blob: a165d5cc4396d22fd11a9593d90e312b909a7336 [file] [log] [blame]
Harald Weltef6dd64d2017-11-19 12:09:51 +01001module MSC_Tests {
2
Harald Welte34b5a952019-05-27 11:54:11 +02003/* Osmocom MSC test suite in in TTCN-3
4 * (C) 2017-2019 Harald Welte <laforge@gnumonks.org>
5 * (C) 2018-2019 sysmocom - s.f.m.c. GmbH
6 * (C) 2018-2019 Vadim Yanitskiy <axilirator@gmail.com>
7 * All rights reserved.
8 *
9 * Released under the terms of GNU General Public License, Version 2 or
10 * (at your option) any later version.
11 *
12 * SPDX-License-Identifier: GPL-2.0-or-later
13 */
14
Harald Weltee13cfb22019-04-23 16:52:02 +020015friend module MSC_Tests_Iu;
16
Harald Weltef6dd64d2017-11-19 12:09:51 +010017import from General_Types all;
18import from Osmocom_Types all;
Pau Espin Pedrole979c402021-04-28 17:29:54 +020019import from GSM_Types all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010020
21import from M3UA_Types all;
22import from M3UA_Emulation all;
23
24import from MTP3asp_Types all;
25import from MTP3asp_PortType all;
26
27import from SCCPasp_Types all;
28import from SCCP_Types all;
29import from SCCP_Emulation all;
30
31import from SCTPasp_Types all;
32import from SCTPasp_PortType all;
33
Harald Weltea49e36e2018-01-21 19:29:33 +010034import from Osmocom_CTRL_Functions all;
35import from Osmocom_CTRL_Types all;
36import from Osmocom_CTRL_Adapter all;
37
Harald Welte3ca1c902018-01-24 18:51:27 +010038import from TELNETasp_PortType all;
39import from Osmocom_VTY_Functions all;
40
Harald Weltea49e36e2018-01-21 19:29:33 +010041import from MNCC_Emulation all;
Harald Welte2bb825f2018-01-22 11:31:18 +010042import from MNCC_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010043
Harald Welte4aa970c2018-01-26 10:38:09 +010044import from MGCP_Emulation all;
45import from MGCP_Types all;
46import from MGCP_Templates all;
47import from SDP_Types all;
48
Harald Weltea49e36e2018-01-21 19:29:33 +010049import from GSUP_Emulation all;
50import from GSUP_Types all;
51import from IPA_Emulation all;
52
Harald Weltef6dd64d2017-11-19 12:09:51 +010053import from BSSAP_Types all;
Harald Welte6811d102019-04-14 22:23:14 +020054import from RAN_Adapter all;
Harald Weltea49e36e2018-01-21 19:29:33 +010055import from BSSAP_CodecPort all;
56import from BSSMAP_Templates all;
Harald Welte6811d102019-04-14 22:23:14 +020057import from RAN_Emulation all;
Harald Weltea49e36e2018-01-21 19:29:33 +010058import from BSC_ConnectionHandler all;
Harald Weltee13cfb22019-04-23 16:52:02 +020059import from RANAP_Templates all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010060
Harald Welte4263c522018-12-06 11:56:27 +010061import from SGsAP_Templates all;
62import from SGsAP_Types all;
63import from SGsAP_Emulation all;
64
Harald Weltea49e36e2018-01-21 19:29:33 +010065import from MobileL3_Types all;
66import from MobileL3_CommonIE_Types all;
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +070067import from MobileL3_SMS_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010068import from L3_Templates all;
Harald Welte158a7ca2018-02-16 18:11:31 +010069import from L3_Common all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010070
Harald Weltef640a012018-04-14 17:49:21 +020071import from SMPP_Types all;
72import from SMPP_Templates all;
73import from SMPP_Emulation all;
74
Stefan Sperlingc307e682018-06-14 15:15:46 +020075import from SCCP_Templates all;
76
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070077import from SS_Types all;
78import from SS_Templates all;
79import from USSD_Helpers all;
Harald Welte4263c522018-12-06 11:56:27 +010080import from DNS_Helpers all;
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070081
Philipp Maier948747b2019-04-02 15:22:33 +020082import from TCCConversion_Functions all;
83
Harald Welte9b751a62019-04-14 17:39:29 +020084const integer NUM_BSC := 3;
Harald Weltef6dd64d2017-11-19 12:09:51 +010085
Harald Welte4263c522018-12-06 11:56:27 +010086/* Needed for SGsAP SMS */
87import from MobileL3_SMS_Types all;
88
Harald Weltea4ca4462018-02-09 00:17:14 +010089type component MTC_CT extends CTRL_Adapter_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +010090 var boolean g_initialized := false;
Harald Weltea49e36e2018-01-21 19:29:33 +010091
Harald Welte6811d102019-04-14 22:23:14 +020092 var RAN_Adapter g_bssap[NUM_BSC];
Harald Weltea4ca4462018-02-09 00:17:14 +010093
Harald Weltea49e36e2018-01-21 19:29:33 +010094 /* no 'adapter_CT' for MNCC or GSUP */
95 var MNCC_Emulation_CT vc_MNCC;
Harald Welte4aa970c2018-01-26 10:38:09 +010096 var MGCP_Emulation_CT vc_MGCP;
Harald Weltea49e36e2018-01-21 19:29:33 +010097 var GSUP_Emulation_CT vc_GSUP;
98 var IPA_Emulation_CT vc_GSUP_IPA;
Harald Weltef640a012018-04-14 17:49:21 +020099 var SMPP_Emulation_CT vc_SMPP;
Harald Welte4263c522018-12-06 11:56:27 +0100100 var SGsAP_Emulation_CT vc_SGsAP;
Harald Weltea49e36e2018-01-21 19:29:33 +0100101
102 /* only to get events from IPA underneath GSUP */
103 port IPA_CTRL_PT GSUP_IPA_EVENT;
Harald Welte3ca1c902018-01-24 18:51:27 +0100104 /* VTY to MSC */
105 port TELNETasp_PT MSCVTY;
Philipp Maier328d1662018-03-07 10:40:27 +0100106
107 /* A port to directly send BSSAP messages. This port is used for
108 * tests that require low level access to sen arbitrary BSSAP
109 * messages. Run f_init_bssap_direct() to connect and initialize */
110 port BSSAP_CODEC_PT BSSAP_DIRECT;
111
112 /* When BSSAP messages are directly sent, then the connection
113 * handler is not active, which means that also no guard timer is
114 * set up. The following timer will serve as a replacement */
115 timer Tguard_direct := 60.0;
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100116
117 /* Configure T(tias) over VTY, seconds */
118 var integer g_msc_sccp_timer_ias := 7 * 60;
119 /* Configure T(tiar) over VTY, seconds */
120 var integer g_msc_sccp_timer_iar := 15 * 60;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100121}
122
123modulepar {
Harald Weltea49e36e2018-01-21 19:29:33 +0100124 /* remote parameters of IUT */
125 charstring mp_msc_ip := "127.0.0.1";
126 integer mp_msc_ctrl_port := 4255;
127 integer mp_msc_vty_port := 4254;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100128
Harald Weltea49e36e2018-01-21 19:29:33 +0100129 /* local parameters of emulated HLR */
Philipp Maier9b690e42018-12-21 11:50:03 +0100130 boolean mp_mm_info := false;
Harald Weltea49e36e2018-01-21 19:29:33 +0100131 charstring mp_hlr_ip := "127.0.0.1";
132 integer mp_hlr_port := 4222;
Harald Welte6126fb02018-01-27 20:08:24 +0100133 charstring mp_mgw_ip := "127.0.0.1";
134 integer mp_mgw_port := 2427;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100135
Harald Weltea49e36e2018-01-21 19:29:33 +0100136 charstring mp_msc_mncc := "/tmp/mncc";
Harald Weltea4ca4462018-02-09 00:17:14 +0100137
Harald Weltef640a012018-04-14 17:49:21 +0200138 integer mp_msc_smpp_port := 2775;
139 charstring mp_smpp_system_id := "msc_tester";
140 charstring mp_smpp_password := "osmocom1";
Harald Welte4263c522018-12-06 11:56:27 +0100141 charstring mp_mme_name := "mmec01.mmegi0001.mme.epc.mnc070.mcc901.3gppnetwork.org";
142 charstring mp_vlr_name := "vlr.example.net";
Harald Weltef640a012018-04-14 17:49:21 +0200143
Harald Welte6811d102019-04-14 22:23:14 +0200144 RAN_Configurations mp_bssap_cfg := {
Philipp Maier75932982018-03-27 14:52:35 +0200145 {
146 sccp_service_type := "mtp3_itu",
147 sctp_addr := { 23905, "127.0.0.1", 2905, "127.0.0.1" },
148 own_pc := 185,
149 own_ssn := 254,
150 peer_pc := 187,
151 peer_ssn := 254,
152 sio := '83'O,
153 rctx := 0
154 },
155 {
156 sccp_service_type := "mtp3_itu",
157 sctp_addr := { 23906, "127.0.0.1", 2905, "127.0.0.1" },
158 own_pc := 186,
159 own_ssn := 254,
160 peer_pc := 187,
161 peer_ssn := 254,
162 sio := '83'O,
163 rctx := 1
164 }
Harald Weltea4ca4462018-02-09 00:17:14 +0100165 };
Harald Weltef6dd64d2017-11-19 12:09:51 +0100166}
167
Philipp Maier328d1662018-03-07 10:40:27 +0100168/* altstep for the global guard timer (only used when BSSAP_DIRECT
169 * is used for communication */
170private altstep as_Tguard_direct() runs on MTC_CT {
171 [] Tguard_direct.timeout {
172 setverdict(fail, "Tguard timeout");
Daniel Willmannafce8662018-07-06 23:11:32 +0200173 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +0100174 }
175}
Harald Weltef6dd64d2017-11-19 12:09:51 +0100176
Neels Hofmeyr2ca1ab42019-03-08 03:45:43 +0100177private altstep as_optional_cc_rel(CallParameters cpars, boolean respond := false) runs on BSC_ConnHdlr {
178 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id))) {
179 if (respond) {
180 var BIT1 tid_remote := '1'B;
181 if (cpars.mo_call) {
182 tid_remote := '0'B;
183 }
184 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id, tid_remote)));
185 }
186 }
Neels Hofmeyrde76f052019-02-26 05:02:46 +0100187}
188
Harald Weltef640a012018-04-14 17:49:21 +0200189function f_init_smpp(charstring id) runs on MTC_CT {
190 id := id & "-SMPP";
191 var EsmePars pars := {
192 mode := MODE_TRANSCEIVER,
193 bind := {
194 system_id := mp_smpp_system_id,
195 password := mp_smpp_password,
196 system_type := "MSC_Tests",
197 interface_version := hex2int('34'H),
198 addr_ton := unknown,
199 addr_npi := unknown,
200 address_range := ""
201 },
202 esme_role := true
203 }
204
205 vc_SMPP := SMPP_Emulation_CT.create(id);
206 map(vc_SMPP:SMPP_PORT, system:SMPP_PORT);
Harald Welte4698a4c2020-08-18 22:57:52 +0200207 vc_SMPP.start(SMPP_Emulation.main_client(pars, mp_msc_ip, mp_msc_smpp_port, "", 0));
Harald Weltef640a012018-04-14 17:49:21 +0200208}
209
210
Harald Weltea49e36e2018-01-21 19:29:33 +0100211function f_init_mncc(charstring id) runs on MTC_CT {
212 id := id & "-MNCC";
213 var MnccOps ops := {
214 create_cb := refers(MNCC_Emulation.ExpectedCreateCallback),
215 unitdata_cb := refers(MNCC_Emulation.DummyUnitdataCallback)
216 }
217
218 vc_MNCC := MNCC_Emulation_CT.create(id);
219 map(vc_MNCC:MNCC, system:MNCC_CODEC_PT);
220 vc_MNCC.start(MNCC_Emulation.main(ops, id, mp_msc_mncc));
Harald Weltef6dd64d2017-11-19 12:09:51 +0100221}
222
Harald Welte4aa970c2018-01-26 10:38:09 +0100223function f_init_mgcp(charstring id) runs on MTC_CT {
224 id := id & "-MGCP";
225 var MGCPOps ops := {
226 create_cb := refers(MGCP_Emulation.ExpectedCreateCallback),
227 unitdata_cb := refers(MGCP_Emulation.DummyUnitdataCallback)
228 }
229 var MGCP_conn_parameters pars := {
Harald Welte6126fb02018-01-27 20:08:24 +0100230 callagent_ip := mp_msc_ip,
Harald Welte4aa970c2018-01-26 10:38:09 +0100231 callagent_udp_port := -1,
Harald Welte6126fb02018-01-27 20:08:24 +0100232 mgw_ip := mp_mgw_ip,
Pau Espin Pedrol1a026a52019-06-18 17:21:52 +0200233 mgw_udp_port := mp_mgw_port,
234 multi_conn_mode := false
Harald Welte4aa970c2018-01-26 10:38:09 +0100235 }
236
237 vc_MGCP := MGCP_Emulation_CT.create(id);
238 map(vc_MGCP:MGCP, system:MGCP_CODEC_PT);
239 vc_MGCP.start(MGCP_Emulation.main(ops, pars, id));
240}
241
Philipp Maierc09a1312019-04-09 16:05:26 +0200242function ForwardUnitdataCallback(PDU_SGsAP msg)
243runs on SGsAP_Emulation_CT return template PDU_SGsAP {
244 SGsAP_CLIENT.send(msg);
245 return omit;
246}
247
Harald Welte4263c522018-12-06 11:56:27 +0100248function f_init_sgsap(charstring id) runs on MTC_CT {
249 id := id & "-SGsAP";
250 var SGsAPOps ops := {
251 create_cb := refers(SGsAP_Emulation.ExpectedCreateCallback),
Philipp Maierc09a1312019-04-09 16:05:26 +0200252 unitdata_cb := refers(ForwardUnitdataCallback)
Harald Welte4263c522018-12-06 11:56:27 +0100253 }
254 var SGsAP_conn_parameters pars := {
255 remote_ip := mp_msc_ip,
256 remote_sctp_port := 29118,
257 local_ip := "",
258 local_sctp_port := -1
259 }
260
261 vc_SGsAP := SGsAP_Emulation_CT.create(id);
262 map(vc_SGsAP:SGsAP, system:SGsAP_CODEC_PT);
263 vc_SGsAP.start(SGsAP_Emulation.main(ops, pars, id));
264}
265
266
Harald Weltea49e36e2018-01-21 19:29:33 +0100267function f_init_gsup(charstring id) runs on MTC_CT {
268 id := id & "-GSUP";
269 var GsupOps ops := {
270 create_cb := refers(GSUP_Emulation.ExpectedCreateCallback)
271 }
272
273 vc_GSUP_IPA := IPA_Emulation_CT.create(id & "-IPA");
274 vc_GSUP := GSUP_Emulation_CT.create(id);
275
276 map(vc_GSUP_IPA:IPA_PORT, system:IPA_CODEC_PT);
277 connect(vc_GSUP:GSUP, vc_GSUP_IPA:IPA_GSUP_PORT);
278 /* we use this hack to get events like ASP_IPA_EVENT_UP */
279 connect(vc_GSUP_IPA:IPA_CTRL_PORT, self:GSUP_IPA_EVENT);
280
281 vc_GSUP.start(GSUP_Emulation.main(ops, id));
282 vc_GSUP_IPA.start(IPA_Emulation.main_server(mp_hlr_ip, mp_hlr_port));
283
284 /* wait for incoming connection to GSUP port before proceeding */
285 timer T := 10.0;
286 T.start;
287 alt {
Vadim Yanitskiy61564be2020-05-18 20:44:14 +0700288 [] GSUP_IPA_EVENT.receive(tr_ASP_IPA_EV(ASP_IPA_EVENT_UP)) { }
Harald Weltea49e36e2018-01-21 19:29:33 +0100289 [] T.timeout {
Harald Welte458fd372018-03-21 11:26:23 +0100290 setverdict(fail, "No connection to GSUP Port");
Daniel Willmannafce8662018-07-06 23:11:32 +0200291 mtc.stop
Harald Weltea49e36e2018-01-21 19:29:33 +0100292 }
293 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100294}
295
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200296function f_init(integer num_bsc := 1, boolean sgsap := false, boolean gsup := true, boolean osmux := false) runs on MTC_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +0100297
298 if (g_initialized == true) {
299 return;
300 }
301 g_initialized := true;
302
Philipp Maier75932982018-03-27 14:52:35 +0200303 if (num_bsc > NUM_BSC) {
Daniel Willmannafce8662018-07-06 23:11:32 +0200304 testcase.stop("excess number of BSC instances requested");
Philipp Maier75932982018-03-27 14:52:35 +0200305 }
306
307 for (var integer i := 0; i < num_bsc; i := i + 1) {
308 if (isbound(mp_bssap_cfg[i])) {
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200309 var RanOps ranops := BSC_RanOps;
310 ranops.use_osmux := osmux;
311 f_ran_adapter_init(g_bssap[i], mp_bssap_cfg[i], "MSC_Test_" & int2str(i), ranops);
Harald Welte3ca0ce12019-04-23 17:18:48 +0200312 f_ran_adapter_start(g_bssap[i]);
Philipp Maier75932982018-03-27 14:52:35 +0200313 } else {
Daniel Willmannafce8662018-07-06 23:11:32 +0200314 testcase.stop("missing BSSAP configuration");
Philipp Maier75932982018-03-27 14:52:35 +0200315 }
316 }
317
Pau Espin Pedrol9a5b8ff2021-01-04 19:01:31 +0100318 f_ipa_ctrl_start_client(mp_msc_ip, mp_msc_ctrl_port);
Harald Weltea49e36e2018-01-21 19:29:33 +0100319 f_init_mncc("MSC_Test");
Harald Welte4aa970c2018-01-26 10:38:09 +0100320 f_init_mgcp("MSC_Test");
Philipp Maierc09a1312019-04-09 16:05:26 +0200321
322 if (gsup == true) {
323 f_init_gsup("MSC_Test");
324 }
Harald Weltef640a012018-04-14 17:49:21 +0200325 f_init_smpp("MSC_Test");
Philipp Maier57865482019-01-07 18:33:13 +0100326
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100327 if (sgsap == true) {
Philipp Maier57865482019-01-07 18:33:13 +0100328 f_init_sgsap("MSC_Test");
329 }
Harald Welte3ca1c902018-01-24 18:51:27 +0100330
331 map(self:MSCVTY, system:MSCVTY);
332 f_vty_set_prompts(MSCVTY);
333 f_vty_transceive(MSCVTY, "enable");
Harald Welteb14c77a2018-01-25 17:25:44 +0100334
335 /* set some defaults */
336 f_vty_config(MSCVTY, "network", "authentication optional");
337 f_vty_config(MSCVTY, "msc", "assign-tmsi");
Oliver Smith1d118ff2019-07-03 10:57:35 +0200338 f_vty_config(MSCVTY, "msc", "check-imei-rqd 0");
Harald Welteb14c77a2018-01-25 17:25:44 +0100339 f_vty_config(MSCVTY, "network", "encryption a5 0");
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100340 f_vty_config(MSCVTY, "cs7 instance 0", "sccp-timer ias " & int2str(g_msc_sccp_timer_ias));
341 f_vty_config(MSCVTY, "cs7 instance 0", "sccp-timer iar " & int2str(g_msc_sccp_timer_iar));
Pau Espin Pedrol9a732a42020-09-15 15:56:33 +0200342 if (osmux) {
343 f_vty_config(MSCVTY, "msc", "osmux on");
344 } else {
345 f_vty_config(MSCVTY, "msc", "osmux off");
Pau Espin Pedrol3dd33bc2019-05-31 17:51:20 +0200346 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100347}
348
Philipp Maier328d1662018-03-07 10:40:27 +0100349/* Initialize for a direct connection to BSSAP. This function is an alternative
350 * to f_init() when the high level functions of the BSC_ConnectionHandler are
351 * not needed. */
352function f_init_bssap_direct() runs on MTC_CT {
Harald Welte3ca0ce12019-04-23 17:18:48 +0200353 f_ran_adapter_init(g_bssap[0], mp_bssap_cfg[0], "MSC_Test", omit);
Philipp Maier75932982018-03-27 14:52:35 +0200354 connect(g_bssap[0].vc_SCCP:SCCP_SP_PORT, self:BSSAP_DIRECT);
Philipp Maier328d1662018-03-07 10:40:27 +0100355
356 /* Start guard timer and activate it as default */
357 Tguard_direct.start
358 activate(as_Tguard_direct());
359}
360
Harald Weltea49e36e2018-01-21 19:29:33 +0100361type function void_fn(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100362
Harald Weltea49e36e2018-01-21 19:29:33 +0100363/* FIXME: move into BSC_ConnectionHandler? */
Harald Welte9b751a62019-04-14 17:39:29 +0200364function f_init_pars(integer imsi_suffix, boolean sgsap := false, boolean gsup := true, integer ran_idx := 0,
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200365 boolean ran_is_geran := true, boolean use_osmux := false, OCT4 gsup_sid := '20000101'O,
366 boolean verify_cell_id := true)
Harald Weltef9abf8d2019-04-21 13:07:17 +0200367runs on MTC_CT return BSC_ConnHdlrPars {
Harald Weltede371492018-01-27 23:44:41 +0100368 var BSC_ConnHdlrNetworkPars net_pars := {
369 kc_support := '0A'O, /* A5/1 and A5/3 enabled */
370 expect_tmsi := true,
371 expect_auth := false,
Oliver Smith1d118ff2019-07-03 10:57:35 +0200372 expect_ciph := false,
373 expect_imei := false,
374 expect_imei_early := false,
375 check_imei_result := OSMO_GSUP_IMEI_RESULT_ACK,
376 check_imei_error := false
Harald Weltede371492018-01-27 23:44:41 +0100377 };
Harald Weltea49e36e2018-01-21 19:29:33 +0100378 var BSC_ConnHdlrPars pars := {
Harald Weltef9abf8d2019-04-21 13:07:17 +0200379 sccp_addr_own := g_bssap[ran_idx].sccp_addr_own,
380 sccp_addr_peer := g_bssap[ran_idx].sccp_addr_peer,
Harald Welteedbab812018-03-18 16:02:25 +0100381 cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42)),
Harald Welte81b7f9d2018-01-24 19:06:24 +0100382 imei := f_gen_imei(imsi_suffix),
383 imsi := f_gen_imsi(imsi_suffix),
384 msisdn := f_gen_msisdn(imsi_suffix),
Harald Welte256571e2018-01-24 18:47:19 +0100385 tmsi := omit,
Harald Welte9de84792018-01-28 01:06:35 +0100386 cm1 := valueof(ts_CM1),
Harald Welte82600572018-01-21 20:54:08 +0100387 cm2 := valueof(ts_CM2_default),
Harald Welte16114282018-01-24 22:41:21 +0100388 cm3 := omit,
Harald Weltede371492018-01-27 23:44:41 +0100389 vec := omit,
Neels Hofmeyrb00c5b02021-06-23 20:05:25 +0200390 vec_keep := false,
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100391 net := net_pars,
Philipp Maieraeb29a82018-11-08 17:40:53 +0100392 send_early_cm := true,
393 ipa_ctrl_ip := mp_msc_ip,
394 ipa_ctrl_port := mp_msc_ctrl_port,
Philipp Maier9b690e42018-12-21 11:50:03 +0100395 ipa_ctrl_enable := true,
Philipp Maier57865482019-01-07 18:33:13 +0100396 mm_info := mp_mm_info,
Philipp Maierc09a1312019-04-09 16:05:26 +0200397 sgsap_enable := sgsap,
Harald Weltef9abf8d2019-04-21 13:07:17 +0200398 gsup_enable := gsup,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +0100399 gsup_sid := gsup_sid,
Harald Weltec1f937a2019-04-21 21:19:23 +0200400 ran_idx := ran_idx,
Harald Welte9b751a62019-04-14 17:39:29 +0200401 use_umts_aka := false,
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200402 ran_is_geran := ran_is_geran,
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200403 use_osmux := use_osmux,
Pau Espin Pedrol833174e2020-09-03 16:46:02 +0200404 use_ipv6 := false,
Pau Espin Pedrole979c402021-04-28 17:29:54 +0200405 verify_cell_id := verify_cell_id,
406 common_id_last_eutran_plmn := omit
Harald Weltea49e36e2018-01-21 19:29:33 +0100407 };
Harald Weltee13cfb22019-04-23 16:52:02 +0200408 if (not ran_is_geran) {
409 pars.use_umts_aka := true;
410 pars.net.expect_auth := true;
411 }
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100412 return pars;
413}
414
Neels Hofmeyr0ac63152019-05-07 01:20:17 +0200415function f_start_handler_with_pars(void_fn fn, BSC_ConnHdlrPars pars, integer bssap_idx := 0) runs on MTC_CT return BSC_ConnHdlr {
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100416 var BSC_ConnHdlr vc_conn;
Neels Hofmeyr0ac63152019-05-07 01:20:17 +0200417 var charstring id := testcasename() & int2str(bssap_idx);
Harald Weltea49e36e2018-01-21 19:29:33 +0100418
419 vc_conn := BSC_ConnHdlr.create(id);
420 /* BSSMAP part / A interface */
Neels Hofmeyr0ac63152019-05-07 01:20:17 +0200421 connect(vc_conn:BSSAP, g_bssap[pars.ran_idx + bssap_idx].vc_RAN:CLIENT);
422 connect(vc_conn:BSSAP_PROC, g_bssap[pars.ran_idx + bssap_idx].vc_RAN:PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100423 /* MNCC part */
424 connect(vc_conn:MNCC, vc_MNCC:MNCC_CLIENT);
425 connect(vc_conn:MNCC_PROC, vc_MNCC:MNCC_PROC);
Harald Welte4aa970c2018-01-26 10:38:09 +0100426 /* MGCP part */
427 connect(vc_conn:MGCP, vc_MGCP:MGCP_CLIENT);
428 connect(vc_conn:MGCP_PROC, vc_MGCP:MGCP_PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100429 /* GSUP part */
Philipp Maierc09a1312019-04-09 16:05:26 +0200430 if (pars.gsup_enable == true) {
431 connect(vc_conn:GSUP, vc_GSUP:GSUP_CLIENT);
432 connect(vc_conn:GSUP_PROC, vc_GSUP:GSUP_PROC);
433 }
Harald Weltef640a012018-04-14 17:49:21 +0200434 /* SMPP part */
435 connect(vc_conn:SMPP, vc_SMPP:SMPP_CLIENT);
436 connect(vc_conn:SMPP_PROC, vc_SMPP:SMPP_PROC);
Harald Welte4263c522018-12-06 11:56:27 +0100437 /* SGs part */
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100438 if (pars.sgsap_enable == true) {
Philipp Maier57865482019-01-07 18:33:13 +0100439 connect(vc_conn:SGsAP, vc_SGsAP:SGsAP_CLIENT);
440 connect(vc_conn:SGsAP_PROC, vc_SGsAP:SGsAP_PROC);
441 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100442
Harald Weltea10db902018-01-27 12:44:49 +0100443 /* We cannot use vc_conn.start(f_init_handler(fn, id, pars)); as we cannot have
444 * a stand-alone 'derefers()' call, see https://www.eclipse.org/forums/index.php/t/1091364/ */
Harald Weltea49e36e2018-01-21 19:29:33 +0100445 vc_conn.start(derefers(fn)(id, pars));
446 return vc_conn;
447}
448
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200449function f_start_handler(void_fn fn, integer imsi_suffix, integer ran_idx := 0, boolean ran_is_geran := true, boolean use_osmux := false,
450 boolean verify_cell_id := true)
Harald Welte9b751a62019-04-14 17:39:29 +0200451runs on MTC_CT return BSC_ConnHdlr {
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200452 return f_start_handler_with_pars(fn, f_init_pars(imsi_suffix, ran_idx := ran_idx, ran_is_geran := ran_is_geran, use_osmux := use_osmux, verify_cell_id := verify_cell_id));
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100453}
454
Harald Weltea49e36e2018-01-21 19:29:33 +0100455private function f_tc_lu_imsi_noauth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100456 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100457 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100458}
Harald Weltea49e36e2018-01-21 19:29:33 +0100459testcase TC_lu_imsi_noauth_tmsi() runs on MTC_CT {
460 var BSC_ConnHdlr vc_conn;
461 f_init();
462
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100463 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi), 1);
Harald Weltea49e36e2018-01-21 19:29:33 +0100464 vc_conn.done;
465}
466
467private function f_tc_lu_imsi_noauth_notmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100468 pars.net.expect_tmsi := false;
Harald Weltea10db902018-01-27 12:44:49 +0100469 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100470 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100471}
Harald Weltea49e36e2018-01-21 19:29:33 +0100472testcase TC_lu_imsi_noauth_notmsi() runs on MTC_CT {
473 var BSC_ConnHdlr vc_conn;
474 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100475 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
Harald Weltea49e36e2018-01-21 19:29:33 +0100476
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100477 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi), 2);
Harald Weltea49e36e2018-01-21 19:29:33 +0100478 vc_conn.done;
479}
480
481/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
Harald Weltee13cfb22019-04-23 16:52:02 +0200482friend function f_tc_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100483 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100484 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
485
486 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +0200487 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyrd076c522019-11-28 01:00:52 +0100488 f_mm_common();
Harald Weltea49e36e2018-01-21 19:29:33 +0100489 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
490 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
491 alt {
Harald Welte5946b332018-03-18 23:32:21 +0100492 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej(int2oct(23,1)))) {
493 f_expect_clear();
494 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100495 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
496 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200497 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100498 }
499 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100500}
501testcase TC_lu_imsi_reject() runs on MTC_CT {
502 var BSC_ConnHdlr vc_conn;
503 f_init();
504
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200505 vc_conn := f_start_handler(refers(f_tc_lu_imsi_reject), 3, verify_cell_id := false);
Harald Weltea49e36e2018-01-21 19:29:33 +0100506 vc_conn.done;
507}
508
Harald Weltee13cfb22019-04-23 16:52:02 +0200509
510
Harald Weltea49e36e2018-01-21 19:29:33 +0100511/* Do LU by IMSI, timeout on GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +0200512friend function f_tc_lu_imsi_timeout_gsup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100513 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100514 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
515
516 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +0200517 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyrd076c522019-11-28 01:00:52 +0100518 f_mm_common();
Harald Weltea49e36e2018-01-21 19:29:33 +0100519 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
520 /* Normally the HLR would need to respond here, but we decide to force a timeout here */
521 alt {
522 /* FIXME: Expect specific reject cause */
Harald Welte5946b332018-03-18 23:32:21 +0100523 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
524 f_expect_clear();
525 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100526 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
527 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200528 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100529 }
530 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100531}
532testcase TC_lu_imsi_timeout_gsup() runs on MTC_CT {
533 var BSC_ConnHdlr vc_conn;
534 f_init();
535
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200536 vc_conn := f_start_handler(refers(f_tc_lu_imsi_timeout_gsup), 4, verify_cell_id := false);
Harald Weltea49e36e2018-01-21 19:29:33 +0100537 vc_conn.done;
538}
539
Harald Weltee13cfb22019-04-23 16:52:02 +0200540
Harald Welte7b1b2812018-01-22 21:23:06 +0100541private function f_tc_lu_imsi_auth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100542 pars.net.expect_auth := true;
Harald Weltea10db902018-01-27 12:44:49 +0100543 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100544 f_perform_lu();
Harald Welte7b1b2812018-01-22 21:23:06 +0100545}
546testcase TC_lu_imsi_auth_tmsi() runs on MTC_CT {
547 var BSC_ConnHdlr vc_conn;
548 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100549 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte7b1b2812018-01-22 21:23:06 +0100550
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100551 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi), 5);
Harald Welte7b1b2812018-01-22 21:23:06 +0100552 vc_conn.done;
553}
554
Harald Weltee13cfb22019-04-23 16:52:02 +0200555
556friend function f_tc_lu_imsi_auth3g_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte8a397ae2019-04-21 22:03:37 +0200557 pars.net.expect_auth := true;
558 pars.use_umts_aka := true;
559 f_init_handler(pars);
560 f_perform_lu();
561}
562testcase TC_lu_imsi_auth3g_tmsi() runs on MTC_CT {
563 var BSC_ConnHdlr vc_conn;
564 f_init();
565 f_vty_config(MSCVTY, "network", "authentication required");
566
567 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi), 1005);
568 vc_conn.done;
569}
Harald Weltea49e36e2018-01-21 19:29:33 +0100570
Pau Espin Pedrold3d54a92019-12-17 17:02:54 +0100571/* Proceed with LU but never receive an TMSI Realloc from MS after LU Accept (OS#4337).
572 * TS 24.008 sec 4.3.1.5 states MSC should simply release all MM connections.
