blob: 72b13ad7d353c607666e0d0220725225ab53d297 [file] [log] [blame]
Harald Weltef6dd64d2017-11-19 12:09:51 +01001module MSC_Tests {
2
3import from General_Types all;
4import from Osmocom_Types all;
5
6import from M3UA_Types all;
7import from M3UA_Emulation all;
8
9import from MTP3asp_Types all;
10import from MTP3asp_PortType all;
11
12import from SCCPasp_Types all;
13import from SCCP_Types all;
14import from SCCP_Emulation all;
15
16import from SCTPasp_Types all;
17import from SCTPasp_PortType all;
18
Harald Weltea49e36e2018-01-21 19:29:33 +010019import from Osmocom_CTRL_Functions all;
20import from Osmocom_CTRL_Types all;
21import from Osmocom_CTRL_Adapter all;
22
Harald Welte3ca1c902018-01-24 18:51:27 +010023import from TELNETasp_PortType all;
24import from Osmocom_VTY_Functions all;
25
Harald Weltea49e36e2018-01-21 19:29:33 +010026import from MNCC_Emulation all;
Harald Welte2bb825f2018-01-22 11:31:18 +010027import from MNCC_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010028
Harald Welte4aa970c2018-01-26 10:38:09 +010029import from MGCP_Emulation all;
30import from MGCP_Types all;
31import from MGCP_Templates all;
32import from SDP_Types all;
33
Harald Weltea49e36e2018-01-21 19:29:33 +010034import from GSUP_Emulation all;
35import from GSUP_Types all;
36import from IPA_Emulation all;
37
Harald Weltef6dd64d2017-11-19 12:09:51 +010038import from BSSAP_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010039import from BSSAP_Adapter all;
40import from BSSAP_CodecPort all;
41import from BSSMAP_Templates all;
42import from BSSMAP_Emulation all;
43import from BSC_ConnectionHandler all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010044
Harald Weltea49e36e2018-01-21 19:29:33 +010045import from MobileL3_Types all;
46import from MobileL3_CommonIE_Types all;
47import from L3_Templates all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010048
Harald Weltef6dd64d2017-11-19 12:09:51 +010049
Harald Weltea49e36e2018-01-21 19:29:33 +010050type component MTC_CT extends BSSAP_Adapter_CT, CTRL_Adapter_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +010051 var boolean g_initialized := false;
Harald Weltea49e36e2018-01-21 19:29:33 +010052
53 /* no 'adapter_CT' for MNCC or GSUP */
54 var MNCC_Emulation_CT vc_MNCC;
Harald Welte4aa970c2018-01-26 10:38:09 +010055 var MGCP_Emulation_CT vc_MGCP;
Harald Weltea49e36e2018-01-21 19:29:33 +010056 var GSUP_Emulation_CT vc_GSUP;
57 var IPA_Emulation_CT vc_GSUP_IPA;
58
59 /* only to get events from IPA underneath GSUP */
60 port IPA_CTRL_PT GSUP_IPA_EVENT;
Harald Welte3ca1c902018-01-24 18:51:27 +010061 /* VTY to MSC */
62 port TELNETasp_PT MSCVTY;
Harald Weltef6dd64d2017-11-19 12:09:51 +010063}
64
65modulepar {
Harald Weltea49e36e2018-01-21 19:29:33 +010066 /* remote parameters of IUT */
67 charstring mp_msc_ip := "127.0.0.1";
68 integer mp_msc_ctrl_port := 4255;
69 integer mp_msc_vty_port := 4254;
Harald Weltef6dd64d2017-11-19 12:09:51 +010070
Harald Weltea49e36e2018-01-21 19:29:33 +010071 /* local parameters of emulated HLR */
72 charstring mp_hlr_ip := "127.0.0.1";
73 integer mp_hlr_port := 4222;
Harald Weltef6dd64d2017-11-19 12:09:51 +010074
Harald Weltea49e36e2018-01-21 19:29:33 +010075 charstring mp_msc_mncc := "/tmp/mncc";
Harald Weltef6dd64d2017-11-19 12:09:51 +010076}
77
78
Harald Weltea49e36e2018-01-21 19:29:33 +010079function f_init_mncc(charstring id) runs on MTC_CT {
80 id := id & "-MNCC";
81 var MnccOps ops := {
82 create_cb := refers(MNCC_Emulation.ExpectedCreateCallback),
83 unitdata_cb := refers(MNCC_Emulation.DummyUnitdataCallback)
84 }
85
86 vc_MNCC := MNCC_Emulation_CT.create(id);
87 map(vc_MNCC:MNCC, system:MNCC_CODEC_PT);
88 vc_MNCC.start(MNCC_Emulation.main(ops, id, mp_msc_mncc));
Harald Weltef6dd64d2017-11-19 12:09:51 +010089}
90
Harald Welte4aa970c2018-01-26 10:38:09 +010091function f_init_mgcp(charstring id) runs on MTC_CT {
92 id := id & "-MGCP";
93 var MGCPOps ops := {
94 create_cb := refers(MGCP_Emulation.ExpectedCreateCallback),
95 unitdata_cb := refers(MGCP_Emulation.DummyUnitdataCallback)
96 }
97 var MGCP_conn_parameters pars := {
98 callagent_ip := "127.0.0.1",
99 callagent_udp_port := -1,
100 mgw_ip := "127.0.0.1",
101 mgw_udp_port := 2427
102 }
103
104 vc_MGCP := MGCP_Emulation_CT.create(id);
105 map(vc_MGCP:MGCP, system:MGCP_CODEC_PT);
106 vc_MGCP.start(MGCP_Emulation.main(ops, pars, id));
107}
108
Harald Weltea49e36e2018-01-21 19:29:33 +0100109function f_init_gsup(charstring id) runs on MTC_CT {
110 id := id & "-GSUP";
111 var GsupOps ops := {
112 create_cb := refers(GSUP_Emulation.ExpectedCreateCallback)
113 }
114
115 vc_GSUP_IPA := IPA_Emulation_CT.create(id & "-IPA");
116 vc_GSUP := GSUP_Emulation_CT.create(id);
117
118 map(vc_GSUP_IPA:IPA_PORT, system:IPA_CODEC_PT);
119 connect(vc_GSUP:GSUP, vc_GSUP_IPA:IPA_GSUP_PORT);
120 /* we use this hack to get events like ASP_IPA_EVENT_UP */
121 connect(vc_GSUP_IPA:IPA_CTRL_PORT, self:GSUP_IPA_EVENT);
122
123 vc_GSUP.start(GSUP_Emulation.main(ops, id));
124 vc_GSUP_IPA.start(IPA_Emulation.main_server(mp_hlr_ip, mp_hlr_port));
125
126 /* wait for incoming connection to GSUP port before proceeding */
127 timer T := 10.0;
128 T.start;
129 alt {
130 [] GSUP_IPA_EVENT.receive(t_ASP_IPA_EVT_UD(ASP_IPA_EVENT_UP)) { }
131 [] T.timeout {
132 setverdict(inconc, "No connection to GSUP Port");
133 self.stop
134 }
135 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100136}
137
Harald Weltea49e36e2018-01-21 19:29:33 +0100138function f_init() runs on MTC_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +0100139
140 if (g_initialized == true) {
141 return;
142 }
143 g_initialized := true;
144
Harald Weltea49e36e2018-01-21 19:29:33 +0100145 f_bssap_init("MSC_Test", BSC_BssmapOps);
146 f_ipa_ctrl_start(mp_msc_ip, mp_msc_ctrl_port);
147 f_init_mncc("MSC_Test");
Harald Welte4aa970c2018-01-26 10:38:09 +0100148 f_init_mgcp("MSC_Test");
Harald Weltea49e36e2018-01-21 19:29:33 +0100149 f_init_gsup("MSC_Test");
Harald Welte3ca1c902018-01-24 18:51:27 +0100150
151 map(self:MSCVTY, system:MSCVTY);
152 f_vty_set_prompts(MSCVTY);
153 f_vty_transceive(MSCVTY, "enable");
Harald Welteb14c77a2018-01-25 17:25:44 +0100154
155 /* set some defaults */
156 f_vty_config(MSCVTY, "network", "authentication optional");
157 f_vty_config(MSCVTY, "msc", "assign-tmsi");
158 f_vty_config(MSCVTY, "network", "encryption a5 0");
Harald Weltef6dd64d2017-11-19 12:09:51 +0100159}
160
161template PDU_BSSAP ts_BSSAP_BSSMAP := {
162 discriminator := '0'B,
163 spare := '0000000'B,
164 dlci := omit,
165 lengthIndicator := 0, /* overwritten by codec */
166 pdu := ?
