blob: 5129c5bd3f54fcf2a05648d71791ad83d67d50ce [file] [log] [blame]
Harald Weltef6dd64d2017-11-19 12:09:51 +01001module MSC_Tests {
2
Harald Welte34b5a952019-05-27 11:54:11 +02003/* Osmocom MSC test suite in in TTCN-3
4 * (C) 2017-2019 Harald Welte <laforge@gnumonks.org>
5 * (C) 2018-2019 sysmocom - s.f.m.c. GmbH
6 * (C) 2018-2019 Vadim Yanitskiy <axilirator@gmail.com>
7 * All rights reserved.
8 *
9 * Released under the terms of GNU General Public License, Version 2 or
10 * (at your option) any later version.
11 *
12 * SPDX-License-Identifier: GPL-2.0-or-later
13 */
14
Harald Weltee13cfb22019-04-23 16:52:02 +020015friend module MSC_Tests_Iu;
16
Harald Weltef6dd64d2017-11-19 12:09:51 +010017import from General_Types all;
18import from Osmocom_Types all;
19
20import from M3UA_Types all;
21import from M3UA_Emulation all;
22
23import from MTP3asp_Types all;
24import from MTP3asp_PortType all;
25
26import from SCCPasp_Types all;
27import from SCCP_Types all;
28import from SCCP_Emulation all;
29
30import from SCTPasp_Types all;
31import from SCTPasp_PortType all;
32
Harald Weltea49e36e2018-01-21 19:29:33 +010033import from Osmocom_CTRL_Functions all;
34import from Osmocom_CTRL_Types all;
35import from Osmocom_CTRL_Adapter all;
36
Harald Welte3ca1c902018-01-24 18:51:27 +010037import from TELNETasp_PortType all;
38import from Osmocom_VTY_Functions all;
39
Harald Weltea49e36e2018-01-21 19:29:33 +010040import from MNCC_Emulation all;
Harald Welte2bb825f2018-01-22 11:31:18 +010041import from MNCC_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010042
Harald Welte4aa970c2018-01-26 10:38:09 +010043import from MGCP_Emulation all;
44import from MGCP_Types all;
45import from MGCP_Templates all;
46import from SDP_Types all;
47
Harald Weltea49e36e2018-01-21 19:29:33 +010048import from GSUP_Emulation all;
49import from GSUP_Types all;
50import from IPA_Emulation all;
51
Harald Weltef6dd64d2017-11-19 12:09:51 +010052import from BSSAP_Types all;
Harald Welte6811d102019-04-14 22:23:14 +020053import from RAN_Adapter all;
Harald Weltea49e36e2018-01-21 19:29:33 +010054import from BSSAP_CodecPort all;
55import from BSSMAP_Templates all;
Harald Welte6811d102019-04-14 22:23:14 +020056import from RAN_Emulation all;
Harald Weltea49e36e2018-01-21 19:29:33 +010057import from BSC_ConnectionHandler all;
Harald Weltee13cfb22019-04-23 16:52:02 +020058import from RANAP_Templates all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010059
Harald Welte4263c522018-12-06 11:56:27 +010060import from SGsAP_Templates all;
61import from SGsAP_Types all;
62import from SGsAP_Emulation all;
63
Harald Weltea49e36e2018-01-21 19:29:33 +010064import from MobileL3_Types all;
65import from MobileL3_CommonIE_Types all;
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +070066import from MobileL3_SMS_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010067import from L3_Templates all;
Harald Welte158a7ca2018-02-16 18:11:31 +010068import from L3_Common all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010069
Harald Weltef640a012018-04-14 17:49:21 +020070import from SMPP_Types all;
71import from SMPP_Templates all;
72import from SMPP_Emulation all;
73
Stefan Sperlingc307e682018-06-14 15:15:46 +020074import from SCCP_Templates all;
75
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070076import from SS_Types all;
77import from SS_Templates all;
78import from USSD_Helpers all;
Harald Welte4263c522018-12-06 11:56:27 +010079import from DNS_Helpers all;
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070080
Philipp Maier948747b2019-04-02 15:22:33 +020081import from TCCConversion_Functions all;
82
Harald Welte9b751a62019-04-14 17:39:29 +020083const integer NUM_BSC := 3;
Harald Weltef6dd64d2017-11-19 12:09:51 +010084
Harald Welte4263c522018-12-06 11:56:27 +010085/* Needed for SGsAP SMS */
86import from MobileL3_SMS_Types all;
87
Harald Weltea4ca4462018-02-09 00:17:14 +010088type component MTC_CT extends CTRL_Adapter_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +010089 var boolean g_initialized := false;
Harald Weltea49e36e2018-01-21 19:29:33 +010090
Harald Welte6811d102019-04-14 22:23:14 +020091 var RAN_Adapter g_bssap[NUM_BSC];
Harald Weltea4ca4462018-02-09 00:17:14 +010092
Harald Weltea49e36e2018-01-21 19:29:33 +010093 /* no 'adapter_CT' for MNCC or GSUP */
94 var MNCC_Emulation_CT vc_MNCC;
Harald Welte4aa970c2018-01-26 10:38:09 +010095 var MGCP_Emulation_CT vc_MGCP;
Harald Weltea49e36e2018-01-21 19:29:33 +010096 var GSUP_Emulation_CT vc_GSUP;
97 var IPA_Emulation_CT vc_GSUP_IPA;
Harald Weltef640a012018-04-14 17:49:21 +020098 var SMPP_Emulation_CT vc_SMPP;
Harald Welte4263c522018-12-06 11:56:27 +010099 var SGsAP_Emulation_CT vc_SGsAP;
Harald Weltea49e36e2018-01-21 19:29:33 +0100100
101 /* only to get events from IPA underneath GSUP */
102 port IPA_CTRL_PT GSUP_IPA_EVENT;
Harald Welte3ca1c902018-01-24 18:51:27 +0100103 /* VTY to MSC */
104 port TELNETasp_PT MSCVTY;
Philipp Maier328d1662018-03-07 10:40:27 +0100105
106 /* A port to directly send BSSAP messages. This port is used for
107 * tests that require low level access to sen arbitrary BSSAP
108 * messages. Run f_init_bssap_direct() to connect and initialize */
109 port BSSAP_CODEC_PT BSSAP_DIRECT;
110
111 /* When BSSAP messages are directly sent, then the connection
112 * handler is not active, which means that also no guard timer is
113 * set up. The following timer will serve as a replacement */
114 timer Tguard_direct := 60.0;
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100115
116 /* Configure T(tias) over VTY, seconds */
117 var integer g_msc_sccp_timer_ias := 7 * 60;
118 /* Configure T(tiar) over VTY, seconds */
119 var integer g_msc_sccp_timer_iar := 15 * 60;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100120}
121
122modulepar {
Harald Weltea49e36e2018-01-21 19:29:33 +0100123 /* remote parameters of IUT */
124 charstring mp_msc_ip := "127.0.0.1";
125 integer mp_msc_ctrl_port := 4255;
126 integer mp_msc_vty_port := 4254;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100127
Harald Weltea49e36e2018-01-21 19:29:33 +0100128 /* local parameters of emulated HLR */
Philipp Maier9b690e42018-12-21 11:50:03 +0100129 boolean mp_mm_info := false;
Harald Weltea49e36e2018-01-21 19:29:33 +0100130 charstring mp_hlr_ip := "127.0.0.1";
131 integer mp_hlr_port := 4222;
Harald Welte6126fb02018-01-27 20:08:24 +0100132 charstring mp_mgw_ip := "127.0.0.1";
133 integer mp_mgw_port := 2427;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100134
Harald Weltea49e36e2018-01-21 19:29:33 +0100135 charstring mp_msc_mncc := "/tmp/mncc";
Harald Weltea4ca4462018-02-09 00:17:14 +0100136
Harald Weltef640a012018-04-14 17:49:21 +0200137 integer mp_msc_smpp_port := 2775;
138 charstring mp_smpp_system_id := "msc_tester";
139 charstring mp_smpp_password := "osmocom1";
Harald Welte4263c522018-12-06 11:56:27 +0100140 charstring mp_mme_name := "mmec01.mmegi0001.mme.epc.mnc070.mcc901.3gppnetwork.org";
141 charstring mp_vlr_name := "vlr.example.net";
Harald Weltef640a012018-04-14 17:49:21 +0200142
Harald Welte6811d102019-04-14 22:23:14 +0200143 RAN_Configurations mp_bssap_cfg := {
Philipp Maier75932982018-03-27 14:52:35 +0200144 {
145 sccp_service_type := "mtp3_itu",
146 sctp_addr := { 23905, "127.0.0.1", 2905, "127.0.0.1" },
147 own_pc := 185,
148 own_ssn := 254,
149 peer_pc := 187,
150 peer_ssn := 254,
151 sio := '83'O,
152 rctx := 0
153 },
154 {
155 sccp_service_type := "mtp3_itu",
156 sctp_addr := { 23906, "127.0.0.1", 2905, "127.0.0.1" },
157 own_pc := 186,
158 own_ssn := 254,
159 peer_pc := 187,
160 peer_ssn := 254,
161 sio := '83'O,
162 rctx := 1
163 }
Harald Weltea4ca4462018-02-09 00:17:14 +0100164 };
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200165
166 boolean mp_enable_cell_id_test := true;
Pau Espin Pedrol609f1d62020-09-15 16:01:55 +0200167
168 boolean mp_enable_crashing_tests := true;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100169}
170
Philipp Maier328d1662018-03-07 10:40:27 +0100171/* altstep for the global guard timer (only used when BSSAP_DIRECT
172 * is used for communication */
173private altstep as_Tguard_direct() runs on MTC_CT {
174 [] Tguard_direct.timeout {
175 setverdict(fail, "Tguard timeout");
Daniel Willmannafce8662018-07-06 23:11:32 +0200176 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +0100177 }
178}
Harald Weltef6dd64d2017-11-19 12:09:51 +0100179
Neels Hofmeyr2ca1ab42019-03-08 03:45:43 +0100180private altstep as_optional_cc_rel(CallParameters cpars, boolean respond := false) runs on BSC_ConnHdlr {
181 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id))) {
182 if (respond) {
183 var BIT1 tid_remote := '1'B;
184 if (cpars.mo_call) {
185 tid_remote := '0'B;
186 }
187 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id, tid_remote)));
188 }
189 }
Neels Hofmeyrde76f052019-02-26 05:02:46 +0100190}
191
Harald Weltef640a012018-04-14 17:49:21 +0200192function f_init_smpp(charstring id) runs on MTC_CT {
193 id := id & "-SMPP";
194 var EsmePars pars := {
195 mode := MODE_TRANSCEIVER,
196 bind := {
197 system_id := mp_smpp_system_id,
198 password := mp_smpp_password,
199 system_type := "MSC_Tests",
200 interface_version := hex2int('34'H),
201 addr_ton := unknown,
202 addr_npi := unknown,
203 address_range := ""
204 },
205 esme_role := true
206 }
207
208 vc_SMPP := SMPP_Emulation_CT.create(id);
209 map(vc_SMPP:SMPP_PORT, system:SMPP_PORT);
Harald Welte4698a4c2020-08-18 22:57:52 +0200210 vc_SMPP.start(SMPP_Emulation.main_client(pars, mp_msc_ip, mp_msc_smpp_port, "", 0));
Harald Weltef640a012018-04-14 17:49:21 +0200211}
212
213
Harald Weltea49e36e2018-01-21 19:29:33 +0100214function f_init_mncc(charstring id) runs on MTC_CT {
215 id := id & "-MNCC";
216 var MnccOps ops := {
217 create_cb := refers(MNCC_Emulation.ExpectedCreateCallback),
218 unitdata_cb := refers(MNCC_Emulation.DummyUnitdataCallback)
219 }
220
221 vc_MNCC := MNCC_Emulation_CT.create(id);
222 map(vc_MNCC:MNCC, system:MNCC_CODEC_PT);
223 vc_MNCC.start(MNCC_Emulation.main(ops, id, mp_msc_mncc));
Harald Weltef6dd64d2017-11-19 12:09:51 +0100224}
225
Harald Welte4aa970c2018-01-26 10:38:09 +0100226function f_init_mgcp(charstring id) runs on MTC_CT {
227 id := id & "-MGCP";
228 var MGCPOps ops := {
229 create_cb := refers(MGCP_Emulation.ExpectedCreateCallback),
230 unitdata_cb := refers(MGCP_Emulation.DummyUnitdataCallback)
231 }
232 var MGCP_conn_parameters pars := {
Harald Welte6126fb02018-01-27 20:08:24 +0100233 callagent_ip := mp_msc_ip,
Harald Welte4aa970c2018-01-26 10:38:09 +0100234 callagent_udp_port := -1,
Harald Welte6126fb02018-01-27 20:08:24 +0100235 mgw_ip := mp_mgw_ip,
Pau Espin Pedrol1a026a52019-06-18 17:21:52 +0200236 mgw_udp_port := mp_mgw_port,
237 multi_conn_mode := false
Harald Welte4aa970c2018-01-26 10:38:09 +0100238 }
239
240 vc_MGCP := MGCP_Emulation_CT.create(id);
241 map(vc_MGCP:MGCP, system:MGCP_CODEC_PT);
242 vc_MGCP.start(MGCP_Emulation.main(ops, pars, id));
243}
244
Philipp Maierc09a1312019-04-09 16:05:26 +0200245function ForwardUnitdataCallback(PDU_SGsAP msg)
246runs on SGsAP_Emulation_CT return template PDU_SGsAP {
247 SGsAP_CLIENT.send(msg);
248 return omit;
249}
250
Harald Welte4263c522018-12-06 11:56:27 +0100251function f_init_sgsap(charstring id) runs on MTC_CT {
252 id := id & "-SGsAP";
253 var SGsAPOps ops := {
254 create_cb := refers(SGsAP_Emulation.ExpectedCreateCallback),
Philipp Maierc09a1312019-04-09 16:05:26 +0200255 unitdata_cb := refers(ForwardUnitdataCallback)
Harald Welte4263c522018-12-06 11:56:27 +0100256 }
257 var SGsAP_conn_parameters pars := {
258 remote_ip := mp_msc_ip,
259 remote_sctp_port := 29118,
260 local_ip := "",
261 local_sctp_port := -1
262 }
263
264 vc_SGsAP := SGsAP_Emulation_CT.create(id);
265 map(vc_SGsAP:SGsAP, system:SGsAP_CODEC_PT);
266 vc_SGsAP.start(SGsAP_Emulation.main(ops, pars, id));
267}
268
269
Harald Weltea49e36e2018-01-21 19:29:33 +0100270function f_init_gsup(charstring id) runs on MTC_CT {
271 id := id & "-GSUP";
272 var GsupOps ops := {
273 create_cb := refers(GSUP_Emulation.ExpectedCreateCallback)
274 }
275
276 vc_GSUP_IPA := IPA_Emulation_CT.create(id & "-IPA");
277 vc_GSUP := GSUP_Emulation_CT.create(id);
278
279 map(vc_GSUP_IPA:IPA_PORT, system:IPA_CODEC_PT);
280 connect(vc_GSUP:GSUP, vc_GSUP_IPA:IPA_GSUP_PORT);
281 /* we use this hack to get events like ASP_IPA_EVENT_UP */
282 connect(vc_GSUP_IPA:IPA_CTRL_PORT, self:GSUP_IPA_EVENT);
283
284 vc_GSUP.start(GSUP_Emulation.main(ops, id));
285 vc_GSUP_IPA.start(IPA_Emulation.main_server(mp_hlr_ip, mp_hlr_port));
286
287 /* wait for incoming connection to GSUP port before proceeding */
288 timer T := 10.0;
289 T.start;
290 alt {
Vadim Yanitskiy61564be2020-05-18 20:44:14 +0700291 [] GSUP_IPA_EVENT.receive(tr_ASP_IPA_EV(ASP_IPA_EVENT_UP)) { }
Harald Weltea49e36e2018-01-21 19:29:33 +0100292 [] T.timeout {
Harald Welte458fd372018-03-21 11:26:23 +0100293 setverdict(fail, "No connection to GSUP Port");
Daniel Willmannafce8662018-07-06 23:11:32 +0200294 mtc.stop
Harald Weltea49e36e2018-01-21 19:29:33 +0100295 }
296 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100297}
298
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200299function f_init(integer num_bsc := 1, boolean sgsap := false, boolean gsup := true, boolean osmux := false) runs on MTC_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +0100300
301 if (g_initialized == true) {
302 return;
303 }
304 g_initialized := true;
305
Philipp Maier75932982018-03-27 14:52:35 +0200306 if (num_bsc > NUM_BSC) {
Daniel Willmannafce8662018-07-06 23:11:32 +0200307 testcase.stop("excess number of BSC instances requested");
Philipp Maier75932982018-03-27 14:52:35 +0200308 }
309
310 for (var integer i := 0; i < num_bsc; i := i + 1) {
311 if (isbound(mp_bssap_cfg[i])) {
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200312 var RanOps ranops := BSC_RanOps;
313 ranops.use_osmux := osmux;
314 f_ran_adapter_init(g_bssap[i], mp_bssap_cfg[i], "MSC_Test_" & int2str(i), ranops);
Harald Welte3ca0ce12019-04-23 17:18:48 +0200315 f_ran_adapter_start(g_bssap[i]);
Philipp Maier75932982018-03-27 14:52:35 +0200316 } else {
Daniel Willmannafce8662018-07-06 23:11:32 +0200317 testcase.stop("missing BSSAP configuration");
Philipp Maier75932982018-03-27 14:52:35 +0200318 }
319 }
320
Harald Weltea49e36e2018-01-21 19:29:33 +0100321 f_ipa_ctrl_start(mp_msc_ip, mp_msc_ctrl_port);
322 f_init_mncc("MSC_Test");
Harald Welte4aa970c2018-01-26 10:38:09 +0100323 f_init_mgcp("MSC_Test");
Philipp Maierc09a1312019-04-09 16:05:26 +0200324
325 if (gsup == true) {
326 f_init_gsup("MSC_Test");
327 }
Harald Weltef640a012018-04-14 17:49:21 +0200328 f_init_smpp("MSC_Test");
Philipp Maier57865482019-01-07 18:33:13 +0100329
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100330 if (sgsap == true) {
Philipp Maier57865482019-01-07 18:33:13 +0100331 f_init_sgsap("MSC_Test");
332 }
Harald Welte3ca1c902018-01-24 18:51:27 +0100333
334 map(self:MSCVTY, system:MSCVTY);
335 f_vty_set_prompts(MSCVTY);
336 f_vty_transceive(MSCVTY, "enable");
Harald Welteb14c77a2018-01-25 17:25:44 +0100337
338 /* set some defaults */
339 f_vty_config(MSCVTY, "network", "authentication optional");
340 f_vty_config(MSCVTY, "msc", "assign-tmsi");
Oliver Smith1d118ff2019-07-03 10:57:35 +0200341 f_vty_config(MSCVTY, "msc", "check-imei-rqd 0");
Harald Welteb14c77a2018-01-25 17:25:44 +0100342 f_vty_config(MSCVTY, "network", "encryption a5 0");
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100343 f_vty_config(MSCVTY, "cs7 instance 0", "sccp-timer ias " & int2str(g_msc_sccp_timer_ias));
344 f_vty_config(MSCVTY, "cs7 instance 0", "sccp-timer iar " & int2str(g_msc_sccp_timer_iar));
Pau Espin Pedrol9a732a42020-09-15 15:56:33 +0200345 if (osmux) {
346 f_vty_config(MSCVTY, "msc", "osmux on");
347 } else {
348 f_vty_config(MSCVTY, "msc", "osmux off");
Pau Espin Pedrol3dd33bc2019-05-31 17:51:20 +0200349 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100350}
351
Philipp Maier328d1662018-03-07 10:40:27 +0100352/* Initialize for a direct connection to BSSAP. This function is an alternative
353 * to f_init() when the high level functions of the BSC_ConnectionHandler are
354 * not needed. */
355function f_init_bssap_direct() runs on MTC_CT {
Harald Welte3ca0ce12019-04-23 17:18:48 +0200356 f_ran_adapter_init(g_bssap[0], mp_bssap_cfg[0], "MSC_Test", omit);
Philipp Maier75932982018-03-27 14:52:35 +0200357 connect(g_bssap[0].vc_SCCP:SCCP_SP_PORT, self:BSSAP_DIRECT);
Philipp Maier328d1662018-03-07 10:40:27 +0100358
359 /* Start guard timer and activate it as default */
360 Tguard_direct.start
361 activate(as_Tguard_direct());
362}
363
Harald Weltea49e36e2018-01-21 19:29:33 +0100364type function void_fn(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100365
Harald Weltea49e36e2018-01-21 19:29:33 +0100366/* FIXME: move into BSC_ConnectionHandler? */
Harald Welte9b751a62019-04-14 17:39:29 +0200367function f_init_pars(integer imsi_suffix, boolean sgsap := false, boolean gsup := true, integer ran_idx := 0,
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200368 boolean ran_is_geran := true, boolean use_osmux := false, OCT4 gsup_sid := '20000101'O,
369 boolean verify_cell_id := true)
Harald Weltef9abf8d2019-04-21 13:07:17 +0200370runs on MTC_CT return BSC_ConnHdlrPars {
Harald Weltede371492018-01-27 23:44:41 +0100371 var BSC_ConnHdlrNetworkPars net_pars := {
372 kc_support := '0A'O, /* A5/1 and A5/3 enabled */
373 expect_tmsi := true,
374 expect_auth := false,
Oliver Smith1d118ff2019-07-03 10:57:35 +0200375 expect_ciph := false,
376 expect_imei := false,
377 expect_imei_early := false,
378 check_imei_result := OSMO_GSUP_IMEI_RESULT_ACK,
379 check_imei_error := false
Harald Weltede371492018-01-27 23:44:41 +0100380 };
Harald Weltea49e36e2018-01-21 19:29:33 +0100381 var BSC_ConnHdlrPars pars := {
Harald Weltef9abf8d2019-04-21 13:07:17 +0200382 sccp_addr_own := g_bssap[ran_idx].sccp_addr_own,
383 sccp_addr_peer := g_bssap[ran_idx].sccp_addr_peer,
Harald Welteedbab812018-03-18 16:02:25 +0100384 cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42)),
Harald Welte81b7f9d2018-01-24 19:06:24 +0100385 imei := f_gen_imei(imsi_suffix),
386 imsi := f_gen_imsi(imsi_suffix),
387 msisdn := f_gen_msisdn(imsi_suffix),
Harald Welte256571e2018-01-24 18:47:19 +0100388 tmsi := omit,
Harald Welte9de84792018-01-28 01:06:35 +0100389 cm1 := valueof(ts_CM1),
Harald Welte82600572018-01-21 20:54:08 +0100390 cm2 := valueof(ts_CM2_default),
Harald Welte16114282018-01-24 22:41:21 +0100391 cm3 := omit,
Harald Weltede371492018-01-27 23:44:41 +0100392 vec := omit,
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100393 net := net_pars,
Philipp Maieraeb29a82018-11-08 17:40:53 +0100394 send_early_cm := true,
395 ipa_ctrl_ip := mp_msc_ip,
396 ipa_ctrl_port := mp_msc_ctrl_port,
Philipp Maier9b690e42018-12-21 11:50:03 +0100397 ipa_ctrl_enable := true,
Philipp Maier57865482019-01-07 18:33:13 +0100398 mm_info := mp_mm_info,
Philipp Maierc09a1312019-04-09 16:05:26 +0200399 sgsap_enable := sgsap,
Harald Weltef9abf8d2019-04-21 13:07:17 +0200400 gsup_enable := gsup,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +0100401 gsup_sid := gsup_sid,
Harald Weltec1f937a2019-04-21 21:19:23 +0200402 ran_idx := ran_idx,
Harald Welte9b751a62019-04-14 17:39:29 +0200403 use_umts_aka := false,
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200404 ran_is_geran := ran_is_geran,
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200405 use_osmux := use_osmux,
Pau Espin Pedrol833174e2020-09-03 16:46:02 +0200406 use_ipv6 := false,
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200407 verify_cell_id := mp_enable_cell_id_test and verify_cell_id
Harald Weltea49e36e2018-01-21 19:29:33 +0100408 };
Harald Weltee13cfb22019-04-23 16:52:02 +0200409 if (not ran_is_geran) {
410 pars.use_umts_aka := true;
411 pars.net.expect_auth := true;
412 }
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100413 return pars;
414}
415
Neels Hofmeyr0ac63152019-05-07 01:20:17 +0200416function f_start_handler_with_pars(void_fn fn, BSC_ConnHdlrPars pars, integer bssap_idx := 0) runs on MTC_CT return BSC_ConnHdlr {
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100417 var BSC_ConnHdlr vc_conn;
Neels Hofmeyr0ac63152019-05-07 01:20:17 +0200418 var charstring id := testcasename() & int2str(bssap_idx);
Harald Weltea49e36e2018-01-21 19:29:33 +0100419
420 vc_conn := BSC_ConnHdlr.create(id);
421 /* BSSMAP part / A interface */
Neels Hofmeyr0ac63152019-05-07 01:20:17 +0200422 connect(vc_conn:BSSAP, g_bssap[pars.ran_idx + bssap_idx].vc_RAN:CLIENT);
423 connect(vc_conn:BSSAP_PROC, g_bssap[pars.ran_idx + bssap_idx].vc_RAN:PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100424 /* MNCC part */
425 connect(vc_conn:MNCC, vc_MNCC:MNCC_CLIENT);
426 connect(vc_conn:MNCC_PROC, vc_MNCC:MNCC_PROC);
Harald Welte4aa970c2018-01-26 10:38:09 +0100427 /* MGCP part */
428 connect(vc_conn:MGCP, vc_MGCP:MGCP_CLIENT);
429 connect(vc_conn:MGCP_PROC, vc_MGCP:MGCP_PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100430 /* GSUP part */
Philipp Maierc09a1312019-04-09 16:05:26 +0200431 if (pars.gsup_enable == true) {
432 connect(vc_conn:GSUP, vc_GSUP:GSUP_CLIENT);
433 connect(vc_conn:GSUP_PROC, vc_GSUP:GSUP_PROC);
434 }
Harald Weltef640a012018-04-14 17:49:21 +0200435 /* SMPP part */
436 connect(vc_conn:SMPP, vc_SMPP:SMPP_CLIENT);
437 connect(vc_conn:SMPP_PROC, vc_SMPP:SMPP_PROC);
Harald Welte4263c522018-12-06 11:56:27 +0100438 /* SGs part */
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100439 if (pars.sgsap_enable == true) {
Philipp Maier57865482019-01-07 18:33:13 +0100440 connect(vc_conn:SGsAP, vc_SGsAP:SGsAP_CLIENT);
441 connect(vc_conn:SGsAP_PROC, vc_SGsAP:SGsAP_PROC);
442 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100443
Harald Weltea10db902018-01-27 12:44:49 +0100444 /* We cannot use vc_conn.start(f_init_handler(fn, id, pars)); as we cannot have
445 * a stand-alone 'derefers()' call, see https://www.eclipse.org/forums/index.php/t/1091364/ */
Harald Weltea49e36e2018-01-21 19:29:33 +0100446 vc_conn.start(derefers(fn)(id, pars));
447 return vc_conn;
448}
449
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200450function f_start_handler(void_fn fn, integer imsi_suffix, integer ran_idx := 0, boolean ran_is_geran := true, boolean use_osmux := false,
451 boolean verify_cell_id := true)
Harald Welte9b751a62019-04-14 17:39:29 +0200452runs on MTC_CT return BSC_ConnHdlr {
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200453 return f_start_handler_with_pars(fn, f_init_pars(imsi_suffix, ran_idx := ran_idx, ran_is_geran := ran_is_geran, use_osmux := use_osmux, verify_cell_id := verify_cell_id));
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100454}
455
Harald Weltea49e36e2018-01-21 19:29:33 +0100456private function f_tc_lu_imsi_noauth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100457 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100458 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100459}
Harald Weltea49e36e2018-01-21 19:29:33 +0100460testcase TC_lu_imsi_noauth_tmsi() runs on MTC_CT {
461 var BSC_ConnHdlr vc_conn;
462 f_init();
463
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100464 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi), 1);
Harald Weltea49e36e2018-01-21 19:29:33 +0100465 vc_conn.done;
466}
467
468private function f_tc_lu_imsi_noauth_notmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100469 pars.net.expect_tmsi := false;
Harald Weltea10db902018-01-27 12:44:49 +0100470 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100471 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100472}
Harald Weltea49e36e2018-01-21 19:29:33 +0100473testcase TC_lu_imsi_noauth_notmsi() runs on MTC_CT {
474 var BSC_ConnHdlr vc_conn;
475 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100476 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
Harald Weltea49e36e2018-01-21 19:29:33 +0100477
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100478 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi), 2);
Harald Weltea49e36e2018-01-21 19:29:33 +0100479 vc_conn.done;
480}
481
482/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
Harald Weltee13cfb22019-04-23 16:52:02 +0200483friend function f_tc_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100484 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100485 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
486
487 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +0200488 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyrd076c522019-11-28 01:00:52 +0100489 f_mm_common();
Harald Weltea49e36e2018-01-21 19:29:33 +0100490 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
491 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
492 alt {
Harald Welte5946b332018-03-18 23:32:21 +0100493 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej(int2oct(23,1)))) {
494 f_expect_clear();
495 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100496 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
497 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200498 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100499 }
500 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100501}
502testcase TC_lu_imsi_reject() runs on MTC_CT {
503 var BSC_ConnHdlr vc_conn;
504 f_init();
505
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200506 vc_conn := f_start_handler(refers(f_tc_lu_imsi_reject), 3, verify_cell_id := false);
Harald Weltea49e36e2018-01-21 19:29:33 +0100507 vc_conn.done;
508}
509
Harald Weltee13cfb22019-04-23 16:52:02 +0200510
511
Harald Weltea49e36e2018-01-21 19:29:33 +0100512/* Do LU by IMSI, timeout on GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +0200513friend function f_tc_lu_imsi_timeout_gsup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100514 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100515 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
516
517 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +0200518 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyrd076c522019-11-28 01:00:52 +0100519 f_mm_common();
Harald Weltea49e36e2018-01-21 19:29:33 +0100520 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
521 /* Normally the HLR would need to respond here, but we decide to force a timeout here */
522 alt {
523 /* FIXME: Expect specific reject cause */
Harald Welte5946b332018-03-18 23:32:21 +0100524 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
525 f_expect_clear();
526 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100527 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
528 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200529 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100530 }
531 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100532}
533testcase TC_lu_imsi_timeout_gsup() runs on MTC_CT {
534 var BSC_ConnHdlr vc_conn;
535 f_init();
536
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200537 vc_conn := f_start_handler(refers(f_tc_lu_imsi_timeout_gsup), 4, verify_cell_id := false);
Harald Weltea49e36e2018-01-21 19:29:33 +0100538 vc_conn.done;
539}
540
Harald Weltee13cfb22019-04-23 16:52:02 +0200541
Harald Welte7b1b2812018-01-22 21:23:06 +0100542private function f_tc_lu_imsi_auth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100543 pars.net.expect_auth := true;
Harald Weltea10db902018-01-27 12:44:49 +0100544 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100545 f_perform_lu();
Harald Welte7b1b2812018-01-22 21:23:06 +0100546}
547testcase TC_lu_imsi_auth_tmsi() runs on MTC_CT {
548 var BSC_ConnHdlr vc_conn;
549 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100550 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte7b1b2812018-01-22 21:23:06 +0100551
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100552 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi), 5);
Harald Welte7b1b2812018-01-22 21:23:06 +0100553 vc_conn.done;
554}
555
Harald Weltee13cfb22019-04-23 16:52:02 +0200556
557friend function f_tc_lu_imsi_auth3g_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte8a397ae2019-04-21 22:03:37 +0200558 pars.net.expect_auth := true;
559 pars.use_umts_aka := true;
560 f_init_handler(pars);
561 f_perform_lu();
562}
563testcase TC_lu_imsi_auth3g_tmsi() runs on MTC_CT {
564 var BSC_ConnHdlr vc_conn;
565 f_init();
566 f_vty_config(MSCVTY, "network", "authentication required");
567
568 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi), 1005);
569 vc_conn.done;
570}
Harald Weltea49e36e2018-01-21 19:29:33 +0100571
Pau Espin Pedrold3d54a92019-12-17 17:02:54 +0100572/* Proceed with LU but never receive an TMSI Realloc from MS after LU Accept (OS#4337).
573 * TS 24.008 sec 4.3.1.5 states MSC should simply release all MM connections.
