blob: a801db92f4b98b713739db5652b2c7700763046a [file] [log] [blame]
Harald Weltef6dd64d2017-11-19 12:09:51 +01001module MSC_Tests {
2
Harald Welte34b5a952019-05-27 11:54:11 +02003/* Osmocom MSC test suite in in TTCN-3
4 * (C) 2017-2019 Harald Welte <laforge@gnumonks.org>
5 * (C) 2018-2019 sysmocom - s.f.m.c. GmbH
6 * (C) 2018-2019 Vadim Yanitskiy <axilirator@gmail.com>
7 * All rights reserved.
8 *
9 * Released under the terms of GNU General Public License, Version 2 or
10 * (at your option) any later version.
11 *
12 * SPDX-License-Identifier: GPL-2.0-or-later
13 */
14
Harald Weltee13cfb22019-04-23 16:52:02 +020015friend module MSC_Tests_Iu;
16
Harald Weltef6dd64d2017-11-19 12:09:51 +010017import from General_Types all;
18import from Osmocom_Types all;
19
20import from M3UA_Types all;
21import from M3UA_Emulation all;
22
23import from MTP3asp_Types all;
24import from MTP3asp_PortType all;
25
26import from SCCPasp_Types all;
27import from SCCP_Types all;
28import from SCCP_Emulation all;
29
30import from SCTPasp_Types all;
31import from SCTPasp_PortType all;
32
Harald Weltea49e36e2018-01-21 19:29:33 +010033import from Osmocom_CTRL_Functions all;
34import from Osmocom_CTRL_Types all;
35import from Osmocom_CTRL_Adapter all;
36
Harald Welte3ca1c902018-01-24 18:51:27 +010037import from TELNETasp_PortType all;
38import from Osmocom_VTY_Functions all;
39
Harald Weltea49e36e2018-01-21 19:29:33 +010040import from MNCC_Emulation all;
Harald Welte2bb825f2018-01-22 11:31:18 +010041import from MNCC_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010042
Harald Welte4aa970c2018-01-26 10:38:09 +010043import from MGCP_Emulation all;
44import from MGCP_Types all;
45import from MGCP_Templates all;
46import from SDP_Types all;
47
Harald Weltea49e36e2018-01-21 19:29:33 +010048import from GSUP_Emulation all;
49import from GSUP_Types all;
50import from IPA_Emulation all;
51
Harald Weltef6dd64d2017-11-19 12:09:51 +010052import from BSSAP_Types all;
Harald Welte6811d102019-04-14 22:23:14 +020053import from RAN_Adapter all;
Harald Weltea49e36e2018-01-21 19:29:33 +010054import from BSSAP_CodecPort all;
55import from BSSMAP_Templates all;
Harald Welte6811d102019-04-14 22:23:14 +020056import from RAN_Emulation all;
Harald Weltea49e36e2018-01-21 19:29:33 +010057import from BSC_ConnectionHandler all;
Harald Weltee13cfb22019-04-23 16:52:02 +020058import from RANAP_Templates all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010059
Harald Welte4263c522018-12-06 11:56:27 +010060import from SGsAP_Templates all;
61import from SGsAP_Types all;
62import from SGsAP_Emulation all;
63
Harald Weltea49e36e2018-01-21 19:29:33 +010064import from MobileL3_Types all;
65import from MobileL3_CommonIE_Types all;
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +070066import from MobileL3_SMS_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010067import from L3_Templates all;
Harald Welte158a7ca2018-02-16 18:11:31 +010068import from L3_Common all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010069
Harald Weltef640a012018-04-14 17:49:21 +020070import from SMPP_Types all;
71import from SMPP_Templates all;
72import from SMPP_Emulation all;
73
Stefan Sperlingc307e682018-06-14 15:15:46 +020074import from SCCP_Templates all;
75
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070076import from SS_Types all;
77import from SS_Templates all;
78import from USSD_Helpers all;
Harald Welte4263c522018-12-06 11:56:27 +010079import from DNS_Helpers all;
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070080
Philipp Maier948747b2019-04-02 15:22:33 +020081import from TCCConversion_Functions all;
82
Harald Welte9b751a62019-04-14 17:39:29 +020083const integer NUM_BSC := 3;
Harald Weltef6dd64d2017-11-19 12:09:51 +010084
Harald Welte4263c522018-12-06 11:56:27 +010085/* Needed for SGsAP SMS */
86import from MobileL3_SMS_Types all;
87
Harald Weltea4ca4462018-02-09 00:17:14 +010088type component MTC_CT extends CTRL_Adapter_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +010089 var boolean g_initialized := false;
Harald Weltea49e36e2018-01-21 19:29:33 +010090
Harald Welte6811d102019-04-14 22:23:14 +020091 var RAN_Adapter g_bssap[NUM_BSC];
Harald Weltea4ca4462018-02-09 00:17:14 +010092
Harald Weltea49e36e2018-01-21 19:29:33 +010093 /* no 'adapter_CT' for MNCC or GSUP */
94 var MNCC_Emulation_CT vc_MNCC;
Harald Welte4aa970c2018-01-26 10:38:09 +010095 var MGCP_Emulation_CT vc_MGCP;
Harald Weltea49e36e2018-01-21 19:29:33 +010096 var GSUP_Emulation_CT vc_GSUP;
97 var IPA_Emulation_CT vc_GSUP_IPA;
Harald Weltef640a012018-04-14 17:49:21 +020098 var SMPP_Emulation_CT vc_SMPP;
Harald Welte4263c522018-12-06 11:56:27 +010099 var SGsAP_Emulation_CT vc_SGsAP;
Harald Weltea49e36e2018-01-21 19:29:33 +0100100
101 /* only to get events from IPA underneath GSUP */
102 port IPA_CTRL_PT GSUP_IPA_EVENT;
Harald Welte3ca1c902018-01-24 18:51:27 +0100103 /* VTY to MSC */
104 port TELNETasp_PT MSCVTY;
Philipp Maier328d1662018-03-07 10:40:27 +0100105
106 /* A port to directly send BSSAP messages. This port is used for
107 * tests that require low level access to sen arbitrary BSSAP
108 * messages. Run f_init_bssap_direct() to connect and initialize */
109 port BSSAP_CODEC_PT BSSAP_DIRECT;
110
111 /* When BSSAP messages are directly sent, then the connection
112 * handler is not active, which means that also no guard timer is
113 * set up. The following timer will serve as a replacement */
114 timer Tguard_direct := 60.0;
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100115
116 /* Configure T(tias) over VTY, seconds */
117 var integer g_msc_sccp_timer_ias := 7 * 60;
118 /* Configure T(tiar) over VTY, seconds */
119 var integer g_msc_sccp_timer_iar := 15 * 60;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100120}
121
122modulepar {
Harald Weltea49e36e2018-01-21 19:29:33 +0100123 /* remote parameters of IUT */
124 charstring mp_msc_ip := "127.0.0.1";
125 integer mp_msc_ctrl_port := 4255;
126 integer mp_msc_vty_port := 4254;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100127
Harald Weltea49e36e2018-01-21 19:29:33 +0100128 /* local parameters of emulated HLR */
Philipp Maier9b690e42018-12-21 11:50:03 +0100129 boolean mp_mm_info := false;
Harald Weltea49e36e2018-01-21 19:29:33 +0100130 charstring mp_hlr_ip := "127.0.0.1";
131 integer mp_hlr_port := 4222;
Harald Welte6126fb02018-01-27 20:08:24 +0100132 charstring mp_mgw_ip := "127.0.0.1";
133 integer mp_mgw_port := 2427;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100134
Harald Weltea49e36e2018-01-21 19:29:33 +0100135 charstring mp_msc_mncc := "/tmp/mncc";
Harald Weltea4ca4462018-02-09 00:17:14 +0100136
Harald Weltef640a012018-04-14 17:49:21 +0200137 integer mp_msc_smpp_port := 2775;
138 charstring mp_smpp_system_id := "msc_tester";
139 charstring mp_smpp_password := "osmocom1";
Harald Welte4263c522018-12-06 11:56:27 +0100140 charstring mp_mme_name := "mmec01.mmegi0001.mme.epc.mnc070.mcc901.3gppnetwork.org";
141 charstring mp_vlr_name := "vlr.example.net";
Harald Weltef640a012018-04-14 17:49:21 +0200142
Pau Espin Pedrol690d6592019-05-31 17:56:32 +0200143 /* Whether to enable osmux tests. Can be dropped completely and enable
144 unconditionally once new version of osmo-msc is released (current
145 version: 1.3.1) */
146 boolean mp_enable_osmux_test := true;
147
Harald Welte6811d102019-04-14 22:23:14 +0200148 RAN_Configurations mp_bssap_cfg := {
Philipp Maier75932982018-03-27 14:52:35 +0200149 {
150 sccp_service_type := "mtp3_itu",
151 sctp_addr := { 23905, "127.0.0.1", 2905, "127.0.0.1" },
152 own_pc := 185,
153 own_ssn := 254,
154 peer_pc := 187,
155 peer_ssn := 254,
156 sio := '83'O,
157 rctx := 0
158 },
159 {
160 sccp_service_type := "mtp3_itu",
161 sctp_addr := { 23906, "127.0.0.1", 2905, "127.0.0.1" },
162 own_pc := 186,
163 own_ssn := 254,
164 peer_pc := 187,
165 peer_ssn := 254,
166 sio := '83'O,
167 rctx := 1
168 }
Harald Weltea4ca4462018-02-09 00:17:14 +0100169 };
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200170
171 boolean mp_enable_cell_id_test := true;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100172}
173
Philipp Maier328d1662018-03-07 10:40:27 +0100174/* altstep for the global guard timer (only used when BSSAP_DIRECT
175 * is used for communication */
176private altstep as_Tguard_direct() runs on MTC_CT {
177 [] Tguard_direct.timeout {
178 setverdict(fail, "Tguard timeout");
Daniel Willmannafce8662018-07-06 23:11:32 +0200179 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +0100180 }
181}
Harald Weltef6dd64d2017-11-19 12:09:51 +0100182
Neels Hofmeyr2ca1ab42019-03-08 03:45:43 +0100183private altstep as_optional_cc_rel(CallParameters cpars, boolean respond := false) runs on BSC_ConnHdlr {
184 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id))) {
185 if (respond) {
186 var BIT1 tid_remote := '1'B;
187 if (cpars.mo_call) {
188 tid_remote := '0'B;
189 }
190 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id, tid_remote)));
191 }
192 }
Neels Hofmeyrde76f052019-02-26 05:02:46 +0100193}
194
Harald Weltef640a012018-04-14 17:49:21 +0200195function f_init_smpp(charstring id) runs on MTC_CT {
196 id := id & "-SMPP";
197 var EsmePars pars := {
198 mode := MODE_TRANSCEIVER,
199 bind := {
200 system_id := mp_smpp_system_id,
201 password := mp_smpp_password,
202 system_type := "MSC_Tests",
203 interface_version := hex2int('34'H),
204 addr_ton := unknown,
205 addr_npi := unknown,
206 address_range := ""
207 },
208 esme_role := true
209 }
210
211 vc_SMPP := SMPP_Emulation_CT.create(id);
212 map(vc_SMPP:SMPP_PORT, system:SMPP_PORT);
Harald Welte4698a4c2020-08-18 22:57:52 +0200213 vc_SMPP.start(SMPP_Emulation.main_client(pars, mp_msc_ip, mp_msc_smpp_port, "", 0));
Harald Weltef640a012018-04-14 17:49:21 +0200214}
215
216
Harald Weltea49e36e2018-01-21 19:29:33 +0100217function f_init_mncc(charstring id) runs on MTC_CT {
218 id := id & "-MNCC";
219 var MnccOps ops := {
220 create_cb := refers(MNCC_Emulation.ExpectedCreateCallback),
221 unitdata_cb := refers(MNCC_Emulation.DummyUnitdataCallback)
222 }
223
224 vc_MNCC := MNCC_Emulation_CT.create(id);
225 map(vc_MNCC:MNCC, system:MNCC_CODEC_PT);
226 vc_MNCC.start(MNCC_Emulation.main(ops, id, mp_msc_mncc));
Harald Weltef6dd64d2017-11-19 12:09:51 +0100227}
228
Harald Welte4aa970c2018-01-26 10:38:09 +0100229function f_init_mgcp(charstring id) runs on MTC_CT {
230 id := id & "-MGCP";
231 var MGCPOps ops := {
232 create_cb := refers(MGCP_Emulation.ExpectedCreateCallback),
233 unitdata_cb := refers(MGCP_Emulation.DummyUnitdataCallback)
234 }
235 var MGCP_conn_parameters pars := {
Harald Welte6126fb02018-01-27 20:08:24 +0100236 callagent_ip := mp_msc_ip,
Harald Welte4aa970c2018-01-26 10:38:09 +0100237 callagent_udp_port := -1,
Harald Welte6126fb02018-01-27 20:08:24 +0100238 mgw_ip := mp_mgw_ip,
Pau Espin Pedrol1a026a52019-06-18 17:21:52 +0200239 mgw_udp_port := mp_mgw_port,
240 multi_conn_mode := false
Harald Welte4aa970c2018-01-26 10:38:09 +0100241 }
242
243 vc_MGCP := MGCP_Emulation_CT.create(id);
244 map(vc_MGCP:MGCP, system:MGCP_CODEC_PT);
245 vc_MGCP.start(MGCP_Emulation.main(ops, pars, id));
246}
247
Philipp Maierc09a1312019-04-09 16:05:26 +0200248function ForwardUnitdataCallback(PDU_SGsAP msg)
249runs on SGsAP_Emulation_CT return template PDU_SGsAP {
250 SGsAP_CLIENT.send(msg);
251 return omit;
252}
253
Harald Welte4263c522018-12-06 11:56:27 +0100254function f_init_sgsap(charstring id) runs on MTC_CT {
255 id := id & "-SGsAP";
256 var SGsAPOps ops := {
257 create_cb := refers(SGsAP_Emulation.ExpectedCreateCallback),
Philipp Maierc09a1312019-04-09 16:05:26 +0200258 unitdata_cb := refers(ForwardUnitdataCallback)
Harald Welte4263c522018-12-06 11:56:27 +0100259 }
260 var SGsAP_conn_parameters pars := {
261 remote_ip := mp_msc_ip,
262 remote_sctp_port := 29118,
263 local_ip := "",
264 local_sctp_port := -1
265 }
266
267 vc_SGsAP := SGsAP_Emulation_CT.create(id);
268 map(vc_SGsAP:SGsAP, system:SGsAP_CODEC_PT);
269 vc_SGsAP.start(SGsAP_Emulation.main(ops, pars, id));
270}
271
272
Harald Weltea49e36e2018-01-21 19:29:33 +0100273function f_init_gsup(charstring id) runs on MTC_CT {
274 id := id & "-GSUP";
275 var GsupOps ops := {
276 create_cb := refers(GSUP_Emulation.ExpectedCreateCallback)
277 }
278
279 vc_GSUP_IPA := IPA_Emulation_CT.create(id & "-IPA");
280 vc_GSUP := GSUP_Emulation_CT.create(id);
281
282 map(vc_GSUP_IPA:IPA_PORT, system:IPA_CODEC_PT);
283 connect(vc_GSUP:GSUP, vc_GSUP_IPA:IPA_GSUP_PORT);
284 /* we use this hack to get events like ASP_IPA_EVENT_UP */
285 connect(vc_GSUP_IPA:IPA_CTRL_PORT, self:GSUP_IPA_EVENT);
286
287 vc_GSUP.start(GSUP_Emulation.main(ops, id));
288 vc_GSUP_IPA.start(IPA_Emulation.main_server(mp_hlr_ip, mp_hlr_port));
289
290 /* wait for incoming connection to GSUP port before proceeding */
291 timer T := 10.0;
292 T.start;
293 alt {
Vadim Yanitskiy61564be2020-05-18 20:44:14 +0700294 [] GSUP_IPA_EVENT.receive(tr_ASP_IPA_EV(ASP_IPA_EVENT_UP)) { }
Harald Weltea49e36e2018-01-21 19:29:33 +0100295 [] T.timeout {
Harald Welte458fd372018-03-21 11:26:23 +0100296 setverdict(fail, "No connection to GSUP Port");
Daniel Willmannafce8662018-07-06 23:11:32 +0200297 mtc.stop
Harald Weltea49e36e2018-01-21 19:29:33 +0100298 }
299 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100300}
301
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200302function f_init(integer num_bsc := 1, boolean sgsap := false, boolean gsup := true, boolean osmux := false) runs on MTC_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +0100303
304 if (g_initialized == true) {
305 return;
306 }
307 g_initialized := true;
308
Philipp Maier75932982018-03-27 14:52:35 +0200309 if (num_bsc > NUM_BSC) {
Daniel Willmannafce8662018-07-06 23:11:32 +0200310 testcase.stop("excess number of BSC instances requested");
Philipp Maier75932982018-03-27 14:52:35 +0200311 }
312
313 for (var integer i := 0; i < num_bsc; i := i + 1) {
314 if (isbound(mp_bssap_cfg[i])) {
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200315 var RanOps ranops := BSC_RanOps;
316 ranops.use_osmux := osmux;
317 f_ran_adapter_init(g_bssap[i], mp_bssap_cfg[i], "MSC_Test_" & int2str(i), ranops);
Harald Welte3ca0ce12019-04-23 17:18:48 +0200318 f_ran_adapter_start(g_bssap[i]);
Philipp Maier75932982018-03-27 14:52:35 +0200319 } else {
Daniel Willmannafce8662018-07-06 23:11:32 +0200320 testcase.stop("missing BSSAP configuration");
Philipp Maier75932982018-03-27 14:52:35 +0200321 }
322 }
323
Harald Weltea49e36e2018-01-21 19:29:33 +0100324 f_ipa_ctrl_start(mp_msc_ip, mp_msc_ctrl_port);
325 f_init_mncc("MSC_Test");
Harald Welte4aa970c2018-01-26 10:38:09 +0100326 f_init_mgcp("MSC_Test");
Philipp Maierc09a1312019-04-09 16:05:26 +0200327
328 if (gsup == true) {
329 f_init_gsup("MSC_Test");
330 }
Harald Weltef640a012018-04-14 17:49:21 +0200331 f_init_smpp("MSC_Test");
Philipp Maier57865482019-01-07 18:33:13 +0100332
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100333 if (sgsap == true) {
Philipp Maier57865482019-01-07 18:33:13 +0100334 f_init_sgsap("MSC_Test");
335 }
Harald Welte3ca1c902018-01-24 18:51:27 +0100336
337 map(self:MSCVTY, system:MSCVTY);
338 f_vty_set_prompts(MSCVTY);
339 f_vty_transceive(MSCVTY, "enable");
Harald Welteb14c77a2018-01-25 17:25:44 +0100340
341 /* set some defaults */
342 f_vty_config(MSCVTY, "network", "authentication optional");
343 f_vty_config(MSCVTY, "msc", "assign-tmsi");
Oliver Smith1d118ff2019-07-03 10:57:35 +0200344 f_vty_config(MSCVTY, "msc", "check-imei-rqd 0");
Harald Welteb14c77a2018-01-25 17:25:44 +0100345 f_vty_config(MSCVTY, "network", "encryption a5 0");
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100346 f_vty_config(MSCVTY, "cs7 instance 0", "sccp-timer ias " & int2str(g_msc_sccp_timer_ias));
347 f_vty_config(MSCVTY, "cs7 instance 0", "sccp-timer iar " & int2str(g_msc_sccp_timer_iar));
Pau Espin Pedrol690d6592019-05-31 17:56:32 +0200348 if (mp_enable_osmux_test) {
349 if (osmux) {
350 f_vty_config(MSCVTY, "msc", "osmux on");
351 } else {
352 f_vty_config(MSCVTY, "msc", "osmux off");
353 }
Pau Espin Pedrol3dd33bc2019-05-31 17:51:20 +0200354 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100355}
356
Philipp Maier328d1662018-03-07 10:40:27 +0100357/* Initialize for a direct connection to BSSAP. This function is an alternative
358 * to f_init() when the high level functions of the BSC_ConnectionHandler are
359 * not needed. */
360function f_init_bssap_direct() runs on MTC_CT {
Harald Welte3ca0ce12019-04-23 17:18:48 +0200361 f_ran_adapter_init(g_bssap[0], mp_bssap_cfg[0], "MSC_Test", omit);
Philipp Maier75932982018-03-27 14:52:35 +0200362 connect(g_bssap[0].vc_SCCP:SCCP_SP_PORT, self:BSSAP_DIRECT);
Philipp Maier328d1662018-03-07 10:40:27 +0100363
364 /* Start guard timer and activate it as default */
365 Tguard_direct.start
366 activate(as_Tguard_direct());
367}
368
Harald Weltea49e36e2018-01-21 19:29:33 +0100369type function void_fn(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100370
Harald Weltea49e36e2018-01-21 19:29:33 +0100371/* FIXME: move into BSC_ConnectionHandler? */
Harald Welte9b751a62019-04-14 17:39:29 +0200372function f_init_pars(integer imsi_suffix, boolean sgsap := false, boolean gsup := true, integer ran_idx := 0,
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200373 boolean ran_is_geran := true, boolean use_osmux := false, OCT4 gsup_sid := '20000101'O,
374 boolean verify_cell_id := true)
Harald Weltef9abf8d2019-04-21 13:07:17 +0200375runs on MTC_CT return BSC_ConnHdlrPars {
Harald Weltede371492018-01-27 23:44:41 +0100376 var BSC_ConnHdlrNetworkPars net_pars := {
377 kc_support := '0A'O, /* A5/1 and A5/3 enabled */
378 expect_tmsi := true,
379 expect_auth := false,
Oliver Smith1d118ff2019-07-03 10:57:35 +0200380 expect_ciph := false,
381 expect_imei := false,
382 expect_imei_early := false,
383 check_imei_result := OSMO_GSUP_IMEI_RESULT_ACK,
384 check_imei_error := false
Harald Weltede371492018-01-27 23:44:41 +0100385 };
Harald Weltea49e36e2018-01-21 19:29:33 +0100386 var BSC_ConnHdlrPars pars := {
Harald Weltef9abf8d2019-04-21 13:07:17 +0200387 sccp_addr_own := g_bssap[ran_idx].sccp_addr_own,
388 sccp_addr_peer := g_bssap[ran_idx].sccp_addr_peer,
Harald Welteedbab812018-03-18 16:02:25 +0100389 cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42)),
Harald Welte81b7f9d2018-01-24 19:06:24 +0100390 imei := f_gen_imei(imsi_suffix),
391 imsi := f_gen_imsi(imsi_suffix),
392 msisdn := f_gen_msisdn(imsi_suffix),
Harald Welte256571e2018-01-24 18:47:19 +0100393 tmsi := omit,
Harald Welte9de84792018-01-28 01:06:35 +0100394 cm1 := valueof(ts_CM1),
Harald Welte82600572018-01-21 20:54:08 +0100395 cm2 := valueof(ts_CM2_default),
Harald Welte16114282018-01-24 22:41:21 +0100396 cm3 := omit,
Harald Weltede371492018-01-27 23:44:41 +0100397 vec := omit,
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100398 net := net_pars,
Philipp Maieraeb29a82018-11-08 17:40:53 +0100399 send_early_cm := true,
400 ipa_ctrl_ip := mp_msc_ip,
401 ipa_ctrl_port := mp_msc_ctrl_port,
Philipp Maier9b690e42018-12-21 11:50:03 +0100402 ipa_ctrl_enable := true,
Philipp Maier57865482019-01-07 18:33:13 +0100403 mm_info := mp_mm_info,
Philipp Maierc09a1312019-04-09 16:05:26 +0200404 sgsap_enable := sgsap,
Harald Weltef9abf8d2019-04-21 13:07:17 +0200405 gsup_enable := gsup,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +0100406 gsup_sid := gsup_sid,
Harald Weltec1f937a2019-04-21 21:19:23 +0200407 ran_idx := ran_idx,
Harald Welte9b751a62019-04-14 17:39:29 +0200408 use_umts_aka := false,
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200409 ran_is_geran := ran_is_geran,
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200410 use_osmux := use_osmux,
411 verify_cell_id := mp_enable_cell_id_test and verify_cell_id
Harald Weltea49e36e2018-01-21 19:29:33 +0100412 };
Harald Weltee13cfb22019-04-23 16:52:02 +0200413 if (not ran_is_geran) {
414 pars.use_umts_aka := true;
415 pars.net.expect_auth := true;
416 }
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100417 return pars;
418}
419
Neels Hofmeyr0ac63152019-05-07 01:20:17 +0200420function f_start_handler_with_pars(void_fn fn, BSC_ConnHdlrPars pars, integer bssap_idx := 0) runs on MTC_CT return BSC_ConnHdlr {
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100421 var BSC_ConnHdlr vc_conn;
Neels Hofmeyr0ac63152019-05-07 01:20:17 +0200422 var charstring id := testcasename() & int2str(bssap_idx);
Harald Weltea49e36e2018-01-21 19:29:33 +0100423
424 vc_conn := BSC_ConnHdlr.create(id);
425 /* BSSMAP part / A interface */
Neels Hofmeyr0ac63152019-05-07 01:20:17 +0200426 connect(vc_conn:BSSAP, g_bssap[pars.ran_idx + bssap_idx].vc_RAN:CLIENT);
427 connect(vc_conn:BSSAP_PROC, g_bssap[pars.ran_idx + bssap_idx].vc_RAN:PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100428 /* MNCC part */
429 connect(vc_conn:MNCC, vc_MNCC:MNCC_CLIENT);
430 connect(vc_conn:MNCC_PROC, vc_MNCC:MNCC_PROC);
Harald Welte4aa970c2018-01-26 10:38:09 +0100431 /* MGCP part */
432 connect(vc_conn:MGCP, vc_MGCP:MGCP_CLIENT);
433 connect(vc_conn:MGCP_PROC, vc_MGCP:MGCP_PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100434 /* GSUP part */
Philipp Maierc09a1312019-04-09 16:05:26 +0200435 if (pars.gsup_enable == true) {
436 connect(vc_conn:GSUP, vc_GSUP:GSUP_CLIENT);
437 connect(vc_conn:GSUP_PROC, vc_GSUP:GSUP_PROC);
438 }
Harald Weltef640a012018-04-14 17:49:21 +0200439 /* SMPP part */
440 connect(vc_conn:SMPP, vc_SMPP:SMPP_CLIENT);
441 connect(vc_conn:SMPP_PROC, vc_SMPP:SMPP_PROC);
Harald Welte4263c522018-12-06 11:56:27 +0100442 /* SGs part */
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100443 if (pars.sgsap_enable == true) {
Philipp Maier57865482019-01-07 18:33:13 +0100444 connect(vc_conn:SGsAP, vc_SGsAP:SGsAP_CLIENT);
445 connect(vc_conn:SGsAP_PROC, vc_SGsAP:SGsAP_PROC);
446 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100447
Harald Weltea10db902018-01-27 12:44:49 +0100448 /* We cannot use vc_conn.start(f_init_handler(fn, id, pars)); as we cannot have
449 * a stand-alone 'derefers()' call, see https://www.eclipse.org/forums/index.php/t/1091364/ */
Harald Weltea49e36e2018-01-21 19:29:33 +0100450 vc_conn.start(derefers(fn)(id, pars));
451 return vc_conn;
452}
453
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200454function f_start_handler(void_fn fn, integer imsi_suffix, integer ran_idx := 0, boolean ran_is_geran := true, boolean use_osmux := false,
455 boolean verify_cell_id := true)
Harald Welte9b751a62019-04-14 17:39:29 +0200456runs on MTC_CT return BSC_ConnHdlr {
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200457 return f_start_handler_with_pars(fn, f_init_pars(imsi_suffix, ran_idx := ran_idx, ran_is_geran := ran_is_geran, use_osmux := use_osmux, verify_cell_id := verify_cell_id));
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100458}
459
Harald Weltea49e36e2018-01-21 19:29:33 +0100460private function f_tc_lu_imsi_noauth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100461 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100462 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100463}
Harald Weltea49e36e2018-01-21 19:29:33 +0100464testcase TC_lu_imsi_noauth_tmsi() runs on MTC_CT {
465 var BSC_ConnHdlr vc_conn;
466 f_init();
467
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100468 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi), 1);
Harald Weltea49e36e2018-01-21 19:29:33 +0100469 vc_conn.done;
470}
471
472private function f_tc_lu_imsi_noauth_notmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100473 pars.net.expect_tmsi := false;
Harald Weltea10db902018-01-27 12:44:49 +0100474 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100475 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100476}
Harald Weltea49e36e2018-01-21 19:29:33 +0100477testcase TC_lu_imsi_noauth_notmsi() runs on MTC_CT {
478 var BSC_ConnHdlr vc_conn;
479 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100480 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
Harald Weltea49e36e2018-01-21 19:29:33 +0100481
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100482 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi), 2);
Harald Weltea49e36e2018-01-21 19:29:33 +0100483 vc_conn.done;
484}
485
486/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
Harald Weltee13cfb22019-04-23 16:52:02 +0200487friend function f_tc_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100488 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100489 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
490
491 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +0200492 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyrd076c522019-11-28 01:00:52 +0100493 f_mm_common();
Harald Weltea49e36e2018-01-21 19:29:33 +0100494 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
495 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
496 alt {
Harald Welte5946b332018-03-18 23:32:21 +0100497 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej(int2oct(23,1)))) {
498 f_expect_clear();
499 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100500 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
501 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200502 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100503 }
504 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100505}
506testcase TC_lu_imsi_reject() runs on MTC_CT {
507 var BSC_ConnHdlr vc_conn;
508 f_init();
509
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200510 vc_conn := f_start_handler(refers(f_tc_lu_imsi_reject), 3, verify_cell_id := false);
Harald Weltea49e36e2018-01-21 19:29:33 +0100511 vc_conn.done;
512}
513
Harald Weltee13cfb22019-04-23 16:52:02 +0200514
515
Harald Weltea49e36e2018-01-21 19:29:33 +0100516/* Do LU by IMSI, timeout on GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +0200517friend function f_tc_lu_imsi_timeout_gsup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100518 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100519 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
520
521 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +0200522 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyrd076c522019-11-28 01:00:52 +0100523 f_mm_common();
Harald Weltea49e36e2018-01-21 19:29:33 +0100524 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
525 /* Normally the HLR would need to respond here, but we decide to force a timeout here */
526 alt {
527 /* FIXME: Expect specific reject cause */
Harald Welte5946b332018-03-18 23:32:21 +0100528 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
529 f_expect_clear();
530 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100531 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
532 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200533 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100534 }
535 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100536}
537testcase TC_lu_imsi_timeout_gsup() runs on MTC_CT {
538 var BSC_ConnHdlr vc_conn;
539 f_init();
540
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200541 vc_conn := f_start_handler(refers(f_tc_lu_imsi_timeout_gsup), 4, verify_cell_id := false);
Harald Weltea49e36e2018-01-21 19:29:33 +0100542 vc_conn.done;
543}
544
Harald Weltee13cfb22019-04-23 16:52:02 +0200545
Harald Welte7b1b2812018-01-22 21:23:06 +0100546private function f_tc_lu_imsi_auth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100547 pars.net.expect_auth := true;
Harald Weltea10db902018-01-27 12:44:49 +0100548 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100549 f_perform_lu();
Harald Welte7b1b2812018-01-22 21:23:06 +0100550}
551testcase TC_lu_imsi_auth_tmsi() runs on MTC_CT {
552 var BSC_ConnHdlr vc_conn;
553 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100554 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte7b1b2812018-01-22 21:23:06 +0100555
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100556 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi), 5);
Harald Welte7b1b2812018-01-22 21:23:06 +0100557 vc_conn.done;
558}
559
Harald Weltee13cfb22019-04-23 16:52:02 +0200560
561friend function f_tc_lu_imsi_auth3g_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte8a397ae2019-04-21 22:03:37 +0200562 pars.net.expect_auth := true;
563 pars.use_umts_aka := true;
564 f_init_handler(pars);
565 f_perform_lu();
566}
567testcase TC_lu_imsi_auth3g_tmsi() runs on MTC_CT {
568 var BSC_ConnHdlr vc_conn;
569 f_init();
570 f_vty_config(MSCVTY, "network", "authentication required");
571
572 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi), 1005);
573 vc_conn.done;
574}
Harald Weltea49e36e2018-01-21 19:29:33 +0100575
Pau Espin Pedrold3d54a92019-12-17 17:02:54 +0100576/* Proceed with LU but never receive an TMSI Realloc from MS after LU Accept (OS#4337).
577 * TS 24.008 sec 4.3.1.5 states MSC should simply release all MM connections.
