blob: 8d29e7a7fff0cdd46b78ad010350f8a2c9a71c73 [file] [log] [blame]
Harald Weltef6dd64d2017-11-19 12:09:51 +01001module MSC_Tests {
2
3import from General_Types all;
4import from Osmocom_Types all;
5
6import from M3UA_Types all;
7import from M3UA_Emulation all;
8
9import from MTP3asp_Types all;
10import from MTP3asp_PortType all;
11
12import from SCCPasp_Types all;
13import from SCCP_Types all;
14import from SCCP_Emulation all;
15
16import from SCTPasp_Types all;
17import from SCTPasp_PortType all;
18
Harald Weltea49e36e2018-01-21 19:29:33 +010019import from Osmocom_CTRL_Functions all;
20import from Osmocom_CTRL_Types all;
21import from Osmocom_CTRL_Adapter all;
22
Harald Welte3ca1c902018-01-24 18:51:27 +010023import from TELNETasp_PortType all;
24import from Osmocom_VTY_Functions all;
25
Harald Weltea49e36e2018-01-21 19:29:33 +010026import from MNCC_Emulation all;
Harald Welte2bb825f2018-01-22 11:31:18 +010027import from MNCC_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010028
Harald Welte4aa970c2018-01-26 10:38:09 +010029import from MGCP_Emulation all;
30import from MGCP_Types all;
31import from MGCP_Templates all;
32import from SDP_Types all;
33
Harald Weltea49e36e2018-01-21 19:29:33 +010034import from GSUP_Emulation all;
35import from GSUP_Types all;
36import from IPA_Emulation all;
37
Harald Weltef6dd64d2017-11-19 12:09:51 +010038import from BSSAP_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010039import from BSSAP_Adapter all;
40import from BSSAP_CodecPort all;
41import from BSSMAP_Templates all;
42import from BSSMAP_Emulation all;
43import from BSC_ConnectionHandler all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010044
Harald Welte4263c522018-12-06 11:56:27 +010045import from SGsAP_Templates all;
46import from SGsAP_Types all;
47import from SGsAP_Emulation all;
48
Harald Weltea49e36e2018-01-21 19:29:33 +010049import from MobileL3_Types all;
50import from MobileL3_CommonIE_Types all;
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +070051import from MobileL3_SMS_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010052import from L3_Templates all;
Harald Welte158a7ca2018-02-16 18:11:31 +010053import from L3_Common all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010054
Harald Weltef640a012018-04-14 17:49:21 +020055import from SMPP_Types all;
56import from SMPP_Templates all;
57import from SMPP_Emulation all;
58
Stefan Sperlingc307e682018-06-14 15:15:46 +020059import from SCCP_Templates all;
60
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070061import from SS_Types all;
62import from SS_Templates all;
63import from USSD_Helpers all;
Harald Welte4263c522018-12-06 11:56:27 +010064import from DNS_Helpers all;
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070065
Philipp Maier75932982018-03-27 14:52:35 +020066const integer NUM_BSC := 2;
67type record of BSSAP_Configuration BSSAP_Configurations;
Harald Weltef6dd64d2017-11-19 12:09:51 +010068
Harald Welte4263c522018-12-06 11:56:27 +010069/* Needed for SGsAP SMS */
70import from MobileL3_SMS_Types all;
71
Harald Weltea4ca4462018-02-09 00:17:14 +010072type component MTC_CT extends CTRL_Adapter_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +010073 var boolean g_initialized := false;
Harald Weltea49e36e2018-01-21 19:29:33 +010074
Philipp Maier75932982018-03-27 14:52:35 +020075 var BSSAP_Adapter g_bssap[NUM_BSC];
Harald Weltea4ca4462018-02-09 00:17:14 +010076
Harald Weltea49e36e2018-01-21 19:29:33 +010077 /* no 'adapter_CT' for MNCC or GSUP */
78 var MNCC_Emulation_CT vc_MNCC;
Harald Welte4aa970c2018-01-26 10:38:09 +010079 var MGCP_Emulation_CT vc_MGCP;
Harald Weltea49e36e2018-01-21 19:29:33 +010080 var GSUP_Emulation_CT vc_GSUP;
81 var IPA_Emulation_CT vc_GSUP_IPA;
Harald Weltef640a012018-04-14 17:49:21 +020082 var SMPP_Emulation_CT vc_SMPP;
Harald Welte4263c522018-12-06 11:56:27 +010083 var SGsAP_Emulation_CT vc_SGsAP;
Harald Weltea49e36e2018-01-21 19:29:33 +010084
85 /* only to get events from IPA underneath GSUP */
86 port IPA_CTRL_PT GSUP_IPA_EVENT;
Harald Welte3ca1c902018-01-24 18:51:27 +010087 /* VTY to MSC */
88 port TELNETasp_PT MSCVTY;
Philipp Maier328d1662018-03-07 10:40:27 +010089
90 /* A port to directly send BSSAP messages. This port is used for
91 * tests that require low level access to sen arbitrary BSSAP
92 * messages. Run f_init_bssap_direct() to connect and initialize */
93 port BSSAP_CODEC_PT BSSAP_DIRECT;
94
95 /* When BSSAP messages are directly sent, then the connection
96 * handler is not active, which means that also no guard timer is
97 * set up. The following timer will serve as a replacement */
98 timer Tguard_direct := 60.0;
Harald Weltef6dd64d2017-11-19 12:09:51 +010099}
100
101modulepar {
Harald Weltea49e36e2018-01-21 19:29:33 +0100102 /* remote parameters of IUT */
103 charstring mp_msc_ip := "127.0.0.1";
104 integer mp_msc_ctrl_port := 4255;
105 integer mp_msc_vty_port := 4254;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100106
Harald Weltea49e36e2018-01-21 19:29:33 +0100107 /* local parameters of emulated HLR */
Philipp Maier9b690e42018-12-21 11:50:03 +0100108 boolean mp_mm_info := false;
Harald Weltea49e36e2018-01-21 19:29:33 +0100109 charstring mp_hlr_ip := "127.0.0.1";
110 integer mp_hlr_port := 4222;
Harald Welte6126fb02018-01-27 20:08:24 +0100111 charstring mp_mgw_ip := "127.0.0.1";
112 integer mp_mgw_port := 2427;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100113
Harald Weltea49e36e2018-01-21 19:29:33 +0100114 charstring mp_msc_mncc := "/tmp/mncc";
Harald Weltea4ca4462018-02-09 00:17:14 +0100115
Harald Weltef640a012018-04-14 17:49:21 +0200116 integer mp_msc_smpp_port := 2775;
117 charstring mp_smpp_system_id := "msc_tester";
118 charstring mp_smpp_password := "osmocom1";
Harald Welte4263c522018-12-06 11:56:27 +0100119 charstring mp_mme_name := "mmec01.mmegi0001.mme.epc.mnc070.mcc901.3gppnetwork.org";
120 charstring mp_vlr_name := "vlr.example.net";
Harald Weltef640a012018-04-14 17:49:21 +0200121
Philipp Maier57865482019-01-07 18:33:13 +0100122 boolean mp_sgsap_enable := false;
123
Philipp Maier75932982018-03-27 14:52:35 +0200124 BSSAP_Configurations mp_bssap_cfg := {
125 {
126 sccp_service_type := "mtp3_itu",
127 sctp_addr := { 23905, "127.0.0.1", 2905, "127.0.0.1" },
128 own_pc := 185,
129 own_ssn := 254,
130 peer_pc := 187,
131 peer_ssn := 254,
132 sio := '83'O,
133 rctx := 0
134 },
135 {
136 sccp_service_type := "mtp3_itu",
137 sctp_addr := { 23906, "127.0.0.1", 2905, "127.0.0.1" },
138 own_pc := 186,
139 own_ssn := 254,
140 peer_pc := 187,
141 peer_ssn := 254,
142 sio := '83'O,
143 rctx := 1
144 }
Harald Weltea4ca4462018-02-09 00:17:14 +0100145 };
Harald Weltef6dd64d2017-11-19 12:09:51 +0100146}
147
Philipp Maier328d1662018-03-07 10:40:27 +0100148/* altstep for the global guard timer (only used when BSSAP_DIRECT
149 * is used for communication */
150private altstep as_Tguard_direct() runs on MTC_CT {
151 [] Tguard_direct.timeout {
152 setverdict(fail, "Tguard timeout");
Daniel Willmannafce8662018-07-06 23:11:32 +0200153 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +0100154 }
155}
Harald Weltef6dd64d2017-11-19 12:09:51 +0100156
Harald Weltef640a012018-04-14 17:49:21 +0200157function f_init_smpp(charstring id) runs on MTC_CT {
158 id := id & "-SMPP";
159 var EsmePars pars := {
160 mode := MODE_TRANSCEIVER,
161 bind := {
162 system_id := mp_smpp_system_id,
163 password := mp_smpp_password,
164 system_type := "MSC_Tests",
165 interface_version := hex2int('34'H),
166 addr_ton := unknown,
167 addr_npi := unknown,
168 address_range := ""
169 },
170 esme_role := true
171 }
172
173 vc_SMPP := SMPP_Emulation_CT.create(id);
174 map(vc_SMPP:SMPP_PORT, system:SMPP_PORT);
175 vc_SMPP.start(SMPP_Emulation.main_client(pars, mp_msc_ip, mp_msc_smpp_port, "", -1));
176}
177
178
Harald Weltea49e36e2018-01-21 19:29:33 +0100179function f_init_mncc(charstring id) runs on MTC_CT {
180 id := id & "-MNCC";
181 var MnccOps ops := {
182 create_cb := refers(MNCC_Emulation.ExpectedCreateCallback),
183 unitdata_cb := refers(MNCC_Emulation.DummyUnitdataCallback)
184 }
185
186 vc_MNCC := MNCC_Emulation_CT.create(id);
187 map(vc_MNCC:MNCC, system:MNCC_CODEC_PT);
188 vc_MNCC.start(MNCC_Emulation.main(ops, id, mp_msc_mncc));
Harald Weltef6dd64d2017-11-19 12:09:51 +0100189}
190
Harald Welte4aa970c2018-01-26 10:38:09 +0100191function f_init_mgcp(charstring id) runs on MTC_CT {
192 id := id & "-MGCP";
193 var MGCPOps ops := {
194 create_cb := refers(MGCP_Emulation.ExpectedCreateCallback),
195 unitdata_cb := refers(MGCP_Emulation.DummyUnitdataCallback)
196 }
197 var MGCP_conn_parameters pars := {
Harald Welte6126fb02018-01-27 20:08:24 +0100198 callagent_ip := mp_msc_ip,
Harald Welte4aa970c2018-01-26 10:38:09 +0100199 callagent_udp_port := -1,
Harald Welte6126fb02018-01-27 20:08:24 +0100200 mgw_ip := mp_mgw_ip,
201 mgw_udp_port := mp_mgw_port
Harald Welte4aa970c2018-01-26 10:38:09 +0100202 }
203
204 vc_MGCP := MGCP_Emulation_CT.create(id);
205 map(vc_MGCP:MGCP, system:MGCP_CODEC_PT);
206 vc_MGCP.start(MGCP_Emulation.main(ops, pars, id));
207}
208
Harald Welte4263c522018-12-06 11:56:27 +0100209function f_init_sgsap(charstring id) runs on MTC_CT {
210 id := id & "-SGsAP";
211 var SGsAPOps ops := {
212 create_cb := refers(SGsAP_Emulation.ExpectedCreateCallback),
213 unitdata_cb := refers(SGsAP_Emulation.DummyUnitdataCallback)
214 }
215 var SGsAP_conn_parameters pars := {
216 remote_ip := mp_msc_ip,
217 remote_sctp_port := 29118,
218 local_ip := "",
219 local_sctp_port := -1
220 }
221
222 vc_SGsAP := SGsAP_Emulation_CT.create(id);
223 map(vc_SGsAP:SGsAP, system:SGsAP_CODEC_PT);
224 vc_SGsAP.start(SGsAP_Emulation.main(ops, pars, id));
225}
226
227
Harald Weltea49e36e2018-01-21 19:29:33 +0100228function f_init_gsup(charstring id) runs on MTC_CT {
229 id := id & "-GSUP";
230 var GsupOps ops := {
231 create_cb := refers(GSUP_Emulation.ExpectedCreateCallback)
232 }
233
234 vc_GSUP_IPA := IPA_Emulation_CT.create(id & "-IPA");
235 vc_GSUP := GSUP_Emulation_CT.create(id);
236
237 map(vc_GSUP_IPA:IPA_PORT, system:IPA_CODEC_PT);
238 connect(vc_GSUP:GSUP, vc_GSUP_IPA:IPA_GSUP_PORT);
239 /* we use this hack to get events like ASP_IPA_EVENT_UP */
240 connect(vc_GSUP_IPA:IPA_CTRL_PORT, self:GSUP_IPA_EVENT);
241
242 vc_GSUP.start(GSUP_Emulation.main(ops, id));
243 vc_GSUP_IPA.start(IPA_Emulation.main_server(mp_hlr_ip, mp_hlr_port));
244
245 /* wait for incoming connection to GSUP port before proceeding */
246 timer T := 10.0;
247 T.start;
248 alt {
249 [] GSUP_IPA_EVENT.receive(t_ASP_IPA_EVT_UD(ASP_IPA_EVENT_UP)) { }
250 [] T.timeout {
Harald Welte458fd372018-03-21 11:26:23 +0100251 setverdict(fail, "No connection to GSUP Port");
Daniel Willmannafce8662018-07-06 23:11:32 +0200252 mtc.stop
Harald Weltea49e36e2018-01-21 19:29:33 +0100253 }
254 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100255}
256
Philipp Maier75932982018-03-27 14:52:35 +0200257function f_init(integer num_bsc := 1) runs on MTC_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +0100258
259 if (g_initialized == true) {
260 return;
261 }
262 g_initialized := true;
263
Philipp Maier75932982018-03-27 14:52:35 +0200264 if (num_bsc > NUM_BSC) {
Daniel Willmannafce8662018-07-06 23:11:32 +0200265 testcase.stop("excess number of BSC instances requested");
Philipp Maier75932982018-03-27 14:52:35 +0200266 }
267
268 for (var integer i := 0; i < num_bsc; i := i + 1) {
269 if (isbound(mp_bssap_cfg[i])) {
Philipp Maierdefd9482018-05-16 16:44:37 +0200270 f_bssap_init(g_bssap[i], mp_bssap_cfg[i], "MSC_Test_" & int2str(i), BSC_BssmapOps);
Harald Welted5833a82018-05-27 16:52:56 +0200271 f_bssap_start(g_bssap[i]);
Philipp Maier75932982018-03-27 14:52:35 +0200272 } else {
Daniel Willmannafce8662018-07-06 23:11:32 +0200273 testcase.stop("missing BSSAP configuration");
Philipp Maier75932982018-03-27 14:52:35 +0200274 }
275 }
276
Harald Weltea49e36e2018-01-21 19:29:33 +0100277 f_ipa_ctrl_start(mp_msc_ip, mp_msc_ctrl_port);
278 f_init_mncc("MSC_Test");
Harald Welte4aa970c2018-01-26 10:38:09 +0100279 f_init_mgcp("MSC_Test");
Harald Weltea49e36e2018-01-21 19:29:33 +0100280 f_init_gsup("MSC_Test");
Harald Weltef640a012018-04-14 17:49:21 +0200281 f_init_smpp("MSC_Test");
Philipp Maier57865482019-01-07 18:33:13 +0100282
283 if (mp_sgsap_enable == true) {
284 f_init_sgsap("MSC_Test");
285 }
Harald Welte3ca1c902018-01-24 18:51:27 +0100286
287 map(self:MSCVTY, system:MSCVTY);
288 f_vty_set_prompts(MSCVTY);
289 f_vty_transceive(MSCVTY, "enable");
Harald Welteb14c77a2018-01-25 17:25:44 +0100290
291 /* set some defaults */
292 f_vty_config(MSCVTY, "network", "authentication optional");
293 f_vty_config(MSCVTY, "msc", "assign-tmsi");
294 f_vty_config(MSCVTY, "network", "encryption a5 0");
Harald Weltef6dd64d2017-11-19 12:09:51 +0100295}
296
Philipp Maier328d1662018-03-07 10:40:27 +0100297/* Initialize for a direct connection to BSSAP. This function is an alternative
298 * to f_init() when the high level functions of the BSC_ConnectionHandler are
299 * not needed. */
300function f_init_bssap_direct() runs on MTC_CT {
Philipp Maier75932982018-03-27 14:52:35 +0200301 f_bssap_init(g_bssap[0], mp_bssap_cfg[0], "MSC_Test", omit);
302 connect(g_bssap[0].vc_SCCP:SCCP_SP_PORT, self:BSSAP_DIRECT);
Philipp Maier328d1662018-03-07 10:40:27 +0100303
304 /* Start guard timer and activate it as default */
305 Tguard_direct.start
306 activate(as_Tguard_direct());
307}
308
Harald Weltef6dd64d2017-11-19 12:09:51 +0100309template PDU_BSSAP ts_BSSAP_BSSMAP := {
310 discriminator := '0'B,
311 spare := '0000000'B,
312 dlci := omit,
313 lengthIndicator := 0, /* overwritten by codec */
314 pdu := ?
315}
316
317template PDU_BSSAP tr_BSSAP_BSSMAP := {
318 discriminator := '0'B,
319 spare := '0000000'B,
320 dlci := omit,
321 lengthIndicator := ?,
322 pdu := {
323 bssmap := ?
324 }
325}
326
327
328type integer BssmapCause;
329
330template (value) BSSMAP_IE_Cause ts_BSSMAP_IE_Cause(BssmapCause val) := {
331 elementIdentifier := '04'O,
332 lengthIndicator := 0,
333 causeValue := int2bit(val, 7),
334 extensionCauseValue := '0'B,
335 spare1 := omit
336}
337
338template (value) PDU_BSSAP ts_BSSMAP_Reset(BssmapCause cause) modifies ts_BSSAP_BSSMAP := {
339 pdu := {
340 bssmap := {
341 reset := {
342 messageType := '30'O,
343 cause := ts_BSSMAP_IE_Cause(cause),
344 a_InterfaceSelectorForReset := omit
345 }
346 }
347 }
348}
349
350template (value) PDU_BSSAP ts_BSSMAP_ResetAck modifies ts_BSSAP_BSSMAP := {
351 pdu := {
352 bssmap := {
353 resetAck := {
354 messageType := '31'O,
355 a_InterfaceSelectorForReset := omit
356 }
357 }
358 }
359}
360
361template PDU_BSSAP tr_BSSMAP_ResetAck modifies tr_BSSAP_BSSMAP := {
362 pdu := {
363 bssmap := {
364 resetAck := {
365 messageType := '31'O,
366 a_InterfaceSelectorForReset := *
367 }
368 }
369 }
370}
371
372template BSSMAP_IE_CellIdentifier ts_BSSMAP_IE_CellID := {
373 elementIdentifier := '05'O,
374 lengthIndicator := 0,
375 cellIdentifierDiscriminator := '0000'B,
376 spare1_4 := '0000'B,
377 cellIdentification := ?