573 */
574friend function f_tc_lu_imsi_timeout_tmsi_realloc(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
575
576 f_init_handler(pars);
577
578 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
579 var PDU_DTAP_MT dtap_mt;
580
581 /* tell GSUP dispatcher to send this IMSI to us */
582 f_create_gsup_expect(hex2str(g_pars.imsi));
583
584 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
585 if (g_pars.ran_is_geran) {
586 f_bssap_compl_l3(l3_lu);
587 if (g_pars.send_early_cm) {
588 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
589 }
590 } else {
591 f_ranap_initial_ue(l3_lu);
592 }
593
594 f_mm_imei_early();
595 f_mm_common();
596 f_msc_lu_hlr();
597 f_mm_imei();
598
599 alt {
600 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) -> value dtap_mt {}
601 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
602 setverdict(fail, "Expected LU ACK, but received LU REJ");
603 mtc.stop;
604 }
605 }
606
607 /* currently (due to bug OS#4337), an extra LU reject is received before
608 terminating the connection. Enabling following line makes the test
609 pass: */
610 //f_expect_lu_reject('16'O); /* Cause: congestion */
611
612 /* f_expect_lu_reject() already waits for T"-1" (X1, 5 seconds), but give some
613 extra time to avoid race conditons... */
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200614 f_expect_clear(7.0, verify_vlr_cell_id := false);
Pau Espin Pedrold3d54a92019-12-17 17:02:54 +0100615
616 setverdict(pass);
617}
618testcase TC_lu_imsi_timeout_tmsi_realloc() runs on MTC_CT {
619 var BSC_ConnHdlr vc_conn;
620 f_init();
621
622 vc_conn := f_start_handler(refers(f_tc_lu_imsi_timeout_tmsi_realloc), 5);
623 vc_conn.done;
624}
625
Harald Weltee13cfb22019-04-23 16:52:02 +0200626
Harald Weltea49e36e2018-01-21 19:29:33 +0100627/* Send CM SERVICE REQ for IMSI that has never performed LU before */
Harald Weltee13cfb22019-04-23 16:52:02 +0200628friend function f_tc_cmserv_imsi_unknown(charstring id, BSC_ConnHdlrPars pars)
Harald Weltea49e36e2018-01-21 19:29:33 +0100629runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100630 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100631
632 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welteedbab812018-03-18 16:02:25 +0100633 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
Harald Welte6ed6bf92018-01-24 21:09:15 +0100634 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
Harald Weltea49e36e2018-01-21 19:29:33 +0100635
636 f_create_gsup_expect(hex2str(g_pars.imsi));
637
638 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200639 f_cl3_or_initial_ue(l3_info);
Harald Welteb7817992019-05-09 13:15:39 +0200640 f_mm_auth();
Harald Weltea49e36e2018-01-21 19:29:33 +0100641
642 timer T := 10.0;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100643 T.start;
644 alt {
Harald Weltea49e36e2018-01-21 19:29:33 +0100645 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
646 //[] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_ACC)) { }
Daniel Willmannafce8662018-07-06 23:11:32 +0200647 [] BSSAP.receive {
648 setverdict(fail, "Received unexpected BSSAP");
649 mtc.stop;
650 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100651 [] GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi)) {
652 setverdict(fail, "Unexpected GSUP UL REQ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200653 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100654 }
Daniel Willmannafce8662018-07-06 23:11:32 +0200655 [] T.timeout {
Neels Hofmeyrf1c3c212020-08-19 13:15:32 +0000656 setverdict(fail, "Timeout waiting for CM SERV REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200657 mtc.stop;
658 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100659 }
660
Harald Welte1ddc7162018-01-27 14:25:46 +0100661 f_expect_clear();
Harald Weltef6dd64d2017-11-19 12:09:51 +0100662}
Harald Weltea49e36e2018-01-21 19:29:33 +0100663testcase TC_cmserv_imsi_unknown() runs on MTC_CT {
664 var BSC_ConnHdlr vc_conn;
665 f_init();
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200666 vc_conn := f_start_handler(refers(f_tc_cmserv_imsi_unknown), 6, verify_cell_id := false);
Harald Weltea49e36e2018-01-21 19:29:33 +0100667 vc_conn.done;
668}
669
Harald Weltee13cfb22019-04-23 16:52:02 +0200670
Neels Hofmeyr13737fb2020-08-19 13:16:14 +0000671/* Send CM SERVICE REQ for TMSI that has never performed LU before */
672friend function f_tc_cmserv_tmsi_unknown(charstring id, BSC_ConnHdlrPars pars)
673runs on BSC_ConnHdlr {
674 f_init_handler(pars);
675
676 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV('57111111'O));
677 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
678 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
679
680 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
681 f_cl3_or_initial_ue(l3_info);
682 f_mm_auth();
683
684 timer T := 10.0;
685 T.start;
686 alt {
687 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
688 [] BSSAP.receive {
689 setverdict(fail, "Received unexpected BSSAP");
690 mtc.stop;
691 }
692 [] T.timeout {
693 setverdict(fail, "Timeout waiting for CM SERV REJ");
694 mtc.stop;
695 }
696 }
697
698 f_expect_clear();
699}
700testcase TC_cmserv_tmsi_unknown() runs on MTC_CT {
701 var BSC_ConnHdlr vc_conn;
702 f_init();
703 vc_conn := f_start_handler(refers(f_tc_cmserv_tmsi_unknown), 57, verify_cell_id := false);
704 vc_conn.done;
705}
706
Neels Hofmeyr14d0b132020-08-19 13:49:05 +0000707/* Send Paging Response for IMSI that has never performed LU before */
708friend function f_tc_paging_response_imsi_unknown(charstring id, BSC_ConnHdlrPars pars)
709runs on BSC_ConnHdlr {
710 f_init_handler(pars);
711
712 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
713 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
714 var PDU_ML3_MS_NW l3_info := valueof(ts_PAG_RESP(mi));
715
716 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
717 f_cl3_or_initial_ue(l3_info);
718
719 /* The Paging Response gets rejected by a direct Clear Command */
720 f_expect_clear();
721}
722testcase TC_paging_response_imsi_unknown() runs on MTC_CT {
723 var BSC_ConnHdlr vc_conn;
724 f_init();
725 vc_conn := f_start_handler(refers(f_tc_paging_response_imsi_unknown), 58, verify_cell_id := false);
726 vc_conn.done;
727}
728
729/* Send Paging Response for TMSI that has never performed LU before */
730friend function f_tc_paging_response_tmsi_unknown(charstring id, BSC_ConnHdlrPars pars)
731runs on BSC_ConnHdlr {
732 f_init_handler(pars);
733
734 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV('59111111'O));
735 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
736 var PDU_ML3_MS_NW l3_info := valueof(ts_PAG_RESP(mi));
737
738 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
739 f_cl3_or_initial_ue(l3_info);
740
741 /* The Paging Response gets rejected by a direct Clear Command */
742 f_expect_clear();
743}
744testcase TC_paging_response_tmsi_unknown() runs on MTC_CT {
745 var BSC_ConnHdlr vc_conn;
746 f_init();
747 vc_conn := f_start_handler(refers(f_tc_paging_response_tmsi_unknown), 59, verify_cell_id := false);
748 vc_conn.done;
749}
750
Neels Hofmeyr13737fb2020-08-19 13:16:14 +0000751
Harald Weltee13cfb22019-04-23 16:52:02 +0200752friend function f_tc_lu_and_mo_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100753 f_init_handler(pars);
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +0200754 var CallParameters cpars := valueof(t_CallParams);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100755 f_perform_lu();
Harald Welteb71901a2018-01-26 19:16:05 +0100756 f_mo_call(cpars);
Harald Welte2bb825f2018-01-22 11:31:18 +0100757}
758testcase TC_lu_and_mo_call() runs on MTC_CT {
759 var BSC_ConnHdlr vc_conn;
760 f_init();
761
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100762 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_call), 7);
Harald Welte071ed732018-01-23 19:53:52 +0100763 vc_conn.done;
764}
Pau Espin Pedrol833174e2020-09-03 16:46:02 +0200765friend function f_tc_lu_and_mo_call_ipv6(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
766 f_init_handler(pars);
767 var CallParameters cpars := valueof(t_CallParams);
768 cpars.mgw_conn_1.mgw_rtp_ip := "::1";
769 cpars.mgw_conn_2.mgw_rtp_ip := "::2";
770 cpars.bss_rtp_ip := "::3";
771 f_perform_lu();
772 f_mo_call(cpars);
773}
774testcase TC_lu_and_mo_call_ipv6() runs on MTC_CT {
775 var BSC_ConnHdlr vc_conn;
776 f_init();
777
778 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_call_ipv6), 7);
779 vc_conn.done;
780}
Harald Welte071ed732018-01-23 19:53:52 +0100781
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100782/* Verify T(iar) triggers and releases the channel */
783friend function f_lu_and_mo_call_sccp_tiar_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
784 timer T_wait_iar := int2float(5 + 1); /* g_msc_sccp_timer_iar + Give extra time (+1 sec) */
785 f_init_handler(pars);
786 var CallParameters cpars := valueof(t_CallParams);
787 f_perform_lu();
788 f_mo_call_establish(cpars);
789
790 /* Expect the channel cleared upon T(iar) triggered: */
791 T_wait_iar.start;
792 alt {
793 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {
794 T_wait_iar.stop
795 setverdict(pass);
796 }
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100797 [] T_wait_iar.timeout {
798 setverdict(fail, "Timeout waiting for T(iar) triggered SCCP RSLD");
799 mtc.stop;
800 }
801 }
Harald Welte4a3fa712020-08-19 08:57:33 +0200802 /* DLCX for both directions; if we don't do this, we might receive either of the two during
803 * shutdown causing race conditions */
804 MGCP.receive(tr_DLCX(?));
805 MGCP.receive(tr_DLCX(?));
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100806
807 setverdict(pass);
808}
809testcase TC_lu_and_mo_call_sccp_tiar_timeout() runs on MTC_CT {
810 var BSC_ConnHdlr vc_conn;
811
812 /* Set T(iar) in MSC low enough that it will trigger before other side
813 has time to keep alive with a T(ias). Keep recommended ratio of
814 T(iar) >= T(ias)*2 */
815 g_msc_sccp_timer_ias := 2;
816 g_msc_sccp_timer_iar := 5;
817
818 f_init();
819
820 vc_conn := f_start_handler(refers(f_lu_and_mo_call_sccp_tiar_timeout), 89);
821 vc_conn.done;
822}
823
Harald Weltee13cfb22019-04-23 16:52:02 +0200824
Harald Welte071ed732018-01-23 19:53:52 +0100825/* Test LU (with authentication enabled), where HLR times out sending SAI response */
Harald Weltee13cfb22019-04-23 16:52:02 +0200826friend function f_tc_lu_auth_sai_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100827 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100828
829 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
830 var PDU_DTAP_MT dtap_mt;
831
832 /* tell GSUP dispatcher to send this IMSI to us */
833 f_create_gsup_expect(hex2str(g_pars.imsi));
834
835 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200836 f_cl3_or_initial_ue(l3_lu);
Harald Welte071ed732018-01-23 19:53:52 +0100837
838 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200839 if (pars.ran_is_geran) {
840 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
841 }
Harald Welte071ed732018-01-23 19:53:52 +0100842
843 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
844 /* The HLR would normally return an auth vector here, but we fail to do so. */
845
846 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100847 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100848}
849testcase TC_lu_auth_sai_timeout() runs on MTC_CT {
850 var BSC_ConnHdlr vc_conn;
851 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100852 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100853
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200854 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_timeout), 8, verify_cell_id := false);
Harald Welte071ed732018-01-23 19:53:52 +0100855 vc_conn.done;
856}
857
Harald Weltee13cfb22019-04-23 16:52:02 +0200858
Harald Welte071ed732018-01-23 19:53:52 +0100859/* Test LU (with authentication enabled), where HLR rejects sending SAI error */
Harald Weltee13cfb22019-04-23 16:52:02 +0200860friend function f_tc_lu_auth_sai_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100861 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100862
863 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
864 var PDU_DTAP_MT dtap_mt;
865
866 /* tell GSUP dispatcher to send this IMSI to us */
867 f_create_gsup_expect(hex2str(g_pars.imsi));
868
869 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200870 f_cl3_or_initial_ue(l3_lu);
Harald Welte071ed732018-01-23 19:53:52 +0100871
872 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200873 if (pars.ran_is_geran) {
874 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
875 }
Harald Welte071ed732018-01-23 19:53:52 +0100876
877 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
878 GSUP.send(ts_GSUP_SAI_ERR(g_pars.imsi, 13));
879
880 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100881 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100882}
883testcase TC_lu_auth_sai_err() runs on MTC_CT {
884 var BSC_ConnHdlr vc_conn;
885 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100886 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100887
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200888 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_err), 9, verify_cell_id := false);
Harald Welte2bb825f2018-01-22 11:31:18 +0100889 vc_conn.done;
890}
Harald Weltea49e36e2018-01-21 19:29:33 +0100891
Harald Weltee13cfb22019-04-23 16:52:02 +0200892
Harald Weltebc881782018-01-23 20:09:15 +0100893/* Test LU but BSC will send a clear request in the middle */
894private function f_tc_lu_clear_request(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100895 f_init_handler(pars);
Harald Weltebc881782018-01-23 20:09:15 +0100896
897 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
898 var PDU_DTAP_MT dtap_mt;
899
900 /* tell GSUP dispatcher to send this IMSI to us */
901 f_create_gsup_expect(hex2str(g_pars.imsi));
902
903 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200904 f_cl3_or_initial_ue(l3_lu);
Harald Welte79f1e452020-08-18 22:55:02 +0200905 f_expect_common_id();
Harald Weltebc881782018-01-23 20:09:15 +0100906
907 /* Send Early Classmark, just for the fun of it */
908 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
909
910 f_sleep(1.0);
911 /* send clear request in the middle of the LU */
912 BSSAP.send(ts_BSSMAP_ClearRequest(0));
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200913 alt {
914 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { repeat; }
915 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {}
916 }
Harald Weltebc881782018-01-23 20:09:15 +0100917 BSSAP.send(ts_BSSMAP_ClearComplete);
Harald Welte89a32492018-01-27 19:07:28 +0100918 alt {
919 /* See https://osmocom.org/issues/2862 */
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200920 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {
921 setverdict(fail, "Got a second Clear Command, only one expected");
Daniel Willmannafce8662018-07-06 23:11:32 +0200922 mtc.stop;
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200923 repeat;
924 }
Harald Welte6811d102019-04-14 22:23:14 +0200925 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte89a32492018-01-27 19:07:28 +0100926 }
Harald Weltebc881782018-01-23 20:09:15 +0100927 setverdict(pass);
928}
929testcase TC_lu_clear_request() runs on MTC_CT {
930 var BSC_ConnHdlr vc_conn;
931 f_init();
932
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100933 vc_conn := f_start_handler(refers(f_tc_lu_clear_request), 10);
Harald Weltebc881782018-01-23 20:09:15 +0100934 vc_conn.done;
935}
936
Vadim Yanitskiy109e7552021-02-05 05:36:02 +0100937/* Test reaction on Clear Request during a MO Call */
938friend function f_TC_mo_mt_call_clear_request(charstring id, BSC_ConnHdlrPars pars)
939runs on BSC_ConnHdlr {
940 var CallParameters cpars := valueof(t_CallParams);
941 var MNCC_PDU mncc_pdu;
942 timer T := 2.0;
943
944 f_init_handler(pars);
945
946 f_perform_lu();
947
948 /* HACK: reducing code duplication ('66'H - MO, '68'H - MT) */
949 if (pars.imsi == '262420002532766'H)
950 { f_mo_call_establish(cpars); }
951 else
952 { f_mt_call_establish(cpars); }
953
954 /* Hold the line for a while... */
955 f_sleep(2.0);
956
957 /* BSC sends BSSMAP Clear Request (e.g. due to RR failure) */
958 BSSAP.send(ts_BSSMAP_ClearRequest(1));
959
960 /* Expect (optional) CC RELEASE and Clear Command */
961 var default ccrel := activate(as_optional_cc_rel(cpars));
962 f_expect_clear();
963 deactivate(ccrel);
964
965 /* Expect RELease indication on the MNCC socket */
966 T.start;
967 alt {
968 [] MNCC.receive(tr_MNCC_REL_ind(cpars.mncc_callref)) -> value mncc_pdu {
969 log("Rx MNCC REL.ind, cause := ", mncc_pdu.u.signal.cause);
970 setverdict(pass);
971 }
972 [] MNCC.receive(MNCC_PDU:?) -> value mncc_pdu {
973 setverdict(fail, "Rx unexpected MNCC PDU: ", mncc_pdu);
974 }
975 [] T.timeout {
976 setverdict(fail, "Timeout waiting for MNCC REL.ind");
977 }
978 }
979}
980testcase TC_mo_call_clear_request() runs on MTC_CT {
981 var BSC_ConnHdlr vc_conn;
982
983 f_init();
984
985 vc_conn := f_start_handler(refers(f_TC_mo_mt_call_clear_request), 2532766); // '66'H - MO
986 vc_conn.done;
987}
988testcase TC_mt_call_clear_request() runs on MTC_CT {
989 var BSC_ConnHdlr vc_conn;
990
991 f_init();
992
993 vc_conn := f_start_handler(refers(f_TC_mo_mt_call_clear_request), 2532768); // '68'H - MT
994 vc_conn.done;
995}
996
Harald Welte66af9e62018-01-24 17:28:21 +0100997/* Test LU but BSC will send a clear request in the middle */
Harald Weltee13cfb22019-04-23 16:52:02 +0200998friend function f_tc_lu_disconnect(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100999 f_init_handler(pars);
Harald Welte66af9e62018-01-24 17:28:21 +01001000
1001 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
1002 var PDU_DTAP_MT dtap_mt;
1003
1004 /* tell GSUP dispatcher to send this IMSI to us */
1005 f_create_gsup_expect(hex2str(g_pars.imsi));
1006
1007 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001008 f_cl3_or_initial_ue(l3_lu);
Harald Welte66af9e62018-01-24 17:28:21 +01001009
1010 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +02001011 if (pars.ran_is_geran) {
1012 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1013 }
Harald Welte66af9e62018-01-24 17:28:21 +01001014
1015 f_sleep(1.0);
1016 /* send clear request in the middle of the LU */
Harald Welte6811d102019-04-14 22:23:14 +02001017 BSSAP.send(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_REQ);
Harald Welte66af9e62018-01-24 17:28:21 +01001018 setverdict(pass);
Neels Hofmeyrbb825c92019-03-06 15:35:50 +01001019 f_sleep(1.0);
Harald Welte66af9e62018-01-24 17:28:21 +01001020}
1021testcase TC_lu_disconnect() runs on MTC_CT {
1022 var BSC_ConnHdlr vc_conn;
1023 f_init();
1024
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001025 vc_conn := f_start_handler(refers(f_tc_lu_disconnect), 11);
Harald Welte66af9e62018-01-24 17:28:21 +01001026 vc_conn.done;
1027}
1028
Harald Welteba7b6d92018-01-23 21:32:34 +01001029/* Test LU but with illegal mobile identity type = IMEI */
Harald Weltee13cfb22019-04-23 16:52:02 +02001030friend function f_tc_lu_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001031 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +01001032
Harald Welte256571e2018-01-24 18:47:19 +01001033 var PDU_ML3_MS_NW l3_lu := f_build_lu_imei(g_pars.imei)
Harald Welteba7b6d92018-01-23 21:32:34 +01001034 var PDU_DTAP_MT dtap_mt;
1035
1036 /* tell GSUP dispatcher to send this IMSI to us */
1037 f_create_gsup_expect(hex2str(g_pars.imsi));
1038
1039 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001040 f_cl3_or_initial_ue(l3_lu);
Harald Welteba7b6d92018-01-23 21:32:34 +01001041
1042 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +02001043 if (pars.ran_is_geran) {
1044 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1045 }
Harald Welteba7b6d92018-01-23 21:32:34 +01001046 /* wait for LU reject, ignore any ID REQ */
1047 alt {
1048 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { }
1049 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req)) { repeat; }
1050 }
1051 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001052 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +01001053}
1054testcase TC_lu_by_imei() runs on MTC_CT {
1055 var BSC_ConnHdlr vc_conn;
1056 f_init();
1057
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001058 vc_conn := f_start_handler(refers(f_tc_lu_by_imei), 12, verify_cell_id := false);
Harald Welteba7b6d92018-01-23 21:32:34 +01001059 vc_conn.done;
1060}
1061
Harald Weltee13cfb22019-04-23 16:52:02 +02001062
Harald Welteba7b6d92018-01-23 21:32:34 +01001063/* Test LU by TMSI with unknown TMSI, expect (and answer) ID REQ. */
1064private function f_tc_lu_tmsi_noauth_unknown(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Stefan Sperling04fc4bc2018-06-25 17:44:57 +02001065 /* We piggyback a test for an MSC crash on overlong IMSI (OS#2864) onto this test. */
1066 var hexstring overlong_imsi := '012345789ABCDEF0123456789ABCDEF'H;
Harald Weltea10db902018-01-27 12:44:49 +01001067 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +01001068
1069 var PDU_ML3_MS_NW l3_lu := f_build_lu_tmsi('01020304'O); /* FIXME: Random */
1070 var PDU_DTAP_MT dtap_mt;
1071
1072 /* tell GSUP dispatcher to send this IMSI to us */
1073 f_create_gsup_expect(hex2str(g_pars.imsi));
1074
1075 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001076 f_cl3_or_initial_ue(l3_lu);
Harald Welteba7b6d92018-01-23 21:32:34 +01001077
1078 /* Send Early Classmark, just for the fun of it */
1079 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1080
1081 /* Wait for + respond to ID REQ (IMSI) */
Oliver Smith32898452019-07-09 12:32:35 +02001082 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
Stefan Sperling04fc4bc2018-06-25 17:44:57 +02001083 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(overlong_imsi))); /* test for OS#2864 */
Harald Welteba7b6d92018-01-23 21:32:34 +01001084 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(g_pars.imsi)));
Harald Welte79f1e452020-08-18 22:55:02 +02001085 f_expect_common_id();
Harald Welteba7b6d92018-01-23 21:32:34 +01001086
1087 /* Expect MSC to do UpdateLocation to HLR; respond to it */
1088 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
1089 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
1090 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
1091 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
1092
1093 alt {
Harald Welte7ec4fa82018-01-27 10:57:40 +01001094 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
1095 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_TmsiRealloc_Cmpl));
1096 }
Harald Welteba7b6d92018-01-23 21:32:34 +01001097 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1098 setverdict(fail, "Expected LU ACK, but received REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +02001099 mtc.stop;
Harald Welteba7b6d92018-01-23 21:32:34 +01001100 }
1101 }
1102
Philipp Maier9b690e42018-12-21 11:50:03 +01001103 /* Wait for MM-Information (if enabled) */
1104 f_expect_mm_info();
1105
Harald Welteba7b6d92018-01-23 21:32:34 +01001106 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001107 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +01001108}
1109testcase TC_lu_by_tmsi_noauth_unknown() runs on MTC_CT {
1110 var BSC_ConnHdlr vc_conn;
1111 f_init();
1112
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001113 vc_conn := f_start_handler(refers(f_tc_lu_tmsi_noauth_unknown), 13);
Harald Welteba7b6d92018-01-23 21:32:34 +01001114 vc_conn.done;
1115}
1116
Neels Hofmeyrfc06c732020-08-19 12:52:28 +00001117/* Test LU by unknown TMSI, while the IMSI is already attached: osmo-msc should switch to the attached vlr_subscr. */
1118private function f_tc_attached_imsi_lu_unknown_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1119 f_init_handler(pars);
1120
1121 var PDU_ML3_MS_NW l3_lu := f_build_lu_tmsi('56111111'O);
1122 var PDU_DTAP_MT dtap_mt;
1123
1124 /* tell GSUP dispatcher to send this IMSI to us */
1125 f_create_gsup_expect(hex2str(g_pars.imsi));
1126
1127 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
1128 f_cl3_or_initial_ue(l3_lu);
1129
1130 /* Send Early Classmark, just for the fun of it */
1131 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1132
1133 /* Wait for + respond to ID REQ (IMSI) */
1134 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
1135 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(g_pars.imsi)));
1136 f_expect_common_id();
1137
1138 /* Expect MSC to do UpdateLocation to HLR; respond to it */
1139 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
1140 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
1141 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
1142 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
1143
1144 alt {
1145 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
1146 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_TmsiRealloc_Cmpl));
1147 }
1148 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1149 setverdict(fail, "Expected LU ACK, but received REJ");
1150 mtc.stop;
1151 }
1152 }
1153
1154 /* Wait for MM-Information (if enabled) */
1155 f_expect_mm_info();
1156
1157 /* wait for normal teardown */
1158 f_expect_clear();
1159
1160 /* Now the same IMSI is still attached in the VLR, and a LU with an unknown TMSI reveals the same IMSI only
1161 * later during ID Response. osmo-msc first creates a new vlr_subscr for the unknown TMSI, and as soon as the
1162 * IMSI becomes known, must notice that this IMSI is still regarded as attached, and must not create evil twins.
1163 */
1164
1165 /* (since the TMSI Reallocation happened, we could do this with exactly the same TMSI as above, but for test
1166 * readability just use a different one.) */
1167 l3_lu := f_build_lu_tmsi('56222222'O);
1168 f_cl3_or_initial_ue(l3_lu);
1169
1170 /* Wait for + respond to ID REQ (IMSI) */
1171 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
1172 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(g_pars.imsi)));
1173 f_expect_common_id();
1174
1175 /* Expect MSC to do UpdateLocation to HLR; respond to it */
1176 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
1177 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
1178 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
1179 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
1180
1181 alt {
1182 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
1183 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_TmsiRealloc_Cmpl));
1184 }
1185 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1186 setverdict(fail, "Expected LU ACK, but received REJ");
1187 mtc.stop;
1188 }
1189 }
1190
1191 /* Wait for MM-Information (if enabled) */
1192 f_expect_mm_info();
1193
1194 /* wait for normal teardown */
1195 f_expect_clear();
1196}
1197testcase TC_attached_imsi_lu_unknown_tmsi() runs on MTC_CT {
1198 var BSC_ConnHdlr vc_conn;
1199 f_init();
1200
1201 vc_conn := f_start_handler(refers(f_tc_attached_imsi_lu_unknown_tmsi), 56);
1202 vc_conn.done;
1203}
1204
Harald Welte4d15fa72020-08-19 08:58:28 +02001205friend function f_imsi_detach_by_imsi() runs on BSC_ConnHdlr {
Harald Welte45164da2018-01-24 12:51:27 +01001206 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1207
1208 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001209 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +01001210
1211 /* Send Early Classmark, just for the fun of it? */
Harald Welte4d15fa72020-08-19 08:58:28 +02001212 if (g_pars.ran_is_geran) {
Harald Weltee13cfb22019-04-23 16:52:02 +02001213 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1214 }
Harald Welte45164da2018-01-24 12:51:27 +01001215
1216 /* wait for normal teardown */
Harald Welte4d15fa72020-08-19 08:58:28 +02001217 f_expect_clear(verify_vlr_cell_id := false);
1218}
1219
1220
1221/* Test IMSI DETACH (MI=IMSI) */
1222friend function f_tc_imsi_detach_by_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1223 f_init_handler(pars);
1224
1225 f_imsi_detach_by_imsi();
Harald Welte45164da2018-01-24 12:51:27 +01001226}
1227testcase TC_imsi_detach_by_imsi() runs on MTC_CT {
1228 var BSC_ConnHdlr vc_conn;
1229 f_init();
1230
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001231 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imsi), 14, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001232 vc_conn.done;
1233}
1234
Harald Weltee13cfb22019-04-23 16:52:02 +02001235
Harald Welte45164da2018-01-24 12:51:27 +01001236/* Test IMSI DETACH (MI=TMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +02001237friend function f_tc_imsi_detach_by_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001238 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001239
1240 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV('01020304'O));
1241
1242 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001243 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +01001244
1245 /* Send Early Classmark, just for the fun of it? */
Harald Weltee13cfb22019-04-23 16:52:02 +02001246 if (pars.ran_is_geran) {
1247 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1248 }
Harald Welte45164da2018-01-24 12:51:27 +01001249
1250 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001251 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001252}
1253testcase TC_imsi_detach_by_tmsi() runs on MTC_CT {
1254 var BSC_ConnHdlr vc_conn;
1255 f_init();
1256
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001257 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_tmsi), 15, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001258 vc_conn.done;
1259}
1260
Harald Weltee13cfb22019-04-23 16:52:02 +02001261
Harald Welte45164da2018-01-24 12:51:27 +01001262/* Test IMSI DETACH (MI=IMEI), which is illegal */
Harald Weltee13cfb22019-04-23 16:52:02 +02001263friend function f_tc_imsi_detach_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001264 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001265
Harald Welte256571e2018-01-24 18:47:19 +01001266 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte45164da2018-01-24 12:51:27 +01001267
1268 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001269 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +01001270
1271 /* Send Early Classmark, just for the fun of it? */
Harald Weltee13cfb22019-04-23 16:52:02 +02001272 if (pars.ran_is_geran) {
1273 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1274 }
Harald Welte45164da2018-01-24 12:51:27 +01001275
1276 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001277 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001278}
1279testcase TC_imsi_detach_by_imei() runs on MTC_CT {
1280 var BSC_ConnHdlr vc_conn;
1281 f_init();
1282
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001283 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imei), 16, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001284 vc_conn.done;
1285}
1286
1287
1288/* helper function for an emergency call. caller passes in mobile identity to use */
1289private function f_emerg_call(MobileIdentityLV mi) runs on BSC_ConnHdlr {
Harald Welte0bef21e2018-02-10 09:48:23 +01001290 var CallParameters cpars := valueof(t_CallParams('112'H, 0));
1291 cpars.emergency := true;
Harald Welte45164da2018-01-24 12:51:27 +01001292
Harald Welte0bef21e2018-02-10 09:48:23 +01001293 f_mo_call(cpars);
Harald Welte45164da2018-01-24 12:51:27 +01001294}
1295
1296/* establish an emergency call by IMEI, no SIM inserted (and hence no IMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +02001297friend function f_tc_emerg_call_imei_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001298 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001299
Harald Welte256571e2018-01-24 18:47:19 +01001300 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001301 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_EMERG_CALL, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001302 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001303 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ('05'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +01001304 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001305}
1306testcase TC_emerg_call_imei_reject() runs on MTC_CT {
1307 var BSC_ConnHdlr vc_conn;
1308 f_init();
1309
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001310 vc_conn := f_start_handler(refers(f_tc_emerg_call_imei_reject), 17, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001311 vc_conn.done;
1312}
1313
Harald Weltee13cfb22019-04-23 16:52:02 +02001314
Harald Welted5b91402018-01-24 18:48:16 +01001315/* establish an emergency call by IMSI, SIM inserted (and hence IMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +02001316friend function f_tc_emerg_call_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001317 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001318 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001319 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001320 /* Then issue emergency call identified by IMSI */
1321 f_emerg_call(valueof(ts_MI_IMSI_LV(g_pars.imsi)));
1322}
1323testcase TC_emerg_call_imsi() runs on MTC_CT {
1324 var BSC_ConnHdlr vc_conn;
1325 f_init();
1326
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001327 vc_conn := f_start_handler(refers(f_tc_emerg_call_imsi), 18);
Harald Welte45164da2018-01-24 12:51:27 +01001328 vc_conn.done;
1329}
1330
Harald Weltee13cfb22019-04-23 16:52:02 +02001331
Harald Welte45164da2018-01-24 12:51:27 +01001332/* CM Service Request for VGCS -> reject */
1333private function f_tc_cm_serv_req_vgcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001334 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001335
1336 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001337 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001338
1339 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001340 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VGCS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001341 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001342 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001343 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001344}
1345testcase TC_cm_serv_req_vgcs_reject() runs on MTC_CT {
1346 var BSC_ConnHdlr vc_conn;
1347 f_init();
1348
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001349 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vgcs_reject), 19);
Harald Welte45164da2018-01-24 12:51:27 +01001350 vc_conn.done;
1351}
1352
1353/* CM Service Request for VBS -> reject */
1354private function f_tc_cm_serv_req_vbs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001355 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001356
1357 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001358 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001359
1360 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001361 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VBS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001362 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001363 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001364 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001365}
1366testcase TC_cm_serv_req_vbs_reject() runs on MTC_CT {
1367 var BSC_ConnHdlr vc_conn;
1368 f_init();
1369
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001370 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vbs_reject), 20);
Harald Welte45164da2018-01-24 12:51:27 +01001371 vc_conn.done;
1372}
1373
1374/* CM Service Request for LCS -> reject */
1375private function f_tc_cm_serv_req_lcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001376 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001377
1378 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001379 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001380
1381 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001382 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_LCS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001383 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001384 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001385 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001386}
1387testcase TC_cm_serv_req_lcs_reject() runs on MTC_CT {
1388 var BSC_ConnHdlr vc_conn;
1389 f_init();
1390
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001391 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_lcs_reject), 21);
Harald Welte45164da2018-01-24 12:51:27 +01001392 vc_conn.done;
1393}
1394
Harald Welte0195ab12018-01-24 21:50:20 +01001395/* CM Re-Establishment Request */
1396private function f_tc_cm_reest_req_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001397 f_init_handler(pars);
Harald Welte0195ab12018-01-24 21:50:20 +01001398
1399 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001400 f_perform_lu();
Harald Welte0195ab12018-01-24 21:50:20 +01001401
1402 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1403 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_REEST_REQ(0, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001404 f_cl3_or_initial_ue(l3_info);
Harald Welte0195ab12018-01-24 21:50:20 +01001405 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001406 f_expect_clear();
Harald Welte0195ab12018-01-24 21:50:20 +01001407}
1408testcase TC_cm_reest_req_reject() runs on MTC_CT {
1409 var BSC_ConnHdlr vc_conn;
1410 f_init();
Harald Welte0195ab12018-01-24 21:50:20 +01001411
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001412 vc_conn := f_start_handler(refers(f_tc_cm_reest_req_reject), 22);
Harald Welte0195ab12018-01-24 21:50:20 +01001413 vc_conn.done;
1414}
1415
Harald Weltec638f4d2018-01-24 22:00:36 +01001416/* Test LU (with authentication enabled), with wrong response from MS */
