or_initial_ue(l3_info);
Harald Welte0195ab12018-01-24 21:50:20 +01001183 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001184 f_expect_clear();
Harald Welte0195ab12018-01-24 21:50:20 +01001185}
1186testcase TC_cm_reest_req_reject() runs on MTC_CT {
1187 var BSC_ConnHdlr vc_conn;
1188 f_init();
Harald Welte0195ab12018-01-24 21:50:20 +01001189
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001190 vc_conn := f_start_handler(refers(f_tc_cm_reest_req_reject), 22);
Harald Welte0195ab12018-01-24 21:50:20 +01001191 vc_conn.done;
1192}
1193
Harald Weltec638f4d2018-01-24 22:00:36 +01001194/* Test LU (with authentication enabled), with wrong response from MS */
1195private function f_tc_lu_auth_2G_fail(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001196 f_init_handler(pars);
Harald Weltec638f4d2018-01-24 22:00:36 +01001197
1198 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
1199
1200 /* tell GSUP dispatcher to send this IMSI to us */
1201 f_create_gsup_expect(hex2str(g_pars.imsi));
1202
1203 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001204 f_cl3_or_initial_ue(l3_lu);
Harald Weltec638f4d2018-01-24 22:00:36 +01001205
1206 /* Send Early Classmark, just for the fun of it */
1207 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1208
1209 var AuthVector vec := f_gen_auth_vec_2g();
1210 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G(vec.rand, vec.sres, vec.kc));
1211 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
1212 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
1213
1214 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_AUTH_REQ(vec.rand)));
1215 /* Send back wrong auth response */
1216 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MT_MM_AUTH_RESP_2G('00000000'O)));
1217
1218 /* Expect GSUP AUTH FAIL REP to HLR */
1219 GSUP.receive(tr_GSUP_AUTH_FAIL_IND(g_pars.imsi));
1220
1221 /* Expect LU REJECT with Cause == Illegal MS */
1222 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej('03'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +01001223 f_expect_clear();
Harald Weltec638f4d2018-01-24 22:00:36 +01001224}
1225testcase TC_lu_auth_2G_fail() runs on MTC_CT {
1226 var BSC_ConnHdlr vc_conn;
1227 f_init();
1228 f_vty_config(MSCVTY, "network", "authentication required");
Harald Weltec638f4d2018-01-24 22:00:36 +01001229
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001230 vc_conn := f_start_handler(refers(f_tc_lu_auth_2G_fail), 23);
Harald Weltec638f4d2018-01-24 22:00:36 +01001231 vc_conn.done;
1232}
1233
Harald Weltede371492018-01-27 23:44:41 +01001234/* A5/1 + A5/3 permitted on network side, and MS capable to do it */
Harald Welte16114282018-01-24 22:41:21 +01001235private function f_tc_lu_imsi_auth_tmsi_encr_13_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +01001236 pars.net.expect_auth := true;
1237 pars.net.expect_ciph := true;
Harald Weltea10db902018-01-27 12:44:49 +01001238 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001239 f_perform_lu();
Harald Welte16114282018-01-24 22:41:21 +01001240}
1241testcase TC_lu_imsi_auth_tmsi_encr_13_13() runs on MTC_CT {
1242 var BSC_ConnHdlr vc_conn;
1243 f_init();
1244 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte16114282018-01-24 22:41:21 +01001245 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
1246
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001247 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_13), 24);
Harald Welte16114282018-01-24 22:41:21 +01001248 vc_conn.done;
1249}
1250
Harald Welte1af6ea82018-01-25 18:33:15 +01001251/* Test Complete L3 without payload */
1252private function f_tc_cl3_no_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001253 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001254
1255 /* Send Complete L3 Info with empty L3 frame */
1256 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1257 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, ''O))));
1258
Harald Weltef466eb42018-01-27 14:26:54 +01001259 timer T := 5.0;
1260 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001261 alt {
Harald Welte6811d102019-04-14 22:23:14 +02001262 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte1af6ea82018-01-25 18:33:15 +01001263 /* Expect LU REJECT with Cause == Illegal MS */
Harald Weltebdb3c452018-03-18 22:43:06 +01001264 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
Harald Welte6811d102019-04-14 22:23:14 +02001265 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001266 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001267 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001268 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001269 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001270 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001271 }
1272 setverdict(pass);
1273}
1274testcase TC_cl3_no_payload() runs on MTC_CT {
1275 var BSC_ConnHdlr vc_conn;
1276 f_init();
1277
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001278 vc_conn := f_start_handler(refers(f_tc_cl3_no_payload), 25);
Harald Welte1af6ea82018-01-25 18:33:15 +01001279 vc_conn.done;
1280}
1281
1282/* Test Complete L3 with random payload */
1283private function f_tc_cl3_rnd_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001284 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001285
Daniel Willmannaa14a382018-07-26 08:29:45 +02001286 /* length is limited by PDU_BSSAP length field which includes some
1287 * other fields beside l3info payload. So payl can only be 240 bytes
1288 * Since rnd() returns values < 1 multiply with 241
1289 */
1290 var integer len := float2int(rnd() * 241.0);
Harald Welte1af6ea82018-01-25 18:33:15 +01001291 var octetstring payl := f_rnd_octstring(len);
1292
1293 /* Send Complete L3 Info with empty L3 frame */
1294 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1295 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, payl))));
1296
Harald Weltef466eb42018-01-27 14:26:54 +01001297 timer T := 5.0;
1298 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001299 alt {
1300 /* Immediate disconnect */
Harald Welte6811d102019-04-14 22:23:14 +02001301 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte1af6ea82018-01-25 18:33:15 +01001302 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
Harald Welte6811d102019-04-14 22:23:14 +02001303 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001304 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001305 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001306 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001307 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001308 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001309 }
1310 setverdict(pass);
1311}
1312testcase TC_cl3_rnd_payload() runs on MTC_CT {
1313 var BSC_ConnHdlr vc_conn;
1314 f_init();
1315
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001316 vc_conn := f_start_handler(refers(f_tc_cl3_rnd_payload), 26);
Harald Welte1af6ea82018-01-25 18:33:15 +01001317 vc_conn.done;
1318}
1319
Harald Welte116e4332018-01-26 22:17:48 +01001320/* Test Complete L3 with random payload */
Harald Weltee13cfb22019-04-23 16:52:02 +02001321friend function f_tc_establish_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001322 f_init_handler(pars);
Harald Welte116e4332018-01-26 22:17:48 +01001323
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001324 f_perform_lu();
Harald Welte116e4332018-01-26 22:17:48 +01001325
Harald Welteb9e86fa2018-04-09 18:18:31 +02001326 f_establish_fully();
Daniel Willmann898a7e02018-05-17 12:16:16 +02001327 f_expect_clear(10.0);
Harald Welte116e4332018-01-26 22:17:48 +01001328}
1329testcase TC_establish_and_nothing() runs on MTC_CT {
1330 var BSC_ConnHdlr vc_conn;
1331 f_init();
1332
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001333 vc_conn := f_start_handler(refers(f_tc_establish_and_nothing), 27);
Harald Welte116e4332018-01-26 22:17:48 +01001334 vc_conn.done;
1335}
1336
Harald Weltee13cfb22019-04-23 16:52:02 +02001337
Harald Welte12510c52018-01-26 22:26:24 +01001338/* Test MO Call SETUP with no response from MNCC */
Harald Weltee13cfb22019-04-23 16:52:02 +02001339friend function f_tc_mo_setup_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier109e6aa2018-10-17 10:53:32 +02001340 f_init_handler(pars, 190.0);
Harald Weltea10db902018-01-27 12:44:49 +01001341
Harald Welte12510c52018-01-26 22:26:24 +01001342 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1343
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001344 f_perform_lu();
Harald Welte12510c52018-01-26 22:26:24 +01001345
Harald Welteb9e86fa2018-04-09 18:18:31 +02001346 f_establish_fully();
Harald Welte12510c52018-01-26 22:26:24 +01001347 f_create_mncc_expect(hex2str(cpars.called_party));
1348 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1349
1350 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
1351
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001352 var default ccrel := activate(as_optional_cc_rel(cpars));
1353
Philipp Maier109e6aa2018-10-17 10:53:32 +02001354 f_expect_clear(185.0);
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001355
1356 deactivate(ccrel);
1357
1358 f_sleep(1.0);
Harald Welte12510c52018-01-26 22:26:24 +01001359}
1360testcase TC_mo_setup_and_nothing() runs on MTC_CT {
1361 var BSC_ConnHdlr vc_conn;
1362 f_init();
1363
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001364 vc_conn := f_start_handler(refers(f_tc_mo_setup_and_nothing), 28);
Harald Welte12510c52018-01-26 22:26:24 +01001365 vc_conn.done;
1366}
1367
Harald Weltee13cfb22019-04-23 16:52:02 +02001368
Harald Welte3ab88002018-01-26 22:37:25 +01001369/* Test MO Call with no response to RAN-side CRCX */
Harald Weltee13cfb22019-04-23 16:52:02 +02001370friend function f_tc_mo_crcx_ran_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001371 f_init_handler(pars);
Harald Welte3ab88002018-01-26 22:37:25 +01001372 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1373 var MNCC_PDU mncc;
1374 var MgcpCommand mgcp_cmd;
1375
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001376 f_perform_lu();
Harald Welte3ab88002018-01-26 22:37:25 +01001377
Harald Welteb9e86fa2018-04-09 18:18:31 +02001378 f_establish_fully();
Harald Welte3ab88002018-01-26 22:37:25 +01001379 f_create_mncc_expect(hex2str(cpars.called_party));
1380 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1381
1382 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
1383 MNCC.receive(tr_MNCC_SETUP_ind(?, tr_MNCC_number(hex2str(cpars.called_party)))) -> value mncc;
1384 cpars.mncc_callref := mncc.u.signal.callref;
1385 MNCC.send(ts_MNCC_CALL_PROC_req(cpars.mncc_callref, cpars.mncc_bearer_cap));
1386 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_CALL_PROC(cpars.transaction_id)));
1387
1388 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
Harald Welte1852a842018-01-26 22:53:36 +01001389 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
1390 cpars.mgcp_ep := mgcp_cmd.line.ep;
Harald Welte3ab88002018-01-26 22:37:25 +01001391 /* never respond to this */
1392
Philipp Maier8e58f592018-03-14 11:10:56 +01001393 /* When the connection with the MGW fails, the MSC will first request
1394 * a release via call control. We will answer this request normally. */
1395 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id)));
1396 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id)));
1397
Harald Welte1ddc7162018-01-27 14:25:46 +01001398 f_expect_clear(30.0);
Harald Welte3ab88002018-01-26 22:37:25 +01001399}
1400testcase TC_mo_crcx_ran_timeout() runs on MTC_CT {
1401 var BSC_ConnHdlr vc_conn;
1402 f_init();
1403
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001404 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_timeout), 29);
Harald Welte3ab88002018-01-26 22:37:25 +01001405 vc_conn.done;
1406}
1407
Harald Weltee13cfb22019-04-23 16:52:02 +02001408
Harald Welte0cc82d92018-01-26 22:52:34 +01001409/* Test MO Call with reject to RAN-side CRCX */
Harald Weltee13cfb22019-04-23 16:52:02 +02001410friend function f_tc_mo_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001411 f_init_handler(pars);
Harald Welte0cc82d92018-01-26 22:52:34 +01001412 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1413 var MNCC_PDU mncc;
1414 var MgcpCommand mgcp_cmd;
1415
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001416 f_perform_lu();
Harald Welte0cc82d92018-01-26 22:52:34 +01001417
Harald Welteb9e86fa2018-04-09 18:18:31 +02001418 f_establish_fully();
Harald Welte0cc82d92018-01-26 22:52:34 +01001419 f_create_mncc_expect(hex2str(cpars.called_party));
1420 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1421
1422 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
1423 MNCC.receive(tr_MNCC_SETUP_ind(?, tr_MNCC_number(hex2str(cpars.called_party)))) -> value mncc;
1424 cpars.mncc_callref := mncc.u.signal.callref;
1425 MNCC.send(ts_MNCC_CALL_PROC_req(cpars.mncc_callref, cpars.mncc_bearer_cap));
1426 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_CALL_PROC(cpars.transaction_id)));
1427
1428 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001429
1430 /* Detect if the received CRCX is a wildcarded CRCX request. If yes,
1431 * set an endpoint name that fits the pattern. If not, just use the
1432 * endpoint name from the request */
1433 if (match(mgcp_cmd.line.ep, t_MGCP_EP_wildcard)) {
1434 cpars.mgcp_ep := "rtpbridge/1@mgw";
1435 } else {
1436 cpars.mgcp_ep := mgcp_cmd.line.ep;
1437 }
1438
Harald Welte0cc82d92018-01-26 22:52:34 +01001439 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001440
Harald Welte0cc82d92018-01-26 22:52:34 +01001441 /* Respond to CRCX with error */
1442 var MgcpResponse mgcp_rsp := {
1443 line := {
1444 code := "542",
1445 trans_id := mgcp_cmd.line.trans_id,
1446 string := "FORCED_FAIL"
1447 },
Harald Welte0cc82d92018-01-26 22:52:34 +01001448 sdp := omit
1449 }
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001450 var MgcpParameter mgcp_rsp_param := {
1451 code := "Z",
1452 val := cpars.mgcp_ep
1453 };
1454 mgcp_rsp.params[0] := mgcp_rsp_param;
Harald Welte0cc82d92018-01-26 22:52:34 +01001455 MGCP.send(mgcp_rsp);
1456
1457 timer T := 30.0;
1458 T.start;
1459 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001460 [] T.timeout {
1461 setverdict(fail, "Timeout waiting for channel release");
1462 mtc.stop;
1463 }
Daniel Willmann5868e622018-02-15 17:42:59 +01001464 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id))) {
1465 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id)));
1466 repeat;
1467 }
Harald Welte0cc82d92018-01-26 22:52:34 +01001468 [] MNCC.receive { repeat; }
1469 [] GSUP.receive { repeat; }
Philipp Maierc6e06f72018-04-11 18:12:23 +02001470 /* Note: As we did not respond properly to the CRCX from the MSC we
1471 * expect the MSC to omit any further MGCP operation (At least in the
1472 * the current implementation, there is no recovery mechanism implemented
1473 * and a DLCX can not be performed as the MSC does not know a specific
1474 * endpoint yet. */
Daniel Willmannafce8662018-07-06 23:11:32 +02001475 [] MGCP.receive {
1476 setverdict(fail, "Unexpected MGCP message");
1477 mtc.stop;
1478 }
Harald Welte5946b332018-03-18 23:32:21 +01001479 [] as_clear_cmd_compl_disc();
Harald Welte0cc82d92018-01-26 22:52:34 +01001480 }
1481}
1482testcase TC_mo_crcx_ran_reject() runs on MTC_CT {
1483 var BSC_ConnHdlr vc_conn;
1484 f_init();
1485
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001486 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_reject), 30);
Harald Welte0cc82d92018-01-26 22:52:34 +01001487 vc_conn.done;
1488}
1489
Harald Welte3ab88002018-01-26 22:37:25 +01001490
Harald Welte812f7a42018-01-27 00:49:18 +01001491/* helper function to start a MT call: MNCC SETUP; Paging; DChan est.; DTAP SETUP */
1492private function f_mt_call_start(inout CallParameters cpars) runs on BSC_ConnHdlr {
1493 var MNCC_PDU mncc;
1494 var MgcpCommand mgcp_cmd;
1495 var OCT4 tmsi;
1496
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001497 f_perform_lu();
Harald Welte812f7a42018-01-27 00:49:18 +01001498 if (isvalue(g_pars.tmsi)) {
1499 tmsi := g_pars.tmsi;
1500 } else {
1501 tmsi := 'FFFFFFFF'O;
1502 }
Harald Welte6811d102019-04-14 22:23:14 +02001503 f_ran_register_imsi(g_pars.imsi, tmsi);
Harald Welte812f7a42018-01-27 00:49:18 +01001504
1505 /* Allocate call reference and send SETUP via MNCC to MSC */
1506 cpars.mncc_callref := f_rnd_int(2147483648);
1507 MNCC.send(ts_MNCC_SETUP_req(cpars.mncc_callref, hex2str(g_pars.msisdn),
1508 hex2str(cpars.called_party), hex2str(g_pars.imsi)));
1509
1510 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02001511 f_expect_paging();
1512
Harald Welte812f7a42018-01-27 00:49:18 +01001513 /* MS -> MSC: PAGING RESPONSE */
Harald Welteb9e86fa2018-04-09 18:18:31 +02001514 f_establish_fully(EST_TYPE_PAG_RESP);
Harald Welte812f7a42018-01-27 00:49:18 +01001515
1516 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1517
1518 /* MSC->MS: SETUP */
1519 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_SETUP(cpars.transaction_id, *, cpars.called_party)));
1520}
1521
1522/* Test MT Call */
Harald Weltee13cfb22019-04-23 16:52:02 +02001523friend function f_tc_mt_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001524 f_init_handler(pars);
Harald Welte812f7a42018-01-27 00:49:18 +01001525 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1526 var MNCC_PDU mncc;
1527 var MgcpCommand mgcp_cmd;
1528
1529 f_mt_call_start(cpars);
1530
1531 /* MS->MSC: CALL CONFIRMED */
1532 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1533
1534 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1535
1536 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1537 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001538
1539 /* Detect if the received CRCX is a wildcarded CRCX request. If yes,
1540 * set an endpoint name that fits the pattern. If not, just use the
1541 * endpoint name from the request */
1542 if (match(mgcp_cmd.line.ep, t_MGCP_EP_wildcard)) {
1543 cpars.mgcp_ep := "rtpbridge/1@mgw";
1544 } else {
1545 cpars.mgcp_ep := mgcp_cmd.line.ep;
1546 }
1547
