blob: db96d608cdbb96b9aab7db4bbc30c3094d5a3bf0 [file] [log] [blame]
Harald Weltef6dd64d2017-11-19 12:09:51 +01001module MSC_Tests {
2
Harald Welte34b5a952019-05-27 11:54:11 +02003/* Osmocom MSC test suite in in TTCN-3
4 * (C) 2017-2019 Harald Welte <laforge@gnumonks.org>
5 * (C) 2018-2019 sysmocom - s.f.m.c. GmbH
6 * (C) 2018-2019 Vadim Yanitskiy <axilirator@gmail.com>
7 * All rights reserved.
8 *
9 * Released under the terms of GNU General Public License, Version 2 or
10 * (at your option) any later version.
11 *
12 * SPDX-License-Identifier: GPL-2.0-or-later
13 */
14
Harald Weltee13cfb22019-04-23 16:52:02 +020015friend module MSC_Tests_Iu;
16
Harald Weltef6dd64d2017-11-19 12:09:51 +010017import from General_Types all;
18import from Osmocom_Types all;
Pau Espin Pedrole979c402021-04-28 17:29:54 +020019import from GSM_Types all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010020
21import from M3UA_Types all;
22import from M3UA_Emulation all;
23
24import from MTP3asp_Types all;
25import from MTP3asp_PortType all;
26
27import from SCCPasp_Types all;
28import from SCCP_Types all;
29import from SCCP_Emulation all;
30
31import from SCTPasp_Types all;
32import from SCTPasp_PortType all;
33
Harald Weltea49e36e2018-01-21 19:29:33 +010034import from Osmocom_CTRL_Functions all;
35import from Osmocom_CTRL_Types all;
36import from Osmocom_CTRL_Adapter all;
37
Harald Welte3ca1c902018-01-24 18:51:27 +010038import from TELNETasp_PortType all;
39import from Osmocom_VTY_Functions all;
40
Harald Weltea49e36e2018-01-21 19:29:33 +010041import from MNCC_Emulation all;
Harald Welte2bb825f2018-01-22 11:31:18 +010042import from MNCC_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010043
Harald Welte4aa970c2018-01-26 10:38:09 +010044import from MGCP_Emulation all;
45import from MGCP_Types all;
46import from MGCP_Templates all;
47import from SDP_Types all;
48
Harald Weltea49e36e2018-01-21 19:29:33 +010049import from GSUP_Emulation all;
50import from GSUP_Types all;
51import from IPA_Emulation all;
52
Harald Weltef6dd64d2017-11-19 12:09:51 +010053import from BSSAP_Types all;
Harald Welte6811d102019-04-14 22:23:14 +020054import from RAN_Adapter all;
Harald Weltea49e36e2018-01-21 19:29:33 +010055import from BSSAP_CodecPort all;
56import from BSSMAP_Templates all;
Harald Welte6811d102019-04-14 22:23:14 +020057import from RAN_Emulation all;
Harald Weltea49e36e2018-01-21 19:29:33 +010058import from BSC_ConnectionHandler all;
Harald Weltee13cfb22019-04-23 16:52:02 +020059import from RANAP_Templates all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010060
Harald Welte4263c522018-12-06 11:56:27 +010061import from SGsAP_Templates all;
62import from SGsAP_Types all;
63import from SGsAP_Emulation all;
64
Harald Weltea49e36e2018-01-21 19:29:33 +010065import from MobileL3_Types all;
66import from MobileL3_CommonIE_Types all;
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +070067import from MobileL3_SMS_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010068import from L3_Templates all;
Harald Welte158a7ca2018-02-16 18:11:31 +010069import from L3_Common all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010070
Harald Weltef640a012018-04-14 17:49:21 +020071import from SMPP_Types all;
72import from SMPP_Templates all;
73import from SMPP_Emulation all;
74
Stefan Sperlingc307e682018-06-14 15:15:46 +020075import from SCCP_Templates all;
76
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070077import from SS_Types all;
78import from SS_Templates all;
79import from USSD_Helpers all;
Harald Welte4263c522018-12-06 11:56:27 +010080import from DNS_Helpers all;
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070081
Philipp Maier948747b2019-04-02 15:22:33 +020082import from TCCConversion_Functions all;
83
Harald Welte9b751a62019-04-14 17:39:29 +020084const integer NUM_BSC := 3;
Harald Weltef6dd64d2017-11-19 12:09:51 +010085
Harald Welte4263c522018-12-06 11:56:27 +010086/* Needed for SGsAP SMS */
87import from MobileL3_SMS_Types all;
88
Harald Weltea4ca4462018-02-09 00:17:14 +010089type component MTC_CT extends CTRL_Adapter_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +010090 var boolean g_initialized := false;
Harald Weltea49e36e2018-01-21 19:29:33 +010091
Harald Welte6811d102019-04-14 22:23:14 +020092 var RAN_Adapter g_bssap[NUM_BSC];
Harald Weltea4ca4462018-02-09 00:17:14 +010093
Harald Weltea49e36e2018-01-21 19:29:33 +010094 /* no 'adapter_CT' for MNCC or GSUP */
95 var MNCC_Emulation_CT vc_MNCC;
Harald Welte4aa970c2018-01-26 10:38:09 +010096 var MGCP_Emulation_CT vc_MGCP;
Harald Weltea49e36e2018-01-21 19:29:33 +010097 var GSUP_Emulation_CT vc_GSUP;
98 var IPA_Emulation_CT vc_GSUP_IPA;
Harald Weltef640a012018-04-14 17:49:21 +020099 var SMPP_Emulation_CT vc_SMPP;
Harald Welte4263c522018-12-06 11:56:27 +0100100 var SGsAP_Emulation_CT vc_SGsAP;
Harald Weltea49e36e2018-01-21 19:29:33 +0100101
102 /* only to get events from IPA underneath GSUP */
103 port IPA_CTRL_PT GSUP_IPA_EVENT;
Harald Welte3ca1c902018-01-24 18:51:27 +0100104 /* VTY to MSC */
105 port TELNETasp_PT MSCVTY;
Philipp Maier328d1662018-03-07 10:40:27 +0100106
107 /* A port to directly send BSSAP messages. This port is used for
108 * tests that require low level access to sen arbitrary BSSAP
109 * messages. Run f_init_bssap_direct() to connect and initialize */
110 port BSSAP_CODEC_PT BSSAP_DIRECT;
111
112 /* When BSSAP messages are directly sent, then the connection
113 * handler is not active, which means that also no guard timer is
114 * set up. The following timer will serve as a replacement */
115 timer Tguard_direct := 60.0;
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100116
117 /* Configure T(tias) over VTY, seconds */
118 var integer g_msc_sccp_timer_ias := 7 * 60;
119 /* Configure T(tiar) over VTY, seconds */
120 var integer g_msc_sccp_timer_iar := 15 * 60;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100121}
122
123modulepar {
Harald Weltea49e36e2018-01-21 19:29:33 +0100124 /* remote parameters of IUT */
125 charstring mp_msc_ip := "127.0.0.1";
126 integer mp_msc_ctrl_port := 4255;
127 integer mp_msc_vty_port := 4254;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100128
Harald Weltea49e36e2018-01-21 19:29:33 +0100129 /* local parameters of emulated HLR */
Philipp Maier9b690e42018-12-21 11:50:03 +0100130 boolean mp_mm_info := false;
Harald Weltea49e36e2018-01-21 19:29:33 +0100131 charstring mp_hlr_ip := "127.0.0.1";
132 integer mp_hlr_port := 4222;
Harald Welte6126fb02018-01-27 20:08:24 +0100133 charstring mp_mgw_ip := "127.0.0.1";
134 integer mp_mgw_port := 2427;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100135
Harald Weltea49e36e2018-01-21 19:29:33 +0100136 charstring mp_msc_mncc := "/tmp/mncc";
Harald Weltea4ca4462018-02-09 00:17:14 +0100137
Harald Weltef640a012018-04-14 17:49:21 +0200138 integer mp_msc_smpp_port := 2775;
139 charstring mp_smpp_system_id := "msc_tester";
140 charstring mp_smpp_password := "osmocom1";
Harald Welte4263c522018-12-06 11:56:27 +0100141 charstring mp_mme_name := "mmec01.mmegi0001.mme.epc.mnc070.mcc901.3gppnetwork.org";
142 charstring mp_vlr_name := "vlr.example.net";
Harald Weltef640a012018-04-14 17:49:21 +0200143
Harald Welte6811d102019-04-14 22:23:14 +0200144 RAN_Configurations mp_bssap_cfg := {
Philipp Maier75932982018-03-27 14:52:35 +0200145 {
146 sccp_service_type := "mtp3_itu",
147 sctp_addr := { 23905, "127.0.0.1", 2905, "127.0.0.1" },
148 own_pc := 185,
149 own_ssn := 254,
150 peer_pc := 187,
151 peer_ssn := 254,
152 sio := '83'O,
153 rctx := 0
154 },
155 {
156 sccp_service_type := "mtp3_itu",
157 sctp_addr := { 23906, "127.0.0.1", 2905, "127.0.0.1" },
158 own_pc := 186,
159 own_ssn := 254,
160 peer_pc := 187,
161 peer_ssn := 254,
162 sio := '83'O,
163 rctx := 1
164 }
Harald Weltea4ca4462018-02-09 00:17:14 +0100165 };
Harald Weltef6dd64d2017-11-19 12:09:51 +0100166}
167
Philipp Maier328d1662018-03-07 10:40:27 +0100168/* altstep for the global guard timer (only used when BSSAP_DIRECT
169 * is used for communication */
170private altstep as_Tguard_direct() runs on MTC_CT {
171 [] Tguard_direct.timeout {
172 setverdict(fail, "Tguard timeout");
Daniel Willmannafce8662018-07-06 23:11:32 +0200173 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +0100174 }
175}
Harald Weltef6dd64d2017-11-19 12:09:51 +0100176
Neels Hofmeyr2ca1ab42019-03-08 03:45:43 +0100177private altstep as_optional_cc_rel(CallParameters cpars, boolean respond := false) runs on BSC_ConnHdlr {
178 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id))) {
179 if (respond) {
180 var BIT1 tid_remote := '1'B;
181 if (cpars.mo_call) {
182 tid_remote := '0'B;
183 }
184 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id, tid_remote)));
185 }
186 }
Neels Hofmeyrde76f052019-02-26 05:02:46 +0100187}
188
Harald Weltef640a012018-04-14 17:49:21 +0200189function f_init_smpp(charstring id) runs on MTC_CT {
190 id := id & "-SMPP";
191 var EsmePars pars := {
192 mode := MODE_TRANSCEIVER,
193 bind := {
194 system_id := mp_smpp_system_id,
195 password := mp_smpp_password,
196 system_type := "MSC_Tests",
197 interface_version := hex2int('34'H),
198 addr_ton := unknown,
199 addr_npi := unknown,
200 address_range := ""
201 },
202 esme_role := true
203 }
204
205 vc_SMPP := SMPP_Emulation_CT.create(id);
206 map(vc_SMPP:SMPP_PORT, system:SMPP_PORT);
Harald Welte4698a4c2020-08-18 22:57:52 +0200207 vc_SMPP.start(SMPP_Emulation.main_client(pars, mp_msc_ip, mp_msc_smpp_port, "", 0));
Harald Weltef640a012018-04-14 17:49:21 +0200208}
209
210
Harald Weltea49e36e2018-01-21 19:29:33 +0100211function f_init_mncc(charstring id) runs on MTC_CT {
212 id := id & "-MNCC";
213 var MnccOps ops := {
214 create_cb := refers(MNCC_Emulation.ExpectedCreateCallback),
215 unitdata_cb := refers(MNCC_Emulation.DummyUnitdataCallback)
216 }
217
218 vc_MNCC := MNCC_Emulation_CT.create(id);
219 map(vc_MNCC:MNCC, system:MNCC_CODEC_PT);
220 vc_MNCC.start(MNCC_Emulation.main(ops, id, mp_msc_mncc));
Harald Weltef6dd64d2017-11-19 12:09:51 +0100221}
222
Harald Welte4aa970c2018-01-26 10:38:09 +0100223function f_init_mgcp(charstring id) runs on MTC_CT {
224 id := id & "-MGCP";
225 var MGCPOps ops := {
226 create_cb := refers(MGCP_Emulation.ExpectedCreateCallback),
227 unitdata_cb := refers(MGCP_Emulation.DummyUnitdataCallback)
228 }
229 var MGCP_conn_parameters pars := {
Harald Welte6126fb02018-01-27 20:08:24 +0100230 callagent_ip := mp_msc_ip,
Harald Welte4aa970c2018-01-26 10:38:09 +0100231 callagent_udp_port := -1,
Harald Welte6126fb02018-01-27 20:08:24 +0100232 mgw_ip := mp_mgw_ip,
Pau Espin Pedrol1a026a52019-06-18 17:21:52 +0200233 mgw_udp_port := mp_mgw_port,
234 multi_conn_mode := false
Harald Welte4aa970c2018-01-26 10:38:09 +0100235 }
236
237 vc_MGCP := MGCP_Emulation_CT.create(id);
238 map(vc_MGCP:MGCP, system:MGCP_CODEC_PT);
239 vc_MGCP.start(MGCP_Emulation.main(ops, pars, id));
240}
241
Philipp Maierc09a1312019-04-09 16:05:26 +0200242function ForwardUnitdataCallback(PDU_SGsAP msg)
243runs on SGsAP_Emulation_CT return template PDU_SGsAP {
244 SGsAP_CLIENT.send(msg);
245 return omit;
246}
247
Harald Welte4263c522018-12-06 11:56:27 +0100248function f_init_sgsap(charstring id) runs on MTC_CT {
249 id := id & "-SGsAP";
250 var SGsAPOps ops := {
251 create_cb := refers(SGsAP_Emulation.ExpectedCreateCallback),
Philipp Maierc09a1312019-04-09 16:05:26 +0200252 unitdata_cb := refers(ForwardUnitdataCallback)
Harald Welte4263c522018-12-06 11:56:27 +0100253 }
254 var SGsAP_conn_parameters pars := {
255 remote_ip := mp_msc_ip,
256 remote_sctp_port := 29118,
257 local_ip := "",
258 local_sctp_port := -1
259 }
260
261 vc_SGsAP := SGsAP_Emulation_CT.create(id);
262 map(vc_SGsAP:SGsAP, system:SGsAP_CODEC_PT);
263 vc_SGsAP.start(SGsAP_Emulation.main(ops, pars, id));
264}
265
266
Harald Weltea49e36e2018-01-21 19:29:33 +0100267function f_init_gsup(charstring id) runs on MTC_CT {
268 id := id & "-GSUP";
269 var GsupOps ops := {
270 create_cb := refers(GSUP_Emulation.ExpectedCreateCallback)
271 }
272
273 vc_GSUP_IPA := IPA_Emulation_CT.create(id & "-IPA");
274 vc_GSUP := GSUP_Emulation_CT.create(id);
275
276 map(vc_GSUP_IPA:IPA_PORT, system:IPA_CODEC_PT);
277 connect(vc_GSUP:GSUP, vc_GSUP_IPA:IPA_GSUP_PORT);
278 /* we use this hack to get events like ASP_IPA_EVENT_UP */
279 connect(vc_GSUP_IPA:IPA_CTRL_PORT, self:GSUP_IPA_EVENT);
280
281 vc_GSUP.start(GSUP_Emulation.main(ops, id));
282 vc_GSUP_IPA.start(IPA_Emulation.main_server(mp_hlr_ip, mp_hlr_port));
283
284 /* wait for incoming connection to GSUP port before proceeding */
285 timer T := 10.0;
286 T.start;
287 alt {
Vadim Yanitskiy61564be2020-05-18 20:44:14 +0700288 [] GSUP_IPA_EVENT.receive(tr_ASP_IPA_EV(ASP_IPA_EVENT_UP)) { }
Harald Weltea49e36e2018-01-21 19:29:33 +0100289 [] T.timeout {
Harald Welte458fd372018-03-21 11:26:23 +0100290 setverdict(fail, "No connection to GSUP Port");
Daniel Willmannafce8662018-07-06 23:11:32 +0200291 mtc.stop
Harald Weltea49e36e2018-01-21 19:29:33 +0100292 }
293 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100294}
295
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200296function f_init(integer num_bsc := 1, boolean sgsap := false, boolean gsup := true, boolean osmux := false) runs on MTC_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +0100297
298 if (g_initialized == true) {
299 return;
300 }
301 g_initialized := true;
302
Philipp Maier75932982018-03-27 14:52:35 +0200303 if (num_bsc > NUM_BSC) {
Daniel Willmannafce8662018-07-06 23:11:32 +0200304 testcase.stop("excess number of BSC instances requested");
Philipp Maier75932982018-03-27 14:52:35 +0200305 }
306
307 for (var integer i := 0; i < num_bsc; i := i + 1) {
308 if (isbound(mp_bssap_cfg[i])) {
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200309 var RanOps ranops := BSC_RanOps;
310 ranops.use_osmux := osmux;
311 f_ran_adapter_init(g_bssap[i], mp_bssap_cfg[i], "MSC_Test_" & int2str(i), ranops);
Harald Welte3ca0ce12019-04-23 17:18:48 +0200312 f_ran_adapter_start(g_bssap[i]);
Philipp Maier75932982018-03-27 14:52:35 +0200313 } else {
Daniel Willmannafce8662018-07-06 23:11:32 +0200314 testcase.stop("missing BSSAP configuration");
Philipp Maier75932982018-03-27 14:52:35 +0200315 }
316 }
317
Pau Espin Pedrol9a5b8ff2021-01-04 19:01:31 +0100318 f_ipa_ctrl_start_client(mp_msc_ip, mp_msc_ctrl_port);
Harald Weltea49e36e2018-01-21 19:29:33 +0100319 f_init_mncc("MSC_Test");
Harald Welte4aa970c2018-01-26 10:38:09 +0100320 f_init_mgcp("MSC_Test");
Philipp Maierc09a1312019-04-09 16:05:26 +0200321
322 if (gsup == true) {
323 f_init_gsup("MSC_Test");
324 }
Harald Weltef640a012018-04-14 17:49:21 +0200325 f_init_smpp("MSC_Test");
Philipp Maier57865482019-01-07 18:33:13 +0100326
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100327 if (sgsap == true) {
Philipp Maier57865482019-01-07 18:33:13 +0100328 f_init_sgsap("MSC_Test");
329 }
Harald Welte3ca1c902018-01-24 18:51:27 +0100330
331 map(self:MSCVTY, system:MSCVTY);
332 f_vty_set_prompts(MSCVTY);
333 f_vty_transceive(MSCVTY, "enable");
Harald Welteb14c77a2018-01-25 17:25:44 +0100334
335 /* set some defaults */
336 f_vty_config(MSCVTY, "network", "authentication optional");
337 f_vty_config(MSCVTY, "msc", "assign-tmsi");
Oliver Smith1d118ff2019-07-03 10:57:35 +0200338 f_vty_config(MSCVTY, "msc", "check-imei-rqd 0");
Harald Welteb14c77a2018-01-25 17:25:44 +0100339 f_vty_config(MSCVTY, "network", "encryption a5 0");
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100340 f_vty_config(MSCVTY, "cs7 instance 0", "sccp-timer ias " & int2str(g_msc_sccp_timer_ias));
341 f_vty_config(MSCVTY, "cs7 instance 0", "sccp-timer iar " & int2str(g_msc_sccp_timer_iar));
Pau Espin Pedrol9a732a42020-09-15 15:56:33 +0200342 if (osmux) {
343 f_vty_config(MSCVTY, "msc", "osmux on");
344 } else {
345 f_vty_config(MSCVTY, "msc", "osmux off");
Pau Espin Pedrol3dd33bc2019-05-31 17:51:20 +0200346 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100347}
348
Philipp Maier328d1662018-03-07 10:40:27 +0100349/* Initialize for a direct connection to BSSAP. This function is an alternative
350 * to f_init() when the high level functions of the BSC_ConnectionHandler are
351 * not needed. */
352function f_init_bssap_direct() runs on MTC_CT {
Harald Welte3ca0ce12019-04-23 17:18:48 +0200353 f_ran_adapter_init(g_bssap[0], mp_bssap_cfg[0], "MSC_Test", omit);
Philipp Maier75932982018-03-27 14:52:35 +0200354 connect(g_bssap[0].vc_SCCP:SCCP_SP_PORT, self:BSSAP_DIRECT);
Philipp Maier328d1662018-03-07 10:40:27 +0100355
356 /* Start guard timer and activate it as default */
357 Tguard_direct.start
358 activate(as_Tguard_direct());
359}
360
Harald Weltea49e36e2018-01-21 19:29:33 +0100361type function void_fn(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100362
Harald Weltea49e36e2018-01-21 19:29:33 +0100363/* FIXME: move into BSC_ConnectionHandler? */
Harald Welte9b751a62019-04-14 17:39:29 +0200364function f_init_pars(integer imsi_suffix, boolean sgsap := false, boolean gsup := true, integer ran_idx := 0,
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200365 boolean ran_is_geran := true, boolean use_osmux := false, OCT4 gsup_sid := '20000101'O,
366 boolean verify_cell_id := true)
Harald Weltef9abf8d2019-04-21 13:07:17 +0200367runs on MTC_CT return BSC_ConnHdlrPars {
Harald Weltede371492018-01-27 23:44:41 +0100368 var BSC_ConnHdlrNetworkPars net_pars := {
369 kc_support := '0A'O, /* A5/1 and A5/3 enabled */
370 expect_tmsi := true,
371 expect_auth := false,
Oliver Smith1d118ff2019-07-03 10:57:35 +0200372 expect_ciph := false,
373 expect_imei := false,
374 expect_imei_early := false,
375 check_imei_result := OSMO_GSUP_IMEI_RESULT_ACK,
376 check_imei_error := false
Harald Weltede371492018-01-27 23:44:41 +0100377 };
Harald Weltea49e36e2018-01-21 19:29:33 +0100378 var BSC_ConnHdlrPars pars := {
Harald Weltef9abf8d2019-04-21 13:07:17 +0200379 sccp_addr_own := g_bssap[ran_idx].sccp_addr_own,
380 sccp_addr_peer := g_bssap[ran_idx].sccp_addr_peer,
Harald Welteedbab812018-03-18 16:02:25 +0100381 cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42)),
Harald Welte81b7f9d2018-01-24 19:06:24 +0100382 imei := f_gen_imei(imsi_suffix),
383 imsi := f_gen_imsi(imsi_suffix),
384 msisdn := f_gen_msisdn(imsi_suffix),
Harald Welte256571e2018-01-24 18:47:19 +0100385 tmsi := omit,
Harald Welte9de84792018-01-28 01:06:35 +0100386 cm1 := valueof(ts_CM1),
Harald Welte82600572018-01-21 20:54:08 +0100387 cm2 := valueof(ts_CM2_default),
Harald Welte16114282018-01-24 22:41:21 +0100388 cm3 := omit,
Harald Weltede371492018-01-27 23:44:41 +0100389 vec := omit,
Neels Hofmeyrb00c5b02021-06-23 20:05:25 +0200390 vec_keep := false,
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100391 net := net_pars,
Philipp Maieraeb29a82018-11-08 17:40:53 +0100392 send_early_cm := true,
393 ipa_ctrl_ip := mp_msc_ip,
394 ipa_ctrl_port := mp_msc_ctrl_port,
Philipp Maier9b690e42018-12-21 11:50:03 +0100395 ipa_ctrl_enable := true,
Philipp Maier57865482019-01-07 18:33:13 +0100396 mm_info := mp_mm_info,
Philipp Maierc09a1312019-04-09 16:05:26 +0200397 sgsap_enable := sgsap,
Harald Weltef9abf8d2019-04-21 13:07:17 +0200398 gsup_enable := gsup,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +0100399 gsup_sid := gsup_sid,
Harald Weltec1f937a2019-04-21 21:19:23 +0200400 ran_idx := ran_idx,
Harald Welte9b751a62019-04-14 17:39:29 +0200401 use_umts_aka := false,
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200402 ran_is_geran := ran_is_geran,
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200403 use_osmux := use_osmux,
Pau Espin Pedrol833174e2020-09-03 16:46:02 +0200404 use_ipv6 := false,
Pau Espin Pedrole979c402021-04-28 17:29:54 +0200405 verify_cell_id := verify_cell_id,
406 common_id_last_eutran_plmn := omit
Harald Weltea49e36e2018-01-21 19:29:33 +0100407 };
Harald Weltee13cfb22019-04-23 16:52:02 +0200408 if (not ran_is_geran) {
409 pars.use_umts_aka := true;
410 pars.net.expect_auth := true;
411 }
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100412 return pars;
413}
414
Neels Hofmeyre1a1b632021-07-28 18:05:43 +0200415function f_start_handler_create(BSC_ConnHdlrPars pars) runs on MTC_CT return BSC_ConnHdlr {
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100416 var BSC_ConnHdlr vc_conn;
Neels Hofmeyr60122f82021-07-28 17:59:38 +0200417 var charstring id := testcasename() & int2str(pars.ran_idx);
Harald Weltea49e36e2018-01-21 19:29:33 +0100418
419 vc_conn := BSC_ConnHdlr.create(id);
Neels Hofmeyr60122f82021-07-28 17:59:38 +0200420
Harald Weltea49e36e2018-01-21 19:29:33 +0100421 /* BSSMAP part / A interface */
Neels Hofmeyr60122f82021-07-28 17:59:38 +0200422 connect(vc_conn:BSSAP, g_bssap[pars.ran_idx].vc_RAN:CLIENT);
423 connect(vc_conn:BSSAP_PROC, g_bssap[pars.ran_idx].vc_RAN:PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100424 /* MNCC part */
425 connect(vc_conn:MNCC, vc_MNCC:MNCC_CLIENT);
426 connect(vc_conn:MNCC_PROC, vc_MNCC:MNCC_PROC);
Harald Welte4aa970c2018-01-26 10:38:09 +0100427 /* MGCP part */
428 connect(vc_conn:MGCP, vc_MGCP:MGCP_CLIENT);
429 connect(vc_conn:MGCP_PROC, vc_MGCP:MGCP_PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100430 /* GSUP part */
Philipp Maierc09a1312019-04-09 16:05:26 +0200431 if (pars.gsup_enable == true) {
432 connect(vc_conn:GSUP, vc_GSUP:GSUP_CLIENT);
433 connect(vc_conn:GSUP_PROC, vc_GSUP:GSUP_PROC);
434 }
Harald Weltef640a012018-04-14 17:49:21 +0200435 /* SMPP part */
436 connect(vc_conn:SMPP, vc_SMPP:SMPP_CLIENT);
437 connect(vc_conn:SMPP_PROC, vc_SMPP:SMPP_PROC);
Harald Welte4263c522018-12-06 11:56:27 +0100438 /* SGs part */
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100439 if (pars.sgsap_enable == true) {
Philipp Maier57865482019-01-07 18:33:13 +0100440 connect(vc_conn:SGsAP, vc_SGsAP:SGsAP_CLIENT);
441 connect(vc_conn:SGsAP_PROC, vc_SGsAP:SGsAP_PROC);
442 }
Neels Hofmeyre1a1b632021-07-28 18:05:43 +0200443 return vc_conn;
444}
Harald Weltea49e36e2018-01-21 19:29:33 +0100445
Neels Hofmeyre1a1b632021-07-28 18:05:43 +0200446function f_start_handler_run(BSC_ConnHdlr vc_conn, void_fn fn, BSC_ConnHdlrPars pars) runs on MTC_CT {
447 var charstring id := testcasename() & int2str(pars.ran_idx);
Harald Weltea10db902018-01-27 12:44:49 +0100448 /* We cannot use vc_conn.start(f_init_handler(fn, id, pars)); as we cannot have
449 * a stand-alone 'derefers()' call, see https://www.eclipse.org/forums/index.php/t/1091364/ */
Harald Weltea49e36e2018-01-21 19:29:33 +0100450 vc_conn.start(derefers(fn)(id, pars));
Neels Hofmeyre1a1b632021-07-28 18:05:43 +0200451}
452
453function f_start_handler_with_pars(void_fn fn, BSC_ConnHdlrPars pars) runs on MTC_CT return BSC_ConnHdlr {
454 var BSC_ConnHdlr vc_conn;
455 vc_conn := f_start_handler_create(pars);
456 f_start_handler_run(vc_conn, fn, pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100457 return vc_conn;
458}
459
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200460function f_start_handler(void_fn fn, integer imsi_suffix, integer ran_idx := 0, boolean ran_is_geran := true, boolean use_osmux := false,
461 boolean verify_cell_id := true)
Harald Welte9b751a62019-04-14 17:39:29 +0200462runs on MTC_CT return BSC_ConnHdlr {
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200463 return f_start_handler_with_pars(fn, f_init_pars(imsi_suffix, ran_idx := ran_idx, ran_is_geran := ran_is_geran, use_osmux := use_osmux, verify_cell_id := verify_cell_id));
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100464}
465
Harald Weltea49e36e2018-01-21 19:29:33 +0100466private function f_tc_lu_imsi_noauth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100467 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100468 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100469}
Harald Weltea49e36e2018-01-21 19:29:33 +0100470testcase TC_lu_imsi_noauth_tmsi() runs on MTC_CT {
471 var BSC_ConnHdlr vc_conn;
472 f_init();
473
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100474 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi), 1);
Harald Weltea49e36e2018-01-21 19:29:33 +0100475 vc_conn.done;
476}
477
478private function f_tc_lu_imsi_noauth_notmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100479 pars.net.expect_tmsi := false;
Harald Weltea10db902018-01-27 12:44:49 +0100480 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100481 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100482}
Harald Weltea49e36e2018-01-21 19:29:33 +0100483testcase TC_lu_imsi_noauth_notmsi() runs on MTC_CT {
484 var BSC_ConnHdlr vc_conn;
485 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100486 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
Harald Weltea49e36e2018-01-21 19:29:33 +0100487
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100488 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi), 2);
Harald Weltea49e36e2018-01-21 19:29:33 +0100489 vc_conn.done;
490}
491
492/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
Harald Weltee13cfb22019-04-23 16:52:02 +0200493friend function f_tc_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100494 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100495 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
496
497 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +0200498 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyrd076c522019-11-28 01:00:52 +0100499 f_mm_common();
Harald Weltea49e36e2018-01-21 19:29:33 +0100500 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
501 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
502 alt {
Harald Welte5946b332018-03-18 23:32:21 +0100503 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej(int2oct(23,1)))) {
504 f_expect_clear();
505 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100506 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
507 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200508 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100509 }
510 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100511}
512testcase TC_lu_imsi_reject() runs on MTC_CT {
513 var BSC_ConnHdlr vc_conn;
514 f_init();
515
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200516 vc_conn := f_start_handler(refers(f_tc_lu_imsi_reject), 3, verify_cell_id := false);
Harald Weltea49e36e2018-01-21 19:29:33 +0100517 vc_conn.done;
518}
519
Harald Weltee13cfb22019-04-23 16:52:02 +0200520
521
Harald Weltea49e36e2018-01-21 19:29:33 +0100522/* Do LU by IMSI, timeout on GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +0200523friend function f_tc_lu_imsi_timeout_gsup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100524 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100525 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
526
527 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +0200528 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyrd076c522019-11-28 01:00:52 +0100529 f_mm_common();
Harald Weltea49e36e2018-01-21 19:29:33 +0100530 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
531 /* Normally the HLR would need to respond here, but we decide to force a timeout here */
532 alt {
533 /* FIXME: Expect specific reject cause */
Harald Welte5946b332018-03-18 23:32:21 +0100534 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
535 f_expect_clear();
536 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100537 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
538 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200539 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100540 }
541 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100542}
543testcase TC_lu_imsi_timeout_gsup() runs on MTC_CT {
544 var BSC_ConnHdlr vc_conn;
545 f_init();
546
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200547 vc_conn := f_start_handler(refers(f_tc_lu_imsi_timeout_gsup), 4, verify_cell_id := false);
Harald Weltea49e36e2018-01-21 19:29:33 +0100548 vc_conn.done;
549}
550
Harald Weltee13cfb22019-04-23 16:52:02 +0200551
Harald Welte7b1b2812018-01-22 21:23:06 +0100552private function f_tc_lu_imsi_auth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100553 pars.net.expect_auth := true;
Harald Weltea10db902018-01-27 12:44:49 +0100554 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100555 f_perform_lu();
Harald Welte7b1b2812018-01-22 21:23:06 +0100556}
557testcase TC_lu_imsi_auth_tmsi() runs on MTC_CT {
558 var BSC_ConnHdlr vc_conn;
559 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100560 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte7b1b2812018-01-22 21:23:06 +0100561
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100562 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi), 5);
Harald Welte7b1b2812018-01-22 21:23:06 +0100563 vc_conn.done;
564}
565
Harald Weltee13cfb22019-04-23 16:52:02 +0200566
567friend function f_tc_lu_imsi_auth3g_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte8a397ae2019-04-21 22:03:37 +0200568 pars.net.expect_auth := true;
569 pars.use_umts_aka := true;
570 f_init_handler(pars);
571 f_perform_lu();
572}
573testcase TC_lu_imsi_auth3g_tmsi() runs on MTC_CT {
574 var BSC_ConnHdlr vc_conn;
575 f_init();
576 f_vty_config(MSCVTY, "network", "authentication required");
577
578 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi), 1005);
579 vc_conn.done;
580}
Harald Weltea49e36e2018-01-21 19:29:33 +0100581
Pau Espin Pedrold3d54a92019-12-17 17:02:54 +0100582/* Proceed with LU but never receive an TMSI Realloc from MS after LU Accept (OS#4337).
583 * TS 24.008 sec 4.3.1.5 states MSC should simply release all MM connections.