167}
168
169template PDU_BSSAP tr_BSSAP_BSSMAP := {
170 discriminator := '0'B,
171 spare := '0000000'B,
172 dlci := omit,
173 lengthIndicator := ?,
174 pdu := {
175 bssmap := ?
176 }
177}
178
179
180type integer BssmapCause;
181
182template (value) BSSMAP_IE_Cause ts_BSSMAP_IE_Cause(BssmapCause val) := {
183 elementIdentifier := '04'O,
184 lengthIndicator := 0,
185 causeValue := int2bit(val, 7),
186 extensionCauseValue := '0'B,
187 spare1 := omit
188}
189
190template (value) PDU_BSSAP ts_BSSMAP_Reset(BssmapCause cause) modifies ts_BSSAP_BSSMAP := {
191 pdu := {
192 bssmap := {
193 reset := {
194 messageType := '30'O,
195 cause := ts_BSSMAP_IE_Cause(cause),
196 a_InterfaceSelectorForReset := omit
197 }
198 }
199 }
200}
201
202template (value) PDU_BSSAP ts_BSSMAP_ResetAck modifies ts_BSSAP_BSSMAP := {
203 pdu := {
204 bssmap := {
205 resetAck := {
206 messageType := '31'O,
207 a_InterfaceSelectorForReset := omit
208 }
209 }
210 }
211}
212
213template PDU_BSSAP tr_BSSMAP_ResetAck modifies tr_BSSAP_BSSMAP := {
214 pdu := {
215 bssmap := {
216 resetAck := {
217 messageType := '31'O,
218 a_InterfaceSelectorForReset := *
219 }
220 }
221 }
222}
223
224template BSSMAP_IE_CellIdentifier ts_BSSMAP_IE_CellID := {
225 elementIdentifier := '05'O,
226 lengthIndicator := 0,
227 cellIdentifierDiscriminator := '0000'B,
228 spare1_4 := '0000'B,
229 cellIdentification := ?
230}
231
232type uint16_t BssmapLAC;
233type uint16_t BssmapCI;
234
235/*
236template BSSMAP_IE_CellIdentifier ts_CellId_CGI(mcc, mnc, lac, ci)
237modifies ts_BSSMAP_IE_CellID := {
238 cellIdentification := {
239 cI_LAC_CGI := {
240 mnc_mcc := FIXME,
241 lac := int2oct(lac, 2),
242 ci := int2oct(ci, 2)
243 }
244 }
245}
246*/
247
248template BSSMAP_IE_CellIdentifier ts_CellID_LAC_CI(BssmapLAC lac, BssmapCI ci)
249modifies ts_BSSMAP_IE_CellID := {
250 cellIdentification := {
251 cI_LAC_CI := {
252 lac := int2oct(lac, 2),
253 ci := int2oct(ci, 2)
254 }
255 }
256}
257
258template BSSMAP_IE_CellIdentifier ts_CellId_CI(BssmapCI ci)
259modifies ts_BSSMAP_IE_CellID := {
260 cellIdentification := {
261 cI_CI := int2oct(ci, 2)
262 }
263}
264
265template BSSMAP_IE_CellIdentifier ts_CellId_none
266modifies ts_BSSMAP_IE_CellID := {
267 cellIdentification := {
268 cI_noCell := ''O
269 }
270}
271
272
273template BSSMAP_IE_Layer3Information ts_BSSMAP_IE_L3Info(octetstring l3info) := {
274 elementIdentifier := '17'O,
275 lengthIndicator := 0,
276 layer3info := l3info
277}
278
279template PDU_BSSAP ts_BSSMAP_ComplL3(BSSMAP_IE_CellIdentifier cell_id, octetstring l3_info)
280modifies ts_BSSAP_BSSMAP := {
281 pdu := {
282 bssmap := {
283 completeLayer3Information := {
284 messageType := '57'O,
285 cellIdentifier := cell_id,
286 layer3Information := ts_BSSMAP_IE_L3Info(l3_info),
287 chosenChannel := omit,
288 lSAIdentifier := omit,
289 aPDU := omit,
290 codecList := omit,
291 redirectAttemptFlag := omit,
292 sendSequenceNumber := omit,
293 iMSI := omit
294 }
295 }
296 }
297}
298
299template PDU_BSSAP ts_BSSMAP_HandoReq(BssmapCause cause, BSSMAP_IE_CellIdentifierList cid_list)
300modifies ts_BSSAP_BSSMAP := {
301 pdu := {
302 bssmap := {
303 handoverRequired := {
304 messageType := '11'O,
305 cause := ts_BSSMAP_IE_Cause(cause),
306 responseRequest := omit,
307 cellIdentifierList := cid_list,
308 circuitPoolList := omit,
309 currentChannelType1 := omit,
310 speechVersion := omit,
311 queueingIndicator := omit,
312 oldToNewBSSInfo := omit,
313 sourceToTargetRNCTransparentInfo := omit,
314 sourceToTargetRNCTransparentInfoCDMA := omit,
315 gERANClassmark := omit,
316 talkerPriority := omit,
317 speechCodec := omit,
318 cSG_Identifier := omit
319 }
320 }
321 }
322}
323
324// enc_PDU_BSSAP
325
326function f_send_BSSAP_UNITDATA(template PDU_BSSAP bssap) runs on MTC_CT {
Harald Weltea49e36e2018-01-21 19:29:33 +0100327 BSSAP.send(ts_BSSAP_UNITDATA_req(g_sccp_addr_peer, g_sccp_addr_own, bssap))
Harald Weltef6dd64d2017-11-19 12:09:51 +0100328}
329
Harald Weltea49e36e2018-01-21 19:29:33 +0100330type function void_fn(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100331
Harald Welte81b7f9d2018-01-24 19:06:24 +0100332private function f_concat_pad(integer tot_len, hexstring prefix, integer suffix) return hexstring {
333 var integer suffix_len := tot_len - lengthof(prefix);
334 var charstring suffix_ch := int2str(suffix);
335 var integer pad_len := suffix_len - lengthof(suffix_ch);
336
337 return prefix & int2hex(0, pad_len) & str2hex(suffix_ch);
Harald Welte256571e2018-01-24 18:47:19 +0100338}
339
Harald Welte81b7f9d2018-01-24 19:06:24 +0100340function f_gen_imei(integer suffix) return hexstring {
341 return f_concat_pad(15, '49999'H, suffix);
Harald Weltea49e36e2018-01-21 19:29:33 +0100342}
343
Harald Welte81b7f9d2018-01-24 19:06:24 +0100344function f_gen_imsi(integer suffix) return hexstring {
345 return f_concat_pad(15, '26242'H, suffix);
346}
347
348function f_gen_msisdn(integer suffix) return hexstring {
349 return f_concat_pad(12, '49123'H, suffix);
Harald Weltea49e36e2018-01-21 19:29:33 +0100350}
351
352/* FIXME: move into BSC_ConnectionHandler? */
353function f_start_handler(void_fn fn, charstring id, integer imsi_suffix) runs on MTC_CT return BSC_ConnHdlr {
354 var BSC_ConnHdlr vc_conn;
355 var BSC_ConnHdlrPars pars := {
356 sccp_addr_own := g_sccp_addr_own,
357 sccp_addr_peer := g_sccp_addr_peer,
358 cell_id := valueof(ts_CellId_CGI('262'H, '042'H, 23, 42)),
Harald Welte81b7f9d2018-01-24 19:06:24 +0100359 imei := f_gen_imei(imsi_suffix),
360 imsi := f_gen_imsi(imsi_suffix),
361 msisdn := f_gen_msisdn(imsi_suffix),
Harald Welte256571e2018-01-24 18:47:19 +0100362 tmsi := omit,
Harald Welte82600572018-01-21 20:54:08 +0100363 cm2 := valueof(ts_CM2_default),
Harald Welte16114282018-01-24 22:41:21 +0100364 cm3 := omit,
Harald Welte148a7082018-01-26 18:56:43 +0100365 vec := omit
Harald Weltea49e36e2018-01-21 19:29:33 +0100366 };
367
368 vc_conn := BSC_ConnHdlr.create(id);
369 /* BSSMAP part / A interface */
370 connect(vc_conn:BSSAP, vc_BSSMAP:CLIENT);
371 connect(vc_conn:BSSAP_PROC, vc_BSSMAP:PROC);
372 /* MNCC part */
373 connect(vc_conn:MNCC, vc_MNCC:MNCC_CLIENT);
374 connect(vc_conn:MNCC_PROC, vc_MNCC:MNCC_PROC);
Harald Welte4aa970c2018-01-26 10:38:09 +0100375 /* MGCP part */
376 connect(vc_conn:MGCP, vc_MGCP:MGCP_CLIENT);
377 connect(vc_conn:MGCP_PROC, vc_MGCP:MGCP_PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100378 /* GSUP part */