Harald Welte812f7a42018-01-27 00:49:18 +01001548 /* Respond to CRCX with error */
1549 var MgcpResponse mgcp_rsp := {
1550 line := {
1551 code := "542",
1552 trans_id := mgcp_cmd.line.trans_id,
1553 string := "FORCED_FAIL"
1554 },
Harald Welte812f7a42018-01-27 00:49:18 +01001555 sdp := omit
1556 }
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001557 var MgcpParameter mgcp_rsp_param := {
1558 code := "Z",
1559 val := cpars.mgcp_ep
1560 };
1561 mgcp_rsp.params[0] := mgcp_rsp_param;
Harald Welte812f7a42018-01-27 00:49:18 +01001562 MGCP.send(mgcp_rsp);
1563
1564 timer T := 30.0;
1565 T.start;
1566 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001567 [] T.timeout {
1568 setverdict(fail, "Timeout waiting for channel release");
1569 mtc.stop;
1570 }
Harald Welte812f7a42018-01-27 00:49:18 +01001571 [] MNCC.receive { repeat; }
1572 [] GSUP.receive { repeat; }
1573 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1574 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
1575 f_create_mgcp_delete_ep(cpars.mgcp_ep);
1576 repeat;
1577 }
1578 [] MGCP.receive { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001579 [] as_clear_cmd_compl_disc();
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001580 [] as_optional_cc_rel(cpars);
Harald Welte812f7a42018-01-27 00:49:18 +01001581 }
1582}
1583testcase TC_mt_crcx_ran_reject() runs on MTC_CT {
1584 var BSC_ConnHdlr vc_conn;
1585 f_init();
1586
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001587 vc_conn := f_start_handler(refers(f_tc_mt_crcx_ran_reject), 31);
Harald Welte812f7a42018-01-27 00:49:18 +01001588 vc_conn.done;
1589}
1590
1591
Harald Weltee13cfb22019-04-23 16:52:02 +02001592
Harald Welte812f7a42018-01-27 00:49:18 +01001593/* Test MT Call T310 timer */
Harald Weltee13cfb22019-04-23 16:52:02 +02001594friend function f_tc_mt_t310(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltead2952e2018-01-27 14:12:46 +01001595 f_init_handler(pars, 200.0);
Harald Welte812f7a42018-01-27 00:49:18 +01001596 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1597 var MNCC_PDU mncc;
1598 var MgcpCommand mgcp_cmd;
1599
1600 f_mt_call_start(cpars);
1601
1602 /* MS->MSC: CALL CONFIRMED */
1603 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1604 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1605
1606 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1607 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
1608 cpars.mgcp_ep := mgcp_cmd.line.ep;
1609 /* FIXME: Respond to CRCX */
1610
1611 /* old libosmocore T310 default timeout is 180s. so let's wait 190 */
1612 timer T := 190.0;
1613 T.start;
1614 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001615 [] T.timeout {
1616 setverdict(fail, "Timeout waiting for T310");
1617 mtc.stop;
1618 }
Harald Welte812f7a42018-01-27 00:49:18 +01001619 [] MNCC.receive(tr_MNCC_DISC_ind(cpars.mncc_callref)) {
1620 MNCC.send(ts_MNCC_REL_req(cpars.mncc_callref, valueof(ts_MNCC_cause(23))));
1621 }
1622 }
1623 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_DISC(cpars.transaction_id)));
1624 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id)));
1625 /* FIXME: We're sending this with TIflag 0: allocated by sender, which is wrong */
1626 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id)));
1627
1628 alt {
Harald Welte812f7a42018-01-27 00:49:18 +01001629 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1630 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
1631 f_create_mgcp_delete_ep(cpars.mgcp_ep);
1632 repeat;
1633 }
Harald Welte5946b332018-03-18 23:32:21 +01001634 [] as_clear_cmd_compl_disc();
Harald Welte812f7a42018-01-27 00:49:18 +01001635 }
1636}
1637testcase TC_mt_t310() runs on MTC_CT {
1638 var BSC_ConnHdlr vc_conn;
1639 f_init();
1640
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001641 vc_conn := f_start_handler(refers(f_tc_mt_t310), 32);
Harald Welte812f7a42018-01-27 00:49:18 +01001642 vc_conn.done;
1643}
1644
Harald Weltee13cfb22019-04-23 16:52:02 +02001645
Harald Welte167458a2018-01-27 15:58:16 +01001646/* Perform successful LU + MO call, then GSUP LocationCancel. Subscriber must be denied CM SERV */
Harald Weltee13cfb22019-04-23 16:52:02 +02001647friend function f_tc_gsup_cancel(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte167458a2018-01-27 15:58:16 +01001648 f_init_handler(pars);
1649 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1650 cpars.bss_rtp_port := 1110;
1651 cpars.mgcp_connection_id_bss := '22222'H;
1652 cpars.mgcp_connection_id_mss := '33333'H;
Daniel Willmann9b0235b2018-07-24 12:13:34 +02001653 cpars.mgcp_ep := "rtpbridge/1@mgw";
Harald Welte167458a2018-01-27 15:58:16 +01001654
1655 /* Location Update to make subscriber known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001656 f_perform_lu();
Harald Welte167458a2018-01-27 15:58:16 +01001657
1658 /* First MO call should succeed */
1659 f_mo_call(cpars);
1660
1661 /* Cancel the subscriber in the VLR */
1662 GSUP.send(ts_GSUP_CL_REQ(g_pars.imsi, OSMO_GSUP_CANCEL_TYPE_WITHDRAW));
1663 alt {
1664 [] GSUP.receive(tr_GSUP_CL_RES(g_pars.imsi)) { }
1665 [] GSUP.receive(tr_GSUP_CL_ERR(g_pars.imsi)) {
1666 setverdict(fail, "Received GSUP Location Cancel Error");
Daniel Willmannafce8662018-07-06 23:11:32 +02001667 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001668 }
1669 }
1670
1671 /* Follow-up transactions should fail */
1672 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1673 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001674 f_cl3_or_initial_ue(l3_info);
Harald Welte167458a2018-01-27 15:58:16 +01001675 alt {
1676 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
1677 [] BSSAP.receive {
1678 setverdict(fail, "Received unexpected BSSAP instead of CM SERV REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +02001679 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001680 }
1681 }
Neels Hofmeyr0f7429a2019-03-07 22:28:41 +01001682
1683 f_expect_clear();
Harald Welte167458a2018-01-27 15:58:16 +01001684 setverdict(pass);
1685}
1686testcase TC_gsup_cancel() runs on MTC_CT {
1687 var BSC_ConnHdlr vc_conn;
1688 f_init();
1689
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001690 vc_conn := f_start_handler(refers(f_tc_gsup_cancel), 33);
Harald Welte167458a2018-01-27 15:58:16 +01001691 vc_conn.done;
1692}
1693
Harald Weltee13cfb22019-04-23 16:52:02 +02001694
Harald Welte9de84792018-01-28 01:06:35 +01001695/* A5/1 only permitted on network side, and MS capable to do it */
1696private function f_tc_lu_imsi_auth_tmsi_encr_1_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1697 pars.net.expect_auth := true;
1698 pars.net.expect_ciph := true;
1699 pars.net.kc_support := '02'O; /* A5/1 only */
1700 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001701 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001702}
1703testcase TC_lu_imsi_auth_tmsi_encr_1_13() runs on MTC_CT {
1704 var BSC_ConnHdlr vc_conn;
1705 f_init();
1706 f_vty_config(MSCVTY, "network", "authentication required");
1707 f_vty_config(MSCVTY, "network", "encryption a5 1");
1708
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001709 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_1_13), 34);
Harald Welte9de84792018-01-28 01:06:35 +01001710 vc_conn.done;
1711}
1712
1713/* A5/3 only permitted on network side, and MS capable to do it */
1714private function f_tc_lu_imsi_auth_tmsi_encr_3_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1715 pars.net.expect_auth := true;
1716 pars.net.expect_ciph := true;
1717 pars.net.kc_support := '08'O; /* A5/3 only */
1718 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001719 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001720}
1721testcase TC_lu_imsi_auth_tmsi_encr_3_13() runs on MTC_CT {
1722 var BSC_ConnHdlr vc_conn;
1723 f_init();
1724 f_vty_config(MSCVTY, "network", "authentication required");
1725 f_vty_config(MSCVTY, "network", "encryption a5 3");
1726
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001727 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_13), 35);
Harald Welte9de84792018-01-28 01:06:35 +01001728 vc_conn.done;
1729}
1730
1731/* A5/3 only permitted on network side, and MS with only A5/1 support */
1732private function f_tc_lu_imsi_auth_tmsi_encr_3_1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1733 pars.net.expect_auth := true;
1734 pars.net.expect_ciph := true;
1735 pars.net.kc_support := '08'O; /* A5/3 only */
1736 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1737 f_init_handler(pars, 15.0);
1738
1739 /* cannot use f_perform_lu() as we expect a reject */
1740 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
1741 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +02001742 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001743 if (pars.send_early_cm) {
1744 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1745 } else {
1746 pars.cm1.esind := '0'B;
1747 }
Harald Welte9de84792018-01-28 01:06:35 +01001748 f_mm_auth();
1749 alt {
Daniel Willmann52918e52018-09-20 14:39:09 +02001750 [] BSSAP.receive(tr_BSSMAP_ClassmarkReq) {
1751 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1752 repeat;
1753 }
Harald Welte5946b332018-03-18 23:32:21 +01001754 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1755 f_expect_clear();
1756 }
Harald Welte9de84792018-01-28 01:06:35 +01001757 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
1758 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02001759 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001760 }
1761 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01001762 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02001763 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001764 }
1765 }
1766 setverdict(pass);
1767}
1768testcase TC_lu_imsi_auth_tmsi_encr_3_1() runs on MTC_CT {
1769 var BSC_ConnHdlr vc_conn;
1770 f_init();
1771 f_vty_config(MSCVTY, "network", "authentication required");
1772 f_vty_config(MSCVTY, "network", "encryption a5 3");
1773
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001774 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 360);
1775 vc_conn.done;
1776}
1777testcase TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() runs on MTC_CT {
1778 var BSC_ConnHdlrPars pars;
1779 var BSC_ConnHdlr vc_conn;
1780 f_init();
1781 f_vty_config(MSCVTY, "network", "authentication required");
1782 f_vty_config(MSCVTY, "network", "encryption a5 3");
1783
1784 pars := f_init_pars(361);
1785 pars.send_early_cm := false;
1786 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), pars);
Harald Welte9de84792018-01-28 01:06:35 +01001787 vc_conn.done;
1788}
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01001789testcase TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() runs on MTC_CT {
1790 var BSC_ConnHdlr vc_conn;
1791 f_init();
1792 f_vty_config(MSCVTY, "network", "authentication required");
1793 f_vty_config(MSCVTY, "network", "encryption a5 3");
1794
1795 /* Make sure the MSC category is on DEBUG level to trigger the log
1796 * message that is reported in OS#2947 to trigger the segfault */
1797 f_vty_config(MSCVTY, "log stderr", "logging level msc debug");
1798
1799 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 362);
1800 vc_conn.done;
1801}
Harald Welte9de84792018-01-28 01:06:35 +01001802
1803/* A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
1804private function f_tc_lu_imsi_auth_tmsi_encr_13_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1805 pars.net.expect_auth := true;
1806 pars.net.expect_ciph := true;
1807 pars.net.kc_support := '0A'O; /* A5/1 + A5/3 */
1808 pars.cm1.a5_1 := '1'B;
1809 pars.cm2.a5_1 := '1'B;
1810 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1811 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
1812 f_init_handler(pars, 15.0);
1813
1814 /* cannot use f_perform_lu() as we expect a reject */
1815 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
1816 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +02001817 f_cl3_or_initial_ue(l3_lu);
Harald Welte9de84792018-01-28 01:06:35 +01001818 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1819 f_mm_auth();
1820 alt {
Harald Welte5946b332018-03-18 23:32:21 +01001821 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1822 f_expect_clear();
1823 }
Harald Welte9de84792018-01-28 01:06:35 +01001824 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
1825 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02001826 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001827 }
1828 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01001829 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02001830 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001831 }
1832 }
1833 setverdict(pass);
1834}
1835testcase TC_lu_imsi_auth_tmsi_encr_13_2() runs on MTC_CT {
1836 var BSC_ConnHdlr vc_conn;
1837 f_init();
1838 f_vty_config(MSCVTY, "network", "authentication required");
1839 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
1840
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001841 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_2), 37);
Harald Welte9de84792018-01-28 01:06:35 +01001842 vc_conn.done;
1843}
1844
1845/* A5/0 + A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
1846private function f_tc_lu_imsi_auth_tmsi_encr_013_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1847 pars.net.expect_auth := true;
1848 pars.net.expect_ciph := true;
1849 pars.net.kc_support := '0B'O; /* A5/1 + A5/3 */
1850 pars.cm1.a5_1 := '1'B;
1851 pars.cm2.a5_1 := '1'B;
1852 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1853 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
1854 f_init_handler(pars, 15.0);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001855 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001856}
1857testcase TC_lu_imsi_auth_tmsi_encr_013_2() runs on MTC_CT {
1858 var BSC_ConnHdlr vc_conn;
1859 f_init();
1860 f_vty_config(MSCVTY, "network", "authentication required");
1861 f_vty_config(MSCVTY, "network", "encryption a5 0 1 3");
1862
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001863 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_013_2), 38);
Harald Welte9de84792018-01-28 01:06:35 +01001864 vc_conn.done;
1865}
1866
Harald Welte33ec09b2018-02-10 15:34:46 +01001867/* LU followed by MT call (including paging) */
1868private function f_tc_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1869 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01001870 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Harald Welte33ec09b2018-02-10 15:34:46 +01001871 cpars.bss_rtp_port := 1110;
1872 cpars.mgcp_connection_id_bss := '10004'H;
1873 cpars.mgcp_connection_id_mss := '10005'H;
1874
Philipp Maier4b2692d2018-03-14 16:37:48 +01001875 /* Note: This is an optional parameter. When the call-agent (MSC) does
1876 * supply a full endpoint name this setting will be overwritten. */
1877 cpars.mgcp_ep := "rtpbridge/1@mgw";
1878
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001879 f_perform_lu();
Harald Welte33ec09b2018-02-10 15:34:46 +01001880 f_mt_call(cpars);
1881}
1882testcase TC_lu_and_mt_call() runs on MTC_CT {
1883 var BSC_ConnHdlr vc_conn;
1884 f_init();
1885
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001886 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call), 39);
Harald Welte33ec09b2018-02-10 15:34:46 +01001887 vc_conn.done;
1888}
1889
Daniel Willmann8b084372018-02-04 13:35:26 +01001890/* Test MO Call SETUP with DTMF */
1891private function f_tc_mo_setup_dtmf_dup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1892 f_init_handler(pars);
1893 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1894 cpars.bss_rtp_port := 1110;
1895 cpars.mgcp_connection_id_bss := '22222'H;
1896 cpars.mgcp_connection_id_mss := '33333'H;
1897
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001898 f_perform_lu();
Daniel Willmann8b084372018-02-04 13:35:26 +01001899 f_mo_seq_dtmf_dup(cpars);
1900}
1901testcase TC_mo_setup_and_dtmf_dup() runs on MTC_CT {
1902 var BSC_ConnHdlr vc_conn;
1903 f_init();
1904
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001905 vc_conn := f_start_handler(refers(f_tc_mo_setup_dtmf_dup), 39);
Daniel Willmann8b084372018-02-04 13:35:26 +01001906 vc_conn.done;
1907}
Harald Welte9de84792018-01-28 01:06:35 +01001908
Philipp Maier328d1662018-03-07 10:40:27 +01001909testcase TC_cr_before_reset() runs on MTC_CT {
1910 timer T := 4.0;
1911 var boolean reset_ack_seen := false;
1912 f_init_bssap_direct();
1913
Harald Welte3ca0ce12019-04-23 17:18:48 +02001914 f_ran_adapter_start(g_bssap[0]);
Daniel Willmann42d1d5b2018-08-07 15:18:41 +02001915
Daniel Willmanne8018962018-08-21 14:18:00 +02001916 f_sleep(3.0);
1917
Philipp Maier328d1662018-03-07 10:40:27 +01001918 /* Make a blind connection attemt, to trigger the deadlock condition */
Philipp Maier75932982018-03-27 14:52:35 +02001919 BSSAP_DIRECT.send(ts_BSSAP_CONNECT_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, 1, omit));
Philipp Maier328d1662018-03-07 10:40:27 +01001920
1921 /* Send a BSSMAP reset */
Philipp Maier75932982018-03-27 14:52:35 +02001922 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_Reset(0)));
Philipp Maier328d1662018-03-07 10:40:27 +01001923 T.start
1924 alt {
1925 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_ResetAck)) {
1926 reset_ack_seen := true;
1927 repeat;
1928 }
1929
1930 /* Acknowledge MSC sided reset requests */
1931 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_Reset)) {
Philipp Maier75932982018-03-27 14:52:35 +02001932 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_ResetAck));
Philipp Maier328d1662018-03-07 10:40:27 +01001933 repeat;
1934 }
1935
1936 /* Ignore all other messages (e.g CR from the connection request) */
1937 [] BSSAP_DIRECT.receive { repeat }
1938
1939 /* If we got no BSSMAP RESET ACK back, then the MSC entered the
1940 * deadlock situation. The MSC is then unable to respond to any
1941 * further BSSMAP RESET or any other sort of traffic. */
1942 [reset_ack_seen == true] T.timeout { setverdict(pass) }
1943 [reset_ack_seen == false] T.timeout {
1944 setverdict(fail, "no BSSMAP RESET ACK seen!");