578 */
579friend function f_tc_lu_imsi_timeout_tmsi_realloc(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
580
581 f_init_handler(pars);
582
583 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
584 var PDU_DTAP_MT dtap_mt;
585
586 /* tell GSUP dispatcher to send this IMSI to us */
587 f_create_gsup_expect(hex2str(g_pars.imsi));
588
589 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
590 if (g_pars.ran_is_geran) {
591 f_bssap_compl_l3(l3_lu);
592 if (g_pars.send_early_cm) {
593 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
594 }
595 } else {
596 f_ranap_initial_ue(l3_lu);
597 }
598
599 f_mm_imei_early();
600 f_mm_common();
601 f_msc_lu_hlr();
602 f_mm_imei();
603
604 alt {
605 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) -> value dtap_mt {}
606 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
607 setverdict(fail, "Expected LU ACK, but received LU REJ");
608 mtc.stop;
609 }
610 }
611
612 /* currently (due to bug OS#4337), an extra LU reject is received before
613 terminating the connection. Enabling following line makes the test
614 pass: */
615 //f_expect_lu_reject('16'O); /* Cause: congestion */
616
617 /* f_expect_lu_reject() already waits for T"-1" (X1, 5 seconds), but give some
618 extra time to avoid race conditons... */
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200619 f_expect_clear(7.0, verify_vlr_cell_id := false);
Pau Espin Pedrold3d54a92019-12-17 17:02:54 +0100620
621 setverdict(pass);
622}
623testcase TC_lu_imsi_timeout_tmsi_realloc() runs on MTC_CT {
624 var BSC_ConnHdlr vc_conn;
625 f_init();
626
627 vc_conn := f_start_handler(refers(f_tc_lu_imsi_timeout_tmsi_realloc), 5);
628 vc_conn.done;
629}
630
Harald Weltee13cfb22019-04-23 16:52:02 +0200631
Harald Weltea49e36e2018-01-21 19:29:33 +0100632/* Send CM SERVICE REQ for IMSI that has never performed LU before */
Harald Weltee13cfb22019-04-23 16:52:02 +0200633friend function f_tc_cmserv_imsi_unknown(charstring id, BSC_ConnHdlrPars pars)
Harald Weltea49e36e2018-01-21 19:29:33 +0100634runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100635 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100636
637 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welteedbab812018-03-18 16:02:25 +0100638 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
Harald Welte6ed6bf92018-01-24 21:09:15 +0100639 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
Harald Weltea49e36e2018-01-21 19:29:33 +0100640
641 f_create_gsup_expect(hex2str(g_pars.imsi));
642
643 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200644 f_cl3_or_initial_ue(l3_info);
Harald Welteb7817992019-05-09 13:15:39 +0200645 f_mm_auth();
Harald Weltea49e36e2018-01-21 19:29:33 +0100646
647 timer T := 10.0;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100648 T.start;
649 alt {
Harald Weltea49e36e2018-01-21 19:29:33 +0100650 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
651 //[] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_ACC)) { }
Daniel Willmannafce8662018-07-06 23:11:32 +0200652 [] BSSAP.receive {
653 setverdict(fail, "Received unexpected BSSAP");
654 mtc.stop;
655 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100656 [] GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi)) {
657 setverdict(fail, "Unexpected GSUP UL REQ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200658 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100659 }
Daniel Willmannafce8662018-07-06 23:11:32 +0200660 [] T.timeout {
Neels Hofmeyrf1c3c212020-08-19 13:15:32 +0000661 setverdict(fail, "Timeout waiting for CM SERV REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200662 mtc.stop;
663 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100664 }
665
Harald Welte1ddc7162018-01-27 14:25:46 +0100666 f_expect_clear();
Harald Weltef6dd64d2017-11-19 12:09:51 +0100667}
Harald Weltea49e36e2018-01-21 19:29:33 +0100668testcase TC_cmserv_imsi_unknown() runs on MTC_CT {
669 var BSC_ConnHdlr vc_conn;
670 f_init();
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200671 vc_conn := f_start_handler(refers(f_tc_cmserv_imsi_unknown), 6, verify_cell_id := false);
Harald Weltea49e36e2018-01-21 19:29:33 +0100672 vc_conn.done;
673}
674
Harald Weltee13cfb22019-04-23 16:52:02 +0200675
676friend function f_tc_lu_and_mo_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100677 f_init_handler(pars);
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +0200678 var CallParameters cpars := valueof(t_CallParams);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100679 f_perform_lu();
Harald Welteb71901a2018-01-26 19:16:05 +0100680 f_mo_call(cpars);
Harald Welte2bb825f2018-01-22 11:31:18 +0100681}
682testcase TC_lu_and_mo_call() runs on MTC_CT {
683 var BSC_ConnHdlr vc_conn;
684 f_init();
685
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100686 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_call), 7);
Harald Welte071ed732018-01-23 19:53:52 +0100687 vc_conn.done;
688}
689
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100690/* Verify T(iar) triggers and releases the channel */
691friend function f_lu_and_mo_call_sccp_tiar_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
692 timer T_wait_iar := int2float(5 + 1); /* g_msc_sccp_timer_iar + Give extra time (+1 sec) */
693 f_init_handler(pars);
694 var CallParameters cpars := valueof(t_CallParams);
695 f_perform_lu();
696 f_mo_call_establish(cpars);
697
698 /* Expect the channel cleared upon T(iar) triggered: */
699 T_wait_iar.start;
700 alt {
701 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {
702 T_wait_iar.stop
703 setverdict(pass);
704 }
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100705 [] T_wait_iar.timeout {
706 setverdict(fail, "Timeout waiting for T(iar) triggered SCCP RSLD");
707 mtc.stop;
708 }
709 }
Harald Welte4a3fa712020-08-19 08:57:33 +0200710 /* DLCX for both directions; if we don't do this, we might receive either of the two during
711 * shutdown causing race conditions */
712 MGCP.receive(tr_DLCX(?));
713 MGCP.receive(tr_DLCX(?));
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100714
715 setverdict(pass);
716}
717testcase TC_lu_and_mo_call_sccp_tiar_timeout() runs on MTC_CT {
718 var BSC_ConnHdlr vc_conn;
719
720 /* Set T(iar) in MSC low enough that it will trigger before other side
721 has time to keep alive with a T(ias). Keep recommended ratio of
722 T(iar) >= T(ias)*2 */
723 g_msc_sccp_timer_ias := 2;
724 g_msc_sccp_timer_iar := 5;
725
726 f_init();
727
728 vc_conn := f_start_handler(refers(f_lu_and_mo_call_sccp_tiar_timeout), 89);
729 vc_conn.done;
730}
731
Harald Weltee13cfb22019-04-23 16:52:02 +0200732
Harald Welte071ed732018-01-23 19:53:52 +0100733/* Test LU (with authentication enabled), where HLR times out sending SAI response */
Harald Weltee13cfb22019-04-23 16:52:02 +0200734friend function f_tc_lu_auth_sai_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100735 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100736
737 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
738 var PDU_DTAP_MT dtap_mt;
739
740 /* tell GSUP dispatcher to send this IMSI to us */
741 f_create_gsup_expect(hex2str(g_pars.imsi));
742
743 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200744 f_cl3_or_initial_ue(l3_lu);
Harald Welte071ed732018-01-23 19:53:52 +0100745
746 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200747 if (pars.ran_is_geran) {
748 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
749 }
Harald Welte071ed732018-01-23 19:53:52 +0100750
751 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
752 /* The HLR would normally return an auth vector here, but we fail to do so. */
753
754 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100755 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100756}
757testcase TC_lu_auth_sai_timeout() runs on MTC_CT {
758 var BSC_ConnHdlr vc_conn;
759 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100760 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100761
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200762 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_timeout), 8, verify_cell_id := false);
Harald Welte071ed732018-01-23 19:53:52 +0100763 vc_conn.done;
764}
765
Harald Weltee13cfb22019-04-23 16:52:02 +0200766
Harald Welte071ed732018-01-23 19:53:52 +0100767/* Test LU (with authentication enabled), where HLR rejects sending SAI error */
Harald Weltee13cfb22019-04-23 16:52:02 +0200768friend function f_tc_lu_auth_sai_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100769 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100770
771 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
772 var PDU_DTAP_MT dtap_mt;
773
774 /* tell GSUP dispatcher to send this IMSI to us */
775 f_create_gsup_expect(hex2str(g_pars.imsi));
776
777 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200778 f_cl3_or_initial_ue(l3_lu);
Harald Welte071ed732018-01-23 19:53:52 +0100779
780 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200781 if (pars.ran_is_geran) {
782 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
783 }
Harald Welte071ed732018-01-23 19:53:52 +0100784
785 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
786 GSUP.send(ts_GSUP_SAI_ERR(g_pars.imsi, 13));
787
788 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100789 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100790}
791testcase TC_lu_auth_sai_err() runs on MTC_CT {
792 var BSC_ConnHdlr vc_conn;
793 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100794 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100795
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200796 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_err), 9, verify_cell_id := false);
Harald Welte2bb825f2018-01-22 11:31:18 +0100797 vc_conn.done;
798}
Harald Weltea49e36e2018-01-21 19:29:33 +0100799
Harald Weltee13cfb22019-04-23 16:52:02 +0200800
Harald Weltebc881782018-01-23 20:09:15 +0100801/* Test LU but BSC will send a clear request in the middle */
802private function f_tc_lu_clear_request(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100803 f_init_handler(pars);
Harald Weltebc881782018-01-23 20:09:15 +0100804
805 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
806 var PDU_DTAP_MT dtap_mt;
807
808 /* tell GSUP dispatcher to send this IMSI to us */
809 f_create_gsup_expect(hex2str(g_pars.imsi));
810
811 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200812 f_cl3_or_initial_ue(l3_lu);
Harald Welte79f1e452020-08-18 22:55:02 +0200813 f_expect_common_id();
Harald Weltebc881782018-01-23 20:09:15 +0100814
815 /* Send Early Classmark, just for the fun of it */
816 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
817
818 f_sleep(1.0);
819 /* send clear request in the middle of the LU */
820 BSSAP.send(ts_BSSMAP_ClearRequest(0));
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200821 alt {
822 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { repeat; }
823 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {}
824 }
Harald Weltebc881782018-01-23 20:09:15 +0100825 BSSAP.send(ts_BSSMAP_ClearComplete);
Harald Welte89a32492018-01-27 19:07:28 +0100826 alt {
827 /* See https://osmocom.org/issues/2862 */
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200828 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {
829 setverdict(fail, "Got a second Clear Command, only one expected");
Daniel Willmannafce8662018-07-06 23:11:32 +0200830 mtc.stop;
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200831 repeat;
832 }
Harald Welte6811d102019-04-14 22:23:14 +0200833 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte89a32492018-01-27 19:07:28 +0100834 }
Harald Weltebc881782018-01-23 20:09:15 +0100835 setverdict(pass);
836}
837testcase TC_lu_clear_request() runs on MTC_CT {
838 var BSC_ConnHdlr vc_conn;
839 f_init();
840
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100841 vc_conn := f_start_handler(refers(f_tc_lu_clear_request), 10);
Harald Weltebc881782018-01-23 20:09:15 +0100842 vc_conn.done;
843}
844
Harald Welte66af9e62018-01-24 17:28:21 +0100845/* Test LU but BSC will send a clear request in the middle */
Harald Weltee13cfb22019-04-23 16:52:02 +0200846friend function f_tc_lu_disconnect(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100847 f_init_handler(pars);
Harald Welte66af9e62018-01-24 17:28:21 +0100848
849 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
850 var PDU_DTAP_MT dtap_mt;
851
852 /* tell GSUP dispatcher to send this IMSI to us */
853 f_create_gsup_expect(hex2str(g_pars.imsi));
854
855 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200856 f_cl3_or_initial_ue(l3_lu);
Harald Welte66af9e62018-01-24 17:28:21 +0100857
858 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200859 if (pars.ran_is_geran) {
860 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
861 }
Harald Welte66af9e62018-01-24 17:28:21 +0100862
863 f_sleep(1.0);
864 /* send clear request in the middle of the LU */
Harald Welte6811d102019-04-14 22:23:14 +0200865 BSSAP.send(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_REQ);
Harald Welte66af9e62018-01-24 17:28:21 +0100866 setverdict(pass);
Neels Hofmeyrbb825c92019-03-06 15:35:50 +0100867 f_sleep(1.0);
Harald Welte66af9e62018-01-24 17:28:21 +0100868}
869testcase TC_lu_disconnect() runs on MTC_CT {
870 var BSC_ConnHdlr vc_conn;
871 f_init();
872
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100873 vc_conn := f_start_handler(refers(f_tc_lu_disconnect), 11);
Harald Welte66af9e62018-01-24 17:28:21 +0100874 vc_conn.done;
875}
876
Harald Welteba7b6d92018-01-23 21:32:34 +0100877/* Test LU but with illegal mobile identity type = IMEI */
Harald Weltee13cfb22019-04-23 16:52:02 +0200878friend function f_tc_lu_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100879 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +0100880
Harald Welte256571e2018-01-24 18:47:19 +0100881 var PDU_ML3_MS_NW l3_lu := f_build_lu_imei(g_pars.imei)
Harald Welteba7b6d92018-01-23 21:32:34 +0100882 var PDU_DTAP_MT dtap_mt;
883
884 /* tell GSUP dispatcher to send this IMSI to us */
885 f_create_gsup_expect(hex2str(g_pars.imsi));
886
887 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200888 f_cl3_or_initial_ue(l3_lu);
Harald Welteba7b6d92018-01-23 21:32:34 +0100889
890 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200891 if (pars.ran_is_geran) {
892 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
893 }
Harald Welteba7b6d92018-01-23 21:32:34 +0100894 /* wait for LU reject, ignore any ID REQ */
895 alt {
896 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { }
897 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req)) { repeat; }
898 }
899 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100900 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +0100901}
902testcase TC_lu_by_imei() runs on MTC_CT {
903 var BSC_ConnHdlr vc_conn;
904 f_init();
905
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200906 vc_conn := f_start_handler(refers(f_tc_lu_by_imei), 12, verify_cell_id := false);
Harald Welteba7b6d92018-01-23 21:32:34 +0100907 vc_conn.done;
908}
909
Harald Weltee13cfb22019-04-23 16:52:02 +0200910
Harald Welteba7b6d92018-01-23 21:32:34 +0100911/* Test LU by TMSI with unknown TMSI, expect (and answer) ID REQ. */
912private function f_tc_lu_tmsi_noauth_unknown(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Stefan Sperling04fc4bc2018-06-25 17:44:57 +0200913 /* We piggyback a test for an MSC crash on overlong IMSI (OS#2864) onto this test. */
914 var hexstring overlong_imsi := '012345789ABCDEF0123456789ABCDEF'H;
Harald Weltea10db902018-01-27 12:44:49 +0100915 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +0100916
917 var PDU_ML3_MS_NW l3_lu := f_build_lu_tmsi('01020304'O); /* FIXME: Random */
918 var PDU_DTAP_MT dtap_mt;
919
920 /* tell GSUP dispatcher to send this IMSI to us */
921 f_create_gsup_expect(hex2str(g_pars.imsi));
922
923 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200924 f_cl3_or_initial_ue(l3_lu);
Harald Welteba7b6d92018-01-23 21:32:34 +0100925
926 /* Send Early Classmark, just for the fun of it */
927 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
928
929 /* Wait for + respond to ID REQ (IMSI) */
Oliver Smith32898452019-07-09 12:32:35 +0200930 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
Stefan Sperling04fc4bc2018-06-25 17:44:57 +0200931 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(overlong_imsi))); /* test for OS#2864 */
Harald Welteba7b6d92018-01-23 21:32:34 +0100932 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(g_pars.imsi)));
Harald Welte79f1e452020-08-18 22:55:02 +0200933 f_expect_common_id();
Harald Welteba7b6d92018-01-23 21:32:34 +0100934
935 /* Expect MSC to do UpdateLocation to HLR; respond to it */
936 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
937 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
938 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
939 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
940
941 alt {
Harald Welte7ec4fa82018-01-27 10:57:40 +0100942 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
943 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_TmsiRealloc_Cmpl));
944 }
Harald Welteba7b6d92018-01-23 21:32:34 +0100945 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
946 setverdict(fail, "Expected LU ACK, but received REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200947 mtc.stop;
Harald Welteba7b6d92018-01-23 21:32:34 +0100948 }
949 }
950
Philipp Maier9b690e42018-12-21 11:50:03 +0100951 /* Wait for MM-Information (if enabled) */
952 f_expect_mm_info();
953
Harald Welteba7b6d92018-01-23 21:32:34 +0100954 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100955 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +0100956}
957testcase TC_lu_by_tmsi_noauth_unknown() runs on MTC_CT {
958 var BSC_ConnHdlr vc_conn;
959 f_init();
960
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100961 vc_conn := f_start_handler(refers(f_tc_lu_tmsi_noauth_unknown), 13);
Harald Welteba7b6d92018-01-23 21:32:34 +0100962 vc_conn.done;
963}
964
Harald Welte4d15fa72020-08-19 08:58:28 +0200965friend function f_imsi_detach_by_imsi() runs on BSC_ConnHdlr {
Harald Welte45164da2018-01-24 12:51:27 +0100966 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
967
968 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200969 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +0100970
971 /* Send Early Classmark, just for the fun of it? */
Harald Welte4d15fa72020-08-19 08:58:28 +0200972 if (g_pars.ran_is_geran) {
Harald Weltee13cfb22019-04-23 16:52:02 +0200973 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
974 }
Harald Welte45164da2018-01-24 12:51:27 +0100975
976 /* wait for normal teardown */
Harald Welte4d15fa72020-08-19 08:58:28 +0200977 f_expect_clear(verify_vlr_cell_id := false);
978}
979
980
981/* Test IMSI DETACH (MI=IMSI) */
982friend function f_tc_imsi_detach_by_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
983 f_init_handler(pars);
984
985 f_imsi_detach_by_imsi();
Harald Welte45164da2018-01-24 12:51:27 +0100986}
987testcase TC_imsi_detach_by_imsi() runs on MTC_CT {
988 var BSC_ConnHdlr vc_conn;
989 f_init();
990
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200991 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imsi), 14, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +0100992 vc_conn.done;
993}
994
Harald Weltee13cfb22019-04-23 16:52:02 +0200995
Harald Welte45164da2018-01-24 12:51:27 +0100996/* Test IMSI DETACH (MI=TMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +0200997friend function f_tc_imsi_detach_by_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100998 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +0100999
1000 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV('01020304'O));
1001
1002 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001003 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +01001004
1005 /* Send Early Classmark, just for the fun of it? */
Harald Weltee13cfb22019-04-23 16:52:02 +02001006 if (pars.ran_is_geran) {
1007 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1008 }
Harald Welte45164da2018-01-24 12:51:27 +01001009
1010 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001011 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001012}
1013testcase TC_imsi_detach_by_tmsi() runs on MTC_CT {
1014 var BSC_ConnHdlr vc_conn;
1015 f_init();
1016
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001017 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_tmsi), 15, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001018 vc_conn.done;
1019}
1020
Harald Weltee13cfb22019-04-23 16:52:02 +02001021
Harald Welte45164da2018-01-24 12:51:27 +01001022/* Test IMSI DETACH (MI=IMEI), which is illegal */
Harald Weltee13cfb22019-04-23 16:52:02 +02001023friend function f_tc_imsi_detach_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001024 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001025
Harald Welte256571e2018-01-24 18:47:19 +01001026 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte45164da2018-01-24 12:51:27 +01001027
1028 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001029 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +01001030
1031 /* Send Early Classmark, just for the fun of it? */
Harald Weltee13cfb22019-04-23 16:52:02 +02001032 if (pars.ran_is_geran) {
1033 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1034 }
Harald Welte45164da2018-01-24 12:51:27 +01001035
1036 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001037 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001038}
1039testcase TC_imsi_detach_by_imei() runs on MTC_CT {
1040 var BSC_ConnHdlr vc_conn;
1041 f_init();
1042
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001043 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imei), 16, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001044 vc_conn.done;
1045}
1046
1047
1048/* helper function for an emergency call. caller passes in mobile identity to use */
1049private function f_emerg_call(MobileIdentityLV mi) runs on BSC_ConnHdlr {
Harald Welte0bef21e2018-02-10 09:48:23 +01001050 var CallParameters cpars := valueof(t_CallParams('112'H, 0));
1051 cpars.emergency := true;
Harald Welte45164da2018-01-24 12:51:27 +01001052
Harald Welte0bef21e2018-02-10 09:48:23 +01001053 f_mo_call(cpars);
Harald Welte45164da2018-01-24 12:51:27 +01001054}
1055
1056/* establish an emergency call by IMEI, no SIM inserted (and hence no IMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +02001057friend function f_tc_emerg_call_imei_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001058 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001059
Harald Welte256571e2018-01-24 18:47:19 +01001060 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001061 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_EMERG_CALL, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001062 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001063 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ('05'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +01001064 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001065}
1066testcase TC_emerg_call_imei_reject() runs on MTC_CT {
1067 var BSC_ConnHdlr vc_conn;
1068 f_init();
1069
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001070 vc_conn := f_start_handler(refers(f_tc_emerg_call_imei_reject), 17, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001071 vc_conn.done;
1072}
1073
Harald Weltee13cfb22019-04-23 16:52:02 +02001074
Harald Welted5b91402018-01-24 18:48:16 +01001075/* establish an emergency call by IMSI, SIM inserted (and hence IMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +02001076friend function f_tc_emerg_call_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001077 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001078 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001079 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001080 /* Then issue emergency call identified by IMSI */
1081 f_emerg_call(valueof(ts_MI_IMSI_LV(g_pars.imsi)));
1082}
1083testcase TC_emerg_call_imsi() runs on MTC_CT {
1084 var BSC_ConnHdlr vc_conn;
1085 f_init();
1086
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001087 vc_conn := f_start_handler(refers(f_tc_emerg_call_imsi), 18);
Harald Welte45164da2018-01-24 12:51:27 +01001088 vc_conn.done;
1089}
1090
Harald Weltee13cfb22019-04-23 16:52:02 +02001091
Harald Welte45164da2018-01-24 12:51:27 +01001092/* CM Service Request for VGCS -> reject */
1093private function f_tc_cm_serv_req_vgcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001094 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001095
1096 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001097 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001098
1099 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001100 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VGCS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001101 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001102 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001103 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001104}
1105testcase TC_cm_serv_req_vgcs_reject() runs on MTC_CT {
1106 var BSC_ConnHdlr vc_conn;
1107 f_init();
1108
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001109 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vgcs_reject), 19);
Harald Welte45164da2018-01-24 12:51:27 +01001110 vc_conn.done;
1111}
1112
1113/* CM Service Request for VBS -> reject */
1114private function f_tc_cm_serv_req_vbs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001115 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001116
1117 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001118 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001119
1120 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001121 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VBS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001122 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001123 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001124 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001125}
1126testcase TC_cm_serv_req_vbs_reject() runs on MTC_CT {
1127 var BSC_ConnHdlr vc_conn;
1128 f_init();
1129
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001130 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vbs_reject), 20);
Harald Welte45164da2018-01-24 12:51:27 +01001131 vc_conn.done;
1132}
1133
1134/* CM Service Request for LCS -> reject */
1135private function f_tc_cm_serv_req_lcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001136 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001137
1138 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001139 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001140
1141 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001142 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_LCS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001143 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001144 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001145 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001146}
1147testcase TC_cm_serv_req_lcs_reject() runs on MTC_CT {
1148 var BSC_ConnHdlr vc_conn;
1149 f_init();
1150
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001151 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_lcs_reject), 21);
Harald Welte45164da2018-01-24 12:51:27 +01001152 vc_conn.done;
1153}
1154
Harald Welte0195ab12018-01-24 21:50:20 +01001155/* CM Re-Establishment Request */
1156private function f_tc_cm_reest_req_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001157 f_init_handler(pars);
Harald Welte0195ab12018-01-24 21:50:20 +01001158
1159 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001160 f_perform_lu();
Harald Welte0195ab12018-01-24 21:50:20 +01001161
1162 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1163 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_REEST_REQ(0, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001164 f_cl3_or_initial_ue(l3_info);
Harald Welte0195ab12018-01-24 21:50:20 +01001165 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001166 f_expect_clear();
Harald Welte0195ab12018-01-24 21:50:20 +01001167}
1168testcase TC_cm_reest_req_reject() runs on MTC_CT {
1169 var BSC_ConnHdlr vc_conn;
1170 f_init();
Harald Welte0195ab12018-01-24 21:50:20 +01001171
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001172 vc_conn := f_start_handler(refers(f_tc_cm_reest_req_reject), 22);
Harald Welte0195ab12018-01-24 21:50:20 +01001173 vc_conn.done;
1174}
1175
Harald Weltec638f4d2018-01-24 22:00:36 +01001176/* Test LU (with authentication enabled), with wrong response from MS */
1177private function f_tc_lu_auth_2G_fail(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001178 f_init_handler(pars);
Harald Weltec638f4d2018-01-24 22:00:36 +01001179
1180 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
1181
1182 /* tell GSUP dispatcher to send this IMSI to us */
1183 f_create_gsup_expect(hex2str(g_pars.imsi));
1184
1185 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001186 f_cl3_or_initial_ue(l3_lu);
Harald Weltec638f4d2018-01-24 22:00:36 +01001187
1188 /* Send Early Classmark, just for the fun of it */
1189 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1190
1191 var AuthVector vec := f_gen_auth_vec_2g();
1192 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G(vec.rand, vec.sres, vec.kc));
1193 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
1194 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
1195
1196 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_AUTH_REQ(vec.rand)));
1197 /* Send back wrong auth response */
1198 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MT_MM_AUTH_RESP_2G('00000000'O)));
1199
1200 /* Expect GSUP AUTH FAIL REP to HLR */
1201 GSUP.receive(tr_GSUP_AUTH_FAIL_IND(g_pars.imsi));
1202
1203 /* Expect LU REJECT with Cause == Illegal MS */
1204 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej('03'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +01001205 f_expect_clear();
Harald Weltec638f4d2018-01-24 22:00:36 +01001206}
1207testcase TC_lu_auth_2G_fail() runs on MTC_CT {
1208 var BSC_ConnHdlr vc_conn;
1209 f_init();
1210 f_vty_config(MSCVTY, "network", "authentication required");
Harald Weltec638f4d2018-01-24 22:00:36 +01001211
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001212 vc_conn := f_start_handler(refers(f_tc_lu_auth_2G_fail), 23, verify_cell_id := false);
Harald Weltec638f4d2018-01-24 22:00:36 +01001213 vc_conn.done;
1214}
1215
Harald Weltede371492018-01-27 23:44:41 +01001216/* A5/1 + A5/3 permitted on network side, and MS capable to do it */
Harald Welte16114282018-01-24 22:41:21 +01001217private function f_tc_lu_imsi_auth_tmsi_encr_13_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +01001218 pars.net.expect_auth := true;
1219 pars.net.expect_ciph := true;
Harald Weltea10db902018-01-27 12:44:49 +01001220 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001221 f_perform_lu();
Harald Welte16114282018-01-24 22:41:21 +01001222}
1223testcase TC_lu_imsi_auth_tmsi_encr_13_13() runs on MTC_CT {
1224 var BSC_ConnHdlr vc_conn;
1225 f_init();
1226 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte16114282018-01-24 22:41:21 +01001227 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
1228
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001229 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_13), 24);
Harald Welte16114282018-01-24 22:41:21 +01001230 vc_conn.done;
1231}
1232
Harald Welte1af6ea82018-01-25 18:33:15 +01001233/* Test Complete L3 without payload */
1234private function f_tc_cl3_no_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001235 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001236
1237 /* Send Complete L3 Info with empty L3 frame */
1238 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1239 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, ''O))));
1240
Harald Weltef466eb42018-01-27 14:26:54 +01001241 timer T := 5.0;
1242 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001243 alt {
Harald Welte6811d102019-04-14 22:23:14 +02001244 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte1af6ea82018-01-25 18:33:15 +01001245 /* Expect LU REJECT with Cause == Illegal MS */
Harald Weltebdb3c452018-03-18 22:43:06 +01001246 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
Harald Welte6811d102019-04-14 22:23:14 +02001247 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001248 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001249 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001250 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001251 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001252 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001253 }