378}
379
380type uint16_t BssmapLAC;
381type uint16_t BssmapCI;
382
383/*
384template BSSMAP_IE_CellIdentifier ts_CellId_CGI(mcc, mnc, lac, ci)
385modifies ts_BSSMAP_IE_CellID := {
386 cellIdentification := {
387 cI_LAC_CGI := {
388 mnc_mcc := FIXME,
389 lac := int2oct(lac, 2),
390 ci := int2oct(ci, 2)
391 }
392 }
393}
394*/
395
396template BSSMAP_IE_CellIdentifier ts_CellID_LAC_CI(BssmapLAC lac, BssmapCI ci)
397modifies ts_BSSMAP_IE_CellID := {
398 cellIdentification := {
399 cI_LAC_CI := {
400 lac := int2oct(lac, 2),
401 ci := int2oct(ci, 2)
402 }
403 }
404}
405
406template BSSMAP_IE_CellIdentifier ts_CellId_CI(BssmapCI ci)
407modifies ts_BSSMAP_IE_CellID := {
408 cellIdentification := {
409 cI_CI := int2oct(ci, 2)
410 }
411}
412
413template BSSMAP_IE_CellIdentifier ts_CellId_none
414modifies ts_BSSMAP_IE_CellID := {
415 cellIdentification := {
416 cI_noCell := ''O
417 }
418}
419
420
421template BSSMAP_IE_Layer3Information ts_BSSMAP_IE_L3Info(octetstring l3info) := {
422 elementIdentifier := '17'O,
423 lengthIndicator := 0,
424 layer3info := l3info
425}
426
427template PDU_BSSAP ts_BSSMAP_ComplL3(BSSMAP_IE_CellIdentifier cell_id, octetstring l3_info)
428modifies ts_BSSAP_BSSMAP := {
429 pdu := {
430 bssmap := {
431 completeLayer3Information := {
432 messageType := '57'O,
433 cellIdentifier := cell_id,
434 layer3Information := ts_BSSMAP_IE_L3Info(l3_info),
435 chosenChannel := omit,
436 lSAIdentifier := omit,
437 aPDU := omit,
438 codecList := omit,
439 redirectAttemptFlag := omit,
440 sendSequenceNumber := omit,
441 iMSI := omit
442 }
443 }
444 }
445}
446
447template PDU_BSSAP ts_BSSMAP_HandoReq(BssmapCause cause, BSSMAP_IE_CellIdentifierList cid_list)
448modifies ts_BSSAP_BSSMAP := {
449 pdu := {
450 bssmap := {
451 handoverRequired := {
452 messageType := '11'O,
453 cause := ts_BSSMAP_IE_Cause(cause),
454 responseRequest := omit,
455 cellIdentifierList := cid_list,
456 circuitPoolList := omit,
457 currentChannelType1 := omit,
458 speechVersion := omit,
459 queueingIndicator := omit,
460 oldToNewBSSInfo := omit,
461 sourceToTargetRNCTransparentInfo := omit,
462 sourceToTargetRNCTransparentInfoCDMA := omit,
463 gERANClassmark := omit,
464 talkerPriority := omit,
465 speechCodec := omit,
466 cSG_Identifier := omit
467 }
468 }
469 }
470}
471
Harald Weltea49e36e2018-01-21 19:29:33 +0100472type function void_fn(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100473
Harald Weltea49e36e2018-01-21 19:29:33 +0100474/* FIXME: move into BSC_ConnectionHandler? */
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100475function f_init_pars(integer imsi_suffix) runs on MTC_CT return BSC_ConnHdlrPars {
Harald Weltede371492018-01-27 23:44:41 +0100476 var BSC_ConnHdlrNetworkPars net_pars := {
477 kc_support := '0A'O, /* A5/1 and A5/3 enabled */
478 expect_tmsi := true,
479 expect_auth := false,
480 expect_ciph := false
481 };
Harald Weltea49e36e2018-01-21 19:29:33 +0100482 var BSC_ConnHdlrPars pars := {
Philipp Maier75932982018-03-27 14:52:35 +0200483 sccp_addr_own := g_bssap[0].sccp_addr_own,
484 sccp_addr_peer := g_bssap[0].sccp_addr_peer,
Harald Welteedbab812018-03-18 16:02:25 +0100485 cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42)),
Harald Welte81b7f9d2018-01-24 19:06:24 +0100486 imei := f_gen_imei(imsi_suffix),
487 imsi := f_gen_imsi(imsi_suffix),
488 msisdn := f_gen_msisdn(imsi_suffix),
Harald Welte256571e2018-01-24 18:47:19 +0100489 tmsi := omit,
Harald Welte9de84792018-01-28 01:06:35 +0100490 cm1 := valueof(ts_CM1),
Harald Welte82600572018-01-21 20:54:08 +0100491 cm2 := valueof(ts_CM2_default),
Harald Welte16114282018-01-24 22:41:21 +0100492 cm3 := omit,
Harald Weltede371492018-01-27 23:44:41 +0100493 vec := omit,
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100494 net := net_pars,
Philipp Maieraeb29a82018-11-08 17:40:53 +0100495 send_early_cm := true,
496 ipa_ctrl_ip := mp_msc_ip,
497 ipa_ctrl_port := mp_msc_ctrl_port,
Philipp Maier9b690e42018-12-21 11:50:03 +0100498 ipa_ctrl_enable := true,
Philipp Maier57865482019-01-07 18:33:13 +0100499 mm_info := mp_mm_info,
500 sgsap_enable := mp_sgsap_enable
Harald Weltea49e36e2018-01-21 19:29:33 +0100501 };
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100502 return pars;
503}
504
505function f_start_handler_with_pars(void_fn fn, BSC_ConnHdlrPars pars) runs on MTC_CT return BSC_ConnHdlr {
506 var BSC_ConnHdlr vc_conn;
507 var charstring id := testcasename();
Harald Weltea49e36e2018-01-21 19:29:33 +0100508
509 vc_conn := BSC_ConnHdlr.create(id);
510 /* BSSMAP part / A interface */
Philipp Maier75932982018-03-27 14:52:35 +0200511 connect(vc_conn:BSSAP, g_bssap[0].vc_BSSMAP:CLIENT);
512 connect(vc_conn:BSSAP_PROC, g_bssap[0].vc_BSSMAP:PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100513 /* MNCC part */
514 connect(vc_conn:MNCC, vc_MNCC:MNCC_CLIENT);
515 connect(vc_conn:MNCC_PROC, vc_MNCC:MNCC_PROC);
Harald Welte4aa970c2018-01-26 10:38:09 +0100516 /* MGCP part */
517 connect(vc_conn:MGCP, vc_MGCP:MGCP_CLIENT);
518 connect(vc_conn:MGCP_PROC, vc_MGCP:MGCP_PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100519 /* GSUP part */
520 connect(vc_conn:GSUP, vc_GSUP:GSUP_CLIENT);
521 connect(vc_conn:GSUP_PROC, vc_GSUP:GSUP_PROC);
Harald Weltef640a012018-04-14 17:49:21 +0200522 /* SMPP part */
523 connect(vc_conn:SMPP, vc_SMPP:SMPP_CLIENT);
524 connect(vc_conn:SMPP_PROC, vc_SMPP:SMPP_PROC);
Harald Welte4263c522018-12-06 11:56:27 +0100525 /* SGs part */
Philipp Maier57865482019-01-07 18:33:13 +0100526 if (mp_sgsap_enable == true) {
527 connect(vc_conn:SGsAP, vc_SGsAP:SGsAP_CLIENT);
528 connect(vc_conn:SGsAP_PROC, vc_SGsAP:SGsAP_PROC);
529 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100530
Harald Weltea10db902018-01-27 12:44:49 +0100531 /* We cannot use vc_conn.start(f_init_handler(fn, id, pars)); as we cannot have
532 * a stand-alone 'derefers()' call, see https://www.eclipse.org/forums/index.php/t/1091364/ */
Harald Weltea49e36e2018-01-21 19:29:33 +0100533 vc_conn.start(derefers(fn)(id, pars));
534 return vc_conn;
535}
536
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100537function f_start_handler(void_fn fn, integer imsi_suffix) runs on MTC_CT return BSC_ConnHdlr {
538 return f_start_handler_with_pars(fn, f_init_pars(imsi_suffix));
539}
540
Harald Weltea49e36e2018-01-21 19:29:33 +0100541private function f_tc_lu_imsi_noauth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100542 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100543 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100544}
Harald Weltea49e36e2018-01-21 19:29:33 +0100545testcase TC_lu_imsi_noauth_tmsi() runs on MTC_CT {
546 var BSC_ConnHdlr vc_conn;
547 f_init();
548
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100549 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi), 1);
Harald Weltea49e36e2018-01-21 19:29:33 +0100550 vc_conn.done;
551}
552
553private function f_tc_lu_imsi_noauth_notmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100554 pars.net.expect_tmsi := false;
Harald Weltea10db902018-01-27 12:44:49 +0100555 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100556 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100557}
Harald Weltea49e36e2018-01-21 19:29:33 +0100558testcase TC_lu_imsi_noauth_notmsi() runs on MTC_CT {
559 var BSC_ConnHdlr vc_conn;
560 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100561 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
Harald Weltea49e36e2018-01-21 19:29:33 +0100562
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100563 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi), 2);
Harald Weltea49e36e2018-01-21 19:29:33 +0100564 vc_conn.done;
565}
566
567/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
568private function f_tc_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100569 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100570 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
571
572 f_create_gsup_expect(hex2str(g_pars.imsi));
573 f_bssap_compl_l3(l3_lu);
574 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
575 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
576 alt {
Harald Welte5946b332018-03-18 23:32:21 +0100577 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej(int2oct(23,1)))) {
578 f_expect_clear();
579 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100580 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
581 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200582 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100583 }
584 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100585}
586testcase TC_lu_imsi_reject() runs on MTC_CT {
587 var BSC_ConnHdlr vc_conn;
588 f_init();
589
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100590 vc_conn := f_start_handler(refers(f_tc_lu_imsi_reject), 3);
Harald Weltea49e36e2018-01-21 19:29:33 +0100591 vc_conn.done;
592}
593
594/* Do LU by IMSI, timeout on GSUP */
595private function f_tc_lu_imsi_timeout_gsup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100596 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100597 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
598
599 f_create_gsup_expect(hex2str(g_pars.imsi));
600 f_bssap_compl_l3(l3_lu);
601 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
602 /* Normally the HLR would need to respond here, but we decide to force a timeout here */
603 alt {
604 /* FIXME: Expect specific reject cause */
Harald Welte5946b332018-03-18 23:32:21 +0100605 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
606 f_expect_clear();
607 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100608 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
609 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200610 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100611 }
612 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100613}
614testcase TC_lu_imsi_timeout_gsup() runs on MTC_CT {
615 var BSC_ConnHdlr vc_conn;
616 f_init();
617
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100618 vc_conn := f_start_handler(refers(f_tc_lu_imsi_timeout_gsup), 4);
Harald Weltea49e36e2018-01-21 19:29:33 +0100619 vc_conn.done;
620}
621
Harald Welte7b1b2812018-01-22 21:23:06 +0100622private function f_tc_lu_imsi_auth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100623 pars.net.expect_auth := true;
Harald Weltea10db902018-01-27 12:44:49 +0100624 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100625 f_perform_lu();
Harald Welte7b1b2812018-01-22 21:23:06 +0100626}
627testcase TC_lu_imsi_auth_tmsi() runs on MTC_CT {
628 var BSC_ConnHdlr vc_conn;
629 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100630 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte7b1b2812018-01-22 21:23:06 +0100631
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100632 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi), 5);
Harald Welte7b1b2812018-01-22 21:23:06 +0100633 vc_conn.done;
634}
635
Harald Weltea49e36e2018-01-21 19:29:33 +0100636
637/* Send CM SERVICE REQ for IMSI that has never performed LU before */
638private function f_tc_cmserv_imsi_unknown(charstring id, BSC_ConnHdlrPars pars)
639runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100640 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100641
642 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welteedbab812018-03-18 16:02:25 +0100643 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
Harald Welte6ed6bf92018-01-24 21:09:15 +0100644 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
Harald Weltea49e36e2018-01-21 19:29:33 +0100645
646 f_create_gsup_expect(hex2str(g_pars.imsi));
647
648 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
649 f_bssap_compl_l3(l3_info);
650
651 timer T := 10.0;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100652 T.start;
653 alt {
Harald Weltea49e36e2018-01-21 19:29:33 +0100654 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
655 //[] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_ACC)) { }
Daniel Willmannafce8662018-07-06 23:11:32 +0200656 [] BSSAP.receive {
657 setverdict(fail, "Received unexpected BSSAP");
658 mtc.stop;
659 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100660 [] GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi)) {
661 setverdict(fail, "Unexpected GSUP UL REQ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200662 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100663 }
Daniel Willmannafce8662018-07-06 23:11:32 +0200664 [] T.timeout {
665 setverdict(fail, "Timeout waiting for CM SERV REQ");
666 mtc.stop;
667 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100668 }
669
Harald Welte1ddc7162018-01-27 14:25:46 +0100670 f_expect_clear();
Harald Weltef6dd64d2017-11-19 12:09:51 +0100671}
Harald Weltea49e36e2018-01-21 19:29:33 +0100672testcase TC_cmserv_imsi_unknown() runs on MTC_CT {
673 var BSC_ConnHdlr vc_conn;
674 f_init();
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100675 vc_conn := f_start_handler(refers(f_tc_cmserv_imsi_unknown), 6);
Harald Weltea49e36e2018-01-21 19:29:33 +0100676 vc_conn.done;
677}
678
Harald Welte2bb825f2018-01-22 11:31:18 +0100679private function f_tc_lu_and_mo_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100680 f_init_handler(pars);
Harald Welteb71901a2018-01-26 19:16:05 +0100681 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
682 cpars.bss_rtp_port := 1110;
683 cpars.mgcp_connection_id_bss := '22222'H;
684 cpars.mgcp_connection_id_mss := '33333'H;
Philipp Maierf1e02bb2018-03-15 16:30:00 +0100685 cpars.mgcp_ep := "rtpbridge/1@mgw";
Harald Welte2bb825f2018-01-22 11:31:18 +0100686
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100687 f_perform_lu();
Harald Welteb71901a2018-01-26 19:16:05 +0100688 f_mo_call(cpars);
Harald Welte2bb825f2018-01-22 11:31:18 +0100689}
690testcase TC_lu_and_mo_call() runs on MTC_CT {
691 var BSC_ConnHdlr vc_conn;
692 f_init();
693
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100694 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_call), 7);
Harald Welte071ed732018-01-23 19:53:52 +0100695 vc_conn.done;
696}
697
698/* Test LU (with authentication enabled), where HLR times out sending SAI response */
699private function f_tc_lu_auth_sai_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100700 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100701
702 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
703 var PDU_DTAP_MT dtap_mt;
704
705 /* tell GSUP dispatcher to send this IMSI to us */
706 f_create_gsup_expect(hex2str(g_pars.imsi));
707
708 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
709 f_bssap_compl_l3(l3_lu);
710
711 /* Send Early Classmark, just for the fun of it */
712 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
713
714 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
715 /* The HLR would normally return an auth vector here, but we fail to do so. */
716
717 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100718 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100719}
720testcase TC_lu_auth_sai_timeout() runs on MTC_CT {
721 var BSC_ConnHdlr vc_conn;
722 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100723 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100724
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100725 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_timeout), 8);
Harald Welte071ed732018-01-23 19:53:52 +0100726 vc_conn.done;
727}
728
729/* Test LU (with authentication enabled), where HLR rejects sending SAI error */
730private function f_tc_lu_auth_sai_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100731 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100732
733 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
734 var PDU_DTAP_MT dtap_mt;
735
736 /* tell GSUP dispatcher to send this IMSI to us */
737 f_create_gsup_expect(hex2str(g_pars.imsi));
738
739 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
740 f_bssap_compl_l3(l3_lu);
741
742 /* Send Early Classmark, just for the fun of it */
743 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
744
745 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
746 GSUP.send(ts_GSUP_SAI_ERR(g_pars.imsi, 13));
747
748 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100749 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100750}
751testcase TC_lu_auth_sai_err() runs on MTC_CT {
752 var BSC_ConnHdlr vc_conn;
753 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100754 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100755
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100756 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_err), 9);
Harald Welte2bb825f2018-01-22 11:31:18 +0100757 vc_conn.done;
758}
Harald Weltea49e36e2018-01-21 19:29:33 +0100759
Harald Weltebc881782018-01-23 20:09:15 +0100760/* Test LU but BSC will send a clear request in the middle */
761private function f_tc_lu_clear_request(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100762 f_init_handler(pars);
Harald Weltebc881782018-01-23 20:09:15 +0100763
764 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
765 var PDU_DTAP_MT dtap_mt;
766
767 /* tell GSUP dispatcher to send this IMSI to us */
768 f_create_gsup_expect(hex2str(g_pars.imsi));
769
770 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
771 f_bssap_compl_l3(l3_lu);
772
773 /* Send Early Classmark, just for the fun of it */
774 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
775
776 f_sleep(1.0);
777 /* send clear request in the middle of the LU */
778 BSSAP.send(ts_BSSMAP_ClearRequest(0));
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200779 alt {
780 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { repeat; }
781 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {}
782 }
Harald Weltebc881782018-01-23 20:09:15 +0100783 BSSAP.send(ts_BSSMAP_ClearComplete);
Harald Welte89a32492018-01-27 19:07:28 +0100784 alt {
785 /* See https://osmocom.org/issues/2862 */
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200786 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {
787 setverdict(fail, "Got a second Clear Command, only one expected");
Daniel Willmannafce8662018-07-06 23:11:32 +0200788 mtc.stop;
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200789 repeat;
790 }
Harald Welte89a32492018-01-27 19:07:28 +0100791 [] BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
792 }
Harald Weltebc881782018-01-23 20:09:15 +0100793 setverdict(pass);
794}
795testcase TC_lu_clear_request() runs on MTC_CT {
796 var BSC_ConnHdlr vc_conn;
797 f_init();
798
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100799 vc_conn := f_start_handler(refers(f_tc_lu_clear_request), 10);
Harald Weltebc881782018-01-23 20:09:15 +0100800 vc_conn.done;
801}
802
Harald Welte66af9e62018-01-24 17:28:21 +0100803/* Test LU but BSC will send a clear request in the middle */
804private function f_tc_lu_disconnect(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100805 f_init_handler(pars);
Harald Welte66af9e62018-01-24 17:28:21 +0100806
807 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
808 var PDU_DTAP_MT dtap_mt;
809
810 /* tell GSUP dispatcher to send this IMSI to us */
811 f_create_gsup_expect(hex2str(g_pars.imsi));
812
813 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
814 f_bssap_compl_l3(l3_lu);
815
816 /* Send Early Classmark, just for the fun of it */
817 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
818
819 f_sleep(1.0);
820 /* send clear request in the middle of the LU */
821 BSSAP.send(BSSAP_Conn_Prim:MSC_CONN_PRIM_DISC_REQ);
822 setverdict(pass);
823}
824testcase TC_lu_disconnect() runs on MTC_CT {
825 var BSC_ConnHdlr vc_conn;
826 f_init();
827
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100828 vc_conn := f_start_handler(refers(f_tc_lu_disconnect), 11);
Harald Welte66af9e62018-01-24 17:28:21 +0100829 vc_conn.done;
830}
831
832
Harald Welteba7b6d92018-01-23 21:32:34 +0100833/* Test LU but with illegal mobile identity type = IMEI */
834private function f_tc_lu_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100835 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +0100836
Harald Welte256571e2018-01-24 18:47:19 +0100837 var PDU_ML3_MS_NW l3_lu := f_build_lu_imei(g_pars.imei)
Harald Welteba7b6d92018-01-23 21:32:34 +0100838 var PDU_DTAP_MT dtap_mt;
839
840 /* tell GSUP dispatcher to send this IMSI to us */
841 f_create_gsup_expect(hex2str(g_pars.imsi));
842
843 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
844 f_bssap_compl_l3(l3_lu);
845
846 /* Send Early Classmark, just for the fun of it */
847 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
848 /* wait for LU reject, ignore any ID REQ */
849 alt {
850 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { }
851 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req)) { repeat; }
852 }
853 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100854 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +0100855}
856testcase TC_lu_by_imei() runs on MTC_CT {
857 var BSC_ConnHdlr vc_conn;
858 f_init();
859
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100860 vc_conn := f_start_handler(refers(f_tc_lu_by_imei), 12);
Harald Welteba7b6d92018-01-23 21:32:34 +0100861 vc_conn.done;
862}
863
864/* Test LU by TMSI with unknown TMSI, expect (and answer) ID REQ. */
865private function f_tc_lu_tmsi_noauth_unknown(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Stefan Sperling04fc4bc2018-06-25 17:44:57 +0200866 /* We piggyback a test for an MSC crash on overlong IMSI (OS#2864) onto this test. */
867 var hexstring overlong_imsi := '012345789ABCDEF0123456789ABCDEF'H;
Harald Weltea10db902018-01-27 12:44:49 +0100868 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +0100869
870 var PDU_ML3_MS_NW l3_lu := f_build_lu_tmsi('01020304'O); /* FIXME: Random */
871 var PDU_DTAP_MT dtap_mt;
872
873 /* tell GSUP dispatcher to send this IMSI to us */
874 f_create_gsup_expect(hex2str(g_pars.imsi));
875
876 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
877 f_bssap_compl_l3(l3_lu);
878
879 /* Send Early Classmark, just for the fun of it */
880 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
881
882 /* Wait for + respond to ID REQ (IMSI) */
883 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req('001'B)));
Stefan Sperling04fc4bc2018-06-25 17:44:57 +0200884 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(overlong_imsi))); /* test for OS#2864 */
Harald Welteba7b6d92018-01-23 21:32:34 +0100885 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(g_pars.imsi)));
886
887 /* Expect MSC to do UpdateLocation to HLR; respond to it */
888 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
889 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
890 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
891 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
892
893 alt {
Harald Welte7ec4fa82018-01-27 10:57:40 +0100894 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
895 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_TmsiRealloc_Cmpl));
896 }
Harald Welteba7b6d92018-01-23 21:32:34 +0100897 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
898 setverdict(fail, "Expected LU ACK, but received REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200899 mtc.stop;
Harald Welteba7b6d92018-01-23 21:32:34 +0100900 }
901 }
902
Philipp Maier9b690e42018-12-21 11:50:03 +0100903 /* Wait for MM-Information (if enabled) */
904 f_expect_mm_info();
905
Harald Welteba7b6d92018-01-23 21:32:34 +0100906 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100907 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +0100908}
909testcase TC_lu_by_tmsi_noauth_unknown() runs on MTC_CT {
910 var BSC_ConnHdlr vc_conn;
911 f_init();
912
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100913 vc_conn := f_start_handler(refers(f_tc_lu_tmsi_noauth_unknown), 13);
Harald Welteba7b6d92018-01-23 21:32:34 +0100914 vc_conn.done;
915}
916
917
Harald Welte45164da2018-01-24 12:51:27 +0100918/* Test IMSI DETACH (MI=IMSI) */
919private function f_tc_imsi_detach_by_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100920 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +0100921
922 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
923
924 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
925 f_bssap_compl_l3(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
926
927 /* Send Early Classmark, just for the fun of it? */
928 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
929
930 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100931 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +0100932}
933testcase TC_imsi_detach_by_imsi() runs on MTC_CT {
934 var BSC_ConnHdlr vc_conn;
935 f_init();
936
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100937 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imsi), 14);
Harald Welte45164da2018-01-24 12:51:27 +0100938 vc_conn.done;
939}
940
941/* Test IMSI DETACH (MI=TMSI) */
942private function f_tc_imsi_detach_by_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100943 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +0100944
945 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV('01020304'O));
946
947 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
948 f_bssap_compl_l3(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
949
950 /* Send Early Classmark, just for the fun of it? */
951 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
952
953 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100954 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +0100955}
956testcase TC_imsi_detach_by_tmsi() runs on MTC_CT {
957 var BSC_ConnHdlr vc_conn;
958 f_init();
959
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100960 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_tmsi), 15);
Harald Welte45164da2018-01-24 12:51:27 +0100961 vc_conn.done;
962}
963
964/* Test IMSI DETACH (MI=IMEI), which is illegal */
965private function f_tc_imsi_detach_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100966 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +0100967
Harald Welte256571e2018-01-24 18:47:19 +0100968 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte45164da2018-01-24 12:51:27 +0100969
970 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
971 f_bssap_compl_l3(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
972
973 /* Send Early Classmark, just for the fun of it? */
974 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
975
976 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100977 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +0100978}
979testcase TC_imsi_detach_by_imei() runs on MTC_CT {
980 var BSC_ConnHdlr vc_conn;
981 f_init();
982
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100983 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imei), 16);
Harald Welte45164da2018-01-24 12:51:27 +0100984 vc_conn.done;
985}
986
987
988/* helper function for an emergency call. caller passes in mobile identity to use */
989private function f_emerg_call(MobileIdentityLV mi) runs on BSC_ConnHdlr {
Harald Welte0bef21e2018-02-10 09:48:23 +0100990 var CallParameters cpars := valueof(t_CallParams('112'H, 0));
991 cpars.emergency := true;
Philipp Maierf1e02bb2018-03-15 16:30:00 +0100992 cpars.mgcp_ep := "rtpbridge/1@mgw";
Harald Welte45164da2018-01-24 12:51:27 +0100993
Harald Welte0bef21e2018-02-10 09:48:23 +0100994 f_mo_call(cpars);
Harald Welte45164da2018-01-24 12:51:27 +0100995}
996
997/* establish an emergency call by IMEI, no SIM inserted (and hence no IMSI) */
998private function f_tc_emerg_call_imei_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100999 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001000