Daniel Willmannafce8662018-07-06 23:11:32 +02001945 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +01001946 }
1947 }
1948}
Harald Welte9de84792018-01-28 01:06:35 +01001949
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001950/* Test MO Call with no response to RAN-side CRCX or DTAP Release */
Harald Weltee13cfb22019-04-23 16:52:02 +02001951friend function f_tc_mo_release_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001952 f_init_handler(pars);
1953 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1954 var MNCC_PDU mncc;
1955 var MgcpCommand mgcp_cmd;
1956
1957 f_perform_lu();
1958
Harald Welteb9e86fa2018-04-09 18:18:31 +02001959 f_establish_fully();
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001960 f_create_mncc_expect(hex2str(cpars.called_party));
1961 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1962
1963 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
1964 MNCC.receive(tr_MNCC_SETUP_ind(?, tr_MNCC_number(hex2str(cpars.called_party)))) -> value mncc;
1965 cpars.mncc_callref := mncc.u.signal.callref;
1966 MNCC.send(ts_MNCC_CALL_PROC_req(cpars.mncc_callref, cpars.mncc_bearer_cap));
1967 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_CALL_PROC(cpars.transaction_id)));
1968
1969 /* Drop CRCX */
1970 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1971
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001972 var default ccrel := activate(as_optional_cc_rel(cpars));
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001973
1974 f_expect_clear(60.0);
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001975
1976 deactivate(ccrel);
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001977}
1978testcase TC_mo_release_timeout() runs on MTC_CT {
1979 var BSC_ConnHdlr vc_conn;
1980 f_init();
1981
1982 vc_conn := f_start_handler(refers(f_tc_mo_release_timeout), 40);
1983 vc_conn.done;
1984}
1985
Harald Welte12510c52018-01-26 22:26:24 +01001986
Philipp Maier2a98a732018-03-19 16:06:12 +01001987/* LU followed by MT call (including paging) */
1988private function f_tc_lu_and_mt_call_no_dlcx_resp(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1989 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01001990 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Philipp Maier2a98a732018-03-19 16:06:12 +01001991 cpars.bss_rtp_port := 1110;
1992 cpars.mgcp_connection_id_bss := '10004'H;
1993 cpars.mgcp_connection_id_mss := '10005'H;
1994
1995 /* Note: This is an optional parameter. When the call-agent (MSC) does
1996 * supply a full endpoint name this setting will be overwritten. */
1997 cpars.mgcp_ep := "rtpbridge/1@mgw";
1998
1999 /* Intentionally disable the CRCX response */
2000 cpars.mgw_drop_dlcx := true;
2001
2002 /* Perform location update and call */
2003 f_perform_lu();
2004 f_mt_call(cpars);
2005}
2006testcase TC_lu_and_mt_call_no_dlcx_resp() runs on MTC_CT {
2007 var BSC_ConnHdlr vc_conn;
2008 f_init();
2009
2010 /* Perform an almost normal looking locationupdate + mt-call, but do
2011 * not respond to the DLCX at the end of the call */
2012 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call_no_dlcx_resp), 41);
2013 vc_conn.done;
2014
2015 /* Wait a guard period until the MGCP layer in the MSC times out,
2016 * if the MSC is vulnerable to the use-after-free situation that is
2017 * fixed by I78f1b6a9149488a4ad3f120c1e190a83c07d4b89 then it should
2018 * segfault now */
2019 f_sleep(6.0);
2020
2021 /* Run the init procedures once more. If the MSC has crashed, this
2022 * this will fail */
2023 f_init();
2024}
Harald Welte45164da2018-01-24 12:51:27 +01002025
Philipp Maier75932982018-03-27 14:52:35 +02002026/* Two BSSMAP resets from two different BSCs */
2027testcase TC_reset_two() runs on MTC_CT {
2028 var BSC_ConnHdlr vc_conn;
2029 f_init(2);
2030 f_sleep(2.0);
2031 setverdict(pass);
2032}
2033
Harald Weltee13cfb22019-04-23 16:52:02 +02002034/* Two BSSMAP resets from two different BSCs plus one IuCS RANAP Reset */
2035testcase TC_reset_two_1iu() runs on MTC_CT {
2036 var BSC_ConnHdlr vc_conn;
2037 f_init(3);
2038 f_sleep(2.0);
2039 setverdict(pass);
2040}
2041
Harald Weltef640a012018-04-14 17:49:21 +02002042/***********************************************************************
2043 * SMS Testing
2044 ***********************************************************************/
2045
Harald Weltef45efeb2018-04-09 18:19:24 +02002046/* LU followed by MO SMS */
Harald Weltee13cfb22019-04-23 16:52:02 +02002047friend function f_tc_lu_and_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02002048 var SmsParameters spars := valueof(t_SmsPars);
2049
2050 f_init_handler(pars);
2051
2052 /* Perform location update and call */
2053 f_perform_lu();
2054
2055 f_establish_fully(EST_TYPE_MO_SMS);
2056
2057 //spars.exp_rp_err := 96; /* invalid mandatory information */
2058 f_mo_sms(spars);
2059
2060 f_expect_clear();
2061}
2062testcase TC_lu_and_mo_sms() runs on MTC_CT {
2063 var BSC_ConnHdlr vc_conn;
2064 f_init();
2065 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_sms), 42);
2066 vc_conn.done;
2067}
2068
Harald Weltee13cfb22019-04-23 16:52:02 +02002069
Harald Weltef45efeb2018-04-09 18:19:24 +02002070private function f_vty_sms_send(charstring imsi, charstring msisdn, charstring text)
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002071runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02002072 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
2073}
2074
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01002075/* Remove still pending SMS */
2076private function f_vty_sms_clear(charstring imsi)
2077runs on BSC_ConnHdlr {
2078 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " sms delete-all");
2079 f_vty_transceive(MSCVTY, "sms-queue clear");
2080}
2081
Harald Weltef45efeb2018-04-09 18:19:24 +02002082/* LU followed by MT SMS */
Harald Weltee13cfb22019-04-23 16:52:02 +02002083friend function f_tc_lu_and_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02002084 var SmsParameters spars := valueof(t_SmsPars);
2085 var OCT4 tmsi;
2086
2087 f_init_handler(pars);
2088
2089 /* Perform location update and call */
2090 f_perform_lu();
2091
2092 /* register an 'expect' for given IMSI (+TMSI) */
2093 if (isvalue(g_pars.tmsi)) {
2094 tmsi := g_pars.tmsi;
2095 } else {
2096 tmsi := 'FFFFFFFF'O;
2097 }
Harald Welte6811d102019-04-14 22:23:14 +02002098 f_ran_register_imsi(g_pars.imsi, tmsi);
Harald Weltef45efeb2018-04-09 18:19:24 +02002099
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002100 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
Harald Weltef45efeb2018-04-09 18:19:24 +02002101
2102 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02002103 f_expect_paging();
2104
Harald Weltef45efeb2018-04-09 18:19:24 +02002105 /* Establish DTAP / BSSAP / SCCP connection */
2106 f_establish_fully(EST_TYPE_PAG_RESP);
2107
2108 spars.tp.ud := 'C8329BFD064D9B53'O;
2109 f_mt_sms(spars);
2110
2111 f_expect_clear();
2112}
2113testcase TC_lu_and_mt_sms() runs on MTC_CT {
2114 var BSC_ConnHdlrPars pars;
2115 var BSC_ConnHdlr vc_conn;
2116 f_init();
2117 pars := f_init_pars(43);
2118 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms), pars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002119 vc_conn.done;
2120}
2121
Harald Weltee13cfb22019-04-23 16:52:02 +02002122
Philipp Maier3983e702018-11-22 19:01:33 +01002123/* Paging for MT SMS but no response */
Harald Weltee13cfb22019-04-23 16:52:02 +02002124friend function f_tc_lu_and_mt_sms_paging_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier3983e702018-11-22 19:01:33 +01002125 var SmsParameters spars := valueof(t_SmsPars);
2126 var OCT4 tmsi;
Philipp Maier3983e702018-11-22 19:01:33 +01002127 f_init_handler(pars, 150.0);
2128
2129 /* Perform location update */
2130 f_perform_lu();
2131
2132 /* register an 'expect' for given IMSI (+TMSI) */
2133 if (isvalue(g_pars.tmsi)) {
2134 tmsi := g_pars.tmsi;
2135 } else {
2136 tmsi := 'FFFFFFFF'O;
2137 }
Harald Welte6811d102019-04-14 22:23:14 +02002138 f_ran_register_imsi(g_pars.imsi, tmsi);
Philipp Maier3983e702018-11-22 19:01:33 +01002139
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002140 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2141
Neels Hofmeyr16237742019-03-06 15:34:01 +01002142 /* Expect the MSC to page exactly once */
Harald Weltee13cfb22019-04-23 16:52:02 +02002143 f_expect_paging();
Philipp Maier3983e702018-11-22 19:01:33 +01002144
2145 /* Wait some time to make sure the MSC is not delivering any further
2146 * paging messages or anything else that could be unexpected. */
2147 timer T := 20.0;
2148 T.start
2149 alt {
Harald Weltee13cfb22019-04-23 16:52:02 +02002150 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi))
Philipp Maier3983e702018-11-22 19:01:33 +01002151 {
2152 setverdict(fail, "paging seems not to stop!");
2153 mtc.stop;
2154 }
Harald Weltee13cfb22019-04-23 16:52:02 +02002155 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi), ?)) {
2156 setverdict(fail, "paging seems not to stop!");
2157 mtc.stop;
2158 }
Philipp Maier3983e702018-11-22 19:01:33 +01002159 [] BSSAP.receive {
2160 setverdict(fail, "unexpected BSSAP message received");
2161 self.stop;
2162 }
2163 [] T.timeout {
2164 setverdict(pass);
2165 }
2166 }
2167
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01002168 f_vty_sms_clear(hex2str(g_pars.imsi));
2169
Philipp Maier3983e702018-11-22 19:01:33 +01002170 setverdict(pass);
2171}
2172testcase TC_lu_and_mt_sms_paging_and_nothing() runs on MTC_CT {
2173 var BSC_ConnHdlrPars pars;
2174 var BSC_ConnHdlr vc_conn;
2175 f_init();
Philipp Maiera99ad262019-01-22 15:35:42 +01002176 pars := f_init_pars(1843);
Philipp Maier3983e702018-11-22 19:01:33 +01002177 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_paging_and_nothing), pars);
Philipp Maier3983e702018-11-22 19:01:33 +01002178 vc_conn.done;
2179}
2180
Harald Weltee13cfb22019-04-23 16:52:02 +02002181
Harald Weltef640a012018-04-14 17:49:21 +02002182/* mobile originated SMS from MS/BTS/BSC side to SMPP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002183friend function f_tc_smpp_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef640a012018-04-14 17:49:21 +02002184 var SmsParameters spars := valueof(t_SmsPars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002185
Harald Weltef640a012018-04-14 17:49:21 +02002186 f_init_handler(pars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002187
Harald Weltef640a012018-04-14 17:49:21 +02002188 /* Perform location update so IMSI is known + registered in MSC/VLR */
2189 f_perform_lu();
2190 f_establish_fully(EST_TYPE_MO_SMS);
2191
2192 f_mo_sms(spars);
2193
2194 var SMPP_PDU smpp;
2195 var template SMPP_PDU tr_smpp := tr_SMPP(c_SMPP_command_id_deliver_sm, ESME_ROK);
2196 tr_smpp.body.deliver_sm := {
2197 service_type := "CMT",
2198 source_addr_ton := network_specific,
2199 source_addr_npi := isdn,
2200 source_addr := hex2str(pars.msisdn),
2201 dest_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
2202 dest_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
2203 destination_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
2204 esm_class := '00000001'B,
2205 protocol_id := 0,
2206 priority_flag := 0,
2207 schedule_delivery_time := "",
2208 replace_if_present := 0,
2209 data_coding := '00000001'B,
2210 sm_default_msg_id := 0,
2211 sm_length := ?,
2212 short_message := spars.tp.ud,
2213 opt_pars := {
2214 {
2215 tag := user_message_reference,
2216 len := 2,
2217 opt_value := {
2218 int2_val := oct2int(spars.tp.msg_ref)
2219 }
2220 }
2221 }
2222 };
2223 alt {
2224 [] SMPP.receive(tr_smpp) -> value smpp {
2225 SMPP.send(ts_SMPP_DELIVER_SM_resp(ESME_ROK, smpp.header.seq_num));
2226 }
2227 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK)) { repeat; }
2228 }
2229
2230 f_expect_clear();
2231}
2232testcase TC_smpp_mo_sms() runs on MTC_CT {
2233 var BSC_ConnHdlr vc_conn;
2234 f_init();
2235 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "default-route");
2236 vc_conn := f_start_handler(refers(f_tc_smpp_mo_sms), 44);
2237 vc_conn.done;
2238 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "no default-route");
2239}
2240
Harald Weltee13cfb22019-04-23 16:52:02 +02002241
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002242/* Test MO-SMS from MS/BTS/BSC towards HLR (via GSUP) */
Harald Weltee13cfb22019-04-23 16:52:02 +02002243friend function f_tc_gsup_mo_sms(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002244runs on BSC_ConnHdlr {
2245 var SmsParameters spars := valueof(t_SmsPars);
2246 var GSUP_PDU gsup_msg_rx;
2247 var octetstring sm_tpdu;
2248
2249 f_init_handler(pars);
2250
2251 /* We need to inspect GSUP activity */
2252 f_create_gsup_expect(hex2str(g_pars.imsi));
2253
2254 /* Perform location update */
2255 f_perform_lu();
2256
2257 /* Send CM Service Request for SMS */
2258 f_establish_fully(EST_TYPE_MO_SMS);
2259
2260 /* Prepare expected SM-RP-UI (SM TPDU) */
2261 enc_TPDU_RP_DATA_MS_SGSN_fast(
2262 valueof(ts_SMS_SUBMIT(spars.tp.msg_ref,
2263 spars.tp.da, spars.tp.pid, spars.tp.dcs,
2264 spars.tp.udl, spars.tp.ud)),
2265 sm_tpdu);
2266
2267 var template GSUP_PDU mo_forwardSM := tr_GSUP_MO_FORWARD_SM_REQ(
2268 imsi := g_pars.imsi,
2269 sm_rp_mr := spars.rp.msg_ref,
2270 /* FIXME: extract SM-RP-DA from spars.rp.dest */
2271 sm_rp_da := tr_GSUP_SM_RP_DA_SMSC_ADDR(?),
2272 /* FIXME: MSISDN coding troubles */
2273 sm_rp_oa := tr_GSUP_SM_RP_OA_MSISDN(?),
2274 /* TODO: can we use decmatch here? */
2275 sm_rp_ui := sm_tpdu
2276 );
2277
2278 /* Submit an SMS on DTAP and expect MO-forwardSM-Req on GSUP */
2279 f_mo_sms_submit(spars);
2280 alt {
2281 [] GSUP.receive(mo_forwardSM) -> value gsup_msg_rx {
2282 log("RX MO-forwardSM-Req");
2283 log(gsup_msg_rx);
2284 setverdict(pass);
2285 }
2286 [] GSUP.receive {
2287 log("RX unexpected GSUP message");
2288 setverdict(fail);
2289 mtc.stop;
2290 }
2291 }
2292
2293 /* Trigger RP-ACK by sending MO-forwardSM-Res */
2294 GSUP.send(valueof(ts_GSUP_MO_FORWARD_SM_RES(
2295 imsi := g_pars.imsi,
2296 sm_rp_mr := spars.rp.msg_ref)));
2297 /* Expect RP-ACK on DTAP */
2298 f_mo_sms_wait_rp_ack(spars);
2299
2300 f_expect_clear();
2301}
2302testcase TC_gsup_mo_sms() runs on MTC_CT {
2303 var BSC_ConnHdlr vc_conn;
2304 f_init();
2305 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2306 vc_conn := f_start_handler(refers(f_tc_gsup_mo_sms), 88);
2307 vc_conn.done;
2308 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2309}
2310
Harald Weltee13cfb22019-04-23 16:52:02 +02002311
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002312/* Test MO-SMMA from MS/BTS/BSC towards HLR (via GSUP) */
Harald Weltee13cfb22019-04-23 16:52:02 +02002313friend function f_tc_gsup_mo_smma(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002314runs on BSC_ConnHdlr {
2315 var SmsParameters spars := valueof(t_SmsPars);
2316 var GSUP_PDU gsup_msg_rx;
2317
2318 f_init_handler(pars);
2319
2320 /* We need to inspect GSUP activity */
2321 f_create_gsup_expect(hex2str(g_pars.imsi));
2322
2323 /* Perform location update */
2324 f_perform_lu();
2325
2326 /* Send CM Service Request for SMS */
2327 f_establish_fully(EST_TYPE_MO_SMS);
2328
2329 var template GSUP_PDU mo_ReadyForSM := tr_GSUP_MO_READY_FOR_SM_REQ(
2330 imsi := g_pars.imsi,
2331 sm_rp_mr := spars.rp.msg_ref,
2332 sm_alert_rsn := GSUP_SM_ALERT_RSN_TYPE_MEM_AVAIL
2333 );
2334
2335 /* Submit an SMS on DTAP and expect MO-forwardSM-Req on GSUP */
2336 f_mo_smma(spars);
2337 alt {
2338 [] GSUP.receive(mo_ReadyForSM) -> value gsup_msg_rx {
2339 log("RX MO-ReadyForSM-Req");
2340 log(gsup_msg_rx);
2341 setverdict(pass);
2342 }
2343 [] GSUP.receive {
2344 log("RX unexpected GSUP message");
2345 setverdict(fail);
2346 mtc.stop;
2347 }
2348 }
2349
2350 /* Trigger RP-ACK by sending MO-forwardSM-Res */
2351 GSUP.send(valueof(ts_GSUP_MO_READY_FOR_SM_RES(
2352 imsi := g_pars.imsi,
2353 sm_rp_mr := spars.rp.msg_ref)));
2354 /* Expect RP-ACK on DTAP */
2355 f_mo_sms_wait_rp_ack(spars);
2356
2357 f_expect_clear();
2358}
2359testcase TC_gsup_mo_smma() runs on MTC_CT {
2360 var BSC_ConnHdlr vc_conn;
2361 f_init();
2362 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2363 vc_conn := f_start_handler(refers(f_tc_gsup_mo_smma), 89);
2364 vc_conn.done;
2365 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2366}
2367
Harald Weltee13cfb22019-04-23 16:52:02 +02002368
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002369/* Helper for sending MT SMS over GSUP */
2370private function f_gsup_forwardSM_req(SmsParameters spars, OCT1 mms := '00'O)
2371runs on BSC_ConnHdlr {
2372 GSUP.send(ts_GSUP_MT_FORWARD_SM_REQ(
2373 imsi := g_pars.imsi,
2374 /* NOTE: MSC should assign RP-MR itself */
2375 sm_rp_mr := 'FF'O,
2376 /* FIXME: extract SM-RP-DA from spars.rp.dest */
2377 /* TODO: fix encoding of ts_GSUP_SM_RP_DA_IMSI */
2378 sm_rp_da := valueof(ts_GSUP_SM_RP_DA_MSISDN(g_pars.msisdn)),
2379 sm_rp_oa := valueof(ts_GSUP_SM_RP_OA_SMSC_ADDR(g_pars.msisdn)),
2380 /* Encoded SMS TPDU (taken from Wireshark)
2381 * FIXME: we should encode spars somehow */
2382 sm_rp_ui := '00068021436500008111328130858200'O,
2383 sm_rp_mms := mms
2384 ));
2385}
2386
2387/* Test successful MT-SMS (RP-ACK) over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002388friend function f_tc_gsup_mt_sms_ack(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002389runs on BSC_ConnHdlr {
2390 var SmsParameters spars := valueof(t_SmsPars);
2391
2392 f_init_handler(pars);
2393
2394 /* We need to inspect GSUP activity */
2395 f_create_gsup_expect(hex2str(g_pars.imsi));
2396
2397 /* Perform location update */
2398 f_perform_lu();
2399
2400 /* Register an 'expect' for given IMSI (+TMSI) */
2401 if (isvalue(g_pars.tmsi)) {
Harald Welte6811d102019-04-14 22:23:14 +02002402 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002403 } else {
Harald Welte6811d102019-04-14 22:23:14 +02002404 f_ran_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002405 }
2406
2407 var template GSUP_PDU mt_forwardSM_res := tr_GSUP_MT_FORWARD_SM_RES(
2408 imsi := g_pars.imsi,
2409 /* NOTE: MSC should assign RP-MR itself */
2410 sm_rp_mr := ?