584 */
585friend function f_tc_lu_imsi_timeout_tmsi_realloc(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
586
587 f_init_handler(pars);
588
589 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
590 var PDU_DTAP_MT dtap_mt;
591
592 /* tell GSUP dispatcher to send this IMSI to us */
593 f_create_gsup_expect(hex2str(g_pars.imsi));
594
595 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
596 if (g_pars.ran_is_geran) {
597 f_bssap_compl_l3(l3_lu);
598 if (g_pars.send_early_cm) {
599 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
600 }
601 } else {
602 f_ranap_initial_ue(l3_lu);
603 }
604
605 f_mm_imei_early();
606 f_mm_common();
607 f_msc_lu_hlr();
608 f_mm_imei();
609
610 alt {
611 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) -> value dtap_mt {}
612 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
613 setverdict(fail, "Expected LU ACK, but received LU REJ");
614 mtc.stop;
615 }
616 }
617
618 /* currently (due to bug OS#4337), an extra LU reject is received before
619 terminating the connection. Enabling following line makes the test
620 pass: */
621 //f_expect_lu_reject('16'O); /* Cause: congestion */
622
623 /* f_expect_lu_reject() already waits for T"-1" (X1, 5 seconds), but give some
624 extra time to avoid race conditons... */
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200625 f_expect_clear(7.0, verify_vlr_cell_id := false);
Pau Espin Pedrold3d54a92019-12-17 17:02:54 +0100626
627 setverdict(pass);
628}
629testcase TC_lu_imsi_timeout_tmsi_realloc() runs on MTC_CT {
630 var BSC_ConnHdlr vc_conn;
631 f_init();
632
633 vc_conn := f_start_handler(refers(f_tc_lu_imsi_timeout_tmsi_realloc), 5);
634 vc_conn.done;
635}
636
Harald Weltee13cfb22019-04-23 16:52:02 +0200637
Harald Weltea49e36e2018-01-21 19:29:33 +0100638/* Send CM SERVICE REQ for IMSI that has never performed LU before */
Harald Weltee13cfb22019-04-23 16:52:02 +0200639friend function f_tc_cmserv_imsi_unknown(charstring id, BSC_ConnHdlrPars pars)
Harald Weltea49e36e2018-01-21 19:29:33 +0100640runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100641 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100642
643 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welteedbab812018-03-18 16:02:25 +0100644 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
Harald Welte6ed6bf92018-01-24 21:09:15 +0100645 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
Harald Weltea49e36e2018-01-21 19:29:33 +0100646
647 f_create_gsup_expect(hex2str(g_pars.imsi));
648
649 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200650 f_cl3_or_initial_ue(l3_info);
Harald Welteb7817992019-05-09 13:15:39 +0200651 f_mm_auth();
Harald Weltea49e36e2018-01-21 19:29:33 +0100652
653 timer T := 10.0;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100654 T.start;
655 alt {
Harald Weltea49e36e2018-01-21 19:29:33 +0100656 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
657 //[] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_ACC)) { }
Daniel Willmannafce8662018-07-06 23:11:32 +0200658 [] BSSAP.receive {
659 setverdict(fail, "Received unexpected BSSAP");
660 mtc.stop;
661 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100662 [] GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi)) {
663 setverdict(fail, "Unexpected GSUP UL REQ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200664 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100665 }
Daniel Willmannafce8662018-07-06 23:11:32 +0200666 [] T.timeout {
Neels Hofmeyrf1c3c212020-08-19 13:15:32 +0000667 setverdict(fail, "Timeout waiting for CM SERV REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200668 mtc.stop;
669 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100670 }
671
Harald Welte1ddc7162018-01-27 14:25:46 +0100672 f_expect_clear();
Harald Weltef6dd64d2017-11-19 12:09:51 +0100673}
Harald Weltea49e36e2018-01-21 19:29:33 +0100674testcase TC_cmserv_imsi_unknown() runs on MTC_CT {
675 var BSC_ConnHdlr vc_conn;
676 f_init();
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200677 vc_conn := f_start_handler(refers(f_tc_cmserv_imsi_unknown), 6, verify_cell_id := false);
Harald Weltea49e36e2018-01-21 19:29:33 +0100678 vc_conn.done;
679}
680
Harald Weltee13cfb22019-04-23 16:52:02 +0200681
Neels Hofmeyr13737fb2020-08-19 13:16:14 +0000682/* Send CM SERVICE REQ for TMSI that has never performed LU before */
683friend function f_tc_cmserv_tmsi_unknown(charstring id, BSC_ConnHdlrPars pars)
684runs on BSC_ConnHdlr {
685 f_init_handler(pars);
686
687 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV('57111111'O));
688 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
689 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
690
691 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
692 f_cl3_or_initial_ue(l3_info);
693 f_mm_auth();
694
695 timer T := 10.0;
696 T.start;
697 alt {
698 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
699 [] BSSAP.receive {
700 setverdict(fail, "Received unexpected BSSAP");
701 mtc.stop;
702 }
703 [] T.timeout {
704 setverdict(fail, "Timeout waiting for CM SERV REJ");
705 mtc.stop;
706 }
707 }
708
709 f_expect_clear();
710}
711testcase TC_cmserv_tmsi_unknown() runs on MTC_CT {
712 var BSC_ConnHdlr vc_conn;
713 f_init();
714 vc_conn := f_start_handler(refers(f_tc_cmserv_tmsi_unknown), 57, verify_cell_id := false);
715 vc_conn.done;
716}
717
Neels Hofmeyr14d0b132020-08-19 13:49:05 +0000718/* Send Paging Response for IMSI that has never performed LU before */
719friend function f_tc_paging_response_imsi_unknown(charstring id, BSC_ConnHdlrPars pars)
720runs on BSC_ConnHdlr {
721 f_init_handler(pars);
722
723 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
724 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
725 var PDU_ML3_MS_NW l3_info := valueof(ts_PAG_RESP(mi));
726
727 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
728 f_cl3_or_initial_ue(l3_info);
729
730 /* The Paging Response gets rejected by a direct Clear Command */
731 f_expect_clear();
732}
733testcase TC_paging_response_imsi_unknown() runs on MTC_CT {
734 var BSC_ConnHdlr vc_conn;
735 f_init();
736 vc_conn := f_start_handler(refers(f_tc_paging_response_imsi_unknown), 58, verify_cell_id := false);
737 vc_conn.done;
738}
739
740/* Send Paging Response for TMSI that has never performed LU before */
741friend function f_tc_paging_response_tmsi_unknown(charstring id, BSC_ConnHdlrPars pars)
742runs on BSC_ConnHdlr {
743 f_init_handler(pars);
744
745 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV('59111111'O));
746 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
747 var PDU_ML3_MS_NW l3_info := valueof(ts_PAG_RESP(mi));
748
749 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
750 f_cl3_or_initial_ue(l3_info);
751
752 /* The Paging Response gets rejected by a direct Clear Command */
753 f_expect_clear();
754}
755testcase TC_paging_response_tmsi_unknown() runs on MTC_CT {
756 var BSC_ConnHdlr vc_conn;
757 f_init();
758 vc_conn := f_start_handler(refers(f_tc_paging_response_tmsi_unknown), 59, verify_cell_id := false);
759 vc_conn.done;
760}
761
Neels Hofmeyr13737fb2020-08-19 13:16:14 +0000762
Harald Weltee13cfb22019-04-23 16:52:02 +0200763friend function f_tc_lu_and_mo_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100764 f_init_handler(pars);
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +0200765 var CallParameters cpars := valueof(t_CallParams);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100766 f_perform_lu();
Harald Welteb71901a2018-01-26 19:16:05 +0100767 f_mo_call(cpars);
Harald Welte2bb825f2018-01-22 11:31:18 +0100768}
769testcase TC_lu_and_mo_call() runs on MTC_CT {
770 var BSC_ConnHdlr vc_conn;
771 f_init();
772
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100773 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_call), 7);
Harald Welte071ed732018-01-23 19:53:52 +0100774 vc_conn.done;
775}
Pau Espin Pedrol833174e2020-09-03 16:46:02 +0200776friend function f_tc_lu_and_mo_call_ipv6(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
777 f_init_handler(pars);
778 var CallParameters cpars := valueof(t_CallParams);
779 cpars.mgw_conn_1.mgw_rtp_ip := "::1";
780 cpars.mgw_conn_2.mgw_rtp_ip := "::2";
781 cpars.bss_rtp_ip := "::3";
782 f_perform_lu();
783 f_mo_call(cpars);
784}
785testcase TC_lu_and_mo_call_ipv6() runs on MTC_CT {
786 var BSC_ConnHdlr vc_conn;
787 f_init();
788
789 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_call_ipv6), 7);
790 vc_conn.done;
791}
Harald Welte071ed732018-01-23 19:53:52 +0100792
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100793/* Verify T(iar) triggers and releases the channel */
794friend function f_lu_and_mo_call_sccp_tiar_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
795 timer T_wait_iar := int2float(5 + 1); /* g_msc_sccp_timer_iar + Give extra time (+1 sec) */
796 f_init_handler(pars);
797 var CallParameters cpars := valueof(t_CallParams);
798 f_perform_lu();
799 f_mo_call_establish(cpars);
800
801 /* Expect the channel cleared upon T(iar) triggered: */
802 T_wait_iar.start;
803 alt {
804 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {
805 T_wait_iar.stop
806 setverdict(pass);
807 }
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100808 [] T_wait_iar.timeout {
809 setverdict(fail, "Timeout waiting for T(iar) triggered SCCP RSLD");
810 mtc.stop;
811 }
812 }
Harald Welte4a3fa712020-08-19 08:57:33 +0200813 /* DLCX for both directions; if we don't do this, we might receive either of the two during
814 * shutdown causing race conditions */
815 MGCP.receive(tr_DLCX(?));
816 MGCP.receive(tr_DLCX(?));
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100817
818 setverdict(pass);
819}
820testcase TC_lu_and_mo_call_sccp_tiar_timeout() runs on MTC_CT {
821 var BSC_ConnHdlr vc_conn;
822
823 /* Set T(iar) in MSC low enough that it will trigger before other side
824 has time to keep alive with a T(ias). Keep recommended ratio of
825 T(iar) >= T(ias)*2 */
826 g_msc_sccp_timer_ias := 2;
827 g_msc_sccp_timer_iar := 5;
828
829 f_init();
830
831 vc_conn := f_start_handler(refers(f_lu_and_mo_call_sccp_tiar_timeout), 89);
832 vc_conn.done;
833}
834
Harald Weltee13cfb22019-04-23 16:52:02 +0200835
Harald Welte071ed732018-01-23 19:53:52 +0100836/* Test LU (with authentication enabled), where HLR times out sending SAI response */
Harald Weltee13cfb22019-04-23 16:52:02 +0200837friend function f_tc_lu_auth_sai_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100838 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100839
840 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
841 var PDU_DTAP_MT dtap_mt;
842
843 /* tell GSUP dispatcher to send this IMSI to us */
844 f_create_gsup_expect(hex2str(g_pars.imsi));
845
846 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200847 f_cl3_or_initial_ue(l3_lu);
Harald Welte071ed732018-01-23 19:53:52 +0100848
849 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200850 if (pars.ran_is_geran) {
851 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
852 }
Harald Welte071ed732018-01-23 19:53:52 +0100853
854 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
855 /* The HLR would normally return an auth vector here, but we fail to do so. */
856
857 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100858 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100859}
860testcase TC_lu_auth_sai_timeout() runs on MTC_CT {
861 var BSC_ConnHdlr vc_conn;
862 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100863 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100864
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200865 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_timeout), 8, verify_cell_id := false);
Harald Welte071ed732018-01-23 19:53:52 +0100866 vc_conn.done;
867}
868
Harald Weltee13cfb22019-04-23 16:52:02 +0200869
Harald Welte071ed732018-01-23 19:53:52 +0100870/* Test LU (with authentication enabled), where HLR rejects sending SAI error */
Harald Weltee13cfb22019-04-23 16:52:02 +0200871friend function f_tc_lu_auth_sai_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100872 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100873
874 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
875 var PDU_DTAP_MT dtap_mt;
876
877 /* tell GSUP dispatcher to send this IMSI to us */
878 f_create_gsup_expect(hex2str(g_pars.imsi));
879
880 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200881 f_cl3_or_initial_ue(l3_lu);
Harald Welte071ed732018-01-23 19:53:52 +0100882
883 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200884 if (pars.ran_is_geran) {
885 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
886 }
Harald Welte071ed732018-01-23 19:53:52 +0100887
888 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
889 GSUP.send(ts_GSUP_SAI_ERR(g_pars.imsi, 13));
890
891 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100892 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100893}
894testcase TC_lu_auth_sai_err() runs on MTC_CT {
895 var BSC_ConnHdlr vc_conn;
896 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100897 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100898
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200899 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_err), 9, verify_cell_id := false);
Harald Welte2bb825f2018-01-22 11:31:18 +0100900 vc_conn.done;
901}
Harald Weltea49e36e2018-01-21 19:29:33 +0100902
Harald Weltee13cfb22019-04-23 16:52:02 +0200903
Harald Weltebc881782018-01-23 20:09:15 +0100904/* Test LU but BSC will send a clear request in the middle */
905private function f_tc_lu_clear_request(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100906 f_init_handler(pars);
Harald Weltebc881782018-01-23 20:09:15 +0100907
908 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
909 var PDU_DTAP_MT dtap_mt;
910
911 /* tell GSUP dispatcher to send this IMSI to us */
912 f_create_gsup_expect(hex2str(g_pars.imsi));
913
914 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200915 f_cl3_or_initial_ue(l3_lu);
Harald Welte79f1e452020-08-18 22:55:02 +0200916 f_expect_common_id();
Harald Weltebc881782018-01-23 20:09:15 +0100917
918 /* Send Early Classmark, just for the fun of it */
919 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
920
921 f_sleep(1.0);
922 /* send clear request in the middle of the LU */
923 BSSAP.send(ts_BSSMAP_ClearRequest(0));
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200924 alt {
925 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { repeat; }
926 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {}
927 }
Harald Weltebc881782018-01-23 20:09:15 +0100928 BSSAP.send(ts_BSSMAP_ClearComplete);
Harald Welte89a32492018-01-27 19:07:28 +0100929 alt {
930 /* See https://osmocom.org/issues/2862 */
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200931 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {
932 setverdict(fail, "Got a second Clear Command, only one expected");
Daniel Willmannafce8662018-07-06 23:11:32 +0200933 mtc.stop;
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200934 repeat;
935 }
Harald Welte6811d102019-04-14 22:23:14 +0200936 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte89a32492018-01-27 19:07:28 +0100937 }
Harald Weltebc881782018-01-23 20:09:15 +0100938 setverdict(pass);
939}
940testcase TC_lu_clear_request() runs on MTC_CT {
941 var BSC_ConnHdlr vc_conn;
942 f_init();
943
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100944 vc_conn := f_start_handler(refers(f_tc_lu_clear_request), 10);
Harald Weltebc881782018-01-23 20:09:15 +0100945 vc_conn.done;
946}
947
Vadim Yanitskiy109e7552021-02-05 05:36:02 +0100948/* Test reaction on Clear Request during a MO Call */
949friend function f_TC_mo_mt_call_clear_request(charstring id, BSC_ConnHdlrPars pars)
950runs on BSC_ConnHdlr {
951 var CallParameters cpars := valueof(t_CallParams);
952 var MNCC_PDU mncc_pdu;
953 timer T := 2.0;
954
955 f_init_handler(pars);
956
957 f_perform_lu();
958
959 /* HACK: reducing code duplication ('66'H - MO, '68'H - MT) */
960 if (pars.imsi == '262420002532766'H)
961 { f_mo_call_establish(cpars); }
962 else
963 { f_mt_call_establish(cpars); }
964
965 /* Hold the line for a while... */
966 f_sleep(2.0);
967
968 /* BSC sends BSSMAP Clear Request (e.g. due to RR failure) */
969 BSSAP.send(ts_BSSMAP_ClearRequest(1));
970
971 /* Expect (optional) CC RELEASE and Clear Command */
972 var default ccrel := activate(as_optional_cc_rel(cpars));
973 f_expect_clear();
974 deactivate(ccrel);
975
976 /* Expect RELease indication on the MNCC socket */
977 T.start;
978 alt {
979 [] MNCC.receive(tr_MNCC_REL_ind(cpars.mncc_callref)) -> value mncc_pdu {
980 log("Rx MNCC REL.ind, cause := ", mncc_pdu.u.signal.cause);
981 setverdict(pass);
982 }
983 [] MNCC.receive(MNCC_PDU:?) -> value mncc_pdu {
984 setverdict(fail, "Rx unexpected MNCC PDU: ", mncc_pdu);
985 }
986 [] T.timeout {
987 setverdict(fail, "Timeout waiting for MNCC REL.ind");
988 }
989 }
990}
991testcase TC_mo_call_clear_request() runs on MTC_CT {
992 var BSC_ConnHdlr vc_conn;
993
994 f_init();
995
996 vc_conn := f_start_handler(refers(f_TC_mo_mt_call_clear_request), 2532766); // '66'H - MO
997 vc_conn.done;
998}
999testcase TC_mt_call_clear_request() runs on MTC_CT {
1000 var BSC_ConnHdlr vc_conn;
1001
1002 f_init();
1003
1004 vc_conn := f_start_handler(refers(f_TC_mo_mt_call_clear_request), 2532768); // '68'H - MT
1005 vc_conn.done;
1006}
1007
Harald Welte66af9e62018-01-24 17:28:21 +01001008/* Test LU but BSC will send a clear request in the middle */
Harald Weltee13cfb22019-04-23 16:52:02 +02001009friend function f_tc_lu_disconnect(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001010 f_init_handler(pars);
Harald Welte66af9e62018-01-24 17:28:21 +01001011
1012 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
1013 var PDU_DTAP_MT dtap_mt;
1014
1015 /* tell GSUP dispatcher to send this IMSI to us */
1016 f_create_gsup_expect(hex2str(g_pars.imsi));
1017
1018 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001019 f_cl3_or_initial_ue(l3_lu);
Harald Welte66af9e62018-01-24 17:28:21 +01001020
1021 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +02001022 if (pars.ran_is_geran) {
1023 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1024 }
Harald Welte66af9e62018-01-24 17:28:21 +01001025
1026 f_sleep(1.0);
1027 /* send clear request in the middle of the LU */
Harald Welte6811d102019-04-14 22:23:14 +02001028 BSSAP.send(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_REQ);
Harald Welte66af9e62018-01-24 17:28:21 +01001029 setverdict(pass);
Neels Hofmeyrbb825c92019-03-06 15:35:50 +01001030 f_sleep(1.0);
Harald Welte66af9e62018-01-24 17:28:21 +01001031}
1032testcase TC_lu_disconnect() runs on MTC_CT {
1033 var BSC_ConnHdlr vc_conn;
1034 f_init();
1035
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001036 vc_conn := f_start_handler(refers(f_tc_lu_disconnect), 11);
Harald Welte66af9e62018-01-24 17:28:21 +01001037 vc_conn.done;
1038}
1039
Harald Welteba7b6d92018-01-23 21:32:34 +01001040/* Test LU but with illegal mobile identity type = IMEI */
Harald Weltee13cfb22019-04-23 16:52:02 +02001041friend function f_tc_lu_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001042 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +01001043
Harald Welte256571e2018-01-24 18:47:19 +01001044 var PDU_ML3_MS_NW l3_lu := f_build_lu_imei(g_pars.imei)
Harald Welteba7b6d92018-01-23 21:32:34 +01001045 var PDU_DTAP_MT dtap_mt;
1046
1047 /* tell GSUP dispatcher to send this IMSI to us */
1048 f_create_gsup_expect(hex2str(g_pars.imsi));
1049
1050 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001051 f_cl3_or_initial_ue(l3_lu);
Harald Welteba7b6d92018-01-23 21:32:34 +01001052
1053 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +02001054 if (pars.ran_is_geran) {
1055 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1056 }
Harald Welteba7b6d92018-01-23 21:32:34 +01001057 /* wait for LU reject, ignore any ID REQ */
1058 alt {
1059 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { }
1060 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req)) { repeat; }
1061 }
1062 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001063 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +01001064}
1065testcase TC_lu_by_imei() runs on MTC_CT {
1066 var BSC_ConnHdlr vc_conn;
1067 f_init();
1068
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001069 vc_conn := f_start_handler(refers(f_tc_lu_by_imei), 12, verify_cell_id := false);
Harald Welteba7b6d92018-01-23 21:32:34 +01001070 vc_conn.done;
1071}
1072
Harald Weltee13cfb22019-04-23 16:52:02 +02001073
Harald Welteba7b6d92018-01-23 21:32:34 +01001074/* Test LU by TMSI with unknown TMSI, expect (and answer) ID REQ. */
1075private function f_tc_lu_tmsi_noauth_unknown(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Stefan Sperling04fc4bc2018-06-25 17:44:57 +02001076 /* We piggyback a test for an MSC crash on overlong IMSI (OS#2864) onto this test. */
1077 var hexstring overlong_imsi := '012345789ABCDEF0123456789ABCDEF'H;
Harald Weltea10db902018-01-27 12:44:49 +01001078 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +01001079
1080 var PDU_ML3_MS_NW l3_lu := f_build_lu_tmsi('01020304'O); /* FIXME: Random */
1081 var PDU_DTAP_MT dtap_mt;
1082
1083 /* tell GSUP dispatcher to send this IMSI to us */
1084 f_create_gsup_expect(hex2str(g_pars.imsi));
1085
1086 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001087 f_cl3_or_initial_ue(l3_lu);
Harald Welteba7b6d92018-01-23 21:32:34 +01001088
1089 /* Send Early Classmark, just for the fun of it */
1090 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1091
1092 /* Wait for + respond to ID REQ (IMSI) */
Oliver Smith32898452019-07-09 12:32:35 +02001093 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
Stefan Sperling04fc4bc2018-06-25 17:44:57 +02001094 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(overlong_imsi))); /* test for OS#2864 */
Harald Welteba7b6d92018-01-23 21:32:34 +01001095 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(g_pars.imsi)));
Harald Welte79f1e452020-08-18 22:55:02 +02001096 f_expect_common_id();
Harald Welteba7b6d92018-01-23 21:32:34 +01001097
1098 /* Expect MSC to do UpdateLocation to HLR; respond to it */
1099 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
1100 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
1101 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
1102 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
1103
1104 alt {
Harald Welte7ec4fa82018-01-27 10:57:40 +01001105 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
1106 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_TmsiRealloc_Cmpl));
1107 }
Harald Welteba7b6d92018-01-23 21:32:34 +01001108 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1109 setverdict(fail, "Expected LU ACK, but received REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +02001110 mtc.stop;
Harald Welteba7b6d92018-01-23 21:32:34 +01001111 }
1112 }
1113
Philipp Maier9b690e42018-12-21 11:50:03 +01001114 /* Wait for MM-Information (if enabled) */
1115 f_expect_mm_info();
1116
Harald Welteba7b6d92018-01-23 21:32:34 +01001117 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001118 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +01001119}
1120testcase TC_lu_by_tmsi_noauth_unknown() runs on MTC_CT {
1121 var BSC_ConnHdlr vc_conn;
1122 f_init();
1123
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001124 vc_conn := f_start_handler(refers(f_tc_lu_tmsi_noauth_unknown), 13);
Harald Welteba7b6d92018-01-23 21:32:34 +01001125 vc_conn.done;
1126}
1127
Neels Hofmeyrfc06c732020-08-19 12:52:28 +00001128/* Test LU by unknown TMSI, while the IMSI is already attached: osmo-msc should switch to the attached vlr_subscr. */
1129private function f_tc_attached_imsi_lu_unknown_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1130 f_init_handler(pars);
1131
1132 var PDU_ML3_MS_NW l3_lu := f_build_lu_tmsi('56111111'O);
1133 var PDU_DTAP_MT dtap_mt;
1134
1135 /* tell GSUP dispatcher to send this IMSI to us */
1136 f_create_gsup_expect(hex2str(g_pars.imsi));
1137
1138 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
1139 f_cl3_or_initial_ue(l3_lu);
1140
1141 /* Send Early Classmark, just for the fun of it */
1142 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1143
1144 /* Wait for + respond to ID REQ (IMSI) */
1145 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
1146 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(g_pars.imsi)));
1147 f_expect_common_id();
1148
1149 /* Expect MSC to do UpdateLocation to HLR; respond to it */
1150 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
1151 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
1152 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
1153 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
1154
1155 alt {
1156 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
1157 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_TmsiRealloc_Cmpl));
1158 }
1159 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1160 setverdict(fail, "Expected LU ACK, but received REJ");
1161 mtc.stop;
1162 }
1163 }
1164
1165 /* Wait for MM-Information (if enabled) */
1166 f_expect_mm_info();
1167
1168 /* wait for normal teardown */
1169 f_expect_clear();
1170
1171 /* Now the same IMSI is still attached in the VLR, and a LU with an unknown TMSI reveals the same IMSI only
1172 * later during ID Response. osmo-msc first creates a new vlr_subscr for the unknown TMSI, and as soon as the
1173 * IMSI becomes known, must notice that this IMSI is still regarded as attached, and must not create evil twins.
1174 */
1175
1176 /* (since the TMSI Reallocation happened, we could do this with exactly the same TMSI as above, but for test
1177 * readability just use a different one.) */
1178 l3_lu := f_build_lu_tmsi('56222222'O);
1179 f_cl3_or_initial_ue(l3_lu);
1180
1181 /* Wait for + respond to ID REQ (IMSI) */
1182 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
1183 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(g_pars.imsi)));
1184 f_expect_common_id();
1185
1186 /* Expect MSC to do UpdateLocation to HLR; respond to it */
1187 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
1188 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
1189 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
1190 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
1191
1192 alt {
1193 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
1194 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_TmsiRealloc_Cmpl));
1195 }
1196 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1197 setverdict(fail, "Expected LU ACK, but received REJ");
1198 mtc.stop;
1199 }
1200 }
1201
1202 /* Wait for MM-Information (if enabled) */
1203 f_expect_mm_info();
1204
1205 /* wait for normal teardown */
1206 f_expect_clear();
1207}
1208testcase TC_attached_imsi_lu_unknown_tmsi() runs on MTC_CT {
1209 var BSC_ConnHdlr vc_conn;
1210 f_init();
1211
1212 vc_conn := f_start_handler(refers(f_tc_attached_imsi_lu_unknown_tmsi), 56);
1213 vc_conn.done;
1214}
1215
Harald Welte4d15fa72020-08-19 08:58:28 +02001216friend function f_imsi_detach_by_imsi() runs on BSC_ConnHdlr {
Harald Welte45164da2018-01-24 12:51:27 +01001217 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1218
1219 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001220 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +01001221
1222 /* Send Early Classmark, just for the fun of it? */
Harald Welte4d15fa72020-08-19 08:58:28 +02001223 if (g_pars.ran_is_geran) {
Harald Weltee13cfb22019-04-23 16:52:02 +02001224 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1225 }
Harald Welte45164da2018-01-24 12:51:27 +01001226
1227 /* wait for normal teardown */
Harald Welte4d15fa72020-08-19 08:58:28 +02001228 f_expect_clear(verify_vlr_cell_id := false);
1229}
1230
1231
1232/* Test IMSI DETACH (MI=IMSI) */
1233friend function f_tc_imsi_detach_by_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1234 f_init_handler(pars);
1235
1236 f_imsi_detach_by_imsi();
Harald Welte45164da2018-01-24 12:51:27 +01001237}
1238testcase TC_imsi_detach_by_imsi() runs on MTC_CT {
1239 var BSC_ConnHdlr vc_conn;
1240 f_init();
1241
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001242 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imsi), 14, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001243 vc_conn.done;
1244}
1245
Harald Weltee13cfb22019-04-23 16:52:02 +02001246
Harald Welte45164da2018-01-24 12:51:27 +01001247/* Test IMSI DETACH (MI=TMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +02001248friend function f_tc_imsi_detach_by_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001249 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001250
1251 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV('01020304'O));
1252
1253 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001254 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +01001255
1256 /* Send Early Classmark, just for the fun of it? */
Harald Weltee13cfb22019-04-23 16:52:02 +02001257 if (pars.ran_is_geran) {
1258 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1259 }
Harald Welte45164da2018-01-24 12:51:27 +01001260
1261 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001262 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001263}
1264testcase TC_imsi_detach_by_tmsi() runs on MTC_CT {
1265 var BSC_ConnHdlr vc_conn;
1266 f_init();
1267
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001268 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_tmsi), 15, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001269 vc_conn.done;
1270}
1271
Harald Weltee13cfb22019-04-23 16:52:02 +02001272
Harald Welte45164da2018-01-24 12:51:27 +01001273/* Test IMSI DETACH (MI=IMEI), which is illegal */
Harald Weltee13cfb22019-04-23 16:52:02 +02001274friend function f_tc_imsi_detach_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001275 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001276
Harald Welte256571e2018-01-24 18:47:19 +01001277 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte45164da2018-01-24 12:51:27 +01001278
1279 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001280 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +01001281
1282 /* Send Early Classmark, just for the fun of it? */
Harald Weltee13cfb22019-04-23 16:52:02 +02001283 if (pars.ran_is_geran) {
1284 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1285 }
Harald Welte45164da2018-01-24 12:51:27 +01001286
1287 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001288 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001289}
1290testcase TC_imsi_detach_by_imei() runs on MTC_CT {
1291 var BSC_ConnHdlr vc_conn;
1292 f_init();
1293
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001294 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imei), 16, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001295 vc_conn.done;
1296}
1297
1298
1299/* helper function for an emergency call. caller passes in mobile identity to use */
1300private function f_emerg_call(MobileIdentityLV mi) runs on BSC_ConnHdlr {
Harald Welte0bef21e2018-02-10 09:48:23 +01001301 var CallParameters cpars := valueof(t_CallParams('112'H, 0));
1302 cpars.emergency := true;
Harald Welte45164da2018-01-24 12:51:27 +01001303
Harald Welte0bef21e2018-02-10 09:48:23 +01001304 f_mo_call(cpars);
Harald Welte45164da2018-01-24 12:51:27 +01001305}
1306
1307/* establish an emergency call by IMEI, no SIM inserted (and hence no IMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +02001308friend function f_tc_emerg_call_imei_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001309 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001310
Harald Welte256571e2018-01-24 18:47:19 +01001311 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001312 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_EMERG_CALL, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001313 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001314 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ('05'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +01001315 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001316}
1317testcase TC_emerg_call_imei_reject() runs on MTC_CT {
1318 var BSC_ConnHdlr vc_conn;
1319 f_init();
1320
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001321 vc_conn := f_start_handler(refers(f_tc_emerg_call_imei_reject), 17, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001322 vc_conn.done;
1323}
1324
Harald Weltee13cfb22019-04-23 16:52:02 +02001325
Harald Welted5b91402018-01-24 18:48:16 +01001326/* establish an emergency call by IMSI, SIM inserted (and hence IMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +02001327friend function f_tc_emerg_call_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001328 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001329 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001330 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001331 /* Then issue emergency call identified by IMSI */
1332 f_emerg_call(valueof(ts_MI_IMSI_LV(g_pars.imsi)));
1333}
1334testcase TC_emerg_call_imsi() runs on MTC_CT {
1335 var BSC_ConnHdlr vc_conn;
1336 f_init();
1337
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001338 vc_conn := f_start_handler(refers(f_tc_emerg_call_imsi), 18);
Harald Welte45164da2018-01-24 12:51:27 +01001339 vc_conn.done;
1340}
1341
Harald Weltee13cfb22019-04-23 16:52:02 +02001342
Harald Welte45164da2018-01-24 12:51:27 +01001343/* CM Service Request for VGCS -> reject */
1344private function f_tc_cm_serv_req_vgcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001345 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001346
1347 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001348 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001349
1350 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001351 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VGCS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001352 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001353 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001354 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001355}
1356testcase TC_cm_serv_req_vgcs_reject() runs on MTC_CT {
1357 var BSC_ConnHdlr vc_conn;
1358 f_init();
1359
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001360 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vgcs_reject), 19);
Harald Welte45164da2018-01-24 12:51:27 +01001361 vc_conn.done;
1362}
1363
1364/* CM Service Request for VBS -> reject */
1365private function f_tc_cm_serv_req_vbs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001366 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001367
1368 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001369 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001370
1371 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001372 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VBS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001373 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001374 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001375 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001376}
1377testcase TC_cm_serv_req_vbs_reject() runs on MTC_CT {
1378 var BSC_ConnHdlr vc_conn;
1379 f_init();
1380
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001381 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vbs_reject), 20);
Harald Welte45164da2018-01-24 12:51:27 +01001382 vc_conn.done;
1383}
1384
1385/* CM Service Request for LCS -> reject */
1386private function f_tc_cm_serv_req_lcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001387 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001388
1389 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001390 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001391
1392 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001393 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_LCS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001394 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001395 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001396 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001397}
1398testcase TC_cm_serv_req_lcs_reject() runs on MTC_CT {
1399 var BSC_ConnHdlr vc_conn;
1400 f_init();
1401
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001402 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_lcs_reject), 21);
Harald Welte45164da2018-01-24 12:51:27 +01001403 vc_conn.done;
1404}
1405
Harald Welte0195ab12018-01-24 21:50:20 +01001406/* CM Re-Establishment Request */
1407private function f_tc_cm_reest_req_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001408 f_init_handler(pars);
Harald Welte0195ab12018-01-24 21:50:20 +01001409
1410 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001411 f_perform_lu();
Harald Welte0195ab12018-01-24 21:50:20 +01001412
1413 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1414 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_REEST_REQ(0, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001415 f_cl3_or_initial_ue(l3_info);
Neels Hofmeyr49bbb512021-07-29 22:51:08 +02001416 /* Older osmo-msc returns: GSM48_REJECT_SRV_OPT_NOT_SUPPORTED = 32,
1417 * newer osmo-msc with CM Re-Establish support returns: GSM48_REJECT_CALL_CAN_NOT_BE_IDENTIFIED = 38 */
1418 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ( (int2oct(32,1), int2oct(38,1)) )));
Harald Welte1ddc7162018-01-27 14:25:46 +01001419 f_expect_clear();
Harald Welte0195ab12018-01-24 21:50:20 +01001420}
1421testcase TC_cm_reest_req_reject() runs on MTC_CT {
1422 var BSC_ConnHdlr vc_conn;
1423 f_init();
Harald Welte0195ab12018-01-24 21:50:20 +01001424
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001425 vc_conn := f_start_handler(refers(f_tc_cm_reest_req_reject), 22);