1417private function f_tc_lu_auth_2G_fail(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001418 f_init_handler(pars);
Harald Weltec638f4d2018-01-24 22:00:36 +01001419
1420 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
1421
1422 /* tell GSUP dispatcher to send this IMSI to us */
1423 f_create_gsup_expect(hex2str(g_pars.imsi));
1424
1425 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001426 f_cl3_or_initial_ue(l3_lu);
Harald Weltec638f4d2018-01-24 22:00:36 +01001427
1428 /* Send Early Classmark, just for the fun of it */
1429 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1430
1431 var AuthVector vec := f_gen_auth_vec_2g();
1432 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G(vec.rand, vec.sres, vec.kc));
1433 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
1434 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
1435
1436 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_AUTH_REQ(vec.rand)));
1437 /* Send back wrong auth response */
1438 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MT_MM_AUTH_RESP_2G('00000000'O)));
1439
1440 /* Expect GSUP AUTH FAIL REP to HLR */
1441 GSUP.receive(tr_GSUP_AUTH_FAIL_IND(g_pars.imsi));
1442
1443 /* Expect LU REJECT with Cause == Illegal MS */
1444 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej('03'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +01001445 f_expect_clear();
Harald Weltec638f4d2018-01-24 22:00:36 +01001446}
1447testcase TC_lu_auth_2G_fail() runs on MTC_CT {
1448 var BSC_ConnHdlr vc_conn;
1449 f_init();
1450 f_vty_config(MSCVTY, "network", "authentication required");
Harald Weltec638f4d2018-01-24 22:00:36 +01001451
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001452 vc_conn := f_start_handler(refers(f_tc_lu_auth_2G_fail), 23, verify_cell_id := false);
Harald Weltec638f4d2018-01-24 22:00:36 +01001453 vc_conn.done;
1454}
1455
Harald Weltede371492018-01-27 23:44:41 +01001456/* A5/1 + A5/3 permitted on network side, and MS capable to do it */
Harald Welte16114282018-01-24 22:41:21 +01001457private function f_tc_lu_imsi_auth_tmsi_encr_13_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +01001458 pars.net.expect_auth := true;
1459 pars.net.expect_ciph := true;
Harald Weltea10db902018-01-27 12:44:49 +01001460 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001461 f_perform_lu();
Harald Welte16114282018-01-24 22:41:21 +01001462}
1463testcase TC_lu_imsi_auth_tmsi_encr_13_13() runs on MTC_CT {
1464 var BSC_ConnHdlr vc_conn;
1465 f_init();
1466 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte16114282018-01-24 22:41:21 +01001467 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
1468
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001469 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_13), 24);
Harald Welte16114282018-01-24 22:41:21 +01001470 vc_conn.done;
1471}
1472
Harald Welte1af6ea82018-01-25 18:33:15 +01001473/* Test Complete L3 without payload */
1474private function f_tc_cl3_no_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001475 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001476
1477 /* Send Complete L3 Info with empty L3 frame */
1478 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1479 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, ''O))));
1480
Harald Weltef466eb42018-01-27 14:26:54 +01001481 timer T := 5.0;
1482 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001483 alt {
Harald Welte6811d102019-04-14 22:23:14 +02001484 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte1af6ea82018-01-25 18:33:15 +01001485 /* Expect LU REJECT with Cause == Illegal MS */
Harald Weltebdb3c452018-03-18 22:43:06 +01001486 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
Harald Welte6811d102019-04-14 22:23:14 +02001487 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001488 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001489 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001490 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001491 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001492 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001493 }
1494 setverdict(pass);
1495}
1496testcase TC_cl3_no_payload() runs on MTC_CT {
1497 var BSC_ConnHdlr vc_conn;
1498 f_init();
1499
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001500 vc_conn := f_start_handler(refers(f_tc_cl3_no_payload), 25);
Harald Welte1af6ea82018-01-25 18:33:15 +01001501 vc_conn.done;
1502}
1503
1504/* Test Complete L3 with random payload */
1505private function f_tc_cl3_rnd_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001506 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001507
Daniel Willmannaa14a382018-07-26 08:29:45 +02001508 /* length is limited by PDU_BSSAP length field which includes some
1509 * other fields beside l3info payload. So payl can only be 240 bytes
1510 * Since rnd() returns values < 1 multiply with 241
1511 */
1512 var integer len := float2int(rnd() * 241.0);
Harald Welte1af6ea82018-01-25 18:33:15 +01001513 var octetstring payl := f_rnd_octstring(len);
1514
1515 /* Send Complete L3 Info with empty L3 frame */
1516 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1517 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, payl))));
1518
Harald Weltef466eb42018-01-27 14:26:54 +01001519 timer T := 5.0;
1520 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001521 alt {
1522 /* Immediate disconnect */
Harald Welte6811d102019-04-14 22:23:14 +02001523 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte1af6ea82018-01-25 18:33:15 +01001524 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
Harald Welte6811d102019-04-14 22:23:14 +02001525 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001526 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001527 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001528 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001529 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001530 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001531 }
1532 setverdict(pass);
1533}
1534testcase TC_cl3_rnd_payload() runs on MTC_CT {
1535 var BSC_ConnHdlr vc_conn;
1536 f_init();
1537
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001538 vc_conn := f_start_handler(refers(f_tc_cl3_rnd_payload), 26);
Harald Welte1af6ea82018-01-25 18:33:15 +01001539 vc_conn.done;
1540}
1541
Harald Welte116e4332018-01-26 22:17:48 +01001542/* Test Complete L3 with random payload */
Harald Weltee13cfb22019-04-23 16:52:02 +02001543friend function f_tc_establish_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001544 f_init_handler(pars);
Harald Welte116e4332018-01-26 22:17:48 +01001545
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001546 f_perform_lu();
Harald Welte116e4332018-01-26 22:17:48 +01001547
Harald Welteb9e86fa2018-04-09 18:18:31 +02001548 f_establish_fully();
Daniel Willmann898a7e02018-05-17 12:16:16 +02001549 f_expect_clear(10.0);
Harald Welte116e4332018-01-26 22:17:48 +01001550}
1551testcase TC_establish_and_nothing() runs on MTC_CT {
1552 var BSC_ConnHdlr vc_conn;
1553 f_init();
1554
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001555 vc_conn := f_start_handler(refers(f_tc_establish_and_nothing), 27);
Harald Welte116e4332018-01-26 22:17:48 +01001556 vc_conn.done;
1557}
1558
Harald Weltee13cfb22019-04-23 16:52:02 +02001559
Harald Welte12510c52018-01-26 22:26:24 +01001560/* Test MO Call SETUP with no response from MNCC */
Harald Weltee13cfb22019-04-23 16:52:02 +02001561friend function f_tc_mo_setup_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier109e6aa2018-10-17 10:53:32 +02001562 f_init_handler(pars, 190.0);
Harald Weltea10db902018-01-27 12:44:49 +01001563
Harald Welte12510c52018-01-26 22:26:24 +01001564 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001565 cpars.mgw_conn_2.resp := 0;
1566 cpars.stop_after_cc_setup := true;
1567
1568 f_vty_config(MSCVTY, "msc", "mncc guard-timeout 20");
Harald Welte12510c52018-01-26 22:26:24 +01001569
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001570 f_perform_lu();
Harald Welte12510c52018-01-26 22:26:24 +01001571
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001572 f_mo_call_establish(cpars);
Harald Welte12510c52018-01-26 22:26:24 +01001573
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001574 var default ccrel := activate(as_optional_cc_rel(cpars));
1575
Philipp Maier109e6aa2018-10-17 10:53:32 +02001576 f_expect_clear(185.0);
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001577
1578 deactivate(ccrel);
1579
1580 f_sleep(1.0);
Harald Welte12510c52018-01-26 22:26:24 +01001581}
1582testcase TC_mo_setup_and_nothing() runs on MTC_CT {
1583 var BSC_ConnHdlr vc_conn;
1584 f_init();
1585
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001586 vc_conn := f_start_handler(refers(f_tc_mo_setup_and_nothing), 28);
Harald Welte12510c52018-01-26 22:26:24 +01001587 vc_conn.done;
1588}
1589
Harald Weltee13cfb22019-04-23 16:52:02 +02001590
Harald Welte3ab88002018-01-26 22:37:25 +01001591/* Test MO Call with no response to RAN-side CRCX */
Harald Weltee13cfb22019-04-23 16:52:02 +02001592friend function f_tc_mo_crcx_ran_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001593 f_init_handler(pars);
Harald Welte3ab88002018-01-26 22:37:25 +01001594 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1595 var MNCC_PDU mncc;
1596 var MgcpCommand mgcp_cmd;
1597
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001598 f_perform_lu();
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001599 /* Do not respond to the second CRCX */
1600 cpars.mgw_conn_2.resp := 0;
1601 f_mo_call_establish(cpars);
Harald Welte3ab88002018-01-26 22:37:25 +01001602
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001603 var default ccrel := activate(as_optional_cc_rel(cpars));
Harald Welte3ab88002018-01-26 22:37:25 +01001604
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001605 f_expect_clear(60.0);
Harald Welte3ab88002018-01-26 22:37:25 +01001606
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001607 deactivate(ccrel);
Harald Welte3ab88002018-01-26 22:37:25 +01001608}
1609testcase TC_mo_crcx_ran_timeout() runs on MTC_CT {
1610 var BSC_ConnHdlr vc_conn;
1611 f_init();
1612
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001613 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_timeout), 29);
Harald Welte3ab88002018-01-26 22:37:25 +01001614 vc_conn.done;
1615}
1616
Harald Weltee13cfb22019-04-23 16:52:02 +02001617
Harald Welte0cc82d92018-01-26 22:52:34 +01001618/* Test MO Call with reject to RAN-side CRCX */
Harald Weltee13cfb22019-04-23 16:52:02 +02001619friend function f_tc_mo_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001620 f_init_handler(pars);
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001621
Harald Welte0cc82d92018-01-26 22:52:34 +01001622 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001623
1624 /* Respond with error for the first CRCX */
1625 cpars.mgw_conn_1.resp := -1;
Harald Welte0cc82d92018-01-26 22:52:34 +01001626
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001627 f_perform_lu();
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001628 f_mo_call_establish(cpars);
Harald Welte0cc82d92018-01-26 22:52:34 +01001629
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001630 var default ccrel := activate(as_optional_cc_rel(cpars));
1631 f_expect_clear(60.0);
1632 deactivate(ccrel);
Harald Welte0cc82d92018-01-26 22:52:34 +01001633}
1634testcase TC_mo_crcx_ran_reject() runs on MTC_CT {
1635 var BSC_ConnHdlr vc_conn;
1636 f_init();
1637
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001638 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_reject), 30);
Harald Welte0cc82d92018-01-26 22:52:34 +01001639 vc_conn.done;
1640}
1641
Harald Welte3ab88002018-01-26 22:37:25 +01001642
Harald Welte812f7a42018-01-27 00:49:18 +01001643/* helper function to start a MT call: MNCC SETUP; Paging; DChan est.; DTAP SETUP */
1644private function f_mt_call_start(inout CallParameters cpars) runs on BSC_ConnHdlr {
1645 var MNCC_PDU mncc;
1646 var MgcpCommand mgcp_cmd;
Harald Welte812f7a42018-01-27 00:49:18 +01001647
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001648 f_perform_lu();
Vadim Yanitskiyae747742020-01-10 00:23:10 +01001649 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Welte812f7a42018-01-27 00:49:18 +01001650
1651 /* Allocate call reference and send SETUP via MNCC to MSC */
1652 cpars.mncc_callref := f_rnd_int(2147483648);
1653 MNCC.send(ts_MNCC_SETUP_req(cpars.mncc_callref, hex2str(g_pars.msisdn),
1654 hex2str(cpars.called_party), hex2str(g_pars.imsi)));
1655
1656 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02001657 f_expect_paging();
1658
Harald Welte812f7a42018-01-27 00:49:18 +01001659 /* MS -> MSC: PAGING RESPONSE */
Harald Welteb9e86fa2018-04-09 18:18:31 +02001660 f_establish_fully(EST_TYPE_PAG_RESP);
Harald Welte812f7a42018-01-27 00:49:18 +01001661
1662 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1663
1664 /* MSC->MS: SETUP */
1665 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_SETUP(cpars.transaction_id, *, cpars.called_party)));
1666}
1667
1668/* Test MT Call */
Harald Weltee13cfb22019-04-23 16:52:02 +02001669friend function f_tc_mt_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001670 f_init_handler(pars);
Harald Welte812f7a42018-01-27 00:49:18 +01001671 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1672 var MNCC_PDU mncc;
1673 var MgcpCommand mgcp_cmd;
1674
1675 f_mt_call_start(cpars);
1676
1677 /* MS->MSC: CALL CONFIRMED */
1678 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1679
1680 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1681
1682 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1683 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001684
1685 /* Detect if the received CRCX is a wildcarded CRCX request. If yes,
1686 * set an endpoint name that fits the pattern. If not, just use the
1687 * endpoint name from the request */
1688 if (match(mgcp_cmd.line.ep, t_MGCP_EP_wildcard)) {
1689 cpars.mgcp_ep := "rtpbridge/1@mgw";
1690 } else {
1691 cpars.mgcp_ep := mgcp_cmd.line.ep;
1692 }
1693
Harald Welte812f7a42018-01-27 00:49:18 +01001694 /* Respond to CRCX with error */
1695 var MgcpResponse mgcp_rsp := {
1696 line := {
1697 code := "542",
1698 trans_id := mgcp_cmd.line.trans_id,
1699 string := "FORCED_FAIL"
1700 },
Harald Welte812f7a42018-01-27 00:49:18 +01001701 sdp := omit
1702 }
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001703 var MgcpParameter mgcp_rsp_param := {
1704 code := "Z",
1705 val := cpars.mgcp_ep
1706 };
1707 mgcp_rsp.params[0] := mgcp_rsp_param;
Harald Welte812f7a42018-01-27 00:49:18 +01001708 MGCP.send(mgcp_rsp);
1709
1710 timer T := 30.0;
1711 T.start;
1712 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001713 [] T.timeout {
1714 setverdict(fail, "Timeout waiting for channel release");
1715 mtc.stop;
1716 }
Harald Welte812f7a42018-01-27 00:49:18 +01001717 [] MNCC.receive { repeat; }
1718 [] GSUP.receive { repeat; }
1719 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1720 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
1721 f_create_mgcp_delete_ep(cpars.mgcp_ep);
1722 repeat;
1723 }
1724 [] MGCP.receive { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001725 [] as_clear_cmd_compl_disc();
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001726 [] as_optional_cc_rel(cpars);
Harald Welte812f7a42018-01-27 00:49:18 +01001727 }
1728}
1729testcase TC_mt_crcx_ran_reject() runs on MTC_CT {
1730 var BSC_ConnHdlr vc_conn;
1731 f_init();
1732
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001733 vc_conn := f_start_handler(refers(f_tc_mt_crcx_ran_reject), 31);
Harald Welte812f7a42018-01-27 00:49:18 +01001734 vc_conn.done;
1735}
1736
1737
Harald Weltee13cfb22019-04-23 16:52:02 +02001738
Harald Welte812f7a42018-01-27 00:49:18 +01001739/* Test MT Call T310 timer */
Harald Weltee13cfb22019-04-23 16:52:02 +02001740friend function f_tc_mt_t310(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte812f7a42018-01-27 00:49:18 +01001741 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
Harald Welte812f7a42018-01-27 00:49:18 +01001742 var MgcpCommand mgcp_cmd;
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001743 var PDU_BSSAP bssap;
1744 timer T310;
Harald Welte812f7a42018-01-27 00:49:18 +01001745
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001746 f_init_handler(pars);
1747
1748 /* Initiate a MT call, establish connection */
Harald Welte812f7a42018-01-27 00:49:18 +01001749 f_mt_call_start(cpars);
1750
1751 /* MS->MSC: CALL CONFIRMED */
1752 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1753 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1754
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001755 /* NOTE: MSC is expected to start T310 here */
Harald Welte812f7a42018-01-27 00:49:18 +01001756
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001757 /* MSC->MGW: CRCX (first) */
1758 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1759 f_handle_crcx(cpars, mgcp_cmd); /* MSC<-MGW: OK */
1760
1761 /* BSC->BSC: BSSMAP ASSIGNMENT REQ */
1762 BSSAP.receive(tr_BSSMAP_AssignmentReq(omit, ?)) -> value bssap;
1763 BSSAP.send(ts_BSSMAP_AssignmentComplete(omit,
1764 aoip := f_ts_BSSMAP_IE_AoIP_TLA(cpars.bss_rtp_ip, cpars.bss_rtp_port),
1765 speechCodec := ts_BSSMAP_IE_SpeechCodec({ ts_CodecFR })));
1766
1767 /* MSC->MGW: MDCX */
1768 MGCP.receive(tr_MDCX) -> value mgcp_cmd;
1769 MGCP.send(ts_MDCX_ACK(mgcp_cmd.line.trans_id, cpars.mgw_conn_1.mgcp_connection_id,
1770 sdp := omit));
1771
1772 /* MSC->MGW: CRCX (second) */
1773 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1774 f_handle_crcx(cpars, mgcp_cmd); /* MSC<-MGW: OK */
1775 MNCC.receive(tr_MNCC_RTP_CREATE(cpars.mncc_callref));
1776
1777 /* Reschedule the guard timeout */
1778 g_Tguard.start(30.0 + 10.0);
1779
1780 /* NOTE: the BSC is expected to respond with CC ALERTING at this state, so
1781 * the MSC would stop T310. However, the idea is to verify T310 expiration
1782 * here, so grab some popcorn and wait for MNCC DISC.ind. */
1783 T310.start(30.0 + 2.0);
Harald Welte812f7a42018-01-27 00:49:18 +01001784 alt {
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001785 [] T310.timeout {
1786 setverdict(fail, "Timeout waiting for MNCC DISC.ind due to T310");
Daniel Willmannafce8662018-07-06 23:11:32 +02001787 mtc.stop;
1788 }
Harald Welte812f7a42018-01-27 00:49:18 +01001789 [] MNCC.receive(tr_MNCC_DISC_ind(cpars.mncc_callref)) {
1790 MNCC.send(ts_MNCC_REL_req(cpars.mncc_callref, valueof(ts_MNCC_cause(23))));
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001791 log("Rx MNCC DISC.ind, T310.read yelds ", T310.read);
1792 setverdict(pass);
Harald Welte812f7a42018-01-27 00:49:18 +01001793 }
1794 }
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001795
Harald Welte812f7a42018-01-27 00:49:18 +01001796 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_DISC(cpars.transaction_id)));
1797 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id)));
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001798 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id, '1'B)));
Harald Welte812f7a42018-01-27 00:49:18 +01001799
1800 alt {
Harald Welte812f7a42018-01-27 00:49:18 +01001801 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1802 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001803 // FIXME: f_create_mgcp_delete_ep(cpars.mgcp_ep);
Harald Welte812f7a42018-01-27 00:49:18 +01001804 repeat;
1805 }
Harald Welte5946b332018-03-18 23:32:21 +01001806 [] as_clear_cmd_compl_disc();
Harald Welte812f7a42018-01-27 00:49:18 +01001807 }
1808}
1809testcase TC_mt_t310() runs on MTC_CT {
1810 var BSC_ConnHdlr vc_conn;
1811 f_init();
1812
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001813 vc_conn := f_start_handler(refers(f_tc_mt_t310), 32);
Harald Welte812f7a42018-01-27 00:49:18 +01001814 vc_conn.done;
1815}
1816
Harald Weltee13cfb22019-04-23 16:52:02 +02001817
Harald Welte167458a2018-01-27 15:58:16 +01001818/* Perform successful LU + MO call, then GSUP LocationCancel. Subscriber must be denied CM SERV */
Harald Weltee13cfb22019-04-23 16:52:02 +02001819friend function f_tc_gsup_cancel(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte167458a2018-01-27 15:58:16 +01001820 f_init_handler(pars);
1821 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Harald Welte167458a2018-01-27 15:58:16 +01001822
1823 /* Location Update to make subscriber known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001824 f_perform_lu();
Harald Welte167458a2018-01-27 15:58:16 +01001825
1826 /* First MO call should succeed */
1827 f_mo_call(cpars);
1828
1829 /* Cancel the subscriber in the VLR */
1830 GSUP.send(ts_GSUP_CL_REQ(g_pars.imsi, OSMO_GSUP_CANCEL_TYPE_WITHDRAW));
1831 alt {
1832 [] GSUP.receive(tr_GSUP_CL_RES(g_pars.imsi)) { }
1833 [] GSUP.receive(tr_GSUP_CL_ERR(g_pars.imsi)) {
1834 setverdict(fail, "Received GSUP Location Cancel Error");
Daniel Willmannafce8662018-07-06 23:11:32 +02001835 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001836 }
1837 }
1838
1839 /* Follow-up transactions should fail */
1840 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1841 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001842 f_cl3_or_initial_ue(l3_info);
Harald Welte167458a2018-01-27 15:58:16 +01001843 alt {
1844 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
1845 [] BSSAP.receive {
1846 setverdict(fail, "Received unexpected BSSAP instead of CM SERV REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +02001847 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001848 }
1849 }
Neels Hofmeyr0f7429a2019-03-07 22:28:41 +01001850
1851 f_expect_clear();
Harald Welte167458a2018-01-27 15:58:16 +01001852 setverdict(pass);
1853}
1854testcase TC_gsup_cancel() runs on MTC_CT {
1855 var BSC_ConnHdlr vc_conn;
1856 f_init();
1857
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001858 vc_conn := f_start_handler(refers(f_tc_gsup_cancel), 33, verify_cell_id := false);
Harald Welte167458a2018-01-27 15:58:16 +01001859 vc_conn.done;
1860}
1861
Harald Weltee13cfb22019-04-23 16:52:02 +02001862
Harald Welte9de84792018-01-28 01:06:35 +01001863/* A5/1 only permitted on network side, and MS capable to do it */
1864private function f_tc_lu_imsi_auth_tmsi_encr_1_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1865 pars.net.expect_auth := true;
1866 pars.net.expect_ciph := true;
1867 pars.net.kc_support := '02'O; /* A5/1 only */
1868 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001869 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001870}
1871testcase TC_lu_imsi_auth_tmsi_encr_1_13() runs on MTC_CT {
1872 var BSC_ConnHdlr vc_conn;
1873 f_init();
1874 f_vty_config(MSCVTY, "network", "authentication required");
1875 f_vty_config(MSCVTY, "network", "encryption a5 1");
1876
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001877 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_1_13), 34);
Harald Welte9de84792018-01-28 01:06:35 +01001878 vc_conn.done;
1879}
1880
1881/* A5/3 only permitted on network side, and MS capable to do it */
1882private function f_tc_lu_imsi_auth_tmsi_encr_3_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1883 pars.net.expect_auth := true;
1884 pars.net.expect_ciph := true;
1885 pars.net.kc_support := '08'O; /* A5/3 only */
1886 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001887 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001888}
1889testcase TC_lu_imsi_auth_tmsi_encr_3_13() runs on MTC_CT {
1890 var BSC_ConnHdlr vc_conn;
1891 f_init();
1892 f_vty_config(MSCVTY, "network", "authentication required");
1893 f_vty_config(MSCVTY, "network", "encryption a5 3");
1894
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001895 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_13), 35);
Harald Welte9de84792018-01-28 01:06:35 +01001896 vc_conn.done;
1897}
1898
1899/* A5/3 only permitted on network side, and MS with only A5/1 support */
1900private function f_tc_lu_imsi_auth_tmsi_encr_3_1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1901 pars.net.expect_auth := true;
1902 pars.net.expect_ciph := true;
1903 pars.net.kc_support := '08'O; /* A5/3 only */
1904 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1905 f_init_handler(pars, 15.0);
1906
1907 /* cannot use f_perform_lu() as we expect a reject */
1908 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
1909 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +02001910 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001911 if (pars.send_early_cm) {
1912 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1913 } else {
1914 pars.cm1.esind := '0'B;
1915 }
Harald Welte9de84792018-01-28 01:06:35 +01001916 f_mm_auth();
1917 alt {
Daniel Willmann52918e52018-09-20 14:39:09 +02001918 [] BSSAP.receive(tr_BSSMAP_ClassmarkReq) {
1919 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1920 repeat;
1921 }
Harald Welte5946b332018-03-18 23:32:21 +01001922 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1923 f_expect_clear();
1924 }
Harald Welte9de84792018-01-28 01:06:35 +01001925 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
1926 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02001927 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001928 }
1929 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01001930 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02001931 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001932 }
1933 }
1934 setverdict(pass);
1935}
1936testcase TC_lu_imsi_auth_tmsi_encr_3_1() runs on MTC_CT {
1937 var BSC_ConnHdlr vc_conn;
1938 f_init();
1939 f_vty_config(MSCVTY, "network", "authentication required");
1940 f_vty_config(MSCVTY, "network", "encryption a5 3");
1941
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001942 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 360, verify_cell_id := false);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001943 vc_conn.done;
1944}
1945testcase TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() runs on MTC_CT {
1946 var BSC_ConnHdlrPars pars;
1947 var BSC_ConnHdlr vc_conn;
1948 f_init();
1949 f_vty_config(MSCVTY, "network", "authentication required");
1950 f_vty_config(MSCVTY, "network", "encryption a5 3");
1951
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001952 pars := f_init_pars(361, verify_cell_id := false);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001953 pars.send_early_cm := false;
1954 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), pars);
Harald Welte9de84792018-01-28 01:06:35 +01001955 vc_conn.done;
1956}
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01001957testcase TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() runs on MTC_CT {
1958 var BSC_ConnHdlr vc_conn;
1959 f_init();
1960 f_vty_config(MSCVTY, "network", "authentication required");
1961 f_vty_config(MSCVTY, "network", "encryption a5 3");
1962
1963 /* Make sure the MSC category is on DEBUG level to trigger the log
1964 * message that is reported in OS#2947 to trigger the segfault */
1965 f_vty_config(MSCVTY, "log stderr", "logging level msc debug");
1966
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001967 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 362, verify_cell_id := false);
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01001968 vc_conn.done;
1969}
Harald Welte9de84792018-01-28 01:06:35 +01001970
1971/* A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
1972private function f_tc_lu_imsi_auth_tmsi_encr_13_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1973 pars.net.expect_auth := true;
1974 pars.net.expect_ciph := true;
1975 pars.net.kc_support := '0A'O; /* A5/1 + A5/3 */
1976 pars.cm1.a5_1 := '1'B;
1977 pars.cm2.a5_1 := '1'B;
1978 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1979 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
1980 f_init_handler(pars, 15.0);
1981
1982 /* cannot use f_perform_lu() as we expect a reject */
1983 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
1984 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +02001985 f_cl3_or_initial_ue(l3_lu);
Harald Welte9de84792018-01-28 01:06:35 +01001986 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1987 f_mm_auth();
1988 alt {
Harald Welte5946b332018-03-18 23:32:21 +01001989 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1990 f_expect_clear();
1991 }
Harald Welte9de84792018-01-28 01:06:35 +01001992 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
1993 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02001994 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001995 }
1996 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01001997 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02001998 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001999 }
2000 }
2001 setverdict(pass);
2002}
2003testcase TC_lu_imsi_auth_tmsi_encr_13_2() runs on MTC_CT {
2004 var BSC_ConnHdlr vc_conn;
2005 f_init();
2006 f_vty_config(MSCVTY, "network", "authentication required");
2007 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
2008
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02002009 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_2), 37, verify_cell_id := false);
Harald Welte9de84792018-01-28 01:06:35 +01002010 vc_conn.done;
2011}
2012
Eric Wild26f4a622021-05-17 15:27:05 +02002013/* A5/0 + A5/1 + A5/3 + a5/4 only permitted on network side, and MS with only A5/1 support */
2014private function f_tc_lu_imsi_auth_tmsi_encr_0134_1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2015 pars.net.expect_auth := true;
2016 pars.net.expect_ciph := true;
2017 pars.net.kc_support := '03'O; /* A5/0 + A5/1 */
2018 pars.cm1.a5_1 := '0'B;
2019 pars.cm2.a5_1 := '0'B;
2020 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
2021 pars.cm2.classmarkInformationType2_oct5.a5_2 := '0'B;
2022 pars.cm2.classmarkInformationType2_oct5.cm3 := '0'B;
2023 pars.cm3 := omit;
2024 pars.use_umts_aka := true;
2025
2026 f_init_handler(pars, 15.0);
2027 f_perform_lu();
2028}
2029testcase TC_lu_imsi_auth_tmsi_encr_0134_1() runs on MTC_CT {
2030 var BSC_ConnHdlr vc_conn;
2031 f_init();
2032 f_vty_config(MSCVTY, "network", "authentication required");
2033 f_vty_config(MSCVTY, "network", "encryption a5 0 1 3 4");
2034
2035 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_0134_1), 39);
2036 vc_conn.done;
2037}
2038
2039/* A5/0 + A5/1 + A5/3 + a5/4 only permitted on network side, and MS with A5/3 + A5/4 support */
2040private function f_tc_lu_imsi_auth_tmsi_encr_0134_34(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2041 pars.net.expect_auth := true;
2042 pars.net.expect_ciph := true;
2043 pars.net.kc_support := '19'O; /* A5/3 + A5/4 */
2044 pars.cm1.a5_1 := '1'B;
2045 pars.cm2.a5_1 := '1'B;
2046 pars.cm2.classmarkInformationType2_oct5.a5_3 := '1'B;
2047 pars.cm2.classmarkInformationType2_oct5.a5_2 := '0'B;
2048 pars.cm2.classmarkInformationType2_oct5.cm3 := '1'B;
2049 pars.cm3 := valueof(ts_CM3_default);
2050 pars.use_umts_aka := true;
2051
2052 f_init_handler(pars, 15.0);
2053 f_perform_lu();
2054}
2055testcase TC_lu_imsi_auth_tmsi_encr_0134_34() runs on MTC_CT {
2056 var BSC_ConnHdlr vc_conn;
2057 f_init();
2058 f_vty_config(MSCVTY, "network", "authentication required");
2059 f_vty_config(MSCVTY, "network", "encryption a5 0 1 3 4");
2060
2061 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_0134_34), 40);
2062 vc_conn.done;
2063}
2064
2065/* A5/0 + A5/1 + A5/3 + a5/4 only permitted on network side, and MS with A5/3 support but no CM3 */
2066private function f_tc_lu_imsi_auth_tmsi_encr_0134_34_no_cm3(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2067 pars.net.expect_auth := true;
2068 pars.net.expect_ciph := true;
2069 pars.net.kc_support := '19'O; /* A5/3 + A5/4 */
2070 pars.cm1.a5_1 := '1'B;
2071 pars.cm2.a5_1 := '1'B;
2072 pars.cm2.classmarkInformationType2_oct5.a5_3 := '1'B;
2073 pars.cm2.classmarkInformationType2_oct5.a5_2 := '0'B;
2074 pars.cm2.classmarkInformationType2_oct5.cm3 := '0'B;
2075 pars.cm3 := omit;
2076 pars.use_umts_aka := true;
2077
2078 f_init_handler(pars, 15.0);
2079 f_perform_lu();
2080}
2081testcase TC_lu_imsi_auth_tmsi_encr_0134_34_no_cm3() runs on MTC_CT {
2082 var BSC_ConnHdlr vc_conn;
2083 f_init();
2084 f_vty_config(MSCVTY, "network", "authentication required");
2085 f_vty_config(MSCVTY, "network", "encryption a5 0 1 3 4");
2086
2087 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_0134_34_no_cm3), 41);
2088 vc_conn.done;
2089}
2090
Harald Welte9de84792018-01-28 01:06:35 +01002091/* A5/0 + A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
2092private function f_tc_lu_imsi_auth_tmsi_encr_013_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2093 pars.net.expect_auth := true;
2094 pars.net.expect_ciph := true;
2095 pars.net.kc_support := '0B'O; /* A5/1 + A5/3 */
2096 pars.cm1.a5_1 := '1'B;
2097 pars.cm2.a5_1 := '1'B;
2098 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
2099 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
2100 f_init_handler(pars, 15.0);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01002101 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01002102}
2103testcase TC_lu_imsi_auth_tmsi_encr_013_2() runs on MTC_CT {
2104 var BSC_ConnHdlr vc_conn;
2105 f_init();
2106 f_vty_config(MSCVTY, "network", "authentication required");
2107 f_vty_config(MSCVTY, "network", "encryption a5 0 1 3");
2108
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01002109 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_013_2), 38);
Harald Welte9de84792018-01-28 01:06:35 +01002110 vc_conn.done;
2111}
2112
Harald Welte33ec09b2018-02-10 15:34:46 +01002113/* LU followed by MT call (including paging) */
Neels Hofmeyr8fe8a902019-11-03 05:51:03 +01002114friend function f_tc_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte33ec09b2018-02-10 15:34:46 +01002115 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01002116 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02002117 cpars.use_osmux := pars.use_osmux;
Harald Welte33ec09b2018-02-10 15:34:46 +01002118
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01002119 f_perform_lu();
Harald Welte33ec09b2018-02-10 15:34:46 +01002120 f_mt_call(cpars);
2121}
2122testcase TC_lu_and_mt_call() runs on MTC_CT {
2123 var BSC_ConnHdlr vc_conn;
2124 f_init();
2125
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01002126 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call), 39);
Harald Welte33ec09b2018-02-10 15:34:46 +01002127 vc_conn.done;
2128}
2129
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02002130testcase TC_lu_and_mt_call_osmux() runs on MTC_CT {
2131 var BSC_ConnHdlr vc_conn;
2132 f_init(1, false, true, true);
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02002133
2134 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call), 39, 0, true, true);
2135 vc_conn.done;
2136}
2137
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02002138/* LU followed by MT call (including paging) */
2139friend function f_tc_lu_and_mt_call_ipv6(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2140 f_init_handler(pars);
2141 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
2142 cpars.mgw_conn_1.mgw_rtp_ip := "::1";
2143 cpars.mgw_conn_2.mgw_rtp_ip := "::2";
2144 cpars.bss_rtp_ip := "::3";
Pau Espin Pedrol563b3d02020-09-09 20:19:52 +02002145 cpars.mncc_rtp_ip := "::9";
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02002146 f_perform_lu();
2147 f_mt_call(cpars);
2148}
2149testcase TC_lu_and_mt_call_ipv6() runs on MTC_CT {
2150 var BSC_ConnHdlr vc_conn;
2151 f_init();
2152
2153 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call_ipv6), 39);
2154 vc_conn.done;
2155}
2156
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01002157/* MT call while already Paging */
2158friend function f_tc_lu_and_mt_call_already_paging(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2159 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
2160 var SmsParameters spars := valueof(t_SmsPars);
2161 var OCT4 tmsi;
2162
2163 f_init_handler(pars);
2164
2165 /* Perform location update */
2166 f_perform_lu();
2167
2168 /* register an 'expect' for given IMSI (+TMSI) */
2169 if (isvalue(g_pars.tmsi)) {
2170 tmsi := g_pars.tmsi;
2171 } else {
2172 tmsi := 'FFFFFFFF'O;
2173 }
2174 f_ran_register_imsi(g_pars.imsi, tmsi);
2175
2176 log("start Paging by an SMS");
2177 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2178
2179 /* MSC->BSC: expect PAGING from MSC */
2180 f_expect_paging();
2181
2182 log("MNCC signals MT call, before Paging Response");
2183 f_mt_call_initate(cpars);
2184 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
2185
2186 f_sleep(0.5);
2187 log("phone answers Paging, expecting both SMS and MT call to be established");
2188 f_establish_fully(EST_TYPE_PAG_RESP);
2189 spars.tp.ud := 'C8329BFD064D9B53'O;
2190 interleave {
2191 [] BSSAP.receive(f_mt_sms_deliver_pdu(spars)) {
2192 log("Got SMS-DELIVER");
2193 };
2194 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_SETUP(cpars.transaction_id, *, cpars.called_party))) {
2195 log("Got CC Setup");
2196 };
2197 }
2198 setverdict(pass);
2199 log("success, tear down");
2200 var default ccrel := activate(as_optional_cc_rel(cpars));
2201 if (g_pars.ran_is_geran) {
2202 BSSAP.send(ts_BSSMAP_ClearRequest(0));
2203 } else {
2204 BSSAP.send(ts_RANAP_IuReleaseRequest(ts_RanapCause_om_intervention));
2205 }
2206 f_expect_clear();
2207 deactivate(ccrel);
2208 f_vty_sms_clear(hex2str(g_pars.imsi));
2209}
2210testcase TC_lu_and_mt_call_already_paging() runs on MTC_CT {
2211 var BSC_ConnHdlrPars pars;
2212 var BSC_ConnHdlr vc_conn;
2213 f_init();
2214 pars := f_init_pars(391);
2215 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_call_already_paging), pars);
