blob: aa23a8474cbf57d59a6f7165deb91e522f42f150 [file] [log] [blame]
Harald Welteb8a4ac82019-06-23 11:04:12 +02001/* MME (Mobility Management Engine) test suite in TTCN-3
2 * (C) 2019 Harald Welte <laforge@gnumonks.org>
3 * All rights reserved.
4 *
5 * Released under the terms of GNU General Public License, Version 2 or
6 * (at your option) any later version.
7 *
8 * SPDX-License-Identifier: GPL-2.0-or-later
9 */
10
11module MME_Tests {
12
Harald Welte95333a12019-07-11 22:51:45 +080013import from General_Types all;
Philipp Maier74d776a2023-07-12 14:04:14 +020014import from Native_Functions all;
15import from IPL4asp_Types all;
Pau Espin Pedrolecfc7d62023-12-13 18:49:29 +010016import from Misc_Helpers all;
Harald Welte95333a12019-07-11 22:51:45 +080017import from S1AP_Types all;
18import from S1AP_Templates all;
19import from S1AP_Emulation all;
20import from S1AP_PDU_Descriptions all;
21import from S1AP_IEs all;
Philipp Maiera9306202023-07-24 11:41:51 +020022import from S1AP_PDU_Contents all;
23import from S1AP_Constants all;
Harald Welte95333a12019-07-11 22:51:45 +080024
25import from NAS_EPS_Types all;
26import from NAS_Templates all;
27
Harald Welte6ec64392019-08-14 12:37:07 +020028import from DIAMETER_Types all;
29import from DIAMETER_Templates all;
Pau Espin Pedrol117a94f2023-12-21 16:10:12 +010030import from DIAMETER_ts29_272_Templates all;
Harald Welte6ec64392019-08-14 12:37:07 +020031import from DIAMETER_Emulation all;
32
Harald Welteb8a4ac82019-06-23 11:04:12 +020033import from SGsAP_Types all;
34import from SGsAP_Templates all;
35import from SGsAP_Emulation all;
36
Philipp Maier74d776a2023-07-12 14:04:14 +020037import from GTP_Emulation all;
38import from GTP_Templates all;
39import from GTP_CodecPort all;
40import from GTPC_Types all;
41
Harald Welte95333a12019-07-11 22:51:45 +080042import from LTE_CryptoFunctions all;
43
Harald Welteb8a4ac82019-06-23 11:04:12 +020044import from L3_Templates all;
45import from DNS_Helpers all;
Harald Welte95333a12019-07-11 22:51:45 +080046import from Osmocom_Types all;
Philipp Maiera9306202023-07-24 11:41:51 +020047import from Osmocom_Gb_Types all;
Harald Welteb8a4ac82019-06-23 11:04:12 +020048
Philipp Maier9abb8c92023-08-31 13:12:28 +020049import from GTPv2_Types all;
50import from GTPv2_Templates all;
51import from GTPv2_Emulation all;
52
Harald Welteb8a4ac82019-06-23 11:04:12 +020053friend module MME_Tests_SGsAP;
54
Harald Welte95333a12019-07-11 22:51:45 +080055/* (maximum) number of emulated eNBs */
56const integer NUM_ENB := 3;
57
58/* (maximum) number of emulated UEs */
59const integer NUM_UE := 3;
60
61/* parameters of emulated ENB */
62type record EnbParams {
63 Global_ENB_ID global_enb_id,
64 integer cell_identity,
65 SupportedTAs supported_tas
66}
67
Pau Espin Pedrolecfc7d62023-12-13 18:49:29 +010068type record BearerConfig {
69 /* EPS Bearer ID */
70 uint4_t ebi optional,
71 /* TEI (Data) local side, S11 (SGW) */
72 OCT4 s11_teid_local optional,
73 /* TEI (Data) remote side, S11 (SGW) */
74 OCT4 s11_teid_remote optional,
75 /* TEI (Data) local side, S5c (PGW) */
76 OCT4 s5c_teid_local optional,
77 /* TEI (Data) remote side, S5c (PGW) */
78 OCT4 s5c_teid_remote optional
79};
80
Harald Welte95333a12019-07-11 22:51:45 +080081/* parameters of emulated UE */
82type record UeParams {
Pau Espin Pedrolecfc7d62023-12-13 18:49:29 +010083 hexstring imsi,
84 charstring ue_ip,
Pau Espin Pedrol408e0ae2023-12-15 18:56:31 +010085 NAS_EPS_Types.GUTI guti optional,
Pau Espin Pedrol3be4d922024-01-15 15:21:57 +010086 octetstring kasme optional,
Pau Espin Pedrolecfc7d62023-12-13 18:49:29 +010087
88 /* TEI (Control) local side, S11 (SGW) */
89 OCT4 s11_teic_local,
90 /* TEI (Control) remote side, S11 (SGW) */
91 OCT4 s11_teic_remote optional,
92 /* TEI (Control) local side, S5c (PGW) */
93 OCT4 s5c_teic_local,
94 /* TEI (Control) remote side, S5c (PGW) */
95 OCT4 s5c_teic_remote optional,
96
97 BearerConfig bearer optional
Harald Welte95333a12019-07-11 22:51:45 +080098}
99
Harald Welteb8a4ac82019-06-23 11:04:12 +0200100type component MTC_CT {
Harald Welte95333a12019-07-11 22:51:45 +0800101 /* S1 intreface of emulated ENBs */
102 var EnbParams g_enb_pars[NUM_ENB];
103 var S1AP_Emulation_CT vc_S1AP[NUM_ENB];
104 port S1AP_PT S1AP_UNIT[NUM_ENB];
105 port S1APEM_PROC_PT S1AP_PROC[NUM_ENB];
106
Harald Welte6ec64392019-08-14 12:37:07 +0200107 /* S6a/S6d interface of emulated HSS */
108 var DIAMETER_Emulation_CT vc_DIAMETER;
109 port DIAMETER_PT DIAMETER_UNIT;
110 port DIAMETEREM_PROC_PT DIAMETER_PROC;
111
Harald Welte95333a12019-07-11 22:51:45 +0800112 /* SGs interface of emulated MSC/VLR */
Harald Welteb8a4ac82019-06-23 11:04:12 +0200113 var SGsAP_Emulation_CT vc_SGsAP;
114 port SGsAP_PT SGsAP_UNIT;
115 port SGsAPEM_PROC_PT SGsAP_PROC;
Harald Welte95333a12019-07-11 22:51:45 +0800116
Philipp Maier74d776a2023-07-12 14:04:14 +0200117 /* Gn interface (GTPv1C) of emulated SGSN (Rel. 7) */
118 var GTP_Emulation_CT vc_GTP;
119
Philipp Maier9abb8c92023-08-31 13:12:28 +0200120 /* S11 interface (GTPv2C) of emulated SGW-C */
121 var GTPv2_Emulation_CT vc_GTP2;
122 port GTP2EM_PT TEID0;
123
Harald Welte95333a12019-07-11 22:51:45 +0800124 var UeParams g_ue_pars[NUM_UE];
Harald Welteb8a4ac82019-06-23 11:04:12 +0200125}
126
Philipp Maiera9306202023-07-24 11:41:51 +0200127/* Encode an S1AP Global-ENB-ID into an octetstring */
128private function enc_S1AP_Global_ENB_ID(Global_ENB_ID global_enb_id) return octetstring {
129
130 /* Due to the limitations of libfftranscode, we can not define encoders (or decoders) for individual
131 * information elements (in S1AP_Types.cc). Unfortuantely Global-ENB-ID also appears in BSSGP in its
132 * encoded form. (see also: GTP-C 3GPP TS 48.018, section 11.3.70). To encode a given Global-ENB-ID
133 * we craft a full S1AP PDU and encode it. Then we can cut out the encoded Global-ENB-ID from the
134 * generated octetstring. */
135
136 var SupportedTAs supported_tas_dummy := {{
137 tAC := '0000'O,
138 broadcastPLMNs := { '00f000'O },
139 iE_Extensions := omit
140 }};
141 var octetstring encoded;
142 var integer global_enb_id_len;
143
144 if (ispresent(global_enb_id.eNB_ID.macroENB_ID)) {
145 global_enb_id_len := 8;
146 } else {
147 /* All other ENB ID types fit into 8 byte (homeENB_ID, short_macroENB_ID, long_macroENB_ID) */
148 global_enb_id_len := 9;
149 }
150
151 encoded := enc_S1AP_PDU(valueof(ts_S1AP_SetupReq(global_enb_id, supported_tas_dummy, v32)));
152
153 return substr(encoded, 11, global_enb_id_len);
154}
155
Philipp Maier9abb8c92023-08-31 13:12:28 +0200156type component ConnHdlr extends S1AP_ConnHdlr, SGsAP_ConnHdlr, DIAMETER_ConnHdlr, GTP_ConnHdlr, GTP2_ConnHdlr {
Harald Welteb8a4ac82019-06-23 11:04:12 +0200157 var ConnHdlrPars g_pars;
158 timer g_Tguard := 30.0;
Philipp Maier74d776a2023-07-12 14:04:14 +0200159
Pau Espin Pedrolcc9b8042023-09-21 17:45:11 +0200160 var GtpPeer g_gn_iface_peer := { connId := 1, remName := mp_gn_remote_ip, remPort := mp_gn_remote_port };
Harald Welteb8a4ac82019-06-23 11:04:12 +0200161}
162
163type record ConnHdlrPars {
Harald Welte95333a12019-07-11 22:51:45 +0800164 /* copied over from MTC_CT on start of component */
165 EnbParams enb_pars[NUM_ENB],
166 /* copied over from MTC_CT on start of component */
167 UeParams ue_pars,
168 /* currently used MME (index into enb_pars, S1AP, ...) */
169 integer mme_idx
Harald Welteb8a4ac82019-06-23 11:04:12 +0200170}
171
172modulepar {
Harald Welte95333a12019-07-11 22:51:45 +0800173 /* S1 interface */
174 charstring mp_mme_ip := "127.0.0.1";
175 integer mp_mme_s1ap_port := 36412;
176 charstring mp_s1_local_ip := "127.0.0.1";
177 integer mp_s1_local_port := 50000;
178
Harald Welte6ec64392019-08-14 12:37:07 +0200179 /* S6 interface */
180 charstring mp_s6_local_ip := "127.0.0.4";
181 integer mp_s6_local_port := 3868;
Pau Espin Pedrol35c0cc22023-12-21 19:23:48 +0100182 charstring mp_s6_diam_realm := "localdomain";
183 charstring mp_s6_local_diam_host := "hss.localdomain";
184 charstring mp_s6_remote_diam_host := "mme.localdomain";
Harald Welte6ec64392019-08-14 12:37:07 +0200185
Harald Welte95333a12019-07-11 22:51:45 +0800186 /* SGs interface */
Harald Welteb8a4ac82019-06-23 11:04:12 +0200187 charstring mp_sgs_local_ip := "127.0.0.1";
188 integer mp_sgs_local_port := 29118;
189 charstring mp_vlr_name := "vlr.example.net";
190 charstring mp_mme_name := "mmec01.mmegi0001.mme.epc.mnc070.mcc901.3gppnetwork.org";
Philipp Maier74d776a2023-07-12 14:04:14 +0200191
192 /* Gn interface (GTPv1C) */
193 charstring mp_gn_local_ip := "127.0.0.22";
194 integer mp_gn_local_port := 2123;
195 charstring mp_gn_remote_ip := "127.0.0.2";
Pau Espin Pedrol11625852023-12-22 14:20:42 +0100196 /* RAI+CI served from emulated peer SGSN: */
Pau Espin Pedrolcc9b8042023-09-21 17:45:11 +0200197 integer mp_gn_remote_port := 2123;
Pau Espin Pedrol11625852023-12-22 14:20:42 +0100198 hexstring mp_gn_local_mcc := '262'H;
199 hexstring mp_gn_local_mnc := 'f42'H;
Pau Espin Pedrol209d0a42023-12-22 14:22:40 +0100200 uint16_t mp_gn_local_lac := 39594;
Pau Espin Pedrol11625852023-12-22 14:20:42 +0100201 uint8_t mp_gn_local_rac := 187;
202 uint16_t mp_gn_local_ci := 1223;
Philipp Maier9abb8c92023-08-31 13:12:28 +0200203
204 /* S11 interface (GTPv2C, interface between MME and SGW) */
205 charstring mp_s11_local_ip := "127.0.0.3";
206 integer mp_s11_local_port := 2123;
207 charstring mp_s11_remote_ip := "127.0.0.2";
208 integer mp_s11_remote_port := 2123;
Pau Espin Pedrolecfc7d62023-12-13 18:49:29 +0100209
210 /* PGW information announced by SGWC. MME never really interacts with these. */