379 connect(vc_conn:GSUP, vc_GSUP:GSUP_CLIENT);
380 connect(vc_conn:GSUP_PROC, vc_GSUP:GSUP_PROC);
381
382 vc_conn.start(derefers(fn)(id, pars));
383 return vc_conn;
384}
385
Harald Welte3ca1c902018-01-24 18:51:27 +0100386function f_vty_config(TELNETasp_PT pt, charstring config_node, charstring cmd)
387{
388 /* enter config mode; enter node */
389 f_vty_enter_config(pt);
390 f_vty_transceive(pt, config_node);
391 /* execute command */
392 f_vty_transceive(pt, cmd);
393 /* leave config mode */
394 f_vty_transceive(pt, "end");
395}
396
Harald Weltea49e36e2018-01-21 19:29:33 +0100397private function f_tc_lu_imsi_noauth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
398 g_pars := pars;
Harald Welte8a121b32018-01-22 03:00:41 +0100399 f_perform_lu(false, true, true);
Harald Weltea49e36e2018-01-21 19:29:33 +0100400}
Harald Weltea49e36e2018-01-21 19:29:33 +0100401testcase TC_lu_imsi_noauth_tmsi() runs on MTC_CT {
402 var BSC_ConnHdlr vc_conn;
403 f_init();
404
405 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi), testcasename(), 1);
406 vc_conn.done;
407}
408
409private function f_tc_lu_imsi_noauth_notmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
410 g_pars := pars;
Harald Welte8a121b32018-01-22 03:00:41 +0100411 f_perform_lu(false, false, true);
Harald Weltea49e36e2018-01-21 19:29:33 +0100412}
Harald Weltea49e36e2018-01-21 19:29:33 +0100413testcase TC_lu_imsi_noauth_notmsi() runs on MTC_CT {
414 var BSC_ConnHdlr vc_conn;
415 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100416 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
Harald Weltea49e36e2018-01-21 19:29:33 +0100417
418 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi), testcasename(), 2);
419 vc_conn.done;
420}
421
422/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
423private function f_tc_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
424 g_pars := pars;
425 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
426
427 f_create_gsup_expect(hex2str(g_pars.imsi));
428 f_bssap_compl_l3(l3_lu);
429 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
430 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
431 alt {
432 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej(int2oct(23,1)))) { }
433 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
434 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
435 self.stop;
436 }
437 }
438 BSSAP.receive(tr_BSSMAP_ClearCommand);
439 BSSAP.send(ts_BSSMAP_ClearComplete);
440 BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_DISC_IND);
441 setverdict(pass);
442}
443testcase TC_lu_imsi_reject() runs on MTC_CT {
444 var BSC_ConnHdlr vc_conn;
445 f_init();
446
447 vc_conn := f_start_handler(refers(f_tc_lu_imsi_reject), testcasename(), 3);
448 vc_conn.done;
449}
450
451/* Do LU by IMSI, timeout on GSUP */
452private function f_tc_lu_imsi_timeout_gsup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
453 g_pars := pars;
454 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
455
456 f_create_gsup_expect(hex2str(g_pars.imsi));
457 f_bssap_compl_l3(l3_lu);
458 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
459 /* Normally the HLR would need to respond here, but we decide to force a timeout here */
460 alt {
461 /* FIXME: Expect specific reject cause */
462 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { }
463 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
464 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
465 self.stop;
466 }
467 }
468 BSSAP.receive(tr_BSSMAP_ClearCommand);
469 BSSAP.send(ts_BSSMAP_ClearComplete);
470 BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_DISC_IND);
471 setverdict(pass);
472}
473testcase TC_lu_imsi_timeout_gsup() runs on MTC_CT {
474 var BSC_ConnHdlr vc_conn;
475 f_init();
476
477 vc_conn := f_start_handler(refers(f_tc_lu_imsi_timeout_gsup), testcasename(), 4);
478 vc_conn.done;
479}
480
Harald Welte7b1b2812018-01-22 21:23:06 +0100481private function f_tc_lu_imsi_auth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
482 g_pars := pars;
483 f_perform_lu(true, true, true);
484}
485testcase TC_lu_imsi_auth_tmsi() runs on MTC_CT {
486 var BSC_ConnHdlr vc_conn;
487 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100488 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte7b1b2812018-01-22 21:23:06 +0100489
490 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi), testcasename(), 5);
491 vc_conn.done;
492}
493
Harald Weltea49e36e2018-01-21 19:29:33 +0100494
495/* Send CM SERVICE REQ for IMSI that has never performed LU before */
496private function f_tc_cmserv_imsi_unknown(charstring id, BSC_ConnHdlrPars pars)
497runs on BSC_ConnHdlr {
498
499 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
500 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '042'H, 23, 42));
Harald Welte6ed6bf92018-01-24 21:09:15 +0100501 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
Harald Weltea49e36e2018-01-21 19:29:33 +0100502
503 f_create_gsup_expect(hex2str(g_pars.imsi));
504
505 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
506 f_bssap_compl_l3(l3_info);
507
508 timer T := 10.0;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100509 T.start;
510 alt {
Harald Weltea49e36e2018-01-21 19:29:33 +0100511 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
512 //[] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_ACC)) { }
513 [] BSSAP.receive { setverdict(fail, "Received unexpected BSSAP"); }
514 [] GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi)) {
515 setverdict(fail, "Unexpected GSUP UL REQ");
516 }
517 [] T.timeout { setverdict(inconc, "Timeout waiting for CM SERV REQ"); }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100518 }
519
Harald Weltea49e36e2018-01-21 19:29:33 +0100520 alt {
521 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {
522 setverdict(pass);
523 }
524 [] BSSAP.receive { setverdict(fail, "Received unexpected BSSAP"); }
525 [] T.timeout { setverdict(inconc, "Timeout waiting for CM SERV REQ"); }
526 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100527}
Harald Weltea49e36e2018-01-21 19:29:33 +0100528testcase TC_cmserv_imsi_unknown() runs on MTC_CT {
529 var BSC_ConnHdlr vc_conn;
530 f_init();
Harald Welte81b7f9d2018-01-24 19:06:24 +0100531 vc_conn := f_start_handler(refers(f_tc_cmserv_imsi_unknown), testcasename(), 6);