2411 );
2412
2413 /* Submit a MT SMS on GSUP */
2414 f_gsup_forwardSM_req(spars);
2415
2416 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002417 f_expect_paging();
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002418 f_establish_fully(EST_TYPE_PAG_RESP);
2419
2420 /* Wait for MT SMS on DTAP */
2421 f_mt_sms_expect(spars);
2422
2423 /* Send RP-ACK and expect MT-forwardSM-Res on GSUP */
2424 f_mt_sms_send_rp_ack(spars);
2425 alt {
2426 [] GSUP.receive(mt_forwardSM_res) {
2427 log("RX MT-forwardSM-Res (RP-ACK)");
2428 setverdict(pass);
2429 }
2430 [] GSUP.receive {
2431 log("RX unexpected GSUP message");
2432 setverdict(fail);
2433 mtc.stop;
2434 }
2435 }
2436
2437 f_expect_clear();
2438}
2439testcase TC_gsup_mt_sms_ack() runs on MTC_CT {
2440 var BSC_ConnHdlrPars pars;
2441 var BSC_ConnHdlr vc_conn;
2442 f_init();
2443 pars := f_init_pars(90);
2444 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2445 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_ack), pars);
2446 vc_conn.done;
2447 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2448}
2449
Harald Weltee13cfb22019-04-23 16:52:02 +02002450
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002451/* Test rejected MT-SMS (RP-ERROR) over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002452friend function f_tc_gsup_mt_sms_err(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002453runs on BSC_ConnHdlr {
2454 var SmsParameters spars := valueof(t_SmsPars);
2455 var OCT1 sm_rp_cause := '78'O; /* dummy RP-Cause value */
2456
2457 f_init_handler(pars);
2458
2459 /* We need to inspect GSUP activity */
2460 f_create_gsup_expect(hex2str(g_pars.imsi));
2461
2462 /* Perform location update */
2463 f_perform_lu();
2464
2465 /* Register an 'expect' for given IMSI (+TMSI) */
2466 if (isvalue(g_pars.tmsi)) {
Harald Welte6811d102019-04-14 22:23:14 +02002467 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002468 } else {
Harald Welte6811d102019-04-14 22:23:14 +02002469 f_ran_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002470 }
2471
2472 var template GSUP_PDU mt_forwardSM_err := tr_GSUP_MT_FORWARD_SM_ERR(
2473 imsi := g_pars.imsi,
2474 /* NOTE: MSC should assign RP-MR itself */
2475 sm_rp_mr := ?,
2476 sm_rp_cause := sm_rp_cause
2477 );
2478
2479 /* Submit a MT SMS on GSUP */
2480 f_gsup_forwardSM_req(spars);
2481
2482 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002483 f_expect_paging();
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002484 f_establish_fully(EST_TYPE_PAG_RESP);
2485
2486 /* Wait for MT SMS on DTAP */
2487 f_mt_sms_expect(spars);
2488
2489 /* Send RP-ERROR and expect MT-forwardSM-Err on GSUP */
2490 f_mt_sms_send_rp_error(spars, oct2int(sm_rp_cause));
2491 alt {
2492 [] GSUP.receive(mt_forwardSM_err) {
2493 log("RX MT-forwardSM-Err (RP-ERROR)");
2494 setverdict(pass);
2495 mtc.stop;
2496 }
2497 [] GSUP.receive {
2498 log("RX unexpected GSUP message");
2499 setverdict(fail);
2500 mtc.stop;
2501 }
2502 }
2503
2504 f_expect_clear();
2505}
2506testcase TC_gsup_mt_sms_err() runs on MTC_CT {
2507 var BSC_ConnHdlrPars pars;
2508 var BSC_ConnHdlr vc_conn;
2509 f_init();
2510 pars := f_init_pars(91);
2511 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2512 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_err), pars);
2513 vc_conn.done;
2514 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2515}
2516
Harald Weltee13cfb22019-04-23 16:52:02 +02002517
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002518/* Test SM-RP-MR assignment for MT-SMS over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002519friend function f_tc_gsup_mt_sms_rp_mr(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002520runs on BSC_ConnHdlr {
2521 var SmsParameters spars1 := valueof(t_SmsPars); /* 1st SMS */
2522 var SmsParameters spars2 := valueof(t_SmsPars); /* 2nd SMS */
2523
2524 f_init_handler(pars);
2525
2526 /* We need to inspect GSUP activity */
2527 f_create_gsup_expect(hex2str(g_pars.imsi));
2528
2529 /* Perform location update */
2530 f_perform_lu();
2531
2532 /* Register an 'expect' for given IMSI (+TMSI) */
2533 if (isvalue(g_pars.tmsi)) {
Harald Welte6811d102019-04-14 22:23:14 +02002534 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002535 } else {
Harald Welte6811d102019-04-14 22:23:14 +02002536 f_ran_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002537 }
2538
2539 /* Submit the 1st MT SMS on GSUP */
2540 log("TX MT-forwardSM-Req for the 1st SMS");
2541 f_gsup_forwardSM_req(spars1);
2542
2543 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002544 f_expect_paging();
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002545 f_establish_fully(EST_TYPE_PAG_RESP);
2546
2547 /* Wait for 1st MT SMS on DTAP */
2548 f_mt_sms_expect(spars1);
2549 log("RX the 1st SMS on DTAP, DTAP TID is ", spars1.tid,
2550 ", SM-RP-MR is ", spars1.rp.msg_ref);
2551
2552 /* Submit the 2nd MT SMS on GSUP */
2553 log("TX MT-forwardSM-Req for the 2nd SMS");
2554 f_gsup_forwardSM_req(spars2);
2555
2556 /* Wait for 2nd MT SMS on DTAP */
2557 f_mt_sms_expect(spars2);
2558 log("RX the 2nd SMS on DTAP, DTAP TID is ", spars2.tid,
2559 ", SM-RP-MR is ", spars2.rp.msg_ref);
2560
2561 /* Both transaction IDs shall be different */
2562 if (spars1.tid == spars2.tid) {
2563 log("Both DTAP transaction IDs shall be different");
2564 setverdict(fail);
2565 }
2566
2567 /* Both SM-RP-MR values shall be different */
2568 if (spars1.rp.msg_ref == spars2.rp.msg_ref) {
2569 log("Both SM-RP-MR values shall be different");
2570 setverdict(fail);
2571 }
2572
2573 /* Both SM-RP-MR values shall be assigned */
2574 if (spars1.rp.msg_ref == 'FF'O) {
2575 log("Unassigned SM-RP-MR value for the 1st SMS");
2576 setverdict(fail);
2577 }
2578 if (spars2.rp.msg_ref == 'FF'O) {
2579 log("Unassigned SM-RP-MR value for the 2nd SMS");
2580 setverdict(fail);
2581 }
2582
2583 /* Send the 1st RP-ACK and expect MT-forwardSM-Res on GSUP */
2584 f_mt_sms_send_rp_ack(spars1);
2585 alt {
2586 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2587 imsi := g_pars.imsi,
2588 sm_rp_mr := spars1.rp.msg_ref
2589 )) {
2590 log("RX MT-forwardSM-Res (RP-ACK)");
2591 setverdict(pass);
2592 }
2593 [] GSUP.receive {
2594 log("RX unexpected GSUP message");
2595 setverdict(fail);
2596 mtc.stop;
2597 }
2598 }
2599
2600 /* Send the 2nd RP-ACK and expect MT-forwardSM-Res on GSUP */
2601 f_mt_sms_send_rp_ack(spars2);
2602 alt {
2603 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2604 imsi := g_pars.imsi,
2605 sm_rp_mr := spars2.rp.msg_ref
2606 )) {
2607 log("RX MT-forwardSM-Res (RP-ACK)");
2608 setverdict(pass);
2609 }
2610 [] GSUP.receive {
2611 log("RX unexpected GSUP message");
2612 setverdict(fail);
2613 mtc.stop;
2614 }
2615 }
2616
2617 f_expect_clear();
2618}
2619testcase TC_gsup_mt_sms_rp_mr() runs on MTC_CT {
2620 var BSC_ConnHdlrPars pars;
2621 var BSC_ConnHdlr vc_conn;
2622 f_init();
2623 pars := f_init_pars(92);
2624 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2625 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_rp_mr), pars);
2626 vc_conn.done;
2627 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2628}
2629
Harald Weltee13cfb22019-04-23 16:52:02 +02002630
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07002631/* Test SM-RP-MR assignment for MT-SMS over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002632friend function f_tc_gsup_mo_mt_sms_rp_mr(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07002633runs on BSC_ConnHdlr {
2634 var SmsParameters spars_mo := valueof(t_SmsPars); /* MO SMMA */
2635 var SmsParameters spars_mt := valueof(t_SmsPars); /* MT SMS */
2636
2637 f_init_handler(pars);
2638
2639 /* We need to inspect GSUP activity */
2640 f_create_gsup_expect(hex2str(g_pars.imsi));
2641
2642 /* Perform location update */
2643 f_perform_lu();
2644
2645 /* Register an 'expect' for given IMSI (+TMSI) */
2646 if (isvalue(g_pars.tmsi)) {
Harald Welte6811d102019-04-14 22:23:14 +02002647 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07002648 } else {
Harald Welte6811d102019-04-14 22:23:14 +02002649 f_ran_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07002650 }
2651
2652 /* Send CM Service Request for MO SMMA */
2653 f_establish_fully(EST_TYPE_MO_SMS);
2654
2655 /* Submit MO SMMA on DTAP */
2656 log("Submit MO SMMA on DTAP, SM-RP-MR is '00'O");
2657 spars_mo.rp.msg_ref := '00'O;
2658 f_mo_smma(spars_mo);
2659
2660 /* Expect MO-forwardSM-Req for MO SMMA on GSUP */
2661 alt {
2662 [] GSUP.receive(tr_GSUP_MO_READY_FOR_SM_REQ(
2663 imsi := g_pars.imsi,
2664 sm_rp_mr := spars_mo.rp.msg_ref,
2665 sm_alert_rsn := GSUP_SM_ALERT_RSN_TYPE_MEM_AVAIL
2666 )) {
2667 log("RX MO-ReadyForSM-Req, SM-RP-MR is '00'O");
2668 setverdict(pass);
2669 }
2670 [] GSUP.receive {
2671 log("RX unexpected GSUP message");
2672 setverdict(fail);
2673 mtc.stop;
2674 }
2675 }
2676
2677 /* Submit MT SMS on GSUP */
2678 log("TX MT-forwardSM-Req for the MT SMS");
2679 f_gsup_forwardSM_req(spars_mt);
2680
2681 /* Wait for MT SMS on DTAP */
2682 f_mt_sms_expect(spars_mt);
2683 log("RX MT SMS on DTAP, DTAP TID is ", spars_mt.tid,
2684 ", SM-RP-MR is ", spars_mt.rp.msg_ref);
2685
2686 /* Both SM-RP-MR values shall be different */
2687 if (spars_mo.rp.msg_ref == spars_mt.rp.msg_ref) {
2688 log("Both SM-RP-MR values shall be different");
2689 setverdict(fail);
2690 }
2691
2692 /* SM-RP-MR value for MT SMS shall be assigned */
2693 if (spars_mt.rp.msg_ref == 'FF'O) {
2694 log("Unassigned SM-RP-MR value for the MT SMS");
2695 setverdict(fail);
2696 }
2697
2698 /* Trigger RP-ACK for MO SMMA by sending MO-forwardSM-Res */
2699 GSUP.send(valueof(ts_GSUP_MO_READY_FOR_SM_RES(
2700 imsi := g_pars.imsi,
2701 sm_rp_mr := spars_mo.rp.msg_ref)));
2702 /* Expect RP-ACK for MO SMMA on DTAP */
2703 f_mo_sms_wait_rp_ack(spars_mo);
2704
2705 /* Send RP-ACK for MT SMS and expect MT-forwardSM-Res on GSUP */
2706 f_mt_sms_send_rp_ack(spars_mt);
2707 alt {
2708 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2709 imsi := g_pars.imsi,
2710 sm_rp_mr := spars_mt.rp.msg_ref
2711 )) {
2712 log("RX MT-forwardSM-Res (RP-ACK)");
2713 setverdict(pass);
2714 }
2715 [] GSUP.receive {
2716 log("RX unexpected GSUP message");
2717 setverdict(fail);
2718 mtc.stop;
2719 }
2720 }
2721
2722 f_expect_clear();
2723}
2724testcase TC_gsup_mo_mt_sms_rp_mr() runs on MTC_CT {
2725 var BSC_ConnHdlrPars pars;
2726 var BSC_ConnHdlr vc_conn;
2727 f_init();
2728 pars := f_init_pars(93);
2729 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2730 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mo_mt_sms_rp_mr), pars);
2731 vc_conn.done;
2732 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2733}
2734
Harald Weltee13cfb22019-04-23 16:52:02 +02002735
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07002736/* Test multi-part MT-SMS over GSUP */
2737private function f_tc_gsup_mt_multi_part_sms(charstring id, BSC_ConnHdlrPars pars)
2738runs on BSC_ConnHdlr {
2739 var SmsParameters spars := valueof(t_SmsPars);
2740
2741 f_init_handler(pars);
2742
2743 /* We need to inspect GSUP activity */
2744 f_create_gsup_expect(hex2str(g_pars.imsi));
2745
2746 /* Perform location update */
2747 f_perform_lu();
2748
2749 /* Register an 'expect' for given IMSI (+TMSI) */
2750 if (isvalue(g_pars.tmsi)) {
Harald Welte6811d102019-04-14 22:23:14 +02002751 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07002752 } else {
Harald Welte6811d102019-04-14 22:23:14 +02002753 f_ran_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07002754 }
2755
2756 var template GSUP_PDU mt_forwardSM_res := tr_GSUP_MT_FORWARD_SM_RES(
2757 imsi := g_pars.imsi,
2758 /* NOTE: MSC should assign RP-MR itself */
2759 sm_rp_mr := ?
2760 );
2761
2762 /* Send 4 messages (NOTE: SM-RP-UI remains unchanged) */
2763 for (var integer i := 3; i >= 0; i := i-1) {
2764 /* Submit a MT SMS on GSUP (MMS is decremented) */
2765 f_gsup_forwardSM_req(spars, int2oct(i, 1));
2766
2767 /* Expect Paging Request and Establish connection */
2768 if (i == 3) { /* ... only once! */
Harald Weltee13cfb22019-04-23 16:52:02 +02002769 f_expect_paging();
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07002770 f_establish_fully(EST_TYPE_PAG_RESP);
2771 }
2772
2773 /* Wait for MT SMS on DTAP */
2774 f_mt_sms_expect(spars);
2775
2776 /* Send RP-ACK and expect MT-forwardSM-Res on GSUP */
2777 f_mt_sms_send_rp_ack(spars);
2778 alt {
2779 [] GSUP.receive(mt_forwardSM_res) {
2780 log("RX MT-forwardSM-Res (RP-ACK)");
2781 setverdict(pass);
2782 }
2783 [] GSUP.receive {
2784 log("RX unexpected GSUP message");
2785 setverdict(fail);
2786 mtc.stop;
2787 }
2788 }
2789
2790 /* Keep some 'distance' between transmissions */
2791 f_sleep(1.5);
2792 }
2793
2794 f_expect_clear();
2795}
2796testcase TC_gsup_mt_multi_part_sms() runs on MTC_CT {
2797 var BSC_ConnHdlrPars pars;
2798 var BSC_ConnHdlr vc_conn;
2799 f_init();
2800 pars := f_init_pars(91);
2801 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2802 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_multi_part_sms), pars);
2803 vc_conn.done;
2804 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2805}
2806
Harald Weltef640a012018-04-14 17:49:21 +02002807/* convert GSM L3 TON to SMPP_TON enum */
2808function f_sm_ton_from_gsm(BIT3 ton) return SMPP_TON {
2809 select (ton) {
2810 case ('000'B) { return unknown; }
2811 case ('001'B) { return international; }
2812 case ('010'B) { return national; }
2813 case ('011'B) { return network_specific; }
2814 case ('100'B) { return subscriber_number; }
2815 case ('101'B) { return alphanumeric; }
2816 case ('110'B) { return abbreviated; }
2817 }
2818 setverdict(fail, "Unknown TON ", ton);
Daniel Willmannafce8662018-07-06 23:11:32 +02002819 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02002820}
2821/* convert GSM L3 NPI to SMPP_NPI enum */
2822function f_sm_npi_from_gsm(BIT4 npi) return SMPP_NPI {
2823 select (npi) {
2824 case ('0000'B) { return unknown; }
2825 case ('0001'B) { return isdn; }
2826 case ('0011'B) { return data; }
2827 case ('0100'B) { return telex; }
2828 case ('0110'B) { return land_mobile; }
2829 case ('1000'B) { return national; }
2830 case ('1001'B) { return private_; }
2831 case ('1010'B) { return ermes; }
2832 }
2833 setverdict(fail, "Unknown NPI ", npi);
Daniel Willmannafce8662018-07-06 23:11:32 +02002834 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02002835}
2836
2837/* build a SMPP_SM from SmsParameters */
2838function f_mt_sm_from_spars(SmsParameters spars)
2839runs on BSC_ConnHdlr return SMPP_SM {
2840 var SMPP_SM sm := {
2841 service_type := "CMT",
2842 source_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
2843 source_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
2844 source_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
2845 dest_addr_ton := international,
2846 dest_addr_npi := isdn,
2847 destination_addr := hex2str(g_pars.msisdn),
2848 esm_class := '00000001'B,
2849 protocol_id := 0,
2850 priority_flag := 0,
2851 schedule_delivery_time := "",
2852 validity_period := "",
2853 registered_delivery := '00000000'B,
2854 replace_if_present := 0,
2855 data_coding := '00000001'B,
2856 sm_default_msg_id := 0,
2857 sm_length := spars.tp.udl,
2858 short_message := spars.tp.ud,
2859 opt_pars := {}
2860 };
2861 return sm;
2862}
2863
2864/* helper function to encode SMS from 'spars', send it via SMPP to MSC; receive it on MS side */
2865private function f_smpp_mt_sms(SmsParameters spars, boolean trans_mode) runs on BSC_ConnHdlr {
2866 var SMPP_SM sm := f_mt_sm_from_spars(spars);
2867 if (trans_mode) {
2868 sm.esm_class := '00000010'B;
2869 }
2870
2871 /* actually cause MSC to send a SMS via SUBMIT-SM from SMPP side */
2872 SMPP.send(ts_SMPP_SUBMIT_SM(sm));
2873 if (not match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
2874 /* if we're not in SMPP transaction mode, we expect the SMPP-level ACK
2875 * before we expect the SMS delivery on the BSC/radio side */
2876 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
2877 }
2878
2879 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02002880 f_expect_paging();
Harald Weltef640a012018-04-14 17:49:21 +02002881 /* Establish DTAP / BSSAP / SCCP connection */
2882 f_establish_fully(EST_TYPE_PAG_RESP);
2883 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
2884
2885 f_mt_sms(spars);
2886
2887 if (match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
2888 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
2889 }
2890 f_expect_clear();
2891}
2892
2893/* mobile terminated SMS, from SMPP to BSC/BTS/MS */
2894private function f_tc_smpp_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2895 f_init_handler(pars);
2896
2897 /* Perform location update so IMSI is known + registered in MSC/VLR */
2898 f_perform_lu();
2899 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
2900
2901 /* register an 'expect' for given IMSI (+TMSI) */
2902 var OCT4 tmsi;
2903 if (isvalue(g_pars.tmsi)) {
2904 tmsi := g_pars.tmsi;
2905 } else {
2906 tmsi := 'FFFFFFFF'O;
2907 }
Harald Welte6811d102019-04-14 22:23:14 +02002908 f_ran_register_imsi(g_pars.imsi, tmsi);
Harald Weltef640a012018-04-14 17:49:21 +02002909
2910 var SmsParameters spars := valueof(t_SmsPars);
2911 /* TODO: test with more intelligent user data; test different coding schemes */
2912 spars.tp.ud := '00'O;
2913 spars.tp.udl := 1;
2914
2915 /* first test the non-transaction store+forward mode */
2916 f_smpp_mt_sms(spars, false);
2917
2918 /* then test the transaction mode */
2919 f_smpp_mt_sms(spars, true);
2920}
2921testcase TC_smpp_mt_sms() runs on MTC_CT {
2922 var BSC_ConnHdlr vc_conn;
2923 f_init();
2924 vc_conn := f_start_handler(refers(f_tc_smpp_mt_sms), 45);
2925 vc_conn.done;
2926}
2927
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002928/***********************************************************************
2929 * USSD Testing
2930 ***********************************************************************/
2931
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07002932private altstep as_unexp_gsup_or_bssap_msg()
2933runs on BSC_ConnHdlr {
2934 [] GSUP.receive {
2935 setverdict(fail, "Unknown/unexpected GSUP received");
2936 self.stop;
2937 }
2938 [] BSSAP.receive {
2939 setverdict(fail, "Unknown/unexpected BSSAP message received");
2940 self.stop;
2941 }
2942}
2943
2944private function f_expect_gsup_msg(template GSUP_PDU msg)
2945runs on BSC_ConnHdlr return GSUP_PDU {
2946 var GSUP_PDU gsup_msg_complete;
2947
2948 alt {
2949 [] GSUP.receive(msg) -> value gsup_msg_complete {
2950 setverdict(pass);
2951 }
2952 /* We don't expect anything else */
2953 [] as_unexp_gsup_or_bssap_msg();
2954 }
2955
2956 return gsup_msg_complete;
2957}
2958
2959private function f_expect_mt_dtap_msg(template PDU_ML3_NW_MS msg)
2960runs on BSC_ConnHdlr return PDU_ML3_NW_MS {
2961 var PDU_DTAP_MT bssap_msg_complete;
2962
2963 alt {
2964 [] BSSAP.receive(tr_PDU_DTAP_MT(msg)) -> value bssap_msg_complete {
2965 setverdict(pass);
2966 }
2967 /* We don't expect anything else */
2968 [] as_unexp_gsup_or_bssap_msg();
2969 }
2970
2971 return bssap_msg_complete.dtap;
2972}
2973
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07002974/* LU followed by MO USSD request */
Harald Weltee13cfb22019-04-23 16:52:02 +02002975friend function f_tc_lu_and_mo_ussd_single_request(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002976runs on BSC_ConnHdlr {
2977 f_init_handler(pars);
2978
2979 /* Perform location update */
2980 f_perform_lu();
2981
2982 /* Send CM Service Request for SS/USSD */
2983 f_establish_fully(EST_TYPE_SS_ACT);
2984
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002985 /* We need to inspect GSUP activity */
2986 f_create_gsup_expect(hex2str(g_pars.imsi));
2987
2988 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
2989 invoke_id := 5, /* Phone may not start from 0 or 1 */
2990 op_code := SS_OP_CODE_PROCESS_USS_REQ,
2991 ussd_string := "*#100#"
2992 );
2993
2994 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
2995 invoke_id := 5, /* InvokeID shall be the same for both REQ and RSP */
2996 op_code := SS_OP_CODE_PROCESS_USS_REQ,
2997 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
2998 )
2999
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003000 /* Compose a new SS/REGISTER message with request */
3001 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
3002 tid := 1, /* We just need a single transaction */
3003 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003004 facility := valueof(facility_req)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003005 );
3006
3007 /* Compose SS/RELEASE_COMPLETE template with expected response */
3008 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
3009 tid := 1, /* Response should arrive within the same transaction */
3010 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003011 facility := valueof(facility_rsp)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003012 );
3013
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003014 /* Compose expected MSC -> HLR message */
3015 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
3016 imsi := g_pars.imsi,
3017 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3018 ss := valueof(facility_req)
3019 );
3020
3021 /* To be used for sending response with correct session ID */
3022 var GSUP_PDU gsup_req_complete;
3023
3024 /* Request own number */
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003025 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003026 /* Expect GSUP message containing the SS payload */
3027 gsup_req_complete := f_expect_gsup_msg(gsup_req);
3028
3029 /* Compose the response from HLR using received session ID */
3030 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
3031 imsi := g_pars.imsi,
3032 sid := gsup_req_complete.ies[1].val.session_id,
3033 state := OSMO_GSUP_SESSION_STATE_END,
3034 ss := valueof(facility_rsp)
3035 );
3036
3037 /* Finally, HLR terminates the session */
3038 GSUP.send(gsup_rsp);
3039 /* Expect RELEASE_COMPLETE message with the response */
3040 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003041
3042 f_expect_clear();
3043}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003044testcase TC_lu_and_mo_ussd_single_request() runs on MTC_CT {
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003045 var BSC_ConnHdlr vc_conn;
3046 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003047 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_single_request), 46);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003048 vc_conn.done;
3049}
3050
Harald Weltee13cfb22019-04-23 16:52:02 +02003051
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003052/* LU followed by MT USSD notification */
Harald Weltee13cfb22019-04-23 16:52:02 +02003053friend function f_tc_lu_and_mt_ussd_notification(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003054runs on BSC_ConnHdlr {
3055 f_init_handler(pars);
3056
3057 /* Perform location update */
3058 f_perform_lu();
3059
Harald Welte6811d102019-04-14 22:23:14 +02003060 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003061
3062 /* We need to inspect GSUP activity */
3063 f_create_gsup_expect(hex2str(g_pars.imsi));
3064
3065 /* Facility IE with network-originated USSD notification */
3066 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3067 op_code := SS_OP_CODE_USS_NOTIFY,
3068 ussd_string := "Mahlzeit!"