Harald Welte0195ab12018-01-24 21:50:20 +01001426 vc_conn.done;
1427}
1428
Harald Weltec638f4d2018-01-24 22:00:36 +01001429/* Test LU (with authentication enabled), with wrong response from MS */
1430private function f_tc_lu_auth_2G_fail(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001431 f_init_handler(pars);
Harald Weltec638f4d2018-01-24 22:00:36 +01001432
1433 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
1434
1435 /* tell GSUP dispatcher to send this IMSI to us */
1436 f_create_gsup_expect(hex2str(g_pars.imsi));
1437
1438 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001439 f_cl3_or_initial_ue(l3_lu);
Harald Weltec638f4d2018-01-24 22:00:36 +01001440
1441 /* Send Early Classmark, just for the fun of it */
1442 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1443
1444 var AuthVector vec := f_gen_auth_vec_2g();
1445 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G(vec.rand, vec.sres, vec.kc));
1446 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
1447 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
1448
1449 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_AUTH_REQ(vec.rand)));
1450 /* Send back wrong auth response */
1451 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MT_MM_AUTH_RESP_2G('00000000'O)));
1452
1453 /* Expect GSUP AUTH FAIL REP to HLR */
1454 GSUP.receive(tr_GSUP_AUTH_FAIL_IND(g_pars.imsi));
1455
1456 /* Expect LU REJECT with Cause == Illegal MS */
1457 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej('03'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +01001458 f_expect_clear();
Harald Weltec638f4d2018-01-24 22:00:36 +01001459}
1460testcase TC_lu_auth_2G_fail() runs on MTC_CT {
1461 var BSC_ConnHdlr vc_conn;
1462 f_init();
1463 f_vty_config(MSCVTY, "network", "authentication required");
Harald Weltec638f4d2018-01-24 22:00:36 +01001464
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001465 vc_conn := f_start_handler(refers(f_tc_lu_auth_2G_fail), 23, verify_cell_id := false);
Harald Weltec638f4d2018-01-24 22:00:36 +01001466 vc_conn.done;
1467}
1468
Harald Weltede371492018-01-27 23:44:41 +01001469/* A5/1 + A5/3 permitted on network side, and MS capable to do it */
Harald Welte16114282018-01-24 22:41:21 +01001470private function f_tc_lu_imsi_auth_tmsi_encr_13_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +01001471 pars.net.expect_auth := true;
1472 pars.net.expect_ciph := true;
Harald Weltea10db902018-01-27 12:44:49 +01001473 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001474 f_perform_lu();
Harald Welte16114282018-01-24 22:41:21 +01001475}
1476testcase TC_lu_imsi_auth_tmsi_encr_13_13() runs on MTC_CT {
1477 var BSC_ConnHdlr vc_conn;
1478 f_init();
1479 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte16114282018-01-24 22:41:21 +01001480 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
1481
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001482 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_13), 24);
Harald Welte16114282018-01-24 22:41:21 +01001483 vc_conn.done;
1484}
1485
Harald Welte1af6ea82018-01-25 18:33:15 +01001486/* Test Complete L3 without payload */
1487private function f_tc_cl3_no_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001488 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001489
1490 /* Send Complete L3 Info with empty L3 frame */
1491 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1492 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, ''O))));
1493
Harald Weltef466eb42018-01-27 14:26:54 +01001494 timer T := 5.0;
1495 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001496 alt {
Harald Welte6811d102019-04-14 22:23:14 +02001497 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte1af6ea82018-01-25 18:33:15 +01001498 /* Expect LU REJECT with Cause == Illegal MS */
Harald Weltebdb3c452018-03-18 22:43:06 +01001499 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
Harald Welte6811d102019-04-14 22:23:14 +02001500 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001501 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001502 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001503 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001504 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001505 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001506 }
1507 setverdict(pass);
1508}
1509testcase TC_cl3_no_payload() runs on MTC_CT {
1510 var BSC_ConnHdlr vc_conn;
1511 f_init();
1512
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001513 vc_conn := f_start_handler(refers(f_tc_cl3_no_payload), 25);
Harald Welte1af6ea82018-01-25 18:33:15 +01001514 vc_conn.done;
1515}
1516
1517/* Test Complete L3 with random payload */
1518private function f_tc_cl3_rnd_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001519 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001520
Daniel Willmannaa14a382018-07-26 08:29:45 +02001521 /* length is limited by PDU_BSSAP length field which includes some
1522 * other fields beside l3info payload. So payl can only be 240 bytes
1523 * Since rnd() returns values < 1 multiply with 241
1524 */
1525 var integer len := float2int(rnd() * 241.0);
Harald Welte1af6ea82018-01-25 18:33:15 +01001526 var octetstring payl := f_rnd_octstring(len);
1527
1528 /* Send Complete L3 Info with empty L3 frame */
1529 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1530 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, payl))));
1531
Harald Weltef466eb42018-01-27 14:26:54 +01001532 timer T := 5.0;
1533 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001534 alt {
1535 /* Immediate disconnect */
Harald Welte6811d102019-04-14 22:23:14 +02001536 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte1af6ea82018-01-25 18:33:15 +01001537 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
Harald Welte6811d102019-04-14 22:23:14 +02001538 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001539 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001540 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001541 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001542 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001543 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001544 }
1545 setverdict(pass);
1546}
1547testcase TC_cl3_rnd_payload() runs on MTC_CT {
1548 var BSC_ConnHdlr vc_conn;
1549 f_init();
1550
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001551 vc_conn := f_start_handler(refers(f_tc_cl3_rnd_payload), 26);
Harald Welte1af6ea82018-01-25 18:33:15 +01001552 vc_conn.done;
1553}
1554
Harald Welte116e4332018-01-26 22:17:48 +01001555/* Test Complete L3 with random payload */
Harald Weltee13cfb22019-04-23 16:52:02 +02001556friend function f_tc_establish_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001557 f_init_handler(pars);
Harald Welte116e4332018-01-26 22:17:48 +01001558
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001559 f_perform_lu();
Harald Welte116e4332018-01-26 22:17:48 +01001560
Harald Welteb9e86fa2018-04-09 18:18:31 +02001561 f_establish_fully();
Daniel Willmann898a7e02018-05-17 12:16:16 +02001562 f_expect_clear(10.0);
Harald Welte116e4332018-01-26 22:17:48 +01001563}
1564testcase TC_establish_and_nothing() runs on MTC_CT {
1565 var BSC_ConnHdlr vc_conn;
1566 f_init();
1567
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001568 vc_conn := f_start_handler(refers(f_tc_establish_and_nothing), 27);
Harald Welte116e4332018-01-26 22:17:48 +01001569 vc_conn.done;
1570}
1571
Harald Weltee13cfb22019-04-23 16:52:02 +02001572
Harald Welte12510c52018-01-26 22:26:24 +01001573/* Test MO Call SETUP with no response from MNCC */
Harald Weltee13cfb22019-04-23 16:52:02 +02001574friend function f_tc_mo_setup_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier109e6aa2018-10-17 10:53:32 +02001575 f_init_handler(pars, 190.0);
Harald Weltea10db902018-01-27 12:44:49 +01001576
Harald Welte12510c52018-01-26 22:26:24 +01001577 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001578 cpars.mgw_conn_2.resp := 0;
1579 cpars.stop_after_cc_setup := true;
1580
1581 f_vty_config(MSCVTY, "msc", "mncc guard-timeout 20");
Harald Welte12510c52018-01-26 22:26:24 +01001582
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001583 f_perform_lu();
Harald Welte12510c52018-01-26 22:26:24 +01001584
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001585 f_mo_call_establish(cpars);
Harald Welte12510c52018-01-26 22:26:24 +01001586
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001587 var default ccrel := activate(as_optional_cc_rel(cpars));
1588
Philipp Maier109e6aa2018-10-17 10:53:32 +02001589 f_expect_clear(185.0);
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001590
1591 deactivate(ccrel);
1592
1593 f_sleep(1.0);
Harald Welte12510c52018-01-26 22:26:24 +01001594}
1595testcase TC_mo_setup_and_nothing() runs on MTC_CT {
1596 var BSC_ConnHdlr vc_conn;
1597 f_init();
1598
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001599 vc_conn := f_start_handler(refers(f_tc_mo_setup_and_nothing), 28);
Harald Welte12510c52018-01-26 22:26:24 +01001600 vc_conn.done;
1601}
1602
Harald Weltee13cfb22019-04-23 16:52:02 +02001603
Harald Welte3ab88002018-01-26 22:37:25 +01001604/* Test MO Call with no response to RAN-side CRCX */
Harald Weltee13cfb22019-04-23 16:52:02 +02001605friend function f_tc_mo_crcx_ran_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001606 f_init_handler(pars);
Harald Welte3ab88002018-01-26 22:37:25 +01001607 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1608 var MNCC_PDU mncc;
1609 var MgcpCommand mgcp_cmd;
1610
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001611 f_perform_lu();
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001612 /* Do not respond to the second CRCX */
1613 cpars.mgw_conn_2.resp := 0;
1614 f_mo_call_establish(cpars);
Harald Welte3ab88002018-01-26 22:37:25 +01001615
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001616 var default ccrel := activate(as_optional_cc_rel(cpars));
Harald Welte3ab88002018-01-26 22:37:25 +01001617
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001618 f_expect_clear(60.0);
Harald Welte3ab88002018-01-26 22:37:25 +01001619
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001620 deactivate(ccrel);
Harald Welte3ab88002018-01-26 22:37:25 +01001621}
1622testcase TC_mo_crcx_ran_timeout() runs on MTC_CT {
1623 var BSC_ConnHdlr vc_conn;
1624 f_init();
1625
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001626 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_timeout), 29);
Harald Welte3ab88002018-01-26 22:37:25 +01001627 vc_conn.done;
1628}
1629
Harald Weltee13cfb22019-04-23 16:52:02 +02001630
Harald Welte0cc82d92018-01-26 22:52:34 +01001631/* Test MO Call with reject to RAN-side CRCX */
Harald Weltee13cfb22019-04-23 16:52:02 +02001632friend function f_tc_mo_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001633 f_init_handler(pars);
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001634
Harald Welte0cc82d92018-01-26 22:52:34 +01001635 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001636
1637 /* Respond with error for the first CRCX */
1638 cpars.mgw_conn_1.resp := -1;
Harald Welte0cc82d92018-01-26 22:52:34 +01001639
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001640 f_perform_lu();
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001641 f_mo_call_establish(cpars);
Harald Welte0cc82d92018-01-26 22:52:34 +01001642
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001643 var default ccrel := activate(as_optional_cc_rel(cpars));
1644 f_expect_clear(60.0);
1645 deactivate(ccrel);
Harald Welte0cc82d92018-01-26 22:52:34 +01001646}
1647testcase TC_mo_crcx_ran_reject() runs on MTC_CT {
1648 var BSC_ConnHdlr vc_conn;
1649 f_init();
1650
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001651 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_reject), 30);
Harald Welte0cc82d92018-01-26 22:52:34 +01001652 vc_conn.done;
1653}
1654
Harald Welte3ab88002018-01-26 22:37:25 +01001655
Harald Welte812f7a42018-01-27 00:49:18 +01001656/* helper function to start a MT call: MNCC SETUP; Paging; DChan est.; DTAP SETUP */
1657private function f_mt_call_start(inout CallParameters cpars) runs on BSC_ConnHdlr {
1658 var MNCC_PDU mncc;
1659 var MgcpCommand mgcp_cmd;
Harald Welte812f7a42018-01-27 00:49:18 +01001660
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001661 f_perform_lu();
Vadim Yanitskiyae747742020-01-10 00:23:10 +01001662 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Welte812f7a42018-01-27 00:49:18 +01001663
1664 /* Allocate call reference and send SETUP via MNCC to MSC */
1665 cpars.mncc_callref := f_rnd_int(2147483648);
1666 MNCC.send(ts_MNCC_SETUP_req(cpars.mncc_callref, hex2str(g_pars.msisdn),
1667 hex2str(cpars.called_party), hex2str(g_pars.imsi)));
1668
1669 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02001670 f_expect_paging();
1671
Harald Welte812f7a42018-01-27 00:49:18 +01001672 /* MS -> MSC: PAGING RESPONSE */
Harald Welteb9e86fa2018-04-09 18:18:31 +02001673 f_establish_fully(EST_TYPE_PAG_RESP);
Harald Welte812f7a42018-01-27 00:49:18 +01001674
1675 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1676
1677 /* MSC->MS: SETUP */
1678 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_SETUP(cpars.transaction_id, *, cpars.called_party)));
1679}
1680
1681/* Test MT Call */
Harald Weltee13cfb22019-04-23 16:52:02 +02001682friend function f_tc_mt_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001683 f_init_handler(pars);
Harald Welte812f7a42018-01-27 00:49:18 +01001684 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1685 var MNCC_PDU mncc;
1686 var MgcpCommand mgcp_cmd;
1687
1688 f_mt_call_start(cpars);
1689
1690 /* MS->MSC: CALL CONFIRMED */
1691 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1692
1693 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1694
1695 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1696 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001697
1698 /* Detect if the received CRCX is a wildcarded CRCX request. If yes,
1699 * set an endpoint name that fits the pattern. If not, just use the
1700 * endpoint name from the request */
1701 if (match(mgcp_cmd.line.ep, t_MGCP_EP_wildcard)) {
1702 cpars.mgcp_ep := "rtpbridge/1@mgw";
1703 } else {
1704 cpars.mgcp_ep := mgcp_cmd.line.ep;
1705 }
1706
Harald Welte812f7a42018-01-27 00:49:18 +01001707 /* Respond to CRCX with error */
1708 var MgcpResponse mgcp_rsp := {
1709 line := {
1710 code := "542",
1711 trans_id := mgcp_cmd.line.trans_id,
1712 string := "FORCED_FAIL"
1713 },
Harald Welte812f7a42018-01-27 00:49:18 +01001714 sdp := omit
1715 }
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001716 var MgcpParameter mgcp_rsp_param := {
1717 code := "Z",
1718 val := cpars.mgcp_ep
1719 };
1720 mgcp_rsp.params[0] := mgcp_rsp_param;
Harald Welte812f7a42018-01-27 00:49:18 +01001721 MGCP.send(mgcp_rsp);
1722
1723 timer T := 30.0;
1724 T.start;
1725 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001726 [] T.timeout {
1727 setverdict(fail, "Timeout waiting for channel release");
1728 mtc.stop;
1729 }
Harald Welte812f7a42018-01-27 00:49:18 +01001730 [] MNCC.receive { repeat; }
1731 [] GSUP.receive { repeat; }
1732 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1733 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
1734 f_create_mgcp_delete_ep(cpars.mgcp_ep);
1735 repeat;
1736 }
1737 [] MGCP.receive { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001738 [] as_clear_cmd_compl_disc();
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001739 [] as_optional_cc_rel(cpars);
Harald Welte812f7a42018-01-27 00:49:18 +01001740 }
1741}
1742testcase TC_mt_crcx_ran_reject() runs on MTC_CT {
1743 var BSC_ConnHdlr vc_conn;
1744 f_init();
1745
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001746 vc_conn := f_start_handler(refers(f_tc_mt_crcx_ran_reject), 31);
Harald Welte812f7a42018-01-27 00:49:18 +01001747 vc_conn.done;
1748}
1749
1750
Harald Weltee13cfb22019-04-23 16:52:02 +02001751
Harald Welte812f7a42018-01-27 00:49:18 +01001752/* Test MT Call T310 timer */
Harald Weltee13cfb22019-04-23 16:52:02 +02001753friend function f_tc_mt_t310(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte812f7a42018-01-27 00:49:18 +01001754 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
Harald Welte812f7a42018-01-27 00:49:18 +01001755 var MgcpCommand mgcp_cmd;
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001756 var PDU_BSSAP bssap;
1757 timer T310;
Harald Welte812f7a42018-01-27 00:49:18 +01001758
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001759 f_init_handler(pars);
1760
1761 /* Initiate a MT call, establish connection */
Harald Welte812f7a42018-01-27 00:49:18 +01001762 f_mt_call_start(cpars);
1763
1764 /* MS->MSC: CALL CONFIRMED */
1765 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1766 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1767
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001768 /* NOTE: MSC is expected to start T310 here */
Harald Welte812f7a42018-01-27 00:49:18 +01001769
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001770 /* MSC->MGW: CRCX (first) */
1771 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1772 f_handle_crcx(cpars, mgcp_cmd); /* MSC<-MGW: OK */
1773
1774 /* BSC->BSC: BSSMAP ASSIGNMENT REQ */
1775 BSSAP.receive(tr_BSSMAP_AssignmentReq(omit, ?)) -> value bssap;
1776 BSSAP.send(ts_BSSMAP_AssignmentComplete(omit,
1777 aoip := f_ts_BSSMAP_IE_AoIP_TLA(cpars.bss_rtp_ip, cpars.bss_rtp_port),
1778 speechCodec := ts_BSSMAP_IE_SpeechCodec({ ts_CodecFR })));
1779
1780 /* MSC->MGW: MDCX */
1781 MGCP.receive(tr_MDCX) -> value mgcp_cmd;
1782 MGCP.send(ts_MDCX_ACK(mgcp_cmd.line.trans_id, cpars.mgw_conn_1.mgcp_connection_id,
1783 sdp := omit));
1784
1785 /* MSC->MGW: CRCX (second) */
1786 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1787 f_handle_crcx(cpars, mgcp_cmd); /* MSC<-MGW: OK */
1788 MNCC.receive(tr_MNCC_RTP_CREATE(cpars.mncc_callref));
1789
1790 /* Reschedule the guard timeout */
1791 g_Tguard.start(30.0 + 10.0);
1792
1793 /* NOTE: the BSC is expected to respond with CC ALERTING at this state, so
1794 * the MSC would stop T310. However, the idea is to verify T310 expiration
1795 * here, so grab some popcorn and wait for MNCC DISC.ind. */
1796 T310.start(30.0 + 2.0);
Harald Welte812f7a42018-01-27 00:49:18 +01001797 alt {
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001798 [] T310.timeout {
1799 setverdict(fail, "Timeout waiting for MNCC DISC.ind due to T310");
Daniel Willmannafce8662018-07-06 23:11:32 +02001800 mtc.stop;
1801 }
Harald Welte812f7a42018-01-27 00:49:18 +01001802 [] MNCC.receive(tr_MNCC_DISC_ind(cpars.mncc_callref)) {
1803 MNCC.send(ts_MNCC_REL_req(cpars.mncc_callref, valueof(ts_MNCC_cause(23))));
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001804 log("Rx MNCC DISC.ind, T310.read yelds ", T310.read);
1805 setverdict(pass);
Harald Welte812f7a42018-01-27 00:49:18 +01001806 }
1807 }
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001808
Harald Welte812f7a42018-01-27 00:49:18 +01001809 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_DISC(cpars.transaction_id)));
1810 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id)));
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001811 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id, '1'B)));
Harald Welte812f7a42018-01-27 00:49:18 +01001812
1813 alt {
Harald Welte812f7a42018-01-27 00:49:18 +01001814 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1815 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001816 // FIXME: f_create_mgcp_delete_ep(cpars.mgcp_ep);
Harald Welte812f7a42018-01-27 00:49:18 +01001817 repeat;
1818 }
Harald Welte5946b332018-03-18 23:32:21 +01001819 [] as_clear_cmd_compl_disc();
Harald Welte812f7a42018-01-27 00:49:18 +01001820 }
1821}
1822testcase TC_mt_t310() runs on MTC_CT {
1823 var BSC_ConnHdlr vc_conn;
1824 f_init();
1825
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001826 vc_conn := f_start_handler(refers(f_tc_mt_t310), 32);
Harald Welte812f7a42018-01-27 00:49:18 +01001827 vc_conn.done;
1828}
1829
Harald Weltee13cfb22019-04-23 16:52:02 +02001830
Harald Welte167458a2018-01-27 15:58:16 +01001831/* Perform successful LU + MO call, then GSUP LocationCancel. Subscriber must be denied CM SERV */
Harald Weltee13cfb22019-04-23 16:52:02 +02001832friend function f_tc_gsup_cancel(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte167458a2018-01-27 15:58:16 +01001833 f_init_handler(pars);
1834 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Harald Welte167458a2018-01-27 15:58:16 +01001835
1836 /* Location Update to make subscriber known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001837 f_perform_lu();
Harald Welte167458a2018-01-27 15:58:16 +01001838
1839 /* First MO call should succeed */
1840 f_mo_call(cpars);
1841
1842 /* Cancel the subscriber in the VLR */
1843 GSUP.send(ts_GSUP_CL_REQ(g_pars.imsi, OSMO_GSUP_CANCEL_TYPE_WITHDRAW));
1844 alt {
1845 [] GSUP.receive(tr_GSUP_CL_RES(g_pars.imsi)) { }
1846 [] GSUP.receive(tr_GSUP_CL_ERR(g_pars.imsi)) {
1847 setverdict(fail, "Received GSUP Location Cancel Error");
Daniel Willmannafce8662018-07-06 23:11:32 +02001848 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001849 }
1850 }
1851
1852 /* Follow-up transactions should fail */
1853 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1854 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001855 f_cl3_or_initial_ue(l3_info);
Harald Welte167458a2018-01-27 15:58:16 +01001856 alt {
1857 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
1858 [] BSSAP.receive {
1859 setverdict(fail, "Received unexpected BSSAP instead of CM SERV REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +02001860 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001861 }
1862 }
Neels Hofmeyr0f7429a2019-03-07 22:28:41 +01001863
1864 f_expect_clear();
Harald Welte167458a2018-01-27 15:58:16 +01001865 setverdict(pass);
1866}
1867testcase TC_gsup_cancel() runs on MTC_CT {
1868 var BSC_ConnHdlr vc_conn;
1869 f_init();
1870
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001871 vc_conn := f_start_handler(refers(f_tc_gsup_cancel), 33, verify_cell_id := false);
Harald Welte167458a2018-01-27 15:58:16 +01001872 vc_conn.done;
1873}
1874
Harald Weltee13cfb22019-04-23 16:52:02 +02001875
Harald Welte9de84792018-01-28 01:06:35 +01001876/* A5/1 only permitted on network side, and MS capable to do it */
1877private function f_tc_lu_imsi_auth_tmsi_encr_1_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1878 pars.net.expect_auth := true;
1879 pars.net.expect_ciph := true;
1880 pars.net.kc_support := '02'O; /* A5/1 only */
1881 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001882 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001883}
1884testcase TC_lu_imsi_auth_tmsi_encr_1_13() runs on MTC_CT {
1885 var BSC_ConnHdlr vc_conn;
1886 f_init();
1887 f_vty_config(MSCVTY, "network", "authentication required");
1888 f_vty_config(MSCVTY, "network", "encryption a5 1");
1889
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001890 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_1_13), 34);
Harald Welte9de84792018-01-28 01:06:35 +01001891 vc_conn.done;
1892}
1893
1894/* A5/3 only permitted on network side, and MS capable to do it */
1895private function f_tc_lu_imsi_auth_tmsi_encr_3_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1896 pars.net.expect_auth := true;
1897 pars.net.expect_ciph := true;
1898 pars.net.kc_support := '08'O; /* A5/3 only */
1899 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001900 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001901}
1902testcase TC_lu_imsi_auth_tmsi_encr_3_13() runs on MTC_CT {
1903 var BSC_ConnHdlr vc_conn;
1904 f_init();
1905 f_vty_config(MSCVTY, "network", "authentication required");
1906 f_vty_config(MSCVTY, "network", "encryption a5 3");
1907
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001908 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_13), 35);
Harald Welte9de84792018-01-28 01:06:35 +01001909 vc_conn.done;
1910}
1911
1912/* A5/3 only permitted on network side, and MS with only A5/1 support */
1913private function f_tc_lu_imsi_auth_tmsi_encr_3_1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1914 pars.net.expect_auth := true;
1915 pars.net.expect_ciph := true;
1916 pars.net.kc_support := '08'O; /* A5/3 only */
1917 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1918 f_init_handler(pars, 15.0);
1919
1920 /* cannot use f_perform_lu() as we expect a reject */
1921 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
1922 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +02001923 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001924 if (pars.send_early_cm) {
1925 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1926 } else {
1927 pars.cm1.esind := '0'B;
1928 }
Harald Welte9de84792018-01-28 01:06:35 +01001929 f_mm_auth();
1930 alt {
Daniel Willmann52918e52018-09-20 14:39:09 +02001931 [] BSSAP.receive(tr_BSSMAP_ClassmarkReq) {
1932 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1933 repeat;
1934 }
Harald Welte5946b332018-03-18 23:32:21 +01001935 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1936 f_expect_clear();
1937 }
Harald Welte9de84792018-01-28 01:06:35 +01001938 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
1939 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02001940 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001941 }
1942 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01001943 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02001944 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001945 }
1946 }
1947 setverdict(pass);
1948}
1949testcase TC_lu_imsi_auth_tmsi_encr_3_1() runs on MTC_CT {
1950 var BSC_ConnHdlr vc_conn;
1951 f_init();
1952 f_vty_config(MSCVTY, "network", "authentication required");
1953 f_vty_config(MSCVTY, "network", "encryption a5 3");
1954
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001955 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 360, verify_cell_id := false);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001956 vc_conn.done;
1957}
1958testcase TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() runs on MTC_CT {
1959 var BSC_ConnHdlrPars pars;
1960 var BSC_ConnHdlr vc_conn;
1961 f_init();
1962 f_vty_config(MSCVTY, "network", "authentication required");
1963 f_vty_config(MSCVTY, "network", "encryption a5 3");
1964
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001965 pars := f_init_pars(361, verify_cell_id := false);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001966 pars.send_early_cm := false;
1967 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), pars);
Harald Welte9de84792018-01-28 01:06:35 +01001968 vc_conn.done;
1969}
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01001970testcase TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() runs on MTC_CT {
1971 var BSC_ConnHdlr vc_conn;
1972 f_init();
1973 f_vty_config(MSCVTY, "network", "authentication required");
1974 f_vty_config(MSCVTY, "network", "encryption a5 3");
1975
1976 /* Make sure the MSC category is on DEBUG level to trigger the log
1977 * message that is reported in OS#2947 to trigger the segfault */
1978 f_vty_config(MSCVTY, "log stderr", "logging level msc debug");
1979
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001980 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 362, verify_cell_id := false);
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01001981 vc_conn.done;
1982}
Harald Welte9de84792018-01-28 01:06:35 +01001983
1984/* A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
1985private function f_tc_lu_imsi_auth_tmsi_encr_13_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1986 pars.net.expect_auth := true;
1987 pars.net.expect_ciph := true;
1988 pars.net.kc_support := '0A'O; /* A5/1 + A5/3 */
1989 pars.cm1.a5_1 := '1'B;
1990 pars.cm2.a5_1 := '1'B;
1991 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1992 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
1993 f_init_handler(pars, 15.0);
1994
1995 /* cannot use f_perform_lu() as we expect a reject */
1996 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
1997 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +02001998 f_cl3_or_initial_ue(l3_lu);
Harald Welte9de84792018-01-28 01:06:35 +01001999 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
2000 f_mm_auth();
2001 alt {
Harald Welte5946b332018-03-18 23:32:21 +01002002 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
2003 f_expect_clear();
2004 }
Harald Welte9de84792018-01-28 01:06:35 +01002005 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
2006 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02002007 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01002008 }
2009 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01002010 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02002011 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01002012 }
2013 }
2014 setverdict(pass);
2015}
2016testcase TC_lu_imsi_auth_tmsi_encr_13_2() runs on MTC_CT {
2017 var BSC_ConnHdlr vc_conn;
2018 f_init();
2019 f_vty_config(MSCVTY, "network", "authentication required");
2020 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
2021
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02002022 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_2), 37, verify_cell_id := false);
Harald Welte9de84792018-01-28 01:06:35 +01002023 vc_conn.done;
2024}
2025
Eric Wild26f4a622021-05-17 15:27:05 +02002026/* A5/0 + A5/1 + A5/3 + a5/4 only permitted on network side, and MS with only A5/1 support */
2027private function f_tc_lu_imsi_auth_tmsi_encr_0134_1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2028 pars.net.expect_auth := true;
2029 pars.net.expect_ciph := true;
2030 pars.net.kc_support := '03'O; /* A5/0 + A5/1 */
2031 pars.cm1.a5_1 := '0'B;
2032 pars.cm2.a5_1 := '0'B;
2033 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
2034 pars.cm2.classmarkInformationType2_oct5.a5_2 := '0'B;
2035 pars.cm2.classmarkInformationType2_oct5.cm3 := '0'B;
2036 pars.cm3 := omit;
2037 pars.use_umts_aka := true;
2038
2039 f_init_handler(pars, 15.0);
2040 f_perform_lu();
2041}
2042testcase TC_lu_imsi_auth_tmsi_encr_0134_1() runs on MTC_CT {
2043 var BSC_ConnHdlr vc_conn;
2044 f_init();
2045 f_vty_config(MSCVTY, "network", "authentication required");
2046 f_vty_config(MSCVTY, "network", "encryption a5 0 1 3 4");
2047
2048 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_0134_1), 39);
2049 vc_conn.done;
2050}
2051
2052/* A5/0 + A5/1 + A5/3 + a5/4 only permitted on network side, and MS with A5/3 + A5/4 support */
2053private function f_tc_lu_imsi_auth_tmsi_encr_0134_34(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2054 pars.net.expect_auth := true;
2055 pars.net.expect_ciph := true;
2056 pars.net.kc_support := '19'O; /* A5/3 + A5/4 */
2057 pars.cm1.a5_1 := '1'B;
2058 pars.cm2.a5_1 := '1'B;
2059 pars.cm2.classmarkInformationType2_oct5.a5_3 := '1'B;
2060 pars.cm2.classmarkInformationType2_oct5.a5_2 := '0'B;
2061 pars.cm2.classmarkInformationType2_oct5.cm3 := '1'B;
2062 pars.cm3 := valueof(ts_CM3_default);
2063 pars.use_umts_aka := true;
2064
2065 f_init_handler(pars, 15.0);
2066 f_perform_lu();
2067}
2068testcase TC_lu_imsi_auth_tmsi_encr_0134_34() runs on MTC_CT {
2069 var BSC_ConnHdlr vc_conn;
2070 f_init();
2071 f_vty_config(MSCVTY, "network", "authentication required");
2072 f_vty_config(MSCVTY, "network", "encryption a5 0 1 3 4");
2073
2074 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_0134_34), 40);
2075 vc_conn.done;
2076}
2077
2078/* A5/0 + A5/1 + A5/3 + a5/4 only permitted on network side, and MS with A5/3 support but no CM3 */
2079private function f_tc_lu_imsi_auth_tmsi_encr_0134_34_no_cm3(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2080 pars.net.expect_auth := true;
2081 pars.net.expect_ciph := true;
2082 pars.net.kc_support := '19'O; /* A5/3 + A5/4 */
2083 pars.cm1.a5_1 := '1'B;
2084 pars.cm2.a5_1 := '1'B;
2085 pars.cm2.classmarkInformationType2_oct5.a5_3 := '1'B;
2086 pars.cm2.classmarkInformationType2_oct5.a5_2 := '0'B;
2087 pars.cm2.classmarkInformationType2_oct5.cm3 := '0'B;
2088 pars.cm3 := omit;
2089 pars.use_umts_aka := true;
2090
2091 f_init_handler(pars, 15.0);
2092 f_perform_lu();
2093}
2094testcase TC_lu_imsi_auth_tmsi_encr_0134_34_no_cm3() runs on MTC_CT {
2095 var BSC_ConnHdlr vc_conn;
2096 f_init();
2097 f_vty_config(MSCVTY, "network", "authentication required");
2098 f_vty_config(MSCVTY, "network", "encryption a5 0 1 3 4");
2099
2100 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_0134_34_no_cm3), 41);
2101 vc_conn.done;
2102}
2103
Harald Welte9de84792018-01-28 01:06:35 +01002104/* A5/0 + A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
2105private function f_tc_lu_imsi_auth_tmsi_encr_013_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2106 pars.net.expect_auth := true;
2107 pars.net.expect_ciph := true;
2108 pars.net.kc_support := '0B'O; /* A5/1 + A5/3 */
2109 pars.cm1.a5_1 := '1'B;
2110 pars.cm2.a5_1 := '1'B;
2111 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
2112 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
2113 f_init_handler(pars, 15.0);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01002114 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01002115}
2116testcase TC_lu_imsi_auth_tmsi_encr_013_2() runs on MTC_CT {
2117 var BSC_ConnHdlr vc_conn;
2118 f_init();
2119 f_vty_config(MSCVTY, "network", "authentication required");
2120 f_vty_config(MSCVTY, "network", "encryption a5 0 1 3");
2121
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01002122 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_013_2), 38);
Harald Welte9de84792018-01-28 01:06:35 +01002123 vc_conn.done;
2124}
2125
Harald Welte33ec09b2018-02-10 15:34:46 +01002126/* LU followed by MT call (including paging) */
Neels Hofmeyr8fe8a902019-11-03 05:51:03 +01002127friend function f_tc_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte33ec09b2018-02-10 15:34:46 +01002128 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01002129 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02002130 cpars.use_osmux := pars.use_osmux;
Harald Welte33ec09b2018-02-10 15:34:46 +01002131
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01002132 f_perform_lu();
Harald Welte33ec09b2018-02-10 15:34:46 +01002133 f_mt_call(cpars);
2134}
2135testcase TC_lu_and_mt_call() runs on MTC_CT {
2136 var BSC_ConnHdlr vc_conn;
2137 f_init();
2138
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01002139 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call), 39);
Harald Welte33ec09b2018-02-10 15:34:46 +01002140 vc_conn.done;
2141}
2142
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02002143testcase TC_lu_and_mt_call_osmux() runs on MTC_CT {
2144 var BSC_ConnHdlr vc_conn;
2145 f_init(1, false, true, true);
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02002146
2147 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call), 39, 0, true, true);
2148 vc_conn.done;
2149}
2150
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02002151/* LU followed by MT call (including paging) */
2152friend function f_tc_lu_and_mt_call_ipv6(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2153 f_init_handler(pars);
2154 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
2155 cpars.mgw_conn_1.mgw_rtp_ip := "::1";
2156 cpars.mgw_conn_2.mgw_rtp_ip := "::2";
2157 cpars.bss_rtp_ip := "::3";
Pau Espin Pedrol563b3d02020-09-09 20:19:52 +02002158 cpars.mncc_rtp_ip := "::9";
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02002159 f_perform_lu();
2160 f_mt_call(cpars);
2161}
2162testcase TC_lu_and_mt_call_ipv6() runs on MTC_CT {
2163 var BSC_ConnHdlr vc_conn;
2164 f_init();
2165
2166 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call_ipv6), 39);
2167 vc_conn.done;
2168}
2169
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01002170/* MT call while already Paging */
2171friend function f_tc_lu_and_mt_call_already_paging(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2172 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
2173 var SmsParameters spars := valueof(t_SmsPars);
2174 var OCT4 tmsi;
2175
2176 f_init_handler(pars);
2177
2178 /* Perform location update */
2179 f_perform_lu();
2180
2181 /* register an 'expect' for given IMSI (+TMSI) */
2182 if (isvalue(g_pars.tmsi)) {
2183 tmsi := g_pars.tmsi;
2184 } else {
2185 tmsi := 'FFFFFFFF'O;
2186 }
2187 f_ran_register_imsi(g_pars.imsi, tmsi);
2188
2189 log("start Paging by an SMS");
2190 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2191
2192 /* MSC->BSC: expect PAGING from MSC */
2193 f_expect_paging();
2194
2195 log("MNCC signals MT call, before Paging Response");
2196 f_mt_call_initate(cpars);
2197 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
2198
2199 f_sleep(0.5);
2200 log("phone answers Paging, expecting both SMS and MT call to be established");
2201 f_establish_fully(EST_TYPE_PAG_RESP);
2202 spars.tp.ud := 'C8329BFD064D9B53'O;
2203 interleave {
2204 [] BSSAP.receive(f_mt_sms_deliver_pdu(spars)) {
2205 log("Got SMS-DELIVER");
2206 };
2207 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_SETUP(cpars.transaction_id, *, cpars.called_party))) {
2208 log("Got CC Setup");
2209 };
2210 }
2211 setverdict(pass);
2212 log("success, tear down");
2213 var default ccrel := activate(as_optional_cc_rel(cpars));
2214 if (g_pars.ran_is_geran) {
2215 BSSAP.send(ts_BSSMAP_ClearRequest(0));
2216 } else {
2217 BSSAP.send(ts_RANAP_IuReleaseRequest(ts_RanapCause_om_intervention));
2218 }
2219 f_expect_clear();
2220 deactivate(ccrel);
2221 f_vty_sms_clear(hex2str(g_pars.imsi));
2222}
2223testcase TC_lu_and_mt_call_already_paging() runs on MTC_CT {
2224 var BSC_ConnHdlrPars pars;
2225 var BSC_ConnHdlr vc_conn;
2226 f_init();
2227 pars := f_init_pars(391);