Harald Weltea49e36e2018-01-21 19:29:33 +0100532 vc_conn.done;
533}
534
Harald Welte2bb825f2018-01-22 11:31:18 +0100535private function f_tc_lu_and_mo_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
536 g_pars := pars;
Harald Welteb71901a2018-01-26 19:16:05 +0100537 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
538 cpars.bss_rtp_port := 1110;
539 cpars.mgcp_connection_id_bss := '22222'H;
540 cpars.mgcp_connection_id_mss := '33333'H;
Harald Welte2bb825f2018-01-22 11:31:18 +0100541
Harald Welteb71901a2018-01-26 19:16:05 +0100542 f_perform_lu(cpars.expect_auth, true, true);
543 f_mo_call(cpars);
Harald Welte2bb825f2018-01-22 11:31:18 +0100544}
545testcase TC_lu_and_mo_call() runs on MTC_CT {
546 var BSC_ConnHdlr vc_conn;
547 f_init();
548
Harald Welte81b7f9d2018-01-24 19:06:24 +0100549 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_call), testcasename(), 7);
Harald Welte071ed732018-01-23 19:53:52 +0100550 vc_conn.done;
551}
552
553/* Test LU (with authentication enabled), where HLR times out sending SAI response */
554private function f_tc_lu_auth_sai_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
555 g_pars := pars;
556
557 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
558 var PDU_DTAP_MT dtap_mt;
559
560 /* tell GSUP dispatcher to send this IMSI to us */
561 f_create_gsup_expect(hex2str(g_pars.imsi));
562
563 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
564 f_bssap_compl_l3(l3_lu);
565
566 /* Send Early Classmark, just for the fun of it */
567 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
568
569 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
570 /* The HLR would normally return an auth vector here, but we fail to do so. */
571
572 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
573 BSSAP.receive(tr_BSSMAP_ClearCommand);
574 BSSAP.send(ts_BSSMAP_ClearComplete);
575 BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_DISC_IND);
576 setverdict(pass);
577}
578testcase TC_lu_auth_sai_timeout() runs on MTC_CT {
579 var BSC_ConnHdlr vc_conn;
580 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100581 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100582
Harald Welte81b7f9d2018-01-24 19:06:24 +0100583 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_timeout), testcasename(), 8);
Harald Welte071ed732018-01-23 19:53:52 +0100584 vc_conn.done;
585}
586
587/* Test LU (with authentication enabled), where HLR rejects sending SAI error */
588private function f_tc_lu_auth_sai_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
589 g_pars := pars;
590
591 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
592 var PDU_DTAP_MT dtap_mt;
593
594 /* tell GSUP dispatcher to send this IMSI to us */
595 f_create_gsup_expect(hex2str(g_pars.imsi));
596
597 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
598 f_bssap_compl_l3(l3_lu);
599
600 /* Send Early Classmark, just for the fun of it */
601 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
602
603 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
604 GSUP.send(ts_GSUP_SAI_ERR(g_pars.imsi, 13));
605
606 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
607 BSSAP.receive(tr_BSSMAP_ClearCommand);
608 BSSAP.send(ts_BSSMAP_ClearComplete);
609 BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_DISC_IND);
610 setverdict(pass);
611}
612testcase TC_lu_auth_sai_err() runs on MTC_CT {
613 var BSC_ConnHdlr vc_conn;
614 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100615 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100616
Harald Welte81b7f9d2018-01-24 19:06:24 +0100617 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_err), testcasename(), 9);
Harald Welte2bb825f2018-01-22 11:31:18 +0100618 vc_conn.done;
619}
Harald Weltea49e36e2018-01-21 19:29:33 +0100620
Harald Weltebc881782018-01-23 20:09:15 +0100621/* Test LU but BSC will send a clear request in the middle */
622private function f_tc_lu_clear_request(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
623 g_pars := pars;
624
625 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
626 var PDU_DTAP_MT dtap_mt;
627
628 /* tell GSUP dispatcher to send this IMSI to us */
629 f_create_gsup_expect(hex2str(g_pars.imsi));
630
631 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
632 f_bssap_compl_l3(l3_lu);
633
634 /* Send Early Classmark, just for the fun of it */
635 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
636
637 f_sleep(1.0);
638 /* send clear request in the middle of the LU */
639 BSSAP.send(ts_BSSMAP_ClearRequest(0));
640 BSSAP.receive(tr_BSSMAP_ClearCommand);
641 BSSAP.send(ts_BSSMAP_ClearComplete);
642 BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_DISC_IND);
643 setverdict(pass);
644}
645testcase TC_lu_clear_request() runs on MTC_CT {
646 var BSC_ConnHdlr vc_conn;
647 f_init();
648
Harald Welte81b7f9d2018-01-24 19:06:24 +0100649 vc_conn := f_start_handler(refers(f_tc_lu_clear_request), testcasename(), 10);
Harald Weltebc881782018-01-23 20:09:15 +0100650 vc_conn.done;
651}
652
Harald Welte66af9e62018-01-24 17:28:21 +0100653/* Test LU but BSC will send a clear request in the middle */
654private function f_tc_lu_disconnect(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
655 g_pars := pars;
656
657 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
658 var PDU_DTAP_MT dtap_mt;
659
660 /* tell GSUP dispatcher to send this IMSI to us */
661 f_create_gsup_expect(hex2str(g_pars.imsi));
662
663 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
664 f_bssap_compl_l3(l3_lu);
665
666 /* Send Early Classmark, just for the fun of it */
667 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
668
669 f_sleep(1.0);
670 /* send clear request in the middle of the LU */
671 BSSAP.send(BSSAP_Conn_Prim:MSC_CONN_PRIM_DISC_REQ);
672 setverdict(pass);
673}
674testcase TC_lu_disconnect() runs on MTC_CT {
675 var BSC_ConnHdlr vc_conn;
676 f_init();
677
Harald Welte81b7f9d2018-01-24 19:06:24 +0100678 vc_conn := f_start_handler(refers(f_tc_lu_disconnect), testcasename(), 11);
Harald Welte66af9e62018-01-24 17:28:21 +0100679 vc_conn.done;
680}
681
682
Harald Welteba7b6d92018-01-23 21:32:34 +0100683/* Test LU but with illegal mobile identity type = IMEI */
684private function f_tc_lu_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
685 g_pars := pars;
686