Harald Welte256571e2018-01-24 18:47:19 +01001001 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001002 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_EMERG_CALL, mi));
Harald Welte45164da2018-01-24 12:51:27 +01001003 f_bssap_compl_l3(l3_info);
1004 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ('05'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +01001005 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001006}
1007testcase TC_emerg_call_imei_reject() runs on MTC_CT {
1008 var BSC_ConnHdlr vc_conn;
1009 f_init();
1010
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001011 vc_conn := f_start_handler(refers(f_tc_emerg_call_imei_reject), 17);
Harald Welte45164da2018-01-24 12:51:27 +01001012 vc_conn.done;
1013}
1014
Harald Welted5b91402018-01-24 18:48:16 +01001015/* establish an emergency call by IMSI, SIM inserted (and hence IMSI) */
Harald Welte45164da2018-01-24 12:51:27 +01001016private function f_tc_emerg_call_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001017 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001018 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001019 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001020 /* Then issue emergency call identified by IMSI */
1021 f_emerg_call(valueof(ts_MI_IMSI_LV(g_pars.imsi)));
1022}
1023testcase TC_emerg_call_imsi() runs on MTC_CT {
1024 var BSC_ConnHdlr vc_conn;
1025 f_init();
1026
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001027 vc_conn := f_start_handler(refers(f_tc_emerg_call_imsi), 18);
Harald Welte45164da2018-01-24 12:51:27 +01001028 vc_conn.done;
1029}
1030
1031/* CM Service Request for VGCS -> reject */
1032private function f_tc_cm_serv_req_vgcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001033 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001034
1035 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001036 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001037
1038 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001039 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VGCS, mi));
Harald Welte45164da2018-01-24 12:51:27 +01001040 f_bssap_compl_l3(l3_info);
1041 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001042 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001043}
1044testcase TC_cm_serv_req_vgcs_reject() runs on MTC_CT {
1045 var BSC_ConnHdlr vc_conn;
1046 f_init();
1047
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001048 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vgcs_reject), 19);
Harald Welte45164da2018-01-24 12:51:27 +01001049 vc_conn.done;
1050}
1051
1052/* CM Service Request for VBS -> reject */
1053private function f_tc_cm_serv_req_vbs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001054 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001055
1056 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001057 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001058
1059 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001060 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VBS, mi));
Harald Welte45164da2018-01-24 12:51:27 +01001061 f_bssap_compl_l3(l3_info);
1062 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001063 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001064}
1065testcase TC_cm_serv_req_vbs_reject() runs on MTC_CT {
1066 var BSC_ConnHdlr vc_conn;
1067 f_init();
1068
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001069 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vbs_reject), 20);
Harald Welte45164da2018-01-24 12:51:27 +01001070 vc_conn.done;
1071}
1072
1073/* CM Service Request for LCS -> reject */
1074private function f_tc_cm_serv_req_lcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001075 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001076
1077 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001078 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001079
1080 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001081 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_LCS, mi));
Harald Welte45164da2018-01-24 12:51:27 +01001082 f_bssap_compl_l3(l3_info);
1083 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001084 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001085}
1086testcase TC_cm_serv_req_lcs_reject() runs on MTC_CT {
1087 var BSC_ConnHdlr vc_conn;
1088 f_init();
1089
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001090 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_lcs_reject), 21);
Harald Welte45164da2018-01-24 12:51:27 +01001091 vc_conn.done;
1092}
1093
Harald Welte0195ab12018-01-24 21:50:20 +01001094/* CM Re-Establishment Request */
1095private function f_tc_cm_reest_req_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001096 f_init_handler(pars);
Harald Welte0195ab12018-01-24 21:50:20 +01001097
1098 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001099 f_perform_lu();
Harald Welte0195ab12018-01-24 21:50:20 +01001100
1101 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1102 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_REEST_REQ(0, mi));
1103 f_bssap_compl_l3(l3_info);
1104 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001105 f_expect_clear();
Harald Welte0195ab12018-01-24 21:50:20 +01001106}
1107testcase TC_cm_reest_req_reject() runs on MTC_CT {
1108 var BSC_ConnHdlr vc_conn;
1109 f_init();
Harald Welte0195ab12018-01-24 21:50:20 +01001110
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001111 vc_conn := f_start_handler(refers(f_tc_cm_reest_req_reject), 22);
Harald Welte0195ab12018-01-24 21:50:20 +01001112 vc_conn.done;
1113}
1114
Harald Weltec638f4d2018-01-24 22:00:36 +01001115/* Test LU (with authentication enabled), with wrong response from MS */
1116private function f_tc_lu_auth_2G_fail(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001117 f_init_handler(pars);
Harald Weltec638f4d2018-01-24 22:00:36 +01001118
1119 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
1120
1121 /* tell GSUP dispatcher to send this IMSI to us */
1122 f_create_gsup_expect(hex2str(g_pars.imsi));
1123
1124 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
1125 f_bssap_compl_l3(l3_lu);
1126
1127 /* Send Early Classmark, just for the fun of it */
1128 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1129
1130 var AuthVector vec := f_gen_auth_vec_2g();
1131 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G(vec.rand, vec.sres, vec.kc));
1132 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
1133 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
1134
1135 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_AUTH_REQ(vec.rand)));
1136 /* Send back wrong auth response */
1137 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MT_MM_AUTH_RESP_2G('00000000'O)));
1138
1139 /* Expect GSUP AUTH FAIL REP to HLR */
1140 GSUP.receive(tr_GSUP_AUTH_FAIL_IND(g_pars.imsi));
1141
1142 /* Expect LU REJECT with Cause == Illegal MS */
1143 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej('03'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +01001144 f_expect_clear();
Harald Weltec638f4d2018-01-24 22:00:36 +01001145}
1146testcase TC_lu_auth_2G_fail() runs on MTC_CT {
1147 var BSC_ConnHdlr vc_conn;
1148 f_init();
1149 f_vty_config(MSCVTY, "network", "authentication required");
Harald Weltec638f4d2018-01-24 22:00:36 +01001150
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001151 vc_conn := f_start_handler(refers(f_tc_lu_auth_2G_fail), 23);
Harald Weltec638f4d2018-01-24 22:00:36 +01001152 vc_conn.done;
1153}
1154
Harald Weltede371492018-01-27 23:44:41 +01001155/* A5/1 + A5/3 permitted on network side, and MS capable to do it */
Harald Welte16114282018-01-24 22:41:21 +01001156private function f_tc_lu_imsi_auth_tmsi_encr_13_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +01001157 pars.net.expect_auth := true;
1158 pars.net.expect_ciph := true;
Harald Weltea10db902018-01-27 12:44:49 +01001159 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001160 f_perform_lu();
Harald Welte16114282018-01-24 22:41:21 +01001161}
1162testcase TC_lu_imsi_auth_tmsi_encr_13_13() runs on MTC_CT {
1163 var BSC_ConnHdlr vc_conn;
1164 f_init();
1165 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte16114282018-01-24 22:41:21 +01001166 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
1167
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001168 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_13), 24);
Harald Welte16114282018-01-24 22:41:21 +01001169 vc_conn.done;
1170}
1171
Harald Welte1af6ea82018-01-25 18:33:15 +01001172/* Test Complete L3 without payload */
1173private function f_tc_cl3_no_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001174 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001175
1176 /* Send Complete L3 Info with empty L3 frame */
1177 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1178 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, ''O))));
1179
Harald Weltef466eb42018-01-27 14:26:54 +01001180 timer T := 5.0;
1181 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001182 alt {
1183 [] BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
1184 /* Expect LU REJECT with Cause == Illegal MS */
Harald Weltebdb3c452018-03-18 22:43:06 +01001185 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
1186 [] BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001187 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001188 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001189 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001190 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001191 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001192 }
1193 setverdict(pass);
1194}
1195testcase TC_cl3_no_payload() runs on MTC_CT {
1196 var BSC_ConnHdlr vc_conn;
1197 f_init();
1198
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001199 vc_conn := f_start_handler(refers(f_tc_cl3_no_payload), 25);
Harald Welte1af6ea82018-01-25 18:33:15 +01001200 vc_conn.done;
1201}
1202
1203/* Test Complete L3 with random payload */
1204private function f_tc_cl3_rnd_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001205 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001206
Daniel Willmannaa14a382018-07-26 08:29:45 +02001207 /* length is limited by PDU_BSSAP length field which includes some
1208 * other fields beside l3info payload. So payl can only be 240 bytes
1209 * Since rnd() returns values < 1 multiply with 241
1210 */
1211 var integer len := float2int(rnd() * 241.0);
Harald Welte1af6ea82018-01-25 18:33:15 +01001212 var octetstring payl := f_rnd_octstring(len);
1213
1214 /* Send Complete L3 Info with empty L3 frame */
1215 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1216 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, payl))));
1217
Harald Weltef466eb42018-01-27 14:26:54 +01001218 timer T := 5.0;
1219 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001220 alt {
1221 /* Immediate disconnect */
1222 [] BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte1af6ea82018-01-25 18:33:15 +01001223 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
Harald Weltebdb3c452018-03-18 22:43:06 +01001224 [] BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001225 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001226 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001227 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001228 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001229 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001230 }
1231 setverdict(pass);
1232}
1233testcase TC_cl3_rnd_payload() runs on MTC_CT {
1234 var BSC_ConnHdlr vc_conn;
1235 f_init();
1236
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001237 vc_conn := f_start_handler(refers(f_tc_cl3_rnd_payload), 26);
Harald Welte1af6ea82018-01-25 18:33:15 +01001238 vc_conn.done;
1239}
1240
Harald Welte116e4332018-01-26 22:17:48 +01001241/* Test Complete L3 with random payload */
1242private function f_tc_establish_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001243 f_init_handler(pars);
Harald Welte116e4332018-01-26 22:17:48 +01001244
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001245 f_perform_lu();
Harald Welte116e4332018-01-26 22:17:48 +01001246
Harald Welteb9e86fa2018-04-09 18:18:31 +02001247 f_establish_fully();
Daniel Willmann898a7e02018-05-17 12:16:16 +02001248 f_expect_clear(10.0);
Harald Welte116e4332018-01-26 22:17:48 +01001249}
1250testcase TC_establish_and_nothing() runs on MTC_CT {
1251 var BSC_ConnHdlr vc_conn;
1252 f_init();
1253
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001254 vc_conn := f_start_handler(refers(f_tc_establish_and_nothing), 27);
Harald Welte116e4332018-01-26 22:17:48 +01001255 vc_conn.done;
1256}
1257
Harald Welte12510c52018-01-26 22:26:24 +01001258/* Test MO Call SETUP with no response from MNCC */
1259private function f_tc_mo_setup_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier109e6aa2018-10-17 10:53:32 +02001260 f_init_handler(pars, 190.0);
Harald Weltea10db902018-01-27 12:44:49 +01001261
Harald Welte12510c52018-01-26 22:26:24 +01001262 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1263
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001264 f_perform_lu();
Harald Welte12510c52018-01-26 22:26:24 +01001265
Harald Welteb9e86fa2018-04-09 18:18:31 +02001266 f_establish_fully();
Harald Welte12510c52018-01-26 22:26:24 +01001267 f_create_mncc_expect(hex2str(cpars.called_party));
1268 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1269
1270 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
1271
Philipp Maier109e6aa2018-10-17 10:53:32 +02001272 f_expect_clear(185.0);
Harald Welte12510c52018-01-26 22:26:24 +01001273}
1274testcase TC_mo_setup_and_nothing() runs on MTC_CT {
1275 var BSC_ConnHdlr vc_conn;
1276 f_init();
1277
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001278 vc_conn := f_start_handler(refers(f_tc_mo_setup_and_nothing), 28);
Harald Welte12510c52018-01-26 22:26:24 +01001279 vc_conn.done;
1280}
1281
Harald Welte3ab88002018-01-26 22:37:25 +01001282/* Test MO Call with no response to RAN-side CRCX */
1283private function f_tc_mo_crcx_ran_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001284 f_init_handler(pars);
Harald Welte3ab88002018-01-26 22:37:25 +01001285 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1286 var MNCC_PDU mncc;
1287 var MgcpCommand mgcp_cmd;
1288
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001289 f_perform_lu();
Harald Welte3ab88002018-01-26 22:37:25 +01001290
Harald Welteb9e86fa2018-04-09 18:18:31 +02001291 f_establish_fully();
Harald Welte3ab88002018-01-26 22:37:25 +01001292 f_create_mncc_expect(hex2str(cpars.called_party));
1293 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1294
1295 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
1296 MNCC.receive(tr_MNCC_SETUP_ind(?, tr_MNCC_number(hex2str(cpars.called_party)))) -> value mncc;
1297 cpars.mncc_callref := mncc.u.signal.callref;
1298 MNCC.send(ts_MNCC_CALL_PROC_req(cpars.mncc_callref, cpars.mncc_bearer_cap));
1299 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_CALL_PROC(cpars.transaction_id)));
1300
1301 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
Harald Welte1852a842018-01-26 22:53:36 +01001302 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
1303 cpars.mgcp_ep := mgcp_cmd.line.ep;
Harald Welte3ab88002018-01-26 22:37:25 +01001304 /* never respond to this */
1305
Philipp Maier8e58f592018-03-14 11:10:56 +01001306 /* When the connection with the MGW fails, the MSC will first request
1307 * a release via call control. We will answer this request normally. */
1308 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id)));
1309 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id)));
1310
Harald Welte1ddc7162018-01-27 14:25:46 +01001311 f_expect_clear(30.0);
Harald Welte3ab88002018-01-26 22:37:25 +01001312}
1313testcase TC_mo_crcx_ran_timeout() runs on MTC_CT {
1314 var BSC_ConnHdlr vc_conn;
1315 f_init();
1316
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001317 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_timeout), 29);
Harald Welte3ab88002018-01-26 22:37:25 +01001318 vc_conn.done;
1319}
1320
Harald Welte0cc82d92018-01-26 22:52:34 +01001321/* Test MO Call with reject to RAN-side CRCX */
1322private function f_tc_mo_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001323 f_init_handler(pars);
Harald Welte0cc82d92018-01-26 22:52:34 +01001324 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1325 var MNCC_PDU mncc;
1326 var MgcpCommand mgcp_cmd;
1327
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001328 f_perform_lu();
Harald Welte0cc82d92018-01-26 22:52:34 +01001329
Harald Welteb9e86fa2018-04-09 18:18:31 +02001330 f_establish_fully();
Harald Welte0cc82d92018-01-26 22:52:34 +01001331 f_create_mncc_expect(hex2str(cpars.called_party));
1332 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1333
1334 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
1335 MNCC.receive(tr_MNCC_SETUP_ind(?, tr_MNCC_number(hex2str(cpars.called_party)))) -> value mncc;
1336 cpars.mncc_callref := mncc.u.signal.callref;
1337 MNCC.send(ts_MNCC_CALL_PROC_req(cpars.mncc_callref, cpars.mncc_bearer_cap));
1338 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_CALL_PROC(cpars.transaction_id)));
1339
1340 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001341
1342 /* Detect if the received CRCX is a wildcarded CRCX request. If yes,
1343 * set an endpoint name that fits the pattern. If not, just use the
1344 * endpoint name from the request */
1345 if (match(mgcp_cmd.line.ep, t_MGCP_EP_wildcard)) {
1346 cpars.mgcp_ep := "rtpbridge/1@mgw";
1347 } else {
1348 cpars.mgcp_ep := mgcp_cmd.line.ep;
1349 }
1350
Harald Welte0cc82d92018-01-26 22:52:34 +01001351 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001352
Harald Welte0cc82d92018-01-26 22:52:34 +01001353 /* Respond to CRCX with error */
1354 var MgcpResponse mgcp_rsp := {
1355 line := {
1356 code := "542",
1357 trans_id := mgcp_cmd.line.trans_id,
1358 string := "FORCED_FAIL"
1359 },
Harald Welte0cc82d92018-01-26 22:52:34 +01001360 sdp := omit
1361 }
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001362 var MgcpParameter mgcp_rsp_param := {
1363 code := "Z",
1364 val := cpars.mgcp_ep
1365 };
1366 mgcp_rsp.params[0] := mgcp_rsp_param;
Harald Welte0cc82d92018-01-26 22:52:34 +01001367 MGCP.send(mgcp_rsp);
1368
1369 timer T := 30.0;
1370 T.start;
1371 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001372 [] T.timeout {
1373 setverdict(fail, "Timeout waiting for channel release");
1374 mtc.stop;
1375 }
Daniel Willmann5868e622018-02-15 17:42:59 +01001376 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id))) {
1377 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id)));
1378 repeat;
1379 }
Harald Welte0cc82d92018-01-26 22:52:34 +01001380 [] MNCC.receive { repeat; }
1381 [] GSUP.receive { repeat; }
Philipp Maierc6e06f72018-04-11 18:12:23 +02001382 /* Note: As we did not respond properly to the CRCX from the MSC we
1383 * expect the MSC to omit any further MGCP operation (At least in the
1384 * the current implementation, there is no recovery mechanism implemented
1385 * and a DLCX can not be performed as the MSC does not know a specific
1386 * endpoint yet. */
Daniel Willmannafce8662018-07-06 23:11:32 +02001387 [] MGCP.receive {
1388 setverdict(fail, "Unexpected MGCP message");
1389 mtc.stop;
1390 }
Harald Welte5946b332018-03-18 23:32:21 +01001391 [] as_clear_cmd_compl_disc();
Harald Welte0cc82d92018-01-26 22:52:34 +01001392 }
1393}
1394testcase TC_mo_crcx_ran_reject() runs on MTC_CT {
1395 var BSC_ConnHdlr vc_conn;
1396 f_init();
1397
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001398 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_reject), 30);
Harald Welte0cc82d92018-01-26 22:52:34 +01001399 vc_conn.done;
1400}
1401
Harald Welte3ab88002018-01-26 22:37:25 +01001402
Harald Welte812f7a42018-01-27 00:49:18 +01001403/* helper function to start a MT call: MNCC SETUP; Paging; DChan est.; DTAP SETUP */
1404private function f_mt_call_start(inout CallParameters cpars) runs on BSC_ConnHdlr {
1405 var MNCC_PDU mncc;
1406 var MgcpCommand mgcp_cmd;
1407 var OCT4 tmsi;
1408
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001409 f_perform_lu();
Harald Welte812f7a42018-01-27 00:49:18 +01001410 if (isvalue(g_pars.tmsi)) {
1411 tmsi := g_pars.tmsi;
1412 } else {
1413 tmsi := 'FFFFFFFF'O;
1414 }
1415 f_bssmap_register_imsi(g_pars.imsi, tmsi);
1416
1417 /* Allocate call reference and send SETUP via MNCC to MSC */
1418 cpars.mncc_callref := f_rnd_int(2147483648);
1419 MNCC.send(ts_MNCC_SETUP_req(cpars.mncc_callref, hex2str(g_pars.msisdn),
1420 hex2str(cpars.called_party), hex2str(g_pars.imsi)));
1421
1422 /* MSC->BSC: expect PAGING from MSC */
1423 BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi));
1424 /* MS -> MSC: PAGING RESPONSE */
Harald Welteb9e86fa2018-04-09 18:18:31 +02001425 f_establish_fully(EST_TYPE_PAG_RESP);
Harald Welte812f7a42018-01-27 00:49:18 +01001426
1427 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1428
1429 /* MSC->MS: SETUP */
1430 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_SETUP(cpars.transaction_id, *, cpars.called_party)));
1431}
1432
1433/* Test MT Call */
1434private function f_tc_mt_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001435 f_init_handler(pars);
Harald Welte812f7a42018-01-27 00:49:18 +01001436 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1437 var MNCC_PDU mncc;
1438 var MgcpCommand mgcp_cmd;
1439
1440 f_mt_call_start(cpars);
1441
1442 /* MS->MSC: CALL CONFIRMED */
1443 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1444
1445 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1446
1447 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1448 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001449
1450 /* Detect if the received CRCX is a wildcarded CRCX request. If yes,
1451 * set an endpoint name that fits the pattern. If not, just use the
1452 * endpoint name from the request */
1453 if (match(mgcp_cmd.line.ep, t_MGCP_EP_wildcard)) {
1454 cpars.mgcp_ep := "rtpbridge/1@mgw";
1455 } else {
1456 cpars.mgcp_ep := mgcp_cmd.line.ep;
1457 }
1458
Harald Welte812f7a42018-01-27 00:49:18 +01001459 /* Respond to CRCX with error */
1460 var MgcpResponse mgcp_rsp := {
1461 line := {
1462 code := "542",
1463 trans_id := mgcp_cmd.line.trans_id,
1464 string := "FORCED_FAIL"
1465 },
Harald Welte812f7a42018-01-27 00:49:18 +01001466 sdp := omit
1467 }
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001468 var MgcpParameter mgcp_rsp_param := {
1469 code := "Z",
1470 val := cpars.mgcp_ep
1471 };
1472 mgcp_rsp.params[0] := mgcp_rsp_param;
Harald Welte812f7a42018-01-27 00:49:18 +01001473 MGCP.send(mgcp_rsp);
1474
1475 timer T := 30.0;
1476 T.start;
1477 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001478 [] T.timeout {
1479 setverdict(fail, "Timeout waiting for channel release");
1480 mtc.stop;
1481 }
Harald Welte812f7a42018-01-27 00:49:18 +01001482 [] BSSAP.receive { repeat; }
1483 [] MNCC.receive { repeat; }
1484 [] GSUP.receive { repeat; }
1485 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1486 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
1487 f_create_mgcp_delete_ep(cpars.mgcp_ep);
1488 repeat;
1489 }
1490 [] MGCP.receive { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001491 [] as_clear_cmd_compl_disc();
Harald Welte812f7a42018-01-27 00:49:18 +01001492 }
1493}
1494testcase TC_mt_crcx_ran_reject() runs on MTC_CT {
1495 var BSC_ConnHdlr vc_conn;
1496 f_init();
1497
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001498 vc_conn := f_start_handler(refers(f_tc_mt_crcx_ran_reject), 31);
Harald Welte812f7a42018-01-27 00:49:18 +01001499 vc_conn.done;
1500}
1501
1502
1503/* Test MT Call T310 timer */
1504private function f_tc_mt_t310(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltead2952e2018-01-27 14:12:46 +01001505 f_init_handler(pars, 200.0);
Harald Welte812f7a42018-01-27 00:49:18 +01001506 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1507 var MNCC_PDU mncc;
1508 var MgcpCommand mgcp_cmd;
1509
1510 f_mt_call_start(cpars);
1511
1512 /* MS->MSC: CALL CONFIRMED */
1513 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1514 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1515
1516 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1517 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
1518 cpars.mgcp_ep := mgcp_cmd.line.ep;
1519 /* FIXME: Respond to CRCX */
1520
1521 /* old libosmocore T310 default timeout is 180s. so let's wait 190 */
1522 timer T := 190.0;
1523 T.start;
1524 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001525 [] T.timeout {
1526 setverdict(fail, "Timeout waiting for T310");
1527 mtc.stop;
1528 }
Harald Welte812f7a42018-01-27 00:49:18 +01001529 [] MNCC.receive(tr_MNCC_DISC_ind(cpars.mncc_callref)) {
1530 MNCC.send(ts_MNCC_REL_req(cpars.mncc_callref, valueof(ts_MNCC_cause(23))));
1531 }
1532 }
1533 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_DISC(cpars.transaction_id)));
1534 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id)));
1535 /* FIXME: We're sending this with TIflag 0: allocated by sender, which is wrong */
1536 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id)));
1537
1538 alt {
Harald Welte812f7a42018-01-27 00:49:18 +01001539 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1540 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
1541 f_create_mgcp_delete_ep(cpars.mgcp_ep);
1542 repeat;
1543 }
Harald Welte5946b332018-03-18 23:32:21 +01001544 [] as_clear_cmd_compl_disc();
Harald Welte812f7a42018-01-27 00:49:18 +01001545 }
1546}
1547testcase TC_mt_t310() runs on MTC_CT {
1548 var BSC_ConnHdlr vc_conn;
1549 f_init();
1550
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001551 vc_conn := f_start_handler(refers(f_tc_mt_t310), 32);
Harald Welte812f7a42018-01-27 00:49:18 +01001552 vc_conn.done;
1553}
1554
Harald Welte167458a2018-01-27 15:58:16 +01001555/* Perform successful LU + MO call, then GSUP LocationCancel. Subscriber must be denied CM SERV */
1556private function f_tc_gsup_cancel(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1557 f_init_handler(pars);
1558 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1559 cpars.bss_rtp_port := 1110;
1560 cpars.mgcp_connection_id_bss := '22222'H;
1561 cpars.mgcp_connection_id_mss := '33333'H;
Daniel Willmann9b0235b2018-07-24 12:13:34 +02001562 cpars.mgcp_ep := "rtpbridge/1@mgw";
Harald Welte167458a2018-01-27 15:58:16 +01001563
1564 /* Location Update to make subscriber known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001565 f_perform_lu();
Harald Welte167458a2018-01-27 15:58:16 +01001566
1567 /* First MO call should succeed */
1568 f_mo_call(cpars);
1569
1570 /* Cancel the subscriber in the VLR */
1571 GSUP.send(ts_GSUP_CL_REQ(g_pars.imsi, OSMO_GSUP_CANCEL_TYPE_WITHDRAW));
1572 alt {
1573 [] GSUP.receive(tr_GSUP_CL_RES(g_pars.imsi)) { }
1574 [] GSUP.receive(tr_GSUP_CL_ERR(g_pars.imsi)) {
1575 setverdict(fail, "Received GSUP Location Cancel Error");
Daniel Willmannafce8662018-07-06 23:11:32 +02001576 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001577 }
1578 }
1579
1580 /* Follow-up transactions should fail */
1581 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1582 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
1583 f_bssap_compl_l3(l3_info);
1584 alt {
1585 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
1586 [] BSSAP.receive {
1587 setverdict(fail, "Received unexpected BSSAP instead of CM SERV REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +02001588 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001589 }