1254 setverdict(pass);
1255}
1256testcase TC_cl3_no_payload() runs on MTC_CT {
1257 var BSC_ConnHdlr vc_conn;
1258 f_init();
1259
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001260 vc_conn := f_start_handler(refers(f_tc_cl3_no_payload), 25);
Harald Welte1af6ea82018-01-25 18:33:15 +01001261 vc_conn.done;
1262}
1263
1264/* Test Complete L3 with random payload */
1265private function f_tc_cl3_rnd_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001266 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001267
Daniel Willmannaa14a382018-07-26 08:29:45 +02001268 /* length is limited by PDU_BSSAP length field which includes some
1269 * other fields beside l3info payload. So payl can only be 240 bytes
1270 * Since rnd() returns values < 1 multiply with 241
1271 */
1272 var integer len := float2int(rnd() * 241.0);
Harald Welte1af6ea82018-01-25 18:33:15 +01001273 var octetstring payl := f_rnd_octstring(len);
1274
1275 /* Send Complete L3 Info with empty L3 frame */
1276 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1277 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, payl))));
1278
Harald Weltef466eb42018-01-27 14:26:54 +01001279 timer T := 5.0;
1280 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001281 alt {
1282 /* Immediate disconnect */
Harald Welte6811d102019-04-14 22:23:14 +02001283 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte1af6ea82018-01-25 18:33:15 +01001284 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
Harald Welte6811d102019-04-14 22:23:14 +02001285 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001286 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001287 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001288 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001289 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001290 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001291 }
1292 setverdict(pass);
1293}
1294testcase TC_cl3_rnd_payload() runs on MTC_CT {
1295 var BSC_ConnHdlr vc_conn;
1296 f_init();
1297
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001298 vc_conn := f_start_handler(refers(f_tc_cl3_rnd_payload), 26);
Harald Welte1af6ea82018-01-25 18:33:15 +01001299 vc_conn.done;
1300}
1301
Harald Welte116e4332018-01-26 22:17:48 +01001302/* Test Complete L3 with random payload */
Harald Weltee13cfb22019-04-23 16:52:02 +02001303friend function f_tc_establish_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001304 f_init_handler(pars);
Harald Welte116e4332018-01-26 22:17:48 +01001305
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001306 f_perform_lu();
Harald Welte116e4332018-01-26 22:17:48 +01001307
Harald Welteb9e86fa2018-04-09 18:18:31 +02001308 f_establish_fully();
Daniel Willmann898a7e02018-05-17 12:16:16 +02001309 f_expect_clear(10.0);
Harald Welte116e4332018-01-26 22:17:48 +01001310}
1311testcase TC_establish_and_nothing() runs on MTC_CT {
1312 var BSC_ConnHdlr vc_conn;
1313 f_init();
1314
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001315 vc_conn := f_start_handler(refers(f_tc_establish_and_nothing), 27);
Harald Welte116e4332018-01-26 22:17:48 +01001316 vc_conn.done;
1317}
1318
Harald Weltee13cfb22019-04-23 16:52:02 +02001319
Harald Welte12510c52018-01-26 22:26:24 +01001320/* Test MO Call SETUP with no response from MNCC */
Harald Weltee13cfb22019-04-23 16:52:02 +02001321friend function f_tc_mo_setup_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier109e6aa2018-10-17 10:53:32 +02001322 f_init_handler(pars, 190.0);
Harald Weltea10db902018-01-27 12:44:49 +01001323
Harald Welte12510c52018-01-26 22:26:24 +01001324 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001325 cpars.mgw_conn_2.resp := 0;
1326 cpars.stop_after_cc_setup := true;
1327
1328 f_vty_config(MSCVTY, "msc", "mncc guard-timeout 20");
Harald Welte12510c52018-01-26 22:26:24 +01001329
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001330 f_perform_lu();
Harald Welte12510c52018-01-26 22:26:24 +01001331
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001332 f_mo_call_establish(cpars);
Harald Welte12510c52018-01-26 22:26:24 +01001333
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001334 var default ccrel := activate(as_optional_cc_rel(cpars));
1335
Philipp Maier109e6aa2018-10-17 10:53:32 +02001336 f_expect_clear(185.0);
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001337
1338 deactivate(ccrel);
1339
1340 f_sleep(1.0);
Harald Welte12510c52018-01-26 22:26:24 +01001341}
1342testcase TC_mo_setup_and_nothing() runs on MTC_CT {
1343 var BSC_ConnHdlr vc_conn;
1344 f_init();
1345
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001346 vc_conn := f_start_handler(refers(f_tc_mo_setup_and_nothing), 28);
Harald Welte12510c52018-01-26 22:26:24 +01001347 vc_conn.done;
1348}
1349
Harald Weltee13cfb22019-04-23 16:52:02 +02001350
Harald Welte3ab88002018-01-26 22:37:25 +01001351/* Test MO Call with no response to RAN-side CRCX */
Harald Weltee13cfb22019-04-23 16:52:02 +02001352friend function f_tc_mo_crcx_ran_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001353 f_init_handler(pars);
Harald Welte3ab88002018-01-26 22:37:25 +01001354 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1355 var MNCC_PDU mncc;
1356 var MgcpCommand mgcp_cmd;
1357
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001358 f_perform_lu();
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001359 /* Do not respond to the second CRCX */
1360 cpars.mgw_conn_2.resp := 0;
1361 f_mo_call_establish(cpars);
Harald Welte3ab88002018-01-26 22:37:25 +01001362
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001363 var default ccrel := activate(as_optional_cc_rel(cpars));
Harald Welte3ab88002018-01-26 22:37:25 +01001364
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001365 f_expect_clear(60.0);
Harald Welte3ab88002018-01-26 22:37:25 +01001366
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001367 deactivate(ccrel);
Harald Welte3ab88002018-01-26 22:37:25 +01001368}
1369testcase TC_mo_crcx_ran_timeout() runs on MTC_CT {
1370 var BSC_ConnHdlr vc_conn;
1371 f_init();
1372
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001373 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_timeout), 29);
Harald Welte3ab88002018-01-26 22:37:25 +01001374 vc_conn.done;
1375}
1376
Harald Weltee13cfb22019-04-23 16:52:02 +02001377
Harald Welte0cc82d92018-01-26 22:52:34 +01001378/* Test MO Call with reject to RAN-side CRCX */
Harald Weltee13cfb22019-04-23 16:52:02 +02001379friend function f_tc_mo_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001380 f_init_handler(pars);
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001381
Harald Welte0cc82d92018-01-26 22:52:34 +01001382 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001383
1384 /* Respond with error for the first CRCX */
1385 cpars.mgw_conn_1.resp := -1;
Harald Welte0cc82d92018-01-26 22:52:34 +01001386
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001387 f_perform_lu();
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001388 f_mo_call_establish(cpars);
Harald Welte0cc82d92018-01-26 22:52:34 +01001389
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001390 var default ccrel := activate(as_optional_cc_rel(cpars));
1391 f_expect_clear(60.0);
1392 deactivate(ccrel);
Harald Welte0cc82d92018-01-26 22:52:34 +01001393}
1394testcase TC_mo_crcx_ran_reject() runs on MTC_CT {
1395 var BSC_ConnHdlr vc_conn;
1396 f_init();
1397
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001398 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_reject), 30);
Harald Welte0cc82d92018-01-26 22:52:34 +01001399 vc_conn.done;
1400}
1401
Harald Welte3ab88002018-01-26 22:37:25 +01001402
Harald Welte812f7a42018-01-27 00:49:18 +01001403/* helper function to start a MT call: MNCC SETUP; Paging; DChan est.; DTAP SETUP */
1404private function f_mt_call_start(inout CallParameters cpars) runs on BSC_ConnHdlr {
1405 var MNCC_PDU mncc;
1406 var MgcpCommand mgcp_cmd;
Harald Welte812f7a42018-01-27 00:49:18 +01001407
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001408 f_perform_lu();
Vadim Yanitskiyae747742020-01-10 00:23:10 +01001409 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Welte812f7a42018-01-27 00:49:18 +01001410
1411 /* Allocate call reference and send SETUP via MNCC to MSC */
1412 cpars.mncc_callref := f_rnd_int(2147483648);
1413 MNCC.send(ts_MNCC_SETUP_req(cpars.mncc_callref, hex2str(g_pars.msisdn),
1414 hex2str(cpars.called_party), hex2str(g_pars.imsi)));
1415
1416 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02001417 f_expect_paging();
1418
Harald Welte812f7a42018-01-27 00:49:18 +01001419 /* MS -> MSC: PAGING RESPONSE */
Harald Welteb9e86fa2018-04-09 18:18:31 +02001420 f_establish_fully(EST_TYPE_PAG_RESP);
Harald Welte812f7a42018-01-27 00:49:18 +01001421
1422 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1423
1424 /* MSC->MS: SETUP */
1425 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_SETUP(cpars.transaction_id, *, cpars.called_party)));
1426}
1427
1428/* Test MT Call */
Harald Weltee13cfb22019-04-23 16:52:02 +02001429friend function f_tc_mt_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001430 f_init_handler(pars);
Harald Welte812f7a42018-01-27 00:49:18 +01001431 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1432 var MNCC_PDU mncc;
1433 var MgcpCommand mgcp_cmd;
1434
1435 f_mt_call_start(cpars);
1436
1437 /* MS->MSC: CALL CONFIRMED */
1438 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1439
1440 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1441
1442 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1443 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001444
1445 /* Detect if the received CRCX is a wildcarded CRCX request. If yes,
1446 * set an endpoint name that fits the pattern. If not, just use the
1447 * endpoint name from the request */
1448 if (match(mgcp_cmd.line.ep, t_MGCP_EP_wildcard)) {
1449 cpars.mgcp_ep := "rtpbridge/1@mgw";
1450 } else {
1451 cpars.mgcp_ep := mgcp_cmd.line.ep;
1452 }
1453
Harald Welte812f7a42018-01-27 00:49:18 +01001454 /* Respond to CRCX with error */
1455 var MgcpResponse mgcp_rsp := {
1456 line := {
1457 code := "542",
1458 trans_id := mgcp_cmd.line.trans_id,
1459 string := "FORCED_FAIL"
1460 },
Harald Welte812f7a42018-01-27 00:49:18 +01001461 sdp := omit
1462 }
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001463 var MgcpParameter mgcp_rsp_param := {
1464 code := "Z",
1465 val := cpars.mgcp_ep
1466 };
1467 mgcp_rsp.params[0] := mgcp_rsp_param;
Harald Welte812f7a42018-01-27 00:49:18 +01001468 MGCP.send(mgcp_rsp);
1469
1470 timer T := 30.0;
1471 T.start;
1472 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001473 [] T.timeout {
1474 setverdict(fail, "Timeout waiting for channel release");
1475 mtc.stop;
1476 }
Harald Welte812f7a42018-01-27 00:49:18 +01001477 [] MNCC.receive { repeat; }
1478 [] GSUP.receive { repeat; }
1479 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1480 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
1481 f_create_mgcp_delete_ep(cpars.mgcp_ep);
1482 repeat;
1483 }
1484 [] MGCP.receive { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001485 [] as_clear_cmd_compl_disc();
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001486 [] as_optional_cc_rel(cpars);
Harald Welte812f7a42018-01-27 00:49:18 +01001487 }
1488}
1489testcase TC_mt_crcx_ran_reject() runs on MTC_CT {
1490 var BSC_ConnHdlr vc_conn;
1491 f_init();
1492
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001493 vc_conn := f_start_handler(refers(f_tc_mt_crcx_ran_reject), 31);
Harald Welte812f7a42018-01-27 00:49:18 +01001494 vc_conn.done;
1495}
1496
1497
Harald Weltee13cfb22019-04-23 16:52:02 +02001498
Harald Welte812f7a42018-01-27 00:49:18 +01001499/* Test MT Call T310 timer */
Harald Weltee13cfb22019-04-23 16:52:02 +02001500friend function f_tc_mt_t310(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltead2952e2018-01-27 14:12:46 +01001501 f_init_handler(pars, 200.0);
Harald Welte812f7a42018-01-27 00:49:18 +01001502 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1503 var MNCC_PDU mncc;
1504 var MgcpCommand mgcp_cmd;
1505
1506 f_mt_call_start(cpars);
1507
1508 /* MS->MSC: CALL CONFIRMED */
1509 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1510 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1511
1512 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1513 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
1514 cpars.mgcp_ep := mgcp_cmd.line.ep;
1515 /* FIXME: Respond to CRCX */
1516
1517 /* old libosmocore T310 default timeout is 180s. so let's wait 190 */
1518 timer T := 190.0;
1519 T.start;
1520 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001521 [] T.timeout {
1522 setverdict(fail, "Timeout waiting for T310");
1523 mtc.stop;
1524 }
Harald Welte812f7a42018-01-27 00:49:18 +01001525 [] MNCC.receive(tr_MNCC_DISC_ind(cpars.mncc_callref)) {
1526 MNCC.send(ts_MNCC_REL_req(cpars.mncc_callref, valueof(ts_MNCC_cause(23))));
1527 }
1528 }
1529 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_DISC(cpars.transaction_id)));
1530 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id)));
1531 /* FIXME: We're sending this with TIflag 0: allocated by sender, which is wrong */
1532 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id)));
1533
1534 alt {
Harald Welte812f7a42018-01-27 00:49:18 +01001535 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1536 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
1537 f_create_mgcp_delete_ep(cpars.mgcp_ep);
1538 repeat;
1539 }
Harald Welte5946b332018-03-18 23:32:21 +01001540 [] as_clear_cmd_compl_disc();
Harald Welte812f7a42018-01-27 00:49:18 +01001541 }
1542}
1543testcase TC_mt_t310() runs on MTC_CT {
1544 var BSC_ConnHdlr vc_conn;
1545 f_init();
1546
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001547 vc_conn := f_start_handler(refers(f_tc_mt_t310), 32);
Harald Welte812f7a42018-01-27 00:49:18 +01001548 vc_conn.done;
1549}
1550
Harald Weltee13cfb22019-04-23 16:52:02 +02001551
Harald Welte167458a2018-01-27 15:58:16 +01001552/* Perform successful LU + MO call, then GSUP LocationCancel. Subscriber must be denied CM SERV */
Harald Weltee13cfb22019-04-23 16:52:02 +02001553friend function f_tc_gsup_cancel(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte167458a2018-01-27 15:58:16 +01001554 f_init_handler(pars);
1555 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Harald Welte167458a2018-01-27 15:58:16 +01001556
1557 /* Location Update to make subscriber known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001558 f_perform_lu();
Harald Welte167458a2018-01-27 15:58:16 +01001559
1560 /* First MO call should succeed */
1561 f_mo_call(cpars);
1562
1563 /* Cancel the subscriber in the VLR */
1564 GSUP.send(ts_GSUP_CL_REQ(g_pars.imsi, OSMO_GSUP_CANCEL_TYPE_WITHDRAW));
1565 alt {
1566 [] GSUP.receive(tr_GSUP_CL_RES(g_pars.imsi)) { }
1567 [] GSUP.receive(tr_GSUP_CL_ERR(g_pars.imsi)) {
1568 setverdict(fail, "Received GSUP Location Cancel Error");
Daniel Willmannafce8662018-07-06 23:11:32 +02001569 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001570 }
1571 }
1572
1573 /* Follow-up transactions should fail */
1574 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1575 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001576 f_cl3_or_initial_ue(l3_info);
Harald Welte167458a2018-01-27 15:58:16 +01001577 alt {
1578 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
1579 [] BSSAP.receive {
1580 setverdict(fail, "Received unexpected BSSAP instead of CM SERV REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +02001581 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001582 }
1583 }
Neels Hofmeyr0f7429a2019-03-07 22:28:41 +01001584
1585 f_expect_clear();
Harald Welte167458a2018-01-27 15:58:16 +01001586 setverdict(pass);
1587}
1588testcase TC_gsup_cancel() runs on MTC_CT {
1589 var BSC_ConnHdlr vc_conn;
1590 f_init();
1591
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001592 vc_conn := f_start_handler(refers(f_tc_gsup_cancel), 33, verify_cell_id := false);
Harald Welte167458a2018-01-27 15:58:16 +01001593 vc_conn.done;
1594}
1595
Harald Weltee13cfb22019-04-23 16:52:02 +02001596
Harald Welte9de84792018-01-28 01:06:35 +01001597/* A5/1 only permitted on network side, and MS capable to do it */
1598private function f_tc_lu_imsi_auth_tmsi_encr_1_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1599 pars.net.expect_auth := true;
1600 pars.net.expect_ciph := true;
1601 pars.net.kc_support := '02'O; /* A5/1 only */
1602 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001603 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001604}
1605testcase TC_lu_imsi_auth_tmsi_encr_1_13() runs on MTC_CT {
1606 var BSC_ConnHdlr vc_conn;
1607 f_init();
1608 f_vty_config(MSCVTY, "network", "authentication required");
1609 f_vty_config(MSCVTY, "network", "encryption a5 1");
1610
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001611 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_1_13), 34);
Harald Welte9de84792018-01-28 01:06:35 +01001612 vc_conn.done;
1613}
1614
1615/* A5/3 only permitted on network side, and MS capable to do it */
1616private function f_tc_lu_imsi_auth_tmsi_encr_3_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1617 pars.net.expect_auth := true;
1618 pars.net.expect_ciph := true;
1619 pars.net.kc_support := '08'O; /* A5/3 only */
1620 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001621 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001622}
1623testcase TC_lu_imsi_auth_tmsi_encr_3_13() runs on MTC_CT {
1624 var BSC_ConnHdlr vc_conn;
1625 f_init();
1626 f_vty_config(MSCVTY, "network", "authentication required");
1627 f_vty_config(MSCVTY, "network", "encryption a5 3");
1628
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001629 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_13), 35);
Harald Welte9de84792018-01-28 01:06:35 +01001630 vc_conn.done;
1631}
1632
1633/* A5/3 only permitted on network side, and MS with only A5/1 support */
1634private function f_tc_lu_imsi_auth_tmsi_encr_3_1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1635 pars.net.expect_auth := true;
1636 pars.net.expect_ciph := true;
1637 pars.net.kc_support := '08'O; /* A5/3 only */
1638 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1639 f_init_handler(pars, 15.0);
1640
1641 /* cannot use f_perform_lu() as we expect a reject */
1642 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
1643 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +02001644 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001645 if (pars.send_early_cm) {
1646 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1647 } else {
1648 pars.cm1.esind := '0'B;
1649 }
Harald Welte9de84792018-01-28 01:06:35 +01001650 f_mm_auth();
1651 alt {
Daniel Willmann52918e52018-09-20 14:39:09 +02001652 [] BSSAP.receive(tr_BSSMAP_ClassmarkReq) {
1653 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1654 repeat;
1655 }
Harald Welte5946b332018-03-18 23:32:21 +01001656 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1657 f_expect_clear();
1658 }
Harald Welte9de84792018-01-28 01:06:35 +01001659 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
1660 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02001661 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001662 }
1663 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01001664 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02001665 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001666 }
1667 }
1668 setverdict(pass);
1669}
1670testcase TC_lu_imsi_auth_tmsi_encr_3_1() runs on MTC_CT {
1671 var BSC_ConnHdlr vc_conn;
1672 f_init();
1673 f_vty_config(MSCVTY, "network", "authentication required");
1674 f_vty_config(MSCVTY, "network", "encryption a5 3");
1675
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001676 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 360, verify_cell_id := false);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001677 vc_conn.done;
1678}
1679testcase TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() runs on MTC_CT {
1680 var BSC_ConnHdlrPars pars;
1681 var BSC_ConnHdlr vc_conn;
1682 f_init();
1683 f_vty_config(MSCVTY, "network", "authentication required");
1684 f_vty_config(MSCVTY, "network", "encryption a5 3");
1685
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001686 pars := f_init_pars(361, verify_cell_id := false);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001687 pars.send_early_cm := false;
1688 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), pars);
Harald Welte9de84792018-01-28 01:06:35 +01001689 vc_conn.done;
1690}
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01001691testcase TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() runs on MTC_CT {
1692 var BSC_ConnHdlr vc_conn;
1693 f_init();
1694 f_vty_config(MSCVTY, "network", "authentication required");
1695 f_vty_config(MSCVTY, "network", "encryption a5 3");
1696
1697 /* Make sure the MSC category is on DEBUG level to trigger the log
1698 * message that is reported in OS#2947 to trigger the segfault */
1699 f_vty_config(MSCVTY, "log stderr", "logging level msc debug");
1700
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001701 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 362, verify_cell_id := false);
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01001702 vc_conn.done;
1703}
Harald Welte9de84792018-01-28 01:06:35 +01001704
1705/* A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
1706private function f_tc_lu_imsi_auth_tmsi_encr_13_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1707 pars.net.expect_auth := true;
1708 pars.net.expect_ciph := true;
1709 pars.net.kc_support := '0A'O; /* A5/1 + A5/3 */
1710 pars.cm1.a5_1 := '1'B;
1711 pars.cm2.a5_1 := '1'B;
1712 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1713 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
1714 f_init_handler(pars, 15.0);
1715
1716 /* cannot use f_perform_lu() as we expect a reject */
1717 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
1718 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +02001719 f_cl3_or_initial_ue(l3_lu);
Harald Welte9de84792018-01-28 01:06:35 +01001720 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1721 f_mm_auth();
1722 alt {
Harald Welte5946b332018-03-18 23:32:21 +01001723 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1724 f_expect_clear();
1725 }
Harald Welte9de84792018-01-28 01:06:35 +01001726 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
1727 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02001728 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001729 }
1730 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01001731 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02001732 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001733 }
1734 }
1735 setverdict(pass);
1736}
1737testcase TC_lu_imsi_auth_tmsi_encr_13_2() runs on MTC_CT {
1738 var BSC_ConnHdlr vc_conn;
1739 f_init();
1740 f_vty_config(MSCVTY, "network", "authentication required");
1741 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
1742
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001743 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_2), 37, verify_cell_id := false);
Harald Welte9de84792018-01-28 01:06:35 +01001744 vc_conn.done;
1745}
1746
1747/* A5/0 + A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
1748private function f_tc_lu_imsi_auth_tmsi_encr_013_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1749 pars.net.expect_auth := true;
1750 pars.net.expect_ciph := true;
1751 pars.net.kc_support := '0B'O; /* A5/1 + A5/3 */
1752 pars.cm1.a5_1 := '1'B;
1753 pars.cm2.a5_1 := '1'B;
1754 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1755 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
1756 f_init_handler(pars, 15.0);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001757 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001758}
1759testcase TC_lu_imsi_auth_tmsi_encr_013_2() runs on MTC_CT {
1760 var BSC_ConnHdlr vc_conn;
1761 f_init();
1762 f_vty_config(MSCVTY, "network", "authentication required");
1763 f_vty_config(MSCVTY, "network", "encryption a5 0 1 3");
1764
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001765 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_013_2), 38);
Harald Welte9de84792018-01-28 01:06:35 +01001766 vc_conn.done;
1767}
1768
Harald Welte33ec09b2018-02-10 15:34:46 +01001769/* LU followed by MT call (including paging) */
Neels Hofmeyr8fe8a902019-11-03 05:51:03 +01001770friend function f_tc_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte33ec09b2018-02-10 15:34:46 +01001771 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01001772 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02001773 cpars.use_osmux := pars.use_osmux;
Harald Welte33ec09b2018-02-10 15:34:46 +01001774
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001775 f_perform_lu();
Harald Welte33ec09b2018-02-10 15:34:46 +01001776 f_mt_call(cpars);
1777}
1778testcase TC_lu_and_mt_call() runs on MTC_CT {
1779 var BSC_ConnHdlr vc_conn;
1780 f_init();
1781
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001782 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call), 39);
Harald Welte33ec09b2018-02-10 15:34:46 +01001783 vc_conn.done;
1784}
1785
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02001786testcase TC_lu_and_mt_call_osmux() runs on MTC_CT {
1787 var BSC_ConnHdlr vc_conn;
1788 f_init(1, false, true, true);
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02001789
1790 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call), 39, 0, true, true);
1791 vc_conn.done;
1792}
1793
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01001794/* MT call while already Paging */
1795friend function f_tc_lu_and_mt_call_already_paging(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1796 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1797 var SmsParameters spars := valueof(t_SmsPars);
1798 var OCT4 tmsi;
1799
1800 f_init_handler(pars);
1801
1802 /* Perform location update */
1803 f_perform_lu();
1804
1805 /* register an 'expect' for given IMSI (+TMSI) */
1806 if (isvalue(g_pars.tmsi)) {
1807 tmsi := g_pars.tmsi;
1808 } else {
1809 tmsi := 'FFFFFFFF'O;
1810 }
1811 f_ran_register_imsi(g_pars.imsi, tmsi);
1812
1813 log("start Paging by an SMS");
1814 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
1815
1816 /* MSC->BSC: expect PAGING from MSC */
1817 f_expect_paging();
1818
1819 log("MNCC signals MT call, before Paging Response");
1820 f_mt_call_initate(cpars);
1821 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
1822
1823 f_sleep(0.5);
1824 log("phone answers Paging, expecting both SMS and MT call to be established");
1825 f_establish_fully(EST_TYPE_PAG_RESP);
1826 spars.tp.ud := 'C8329BFD064D9B53'O;
1827 interleave {
1828 [] BSSAP.receive(f_mt_sms_deliver_pdu(spars)) {
1829 log("Got SMS-DELIVER");
1830 };
1831 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_SETUP(cpars.transaction_id, *, cpars.called_party))) {
1832 log("Got CC Setup");
1833 };
1834 }
1835 setverdict(pass);
1836 log("success, tear down");
1837 var default ccrel := activate(as_optional_cc_rel(cpars));
1838 if (g_pars.ran_is_geran) {
1839 BSSAP.send(ts_BSSMAP_ClearRequest(0));
1840 } else {
1841 BSSAP.send(ts_RANAP_IuReleaseRequest(ts_RanapCause_om_intervention));
1842 }
1843 f_expect_clear();
1844 deactivate(ccrel);
1845 f_vty_sms_clear(hex2str(g_pars.imsi));
1846}
1847testcase TC_lu_and_mt_call_already_paging() runs on MTC_CT {
1848 var BSC_ConnHdlrPars pars;
1849 var BSC_ConnHdlr vc_conn;
1850 f_init();
1851 pars := f_init_pars(391);
1852 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_call_already_paging), pars);
1853 vc_conn.done;
1854}
1855
Daniel Willmann8b084372018-02-04 13:35:26 +01001856/* Test MO Call SETUP with DTMF */
1857private function f_tc_mo_setup_dtmf_dup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1858 f_init_handler(pars);
1859 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Daniel Willmann8b084372018-02-04 13:35:26 +01001860
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001861 f_perform_lu();
Daniel Willmann8b084372018-02-04 13:35:26 +01001862 f_mo_seq_dtmf_dup(cpars);
1863}
1864testcase TC_mo_setup_and_dtmf_dup() runs on MTC_CT {
1865 var BSC_ConnHdlr vc_conn;
1866 f_init();
1867
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001868 vc_conn := f_start_handler(refers(f_tc_mo_setup_dtmf_dup), 39);
Daniel Willmann8b084372018-02-04 13:35:26 +01001869 vc_conn.done;
1870}
Harald Welte9de84792018-01-28 01:06:35 +01001871
Philipp Maier328d1662018-03-07 10:40:27 +01001872testcase TC_cr_before_reset() runs on MTC_CT {
1873 timer T := 4.0;
1874 var boolean reset_ack_seen := false;
1875 f_init_bssap_direct();
1876
Harald Welte3ca0ce12019-04-23 17:18:48 +02001877 f_ran_adapter_start(g_bssap[0]);
Daniel Willmann42d1d5b2018-08-07 15:18:41 +02001878
Daniel Willmanne8018962018-08-21 14:18:00 +02001879 f_sleep(3.0);
1880
Philipp Maier328d1662018-03-07 10:40:27 +01001881 /* Make a blind connection attemt, to trigger the deadlock condition */
Philipp Maier75932982018-03-27 14:52:35 +02001882 BSSAP_DIRECT.send(ts_BSSAP_CONNECT_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, 1, omit));
Philipp Maier328d1662018-03-07 10:40:27 +01001883
1884 /* Send a BSSMAP reset */
Philipp Maier75932982018-03-27 14:52:35 +02001885 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_Reset(0)));
Philipp Maier328d1662018-03-07 10:40:27 +01001886 T.start
1887 alt {
1888 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_ResetAck)) {
1889 reset_ack_seen := true;
1890 repeat;
1891 }
1892
1893 /* Acknowledge MSC sided reset requests */
1894 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_Reset)) {
Philipp Maier75932982018-03-27 14:52:35 +02001895 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_ResetAck));
Philipp Maier328d1662018-03-07 10:40:27 +01001896 repeat;
1897 }
1898
1899 /* Ignore all other messages (e.g CR from the connection request) */
1900 [] BSSAP_DIRECT.receive { repeat }
1901
1902 /* If we got no BSSMAP RESET ACK back, then the MSC entered the
1903 * deadlock situation. The MSC is then unable to respond to any
1904 * further BSSMAP RESET or any other sort of traffic. */
1905 [reset_ack_seen == true] T.timeout { setverdict(pass) }
1906 [reset_ack_seen == false] T.timeout {
1907 setverdict(fail, "no BSSMAP RESET ACK seen!");
Daniel Willmannafce8662018-07-06 23:11:32 +02001908 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +01001909 }
Pau Espin Pedrol7e9178d2019-12-17 17:52:17 +01001910 }
Philipp Maier328d1662018-03-07 10:40:27 +01001911}
Harald Welte9de84792018-01-28 01:06:35 +01001912
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001913/* Test MO Call with no response to RAN-side CRCX or DTAP Release */
Harald Weltee13cfb22019-04-23 16:52:02 +02001914friend function f_tc_mo_release_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001915 f_init_handler(pars);
1916 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1917 var MNCC_PDU mncc;
1918 var MgcpCommand mgcp_cmd;
1919
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001920 /* Do not respond to the second CRCX */
1921 cpars.mgw_conn_2.resp := 0;
1922
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001923 f_perform_lu();
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001924 f_mo_call_establish(cpars);
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001925
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001926 var default ccrel := activate(as_optional_cc_rel(cpars));
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001927
1928 f_expect_clear(60.0);
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001929
1930 deactivate(ccrel);
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001931}
1932testcase TC_mo_release_timeout() runs on MTC_CT {
1933 var BSC_ConnHdlr vc_conn;
1934 f_init();
1935
1936 vc_conn := f_start_handler(refers(f_tc_mo_release_timeout), 40);
1937 vc_conn.done;
1938}
1939
Harald Welte12510c52018-01-26 22:26:24 +01001940
Philipp Maier2a98a732018-03-19 16:06:12 +01001941/* LU followed by MT call (including paging) */
1942private function f_tc_lu_and_mt_call_no_dlcx_resp(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1943 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01001944 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Philipp Maier2a98a732018-03-19 16:06:12 +01001945
1946 /* Intentionally disable the CRCX response */
1947 cpars.mgw_drop_dlcx := true;
1948
1949 /* Perform location update and call */
1950 f_perform_lu();
1951 f_mt_call(cpars);
1952}
1953testcase TC_lu_and_mt_call_no_dlcx_resp() runs on MTC_CT {