211 charstring mp_s5c_pgw_ip := "1.2.3.4";
Harald Welteb8a4ac82019-06-23 11:04:12 +0200212}
213
214/* send incoming unit data messages (like reset) to global SGsAP_UNIT port */
215friend function ForwardUnitdataCallback(PDU_SGsAP msg)
216runs on SGsAP_Emulation_CT return template PDU_SGsAP {
217 SGsAP_UNIT.send(msg);
218 return omit;
219}
220
221friend function f_init_sgsap(charstring id) runs on MTC_CT {
222 id := id & "-SGsAP";
223 var SGsAPOps ops := {
224 create_cb := refers(SGsAP_Emulation.ExpectedCreateCallback),
225 unitdata_cb := refers(ForwardUnitdataCallback)
226 }
227 var SGsAP_conn_parameters pars := {
228 remote_ip := "",
229 remote_sctp_port := -1,
230 local_ip := mp_sgs_local_ip,
231 local_sctp_port := mp_sgs_local_port
232 }
233
234 vc_SGsAP := SGsAP_Emulation_CT.create(id);
235 map(vc_SGsAP:SGsAP, system:SGsAP_CODEC_PT);
236 connect(vc_SGsAP:SGsAP_PROC, self:SGsAP_PROC);
237 connect(vc_SGsAP:SGsAP_UNIT, self:SGsAP_UNIT);
238 vc_SGsAP.start(SGsAP_Emulation.main(ops, pars, id));
239}
240
Harald Welte95333a12019-07-11 22:51:45 +0800241/* send incoming unit data messages (like reset) to global S1AP_UNIT port */
242friend function S1apForwardUnitdataCallback(S1AP_PDU msg)
243runs on S1AP_Emulation_CT return template S1AP_PDU {
244 S1AP_UNIT.send(msg);
245 return omit;
246}
247
Harald Welte95333a12019-07-11 22:51:45 +0800248friend function f_init_one_enb(charstring id, integer num := 0) runs on MTC_CT {
249 id := id & "-S1AP" & int2str(num);
250 var S1APOps ops := {
Philipp Maier7147c922023-07-07 14:18:32 +0200251 create_cb := refers(S1AP_Emulation.ExpectedCreateCallback),
Harald Welte95333a12019-07-11 22:51:45 +0800252 unitdata_cb := refers(S1apForwardUnitdataCallback)
253 }
254 var S1AP_conn_parameters pars := {
255 remote_ip := mp_mme_ip,
256 remote_sctp_port := mp_mme_s1ap_port,
257 local_ip := mp_s1_local_ip,
258 local_sctp_port := mp_s1_local_port + num,
259 role := NAS_ROLE_UE
260 }
261 var PLMNidentity plmn_id := '00f110'O;
262 var EnbParams enb_pars := {
263 global_enb_id := {
264 pLMNidentity := plmn_id,
265 eNB_ID := {
266 macroENB_ID := int2bit(num, 20)
267 },
268 iE_Extensions := omit
269 },
270 cell_identity := num,
271 supported_tas := {
272 {
273 tAC := int2oct(12345, 2),
274 broadcastPLMNs := { plmn_id },
275 iE_Extensions := omit
276 }
277 }
278 };
279
280 g_enb_pars[num] := enb_pars;
281 vc_S1AP[num] := S1AP_Emulation_CT.create(id);
282 map(vc_S1AP[num]:S1AP, system:S1AP_CODEC_PT);
283 connect(vc_S1AP[num]:S1AP_PROC, self:S1AP_PROC[num]);
284 connect(vc_S1AP[num]:S1AP_UNIT, self:S1AP_UNIT[num]);
285 vc_S1AP[num].start(S1AP_Emulation.main(ops, pars, id));
286 S1AP_UNIT[num].receive(S1APEM_Event:{up_down:=S1APEM_EVENT_UP});
287}
288friend function f_init_one_ue(inout UeParams uep, integer imsi_suffix) {
289 uep := {
Pau Espin Pedrolecfc7d62023-12-13 18:49:29 +0100290 imsi := f_gen_imsi(imsi_suffix),
291 ue_ip := "192.168.123.50",
Pau Espin Pedrol408e0ae2023-12-15 18:56:31 +0100292 guti := omit,
Pau Espin Pedrol3be4d922024-01-15 15:21:57 +0100293 kasme := omit,
Pau Espin Pedrolecfc7d62023-12-13 18:49:29 +0100294 s11_teic_local := '00000000'O,
295 s11_teic_remote := omit,
296 s5c_teic_local := '00000000'O,
297 s5c_teic_remote := omit,
298 bearer := {
299 ebi := omit,
300 s11_teid_local := omit,
301 s11_teid_remote := omit,
302 s5c_teid_local := omit,
303 s5c_teid_remote := omit
304 }
Harald Welte95333a12019-07-11 22:51:45 +0800305 }
306}
307friend function f_init_s1ap(charstring id, integer imsi_suffix) runs on MTC_CT {
308 var integer i;
309 for (i := 0; i < NUM_ENB; i := i+1) {
310 f_init_one_enb(id, i);
311 }
312 for (i := 0; i < NUM_UE; i := i+1) {
313 f_init_one_ue(g_ue_pars[i], i*1000 + imsi_suffix);
314 }
315}
316
Harald Welte6ec64392019-08-14 12:37:07 +0200317friend function DiameterForwardUnitdataCallback(PDU_DIAMETER msg)
318runs on DIAMETER_Emulation_CT return template PDU_DIAMETER {
319 DIAMETER_UNIT.send(msg);
320 return omit;
321}
322
323friend function f_init_diameter(charstring id) runs on MTC_CT {
324 var DIAMETEROps ops := {
325 create_cb := refers(DIAMETER_Emulation.ExpectedCreateCallback),
Vadim Yanitskiyb46f01e2021-12-06 03:23:13 +0300326 unitdata_cb := refers(DiameterForwardUnitdataCallback),
327 raw := false /* handler mode (IMSI based routing) */
Harald Welte6ec64392019-08-14 12:37:07 +0200328 };
329 var DIAMETER_conn_parameters pars := {
330 remote_ip := mp_mme_ip,
331 remote_sctp_port := -1,
332 local_ip := mp_s6_local_ip,
Harald Welte61f73d52020-04-26 21:41:12 +0200333 local_sctp_port := mp_s6_local_port,
334 origin_host := "hss.localdomain",
335 origin_realm := "localdomain",
Pau Espin Pedrol33b47492022-03-08 17:43:01 +0100336 auth_app_id := omit,
Harald Welte61f73d52020-04-26 21:41:12 +0200337 vendor_app_id := c_DIAMETER_3GPP_S6_AID
Harald Welte6ec64392019-08-14 12:37:07 +0200338 };
339 vc_DIAMETER := DIAMETER_Emulation_CT.create(id);
340 map(vc_DIAMETER:DIAMETER, system:DIAMETER_CODEC_PT);
341 connect(vc_DIAMETER:DIAMETER_UNIT, self:DIAMETER_UNIT);
342 connect(vc_DIAMETER:DIAMETER_PROC, self:DIAMETER_PROC);
343 vc_DIAMETER.start(DIAMETER_Emulation.main(ops, pars, id));
Harald Welted01b5d02020-04-26 22:05:53 +0200344
345 f_diameter_wait_capability(DIAMETER_UNIT);
Harald Welte6ec64392019-08-14 12:37:07 +0200346}
347
Philipp Maier74d776a2023-07-12 14:04:14 +0200348friend function f_init_gtp(charstring id) runs on MTC_CT {
349 id := id & "-GTP";
350
351 var GtpEmulationCfg gtp_cfg := {
352 gtpc_bind_ip := mp_gn_local_ip,
353 gtpc_bind_port := mp_gn_local_port,
354 gtpu_bind_ip := omit,
355 gtpu_bind_port := omit,
356 sgsn_role := true
357 };
358
359 vc_GTP := GTP_Emulation_CT.create(id);
360 vc_GTP.start(GTP_Emulation.main(gtp_cfg));
361}
362
Philipp Maier9abb8c92023-08-31 13:12:28 +0200363friend function f_init_gtpv2_s11(charstring id) runs on MTC_CT {
364 id := id & "-GTPV2";
365
366 var Gtp2EmulationCfg cfg := {
367 gtpc_bind_ip := mp_s11_local_ip,
368 gtpc_bind_port := mp_s11_local_port,
369 gtpc_remote_ip := mp_s11_remote_ip,
370 gtpc_remote_port := mp_s11_remote_port,
371 sgw_role := true,
372 use_gtpu_daemon := false
373 };
374
375 vc_GTP2 := GTPv2_Emulation_CT.create(id);
376 map(vc_GTP2:GTP2C, system:GTP2C);
377 connect(vc_GTP2:TEID0, self:TEID0);
378 vc_GTP2.start(GTPv2_Emulation.main(cfg));
379}
380
381friend template (value) S1AP_IEs.TAI ts_enb_S1AP_TAI(EnbParams enb) := {
Harald Welte95333a12019-07-11 22:51:45 +0800382 pLMNidentity := enb.global_enb_id.pLMNidentity,
383 tAC := enb.supported_tas[0].tAC,
384 iE_Extensions := omit
385}
386
387friend template (value) EUTRAN_CGI ts_enb_S1AP_CGI(EnbParams enb) := {
388 pLMNidentity := enb.global_enb_id.pLMNidentity,
389 cell_ID := int2bit(enb.cell_identity, 28),
390 iE_Extensions := omit
391}
392
393
Harald Welteb8a4ac82019-06-23 11:04:12 +0200394/* generate parameters for a connection handler */
Harald Welte95333a12019-07-11 22:51:45 +0800395friend function f_init_pars(integer ue_idx := 0)
Harald Welteb8a4ac82019-06-23 11:04:12 +0200396runs on MTC_CT return ConnHdlrPars {
397 var ConnHdlrPars pars := {
Harald Welte95333a12019-07-11 22:51:45 +0800398 enb_pars := g_enb_pars,
399 ue_pars := g_ue_pars[ue_idx],
400 mme_idx := 0
Harald Welteb8a4ac82019-06-23 11:04:12 +0200401 };
402 return pars;
403}
404
405type function void_fn(ConnHdlrPars pars) runs on ConnHdlr;
406
407/* start a connection handler with given parameters */
408friend function f_start_handler_with_pars(void_fn fn, ConnHdlrPars pars, integer s1ap_idx := 0)
409runs on MTC_CT return ConnHdlr {
410 var ConnHdlr vc_conn;
411 var charstring id := testcasename() & int2str(s1ap_idx);
412
413 vc_conn := ConnHdlr.create(id);
Harald Welte95333a12019-07-11 22:51:45 +0800414 /* S1AP part */
415 connect(vc_conn:S1AP, vc_S1AP[s1ap_idx]:S1AP_CLIENT);
416 connect(vc_conn:S1AP_PROC, vc_S1AP[s1ap_idx]:S1AP_PROC);
417 if (isbound(vc_SGsAP)) {
418 /* SGsAP part */
419 connect(vc_conn:SGsAP, vc_SGsAP:SGsAP_CLIENT);
420 connect(vc_conn:SGsAP_PROC, vc_SGsAP:SGsAP_PROC);
421 }
Harald Welte6ec64392019-08-14 12:37:07 +0200422 if (isbound(vc_DIAMETER)) {
423 connect(vc_conn:DIAMETER, vc_DIAMETER:DIAMETER_CLIENT);
424 connect(vc_conn:DIAMETER_PROC, vc_DIAMETER:DIAMETER_PROC);
425 }
Philipp Maier74d776a2023-07-12 14:04:14 +0200426 if (isbound(vc_GTP)) {
427 connect(vc_conn:GTP, vc_GTP:CLIENT);
428 connect(vc_conn:GTP_PROC, vc_GTP:CLIENT_PROC);
429 }
Philipp Maier9abb8c92023-08-31 13:12:28 +0200430 if (isbound(vc_GTP2)) {
431 connect(vc_conn:GTP2, vc_GTP2:CLIENT);
432 connect(vc_conn:GTP2_PROC, vc_GTP2:CLIENT_PROC);
433 }
Harald Welteb8a4ac82019-06-23 11:04:12 +0200434
435 /* We cannot use vc_conn.start(f_init_handler(fn, id, pars)); as we cannot have
436 * a stand-alone 'derefers()' call, see https://www.eclipse.org/forums/index.php/t/1091364/ */
437 vc_conn.start(derefers(fn)(pars));
438 return vc_conn;
439}
440
441/* altstep for the global guard timer */
442private altstep as_Tguard()runs on ConnHdlr {
443 [] g_Tguard.timeout {
444 setverdict(fail, "Tguard timeout");
445 mtc.stop;
446 }
447}
448
449friend function f_init_handler(ConnHdlrPars pars, float t_guard := 30.0) runs on ConnHdlr {
450 /* make parameters available via component variable */
451 g_pars := pars;
452 /* start guard timre and activate it as default */
453 g_Tguard.start(t_guard);
454 activate(as_Tguard());
Harald Welte6ec64392019-08-14 12:37:07 +0200455 if (DIAMETER_PROC.checkstate("Connected")) {
Pau Espin Pedroldb017f42023-08-25 19:22:25 +0200456 f_diameter_expect_imsi(g_pars.ue_pars.imsi);