1590 }
1591 setverdict(pass);
1592}
1593testcase TC_gsup_cancel() runs on MTC_CT {
1594 var BSC_ConnHdlr vc_conn;
1595 f_init();
1596
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001597 vc_conn := f_start_handler(refers(f_tc_gsup_cancel), 33);
Harald Welte167458a2018-01-27 15:58:16 +01001598 vc_conn.done;
1599}
1600
Harald Welte9de84792018-01-28 01:06:35 +01001601/* A5/1 only permitted on network side, and MS capable to do it */
1602private function f_tc_lu_imsi_auth_tmsi_encr_1_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1603 pars.net.expect_auth := true;
1604 pars.net.expect_ciph := true;
1605 pars.net.kc_support := '02'O; /* A5/1 only */
1606 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001607 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001608}
1609testcase TC_lu_imsi_auth_tmsi_encr_1_13() runs on MTC_CT {
1610 var BSC_ConnHdlr vc_conn;
1611 f_init();
1612 f_vty_config(MSCVTY, "network", "authentication required");
1613 f_vty_config(MSCVTY, "network", "encryption a5 1");
1614
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001615 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_1_13), 34);
Harald Welte9de84792018-01-28 01:06:35 +01001616 vc_conn.done;
1617}
1618
1619/* A5/3 only permitted on network side, and MS capable to do it */
1620private function f_tc_lu_imsi_auth_tmsi_encr_3_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1621 pars.net.expect_auth := true;
1622 pars.net.expect_ciph := true;
1623 pars.net.kc_support := '08'O; /* A5/3 only */
1624 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001625 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001626}
1627testcase TC_lu_imsi_auth_tmsi_encr_3_13() runs on MTC_CT {
1628 var BSC_ConnHdlr vc_conn;
1629 f_init();
1630 f_vty_config(MSCVTY, "network", "authentication required");
1631 f_vty_config(MSCVTY, "network", "encryption a5 3");
1632
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001633 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_13), 35);
Harald Welte9de84792018-01-28 01:06:35 +01001634 vc_conn.done;
1635}
1636
1637/* A5/3 only permitted on network side, and MS with only A5/1 support */
1638private function f_tc_lu_imsi_auth_tmsi_encr_3_1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1639 pars.net.expect_auth := true;
1640 pars.net.expect_ciph := true;
1641 pars.net.kc_support := '08'O; /* A5/3 only */
1642 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1643 f_init_handler(pars, 15.0);
1644
1645 /* cannot use f_perform_lu() as we expect a reject */
1646 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
1647 f_create_gsup_expect(hex2str(g_pars.imsi));
1648 f_bssap_compl_l3(l3_lu);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001649 if (pars.send_early_cm) {
1650 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1651 } else {
1652 pars.cm1.esind := '0'B;
1653 }
Harald Welte9de84792018-01-28 01:06:35 +01001654 f_mm_auth();
1655 alt {
Daniel Willmann52918e52018-09-20 14:39:09 +02001656 [] BSSAP.receive(tr_BSSMAP_ClassmarkReq) {
1657 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1658 repeat;
1659 }
Harald Welte5946b332018-03-18 23:32:21 +01001660 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1661 f_expect_clear();
1662 }
Harald Welte9de84792018-01-28 01:06:35 +01001663 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
1664 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02001665 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001666 }
1667 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01001668 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02001669 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001670 }
1671 }
1672 setverdict(pass);
1673}
1674testcase TC_lu_imsi_auth_tmsi_encr_3_1() runs on MTC_CT {
1675 var BSC_ConnHdlr vc_conn;
1676 f_init();
1677 f_vty_config(MSCVTY, "network", "authentication required");
1678 f_vty_config(MSCVTY, "network", "encryption a5 3");
1679
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001680 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 360);
1681 vc_conn.done;
1682}
1683testcase TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() runs on MTC_CT {
1684 var BSC_ConnHdlrPars pars;
1685 var BSC_ConnHdlr vc_conn;
1686 f_init();
1687 f_vty_config(MSCVTY, "network", "authentication required");
1688 f_vty_config(MSCVTY, "network", "encryption a5 3");
1689
1690 pars := f_init_pars(361);
1691 pars.send_early_cm := false;
1692 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), pars);
Harald Welte9de84792018-01-28 01:06:35 +01001693 vc_conn.done;
1694}
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01001695testcase TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() runs on MTC_CT {
1696 var BSC_ConnHdlr vc_conn;
1697 f_init();
1698 f_vty_config(MSCVTY, "network", "authentication required");
1699 f_vty_config(MSCVTY, "network", "encryption a5 3");
1700
1701 /* Make sure the MSC category is on DEBUG level to trigger the log
1702 * message that is reported in OS#2947 to trigger the segfault */
1703 f_vty_config(MSCVTY, "log stderr", "logging level msc debug");
1704
1705 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 362);
1706 vc_conn.done;
1707}
Harald Welte9de84792018-01-28 01:06:35 +01001708
1709/* A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
1710private function f_tc_lu_imsi_auth_tmsi_encr_13_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1711 pars.net.expect_auth := true;
1712 pars.net.expect_ciph := true;
1713 pars.net.kc_support := '0A'O; /* A5/1 + A5/3 */
1714 pars.cm1.a5_1 := '1'B;
1715 pars.cm2.a5_1 := '1'B;
1716 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1717 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
1718 f_init_handler(pars, 15.0);
1719
1720 /* cannot use f_perform_lu() as we expect a reject */
1721 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
1722 f_create_gsup_expect(hex2str(g_pars.imsi));
1723 f_bssap_compl_l3(l3_lu);
1724 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1725 f_mm_auth();
1726 alt {
Harald Welte5946b332018-03-18 23:32:21 +01001727 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1728 f_expect_clear();
1729 }
Harald Welte9de84792018-01-28 01:06:35 +01001730 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
1731 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02001732 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001733 }
1734 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01001735 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02001736 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001737 }
1738 }
1739 setverdict(pass);
1740}
1741testcase TC_lu_imsi_auth_tmsi_encr_13_2() runs on MTC_CT {
1742 var BSC_ConnHdlr vc_conn;
1743 f_init();
1744 f_vty_config(MSCVTY, "network", "authentication required");
1745 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
1746
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001747 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_2), 37);
Harald Welte9de84792018-01-28 01:06:35 +01001748 vc_conn.done;
1749}
1750
1751/* A5/0 + A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
1752private function f_tc_lu_imsi_auth_tmsi_encr_013_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1753 pars.net.expect_auth := true;
1754 pars.net.expect_ciph := true;
1755 pars.net.kc_support := '0B'O; /* A5/1 + A5/3 */
1756 pars.cm1.a5_1 := '1'B;
1757 pars.cm2.a5_1 := '1'B;
1758 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1759 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
1760 f_init_handler(pars, 15.0);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001761 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001762}
1763testcase TC_lu_imsi_auth_tmsi_encr_013_2() runs on MTC_CT {
1764 var BSC_ConnHdlr vc_conn;
1765 f_init();
1766 f_vty_config(MSCVTY, "network", "authentication required");
1767 f_vty_config(MSCVTY, "network", "encryption a5 0 1 3");
1768
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001769 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_013_2), 38);
Harald Welte9de84792018-01-28 01:06:35 +01001770 vc_conn.done;
1771}
1772
Harald Welte33ec09b2018-02-10 15:34:46 +01001773/* LU followed by MT call (including paging) */
1774private function f_tc_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1775 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01001776 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Harald Welte33ec09b2018-02-10 15:34:46 +01001777 cpars.bss_rtp_port := 1110;
1778 cpars.mgcp_connection_id_bss := '10004'H;
1779 cpars.mgcp_connection_id_mss := '10005'H;
1780
Philipp Maier4b2692d2018-03-14 16:37:48 +01001781 /* Note: This is an optional parameter. When the call-agent (MSC) does
1782 * supply a full endpoint name this setting will be overwritten. */
1783 cpars.mgcp_ep := "rtpbridge/1@mgw";
1784
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001785 f_perform_lu();
Harald Welte33ec09b2018-02-10 15:34:46 +01001786 f_mt_call(cpars);
1787}
1788testcase TC_lu_and_mt_call() runs on MTC_CT {
1789 var BSC_ConnHdlr vc_conn;
1790 f_init();
1791
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001792 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call), 39);
Harald Welte33ec09b2018-02-10 15:34:46 +01001793 vc_conn.done;
1794}
1795
Daniel Willmann8b084372018-02-04 13:35:26 +01001796/* Test MO Call SETUP with DTMF */
1797private function f_tc_mo_setup_dtmf_dup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1798 f_init_handler(pars);
1799 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1800 cpars.bss_rtp_port := 1110;
1801 cpars.mgcp_connection_id_bss := '22222'H;
1802 cpars.mgcp_connection_id_mss := '33333'H;
1803
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001804 f_perform_lu();
Daniel Willmann8b084372018-02-04 13:35:26 +01001805 f_mo_seq_dtmf_dup(cpars);
1806}
1807testcase TC_mo_setup_and_dtmf_dup() runs on MTC_CT {
1808 var BSC_ConnHdlr vc_conn;
1809 f_init();
1810
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001811 vc_conn := f_start_handler(refers(f_tc_mo_setup_dtmf_dup), 39);
Daniel Willmann8b084372018-02-04 13:35:26 +01001812 vc_conn.done;
1813}
Harald Welte9de84792018-01-28 01:06:35 +01001814
Philipp Maier328d1662018-03-07 10:40:27 +01001815testcase TC_cr_before_reset() runs on MTC_CT {
1816 timer T := 4.0;
1817 var boolean reset_ack_seen := false;
1818 f_init_bssap_direct();
1819
Daniel Willmann42d1d5b2018-08-07 15:18:41 +02001820 f_bssap_start(g_bssap[0]);
1821
Daniel Willmanne8018962018-08-21 14:18:00 +02001822 f_sleep(3.0);
1823
Philipp Maier328d1662018-03-07 10:40:27 +01001824 /* Make a blind connection attemt, to trigger the deadlock condition */
Philipp Maier75932982018-03-27 14:52:35 +02001825 BSSAP_DIRECT.send(ts_BSSAP_CONNECT_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, 1, omit));
Philipp Maier328d1662018-03-07 10:40:27 +01001826
1827 /* Send a BSSMAP reset */
Philipp Maier75932982018-03-27 14:52:35 +02001828 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_Reset(0)));
Philipp Maier328d1662018-03-07 10:40:27 +01001829 T.start
1830 alt {
1831 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_ResetAck)) {
1832 reset_ack_seen := true;
1833 repeat;
1834 }
1835
1836 /* Acknowledge MSC sided reset requests */
1837 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_Reset)) {
Philipp Maier75932982018-03-27 14:52:35 +02001838 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_ResetAck));
Philipp Maier328d1662018-03-07 10:40:27 +01001839 repeat;
1840 }
1841
1842 /* Ignore all other messages (e.g CR from the connection request) */
1843 [] BSSAP_DIRECT.receive { repeat }
1844
1845 /* If we got no BSSMAP RESET ACK back, then the MSC entered the
1846 * deadlock situation. The MSC is then unable to respond to any
1847 * further BSSMAP RESET or any other sort of traffic. */
1848 [reset_ack_seen == true] T.timeout { setverdict(pass) }
1849 [reset_ack_seen == false] T.timeout {
1850 setverdict(fail, "no BSSMAP RESET ACK seen!");
Daniel Willmannafce8662018-07-06 23:11:32 +02001851 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +01001852 }
1853 }
1854}
Harald Welte9de84792018-01-28 01:06:35 +01001855
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001856/* Test MO Call with no response to RAN-side CRCX or DTAP Release */
1857private function f_tc_mo_release_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1858 f_init_handler(pars);
1859 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1860 var MNCC_PDU mncc;
1861 var MgcpCommand mgcp_cmd;
1862
1863 f_perform_lu();
1864
Harald Welteb9e86fa2018-04-09 18:18:31 +02001865 f_establish_fully();
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001866 f_create_mncc_expect(hex2str(cpars.called_party));
1867 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1868
1869 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
1870 MNCC.receive(tr_MNCC_SETUP_ind(?, tr_MNCC_number(hex2str(cpars.called_party)))) -> value mncc;
1871 cpars.mncc_callref := mncc.u.signal.callref;
1872 MNCC.send(ts_MNCC_CALL_PROC_req(cpars.mncc_callref, cpars.mncc_bearer_cap));
1873 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_CALL_PROC(cpars.transaction_id)));
1874
1875 /* Drop CRCX */
1876 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1877
1878 /* Drop DTAP Release */
1879 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id)));
1880
1881 /* Drop resent DTAP Release */
1882 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id)));
1883
1884 f_expect_clear(60.0);
1885}
1886testcase TC_mo_release_timeout() runs on MTC_CT {
1887 var BSC_ConnHdlr vc_conn;
1888 f_init();
1889
1890 vc_conn := f_start_handler(refers(f_tc_mo_release_timeout), 40);
1891 vc_conn.done;
1892}
1893
Harald Welte12510c52018-01-26 22:26:24 +01001894
Philipp Maier2a98a732018-03-19 16:06:12 +01001895/* LU followed by MT call (including paging) */
1896private function f_tc_lu_and_mt_call_no_dlcx_resp(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1897 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01001898 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Philipp Maier2a98a732018-03-19 16:06:12 +01001899 cpars.bss_rtp_port := 1110;
1900 cpars.mgcp_connection_id_bss := '10004'H;
1901 cpars.mgcp_connection_id_mss := '10005'H;
1902
1903 /* Note: This is an optional parameter. When the call-agent (MSC) does
1904 * supply a full endpoint name this setting will be overwritten. */
1905 cpars.mgcp_ep := "rtpbridge/1@mgw";
1906
1907 /* Intentionally disable the CRCX response */
1908 cpars.mgw_drop_dlcx := true;
1909
1910 /* Perform location update and call */
1911 f_perform_lu();
1912 f_mt_call(cpars);
1913}
1914testcase TC_lu_and_mt_call_no_dlcx_resp() runs on MTC_CT {
1915 var BSC_ConnHdlr vc_conn;
1916 f_init();
1917
1918 /* Perform an almost normal looking locationupdate + mt-call, but do
1919 * not respond to the DLCX at the end of the call */
1920 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call_no_dlcx_resp), 41);
1921 vc_conn.done;
1922
1923 /* Wait a guard period until the MGCP layer in the MSC times out,
1924 * if the MSC is vulnerable to the use-after-free situation that is
1925 * fixed by I78f1b6a9149488a4ad3f120c1e190a83c07d4b89 then it should
1926 * segfault now */
1927 f_sleep(6.0);
1928
1929 /* Run the init procedures once more. If the MSC has crashed, this
1930 * this will fail */
1931 f_init();
1932}
Harald Welte45164da2018-01-24 12:51:27 +01001933
Philipp Maier75932982018-03-27 14:52:35 +02001934/* Two BSSMAP resets from two different BSCs */
1935testcase TC_reset_two() runs on MTC_CT {
1936 var BSC_ConnHdlr vc_conn;
1937 f_init(2);
1938 f_sleep(2.0);
1939 setverdict(pass);
1940}
1941
Harald Weltef640a012018-04-14 17:49:21 +02001942/***********************************************************************
1943 * SMS Testing
1944 ***********************************************************************/
1945
Harald Weltef45efeb2018-04-09 18:19:24 +02001946/* LU followed by MO SMS */
1947private function f_tc_lu_and_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1948 var SmsParameters spars := valueof(t_SmsPars);
1949
1950 f_init_handler(pars);
1951
1952 /* Perform location update and call */
1953 f_perform_lu();
1954
1955 f_establish_fully(EST_TYPE_MO_SMS);
1956
1957 //spars.exp_rp_err := 96; /* invalid mandatory information */
1958 f_mo_sms(spars);
1959
1960 f_expect_clear();
1961}
1962testcase TC_lu_and_mo_sms() runs on MTC_CT {
1963 var BSC_ConnHdlr vc_conn;
1964 f_init();
1965 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_sms), 42);
1966 vc_conn.done;
1967}
1968
1969private function f_vty_sms_send(charstring imsi, charstring msisdn, charstring text)
1970runs on MTC_CT {
1971 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
1972}
1973
1974/* LU followed by MT SMS */
1975private function f_tc_lu_and_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1976 var SmsParameters spars := valueof(t_SmsPars);
1977 var OCT4 tmsi;
1978
1979 f_init_handler(pars);
1980
1981 /* Perform location update and call */
1982 f_perform_lu();
1983
1984 /* register an 'expect' for given IMSI (+TMSI) */
1985 if (isvalue(g_pars.tmsi)) {
1986 tmsi := g_pars.tmsi;
1987 } else {
1988 tmsi := 'FFFFFFFF'O;
1989 }
1990 f_bssmap_register_imsi(g_pars.imsi, tmsi);
1991
1992 /* FIXME: actually cause MSC to send a SMS via VTY or SMPP */
1993
1994 /* MSC->BSC: expect PAGING from MSC */
1995 BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi));
1996 /* Establish DTAP / BSSAP / SCCP connection */
1997 f_establish_fully(EST_TYPE_PAG_RESP);
1998
1999 spars.tp.ud := 'C8329BFD064D9B53'O;
2000 f_mt_sms(spars);
2001
2002 f_expect_clear();
2003}
2004testcase TC_lu_and_mt_sms() runs on MTC_CT {
2005 var BSC_ConnHdlrPars pars;
2006 var BSC_ConnHdlr vc_conn;
2007 f_init();
2008 pars := f_init_pars(43);
2009 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms), pars);
2010 f_sleep(2.0);
2011 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2012 vc_conn.done;
2013}
2014
Philipp Maier3983e702018-11-22 19:01:33 +01002015/* Paging for MT SMS but no response */
2016private function f_tc_lu_and_mt_sms_paging_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2017 var SmsParameters spars := valueof(t_SmsPars);
2018 var OCT4 tmsi;
2019 var integer page_count := 0;
2020 f_init_handler(pars, 150.0);
2021
2022 /* Perform location update */
2023 f_perform_lu();
2024
2025 /* register an 'expect' for given IMSI (+TMSI) */
2026 if (isvalue(g_pars.tmsi)) {
2027 tmsi := g_pars.tmsi;
2028 } else {
2029 tmsi := 'FFFFFFFF'O;
2030 }
2031 f_bssmap_register_imsi(g_pars.imsi, tmsi);
2032
2033 /* Expect the MSC to page exactly 10 times before giving up */
2034 alt {
2035 [] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi))
2036 {
2037 page_count := page_count + 1;
2038
2039 if (page_count < 10) {
2040 repeat;
2041 }
2042 }
2043 [] BSSAP.receive {
2044 setverdict(fail, "unexpected BSSAP message received");
2045 self.stop;
2046 }
2047 }
2048
2049 /* Wait some time to make sure the MSC is not delivering any further
2050 * paging messages or anything else that could be unexpected. */
2051 timer T := 20.0;
2052 T.start
2053 alt {
2054 [] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi))
2055 {
2056 setverdict(fail, "paging seems not to stop!");
2057 mtc.stop;
2058 }
2059 [] BSSAP.receive {
2060 setverdict(fail, "unexpected BSSAP message received");
2061 self.stop;
2062 }
2063 [] T.timeout {
2064 setverdict(pass);
2065 }
2066 }
2067
2068 setverdict(pass);
2069}
2070testcase TC_lu_and_mt_sms_paging_and_nothing() runs on MTC_CT {
2071 var BSC_ConnHdlrPars pars;
2072 var BSC_ConnHdlr vc_conn;
2073 f_init();
Philipp Maiera99ad262019-01-22 15:35:42 +01002074 pars := f_init_pars(1843);
Philipp Maier3983e702018-11-22 19:01:33 +01002075 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_paging_and_nothing), pars);
2076 f_sleep(2.0);
2077 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2078 vc_conn.done;
2079}
2080
Harald Weltef640a012018-04-14 17:49:21 +02002081/* mobile originated SMS from MS/BTS/BSC side to SMPP */
2082private function f_tc_smpp_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2083 var SmsParameters spars := valueof(t_SmsPars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002084
Harald Weltef640a012018-04-14 17:49:21 +02002085 f_init_handler(pars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002086
Harald Weltef640a012018-04-14 17:49:21 +02002087 /* Perform location update so IMSI is known + registered in MSC/VLR */
2088 f_perform_lu();
2089 f_establish_fully(EST_TYPE_MO_SMS);
2090
2091 f_mo_sms(spars);
2092
2093 var SMPP_PDU smpp;
2094 var template SMPP_PDU tr_smpp := tr_SMPP(c_SMPP_command_id_deliver_sm, ESME_ROK);
2095 tr_smpp.body.deliver_sm := {
2096 service_type := "CMT",
2097 source_addr_ton := network_specific,
2098 source_addr_npi := isdn,
2099 source_addr := hex2str(pars.msisdn),
2100 dest_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
2101 dest_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
2102 destination_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
2103 esm_class := '00000001'B,
2104 protocol_id := 0,
2105 priority_flag := 0,
2106 schedule_delivery_time := "",
2107 replace_if_present := 0,
2108 data_coding := '00000001'B,
2109 sm_default_msg_id := 0,
2110 sm_length := ?,
2111 short_message := spars.tp.ud,
2112 opt_pars := {
2113 {
2114 tag := user_message_reference,
2115 len := 2,
2116 opt_value := {
2117 int2_val := oct2int(spars.tp.msg_ref)
2118 }
2119 }
2120 }
2121 };
2122 alt {
2123 [] SMPP.receive(tr_smpp) -> value smpp {
2124 SMPP.send(ts_SMPP_DELIVER_SM_resp(ESME_ROK, smpp.header.seq_num));
2125 }
2126 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK)) { repeat; }
2127 }
2128
2129 f_expect_clear();
2130}
2131testcase TC_smpp_mo_sms() runs on MTC_CT {
2132 var BSC_ConnHdlr vc_conn;
2133 f_init();
2134 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "default-route");
2135 vc_conn := f_start_handler(refers(f_tc_smpp_mo_sms), 44);
2136 vc_conn.done;
2137 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "no default-route");
2138}
2139
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002140/* Test MO-SMS from MS/BTS/BSC towards HLR (via GSUP) */
2141private function f_tc_gsup_mo_sms(charstring id, BSC_ConnHdlrPars pars)
2142runs on BSC_ConnHdlr {
2143 var SmsParameters spars := valueof(t_SmsPars);
2144 var GSUP_PDU gsup_msg_rx;
2145 var octetstring sm_tpdu;
2146
2147 f_init_handler(pars);
2148
2149 /* We need to inspect GSUP activity */
2150 f_create_gsup_expect(hex2str(g_pars.imsi));
2151
2152 /* Perform location update */
2153 f_perform_lu();
2154
2155 /* Send CM Service Request for SMS */
2156 f_establish_fully(EST_TYPE_MO_SMS);
2157
2158 /* Prepare expected SM-RP-UI (SM TPDU) */
2159 enc_TPDU_RP_DATA_MS_SGSN_fast(
2160 valueof(ts_SMS_SUBMIT(spars.tp.msg_ref,
2161 spars.tp.da, spars.tp.pid, spars.tp.dcs,
2162 spars.tp.udl, spars.tp.ud)),
2163 sm_tpdu);
2164
2165 var template GSUP_PDU mo_forwardSM := tr_GSUP_MO_FORWARD_SM_REQ(
2166 imsi := g_pars.imsi,
2167 sm_rp_mr := spars.rp.msg_ref,
2168 /* FIXME: extract SM-RP-DA from spars.rp.dest */
2169 sm_rp_da := tr_GSUP_SM_RP_DA_SMSC_ADDR(?),
2170 /* FIXME: MSISDN coding troubles */
2171 sm_rp_oa := tr_GSUP_SM_RP_OA_MSISDN(?),
2172 /* TODO: can we use decmatch here? */
2173 sm_rp_ui := sm_tpdu
2174 );
2175
2176 /* Submit an SMS on DTAP and expect MO-forwardSM-Req on GSUP */
2177 f_mo_sms_submit(spars);
2178 alt {
2179 [] GSUP.receive(mo_forwardSM) -> value gsup_msg_rx {
2180 log("RX MO-forwardSM-Req");
2181 log(gsup_msg_rx);
2182 setverdict(pass);
2183 }
2184 [] GSUP.receive {
2185 log("RX unexpected GSUP message");
2186 setverdict(fail);
2187 mtc.stop;
2188 }
2189 }
2190
2191 /* Trigger RP-ACK by sending MO-forwardSM-Res */
2192 GSUP.send(valueof(ts_GSUP_MO_FORWARD_SM_RES(
2193 imsi := g_pars.imsi,
2194 sm_rp_mr := spars.rp.msg_ref)));
2195 /* Expect RP-ACK on DTAP */
2196 f_mo_sms_wait_rp_ack(spars);
2197
2198 f_expect_clear();
2199}
2200testcase TC_gsup_mo_sms() runs on MTC_CT {
2201 var BSC_ConnHdlr vc_conn;
2202 f_init();
2203 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2204 vc_conn := f_start_handler(refers(f_tc_gsup_mo_sms), 88);
2205 vc_conn.done;
2206 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2207}
2208
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002209/* Test MO-SMMA from MS/BTS/BSC towards HLR (via GSUP) */
2210private function f_tc_gsup_mo_smma(charstring id, BSC_ConnHdlrPars pars)
2211runs on BSC_ConnHdlr {
2212 var SmsParameters spars := valueof(t_SmsPars);
2213 var GSUP_PDU gsup_msg_rx;
2214
2215 f_init_handler(pars);
2216
2217 /* We need to inspect GSUP activity */
2218 f_create_gsup_expect(hex2str(g_pars.imsi));
2219
2220 /* Perform location update */
2221 f_perform_lu();
2222
2223 /* Send CM Service Request for SMS */
2224 f_establish_fully(EST_TYPE_MO_SMS);
2225
2226 var template GSUP_PDU mo_ReadyForSM := tr_GSUP_MO_READY_FOR_SM_REQ(
2227 imsi := g_pars.imsi,
2228 sm_rp_mr := spars.rp.msg_ref,
2229 sm_alert_rsn := GSUP_SM_ALERT_RSN_TYPE_MEM_AVAIL
2230 );
2231
2232 /* Submit an SMS on DTAP and expect MO-forwardSM-Req on GSUP */
2233 f_mo_smma(spars);
2234 alt {
2235 [] GSUP.receive(mo_ReadyForSM) -> value gsup_msg_rx {
2236 log("RX MO-ReadyForSM-Req");
2237 log(gsup_msg_rx);
2238 setverdict(pass);
2239 }
2240 [] GSUP.receive {
2241 log("RX unexpected GSUP message");
2242 setverdict(fail);
2243 mtc.stop;
2244 }
2245 }
2246
2247 /* Trigger RP-ACK by sending MO-forwardSM-Res */
2248 GSUP.send(valueof(ts_GSUP_MO_READY_FOR_SM_RES(
2249 imsi := g_pars.imsi,
2250 sm_rp_mr := spars.rp.msg_ref)));
2251 /* Expect RP-ACK on DTAP */
2252 f_mo_sms_wait_rp_ack(spars);
2253
2254 f_expect_clear();
2255}
2256testcase TC_gsup_mo_smma() runs on MTC_CT {
2257 var BSC_ConnHdlr vc_conn;
2258 f_init();
2259 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2260 vc_conn := f_start_handler(refers(f_tc_gsup_mo_smma), 89);
2261 vc_conn.done;
2262 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2263}
2264
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002265/* Helper for sending MT SMS over GSUP */
2266private function f_gsup_forwardSM_req(SmsParameters spars, OCT1 mms := '00'O)
2267runs on BSC_ConnHdlr {
2268 GSUP.send(ts_GSUP_MT_FORWARD_SM_REQ(
2269 imsi := g_pars.imsi,
2270 /* NOTE: MSC should assign RP-MR itself */
2271 sm_rp_mr := 'FF'O,
2272 /* FIXME: extract SM-RP-DA from spars.rp.dest */
2273 /* TODO: fix encoding of ts_GSUP_SM_RP_DA_IMSI */
2274 sm_rp_da := valueof(ts_GSUP_SM_RP_DA_MSISDN(g_pars.msisdn)),
2275 sm_rp_oa := valueof(ts_GSUP_SM_RP_OA_SMSC_ADDR(g_pars.msisdn)),
2276 /* Encoded SMS TPDU (taken from Wireshark)
2277 * FIXME: we should encode spars somehow */
2278 sm_rp_ui := '00068021436500008111328130858200'O,
2279 sm_rp_mms := mms
2280 ));
2281}
2282
2283/* Test successful MT-SMS (RP-ACK) over GSUP */
2284private function f_tc_gsup_mt_sms_ack(charstring id, BSC_ConnHdlrPars pars)
2285runs on BSC_ConnHdlr {
2286 var SmsParameters spars := valueof(t_SmsPars);
2287
2288 f_init_handler(pars);
2289
2290 /* We need to inspect GSUP activity */
2291 f_create_gsup_expect(hex2str(g_pars.imsi));
2292
2293 /* Perform location update */
2294 f_perform_lu();
2295
2296 /* Register an 'expect' for given IMSI (+TMSI) */
2297 if (isvalue(g_pars.tmsi)) {
2298 f_bssmap_register_imsi(g_pars.imsi, g_pars.tmsi);
2299 } else {
2300 f_bssmap_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
2301 }
2302
2303 var template GSUP_PDU mt_forwardSM_res := tr_GSUP_MT_FORWARD_SM_RES(
2304 imsi := g_pars.imsi,
2305 /* NOTE: MSC should assign RP-MR itself */
2306 sm_rp_mr := ?