Harald Welte256571e2018-01-24 18:47:19 +0100687 var PDU_ML3_MS_NW l3_lu := f_build_lu_imei(g_pars.imei)
Harald Welteba7b6d92018-01-23 21:32:34 +0100688 var PDU_DTAP_MT dtap_mt;
689
690 /* tell GSUP dispatcher to send this IMSI to us */
691 f_create_gsup_expect(hex2str(g_pars.imsi));
692
693 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
694 f_bssap_compl_l3(l3_lu);
695
696 /* Send Early Classmark, just for the fun of it */
697 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
698 /* wait for LU reject, ignore any ID REQ */
699 alt {
700 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { }
701 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req)) { repeat; }
702 }
703 /* wait for normal teardown */
704 BSSAP.receive(tr_BSSMAP_ClearCommand);
705 BSSAP.send(ts_BSSMAP_ClearComplete);
706 BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_DISC_IND);
707 setverdict(pass);
708}
709testcase TC_lu_by_imei() runs on MTC_CT {
710 var BSC_ConnHdlr vc_conn;
711 f_init();
712
Harald Welte81b7f9d2018-01-24 19:06:24 +0100713 vc_conn := f_start_handler(refers(f_tc_lu_by_imei), testcasename(), 12);
Harald Welteba7b6d92018-01-23 21:32:34 +0100714 vc_conn.done;
715}
716
717/* Test LU by TMSI with unknown TMSI, expect (and answer) ID REQ. */
718private function f_tc_lu_tmsi_noauth_unknown(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
719 g_pars := pars;
720
721 var PDU_ML3_MS_NW l3_lu := f_build_lu_tmsi('01020304'O); /* FIXME: Random */
722 var PDU_DTAP_MT dtap_mt;
723
724 /* tell GSUP dispatcher to send this IMSI to us */
725 f_create_gsup_expect(hex2str(g_pars.imsi));
726
727 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
728 f_bssap_compl_l3(l3_lu);
729
730 /* Send Early Classmark, just for the fun of it */
731 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
732
733 /* Wait for + respond to ID REQ (IMSI) */
734 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req('001'B)));
735 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(g_pars.imsi)));
736
737 /* Expect MSC to do UpdateLocation to HLR; respond to it */
738 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
739 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
740 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
741 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
742
743 alt {
744 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) { }
745 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
746 setverdict(fail, "Expected LU ACK, but received REJ");
747 }
748 }
749
750 /* wait for normal teardown */
751 BSSAP.receive(tr_BSSMAP_ClearCommand);
752 BSSAP.send(ts_BSSMAP_ClearComplete);
753 BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_DISC_IND);
754 setverdict(pass);
755}
756testcase TC_lu_by_tmsi_noauth_unknown() runs on MTC_CT {
757 var BSC_ConnHdlr vc_conn;
758 f_init();
759
Harald Welte81b7f9d2018-01-24 19:06:24 +0100760 vc_conn := f_start_handler(refers(f_tc_lu_tmsi_noauth_unknown), testcasename(), 13);
Harald Welteba7b6d92018-01-23 21:32:34 +0100761 vc_conn.done;
762}
763
764
Harald Welte45164da2018-01-24 12:51:27 +0100765/* Test IMSI DETACH (MI=IMSI) */
766private function f_tc_imsi_detach_by_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
767 g_pars := pars;
768
769 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
770
771 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
772 f_bssap_compl_l3(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
773
774 /* Send Early Classmark, just for the fun of it? */
775 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
776
777 /* wait for normal teardown */
778 BSSAP.receive(tr_BSSMAP_ClearCommand);
779 BSSAP.send(ts_BSSMAP_ClearComplete);
780 BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_DISC_IND);
781 setverdict(pass);
782}
783testcase TC_imsi_detach_by_imsi() runs on MTC_CT {
784 var BSC_ConnHdlr vc_conn;
785 f_init();
786
Harald Welte81b7f9d2018-01-24 19:06:24 +0100787 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imsi), testcasename(), 14);
Harald Welte45164da2018-01-24 12:51:27 +0100788 vc_conn.done;
789}
790
791/* Test IMSI DETACH (MI=TMSI) */
792private function f_tc_imsi_detach_by_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
793 g_pars := pars;
794
795 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV('01020304'O));
796
797 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
798 f_bssap_compl_l3(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
799
800 /* Send Early Classmark, just for the fun of it? */
801 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
802
803 /* wait for normal teardown */
804 BSSAP.receive(tr_BSSMAP_ClearCommand);
805 BSSAP.send(ts_BSSMAP_ClearComplete);
806 BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_DISC_IND);
807 setverdict(pass);
808}
809testcase TC_imsi_detach_by_tmsi() runs on MTC_CT {
810 var BSC_ConnHdlr vc_conn;
811 f_init();
812
Harald Welte81b7f9d2018-01-24 19:06:24 +0100813 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_tmsi), testcasename(), 15);
Harald Welte45164da2018-01-24 12:51:27 +0100814 vc_conn.done;
815}
816
817/* Test IMSI DETACH (MI=IMEI), which is illegal */
818private function f_tc_imsi_detach_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
819 g_pars := pars;
820
Harald Welte256571e2018-01-24 18:47:19 +0100821 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte45164da2018-01-24 12:51:27 +0100822
823 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
824 f_bssap_compl_l3(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
825
826 /* Send Early Classmark, just for the fun of it? */
827 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
828
829 /* wait for normal teardown */
830 BSSAP.receive(tr_BSSMAP_ClearCommand);
831 BSSAP.send(ts_BSSMAP_ClearComplete);
832 BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_DISC_IND);
833 setverdict(pass);
834}
835testcase TC_imsi_detach_by_imei() runs on MTC_CT {
836 var BSC_ConnHdlr vc_conn;
837 f_init();
838
Harald Welte81b7f9d2018-01-24 19:06:24 +0100839 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imei), testcasename(), 16);
Harald Welte45164da2018-01-24 12:51:27 +0100840 vc_conn.done;
841}
842
843
844/* helper function for an emergency call. caller passes in mobile identity to use */
845private function f_emerg_call(MobileIdentityLV mi) runs on BSC_ConnHdlr {
846