Harald Welte6ec64392019-08-14 12:37:07 +0200457 }
Harald Welte95333a12019-07-11 22:51:45 +0800458 if (SGsAP_PROC.checkstate("Connected")) {
459 /* Route all SGsAP mesages for our IMSIto us */
460 f_create_sgsap_expect(pars.ue_pars.imsi);
461 }
462}
463
464
465
Philipp Maier9abb8c92023-08-31 13:12:28 +0200466friend function f_s1ap_setup(integer idx := 0, template S1AP_IEs.Cause cause := omit) runs on MTC_CT {
467 var template (present) S1AP_IEs.Cause exp_cause;
Harald Welte95333a12019-07-11 22:51:45 +0800468 var boolean exp_fail := false;
469 timer T := 5.0;
470 if (not istemplatekind(cause, "omit")) {
471 exp_fail := true;
472 exp_cause := cause;
473 }
474
475 S1AP_UNIT[idx].send(ts_S1AP_SetupReq(g_enb_pars[idx].global_enb_id,
476 g_enb_pars[idx].supported_tas, v32));
477 T.start;
478 alt {
479 [exp_fail] S1AP_UNIT[idx].receive(tr_S1AP_SetupFail(exp_cause)) {
480 setverdict(pass);
481 }
482 [not exp_fail] S1AP_UNIT[idx].receive(tr_S1AP_SetupResp) {
483 setverdict(pass);
484 }
485 [] S1AP_UNIT[idx].receive {
486 setverdict(fail, "Received unexpected S1AP");
487 }
488 [] T.timeout {
489 setverdict(fail, "Timeout waiting for S1AP Setup result");
490 }
491 }
492}
493
494/* Unsuccessful S1 Setup procedure to MME (wrong PLMN) */
495testcase TC_s1ap_setup_wrong_plmn() runs on MTC_CT {
496 var charstring id := testcasename();
497 f_init_s1ap(id, 1);
498 g_enb_pars[0].global_enb_id.pLMNidentity := '62F224'O;
499 f_s1ap_setup(0, {misc:=unknown_PLMN});
500}
501
502/* Unsuccessful S1 Setup procedure to MME (wrong PLMN) */
503testcase TC_s1ap_setup_wrong_tac() runs on MTC_CT {
504 var charstring id := testcasename();
505 f_init_s1ap(id, 2);
506 g_enb_pars[0].supported_tas[0].broadcastPLMNs[0] := '62F224'O;
507 f_s1ap_setup(0, {misc:=unknown_PLMN});
508}
509
510/* Successful S1 Setup procedure to MME */
511testcase TC_s1ap_setup() runs on MTC_CT {
512 var charstring id := testcasename();
513 f_init_s1ap(id, 3);
514 f_s1ap_setup(0);
515}
516
517private const EPS_QualityOfServiceV c_NAS_defaultQoS := {
518 qCI := '00'O,
519 maxBitRateUplink := omit,
520 maxBitRateDownlink := omit,
521 guaranteedBitRateUplink := omit,
522 guaranteedBitRateDownlink := omit,
523 maxBitRateUplinkExt := omit,
524 maxBitRateDownlinkExt := omit,
525 guaranteedBitRateUplinkExt := omit,
526 guaranteedBitRateDownlinkExt := omit,
527 maxBitRateUplinkExt2 := omit,
528 maxBitRateDownlinkExt2 := omit,
529 guaranteedBitRateUplinkExt2 := omit,
530 guaranteedBitRateDownlinkExt2 := omit
531};
532
533private const UENetworkCapabilityV c_NAS_defaultUeNetCap := {
534 eEA := '10000000'B,
535 eIA := '11000000'B,
536 uEA := omit,
537 uIA := omit,
538 uCS2 := omit,
539 nF := omit,
540 vCC := omit,
541 lCS := omit,
542 lPP := omit,
543 aCC_CSFB := omit,
544 h245_ASH := omit,
545 proSe := omit,
546 proSe_dd := omit,
547 proSe_dc := omit,
548 proSe_relay := omit,
549 cP_CIoT := omit,
550 uP_CIoT := omit,
551 s1_Udata := omit,
552 eRwoPDN := omit,
553 hC_CP_CIoT := omit,
554 ePCO := omit,
555 multipleDRB := omit,
556 v2XPC5 := omit,
557 restrictEC := omit,
558 cPbackoff := omit,
559 dCNR := omit,
560 n1Mode := omit,
561 sGC := omit,
562 spare1 := omit,
563 spare := omit
564};
565
566private const octetstring c_NAS_defaultAPN := '00'O;
567
568private altstep as_s1ap_handle_auth() runs on ConnHdlr {
569 var PDU_NAS_EPS rx_nas;
570 [] S1AP.receive(tr_NAS_AuthReq) -> value rx_nas {
571 /* static XRES result as we fixed the HSS RAND value and always have the following
572 RAND: 20080c3818183b522614162c07601d0d
573 AUTN: f11b89a2a8be00001f9c526f3d75d44c
574 IK: 11329aae8e8d2941bb226b2061137c58
575 CK: 740d62df9803eebde5120acf358433d0
576 RES: 6a91970e838fd079
577 SRES: e91e4777
578 Kc: 3b0f999e42198874
579 SQN: 32
580 IND: 0
581 */
582 /* KASME: 95AFAD9A0D29AFAA079A9451DF7161D7EE4CBF2AF9387F766D058BB6B44B905D */
583 const OCT16 ck := '740d62df9803eebde5120acf358433d0'O;
584 const OCT16 ik := '11329aae8e8d2941bb226b2061137c58'O;
585 const OCT16 autn := 'f11b89a2a8be00001f9c526f3d75d44c'O;
586 const OCT8 res := '6a91970e838fd079'O;
587 const OCT3 plmn_id := '00F110'O;
588 const OCT6 sqn := '000000000020'O;
589 const OCT6 ak := substr(autn, 0, 6) xor4b sqn;
Pau Espin Pedrol3be4d922024-01-15 15:21:57 +0100590 g_pars.ue_pars.kasme := f_kdf_kasme(ck, ik, plmn_id, sqn, ak);
Harald Welte95333a12019-07-11 22:51:45 +0800591 var S1APEM_Config cfg := {
592 set_nas_keys := {
Pau Espin Pedrol3be4d922024-01-15 15:21:57 +0100593 k_nas_int := f_kdf_nas_int(1, g_pars.ue_pars.kasme),
594 k_nas_enc := f_kdf_nas_enc(1, g_pars.ue_pars.kasme)
Harald Welte95333a12019-07-11 22:51:45 +0800595 }
596 };
597 S1AP.send(cfg);
598 S1AP.send(ts_NAS_AuthResp(res));
599 }
600}
601
602private altstep as_s1ap_handle_sec_mode() runs on ConnHdlr {
603 var PDU_NAS_EPS rx_nas;
604 var NAS_SecurityAlgorithmsV alg := {
605 typeOfIntegrityProtection := '001'B,
606 spare1 := '0'B,
607 typeOfCiphering := '000'B,
608 spare2 := '0'B
609 };
610 var NAS_KeySetIdentifierV kset_id := {
611 identifier := '000'B,
612 tSC := '0'B
613 };
614 [] S1AP.receive(tr_NAS_SecModeCmd(alg, kset_id, ?)) {
615 S1AP.send(ts_NAS_SecModeCmpl);
616 }
617}
618
Pau Espin Pedrolecfc7d62023-12-13 18:49:29 +0100619
Pau Espin Pedrol35618872024-01-15 15:25:18 +0100620private altstep as_s1ap_handle_IntialCtxSetupReq_Attach_Accept() runs on ConnHdlr {
Pau Espin Pedrolecfc7d62023-12-13 18:49:29 +0100621 var S1AP_PDU rx_msg;
622 var PDU_NAS_EPS rx_nas;
623 [] S1AP.receive(tr_S1AP_IntialCtxSetupReq) -> value rx_msg {
624 var template (omit) MME_UE_S1AP_ID mme_ue_id := f_S1AP_get_MME_UE_S1AP_ID(rx_msg);
625 var template (omit) ENB_UE_S1AP_ID enb_ue_id := f_S1AP_get_ENB_UE_S1AP_ID(rx_msg);
626 var template (value) E_RABSetupItemCtxtSURes rab_setup_it;
627 var template (value) E_RABSetupListCtxtSURes rab_setup_items;
628 var octetstring esm_enc;
629 var template (value) PDU_NAS_EPS nas;
Pau Espin Pedrol408e0ae2023-12-15 18:56:31 +0100630 var EPS_MobileIdentityTLV mi_tlv;
631
632 S1AP.receive(tr_NAS_AttachAccept()) -> value rx_nas;
633 mi_tlv := rx_nas.ePS_messages.ePS_MobilityManagement.pDU_NAS_EPS_AttachAccept.gUTI;
634 if (mi_tlv.ePS_MobileIdentity.ePS_MobileIdentity.typeOfIdentity != '110'B) {
635 Misc_Helpers.f_shutdown(__BFILE__, __LINE__, fail, log2str("Rx GUTI of unexpected MI type: ", mi_tlv));
636 }
637 g_pars.ue_pars.guti := mi_tlv.ePS_MobileIdentity.ePS_MobileIdentity.oddEvenInd_identity.guti
Pau Espin Pedrolecfc7d62023-12-13 18:49:29 +0100638
639 rab_setup_it := ts_S1AP_RABSetupItemCtxtSURes(rab_id := 5,
640 tla := oct2bit(f_inet_addr(mp_mme_ip)),
641 gtp_teid := '00000002'O);
642 rab_setup_items := ts_S1AP_RABSetupListCtxtSURes(rab_setup_it);
643 S1AP.send(ts_S1AP_InitialCtxSetupResp(valueof(mme_ue_id), valueof(enb_ue_id), rab_setup_items));
644
645 nas := ts_NAS_ActDefEpsBearCtxAck(int2bit(g_pars.ue_pars.bearer.ebi, 4), '00000000'B, omit);
646 esm_enc := enc_PDU_NAS_EPS(valueof(nas));
647 S1AP.send(ts_NAS_AttachComplete(esm_enc));
Pau Espin Pedrol278f5432023-12-21 19:21:28 +0100648
649 /* Optional from the network: */
650 S1AP.receive(tr_NAS_EMMInformation);
Pau Espin Pedrolecfc7d62023-12-13 18:49:29 +0100651 }
652 [] S1AP.receive(PDU_NAS_EPS:?) -> value rx_nas {
653 Misc_Helpers.f_shutdown(__BFILE__, __LINE__, fail, log2str("Rx Unexpected NAS PDU msg: ", rx_nas));
654 }
655}
656
Pau Espin Pedrol35618872024-01-15 15:25:18 +0100657private altstep as_s1ap_handle_IntialCtxSetupReq_TAU_Accept() runs on ConnHdlr {
658 var S1AP_PDU rx_msg;
659 var PDU_NAS_EPS rx_nas;
660 [] S1AP.receive(tr_S1AP_IntialCtxSetupReq) -> value rx_msg {
661 /* 3GPP TS 23.401 D.3.6 step 22: */
662 var template (omit) MME_UE_S1AP_ID mme_ue_id := f_S1AP_get_MME_UE_S1AP_ID(rx_msg);
663 var template (omit) ENB_UE_S1AP_ID enb_ue_id := f_S1AP_get_ENB_UE_S1AP_ID(rx_msg);
664 var template (value) E_RABSetupItemCtxtSURes rab_setup_it;
665 var template (value) E_RABSetupListCtxtSURes rab_setup_items;
666 var S1APEM_Config cfg;
667
668 S1AP.receive(tr_PDU_NAS_EPS_TrackingAreaUpdateAccept)-> value rx_nas;
669
670 /* Configure integrity protection: */
671 cfg := {
672 set_nas_alg_int := NAS_ALG_IP_EIA1
673 };
674 S1AP.send(cfg);
675
676 rab_setup_it := ts_S1AP_RABSetupItemCtxtSURes(rab_id := 5,
677 tla := oct2bit(f_inet_addr(mp_mme_ip)),
678 gtp_teid := '00000002'O);
679 rab_setup_items := ts_S1AP_RABSetupListCtxtSURes(rab_setup_it);
680 S1AP.send(ts_S1AP_InitialCtxSetupResp(valueof(mme_ue_id), valueof(enb_ue_id), rab_setup_items));
681
682 /* 3GPP TS 23.401 D.3.6 step 23: */
683 /* Integrity Protection: TS 24.301 Section 4.4.4.3*/
684 S1AP.send(ts_PDU_NAS_EPS_TrackingAreaUpdateComplete(c_EPS_SEC_IP));
685 }
686 [] S1AP.receive(PDU_NAS_EPS:?) -> value rx_nas {
687 Misc_Helpers.f_shutdown(__BFILE__, __LINE__, fail, log2str("Rx Unexpected NAS PDU msg: ", rx_nas));
688 }
689}
690
Pau Espin Pedrol35c0cc22023-12-21 19:23:48 +0100691private altstep as_s1ap_handle_UeContextReleaseCmd(template S1AP_IEs.Cause cause := ?) runs on ConnHdlr {
692 var S1AP_PDU rx_msg;
693 var PDU_NAS_EPS rx_nas;
694 [] S1AP.receive(tr_S1AP_UeContextReleaseCmd(?, cause)) -> value rx_msg {
695 var template MME_UE_S1AP_ID mme_ue_id;
696 var template ENB_UE_S1AP_ID enb_ue_id;
697 if (not ispresent(rx_msg.initiatingMessage.value_.uEContextReleaseCommand.protocolIEs[0].value_.uE_S1AP_IDs.uE_S1AP_ID_pair)) {
698 /* TODO: The UE CONTEXT RELEASE COMMAND (see also: 3GPP TS 36.413, section 9.1.4.6), may identify the
699 * context by either an uE_S1AP_ID_pair (MME_UE_S1AP_ID and ENB_UE_S1AP_ID) or an MME_UE_S1AP_ID alone.