574 */
575friend function f_tc_lu_imsi_timeout_tmsi_realloc(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
576
577 f_init_handler(pars);
578
579 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
580 var PDU_DTAP_MT dtap_mt;
581
582 /* tell GSUP dispatcher to send this IMSI to us */
583 f_create_gsup_expect(hex2str(g_pars.imsi));
584
585 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
586 if (g_pars.ran_is_geran) {
587 f_bssap_compl_l3(l3_lu);
588 if (g_pars.send_early_cm) {
589 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
590 }
591 } else {
592 f_ranap_initial_ue(l3_lu);
593 }
594
595 f_mm_imei_early();
596 f_mm_common();
597 f_msc_lu_hlr();
598 f_mm_imei();
599
600 alt {
601 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) -> value dtap_mt {}
602 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
603 setverdict(fail, "Expected LU ACK, but received LU REJ");
604 mtc.stop;
605 }
606 }
607
608 /* currently (due to bug OS#4337), an extra LU reject is received before
609 terminating the connection. Enabling following line makes the test
610 pass: */
611 //f_expect_lu_reject('16'O); /* Cause: congestion */
612
613 /* f_expect_lu_reject() already waits for T"-1" (X1, 5 seconds), but give some
614 extra time to avoid race conditons... */
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200615 f_expect_clear(7.0, verify_vlr_cell_id := false);
Pau Espin Pedrold3d54a92019-12-17 17:02:54 +0100616
617 setverdict(pass);
618}
619testcase TC_lu_imsi_timeout_tmsi_realloc() runs on MTC_CT {
620 var BSC_ConnHdlr vc_conn;
621 f_init();
622
623 vc_conn := f_start_handler(refers(f_tc_lu_imsi_timeout_tmsi_realloc), 5);
624 vc_conn.done;
625}
626
Harald Weltee13cfb22019-04-23 16:52:02 +0200627
Harald Weltea49e36e2018-01-21 19:29:33 +0100628/* Send CM SERVICE REQ for IMSI that has never performed LU before */
Harald Weltee13cfb22019-04-23 16:52:02 +0200629friend function f_tc_cmserv_imsi_unknown(charstring id, BSC_ConnHdlrPars pars)
Harald Weltea49e36e2018-01-21 19:29:33 +0100630runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100631 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100632
633 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welteedbab812018-03-18 16:02:25 +0100634 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
Harald Welte6ed6bf92018-01-24 21:09:15 +0100635 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
Harald Weltea49e36e2018-01-21 19:29:33 +0100636
637 f_create_gsup_expect(hex2str(g_pars.imsi));
638
639 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200640 f_cl3_or_initial_ue(l3_info);
Harald Welteb7817992019-05-09 13:15:39 +0200641 f_mm_auth();
Harald Weltea49e36e2018-01-21 19:29:33 +0100642
643 timer T := 10.0;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100644 T.start;
645 alt {
Harald Weltea49e36e2018-01-21 19:29:33 +0100646 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
647 //[] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_ACC)) { }
Daniel Willmannafce8662018-07-06 23:11:32 +0200648 [] BSSAP.receive {
649 setverdict(fail, "Received unexpected BSSAP");
650 mtc.stop;
651 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100652 [] GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi)) {
653 setverdict(fail, "Unexpected GSUP UL REQ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200654 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100655 }
Daniel Willmannafce8662018-07-06 23:11:32 +0200656 [] T.timeout {
Neels Hofmeyrf1c3c212020-08-19 13:15:32 +0000657 setverdict(fail, "Timeout waiting for CM SERV REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200658 mtc.stop;
659 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100660 }
661
Harald Welte1ddc7162018-01-27 14:25:46 +0100662 f_expect_clear();
Harald Weltef6dd64d2017-11-19 12:09:51 +0100663}
Harald Weltea49e36e2018-01-21 19:29:33 +0100664testcase TC_cmserv_imsi_unknown() runs on MTC_CT {
665 var BSC_ConnHdlr vc_conn;
666 f_init();
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200667 vc_conn := f_start_handler(refers(f_tc_cmserv_imsi_unknown), 6, verify_cell_id := false);
Harald Weltea49e36e2018-01-21 19:29:33 +0100668 vc_conn.done;
669}
670
Harald Weltee13cfb22019-04-23 16:52:02 +0200671
Neels Hofmeyr13737fb2020-08-19 13:16:14 +0000672/* Send CM SERVICE REQ for TMSI that has never performed LU before */
673friend function f_tc_cmserv_tmsi_unknown(charstring id, BSC_ConnHdlrPars pars)
674runs on BSC_ConnHdlr {
675 f_init_handler(pars);
676
677 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV('57111111'O));
678 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
679 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
680
681 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
682 f_cl3_or_initial_ue(l3_info);
683 f_mm_auth();
684
685 timer T := 10.0;
686 T.start;
687 alt {
688 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
689 [] BSSAP.receive {
690 setverdict(fail, "Received unexpected BSSAP");
691 mtc.stop;
692 }
693 [] T.timeout {
694 setverdict(fail, "Timeout waiting for CM SERV REJ");
695 mtc.stop;
696 }
697 }
698
699 f_expect_clear();
700}
701testcase TC_cmserv_tmsi_unknown() runs on MTC_CT {
702 var BSC_ConnHdlr vc_conn;
703 f_init();
704 vc_conn := f_start_handler(refers(f_tc_cmserv_tmsi_unknown), 57, verify_cell_id := false);
705 vc_conn.done;
706}
707
Neels Hofmeyr14d0b132020-08-19 13:49:05 +0000708/* Send Paging Response for IMSI that has never performed LU before */
709friend function f_tc_paging_response_imsi_unknown(charstring id, BSC_ConnHdlrPars pars)
710runs on BSC_ConnHdlr {
711 f_init_handler(pars);
712
713 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
714 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
715 var PDU_ML3_MS_NW l3_info := valueof(ts_PAG_RESP(mi));
716
717 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
718 f_cl3_or_initial_ue(l3_info);
719
720 /* The Paging Response gets rejected by a direct Clear Command */
721 f_expect_clear();
722}
723testcase TC_paging_response_imsi_unknown() runs on MTC_CT {
724 var BSC_ConnHdlr vc_conn;
725 f_init();
726 vc_conn := f_start_handler(refers(f_tc_paging_response_imsi_unknown), 58, verify_cell_id := false);
727 vc_conn.done;
728}
729
730/* Send Paging Response for TMSI that has never performed LU before */
731friend function f_tc_paging_response_tmsi_unknown(charstring id, BSC_ConnHdlrPars pars)
732runs on BSC_ConnHdlr {
733 f_init_handler(pars);
734
735 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV('59111111'O));
736 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
737 var PDU_ML3_MS_NW l3_info := valueof(ts_PAG_RESP(mi));
738
739 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
740 f_cl3_or_initial_ue(l3_info);
741
742 /* The Paging Response gets rejected by a direct Clear Command */
743 f_expect_clear();
744}
745testcase TC_paging_response_tmsi_unknown() runs on MTC_CT {
746 var BSC_ConnHdlr vc_conn;
747 f_init();
748 vc_conn := f_start_handler(refers(f_tc_paging_response_tmsi_unknown), 59, verify_cell_id := false);
749 vc_conn.done;
750}
751
Neels Hofmeyr13737fb2020-08-19 13:16:14 +0000752
Harald Weltee13cfb22019-04-23 16:52:02 +0200753friend function f_tc_lu_and_mo_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100754 f_init_handler(pars);
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +0200755 var CallParameters cpars := valueof(t_CallParams);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100756 f_perform_lu();
Harald Welteb71901a2018-01-26 19:16:05 +0100757 f_mo_call(cpars);
Harald Welte2bb825f2018-01-22 11:31:18 +0100758}
759testcase TC_lu_and_mo_call() runs on MTC_CT {
760 var BSC_ConnHdlr vc_conn;
761 f_init();
762
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100763 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_call), 7);
Harald Welte071ed732018-01-23 19:53:52 +0100764 vc_conn.done;
765}
Pau Espin Pedrol833174e2020-09-03 16:46:02 +0200766friend function f_tc_lu_and_mo_call_ipv6(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
767 f_init_handler(pars);
768 var CallParameters cpars := valueof(t_CallParams);
769 cpars.mgw_conn_1.mgw_rtp_ip := "::1";
770 cpars.mgw_conn_2.mgw_rtp_ip := "::2";
771 cpars.bss_rtp_ip := "::3";
772 f_perform_lu();
773 f_mo_call(cpars);
774}
775testcase TC_lu_and_mo_call_ipv6() runs on MTC_CT {
776 var BSC_ConnHdlr vc_conn;
777 f_init();
778
779 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_call_ipv6), 7);
780 vc_conn.done;
781}
Harald Welte071ed732018-01-23 19:53:52 +0100782
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100783/* Verify T(iar) triggers and releases the channel */
784friend function f_lu_and_mo_call_sccp_tiar_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
785 timer T_wait_iar := int2float(5 + 1); /* g_msc_sccp_timer_iar + Give extra time (+1 sec) */
786 f_init_handler(pars);
787 var CallParameters cpars := valueof(t_CallParams);
788 f_perform_lu();
789 f_mo_call_establish(cpars);
790
791 /* Expect the channel cleared upon T(iar) triggered: */
792 T_wait_iar.start;
793 alt {
794 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {
795 T_wait_iar.stop
796 setverdict(pass);
797 }
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100798 [] T_wait_iar.timeout {
799 setverdict(fail, "Timeout waiting for T(iar) triggered SCCP RSLD");
800 mtc.stop;
801 }
802 }
Harald Welte4a3fa712020-08-19 08:57:33 +0200803 /* DLCX for both directions; if we don't do this, we might receive either of the two during
804 * shutdown causing race conditions */
805 MGCP.receive(tr_DLCX(?));
806 MGCP.receive(tr_DLCX(?));
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100807
808 setverdict(pass);
809}
810testcase TC_lu_and_mo_call_sccp_tiar_timeout() runs on MTC_CT {
811 var BSC_ConnHdlr vc_conn;
812
813 /* Set T(iar) in MSC low enough that it will trigger before other side
814 has time to keep alive with a T(ias). Keep recommended ratio of
815 T(iar) >= T(ias)*2 */
816 g_msc_sccp_timer_ias := 2;
817 g_msc_sccp_timer_iar := 5;
818
819 f_init();
820
821 vc_conn := f_start_handler(refers(f_lu_and_mo_call_sccp_tiar_timeout), 89);
822 vc_conn.done;
823}
824
Harald Weltee13cfb22019-04-23 16:52:02 +0200825
Harald Welte071ed732018-01-23 19:53:52 +0100826/* Test LU (with authentication enabled), where HLR times out sending SAI response */
Harald Weltee13cfb22019-04-23 16:52:02 +0200827friend function f_tc_lu_auth_sai_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100828 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100829
830 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
831 var PDU_DTAP_MT dtap_mt;
832
833 /* tell GSUP dispatcher to send this IMSI to us */
834 f_create_gsup_expect(hex2str(g_pars.imsi));
835
836 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200837 f_cl3_or_initial_ue(l3_lu);
Harald Welte071ed732018-01-23 19:53:52 +0100838
839 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200840 if (pars.ran_is_geran) {
841 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
842 }
Harald Welte071ed732018-01-23 19:53:52 +0100843
844 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
845 /* The HLR would normally return an auth vector here, but we fail to do so. */
846
847 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100848 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100849}
850testcase TC_lu_auth_sai_timeout() runs on MTC_CT {
851 var BSC_ConnHdlr vc_conn;
852 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100853 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100854
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200855 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_timeout), 8, verify_cell_id := false);
Harald Welte071ed732018-01-23 19:53:52 +0100856 vc_conn.done;
857}
858
Harald Weltee13cfb22019-04-23 16:52:02 +0200859
Harald Welte071ed732018-01-23 19:53:52 +0100860/* Test LU (with authentication enabled), where HLR rejects sending SAI error */
Harald Weltee13cfb22019-04-23 16:52:02 +0200861friend function f_tc_lu_auth_sai_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100862 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100863
864 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
865 var PDU_DTAP_MT dtap_mt;
866
867 /* tell GSUP dispatcher to send this IMSI to us */
868 f_create_gsup_expect(hex2str(g_pars.imsi));
869
870 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200871 f_cl3_or_initial_ue(l3_lu);
Harald Welte071ed732018-01-23 19:53:52 +0100872
873 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200874 if (pars.ran_is_geran) {
875 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
876 }
Harald Welte071ed732018-01-23 19:53:52 +0100877
878 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
879 GSUP.send(ts_GSUP_SAI_ERR(g_pars.imsi, 13));
880
881 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100882 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100883}
884testcase TC_lu_auth_sai_err() runs on MTC_CT {
885 var BSC_ConnHdlr vc_conn;
886 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100887 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100888
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200889 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_err), 9, verify_cell_id := false);
Harald Welte2bb825f2018-01-22 11:31:18 +0100890 vc_conn.done;
891}
Harald Weltea49e36e2018-01-21 19:29:33 +0100892
Harald Weltee13cfb22019-04-23 16:52:02 +0200893
Harald Weltebc881782018-01-23 20:09:15 +0100894/* Test LU but BSC will send a clear request in the middle */
895private function f_tc_lu_clear_request(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100896 f_init_handler(pars);
Harald Weltebc881782018-01-23 20:09:15 +0100897
898 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
899 var PDU_DTAP_MT dtap_mt;
900
901 /* tell GSUP dispatcher to send this IMSI to us */
902 f_create_gsup_expect(hex2str(g_pars.imsi));
903
904 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200905 f_cl3_or_initial_ue(l3_lu);
Harald Welte79f1e452020-08-18 22:55:02 +0200906 f_expect_common_id();
Harald Weltebc881782018-01-23 20:09:15 +0100907
908 /* Send Early Classmark, just for the fun of it */
909 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
910
911 f_sleep(1.0);
912 /* send clear request in the middle of the LU */
913 BSSAP.send(ts_BSSMAP_ClearRequest(0));
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200914 alt {
915 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { repeat; }
916 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {}
917 }
Harald Weltebc881782018-01-23 20:09:15 +0100918 BSSAP.send(ts_BSSMAP_ClearComplete);
Harald Welte89a32492018-01-27 19:07:28 +0100919 alt {
920 /* See https://osmocom.org/issues/2862 */
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200921 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {
922 setverdict(fail, "Got a second Clear Command, only one expected");
Daniel Willmannafce8662018-07-06 23:11:32 +0200923 mtc.stop;
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200924 repeat;
925 }
Harald Welte6811d102019-04-14 22:23:14 +0200926 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte89a32492018-01-27 19:07:28 +0100927 }
Harald Weltebc881782018-01-23 20:09:15 +0100928 setverdict(pass);
929}
930testcase TC_lu_clear_request() runs on MTC_CT {
931 var BSC_ConnHdlr vc_conn;
932 f_init();
933
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100934 vc_conn := f_start_handler(refers(f_tc_lu_clear_request), 10);
Harald Weltebc881782018-01-23 20:09:15 +0100935 vc_conn.done;
936}
937
Harald Welte66af9e62018-01-24 17:28:21 +0100938/* Test LU but BSC will send a clear request in the middle */
Harald Weltee13cfb22019-04-23 16:52:02 +0200939friend function f_tc_lu_disconnect(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100940 f_init_handler(pars);
Harald Welte66af9e62018-01-24 17:28:21 +0100941
942 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
943 var PDU_DTAP_MT dtap_mt;
944
945 /* tell GSUP dispatcher to send this IMSI to us */
946 f_create_gsup_expect(hex2str(g_pars.imsi));
947
948 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200949 f_cl3_or_initial_ue(l3_lu);
Harald Welte66af9e62018-01-24 17:28:21 +0100950
951 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200952 if (pars.ran_is_geran) {
953 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
954 }
Harald Welte66af9e62018-01-24 17:28:21 +0100955
956 f_sleep(1.0);
957 /* send clear request in the middle of the LU */
Harald Welte6811d102019-04-14 22:23:14 +0200958 BSSAP.send(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_REQ);
Harald Welte66af9e62018-01-24 17:28:21 +0100959 setverdict(pass);
Neels Hofmeyrbb825c92019-03-06 15:35:50 +0100960 f_sleep(1.0);
Harald Welte66af9e62018-01-24 17:28:21 +0100961}
962testcase TC_lu_disconnect() runs on MTC_CT {
963 var BSC_ConnHdlr vc_conn;
964 f_init();
965
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100966 vc_conn := f_start_handler(refers(f_tc_lu_disconnect), 11);
Harald Welte66af9e62018-01-24 17:28:21 +0100967 vc_conn.done;
968}
969
Harald Welteba7b6d92018-01-23 21:32:34 +0100970/* Test LU but with illegal mobile identity type = IMEI */
Harald Weltee13cfb22019-04-23 16:52:02 +0200971friend function f_tc_lu_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100972 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +0100973
Harald Welte256571e2018-01-24 18:47:19 +0100974 var PDU_ML3_MS_NW l3_lu := f_build_lu_imei(g_pars.imei)
Harald Welteba7b6d92018-01-23 21:32:34 +0100975 var PDU_DTAP_MT dtap_mt;
976
977 /* tell GSUP dispatcher to send this IMSI to us */
978 f_create_gsup_expect(hex2str(g_pars.imsi));
979
980 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200981 f_cl3_or_initial_ue(l3_lu);
Harald Welteba7b6d92018-01-23 21:32:34 +0100982
983 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200984 if (pars.ran_is_geran) {
985 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
986 }
Harald Welteba7b6d92018-01-23 21:32:34 +0100987 /* wait for LU reject, ignore any ID REQ */
988 alt {
989 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { }
990 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req)) { repeat; }
991 }
992 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100993 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +0100994}
995testcase TC_lu_by_imei() runs on MTC_CT {
996 var BSC_ConnHdlr vc_conn;
997 f_init();
998
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200999 vc_conn := f_start_handler(refers(f_tc_lu_by_imei), 12, verify_cell_id := false);
Harald Welteba7b6d92018-01-23 21:32:34 +01001000 vc_conn.done;
1001}
1002
Harald Weltee13cfb22019-04-23 16:52:02 +02001003
Harald Welteba7b6d92018-01-23 21:32:34 +01001004/* Test LU by TMSI with unknown TMSI, expect (and answer) ID REQ. */
1005private function f_tc_lu_tmsi_noauth_unknown(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Stefan Sperling04fc4bc2018-06-25 17:44:57 +02001006 /* We piggyback a test for an MSC crash on overlong IMSI (OS#2864) onto this test. */
1007 var hexstring overlong_imsi := '012345789ABCDEF0123456789ABCDEF'H;
Harald Weltea10db902018-01-27 12:44:49 +01001008 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +01001009
1010 var PDU_ML3_MS_NW l3_lu := f_build_lu_tmsi('01020304'O); /* FIXME: Random */
1011 var PDU_DTAP_MT dtap_mt;
1012
1013 /* tell GSUP dispatcher to send this IMSI to us */
1014 f_create_gsup_expect(hex2str(g_pars.imsi));
1015
1016 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001017 f_cl3_or_initial_ue(l3_lu);
Harald Welteba7b6d92018-01-23 21:32:34 +01001018
1019 /* Send Early Classmark, just for the fun of it */
1020 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1021
1022 /* Wait for + respond to ID REQ (IMSI) */
Oliver Smith32898452019-07-09 12:32:35 +02001023 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
Stefan Sperling04fc4bc2018-06-25 17:44:57 +02001024 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(overlong_imsi))); /* test for OS#2864 */
Harald Welteba7b6d92018-01-23 21:32:34 +01001025 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(g_pars.imsi)));
Harald Welte79f1e452020-08-18 22:55:02 +02001026 f_expect_common_id();
Harald Welteba7b6d92018-01-23 21:32:34 +01001027
1028 /* Expect MSC to do UpdateLocation to HLR; respond to it */
1029 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
1030 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
1031 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
1032 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
1033
1034 alt {
Harald Welte7ec4fa82018-01-27 10:57:40 +01001035 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
1036 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_TmsiRealloc_Cmpl));
1037 }
Harald Welteba7b6d92018-01-23 21:32:34 +01001038 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1039 setverdict(fail, "Expected LU ACK, but received REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +02001040 mtc.stop;
Harald Welteba7b6d92018-01-23 21:32:34 +01001041 }
1042 }
1043
Philipp Maier9b690e42018-12-21 11:50:03 +01001044 /* Wait for MM-Information (if enabled) */
1045 f_expect_mm_info();
1046
Harald Welteba7b6d92018-01-23 21:32:34 +01001047 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001048 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +01001049}
1050testcase TC_lu_by_tmsi_noauth_unknown() runs on MTC_CT {
1051 var BSC_ConnHdlr vc_conn;
1052 f_init();
1053
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001054 vc_conn := f_start_handler(refers(f_tc_lu_tmsi_noauth_unknown), 13);
Harald Welteba7b6d92018-01-23 21:32:34 +01001055 vc_conn.done;
1056}
1057
Neels Hofmeyrfc06c732020-08-19 12:52:28 +00001058/* Test LU by unknown TMSI, while the IMSI is already attached: osmo-msc should switch to the attached vlr_subscr. */
1059private function f_tc_attached_imsi_lu_unknown_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1060 f_init_handler(pars);
1061
1062 var PDU_ML3_MS_NW l3_lu := f_build_lu_tmsi('56111111'O);
1063 var PDU_DTAP_MT dtap_mt;
1064
1065 /* tell GSUP dispatcher to send this IMSI to us */
1066 f_create_gsup_expect(hex2str(g_pars.imsi));
1067
1068 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
1069 f_cl3_or_initial_ue(l3_lu);
1070
1071 /* Send Early Classmark, just for the fun of it */
1072 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1073
1074 /* Wait for + respond to ID REQ (IMSI) */
1075 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
1076 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(g_pars.imsi)));
1077 f_expect_common_id();
1078
1079 /* Expect MSC to do UpdateLocation to HLR; respond to it */
1080 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
1081 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
1082 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
1083 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
1084
1085 alt {
1086 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
1087 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_TmsiRealloc_Cmpl));
1088 }
1089 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1090 setverdict(fail, "Expected LU ACK, but received REJ");
1091 mtc.stop;
1092 }
1093 }
1094
1095 /* Wait for MM-Information (if enabled) */
1096 f_expect_mm_info();
1097
1098 /* wait for normal teardown */
1099 f_expect_clear();
1100
1101 /* Now the same IMSI is still attached in the VLR, and a LU with an unknown TMSI reveals the same IMSI only
1102 * later during ID Response. osmo-msc first creates a new vlr_subscr for the unknown TMSI, and as soon as the
1103 * IMSI becomes known, must notice that this IMSI is still regarded as attached, and must not create evil twins.
1104 */
1105
1106 /* (since the TMSI Reallocation happened, we could do this with exactly the same TMSI as above, but for test
1107 * readability just use a different one.) */
1108 l3_lu := f_build_lu_tmsi('56222222'O);
1109 f_cl3_or_initial_ue(l3_lu);
1110
1111 /* Wait for + respond to ID REQ (IMSI) */
1112 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
1113 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(g_pars.imsi)));
1114 f_expect_common_id();
1115
1116 /* Expect MSC to do UpdateLocation to HLR; respond to it */
1117 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
1118 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
1119 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
1120 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
1121
1122 alt {
1123 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
1124 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_TmsiRealloc_Cmpl));
1125 }
1126 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1127 setverdict(fail, "Expected LU ACK, but received REJ");
1128 mtc.stop;
1129 }
1130 }
1131
1132 /* Wait for MM-Information (if enabled) */
1133 f_expect_mm_info();
1134
1135 /* wait for normal teardown */
1136 f_expect_clear();
1137}
1138testcase TC_attached_imsi_lu_unknown_tmsi() runs on MTC_CT {
1139 var BSC_ConnHdlr vc_conn;
1140 f_init();
1141
1142 vc_conn := f_start_handler(refers(f_tc_attached_imsi_lu_unknown_tmsi), 56);
1143 vc_conn.done;
1144}
1145
Harald Welte4d15fa72020-08-19 08:58:28 +02001146friend function f_imsi_detach_by_imsi() runs on BSC_ConnHdlr {
Harald Welte45164da2018-01-24 12:51:27 +01001147 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1148
1149 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001150 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +01001151
1152 /* Send Early Classmark, just for the fun of it? */
Harald Welte4d15fa72020-08-19 08:58:28 +02001153 if (g_pars.ran_is_geran) {
Harald Weltee13cfb22019-04-23 16:52:02 +02001154 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1155 }
Harald Welte45164da2018-01-24 12:51:27 +01001156
1157 /* wait for normal teardown */
Harald Welte4d15fa72020-08-19 08:58:28 +02001158 f_expect_clear(verify_vlr_cell_id := false);
1159}
1160
1161
1162/* Test IMSI DETACH (MI=IMSI) */
1163friend function f_tc_imsi_detach_by_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1164 f_init_handler(pars);
1165
1166 f_imsi_detach_by_imsi();
Harald Welte45164da2018-01-24 12:51:27 +01001167}
1168testcase TC_imsi_detach_by_imsi() runs on MTC_CT {
1169 var BSC_ConnHdlr vc_conn;
1170 f_init();
1171
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001172 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imsi), 14, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001173 vc_conn.done;
1174}
1175
Harald Weltee13cfb22019-04-23 16:52:02 +02001176
Harald Welte45164da2018-01-24 12:51:27 +01001177/* Test IMSI DETACH (MI=TMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +02001178friend function f_tc_imsi_detach_by_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001179 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001180
1181 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV('01020304'O));
1182
1183 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001184 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +01001185
1186 /* Send Early Classmark, just for the fun of it? */
Harald Weltee13cfb22019-04-23 16:52:02 +02001187 if (pars.ran_is_geran) {
1188 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1189 }
Harald Welte45164da2018-01-24 12:51:27 +01001190
1191 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001192 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001193}
1194testcase TC_imsi_detach_by_tmsi() runs on MTC_CT {
1195 var BSC_ConnHdlr vc_conn;
1196 f_init();
1197
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001198 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_tmsi), 15, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001199 vc_conn.done;
1200}
1201
Harald Weltee13cfb22019-04-23 16:52:02 +02001202
Harald Welte45164da2018-01-24 12:51:27 +01001203/* Test IMSI DETACH (MI=IMEI), which is illegal */
Harald Weltee13cfb22019-04-23 16:52:02 +02001204friend function f_tc_imsi_detach_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001205 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001206
Harald Welte256571e2018-01-24 18:47:19 +01001207 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte45164da2018-01-24 12:51:27 +01001208
1209 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001210 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +01001211
1212 /* Send Early Classmark, just for the fun of it? */
Harald Weltee13cfb22019-04-23 16:52:02 +02001213 if (pars.ran_is_geran) {
1214 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1215 }
Harald Welte45164da2018-01-24 12:51:27 +01001216
1217 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001218 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001219}
1220testcase TC_imsi_detach_by_imei() runs on MTC_CT {
1221 var BSC_ConnHdlr vc_conn;
1222 f_init();
1223
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001224 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imei), 16, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001225 vc_conn.done;
1226}
1227
1228
1229/* helper function for an emergency call. caller passes in mobile identity to use */
1230private function f_emerg_call(MobileIdentityLV mi) runs on BSC_ConnHdlr {
Harald Welte0bef21e2018-02-10 09:48:23 +01001231 var CallParameters cpars := valueof(t_CallParams('112'H, 0));
1232 cpars.emergency := true;
Harald Welte45164da2018-01-24 12:51:27 +01001233
Harald Welte0bef21e2018-02-10 09:48:23 +01001234 f_mo_call(cpars);
Harald Welte45164da2018-01-24 12:51:27 +01001235}
1236
1237/* establish an emergency call by IMEI, no SIM inserted (and hence no IMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +02001238friend function f_tc_emerg_call_imei_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001239 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001240
Harald Welte256571e2018-01-24 18:47:19 +01001241 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001242 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_EMERG_CALL, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001243 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001244 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ('05'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +01001245 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001246}
1247testcase TC_emerg_call_imei_reject() runs on MTC_CT {
1248 var BSC_ConnHdlr vc_conn;
1249 f_init();
1250
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001251 vc_conn := f_start_handler(refers(f_tc_emerg_call_imei_reject), 17, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001252 vc_conn.done;
1253}
1254
Harald Weltee13cfb22019-04-23 16:52:02 +02001255
Harald Welted5b91402018-01-24 18:48:16 +01001256/* establish an emergency call by IMSI, SIM inserted (and hence IMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +02001257friend function f_tc_emerg_call_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001258 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001259 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001260 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001261 /* Then issue emergency call identified by IMSI */
1262 f_emerg_call(valueof(ts_MI_IMSI_LV(g_pars.imsi)));
1263}
1264testcase TC_emerg_call_imsi() runs on MTC_CT {
1265 var BSC_ConnHdlr vc_conn;
1266 f_init();
1267
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001268 vc_conn := f_start_handler(refers(f_tc_emerg_call_imsi), 18);
Harald Welte45164da2018-01-24 12:51:27 +01001269 vc_conn.done;
1270}
1271
Harald Weltee13cfb22019-04-23 16:52:02 +02001272
Harald Welte45164da2018-01-24 12:51:27 +01001273/* CM Service Request for VGCS -> reject */
1274private function f_tc_cm_serv_req_vgcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001275 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001276
1277 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001278 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001279
1280 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001281 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VGCS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001282 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001283 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001284 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001285}
1286testcase TC_cm_serv_req_vgcs_reject() runs on MTC_CT {
1287 var BSC_ConnHdlr vc_conn;
1288 f_init();
1289
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001290 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vgcs_reject), 19);
Harald Welte45164da2018-01-24 12:51:27 +01001291 vc_conn.done;
1292}
1293
1294/* CM Service Request for VBS -> reject */
1295private function f_tc_cm_serv_req_vbs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001296 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001297
1298 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001299 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001300
1301 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001302 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VBS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001303 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001304 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001305 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001306}
1307testcase TC_cm_serv_req_vbs_reject() runs on MTC_CT {
1308 var BSC_ConnHdlr vc_conn;
1309 f_init();
1310
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001311 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vbs_reject), 20);
Harald Welte45164da2018-01-24 12:51:27 +01001312 vc_conn.done;
1313}
1314
1315/* CM Service Request for LCS -> reject */
1316private function f_tc_cm_serv_req_lcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001317 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001318
1319 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001320 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001321
1322 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001323 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_LCS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001324 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001325 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001326 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001327}
1328testcase TC_cm_serv_req_lcs_reject() runs on MTC_CT {
1329 var BSC_ConnHdlr vc_conn;
1330 f_init();
1331
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001332 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_lcs_reject), 21);
Harald Welte45164da2018-01-24 12:51:27 +01001333 vc_conn.done;
1334}
1335
Harald Welte0195ab12018-01-24 21:50:20 +01001336/* CM Re-Establishment Request */
1337private function f_tc_cm_reest_req_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001338 f_init_handler(pars);
Harald Welte0195ab12018-01-24 21:50:20 +01001339
1340 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001341 f_perform_lu();
Harald Welte0195ab12018-01-24 21:50:20 +01001342
1343 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1344 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_REEST_REQ(0, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001345 f_cl3_or_initial_ue(l3_info);
Harald Welte0195ab12018-01-24 21:50:20 +01001346 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001347 f_expect_clear();
Harald Welte0195ab12018-01-24 21:50:20 +01001348}