Harald Welte6ed6bf92018-01-24 21:09:15 +0100847 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_EMERG_CALL, mi));
Harald Welte45164da2018-01-24 12:51:27 +0100848 f_bssap_compl_l3(l3_info);
849 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_ACC));
850
851 var hexstring called := '112'H;
852 var integer tid := 0;
853 var MNCC_PDU mncc;
854 f_create_mncc_expect(hex2str(called));
855
856 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_EMERG_SETUP(tid)));
857 MNCC.receive(tr_MNCC_SETUP_ind(?, tr_MNCC_number(hex2str(called)))) -> value mncc;
858 /* FIXME: extract call_id */
859
860 /* Call Proceeding */
861 MNCC.send(ts_MNCC_CALL_PROC_req(mncc.u.signal.callref, ts_MNCC_bcap_voice));
862 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_CALL_PROC(tid)));
863
864 /* Alerting */
865 MNCC.send(ts_MNCC_ALERT_req(mncc.u.signal.callref));
866 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_ALERTING(tid)));
867
868 /* Answer. This causes TCH assignment in case of "late assignment" */
Harald Welte4017d552018-01-26 21:40:05 +0100869 //MNCC.send(ts_MNCC_SETUP_COMPL_req(mncc.u.signal.callref));
870 MNCC.send(ts_MNCC_SETUP_rsp(mncc.u.signal.callref));
Harald Welte45164da2018-01-24 12:51:27 +0100871
872 f_sleep(3.0);
873
874 /* Hangup by "B" side */
875 MNCC.send(ts_MNCC_DISC_req(mncc.u.signal.callref, valueof(ts_MNCC_cause(23))));
876 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_DISC(tid)));
877
878 /* Release of call */
879 MNCC.send(ts_MNCC_REL_req(mncc.u.signal.callref, valueof(ts_MNCC_cause(42))));
880 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(tid)));
881
882 /* clearing of radio channel */
883 BSSAP.receive(tr_BSSMAP_ClearCommand);
884 BSSAP.send(ts_BSSMAP_ClearComplete);
885 BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_DISC_IND);
886
887 f_sleep(5.0);
888}
889
890/* establish an emergency call by IMEI, no SIM inserted (and hence no IMSI) */
891private function f_tc_emerg_call_imei_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
892 g_pars := pars;
893
Harald Welte256571e2018-01-24 18:47:19 +0100894 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte6ed6bf92018-01-24 21:09:15 +0100895 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_EMERG_CALL, mi));
Harald Welte45164da2018-01-24 12:51:27 +0100896 f_bssap_compl_l3(l3_info);
897 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ('05'O)));
Harald Weltef6b62ee2018-01-24 21:49:32 +0100898 BSSAP.receive(tr_BSSMAP_ClearCommand);
899 BSSAP.send(ts_BSSMAP_ClearComplete);
900 BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_DISC_IND);
Harald Welte45164da2018-01-24 12:51:27 +0100901 setverdict(pass);
902}
903testcase TC_emerg_call_imei_reject() runs on MTC_CT {
904 var BSC_ConnHdlr vc_conn;
905 f_init();
906
Harald Welte81b7f9d2018-01-24 19:06:24 +0100907 vc_conn := f_start_handler(refers(f_tc_emerg_call_imei_reject), testcasename(), 17);
Harald Welte45164da2018-01-24 12:51:27 +0100908 vc_conn.done;
909}
910
Harald Welted5b91402018-01-24 18:48:16 +0100911/* establish an emergency call by IMSI, SIM inserted (and hence IMSI) */
Harald Welte45164da2018-01-24 12:51:27 +0100912private function f_tc_emerg_call_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
913 g_pars := pars;
914 /* First perform location update to ensure subscriber is known */
915 f_perform_lu(false, true, true);
916 /* Then issue emergency call identified by IMSI */
917 f_emerg_call(valueof(ts_MI_IMSI_LV(g_pars.imsi)));
918}
919testcase TC_emerg_call_imsi() runs on MTC_CT {
920 var BSC_ConnHdlr vc_conn;
921 f_init();
922
Harald Welte81b7f9d2018-01-24 19:06:24 +0100923 vc_conn := f_start_handler(refers(f_tc_emerg_call_imsi), testcasename(), 18);
Harald Welte45164da2018-01-24 12:51:27 +0100924 vc_conn.done;
925}
926
927/* CM Service Request for VGCS -> reject */
928private function f_tc_cm_serv_req_vgcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
929 g_pars := pars;
930
931 /* First perform location update to ensure subscriber is known */
932 f_perform_lu(false, true, true);
933
934 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +0100935 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VGCS, mi));
Harald Welte45164da2018-01-24 12:51:27 +0100936 f_bssap_compl_l3(l3_info);
937 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Weltef6b62ee2018-01-24 21:49:32 +0100938 BSSAP.receive(tr_BSSMAP_ClearCommand);
939 BSSAP.send(ts_BSSMAP_ClearComplete);
940 BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_DISC_IND);
Harald Welte45164da2018-01-24 12:51:27 +0100941 setverdict(pass);
942}
943testcase TC_cm_serv_req_vgcs_reject() runs on MTC_CT {
944 var BSC_ConnHdlr vc_conn;
945 f_init();
946
Harald Welte81b7f9d2018-01-24 19:06:24 +0100947 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vgcs_reject), testcasename(), 19);
Harald Welte45164da2018-01-24 12:51:27 +0100948 vc_conn.done;
949}
950
951/* CM Service Request for VBS -> reject */
952private function f_tc_cm_serv_req_vbs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
953 g_pars := pars;
954
955 /* First perform location update to ensure subscriber is known */
956 f_perform_lu(false, true, true);
957
958 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +0100959 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VBS, mi));
Harald Welte45164da2018-01-24 12:51:27 +0100960 f_bssap_compl_l3(l3_info);
961 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Weltef6b62ee2018-01-24 21:49:32 +0100962 BSSAP.receive(tr_BSSMAP_ClearCommand);
963 BSSAP.send(ts_BSSMAP_ClearComplete);
964 BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_DISC_IND);
Harald Welte45164da2018-01-24 12:51:27 +0100965 setverdict(pass);
966}
967testcase TC_cm_serv_req_vbs_reject() runs on MTC_CT {
968 var BSC_ConnHdlr vc_conn;
969 f_init();
970
Harald Welte81b7f9d2018-01-24 19:06:24 +0100971 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vbs_reject), testcasename(), 20);
Harald Welte45164da2018-01-24 12:51:27 +0100972 vc_conn.done;
973}
974
975/* CM Service Request for LCS -> reject */
976private function f_tc_cm_serv_req_lcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
977 g_pars := pars;
978
979 /* First perform location update to ensure subscriber is known */
980 f_perform_lu(false, true, true);
981
982 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +0100983 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_LCS, mi));