1954 var BSC_ConnHdlr vc_conn;
1955 f_init();
1956
1957 /* Perform an almost normal looking locationupdate + mt-call, but do
1958 * not respond to the DLCX at the end of the call */
1959 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call_no_dlcx_resp), 41);
1960 vc_conn.done;
1961
1962 /* Wait a guard period until the MGCP layer in the MSC times out,
1963 * if the MSC is vulnerable to the use-after-free situation that is
1964 * fixed by I78f1b6a9149488a4ad3f120c1e190a83c07d4b89 then it should
1965 * segfault now */
1966 f_sleep(6.0);
1967
1968 /* Run the init procedures once more. If the MSC has crashed, this
1969 * this will fail */
1970 f_init();
1971}
Harald Welte45164da2018-01-24 12:51:27 +01001972
Philipp Maier75932982018-03-27 14:52:35 +02001973/* Two BSSMAP resets from two different BSCs */
1974testcase TC_reset_two() runs on MTC_CT {
1975 var BSC_ConnHdlr vc_conn;
1976 f_init(2);
1977 f_sleep(2.0);
1978 setverdict(pass);
1979}
1980
Harald Weltee13cfb22019-04-23 16:52:02 +02001981/* Two BSSMAP resets from two different BSCs plus one IuCS RANAP Reset */
1982testcase TC_reset_two_1iu() runs on MTC_CT {
1983 var BSC_ConnHdlr vc_conn;
1984 f_init(3);
1985 f_sleep(2.0);
1986 setverdict(pass);
1987}
1988
Harald Weltef640a012018-04-14 17:49:21 +02001989/***********************************************************************
1990 * SMS Testing
1991 ***********************************************************************/
1992
Harald Weltef45efeb2018-04-09 18:19:24 +02001993/* LU followed by MO SMS */
Harald Weltee13cfb22019-04-23 16:52:02 +02001994friend function f_tc_lu_and_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02001995 var SmsParameters spars := valueof(t_SmsPars);
1996
1997 f_init_handler(pars);
1998
1999 /* Perform location update and call */
2000 f_perform_lu();
2001
2002 f_establish_fully(EST_TYPE_MO_SMS);
2003
2004 //spars.exp_rp_err := 96; /* invalid mandatory information */
2005 f_mo_sms(spars);
2006
2007 f_expect_clear();
2008}
2009testcase TC_lu_and_mo_sms() runs on MTC_CT {
2010 var BSC_ConnHdlr vc_conn;
2011 f_init();
2012 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_sms), 42);
2013 vc_conn.done;
2014}
2015
Harald Weltee13cfb22019-04-23 16:52:02 +02002016
Harald Weltef45efeb2018-04-09 18:19:24 +02002017private function f_vty_sms_send(charstring imsi, charstring msisdn, charstring text)
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002018runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02002019 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
2020}
2021
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01002022/* Remove still pending SMS */
2023private function f_vty_sms_clear(charstring imsi)
2024runs on BSC_ConnHdlr {
2025 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " sms delete-all");
2026 f_vty_transceive(MSCVTY, "sms-queue clear");
2027}
2028
Harald Weltef45efeb2018-04-09 18:19:24 +02002029/* LU followed by MT SMS */
Harald Weltee13cfb22019-04-23 16:52:02 +02002030friend function f_tc_lu_and_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02002031 var SmsParameters spars := valueof(t_SmsPars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002032
2033 f_init_handler(pars);
2034
2035 /* Perform location update and call */
2036 f_perform_lu();
2037
2038 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002039 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Weltef45efeb2018-04-09 18:19:24 +02002040
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002041 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
Harald Weltef45efeb2018-04-09 18:19:24 +02002042
2043 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02002044 f_expect_paging();
2045
Harald Weltef45efeb2018-04-09 18:19:24 +02002046 /* Establish DTAP / BSSAP / SCCP connection */
2047 f_establish_fully(EST_TYPE_PAG_RESP);
2048
2049 spars.tp.ud := 'C8329BFD064D9B53'O;
2050 f_mt_sms(spars);
2051
2052 f_expect_clear();
2053}
2054testcase TC_lu_and_mt_sms() runs on MTC_CT {
2055 var BSC_ConnHdlrPars pars;
2056 var BSC_ConnHdlr vc_conn;
2057 f_init();
2058 pars := f_init_pars(43);
2059 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms), pars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002060 vc_conn.done;
2061}
2062
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01002063/* SMS added while already Paging */
2064friend function f_tc_lu_and_mt_sms_already_paging(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2065 var SmsParameters spars := valueof(t_SmsPars);
2066 var OCT4 tmsi;
2067
2068 f_init_handler(pars);
2069
2070 f_perform_lu();
2071
2072 /* register an 'expect' for given IMSI (+TMSI) */
2073 if (isvalue(g_pars.tmsi)) {
2074 tmsi := g_pars.tmsi;
2075 } else {
2076 tmsi := 'FFFFFFFF'O;
2077 }
2078 f_ran_register_imsi(g_pars.imsi, tmsi);
2079
2080 log("first SMS");
2081 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2082
2083 /* MSC->BSC: expect PAGING from MSC */
2084 f_expect_paging();
2085
2086 log("second SMS");
2087 /* Now osmo-msc is in state "Paging pending", make sure that another SMS to be sent at this time just joins in
2088 * with the pending paging. Another SMS: */
2089 f_vty_sms_send(hex2str(pars.imsi), "2342", "Another SMS");
2090
2091 /* Establish DTAP / BSSAP / SCCP connection */
2092 f_establish_fully(EST_TYPE_PAG_RESP);
2093
2094 spars.tp.ud := 'C8329BFD064D9B53'O;
2095 f_mt_sms(spars);
2096
2097 spars.tp.ud := '41F79B8E2ECB41D3E614'O;
2098 f_mt_sms(spars);
2099
2100 f_expect_clear();
2101}
2102testcase TC_lu_and_mt_sms_already_paging() runs on MTC_CT {
2103 var BSC_ConnHdlrPars pars;
2104 var BSC_ConnHdlr vc_conn;
2105 f_init();
2106 pars := f_init_pars(44);
2107 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_already_paging), pars);
2108 vc_conn.done;
2109}
Harald Weltee13cfb22019-04-23 16:52:02 +02002110
Philipp Maier3983e702018-11-22 19:01:33 +01002111/* Paging for MT SMS but no response */
Harald Weltee13cfb22019-04-23 16:52:02 +02002112friend function f_tc_lu_and_mt_sms_paging_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier3983e702018-11-22 19:01:33 +01002113 var SmsParameters spars := valueof(t_SmsPars);
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002114
Philipp Maier3983e702018-11-22 19:01:33 +01002115 f_init_handler(pars, 150.0);
2116
2117 /* Perform location update */
2118 f_perform_lu();
2119
2120 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002121 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Philipp Maier3983e702018-11-22 19:01:33 +01002122
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002123 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2124
Neels Hofmeyr16237742019-03-06 15:34:01 +01002125 /* Expect the MSC to page exactly once */
Harald Weltee13cfb22019-04-23 16:52:02 +02002126 f_expect_paging();
Philipp Maier3983e702018-11-22 19:01:33 +01002127
2128 /* Wait some time to make sure the MSC is not delivering any further
2129 * paging messages or anything else that could be unexpected. */
2130 timer T := 20.0;
2131 T.start
2132 alt {
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002133 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
2134 setverdict(fail, "paging seems not to stop!");
2135 mtc.stop;
Philipp Maier3983e702018-11-22 19:01:33 +01002136 }
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002137 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
2138 setverdict(fail, "paging seems not to stop!");
2139 mtc.stop;
Harald Weltee13cfb22019-04-23 16:52:02 +02002140 }
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002141 [] BSSAP.receive {
2142 setverdict(fail, "unexpected BSSAP message received");
2143 self.stop;
Philipp Maier3983e702018-11-22 19:01:33 +01002144 }
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002145 [] T.timeout {
2146 setverdict(pass);
Philipp Maier3983e702018-11-22 19:01:33 +01002147 }
2148 }
2149
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01002150 f_vty_sms_clear(hex2str(g_pars.imsi));
2151
Philipp Maier3983e702018-11-22 19:01:33 +01002152 setverdict(pass);
2153}
2154testcase TC_lu_and_mt_sms_paging_and_nothing() runs on MTC_CT {
2155 var BSC_ConnHdlrPars pars;
2156 var BSC_ConnHdlr vc_conn;
2157 f_init();
Philipp Maiera99ad262019-01-22 15:35:42 +01002158 pars := f_init_pars(1843);
Philipp Maier3983e702018-11-22 19:01:33 +01002159 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_paging_and_nothing), pars);
Philipp Maier3983e702018-11-22 19:01:33 +01002160 vc_conn.done;
2161}
2162
Alexander Couzensfc02f242019-09-12 03:43:18 +02002163/* LU followed by MT SMS with repeated paging */
2164friend function f_tc_lu_and_mt_sms_paging_repeated(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2165 var SmsParameters spars := valueof(t_SmsPars);
Alexander Couzensfc02f242019-09-12 03:43:18 +02002166
2167 f_init_handler(pars);
2168
2169 /* Perform location update and call */
2170 f_perform_lu();
2171
2172 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002173 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Alexander Couzensfc02f242019-09-12 03:43:18 +02002174
2175 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2176
Neels Hofmeyrc3accec2019-11-28 01:09:47 +01002177 log("Expecting first Paging");
Alexander Couzensfc02f242019-09-12 03:43:18 +02002178 /* MSC->BSC: expect PAGING from MSC */
2179 f_expect_paging();
2180
Neels Hofmeyrc3accec2019-11-28 01:09:47 +01002181 if (g_pars.ran_is_geran) {
2182 log("GERAN: expect no further Paging");
2183 } else {
2184 log("UTRAN: expect more Paging");
2185 }
2186
2187 timer T := 5.0;
2188 T.start;
2189 alt {
2190 [g_pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
2191 setverdict(fail, "GERAN should not repeat Paging, but received a second Paging");
2192 mtc.stop;
2193 }
2194 [not g_pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
2195 log("UTRAN: second Paging received, as expected");
2196 setverdict(pass);
2197 }
2198 [] T.timeout {
2199 if (g_pars.ran_is_geran) {
2200 log("GERAN: No further Paging received, as expected");
2201 setverdict(pass);
2202 } else {
2203 setverdict(fail, "UTRAN: Expected a second Paging");
2204 mtc.stop;
2205 }
2206 }
2207 }
Alexander Couzensfc02f242019-09-12 03:43:18 +02002208
2209 /* Establish DTAP / BSSAP / SCCP connection */
2210 f_establish_fully(EST_TYPE_PAG_RESP);
2211
2212 spars.tp.ud := 'C8329BFD064D9B53'O;
2213 f_mt_sms(spars);
2214
2215 f_expect_clear();
2216}
2217testcase TC_lu_and_mt_sms_paging_repeated() runs on MTC_CT {
2218 var BSC_ConnHdlrPars pars;
2219 var BSC_ConnHdlr vc_conn;
2220 f_init();
2221 pars := f_init_pars(1844);
2222 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_paging_repeated), pars);
2223 vc_conn.done;
2224}
Harald Weltee13cfb22019-04-23 16:52:02 +02002225
Harald Weltef640a012018-04-14 17:49:21 +02002226/* mobile originated SMS from MS/BTS/BSC side to SMPP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002227friend function f_tc_smpp_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef640a012018-04-14 17:49:21 +02002228 var SmsParameters spars := valueof(t_SmsPars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002229
Harald Weltef640a012018-04-14 17:49:21 +02002230 f_init_handler(pars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002231
Harald Weltef640a012018-04-14 17:49:21 +02002232 /* Perform location update so IMSI is known + registered in MSC/VLR */
2233 f_perform_lu();
Harald Weltef640a012018-04-14 17:49:21 +02002234
Vadim Yanitskiy2d3f8462020-01-15 11:44:12 +07002235 /* MS/UE submits a MO SMS */
2236 f_establish_fully(EST_TYPE_MO_SMS);
2237 f_mo_sms_submit(spars);
Harald Weltef640a012018-04-14 17:49:21 +02002238
2239 var SMPP_PDU smpp;
2240 var template SMPP_PDU tr_smpp := tr_SMPP(c_SMPP_command_id_deliver_sm, ESME_ROK);
2241 tr_smpp.body.deliver_sm := {
2242 service_type := "CMT",
2243 source_addr_ton := network_specific,
2244 source_addr_npi := isdn,
2245 source_addr := hex2str(pars.msisdn),
2246 dest_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
2247 dest_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
2248 destination_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
2249 esm_class := '00000001'B,
2250 protocol_id := 0,
2251 priority_flag := 0,
2252 schedule_delivery_time := "",
2253 replace_if_present := 0,
2254 data_coding := '00000001'B,
2255 sm_default_msg_id := 0,
2256 sm_length := ?,
2257 short_message := spars.tp.ud,
2258 opt_pars := {
2259 {
2260 tag := user_message_reference,
2261 len := 2,
2262 opt_value := {
2263 int2_val := oct2int(spars.tp.msg_ref)
2264 }
2265 }
2266 }
2267 };
2268 alt {
2269 [] SMPP.receive(tr_smpp) -> value smpp {
2270 SMPP.send(ts_SMPP_DELIVER_SM_resp(ESME_ROK, smpp.header.seq_num));
2271 }
2272 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK)) { repeat; }
2273 }
2274
Vadim Yanitskiy2d3f8462020-01-15 11:44:12 +07002275 /* MSC terminates the SMS transaction with RP-ACK */
2276 f_mo_sms_wait_rp_ack(spars);
2277
Harald Weltef640a012018-04-14 17:49:21 +02002278 f_expect_clear();
2279}
2280testcase TC_smpp_mo_sms() runs on MTC_CT {
2281 var BSC_ConnHdlr vc_conn;
2282 f_init();
2283 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "default-route");
2284 vc_conn := f_start_handler(refers(f_tc_smpp_mo_sms), 44);
2285 vc_conn.done;
2286 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "no default-route");
2287}
2288
Vadim Yanitskiy33820762020-01-15 11:26:07 +07002289/* Test case for OS#4351: make sure that RP-ERROR from ESME is properly sent to the MS/UE */
2290friend function f_tc_smpp_mo_sms_rp_error(charstring id, BSC_ConnHdlrPars pars)
2291runs on BSC_ConnHdlr {
2292 var SmsParameters spars := valueof(t_SmsPars);
2293 var SMPP_PDU smpp_pdu;
2294 timer T := 3.0;
2295
2296 f_init_handler(pars);
2297
2298 /* Perform location update */
2299 f_perform_lu();
2300
2301 /* MS/UE submits a MO SMS */
2302 f_establish_fully(EST_TYPE_MO_SMS);
2303 f_mo_sms_submit(spars);
2304
2305 /* ESME responds with an error (Invalid Destination Address) */
2306 T.start;
2307 alt {
2308 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_deliver_sm, ESME_ROK, body := ?)) -> value smpp_pdu {
2309 SMPP.send(ts_SMPP_DELIVER_SM_resp(ESME_RINVDSTADR, smpp_pdu.header.seq_num));
2310 }
2311 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK)) { repeat; }
2312 [] T.timeout {
2313 setverdict(fail, "Timeout waiting for SMPP DELIVER-SM");
2314 mtc.stop;
2315 }
2316 }
2317
2318 /* Expect RP-ERROR on BSSAP interface */
2319 spars.exp_rp_err := 1; /* FIXME: GSM411_RP_CAUSE_MO_NUM_UNASSIGNED */
2320 f_mo_sms_wait_rp_ack(spars);
2321
2322 f_expect_clear();
2323}
2324testcase TC_smpp_mo_sms_rp_error() runs on MTC_CT {
2325 var BSC_ConnHdlr vc_conn;
2326 f_init();
2327 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "default-route");
2328 vc_conn := f_start_handler(refers(f_tc_smpp_mo_sms_rp_error), 45);
2329 vc_conn.done;
2330 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "no default-route");
2331}
2332
Harald Weltee13cfb22019-04-23 16:52:02 +02002333
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002334/* Test MO-SMS from MS/BTS/BSC towards HLR (via GSUP) */
Harald Weltee13cfb22019-04-23 16:52:02 +02002335friend function f_tc_gsup_mo_sms(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002336runs on BSC_ConnHdlr {
2337 var SmsParameters spars := valueof(t_SmsPars);
2338 var GSUP_PDU gsup_msg_rx;
2339 var octetstring sm_tpdu;
2340
2341 f_init_handler(pars);
2342
2343 /* We need to inspect GSUP activity */
2344 f_create_gsup_expect(hex2str(g_pars.imsi));
2345
2346 /* Perform location update */
2347 f_perform_lu();
2348
2349 /* Send CM Service Request for SMS */
2350 f_establish_fully(EST_TYPE_MO_SMS);
2351
2352 /* Prepare expected SM-RP-UI (SM TPDU) */
2353 enc_TPDU_RP_DATA_MS_SGSN_fast(
2354 valueof(ts_SMS_SUBMIT(spars.tp.msg_ref,
2355 spars.tp.da, spars.tp.pid, spars.tp.dcs,
2356 spars.tp.udl, spars.tp.ud)),
2357 sm_tpdu);
2358
2359 var template GSUP_PDU mo_forwardSM := tr_GSUP_MO_FORWARD_SM_REQ(
2360 imsi := g_pars.imsi,
2361 sm_rp_mr := spars.rp.msg_ref,
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09002362 /* SM-RP-DA: SMSC address */
2363 sm_rp_da := tr_GSUP_SM_RP_DA_SMSC_ADDR(t_GSUP_SM_RP_Addr(
2364 number := spars.rp.smsc_addr.rP_NumberDigits,
2365 npi := spars.rp.smsc_addr.rP_NumberingPlanIdentification,
2366 ton := spars.rp.smsc_addr.rP_TypeOfNumber,
2367 ext := spars.rp.smsc_addr.rP_Ext)),
2368 /* SM-RP-OA: subscriber's MSISDN (filled in by MSC) */
2369 sm_rp_oa := tr_GSUP_SM_RP_OA_MSISDN(t_GSUP_SM_RP_Addr(
2370 number := g_pars.msisdn,
2371 /* NOTE: MSISDN in g_pars lacks this info, assuming defaults */
2372 npi := '0001'B, ton := '001'B, ext := '1'B)),
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002373 /* TODO: can we use decmatch here? */
2374 sm_rp_ui := sm_tpdu
2375 );
2376
2377 /* Submit an SMS on DTAP and expect MO-forwardSM-Req on GSUP */
2378 f_mo_sms_submit(spars);
2379 alt {
2380 [] GSUP.receive(mo_forwardSM) -> value gsup_msg_rx {
Vadim Yanitskiya358dd42020-01-15 10:42:47 +07002381 log("RX MO-forwardSM-Req: ", gsup_msg_rx);
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002382 setverdict(pass);
2383 }
2384 [] GSUP.receive {
2385 log("RX unexpected GSUP message");
2386 setverdict(fail);
2387 mtc.stop;
2388 }
2389 }
2390
2391 /* Trigger RP-ACK by sending MO-forwardSM-Res */
2392 GSUP.send(valueof(ts_GSUP_MO_FORWARD_SM_RES(
2393 imsi := g_pars.imsi,
2394 sm_rp_mr := spars.rp.msg_ref)));
2395 /* Expect RP-ACK on DTAP */
2396 f_mo_sms_wait_rp_ack(spars);
2397
2398 f_expect_clear();
2399}
2400testcase TC_gsup_mo_sms() runs on MTC_CT {
2401 var BSC_ConnHdlr vc_conn;
2402 f_init();
2403 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2404 vc_conn := f_start_handler(refers(f_tc_gsup_mo_sms), 88);
2405 vc_conn.done;
2406 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2407}
2408
Harald Weltee13cfb22019-04-23 16:52:02 +02002409
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002410/* Test MO-SMMA from MS/BTS/BSC towards HLR (via GSUP) */
Harald Weltee13cfb22019-04-23 16:52:02 +02002411friend function f_tc_gsup_mo_smma(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002412runs on BSC_ConnHdlr {
2413 var SmsParameters spars := valueof(t_SmsPars);
2414 var GSUP_PDU gsup_msg_rx;
2415
2416 f_init_handler(pars);
2417
2418 /* We need to inspect GSUP activity */
2419 f_create_gsup_expect(hex2str(g_pars.imsi));
2420
2421 /* Perform location update */
2422 f_perform_lu();
2423
2424 /* Send CM Service Request for SMS */
2425 f_establish_fully(EST_TYPE_MO_SMS);
2426
2427 var template GSUP_PDU mo_ReadyForSM := tr_GSUP_MO_READY_FOR_SM_REQ(
2428 imsi := g_pars.imsi,
2429 sm_rp_mr := spars.rp.msg_ref,
2430 sm_alert_rsn := GSUP_SM_ALERT_RSN_TYPE_MEM_AVAIL
2431 );
2432
2433 /* Submit an SMS on DTAP and expect MO-forwardSM-Req on GSUP */
2434 f_mo_smma(spars);
2435 alt {
2436 [] GSUP.receive(mo_ReadyForSM) -> value gsup_msg_rx {
Vadim Yanitskiya358dd42020-01-15 10:42:47 +07002437 log("RX MO-ReadyForSM-Req: ", gsup_msg_rx);
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002438 setverdict(pass);
2439 }
2440 [] GSUP.receive {
2441 log("RX unexpected GSUP message");
2442 setverdict(fail);
2443 mtc.stop;
2444 }
2445 }
2446
2447 /* Trigger RP-ACK by sending MO-forwardSM-Res */
2448 GSUP.send(valueof(ts_GSUP_MO_READY_FOR_SM_RES(
2449 imsi := g_pars.imsi,
2450 sm_rp_mr := spars.rp.msg_ref)));
2451 /* Expect RP-ACK on DTAP */
2452 f_mo_sms_wait_rp_ack(spars);
2453
2454 f_expect_clear();
2455}
2456testcase TC_gsup_mo_smma() runs on MTC_CT {
2457 var BSC_ConnHdlr vc_conn;
2458 f_init();
2459 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2460 vc_conn := f_start_handler(refers(f_tc_gsup_mo_smma), 89);
2461 vc_conn.done;
2462 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2463}
2464
Harald Weltee13cfb22019-04-23 16:52:02 +02002465
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002466/* Helper for sending MT SMS over GSUP */
2467private function f_gsup_forwardSM_req(SmsParameters spars, OCT1 mms := '00'O)
2468runs on BSC_ConnHdlr {
Vadim Yanitskiya52347c2019-12-12 17:32:33 +09002469 var GSUP_SM_RP_Addr msisdn := valueof(t_GSUP_SM_RP_Addr(g_pars.msisdn));
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09002470 var GSUP_SM_RP_Addr smsc := valueof(t_GSUP_SM_RP_Addr(
2471 number := spars.rp.smsc_addr.rP_NumberDigits,
2472 npi := spars.rp.smsc_addr.rP_NumberingPlanIdentification,
2473 ton := spars.rp.smsc_addr.rP_TypeOfNumber,
2474 ext := spars.rp.smsc_addr.rP_Ext));
Vadim Yanitskiya52347c2019-12-12 17:32:33 +09002475
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002476 GSUP.send(ts_GSUP_MT_FORWARD_SM_REQ(
2477 imsi := g_pars.imsi,
2478 /* NOTE: MSC should assign RP-MR itself */
2479 sm_rp_mr := 'FF'O,
Vadim Yanitskiya52347c2019-12-12 17:32:33 +09002480 sm_rp_da := valueof(ts_GSUP_SM_RP_DA_MSISDN(msisdn)),
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09002481 sm_rp_oa := valueof(ts_GSUP_SM_RP_OA_SMSC_ADDR(smsc)),
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002482 /* Encoded SMS TPDU (taken from Wireshark)
2483 * FIXME: we should encode spars somehow */
2484 sm_rp_ui := '00068021436500008111328130858200'O,
2485 sm_rp_mms := mms
2486 ));
2487}
2488
2489/* Test successful MT-SMS (RP-ACK) over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002490friend function f_tc_gsup_mt_sms_ack(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002491runs on BSC_ConnHdlr {
2492 var SmsParameters spars := valueof(t_SmsPars);
2493
2494 f_init_handler(pars);
2495
2496 /* We need to inspect GSUP activity */
2497 f_create_gsup_expect(hex2str(g_pars.imsi));
2498
2499 /* Perform location update */
2500 f_perform_lu();
2501
2502 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002503 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002504
2505 var template GSUP_PDU mt_forwardSM_res := tr_GSUP_MT_FORWARD_SM_RES(
2506 imsi := g_pars.imsi,
2507 /* NOTE: MSC should assign RP-MR itself */
2508 sm_rp_mr := ?
2509 );
2510
2511 /* Submit a MT SMS on GSUP */
2512 f_gsup_forwardSM_req(spars);
2513
2514 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002515 f_expect_paging();
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002516 f_establish_fully(EST_TYPE_PAG_RESP);
2517
2518 /* Wait for MT SMS on DTAP */
2519 f_mt_sms_expect(spars);
2520
2521 /* Send RP-ACK and expect MT-forwardSM-Res on GSUP */
2522 f_mt_sms_send_rp_ack(spars);
2523 alt {
2524 [] GSUP.receive(mt_forwardSM_res) {
2525 log("RX MT-forwardSM-Res (RP-ACK)");
2526 setverdict(pass);
2527 }
2528 [] GSUP.receive {
2529 log("RX unexpected GSUP message");
2530 setverdict(fail);
2531 mtc.stop;
2532 }
2533 }
2534
2535 f_expect_clear();
2536}
2537testcase TC_gsup_mt_sms_ack() runs on MTC_CT {
2538 var BSC_ConnHdlrPars pars;
2539 var BSC_ConnHdlr vc_conn;
2540 f_init();
2541 pars := f_init_pars(90);
2542 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2543 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_ack), pars);
2544 vc_conn.done;
2545 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2546}
2547
Harald Weltee13cfb22019-04-23 16:52:02 +02002548
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002549/* Test rejected MT-SMS (RP-ERROR) over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002550friend function f_tc_gsup_mt_sms_err(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002551runs on BSC_ConnHdlr {
2552 var SmsParameters spars := valueof(t_SmsPars);
2553 var OCT1 sm_rp_cause := '78'O; /* dummy RP-Cause value */
2554
2555 f_init_handler(pars);
2556
2557 /* We need to inspect GSUP activity */
2558 f_create_gsup_expect(hex2str(g_pars.imsi));
2559
2560 /* Perform location update */
2561 f_perform_lu();
2562
2563 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002564 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002565
2566 var template GSUP_PDU mt_forwardSM_err := tr_GSUP_MT_FORWARD_SM_ERR(
2567 imsi := g_pars.imsi,
2568 /* NOTE: MSC should assign RP-MR itself */
2569 sm_rp_mr := ?,
2570 sm_rp_cause := sm_rp_cause
2571 );
2572
2573 /* Submit a MT SMS on GSUP */
2574 f_gsup_forwardSM_req(spars);
2575
2576 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002577 f_expect_paging();
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002578 f_establish_fully(EST_TYPE_PAG_RESP);
2579
2580 /* Wait for MT SMS on DTAP */
2581 f_mt_sms_expect(spars);
2582
2583 /* Send RP-ERROR and expect MT-forwardSM-Err on GSUP */
2584 f_mt_sms_send_rp_error(spars, oct2int(sm_rp_cause));
2585 alt {
2586 [] GSUP.receive(mt_forwardSM_err) {
2587 log("RX MT-forwardSM-Err (RP-ERROR)");
2588 setverdict(pass);
2589 mtc.stop;
2590 }
2591 [] GSUP.receive {
2592 log("RX unexpected GSUP message");
2593 setverdict(fail);
2594 mtc.stop;
2595 }
2596 }
2597
2598 f_expect_clear();
2599}
2600testcase TC_gsup_mt_sms_err() runs on MTC_CT {
2601 var BSC_ConnHdlrPars pars;
2602 var BSC_ConnHdlr vc_conn;
2603 f_init();
2604 pars := f_init_pars(91);
2605 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2606 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_err), pars);
2607 vc_conn.done;
2608 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2609}
2610
Harald Weltee13cfb22019-04-23 16:52:02 +02002611
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002612/* Test SM-RP-MR assignment for MT-SMS over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002613friend function f_tc_gsup_mt_sms_rp_mr(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002614runs on BSC_ConnHdlr {
2615 var SmsParameters spars1 := valueof(t_SmsPars); /* 1st SMS */
2616 var SmsParameters spars2 := valueof(t_SmsPars); /* 2nd SMS */
2617
2618 f_init_handler(pars);
2619
2620 /* We need to inspect GSUP activity */
2621 f_create_gsup_expect(hex2str(g_pars.imsi));
2622
2623 /* Perform location update */
2624 f_perform_lu();
2625
2626 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002627 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002628
2629 /* Submit the 1st MT SMS on GSUP */
2630 log("TX MT-forwardSM-Req for the 1st SMS");
2631 f_gsup_forwardSM_req(spars1);
2632
2633 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002634 f_expect_paging();
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002635 f_establish_fully(EST_TYPE_PAG_RESP);
2636
2637 /* Wait for 1st MT SMS on DTAP */
2638 f_mt_sms_expect(spars1);
2639 log("RX the 1st SMS on DTAP, DTAP TID is ", spars1.tid,
2640 ", SM-RP-MR is ", spars1.rp.msg_ref);
2641
2642 /* Submit the 2nd MT SMS on GSUP */
2643 log("TX MT-forwardSM-Req for the 2nd SMS");
2644 f_gsup_forwardSM_req(spars2);
2645
2646 /* Wait for 2nd MT SMS on DTAP */
2647 f_mt_sms_expect(spars2);
2648 log("RX the 2nd SMS on DTAP, DTAP TID is ", spars2.tid,
2649 ", SM-RP-MR is ", spars2.rp.msg_ref);
2650
2651 /* Both transaction IDs shall be different */
2652 if (spars1.tid == spars2.tid) {
2653 log("Both DTAP transaction IDs shall be different");
2654 setverdict(fail);
2655 }
2656
2657 /* Both SM-RP-MR values shall be different */
2658 if (spars1.rp.msg_ref == spars2.rp.msg_ref) {
2659 log("Both SM-RP-MR values shall be different");
2660 setverdict(fail);
2661 }
2662
2663 /* Both SM-RP-MR values shall be assigned */
2664 if (spars1.rp.msg_ref == 'FF'O) {
2665 log("Unassigned SM-RP-MR value for the 1st SMS");
2666 setverdict(fail);
2667 }
2668 if (spars2.rp.msg_ref == 'FF'O) {
2669 log("Unassigned SM-RP-MR value for the 2nd SMS");
2670 setverdict(fail);
2671 }
2672
2673 /* Send the 1st RP-ACK and expect MT-forwardSM-Res on GSUP */
2674 f_mt_sms_send_rp_ack(spars1);
2675 alt {
2676 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2677 imsi := g_pars.imsi,
2678 sm_rp_mr := spars1.rp.msg_ref
2679 )) {
2680 log("RX MT-forwardSM-Res (RP-ACK)");
2681 setverdict(pass);
2682 }
2683 [] GSUP.receive {
2684 log("RX unexpected GSUP message");
2685 setverdict(fail);
2686 mtc.stop;
2687 }
2688 }
2689
2690 /* Send the 2nd RP-ACK and expect MT-forwardSM-Res on GSUP */
2691 f_mt_sms_send_rp_ack(spars2);
2692 alt {
2693 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2694 imsi := g_pars.imsi,
2695 sm_rp_mr := spars2.rp.msg_ref
2696 )) {
2697 log("RX MT-forwardSM-Res (RP-ACK)");
2698 setverdict(pass);
2699 }
2700 [] GSUP.receive {
2701 log("RX unexpected GSUP message");
2702 setverdict(fail);
2703 mtc.stop;
2704 }
2705 }
2706
2707 f_expect_clear();
2708}
2709testcase TC_gsup_mt_sms_rp_mr() runs on MTC_CT {
2710 var BSC_ConnHdlrPars pars;
2711 var BSC_ConnHdlr vc_conn;
2712 f_init();
2713 pars := f_init_pars(92);
2714 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2715 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_rp_mr), pars);
2716 vc_conn.done;
2717 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2718}
2719
Harald Weltee13cfb22019-04-23 16:52:02 +02002720
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07002721/* Test SM-RP-MR assignment for MT-SMS over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002722friend function f_tc_gsup_mo_mt_sms_rp_mr(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07002723runs on BSC_ConnHdlr {
2724 var SmsParameters spars_mo := valueof(t_SmsPars); /* MO SMMA */
2725 var SmsParameters spars_mt := valueof(t_SmsPars); /* MT SMS */
2726
2727 f_init_handler(pars);
2728
2729 /* We need to inspect GSUP activity */
2730 f_create_gsup_expect(hex2str(g_pars.imsi));
2731
2732 /* Perform location update */
2733 f_perform_lu();
2734
2735 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002736 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07002737
2738 /* Send CM Service Request for MO SMMA */
2739 f_establish_fully(EST_TYPE_MO_SMS);
2740
2741 /* Submit MO SMMA on DTAP */
2742 log("Submit MO SMMA on DTAP, SM-RP-MR is '00'O");
2743 spars_mo.rp.msg_ref := '00'O;
2744 f_mo_smma(spars_mo);
2745
2746 /* Expect MO-forwardSM-Req for MO SMMA on GSUP */
2747 alt {
2748 [] GSUP.receive(tr_GSUP_MO_READY_FOR_SM_REQ(
2749 imsi := g_pars.imsi,
2750 sm_rp_mr := spars_mo.rp.msg_ref,
2751 sm_alert_rsn := GSUP_SM_ALERT_RSN_TYPE_MEM_AVAIL
2752 )) {
2753 log("RX MO-ReadyForSM-Req, SM-RP-MR is '00'O");
2754 setverdict(pass);
2755 }
2756 [] GSUP.receive {
2757 log("RX unexpected GSUP message");
2758 setverdict(fail);
2759 mtc.stop;
2760 }
2761 }
2762
2763 /* Submit MT SMS on GSUP */
2764 log("TX MT-forwardSM-Req for the MT SMS");
2765 f_gsup_forwardSM_req(spars_mt);
2766
2767 /* Wait for MT SMS on DTAP */
2768 f_mt_sms_expect(spars_mt);
2769 log("RX MT SMS on DTAP, DTAP TID is ", spars_mt.tid,
2770 ", SM-RP-MR is ", spars_mt.rp.msg_ref);
2771
2772 /* Both SM-RP-MR values shall be different */
2773 if (spars_mo.rp.msg_ref == spars_mt.rp.msg_ref) {
2774 log("Both SM-RP-MR values shall be different");
2775 setverdict(fail);
2776 }
2777
2778 /* SM-RP-MR value for MT SMS shall be assigned */
2779 if (spars_mt.rp.msg_ref == 'FF'O) {
2780 log("Unassigned SM-RP-MR value for the MT SMS");
2781 setverdict(fail);
2782 }
2783
2784 /* Trigger RP-ACK for MO SMMA by sending MO-forwardSM-Res */
2785 GSUP.send(valueof(ts_GSUP_MO_READY_FOR_SM_RES(
2786 imsi := g_pars.imsi,
2787 sm_rp_mr := spars_mo.rp.msg_ref)));
2788 /* Expect RP-ACK for MO SMMA on DTAP */
2789 f_mo_sms_wait_rp_ack(spars_mo);
2790
2791 /* Send RP-ACK for MT SMS and expect MT-forwardSM-Res on GSUP */
2792 f_mt_sms_send_rp_ack(spars_mt);
2793 alt {
2794 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2795 imsi := g_pars.imsi,
2796 sm_rp_mr := spars_mt.rp.msg_ref
2797 )) {
2798 log("RX MT-forwardSM-Res (RP-ACK)");
2799 setverdict(pass);
2800 }
2801 [] GSUP.receive {
2802 log("RX unexpected GSUP message");
2803 setverdict(fail);
2804 mtc.stop;
2805 }
2806 }
2807
2808 f_expect_clear();
2809}
2810testcase TC_gsup_mo_mt_sms_rp_mr() runs on MTC_CT {
2811 var BSC_ConnHdlrPars pars;
2812 var BSC_ConnHdlr vc_conn;
2813 f_init();
2814 pars := f_init_pars(93);
2815 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2816 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mo_mt_sms_rp_mr), pars);
2817 vc_conn.done;
2818 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2819}
2820
Harald Weltee13cfb22019-04-23 16:52:02 +02002821
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07002822/* Test multi-part MT-SMS over GSUP */
2823private function f_tc_gsup_mt_multi_part_sms(charstring id, BSC_ConnHdlrPars pars)
2824runs on BSC_ConnHdlr {
2825 var SmsParameters spars := valueof(t_SmsPars);
2826
2827 f_init_handler(pars);
2828
2829 /* We need to inspect GSUP activity */
2830 f_create_gsup_expect(hex2str(g_pars.imsi));
2831
2832 /* Perform location update */
2833 f_perform_lu();
2834
2835 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002836 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07002837
2838 var template GSUP_PDU mt_forwardSM_res := tr_GSUP_MT_FORWARD_SM_RES(
2839 imsi := g_pars.imsi,
2840 /* NOTE: MSC should assign RP-MR itself */
2841 sm_rp_mr := ?