2307 );
2308
2309 /* Submit a MT SMS on GSUP */
2310 f_gsup_forwardSM_req(spars);
2311
2312 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
2313 BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi));
2314 f_establish_fully(EST_TYPE_PAG_RESP);
2315
2316 /* Wait for MT SMS on DTAP */
2317 f_mt_sms_expect(spars);
2318
2319 /* Send RP-ACK and expect MT-forwardSM-Res on GSUP */
2320 f_mt_sms_send_rp_ack(spars);
2321 alt {
2322 [] GSUP.receive(mt_forwardSM_res) {
2323 log("RX MT-forwardSM-Res (RP-ACK)");
2324 setverdict(pass);
2325 }
2326 [] GSUP.receive {
2327 log("RX unexpected GSUP message");
2328 setverdict(fail);
2329 mtc.stop;
2330 }
2331 }
2332
2333 f_expect_clear();
2334}
2335testcase TC_gsup_mt_sms_ack() runs on MTC_CT {
2336 var BSC_ConnHdlrPars pars;
2337 var BSC_ConnHdlr vc_conn;
2338 f_init();
2339 pars := f_init_pars(90);
2340 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2341 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_ack), pars);
2342 vc_conn.done;
2343 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2344}
2345
2346/* Test rejected MT-SMS (RP-ERROR) over GSUP */
2347private function f_tc_gsup_mt_sms_err(charstring id, BSC_ConnHdlrPars pars)
2348runs on BSC_ConnHdlr {
2349 var SmsParameters spars := valueof(t_SmsPars);
2350 var OCT1 sm_rp_cause := '78'O; /* dummy RP-Cause value */
2351
2352 f_init_handler(pars);
2353
2354 /* We need to inspect GSUP activity */
2355 f_create_gsup_expect(hex2str(g_pars.imsi));
2356
2357 /* Perform location update */
2358 f_perform_lu();
2359
2360 /* Register an 'expect' for given IMSI (+TMSI) */
2361 if (isvalue(g_pars.tmsi)) {
2362 f_bssmap_register_imsi(g_pars.imsi, g_pars.tmsi);
2363 } else {
2364 f_bssmap_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
2365 }
2366
2367 var template GSUP_PDU mt_forwardSM_err := tr_GSUP_MT_FORWARD_SM_ERR(
2368 imsi := g_pars.imsi,
2369 /* NOTE: MSC should assign RP-MR itself */
2370 sm_rp_mr := ?,
2371 sm_rp_cause := sm_rp_cause
2372 );
2373
2374 /* Submit a MT SMS on GSUP */
2375 f_gsup_forwardSM_req(spars);
2376
2377 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
2378 BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi));
2379 f_establish_fully(EST_TYPE_PAG_RESP);
2380
2381 /* Wait for MT SMS on DTAP */
2382 f_mt_sms_expect(spars);
2383
2384 /* Send RP-ERROR and expect MT-forwardSM-Err on GSUP */
2385 f_mt_sms_send_rp_error(spars, oct2int(sm_rp_cause));
2386 alt {
2387 [] GSUP.receive(mt_forwardSM_err) {
2388 log("RX MT-forwardSM-Err (RP-ERROR)");
2389 setverdict(pass);
2390 mtc.stop;
2391 }
2392 [] GSUP.receive {
2393 log("RX unexpected GSUP message");
2394 setverdict(fail);
2395 mtc.stop;
2396 }
2397 }
2398
2399 f_expect_clear();
2400}
2401testcase TC_gsup_mt_sms_err() runs on MTC_CT {
2402 var BSC_ConnHdlrPars pars;
2403 var BSC_ConnHdlr vc_conn;
2404 f_init();
2405 pars := f_init_pars(91);
2406 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2407 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_err), pars);
2408 vc_conn.done;
2409 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2410}
2411
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002412/* Test SM-RP-MR assignment for MT-SMS over GSUP */
2413private function f_tc_gsup_mt_sms_rp_mr(charstring id, BSC_ConnHdlrPars pars)
2414runs on BSC_ConnHdlr {
2415 var SmsParameters spars1 := valueof(t_SmsPars); /* 1st SMS */
2416 var SmsParameters spars2 := valueof(t_SmsPars); /* 2nd SMS */
2417
2418 f_init_handler(pars);
2419
2420 /* We need to inspect GSUP activity */
2421 f_create_gsup_expect(hex2str(g_pars.imsi));
2422
2423 /* Perform location update */
2424 f_perform_lu();
2425
2426 /* Register an 'expect' for given IMSI (+TMSI) */
2427 if (isvalue(g_pars.tmsi)) {
2428 f_bssmap_register_imsi(g_pars.imsi, g_pars.tmsi);
2429 } else {
2430 f_bssmap_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
2431 }
2432
2433 /* Submit the 1st MT SMS on GSUP */
2434 log("TX MT-forwardSM-Req for the 1st SMS");
2435 f_gsup_forwardSM_req(spars1);
2436
2437 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
2438 BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi));
2439 f_establish_fully(EST_TYPE_PAG_RESP);
2440
2441 /* Wait for 1st MT SMS on DTAP */
2442 f_mt_sms_expect(spars1);
2443 log("RX the 1st SMS on DTAP, DTAP TID is ", spars1.tid,
2444 ", SM-RP-MR is ", spars1.rp.msg_ref);
2445
2446 /* Submit the 2nd MT SMS on GSUP */
2447 log("TX MT-forwardSM-Req for the 2nd SMS");
2448 f_gsup_forwardSM_req(spars2);
2449
2450 /* Wait for 2nd MT SMS on DTAP */
2451 f_mt_sms_expect(spars2);
2452 log("RX the 2nd SMS on DTAP, DTAP TID is ", spars2.tid,
2453 ", SM-RP-MR is ", spars2.rp.msg_ref);
2454
2455 /* Both transaction IDs shall be different */
2456 if (spars1.tid == spars2.tid) {
2457 log("Both DTAP transaction IDs shall be different");
2458 setverdict(fail);
2459 }
2460
2461 /* Both SM-RP-MR values shall be different */
2462 if (spars1.rp.msg_ref == spars2.rp.msg_ref) {
2463 log("Both SM-RP-MR values shall be different");
2464 setverdict(fail);
2465 }
2466
2467 /* Both SM-RP-MR values shall be assigned */
2468 if (spars1.rp.msg_ref == 'FF'O) {
2469 log("Unassigned SM-RP-MR value for the 1st SMS");
2470 setverdict(fail);
2471 }
2472 if (spars2.rp.msg_ref == 'FF'O) {
2473 log("Unassigned SM-RP-MR value for the 2nd SMS");
2474 setverdict(fail);
2475 }
2476
2477 /* Send the 1st RP-ACK and expect MT-forwardSM-Res on GSUP */
2478 f_mt_sms_send_rp_ack(spars1);
2479 alt {
2480 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2481 imsi := g_pars.imsi,
2482 sm_rp_mr := spars1.rp.msg_ref
2483 )) {
2484 log("RX MT-forwardSM-Res (RP-ACK)");
2485 setverdict(pass);
2486 }
2487 [] GSUP.receive {
2488 log("RX unexpected GSUP message");
2489 setverdict(fail);
2490 mtc.stop;
2491 }
2492 }
2493
2494 /* Send the 2nd RP-ACK and expect MT-forwardSM-Res on GSUP */
2495 f_mt_sms_send_rp_ack(spars2);
2496 alt {
2497 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2498 imsi := g_pars.imsi,
2499 sm_rp_mr := spars2.rp.msg_ref
2500 )) {
2501 log("RX MT-forwardSM-Res (RP-ACK)");
2502 setverdict(pass);
2503 }
2504 [] GSUP.receive {
2505 log("RX unexpected GSUP message");
2506 setverdict(fail);
2507 mtc.stop;
2508 }
2509 }
2510
2511 f_expect_clear();
2512}
2513testcase TC_gsup_mt_sms_rp_mr() runs on MTC_CT {
2514 var BSC_ConnHdlrPars pars;
2515 var BSC_ConnHdlr vc_conn;
2516 f_init();
2517 pars := f_init_pars(92);
2518 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2519 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_rp_mr), pars);
2520 vc_conn.done;
2521 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2522}
2523
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07002524/* Test SM-RP-MR assignment for MT-SMS over GSUP */
2525private function f_tc_gsup_mo_mt_sms_rp_mr(charstring id, BSC_ConnHdlrPars pars)
2526runs on BSC_ConnHdlr {
2527 var SmsParameters spars_mo := valueof(t_SmsPars); /* MO SMMA */
2528 var SmsParameters spars_mt := valueof(t_SmsPars); /* MT SMS */
2529
2530 f_init_handler(pars);
2531
2532 /* We need to inspect GSUP activity */
2533 f_create_gsup_expect(hex2str(g_pars.imsi));
2534
2535 /* Perform location update */
2536 f_perform_lu();
2537
2538 /* Register an 'expect' for given IMSI (+TMSI) */
2539 if (isvalue(g_pars.tmsi)) {
2540 f_bssmap_register_imsi(g_pars.imsi, g_pars.tmsi);
2541 } else {
2542 f_bssmap_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
2543 }
2544
2545 /* Send CM Service Request for MO SMMA */
2546 f_establish_fully(EST_TYPE_MO_SMS);
2547
2548 /* Submit MO SMMA on DTAP */
2549 log("Submit MO SMMA on DTAP, SM-RP-MR is '00'O");
2550 spars_mo.rp.msg_ref := '00'O;
2551 f_mo_smma(spars_mo);
2552
2553 /* Expect MO-forwardSM-Req for MO SMMA on GSUP */
2554 alt {
2555 [] GSUP.receive(tr_GSUP_MO_READY_FOR_SM_REQ(
2556 imsi := g_pars.imsi,
2557 sm_rp_mr := spars_mo.rp.msg_ref,
2558 sm_alert_rsn := GSUP_SM_ALERT_RSN_TYPE_MEM_AVAIL
2559 )) {
2560 log("RX MO-ReadyForSM-Req, SM-RP-MR is '00'O");
2561 setverdict(pass);
2562 }
2563 [] GSUP.receive {
2564 log("RX unexpected GSUP message");
2565 setverdict(fail);
2566 mtc.stop;
2567 }
2568 }
2569
2570 /* Submit MT SMS on GSUP */
2571 log("TX MT-forwardSM-Req for the MT SMS");
2572 f_gsup_forwardSM_req(spars_mt);
2573
2574 /* Wait for MT SMS on DTAP */
2575 f_mt_sms_expect(spars_mt);
2576 log("RX MT SMS on DTAP, DTAP TID is ", spars_mt.tid,
2577 ", SM-RP-MR is ", spars_mt.rp.msg_ref);
2578
2579 /* Both SM-RP-MR values shall be different */
2580 if (spars_mo.rp.msg_ref == spars_mt.rp.msg_ref) {
2581 log("Both SM-RP-MR values shall be different");
2582 setverdict(fail);
2583 }
2584
2585 /* SM-RP-MR value for MT SMS shall be assigned */
2586 if (spars_mt.rp.msg_ref == 'FF'O) {
2587 log("Unassigned SM-RP-MR value for the MT SMS");
2588 setverdict(fail);
2589 }
2590
2591 /* Trigger RP-ACK for MO SMMA by sending MO-forwardSM-Res */
2592 GSUP.send(valueof(ts_GSUP_MO_READY_FOR_SM_RES(
2593 imsi := g_pars.imsi,
2594 sm_rp_mr := spars_mo.rp.msg_ref)));
2595 /* Expect RP-ACK for MO SMMA on DTAP */
2596 f_mo_sms_wait_rp_ack(spars_mo);
2597
2598 /* Send RP-ACK for MT SMS and expect MT-forwardSM-Res on GSUP */
2599 f_mt_sms_send_rp_ack(spars_mt);
2600 alt {
2601 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2602 imsi := g_pars.imsi,
2603 sm_rp_mr := spars_mt.rp.msg_ref
2604 )) {
2605 log("RX MT-forwardSM-Res (RP-ACK)");
2606 setverdict(pass);
2607 }
2608 [] GSUP.receive {
2609 log("RX unexpected GSUP message");
2610 setverdict(fail);
2611 mtc.stop;
2612 }
2613 }
2614
2615 f_expect_clear();
2616}
2617testcase TC_gsup_mo_mt_sms_rp_mr() runs on MTC_CT {
2618 var BSC_ConnHdlrPars pars;
2619 var BSC_ConnHdlr vc_conn;
2620 f_init();
2621 pars := f_init_pars(93);
2622 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2623 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mo_mt_sms_rp_mr), pars);
2624 vc_conn.done;
2625 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2626}
2627
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07002628/* Test multi-part MT-SMS over GSUP */
2629private function f_tc_gsup_mt_multi_part_sms(charstring id, BSC_ConnHdlrPars pars)
2630runs on BSC_ConnHdlr {
2631 var SmsParameters spars := valueof(t_SmsPars);
2632
2633 f_init_handler(pars);
2634
2635 /* We need to inspect GSUP activity */
2636 f_create_gsup_expect(hex2str(g_pars.imsi));
2637
2638 /* Perform location update */
2639 f_perform_lu();
2640
2641 /* Register an 'expect' for given IMSI (+TMSI) */
2642 if (isvalue(g_pars.tmsi)) {
2643 f_bssmap_register_imsi(g_pars.imsi, g_pars.tmsi);
2644 } else {
2645 f_bssmap_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
2646 }
2647
2648 var template GSUP_PDU mt_forwardSM_res := tr_GSUP_MT_FORWARD_SM_RES(
2649 imsi := g_pars.imsi,
2650 /* NOTE: MSC should assign RP-MR itself */
2651 sm_rp_mr := ?