2216 vc_conn.done;
2217}
2218
Daniel Willmann8b084372018-02-04 13:35:26 +01002219/* Test MO Call SETUP with DTMF */
2220private function f_tc_mo_setup_dtmf_dup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2221 f_init_handler(pars);
2222 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Daniel Willmann8b084372018-02-04 13:35:26 +01002223
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01002224 f_perform_lu();
Daniel Willmann8b084372018-02-04 13:35:26 +01002225 f_mo_seq_dtmf_dup(cpars);
2226}
2227testcase TC_mo_setup_and_dtmf_dup() runs on MTC_CT {
2228 var BSC_ConnHdlr vc_conn;
2229 f_init();
2230
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01002231 vc_conn := f_start_handler(refers(f_tc_mo_setup_dtmf_dup), 39);
Daniel Willmann8b084372018-02-04 13:35:26 +01002232 vc_conn.done;
2233}
Harald Welte9de84792018-01-28 01:06:35 +01002234
Philipp Maier328d1662018-03-07 10:40:27 +01002235testcase TC_cr_before_reset() runs on MTC_CT {
2236 timer T := 4.0;
2237 var boolean reset_ack_seen := false;
2238 f_init_bssap_direct();
2239
Harald Welte3ca0ce12019-04-23 17:18:48 +02002240 f_ran_adapter_start(g_bssap[0]);
Daniel Willmann42d1d5b2018-08-07 15:18:41 +02002241
Daniel Willmanne8018962018-08-21 14:18:00 +02002242 f_sleep(3.0);
2243
Philipp Maier328d1662018-03-07 10:40:27 +01002244 /* Make a blind connection attemt, to trigger the deadlock condition */
Philipp Maier75932982018-03-27 14:52:35 +02002245 BSSAP_DIRECT.send(ts_BSSAP_CONNECT_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, 1, omit));
Philipp Maier328d1662018-03-07 10:40:27 +01002246
2247 /* Send a BSSMAP reset */
Philipp Maier75932982018-03-27 14:52:35 +02002248 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_Reset(0)));
Philipp Maier328d1662018-03-07 10:40:27 +01002249 T.start
2250 alt {
2251 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_ResetAck)) {
2252 reset_ack_seen := true;
2253 repeat;
2254 }
2255
2256 /* Acknowledge MSC sided reset requests */
2257 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_Reset)) {
Philipp Maier75932982018-03-27 14:52:35 +02002258 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_ResetAck));
Philipp Maier328d1662018-03-07 10:40:27 +01002259 repeat;
2260 }
2261
2262 /* Ignore all other messages (e.g CR from the connection request) */
2263 [] BSSAP_DIRECT.receive { repeat }
2264
2265 /* If we got no BSSMAP RESET ACK back, then the MSC entered the
2266 * deadlock situation. The MSC is then unable to respond to any
2267 * further BSSMAP RESET or any other sort of traffic. */
2268 [reset_ack_seen == true] T.timeout { setverdict(pass) }
2269 [reset_ack_seen == false] T.timeout {
2270 setverdict(fail, "no BSSMAP RESET ACK seen!");
Daniel Willmannafce8662018-07-06 23:11:32 +02002271 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +01002272 }
Pau Espin Pedrol7e9178d2019-12-17 17:52:17 +01002273 }
Philipp Maier328d1662018-03-07 10:40:27 +01002274}
Harald Welte9de84792018-01-28 01:06:35 +01002275
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002276/* Test MO Call with no response to RAN-side CRCX or DTAP Release */
Harald Weltee13cfb22019-04-23 16:52:02 +02002277friend function f_tc_mo_release_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002278 f_init_handler(pars);
2279 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
2280 var MNCC_PDU mncc;
2281 var MgcpCommand mgcp_cmd;
2282
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02002283 /* Do not respond to the second CRCX */
2284 cpars.mgw_conn_2.resp := 0;
2285
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002286 f_perform_lu();
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02002287 f_mo_call_establish(cpars);
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002288
Neels Hofmeyrde76f052019-02-26 05:02:46 +01002289 var default ccrel := activate(as_optional_cc_rel(cpars));
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002290
2291 f_expect_clear(60.0);
Neels Hofmeyrde76f052019-02-26 05:02:46 +01002292
2293 deactivate(ccrel);
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002294}
2295testcase TC_mo_release_timeout() runs on MTC_CT {
2296 var BSC_ConnHdlr vc_conn;
2297 f_init();
2298
2299 vc_conn := f_start_handler(refers(f_tc_mo_release_timeout), 40);
2300 vc_conn.done;
2301}
2302
Harald Welte12510c52018-01-26 22:26:24 +01002303
Philipp Maier2a98a732018-03-19 16:06:12 +01002304/* LU followed by MT call (including paging) */
2305private function f_tc_lu_and_mt_call_no_dlcx_resp(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2306 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01002307 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Philipp Maier2a98a732018-03-19 16:06:12 +01002308
2309 /* Intentionally disable the CRCX response */
2310 cpars.mgw_drop_dlcx := true;
2311
2312 /* Perform location update and call */
2313 f_perform_lu();
2314 f_mt_call(cpars);
2315}
2316testcase TC_lu_and_mt_call_no_dlcx_resp() runs on MTC_CT {
2317 var BSC_ConnHdlr vc_conn;
2318 f_init();
2319
2320 /* Perform an almost normal looking locationupdate + mt-call, but do
2321 * not respond to the DLCX at the end of the call */
2322 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call_no_dlcx_resp), 41);
2323 vc_conn.done;
2324
2325 /* Wait a guard period until the MGCP layer in the MSC times out,
2326 * if the MSC is vulnerable to the use-after-free situation that is
2327 * fixed by I78f1b6a9149488a4ad3f120c1e190a83c07d4b89 then it should
2328 * segfault now */
2329 f_sleep(6.0);
2330
2331 /* Run the init procedures once more. If the MSC has crashed, this
2332 * this will fail */
2333 f_init();
2334}
Harald Welte45164da2018-01-24 12:51:27 +01002335
Philipp Maier75932982018-03-27 14:52:35 +02002336/* Two BSSMAP resets from two different BSCs */
2337testcase TC_reset_two() runs on MTC_CT {
2338 var BSC_ConnHdlr vc_conn;
2339 f_init(2);
2340 f_sleep(2.0);
2341 setverdict(pass);
2342}
2343
Harald Weltee13cfb22019-04-23 16:52:02 +02002344/* Two BSSMAP resets from two different BSCs plus one IuCS RANAP Reset */
2345testcase TC_reset_two_1iu() runs on MTC_CT {
2346 var BSC_ConnHdlr vc_conn;
2347 f_init(3);
2348 f_sleep(2.0);
2349 setverdict(pass);
2350}
2351
Harald Weltef640a012018-04-14 17:49:21 +02002352/***********************************************************************
2353 * SMS Testing
2354 ***********************************************************************/
2355
Harald Weltef45efeb2018-04-09 18:19:24 +02002356/* LU followed by MO SMS */
Harald Weltee13cfb22019-04-23 16:52:02 +02002357friend function f_tc_lu_and_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02002358 var SmsParameters spars := valueof(t_SmsPars);
2359
2360 f_init_handler(pars);
2361
2362 /* Perform location update and call */
2363 f_perform_lu();
2364
2365 f_establish_fully(EST_TYPE_MO_SMS);
2366
2367 //spars.exp_rp_err := 96; /* invalid mandatory information */
2368 f_mo_sms(spars);
2369
2370 f_expect_clear();
2371}
2372testcase TC_lu_and_mo_sms() runs on MTC_CT {
2373 var BSC_ConnHdlr vc_conn;
2374 f_init();
2375 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_sms), 42);
2376 vc_conn.done;
2377}
2378
Harald Weltee13cfb22019-04-23 16:52:02 +02002379
Harald Weltef45efeb2018-04-09 18:19:24 +02002380private function f_vty_sms_send(charstring imsi, charstring msisdn, charstring text)
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002381runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02002382 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
2383}
2384
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01002385/* Remove still pending SMS */
2386private function f_vty_sms_clear(charstring imsi)
2387runs on BSC_ConnHdlr {
2388 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " sms delete-all");
2389 f_vty_transceive(MSCVTY, "sms-queue clear");
2390}
2391
Harald Weltef45efeb2018-04-09 18:19:24 +02002392/* LU followed by MT SMS */
Harald Weltee13cfb22019-04-23 16:52:02 +02002393friend function f_tc_lu_and_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02002394 var SmsParameters spars := valueof(t_SmsPars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002395
2396 f_init_handler(pars);
2397
2398 /* Perform location update and call */
2399 f_perform_lu();
2400
2401 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002402 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Weltef45efeb2018-04-09 18:19:24 +02002403
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002404 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
Harald Weltef45efeb2018-04-09 18:19:24 +02002405
2406 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02002407 f_expect_paging();
2408
Harald Weltef45efeb2018-04-09 18:19:24 +02002409 /* Establish DTAP / BSSAP / SCCP connection */
2410 f_establish_fully(EST_TYPE_PAG_RESP);
2411
2412 spars.tp.ud := 'C8329BFD064D9B53'O;
2413 f_mt_sms(spars);
2414
2415 f_expect_clear();
2416}
2417testcase TC_lu_and_mt_sms() runs on MTC_CT {
2418 var BSC_ConnHdlrPars pars;
2419 var BSC_ConnHdlr vc_conn;
2420 f_init();
2421 pars := f_init_pars(43);
2422 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms), pars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002423 vc_conn.done;
2424}
2425
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01002426/* SMS added while already Paging */
2427friend function f_tc_lu_and_mt_sms_already_paging(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2428 var SmsParameters spars := valueof(t_SmsPars);
2429 var OCT4 tmsi;
2430
2431 f_init_handler(pars);
2432
2433 f_perform_lu();
2434
2435 /* register an 'expect' for given IMSI (+TMSI) */
2436 if (isvalue(g_pars.tmsi)) {
2437 tmsi := g_pars.tmsi;
2438 } else {
2439 tmsi := 'FFFFFFFF'O;
2440 }
2441 f_ran_register_imsi(g_pars.imsi, tmsi);
2442
2443 log("first SMS");
2444 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2445
2446 /* MSC->BSC: expect PAGING from MSC */
2447 f_expect_paging();
2448
2449 log("second SMS");
2450 /* Now osmo-msc is in state "Paging pending", make sure that another SMS to be sent at this time just joins in
2451 * with the pending paging. Another SMS: */
2452 f_vty_sms_send(hex2str(pars.imsi), "2342", "Another SMS");
2453
2454 /* Establish DTAP / BSSAP / SCCP connection */
2455 f_establish_fully(EST_TYPE_PAG_RESP);
2456
2457 spars.tp.ud := 'C8329BFD064D9B53'O;
2458 f_mt_sms(spars);
2459
2460 spars.tp.ud := '41F79B8E2ECB41D3E614'O;
2461 f_mt_sms(spars);
2462
2463 f_expect_clear();
2464}
2465testcase TC_lu_and_mt_sms_already_paging() runs on MTC_CT {
2466 var BSC_ConnHdlrPars pars;
2467 var BSC_ConnHdlr vc_conn;
2468 f_init();
2469 pars := f_init_pars(44);
2470 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_already_paging), pars);
2471 vc_conn.done;
2472}
Harald Weltee13cfb22019-04-23 16:52:02 +02002473
Philipp Maier3983e702018-11-22 19:01:33 +01002474/* Paging for MT SMS but no response */
Harald Weltee13cfb22019-04-23 16:52:02 +02002475friend function f_tc_lu_and_mt_sms_paging_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier3983e702018-11-22 19:01:33 +01002476 var SmsParameters spars := valueof(t_SmsPars);
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002477
Philipp Maier3983e702018-11-22 19:01:33 +01002478 f_init_handler(pars, 150.0);
2479
2480 /* Perform location update */
2481 f_perform_lu();
2482
2483 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002484 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Philipp Maier3983e702018-11-22 19:01:33 +01002485
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002486 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2487
Neels Hofmeyr16237742019-03-06 15:34:01 +01002488 /* Expect the MSC to page exactly once */
Harald Weltee13cfb22019-04-23 16:52:02 +02002489 f_expect_paging();
Philipp Maier3983e702018-11-22 19:01:33 +01002490
2491 /* Wait some time to make sure the MSC is not delivering any further
2492 * paging messages or anything else that could be unexpected. */
2493 timer T := 20.0;
2494 T.start
2495 alt {
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002496 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
2497 setverdict(fail, "paging seems not to stop!");
2498 mtc.stop;
Philipp Maier3983e702018-11-22 19:01:33 +01002499 }
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002500 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
2501 setverdict(fail, "paging seems not to stop!");
2502 mtc.stop;
Harald Weltee13cfb22019-04-23 16:52:02 +02002503 }
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002504 [] BSSAP.receive {
2505 setverdict(fail, "unexpected BSSAP message received");
2506 self.stop;
Philipp Maier3983e702018-11-22 19:01:33 +01002507 }
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002508 [] T.timeout {
2509 setverdict(pass);
Philipp Maier3983e702018-11-22 19:01:33 +01002510 }
2511 }
2512
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01002513 f_vty_sms_clear(hex2str(g_pars.imsi));
2514
Philipp Maier3983e702018-11-22 19:01:33 +01002515 setverdict(pass);
2516}
2517testcase TC_lu_and_mt_sms_paging_and_nothing() runs on MTC_CT {
2518 var BSC_ConnHdlrPars pars;
2519 var BSC_ConnHdlr vc_conn;
2520 f_init();
Philipp Maiera99ad262019-01-22 15:35:42 +01002521 pars := f_init_pars(1843);
Philipp Maier3983e702018-11-22 19:01:33 +01002522 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_paging_and_nothing), pars);
Philipp Maier3983e702018-11-22 19:01:33 +01002523 vc_conn.done;
2524}
2525
Alexander Couzensfc02f242019-09-12 03:43:18 +02002526/* LU followed by MT SMS with repeated paging */
2527friend function f_tc_lu_and_mt_sms_paging_repeated(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2528 var SmsParameters spars := valueof(t_SmsPars);
Alexander Couzensfc02f242019-09-12 03:43:18 +02002529
2530 f_init_handler(pars);
2531
2532 /* Perform location update and call */
2533 f_perform_lu();
2534
2535 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002536 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Alexander Couzensfc02f242019-09-12 03:43:18 +02002537
2538 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2539
Neels Hofmeyrc3accec2019-11-28 01:09:47 +01002540 log("Expecting first Paging");
Alexander Couzensfc02f242019-09-12 03:43:18 +02002541 /* MSC->BSC: expect PAGING from MSC */
2542 f_expect_paging();
2543
Neels Hofmeyrc3accec2019-11-28 01:09:47 +01002544 if (g_pars.ran_is_geran) {
2545 log("GERAN: expect no further Paging");
2546 } else {
2547 log("UTRAN: expect more Paging");
2548 }
2549
2550 timer T := 5.0;
2551 T.start;
2552 alt {
2553 [g_pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
2554 setverdict(fail, "GERAN should not repeat Paging, but received a second Paging");
2555 mtc.stop;
2556 }
2557 [not g_pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
2558 log("UTRAN: second Paging received, as expected");
2559 setverdict(pass);
2560 }
2561 [] T.timeout {
2562 if (g_pars.ran_is_geran) {
2563 log("GERAN: No further Paging received, as expected");
2564 setverdict(pass);
2565 } else {
2566 setverdict(fail, "UTRAN: Expected a second Paging");
2567 mtc.stop;
2568 }
2569 }
2570 }
Alexander Couzensfc02f242019-09-12 03:43:18 +02002571
2572 /* Establish DTAP / BSSAP / SCCP connection */
2573 f_establish_fully(EST_TYPE_PAG_RESP);
2574
2575 spars.tp.ud := 'C8329BFD064D9B53'O;
2576 f_mt_sms(spars);
2577
2578 f_expect_clear();
2579}
2580testcase TC_lu_and_mt_sms_paging_repeated() runs on MTC_CT {
2581 var BSC_ConnHdlrPars pars;
2582 var BSC_ConnHdlr vc_conn;
2583 f_init();
2584 pars := f_init_pars(1844);
2585 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_paging_repeated), pars);
2586 vc_conn.done;
2587}
Harald Weltee13cfb22019-04-23 16:52:02 +02002588
Harald Weltef640a012018-04-14 17:49:21 +02002589/* mobile originated SMS from MS/BTS/BSC side to SMPP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002590friend function f_tc_smpp_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef640a012018-04-14 17:49:21 +02002591 var SmsParameters spars := valueof(t_SmsPars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002592
Harald Weltef640a012018-04-14 17:49:21 +02002593 f_init_handler(pars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002594
Harald Weltef640a012018-04-14 17:49:21 +02002595 /* Perform location update so IMSI is known + registered in MSC/VLR */
2596 f_perform_lu();
Harald Weltef640a012018-04-14 17:49:21 +02002597
Vadim Yanitskiy2d3f8462020-01-15 11:44:12 +07002598 /* MS/UE submits a MO SMS */
2599 f_establish_fully(EST_TYPE_MO_SMS);
2600 f_mo_sms_submit(spars);
Harald Weltef640a012018-04-14 17:49:21 +02002601
2602 var SMPP_PDU smpp;
2603 var template SMPP_PDU tr_smpp := tr_SMPP(c_SMPP_command_id_deliver_sm, ESME_ROK);
2604 tr_smpp.body.deliver_sm := {
2605 service_type := "CMT",
2606 source_addr_ton := network_specific,
2607 source_addr_npi := isdn,
2608 source_addr := hex2str(pars.msisdn),
2609 dest_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
2610 dest_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
2611 destination_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
2612 esm_class := '00000001'B,
2613 protocol_id := 0,
2614 priority_flag := 0,
2615 schedule_delivery_time := "",
2616 replace_if_present := 0,
2617 data_coding := '00000001'B,
2618 sm_default_msg_id := 0,
2619 sm_length := ?,
2620 short_message := spars.tp.ud,
2621 opt_pars := {
2622 {
2623 tag := user_message_reference,
2624 len := 2,
2625 opt_value := {
2626 int2_val := oct2int(spars.tp.msg_ref)
2627 }
2628 }
2629 }
2630 };
2631 alt {
2632 [] SMPP.receive(tr_smpp) -> value smpp {
2633 SMPP.send(ts_SMPP_DELIVER_SM_resp(ESME_ROK, smpp.header.seq_num));
2634 }
2635 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK)) { repeat; }
2636 }
2637
Vadim Yanitskiy2d3f8462020-01-15 11:44:12 +07002638 /* MSC terminates the SMS transaction with RP-ACK */
2639 f_mo_sms_wait_rp_ack(spars);
2640
Harald Weltef640a012018-04-14 17:49:21 +02002641 f_expect_clear();
2642}
2643testcase TC_smpp_mo_sms() runs on MTC_CT {
2644 var BSC_ConnHdlr vc_conn;
2645 f_init();
2646 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "default-route");
2647 vc_conn := f_start_handler(refers(f_tc_smpp_mo_sms), 44);
2648 vc_conn.done;
2649 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "no default-route");
2650}
2651
Vadim Yanitskiy33820762020-01-15 11:26:07 +07002652/* Test case for OS#4351: make sure that RP-ERROR from ESME is properly sent to the MS/UE */
2653friend function f_tc_smpp_mo_sms_rp_error(charstring id, BSC_ConnHdlrPars pars)
2654runs on BSC_ConnHdlr {
2655 var SmsParameters spars := valueof(t_SmsPars);
2656 var SMPP_PDU smpp_pdu;
2657 timer T := 3.0;
2658
2659 f_init_handler(pars);
2660
2661 /* Perform location update */
2662 f_perform_lu();
2663
2664 /* MS/UE submits a MO SMS */
2665 f_establish_fully(EST_TYPE_MO_SMS);
2666 f_mo_sms_submit(spars);
2667
2668 /* ESME responds with an error (Invalid Destination Address) */
2669 T.start;
2670 alt {
2671 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_deliver_sm, ESME_ROK, body := ?)) -> value smpp_pdu {
2672 SMPP.send(ts_SMPP_DELIVER_SM_resp(ESME_RINVDSTADR, smpp_pdu.header.seq_num));
2673 }
2674 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK)) { repeat; }
2675 [] T.timeout {
2676 setverdict(fail, "Timeout waiting for SMPP DELIVER-SM");
2677 mtc.stop;
2678 }
2679 }
2680
2681 /* Expect RP-ERROR on BSSAP interface */
2682 spars.exp_rp_err := 1; /* FIXME: GSM411_RP_CAUSE_MO_NUM_UNASSIGNED */
2683 f_mo_sms_wait_rp_ack(spars);
2684
2685 f_expect_clear();
2686}
2687testcase TC_smpp_mo_sms_rp_error() runs on MTC_CT {
2688 var BSC_ConnHdlr vc_conn;
2689 f_init();
2690 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "default-route");
2691 vc_conn := f_start_handler(refers(f_tc_smpp_mo_sms_rp_error), 45);
2692 vc_conn.done;
2693 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "no default-route");
2694}
2695
Harald Weltee13cfb22019-04-23 16:52:02 +02002696
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002697/* Test MO-SMS from MS/BTS/BSC towards HLR (via GSUP) */
Harald Weltee13cfb22019-04-23 16:52:02 +02002698friend function f_tc_gsup_mo_sms(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002699runs on BSC_ConnHdlr {
2700 var SmsParameters spars := valueof(t_SmsPars);
2701 var GSUP_PDU gsup_msg_rx;
2702 var octetstring sm_tpdu;
2703
2704 f_init_handler(pars);
2705
2706 /* We need to inspect GSUP activity */
2707 f_create_gsup_expect(hex2str(g_pars.imsi));
2708
2709 /* Perform location update */
2710 f_perform_lu();
2711
2712 /* Send CM Service Request for SMS */
2713 f_establish_fully(EST_TYPE_MO_SMS);
2714
2715 /* Prepare expected SM-RP-UI (SM TPDU) */
2716 enc_TPDU_RP_DATA_MS_SGSN_fast(
2717 valueof(ts_SMS_SUBMIT(spars.tp.msg_ref,
2718 spars.tp.da, spars.tp.pid, spars.tp.dcs,
2719 spars.tp.udl, spars.tp.ud)),
2720 sm_tpdu);
2721
2722 var template GSUP_PDU mo_forwardSM := tr_GSUP_MO_FORWARD_SM_REQ(
2723 imsi := g_pars.imsi,
2724 sm_rp_mr := spars.rp.msg_ref,
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09002725 /* SM-RP-DA: SMSC address */
2726 sm_rp_da := tr_GSUP_SM_RP_DA_SMSC_ADDR(t_GSUP_SM_RP_Addr(
2727 number := spars.rp.smsc_addr.rP_NumberDigits,
2728 npi := spars.rp.smsc_addr.rP_NumberingPlanIdentification,
2729 ton := spars.rp.smsc_addr.rP_TypeOfNumber,
2730 ext := spars.rp.smsc_addr.rP_Ext)),
2731 /* SM-RP-OA: subscriber's MSISDN (filled in by MSC) */
2732 sm_rp_oa := tr_GSUP_SM_RP_OA_MSISDN(t_GSUP_SM_RP_Addr(
2733 number := g_pars.msisdn,
2734 /* NOTE: MSISDN in g_pars lacks this info, assuming defaults */
2735 npi := '0001'B, ton := '001'B, ext := '1'B)),
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002736 /* TODO: can we use decmatch here? */
2737 sm_rp_ui := sm_tpdu
2738 );
2739
2740 /* Submit an SMS on DTAP and expect MO-forwardSM-Req on GSUP */
2741 f_mo_sms_submit(spars);
2742 alt {
2743 [] GSUP.receive(mo_forwardSM) -> value gsup_msg_rx {
Vadim Yanitskiya358dd42020-01-15 10:42:47 +07002744 log("RX MO-forwardSM-Req: ", gsup_msg_rx);
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002745 setverdict(pass);
2746 }
2747 [] GSUP.receive {
2748 log("RX unexpected GSUP message");
2749 setverdict(fail);
2750 mtc.stop;
2751 }
2752 }
2753
2754 /* Trigger RP-ACK by sending MO-forwardSM-Res */
2755 GSUP.send(valueof(ts_GSUP_MO_FORWARD_SM_RES(
2756 imsi := g_pars.imsi,
2757 sm_rp_mr := spars.rp.msg_ref)));
2758 /* Expect RP-ACK on DTAP */
2759 f_mo_sms_wait_rp_ack(spars);
2760
2761 f_expect_clear();
2762}
2763testcase TC_gsup_mo_sms() runs on MTC_CT {
2764 var BSC_ConnHdlr vc_conn;
2765 f_init();
2766 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2767 vc_conn := f_start_handler(refers(f_tc_gsup_mo_sms), 88);
2768 vc_conn.done;
2769 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2770}
2771
Harald Weltee13cfb22019-04-23 16:52:02 +02002772
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002773/* Test MO-SMMA from MS/BTS/BSC towards HLR (via GSUP) */
Harald Weltee13cfb22019-04-23 16:52:02 +02002774friend function f_tc_gsup_mo_smma(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002775runs on BSC_ConnHdlr {
2776 var SmsParameters spars := valueof(t_SmsPars);
2777 var GSUP_PDU gsup_msg_rx;
2778
2779 f_init_handler(pars);
2780
2781 /* We need to inspect GSUP activity */
2782 f_create_gsup_expect(hex2str(g_pars.imsi));
2783
2784 /* Perform location update */
2785 f_perform_lu();
2786
2787 /* Send CM Service Request for SMS */
2788 f_establish_fully(EST_TYPE_MO_SMS);
2789
2790 var template GSUP_PDU mo_ReadyForSM := tr_GSUP_MO_READY_FOR_SM_REQ(
2791 imsi := g_pars.imsi,
2792 sm_rp_mr := spars.rp.msg_ref,
2793 sm_alert_rsn := GSUP_SM_ALERT_RSN_TYPE_MEM_AVAIL
2794 );
2795
2796 /* Submit an SMS on DTAP and expect MO-forwardSM-Req on GSUP */
2797 f_mo_smma(spars);
2798 alt {
2799 [] GSUP.receive(mo_ReadyForSM) -> value gsup_msg_rx {
Vadim Yanitskiya358dd42020-01-15 10:42:47 +07002800 log("RX MO-ReadyForSM-Req: ", gsup_msg_rx);
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002801 setverdict(pass);
2802 }
2803 [] GSUP.receive {
2804 log("RX unexpected GSUP message");
2805 setverdict(fail);
2806 mtc.stop;
2807 }
2808 }
2809
2810 /* Trigger RP-ACK by sending MO-forwardSM-Res */
2811 GSUP.send(valueof(ts_GSUP_MO_READY_FOR_SM_RES(
2812 imsi := g_pars.imsi,
2813 sm_rp_mr := spars.rp.msg_ref)));
2814 /* Expect RP-ACK on DTAP */
2815 f_mo_sms_wait_rp_ack(spars);
2816
2817 f_expect_clear();
2818}
2819testcase TC_gsup_mo_smma() runs on MTC_CT {
2820 var BSC_ConnHdlr vc_conn;
2821 f_init();
2822 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2823 vc_conn := f_start_handler(refers(f_tc_gsup_mo_smma), 89);
2824 vc_conn.done;
2825 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2826}
2827
Harald Weltee13cfb22019-04-23 16:52:02 +02002828
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002829/* Helper for sending MT SMS over GSUP */
2830private function f_gsup_forwardSM_req(SmsParameters spars, OCT1 mms := '00'O)
2831runs on BSC_ConnHdlr {
Vadim Yanitskiya52347c2019-12-12 17:32:33 +09002832 var GSUP_SM_RP_Addr msisdn := valueof(t_GSUP_SM_RP_Addr(g_pars.msisdn));
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09002833 var GSUP_SM_RP_Addr smsc := valueof(t_GSUP_SM_RP_Addr(
2834 number := spars.rp.smsc_addr.rP_NumberDigits,
2835 npi := spars.rp.smsc_addr.rP_NumberingPlanIdentification,
2836 ton := spars.rp.smsc_addr.rP_TypeOfNumber,
2837 ext := spars.rp.smsc_addr.rP_Ext));
Vadim Yanitskiya52347c2019-12-12 17:32:33 +09002838
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002839 GSUP.send(ts_GSUP_MT_FORWARD_SM_REQ(
2840 imsi := g_pars.imsi,
2841 /* NOTE: MSC should assign RP-MR itself */
2842 sm_rp_mr := 'FF'O,
Vadim Yanitskiya52347c2019-12-12 17:32:33 +09002843 sm_rp_da := valueof(ts_GSUP_SM_RP_DA_MSISDN(msisdn)),
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09002844 sm_rp_oa := valueof(ts_GSUP_SM_RP_OA_SMSC_ADDR(smsc)),
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002845 /* Encoded SMS TPDU (taken from Wireshark)
2846 * FIXME: we should encode spars somehow */
2847 sm_rp_ui := '00068021436500008111328130858200'O,
2848 sm_rp_mms := mms
2849 ));
2850}
2851
2852/* Test successful MT-SMS (RP-ACK) over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002853friend function f_tc_gsup_mt_sms_ack(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002854runs on BSC_ConnHdlr {
2855 var SmsParameters spars := valueof(t_SmsPars);
2856
2857 f_init_handler(pars);
2858
2859 /* We need to inspect GSUP activity */
2860 f_create_gsup_expect(hex2str(g_pars.imsi));
2861
2862 /* Perform location update */
2863 f_perform_lu();
2864
2865 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002866 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002867
2868 var template GSUP_PDU mt_forwardSM_res := tr_GSUP_MT_FORWARD_SM_RES(
2869 imsi := g_pars.imsi,
2870 /* NOTE: MSC should assign RP-MR itself */
2871 sm_rp_mr := ?
2872 );
2873
2874 /* Submit a MT SMS on GSUP */
2875 f_gsup_forwardSM_req(spars);
2876
2877 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002878 f_expect_paging();
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002879 f_establish_fully(EST_TYPE_PAG_RESP);
2880
2881 /* Wait for MT SMS on DTAP */
2882 f_mt_sms_expect(spars);
2883
2884 /* Send RP-ACK and expect MT-forwardSM-Res on GSUP */
2885 f_mt_sms_send_rp_ack(spars);
2886 alt {
2887 [] GSUP.receive(mt_forwardSM_res) {
2888 log("RX MT-forwardSM-Res (RP-ACK)");
2889 setverdict(pass);
2890 }
2891 [] GSUP.receive {
2892 log("RX unexpected GSUP message");
2893 setverdict(fail);
2894 mtc.stop;
2895 }
2896 }
2897
2898 f_expect_clear();
2899}
2900testcase TC_gsup_mt_sms_ack() runs on MTC_CT {
2901 var BSC_ConnHdlrPars pars;
2902 var BSC_ConnHdlr vc_conn;
2903 f_init();
2904 pars := f_init_pars(90);
2905 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2906 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_ack), pars);
2907 vc_conn.done;
2908 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2909}
2910
Harald Weltee13cfb22019-04-23 16:52:02 +02002911
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002912/* Test rejected MT-SMS (RP-ERROR) over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002913friend function f_tc_gsup_mt_sms_err(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002914runs on BSC_ConnHdlr {
2915 var SmsParameters spars := valueof(t_SmsPars);
2916 var OCT1 sm_rp_cause := '78'O; /* dummy RP-Cause value */
2917
2918 f_init_handler(pars);
2919
2920 /* We need to inspect GSUP activity */
2921 f_create_gsup_expect(hex2str(g_pars.imsi));
2922
2923 /* Perform location update */
2924 f_perform_lu();
2925
2926 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002927 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002928
2929 var template GSUP_PDU mt_forwardSM_err := tr_GSUP_MT_FORWARD_SM_ERR(
2930 imsi := g_pars.imsi,
2931 /* NOTE: MSC should assign RP-MR itself */
2932 sm_rp_mr := ?,
2933 sm_rp_cause := sm_rp_cause
2934 );
2935
2936 /* Submit a MT SMS on GSUP */
2937 f_gsup_forwardSM_req(spars);
2938
2939 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002940 f_expect_paging();
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002941 f_establish_fully(EST_TYPE_PAG_RESP);
2942
2943 /* Wait for MT SMS on DTAP */
2944 f_mt_sms_expect(spars);
2945
2946 /* Send RP-ERROR and expect MT-forwardSM-Err on GSUP */
2947 f_mt_sms_send_rp_error(spars, oct2int(sm_rp_cause));
2948 alt {
2949 [] GSUP.receive(mt_forwardSM_err) {
2950 log("RX MT-forwardSM-Err (RP-ERROR)");
2951 setverdict(pass);
2952 mtc.stop;
2953 }
2954 [] GSUP.receive {
2955 log("RX unexpected GSUP message");
2956 setverdict(fail);
2957 mtc.stop;
2958 }
2959 }
2960
2961 f_expect_clear();
2962}
2963testcase TC_gsup_mt_sms_err() runs on MTC_CT {
2964 var BSC_ConnHdlrPars pars;
2965 var BSC_ConnHdlr vc_conn;
2966 f_init();
2967 pars := f_init_pars(91);
2968 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2969 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_err), pars);
2970 vc_conn.done;
2971 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2972}
2973
Harald Weltee13cfb22019-04-23 16:52:02 +02002974
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002975/* Test SM-RP-MR assignment for MT-SMS over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002976friend function f_tc_gsup_mt_sms_rp_mr(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002977runs on BSC_ConnHdlr {
2978 var SmsParameters spars1 := valueof(t_SmsPars); /* 1st SMS */
2979 var SmsParameters spars2 := valueof(t_SmsPars); /* 2nd SMS */
2980
2981 f_init_handler(pars);
2982
2983 /* We need to inspect GSUP activity */
2984 f_create_gsup_expect(hex2str(g_pars.imsi));
2985
2986 /* Perform location update */
2987 f_perform_lu();
2988
2989 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002990 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002991
2992 /* Submit the 1st MT SMS on GSUP */
2993 log("TX MT-forwardSM-Req for the 1st SMS");
2994 f_gsup_forwardSM_req(spars1);
2995
2996 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002997 f_expect_paging();
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002998 f_establish_fully(EST_TYPE_PAG_RESP);
2999
3000 /* Wait for 1st MT SMS on DTAP */
3001 f_mt_sms_expect(spars1);
3002 log("RX the 1st SMS on DTAP, DTAP TID is ", spars1.tid,
3003 ", SM-RP-MR is ", spars1.rp.msg_ref);
3004
3005 /* Submit the 2nd MT SMS on GSUP */
3006 log("TX MT-forwardSM-Req for the 2nd SMS");
3007 f_gsup_forwardSM_req(spars2);
3008
3009 /* Wait for 2nd MT SMS on DTAP */
3010 f_mt_sms_expect(spars2);
3011 log("RX the 2nd SMS on DTAP, DTAP TID is ", spars2.tid,
3012 ", SM-RP-MR is ", spars2.rp.msg_ref);
3013
3014 /* Both transaction IDs shall be different */
3015 if (spars1.tid == spars2.tid) {
3016 log("Both DTAP transaction IDs shall be different");
3017 setverdict(fail);
3018 }
3019
3020 /* Both SM-RP-MR values shall be different */
3021 if (spars1.rp.msg_ref == spars2.rp.msg_ref) {
3022 log("Both SM-RP-MR values shall be different");
3023 setverdict(fail);
3024 }
3025
3026 /* Both SM-RP-MR values shall be assigned */
3027 if (spars1.rp.msg_ref == 'FF'O) {
3028 log("Unassigned SM-RP-MR value for the 1st SMS");
3029 setverdict(fail);
3030 }
3031 if (spars2.rp.msg_ref == 'FF'O) {
3032 log("Unassigned SM-RP-MR value for the 2nd SMS");
3033 setverdict(fail);
3034 }
3035
3036 /* Send the 1st RP-ACK and expect MT-forwardSM-Res on GSUP */
3037 f_mt_sms_send_rp_ack(spars1);
3038 alt {
3039 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
3040 imsi := g_pars.imsi,
3041 sm_rp_mr := spars1.rp.msg_ref
3042 )) {
3043 log("RX MT-forwardSM-Res (RP-ACK)");
3044 setverdict(pass);
3045 }
3046 [] GSUP.receive {
3047 log("RX unexpected GSUP message");
3048 setverdict(fail);
3049 mtc.stop;
3050 }
3051 }
3052
3053 /* Send the 2nd RP-ACK and expect MT-forwardSM-Res on GSUP */
3054 f_mt_sms_send_rp_ack(spars2);
3055 alt {
3056 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
3057 imsi := g_pars.imsi,
3058 sm_rp_mr := spars2.rp.msg_ref
3059 )) {
3060 log("RX MT-forwardSM-Res (RP-ACK)");
3061 setverdict(pass);
3062 }
3063 [] GSUP.receive {
3064 log("RX unexpected GSUP message");
3065 setverdict(fail);
3066 mtc.stop;
3067 }
3068 }
3069
3070 f_expect_clear();
3071}
3072testcase TC_gsup_mt_sms_rp_mr() runs on MTC_CT {
3073 var BSC_ConnHdlrPars pars;
3074 var BSC_ConnHdlr vc_conn;
3075 f_init();
3076 pars := f_init_pars(92);
3077 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
3078 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_rp_mr), pars);
3079 vc_conn.done;
3080 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
3081}
3082
Harald Weltee13cfb22019-04-23 16:52:02 +02003083
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07003084/* Test SM-RP-MR assignment for MT-SMS over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02003085friend function f_tc_gsup_mo_mt_sms_rp_mr(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07003086runs on BSC_ConnHdlr {
3087 var SmsParameters spars_mo := valueof(t_SmsPars); /* MO SMMA */
3088 var SmsParameters spars_mt := valueof(t_SmsPars); /* MT SMS */
3089
3090 f_init_handler(pars);
3091
3092 /* We need to inspect GSUP activity */
3093 f_create_gsup_expect(hex2str(g_pars.imsi));
3094
3095 /* Perform location update */
3096 f_perform_lu();
3097
3098 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01003099 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07003100
3101 /* Send CM Service Request for MO SMMA */
3102 f_establish_fully(EST_TYPE_MO_SMS);
3103
3104 /* Submit MO SMMA on DTAP */
3105 log("Submit MO SMMA on DTAP, SM-RP-MR is '00'O");
3106 spars_mo.rp.msg_ref := '00'O;
3107 f_mo_smma(spars_mo);
3108
3109 /* Expect MO-forwardSM-Req for MO SMMA on GSUP */
3110 alt {
3111 [] GSUP.receive(tr_GSUP_MO_READY_FOR_SM_REQ(
3112 imsi := g_pars.imsi,
3113 sm_rp_mr := spars_mo.rp.msg_ref,
3114 sm_alert_rsn := GSUP_SM_ALERT_RSN_TYPE_MEM_AVAIL
3115 )) {
3116 log("RX MO-ReadyForSM-Req, SM-RP-MR is '00'O");
3117 setverdict(pass);
3118 }
3119 [] GSUP.receive {
3120 log("RX unexpected GSUP message");
3121 setverdict(fail);
3122 mtc.stop;
3123 }
3124 }
3125
3126 /* Submit MT SMS on GSUP */
3127 log("TX MT-forwardSM-Req for the MT SMS");
3128 f_gsup_forwardSM_req(spars_mt);
3129
3130 /* Wait for MT SMS on DTAP */
3131 f_mt_sms_expect(spars_mt);
3132 log("RX MT SMS on DTAP, DTAP TID is ", spars_mt.tid,
3133 ", SM-RP-MR is ", spars_mt.rp.msg_ref);
3134
3135 /* Both SM-RP-MR values shall be different */
3136 if (spars_mo.rp.msg_ref == spars_mt.rp.msg_ref) {
3137 log("Both SM-RP-MR values shall be different");
3138 setverdict(fail);
3139 }
3140
3141 /* SM-RP-MR value for MT SMS shall be assigned */
3142 if (spars_mt.rp.msg_ref == 'FF'O) {
3143 log("Unassigned SM-RP-MR value for the MT SMS");
3144 setverdict(fail);
3145 }
3146
3147 /* Trigger RP-ACK for MO SMMA by sending MO-forwardSM-Res */
3148 GSUP.send(valueof(ts_GSUP_MO_READY_FOR_SM_RES(
3149 imsi := g_pars.imsi,
3150 sm_rp_mr := spars_mo.rp.msg_ref)));
3151 /* Expect RP-ACK for MO SMMA on DTAP */
3152 f_mo_sms_wait_rp_ack(spars_mo);
3153
3154 /* Send RP-ACK for MT SMS and expect MT-forwardSM-Res on GSUP */
3155 f_mt_sms_send_rp_ack(spars_mt);
3156 alt {
3157 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
3158 imsi := g_pars.imsi,
3159 sm_rp_mr := spars_mt.rp.msg_ref
3160 )) {
3161 log("RX MT-forwardSM-Res (RP-ACK)");
3162 setverdict(pass);
3163 }
3164 [] GSUP.receive {
3165 log("RX unexpected GSUP message");
3166 setverdict(fail);
3167 mtc.stop;
3168 }
3169 }
3170
3171 f_expect_clear();
3172}
3173testcase TC_gsup_mo_mt_sms_rp_mr() runs on MTC_CT {
3174 var BSC_ConnHdlrPars pars;
3175 var BSC_ConnHdlr vc_conn;
3176 f_init();
3177 pars := f_init_pars(93);
3178 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
3179 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mo_mt_sms_rp_mr), pars);
3180 vc_conn.done;
3181 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
3182}
3183
Harald Weltee13cfb22019-04-23 16:52:02 +02003184
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07003185/* Test multi-part MT-SMS over GSUP */
3186private function f_tc_gsup_mt_multi_part_sms(charstring id, BSC_ConnHdlrPars pars)
3187runs on BSC_ConnHdlr {
3188 var SmsParameters spars := valueof(t_SmsPars);
3189
3190 f_init_handler(pars);
3191
3192 /* We need to inspect GSUP activity */
3193 f_create_gsup_expect(hex2str(g_pars.imsi));
3194
3195 /* Perform location update */
3196 f_perform_lu();
3197
3198 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01003199 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07003200
3201 var template GSUP_PDU mt_forwardSM_res := tr_GSUP_MT_FORWARD_SM_RES(
3202 imsi := g_pars.imsi,
3203 /* NOTE: MSC should assign RP-MR itself */
3204 sm_rp_mr := ?