2228 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_call_already_paging), pars);
2229 vc_conn.done;
2230}
2231
Daniel Willmann8b084372018-02-04 13:35:26 +01002232/* Test MO Call SETUP with DTMF */
2233private function f_tc_mo_setup_dtmf_dup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2234 f_init_handler(pars);
2235 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Daniel Willmann8b084372018-02-04 13:35:26 +01002236
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01002237 f_perform_lu();
Daniel Willmann8b084372018-02-04 13:35:26 +01002238 f_mo_seq_dtmf_dup(cpars);
2239}
2240testcase TC_mo_setup_and_dtmf_dup() runs on MTC_CT {
2241 var BSC_ConnHdlr vc_conn;
2242 f_init();
2243
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01002244 vc_conn := f_start_handler(refers(f_tc_mo_setup_dtmf_dup), 39);
Daniel Willmann8b084372018-02-04 13:35:26 +01002245 vc_conn.done;
2246}
Harald Welte9de84792018-01-28 01:06:35 +01002247
Philipp Maier328d1662018-03-07 10:40:27 +01002248testcase TC_cr_before_reset() runs on MTC_CT {
2249 timer T := 4.0;
2250 var boolean reset_ack_seen := false;
2251 f_init_bssap_direct();
2252
Harald Welte3ca0ce12019-04-23 17:18:48 +02002253 f_ran_adapter_start(g_bssap[0]);
Daniel Willmann42d1d5b2018-08-07 15:18:41 +02002254
Daniel Willmanne8018962018-08-21 14:18:00 +02002255 f_sleep(3.0);
2256
Philipp Maier328d1662018-03-07 10:40:27 +01002257 /* Make a blind connection attemt, to trigger the deadlock condition */
Philipp Maier75932982018-03-27 14:52:35 +02002258 BSSAP_DIRECT.send(ts_BSSAP_CONNECT_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, 1, omit));
Philipp Maier328d1662018-03-07 10:40:27 +01002259
2260 /* Send a BSSMAP reset */
Philipp Maier75932982018-03-27 14:52:35 +02002261 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_Reset(0)));
Philipp Maier328d1662018-03-07 10:40:27 +01002262 T.start
2263 alt {
2264 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_ResetAck)) {
2265 reset_ack_seen := true;
2266 repeat;
2267 }
2268
2269 /* Acknowledge MSC sided reset requests */
2270 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_Reset)) {
Philipp Maier75932982018-03-27 14:52:35 +02002271 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_ResetAck));
Philipp Maier328d1662018-03-07 10:40:27 +01002272 repeat;
2273 }
2274
2275 /* Ignore all other messages (e.g CR from the connection request) */
2276 [] BSSAP_DIRECT.receive { repeat }
2277
2278 /* If we got no BSSMAP RESET ACK back, then the MSC entered the
2279 * deadlock situation. The MSC is then unable to respond to any
2280 * further BSSMAP RESET or any other sort of traffic. */
2281 [reset_ack_seen == true] T.timeout { setverdict(pass) }
2282 [reset_ack_seen == false] T.timeout {
2283 setverdict(fail, "no BSSMAP RESET ACK seen!");
Daniel Willmannafce8662018-07-06 23:11:32 +02002284 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +01002285 }
Pau Espin Pedrol7e9178d2019-12-17 17:52:17 +01002286 }
Philipp Maier328d1662018-03-07 10:40:27 +01002287}
Harald Welte9de84792018-01-28 01:06:35 +01002288
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002289/* Test MO Call with no response to RAN-side CRCX or DTAP Release */
Harald Weltee13cfb22019-04-23 16:52:02 +02002290friend function f_tc_mo_release_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002291 f_init_handler(pars);
2292 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
2293 var MNCC_PDU mncc;
2294 var MgcpCommand mgcp_cmd;
2295
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02002296 /* Do not respond to the second CRCX */
2297 cpars.mgw_conn_2.resp := 0;
2298
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002299 f_perform_lu();
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02002300 f_mo_call_establish(cpars);
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002301
Neels Hofmeyrde76f052019-02-26 05:02:46 +01002302 var default ccrel := activate(as_optional_cc_rel(cpars));
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002303
2304 f_expect_clear(60.0);
Neels Hofmeyrde76f052019-02-26 05:02:46 +01002305
2306 deactivate(ccrel);
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002307}
2308testcase TC_mo_release_timeout() runs on MTC_CT {
2309 var BSC_ConnHdlr vc_conn;
2310 f_init();
2311
2312 vc_conn := f_start_handler(refers(f_tc_mo_release_timeout), 40);
2313 vc_conn.done;
2314}
2315
Harald Welte12510c52018-01-26 22:26:24 +01002316
Philipp Maier2a98a732018-03-19 16:06:12 +01002317/* LU followed by MT call (including paging) */
2318private function f_tc_lu_and_mt_call_no_dlcx_resp(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2319 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01002320 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Philipp Maier2a98a732018-03-19 16:06:12 +01002321
2322 /* Intentionally disable the CRCX response */
2323 cpars.mgw_drop_dlcx := true;
2324
2325 /* Perform location update and call */
2326 f_perform_lu();
2327 f_mt_call(cpars);
2328}
2329testcase TC_lu_and_mt_call_no_dlcx_resp() runs on MTC_CT {
2330 var BSC_ConnHdlr vc_conn;
2331 f_init();
2332
2333 /* Perform an almost normal looking locationupdate + mt-call, but do
2334 * not respond to the DLCX at the end of the call */
2335 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call_no_dlcx_resp), 41);
2336 vc_conn.done;
2337
2338 /* Wait a guard period until the MGCP layer in the MSC times out,
2339 * if the MSC is vulnerable to the use-after-free situation that is
2340 * fixed by I78f1b6a9149488a4ad3f120c1e190a83c07d4b89 then it should
2341 * segfault now */
2342 f_sleep(6.0);
2343
2344 /* Run the init procedures once more. If the MSC has crashed, this
2345 * this will fail */
2346 f_init();
2347}
Harald Welte45164da2018-01-24 12:51:27 +01002348
Philipp Maier75932982018-03-27 14:52:35 +02002349/* Two BSSMAP resets from two different BSCs */
2350testcase TC_reset_two() runs on MTC_CT {
2351 var BSC_ConnHdlr vc_conn;
2352 f_init(2);
2353 f_sleep(2.0);
2354 setverdict(pass);
2355}
2356
Harald Weltee13cfb22019-04-23 16:52:02 +02002357/* Two BSSMAP resets from two different BSCs plus one IuCS RANAP Reset */
2358testcase TC_reset_two_1iu() runs on MTC_CT {
2359 var BSC_ConnHdlr vc_conn;
2360 f_init(3);
2361 f_sleep(2.0);
2362 setverdict(pass);
2363}
2364
Harald Weltef640a012018-04-14 17:49:21 +02002365/***********************************************************************
2366 * SMS Testing
2367 ***********************************************************************/
2368
Harald Weltef45efeb2018-04-09 18:19:24 +02002369/* LU followed by MO SMS */
Harald Weltee13cfb22019-04-23 16:52:02 +02002370friend function f_tc_lu_and_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02002371 var SmsParameters spars := valueof(t_SmsPars);
2372
2373 f_init_handler(pars);
2374
2375 /* Perform location update and call */
2376 f_perform_lu();
2377
2378 f_establish_fully(EST_TYPE_MO_SMS);
2379
2380 //spars.exp_rp_err := 96; /* invalid mandatory information */
2381 f_mo_sms(spars);
2382
2383 f_expect_clear();
2384}
2385testcase TC_lu_and_mo_sms() runs on MTC_CT {
2386 var BSC_ConnHdlr vc_conn;
2387 f_init();
2388 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_sms), 42);
2389 vc_conn.done;
2390}
2391
Harald Weltee13cfb22019-04-23 16:52:02 +02002392
Harald Weltef45efeb2018-04-09 18:19:24 +02002393private function f_vty_sms_send(charstring imsi, charstring msisdn, charstring text)
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002394runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02002395 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
2396}
2397
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01002398/* Remove still pending SMS */
2399private function f_vty_sms_clear(charstring imsi)
2400runs on BSC_ConnHdlr {
2401 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " sms delete-all");
2402 f_vty_transceive(MSCVTY, "sms-queue clear");
2403}
2404
Harald Weltef45efeb2018-04-09 18:19:24 +02002405/* LU followed by MT SMS */
Harald Weltee13cfb22019-04-23 16:52:02 +02002406friend function f_tc_lu_and_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02002407 var SmsParameters spars := valueof(t_SmsPars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002408
2409 f_init_handler(pars);
2410
2411 /* Perform location update and call */
2412 f_perform_lu();
2413
2414 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002415 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Weltef45efeb2018-04-09 18:19:24 +02002416
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002417 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
Harald Weltef45efeb2018-04-09 18:19:24 +02002418
2419 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02002420 f_expect_paging();
2421
Harald Weltef45efeb2018-04-09 18:19:24 +02002422 /* Establish DTAP / BSSAP / SCCP connection */
2423 f_establish_fully(EST_TYPE_PAG_RESP);
2424
2425 spars.tp.ud := 'C8329BFD064D9B53'O;
2426 f_mt_sms(spars);
2427
2428 f_expect_clear();
2429}
2430testcase TC_lu_and_mt_sms() runs on MTC_CT {
2431 var BSC_ConnHdlrPars pars;
2432 var BSC_ConnHdlr vc_conn;
2433 f_init();
2434 pars := f_init_pars(43);
2435 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms), pars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002436 vc_conn.done;
2437}
2438
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01002439/* SMS added while already Paging */
2440friend function f_tc_lu_and_mt_sms_already_paging(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2441 var SmsParameters spars := valueof(t_SmsPars);
2442 var OCT4 tmsi;
2443
2444 f_init_handler(pars);
2445
2446 f_perform_lu();
2447
2448 /* register an 'expect' for given IMSI (+TMSI) */
2449 if (isvalue(g_pars.tmsi)) {
2450 tmsi := g_pars.tmsi;
2451 } else {
2452 tmsi := 'FFFFFFFF'O;
2453 }
2454 f_ran_register_imsi(g_pars.imsi, tmsi);
2455
2456 log("first SMS");
2457 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2458
2459 /* MSC->BSC: expect PAGING from MSC */
2460 f_expect_paging();
2461
2462 log("second SMS");
2463 /* Now osmo-msc is in state "Paging pending", make sure that another SMS to be sent at this time just joins in
2464 * with the pending paging. Another SMS: */
2465 f_vty_sms_send(hex2str(pars.imsi), "2342", "Another SMS");
2466
2467 /* Establish DTAP / BSSAP / SCCP connection */
2468 f_establish_fully(EST_TYPE_PAG_RESP);
2469
2470 spars.tp.ud := 'C8329BFD064D9B53'O;
2471 f_mt_sms(spars);
2472
2473 spars.tp.ud := '41F79B8E2ECB41D3E614'O;
2474 f_mt_sms(spars);
2475
2476 f_expect_clear();
2477}
2478testcase TC_lu_and_mt_sms_already_paging() runs on MTC_CT {
2479 var BSC_ConnHdlrPars pars;
2480 var BSC_ConnHdlr vc_conn;
2481 f_init();
2482 pars := f_init_pars(44);
2483 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_already_paging), pars);
2484 vc_conn.done;
2485}
Harald Weltee13cfb22019-04-23 16:52:02 +02002486
Philipp Maier3983e702018-11-22 19:01:33 +01002487/* Paging for MT SMS but no response */
Harald Weltee13cfb22019-04-23 16:52:02 +02002488friend function f_tc_lu_and_mt_sms_paging_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier3983e702018-11-22 19:01:33 +01002489 var SmsParameters spars := valueof(t_SmsPars);
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002490
Philipp Maier3983e702018-11-22 19:01:33 +01002491 f_init_handler(pars, 150.0);
2492
2493 /* Perform location update */
2494 f_perform_lu();
2495
2496 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002497 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Philipp Maier3983e702018-11-22 19:01:33 +01002498
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002499 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2500
Neels Hofmeyr16237742019-03-06 15:34:01 +01002501 /* Expect the MSC to page exactly once */
Harald Weltee13cfb22019-04-23 16:52:02 +02002502 f_expect_paging();
Philipp Maier3983e702018-11-22 19:01:33 +01002503
2504 /* Wait some time to make sure the MSC is not delivering any further
2505 * paging messages or anything else that could be unexpected. */
2506 timer T := 20.0;
2507 T.start
2508 alt {
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002509 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
2510 setverdict(fail, "paging seems not to stop!");
2511 mtc.stop;
Philipp Maier3983e702018-11-22 19:01:33 +01002512 }
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002513 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
2514 setverdict(fail, "paging seems not to stop!");
2515 mtc.stop;
Harald Weltee13cfb22019-04-23 16:52:02 +02002516 }
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002517 [] BSSAP.receive {
2518 setverdict(fail, "unexpected BSSAP message received");
2519 self.stop;
Philipp Maier3983e702018-11-22 19:01:33 +01002520 }
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002521 [] T.timeout {
2522 setverdict(pass);
Philipp Maier3983e702018-11-22 19:01:33 +01002523 }
2524 }
2525
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01002526 f_vty_sms_clear(hex2str(g_pars.imsi));
2527
Philipp Maier3983e702018-11-22 19:01:33 +01002528 setverdict(pass);
2529}
2530testcase TC_lu_and_mt_sms_paging_and_nothing() runs on MTC_CT {
2531 var BSC_ConnHdlrPars pars;
2532 var BSC_ConnHdlr vc_conn;
2533 f_init();
Philipp Maiera99ad262019-01-22 15:35:42 +01002534 pars := f_init_pars(1843);
Philipp Maier3983e702018-11-22 19:01:33 +01002535 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_paging_and_nothing), pars);
Philipp Maier3983e702018-11-22 19:01:33 +01002536 vc_conn.done;
2537}
2538
Alexander Couzensfc02f242019-09-12 03:43:18 +02002539/* LU followed by MT SMS with repeated paging */
2540friend function f_tc_lu_and_mt_sms_paging_repeated(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2541 var SmsParameters spars := valueof(t_SmsPars);
Alexander Couzensfc02f242019-09-12 03:43:18 +02002542
2543 f_init_handler(pars);
2544
2545 /* Perform location update and call */
2546 f_perform_lu();
2547
2548 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002549 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Alexander Couzensfc02f242019-09-12 03:43:18 +02002550
2551 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2552
Neels Hofmeyrc3accec2019-11-28 01:09:47 +01002553 log("Expecting first Paging");
Alexander Couzensfc02f242019-09-12 03:43:18 +02002554 /* MSC->BSC: expect PAGING from MSC */
2555 f_expect_paging();
2556
Neels Hofmeyrc3accec2019-11-28 01:09:47 +01002557 if (g_pars.ran_is_geran) {
2558 log("GERAN: expect no further Paging");
2559 } else {
2560 log("UTRAN: expect more Paging");
2561 }
2562
2563 timer T := 5.0;
2564 T.start;
2565 alt {
2566 [g_pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
2567 setverdict(fail, "GERAN should not repeat Paging, but received a second Paging");
2568 mtc.stop;
2569 }
2570 [not g_pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
2571 log("UTRAN: second Paging received, as expected");
2572 setverdict(pass);
2573 }
2574 [] T.timeout {
2575 if (g_pars.ran_is_geran) {
2576 log("GERAN: No further Paging received, as expected");
2577 setverdict(pass);
2578 } else {
2579 setverdict(fail, "UTRAN: Expected a second Paging");
2580 mtc.stop;
2581 }
2582 }
2583 }
Alexander Couzensfc02f242019-09-12 03:43:18 +02002584
2585 /* Establish DTAP / BSSAP / SCCP connection */
2586 f_establish_fully(EST_TYPE_PAG_RESP);
2587
2588 spars.tp.ud := 'C8329BFD064D9B53'O;
2589 f_mt_sms(spars);
2590
2591 f_expect_clear();
2592}
2593testcase TC_lu_and_mt_sms_paging_repeated() runs on MTC_CT {
2594 var BSC_ConnHdlrPars pars;
2595 var BSC_ConnHdlr vc_conn;
2596 f_init();
2597 pars := f_init_pars(1844);
2598 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_paging_repeated), pars);
2599 vc_conn.done;
2600}
Harald Weltee13cfb22019-04-23 16:52:02 +02002601
Harald Weltef640a012018-04-14 17:49:21 +02002602/* mobile originated SMS from MS/BTS/BSC side to SMPP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002603friend function f_tc_smpp_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef640a012018-04-14 17:49:21 +02002604 var SmsParameters spars := valueof(t_SmsPars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002605
Harald Weltef640a012018-04-14 17:49:21 +02002606 f_init_handler(pars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002607
Harald Weltef640a012018-04-14 17:49:21 +02002608 /* Perform location update so IMSI is known + registered in MSC/VLR */
2609 f_perform_lu();
Harald Weltef640a012018-04-14 17:49:21 +02002610
Vadim Yanitskiy2d3f8462020-01-15 11:44:12 +07002611 /* MS/UE submits a MO SMS */
2612 f_establish_fully(EST_TYPE_MO_SMS);
2613 f_mo_sms_submit(spars);
Harald Weltef640a012018-04-14 17:49:21 +02002614
2615 var SMPP_PDU smpp;
2616 var template SMPP_PDU tr_smpp := tr_SMPP(c_SMPP_command_id_deliver_sm, ESME_ROK);
2617 tr_smpp.body.deliver_sm := {
2618 service_type := "CMT",
2619 source_addr_ton := network_specific,
2620 source_addr_npi := isdn,
2621 source_addr := hex2str(pars.msisdn),
2622 dest_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
2623 dest_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
2624 destination_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
2625 esm_class := '00000001'B,
2626 protocol_id := 0,
2627 priority_flag := 0,
2628 schedule_delivery_time := "",
2629 replace_if_present := 0,
2630 data_coding := '00000001'B,
2631 sm_default_msg_id := 0,
2632 sm_length := ?,
2633 short_message := spars.tp.ud,
2634 opt_pars := {
2635 {
2636 tag := user_message_reference,
2637 len := 2,
2638 opt_value := {
2639 int2_val := oct2int(spars.tp.msg_ref)
2640 }
2641 }
2642 }
2643 };
2644 alt {
2645 [] SMPP.receive(tr_smpp) -> value smpp {
2646 SMPP.send(ts_SMPP_DELIVER_SM_resp(ESME_ROK, smpp.header.seq_num));
2647 }
2648 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK)) { repeat; }
2649 }
2650
Vadim Yanitskiy2d3f8462020-01-15 11:44:12 +07002651 /* MSC terminates the SMS transaction with RP-ACK */
2652 f_mo_sms_wait_rp_ack(spars);
2653
Harald Weltef640a012018-04-14 17:49:21 +02002654 f_expect_clear();
2655}
2656testcase TC_smpp_mo_sms() runs on MTC_CT {
2657 var BSC_ConnHdlr vc_conn;
2658 f_init();
2659 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "default-route");
2660 vc_conn := f_start_handler(refers(f_tc_smpp_mo_sms), 44);
2661 vc_conn.done;
2662 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "no default-route");
2663}
2664
Vadim Yanitskiy33820762020-01-15 11:26:07 +07002665/* Test case for OS#4351: make sure that RP-ERROR from ESME is properly sent to the MS/UE */
2666friend function f_tc_smpp_mo_sms_rp_error(charstring id, BSC_ConnHdlrPars pars)
2667runs on BSC_ConnHdlr {
2668 var SmsParameters spars := valueof(t_SmsPars);
2669 var SMPP_PDU smpp_pdu;
2670 timer T := 3.0;
2671
2672 f_init_handler(pars);
2673
2674 /* Perform location update */
2675 f_perform_lu();
2676
2677 /* MS/UE submits a MO SMS */
2678 f_establish_fully(EST_TYPE_MO_SMS);
2679 f_mo_sms_submit(spars);
2680
2681 /* ESME responds with an error (Invalid Destination Address) */
2682 T.start;
2683 alt {
2684 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_deliver_sm, ESME_ROK, body := ?)) -> value smpp_pdu {
2685 SMPP.send(ts_SMPP_DELIVER_SM_resp(ESME_RINVDSTADR, smpp_pdu.header.seq_num));
2686 }
2687 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK)) { repeat; }
2688 [] T.timeout {
2689 setverdict(fail, "Timeout waiting for SMPP DELIVER-SM");
2690 mtc.stop;
2691 }
2692 }
2693
2694 /* Expect RP-ERROR on BSSAP interface */
2695 spars.exp_rp_err := 1; /* FIXME: GSM411_RP_CAUSE_MO_NUM_UNASSIGNED */
2696 f_mo_sms_wait_rp_ack(spars);
2697
2698 f_expect_clear();
2699}
2700testcase TC_smpp_mo_sms_rp_error() runs on MTC_CT {
2701 var BSC_ConnHdlr vc_conn;
2702 f_init();
2703 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "default-route");
2704 vc_conn := f_start_handler(refers(f_tc_smpp_mo_sms_rp_error), 45);
2705 vc_conn.done;
2706 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "no default-route");
2707}
2708
Harald Weltee13cfb22019-04-23 16:52:02 +02002709
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002710/* Test MO-SMS from MS/BTS/BSC towards HLR (via GSUP) */
Harald Weltee13cfb22019-04-23 16:52:02 +02002711friend function f_tc_gsup_mo_sms(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002712runs on BSC_ConnHdlr {
2713 var SmsParameters spars := valueof(t_SmsPars);
2714 var GSUP_PDU gsup_msg_rx;
2715 var octetstring sm_tpdu;
2716
2717 f_init_handler(pars);
2718
2719 /* We need to inspect GSUP activity */
2720 f_create_gsup_expect(hex2str(g_pars.imsi));
2721
2722 /* Perform location update */
2723 f_perform_lu();
2724
2725 /* Send CM Service Request for SMS */
2726 f_establish_fully(EST_TYPE_MO_SMS);
2727
2728 /* Prepare expected SM-RP-UI (SM TPDU) */
2729 enc_TPDU_RP_DATA_MS_SGSN_fast(
2730 valueof(ts_SMS_SUBMIT(spars.tp.msg_ref,
2731 spars.tp.da, spars.tp.pid, spars.tp.dcs,
2732 spars.tp.udl, spars.tp.ud)),
2733 sm_tpdu);
2734
2735 var template GSUP_PDU mo_forwardSM := tr_GSUP_MO_FORWARD_SM_REQ(
2736 imsi := g_pars.imsi,
2737 sm_rp_mr := spars.rp.msg_ref,
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09002738 /* SM-RP-DA: SMSC address */
2739 sm_rp_da := tr_GSUP_SM_RP_DA_SMSC_ADDR(t_GSUP_SM_RP_Addr(
2740 number := spars.rp.smsc_addr.rP_NumberDigits,
2741 npi := spars.rp.smsc_addr.rP_NumberingPlanIdentification,
2742 ton := spars.rp.smsc_addr.rP_TypeOfNumber,
2743 ext := spars.rp.smsc_addr.rP_Ext)),
2744 /* SM-RP-OA: subscriber's MSISDN (filled in by MSC) */
2745 sm_rp_oa := tr_GSUP_SM_RP_OA_MSISDN(t_GSUP_SM_RP_Addr(
2746 number := g_pars.msisdn,
2747 /* NOTE: MSISDN in g_pars lacks this info, assuming defaults */
2748 npi := '0001'B, ton := '001'B, ext := '1'B)),
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002749 /* TODO: can we use decmatch here? */
2750 sm_rp_ui := sm_tpdu
2751 );
2752
2753 /* Submit an SMS on DTAP and expect MO-forwardSM-Req on GSUP */
2754 f_mo_sms_submit(spars);
2755 alt {
2756 [] GSUP.receive(mo_forwardSM) -> value gsup_msg_rx {
Vadim Yanitskiya358dd42020-01-15 10:42:47 +07002757 log("RX MO-forwardSM-Req: ", gsup_msg_rx);
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002758 setverdict(pass);
2759 }
2760 [] GSUP.receive {
2761 log("RX unexpected GSUP message");
2762 setverdict(fail);
2763 mtc.stop;
2764 }
2765 }
2766
2767 /* Trigger RP-ACK by sending MO-forwardSM-Res */
2768 GSUP.send(valueof(ts_GSUP_MO_FORWARD_SM_RES(
2769 imsi := g_pars.imsi,
2770 sm_rp_mr := spars.rp.msg_ref)));
2771 /* Expect RP-ACK on DTAP */
2772 f_mo_sms_wait_rp_ack(spars);
2773
2774 f_expect_clear();
2775}
2776testcase TC_gsup_mo_sms() runs on MTC_CT {
2777 var BSC_ConnHdlr vc_conn;
2778 f_init();
2779 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2780 vc_conn := f_start_handler(refers(f_tc_gsup_mo_sms), 88);
2781 vc_conn.done;
2782 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2783}
2784
Harald Weltee13cfb22019-04-23 16:52:02 +02002785
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002786/* Test MO-SMMA from MS/BTS/BSC towards HLR (via GSUP) */
Harald Weltee13cfb22019-04-23 16:52:02 +02002787friend function f_tc_gsup_mo_smma(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002788runs on BSC_ConnHdlr {
2789 var SmsParameters spars := valueof(t_SmsPars);
2790 var GSUP_PDU gsup_msg_rx;
2791
2792 f_init_handler(pars);
2793
2794 /* We need to inspect GSUP activity */
2795 f_create_gsup_expect(hex2str(g_pars.imsi));
2796
2797 /* Perform location update */
2798 f_perform_lu();
2799
2800 /* Send CM Service Request for SMS */
2801 f_establish_fully(EST_TYPE_MO_SMS);
2802
2803 var template GSUP_PDU mo_ReadyForSM := tr_GSUP_MO_READY_FOR_SM_REQ(
2804 imsi := g_pars.imsi,
2805 sm_rp_mr := spars.rp.msg_ref,
2806 sm_alert_rsn := GSUP_SM_ALERT_RSN_TYPE_MEM_AVAIL
2807 );
2808
2809 /* Submit an SMS on DTAP and expect MO-forwardSM-Req on GSUP */
2810 f_mo_smma(spars);
2811 alt {
2812 [] GSUP.receive(mo_ReadyForSM) -> value gsup_msg_rx {
Vadim Yanitskiya358dd42020-01-15 10:42:47 +07002813 log("RX MO-ReadyForSM-Req: ", gsup_msg_rx);
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002814 setverdict(pass);
2815 }
2816 [] GSUP.receive {
2817 log("RX unexpected GSUP message");
2818 setverdict(fail);
2819 mtc.stop;
2820 }
2821 }
2822
2823 /* Trigger RP-ACK by sending MO-forwardSM-Res */
2824 GSUP.send(valueof(ts_GSUP_MO_READY_FOR_SM_RES(
2825 imsi := g_pars.imsi,
2826 sm_rp_mr := spars.rp.msg_ref)));
2827 /* Expect RP-ACK on DTAP */
2828 f_mo_sms_wait_rp_ack(spars);
2829
2830 f_expect_clear();
2831}
2832testcase TC_gsup_mo_smma() runs on MTC_CT {
2833 var BSC_ConnHdlr vc_conn;
2834 f_init();
2835 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2836 vc_conn := f_start_handler(refers(f_tc_gsup_mo_smma), 89);
2837 vc_conn.done;
2838 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2839}
2840
Harald Weltee13cfb22019-04-23 16:52:02 +02002841
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002842/* Helper for sending MT SMS over GSUP */
2843private function f_gsup_forwardSM_req(SmsParameters spars, OCT1 mms := '00'O)
2844runs on BSC_ConnHdlr {
Vadim Yanitskiya52347c2019-12-12 17:32:33 +09002845 var GSUP_SM_RP_Addr msisdn := valueof(t_GSUP_SM_RP_Addr(g_pars.msisdn));
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09002846 var GSUP_SM_RP_Addr smsc := valueof(t_GSUP_SM_RP_Addr(
2847 number := spars.rp.smsc_addr.rP_NumberDigits,
2848 npi := spars.rp.smsc_addr.rP_NumberingPlanIdentification,
2849 ton := spars.rp.smsc_addr.rP_TypeOfNumber,
2850 ext := spars.rp.smsc_addr.rP_Ext));
Vadim Yanitskiya52347c2019-12-12 17:32:33 +09002851
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002852 GSUP.send(ts_GSUP_MT_FORWARD_SM_REQ(
2853 imsi := g_pars.imsi,
2854 /* NOTE: MSC should assign RP-MR itself */
2855 sm_rp_mr := 'FF'O,
Vadim Yanitskiya52347c2019-12-12 17:32:33 +09002856 sm_rp_da := valueof(ts_GSUP_SM_RP_DA_MSISDN(msisdn)),
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09002857 sm_rp_oa := valueof(ts_GSUP_SM_RP_OA_SMSC_ADDR(smsc)),
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002858 /* Encoded SMS TPDU (taken from Wireshark)
2859 * FIXME: we should encode spars somehow */
2860 sm_rp_ui := '00068021436500008111328130858200'O,
2861 sm_rp_mms := mms
2862 ));
2863}
2864
2865/* Test successful MT-SMS (RP-ACK) over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002866friend function f_tc_gsup_mt_sms_ack(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002867runs on BSC_ConnHdlr {
2868 var SmsParameters spars := valueof(t_SmsPars);
2869
2870 f_init_handler(pars);
2871
2872 /* We need to inspect GSUP activity */
2873 f_create_gsup_expect(hex2str(g_pars.imsi));
2874
2875 /* Perform location update */
2876 f_perform_lu();
2877
2878 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002879 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002880
2881 var template GSUP_PDU mt_forwardSM_res := tr_GSUP_MT_FORWARD_SM_RES(
2882 imsi := g_pars.imsi,
2883 /* NOTE: MSC should assign RP-MR itself */
2884 sm_rp_mr := ?
2885 );
2886
2887 /* Submit a MT SMS on GSUP */
2888 f_gsup_forwardSM_req(spars);
2889
2890 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002891 f_expect_paging();
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002892 f_establish_fully(EST_TYPE_PAG_RESP);
2893
2894 /* Wait for MT SMS on DTAP */
2895 f_mt_sms_expect(spars);
2896
2897 /* Send RP-ACK and expect MT-forwardSM-Res on GSUP */
2898 f_mt_sms_send_rp_ack(spars);
2899 alt {
2900 [] GSUP.receive(mt_forwardSM_res) {
2901 log("RX MT-forwardSM-Res (RP-ACK)");
2902 setverdict(pass);
2903 }
2904 [] GSUP.receive {
2905 log("RX unexpected GSUP message");
2906 setverdict(fail);
2907 mtc.stop;
2908 }
2909 }
2910
2911 f_expect_clear();
2912}
2913testcase TC_gsup_mt_sms_ack() runs on MTC_CT {
2914 var BSC_ConnHdlrPars pars;
2915 var BSC_ConnHdlr vc_conn;
2916 f_init();
2917 pars := f_init_pars(90);
2918 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2919 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_ack), pars);
2920 vc_conn.done;
2921 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2922}
2923
Harald Weltee13cfb22019-04-23 16:52:02 +02002924
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002925/* Test rejected MT-SMS (RP-ERROR) over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002926friend function f_tc_gsup_mt_sms_err(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002927runs on BSC_ConnHdlr {
2928 var SmsParameters spars := valueof(t_SmsPars);
2929 var OCT1 sm_rp_cause := '78'O; /* dummy RP-Cause value */
2930
2931 f_init_handler(pars);
2932
2933 /* We need to inspect GSUP activity */
2934 f_create_gsup_expect(hex2str(g_pars.imsi));
2935
2936 /* Perform location update */
2937 f_perform_lu();
2938
2939 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002940 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002941
2942 var template GSUP_PDU mt_forwardSM_err := tr_GSUP_MT_FORWARD_SM_ERR(
2943 imsi := g_pars.imsi,
2944 /* NOTE: MSC should assign RP-MR itself */
2945 sm_rp_mr := ?,
2946 sm_rp_cause := sm_rp_cause
2947 );
2948
2949 /* Submit a MT SMS on GSUP */
2950 f_gsup_forwardSM_req(spars);
2951
2952 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002953 f_expect_paging();
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002954 f_establish_fully(EST_TYPE_PAG_RESP);
2955
2956 /* Wait for MT SMS on DTAP */
2957 f_mt_sms_expect(spars);
2958
2959 /* Send RP-ERROR and expect MT-forwardSM-Err on GSUP */
2960 f_mt_sms_send_rp_error(spars, oct2int(sm_rp_cause));
2961 alt {
2962 [] GSUP.receive(mt_forwardSM_err) {
2963 log("RX MT-forwardSM-Err (RP-ERROR)");
2964 setverdict(pass);
2965 mtc.stop;
2966 }
2967 [] GSUP.receive {
2968 log("RX unexpected GSUP message");
2969 setverdict(fail);
2970 mtc.stop;
2971 }
2972 }
2973
2974 f_expect_clear();
2975}
2976testcase TC_gsup_mt_sms_err() runs on MTC_CT {
2977 var BSC_ConnHdlrPars pars;
2978 var BSC_ConnHdlr vc_conn;
2979 f_init();
2980 pars := f_init_pars(91);
2981 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2982 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_err), pars);
2983 vc_conn.done;
2984 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2985}
2986
Harald Weltee13cfb22019-04-23 16:52:02 +02002987
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002988/* Test SM-RP-MR assignment for MT-SMS over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002989friend function f_tc_gsup_mt_sms_rp_mr(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002990runs on BSC_ConnHdlr {
2991 var SmsParameters spars1 := valueof(t_SmsPars); /* 1st SMS */
2992 var SmsParameters spars2 := valueof(t_SmsPars); /* 2nd SMS */
2993
2994 f_init_handler(pars);
2995
2996 /* We need to inspect GSUP activity */
2997 f_create_gsup_expect(hex2str(g_pars.imsi));
2998
2999 /* Perform location update */
3000 f_perform_lu();
3001
3002 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01003003 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07003004
3005 /* Submit the 1st MT SMS on GSUP */
3006 log("TX MT-forwardSM-Req for the 1st SMS");
3007 f_gsup_forwardSM_req(spars1);
3008
3009 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02003010 f_expect_paging();
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07003011 f_establish_fully(EST_TYPE_PAG_RESP);
3012
3013 /* Wait for 1st MT SMS on DTAP */
3014 f_mt_sms_expect(spars1);
3015 log("RX the 1st SMS on DTAP, DTAP TID is ", spars1.tid,
3016 ", SM-RP-MR is ", spars1.rp.msg_ref);
3017
3018 /* Submit the 2nd MT SMS on GSUP */
3019 log("TX MT-forwardSM-Req for the 2nd SMS");
3020 f_gsup_forwardSM_req(spars2);
3021
3022 /* Wait for 2nd MT SMS on DTAP */
3023 f_mt_sms_expect(spars2);
3024 log("RX the 2nd SMS on DTAP, DTAP TID is ", spars2.tid,
3025 ", SM-RP-MR is ", spars2.rp.msg_ref);
3026
3027 /* Both transaction IDs shall be different */
3028 if (spars1.tid == spars2.tid) {
3029 log("Both DTAP transaction IDs shall be different");
3030 setverdict(fail);
3031 }
3032
3033 /* Both SM-RP-MR values shall be different */
3034 if (spars1.rp.msg_ref == spars2.rp.msg_ref) {
3035 log("Both SM-RP-MR values shall be different");
3036 setverdict(fail);
3037 }
3038
3039 /* Both SM-RP-MR values shall be assigned */
3040 if (spars1.rp.msg_ref == 'FF'O) {
3041 log("Unassigned SM-RP-MR value for the 1st SMS");
3042 setverdict(fail);
3043 }
3044 if (spars2.rp.msg_ref == 'FF'O) {
3045 log("Unassigned SM-RP-MR value for the 2nd SMS");
3046 setverdict(fail);
3047 }
3048
3049 /* Send the 1st RP-ACK and expect MT-forwardSM-Res on GSUP */
3050 f_mt_sms_send_rp_ack(spars1);
3051 alt {
3052 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
3053 imsi := g_pars.imsi,
3054 sm_rp_mr := spars1.rp.msg_ref
3055 )) {
3056 log("RX MT-forwardSM-Res (RP-ACK)");
3057 setverdict(pass);
3058 }
3059 [] GSUP.receive {
3060 log("RX unexpected GSUP message");
3061 setverdict(fail);
3062 mtc.stop;
3063 }
3064 }
3065
3066 /* Send the 2nd RP-ACK and expect MT-forwardSM-Res on GSUP */
3067 f_mt_sms_send_rp_ack(spars2);
3068 alt {
3069 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
3070 imsi := g_pars.imsi,
3071 sm_rp_mr := spars2.rp.msg_ref
3072 )) {
3073 log("RX MT-forwardSM-Res (RP-ACK)");
3074 setverdict(pass);
3075 }
3076 [] GSUP.receive {
3077 log("RX unexpected GSUP message");
3078 setverdict(fail);
3079 mtc.stop;
3080 }
3081 }
3082
3083 f_expect_clear();
3084}
3085testcase TC_gsup_mt_sms_rp_mr() runs on MTC_CT {
3086 var BSC_ConnHdlrPars pars;
3087 var BSC_ConnHdlr vc_conn;
3088 f_init();
3089 pars := f_init_pars(92);
3090 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
3091 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_rp_mr), pars);
3092 vc_conn.done;
3093 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
3094}
3095
Harald Weltee13cfb22019-04-23 16:52:02 +02003096
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07003097/* Test SM-RP-MR assignment for MT-SMS over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02003098friend function f_tc_gsup_mo_mt_sms_rp_mr(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07003099runs on BSC_ConnHdlr {
3100 var SmsParameters spars_mo := valueof(t_SmsPars); /* MO SMMA */
3101 var SmsParameters spars_mt := valueof(t_SmsPars); /* MT SMS */
3102
3103 f_init_handler(pars);
3104
3105 /* We need to inspect GSUP activity */
3106 f_create_gsup_expect(hex2str(g_pars.imsi));
3107
3108 /* Perform location update */
3109 f_perform_lu();
3110
3111 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01003112 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07003113
3114 /* Send CM Service Request for MO SMMA */
3115 f_establish_fully(EST_TYPE_MO_SMS);
3116
3117 /* Submit MO SMMA on DTAP */
3118 log("Submit MO SMMA on DTAP, SM-RP-MR is '00'O");
3119 spars_mo.rp.msg_ref := '00'O;
3120 f_mo_smma(spars_mo);
3121
3122 /* Expect MO-forwardSM-Req for MO SMMA on GSUP */
3123 alt {
3124 [] GSUP.receive(tr_GSUP_MO_READY_FOR_SM_REQ(
3125 imsi := g_pars.imsi,
3126 sm_rp_mr := spars_mo.rp.msg_ref,
3127 sm_alert_rsn := GSUP_SM_ALERT_RSN_TYPE_MEM_AVAIL
3128 )) {
3129 log("RX MO-ReadyForSM-Req, SM-RP-MR is '00'O");
3130 setverdict(pass);
3131 }
3132 [] GSUP.receive {
3133 log("RX unexpected GSUP message");
3134 setverdict(fail);
3135 mtc.stop;
3136 }
3137 }
3138
3139 /* Submit MT SMS on GSUP */
3140 log("TX MT-forwardSM-Req for the MT SMS");
3141 f_gsup_forwardSM_req(spars_mt);
3142
3143 /* Wait for MT SMS on DTAP */
3144 f_mt_sms_expect(spars_mt);
3145 log("RX MT SMS on DTAP, DTAP TID is ", spars_mt.tid,
3146 ", SM-RP-MR is ", spars_mt.rp.msg_ref);
3147
3148 /* Both SM-RP-MR values shall be different */
3149 if (spars_mo.rp.msg_ref == spars_mt.rp.msg_ref) {
3150 log("Both SM-RP-MR values shall be different");
3151 setverdict(fail);
3152 }
3153
3154 /* SM-RP-MR value for MT SMS shall be assigned */
3155 if (spars_mt.rp.msg_ref == 'FF'O) {
3156 log("Unassigned SM-RP-MR value for the MT SMS");
3157 setverdict(fail);
3158 }
3159
3160 /* Trigger RP-ACK for MO SMMA by sending MO-forwardSM-Res */
3161 GSUP.send(valueof(ts_GSUP_MO_READY_FOR_SM_RES(
3162 imsi := g_pars.imsi,
3163 sm_rp_mr := spars_mo.rp.msg_ref)));
3164 /* Expect RP-ACK for MO SMMA on DTAP */
3165 f_mo_sms_wait_rp_ack(spars_mo);
3166
3167 /* Send RP-ACK for MT SMS and expect MT-forwardSM-Res on GSUP */
3168 f_mt_sms_send_rp_ack(spars_mt);
3169 alt {
3170 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
3171 imsi := g_pars.imsi,
3172 sm_rp_mr := spars_mt.rp.msg_ref
3173 )) {
3174 log("RX MT-forwardSM-Res (RP-ACK)");
3175 setverdict(pass);
3176 }
3177 [] GSUP.receive {
3178 log("RX unexpected GSUP message");
3179 setverdict(fail);
3180 mtc.stop;
3181 }
3182 }
3183
3184 f_expect_clear();
3185}
3186testcase TC_gsup_mo_mt_sms_rp_mr() runs on MTC_CT {
3187 var BSC_ConnHdlrPars pars;
3188 var BSC_ConnHdlr vc_conn;
3189 f_init();
3190 pars := f_init_pars(93);
3191 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
3192 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mo_mt_sms_rp_mr), pars);
3193 vc_conn.done;
3194 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
3195}
3196
Harald Weltee13cfb22019-04-23 16:52:02 +02003197
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07003198/* Test multi-part MT-SMS over GSUP */
3199private function f_tc_gsup_mt_multi_part_sms(charstring id, BSC_ConnHdlrPars pars)
3200runs on BSC_ConnHdlr {
3201 var SmsParameters spars := valueof(t_SmsPars);
3202
3203 f_init_handler(pars);
3204
3205 /* We need to inspect GSUP activity */
3206 f_create_gsup_expect(hex2str(g_pars.imsi));
3207
3208 /* Perform location update */
3209 f_perform_lu();
3210
3211 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01003212 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07003213
3214 var template GSUP_PDU mt_forwardSM_res := tr_GSUP_MT_FORWARD_SM_RES(
3215 imsi := g_pars.imsi,
3216 /* NOTE: MSC should assign RP-MR itself */
3217 sm_rp_mr := ?