3069 );
3070
3071 /* Facility IE with acknowledgment to the USSD notification */
3072 var template OCTN facility_rsp := enc_SS_FacilityInformation(
3073 /* In case of USSD notification, Return Result is empty */
3074 valueof(ts_SS_USSD_FACILITY_RETURN_RESULT_EMPTY())
3075 );
3076
3077 /* Compose a new MT SS/REGISTER message with USSD notification */
3078 var template PDU_ML3_NW_MS ussd_ntf := tr_ML3_MT_SS_REGISTER(
3079 tid := 0, /* FIXME: most likely, it should be 0 */
3080 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3081 facility := valueof(facility_req)
3082 );
3083
3084 /* Compose HLR -> MSC GSUP message */
3085 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3086 imsi := g_pars.imsi,
3087 sid := '20000101'O,
3088 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3089 ss := valueof(facility_req)
3090 );
3091
3092 /* Send it to MSC and expect Paging Request */
3093 GSUP.send(gsup_req);
3094 alt {
Harald Weltee13cfb22019-04-23 16:52:02 +02003095 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
3096 setverdict(pass);
3097 }
3098 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi), ?)) {
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003099 setverdict(pass);
3100 }
3101 /* We don't expect anything else */
3102 [] as_unexp_gsup_or_bssap_msg();
3103 }
3104
3105 /* Send Paging Response and expect USSD notification */
3106 f_establish_fully(EST_TYPE_PAG_RESP);
3107 /* Expect MT REGISTER message with USSD notification */
3108 f_expect_mt_dtap_msg(ussd_ntf);
3109
3110 /* Compose a new MO SS/FACILITY message with empty response */
3111 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
3112 tid := 0, /* FIXME: it shall match the request tid */
3113 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3114 facility := valueof(facility_rsp)
3115 );
3116
3117 /* Compose expected MSC -> HLR GSUP message */
3118 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
3119 imsi := g_pars.imsi,
3120 sid := '20000101'O,
3121 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3122 ss := valueof(facility_rsp)
3123 );
3124
3125 /* MS sends response to the notification */
3126 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
3127 /* Expect GSUP message containing the SS payload */
3128 f_expect_gsup_msg(gsup_rsp);
3129
3130 /* Compose expected MT SS/RELEASE COMPLETE message */
3131 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
3132 tid := 0, /* FIXME: it shall match the request tid */
3133 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3134 facility := omit
3135 );
3136
3137 /* Compose MSC -> HLR GSUP message */
3138 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
3139 imsi := g_pars.imsi,
3140 sid := '20000101'O,
3141 state := OSMO_GSUP_SESSION_STATE_END
3142 );
3143
3144 /* Finally, HLR terminates the session */
3145 GSUP.send(gsup_term)
3146 /* Expect MT RELEASE COMPLETE without Facility IE */
3147 f_expect_mt_dtap_msg(ussd_term);
3148
3149 f_expect_clear();
3150}
3151testcase TC_lu_and_mt_ussd_notification() runs on MTC_CT {
3152 var BSC_ConnHdlr vc_conn;
3153 f_init();
3154 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_notification), 47);
3155 vc_conn.done;
3156}
3157
Harald Weltee13cfb22019-04-23 16:52:02 +02003158
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003159/* LU followed by MT call and MO USSD request during this call */
Harald Weltee13cfb22019-04-23 16:52:02 +02003160friend function f_tc_lu_and_mo_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003161runs on BSC_ConnHdlr {
3162 f_init_handler(pars);
3163
3164 /* Call parameters taken from f_tc_lu_and_mt_call */
3165 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
3166 cpars.mgcp_connection_id_bss := '10004'H;
3167 cpars.mgcp_connection_id_mss := '10005'H;
3168 cpars.mgcp_ep := "rtpbridge/1@mgw";
3169 cpars.bss_rtp_port := 1110;
3170
3171 /* Perform location update */
3172 f_perform_lu();
3173
3174 /* Establish a MT call */
3175 f_mt_call_establish(cpars);
3176
3177 /* Hold the call for some time */
3178 f_sleep(1.0);
3179
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003180 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3181 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3182 ussd_string := "*#100#"
3183 );
3184
3185 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3186 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3187 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
3188 )
3189
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003190 /* Compose a new SS/REGISTER message with request */
3191 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
3192 tid := 1, /* We just need a single transaction */
3193 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003194 facility := valueof(facility_req)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003195 );
3196
3197 /* Compose SS/RELEASE_COMPLETE template with expected response */
3198 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
3199 tid := 1, /* Response should arrive within the same transaction */
3200 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003201 facility := valueof(facility_rsp)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003202 );
3203
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003204 /* Compose expected MSC -> HLR message */
3205 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
3206 imsi := g_pars.imsi,
3207 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3208 ss := valueof(facility_req)
3209 );
3210
3211 /* To be used for sending response with correct session ID */
3212 var GSUP_PDU gsup_req_complete;
3213
3214 /* Request own number */
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003215 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003216 /* Expect GSUP message containing the SS payload */
3217 gsup_req_complete := f_expect_gsup_msg(gsup_req);
3218
3219 /* Compose the response from HLR using received session ID */
3220 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
3221 imsi := g_pars.imsi,
3222 sid := gsup_req_complete.ies[1].val.session_id,
3223 state := OSMO_GSUP_SESSION_STATE_END,
3224 ss := valueof(facility_rsp)
3225 );
3226
3227 /* Finally, HLR terminates the session */
3228 GSUP.send(gsup_rsp);
3229 /* Expect RELEASE_COMPLETE message with the response */
3230 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003231
3232 /* Hold the call for some time */
3233 f_sleep(1.0);
3234
3235 /* Release the call (does Clear Complete itself) */
3236 f_call_hangup(cpars, true);
3237}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003238testcase TC_lu_and_mo_ussd_during_mt_call() runs on MTC_CT {
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003239 var BSC_ConnHdlr vc_conn;
3240 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003241 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_during_mt_call), 48);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003242 vc_conn.done;
3243}
3244
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003245/* BSSMAP Clear Request in the middle of a call, see OS#3062 */
Harald Weltee13cfb22019-04-23 16:52:02 +02003246friend function f_tc_mo_cc_bssmap_clear(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003247 f_init_handler(pars);
3248 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
3249 var MNCC_PDU mncc;
3250 var MgcpCommand mgcp_cmd;
3251
3252 f_perform_lu();
3253
3254 f_establish_fully();
3255 f_create_mncc_expect(hex2str(cpars.called_party));
3256 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
3257
3258 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
3259 MNCC.receive(tr_MNCC_SETUP_ind(?, tr_MNCC_number(hex2str(cpars.called_party)))) -> value mncc;
3260 cpars.mncc_callref := mncc.u.signal.callref;
3261 log("mncc_callref=", cpars.mncc_callref);
3262 MNCC.send(ts_MNCC_CALL_PROC_req(cpars.mncc_callref, cpars.mncc_bearer_cap));
3263 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_CALL_PROC(cpars.transaction_id)));
3264
3265 MNCC.send(ts_MNCC_ALERT_req(cpars.mncc_callref));
3266 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_ALERTING(cpars.transaction_id)));
3267 MGCP.receive(tr_CRCX);
3268
3269 f_sleep(1.0);
Harald Weltee13cfb22019-04-23 16:52:02 +02003270 if (pars.ran_is_geran) {
3271 BSSAP.send(ts_BSSMAP_ClearRequest(0));
3272 } else {
3273 BSSAP.send(ts_RANAP_IuReleaseRequest(ts_RanapCause_om_intervention));
3274 }
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003275
Neels Hofmeyrde76f052019-02-26 05:02:46 +01003276 var default ccrel := activate(as_optional_cc_rel(cpars));
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003277
Harald Weltee13cfb22019-04-23 16:52:02 +02003278 if (pars.ran_is_geran) {
3279 interleave {
3280 [] MNCC.receive(tr_MNCC_REL_ind(?, ?)) { };
3281 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {
Neels Hofmeyrde76f052019-02-26 05:02:46 +01003282 BSSAP.send(ts_BSSMAP_ClearComplete);
Harald Weltee13cfb22019-04-23 16:52:02 +02003283 };
3284 }
3285 } else {
3286 interleave {
3287 [] MNCC.receive(tr_MNCC_REL_ind(?, ?)) { };
3288 [] BSSAP.receive(tr_RANAP_IuReleaseCommand(?)) {
3289 BSSAP.send(ts_RANAP_IuReleaseComplete);
3290 };
3291 }
Neels Hofmeyrde76f052019-02-26 05:02:46 +01003292 }
3293
3294 deactivate(ccrel);
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003295
3296 f_sleep(1.0);
3297}
3298testcase TC_mo_cc_bssmap_clear() runs on MTC_CT {
3299 var BSC_ConnHdlr vc_conn;
3300 f_init();
3301
3302 vc_conn := f_start_handler(refers(f_tc_mo_cc_bssmap_clear), 43);
3303 vc_conn.done;
3304}
3305
Harald Weltee13cfb22019-04-23 16:52:02 +02003306
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003307/* LU followed by MT call and MT USSD request during this call */
Harald Weltee13cfb22019-04-23 16:52:02 +02003308friend function f_tc_lu_and_mt_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003309runs on BSC_ConnHdlr {
3310 f_init_handler(pars);
3311
3312 /* Call parameters taken from f_tc_lu_and_mt_call */
3313 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
3314 cpars.mgcp_connection_id_bss := '10004'H;
3315 cpars.mgcp_connection_id_mss := '10005'H;
3316 cpars.mgcp_ep := "rtpbridge/1@mgw";
3317 cpars.bss_rtp_port := 1110;
3318
3319 /* Perform location update */
3320 f_perform_lu();
3321
3322 /* Establish a MT call */
3323 f_mt_call_establish(cpars);
3324
3325 /* Hold the call for some time */
3326 f_sleep(1.0);
3327
3328 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3329 op_code := SS_OP_CODE_USS_REQUEST,
3330 ussd_string := "Please type anything..."
3331 );
3332
3333 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3334 op_code := SS_OP_CODE_USS_REQUEST,
3335 ussd_string := "Nope."
3336 )
3337
3338 /* Compose MT SS/REGISTER message with network-originated request */
3339 var template (value) PDU_ML3_NW_MS ussd_req := ts_ML3_MT_SS_REGISTER(
3340 tid := 0, /* FIXME: most likely, it should be 0 */
3341 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3342 facility := valueof(facility_req)
3343 );
3344
3345 /* Compose HLR -> MSC GSUP message */
3346 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3347 imsi := g_pars.imsi,
3348 sid := '20000101'O,
3349 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3350 ss := valueof(facility_req)
3351 );
3352
3353 /* Send it to MSC */
3354 GSUP.send(gsup_req);
3355 /* Expect MT REGISTER message with USSD request */
3356 f_expect_mt_dtap_msg(ussd_req);
3357
3358 /* Compose a new MO SS/FACILITY message with response */
3359 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
3360 tid := 0, /* FIXME: it shall match the request tid */
3361 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3362 facility := valueof(facility_rsp)
3363 );
3364
3365 /* Compose expected MSC -> HLR GSUP message */
3366 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
3367 imsi := g_pars.imsi,
3368 sid := '20000101'O,
3369 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3370 ss := valueof(facility_rsp)
3371 );
3372
3373 /* MS sends response */
3374 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
3375 f_expect_gsup_msg(gsup_rsp);
3376
3377 /* Compose expected MT SS/RELEASE COMPLETE message */
3378 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
3379 tid := 0, /* FIXME: it shall match the request tid */
3380 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3381 facility := omit
3382 );
3383
3384 /* Compose MSC -> HLR GSUP message */
3385 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
3386 imsi := g_pars.imsi,
3387 sid := '20000101'O,
3388 state := OSMO_GSUP_SESSION_STATE_END
3389 );
3390
3391 /* Finally, HLR terminates the session */
3392 GSUP.send(gsup_term);
3393 /* Expect MT RELEASE COMPLETE without Facility IE */
3394 f_expect_mt_dtap_msg(ussd_term);
3395
3396 /* Hold the call for some time */
3397 f_sleep(1.0);
3398
3399 /* Release the call (does Clear Complete itself) */
3400 f_call_hangup(cpars, true);
3401}
3402testcase TC_lu_and_mt_ussd_during_mt_call() runs on MTC_CT {
3403 var BSC_ConnHdlr vc_conn;
3404 f_init();
3405 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_during_mt_call), 49);
3406 vc_conn.done;
3407}
3408
Harald Weltee13cfb22019-04-23 16:52:02 +02003409
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07003410/* LU followed by MO USSD request and MO Release during transaction */
Harald Weltee13cfb22019-04-23 16:52:02 +02003411friend function f_tc_lu_and_mo_ussd_mo_release(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07003412runs on BSC_ConnHdlr {
3413 f_init_handler(pars);
3414
3415 /* Perform location update */
3416 f_perform_lu();
3417
3418 /* Send CM Service Request for SS/USSD */
3419 f_establish_fully(EST_TYPE_SS_ACT);
3420
3421 /* We need to inspect GSUP activity */
3422 f_create_gsup_expect(hex2str(g_pars.imsi));
3423
3424 var template OCTN facility_ms_req := f_USSD_FACILITY_IE_INVOKE(
3425 invoke_id := 1, /* Initial request */
3426 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3427 ussd_string := "*6766*266#"
3428 );
3429
3430 var template OCTN facility_net_req := f_USSD_FACILITY_IE_INVOKE(
3431 invoke_id := 2, /* Counter request */
3432 op_code := SS_OP_CODE_USS_REQUEST,
3433 ussd_string := "Password?!?"