2652 );
2653
2654 /* Send 4 messages (NOTE: SM-RP-UI remains unchanged) */
2655 for (var integer i := 3; i >= 0; i := i-1) {
2656 /* Submit a MT SMS on GSUP (MMS is decremented) */
2657 f_gsup_forwardSM_req(spars, int2oct(i, 1));
2658
2659 /* Expect Paging Request and Establish connection */
2660 if (i == 3) { /* ... only once! */
2661 BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi));
2662 f_establish_fully(EST_TYPE_PAG_RESP);
2663 }
2664
2665 /* Wait for MT SMS on DTAP */
2666 f_mt_sms_expect(spars);
2667
2668 /* Send RP-ACK and expect MT-forwardSM-Res on GSUP */
2669 f_mt_sms_send_rp_ack(spars);
2670 alt {
2671 [] GSUP.receive(mt_forwardSM_res) {
2672 log("RX MT-forwardSM-Res (RP-ACK)");
2673 setverdict(pass);
2674 }
2675 [] GSUP.receive {
2676 log("RX unexpected GSUP message");
2677 setverdict(fail);
2678 mtc.stop;
2679 }
2680 }
2681
2682 /* Keep some 'distance' between transmissions */
2683 f_sleep(1.5);
2684 }
2685
2686 f_expect_clear();
2687}
2688testcase TC_gsup_mt_multi_part_sms() runs on MTC_CT {
2689 var BSC_ConnHdlrPars pars;
2690 var BSC_ConnHdlr vc_conn;
2691 f_init();
2692 pars := f_init_pars(91);
2693 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2694 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_multi_part_sms), pars);
2695 vc_conn.done;
2696 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2697}
2698
Harald Weltef640a012018-04-14 17:49:21 +02002699/* convert GSM L3 TON to SMPP_TON enum */
2700function f_sm_ton_from_gsm(BIT3 ton) return SMPP_TON {
2701 select (ton) {
2702 case ('000'B) { return unknown; }
2703 case ('001'B) { return international; }
2704 case ('010'B) { return national; }
2705 case ('011'B) { return network_specific; }
2706 case ('100'B) { return subscriber_number; }
2707 case ('101'B) { return alphanumeric; }
2708 case ('110'B) { return abbreviated; }
2709 }
2710 setverdict(fail, "Unknown TON ", ton);
Daniel Willmannafce8662018-07-06 23:11:32 +02002711 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02002712}
2713/* convert GSM L3 NPI to SMPP_NPI enum */
2714function f_sm_npi_from_gsm(BIT4 npi) return SMPP_NPI {
2715 select (npi) {
2716 case ('0000'B) { return unknown; }
2717 case ('0001'B) { return isdn; }
2718 case ('0011'B) { return data; }
2719 case ('0100'B) { return telex; }
2720 case ('0110'B) { return land_mobile; }
2721 case ('1000'B) { return national; }
2722 case ('1001'B) { return private_; }
2723 case ('1010'B) { return ermes; }
2724 }
2725 setverdict(fail, "Unknown NPI ", npi);
Daniel Willmannafce8662018-07-06 23:11:32 +02002726 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02002727}
2728
2729/* build a SMPP_SM from SmsParameters */
2730function f_mt_sm_from_spars(SmsParameters spars)
2731runs on BSC_ConnHdlr return SMPP_SM {
2732 var SMPP_SM sm := {
2733 service_type := "CMT",
2734 source_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
2735 source_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
2736 source_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
2737 dest_addr_ton := international,
2738 dest_addr_npi := isdn,
2739 destination_addr := hex2str(g_pars.msisdn),
2740 esm_class := '00000001'B,
2741 protocol_id := 0,
2742 priority_flag := 0,
2743 schedule_delivery_time := "",
2744 validity_period := "",
2745 registered_delivery := '00000000'B,
2746 replace_if_present := 0,
2747 data_coding := '00000001'B,
2748 sm_default_msg_id := 0,
2749 sm_length := spars.tp.udl,
2750 short_message := spars.tp.ud,
2751 opt_pars := {}
2752 };
2753 return sm;
2754}
2755
2756/* helper function to encode SMS from 'spars', send it via SMPP to MSC; receive it on MS side */
2757private function f_smpp_mt_sms(SmsParameters spars, boolean trans_mode) runs on BSC_ConnHdlr {
2758 var SMPP_SM sm := f_mt_sm_from_spars(spars);
2759 if (trans_mode) {
2760 sm.esm_class := '00000010'B;
2761 }
2762
2763 /* actually cause MSC to send a SMS via SUBMIT-SM from SMPP side */
2764 SMPP.send(ts_SMPP_SUBMIT_SM(sm));
2765 if (not match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
2766 /* if we're not in SMPP transaction mode, we expect the SMPP-level ACK
2767 * before we expect the SMS delivery on the BSC/radio side */
2768 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
2769 }
2770
2771 /* MSC->BSC: expect PAGING from MSC */
2772 BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi));
2773 /* Establish DTAP / BSSAP / SCCP connection */
2774 f_establish_fully(EST_TYPE_PAG_RESP);
2775 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
2776
2777 f_mt_sms(spars);
2778
2779 if (match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
2780 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
2781 }
2782 f_expect_clear();
2783}
2784
2785/* mobile terminated SMS, from SMPP to BSC/BTS/MS */
2786private function f_tc_smpp_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2787 f_init_handler(pars);
2788
2789 /* Perform location update so IMSI is known + registered in MSC/VLR */
2790 f_perform_lu();
2791 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
2792
2793 /* register an 'expect' for given IMSI (+TMSI) */
2794 var OCT4 tmsi;
2795 if (isvalue(g_pars.tmsi)) {
2796 tmsi := g_pars.tmsi;
2797 } else {
2798 tmsi := 'FFFFFFFF'O;
2799 }
2800 f_bssmap_register_imsi(g_pars.imsi, tmsi);
2801
2802 var SmsParameters spars := valueof(t_SmsPars);
2803 /* TODO: test with more intelligent user data; test different coding schemes */
2804 spars.tp.ud := '00'O;
2805 spars.tp.udl := 1;
2806
2807 /* first test the non-transaction store+forward mode */
2808 f_smpp_mt_sms(spars, false);
2809
2810 /* then test the transaction mode */
2811 f_smpp_mt_sms(spars, true);
2812}
2813testcase TC_smpp_mt_sms() runs on MTC_CT {
2814 var BSC_ConnHdlr vc_conn;
2815 f_init();
2816 vc_conn := f_start_handler(refers(f_tc_smpp_mt_sms), 45);
2817 vc_conn.done;
2818}
2819
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002820/***********************************************************************
2821 * USSD Testing
2822 ***********************************************************************/
2823
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07002824private altstep as_unexp_gsup_or_bssap_msg()
2825runs on BSC_ConnHdlr {
2826 [] GSUP.receive {
2827 setverdict(fail, "Unknown/unexpected GSUP received");
2828 self.stop;
2829 }
2830 [] BSSAP.receive {
2831 setverdict(fail, "Unknown/unexpected BSSAP message received");
2832 self.stop;
2833 }
2834}
2835
2836private function f_expect_gsup_msg(template GSUP_PDU msg)
2837runs on BSC_ConnHdlr return GSUP_PDU {
2838 var GSUP_PDU gsup_msg_complete;
2839
2840 alt {
2841 [] GSUP.receive(msg) -> value gsup_msg_complete {
2842 setverdict(pass);
2843 }
2844 /* We don't expect anything else */
2845 [] as_unexp_gsup_or_bssap_msg();
2846 }
2847
2848 return gsup_msg_complete;
2849}
2850
2851private function f_expect_mt_dtap_msg(template PDU_ML3_NW_MS msg)
2852runs on BSC_ConnHdlr return PDU_ML3_NW_MS {
2853 var PDU_DTAP_MT bssap_msg_complete;
2854
2855 alt {
2856 [] BSSAP.receive(tr_PDU_DTAP_MT(msg)) -> value bssap_msg_complete {
2857 setverdict(pass);
2858 }
2859 /* We don't expect anything else */
2860 [] as_unexp_gsup_or_bssap_msg();
2861 }
2862
2863 return bssap_msg_complete.dtap;
2864}
2865
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07002866/* LU followed by MO USSD request */
2867private function f_tc_lu_and_mo_ussd_single_request(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002868runs on BSC_ConnHdlr {
2869 f_init_handler(pars);
2870
2871 /* Perform location update */
2872 f_perform_lu();
2873
2874 /* Send CM Service Request for SS/USSD */
2875 f_establish_fully(EST_TYPE_SS_ACT);
2876
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002877 /* We need to inspect GSUP activity */
2878 f_create_gsup_expect(hex2str(g_pars.imsi));
2879
2880 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
2881 invoke_id := 5, /* Phone may not start from 0 or 1 */
2882 op_code := SS_OP_CODE_PROCESS_USS_REQ,
2883 ussd_string := "*#100#"
2884 );
2885
2886 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
2887 invoke_id := 5, /* InvokeID shall be the same for both REQ and RSP */
2888 op_code := SS_OP_CODE_PROCESS_USS_REQ,
2889 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
2890 )
2891
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002892 /* Compose a new SS/REGISTER message with request */
2893 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
2894 tid := 1, /* We just need a single transaction */
2895 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002896 facility := valueof(facility_req)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002897 );
2898
2899 /* Compose SS/RELEASE_COMPLETE template with expected response */
2900 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
2901 tid := 1, /* Response should arrive within the same transaction */
2902 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002903 facility := valueof(facility_rsp)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002904 );
2905
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002906 /* Compose expected MSC -> HLR message */
2907 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
2908 imsi := g_pars.imsi,
2909 state := OSMO_GSUP_SESSION_STATE_BEGIN,
2910 ss := valueof(facility_req)
2911 );
2912
2913 /* To be used for sending response with correct session ID */
2914 var GSUP_PDU gsup_req_complete;
2915
2916 /* Request own number */
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002917 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002918 /* Expect GSUP message containing the SS payload */
2919 gsup_req_complete := f_expect_gsup_msg(gsup_req);
2920
2921 /* Compose the response from HLR using received session ID */
2922 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
2923 imsi := g_pars.imsi,
2924 sid := gsup_req_complete.ies[1].val.session_id,
2925 state := OSMO_GSUP_SESSION_STATE_END,
2926 ss := valueof(facility_rsp)
2927 );
2928
2929 /* Finally, HLR terminates the session */
2930 GSUP.send(gsup_rsp);
2931 /* Expect RELEASE_COMPLETE message with the response */
2932 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002933
2934 f_expect_clear();
2935}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07002936testcase TC_lu_and_mo_ussd_single_request() runs on MTC_CT {
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002937 var BSC_ConnHdlr vc_conn;
2938 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07002939 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_single_request), 46);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002940 vc_conn.done;
2941}
2942
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07002943/* LU followed by MT USSD notification */
2944private function f_tc_lu_and_mt_ussd_notification(charstring id, BSC_ConnHdlrPars pars)
2945runs on BSC_ConnHdlr {
2946 f_init_handler(pars);
2947
2948 /* Perform location update */
2949 f_perform_lu();
2950
2951 f_bssmap_register_imsi(g_pars.imsi, g_pars.tmsi);
2952
2953 /* We need to inspect GSUP activity */
2954 f_create_gsup_expect(hex2str(g_pars.imsi));
2955
2956 /* Facility IE with network-originated USSD notification */
2957 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
2958 op_code := SS_OP_CODE_USS_NOTIFY,
2959 ussd_string := "Mahlzeit!"
2960 );
2961
2962 /* Facility IE with acknowledgment to the USSD notification */
2963 var template OCTN facility_rsp := enc_SS_FacilityInformation(
2964 /* In case of USSD notification, Return Result is empty */
2965 valueof(ts_SS_USSD_FACILITY_RETURN_RESULT_EMPTY())
2966 );
2967
2968 /* Compose a new MT SS/REGISTER message with USSD notification */
2969 var template PDU_ML3_NW_MS ussd_ntf := tr_ML3_MT_SS_REGISTER(
2970 tid := 0, /* FIXME: most likely, it should be 0 */
2971 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
2972 facility := valueof(facility_req)
2973 );
2974
2975 /* Compose HLR -> MSC GSUP message */
2976 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
2977 imsi := g_pars.imsi,
2978 sid := '20000101'O,
2979 state := OSMO_GSUP_SESSION_STATE_BEGIN,
2980 ss := valueof(facility_req)
2981 );
2982
2983 /* Send it to MSC and expect Paging Request */
2984 GSUP.send(gsup_req);
2985 alt {
2986 [] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
2987 setverdict(pass);
2988 }
2989 /* We don't expect anything else */
2990 [] as_unexp_gsup_or_bssap_msg();
2991 }
2992
2993 /* Send Paging Response and expect USSD notification */
2994 f_establish_fully(EST_TYPE_PAG_RESP);
2995 /* Expect MT REGISTER message with USSD notification */
2996 f_expect_mt_dtap_msg(ussd_ntf);
2997
2998 /* Compose a new MO SS/FACILITY message with empty response */
2999 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
3000 tid := 0, /* FIXME: it shall match the request tid */
3001 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3002 facility := valueof(facility_rsp)
3003 );
3004
3005 /* Compose expected MSC -> HLR GSUP message */
3006 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
3007 imsi := g_pars.imsi,
3008 sid := '20000101'O,
3009 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3010 ss := valueof(facility_rsp)
3011 );
3012
3013 /* MS sends response to the notification */
3014 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
3015 /* Expect GSUP message containing the SS payload */
3016 f_expect_gsup_msg(gsup_rsp);
3017
3018 /* Compose expected MT SS/RELEASE COMPLETE message */
3019 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
3020 tid := 0, /* FIXME: it shall match the request tid */
3021 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3022 facility := omit
3023 );
3024
3025 /* Compose MSC -> HLR GSUP message */
3026 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
3027 imsi := g_pars.imsi,
3028 sid := '20000101'O,
3029 state := OSMO_GSUP_SESSION_STATE_END
3030 );
3031
3032 /* Finally, HLR terminates the session */
3033 GSUP.send(gsup_term)
3034 /* Expect MT RELEASE COMPLETE without Facility IE */
3035 f_expect_mt_dtap_msg(ussd_term);
3036
3037 f_expect_clear();
3038}
3039testcase TC_lu_and_mt_ussd_notification() runs on MTC_CT {
3040 var BSC_ConnHdlr vc_conn;
3041 f_init();
3042 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_notification), 47);
3043 vc_conn.done;
3044}
3045
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003046/* LU followed by MT call and MO USSD request during this call */
3047private function f_tc_lu_and_mo_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003048runs on BSC_ConnHdlr {
3049 f_init_handler(pars);
3050
3051 /* Call parameters taken from f_tc_lu_and_mt_call */
3052 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
3053 cpars.mgcp_connection_id_bss := '10004'H;
3054 cpars.mgcp_connection_id_mss := '10005'H;
3055 cpars.mgcp_ep := "rtpbridge/1@mgw";
3056 cpars.bss_rtp_port := 1110;
3057
3058 /* Perform location update */
3059 f_perform_lu();
3060
3061 /* Establish a MT call */
3062 f_mt_call_establish(cpars);
3063
3064 /* Hold the call for some time */
3065 f_sleep(1.0);
3066
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003067 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3068 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3069 ussd_string := "*#100#"
3070 );
3071
3072 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3073 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3074 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
3075 )
3076
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003077 /* Compose a new SS/REGISTER message with request */
3078 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
3079 tid := 1, /* We just need a single transaction */
3080 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003081 facility := valueof(facility_req)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003082 );
3083
3084 /* Compose SS/RELEASE_COMPLETE template with expected response */
3085 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
3086 tid := 1, /* Response should arrive within the same transaction */
3087 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003088 facility := valueof(facility_rsp)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003089 );
3090
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003091 /* Compose expected MSC -> HLR message */
3092 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
3093 imsi := g_pars.imsi,
3094 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3095 ss := valueof(facility_req)
3096 );
3097
3098 /* To be used for sending response with correct session ID */
3099 var GSUP_PDU gsup_req_complete;
3100
3101 /* Request own number */
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003102 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003103 /* Expect GSUP message containing the SS payload */
3104 gsup_req_complete := f_expect_gsup_msg(gsup_req);
3105
3106 /* Compose the response from HLR using received session ID */
3107 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
3108 imsi := g_pars.imsi,
3109 sid := gsup_req_complete.ies[1].val.session_id,
3110 state := OSMO_GSUP_SESSION_STATE_END,
3111 ss := valueof(facility_rsp)
3112 );
3113
3114 /* Finally, HLR terminates the session */
3115 GSUP.send(gsup_rsp);
3116 /* Expect RELEASE_COMPLETE message with the response */
3117 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003118
3119 /* Hold the call for some time */
3120 f_sleep(1.0);
3121
3122 /* Release the call (does Clear Complete itself) */
3123 f_call_hangup(cpars, true);
3124}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003125testcase TC_lu_and_mo_ussd_during_mt_call() runs on MTC_CT {
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003126 var BSC_ConnHdlr vc_conn;
3127 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003128 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_during_mt_call), 48);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003129 vc_conn.done;
3130}
3131
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003132/* BSSMAP Clear Request in the middle of a call, see OS#3062 */
3133private function f_tc_mo_cc_bssmap_clear(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3134 f_init_handler(pars);
3135 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
3136 var MNCC_PDU mncc;
3137 var MgcpCommand mgcp_cmd;
3138
3139 f_perform_lu();
3140
3141 f_establish_fully();
3142 f_create_mncc_expect(hex2str(cpars.called_party));
3143 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
3144
3145 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
3146 MNCC.receive(tr_MNCC_SETUP_ind(?, tr_MNCC_number(hex2str(cpars.called_party)))) -> value mncc;
3147 cpars.mncc_callref := mncc.u.signal.callref;
3148 log("mncc_callref=", cpars.mncc_callref);
3149 MNCC.send(ts_MNCC_CALL_PROC_req(cpars.mncc_callref, cpars.mncc_bearer_cap));
3150 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_CALL_PROC(cpars.transaction_id)));
3151
3152 MNCC.send(ts_MNCC_ALERT_req(cpars.mncc_callref));
3153 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_ALERTING(cpars.transaction_id)));
3154 MGCP.receive(tr_CRCX);
3155
3156 f_sleep(1.0);
3157 BSSAP.send(ts_BSSMAP_ClearRequest(0));
3158
3159 MNCC.receive(tr_MNCC_REL_ind(?, ?)) -> value mncc;
3160
3161 BSSAP.receive(tr_BSSMAP_ClearCommand);
3162 BSSAP.send(ts_BSSMAP_ClearComplete);
3163
3164 f_sleep(1.0);
3165}
3166testcase TC_mo_cc_bssmap_clear() runs on MTC_CT {
3167 var BSC_ConnHdlr vc_conn;
3168 f_init();
3169
3170 vc_conn := f_start_handler(refers(f_tc_mo_cc_bssmap_clear), 43);
3171 vc_conn.done;
3172}
3173
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003174/* LU followed by MT call and MT USSD request during this call */
3175private function f_tc_lu_and_mt_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
3176runs on BSC_ConnHdlr {
3177 f_init_handler(pars);
3178
3179 /* Call parameters taken from f_tc_lu_and_mt_call */
3180 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
3181 cpars.mgcp_connection_id_bss := '10004'H;
3182 cpars.mgcp_connection_id_mss := '10005'H;
3183 cpars.mgcp_ep := "rtpbridge/1@mgw";
3184 cpars.bss_rtp_port := 1110;
3185
3186 /* Perform location update */
3187 f_perform_lu();
3188
3189 /* Establish a MT call */
3190 f_mt_call_establish(cpars);
3191
3192 /* Hold the call for some time */
3193 f_sleep(1.0);
3194
3195 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3196 op_code := SS_OP_CODE_USS_REQUEST,
3197 ussd_string := "Please type anything..."
3198 );
3199
3200 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3201 op_code := SS_OP_CODE_USS_REQUEST,
3202 ussd_string := "Nope."
3203 )
3204
3205 /* Compose MT SS/REGISTER message with network-originated request */
3206 var template (value) PDU_ML3_NW_MS ussd_req := ts_ML3_MT_SS_REGISTER(
3207 tid := 0, /* FIXME: most likely, it should be 0 */
3208 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3209 facility := valueof(facility_req)
3210 );
3211
3212 /* Compose HLR -> MSC GSUP message */
3213 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3214 imsi := g_pars.imsi,
3215 sid := '20000101'O,
3216 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3217 ss := valueof(facility_req)
3218 );
3219
3220 /* Send it to MSC */
3221 GSUP.send(gsup_req);
3222 /* Expect MT REGISTER message with USSD request */
3223 f_expect_mt_dtap_msg(ussd_req);
3224
3225 /* Compose a new MO SS/FACILITY message with response */
3226 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
3227 tid := 0, /* FIXME: it shall match the request tid */
3228 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3229 facility := valueof(facility_rsp)
3230 );
3231
3232 /* Compose expected MSC -> HLR GSUP message */
3233 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
3234 imsi := g_pars.imsi,
3235 sid := '20000101'O,
3236 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3237 ss := valueof(facility_rsp)
3238 );
3239
3240 /* MS sends response */
3241 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
3242 f_expect_gsup_msg(gsup_rsp);
3243
3244 /* Compose expected MT SS/RELEASE COMPLETE message */
3245 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
3246 tid := 0, /* FIXME: it shall match the request tid */
3247 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3248 facility := omit
3249 );
3250
3251 /* Compose MSC -> HLR GSUP message */
3252 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
3253 imsi := g_pars.imsi,
3254 sid := '20000101'O,
3255 state := OSMO_GSUP_SESSION_STATE_END
3256 );
3257
3258 /* Finally, HLR terminates the session */
3259 GSUP.send(gsup_term);
3260 /* Expect MT RELEASE COMPLETE without Facility IE */
3261 f_expect_mt_dtap_msg(ussd_term);
3262
3263 /* Hold the call for some time */
3264 f_sleep(1.0);
3265
3266 /* Release the call (does Clear Complete itself) */
3267 f_call_hangup(cpars, true);
3268}
3269testcase TC_lu_and_mt_ussd_during_mt_call() runs on MTC_CT {
3270 var BSC_ConnHdlr vc_conn;
3271 f_init();
3272 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_during_mt_call), 49);
3273 vc_conn.done;
3274}
3275
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07003276/* LU followed by MO USSD request and MO Release during transaction */
3277private function f_tc_lu_and_mo_ussd_mo_release(charstring id, BSC_ConnHdlrPars pars)
3278runs on BSC_ConnHdlr {
3279 f_init_handler(pars);
3280
3281 /* Perform location update */
3282 f_perform_lu();
3283
3284 /* Send CM Service Request for SS/USSD */
3285 f_establish_fully(EST_TYPE_SS_ACT);
3286
3287 /* We need to inspect GSUP activity */
3288 f_create_gsup_expect(hex2str(g_pars.imsi));
3289
3290 var template OCTN facility_ms_req := f_USSD_FACILITY_IE_INVOKE(
3291 invoke_id := 1, /* Initial request */
3292 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3293 ussd_string := "*6766*266#"
3294 );
3295
3296 var template OCTN facility_net_req := f_USSD_FACILITY_IE_INVOKE(
3297 invoke_id := 2, /* Counter request */
3298 op_code := SS_OP_CODE_USS_REQUEST,
3299 ussd_string := "Password?!?"
3300 )
3301
3302 /* Compose MO SS/REGISTER message with request */
3303 var template (value) PDU_ML3_MS_NW ussd_ms_req := ts_ML3_MO_SS_REGISTER(
3304 tid := 1, /* We just need a single transaction */
3305 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3306 facility := valueof(facility_ms_req)
3307 );
3308
3309 /* Compose expected MSC -> HLR message */
3310 var template GSUP_PDU gsup_ms_req := tr_GSUP_PROC_SS_REQ(
3311 imsi := g_pars.imsi,
3312 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3313 ss := valueof(facility_ms_req)
3314 );
3315
3316 /* To be used for sending response with correct session ID */
3317 var GSUP_PDU gsup_ms_req_complete;
3318
3319 /* Initiate a new transaction */
3320 BSSAP.send(ts_PDU_DTAP_MO(ussd_ms_req));
3321 /* Expect GSUP request with original Facility IE */
3322 gsup_ms_req_complete := f_expect_gsup_msg(gsup_ms_req);
3323
3324 /* Compose the response from HLR using received session ID */
3325 var template (value) GSUP_PDU gsup_net_req := ts_GSUP_PROC_SS_REQ(
3326 imsi := g_pars.imsi,
3327 sid := gsup_ms_req_complete.ies[1].val.session_id,
3328 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3329 ss := valueof(facility_net_req)
3330 );
3331
3332 /* Compose expected MT SS/FACILITY template with counter request */
3333 var template PDU_ML3_NW_MS ussd_net_req := tr_ML3_MT_SS_FACILITY(
3334 tid := 1, /* Response should arrive within the same transaction */
3335 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3336 facility := valueof(facility_net_req)
3337 );
3338
3339 /* Send response over GSUP */
3340 GSUP.send(gsup_net_req);
3341 /* Expect MT SS/FACILITY message with counter request */
3342 f_expect_mt_dtap_msg(ussd_net_req);
3343
3344 /* Compose MO SS/RELEASE COMPLETE */
3345 var template (value) PDU_ML3_MS_NW ussd_abort := ts_ML3_MO_SS_RELEASE_COMPLETE(
3346 tid := 1, /* Response should arrive within the same transaction */
3347 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3348 facility := omit
3349 /* TODO: cause? */
3350 );
3351
3352 /* Compose expected HLR -> MSC abort message */
3353 var template GSUP_PDU gsup_abort := tr_GSUP_PROC_SS_REQ(
3354 imsi := g_pars.imsi,
3355 sid := gsup_ms_req_complete.ies[1].val.session_id,
3356 state := OSMO_GSUP_SESSION_STATE_END
3357 );
3358
3359 /* Abort transaction */
3360 BSSAP.send(ts_PDU_DTAP_MO(ussd_abort));
3361 /* Expect GSUP message indicating abort */
3362 f_expect_gsup_msg(gsup_abort);
3363
3364 f_expect_clear();
3365}
3366testcase TC_lu_and_mo_ussd_mo_release() runs on MTC_CT {
3367 var BSC_ConnHdlr vc_conn;
3368 f_init();
3369 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_mo_release), 50);
3370 vc_conn.done;
3371}
3372
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003373/* LU followed by MO USSD request and MT Release due to timeout */
3374private function f_tc_lu_and_ss_session_timeout(charstring id, BSC_ConnHdlrPars pars)
3375runs on BSC_ConnHdlr {
3376 f_init_handler(pars);
3377
3378 /* Perform location update */
3379 f_perform_lu();
3380
3381 /* Send CM Service Request for SS/USSD */
3382 f_establish_fully(EST_TYPE_SS_ACT);
3383
3384 /* We need to inspect GSUP activity */
3385 f_create_gsup_expect(hex2str(g_pars.imsi));
3386
3387 var template OCTN facility_ms_req := f_USSD_FACILITY_IE_INVOKE(
3388 invoke_id := 1,
3389 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3390 ussd_string := "#release_me");
3391
3392 /* Compose MO SS/REGISTER message with request */
3393 var template (value) PDU_ML3_MS_NW ussd_ms_req := ts_ML3_MO_SS_REGISTER(
3394 tid := 1, /* An arbitrary transaction identifier */
3395 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3396 facility := valueof(facility_ms_req));
3397
3398 /* Compose expected MSC -> HLR message */
3399 var template GSUP_PDU gsup_ms_req := tr_GSUP_PROC_SS_REQ(
3400 imsi := g_pars.imsi,
3401 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3402 ss := valueof(facility_ms_req));
3403
3404 /* To be used for sending response with correct session ID */
3405 var GSUP_PDU gsup_ms_req_complete;
3406
3407 /* Initiate a new SS transaction */
3408 BSSAP.send(ts_PDU_DTAP_MO(ussd_ms_req));
3409 /* Expect GSUP request with original Facility IE */
3410 gsup_ms_req_complete := f_expect_gsup_msg(gsup_ms_req);
3411
3412 /* Don't respond, wait for timeout */
3413 f_sleep(3.0);
3414
3415 var template PDU_ML3_NW_MS dtap_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
3416 tid := 1, /* Should match the request's tid */
3417 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3418 cause := *, /* TODO: expect some specific value */
3419 facility := omit);
3420
3421 var template GSUP_PDU gsup_rel := tr_GSUP_PROC_SS_ERR(
3422 imsi := g_pars.imsi,
3423 sid := gsup_ms_req_complete.ies[1].val.session_id,
3424 state := OSMO_GSUP_SESSION_STATE_END,
3425 cause := ?); /* TODO: expect some specific value */
3426
3427 /* Expect release on both interfaces */
3428 interleave {
3429 [] BSSAP.receive(tr_PDU_DTAP_MT(dtap_rel)) { };
3430 [] GSUP.receive(gsup_rel) { };
3431 }
3432
3433 f_expect_clear();
3434 setverdict(pass);
3435}
3436testcase TC_lu_and_ss_session_timeout() runs on MTC_CT {
3437 var BSC_ConnHdlr vc_conn;
3438 f_init();
Vadim Yanitskiy36d28dd2018-12-03 02:45:45 +07003439 f_vty_config(MSCVTY, "msc", "ncss guard-timeout 3");
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003440 vc_conn := f_start_handler(refers(f_tc_lu_and_ss_session_timeout), 51);
3441 vc_conn.done;
Vadim Yanitskiy36d28dd2018-12-03 02:45:45 +07003442 f_vty_config(MSCVTY, "msc", "ncss guard-timeout 0");
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003443}
3444
Stefan Sperling89eb1f32018-12-17 15:06:20 +01003445/* A5/1 only permitted on network side; attempt an invalid CIPHER MODE COMPLETE with A5/3 which MSC should reject. */
3446private function f_tc_cipher_complete_with_invalid_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3447 pars.net.expect_auth := true;
3448 pars.net.expect_ciph := true;
3449 pars.net.kc_support := '02'O; /* A5/1 only */
3450 f_init_handler(pars);
3451
3452 g_pars.vec := f_gen_auth_vec_2g();
3453
3454 /* Can't use f_perform_lu() directly. Code below is based on it. */
3455
3456 /* tell GSUP dispatcher to send this IMSI to us */
3457 f_create_gsup_expect(hex2str(g_pars.imsi));
3458
3459 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
3460 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
3461 f_bssap_compl_l3(l3_lu);
3462
3463 f_mm_auth();
3464
3465 var OCT1 a5_net := f_alg_mask_from_cm(g_pars.cm2);
3466 var OCT1 a5_intersect := g_pars.net.kc_support and4b a5_net;
3467 alt {
3468 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(a5_intersect, g_pars.vec.kc)) {
3469 BSSAP.send(ts_BSSMAP_CipherModeCompl(int2oct(4 /* "accept" A5/3 */, 1)));
3470 }
3471 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?, g_pars.vec.kc)) {
3472 setverdict(fail, "Wrong ciphering algorithm mask in CiphModCmd");
3473 mtc.stop;
3474 }
3475 [] BSSAP.receive {
3476 setverdict(fail, "Unknown/unexpected BSSAP received");
3477 mtc.stop;
3478 }
3479 }
3480
3481 /* Expect LU reject from MSC. */
3482 alt {
3483 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
3484 setverdict(pass);
3485 }
3486 [] BSSAP.receive {
3487 setverdict(fail, "Unknown/unexpected BSSAP received");
3488 mtc.stop;
3489 }
3490 }
Stefan Sperlingc620b352018-12-18 17:23:36 +01003491 f_expect_clear();
Stefan Sperling89eb1f32018-12-17 15:06:20 +01003492}
3493
3494testcase TC_cipher_complete_with_invalid_cipher() runs on MTC_CT {
3495 var BSC_ConnHdlr vc_conn;
3496 f_init();
3497 f_vty_config(MSCVTY, "network", "encryption a5 1");
3498
3499 vc_conn := f_start_handler(refers(f_tc_cipher_complete_with_invalid_cipher), 52);
3500 vc_conn.done;
3501}
3502
Harald Weltef640a012018-04-14 17:49:21 +02003503/* TODO (SMS):
3504 * different user data lengths
3505 * SMPP transaction mode with unsuccessful delivery
3506 * queued MT-SMS with no paging response + later delivery
3507 * different data coding schemes
3508 * multi-part SMS
3509 * user-data headers
3510 * TP-PID for SMS to SIM
3511 * behavior if SMS memory is full + RP-SMMA
3512 * delivery reports
3513 * SMPP osmocom extensions
3514 * more-messages-to-send
3515 * SMS during ongoing call (SACCH/SAPI3)
3516 */
3517
3518/* TODO (General):
Harald Welteba7b6d92018-01-23 21:32:34 +01003519 * continue to send repeated MO signalling messages to keep channel open: does MSC tmeout?