2842 );
2843
2844 /* Send 4 messages (NOTE: SM-RP-UI remains unchanged) */
2845 for (var integer i := 3; i >= 0; i := i-1) {
2846 /* Submit a MT SMS on GSUP (MMS is decremented) */
2847 f_gsup_forwardSM_req(spars, int2oct(i, 1));
2848
2849 /* Expect Paging Request and Establish connection */
2850 if (i == 3) { /* ... only once! */
Harald Weltee13cfb22019-04-23 16:52:02 +02002851 f_expect_paging();
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07002852 f_establish_fully(EST_TYPE_PAG_RESP);
2853 }
2854
2855 /* Wait for MT SMS on DTAP */
2856 f_mt_sms_expect(spars);
2857
2858 /* Send RP-ACK and expect MT-forwardSM-Res on GSUP */
2859 f_mt_sms_send_rp_ack(spars);
2860 alt {
2861 [] GSUP.receive(mt_forwardSM_res) {
2862 log("RX MT-forwardSM-Res (RP-ACK)");
2863 setverdict(pass);
2864 }
2865 [] GSUP.receive {
2866 log("RX unexpected GSUP message");
2867 setverdict(fail);
2868 mtc.stop;
2869 }
2870 }
2871
2872 /* Keep some 'distance' between transmissions */
2873 f_sleep(1.5);
2874 }
2875
2876 f_expect_clear();
2877}
2878testcase TC_gsup_mt_multi_part_sms() runs on MTC_CT {
2879 var BSC_ConnHdlrPars pars;
2880 var BSC_ConnHdlr vc_conn;
2881 f_init();
2882 pars := f_init_pars(91);
2883 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2884 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_multi_part_sms), pars);
2885 vc_conn.done;
2886 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2887}
2888
Harald Weltef640a012018-04-14 17:49:21 +02002889/* convert GSM L3 TON to SMPP_TON enum */
2890function f_sm_ton_from_gsm(BIT3 ton) return SMPP_TON {
2891 select (ton) {
2892 case ('000'B) { return unknown; }
2893 case ('001'B) { return international; }
2894 case ('010'B) { return national; }
2895 case ('011'B) { return network_specific; }
2896 case ('100'B) { return subscriber_number; }
2897 case ('101'B) { return alphanumeric; }
2898 case ('110'B) { return abbreviated; }
2899 }
2900 setverdict(fail, "Unknown TON ", ton);
Daniel Willmannafce8662018-07-06 23:11:32 +02002901 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02002902}
2903/* convert GSM L3 NPI to SMPP_NPI enum */
2904function f_sm_npi_from_gsm(BIT4 npi) return SMPP_NPI {
2905 select (npi) {
2906 case ('0000'B) { return unknown; }
2907 case ('0001'B) { return isdn; }
2908 case ('0011'B) { return data; }
2909 case ('0100'B) { return telex; }
2910 case ('0110'B) { return land_mobile; }
2911 case ('1000'B) { return national; }
2912 case ('1001'B) { return private_; }
2913 case ('1010'B) { return ermes; }
2914 }
2915 setverdict(fail, "Unknown NPI ", npi);
Daniel Willmannafce8662018-07-06 23:11:32 +02002916 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02002917}
2918
2919/* build a SMPP_SM from SmsParameters */
2920function f_mt_sm_from_spars(SmsParameters spars)
2921runs on BSC_ConnHdlr return SMPP_SM {
2922 var SMPP_SM sm := {
2923 service_type := "CMT",
2924 source_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
2925 source_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
2926 source_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
2927 dest_addr_ton := international,
2928 dest_addr_npi := isdn,
2929 destination_addr := hex2str(g_pars.msisdn),
2930 esm_class := '00000001'B,
2931 protocol_id := 0,
2932 priority_flag := 0,
2933 schedule_delivery_time := "",
2934 validity_period := "",
2935 registered_delivery := '00000000'B,
2936 replace_if_present := 0,
2937 data_coding := '00000001'B,
2938 sm_default_msg_id := 0,
2939 sm_length := spars.tp.udl,
2940 short_message := spars.tp.ud,
2941 opt_pars := {}
2942 };
2943 return sm;
2944}
2945
2946/* helper function to encode SMS from 'spars', send it via SMPP to MSC; receive it on MS side */
2947private function f_smpp_mt_sms(SmsParameters spars, boolean trans_mode) runs on BSC_ConnHdlr {
2948 var SMPP_SM sm := f_mt_sm_from_spars(spars);
2949 if (trans_mode) {
2950 sm.esm_class := '00000010'B;
2951 }
2952
2953 /* actually cause MSC to send a SMS via SUBMIT-SM from SMPP side */
2954 SMPP.send(ts_SMPP_SUBMIT_SM(sm));
2955 if (not match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
2956 /* if we're not in SMPP transaction mode, we expect the SMPP-level ACK
2957 * before we expect the SMS delivery on the BSC/radio side */
2958 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
2959 }
2960
2961 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02002962 f_expect_paging();
Harald Weltef640a012018-04-14 17:49:21 +02002963 /* Establish DTAP / BSSAP / SCCP connection */
2964 f_establish_fully(EST_TYPE_PAG_RESP);
2965 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
2966
2967 f_mt_sms(spars);
2968
2969 if (match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
2970 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
2971 }
2972 f_expect_clear();
2973}
2974
2975/* mobile terminated SMS, from SMPP to BSC/BTS/MS */
2976private function f_tc_smpp_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2977 f_init_handler(pars);
2978
2979 /* Perform location update so IMSI is known + registered in MSC/VLR */
2980 f_perform_lu();
2981 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
2982
2983 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002984 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Weltef640a012018-04-14 17:49:21 +02002985
2986 var SmsParameters spars := valueof(t_SmsPars);
2987 /* TODO: test with more intelligent user data; test different coding schemes */
2988 spars.tp.ud := '00'O;
2989 spars.tp.udl := 1;
2990
2991 /* first test the non-transaction store+forward mode */
2992 f_smpp_mt_sms(spars, false);
2993
2994 /* then test the transaction mode */
2995 f_smpp_mt_sms(spars, true);
2996}
2997testcase TC_smpp_mt_sms() runs on MTC_CT {
2998 var BSC_ConnHdlr vc_conn;
2999 f_init();
3000 vc_conn := f_start_handler(refers(f_tc_smpp_mt_sms), 45);
3001 vc_conn.done;
3002}
3003
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003004/***********************************************************************
3005 * USSD Testing
3006 ***********************************************************************/
3007
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003008private altstep as_unexp_gsup_or_bssap_msg()
3009runs on BSC_ConnHdlr {
3010 [] GSUP.receive {
3011 setverdict(fail, "Unknown/unexpected GSUP received");
3012 self.stop;
3013 }
3014 [] BSSAP.receive {
3015 setverdict(fail, "Unknown/unexpected BSSAP message received");
3016 self.stop;
3017 }
3018}
3019
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003020private function f_expect_gsup_msg(template GSUP_PDU msg,
3021 float T_val := 2.0)
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003022runs on BSC_ConnHdlr return GSUP_PDU {
3023 var GSUP_PDU gsup_msg_complete;
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003024 timer T := T_val;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003025
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003026 T.start;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003027 alt {
3028 [] GSUP.receive(msg) -> value gsup_msg_complete {
3029 setverdict(pass);
3030 }
3031 /* We don't expect anything else */
3032 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003033 [] T.timeout {
3034 setverdict(fail, "Timeout waiting for GSUP message: ", msg);
3035 }
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003036 }
3037
3038 return gsup_msg_complete;
3039}
3040
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003041private function f_expect_mt_dtap_msg(template PDU_ML3_NW_MS msg,
3042 float T_val := 2.0)
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003043runs on BSC_ConnHdlr return PDU_ML3_NW_MS {
3044 var PDU_DTAP_MT bssap_msg_complete;
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003045 timer T := T_val;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003046
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003047 T.start;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003048 alt {
3049 [] BSSAP.receive(tr_PDU_DTAP_MT(msg)) -> value bssap_msg_complete {
3050 setverdict(pass);
3051 }
3052 /* We don't expect anything else */
3053 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003054 [] T.timeout {
3055 setverdict(fail, "Timeout waiting for BSSAP message: ", msg);
3056 }
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003057 }
3058
3059 return bssap_msg_complete.dtap;
3060}
3061
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003062/* LU followed by MO USSD request */
Harald Weltee13cfb22019-04-23 16:52:02 +02003063friend function f_tc_lu_and_mo_ussd_single_request(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003064runs on BSC_ConnHdlr {
3065 f_init_handler(pars);
3066
3067 /* Perform location update */
3068 f_perform_lu();
3069
3070 /* Send CM Service Request for SS/USSD */
3071 f_establish_fully(EST_TYPE_SS_ACT);
3072
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003073 /* We need to inspect GSUP activity */
3074 f_create_gsup_expect(hex2str(g_pars.imsi));
3075
3076 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3077 invoke_id := 5, /* Phone may not start from 0 or 1 */
3078 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3079 ussd_string := "*#100#"
3080 );
3081
3082 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3083 invoke_id := 5, /* InvokeID shall be the same for both REQ and RSP */
3084 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3085 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
3086 )
3087
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003088 /* Compose a new SS/REGISTER message with request */
3089 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
3090 tid := 1, /* We just need a single transaction */
3091 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003092 facility := valueof(facility_req)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003093 );
3094
3095 /* Compose SS/RELEASE_COMPLETE template with expected response */
3096 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
3097 tid := 1, /* Response should arrive within the same transaction */
3098 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003099 facility := valueof(facility_rsp)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003100 );
3101
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003102 /* Compose expected MSC -> HLR message */
3103 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
3104 imsi := g_pars.imsi,
3105 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3106 ss := valueof(facility_req)
3107 );
3108
3109 /* To be used for sending response with correct session ID */
3110 var GSUP_PDU gsup_req_complete;
3111
3112 /* Request own number */
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003113 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003114 /* Expect GSUP message containing the SS payload */
3115 gsup_req_complete := f_expect_gsup_msg(gsup_req);
3116
3117 /* Compose the response from HLR using received session ID */
3118 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
3119 imsi := g_pars.imsi,
3120 sid := gsup_req_complete.ies[1].val.session_id,
3121 state := OSMO_GSUP_SESSION_STATE_END,
3122 ss := valueof(facility_rsp)
3123 );
3124
3125 /* Finally, HLR terminates the session */
3126 GSUP.send(gsup_rsp);
3127 /* Expect RELEASE_COMPLETE message with the response */
3128 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003129
3130 f_expect_clear();
3131}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003132testcase TC_lu_and_mo_ussd_single_request() runs on MTC_CT {
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003133 var BSC_ConnHdlr vc_conn;
3134 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003135 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_single_request), 46);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003136 vc_conn.done;
3137}
3138
Harald Weltee13cfb22019-04-23 16:52:02 +02003139
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003140/* LU followed by MT USSD notification */
Harald Weltee13cfb22019-04-23 16:52:02 +02003141friend function f_tc_lu_and_mt_ussd_notification(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003142runs on BSC_ConnHdlr {
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003143 timer T := 5.0;
3144
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003145 f_init_handler(pars);
3146
3147 /* Perform location update */
3148 f_perform_lu();
3149
Harald Welte6811d102019-04-14 22:23:14 +02003150 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003151
3152 /* We need to inspect GSUP activity */
3153 f_create_gsup_expect(hex2str(g_pars.imsi));
3154
3155 /* Facility IE with network-originated USSD notification */
3156 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3157 op_code := SS_OP_CODE_USS_NOTIFY,
3158 ussd_string := "Mahlzeit!"
3159 );
3160
3161 /* Facility IE with acknowledgment to the USSD notification */
3162 var template OCTN facility_rsp := enc_SS_FacilityInformation(
3163 /* In case of USSD notification, Return Result is empty */
3164 valueof(ts_SS_USSD_FACILITY_RETURN_RESULT_EMPTY())
3165 );
3166
3167 /* Compose a new MT SS/REGISTER message with USSD notification */
3168 var template PDU_ML3_NW_MS ussd_ntf := tr_ML3_MT_SS_REGISTER(
3169 tid := 0, /* FIXME: most likely, it should be 0 */
3170 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3171 facility := valueof(facility_req)
3172 );
3173
3174 /* Compose HLR -> MSC GSUP message */
3175 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3176 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003177 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003178 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3179 ss := valueof(facility_req)
3180 );
3181
3182 /* Send it to MSC and expect Paging Request */
3183 GSUP.send(gsup_req);
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003184 T.start;
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003185 alt {
Harald Weltee13cfb22019-04-23 16:52:02 +02003186 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
3187 setverdict(pass);
3188 }
Harald Welte62113fc2019-05-09 13:04:02 +02003189 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003190 setverdict(pass);
3191 }
3192 /* We don't expect anything else */
3193 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003194 [] T.timeout {
3195 setverdict(fail, "Timeout waiting for Paging Request");
3196 }
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003197 }
3198
3199 /* Send Paging Response and expect USSD notification */
3200 f_establish_fully(EST_TYPE_PAG_RESP);
3201 /* Expect MT REGISTER message with USSD notification */
3202 f_expect_mt_dtap_msg(ussd_ntf);
3203
3204 /* Compose a new MO SS/FACILITY message with empty response */
3205 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
3206 tid := 0, /* FIXME: it shall match the request tid */
3207 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3208 facility := valueof(facility_rsp)
3209 );
3210
3211 /* Compose expected MSC -> HLR GSUP message */
3212 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
3213 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003214 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003215 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3216 ss := valueof(facility_rsp)
3217 );
3218
3219 /* MS sends response to the notification */
3220 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
3221 /* Expect GSUP message containing the SS payload */
3222 f_expect_gsup_msg(gsup_rsp);
3223
3224 /* Compose expected MT SS/RELEASE COMPLETE message */
3225 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
3226 tid := 0, /* FIXME: it shall match the request tid */
3227 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3228 facility := omit
3229 );
3230
3231 /* Compose MSC -> HLR GSUP message */
3232 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
3233 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003234 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003235 state := OSMO_GSUP_SESSION_STATE_END
3236 );
3237
3238 /* Finally, HLR terminates the session */
3239 GSUP.send(gsup_term)
3240 /* Expect MT RELEASE COMPLETE without Facility IE */
3241 f_expect_mt_dtap_msg(ussd_term);
3242
3243 f_expect_clear();
3244}
3245testcase TC_lu_and_mt_ussd_notification() runs on MTC_CT {
3246 var BSC_ConnHdlr vc_conn;
3247 f_init();
3248 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_notification), 47);
3249 vc_conn.done;
3250}
3251
Harald Weltee13cfb22019-04-23 16:52:02 +02003252
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003253/* LU followed by MT call and MO USSD request during this call */
Harald Weltee13cfb22019-04-23 16:52:02 +02003254friend function f_tc_lu_and_mo_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003255runs on BSC_ConnHdlr {
3256 f_init_handler(pars);
3257
3258 /* Call parameters taken from f_tc_lu_and_mt_call */
3259 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003260
3261 /* Perform location update */
3262 f_perform_lu();
3263
3264 /* Establish a MT call */
3265 f_mt_call_establish(cpars);
3266
3267 /* Hold the call for some time */
3268 f_sleep(1.0);
3269
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003270 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3271 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3272 ussd_string := "*#100#"
3273 );
3274
3275 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3276 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3277 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
3278 )
3279
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003280 /* Compose a new SS/REGISTER message with request */
3281 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
3282 tid := 1, /* We just need a single transaction */
3283 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003284 facility := valueof(facility_req)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003285 );
3286
3287 /* Compose SS/RELEASE_COMPLETE template with expected response */
3288 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
3289 tid := 1, /* Response should arrive within the same transaction */
3290 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003291 facility := valueof(facility_rsp)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003292 );
3293
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003294 /* Compose expected MSC -> HLR message */
3295 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
3296 imsi := g_pars.imsi,
3297 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3298 ss := valueof(facility_req)
3299 );
3300
3301 /* To be used for sending response with correct session ID */
3302 var GSUP_PDU gsup_req_complete;
3303
3304 /* Request own number */
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003305 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003306 /* Expect GSUP message containing the SS payload */
3307 gsup_req_complete := f_expect_gsup_msg(gsup_req);
3308
3309 /* Compose the response from HLR using received session ID */
3310 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
3311 imsi := g_pars.imsi,
3312 sid := gsup_req_complete.ies[1].val.session_id,
3313 state := OSMO_GSUP_SESSION_STATE_END,
3314 ss := valueof(facility_rsp)
3315 );
3316
3317 /* Finally, HLR terminates the session */
3318 GSUP.send(gsup_rsp);
3319 /* Expect RELEASE_COMPLETE message with the response */
3320 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003321
3322 /* Hold the call for some time */
3323 f_sleep(1.0);
3324
3325 /* Release the call (does Clear Complete itself) */
3326 f_call_hangup(cpars, true);
3327}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003328testcase TC_lu_and_mo_ussd_during_mt_call() runs on MTC_CT {
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003329 var BSC_ConnHdlr vc_conn;
3330 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003331 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_during_mt_call), 48);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003332 vc_conn.done;
3333}
3334
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003335/* BSSMAP Clear Request in the middle of a call, see OS#3062 */
Harald Weltee13cfb22019-04-23 16:52:02 +02003336friend function f_tc_mo_cc_bssmap_clear(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003337 f_init_handler(pars);
3338 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02003339 cpars.ran_clear_when_alerting := true;
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003340
3341 f_perform_lu();
3342
Neels Hofmeyrde76f052019-02-26 05:02:46 +01003343 var default ccrel := activate(as_optional_cc_rel(cpars));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02003344 f_mo_call_establish(cpars);
3345 f_expect_clear()
Neels Hofmeyrde76f052019-02-26 05:02:46 +01003346 deactivate(ccrel);
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003347
3348 f_sleep(1.0);
3349}
3350testcase TC_mo_cc_bssmap_clear() runs on MTC_CT {
3351 var BSC_ConnHdlr vc_conn;
3352 f_init();
3353
3354 vc_conn := f_start_handler(refers(f_tc_mo_cc_bssmap_clear), 43);
3355 vc_conn.done;
3356}
3357
Harald Weltee13cfb22019-04-23 16:52:02 +02003358
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003359/* LU followed by MT call and MT USSD request during this call */
Harald Weltee13cfb22019-04-23 16:52:02 +02003360friend function f_tc_lu_and_mt_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003361runs on BSC_ConnHdlr {
3362 f_init_handler(pars);
3363
3364 /* Call parameters taken from f_tc_lu_and_mt_call */
3365 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003366
3367 /* Perform location update */
3368 f_perform_lu();
3369
3370 /* Establish a MT call */
3371 f_mt_call_establish(cpars);
3372
3373 /* Hold the call for some time */
3374 f_sleep(1.0);
3375
3376 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3377 op_code := SS_OP_CODE_USS_REQUEST,
3378 ussd_string := "Please type anything..."
3379 );
3380
3381 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3382 op_code := SS_OP_CODE_USS_REQUEST,
3383 ussd_string := "Nope."
3384 )
3385
3386 /* Compose MT SS/REGISTER message with network-originated request */
3387 var template (value) PDU_ML3_NW_MS ussd_req := ts_ML3_MT_SS_REGISTER(
3388 tid := 0, /* FIXME: most likely, it should be 0 */
3389 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3390 facility := valueof(facility_req)
3391 );
3392
3393 /* Compose HLR -> MSC GSUP message */
3394 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3395 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003396 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003397 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3398 ss := valueof(facility_req)
3399 );
3400
3401 /* Send it to MSC */
3402 GSUP.send(gsup_req);
3403 /* Expect MT REGISTER message with USSD request */
3404 f_expect_mt_dtap_msg(ussd_req);
3405
3406 /* Compose a new MO SS/FACILITY message with response */
3407 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
3408 tid := 0, /* FIXME: it shall match the request tid */
3409 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3410 facility := valueof(facility_rsp)
3411 );
3412
3413 /* Compose expected MSC -> HLR GSUP message */
3414 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
3415 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003416 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003417 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3418 ss := valueof(facility_rsp)
3419 );
3420
3421 /* MS sends response */
3422 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
3423 f_expect_gsup_msg(gsup_rsp);
3424
3425 /* Compose expected MT SS/RELEASE COMPLETE message */
3426 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
3427 tid := 0, /* FIXME: it shall match the request tid */
3428 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3429 facility := omit
3430 );
3431
3432 /* Compose MSC -> HLR GSUP message */
3433 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
3434 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003435 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003436 state := OSMO_GSUP_SESSION_STATE_END
3437 );
3438
3439 /* Finally, HLR terminates the session */
3440 GSUP.send(gsup_term);
3441 /* Expect MT RELEASE COMPLETE without Facility IE */
3442 f_expect_mt_dtap_msg(ussd_term);
3443
3444 /* Hold the call for some time */
3445 f_sleep(1.0);
3446
3447 /* Release the call (does Clear Complete itself) */
3448 f_call_hangup(cpars, true);
3449}
3450testcase TC_lu_and_mt_ussd_during_mt_call() runs on MTC_CT {
3451 var BSC_ConnHdlr vc_conn;
3452 f_init();
3453 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_during_mt_call), 49);
3454 vc_conn.done;
3455}
3456
Harald Weltee13cfb22019-04-23 16:52:02 +02003457
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07003458/* LU followed by MO USSD request and MO Release during transaction */
Harald Weltee13cfb22019-04-23 16:52:02 +02003459friend function f_tc_lu_and_mo_ussd_mo_release(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07003460runs on BSC_ConnHdlr {
3461 f_init_handler(pars);
3462
3463 /* Perform location update */
3464 f_perform_lu();
3465
3466 /* Send CM Service Request for SS/USSD */
3467 f_establish_fully(EST_TYPE_SS_ACT);
3468
3469 /* We need to inspect GSUP activity */
3470 f_create_gsup_expect(hex2str(g_pars.imsi));
3471
3472 var template OCTN facility_ms_req := f_USSD_FACILITY_IE_INVOKE(
3473 invoke_id := 1, /* Initial request */
3474 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3475 ussd_string := "*6766*266#"
3476 );
3477
3478 var template OCTN facility_net_req := f_USSD_FACILITY_IE_INVOKE(
3479 invoke_id := 2, /* Counter request */
3480 op_code := SS_OP_CODE_USS_REQUEST,
3481 ussd_string := "Password?!?"
3482 )
3483
3484 /* Compose MO SS/REGISTER message with request */
3485 var template (value) PDU_ML3_MS_NW ussd_ms_req := ts_ML3_MO_SS_REGISTER(
3486 tid := 1, /* We just need a single transaction */
3487 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3488 facility := valueof(facility_ms_req)
3489 );
3490
3491 /* Compose expected MSC -> HLR message */
3492 var template GSUP_PDU gsup_ms_req := tr_GSUP_PROC_SS_REQ(
3493 imsi := g_pars.imsi,
3494 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3495 ss := valueof(facility_ms_req)
3496 );
3497
3498 /* To be used for sending response with correct session ID */
3499 var GSUP_PDU gsup_ms_req_complete;
3500
3501 /* Initiate a new transaction */
3502 BSSAP.send(ts_PDU_DTAP_MO(ussd_ms_req));
3503 /* Expect GSUP request with original Facility IE */
3504 gsup_ms_req_complete := f_expect_gsup_msg(gsup_ms_req);
3505
3506 /* Compose the response from HLR using received session ID */
3507 var template (value) GSUP_PDU gsup_net_req := ts_GSUP_PROC_SS_REQ(
3508 imsi := g_pars.imsi,
3509 sid := gsup_ms_req_complete.ies[1].val.session_id,
3510 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3511 ss := valueof(facility_net_req)
3512 );
3513
3514 /* Compose expected MT SS/FACILITY template with counter request */
3515 var template PDU_ML3_NW_MS ussd_net_req := tr_ML3_MT_SS_FACILITY(
3516 tid := 1, /* Response should arrive within the same transaction */
3517 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3518 facility := valueof(facility_net_req)
3519 );
3520
3521 /* Send response over GSUP */
3522 GSUP.send(gsup_net_req);
3523 /* Expect MT SS/FACILITY message with counter request */
3524 f_expect_mt_dtap_msg(ussd_net_req);
3525
3526 /* Compose MO SS/RELEASE COMPLETE */
3527 var template (value) PDU_ML3_MS_NW ussd_abort := ts_ML3_MO_SS_RELEASE_COMPLETE(
3528 tid := 1, /* Response should arrive within the same transaction */
3529 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3530 facility := omit
3531 /* TODO: cause? */
3532 );
3533
3534 /* Compose expected HLR -> MSC abort message */
3535 var template GSUP_PDU gsup_abort := tr_GSUP_PROC_SS_REQ(
3536 imsi := g_pars.imsi,
3537 sid := gsup_ms_req_complete.ies[1].val.session_id,
3538 state := OSMO_GSUP_SESSION_STATE_END
3539 );
3540
3541 /* Abort transaction */
3542 BSSAP.send(ts_PDU_DTAP_MO(ussd_abort));
3543 /* Expect GSUP message indicating abort */
3544 f_expect_gsup_msg(gsup_abort);
3545
3546 f_expect_clear();
3547}
3548testcase TC_lu_and_mo_ussd_mo_release() runs on MTC_CT {
3549 var BSC_ConnHdlr vc_conn;
3550 f_init();
3551 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_mo_release), 50);
3552 vc_conn.done;
3553}
3554
Harald Weltee13cfb22019-04-23 16:52:02 +02003555
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003556/* LU followed by MO USSD request and MT Release due to timeout */
Harald Weltee13cfb22019-04-23 16:52:02 +02003557friend function f_tc_lu_and_ss_session_timeout(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003558runs on BSC_ConnHdlr {
3559 f_init_handler(pars);
3560
3561 /* Perform location update */
3562 f_perform_lu();
3563
3564 /* Send CM Service Request for SS/USSD */
3565 f_establish_fully(EST_TYPE_SS_ACT);
3566
3567 /* We need to inspect GSUP activity */
3568 f_create_gsup_expect(hex2str(g_pars.imsi));
3569
3570 var template OCTN facility_ms_req := f_USSD_FACILITY_IE_INVOKE(
3571 invoke_id := 1,
3572 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3573 ussd_string := "#release_me");
3574
3575 /* Compose MO SS/REGISTER message with request */
3576 var template (value) PDU_ML3_MS_NW ussd_ms_req := ts_ML3_MO_SS_REGISTER(
3577 tid := 1, /* An arbitrary transaction identifier */
3578 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3579 facility := valueof(facility_ms_req));
3580
3581 /* Compose expected MSC -> HLR message */
3582 var template GSUP_PDU gsup_ms_req := tr_GSUP_PROC_SS_REQ(
3583 imsi := g_pars.imsi,
3584 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3585 ss := valueof(facility_ms_req));
3586
3587 /* To be used for sending response with correct session ID */
3588 var GSUP_PDU gsup_ms_req_complete;
3589
3590 /* Initiate a new SS transaction */
3591 BSSAP.send(ts_PDU_DTAP_MO(ussd_ms_req));
3592 /* Expect GSUP request with original Facility IE */
3593 gsup_ms_req_complete := f_expect_gsup_msg(gsup_ms_req);
3594
3595 /* Don't respond, wait for timeout */
3596 f_sleep(3.0);
3597
3598 var template PDU_ML3_NW_MS dtap_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
3599 tid := 1, /* Should match the request's tid */
3600 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3601 cause := *, /* TODO: expect some specific value */
3602 facility := omit);
3603
3604 var template GSUP_PDU gsup_rel := tr_GSUP_PROC_SS_ERR(
3605 imsi := g_pars.imsi,
3606 sid := gsup_ms_req_complete.ies[1].val.session_id,
3607 state := OSMO_GSUP_SESSION_STATE_END,
3608 cause := ?); /* TODO: expect some specific value */
3609
3610 /* Expect release on both interfaces */
3611 interleave {
3612 [] BSSAP.receive(tr_PDU_DTAP_MT(dtap_rel)) { };
3613 [] GSUP.receive(gsup_rel) { };
3614 }
3615
3616 f_expect_clear();
3617 setverdict(pass);
3618}
3619testcase TC_lu_and_ss_session_timeout() runs on MTC_CT {
3620 var BSC_ConnHdlr vc_conn;
3621 f_init();
Vadim Yanitskiy36d28dd2018-12-03 02:45:45 +07003622 f_vty_config(MSCVTY, "msc", "ncss guard-timeout 3");
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003623 vc_conn := f_start_handler(refers(f_tc_lu_and_ss_session_timeout), 51);
3624 vc_conn.done;
Vadim Yanitskiy36d28dd2018-12-03 02:45:45 +07003625 f_vty_config(MSCVTY, "msc", "ncss guard-timeout 0");
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003626}
3627
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07003628/* MT (network-originated) USSD for unknown subscriber */
3629friend function f_tc_mt_ussd_for_unknown_subscr(charstring id, BSC_ConnHdlrPars pars)
3630runs on BSC_ConnHdlr {
3631 var hexstring imsi := '000000000000000'H; /* Some unknown IMSI */
3632 var OCT4 sid := '20000222'O;
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07003633
3634 f_init_handler(pars);
3635 f_ran_register_imsi(imsi, 'FFFFFFFF'O);
3636 f_create_gsup_expect(hex2str(imsi));
3637
3638 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3639 imsi := imsi,
3640 sid := sid,
3641 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3642 ss := f_rnd_octstring(23)
3643 );
3644
3645 /* Error with cause GMM_CAUSE_IMSI_UNKNOWN */
3646 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
3647 imsi := imsi,
3648 sid := sid,
3649 state := OSMO_GSUP_SESSION_STATE_END,
3650 cause := 2 /* FIXME: introduce an enumerated type! */
3651 );
3652
3653 /* Initiate a MT USSD notification */
3654 GSUP.send(gsup_req);
3655
3656 /* Expect GSUP PROC_SS_ERROR message */
Vadim Yanitskiy851798c2019-06-15 14:22:28 +07003657 f_expect_gsup_msg(gsup_rsp);
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07003658}
3659testcase TC_mt_ussd_for_unknown_subscr() runs on MTC_CT {
3660 var BSC_ConnHdlr vc_conn;
3661 f_init();
3662 vc_conn := f_start_handler(refers(f_tc_mt_ussd_for_unknown_subscr), 0);
3663 vc_conn.done;
3664}
3665
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07003666/* MO (mobile-originated) SS/USSD for unknown transaction */
3667friend function f_tc_mo_ussd_for_unknown_trans(charstring id, BSC_ConnHdlrPars pars)
3668runs on BSC_ConnHdlr {
3669 f_init_handler(pars);
3670
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01003671 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07003672 f_create_gsup_expect(hex2str(g_pars.imsi));
3673
3674 /* Perform location update */
3675 f_perform_lu();
3676
3677 /* Send CM Service Request for SS/USSD */
3678 f_establish_fully(EST_TYPE_SS_ACT);
3679
3680 /* GSM 04.80 FACILITY message for a non-existing transaction */
3681 var template (value) PDU_ML3_MS_NW mo_ss_fac := ts_ML3_MO_SS_FACILITY(
3682 tid := 1, /* An arbitrary transaction identifier */
3683 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3684 facility := f_rnd_octstring(23) /* We don't care about the Facility IE */
3685 );
3686
3687 /* GSM 04.80 RELEASE COMPLETE message for a non-existing transaction */
3688 var template (value) PDU_ML3_MS_NW mo_ss_rel := ts_ML3_MO_SS_RELEASE_COMPLETE(
3689 tid := 1, /* An arbitrary transaction identifier */
3690 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3691 facility := f_rnd_octstring(23) /* We don't care about the Facility IE */
3692 );
3693
3694 /* Expected response from the network */
3695 var template PDU_ML3_NW_MS mt_ss_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
3696 tid := 1, /* Same as in the FACILITY message */
3697 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3698 facility := omit
3699 );
3700
3701 /* Send GSM 04.80 FACILITY for non-existing transaction */
3702 BSSAP.send(ts_PDU_DTAP_MO(mo_ss_fac));
3703
3704 /* Expect GSM 04.80 RELEASE COMPLETE message */
3705 f_expect_mt_dtap_msg(mt_ss_rel);
3706 f_expect_clear();
3707
3708 /* Send another CM Service Request for SS/USSD */
3709 f_establish_fully(EST_TYPE_SS_ACT);
3710
3711 /* Send GSM 04.80 RELEASE COMPLETE for non-existing transaction */
3712 BSSAP.send(ts_PDU_DTAP_MO(mo_ss_rel));
3713
3714 /* Expect GSM 04.80 RELEASE COMPLETE message */
3715 f_expect_mt_dtap_msg(mt_ss_rel);
3716 f_expect_clear();
3717}
3718testcase TC_mo_ussd_for_unknown_trans() runs on MTC_CT {
3719 var BSC_ConnHdlr vc_conn;
3720 f_init();
3721 vc_conn := f_start_handler(refers(f_tc_mo_ussd_for_unknown_trans), 111);
3722 vc_conn.done;
3723}
3724
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07003725/* MT (network-originated) USSD for unknown session */
3726friend function f_tc_proc_ss_for_unknown_session(charstring id, BSC_ConnHdlrPars pars)
3727runs on BSC_ConnHdlr {
3728 var OCT4 sid := '20000333'O;
3729
3730 f_init_handler(pars);
3731
3732 /* Perform location update */
3733 f_perform_lu();
3734
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01003735 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07003736 f_create_gsup_expect(hex2str(g_pars.imsi));
3737
3738 /* Request referencing a non-existing SS session */
3739 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3740 imsi := g_pars.imsi,
3741 sid := sid,
3742 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3743 ss := f_rnd_octstring(23)
3744 );
3745
3746 /* Error with some cause value */
3747 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
3748 imsi := g_pars.imsi,
3749 sid := sid,
3750 state := OSMO_GSUP_SESSION_STATE_END,
3751 cause := ? /* FIXME: introduce an enumerated type! */
3752 );
3753
3754 /* Initiate a MT USSD notification */
3755 GSUP.send(gsup_req);
3756
3757 /* Expect GSUP PROC_SS_ERROR message */
3758 f_expect_gsup_msg(gsup_rsp);
3759}
3760testcase TC_proc_ss_for_unknown_session() runs on MTC_CT {
3761 var BSC_ConnHdlr vc_conn;
3762 f_init();
3763 vc_conn := f_start_handler(refers(f_tc_proc_ss_for_unknown_session), 110);
3764 vc_conn.done;
3765}
3766
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003767/* MT (network-originated) USSD and no response to Paging Request */
3768friend function f_tc_proc_ss_paging_fail(charstring id, BSC_ConnHdlrPars pars)
3769runs on BSC_ConnHdlr {
3770 timer TP := 2.0; /* Paging timer */
3771
3772 f_init_handler(pars);
3773
3774 /* Perform location update */
3775 f_perform_lu();
3776
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01003777 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003778 f_create_gsup_expect(hex2str(g_pars.imsi));
3779
3780 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3781 imsi := g_pars.imsi,
3782 sid := '20000444'O,
3783 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3784 ss := f_rnd_octstring(23)
3785 );
3786
3787 /* Error with some cause value */
3788 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
3789 imsi := g_pars.imsi,
3790 sid := '20000444'O,
3791 state := OSMO_GSUP_SESSION_STATE_END,
3792 cause := ? /* FIXME: introduce an enumerated type! */
3793 );
3794
3795 /* Initiate a MT USSD notification */
3796 GSUP.send(gsup_req);
3797
3798 /* Send it to MSC and expect Paging Request */
3799 TP.start;
3800 alt {
3801 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
3802 setverdict(pass);
3803 }
3804 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
3805 setverdict(pass);
3806 }
3807 /* We don't expect anything else */
3808 [] as_unexp_gsup_or_bssap_msg();
3809 [] TP.timeout {
3810 setverdict(fail, "Timeout waiting for Paging Request");
3811 }
3812 }
3813
Vadim Yanitskiyd24b5252019-10-02 00:04:51 +07003814 /* Wait up to 20 seconds for GSUP PROC_SS_ERROR message.