3434 )
3435
3436 /* Compose MO SS/REGISTER message with request */
3437 var template (value) PDU_ML3_MS_NW ussd_ms_req := ts_ML3_MO_SS_REGISTER(
3438 tid := 1, /* We just need a single transaction */
3439 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3440 facility := valueof(facility_ms_req)
3441 );
3442
3443 /* Compose expected MSC -> HLR message */
3444 var template GSUP_PDU gsup_ms_req := tr_GSUP_PROC_SS_REQ(
3445 imsi := g_pars.imsi,
3446 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3447 ss := valueof(facility_ms_req)
3448 );
3449
3450 /* To be used for sending response with correct session ID */
3451 var GSUP_PDU gsup_ms_req_complete;
3452
3453 /* Initiate a new transaction */
3454 BSSAP.send(ts_PDU_DTAP_MO(ussd_ms_req));
3455 /* Expect GSUP request with original Facility IE */
3456 gsup_ms_req_complete := f_expect_gsup_msg(gsup_ms_req);
3457
3458 /* Compose the response from HLR using received session ID */
3459 var template (value) GSUP_PDU gsup_net_req := ts_GSUP_PROC_SS_REQ(
3460 imsi := g_pars.imsi,
3461 sid := gsup_ms_req_complete.ies[1].val.session_id,
3462 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3463 ss := valueof(facility_net_req)
3464 );
3465
3466 /* Compose expected MT SS/FACILITY template with counter request */
3467 var template PDU_ML3_NW_MS ussd_net_req := tr_ML3_MT_SS_FACILITY(
3468 tid := 1, /* Response should arrive within the same transaction */
3469 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3470 facility := valueof(facility_net_req)
3471 );
3472
3473 /* Send response over GSUP */
3474 GSUP.send(gsup_net_req);
3475 /* Expect MT SS/FACILITY message with counter request */
3476 f_expect_mt_dtap_msg(ussd_net_req);
3477
3478 /* Compose MO SS/RELEASE COMPLETE */
3479 var template (value) PDU_ML3_MS_NW ussd_abort := ts_ML3_MO_SS_RELEASE_COMPLETE(
3480 tid := 1, /* Response should arrive within the same transaction */
3481 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3482 facility := omit
3483 /* TODO: cause? */
3484 );
3485
3486 /* Compose expected HLR -> MSC abort message */
3487 var template GSUP_PDU gsup_abort := tr_GSUP_PROC_SS_REQ(
3488 imsi := g_pars.imsi,
3489 sid := gsup_ms_req_complete.ies[1].val.session_id,
3490 state := OSMO_GSUP_SESSION_STATE_END
3491 );
3492
3493 /* Abort transaction */
3494 BSSAP.send(ts_PDU_DTAP_MO(ussd_abort));
3495 /* Expect GSUP message indicating abort */
3496 f_expect_gsup_msg(gsup_abort);
3497
3498 f_expect_clear();
3499}
3500testcase TC_lu_and_mo_ussd_mo_release() runs on MTC_CT {
3501 var BSC_ConnHdlr vc_conn;
3502 f_init();
3503 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_mo_release), 50);
3504 vc_conn.done;
3505}
3506
Harald Weltee13cfb22019-04-23 16:52:02 +02003507
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003508/* LU followed by MO USSD request and MT Release due to timeout */
Harald Weltee13cfb22019-04-23 16:52:02 +02003509friend function f_tc_lu_and_ss_session_timeout(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003510runs on BSC_ConnHdlr {
3511 f_init_handler(pars);
3512
3513 /* Perform location update */
3514 f_perform_lu();
3515
3516 /* Send CM Service Request for SS/USSD */
3517 f_establish_fully(EST_TYPE_SS_ACT);
3518
3519 /* We need to inspect GSUP activity */
3520 f_create_gsup_expect(hex2str(g_pars.imsi));
3521
3522 var template OCTN facility_ms_req := f_USSD_FACILITY_IE_INVOKE(
3523 invoke_id := 1,
3524 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3525 ussd_string := "#release_me");
3526
3527 /* Compose MO SS/REGISTER message with request */
3528 var template (value) PDU_ML3_MS_NW ussd_ms_req := ts_ML3_MO_SS_REGISTER(
3529 tid := 1, /* An arbitrary transaction identifier */
3530 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3531 facility := valueof(facility_ms_req));
3532
3533 /* Compose expected MSC -> HLR message */
3534 var template GSUP_PDU gsup_ms_req := tr_GSUP_PROC_SS_REQ(
3535 imsi := g_pars.imsi,
3536 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3537 ss := valueof(facility_ms_req));
3538
3539 /* To be used for sending response with correct session ID */
3540 var GSUP_PDU gsup_ms_req_complete;
3541
3542 /* Initiate a new SS transaction */
3543 BSSAP.send(ts_PDU_DTAP_MO(ussd_ms_req));
3544 /* Expect GSUP request with original Facility IE */
3545 gsup_ms_req_complete := f_expect_gsup_msg(gsup_ms_req);
3546
3547 /* Don't respond, wait for timeout */
3548 f_sleep(3.0);
3549
3550 var template PDU_ML3_NW_MS dtap_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
3551 tid := 1, /* Should match the request's tid */
3552 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3553 cause := *, /* TODO: expect some specific value */
3554 facility := omit);
3555
3556 var template GSUP_PDU gsup_rel := tr_GSUP_PROC_SS_ERR(
3557 imsi := g_pars.imsi,
3558 sid := gsup_ms_req_complete.ies[1].val.session_id,
3559 state := OSMO_GSUP_SESSION_STATE_END,
3560 cause := ?); /* TODO: expect some specific value */
3561
3562 /* Expect release on both interfaces */
3563 interleave {
3564 [] BSSAP.receive(tr_PDU_DTAP_MT(dtap_rel)) { };
3565 [] GSUP.receive(gsup_rel) { };
3566 }
3567
3568 f_expect_clear();
3569 setverdict(pass);
3570}
3571testcase TC_lu_and_ss_session_timeout() runs on MTC_CT {
3572 var BSC_ConnHdlr vc_conn;
3573 f_init();
Vadim Yanitskiy36d28dd2018-12-03 02:45:45 +07003574 f_vty_config(MSCVTY, "msc", "ncss guard-timeout 3");
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003575 vc_conn := f_start_handler(refers(f_tc_lu_and_ss_session_timeout), 51);
3576 vc_conn.done;
Vadim Yanitskiy36d28dd2018-12-03 02:45:45 +07003577 f_vty_config(MSCVTY, "msc", "ncss guard-timeout 0");
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003578}
3579
Harald Weltee13cfb22019-04-23 16:52:02 +02003580
Stefan Sperling89eb1f32018-12-17 15:06:20 +01003581/* A5/1 only permitted on network side; attempt an invalid CIPHER MODE COMPLETE with A5/3 which MSC should reject. */
3582private function f_tc_cipher_complete_with_invalid_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3583 pars.net.expect_auth := true;
3584 pars.net.expect_ciph := true;
3585 pars.net.kc_support := '02'O; /* A5/1 only */
3586 f_init_handler(pars);
3587
3588 g_pars.vec := f_gen_auth_vec_2g();
3589
3590 /* Can't use f_perform_lu() directly. Code below is based on it. */
3591
3592 /* tell GSUP dispatcher to send this IMSI to us */
3593 f_create_gsup_expect(hex2str(g_pars.imsi));
3594
3595 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
3596 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
Harald Weltedceacc72019-04-21 20:58:35 +02003597 f_cl3_or_initial_ue(l3_lu);
Stefan Sperling89eb1f32018-12-17 15:06:20 +01003598
3599 f_mm_auth();
3600
3601 var OCT1 a5_net := f_alg_mask_from_cm(g_pars.cm2);
3602 var OCT1 a5_intersect := g_pars.net.kc_support and4b a5_net;
3603 alt {
3604 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(a5_intersect, g_pars.vec.kc)) {
3605 BSSAP.send(ts_BSSMAP_CipherModeCompl(int2oct(4 /* "accept" A5/3 */, 1)));
3606 }
3607 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?, g_pars.vec.kc)) {
3608 setverdict(fail, "Wrong ciphering algorithm mask in CiphModCmd");
3609 mtc.stop;
3610 }
3611 [] BSSAP.receive {
3612 setverdict(fail, "Unknown/unexpected BSSAP received");
3613 mtc.stop;
3614 }
3615 }
3616
3617 /* Expect LU reject from MSC. */
3618 alt {
3619 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
3620 setverdict(pass);
3621 }
3622 [] BSSAP.receive {
3623 setverdict(fail, "Unknown/unexpected BSSAP received");
3624 mtc.stop;
3625 }
3626 }
Stefan Sperlingc620b352018-12-18 17:23:36 +01003627 f_expect_clear();
Stefan Sperling89eb1f32018-12-17 15:06:20 +01003628}
3629
3630testcase TC_cipher_complete_with_invalid_cipher() runs on MTC_CT {
3631 var BSC_ConnHdlr vc_conn;
3632 f_init();
3633 f_vty_config(MSCVTY, "network", "encryption a5 1");
3634
3635 vc_conn := f_start_handler(refers(f_tc_cipher_complete_with_invalid_cipher), 52);
3636 vc_conn.done;
3637}
3638
Harald Weltef640a012018-04-14 17:49:21 +02003639/* TODO (SMS):
3640 * different user data lengths
3641 * SMPP transaction mode with unsuccessful delivery
3642 * queued MT-SMS with no paging response + later delivery
3643 * different data coding schemes
3644 * multi-part SMS
3645 * user-data headers
3646 * TP-PID for SMS to SIM
3647 * behavior if SMS memory is full + RP-SMMA
3648 * delivery reports
3649 * SMPP osmocom extensions
3650 * more-messages-to-send
3651 * SMS during ongoing call (SACCH/SAPI3)
3652 */
3653
3654/* TODO (General):
Harald Welteba7b6d92018-01-23 21:32:34 +01003655 * continue to send repeated MO signalling messages to keep channel open: does MSC tmeout?
3656 * malformed messages (missing IE, invalid message type): properly rejected?
3657 * MT call while LU or is ongoing: Do we use existing lchan or page while lchan active?
3658 * 3G/2G auth permutations
3659 * encryption algorithms vs. classmark vs. vty config
Harald Welteba7b6d92018-01-23 21:32:34 +01003660 * send new transaction after/during clear (like SMS, ...)
Harald Welte45164da2018-01-24 12:51:27 +01003661 * too long L3 INFO in DTAP
3662 * too long / padded BSSAP
3663 * too long / short TLV values
Harald Welteba7b6d92018-01-23 21:32:34 +01003664 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01003665
Harald Weltee13cfb22019-04-23 16:52:02 +02003666/***********************************************************************
3667 * SGsAP Testing
3668 ***********************************************************************/
3669
Philipp Maier948747b2019-04-02 15:22:33 +02003670/* Check if a subscriber exists in the VLR */
3671private function f_ctrl_subscr_in_vlr(charstring imsi_or_msisdn) runs on BSC_ConnHdlr return boolean {
3672
3673 var CtrlValue active_subsribers;
3674 var integer rc;
3675 active_subsribers := f_ctrl_get(IPA_CTRL, "subscriber-list-active-v1");
3676
3677 rc := f_strstr(active_subsribers, imsi_or_msisdn);
3678 if (rc < 0) {
3679 return false;
3680 }
3681
3682 return true;
3683}
3684
Harald Welte4263c522018-12-06 11:56:27 +01003685/* Perform a location updatye at the A-Interface and run some checks to confirm
3686 * that everything is back to normal. */
3687private function f_sgsap_bssmap_screening() runs on BSC_ConnHdlr {
3688 var SmsParameters spars := valueof(t_SmsPars);
3689
3690 /* Perform a location update, the SGs association is expected to fall
3691 * back to NULL */
3692 f_perform_lu();
3693 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
3694
3695 /* Trigger a paging request and expect the paging on BSSMAP, this is
3696 * to make sure that pagings are sent throught the A-Interface again
3697 * and not throught the SGs interface.*/
Harald Welte6811d102019-04-14 22:23:14 +02003698 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Welte4263c522018-12-06 11:56:27 +01003699 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
3700
3701 alt {
Harald Weltee13cfb22019-04-23 16:52:02 +02003702 [g_pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)); {
3703 setverdict(pass);
3704 }
3705 [not g_pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi), ?)) {
Harald Welte4263c522018-12-06 11:56:27 +01003706 setverdict(pass);
3707 }
3708 [] SGsAP.receive {
3709 setverdict(fail, "Received unexpected message on SGs");
3710 }
3711 }
3712
3713 /* Send an SMS to make sure that also payload messages are routed
3714 * throught the A-Interface again */
3715 f_establish_fully(EST_TYPE_MO_SMS);
3716 f_mo_sms(spars);
3717 f_expect_clear();
3718}
3719
3720private function f_tc_sgsap_reset(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3721 var charstring vlr_name;
3722 f_init_handler(pars);
3723
3724 vlr_name := f_sgsap_reset_mme(mp_mme_name);
3725 log("VLR name: ", vlr_name);
3726 setverdict(pass);
Neels Hofmeyrc0b520d2019-03-06 15:35:50 +01003727 f_sleep(1.0);
Harald Welte4263c522018-12-06 11:56:27 +01003728}
3729
3730testcase TC_sgsap_reset() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003731 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01003732 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003733 f_init(1, true);
3734 pars := f_init_pars(11810, true);
3735 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_reset), pars);
Harald Welte4263c522018-12-06 11:56:27 +01003736 vc_conn.done;
3737}
3738
3739/* like f_mm_auth() but for SGs */
3740function f_mm_auth_sgs() runs on BSC_ConnHdlr {
3741 if (g_pars.net.expect_auth) {
3742 g_pars.vec := f_gen_auth_vec_3g();
3743 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G3G(g_pars.vec.rand,
3744 g_pars.vec.sres,
3745 g_pars.vec.kc,
3746 g_pars.vec.ik,
3747 g_pars.vec.ck,
3748 g_pars.vec.autn,
3749 g_pars.vec.res));
3750 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
3751 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
3752 SGsAP.receive(tr_ML3_MT_MM_AUTH_REQ_3G(g_pars.vec.rand, g_pars.vec.autn));
3753 SGsAP.send(ts_ML3_MT_MM_AUTH_RESP_3G(g_pars.vec.sres, g_pars.vec.res));
3754 }
3755}
3756
3757/* like f_perform_lu(), but on SGs rather than BSSAP */
3758function f_sgs_perform_lu() runs on BSC_ConnHdlr {
3759 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
3760 var PDU_SGsAP lur;
3761 var PDU_SGsAP lua;
3762 var PDU_SGsAP mm_info;
3763 var octetstring mm_info_dtap;
3764
3765 /* tell GSUP dispatcher to send this IMSI to us */
3766 f_create_gsup_expect(hex2str(g_pars.imsi));
3767
3768 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
3769 ts_SGsAP_LAI('901'H, '70'H, 2342)));
3770 /* Old LAI, if MS sends it */
3771 /* TMSI status, if MS has no valid TMSI */
3772 /* IMEISV, if it supports "automatic device detection" */
3773 /* TAI, if available in MME */
3774 /* E-CGI, if available in MME */
3775 SGsAP.send(lur);
3776
3777 /* FIXME: is this really done over SGs? The Ue is already authenticated
3778 * via the MME ... */
3779 f_mm_auth_sgs();
3780
3781 /* Expect MSC to perform LU with HLR */
3782 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
3783 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
3784 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
3785 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
3786
3787 alt {
3788 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) -> value lua {
3789 if (isvalue(lua.sGsAP_LOCATION_UPDATE_ACCEPT.newTMSIorIMSI.iD.iD.tmsi_ptmsi.octets)) {
3790 g_pars.tmsi :=lua.sGsAP_LOCATION_UPDATE_ACCEPT.newTMSIorIMSI.iD.iD.tmsi_ptmsi.octets
3791 SGsAP.send(ts_SGsAP_TMSI_REALL_CMPL(g_pars.imsi));
3792 }
3793 setverdict(pass);
3794 }
3795 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
3796 setverdict(fail, "Received LU-REJECT instead of ACCEPT");
3797 }
3798 [] SGsAP.receive {
3799 setverdict(fail, "Received unexpected message on SGs");
3800 }
3801 }
3802
3803 /* Check MM information */
3804 if (mp_mm_info == true) {
3805 SGsAP.receive(tr_SGsAP_MM_INFO_REQ(g_pars.imsi, ?)) -> value mm_info;
3806 mm_info_dtap := '0532'O & mm_info.sGsAP_MM_INFORMATION_REQUEST.mM_Information.information;
3807 if (not match(dec_PDU_ML3_NW_MS(mm_info_dtap), tr_ML3_MT_MM_Info)) {
3808 setverdict(fail, "Unexpected MM Information");
3809 }
3810 }
3811
3812 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
3813}
3814
3815private function f_tc_sgsap_lu(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3816 f_init_handler(pars);
3817 f_sgs_perform_lu();
3818 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
3819
3820 f_sgsap_bssmap_screening();
3821
3822 setverdict(pass);
3823}
3824testcase TC_sgsap_lu() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003825 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01003826 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003827 f_init(1, true);
3828 pars := f_init_pars(11811, true);
3829 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu), pars);
Harald Welte4263c522018-12-06 11:56:27 +01003830 vc_conn.done;
3831}
3832
3833/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
3834private function f_tc_sgsap_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3835 f_init_handler(pars);
3836 var PDU_SGsAP lur;
3837
3838 f_create_gsup_expect(hex2str(g_pars.imsi));
3839 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
3840 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
3841 ts_SGsAP_LAI('901'H, '70'H, 2342)));
3842 SGsAP.send(lur);
3843
3844 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
3845 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
3846 alt {
3847 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
3848 setverdict(pass);
3849 }
3850 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) {
3851 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
3852 mtc.stop;
3853 }
3854 [] SGsAP.receive {
3855 setverdict(fail, "Received unexpected message on SGs");
3856 }
3857 }
3858
3859 f_sgsap_bssmap_screening();
3860
3861 setverdict(pass);
3862}
3863testcase TC_sgsap_lu_imsi_reject() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003864 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01003865 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003866 f_init(1, true);
3867 pars := f_init_pars(11812, true);
Harald Welte4263c522018-12-06 11:56:27 +01003868
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003869 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_imsi_reject), pars);
Harald Welte4263c522018-12-06 11:56:27 +01003870 vc_conn.done;
3871}
3872
3873/* Do LU by IMSI, but then remain silent so that Ts6-1 times out */
3874private function f_tc_sgsap_lu_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3875 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
3876 var PDU_SGsAP lur;
3877
3878 f_init_handler(pars);
3879
3880 /* tell GSUP dispatcher to send this IMSI to us */
3881 f_create_gsup_expect(hex2str(g_pars.imsi));
3882
3883 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
3884 ts_SGsAP_LAI('901'H, '70'H, 2342)));
3885 /* Old LAI, if MS sends it */
3886 /* TMSI status, if MS has no valid TMSI */
3887 /* IMEISV, if it supports "automatic device detection" */
3888 /* TAI, if available in MME */
3889 /* E-CGI, if available in MME */
3890 SGsAP.send(lur);
3891
3892 /* FIXME: is this really done over SGs? The Ue is already authenticated
3893 * via the MME ... */
3894 f_mm_auth_sgs();
3895
3896 /* Expect MSC to perform LU with HLR */
3897 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
3898 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
3899 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
3900 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
3901
3902 alt {
3903 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) {
3904 setverdict(pass);
3905 }
3906 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
3907 setverdict(fail, "Received LU-REJECT instead of ACCEPT");
3908 }
3909 [] SGsAP.receive {
3910 setverdict(fail, "Received unexpected message on SGs");
3911 }
3912 }
3913
3914 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
3915
3916 /* Wait until the VLR has abort the TMSI reallocation procedure */
3917 f_sleep(45.0);
3918
3919 /* The outcome does not change the SGs state, see also 5.2.3.4 */
3920 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
3921
3922 f_sgsap_bssmap_screening();
3923
3924 setverdict(pass);
3925}
3926testcase TC_sgsap_lu_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003927 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01003928 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003929 f_init(1, true);
3930 pars := f_init_pars(11813, true);
Harald Welte4263c522018-12-06 11:56:27 +01003931