700 * The latter case is not implemented here yet. */
701 Misc_Helpers.f_shutdown(__BFILE__, __LINE__, fail, log2str("complete implementation of UeContextReleaseCmd handling"));
702 return;
703 }
704
705 mme_ue_id := rx_msg.initiatingMessage.value_.uEContextReleaseCommand.protocolIEs[0].value_.uE_S1AP_IDs.uE_S1AP_ID_pair.mME_UE_S1AP_ID;
706 enb_ue_id := rx_msg.initiatingMessage.value_.uEContextReleaseCommand.protocolIEs[0].value_.uE_S1AP_IDs.uE_S1AP_ID_pair.eNB_UE_S1AP_ID;
707
708 S1AP.send(ts_S1AP_UeContextReleaseCompl(mme_ue_id, enb_ue_id));
709 }
710 [] S1AP.receive(PDU_NAS_EPS:?) -> value rx_nas {
711 Misc_Helpers.f_shutdown(__BFILE__, __LINE__, fail, log2str("Rx Unexpected NAS PDU msg: ", rx_nas));
712 }
713}
714
Harald Welte6ec64392019-08-14 12:37:07 +0200715/* Exepect AuthInfoReq (AIR) from HSS; respond with AuthInforAnswer (AIA) */
716private altstep as_DIA_AuthInfo() runs on ConnHdlr {
717 var PDU_DIAMETER rx_dia;
718 [] DIAMETER.receive(tr_DIA_AIR(g_pars.ue_pars.imsi)) -> value rx_dia {
719 var template (omit) AVP avp;
720 var octetstring sess_id;
721 var octetstring vplmn_id;
722 var hexstring imsi;
723 var template (value) AVP_list auth_info_content;
724
725 /* retrieve input data */
726 imsi := valueof(f_DIAMETER_get_imsi(rx_dia));
727 avp := f_DIAMETER_get_avp(rx_dia, c_AVP_Code_BASE_NONE_Session_Id);
728 sess_id := valueof(avp.avp_data.avp_BASE_NONE_Session_Id);
729 avp := f_DIAMETER_get_avp(rx_dia, c_AVP_Code_AAA_3GPP_Visited_PLMN_Id);
730 vplmn_id := valueof(avp.avp_data.avp_AAA_3GPP_Visited_PLMN_Id);
731
732 /* compute tuple */
733 auth_info_content := { ts_AVP_EutranVec(1, '20080c3818183b522614162c07601d0d'O, '6a91970e838fd079'O, 'f11b89a2a8be00001f9c526f3d75d44c'O, '95AFAD9A0D29AFAA079A9451DF7161D7EE4CBF2AF9387F766D058BB6B44B905D'O) };
734
Vadim Yanitskiy2dba4942021-12-11 15:46:30 +0300735 DIAMETER.send(ts_DIA_AIA(auth_info_content, sess_id,
736 hbh_id := rx_dia.hop_by_hop_id,
737 ete_id := rx_dia.end_to_end_id));
Harald Welte6ec64392019-08-14 12:37:07 +0200738 }
739}
740
741/* Expect UpdateLocationReq (ULR); respond with UpdateLocationAnswer (ULA) */
742private altstep as_DIA_UpdLoc() runs on ConnHdlr {
743 var PDU_DIAMETER rx_dia;
744 [] DIAMETER.receive(tr_DIA_ULR(g_pars.ue_pars.imsi)) -> value rx_dia {
745 var template (omit) AVP avp;
Harald Welte6ec64392019-08-14 12:37:07 +0200746 var hexstring imsi;
747 var template (value) AVP_list sub_data;
748
749 /* retrieve input data */
750 imsi := valueof(f_DIAMETER_get_imsi(rx_dia));
751 avp := f_DIAMETER_get_avp(rx_dia, c_AVP_Code_BASE_NONE_Session_Id);
Harald Welte6ec64392019-08-14 12:37:07 +0200752
753 sub_data := {
754 ts_AVP_3GPP_SubscriberStatus(SERVICE_GRANTED),
755 ts_AVP_3GPP_SubscrRauTauTmr(30),
756 ts_AVP_3GPP_AMBR(1000, 2000),
757 ts_AVP_3GPP_ApnConfigProfile({
758 ts_AVP_3GPP_ContextId(1),
759 ts_AVP_3GPP_AllApnConfigsIncl,
760 ts_AVP_3GPP_ApnConfig(1, IPv4, "*")
761 })
762 };
763
Vadim Yanitskiy0e8f5162021-12-15 05:00:32 +0300764 DIAMETER.send(ts_DIA_ULA(sub_data, avp.avp_data.avp_BASE_NONE_Session_Id,
765 hbh_id := rx_dia.hop_by_hop_id,
766 ete_id := rx_dia.end_to_end_id));
Harald Welte6ec64392019-08-14 12:37:07 +0200767 }
768}
769
Pau Espin Pedrol35c0cc22023-12-21 19:23:48 +0100770private function f_DIA_CancelLocation(integer idx := 0, template S1AP_IEs.Cause cause := omit) runs on ConnHdlr {
771
772 var UINT32 hbh_id := f_rnd_octstring(4);
773 var UINT32 ete_id := f_rnd_octstring(4);
774 var PDU_DIAMETER rx_dia;
775
776 /* Unlike CLR, CLA contains no IMSI. Register ete_id in DIAMETER_Emulation,
777 * so AIA is forwarded back to us in DIAMETER port instead of MTC_CT.DIAMETER_UNIT.
778 */
779 f_diameter_expect_eteid(ete_id);
780
781 DIAMETER.send(ts_DIA_CLR(g_pars.ue_pars.imsi, SGSN_UPDATE_PROCEDURE,
782 orig_host := mp_s6_local_diam_host,
783 orig_realm := mp_s6_diam_realm,
784 dest_host := mp_s6_remote_diam_host,
785 dest_realm := mp_s6_diam_realm,
786 hbh_id := hbh_id,
787 ete_id := ete_id));
788
789 alt {
790 [] DIAMETER.receive(tr_DIA_CLA) -> value rx_dia {}
791 [] DIAMETER.receive(PDU_DIAMETER:?) -> value rx_dia {
792 Misc_Helpers.f_shutdown(__BFILE__, __LINE__, fail, log2str("Unexpected Diameter S6b msg rx: ", rx_dia));
793 }
794 }
795}
796
Pau Espin Pedrolecfc7d62023-12-13 18:49:29 +0100797private altstep as_GTP2C_CreateSession_success() runs on ConnHdlr {
798 var PDU_GTPCv2 rx_msg;
799 var BearerContextIEs rx_bctx_ies;
800 var template (value) FullyQualifiedTEID s11_fteid_c_ie, s11_fteid_u_ie, s5c_fteid_c_ie, s5c_fteid_u_ie;
801 var template (value) PDN_AddressAllocation paa;
802 var template (value) BearerContextIEs bctx_ies;
Harald Welte6ec64392019-08-14 12:37:07 +0200803
Pau Espin Pedrolecfc7d62023-12-13 18:49:29 +0100804 [] GTP2.receive(tr_GTP2C_CreateSessionReq(g_pars.ue_pars.imsi)) -> value rx_msg {
805 /* Parse TEIC and Bearer EBI and TEID and store it in g_pars */
806 g_pars.ue_pars.s11_teic_remote := rx_msg.gtpcv2_pdu.createSessionRequest.fullyQualifiedTEID[0].tEID_GRE_Key;
807 g_pars.ue_pars.s5c_teic_remote := rx_msg.gtpcv2_pdu.createSessionRequest.fullyQualifiedTEID[1].tEID_GRE_Key;
808
809 rx_bctx_ies := rx_msg.gtpcv2_pdu.createSessionRequest.bearerContextGrouped[0].bearerContextIEs;
810 g_pars.ue_pars.bearer.ebi := rx_bctx_ies.ePS_Bearer_ID.ePS_Bearer_ID_Value;
811
812 /* allocate + register TEID-C on local side */
813 g_pars.ue_pars.s11_teic_local := f_gtp2_allocate_teid();
814 g_pars.ue_pars.bearer.s11_teid_local := g_pars.ue_pars.s11_teic_local;
815 g_pars.ue_pars.s5c_teic_local := f_gtp2_allocate_teid();
816 g_pars.ue_pars.bearer.s5c_teid_local := g_pars.ue_pars.s5c_teic_local;
817
818 s11_fteid_c_ie := ts_GTP2C_FTEID(FTEID_IF_S11_MME_GTPC, g_pars.ue_pars.s11_teic_local, 0,
819 f_inet_addr(mp_s11_local_ip), omit);
820 s5c_fteid_c_ie := ts_GTP2C_FTEID(FTEID_IF_S5S8_PGW_GTPC, g_pars.ue_pars.s5c_teic_local, 1,
821 f_inet_addr(mp_s5c_pgw_ip), omit);
822 s11_fteid_u_ie := ts_GTP2C_FTEID(FTEID_IF_S1U_SGW_GTPU, g_pars.ue_pars.bearer.s11_teid_local, 0,
823 f_inet_addr(mp_s11_local_ip), omit);
824 s5c_fteid_u_ie := ts_GTP2C_FTEID(FTEID_IF_S5S8_PGW_GTPU, g_pars.ue_pars.bearer.s5c_teid_local, 2,
825 f_inet_addr(mp_s5c_pgw_ip), omit);
826 paa := ts_GTP2C_PdnAddrAlloc_v4(f_inet_addr(g_pars.ue_pars.ue_ip));
827 bctx_ies := ts_GTP2C_BcContextIE(ebi := g_pars.ue_pars.bearer.ebi,
828 teid_list := { s11_fteid_u_ie, s5c_fteid_u_ie },
829 qos := ts_GTP2C_BearerQos('09'O, 0, 0, 0, 0),
830 charging_id := ts_GTP2C_ChargingID(g_pars.ue_pars.bearer.s11_teid_local));
831
832 GTP2.send(ts_GTP2C_CreateSessionResp(g_pars.ue_pars.s11_teic_remote,
833 rx_msg.sequenceNumber,
834 { s11_fteid_c_ie, s5c_fteid_c_ie },
835 paa, { ts_GTP2C_BcGrouped(bctx_ies) } ));
836 setverdict(pass);
837 }
838 [] GTP2.receive {
839 Misc_Helpers.f_shutdown(__BFILE__, __LINE__, fail,
840 log2str("Unexpected GTPv2/S11 message from MME"));
841 }
842}
843
844private altstep as_GTP2C_ModifyBearer_success() runs on ConnHdlr {
845 var PDU_GTPCv2 rx_msg;
846 var BearerContextIEs rx_bctx_ies;
847 var template (value) FullyQualifiedTEID s11_fteid_c_ie, s11_fteid_u_ie, s5c_fteid_c_ie, s5c_fteid_u_ie;
848 var template (value) BearerContextIEs bctx_ies;
849
850 [] GTP2.receive(tr_GTP2C_ModifyBearerReq(g_pars.ue_pars.s11_teic_local)) -> value rx_msg {
851
852 rx_bctx_ies := rx_msg.gtpcv2_pdu.modifyBearerRequest.bearerContextGrouped[0].bearerContextIEs;
853
854 /* TODO: validate the S1-U fullyQualifiedTEID announces the IP address provided by the ENB in InitialCtxSetupResp */
855 // rx_bctx_ies.fullyQualifiedTEID[0]. == f_inet_addr(mp_mme_ip)
856
857 /* Update S11 TEID */
858 g_pars.ue_pars.bearer.s11_teid_remote := rx_bctx_ies.fullyQualifiedTEID[0].tEID_GRE_Key;
859
860 s11_fteid_u_ie := ts_GTP2C_FTEID(FTEID_IF_S1U_SGW_GTPU, g_pars.ue_pars.bearer.s11_teid_local, 0,
861 f_inet_addr(mp_s11_local_ip), omit);
862 bctx_ies := ts_GTP2C_BcContextIE(ebi := g_pars.ue_pars.bearer.ebi,
863 teid_list := { s11_fteid_u_ie },
864 qos := ts_GTP2C_BearerQos('09'O, 0, 0, 0, 0),
865 charging_id := ts_GTP2C_ChargingID(g_pars.ue_pars.bearer.s11_teid_local));
866
867 GTP2.send(ts_GTP2C_ModifyBearerResp(g_pars.ue_pars.s11_teic_remote,
868 rx_msg.sequenceNumber,
869 Request_accepted,
870 g_pars.ue_pars.bearer.ebi,
871 { ts_GTP2C_BcGrouped(bctx_ies) } ));
872 setverdict(pass);
873 }
874 [] GTP2.receive {
875 Misc_Helpers.f_shutdown(__BFILE__, __LINE__, fail,
876 log2str("Unexpected GTPv2/S11 message from MME"));
877 }
878}
879
Pau Espin Pedrol78c5e412023-12-21 19:50:11 +0100880private altstep as_GTP2C_DeleteSession_success(template Indication ind_flags := *) runs on ConnHdlr {
Pau Espin Pedrol35c0cc22023-12-21 19:23:48 +0100881 var PDU_GTPCv2 rx_msg;