3815 * OsmoMSC waits for Paging Response 10 seconds by default. */
3816 f_expect_gsup_msg(gsup_rsp, T_val := 20.0);
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003817}
3818testcase TC_proc_ss_paging_fail() runs on MTC_CT {
3819 var BSC_ConnHdlr vc_conn;
3820 f_init();
3821 vc_conn := f_start_handler(refers(f_tc_proc_ss_paging_fail), 101);
3822 vc_conn.done;
3823}
3824
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07003825/* MT (network-originated) USSD followed by immediate abort */
3826friend function f_tc_proc_ss_abort(charstring id, BSC_ConnHdlrPars pars)
3827runs on BSC_ConnHdlr {
3828 var octetstring facility := f_rnd_octstring(23);
3829 var OCT4 sid := '20000555'O;
3830 timer TP := 2.0;
3831
3832 f_init_handler(pars);
3833
3834 /* Perform location update */
3835 f_perform_lu();
3836
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01003837 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07003838 f_create_gsup_expect(hex2str(g_pars.imsi));
3839
3840 /* PROC_SS_REQ initiates a mobile-originated SS/USSD session */
3841 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3842 imsi := g_pars.imsi, sid := sid,
3843 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3844 ss := facility
3845 );
3846
3847 /* On the MS side, we expect GSM 04.80 REGISTER message */
3848 var template PDU_ML3_NW_MS dtap_reg := tr_ML3_MT_SS_REGISTER(
3849 tid := 0, /* Most likely, it should be 0 */
3850 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3851 facility := facility
3852 );
3853
3854 /* PROC_SS_ERR with SESSION_STATE_END terminates the SS/USSD session */
3855 var template (value) GSUP_PDU gsup_abort := ts_GSUP_PROC_SS_ERR(
3856 imsi := g_pars.imsi, sid := sid,
3857 state := OSMO_GSUP_SESSION_STATE_END,
3858 cause := 0 /* FIXME: introduce an enumerated type! */
3859 );
3860
3861 /* On the MS side, we expect GSM 04.80 REGISTER message */
3862 var template PDU_ML3_NW_MS dtap_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
3863 tid := 0, /* Most likely, it should be 0 */
3864 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3865 cause := *, /* FIXME: expect some specific cause value */
3866 facility := omit
3867 );
3868
3869 /* Initiate a MT USSD with random payload */
3870 GSUP.send(gsup_req);
3871
3872 /* Expect Paging Request */
3873 TP.start;
3874 alt {
3875 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
3876 setverdict(pass);
3877 }
3878 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
3879 setverdict(pass);
3880 }
3881 /* We don't expect anything else */
3882 [] as_unexp_gsup_or_bssap_msg();
3883 [] TP.timeout {
3884 setverdict(fail, "Timeout waiting for Paging Request");
3885 }
3886 }
3887
3888 /* Send Paging Response and establish connection */
3889 f_establish_fully(EST_TYPE_PAG_RESP);
3890 /* Expect MT REGISTER message with random facility */
3891 f_expect_mt_dtap_msg(dtap_reg);
3892
3893 /* HLR/EUSE decides to abort the session even
3894 * before getting any response from the MS */
3895 /* Initiate a MT USSD with random payload */
3896 GSUP.send(gsup_abort);
3897
3898 /* Expect RELEASE COMPLETE on ths MS side */
3899 f_expect_mt_dtap_msg(dtap_rel);
3900
3901 f_expect_clear();
3902}
3903testcase TC_proc_ss_abort() runs on MTC_CT {
3904 var BSC_ConnHdlr vc_conn;
3905 f_init();
3906 vc_conn := f_start_handler(refers(f_tc_proc_ss_abort), 102);
3907 vc_conn.done;
3908}
3909
Harald Weltee13cfb22019-04-23 16:52:02 +02003910
Vadim Yanitskiy1c9754d2020-01-07 21:56:55 +01003911/* Verify multiple concurrent MO SS/USSD transactions
3912 * (one subscriber - one transaction) */
3913testcase TC_multi_lu_and_mo_ussd() runs on MTC_CT {
3914 var BSC_ConnHdlr vc_conn[16];
3915 var integer i;
3916
3917 f_init();
3918
3919 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
3920 vc_conn[i] := f_start_handler(refers(f_tc_lu_and_mo_ussd_single_request), 210 + i);
3921 }
3922
3923 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
3924 vc_conn[i].done;
3925 }
3926}
3927
3928/* Verify multiple concurrent MT SS/USSD transactions
3929 * (one subscriber - one transaction) */
3930testcase TC_multi_lu_and_mt_ussd() runs on MTC_CT {
3931 var BSC_ConnHdlr vc_conn[16];
3932 var integer i;
3933 var OCT4 sid;
3934
3935 f_init();
3936
3937 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
3938 sid := '200001'O & int2oct(i, 1); /* All transactions must use different session ID */
3939 vc_conn[i] := f_start_handler_with_pars(refers(f_tc_lu_and_mt_ussd_notification),
3940 f_init_pars(226 + i, gsup_sid := sid));
3941 }
3942
3943 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
3944 vc_conn[i].done;
3945 }
3946}
3947
3948
Stefan Sperling89eb1f32018-12-17 15:06:20 +01003949/* A5/1 only permitted on network side; attempt an invalid CIPHER MODE COMPLETE with A5/3 which MSC should reject. */
3950private function f_tc_cipher_complete_with_invalid_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3951 pars.net.expect_auth := true;
3952 pars.net.expect_ciph := true;
3953 pars.net.kc_support := '02'O; /* A5/1 only */
3954 f_init_handler(pars);
3955
3956 g_pars.vec := f_gen_auth_vec_2g();
3957
3958 /* Can't use f_perform_lu() directly. Code below is based on it. */
3959
3960 /* tell GSUP dispatcher to send this IMSI to us */
3961 f_create_gsup_expect(hex2str(g_pars.imsi));
3962
3963 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
3964 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
Harald Weltedceacc72019-04-21 20:58:35 +02003965 f_cl3_or_initial_ue(l3_lu);
Stefan Sperling89eb1f32018-12-17 15:06:20 +01003966
3967 f_mm_auth();
3968
3969 var OCT1 a5_net := f_alg_mask_from_cm(g_pars.cm2);
3970 var OCT1 a5_intersect := g_pars.net.kc_support and4b a5_net;
3971 alt {
3972 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(a5_intersect, g_pars.vec.kc)) {
3973 BSSAP.send(ts_BSSMAP_CipherModeCompl(int2oct(4 /* "accept" A5/3 */, 1)));
3974 }
3975 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?, g_pars.vec.kc)) {
3976 setverdict(fail, "Wrong ciphering algorithm mask in CiphModCmd");
3977 mtc.stop;
3978 }
3979 [] BSSAP.receive {
3980 setverdict(fail, "Unknown/unexpected BSSAP received");
3981 mtc.stop;
3982 }
3983 }
Harald Welte79f1e452020-08-18 22:55:02 +02003984 f_expect_common_id();
Stefan Sperling89eb1f32018-12-17 15:06:20 +01003985
3986 /* Expect LU reject from MSC. */
3987 alt {
3988 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
3989 setverdict(pass);
3990 }
3991 [] BSSAP.receive {
3992 setverdict(fail, "Unknown/unexpected BSSAP received");
3993 mtc.stop;
3994 }
3995 }
Stefan Sperlingc620b352018-12-18 17:23:36 +01003996 f_expect_clear();
Stefan Sperling89eb1f32018-12-17 15:06:20 +01003997}
3998
3999testcase TC_cipher_complete_with_invalid_cipher() runs on MTC_CT {
4000 var BSC_ConnHdlr vc_conn;
4001 f_init();
4002 f_vty_config(MSCVTY, "network", "encryption a5 1");
4003
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02004004 vc_conn := f_start_handler(refers(f_tc_cipher_complete_with_invalid_cipher), 52, verify_cell_id := false);
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004005 vc_conn.done;
4006}
4007
Harald Welteb2284bd2019-05-10 11:30:43 +02004008/* Location Update with invalid (non-matching) MCC/MNC reported on BSSMAP level from BSC */
4009friend function f_tc_lu_with_invalid_mcc_mnc(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4010 f_init_handler(pars);
4011
4012 /* tell GSUP dispatcher to send this IMSI to us */
4013 f_create_gsup_expect(hex2str(g_pars.imsi));
4014
4015 /* modify the cell ID which will be used to construct the COMPLELTE L3 or InitialUE */
4016 g_pars.cell_id := valueof(ts_CellId_CGI('333'H, '22'H, 23, 42));
4017
4018 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
4019 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
4020 f_cl3_or_initial_ue(l3_lu);
Harald Welte79f1e452020-08-18 22:55:02 +02004021 f_expect_common_id();
Harald Welteb2284bd2019-05-10 11:30:43 +02004022
4023 /* Expect LU reject from MSC. */
4024 alt {
4025 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
4026 setverdict(pass);
4027 }
4028 [] BSSAP.receive {
4029 setverdict(fail, "Unknown/unexpected BSSAP received");
4030 mtc.stop;
4031 }
4032 }
4033 f_expect_clear();
4034}
4035testcase TC_lu_with_invalid_mcc_mnc() runs on MTC_CT {
4036 var BSC_ConnHdlr vc_conn;
4037 f_init();
4038 vc_conn := f_start_handler(refers(f_tc_lu_with_invalid_mcc_mnc), 54);
4039 vc_conn.done;
4040}
4041
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01004042private function f_tc_cipher_complete_without_alg(charstring id, BSC_ConnHdlrPars pars, octetstring kc_support) runs on BSC_ConnHdlr {
4043 pars.net.expect_auth := true;
4044 pars.net.expect_ciph := true;
4045 pars.net.kc_support := kc_support;
4046 f_init_handler(pars);
4047
4048 g_pars.vec := f_gen_auth_vec_2g();
4049
4050 /* Can't use f_perform_lu() directly. Code below is based on it. */
4051
4052 /* tell GSUP dispatcher to send this IMSI to us */
4053 f_create_gsup_expect(hex2str(g_pars.imsi));
4054
4055 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
4056 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
4057 f_cl3_or_initial_ue(l3_lu);
4058
4059 f_mm_auth();
4060
4061 var OCT1 a5_net := f_alg_mask_from_cm(g_pars.cm2);
4062 var OCT1 a5_intersect := g_pars.net.kc_support and4b a5_net;
4063 alt {
4064 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(a5_intersect, g_pars.vec.kc)) {
4065 BSSAP.send(ts_BSSMAP_CipherModeComplAlg(omit));
4066 }
4067 [] BSSAP.receive(tr_BSSMAP_ClassmarkReq) {
4068 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
4069 repeat;
4070 }
4071 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?, g_pars.vec.kc)) {
4072 setverdict(fail, "Wrong ciphering algorithm mask in CiphModCmd");
4073 mtc.stop;
4074 }
4075 [] BSSAP.receive {
4076 setverdict(fail, "Unknown/unexpected BSSAP received");
4077 mtc.stop;
4078 }
4079 }
Harald Welte79f1e452020-08-18 22:55:02 +02004080 f_expect_common_id();
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01004081
4082 /* TODO: Verify MSC is using the best cipher available! How? */
4083
4084 f_msc_lu_hlr();
4085 f_accept_reject_lu();
4086 f_expect_clear();
4087 setverdict(pass);
4088}
4089
4090/* A5/1 only permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
4091private function f_tc_cipher_complete_1_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4092 f_tc_cipher_complete_without_alg(id, pars, '02'O /* A5/1 only */);
4093}
4094
4095/* A5/3 only permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
4096private function f_tc_cipher_complete_3_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4097 f_tc_cipher_complete_without_alg(id, pars, '08'O /* A5/3 only */);
4098}
4099
4100/* A5/1 + A5/3 permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
4101private function f_tc_cipher_complete_13_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4102 f_tc_cipher_complete_without_alg(id, pars, '0A'O /* A5/1 and A5/3 enabled */);
4103}
4104
4105testcase TC_cipher_complete_1_without_cipher() runs on MTC_CT {
4106 var BSC_ConnHdlr vc_conn;
4107 f_init();
4108 f_vty_config(MSCVTY, "network", "encryption a5 1");
4109
4110 vc_conn := f_start_handler(refers(f_tc_cipher_complete_1_without_cipher), 53);
4111 vc_conn.done;
4112}
4113
4114testcase TC_cipher_complete_3_without_cipher() runs on MTC_CT {
4115 var BSC_ConnHdlr vc_conn;
4116 f_init();
4117 f_vty_config(MSCVTY, "network", "encryption a5 3");
4118
4119 vc_conn := f_start_handler(refers(f_tc_cipher_complete_3_without_cipher), 54);
4120 vc_conn.done;
4121}
4122
4123testcase TC_cipher_complete_13_without_cipher() runs on MTC_CT {
4124 var BSC_ConnHdlr vc_conn;
4125 f_init();
4126 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
4127
4128 vc_conn := f_start_handler(refers(f_tc_cipher_complete_13_without_cipher), 55);
4129 vc_conn.done;
4130}
Harald Welteb2284bd2019-05-10 11:30:43 +02004131
Harald Weltef640a012018-04-14 17:49:21 +02004132/* TODO (SMS):
4133 * different user data lengths
4134 * SMPP transaction mode with unsuccessful delivery
4135 * queued MT-SMS with no paging response + later delivery
4136 * different data coding schemes
4137 * multi-part SMS
4138 * user-data headers
4139 * TP-PID for SMS to SIM
4140 * behavior if SMS memory is full + RP-SMMA
4141 * delivery reports
4142 * SMPP osmocom extensions
4143 * more-messages-to-send
4144 * SMS during ongoing call (SACCH/SAPI3)
4145 */
4146
4147/* TODO (General):
Harald Welteba7b6d92018-01-23 21:32:34 +01004148 * continue to send repeated MO signalling messages to keep channel open: does MSC tmeout?
4149 * malformed messages (missing IE, invalid message type): properly rejected?
4150 * MT call while LU or is ongoing: Do we use existing lchan or page while lchan active?
4151 * 3G/2G auth permutations
4152 * encryption algorithms vs. classmark vs. vty config
Harald Welteba7b6d92018-01-23 21:32:34 +01004153 * send new transaction after/during clear (like SMS, ...)
Harald Welte45164da2018-01-24 12:51:27 +01004154 * too long L3 INFO in DTAP
4155 * too long / padded BSSAP
4156 * too long / short TLV values
Harald Welteba7b6d92018-01-23 21:32:34 +01004157 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01004158
Harald Weltee13cfb22019-04-23 16:52:02 +02004159/***********************************************************************
4160 * SGsAP Testing
4161 ***********************************************************************/
4162
Philipp Maier948747b2019-04-02 15:22:33 +02004163/* Check if a subscriber exists in the VLR */
4164private function f_ctrl_subscr_in_vlr(charstring imsi_or_msisdn) runs on BSC_ConnHdlr return boolean {
4165
4166 var CtrlValue active_subsribers;
4167 var integer rc;
4168 active_subsribers := f_ctrl_get(IPA_CTRL, "subscriber-list-active-v1");
4169
4170 rc := f_strstr(active_subsribers, imsi_or_msisdn);
4171 if (rc < 0) {
4172 return false;
4173 }
4174
4175 return true;
4176}
4177
Harald Welte4263c522018-12-06 11:56:27 +01004178/* Perform a location updatye at the A-Interface and run some checks to confirm
4179 * that everything is back to normal. */
4180private function f_sgsap_bssmap_screening() runs on BSC_ConnHdlr {
4181 var SmsParameters spars := valueof(t_SmsPars);
4182
4183 /* Perform a location update, the SGs association is expected to fall
4184 * back to NULL */
4185 f_perform_lu();
4186 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4187
4188 /* Trigger a paging request and expect the paging on BSSMAP, this is
4189 * to make sure that pagings are sent throught the A-Interface again
4190 * and not throught the SGs interface.*/
Harald Welte6811d102019-04-14 22:23:14 +02004191 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Welte4263c522018-12-06 11:56:27 +01004192 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4193
4194 alt {
Harald Weltee13cfb22019-04-23 16:52:02 +02004195 [g_pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)); {
4196 setverdict(pass);
4197 }
Harald Welte62113fc2019-05-09 13:04:02 +02004198 [not g_pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
Harald Welte4263c522018-12-06 11:56:27 +01004199 setverdict(pass);
4200 }
4201 [] SGsAP.receive {
4202 setverdict(fail, "Received unexpected message on SGs");
4203 }
4204 }
4205
4206 /* Send an SMS to make sure that also payload messages are routed
4207 * throught the A-Interface again */
4208 f_establish_fully(EST_TYPE_MO_SMS);
4209 f_mo_sms(spars);
4210 f_expect_clear();
4211}
4212
4213private function f_tc_sgsap_reset(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4214 var charstring vlr_name;
4215 f_init_handler(pars);
4216
4217 vlr_name := f_sgsap_reset_mme(mp_mme_name);
4218 log("VLR name: ", vlr_name);
4219 setverdict(pass);
Neels Hofmeyrc0b520d2019-03-06 15:35:50 +01004220 f_sleep(1.0);
Harald Welte4263c522018-12-06 11:56:27 +01004221}
4222
4223testcase TC_sgsap_reset() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004224 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004225 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004226 f_init(1, true);
4227 pars := f_init_pars(11810, true);
4228 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_reset), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004229 vc_conn.done;
4230}
4231
4232/* like f_mm_auth() but for SGs */
4233function f_mm_auth_sgs() runs on BSC_ConnHdlr {
4234 if (g_pars.net.expect_auth) {
4235 g_pars.vec := f_gen_auth_vec_3g();
4236 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G3G(g_pars.vec.rand,
4237 g_pars.vec.sres,
4238 g_pars.vec.kc,
4239 g_pars.vec.ik,
4240 g_pars.vec.ck,
4241 g_pars.vec.autn,
4242 g_pars.vec.res));
4243 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
4244 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
4245 SGsAP.receive(tr_ML3_MT_MM_AUTH_REQ_3G(g_pars.vec.rand, g_pars.vec.autn));
4246 SGsAP.send(ts_ML3_MT_MM_AUTH_RESP_3G(g_pars.vec.sres, g_pars.vec.res));
4247 }
4248}
4249
4250/* like f_perform_lu(), but on SGs rather than BSSAP */
4251function f_sgs_perform_lu() runs on BSC_ConnHdlr {
4252 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4253 var PDU_SGsAP lur;
4254 var PDU_SGsAP lua;
4255 var PDU_SGsAP mm_info;
4256 var octetstring mm_info_dtap;
4257
4258 /* tell GSUP dispatcher to send this IMSI to us */
4259 f_create_gsup_expect(hex2str(g_pars.imsi));
4260
4261 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
4262 ts_SGsAP_LAI('901'H, '70'H, 2342)));
4263 /* Old LAI, if MS sends it */
4264 /* TMSI status, if MS has no valid TMSI */
4265 /* IMEISV, if it supports "automatic device detection" */
4266 /* TAI, if available in MME */
4267 /* E-CGI, if available in MME */
4268 SGsAP.send(lur);
4269
4270 /* FIXME: is this really done over SGs? The Ue is already authenticated
4271 * via the MME ... */
4272 f_mm_auth_sgs();
4273
4274 /* Expect MSC to perform LU with HLR */
4275 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4276 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
4277 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
4278 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
4279
4280 alt {
4281 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) -> value lua {
4282 if (isvalue(lua.sGsAP_LOCATION_UPDATE_ACCEPT.newTMSIorIMSI.iD.iD.tmsi_ptmsi.octets)) {
4283 g_pars.tmsi :=lua.sGsAP_LOCATION_UPDATE_ACCEPT.newTMSIorIMSI.iD.iD.tmsi_ptmsi.octets
4284 SGsAP.send(ts_SGsAP_TMSI_REALL_CMPL(g_pars.imsi));
4285 }
4286 setverdict(pass);
4287 }
4288 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4289 setverdict(fail, "Received LU-REJECT instead of ACCEPT");
4290 }
4291 [] SGsAP.receive {
4292 setverdict(fail, "Received unexpected message on SGs");
4293 }
4294 }
4295
4296 /* Check MM information */
4297 if (mp_mm_info == true) {
4298 SGsAP.receive(tr_SGsAP_MM_INFO_REQ(g_pars.imsi, ?)) -> value mm_info;
4299 mm_info_dtap := '0532'O & mm_info.sGsAP_MM_INFORMATION_REQUEST.mM_Information.information;
4300 if (not match(dec_PDU_ML3_NW_MS(mm_info_dtap), tr_ML3_MT_MM_Info)) {
4301 setverdict(fail, "Unexpected MM Information");
4302 }
4303 }
4304
4305 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4306}
4307
4308private function f_tc_sgsap_lu(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4309 f_init_handler(pars);
4310 f_sgs_perform_lu();
4311 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4312
4313 f_sgsap_bssmap_screening();
4314
4315 setverdict(pass);
4316}
4317testcase TC_sgsap_lu() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004318 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004319 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004320 f_init(1, true);
4321 pars := f_init_pars(11811, true);
4322 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004323 vc_conn.done;
4324}
4325
4326/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
4327private function f_tc_sgsap_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4328 f_init_handler(pars);
4329 var PDU_SGsAP lur;
4330
4331 f_create_gsup_expect(hex2str(g_pars.imsi));
4332 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4333 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
4334 ts_SGsAP_LAI('901'H, '70'H, 2342)));
4335 SGsAP.send(lur);
4336
4337 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4338 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
4339 alt {
4340 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4341 setverdict(pass);
4342 }
4343 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) {
4344 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
4345 mtc.stop;
4346 }
4347 [] SGsAP.receive {
4348 setverdict(fail, "Received unexpected message on SGs");
4349 }
4350 }
4351
4352 f_sgsap_bssmap_screening();
4353
4354 setverdict(pass);
4355}
4356testcase TC_sgsap_lu_imsi_reject() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004357 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004358 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004359 f_init(1, true);
4360 pars := f_init_pars(11812, true);
Harald Welte4263c522018-12-06 11:56:27 +01004361
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004362 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_imsi_reject), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004363 vc_conn.done;
4364}
4365
4366/* Do LU by IMSI, but then remain silent so that Ts6-1 times out */
4367private function f_tc_sgsap_lu_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4368 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4369 var PDU_SGsAP lur;
4370
4371 f_init_handler(pars);
4372
4373 /* tell GSUP dispatcher to send this IMSI to us */
4374 f_create_gsup_expect(hex2str(g_pars.imsi));
4375
4376 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
4377 ts_SGsAP_LAI('901'H, '70'H, 2342)));
4378 /* Old LAI, if MS sends it */
4379 /* TMSI status, if MS has no valid TMSI */
4380 /* IMEISV, if it supports "automatic device detection" */
4381 /* TAI, if available in MME */
4382 /* E-CGI, if available in MME */
4383 SGsAP.send(lur);
4384
4385 /* FIXME: is this really done over SGs? The Ue is already authenticated
4386 * via the MME ... */
4387 f_mm_auth_sgs();
4388
4389 /* Expect MSC to perform LU with HLR */
4390 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4391 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
4392 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
4393 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
4394
4395 alt {
4396 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) {
4397 setverdict(pass);
4398 }
4399 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4400 setverdict(fail, "Received LU-REJECT instead of ACCEPT");
4401 }
4402 [] SGsAP.receive {
4403 setverdict(fail, "Received unexpected message on SGs");
4404 }
4405 }
4406
4407 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4408
4409 /* Wait until the VLR has abort the TMSI reallocation procedure */
4410 f_sleep(45.0);
4411
4412 /* The outcome does not change the SGs state, see also 5.2.3.4 */
4413 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4414
4415 f_sgsap_bssmap_screening();
4416
4417 setverdict(pass);
4418}
4419testcase TC_sgsap_lu_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004420 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004421 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004422 f_init(1, true);
4423 pars := f_init_pars(11813, true);
Harald Welte4263c522018-12-06 11:56:27 +01004424
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004425 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004426 vc_conn.done;
4427}
4428
4429private function f_tc_sgsap_expl_imsi_det_eps(charstring id, BSC_ConnHdlrPars pars)
4430runs on BSC_ConnHdlr {
4431 f_init_handler(pars);
4432 f_sgs_perform_lu();
4433 f_sleep(3.0);
4434
4435 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4436 SGsAP.send(ts_SGsAP_EPS_DETACH_IND(g_pars.imsi, mme_name, UE_initiated));
4437 SGsAP.receive(tr_SGsAP_EPS_DETACH_ACK(g_pars.imsi));
4438 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4439
4440 f_sgsap_bssmap_screening();
4441
4442 setverdict(pass);
4443}
4444testcase TC_sgsap_expl_imsi_det_eps() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004445 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004446 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004447 f_init(1, true);
4448 pars := f_init_pars(11814, true);
4449 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_expl_imsi_det_eps), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004450 vc_conn.done;
4451}
4452
Philipp Maierfc19f172019-03-21 11:17:54 +01004453private function f_tc_sgsap_impl_imsi_det_eps(charstring id, BSC_ConnHdlrPars pars)
4454runs on BSC_ConnHdlr {
4455 f_init_handler(pars);
4456 f_sgs_perform_lu();
4457 f_sleep(3.0);
4458
4459 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4460 SGsAP.send(ts_SGsAP_EPS_DETACH_IND(g_pars.imsi, mme_name, network_initiated));
4461 SGsAP.receive(tr_SGsAP_EPS_DETACH_ACK(g_pars.imsi));
4462 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4463
4464 f_sgsap_bssmap_screening();
4465
4466 setverdict(pass);
4467}
4468testcase TC_sgsap_impl_imsi_det_eps() runs on MTC_CT {
4469 var BSC_ConnHdlrPars pars;
4470 var BSC_ConnHdlr vc_conn;
4471 f_init(1, true);
4472 pars := f_init_pars(11814, true);
4473 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_impl_imsi_det_eps), pars);
4474 vc_conn.done;
4475}
4476
Harald Welte4263c522018-12-06 11:56:27 +01004477private function f_tc_sgsap_expl_imsi_det_noneps(charstring id, BSC_ConnHdlrPars pars)
4478runs on BSC_ConnHdlr {
4479 f_init_handler(pars);
4480 f_sgs_perform_lu();
4481 f_sleep(3.0);
4482
4483 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4484 SGsAP.send(ts_SGsAP_IMSI_DETACH_IND(g_pars.imsi, mme_name, combined_UE_initiated));
4485 SGsAP.receive(tr_SGsAP_IMSI_DETACH_ACK(g_pars.imsi));
Philipp Maierd08e7e72019-04-02 15:27:10 +02004486
4487 if (f_ctrl_subscr_in_vlr(hex2str(g_pars.imsi))) {
4488 setverdict(fail, "subscriber not removed from VLR");
4489 }
Harald Welte4263c522018-12-06 11:56:27 +01004490
4491 f_sgsap_bssmap_screening();
4492
4493 setverdict(pass);
4494}
4495testcase TC_sgsap_expl_imsi_det_noneps() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004496 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004497 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004498 f_init(1, true);
4499 pars := f_init_pars(11815, true);
4500 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_expl_imsi_det_noneps), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004501 vc_conn.done;
4502}
4503
Philipp Maier5d812702019-03-21 10:51:26 +01004504private function f_tc_sgsap_impl_imsi_det_noneps(charstring id, BSC_ConnHdlrPars pars)
4505runs on BSC_ConnHdlr {
4506 f_init_handler(pars);
4507 f_sgs_perform_lu();
4508 f_sleep(3.0);
4509
4510 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4511 SGsAP.send(ts_SGsAP_IMSI_DETACH_IND(g_pars.imsi, mme_name, implicit_network_initiated));
4512 SGsAP.receive(tr_SGsAP_IMSI_DETACH_ACK(g_pars.imsi));
4513
4514 if (f_ctrl_subscr_in_vlr(hex2str(g_pars.imsi))) {
4515 setverdict(fail, "subscriber not removed from VLR");
4516 }
4517
4518 f_sgsap_bssmap_screening();
4519
4520 setverdict(pass);
4521}
4522testcase TC_sgsap_impl_imsi_det_noneps() runs on MTC_CT {
4523 var BSC_ConnHdlrPars pars;
4524 var BSC_ConnHdlr vc_conn;
4525 f_init(1, true);
4526 pars := f_init_pars(11815, true);
4527 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_impl_imsi_det_noneps), pars);
4528 vc_conn.done;
4529}
4530
Harald Welte4263c522018-12-06 11:56:27 +01004531/* Trigger a paging request via VTY and send a paging reject in response */
4532private function f_tc_sgsap_paging_rej(charstring id, BSC_ConnHdlrPars pars)
4533runs on BSC_ConnHdlr {
4534 f_init_handler(pars);
4535 f_sgs_perform_lu();
4536 f_sleep(1.0);
4537
4538 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4539 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4540 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4541 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4542
4543 /* Initiate paging via VTY */
4544 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4545 alt {
4546 [] SGsAP.receive(exp_resp) {
4547 setverdict(pass);
4548 }
4549 [] SGsAP.receive {
4550 setverdict(fail, "Received unexpected message on SGs");
4551 }
4552 }
4553
4554 /* Now reject the paging */
4555 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, IMSI_unknown));
4556
4557 /* Wait for the states inside the MSC to settle and check the state
4558 * of the SGs Association */
4559 f_sleep(1.0);
4560 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4561
4562 /* FIXME: At the moment we send an IMSI_unknown as cause code, which is fine,
4563 * but we also need to cover tha case where the cause code indicates an
4564 * "IMSI detached for EPS services". In those cases the VLR is expected to
4565 * try paging on tha A/Iu interface. This will be another testcase similar to
4566 * this one, but extended with checks for the presence of the A/Iu paging
4567 * messages. */
4568
4569 f_sgsap_bssmap_screening();
4570
4571 setverdict(pass);
4572}
4573testcase TC_sgsap_paging_rej() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004574 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004575 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004576 f_init(1, true);
4577 pars := f_init_pars(11816, true);
4578 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_rej), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004579 vc_conn.done;
4580}
4581
4582/* Trigger a paging request via VTY and send a paging reject that indicates
4583 * that the subscriber intentionally rejected the call. */
4584private function f_tc_sgsap_paging_subscr_rej(charstring id, BSC_ConnHdlrPars pars)
4585runs on BSC_ConnHdlr {
4586 f_init_handler(pars);
4587 f_sgs_perform_lu();
4588 f_sleep(1.0);
4589
4590 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4591 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4592 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4593 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4594
4595 /* Initiate paging via VTY */
4596 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4597 alt {
4598 [] SGsAP.receive(exp_resp) {
4599 setverdict(pass);
4600 }
4601 [] SGsAP.receive {
4602 setverdict(fail, "Received unexpected message on SGs");
4603 }
4604 }
4605
4606 /* Now reject the paging */
4607 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, user_rejected_mobile_terminating_CS_fallback_call));
4608
4609 /* Wait for the states inside the MSC to settle and check the state
4610 * of the SGs Association */
4611 f_sleep(1.0);
4612 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4613
4614 /* FIXME: The VLR is supposed to trigger an User Determined User Busy (UDUB) as specified
4615 * in 3GPP TS 24.082, this is not yet implemented in the MSC or in this tests, we need
4616 * to check back how this works and how it can be tested */
4617
4618 f_sgsap_bssmap_screening();
4619
4620 setverdict(pass);
4621}
4622testcase TC_sgsap_paging_subscr_rej() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004623 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004624 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004625 f_init(1, true);
4626 pars := f_init_pars(11817, true);
4627 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_subscr_rej), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004628 vc_conn.done;
4629}
4630
4631/* Trigger a paging request via VTY and send an UE unreacable messge in response */
4632private function f_tc_sgsap_paging_ue_unr(charstring id, BSC_ConnHdlrPars pars)
4633runs on BSC_ConnHdlr {
4634 f_init_handler(pars);
4635 f_sgs_perform_lu();
4636 f_sleep(1.0);
4637
4638 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4639 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4640 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4641 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4642
4643 /* Initiate paging via VTY */
4644 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4645 alt {
4646 [] SGsAP.receive(exp_resp) {
4647 setverdict(pass);
4648 }
4649 [] SGsAP.receive {
4650 setverdict(fail, "Received unexpected message on SGs");
4651 }
4652 }
4653
4654 /* Now pretend that the UE is unreachable */
4655 SGsAP.send(ts_SGsAP_UE_UNREACHABLE(g_pars.imsi, UE_unreachable));
4656
4657 /* Wait for the states inside the MSC to settle and check the state
4658 * of the SGs Association. */
4659 f_sleep(1.0);
4660 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4661
4662 f_sgsap_bssmap_screening();
4663
4664 setverdict(pass);
4665}
4666testcase TC_sgsap_paging_ue_unr() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004667 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004668 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004669 f_init(1, true);