1349testcase TC_cm_reest_req_reject() runs on MTC_CT {
1350 var BSC_ConnHdlr vc_conn;
1351 f_init();
Harald Welte0195ab12018-01-24 21:50:20 +01001352
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001353 vc_conn := f_start_handler(refers(f_tc_cm_reest_req_reject), 22);
Harald Welte0195ab12018-01-24 21:50:20 +01001354 vc_conn.done;
1355}
1356
Harald Weltec638f4d2018-01-24 22:00:36 +01001357/* Test LU (with authentication enabled), with wrong response from MS */
1358private function f_tc_lu_auth_2G_fail(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001359 f_init_handler(pars);
Harald Weltec638f4d2018-01-24 22:00:36 +01001360
1361 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
1362
1363 /* tell GSUP dispatcher to send this IMSI to us */
1364 f_create_gsup_expect(hex2str(g_pars.imsi));
1365
1366 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001367 f_cl3_or_initial_ue(l3_lu);
Harald Weltec638f4d2018-01-24 22:00:36 +01001368
1369 /* Send Early Classmark, just for the fun of it */
1370 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1371
1372 var AuthVector vec := f_gen_auth_vec_2g();
1373 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G(vec.rand, vec.sres, vec.kc));
1374 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
1375 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
1376
1377 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_AUTH_REQ(vec.rand)));
1378 /* Send back wrong auth response */
1379 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MT_MM_AUTH_RESP_2G('00000000'O)));
1380
1381 /* Expect GSUP AUTH FAIL REP to HLR */
1382 GSUP.receive(tr_GSUP_AUTH_FAIL_IND(g_pars.imsi));
1383
1384 /* Expect LU REJECT with Cause == Illegal MS */
1385 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej('03'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +01001386 f_expect_clear();
Harald Weltec638f4d2018-01-24 22:00:36 +01001387}
1388testcase TC_lu_auth_2G_fail() runs on MTC_CT {
1389 var BSC_ConnHdlr vc_conn;
1390 f_init();
1391 f_vty_config(MSCVTY, "network", "authentication required");
Harald Weltec638f4d2018-01-24 22:00:36 +01001392
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001393 vc_conn := f_start_handler(refers(f_tc_lu_auth_2G_fail), 23, verify_cell_id := false);
Harald Weltec638f4d2018-01-24 22:00:36 +01001394 vc_conn.done;
1395}
1396
Harald Weltede371492018-01-27 23:44:41 +01001397/* A5/1 + A5/3 permitted on network side, and MS capable to do it */
Harald Welte16114282018-01-24 22:41:21 +01001398private function f_tc_lu_imsi_auth_tmsi_encr_13_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +01001399 pars.net.expect_auth := true;
1400 pars.net.expect_ciph := true;
Harald Weltea10db902018-01-27 12:44:49 +01001401 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001402 f_perform_lu();
Harald Welte16114282018-01-24 22:41:21 +01001403}
1404testcase TC_lu_imsi_auth_tmsi_encr_13_13() runs on MTC_CT {
1405 var BSC_ConnHdlr vc_conn;
1406 f_init();
1407 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte16114282018-01-24 22:41:21 +01001408 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
1409
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001410 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_13), 24);
Harald Welte16114282018-01-24 22:41:21 +01001411 vc_conn.done;
1412}
1413
Harald Welte1af6ea82018-01-25 18:33:15 +01001414/* Test Complete L3 without payload */
1415private function f_tc_cl3_no_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001416 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001417
1418 /* Send Complete L3 Info with empty L3 frame */
1419 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1420 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, ''O))));
1421
Harald Weltef466eb42018-01-27 14:26:54 +01001422 timer T := 5.0;
1423 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001424 alt {
Harald Welte6811d102019-04-14 22:23:14 +02001425 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte1af6ea82018-01-25 18:33:15 +01001426 /* Expect LU REJECT with Cause == Illegal MS */
Harald Weltebdb3c452018-03-18 22:43:06 +01001427 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
Harald Welte6811d102019-04-14 22:23:14 +02001428 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001429 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001430 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001431 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001432 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001433 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001434 }
1435 setverdict(pass);
1436}
1437testcase TC_cl3_no_payload() runs on MTC_CT {
1438 var BSC_ConnHdlr vc_conn;
1439 f_init();
1440
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001441 vc_conn := f_start_handler(refers(f_tc_cl3_no_payload), 25);
Harald Welte1af6ea82018-01-25 18:33:15 +01001442 vc_conn.done;
1443}
1444
1445/* Test Complete L3 with random payload */
1446private function f_tc_cl3_rnd_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001447 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001448
Daniel Willmannaa14a382018-07-26 08:29:45 +02001449 /* length is limited by PDU_BSSAP length field which includes some
1450 * other fields beside l3info payload. So payl can only be 240 bytes
1451 * Since rnd() returns values < 1 multiply with 241
1452 */
1453 var integer len := float2int(rnd() * 241.0);
Harald Welte1af6ea82018-01-25 18:33:15 +01001454 var octetstring payl := f_rnd_octstring(len);
1455
1456 /* Send Complete L3 Info with empty L3 frame */
1457 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1458 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, payl))));
1459
Harald Weltef466eb42018-01-27 14:26:54 +01001460 timer T := 5.0;
1461 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001462 alt {
1463 /* Immediate disconnect */
Harald Welte6811d102019-04-14 22:23:14 +02001464 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte1af6ea82018-01-25 18:33:15 +01001465 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
Harald Welte6811d102019-04-14 22:23:14 +02001466 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001467 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001468 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001469 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001470 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001471 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001472 }
1473 setverdict(pass);
1474}
1475testcase TC_cl3_rnd_payload() runs on MTC_CT {
1476 var BSC_ConnHdlr vc_conn;
1477 f_init();
1478
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001479 vc_conn := f_start_handler(refers(f_tc_cl3_rnd_payload), 26);
Harald Welte1af6ea82018-01-25 18:33:15 +01001480 vc_conn.done;
1481}
1482
Harald Welte116e4332018-01-26 22:17:48 +01001483/* Test Complete L3 with random payload */
Harald Weltee13cfb22019-04-23 16:52:02 +02001484friend function f_tc_establish_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001485 f_init_handler(pars);
Harald Welte116e4332018-01-26 22:17:48 +01001486
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001487 f_perform_lu();
Harald Welte116e4332018-01-26 22:17:48 +01001488
Harald Welteb9e86fa2018-04-09 18:18:31 +02001489 f_establish_fully();
Daniel Willmann898a7e02018-05-17 12:16:16 +02001490 f_expect_clear(10.0);
Harald Welte116e4332018-01-26 22:17:48 +01001491}
1492testcase TC_establish_and_nothing() runs on MTC_CT {
1493 var BSC_ConnHdlr vc_conn;
1494 f_init();
1495
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001496 vc_conn := f_start_handler(refers(f_tc_establish_and_nothing), 27);
Harald Welte116e4332018-01-26 22:17:48 +01001497 vc_conn.done;
1498}
1499
Harald Weltee13cfb22019-04-23 16:52:02 +02001500
Harald Welte12510c52018-01-26 22:26:24 +01001501/* Test MO Call SETUP with no response from MNCC */
Harald Weltee13cfb22019-04-23 16:52:02 +02001502friend function f_tc_mo_setup_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier109e6aa2018-10-17 10:53:32 +02001503 f_init_handler(pars, 190.0);
Harald Weltea10db902018-01-27 12:44:49 +01001504
Harald Welte12510c52018-01-26 22:26:24 +01001505 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001506 cpars.mgw_conn_2.resp := 0;
1507 cpars.stop_after_cc_setup := true;
1508
1509 f_vty_config(MSCVTY, "msc", "mncc guard-timeout 20");
Harald Welte12510c52018-01-26 22:26:24 +01001510
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001511 f_perform_lu();
Harald Welte12510c52018-01-26 22:26:24 +01001512
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001513 f_mo_call_establish(cpars);
Harald Welte12510c52018-01-26 22:26:24 +01001514
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001515 var default ccrel := activate(as_optional_cc_rel(cpars));
1516
Philipp Maier109e6aa2018-10-17 10:53:32 +02001517 f_expect_clear(185.0);
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001518
1519 deactivate(ccrel);
1520
1521 f_sleep(1.0);
Harald Welte12510c52018-01-26 22:26:24 +01001522}
1523testcase TC_mo_setup_and_nothing() runs on MTC_CT {
1524 var BSC_ConnHdlr vc_conn;
1525 f_init();
1526
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001527 vc_conn := f_start_handler(refers(f_tc_mo_setup_and_nothing), 28);
Harald Welte12510c52018-01-26 22:26:24 +01001528 vc_conn.done;
1529}
1530
Harald Weltee13cfb22019-04-23 16:52:02 +02001531
Harald Welte3ab88002018-01-26 22:37:25 +01001532/* Test MO Call with no response to RAN-side CRCX */
Harald Weltee13cfb22019-04-23 16:52:02 +02001533friend function f_tc_mo_crcx_ran_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001534 f_init_handler(pars);
Harald Welte3ab88002018-01-26 22:37:25 +01001535 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1536 var MNCC_PDU mncc;
1537 var MgcpCommand mgcp_cmd;
1538
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001539 f_perform_lu();
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001540 /* Do not respond to the second CRCX */
1541 cpars.mgw_conn_2.resp := 0;
1542 f_mo_call_establish(cpars);
Harald Welte3ab88002018-01-26 22:37:25 +01001543
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001544 var default ccrel := activate(as_optional_cc_rel(cpars));
Harald Welte3ab88002018-01-26 22:37:25 +01001545
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001546 f_expect_clear(60.0);
Harald Welte3ab88002018-01-26 22:37:25 +01001547
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001548 deactivate(ccrel);
Harald Welte3ab88002018-01-26 22:37:25 +01001549}
1550testcase TC_mo_crcx_ran_timeout() runs on MTC_CT {
1551 var BSC_ConnHdlr vc_conn;
1552 f_init();
1553
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001554 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_timeout), 29);
Harald Welte3ab88002018-01-26 22:37:25 +01001555 vc_conn.done;
1556}
1557
Harald Weltee13cfb22019-04-23 16:52:02 +02001558
Harald Welte0cc82d92018-01-26 22:52:34 +01001559/* Test MO Call with reject to RAN-side CRCX */
Harald Weltee13cfb22019-04-23 16:52:02 +02001560friend function f_tc_mo_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001561 f_init_handler(pars);
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001562
Harald Welte0cc82d92018-01-26 22:52:34 +01001563 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001564
1565 /* Respond with error for the first CRCX */
1566 cpars.mgw_conn_1.resp := -1;
Harald Welte0cc82d92018-01-26 22:52:34 +01001567
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001568 f_perform_lu();
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001569 f_mo_call_establish(cpars);
Harald Welte0cc82d92018-01-26 22:52:34 +01001570
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001571 var default ccrel := activate(as_optional_cc_rel(cpars));
1572 f_expect_clear(60.0);
1573 deactivate(ccrel);
Harald Welte0cc82d92018-01-26 22:52:34 +01001574}
1575testcase TC_mo_crcx_ran_reject() runs on MTC_CT {
1576 var BSC_ConnHdlr vc_conn;
1577 f_init();
1578
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001579 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_reject), 30);
Harald Welte0cc82d92018-01-26 22:52:34 +01001580 vc_conn.done;
1581}
1582
Harald Welte3ab88002018-01-26 22:37:25 +01001583
Harald Welte812f7a42018-01-27 00:49:18 +01001584/* helper function to start a MT call: MNCC SETUP; Paging; DChan est.; DTAP SETUP */
1585private function f_mt_call_start(inout CallParameters cpars) runs on BSC_ConnHdlr {
1586 var MNCC_PDU mncc;
1587 var MgcpCommand mgcp_cmd;
Harald Welte812f7a42018-01-27 00:49:18 +01001588
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001589 f_perform_lu();
Vadim Yanitskiyae747742020-01-10 00:23:10 +01001590 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Welte812f7a42018-01-27 00:49:18 +01001591
1592 /* Allocate call reference and send SETUP via MNCC to MSC */
1593 cpars.mncc_callref := f_rnd_int(2147483648);
1594 MNCC.send(ts_MNCC_SETUP_req(cpars.mncc_callref, hex2str(g_pars.msisdn),
1595 hex2str(cpars.called_party), hex2str(g_pars.imsi)));
1596
1597 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02001598 f_expect_paging();
1599
Harald Welte812f7a42018-01-27 00:49:18 +01001600 /* MS -> MSC: PAGING RESPONSE */
Harald Welteb9e86fa2018-04-09 18:18:31 +02001601 f_establish_fully(EST_TYPE_PAG_RESP);
Harald Welte812f7a42018-01-27 00:49:18 +01001602
1603 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1604
1605 /* MSC->MS: SETUP */
1606 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_SETUP(cpars.transaction_id, *, cpars.called_party)));
1607}
1608
1609/* Test MT Call */
Harald Weltee13cfb22019-04-23 16:52:02 +02001610friend function f_tc_mt_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001611 f_init_handler(pars);
Harald Welte812f7a42018-01-27 00:49:18 +01001612 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1613 var MNCC_PDU mncc;
1614 var MgcpCommand mgcp_cmd;
1615
1616 f_mt_call_start(cpars);
1617
1618 /* MS->MSC: CALL CONFIRMED */
1619 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1620
1621 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1622
1623 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1624 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001625
1626 /* Detect if the received CRCX is a wildcarded CRCX request. If yes,
1627 * set an endpoint name that fits the pattern. If not, just use the
1628 * endpoint name from the request */
1629 if (match(mgcp_cmd.line.ep, t_MGCP_EP_wildcard)) {
1630 cpars.mgcp_ep := "rtpbridge/1@mgw";
1631 } else {
1632 cpars.mgcp_ep := mgcp_cmd.line.ep;
1633 }
1634
Harald Welte812f7a42018-01-27 00:49:18 +01001635 /* Respond to CRCX with error */
1636 var MgcpResponse mgcp_rsp := {
1637 line := {
1638 code := "542",
1639 trans_id := mgcp_cmd.line.trans_id,
1640 string := "FORCED_FAIL"
1641 },
Harald Welte812f7a42018-01-27 00:49:18 +01001642 sdp := omit
1643 }
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001644 var MgcpParameter mgcp_rsp_param := {
1645 code := "Z",
1646 val := cpars.mgcp_ep
1647 };
1648 mgcp_rsp.params[0] := mgcp_rsp_param;
Harald Welte812f7a42018-01-27 00:49:18 +01001649 MGCP.send(mgcp_rsp);
1650
1651 timer T := 30.0;
1652 T.start;
1653 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001654 [] T.timeout {
1655 setverdict(fail, "Timeout waiting for channel release");
1656 mtc.stop;
1657 }
Harald Welte812f7a42018-01-27 00:49:18 +01001658 [] MNCC.receive { repeat; }
1659 [] GSUP.receive { repeat; }
1660 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1661 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
1662 f_create_mgcp_delete_ep(cpars.mgcp_ep);
1663 repeat;
1664 }
1665 [] MGCP.receive { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001666 [] as_clear_cmd_compl_disc();
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001667 [] as_optional_cc_rel(cpars);
Harald Welte812f7a42018-01-27 00:49:18 +01001668 }
1669}
1670testcase TC_mt_crcx_ran_reject() runs on MTC_CT {
1671 var BSC_ConnHdlr vc_conn;
1672 f_init();
1673
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001674 vc_conn := f_start_handler(refers(f_tc_mt_crcx_ran_reject), 31);
Harald Welte812f7a42018-01-27 00:49:18 +01001675 vc_conn.done;
1676}
1677
1678
Harald Weltee13cfb22019-04-23 16:52:02 +02001679
Harald Welte812f7a42018-01-27 00:49:18 +01001680/* Test MT Call T310 timer */
Harald Weltee13cfb22019-04-23 16:52:02 +02001681friend function f_tc_mt_t310(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltead2952e2018-01-27 14:12:46 +01001682 f_init_handler(pars, 200.0);
Harald Welte812f7a42018-01-27 00:49:18 +01001683 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1684 var MNCC_PDU mncc;
1685 var MgcpCommand mgcp_cmd;
1686
1687 f_mt_call_start(cpars);
1688
1689 /* MS->MSC: CALL CONFIRMED */
1690 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1691 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1692
1693 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1694 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
1695 cpars.mgcp_ep := mgcp_cmd.line.ep;
1696 /* FIXME: Respond to CRCX */
1697
1698 /* old libosmocore T310 default timeout is 180s. so let's wait 190 */
1699 timer T := 190.0;
1700 T.start;
1701 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001702 [] T.timeout {
1703 setverdict(fail, "Timeout waiting for T310");
1704 mtc.stop;
1705 }
Harald Welte812f7a42018-01-27 00:49:18 +01001706 [] MNCC.receive(tr_MNCC_DISC_ind(cpars.mncc_callref)) {
1707 MNCC.send(ts_MNCC_REL_req(cpars.mncc_callref, valueof(ts_MNCC_cause(23))));
1708 }
1709 }
1710 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_DISC(cpars.transaction_id)));
1711 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id)));
1712 /* FIXME: We're sending this with TIflag 0: allocated by sender, which is wrong */
1713 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id)));
1714
1715 alt {
Harald Welte812f7a42018-01-27 00:49:18 +01001716 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1717 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
1718 f_create_mgcp_delete_ep(cpars.mgcp_ep);
1719 repeat;
1720 }
Harald Welte5946b332018-03-18 23:32:21 +01001721 [] as_clear_cmd_compl_disc();
Harald Welte812f7a42018-01-27 00:49:18 +01001722 }
1723}
1724testcase TC_mt_t310() runs on MTC_CT {
1725 var BSC_ConnHdlr vc_conn;
1726 f_init();
1727
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001728 vc_conn := f_start_handler(refers(f_tc_mt_t310), 32);
Harald Welte812f7a42018-01-27 00:49:18 +01001729 vc_conn.done;
1730}
1731
Harald Weltee13cfb22019-04-23 16:52:02 +02001732
Harald Welte167458a2018-01-27 15:58:16 +01001733/* Perform successful LU + MO call, then GSUP LocationCancel. Subscriber must be denied CM SERV */
Harald Weltee13cfb22019-04-23 16:52:02 +02001734friend function f_tc_gsup_cancel(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte167458a2018-01-27 15:58:16 +01001735 f_init_handler(pars);
1736 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Harald Welte167458a2018-01-27 15:58:16 +01001737
1738 /* Location Update to make subscriber known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001739 f_perform_lu();
Harald Welte167458a2018-01-27 15:58:16 +01001740
1741 /* First MO call should succeed */
1742 f_mo_call(cpars);
1743
1744 /* Cancel the subscriber in the VLR */
1745 GSUP.send(ts_GSUP_CL_REQ(g_pars.imsi, OSMO_GSUP_CANCEL_TYPE_WITHDRAW));
1746 alt {
1747 [] GSUP.receive(tr_GSUP_CL_RES(g_pars.imsi)) { }
1748 [] GSUP.receive(tr_GSUP_CL_ERR(g_pars.imsi)) {
1749 setverdict(fail, "Received GSUP Location Cancel Error");
Daniel Willmannafce8662018-07-06 23:11:32 +02001750 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001751 }
1752 }
1753
1754 /* Follow-up transactions should fail */
1755 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1756 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001757 f_cl3_or_initial_ue(l3_info);
Harald Welte167458a2018-01-27 15:58:16 +01001758 alt {
1759 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
1760 [] BSSAP.receive {
1761 setverdict(fail, "Received unexpected BSSAP instead of CM SERV REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +02001762 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001763 }
1764 }
Neels Hofmeyr0f7429a2019-03-07 22:28:41 +01001765
1766 f_expect_clear();
Harald Welte167458a2018-01-27 15:58:16 +01001767 setverdict(pass);
1768}
1769testcase TC_gsup_cancel() runs on MTC_CT {
1770 var BSC_ConnHdlr vc_conn;
1771 f_init();
1772
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001773 vc_conn := f_start_handler(refers(f_tc_gsup_cancel), 33, verify_cell_id := false);
Harald Welte167458a2018-01-27 15:58:16 +01001774 vc_conn.done;
1775}
1776
Harald Weltee13cfb22019-04-23 16:52:02 +02001777
Harald Welte9de84792018-01-28 01:06:35 +01001778/* A5/1 only permitted on network side, and MS capable to do it */
1779private function f_tc_lu_imsi_auth_tmsi_encr_1_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1780 pars.net.expect_auth := true;
1781 pars.net.expect_ciph := true;
1782 pars.net.kc_support := '02'O; /* A5/1 only */
1783 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001784 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001785}
1786testcase TC_lu_imsi_auth_tmsi_encr_1_13() runs on MTC_CT {
1787 var BSC_ConnHdlr vc_conn;
1788 f_init();
1789 f_vty_config(MSCVTY, "network", "authentication required");
1790 f_vty_config(MSCVTY, "network", "encryption a5 1");
1791
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001792 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_1_13), 34);
Harald Welte9de84792018-01-28 01:06:35 +01001793 vc_conn.done;
1794}
1795
1796/* A5/3 only permitted on network side, and MS capable to do it */
1797private function f_tc_lu_imsi_auth_tmsi_encr_3_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1798 pars.net.expect_auth := true;
1799 pars.net.expect_ciph := true;
1800 pars.net.kc_support := '08'O; /* A5/3 only */
1801 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001802 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001803}
1804testcase TC_lu_imsi_auth_tmsi_encr_3_13() runs on MTC_CT {
1805 var BSC_ConnHdlr vc_conn;
1806 f_init();
1807 f_vty_config(MSCVTY, "network", "authentication required");
1808 f_vty_config(MSCVTY, "network", "encryption a5 3");
1809
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001810 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_13), 35);
Harald Welte9de84792018-01-28 01:06:35 +01001811 vc_conn.done;
1812}
1813
1814/* A5/3 only permitted on network side, and MS with only A5/1 support */
1815private function f_tc_lu_imsi_auth_tmsi_encr_3_1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1816 pars.net.expect_auth := true;
1817 pars.net.expect_ciph := true;
1818 pars.net.kc_support := '08'O; /* A5/3 only */
1819 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1820 f_init_handler(pars, 15.0);
1821
1822 /* cannot use f_perform_lu() as we expect a reject */
1823 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
1824 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +02001825 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001826 if (pars.send_early_cm) {
1827 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1828 } else {
1829 pars.cm1.esind := '0'B;
1830 }
Harald Welte9de84792018-01-28 01:06:35 +01001831 f_mm_auth();
1832 alt {
Daniel Willmann52918e52018-09-20 14:39:09 +02001833 [] BSSAP.receive(tr_BSSMAP_ClassmarkReq) {
1834 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1835 repeat;
1836 }
Harald Welte5946b332018-03-18 23:32:21 +01001837 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1838 f_expect_clear();
1839 }
Harald Welte9de84792018-01-28 01:06:35 +01001840 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
1841 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02001842 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001843 }
1844 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01001845 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02001846 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001847 }
1848 }
1849 setverdict(pass);
1850}
1851testcase TC_lu_imsi_auth_tmsi_encr_3_1() runs on MTC_CT {
1852 var BSC_ConnHdlr vc_conn;
1853 f_init();
1854 f_vty_config(MSCVTY, "network", "authentication required");
1855 f_vty_config(MSCVTY, "network", "encryption a5 3");
1856
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001857 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 360, verify_cell_id := false);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001858 vc_conn.done;
1859}
1860testcase TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() runs on MTC_CT {
1861 var BSC_ConnHdlrPars pars;
1862 var BSC_ConnHdlr vc_conn;
1863 f_init();
1864 f_vty_config(MSCVTY, "network", "authentication required");
1865 f_vty_config(MSCVTY, "network", "encryption a5 3");
1866
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001867 pars := f_init_pars(361, verify_cell_id := false);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001868 pars.send_early_cm := false;
1869 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), pars);
Harald Welte9de84792018-01-28 01:06:35 +01001870 vc_conn.done;
1871}
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01001872testcase TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() runs on MTC_CT {
1873 var BSC_ConnHdlr vc_conn;
1874 f_init();
1875 f_vty_config(MSCVTY, "network", "authentication required");
1876 f_vty_config(MSCVTY, "network", "encryption a5 3");
1877
1878 /* Make sure the MSC category is on DEBUG level to trigger the log
1879 * message that is reported in OS#2947 to trigger the segfault */
1880 f_vty_config(MSCVTY, "log stderr", "logging level msc debug");
1881
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001882 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 362, verify_cell_id := false);
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01001883 vc_conn.done;
1884}
Harald Welte9de84792018-01-28 01:06:35 +01001885
1886/* A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
1887private function f_tc_lu_imsi_auth_tmsi_encr_13_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1888 pars.net.expect_auth := true;
1889 pars.net.expect_ciph := true;
1890 pars.net.kc_support := '0A'O; /* A5/1 + A5/3 */
1891 pars.cm1.a5_1 := '1'B;
1892 pars.cm2.a5_1 := '1'B;
1893 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1894 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
1895 f_init_handler(pars, 15.0);
1896
1897 /* cannot use f_perform_lu() as we expect a reject */
1898 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
1899 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +02001900 f_cl3_or_initial_ue(l3_lu);
Harald Welte9de84792018-01-28 01:06:35 +01001901 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1902 f_mm_auth();
1903 alt {
Harald Welte5946b332018-03-18 23:32:21 +01001904 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1905 f_expect_clear();
1906 }
Harald Welte9de84792018-01-28 01:06:35 +01001907 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
1908 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02001909 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001910 }
1911 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01001912 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02001913 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001914 }
1915 }
1916 setverdict(pass);
1917}
1918testcase TC_lu_imsi_auth_tmsi_encr_13_2() runs on MTC_CT {
1919 var BSC_ConnHdlr vc_conn;
1920 f_init();
1921 f_vty_config(MSCVTY, "network", "authentication required");
1922 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
1923
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001924 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_2), 37, verify_cell_id := false);
Harald Welte9de84792018-01-28 01:06:35 +01001925 vc_conn.done;
1926}
1927
1928/* A5/0 + A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
1929private function f_tc_lu_imsi_auth_tmsi_encr_013_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1930 pars.net.expect_auth := true;
1931 pars.net.expect_ciph := true;
1932 pars.net.kc_support := '0B'O; /* A5/1 + A5/3 */
1933 pars.cm1.a5_1 := '1'B;
1934 pars.cm2.a5_1 := '1'B;
1935 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1936 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
1937 f_init_handler(pars, 15.0);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001938 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001939}
1940testcase TC_lu_imsi_auth_tmsi_encr_013_2() runs on MTC_CT {
1941 var BSC_ConnHdlr vc_conn;
1942 f_init();
1943 f_vty_config(MSCVTY, "network", "authentication required");
1944 f_vty_config(MSCVTY, "network", "encryption a5 0 1 3");
1945
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001946 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_013_2), 38);
Harald Welte9de84792018-01-28 01:06:35 +01001947 vc_conn.done;
1948}
1949
Harald Welte33ec09b2018-02-10 15:34:46 +01001950/* LU followed by MT call (including paging) */
Neels Hofmeyr8fe8a902019-11-03 05:51:03 +01001951friend function f_tc_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte33ec09b2018-02-10 15:34:46 +01001952 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01001953 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02001954 cpars.use_osmux := pars.use_osmux;
Harald Welte33ec09b2018-02-10 15:34:46 +01001955
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001956 f_perform_lu();
Harald Welte33ec09b2018-02-10 15:34:46 +01001957 f_mt_call(cpars);
1958}
1959testcase TC_lu_and_mt_call() runs on MTC_CT {
1960 var BSC_ConnHdlr vc_conn;
1961 f_init();
1962
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001963 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call), 39);
Harald Welte33ec09b2018-02-10 15:34:46 +01001964 vc_conn.done;
1965}
1966
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02001967testcase TC_lu_and_mt_call_osmux() runs on MTC_CT {
1968 var BSC_ConnHdlr vc_conn;
1969 f_init(1, false, true, true);
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02001970
1971 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call), 39, 0, true, true);
1972 vc_conn.done;
1973}
1974
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02001975/* LU followed by MT call (including paging) */
1976friend function f_tc_lu_and_mt_call_ipv6(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1977 f_init_handler(pars);
1978 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1979 cpars.mgw_conn_1.mgw_rtp_ip := "::1";
1980 cpars.mgw_conn_2.mgw_rtp_ip := "::2";
1981 cpars.bss_rtp_ip := "::3";
Pau Espin Pedrol563b3d02020-09-09 20:19:52 +02001982 cpars.mncc_rtp_ip := "::9";
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02001983 f_perform_lu();
1984 f_mt_call(cpars);
1985}
1986testcase TC_lu_and_mt_call_ipv6() runs on MTC_CT {
1987 var BSC_ConnHdlr vc_conn;
1988 f_init();
1989
1990 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call_ipv6), 39);
1991 vc_conn.done;
1992}
1993
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01001994/* MT call while already Paging */
1995friend function f_tc_lu_and_mt_call_already_paging(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1996 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1997 var SmsParameters spars := valueof(t_SmsPars);
1998 var OCT4 tmsi;
1999
2000 f_init_handler(pars);
2001
2002 /* Perform location update */
2003 f_perform_lu();
2004
2005 /* register an 'expect' for given IMSI (+TMSI) */
2006 if (isvalue(g_pars.tmsi)) {
2007 tmsi := g_pars.tmsi;
2008 } else {
2009 tmsi := 'FFFFFFFF'O;
2010 }
2011 f_ran_register_imsi(g_pars.imsi, tmsi);
2012
2013 log("start Paging by an SMS");
2014 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2015
2016 /* MSC->BSC: expect PAGING from MSC */
2017 f_expect_paging();
2018
2019 log("MNCC signals MT call, before Paging Response");
2020 f_mt_call_initate(cpars);
2021 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
2022
2023 f_sleep(0.5);
2024 log("phone answers Paging, expecting both SMS and MT call to be established");
2025 f_establish_fully(EST_TYPE_PAG_RESP);
2026 spars.tp.ud := 'C8329BFD064D9B53'O;
2027 interleave {
2028 [] BSSAP.receive(f_mt_sms_deliver_pdu(spars)) {
2029 log("Got SMS-DELIVER");
2030 };
2031 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_SETUP(cpars.transaction_id, *, cpars.called_party))) {
2032 log("Got CC Setup");
2033 };
2034 }
2035 setverdict(pass);
2036 log("success, tear down");
2037 var default ccrel := activate(as_optional_cc_rel(cpars));
2038 if (g_pars.ran_is_geran) {
2039 BSSAP.send(ts_BSSMAP_ClearRequest(0));
2040 } else {
2041 BSSAP.send(ts_RANAP_IuReleaseRequest(ts_RanapCause_om_intervention));
2042 }
2043 f_expect_clear();
2044 deactivate(ccrel);
2045 f_vty_sms_clear(hex2str(g_pars.imsi));
2046}
2047testcase TC_lu_and_mt_call_already_paging() runs on MTC_CT {
2048 var BSC_ConnHdlrPars pars;
2049 var BSC_ConnHdlr vc_conn;
2050 f_init();
2051 pars := f_init_pars(391);
2052 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_call_already_paging), pars);
2053 vc_conn.done;
2054}
2055
Daniel Willmann8b084372018-02-04 13:35:26 +01002056/* Test MO Call SETUP with DTMF */
2057private function f_tc_mo_setup_dtmf_dup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2058 f_init_handler(pars);
2059 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Daniel Willmann8b084372018-02-04 13:35:26 +01002060
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01002061 f_perform_lu();
Daniel Willmann8b084372018-02-04 13:35:26 +01002062 f_mo_seq_dtmf_dup(cpars);
2063}
2064testcase TC_mo_setup_and_dtmf_dup() runs on MTC_CT {
2065 var BSC_ConnHdlr vc_conn;
2066 f_init();
2067
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01002068 vc_conn := f_start_handler(refers(f_tc_mo_setup_dtmf_dup), 39);
Daniel Willmann8b084372018-02-04 13:35:26 +01002069 vc_conn.done;
2070}
Harald Welte9de84792018-01-28 01:06:35 +01002071
Philipp Maier328d1662018-03-07 10:40:27 +01002072testcase TC_cr_before_reset() runs on MTC_CT {
2073 timer T := 4.0;
2074 var boolean reset_ack_seen := false;
2075 f_init_bssap_direct();
2076
Harald Welte3ca0ce12019-04-23 17:18:48 +02002077 f_ran_adapter_start(g_bssap[0]);
Daniel Willmann42d1d5b2018-08-07 15:18:41 +02002078
Daniel Willmanne8018962018-08-21 14:18:00 +02002079 f_sleep(3.0);
2080
Philipp Maier328d1662018-03-07 10:40:27 +01002081 /* Make a blind connection attemt, to trigger the deadlock condition */
Philipp Maier75932982018-03-27 14:52:35 +02002082 BSSAP_DIRECT.send(ts_BSSAP_CONNECT_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, 1, omit));
Philipp Maier328d1662018-03-07 10:40:27 +01002083
2084 /* Send a BSSMAP reset */
Philipp Maier75932982018-03-27 14:52:35 +02002085 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_Reset(0)));
Philipp Maier328d1662018-03-07 10:40:27 +01002086 T.start
2087 alt {
2088 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_ResetAck)) {
2089 reset_ack_seen := true;
2090 repeat;
2091 }
2092
2093 /* Acknowledge MSC sided reset requests */
2094 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_Reset)) {
Philipp Maier75932982018-03-27 14:52:35 +02002095 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_ResetAck));
Philipp Maier328d1662018-03-07 10:40:27 +01002096 repeat;
2097 }
2098
2099 /* Ignore all other messages (e.g CR from the connection request) */