3205 );
3206
3207 /* Send 4 messages (NOTE: SM-RP-UI remains unchanged) */
3208 for (var integer i := 3; i >= 0; i := i-1) {
3209 /* Submit a MT SMS on GSUP (MMS is decremented) */
3210 f_gsup_forwardSM_req(spars, int2oct(i, 1));
3211
3212 /* Expect Paging Request and Establish connection */
3213 if (i == 3) { /* ... only once! */
Harald Weltee13cfb22019-04-23 16:52:02 +02003214 f_expect_paging();
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07003215 f_establish_fully(EST_TYPE_PAG_RESP);
3216 }
3217
3218 /* Wait for MT SMS on DTAP */
3219 f_mt_sms_expect(spars);
3220
3221 /* Send RP-ACK and expect MT-forwardSM-Res on GSUP */
3222 f_mt_sms_send_rp_ack(spars);
3223 alt {
3224 [] GSUP.receive(mt_forwardSM_res) {
3225 log("RX MT-forwardSM-Res (RP-ACK)");
3226 setverdict(pass);
3227 }
3228 [] GSUP.receive {
3229 log("RX unexpected GSUP message");
3230 setverdict(fail);
3231 mtc.stop;
3232 }
3233 }
3234
3235 /* Keep some 'distance' between transmissions */
3236 f_sleep(1.5);
3237 }
3238
3239 f_expect_clear();
3240}
3241testcase TC_gsup_mt_multi_part_sms() runs on MTC_CT {
3242 var BSC_ConnHdlrPars pars;
3243 var BSC_ConnHdlr vc_conn;
3244 f_init();
3245 pars := f_init_pars(91);
3246 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
3247 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_multi_part_sms), pars);
3248 vc_conn.done;
3249 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
3250}
3251
Harald Weltef640a012018-04-14 17:49:21 +02003252/* convert GSM L3 TON to SMPP_TON enum */
3253function f_sm_ton_from_gsm(BIT3 ton) return SMPP_TON {
3254 select (ton) {
3255 case ('000'B) { return unknown; }
3256 case ('001'B) { return international; }
3257 case ('010'B) { return national; }
3258 case ('011'B) { return network_specific; }
3259 case ('100'B) { return subscriber_number; }
3260 case ('101'B) { return alphanumeric; }
3261 case ('110'B) { return abbreviated; }
3262 }
3263 setverdict(fail, "Unknown TON ", ton);
Daniel Willmannafce8662018-07-06 23:11:32 +02003264 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02003265}
3266/* convert GSM L3 NPI to SMPP_NPI enum */
3267function f_sm_npi_from_gsm(BIT4 npi) return SMPP_NPI {
3268 select (npi) {
3269 case ('0000'B) { return unknown; }
3270 case ('0001'B) { return isdn; }
3271 case ('0011'B) { return data; }
3272 case ('0100'B) { return telex; }
3273 case ('0110'B) { return land_mobile; }
3274 case ('1000'B) { return national; }
3275 case ('1001'B) { return private_; }
3276 case ('1010'B) { return ermes; }
3277 }
3278 setverdict(fail, "Unknown NPI ", npi);
Daniel Willmannafce8662018-07-06 23:11:32 +02003279 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02003280}
3281
3282/* build a SMPP_SM from SmsParameters */
3283function f_mt_sm_from_spars(SmsParameters spars)
3284runs on BSC_ConnHdlr return SMPP_SM {
3285 var SMPP_SM sm := {
3286 service_type := "CMT",
3287 source_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
3288 source_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
3289 source_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
3290 dest_addr_ton := international,
3291 dest_addr_npi := isdn,
3292 destination_addr := hex2str(g_pars.msisdn),
3293 esm_class := '00000001'B,
3294 protocol_id := 0,
3295 priority_flag := 0,
3296 schedule_delivery_time := "",
3297 validity_period := "",
3298 registered_delivery := '00000000'B,
3299 replace_if_present := 0,
3300 data_coding := '00000001'B,
3301 sm_default_msg_id := 0,
3302 sm_length := spars.tp.udl,
3303 short_message := spars.tp.ud,
3304 opt_pars := {}
3305 };
3306 return sm;
3307}
3308
3309/* helper function to encode SMS from 'spars', send it via SMPP to MSC; receive it on MS side */
3310private function f_smpp_mt_sms(SmsParameters spars, boolean trans_mode) runs on BSC_ConnHdlr {
3311 var SMPP_SM sm := f_mt_sm_from_spars(spars);
3312 if (trans_mode) {
3313 sm.esm_class := '00000010'B;
3314 }
3315
3316 /* actually cause MSC to send a SMS via SUBMIT-SM from SMPP side */
3317 SMPP.send(ts_SMPP_SUBMIT_SM(sm));
3318 if (not match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
3319 /* if we're not in SMPP transaction mode, we expect the SMPP-level ACK
3320 * before we expect the SMS delivery on the BSC/radio side */
3321 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
3322 }
3323
3324 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02003325 f_expect_paging();
Harald Weltef640a012018-04-14 17:49:21 +02003326 /* Establish DTAP / BSSAP / SCCP connection */
3327 f_establish_fully(EST_TYPE_PAG_RESP);
3328 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
3329
3330 f_mt_sms(spars);
3331
3332 if (match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
3333 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
3334 }
3335 f_expect_clear();
3336}
3337
3338/* mobile terminated SMS, from SMPP to BSC/BTS/MS */
3339private function f_tc_smpp_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3340 f_init_handler(pars);
3341
3342 /* Perform location update so IMSI is known + registered in MSC/VLR */
3343 f_perform_lu();
3344 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
3345
3346 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01003347 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Weltef640a012018-04-14 17:49:21 +02003348
3349 var SmsParameters spars := valueof(t_SmsPars);
3350 /* TODO: test with more intelligent user data; test different coding schemes */
3351 spars.tp.ud := '00'O;
3352 spars.tp.udl := 1;
3353
3354 /* first test the non-transaction store+forward mode */
3355 f_smpp_mt_sms(spars, false);
3356
3357 /* then test the transaction mode */
3358 f_smpp_mt_sms(spars, true);
3359}
3360testcase TC_smpp_mt_sms() runs on MTC_CT {
3361 var BSC_ConnHdlr vc_conn;
3362 f_init();
3363 vc_conn := f_start_handler(refers(f_tc_smpp_mt_sms), 45);
3364 vc_conn.done;
3365}
3366
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003367/***********************************************************************
3368 * USSD Testing
3369 ***********************************************************************/
3370
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003371private altstep as_unexp_gsup_or_bssap_msg()
3372runs on BSC_ConnHdlr {
3373 [] GSUP.receive {
3374 setverdict(fail, "Unknown/unexpected GSUP received");
3375 self.stop;
3376 }
3377 [] BSSAP.receive {
3378 setverdict(fail, "Unknown/unexpected BSSAP message received");
3379 self.stop;
3380 }
3381}
3382
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003383private function f_expect_gsup_msg(template GSUP_PDU msg,
3384 float T_val := 2.0)
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003385runs on BSC_ConnHdlr return GSUP_PDU {
3386 var GSUP_PDU gsup_msg_complete;
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003387 timer T := T_val;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003388
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003389 T.start;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003390 alt {
3391 [] GSUP.receive(msg) -> value gsup_msg_complete {
3392 setverdict(pass);
3393 }
3394 /* We don't expect anything else */
3395 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003396 [] T.timeout {
3397 setverdict(fail, "Timeout waiting for GSUP message: ", msg);
3398 }
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003399 }
3400
3401 return gsup_msg_complete;
3402}
3403
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003404private function f_expect_mt_dtap_msg(template PDU_ML3_NW_MS msg,
3405 float T_val := 2.0)
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003406runs on BSC_ConnHdlr return PDU_ML3_NW_MS {
3407 var PDU_DTAP_MT bssap_msg_complete;
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003408 timer T := T_val;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003409
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003410 T.start;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003411 alt {
3412 [] BSSAP.receive(tr_PDU_DTAP_MT(msg)) -> value bssap_msg_complete {
3413 setverdict(pass);
3414 }
3415 /* We don't expect anything else */
3416 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003417 [] T.timeout {
3418 setverdict(fail, "Timeout waiting for BSSAP message: ", msg);
3419 }
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003420 }
3421
3422 return bssap_msg_complete.dtap;
3423}
3424
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003425/* LU followed by MO USSD request */
Harald Weltee13cfb22019-04-23 16:52:02 +02003426friend function f_tc_lu_and_mo_ussd_single_request(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003427runs on BSC_ConnHdlr {
3428 f_init_handler(pars);
3429
3430 /* Perform location update */
3431 f_perform_lu();
3432
3433 /* Send CM Service Request for SS/USSD */
3434 f_establish_fully(EST_TYPE_SS_ACT);
3435
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003436 /* We need to inspect GSUP activity */
3437 f_create_gsup_expect(hex2str(g_pars.imsi));
3438
3439 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3440 invoke_id := 5, /* Phone may not start from 0 or 1 */
3441 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3442 ussd_string := "*#100#"
3443 );
3444
3445 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3446 invoke_id := 5, /* InvokeID shall be the same for both REQ and RSP */
3447 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3448 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
3449 )
3450
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003451 /* Compose a new SS/REGISTER message with request */
3452 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
3453 tid := 1, /* We just need a single transaction */
3454 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003455 facility := valueof(facility_req)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003456 );
3457
3458 /* Compose SS/RELEASE_COMPLETE template with expected response */
3459 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
3460 tid := 1, /* Response should arrive within the same transaction */
3461 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003462 facility := valueof(facility_rsp)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003463 );
3464
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003465 /* Compose expected MSC -> HLR message */
3466 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
3467 imsi := g_pars.imsi,
3468 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3469 ss := valueof(facility_req)
3470 );
3471
3472 /* To be used for sending response with correct session ID */
3473 var GSUP_PDU gsup_req_complete;
3474
3475 /* Request own number */
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003476 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003477 /* Expect GSUP message containing the SS payload */
3478 gsup_req_complete := f_expect_gsup_msg(gsup_req);
3479
3480 /* Compose the response from HLR using received session ID */
3481 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
3482 imsi := g_pars.imsi,
3483 sid := gsup_req_complete.ies[1].val.session_id,
3484 state := OSMO_GSUP_SESSION_STATE_END,
3485 ss := valueof(facility_rsp)
3486 );
3487
3488 /* Finally, HLR terminates the session */
3489 GSUP.send(gsup_rsp);
3490 /* Expect RELEASE_COMPLETE message with the response */
3491 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003492
3493 f_expect_clear();
3494}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003495testcase TC_lu_and_mo_ussd_single_request() runs on MTC_CT {
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003496 var BSC_ConnHdlr vc_conn;
3497 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003498 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_single_request), 46);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003499 vc_conn.done;
3500}
3501
Harald Weltee13cfb22019-04-23 16:52:02 +02003502
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003503/* LU followed by MT USSD notification */
Harald Weltee13cfb22019-04-23 16:52:02 +02003504friend function f_tc_lu_and_mt_ussd_notification(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003505runs on BSC_ConnHdlr {
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003506 timer T := 5.0;
3507
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003508 f_init_handler(pars);
3509
3510 /* Perform location update */
3511 f_perform_lu();
3512
Harald Welte6811d102019-04-14 22:23:14 +02003513 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003514
3515 /* We need to inspect GSUP activity */
3516 f_create_gsup_expect(hex2str(g_pars.imsi));
3517
3518 /* Facility IE with network-originated USSD notification */
3519 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3520 op_code := SS_OP_CODE_USS_NOTIFY,
3521 ussd_string := "Mahlzeit!"
3522 );
3523
3524 /* Facility IE with acknowledgment to the USSD notification */
3525 var template OCTN facility_rsp := enc_SS_FacilityInformation(
3526 /* In case of USSD notification, Return Result is empty */
3527 valueof(ts_SS_USSD_FACILITY_RETURN_RESULT_EMPTY())
3528 );
3529
3530 /* Compose a new MT SS/REGISTER message with USSD notification */
3531 var template PDU_ML3_NW_MS ussd_ntf := tr_ML3_MT_SS_REGISTER(
3532 tid := 0, /* FIXME: most likely, it should be 0 */
3533 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3534 facility := valueof(facility_req)
3535 );
3536
3537 /* Compose HLR -> MSC GSUP message */
3538 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3539 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003540 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003541 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3542 ss := valueof(facility_req)
3543 );
3544
3545 /* Send it to MSC and expect Paging Request */
3546 GSUP.send(gsup_req);
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003547 T.start;
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003548 alt {
Harald Weltee13cfb22019-04-23 16:52:02 +02003549 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
3550 setverdict(pass);
3551 }
Harald Welte62113fc2019-05-09 13:04:02 +02003552 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003553 setverdict(pass);
3554 }
3555 /* We don't expect anything else */
3556 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003557 [] T.timeout {
3558 setverdict(fail, "Timeout waiting for Paging Request");
3559 }
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003560 }
3561
3562 /* Send Paging Response and expect USSD notification */
3563 f_establish_fully(EST_TYPE_PAG_RESP);
3564 /* Expect MT REGISTER message with USSD notification */
3565 f_expect_mt_dtap_msg(ussd_ntf);
3566
3567 /* Compose a new MO SS/FACILITY message with empty response */
3568 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
3569 tid := 0, /* FIXME: it shall match the request tid */
3570 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3571 facility := valueof(facility_rsp)
3572 );
3573
3574 /* Compose expected MSC -> HLR GSUP message */
3575 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
3576 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003577 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003578 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3579 ss := valueof(facility_rsp)
3580 );
3581
3582 /* MS sends response to the notification */
3583 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
3584 /* Expect GSUP message containing the SS payload */
3585 f_expect_gsup_msg(gsup_rsp);
3586
3587 /* Compose expected MT SS/RELEASE COMPLETE message */
3588 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
3589 tid := 0, /* FIXME: it shall match the request tid */
3590 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3591 facility := omit
3592 );
3593
3594 /* Compose MSC -> HLR GSUP message */
3595 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
3596 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003597 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003598 state := OSMO_GSUP_SESSION_STATE_END
3599 );
3600
3601 /* Finally, HLR terminates the session */
3602 GSUP.send(gsup_term)
3603 /* Expect MT RELEASE COMPLETE without Facility IE */
3604 f_expect_mt_dtap_msg(ussd_term);
3605
3606 f_expect_clear();
3607}
3608testcase TC_lu_and_mt_ussd_notification() runs on MTC_CT {
3609 var BSC_ConnHdlr vc_conn;
3610 f_init();
3611 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_notification), 47);
3612 vc_conn.done;
3613}
3614
Harald Weltee13cfb22019-04-23 16:52:02 +02003615
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003616/* LU followed by MT call and MO USSD request during this call */
Harald Weltee13cfb22019-04-23 16:52:02 +02003617friend function f_tc_lu_and_mo_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003618runs on BSC_ConnHdlr {
3619 f_init_handler(pars);
3620
3621 /* Call parameters taken from f_tc_lu_and_mt_call */
3622 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003623
3624 /* Perform location update */
3625 f_perform_lu();
3626
3627 /* Establish a MT call */
3628 f_mt_call_establish(cpars);
3629
3630 /* Hold the call for some time */
3631 f_sleep(1.0);
3632
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003633 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3634 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3635 ussd_string := "*#100#"
3636 );
3637
3638 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3639 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3640 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
3641 )
3642
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003643 /* Compose a new SS/REGISTER message with request */
3644 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
3645 tid := 1, /* We just need a single transaction */
3646 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003647 facility := valueof(facility_req)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003648 );
3649
3650 /* Compose SS/RELEASE_COMPLETE template with expected response */
3651 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
3652 tid := 1, /* Response should arrive within the same transaction */
3653 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003654 facility := valueof(facility_rsp)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003655 );
3656
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003657 /* Compose expected MSC -> HLR message */
3658 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
3659 imsi := g_pars.imsi,
3660 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3661 ss := valueof(facility_req)
3662 );
3663
3664 /* To be used for sending response with correct session ID */
3665 var GSUP_PDU gsup_req_complete;
3666
3667 /* Request own number */
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003668 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003669 /* Expect GSUP message containing the SS payload */
3670 gsup_req_complete := f_expect_gsup_msg(gsup_req);
3671
3672 /* Compose the response from HLR using received session ID */
3673 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
3674 imsi := g_pars.imsi,
3675 sid := gsup_req_complete.ies[1].val.session_id,
3676 state := OSMO_GSUP_SESSION_STATE_END,
3677 ss := valueof(facility_rsp)
3678 );
3679
3680 /* Finally, HLR terminates the session */
3681 GSUP.send(gsup_rsp);
3682 /* Expect RELEASE_COMPLETE message with the response */
3683 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003684
3685 /* Hold the call for some time */
3686 f_sleep(1.0);
3687
3688 /* Release the call (does Clear Complete itself) */
3689 f_call_hangup(cpars, true);
3690}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003691testcase TC_lu_and_mo_ussd_during_mt_call() runs on MTC_CT {
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003692 var BSC_ConnHdlr vc_conn;
3693 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003694 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_during_mt_call), 48);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003695 vc_conn.done;
3696}
3697
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003698/* BSSMAP Clear Request in the middle of a call, see OS#3062 */
Harald Weltee13cfb22019-04-23 16:52:02 +02003699friend function f_tc_mo_cc_bssmap_clear(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003700 f_init_handler(pars);
3701 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02003702 cpars.ran_clear_when_alerting := true;
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003703
3704 f_perform_lu();
3705
Neels Hofmeyrde76f052019-02-26 05:02:46 +01003706 var default ccrel := activate(as_optional_cc_rel(cpars));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02003707 f_mo_call_establish(cpars);
3708 f_expect_clear()
Neels Hofmeyrde76f052019-02-26 05:02:46 +01003709 deactivate(ccrel);
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003710
3711 f_sleep(1.0);
3712}
3713testcase TC_mo_cc_bssmap_clear() runs on MTC_CT {
3714 var BSC_ConnHdlr vc_conn;
3715 f_init();
3716
3717 vc_conn := f_start_handler(refers(f_tc_mo_cc_bssmap_clear), 43);
3718 vc_conn.done;
3719}
3720
Harald Weltee13cfb22019-04-23 16:52:02 +02003721
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003722/* LU followed by MT call and MT USSD request during this call */
Harald Weltee13cfb22019-04-23 16:52:02 +02003723friend function f_tc_lu_and_mt_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003724runs on BSC_ConnHdlr {
3725 f_init_handler(pars);
3726
3727 /* Call parameters taken from f_tc_lu_and_mt_call */
3728 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003729
3730 /* Perform location update */
3731 f_perform_lu();
3732
3733 /* Establish a MT call */
3734 f_mt_call_establish(cpars);
3735
3736 /* Hold the call for some time */
3737 f_sleep(1.0);
3738
3739 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3740 op_code := SS_OP_CODE_USS_REQUEST,
3741 ussd_string := "Please type anything..."
3742 );
3743
3744 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3745 op_code := SS_OP_CODE_USS_REQUEST,
3746 ussd_string := "Nope."
3747 )
3748
3749 /* Compose MT SS/REGISTER message with network-originated request */
3750 var template (value) PDU_ML3_NW_MS ussd_req := ts_ML3_MT_SS_REGISTER(
3751 tid := 0, /* FIXME: most likely, it should be 0 */
3752 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3753 facility := valueof(facility_req)
3754 );
3755
3756 /* Compose HLR -> MSC GSUP message */
3757 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3758 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003759 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003760 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3761 ss := valueof(facility_req)
3762 );
3763
3764 /* Send it to MSC */
3765 GSUP.send(gsup_req);
3766 /* Expect MT REGISTER message with USSD request */
3767 f_expect_mt_dtap_msg(ussd_req);
3768
3769 /* Compose a new MO SS/FACILITY message with response */
3770 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
3771 tid := 0, /* FIXME: it shall match the request tid */
3772 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3773 facility := valueof(facility_rsp)
3774 );
3775
3776 /* Compose expected MSC -> HLR GSUP message */
3777 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
3778 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003779 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003780 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3781 ss := valueof(facility_rsp)
3782 );
3783
3784 /* MS sends response */
3785 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
3786 f_expect_gsup_msg(gsup_rsp);
3787
3788 /* Compose expected MT SS/RELEASE COMPLETE message */
3789 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
3790 tid := 0, /* FIXME: it shall match the request tid */
3791 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3792 facility := omit
3793 );
3794
3795 /* Compose MSC -> HLR GSUP message */
3796 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
3797 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003798 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003799 state := OSMO_GSUP_SESSION_STATE_END
3800 );
3801
3802 /* Finally, HLR terminates the session */
3803 GSUP.send(gsup_term);
3804 /* Expect MT RELEASE COMPLETE without Facility IE */
3805 f_expect_mt_dtap_msg(ussd_term);
3806
3807 /* Hold the call for some time */
3808 f_sleep(1.0);
3809
3810 /* Release the call (does Clear Complete itself) */
3811 f_call_hangup(cpars, true);
3812}
3813testcase TC_lu_and_mt_ussd_during_mt_call() runs on MTC_CT {
3814 var BSC_ConnHdlr vc_conn;
3815 f_init();
3816 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_during_mt_call), 49);
3817 vc_conn.done;
3818}
3819
Harald Weltee13cfb22019-04-23 16:52:02 +02003820
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07003821/* LU followed by MO USSD request and MO Release during transaction */
Harald Weltee13cfb22019-04-23 16:52:02 +02003822friend function f_tc_lu_and_mo_ussd_mo_release(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07003823runs on BSC_ConnHdlr {
3824 f_init_handler(pars);
3825
3826 /* Perform location update */
3827 f_perform_lu();
3828
3829 /* Send CM Service Request for SS/USSD */
3830 f_establish_fully(EST_TYPE_SS_ACT);
3831
3832 /* We need to inspect GSUP activity */
3833 f_create_gsup_expect(hex2str(g_pars.imsi));
3834
3835 var template OCTN facility_ms_req := f_USSD_FACILITY_IE_INVOKE(
3836 invoke_id := 1, /* Initial request */
3837 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3838 ussd_string := "*6766*266#"
3839 );
3840
3841 var template OCTN facility_net_req := f_USSD_FACILITY_IE_INVOKE(
3842 invoke_id := 2, /* Counter request */
3843 op_code := SS_OP_CODE_USS_REQUEST,
3844 ussd_string := "Password?!?"
3845 )
3846
3847 /* Compose MO SS/REGISTER message with request */
3848 var template (value) PDU_ML3_MS_NW ussd_ms_req := ts_ML3_MO_SS_REGISTER(
3849 tid := 1, /* We just need a single transaction */
3850 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3851 facility := valueof(facility_ms_req)
3852 );
3853
3854 /* Compose expected MSC -> HLR message */
3855 var template GSUP_PDU gsup_ms_req := tr_GSUP_PROC_SS_REQ(
3856 imsi := g_pars.imsi,
3857 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3858 ss := valueof(facility_ms_req)
3859 );
3860
3861 /* To be used for sending response with correct session ID */
3862 var GSUP_PDU gsup_ms_req_complete;
3863
3864 /* Initiate a new transaction */
3865 BSSAP.send(ts_PDU_DTAP_MO(ussd_ms_req));
3866 /* Expect GSUP request with original Facility IE */
3867 gsup_ms_req_complete := f_expect_gsup_msg(gsup_ms_req);
3868
3869 /* Compose the response from HLR using received session ID */
3870 var template (value) GSUP_PDU gsup_net_req := ts_GSUP_PROC_SS_REQ(
3871 imsi := g_pars.imsi,
3872 sid := gsup_ms_req_complete.ies[1].val.session_id,
3873 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3874 ss := valueof(facility_net_req)
3875 );
3876
3877 /* Compose expected MT SS/FACILITY template with counter request */
3878 var template PDU_ML3_NW_MS ussd_net_req := tr_ML3_MT_SS_FACILITY(
3879 tid := 1, /* Response should arrive within the same transaction */
3880 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3881 facility := valueof(facility_net_req)
3882 );
3883
3884 /* Send response over GSUP */
3885 GSUP.send(gsup_net_req);
3886 /* Expect MT SS/FACILITY message with counter request */
3887 f_expect_mt_dtap_msg(ussd_net_req);
3888
3889 /* Compose MO SS/RELEASE COMPLETE */
3890 var template (value) PDU_ML3_MS_NW ussd_abort := ts_ML3_MO_SS_RELEASE_COMPLETE(
3891 tid := 1, /* Response should arrive within the same transaction */
3892 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3893 facility := omit
3894 /* TODO: cause? */
3895 );
3896
3897 /* Compose expected HLR -> MSC abort message */
3898 var template GSUP_PDU gsup_abort := tr_GSUP_PROC_SS_REQ(
3899 imsi := g_pars.imsi,
3900 sid := gsup_ms_req_complete.ies[1].val.session_id,
3901 state := OSMO_GSUP_SESSION_STATE_END
3902 );
3903
3904 /* Abort transaction */
3905 BSSAP.send(ts_PDU_DTAP_MO(ussd_abort));
3906 /* Expect GSUP message indicating abort */
3907 f_expect_gsup_msg(gsup_abort);
3908
3909 f_expect_clear();
3910}
3911testcase TC_lu_and_mo_ussd_mo_release() runs on MTC_CT {
3912 var BSC_ConnHdlr vc_conn;
3913 f_init();
3914 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_mo_release), 50);
3915 vc_conn.done;
3916}
3917
Harald Weltee13cfb22019-04-23 16:52:02 +02003918
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003919/* LU followed by MO USSD request and MT Release due to timeout */
Harald Weltee13cfb22019-04-23 16:52:02 +02003920friend function f_tc_lu_and_ss_session_timeout(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003921runs on BSC_ConnHdlr {
3922 f_init_handler(pars);
3923
3924 /* Perform location update */
3925 f_perform_lu();
3926
3927 /* Send CM Service Request for SS/USSD */
3928 f_establish_fully(EST_TYPE_SS_ACT);
3929
3930 /* We need to inspect GSUP activity */
3931 f_create_gsup_expect(hex2str(g_pars.imsi));
3932
3933 var template OCTN facility_ms_req := f_USSD_FACILITY_IE_INVOKE(
3934 invoke_id := 1,
3935 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3936 ussd_string := "#release_me");
3937
3938 /* Compose MO SS/REGISTER message with request */
3939 var template (value) PDU_ML3_MS_NW ussd_ms_req := ts_ML3_MO_SS_REGISTER(
3940 tid := 1, /* An arbitrary transaction identifier */
3941 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3942 facility := valueof(facility_ms_req));
3943
3944 /* Compose expected MSC -> HLR message */
3945 var template GSUP_PDU gsup_ms_req := tr_GSUP_PROC_SS_REQ(
3946 imsi := g_pars.imsi,
3947 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3948 ss := valueof(facility_ms_req));
3949
3950 /* To be used for sending response with correct session ID */
3951 var GSUP_PDU gsup_ms_req_complete;
3952
3953 /* Initiate a new SS transaction */
3954 BSSAP.send(ts_PDU_DTAP_MO(ussd_ms_req));
3955 /* Expect GSUP request with original Facility IE */
3956 gsup_ms_req_complete := f_expect_gsup_msg(gsup_ms_req);
3957
3958 /* Don't respond, wait for timeout */
3959 f_sleep(3.0);
3960
3961 var template PDU_ML3_NW_MS dtap_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
3962 tid := 1, /* Should match the request's tid */
3963 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3964 cause := *, /* TODO: expect some specific value */
3965 facility := omit);
3966
3967 var template GSUP_PDU gsup_rel := tr_GSUP_PROC_SS_ERR(
3968 imsi := g_pars.imsi,
3969 sid := gsup_ms_req_complete.ies[1].val.session_id,
3970 state := OSMO_GSUP_SESSION_STATE_END,
3971 cause := ?); /* TODO: expect some specific value */
3972
3973 /* Expect release on both interfaces */
3974 interleave {
3975 [] BSSAP.receive(tr_PDU_DTAP_MT(dtap_rel)) { };
3976 [] GSUP.receive(gsup_rel) { };
3977 }
3978
3979 f_expect_clear();
3980 setverdict(pass);
3981}
3982testcase TC_lu_and_ss_session_timeout() runs on MTC_CT {
3983 var BSC_ConnHdlr vc_conn;
3984 f_init();
Vadim Yanitskiy36d28dd2018-12-03 02:45:45 +07003985 f_vty_config(MSCVTY, "msc", "ncss guard-timeout 3");
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003986 vc_conn := f_start_handler(refers(f_tc_lu_and_ss_session_timeout), 51);
3987 vc_conn.done;
Vadim Yanitskiy36d28dd2018-12-03 02:45:45 +07003988 f_vty_config(MSCVTY, "msc", "ncss guard-timeout 0");
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003989}
3990
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07003991/* MT (network-originated) USSD for unknown subscriber */
3992friend function f_tc_mt_ussd_for_unknown_subscr(charstring id, BSC_ConnHdlrPars pars)
3993runs on BSC_ConnHdlr {
3994 var hexstring imsi := '000000000000000'H; /* Some unknown IMSI */
3995 var OCT4 sid := '20000222'O;
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07003996
3997 f_init_handler(pars);
3998 f_ran_register_imsi(imsi, 'FFFFFFFF'O);
3999 f_create_gsup_expect(hex2str(imsi));
4000
4001 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
4002 imsi := imsi,
4003 sid := sid,
4004 state := OSMO_GSUP_SESSION_STATE_BEGIN,
4005 ss := f_rnd_octstring(23)
4006 );
4007
4008 /* Error with cause GMM_CAUSE_IMSI_UNKNOWN */
4009 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
4010 imsi := imsi,
4011 sid := sid,
4012 state := OSMO_GSUP_SESSION_STATE_END,
4013 cause := 2 /* FIXME: introduce an enumerated type! */
4014 );
4015
4016 /* Initiate a MT USSD notification */
4017 GSUP.send(gsup_req);
4018
4019 /* Expect GSUP PROC_SS_ERROR message */
Vadim Yanitskiy851798c2019-06-15 14:22:28 +07004020 f_expect_gsup_msg(gsup_rsp);
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07004021}
4022testcase TC_mt_ussd_for_unknown_subscr() runs on MTC_CT {
4023 var BSC_ConnHdlr vc_conn;
4024 f_init();
4025 vc_conn := f_start_handler(refers(f_tc_mt_ussd_for_unknown_subscr), 0);
4026 vc_conn.done;
4027}
4028
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07004029/* MO (mobile-originated) SS/USSD for unknown transaction */
4030friend function f_tc_mo_ussd_for_unknown_trans(charstring id, BSC_ConnHdlrPars pars)
4031runs on BSC_ConnHdlr {
4032 f_init_handler(pars);
4033
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01004034 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07004035 f_create_gsup_expect(hex2str(g_pars.imsi));
4036
4037 /* Perform location update */
4038 f_perform_lu();
4039
4040 /* Send CM Service Request for SS/USSD */
4041 f_establish_fully(EST_TYPE_SS_ACT);
4042
4043 /* GSM 04.80 FACILITY message for a non-existing transaction */
4044 var template (value) PDU_ML3_MS_NW mo_ss_fac := ts_ML3_MO_SS_FACILITY(
4045 tid := 1, /* An arbitrary transaction identifier */
4046 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
4047 facility := f_rnd_octstring(23) /* We don't care about the Facility IE */
4048 );
4049
4050 /* GSM 04.80 RELEASE COMPLETE message for a non-existing transaction */
4051 var template (value) PDU_ML3_MS_NW mo_ss_rel := ts_ML3_MO_SS_RELEASE_COMPLETE(
4052 tid := 1, /* An arbitrary transaction identifier */
4053 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
4054 facility := f_rnd_octstring(23) /* We don't care about the Facility IE */
4055 );
4056
4057 /* Expected response from the network */
4058 var template PDU_ML3_NW_MS mt_ss_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
4059 tid := 1, /* Same as in the FACILITY message */
4060 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
4061 facility := omit
4062 );
4063
4064 /* Send GSM 04.80 FACILITY for non-existing transaction */
4065 BSSAP.send(ts_PDU_DTAP_MO(mo_ss_fac));
4066
4067 /* Expect GSM 04.80 RELEASE COMPLETE message */
4068 f_expect_mt_dtap_msg(mt_ss_rel);
4069 f_expect_clear();
4070
4071 /* Send another CM Service Request for SS/USSD */
4072 f_establish_fully(EST_TYPE_SS_ACT);
4073
4074 /* Send GSM 04.80 RELEASE COMPLETE for non-existing transaction */
4075 BSSAP.send(ts_PDU_DTAP_MO(mo_ss_rel));
4076
4077 /* Expect GSM 04.80 RELEASE COMPLETE message */
4078 f_expect_mt_dtap_msg(mt_ss_rel);
4079 f_expect_clear();
4080}
4081testcase TC_mo_ussd_for_unknown_trans() runs on MTC_CT {
4082 var BSC_ConnHdlr vc_conn;
4083 f_init();
4084 vc_conn := f_start_handler(refers(f_tc_mo_ussd_for_unknown_trans), 111);
4085 vc_conn.done;
4086}
4087
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07004088/* MT (network-originated) USSD for unknown session */
4089friend function f_tc_proc_ss_for_unknown_session(charstring id, BSC_ConnHdlrPars pars)
4090runs on BSC_ConnHdlr {
4091 var OCT4 sid := '20000333'O;
4092
4093 f_init_handler(pars);
4094
4095 /* Perform location update */
4096 f_perform_lu();
4097
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01004098 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07004099 f_create_gsup_expect(hex2str(g_pars.imsi));
4100
4101 /* Request referencing a non-existing SS session */
4102 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
4103 imsi := g_pars.imsi,
4104 sid := sid,
4105 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
4106 ss := f_rnd_octstring(23)
4107 );
4108
4109 /* Error with some cause value */
4110 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
4111 imsi := g_pars.imsi,
4112 sid := sid,
4113 state := OSMO_GSUP_SESSION_STATE_END,
4114 cause := ? /* FIXME: introduce an enumerated type! */
4115 );
4116
4117 /* Initiate a MT USSD notification */
4118 GSUP.send(gsup_req);
4119
4120 /* Expect GSUP PROC_SS_ERROR message */
4121 f_expect_gsup_msg(gsup_rsp);
4122}
4123testcase TC_proc_ss_for_unknown_session() runs on MTC_CT {
4124 var BSC_ConnHdlr vc_conn;
4125 f_init();
4126 vc_conn := f_start_handler(refers(f_tc_proc_ss_for_unknown_session), 110);
4127 vc_conn.done;
4128}
4129
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07004130/* MT (network-originated) USSD and no response to Paging Request */
4131friend function f_tc_proc_ss_paging_fail(charstring id, BSC_ConnHdlrPars pars)
4132runs on BSC_ConnHdlr {
4133 timer TP := 2.0; /* Paging timer */
4134
4135 f_init_handler(pars);
4136
4137 /* Perform location update */
4138 f_perform_lu();
4139
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01004140 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07004141 f_create_gsup_expect(hex2str(g_pars.imsi));
4142
4143 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
4144 imsi := g_pars.imsi,
4145 sid := '20000444'O,
4146 state := OSMO_GSUP_SESSION_STATE_BEGIN,
4147 ss := f_rnd_octstring(23)
4148 );
4149
4150 /* Error with some cause value */
4151 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
4152 imsi := g_pars.imsi,
4153 sid := '20000444'O,
4154 state := OSMO_GSUP_SESSION_STATE_END,
4155 cause := ? /* FIXME: introduce an enumerated type! */
4156 );
4157
4158 /* Initiate a MT USSD notification */
4159 GSUP.send(gsup_req);
4160
4161 /* Send it to MSC and expect Paging Request */
4162 TP.start;
4163 alt {
4164 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
4165 setverdict(pass);
4166 }
4167 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
4168 setverdict(pass);
4169 }
4170 /* We don't expect anything else */
4171 [] as_unexp_gsup_or_bssap_msg();
4172 [] TP.timeout {
4173 setverdict(fail, "Timeout waiting for Paging Request");
4174 }
4175 }
4176
Vadim Yanitskiyd24b5252019-10-02 00:04:51 +07004177 /* Wait up to 20 seconds for GSUP PROC_SS_ERROR message.