4670 pars := f_init_pars(11818, true);
4671 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_ue_unr), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004672 vc_conn.done;
4673}
4674
4675/* Trigger a paging request via VTY but don't respond to it */
4676private function f_tc_sgsap_paging_and_nothing(charstring id, BSC_ConnHdlrPars pars)
4677runs on BSC_ConnHdlr {
4678 f_init_handler(pars);
4679 f_sgs_perform_lu();
4680 f_sleep(1.0);
4681
4682 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4683 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
Philipp Maier34218102019-09-24 09:15:49 +02004684 var template PDU_SGsAP exp_serv_abrt := ts_SGsAP_SERVICE_ABORT_REQ(g_pars.imsi);
Harald Welte4263c522018-12-06 11:56:27 +01004685 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4686 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4687
4688 /* Initiate paging via VTY */
4689 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4690 alt {
4691 [] SGsAP.receive(exp_resp) {
4692 setverdict(pass);
4693 }
4694 [] SGsAP.receive {
4695 setverdict(fail, "Received unexpected message on SGs");
4696 }
4697 }
4698
Philipp Maier34218102019-09-24 09:15:49 +02004699 /* While we are doing nothing, expect an SGsAP-SERVICE-ABORT-REQUEST
4700 * after some time */
4701 timer T := 10.0;
4702 T.start
4703 alt {
4704 [] SGsAP.receive(exp_serv_abrt)
4705 {
4706 setverdict(pass);
4707 }
4708 [] SGsAP.receive {
4709 setverdict(fail, "unexpected SGsAP message received");
4710 self.stop;
4711 }
4712 [] T.timeout {
4713 setverdict(fail, "MSC did not send SGsAP-SERVICE-ABORT-REQUEST");
4714 self.stop;
4715 }
4716 }
4717
4718 /* The SGs association must remain unchanged. */
Harald Welte4263c522018-12-06 11:56:27 +01004719 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4720
4721 f_sgsap_bssmap_screening();
4722
4723 setverdict(pass);
4724}
4725testcase TC_sgsap_paging_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004726 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004727 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004728 f_init(1, true);
4729 pars := f_init_pars(11819, true);
4730 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004731 vc_conn.done;
4732}
4733
4734/* Trigger a paging request via VTY and slip in an LU */
4735private function f_tc_sgsap_paging_and_lu(charstring id, BSC_ConnHdlrPars pars)
4736runs on BSC_ConnHdlr {
4737 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4738 f_init_handler(pars);
4739
4740 /* First we prepar the situation, where the SGs association is in state
4741 * NULL and the confirmed by radio contact indicator is set to false
4742 * as well. This can be archived by performing an SGs LU and then
4743 * resetting the VLR */
4744 f_sgs_perform_lu();
4745 f_sgsap_reset_mme(mp_mme_name);
4746 f_sleep(1.0);
4747 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4748
4749 /* Perform a paging, expect the paging messages on the SGs interface */
4750 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4751 alt {
4752 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
4753 setverdict(pass);
4754 }
4755 [] SGsAP.receive {
4756 setverdict(fail, "Received unexpected message on SGs");
4757 }
4758 }
4759
4760 /* Perform the LU as normal */
4761 f_sgs_perform_lu();
4762 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4763
4764 /* Expect a new paging request right after the LU */
4765 alt {
4766 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
4767 setverdict(pass);
4768 }
4769 [] SGsAP.receive {
4770 setverdict(fail, "Received unexpected message on SGs");
4771 }
4772 }
4773
4774 /* Test is done now, lets round everything up by rejecting the paging
4775 * cleanly. */
4776 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, user_rejected_mobile_terminating_CS_fallback_call));
4777 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4778
4779 f_sgsap_bssmap_screening();
4780
4781 setverdict(pass);
4782}
4783testcase TC_sgsap_paging_and_lu() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004784 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004785 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004786 f_init(1, true);
4787 pars := f_init_pars(11820, true);
4788 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_and_lu), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004789 vc_conn.done;
4790}
4791
4792/* Send unexpected unit-data through the SGs interface */
4793private function f_tc_sgsap_unexp_ud(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4794 f_init_handler(pars);
4795 f_sleep(1.0);
4796
4797 /* This simulates what happens when a subscriber without SGs
4798 * association gets unitdata via the SGs interface. */
4799
4800 /* Make sure the subscriber exists and the SGs association
4801 * is in NULL state */
4802 f_perform_lu();
4803 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4804
4805 /* Send some random unit data, the MSC/VLR should send a release
4806 * immediately. */
4807 SGsAP.send(ts_SGsAP_UL_UD(pars.imsi,'1234'O));
4808 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, IMSI_detached_for_EPS_nonEPS_services));
4809
4810 f_sgsap_bssmap_screening();
4811
4812 setverdict(pass);
4813}
4814testcase TC_sgsap_unexp_ud() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004815 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004816 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004817 f_init(1, true);
4818 pars := f_init_pars(11821, true);
4819 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_unexp_ud), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004820 vc_conn.done;
4821}
4822
4823/* Send unsolicited unit-data through the SGs interface */
4824private function f_tc_sgsap_unsol_ud(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4825 f_init_handler(pars);
4826 f_sleep(1.0);
4827
4828 /* This simulates what happens when the MME attempts to send unitdata
4829 * to a subscriber that is completely unknown to the VLR */
4830
4831 /* Send some random unit data, the MSC/VLR should send a release
4832 * immediately. */
4833 SGsAP.send(ts_SGsAP_UL_UD(pars.imsi,'1234'O));
4834 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, IMSI_unknown));
4835
4836 f_sgsap_bssmap_screening();
4837
Harald Welte4d15fa72020-08-19 08:58:28 +02004838 /* clean-up VLR state about this subscriber */
4839 f_imsi_detach_by_imsi();
4840
Harald Welte4263c522018-12-06 11:56:27 +01004841 setverdict(pass);
4842}
4843testcase TC_sgsap_unsol_ud() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004844 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004845 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004846 f_init(1, true);
4847 pars := f_init_pars(11822, true);
4848 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_unsol_ud), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004849 vc_conn.done;
4850}
4851
4852private altstep as_other_sms_sgs() runs on BSC_ConnHdlr {
4853 /* FIXME: Match an actual payload (second questionmark), the type is
4854 * octetstring, how do we use a tr_PDU_DTAP_MT here? */
4855 [] SGsAP.receive(tr_SGsAP_DL_UD(?,?)) {
4856 setverdict(fail, "Unexpected SMS related PDU from MSC");
4857 mtc.stop;
4858 }
4859}
4860
4861/* receive a MT-SMS delivered from the MSC/SMSC over an already existing SGsAP connection */
4862function f_mt_sms_sgs(inout SmsParameters spars)
4863runs on BSC_ConnHdlr {
4864 var template (value) TPDU_RP_DATA_MS_SGSN tp_mo;
4865 var template (value) RPDU_MS_SGSN rp_mo;
4866 var template (value) PDU_ML3_MS_NW l3_mo;
4867
4868 var template TPDU_RP_DATA_SGSN_MS tp_mt;
4869 var template RPDU_SGSN_MS rp_mt;
4870 var template PDU_ML3_NW_MS l3_mt;
4871
4872 var PDU_ML3_NW_MS sgsap_l3_mt;
4873
4874 var default d := activate(as_other_sms_sgs());
4875
4876 /* Expect CP-DATA(RP-DATA(SMS-DELIVER)) */
4877 tp_mt := tr_SMS_DELIVER(?, spars.tp.ud, spars.tp.pid, spars.tp.dcs, ?);
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09004878 rp_mt := tr_RP_DATA_MT(?, spars.rp.smsc_addr, omit, tp_mt);
Harald Welte4263c522018-12-06 11:56:27 +01004879 l3_mt := tr_ML3_MT_SMS(?, c_TIF_ORIG, tr_CP_DATA_MT(rp_mt));
4880
4881 SGsAP.receive(l3_mt) -> value sgsap_l3_mt;
4882
4883 /* Extract relevant identifiers */
4884 spars.tid := bit2int(sgsap_l3_mt.tiOrSkip.transactionId.tio);
4885 spars.rp.msg_ref := sgsap_l3_mt.msgs.sms.cP_DATA.cP_User_Data.cP_RPDU.rP_DATA_SGSN_MS.rP_MessageReference;
4886
4887 /* send CP-ACK for CP-DATA just received */
4888 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_REPL, ts_CP_ACK_MO);
4889
4890 SGsAP.send(l3_mo);
4891
4892 /* send RP-ACK for RP-DATA */
4893 rp_mo := ts_RP_ACK_MO(spars.rp.msg_ref);
4894 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_REPL, ts_CP_DATA_MO(rp_mo));
4895
4896 SGsAP.send(l3_mo);
4897
4898 /* expect CP-ACK for CP-DATA(RP-ACK) just sent */
4899 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_ORIG, tr_CP_ACK_MT);
4900
4901 SGsAP.receive(l3_mt);
4902
4903 deactivate(d);
4904
4905 setverdict(pass);
4906}
4907
4908/* submit a MO-SMS to MSC/SMSC over an already existing SGsAP connection */
4909function f_mo_sms_sgs(inout SmsParameters spars)
4910runs on BSC_ConnHdlr {
4911 var template (value) TPDU_RP_DATA_MS_SGSN tp_mo;
4912 var template (value) RPDU_MS_SGSN rp_mo;
4913 var template (value) PDU_ML3_MS_NW l3_mo;
4914
4915 var template TPDU_RP_DATA_SGSN_MS tp_mt;
4916 var template RPDU_SGSN_MS rp_mt;
4917 var template PDU_ML3_NW_MS l3_mt;
4918
4919 var default d := activate(as_other_sms_sgs());
4920
4921 /* just in case this is routed to SMPP.. */
4922 f_create_smpp_expect(hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue));
4923
4924 tp_mo := ts_SMS_SUBMIT(spars.tp.msg_ref, spars.tp.da, spars.tp.pid, spars.tp.dcs,
4925 spars.tp.udl, spars.tp.ud);
Vadim Yanitskiy437b5a62019-12-15 14:13:39 +09004926 rp_mo := ts_RP_DATA_MO(spars.rp.msg_ref, omit, spars.rp.smsc_addr, tp_mo);
Harald Welte4263c522018-12-06 11:56:27 +01004927 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_DATA_MO(rp_mo));
4928
4929 SGsAP.send(l3_mo);
4930
4931 /* receive CP-ACK for CP-DATA above */
4932 SGsAP.receive(tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_ACK_MT));
4933
4934 if (ispresent(spars.exp_rp_err)) {
4935 /* expect an RP-ERROR message from MSC with given cause */
4936 rp_mt := tr_RP_ERROR_MT(spars.rp.msg_ref, spars.exp_rp_err);
4937 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_DATA_MT(rp_mt));
4938 SGsAP.receive(l3_mt);
4939 /* send CP-ACK for CP-DATA just received */
4940 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_ACK_MO);
4941 SGsAP.send(l3_mo);
4942 } else {
4943 /* expect RP-ACK for RP-DATA */
4944 rp_mt := tr_RP_ACK_MT(spars.rp.msg_ref);
4945 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_DATA_MT(rp_mt));
4946 SGsAP.receive(l3_mt);
4947 /* send CP-ACO for CP-DATA just received */
4948 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_ACK_MO);
4949 SGsAP.send(l3_mo);
4950 }
4951
4952 deactivate(d);
4953
4954 setverdict(pass);
4955}
4956
4957private function f_vty_sms_send_conn_hdlr(charstring imsi, charstring msisdn, charstring text)
4958runs on BSC_ConnHdlr {
4959 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
4960}
4961
4962/* Send a MT SMS via SGs interface */
4963private function f_tc_sgsap_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4964 f_init_handler(pars);
4965 f_sgs_perform_lu();
4966 f_sleep(1.0);
4967 var SmsParameters spars := valueof(t_SmsPars);
4968 spars.tp.ud := 'C8329BFD064D9B53'O;
4969
4970 /* Trigger SMS via VTY */
4971 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
4972 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4973
4974 /* Expect a paging request and respond accordingly with a service request */
4975 SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, SMS_indicator, omit));
4976 SGsAP.send(ts_SGsAP_SERVICE_REQ(pars.imsi, SMS_indicator, EMM_CONNECTED));
4977
4978 /* Connection is now live, receive the MT-SMS */
4979 f_mt_sms_sgs(spars);
4980
4981 /* Expect a concluding release from the MSC */
4982 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, omit));
4983
4984 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
4985 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4986
4987 f_sgsap_bssmap_screening();
4988
4989 setverdict(pass);
4990}
4991testcase TC_sgsap_mt_sms() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004992 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004993 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004994 f_init(1, true);
4995 pars := f_init_pars(11823, true);
4996 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004997 vc_conn.done;
4998}
4999
5000/* Send a MO SMS via SGs interface */
5001private function f_tc_sgsap_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5002 f_init_handler(pars);
5003 f_sgs_perform_lu();
5004 f_sleep(1.0);
5005 var SmsParameters spars := valueof(t_SmsPars);
5006 spars.tp.ud := 'C8329BFD064D9B53'O;
5007
5008 /* Send the MO-SMS */
5009 f_mo_sms_sgs(spars);
5010
5011 /* Expect a concluding release from the MSC/VLR */
5012 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, omit));
5013
5014 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
5015 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5016
5017 setverdict(pass);
5018
5019 f_sgsap_bssmap_screening()
5020}
5021testcase TC_sgsap_mo_sms() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005022 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005023 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005024 f_init(1, true);
5025 pars := f_init_pars(11824, true);
5026 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mo_sms), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005027 vc_conn.done;
5028}
5029
5030/* Trigger sending of an MT sms via VTY but never respond to anything */
5031private function f_tc_sgsap_mt_sms_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5032 f_init_handler(pars, 170.0);
5033 f_sgs_perform_lu();
5034 f_sleep(1.0);
5035
5036 var SmsParameters spars := valueof(t_SmsPars);
5037 spars.tp.ud := 'C8329BFD064D9B53'O;
5038 var integer page_count := 0;
5039 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5040 var template PDU_SGsAP exp_pag_req := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, SMS_indicator, omit);
5041 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
5042 exp_pag_req.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
5043
5044 /* Trigger SMS via VTY */
5045 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
5046
Neels Hofmeyr16237742019-03-06 15:34:01 +01005047 /* Expect the MSC/VLR to page exactly once */
5048 SGsAP.receive(exp_pag_req);
Harald Welte4263c522018-12-06 11:56:27 +01005049
5050 /* Wait some time to make sure the MSC is not delivering any further
5051 * paging messages or anything else that could be unexpected. */
5052 timer T := 20.0;
5053 T.start
5054 alt {
5055 [] SGsAP.receive(exp_pag_req)
5056 {
5057 setverdict(fail, "paging seems not to stop!");
5058 mtc.stop;
5059 }
5060 [] SGsAP.receive {
5061 setverdict(fail, "unexpected SGsAP message received");
5062 self.stop;
5063 }
5064 [] T.timeout {
5065 setverdict(pass);
5066 }
5067 }
5068
5069 /* Even on a failed paging the SGs Association should stay intact */
5070 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5071
Philipp Maier26bdb8c2019-09-24 09:21:12 +02005072 /* Make sure that the SMS we just inserted is cleared and the
5073 * subscriber is expired. This is necessary because otherwise the MSC
5074 * might re-try the SMS delivery and disturb the following tests. */
Harald Welte4263c522018-12-06 11:56:27 +01005075
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01005076 f_vty_sms_clear(hex2str(g_pars.imsi));
5077
Harald Welte4263c522018-12-06 11:56:27 +01005078 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " expire");
5079
5080 setverdict(pass);
Neels Hofmeyrb0f82342019-03-06 15:36:51 +01005081
5082 f_sgsap_bssmap_screening();
Harald Welte4263c522018-12-06 11:56:27 +01005083}
5084testcase TC_sgsap_mt_sms_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005085 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005086 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005087 f_init(1, true);
5088 pars := f_init_pars(11825, true);
5089 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005090 vc_conn.done;
5091}
5092
5093/* Trigger sending of an MT sms via VTY but reject the paging immediately */
5094private function f_tc_sgsap_mt_sms_and_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5095 f_init_handler(pars, 150.0);
5096 f_sgs_perform_lu();
5097 f_sleep(1.0);
5098
5099 var SmsParameters spars := valueof(t_SmsPars);
5100 spars.tp.ud := 'C8329BFD064D9B53'O;
5101 var integer page_count := 0;
5102 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5103 var template PDU_SGsAP exp_pag_req := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, SMS_indicator, omit);
5104 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
5105 exp_pag_req.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
5106
5107 /* Trigger SMS via VTY */
5108 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
5109
5110 /* Expect a paging request and reject it immediately */
5111 SGsAP.receive(exp_pag_req);
5112 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, IMSI_unknown));
5113
5114 /* The MSC/VLR should no longer try to page once the paging has been
5115 * rejected. Wait some time and check if there are no unexpected
5116 * messages on the SGs interface. */
5117 timer T := 20.0;
5118 T.start
5119 alt {
5120 [] SGsAP.receive(exp_pag_req)
5121 {
5122 setverdict(fail, "paging seems not to stop!");
5123 mtc.stop;
5124 }
5125 [] SGsAP.receive {
5126 setverdict(fail, "unexpected SGsAP message received");
5127 self.stop;
5128 }
5129 [] T.timeout {
5130 setverdict(pass);
5131 }
5132 }
5133
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01005134 f_vty_sms_clear(hex2str(g_pars.imsi));
5135
Harald Welte4263c522018-12-06 11:56:27 +01005136 /* A rejected paging with IMSI_unknown (see above) should always send
5137 * the SGs association to NULL. */
5138 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
5139
5140 f_sgsap_bssmap_screening();
5141
Harald Welte4263c522018-12-06 11:56:27 +01005142 setverdict(pass);
5143}
5144testcase TC_sgsap_mt_sms_and_reject() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005145 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005146 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005147 f_init(1, true);
5148 pars := f_init_pars(11826, true);
5149 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms_and_reject), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005150 vc_conn.done;
5151}
5152
5153/* Perform an MT CSDB call including LU */
5154private function f_mt_lu_and_csfb_call(charstring id, BSC_ConnHdlrPars pars, boolean bssmap_lu) runs on BSC_ConnHdlr {
5155 f_init_handler(pars);
5156
5157 /* Be sure that the BSSMAP reset is done before we begin. */
5158 f_sleep(2.0);
5159
5160 /* Testcase variation: See what happens when we do a regular BSSMAP
5161 * LU first (this should not hurt in any way!) */
5162 if (bssmap_lu) {
5163 f_perform_lu();
5164 }
5165
5166 f_sgs_perform_lu();
5167 f_sleep(1.0);
5168
5169 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5170 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Harald Welte4263c522018-12-06 11:56:27 +01005171
5172 /* Initiate a call via MNCC interface */
5173 f_mt_call_initate(cpars);
5174
5175 /* Expect a paging request and respond accordingly with a service request */
5176 SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit));
5177 SGsAP.send(ts_SGsAP_SERVICE_REQ(pars.imsi, CS_call_indicator, EMM_CONNECTED));
5178
5179 /* Complete the call, hold it for some time and then tear it down */
5180 f_mt_call_complete(cpars);
5181 f_sleep(3.0);
Harald Welte4c422b72019-02-17 16:27:10 +01005182 f_call_hangup(cpars, true, is_csfb := true);
Harald Welte4263c522018-12-06 11:56:27 +01005183
5184 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
5185 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5186
Harald Welte4263c522018-12-06 11:56:27 +01005187 /* Test for successful return by triggering a paging, when the paging
5188 * request is received via SGs, we can be sure that the MSC/VLR has
5189 * recognized that the UE is now back on 4G */
5190 f_sleep(1.0);
5191 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
5192 alt {
5193 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
5194 setverdict(pass);
5195 }
5196 [] SGsAP.receive {
5197 setverdict(fail, "Received unexpected message on SGs");
5198 }
5199 }
5200
5201 f_sgsap_bssmap_screening();
5202
5203 setverdict(pass);
5204}
5205
5206/* Perform a regular BSSAP LU first, do a SGSAP LU and then make a CSFB call */
5207private function f_tc_bssap_lu_sgsap_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5208 f_mt_lu_and_csfb_call(id, pars, true);
5209}
5210testcase TC_bssap_lu_sgsap_lu_and_mt_call() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005211 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005212 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005213 f_init(1, true);
5214 pars := f_init_pars(118139, true);
Harald Welte4263c522018-12-06 11:56:27 +01005215
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005216 vc_conn := f_start_handler_with_pars(refers(f_tc_bssap_lu_sgsap_lu_and_mt_call), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005217 vc_conn.done;
5218}
5219
Harald Welte4263c522018-12-06 11:56:27 +01005220/* Perform a SGSAP LU and then make a CSFB call */
5221private function f_tc_sgsap_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5222 f_mt_lu_and_csfb_call(id, pars, false);
5223}
5224testcase TC_sgsap_lu_and_mt_call() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005225 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005226 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005227 f_init(1, true);
5228 pars := f_init_pars(11827, true);
Harald Welte4263c522018-12-06 11:56:27 +01005229
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005230 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_and_mt_call), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005231 vc_conn.done;
5232}
5233
Philipp Maier628c0052019-04-09 17:36:57 +02005234/* Simulate an HLR/VLR failure */
5235private function f_tc_sgsap_vlr_failure(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5236 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
5237 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5238
5239 var PDU_SGsAP lur;
5240
5241 f_init_handler(pars);
5242
5243 /* Attempt location update (which is expected to fail) */
5244 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
5245 ts_SGsAP_LAI('901'H, '70'H, 2342)));
5246 SGsAP.send(lur);
5247
5248 /* Respond to SGsAP-RESET-INDICATION from VLR */
5249 alt {
5250 [] SGsAP.receive(tr_SGsAP_RESET_IND_VLR(vlr_name)); {
5251 SGsAP.send(valueof(ts_SGsAP_RESET_ACK_MME(mme_name)));
5252 setverdict(pass);
5253 }
5254 [] SGsAP.receive {
5255 setverdict(fail, "Received unexpected message on SGs");
5256 }
5257 }
5258
5259 f_sleep(1.0);
5260 setverdict(pass);
5261}
5262testcase TC_sgsap_vlr_failure() runs on MTC_CT {
5263 var BSC_ConnHdlrPars pars;
5264 var BSC_ConnHdlr vc_conn;
5265 f_init(1, true, false);
5266 pars := f_init_pars(11811, true, false);
5267 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_vlr_failure), pars);
5268 vc_conn.done;
5269}
5270
Harald Welte4263c522018-12-06 11:56:27 +01005271/* SGs TODO:
5272 * LU attempt for IMSI without NAM_PS in HLR
5273 * LU attempt with AUTH FAIL due to invalid RES/SRES
5274 * LU attempt with no response from HLR (VLR should timeout + LU REJ)
5275 * LU attempt with new TMSI but without TMSI REALL CMPL baco to VLR
5276 * implicit IMSI detach from EPS
5277 * implicit IMSI detach from non-EPS
5278 * MM INFO
5279 *
5280 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01005281
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005282private function f_tc_ho_inter_bsc_unknown_cell(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5283 f_init_handler(pars);
5284 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005285
5286 f_perform_lu();
5287 f_mo_call_establish(cpars);
5288
5289 f_sleep(1.0);
5290
5291 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5292 var BssmapCause cause := enum2int(cause_val);
5293
5294 var template BSSMAP_FIELD_CellIdentificationList cil;
5295 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('023'H, '42'H, 999) } };
5296
5297 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5298 BSSAP.receive(tr_BSSMAP_HandoverRequiredReject);
5299
5300 f_call_hangup(cpars, true);
5301}
5302testcase TC_ho_inter_bsc_unknown_cell() runs on MTC_CT {
5303 var BSC_ConnHdlr vc_conn;
5304 f_init();
5305
5306 vc_conn := f_start_handler(refers(f_tc_ho_inter_bsc_unknown_cell), 53);
5307 vc_conn.done;
5308}
5309
5310private altstep as_mgcp_ack_all_mdcx(CallParameters cpars) runs on BSC_ConnHdlr {
5311 var MgcpCommand mgcp_cmd;
5312 [] MGCP.receive(tr_MDCX) -> value mgcp_cmd {
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02005313 var SDP_Message sdp := valueof(ts_SDP(cpars.mgw_conn_2.mgw_rtp_ip, cpars.mgw_conn_2.mgw_rtp_ip,
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005314 hex2str(cpars.mgcp_call_id), "42",
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02005315 cpars.mgw_conn_2.mgw_rtp_port,
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005316 { int2str(cpars.rtp_payload_type) },
5317 { valueof(ts_SDP_rtpmap(cpars.rtp_payload_type,
5318 cpars.rtp_sdp_format)),
5319 valueof(ts_SDP_ptime(20)) }));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02005320 MGCP.send(ts_MDCX_ACK(mgcp_cmd.line.trans_id, cpars.mgw_conn_2.mgcp_connection_id, sdp));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005321 repeat;
5322 }
5323}
5324
5325private function f_tc_ho_inter_bsc0(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5326 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005327
5328 f_init_handler(pars);
5329
5330 f_vty_transceive(MSCVTY, "configure terminal");
5331 f_vty_transceive(MSCVTY, "msc");
5332 f_vty_transceive(MSCVTY, "neighbor a cgi 262 42 23 42 ran-pc 0.24.1");
5333 f_vty_transceive(MSCVTY, "neighbor a lac 5 ran-pc 0.24.2");
5334 f_vty_transceive(MSCVTY, "exit");
5335 f_vty_transceive(MSCVTY, "exit");
5336
5337 f_perform_lu();
5338 f_mo_call_establish(cpars);
5339
5340 f_sleep(1.0);
5341
5342 var default ack_mdcx := activate(as_mgcp_ack_all_mdcx(cpars));
5343
5344 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5345 var BssmapCause cause := enum2int(cause_val);
5346
5347 var template BSSMAP_FIELD_CellIdentificationList cil;
5348 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('023'H, '42'H, 5) } };
5349
5350 /* old BSS sends Handover Required */
5351 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5352
5353 /* Now the action goes on in f_tc_ho_inter_bsc1() */
5354
5355 /* MSC forwards the RR Handover Command to old BSS */
5356 var PDU_BSSAP ho_command;
5357 BSSAP.receive(tr_BSSMAP_HandoverCommand) -> value ho_command;
5358
5359 log("GOT HandoverCommand", ho_command);
5360
5361 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
5362
5363 /* f_tc_ho_inter_bsc1() completes Handover, then expecting a Clear here. */
5364 f_expect_clear();
5365
5366 log("FIRST inter-BSC Handover done");
5367
5368
5369 /* ------------------------ */
5370
5371 /* Ok, that went well, now the other BSC is handovering back here --
5372 * from now on this here is the new BSS. */
5373 f_create_bssmap_exp_handoverRequest(193);
5374
5375 var PDU_BSSAP ho_request;
5376 BSSAP.receive(tr_BSSMAP_HandoverRequest) -> value ho_request;
5377
5378 /* new BSS composes a RR Handover Command */
5379 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5380 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
5381 var BSSMAP_IE_AoIP_TransportLayerAddress tla := valueof(ts_BSSMAP_IE_AoIP_TLA4('01020304'O, 2342));
5382 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5383 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5384
5385 /* Now f_tc_ho_inter_bsc1() expects HandoverCommand */
5386
5387 f_sleep(0.5);
5388
5389 /* Notify that the MS is now over here */
5390
5391 BSSAP.send(ts_BSSMAP_HandoverDetect);
5392 f_sleep(0.1);
5393 BSSAP.send(ts_BSSMAP_HandoverComplete);
5394
5395 f_sleep(3.0);
5396
5397 deactivate(ack_mdcx);
5398
5399 var default ccrel := activate(as_optional_cc_rel(cpars, true));
5400
5401 /* blatant cheating */
5402 var N_Sd_Array last_n_sd := f_bssmap_last_n_sd();
5403 last_n_sd[0] := 3;
5404 f_bssmap_continue_after_n_sd(last_n_sd);
5405
5406 f_call_hangup(cpars, true);
5407 f_sleep(1.0);
5408 deactivate(ccrel);
5409
5410 setverdict(pass);
5411}
5412private function f_tc_ho_inter_bsc1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5413 f_init_handler(pars);
5414 f_create_bssmap_exp_handoverRequest(194);
5415
5416 var PDU_BSSAP ho_request;
5417 BSSAP.receive(tr_BSSMAP_HandoverRequest) -> value ho_request;
5418
5419 /* new BSS composes a RR Handover Command */
5420 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5421 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
5422 var BSSMAP_IE_AoIP_TransportLayerAddress tla := valueof(ts_BSSMAP_IE_AoIP_TLA4('01020304'O, 2342));
5423 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5424 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5425
5426 /* Now f_tc_ho_inter_bsc0() expects HandoverCommand */
5427
5428 f_sleep(0.5);
5429
5430 /* Notify that the MS is now over here */
5431
5432 BSSAP.send(ts_BSSMAP_HandoverDetect);
5433 f_sleep(0.1);
5434 BSSAP.send(ts_BSSMAP_HandoverComplete);
5435
5436 f_sleep(3.0);
5437
5438 /* Now I'd like to f_call_hangup() but we don't know any cpars here. So
5439 * ... handover back to the first BSC :P */
5440
5441 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5442 var BssmapCause cause := enum2int(cause_val);
5443
5444 var template BSSMAP_FIELD_CellIdentificationList cil;
5445 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('262'H, '42'H, 23) } };
5446
5447 /* old BSS sends Handover Required */
5448 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5449
5450 /* Now the action goes on in f_tc_ho_inter_bsc0() */
5451
5452 /* MSC forwards the RR Handover Command to old BSS */
5453 var PDU_BSSAP ho_command;
5454 BSSAP.receive(tr_BSSMAP_HandoverCommand) -> value ho_command;
5455
5456 log("GOT HandoverCommand", ho_command);
5457
5458 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
5459
5460 /* f_tc_ho_inter_bsc1() completes Handover, then expecting a Clear here. */
5461 f_expect_clear();
5462 setverdict(pass);
5463}
5464testcase TC_ho_inter_bsc() runs on MTC_CT {
5465 var BSC_ConnHdlr vc_conn0;
5466 var BSC_ConnHdlr vc_conn1;
5467 f_init(2);
5468
5469 var BSC_ConnHdlrPars pars0 := f_init_pars(53);
5470 var BSC_ConnHdlrPars pars1 := f_init_pars(53);
5471
5472 vc_conn0 := f_start_handler_with_pars(refers(f_tc_ho_inter_bsc0), pars0, 0);
5473 vc_conn1 := f_start_handler_with_pars(refers(f_tc_ho_inter_bsc1), pars1, 1);
5474 vc_conn0.done;
5475 vc_conn1.done;
5476}
5477
5478function f_ML3_patch_seq_nr_MS_NW(in uint2_t seq_nr, inout octetstring enc_l3) {
5479 log("MS_NW patching N(SD)=", seq_nr, " into dtap ", enc_l3);
5480 enc_l3[2] := (enc_l3[2] and4b '3f'O) or4b bit2oct(int2bit(seq_nr, 8) << 6);
5481 log("MS_NW patched enc_l3: ", enc_l3);
5482}
5483
5484private function f_tc_ho_inter_msc_out(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5485 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005486 var hexstring ho_number := f_gen_msisdn(99999);
5487
5488 f_init_handler(pars);
5489
5490 f_create_mncc_expect(hex2str(ho_number));
5491
5492 f_vty_transceive(MSCVTY, "configure terminal");
5493 f_vty_transceive(MSCVTY, "msc");
5494 f_vty_transceive(MSCVTY, "neighbor a cgi 017 017 1 1 msc-ipa-name msc-017-017-1");
5495 f_vty_transceive(MSCVTY, "exit");
5496 f_vty_transceive(MSCVTY, "exit");
5497
5498 f_perform_lu();
5499 f_mo_call_establish(cpars);
5500
5501 f_sleep(1.0);
5502
5503 var default ack_mdcx := activate(as_mgcp_ack_all_mdcx(cpars));
5504
5505 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5506 var BssmapCause cause := enum2int(cause_val);
5507
5508 var template BSSMAP_FIELD_CellIdentificationList cil;
5509 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('017'H, '017'H, 1) } };
5510
5511 /* old BSS sends Handover Required */
5512 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5513
5514 /* The target cell 017-017 LAC 1 is configured to be a remote MSC of name "msc-017-017-1".