3520 * malformed messages (missing IE, invalid message type): properly rejected?
3521 * MT call while LU or is ongoing: Do we use existing lchan or page while lchan active?
3522 * 3G/2G auth permutations
3523 * encryption algorithms vs. classmark vs. vty config
Harald Welteba7b6d92018-01-23 21:32:34 +01003524 * send new transaction after/during clear (like SMS, ...)
Harald Welte45164da2018-01-24 12:51:27 +01003525 * too long L3 INFO in DTAP
3526 * too long / padded BSSAP
3527 * too long / short TLV values
Harald Welteba7b6d92018-01-23 21:32:34 +01003528 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01003529
Harald Welte4263c522018-12-06 11:56:27 +01003530/* Perform a location updatye at the A-Interface and run some checks to confirm
3531 * that everything is back to normal. */
3532private function f_sgsap_bssmap_screening() runs on BSC_ConnHdlr {
3533 var SmsParameters spars := valueof(t_SmsPars);
3534
3535 /* Perform a location update, the SGs association is expected to fall
3536 * back to NULL */
3537 f_perform_lu();
3538 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
3539
3540 /* Trigger a paging request and expect the paging on BSSMAP, this is
3541 * to make sure that pagings are sent throught the A-Interface again
3542 * and not throught the SGs interface.*/
3543 f_bssmap_register_imsi(g_pars.imsi, g_pars.tmsi);
3544 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
3545
3546 alt {
3547 [] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)); {
3548 setverdict(pass);
3549 }
3550 [] SGsAP.receive {
3551 setverdict(fail, "Received unexpected message on SGs");
3552 }
3553 }
3554
3555 /* Send an SMS to make sure that also payload messages are routed
3556 * throught the A-Interface again */
3557 f_establish_fully(EST_TYPE_MO_SMS);
3558 f_mo_sms(spars);
3559 f_expect_clear();
3560}
3561
3562private function f_tc_sgsap_reset(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3563 var charstring vlr_name;
3564 f_init_handler(pars);
3565
3566 vlr_name := f_sgsap_reset_mme(mp_mme_name);
3567 log("VLR name: ", vlr_name);
3568 setverdict(pass);
3569}
3570
3571testcase TC_sgsap_reset() runs on MTC_CT {
3572 var BSC_ConnHdlr vc_conn;
3573 f_init();
3574 vc_conn := f_start_handler(refers(f_tc_sgsap_reset), 10);
3575 vc_conn.done;
3576}
3577
3578/* like f_mm_auth() but for SGs */
3579function f_mm_auth_sgs() runs on BSC_ConnHdlr {
3580 if (g_pars.net.expect_auth) {
3581 g_pars.vec := f_gen_auth_vec_3g();
3582 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G3G(g_pars.vec.rand,
3583 g_pars.vec.sres,
3584 g_pars.vec.kc,
3585 g_pars.vec.ik,
3586 g_pars.vec.ck,
3587 g_pars.vec.autn,
3588 g_pars.vec.res));
3589 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
3590 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
3591 SGsAP.receive(tr_ML3_MT_MM_AUTH_REQ_3G(g_pars.vec.rand, g_pars.vec.autn));
3592 SGsAP.send(ts_ML3_MT_MM_AUTH_RESP_3G(g_pars.vec.sres, g_pars.vec.res));
3593 }
3594}
3595
3596/* like f_perform_lu(), but on SGs rather than BSSAP */
3597function f_sgs_perform_lu() runs on BSC_ConnHdlr {
3598 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
3599 var PDU_SGsAP lur;
3600 var PDU_SGsAP lua;
3601 var PDU_SGsAP mm_info;
3602 var octetstring mm_info_dtap;
3603
3604 /* tell GSUP dispatcher to send this IMSI to us */
3605 f_create_gsup_expect(hex2str(g_pars.imsi));
3606
3607 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
3608 ts_SGsAP_LAI('901'H, '70'H, 2342)));
3609 /* Old LAI, if MS sends it */
3610 /* TMSI status, if MS has no valid TMSI */
3611 /* IMEISV, if it supports "automatic device detection" */
3612 /* TAI, if available in MME */
3613 /* E-CGI, if available in MME */
3614 SGsAP.send(lur);
3615
3616 /* FIXME: is this really done over SGs? The Ue is already authenticated
3617 * via the MME ... */
3618 f_mm_auth_sgs();
3619
3620 /* Expect MSC to perform LU with HLR */
3621 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
3622 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
3623 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
3624 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
3625
3626 alt {
3627 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) -> value lua {
3628 if (isvalue(lua.sGsAP_LOCATION_UPDATE_ACCEPT.newTMSIorIMSI.iD.iD.tmsi_ptmsi.octets)) {
3629 g_pars.tmsi :=lua.sGsAP_LOCATION_UPDATE_ACCEPT.newTMSIorIMSI.iD.iD.tmsi_ptmsi.octets
3630 SGsAP.send(ts_SGsAP_TMSI_REALL_CMPL(g_pars.imsi));
3631 }
3632 setverdict(pass);
3633 }
3634 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
3635 setverdict(fail, "Received LU-REJECT instead of ACCEPT");
3636 }
3637 [] SGsAP.receive {
3638 setverdict(fail, "Received unexpected message on SGs");
3639 }
3640 }
3641
3642 /* Check MM information */
3643 if (mp_mm_info == true) {
3644 SGsAP.receive(tr_SGsAP_MM_INFO_REQ(g_pars.imsi, ?)) -> value mm_info;
3645 mm_info_dtap := '0532'O & mm_info.sGsAP_MM_INFORMATION_REQUEST.mM_Information.information;
3646 if (not match(dec_PDU_ML3_NW_MS(mm_info_dtap), tr_ML3_MT_MM_Info)) {
3647 setverdict(fail, "Unexpected MM Information");
3648 }
3649 }
3650
3651 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
3652}
3653
3654private function f_tc_sgsap_lu(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3655 f_init_handler(pars);
3656 f_sgs_perform_lu();
3657 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
3658
3659 f_sgsap_bssmap_screening();
3660
3661 setverdict(pass);
3662}
3663testcase TC_sgsap_lu() runs on MTC_CT {
3664 var BSC_ConnHdlr vc_conn;
3665 f_init();
3666 vc_conn := f_start_handler(refers(f_tc_sgsap_lu), 10);
3667 vc_conn.done;
3668}
3669
3670/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
3671private function f_tc_sgsap_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3672 f_init_handler(pars);
3673 var PDU_SGsAP lur;
3674
3675 f_create_gsup_expect(hex2str(g_pars.imsi));
3676 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
3677 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
3678 ts_SGsAP_LAI('901'H, '70'H, 2342)));
3679 SGsAP.send(lur);
3680
3681 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
3682 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
3683 alt {
3684 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
3685 setverdict(pass);
3686 }
3687 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) {
3688 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
3689 mtc.stop;
3690 }
3691 [] SGsAP.receive {
3692 setverdict(fail, "Received unexpected message on SGs");
3693 }
3694 }
3695
3696 f_sgsap_bssmap_screening();
3697
3698 setverdict(pass);
3699}
3700testcase TC_sgsap_lu_imsi_reject() runs on MTC_CT {
3701 var BSC_ConnHdlr vc_conn;
3702 f_init();
3703
3704 vc_conn := f_start_handler(refers(f_tc_sgsap_lu_imsi_reject), 3);
3705 vc_conn.done;
3706}
3707
3708/* Do LU by IMSI, but then remain silent so that Ts6-1 times out */
3709private function f_tc_sgsap_lu_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3710 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
3711 var PDU_SGsAP lur;
3712
3713 f_init_handler(pars);
3714
3715 /* tell GSUP dispatcher to send this IMSI to us */
3716 f_create_gsup_expect(hex2str(g_pars.imsi));
3717
3718 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
3719 ts_SGsAP_LAI('901'H, '70'H, 2342)));
3720 /* Old LAI, if MS sends it */
3721 /* TMSI status, if MS has no valid TMSI */
3722 /* IMEISV, if it supports "automatic device detection" */
3723 /* TAI, if available in MME */
3724 /* E-CGI, if available in MME */
3725 SGsAP.send(lur);
3726
3727 /* FIXME: is this really done over SGs? The Ue is already authenticated
3728 * via the MME ... */
3729 f_mm_auth_sgs();
3730
3731 /* Expect MSC to perform LU with HLR */
3732 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
3733 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
3734 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
3735 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
3736
3737 alt {
3738 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) {
3739 setverdict(pass);
3740 }
3741 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
3742 setverdict(fail, "Received LU-REJECT instead of ACCEPT");
3743 }
3744 [] SGsAP.receive {
3745 setverdict(fail, "Received unexpected message on SGs");
3746 }
3747 }
3748
3749 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
3750
3751 /* Wait until the VLR has abort the TMSI reallocation procedure */
3752 f_sleep(45.0);
3753
3754 /* The outcome does not change the SGs state, see also 5.2.3.4 */
3755 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
3756
3757 f_sgsap_bssmap_screening();
3758
3759 setverdict(pass);
3760}
3761testcase TC_sgsap_lu_and_nothing() runs on MTC_CT {
3762 var BSC_ConnHdlr vc_conn;
3763 f_init();
3764
3765 vc_conn := f_start_handler(refers(f_tc_sgsap_lu_and_nothing), 3);
3766 vc_conn.done;
3767}
3768
3769private function f_tc_sgsap_expl_imsi_det_eps(charstring id, BSC_ConnHdlrPars pars)
3770runs on BSC_ConnHdlr {
3771 f_init_handler(pars);
3772 f_sgs_perform_lu();
3773 f_sleep(3.0);
3774
3775 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
3776 SGsAP.send(ts_SGsAP_EPS_DETACH_IND(g_pars.imsi, mme_name, UE_initiated));
3777 SGsAP.receive(tr_SGsAP_EPS_DETACH_ACK(g_pars.imsi));
3778 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
3779
3780 f_sgsap_bssmap_screening();
3781
3782 setverdict(pass);
3783}
3784testcase TC_sgsap_expl_imsi_det_eps() runs on MTC_CT {
3785 var BSC_ConnHdlr vc_conn;
3786 f_init();
3787 vc_conn := f_start_handler(refers(f_tc_sgsap_expl_imsi_det_eps), 10);
3788 vc_conn.done;
3789}
3790
3791private function f_tc_sgsap_expl_imsi_det_noneps(charstring id, BSC_ConnHdlrPars pars)
3792runs on BSC_ConnHdlr {
3793 f_init_handler(pars);
3794 f_sgs_perform_lu();
3795 f_sleep(3.0);
3796
3797 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
3798 SGsAP.send(ts_SGsAP_IMSI_DETACH_IND(g_pars.imsi, mme_name, combined_UE_initiated));
3799 SGsAP.receive(tr_SGsAP_IMSI_DETACH_ACK(g_pars.imsi));
3800 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
3801 /* FIXME: How to verify that VLR has removed MM context? */
3802
3803 f_sgsap_bssmap_screening();
3804
3805 setverdict(pass);
3806}
3807testcase TC_sgsap_expl_imsi_det_noneps() runs on MTC_CT {
3808 var BSC_ConnHdlr vc_conn;
3809 f_init();
3810 vc_conn := f_start_handler(refers(f_tc_sgsap_expl_imsi_det_noneps), 1081);
3811 vc_conn.done;
3812}
3813
3814/* Trigger a paging request via VTY and send a paging reject in response */
3815private function f_tc_sgsap_paging_rej(charstring id, BSC_ConnHdlrPars pars)
3816runs on BSC_ConnHdlr {
3817 f_init_handler(pars);
3818 f_sgs_perform_lu();
3819 f_sleep(1.0);
3820
3821 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
3822 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
3823 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
3824 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
3825
3826 /* Initiate paging via VTY */
3827 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
3828 alt {
3829 [] SGsAP.receive(exp_resp) {
3830 setverdict(pass);
3831 }
3832 [] SGsAP.receive {
3833 setverdict(fail, "Received unexpected message on SGs");
3834 }
3835 }
3836
3837 /* Now reject the paging */
3838 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, IMSI_unknown));
3839
3840 /* Wait for the states inside the MSC to settle and check the state
3841 * of the SGs Association */
3842 f_sleep(1.0);
3843 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
3844
3845 /* FIXME: At the moment we send an IMSI_unknown as cause code, which is fine,
3846 * but we also need to cover tha case where the cause code indicates an
3847 * "IMSI detached for EPS services". In those cases the VLR is expected to
3848 * try paging on tha A/Iu interface. This will be another testcase similar to
3849 * this one, but extended with checks for the presence of the A/Iu paging
3850 * messages. */
3851
3852 f_sgsap_bssmap_screening();
3853
3854 setverdict(pass);
3855}
3856testcase TC_sgsap_paging_rej() runs on MTC_CT {
3857 var BSC_ConnHdlr vc_conn;
3858 f_init();
3859 vc_conn := f_start_handler(refers(f_tc_sgsap_paging_rej), 1082);
3860 vc_conn.done;
3861}
3862
3863/* Trigger a paging request via VTY and send a paging reject that indicates
3864 * that the subscriber intentionally rejected the call. */
3865private function f_tc_sgsap_paging_subscr_rej(charstring id, BSC_ConnHdlrPars pars)
3866runs on BSC_ConnHdlr {
3867 f_init_handler(pars);
3868 f_sgs_perform_lu();
3869 f_sleep(1.0);
3870
3871 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
3872 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
3873 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
3874 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
3875
3876 /* Initiate paging via VTY */
3877 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
3878 alt {
3879 [] SGsAP.receive(exp_resp) {
3880 setverdict(pass);
3881 }
3882 [] SGsAP.receive {
3883 setverdict(fail, "Received unexpected message on SGs");
3884 }
3885 }
3886
3887 /* Now reject the paging */
3888 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, user_rejected_mobile_terminating_CS_fallback_call));
3889
3890 /* Wait for the states inside the MSC to settle and check the state
3891 * of the SGs Association */
3892 f_sleep(1.0);
3893 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
3894
3895 /* FIXME: The VLR is supposed to trigger an User Determined User Busy (UDUB) as specified
3896 * in 3GPP TS 24.082, this is not yet implemented in the MSC or in this tests, we need
3897 * to check back how this works and how it can be tested */
3898
3899 f_sgsap_bssmap_screening();
3900
3901 setverdict(pass);
3902}
3903testcase TC_sgsap_paging_subscr_rej() runs on MTC_CT {
3904 var BSC_ConnHdlr vc_conn;
3905 f_init();
3906 vc_conn := f_start_handler(refers(f_tc_sgsap_paging_subscr_rej), 1083);
3907 vc_conn.done;
3908}
3909
3910/* Trigger a paging request via VTY and send an UE unreacable messge in response */
3911private function f_tc_sgsap_paging_ue_unr(charstring id, BSC_ConnHdlrPars pars)
3912runs on BSC_ConnHdlr {
3913 f_init_handler(pars);
3914 f_sgs_perform_lu();
3915 f_sleep(1.0);
3916
3917 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
3918 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
3919 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
3920 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
3921
3922 /* Initiate paging via VTY */
3923 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
3924 alt {
3925 [] SGsAP.receive(exp_resp) {
3926 setverdict(pass);
3927 }
3928 [] SGsAP.receive {
3929 setverdict(fail, "Received unexpected message on SGs");
3930 }
3931 }
3932
3933 /* Now pretend that the UE is unreachable */
3934 SGsAP.send(ts_SGsAP_UE_UNREACHABLE(g_pars.imsi, UE_unreachable));
3935
3936 /* Wait for the states inside the MSC to settle and check the state
3937 * of the SGs Association. */
3938 f_sleep(1.0);
3939 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
3940
3941 f_sgsap_bssmap_screening();
3942
3943 setverdict(pass);
3944}
3945testcase TC_sgsap_paging_ue_unr() runs on MTC_CT {
3946 var BSC_ConnHdlr vc_conn;
3947 f_init();
3948 vc_conn := f_start_handler(refers(f_tc_sgsap_paging_ue_unr), 10);
3949 vc_conn.done;
3950}
3951
3952/* Trigger a paging request via VTY but don't respond to it */
3953private function f_tc_sgsap_paging_and_nothing(charstring id, BSC_ConnHdlrPars pars)
3954runs on BSC_ConnHdlr {
3955 f_init_handler(pars);
3956 f_sgs_perform_lu();
3957 f_sleep(1.0);
3958
3959 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
3960 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
3961 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
3962 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
3963
3964 /* Initiate paging via VTY */
3965 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
3966 alt {
3967 [] SGsAP.receive(exp_resp) {
3968 setverdict(pass);
3969 }
3970 [] SGsAP.receive {
3971 setverdict(fail, "Received unexpected message on SGs");
3972 }
3973 }
3974
3975 /* Now do nothing, the MSC/VLR should fail silently to page after a
3976 * few seconds, The SGs association must remain unchanged. */
3977 f_sleep(15.0);
3978 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
3979
3980 f_sgsap_bssmap_screening();
3981
3982 setverdict(pass);
3983}
3984testcase TC_sgsap_paging_and_nothing() runs on MTC_CT {
3985 var BSC_ConnHdlr vc_conn;
3986 f_init();
3987 vc_conn := f_start_handler(refers(f_tc_sgsap_paging_and_nothing), 92);
3988 vc_conn.done;
3989}
3990
3991/* Trigger a paging request via VTY and slip in an LU */
3992private function f_tc_sgsap_paging_and_lu(charstring id, BSC_ConnHdlrPars pars)
3993runs on BSC_ConnHdlr {
3994 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
3995 f_init_handler(pars);
3996
3997 /* First we prepar the situation, where the SGs association is in state
3998 * NULL and the confirmed by radio contact indicator is set to false
3999 * as well. This can be archived by performing an SGs LU and then
4000 * resetting the VLR */
4001 f_sgs_perform_lu();
4002 f_sgsap_reset_mme(mp_mme_name);
4003 f_sleep(1.0);
4004 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4005
4006 /* Perform a paging, expect the paging messages on the SGs interface */
4007 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4008 alt {
4009 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
4010 setverdict(pass);
4011 }
4012 [] SGsAP.receive {
4013 setverdict(fail, "Received unexpected message on SGs");
4014 }
4015 }
4016
4017 /* Perform the LU as normal */
4018 f_sgs_perform_lu();
4019 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4020
4021 /* Expect a new paging request right after the LU */
4022 alt {
4023 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
4024 setverdict(pass);
4025 }
4026 [] SGsAP.receive {
4027 setverdict(fail, "Received unexpected message on SGs");
4028 }
4029 }
4030
4031 /* Test is done now, lets round everything up by rejecting the paging
4032 * cleanly. */
4033 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, user_rejected_mobile_terminating_CS_fallback_call));
4034 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4035
4036 f_sgsap_bssmap_screening();
4037
4038 setverdict(pass);
4039}
4040testcase TC_sgsap_paging_and_lu() runs on MTC_CT {
4041 var BSC_ConnHdlr vc_conn;
4042 f_init();
4043 vc_conn := f_start_handler(refers(f_tc_sgsap_paging_and_lu), 9792);
4044 vc_conn.done;
4045}
4046
4047/* Send unexpected unit-data through the SGs interface */
4048private function f_tc_sgsap_unexp_ud(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4049 f_init_handler(pars);
4050 f_sleep(1.0);
4051
4052 /* This simulates what happens when a subscriber without SGs
4053 * association gets unitdata via the SGs interface. */
4054
4055 /* Make sure the subscriber exists and the SGs association
4056 * is in NULL state */
4057 f_perform_lu();
4058 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4059
4060 /* Send some random unit data, the MSC/VLR should send a release
4061 * immediately. */
4062 SGsAP.send(ts_SGsAP_UL_UD(pars.imsi,'1234'O));
4063 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, IMSI_detached_for_EPS_nonEPS_services));
4064
4065 f_sgsap_bssmap_screening();
4066
4067 setverdict(pass);
4068}
4069testcase TC_sgsap_unexp_ud() runs on MTC_CT {
4070 var BSC_ConnHdlr vc_conn;
4071 f_init();
4072 vc_conn := f_start_handler(refers(f_tc_sgsap_unexp_ud), 2145);
4073 vc_conn.done;
4074}
4075
4076/* Send unsolicited unit-data through the SGs interface */
4077private function f_tc_sgsap_unsol_ud(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4078 f_init_handler(pars);
4079 f_sleep(1.0);
4080
4081 /* This simulates what happens when the MME attempts to send unitdata
4082 * to a subscriber that is completely unknown to the VLR */
4083
4084 /* Send some random unit data, the MSC/VLR should send a release
4085 * immediately. */
4086 SGsAP.send(ts_SGsAP_UL_UD(pars.imsi,'1234'O));
4087 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, IMSI_unknown));
4088
4089 f_sgsap_bssmap_screening();
4090
4091 setverdict(pass);
4092}
4093testcase TC_sgsap_unsol_ud() runs on MTC_CT {
4094 var BSC_ConnHdlr vc_conn;
4095 f_init();
4096 vc_conn := f_start_handler(refers(f_tc_sgsap_unsol_ud), 146);
4097 vc_conn.done;