2100 [] BSSAP_DIRECT.receive { repeat }
2101
2102 /* If we got no BSSMAP RESET ACK back, then the MSC entered the
2103 * deadlock situation. The MSC is then unable to respond to any
2104 * further BSSMAP RESET or any other sort of traffic. */
2105 [reset_ack_seen == true] T.timeout { setverdict(pass) }
2106 [reset_ack_seen == false] T.timeout {
2107 setverdict(fail, "no BSSMAP RESET ACK seen!");
Daniel Willmannafce8662018-07-06 23:11:32 +02002108 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +01002109 }
Pau Espin Pedrol7e9178d2019-12-17 17:52:17 +01002110 }
Philipp Maier328d1662018-03-07 10:40:27 +01002111}
Harald Welte9de84792018-01-28 01:06:35 +01002112
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002113/* Test MO Call with no response to RAN-side CRCX or DTAP Release */
Harald Weltee13cfb22019-04-23 16:52:02 +02002114friend function f_tc_mo_release_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002115 f_init_handler(pars);
2116 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
2117 var MNCC_PDU mncc;
2118 var MgcpCommand mgcp_cmd;
2119
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02002120 /* Do not respond to the second CRCX */
2121 cpars.mgw_conn_2.resp := 0;
2122
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002123 f_perform_lu();
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02002124 f_mo_call_establish(cpars);
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002125
Neels Hofmeyrde76f052019-02-26 05:02:46 +01002126 var default ccrel := activate(as_optional_cc_rel(cpars));
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002127
2128 f_expect_clear(60.0);
Neels Hofmeyrde76f052019-02-26 05:02:46 +01002129
2130 deactivate(ccrel);
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002131}
2132testcase TC_mo_release_timeout() runs on MTC_CT {
2133 var BSC_ConnHdlr vc_conn;
2134 f_init();
2135
2136 vc_conn := f_start_handler(refers(f_tc_mo_release_timeout), 40);
2137 vc_conn.done;
2138}
2139
Harald Welte12510c52018-01-26 22:26:24 +01002140
Philipp Maier2a98a732018-03-19 16:06:12 +01002141/* LU followed by MT call (including paging) */
2142private function f_tc_lu_and_mt_call_no_dlcx_resp(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2143 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01002144 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Philipp Maier2a98a732018-03-19 16:06:12 +01002145
2146 /* Intentionally disable the CRCX response */
2147 cpars.mgw_drop_dlcx := true;
2148
2149 /* Perform location update and call */
2150 f_perform_lu();
2151 f_mt_call(cpars);
2152}
2153testcase TC_lu_and_mt_call_no_dlcx_resp() runs on MTC_CT {
2154 var BSC_ConnHdlr vc_conn;
2155 f_init();
2156
2157 /* Perform an almost normal looking locationupdate + mt-call, but do
2158 * not respond to the DLCX at the end of the call */
2159 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call_no_dlcx_resp), 41);
2160 vc_conn.done;
2161
2162 /* Wait a guard period until the MGCP layer in the MSC times out,
2163 * if the MSC is vulnerable to the use-after-free situation that is
2164 * fixed by I78f1b6a9149488a4ad3f120c1e190a83c07d4b89 then it should
2165 * segfault now */
2166 f_sleep(6.0);
2167
2168 /* Run the init procedures once more. If the MSC has crashed, this
2169 * this will fail */
2170 f_init();
2171}
Harald Welte45164da2018-01-24 12:51:27 +01002172
Philipp Maier75932982018-03-27 14:52:35 +02002173/* Two BSSMAP resets from two different BSCs */
2174testcase TC_reset_two() runs on MTC_CT {
2175 var BSC_ConnHdlr vc_conn;
2176 f_init(2);
2177 f_sleep(2.0);
2178 setverdict(pass);
2179}
2180
Harald Weltee13cfb22019-04-23 16:52:02 +02002181/* Two BSSMAP resets from two different BSCs plus one IuCS RANAP Reset */
2182testcase TC_reset_two_1iu() runs on MTC_CT {
2183 var BSC_ConnHdlr vc_conn;
2184 f_init(3);
2185 f_sleep(2.0);
2186 setverdict(pass);
2187}
2188
Harald Weltef640a012018-04-14 17:49:21 +02002189/***********************************************************************
2190 * SMS Testing
2191 ***********************************************************************/
2192
Harald Weltef45efeb2018-04-09 18:19:24 +02002193/* LU followed by MO SMS */
Harald Weltee13cfb22019-04-23 16:52:02 +02002194friend function f_tc_lu_and_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02002195 var SmsParameters spars := valueof(t_SmsPars);
2196
2197 f_init_handler(pars);
2198
2199 /* Perform location update and call */
2200 f_perform_lu();
2201
2202 f_establish_fully(EST_TYPE_MO_SMS);
2203
2204 //spars.exp_rp_err := 96; /* invalid mandatory information */
2205 f_mo_sms(spars);
2206
2207 f_expect_clear();
2208}
2209testcase TC_lu_and_mo_sms() runs on MTC_CT {
2210 var BSC_ConnHdlr vc_conn;
2211 f_init();
2212 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_sms), 42);
2213 vc_conn.done;
2214}
2215
Harald Weltee13cfb22019-04-23 16:52:02 +02002216
Harald Weltef45efeb2018-04-09 18:19:24 +02002217private function f_vty_sms_send(charstring imsi, charstring msisdn, charstring text)
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002218runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02002219 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
2220}
2221
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01002222/* Remove still pending SMS */
2223private function f_vty_sms_clear(charstring imsi)
2224runs on BSC_ConnHdlr {
2225 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " sms delete-all");
2226 f_vty_transceive(MSCVTY, "sms-queue clear");
2227}
2228
Harald Weltef45efeb2018-04-09 18:19:24 +02002229/* LU followed by MT SMS */
Harald Weltee13cfb22019-04-23 16:52:02 +02002230friend function f_tc_lu_and_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02002231 var SmsParameters spars := valueof(t_SmsPars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002232
2233 f_init_handler(pars);
2234
2235 /* Perform location update and call */
2236 f_perform_lu();
2237
2238 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002239 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Weltef45efeb2018-04-09 18:19:24 +02002240
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002241 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
Harald Weltef45efeb2018-04-09 18:19:24 +02002242
2243 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02002244 f_expect_paging();
2245
Harald Weltef45efeb2018-04-09 18:19:24 +02002246 /* Establish DTAP / BSSAP / SCCP connection */
2247 f_establish_fully(EST_TYPE_PAG_RESP);
2248
2249 spars.tp.ud := 'C8329BFD064D9B53'O;
2250 f_mt_sms(spars);
2251
2252 f_expect_clear();
2253}
2254testcase TC_lu_and_mt_sms() runs on MTC_CT {
2255 var BSC_ConnHdlrPars pars;
2256 var BSC_ConnHdlr vc_conn;
2257 f_init();
2258 pars := f_init_pars(43);
2259 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms), pars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002260 vc_conn.done;
2261}
2262
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01002263/* SMS added while already Paging */
2264friend function f_tc_lu_and_mt_sms_already_paging(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2265 var SmsParameters spars := valueof(t_SmsPars);
2266 var OCT4 tmsi;
2267
2268 f_init_handler(pars);
2269
2270 f_perform_lu();
2271
2272 /* register an 'expect' for given IMSI (+TMSI) */
2273 if (isvalue(g_pars.tmsi)) {
2274 tmsi := g_pars.tmsi;
2275 } else {
2276 tmsi := 'FFFFFFFF'O;
2277 }
2278 f_ran_register_imsi(g_pars.imsi, tmsi);
2279
2280 log("first SMS");
2281 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2282
2283 /* MSC->BSC: expect PAGING from MSC */
2284 f_expect_paging();
2285
2286 log("second SMS");
2287 /* Now osmo-msc is in state "Paging pending", make sure that another SMS to be sent at this time just joins in
2288 * with the pending paging. Another SMS: */
2289 f_vty_sms_send(hex2str(pars.imsi), "2342", "Another SMS");
2290
2291 /* Establish DTAP / BSSAP / SCCP connection */
2292 f_establish_fully(EST_TYPE_PAG_RESP);
2293
2294 spars.tp.ud := 'C8329BFD064D9B53'O;
2295 f_mt_sms(spars);
2296
2297 spars.tp.ud := '41F79B8E2ECB41D3E614'O;
2298 f_mt_sms(spars);
2299
2300 f_expect_clear();
2301}
2302testcase TC_lu_and_mt_sms_already_paging() runs on MTC_CT {
2303 var BSC_ConnHdlrPars pars;
2304 var BSC_ConnHdlr vc_conn;
2305 f_init();
2306 pars := f_init_pars(44);
2307 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_already_paging), pars);
2308 vc_conn.done;
2309}
Harald Weltee13cfb22019-04-23 16:52:02 +02002310
Philipp Maier3983e702018-11-22 19:01:33 +01002311/* Paging for MT SMS but no response */
Harald Weltee13cfb22019-04-23 16:52:02 +02002312friend function f_tc_lu_and_mt_sms_paging_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier3983e702018-11-22 19:01:33 +01002313 var SmsParameters spars := valueof(t_SmsPars);
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002314
Philipp Maier3983e702018-11-22 19:01:33 +01002315 f_init_handler(pars, 150.0);
2316
2317 /* Perform location update */
2318 f_perform_lu();
2319
2320 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002321 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Philipp Maier3983e702018-11-22 19:01:33 +01002322
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002323 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2324
Neels Hofmeyr16237742019-03-06 15:34:01 +01002325 /* Expect the MSC to page exactly once */
Harald Weltee13cfb22019-04-23 16:52:02 +02002326 f_expect_paging();
Philipp Maier3983e702018-11-22 19:01:33 +01002327
2328 /* Wait some time to make sure the MSC is not delivering any further
2329 * paging messages or anything else that could be unexpected. */
2330 timer T := 20.0;
2331 T.start
2332 alt {
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002333 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
2334 setverdict(fail, "paging seems not to stop!");
2335 mtc.stop;
Philipp Maier3983e702018-11-22 19:01:33 +01002336 }
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002337 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
2338 setverdict(fail, "paging seems not to stop!");
2339 mtc.stop;
Harald Weltee13cfb22019-04-23 16:52:02 +02002340 }
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002341 [] BSSAP.receive {
2342 setverdict(fail, "unexpected BSSAP message received");
2343 self.stop;
Philipp Maier3983e702018-11-22 19:01:33 +01002344 }
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002345 [] T.timeout {
2346 setverdict(pass);
Philipp Maier3983e702018-11-22 19:01:33 +01002347 }
2348 }
2349
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01002350 f_vty_sms_clear(hex2str(g_pars.imsi));
2351
Philipp Maier3983e702018-11-22 19:01:33 +01002352 setverdict(pass);
2353}
2354testcase TC_lu_and_mt_sms_paging_and_nothing() runs on MTC_CT {
2355 var BSC_ConnHdlrPars pars;
2356 var BSC_ConnHdlr vc_conn;
2357 f_init();
Philipp Maiera99ad262019-01-22 15:35:42 +01002358 pars := f_init_pars(1843);
Philipp Maier3983e702018-11-22 19:01:33 +01002359 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_paging_and_nothing), pars);
Philipp Maier3983e702018-11-22 19:01:33 +01002360 vc_conn.done;
2361}
2362
Alexander Couzensfc02f242019-09-12 03:43:18 +02002363/* LU followed by MT SMS with repeated paging */
2364friend function f_tc_lu_and_mt_sms_paging_repeated(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2365 var SmsParameters spars := valueof(t_SmsPars);
Alexander Couzensfc02f242019-09-12 03:43:18 +02002366
2367 f_init_handler(pars);
2368
2369 /* Perform location update and call */
2370 f_perform_lu();
2371
2372 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002373 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Alexander Couzensfc02f242019-09-12 03:43:18 +02002374
2375 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2376
Neels Hofmeyrc3accec2019-11-28 01:09:47 +01002377 log("Expecting first Paging");
Alexander Couzensfc02f242019-09-12 03:43:18 +02002378 /* MSC->BSC: expect PAGING from MSC */
2379 f_expect_paging();
2380
Neels Hofmeyrc3accec2019-11-28 01:09:47 +01002381 if (g_pars.ran_is_geran) {
2382 log("GERAN: expect no further Paging");
2383 } else {
2384 log("UTRAN: expect more Paging");
2385 }
2386
2387 timer T := 5.0;
2388 T.start;
2389 alt {
2390 [g_pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
2391 setverdict(fail, "GERAN should not repeat Paging, but received a second Paging");
2392 mtc.stop;
2393 }
2394 [not g_pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
2395 log("UTRAN: second Paging received, as expected");
2396 setverdict(pass);
2397 }
2398 [] T.timeout {
2399 if (g_pars.ran_is_geran) {
2400 log("GERAN: No further Paging received, as expected");
2401 setverdict(pass);
2402 } else {
2403 setverdict(fail, "UTRAN: Expected a second Paging");
2404 mtc.stop;
2405 }
2406 }
2407 }
Alexander Couzensfc02f242019-09-12 03:43:18 +02002408
2409 /* Establish DTAP / BSSAP / SCCP connection */
2410 f_establish_fully(EST_TYPE_PAG_RESP);
2411
2412 spars.tp.ud := 'C8329BFD064D9B53'O;
2413 f_mt_sms(spars);
2414
2415 f_expect_clear();
2416}
2417testcase TC_lu_and_mt_sms_paging_repeated() runs on MTC_CT {
2418 var BSC_ConnHdlrPars pars;
2419 var BSC_ConnHdlr vc_conn;
2420 f_init();
2421 pars := f_init_pars(1844);
2422 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_paging_repeated), pars);
2423 vc_conn.done;
2424}
Harald Weltee13cfb22019-04-23 16:52:02 +02002425
Harald Weltef640a012018-04-14 17:49:21 +02002426/* mobile originated SMS from MS/BTS/BSC side to SMPP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002427friend function f_tc_smpp_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef640a012018-04-14 17:49:21 +02002428 var SmsParameters spars := valueof(t_SmsPars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002429
Harald Weltef640a012018-04-14 17:49:21 +02002430 f_init_handler(pars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002431
Harald Weltef640a012018-04-14 17:49:21 +02002432 /* Perform location update so IMSI is known + registered in MSC/VLR */
2433 f_perform_lu();
Harald Weltef640a012018-04-14 17:49:21 +02002434
Vadim Yanitskiy2d3f8462020-01-15 11:44:12 +07002435 /* MS/UE submits a MO SMS */
2436 f_establish_fully(EST_TYPE_MO_SMS);
2437 f_mo_sms_submit(spars);
Harald Weltef640a012018-04-14 17:49:21 +02002438
2439 var SMPP_PDU smpp;
2440 var template SMPP_PDU tr_smpp := tr_SMPP(c_SMPP_command_id_deliver_sm, ESME_ROK);
2441 tr_smpp.body.deliver_sm := {
2442 service_type := "CMT",
2443 source_addr_ton := network_specific,
2444 source_addr_npi := isdn,
2445 source_addr := hex2str(pars.msisdn),
2446 dest_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
2447 dest_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
2448 destination_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
2449 esm_class := '00000001'B,
2450 protocol_id := 0,
2451 priority_flag := 0,
2452 schedule_delivery_time := "",
2453 replace_if_present := 0,
2454 data_coding := '00000001'B,
2455 sm_default_msg_id := 0,
2456 sm_length := ?,
2457 short_message := spars.tp.ud,
2458 opt_pars := {
2459 {
2460 tag := user_message_reference,
2461 len := 2,
2462 opt_value := {
2463 int2_val := oct2int(spars.tp.msg_ref)
2464 }
2465 }
2466 }
2467 };
2468 alt {
2469 [] SMPP.receive(tr_smpp) -> value smpp {
2470 SMPP.send(ts_SMPP_DELIVER_SM_resp(ESME_ROK, smpp.header.seq_num));
2471 }
2472 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK)) { repeat; }
2473 }
2474
Vadim Yanitskiy2d3f8462020-01-15 11:44:12 +07002475 /* MSC terminates the SMS transaction with RP-ACK */
2476 f_mo_sms_wait_rp_ack(spars);
2477
Harald Weltef640a012018-04-14 17:49:21 +02002478 f_expect_clear();
2479}
2480testcase TC_smpp_mo_sms() runs on MTC_CT {
2481 var BSC_ConnHdlr vc_conn;
2482 f_init();
2483 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "default-route");
2484 vc_conn := f_start_handler(refers(f_tc_smpp_mo_sms), 44);
2485 vc_conn.done;
2486 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "no default-route");
2487}
2488
Vadim Yanitskiy33820762020-01-15 11:26:07 +07002489/* Test case for OS#4351: make sure that RP-ERROR from ESME is properly sent to the MS/UE */
2490friend function f_tc_smpp_mo_sms_rp_error(charstring id, BSC_ConnHdlrPars pars)
2491runs on BSC_ConnHdlr {
2492 var SmsParameters spars := valueof(t_SmsPars);
2493 var SMPP_PDU smpp_pdu;
2494 timer T := 3.0;
2495
2496 f_init_handler(pars);
2497
2498 /* Perform location update */
2499 f_perform_lu();
2500
2501 /* MS/UE submits a MO SMS */
2502 f_establish_fully(EST_TYPE_MO_SMS);
2503 f_mo_sms_submit(spars);
2504
2505 /* ESME responds with an error (Invalid Destination Address) */
2506 T.start;
2507 alt {
2508 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_deliver_sm, ESME_ROK, body := ?)) -> value smpp_pdu {
2509 SMPP.send(ts_SMPP_DELIVER_SM_resp(ESME_RINVDSTADR, smpp_pdu.header.seq_num));
2510 }
2511 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK)) { repeat; }
2512 [] T.timeout {
2513 setverdict(fail, "Timeout waiting for SMPP DELIVER-SM");
2514 mtc.stop;
2515 }
2516 }
2517
2518 /* Expect RP-ERROR on BSSAP interface */
2519 spars.exp_rp_err := 1; /* FIXME: GSM411_RP_CAUSE_MO_NUM_UNASSIGNED */
2520 f_mo_sms_wait_rp_ack(spars);
2521
2522 f_expect_clear();
2523}
2524testcase TC_smpp_mo_sms_rp_error() runs on MTC_CT {
2525 var BSC_ConnHdlr vc_conn;
2526 f_init();
2527 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "default-route");
2528 vc_conn := f_start_handler(refers(f_tc_smpp_mo_sms_rp_error), 45);
2529 vc_conn.done;
2530 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "no default-route");
2531}
2532
Harald Weltee13cfb22019-04-23 16:52:02 +02002533
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002534/* Test MO-SMS from MS/BTS/BSC towards HLR (via GSUP) */
Harald Weltee13cfb22019-04-23 16:52:02 +02002535friend function f_tc_gsup_mo_sms(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002536runs on BSC_ConnHdlr {
2537 var SmsParameters spars := valueof(t_SmsPars);
2538 var GSUP_PDU gsup_msg_rx;
2539 var octetstring sm_tpdu;
2540
2541 f_init_handler(pars);
2542
2543 /* We need to inspect GSUP activity */
2544 f_create_gsup_expect(hex2str(g_pars.imsi));
2545
2546 /* Perform location update */
2547 f_perform_lu();
2548
2549 /* Send CM Service Request for SMS */
2550 f_establish_fully(EST_TYPE_MO_SMS);
2551
2552 /* Prepare expected SM-RP-UI (SM TPDU) */
2553 enc_TPDU_RP_DATA_MS_SGSN_fast(
2554 valueof(ts_SMS_SUBMIT(spars.tp.msg_ref,
2555 spars.tp.da, spars.tp.pid, spars.tp.dcs,
2556 spars.tp.udl, spars.tp.ud)),
2557 sm_tpdu);
2558
2559 var template GSUP_PDU mo_forwardSM := tr_GSUP_MO_FORWARD_SM_REQ(
2560 imsi := g_pars.imsi,
2561 sm_rp_mr := spars.rp.msg_ref,
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09002562 /* SM-RP-DA: SMSC address */
2563 sm_rp_da := tr_GSUP_SM_RP_DA_SMSC_ADDR(t_GSUP_SM_RP_Addr(
2564 number := spars.rp.smsc_addr.rP_NumberDigits,
2565 npi := spars.rp.smsc_addr.rP_NumberingPlanIdentification,
2566 ton := spars.rp.smsc_addr.rP_TypeOfNumber,
2567 ext := spars.rp.smsc_addr.rP_Ext)),
2568 /* SM-RP-OA: subscriber's MSISDN (filled in by MSC) */
2569 sm_rp_oa := tr_GSUP_SM_RP_OA_MSISDN(t_GSUP_SM_RP_Addr(
2570 number := g_pars.msisdn,
2571 /* NOTE: MSISDN in g_pars lacks this info, assuming defaults */
2572 npi := '0001'B, ton := '001'B, ext := '1'B)),
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002573 /* TODO: can we use decmatch here? */
2574 sm_rp_ui := sm_tpdu
2575 );
2576
2577 /* Submit an SMS on DTAP and expect MO-forwardSM-Req on GSUP */
2578 f_mo_sms_submit(spars);
2579 alt {
2580 [] GSUP.receive(mo_forwardSM) -> value gsup_msg_rx {
Vadim Yanitskiya358dd42020-01-15 10:42:47 +07002581 log("RX MO-forwardSM-Req: ", gsup_msg_rx);
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002582 setverdict(pass);
2583 }
2584 [] GSUP.receive {
2585 log("RX unexpected GSUP message");
2586 setverdict(fail);
2587 mtc.stop;
2588 }
2589 }
2590
2591 /* Trigger RP-ACK by sending MO-forwardSM-Res */
2592 GSUP.send(valueof(ts_GSUP_MO_FORWARD_SM_RES(
2593 imsi := g_pars.imsi,
2594 sm_rp_mr := spars.rp.msg_ref)));
2595 /* Expect RP-ACK on DTAP */
2596 f_mo_sms_wait_rp_ack(spars);
2597
2598 f_expect_clear();
2599}
2600testcase TC_gsup_mo_sms() runs on MTC_CT {
2601 var BSC_ConnHdlr vc_conn;
2602 f_init();
2603 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2604 vc_conn := f_start_handler(refers(f_tc_gsup_mo_sms), 88);
2605 vc_conn.done;
2606 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2607}
2608
Harald Weltee13cfb22019-04-23 16:52:02 +02002609
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002610/* Test MO-SMMA from MS/BTS/BSC towards HLR (via GSUP) */
Harald Weltee13cfb22019-04-23 16:52:02 +02002611friend function f_tc_gsup_mo_smma(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002612runs on BSC_ConnHdlr {
2613 var SmsParameters spars := valueof(t_SmsPars);
2614 var GSUP_PDU gsup_msg_rx;
2615
2616 f_init_handler(pars);
2617
2618 /* We need to inspect GSUP activity */
2619 f_create_gsup_expect(hex2str(g_pars.imsi));
2620
2621 /* Perform location update */
2622 f_perform_lu();
2623
2624 /* Send CM Service Request for SMS */
2625 f_establish_fully(EST_TYPE_MO_SMS);
2626
2627 var template GSUP_PDU mo_ReadyForSM := tr_GSUP_MO_READY_FOR_SM_REQ(
2628 imsi := g_pars.imsi,
2629 sm_rp_mr := spars.rp.msg_ref,
2630 sm_alert_rsn := GSUP_SM_ALERT_RSN_TYPE_MEM_AVAIL
2631 );
2632
2633 /* Submit an SMS on DTAP and expect MO-forwardSM-Req on GSUP */
2634 f_mo_smma(spars);
2635 alt {
2636 [] GSUP.receive(mo_ReadyForSM) -> value gsup_msg_rx {
Vadim Yanitskiya358dd42020-01-15 10:42:47 +07002637 log("RX MO-ReadyForSM-Req: ", gsup_msg_rx);
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002638 setverdict(pass);
2639 }
2640 [] GSUP.receive {
2641 log("RX unexpected GSUP message");
2642 setverdict(fail);
2643 mtc.stop;
2644 }
2645 }
2646
2647 /* Trigger RP-ACK by sending MO-forwardSM-Res */
2648 GSUP.send(valueof(ts_GSUP_MO_READY_FOR_SM_RES(
2649 imsi := g_pars.imsi,
2650 sm_rp_mr := spars.rp.msg_ref)));
2651 /* Expect RP-ACK on DTAP */
2652 f_mo_sms_wait_rp_ack(spars);
2653
2654 f_expect_clear();
2655}
2656testcase TC_gsup_mo_smma() runs on MTC_CT {
2657 var BSC_ConnHdlr vc_conn;
2658 f_init();
2659 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2660 vc_conn := f_start_handler(refers(f_tc_gsup_mo_smma), 89);
2661 vc_conn.done;
2662 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2663}
2664
Harald Weltee13cfb22019-04-23 16:52:02 +02002665
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002666/* Helper for sending MT SMS over GSUP */
2667private function f_gsup_forwardSM_req(SmsParameters spars, OCT1 mms := '00'O)
2668runs on BSC_ConnHdlr {
Vadim Yanitskiya52347c2019-12-12 17:32:33 +09002669 var GSUP_SM_RP_Addr msisdn := valueof(t_GSUP_SM_RP_Addr(g_pars.msisdn));
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09002670 var GSUP_SM_RP_Addr smsc := valueof(t_GSUP_SM_RP_Addr(
2671 number := spars.rp.smsc_addr.rP_NumberDigits,
2672 npi := spars.rp.smsc_addr.rP_NumberingPlanIdentification,
2673 ton := spars.rp.smsc_addr.rP_TypeOfNumber,
2674 ext := spars.rp.smsc_addr.rP_Ext));
Vadim Yanitskiya52347c2019-12-12 17:32:33 +09002675
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002676 GSUP.send(ts_GSUP_MT_FORWARD_SM_REQ(
2677 imsi := g_pars.imsi,
2678 /* NOTE: MSC should assign RP-MR itself */
2679 sm_rp_mr := 'FF'O,
Vadim Yanitskiya52347c2019-12-12 17:32:33 +09002680 sm_rp_da := valueof(ts_GSUP_SM_RP_DA_MSISDN(msisdn)),
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09002681 sm_rp_oa := valueof(ts_GSUP_SM_RP_OA_SMSC_ADDR(smsc)),
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002682 /* Encoded SMS TPDU (taken from Wireshark)
2683 * FIXME: we should encode spars somehow */
2684 sm_rp_ui := '00068021436500008111328130858200'O,
2685 sm_rp_mms := mms
2686 ));
2687}
2688
2689/* Test successful MT-SMS (RP-ACK) over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002690friend function f_tc_gsup_mt_sms_ack(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002691runs on BSC_ConnHdlr {
2692 var SmsParameters spars := valueof(t_SmsPars);
2693
2694 f_init_handler(pars);
2695
2696 /* We need to inspect GSUP activity */
2697 f_create_gsup_expect(hex2str(g_pars.imsi));
2698
2699 /* Perform location update */
2700 f_perform_lu();
2701
2702 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002703 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002704
2705 var template GSUP_PDU mt_forwardSM_res := tr_GSUP_MT_FORWARD_SM_RES(
2706 imsi := g_pars.imsi,
2707 /* NOTE: MSC should assign RP-MR itself */
2708 sm_rp_mr := ?
2709 );
2710
2711 /* Submit a MT SMS on GSUP */
2712 f_gsup_forwardSM_req(spars);
2713
2714 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002715 f_expect_paging();
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002716 f_establish_fully(EST_TYPE_PAG_RESP);
2717
2718 /* Wait for MT SMS on DTAP */
2719 f_mt_sms_expect(spars);
2720
2721 /* Send RP-ACK and expect MT-forwardSM-Res on GSUP */
2722 f_mt_sms_send_rp_ack(spars);
2723 alt {
2724 [] GSUP.receive(mt_forwardSM_res) {
2725 log("RX MT-forwardSM-Res (RP-ACK)");
2726 setverdict(pass);
2727 }
2728 [] GSUP.receive {
2729 log("RX unexpected GSUP message");
2730 setverdict(fail);
2731 mtc.stop;
2732 }
2733 }
2734
2735 f_expect_clear();
2736}
2737testcase TC_gsup_mt_sms_ack() runs on MTC_CT {
2738 var BSC_ConnHdlrPars pars;
2739 var BSC_ConnHdlr vc_conn;
2740 f_init();
2741 pars := f_init_pars(90);
2742 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2743 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_ack), pars);
2744 vc_conn.done;
2745 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2746}
2747
Harald Weltee13cfb22019-04-23 16:52:02 +02002748
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002749/* Test rejected MT-SMS (RP-ERROR) over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002750friend function f_tc_gsup_mt_sms_err(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002751runs on BSC_ConnHdlr {
2752 var SmsParameters spars := valueof(t_SmsPars);
2753 var OCT1 sm_rp_cause := '78'O; /* dummy RP-Cause value */
2754
2755 f_init_handler(pars);
2756
2757 /* We need to inspect GSUP activity */
2758 f_create_gsup_expect(hex2str(g_pars.imsi));
2759
2760 /* Perform location update */
2761 f_perform_lu();
2762
2763 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002764 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002765
2766 var template GSUP_PDU mt_forwardSM_err := tr_GSUP_MT_FORWARD_SM_ERR(
2767 imsi := g_pars.imsi,
2768 /* NOTE: MSC should assign RP-MR itself */
2769 sm_rp_mr := ?,
2770 sm_rp_cause := sm_rp_cause
2771 );
2772
2773 /* Submit a MT SMS on GSUP */
2774 f_gsup_forwardSM_req(spars);
2775
2776 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002777 f_expect_paging();
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002778 f_establish_fully(EST_TYPE_PAG_RESP);
2779
2780 /* Wait for MT SMS on DTAP */
2781 f_mt_sms_expect(spars);
2782
2783 /* Send RP-ERROR and expect MT-forwardSM-Err on GSUP */
2784 f_mt_sms_send_rp_error(spars, oct2int(sm_rp_cause));
2785 alt {
2786 [] GSUP.receive(mt_forwardSM_err) {
2787 log("RX MT-forwardSM-Err (RP-ERROR)");
2788 setverdict(pass);
2789 mtc.stop;
2790 }
2791 [] GSUP.receive {
2792 log("RX unexpected GSUP message");
2793 setverdict(fail);
2794 mtc.stop;
2795 }
2796 }
2797
2798 f_expect_clear();
2799}
2800testcase TC_gsup_mt_sms_err() runs on MTC_CT {
2801 var BSC_ConnHdlrPars pars;
2802 var BSC_ConnHdlr vc_conn;
2803 f_init();
2804 pars := f_init_pars(91);
2805 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2806 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_err), pars);
2807 vc_conn.done;
2808 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2809}
2810
Harald Weltee13cfb22019-04-23 16:52:02 +02002811
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002812/* Test SM-RP-MR assignment for MT-SMS over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002813friend function f_tc_gsup_mt_sms_rp_mr(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002814runs on BSC_ConnHdlr {
2815 var SmsParameters spars1 := valueof(t_SmsPars); /* 1st SMS */
2816 var SmsParameters spars2 := valueof(t_SmsPars); /* 2nd SMS */
2817
2818 f_init_handler(pars);
2819
2820 /* We need to inspect GSUP activity */
2821 f_create_gsup_expect(hex2str(g_pars.imsi));
2822
2823 /* Perform location update */
2824 f_perform_lu();
2825
2826 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002827 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002828
2829 /* Submit the 1st MT SMS on GSUP */
2830 log("TX MT-forwardSM-Req for the 1st SMS");
2831 f_gsup_forwardSM_req(spars1);
2832
2833 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002834 f_expect_paging();
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002835 f_establish_fully(EST_TYPE_PAG_RESP);
2836
2837 /* Wait for 1st MT SMS on DTAP */
2838 f_mt_sms_expect(spars1);
2839 log("RX the 1st SMS on DTAP, DTAP TID is ", spars1.tid,
2840 ", SM-RP-MR is ", spars1.rp.msg_ref);
2841
2842 /* Submit the 2nd MT SMS on GSUP */
2843 log("TX MT-forwardSM-Req for the 2nd SMS");
2844 f_gsup_forwardSM_req(spars2);
2845
2846 /* Wait for 2nd MT SMS on DTAP */
2847 f_mt_sms_expect(spars2);
2848 log("RX the 2nd SMS on DTAP, DTAP TID is ", spars2.tid,
2849 ", SM-RP-MR is ", spars2.rp.msg_ref);
2850
2851 /* Both transaction IDs shall be different */
2852 if (spars1.tid == spars2.tid) {
2853 log("Both DTAP transaction IDs shall be different");
2854 setverdict(fail);
2855 }
2856
2857 /* Both SM-RP-MR values shall be different */
2858 if (spars1.rp.msg_ref == spars2.rp.msg_ref) {
2859 log("Both SM-RP-MR values shall be different");
2860 setverdict(fail);
2861 }
2862
2863 /* Both SM-RP-MR values shall be assigned */
2864 if (spars1.rp.msg_ref == 'FF'O) {
2865 log("Unassigned SM-RP-MR value for the 1st SMS");
2866 setverdict(fail);
2867 }
2868 if (spars2.rp.msg_ref == 'FF'O) {
2869 log("Unassigned SM-RP-MR value for the 2nd SMS");
2870 setverdict(fail);
2871 }
2872
2873 /* Send the 1st RP-ACK and expect MT-forwardSM-Res on GSUP */
2874 f_mt_sms_send_rp_ack(spars1);
2875 alt {
2876 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2877 imsi := g_pars.imsi,
2878 sm_rp_mr := spars1.rp.msg_ref
2879 )) {
2880 log("RX MT-forwardSM-Res (RP-ACK)");
2881 setverdict(pass);
2882 }
2883 [] GSUP.receive {
2884 log("RX unexpected GSUP message");
2885 setverdict(fail);
2886 mtc.stop;
2887 }
2888 }
2889
2890 /* Send the 2nd RP-ACK and expect MT-forwardSM-Res on GSUP */
2891 f_mt_sms_send_rp_ack(spars2);
2892 alt {
2893 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2894 imsi := g_pars.imsi,
2895 sm_rp_mr := spars2.rp.msg_ref
2896 )) {
2897 log("RX MT-forwardSM-Res (RP-ACK)");
2898 setverdict(pass);
2899 }
2900 [] GSUP.receive {
2901 log("RX unexpected GSUP message");
2902 setverdict(fail);
2903 mtc.stop;
2904 }
2905 }
2906
2907 f_expect_clear();
2908}
2909testcase TC_gsup_mt_sms_rp_mr() runs on MTC_CT {
2910 var BSC_ConnHdlrPars pars;
2911 var BSC_ConnHdlr vc_conn;
2912 f_init();
2913 pars := f_init_pars(92);
2914 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2915 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_rp_mr), pars);
2916 vc_conn.done;
2917 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2918}
2919
Harald Weltee13cfb22019-04-23 16:52:02 +02002920
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07002921/* Test SM-RP-MR assignment for MT-SMS over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002922friend function f_tc_gsup_mo_mt_sms_rp_mr(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07002923runs on BSC_ConnHdlr {
2924 var SmsParameters spars_mo := valueof(t_SmsPars); /* MO SMMA */
2925 var SmsParameters spars_mt := valueof(t_SmsPars); /* MT SMS */
2926
2927 f_init_handler(pars);
2928
2929 /* We need to inspect GSUP activity */
2930 f_create_gsup_expect(hex2str(g_pars.imsi));
2931
2932 /* Perform location update */
2933 f_perform_lu();
2934
2935 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002936 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07002937
2938 /* Send CM Service Request for MO SMMA */
2939 f_establish_fully(EST_TYPE_MO_SMS);
2940
2941 /* Submit MO SMMA on DTAP */
2942 log("Submit MO SMMA on DTAP, SM-RP-MR is '00'O");
2943 spars_mo.rp.msg_ref := '00'O;
2944 f_mo_smma(spars_mo);
2945
2946 /* Expect MO-forwardSM-Req for MO SMMA on GSUP */
2947 alt {
2948 [] GSUP.receive(tr_GSUP_MO_READY_FOR_SM_REQ(
2949 imsi := g_pars.imsi,
2950 sm_rp_mr := spars_mo.rp.msg_ref,
2951 sm_alert_rsn := GSUP_SM_ALERT_RSN_TYPE_MEM_AVAIL
2952 )) {
2953 log("RX MO-ReadyForSM-Req, SM-RP-MR is '00'O");
2954 setverdict(pass);
2955 }
2956 [] GSUP.receive {
2957 log("RX unexpected GSUP message");
2958 setverdict(fail);
2959 mtc.stop;
2960 }
2961 }
2962
2963 /* Submit MT SMS on GSUP */
2964 log("TX MT-forwardSM-Req for the MT SMS");
2965 f_gsup_forwardSM_req(spars_mt);
2966
2967 /* Wait for MT SMS on DTAP */
2968 f_mt_sms_expect(spars_mt);
2969 log("RX MT SMS on DTAP, DTAP TID is ", spars_mt.tid,
2970 ", SM-RP-MR is ", spars_mt.rp.msg_ref);
2971
2972 /* Both SM-RP-MR values shall be different */
2973 if (spars_mo.rp.msg_ref == spars_mt.rp.msg_ref) {
2974 log("Both SM-RP-MR values shall be different");
2975 setverdict(fail);
2976 }
2977
2978 /* SM-RP-MR value for MT SMS shall be assigned */
2979 if (spars_mt.rp.msg_ref == 'FF'O) {
2980 log("Unassigned SM-RP-MR value for the MT SMS");
2981 setverdict(fail);
2982 }
2983
2984 /* Trigger RP-ACK for MO SMMA by sending MO-forwardSM-Res */
2985 GSUP.send(valueof(ts_GSUP_MO_READY_FOR_SM_RES(
2986 imsi := g_pars.imsi,
2987 sm_rp_mr := spars_mo.rp.msg_ref)));
2988 /* Expect RP-ACK for MO SMMA on DTAP */
2989 f_mo_sms_wait_rp_ack(spars_mo);
2990
2991 /* Send RP-ACK for MT SMS and expect MT-forwardSM-Res on GSUP */
2992 f_mt_sms_send_rp_ack(spars_mt);
2993 alt {
2994 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2995 imsi := g_pars.imsi,
2996 sm_rp_mr := spars_mt.rp.msg_ref
2997 )) {
2998 log("RX MT-forwardSM-Res (RP-ACK)");
2999 setverdict(pass);
3000 }
3001 [] GSUP.receive {
3002 log("RX unexpected GSUP message");
3003 setverdict(fail);
3004 mtc.stop;
3005 }
3006 }
3007
3008 f_expect_clear();
3009}
3010testcase TC_gsup_mo_mt_sms_rp_mr() runs on MTC_CT {
3011 var BSC_ConnHdlrPars pars;
3012 var BSC_ConnHdlr vc_conn;
3013 f_init();
3014 pars := f_init_pars(93);
3015 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
3016 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mo_mt_sms_rp_mr), pars);
3017 vc_conn.done;
3018 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
3019}
3020
Harald Weltee13cfb22019-04-23 16:52:02 +02003021
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07003022/* Test multi-part MT-SMS over GSUP */
3023private function f_tc_gsup_mt_multi_part_sms(charstring id, BSC_ConnHdlrPars pars)
3024runs on BSC_ConnHdlr {
3025 var SmsParameters spars := valueof(t_SmsPars);
3026
3027 f_init_handler(pars);
3028
3029 /* We need to inspect GSUP activity */
3030 f_create_gsup_expect(hex2str(g_pars.imsi));
3031
3032 /* Perform location update */
3033 f_perform_lu();
3034
3035 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01003036 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07003037
3038 var template GSUP_PDU mt_forwardSM_res := tr_GSUP_MT_FORWARD_SM_RES(
3039 imsi := g_pars.imsi,
3040 /* NOTE: MSC should assign RP-MR itself */
3041 sm_rp_mr := ?