5515 * This MSC tries to reach the other MSC via GSUP. */
5516
5517 var octetstring remote_msc_name := '6D73632D3031372D3031372D3100'O; /* "msc-017-017-1\0" as octetstring */
5518 var GSUP_PDU prep_ho_req;
5519 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_HANDOVER_REQUEST,
5520 pars.imsi, destination_name := remote_msc_name)) -> value prep_ho_req;
5521
5522 var GSUP_IeValue source_name_ie;
5523 f_gsup_find_ie(prep_ho_req, OSMO_GSUP_SOURCE_NAME_IE, source_name_ie);
5524 var octetstring local_msc_name := source_name_ie.source_name;
5525
5526 /* Remote MSC has figured out its BSC and signals success */
5527 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5528 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
5529 var PDU_BSSAP ho_req_ack := valueof(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5530 aoIPTransportLayer := omit,
5531 speechCodec := ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5532 GSUP.send(ts_GSUP_E_PrepareHandoverResult(
5533 pars.imsi,
5534 ho_number,
5535 remote_msc_name, local_msc_name,
5536 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006, enc_PDU_BSSAP(ho_req_ack)))));
5537
5538 /* MSC forwards the RR Handover Command to old BSS */
5539 BSSAP.receive(tr_BSSMAP_HandoverCommand);
5540
5541 /* The MS shows up at remote new BSS */
5542
5543 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PROCESS_ACCESS_SIGNALLING_REQUEST,
5544 pars.imsi, remote_msc_name, local_msc_name,
5545 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5546 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverDetect))))));
5547 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
5548 f_sleep(0.1);
5549
5550 /* Save the MS sequence counters for use on the other connection */
5551 var N_Sd_Array last_n_sd := f_bssmap_last_n_sd();
5552
5553 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_SEND_END_SIGNAL_REQUEST,
5554 pars.imsi, remote_msc_name, local_msc_name,
5555 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5556 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverComplete))))));
5557
5558 /* The local BSS conn clears, all communication goes via remote MSC now */
5559 f_expect_clear();
5560
5561 /**********************************/
5562 /* Play through some signalling across the inter-MSC link.
5563 * This is a copy of f_tc_lu_and_mo_ussd_single_request() translated into GSUP AN-APDUs. */
5564
5565 if (false) {
5566 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
5567 invoke_id := 5, /* Phone may not start from 0 or 1 */
5568 op_code := SS_OP_CODE_PROCESS_USS_REQ,
5569 ussd_string := "*#100#"
5570 );
5571
5572 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
5573 invoke_id := 5, /* InvokeID shall be the same for both REQ and RSP */
5574 op_code := SS_OP_CODE_PROCESS_USS_REQ,
5575 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
5576 )
5577
5578 /* Compose a new SS/REGISTER message with request */
5579 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
5580 tid := 1, /* We just need a single transaction */
5581 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
5582 facility := valueof(facility_req)
5583 );
5584 var PDU_ML3_MS_NW ussd_req_v := valueof(ussd_req);
5585
5586 /* Compose SS/RELEASE_COMPLETE template with expected response */
5587 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
5588 tid := 1, /* Response should arrive within the same transaction */
5589 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
5590 facility := valueof(facility_rsp)
5591 );
5592
5593 /* Compose expected MSC -> HLR message */
5594 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
5595 imsi := g_pars.imsi,
5596 state := OSMO_GSUP_SESSION_STATE_BEGIN,
5597 ss := valueof(facility_req)
5598 );
5599
5600 /* To be used for sending response with correct session ID */
5601 var GSUP_PDU gsup_req_complete;
5602
5603 /* Request own number */
5604 /* From remote MSC instead of BSSAP directly */
5605 /* Patch the correct N_SD value into the message. */
5606 var octetstring l3_enc := enc_PDU_ML3_MS_NW(ussd_req_v);
5607 var RAN_Emulation.ConnectionData cd;
5608 f_ML3_patch_seq_nr_MS_NW(f_next_n_sd(last_n_sd, f_ML3_n_sd_idx(ussd_req_v)), l3_enc);
5609 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PROCESS_ACCESS_SIGNALLING_REQUEST,
5610 pars.imsi, remote_msc_name, local_msc_name,
5611 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5612 enc_PDU_BSSAP(valueof(ts_BSSAP_DTAP(l3_enc)))
5613 ))
5614 ));
5615
5616 /* Expect GSUP message containing the SS payload */
5617 gsup_req_complete := f_expect_gsup_msg(gsup_req);
5618
5619 /* Compose the response from HLR using received session ID */
5620 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
5621 imsi := g_pars.imsi,
5622 sid := gsup_req_complete.ies[1].val.session_id,
5623 state := OSMO_GSUP_SESSION_STATE_END,
5624 ss := valueof(facility_rsp)
5625 );
5626
5627 /* Finally, HLR terminates the session */
5628 GSUP.send(gsup_rsp);
5629
5630 /* The USSD response goes out to remote MSC, on GSUP E instead of BSSAP */
5631 var GSUP_PDU gsup_ussd_rsp;
5632 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_FORWARD_ACCESS_SIGNALLING_REQUEST,
5633 pars.imsi, destination_name := remote_msc_name)) -> value gsup_ussd_rsp;
5634
5635 var GSUP_IeValue an_apdu;
5636 if (not f_gsup_find_ie(gsup_ussd_rsp, OSMO_GSUP_AN_APDU_IE, an_apdu)) {
5637 setverdict(fail, "No AN-APDU in received GSUP message. Expected USSD response in DTAP, got", gsup_ussd_rsp);
5638 mtc.stop;
5639 }
5640 var PDU_BSSAP bssap_dtap_mt := dec_PDU_BSSAP(an_apdu.an_apdu.pdu);
5641 var PDU_ML3_NW_MS dtap_mt := dec_PDU_ML3_NW_MS(bssap_dtap_mt.pdu.dtap);
5642 log("Expecting", ussd_rsp);
5643 log("Got", dtap_mt);
5644 if (not match(dtap_mt, ussd_rsp)) {
5645 setverdict(fail, "Unexpected GSUP message. Expected USSD response in DTAP, got", gsup_ussd_rsp);
5646 mtc.stop;
5647 }
5648 }
5649 /**********************************/
5650
5651
5652 /* inter-MSC handover back to the first MSC */
5653 f_create_bssmap_exp_handoverRequest(193);
5654 cil := { cIl_CGI := { ts_BSSMAP_CI_CGI('262'H, '42'H, 23, 42) } };
5655
5656 /* old BSS sends Handover Required, via inter-MSC E link: like
5657 * BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5658 * but via GSUP */
5659 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_SUBSEQUENT_HANDOVER_REQUEST,
5660 pars.imsi, remote_msc_name, local_msc_name,
5661 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5662 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverRequired(cause, cil)))
5663 ))
5664 ));
5665
5666 /* MSC asks local BSS to prepare Handover to it */
5667 BSSAP.receive(tr_BSSMAP_HandoverRequest);
5668
5669 /* Make sure the new BSSAP conn continues with the correct N_SD sequence numbers */
5670 f_bssmap_continue_after_n_sd(last_n_sd);
5671
5672 /* new BSS composes a RR Handover Command */
5673 rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5674 rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
5675 var BSSMAP_IE_AoIP_TransportLayerAddress tla := valueof(ts_BSSMAP_IE_AoIP_TLA4('01020304'O, 2342));
5676 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5677 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5678
5679 /* HandoverCommand goes out via remote MSC-I */
5680 var GSUP_PDU prep_subsq_ho_res;
5681 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_SUBSEQUENT_HANDOVER_RESULT,
5682 pars.imsi, destination_name := remote_msc_name)) -> value prep_subsq_ho_res;
5683
5684 /* MS shows up at the local BSS */
5685 BSSAP.send(ts_BSSMAP_HandoverDetect);
5686 f_sleep(0.1);
5687 BSSAP.send(ts_BSSMAP_HandoverComplete);
5688
5689 /* Handover Succeeded message */
5690 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_FORWARD_ACCESS_SIGNALLING_REQUEST,
5691 pars.imsi, destination_name := remote_msc_name));
5692
5693 /* MS has handovered to here, Clear Command goes out via remote MSC-I -- in form of a GSUP Close. */
5694 GSUP.receive(tr_GSUP_E_NO_PDU(OSMO_GSUP_MSGT_E_CLOSE,
5695 pars.imsi, destination_name := remote_msc_name));
5696
5697 /* Handover ends successfully. Call goes on for a little longer and then we hang up. */
5698
5699 f_sleep(1.0);
5700 deactivate(ack_mdcx);
5701
5702 /* FIXME: the inter-MSC call has put a number of MNCC messages in the queue, which above code should expect and
5703 * clear out. The f_call_hangup() expects an MNCC_REL_IND, so, for the time being, just clear the MNCC messages
5704 * before starting the call hangup. Instead of this, the individual messages should be tested for above. */
5705 MNCC.clear;
5706
5707 var default ccrel := activate(as_optional_cc_rel(cpars, true));
5708 f_call_hangup(cpars, true);
5709 f_sleep(1.0);
5710 deactivate(ccrel);
5711
5712 setverdict(pass);
5713}
5714testcase TC_ho_inter_msc_out() runs on MTC_CT {
5715 var BSC_ConnHdlr vc_conn;
5716 f_init(1);
5717
5718 var BSC_ConnHdlrPars pars := f_init_pars(54);
5719
5720 vc_conn := f_start_handler_with_pars(refers(f_tc_ho_inter_msc_out), pars, 0);
5721 vc_conn.done;
5722}
5723
Oliver Smith1d118ff2019-07-03 10:57:35 +02005724private function f_tc_lu_imsi_auth_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5725 pars.net.expect_auth := true;
5726 pars.net.expect_imei := true;
5727 f_init_handler(pars);
5728 f_perform_lu();
5729}
5730testcase TC_lu_imsi_auth_tmsi_check_imei() runs on MTC_CT {
5731 var BSC_ConnHdlr vc_conn;
5732 f_init();
5733 f_vty_config(MSCVTY, "network", "authentication required");
5734 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
5735
5736 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei), 5);
5737 vc_conn.done;
5738}
5739
5740private function f_tc_lu_imsi_auth3g_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5741 pars.net.expect_auth := true;
5742 pars.use_umts_aka := true;
5743 pars.net.expect_imei := true;
5744 f_init_handler(pars);
5745 f_perform_lu();
5746}
5747testcase TC_lu_imsi_auth3g_tmsi_check_imei() runs on MTC_CT {
5748 var BSC_ConnHdlr vc_conn;
5749 f_init();
5750 f_vty_config(MSCVTY, "network", "authentication required");
5751 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
5752
5753 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi_check_imei), 5);
5754 vc_conn.done;
5755}
5756
5757private function f_tc_lu_imsi_noauth_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5758 pars.net.expect_imei := true;
5759 f_init_handler(pars);
5760 f_perform_lu();
5761}
5762testcase TC_lu_imsi_noauth_tmsi_check_imei() runs on MTC_CT {
5763 var BSC_ConnHdlr vc_conn;
5764 f_init();
5765 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
5766
5767 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi_check_imei), 5);
5768 vc_conn.done;
5769}
5770
5771private function f_tc_lu_imsi_noauth_notmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5772 pars.net.expect_tmsi := false;
5773 pars.net.expect_imei := true;
5774 f_init_handler(pars);
5775 f_perform_lu();
5776}
5777testcase TC_lu_imsi_noauth_notmsi_check_imei() runs on MTC_CT {
5778 var BSC_ConnHdlr vc_conn;
5779 f_init();
5780 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
5781 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
5782
5783 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi_check_imei), 5);
5784 vc_conn.done;
5785}
5786
5787private function f_tc_lu_imsi_auth_tmsi_check_imei_nack(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5788 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02005789
5790 pars.net.expect_auth := true;
5791 pars.net.expect_imei := true;
5792 pars.net.check_imei_result := OSMO_GSUP_IMEI_RESULT_NACK;
5793 f_init_handler(pars);
5794
5795 /* Cannot use f_perform_lu() as we expect a reject */
5796 l3_lu := f_build_lu_imsi(g_pars.imsi)
5797 f_create_gsup_expect(hex2str(g_pars.imsi));
5798 f_bssap_compl_l3(l3_lu);
5799 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
5800
5801 f_mm_common();
5802 f_msc_lu_hlr();
5803 f_mm_imei();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02005804 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02005805 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02005806}
5807testcase TC_lu_imsi_auth_tmsi_check_imei_nack() runs on MTC_CT {
5808 var BSC_ConnHdlr vc_conn;
5809 f_init();
5810 f_vty_config(MSCVTY, "network", "authentication required");
5811 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
5812
5813 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_nack), 5);
5814 vc_conn.done;
5815}
5816
5817private function f_tc_lu_imsi_auth_tmsi_check_imei_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5818 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02005819
5820 pars.net.expect_auth := true;
5821 pars.net.expect_imei := true;
5822 pars.net.check_imei_error := true;
5823 f_init_handler(pars);
5824
5825 /* Cannot use f_perform_lu() as we expect a reject */
5826 l3_lu := f_build_lu_imsi(g_pars.imsi)
5827 f_create_gsup_expect(hex2str(g_pars.imsi));
5828 f_bssap_compl_l3(l3_lu);
5829 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
5830
5831 f_mm_common();
5832 f_msc_lu_hlr();
5833 f_mm_imei();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02005834 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02005835 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02005836}
5837testcase TC_lu_imsi_auth_tmsi_check_imei_err() runs on MTC_CT {
5838 var BSC_ConnHdlr vc_conn;
5839 f_init();
5840 f_vty_config(MSCVTY, "network", "authentication required");
5841 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
5842
5843 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_err), 5);
5844 vc_conn.done;
5845}
5846
5847private function f_tc_lu_imsi_auth_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5848 pars.net.expect_auth := true;
5849 pars.net.expect_imei_early := true;
5850 f_init_handler(pars);
5851 f_perform_lu();
5852}
5853testcase TC_lu_imsi_auth_tmsi_check_imei_early() runs on MTC_CT {
5854 var BSC_ConnHdlr vc_conn;
5855 f_init();
5856 f_vty_config(MSCVTY, "network", "authentication required");
5857 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
5858
5859 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early), 5);
5860 vc_conn.done;
5861}
5862
5863private function f_tc_lu_imsi_auth3g_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5864 pars.net.expect_auth := true;
5865 pars.use_umts_aka := true;
5866 pars.net.expect_imei_early := true;
5867 f_init_handler(pars);
5868 f_perform_lu();
5869}
5870testcase TC_lu_imsi_auth3g_tmsi_check_imei_early() runs on MTC_CT {
5871 var BSC_ConnHdlr vc_conn;
5872 f_init();
5873 f_vty_config(MSCVTY, "network", "authentication required");
5874 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
5875
5876 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi_check_imei_early), 5);
5877 vc_conn.done;
5878}
5879
5880private function f_tc_lu_imsi_noauth_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5881 pars.net.expect_imei_early := true;
5882 f_init_handler(pars);
5883 f_perform_lu();
5884}
5885testcase TC_lu_imsi_noauth_tmsi_check_imei_early() runs on MTC_CT {
5886 var BSC_ConnHdlr vc_conn;
5887 f_init();
5888 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
5889
5890 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi_check_imei_early), 5);
5891 vc_conn.done;
5892}
5893
5894private function f_tc_lu_imsi_noauth_notmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5895 pars.net.expect_tmsi := false;
5896 pars.net.expect_imei_early := true;
5897 f_init_handler(pars);
5898 f_perform_lu();
5899}
5900testcase TC_lu_imsi_noauth_notmsi_check_imei_early() runs on MTC_CT {
5901 var BSC_ConnHdlr vc_conn;
5902 f_init();
5903 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
5904 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
5905
5906 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi_check_imei_early), 5);
5907 vc_conn.done;
5908}
5909
5910private function f_tc_lu_imsi_auth_tmsi_check_imei_early_nack(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5911 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02005912
5913 pars.net.expect_auth := true;
5914 pars.net.expect_imei_early := true;
5915 pars.net.check_imei_result := OSMO_GSUP_IMEI_RESULT_NACK;
5916 f_init_handler(pars);
5917
5918 /* Cannot use f_perform_lu() as we expect a reject */
5919 l3_lu := f_build_lu_imsi(g_pars.imsi)
5920 f_create_gsup_expect(hex2str(g_pars.imsi));
5921 f_bssap_compl_l3(l3_lu);
5922 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
5923
5924 f_mm_imei_early();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02005925 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02005926 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02005927}
5928testcase TC_lu_imsi_auth_tmsi_check_imei_early_nack() runs on MTC_CT {
5929 var BSC_ConnHdlr vc_conn;
5930 f_init();
5931 f_vty_config(MSCVTY, "network", "authentication required");
5932 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
5933
5934 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early_nack), 5);
5935 vc_conn.done;
5936}
5937
5938private function f_tc_lu_imsi_auth_tmsi_check_imei_early_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5939 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02005940
5941 pars.net.expect_auth := true;
5942 pars.net.expect_imei_early := true;
5943 pars.net.check_imei_error := true;
5944 f_init_handler(pars);
5945
5946 /* Cannot use f_perform_lu() as we expect a reject */
5947 l3_lu := f_build_lu_imsi(g_pars.imsi)
5948 f_create_gsup_expect(hex2str(g_pars.imsi));
5949 f_bssap_compl_l3(l3_lu);
5950 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
5951
5952 f_mm_imei_early();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02005953 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02005954 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02005955}
5956testcase TC_lu_imsi_auth_tmsi_check_imei_early_err() runs on MTC_CT {
5957 var BSC_ConnHdlr vc_conn;
5958 f_init();
5959 f_vty_config(MSCVTY, "network", "authentication required");
5960 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
5961
5962 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early_err), 5);
5963 vc_conn.done;
5964}
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005965
Neels Hofmeyr8df69622019-11-02 19:16:03 +01005966friend function f_tc_invalid_mgcp_crash(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5967 f_init_handler(pars);
5968 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
5969
5970 /* Set invalid IP address so that osmo-msc discards the rtp_stream and MGCP endpoint FSM instances in the middle
5971 * of successful MGCP response dispatch. If things aren't safeguarded, the on_success() in osmo_mgcpc_ep_fsm
5972 * will cause a use-after-free after that event dispatch. */
5973 cpars.mgw_conn_1.mgw_rtp_ip := "0.0.0.0";
5974 cpars.mgw_conn_2.mgw_rtp_ip := "0.0.0.0";
5975 cpars.rtp_sdp_format := "FOO/8000";
5976 cpars.expect_release := true;
5977
5978 f_perform_lu();
5979 f_mo_call_establish(cpars);
5980}
5981testcase TC_invalid_mgcp_crash() runs on MTC_CT {
5982 var BSC_ConnHdlr vc_conn;
5983 f_init();
5984
5985 vc_conn := f_start_handler(refers(f_tc_invalid_mgcp_crash), 7);
5986 vc_conn.done;
5987}
5988
Vadim Yanitskiyeddebaa2019-12-28 17:45:34 +01005989friend function f_tc_mm_id_resp_no_identity(charstring id, BSC_ConnHdlrPars pars)
5990runs on BSC_ConnHdlr {
5991 pars.tmsi := 'FFFFFFFF'O;
5992 f_init_handler(pars);
5993
5994 f_create_gsup_expect(hex2str(g_pars.imsi));
5995
5996 /* Initiate Location Updating using an unknown TMSI */
5997 f_bssap_compl_l3(f_build_lu_tmsi(pars.tmsi));
5998
5999 /* Expect an Identity Request, send response with no identity */
6000 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
6001 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp({
6002 lengthIndicator := 1,
6003 mobileIdentityV := {
6004 typeOfIdentity := '000'B,
6005 oddEvenInd_identity := {
6006 no_identity := {
6007 oddevenIndicator := '0'B,
6008 fillerDigits := '00000'H
6009 }
6010 }
6011 }
6012 })));
6013
6014 f_expect_lu_reject();
6015 f_expect_clear();
6016}
6017testcase TC_mm_id_resp_no_identity() runs on MTC_CT {
6018 var BSC_ConnHdlr vc_conn;
6019
6020 f_init();
6021
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02006022 vc_conn := f_start_handler(refers(f_tc_mm_id_resp_no_identity), 7, verify_cell_id := false);
Vadim Yanitskiyeddebaa2019-12-28 17:45:34 +01006023 vc_conn.done;
6024}
6025
Vadim Yanitskiy25219062020-01-21 01:41:33 +07006026/* Verify the case when T3212 expires during Paging procedure, just before the receipt
6027 * of Paging Response. This used to provoke a NULL-pointer dereference in old versions
6028 * of OsmoMSC, but apparently the bug has been fixed, and we're safe now. */
6029friend function f_tc_lu_and_expire_while_paging(charstring id, BSC_ConnHdlrPars pars)
6030runs on BSC_ConnHdlr {
6031 var charstring imsi := hex2str(pars.imsi);
6032
6033 f_init_handler(pars);
6034
6035 /* Perform location update */
6036 f_perform_lu();
6037
6038 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
6039 f_create_gsup_expect(hex2str(g_pars.imsi));
6040
6041 /* Initiate paging procedure from the VTY */
6042 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " paging");
6043 f_expect_paging();
6044
6045 /* Emulate T3212 expiration during paging (we don't want to wait, right?) */
6046 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " expire");
6047
6048 /* MS sends PAGING RESPONSE, *old* OsmoMSC crashes here... */
6049 f_establish_fully(EST_TYPE_PAG_RESP);
6050
6051 /* The recent OsmoMSC keeps subscriber in its VLR unless the Paging is completed.
6052 * In this case we do not send anything and just wait for a Clear Command. */
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02006053 f_expect_clear(verify_vlr_cell_id := false);
Vadim Yanitskiy25219062020-01-21 01:41:33 +07006054}
6055testcase TC_lu_and_expire_while_paging() runs on MTC_CT {
6056 var BSC_ConnHdlr vc_conn;
6057
6058 f_init();
6059
6060 vc_conn := f_start_handler(refers(f_tc_lu_and_expire_while_paging), 7);
6061 vc_conn.done;
6062}
6063
Harald Weltef6dd64d2017-11-19 12:09:51 +01006064control {
Philipp Maier328d1662018-03-07 10:40:27 +01006065 execute( TC_cr_before_reset() );
Harald Weltea49e36e2018-01-21 19:29:33 +01006066 execute( TC_lu_imsi_noauth_tmsi() );
Harald Welted2328a22018-01-27 14:27:16 +01006067 execute( TC_lu_imsi_noauth_notmsi() );
Harald Weltea49e36e2018-01-21 19:29:33 +01006068 execute( TC_lu_imsi_reject() );
6069 execute( TC_lu_imsi_timeout_gsup() );
Harald Welted2328a22018-01-27 14:27:16 +01006070 execute( TC_lu_imsi_auth_tmsi() );
Harald Welte8a397ae2019-04-21 22:03:37 +02006071 execute( TC_lu_imsi_auth3g_tmsi() );
Pau Espin Pedrold3d54a92019-12-17 17:02:54 +01006072 execute( TC_lu_imsi_timeout_tmsi_realloc() );
Harald Welted2328a22018-01-27 14:27:16 +01006073 execute( TC_cmserv_imsi_unknown() );
Harald Welte2bb825f2018-01-22 11:31:18 +01006074 execute( TC_lu_and_mo_call() );
Pau Espin Pedrola42745c2020-01-10 18:03:28 +01006075 execute( TC_lu_and_mo_call_sccp_tiar_timeout() );
Harald Welte071ed732018-01-23 19:53:52 +01006076 execute( TC_lu_auth_sai_timeout() );
6077 execute( TC_lu_auth_sai_err() );
Harald Weltee1a2f3c2018-01-24 17:28:48 +01006078 execute( TC_lu_clear_request() );
6079 execute( TC_lu_disconnect() );
6080 execute( TC_lu_by_imei() );
6081 execute( TC_lu_by_tmsi_noauth_unknown() );
6082 execute( TC_imsi_detach_by_imsi() );
6083 execute( TC_imsi_detach_by_tmsi() );
6084 execute( TC_imsi_detach_by_imei() );
6085 execute( TC_emerg_call_imei_reject() );
6086 execute( TC_emerg_call_imsi() );
6087 execute( TC_cm_serv_req_vgcs_reject() );
6088 execute( TC_cm_serv_req_vbs_reject() );
6089 execute( TC_cm_serv_req_lcs_reject() );
Harald Welte0195ab12018-01-24 21:50:20 +01006090 execute( TC_cm_reest_req_reject() );
Harald Welte1af6ea82018-01-25 18:33:15 +01006091 execute( TC_lu_auth_2G_fail() );
6092 execute( TC_lu_imsi_auth_tmsi_encr_13_13() );
6093 execute( TC_cl3_no_payload() );
6094 execute( TC_cl3_rnd_payload() );
Harald Welte1852a842018-01-26 22:53:36 +01006095 execute( TC_establish_and_nothing() );
6096 execute( TC_mo_setup_and_nothing() );
6097 execute( TC_mo_crcx_ran_timeout() );
6098 execute( TC_mo_crcx_ran_reject() );
Harald Welted2328a22018-01-27 14:27:16 +01006099 execute( TC_mt_crcx_ran_reject() );
Daniel Willmann8b084372018-02-04 13:35:26 +01006100 execute( TC_mo_setup_and_dtmf_dup() );
Harald Welteaa54cf82018-01-30 08:15:32 +01006101 //execute( TC_mt_t310() );
Harald Welte167458a2018-01-27 15:58:16 +01006102 execute( TC_gsup_cancel() );
Harald Welte9de84792018-01-28 01:06:35 +01006103 execute( TC_lu_imsi_auth_tmsi_encr_1_13() );
6104 execute( TC_lu_imsi_auth_tmsi_encr_3_13() );
6105 execute( TC_lu_imsi_auth_tmsi_encr_3_1() );
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01006106 execute( TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() );
Harald Welte9de84792018-01-28 01:06:35 +01006107 execute( TC_lu_imsi_auth_tmsi_encr_13_2() );
6108 execute( TC_lu_imsi_auth_tmsi_encr_013_2() );
Philipp Maier94f3f1b2018-03-15 18:54:13 +01006109 execute( TC_mo_release_timeout() );
Philipp Maier2a98a732018-03-19 16:06:12 +01006110 execute( TC_lu_and_mt_call_no_dlcx_resp() );
Philipp Maier75932982018-03-27 14:52:35 +02006111 execute( TC_reset_two() );
Harald Welte33ec09b2018-02-10 15:34:46 +01006112
6113 execute( TC_lu_and_mt_call() );
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01006114 execute( TC_lu_and_mt_call_already_paging() );
Harald Welte33ec09b2018-02-10 15:34:46 +01006115
Harald Weltef45efeb2018-04-09 18:19:24 +02006116 execute( TC_lu_and_mo_sms() );
6117 execute( TC_lu_and_mt_sms() );
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01006118 execute( TC_lu_and_mt_sms_already_paging() );
Philipp Maier3983e702018-11-22 19:01:33 +01006119 execute( TC_lu_and_mt_sms_paging_and_nothing() );
Alexander Couzensfc02f242019-09-12 03:43:18 +02006120 execute( TC_lu_and_mt_sms_paging_repeated() );
Harald Weltef640a012018-04-14 17:49:21 +02006121 execute( TC_smpp_mo_sms() );
Vadim Yanitskiy33820762020-01-15 11:26:07 +07006122 execute( TC_smpp_mo_sms_rp_error() );
Harald Weltef640a012018-04-14 17:49:21 +02006123 execute( TC_smpp_mt_sms() );
Harald Weltef45efeb2018-04-09 18:19:24 +02006124
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07006125 execute( TC_gsup_mo_sms() );
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07006126 execute( TC_gsup_mo_smma() );
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07006127 execute( TC_gsup_mt_sms_ack() );
6128 execute( TC_gsup_mt_sms_err() );
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07006129 execute( TC_gsup_mt_sms_rp_mr() );
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07006130 execute( TC_gsup_mo_mt_sms_rp_mr() );
Vadim Yanitskiya2a8a112019-07-08 20:04:32 +07006131 execute( TC_gsup_mt_multi_part_sms() );
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07006132
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07006133 execute( TC_lu_and_mo_ussd_single_request() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07006134 execute( TC_lu_and_mt_ussd_notification() );
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07006135 execute( TC_lu_and_mo_ussd_during_mt_call() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07006136 execute( TC_lu_and_mt_ussd_during_mt_call() );
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07006137 execute( TC_lu_and_mo_ussd_mo_release() );
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07006138 execute( TC_lu_and_ss_session_timeout() );
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07006139
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07006140 execute( TC_mt_ussd_for_unknown_subscr() );
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07006141 execute( TC_mo_ussd_for_unknown_trans() );
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07006142 execute( TC_proc_ss_for_unknown_session() );
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07006143 execute( TC_proc_ss_paging_fail() );
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07006144 execute( TC_proc_ss_abort() );
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07006145
Vadim Yanitskiy1c9754d2020-01-07 21:56:55 +01006146 execute( TC_multi_lu_and_mo_ussd() );
6147 execute( TC_multi_lu_and_mt_ussd() );
6148
Stefan Sperling89eb1f32018-12-17 15:06:20 +01006149 execute( TC_cipher_complete_with_invalid_cipher() );
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01006150 execute( TC_cipher_complete_1_without_cipher() );
6151 execute( TC_cipher_complete_3_without_cipher() );
6152 execute( TC_cipher_complete_13_without_cipher() );
Harald Welteb2284bd2019-05-10 11:30:43 +02006153 execute( TC_lu_with_invalid_mcc_mnc() );
Stefan Sperling89eb1f32018-12-17 15:06:20 +01006154
Harald Welte4263c522018-12-06 11:56:27 +01006155 execute( TC_sgsap_reset() );
6156 execute( TC_sgsap_lu() );
6157 execute( TC_sgsap_lu_imsi_reject() );
6158 execute( TC_sgsap_lu_and_nothing() );
6159 execute( TC_sgsap_expl_imsi_det_eps() );
Philipp Maierfc19f172019-03-21 11:17:54 +01006160 execute( TC_sgsap_impl_imsi_det_eps() );
Harald Welte4263c522018-12-06 11:56:27 +01006161 execute( TC_sgsap_expl_imsi_det_noneps() );
Philipp Maier5d812702019-03-21 10:51:26 +01006162 execute( TC_sgsap_impl_imsi_det_noneps() );
Harald Welte4263c522018-12-06 11:56:27 +01006163 execute( TC_sgsap_paging_rej() );
6164 execute( TC_sgsap_paging_subscr_rej() );
6165 execute( TC_sgsap_paging_ue_unr() );
6166 execute( TC_sgsap_paging_and_nothing() );
6167 execute( TC_sgsap_paging_and_lu() );
6168 execute( TC_sgsap_mt_sms() );
6169 execute( TC_sgsap_mo_sms() );
6170 execute( TC_sgsap_mt_sms_and_nothing() );
6171 execute( TC_sgsap_mt_sms_and_reject() );
6172 execute( TC_sgsap_unexp_ud() );
6173 execute( TC_sgsap_unsol_ud() );
6174 execute( TC_bssap_lu_sgsap_lu_and_mt_call() );
6175 execute( TC_sgsap_lu_and_mt_call() );
Philipp Maier628c0052019-04-09 17:36:57 +02006176 execute( TC_sgsap_vlr_failure() );
Harald Welte4263c522018-12-06 11:56:27 +01006177
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006178 execute( TC_ho_inter_bsc_unknown_cell() );
6179 execute( TC_ho_inter_bsc() );
6180
6181 execute( TC_ho_inter_msc_out() );
6182
Oliver Smith1d118ff2019-07-03 10:57:35 +02006183 execute( TC_lu_imsi_auth_tmsi_check_imei() );
6184 execute( TC_lu_imsi_auth3g_tmsi_check_imei() );
6185 execute( TC_lu_imsi_noauth_tmsi_check_imei() );
6186 execute( TC_lu_imsi_noauth_notmsi_check_imei() );
6187 execute( TC_lu_imsi_auth_tmsi_check_imei_nack() );
6188 execute( TC_lu_imsi_auth_tmsi_check_imei_err() );
6189 execute( TC_lu_imsi_auth_tmsi_check_imei_early() );
6190 execute( TC_lu_imsi_auth3g_tmsi_check_imei_early() );
6191 execute( TC_lu_imsi_noauth_tmsi_check_imei_early() );
6192 execute( TC_lu_imsi_noauth_notmsi_check_imei_early() );
6193 execute( TC_lu_imsi_auth_tmsi_check_imei_early_nack() );
6194 execute( TC_lu_imsi_auth_tmsi_check_imei_early_err() );
6195
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01006196 /* Run this last: at the time of writing this test crashes the MSC */
6197 execute( TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() );
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02006198 execute( TC_mo_cc_bssmap_clear() );
Pau Espin Pedrol690d6592019-05-31 17:56:32 +02006199 if (mp_enable_osmux_test) {
6200 execute( TC_lu_and_mt_call_osmux() );
6201 }
Neels Hofmeyr8df69622019-11-02 19:16:03 +01006202 execute( TC_invalid_mgcp_crash() );
Vadim Yanitskiyeddebaa2019-12-28 17:45:34 +01006203 execute( TC_mm_id_resp_no_identity() );
Vadim Yanitskiy25219062020-01-21 01:41:33 +07006204 execute( TC_lu_and_expire_while_paging() );
Harald Weltef6dd64d2017-11-19 12:09:51 +01006205}
6206
6207
6208}