882
Pau Espin Pedrol78c5e412023-12-21 19:50:11 +0100883 [] GTP2.receive(tr_GTP2C_DeleteSessionReq(g_pars.ue_pars.s11_teic_local, indicationFlags := ind_flags)) -> value rx_msg {
Pau Espin Pedrol35c0cc22023-12-21 19:23:48 +0100884 GTP2.send(ts_GTP2C_DeleteSessionResp(g_pars.ue_pars.s11_teic_remote,
885 rx_msg.sequenceNumber,
886 Request_accepted));
887 setverdict(pass);
888 }
889 [] GTP2.receive {
890 Misc_Helpers.f_shutdown(__BFILE__, __LINE__, fail,
891 log2str("Unexpected GTPv2/S11 message from MME"));
892 }
893}
894
Pau Espin Pedrol3be4d922024-01-15 15:21:57 +0100895
896/* 3GPP TS 23.401 D.3.5, TS 23.003 2.8.2.1 */
897private function guti2rai_ptmsi(in NAS_EPS_Types.GUTI guti, in OCT2 truncated_nas_token, out RoutingAreaIdentity rai, out OCT4 ptmsi, out OCT3 ptmsi_sig) runs on ConnHdlr {
898 var bitstring mtmsi_bits := oct2bit(guti.mTMSI);
899 var bitstring ptmsi_bits;
900 var bitstring ptmsi_sig_bits;
901
902 rai := valueof(ts_RoutingAreaIdentity(guti.mccDigit1 & guti.mccDigit2 & guti.mccDigit3,
903 guti.mncDigit3 & guti.mncDigit1 & guti.mncDigit2,
904 guti.mMEGI, guti.mMEC));
905 /* 3GPP TS 23.003 2.8.2.0: "P-TMSI shall be of 32 bits length where the two topmost bits are
906 * reserved and always set to '11'. Hence, for a UE which may handover to GERAN/UTRAN (based on
907 * subscription and UE capabilities), the corresponding bits in the M-TMSI are set to '11'"
908 */
909 ptmsi_bits := '11'B & substr(mtmsi_bits, 2, 6) & oct2bit(guti.mMEC) & substr(mtmsi_bits, 16, 16);
910 ptmsi_sig_bits := substr(mtmsi_bits, 8, 8) & oct2bit(truncated_nas_token);
911 ptmsi := bit2oct(ptmsi_bits);
912 ptmsi_sig := bit2oct(ptmsi_sig_bits);
913 /* TODO: The UE shall fill the remaining 2 octets of the <P-TMSI signature> according to clauses 9.1.1, 9.4.1, 10.2.1, or
914 * 10.5.1 of 3GPP TS.33.401 [89] , as appropriate, for RAU/Attach procedures.*/
915}
916
917/* Test UE attached to EUTRAN reselecting a GERAN cell. In this scenario, the
918 * new SGSN will attempt to obtain information of the UE from the old SGSN (MME)
919 * through Gn interface using SGSN Context Request/Response procedure (OS#6294). */
Pau Espin Pedrol35c0cc22023-12-21 19:23:48 +0100920private function f_gtp_sgsn_context_4g_to_2g(OCT4 new_sgsn_local_teid := '12345678'O) runs on ConnHdlr {
921 var template (value) GTPC_PDUs SGSNContextReqPDU;
922 var RoutingAreaIdentity rai;
923 var OCT4 ptmsi;
924 var OCT3 ptmsi_sig;
925 var Gtp1cUnitdata gtpc_pdu;
926 var OCT4 old_mme_local_teid;
Pau Espin Pedrol20f35142024-01-15 18:47:05 +0100927 var uint16_t gtpc_seq_nr := f_rnd_int(65535);
Pau Espin Pedrol35c0cc22023-12-21 19:23:48 +0100928
Pau Espin Pedrol3be4d922024-01-15 15:21:57 +0100929 /* Derive NAS Token (and post-increment ul_count): */
930 var OCT32 nas_token := f_s1apem_derive_nas_token(g_pars.ue_pars.kasme);
931 var OCT2 truncated_nas_token := substr(nas_token, 30, 2);
932
933 guti2rai_ptmsi(g_pars.ue_pars.guti, truncated_nas_token, rai, ptmsi, ptmsi_sig);
Pau Espin Pedrol35c0cc22023-12-21 19:23:48 +0100934
935 SGSNContextReqPDU := ts_SGSNContextReqPDU(rai, new_sgsn_local_teid, f_inet_addr(mp_gn_local_ip),
936 ptmsi := ts_PTMSI(ptmsi), ptmsi_sig := ts_PTMSI_sig(ptmsi_sig));
Pau Espin Pedrol20f35142024-01-15 18:47:05 +0100937 GTP.send(ts_GTPC_SGSNContextReq(g_gn_iface_peer, gtpc_seq_nr, SGSNContextReqPDU));
Pau Espin Pedrol35c0cc22023-12-21 19:23:48 +0100938
939 timer T := 5.0;
940 T.start;
941 alt {
942 [] GTP.receive(tr_GTPC_SGSNContextResp(g_gn_iface_peer, new_sgsn_local_teid,
943 tr_SGSNContextRespPDU(GTP_CAUSE_REQUEST_ACCEPTED,
944 g_pars.ue_pars.imsi))) -> value gtpc_pdu {
945 old_mme_local_teid := gtpc_pdu.gtpc.gtpc_pdu.sgsn_ContextResponse.teidControlPlane.teidControlPlane;
946 setverdict(pass);
947 }
948 [] GTP.receive {
Pau Espin Pedrol3be4d922024-01-15 15:21:57 +0100949 Misc_Helpers.f_shutdown(__BFILE__, __LINE__, fail, log2str("unexpected GTPC message from MME"));
Pau Espin Pedrol35c0cc22023-12-21 19:23:48 +0100950 }
951 [] T.timeout {
Pau Espin Pedrol3be4d922024-01-15 15:21:57 +0100952 Misc_Helpers.f_shutdown(__BFILE__, __LINE__, fail, log2str("no SGSN Context Response from MME"));
Pau Espin Pedrol35c0cc22023-12-21 19:23:48 +0100953 }
954 }
955
956 GTP.send(ts_GTPC_SGSNContextAck(g_gn_iface_peer, old_mme_local_teid,
957 oct2int(gtpc_pdu.gtpc.opt_part.sequenceNumber),
958 ts_SGSNContextAckPDU(GTP_CAUSE_REQUEST_ACCEPTED)));
959
960}
Pau Espin Pedrolecfc7d62023-12-13 18:49:29 +0100961
Pau Espin Pedrol35618872024-01-15 15:25:18 +0100962private altstep as_gtp_sgsn_context_2g_to_4g(OCT4 new_sgsn_teid := 'ABABABAB'O, GTP_Templates.GTP_RATType rat_type := GTP_RAT_TYPE_EUTRAN) runs on ConnHdlr {
963 var Gtp1cUnitdata gtpc_pdu;
964
965 [] GTP.receive(tr_GTPC_SGSNContextReq(g_gn_iface_peer, tr_SGSNContextReqPDU(rat_type := int2oct(enum2int(rat_type), 1)))) -> value gtpc_pdu {
966 var template (value) PDP_Context_GTPC pdp_ctx;
967 var template (value) GTPC_PDUs SGSNContextRespPDU;
968 var Gtp1cUnitdata gtpc_pdu_ack;
969 var OCT4 old_mme_remote_teid := gtpc_pdu.gtpc.gtpc_pdu.sgsn_ContextRequest.teidControlPlane.teidControlPlane;
970
971 const OCT16 ck := '740d62df9803eebde5120acf358433d0'O;
972 const OCT16 ik := '11329aae8e8d2941bb226b2061137c58'O;
973
974 pdp_ctx := ts_PDP_Context_GTPC(f_inet_addr(g_pars.ue_pars.ue_ip),
975 f_inet_addr(mp_gn_local_ip),
976 c_NAS_defaultAPN,
977 ggsn_teic := '12345678'O,
978 ggsn_teid := '87654321'O);
979 SGSNContextRespPDU := ts_SGSNContextRespPDU(GTP_CAUSE_REQUEST_ACCEPTED,
980 g_pars.ue_pars.imsi,
981 new_sgsn_teid,
982 f_inet_addr(mp_gn_local_ip),
983 ts_MM_ContextUMTS(ck, ik),
984 { pdp_ctx });
985 GTP.send(ts_GTPC_SGSNContextResp(g_gn_iface_peer,
986 old_mme_remote_teid,
987 oct2int(gtpc_pdu.gtpc.opt_part.sequenceNumber),
988 SGSNContextRespPDU));
989
990 GTP.receive(tr_GTPC_SGSNContextAck(g_gn_iface_peer, new_sgsn_teid,
991 tr_SGSNContextAckPDU(GTP_CAUSE_REQUEST_ACCEPTED))) -> value gtpc_pdu;
992 setverdict(pass);
993 }
994 [] GTP.receive {
995 setverdict(fail, "unexpected GTPC message from MME");
996 }
997}
998
Pau Espin Pedrolecfc7d62023-12-13 18:49:29 +0100999private function f_attach() runs on ConnHdlr {
1000 var template (value) EPS_MobileIdentityV mi := ts_NAS_MobileId_IMSI(g_pars.ue_pars.imsi);
Harald Welte95333a12019-07-11 22:51:45 +08001001 var template (value) PDU_NAS_EPS nas_esm, nas_emm;
Philipp Maierf74f3192023-09-01 17:24:36 +02001002 timer T := 5.0;
1003
Harald Welte95333a12019-07-11 22:51:45 +08001004 nas_esm := ts_NAS_PdnConnReq(bearer_id := '0000'B, proc_tid := int2bit(1,8),
1005 pdn_type := NAS_PDN_T_IPv4, req_type := '001'B);
1006 nas_emm := ts_NAS_AttachRequest(att_type := '000'B, kset_id := '000'B, mobile_id := mi,
1007 ue_net_cap := c_NAS_defaultUeNetCap,
1008 esm_enc := enc_PDU_NAS_EPS(valueof(nas_esm)));
1009 var template (value) S1AP_PDU tx;
1010 tx := ts_S1AP_InitialUE(p_eNB_value := 0, p_nasPdu := enc_PDU_NAS_EPS(valueof(nas_emm)),
1011 p_tAI := ts_enb_S1AP_TAI(g_pars.enb_pars[g_pars.mme_idx]),
1012 p_eUTRAN_CGI := ts_enb_S1AP_CGI(g_pars.enb_pars[g_pars.mme_idx]),
1013 p_rrcCause := mo_Signalling);
1014 S1AP.send(tx);
1015
Harald Welte6ec64392019-08-14 12:37:07 +02001016 as_DIA_AuthInfo();
Harald Welte95333a12019-07-11 22:51:45 +08001017 as_s1ap_handle_auth();
Harald Welte6ec64392019-08-14 12:37:07 +02001018 alt {
1019 [] as_DIA_UpdLoc() {
1020 as_s1ap_handle_sec_mode();
1021 }
1022 [] as_s1ap_handle_sec_mode() {
1023 as_DIA_UpdLoc();
1024 }
1025 }
Harald Welte95333a12019-07-11 22:51:45 +08001026
Philipp Maierf74f3192023-09-01 17:24:36 +02001027 /* We now expect the MME to send a Create Session Request to the SGW-C */
Philipp Maierf74f3192023-09-01 17:24:36 +02001028 f_gtp2_register_udmsg('20'O);
1029 T.start;
1030 alt {
Pau Espin Pedrolecfc7d62023-12-13 18:49:29 +01001031 [] as_GTP2C_CreateSession_success();
1032 [] T.timeout { Misc_Helpers.f_shutdown(__BFILE__, __LINE__, fail, log2str("No message from MME")); }
Philipp Maierf74f3192023-09-01 17:24:36 +02001033 }
1034
Pau Espin Pedrolecfc7d62023-12-13 18:49:29 +01001035 T.start;
1036 alt {
Pau Espin Pedrol35618872024-01-15 15:25:18 +01001037 [] as_s1ap_handle_IntialCtxSetupReq_Attach_Accept();
Pau Espin Pedrolecfc7d62023-12-13 18:49:29 +01001038 [] T.timeout { Misc_Helpers.f_shutdown(__BFILE__, __LINE__, fail, log2str("No message from MME")); }
1039 }
Philipp Maierf74f3192023-09-01 17:24:36 +02001040
Pau Espin Pedrolecfc7d62023-12-13 18:49:29 +01001041 /* We now expect the MME to send a Modify Bearer Request to the SGW-C */
1042 f_gtp2_register_udmsg('22'O);
1043 T.start;
1044 alt {
1045 [] as_GTP2C_ModifyBearer_success();
1046 [] T.timeout { Misc_Helpers.f_shutdown(__BFILE__, __LINE__, fail, log2str("No message from MME")); }