3042 );
3043
3044 /* Send 4 messages (NOTE: SM-RP-UI remains unchanged) */
3045 for (var integer i := 3; i >= 0; i := i-1) {
3046 /* Submit a MT SMS on GSUP (MMS is decremented) */
3047 f_gsup_forwardSM_req(spars, int2oct(i, 1));
3048
3049 /* Expect Paging Request and Establish connection */
3050 if (i == 3) { /* ... only once! */
Harald Weltee13cfb22019-04-23 16:52:02 +02003051 f_expect_paging();
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07003052 f_establish_fully(EST_TYPE_PAG_RESP);
3053 }
3054
3055 /* Wait for MT SMS on DTAP */
3056 f_mt_sms_expect(spars);
3057
3058 /* Send RP-ACK and expect MT-forwardSM-Res on GSUP */
3059 f_mt_sms_send_rp_ack(spars);
3060 alt {
3061 [] GSUP.receive(mt_forwardSM_res) {
3062 log("RX MT-forwardSM-Res (RP-ACK)");
3063 setverdict(pass);
3064 }
3065 [] GSUP.receive {
3066 log("RX unexpected GSUP message");
3067 setverdict(fail);
3068 mtc.stop;
3069 }
3070 }
3071
3072 /* Keep some 'distance' between transmissions */
3073 f_sleep(1.5);
3074 }
3075
3076 f_expect_clear();
3077}
3078testcase TC_gsup_mt_multi_part_sms() runs on MTC_CT {
3079 var BSC_ConnHdlrPars pars;
3080 var BSC_ConnHdlr vc_conn;
3081 f_init();
3082 pars := f_init_pars(91);
3083 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
3084 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_multi_part_sms), pars);
3085 vc_conn.done;
3086 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
3087}
3088
Harald Weltef640a012018-04-14 17:49:21 +02003089/* convert GSM L3 TON to SMPP_TON enum */
3090function f_sm_ton_from_gsm(BIT3 ton) return SMPP_TON {
3091 select (ton) {
3092 case ('000'B) { return unknown; }
3093 case ('001'B) { return international; }
3094 case ('010'B) { return national; }
3095 case ('011'B) { return network_specific; }
3096 case ('100'B) { return subscriber_number; }
3097 case ('101'B) { return alphanumeric; }
3098 case ('110'B) { return abbreviated; }
3099 }
3100 setverdict(fail, "Unknown TON ", ton);
Daniel Willmannafce8662018-07-06 23:11:32 +02003101 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02003102}
3103/* convert GSM L3 NPI to SMPP_NPI enum */
3104function f_sm_npi_from_gsm(BIT4 npi) return SMPP_NPI {
3105 select (npi) {
3106 case ('0000'B) { return unknown; }
3107 case ('0001'B) { return isdn; }
3108 case ('0011'B) { return data; }
3109 case ('0100'B) { return telex; }
3110 case ('0110'B) { return land_mobile; }
3111 case ('1000'B) { return national; }
3112 case ('1001'B) { return private_; }
3113 case ('1010'B) { return ermes; }
3114 }
3115 setverdict(fail, "Unknown NPI ", npi);
Daniel Willmannafce8662018-07-06 23:11:32 +02003116 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02003117}
3118
3119/* build a SMPP_SM from SmsParameters */
3120function f_mt_sm_from_spars(SmsParameters spars)
3121runs on BSC_ConnHdlr return SMPP_SM {
3122 var SMPP_SM sm := {
3123 service_type := "CMT",
3124 source_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
3125 source_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
3126 source_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
3127 dest_addr_ton := international,
3128 dest_addr_npi := isdn,
3129 destination_addr := hex2str(g_pars.msisdn),
3130 esm_class := '00000001'B,
3131 protocol_id := 0,
3132 priority_flag := 0,
3133 schedule_delivery_time := "",
3134 validity_period := "",
3135 registered_delivery := '00000000'B,
3136 replace_if_present := 0,
3137 data_coding := '00000001'B,
3138 sm_default_msg_id := 0,
3139 sm_length := spars.tp.udl,
3140 short_message := spars.tp.ud,
3141 opt_pars := {}
3142 };
3143 return sm;
3144}
3145
3146/* helper function to encode SMS from 'spars', send it via SMPP to MSC; receive it on MS side */
3147private function f_smpp_mt_sms(SmsParameters spars, boolean trans_mode) runs on BSC_ConnHdlr {
3148 var SMPP_SM sm := f_mt_sm_from_spars(spars);
3149 if (trans_mode) {
3150 sm.esm_class := '00000010'B;
3151 }
3152
3153 /* actually cause MSC to send a SMS via SUBMIT-SM from SMPP side */
3154 SMPP.send(ts_SMPP_SUBMIT_SM(sm));
3155 if (not match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
3156 /* if we're not in SMPP transaction mode, we expect the SMPP-level ACK
3157 * before we expect the SMS delivery on the BSC/radio side */
3158 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
3159 }
3160
3161 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02003162 f_expect_paging();
Harald Weltef640a012018-04-14 17:49:21 +02003163 /* Establish DTAP / BSSAP / SCCP connection */
3164 f_establish_fully(EST_TYPE_PAG_RESP);
3165 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
3166
3167 f_mt_sms(spars);
3168
3169 if (match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
3170 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
3171 }
3172 f_expect_clear();
3173}
3174
3175/* mobile terminated SMS, from SMPP to BSC/BTS/MS */
3176private function f_tc_smpp_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3177 f_init_handler(pars);
3178
3179 /* Perform location update so IMSI is known + registered in MSC/VLR */
3180 f_perform_lu();
3181 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
3182
3183 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01003184 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Weltef640a012018-04-14 17:49:21 +02003185
3186 var SmsParameters spars := valueof(t_SmsPars);
3187 /* TODO: test with more intelligent user data; test different coding schemes */
3188 spars.tp.ud := '00'O;
3189 spars.tp.udl := 1;
3190
3191 /* first test the non-transaction store+forward mode */
3192 f_smpp_mt_sms(spars, false);
3193
3194 /* then test the transaction mode */
3195 f_smpp_mt_sms(spars, true);
3196}
3197testcase TC_smpp_mt_sms() runs on MTC_CT {
3198 var BSC_ConnHdlr vc_conn;
3199 f_init();
3200 vc_conn := f_start_handler(refers(f_tc_smpp_mt_sms), 45);
3201 vc_conn.done;
3202}
3203
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003204/***********************************************************************
3205 * USSD Testing
3206 ***********************************************************************/
3207
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003208private altstep as_unexp_gsup_or_bssap_msg()
3209runs on BSC_ConnHdlr {
3210 [] GSUP.receive {
3211 setverdict(fail, "Unknown/unexpected GSUP received");
3212 self.stop;
3213 }
3214 [] BSSAP.receive {
3215 setverdict(fail, "Unknown/unexpected BSSAP message received");
3216 self.stop;
3217 }
3218}
3219
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003220private function f_expect_gsup_msg(template GSUP_PDU msg,
3221 float T_val := 2.0)
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003222runs on BSC_ConnHdlr return GSUP_PDU {
3223 var GSUP_PDU gsup_msg_complete;
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003224 timer T := T_val;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003225
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003226 T.start;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003227 alt {
3228 [] GSUP.receive(msg) -> value gsup_msg_complete {
3229 setverdict(pass);
3230 }
3231 /* We don't expect anything else */
3232 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003233 [] T.timeout {
3234 setverdict(fail, "Timeout waiting for GSUP message: ", msg);
3235 }
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003236 }
3237
3238 return gsup_msg_complete;
3239}
3240
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003241private function f_expect_mt_dtap_msg(template PDU_ML3_NW_MS msg,
3242 float T_val := 2.0)
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003243runs on BSC_ConnHdlr return PDU_ML3_NW_MS {
3244 var PDU_DTAP_MT bssap_msg_complete;
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003245 timer T := T_val;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003246
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003247 T.start;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003248 alt {
3249 [] BSSAP.receive(tr_PDU_DTAP_MT(msg)) -> value bssap_msg_complete {
3250 setverdict(pass);
3251 }
3252 /* We don't expect anything else */
3253 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003254 [] T.timeout {
3255 setverdict(fail, "Timeout waiting for BSSAP message: ", msg);
3256 }
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003257 }
3258
3259 return bssap_msg_complete.dtap;
3260}
3261
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003262/* LU followed by MO USSD request */
Harald Weltee13cfb22019-04-23 16:52:02 +02003263friend function f_tc_lu_and_mo_ussd_single_request(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003264runs on BSC_ConnHdlr {
3265 f_init_handler(pars);
3266
3267 /* Perform location update */
3268 f_perform_lu();
3269
3270 /* Send CM Service Request for SS/USSD */
3271 f_establish_fully(EST_TYPE_SS_ACT);
3272
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003273 /* We need to inspect GSUP activity */
3274 f_create_gsup_expect(hex2str(g_pars.imsi));
3275
3276 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3277 invoke_id := 5, /* Phone may not start from 0 or 1 */
3278 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3279 ussd_string := "*#100#"
3280 );
3281
3282 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3283 invoke_id := 5, /* InvokeID shall be the same for both REQ and RSP */
3284 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3285 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
3286 )
3287
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003288 /* Compose a new SS/REGISTER message with request */
3289 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
3290 tid := 1, /* We just need a single transaction */
3291 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003292 facility := valueof(facility_req)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003293 );
3294
3295 /* Compose SS/RELEASE_COMPLETE template with expected response */
3296 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
3297 tid := 1, /* Response should arrive within the same transaction */
3298 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003299 facility := valueof(facility_rsp)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003300 );
3301
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003302 /* Compose expected MSC -> HLR message */
3303 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
3304 imsi := g_pars.imsi,
3305 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3306 ss := valueof(facility_req)
3307 );
3308
3309 /* To be used for sending response with correct session ID */
3310 var GSUP_PDU gsup_req_complete;
3311
3312 /* Request own number */
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003313 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003314 /* Expect GSUP message containing the SS payload */
3315 gsup_req_complete := f_expect_gsup_msg(gsup_req);
3316
3317 /* Compose the response from HLR using received session ID */
3318 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
3319 imsi := g_pars.imsi,
3320 sid := gsup_req_complete.ies[1].val.session_id,
3321 state := OSMO_GSUP_SESSION_STATE_END,
3322 ss := valueof(facility_rsp)
3323 );
3324
3325 /* Finally, HLR terminates the session */
3326 GSUP.send(gsup_rsp);
3327 /* Expect RELEASE_COMPLETE message with the response */
3328 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003329
3330 f_expect_clear();
3331}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003332testcase TC_lu_and_mo_ussd_single_request() runs on MTC_CT {
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003333 var BSC_ConnHdlr vc_conn;
3334 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003335 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_single_request), 46);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003336 vc_conn.done;
3337}
3338
Harald Weltee13cfb22019-04-23 16:52:02 +02003339
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003340/* LU followed by MT USSD notification */
Harald Weltee13cfb22019-04-23 16:52:02 +02003341friend function f_tc_lu_and_mt_ussd_notification(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003342runs on BSC_ConnHdlr {
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003343 timer T := 5.0;
3344
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003345 f_init_handler(pars);
3346
3347 /* Perform location update */
3348 f_perform_lu();
3349
Harald Welte6811d102019-04-14 22:23:14 +02003350 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003351
3352 /* We need to inspect GSUP activity */
3353 f_create_gsup_expect(hex2str(g_pars.imsi));
3354
3355 /* Facility IE with network-originated USSD notification */
3356 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3357 op_code := SS_OP_CODE_USS_NOTIFY,
3358 ussd_string := "Mahlzeit!"
3359 );
3360
3361 /* Facility IE with acknowledgment to the USSD notification */
3362 var template OCTN facility_rsp := enc_SS_FacilityInformation(
3363 /* In case of USSD notification, Return Result is empty */
3364 valueof(ts_SS_USSD_FACILITY_RETURN_RESULT_EMPTY())
3365 );
3366
3367 /* Compose a new MT SS/REGISTER message with USSD notification */
3368 var template PDU_ML3_NW_MS ussd_ntf := tr_ML3_MT_SS_REGISTER(
3369 tid := 0, /* FIXME: most likely, it should be 0 */
3370 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3371 facility := valueof(facility_req)
3372 );
3373
3374 /* Compose HLR -> MSC GSUP message */
3375 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3376 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003377 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003378 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3379 ss := valueof(facility_req)
3380 );
3381
3382 /* Send it to MSC and expect Paging Request */
3383 GSUP.send(gsup_req);
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003384 T.start;
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003385 alt {
Harald Weltee13cfb22019-04-23 16:52:02 +02003386 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
3387 setverdict(pass);
3388 }
Harald Welte62113fc2019-05-09 13:04:02 +02003389 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003390 setverdict(pass);
3391 }
3392 /* We don't expect anything else */
3393 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003394 [] T.timeout {
3395 setverdict(fail, "Timeout waiting for Paging Request");
3396 }
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003397 }
3398
3399 /* Send Paging Response and expect USSD notification */
3400 f_establish_fully(EST_TYPE_PAG_RESP);
3401 /* Expect MT REGISTER message with USSD notification */
3402 f_expect_mt_dtap_msg(ussd_ntf);
3403
3404 /* Compose a new MO SS/FACILITY message with empty response */
3405 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
3406 tid := 0, /* FIXME: it shall match the request tid */
3407 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3408 facility := valueof(facility_rsp)
3409 );
3410
3411 /* Compose expected MSC -> HLR GSUP message */
3412 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
3413 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003414 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003415 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3416 ss := valueof(facility_rsp)
3417 );
3418
3419 /* MS sends response to the notification */
3420 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
3421 /* Expect GSUP message containing the SS payload */
3422 f_expect_gsup_msg(gsup_rsp);
3423
3424 /* Compose expected MT SS/RELEASE COMPLETE message */
3425 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
3426 tid := 0, /* FIXME: it shall match the request tid */
3427 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3428 facility := omit
3429 );
3430
3431 /* Compose MSC -> HLR GSUP message */
3432 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
3433 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003434 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003435 state := OSMO_GSUP_SESSION_STATE_END
3436 );
3437
3438 /* Finally, HLR terminates the session */
3439 GSUP.send(gsup_term)
3440 /* Expect MT RELEASE COMPLETE without Facility IE */
3441 f_expect_mt_dtap_msg(ussd_term);
3442
3443 f_expect_clear();
3444}
3445testcase TC_lu_and_mt_ussd_notification() runs on MTC_CT {
3446 var BSC_ConnHdlr vc_conn;
3447 f_init();
3448 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_notification), 47);
3449 vc_conn.done;
3450}
3451
Harald Weltee13cfb22019-04-23 16:52:02 +02003452
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003453/* LU followed by MT call and MO USSD request during this call */
Harald Weltee13cfb22019-04-23 16:52:02 +02003454friend function f_tc_lu_and_mo_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003455runs on BSC_ConnHdlr {
3456 f_init_handler(pars);
3457
3458 /* Call parameters taken from f_tc_lu_and_mt_call */
3459 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003460
3461 /* Perform location update */
3462 f_perform_lu();
3463
3464 /* Establish a MT call */
3465 f_mt_call_establish(cpars);
3466
3467 /* Hold the call for some time */
3468 f_sleep(1.0);
3469
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003470 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3471 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3472 ussd_string := "*#100#"
3473 );
3474
3475 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3476 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3477 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
3478 )
3479
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003480 /* Compose a new SS/REGISTER message with request */
3481 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
3482 tid := 1, /* We just need a single transaction */
3483 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003484 facility := valueof(facility_req)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003485 );
3486
3487 /* Compose SS/RELEASE_COMPLETE template with expected response */
3488 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
3489 tid := 1, /* Response should arrive within the same transaction */
3490 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003491 facility := valueof(facility_rsp)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003492 );
3493
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003494 /* Compose expected MSC -> HLR message */
3495 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
3496 imsi := g_pars.imsi,
3497 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3498 ss := valueof(facility_req)
3499 );
3500
3501 /* To be used for sending response with correct session ID */
3502 var GSUP_PDU gsup_req_complete;
3503
3504 /* Request own number */
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003505 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003506 /* Expect GSUP message containing the SS payload */
3507 gsup_req_complete := f_expect_gsup_msg(gsup_req);
3508
3509 /* Compose the response from HLR using received session ID */
3510 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
3511 imsi := g_pars.imsi,
3512 sid := gsup_req_complete.ies[1].val.session_id,
3513 state := OSMO_GSUP_SESSION_STATE_END,
3514 ss := valueof(facility_rsp)
3515 );
3516
3517 /* Finally, HLR terminates the session */
3518 GSUP.send(gsup_rsp);
3519 /* Expect RELEASE_COMPLETE message with the response */
3520 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003521
3522 /* Hold the call for some time */
3523 f_sleep(1.0);
3524
3525 /* Release the call (does Clear Complete itself) */
3526 f_call_hangup(cpars, true);
3527}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003528testcase TC_lu_and_mo_ussd_during_mt_call() runs on MTC_CT {
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003529 var BSC_ConnHdlr vc_conn;
3530 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003531 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_during_mt_call), 48);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003532 vc_conn.done;
3533}
3534
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003535/* BSSMAP Clear Request in the middle of a call, see OS#3062 */
Harald Weltee13cfb22019-04-23 16:52:02 +02003536friend function f_tc_mo_cc_bssmap_clear(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003537 f_init_handler(pars);
3538 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02003539 cpars.ran_clear_when_alerting := true;
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003540
3541 f_perform_lu();
3542
Neels Hofmeyrde76f052019-02-26 05:02:46 +01003543 var default ccrel := activate(as_optional_cc_rel(cpars));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02003544 f_mo_call_establish(cpars);
3545 f_expect_clear()
Neels Hofmeyrde76f052019-02-26 05:02:46 +01003546 deactivate(ccrel);
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003547
3548 f_sleep(1.0);
3549}
3550testcase TC_mo_cc_bssmap_clear() runs on MTC_CT {
3551 var BSC_ConnHdlr vc_conn;
3552 f_init();
3553
3554 vc_conn := f_start_handler(refers(f_tc_mo_cc_bssmap_clear), 43);
3555 vc_conn.done;
3556}
3557
Harald Weltee13cfb22019-04-23 16:52:02 +02003558
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003559/* LU followed by MT call and MT USSD request during this call */
Harald Weltee13cfb22019-04-23 16:52:02 +02003560friend function f_tc_lu_and_mt_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003561runs on BSC_ConnHdlr {
3562 f_init_handler(pars);
3563
3564 /* Call parameters taken from f_tc_lu_and_mt_call */
3565 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003566
3567 /* Perform location update */
3568 f_perform_lu();
3569
3570 /* Establish a MT call */
3571 f_mt_call_establish(cpars);
3572
3573 /* Hold the call for some time */
3574 f_sleep(1.0);
3575
3576 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3577 op_code := SS_OP_CODE_USS_REQUEST,
3578 ussd_string := "Please type anything..."
3579 );
3580
3581 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3582 op_code := SS_OP_CODE_USS_REQUEST,
3583 ussd_string := "Nope."
3584 )
3585
3586 /* Compose MT SS/REGISTER message with network-originated request */
3587 var template (value) PDU_ML3_NW_MS ussd_req := ts_ML3_MT_SS_REGISTER(
3588 tid := 0, /* FIXME: most likely, it should be 0 */
3589 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3590 facility := valueof(facility_req)
3591 );
3592
3593 /* Compose HLR -> MSC GSUP message */
3594 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3595 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003596 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003597 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3598 ss := valueof(facility_req)
3599 );
3600
3601 /* Send it to MSC */
3602 GSUP.send(gsup_req);
3603 /* Expect MT REGISTER message with USSD request */
3604 f_expect_mt_dtap_msg(ussd_req);
3605
3606 /* Compose a new MO SS/FACILITY message with response */
3607 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
3608 tid := 0, /* FIXME: it shall match the request tid */
3609 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3610 facility := valueof(facility_rsp)
3611 );
3612
3613 /* Compose expected MSC -> HLR GSUP message */
3614 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
3615 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003616 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003617 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3618 ss := valueof(facility_rsp)
3619 );
3620
3621 /* MS sends response */
3622 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
3623 f_expect_gsup_msg(gsup_rsp);
3624
3625 /* Compose expected MT SS/RELEASE COMPLETE message */
3626 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
3627 tid := 0, /* FIXME: it shall match the request tid */
3628 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3629 facility := omit
3630 );
3631
3632 /* Compose MSC -> HLR GSUP message */
3633 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
3634 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003635 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003636 state := OSMO_GSUP_SESSION_STATE_END
3637 );
3638
3639 /* Finally, HLR terminates the session */
3640 GSUP.send(gsup_term);
3641 /* Expect MT RELEASE COMPLETE without Facility IE */
3642 f_expect_mt_dtap_msg(ussd_term);
3643
3644 /* Hold the call for some time */
3645 f_sleep(1.0);
3646
3647 /* Release the call (does Clear Complete itself) */
3648 f_call_hangup(cpars, true);
3649}
3650testcase TC_lu_and_mt_ussd_during_mt_call() runs on MTC_CT {
3651 var BSC_ConnHdlr vc_conn;
3652 f_init();
3653 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_during_mt_call), 49);
3654 vc_conn.done;
3655}
3656
Harald Weltee13cfb22019-04-23 16:52:02 +02003657
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07003658/* LU followed by MO USSD request and MO Release during transaction */
Harald Weltee13cfb22019-04-23 16:52:02 +02003659friend function f_tc_lu_and_mo_ussd_mo_release(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07003660runs on BSC_ConnHdlr {
3661 f_init_handler(pars);
3662
3663 /* Perform location update */
3664 f_perform_lu();
3665
3666 /* Send CM Service Request for SS/USSD */
3667 f_establish_fully(EST_TYPE_SS_ACT);
3668
3669 /* We need to inspect GSUP activity */
3670 f_create_gsup_expect(hex2str(g_pars.imsi));
3671
3672 var template OCTN facility_ms_req := f_USSD_FACILITY_IE_INVOKE(
3673 invoke_id := 1, /* Initial request */
3674 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3675 ussd_string := "*6766*266#"
3676 );
3677
3678 var template OCTN facility_net_req := f_USSD_FACILITY_IE_INVOKE(
3679 invoke_id := 2, /* Counter request */
3680 op_code := SS_OP_CODE_USS_REQUEST,
3681 ussd_string := "Password?!?"
3682 )
3683
3684 /* Compose MO SS/REGISTER message with request */
3685 var template (value) PDU_ML3_MS_NW ussd_ms_req := ts_ML3_MO_SS_REGISTER(
3686 tid := 1, /* We just need a single transaction */
3687 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3688 facility := valueof(facility_ms_req)
3689 );
3690
3691 /* Compose expected MSC -> HLR message */
3692 var template GSUP_PDU gsup_ms_req := tr_GSUP_PROC_SS_REQ(
3693 imsi := g_pars.imsi,
3694 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3695 ss := valueof(facility_ms_req)
3696 );
3697
3698 /* To be used for sending response with correct session ID */
3699 var GSUP_PDU gsup_ms_req_complete;
3700
3701 /* Initiate a new transaction */
3702 BSSAP.send(ts_PDU_DTAP_MO(ussd_ms_req));
3703 /* Expect GSUP request with original Facility IE */
3704 gsup_ms_req_complete := f_expect_gsup_msg(gsup_ms_req);
3705
3706 /* Compose the response from HLR using received session ID */
3707 var template (value) GSUP_PDU gsup_net_req := ts_GSUP_PROC_SS_REQ(
3708 imsi := g_pars.imsi,
3709 sid := gsup_ms_req_complete.ies[1].val.session_id,
3710 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3711 ss := valueof(facility_net_req)
3712 );
3713
3714 /* Compose expected MT SS/FACILITY template with counter request */
3715 var template PDU_ML3_NW_MS ussd_net_req := tr_ML3_MT_SS_FACILITY(
3716 tid := 1, /* Response should arrive within the same transaction */
3717 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3718 facility := valueof(facility_net_req)
3719 );
3720
3721 /* Send response over GSUP */
3722 GSUP.send(gsup_net_req);
3723 /* Expect MT SS/FACILITY message with counter request */
3724 f_expect_mt_dtap_msg(ussd_net_req);
3725
3726 /* Compose MO SS/RELEASE COMPLETE */
3727 var template (value) PDU_ML3_MS_NW ussd_abort := ts_ML3_MO_SS_RELEASE_COMPLETE(
3728 tid := 1, /* Response should arrive within the same transaction */
3729 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3730 facility := omit
3731 /* TODO: cause? */
3732 );
3733
3734 /* Compose expected HLR -> MSC abort message */
3735 var template GSUP_PDU gsup_abort := tr_GSUP_PROC_SS_REQ(
3736 imsi := g_pars.imsi,
3737 sid := gsup_ms_req_complete.ies[1].val.session_id,
3738 state := OSMO_GSUP_SESSION_STATE_END
3739 );
3740
3741 /* Abort transaction */
3742 BSSAP.send(ts_PDU_DTAP_MO(ussd_abort));
3743 /* Expect GSUP message indicating abort */
3744 f_expect_gsup_msg(gsup_abort);
3745
3746 f_expect_clear();
3747}
3748testcase TC_lu_and_mo_ussd_mo_release() runs on MTC_CT {
3749 var BSC_ConnHdlr vc_conn;
3750 f_init();
3751 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_mo_release), 50);
3752 vc_conn.done;
3753}
3754
Harald Weltee13cfb22019-04-23 16:52:02 +02003755
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003756/* LU followed by MO USSD request and MT Release due to timeout */
Harald Weltee13cfb22019-04-23 16:52:02 +02003757friend function f_tc_lu_and_ss_session_timeout(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003758runs on BSC_ConnHdlr {
3759 f_init_handler(pars);
3760
3761 /* Perform location update */
3762 f_perform_lu();
3763
3764 /* Send CM Service Request for SS/USSD */
3765 f_establish_fully(EST_TYPE_SS_ACT);
3766
3767 /* We need to inspect GSUP activity */
3768 f_create_gsup_expect(hex2str(g_pars.imsi));
3769
3770 var template OCTN facility_ms_req := f_USSD_FACILITY_IE_INVOKE(
3771 invoke_id := 1,
3772 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3773 ussd_string := "#release_me");
3774
3775 /* Compose MO SS/REGISTER message with request */
3776 var template (value) PDU_ML3_MS_NW ussd_ms_req := ts_ML3_MO_SS_REGISTER(
3777 tid := 1, /* An arbitrary transaction identifier */
3778 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3779 facility := valueof(facility_ms_req));
3780
3781 /* Compose expected MSC -> HLR message */
3782 var template GSUP_PDU gsup_ms_req := tr_GSUP_PROC_SS_REQ(
3783 imsi := g_pars.imsi,
3784 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3785 ss := valueof(facility_ms_req));
3786
3787 /* To be used for sending response with correct session ID */
3788 var GSUP_PDU gsup_ms_req_complete;
3789
3790 /* Initiate a new SS transaction */
3791 BSSAP.send(ts_PDU_DTAP_MO(ussd_ms_req));
3792 /* Expect GSUP request with original Facility IE */
3793 gsup_ms_req_complete := f_expect_gsup_msg(gsup_ms_req);
3794
3795 /* Don't respond, wait for timeout */
3796 f_sleep(3.0);
3797
3798 var template PDU_ML3_NW_MS dtap_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
3799 tid := 1, /* Should match the request's tid */
3800 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3801 cause := *, /* TODO: expect some specific value */
3802 facility := omit);
3803
3804 var template GSUP_PDU gsup_rel := tr_GSUP_PROC_SS_ERR(
3805 imsi := g_pars.imsi,
3806 sid := gsup_ms_req_complete.ies[1].val.session_id,
3807 state := OSMO_GSUP_SESSION_STATE_END,
3808 cause := ?); /* TODO: expect some specific value */
3809
3810 /* Expect release on both interfaces */
3811 interleave {
3812 [] BSSAP.receive(tr_PDU_DTAP_MT(dtap_rel)) { };
3813 [] GSUP.receive(gsup_rel) { };
3814 }
3815
3816 f_expect_clear();
3817 setverdict(pass);
3818}
3819testcase TC_lu_and_ss_session_timeout() runs on MTC_CT {
3820 var BSC_ConnHdlr vc_conn;
3821 f_init();
Vadim Yanitskiy36d28dd2018-12-03 02:45:45 +07003822 f_vty_config(MSCVTY, "msc", "ncss guard-timeout 3");
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003823 vc_conn := f_start_handler(refers(f_tc_lu_and_ss_session_timeout), 51);
3824 vc_conn.done;
Vadim Yanitskiy36d28dd2018-12-03 02:45:45 +07003825 f_vty_config(MSCVTY, "msc", "ncss guard-timeout 0");
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003826}
3827
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07003828/* MT (network-originated) USSD for unknown subscriber */
3829friend function f_tc_mt_ussd_for_unknown_subscr(charstring id, BSC_ConnHdlrPars pars)
3830runs on BSC_ConnHdlr {
3831 var hexstring imsi := '000000000000000'H; /* Some unknown IMSI */
3832 var OCT4 sid := '20000222'O;
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07003833
3834 f_init_handler(pars);
3835 f_ran_register_imsi(imsi, 'FFFFFFFF'O);
3836 f_create_gsup_expect(hex2str(imsi));
3837
3838 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3839 imsi := imsi,
3840 sid := sid,
3841 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3842 ss := f_rnd_octstring(23)
3843 );
3844
3845 /* Error with cause GMM_CAUSE_IMSI_UNKNOWN */
3846 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
3847 imsi := imsi,
3848 sid := sid,
3849 state := OSMO_GSUP_SESSION_STATE_END,
3850 cause := 2 /* FIXME: introduce an enumerated type! */
3851 );
3852
3853 /* Initiate a MT USSD notification */
3854 GSUP.send(gsup_req);
3855
3856 /* Expect GSUP PROC_SS_ERROR message */
Vadim Yanitskiy851798c2019-06-15 14:22:28 +07003857 f_expect_gsup_msg(gsup_rsp);
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07003858}
3859testcase TC_mt_ussd_for_unknown_subscr() runs on MTC_CT {
3860 var BSC_ConnHdlr vc_conn;
3861 f_init();
3862 vc_conn := f_start_handler(refers(f_tc_mt_ussd_for_unknown_subscr), 0);
3863 vc_conn.done;
3864}
3865
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07003866/* MO (mobile-originated) SS/USSD for unknown transaction */
3867friend function f_tc_mo_ussd_for_unknown_trans(charstring id, BSC_ConnHdlrPars pars)
3868runs on BSC_ConnHdlr {
3869 f_init_handler(pars);
3870
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01003871 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07003872 f_create_gsup_expect(hex2str(g_pars.imsi));
3873
3874 /* Perform location update */
3875 f_perform_lu();
3876
3877 /* Send CM Service Request for SS/USSD */
3878 f_establish_fully(EST_TYPE_SS_ACT);
3879
3880 /* GSM 04.80 FACILITY message for a non-existing transaction */
3881 var template (value) PDU_ML3_MS_NW mo_ss_fac := ts_ML3_MO_SS_FACILITY(
3882 tid := 1, /* An arbitrary transaction identifier */
3883 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3884 facility := f_rnd_octstring(23) /* We don't care about the Facility IE */
3885 );
3886
3887 /* GSM 04.80 RELEASE COMPLETE message for a non-existing transaction */
3888 var template (value) PDU_ML3_MS_NW mo_ss_rel := ts_ML3_MO_SS_RELEASE_COMPLETE(
3889 tid := 1, /* An arbitrary transaction identifier */
3890 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3891 facility := f_rnd_octstring(23) /* We don't care about the Facility IE */
3892 );
3893
3894 /* Expected response from the network */
3895 var template PDU_ML3_NW_MS mt_ss_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
3896 tid := 1, /* Same as in the FACILITY message */
3897 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3898 facility := omit
3899 );
3900
3901 /* Send GSM 04.80 FACILITY for non-existing transaction */
3902 BSSAP.send(ts_PDU_DTAP_MO(mo_ss_fac));
3903
3904 /* Expect GSM 04.80 RELEASE COMPLETE message */
3905 f_expect_mt_dtap_msg(mt_ss_rel);
3906 f_expect_clear();
3907
3908 /* Send another CM Service Request for SS/USSD */
3909 f_establish_fully(EST_TYPE_SS_ACT);
3910
3911 /* Send GSM 04.80 RELEASE COMPLETE for non-existing transaction */
3912 BSSAP.send(ts_PDU_DTAP_MO(mo_ss_rel));
3913
3914 /* Expect GSM 04.80 RELEASE COMPLETE message */
3915 f_expect_mt_dtap_msg(mt_ss_rel);
3916 f_expect_clear();
3917}
3918testcase TC_mo_ussd_for_unknown_trans() runs on MTC_CT {
3919 var BSC_ConnHdlr vc_conn;
3920 f_init();
3921 vc_conn := f_start_handler(refers(f_tc_mo_ussd_for_unknown_trans), 111);
3922 vc_conn.done;
3923}
3924
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07003925/* MT (network-originated) USSD for unknown session */
3926friend function f_tc_proc_ss_for_unknown_session(charstring id, BSC_ConnHdlrPars pars)
3927runs on BSC_ConnHdlr {
3928 var OCT4 sid := '20000333'O;
3929
3930 f_init_handler(pars);
3931
3932 /* Perform location update */
3933 f_perform_lu();
3934
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01003935 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07003936 f_create_gsup_expect(hex2str(g_pars.imsi));
3937
3938 /* Request referencing a non-existing SS session */
3939 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3940 imsi := g_pars.imsi,
3941 sid := sid,
3942 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3943 ss := f_rnd_octstring(23)
3944 );
3945
3946 /* Error with some cause value */
3947 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
3948 imsi := g_pars.imsi,
3949 sid := sid,
3950 state := OSMO_GSUP_SESSION_STATE_END,
3951 cause := ? /* FIXME: introduce an enumerated type! */
3952 );
3953
3954 /* Initiate a MT USSD notification */
3955 GSUP.send(gsup_req);
3956
3957 /* Expect GSUP PROC_SS_ERROR message */
3958 f_expect_gsup_msg(gsup_rsp);
3959}
3960testcase TC_proc_ss_for_unknown_session() runs on MTC_CT {
3961 var BSC_ConnHdlr vc_conn;
3962 f_init();
3963 vc_conn := f_start_handler(refers(f_tc_proc_ss_for_unknown_session), 110);
3964 vc_conn.done;
3965}
3966
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003967/* MT (network-originated) USSD and no response to Paging Request */
3968friend function f_tc_proc_ss_paging_fail(charstring id, BSC_ConnHdlrPars pars)
3969runs on BSC_ConnHdlr {
3970 timer TP := 2.0; /* Paging timer */
3971
3972 f_init_handler(pars);
3973
3974 /* Perform location update */
3975 f_perform_lu();
3976
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01003977 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003978 f_create_gsup_expect(hex2str(g_pars.imsi));
3979
3980 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3981 imsi := g_pars.imsi,
3982 sid := '20000444'O,
3983 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3984 ss := f_rnd_octstring(23)
3985 );
3986
3987 /* Error with some cause value */
3988 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
3989 imsi := g_pars.imsi,
3990 sid := '20000444'O,
3991 state := OSMO_GSUP_SESSION_STATE_END,
3992 cause := ? /* FIXME: introduce an enumerated type! */
3993 );
3994
3995 /* Initiate a MT USSD notification */
3996 GSUP.send(gsup_req);
3997
3998 /* Send it to MSC and expect Paging Request */
3999 TP.start;
4000 alt {
4001 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
4002 setverdict(pass);
4003 }
4004 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
4005 setverdict(pass);
4006 }
4007 /* We don't expect anything else */
4008 [] as_unexp_gsup_or_bssap_msg();
4009 [] TP.timeout {
4010 setverdict(fail, "Timeout waiting for Paging Request");
4011 }
4012 }
4013
Vadim Yanitskiyd24b5252019-10-02 00:04:51 +07004014 /* Wait up to 20 seconds for GSUP PROC_SS_ERROR message.