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003932 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01003933 vc_conn.done;
3934}
3935
3936private function f_tc_sgsap_expl_imsi_det_eps(charstring id, BSC_ConnHdlrPars pars)
3937runs on BSC_ConnHdlr {
3938 f_init_handler(pars);
3939 f_sgs_perform_lu();
3940 f_sleep(3.0);
3941
3942 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
3943 SGsAP.send(ts_SGsAP_EPS_DETACH_IND(g_pars.imsi, mme_name, UE_initiated));
3944 SGsAP.receive(tr_SGsAP_EPS_DETACH_ACK(g_pars.imsi));
3945 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
3946
3947 f_sgsap_bssmap_screening();
3948
3949 setverdict(pass);
3950}
3951testcase TC_sgsap_expl_imsi_det_eps() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003952 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01003953 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003954 f_init(1, true);
3955 pars := f_init_pars(11814, true);
3956 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_expl_imsi_det_eps), pars);
Harald Welte4263c522018-12-06 11:56:27 +01003957 vc_conn.done;
3958}
3959
Philipp Maierfc19f172019-03-21 11:17:54 +01003960private function f_tc_sgsap_impl_imsi_det_eps(charstring id, BSC_ConnHdlrPars pars)
3961runs on BSC_ConnHdlr {
3962 f_init_handler(pars);
3963 f_sgs_perform_lu();
3964 f_sleep(3.0);
3965
3966 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
3967 SGsAP.send(ts_SGsAP_EPS_DETACH_IND(g_pars.imsi, mme_name, network_initiated));
3968 SGsAP.receive(tr_SGsAP_EPS_DETACH_ACK(g_pars.imsi));
3969 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
3970
3971 f_sgsap_bssmap_screening();
3972
3973 setverdict(pass);
3974}
3975testcase TC_sgsap_impl_imsi_det_eps() runs on MTC_CT {
3976 var BSC_ConnHdlrPars pars;
3977 var BSC_ConnHdlr vc_conn;
3978 f_init(1, true);
3979 pars := f_init_pars(11814, true);
3980 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_impl_imsi_det_eps), pars);
3981 vc_conn.done;
3982}
3983
Harald Welte4263c522018-12-06 11:56:27 +01003984private function f_tc_sgsap_expl_imsi_det_noneps(charstring id, BSC_ConnHdlrPars pars)
3985runs on BSC_ConnHdlr {
3986 f_init_handler(pars);
3987 f_sgs_perform_lu();
3988 f_sleep(3.0);
3989
3990 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
3991 SGsAP.send(ts_SGsAP_IMSI_DETACH_IND(g_pars.imsi, mme_name, combined_UE_initiated));
3992 SGsAP.receive(tr_SGsAP_IMSI_DETACH_ACK(g_pars.imsi));
Philipp Maierd08e7e72019-04-02 15:27:10 +02003993
3994 if (f_ctrl_subscr_in_vlr(hex2str(g_pars.imsi))) {
3995 setverdict(fail, "subscriber not removed from VLR");
3996 }
Harald Welte4263c522018-12-06 11:56:27 +01003997
3998 f_sgsap_bssmap_screening();
3999
4000 setverdict(pass);
4001}
4002testcase TC_sgsap_expl_imsi_det_noneps() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004003 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004004 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004005 f_init(1, true);
4006 pars := f_init_pars(11815, true);
4007 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_expl_imsi_det_noneps), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004008 vc_conn.done;
4009}
4010
Philipp Maier5d812702019-03-21 10:51:26 +01004011private function f_tc_sgsap_impl_imsi_det_noneps(charstring id, BSC_ConnHdlrPars pars)
4012runs on BSC_ConnHdlr {
4013 f_init_handler(pars);
4014 f_sgs_perform_lu();
4015 f_sleep(3.0);
4016
4017 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4018 SGsAP.send(ts_SGsAP_IMSI_DETACH_IND(g_pars.imsi, mme_name, implicit_network_initiated));
4019 SGsAP.receive(tr_SGsAP_IMSI_DETACH_ACK(g_pars.imsi));
4020
4021 if (f_ctrl_subscr_in_vlr(hex2str(g_pars.imsi))) {
4022 setverdict(fail, "subscriber not removed from VLR");
4023 }
4024
4025 f_sgsap_bssmap_screening();
4026
4027 setverdict(pass);
4028}
4029testcase TC_sgsap_impl_imsi_det_noneps() runs on MTC_CT {
4030 var BSC_ConnHdlrPars pars;
4031 var BSC_ConnHdlr vc_conn;
4032 f_init(1, true);
4033 pars := f_init_pars(11815, true);
4034 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_impl_imsi_det_noneps), pars);
4035 vc_conn.done;
4036}
4037
Harald Welte4263c522018-12-06 11:56:27 +01004038/* Trigger a paging request via VTY and send a paging reject in response */
4039private function f_tc_sgsap_paging_rej(charstring id, BSC_ConnHdlrPars pars)
4040runs on BSC_ConnHdlr {
4041 f_init_handler(pars);
4042 f_sgs_perform_lu();
4043 f_sleep(1.0);
4044
4045 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4046 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4047 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4048 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4049
4050 /* Initiate paging via VTY */
4051 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4052 alt {
4053 [] SGsAP.receive(exp_resp) {
4054 setverdict(pass);
4055 }
4056 [] SGsAP.receive {
4057 setverdict(fail, "Received unexpected message on SGs");
4058 }
4059 }
4060
4061 /* Now reject the paging */
4062 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, IMSI_unknown));
4063
4064 /* Wait for the states inside the MSC to settle and check the state
4065 * of the SGs Association */
4066 f_sleep(1.0);
4067 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4068
4069 /* FIXME: At the moment we send an IMSI_unknown as cause code, which is fine,
4070 * but we also need to cover tha case where the cause code indicates an
4071 * "IMSI detached for EPS services". In those cases the VLR is expected to
4072 * try paging on tha A/Iu interface. This will be another testcase similar to
4073 * this one, but extended with checks for the presence of the A/Iu paging
4074 * messages. */
4075
4076 f_sgsap_bssmap_screening();
4077
4078 setverdict(pass);
4079}
4080testcase TC_sgsap_paging_rej() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004081 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004082 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004083 f_init(1, true);
4084 pars := f_init_pars(11816, true);
4085 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_rej), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004086 vc_conn.done;
4087}
4088
4089/* Trigger a paging request via VTY and send a paging reject that indicates
4090 * that the subscriber intentionally rejected the call. */
4091private function f_tc_sgsap_paging_subscr_rej(charstring id, BSC_ConnHdlrPars pars)
4092runs on BSC_ConnHdlr {
4093 f_init_handler(pars);
4094 f_sgs_perform_lu();
4095 f_sleep(1.0);
4096
4097 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4098 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4099 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4100 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4101
4102 /* Initiate paging via VTY */
4103 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4104 alt {
4105 [] SGsAP.receive(exp_resp) {
4106 setverdict(pass);
4107 }
4108 [] SGsAP.receive {
4109 setverdict(fail, "Received unexpected message on SGs");
4110 }
4111 }
4112
4113 /* Now reject the paging */
4114 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, user_rejected_mobile_terminating_CS_fallback_call));
4115
4116 /* Wait for the states inside the MSC to settle and check the state
4117 * of the SGs Association */
4118 f_sleep(1.0);
4119 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4120
4121 /* FIXME: The VLR is supposed to trigger an User Determined User Busy (UDUB) as specified
4122 * in 3GPP TS 24.082, this is not yet implemented in the MSC or in this tests, we need
4123 * to check back how this works and how it can be tested */
4124
4125 f_sgsap_bssmap_screening();
4126
4127 setverdict(pass);
4128}
4129testcase TC_sgsap_paging_subscr_rej() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004130 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004131 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004132 f_init(1, true);
4133 pars := f_init_pars(11817, true);
4134 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_subscr_rej), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004135 vc_conn.done;
4136}
4137
4138/* Trigger a paging request via VTY and send an UE unreacable messge in response */
4139private function f_tc_sgsap_paging_ue_unr(charstring id, BSC_ConnHdlrPars pars)
4140runs on BSC_ConnHdlr {
4141 f_init_handler(pars);
4142 f_sgs_perform_lu();
4143 f_sleep(1.0);
4144
4145 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4146 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4147 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4148 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4149
4150 /* Initiate paging via VTY */
4151 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4152 alt {
4153 [] SGsAP.receive(exp_resp) {
4154 setverdict(pass);
4155 }
4156 [] SGsAP.receive {
4157 setverdict(fail, "Received unexpected message on SGs");
4158 }
4159 }
4160
4161 /* Now pretend that the UE is unreachable */
4162 SGsAP.send(ts_SGsAP_UE_UNREACHABLE(g_pars.imsi, UE_unreachable));
4163
4164 /* Wait for the states inside the MSC to settle and check the state
4165 * of the SGs Association. */
4166 f_sleep(1.0);
4167 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4168
4169 f_sgsap_bssmap_screening();
4170
4171 setverdict(pass);
4172}
4173testcase TC_sgsap_paging_ue_unr() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004174 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004175 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004176 f_init(1, true);
4177 pars := f_init_pars(11818, true);
4178 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_ue_unr), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004179 vc_conn.done;
4180}
4181
4182/* Trigger a paging request via VTY but don't respond to it */
4183private function f_tc_sgsap_paging_and_nothing(charstring id, BSC_ConnHdlrPars pars)
4184runs on BSC_ConnHdlr {
4185 f_init_handler(pars);
4186 f_sgs_perform_lu();
4187 f_sleep(1.0);
4188
4189 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4190 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4191 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4192 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4193
4194 /* Initiate paging via VTY */
4195 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4196 alt {
4197 [] SGsAP.receive(exp_resp) {
4198 setverdict(pass);
4199 }
4200 [] SGsAP.receive {
4201 setverdict(fail, "Received unexpected message on SGs");
4202 }
4203 }
4204
4205 /* Now do nothing, the MSC/VLR should fail silently to page after a
4206 * few seconds, The SGs association must remain unchanged. */
4207 f_sleep(15.0);
4208 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4209
4210 f_sgsap_bssmap_screening();
4211
4212 setverdict(pass);
4213}
4214testcase TC_sgsap_paging_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004215 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004216 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004217 f_init(1, true);
4218 pars := f_init_pars(11819, true);
4219 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004220 vc_conn.done;
4221}
4222
4223/* Trigger a paging request via VTY and slip in an LU */
4224private function f_tc_sgsap_paging_and_lu(charstring id, BSC_ConnHdlrPars pars)
4225runs on BSC_ConnHdlr {
4226 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4227 f_init_handler(pars);
4228
4229 /* First we prepar the situation, where the SGs association is in state
4230 * NULL and the confirmed by radio contact indicator is set to false
4231 * as well. This can be archived by performing an SGs LU and then
4232 * resetting the VLR */
4233 f_sgs_perform_lu();
4234 f_sgsap_reset_mme(mp_mme_name);
4235 f_sleep(1.0);
4236 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4237
4238 /* Perform a paging, expect the paging messages on the SGs interface */
4239 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4240 alt {
4241 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
4242 setverdict(pass);
4243 }
4244 [] SGsAP.receive {
4245 setverdict(fail, "Received unexpected message on SGs");
4246 }
4247 }
4248
4249 /* Perform the LU as normal */
4250 f_sgs_perform_lu();
4251 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4252
4253 /* Expect a new paging request right after the LU */
4254 alt {
4255 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
4256 setverdict(pass);
4257 }
4258 [] SGsAP.receive {
4259 setverdict(fail, "Received unexpected message on SGs");
4260 }
4261 }
4262
4263 /* Test is done now, lets round everything up by rejecting the paging
4264 * cleanly. */
4265 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, user_rejected_mobile_terminating_CS_fallback_call));
4266 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4267
4268 f_sgsap_bssmap_screening();
4269
4270 setverdict(pass);
4271}
4272testcase TC_sgsap_paging_and_lu() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004273 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004274 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004275 f_init(1, true);
4276 pars := f_init_pars(11820, true);
4277 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_and_lu), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004278 vc_conn.done;
4279}
4280
4281/* Send unexpected unit-data through the SGs interface */
4282private function f_tc_sgsap_unexp_ud(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4283 f_init_handler(pars);
4284 f_sleep(1.0);
4285
4286 /* This simulates what happens when a subscriber without SGs
4287 * association gets unitdata via the SGs interface. */
4288
4289 /* Make sure the subscriber exists and the SGs association
4290 * is in NULL state */
4291 f_perform_lu();
4292 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4293
4294 /* Send some random unit data, the MSC/VLR should send a release
4295 * immediately. */
4296 SGsAP.send(ts_SGsAP_UL_UD(pars.imsi,'1234'O));
4297 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, IMSI_detached_for_EPS_nonEPS_services));
4298
4299 f_sgsap_bssmap_screening();
4300
4301 setverdict(pass);
4302}
4303testcase TC_sgsap_unexp_ud() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004304 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004305 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004306 f_init(1, true);
4307 pars := f_init_pars(11821, true);
4308 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_unexp_ud), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004309 vc_conn.done;
4310}
4311
4312/* Send unsolicited unit-data through the SGs interface */
4313private function f_tc_sgsap_unsol_ud(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4314 f_init_handler(pars);
4315 f_sleep(1.0);
4316
4317 /* This simulates what happens when the MME attempts to send unitdata
4318 * to a subscriber that is completely unknown to the VLR */
4319
4320 /* Send some random unit data, the MSC/VLR should send a release
4321 * immediately. */
4322 SGsAP.send(ts_SGsAP_UL_UD(pars.imsi,'1234'O));
4323 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, IMSI_unknown));
4324
4325 f_sgsap_bssmap_screening();
4326
4327 setverdict(pass);
4328}
4329testcase TC_sgsap_unsol_ud() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004330 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004331 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004332 f_init(1, true);
4333 pars := f_init_pars(11822, true);
4334 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_unsol_ud), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004335 vc_conn.done;
4336}
4337
4338private altstep as_other_sms_sgs() runs on BSC_ConnHdlr {
4339 /* FIXME: Match an actual payload (second questionmark), the type is
4340 * octetstring, how do we use a tr_PDU_DTAP_MT here? */
4341 [] SGsAP.receive(tr_SGsAP_DL_UD(?,?)) {
4342 setverdict(fail, "Unexpected SMS related PDU from MSC");
4343 mtc.stop;
4344 }
4345}
4346
4347/* receive a MT-SMS delivered from the MSC/SMSC over an already existing SGsAP connection */
4348function f_mt_sms_sgs(inout SmsParameters spars)
4349runs on BSC_ConnHdlr {
4350 var template (value) TPDU_RP_DATA_MS_SGSN tp_mo;
4351 var template (value) RPDU_MS_SGSN rp_mo;
4352 var template (value) PDU_ML3_MS_NW l3_mo;
4353
4354 var template TPDU_RP_DATA_SGSN_MS tp_mt;
4355 var template RPDU_SGSN_MS rp_mt;
4356 var template PDU_ML3_NW_MS l3_mt;
4357
4358 var PDU_ML3_NW_MS sgsap_l3_mt;
4359
4360 var default d := activate(as_other_sms_sgs());
4361
4362 /* Expect CP-DATA(RP-DATA(SMS-DELIVER)) */
4363 tp_mt := tr_SMS_DELIVER(?, spars.tp.ud, spars.tp.pid, spars.tp.dcs, ?);
4364 rp_mt := tr_RP_DATA_MT(?, ?, omit, tp_mt);
4365 l3_mt := tr_ML3_MT_SMS(?, c_TIF_ORIG, tr_CP_DATA_MT(rp_mt));
4366
4367 SGsAP.receive(l3_mt) -> value sgsap_l3_mt;
4368
4369 /* Extract relevant identifiers */
4370 spars.tid := bit2int(sgsap_l3_mt.tiOrSkip.transactionId.tio);
4371 spars.rp.msg_ref := sgsap_l3_mt.msgs.sms.cP_DATA.cP_User_Data.cP_RPDU.rP_DATA_SGSN_MS.rP_MessageReference;
4372
4373 /* send CP-ACK for CP-DATA just received */
4374 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_REPL, ts_CP_ACK_MO);
4375
4376 SGsAP.send(l3_mo);
4377
4378 /* send RP-ACK for RP-DATA */
4379 rp_mo := ts_RP_ACK_MO(spars.rp.msg_ref);
4380 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_REPL, ts_CP_DATA_MO(rp_mo));
4381
4382 SGsAP.send(l3_mo);
4383
4384 /* expect CP-ACK for CP-DATA(RP-ACK) just sent */
4385 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_ORIG, tr_CP_ACK_MT);
4386
4387 SGsAP.receive(l3_mt);
4388
4389 deactivate(d);
4390
4391 setverdict(pass);
4392}
4393
4394/* submit a MO-SMS to MSC/SMSC over an already existing SGsAP connection */
4395function f_mo_sms_sgs(inout SmsParameters spars)
4396runs on BSC_ConnHdlr {
4397 var template (value) TPDU_RP_DATA_MS_SGSN tp_mo;
4398 var template (value) RPDU_MS_SGSN rp_mo;
4399 var template (value) PDU_ML3_MS_NW l3_mo;
4400
4401 var template TPDU_RP_DATA_SGSN_MS tp_mt;
4402 var template RPDU_SGSN_MS rp_mt;
4403 var template PDU_ML3_NW_MS l3_mt;
4404
4405 var default d := activate(as_other_sms_sgs());
4406
4407 /* just in case this is routed to SMPP.. */
4408 f_create_smpp_expect(hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue));
4409
4410 tp_mo := ts_SMS_SUBMIT(spars.tp.msg_ref, spars.tp.da, spars.tp.pid, spars.tp.dcs,
4411 spars.tp.udl, spars.tp.ud);
4412 rp_mo := ts_RP_DATA_MO(spars.rp.msg_ref, spars.rp.orig, spars.rp.dest, tp_mo);
4413 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_DATA_MO(rp_mo));
4414
4415 SGsAP.send(l3_mo);
4416
4417 /* receive CP-ACK for CP-DATA above */
4418 SGsAP.receive(tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_ACK_MT));
4419
4420 if (ispresent(spars.exp_rp_err)) {
4421 /* expect an RP-ERROR message from MSC with given cause */
4422 rp_mt := tr_RP_ERROR_MT(spars.rp.msg_ref, spars.exp_rp_err);
4423 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_DATA_MT(rp_mt));
4424 SGsAP.receive(l3_mt);
4425 /* send CP-ACK for CP-DATA just received */
4426 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_ACK_MO);
4427 SGsAP.send(l3_mo);
4428 } else {
4429 /* expect RP-ACK for RP-DATA */
4430 rp_mt := tr_RP_ACK_MT(spars.rp.msg_ref);
4431 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_DATA_MT(rp_mt));
4432 SGsAP.receive(l3_mt);
4433 /* send CP-ACO for CP-DATA just received */
4434 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_ACK_MO);
4435 SGsAP.send(l3_mo);
4436 }
4437
4438 deactivate(d);
4439
4440 setverdict(pass);
4441}
4442
4443private function f_vty_sms_send_conn_hdlr(charstring imsi, charstring msisdn, charstring text)
4444runs on BSC_ConnHdlr {