1047 }
1048}
1049
1050private function f_TC_attach(ConnHdlrPars pars) runs on ConnHdlr {
1051 f_init_handler(pars);
1052 f_attach();
Harald Welte95333a12019-07-11 22:51:45 +08001053}
1054testcase TC_s1ap_attach() runs on MTC_CT {
1055 var charstring id := testcasename();
1056
Harald Welte6ec64392019-08-14 12:37:07 +02001057 f_init_diameter(id);
1058 f_sleep(10.0);
Harald Welte95333a12019-07-11 22:51:45 +08001059 f_init_s1ap(id, 4);
Philipp Maierf74f3192023-09-01 17:24:36 +02001060 f_init_gtpv2_s11(id);
Harald Welte95333a12019-07-11 22:51:45 +08001061 f_s1ap_setup(0);
1062
1063 var ConnHdlrPars pars := f_init_pars(ue_idx := 0);
1064 var ConnHdlr vc_conn;
1065 vc_conn := f_start_handler_with_pars(refers(f_TC_attach), pars);
1066 vc_conn.done;
1067}
1068
Philipp Maier74d776a2023-07-12 14:04:14 +02001069private function f_TC_gn_echo_request(ConnHdlrPars pars) runs on ConnHdlr {
1070 timer T := 5.0;
1071 f_init_handler(pars);
1072 f_gtp_register_teid('00000000'O);
1073
1074 GTP.send(ts_GTPC_PING(g_gn_iface_peer, 1));
1075 T.start;
1076 alt {
1077 [] GTP.receive(tr_GTPC_PONG(?)) {
1078 setverdict(pass);
1079 }
1080 [] GTP.receive {
1081 setverdict(fail, "unexpected GTPC message from MME");
1082 }
1083 [] T.timeout {
1084 setverdict(fail, "no GTPC ECHO RESPONSE from MME");
1085 }
1086 }
1087}
1088testcase TC_gn_echo_request() runs on MTC_CT {
1089 var charstring id := testcasename();
1090
1091 f_init_diameter(id);
Pau Espin Pedrolae747ac2023-12-20 20:55:32 +01001092 f_init_s1ap(id, 0);
Philipp Maier74d776a2023-07-12 14:04:14 +02001093 f_s1ap_setup(0);
1094 f_init_gtp(id);
1095
1096 var ConnHdlrPars pars := f_init_pars(ue_idx := 0);
1097 var ConnHdlr vc_conn;
1098 vc_conn := f_start_handler_with_pars(refers(f_TC_gn_echo_request), pars);
1099 vc_conn.done;
1100}
1101
Philipp Maiera9306202023-07-24 11:41:51 +02001102external function enc_PDU_GTPC_RAN_INF_REQ(in PDU_BSSGP_RAN_INFORMATION_REQUEST_GTPC gtpc_pdu) return octetstring
1103with { extension "prototype(convert)"
1104 extension "encode(RAW)"
1105 }
1106
1107external function enc_PDU_GTPC_RAN_INF(in PDU_BSSGP_RAN_INFORMATION_GTPC gtpc_pdu) return octetstring
1108with { extension "prototype(convert)"
1109 extension "encode(RAW)"
1110 }
1111
1112function f_convert_plmn(OCT3 pLMNidentity) return hexstring {
1113 var hexstring pLMNidentity_hex := oct2hex(pLMNidentity);
1114 var hexstring pLMNidentity_hex_swapped;
1115 pLMNidentity_hex_swapped[0] := pLMNidentity_hex[1];
1116 pLMNidentity_hex_swapped[1] := pLMNidentity_hex[0];
1117 pLMNidentity_hex_swapped[2] := pLMNidentity_hex[3];
1118 pLMNidentity_hex_swapped[3] := pLMNidentity_hex[2];
1119 pLMNidentity_hex_swapped[4] := pLMNidentity_hex[5];
1120 pLMNidentity_hex_swapped[5] := pLMNidentity_hex[4];
1121 return pLMNidentity_hex_swapped;
1122}
1123
1124/* Make a template for a GTPC BSSGP container that contains a RAN INFORMATION REQUEST. The template can be used to
1125 * craft the request for the S1AP/S1-MME interface and also to verfify the contents of the coresponding request on
1126 * the GTPC/Gn interface */
1127private function f_make_ts_GTPC_RAN_Information_Request(GTP_CellId geran_gtp_ci)
1128 runs on ConnHdlr return template (value) PDU_BSSGP_RAN_INFORMATION_REQUEST_GTPC {
1129 var template (value) RIM_Routing_Address_GTPC gtpc_dst_addr, gtpc_src_addr;
1130 var template (value) RAN_Information_Request_RIM_Container_GTPC gtpc_rim_req_cont;
1131 var template (value) PDU_BSSGP_RAN_INFORMATION_REQUEST_GTPC gtpc_bssgp_cont;
1132 var octetstring gnbid;
1133 var GTP_CellId eutran_gtp_ci;
1134 eutran_gtp_ci.ra_id.lai.mcc_mnc := f_convert_plmn(g_pars.enb_pars[g_pars.mme_idx].global_enb_id.pLMNidentity);
1135
1136 gnbid := enc_S1AP_Global_ENB_ID(g_pars.enb_pars[g_pars.mme_idx].global_enb_id);
1137 gtpc_dst_addr := t_GTPC_RIM_Routing_Address_cid(geran_gtp_ci);
1138 gtpc_src_addr := t_GTPC_RIM_Routing_Address_enbid(eutran_gtp_ci,
1139 oct2int(g_pars.enb_pars[g_pars.mme_idx].supported_tas[0].tAC),
1140 gnbid);
1141
1142 gtpc_rim_req_cont := ts_GTPC_RAN_Information_Request_RIM_Container(
1143 ts_GTPC_RIM_Application_Identity(RIM_APP_ID_NACC),
1144 ts_GTPC_RIM_Sequence_Number(1),
1145 ts_GTPC_RIM_PDU_Indications(false, RIM_PDU_TYPE_SING_REP),
1146 ts_GTPC_RIM_Protocol_Version_Number(1),
1147 tsu_GTPC_RAN_Information_Request_Application_Container_NACC(geran_gtp_ci),
1148 omit);
1149 gtpc_bssgp_cont := ts_GTPC_RAN_Information_Request(
1150 ts_GTPC_RIM_Routing_Information(RIM_ADDR_GERAN_CELL_ID, gtpc_dst_addr),
1151 ts_GTPC_RIM_Routing_Information(RIM_ADDR_EUTRAN_NODEB_ID, gtpc_src_addr),
1152 gtpc_rim_req_cont);
1153
1154 return gtpc_bssgp_cont;
1155}
1156
1157private function f_make_tr_GTPC_RAN_Information_Request(GTP_CellId geran_gtp_ci)
1158 runs on ConnHdlr return template (present) PDU_BSSGP_RAN_INFORMATION_REQUEST_GTPC {
1159 var template (present) RIM_Routing_Address_GTPC gtpc_dst_addr, gtpc_src_addr;
1160 var template (present) RAN_Information_Request_RIM_Container_GTPC gtpc_rim_req_cont;
1161 var template (present) PDU_BSSGP_RAN_INFORMATION_REQUEST_GTPC gtpc_bssgp_cont;
1162 var octetstring gnbid;
1163 var GTP_CellId eutran_gtp_ci;
1164 eutran_gtp_ci.ra_id.lai.mcc_mnc := f_convert_plmn(g_pars.enb_pars[g_pars.mme_idx].global_enb_id.pLMNidentity);
1165
1166 gnbid := enc_S1AP_Global_ENB_ID(g_pars.enb_pars[g_pars.mme_idx].global_enb_id);
1167 gtpc_dst_addr := t_GTPC_RIM_Routing_Address_cid(geran_gtp_ci);
1168 gtpc_src_addr := t_GTPC_RIM_Routing_Address_enbid(eutran_gtp_ci,
1169 oct2int(g_pars.enb_pars[g_pars.mme_idx].supported_tas[0].tAC),
1170 gnbid);
1171
1172 gtpc_rim_req_cont := tr_GTPC_RAN_Information_Request_RIM_Container(
1173 ts_GTPC_RIM_Application_Identity(RIM_APP_ID_NACC),
1174 ts_GTPC_RIM_Sequence_Number(1),
1175 ts_GTPC_RIM_PDU_Indications(false, RIM_PDU_TYPE_SING_REP),
1176 ts_GTPC_RIM_Protocol_Version_Number(1),
1177 tru_GTPC_RAN_Information_Request_Application_Container_NACC(geran_gtp_ci));
1178 gtpc_bssgp_cont := tr_GTPC_RAN_Information_Request(
1179 tr_GTPC_RIM_Routing_Information(RIM_ADDR_GERAN_CELL_ID, gtpc_dst_addr),
1180 tr_GTPC_RIM_Routing_Information(RIM_ADDR_EUTRAN_NODEB_ID, gtpc_src_addr),
1181 gtpc_rim_req_cont);
1182
1183 return gtpc_bssgp_cont;
1184}
1185
1186/* Make initial RAN INFORMATION REQUEST message that is sent on the S1AP/S1-MME interface */
1187private function f_make_ts_S1AP_eNBDirectInfTrans(GTP_CellId geran_gtp_ci)
1188 runs on ConnHdlr return template (value) S1AP_PDU {
1189 var template (value) Inter_SystemInformationTransferType inf;
1190
1191 inf.rIMTransfer.rIMInformation := enc_PDU_GTPC_RAN_INF_REQ(valueof(f_make_ts_GTPC_RAN_Information_Request(geran_gtp_ci)));
1192 inf.rIMTransfer.rIMRoutingAddress.gERAN_Cell_ID.lAI.pLMNidentity := hex2oct(f_convert_plmn(hex2oct(geran_gtp_ci.ra_id.lai.mcc_mnc)));
1193 inf.rIMTransfer.rIMRoutingAddress.gERAN_Cell_ID.lAI.lAC := int2oct(geran_gtp_ci.ra_id.lai.lac, 2);
1194 inf.rIMTransfer.rIMRoutingAddress.gERAN_Cell_ID.lAI.iE_Extensions := omit;
1195 inf.rIMTransfer.rIMRoutingAddress.gERAN_Cell_ID.rAC := int2oct(geran_gtp_ci.ra_id.rac, 1);
1196 inf.rIMTransfer.rIMRoutingAddress.gERAN_Cell_ID.cI := int2oct(geran_gtp_ci.cell_id, 2);
1197 inf.rIMTransfer.rIMRoutingAddress.gERAN_Cell_ID.iE_Extensions := omit;
1198 inf.rIMTransfer.iE_Extensions := omit;
1199
1200 return ts_S1AP_eNBDirectInfTrans(inf);
1201}
1202
1203/* Make RAN INFORMATION (response) message that is sent on the GTPC/Gn interface */
1204private function f_make_ts_GTPC_RANInfoRelay(template Gtp1cUnitdata req_gtpc_pdu,
1205 GTP_CellId geran_gtp_ci, octetstring geran_si)
1206 runs on ConnHdlr return template (value) Gtp1cUnitdata {
1207 var template Gtp1cUnitdata res_gtpc_pdu;
1208 var template RAN_Information_RIM_Container_GTPC gtpc_rim_res_cont;
1209 var template PDU_BSSGP_RAN_INFORMATION_GTPC gtpc_bssgp_rim_res_pdu;
1210 var template RIM_Routing_Information_GTPC gtpc_rim_dst_cell_id, gtpc_rim_src_cell_id;
1211 var template RIM_RoutingAddress gtpc_rim_ra;
1212 var template RIM_RoutingAddress_Discriminator gtpc_rim_ra_discr;
1213
1214 /* Assemble GTPC RAN Information */
1215 gtpc_rim_res_cont := ts_GTPC_RAN_Information_RIM_Container(ts_GTPC_RIM_Application_Identity(RIM_APP_ID_NACC),
1216 ts_GTPC_RIM_Sequence_Number(2),
1217 ts_GTPC_RIM_PDU_Indications(false, RIM_PDU_TYPE_SING_REP),
1218 ts_GTPC_RIM_Protocol_Version_Number(1),
1219 tsu_GTPC_ApplContainer_or_ApplErrContainer_NACC(tsu_GTPC_ApplContainer_NACC(geran_gtp_ci, false, 3, geran_si)),
1220 omit);
1221
1222 /* The source becomes the destination and vice versa */
1223 gtpc_rim_dst_cell_id := req_gtpc_pdu.gtpc.gtpc_pdu.ranInformationRelay.transparentContainer.