4015 * OsmoMSC waits for Paging Response 10 seconds by default. */
4016 f_expect_gsup_msg(gsup_rsp, T_val := 20.0);
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07004017}
4018testcase TC_proc_ss_paging_fail() runs on MTC_CT {
4019 var BSC_ConnHdlr vc_conn;
4020 f_init();
4021 vc_conn := f_start_handler(refers(f_tc_proc_ss_paging_fail), 101);
4022 vc_conn.done;
4023}
4024
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07004025/* MT (network-originated) USSD followed by immediate abort */
4026friend function f_tc_proc_ss_abort(charstring id, BSC_ConnHdlrPars pars)
4027runs on BSC_ConnHdlr {
4028 var octetstring facility := f_rnd_octstring(23);
4029 var OCT4 sid := '20000555'O;
4030 timer TP := 2.0;
4031
4032 f_init_handler(pars);
4033
4034 /* Perform location update */
4035 f_perform_lu();
4036
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01004037 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07004038 f_create_gsup_expect(hex2str(g_pars.imsi));
4039
4040 /* PROC_SS_REQ initiates a mobile-originated SS/USSD session */
4041 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
4042 imsi := g_pars.imsi, sid := sid,
4043 state := OSMO_GSUP_SESSION_STATE_BEGIN,
4044 ss := facility
4045 );
4046
4047 /* On the MS side, we expect GSM 04.80 REGISTER message */
4048 var template PDU_ML3_NW_MS dtap_reg := tr_ML3_MT_SS_REGISTER(
4049 tid := 0, /* Most likely, it should be 0 */
4050 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
4051 facility := facility
4052 );
4053
4054 /* PROC_SS_ERR with SESSION_STATE_END terminates the SS/USSD session */
4055 var template (value) GSUP_PDU gsup_abort := ts_GSUP_PROC_SS_ERR(
4056 imsi := g_pars.imsi, sid := sid,
4057 state := OSMO_GSUP_SESSION_STATE_END,
4058 cause := 0 /* FIXME: introduce an enumerated type! */
4059 );
4060
4061 /* On the MS side, we expect GSM 04.80 REGISTER message */
4062 var template PDU_ML3_NW_MS dtap_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
4063 tid := 0, /* Most likely, it should be 0 */
4064 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
4065 cause := *, /* FIXME: expect some specific cause value */
4066 facility := omit
4067 );
4068
4069 /* Initiate a MT USSD with random payload */
4070 GSUP.send(gsup_req);
4071
4072 /* Expect Paging Request */
4073 TP.start;
4074 alt {
4075 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
4076 setverdict(pass);
4077 }
4078 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
4079 setverdict(pass);
4080 }
4081 /* We don't expect anything else */
4082 [] as_unexp_gsup_or_bssap_msg();
4083 [] TP.timeout {
4084 setverdict(fail, "Timeout waiting for Paging Request");
4085 }
4086 }
4087
4088 /* Send Paging Response and establish connection */
4089 f_establish_fully(EST_TYPE_PAG_RESP);
4090 /* Expect MT REGISTER message with random facility */
4091 f_expect_mt_dtap_msg(dtap_reg);
4092
4093 /* HLR/EUSE decides to abort the session even
4094 * before getting any response from the MS */
4095 /* Initiate a MT USSD with random payload */
4096 GSUP.send(gsup_abort);
4097
4098 /* Expect RELEASE COMPLETE on ths MS side */
4099 f_expect_mt_dtap_msg(dtap_rel);
4100
4101 f_expect_clear();
4102}
4103testcase TC_proc_ss_abort() runs on MTC_CT {
4104 var BSC_ConnHdlr vc_conn;
4105 f_init();
4106 vc_conn := f_start_handler(refers(f_tc_proc_ss_abort), 102);
4107 vc_conn.done;
4108}
4109
Harald Weltee13cfb22019-04-23 16:52:02 +02004110
Vadim Yanitskiy1c9754d2020-01-07 21:56:55 +01004111/* Verify multiple concurrent MO SS/USSD transactions
4112 * (one subscriber - one transaction) */
4113testcase TC_multi_lu_and_mo_ussd() runs on MTC_CT {
4114 var BSC_ConnHdlr vc_conn[16];
4115 var integer i;
4116
4117 f_init();
4118
4119 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
4120 vc_conn[i] := f_start_handler(refers(f_tc_lu_and_mo_ussd_single_request), 210 + i);
4121 }
4122
4123 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
4124 vc_conn[i].done;
4125 }
4126}
4127
4128/* Verify multiple concurrent MT SS/USSD transactions
4129 * (one subscriber - one transaction) */
4130testcase TC_multi_lu_and_mt_ussd() runs on MTC_CT {
4131 var BSC_ConnHdlr vc_conn[16];
4132 var integer i;
4133 var OCT4 sid;
4134
4135 f_init();
4136
4137 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
4138 sid := '200001'O & int2oct(i, 1); /* All transactions must use different session ID */
4139 vc_conn[i] := f_start_handler_with_pars(refers(f_tc_lu_and_mt_ussd_notification),
4140 f_init_pars(226 + i, gsup_sid := sid));
4141 }
4142
4143 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
4144 vc_conn[i].done;
4145 }
4146}
4147
4148
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004149/* A5/1 only permitted on network side; attempt an invalid CIPHER MODE COMPLETE with A5/3 which MSC should reject. */
4150private function f_tc_cipher_complete_with_invalid_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4151 pars.net.expect_auth := true;
4152 pars.net.expect_ciph := true;
4153 pars.net.kc_support := '02'O; /* A5/1 only */
4154 f_init_handler(pars);
4155
4156 g_pars.vec := f_gen_auth_vec_2g();
4157
4158 /* Can't use f_perform_lu() directly. Code below is based on it. */
4159
4160 /* tell GSUP dispatcher to send this IMSI to us */
4161 f_create_gsup_expect(hex2str(g_pars.imsi));
4162
4163 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
4164 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
Harald Weltedceacc72019-04-21 20:58:35 +02004165 f_cl3_or_initial_ue(l3_lu);
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004166
4167 f_mm_auth();
4168
4169 var OCT1 a5_net := f_alg_mask_from_cm(g_pars.cm2);
4170 var OCT1 a5_intersect := g_pars.net.kc_support and4b a5_net;
4171 alt {
4172 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(a5_intersect, g_pars.vec.kc)) {
4173 BSSAP.send(ts_BSSMAP_CipherModeCompl(int2oct(4 /* "accept" A5/3 */, 1)));
4174 }
4175 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?, g_pars.vec.kc)) {
4176 setverdict(fail, "Wrong ciphering algorithm mask in CiphModCmd");
4177 mtc.stop;
4178 }
4179 [] BSSAP.receive {
4180 setverdict(fail, "Unknown/unexpected BSSAP received");
4181 mtc.stop;
4182 }
4183 }
Harald Welte79f1e452020-08-18 22:55:02 +02004184 f_expect_common_id();
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004185
4186 /* Expect LU reject from MSC. */
4187 alt {
4188 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
4189 setverdict(pass);
4190 }
4191 [] BSSAP.receive {
4192 setverdict(fail, "Unknown/unexpected BSSAP received");
4193 mtc.stop;
4194 }
4195 }
Stefan Sperlingc620b352018-12-18 17:23:36 +01004196 f_expect_clear();
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004197}
4198
4199testcase TC_cipher_complete_with_invalid_cipher() runs on MTC_CT {
4200 var BSC_ConnHdlr vc_conn;
4201 f_init();
4202 f_vty_config(MSCVTY, "network", "encryption a5 1");
4203
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02004204 vc_conn := f_start_handler(refers(f_tc_cipher_complete_with_invalid_cipher), 52, verify_cell_id := false);
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004205 vc_conn.done;
4206}
4207
Harald Welteb2284bd2019-05-10 11:30:43 +02004208/* Location Update with invalid (non-matching) MCC/MNC reported on BSSMAP level from BSC */
4209friend function f_tc_lu_with_invalid_mcc_mnc(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4210 f_init_handler(pars);
4211
4212 /* tell GSUP dispatcher to send this IMSI to us */
4213 f_create_gsup_expect(hex2str(g_pars.imsi));
4214
4215 /* modify the cell ID which will be used to construct the COMPLELTE L3 or InitialUE */
4216 g_pars.cell_id := valueof(ts_CellId_CGI('333'H, '22'H, 23, 42));
4217
4218 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
4219 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
4220 f_cl3_or_initial_ue(l3_lu);
Harald Welte79f1e452020-08-18 22:55:02 +02004221 f_expect_common_id();
Harald Welteb2284bd2019-05-10 11:30:43 +02004222
4223 /* Expect LU reject from MSC. */
4224 alt {
4225 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
4226 setverdict(pass);
4227 }
4228 [] BSSAP.receive {
4229 setverdict(fail, "Unknown/unexpected BSSAP received");
4230 mtc.stop;
4231 }
4232 }
4233 f_expect_clear();
4234}
4235testcase TC_lu_with_invalid_mcc_mnc() runs on MTC_CT {
4236 var BSC_ConnHdlr vc_conn;
4237 f_init();
4238 vc_conn := f_start_handler(refers(f_tc_lu_with_invalid_mcc_mnc), 54);
4239 vc_conn.done;
4240}
4241
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01004242private function f_tc_cipher_complete_without_alg(charstring id, BSC_ConnHdlrPars pars, octetstring kc_support) runs on BSC_ConnHdlr {
4243 pars.net.expect_auth := true;
4244 pars.net.expect_ciph := true;
4245 pars.net.kc_support := kc_support;
4246 f_init_handler(pars);
4247
4248 g_pars.vec := f_gen_auth_vec_2g();
4249
4250 /* Can't use f_perform_lu() directly. Code below is based on it. */
4251
4252 /* tell GSUP dispatcher to send this IMSI to us */
4253 f_create_gsup_expect(hex2str(g_pars.imsi));
4254
4255 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
4256 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
4257 f_cl3_or_initial_ue(l3_lu);
4258
4259 f_mm_auth();
4260
4261 var OCT1 a5_net := f_alg_mask_from_cm(g_pars.cm2);
4262 var OCT1 a5_intersect := g_pars.net.kc_support and4b a5_net;
4263 alt {
4264 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(a5_intersect, g_pars.vec.kc)) {
4265 BSSAP.send(ts_BSSMAP_CipherModeComplAlg(omit));
4266 }
4267 [] BSSAP.receive(tr_BSSMAP_ClassmarkReq) {
4268 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
4269 repeat;
4270 }
4271 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?, g_pars.vec.kc)) {
4272 setverdict(fail, "Wrong ciphering algorithm mask in CiphModCmd");
4273 mtc.stop;
4274 }
4275 [] BSSAP.receive {
4276 setverdict(fail, "Unknown/unexpected BSSAP received");
4277 mtc.stop;
4278 }
4279 }
Harald Welte79f1e452020-08-18 22:55:02 +02004280 f_expect_common_id();
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01004281
4282 /* TODO: Verify MSC is using the best cipher available! How? */
4283
4284 f_msc_lu_hlr();
4285 f_accept_reject_lu();
4286 f_expect_clear();
4287 setverdict(pass);
4288}
4289
4290/* A5/1 only permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
4291private function f_tc_cipher_complete_1_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4292 f_tc_cipher_complete_without_alg(id, pars, '02'O /* A5/1 only */);
4293}
4294
4295/* A5/3 only permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
4296private function f_tc_cipher_complete_3_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4297 f_tc_cipher_complete_without_alg(id, pars, '08'O /* A5/3 only */);
4298}
4299
4300/* A5/1 + A5/3 permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
4301private function f_tc_cipher_complete_13_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4302 f_tc_cipher_complete_without_alg(id, pars, '0A'O /* A5/1 and A5/3 enabled */);
4303}
4304
4305testcase TC_cipher_complete_1_without_cipher() runs on MTC_CT {
4306 var BSC_ConnHdlr vc_conn;
4307 f_init();
4308 f_vty_config(MSCVTY, "network", "encryption a5 1");
4309
4310 vc_conn := f_start_handler(refers(f_tc_cipher_complete_1_without_cipher), 53);
4311 vc_conn.done;
4312}
4313
4314testcase TC_cipher_complete_3_without_cipher() runs on MTC_CT {
4315 var BSC_ConnHdlr vc_conn;
4316 f_init();
4317 f_vty_config(MSCVTY, "network", "encryption a5 3");
4318
4319 vc_conn := f_start_handler(refers(f_tc_cipher_complete_3_without_cipher), 54);
4320 vc_conn.done;
4321}
4322
4323testcase TC_cipher_complete_13_without_cipher() runs on MTC_CT {
4324 var BSC_ConnHdlr vc_conn;
4325 f_init();
4326 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
4327
4328 vc_conn := f_start_handler(refers(f_tc_cipher_complete_13_without_cipher), 55);
4329 vc_conn.done;
4330}
Harald Welteb2284bd2019-05-10 11:30:43 +02004331
Harald Weltef640a012018-04-14 17:49:21 +02004332/* TODO (SMS):
4333 * different user data lengths
4334 * SMPP transaction mode with unsuccessful delivery
4335 * queued MT-SMS with no paging response + later delivery
4336 * different data coding schemes
4337 * multi-part SMS
4338 * user-data headers
4339 * TP-PID for SMS to SIM
4340 * behavior if SMS memory is full + RP-SMMA
4341 * delivery reports
4342 * SMPP osmocom extensions
4343 * more-messages-to-send
4344 * SMS during ongoing call (SACCH/SAPI3)
4345 */
4346
4347/* TODO (General):
Harald Welteba7b6d92018-01-23 21:32:34 +01004348 * continue to send repeated MO signalling messages to keep channel open: does MSC tmeout?
4349 * malformed messages (missing IE, invalid message type): properly rejected?
4350 * MT call while LU or is ongoing: Do we use existing lchan or page while lchan active?
4351 * 3G/2G auth permutations
4352 * encryption algorithms vs. classmark vs. vty config
Harald Welteba7b6d92018-01-23 21:32:34 +01004353 * send new transaction after/during clear (like SMS, ...)
Harald Welte45164da2018-01-24 12:51:27 +01004354 * too long L3 INFO in DTAP
4355 * too long / padded BSSAP
4356 * too long / short TLV values
Harald Welteba7b6d92018-01-23 21:32:34 +01004357 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01004358
Harald Weltee13cfb22019-04-23 16:52:02 +02004359/***********************************************************************
4360 * SGsAP Testing
4361 ***********************************************************************/
4362
Philipp Maier948747b2019-04-02 15:22:33 +02004363/* Check if a subscriber exists in the VLR */
4364private function f_ctrl_subscr_in_vlr(charstring imsi_or_msisdn) runs on BSC_ConnHdlr return boolean {
4365
4366 var CtrlValue active_subsribers;
4367 var integer rc;
4368 active_subsribers := f_ctrl_get(IPA_CTRL, "subscriber-list-active-v1");
4369
4370 rc := f_strstr(active_subsribers, imsi_or_msisdn);
4371 if (rc < 0) {
4372 return false;
4373 }
4374
4375 return true;
4376}
4377
Harald Welte4263c522018-12-06 11:56:27 +01004378/* Perform a location updatye at the A-Interface and run some checks to confirm
4379 * that everything is back to normal. */
4380private function f_sgsap_bssmap_screening() runs on BSC_ConnHdlr {
4381 var SmsParameters spars := valueof(t_SmsPars);
4382
4383 /* Perform a location update, the SGs association is expected to fall
4384 * back to NULL */
4385 f_perform_lu();
4386 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4387
4388 /* Trigger a paging request and expect the paging on BSSMAP, this is
4389 * to make sure that pagings are sent throught the A-Interface again
4390 * and not throught the SGs interface.*/
Harald Welte6811d102019-04-14 22:23:14 +02004391 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Welte4263c522018-12-06 11:56:27 +01004392 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4393
4394 alt {
Harald Weltee13cfb22019-04-23 16:52:02 +02004395 [g_pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)); {
4396 setverdict(pass);
4397 }
Harald Welte62113fc2019-05-09 13:04:02 +02004398 [not g_pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
Harald Welte4263c522018-12-06 11:56:27 +01004399 setverdict(pass);
4400 }
4401 [] SGsAP.receive {
4402 setverdict(fail, "Received unexpected message on SGs");
4403 }
4404 }
4405
4406 /* Send an SMS to make sure that also payload messages are routed
4407 * throught the A-Interface again */
4408 f_establish_fully(EST_TYPE_MO_SMS);
4409 f_mo_sms(spars);
4410 f_expect_clear();
4411}
4412
4413private function f_tc_sgsap_reset(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4414 var charstring vlr_name;
4415 f_init_handler(pars);
4416
4417 vlr_name := f_sgsap_reset_mme(mp_mme_name);
4418 log("VLR name: ", vlr_name);
4419 setverdict(pass);
Neels Hofmeyrc0b520d2019-03-06 15:35:50 +01004420 f_sleep(1.0);
Harald Welte4263c522018-12-06 11:56:27 +01004421}
4422
4423testcase TC_sgsap_reset() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004424 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004425 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004426 f_init(1, true);
4427 pars := f_init_pars(11810, true);
4428 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_reset), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004429 vc_conn.done;
4430}
4431
4432/* like f_mm_auth() but for SGs */
4433function f_mm_auth_sgs() runs on BSC_ConnHdlr {
4434 if (g_pars.net.expect_auth) {
4435 g_pars.vec := f_gen_auth_vec_3g();
4436 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G3G(g_pars.vec.rand,
4437 g_pars.vec.sres,
4438 g_pars.vec.kc,
4439 g_pars.vec.ik,
4440 g_pars.vec.ck,
4441 g_pars.vec.autn,
4442 g_pars.vec.res));
4443 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
4444 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
4445 SGsAP.receive(tr_ML3_MT_MM_AUTH_REQ_3G(g_pars.vec.rand, g_pars.vec.autn));
4446 SGsAP.send(ts_ML3_MT_MM_AUTH_RESP_3G(g_pars.vec.sres, g_pars.vec.res));
4447 }
4448}
4449
4450/* like f_perform_lu(), but on SGs rather than BSSAP */
4451function f_sgs_perform_lu() runs on BSC_ConnHdlr {
4452 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4453 var PDU_SGsAP lur;
4454 var PDU_SGsAP lua;
4455 var PDU_SGsAP mm_info;
4456 var octetstring mm_info_dtap;
4457
4458 /* tell GSUP dispatcher to send this IMSI to us */
4459 f_create_gsup_expect(hex2str(g_pars.imsi));
4460
4461 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
4462 ts_SGsAP_LAI('901'H, '70'H, 2342)));
4463 /* Old LAI, if MS sends it */
4464 /* TMSI status, if MS has no valid TMSI */
4465 /* IMEISV, if it supports "automatic device detection" */
4466 /* TAI, if available in MME */
4467 /* E-CGI, if available in MME */
4468 SGsAP.send(lur);
4469
4470 /* FIXME: is this really done over SGs? The Ue is already authenticated
4471 * via the MME ... */
4472 f_mm_auth_sgs();
4473
4474 /* Expect MSC to perform LU with HLR */
4475 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4476 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
4477 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
4478 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
4479
4480 alt {
4481 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) -> value lua {
4482 if (isvalue(lua.sGsAP_LOCATION_UPDATE_ACCEPT.newTMSIorIMSI.iD.iD.tmsi_ptmsi.octets)) {
4483 g_pars.tmsi :=lua.sGsAP_LOCATION_UPDATE_ACCEPT.newTMSIorIMSI.iD.iD.tmsi_ptmsi.octets
4484 SGsAP.send(ts_SGsAP_TMSI_REALL_CMPL(g_pars.imsi));
4485 }
4486 setverdict(pass);
4487 }
4488 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4489 setverdict(fail, "Received LU-REJECT instead of ACCEPT");
4490 }
4491 [] SGsAP.receive {
4492 setverdict(fail, "Received unexpected message on SGs");
4493 }
4494 }
4495
4496 /* Check MM information */
4497 if (mp_mm_info == true) {
4498 SGsAP.receive(tr_SGsAP_MM_INFO_REQ(g_pars.imsi, ?)) -> value mm_info;
4499 mm_info_dtap := '0532'O & mm_info.sGsAP_MM_INFORMATION_REQUEST.mM_Information.information;
4500 if (not match(dec_PDU_ML3_NW_MS(mm_info_dtap), tr_ML3_MT_MM_Info)) {
4501 setverdict(fail, "Unexpected MM Information");
4502 }
4503 }
4504
4505 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4506}
4507
4508private function f_tc_sgsap_lu(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4509 f_init_handler(pars);
4510 f_sgs_perform_lu();
4511 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4512
4513 f_sgsap_bssmap_screening();
4514
4515 setverdict(pass);
4516}
4517testcase TC_sgsap_lu() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004518 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004519 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004520 f_init(1, true);
4521 pars := f_init_pars(11811, true);
4522 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004523 vc_conn.done;
4524}
4525
4526/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
4527private function f_tc_sgsap_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4528 f_init_handler(pars);
4529 var PDU_SGsAP lur;
4530
4531 f_create_gsup_expect(hex2str(g_pars.imsi));
4532 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4533 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
4534 ts_SGsAP_LAI('901'H, '70'H, 2342)));
4535 SGsAP.send(lur);
4536
4537 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4538 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
4539 alt {
4540 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4541 setverdict(pass);
4542 }
4543 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) {
4544 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
4545 mtc.stop;
4546 }
4547 [] SGsAP.receive {
4548 setverdict(fail, "Received unexpected message on SGs");
4549 }
4550 }
4551
4552 f_sgsap_bssmap_screening();
4553
4554 setverdict(pass);
4555}
4556testcase TC_sgsap_lu_imsi_reject() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004557 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004558 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004559 f_init(1, true);
4560 pars := f_init_pars(11812, true);
Harald Welte4263c522018-12-06 11:56:27 +01004561
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004562 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_imsi_reject), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004563 vc_conn.done;
4564}
4565
4566/* Do LU by IMSI, but then remain silent so that Ts6-1 times out */
4567private function f_tc_sgsap_lu_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4568 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4569 var PDU_SGsAP lur;
4570
4571 f_init_handler(pars);
4572
4573 /* tell GSUP dispatcher to send this IMSI to us */
4574 f_create_gsup_expect(hex2str(g_pars.imsi));
4575
4576 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
4577 ts_SGsAP_LAI('901'H, '70'H, 2342)));
4578 /* Old LAI, if MS sends it */
4579 /* TMSI status, if MS has no valid TMSI */
4580 /* IMEISV, if it supports "automatic device detection" */
4581 /* TAI, if available in MME */
4582 /* E-CGI, if available in MME */
4583 SGsAP.send(lur);
4584
4585 /* FIXME: is this really done over SGs? The Ue is already authenticated
4586 * via the MME ... */
4587 f_mm_auth_sgs();
4588
4589 /* Expect MSC to perform LU with HLR */
4590 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4591 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
4592 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
4593 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
4594
4595 alt {
4596 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) {
4597 setverdict(pass);
4598 }
4599 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4600 setverdict(fail, "Received LU-REJECT instead of ACCEPT");
4601 }
4602 [] SGsAP.receive {
4603 setverdict(fail, "Received unexpected message on SGs");
4604 }
4605 }
4606
4607 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4608
4609 /* Wait until the VLR has abort the TMSI reallocation procedure */
4610 f_sleep(45.0);
4611
4612 /* The outcome does not change the SGs state, see also 5.2.3.4 */
4613 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4614
4615 f_sgsap_bssmap_screening();
4616
4617 setverdict(pass);
4618}
4619testcase TC_sgsap_lu_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004620 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004621 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004622 f_init(1, true);
4623 pars := f_init_pars(11813, true);
Harald Welte4263c522018-12-06 11:56:27 +01004624
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004625 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004626 vc_conn.done;
4627}
4628
4629private function f_tc_sgsap_expl_imsi_det_eps(charstring id, BSC_ConnHdlrPars pars)
4630runs on BSC_ConnHdlr {
4631 f_init_handler(pars);
4632 f_sgs_perform_lu();
4633 f_sleep(3.0);
4634
4635 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4636 SGsAP.send(ts_SGsAP_EPS_DETACH_IND(g_pars.imsi, mme_name, UE_initiated));
4637 SGsAP.receive(tr_SGsAP_EPS_DETACH_ACK(g_pars.imsi));
4638 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4639
4640 f_sgsap_bssmap_screening();
4641
4642 setverdict(pass);
4643}
4644testcase TC_sgsap_expl_imsi_det_eps() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004645 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004646 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004647 f_init(1, true);
4648 pars := f_init_pars(11814, true);
4649 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_expl_imsi_det_eps), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004650 vc_conn.done;
4651}
4652
Philipp Maierfc19f172019-03-21 11:17:54 +01004653private function f_tc_sgsap_impl_imsi_det_eps(charstring id, BSC_ConnHdlrPars pars)
4654runs on BSC_ConnHdlr {
4655 f_init_handler(pars);
4656 f_sgs_perform_lu();
4657 f_sleep(3.0);
4658
4659 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4660 SGsAP.send(ts_SGsAP_EPS_DETACH_IND(g_pars.imsi, mme_name, network_initiated));
4661 SGsAP.receive(tr_SGsAP_EPS_DETACH_ACK(g_pars.imsi));
4662 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4663
4664 f_sgsap_bssmap_screening();
4665
4666 setverdict(pass);
4667}
4668testcase TC_sgsap_impl_imsi_det_eps() runs on MTC_CT {
4669 var BSC_ConnHdlrPars pars;
4670 var BSC_ConnHdlr vc_conn;
4671 f_init(1, true);
4672 pars := f_init_pars(11814, true);
4673 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_impl_imsi_det_eps), pars);
4674 vc_conn.done;
4675}
4676
Harald Welte4263c522018-12-06 11:56:27 +01004677private function f_tc_sgsap_expl_imsi_det_noneps(charstring id, BSC_ConnHdlrPars pars)
4678runs on BSC_ConnHdlr {
4679 f_init_handler(pars);
4680 f_sgs_perform_lu();
4681 f_sleep(3.0);
4682
4683 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4684 SGsAP.send(ts_SGsAP_IMSI_DETACH_IND(g_pars.imsi, mme_name, combined_UE_initiated));
4685 SGsAP.receive(tr_SGsAP_IMSI_DETACH_ACK(g_pars.imsi));
Philipp Maierd08e7e72019-04-02 15:27:10 +02004686
4687 if (f_ctrl_subscr_in_vlr(hex2str(g_pars.imsi))) {
4688 setverdict(fail, "subscriber not removed from VLR");
4689 }
Harald Welte4263c522018-12-06 11:56:27 +01004690
4691 f_sgsap_bssmap_screening();
4692
4693 setverdict(pass);
4694}
4695testcase TC_sgsap_expl_imsi_det_noneps() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004696 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004697 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004698 f_init(1, true);
4699 pars := f_init_pars(11815, true);
4700 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_expl_imsi_det_noneps), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004701 vc_conn.done;
4702}
4703
Philipp Maier5d812702019-03-21 10:51:26 +01004704private function f_tc_sgsap_impl_imsi_det_noneps(charstring id, BSC_ConnHdlrPars pars)
4705runs on BSC_ConnHdlr {
4706 f_init_handler(pars);
4707 f_sgs_perform_lu();
4708 f_sleep(3.0);
4709
4710 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4711 SGsAP.send(ts_SGsAP_IMSI_DETACH_IND(g_pars.imsi, mme_name, implicit_network_initiated));
4712 SGsAP.receive(tr_SGsAP_IMSI_DETACH_ACK(g_pars.imsi));
4713
4714 if (f_ctrl_subscr_in_vlr(hex2str(g_pars.imsi))) {
4715 setverdict(fail, "subscriber not removed from VLR");
4716 }
4717
4718 f_sgsap_bssmap_screening();
4719
4720 setverdict(pass);
4721}
4722testcase TC_sgsap_impl_imsi_det_noneps() runs on MTC_CT {
4723 var BSC_ConnHdlrPars pars;
4724 var BSC_ConnHdlr vc_conn;
4725 f_init(1, true);
4726 pars := f_init_pars(11815, true);
4727 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_impl_imsi_det_noneps), pars);
4728 vc_conn.done;
4729}
4730
Harald Welte4263c522018-12-06 11:56:27 +01004731/* Trigger a paging request via VTY and send a paging reject in response */
4732private function f_tc_sgsap_paging_rej(charstring id, BSC_ConnHdlrPars pars)
4733runs on BSC_ConnHdlr {
4734 f_init_handler(pars);
4735 f_sgs_perform_lu();
4736 f_sleep(1.0);
4737
4738 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4739 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4740 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4741 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4742
4743 /* Initiate paging via VTY */
4744 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4745 alt {
4746 [] SGsAP.receive(exp_resp) {
4747 setverdict(pass);
4748 }
4749 [] SGsAP.receive {
4750 setverdict(fail, "Received unexpected message on SGs");
4751 }
4752 }
4753
4754 /* Now reject the paging */
4755 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, IMSI_unknown));
4756
4757 /* Wait for the states inside the MSC to settle and check the state
4758 * of the SGs Association */
4759 f_sleep(1.0);
4760 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4761
4762 /* FIXME: At the moment we send an IMSI_unknown as cause code, which is fine,
4763 * but we also need to cover tha case where the cause code indicates an
4764 * "IMSI detached for EPS services". In those cases the VLR is expected to
4765 * try paging on tha A/Iu interface. This will be another testcase similar to
4766 * this one, but extended with checks for the presence of the A/Iu paging
4767 * messages. */
4768
4769 f_sgsap_bssmap_screening();
4770
4771 setverdict(pass);
4772}
4773testcase TC_sgsap_paging_rej() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004774 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004775 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004776 f_init(1, true);
4777 pars := f_init_pars(11816, true);
4778 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_rej), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004779 vc_conn.done;
4780}
4781
4782/* Trigger a paging request via VTY and send a paging reject that indicates
4783 * that the subscriber intentionally rejected the call. */
4784private function f_tc_sgsap_paging_subscr_rej(charstring id, BSC_ConnHdlrPars pars)
4785runs on BSC_ConnHdlr {
4786 f_init_handler(pars);
4787 f_sgs_perform_lu();
4788 f_sleep(1.0);
4789
4790 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4791 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4792 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4793 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4794
4795 /* Initiate paging via VTY */
4796 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4797 alt {
4798 [] SGsAP.receive(exp_resp) {
4799 setverdict(pass);
4800 }
4801 [] SGsAP.receive {
4802 setverdict(fail, "Received unexpected message on SGs");
4803 }
4804 }
4805
4806 /* Now reject the paging */
4807 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, user_rejected_mobile_terminating_CS_fallback_call));
4808
4809 /* Wait for the states inside the MSC to settle and check the state
4810 * of the SGs Association */
4811 f_sleep(1.0);
4812 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4813
4814 /* FIXME: The VLR is supposed to trigger an User Determined User Busy (UDUB) as specified
4815 * in 3GPP TS 24.082, this is not yet implemented in the MSC or in this tests, we need
4816 * to check back how this works and how it can be tested */
4817
4818 f_sgsap_bssmap_screening();
4819
4820 setverdict(pass);
4821}
4822testcase TC_sgsap_paging_subscr_rej() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004823 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004824 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004825 f_init(1, true);
4826 pars := f_init_pars(11817, true);
4827 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_subscr_rej), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004828 vc_conn.done;
4829}
4830
4831/* Trigger a paging request via VTY and send an UE unreacable messge in response */
4832private function f_tc_sgsap_paging_ue_unr(charstring id, BSC_ConnHdlrPars pars)
4833runs on BSC_ConnHdlr {
4834 f_init_handler(pars);
4835 f_sgs_perform_lu();
4836 f_sleep(1.0);
4837
4838 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4839 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4840 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4841 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4842
4843 /* Initiate paging via VTY */
4844 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4845 alt {
4846 [] SGsAP.receive(exp_resp) {
4847 setverdict(pass);
4848 }
4849 [] SGsAP.receive {
4850 setverdict(fail, "Received unexpected message on SGs");
4851 }
4852 }
4853
4854 /* Now pretend that the UE is unreachable */
4855 SGsAP.send(ts_SGsAP_UE_UNREACHABLE(g_pars.imsi, UE_unreachable));
4856
4857 /* Wait for the states inside the MSC to settle and check the state
4858 * of the SGs Association. */
4859 f_sleep(1.0);
4860 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4861
4862 f_sgsap_bssmap_screening();
4863
4864 setverdict(pass);
4865}
4866testcase TC_sgsap_paging_ue_unr() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004867 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004868 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004869 f_init(1, true);
4870 pars := f_init_pars(11818, true);
4871 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_ue_unr), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004872 vc_conn.done;
4873}
4874
4875/* Trigger a paging request via VTY but don't respond to it */
4876private function f_tc_sgsap_paging_and_nothing(charstring id, BSC_ConnHdlrPars pars)
4877runs on BSC_ConnHdlr {
4878 f_init_handler(pars);
4879 f_sgs_perform_lu();
4880 f_sleep(1.0);
4881
4882 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4883 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
Philipp Maier34218102019-09-24 09:15:49 +02004884 var template PDU_SGsAP exp_serv_abrt := ts_SGsAP_SERVICE_ABORT_REQ(g_pars.imsi);