Harald Welte45164da2018-01-24 12:51:27 +0100984 f_bssap_compl_l3(l3_info);
985 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte0195ab12018-01-24 21:50:20 +0100986 BSSAP.receive(tr_BSSMAP_ClearCommand);
987 BSSAP.send(ts_BSSMAP_ClearComplete);
988 BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_DISC_IND);
Harald Welte45164da2018-01-24 12:51:27 +0100989 setverdict(pass);
990}
991testcase TC_cm_serv_req_lcs_reject() runs on MTC_CT {
992 var BSC_ConnHdlr vc_conn;
993 f_init();
994
Harald Welte81b7f9d2018-01-24 19:06:24 +0100995 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_lcs_reject), testcasename(), 21);
Harald Welte45164da2018-01-24 12:51:27 +0100996 vc_conn.done;
997}
998
Harald Welte0195ab12018-01-24 21:50:20 +0100999/* CM Re-Establishment Request */
1000private function f_tc_cm_reest_req_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1001 g_pars := pars;
1002
1003 /* First perform location update to ensure subscriber is known */
1004 f_perform_lu(false, true, true);
1005
1006 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1007 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_REEST_REQ(0, mi));
1008 f_bssap_compl_l3(l3_info);
1009 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
1010 BSSAP.receive(tr_BSSMAP_ClearCommand);
1011 BSSAP.send(ts_BSSMAP_ClearComplete);
1012 BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_DISC_IND);
1013 setverdict(pass);
1014}
1015testcase TC_cm_reest_req_reject() runs on MTC_CT {
1016 var BSC_ConnHdlr vc_conn;
1017 f_init();
Harald Welte0195ab12018-01-24 21:50:20 +01001018
1019 vc_conn := f_start_handler(refers(f_tc_cm_reest_req_reject), testcasename(), 22);
1020 vc_conn.done;
1021}
1022
Harald Weltec638f4d2018-01-24 22:00:36 +01001023/* Test LU (with authentication enabled), with wrong response from MS */
1024private function f_tc_lu_auth_2G_fail(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1025 g_pars := pars;
1026
1027 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
1028
1029 /* tell GSUP dispatcher to send this IMSI to us */
1030 f_create_gsup_expect(hex2str(g_pars.imsi));
1031
1032 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
1033 f_bssap_compl_l3(l3_lu);
1034
1035 /* Send Early Classmark, just for the fun of it */
1036 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1037
1038 var AuthVector vec := f_gen_auth_vec_2g();
1039 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G(vec.rand, vec.sres, vec.kc));
1040 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
1041 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
1042
1043 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_AUTH_REQ(vec.rand)));
1044 /* Send back wrong auth response */
1045 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MT_MM_AUTH_RESP_2G('00000000'O)));
1046
1047 /* Expect GSUP AUTH FAIL REP to HLR */
1048 GSUP.receive(tr_GSUP_AUTH_FAIL_IND(g_pars.imsi));
1049
1050 /* Expect LU REJECT with Cause == Illegal MS */
1051 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej('03'O)));
1052 BSSAP.receive(tr_BSSMAP_ClearCommand);
1053 BSSAP.send(ts_BSSMAP_ClearComplete);
1054 BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_DISC_IND);
1055 setverdict(pass);
1056}
1057testcase TC_lu_auth_2G_fail() runs on MTC_CT {
1058 var BSC_ConnHdlr vc_conn;
1059 f_init();
1060 f_vty_config(MSCVTY, "network", "authentication required");
1061 f_vty_config(MSCVTY, "msc", "assign-tmsi");
1062
1063 vc_conn := f_start_handler(refers(f_tc_lu_auth_2G_fail), testcasename(), 23);
1064 vc_conn.done;
1065}
1066
Harald Welte16114282018-01-24 22:41:21 +01001067private function f_tc_lu_imsi_auth_tmsi_encr_13_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1068 g_pars := pars;
1069 f_perform_lu(true, true, true, true);
1070}
1071testcase TC_lu_imsi_auth_tmsi_encr_13_13() runs on MTC_CT {
1072 var BSC_ConnHdlr vc_conn;
1073 f_init();
1074 f_vty_config(MSCVTY, "network", "authentication required");
1075 f_vty_config(MSCVTY, "msc", "assign-tmsi");
1076 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
1077
1078 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_13), testcasename(), 24);
1079 vc_conn.done;
1080}
1081
Harald Welte1af6ea82018-01-25 18:33:15 +01001082/* Test Complete L3 without payload */
1083private function f_tc_cl3_no_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1084 g_pars := pars;
1085
1086 /* Send Complete L3 Info with empty L3 frame */
1087 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1088 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, ''O))));
1089
1090 alt {
1091 [] BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
1092 /* Expect LU REJECT with Cause == Illegal MS */
1093 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {
1094 BSSAP.send(ts_BSSMAP_ClearComplete);
1095 BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_DISC_IND);
1096 }
1097 }
1098 setverdict(pass);
1099}
1100testcase TC_cl3_no_payload() runs on MTC_CT {
1101 var BSC_ConnHdlr vc_conn;
1102 f_init();
1103
1104 vc_conn := f_start_handler(refers(f_tc_cl3_no_payload), testcasename(), 24);
1105 vc_conn.done;
1106}
1107
1108/* Test Complete L3 with random payload */
1109private function f_tc_cl3_rnd_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1110 g_pars := pars;
1111
1112 var integer len := float2int(rnd() * 256.0);
1113 var octetstring payl := f_rnd_octstring(len);
1114
1115 /* Send Complete L3 Info with empty L3 frame */
1116 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1117 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, payl))));
1118
1119 alt {
1120 /* Immediate disconnect */
1121 [] BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
1122 /* Expect LU REJECT with Cause == Illegal MS */
1123 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {
1124 BSSAP.send(ts_BSSMAP_ClearComplete);
1125 BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_DISC_IND);
1126 }
1127 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
1128 }
1129 setverdict(pass);
1130}
1131testcase TC_cl3_rnd_payload() runs on MTC_CT {
1132 var BSC_ConnHdlr vc_conn;
1133 f_init();
1134
1135 vc_conn := f_start_handler(refers(f_tc_cl3_rnd_payload), testcasename(), 24);
1136 vc_conn.done;
1137}
1138
Harald Welte116e4332018-01-26 22:17:48 +01001139/* Test Complete L3 with random payload */