4445 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
4446}
4447
4448/* Send a MT SMS via SGs interface */
4449private function f_tc_sgsap_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4450 f_init_handler(pars);
4451 f_sgs_perform_lu();
4452 f_sleep(1.0);
4453 var SmsParameters spars := valueof(t_SmsPars);
4454 spars.tp.ud := 'C8329BFD064D9B53'O;
4455
4456 /* Trigger SMS via VTY */
4457 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
4458 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4459
4460 /* Expect a paging request and respond accordingly with a service request */
4461 SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, SMS_indicator, omit));
4462 SGsAP.send(ts_SGsAP_SERVICE_REQ(pars.imsi, SMS_indicator, EMM_CONNECTED));
4463
4464 /* Connection is now live, receive the MT-SMS */
4465 f_mt_sms_sgs(spars);
4466
4467 /* Expect a concluding release from the MSC */
4468 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, omit));
4469
4470 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
4471 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4472
4473 f_sgsap_bssmap_screening();
4474
4475 setverdict(pass);
4476}
4477testcase TC_sgsap_mt_sms() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004478 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004479 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004480 f_init(1, true);
4481 pars := f_init_pars(11823, true);
4482 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004483 vc_conn.done;
4484}
4485
4486/* Send a MO SMS via SGs interface */
4487private function f_tc_sgsap_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4488 f_init_handler(pars);
4489 f_sgs_perform_lu();
4490 f_sleep(1.0);
4491 var SmsParameters spars := valueof(t_SmsPars);
4492 spars.tp.ud := 'C8329BFD064D9B53'O;
4493
4494 /* Send the MO-SMS */
4495 f_mo_sms_sgs(spars);
4496
4497 /* Expect a concluding release from the MSC/VLR */
4498 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, omit));
4499
4500 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
4501 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4502
4503 setverdict(pass);
4504
4505 f_sgsap_bssmap_screening()
4506}
4507testcase TC_sgsap_mo_sms() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004508 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004509 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004510 f_init(1, true);
4511 pars := f_init_pars(11824, true);
4512 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mo_sms), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004513 vc_conn.done;
4514}
4515
4516/* Trigger sending of an MT sms via VTY but never respond to anything */
4517private function f_tc_sgsap_mt_sms_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4518 f_init_handler(pars, 170.0);
4519 f_sgs_perform_lu();
4520 f_sleep(1.0);
4521
4522 var SmsParameters spars := valueof(t_SmsPars);
4523 spars.tp.ud := 'C8329BFD064D9B53'O;
4524 var integer page_count := 0;
4525 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4526 var template PDU_SGsAP exp_pag_req := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, SMS_indicator, omit);
4527 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4528 exp_pag_req.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4529
4530 /* Trigger SMS via VTY */
4531 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
4532
Neels Hofmeyr16237742019-03-06 15:34:01 +01004533 /* Expect the MSC/VLR to page exactly once */
4534 SGsAP.receive(exp_pag_req);
Harald Welte4263c522018-12-06 11:56:27 +01004535
4536 /* Wait some time to make sure the MSC is not delivering any further
4537 * paging messages or anything else that could be unexpected. */
4538 timer T := 20.0;
4539 T.start
4540 alt {
4541 [] SGsAP.receive(exp_pag_req)
4542 {
4543 setverdict(fail, "paging seems not to stop!");
4544 mtc.stop;
4545 }
4546 [] SGsAP.receive {
4547 setverdict(fail, "unexpected SGsAP message received");
4548 self.stop;
4549 }
4550 [] T.timeout {
4551 setverdict(pass);
4552 }
4553 }
4554
4555 /* Even on a failed paging the SGs Association should stay intact */
4556 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4557
4558 /* Note: We do not execute f_sgsap_bssmap_screening() here since the
4559 * MSC/VLR would re-try to deliver the test SMS trigered above and
4560 * so the screening would fail. */
4561
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01004562 f_vty_sms_clear(hex2str(g_pars.imsi));
4563
Harald Welte4263c522018-12-06 11:56:27 +01004564 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " expire");
4565
4566 setverdict(pass);
Neels Hofmeyrb0f82342019-03-06 15:36:51 +01004567
4568 f_sgsap_bssmap_screening();
Harald Welte4263c522018-12-06 11:56:27 +01004569}
4570testcase TC_sgsap_mt_sms_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004571 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004572 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004573 f_init(1, true);
4574 pars := f_init_pars(11825, true);
4575 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004576 vc_conn.done;
4577}
4578
4579/* Trigger sending of an MT sms via VTY but reject the paging immediately */
4580private function f_tc_sgsap_mt_sms_and_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4581 f_init_handler(pars, 150.0);
4582 f_sgs_perform_lu();
4583 f_sleep(1.0);
4584
4585 var SmsParameters spars := valueof(t_SmsPars);
4586 spars.tp.ud := 'C8329BFD064D9B53'O;
4587 var integer page_count := 0;
4588 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4589 var template PDU_SGsAP exp_pag_req := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, SMS_indicator, omit);
4590 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4591 exp_pag_req.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4592
4593 /* Trigger SMS via VTY */
4594 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
4595
4596 /* Expect a paging request and reject it immediately */
4597 SGsAP.receive(exp_pag_req);
4598 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, IMSI_unknown));
4599
4600 /* The MSC/VLR should no longer try to page once the paging has been
4601 * rejected. Wait some time and check if there are no unexpected
4602 * messages on the SGs interface. */
4603 timer T := 20.0;
4604 T.start
4605 alt {
4606 [] SGsAP.receive(exp_pag_req)
4607 {
4608 setverdict(fail, "paging seems not to stop!");
4609 mtc.stop;
4610 }
4611 [] SGsAP.receive {
4612 setverdict(fail, "unexpected SGsAP message received");
4613 self.stop;
4614 }
4615 [] T.timeout {
4616 setverdict(pass);
4617 }
4618 }
4619
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01004620 f_vty_sms_clear(hex2str(g_pars.imsi));
4621
Harald Welte4263c522018-12-06 11:56:27 +01004622 /* A rejected paging with IMSI_unknown (see above) should always send
4623 * the SGs association to NULL. */
4624 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4625
4626 f_sgsap_bssmap_screening();
4627
Harald Welte4263c522018-12-06 11:56:27 +01004628 setverdict(pass);
4629}
4630testcase TC_sgsap_mt_sms_and_reject() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004631 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004632 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004633 f_init(1, true);
4634 pars := f_init_pars(11826, true);
4635 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms_and_reject), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004636 vc_conn.done;
4637}
4638
4639/* Perform an MT CSDB call including LU */
4640private function f_mt_lu_and_csfb_call(charstring id, BSC_ConnHdlrPars pars, boolean bssmap_lu) runs on BSC_ConnHdlr {
4641 f_init_handler(pars);
4642
4643 /* Be sure that the BSSMAP reset is done before we begin. */
4644 f_sleep(2.0);
4645
4646 /* Testcase variation: See what happens when we do a regular BSSMAP
4647 * LU first (this should not hurt in any way!) */
4648 if (bssmap_lu) {
4649 f_perform_lu();
4650 }
4651
4652 f_sgs_perform_lu();
4653 f_sleep(1.0);
4654
4655 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4656 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
4657 cpars.bss_rtp_port := 1110;
4658 cpars.mgcp_connection_id_bss := '10004'H;
4659 cpars.mgcp_connection_id_mss := '10005'H;
4660
4661 /* Note: This is an optional parameter. When the call-agent (MSC) does
4662 * supply a full endpoint name this setting will be overwritten. */
4663 cpars.mgcp_ep := "rtpbridge/1@mgw";
4664
4665 /* Initiate a call via MNCC interface */
4666 f_mt_call_initate(cpars);
4667
4668 /* Expect a paging request and respond accordingly with a service request */
4669 SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit));
4670 SGsAP.send(ts_SGsAP_SERVICE_REQ(pars.imsi, CS_call_indicator, EMM_CONNECTED));
4671
4672 /* Complete the call, hold it for some time and then tear it down */
4673 f_mt_call_complete(cpars);
4674 f_sleep(3.0);
Harald Welte4c422b72019-02-17 16:27:10 +01004675 f_call_hangup(cpars, true, is_csfb := true);
Harald Welte4263c522018-12-06 11:56:27 +01004676
4677 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
4678 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4679
4680 /* Finally simulate the return of the UE to the 4G network */
4681 SGsAP.send(ts_SGsAP_MO_CSFB_IND(pars.imsi));
4682
4683 /* Test for successful return by triggering a paging, when the paging
4684 * request is received via SGs, we can be sure that the MSC/VLR has
4685 * recognized that the UE is now back on 4G */
4686 f_sleep(1.0);
4687 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4688 alt {
4689 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
4690 setverdict(pass);
4691 }
4692 [] SGsAP.receive {
4693 setverdict(fail, "Received unexpected message on SGs");
4694 }
4695 }
4696
4697 f_sgsap_bssmap_screening();
4698
4699 setverdict(pass);
4700}
4701
4702/* Perform a regular BSSAP LU first, do a SGSAP LU and then make a CSFB call */
4703private function f_tc_bssap_lu_sgsap_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4704 f_mt_lu_and_csfb_call(id, pars, true);
4705}
4706testcase TC_bssap_lu_sgsap_lu_and_mt_call() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004707 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004708 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004709 f_init(1, true);
4710 pars := f_init_pars(118139, true);
Harald Welte4263c522018-12-06 11:56:27 +01004711
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004712 vc_conn := f_start_handler_with_pars(refers(f_tc_bssap_lu_sgsap_lu_and_mt_call), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004713 vc_conn.done;
4714}
4715
4716
4717/* Perform a SGSAP LU and then make a CSFB call */
4718private function f_tc_sgsap_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4719 f_mt_lu_and_csfb_call(id, pars, false);
4720}
4721testcase TC_sgsap_lu_and_mt_call() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004722 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004723 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004724 f_init(1, true);
4725 pars := f_init_pars(11827, true);
Harald Welte4263c522018-12-06 11:56:27 +01004726
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004727 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_and_mt_call), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004728 vc_conn.done;
4729}
4730
Philipp Maier628c0052019-04-09 17:36:57 +02004731/* Simulate an HLR/VLR failure */
4732private function f_tc_sgsap_vlr_failure(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4733 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4734 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4735
4736 var PDU_SGsAP lur;
4737
4738 f_init_handler(pars);
4739
4740 /* Attempt location update (which is expected to fail) */
4741 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
4742 ts_SGsAP_LAI('901'H, '70'H, 2342)));
4743 SGsAP.send(lur);
4744
4745 /* Respond to SGsAP-RESET-INDICATION from VLR */
4746 alt {
4747 [] SGsAP.receive(tr_SGsAP_RESET_IND_VLR(vlr_name)); {
4748 SGsAP.send(valueof(ts_SGsAP_RESET_ACK_MME(mme_name)));
4749 setverdict(pass);
4750 }
4751 [] SGsAP.receive {
4752 setverdict(fail, "Received unexpected message on SGs");
4753 }
4754 }
4755
4756 f_sleep(1.0);
4757 setverdict(pass);
4758}
4759testcase TC_sgsap_vlr_failure() runs on MTC_CT {
4760 var BSC_ConnHdlrPars pars;
4761 var BSC_ConnHdlr vc_conn;
4762 f_init(1, true, false);
4763 pars := f_init_pars(11811, true, false);
4764 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_vlr_failure), pars);
4765 vc_conn.done;
4766}
4767
Harald Welte4263c522018-12-06 11:56:27 +01004768/* SGs TODO:
4769 * LU attempt for IMSI without NAM_PS in HLR
4770 * LU attempt with AUTH FAIL due to invalid RES/SRES
4771 * LU attempt with no response from HLR (VLR should timeout + LU REJ)
4772 * LU attempt with new TMSI but without TMSI REALL CMPL baco to VLR
4773 * implicit IMSI detach from EPS
4774 * implicit IMSI detach from non-EPS
4775 * MM INFO
4776 *
4777 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01004778
4779control {
Philipp Maier328d1662018-03-07 10:40:27 +01004780 execute( TC_cr_before_reset() );
Harald Weltea49e36e2018-01-21 19:29:33 +01004781 execute( TC_lu_imsi_noauth_tmsi() );
Harald Welted2328a22018-01-27 14:27:16 +01004782 execute( TC_lu_imsi_noauth_notmsi() );
Harald Weltea49e36e2018-01-21 19:29:33 +01004783 execute( TC_lu_imsi_reject() );
4784 execute( TC_lu_imsi_timeout_gsup() );
Harald Welted2328a22018-01-27 14:27:16 +01004785 execute( TC_lu_imsi_auth_tmsi() );
Harald Welte8a397ae2019-04-21 22:03:37 +02004786 execute( TC_lu_imsi_auth3g_tmsi() );
Harald Welted2328a22018-01-27 14:27:16 +01004787 execute( TC_cmserv_imsi_unknown() );
Harald Welte2bb825f2018-01-22 11:31:18 +01004788 execute( TC_lu_and_mo_call() );
Harald Welte071ed732018-01-23 19:53:52 +01004789 execute( TC_lu_auth_sai_timeout() );
4790 execute( TC_lu_auth_sai_err() );
Harald Weltee1a2f3c2018-01-24 17:28:48 +01004791 execute( TC_lu_clear_request() );
4792 execute( TC_lu_disconnect() );
4793 execute( TC_lu_by_imei() );
4794 execute( TC_lu_by_tmsi_noauth_unknown() );
4795 execute( TC_imsi_detach_by_imsi() );
4796 execute( TC_imsi_detach_by_tmsi() );
4797 execute( TC_imsi_detach_by_imei() );
4798 execute( TC_emerg_call_imei_reject() );
4799 execute( TC_emerg_call_imsi() );
4800 execute( TC_cm_serv_req_vgcs_reject() );
4801 execute( TC_cm_serv_req_vbs_reject() );
4802 execute( TC_cm_serv_req_lcs_reject() );
Harald Welte0195ab12018-01-24 21:50:20 +01004803 execute( TC_cm_reest_req_reject() );
Harald Welte1af6ea82018-01-25 18:33:15 +01004804 execute( TC_lu_auth_2G_fail() );
4805 execute( TC_lu_imsi_auth_tmsi_encr_13_13() );
4806 execute( TC_cl3_no_payload() );
4807 execute( TC_cl3_rnd_payload() );
Harald Welte1852a842018-01-26 22:53:36 +01004808 execute( TC_establish_and_nothing() );
4809 execute( TC_mo_setup_and_nothing() );
4810 execute( TC_mo_crcx_ran_timeout() );
4811 execute( TC_mo_crcx_ran_reject() );
Harald Welted2328a22018-01-27 14:27:16 +01004812 execute( TC_mt_crcx_ran_reject() );
Daniel Willmann8b084372018-02-04 13:35:26 +01004813 execute( TC_mo_setup_and_dtmf_dup() );
Harald Welteaa54cf82018-01-30 08:15:32 +01004814 //execute( TC_mt_t310() );
Harald Welte167458a2018-01-27 15:58:16 +01004815 execute( TC_gsup_cancel() );
Harald Welte9de84792018-01-28 01:06:35 +01004816 execute( TC_lu_imsi_auth_tmsi_encr_1_13() );
4817 execute( TC_lu_imsi_auth_tmsi_encr_3_13() );
4818 execute( TC_lu_imsi_auth_tmsi_encr_3_1() );
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01004819 execute( TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() );
Harald Welte9de84792018-01-28 01:06:35 +01004820 execute( TC_lu_imsi_auth_tmsi_encr_13_2() );
4821 execute( TC_lu_imsi_auth_tmsi_encr_013_2() );
Philipp Maier94f3f1b2018-03-15 18:54:13 +01004822 execute( TC_mo_release_timeout() );
Philipp Maier2a98a732018-03-19 16:06:12 +01004823 execute( TC_lu_and_mt_call_no_dlcx_resp() );
Philipp Maier75932982018-03-27 14:52:35 +02004824 execute( TC_reset_two() );
Harald Welte33ec09b2018-02-10 15:34:46 +01004825
4826 execute( TC_lu_and_mt_call() );
4827
Harald Weltef45efeb2018-04-09 18:19:24 +02004828 execute( TC_lu_and_mo_sms() );
4829 execute( TC_lu_and_mt_sms() );
Philipp Maier3983e702018-11-22 19:01:33 +01004830 execute( TC_lu_and_mt_sms_paging_and_nothing() );
Harald Weltef640a012018-04-14 17:49:21 +02004831 execute( TC_smpp_mo_sms() );
4832 execute( TC_smpp_mt_sms() );
Harald Weltef45efeb2018-04-09 18:19:24 +02004833
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07004834 execute( TC_gsup_mo_sms() );
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07004835 execute( TC_gsup_mo_smma() );
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07004836 execute( TC_gsup_mt_sms_ack() );
4837 execute( TC_gsup_mt_sms_err() );
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07004838 execute( TC_gsup_mt_sms_rp_mr() );
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07004839 execute( TC_gsup_mo_mt_sms_rp_mr() );
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07004840
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07004841 execute( TC_lu_and_mo_ussd_single_request() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07004842 execute( TC_lu_and_mt_ussd_notification() );
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07004843 execute( TC_lu_and_mo_ussd_during_mt_call() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07004844 execute( TC_lu_and_mt_ussd_during_mt_call() );
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07004845 execute( TC_lu_and_mo_ussd_mo_release() );
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07004846 execute( TC_lu_and_ss_session_timeout() );
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07004847
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004848 execute( TC_cipher_complete_with_invalid_cipher() );
4849
Harald Welte4263c522018-12-06 11:56:27 +01004850 execute( TC_sgsap_reset() );
4851 execute( TC_sgsap_lu() );
4852 execute( TC_sgsap_lu_imsi_reject() );
4853 execute( TC_sgsap_lu_and_nothing() );
4854 execute( TC_sgsap_expl_imsi_det_eps() );
Philipp Maierfc19f172019-03-21 11:17:54 +01004855 execute( TC_sgsap_impl_imsi_det_eps() );
Harald Welte4263c522018-12-06 11:56:27 +01004856 execute( TC_sgsap_expl_imsi_det_noneps() );
Philipp Maier5d812702019-03-21 10:51:26 +01004857 execute( TC_sgsap_impl_imsi_det_noneps() );
Harald Welte4263c522018-12-06 11:56:27 +01004858 execute( TC_sgsap_paging_rej() );
4859 execute( TC_sgsap_paging_subscr_rej() );
4860 execute( TC_sgsap_paging_ue_unr() );
4861 execute( TC_sgsap_paging_and_nothing() );
4862 execute( TC_sgsap_paging_and_lu() );
4863 execute( TC_sgsap_mt_sms() );
4864 execute( TC_sgsap_mo_sms() );
4865 execute( TC_sgsap_mt_sms_and_nothing() );
4866 execute( TC_sgsap_mt_sms_and_reject() );
4867 execute( TC_sgsap_unexp_ud() );
4868 execute( TC_sgsap_unsol_ud() );
4869 execute( TC_bssap_lu_sgsap_lu_and_mt_call() );
4870 execute( TC_sgsap_lu_and_mt_call() );
Philipp Maier628c0052019-04-09 17:36:57 +02004871 execute( TC_sgsap_vlr_failure() );
Harald Welte4263c522018-12-06 11:56:27 +01004872
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01004873 /* Run this last: at the time of writing this test crashes the MSC */
4874 execute( TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() );
Philipp Maierdb7fb8d2019-02-11 10:50:13 +01004875 execute( TC_gsup_mt_multi_part_sms() );
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02004876 execute( TC_mo_cc_bssmap_clear() );
Harald Weltef6dd64d2017-11-19 12:09:51 +01004877}
4878
4879
4880}