3218 );
3219
3220 /* Send 4 messages (NOTE: SM-RP-UI remains unchanged) */
3221 for (var integer i := 3; i >= 0; i := i-1) {
3222 /* Submit a MT SMS on GSUP (MMS is decremented) */
3223 f_gsup_forwardSM_req(spars, int2oct(i, 1));
3224
3225 /* Expect Paging Request and Establish connection */
3226 if (i == 3) { /* ... only once! */
Harald Weltee13cfb22019-04-23 16:52:02 +02003227 f_expect_paging();
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07003228 f_establish_fully(EST_TYPE_PAG_RESP);
3229 }
3230
3231 /* Wait for MT SMS on DTAP */
3232 f_mt_sms_expect(spars);
3233
3234 /* Send RP-ACK and expect MT-forwardSM-Res on GSUP */
3235 f_mt_sms_send_rp_ack(spars);
3236 alt {
3237 [] GSUP.receive(mt_forwardSM_res) {
3238 log("RX MT-forwardSM-Res (RP-ACK)");
3239 setverdict(pass);
3240 }
3241 [] GSUP.receive {
3242 log("RX unexpected GSUP message");
3243 setverdict(fail);
3244 mtc.stop;
3245 }
3246 }
3247
3248 /* Keep some 'distance' between transmissions */
3249 f_sleep(1.5);
3250 }
3251
3252 f_expect_clear();
3253}
3254testcase TC_gsup_mt_multi_part_sms() runs on MTC_CT {
3255 var BSC_ConnHdlrPars pars;
3256 var BSC_ConnHdlr vc_conn;
3257 f_init();
3258 pars := f_init_pars(91);
3259 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
3260 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_multi_part_sms), pars);
3261 vc_conn.done;
3262 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
3263}
3264
Harald Weltef640a012018-04-14 17:49:21 +02003265/* convert GSM L3 TON to SMPP_TON enum */
3266function f_sm_ton_from_gsm(BIT3 ton) return SMPP_TON {
3267 select (ton) {
3268 case ('000'B) { return unknown; }
3269 case ('001'B) { return international; }
3270 case ('010'B) { return national; }
3271 case ('011'B) { return network_specific; }
3272 case ('100'B) { return subscriber_number; }
3273 case ('101'B) { return alphanumeric; }
3274 case ('110'B) { return abbreviated; }
3275 }
3276 setverdict(fail, "Unknown TON ", ton);
Daniel Willmannafce8662018-07-06 23:11:32 +02003277 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02003278}
3279/* convert GSM L3 NPI to SMPP_NPI enum */
3280function f_sm_npi_from_gsm(BIT4 npi) return SMPP_NPI {
3281 select (npi) {
3282 case ('0000'B) { return unknown; }
3283 case ('0001'B) { return isdn; }
3284 case ('0011'B) { return data; }
3285 case ('0100'B) { return telex; }
3286 case ('0110'B) { return land_mobile; }
3287 case ('1000'B) { return national; }
3288 case ('1001'B) { return private_; }
3289 case ('1010'B) { return ermes; }
3290 }
3291 setverdict(fail, "Unknown NPI ", npi);
Daniel Willmannafce8662018-07-06 23:11:32 +02003292 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02003293}
3294
3295/* build a SMPP_SM from SmsParameters */
3296function f_mt_sm_from_spars(SmsParameters spars)
3297runs on BSC_ConnHdlr return SMPP_SM {
3298 var SMPP_SM sm := {
3299 service_type := "CMT",
3300 source_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
3301 source_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
3302 source_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
3303 dest_addr_ton := international,
3304 dest_addr_npi := isdn,
3305 destination_addr := hex2str(g_pars.msisdn),
3306 esm_class := '00000001'B,
3307 protocol_id := 0,
3308 priority_flag := 0,
3309 schedule_delivery_time := "",
3310 validity_period := "",
3311 registered_delivery := '00000000'B,
3312 replace_if_present := 0,
3313 data_coding := '00000001'B,
3314 sm_default_msg_id := 0,
3315 sm_length := spars.tp.udl,
3316 short_message := spars.tp.ud,
3317 opt_pars := {}
3318 };
3319 return sm;
3320}
3321
3322/* helper function to encode SMS from 'spars', send it via SMPP to MSC; receive it on MS side */
3323private function f_smpp_mt_sms(SmsParameters spars, boolean trans_mode) runs on BSC_ConnHdlr {
3324 var SMPP_SM sm := f_mt_sm_from_spars(spars);
3325 if (trans_mode) {
3326 sm.esm_class := '00000010'B;
3327 }
3328
3329 /* actually cause MSC to send a SMS via SUBMIT-SM from SMPP side */
3330 SMPP.send(ts_SMPP_SUBMIT_SM(sm));
3331 if (not match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
3332 /* if we're not in SMPP transaction mode, we expect the SMPP-level ACK
3333 * before we expect the SMS delivery on the BSC/radio side */
3334 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
3335 }
3336
3337 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02003338 f_expect_paging();
Harald Weltef640a012018-04-14 17:49:21 +02003339 /* Establish DTAP / BSSAP / SCCP connection */
3340 f_establish_fully(EST_TYPE_PAG_RESP);
3341 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
3342
3343 f_mt_sms(spars);
3344
3345 if (match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
3346 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
3347 }
3348 f_expect_clear();
3349}
3350
3351/* mobile terminated SMS, from SMPP to BSC/BTS/MS */
3352private function f_tc_smpp_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3353 f_init_handler(pars);
3354
3355 /* Perform location update so IMSI is known + registered in MSC/VLR */
3356 f_perform_lu();
3357 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
3358
3359 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01003360 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Weltef640a012018-04-14 17:49:21 +02003361
3362 var SmsParameters spars := valueof(t_SmsPars);
3363 /* TODO: test with more intelligent user data; test different coding schemes */
3364 spars.tp.ud := '00'O;
3365 spars.tp.udl := 1;
3366
3367 /* first test the non-transaction store+forward mode */
3368 f_smpp_mt_sms(spars, false);
3369
3370 /* then test the transaction mode */
3371 f_smpp_mt_sms(spars, true);
3372}
3373testcase TC_smpp_mt_sms() runs on MTC_CT {
3374 var BSC_ConnHdlr vc_conn;
3375 f_init();
3376 vc_conn := f_start_handler(refers(f_tc_smpp_mt_sms), 45);
3377 vc_conn.done;
3378}
3379
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003380/***********************************************************************
3381 * USSD Testing
3382 ***********************************************************************/
3383
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003384private altstep as_unexp_gsup_or_bssap_msg()
3385runs on BSC_ConnHdlr {
3386 [] GSUP.receive {
3387 setverdict(fail, "Unknown/unexpected GSUP received");
3388 self.stop;
3389 }
3390 [] BSSAP.receive {
3391 setverdict(fail, "Unknown/unexpected BSSAP message received");
3392 self.stop;
3393 }
3394}
3395
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003396private function f_expect_gsup_msg(template GSUP_PDU msg,
3397 float T_val := 2.0)
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003398runs on BSC_ConnHdlr return GSUP_PDU {
3399 var GSUP_PDU gsup_msg_complete;
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003400 timer T := T_val;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003401
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003402 T.start;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003403 alt {
3404 [] GSUP.receive(msg) -> value gsup_msg_complete {
3405 setverdict(pass);
3406 }
3407 /* We don't expect anything else */
3408 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003409 [] T.timeout {
3410 setverdict(fail, "Timeout waiting for GSUP message: ", msg);
3411 }
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003412 }
3413
3414 return gsup_msg_complete;
3415}
3416
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003417private function f_expect_mt_dtap_msg(template PDU_ML3_NW_MS msg,
3418 float T_val := 2.0)
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003419runs on BSC_ConnHdlr return PDU_ML3_NW_MS {
3420 var PDU_DTAP_MT bssap_msg_complete;
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003421 timer T := T_val;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003422
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003423 T.start;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003424 alt {
3425 [] BSSAP.receive(tr_PDU_DTAP_MT(msg)) -> value bssap_msg_complete {
3426 setverdict(pass);
3427 }
3428 /* We don't expect anything else */
3429 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003430 [] T.timeout {
3431 setverdict(fail, "Timeout waiting for BSSAP message: ", msg);
3432 }
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003433 }
3434
3435 return bssap_msg_complete.dtap;
3436}
3437
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003438/* LU followed by MO USSD request */
Harald Weltee13cfb22019-04-23 16:52:02 +02003439friend function f_tc_lu_and_mo_ussd_single_request(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003440runs on BSC_ConnHdlr {
3441 f_init_handler(pars);
3442
3443 /* Perform location update */
3444 f_perform_lu();
3445
3446 /* Send CM Service Request for SS/USSD */
3447 f_establish_fully(EST_TYPE_SS_ACT);
3448
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003449 /* We need to inspect GSUP activity */
3450 f_create_gsup_expect(hex2str(g_pars.imsi));
3451
3452 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3453 invoke_id := 5, /* Phone may not start from 0 or 1 */
3454 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3455 ussd_string := "*#100#"
3456 );
3457
3458 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3459 invoke_id := 5, /* InvokeID shall be the same for both REQ and RSP */
3460 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3461 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
3462 )
3463
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003464 /* Compose a new SS/REGISTER message with request */
3465 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
3466 tid := 1, /* We just need a single transaction */
3467 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003468 facility := valueof(facility_req)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003469 );
3470
3471 /* Compose SS/RELEASE_COMPLETE template with expected response */
3472 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
3473 tid := 1, /* Response should arrive within the same transaction */
3474 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003475 facility := valueof(facility_rsp)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003476 );
3477
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003478 /* Compose expected MSC -> HLR message */
3479 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
3480 imsi := g_pars.imsi,
3481 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3482 ss := valueof(facility_req)
3483 );
3484
3485 /* To be used for sending response with correct session ID */
3486 var GSUP_PDU gsup_req_complete;
3487
3488 /* Request own number */
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003489 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003490 /* Expect GSUP message containing the SS payload */
3491 gsup_req_complete := f_expect_gsup_msg(gsup_req);
3492
3493 /* Compose the response from HLR using received session ID */
3494 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
3495 imsi := g_pars.imsi,
3496 sid := gsup_req_complete.ies[1].val.session_id,
3497 state := OSMO_GSUP_SESSION_STATE_END,
3498 ss := valueof(facility_rsp)
3499 );
3500
3501 /* Finally, HLR terminates the session */
3502 GSUP.send(gsup_rsp);
3503 /* Expect RELEASE_COMPLETE message with the response */
3504 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003505
3506 f_expect_clear();
3507}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003508testcase TC_lu_and_mo_ussd_single_request() runs on MTC_CT {
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003509 var BSC_ConnHdlr vc_conn;
3510 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003511 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_single_request), 46);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003512 vc_conn.done;
3513}
3514
Harald Weltee13cfb22019-04-23 16:52:02 +02003515
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003516/* LU followed by MT USSD notification */
Harald Weltee13cfb22019-04-23 16:52:02 +02003517friend function f_tc_lu_and_mt_ussd_notification(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003518runs on BSC_ConnHdlr {
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003519 timer T := 5.0;
3520
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003521 f_init_handler(pars);
3522
3523 /* Perform location update */
3524 f_perform_lu();
3525
Harald Welte6811d102019-04-14 22:23:14 +02003526 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003527
3528 /* We need to inspect GSUP activity */
3529 f_create_gsup_expect(hex2str(g_pars.imsi));
3530
3531 /* Facility IE with network-originated USSD notification */
3532 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3533 op_code := SS_OP_CODE_USS_NOTIFY,
3534 ussd_string := "Mahlzeit!"
3535 );
3536
3537 /* Facility IE with acknowledgment to the USSD notification */
3538 var template OCTN facility_rsp := enc_SS_FacilityInformation(
3539 /* In case of USSD notification, Return Result is empty */
3540 valueof(ts_SS_USSD_FACILITY_RETURN_RESULT_EMPTY())
3541 );
3542
3543 /* Compose a new MT SS/REGISTER message with USSD notification */
3544 var template PDU_ML3_NW_MS ussd_ntf := tr_ML3_MT_SS_REGISTER(
3545 tid := 0, /* FIXME: most likely, it should be 0 */
3546 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3547 facility := valueof(facility_req)
3548 );
3549
3550 /* Compose HLR -> MSC GSUP message */
3551 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3552 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003553 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003554 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3555 ss := valueof(facility_req)
3556 );
3557
3558 /* Send it to MSC and expect Paging Request */
3559 GSUP.send(gsup_req);
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003560 T.start;
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003561 alt {
Harald Weltee13cfb22019-04-23 16:52:02 +02003562 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
3563 setverdict(pass);
3564 }
Harald Welte62113fc2019-05-09 13:04:02 +02003565 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003566 setverdict(pass);
3567 }
3568 /* We don't expect anything else */
3569 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003570 [] T.timeout {
3571 setverdict(fail, "Timeout waiting for Paging Request");
3572 }
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003573 }
3574
3575 /* Send Paging Response and expect USSD notification */
3576 f_establish_fully(EST_TYPE_PAG_RESP);
3577 /* Expect MT REGISTER message with USSD notification */
3578 f_expect_mt_dtap_msg(ussd_ntf);
3579
3580 /* Compose a new MO SS/FACILITY message with empty response */
3581 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
3582 tid := 0, /* FIXME: it shall match the request tid */
3583 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3584 facility := valueof(facility_rsp)
3585 );
3586
3587 /* Compose expected MSC -> HLR GSUP message */
3588 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
3589 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003590 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003591 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3592 ss := valueof(facility_rsp)
3593 );
3594
3595 /* MS sends response to the notification */
3596 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
3597 /* Expect GSUP message containing the SS payload */
3598 f_expect_gsup_msg(gsup_rsp);
3599
3600 /* Compose expected MT SS/RELEASE COMPLETE message */
3601 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
3602 tid := 0, /* FIXME: it shall match the request tid */
3603 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3604 facility := omit
3605 );
3606
3607 /* Compose MSC -> HLR GSUP message */
3608 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
3609 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003610 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003611 state := OSMO_GSUP_SESSION_STATE_END
3612 );
3613
3614 /* Finally, HLR terminates the session */
3615 GSUP.send(gsup_term)
3616 /* Expect MT RELEASE COMPLETE without Facility IE */
3617 f_expect_mt_dtap_msg(ussd_term);
3618
3619 f_expect_clear();
3620}
3621testcase TC_lu_and_mt_ussd_notification() runs on MTC_CT {
3622 var BSC_ConnHdlr vc_conn;
3623 f_init();
3624 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_notification), 47);
3625 vc_conn.done;
3626}
3627
Harald Weltee13cfb22019-04-23 16:52:02 +02003628
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003629/* LU followed by MT call and MO USSD request during this call */
Harald Weltee13cfb22019-04-23 16:52:02 +02003630friend function f_tc_lu_and_mo_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003631runs on BSC_ConnHdlr {
3632 f_init_handler(pars);
3633
3634 /* Call parameters taken from f_tc_lu_and_mt_call */
3635 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003636
3637 /* Perform location update */
3638 f_perform_lu();
3639
3640 /* Establish a MT call */
3641 f_mt_call_establish(cpars);
3642
3643 /* Hold the call for some time */
3644 f_sleep(1.0);
3645
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003646 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3647 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3648 ussd_string := "*#100#"
3649 );
3650
3651 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3652 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3653 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
3654 )
3655
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003656 /* Compose a new SS/REGISTER message with request */
3657 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
3658 tid := 1, /* We just need a single transaction */
3659 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003660 facility := valueof(facility_req)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003661 );
3662
3663 /* Compose SS/RELEASE_COMPLETE template with expected response */
3664 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
3665 tid := 1, /* Response should arrive within the same transaction */
3666 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003667 facility := valueof(facility_rsp)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003668 );
3669
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003670 /* Compose expected MSC -> HLR message */
3671 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
3672 imsi := g_pars.imsi,
3673 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3674 ss := valueof(facility_req)
3675 );
3676
3677 /* To be used for sending response with correct session ID */
3678 var GSUP_PDU gsup_req_complete;
3679
3680 /* Request own number */
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003681 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003682 /* Expect GSUP message containing the SS payload */
3683 gsup_req_complete := f_expect_gsup_msg(gsup_req);
3684
3685 /* Compose the response from HLR using received session ID */
3686 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
3687 imsi := g_pars.imsi,
3688 sid := gsup_req_complete.ies[1].val.session_id,
3689 state := OSMO_GSUP_SESSION_STATE_END,
3690 ss := valueof(facility_rsp)
3691 );
3692
3693 /* Finally, HLR terminates the session */
3694 GSUP.send(gsup_rsp);
3695 /* Expect RELEASE_COMPLETE message with the response */
3696 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003697
3698 /* Hold the call for some time */
3699 f_sleep(1.0);
3700
3701 /* Release the call (does Clear Complete itself) */
3702 f_call_hangup(cpars, true);
3703}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003704testcase TC_lu_and_mo_ussd_during_mt_call() runs on MTC_CT {
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003705 var BSC_ConnHdlr vc_conn;
3706 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003707 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_during_mt_call), 48);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003708 vc_conn.done;
3709}
3710
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003711/* BSSMAP Clear Request in the middle of a call, see OS#3062 */
Harald Weltee13cfb22019-04-23 16:52:02 +02003712friend function f_tc_mo_cc_bssmap_clear(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003713 f_init_handler(pars);
3714 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02003715 cpars.ran_clear_when_alerting := true;
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003716
3717 f_perform_lu();
3718
Neels Hofmeyrde76f052019-02-26 05:02:46 +01003719 var default ccrel := activate(as_optional_cc_rel(cpars));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02003720 f_mo_call_establish(cpars);
3721 f_expect_clear()
Neels Hofmeyrde76f052019-02-26 05:02:46 +01003722 deactivate(ccrel);
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003723
3724 f_sleep(1.0);
3725}
3726testcase TC_mo_cc_bssmap_clear() runs on MTC_CT {
3727 var BSC_ConnHdlr vc_conn;
3728 f_init();
3729
3730 vc_conn := f_start_handler(refers(f_tc_mo_cc_bssmap_clear), 43);
3731 vc_conn.done;
3732}
3733
Harald Weltee13cfb22019-04-23 16:52:02 +02003734
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003735/* LU followed by MT call and MT USSD request during this call */
Harald Weltee13cfb22019-04-23 16:52:02 +02003736friend function f_tc_lu_and_mt_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003737runs on BSC_ConnHdlr {
3738 f_init_handler(pars);
3739
3740 /* Call parameters taken from f_tc_lu_and_mt_call */
3741 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003742
3743 /* Perform location update */
3744 f_perform_lu();
3745
3746 /* Establish a MT call */
3747 f_mt_call_establish(cpars);
3748
3749 /* Hold the call for some time */
3750 f_sleep(1.0);
3751
3752 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3753 op_code := SS_OP_CODE_USS_REQUEST,
3754 ussd_string := "Please type anything..."
3755 );
3756
3757 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3758 op_code := SS_OP_CODE_USS_REQUEST,
3759 ussd_string := "Nope."
3760 )
3761
3762 /* Compose MT SS/REGISTER message with network-originated request */
3763 var template (value) PDU_ML3_NW_MS ussd_req := ts_ML3_MT_SS_REGISTER(
3764 tid := 0, /* FIXME: most likely, it should be 0 */
3765 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3766 facility := valueof(facility_req)
3767 );
3768
3769 /* Compose HLR -> MSC GSUP message */
3770 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3771 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003772 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003773 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3774 ss := valueof(facility_req)
3775 );
3776
3777 /* Send it to MSC */
3778 GSUP.send(gsup_req);
3779 /* Expect MT REGISTER message with USSD request */
3780 f_expect_mt_dtap_msg(ussd_req);
3781
3782 /* Compose a new MO SS/FACILITY message with response */
3783 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
3784 tid := 0, /* FIXME: it shall match the request tid */
3785 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3786 facility := valueof(facility_rsp)
3787 );
3788
3789 /* Compose expected MSC -> HLR GSUP message */
3790 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
3791 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003792 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003793 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3794 ss := valueof(facility_rsp)
3795 );
3796
3797 /* MS sends response */
3798 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
3799 f_expect_gsup_msg(gsup_rsp);
3800
3801 /* Compose expected MT SS/RELEASE COMPLETE message */
3802 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
3803 tid := 0, /* FIXME: it shall match the request tid */
3804 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3805 facility := omit
3806 );
3807
3808 /* Compose MSC -> HLR GSUP message */
3809 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
3810 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003811 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003812 state := OSMO_GSUP_SESSION_STATE_END
3813 );
3814
3815 /* Finally, HLR terminates the session */
3816 GSUP.send(gsup_term);
3817 /* Expect MT RELEASE COMPLETE without Facility IE */
3818 f_expect_mt_dtap_msg(ussd_term);
3819
3820 /* Hold the call for some time */
3821 f_sleep(1.0);
3822
3823 /* Release the call (does Clear Complete itself) */
3824 f_call_hangup(cpars, true);
3825}
3826testcase TC_lu_and_mt_ussd_during_mt_call() runs on MTC_CT {
3827 var BSC_ConnHdlr vc_conn;
3828 f_init();
3829 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_during_mt_call), 49);
3830 vc_conn.done;
3831}
3832
Harald Weltee13cfb22019-04-23 16:52:02 +02003833
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07003834/* LU followed by MO USSD request and MO Release during transaction */
Harald Weltee13cfb22019-04-23 16:52:02 +02003835friend function f_tc_lu_and_mo_ussd_mo_release(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07003836runs on BSC_ConnHdlr {
3837 f_init_handler(pars);
3838
3839 /* Perform location update */
3840 f_perform_lu();
3841
3842 /* Send CM Service Request for SS/USSD */
3843 f_establish_fully(EST_TYPE_SS_ACT);
3844
3845 /* We need to inspect GSUP activity */
3846 f_create_gsup_expect(hex2str(g_pars.imsi));
3847
3848 var template OCTN facility_ms_req := f_USSD_FACILITY_IE_INVOKE(
3849 invoke_id := 1, /* Initial request */
3850 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3851 ussd_string := "*6766*266#"
3852 );
3853
3854 var template OCTN facility_net_req := f_USSD_FACILITY_IE_INVOKE(
3855 invoke_id := 2, /* Counter request */
3856 op_code := SS_OP_CODE_USS_REQUEST,
3857 ussd_string := "Password?!?"
3858 )
3859
3860 /* Compose MO SS/REGISTER message with request */
3861 var template (value) PDU_ML3_MS_NW ussd_ms_req := ts_ML3_MO_SS_REGISTER(
3862 tid := 1, /* We just need a single transaction */
3863 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3864 facility := valueof(facility_ms_req)
3865 );
3866
3867 /* Compose expected MSC -> HLR message */
3868 var template GSUP_PDU gsup_ms_req := tr_GSUP_PROC_SS_REQ(
3869 imsi := g_pars.imsi,
3870 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3871 ss := valueof(facility_ms_req)
3872 );
3873
3874 /* To be used for sending response with correct session ID */
3875 var GSUP_PDU gsup_ms_req_complete;
3876
3877 /* Initiate a new transaction */
3878 BSSAP.send(ts_PDU_DTAP_MO(ussd_ms_req));
3879 /* Expect GSUP request with original Facility IE */
3880 gsup_ms_req_complete := f_expect_gsup_msg(gsup_ms_req);
3881
3882 /* Compose the response from HLR using received session ID */
3883 var template (value) GSUP_PDU gsup_net_req := ts_GSUP_PROC_SS_REQ(
3884 imsi := g_pars.imsi,
3885 sid := gsup_ms_req_complete.ies[1].val.session_id,
3886 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3887 ss := valueof(facility_net_req)
3888 );
3889
3890 /* Compose expected MT SS/FACILITY template with counter request */
3891 var template PDU_ML3_NW_MS ussd_net_req := tr_ML3_MT_SS_FACILITY(
3892 tid := 1, /* Response should arrive within the same transaction */
3893 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3894 facility := valueof(facility_net_req)
3895 );
3896
3897 /* Send response over GSUP */
3898 GSUP.send(gsup_net_req);
3899 /* Expect MT SS/FACILITY message with counter request */
3900 f_expect_mt_dtap_msg(ussd_net_req);
3901
3902 /* Compose MO SS/RELEASE COMPLETE */
3903 var template (value) PDU_ML3_MS_NW ussd_abort := ts_ML3_MO_SS_RELEASE_COMPLETE(
3904 tid := 1, /* Response should arrive within the same transaction */
3905 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3906 facility := omit
3907 /* TODO: cause? */
3908 );
3909
3910 /* Compose expected HLR -> MSC abort message */
3911 var template GSUP_PDU gsup_abort := tr_GSUP_PROC_SS_REQ(
3912 imsi := g_pars.imsi,
3913 sid := gsup_ms_req_complete.ies[1].val.session_id,
3914 state := OSMO_GSUP_SESSION_STATE_END
3915 );
3916
3917 /* Abort transaction */
3918 BSSAP.send(ts_PDU_DTAP_MO(ussd_abort));
3919 /* Expect GSUP message indicating abort */
3920 f_expect_gsup_msg(gsup_abort);
3921
3922 f_expect_clear();
3923}
3924testcase TC_lu_and_mo_ussd_mo_release() runs on MTC_CT {
3925 var BSC_ConnHdlr vc_conn;
3926 f_init();
3927 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_mo_release), 50);
3928 vc_conn.done;
3929}
3930
Harald Weltee13cfb22019-04-23 16:52:02 +02003931
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003932/* LU followed by MO USSD request and MT Release due to timeout */
Harald Weltee13cfb22019-04-23 16:52:02 +02003933friend function f_tc_lu_and_ss_session_timeout(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003934runs on BSC_ConnHdlr {
3935 f_init_handler(pars);
3936
3937 /* Perform location update */
3938 f_perform_lu();
3939
3940 /* Send CM Service Request for SS/USSD */
3941 f_establish_fully(EST_TYPE_SS_ACT);
3942
3943 /* We need to inspect GSUP activity */
3944 f_create_gsup_expect(hex2str(g_pars.imsi));
3945
3946 var template OCTN facility_ms_req := f_USSD_FACILITY_IE_INVOKE(
3947 invoke_id := 1,
3948 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3949 ussd_string := "#release_me");
3950
3951 /* Compose MO SS/REGISTER message with request */
3952 var template (value) PDU_ML3_MS_NW ussd_ms_req := ts_ML3_MO_SS_REGISTER(
3953 tid := 1, /* An arbitrary transaction identifier */
3954 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3955 facility := valueof(facility_ms_req));
3956
3957 /* Compose expected MSC -> HLR message */
3958 var template GSUP_PDU gsup_ms_req := tr_GSUP_PROC_SS_REQ(
3959 imsi := g_pars.imsi,
3960 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3961 ss := valueof(facility_ms_req));
3962
3963 /* To be used for sending response with correct session ID */
3964 var GSUP_PDU gsup_ms_req_complete;
3965
3966 /* Initiate a new SS transaction */
3967 BSSAP.send(ts_PDU_DTAP_MO(ussd_ms_req));
3968 /* Expect GSUP request with original Facility IE */
3969 gsup_ms_req_complete := f_expect_gsup_msg(gsup_ms_req);
3970
3971 /* Don't respond, wait for timeout */
3972 f_sleep(3.0);
3973
3974 var template PDU_ML3_NW_MS dtap_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
3975 tid := 1, /* Should match the request's tid */
3976 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3977 cause := *, /* TODO: expect some specific value */
3978 facility := omit);
3979
3980 var template GSUP_PDU gsup_rel := tr_GSUP_PROC_SS_ERR(
3981 imsi := g_pars.imsi,
3982 sid := gsup_ms_req_complete.ies[1].val.session_id,
3983 state := OSMO_GSUP_SESSION_STATE_END,
3984 cause := ?); /* TODO: expect some specific value */
3985
3986 /* Expect release on both interfaces */
3987 interleave {
3988 [] BSSAP.receive(tr_PDU_DTAP_MT(dtap_rel)) { };
3989 [] GSUP.receive(gsup_rel) { };
3990 }
3991
3992 f_expect_clear();
3993 setverdict(pass);
3994}
3995testcase TC_lu_and_ss_session_timeout() runs on MTC_CT {
3996 var BSC_ConnHdlr vc_conn;
3997 f_init();
Vadim Yanitskiy36d28dd2018-12-03 02:45:45 +07003998 f_vty_config(MSCVTY, "msc", "ncss guard-timeout 3");
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003999 vc_conn := f_start_handler(refers(f_tc_lu_and_ss_session_timeout), 51);
4000 vc_conn.done;
Vadim Yanitskiy36d28dd2018-12-03 02:45:45 +07004001 f_vty_config(MSCVTY, "msc", "ncss guard-timeout 0");
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07004002}
4003
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07004004/* MT (network-originated) USSD for unknown subscriber */
4005friend function f_tc_mt_ussd_for_unknown_subscr(charstring id, BSC_ConnHdlrPars pars)
4006runs on BSC_ConnHdlr {
4007 var hexstring imsi := '000000000000000'H; /* Some unknown IMSI */
4008 var OCT4 sid := '20000222'O;
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07004009
4010 f_init_handler(pars);
4011 f_ran_register_imsi(imsi, 'FFFFFFFF'O);
4012 f_create_gsup_expect(hex2str(imsi));
4013
4014 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
4015 imsi := imsi,
4016 sid := sid,
4017 state := OSMO_GSUP_SESSION_STATE_BEGIN,
4018 ss := f_rnd_octstring(23)
4019 );
4020
4021 /* Error with cause GMM_CAUSE_IMSI_UNKNOWN */
4022 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
4023 imsi := imsi,
4024 sid := sid,
4025 state := OSMO_GSUP_SESSION_STATE_END,
4026 cause := 2 /* FIXME: introduce an enumerated type! */
4027 );
4028
4029 /* Initiate a MT USSD notification */
4030 GSUP.send(gsup_req);
4031
4032 /* Expect GSUP PROC_SS_ERROR message */
Vadim Yanitskiy851798c2019-06-15 14:22:28 +07004033 f_expect_gsup_msg(gsup_rsp);
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07004034}
4035testcase TC_mt_ussd_for_unknown_subscr() runs on MTC_CT {
4036 var BSC_ConnHdlr vc_conn;
4037 f_init();
4038 vc_conn := f_start_handler(refers(f_tc_mt_ussd_for_unknown_subscr), 0);
4039 vc_conn.done;
4040}
4041
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07004042/* MO (mobile-originated) SS/USSD for unknown transaction */
4043friend function f_tc_mo_ussd_for_unknown_trans(charstring id, BSC_ConnHdlrPars pars)
4044runs on BSC_ConnHdlr {
4045 f_init_handler(pars);
4046
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01004047 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07004048 f_create_gsup_expect(hex2str(g_pars.imsi));
4049
4050 /* Perform location update */
4051 f_perform_lu();
4052
4053 /* Send CM Service Request for SS/USSD */
4054 f_establish_fully(EST_TYPE_SS_ACT);
4055
4056 /* GSM 04.80 FACILITY message for a non-existing transaction */
4057 var template (value) PDU_ML3_MS_NW mo_ss_fac := ts_ML3_MO_SS_FACILITY(
4058 tid := 1, /* An arbitrary transaction identifier */
4059 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
4060 facility := f_rnd_octstring(23) /* We don't care about the Facility IE */
4061 );
4062
4063 /* GSM 04.80 RELEASE COMPLETE message for a non-existing transaction */
4064 var template (value) PDU_ML3_MS_NW mo_ss_rel := ts_ML3_MO_SS_RELEASE_COMPLETE(
4065 tid := 1, /* An arbitrary transaction identifier */
4066 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
4067 facility := f_rnd_octstring(23) /* We don't care about the Facility IE */
4068 );
4069
4070 /* Expected response from the network */
4071 var template PDU_ML3_NW_MS mt_ss_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
4072 tid := 1, /* Same as in the FACILITY message */
4073 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
4074 facility := omit
4075 );
4076
4077 /* Send GSM 04.80 FACILITY for non-existing transaction */
4078 BSSAP.send(ts_PDU_DTAP_MO(mo_ss_fac));
4079
4080 /* Expect GSM 04.80 RELEASE COMPLETE message */
4081 f_expect_mt_dtap_msg(mt_ss_rel);
4082 f_expect_clear();
4083
4084 /* Send another CM Service Request for SS/USSD */
4085 f_establish_fully(EST_TYPE_SS_ACT);
4086
4087 /* Send GSM 04.80 RELEASE COMPLETE for non-existing transaction */
4088 BSSAP.send(ts_PDU_DTAP_MO(mo_ss_rel));
4089
4090 /* Expect GSM 04.80 RELEASE COMPLETE message */
4091 f_expect_mt_dtap_msg(mt_ss_rel);
4092 f_expect_clear();
4093}
4094testcase TC_mo_ussd_for_unknown_trans() runs on MTC_CT {
4095 var BSC_ConnHdlr vc_conn;
4096 f_init();
4097 vc_conn := f_start_handler(refers(f_tc_mo_ussd_for_unknown_trans), 111);
4098 vc_conn.done;
4099}
4100
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07004101/* MT (network-originated) USSD for unknown session */
4102friend function f_tc_proc_ss_for_unknown_session(charstring id, BSC_ConnHdlrPars pars)
4103runs on BSC_ConnHdlr {
4104 var OCT4 sid := '20000333'O;
4105
4106 f_init_handler(pars);
4107
4108 /* Perform location update */
4109 f_perform_lu();
4110
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01004111 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07004112 f_create_gsup_expect(hex2str(g_pars.imsi));
4113
4114 /* Request referencing a non-existing SS session */
4115 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
4116 imsi := g_pars.imsi,
4117 sid := sid,
4118 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
4119 ss := f_rnd_octstring(23)
4120 );
4121
4122 /* Error with some cause value */
4123 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
4124 imsi := g_pars.imsi,
4125 sid := sid,
4126 state := OSMO_GSUP_SESSION_STATE_END,
4127 cause := ? /* FIXME: introduce an enumerated type! */
4128 );
4129
4130 /* Initiate a MT USSD notification */
4131 GSUP.send(gsup_req);
4132
4133 /* Expect GSUP PROC_SS_ERROR message */
4134 f_expect_gsup_msg(gsup_rsp);
4135}
4136testcase TC_proc_ss_for_unknown_session() runs on MTC_CT {
4137 var BSC_ConnHdlr vc_conn;
4138 f_init();
4139 vc_conn := f_start_handler(refers(f_tc_proc_ss_for_unknown_session), 110);
4140 vc_conn.done;
4141}
4142
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07004143/* MT (network-originated) USSD and no response to Paging Request */
4144friend function f_tc_proc_ss_paging_fail(charstring id, BSC_ConnHdlrPars pars)
4145runs on BSC_ConnHdlr {
4146 timer TP := 2.0; /* Paging timer */
4147
4148 f_init_handler(pars);
4149
4150 /* Perform location update */
4151 f_perform_lu();
4152
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01004153 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07004154 f_create_gsup_expect(hex2str(g_pars.imsi));
4155
4156 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
4157 imsi := g_pars.imsi,
4158 sid := '20000444'O,
4159 state := OSMO_GSUP_SESSION_STATE_BEGIN,
4160 ss := f_rnd_octstring(23)
4161 );
4162
4163 /* Error with some cause value */
4164 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
4165 imsi := g_pars.imsi,
4166 sid := '20000444'O,
4167 state := OSMO_GSUP_SESSION_STATE_END,
4168 cause := ? /* FIXME: introduce an enumerated type! */
4169 );
4170
4171 /* Initiate a MT USSD notification */
4172 GSUP.send(gsup_req);
4173
4174 /* Send it to MSC and expect Paging Request */
4175 TP.start;
4176 alt {
4177 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
4178 setverdict(pass);
4179 }
4180 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
4181 setverdict(pass);
4182 }
4183 /* We don't expect anything else */
4184 [] as_unexp_gsup_or_bssap_msg();
4185 [] TP.timeout {
4186 setverdict(fail, "Timeout waiting for Paging Request");
4187 }
4188 }
4189
Vadim Yanitskiyd24b5252019-10-02 00:04:51 +07004190 /* Wait up to 20 seconds for GSUP PROC_SS_ERROR message.
4191 * OsmoMSC waits for Paging Response 10 seconds by default. */
4192 f_expect_gsup_msg(gsup_rsp, T_val := 20.0);
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07004193}
4194testcase TC_proc_ss_paging_fail() runs on MTC_CT {
4195 var BSC_ConnHdlr vc_conn;
4196 f_init();
4197 vc_conn := f_start_handler(refers(f_tc_proc_ss_paging_fail), 101);
4198 vc_conn.done;
4199}
4200
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07004201/* MT (network-originated) USSD followed by immediate abort */
4202friend function f_tc_proc_ss_abort(charstring id, BSC_ConnHdlrPars pars)
4203runs on BSC_ConnHdlr {
4204 var octetstring facility := f_rnd_octstring(23);
4205 var OCT4 sid := '20000555'O;
4206 timer TP := 2.0;
4207
4208 f_init_handler(pars);
4209
4210 /* Perform location update */
4211 f_perform_lu();
4212
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01004213 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07004214 f_create_gsup_expect(hex2str(g_pars.imsi));
4215
4216 /* PROC_SS_REQ initiates a mobile-originated SS/USSD session */
4217 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
4218 imsi := g_pars.imsi, sid := sid,
4219 state := OSMO_GSUP_SESSION_STATE_BEGIN,
4220 ss := facility
4221 );
4222
4223 /* On the MS side, we expect GSM 04.80 REGISTER message */
4224 var template PDU_ML3_NW_MS dtap_reg := tr_ML3_MT_SS_REGISTER(
4225 tid := 0, /* Most likely, it should be 0 */
4226 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
4227 facility := facility
4228 );
4229
4230 /* PROC_SS_ERR with SESSION_STATE_END terminates the SS/USSD session */
4231 var template (value) GSUP_PDU gsup_abort := ts_GSUP_PROC_SS_ERR(
4232 imsi := g_pars.imsi, sid := sid,
4233 state := OSMO_GSUP_SESSION_STATE_END,
4234 cause := 0 /* FIXME: introduce an enumerated type! */
4235 );
4236
4237 /* On the MS side, we expect GSM 04.80 REGISTER message */
4238 var template PDU_ML3_NW_MS dtap_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
4239 tid := 0, /* Most likely, it should be 0 */
4240 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
4241 cause := *, /* FIXME: expect some specific cause value */
4242 facility := omit
4243 );
4244
4245 /* Initiate a MT USSD with random payload */
4246 GSUP.send(gsup_req);
4247
4248 /* Expect Paging Request */
4249 TP.start;
4250 alt {
4251 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
4252 setverdict(pass);
4253 }
4254 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
4255 setverdict(pass);
4256 }
4257 /* We don't expect anything else */
4258 [] as_unexp_gsup_or_bssap_msg();
4259 [] TP.timeout {
4260 setverdict(fail, "Timeout waiting for Paging Request");
4261 }
4262 }
4263
4264 /* Send Paging Response and establish connection */
4265 f_establish_fully(EST_TYPE_PAG_RESP);
4266 /* Expect MT REGISTER message with random facility */
4267 f_expect_mt_dtap_msg(dtap_reg);
4268
4269 /* HLR/EUSE decides to abort the session even
4270 * before getting any response from the MS */
4271 /* Initiate a MT USSD with random payload */
4272 GSUP.send(gsup_abort);
4273
4274 /* Expect RELEASE COMPLETE on ths MS side */
4275 f_expect_mt_dtap_msg(dtap_rel);
4276
4277 f_expect_clear();
4278}
4279testcase TC_proc_ss_abort() runs on MTC_CT {
4280 var BSC_ConnHdlr vc_conn;
4281 f_init();
4282 vc_conn := f_start_handler(refers(f_tc_proc_ss_abort), 102);
4283 vc_conn.done;
4284}
4285
Harald Weltee13cfb22019-04-23 16:52:02 +02004286
Vadim Yanitskiy1c9754d2020-01-07 21:56:55 +01004287/* Verify multiple concurrent MO SS/USSD transactions
4288 * (one subscriber - one transaction) */
4289testcase TC_multi_lu_and_mo_ussd() runs on MTC_CT {
4290 var BSC_ConnHdlr vc_conn[16];
4291 var integer i;
4292
4293 f_init();
4294
4295 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
4296 vc_conn[i] := f_start_handler(refers(f_tc_lu_and_mo_ussd_single_request), 210 + i);
4297 }
4298
4299 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
4300 vc_conn[i].done;
4301 }
4302}
4303
4304/* Verify multiple concurrent MT SS/USSD transactions
4305 * (one subscriber - one transaction) */
4306testcase TC_multi_lu_and_mt_ussd() runs on MTC_CT {
4307 var BSC_ConnHdlr vc_conn[16];
4308 var integer i;
4309 var OCT4 sid;
4310
4311 f_init();
4312
4313 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
4314 sid := '200001'O & int2oct(i, 1); /* All transactions must use different session ID */
4315 vc_conn[i] := f_start_handler_with_pars(refers(f_tc_lu_and_mt_ussd_notification),
4316 f_init_pars(226 + i, gsup_sid := sid));
4317 }
4318
4319 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
4320 vc_conn[i].done;
4321 }
4322}
4323
4324
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004325/* A5/1 only permitted on network side; attempt an invalid CIPHER MODE COMPLETE with A5/3 which MSC should reject. */
4326private function f_tc_cipher_complete_with_invalid_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4327 pars.net.expect_auth := true;
4328 pars.net.expect_ciph := true;
4329 pars.net.kc_support := '02'O; /* A5/1 only */
4330 f_init_handler(pars);
4331
4332 g_pars.vec := f_gen_auth_vec_2g();
4333
4334 /* Can't use f_perform_lu() directly. Code below is based on it. */
4335
4336 /* tell GSUP dispatcher to send this IMSI to us */
4337 f_create_gsup_expect(hex2str(g_pars.imsi));
4338
4339 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
4340 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
Harald Weltedceacc72019-04-21 20:58:35 +02004341 f_cl3_or_initial_ue(l3_lu);
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004342
4343 f_mm_auth();
4344
4345 var OCT1 a5_net := f_alg_mask_from_cm(g_pars.cm2);
4346 var OCT1 a5_intersect := g_pars.net.kc_support and4b a5_net;
4347 alt {
4348 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(a5_intersect, g_pars.vec.kc)) {
4349 BSSAP.send(ts_BSSMAP_CipherModeCompl(int2oct(4 /* "accept" A5/3 */, 1)));
4350 }
4351 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?, g_pars.vec.kc)) {
4352 setverdict(fail, "Wrong ciphering algorithm mask in CiphModCmd");
4353 mtc.stop;
4354 }
4355 [] BSSAP.receive {
4356 setverdict(fail, "Unknown/unexpected BSSAP received");
4357 mtc.stop;
4358 }
4359 }
Harald Welte79f1e452020-08-18 22:55:02 +02004360 f_expect_common_id();
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004361
4362 /* Expect LU reject from MSC. */
4363 alt {
4364 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
4365 setverdict(pass);
4366 }
4367 [] BSSAP.receive {
4368 setverdict(fail, "Unknown/unexpected BSSAP received");
4369 mtc.stop;
4370 }
4371 }
Stefan Sperlingc620b352018-12-18 17:23:36 +01004372 f_expect_clear();
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004373}
4374
4375testcase TC_cipher_complete_with_invalid_cipher() runs on MTC_CT {
4376 var BSC_ConnHdlr vc_conn;
4377 f_init();
4378 f_vty_config(MSCVTY, "network", "encryption a5 1");
4379
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02004380 vc_conn := f_start_handler(refers(f_tc_cipher_complete_with_invalid_cipher), 52, verify_cell_id := false);
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004381 vc_conn.done;
4382}
4383
Harald Welteb2284bd2019-05-10 11:30:43 +02004384/* Location Update with invalid (non-matching) MCC/MNC reported on BSSMAP level from BSC */
4385friend function f_tc_lu_with_invalid_mcc_mnc(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4386 f_init_handler(pars);
4387
4388 /* tell GSUP dispatcher to send this IMSI to us */
4389 f_create_gsup_expect(hex2str(g_pars.imsi));
4390
4391 /* modify the cell ID which will be used to construct the COMPLELTE L3 or InitialUE */
4392 g_pars.cell_id := valueof(ts_CellId_CGI('333'H, '22'H, 23, 42));
4393
4394 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
4395 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
4396 f_cl3_or_initial_ue(l3_lu);
Harald Welte79f1e452020-08-18 22:55:02 +02004397 f_expect_common_id();
Harald Welteb2284bd2019-05-10 11:30:43 +02004398
4399 /* Expect LU reject from MSC. */
4400 alt {
4401 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
4402 setverdict(pass);
4403 }
4404 [] BSSAP.receive {
4405 setverdict(fail, "Unknown/unexpected BSSAP received");
4406 mtc.stop;
4407 }
4408 }
4409 f_expect_clear();
4410}
4411testcase TC_lu_with_invalid_mcc_mnc() runs on MTC_CT {
4412 var BSC_ConnHdlr vc_conn;
4413 f_init();
4414 vc_conn := f_start_handler(refers(f_tc_lu_with_invalid_mcc_mnc), 54);
4415 vc_conn.done;
4416}
4417
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01004418private function f_tc_cipher_complete_without_alg(charstring id, BSC_ConnHdlrPars pars, octetstring kc_support) runs on BSC_ConnHdlr {
4419 pars.net.expect_auth := true;
4420 pars.net.expect_ciph := true;
4421 pars.net.kc_support := kc_support;
4422 f_init_handler(pars);
4423
4424 g_pars.vec := f_gen_auth_vec_2g();
4425
4426 /* Can't use f_perform_lu() directly. Code below is based on it. */
4427
4428 /* tell GSUP dispatcher to send this IMSI to us */
4429 f_create_gsup_expect(hex2str(g_pars.imsi));
4430
4431 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
4432 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
4433 f_cl3_or_initial_ue(l3_lu);
4434
4435 f_mm_auth();
4436
4437 var OCT1 a5_net := f_alg_mask_from_cm(g_pars.cm2);
4438 var OCT1 a5_intersect := g_pars.net.kc_support and4b a5_net;
4439 alt {
4440 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(a5_intersect, g_pars.vec.kc)) {
4441 BSSAP.send(ts_BSSMAP_CipherModeComplAlg(omit));
4442 }
4443 [] BSSAP.receive(tr_BSSMAP_ClassmarkReq) {
4444 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
4445 repeat;
4446 }
4447 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?, g_pars.vec.kc)) {
4448 setverdict(fail, "Wrong ciphering algorithm mask in CiphModCmd");
4449 mtc.stop;
4450 }
4451 [] BSSAP.receive {
4452 setverdict(fail, "Unknown/unexpected BSSAP received");
4453 mtc.stop;
4454 }
4455 }
Harald Welte79f1e452020-08-18 22:55:02 +02004456 f_expect_common_id();
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01004457
4458 /* TODO: Verify MSC is using the best cipher available! How? */
4459
4460 f_msc_lu_hlr();
4461 f_accept_reject_lu();
4462 f_expect_clear();
4463 setverdict(pass);
4464}
4465
4466/* A5/1 only permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
4467private function f_tc_cipher_complete_1_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4468 f_tc_cipher_complete_without_alg(id, pars, '02'O /* A5/1 only */);
4469}
4470
4471/* A5/3 only permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
4472private function f_tc_cipher_complete_3_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4473 f_tc_cipher_complete_without_alg(id, pars, '08'O /* A5/3 only */);
4474}
4475
4476/* A5/1 + A5/3 permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
4477private function f_tc_cipher_complete_13_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4478 f_tc_cipher_complete_without_alg(id, pars, '0A'O /* A5/1 and A5/3 enabled */);
4479}
4480
4481testcase TC_cipher_complete_1_without_cipher() runs on MTC_CT {
4482 var BSC_ConnHdlr vc_conn;
4483 f_init();
4484 f_vty_config(MSCVTY, "network", "encryption a5 1");
4485
4486 vc_conn := f_start_handler(refers(f_tc_cipher_complete_1_without_cipher), 53);
4487 vc_conn.done;
4488}
4489
4490testcase TC_cipher_complete_3_without_cipher() runs on MTC_CT {
4491 var BSC_ConnHdlr vc_conn;
4492 f_init();
4493 f_vty_config(MSCVTY, "network", "encryption a5 3");
4494
4495 vc_conn := f_start_handler(refers(f_tc_cipher_complete_3_without_cipher), 54);
4496 vc_conn.done;
4497}
4498
4499testcase TC_cipher_complete_13_without_cipher() runs on MTC_CT {
4500 var BSC_ConnHdlr vc_conn;
4501 f_init();
4502 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
4503
4504 vc_conn := f_start_handler(refers(f_tc_cipher_complete_13_without_cipher), 55);
4505 vc_conn.done;
4506}
Harald Welteb2284bd2019-05-10 11:30:43 +02004507
Harald Weltef640a012018-04-14 17:49:21 +02004508/* TODO (SMS):
4509 * different user data lengths
4510 * SMPP transaction mode with unsuccessful delivery
4511 * queued MT-SMS with no paging response + later delivery
4512 * different data coding schemes
4513 * multi-part SMS
4514 * user-data headers
4515 * TP-PID for SMS to SIM
4516 * behavior if SMS memory is full + RP-SMMA
4517 * delivery reports
4518 * SMPP osmocom extensions
4519 * more-messages-to-send
4520 * SMS during ongoing call (SACCH/SAPI3)
4521 */
4522
4523/* TODO (General):
Harald Welteba7b6d92018-01-23 21:32:34 +01004524 * continue to send repeated MO signalling messages to keep channel open: does MSC tmeout?