4178 * OsmoMSC waits for Paging Response 10 seconds by default. */
4179 f_expect_gsup_msg(gsup_rsp, T_val := 20.0);
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07004180}
4181testcase TC_proc_ss_paging_fail() runs on MTC_CT {
4182 var BSC_ConnHdlr vc_conn;
4183 f_init();
4184 vc_conn := f_start_handler(refers(f_tc_proc_ss_paging_fail), 101);
4185 vc_conn.done;
4186}
4187
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07004188/* MT (network-originated) USSD followed by immediate abort */
4189friend function f_tc_proc_ss_abort(charstring id, BSC_ConnHdlrPars pars)
4190runs on BSC_ConnHdlr {
4191 var octetstring facility := f_rnd_octstring(23);
4192 var OCT4 sid := '20000555'O;
4193 timer TP := 2.0;
4194
4195 f_init_handler(pars);
4196
4197 /* Perform location update */
4198 f_perform_lu();
4199
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01004200 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07004201 f_create_gsup_expect(hex2str(g_pars.imsi));
4202
4203 /* PROC_SS_REQ initiates a mobile-originated SS/USSD session */
4204 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
4205 imsi := g_pars.imsi, sid := sid,
4206 state := OSMO_GSUP_SESSION_STATE_BEGIN,
4207 ss := facility
4208 );
4209
4210 /* On the MS side, we expect GSM 04.80 REGISTER message */
4211 var template PDU_ML3_NW_MS dtap_reg := tr_ML3_MT_SS_REGISTER(
4212 tid := 0, /* Most likely, it should be 0 */
4213 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
4214 facility := facility
4215 );
4216
4217 /* PROC_SS_ERR with SESSION_STATE_END terminates the SS/USSD session */
4218 var template (value) GSUP_PDU gsup_abort := ts_GSUP_PROC_SS_ERR(
4219 imsi := g_pars.imsi, sid := sid,
4220 state := OSMO_GSUP_SESSION_STATE_END,
4221 cause := 0 /* FIXME: introduce an enumerated type! */
4222 );
4223
4224 /* On the MS side, we expect GSM 04.80 REGISTER message */
4225 var template PDU_ML3_NW_MS dtap_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
4226 tid := 0, /* Most likely, it should be 0 */
4227 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
4228 cause := *, /* FIXME: expect some specific cause value */
4229 facility := omit
4230 );
4231
4232 /* Initiate a MT USSD with random payload */
4233 GSUP.send(gsup_req);
4234
4235 /* Expect Paging Request */
4236 TP.start;
4237 alt {
4238 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
4239 setverdict(pass);
4240 }
4241 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
4242 setverdict(pass);
4243 }
4244 /* We don't expect anything else */
4245 [] as_unexp_gsup_or_bssap_msg();
4246 [] TP.timeout {
4247 setverdict(fail, "Timeout waiting for Paging Request");
4248 }
4249 }
4250
4251 /* Send Paging Response and establish connection */
4252 f_establish_fully(EST_TYPE_PAG_RESP);
4253 /* Expect MT REGISTER message with random facility */
4254 f_expect_mt_dtap_msg(dtap_reg);
4255
4256 /* HLR/EUSE decides to abort the session even
4257 * before getting any response from the MS */
4258 /* Initiate a MT USSD with random payload */
4259 GSUP.send(gsup_abort);
4260
4261 /* Expect RELEASE COMPLETE on ths MS side */
4262 f_expect_mt_dtap_msg(dtap_rel);
4263
4264 f_expect_clear();
4265}
4266testcase TC_proc_ss_abort() runs on MTC_CT {
4267 var BSC_ConnHdlr vc_conn;
4268 f_init();
4269 vc_conn := f_start_handler(refers(f_tc_proc_ss_abort), 102);
4270 vc_conn.done;
4271}
4272
Harald Weltee13cfb22019-04-23 16:52:02 +02004273
Vadim Yanitskiy1c9754d2020-01-07 21:56:55 +01004274/* Verify multiple concurrent MO SS/USSD transactions
4275 * (one subscriber - one transaction) */
4276testcase TC_multi_lu_and_mo_ussd() runs on MTC_CT {
4277 var BSC_ConnHdlr vc_conn[16];
4278 var integer i;
4279
4280 f_init();
4281
4282 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
4283 vc_conn[i] := f_start_handler(refers(f_tc_lu_and_mo_ussd_single_request), 210 + i);
4284 }
4285
4286 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
4287 vc_conn[i].done;
4288 }
4289}
4290
4291/* Verify multiple concurrent MT SS/USSD transactions
4292 * (one subscriber - one transaction) */
4293testcase TC_multi_lu_and_mt_ussd() runs on MTC_CT {
4294 var BSC_ConnHdlr vc_conn[16];
4295 var integer i;
4296 var OCT4 sid;
4297
4298 f_init();
4299
4300 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
4301 sid := '200001'O & int2oct(i, 1); /* All transactions must use different session ID */
4302 vc_conn[i] := f_start_handler_with_pars(refers(f_tc_lu_and_mt_ussd_notification),
4303 f_init_pars(226 + i, gsup_sid := sid));
4304 }
4305
4306 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
4307 vc_conn[i].done;
4308 }
4309}
4310
4311
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004312/* A5/1 only permitted on network side; attempt an invalid CIPHER MODE COMPLETE with A5/3 which MSC should reject. */
4313private function f_tc_cipher_complete_with_invalid_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4314 pars.net.expect_auth := true;
4315 pars.net.expect_ciph := true;
4316 pars.net.kc_support := '02'O; /* A5/1 only */
4317 f_init_handler(pars);
4318
4319 g_pars.vec := f_gen_auth_vec_2g();
4320
4321 /* Can't use f_perform_lu() directly. Code below is based on it. */
4322
4323 /* tell GSUP dispatcher to send this IMSI to us */
4324 f_create_gsup_expect(hex2str(g_pars.imsi));
4325
4326 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
4327 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
Harald Weltedceacc72019-04-21 20:58:35 +02004328 f_cl3_or_initial_ue(l3_lu);
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004329
4330 f_mm_auth();
4331
4332 var OCT1 a5_net := f_alg_mask_from_cm(g_pars.cm2);
4333 var OCT1 a5_intersect := g_pars.net.kc_support and4b a5_net;
4334 alt {
4335 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(a5_intersect, g_pars.vec.kc)) {
4336 BSSAP.send(ts_BSSMAP_CipherModeCompl(int2oct(4 /* "accept" A5/3 */, 1)));
4337 }
4338 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?, g_pars.vec.kc)) {
4339 setverdict(fail, "Wrong ciphering algorithm mask in CiphModCmd");
4340 mtc.stop;
4341 }
4342 [] BSSAP.receive {
4343 setverdict(fail, "Unknown/unexpected BSSAP received");
4344 mtc.stop;
4345 }
4346 }
Harald Welte79f1e452020-08-18 22:55:02 +02004347 f_expect_common_id();
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004348
4349 /* Expect LU reject from MSC. */
4350 alt {
4351 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
4352 setverdict(pass);
4353 }
4354 [] BSSAP.receive {
4355 setverdict(fail, "Unknown/unexpected BSSAP received");
4356 mtc.stop;
4357 }
4358 }
Stefan Sperlingc620b352018-12-18 17:23:36 +01004359 f_expect_clear();
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004360}
4361
4362testcase TC_cipher_complete_with_invalid_cipher() runs on MTC_CT {
4363 var BSC_ConnHdlr vc_conn;
4364 f_init();
4365 f_vty_config(MSCVTY, "network", "encryption a5 1");
4366
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02004367 vc_conn := f_start_handler(refers(f_tc_cipher_complete_with_invalid_cipher), 52, verify_cell_id := false);
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004368 vc_conn.done;
4369}
4370
Harald Welteb2284bd2019-05-10 11:30:43 +02004371/* Location Update with invalid (non-matching) MCC/MNC reported on BSSMAP level from BSC */
4372friend function f_tc_lu_with_invalid_mcc_mnc(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4373 f_init_handler(pars);
4374
4375 /* tell GSUP dispatcher to send this IMSI to us */
4376 f_create_gsup_expect(hex2str(g_pars.imsi));
4377
4378 /* modify the cell ID which will be used to construct the COMPLELTE L3 or InitialUE */
4379 g_pars.cell_id := valueof(ts_CellId_CGI('333'H, '22'H, 23, 42));
4380
4381 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
4382 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
4383 f_cl3_or_initial_ue(l3_lu);
Harald Welte79f1e452020-08-18 22:55:02 +02004384 f_expect_common_id();
Harald Welteb2284bd2019-05-10 11:30:43 +02004385
4386 /* Expect LU reject from MSC. */
4387 alt {
4388 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
4389 setverdict(pass);
4390 }
4391 [] BSSAP.receive {
4392 setverdict(fail, "Unknown/unexpected BSSAP received");
4393 mtc.stop;
4394 }
4395 }
4396 f_expect_clear();
4397}
4398testcase TC_lu_with_invalid_mcc_mnc() runs on MTC_CT {
4399 var BSC_ConnHdlr vc_conn;
4400 f_init();
4401 vc_conn := f_start_handler(refers(f_tc_lu_with_invalid_mcc_mnc), 54);
4402 vc_conn.done;
4403}
4404
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01004405private function f_tc_cipher_complete_without_alg(charstring id, BSC_ConnHdlrPars pars, octetstring kc_support) runs on BSC_ConnHdlr {
4406 pars.net.expect_auth := true;
4407 pars.net.expect_ciph := true;
4408 pars.net.kc_support := kc_support;
4409 f_init_handler(pars);
4410
4411 g_pars.vec := f_gen_auth_vec_2g();
4412
4413 /* Can't use f_perform_lu() directly. Code below is based on it. */
4414
4415 /* tell GSUP dispatcher to send this IMSI to us */
4416 f_create_gsup_expect(hex2str(g_pars.imsi));
4417
4418 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
4419 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
4420 f_cl3_or_initial_ue(l3_lu);
4421
4422 f_mm_auth();
4423
4424 var OCT1 a5_net := f_alg_mask_from_cm(g_pars.cm2);
4425 var OCT1 a5_intersect := g_pars.net.kc_support and4b a5_net;
4426 alt {
4427 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(a5_intersect, g_pars.vec.kc)) {
4428 BSSAP.send(ts_BSSMAP_CipherModeComplAlg(omit));
4429 }
4430 [] BSSAP.receive(tr_BSSMAP_ClassmarkReq) {
4431 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
4432 repeat;
4433 }
4434 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?, g_pars.vec.kc)) {
4435 setverdict(fail, "Wrong ciphering algorithm mask in CiphModCmd");
4436 mtc.stop;
4437 }
4438 [] BSSAP.receive {
4439 setverdict(fail, "Unknown/unexpected BSSAP received");
4440 mtc.stop;
4441 }
4442 }
Harald Welte79f1e452020-08-18 22:55:02 +02004443 f_expect_common_id();
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01004444
4445 /* TODO: Verify MSC is using the best cipher available! How? */
4446
4447 f_msc_lu_hlr();
4448 f_accept_reject_lu();
4449 f_expect_clear();
4450 setverdict(pass);
4451}
4452
4453/* A5/1 only permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
4454private function f_tc_cipher_complete_1_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4455 f_tc_cipher_complete_without_alg(id, pars, '02'O /* A5/1 only */);
4456}
4457
4458/* A5/3 only permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
4459private function f_tc_cipher_complete_3_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4460 f_tc_cipher_complete_without_alg(id, pars, '08'O /* A5/3 only */);
4461}
4462
4463/* A5/1 + A5/3 permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
4464private function f_tc_cipher_complete_13_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4465 f_tc_cipher_complete_without_alg(id, pars, '0A'O /* A5/1 and A5/3 enabled */);
4466}
4467
4468testcase TC_cipher_complete_1_without_cipher() runs on MTC_CT {
4469 var BSC_ConnHdlr vc_conn;
4470 f_init();
4471 f_vty_config(MSCVTY, "network", "encryption a5 1");
4472
4473 vc_conn := f_start_handler(refers(f_tc_cipher_complete_1_without_cipher), 53);
4474 vc_conn.done;
4475}
4476
4477testcase TC_cipher_complete_3_without_cipher() runs on MTC_CT {
4478 var BSC_ConnHdlr vc_conn;
4479 f_init();
4480 f_vty_config(MSCVTY, "network", "encryption a5 3");
4481
4482 vc_conn := f_start_handler(refers(f_tc_cipher_complete_3_without_cipher), 54);
4483 vc_conn.done;
4484}
4485
4486testcase TC_cipher_complete_13_without_cipher() runs on MTC_CT {
4487 var BSC_ConnHdlr vc_conn;
4488 f_init();
4489 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
4490
4491 vc_conn := f_start_handler(refers(f_tc_cipher_complete_13_without_cipher), 55);
4492 vc_conn.done;
4493}
Harald Welteb2284bd2019-05-10 11:30:43 +02004494
Harald Weltef640a012018-04-14 17:49:21 +02004495/* TODO (SMS):
4496 * different user data lengths
4497 * SMPP transaction mode with unsuccessful delivery
4498 * queued MT-SMS with no paging response + later delivery
4499 * different data coding schemes
4500 * multi-part SMS
4501 * user-data headers
4502 * TP-PID for SMS to SIM
4503 * behavior if SMS memory is full + RP-SMMA
4504 * delivery reports
4505 * SMPP osmocom extensions
4506 * more-messages-to-send
4507 * SMS during ongoing call (SACCH/SAPI3)
4508 */
4509
4510/* TODO (General):
Harald Welteba7b6d92018-01-23 21:32:34 +01004511 * continue to send repeated MO signalling messages to keep channel open: does MSC tmeout?
4512 * malformed messages (missing IE, invalid message type): properly rejected?
4513 * MT call while LU or is ongoing: Do we use existing lchan or page while lchan active?
4514 * 3G/2G auth permutations
4515 * encryption algorithms vs. classmark vs. vty config
Harald Welteba7b6d92018-01-23 21:32:34 +01004516 * send new transaction after/during clear (like SMS, ...)
Harald Welte45164da2018-01-24 12:51:27 +01004517 * too long L3 INFO in DTAP
4518 * too long / padded BSSAP
4519 * too long / short TLV values
Harald Welteba7b6d92018-01-23 21:32:34 +01004520 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01004521
Harald Weltee13cfb22019-04-23 16:52:02 +02004522/***********************************************************************
4523 * SGsAP Testing
4524 ***********************************************************************/
4525
Philipp Maier948747b2019-04-02 15:22:33 +02004526/* Check if a subscriber exists in the VLR */
4527private function f_ctrl_subscr_in_vlr(charstring imsi_or_msisdn) runs on BSC_ConnHdlr return boolean {
4528
4529 var CtrlValue active_subsribers;
4530 var integer rc;
4531 active_subsribers := f_ctrl_get(IPA_CTRL, "subscriber-list-active-v1");
4532
4533 rc := f_strstr(active_subsribers, imsi_or_msisdn);
4534 if (rc < 0) {
4535 return false;
4536 }
4537
4538 return true;
4539}
4540
Harald Welte4263c522018-12-06 11:56:27 +01004541/* Perform a location updatye at the A-Interface and run some checks to confirm
4542 * that everything is back to normal. */
4543private function f_sgsap_bssmap_screening() runs on BSC_ConnHdlr {
4544 var SmsParameters spars := valueof(t_SmsPars);
4545
4546 /* Perform a location update, the SGs association is expected to fall
4547 * back to NULL */
4548 f_perform_lu();
4549 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4550
4551 /* Trigger a paging request and expect the paging on BSSMAP, this is
4552 * to make sure that pagings are sent throught the A-Interface again
4553 * and not throught the SGs interface.*/
Harald Welte6811d102019-04-14 22:23:14 +02004554 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Welte4263c522018-12-06 11:56:27 +01004555 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4556
4557 alt {
Harald Weltee13cfb22019-04-23 16:52:02 +02004558 [g_pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)); {
4559 setverdict(pass);
4560 }
Harald Welte62113fc2019-05-09 13:04:02 +02004561 [not g_pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
Harald Welte4263c522018-12-06 11:56:27 +01004562 setverdict(pass);
4563 }
4564 [] SGsAP.receive {
4565 setverdict(fail, "Received unexpected message on SGs");
4566 }
4567 }
4568
4569 /* Send an SMS to make sure that also payload messages are routed
4570 * throught the A-Interface again */
4571 f_establish_fully(EST_TYPE_MO_SMS);
4572 f_mo_sms(spars);
4573 f_expect_clear();
4574}
4575
4576private function f_tc_sgsap_reset(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4577 var charstring vlr_name;
4578 f_init_handler(pars);
4579
4580 vlr_name := f_sgsap_reset_mme(mp_mme_name);
4581 log("VLR name: ", vlr_name);
4582 setverdict(pass);
Neels Hofmeyrc0b520d2019-03-06 15:35:50 +01004583 f_sleep(1.0);
Harald Welte4263c522018-12-06 11:56:27 +01004584}
4585
4586testcase TC_sgsap_reset() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004587 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004588 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004589 f_init(1, true);
4590 pars := f_init_pars(11810, true);
4591 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_reset), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004592 vc_conn.done;
4593}
4594
4595/* like f_mm_auth() but for SGs */
4596function f_mm_auth_sgs() runs on BSC_ConnHdlr {
4597 if (g_pars.net.expect_auth) {
4598 g_pars.vec := f_gen_auth_vec_3g();
4599 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G3G(g_pars.vec.rand,
4600 g_pars.vec.sres,
4601 g_pars.vec.kc,
4602 g_pars.vec.ik,
4603 g_pars.vec.ck,
4604 g_pars.vec.autn,
4605 g_pars.vec.res));
4606 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
4607 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
4608 SGsAP.receive(tr_ML3_MT_MM_AUTH_REQ_3G(g_pars.vec.rand, g_pars.vec.autn));
4609 SGsAP.send(ts_ML3_MT_MM_AUTH_RESP_3G(g_pars.vec.sres, g_pars.vec.res));
4610 }
4611}
4612
4613/* like f_perform_lu(), but on SGs rather than BSSAP */
4614function f_sgs_perform_lu() runs on BSC_ConnHdlr {
4615 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4616 var PDU_SGsAP lur;
4617 var PDU_SGsAP lua;
4618 var PDU_SGsAP mm_info;
4619 var octetstring mm_info_dtap;
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004620 var GsmMcc mcc;
4621 var GsmMnc mnc;
4622 var template (omit) TrackingAreaIdentityValue tai := omit;
Harald Welte4263c522018-12-06 11:56:27 +01004623
4624 /* tell GSUP dispatcher to send this IMSI to us */
4625 f_create_gsup_expect(hex2str(g_pars.imsi));
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004626 if (g_pars.common_id_last_eutran_plmn != omit) {
4627 f_dec_mcc_mnc(g_pars.common_id_last_eutran_plmn, mcc, mnc);
4628 tai := ts_SGsAP_TAI(mcc, mnc, 555);
4629 }
Harald Welte4263c522018-12-06 11:56:27 +01004630 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
Pau Espin Pedrol3768a6f2021-04-28 14:24:23 +02004631 ts_SGsAP_LAI('901'H, '70'H, 2342),
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004632 tai));
Harald Welte4263c522018-12-06 11:56:27 +01004633 /* Old LAI, if MS sends it */
4634 /* TMSI status, if MS has no valid TMSI */
4635 /* IMEISV, if it supports "automatic device detection" */
4636 /* TAI, if available in MME */
4637 /* E-CGI, if available in MME */
4638 SGsAP.send(lur);
4639
4640 /* FIXME: is this really done over SGs? The Ue is already authenticated
4641 * via the MME ... */
4642 f_mm_auth_sgs();
4643
4644 /* Expect MSC to perform LU with HLR */
4645 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4646 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
4647 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
4648 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
4649
4650 alt {
4651 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) -> value lua {
4652 if (isvalue(lua.sGsAP_LOCATION_UPDATE_ACCEPT.newTMSIorIMSI.iD.iD.tmsi_ptmsi.octets)) {
4653 g_pars.tmsi :=lua.sGsAP_LOCATION_UPDATE_ACCEPT.newTMSIorIMSI.iD.iD.tmsi_ptmsi.octets
4654 SGsAP.send(ts_SGsAP_TMSI_REALL_CMPL(g_pars.imsi));
4655 }
4656 setverdict(pass);
4657 }
4658 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4659 setverdict(fail, "Received LU-REJECT instead of ACCEPT");
4660 }
4661 [] SGsAP.receive {
4662 setverdict(fail, "Received unexpected message on SGs");
4663 }
4664 }
4665
4666 /* Check MM information */
4667 if (mp_mm_info == true) {
4668 SGsAP.receive(tr_SGsAP_MM_INFO_REQ(g_pars.imsi, ?)) -> value mm_info;
4669 mm_info_dtap := '0532'O & mm_info.sGsAP_MM_INFORMATION_REQUEST.mM_Information.information;
4670 if (not match(dec_PDU_ML3_NW_MS(mm_info_dtap), tr_ML3_MT_MM_Info)) {
4671 setverdict(fail, "Unexpected MM Information");
4672 }
4673 }
4674
4675 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4676}
4677
4678private function f_tc_sgsap_lu(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4679 f_init_handler(pars);
4680 f_sgs_perform_lu();
4681 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4682
4683 f_sgsap_bssmap_screening();
4684
4685 setverdict(pass);
4686}
4687testcase TC_sgsap_lu() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004688 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004689 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004690 f_init(1, true);
4691 pars := f_init_pars(11811, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004692 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004693 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004694 vc_conn.done;
4695}
4696
4697/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
4698private function f_tc_sgsap_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4699 f_init_handler(pars);
4700 var PDU_SGsAP lur;
4701
4702 f_create_gsup_expect(hex2str(g_pars.imsi));
4703 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4704 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
4705 ts_SGsAP_LAI('901'H, '70'H, 2342)));
4706 SGsAP.send(lur);
4707
4708 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4709 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
4710 alt {
4711 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4712 setverdict(pass);
4713 }
4714 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) {
4715 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
4716 mtc.stop;
4717 }
4718 [] SGsAP.receive {
4719 setverdict(fail, "Received unexpected message on SGs");
4720 }
4721 }
4722
4723 f_sgsap_bssmap_screening();
4724
4725 setverdict(pass);
4726}
4727testcase TC_sgsap_lu_imsi_reject() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004728 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004729 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004730 f_init(1, true);
4731 pars := f_init_pars(11812, true);
Harald Welte4263c522018-12-06 11:56:27 +01004732
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004733 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_imsi_reject), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004734 vc_conn.done;
4735}
4736
4737/* Do LU by IMSI, but then remain silent so that Ts6-1 times out */
4738private function f_tc_sgsap_lu_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4739 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4740 var PDU_SGsAP lur;
4741
4742 f_init_handler(pars);
4743
4744 /* tell GSUP dispatcher to send this IMSI to us */
4745 f_create_gsup_expect(hex2str(g_pars.imsi));
4746
4747 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
4748 ts_SGsAP_LAI('901'H, '70'H, 2342)));
4749 /* Old LAI, if MS sends it */
4750 /* TMSI status, if MS has no valid TMSI */
4751 /* IMEISV, if it supports "automatic device detection" */
4752 /* TAI, if available in MME */
4753 /* E-CGI, if available in MME */
4754 SGsAP.send(lur);
4755
4756 /* FIXME: is this really done over SGs? The Ue is already authenticated
4757 * via the MME ... */
4758 f_mm_auth_sgs();
4759
4760 /* Expect MSC to perform LU with HLR */
4761 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4762 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
4763 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
4764 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
4765
4766 alt {
4767 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) {
4768 setverdict(pass);
4769 }
4770 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4771 setverdict(fail, "Received LU-REJECT instead of ACCEPT");
4772 }
4773 [] SGsAP.receive {
4774 setverdict(fail, "Received unexpected message on SGs");
4775 }
4776 }
4777
4778 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4779
4780 /* Wait until the VLR has abort the TMSI reallocation procedure */
4781 f_sleep(45.0);
4782
4783 /* The outcome does not change the SGs state, see also 5.2.3.4 */
4784 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4785
4786 f_sgsap_bssmap_screening();
4787
4788 setverdict(pass);
4789}
4790testcase TC_sgsap_lu_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004791 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004792 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004793 f_init(1, true);
4794 pars := f_init_pars(11813, true);
Harald Welte4263c522018-12-06 11:56:27 +01004795
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004796 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004797 vc_conn.done;
4798}
4799
4800private function f_tc_sgsap_expl_imsi_det_eps(charstring id, BSC_ConnHdlrPars pars)
4801runs on BSC_ConnHdlr {
4802 f_init_handler(pars);
4803 f_sgs_perform_lu();
4804 f_sleep(3.0);
4805
4806 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4807 SGsAP.send(ts_SGsAP_EPS_DETACH_IND(g_pars.imsi, mme_name, UE_initiated));
4808 SGsAP.receive(tr_SGsAP_EPS_DETACH_ACK(g_pars.imsi));
4809 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4810
4811 f_sgsap_bssmap_screening();
4812
4813 setverdict(pass);
4814}
4815testcase TC_sgsap_expl_imsi_det_eps() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004816 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004817 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004818 f_init(1, true);
4819 pars := f_init_pars(11814, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004820 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004821 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_expl_imsi_det_eps), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004822 vc_conn.done;
4823}
4824
Philipp Maierfc19f172019-03-21 11:17:54 +01004825private function f_tc_sgsap_impl_imsi_det_eps(charstring id, BSC_ConnHdlrPars pars)
4826runs on BSC_ConnHdlr {
4827 f_init_handler(pars);
4828 f_sgs_perform_lu();
4829 f_sleep(3.0);
4830
4831 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4832 SGsAP.send(ts_SGsAP_EPS_DETACH_IND(g_pars.imsi, mme_name, network_initiated));
4833 SGsAP.receive(tr_SGsAP_EPS_DETACH_ACK(g_pars.imsi));
4834 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4835
4836 f_sgsap_bssmap_screening();
4837
4838 setverdict(pass);
4839}
4840testcase TC_sgsap_impl_imsi_det_eps() runs on MTC_CT {
4841 var BSC_ConnHdlrPars pars;
4842 var BSC_ConnHdlr vc_conn;
4843 f_init(1, true);
4844 pars := f_init_pars(11814, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004845 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maierfc19f172019-03-21 11:17:54 +01004846 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_impl_imsi_det_eps), pars);
4847 vc_conn.done;
4848}
4849
Harald Welte4263c522018-12-06 11:56:27 +01004850private function f_tc_sgsap_expl_imsi_det_noneps(charstring id, BSC_ConnHdlrPars pars)
4851runs on BSC_ConnHdlr {
4852 f_init_handler(pars);
4853 f_sgs_perform_lu();
4854 f_sleep(3.0);
4855
4856 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4857 SGsAP.send(ts_SGsAP_IMSI_DETACH_IND(g_pars.imsi, mme_name, combined_UE_initiated));
4858 SGsAP.receive(tr_SGsAP_IMSI_DETACH_ACK(g_pars.imsi));
Philipp Maierd08e7e72019-04-02 15:27:10 +02004859
4860 if (f_ctrl_subscr_in_vlr(hex2str(g_pars.imsi))) {
4861 setverdict(fail, "subscriber not removed from VLR");
4862 }
Harald Welte4263c522018-12-06 11:56:27 +01004863
4864 f_sgsap_bssmap_screening();
4865
4866 setverdict(pass);
4867}
4868testcase TC_sgsap_expl_imsi_det_noneps() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004869 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004870 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004871 f_init(1, true);
4872 pars := f_init_pars(11815, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004873 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004874 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_expl_imsi_det_noneps), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004875 vc_conn.done;
4876}
4877
Philipp Maier5d812702019-03-21 10:51:26 +01004878private function f_tc_sgsap_impl_imsi_det_noneps(charstring id, BSC_ConnHdlrPars pars)
4879runs on BSC_ConnHdlr {
4880 f_init_handler(pars);
4881 f_sgs_perform_lu();
4882 f_sleep(3.0);
4883
4884 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4885 SGsAP.send(ts_SGsAP_IMSI_DETACH_IND(g_pars.imsi, mme_name, implicit_network_initiated));
4886 SGsAP.receive(tr_SGsAP_IMSI_DETACH_ACK(g_pars.imsi));
4887
4888 if (f_ctrl_subscr_in_vlr(hex2str(g_pars.imsi))) {
4889 setverdict(fail, "subscriber not removed from VLR");
4890 }
4891
4892 f_sgsap_bssmap_screening();
4893
4894 setverdict(pass);
4895}
4896testcase TC_sgsap_impl_imsi_det_noneps() runs on MTC_CT {
4897 var BSC_ConnHdlrPars pars;
4898 var BSC_ConnHdlr vc_conn;
4899 f_init(1, true);
4900 pars := f_init_pars(11815, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004901 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier5d812702019-03-21 10:51:26 +01004902 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_impl_imsi_det_noneps), pars);
4903 vc_conn.done;
4904}
4905
Harald Welte4263c522018-12-06 11:56:27 +01004906/* Trigger a paging request via VTY and send a paging reject in response */
4907private function f_tc_sgsap_paging_rej(charstring id, BSC_ConnHdlrPars pars)
4908runs on BSC_ConnHdlr {
4909 f_init_handler(pars);
4910 f_sgs_perform_lu();
4911 f_sleep(1.0);
4912
4913 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4914 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4915 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4916 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4917
4918 /* Initiate paging via VTY */
4919 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4920 alt {
4921 [] SGsAP.receive(exp_resp) {
4922 setverdict(pass);
4923 }
4924 [] SGsAP.receive {
4925 setverdict(fail, "Received unexpected message on SGs");
4926 }
4927 }
4928
4929 /* Now reject the paging */
4930 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, IMSI_unknown));
4931
4932 /* Wait for the states inside the MSC to settle and check the state
4933 * of the SGs Association */
4934 f_sleep(1.0);
4935 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4936
4937 /* FIXME: At the moment we send an IMSI_unknown as cause code, which is fine,
4938 * but we also need to cover tha case where the cause code indicates an
4939 * "IMSI detached for EPS services". In those cases the VLR is expected to
4940 * try paging on tha A/Iu interface. This will be another testcase similar to
4941 * this one, but extended with checks for the presence of the A/Iu paging
4942 * messages. */
4943
4944 f_sgsap_bssmap_screening();
4945
4946 setverdict(pass);
4947}
4948testcase TC_sgsap_paging_rej() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004949 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004950 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004951 f_init(1, true);
4952 pars := f_init_pars(11816, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004953 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004954 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_rej), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004955 vc_conn.done;
4956}
4957
4958/* Trigger a paging request via VTY and send a paging reject that indicates
4959 * that the subscriber intentionally rejected the call. */
4960private function f_tc_sgsap_paging_subscr_rej(charstring id, BSC_ConnHdlrPars pars)
4961runs on BSC_ConnHdlr {
4962 f_init_handler(pars);
4963 f_sgs_perform_lu();
4964 f_sleep(1.0);
4965
4966 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4967 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4968 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4969 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4970
4971 /* Initiate paging via VTY */
4972 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4973 alt {
4974 [] SGsAP.receive(exp_resp) {
4975 setverdict(pass);
4976 }
4977 [] SGsAP.receive {
4978 setverdict(fail, "Received unexpected message on SGs");
4979 }
4980 }
4981
4982 /* Now reject the paging */
4983 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, user_rejected_mobile_terminating_CS_fallback_call));
4984
4985 /* Wait for the states inside the MSC to settle and check the state
4986 * of the SGs Association */
4987 f_sleep(1.0);
4988 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4989
4990 /* FIXME: The VLR is supposed to trigger an User Determined User Busy (UDUB) as specified
4991 * in 3GPP TS 24.082, this is not yet implemented in the MSC or in this tests, we need
4992 * to check back how this works and how it can be tested */
4993
4994 f_sgsap_bssmap_screening();
4995
4996 setverdict(pass);
4997}
4998testcase TC_sgsap_paging_subscr_rej() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004999 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005000 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005001 f_init(1, true);
5002 pars := f_init_pars(11817, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005003 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005004 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_subscr_rej), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005005 vc_conn.done;
5006}
5007
5008/* Trigger a paging request via VTY and send an UE unreacable messge in response */
5009private function f_tc_sgsap_paging_ue_unr(charstring id, BSC_ConnHdlrPars pars)
5010runs on BSC_ConnHdlr {
5011 f_init_handler(pars);
5012 f_sgs_perform_lu();
5013 f_sleep(1.0);
5014
5015 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5016 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
5017 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
5018 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
5019
5020 /* Initiate paging via VTY */
5021 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
5022 alt {
5023 [] SGsAP.receive(exp_resp) {
5024 setverdict(pass);
5025 }
5026 [] SGsAP.receive {
5027 setverdict(fail, "Received unexpected message on SGs");
5028 }
5029 }
5030
5031 /* Now pretend that the UE is unreachable */
5032 SGsAP.send(ts_SGsAP_UE_UNREACHABLE(g_pars.imsi, UE_unreachable));
5033
5034 /* Wait for the states inside the MSC to settle and check the state
5035 * of the SGs Association. */
5036 f_sleep(1.0);
5037 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5038
5039 f_sgsap_bssmap_screening();
5040
5041 setverdict(pass);
5042}
5043testcase TC_sgsap_paging_ue_unr() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005044 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005045 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005046 f_init(1, true);
5047 pars := f_init_pars(11818, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005048 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005049 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_ue_unr), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005050 vc_conn.done;
5051}
5052
5053/* Trigger a paging request via VTY but don't respond to it */
5054private function f_tc_sgsap_paging_and_nothing(charstring id, BSC_ConnHdlrPars pars)
5055runs on BSC_ConnHdlr {
5056 f_init_handler(pars);
5057 f_sgs_perform_lu();
5058 f_sleep(1.0);
5059
5060 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5061 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
Philipp Maier34218102019-09-24 09:15:49 +02005062 var template PDU_SGsAP exp_serv_abrt := ts_SGsAP_SERVICE_ABORT_REQ(g_pars.imsi);
Harald Welte4263c522018-12-06 11:56:27 +01005063 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
5064 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
5065
5066 /* Initiate paging via VTY */
5067 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
5068 alt {
5069 [] SGsAP.receive(exp_resp) {
5070 setverdict(pass);
5071 }
5072 [] SGsAP.receive {
5073 setverdict(fail, "Received unexpected message on SGs");
5074 }
5075 }
5076
Philipp Maier34218102019-09-24 09:15:49 +02005077 /* While we are doing nothing, expect an SGsAP-SERVICE-ABORT-REQUEST
5078 * after some time */
5079 timer T := 10.0;
5080 T.start
5081 alt {
5082 [] SGsAP.receive(exp_serv_abrt)
5083 {
5084 setverdict(pass);
5085 }
5086 [] SGsAP.receive {
5087 setverdict(fail, "unexpected SGsAP message received");
5088 self.stop;
5089 }
5090 [] T.timeout {
5091 setverdict(fail, "MSC did not send SGsAP-SERVICE-ABORT-REQUEST");
5092 self.stop;
5093 }
5094 }
5095
5096 /* The SGs association must remain unchanged. */
Harald Welte4263c522018-12-06 11:56:27 +01005097 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5098
5099 f_sgsap_bssmap_screening();
5100
5101 setverdict(pass);
5102}
5103testcase TC_sgsap_paging_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005104 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005105 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005106 f_init(1, true);
5107 pars := f_init_pars(11819, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005108 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005109 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005110 vc_conn.done;
5111}
5112
5113/* Trigger a paging request via VTY and slip in an LU */
5114private function f_tc_sgsap_paging_and_lu(charstring id, BSC_ConnHdlrPars pars)
5115runs on BSC_ConnHdlr {
5116 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5117 f_init_handler(pars);
5118
5119 /* First we prepar the situation, where the SGs association is in state
5120 * NULL and the confirmed by radio contact indicator is set to false
5121 * as well. This can be archived by performing an SGs LU and then
5122 * resetting the VLR */
5123 f_sgs_perform_lu();
5124 f_sgsap_reset_mme(mp_mme_name);
5125 f_sleep(1.0);
5126 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
5127
5128 /* Perform a paging, expect the paging messages on the SGs interface */
5129 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
5130 alt {
5131 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
5132 setverdict(pass);
5133 }
5134 [] SGsAP.receive {
5135 setverdict(fail, "Received unexpected message on SGs");
5136 }
5137 }
5138
5139 /* Perform the LU as normal */
5140 f_sgs_perform_lu();
5141 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5142
5143 /* Expect a new paging request right after the LU */
5144 alt {
5145 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
5146 setverdict(pass);
5147 }
5148 [] SGsAP.receive {
5149 setverdict(fail, "Received unexpected message on SGs");
5150 }
5151 }
5152
5153 /* Test is done now, lets round everything up by rejecting the paging
5154 * cleanly. */
5155 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, user_rejected_mobile_terminating_CS_fallback_call));
5156 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5157
5158 f_sgsap_bssmap_screening();
5159
5160 setverdict(pass);
5161}
5162testcase TC_sgsap_paging_and_lu() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005163 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005164 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005165 f_init(1, true);
5166 pars := f_init_pars(11820, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005167 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005168 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_and_lu), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005169 vc_conn.done;