4098}
4099
4100private altstep as_other_sms_sgs() runs on BSC_ConnHdlr {
4101 /* FIXME: Match an actual payload (second questionmark), the type is
4102 * octetstring, how do we use a tr_PDU_DTAP_MT here? */
4103 [] SGsAP.receive(tr_SGsAP_DL_UD(?,?)) {
4104 setverdict(fail, "Unexpected SMS related PDU from MSC");
4105 mtc.stop;
4106 }
4107}
4108
4109/* receive a MT-SMS delivered from the MSC/SMSC over an already existing SGsAP connection */
4110function f_mt_sms_sgs(inout SmsParameters spars)
4111runs on BSC_ConnHdlr {
4112 var template (value) TPDU_RP_DATA_MS_SGSN tp_mo;
4113 var template (value) RPDU_MS_SGSN rp_mo;
4114 var template (value) PDU_ML3_MS_NW l3_mo;
4115
4116 var template TPDU_RP_DATA_SGSN_MS tp_mt;
4117 var template RPDU_SGSN_MS rp_mt;
4118 var template PDU_ML3_NW_MS l3_mt;
4119
4120 var PDU_ML3_NW_MS sgsap_l3_mt;
4121
4122 var default d := activate(as_other_sms_sgs());
4123
4124 /* Expect CP-DATA(RP-DATA(SMS-DELIVER)) */
4125 tp_mt := tr_SMS_DELIVER(?, spars.tp.ud, spars.tp.pid, spars.tp.dcs, ?);
4126 rp_mt := tr_RP_DATA_MT(?, ?, omit, tp_mt);
4127 l3_mt := tr_ML3_MT_SMS(?, c_TIF_ORIG, tr_CP_DATA_MT(rp_mt));
4128
4129 SGsAP.receive(l3_mt) -> value sgsap_l3_mt;
4130
4131 /* Extract relevant identifiers */
4132 spars.tid := bit2int(sgsap_l3_mt.tiOrSkip.transactionId.tio);
4133 spars.rp.msg_ref := sgsap_l3_mt.msgs.sms.cP_DATA.cP_User_Data.cP_RPDU.rP_DATA_SGSN_MS.rP_MessageReference;
4134
4135 /* send CP-ACK for CP-DATA just received */
4136 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_REPL, ts_CP_ACK_MO);
4137
4138 SGsAP.send(l3_mo);
4139
4140 /* send RP-ACK for RP-DATA */
4141 rp_mo := ts_RP_ACK_MO(spars.rp.msg_ref);
4142 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_REPL, ts_CP_DATA_MO(rp_mo));
4143
4144 SGsAP.send(l3_mo);
4145
4146 /* expect CP-ACK for CP-DATA(RP-ACK) just sent */
4147 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_ORIG, tr_CP_ACK_MT);
4148
4149 SGsAP.receive(l3_mt);
4150
4151 deactivate(d);
4152
4153 setverdict(pass);
4154}
4155
4156/* submit a MO-SMS to MSC/SMSC over an already existing SGsAP connection */
4157function f_mo_sms_sgs(inout SmsParameters spars)
4158runs on BSC_ConnHdlr {
4159 var template (value) TPDU_RP_DATA_MS_SGSN tp_mo;
4160 var template (value) RPDU_MS_SGSN rp_mo;
4161 var template (value) PDU_ML3_MS_NW l3_mo;
4162
4163 var template TPDU_RP_DATA_SGSN_MS tp_mt;
4164 var template RPDU_SGSN_MS rp_mt;
4165 var template PDU_ML3_NW_MS l3_mt;
4166
4167 var default d := activate(as_other_sms_sgs());
4168
4169 /* just in case this is routed to SMPP.. */
4170 f_create_smpp_expect(hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue));
4171
4172 tp_mo := ts_SMS_SUBMIT(spars.tp.msg_ref, spars.tp.da, spars.tp.pid, spars.tp.dcs,
4173 spars.tp.udl, spars.tp.ud);
4174 rp_mo := ts_RP_DATA_MO(spars.rp.msg_ref, spars.rp.orig, spars.rp.dest, tp_mo);
4175 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_DATA_MO(rp_mo));
4176
4177 SGsAP.send(l3_mo);
4178
4179 /* receive CP-ACK for CP-DATA above */
4180 SGsAP.receive(tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_ACK_MT));
4181
4182 if (ispresent(spars.exp_rp_err)) {
4183 /* expect an RP-ERROR message from MSC with given cause */
4184 rp_mt := tr_RP_ERROR_MT(spars.rp.msg_ref, spars.exp_rp_err);
4185 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_DATA_MT(rp_mt));
4186 SGsAP.receive(l3_mt);
4187 /* send CP-ACK for CP-DATA just received */
4188 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_ACK_MO);
4189 SGsAP.send(l3_mo);
4190 } else {
4191 /* expect RP-ACK for RP-DATA */
4192 rp_mt := tr_RP_ACK_MT(spars.rp.msg_ref);
4193 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_DATA_MT(rp_mt));
4194 SGsAP.receive(l3_mt);
4195 /* send CP-ACO for CP-DATA just received */
4196 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_ACK_MO);
4197 SGsAP.send(l3_mo);
4198 }
4199
4200 deactivate(d);
4201
4202 setverdict(pass);
4203}
4204
4205private function f_vty_sms_send_conn_hdlr(charstring imsi, charstring msisdn, charstring text)
4206runs on BSC_ConnHdlr {
4207 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
4208}
4209
4210/* Send a MT SMS via SGs interface */
4211private function f_tc_sgsap_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4212 f_init_handler(pars);
4213 f_sgs_perform_lu();
4214 f_sleep(1.0);
4215 var SmsParameters spars := valueof(t_SmsPars);
4216 spars.tp.ud := 'C8329BFD064D9B53'O;
4217
4218 /* Trigger SMS via VTY */
4219 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
4220 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4221
4222 /* Expect a paging request and respond accordingly with a service request */
4223 SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, SMS_indicator, omit));
4224 SGsAP.send(ts_SGsAP_SERVICE_REQ(pars.imsi, SMS_indicator, EMM_CONNECTED));
4225
4226 /* Connection is now live, receive the MT-SMS */
4227 f_mt_sms_sgs(spars);
4228
4229 /* Expect a concluding release from the MSC */
4230 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, omit));
4231
4232 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
4233 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4234
4235 f_sgsap_bssmap_screening();
4236
4237 setverdict(pass);
4238}
4239testcase TC_sgsap_mt_sms() runs on MTC_CT {
4240 var BSC_ConnHdlr vc_conn;
4241 f_init();
4242 vc_conn := f_start_handler(refers(f_tc_sgsap_mt_sms), 1145);
4243 vc_conn.done;
4244}
4245
4246/* Send a MO SMS via SGs interface */
4247private function f_tc_sgsap_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4248 f_init_handler(pars);
4249 f_sgs_perform_lu();
4250 f_sleep(1.0);
4251 var SmsParameters spars := valueof(t_SmsPars);
4252 spars.tp.ud := 'C8329BFD064D9B53'O;
4253
4254 /* Send the MO-SMS */
4255 f_mo_sms_sgs(spars);
4256
4257 /* Expect a concluding release from the MSC/VLR */
4258 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, omit));
4259
4260 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
4261 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4262
4263 setverdict(pass);
4264
4265 f_sgsap_bssmap_screening()
4266}
4267testcase TC_sgsap_mo_sms() runs on MTC_CT {
4268 var BSC_ConnHdlr vc_conn;
4269 f_init();
4270 vc_conn := f_start_handler(refers(f_tc_sgsap_mo_sms), 3145);
4271 vc_conn.done;
4272}
4273
4274/* Trigger sending of an MT sms via VTY but never respond to anything */
4275private function f_tc_sgsap_mt_sms_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4276 f_init_handler(pars, 170.0);
4277 f_sgs_perform_lu();
4278 f_sleep(1.0);
4279
4280 var SmsParameters spars := valueof(t_SmsPars);
4281 spars.tp.ud := 'C8329BFD064D9B53'O;
4282 var integer page_count := 0;
4283 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4284 var template PDU_SGsAP exp_pag_req := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, SMS_indicator, omit);
4285 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4286 exp_pag_req.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4287
4288 /* Trigger SMS via VTY */
4289 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
4290
4291 /* Expect the MSC/VLR to page exactly 10 times before giving up */
4292 alt {
4293 [] SGsAP.receive(exp_pag_req)
4294 {
4295 page_count := page_count + 1;
4296
4297 if (page_count < 10) {
4298 repeat;
4299 }
4300 }
4301 [] SGsAP.receive {
4302 setverdict(fail, "unexpected SGsAP message received");
4303 self.stop;
4304 }
4305 }
4306
4307 /* Wait some time to make sure the MSC is not delivering any further
4308 * paging messages or anything else that could be unexpected. */
4309 timer T := 20.0;
4310 T.start
4311 alt {
4312 [] SGsAP.receive(exp_pag_req)
4313 {
4314 setverdict(fail, "paging seems not to stop!");
4315 mtc.stop;
4316 }
4317 [] SGsAP.receive {
4318 setverdict(fail, "unexpected SGsAP message received");
4319 self.stop;
4320 }
4321 [] T.timeout {
4322 setverdict(pass);
4323 }
4324 }
4325
4326 /* Even on a failed paging the SGs Association should stay intact */
4327 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4328
4329 /* Note: We do not execute f_sgsap_bssmap_screening() here since the
4330 * MSC/VLR would re-try to deliver the test SMS trigered above and
4331 * so the screening would fail. */
4332
4333 /* Expire the subscriber now to avoid that the MSC will try the SMS
4334 * delivery at some later point. */
4335 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " expire");
4336
4337 setverdict(pass);
4338}
4339testcase TC_sgsap_mt_sms_and_nothing() runs on MTC_CT {
4340 var BSC_ConnHdlr vc_conn;
4341 f_init();
4342 vc_conn := f_start_handler(refers(f_tc_sgsap_mt_sms_and_nothing), 4581);
4343 vc_conn.done;
4344}
4345
4346/* Trigger sending of an MT sms via VTY but reject the paging immediately */
4347private function f_tc_sgsap_mt_sms_and_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4348 f_init_handler(pars, 150.0);
4349 f_sgs_perform_lu();
4350 f_sleep(1.0);
4351
4352 var SmsParameters spars := valueof(t_SmsPars);
4353 spars.tp.ud := 'C8329BFD064D9B53'O;
4354 var integer page_count := 0;
4355 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4356 var template PDU_SGsAP exp_pag_req := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, SMS_indicator, omit);
4357 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4358 exp_pag_req.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4359
4360 /* Trigger SMS via VTY */
4361 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
4362
4363 /* Expect a paging request and reject it immediately */
4364 SGsAP.receive(exp_pag_req);
4365 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, IMSI_unknown));
4366
4367 /* The MSC/VLR should no longer try to page once the paging has been
4368 * rejected. Wait some time and check if there are no unexpected
4369 * messages on the SGs interface. */
4370 timer T := 20.0;
4371 T.start
4372 alt {
4373 [] SGsAP.receive(exp_pag_req)
4374 {
4375 setverdict(fail, "paging seems not to stop!");
4376 mtc.stop;
4377 }
4378 [] SGsAP.receive {
4379 setverdict(fail, "unexpected SGsAP message received");
4380 self.stop;
4381 }
4382 [] T.timeout {
4383 setverdict(pass);
4384 }
4385 }
4386
4387 /* A rejected paging with IMSI_unknown (see above) should always send
4388 * the SGs association to NULL. */
4389 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4390
4391 f_sgsap_bssmap_screening();
4392
4393 /* Expire the subscriber now to avoid that the MSC will try the SMS
4394 * delivery at some later point. */
4395 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " expire");
4396
4397 setverdict(pass);
4398}
4399testcase TC_sgsap_mt_sms_and_reject() runs on MTC_CT {
4400 var BSC_ConnHdlr vc_conn;
4401 f_init();
4402 vc_conn := f_start_handler(refers(f_tc_sgsap_mt_sms_and_reject), 4145);
4403 vc_conn.done;
4404}
4405
4406/* Perform an MT CSDB call including LU */
4407private function f_mt_lu_and_csfb_call(charstring id, BSC_ConnHdlrPars pars, boolean bssmap_lu) runs on BSC_ConnHdlr {
4408 f_init_handler(pars);
4409
4410 /* Be sure that the BSSMAP reset is done before we begin. */
4411 f_sleep(2.0);
4412
4413 /* Testcase variation: See what happens when we do a regular BSSMAP
4414 * LU first (this should not hurt in any way!) */
4415 if (bssmap_lu) {
4416 f_perform_lu();
4417 }
4418
4419 f_sgs_perform_lu();
4420 f_sleep(1.0);
4421
4422 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4423 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
4424 cpars.bss_rtp_port := 1110;
4425 cpars.mgcp_connection_id_bss := '10004'H;
4426 cpars.mgcp_connection_id_mss := '10005'H;
4427
4428 /* Note: This is an optional parameter. When the call-agent (MSC) does
4429 * supply a full endpoint name this setting will be overwritten. */
4430 cpars.mgcp_ep := "rtpbridge/1@mgw";
4431
4432 /* Initiate a call via MNCC interface */
4433 f_mt_call_initate(cpars);
4434
4435 /* Expect a paging request and respond accordingly with a service request */
4436 SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit));
4437 SGsAP.send(ts_SGsAP_SERVICE_REQ(pars.imsi, CS_call_indicator, EMM_CONNECTED));
4438
4439 /* Complete the call, hold it for some time and then tear it down */
4440 f_mt_call_complete(cpars);
4441 f_sleep(3.0);
4442 f_call_hangup(cpars, true);
4443
4444 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
4445 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4446
4447 /* Finally simulate the return of the UE to the 4G network */
4448 SGsAP.send(ts_SGsAP_MO_CSFB_IND(pars.imsi));
4449
4450 /* Test for successful return by triggering a paging, when the paging
4451 * request is received via SGs, we can be sure that the MSC/VLR has
4452 * recognized that the UE is now back on 4G */
4453 f_sleep(1.0);
4454 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4455 alt {
4456 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
4457 setverdict(pass);
4458 }
4459 [] SGsAP.receive {
4460 setverdict(fail, "Received unexpected message on SGs");
4461 }
4462 }
4463
4464 f_sgsap_bssmap_screening();
4465
4466 setverdict(pass);
4467}
4468
4469/* Perform a regular BSSAP LU first, do a SGSAP LU and then make a CSFB call */
4470private function f_tc_bssap_lu_sgsap_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4471 f_mt_lu_and_csfb_call(id, pars, true);
4472}
4473testcase TC_bssap_lu_sgsap_lu_and_mt_call() runs on MTC_CT {
4474 var BSC_ConnHdlr vc_conn;
4475 f_init();
4476
4477 vc_conn := f_start_handler(refers(f_tc_bssap_lu_sgsap_lu_and_mt_call), 139);
4478 vc_conn.done;
4479}
4480
4481
4482/* Perform a SGSAP LU and then make a CSFB call */
4483private function f_tc_sgsap_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4484 f_mt_lu_and_csfb_call(id, pars, false);
4485}
4486testcase TC_sgsap_lu_and_mt_call() runs on MTC_CT {
4487 var BSC_ConnHdlr vc_conn;
4488 f_init();
4489
4490 vc_conn := f_start_handler(refers(f_tc_sgsap_lu_and_mt_call), 239);
4491 vc_conn.done;
4492}
4493
4494/* SGs TODO:
4495 * LU attempt for IMSI without NAM_PS in HLR
4496 * LU attempt with AUTH FAIL due to invalid RES/SRES
4497 * LU attempt with no response from HLR (VLR should timeout + LU REJ)
4498 * LU attempt with new TMSI but without TMSI REALL CMPL baco to VLR
4499 * implicit IMSI detach from EPS
4500 * implicit IMSI detach from non-EPS
4501 * MM INFO
4502 *
4503 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01004504
4505control {
Philipp Maier328d1662018-03-07 10:40:27 +01004506 execute( TC_cr_before_reset() );
Harald Weltea49e36e2018-01-21 19:29:33 +01004507 execute( TC_lu_imsi_noauth_tmsi() );
Harald Welted2328a22018-01-27 14:27:16 +01004508 execute( TC_lu_imsi_noauth_notmsi() );
Harald Weltea49e36e2018-01-21 19:29:33 +01004509 execute( TC_lu_imsi_reject() );
4510 execute( TC_lu_imsi_timeout_gsup() );
Harald Welted2328a22018-01-27 14:27:16 +01004511 execute( TC_lu_imsi_auth_tmsi() );
4512 execute( TC_cmserv_imsi_unknown() );
Harald Welte2bb825f2018-01-22 11:31:18 +01004513 execute( TC_lu_and_mo_call() );
Harald Welte071ed732018-01-23 19:53:52 +01004514 execute( TC_lu_auth_sai_timeout() );
4515 execute( TC_lu_auth_sai_err() );
Harald Weltee1a2f3c2018-01-24 17:28:48 +01004516 execute( TC_lu_clear_request() );
4517 execute( TC_lu_disconnect() );
4518 execute( TC_lu_by_imei() );
4519 execute( TC_lu_by_tmsi_noauth_unknown() );
4520 execute( TC_imsi_detach_by_imsi() );
4521 execute( TC_imsi_detach_by_tmsi() );
4522 execute( TC_imsi_detach_by_imei() );
4523 execute( TC_emerg_call_imei_reject() );
4524 execute( TC_emerg_call_imsi() );
4525 execute( TC_cm_serv_req_vgcs_reject() );
4526 execute( TC_cm_serv_req_vbs_reject() );
4527 execute( TC_cm_serv_req_lcs_reject() );
Harald Welte0195ab12018-01-24 21:50:20 +01004528 execute( TC_cm_reest_req_reject() );
Harald Welte1af6ea82018-01-25 18:33:15 +01004529 execute( TC_lu_auth_2G_fail() );
4530 execute( TC_lu_imsi_auth_tmsi_encr_13_13() );
4531 execute( TC_cl3_no_payload() );
4532 execute( TC_cl3_rnd_payload() );
Harald Welte1852a842018-01-26 22:53:36 +01004533 execute( TC_establish_and_nothing() );
4534 execute( TC_mo_setup_and_nothing() );
4535 execute( TC_mo_crcx_ran_timeout() );
4536 execute( TC_mo_crcx_ran_reject() );
Harald Welted2328a22018-01-27 14:27:16 +01004537 execute( TC_mt_crcx_ran_reject() );
Daniel Willmann8b084372018-02-04 13:35:26 +01004538 execute( TC_mo_setup_and_dtmf_dup() );
Harald Welteaa54cf82018-01-30 08:15:32 +01004539 //execute( TC_mt_t310() );
Harald Welte167458a2018-01-27 15:58:16 +01004540 execute( TC_gsup_cancel() );
Harald Welte9de84792018-01-28 01:06:35 +01004541 execute( TC_lu_imsi_auth_tmsi_encr_1_13() );
4542 execute( TC_lu_imsi_auth_tmsi_encr_3_13() );
4543 execute( TC_lu_imsi_auth_tmsi_encr_3_1() );
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01004544 execute( TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() );
Harald Welte9de84792018-01-28 01:06:35 +01004545 execute( TC_lu_imsi_auth_tmsi_encr_13_2() );
4546 execute( TC_lu_imsi_auth_tmsi_encr_013_2() );
Philipp Maier94f3f1b2018-03-15 18:54:13 +01004547 execute( TC_mo_release_timeout() );
Philipp Maier2a98a732018-03-19 16:06:12 +01004548 execute( TC_lu_and_mt_call_no_dlcx_resp() );
Philipp Maier75932982018-03-27 14:52:35 +02004549 execute( TC_reset_two() );
Harald Welte33ec09b2018-02-10 15:34:46 +01004550
4551 execute( TC_lu_and_mt_call() );
4552
Harald Weltef45efeb2018-04-09 18:19:24 +02004553 execute( TC_lu_and_mo_sms() );
4554 execute( TC_lu_and_mt_sms() );
Philipp Maier3983e702018-11-22 19:01:33 +01004555 execute( TC_lu_and_mt_sms_paging_and_nothing() );
Harald Weltef640a012018-04-14 17:49:21 +02004556 execute( TC_smpp_mo_sms() );
4557 execute( TC_smpp_mt_sms() );
Harald Weltef45efeb2018-04-09 18:19:24 +02004558
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07004559 execute( TC_gsup_mo_sms() );
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07004560 execute( TC_gsup_mo_smma() );
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07004561 execute( TC_gsup_mt_sms_ack() );
4562 execute( TC_gsup_mt_sms_err() );
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07004563 execute( TC_gsup_mt_sms_rp_mr() );
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07004564 execute( TC_gsup_mo_mt_sms_rp_mr() );
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07004565 execute( TC_gsup_mt_multi_part_sms() );
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07004566
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07004567 execute( TC_lu_and_mo_ussd_single_request() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07004568 execute( TC_lu_and_mt_ussd_notification() );
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07004569 execute( TC_lu_and_mo_ussd_during_mt_call() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07004570 execute( TC_lu_and_mt_ussd_during_mt_call() );
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07004571 execute( TC_lu_and_mo_ussd_mo_release() );
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07004572 execute( TC_lu_and_ss_session_timeout() );
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07004573
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004574 execute( TC_cipher_complete_with_invalid_cipher() );
4575
Harald Welte4263c522018-12-06 11:56:27 +01004576 execute( TC_sgsap_reset() );
4577 execute( TC_sgsap_lu() );
4578 execute( TC_sgsap_lu_imsi_reject() );
4579 execute( TC_sgsap_lu_and_nothing() );
4580 execute( TC_sgsap_expl_imsi_det_eps() );
4581 execute( TC_sgsap_expl_imsi_det_noneps() );
4582 execute( TC_sgsap_paging_rej() );
4583 execute( TC_sgsap_paging_subscr_rej() );
4584 execute( TC_sgsap_paging_ue_unr() );
4585 execute( TC_sgsap_paging_and_nothing() );
4586 execute( TC_sgsap_paging_and_lu() );
4587 execute( TC_sgsap_mt_sms() );
4588 execute( TC_sgsap_mo_sms() );
4589 execute( TC_sgsap_mt_sms_and_nothing() );
4590 execute( TC_sgsap_mt_sms_and_reject() );
4591 execute( TC_sgsap_unexp_ud() );
4592 execute( TC_sgsap_unsol_ud() );
4593 execute( TC_bssap_lu_sgsap_lu_and_mt_call() );
4594 execute( TC_sgsap_lu_and_mt_call() );
4595
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01004596 /* Run this last: at the time of writing this test crashes the MSC */
4597 execute( TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() );
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02004598 execute( TC_mo_cc_bssmap_clear() );
Harald Weltef6dd64d2017-11-19 12:09:51 +01004599}
4600
4601
4602}