Harald Welte4263c522018-12-06 11:56:27 +01004885 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4886 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4887
4888 /* Initiate paging via VTY */
4889 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4890 alt {
4891 [] SGsAP.receive(exp_resp) {
4892 setverdict(pass);
4893 }
4894 [] SGsAP.receive {
4895 setverdict(fail, "Received unexpected message on SGs");
4896 }
4897 }
4898
Philipp Maier34218102019-09-24 09:15:49 +02004899 /* While we are doing nothing, expect an SGsAP-SERVICE-ABORT-REQUEST
4900 * after some time */
4901 timer T := 10.0;
4902 T.start
4903 alt {
4904 [] SGsAP.receive(exp_serv_abrt)
4905 {
4906 setverdict(pass);
4907 }
4908 [] SGsAP.receive {
4909 setverdict(fail, "unexpected SGsAP message received");
4910 self.stop;
4911 }
4912 [] T.timeout {
4913 setverdict(fail, "MSC did not send SGsAP-SERVICE-ABORT-REQUEST");
4914 self.stop;
4915 }
4916 }
4917
4918 /* The SGs association must remain unchanged. */
Harald Welte4263c522018-12-06 11:56:27 +01004919 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4920
4921 f_sgsap_bssmap_screening();
4922
4923 setverdict(pass);
4924}
4925testcase TC_sgsap_paging_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004926 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004927 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004928 f_init(1, true);
4929 pars := f_init_pars(11819, true);
4930 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004931 vc_conn.done;
4932}
4933
4934/* Trigger a paging request via VTY and slip in an LU */
4935private function f_tc_sgsap_paging_and_lu(charstring id, BSC_ConnHdlrPars pars)
4936runs on BSC_ConnHdlr {
4937 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4938 f_init_handler(pars);
4939
4940 /* First we prepar the situation, where the SGs association is in state
4941 * NULL and the confirmed by radio contact indicator is set to false
4942 * as well. This can be archived by performing an SGs LU and then
4943 * resetting the VLR */
4944 f_sgs_perform_lu();
4945 f_sgsap_reset_mme(mp_mme_name);
4946 f_sleep(1.0);
4947 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4948
4949 /* Perform a paging, expect the paging messages on the SGs interface */
4950 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4951 alt {
4952 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
4953 setverdict(pass);
4954 }
4955 [] SGsAP.receive {
4956 setverdict(fail, "Received unexpected message on SGs");
4957 }
4958 }
4959
4960 /* Perform the LU as normal */
4961 f_sgs_perform_lu();
4962 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4963
4964 /* Expect a new paging request right after the LU */
4965 alt {
4966 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
4967 setverdict(pass);
4968 }
4969 [] SGsAP.receive {
4970 setverdict(fail, "Received unexpected message on SGs");
4971 }
4972 }
4973
4974 /* Test is done now, lets round everything up by rejecting the paging
4975 * cleanly. */
4976 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, user_rejected_mobile_terminating_CS_fallback_call));
4977 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4978
4979 f_sgsap_bssmap_screening();
4980
4981 setverdict(pass);
4982}
4983testcase TC_sgsap_paging_and_lu() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004984 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004985 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004986 f_init(1, true);
4987 pars := f_init_pars(11820, true);
4988 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_and_lu), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004989 vc_conn.done;
4990}
4991
4992/* Send unexpected unit-data through the SGs interface */
4993private function f_tc_sgsap_unexp_ud(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4994 f_init_handler(pars);
4995 f_sleep(1.0);
4996
4997 /* This simulates what happens when a subscriber without SGs
4998 * association gets unitdata via the SGs interface. */
4999
5000 /* Make sure the subscriber exists and the SGs association
5001 * is in NULL state */
5002 f_perform_lu();
5003 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
5004
5005 /* Send some random unit data, the MSC/VLR should send a release
5006 * immediately. */
5007 SGsAP.send(ts_SGsAP_UL_UD(pars.imsi,'1234'O));
5008 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, IMSI_detached_for_EPS_nonEPS_services));
5009
5010 f_sgsap_bssmap_screening();
5011
5012 setverdict(pass);
5013}
5014testcase TC_sgsap_unexp_ud() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005015 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005016 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005017 f_init(1, true);
5018 pars := f_init_pars(11821, true);
5019 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_unexp_ud), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005020 vc_conn.done;
5021}
5022
5023/* Send unsolicited unit-data through the SGs interface */
5024private function f_tc_sgsap_unsol_ud(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5025 f_init_handler(pars);
5026 f_sleep(1.0);
5027
5028 /* This simulates what happens when the MME attempts to send unitdata
5029 * to a subscriber that is completely unknown to the VLR */
5030
5031 /* Send some random unit data, the MSC/VLR should send a release
5032 * immediately. */
5033 SGsAP.send(ts_SGsAP_UL_UD(pars.imsi,'1234'O));
5034 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, IMSI_unknown));
5035
5036 f_sgsap_bssmap_screening();
5037
Harald Welte4d15fa72020-08-19 08:58:28 +02005038 /* clean-up VLR state about this subscriber */
5039 f_imsi_detach_by_imsi();
5040
Harald Welte4263c522018-12-06 11:56:27 +01005041 setverdict(pass);
5042}
5043testcase TC_sgsap_unsol_ud() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005044 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005045 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005046 f_init(1, true);
5047 pars := f_init_pars(11822, true);
5048 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_unsol_ud), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005049 vc_conn.done;
5050}
5051
5052private altstep as_other_sms_sgs() runs on BSC_ConnHdlr {
5053 /* FIXME: Match an actual payload (second questionmark), the type is
5054 * octetstring, how do we use a tr_PDU_DTAP_MT here? */
5055 [] SGsAP.receive(tr_SGsAP_DL_UD(?,?)) {
5056 setverdict(fail, "Unexpected SMS related PDU from MSC");
5057 mtc.stop;
5058 }
5059}
5060
5061/* receive a MT-SMS delivered from the MSC/SMSC over an already existing SGsAP connection */
5062function f_mt_sms_sgs(inout SmsParameters spars)
5063runs on BSC_ConnHdlr {
5064 var template (value) TPDU_RP_DATA_MS_SGSN tp_mo;
5065 var template (value) RPDU_MS_SGSN rp_mo;
5066 var template (value) PDU_ML3_MS_NW l3_mo;
5067
5068 var template TPDU_RP_DATA_SGSN_MS tp_mt;
5069 var template RPDU_SGSN_MS rp_mt;
5070 var template PDU_ML3_NW_MS l3_mt;
5071
5072 var PDU_ML3_NW_MS sgsap_l3_mt;
5073
5074 var default d := activate(as_other_sms_sgs());
5075
5076 /* Expect CP-DATA(RP-DATA(SMS-DELIVER)) */
5077 tp_mt := tr_SMS_DELIVER(?, spars.tp.ud, spars.tp.pid, spars.tp.dcs, ?);
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09005078 rp_mt := tr_RP_DATA_MT(?, spars.rp.smsc_addr, omit, tp_mt);
Harald Welte4263c522018-12-06 11:56:27 +01005079 l3_mt := tr_ML3_MT_SMS(?, c_TIF_ORIG, tr_CP_DATA_MT(rp_mt));
5080
5081 SGsAP.receive(l3_mt) -> value sgsap_l3_mt;
5082
5083 /* Extract relevant identifiers */
5084 spars.tid := bit2int(sgsap_l3_mt.tiOrSkip.transactionId.tio);
5085 spars.rp.msg_ref := sgsap_l3_mt.msgs.sms.cP_DATA.cP_User_Data.cP_RPDU.rP_DATA_SGSN_MS.rP_MessageReference;
5086
5087 /* send CP-ACK for CP-DATA just received */
5088 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_REPL, ts_CP_ACK_MO);
5089
5090 SGsAP.send(l3_mo);
5091
5092 /* send RP-ACK for RP-DATA */
5093 rp_mo := ts_RP_ACK_MO(spars.rp.msg_ref);
5094 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_REPL, ts_CP_DATA_MO(rp_mo));
5095
5096 SGsAP.send(l3_mo);
5097
5098 /* expect CP-ACK for CP-DATA(RP-ACK) just sent */
5099 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_ORIG, tr_CP_ACK_MT);
5100
5101 SGsAP.receive(l3_mt);
5102
5103 deactivate(d);
5104
5105 setverdict(pass);
5106}
5107
5108/* submit a MO-SMS to MSC/SMSC over an already existing SGsAP connection */
5109function f_mo_sms_sgs(inout SmsParameters spars)
5110runs on BSC_ConnHdlr {
5111 var template (value) TPDU_RP_DATA_MS_SGSN tp_mo;
5112 var template (value) RPDU_MS_SGSN rp_mo;
5113 var template (value) PDU_ML3_MS_NW l3_mo;
5114
5115 var template TPDU_RP_DATA_SGSN_MS tp_mt;
5116 var template RPDU_SGSN_MS rp_mt;
5117 var template PDU_ML3_NW_MS l3_mt;
5118
5119 var default d := activate(as_other_sms_sgs());
5120
5121 /* just in case this is routed to SMPP.. */
5122 f_create_smpp_expect(hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue));
5123
5124 tp_mo := ts_SMS_SUBMIT(spars.tp.msg_ref, spars.tp.da, spars.tp.pid, spars.tp.dcs,
5125 spars.tp.udl, spars.tp.ud);
Vadim Yanitskiy437b5a62019-12-15 14:13:39 +09005126 rp_mo := ts_RP_DATA_MO(spars.rp.msg_ref, omit, spars.rp.smsc_addr, tp_mo);
Harald Welte4263c522018-12-06 11:56:27 +01005127 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_DATA_MO(rp_mo));
5128
5129 SGsAP.send(l3_mo);
5130
5131 /* receive CP-ACK for CP-DATA above */
5132 SGsAP.receive(tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_ACK_MT));
5133
5134 if (ispresent(spars.exp_rp_err)) {
5135 /* expect an RP-ERROR message from MSC with given cause */
5136 rp_mt := tr_RP_ERROR_MT(spars.rp.msg_ref, spars.exp_rp_err);
5137 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_DATA_MT(rp_mt));
5138 SGsAP.receive(l3_mt);
5139 /* send CP-ACK for CP-DATA just received */
5140 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_ACK_MO);
5141 SGsAP.send(l3_mo);
5142 } else {
5143 /* expect RP-ACK for RP-DATA */
5144 rp_mt := tr_RP_ACK_MT(spars.rp.msg_ref);
5145 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_DATA_MT(rp_mt));
5146 SGsAP.receive(l3_mt);
5147 /* send CP-ACO for CP-DATA just received */
5148 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_ACK_MO);
5149 SGsAP.send(l3_mo);
5150 }
5151
5152 deactivate(d);
5153
5154 setverdict(pass);
5155}
5156
5157private function f_vty_sms_send_conn_hdlr(charstring imsi, charstring msisdn, charstring text)
5158runs on BSC_ConnHdlr {
5159 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
5160}
5161
5162/* Send a MT SMS via SGs interface */
5163private function f_tc_sgsap_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5164 f_init_handler(pars);
5165 f_sgs_perform_lu();
5166 f_sleep(1.0);
5167 var SmsParameters spars := valueof(t_SmsPars);
5168 spars.tp.ud := 'C8329BFD064D9B53'O;
5169
5170 /* Trigger SMS via VTY */
5171 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
5172 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5173
5174 /* Expect a paging request and respond accordingly with a service request */
5175 SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, SMS_indicator, omit));
5176 SGsAP.send(ts_SGsAP_SERVICE_REQ(pars.imsi, SMS_indicator, EMM_CONNECTED));
5177
5178 /* Connection is now live, receive the MT-SMS */
5179 f_mt_sms_sgs(spars);
5180
5181 /* Expect a concluding release from the MSC */
5182 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, omit));
5183
5184 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
5185 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5186
5187 f_sgsap_bssmap_screening();
5188
5189 setverdict(pass);
5190}
5191testcase TC_sgsap_mt_sms() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005192 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005193 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005194 f_init(1, true);
5195 pars := f_init_pars(11823, true);
5196 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005197 vc_conn.done;
5198}
5199
5200/* Send a MO SMS via SGs interface */
5201private function f_tc_sgsap_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5202 f_init_handler(pars);
5203 f_sgs_perform_lu();
5204 f_sleep(1.0);
5205 var SmsParameters spars := valueof(t_SmsPars);
5206 spars.tp.ud := 'C8329BFD064D9B53'O;
5207
5208 /* Send the MO-SMS */
5209 f_mo_sms_sgs(spars);
5210
5211 /* Expect a concluding release from the MSC/VLR */
5212 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, omit));
5213
5214 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
5215 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5216
5217 setverdict(pass);
5218
5219 f_sgsap_bssmap_screening()
5220}
5221testcase TC_sgsap_mo_sms() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005222 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005223 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005224 f_init(1, true);
5225 pars := f_init_pars(11824, true);
5226 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mo_sms), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005227 vc_conn.done;
5228}
5229
5230/* Trigger sending of an MT sms via VTY but never respond to anything */
5231private function f_tc_sgsap_mt_sms_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5232 f_init_handler(pars, 170.0);
5233 f_sgs_perform_lu();
5234 f_sleep(1.0);
5235
5236 var SmsParameters spars := valueof(t_SmsPars);
5237 spars.tp.ud := 'C8329BFD064D9B53'O;
5238 var integer page_count := 0;
5239 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5240 var template PDU_SGsAP exp_pag_req := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, SMS_indicator, omit);
5241 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
5242 exp_pag_req.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
5243
5244 /* Trigger SMS via VTY */
5245 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
5246
Neels Hofmeyr16237742019-03-06 15:34:01 +01005247 /* Expect the MSC/VLR to page exactly once */
5248 SGsAP.receive(exp_pag_req);
Harald Welte4263c522018-12-06 11:56:27 +01005249
5250 /* Wait some time to make sure the MSC is not delivering any further
5251 * paging messages or anything else that could be unexpected. */
5252 timer T := 20.0;
5253 T.start
5254 alt {
5255 [] SGsAP.receive(exp_pag_req)
5256 {
5257 setverdict(fail, "paging seems not to stop!");
5258 mtc.stop;
5259 }
5260 [] SGsAP.receive {
5261 setverdict(fail, "unexpected SGsAP message received");
5262 self.stop;
5263 }
5264 [] T.timeout {
5265 setverdict(pass);
5266 }
5267 }
5268
5269 /* Even on a failed paging the SGs Association should stay intact */
5270 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5271
Philipp Maier26bdb8c2019-09-24 09:21:12 +02005272 /* Make sure that the SMS we just inserted is cleared and the
5273 * subscriber is expired. This is necessary because otherwise the MSC
5274 * might re-try the SMS delivery and disturb the following tests. */
Harald Welte4263c522018-12-06 11:56:27 +01005275
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01005276 f_vty_sms_clear(hex2str(g_pars.imsi));
5277
Harald Welte4263c522018-12-06 11:56:27 +01005278 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " expire");
5279
5280 setverdict(pass);
Neels Hofmeyrb0f82342019-03-06 15:36:51 +01005281
5282 f_sgsap_bssmap_screening();
Harald Welte4263c522018-12-06 11:56:27 +01005283}
5284testcase TC_sgsap_mt_sms_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005285 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005286 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005287 f_init(1, true);
5288 pars := f_init_pars(11825, true);
5289 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005290 vc_conn.done;
5291}
5292
5293/* Trigger sending of an MT sms via VTY but reject the paging immediately */
5294private function f_tc_sgsap_mt_sms_and_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5295 f_init_handler(pars, 150.0);
5296 f_sgs_perform_lu();
5297 f_sleep(1.0);
5298
5299 var SmsParameters spars := valueof(t_SmsPars);
5300 spars.tp.ud := 'C8329BFD064D9B53'O;
5301 var integer page_count := 0;
5302 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5303 var template PDU_SGsAP exp_pag_req := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, SMS_indicator, omit);
5304 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
5305 exp_pag_req.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
5306
5307 /* Trigger SMS via VTY */
5308 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
5309
5310 /* Expect a paging request and reject it immediately */
5311 SGsAP.receive(exp_pag_req);
5312 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, IMSI_unknown));
5313
5314 /* The MSC/VLR should no longer try to page once the paging has been
5315 * rejected. Wait some time and check if there are no unexpected
5316 * messages on the SGs interface. */
5317 timer T := 20.0;
5318 T.start
5319 alt {
5320 [] SGsAP.receive(exp_pag_req)
5321 {
5322 setverdict(fail, "paging seems not to stop!");
5323 mtc.stop;
5324 }
5325 [] SGsAP.receive {
5326 setverdict(fail, "unexpected SGsAP message received");
5327 self.stop;
5328 }
5329 [] T.timeout {
5330 setverdict(pass);
5331 }
5332 }
5333
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01005334 f_vty_sms_clear(hex2str(g_pars.imsi));
5335
Harald Welte4263c522018-12-06 11:56:27 +01005336 /* A rejected paging with IMSI_unknown (see above) should always send
5337 * the SGs association to NULL. */
5338 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
5339
5340 f_sgsap_bssmap_screening();
5341
Harald Welte4263c522018-12-06 11:56:27 +01005342 setverdict(pass);
5343}
5344testcase TC_sgsap_mt_sms_and_reject() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005345 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005346 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005347 f_init(1, true);
5348 pars := f_init_pars(11826, true);
5349 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms_and_reject), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005350 vc_conn.done;
5351}
5352
5353/* Perform an MT CSDB call including LU */
5354private function f_mt_lu_and_csfb_call(charstring id, BSC_ConnHdlrPars pars, boolean bssmap_lu) runs on BSC_ConnHdlr {
5355 f_init_handler(pars);
5356
5357 /* Be sure that the BSSMAP reset is done before we begin. */
5358 f_sleep(2.0);
5359
5360 /* Testcase variation: See what happens when we do a regular BSSMAP
5361 * LU first (this should not hurt in any way!) */
5362 if (bssmap_lu) {
5363 f_perform_lu();
5364 }
5365
5366 f_sgs_perform_lu();
5367 f_sleep(1.0);
5368
5369 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5370 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Harald Welte4263c522018-12-06 11:56:27 +01005371
5372 /* Initiate a call via MNCC interface */
5373 f_mt_call_initate(cpars);
5374
5375 /* Expect a paging request and respond accordingly with a service request */
5376 SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit));
5377 SGsAP.send(ts_SGsAP_SERVICE_REQ(pars.imsi, CS_call_indicator, EMM_CONNECTED));
5378
5379 /* Complete the call, hold it for some time and then tear it down */
5380 f_mt_call_complete(cpars);
5381 f_sleep(3.0);
Harald Welte4c422b72019-02-17 16:27:10 +01005382 f_call_hangup(cpars, true, is_csfb := true);
Harald Welte4263c522018-12-06 11:56:27 +01005383
5384 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
5385 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5386
Harald Welte4263c522018-12-06 11:56:27 +01005387 /* Test for successful return by triggering a paging, when the paging
5388 * request is received via SGs, we can be sure that the MSC/VLR has
5389 * recognized that the UE is now back on 4G */
5390 f_sleep(1.0);
5391 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
5392 alt {
5393 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
5394 setverdict(pass);
5395 }
5396 [] SGsAP.receive {
5397 setverdict(fail, "Received unexpected message on SGs");
5398 }
5399 }
5400
5401 f_sgsap_bssmap_screening();
5402
5403 setverdict(pass);
5404}
5405
5406/* Perform a regular BSSAP LU first, do a SGSAP LU and then make a CSFB call */
5407private function f_tc_bssap_lu_sgsap_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5408 f_mt_lu_and_csfb_call(id, pars, true);
5409}
5410testcase TC_bssap_lu_sgsap_lu_and_mt_call() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005411 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005412 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005413 f_init(1, true);
5414 pars := f_init_pars(118139, true);
Harald Welte4263c522018-12-06 11:56:27 +01005415
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005416 vc_conn := f_start_handler_with_pars(refers(f_tc_bssap_lu_sgsap_lu_and_mt_call), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005417 vc_conn.done;
5418}
5419
Harald Welte4263c522018-12-06 11:56:27 +01005420/* Perform a SGSAP LU and then make a CSFB call */
5421private function f_tc_sgsap_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5422 f_mt_lu_and_csfb_call(id, pars, false);
5423}
5424testcase TC_sgsap_lu_and_mt_call() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005425 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005426 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005427 f_init(1, true);
5428 pars := f_init_pars(11827, true);
Harald Welte4263c522018-12-06 11:56:27 +01005429
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005430 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_and_mt_call), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005431 vc_conn.done;
5432}
5433
Philipp Maier628c0052019-04-09 17:36:57 +02005434/* Simulate an HLR/VLR failure */
5435private function f_tc_sgsap_vlr_failure(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5436 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
5437 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5438
5439 var PDU_SGsAP lur;
5440
5441 f_init_handler(pars);
5442
5443 /* Attempt location update (which is expected to fail) */
5444 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
5445 ts_SGsAP_LAI('901'H, '70'H, 2342)));
5446 SGsAP.send(lur);
5447
5448 /* Respond to SGsAP-RESET-INDICATION from VLR */
5449 alt {
5450 [] SGsAP.receive(tr_SGsAP_RESET_IND_VLR(vlr_name)); {
5451 SGsAP.send(valueof(ts_SGsAP_RESET_ACK_MME(mme_name)));
5452 setverdict(pass);
5453 }
5454 [] SGsAP.receive {
5455 setverdict(fail, "Received unexpected message on SGs");
5456 }
5457 }
5458
5459 f_sleep(1.0);
5460 setverdict(pass);
5461}
5462testcase TC_sgsap_vlr_failure() runs on MTC_CT {
5463 var BSC_ConnHdlrPars pars;
5464 var BSC_ConnHdlr vc_conn;
5465 f_init(1, true, false);
5466 pars := f_init_pars(11811, true, false);
5467 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_vlr_failure), pars);
5468 vc_conn.done;
5469}
5470
Harald Welte4263c522018-12-06 11:56:27 +01005471/* SGs TODO:
5472 * LU attempt for IMSI without NAM_PS in HLR
5473 * LU attempt with AUTH FAIL due to invalid RES/SRES
5474 * LU attempt with no response from HLR (VLR should timeout + LU REJ)
5475 * LU attempt with new TMSI but without TMSI REALL CMPL baco to VLR
5476 * implicit IMSI detach from EPS
5477 * implicit IMSI detach from non-EPS
5478 * MM INFO
5479 *
5480 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01005481
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005482private function f_tc_ho_inter_bsc_unknown_cell(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5483 f_init_handler(pars);
5484 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005485
5486 f_perform_lu();
5487 f_mo_call_establish(cpars);
5488
5489 f_sleep(1.0);
5490
5491 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5492 var BssmapCause cause := enum2int(cause_val);
5493
5494 var template BSSMAP_FIELD_CellIdentificationList cil;
5495 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('023'H, '42'H, 999) } };
5496
5497 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5498 BSSAP.receive(tr_BSSMAP_HandoverRequiredReject);
5499
5500 f_call_hangup(cpars, true);
5501}
5502testcase TC_ho_inter_bsc_unknown_cell() runs on MTC_CT {
5503 var BSC_ConnHdlr vc_conn;
5504 f_init();
5505
5506 vc_conn := f_start_handler(refers(f_tc_ho_inter_bsc_unknown_cell), 53);
5507 vc_conn.done;
5508}
5509
5510private altstep as_mgcp_ack_all_mdcx(CallParameters cpars) runs on BSC_ConnHdlr {
5511 var MgcpCommand mgcp_cmd;
5512 [] MGCP.receive(tr_MDCX) -> value mgcp_cmd {
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02005513 var SDP_Message sdp := valueof(ts_SDP(cpars.mgw_conn_2.mgw_rtp_ip, cpars.mgw_conn_2.mgw_rtp_ip,
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005514 hex2str(cpars.mgcp_call_id), "42",
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02005515 cpars.mgw_conn_2.mgw_rtp_port,
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005516 { int2str(cpars.rtp_payload_type) },
5517 { valueof(ts_SDP_rtpmap(cpars.rtp_payload_type,
5518 cpars.rtp_sdp_format)),
5519 valueof(ts_SDP_ptime(20)) }));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02005520 MGCP.send(ts_MDCX_ACK(mgcp_cmd.line.trans_id, cpars.mgw_conn_2.mgcp_connection_id, sdp));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005521 repeat;
5522 }
5523}
5524
5525private function f_tc_ho_inter_bsc0(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005526 var CallParameters cpars;
5527
5528 cpars := valueof(t_CallParams('12345'H, 0));
5529 if (pars.use_ipv6) {
5530 cpars.mgw_conn_1.mgw_rtp_ip := "::1";
5531 cpars.mgw_conn_2.mgw_rtp_ip := "::2";
5532 cpars.bss_rtp_ip := "::3";
5533 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005534
5535 f_init_handler(pars);
5536
5537 f_vty_transceive(MSCVTY, "configure terminal");
5538 f_vty_transceive(MSCVTY, "msc");
5539 f_vty_transceive(MSCVTY, "neighbor a cgi 262 42 23 42 ran-pc 0.24.1");
5540 f_vty_transceive(MSCVTY, "neighbor a lac 5 ran-pc 0.24.2");
5541 f_vty_transceive(MSCVTY, "exit");
5542 f_vty_transceive(MSCVTY, "exit");
5543
5544 f_perform_lu();
5545 f_mo_call_establish(cpars);
5546
5547 f_sleep(1.0);
5548
5549 var default ack_mdcx := activate(as_mgcp_ack_all_mdcx(cpars));
5550
5551 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5552 var BssmapCause cause := enum2int(cause_val);
5553
5554 var template BSSMAP_FIELD_CellIdentificationList cil;
5555 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('023'H, '42'H, 5) } };
5556
5557 /* old BSS sends Handover Required */
5558 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5559
5560 /* Now the action goes on in f_tc_ho_inter_bsc1() */
5561
5562 /* MSC forwards the RR Handover Command to old BSS */
5563 var PDU_BSSAP ho_command;
5564 BSSAP.receive(tr_BSSMAP_HandoverCommand) -> value ho_command;
5565
5566 log("GOT HandoverCommand", ho_command);
5567
5568 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
5569
5570 /* f_tc_ho_inter_bsc1() completes Handover, then expecting a Clear here. */
5571 f_expect_clear();
5572
5573 log("FIRST inter-BSC Handover done");
5574
5575
5576 /* ------------------------ */
5577
5578 /* Ok, that went well, now the other BSC is handovering back here --
5579 * from now on this here is the new BSS. */
5580 f_create_bssmap_exp_handoverRequest(193);
5581
5582 var PDU_BSSAP ho_request;
5583 BSSAP.receive(tr_BSSMAP_HandoverRequest) -> value ho_request;
5584
5585 /* new BSS composes a RR Handover Command */
5586 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5587 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005588 var BSSMAP_IE_AoIP_TransportLayerAddress tla tla :=
5589 valueof(f_ts_BSSMAP_IE_AoIP_TLA(cpars.bss_rtp_ip, cpars.bss_rtp_port));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005590 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5591 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5592
5593 /* Now f_tc_ho_inter_bsc1() expects HandoverCommand */
5594
5595 f_sleep(0.5);
5596
5597 /* Notify that the MS is now over here */
5598
5599 BSSAP.send(ts_BSSMAP_HandoverDetect);
5600 f_sleep(0.1);
5601 BSSAP.send(ts_BSSMAP_HandoverComplete);
5602
5603 f_sleep(3.0);
5604
5605 deactivate(ack_mdcx);
5606
5607 var default ccrel := activate(as_optional_cc_rel(cpars, true));
5608
5609 /* blatant cheating */
5610 var N_Sd_Array last_n_sd := f_bssmap_last_n_sd();
5611 last_n_sd[0] := 3;
5612 f_bssmap_continue_after_n_sd(last_n_sd);
5613
5614 f_call_hangup(cpars, true);
5615 f_sleep(1.0);
5616 deactivate(ccrel);
5617
5618 setverdict(pass);
5619}
5620private function f_tc_ho_inter_bsc1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005621 var charstring bss_rtp_ip;
5622 if (pars.use_ipv6) {
5623 bss_rtp_ip := "::8";
5624 } else {
5625 bss_rtp_ip := "1.2.3.4";
5626 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005627 f_init_handler(pars);
5628 f_create_bssmap_exp_handoverRequest(194);
5629
5630 var PDU_BSSAP ho_request;
5631 BSSAP.receive(tr_BSSMAP_HandoverRequest) -> value ho_request;
5632
5633 /* new BSS composes a RR Handover Command */
5634 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5635 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005636 var BSSMAP_IE_AoIP_TransportLayerAddress tla :=
5637 valueof(f_ts_BSSMAP_IE_AoIP_TLA(bss_rtp_ip, 2342));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005638 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5639 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5640
5641 /* Now f_tc_ho_inter_bsc0() expects HandoverCommand */
5642
5643 f_sleep(0.5);
5644
5645 /* Notify that the MS is now over here */
5646
5647 BSSAP.send(ts_BSSMAP_HandoverDetect);
5648 f_sleep(0.1);
5649 BSSAP.send(ts_BSSMAP_HandoverComplete);
5650
5651 f_sleep(3.0);
5652
5653 /* Now I'd like to f_call_hangup() but we don't know any cpars here. So
5654 * ... handover back to the first BSC :P */
5655
5656 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5657 var BssmapCause cause := enum2int(cause_val);
5658
5659 var template BSSMAP_FIELD_CellIdentificationList cil;
5660 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('262'H, '42'H, 23) } };
5661
5662 /* old BSS sends Handover Required */
5663 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5664
5665 /* Now the action goes on in f_tc_ho_inter_bsc0() */
5666
5667 /* MSC forwards the RR Handover Command to old BSS */
5668 var PDU_BSSAP ho_command;
5669 BSSAP.receive(tr_BSSMAP_HandoverCommand) -> value ho_command;
5670
5671 log("GOT HandoverCommand", ho_command);
5672
5673 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
5674
5675 /* f_tc_ho_inter_bsc1() completes Handover, then expecting a Clear here. */
5676 f_expect_clear();
5677 setverdict(pass);
5678}
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005679function f_tc_ho_inter_bsc_main(boolean use_ipv6 := false) runs on MTC_CT {
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005680 var BSC_ConnHdlr vc_conn0;
5681 var BSC_ConnHdlr vc_conn1;
5682 f_init(2);
5683
5684 var BSC_ConnHdlrPars pars0 := f_init_pars(53);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005685 pars0.use_ipv6 := use_ipv6;
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005686 var BSC_ConnHdlrPars pars1 := f_init_pars(53);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005687 pars1.use_ipv6 := use_ipv6;
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005688
5689 vc_conn0 := f_start_handler_with_pars(refers(f_tc_ho_inter_bsc0), pars0, 0);
5690 vc_conn1 := f_start_handler_with_pars(refers(f_tc_ho_inter_bsc1), pars1, 1);
5691 vc_conn0.done;
5692 vc_conn1.done;
5693}
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005694testcase TC_ho_inter_bsc() runs on MTC_CT {
5695 f_tc_ho_inter_bsc_main(false);
5696}
5697testcase TC_ho_inter_bsc_ipv6() runs on MTC_CT {
5698 f_tc_ho_inter_bsc_main(true);
5699}
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005700
5701function f_ML3_patch_seq_nr_MS_NW(in uint2_t seq_nr, inout octetstring enc_l3) {
5702 log("MS_NW patching N(SD)=", seq_nr, " into dtap ", enc_l3);
5703 enc_l3[2] := (enc_l3[2] and4b '3f'O) or4b bit2oct(int2bit(seq_nr, 8) << 6);
5704 log("MS_NW patched enc_l3: ", enc_l3);
5705}
5706
5707private function f_tc_ho_inter_msc_out(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005708 var CallParameters cpars;
5709
5710 cpars := valueof(t_CallParams('12345'H, 0));
5711 if (pars.use_ipv6) {
5712 cpars.mgw_conn_1.mgw_rtp_ip := "::1";
5713 cpars.mgw_conn_2.mgw_rtp_ip := "::2";
5714 cpars.bss_rtp_ip := "::3";
5715 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005716 var hexstring ho_number := f_gen_msisdn(99999);
5717
5718 f_init_handler(pars);
5719
5720 f_create_mncc_expect(hex2str(ho_number));
5721
5722 f_vty_transceive(MSCVTY, "configure terminal");
5723 f_vty_transceive(MSCVTY, "msc");
5724 f_vty_transceive(MSCVTY, "neighbor a cgi 017 017 1 1 msc-ipa-name msc-017-017-1");
5725 f_vty_transceive(MSCVTY, "exit");
5726 f_vty_transceive(MSCVTY, "exit");
5727
5728 f_perform_lu();
5729 f_mo_call_establish(cpars);
5730
5731 f_sleep(1.0);
5732
5733 var default ack_mdcx := activate(as_mgcp_ack_all_mdcx(cpars));
5734
5735 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5736 var BssmapCause cause := enum2int(cause_val);
5737
5738 var template BSSMAP_FIELD_CellIdentificationList cil;
5739 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('017'H, '017'H, 1) } };
5740
5741 /* old BSS sends Handover Required */
5742 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5743
5744 /* The target cell 017-017 LAC 1 is configured to be a remote MSC of name "msc-017-017-1".