5170}
5171
5172/* Send unexpected unit-data through the SGs interface */
5173private function f_tc_sgsap_unexp_ud(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5174 f_init_handler(pars);
5175 f_sleep(1.0);
5176
5177 /* This simulates what happens when a subscriber without SGs
5178 * association gets unitdata via the SGs interface. */
5179
5180 /* Make sure the subscriber exists and the SGs association
5181 * is in NULL state */
5182 f_perform_lu();
5183 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
5184
5185 /* Send some random unit data, the MSC/VLR should send a release
5186 * immediately. */
5187 SGsAP.send(ts_SGsAP_UL_UD(pars.imsi,'1234'O));
5188 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, IMSI_detached_for_EPS_nonEPS_services));
5189
5190 f_sgsap_bssmap_screening();
5191
5192 setverdict(pass);
5193}
5194testcase TC_sgsap_unexp_ud() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005195 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005196 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005197 f_init(1, true);
5198 pars := f_init_pars(11821, true);
5199 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_unexp_ud), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005200 vc_conn.done;
5201}
5202
5203/* Send unsolicited unit-data through the SGs interface */
5204private function f_tc_sgsap_unsol_ud(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5205 f_init_handler(pars);
5206 f_sleep(1.0);
5207
5208 /* This simulates what happens when the MME attempts to send unitdata
5209 * to a subscriber that is completely unknown to the VLR */
5210
5211 /* Send some random unit data, the MSC/VLR should send a release
5212 * immediately. */
5213 SGsAP.send(ts_SGsAP_UL_UD(pars.imsi,'1234'O));
5214 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, IMSI_unknown));
5215
5216 f_sgsap_bssmap_screening();
5217
Harald Welte4d15fa72020-08-19 08:58:28 +02005218 /* clean-up VLR state about this subscriber */
5219 f_imsi_detach_by_imsi();
5220
Harald Welte4263c522018-12-06 11:56:27 +01005221 setverdict(pass);
5222}
5223testcase TC_sgsap_unsol_ud() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005224 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005225 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005226 f_init(1, true);
5227 pars := f_init_pars(11822, true);
5228 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_unsol_ud), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005229 vc_conn.done;
5230}
5231
5232private altstep as_other_sms_sgs() runs on BSC_ConnHdlr {
5233 /* FIXME: Match an actual payload (second questionmark), the type is
5234 * octetstring, how do we use a tr_PDU_DTAP_MT here? */
5235 [] SGsAP.receive(tr_SGsAP_DL_UD(?,?)) {
5236 setverdict(fail, "Unexpected SMS related PDU from MSC");
5237 mtc.stop;
5238 }
5239}
5240
5241/* receive a MT-SMS delivered from the MSC/SMSC over an already existing SGsAP connection */
5242function f_mt_sms_sgs(inout SmsParameters spars)
5243runs on BSC_ConnHdlr {
5244 var template (value) TPDU_RP_DATA_MS_SGSN tp_mo;
5245 var template (value) RPDU_MS_SGSN rp_mo;
5246 var template (value) PDU_ML3_MS_NW l3_mo;
5247
5248 var template TPDU_RP_DATA_SGSN_MS tp_mt;
5249 var template RPDU_SGSN_MS rp_mt;
5250 var template PDU_ML3_NW_MS l3_mt;
5251
5252 var PDU_ML3_NW_MS sgsap_l3_mt;
5253
5254 var default d := activate(as_other_sms_sgs());
5255
5256 /* Expect CP-DATA(RP-DATA(SMS-DELIVER)) */
5257 tp_mt := tr_SMS_DELIVER(?, spars.tp.ud, spars.tp.pid, spars.tp.dcs, ?);
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09005258 rp_mt := tr_RP_DATA_MT(?, spars.rp.smsc_addr, omit, tp_mt);
Harald Welte4263c522018-12-06 11:56:27 +01005259 l3_mt := tr_ML3_MT_SMS(?, c_TIF_ORIG, tr_CP_DATA_MT(rp_mt));
5260
5261 SGsAP.receive(l3_mt) -> value sgsap_l3_mt;
5262
5263 /* Extract relevant identifiers */
5264 spars.tid := bit2int(sgsap_l3_mt.tiOrSkip.transactionId.tio);
5265 spars.rp.msg_ref := sgsap_l3_mt.msgs.sms.cP_DATA.cP_User_Data.cP_RPDU.rP_DATA_SGSN_MS.rP_MessageReference;
5266
5267 /* send CP-ACK for CP-DATA just received */
5268 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_REPL, ts_CP_ACK_MO);
5269
5270 SGsAP.send(l3_mo);
5271
5272 /* send RP-ACK for RP-DATA */
5273 rp_mo := ts_RP_ACK_MO(spars.rp.msg_ref);
5274 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_REPL, ts_CP_DATA_MO(rp_mo));
5275
5276 SGsAP.send(l3_mo);
5277
5278 /* expect CP-ACK for CP-DATA(RP-ACK) just sent */
5279 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_ORIG, tr_CP_ACK_MT);
5280
5281 SGsAP.receive(l3_mt);
5282
5283 deactivate(d);
5284
5285 setverdict(pass);
5286}
5287
5288/* submit a MO-SMS to MSC/SMSC over an already existing SGsAP connection */
5289function f_mo_sms_sgs(inout SmsParameters spars)
5290runs on BSC_ConnHdlr {
5291 var template (value) TPDU_RP_DATA_MS_SGSN tp_mo;
5292 var template (value) RPDU_MS_SGSN rp_mo;
5293 var template (value) PDU_ML3_MS_NW l3_mo;
5294
5295 var template TPDU_RP_DATA_SGSN_MS tp_mt;
5296 var template RPDU_SGSN_MS rp_mt;
5297 var template PDU_ML3_NW_MS l3_mt;
5298
5299 var default d := activate(as_other_sms_sgs());
5300
5301 /* just in case this is routed to SMPP.. */
5302 f_create_smpp_expect(hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue));
5303
5304 tp_mo := ts_SMS_SUBMIT(spars.tp.msg_ref, spars.tp.da, spars.tp.pid, spars.tp.dcs,
5305 spars.tp.udl, spars.tp.ud);
Vadim Yanitskiy437b5a62019-12-15 14:13:39 +09005306 rp_mo := ts_RP_DATA_MO(spars.rp.msg_ref, omit, spars.rp.smsc_addr, tp_mo);
Harald Welte4263c522018-12-06 11:56:27 +01005307 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_DATA_MO(rp_mo));
5308
5309 SGsAP.send(l3_mo);
5310
5311 /* receive CP-ACK for CP-DATA above */
5312 SGsAP.receive(tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_ACK_MT));
5313
5314 if (ispresent(spars.exp_rp_err)) {
5315 /* expect an RP-ERROR message from MSC with given cause */
5316 rp_mt := tr_RP_ERROR_MT(spars.rp.msg_ref, spars.exp_rp_err);
5317 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_DATA_MT(rp_mt));
5318 SGsAP.receive(l3_mt);
5319 /* send CP-ACK for CP-DATA just received */
5320 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_ACK_MO);
5321 SGsAP.send(l3_mo);
5322 } else {
5323 /* expect RP-ACK for RP-DATA */
5324 rp_mt := tr_RP_ACK_MT(spars.rp.msg_ref);
5325 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_DATA_MT(rp_mt));
5326 SGsAP.receive(l3_mt);
5327 /* send CP-ACO for CP-DATA just received */
5328 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_ACK_MO);
5329 SGsAP.send(l3_mo);
5330 }
5331
5332 deactivate(d);
5333
5334 setverdict(pass);
5335}
5336
5337private function f_vty_sms_send_conn_hdlr(charstring imsi, charstring msisdn, charstring text)
5338runs on BSC_ConnHdlr {
5339 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
5340}
5341
5342/* Send a MT SMS via SGs interface */
5343private function f_tc_sgsap_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5344 f_init_handler(pars);
5345 f_sgs_perform_lu();
5346 f_sleep(1.0);
5347 var SmsParameters spars := valueof(t_SmsPars);
5348 spars.tp.ud := 'C8329BFD064D9B53'O;
5349
5350 /* Trigger SMS via VTY */
5351 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
5352 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5353
5354 /* Expect a paging request and respond accordingly with a service request */
5355 SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, SMS_indicator, omit));
5356 SGsAP.send(ts_SGsAP_SERVICE_REQ(pars.imsi, SMS_indicator, EMM_CONNECTED));
5357
5358 /* Connection is now live, receive the MT-SMS */
5359 f_mt_sms_sgs(spars);
5360
5361 /* Expect a concluding release from the MSC */
5362 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, omit));
5363
5364 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
5365 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5366
5367 f_sgsap_bssmap_screening();
5368
5369 setverdict(pass);
5370}
5371testcase TC_sgsap_mt_sms() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005372 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005373 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005374 f_init(1, true);
5375 pars := f_init_pars(11823, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005376 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005377 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005378 vc_conn.done;
5379}
5380
5381/* Send a MO SMS via SGs interface */
5382private function f_tc_sgsap_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5383 f_init_handler(pars);
5384 f_sgs_perform_lu();
5385 f_sleep(1.0);
5386 var SmsParameters spars := valueof(t_SmsPars);
5387 spars.tp.ud := 'C8329BFD064D9B53'O;
5388
5389 /* Send the MO-SMS */
5390 f_mo_sms_sgs(spars);
5391
5392 /* Expect a concluding release from the MSC/VLR */
5393 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, omit));
5394
5395 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
5396 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5397
5398 setverdict(pass);
5399
5400 f_sgsap_bssmap_screening()
5401}
5402testcase TC_sgsap_mo_sms() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005403 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005404 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005405 f_init(1, true);
5406 pars := f_init_pars(11824, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005407 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005408 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mo_sms), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005409 vc_conn.done;
5410}
5411
5412/* Trigger sending of an MT sms via VTY but never respond to anything */
5413private function f_tc_sgsap_mt_sms_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5414 f_init_handler(pars, 170.0);
5415 f_sgs_perform_lu();
5416 f_sleep(1.0);
5417
5418 var SmsParameters spars := valueof(t_SmsPars);
5419 spars.tp.ud := 'C8329BFD064D9B53'O;
5420 var integer page_count := 0;
5421 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5422 var template PDU_SGsAP exp_pag_req := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, SMS_indicator, omit);
5423 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
5424 exp_pag_req.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
5425
5426 /* Trigger SMS via VTY */
5427 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
5428
Neels Hofmeyr16237742019-03-06 15:34:01 +01005429 /* Expect the MSC/VLR to page exactly once */
5430 SGsAP.receive(exp_pag_req);
Harald Welte4263c522018-12-06 11:56:27 +01005431
5432 /* Wait some time to make sure the MSC is not delivering any further
5433 * paging messages or anything else that could be unexpected. */
5434 timer T := 20.0;
5435 T.start
5436 alt {
5437 [] SGsAP.receive(exp_pag_req)
5438 {
5439 setverdict(fail, "paging seems not to stop!");
5440 mtc.stop;
5441 }
5442 [] SGsAP.receive {
5443 setverdict(fail, "unexpected SGsAP message received");
5444 self.stop;
5445 }
5446 [] T.timeout {
5447 setverdict(pass);
5448 }
5449 }
5450
5451 /* Even on a failed paging the SGs Association should stay intact */
5452 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5453
Philipp Maier26bdb8c2019-09-24 09:21:12 +02005454 /* Make sure that the SMS we just inserted is cleared and the
5455 * subscriber is expired. This is necessary because otherwise the MSC
5456 * might re-try the SMS delivery and disturb the following tests. */
Harald Welte4263c522018-12-06 11:56:27 +01005457
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01005458 f_vty_sms_clear(hex2str(g_pars.imsi));
5459
Harald Welte4263c522018-12-06 11:56:27 +01005460 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " expire");
5461
5462 setverdict(pass);
Neels Hofmeyrb0f82342019-03-06 15:36:51 +01005463
5464 f_sgsap_bssmap_screening();
Harald Welte4263c522018-12-06 11:56:27 +01005465}
5466testcase TC_sgsap_mt_sms_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005467 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005468 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005469 f_init(1, true);
5470 pars := f_init_pars(11825, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005471 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005472 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005473 vc_conn.done;
5474}
5475
5476/* Trigger sending of an MT sms via VTY but reject the paging immediately */
5477private function f_tc_sgsap_mt_sms_and_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5478 f_init_handler(pars, 150.0);
5479 f_sgs_perform_lu();
5480 f_sleep(1.0);
5481
5482 var SmsParameters spars := valueof(t_SmsPars);
5483 spars.tp.ud := 'C8329BFD064D9B53'O;
5484 var integer page_count := 0;
5485 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5486 var template PDU_SGsAP exp_pag_req := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, SMS_indicator, omit);
5487 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
5488 exp_pag_req.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
5489
5490 /* Trigger SMS via VTY */
5491 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
5492
5493 /* Expect a paging request and reject it immediately */
5494 SGsAP.receive(exp_pag_req);
5495 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, IMSI_unknown));
5496
5497 /* The MSC/VLR should no longer try to page once the paging has been
5498 * rejected. Wait some time and check if there are no unexpected
5499 * messages on the SGs interface. */
5500 timer T := 20.0;
5501 T.start
5502 alt {
5503 [] SGsAP.receive(exp_pag_req)
5504 {
5505 setverdict(fail, "paging seems not to stop!");
5506 mtc.stop;
5507 }
5508 [] SGsAP.receive {
5509 setverdict(fail, "unexpected SGsAP message received");
5510 self.stop;
5511 }
5512 [] T.timeout {
5513 setverdict(pass);
5514 }
5515 }
5516
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01005517 f_vty_sms_clear(hex2str(g_pars.imsi));
5518
Harald Welte4263c522018-12-06 11:56:27 +01005519 /* A rejected paging with IMSI_unknown (see above) should always send
5520 * the SGs association to NULL. */
5521 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
5522
5523 f_sgsap_bssmap_screening();
5524
Harald Welte4263c522018-12-06 11:56:27 +01005525 setverdict(pass);
5526}
5527testcase TC_sgsap_mt_sms_and_reject() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005528 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005529 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005530 f_init(1, true);
5531 pars := f_init_pars(11826, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005532 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005533 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms_and_reject), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005534 vc_conn.done;
5535}
5536
Pau Espin Pedrol3acd19e2021-04-28 12:59:52 +02005537/* Perform an MT CSFB call including LU */
Harald Welte4263c522018-12-06 11:56:27 +01005538private function f_mt_lu_and_csfb_call(charstring id, BSC_ConnHdlrPars pars, boolean bssmap_lu) runs on BSC_ConnHdlr {
5539 f_init_handler(pars);
5540
5541 /* Be sure that the BSSMAP reset is done before we begin. */
5542 f_sleep(2.0);
5543
5544 /* Testcase variation: See what happens when we do a regular BSSMAP
5545 * LU first (this should not hurt in any way!) */
5546 if (bssmap_lu) {
5547 f_perform_lu();
5548 }
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005549 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Harald Welte4263c522018-12-06 11:56:27 +01005550
5551 f_sgs_perform_lu();
5552 f_sleep(1.0);
5553
5554 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5555 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Harald Welte4263c522018-12-06 11:56:27 +01005556
5557 /* Initiate a call via MNCC interface */
5558 f_mt_call_initate(cpars);
5559
5560 /* Expect a paging request and respond accordingly with a service request */
5561 SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit));
5562 SGsAP.send(ts_SGsAP_SERVICE_REQ(pars.imsi, CS_call_indicator, EMM_CONNECTED));
5563
5564 /* Complete the call, hold it for some time and then tear it down */
5565 f_mt_call_complete(cpars);
5566 f_sleep(3.0);
Harald Welte4c422b72019-02-17 16:27:10 +01005567 f_call_hangup(cpars, true, is_csfb := true);
Harald Welte4263c522018-12-06 11:56:27 +01005568
5569 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
5570 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5571
Harald Welte4263c522018-12-06 11:56:27 +01005572 /* Test for successful return by triggering a paging, when the paging
5573 * request is received via SGs, we can be sure that the MSC/VLR has
5574 * recognized that the UE is now back on 4G */
5575 f_sleep(1.0);
5576 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
5577 alt {
5578 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
5579 setverdict(pass);
5580 }
5581 [] SGsAP.receive {
5582 setverdict(fail, "Received unexpected message on SGs");
5583 }
5584 }
5585
5586 f_sgsap_bssmap_screening();
5587
5588 setverdict(pass);
5589}
5590
5591/* Perform a regular BSSAP LU first, do a SGSAP LU and then make a CSFB call */
5592private function f_tc_bssap_lu_sgsap_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5593 f_mt_lu_and_csfb_call(id, pars, true);
5594}
5595testcase TC_bssap_lu_sgsap_lu_and_mt_call() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005596 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005597 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005598 f_init(1, true);
5599 pars := f_init_pars(118139, true);
Harald Welte4263c522018-12-06 11:56:27 +01005600
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005601 vc_conn := f_start_handler_with_pars(refers(f_tc_bssap_lu_sgsap_lu_and_mt_call), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005602 vc_conn.done;
5603}
5604
Harald Welte4263c522018-12-06 11:56:27 +01005605/* Perform a SGSAP LU and then make a CSFB call */
5606private function f_tc_sgsap_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5607 f_mt_lu_and_csfb_call(id, pars, false);
5608}
5609testcase TC_sgsap_lu_and_mt_call() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005610 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005611 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005612 f_init(1, true);
5613 pars := f_init_pars(11827, true);
Harald Welte4263c522018-12-06 11:56:27 +01005614
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005615 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_and_mt_call), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005616 vc_conn.done;
5617}
5618
Philipp Maier628c0052019-04-09 17:36:57 +02005619/* Simulate an HLR/VLR failure */
5620private function f_tc_sgsap_vlr_failure(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5621 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
5622 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5623
5624 var PDU_SGsAP lur;
5625
5626 f_init_handler(pars);
5627
5628 /* Attempt location update (which is expected to fail) */
5629 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
5630 ts_SGsAP_LAI('901'H, '70'H, 2342)));
5631 SGsAP.send(lur);
5632
5633 /* Respond to SGsAP-RESET-INDICATION from VLR */
5634 alt {
5635 [] SGsAP.receive(tr_SGsAP_RESET_IND_VLR(vlr_name)); {
5636 SGsAP.send(valueof(ts_SGsAP_RESET_ACK_MME(mme_name)));
5637 setverdict(pass);
5638 }
5639 [] SGsAP.receive {
5640 setverdict(fail, "Received unexpected message on SGs");
5641 }
5642 }
5643
5644 f_sleep(1.0);
5645 setverdict(pass);
5646}
5647testcase TC_sgsap_vlr_failure() runs on MTC_CT {
5648 var BSC_ConnHdlrPars pars;
5649 var BSC_ConnHdlr vc_conn;
5650 f_init(1, true, false);
5651 pars := f_init_pars(11811, true, false);
5652 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_vlr_failure), pars);
5653 vc_conn.done;
5654}
5655
Harald Welte4263c522018-12-06 11:56:27 +01005656/* SGs TODO:
5657 * LU attempt for IMSI without NAM_PS in HLR
5658 * LU attempt with AUTH FAIL due to invalid RES/SRES
5659 * LU attempt with no response from HLR (VLR should timeout + LU REJ)
5660 * LU attempt with new TMSI but without TMSI REALL CMPL baco to VLR
5661 * implicit IMSI detach from EPS
5662 * implicit IMSI detach from non-EPS
5663 * MM INFO
5664 *
5665 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01005666
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005667private function f_tc_ho_inter_bsc_unknown_cell(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5668 f_init_handler(pars);
5669 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005670
5671 f_perform_lu();
5672 f_mo_call_establish(cpars);
5673
5674 f_sleep(1.0);
5675
5676 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5677 var BssmapCause cause := enum2int(cause_val);
5678
5679 var template BSSMAP_FIELD_CellIdentificationList cil;
5680 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('023'H, '42'H, 999) } };
5681
5682 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5683 BSSAP.receive(tr_BSSMAP_HandoverRequiredReject);
5684
5685 f_call_hangup(cpars, true);
5686}
5687testcase TC_ho_inter_bsc_unknown_cell() runs on MTC_CT {
5688 var BSC_ConnHdlr vc_conn;
5689 f_init();
5690
5691 vc_conn := f_start_handler(refers(f_tc_ho_inter_bsc_unknown_cell), 53);
5692 vc_conn.done;
5693}
5694
5695private altstep as_mgcp_ack_all_mdcx(CallParameters cpars) runs on BSC_ConnHdlr {
5696 var MgcpCommand mgcp_cmd;
5697 [] MGCP.receive(tr_MDCX) -> value mgcp_cmd {
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02005698 var SDP_Message sdp := valueof(ts_SDP(cpars.mgw_conn_2.mgw_rtp_ip, cpars.mgw_conn_2.mgw_rtp_ip,
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005699 hex2str(cpars.mgcp_call_id), "42",
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02005700 cpars.mgw_conn_2.mgw_rtp_port,
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005701 { int2str(cpars.rtp_payload_type) },
5702 { valueof(ts_SDP_rtpmap(cpars.rtp_payload_type,
5703 cpars.rtp_sdp_format)),
5704 valueof(ts_SDP_ptime(20)) }));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02005705 MGCP.send(ts_MDCX_ACK(mgcp_cmd.line.trans_id, cpars.mgw_conn_2.mgcp_connection_id, sdp));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005706 repeat;
5707 }
5708}
5709
5710private function f_tc_ho_inter_bsc0(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005711 var CallParameters cpars;
5712
5713 cpars := valueof(t_CallParams('12345'H, 0));
5714 if (pars.use_ipv6) {
5715 cpars.mgw_conn_1.mgw_rtp_ip := "::1";
5716 cpars.mgw_conn_2.mgw_rtp_ip := "::2";
5717 cpars.bss_rtp_ip := "::3";
5718 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005719
5720 f_init_handler(pars);
5721
5722 f_vty_transceive(MSCVTY, "configure terminal");
5723 f_vty_transceive(MSCVTY, "msc");
5724 f_vty_transceive(MSCVTY, "neighbor a cgi 262 42 23 42 ran-pc 0.24.1");
Neels Hofmeyr2822d072021-06-23 03:20:32 +02005725 f_vty_transceive(MSCVTY, "neighbor a cgi 023 42 5 6 ran-pc 0.24.2");
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005726 f_vty_transceive(MSCVTY, "exit");
5727 f_vty_transceive(MSCVTY, "exit");
5728
5729 f_perform_lu();
5730 f_mo_call_establish(cpars);
5731
5732 f_sleep(1.0);
5733
5734 var default ack_mdcx := activate(as_mgcp_ack_all_mdcx(cpars));
5735
5736 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5737 var BssmapCause cause := enum2int(cause_val);
5738
5739 var template BSSMAP_FIELD_CellIdentificationList cil;
Neels Hofmeyr2822d072021-06-23 03:20:32 +02005740 cil := { cIl_CGI := { ts_BSSMAP_CI_CGI('023'H, '42'H, 5, 6) } };
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005741
5742 /* old BSS sends Handover Required */
5743 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5744
5745 /* Now the action goes on in f_tc_ho_inter_bsc1() */
5746
5747 /* MSC forwards the RR Handover Command to old BSS */
5748 var PDU_BSSAP ho_command;
5749 BSSAP.receive(tr_BSSMAP_HandoverCommand) -> value ho_command;
5750
5751 log("GOT HandoverCommand", ho_command);
5752
5753 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
5754
5755 /* f_tc_ho_inter_bsc1() completes Handover, then expecting a Clear here. */
5756 f_expect_clear();
5757
5758 log("FIRST inter-BSC Handover done");
5759
5760
5761 /* ------------------------ */
5762
5763 /* Ok, that went well, now the other BSC is handovering back here --
5764 * from now on this here is the new BSS. */
5765 f_create_bssmap_exp_handoverRequest(193);
5766
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005767 var template BSSMAP_IE_EncryptionInformation encryptionInformation;
5768 var template BSSMAP_IE_ChosenEncryptionAlgorithm chosenEncryptionAlgorithm;
5769 var template BSSMAP_IE_KC128 kC128;
5770 var OCT1 a5_perm_alg;
5771 f_get_expected_encryption(encryptionInformation, chosenEncryptionAlgorithm, kC128, a5_perm_alg);
5772 var template PDU_BSSAP expect_ho_request := tr_BSSMAP_HandoverRequest(encryptionInformation, chosenEncryptionAlgorithm, kC128);
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005773 var PDU_BSSAP ho_request;
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005774 alt {
5775 [] BSSAP.receive(expect_ho_request);
5776 [] BSSAP.receive(tr_BSSMAP_HandoverRequest) -> value ho_request {
5777 log("Error: Wrong handoverRequest received. Expected: ", expect_ho_request,
5778 " got ", ho_request);
5779 setverdict(fail, "Wrong handoverRequest received");
5780 mtc.stop;
5781 }
5782 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005783
5784 /* new BSS composes a RR Handover Command */
5785 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5786 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005787 var BSSMAP_IE_AoIP_TransportLayerAddress tla tla :=
5788 valueof(f_ts_BSSMAP_IE_AoIP_TLA(cpars.bss_rtp_ip, cpars.bss_rtp_port));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005789 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5790 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5791
5792 /* Now f_tc_ho_inter_bsc1() expects HandoverCommand */
5793
5794 f_sleep(0.5);
5795
5796 /* Notify that the MS is now over here */
5797
5798 BSSAP.send(ts_BSSMAP_HandoverDetect);
5799 f_sleep(0.1);
5800 BSSAP.send(ts_BSSMAP_HandoverComplete);
5801
5802 f_sleep(3.0);
5803
5804 deactivate(ack_mdcx);
5805
5806 var default ccrel := activate(as_optional_cc_rel(cpars, true));
5807
5808 /* blatant cheating */
5809 var N_Sd_Array last_n_sd := f_bssmap_last_n_sd();
5810 last_n_sd[0] := 3;
5811 f_bssmap_continue_after_n_sd(last_n_sd);
5812
5813 f_call_hangup(cpars, true);
5814 f_sleep(1.0);
5815 deactivate(ccrel);
5816
5817 setverdict(pass);
5818}
5819private function f_tc_ho_inter_bsc1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005820 var charstring bss_rtp_ip;
5821 if (pars.use_ipv6) {
5822 bss_rtp_ip := "::8";
5823 } else {
5824 bss_rtp_ip := "1.2.3.4";
5825 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005826 f_init_handler(pars);
5827 f_create_bssmap_exp_handoverRequest(194);
5828
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005829 var template BSSMAP_IE_EncryptionInformation encryptionInformation;
5830 var template BSSMAP_IE_ChosenEncryptionAlgorithm chosenEncryptionAlgorithm;
5831 var template BSSMAP_IE_KC128 kC128;
5832 var OCT1 a5_perm_alg;
5833 f_get_expected_encryption(encryptionInformation, chosenEncryptionAlgorithm, kC128, a5_perm_alg);
5834 var template PDU_BSSAP expect_ho_request := tr_BSSMAP_HandoverRequest(encryptionInformation, chosenEncryptionAlgorithm, kC128);
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005835 var PDU_BSSAP ho_request;
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005836 alt {
5837 [] BSSAP.receive(expect_ho_request);
5838 [] BSSAP.receive(tr_BSSMAP_HandoverRequest) -> value ho_request {
5839 log("Error: Wrong handoverRequest received. Expected: ", expect_ho_request,
5840 " got ", ho_request);
5841 setverdict(fail, "Wrong handoverRequest received");
5842 mtc.stop;
5843 }
5844 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005845 /* new BSS composes a RR Handover Command */
5846 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5847 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005848 var BSSMAP_IE_AoIP_TransportLayerAddress tla :=
5849 valueof(f_ts_BSSMAP_IE_AoIP_TLA(bss_rtp_ip, 2342));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005850 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5851 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5852
5853 /* Now f_tc_ho_inter_bsc0() expects HandoverCommand */
5854
5855 f_sleep(0.5);
5856
5857 /* Notify that the MS is now over here */
5858
5859 BSSAP.send(ts_BSSMAP_HandoverDetect);
5860 f_sleep(0.1);
5861 BSSAP.send(ts_BSSMAP_HandoverComplete);
5862
5863 f_sleep(3.0);
5864
5865 /* Now I'd like to f_call_hangup() but we don't know any cpars here. So
5866 * ... handover back to the first BSC :P */
5867
5868 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5869 var BssmapCause cause := enum2int(cause_val);
5870
5871 var template BSSMAP_FIELD_CellIdentificationList cil;
Neels Hofmeyr2822d072021-06-23 03:20:32 +02005872 cil := { cIl_CGI := { ts_BSSMAP_CI_CGI('262'H, '42'H, 23, 42) } };
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005873
5874 /* old BSS sends Handover Required */
5875 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5876
5877 /* Now the action goes on in f_tc_ho_inter_bsc0() */
5878
5879 /* MSC forwards the RR Handover Command to old BSS */
5880 var PDU_BSSAP ho_command;
5881 BSSAP.receive(tr_BSSMAP_HandoverCommand) -> value ho_command;
5882
5883 log("GOT HandoverCommand", ho_command);
5884
5885 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
5886
5887 /* f_tc_ho_inter_bsc1() completes Handover, then expecting a Clear here. */
5888 f_expect_clear();
5889 setverdict(pass);
5890}
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005891function f_tc_ho_inter_bsc_main(boolean use_ipv6 := false, integer a5_n := 0) runs on MTC_CT {
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005892 var BSC_ConnHdlr vc_conn0;
5893 var BSC_ConnHdlr vc_conn1;
5894 f_init(2);
5895
5896 var BSC_ConnHdlrPars pars0 := f_init_pars(53);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005897 pars0.use_ipv6 := use_ipv6;
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005898 pars0.net.expect_ciph := a5_n > 0;
5899 pars0.net.expect_auth := pars0.net.expect_ciph;
5900 pars0.net.kc_support := bit2oct('00000001'B << a5_n);
5901 pars0.cm2.classmarkInformationType2_oct5.a5_3 := '1'B;
5902 pars0.cm2.classmarkInformationType2_oct5.a5_2 := '0'B;
5903 pars0.cm2.classmarkInformationType2_oct5.cm3 := '1'B;
5904 pars0.cm3 := valueof(ts_CM3_default);
5905 pars0.use_umts_aka := true;
5906 pars0.vec := f_gen_auth_vec_3g();
5907 pars0.vec_keep := true;
5908
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005909 var BSC_ConnHdlrPars pars1 := f_init_pars(53);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005910 pars1.use_ipv6 := use_ipv6;
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005911 pars1.net.expect_ciph := pars0.net.expect_ciph;
5912 pars1.net.expect_auth := pars0.net.expect_ciph;
5913 pars1.net.kc_support := bit2oct('00000001'B << a5_n);
5914 pars1.cm2 := pars0.cm2;
5915 pars1.cm3 := pars0.cm3;
5916 pars1.use_umts_aka := true;
5917 /* Both components need the same auth vector info because we expect f_tc_ho_inter_bsc0's ciphering key to be
5918 * identical to the one that shows up in f_tc_ho_inter_bsc1. Can only do that by feeding in a vector to both
5919 * components and then not overwriting it in BSC_ConnectionHandler. */
5920 pars1.vec := pars0.vec;
5921 pars1.vec_keep := true;
5922
5923 if (a5_n > 0) {
5924 f_vty_config(MSCVTY, "network", "authentication required");
5925 }
5926 f_vty_config(MSCVTY, "network", "encryption a5 " & int2str(a5_n));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005927
5928 vc_conn0 := f_start_handler_with_pars(refers(f_tc_ho_inter_bsc0), pars0, 0);
5929 vc_conn1 := f_start_handler_with_pars(refers(f_tc_ho_inter_bsc1), pars1, 1);
5930 vc_conn0.done;
5931 vc_conn1.done;
5932}
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005933testcase TC_ho_inter_bsc() runs on MTC_CT {
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005934 f_tc_ho_inter_bsc_main(false, a5_n := 0);
5935}
5936testcase TC_ho_inter_bsc_a5_1() runs on MTC_CT {
5937 f_tc_ho_inter_bsc_main(false, a5_n := 1);
5938}
5939testcase TC_ho_inter_bsc_a5_3() runs on MTC_CT {
5940 f_tc_ho_inter_bsc_main(false, a5_n := 3);
5941}
5942testcase TC_ho_inter_bsc_a5_4() runs on MTC_CT {
5943 f_tc_ho_inter_bsc_main(false, a5_n := 4);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005944}
5945testcase TC_ho_inter_bsc_ipv6() runs on MTC_CT {
5946 f_tc_ho_inter_bsc_main(true);
5947}
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005948
5949function f_ML3_patch_seq_nr_MS_NW(in uint2_t seq_nr, inout octetstring enc_l3) {
5950 log("MS_NW patching N(SD)=", seq_nr, " into dtap ", enc_l3);
5951 enc_l3[2] := (enc_l3[2] and4b '3f'O) or4b bit2oct(int2bit(seq_nr, 8) << 6);
5952 log("MS_NW patched enc_l3: ", enc_l3);
5953}
5954
5955private function f_tc_ho_inter_msc_out(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005956 var CallParameters cpars;
Neels Hofmeyr906af102021-07-01 12:08:35 +02005957 var PDU_BSSAP ho_request;
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005958
5959 cpars := valueof(t_CallParams('12345'H, 0));
5960 if (pars.use_ipv6) {
5961 cpars.mgw_conn_1.mgw_rtp_ip := "::1";
5962 cpars.mgw_conn_2.mgw_rtp_ip := "::2";
5963 cpars.bss_rtp_ip := "::3";
5964 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005965 var hexstring ho_number := f_gen_msisdn(99999);
5966
5967 f_init_handler(pars);
5968
5969 f_create_mncc_expect(hex2str(ho_number));
5970
5971 f_vty_transceive(MSCVTY, "configure terminal");
5972 f_vty_transceive(MSCVTY, "msc");
5973 f_vty_transceive(MSCVTY, "neighbor a cgi 017 017 1 1 msc-ipa-name msc-017-017-1");
5974 f_vty_transceive(MSCVTY, "exit");
5975 f_vty_transceive(MSCVTY, "exit");
5976
5977 f_perform_lu();
5978 f_mo_call_establish(cpars);
5979
5980 f_sleep(1.0);
5981
5982 var default ack_mdcx := activate(as_mgcp_ack_all_mdcx(cpars));
5983
5984 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5985 var BssmapCause cause := enum2int(cause_val);
5986
5987 var template BSSMAP_FIELD_CellIdentificationList cil;
Neels Hofmeyr36ebc332021-06-23 03:20:32 +02005988 cil := { cIl_CGI := { ts_BSSMAP_CI_CGI('017'H, '017'H, 1, 1) } };
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005989
5990 /* old BSS sends Handover Required */
5991 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5992
5993 /* The target cell 017-017 LAC 1 is configured to be a remote MSC of name "msc-017-017-1".
5994 * This MSC tries to reach the other MSC via GSUP. */
5995
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02005996 var template BSSMAP_IE_EncryptionInformation encryptionInformation;
5997 var template BSSMAP_IE_ChosenEncryptionAlgorithm chosenEncryptionAlgorithm;
5998 var template BSSMAP_IE_KC128 kC128;
5999 var OCT1 a5_perm_alg;
6000 f_get_expected_encryption(encryptionInformation, chosenEncryptionAlgorithm, kC128, a5_perm_alg);
6001 var template PDU_BSSAP expect_ho_request := tr_BSSMAP_HandoverRequest(encryptionInformation, chosenEncryptionAlgorithm, kC128);
6002
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006003 var octetstring remote_msc_name := '6D73632D3031372D3031372D3100'O; /* "msc-017-017-1\0" as octetstring */
6004 var GSUP_PDU prep_ho_req;
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006005 alt {
6006 [] GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_HANDOVER_REQUEST,
6007 pars.imsi, destination_name := remote_msc_name,
Neels Hofmeyrec2e1f72021-07-02 02:08:32 +02006008 an_apdu := t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006, pdu := ?))) -> value prep_ho_req;
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006009 [] GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_HANDOVER_REQUEST)) {
6010 setverdict(fail, "Wrong OSMO_GSUP_MSGT_E_PREPARE_HANDOVER_REQUEST message received");
6011 mtc.stop;
6012 }
6013 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006014
6015 var GSUP_IeValue source_name_ie;
6016 f_gsup_find_ie(prep_ho_req, OSMO_GSUP_SOURCE_NAME_IE, source_name_ie);
6017 var octetstring local_msc_name := source_name_ie.source_name;
6018
Neels Hofmeyrec2e1f72021-07-02 02:08:32 +02006019 /* Decode PDU to 1) match with expect_ho_request and 2) to forward the actual chosen encryption algorithm. */
Neels Hofmeyr906af102021-07-01 12:08:35 +02006020 var GSUP_IeValue an_apdu_ie;
6021 f_gsup_find_ie(prep_ho_req, OSMO_GSUP_AN_APDU_IE, an_apdu_ie);
6022 ho_request := dec_PDU_BSSAP(an_apdu_ie.an_apdu.pdu);
Neels Hofmeyrec2e1f72021-07-02 02:08:32 +02006023 if (not match(ho_request, expect_ho_request)) {
6024 setverdict(fail, "Wrong PDU in OSMO_GSUP_MSGT_E_PREPARE_HANDOVER_REQUEST message received");
6025 mtc.stop;
6026 }
Neels Hofmeyr906af102021-07-01 12:08:35 +02006027
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006028 /* Remote MSC has figured out its BSC and signals success */
6029 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
6030 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
6031 var PDU_BSSAP ho_req_ack := valueof(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
Neels Hofmeyr906af102021-07-01 12:08:35 +02006032 aoIPTransportLayer := omit,
6033 speechCodec := ts_BSSMAP_IE_SpeechCodec({ts_CodecFR}),
6034 chosenEncryptionAlgorithm := ho_request.pdu.bssmap.handoverRequest.chosenEncryptionAlgorithm));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006035 GSUP.send(ts_GSUP_E_PrepareHandoverResult(
6036 pars.imsi,
6037 ho_number,
6038 remote_msc_name, local_msc_name,
6039 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006, enc_PDU_BSSAP(ho_req_ack)))));
6040
6041 /* MSC forwards the RR Handover Command to old BSS */
6042 BSSAP.receive(tr_BSSMAP_HandoverCommand);
6043
6044 /* The MS shows up at remote new BSS */
6045
6046 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PROCESS_ACCESS_SIGNALLING_REQUEST,
6047 pars.imsi, remote_msc_name, local_msc_name,
6048 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
6049 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverDetect))))));
6050 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
6051 f_sleep(0.1);
6052
6053 /* Save the MS sequence counters for use on the other connection */
6054 var N_Sd_Array last_n_sd := f_bssmap_last_n_sd();
6055
6056 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_SEND_END_SIGNAL_REQUEST,
6057 pars.imsi, remote_msc_name, local_msc_name,
6058 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
6059 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverComplete))))));
6060
6061 /* The local BSS conn clears, all communication goes via remote MSC now */
6062 f_expect_clear();
6063
6064 /**********************************/
6065 /* Play through some signalling across the inter-MSC link.