1224 rANTransparentContainerField.pDU_BSSGP_RAN_INFORMATION_REQUEST.source_Cell_Identifier
1225 gtpc_rim_src_cell_id := req_gtpc_pdu.gtpc.gtpc_pdu.ranInformationRelay.transparentContainer.
1226 rANTransparentContainerField.pDU_BSSGP_RAN_INFORMATION_REQUEST.destination_Cell_Identifier
1227 gtpc_bssgp_rim_res_pdu := ts_GTPC_RAN_Information(gtpc_rim_dst_cell_id,
1228 gtpc_rim_src_cell_id,
1229 gtpc_rim_res_cont);
1230
1231 /* Assemble RIM Routing Address (essentially a copy of the destination cell identifier)*/
1232 gtpc_rim_ra := ts_RIM_RoutingAddress(enc_RIM_Routing_Address_GTPC(valueof(gtpc_rim_dst_cell_id.rIM_Routing_Address)));
1233 gtpc_rim_ra_discr := ts_RIM_RoutingAddress_Discriminator(hex2bit(valueof(gtpc_rim_dst_cell_id.rIMRoutingAddressDiscriminator)));
1234
1235 res_gtpc_pdu := ts_GTPC_RANInfoRelay(g_gn_iface_peer,
1236 ts_RANTransparentContainer_RAN_INFO(gtpc_bssgp_rim_res_pdu),
1237 gtpc_rim_ra, gtpc_rim_ra_discr);
1238
1239 return res_gtpc_pdu;
1240}
1241
1242/* Make template to verify the RAN INFORMATION REQUEST as it appears on the GTPC/Gn interface */
1243private function f_make_tr_GTPC_MsgType(GTP_CellId geran_gtp_ci)
1244 runs on ConnHdlr return template (present) Gtp1cUnitdata {
1245 var template Gtp1cUnitdata msg;
1246 var template GTPC_PDUs pdus;
1247 var template RANTransparentContainer ran_transp_cont;
1248
1249 ran_transp_cont := tr_RANTransparentContainer_RAN_INFO_REQ(
1250 f_make_tr_GTPC_RAN_Information_Request(geran_gtp_ci));
1251 pdus := tr_RANInfoRelay(ran_transp_cont);
1252 msg := tr_GTPC_MsgType(g_gn_iface_peer, rANInformationRelay, '00000000'O, pdus);
1253
1254 return msg;
1255}
1256
1257/* Make template to verify the RAN INFORMATION (response) as it appears on the S1AP/S1-MME interface */
1258private function f_make_tr_S1AP_MMEDirectInfTrans(Gtp1cUnitdata ran_information_gtpc_pdu)
1259 runs on ConnHdlr return template (present) S1AP_PDU {
1260 var template S1AP_PDU msg;
1261 var template Inter_SystemInformationTransferType inf;
1262
1263 inf.rIMTransfer.rIMInformation := enc_PDU_GTPC_RAN_INF(
1264 ran_information_gtpc_pdu.gtpc.gtpc_pdu.ranInformationRelay.
1265 transparentContainer.rANTransparentContainerField.
1266 pDU_BSSGP_RAN_INFORMATION);
1267 inf.rIMTransfer.rIMRoutingAddress := omit;
1268 inf.rIMTransfer.iE_Extensions := omit;
1269 msg := tr_S1AP_MMEDirectInfTrans(inf);
1270
1271 return msg;
1272}
1273
1274private function f_TC_RIM_RAN_INF(ConnHdlrPars pars) runs on ConnHdlr {
1275 timer T := 5.0;
1276 f_init_handler(pars);
1277 f_gtp_register_teid('00000000'O);
1278 var Gtp1cUnitdata req_gtpc_pdu;
1279 var Gtp1cUnitdata resp_gtpc_pdu;
1280 var GTP_CellId geran_gtp_ci;
1281
1282 /* Assemble data of a fictitiously GERAN cell */
Pau Espin Pedrol11625852023-12-22 14:20:42 +01001283 geran_gtp_ci.ra_id.rac := mp_gn_local_rac;
1284 geran_gtp_ci.ra_id.lai.mcc_mnc := mp_gn_local_mcc & mp_gn_local_mnc;
1285 geran_gtp_ci.ra_id.lai.lac := mp_gn_local_lac;
1286 geran_gtp_ci.cell_id := mp_gn_local_ci;
Philipp Maiera9306202023-07-24 11:41:51 +02001287 const octetstring geran_si1 := '198fb100000000000000000000000000007900002b'O;
1288 const octetstring geran_si3 := '1b753000f110236ec9033c2747407900003c0b2b2b'O;
1289 const octetstring geran_si13 := '009000185a6fc9e08410ab2b2b2b2b2b2b2b2b2b2b'O;
1290 const octetstring geran_si := geran_si1 & geran_si3 & geran_si13;
1291
1292 /* Send initial RAN information request via S1AP to MME and expect the MME to forward the request on GTP-C
1293 * (eNB -> MME -> SGSN) */
1294 S1AP.send(f_make_ts_S1AP_eNBDirectInfTrans(geran_gtp_ci));
1295 T.start;
1296 alt {
1297 [] GTP.receive(f_make_tr_GTPC_MsgType(geran_gtp_ci)) -> value req_gtpc_pdu {
1298 setverdict(pass);
1299 }
1300 [] GTP.receive {
1301 setverdict(fail, "unexpected GTPC message from MME");
1302 }
1303 [] T.timeout {
1304 setverdict(fail, "no GTPC RAN INFORMATION REQUEST from MME");
1305 }
1306 }
1307
1308 /* Send RAN information response via GTP-C to MME and expect the MME to forward the respnse on S1AP
1309 * (SGSN -> MME -> eNB) */
1310 f_create_s1ap_expect_proc(id_MMEDirectInformationTransfer, self);
1311 resp_gtpc_pdu := valueof(f_make_ts_GTPC_RANInfoRelay(req_gtpc_pdu, geran_gtp_ci, geran_si));
1312 GTP.send(resp_gtpc_pdu);
1313 T.start;
1314 alt {
1315 [] S1AP.receive(f_make_tr_S1AP_MMEDirectInfTrans(resp_gtpc_pdu)) {
1316 setverdict(pass);
1317 }
1318 [] S1AP.receive {
1319 setverdict(fail, "unexpected S1AP message from MME");
1320 }
1321 [] T.timeout {
1322 setverdict(fail, "no S1AP RAN INFORMATION from MME");
1323 }
1324 }
1325
1326 setverdict(pass);
1327}
1328
1329testcase TC_RIM_RAN_INF() runs on MTC_CT {
1330 var charstring id := testcasename();
1331
1332 f_init_diameter(id);
Pau Espin Pedrolae747ac2023-12-20 20:55:32 +01001333 f_init_s1ap(id, 0);
Philipp Maiera9306202023-07-24 11:41:51 +02001334 f_s1ap_setup(0);
1335 f_init_gtp(id);
1336
Philipp Maiera9306202023-07-24 11:41:51 +02001337 var ConnHdlrPars pars := f_init_pars(ue_idx := 0);
1338 var ConnHdlr vc_conn;
1339 vc_conn := f_start_handler_with_pars(refers(f_TC_RIM_RAN_INF), pars);
1340
1341 vc_conn.done;
1342}
1343
Philipp Maier46059f02023-08-16 14:45:27 +02001344/* Successful RESET procedure from eNB to MME */
1345testcase TC_s1ap_reset() runs on MTC_CT {
1346 var charstring id := testcasename();
Pau Espin Pedrolae747ac2023-12-20 20:55:32 +01001347 f_init_s1ap(id, 0);
Philipp Maier46059f02023-08-16 14:45:27 +02001348 f_s1ap_setup(0);
1349
Philipp Maier9abb8c92023-08-31 13:12:28 +02001350 var template (value) S1AP_IEs.Cause reset_cause := {misc := om_intervention};
Philipp Maier46059f02023-08-16 14:45:27 +02001351 var template (value) ResetType reset_type := {s1_Interface := reset_all};
1352 timer T := 5.0;
1353
1354 S1AP_UNIT[0].send(ts_S1AP_Reset(reset_cause, reset_type));
1355 T.start;
1356 alt {
1357 [] S1AP_UNIT[0].receive(tr_S1AP_ResetAck_any) {
1358 setverdict(pass);
1359 }
1360 [] S1AP_UNIT[0].receive {
1361 setverdict(fail, "Received unexpected S1AP");
1362 }
1363 [] T.timeout {
1364 setverdict(fail, "Timeout waiting for S1AP Setup result");
1365 }
1366 }
1367}
1368
Philipp Maier26a09f32023-09-01 14:18:33 +02001369/* Tracking area update with a GUTI (TMSI) that is unknown to the MME. The MME is expected to reject this TAU
1370 * request. */
1371private function f_TC_tau_unknown_guti(ConnHdlrPars pars) runs on ConnHdlr {
1372
1373 f_init_handler(pars);
1374 var template (value) EPS_MobileIdentityV mi := ts_NAS_MobileId_IMSI(pars.ue_pars.imsi);
1375 var template (value) S1AP_PDU tx;
1376 var template (value) PDU_NAS_EPS nas_tau;
1377 timer T := 5.0;
1378
1379 var hexstring mcc_mnc := f_convert_plmn(g_pars.enb_pars[g_pars.mme_idx].global_enb_id.pLMNidentity);
1380 var EPS_MobileIdentityLV old_guti := valueof(ts_EPS_MobileId_GUTI(mcc_mnc, '0001'O, '01'O, 'AABBCCDD'O));
1381 nas_tau := ts_PDU_NAS_EPS_TrackingAreaUpdateRequest(old_guti);
1382
1383 tx := ts_S1AP_InitialUE(p_eNB_value := 0, p_nasPdu := enc_PDU_NAS_EPS(valueof(nas_tau)),
1384 p_tAI := ts_enb_S1AP_TAI(g_pars.enb_pars[g_pars.mme_idx]),
1385 p_eUTRAN_CGI := ts_enb_S1AP_CGI(g_pars.enb_pars[g_pars.mme_idx]),
1386 p_rrcCause := mo_Signalling);
1387
1388 S1AP.send(tx);
1389
1390 T.start;
1391 alt {
1392 [] S1AP.receive(tr_PDU_NAS_EPS_TrackingAreaUpdateReject) {
1393 setverdict(pass);
1394 }
1395 [] S1AP.receive {
1396 setverdict(fail, "unexpected S1AP message from MME");
1397 }
1398 [] T.timeout {
1399 setverdict(fail, "no message from MME");
1400 }
1401 }
1402
Pau Espin Pedrola88e51d2024-01-08 15:44:36 +01001403 as_s1ap_handle_UeContextReleaseCmd();
Philipp Maier26a09f32023-09-01 14:18:33 +02001404}
1405testcase TC_s1ap_tau_unknown_guti() runs on MTC_CT {
1406 var charstring id := testcasename();
1407
1408 f_init_diameter(id);
Pau Espin Pedrolae747ac2023-12-20 20:55:32 +01001409 f_init_s1ap(id, 5);
Philipp Maier26a09f32023-09-01 14:18:33 +02001410 f_s1ap_setup(0);
1411
1412 var ConnHdlrPars pars := f_init_pars(ue_idx := 0);
1413 var ConnHdlr vc_conn;
1414 vc_conn := f_start_handler_with_pars(refers(f_TC_tau_unknown_guti), pars);
1415 vc_conn.done;
1416}
1417
Pau Espin Pedrol408e0ae2023-12-15 18:56:31 +01001418private function f_TC_ue_cell_reselect_eutran_to_geran(ConnHdlrPars pars) runs on ConnHdlr {
Pau Espin Pedrol408e0ae2023-12-15 18:56:31 +01001419 f_init_handler(pars);
1420 f_gtp_register_imsi(g_pars.ue_pars.imsi);
1421 f_attach();
1422
Pau Espin Pedrol35c0cc22023-12-21 19:23:48 +01001423 /* TS 23.401 Figure D.3.5-1 Steps 1,2,3,4: */
1424 f_gtp_sgsn_context_4g_to_2g();
Pau Espin Pedrol408e0ae2023-12-15 18:56:31 +01001425
Pau Espin Pedrol35c0cc22023-12-21 19:23:48 +01001426 /* TS 23.401 Figure D.3.5-1 Step 8: */
1427 f_DIA_CancelLocation();
Pau Espin Pedrol408e0ae2023-12-15 18:56:31 +01001428
Pau Espin Pedrol35c0cc22023-12-21 19:23:48 +01001429 /* TS 23.401 Figure D.3.5-1 Step 13:
1430 * Upon rx of SGSN Context Acknowledge, MME released the ENB/UE context:
1431 */
1432 as_s1ap_handle_UeContextReleaseCmd();
Pau Espin Pedrol408e0ae2023-12-15 18:56:31 +01001433
Pau Espin Pedrol35c0cc22023-12-21 19:23:48 +01001434 /* TS 23.401 Figure D.3.5-1 Step 13:
Pau Espin Pedrol78c5e412023-12-21 19:50:11 +01001435 * After Gn timer triggers, the SGW session is deleted.