4525 * malformed messages (missing IE, invalid message type): properly rejected?
4526 * MT call while LU or is ongoing: Do we use existing lchan or page while lchan active?
4527 * 3G/2G auth permutations
4528 * encryption algorithms vs. classmark vs. vty config
Harald Welteba7b6d92018-01-23 21:32:34 +01004529 * send new transaction after/during clear (like SMS, ...)
Harald Welte45164da2018-01-24 12:51:27 +01004530 * too long L3 INFO in DTAP
4531 * too long / padded BSSAP
4532 * too long / short TLV values
Harald Welteba7b6d92018-01-23 21:32:34 +01004533 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01004534
Harald Weltee13cfb22019-04-23 16:52:02 +02004535/***********************************************************************
4536 * SGsAP Testing
4537 ***********************************************************************/
4538
Philipp Maier948747b2019-04-02 15:22:33 +02004539/* Check if a subscriber exists in the VLR */
4540private function f_ctrl_subscr_in_vlr(charstring imsi_or_msisdn) runs on BSC_ConnHdlr return boolean {
4541
4542 var CtrlValue active_subsribers;
4543 var integer rc;
4544 active_subsribers := f_ctrl_get(IPA_CTRL, "subscriber-list-active-v1");
4545
4546 rc := f_strstr(active_subsribers, imsi_or_msisdn);
4547 if (rc < 0) {
4548 return false;
4549 }
4550
4551 return true;
4552}
4553
Pau Espin Pedrolcefe9da2021-07-02 18:38:27 +02004554/* Perform a Location Update at the A-Interface and run some checks to confirm
Harald Welte4263c522018-12-06 11:56:27 +01004555 * that everything is back to normal. */
4556private function f_sgsap_bssmap_screening() runs on BSC_ConnHdlr {
4557 var SmsParameters spars := valueof(t_SmsPars);
4558
Pau Espin Pedrol7593a8a2021-07-02 18:55:16 +02004559 /* From now on, since we initiated LU from A-Interface, we expect no
4560 * LastEutranPLMNId on Common Id, since the SGs interface should be gone
4561 */
4562 g_pars.common_id_last_eutran_plmn := omit;
4563
Harald Welte4263c522018-12-06 11:56:27 +01004564 /* Perform a location update, the SGs association is expected to fall
4565 * back to NULL */
4566 f_perform_lu();
4567 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4568
4569 /* Trigger a paging request and expect the paging on BSSMAP, this is
4570 * to make sure that pagings are sent throught the A-Interface again
4571 * and not throught the SGs interface.*/
Harald Welte6811d102019-04-14 22:23:14 +02004572 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Welte4263c522018-12-06 11:56:27 +01004573 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4574
4575 alt {
Harald Weltee13cfb22019-04-23 16:52:02 +02004576 [g_pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)); {
4577 setverdict(pass);
4578 }
Harald Welte62113fc2019-05-09 13:04:02 +02004579 [not g_pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
Harald Welte4263c522018-12-06 11:56:27 +01004580 setverdict(pass);
4581 }
4582 [] SGsAP.receive {
4583 setverdict(fail, "Received unexpected message on SGs");
4584 }
4585 }
4586
4587 /* Send an SMS to make sure that also payload messages are routed
4588 * throught the A-Interface again */
4589 f_establish_fully(EST_TYPE_MO_SMS);
4590 f_mo_sms(spars);
4591 f_expect_clear();
4592}
4593
4594private function f_tc_sgsap_reset(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4595 var charstring vlr_name;
4596 f_init_handler(pars);
4597
4598 vlr_name := f_sgsap_reset_mme(mp_mme_name);
4599 log("VLR name: ", vlr_name);
4600 setverdict(pass);
Neels Hofmeyrc0b520d2019-03-06 15:35:50 +01004601 f_sleep(1.0);
Harald Welte4263c522018-12-06 11:56:27 +01004602}
4603
4604testcase TC_sgsap_reset() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004605 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004606 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004607 f_init(1, true);
4608 pars := f_init_pars(11810, true);
4609 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_reset), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004610 vc_conn.done;
4611}
4612
4613/* like f_mm_auth() but for SGs */
4614function f_mm_auth_sgs() runs on BSC_ConnHdlr {
4615 if (g_pars.net.expect_auth) {
4616 g_pars.vec := f_gen_auth_vec_3g();
4617 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G3G(g_pars.vec.rand,
4618 g_pars.vec.sres,
4619 g_pars.vec.kc,
4620 g_pars.vec.ik,
4621 g_pars.vec.ck,
4622 g_pars.vec.autn,
4623 g_pars.vec.res));
4624 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
4625 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
4626 SGsAP.receive(tr_ML3_MT_MM_AUTH_REQ_3G(g_pars.vec.rand, g_pars.vec.autn));
4627 SGsAP.send(ts_ML3_MT_MM_AUTH_RESP_3G(g_pars.vec.sres, g_pars.vec.res));
4628 }
4629}
4630
4631/* like f_perform_lu(), but on SGs rather than BSSAP */
4632function f_sgs_perform_lu() runs on BSC_ConnHdlr {
4633 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4634 var PDU_SGsAP lur;
4635 var PDU_SGsAP lua;
4636 var PDU_SGsAP mm_info;
4637 var octetstring mm_info_dtap;
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004638 var GsmMcc mcc;
4639 var GsmMnc mnc;
4640 var template (omit) TrackingAreaIdentityValue tai := omit;
Harald Welte4263c522018-12-06 11:56:27 +01004641
4642 /* tell GSUP dispatcher to send this IMSI to us */
4643 f_create_gsup_expect(hex2str(g_pars.imsi));
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004644 if (g_pars.common_id_last_eutran_plmn != omit) {
4645 f_dec_mcc_mnc(g_pars.common_id_last_eutran_plmn, mcc, mnc);
4646 tai := ts_SGsAP_TAI(mcc, mnc, 555);
4647 }
Harald Welte4263c522018-12-06 11:56:27 +01004648 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
Pau Espin Pedrol3768a6f2021-04-28 14:24:23 +02004649 ts_SGsAP_LAI('901'H, '70'H, 2342),
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004650 tai));
Harald Welte4263c522018-12-06 11:56:27 +01004651 /* Old LAI, if MS sends it */
4652 /* TMSI status, if MS has no valid TMSI */
4653 /* IMEISV, if it supports "automatic device detection" */
4654 /* TAI, if available in MME */
4655 /* E-CGI, if available in MME */
4656 SGsAP.send(lur);
4657
4658 /* FIXME: is this really done over SGs? The Ue is already authenticated
4659 * via the MME ... */
4660 f_mm_auth_sgs();
4661
4662 /* Expect MSC to perform LU with HLR */
4663 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4664 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
4665 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
4666 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
4667
4668 alt {
4669 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) -> value lua {
4670 if (isvalue(lua.sGsAP_LOCATION_UPDATE_ACCEPT.newTMSIorIMSI.iD.iD.tmsi_ptmsi.octets)) {
4671 g_pars.tmsi :=lua.sGsAP_LOCATION_UPDATE_ACCEPT.newTMSIorIMSI.iD.iD.tmsi_ptmsi.octets
4672 SGsAP.send(ts_SGsAP_TMSI_REALL_CMPL(g_pars.imsi));
4673 }
4674 setverdict(pass);
4675 }
4676 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4677 setverdict(fail, "Received LU-REJECT instead of ACCEPT");
4678 }
4679 [] SGsAP.receive {
4680 setverdict(fail, "Received unexpected message on SGs");
4681 }
4682 }
4683
4684 /* Check MM information */
4685 if (mp_mm_info == true) {
4686 SGsAP.receive(tr_SGsAP_MM_INFO_REQ(g_pars.imsi, ?)) -> value mm_info;
4687 mm_info_dtap := '0532'O & mm_info.sGsAP_MM_INFORMATION_REQUEST.mM_Information.information;
4688 if (not match(dec_PDU_ML3_NW_MS(mm_info_dtap), tr_ML3_MT_MM_Info)) {
4689 setverdict(fail, "Unexpected MM Information");
4690 }
4691 }
4692
4693 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4694}
4695
4696private function f_tc_sgsap_lu(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4697 f_init_handler(pars);
4698 f_sgs_perform_lu();
4699 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4700
4701 f_sgsap_bssmap_screening();
4702
4703 setverdict(pass);
4704}
4705testcase TC_sgsap_lu() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004706 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004707 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004708 f_init(1, true);
4709 pars := f_init_pars(11811, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004710 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004711 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004712 vc_conn.done;
4713}
4714
4715/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
4716private function f_tc_sgsap_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4717 f_init_handler(pars);
4718 var PDU_SGsAP lur;
4719
4720 f_create_gsup_expect(hex2str(g_pars.imsi));
4721 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4722 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
4723 ts_SGsAP_LAI('901'H, '70'H, 2342)));
4724 SGsAP.send(lur);
4725
4726 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4727 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
4728 alt {
4729 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4730 setverdict(pass);
4731 }
4732 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) {
4733 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
4734 mtc.stop;
4735 }
4736 [] SGsAP.receive {
4737 setverdict(fail, "Received unexpected message on SGs");
4738 }
4739 }
4740
4741 f_sgsap_bssmap_screening();
4742
4743 setverdict(pass);
4744}
4745testcase TC_sgsap_lu_imsi_reject() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004746 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004747 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004748 f_init(1, true);
4749 pars := f_init_pars(11812, true);
Harald Welte4263c522018-12-06 11:56:27 +01004750
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004751 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_imsi_reject), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004752 vc_conn.done;
4753}
4754
4755/* Do LU by IMSI, but then remain silent so that Ts6-1 times out */
4756private function f_tc_sgsap_lu_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4757 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4758 var PDU_SGsAP lur;
4759
4760 f_init_handler(pars);
4761
4762 /* tell GSUP dispatcher to send this IMSI to us */
4763 f_create_gsup_expect(hex2str(g_pars.imsi));
4764
4765 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
4766 ts_SGsAP_LAI('901'H, '70'H, 2342)));
4767 /* Old LAI, if MS sends it */
4768 /* TMSI status, if MS has no valid TMSI */
4769 /* IMEISV, if it supports "automatic device detection" */
4770 /* TAI, if available in MME */
4771 /* E-CGI, if available in MME */
4772 SGsAP.send(lur);
4773
4774 /* FIXME: is this really done over SGs? The Ue is already authenticated
4775 * via the MME ... */
4776 f_mm_auth_sgs();
4777
4778 /* Expect MSC to perform LU with HLR */
4779 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4780 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
4781 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
4782 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
4783
4784 alt {
4785 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) {
4786 setverdict(pass);
4787 }
4788 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4789 setverdict(fail, "Received LU-REJECT instead of ACCEPT");
4790 }
4791 [] SGsAP.receive {
4792 setverdict(fail, "Received unexpected message on SGs");
4793 }
4794 }
4795
4796 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4797
4798 /* Wait until the VLR has abort the TMSI reallocation procedure */
4799 f_sleep(45.0);
4800
4801 /* The outcome does not change the SGs state, see also 5.2.3.4 */
4802 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4803
4804 f_sgsap_bssmap_screening();
4805
4806 setverdict(pass);
4807}
4808testcase TC_sgsap_lu_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004809 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004810 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004811 f_init(1, true);
4812 pars := f_init_pars(11813, true);
Harald Welte4263c522018-12-06 11:56:27 +01004813
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004814 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004815 vc_conn.done;
4816}
4817
4818private function f_tc_sgsap_expl_imsi_det_eps(charstring id, BSC_ConnHdlrPars pars)
4819runs on BSC_ConnHdlr {
4820 f_init_handler(pars);
4821 f_sgs_perform_lu();
4822 f_sleep(3.0);
4823
4824 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4825 SGsAP.send(ts_SGsAP_EPS_DETACH_IND(g_pars.imsi, mme_name, UE_initiated));
4826 SGsAP.receive(tr_SGsAP_EPS_DETACH_ACK(g_pars.imsi));
4827 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4828
4829 f_sgsap_bssmap_screening();
4830
4831 setverdict(pass);
4832}
4833testcase TC_sgsap_expl_imsi_det_eps() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004834 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004835 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004836 f_init(1, true);
4837 pars := f_init_pars(11814, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004838 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004839 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_expl_imsi_det_eps), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004840 vc_conn.done;
4841}
4842
Philipp Maierfc19f172019-03-21 11:17:54 +01004843private function f_tc_sgsap_impl_imsi_det_eps(charstring id, BSC_ConnHdlrPars pars)
4844runs on BSC_ConnHdlr {
4845 f_init_handler(pars);
4846 f_sgs_perform_lu();
4847 f_sleep(3.0);
4848
4849 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4850 SGsAP.send(ts_SGsAP_EPS_DETACH_IND(g_pars.imsi, mme_name, network_initiated));
4851 SGsAP.receive(tr_SGsAP_EPS_DETACH_ACK(g_pars.imsi));
4852 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4853
4854 f_sgsap_bssmap_screening();
4855
4856 setverdict(pass);
4857}
4858testcase TC_sgsap_impl_imsi_det_eps() runs on MTC_CT {
4859 var BSC_ConnHdlrPars pars;
4860 var BSC_ConnHdlr vc_conn;
4861 f_init(1, true);
4862 pars := f_init_pars(11814, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004863 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maierfc19f172019-03-21 11:17:54 +01004864 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_impl_imsi_det_eps), pars);
4865 vc_conn.done;
4866}
4867
Harald Welte4263c522018-12-06 11:56:27 +01004868private function f_tc_sgsap_expl_imsi_det_noneps(charstring id, BSC_ConnHdlrPars pars)
4869runs on BSC_ConnHdlr {
4870 f_init_handler(pars);
4871 f_sgs_perform_lu();
4872 f_sleep(3.0);
4873
4874 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4875 SGsAP.send(ts_SGsAP_IMSI_DETACH_IND(g_pars.imsi, mme_name, combined_UE_initiated));
4876 SGsAP.receive(tr_SGsAP_IMSI_DETACH_ACK(g_pars.imsi));
Philipp Maierd08e7e72019-04-02 15:27:10 +02004877
4878 if (f_ctrl_subscr_in_vlr(hex2str(g_pars.imsi))) {
4879 setverdict(fail, "subscriber not removed from VLR");
4880 }
Harald Welte4263c522018-12-06 11:56:27 +01004881
4882 f_sgsap_bssmap_screening();
4883
4884 setverdict(pass);
4885}
4886testcase TC_sgsap_expl_imsi_det_noneps() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004887 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004888 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004889 f_init(1, true);
4890 pars := f_init_pars(11815, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004891 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004892 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_expl_imsi_det_noneps), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004893 vc_conn.done;
4894}
4895
Philipp Maier5d812702019-03-21 10:51:26 +01004896private function f_tc_sgsap_impl_imsi_det_noneps(charstring id, BSC_ConnHdlrPars pars)
4897runs on BSC_ConnHdlr {
4898 f_init_handler(pars);
4899 f_sgs_perform_lu();
4900 f_sleep(3.0);
4901
4902 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4903 SGsAP.send(ts_SGsAP_IMSI_DETACH_IND(g_pars.imsi, mme_name, implicit_network_initiated));
4904 SGsAP.receive(tr_SGsAP_IMSI_DETACH_ACK(g_pars.imsi));
4905
4906 if (f_ctrl_subscr_in_vlr(hex2str(g_pars.imsi))) {
4907 setverdict(fail, "subscriber not removed from VLR");
4908 }
4909
4910 f_sgsap_bssmap_screening();
4911
4912 setverdict(pass);
4913}
4914testcase TC_sgsap_impl_imsi_det_noneps() runs on MTC_CT {
4915 var BSC_ConnHdlrPars pars;
4916 var BSC_ConnHdlr vc_conn;
4917 f_init(1, true);
4918 pars := f_init_pars(11815, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004919 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier5d812702019-03-21 10:51:26 +01004920 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_impl_imsi_det_noneps), pars);
4921 vc_conn.done;
4922}
4923
Harald Welte4263c522018-12-06 11:56:27 +01004924/* Trigger a paging request via VTY and send a paging reject in response */
4925private function f_tc_sgsap_paging_rej(charstring id, BSC_ConnHdlrPars pars)
4926runs on BSC_ConnHdlr {
4927 f_init_handler(pars);
4928 f_sgs_perform_lu();
4929 f_sleep(1.0);
4930
4931 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4932 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4933 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4934 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4935
4936 /* Initiate paging via VTY */
4937 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4938 alt {
4939 [] SGsAP.receive(exp_resp) {
4940 setverdict(pass);
4941 }
4942 [] SGsAP.receive {
4943 setverdict(fail, "Received unexpected message on SGs");
4944 }
4945 }
4946
4947 /* Now reject the paging */
4948 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, IMSI_unknown));
4949
4950 /* Wait for the states inside the MSC to settle and check the state
4951 * of the SGs Association */
4952 f_sleep(1.0);
4953 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4954
4955 /* FIXME: At the moment we send an IMSI_unknown as cause code, which is fine,
4956 * but we also need to cover tha case where the cause code indicates an
4957 * "IMSI detached for EPS services". In those cases the VLR is expected to
4958 * try paging on tha A/Iu interface. This will be another testcase similar to
4959 * this one, but extended with checks for the presence of the A/Iu paging
4960 * messages. */
4961
4962 f_sgsap_bssmap_screening();
4963
4964 setverdict(pass);
4965}
4966testcase TC_sgsap_paging_rej() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004967 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004968 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004969 f_init(1, true);
4970 pars := f_init_pars(11816, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004971 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004972 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_rej), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004973 vc_conn.done;
4974}
4975
4976/* Trigger a paging request via VTY and send a paging reject that indicates
4977 * that the subscriber intentionally rejected the call. */
4978private function f_tc_sgsap_paging_subscr_rej(charstring id, BSC_ConnHdlrPars pars)
4979runs on BSC_ConnHdlr {
4980 f_init_handler(pars);
4981 f_sgs_perform_lu();
4982 f_sleep(1.0);
4983
4984 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4985 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4986 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4987 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4988
4989 /* Initiate paging via VTY */
4990 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4991 alt {
4992 [] SGsAP.receive(exp_resp) {
4993 setverdict(pass);
4994 }
4995 [] SGsAP.receive {
4996 setverdict(fail, "Received unexpected message on SGs");
4997 }
4998 }
4999
5000 /* Now reject the paging */
5001 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, user_rejected_mobile_terminating_CS_fallback_call));
5002
5003 /* Wait for the states inside the MSC to settle and check the state
5004 * of the SGs Association */
5005 f_sleep(1.0);
5006 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5007
5008 /* FIXME: The VLR is supposed to trigger an User Determined User Busy (UDUB) as specified
5009 * in 3GPP TS 24.082, this is not yet implemented in the MSC or in this tests, we need
5010 * to check back how this works and how it can be tested */
5011
5012 f_sgsap_bssmap_screening();
5013
5014 setverdict(pass);
5015}
5016testcase TC_sgsap_paging_subscr_rej() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005017 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005018 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005019 f_init(1, true);
5020 pars := f_init_pars(11817, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005021 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005022 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_subscr_rej), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005023 vc_conn.done;
5024}
5025
5026/* Trigger a paging request via VTY and send an UE unreacable messge in response */
5027private function f_tc_sgsap_paging_ue_unr(charstring id, BSC_ConnHdlrPars pars)
5028runs on BSC_ConnHdlr {
5029 f_init_handler(pars);
5030 f_sgs_perform_lu();
5031 f_sleep(1.0);
5032
5033 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5034 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
5035 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
5036 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
5037
5038 /* Initiate paging via VTY */
5039 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
5040 alt {
5041 [] SGsAP.receive(exp_resp) {
5042 setverdict(pass);
5043 }
5044 [] SGsAP.receive {
5045 setverdict(fail, "Received unexpected message on SGs");
5046 }
5047 }
5048
5049 /* Now pretend that the UE is unreachable */
5050 SGsAP.send(ts_SGsAP_UE_UNREACHABLE(g_pars.imsi, UE_unreachable));
5051
5052 /* Wait for the states inside the MSC to settle and check the state
5053 * of the SGs Association. */
5054 f_sleep(1.0);
5055 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5056
5057 f_sgsap_bssmap_screening();
5058
5059 setverdict(pass);
5060}
5061testcase TC_sgsap_paging_ue_unr() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005062 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005063 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005064 f_init(1, true);
5065 pars := f_init_pars(11818, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005066 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005067 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_ue_unr), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005068 vc_conn.done;
5069}
5070
5071/* Trigger a paging request via VTY but don't respond to it */
5072private function f_tc_sgsap_paging_and_nothing(charstring id, BSC_ConnHdlrPars pars)
5073runs on BSC_ConnHdlr {
5074 f_init_handler(pars);
5075 f_sgs_perform_lu();
5076 f_sleep(1.0);
5077
5078 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5079 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
Philipp Maier34218102019-09-24 09:15:49 +02005080 var template PDU_SGsAP exp_serv_abrt := ts_SGsAP_SERVICE_ABORT_REQ(g_pars.imsi);
Harald Welte4263c522018-12-06 11:56:27 +01005081 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
5082 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
5083
5084 /* Initiate paging via VTY */
5085 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
5086 alt {
5087 [] SGsAP.receive(exp_resp) {
5088 setverdict(pass);
5089 }
5090 [] SGsAP.receive {
5091 setverdict(fail, "Received unexpected message on SGs");
5092 }
5093 }
5094
Philipp Maier34218102019-09-24 09:15:49 +02005095 /* While we are doing nothing, expect an SGsAP-SERVICE-ABORT-REQUEST
5096 * after some time */
5097 timer T := 10.0;
5098 T.start
5099 alt {
5100 [] SGsAP.receive(exp_serv_abrt)
5101 {
5102 setverdict(pass);
5103 }
5104 [] SGsAP.receive {
5105 setverdict(fail, "unexpected SGsAP message received");
5106 self.stop;
5107 }
5108 [] T.timeout {
5109 setverdict(fail, "MSC did not send SGsAP-SERVICE-ABORT-REQUEST");
5110 self.stop;
5111 }
5112 }
5113
5114 /* The SGs association must remain unchanged. */
Harald Welte4263c522018-12-06 11:56:27 +01005115 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5116
5117 f_sgsap_bssmap_screening();
5118
5119 setverdict(pass);
5120}
5121testcase TC_sgsap_paging_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005122 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005123 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005124 f_init(1, true);
5125 pars := f_init_pars(11819, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005126 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005127 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005128 vc_conn.done;
5129}
5130
5131/* Trigger a paging request via VTY and slip in an LU */
5132private function f_tc_sgsap_paging_and_lu(charstring id, BSC_ConnHdlrPars pars)
5133runs on BSC_ConnHdlr {
5134 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5135 f_init_handler(pars);
5136
5137 /* First we prepar the situation, where the SGs association is in state
5138 * NULL and the confirmed by radio contact indicator is set to false
5139 * as well. This can be archived by performing an SGs LU and then
5140 * resetting the VLR */
5141 f_sgs_perform_lu();
5142 f_sgsap_reset_mme(mp_mme_name);
5143 f_sleep(1.0);
5144 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
5145
5146 /* Perform a paging, expect the paging messages on the SGs interface */
5147 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
5148 alt {
5149 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
5150 setverdict(pass);
5151 }
5152 [] SGsAP.receive {
5153 setverdict(fail, "Received unexpected message on SGs");
5154 }
5155 }
5156
5157 /* Perform the LU as normal */
5158 f_sgs_perform_lu();
5159 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5160
5161 /* Expect a new paging request right after the LU */
5162 alt {
5163 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
5164 setverdict(pass);
5165 }
5166 [] SGsAP.receive {
5167 setverdict(fail, "Received unexpected message on SGs");
5168 }
5169 }
5170
5171 /* Test is done now, lets round everything up by rejecting the paging
5172 * cleanly. */
5173 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, user_rejected_mobile_terminating_CS_fallback_call));
5174 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5175
5176 f_sgsap_bssmap_screening();
5177
5178 setverdict(pass);
5179}
5180testcase TC_sgsap_paging_and_lu() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005181 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005182 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005183 f_init(1, true);
5184 pars := f_init_pars(11820, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005185 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005186 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_and_lu), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005187 vc_conn.done;
5188}
5189
5190/* Send unexpected unit-data through the SGs interface */
5191private function f_tc_sgsap_unexp_ud(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5192 f_init_handler(pars);
5193 f_sleep(1.0);
5194
5195 /* This simulates what happens when a subscriber without SGs
5196 * association gets unitdata via the SGs interface. */
5197
5198 /* Make sure the subscriber exists and the SGs association
5199 * is in NULL state */
5200 f_perform_lu();
5201 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
5202
5203 /* Send some random unit data, the MSC/VLR should send a release
5204 * immediately. */
5205 SGsAP.send(ts_SGsAP_UL_UD(pars.imsi,'1234'O));
5206 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, IMSI_detached_for_EPS_nonEPS_services));
5207
5208 f_sgsap_bssmap_screening();
5209
5210 setverdict(pass);
5211}
5212testcase TC_sgsap_unexp_ud() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005213 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005214 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005215 f_init(1, true);
5216 pars := f_init_pars(11821, true);
5217 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_unexp_ud), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005218 vc_conn.done;
5219}
5220
5221/* Send unsolicited unit-data through the SGs interface */
5222private function f_tc_sgsap_unsol_ud(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5223 f_init_handler(pars);
5224 f_sleep(1.0);
5225
5226 /* This simulates what happens when the MME attempts to send unitdata
5227 * to a subscriber that is completely unknown to the VLR */
5228
5229 /* Send some random unit data, the MSC/VLR should send a release
5230 * immediately. */
5231 SGsAP.send(ts_SGsAP_UL_UD(pars.imsi,'1234'O));
5232 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, IMSI_unknown));
5233
5234 f_sgsap_bssmap_screening();
5235
Harald Welte4d15fa72020-08-19 08:58:28 +02005236 /* clean-up VLR state about this subscriber */
5237 f_imsi_detach_by_imsi();
5238
Harald Welte4263c522018-12-06 11:56:27 +01005239 setverdict(pass);
5240}
5241testcase TC_sgsap_unsol_ud() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005242 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005243 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005244 f_init(1, true);
5245 pars := f_init_pars(11822, true);
5246 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_unsol_ud), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005247 vc_conn.done;
5248}
5249
5250private altstep as_other_sms_sgs() runs on BSC_ConnHdlr {
5251 /* FIXME: Match an actual payload (second questionmark), the type is
5252 * octetstring, how do we use a tr_PDU_DTAP_MT here? */
5253 [] SGsAP.receive(tr_SGsAP_DL_UD(?,?)) {
5254 setverdict(fail, "Unexpected SMS related PDU from MSC");
5255 mtc.stop;
5256 }
5257}
5258
5259/* receive a MT-SMS delivered from the MSC/SMSC over an already existing SGsAP connection */
5260function f_mt_sms_sgs(inout SmsParameters spars)
5261runs on BSC_ConnHdlr {
5262 var template (value) TPDU_RP_DATA_MS_SGSN tp_mo;
5263 var template (value) RPDU_MS_SGSN rp_mo;
5264 var template (value) PDU_ML3_MS_NW l3_mo;
5265
5266 var template TPDU_RP_DATA_SGSN_MS tp_mt;
5267 var template RPDU_SGSN_MS rp_mt;
5268 var template PDU_ML3_NW_MS l3_mt;
5269
5270 var PDU_ML3_NW_MS sgsap_l3_mt;
5271
5272 var default d := activate(as_other_sms_sgs());
5273
5274 /* Expect CP-DATA(RP-DATA(SMS-DELIVER)) */
5275 tp_mt := tr_SMS_DELIVER(?, spars.tp.ud, spars.tp.pid, spars.tp.dcs, ?);
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09005276 rp_mt := tr_RP_DATA_MT(?, spars.rp.smsc_addr, omit, tp_mt);
Harald Welte4263c522018-12-06 11:56:27 +01005277 l3_mt := tr_ML3_MT_SMS(?, c_TIF_ORIG, tr_CP_DATA_MT(rp_mt));
5278
5279 SGsAP.receive(l3_mt) -> value sgsap_l3_mt;
5280
5281 /* Extract relevant identifiers */
5282 spars.tid := bit2int(sgsap_l3_mt.tiOrSkip.transactionId.tio);
5283 spars.rp.msg_ref := sgsap_l3_mt.msgs.sms.cP_DATA.cP_User_Data.cP_RPDU.rP_DATA_SGSN_MS.rP_MessageReference;
5284
5285 /* send CP-ACK for CP-DATA just received */
5286 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_REPL, ts_CP_ACK_MO);
5287
5288 SGsAP.send(l3_mo);
5289
5290 /* send RP-ACK for RP-DATA */
5291 rp_mo := ts_RP_ACK_MO(spars.rp.msg_ref);
5292 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_REPL, ts_CP_DATA_MO(rp_mo));
5293
5294 SGsAP.send(l3_mo);
5295
5296 /* expect CP-ACK for CP-DATA(RP-ACK) just sent */
5297 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_ORIG, tr_CP_ACK_MT);
5298
5299 SGsAP.receive(l3_mt);
5300
5301 deactivate(d);
5302
5303 setverdict(pass);
5304}
5305
5306/* submit a MO-SMS to MSC/SMSC over an already existing SGsAP connection */
5307function f_mo_sms_sgs(inout SmsParameters spars)
5308runs on BSC_ConnHdlr {
5309 var template (value) TPDU_RP_DATA_MS_SGSN tp_mo;
5310 var template (value) RPDU_MS_SGSN rp_mo;
5311 var template (value) PDU_ML3_MS_NW l3_mo;
5312
5313 var template TPDU_RP_DATA_SGSN_MS tp_mt;
5314 var template RPDU_SGSN_MS rp_mt;
5315 var template PDU_ML3_NW_MS l3_mt;
5316
5317 var default d := activate(as_other_sms_sgs());
5318
5319 /* just in case this is routed to SMPP.. */
5320 f_create_smpp_expect(hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue));
5321
5322 tp_mo := ts_SMS_SUBMIT(spars.tp.msg_ref, spars.tp.da, spars.tp.pid, spars.tp.dcs,
5323 spars.tp.udl, spars.tp.ud);
Vadim Yanitskiy437b5a62019-12-15 14:13:39 +09005324 rp_mo := ts_RP_DATA_MO(spars.rp.msg_ref, omit, spars.rp.smsc_addr, tp_mo);
Harald Welte4263c522018-12-06 11:56:27 +01005325 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_DATA_MO(rp_mo));
5326
5327 SGsAP.send(l3_mo);
5328
5329 /* receive CP-ACK for CP-DATA above */
5330 SGsAP.receive(tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_ACK_MT));
5331
5332 if (ispresent(spars.exp_rp_err)) {
5333 /* expect an RP-ERROR message from MSC with given cause */
5334 rp_mt := tr_RP_ERROR_MT(spars.rp.msg_ref, spars.exp_rp_err);
5335 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_DATA_MT(rp_mt));
5336 SGsAP.receive(l3_mt);
5337 /* send CP-ACK for CP-DATA just received */
5338 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_ACK_MO);
5339 SGsAP.send(l3_mo);
5340 } else {
5341 /* expect RP-ACK for RP-DATA */
5342 rp_mt := tr_RP_ACK_MT(spars.rp.msg_ref);
5343 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_DATA_MT(rp_mt));
5344 SGsAP.receive(l3_mt);
5345 /* send CP-ACO for CP-DATA just received */