5745 * This MSC tries to reach the other MSC via GSUP. */
5746
5747 var octetstring remote_msc_name := '6D73632D3031372D3031372D3100'O; /* "msc-017-017-1\0" as octetstring */
5748 var GSUP_PDU prep_ho_req;
5749 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_HANDOVER_REQUEST,
5750 pars.imsi, destination_name := remote_msc_name)) -> value prep_ho_req;
5751
5752 var GSUP_IeValue source_name_ie;
5753 f_gsup_find_ie(prep_ho_req, OSMO_GSUP_SOURCE_NAME_IE, source_name_ie);
5754 var octetstring local_msc_name := source_name_ie.source_name;
5755
5756 /* Remote MSC has figured out its BSC and signals success */
5757 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5758 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
5759 var PDU_BSSAP ho_req_ack := valueof(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5760 aoIPTransportLayer := omit,
5761 speechCodec := ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5762 GSUP.send(ts_GSUP_E_PrepareHandoverResult(
5763 pars.imsi,
5764 ho_number,
5765 remote_msc_name, local_msc_name,
5766 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006, enc_PDU_BSSAP(ho_req_ack)))));
5767
5768 /* MSC forwards the RR Handover Command to old BSS */
5769 BSSAP.receive(tr_BSSMAP_HandoverCommand);
5770
5771 /* The MS shows up at remote new BSS */
5772
5773 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PROCESS_ACCESS_SIGNALLING_REQUEST,
5774 pars.imsi, remote_msc_name, local_msc_name,
5775 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5776 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverDetect))))));
5777 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
5778 f_sleep(0.1);
5779
5780 /* Save the MS sequence counters for use on the other connection */
5781 var N_Sd_Array last_n_sd := f_bssmap_last_n_sd();
5782
5783 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_SEND_END_SIGNAL_REQUEST,
5784 pars.imsi, remote_msc_name, local_msc_name,
5785 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5786 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverComplete))))));
5787
5788 /* The local BSS conn clears, all communication goes via remote MSC now */
5789 f_expect_clear();
5790
5791 /**********************************/
5792 /* Play through some signalling across the inter-MSC link.
5793 * This is a copy of f_tc_lu_and_mo_ussd_single_request() translated into GSUP AN-APDUs. */
5794
5795 if (false) {
5796 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
5797 invoke_id := 5, /* Phone may not start from 0 or 1 */
5798 op_code := SS_OP_CODE_PROCESS_USS_REQ,
5799 ussd_string := "*#100#"
5800 );
5801
5802 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
5803 invoke_id := 5, /* InvokeID shall be the same for both REQ and RSP */
5804 op_code := SS_OP_CODE_PROCESS_USS_REQ,
5805 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
5806 )
5807
5808 /* Compose a new SS/REGISTER message with request */
5809 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
5810 tid := 1, /* We just need a single transaction */
5811 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
5812 facility := valueof(facility_req)
5813 );
5814 var PDU_ML3_MS_NW ussd_req_v := valueof(ussd_req);
5815
5816 /* Compose SS/RELEASE_COMPLETE template with expected response */
5817 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
5818 tid := 1, /* Response should arrive within the same transaction */
5819 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
5820 facility := valueof(facility_rsp)
5821 );
5822
5823 /* Compose expected MSC -> HLR message */
5824 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
5825 imsi := g_pars.imsi,
5826 state := OSMO_GSUP_SESSION_STATE_BEGIN,
5827 ss := valueof(facility_req)
5828 );
5829
5830 /* To be used for sending response with correct session ID */
5831 var GSUP_PDU gsup_req_complete;
5832
5833 /* Request own number */
5834 /* From remote MSC instead of BSSAP directly */
5835 /* Patch the correct N_SD value into the message. */
5836 var octetstring l3_enc := enc_PDU_ML3_MS_NW(ussd_req_v);
5837 var RAN_Emulation.ConnectionData cd;
5838 f_ML3_patch_seq_nr_MS_NW(f_next_n_sd(last_n_sd, f_ML3_n_sd_idx(ussd_req_v)), l3_enc);
5839 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PROCESS_ACCESS_SIGNALLING_REQUEST,
5840 pars.imsi, remote_msc_name, local_msc_name,
5841 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5842 enc_PDU_BSSAP(valueof(ts_BSSAP_DTAP(l3_enc)))
5843 ))
5844 ));
5845
5846 /* Expect GSUP message containing the SS payload */
5847 gsup_req_complete := f_expect_gsup_msg(gsup_req);
5848
5849 /* Compose the response from HLR using received session ID */
5850 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
5851 imsi := g_pars.imsi,
5852 sid := gsup_req_complete.ies[1].val.session_id,
5853 state := OSMO_GSUP_SESSION_STATE_END,
5854 ss := valueof(facility_rsp)
5855 );
5856
5857 /* Finally, HLR terminates the session */
5858 GSUP.send(gsup_rsp);
5859
5860 /* The USSD response goes out to remote MSC, on GSUP E instead of BSSAP */
5861 var GSUP_PDU gsup_ussd_rsp;
5862 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_FORWARD_ACCESS_SIGNALLING_REQUEST,
5863 pars.imsi, destination_name := remote_msc_name)) -> value gsup_ussd_rsp;
5864
5865 var GSUP_IeValue an_apdu;
5866 if (not f_gsup_find_ie(gsup_ussd_rsp, OSMO_GSUP_AN_APDU_IE, an_apdu)) {
5867 setverdict(fail, "No AN-APDU in received GSUP message. Expected USSD response in DTAP, got", gsup_ussd_rsp);
5868 mtc.stop;
5869 }
5870 var PDU_BSSAP bssap_dtap_mt := dec_PDU_BSSAP(an_apdu.an_apdu.pdu);
5871 var PDU_ML3_NW_MS dtap_mt := dec_PDU_ML3_NW_MS(bssap_dtap_mt.pdu.dtap);
5872 log("Expecting", ussd_rsp);
5873 log("Got", dtap_mt);
5874 if (not match(dtap_mt, ussd_rsp)) {
5875 setverdict(fail, "Unexpected GSUP message. Expected USSD response in DTAP, got", gsup_ussd_rsp);
5876 mtc.stop;
5877 }
5878 }
5879 /**********************************/
5880
5881
5882 /* inter-MSC handover back to the first MSC */
5883 f_create_bssmap_exp_handoverRequest(193);
5884 cil := { cIl_CGI := { ts_BSSMAP_CI_CGI('262'H, '42'H, 23, 42) } };
5885
5886 /* old BSS sends Handover Required, via inter-MSC E link: like
5887 * BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5888 * but via GSUP */
5889 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_SUBSEQUENT_HANDOVER_REQUEST,
5890 pars.imsi, remote_msc_name, local_msc_name,
5891 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5892 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverRequired(cause, cil)))
5893 ))
5894 ));
5895
5896 /* MSC asks local BSS to prepare Handover to it */
5897 BSSAP.receive(tr_BSSMAP_HandoverRequest);
5898
5899 /* Make sure the new BSSAP conn continues with the correct N_SD sequence numbers */
5900 f_bssmap_continue_after_n_sd(last_n_sd);
5901
5902 /* new BSS composes a RR Handover Command */
5903 rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5904 rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005905 var BSSMAP_IE_AoIP_TransportLayerAddress tla :=
5906 valueof(f_ts_BSSMAP_IE_AoIP_TLA(cpars.bss_rtp_ip, cpars.bss_rtp_port));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005907 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5908 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5909
5910 /* HandoverCommand goes out via remote MSC-I */
5911 var GSUP_PDU prep_subsq_ho_res;
5912 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_SUBSEQUENT_HANDOVER_RESULT,
5913 pars.imsi, destination_name := remote_msc_name)) -> value prep_subsq_ho_res;
5914
5915 /* MS shows up at the local BSS */
5916 BSSAP.send(ts_BSSMAP_HandoverDetect);
5917 f_sleep(0.1);
5918 BSSAP.send(ts_BSSMAP_HandoverComplete);
5919
5920 /* Handover Succeeded message */
5921 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_FORWARD_ACCESS_SIGNALLING_REQUEST,
5922 pars.imsi, destination_name := remote_msc_name));
5923
5924 /* MS has handovered to here, Clear Command goes out via remote MSC-I -- in form of a GSUP Close. */
5925 GSUP.receive(tr_GSUP_E_NO_PDU(OSMO_GSUP_MSGT_E_CLOSE,
5926 pars.imsi, destination_name := remote_msc_name));
5927
5928 /* Handover ends successfully. Call goes on for a little longer and then we hang up. */
5929
5930 f_sleep(1.0);
5931 deactivate(ack_mdcx);
5932
5933 /* FIXME: the inter-MSC call has put a number of MNCC messages in the queue, which above code should expect and
5934 * clear out. The f_call_hangup() expects an MNCC_REL_IND, so, for the time being, just clear the MNCC messages
5935 * before starting the call hangup. Instead of this, the individual messages should be tested for above. */
5936 MNCC.clear;
5937
5938 var default ccrel := activate(as_optional_cc_rel(cpars, true));
5939 f_call_hangup(cpars, true);
5940 f_sleep(1.0);
5941 deactivate(ccrel);
5942
5943 setverdict(pass);
5944}
5945testcase TC_ho_inter_msc_out() runs on MTC_CT {
5946 var BSC_ConnHdlr vc_conn;
5947 f_init(1);
5948
5949 var BSC_ConnHdlrPars pars := f_init_pars(54);
5950
5951 vc_conn := f_start_handler_with_pars(refers(f_tc_ho_inter_msc_out), pars, 0);
5952 vc_conn.done;
5953}
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005954testcase TC_ho_inter_msc_out_ipv6() runs on MTC_CT {
5955 var BSC_ConnHdlr vc_conn;
5956 f_init(1);
5957
5958 var BSC_ConnHdlrPars pars := f_init_pars(54);
5959 pars.use_ipv6 := true;
5960
5961 vc_conn := f_start_handler_with_pars(refers(f_tc_ho_inter_msc_out), pars, 0);
5962 vc_conn.done;
5963}
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005964
Oliver Smith1d118ff2019-07-03 10:57:35 +02005965private function f_tc_lu_imsi_auth_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5966 pars.net.expect_auth := true;
5967 pars.net.expect_imei := true;
5968 f_init_handler(pars);
5969 f_perform_lu();
5970}
5971testcase TC_lu_imsi_auth_tmsi_check_imei() runs on MTC_CT {
5972 var BSC_ConnHdlr vc_conn;
5973 f_init();
5974 f_vty_config(MSCVTY, "network", "authentication required");
5975 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
5976
5977 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei), 5);
5978 vc_conn.done;
5979}
5980
5981private function f_tc_lu_imsi_auth3g_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5982 pars.net.expect_auth := true;
5983 pars.use_umts_aka := true;
5984 pars.net.expect_imei := true;
5985 f_init_handler(pars);
5986 f_perform_lu();
5987}
5988testcase TC_lu_imsi_auth3g_tmsi_check_imei() runs on MTC_CT {
5989 var BSC_ConnHdlr vc_conn;
5990 f_init();
5991 f_vty_config(MSCVTY, "network", "authentication required");
5992 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
5993
5994 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi_check_imei), 5);
5995 vc_conn.done;
5996}
5997
5998private function f_tc_lu_imsi_noauth_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5999 pars.net.expect_imei := true;
6000 f_init_handler(pars);
6001 f_perform_lu();
6002}
6003testcase TC_lu_imsi_noauth_tmsi_check_imei() runs on MTC_CT {
6004 var BSC_ConnHdlr vc_conn;
6005 f_init();
6006 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6007
6008 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi_check_imei), 5);
6009 vc_conn.done;
6010}
6011
6012private function f_tc_lu_imsi_noauth_notmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6013 pars.net.expect_tmsi := false;
6014 pars.net.expect_imei := true;
6015 f_init_handler(pars);
6016 f_perform_lu();
6017}
6018testcase TC_lu_imsi_noauth_notmsi_check_imei() runs on MTC_CT {
6019 var BSC_ConnHdlr vc_conn;
6020 f_init();
6021 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
6022 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6023
6024 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi_check_imei), 5);
6025 vc_conn.done;
6026}
6027
6028private function f_tc_lu_imsi_auth_tmsi_check_imei_nack(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6029 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02006030
6031 pars.net.expect_auth := true;
6032 pars.net.expect_imei := true;
6033 pars.net.check_imei_result := OSMO_GSUP_IMEI_RESULT_NACK;
6034 f_init_handler(pars);
6035
6036 /* Cannot use f_perform_lu() as we expect a reject */
6037 l3_lu := f_build_lu_imsi(g_pars.imsi)
6038 f_create_gsup_expect(hex2str(g_pars.imsi));
6039 f_bssap_compl_l3(l3_lu);
6040 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
6041
6042 f_mm_common();
6043 f_msc_lu_hlr();
6044 f_mm_imei();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02006045 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02006046 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02006047}
6048testcase TC_lu_imsi_auth_tmsi_check_imei_nack() runs on MTC_CT {
6049 var BSC_ConnHdlr vc_conn;
6050 f_init();
6051 f_vty_config(MSCVTY, "network", "authentication required");
6052 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6053
6054 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_nack), 5);
6055 vc_conn.done;
6056}
6057
6058private function f_tc_lu_imsi_auth_tmsi_check_imei_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6059 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02006060
6061 pars.net.expect_auth := true;
6062 pars.net.expect_imei := true;
6063 pars.net.check_imei_error := true;
6064 f_init_handler(pars);
6065
6066 /* Cannot use f_perform_lu() as we expect a reject */
6067 l3_lu := f_build_lu_imsi(g_pars.imsi)
6068 f_create_gsup_expect(hex2str(g_pars.imsi));
6069 f_bssap_compl_l3(l3_lu);
6070 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
6071
6072 f_mm_common();
6073 f_msc_lu_hlr();
6074 f_mm_imei();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02006075 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02006076 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02006077}
6078testcase TC_lu_imsi_auth_tmsi_check_imei_err() runs on MTC_CT {
6079 var BSC_ConnHdlr vc_conn;
6080 f_init();
6081 f_vty_config(MSCVTY, "network", "authentication required");
6082 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6083
6084 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_err), 5);
6085 vc_conn.done;
6086}
6087
6088private function f_tc_lu_imsi_auth_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6089 pars.net.expect_auth := true;
6090 pars.net.expect_imei_early := true;
6091 f_init_handler(pars);
6092 f_perform_lu();
6093}
6094testcase TC_lu_imsi_auth_tmsi_check_imei_early() runs on MTC_CT {
6095 var BSC_ConnHdlr vc_conn;
6096 f_init();
6097 f_vty_config(MSCVTY, "network", "authentication required");
6098 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6099
6100 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early), 5);
6101 vc_conn.done;
6102}
6103
6104private function f_tc_lu_imsi_auth3g_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6105 pars.net.expect_auth := true;
6106 pars.use_umts_aka := true;
6107 pars.net.expect_imei_early := true;
6108 f_init_handler(pars);
6109 f_perform_lu();
6110}
6111testcase TC_lu_imsi_auth3g_tmsi_check_imei_early() runs on MTC_CT {
6112 var BSC_ConnHdlr vc_conn;
6113 f_init();
6114 f_vty_config(MSCVTY, "network", "authentication required");
6115 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6116
6117 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi_check_imei_early), 5);
6118 vc_conn.done;
6119}
6120
6121private function f_tc_lu_imsi_noauth_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6122 pars.net.expect_imei_early := true;
6123 f_init_handler(pars);
6124 f_perform_lu();
6125}
6126testcase TC_lu_imsi_noauth_tmsi_check_imei_early() runs on MTC_CT {
6127 var BSC_ConnHdlr vc_conn;
6128 f_init();
6129 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6130
6131 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi_check_imei_early), 5);
6132 vc_conn.done;
6133}
6134
6135private function f_tc_lu_imsi_noauth_notmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6136 pars.net.expect_tmsi := false;
6137 pars.net.expect_imei_early := true;
6138 f_init_handler(pars);
6139 f_perform_lu();
6140}
6141testcase TC_lu_imsi_noauth_notmsi_check_imei_early() runs on MTC_CT {
6142 var BSC_ConnHdlr vc_conn;
6143 f_init();
6144 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
6145 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6146
6147 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi_check_imei_early), 5);
6148 vc_conn.done;
6149}
6150
6151private function f_tc_lu_imsi_auth_tmsi_check_imei_early_nack(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6152 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02006153
6154 pars.net.expect_auth := true;
6155 pars.net.expect_imei_early := true;
6156 pars.net.check_imei_result := OSMO_GSUP_IMEI_RESULT_NACK;
6157 f_init_handler(pars);
6158
6159 /* Cannot use f_perform_lu() as we expect a reject */
6160 l3_lu := f_build_lu_imsi(g_pars.imsi)
6161 f_create_gsup_expect(hex2str(g_pars.imsi));
6162 f_bssap_compl_l3(l3_lu);
6163 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
6164
6165 f_mm_imei_early();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02006166 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02006167 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02006168}
6169testcase TC_lu_imsi_auth_tmsi_check_imei_early_nack() runs on MTC_CT {
6170 var BSC_ConnHdlr vc_conn;
6171 f_init();
6172 f_vty_config(MSCVTY, "network", "authentication required");
6173 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6174
6175 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early_nack), 5);
6176 vc_conn.done;
6177}
6178
6179private function f_tc_lu_imsi_auth_tmsi_check_imei_early_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6180 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02006181
6182 pars.net.expect_auth := true;
6183 pars.net.expect_imei_early := true;
6184 pars.net.check_imei_error := true;
6185 f_init_handler(pars);
6186
6187 /* Cannot use f_perform_lu() as we expect a reject */
6188 l3_lu := f_build_lu_imsi(g_pars.imsi)
6189 f_create_gsup_expect(hex2str(g_pars.imsi));
6190 f_bssap_compl_l3(l3_lu);
6191 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
6192
6193 f_mm_imei_early();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02006194 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02006195 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02006196}
6197testcase TC_lu_imsi_auth_tmsi_check_imei_early_err() runs on MTC_CT {
6198 var BSC_ConnHdlr vc_conn;
6199 f_init();
6200 f_vty_config(MSCVTY, "network", "authentication required");
6201 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6202
6203 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early_err), 5);
6204 vc_conn.done;
6205}
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006206
Neels Hofmeyr8df69622019-11-02 19:16:03 +01006207friend function f_tc_invalid_mgcp_crash(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6208 f_init_handler(pars);
6209 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
6210
6211 /* Set invalid IP address so that osmo-msc discards the rtp_stream and MGCP endpoint FSM instances in the middle
6212 * of successful MGCP response dispatch. If things aren't safeguarded, the on_success() in osmo_mgcpc_ep_fsm
6213 * will cause a use-after-free after that event dispatch. */
6214 cpars.mgw_conn_1.mgw_rtp_ip := "0.0.0.0";
6215 cpars.mgw_conn_2.mgw_rtp_ip := "0.0.0.0";
6216 cpars.rtp_sdp_format := "FOO/8000";
6217 cpars.expect_release := true;
6218
6219 f_perform_lu();
6220 f_mo_call_establish(cpars);
6221}
6222testcase TC_invalid_mgcp_crash() runs on MTC_CT {
6223 var BSC_ConnHdlr vc_conn;
6224 f_init();
6225
6226 vc_conn := f_start_handler(refers(f_tc_invalid_mgcp_crash), 7);
6227 vc_conn.done;
6228}
6229
Vadim Yanitskiyeddebaa2019-12-28 17:45:34 +01006230friend function f_tc_mm_id_resp_no_identity(charstring id, BSC_ConnHdlrPars pars)
6231runs on BSC_ConnHdlr {
6232 pars.tmsi := 'FFFFFFFF'O;
6233 f_init_handler(pars);
6234
6235 f_create_gsup_expect(hex2str(g_pars.imsi));
6236
6237 /* Initiate Location Updating using an unknown TMSI */
6238 f_bssap_compl_l3(f_build_lu_tmsi(pars.tmsi));
6239
6240 /* Expect an Identity Request, send response with no identity */
6241 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
6242 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp({
6243 lengthIndicator := 1,
6244 mobileIdentityV := {
6245 typeOfIdentity := '000'B,
6246 oddEvenInd_identity := {
6247 no_identity := {
6248 oddevenIndicator := '0'B,
6249 fillerDigits := '00000'H
6250 }
6251 }
6252 }
6253 })));
6254
6255 f_expect_lu_reject();
6256 f_expect_clear();
6257}
6258testcase TC_mm_id_resp_no_identity() runs on MTC_CT {
6259 var BSC_ConnHdlr vc_conn;
6260
6261 f_init();
6262
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02006263 vc_conn := f_start_handler(refers(f_tc_mm_id_resp_no_identity), 7, verify_cell_id := false);
Vadim Yanitskiyeddebaa2019-12-28 17:45:34 +01006264 vc_conn.done;
6265}
6266
Vadim Yanitskiy25219062020-01-21 01:41:33 +07006267/* Verify the case when T3212 expires during Paging procedure, just before the receipt
6268 * of Paging Response. This used to provoke a NULL-pointer dereference in old versions
6269 * of OsmoMSC, but apparently the bug has been fixed, and we're safe now. */
6270friend function f_tc_lu_and_expire_while_paging(charstring id, BSC_ConnHdlrPars pars)
6271runs on BSC_ConnHdlr {
6272 var charstring imsi := hex2str(pars.imsi);
6273
6274 f_init_handler(pars);
6275
6276 /* Perform location update */
6277 f_perform_lu();
6278
6279 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
6280 f_create_gsup_expect(hex2str(g_pars.imsi));
6281
6282 /* Initiate paging procedure from the VTY */
6283 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " paging");
6284 f_expect_paging();
6285
6286 /* Emulate T3212 expiration during paging (we don't want to wait, right?) */
6287 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " expire");
6288
6289 /* MS sends PAGING RESPONSE, *old* OsmoMSC crashes here... */
6290 f_establish_fully(EST_TYPE_PAG_RESP);
6291
6292 /* The recent OsmoMSC keeps subscriber in its VLR unless the Paging is completed.
6293 * In this case we do not send anything and just wait for a Clear Command. */
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02006294 f_expect_clear(verify_vlr_cell_id := false);
Vadim Yanitskiy25219062020-01-21 01:41:33 +07006295}
6296testcase TC_lu_and_expire_while_paging() runs on MTC_CT {
6297 var BSC_ConnHdlr vc_conn;
6298
6299 f_init();
6300
6301 vc_conn := f_start_handler(refers(f_tc_lu_and_expire_while_paging), 7);
6302 vc_conn.done;
6303}
6304
Harald Weltef6dd64d2017-11-19 12:09:51 +01006305control {
Philipp Maier328d1662018-03-07 10:40:27 +01006306 execute( TC_cr_before_reset() );
Harald Weltea49e36e2018-01-21 19:29:33 +01006307 execute( TC_lu_imsi_noauth_tmsi() );
Harald Welted2328a22018-01-27 14:27:16 +01006308 execute( TC_lu_imsi_noauth_notmsi() );
Harald Weltea49e36e2018-01-21 19:29:33 +01006309 execute( TC_lu_imsi_reject() );
6310 execute( TC_lu_imsi_timeout_gsup() );
Harald Welted2328a22018-01-27 14:27:16 +01006311 execute( TC_lu_imsi_auth_tmsi() );
Harald Welte8a397ae2019-04-21 22:03:37 +02006312 execute( TC_lu_imsi_auth3g_tmsi() );
Pau Espin Pedrold3d54a92019-12-17 17:02:54 +01006313 execute( TC_lu_imsi_timeout_tmsi_realloc() );
Harald Welted2328a22018-01-27 14:27:16 +01006314 execute( TC_cmserv_imsi_unknown() );
Neels Hofmeyr13737fb2020-08-19 13:16:14 +00006315 execute( TC_cmserv_tmsi_unknown() );
Harald Welte2bb825f2018-01-22 11:31:18 +01006316 execute( TC_lu_and_mo_call() );
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006317 execute( TC_lu_and_mo_call_ipv6() );
Pau Espin Pedrola42745c2020-01-10 18:03:28 +01006318 execute( TC_lu_and_mo_call_sccp_tiar_timeout() );
Harald Welte071ed732018-01-23 19:53:52 +01006319 execute( TC_lu_auth_sai_timeout() );
6320 execute( TC_lu_auth_sai_err() );
Harald Weltee1a2f3c2018-01-24 17:28:48 +01006321 execute( TC_lu_clear_request() );
6322 execute( TC_lu_disconnect() );
6323 execute( TC_lu_by_imei() );
6324 execute( TC_lu_by_tmsi_noauth_unknown() );
Neels Hofmeyrfc06c732020-08-19 12:52:28 +00006325 execute( TC_attached_imsi_lu_unknown_tmsi() );
Harald Weltee1a2f3c2018-01-24 17:28:48 +01006326 execute( TC_imsi_detach_by_imsi() );
6327 execute( TC_imsi_detach_by_tmsi() );
6328 execute( TC_imsi_detach_by_imei() );
6329 execute( TC_emerg_call_imei_reject() );
6330 execute( TC_emerg_call_imsi() );
6331 execute( TC_cm_serv_req_vgcs_reject() );
6332 execute( TC_cm_serv_req_vbs_reject() );
6333 execute( TC_cm_serv_req_lcs_reject() );
Harald Welte0195ab12018-01-24 21:50:20 +01006334 execute( TC_cm_reest_req_reject() );
Harald Welte1af6ea82018-01-25 18:33:15 +01006335 execute( TC_lu_auth_2G_fail() );
6336 execute( TC_lu_imsi_auth_tmsi_encr_13_13() );
6337 execute( TC_cl3_no_payload() );
6338 execute( TC_cl3_rnd_payload() );
Harald Welte1852a842018-01-26 22:53:36 +01006339 execute( TC_establish_and_nothing() );
6340 execute( TC_mo_setup_and_nothing() );
6341 execute( TC_mo_crcx_ran_timeout() );
6342 execute( TC_mo_crcx_ran_reject() );
Harald Welted2328a22018-01-27 14:27:16 +01006343 execute( TC_mt_crcx_ran_reject() );
Daniel Willmann8b084372018-02-04 13:35:26 +01006344 execute( TC_mo_setup_and_dtmf_dup() );
Harald Welteaa54cf82018-01-30 08:15:32 +01006345 //execute( TC_mt_t310() );
Harald Welte167458a2018-01-27 15:58:16 +01006346 execute( TC_gsup_cancel() );
Harald Welte9de84792018-01-28 01:06:35 +01006347 execute( TC_lu_imsi_auth_tmsi_encr_1_13() );
6348 execute( TC_lu_imsi_auth_tmsi_encr_3_13() );
6349 execute( TC_lu_imsi_auth_tmsi_encr_3_1() );
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01006350 execute( TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() );
Harald Welte9de84792018-01-28 01:06:35 +01006351 execute( TC_lu_imsi_auth_tmsi_encr_13_2() );
6352 execute( TC_lu_imsi_auth_tmsi_encr_013_2() );
Philipp Maier94f3f1b2018-03-15 18:54:13 +01006353 execute( TC_mo_release_timeout() );
Philipp Maier2a98a732018-03-19 16:06:12 +01006354 execute( TC_lu_and_mt_call_no_dlcx_resp() );
Philipp Maier75932982018-03-27 14:52:35 +02006355 execute( TC_reset_two() );
Harald Welte33ec09b2018-02-10 15:34:46 +01006356
6357 execute( TC_lu_and_mt_call() );
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006358 execute( TC_lu_and_mt_call_ipv6() );
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01006359 execute( TC_lu_and_mt_call_already_paging() );
Pau Espin Pedrol9a732a42020-09-15 15:56:33 +02006360 execute( TC_lu_and_mt_call_osmux() );
Harald Welte33ec09b2018-02-10 15:34:46 +01006361
Harald Weltef45efeb2018-04-09 18:19:24 +02006362 execute( TC_lu_and_mo_sms() );
6363 execute( TC_lu_and_mt_sms() );
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01006364 execute( TC_lu_and_mt_sms_already_paging() );
Philipp Maier3983e702018-11-22 19:01:33 +01006365 execute( TC_lu_and_mt_sms_paging_and_nothing() );
Alexander Couzensfc02f242019-09-12 03:43:18 +02006366 execute( TC_lu_and_mt_sms_paging_repeated() );
Harald Weltef640a012018-04-14 17:49:21 +02006367 execute( TC_smpp_mo_sms() );
Vadim Yanitskiy33820762020-01-15 11:26:07 +07006368 execute( TC_smpp_mo_sms_rp_error() );
Harald Weltef640a012018-04-14 17:49:21 +02006369 execute( TC_smpp_mt_sms() );
Harald Weltef45efeb2018-04-09 18:19:24 +02006370
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07006371 execute( TC_gsup_mo_sms() );
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07006372 execute( TC_gsup_mo_smma() );
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07006373 execute( TC_gsup_mt_sms_ack() );
6374 execute( TC_gsup_mt_sms_err() );
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07006375 execute( TC_gsup_mt_sms_rp_mr() );
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07006376 execute( TC_gsup_mo_mt_sms_rp_mr() );
Vadim Yanitskiya2a8a112019-07-08 20:04:32 +07006377 execute( TC_gsup_mt_multi_part_sms() );
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07006378
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07006379 execute( TC_lu_and_mo_ussd_single_request() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07006380 execute( TC_lu_and_mt_ussd_notification() );
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07006381 execute( TC_lu_and_mo_ussd_during_mt_call() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07006382 execute( TC_lu_and_mt_ussd_during_mt_call() );
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07006383 execute( TC_lu_and_mo_ussd_mo_release() );
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07006384 execute( TC_lu_and_ss_session_timeout() );
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07006385
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07006386 execute( TC_mt_ussd_for_unknown_subscr() );
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07006387 execute( TC_mo_ussd_for_unknown_trans() );
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07006388 execute( TC_proc_ss_for_unknown_session() );
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07006389 execute( TC_proc_ss_paging_fail() );
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07006390 execute( TC_proc_ss_abort() );
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07006391
Vadim Yanitskiy1c9754d2020-01-07 21:56:55 +01006392 execute( TC_multi_lu_and_mo_ussd() );
6393 execute( TC_multi_lu_and_mt_ussd() );
6394
Stefan Sperling89eb1f32018-12-17 15:06:20 +01006395 execute( TC_cipher_complete_with_invalid_cipher() );
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01006396 execute( TC_cipher_complete_1_without_cipher() );
6397 execute( TC_cipher_complete_3_without_cipher() );
6398 execute( TC_cipher_complete_13_without_cipher() );
Harald Welteb2284bd2019-05-10 11:30:43 +02006399 execute( TC_lu_with_invalid_mcc_mnc() );
Stefan Sperling89eb1f32018-12-17 15:06:20 +01006400
Harald Welte4263c522018-12-06 11:56:27 +01006401 execute( TC_sgsap_reset() );
6402 execute( TC_sgsap_lu() );
6403 execute( TC_sgsap_lu_imsi_reject() );
6404 execute( TC_sgsap_lu_and_nothing() );
6405 execute( TC_sgsap_expl_imsi_det_eps() );
Philipp Maierfc19f172019-03-21 11:17:54 +01006406 execute( TC_sgsap_impl_imsi_det_eps() );
Harald Welte4263c522018-12-06 11:56:27 +01006407 execute( TC_sgsap_expl_imsi_det_noneps() );
Philipp Maier5d812702019-03-21 10:51:26 +01006408 execute( TC_sgsap_impl_imsi_det_noneps() );
Harald Welte4263c522018-12-06 11:56:27 +01006409 execute( TC_sgsap_paging_rej() );
6410 execute( TC_sgsap_paging_subscr_rej() );
6411 execute( TC_sgsap_paging_ue_unr() );
6412 execute( TC_sgsap_paging_and_nothing() );
6413 execute( TC_sgsap_paging_and_lu() );
6414 execute( TC_sgsap_mt_sms() );
6415 execute( TC_sgsap_mo_sms() );
6416 execute( TC_sgsap_mt_sms_and_nothing() );
6417 execute( TC_sgsap_mt_sms_and_reject() );
6418 execute( TC_sgsap_unexp_ud() );
6419 execute( TC_sgsap_unsol_ud() );
6420 execute( TC_bssap_lu_sgsap_lu_and_mt_call() );
6421 execute( TC_sgsap_lu_and_mt_call() );
Philipp Maier628c0052019-04-09 17:36:57 +02006422 execute( TC_sgsap_vlr_failure() );
Harald Welte4263c522018-12-06 11:56:27 +01006423
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006424 execute( TC_ho_inter_bsc_unknown_cell() );
6425 execute( TC_ho_inter_bsc() );
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006426 execute( TC_ho_inter_bsc_ipv6() );
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006427
6428 execute( TC_ho_inter_msc_out() );
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006429 execute( TC_ho_inter_msc_out_ipv6() );
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006430
Oliver Smith1d118ff2019-07-03 10:57:35 +02006431 execute( TC_lu_imsi_auth_tmsi_check_imei() );
6432 execute( TC_lu_imsi_auth3g_tmsi_check_imei() );
6433 execute( TC_lu_imsi_noauth_tmsi_check_imei() );
6434 execute( TC_lu_imsi_noauth_notmsi_check_imei() );
6435 execute( TC_lu_imsi_auth_tmsi_check_imei_nack() );
6436 execute( TC_lu_imsi_auth_tmsi_check_imei_err() );
6437 execute( TC_lu_imsi_auth_tmsi_check_imei_early() );
6438 execute( TC_lu_imsi_auth3g_tmsi_check_imei_early() );
6439 execute( TC_lu_imsi_noauth_tmsi_check_imei_early() );
6440 execute( TC_lu_imsi_noauth_notmsi_check_imei_early() );
6441 execute( TC_lu_imsi_auth_tmsi_check_imei_early_nack() );
6442 execute( TC_lu_imsi_auth_tmsi_check_imei_early_err() );
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01006443 execute( TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() );
Pau Espin Pedrol609f1d62020-09-15 16:01:55 +02006444
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02006445 execute( TC_mo_cc_bssmap_clear() );
Neels Hofmeyr8df69622019-11-02 19:16:03 +01006446 execute( TC_invalid_mgcp_crash() );
Vadim Yanitskiyeddebaa2019-12-28 17:45:34 +01006447 execute( TC_mm_id_resp_no_identity() );
Vadim Yanitskiy25219062020-01-21 01:41:33 +07006448 execute( TC_lu_and_expire_while_paging() );
Pau Espin Pedrol609f1d62020-09-15 16:01:55 +02006449 if (mp_enable_crashing_tests) {
6450 execute( TC_paging_response_imsi_unknown() );
6451 execute( TC_paging_response_tmsi_unknown() );
6452 }
Harald Weltef6dd64d2017-11-19 12:09:51 +01006453}
6454
6455
6456}