1140private function f_tc_establish_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1141 g_pars := pars;
1142
1143 f_perform_lu(false, true, true, false);
1144
1145 f_establish_fully(valueof(ts_MI_IMSI_LV(g_pars.imsi)), false, false);
1146 timer T := 30.0;
1147 alt {
Harald Welte12510c52018-01-26 22:26:24 +01001148 [] T.timeout { setverdict(fail, "Timeout waiting for channel release"); self.stop; }
Harald Welte116e4332018-01-26 22:17:48 +01001149 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {
1150 BSSAP.send(ts_BSSMAP_ClearComplete);
1151 BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_DISC_IND);
1152 setverdict(pass);
1153 }
1154 [] BSSAP.receive { repeat; }
1155 [] MNCC.receive { repeat; }
1156 [] GSUP.receive { repeat; }
1157 [] MGCP.receive { repeat; }
1158 }
1159}
1160testcase TC_establish_and_nothing() runs on MTC_CT {
1161 var BSC_ConnHdlr vc_conn;
1162 f_init();
1163
1164 vc_conn := f_start_handler(refers(f_tc_establish_and_nothing), testcasename(), 25);
1165 vc_conn.done;
1166}
1167
Harald Welte12510c52018-01-26 22:26:24 +01001168/* Test MO Call SETUP with no response from MNCC */
1169private function f_tc_mo_setup_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1170 g_pars := pars;
1171 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1172
1173 f_perform_lu(false, true, true, false);
1174
1175 f_establish_fully(valueof(ts_MI_IMSI_LV(g_pars.imsi)), false, false);
1176 f_create_mncc_expect(hex2str(cpars.called_party));
1177 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1178
1179 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
1180
1181 timer T := 30.0;
1182 alt {
1183 [] T.timeout { setverdict(fail, "Timeout waiting for channel release"); self.stop; }
1184 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {
1185 BSSAP.send(ts_BSSMAP_ClearComplete);
1186 BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_DISC_IND);
1187 setverdict(pass);
1188 }
1189 [] BSSAP.receive { repeat; }
1190 [] MNCC.receive { repeat; }
1191 [] GSUP.receive { repeat; }
1192 [] MGCP.receive { repeat; }
1193 }
1194}
1195testcase TC_mo_setup_and_nothing() runs on MTC_CT {
1196 var BSC_ConnHdlr vc_conn;
1197 f_init();
1198
1199 vc_conn := f_start_handler(refers(f_tc_mo_setup_and_nothing), testcasename(), 26);
1200 vc_conn.done;
1201}
1202
Harald Welte3ab88002018-01-26 22:37:25 +01001203/* Test MO Call with no response to RAN-side CRCX */
1204private function f_tc_mo_crcx_ran_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1205 g_pars := pars;
1206 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1207 var MNCC_PDU mncc;
1208 var MgcpCommand mgcp_cmd;
1209
1210 f_perform_lu(false, true, true, false);
1211
1212 f_establish_fully(valueof(ts_MI_IMSI_LV(g_pars.imsi)), false, false);
1213 f_create_mncc_expect(hex2str(cpars.called_party));
1214 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1215
1216 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
1217 MNCC.receive(tr_MNCC_SETUP_ind(?, tr_MNCC_number(hex2str(cpars.called_party)))) -> value mncc;
1218 cpars.mncc_callref := mncc.u.signal.callref;
1219 MNCC.send(ts_MNCC_CALL_PROC_req(cpars.mncc_callref, cpars.mncc_bearer_cap));
1220 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_CALL_PROC(cpars.transaction_id)));
1221
1222 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1223 /* never respond to this */
1224
1225 timer T := 30.0;
1226 alt {
1227 [] T.timeout { setverdict(fail, "Timeout waiting for channel release"); self.stop; }
1228 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {
1229 BSSAP.send(ts_BSSMAP_ClearComplete);
1230 BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_DISC_IND);
1231 setverdict(pass);
1232 }
1233 [] BSSAP.receive { repeat; }
1234 [] MNCC.receive { repeat; }
1235 [] GSUP.receive { repeat; }
1236 [] MGCP.receive { repeat; }
1237 }
1238}
1239testcase TC_mo_crcx_ran_timeout() runs on MTC_CT {
1240 var BSC_ConnHdlr vc_conn;
1241 f_init();
1242
1243 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_timeout), testcasename(), 27);
1244 vc_conn.done;
1245}
1246
1247
Harald Welte12510c52018-01-26 22:26:24 +01001248
Harald Welte45164da2018-01-24 12:51:27 +01001249
Harald Welteba7b6d92018-01-23 21:32:34 +01001250/* TODO:
1251 * continue to send repeated MO signalling messages to keep channel open: does MSC tmeout?
1252 * malformed messages (missing IE, invalid message type): properly rejected?
1253 * MT call while LU or is ongoing: Do we use existing lchan or page while lchan active?
1254 * 3G/2G auth permutations
1255 * encryption algorithms vs. classmark vs. vty config
Harald Welteba7b6d92018-01-23 21:32:34 +01001256 * send new transaction after/during clear (like SMS, ...)
Harald Welte45164da2018-01-24 12:51:27 +01001257 * too long L3 INFO in DTAP
1258 * too long / padded BSSAP
1259 * too long / short TLV values
Harald Welteba7b6d92018-01-23 21:32:34 +01001260 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01001261
1262
1263control {
Harald Weltea49e36e2018-01-21 19:29:33 +01001264 execute( TC_cmserv_imsi_unknown() );
1265 execute( TC_lu_imsi_noauth_tmsi() );
1266 //execute( TC_lu_imsi_noauth_notmsi() );
1267 execute( TC_lu_imsi_reject() );
1268 execute( TC_lu_imsi_timeout_gsup() );
Harald Welte2bb825f2018-01-22 11:31:18 +01001269 execute( TC_lu_and_mo_call() );
Harald Welte071ed732018-01-23 19:53:52 +01001270 execute( TC_lu_auth_sai_timeout() );
1271 execute( TC_lu_auth_sai_err() );
Harald Weltee1a2f3c2018-01-24 17:28:48 +01001272 execute( TC_lu_clear_request() );
1273 execute( TC_lu_disconnect() );
1274 execute( TC_lu_by_imei() );
1275 execute( TC_lu_by_tmsi_noauth_unknown() );
1276 execute( TC_imsi_detach_by_imsi() );
1277 execute( TC_imsi_detach_by_tmsi() );
1278 execute( TC_imsi_detach_by_imei() );
1279 execute( TC_emerg_call_imei_reject() );
1280 execute( TC_emerg_call_imsi() );
1281 execute( TC_cm_serv_req_vgcs_reject() );
1282 execute( TC_cm_serv_req_vbs_reject() );
1283 execute( TC_cm_serv_req_lcs_reject() );
Harald Welte0195ab12018-01-24 21:50:20 +01001284 execute( TC_cm_reest_req_reject() );
Harald Welte1af6ea82018-01-25 18:33:15 +01001285 execute( TC_lu_auth_2G_fail() );
1286 execute( TC_lu_imsi_auth_tmsi_encr_13_13() );
1287 execute( TC_cl3_no_payload() );
1288 execute( TC_cl3_rnd_payload() );
Harald Weltef6dd64d2017-11-19 12:09:51 +01001289}
1290
1291
1292}