6066 * This is a copy of f_tc_lu_and_mo_ussd_single_request() translated into GSUP AN-APDUs. */
6067
6068 if (false) {
6069 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
6070 invoke_id := 5, /* Phone may not start from 0 or 1 */
6071 op_code := SS_OP_CODE_PROCESS_USS_REQ,
6072 ussd_string := "*#100#"
6073 );
6074
6075 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
6076 invoke_id := 5, /* InvokeID shall be the same for both REQ and RSP */
6077 op_code := SS_OP_CODE_PROCESS_USS_REQ,
6078 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
6079 )
6080
6081 /* Compose a new SS/REGISTER message with request */
6082 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
6083 tid := 1, /* We just need a single transaction */
6084 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
6085 facility := valueof(facility_req)
6086 );
6087 var PDU_ML3_MS_NW ussd_req_v := valueof(ussd_req);
6088
6089 /* Compose SS/RELEASE_COMPLETE template with expected response */
6090 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
6091 tid := 1, /* Response should arrive within the same transaction */
6092 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
6093 facility := valueof(facility_rsp)
6094 );
6095
6096 /* Compose expected MSC -> HLR message */
6097 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
6098 imsi := g_pars.imsi,
6099 state := OSMO_GSUP_SESSION_STATE_BEGIN,
6100 ss := valueof(facility_req)
6101 );
6102
6103 /* To be used for sending response with correct session ID */
6104 var GSUP_PDU gsup_req_complete;
6105
6106 /* Request own number */
6107 /* From remote MSC instead of BSSAP directly */
6108 /* Patch the correct N_SD value into the message. */
6109 var octetstring l3_enc := enc_PDU_ML3_MS_NW(ussd_req_v);
6110 var RAN_Emulation.ConnectionData cd;
6111 f_ML3_patch_seq_nr_MS_NW(f_next_n_sd(last_n_sd, f_ML3_n_sd_idx(ussd_req_v)), l3_enc);
6112 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PROCESS_ACCESS_SIGNALLING_REQUEST,
6113 pars.imsi, remote_msc_name, local_msc_name,
6114 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
6115 enc_PDU_BSSAP(valueof(ts_BSSAP_DTAP(l3_enc)))
6116 ))
6117 ));
6118
6119 /* Expect GSUP message containing the SS payload */
6120 gsup_req_complete := f_expect_gsup_msg(gsup_req);
6121
6122 /* Compose the response from HLR using received session ID */
6123 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
6124 imsi := g_pars.imsi,
6125 sid := gsup_req_complete.ies[1].val.session_id,
6126 state := OSMO_GSUP_SESSION_STATE_END,
6127 ss := valueof(facility_rsp)
6128 );
6129
6130 /* Finally, HLR terminates the session */
6131 GSUP.send(gsup_rsp);
6132
6133 /* The USSD response goes out to remote MSC, on GSUP E instead of BSSAP */
6134 var GSUP_PDU gsup_ussd_rsp;
6135 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_FORWARD_ACCESS_SIGNALLING_REQUEST,
6136 pars.imsi, destination_name := remote_msc_name)) -> value gsup_ussd_rsp;
6137
6138 var GSUP_IeValue an_apdu;
6139 if (not f_gsup_find_ie(gsup_ussd_rsp, OSMO_GSUP_AN_APDU_IE, an_apdu)) {
6140 setverdict(fail, "No AN-APDU in received GSUP message. Expected USSD response in DTAP, got", gsup_ussd_rsp);
6141 mtc.stop;
6142 }
6143 var PDU_BSSAP bssap_dtap_mt := dec_PDU_BSSAP(an_apdu.an_apdu.pdu);
6144 var PDU_ML3_NW_MS dtap_mt := dec_PDU_ML3_NW_MS(bssap_dtap_mt.pdu.dtap);
6145 log("Expecting", ussd_rsp);
6146 log("Got", dtap_mt);
6147 if (not match(dtap_mt, ussd_rsp)) {
6148 setverdict(fail, "Unexpected GSUP message. Expected USSD response in DTAP, got", gsup_ussd_rsp);
6149 mtc.stop;
6150 }
6151 }
6152 /**********************************/
6153
6154
6155 /* inter-MSC handover back to the first MSC */
6156 f_create_bssmap_exp_handoverRequest(193);
6157 cil := { cIl_CGI := { ts_BSSMAP_CI_CGI('262'H, '42'H, 23, 42) } };
6158
6159 /* old BSS sends Handover Required, via inter-MSC E link: like
6160 * BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
6161 * but via GSUP */
6162 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_SUBSEQUENT_HANDOVER_REQUEST,
6163 pars.imsi, remote_msc_name, local_msc_name,
6164 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
6165 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverRequired(cause, cil)))
6166 ))
6167 ));
6168
6169 /* MSC asks local BSS to prepare Handover to it */
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006170 f_get_expected_encryption(encryptionInformation, chosenEncryptionAlgorithm, kC128, a5_perm_alg);
6171 expect_ho_request := tr_BSSMAP_HandoverRequest(encryptionInformation, chosenEncryptionAlgorithm, kC128);
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006172 alt {
Neels Hofmeyr906af102021-07-01 12:08:35 +02006173 [] BSSAP.receive(expect_ho_request) -> value ho_request;
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006174 [] BSSAP.receive(tr_BSSMAP_HandoverRequest) -> value ho_request {
6175 log("Error: Wrong handoverRequest received. Expected: ", expect_ho_request,
6176 " got ", ho_request);
6177 setverdict(fail, "Wrong handoverRequest received");
6178 mtc.stop;
6179 }
6180 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006181
6182 /* Make sure the new BSSAP conn continues with the correct N_SD sequence numbers */
6183 f_bssmap_continue_after_n_sd(last_n_sd);
6184
6185 /* new BSS composes a RR Handover Command */
6186 rr_ho_cmd := valueof(ts_RR_HandoverCommand);
6187 rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006188 var BSSMAP_IE_AoIP_TransportLayerAddress tla :=
6189 valueof(f_ts_BSSMAP_IE_AoIP_TLA(cpars.bss_rtp_ip, cpars.bss_rtp_port));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006190 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
Neels Hofmeyr906af102021-07-01 12:08:35 +02006191 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR}),
6192 chosenEncryptionAlgorithm := ho_request.pdu.bssmap.handoverRequest.chosenEncryptionAlgorithm));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006193
6194 /* HandoverCommand goes out via remote MSC-I */
6195 var GSUP_PDU prep_subsq_ho_res;
6196 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_SUBSEQUENT_HANDOVER_RESULT,
6197 pars.imsi, destination_name := remote_msc_name)) -> value prep_subsq_ho_res;
6198
6199 /* MS shows up at the local BSS */
6200 BSSAP.send(ts_BSSMAP_HandoverDetect);
6201 f_sleep(0.1);
6202 BSSAP.send(ts_BSSMAP_HandoverComplete);
6203
6204 /* Handover Succeeded message */
6205 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_FORWARD_ACCESS_SIGNALLING_REQUEST,
6206 pars.imsi, destination_name := remote_msc_name));
6207
6208 /* MS has handovered to here, Clear Command goes out via remote MSC-I -- in form of a GSUP Close. */
6209 GSUP.receive(tr_GSUP_E_NO_PDU(OSMO_GSUP_MSGT_E_CLOSE,
6210 pars.imsi, destination_name := remote_msc_name));
6211
6212 /* Handover ends successfully. Call goes on for a little longer and then we hang up. */
6213
6214 f_sleep(1.0);
6215 deactivate(ack_mdcx);
6216
6217 /* FIXME: the inter-MSC call has put a number of MNCC messages in the queue, which above code should expect and
6218 * clear out. The f_call_hangup() expects an MNCC_REL_IND, so, for the time being, just clear the MNCC messages
6219 * before starting the call hangup. Instead of this, the individual messages should be tested for above. */
6220 MNCC.clear;
6221
6222 var default ccrel := activate(as_optional_cc_rel(cpars, true));
6223 f_call_hangup(cpars, true);
6224 f_sleep(1.0);
6225 deactivate(ccrel);
6226
6227 setverdict(pass);
6228}
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006229function f_tc_ho_inter_msc_out_a5(integer a5_n) runs on MTC_CT {
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006230 var BSC_ConnHdlr vc_conn;
6231 f_init(1);
6232
6233 var BSC_ConnHdlrPars pars := f_init_pars(54);
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006234 pars.net.expect_ciph := a5_n > 0;
6235 pars.net.expect_auth := pars.net.expect_ciph;
6236 pars.net.kc_support := bit2oct('00000001'B << a5_n);
6237 pars.cm2.classmarkInformationType2_oct5.a5_3 := '1'B;
6238 pars.cm2.classmarkInformationType2_oct5.a5_2 := '0'B;
6239 pars.cm2.classmarkInformationType2_oct5.cm3 := '1'B;
6240 pars.cm3 := valueof(ts_CM3_default);
6241 pars.use_umts_aka := true;
6242
6243 if (a5_n > 0) {
6244 f_vty_config(MSCVTY, "network", "authentication required");
6245 }
6246 f_vty_config(MSCVTY, "network", "encryption a5 " & int2str(a5_n));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006247
6248 vc_conn := f_start_handler_with_pars(refers(f_tc_ho_inter_msc_out), pars, 0);
6249 vc_conn.done;
6250}
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006251testcase TC_ho_inter_msc_out() runs on MTC_CT {
6252 f_tc_ho_inter_msc_out_a5(0);
6253}
6254testcase TC_ho_inter_msc_out_a5_1() runs on MTC_CT {
6255 f_tc_ho_inter_msc_out_a5(1);
6256}
6257testcase TC_ho_inter_msc_out_a5_3() runs on MTC_CT {
6258 f_tc_ho_inter_msc_out_a5(3);
6259}
6260testcase TC_ho_inter_msc_out_a5_4() runs on MTC_CT {
6261 f_tc_ho_inter_msc_out_a5(4);
6262}
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006263testcase TC_ho_inter_msc_out_ipv6() runs on MTC_CT {
6264 var BSC_ConnHdlr vc_conn;
6265 f_init(1);
6266
6267 var BSC_ConnHdlrPars pars := f_init_pars(54);
6268 pars.use_ipv6 := true;
6269
6270 vc_conn := f_start_handler_with_pars(refers(f_tc_ho_inter_msc_out), pars, 0);
6271 vc_conn.done;
6272}
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006273
Oliver Smith1d118ff2019-07-03 10:57:35 +02006274private function f_tc_lu_imsi_auth_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6275 pars.net.expect_auth := true;
6276 pars.net.expect_imei := true;
6277 f_init_handler(pars);
6278 f_perform_lu();
6279}
6280testcase TC_lu_imsi_auth_tmsi_check_imei() runs on MTC_CT {
6281 var BSC_ConnHdlr vc_conn;
6282 f_init();
6283 f_vty_config(MSCVTY, "network", "authentication required");
6284 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6285
6286 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei), 5);
6287 vc_conn.done;
6288}
6289
6290private function f_tc_lu_imsi_auth3g_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6291 pars.net.expect_auth := true;
6292 pars.use_umts_aka := true;
6293 pars.net.expect_imei := true;
6294 f_init_handler(pars);
6295 f_perform_lu();
6296}
6297testcase TC_lu_imsi_auth3g_tmsi_check_imei() runs on MTC_CT {
6298 var BSC_ConnHdlr vc_conn;
6299 f_init();
6300 f_vty_config(MSCVTY, "network", "authentication required");
6301 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6302
6303 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi_check_imei), 5);
6304 vc_conn.done;
6305}
6306
6307private function f_tc_lu_imsi_noauth_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6308 pars.net.expect_imei := true;
6309 f_init_handler(pars);
6310 f_perform_lu();
6311}
6312testcase TC_lu_imsi_noauth_tmsi_check_imei() runs on MTC_CT {
6313 var BSC_ConnHdlr vc_conn;
6314 f_init();
6315 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6316
6317 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi_check_imei), 5);
6318 vc_conn.done;
6319}
6320
6321private function f_tc_lu_imsi_noauth_notmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6322 pars.net.expect_tmsi := false;
6323 pars.net.expect_imei := true;
6324 f_init_handler(pars);
6325 f_perform_lu();
6326}
6327testcase TC_lu_imsi_noauth_notmsi_check_imei() runs on MTC_CT {
6328 var BSC_ConnHdlr vc_conn;
6329 f_init();
6330 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
6331 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6332
6333 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi_check_imei), 5);
6334 vc_conn.done;
6335}
6336
6337private function f_tc_lu_imsi_auth_tmsi_check_imei_nack(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6338 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02006339
6340 pars.net.expect_auth := true;
6341 pars.net.expect_imei := true;
6342 pars.net.check_imei_result := OSMO_GSUP_IMEI_RESULT_NACK;
6343 f_init_handler(pars);
6344
6345 /* Cannot use f_perform_lu() as we expect a reject */
6346 l3_lu := f_build_lu_imsi(g_pars.imsi)
6347 f_create_gsup_expect(hex2str(g_pars.imsi));
6348 f_bssap_compl_l3(l3_lu);
6349 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
6350
6351 f_mm_common();
6352 f_msc_lu_hlr();
6353 f_mm_imei();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02006354 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02006355 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02006356}
6357testcase TC_lu_imsi_auth_tmsi_check_imei_nack() runs on MTC_CT {
6358 var BSC_ConnHdlr vc_conn;
6359 f_init();
6360 f_vty_config(MSCVTY, "network", "authentication required");
6361 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6362
6363 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_nack), 5);
6364 vc_conn.done;
6365}
6366
6367private function f_tc_lu_imsi_auth_tmsi_check_imei_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6368 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02006369
6370 pars.net.expect_auth := true;
6371 pars.net.expect_imei := true;
6372 pars.net.check_imei_error := true;
6373 f_init_handler(pars);
6374
6375 /* Cannot use f_perform_lu() as we expect a reject */
6376 l3_lu := f_build_lu_imsi(g_pars.imsi)
6377 f_create_gsup_expect(hex2str(g_pars.imsi));
6378 f_bssap_compl_l3(l3_lu);
6379 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
6380
6381 f_mm_common();
6382 f_msc_lu_hlr();
6383 f_mm_imei();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02006384 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02006385 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02006386}
6387testcase TC_lu_imsi_auth_tmsi_check_imei_err() runs on MTC_CT {
6388 var BSC_ConnHdlr vc_conn;
6389 f_init();
6390 f_vty_config(MSCVTY, "network", "authentication required");
6391 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6392
6393 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_err), 5);
6394 vc_conn.done;
6395}
6396
6397private function f_tc_lu_imsi_auth_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6398 pars.net.expect_auth := true;
6399 pars.net.expect_imei_early := true;
6400 f_init_handler(pars);
6401 f_perform_lu();
6402}
6403testcase TC_lu_imsi_auth_tmsi_check_imei_early() runs on MTC_CT {
6404 var BSC_ConnHdlr vc_conn;
6405 f_init();
6406 f_vty_config(MSCVTY, "network", "authentication required");
6407 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6408
6409 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early), 5);
6410 vc_conn.done;
6411}
6412
6413private function f_tc_lu_imsi_auth3g_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6414 pars.net.expect_auth := true;
6415 pars.use_umts_aka := true;
6416 pars.net.expect_imei_early := true;
6417 f_init_handler(pars);
6418 f_perform_lu();
6419}
6420testcase TC_lu_imsi_auth3g_tmsi_check_imei_early() runs on MTC_CT {
6421 var BSC_ConnHdlr vc_conn;
6422 f_init();
6423 f_vty_config(MSCVTY, "network", "authentication required");
6424 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6425
6426 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi_check_imei_early), 5);
6427 vc_conn.done;
6428}
6429
6430private function f_tc_lu_imsi_noauth_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6431 pars.net.expect_imei_early := true;
6432 f_init_handler(pars);
6433 f_perform_lu();
6434}
6435testcase TC_lu_imsi_noauth_tmsi_check_imei_early() runs on MTC_CT {
6436 var BSC_ConnHdlr vc_conn;
6437 f_init();
6438 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6439
6440 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi_check_imei_early), 5);
6441 vc_conn.done;
6442}
6443
6444private function f_tc_lu_imsi_noauth_notmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6445 pars.net.expect_tmsi := false;
6446 pars.net.expect_imei_early := true;
6447 f_init_handler(pars);
6448 f_perform_lu();
6449}
6450testcase TC_lu_imsi_noauth_notmsi_check_imei_early() runs on MTC_CT {
6451 var BSC_ConnHdlr vc_conn;
6452 f_init();
6453 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
6454 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6455
6456 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi_check_imei_early), 5);
6457 vc_conn.done;
6458}
6459
6460private function f_tc_lu_imsi_auth_tmsi_check_imei_early_nack(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6461 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02006462
6463 pars.net.expect_auth := true;
6464 pars.net.expect_imei_early := true;
6465 pars.net.check_imei_result := OSMO_GSUP_IMEI_RESULT_NACK;
6466 f_init_handler(pars);
6467
6468 /* Cannot use f_perform_lu() as we expect a reject */
6469 l3_lu := f_build_lu_imsi(g_pars.imsi)
6470 f_create_gsup_expect(hex2str(g_pars.imsi));
6471 f_bssap_compl_l3(l3_lu);
6472 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
6473
6474 f_mm_imei_early();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02006475 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02006476 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02006477}
6478testcase TC_lu_imsi_auth_tmsi_check_imei_early_nack() runs on MTC_CT {
6479 var BSC_ConnHdlr vc_conn;
6480 f_init();
6481 f_vty_config(MSCVTY, "network", "authentication required");
6482 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6483
6484 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early_nack), 5);
6485 vc_conn.done;
6486}
6487
6488private function f_tc_lu_imsi_auth_tmsi_check_imei_early_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6489 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02006490
6491 pars.net.expect_auth := true;
6492 pars.net.expect_imei_early := true;
6493 pars.net.check_imei_error := true;
6494 f_init_handler(pars);
6495
6496 /* Cannot use f_perform_lu() as we expect a reject */
6497 l3_lu := f_build_lu_imsi(g_pars.imsi)
6498 f_create_gsup_expect(hex2str(g_pars.imsi));
6499 f_bssap_compl_l3(l3_lu);
6500 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
6501
6502 f_mm_imei_early();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02006503 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02006504 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02006505}
6506testcase TC_lu_imsi_auth_tmsi_check_imei_early_err() runs on MTC_CT {
6507 var BSC_ConnHdlr vc_conn;
6508 f_init();
6509 f_vty_config(MSCVTY, "network", "authentication required");
6510 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6511
6512 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early_err), 5);
6513 vc_conn.done;
6514}
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006515
Neels Hofmeyr8df69622019-11-02 19:16:03 +01006516friend function f_tc_invalid_mgcp_crash(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6517 f_init_handler(pars);
6518 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
6519
6520 /* Set invalid IP address so that osmo-msc discards the rtp_stream and MGCP endpoint FSM instances in the middle
6521 * of successful MGCP response dispatch. If things aren't safeguarded, the on_success() in osmo_mgcpc_ep_fsm
6522 * will cause a use-after-free after that event dispatch. */
6523 cpars.mgw_conn_1.mgw_rtp_ip := "0.0.0.0";
6524 cpars.mgw_conn_2.mgw_rtp_ip := "0.0.0.0";
6525 cpars.rtp_sdp_format := "FOO/8000";
6526 cpars.expect_release := true;
6527
6528 f_perform_lu();
6529 f_mo_call_establish(cpars);
6530}
6531testcase TC_invalid_mgcp_crash() runs on MTC_CT {
6532 var BSC_ConnHdlr vc_conn;
6533 f_init();
6534
6535 vc_conn := f_start_handler(refers(f_tc_invalid_mgcp_crash), 7);
6536 vc_conn.done;
6537}
6538
Vadim Yanitskiyeddebaa2019-12-28 17:45:34 +01006539friend function f_tc_mm_id_resp_no_identity(charstring id, BSC_ConnHdlrPars pars)
6540runs on BSC_ConnHdlr {
6541 pars.tmsi := 'FFFFFFFF'O;
6542 f_init_handler(pars);
6543
6544 f_create_gsup_expect(hex2str(g_pars.imsi));
6545
6546 /* Initiate Location Updating using an unknown TMSI */
6547 f_bssap_compl_l3(f_build_lu_tmsi(pars.tmsi));
6548
6549 /* Expect an Identity Request, send response with no identity */
6550 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
6551 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp({
6552 lengthIndicator := 1,
6553 mobileIdentityV := {
6554 typeOfIdentity := '000'B,
6555 oddEvenInd_identity := {
6556 no_identity := {
6557 oddevenIndicator := '0'B,
6558 fillerDigits := '00000'H
6559 }
6560 }
6561 }
6562 })));
6563
6564 f_expect_lu_reject();
6565 f_expect_clear();
6566}
6567testcase TC_mm_id_resp_no_identity() runs on MTC_CT {
6568 var BSC_ConnHdlr vc_conn;
6569
6570 f_init();
6571
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02006572 vc_conn := f_start_handler(refers(f_tc_mm_id_resp_no_identity), 7, verify_cell_id := false);
Vadim Yanitskiyeddebaa2019-12-28 17:45:34 +01006573 vc_conn.done;
6574}
6575
Vadim Yanitskiy25219062020-01-21 01:41:33 +07006576/* Verify the case when T3212 expires during Paging procedure, just before the receipt
6577 * of Paging Response. This used to provoke a NULL-pointer dereference in old versions
6578 * of OsmoMSC, but apparently the bug has been fixed, and we're safe now. */
6579friend function f_tc_lu_and_expire_while_paging(charstring id, BSC_ConnHdlrPars pars)
6580runs on BSC_ConnHdlr {
6581 var charstring imsi := hex2str(pars.imsi);
6582
6583 f_init_handler(pars);
6584
6585 /* Perform location update */
6586 f_perform_lu();
6587
6588 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
6589 f_create_gsup_expect(hex2str(g_pars.imsi));
6590
6591 /* Initiate paging procedure from the VTY */
6592 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " paging");
6593 f_expect_paging();
6594
6595 /* Emulate T3212 expiration during paging (we don't want to wait, right?) */
6596 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " expire");
6597
6598 /* MS sends PAGING RESPONSE, *old* OsmoMSC crashes here... */
6599 f_establish_fully(EST_TYPE_PAG_RESP);
6600
6601 /* The recent OsmoMSC keeps subscriber in its VLR unless the Paging is completed.
6602 * In this case we do not send anything and just wait for a Clear Command. */
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02006603 f_expect_clear(verify_vlr_cell_id := false);
Vadim Yanitskiy25219062020-01-21 01:41:33 +07006604}
6605testcase TC_lu_and_expire_while_paging() runs on MTC_CT {
6606 var BSC_ConnHdlr vc_conn;
6607
6608 f_init();
6609
6610 vc_conn := f_start_handler(refers(f_tc_lu_and_expire_while_paging), 7);
6611 vc_conn.done;
6612}
6613
Harald Weltef6dd64d2017-11-19 12:09:51 +01006614control {
Philipp Maier328d1662018-03-07 10:40:27 +01006615 execute( TC_cr_before_reset() );
Harald Weltea49e36e2018-01-21 19:29:33 +01006616 execute( TC_lu_imsi_noauth_tmsi() );
Harald Welted2328a22018-01-27 14:27:16 +01006617 execute( TC_lu_imsi_noauth_notmsi() );
Harald Weltea49e36e2018-01-21 19:29:33 +01006618 execute( TC_lu_imsi_reject() );
6619 execute( TC_lu_imsi_timeout_gsup() );
Harald Welted2328a22018-01-27 14:27:16 +01006620 execute( TC_lu_imsi_auth_tmsi() );
Harald Welte8a397ae2019-04-21 22:03:37 +02006621 execute( TC_lu_imsi_auth3g_tmsi() );
Pau Espin Pedrold3d54a92019-12-17 17:02:54 +01006622 execute( TC_lu_imsi_timeout_tmsi_realloc() );
Harald Welted2328a22018-01-27 14:27:16 +01006623 execute( TC_cmserv_imsi_unknown() );
Neels Hofmeyr13737fb2020-08-19 13:16:14 +00006624 execute( TC_cmserv_tmsi_unknown() );
Harald Welte2bb825f2018-01-22 11:31:18 +01006625 execute( TC_lu_and_mo_call() );
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006626 execute( TC_lu_and_mo_call_ipv6() );
Pau Espin Pedrola42745c2020-01-10 18:03:28 +01006627 execute( TC_lu_and_mo_call_sccp_tiar_timeout() );
Harald Welte071ed732018-01-23 19:53:52 +01006628 execute( TC_lu_auth_sai_timeout() );
6629 execute( TC_lu_auth_sai_err() );
Harald Weltee1a2f3c2018-01-24 17:28:48 +01006630 execute( TC_lu_clear_request() );
Vadim Yanitskiy109e7552021-02-05 05:36:02 +01006631 execute( TC_mo_call_clear_request() );
6632 execute( TC_mt_call_clear_request() );
Harald Weltee1a2f3c2018-01-24 17:28:48 +01006633 execute( TC_lu_disconnect() );
6634 execute( TC_lu_by_imei() );
6635 execute( TC_lu_by_tmsi_noauth_unknown() );
Neels Hofmeyrfc06c732020-08-19 12:52:28 +00006636 execute( TC_attached_imsi_lu_unknown_tmsi() );
Harald Weltee1a2f3c2018-01-24 17:28:48 +01006637 execute( TC_imsi_detach_by_imsi() );
6638 execute( TC_imsi_detach_by_tmsi() );
6639 execute( TC_imsi_detach_by_imei() );
6640 execute( TC_emerg_call_imei_reject() );
6641 execute( TC_emerg_call_imsi() );
6642 execute( TC_cm_serv_req_vgcs_reject() );
6643 execute( TC_cm_serv_req_vbs_reject() );
6644 execute( TC_cm_serv_req_lcs_reject() );
Harald Welte0195ab12018-01-24 21:50:20 +01006645 execute( TC_cm_reest_req_reject() );
Harald Welte1af6ea82018-01-25 18:33:15 +01006646 execute( TC_lu_auth_2G_fail() );
6647 execute( TC_lu_imsi_auth_tmsi_encr_13_13() );
6648 execute( TC_cl3_no_payload() );
6649 execute( TC_cl3_rnd_payload() );
Harald Welte1852a842018-01-26 22:53:36 +01006650 execute( TC_establish_and_nothing() );
6651 execute( TC_mo_setup_and_nothing() );
6652 execute( TC_mo_crcx_ran_timeout() );
6653 execute( TC_mo_crcx_ran_reject() );
Harald Welted2328a22018-01-27 14:27:16 +01006654 execute( TC_mt_crcx_ran_reject() );
Daniel Willmann8b084372018-02-04 13:35:26 +01006655 execute( TC_mo_setup_and_dtmf_dup() );
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01006656 execute( TC_mt_t310() );
Harald Welte167458a2018-01-27 15:58:16 +01006657 execute( TC_gsup_cancel() );
Harald Welte9de84792018-01-28 01:06:35 +01006658 execute( TC_lu_imsi_auth_tmsi_encr_1_13() );
6659 execute( TC_lu_imsi_auth_tmsi_encr_3_13() );
6660 execute( TC_lu_imsi_auth_tmsi_encr_3_1() );
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01006661 execute( TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() );
Harald Welte9de84792018-01-28 01:06:35 +01006662 execute( TC_lu_imsi_auth_tmsi_encr_13_2() );
6663 execute( TC_lu_imsi_auth_tmsi_encr_013_2() );
Eric Wild26f4a622021-05-17 15:27:05 +02006664 execute( TC_lu_imsi_auth_tmsi_encr_0134_1() );
6665 execute( TC_lu_imsi_auth_tmsi_encr_0134_34() );
6666 execute( TC_lu_imsi_auth_tmsi_encr_0134_34_no_cm3() );
6667
Philipp Maier94f3f1b2018-03-15 18:54:13 +01006668 execute( TC_mo_release_timeout() );
Philipp Maier2a98a732018-03-19 16:06:12 +01006669 execute( TC_lu_and_mt_call_no_dlcx_resp() );
Philipp Maier75932982018-03-27 14:52:35 +02006670 execute( TC_reset_two() );
Harald Welte33ec09b2018-02-10 15:34:46 +01006671
6672 execute( TC_lu_and_mt_call() );
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006673 execute( TC_lu_and_mt_call_ipv6() );
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01006674 execute( TC_lu_and_mt_call_already_paging() );
Pau Espin Pedrol9a732a42020-09-15 15:56:33 +02006675 execute( TC_lu_and_mt_call_osmux() );
Harald Welte33ec09b2018-02-10 15:34:46 +01006676
Harald Weltef45efeb2018-04-09 18:19:24 +02006677 execute( TC_lu_and_mo_sms() );
6678 execute( TC_lu_and_mt_sms() );
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01006679 execute( TC_lu_and_mt_sms_already_paging() );
Philipp Maier3983e702018-11-22 19:01:33 +01006680 execute( TC_lu_and_mt_sms_paging_and_nothing() );
Alexander Couzensfc02f242019-09-12 03:43:18 +02006681 execute( TC_lu_and_mt_sms_paging_repeated() );
Harald Weltef640a012018-04-14 17:49:21 +02006682 execute( TC_smpp_mo_sms() );
Vadim Yanitskiy33820762020-01-15 11:26:07 +07006683 execute( TC_smpp_mo_sms_rp_error() );
Harald Weltef640a012018-04-14 17:49:21 +02006684 execute( TC_smpp_mt_sms() );
Harald Weltef45efeb2018-04-09 18:19:24 +02006685
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07006686 execute( TC_gsup_mo_sms() );
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07006687 execute( TC_gsup_mo_smma() );
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07006688 execute( TC_gsup_mt_sms_ack() );
6689 execute( TC_gsup_mt_sms_err() );
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07006690 execute( TC_gsup_mt_sms_rp_mr() );
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07006691 execute( TC_gsup_mo_mt_sms_rp_mr() );
Vadim Yanitskiya2a8a112019-07-08 20:04:32 +07006692 execute( TC_gsup_mt_multi_part_sms() );
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07006693
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07006694 execute( TC_lu_and_mo_ussd_single_request() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07006695 execute( TC_lu_and_mt_ussd_notification() );
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07006696 execute( TC_lu_and_mo_ussd_during_mt_call() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07006697 execute( TC_lu_and_mt_ussd_during_mt_call() );
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07006698 execute( TC_lu_and_mo_ussd_mo_release() );
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07006699 execute( TC_lu_and_ss_session_timeout() );
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07006700
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07006701 execute( TC_mt_ussd_for_unknown_subscr() );
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07006702 execute( TC_mo_ussd_for_unknown_trans() );
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07006703 execute( TC_proc_ss_for_unknown_session() );
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07006704 execute( TC_proc_ss_paging_fail() );
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07006705 execute( TC_proc_ss_abort() );
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07006706
Vadim Yanitskiy1c9754d2020-01-07 21:56:55 +01006707 execute( TC_multi_lu_and_mo_ussd() );
6708 execute( TC_multi_lu_and_mt_ussd() );
6709
Stefan Sperling89eb1f32018-12-17 15:06:20 +01006710 execute( TC_cipher_complete_with_invalid_cipher() );
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01006711 execute( TC_cipher_complete_1_without_cipher() );
6712 execute( TC_cipher_complete_3_without_cipher() );
6713 execute( TC_cipher_complete_13_without_cipher() );
Harald Welteb2284bd2019-05-10 11:30:43 +02006714 execute( TC_lu_with_invalid_mcc_mnc() );
Stefan Sperling89eb1f32018-12-17 15:06:20 +01006715
Harald Welte4263c522018-12-06 11:56:27 +01006716 execute( TC_sgsap_reset() );
6717 execute( TC_sgsap_lu() );
6718 execute( TC_sgsap_lu_imsi_reject() );
6719 execute( TC_sgsap_lu_and_nothing() );
6720 execute( TC_sgsap_expl_imsi_det_eps() );
Philipp Maierfc19f172019-03-21 11:17:54 +01006721 execute( TC_sgsap_impl_imsi_det_eps() );
Harald Welte4263c522018-12-06 11:56:27 +01006722 execute( TC_sgsap_expl_imsi_det_noneps() );
Philipp Maier5d812702019-03-21 10:51:26 +01006723 execute( TC_sgsap_impl_imsi_det_noneps() );
Harald Welte4263c522018-12-06 11:56:27 +01006724 execute( TC_sgsap_paging_rej() );
6725 execute( TC_sgsap_paging_subscr_rej() );
6726 execute( TC_sgsap_paging_ue_unr() );
6727 execute( TC_sgsap_paging_and_nothing() );
6728 execute( TC_sgsap_paging_and_lu() );
6729 execute( TC_sgsap_mt_sms() );
6730 execute( TC_sgsap_mo_sms() );
6731 execute( TC_sgsap_mt_sms_and_nothing() );
6732 execute( TC_sgsap_mt_sms_and_reject() );
6733 execute( TC_sgsap_unexp_ud() );
6734 execute( TC_sgsap_unsol_ud() );
6735 execute( TC_bssap_lu_sgsap_lu_and_mt_call() );
6736 execute( TC_sgsap_lu_and_mt_call() );
Philipp Maier628c0052019-04-09 17:36:57 +02006737 execute( TC_sgsap_vlr_failure() );
Harald Welte4263c522018-12-06 11:56:27 +01006738
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006739 execute( TC_ho_inter_bsc_unknown_cell() );
6740 execute( TC_ho_inter_bsc() );
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02006741 execute( TC_ho_inter_bsc_a5_1() );
6742 execute( TC_ho_inter_bsc_a5_3() );
6743 execute( TC_ho_inter_bsc_a5_4() );
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006744 execute( TC_ho_inter_bsc_ipv6() );
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006745
6746 execute( TC_ho_inter_msc_out() );
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006747 execute( TC_ho_inter_msc_out_a5_1() );
6748 execute( TC_ho_inter_msc_out_a5_3() );
6749 execute( TC_ho_inter_msc_out_a5_4() );
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006750 execute( TC_ho_inter_msc_out_ipv6() );
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006751
Oliver Smith1d118ff2019-07-03 10:57:35 +02006752 execute( TC_lu_imsi_auth_tmsi_check_imei() );
6753 execute( TC_lu_imsi_auth3g_tmsi_check_imei() );
6754 execute( TC_lu_imsi_noauth_tmsi_check_imei() );
6755 execute( TC_lu_imsi_noauth_notmsi_check_imei() );
6756 execute( TC_lu_imsi_auth_tmsi_check_imei_nack() );
6757 execute( TC_lu_imsi_auth_tmsi_check_imei_err() );
6758 execute( TC_lu_imsi_auth_tmsi_check_imei_early() );
6759 execute( TC_lu_imsi_auth3g_tmsi_check_imei_early() );
6760 execute( TC_lu_imsi_noauth_tmsi_check_imei_early() );
6761 execute( TC_lu_imsi_noauth_notmsi_check_imei_early() );
6762 execute( TC_lu_imsi_auth_tmsi_check_imei_early_nack() );
6763 execute( TC_lu_imsi_auth_tmsi_check_imei_early_err() );
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01006764 execute( TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() );
Pau Espin Pedrol609f1d62020-09-15 16:01:55 +02006765
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02006766 execute( TC_mo_cc_bssmap_clear() );
Neels Hofmeyr8df69622019-11-02 19:16:03 +01006767 execute( TC_invalid_mgcp_crash() );
Vadim Yanitskiyeddebaa2019-12-28 17:45:34 +01006768 execute( TC_mm_id_resp_no_identity() );
Vadim Yanitskiy25219062020-01-21 01:41:33 +07006769 execute( TC_lu_and_expire_while_paging() );
Pau Espin Pedrol174fac22021-02-26 13:20:10 +01006770 execute( TC_paging_response_imsi_unknown() );
6771 execute( TC_paging_response_tmsi_unknown() );
Harald Weltef6dd64d2017-11-19 12:09:51 +01006772}
6773
6774
6775}