5346 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_ACK_MO);
5347 SGsAP.send(l3_mo);
5348 }
5349
5350 deactivate(d);
5351
5352 setverdict(pass);
5353}
5354
5355private function f_vty_sms_send_conn_hdlr(charstring imsi, charstring msisdn, charstring text)
5356runs on BSC_ConnHdlr {
5357 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
5358}
5359
5360/* Send a MT SMS via SGs interface */
5361private function f_tc_sgsap_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5362 f_init_handler(pars);
5363 f_sgs_perform_lu();
5364 f_sleep(1.0);
5365 var SmsParameters spars := valueof(t_SmsPars);
5366 spars.tp.ud := 'C8329BFD064D9B53'O;
5367
5368 /* Trigger SMS via VTY */
5369 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
5370 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5371
5372 /* Expect a paging request and respond accordingly with a service request */
5373 SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, SMS_indicator, omit));
5374 SGsAP.send(ts_SGsAP_SERVICE_REQ(pars.imsi, SMS_indicator, EMM_CONNECTED));
5375
5376 /* Connection is now live, receive the MT-SMS */
5377 f_mt_sms_sgs(spars);
5378
5379 /* Expect a concluding release from the MSC */
5380 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, omit));
5381
5382 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
5383 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5384
5385 f_sgsap_bssmap_screening();
5386
5387 setverdict(pass);
5388}
5389testcase TC_sgsap_mt_sms() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005390 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005391 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005392 f_init(1, true);
5393 pars := f_init_pars(11823, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005394 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005395 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005396 vc_conn.done;
5397}
5398
5399/* Send a MO SMS via SGs interface */
5400private function f_tc_sgsap_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5401 f_init_handler(pars);
5402 f_sgs_perform_lu();
5403 f_sleep(1.0);
5404 var SmsParameters spars := valueof(t_SmsPars);
5405 spars.tp.ud := 'C8329BFD064D9B53'O;
5406
5407 /* Send the MO-SMS */
5408 f_mo_sms_sgs(spars);
5409
5410 /* Expect a concluding release from the MSC/VLR */
5411 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, omit));
5412
5413 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
5414 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5415
5416 setverdict(pass);
5417
5418 f_sgsap_bssmap_screening()
5419}
5420testcase TC_sgsap_mo_sms() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005421 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005422 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005423 f_init(1, true);
5424 pars := f_init_pars(11824, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005425 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005426 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mo_sms), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005427 vc_conn.done;
5428}
5429
5430/* Trigger sending of an MT sms via VTY but never respond to anything */
5431private function f_tc_sgsap_mt_sms_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5432 f_init_handler(pars, 170.0);
5433 f_sgs_perform_lu();
5434 f_sleep(1.0);
5435
5436 var SmsParameters spars := valueof(t_SmsPars);
5437 spars.tp.ud := 'C8329BFD064D9B53'O;
5438 var integer page_count := 0;
5439 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5440 var template PDU_SGsAP exp_pag_req := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, SMS_indicator, omit);
5441 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
5442 exp_pag_req.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
5443
5444 /* Trigger SMS via VTY */
5445 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
5446
Neels Hofmeyr16237742019-03-06 15:34:01 +01005447 /* Expect the MSC/VLR to page exactly once */
5448 SGsAP.receive(exp_pag_req);
Harald Welte4263c522018-12-06 11:56:27 +01005449
5450 /* Wait some time to make sure the MSC is not delivering any further
5451 * paging messages or anything else that could be unexpected. */
5452 timer T := 20.0;
5453 T.start
5454 alt {
5455 [] SGsAP.receive(exp_pag_req)
5456 {
5457 setverdict(fail, "paging seems not to stop!");
5458 mtc.stop;
5459 }
5460 [] SGsAP.receive {
5461 setverdict(fail, "unexpected SGsAP message received");
5462 self.stop;
5463 }
5464 [] T.timeout {
5465 setverdict(pass);
5466 }
5467 }
5468
5469 /* Even on a failed paging the SGs Association should stay intact */
5470 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5471
Philipp Maier26bdb8c2019-09-24 09:21:12 +02005472 /* Make sure that the SMS we just inserted is cleared and the
5473 * subscriber is expired. This is necessary because otherwise the MSC
5474 * might re-try the SMS delivery and disturb the following tests. */
Harald Welte4263c522018-12-06 11:56:27 +01005475
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01005476 f_vty_sms_clear(hex2str(g_pars.imsi));
5477
Harald Welte4263c522018-12-06 11:56:27 +01005478 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " expire");
5479
5480 setverdict(pass);
Neels Hofmeyrb0f82342019-03-06 15:36:51 +01005481
5482 f_sgsap_bssmap_screening();
Harald Welte4263c522018-12-06 11:56:27 +01005483}
5484testcase TC_sgsap_mt_sms_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005485 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005486 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005487 f_init(1, true);
5488 pars := f_init_pars(11825, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005489 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005490 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005491 vc_conn.done;
5492}
5493
5494/* Trigger sending of an MT sms via VTY but reject the paging immediately */
5495private function f_tc_sgsap_mt_sms_and_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5496 f_init_handler(pars, 150.0);
5497 f_sgs_perform_lu();
5498 f_sleep(1.0);
5499
5500 var SmsParameters spars := valueof(t_SmsPars);
5501 spars.tp.ud := 'C8329BFD064D9B53'O;
5502 var integer page_count := 0;
5503 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5504 var template PDU_SGsAP exp_pag_req := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, SMS_indicator, omit);
5505 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
5506 exp_pag_req.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
5507
5508 /* Trigger SMS via VTY */
5509 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
5510
5511 /* Expect a paging request and reject it immediately */
5512 SGsAP.receive(exp_pag_req);
5513 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, IMSI_unknown));
5514
5515 /* The MSC/VLR should no longer try to page once the paging has been
5516 * rejected. Wait some time and check if there are no unexpected
5517 * messages on the SGs interface. */
5518 timer T := 20.0;
5519 T.start
5520 alt {
5521 [] SGsAP.receive(exp_pag_req)
5522 {
5523 setverdict(fail, "paging seems not to stop!");
5524 mtc.stop;
5525 }
5526 [] SGsAP.receive {
5527 setverdict(fail, "unexpected SGsAP message received");
5528 self.stop;
5529 }
5530 [] T.timeout {
5531 setverdict(pass);
5532 }
5533 }
5534
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01005535 f_vty_sms_clear(hex2str(g_pars.imsi));
5536
Harald Welte4263c522018-12-06 11:56:27 +01005537 /* A rejected paging with IMSI_unknown (see above) should always send
5538 * the SGs association to NULL. */
5539 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
5540
5541 f_sgsap_bssmap_screening();
5542
Harald Welte4263c522018-12-06 11:56:27 +01005543 setverdict(pass);
5544}
5545testcase TC_sgsap_mt_sms_and_reject() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005546 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005547 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005548 f_init(1, true);
5549 pars := f_init_pars(11826, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005550 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005551 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms_and_reject), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005552 vc_conn.done;
5553}
5554
Pau Espin Pedrol3acd19e2021-04-28 12:59:52 +02005555/* Perform an MT CSFB call including LU */
Harald Welte4263c522018-12-06 11:56:27 +01005556private function f_mt_lu_and_csfb_call(charstring id, BSC_ConnHdlrPars pars, boolean bssmap_lu) runs on BSC_ConnHdlr {
5557 f_init_handler(pars);
5558
5559 /* Be sure that the BSSMAP reset is done before we begin. */
5560 f_sleep(2.0);
5561
5562 /* Testcase variation: See what happens when we do a regular BSSMAP
5563 * LU first (this should not hurt in any way!) */
5564 if (bssmap_lu) {
5565 f_perform_lu();
5566 }
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005567 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Harald Welte4263c522018-12-06 11:56:27 +01005568
5569 f_sgs_perform_lu();
5570 f_sleep(1.0);
5571
5572 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5573 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Harald Welte4263c522018-12-06 11:56:27 +01005574
5575 /* Initiate a call via MNCC interface */
5576 f_mt_call_initate(cpars);
5577
5578 /* Expect a paging request and respond accordingly with a service request */
5579 SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit));
5580 SGsAP.send(ts_SGsAP_SERVICE_REQ(pars.imsi, CS_call_indicator, EMM_CONNECTED));
5581
5582 /* Complete the call, hold it for some time and then tear it down */
5583 f_mt_call_complete(cpars);
5584 f_sleep(3.0);
Harald Welte4c422b72019-02-17 16:27:10 +01005585 f_call_hangup(cpars, true, is_csfb := true);
Harald Welte4263c522018-12-06 11:56:27 +01005586
5587 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
5588 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5589
Harald Welte4263c522018-12-06 11:56:27 +01005590 /* Test for successful return by triggering a paging, when the paging
5591 * request is received via SGs, we can be sure that the MSC/VLR has
5592 * recognized that the UE is now back on 4G */
5593 f_sleep(1.0);
5594 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
5595 alt {
5596 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
5597 setverdict(pass);
5598 }
5599 [] SGsAP.receive {
5600 setverdict(fail, "Received unexpected message on SGs");
5601 }
5602 }
5603
5604 f_sgsap_bssmap_screening();
5605
5606 setverdict(pass);
5607}
5608
5609/* Perform a regular BSSAP LU first, do a SGSAP LU and then make a CSFB call */
5610private function f_tc_bssap_lu_sgsap_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5611 f_mt_lu_and_csfb_call(id, pars, true);
5612}
5613testcase TC_bssap_lu_sgsap_lu_and_mt_call() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005614 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005615 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005616 f_init(1, true);
5617 pars := f_init_pars(118139, true);
Harald Welte4263c522018-12-06 11:56:27 +01005618
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005619 vc_conn := f_start_handler_with_pars(refers(f_tc_bssap_lu_sgsap_lu_and_mt_call), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005620 vc_conn.done;
5621}
5622
Harald Welte4263c522018-12-06 11:56:27 +01005623/* Perform a SGSAP LU and then make a CSFB call */
5624private function f_tc_sgsap_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5625 f_mt_lu_and_csfb_call(id, pars, false);
5626}
5627testcase TC_sgsap_lu_and_mt_call() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005628 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005629 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005630 f_init(1, true);
5631 pars := f_init_pars(11827, true);
Harald Welte4263c522018-12-06 11:56:27 +01005632
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005633 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_and_mt_call), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005634 vc_conn.done;
5635}
5636
Philipp Maier628c0052019-04-09 17:36:57 +02005637/* Simulate an HLR/VLR failure */
5638private function f_tc_sgsap_vlr_failure(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5639 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
5640 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5641
5642 var PDU_SGsAP lur;
5643
5644 f_init_handler(pars);
5645
5646 /* Attempt location update (which is expected to fail) */
5647 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
5648 ts_SGsAP_LAI('901'H, '70'H, 2342)));
5649 SGsAP.send(lur);
5650
5651 /* Respond to SGsAP-RESET-INDICATION from VLR */
5652 alt {
5653 [] SGsAP.receive(tr_SGsAP_RESET_IND_VLR(vlr_name)); {
5654 SGsAP.send(valueof(ts_SGsAP_RESET_ACK_MME(mme_name)));
5655 setverdict(pass);
5656 }
5657 [] SGsAP.receive {
5658 setverdict(fail, "Received unexpected message on SGs");
5659 }
5660 }
5661
5662 f_sleep(1.0);
5663 setverdict(pass);
5664}
5665testcase TC_sgsap_vlr_failure() runs on MTC_CT {
5666 var BSC_ConnHdlrPars pars;
5667 var BSC_ConnHdlr vc_conn;
5668 f_init(1, true, false);
5669 pars := f_init_pars(11811, true, false);
5670 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_vlr_failure), pars);
5671 vc_conn.done;
5672}
5673
Harald Welte4263c522018-12-06 11:56:27 +01005674/* SGs TODO:
5675 * LU attempt for IMSI without NAM_PS in HLR
5676 * LU attempt with AUTH FAIL due to invalid RES/SRES
5677 * LU attempt with no response from HLR (VLR should timeout + LU REJ)
5678 * LU attempt with new TMSI but without TMSI REALL CMPL baco to VLR
5679 * implicit IMSI detach from EPS
5680 * implicit IMSI detach from non-EPS
5681 * MM INFO
5682 *
5683 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01005684
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005685private function f_tc_ho_inter_bsc_unknown_cell(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5686 f_init_handler(pars);
5687 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005688
5689 f_perform_lu();
5690 f_mo_call_establish(cpars);
5691
5692 f_sleep(1.0);
5693
5694 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5695 var BssmapCause cause := enum2int(cause_val);
5696
5697 var template BSSMAP_FIELD_CellIdentificationList cil;
5698 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('023'H, '42'H, 999) } };
5699
5700 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5701 BSSAP.receive(tr_BSSMAP_HandoverRequiredReject);
5702
5703 f_call_hangup(cpars, true);
5704}
5705testcase TC_ho_inter_bsc_unknown_cell() runs on MTC_CT {
5706 var BSC_ConnHdlr vc_conn;
5707 f_init();
5708
5709 vc_conn := f_start_handler(refers(f_tc_ho_inter_bsc_unknown_cell), 53);
5710 vc_conn.done;
5711}
5712
5713private altstep as_mgcp_ack_all_mdcx(CallParameters cpars) runs on BSC_ConnHdlr {
5714 var MgcpCommand mgcp_cmd;
5715 [] MGCP.receive(tr_MDCX) -> value mgcp_cmd {
Neels Hofmeyr8913b9e2021-07-27 22:33:45 +02005716 var charstring conn_id;
5717 f_mgcp_find_param_entry(mgcp_cmd.params, "I", conn_id);
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02005718 var SDP_Message sdp := valueof(ts_SDP(cpars.mgw_conn_2.mgw_rtp_ip, cpars.mgw_conn_2.mgw_rtp_ip,
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005719 hex2str(cpars.mgcp_call_id), "42",
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02005720 cpars.mgw_conn_2.mgw_rtp_port,
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005721 { int2str(cpars.rtp_payload_type) },
5722 { valueof(ts_SDP_rtpmap(cpars.rtp_payload_type,
5723 cpars.rtp_sdp_format)),
5724 valueof(ts_SDP_ptime(20)) }));
Neels Hofmeyr8913b9e2021-07-27 22:33:45 +02005725 MGCP.send(ts_MDCX_ACK(mgcp_cmd.line.trans_id, str2hex(conn_id), sdp));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005726 repeat;
5727 }
5728}
5729
Neels Hofmeyr8853afb2021-07-27 22:34:15 +02005730private altstep as_mgcp_ack_all_dlcx(CallParameters cpars) runs on BSC_ConnHdlr {
5731 var MgcpCommand mgcp_cmd;
5732 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
5733 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
5734 repeat;
5735 }
5736}
5737
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005738private function f_tc_ho_inter_bsc0(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005739 var CallParameters cpars;
5740
5741 cpars := valueof(t_CallParams('12345'H, 0));
5742 if (pars.use_ipv6) {
5743 cpars.mgw_conn_1.mgw_rtp_ip := "::1";
5744 cpars.mgw_conn_2.mgw_rtp_ip := "::2";
5745 cpars.bss_rtp_ip := "::3";
5746 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005747
5748 f_init_handler(pars);
5749
5750 f_vty_transceive(MSCVTY, "configure terminal");
5751 f_vty_transceive(MSCVTY, "msc");
5752 f_vty_transceive(MSCVTY, "neighbor a cgi 262 42 23 42 ran-pc 0.24.1");
Neels Hofmeyr2822d072021-06-23 03:20:32 +02005753 f_vty_transceive(MSCVTY, "neighbor a cgi 023 42 5 6 ran-pc 0.24.2");
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005754 f_vty_transceive(MSCVTY, "exit");
5755 f_vty_transceive(MSCVTY, "exit");
5756
5757 f_perform_lu();
5758 f_mo_call_establish(cpars);
5759
5760 f_sleep(1.0);
5761
5762 var default ack_mdcx := activate(as_mgcp_ack_all_mdcx(cpars));
5763
5764 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5765 var BssmapCause cause := enum2int(cause_val);
5766
5767 var template BSSMAP_FIELD_CellIdentificationList cil;
Neels Hofmeyr2822d072021-06-23 03:20:32 +02005768 cil := { cIl_CGI := { ts_BSSMAP_CI_CGI('023'H, '42'H, 5, 6) } };
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005769
5770 /* old BSS sends Handover Required */
5771 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5772
5773 /* Now the action goes on in f_tc_ho_inter_bsc1() */
5774
5775 /* MSC forwards the RR Handover Command to old BSS */
5776 var PDU_BSSAP ho_command;
5777 BSSAP.receive(tr_BSSMAP_HandoverCommand) -> value ho_command;
5778
5779 log("GOT HandoverCommand", ho_command);
5780
5781 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
5782
5783 /* f_tc_ho_inter_bsc1() completes Handover, then expecting a Clear here. */
5784 f_expect_clear();
5785
5786 log("FIRST inter-BSC Handover done");
5787
5788
5789 /* ------------------------ */
5790
5791 /* Ok, that went well, now the other BSC is handovering back here --
5792 * from now on this here is the new BSS. */
5793 f_create_bssmap_exp_handoverRequest(193);
5794
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005795 var template BSSMAP_IE_EncryptionInformation encryptionInformation;
5796 var template BSSMAP_IE_ChosenEncryptionAlgorithm chosenEncryptionAlgorithm;
5797 var template BSSMAP_IE_KC128 kC128;
5798 var OCT1 a5_perm_alg;
5799 f_get_expected_encryption(encryptionInformation, chosenEncryptionAlgorithm, kC128, a5_perm_alg);
5800 var template PDU_BSSAP expect_ho_request := tr_BSSMAP_HandoverRequest(encryptionInformation, chosenEncryptionAlgorithm, kC128);
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005801 var PDU_BSSAP ho_request;
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005802 alt {
5803 [] BSSAP.receive(expect_ho_request);
5804 [] BSSAP.receive(tr_BSSMAP_HandoverRequest) -> value ho_request {
5805 log("Error: Wrong handoverRequest received. Expected: ", expect_ho_request,
5806 " got ", ho_request);
5807 setverdict(fail, "Wrong handoverRequest received");
5808 mtc.stop;
5809 }
5810 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005811
5812 /* new BSS composes a RR Handover Command */
5813 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5814 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005815 var BSSMAP_IE_AoIP_TransportLayerAddress tla tla :=
5816 valueof(f_ts_BSSMAP_IE_AoIP_TLA(cpars.bss_rtp_ip, cpars.bss_rtp_port));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005817 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5818 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5819
5820 /* Now f_tc_ho_inter_bsc1() expects HandoverCommand */
5821
5822 f_sleep(0.5);
5823
5824 /* Notify that the MS is now over here */
5825
5826 BSSAP.send(ts_BSSMAP_HandoverDetect);
5827 f_sleep(0.1);
5828 BSSAP.send(ts_BSSMAP_HandoverComplete);
5829
5830 f_sleep(3.0);
5831
5832 deactivate(ack_mdcx);
5833
5834 var default ccrel := activate(as_optional_cc_rel(cpars, true));
5835
5836 /* blatant cheating */
5837 var N_Sd_Array last_n_sd := f_bssmap_last_n_sd();
5838 last_n_sd[0] := 3;
5839 f_bssmap_continue_after_n_sd(last_n_sd);
5840
5841 f_call_hangup(cpars, true);
5842 f_sleep(1.0);
5843 deactivate(ccrel);
5844
5845 setverdict(pass);
5846}
5847private function f_tc_ho_inter_bsc1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005848 var charstring bss_rtp_ip;
5849 if (pars.use_ipv6) {
5850 bss_rtp_ip := "::8";
5851 } else {
5852 bss_rtp_ip := "1.2.3.4";
5853 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005854 f_init_handler(pars);
5855 f_create_bssmap_exp_handoverRequest(194);
5856
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005857 var template BSSMAP_IE_EncryptionInformation encryptionInformation;
5858 var template BSSMAP_IE_ChosenEncryptionAlgorithm chosenEncryptionAlgorithm;
5859 var template BSSMAP_IE_KC128 kC128;
5860 var OCT1 a5_perm_alg;
5861 f_get_expected_encryption(encryptionInformation, chosenEncryptionAlgorithm, kC128, a5_perm_alg);
5862 var template PDU_BSSAP expect_ho_request := tr_BSSMAP_HandoverRequest(encryptionInformation, chosenEncryptionAlgorithm, kC128);
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005863 var PDU_BSSAP ho_request;
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005864 alt {
5865 [] BSSAP.receive(expect_ho_request);
5866 [] BSSAP.receive(tr_BSSMAP_HandoverRequest) -> value ho_request {
5867 log("Error: Wrong handoverRequest received. Expected: ", expect_ho_request,
5868 " got ", ho_request);
5869 setverdict(fail, "Wrong handoverRequest received");
5870 mtc.stop;
5871 }
5872 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005873 /* new BSS composes a RR Handover Command */
5874 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5875 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005876 var BSSMAP_IE_AoIP_TransportLayerAddress tla :=
5877 valueof(f_ts_BSSMAP_IE_AoIP_TLA(bss_rtp_ip, 2342));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005878 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5879 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5880
5881 /* Now f_tc_ho_inter_bsc0() expects HandoverCommand */
5882
5883 f_sleep(0.5);
5884
5885 /* Notify that the MS is now over here */
5886
5887 BSSAP.send(ts_BSSMAP_HandoverDetect);
5888 f_sleep(0.1);
5889 BSSAP.send(ts_BSSMAP_HandoverComplete);
5890
5891 f_sleep(3.0);
5892
5893 /* Now I'd like to f_call_hangup() but we don't know any cpars here. So
5894 * ... handover back to the first BSC :P */
5895
5896 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5897 var BssmapCause cause := enum2int(cause_val);
5898
5899 var template BSSMAP_FIELD_CellIdentificationList cil;
Neels Hofmeyr2822d072021-06-23 03:20:32 +02005900 cil := { cIl_CGI := { ts_BSSMAP_CI_CGI('262'H, '42'H, 23, 42) } };
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005901
5902 /* old BSS sends Handover Required */
5903 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5904
5905 /* Now the action goes on in f_tc_ho_inter_bsc0() */
5906
5907 /* MSC forwards the RR Handover Command to old BSS */
5908 var PDU_BSSAP ho_command;
5909 BSSAP.receive(tr_BSSMAP_HandoverCommand) -> value ho_command;
5910
5911 log("GOT HandoverCommand", ho_command);
5912
5913 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
5914
5915 /* f_tc_ho_inter_bsc1() completes Handover, then expecting a Clear here. */
5916 f_expect_clear();
5917 setverdict(pass);
5918}
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005919function f_tc_ho_inter_bsc_main(boolean use_ipv6 := false, integer a5_n := 0) runs on MTC_CT {
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005920 var BSC_ConnHdlr vc_conn0;
5921 var BSC_ConnHdlr vc_conn1;
5922 f_init(2);
5923
5924 var BSC_ConnHdlrPars pars0 := f_init_pars(53);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005925 pars0.use_ipv6 := use_ipv6;
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005926 pars0.net.expect_ciph := a5_n > 0;
5927 pars0.net.expect_auth := pars0.net.expect_ciph;
5928 pars0.net.kc_support := bit2oct('00000001'B << a5_n);
5929 pars0.cm2.classmarkInformationType2_oct5.a5_3 := '1'B;
5930 pars0.cm2.classmarkInformationType2_oct5.a5_2 := '0'B;
5931 pars0.cm2.classmarkInformationType2_oct5.cm3 := '1'B;
5932 pars0.cm3 := valueof(ts_CM3_default);
5933 pars0.use_umts_aka := true;
5934 pars0.vec := f_gen_auth_vec_3g();
5935 pars0.vec_keep := true;
Neels Hofmeyr60122f82021-07-28 17:59:38 +02005936 pars0.ran_idx := 0;
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005937
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005938 var BSC_ConnHdlrPars pars1 := f_init_pars(53);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005939 pars1.use_ipv6 := use_ipv6;
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005940 pars1.net.expect_ciph := pars0.net.expect_ciph;
5941 pars1.net.expect_auth := pars0.net.expect_ciph;
5942 pars1.net.kc_support := bit2oct('00000001'B << a5_n);
5943 pars1.cm2 := pars0.cm2;
5944 pars1.cm3 := pars0.cm3;
5945 pars1.use_umts_aka := true;
5946 /* Both components need the same auth vector info because we expect f_tc_ho_inter_bsc0's ciphering key to be
5947 * identical to the one that shows up in f_tc_ho_inter_bsc1. Can only do that by feeding in a vector to both
5948 * components and then not overwriting it in BSC_ConnectionHandler. */
5949 pars1.vec := pars0.vec;
5950 pars1.vec_keep := true;
Neels Hofmeyr60122f82021-07-28 17:59:38 +02005951 pars1.ran_idx := 1;
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005952
5953 if (a5_n > 0) {
5954 f_vty_config(MSCVTY, "network", "authentication required");
5955 }
5956 f_vty_config(MSCVTY, "network", "encryption a5 " & int2str(a5_n));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005957
Neels Hofmeyr60122f82021-07-28 17:59:38 +02005958 vc_conn0 := f_start_handler_with_pars(refers(f_tc_ho_inter_bsc0), pars0);
5959 vc_conn1 := f_start_handler_with_pars(refers(f_tc_ho_inter_bsc1), pars1);
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005960 vc_conn0.done;
5961 vc_conn1.done;
5962}
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005963testcase TC_ho_inter_bsc() runs on MTC_CT {
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005964 f_tc_ho_inter_bsc_main(false, a5_n := 0);
5965}
5966testcase TC_ho_inter_bsc_a5_1() runs on MTC_CT {
5967 f_tc_ho_inter_bsc_main(false, a5_n := 1);
5968}
5969testcase TC_ho_inter_bsc_a5_3() runs on MTC_CT {
5970 f_tc_ho_inter_bsc_main(false, a5_n := 3);
5971}
5972testcase TC_ho_inter_bsc_a5_4() runs on MTC_CT {
5973 f_tc_ho_inter_bsc_main(false, a5_n := 4);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005974}
5975testcase TC_ho_inter_bsc_ipv6() runs on MTC_CT {
5976 f_tc_ho_inter_bsc_main(true);
5977}
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005978
5979function f_ML3_patch_seq_nr_MS_NW(in uint2_t seq_nr, inout octetstring enc_l3) {
5980 log("MS_NW patching N(SD)=", seq_nr, " into dtap ", enc_l3);
5981 enc_l3[2] := (enc_l3[2] and4b '3f'O) or4b bit2oct(int2bit(seq_nr, 8) << 6);
5982 log("MS_NW patched enc_l3: ", enc_l3);
5983}
5984
5985private function f_tc_ho_inter_msc_out(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005986 var CallParameters cpars;
Neels Hofmeyr906af102021-07-01 12:08:35 +02005987 var PDU_BSSAP ho_request;
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005988
5989 cpars := valueof(t_CallParams('12345'H, 0));
5990 if (pars.use_ipv6) {
5991 cpars.mgw_conn_1.mgw_rtp_ip := "::1";
5992 cpars.mgw_conn_2.mgw_rtp_ip := "::2";
5993 cpars.bss_rtp_ip := "::3";
5994 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005995 var hexstring ho_number := f_gen_msisdn(99999);
5996
5997 f_init_handler(pars);
5998
5999 f_create_mncc_expect(hex2str(ho_number));
6000
6001 f_vty_transceive(MSCVTY, "configure terminal");
6002 f_vty_transceive(MSCVTY, "msc");
6003 f_vty_transceive(MSCVTY, "neighbor a cgi 017 017 1 1 msc-ipa-name msc-017-017-1");
6004 f_vty_transceive(MSCVTY, "exit");
6005 f_vty_transceive(MSCVTY, "exit");
6006
6007 f_perform_lu();
6008 f_mo_call_establish(cpars);
6009
6010 f_sleep(1.0);
6011
6012 var default ack_mdcx := activate(as_mgcp_ack_all_mdcx(cpars));
6013
6014 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
6015 var BssmapCause cause := enum2int(cause_val);
6016
6017 var template BSSMAP_FIELD_CellIdentificationList cil;
Neels Hofmeyr36ebc332021-06-23 03:20:32 +02006018 cil := { cIl_CGI := { ts_BSSMAP_CI_CGI('017'H, '017'H, 1, 1) } };
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006019
6020 /* old BSS sends Handover Required */
6021 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
6022
6023 /* The target cell 017-017 LAC 1 is configured to be a remote MSC of name "msc-017-017-1".
6024 * This MSC tries to reach the other MSC via GSUP. */
6025
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006026 var template BSSMAP_IE_EncryptionInformation encryptionInformation;
6027 var template BSSMAP_IE_ChosenEncryptionAlgorithm chosenEncryptionAlgorithm;
6028 var template BSSMAP_IE_KC128 kC128;
6029 var OCT1 a5_perm_alg;
6030 f_get_expected_encryption(encryptionInformation, chosenEncryptionAlgorithm, kC128, a5_perm_alg);
6031 var template PDU_BSSAP expect_ho_request := tr_BSSMAP_HandoverRequest(encryptionInformation, chosenEncryptionAlgorithm, kC128);
6032
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006033 var octetstring remote_msc_name := '6D73632D3031372D3031372D3100'O; /* "msc-017-017-1\0" as octetstring */
6034 var GSUP_PDU prep_ho_req;
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006035 alt {
6036 [] GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_HANDOVER_REQUEST,
6037 pars.imsi, destination_name := remote_msc_name,
Neels Hofmeyrec2e1f72021-07-02 02:08:32 +02006038 an_apdu := t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006, pdu := ?))) -> value prep_ho_req;
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006039 [] GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_HANDOVER_REQUEST)) {
6040 setverdict(fail, "Wrong OSMO_GSUP_MSGT_E_PREPARE_HANDOVER_REQUEST message received");
6041 mtc.stop;
6042 }
6043 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006044
6045 var GSUP_IeValue source_name_ie;
6046 f_gsup_find_ie(prep_ho_req, OSMO_GSUP_SOURCE_NAME_IE, source_name_ie);
6047 var octetstring local_msc_name := source_name_ie.source_name;
6048
Neels Hofmeyrec2e1f72021-07-02 02:08:32 +02006049 /* Decode PDU to 1) match with expect_ho_request and 2) to forward the actual chosen encryption algorithm. */
Neels Hofmeyr906af102021-07-01 12:08:35 +02006050 var GSUP_IeValue an_apdu_ie;
6051 f_gsup_find_ie(prep_ho_req, OSMO_GSUP_AN_APDU_IE, an_apdu_ie);
6052 ho_request := dec_PDU_BSSAP(an_apdu_ie.an_apdu.pdu);
Neels Hofmeyrec2e1f72021-07-02 02:08:32 +02006053 if (not match(ho_request, expect_ho_request)) {
6054 setverdict(fail, "Wrong PDU in OSMO_GSUP_MSGT_E_PREPARE_HANDOVER_REQUEST message received");
6055 mtc.stop;
6056 }
Neels Hofmeyr906af102021-07-01 12:08:35 +02006057
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006058 /* Remote MSC has figured out its BSC and signals success */
6059 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
6060 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
6061 var PDU_BSSAP ho_req_ack := valueof(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
Neels Hofmeyr906af102021-07-01 12:08:35 +02006062 aoIPTransportLayer := omit,
6063 speechCodec := ts_BSSMAP_IE_SpeechCodec({ts_CodecFR}),
6064 chosenEncryptionAlgorithm := ho_request.pdu.bssmap.handoverRequest.chosenEncryptionAlgorithm));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006065 GSUP.send(ts_GSUP_E_PrepareHandoverResult(
6066 pars.imsi,
6067 ho_number,
6068 remote_msc_name, local_msc_name,
6069 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006, enc_PDU_BSSAP(ho_req_ack)))));
6070
6071 /* MSC forwards the RR Handover Command to old BSS */
6072 BSSAP.receive(tr_BSSMAP_HandoverCommand);
6073
6074 /* The MS shows up at remote new BSS */
6075
6076 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PROCESS_ACCESS_SIGNALLING_REQUEST,
6077 pars.imsi, remote_msc_name, local_msc_name,
6078 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
6079 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverDetect))))));
6080 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
6081 f_sleep(0.1);
6082
6083 /* Save the MS sequence counters for use on the other connection */
6084 var N_Sd_Array last_n_sd := f_bssmap_last_n_sd();
6085
6086 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_SEND_END_SIGNAL_REQUEST,
6087 pars.imsi, remote_msc_name, local_msc_name,
6088 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
6089 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverComplete))))));
6090
6091 /* The local BSS conn clears, all communication goes via remote MSC now */
6092 f_expect_clear();
6093
6094 /**********************************/
6095 /* Play through some signalling across the inter-MSC link.