1436 * Make sure Operation Indication is set to 0, to tell the SGW to keep the Session up at the PGW.
Pau Espin Pedrol35c0cc22023-12-21 19:23:48 +01001437 */
Pau Espin Pedrol78c5e412023-12-21 19:50:11 +01001438 as_GTP2C_DeleteSession_success(tr_GTP2C_Indication(oI := '0'B));
Pau Espin Pedrol35c0cc22023-12-21 19:23:48 +01001439 /* Let MME some time to handle the Create Session Response: */
Pau Espin Pedrol408e0ae2023-12-15 18:56:31 +01001440 f_sleep(3.0);
1441}
1442testcase TC_ue_cell_reselect_eutran_to_geran() runs on MTC_CT {
1443 var charstring id := testcasename();
1444
1445 f_init_diameter(id);
Pau Espin Pedrolae747ac2023-12-20 20:55:32 +01001446 f_init_s1ap(id, 6);
Pau Espin Pedrol408e0ae2023-12-15 18:56:31 +01001447 f_init_gtpv2_s11(id);
1448 f_s1ap_setup(0);
1449 f_init_gtp(id);
1450
1451 var ConnHdlrPars pars := f_init_pars(ue_idx := 0);
1452 var ConnHdlr vc_conn;
1453 vc_conn := f_start_handler_with_pars(refers(f_TC_ue_cell_reselect_eutran_to_geran), pars);
1454 vc_conn.done;
1455}
1456
Pau Espin Pedrol35618872024-01-15 15:25:18 +01001457/* 3GPP TS 23.401 D.3.6, TS 23.003 2.8.2.2 */
1458private function rai_ptmsi2_guti(in RoutingAreaIdentity rai, in OCT4 ptmsi, in OCT3 ptmsi_sig, out NAS_EPS_Types.GUTI guti) runs on ConnHdlr {
1459
1460
1461 var bitstring ptmsi_bits := oct2bit(ptmsi);
1462 var bitstring ptmsi_sig_bits := oct2bit(ptmsi_sig);
1463 var bitstring mtmsi_bits := '11'B &
1464 substr(ptmsi_bits, 2, 6) &
1465 substr(ptmsi_sig_bits, 0, 8) &
1466 substr(ptmsi_bits, 16, 16);
1467 guti := valueof(ts_NAS_GUTI(mcc_mnc := rai.mcc_digits & rai.mnc_digits,
1468 mmegi := rai.lac,
1469 mmec := rai.rac,
1470 tmsi := bit2oct(mtmsi_bits)));
1471}
1472/* Test UE attached to GERAN reselecting a EUTRAN cell. In this scenario, the
1473 * new MME will attempt to obtain information of the UE from the old SGSN
1474 * through Gn interface using SGSN Context Request/Response procedure (OS#6294). */
1475/* 3GPP TS 23.401 D.3.6, TS 23.003 2.8.2.1 */
1476private function f_TC_ue_cell_reselect_geran_to_eutran(ConnHdlrPars pars) runs on ConnHdlr {
1477 f_init_handler(pars);
1478 f_gtp_register_imsi(g_pars.ue_pars.imsi);
1479 f_gtp2_register_imsi(g_pars.ue_pars.imsi);
1480 /* SGSN Context Req doesn't necessarily contain IMSI, hence expect it through TEID=0 */
1481 f_gtp_register_teid('00000000'O);
1482 /* passed in SGSN Context Resp to MME, will be used by MME when answering with SGSN Context Ack: */
1483 const OCT4 new_sgsn_teid := 'ABABABAB'O;
1484 f_gtp_register_teid(new_sgsn_teid);
1485
1486 var template (value) EPS_MobileIdentityV mi := ts_NAS_MobileId_IMSI(pars.ue_pars.imsi);
1487 var template (value) S1AP_PDU tx;
1488 var template (value) PDU_NAS_EPS nas_tau;
1489 var RoutingAreaIdentity rai;
1490 var OCT4 ptmsi := f_gen_tmsi(suffix := 0, nri_v := 0, nri_bitlen := 8);
1491 var OCT3 ptmsi_sig := f_rnd_octstring(3);
1492 var NAS_EPS_Types.GUTI guti_val;
1493 var template (value) EPS_MobileIdentityLV old_guti;
1494 var S1APEM_Config cfg;
1495 timer T := 5.0;
1496
1497 rai := valueof(ts_RoutingAreaIdentity(mp_gn_local_mcc, mp_gn_local_mnc,
1498 int2oct(mp_gn_local_lac, 2), int2oct(mp_gn_local_rac, 1)));
1499 rai_ptmsi2_guti(rai, ptmsi, ptmsi_sig, guti_val);
1500 old_guti := ts_EPS_MobileId_GUTI_(guti_val);
1501
1502 nas_tau := ts_PDU_NAS_EPS_TrackingAreaUpdateRequest(old_guti,
1503 ts_PTMSI_SignatureTV(ptmsi_sig),
1504 ts_GUTI_TypeTV(GUTI_TYPE_MAPPED),
1505 ts_NonceTV('12345678'O),
1506 ts_CipheringKeySequenceNumberTV('000'B));
1507 tx := ts_S1AP_InitialUE(p_eNB_value := 0, p_nasPdu := enc_PDU_NAS_EPS(valueof(nas_tau)),
1508 p_tAI := ts_enb_S1AP_TAI(g_pars.enb_pars[g_pars.mme_idx]),
1509 p_eUTRAN_CGI := ts_enb_S1AP_CGI(g_pars.enb_pars[g_pars.mme_idx]),
1510 p_rrcCause := mo_Signalling);
1511
1512 S1AP.send(tx);
1513
1514 /* NAS counts are reset to zero when a mapped security context is created. */
1515 cfg := {
1516 reset_nas_counts := {}
1517 };
1518 S1AP.send(cfg);
1519
1520 as_gtp_sgsn_context_2g_to_4g(new_sgsn_teid);
1521
1522 /* We now expect the MME to send a Create Session Request to the SGW-C */
1523 T.start;
1524 alt {
1525 [] as_GTP2C_CreateSession_success();
1526 [] T.timeout { Misc_Helpers.f_shutdown(__BFILE__, __LINE__, fail, log2str("No message from MME")); }
1527 }
1528
1529 /* 3GPP TS 23.401 D.3.6 steps 14-21: */
1530 as_DIA_UpdLoc();
1531
1532 /* 3GPP TS 23.401 D.3.6 step 22, 23: */
1533 as_s1ap_handle_IntialCtxSetupReq_TAU_Accept();
1534
1535 /* We now expect the MME to send a Modify Bearer Request to the SGW-C */
1536 T.start;
1537 alt {
1538 [] as_GTP2C_ModifyBearer_success();
1539 [] T.timeout { Misc_Helpers.f_shutdown(__BFILE__, __LINE__, fail, log2str("No message from MME")); }
1540 }
1541
1542 /* Leave some time for MME to handle Modify Bearer Response: */
1543 f_sleep(1.0);
1544}
1545testcase TC_ue_cell_reselect_geran_to_eutran() runs on MTC_CT {
1546 var charstring id := testcasename();
1547
1548 f_init_diameter(id);
1549 f_init_s1ap(id, 7);
1550 f_init_gtpv2_s11(id);
1551 f_s1ap_setup(0);
1552 f_init_gtp(id);
1553
1554 var ConnHdlrPars pars := f_init_pars(ue_idx := 0);
1555 var ConnHdlr vc_conn;
1556 vc_conn := f_start_handler_with_pars(refers(f_TC_ue_cell_reselect_geran_to_eutran), pars);
1557 vc_conn.done;
1558}
1559
Harald Welte95333a12019-07-11 22:51:45 +08001560control {
1561 execute( TC_s1ap_setup_wrong_plmn() );
1562 execute( TC_s1ap_setup_wrong_tac() );
1563 execute( TC_s1ap_setup() );
Harald Welte6ec64392019-08-14 12:37:07 +02001564 execute( TC_s1ap_attach() );
Philipp Maier26a09f32023-09-01 14:18:33 +02001565 execute( TC_s1ap_tau_unknown_guti() );
Philipp Maier74d776a2023-07-12 14:04:14 +02001566 execute( TC_gn_echo_request() );
Philipp Maiera9306202023-07-24 11:41:51 +02001567 execute( TC_RIM_RAN_INF() );
Philipp Maier46059f02023-08-16 14:45:27 +02001568 execute( TC_s1ap_reset() );
Pau Espin Pedrol408e0ae2023-12-15 18:56:31 +01001569 execute( TC_ue_cell_reselect_eutran_to_geran() );
Pau Espin Pedrol35618872024-01-15 15:25:18 +01001570 execute( TC_ue_cell_reselect_geran_to_eutran() );
Harald Welteb8a4ac82019-06-23 11:04:12 +02001571}
1572
Philipp Maier46059f02023-08-16 14:45:27 +02001573
Harald Welteb8a4ac82019-06-23 11:04:12 +02001574}