6096 * This is a copy of f_tc_lu_and_mo_ussd_single_request() translated into GSUP AN-APDUs. */
6097
6098 if (false) {
6099 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
6100 invoke_id := 5, /* Phone may not start from 0 or 1 */
6101 op_code := SS_OP_CODE_PROCESS_USS_REQ,
6102 ussd_string := "*#100#"
6103 );
6104
6105 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
6106 invoke_id := 5, /* InvokeID shall be the same for both REQ and RSP */
6107 op_code := SS_OP_CODE_PROCESS_USS_REQ,
6108 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
6109 )
6110
6111 /* Compose a new SS/REGISTER message with request */
6112 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
6113 tid := 1, /* We just need a single transaction */
6114 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
6115 facility := valueof(facility_req)
6116 );
6117 var PDU_ML3_MS_NW ussd_req_v := valueof(ussd_req);
6118
6119 /* Compose SS/RELEASE_COMPLETE template with expected response */
6120 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
6121 tid := 1, /* Response should arrive within the same transaction */
6122 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
6123 facility := valueof(facility_rsp)
6124 );
6125
6126 /* Compose expected MSC -> HLR message */
6127 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
6128 imsi := g_pars.imsi,
6129 state := OSMO_GSUP_SESSION_STATE_BEGIN,
6130 ss := valueof(facility_req)
6131 );
6132
6133 /* To be used for sending response with correct session ID */
6134 var GSUP_PDU gsup_req_complete;
6135
6136 /* Request own number */
6137 /* From remote MSC instead of BSSAP directly */
6138 /* Patch the correct N_SD value into the message. */
6139 var octetstring l3_enc := enc_PDU_ML3_MS_NW(ussd_req_v);
6140 var RAN_Emulation.ConnectionData cd;
6141 f_ML3_patch_seq_nr_MS_NW(f_next_n_sd(last_n_sd, f_ML3_n_sd_idx(ussd_req_v)), l3_enc);
6142 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PROCESS_ACCESS_SIGNALLING_REQUEST,
6143 pars.imsi, remote_msc_name, local_msc_name,
6144 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
6145 enc_PDU_BSSAP(valueof(ts_BSSAP_DTAP(l3_enc)))
6146 ))
6147 ));
6148
6149 /* Expect GSUP message containing the SS payload */
6150 gsup_req_complete := f_expect_gsup_msg(gsup_req);
6151
6152 /* Compose the response from HLR using received session ID */
6153 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
6154 imsi := g_pars.imsi,
6155 sid := gsup_req_complete.ies[1].val.session_id,
6156 state := OSMO_GSUP_SESSION_STATE_END,
6157 ss := valueof(facility_rsp)
6158 );
6159
6160 /* Finally, HLR terminates the session */
6161 GSUP.send(gsup_rsp);
6162
6163 /* The USSD response goes out to remote MSC, on GSUP E instead of BSSAP */
6164 var GSUP_PDU gsup_ussd_rsp;
6165 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_FORWARD_ACCESS_SIGNALLING_REQUEST,
6166 pars.imsi, destination_name := remote_msc_name)) -> value gsup_ussd_rsp;
6167
6168 var GSUP_IeValue an_apdu;
6169 if (not f_gsup_find_ie(gsup_ussd_rsp, OSMO_GSUP_AN_APDU_IE, an_apdu)) {
6170 setverdict(fail, "No AN-APDU in received GSUP message. Expected USSD response in DTAP, got", gsup_ussd_rsp);
6171 mtc.stop;
6172 }
6173 var PDU_BSSAP bssap_dtap_mt := dec_PDU_BSSAP(an_apdu.an_apdu.pdu);
6174 var PDU_ML3_NW_MS dtap_mt := dec_PDU_ML3_NW_MS(bssap_dtap_mt.pdu.dtap);
6175 log("Expecting", ussd_rsp);
6176 log("Got", dtap_mt);
6177 if (not match(dtap_mt, ussd_rsp)) {
6178 setverdict(fail, "Unexpected GSUP message. Expected USSD response in DTAP, got", gsup_ussd_rsp);
6179 mtc.stop;
6180 }
6181 }
6182 /**********************************/
6183
6184
6185 /* inter-MSC handover back to the first MSC */
6186 f_create_bssmap_exp_handoverRequest(193);
6187 cil := { cIl_CGI := { ts_BSSMAP_CI_CGI('262'H, '42'H, 23, 42) } };
6188
6189 /* old BSS sends Handover Required, via inter-MSC E link: like
6190 * BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
6191 * but via GSUP */
6192 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_SUBSEQUENT_HANDOVER_REQUEST,
6193 pars.imsi, remote_msc_name, local_msc_name,
6194 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
6195 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverRequired(cause, cil)))
6196 ))
6197 ));
6198
6199 /* MSC asks local BSS to prepare Handover to it */
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006200 f_get_expected_encryption(encryptionInformation, chosenEncryptionAlgorithm, kC128, a5_perm_alg);
6201 expect_ho_request := tr_BSSMAP_HandoverRequest(encryptionInformation, chosenEncryptionAlgorithm, kC128);
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006202 alt {
Neels Hofmeyr906af102021-07-01 12:08:35 +02006203 [] BSSAP.receive(expect_ho_request) -> value ho_request;
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006204 [] BSSAP.receive(tr_BSSMAP_HandoverRequest) -> value ho_request {
6205 log("Error: Wrong handoverRequest received. Expected: ", expect_ho_request,
6206 " got ", ho_request);
6207 setverdict(fail, "Wrong handoverRequest received");
6208 mtc.stop;
6209 }
6210 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006211
6212 /* Make sure the new BSSAP conn continues with the correct N_SD sequence numbers */
6213 f_bssmap_continue_after_n_sd(last_n_sd);
6214
6215 /* new BSS composes a RR Handover Command */
6216 rr_ho_cmd := valueof(ts_RR_HandoverCommand);
6217 rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006218 var BSSMAP_IE_AoIP_TransportLayerAddress tla :=
6219 valueof(f_ts_BSSMAP_IE_AoIP_TLA(cpars.bss_rtp_ip, cpars.bss_rtp_port));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006220 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
Neels Hofmeyr906af102021-07-01 12:08:35 +02006221 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR}),
6222 chosenEncryptionAlgorithm := ho_request.pdu.bssmap.handoverRequest.chosenEncryptionAlgorithm));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006223
6224 /* HandoverCommand goes out via remote MSC-I */
6225 var GSUP_PDU prep_subsq_ho_res;
6226 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_SUBSEQUENT_HANDOVER_RESULT,
6227 pars.imsi, destination_name := remote_msc_name)) -> value prep_subsq_ho_res;
6228
6229 /* MS shows up at the local BSS */
6230 BSSAP.send(ts_BSSMAP_HandoverDetect);
6231 f_sleep(0.1);
6232 BSSAP.send(ts_BSSMAP_HandoverComplete);
6233
6234 /* Handover Succeeded message */
6235 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_FORWARD_ACCESS_SIGNALLING_REQUEST,
6236 pars.imsi, destination_name := remote_msc_name));
6237
6238 /* MS has handovered to here, Clear Command goes out via remote MSC-I -- in form of a GSUP Close. */
6239 GSUP.receive(tr_GSUP_E_NO_PDU(OSMO_GSUP_MSGT_E_CLOSE,
6240 pars.imsi, destination_name := remote_msc_name));
6241
6242 /* Handover ends successfully. Call goes on for a little longer and then we hang up. */
6243
6244 f_sleep(1.0);
6245 deactivate(ack_mdcx);
6246
6247 /* FIXME: the inter-MSC call has put a number of MNCC messages in the queue, which above code should expect and
6248 * clear out. The f_call_hangup() expects an MNCC_REL_IND, so, for the time being, just clear the MNCC messages
6249 * before starting the call hangup. Instead of this, the individual messages should be tested for above. */
6250 MNCC.clear;
6251
6252 var default ccrel := activate(as_optional_cc_rel(cpars, true));
6253 f_call_hangup(cpars, true);
6254 f_sleep(1.0);
6255 deactivate(ccrel);
6256
6257 setverdict(pass);
6258}
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006259function f_tc_ho_inter_msc_out_a5(integer a5_n) runs on MTC_CT {
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006260 var BSC_ConnHdlr vc_conn;
6261 f_init(1);
6262
6263 var BSC_ConnHdlrPars pars := f_init_pars(54);
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006264 pars.net.expect_ciph := a5_n > 0;
6265 pars.net.expect_auth := pars.net.expect_ciph;
6266 pars.net.kc_support := bit2oct('00000001'B << a5_n);
6267 pars.cm2.classmarkInformationType2_oct5.a5_3 := '1'B;
6268 pars.cm2.classmarkInformationType2_oct5.a5_2 := '0'B;
6269 pars.cm2.classmarkInformationType2_oct5.cm3 := '1'B;
6270 pars.cm3 := valueof(ts_CM3_default);
6271 pars.use_umts_aka := true;
6272
6273 if (a5_n > 0) {
6274 f_vty_config(MSCVTY, "network", "authentication required");
6275 }
6276 f_vty_config(MSCVTY, "network", "encryption a5 " & int2str(a5_n));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006277
Neels Hofmeyr60122f82021-07-28 17:59:38 +02006278 vc_conn := f_start_handler_with_pars(refers(f_tc_ho_inter_msc_out), pars);
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006279 vc_conn.done;
6280}
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006281testcase TC_ho_inter_msc_out() runs on MTC_CT {
6282 f_tc_ho_inter_msc_out_a5(0);
6283}
6284testcase TC_ho_inter_msc_out_a5_1() runs on MTC_CT {
6285 f_tc_ho_inter_msc_out_a5(1);
6286}
6287testcase TC_ho_inter_msc_out_a5_3() runs on MTC_CT {
6288 f_tc_ho_inter_msc_out_a5(3);
6289}
6290testcase TC_ho_inter_msc_out_a5_4() runs on MTC_CT {
6291 f_tc_ho_inter_msc_out_a5(4);
6292}
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006293testcase TC_ho_inter_msc_out_ipv6() runs on MTC_CT {
6294 var BSC_ConnHdlr vc_conn;
6295 f_init(1);
6296
6297 var BSC_ConnHdlrPars pars := f_init_pars(54);
6298 pars.use_ipv6 := true;
6299
Neels Hofmeyr60122f82021-07-28 17:59:38 +02006300 vc_conn := f_start_handler_with_pars(refers(f_tc_ho_inter_msc_out), pars);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006301 vc_conn.done;
6302}
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006303
Oliver Smith1d118ff2019-07-03 10:57:35 +02006304private function f_tc_lu_imsi_auth_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6305 pars.net.expect_auth := true;
6306 pars.net.expect_imei := true;
6307 f_init_handler(pars);
6308 f_perform_lu();
6309}
6310testcase TC_lu_imsi_auth_tmsi_check_imei() runs on MTC_CT {
6311 var BSC_ConnHdlr vc_conn;
6312 f_init();
6313 f_vty_config(MSCVTY, "network", "authentication required");
6314 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6315
6316 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei), 5);
6317 vc_conn.done;
6318}
6319
6320private function f_tc_lu_imsi_auth3g_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6321 pars.net.expect_auth := true;
6322 pars.use_umts_aka := true;
6323 pars.net.expect_imei := true;
6324 f_init_handler(pars);
6325 f_perform_lu();
6326}
6327testcase TC_lu_imsi_auth3g_tmsi_check_imei() runs on MTC_CT {
6328 var BSC_ConnHdlr vc_conn;
6329 f_init();
6330 f_vty_config(MSCVTY, "network", "authentication required");
6331 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6332
6333 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi_check_imei), 5);
6334 vc_conn.done;
6335}
6336
6337private function f_tc_lu_imsi_noauth_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6338 pars.net.expect_imei := true;
6339 f_init_handler(pars);
6340 f_perform_lu();
6341}
6342testcase TC_lu_imsi_noauth_tmsi_check_imei() runs on MTC_CT {
6343 var BSC_ConnHdlr vc_conn;
6344 f_init();
6345 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6346
6347 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi_check_imei), 5);
6348 vc_conn.done;
6349}
6350
6351private function f_tc_lu_imsi_noauth_notmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6352 pars.net.expect_tmsi := false;
6353 pars.net.expect_imei := true;
6354 f_init_handler(pars);
6355 f_perform_lu();
6356}
6357testcase TC_lu_imsi_noauth_notmsi_check_imei() runs on MTC_CT {
6358 var BSC_ConnHdlr vc_conn;
6359 f_init();
6360 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
6361 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6362
6363 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi_check_imei), 5);
6364 vc_conn.done;
6365}
6366
6367private function f_tc_lu_imsi_auth_tmsi_check_imei_nack(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6368 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02006369
6370 pars.net.expect_auth := true;
6371 pars.net.expect_imei := true;
6372 pars.net.check_imei_result := OSMO_GSUP_IMEI_RESULT_NACK;
6373 f_init_handler(pars);
6374
6375 /* Cannot use f_perform_lu() as we expect a reject */
6376 l3_lu := f_build_lu_imsi(g_pars.imsi)
6377 f_create_gsup_expect(hex2str(g_pars.imsi));
6378 f_bssap_compl_l3(l3_lu);
6379 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
6380
6381 f_mm_common();
6382 f_msc_lu_hlr();
6383 f_mm_imei();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02006384 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02006385 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02006386}
6387testcase TC_lu_imsi_auth_tmsi_check_imei_nack() runs on MTC_CT {
6388 var BSC_ConnHdlr vc_conn;
6389 f_init();
6390 f_vty_config(MSCVTY, "network", "authentication required");
6391 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6392
6393 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_nack), 5);
6394 vc_conn.done;
6395}
6396
6397private function f_tc_lu_imsi_auth_tmsi_check_imei_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6398 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02006399
6400 pars.net.expect_auth := true;
6401 pars.net.expect_imei := true;
6402 pars.net.check_imei_error := true;
6403 f_init_handler(pars);
6404
6405 /* Cannot use f_perform_lu() as we expect a reject */
6406 l3_lu := f_build_lu_imsi(g_pars.imsi)
6407 f_create_gsup_expect(hex2str(g_pars.imsi));
6408 f_bssap_compl_l3(l3_lu);
6409 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
6410
6411 f_mm_common();
6412 f_msc_lu_hlr();
6413 f_mm_imei();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02006414 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02006415 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02006416}
6417testcase TC_lu_imsi_auth_tmsi_check_imei_err() runs on MTC_CT {
6418 var BSC_ConnHdlr vc_conn;
6419 f_init();
6420 f_vty_config(MSCVTY, "network", "authentication required");
6421 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6422
6423 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_err), 5);
6424 vc_conn.done;
6425}
6426
6427private function f_tc_lu_imsi_auth_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6428 pars.net.expect_auth := true;
6429 pars.net.expect_imei_early := true;
6430 f_init_handler(pars);
6431 f_perform_lu();
6432}
6433testcase TC_lu_imsi_auth_tmsi_check_imei_early() runs on MTC_CT {
6434 var BSC_ConnHdlr vc_conn;
6435 f_init();
6436 f_vty_config(MSCVTY, "network", "authentication required");
6437 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6438
6439 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early), 5);
6440 vc_conn.done;
6441}
6442
6443private function f_tc_lu_imsi_auth3g_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6444 pars.net.expect_auth := true;
6445 pars.use_umts_aka := true;
6446 pars.net.expect_imei_early := true;
6447 f_init_handler(pars);
6448 f_perform_lu();
6449}
6450testcase TC_lu_imsi_auth3g_tmsi_check_imei_early() runs on MTC_CT {
6451 var BSC_ConnHdlr vc_conn;
6452 f_init();
6453 f_vty_config(MSCVTY, "network", "authentication required");
6454 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6455
6456 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi_check_imei_early), 5);
6457 vc_conn.done;
6458}
6459
6460private function f_tc_lu_imsi_noauth_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6461 pars.net.expect_imei_early := true;
6462 f_init_handler(pars);
6463 f_perform_lu();
6464}
6465testcase TC_lu_imsi_noauth_tmsi_check_imei_early() runs on MTC_CT {
6466 var BSC_ConnHdlr vc_conn;
6467 f_init();
6468 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6469
6470 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi_check_imei_early), 5);
6471 vc_conn.done;
6472}
6473
6474private function f_tc_lu_imsi_noauth_notmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6475 pars.net.expect_tmsi := false;
6476 pars.net.expect_imei_early := true;
6477 f_init_handler(pars);
6478 f_perform_lu();
6479}
6480testcase TC_lu_imsi_noauth_notmsi_check_imei_early() runs on MTC_CT {
6481 var BSC_ConnHdlr vc_conn;
6482 f_init();
6483 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
6484 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6485
6486 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi_check_imei_early), 5);
6487 vc_conn.done;
6488}
6489
6490private function f_tc_lu_imsi_auth_tmsi_check_imei_early_nack(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6491 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02006492
6493 pars.net.expect_auth := true;
6494 pars.net.expect_imei_early := true;
6495 pars.net.check_imei_result := OSMO_GSUP_IMEI_RESULT_NACK;
6496 f_init_handler(pars);
6497
6498 /* Cannot use f_perform_lu() as we expect a reject */
6499 l3_lu := f_build_lu_imsi(g_pars.imsi)
6500 f_create_gsup_expect(hex2str(g_pars.imsi));
6501 f_bssap_compl_l3(l3_lu);
6502 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
6503
6504 f_mm_imei_early();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02006505 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02006506 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02006507}
6508testcase TC_lu_imsi_auth_tmsi_check_imei_early_nack() runs on MTC_CT {
6509 var BSC_ConnHdlr vc_conn;
6510 f_init();
6511 f_vty_config(MSCVTY, "network", "authentication required");
6512 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6513
6514 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early_nack), 5);
6515 vc_conn.done;
6516}
6517
6518private function f_tc_lu_imsi_auth_tmsi_check_imei_early_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6519 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02006520
6521 pars.net.expect_auth := true;
6522 pars.net.expect_imei_early := true;
6523 pars.net.check_imei_error := true;
6524 f_init_handler(pars);
6525
6526 /* Cannot use f_perform_lu() as we expect a reject */
6527 l3_lu := f_build_lu_imsi(g_pars.imsi)
6528 f_create_gsup_expect(hex2str(g_pars.imsi));
6529 f_bssap_compl_l3(l3_lu);
6530 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
6531
6532 f_mm_imei_early();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02006533 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02006534 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02006535}
6536testcase TC_lu_imsi_auth_tmsi_check_imei_early_err() runs on MTC_CT {
6537 var BSC_ConnHdlr vc_conn;
6538 f_init();
6539 f_vty_config(MSCVTY, "network", "authentication required");
6540 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6541
6542 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early_err), 5);
6543 vc_conn.done;
6544}
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006545
Neels Hofmeyr8df69622019-11-02 19:16:03 +01006546friend function f_tc_invalid_mgcp_crash(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6547 f_init_handler(pars);
6548 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
6549
6550 /* Set invalid IP address so that osmo-msc discards the rtp_stream and MGCP endpoint FSM instances in the middle
6551 * of successful MGCP response dispatch. If things aren't safeguarded, the on_success() in osmo_mgcpc_ep_fsm
6552 * will cause a use-after-free after that event dispatch. */
6553 cpars.mgw_conn_1.mgw_rtp_ip := "0.0.0.0";
6554 cpars.mgw_conn_2.mgw_rtp_ip := "0.0.0.0";
6555 cpars.rtp_sdp_format := "FOO/8000";
6556 cpars.expect_release := true;
6557
6558 f_perform_lu();
6559 f_mo_call_establish(cpars);
6560}
6561testcase TC_invalid_mgcp_crash() runs on MTC_CT {
6562 var BSC_ConnHdlr vc_conn;
6563 f_init();
6564
6565 vc_conn := f_start_handler(refers(f_tc_invalid_mgcp_crash), 7);
6566 vc_conn.done;
6567}
6568
Vadim Yanitskiyeddebaa2019-12-28 17:45:34 +01006569friend function f_tc_mm_id_resp_no_identity(charstring id, BSC_ConnHdlrPars pars)
6570runs on BSC_ConnHdlr {
6571 pars.tmsi := 'FFFFFFFF'O;
6572 f_init_handler(pars);
6573
6574 f_create_gsup_expect(hex2str(g_pars.imsi));
6575
6576 /* Initiate Location Updating using an unknown TMSI */
6577 f_bssap_compl_l3(f_build_lu_tmsi(pars.tmsi));
6578
6579 /* Expect an Identity Request, send response with no identity */
6580 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
6581 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp({
6582 lengthIndicator := 1,
6583 mobileIdentityV := {
6584 typeOfIdentity := '000'B,
6585 oddEvenInd_identity := {
6586 no_identity := {
6587 oddevenIndicator := '0'B,
6588 fillerDigits := '00000'H
6589 }
6590 }
6591 }
6592 })));
6593
6594 f_expect_lu_reject();
6595 f_expect_clear();
6596}
6597testcase TC_mm_id_resp_no_identity() runs on MTC_CT {
6598 var BSC_ConnHdlr vc_conn;
6599
6600 f_init();
6601
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02006602 vc_conn := f_start_handler(refers(f_tc_mm_id_resp_no_identity), 7, verify_cell_id := false);
Vadim Yanitskiyeddebaa2019-12-28 17:45:34 +01006603 vc_conn.done;
6604}
6605
Vadim Yanitskiy25219062020-01-21 01:41:33 +07006606/* Verify the case when T3212 expires during Paging procedure, just before the receipt
6607 * of Paging Response. This used to provoke a NULL-pointer dereference in old versions
6608 * of OsmoMSC, but apparently the bug has been fixed, and we're safe now. */
6609friend function f_tc_lu_and_expire_while_paging(charstring id, BSC_ConnHdlrPars pars)
6610runs on BSC_ConnHdlr {
6611 var charstring imsi := hex2str(pars.imsi);
6612
6613 f_init_handler(pars);
6614
6615 /* Perform location update */
6616 f_perform_lu();
6617
6618 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
6619 f_create_gsup_expect(hex2str(g_pars.imsi));
6620
6621 /* Initiate paging procedure from the VTY */
6622 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " paging");
6623 f_expect_paging();
6624
6625 /* Emulate T3212 expiration during paging (we don't want to wait, right?) */
6626 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " expire");
6627
6628 /* MS sends PAGING RESPONSE, *old* OsmoMSC crashes here... */
6629 f_establish_fully(EST_TYPE_PAG_RESP);
6630
6631 /* The recent OsmoMSC keeps subscriber in its VLR unless the Paging is completed.
6632 * In this case we do not send anything and just wait for a Clear Command. */
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02006633 f_expect_clear(verify_vlr_cell_id := false);
Vadim Yanitskiy25219062020-01-21 01:41:33 +07006634}
6635testcase TC_lu_and_expire_while_paging() runs on MTC_CT {
6636 var BSC_ConnHdlr vc_conn;
6637
6638 f_init();
6639
6640 vc_conn := f_start_handler(refers(f_tc_lu_and_expire_while_paging), 7);
6641 vc_conn.done;
6642}
6643
Neels Hofmeyr4f099b42021-07-27 03:45:26 +02006644const charstring REEST_LOST_CONNECTION := "REEST_LOST_CONNECTION";
6645const charstring REEST_CLEARED := "REEST_CLEARED";
6646
6647friend function f_tc_call_re_establishment_1(charstring id, BSC_ConnHdlrPars pars)
6648 runs on BSC_ConnHdlr {
6649 f_init_handler(pars, t_guard := 30.0);
6650
6651 f_perform_lu();
6652
6653 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
6654 f_mo_call_establish(cpars);
6655 f_sleep(3.0);
6656 COORD.send(REEST_LOST_CONNECTION);
6657 COORD.send(cpars);
6658 f_expect_clear(verify_vlr_cell_id := false);
6659 COORD.send(REEST_CLEARED);
6660}
6661
6662friend function f_tc_call_re_establishment_2(charstring id, BSC_ConnHdlrPars pars)
6663 runs on BSC_ConnHdlr {
6664 f_init_handler(pars, t_guard := 30.0);
6665 var CallParameters cpars;
6666
6667 COORD.receive(REEST_LOST_CONNECTION);
6668 COORD.receive(tr_CallParams) -> value cpars;
6669
6670 f_gsup_change_connhdlr(hex2str(g_pars.imsi));
6671 f_create_smpp_expect(hex2str(pars.msisdn));
6672
6673 /* The MS has lost the first channel and decides to show up on a new conn (on a nearby neighbor cell) to ask for
6674 * CM Re-Establishment. Send a Complete Layer 3 to osmo-msc with a CM Re-Establishment Request. */
6675 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
6676 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_REESTABL_REQ(mi));
6677 f_cl3_or_initial_ue(l3_info);
6678
6679 /* At this point the other test component should receive the Clear Command for the first A connection. */
6680
6681 /* This new connection continues with Authentication... */
6682 f_mm_common();
6683
6684 /* ...and with Assignment of a voice channel. */
6685 var template BSSMAP_IE_AoIP_TransportLayerAddress tla_ass :=
6686 f_tr_BSSMAP_IE_AoIP_TLA(cpars.mgw_conn_1.mgw_rtp_ip, ?);
6687 BSSAP.receive(tr_BSSMAP_AssignmentReq(omit, tla_ass));
6688 /* By this Assignment Request, the CM Re-Establishment Request is implicitly accepted. */
6689
6690 /* Send Assignment Complete from BSC */
6691 var template BSSMAP_IE_AoIP_TransportLayerAddress tla;
6692 tla := f_ts_BSSMAP_IE_AoIP_TLA(cpars.bss_rtp_ip, cpars.bss_rtp_port);
6693 var BSSMAP_IE_SpeechCodec codec;
6694 codec := valueof(ts_BSSMAP_IE_SpeechCodec({ts_CodecFR}));
6695
6696 /* Make really sure the other component is done with its MGCP */
6697 COORD.receive(REEST_CLEARED);
6698
6699 /* Transfer state for this call over to this test component so we can resolve MNCC and MGCP in this function. */
6700 f_mncc_change_connhdlr(cpars.mncc_callref);
6701 f_mgcp_change_connhdlr(cpars.mgcp_ep);
6702
6703 /* osmo-msc may redirect the MGW endpoint to the newly allocated channel.
6704 * Apparently osmo-msc currently also sends an MDCX to the CN side, just repeating the same configuration that
6705 * is already in use. This test accepts any number of or even lack of MDCX. */
6706 var default ack_mdcx := activate(as_mgcp_ack_all_mdcx(cpars));
6707
6708 BSSAP.send(ts_BSSMAP_AssignmentComplete(omit, tla, codec));
6709 /* The call has been fully re-established.
6710 * Let a bit of time pass before hanging up, for everything to settle. */
6711 f_sleep(3.0);
6712
6713 deactivate(ack_mdcx);
6714
6715 /* Hang up the call and clear the new, second A connection */
6716 var default ack_dlcx := activate(as_mgcp_ack_all_dlcx(cpars));
6717
6718 /* CC release. This is the proper MS initiated release sequence as shown by
6719 * https://git.osmocom.org/osmo-msc/tree/doc/sequence_charts/voice_call_full.msc?id=e53ecde83e4fb2470209e818e9ad76a2d6a19190
6720 * f_call_hangup() seems a bit mixed up, so here a "proper" sequence. Fix of f_call_hangup() pending. */
6721 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_DISC(cpars.transaction_id, '0'B, '0000000'B)));
6722 MNCC.receive(tr_MNCC_DISC_ind(cpars.mncc_callref));
6723 MNCC.send(ts_MNCC_REL_req(cpars.mncc_callref, valueof(ts_MNCC_cause(23))));
6724 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id)));
6725 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id, '0'B)));
6726 MNCC.receive(tr_MNCC_REL_cnf(cpars.mncc_callref, cause := *));
6727
6728 /* BSSAP clear */
6729 interleave {
6730 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {
6731 BSSAP.send(ts_BSSMAP_ClearComplete);
6732 }
6733 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND);
6734 }
6735
6736 f_sleep(1.0);
6737 deactivate(ack_dlcx);
6738}
6739
6740testcase TC_call_re_establishment() runs on MTC_CT {
6741 var BSC_ConnHdlr vc_conn1;
6742 var BSC_ConnHdlr vc_conn2;
6743 f_init();
6744
6745 var BSC_ConnHdlrPars pars1 := f_init_pars(91);
6746 var BSC_ConnHdlrPars pars2 := pars1;
6747
6748 vc_conn1 := f_start_handler_create(pars1);
6749 vc_conn2 := f_start_handler_create(pars2);
6750 connect(vc_conn1:COORD, vc_conn2:COORD);
6751 f_start_handler_run(vc_conn1, refers(f_tc_call_re_establishment_1), pars1);
6752 f_start_handler_run(vc_conn2, refers(f_tc_call_re_establishment_2), pars2);
6753 vc_conn1.done;
6754 vc_conn2.done;
6755}
6756
Neels Hofmeyra9b2dcf2021-07-28 00:57:58 +02006757testcase TC_call_re_establishment_auth() runs on MTC_CT {
6758 var BSC_ConnHdlr vc_conn1;
6759 var BSC_ConnHdlr vc_conn2;
6760 f_init();
6761
6762 f_vty_config(MSCVTY, "network", "authentication required");
6763
6764 var BSC_ConnHdlrPars pars1 := f_init_pars(92);
6765 pars1.net.expect_auth := true;
6766 var BSC_ConnHdlrPars pars2 := pars1;
6767
6768 vc_conn1 := f_start_handler_create(pars1);
6769 vc_conn2 := f_start_handler_create(pars2);
6770 connect(vc_conn1:COORD, vc_conn2:COORD);
6771 f_start_handler_run(vc_conn1, refers(f_tc_call_re_establishment_1), pars1);
6772 f_start_handler_run(vc_conn2, refers(f_tc_call_re_establishment_2), pars2);
6773 vc_conn1.done;
6774 vc_conn2.done;
6775}
6776
Neels Hofmeyr48e4d7d2021-07-28 00:57:58 +02006777testcase TC_call_re_establishment_ciph() runs on MTC_CT {
6778 var BSC_ConnHdlr vc_conn1;
6779 var BSC_ConnHdlr vc_conn2;
6780 f_init();
6781
6782 f_vty_config(MSCVTY, "network", "authentication required");
6783 f_vty_config(MSCVTY, "network", "encryption a5 3");
6784
6785 var BSC_ConnHdlrPars pars1 := f_init_pars(92);
6786 pars1.net.expect_auth := true;
6787 pars1.net.expect_ciph := true;
6788 pars1.net.kc_support := '08'O; /* A5/3 only */
6789 var BSC_ConnHdlrPars pars2 := pars1;
6790
6791 vc_conn1 := f_start_handler_create(pars1);
6792 vc_conn2 := f_start_handler_create(pars2);
6793 connect(vc_conn1:COORD, vc_conn2:COORD);
6794 f_start_handler_run(vc_conn1, refers(f_tc_call_re_establishment_1), pars1);
6795 f_start_handler_run(vc_conn2, refers(f_tc_call_re_establishment_2), pars2);
6796 vc_conn1.done;
6797 vc_conn2.done;
6798}
6799
Harald Weltef6dd64d2017-11-19 12:09:51 +01006800control {
Philipp Maier328d1662018-03-07 10:40:27 +01006801 execute( TC_cr_before_reset() );
Harald Weltea49e36e2018-01-21 19:29:33 +01006802 execute( TC_lu_imsi_noauth_tmsi() );
Harald Welted2328a22018-01-27 14:27:16 +01006803 execute( TC_lu_imsi_noauth_notmsi() );
Harald Weltea49e36e2018-01-21 19:29:33 +01006804 execute( TC_lu_imsi_reject() );
6805 execute( TC_lu_imsi_timeout_gsup() );
Harald Welted2328a22018-01-27 14:27:16 +01006806 execute( TC_lu_imsi_auth_tmsi() );
Harald Welte8a397ae2019-04-21 22:03:37 +02006807 execute( TC_lu_imsi_auth3g_tmsi() );
Pau Espin Pedrold3d54a92019-12-17 17:02:54 +01006808 execute( TC_lu_imsi_timeout_tmsi_realloc() );
Harald Welted2328a22018-01-27 14:27:16 +01006809 execute( TC_cmserv_imsi_unknown() );
Neels Hofmeyr13737fb2020-08-19 13:16:14 +00006810 execute( TC_cmserv_tmsi_unknown() );
Harald Welte2bb825f2018-01-22 11:31:18 +01006811 execute( TC_lu_and_mo_call() );
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006812 execute( TC_lu_and_mo_call_ipv6() );
Pau Espin Pedrola42745c2020-01-10 18:03:28 +01006813 execute( TC_lu_and_mo_call_sccp_tiar_timeout() );
Harald Welte071ed732018-01-23 19:53:52 +01006814 execute( TC_lu_auth_sai_timeout() );
6815 execute( TC_lu_auth_sai_err() );
Harald Weltee1a2f3c2018-01-24 17:28:48 +01006816 execute( TC_lu_clear_request() );
Vadim Yanitskiy109e7552021-02-05 05:36:02 +01006817 execute( TC_mo_call_clear_request() );
6818 execute( TC_mt_call_clear_request() );
Harald Weltee1a2f3c2018-01-24 17:28:48 +01006819 execute( TC_lu_disconnect() );
6820 execute( TC_lu_by_imei() );
6821 execute( TC_lu_by_tmsi_noauth_unknown() );
Neels Hofmeyrfc06c732020-08-19 12:52:28 +00006822 execute( TC_attached_imsi_lu_unknown_tmsi() );
Harald Weltee1a2f3c2018-01-24 17:28:48 +01006823 execute( TC_imsi_detach_by_imsi() );
6824 execute( TC_imsi_detach_by_tmsi() );
6825 execute( TC_imsi_detach_by_imei() );
6826 execute( TC_emerg_call_imei_reject() );
6827 execute( TC_emerg_call_imsi() );
6828 execute( TC_cm_serv_req_vgcs_reject() );
6829 execute( TC_cm_serv_req_vbs_reject() );
6830 execute( TC_cm_serv_req_lcs_reject() );
Harald Welte0195ab12018-01-24 21:50:20 +01006831 execute( TC_cm_reest_req_reject() );
Harald Welte1af6ea82018-01-25 18:33:15 +01006832 execute( TC_lu_auth_2G_fail() );
6833 execute( TC_lu_imsi_auth_tmsi_encr_13_13() );
6834 execute( TC_cl3_no_payload() );
6835 execute( TC_cl3_rnd_payload() );
Harald Welte1852a842018-01-26 22:53:36 +01006836 execute( TC_establish_and_nothing() );
6837 execute( TC_mo_setup_and_nothing() );
6838 execute( TC_mo_crcx_ran_timeout() );
6839 execute( TC_mo_crcx_ran_reject() );
Harald Welted2328a22018-01-27 14:27:16 +01006840 execute( TC_mt_crcx_ran_reject() );
Daniel Willmann8b084372018-02-04 13:35:26 +01006841 execute( TC_mo_setup_and_dtmf_dup() );
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01006842 execute( TC_mt_t310() );
Harald Welte167458a2018-01-27 15:58:16 +01006843 execute( TC_gsup_cancel() );
Harald Welte9de84792018-01-28 01:06:35 +01006844 execute( TC_lu_imsi_auth_tmsi_encr_1_13() );
6845 execute( TC_lu_imsi_auth_tmsi_encr_3_13() );
6846 execute( TC_lu_imsi_auth_tmsi_encr_3_1() );
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01006847 execute( TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() );
Harald Welte9de84792018-01-28 01:06:35 +01006848 execute( TC_lu_imsi_auth_tmsi_encr_13_2() );
6849 execute( TC_lu_imsi_auth_tmsi_encr_013_2() );
Eric Wild26f4a622021-05-17 15:27:05 +02006850 execute( TC_lu_imsi_auth_tmsi_encr_0134_1() );
6851 execute( TC_lu_imsi_auth_tmsi_encr_0134_34() );
6852 execute( TC_lu_imsi_auth_tmsi_encr_0134_34_no_cm3() );
6853
Philipp Maier94f3f1b2018-03-15 18:54:13 +01006854 execute( TC_mo_release_timeout() );
Philipp Maier2a98a732018-03-19 16:06:12 +01006855 execute( TC_lu_and_mt_call_no_dlcx_resp() );
Philipp Maier75932982018-03-27 14:52:35 +02006856 execute( TC_reset_two() );
Harald Welte33ec09b2018-02-10 15:34:46 +01006857
6858 execute( TC_lu_and_mt_call() );
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006859 execute( TC_lu_and_mt_call_ipv6() );
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01006860 execute( TC_lu_and_mt_call_already_paging() );
Pau Espin Pedrol9a732a42020-09-15 15:56:33 +02006861 execute( TC_lu_and_mt_call_osmux() );
Harald Welte33ec09b2018-02-10 15:34:46 +01006862
Harald Weltef45efeb2018-04-09 18:19:24 +02006863 execute( TC_lu_and_mo_sms() );
6864 execute( TC_lu_and_mt_sms() );
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01006865 execute( TC_lu_and_mt_sms_already_paging() );
Philipp Maier3983e702018-11-22 19:01:33 +01006866 execute( TC_lu_and_mt_sms_paging_and_nothing() );
Alexander Couzensfc02f242019-09-12 03:43:18 +02006867 execute( TC_lu_and_mt_sms_paging_repeated() );
Harald Weltef640a012018-04-14 17:49:21 +02006868 execute( TC_smpp_mo_sms() );
Vadim Yanitskiy33820762020-01-15 11:26:07 +07006869 execute( TC_smpp_mo_sms_rp_error() );
Harald Weltef640a012018-04-14 17:49:21 +02006870 execute( TC_smpp_mt_sms() );
Harald Weltef45efeb2018-04-09 18:19:24 +02006871
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07006872 execute( TC_gsup_mo_sms() );
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07006873 execute( TC_gsup_mo_smma() );
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07006874 execute( TC_gsup_mt_sms_ack() );
6875 execute( TC_gsup_mt_sms_err() );
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07006876 execute( TC_gsup_mt_sms_rp_mr() );
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07006877 execute( TC_gsup_mo_mt_sms_rp_mr() );
Vadim Yanitskiya2a8a112019-07-08 20:04:32 +07006878 execute( TC_gsup_mt_multi_part_sms() );
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07006879
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07006880 execute( TC_lu_and_mo_ussd_single_request() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07006881 execute( TC_lu_and_mt_ussd_notification() );
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07006882 execute( TC_lu_and_mo_ussd_during_mt_call() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07006883 execute( TC_lu_and_mt_ussd_during_mt_call() );
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07006884 execute( TC_lu_and_mo_ussd_mo_release() );
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07006885 execute( TC_lu_and_ss_session_timeout() );
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07006886
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07006887 execute( TC_mt_ussd_for_unknown_subscr() );
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07006888 execute( TC_mo_ussd_for_unknown_trans() );
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07006889 execute( TC_proc_ss_for_unknown_session() );
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07006890 execute( TC_proc_ss_paging_fail() );
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07006891 execute( TC_proc_ss_abort() );
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07006892
Vadim Yanitskiy1c9754d2020-01-07 21:56:55 +01006893 execute( TC_multi_lu_and_mo_ussd() );
6894 execute( TC_multi_lu_and_mt_ussd() );
6895
Stefan Sperling89eb1f32018-12-17 15:06:20 +01006896 execute( TC_cipher_complete_with_invalid_cipher() );
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01006897 execute( TC_cipher_complete_1_without_cipher() );
6898 execute( TC_cipher_complete_3_without_cipher() );
6899 execute( TC_cipher_complete_13_without_cipher() );
Harald Welteb2284bd2019-05-10 11:30:43 +02006900 execute( TC_lu_with_invalid_mcc_mnc() );
Stefan Sperling89eb1f32018-12-17 15:06:20 +01006901
Harald Welte4263c522018-12-06 11:56:27 +01006902 execute( TC_sgsap_reset() );
6903 execute( TC_sgsap_lu() );
6904 execute( TC_sgsap_lu_imsi_reject() );
6905 execute( TC_sgsap_lu_and_nothing() );
6906 execute( TC_sgsap_expl_imsi_det_eps() );
Philipp Maierfc19f172019-03-21 11:17:54 +01006907 execute( TC_sgsap_impl_imsi_det_eps() );
Harald Welte4263c522018-12-06 11:56:27 +01006908 execute( TC_sgsap_expl_imsi_det_noneps() );
Philipp Maier5d812702019-03-21 10:51:26 +01006909 execute( TC_sgsap_impl_imsi_det_noneps() );
Harald Welte4263c522018-12-06 11:56:27 +01006910 execute( TC_sgsap_paging_rej() );
6911 execute( TC_sgsap_paging_subscr_rej() );
6912 execute( TC_sgsap_paging_ue_unr() );
6913 execute( TC_sgsap_paging_and_nothing() );
6914 execute( TC_sgsap_paging_and_lu() );
6915 execute( TC_sgsap_mt_sms() );
6916 execute( TC_sgsap_mo_sms() );
6917 execute( TC_sgsap_mt_sms_and_nothing() );
6918 execute( TC_sgsap_mt_sms_and_reject() );
6919 execute( TC_sgsap_unexp_ud() );
6920 execute( TC_sgsap_unsol_ud() );
6921 execute( TC_bssap_lu_sgsap_lu_and_mt_call() );
6922 execute( TC_sgsap_lu_and_mt_call() );
Philipp Maier628c0052019-04-09 17:36:57 +02006923 execute( TC_sgsap_vlr_failure() );
Harald Welte4263c522018-12-06 11:56:27 +01006924
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006925 execute( TC_ho_inter_bsc_unknown_cell() );
6926 execute( TC_ho_inter_bsc() );
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02006927 execute( TC_ho_inter_bsc_a5_1() );
6928 execute( TC_ho_inter_bsc_a5_3() );
6929 execute( TC_ho_inter_bsc_a5_4() );
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006930 execute( TC_ho_inter_bsc_ipv6() );
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006931
6932 execute( TC_ho_inter_msc_out() );
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006933 execute( TC_ho_inter_msc_out_a5_1() );
6934 execute( TC_ho_inter_msc_out_a5_3() );
6935 execute( TC_ho_inter_msc_out_a5_4() );
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006936 execute( TC_ho_inter_msc_out_ipv6() );
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006937
Oliver Smith1d118ff2019-07-03 10:57:35 +02006938 execute( TC_lu_imsi_auth_tmsi_check_imei() );
6939 execute( TC_lu_imsi_auth3g_tmsi_check_imei() );
6940 execute( TC_lu_imsi_noauth_tmsi_check_imei() );
6941 execute( TC_lu_imsi_noauth_notmsi_check_imei() );
6942 execute( TC_lu_imsi_auth_tmsi_check_imei_nack() );
6943 execute( TC_lu_imsi_auth_tmsi_check_imei_err() );
6944 execute( TC_lu_imsi_auth_tmsi_check_imei_early() );
6945 execute( TC_lu_imsi_auth3g_tmsi_check_imei_early() );
6946 execute( TC_lu_imsi_noauth_tmsi_check_imei_early() );
6947 execute( TC_lu_imsi_noauth_notmsi_check_imei_early() );
6948 execute( TC_lu_imsi_auth_tmsi_check_imei_early_nack() );
6949 execute( TC_lu_imsi_auth_tmsi_check_imei_early_err() );
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01006950 execute( TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() );
Pau Espin Pedrol609f1d62020-09-15 16:01:55 +02006951
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02006952 execute( TC_mo_cc_bssmap_clear() );
Neels Hofmeyr8df69622019-11-02 19:16:03 +01006953 execute( TC_invalid_mgcp_crash() );
Vadim Yanitskiyeddebaa2019-12-28 17:45:34 +01006954 execute( TC_mm_id_resp_no_identity() );
Vadim Yanitskiy25219062020-01-21 01:41:33 +07006955 execute( TC_lu_and_expire_while_paging() );
Pau Espin Pedrol174fac22021-02-26 13:20:10 +01006956 execute( TC_paging_response_imsi_unknown() );
6957 execute( TC_paging_response_tmsi_unknown() );
Neels Hofmeyr4f099b42021-07-27 03:45:26 +02006958
6959 execute( TC_call_re_establishment() );
Neels Hofmeyra9b2dcf2021-07-28 00:57:58 +02006960 execute( TC_call_re_establishment_auth() );
Neels Hofmeyr48e4d7d2021-07-28 00:57:58 +02006961 execute( TC_call_re_establishment_ciph() );
Harald Weltef6dd64d2017-11-19 12:09:51 +01006962}
6963
6964
6965}